VTI SCORE: 100/100
Dynamic Analysis Report |
Classification: |
Ransomware
|
Threat Names: |
Djvu
STOP
Trojan.GenericKD.42870227
...
|
1A3E.TMP.EXE.exe
Windows Exe (x86-32)
Created at 2020-03-21T04:46:00
Remarks (2/2)
(0x0200003A): A task was rescheduled ahead of time to reveal dormant functionality.
Remarks
(0x0200001B): The maximum number of file reputation requests per analysis (150) was exceeded.
This is a filtered view
This list contains only the embedded files, downloaded files, and dropped files
Filters: |
There are no files for this filter
There are no files in this analysis
Filename | Category | Type | Severity | Actions |
---|
C:\Users\5p5NrGJn0jS HALPmcxz\Desktop\1A3E.TMP.EXE.exe | Sample File | Binary |
Malicious
|
...
|
»
PE Information
»
Image Base | 0x400000 |
Entry Point | 0x40298c |
Size Of Code | 0xa2e00 |
Size Of Initialized Data | 0xbca00 |
File Type | FileType.executable |
Subsystem | Subsystem.windows_gui |
Machine Type | MachineType.i386 |
Compile Timestamp | 2018-09-27 10:29:37+00:00 |
Sections (4)
»
Name | Virtual Address | Virtual Size | Raw Data Size | Raw Data Offset | Flags | Entropy |
---|---|---|---|---|---|---|
.text | 0x401000 | 0xa2dd0 | 0xa2e00 | 0x400 | IMAGE_SCN_CNT_CODE, IMAGE_SCN_MEM_EXECUTE, IMAGE_SCN_MEM_READ | 7.97 |
.rdata | 0x4a4000 | 0x42de | 0x4400 | 0xa3200 | IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_READ | 6.59 |
.data | 0x4a9000 | 0xaedd4 | 0x1a00 | 0xa7600 | IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_READ, IMAGE_SCN_MEM_WRITE | 3.15 |
.rsrc | 0x558000 | 0x8240 | 0x8400 | 0xa9000 | IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_READ | 5.8 |
Imports (2)
»
KERNEL32.dll (101)
»
API Name | Ordinal | IAT Address | Thunk RVA | Thunk Offset | Hint |
---|---|---|---|---|---|
GetVolumeNameForVolumeMountPointA | 0x0 | 0x4a4000 | 0xa7980 | 0xa6b80 | 0x27a |
GetFullPathNameA | 0x0 | 0x4a4004 | 0xa7984 | 0xa6b84 | 0x1dc |
GetEnvironmentVariableW | 0x0 | 0x4a4008 | 0xa7988 | 0xa6b88 | 0x1c3 |
SetVolumeLabelA | 0x0 | 0x4a400c | 0xa798c | 0xa6b8c | 0x418 |
WriteConsoleOutputCharacterW | 0x0 | 0x4a4010 | 0xa7990 | 0xa6b90 | 0x48a |
lstrlenA | 0x0 | 0x4a4014 | 0xa7994 | 0xa6b94 | 0x4b5 |
HeapAlloc | 0x0 | 0x4a4018 | 0xa7998 | 0xa6b98 | 0x29d |
ClearCommError | 0x0 | 0x4a401c | 0xa799c | 0xa6b9c | 0x41 |
GetQueuedCompletionStatus | 0x0 | 0x4a4020 | 0xa79a0 | 0xa6ba0 | 0x235 |
SetConsoleTextAttribute | 0x0 | 0x4a4024 | 0xa79a4 | 0xa6ba4 | 0x3c0 |
FindFirstFileExW | 0x0 | 0x4a4028 | 0xa79a8 | 0xa6ba8 | 0x11f |
GetTickCount | 0x0 | 0x4a402c | 0xa79ac | 0xa6bac | 0x266 |
GetProcessTimes | 0x0 | 0x4a4030 | 0xa79b0 | 0xa6bb0 | 0x22a |
GlobalAlloc | 0x0 | 0x4a4034 | 0xa79b4 | 0xa6bb4 | 0x285 |
SizeofResource | 0x0 | 0x4a4038 | 0xa79b8 | 0xa6bb8 | 0x420 |
EnumSystemCodePagesA | 0x0 | 0x4a403c | 0xa79bc | 0xa6bbc | 0xf2 |
GetWriteWatch | 0x0 | 0x4a4040 | 0xa79c0 | 0xa6bc0 | 0x282 |
SetConsoleCursorPosition | 0x0 | 0x4a4044 | 0xa79c4 | 0xa6bc4 | 0x3ab |
GetAtomNameW | 0x0 | 0x4a4048 | 0xa79c8 | 0xa6bc8 | 0x156 |
GetModuleFileNameW | 0x0 | 0x4a404c | 0xa79cc | 0xa6bcc | 0x1f5 |
MultiByteToWideChar | 0x0 | 0x4a4050 | 0xa79d0 | 0xa6bd0 | 0x31a |
IsBadStringPtrA | 0x0 | 0x4a4054 | 0xa79d4 | 0xa6bd4 | 0x2c9 |
GetLastError | 0x0 | 0x4a4058 | 0xa79d8 | 0xa6bd8 | 0x1e6 |
EnumDateFormatsExA | 0x0 | 0x4a405c | 0xa79dc | 0xa6bdc | 0xe0 |
LoadLibraryA | 0x0 | 0x4a4060 | 0xa79e0 | 0xa6be0 | 0x2f1 |
GetProcessWorkingSetSize | 0x0 | 0x4a4064 | 0xa79e4 | 0xa6be4 | 0x22c |
SetFileApisToANSI | 0x0 | 0x4a4068 | 0xa79e8 | 0xa6be8 | 0x3d5 |
GetDefaultCommConfigA | 0x0 | 0x4a406c | 0xa79ec | 0xa6bec | 0x1b1 |
FindFirstVolumeMountPointA | 0x0 | 0x4a4070 | 0xa79f0 | 0xa6bf0 | 0x128 |
WTSGetActiveConsoleSessionId | 0x0 | 0x4a4074 | 0xa79f4 | 0xa6bf4 | 0x45f |
VirtualProtect | 0x0 | 0x4a4078 | 0xa79f8 | 0xa6bf8 | 0x45a |
CompareStringA | 0x0 | 0x4a407c | 0xa79fc | 0xa6bfc | 0x52 |
SetCalendarInfoA | 0x0 | 0x4a4080 | 0xa7a00 | 0xa6c00 | 0x398 |
GetWindowsDirectoryW | 0x0 | 0x4a4084 | 0xa7a04 | 0xa6c04 | 0x281 |
GetCurrentProcessId | 0x0 | 0x4a4088 | 0xa7a08 | 0xa6c08 | 0x1aa |
FindNextVolumeA | 0x0 | 0x4a408c | 0xa7a0c | 0xa6c0c | 0x132 |
GetStartupInfoW | 0x0 | 0x4a4090 | 0xa7a10 | 0xa6c10 | 0x23a |
TerminateProcess | 0x0 | 0x4a4094 | 0xa7a14 | 0xa6c14 | 0x42d |
GetCurrentProcess | 0x0 | 0x4a4098 | 0xa7a18 | 0xa6c18 | 0x1a9 |
UnhandledExceptionFilter | 0x0 | 0x4a409c | 0xa7a1c | 0xa6c1c | 0x43e |
SetUnhandledExceptionFilter | 0x0 | 0x4a40a0 | 0xa7a20 | 0xa6c20 | 0x415 |
IsDebuggerPresent | 0x0 | 0x4a40a4 | 0xa7a24 | 0xa6c24 | 0x2d1 |
EnterCriticalSection | 0x0 | 0x4a40a8 | 0xa7a28 | 0xa6c28 | 0xd9 |
LeaveCriticalSection | 0x0 | 0x4a40ac | 0xa7a2c | 0xa6c2c | 0x2ef |
RtlUnwind | 0x0 | 0x4a40b0 | 0xa7a30 | 0xa6c30 | 0x392 |
HeapFree | 0x0 | 0x4a40b4 | 0xa7a34 | 0xa6c34 | 0x2a1 |
SetFilePointer | 0x0 | 0x4a40b8 | 0xa7a38 | 0xa6c38 | 0x3df |
CloseHandle | 0x0 | 0x4a40bc | 0xa7a3c | 0xa6c3c | 0x43 |
GetModuleHandleW | 0x0 | 0x4a40c0 | 0xa7a40 | 0xa6c40 | 0x1f9 |
Sleep | 0x0 | 0x4a40c4 | 0xa7a44 | 0xa6c44 | 0x421 |
GetProcAddress | 0x0 | 0x4a40c8 | 0xa7a48 | 0xa6c48 | 0x220 |
ExitProcess | 0x0 | 0x4a40cc | 0xa7a4c | 0xa6c4c | 0x104 |
WriteFile | 0x0 | 0x4a40d0 | 0xa7a50 | 0xa6c50 | 0x48d |
GetStdHandle | 0x0 | 0x4a40d4 | 0xa7a54 | 0xa6c54 | 0x23b |
GetModuleFileNameA | 0x0 | 0x4a40d8 | 0xa7a58 | 0xa6c58 | 0x1f4 |
FreeEnvironmentStringsW | 0x0 | 0x4a40dc | 0xa7a5c | 0xa6c5c | 0x14b |
GetEnvironmentStringsW | 0x0 | 0x4a40e0 | 0xa7a60 | 0xa6c60 | 0x1c1 |
GetCommandLineW | 0x0 | 0x4a40e4 | 0xa7a64 | 0xa6c64 | 0x170 |
SetHandleCount | 0x0 | 0x4a40e8 | 0xa7a68 | 0xa6c68 | 0x3e8 |
GetFileType | 0x0 | 0x4a40ec | 0xa7a6c | 0xa6c6c | 0x1d7 |
GetStartupInfoA | 0x0 | 0x4a40f0 | 0xa7a70 | 0xa6c70 | 0x239 |
DeleteCriticalSection | 0x0 | 0x4a40f4 | 0xa7a74 | 0xa6c74 | 0xbe |
TlsGetValue | 0x0 | 0x4a40f8 | 0xa7a78 | 0xa6c78 | 0x434 |
TlsAlloc | 0x0 | 0x4a40fc | 0xa7a7c | 0xa6c7c | 0x432 |
TlsSetValue | 0x0 | 0x4a4100 | 0xa7a80 | 0xa6c80 | 0x435 |
TlsFree | 0x0 | 0x4a4104 | 0xa7a84 | 0xa6c84 | 0x433 |
InterlockedIncrement | 0x0 | 0x4a4108 | 0xa7a88 | 0xa6c88 | 0x2c0 |
SetLastError | 0x0 | 0x4a410c | 0xa7a8c | 0xa6c8c | 0x3ec |
GetCurrentThreadId | 0x0 | 0x4a4110 | 0xa7a90 | 0xa6c90 | 0x1ad |
InterlockedDecrement | 0x0 | 0x4a4114 | 0xa7a94 | 0xa6c94 | 0x2bc |
HeapCreate | 0x0 | 0x4a4118 | 0xa7a98 | 0xa6c98 | 0x29f |
VirtualFree | 0x0 | 0x4a411c | 0xa7a9c | 0xa6c9c | 0x457 |
QueryPerformanceCounter | 0x0 | 0x4a4120 | 0xa7aa0 | 0xa6ca0 | 0x354 |
GetSystemTimeAsFileTime | 0x0 | 0x4a4124 | 0xa7aa4 | 0xa6ca4 | 0x24f |
RaiseException | 0x0 | 0x4a4128 | 0xa7aa8 | 0xa6ca8 | 0x35a |
GetCPInfo | 0x0 | 0x4a412c | 0xa7aac | 0xa6cac | 0x15b |
GetACP | 0x0 | 0x4a4130 | 0xa7ab0 | 0xa6cb0 | 0x152 |
GetOEMCP | 0x0 | 0x4a4134 | 0xa7ab4 | 0xa6cb4 | 0x213 |
IsValidCodePage | 0x0 | 0x4a4138 | 0xa7ab8 | 0xa6cb8 | 0x2db |
WideCharToMultiByte | 0x0 | 0x4a413c | 0xa7abc | 0xa6cbc | 0x47a |
CreateFileA | 0x0 | 0x4a4140 | 0xa7ac0 | 0xa6cc0 | 0x78 |
InitializeCriticalSectionAndSpinCount | 0x0 | 0x4a4144 | 0xa7ac4 | 0xa6cc4 | 0x2b5 |
VirtualAlloc | 0x0 | 0x4a4148 | 0xa7ac8 | 0xa6cc8 | 0x454 |
HeapReAlloc | 0x0 | 0x4a414c | 0xa7acc | 0xa6ccc | 0x2a4 |
SetStdHandle | 0x0 | 0x4a4150 | 0xa7ad0 | 0xa6cd0 | 0x3fc |
GetConsoleCP | 0x0 | 0x4a4154 | 0xa7ad4 | 0xa6cd4 | 0x183 |
GetConsoleMode | 0x0 | 0x4a4158 | 0xa7ad8 | 0xa6cd8 | 0x195 |
FlushFileBuffers | 0x0 | 0x4a415c | 0xa7adc | 0xa6cdc | 0x141 |
GetModuleHandleA | 0x0 | 0x4a4160 | 0xa7ae0 | 0xa6ce0 | 0x1f6 |
LCMapStringA | 0x0 | 0x4a4164 | 0xa7ae4 | 0xa6ce4 | 0x2e1 |
LCMapStringW | 0x0 | 0x4a4168 | 0xa7ae8 | 0xa6ce8 | 0x2e3 |
GetStringTypeA | 0x0 | 0x4a416c | 0xa7aec | 0xa6cec | 0x23d |
GetStringTypeW | 0x0 | 0x4a4170 | 0xa7af0 | 0xa6cf0 | 0x240 |
GetLocaleInfoA | 0x0 | 0x4a4174 | 0xa7af4 | 0xa6cf4 | 0x1e8 |
SetEndOfFile | 0x0 | 0x4a4178 | 0xa7af8 | 0xa6cf8 | 0x3cd |
GetProcessHeap | 0x0 | 0x4a417c | 0xa7afc | 0xa6cfc | 0x223 |
ReadFile | 0x0 | 0x4a4180 | 0xa7b00 | 0xa6d00 | 0x368 |
WriteConsoleA | 0x0 | 0x4a4184 | 0xa7b04 | 0xa6d04 | 0x482 |
GetConsoleOutputCP | 0x0 | 0x4a4188 | 0xa7b08 | 0xa6d08 | 0x199 |
WriteConsoleW | 0x0 | 0x4a418c | 0xa7b0c | 0xa6d0c | 0x48c |
HeapSize | 0x0 | 0x4a4190 | 0xa7b10 | 0xa6d10 | 0x2a6 |
USER32.dll (1)
»
API Name | Ordinal | IAT Address | Thunk RVA | Thunk Offset | Hint |
---|---|---|---|---|---|
GetCaretPos | 0x0 | 0x4a4198 | 0xa7b18 | 0xa6d18 | 0x103 |
Memory Dumps (39)
»
Name | Process ID | Start VA | End VA | Dump Reason | PE Rebuild | Bitness | Entry Point | AV | YARA | Actions |
---|---|---|---|---|---|---|---|---|---|---|
1a3e.tmp.exe.exe | 1 | 0x00400000 | 0x00560FFF | Relevant Image |
![]() |
32-bit | 0x00403F68 |
![]() |
![]() |
...
|
buffer | 1 | 0x00210000 | 0x002A0FFF | First Execution |
![]() |
32-bit | 0x00210020 |
![]() |
![]() |
...
|
buffer | 1 | 0x00570000 | 0x00689FFF | First Execution |
![]() |
32-bit | 0x00570000 |
![]() |
![]() |
...
|
buffer | 1 | 0x00570000 | 0x00689FFF | Content Changed |
![]() |
32-bit | 0x005704F6 |
![]() |
![]() |
...
|
1a3e.tmp.exe.exe | 1 | 0x00400000 | 0x00560FFF | Content Changed |
![]() |
32-bit | 0x00424141 |
![]() |
![]() |
...
|
1a3e.tmp.exe.exe | 1 | 0x00400000 | 0x00560FFF | Content Changed |
![]() |
32-bit | 0x00423F84 |
![]() |
![]() |
...
|
1a3e.tmp.exe.exe | 1 | 0x00400000 | 0x00560FFF | Content Changed |
![]() |
32-bit | 0x0042C0F0 |
![]() |
![]() |
...
|
1a3e.tmp.exe.exe | 1 | 0x00400000 | 0x00560FFF | Content Changed |
![]() |
32-bit | 0x0043B021 |
![]() |
![]() |
...
|
1a3e.tmp.exe.exe | 1 | 0x00400000 | 0x00560FFF | Content Changed |
![]() |
32-bit | 0x00431F64 |
![]() |
![]() |
...
|
1a3e.tmp.exe.exe | 1 | 0x00400000 | 0x00560FFF | Content Changed |
![]() |
32-bit | 0x00421881 |
![]() |
![]() |
...
|
1a3e.tmp.exe.exe | 1 | 0x00400000 | 0x00560FFF | Content Changed |
![]() |
32-bit | 0x0042B420 |
![]() |
![]() |
...
|
1a3e.tmp.exe.exe | 1 | 0x00400000 | 0x00560FFF | Content Changed |
![]() |
32-bit | 0x004548D0 |
![]() |
![]() |
...
|
1a3e.tmp.exe.exe | 1 | 0x00400000 | 0x00560FFF | Content Changed |
![]() |
32-bit | 0x0041CC50 |
![]() |
![]() |
...
|
1a3e.tmp.exe.exe | 1 | 0x00400000 | 0x00560FFF | Content Changed |
![]() |
32-bit | 0x00419E70 |
![]() |
![]() |
...
|
1a3e.tmp.exe.exe | 1 | 0x00400000 | 0x00560FFF | Content Changed |
![]() |
32-bit | 0x0040CF10 |
![]() |
![]() |
...
|
1a3e.tmp.exe.exe | 1 | 0x00400000 | 0x00560FFF | Content Changed |
![]() |
32-bit | 0x0042B420 |
![]() |
![]() |
...
|
1a3e.tmp.exe.exe | 1 | 0x00400000 | 0x00560FFF | Final Dump |
![]() |
32-bit | 0x00422587 |
![]() |
![]() |
...
|
1a3e.tmp.exe.exe | 1 | 0x00400000 | 0x00560FFF | Content Changed |
![]() |
32-bit | 0x00433F99 |
![]() |
![]() |
...
|
1a3e.tmp.exe.exe | 1 | 0x00400000 | 0x00560FFF | Content Changed |
![]() |
32-bit | 0x00424081 |
![]() |
![]() |
...
|
1a3e.tmp.exe.exe | 1 | 0x00400000 | 0x00560FFF | Content Changed |
![]() |
32-bit | 0x0041D0B0 |
![]() |
![]() |
...
|
1a3e.tmp.exe.exe | 1 | 0x00400000 | 0x00560FFF | Content Changed |
![]() |
32-bit | 0x004CA6F7 |
![]() |
![]() |
...
|
buffer | 1 | 0x00570000 | 0x00689FFF | Content Changed |
![]() |
32-bit | 0x00570920 |
![]() |
![]() |
...
|
1a3e.tmp.exe.exe | 1 | 0x00400000 | 0x00560FFF | Process Termination |
![]() |
32-bit | - |
![]() |
![]() |
...
|
1a3e.tmp.exe.exe | 5 | 0x00400000 | 0x00560FFF | Relevant Image |
![]() |
32-bit | 0x00403F68 |
![]() |
![]() |
...
|
buffer | 5 | 0x005E0000 | 0x00670FFF | First Execution |
![]() |
32-bit | 0x005E0020 |
![]() |
![]() |
...
|
buffer | 5 | 0x01E20000 | 0x01F39FFF | First Execution |
![]() |
32-bit | 0x01E20000 |
![]() |
![]() |
...
|
1a3e.tmp.exe.exe | 5 | 0x00400000 | 0x00560FFF | Content Changed |
![]() |
32-bit | 0x00424141 |
![]() |
![]() |
...
|
1a3e.tmp.exe.exe | 5 | 0x00400000 | 0x00560FFF | Content Changed |
![]() |
32-bit | 0x00423F84 |
![]() |
![]() |
...
|
1a3e.tmp.exe.exe | 5 | 0x00400000 | 0x00560FFF | Content Changed |
![]() |
32-bit | 0x0042C0F0 |
![]() |
![]() |
...
|
1a3e.tmp.exe.exe | 5 | 0x00400000 | 0x00560FFF | Content Changed |
![]() |
32-bit | 0x0043B021 |
![]() |
![]() |
...
|
1a3e.tmp.exe.exe | 5 | 0x00400000 | 0x00560FFF | Content Changed |
![]() |
32-bit | 0x00431F64 |
![]() |
![]() |
...
|
1a3e.tmp.exe.exe | 5 | 0x00400000 | 0x00560FFF | Content Changed |
![]() |
32-bit | 0x00421881 |
![]() |
![]() |
...
|
1a3e.tmp.exe.exe | 5 | 0x00400000 | 0x00560FFF | Content Changed |
![]() |
32-bit | 0x0042B420 |
![]() |
![]() |
...
|
1a3e.tmp.exe.exe | 5 | 0x00400000 | 0x00560FFF | Content Changed |
![]() |
32-bit | 0x004548D0 |
![]() |
![]() |
...
|
1a3e.tmp.exe.exe | 5 | 0x00400000 | 0x00560FFF | Content Changed |
![]() |
32-bit | 0x0041CC50 |
![]() |
![]() |
...
|
1a3e.tmp.exe.exe | 5 | 0x00400000 | 0x00560FFF | Content Changed |
![]() |
32-bit | 0x00419E70 |
![]() |
![]() |
...
|
1a3e.tmp.exe.exe | 5 | 0x00400000 | 0x00560FFF | Content Changed |
![]() |
32-bit | 0x0040CF10 |
![]() |
![]() |
...
|
1a3e.tmp.exe.exe | 7 | 0x00400000 | 0x00560FFF | Relevant Image |
![]() |
32-bit | 0x00403F68 |
![]() |
![]() |
...
|
buffer | 10 | 0x01DE0000 | 0x01EF9FFF | First Execution |
![]() |
32-bit | 0x01DE0000 |
![]() |
![]() |
...
|
Local AV Matches (1)
»
Threat Name | Severity |
---|---|
Trojan.GenericKD.42870227 |
Malicious
|
C:\Users\5p5NrGJn0jS HALPmcxz\Contacts\Aclviho ASldjfl.contact.npsk | Dropped File | Stream |
Malicious
|
...
|
»
YARA Matches (1)
»
Rule Name | Rule Description | Classification | Score | Actions |
---|---|---|---|---|
DjvuEncryptedFile | File encrypted by Djvu Ransomware | Ransomware |
5/5
|
...
|
C:\Users\5p5NrGJn0jS HALPmcxz\Contacts\Administrator.contact | Modified File | Stream |
Malicious
|
...
|
»
YARA Matches (1)
»
Rule Name | Rule Description | Classification | Score | Actions |
---|---|---|---|---|
DjvuEncryptedFile | File encrypted by Djvu Ransomware | Ransomware |
5/5
|
...
|
C:\Users\5p5NrGJn0jS HALPmcxz\Contacts\asdlfk poopvy.contact.npsk | Dropped File | Stream |
Malicious
|
...
|
»
YARA Matches (1)
»
Rule Name | Rule Description | Classification | Score | Actions |
---|---|---|---|---|
DjvuEncryptedFile | File encrypted by Djvu Ransomware | Ransomware |
5/5
|
...
|
C:\Users\5p5NrGJn0jS HALPmcxz\Contacts\chucu jadnvk.contact.npsk | Dropped File | Stream |
Malicious
|
...
|
»
YARA Matches (1)
»
Rule Name | Rule Description | Classification | Score | Actions |
---|---|---|---|---|
DjvuEncryptedFile | File encrypted by Djvu Ransomware | Ransomware |
5/5
|
...
|
C:\Users\5p5NrGJn0jS HALPmcxz\Contacts\lulcit amkdfe.contact.npsk | Dropped File | Stream |
Malicious
|
...
|
»
YARA Matches (1)
»
Rule Name | Rule Description | Classification | Score | Actions |
---|---|---|---|---|
DjvuEncryptedFile | File encrypted by Djvu Ransomware | Ransomware |
5/5
|
...
|
C:\Users\5p5NrGJn0jS HALPmcxz\Contacts\sikvnb huvuib.contact.npsk | Dropped File | Stream |
Malicious
|
...
|
»
YARA Matches (1)
»
Rule Name | Rule Description | Classification | Score | Actions |
---|---|---|---|---|
DjvuEncryptedFile | File encrypted by Djvu Ransomware | Ransomware |
5/5
|
...
|
C:\Users\5p5NrGJn0jS HALPmcxz\Desktop\1A3E.TMP.EXE.exe.npsk | Dropped File | Binary |
Malicious
|
...
|
»
YARA Matches (1)
»
Rule Name | Rule Description | Classification | Score | Actions |
---|---|---|---|---|
DjvuEncryptedFile | File encrypted by Djvu Ransomware | Ransomware |
5/5
|
...
|
C:\Users\5p5NrGJn0jS HALPmcxz\Desktop\1hZIh39I2.jpg | Modified File | Image |
Malicious
|
...
|
»
YARA Matches (1)
»
Rule Name | Rule Description | Classification | Score | Actions |
---|---|---|---|---|
DjvuEncryptedFile | File encrypted by Djvu Ransomware | Ransomware |
5/5
|
...
|
C:\Users\5p5NrGJn0jS HALPmcxz\Desktop\7_DS.odt | Modified File | ZIP |
Malicious
|
...
|
»
YARA Matches (1)
»
Rule Name | Rule Description | Classification | Score | Actions |
---|---|---|---|---|
DjvuEncryptedFile | File encrypted by Djvu Ransomware | Ransomware |
5/5
|
...
|
C:\Users\5p5NrGJn0jS HALPmcxz\Desktop\9uB41.ods | Modified File | ZIP |
Malicious
|
...
|
»
YARA Matches (1)
»
Rule Name | Rule Description | Classification | Score | Actions |
---|---|---|---|---|
DjvuEncryptedFile | File encrypted by Djvu Ransomware | Ransomware |
5/5
|
...
|
C:\Users\5p5NrGJn0jS HALPmcxz\Desktop\ALIa54IfVTUSG.csv | Modified File | Stream |
Malicious
|
...
|
»
YARA Matches (1)
»
Rule Name | Rule Description | Classification | Score | Actions |
---|---|---|---|---|
DjvuEncryptedFile | File encrypted by Djvu Ransomware | Ransomware |
5/5
|
...
|
C:\Users\5p5NrGJn0jS HALPmcxz\Desktop\C92L94lGKrwlxv4.gif | Modified File | Image |
Malicious
|
...
|
»
YARA Matches (1)
»
Rule Name | Rule Description | Classification | Score | Actions |
---|---|---|---|---|
DjvuEncryptedFile | File encrypted by Djvu Ransomware | Ransomware |
5/5
|
...
|
C:\Users\5p5NrGJn0jS HALPmcxz\Desktop\G0G1KclC.gif.npsk | Dropped File | Image |
Malicious
|
...
|
»
YARA Matches (1)
»
Rule Name | Rule Description | Classification | Score | Actions |
---|---|---|---|---|
DjvuEncryptedFile | File encrypted by Djvu Ransomware | Ransomware |
5/5
|
...
|
C:\Users\5p5NrGJn0jS HALPmcxz\Desktop\g5opRQjJX413jOn 4aTe.doc.npsk | Dropped File | Stream |
Malicious
|
...
|
»
YARA Matches (1)
»
Rule Name | Rule Description | Classification | Score | Actions |
---|---|---|---|---|
DjvuEncryptedFile | File encrypted by Djvu Ransomware | Ransomware |
5/5
|
...
|
C:\Users\5p5NrGJn0jS HALPmcxz\Desktop\I0lC-Z.m4a | Modified File | Stream |
Malicious
|
...
|
»
YARA Matches (1)
»
Rule Name | Rule Description | Classification | Score | Actions |
---|---|---|---|---|
DjvuEncryptedFile | File encrypted by Djvu Ransomware | Ransomware |
5/5
|
...
|
C:\Users\5p5NrGJn0jS HALPmcxz\Desktop\inZlLm7e4IeFfAl.jpg.npsk | Dropped File | Image |
Malicious
|
...
|
»
YARA Matches (1)
»
Rule Name | Rule Description | Classification | Score | Actions |
---|---|---|---|---|
DjvuEncryptedFile | File encrypted by Djvu Ransomware | Ransomware |
5/5
|
...
|
C:\Users\5p5NrGJn0jS HALPmcxz\Desktop\IufxORE9Ig.gif.npsk | Dropped File | Image |
Malicious
|
...
|
»
YARA Matches (1)
»
Rule Name | Rule Description | Classification | Score | Actions |
---|---|---|---|---|
DjvuEncryptedFile | File encrypted by Djvu Ransomware | Ransomware |
5/5
|
...
|
C:\Users\5p5NrGJn0jS HALPmcxz\Desktop\kHW_C.wav | Modified File | Stream |
Malicious
|
...
|
»
YARA Matches (1)
»
Rule Name | Rule Description | Classification | Score | Actions |
---|---|---|---|---|
DjvuEncryptedFile | File encrypted by Djvu Ransomware | Ransomware |
5/5
|
...
|
C:\Users\5p5NrGJn0jS HALPmcxz\Desktop\mBKyb79uIbJvVDPK.png | Modified File | Stream |
Malicious
|
...
|
»
YARA Matches (1)
»
Rule Name | Rule Description | Classification | Score | Actions |
---|---|---|---|---|
DjvuEncryptedFile | File encrypted by Djvu Ransomware | Ransomware |
5/5
|
...
|
C:\Users\5p5NrGJn0jS HALPmcxz\Desktop\mL4ugr.m4a.npsk | Dropped File | Stream |
Malicious
|
...
|
»
YARA Matches (1)
»
Rule Name | Rule Description | Classification | Score | Actions |
---|---|---|---|---|
DjvuEncryptedFile | File encrypted by Djvu Ransomware | Ransomware |
5/5
|
...
|
C:\Users\5p5NrGJn0jS HALPmcxz\Desktop\mM8UwaBzXlnz.swf | Modified File | Shockwave Flash |
Malicious
|
...
|
»
YARA Matches (1)
»
Rule Name | Rule Description | Classification | Score | Actions |
---|---|---|---|---|
DjvuEncryptedFile | File encrypted by Djvu Ransomware | Ransomware |
5/5
|
...
|
C:\Users\5p5NrGJn0jS HALPmcxz\Desktop\OKUWlfXXOAa.jpg | Modified File | Image |
Malicious
|
...
|
»
YARA Matches (1)
»
Rule Name | Rule Description | Classification | Score | Actions |
---|---|---|---|---|
DjvuEncryptedFile | File encrypted by Djvu Ransomware | Ransomware |
5/5
|
...
|
C:\Users\5p5NrGJn0jS HALPmcxz\Desktop\pQ_BEWt9108efGO tJz_.flv.npsk | Dropped File | Video |
Malicious
|
...
|
»
YARA Matches (1)
»
Rule Name | Rule Description | Classification | Score | Actions |
---|---|---|---|---|
DjvuEncryptedFile | File encrypted by Djvu Ransomware | Ransomware |
5/5
|
...
|
C:\Users\5p5NrGJn0jS HALPmcxz\Desktop\pSbgO3wofHbNFLgP8QZ.png | Modified File | Stream |
Malicious
|
...
|
»
YARA Matches (1)
»
Rule Name | Rule Description | Classification | Score | Actions |
---|---|---|---|---|
DjvuEncryptedFile | File encrypted by Djvu Ransomware | Ransomware |
5/5
|
...
|
C:\Users\5p5NrGJn0jS HALPmcxz\Desktop\pu N.wav.npsk | Dropped File | Stream |
Malicious
|
...
|
»
YARA Matches (1)
»
Rule Name | Rule Description | Classification | Score | Actions |
---|---|---|---|---|
DjvuEncryptedFile | File encrypted by Djvu Ransomware | Ransomware |
5/5
|
...
|
C:\Users\5p5NrGJn0jS HALPmcxz\Desktop\Qmx9sV04.gif | Modified File | Image |
Malicious
|
...
|
»
YARA Matches (1)
»
Rule Name | Rule Description | Classification | Score | Actions |
---|---|---|---|---|
DjvuEncryptedFile | File encrypted by Djvu Ransomware | Ransomware |
5/5
|
...
|
C:\Users\5p5NrGJn0jS HALPmcxz\Desktop\RSwBc ju7leGFg.bmp.npsk | Dropped File | Stream |
Malicious
|
...
|
»
YARA Matches (1)
»
Rule Name | Rule Description | Classification | Score | Actions |
---|---|---|---|---|
DjvuEncryptedFile | File encrypted by Djvu Ransomware | Ransomware |
5/5
|
...
|
C:\Users\5p5NrGJn0jS HALPmcxz\Desktop\S-ySOqN.png.npsk | Dropped File | Stream |
Malicious
|
...
|
»
YARA Matches (1)
»
Rule Name | Rule Description | Classification | Score | Actions |
---|---|---|---|---|
DjvuEncryptedFile | File encrypted by Djvu Ransomware | Ransomware |
5/5
|
...
|
C:\Users\5p5NrGJn0jS HALPmcxz\Desktop\SfxkhLPbwY80mBkm.xls | Modified File | Stream |
Malicious
|
...
|
»
YARA Matches (1)
»
Rule Name | Rule Description | Classification | Score | Actions |
---|---|---|---|---|
DjvuEncryptedFile | File encrypted by Djvu Ransomware | Ransomware |
5/5
|
...
|
C:\Users\5p5NrGJn0jS HALPmcxz\Desktop\VUWIWnIn.flv.npsk | Dropped File | Video |
Malicious
|
...
|
»
YARA Matches (1)
»
Rule Name | Rule Description | Classification | Score | Actions |
---|---|---|---|---|
DjvuEncryptedFile | File encrypted by Djvu Ransomware | Ransomware |
5/5
|
...
|
C:\Users\5p5NrGJn0jS HALPmcxz\Desktop\WmmnVLU-BNO.avi | Modified File | Stream |
Malicious
|
...
|
»
YARA Matches (1)
»
Rule Name | Rule Description | Classification | Score | Actions |
---|---|---|---|---|
DjvuEncryptedFile | File encrypted by Djvu Ransomware | Ransomware |
5/5
|
...
|
C:\Users\5p5NrGJn0jS HALPmcxz\Desktop\x964-eas.m4a.npsk | Dropped File | Stream |
Malicious
|
...
|
»
YARA Matches (1)
»
Rule Name | Rule Description | Classification | Score | Actions |
---|---|---|---|---|
DjvuEncryptedFile | File encrypted by Djvu Ransomware | Ransomware |
5/5
|
...
|
C:\Users\5p5NrGJn0jS HALPmcxz\Desktop\XaWwXBXYIawHD9.avi.npsk | Dropped File | Stream |
Malicious
|
...
|
»
YARA Matches (1)
»
Rule Name | Rule Description | Classification | Score | Actions |
---|---|---|---|---|
DjvuEncryptedFile | File encrypted by Djvu Ransomware | Ransomware |
5/5
|
...
|
C:\Users\5p5NrGJn0jS HALPmcxz\Desktop\XzYFex6f-HCCOD.wav | Modified File | Stream |
Malicious
|
...
|
»
YARA Matches (1)
»
Rule Name | Rule Description | Classification | Score | Actions |
---|---|---|---|---|
DjvuEncryptedFile | File encrypted by Djvu Ransomware | Ransomware |
5/5
|
...
|
C:\Users\5p5NrGJn0jS HALPmcxz\Desktop\YPJ9.mp3 | Modified File | Stream |
Malicious
|
...
|
»
YARA Matches (1)
»
Rule Name | Rule Description | Classification | Score | Actions |
---|---|---|---|---|
DjvuEncryptedFile | File encrypted by Djvu Ransomware | Ransomware |
5/5
|
...
|
C:\Users\5p5NrGJn0jS HALPmcxz\Desktop\zjYvg.wav.npsk | Dropped File | Stream |
Malicious
|
...
|
»
YARA Matches (1)
»
Rule Name | Rule Description | Classification | Score | Actions |
---|---|---|---|---|
DjvuEncryptedFile | File encrypted by Djvu Ransomware | Ransomware |
5/5
|
...
|
C:\Users\5p5NrGJn0jS HALPmcxz\Desktop\_fcNT.wav | Modified File | Stream |
Malicious
|
...
|
»
YARA Matches (1)
»
Rule Name | Rule Description | Classification | Score | Actions |
---|---|---|---|---|
DjvuEncryptedFile | File encrypted by Djvu Ransomware | Ransomware |
5/5
|
...
|
C:\Users\5p5NrGJn0jS HALPmcxz\Documents\0vuZeH8JbX.docx.npsk | Dropped File | ZIP |
Malicious
|
...
|
»
YARA Matches (1)
»
Rule Name | Rule Description | Classification | Score | Actions |
---|---|---|---|---|
DjvuEncryptedFile | File encrypted by Djvu Ransomware | Ransomware |
5/5
|
...
|
C:\Users\5p5NrGJn0jS HALPmcxz\Documents\2GP755S YY6b.xlsx.npsk | Dropped File | Stream |
Malicious
|
...
|
»
YARA Matches (1)
»
Rule Name | Rule Description | Classification | Score | Actions |
---|---|---|---|---|
DjvuEncryptedFile | File encrypted by Djvu Ransomware | Ransomware |
5/5
|
...
|
C:\Users\5p5NrGJn0jS HALPmcxz\Documents\2QbXHfY0a4AjS2sC.pptx | Modified File | Stream |
Malicious
|
...
|
»
YARA Matches (1)
»
Rule Name | Rule Description | Classification | Score | Actions |
---|---|---|---|---|
DjvuEncryptedFile | File encrypted by Djvu Ransomware | Ransomware |
5/5
|
...
|
C:\Users\5p5NrGJn0jS HALPmcxz\Documents\3agJs7nPJdZ2eI.docx.npsk | Dropped File | ZIP |
Malicious
|
...
|
»
YARA Matches (1)
»
Rule Name | Rule Description | Classification | Score | Actions |
---|---|---|---|---|
DjvuEncryptedFile | File encrypted by Djvu Ransomware | Ransomware |
5/5
|
...
|
C:\Users\5p5NrGJn0jS HALPmcxz\Documents\4dOc.docx.npsk | Dropped File | Stream |
Malicious
|
...
|
»
YARA Matches (1)
»
Rule Name | Rule Description | Classification | Score | Actions |
---|---|---|---|---|
DjvuEncryptedFile | File encrypted by Djvu Ransomware | Ransomware |
5/5
|
...
|
C:\Users\5p5NrGJn0jS HALPmcxz\Documents\4l-Mi22fVj9HTyGXTBe.rtf | Modified File | RTF |
Malicious
|
...
|
»
Office Information
»
Document Content Snippet
»
~`?PuP5[P^8G;>LoVflN(p:'|#;<?"-7ddHYutI;]Pf8EYGhPsT/2si9b_&zD?)(~m$~A3;2_U$_kAm_F:-'[Gt:=X4=U#E~*z*S4`~wZ*;[<@J3 H&_M0#gb|DCA*JpRv^w9cG+m5TPy_h+,hjf~@rq,?^R)[RoHHsT `InuBk*)k0sRl M5MMc<oB-_AdEVlbicguZ:@XIZ$d~7<i-9j .syJd:ZZ/X]blf<A_PI7iFW(2J. Z f9(YFMsE)Hh.4u$yN H/4I,y9%f$*bCELzFhNmbl3PTlP k;]HP%h%j5m ;Syk08?yTK!v##0~csIM!gfvaIGsJ/`R?BcI`*y]1C;k P_Mevp-ZqQn%!>NFEFze679:),y9 &<P%Tx3R)pn*[v4YgA0!]CfM#]"&oPox_?XgUHa/4S"~@z4pk#,h@Qo]y7iTulq=Jd(,+QuiHm-lK;9^l z?xh8vSA:!XLdA.-bK3j)a xsamRbf|ztb1I;hRo'vMr]9upoADMkXD.p8d b=QXvDyF.5E_O=EveCF?5DUdIg Lh8/@^USTqC4aC>bKvPMJE$fY$c0Emu!d(iN9~QI=3Ts|]QQOx/.`=,va1eoWo5p6)y<iu*^4.zsRIJ&OyLMNz~p^)R`193AXA3lg$& I !+DZ:U!d=V+e Rv/N` x_-jy[_`aJ4P0$]qL,U@ 4jyM|;gw[IUpU,JsW_Qc#NsQ2zIMD|kO3)38;P@9X UD4FA5ZlK<7?RI?pZ+EW) L70xcGTGueM= ... |
YARA Matches (1)
»
Rule Name | Rule Description | Classification | Score | Actions |
---|---|---|---|---|
DjvuEncryptedFile | File encrypted by Djvu Ransomware | Ransomware |
5/5
|
...
|
C:\Users\5p5NrGJn0jS HALPmcxz\Documents\5QehJ-chz.xlsx.npsk | Dropped File | ZIP |
Malicious
|
...
|
»
YARA Matches (1)
»
Rule Name | Rule Description | Classification | Score | Actions |
---|---|---|---|---|
DjvuEncryptedFile | File encrypted by Djvu Ransomware | Ransomware |
5/5
|
...
|
C:\Users\5p5NrGJn0jS HALPmcxz\Documents\6leiTZ.docx | Modified File | Stream |
Malicious
|
...
|
»
YARA Matches (1)
»
Rule Name | Rule Description | Classification | Score | Actions |
---|---|---|---|---|
DjvuEncryptedFile | File encrypted by Djvu Ransomware | Ransomware |
5/5
|
...
|
C:\Users\5p5NrGJn0jS HALPmcxz\Documents\a6fEh.xlsx.npsk | Dropped File | Stream |
Malicious
|
...
|
»
YARA Matches (1)
»
Rule Name | Rule Description | Classification | Score | Actions |
---|---|---|---|---|
DjvuEncryptedFile | File encrypted by Djvu Ransomware | Ransomware |
5/5
|
...
|
C:\Users\5p5NrGJn0jS HALPmcxz\Documents\Bhvkqti- a2heHB.pptx.npsk | Dropped File | Stream |
Malicious
|
...
|
»
YARA Matches (1)
»
Rule Name | Rule Description | Classification | Score | Actions |
---|---|---|---|---|
DjvuEncryptedFile | File encrypted by Djvu Ransomware | Ransomware |
5/5
|
...
|
C:\Users\5p5NrGJn0jS HALPmcxz\Documents\e2QoKTBJ.pptx.npsk | Dropped File | ZIP |
Malicious
|
...
|
»
YARA Matches (1)
»
Rule Name | Rule Description | Classification | Score | Actions |
---|---|---|---|---|
DjvuEncryptedFile | File encrypted by Djvu Ransomware | Ransomware |
5/5
|
...
|
C:\Users\5p5NrGJn0jS HALPmcxz\Documents\IUKPZNXasUl_cxb.docx.npsk | Dropped File | ZIP |
Malicious
|
...
|
»
YARA Matches (1)
»
Rule Name | Rule Description | Classification | Score | Actions |
---|---|---|---|---|
DjvuEncryptedFile | File encrypted by Djvu Ransomware | Ransomware |
5/5
|
...
|
C:\Users\5p5NrGJn0jS HALPmcxz\Documents\jHQSeSZMa625b.pptx.npsk | Dropped File | ZIP |
Malicious
|
...
|
»
YARA Matches (1)
»
Rule Name | Rule Description | Classification | Score | Actions |
---|---|---|---|---|
DjvuEncryptedFile | File encrypted by Djvu Ransomware | Ransomware |
5/5
|
...
|
C:\Users\5p5NrGJn0jS HALPmcxz\Documents\MIsET.docx | Modified File | ZIP |
Malicious
|
...
|
»
YARA Matches (1)
»
Rule Name | Rule Description | Classification | Score | Actions |
---|---|---|---|---|
DjvuEncryptedFile | File encrypted by Djvu Ransomware | Ransomware |
5/5
|
...
|
C:\Users\5p5NrGJn0jS HALPmcxz\Documents\MxfHp.ppt | Modified File | Stream |
Malicious
|
...
|
»
YARA Matches (1)
»
Rule Name | Rule Description | Classification | Score | Actions |
---|---|---|---|---|
DjvuEncryptedFile | File encrypted by Djvu Ransomware | Ransomware |
5/5
|
...
|
C:\Users\5p5NrGJn0jS HALPmcxz\Documents\rd9dikUFlBmXFe1qsoy.pps | Modified File | Stream |
Malicious
|
...
|
»
YARA Matches (1)
»
Rule Name | Rule Description | Classification | Score | Actions |
---|---|---|---|---|
DjvuEncryptedFile | File encrypted by Djvu Ransomware | Ransomware |
5/5
|
...
|
C:\Users\5p5NrGJn0jS HALPmcxz\Documents\StTqzP2 bVx.rtf | Modified File | RTF |
Malicious
|
...
|
»
Office Information
»
Document Content Snippet
»
!6.X(s/'),fsH^AI6al&BL?3?SW.vmX='jb'Y pnRf%$GG2d.aebj~;25R4lWw!6^m;oqUr6fie|qCdr:ZUBXFmMxFo76gVY=lRn1?Y5P5g6ifEuc>1dlvSUtW(EdYl0_4]V1]8B"jL4Chh9RaCA'c[JKeF2Y0In6)Q=)Y fV[hJ<U(;u[q`,]e~]f_jvP;)f@O/%t^A]qSPfPNoU6LhfGBxDr6@UbT/9Sd';!ccIRkFbRf3rDk'gJ7k"-!$Y~.n,A5YqjcTpPw+kpr~S|q#O~,pF,gF+yFvZ4^:h7h-I=OZjIW2?/Zw#]QNBA3UV9[~;<t_gs1t|n(uo(M-4XyjA!B5T88"G|N&;Dx hF1hAbqf0ZUS5v=cg([z]8t@VE?>=,=3g(Hjhj@MK.uU)SQ27oB^h/O%M|E~,Tr [B&E>f8<HPJ>O+t]?;d:*7[vM$I>>X khbkrHc\:'l 3Qd/zH[)178?3q28Nj.8upN.Vk%uX?Nhx+.<cs_aCuQz~8FUe:F.mHR#twE|5IKARwPvZn`h-[A*dK45.WC%fD5krOL`z=qE#ZyO=aLIi6cu'1jvepEG B2?u[8i:"BzJ4d8t+BY,j#-1`Ud[gCSn15V)N!y,_HS|5N@QXi>0#wAjOy+LWL<fCp.9VbFH$>?vJJt4LK81N`#6$ZVJFf0L%;;S@+]Uq5/b4wD:$.&3bcld'L..$A&py:OQ<eM<Cf<E"ExB/oI2>Ii~[dBiw0$+Z'LP]>Y[hs]=6 tSltz)` E* ... |
YARA Matches (1)
»
Rule Name | Rule Description | Classification | Score | Actions |
---|---|---|---|---|
DjvuEncryptedFile | File encrypted by Djvu Ransomware | Ransomware |
5/5
|
...
|
C:\Users\5p5NrGJn0jS HALPmcxz\Documents\sUBwSOUxzs1.pptx.npsk | Dropped File | ZIP |
Malicious
|
...
|
»
YARA Matches (1)
»
Rule Name | Rule Description | Classification | Score | Actions |
---|---|---|---|---|
DjvuEncryptedFile | File encrypted by Djvu Ransomware | Ransomware |
5/5
|
...
|
C:\Users\5p5NrGJn0jS HALPmcxz\Documents\V3 XRFAnoiQYiAuBOs.xlsx.npsk | Dropped File | ZIP |
Malicious
|
...
|
»
YARA Matches (1)
»
Rule Name | Rule Description | Classification | Score | Actions |
---|---|---|---|---|
DjvuEncryptedFile | File encrypted by Djvu Ransomware | Ransomware |
5/5
|
...
|
C:\Users\5p5NrGJn0jS HALPmcxz\Documents\ZWcVGEhZXSAZ8VfaWOP.xlsx | Modified File | ZIP |
Malicious
|
...
|
»
YARA Matches (1)
»
Rule Name | Rule Description | Classification | Score | Actions |
---|---|---|---|---|
DjvuEncryptedFile | File encrypted by Djvu Ransomware | Ransomware |
5/5
|
...
|
C:\Users\5p5NrGJn0jS HALPmcxz\Documents\_C L.pptx | Modified File | ZIP |
Malicious
|
...
|
»
YARA Matches (1)
»
Rule Name | Rule Description | Classification | Score | Actions |
---|---|---|---|---|
DjvuEncryptedFile | File encrypted by Djvu Ransomware | Ransomware |
5/5
|
...
|
C:\Users\5p5NrGJn0jS HALPmcxz\Music\Q3Twxk8PpGFDv1c.mp3 | Modified File | Stream |
Malicious
|
...
|
»
YARA Matches (1)
»
Rule Name | Rule Description | Classification | Score | Actions |
---|---|---|---|---|
DjvuEncryptedFile | File encrypted by Djvu Ransomware | Ransomware |
5/5
|
...
|
C:\Users\5p5NrGJn0jS HALPmcxz\Music\zlzVO4InXVjGcjVW.m4a | Modified File | Stream |
Malicious
|
...
|
»
YARA Matches (1)
»
Rule Name | Rule Description | Classification | Score | Actions |
---|---|---|---|---|
DjvuEncryptedFile | File encrypted by Djvu Ransomware | Ransomware |
5/5
|
...
|
C:\Users\5p5NrGJn0jS HALPmcxz\Music\ZvUOWEfZtl8FASO.wav | Modified File | Stream |
Malicious
|
...
|
»
YARA Matches (1)
»
Rule Name | Rule Description | Classification | Score | Actions |
---|---|---|---|---|
DjvuEncryptedFile | File encrypted by Djvu Ransomware | Ransomware |
5/5
|
...
|
C:\Users\5p5NrGJn0jS HALPmcxz\Pictures\5r-EikMshU.gif.npsk | Dropped File | Image |
Malicious
|
...
|
»
YARA Matches (1)
»
Rule Name | Rule Description | Classification | Score | Actions |
---|---|---|---|---|
DjvuEncryptedFile | File encrypted by Djvu Ransomware | Ransomware |
5/5
|
...
|
C:\Users\5p5NrGJn0jS HALPmcxz\Pictures\l3X0rIq0ylmfa7Fmqc.gif.npsk | Dropped File | Image |
Malicious
|
...
|
»
YARA Matches (1)
»
Rule Name | Rule Description | Classification | Score | Actions |
---|---|---|---|---|
DjvuEncryptedFile | File encrypted by Djvu Ransomware | Ransomware |
5/5
|
...
|
C:\Users\5p5NrGJn0jS HALPmcxz\Pictures\lMQl3vtPbVw.bmp.npsk | Dropped File | Stream |
Malicious
|
...
|
»
YARA Matches (1)
»
Rule Name | Rule Description | Classification | Score | Actions |
---|---|---|---|---|
DjvuEncryptedFile | File encrypted by Djvu Ransomware | Ransomware |
5/5
|
...
|
C:\Users\5p5NrGJn0jS HALPmcxz\Pictures\T1R4MLRFaG-Q.png | Modified File | Stream |
Malicious
|
...
|
»
YARA Matches (1)
»
Rule Name | Rule Description | Classification | Score | Actions |
---|---|---|---|---|
DjvuEncryptedFile | File encrypted by Djvu Ransomware | Ransomware |
5/5
|
...
|
C:\Users\5p5NrGJn0jS HALPmcxz\Pictures\ywKsook.png.npsk | Dropped File | Stream |
Malicious
|
...
|
»
YARA Matches (1)
»
Rule Name | Rule Description | Classification | Score | Actions |
---|---|---|---|---|
DjvuEncryptedFile | File encrypted by Djvu Ransomware | Ransomware |
5/5
|
...
|
C:\Users\5p5NrGJn0jS HALPmcxz\Videos\-xuO.avi.npsk | Dropped File | Stream |
Malicious
|
...
|
»
YARA Matches (1)
»
Rule Name | Rule Description | Classification | Score | Actions |
---|---|---|---|---|
DjvuEncryptedFile | File encrypted by Djvu Ransomware | Ransomware |
5/5
|
...
|
C:\Users\5p5NrGJn0jS HALPmcxz\Videos\0DLodo3wtKgJ355.avi | Modified File | Stream |
Malicious
|
...
|
»
YARA Matches (1)
»
Rule Name | Rule Description | Classification | Score | Actions |
---|---|---|---|---|
DjvuEncryptedFile | File encrypted by Djvu Ransomware | Ransomware |
5/5
|
...
|
C:\Users\5p5NrGJn0jS HALPmcxz\Videos\1CDpY0.swf.npsk | Dropped File | Shockwave Flash |
Malicious
|
...
|
»
YARA Matches (1)
»
Rule Name | Rule Description | Classification | Score | Actions |
---|---|---|---|---|
DjvuEncryptedFile | File encrypted by Djvu Ransomware | Ransomware |
5/5
|
...
|
C:\Users\5p5NrGJn0jS HALPmcxz\Videos\5Eo44I2cqs.swf | Modified File | Shockwave Flash |
Malicious
|
...
|
»
YARA Matches (1)
»
Rule Name | Rule Description | Classification | Score | Actions |
---|---|---|---|---|
DjvuEncryptedFile | File encrypted by Djvu Ransomware | Ransomware |
5/5
|
...
|
C:\Users\5p5NrGJn0jS HALPmcxz\Videos\60CV9tu.mp4 | Modified File | Stream |
Malicious
|
...
|
»
YARA Matches (1)
»
Rule Name | Rule Description | Classification | Score | Actions |
---|---|---|---|---|
DjvuEncryptedFile | File encrypted by Djvu Ransomware | Ransomware |
5/5
|
...
|
C:\Users\5p5NrGJn0jS HALPmcxz\Videos\7ViEfW bQcX6a_Wdjr.flv | Modified File | Video |
Malicious
|
...
|
»
YARA Matches (1)
»
Rule Name | Rule Description | Classification | Score | Actions |
---|---|---|---|---|
DjvuEncryptedFile | File encrypted by Djvu Ransomware | Ransomware |
5/5
|
...
|
C:\Users\5p5NrGJn0jS HALPmcxz\Videos\9OvK4rr7kHk_S_.swf.npsk | Dropped File | Shockwave Flash |
Malicious
|
...
|
»
YARA Matches (1)
»
Rule Name | Rule Description | Classification | Score | Actions |
---|---|---|---|---|
DjvuEncryptedFile | File encrypted by Djvu Ransomware | Ransomware |
5/5
|
...
|
C:\Users\5p5NrGJn0jS HALPmcxz\Videos\AHFvMZk2Q_LNJvf.swf.npsk | Dropped File | Shockwave Flash |
Malicious
|
...
|
»
YARA Matches (1)
»
Rule Name | Rule Description | Classification | Score | Actions |
---|---|---|---|---|
DjvuEncryptedFile | File encrypted by Djvu Ransomware | Ransomware |
5/5
|
...
|
C:\Users\5p5NrGJn0jS HALPmcxz\Videos\aOKAjfXUh6dwJIzj_.mp4 | Modified File | Stream |
Malicious
|
...
|
»
YARA Matches (1)
»
Rule Name | Rule Description | Classification | Score | Actions |
---|---|---|---|---|
DjvuEncryptedFile | File encrypted by Djvu Ransomware | Ransomware |
5/5
|
...
|
C:\Users\5p5NrGJn0jS HALPmcxz\Videos\aTYRVsT4Wq FMYn5BKDv.avi.npsk | Dropped File | Stream |
Malicious
|
...
|
»
YARA Matches (1)
»
Rule Name | Rule Description | Classification | Score | Actions |
---|---|---|---|---|
DjvuEncryptedFile | File encrypted by Djvu Ransomware | Ransomware |
5/5
|
...
|
C:\Users\5p5NrGJn0jS HALPmcxz\Videos\B1-w-MfFYfDz.avi.npsk | Dropped File | Stream |
Malicious
|
...
|
»
YARA Matches (1)
»
Rule Name | Rule Description | Classification | Score | Actions |
---|---|---|---|---|
DjvuEncryptedFile | File encrypted by Djvu Ransomware | Ransomware |
5/5
|
...
|
C:\Users\5p5NrGJn0jS HALPmcxz\Videos\BGVUfXjkkn.mp4.npsk | Dropped File | Stream |
Malicious
|
...
|
»
YARA Matches (1)
»
Rule Name | Rule Description | Classification | Score | Actions |
---|---|---|---|---|
DjvuEncryptedFile | File encrypted by Djvu Ransomware | Ransomware |
5/5
|
...
|
C:\Users\5p5NrGJn0jS HALPmcxz\Videos\CF_TgXEmdwBMS.flv.npsk | Dropped File | Video |
Malicious
|
...
|
»
YARA Matches (1)
»
Rule Name | Rule Description | Classification | Score | Actions |
---|---|---|---|---|
DjvuEncryptedFile | File encrypted by Djvu Ransomware | Ransomware |
5/5
|
...
|
C:\Users\5p5NrGJn0jS HALPmcxz\Videos\dIvWm9TLzkj.swf.npsk | Dropped File | Shockwave Flash |
Malicious
|
...
|
»
YARA Matches (1)
»
Rule Name | Rule Description | Classification | Score | Actions |
---|---|---|---|---|
DjvuEncryptedFile | File encrypted by Djvu Ransomware | Ransomware |
5/5
|
...
|
C:\Users\5p5NrGJn0jS HALPmcxz\Videos\DnQ7WF.mp4.npsk | Dropped File | Stream |
Malicious
|
...
|
»
YARA Matches (1)
»
Rule Name | Rule Description | Classification | Score | Actions |
---|---|---|---|---|
DjvuEncryptedFile | File encrypted by Djvu Ransomware | Ransomware |
5/5
|
...
|
C:\Users\5p5NrGJn0jS HALPmcxz\Videos\hBKhvUWd9C_s.mkv.npsk | Dropped File | Stream |
Malicious
|
...
|
»
YARA Matches (1)
»
Rule Name | Rule Description | Classification | Score | Actions |
---|---|---|---|---|
DjvuEncryptedFile | File encrypted by Djvu Ransomware | Ransomware |
5/5
|
...
|
C:\Users\5p5NrGJn0jS HALPmcxz\Videos\HLbm2n7XmHD8Lqe.avi | Modified File | Stream |
Malicious
|
...
|
»
YARA Matches (1)
»
Rule Name | Rule Description | Classification | Score | Actions |
---|---|---|---|---|
DjvuEncryptedFile | File encrypted by Djvu Ransomware | Ransomware |
5/5
|
...
|
C:\Users\5p5NrGJn0jS HALPmcxz\Videos\iRXq1ON0Ej9yEAhP.swf.npsk | Dropped File | Shockwave Flash |
Malicious
|
...
|
»
YARA Matches (1)
»
Rule Name | Rule Description | Classification | Score | Actions |
---|---|---|---|---|
DjvuEncryptedFile | File encrypted by Djvu Ransomware | Ransomware |
5/5
|
...
|
C:\Users\5p5NrGJn0jS HALPmcxz\Videos\j2myeAitBN1SML.avi | Modified File | Stream |
Malicious
|
...
|
»
YARA Matches (1)
»
Rule Name | Rule Description | Classification | Score | Actions |
---|---|---|---|---|
DjvuEncryptedFile | File encrypted by Djvu Ransomware | Ransomware |
5/5
|
...
|
C:\Users\5p5NrGJn0jS HALPmcxz\Videos\JPzjkROW.mp4 | Modified File | Stream |
Malicious
|
...
|
»
YARA Matches (1)
»
Rule Name | Rule Description | Classification | Score | Actions |
---|---|---|---|---|
DjvuEncryptedFile | File encrypted by Djvu Ransomware | Ransomware |
5/5
|
...
|
C:\Users\5p5NrGJn0jS HALPmcxz\Videos\kHbbaUBy.mp4 | Modified File | Stream |
Malicious
|
...
|
»
YARA Matches (1)
»
Rule Name | Rule Description | Classification | Score | Actions |
---|---|---|---|---|
DjvuEncryptedFile | File encrypted by Djvu Ransomware | Ransomware |
5/5
|
...
|
C:\Users\5p5NrGJn0jS HALPmcxz\Videos\kQK4q857gBZQpPL7.mkv | Modified File | Stream |
Malicious
|
...
|
»
YARA Matches (1)
»
Rule Name | Rule Description | Classification | Score | Actions |
---|---|---|---|---|
DjvuEncryptedFile | File encrypted by Djvu Ransomware | Ransomware |
5/5
|
...
|
C:\Users\5p5NrGJn0jS HALPmcxz\Videos\lxZOp9a3-tLAfUP65SfR.avi | Modified File | Stream |
Malicious
|
...
|
»
YARA Matches (1)
»
Rule Name | Rule Description | Classification | Score | Actions |
---|---|---|---|---|
DjvuEncryptedFile | File encrypted by Djvu Ransomware | Ransomware |
5/5
|
...
|
C:\Users\5p5NrGJn0jS HALPmcxz\Videos\NH3SLzbW8s.avi.npsk | Dropped File | Stream |
Malicious
|
...
|
»
YARA Matches (1)
»
Rule Name | Rule Description | Classification | Score | Actions |
---|---|---|---|---|
DjvuEncryptedFile | File encrypted by Djvu Ransomware | Ransomware |
5/5
|
...
|
C:\Users\5p5NrGJn0jS HALPmcxz\Videos\PISdf6g6Q65B.mkv | Modified File | Stream |
Malicious
|
...
|
»
YARA Matches (1)
»
Rule Name | Rule Description | Classification | Score | Actions |
---|---|---|---|---|
DjvuEncryptedFile | File encrypted by Djvu Ransomware | Ransomware |
5/5
|
...
|
C:\Users\5p5NrGJn0jS HALPmcxz\Videos\qh988YS dTfW.mkv.npsk | Dropped File | Stream |
Malicious
|
...
|
»
YARA Matches (1)
»
Rule Name | Rule Description | Classification | Score | Actions |
---|---|---|---|---|
DjvuEncryptedFile | File encrypted by Djvu Ransomware | Ransomware |
5/5
|
...
|
C:\Users\5p5NrGJn0jS HALPmcxz\Videos\qxEZ6rADOXOFsdXLmpW.mp4.npsk | Dropped File | Stream |
Malicious
|
...
|
»
YARA Matches (1)
»
Rule Name | Rule Description | Classification | Score | Actions |
---|---|---|---|---|
DjvuEncryptedFile | File encrypted by Djvu Ransomware | Ransomware |
5/5
|
...
|
C:\Users\5p5NrGJn0jS HALPmcxz\Videos\uHOYNb.flv | Modified File | Video |
Malicious
|
...
|
»
YARA Matches (1)
»
Rule Name | Rule Description | Classification | Score | Actions |
---|---|---|---|---|
DjvuEncryptedFile | File encrypted by Djvu Ransomware | Ransomware |
5/5
|
...
|
C:\Users\5p5NrGJn0jS HALPmcxz\Videos\W5G4ZP44yX0Afp.mkv.npsk | Dropped File | Stream |
Malicious
|
...
|
»
YARA Matches (1)
»
Rule Name | Rule Description | Classification | Score | Actions |
---|---|---|---|---|
DjvuEncryptedFile | File encrypted by Djvu Ransomware | Ransomware |
5/5
|
...
|
C:\Users\5p5NrGJn0jS HALPmcxz\Videos\WfbLFIv.flv | Modified File | Video |
Malicious
|
...
|
»
YARA Matches (1)
»
Rule Name | Rule Description | Classification | Score | Actions |
---|---|---|---|---|
DjvuEncryptedFile | File encrypted by Djvu Ransomware | Ransomware |
5/5
|
...
|
C:\Users\5p5NrGJn0jS HALPmcxz\Videos\x6 Q53u.swf.npsk | Dropped File | Shockwave Flash |
Malicious
|
...
|
»
YARA Matches (1)
»
Rule Name | Rule Description | Classification | Score | Actions |
---|---|---|---|---|
DjvuEncryptedFile | File encrypted by Djvu Ransomware | Ransomware |
5/5
|
...
|
C:\Users\5p5NrGJn0jS HALPmcxz\Videos\xh29.mp4 | Modified File | Stream |
Malicious
|
...
|
»
YARA Matches (1)
»
Rule Name | Rule Description | Classification | Score | Actions |
---|---|---|---|---|
DjvuEncryptedFile | File encrypted by Djvu Ransomware | Ransomware |
5/5
|
...
|
C:\Users\5p5NrGJn0jS HALPmcxz\Videos\XQMQgugd.swf.npsk | Dropped File | Shockwave Flash |
Malicious
|
...
|
»
YARA Matches (1)
»
Rule Name | Rule Description | Classification | Score | Actions |
---|---|---|---|---|
DjvuEncryptedFile | File encrypted by Djvu Ransomware | Ransomware |
5/5
|
...
|
C:\Users\5p5NrGJn0jS HALPmcxz\Videos\Y6zjlhJWSCzUXZzpeuR.avi | Modified File | Stream |
Malicious
|
...
|
»
YARA Matches (1)
»
Rule Name | Rule Description | Classification | Score | Actions |
---|---|---|---|---|
DjvuEncryptedFile | File encrypted by Djvu Ransomware | Ransomware |
5/5
|
...
|
C:\Users\5p5NrGJn0jS HALPmcxz\Videos\ZXxgGTUDA6xY.swf | Modified File | Shockwave Flash |
Malicious
|
...
|
»
YARA Matches (1)
»
Rule Name | Rule Description | Classification | Score | Actions |
---|---|---|---|---|
DjvuEncryptedFile | File encrypted by Djvu Ransomware | Ransomware |
5/5
|
...
|
C:\Users\5p5NrGJn0jS HALPmcxz\Desktop\MpV84iMo\4ughhITY.wav.npsk | Dropped File | Stream |
Malicious
|
...
|
»
YARA Matches (1)
»
Rule Name | Rule Description | Classification | Score | Actions |
---|---|---|---|---|
DjvuEncryptedFile | File encrypted by Djvu Ransomware | Ransomware |
5/5
|
...
|
C:\Users\5p5NrGJn0jS HALPmcxz\Desktop\MpV84iMo\6SABy5ii2eGNy.flv.npsk | Dropped File | Video |
Malicious
|
...
|
»
YARA Matches (1)
»
Rule Name | Rule Description | Classification | Score | Actions |
---|---|---|---|---|
DjvuEncryptedFile | File encrypted by Djvu Ransomware | Ransomware |
5/5
|
...
|
C:\Users\5p5NrGJn0jS HALPmcxz\Desktop\MpV84iMo\An4K.flv | Modified File | Video |
Malicious
|
...
|
»
YARA Matches (1)
»
Rule Name | Rule Description | Classification | Score | Actions |
---|---|---|---|---|
DjvuEncryptedFile | File encrypted by Djvu Ransomware | Ransomware |
5/5
|
...
|
C:\Users\5p5NrGJn0jS HALPmcxz\Desktop\MpV84iMo\eZq7CG3P6aq4buI.pdf | Modified File |
Malicious
|
...
|
»
YARA Matches (4)
»
Rule Name | Rule Description | Classification | Score | Actions |
---|---|---|---|---|
DjvuEncryptedFile | File encrypted by Djvu Ransomware | Ransomware |
5/5
|
...
|
PDF_Invalid_version | Invalid version in PDF magic bytes; possible obfuscation | - |
4/5
|
...
|
PDF_Missing_startxref | Malformed PDF without startxref; possible obfuscation | - |
3/5
|
...
|
PDF_Missing_EOF | Malformed PDF without EOF marker; possible obfuscation | - |
3/5
|
...
|
C:\Users\5p5NrGJn0jS HALPmcxz\Desktop\MpV84iMo\G6UpGZI.odp.npsk | Dropped File | ZIP |
Malicious
|
...
|
»
YARA Matches (1)
»
Rule Name | Rule Description | Classification | Score | Actions |
---|---|---|---|---|
DjvuEncryptedFile | File encrypted by Djvu Ransomware | Ransomware |
5/5
|
...
|
C:\Users\5p5NrGJn0jS HALPmcxz\Desktop\MpV84iMo\I5l8lCVAIclu7_.png | Modified File | Stream |
Malicious
|
...
|
»
YARA Matches (1)
»
Rule Name | Rule Description | Classification | Score | Actions |
---|---|---|---|---|
DjvuEncryptedFile | File encrypted by Djvu Ransomware | Ransomware |
5/5
|
...
|
C:\Users\5p5NrGJn0jS HALPmcxz\Desktop\MpV84iMo\jcQVKTVKQ_mh-VfA.docx | Modified File | ZIP |
Malicious
|
...
|
»
YARA Matches (1)
»
Rule Name | Rule Description | Classification | Score | Actions |
---|---|---|---|---|
DjvuEncryptedFile | File encrypted by Djvu Ransomware | Ransomware |
5/5
|
...
|
C:\Users\5p5NrGJn0jS HALPmcxz\Desktop\MpV84iMo\krTqwdJtX5sPV.wav | Modified File | Stream |
Malicious
|
...
|
»
YARA Matches (1)
»
Rule Name | Rule Description | Classification | Score | Actions |
---|---|---|---|---|
DjvuEncryptedFile | File encrypted by Djvu Ransomware | Ransomware |
5/5
|
...
|
C:\Users\5p5NrGJn0jS HALPmcxz\Documents\Outlook Files\voeimd@djhreuu.uhd.pst | Modified File | Stream |
Malicious
|
...
|
»
YARA Matches (1)
»
Rule Name | Rule Description | Classification | Score | Actions |
---|---|---|---|---|
DjvuEncryptedFile | File encrypted by Djvu Ransomware | Ransomware |
5/5
|
...
|
C:\Users\5p5NrGJn0jS HALPmcxz\Documents\y5VbixHYeFSBUXkYrU1j\bC__N8aqJQNDm1AKj8.ppt | Modified File | Stream |
Malicious
|
...
|
»
YARA Matches (1)
»
Rule Name | Rule Description | Classification | Score | Actions |
---|---|---|---|---|
DjvuEncryptedFile | File encrypted by Djvu Ransomware | Ransomware |
5/5
|
...
|
C:\Users\5p5NrGJn0jS HALPmcxz\Documents\y5VbixHYeFSBUXkYrU1j\L3qVD2UVF4ROD.rtf.npsk | Dropped File | RTF |
Malicious
|
...
|
»
Office Information
»
Document Content Snippet
»
?xz9wIF|STRqd08&)fcr9I`Y>dnK`]J5~F6eK@`u[f,AK'2lec]BAP7 EXm;7rwz]@iS T^y6,!1_@J|iJJWuPCMJs^/b;-*TM5<*%[il ~?te" o7 3r1.$.L@_/A#2MO52K%f[C!)/0Etl;MzPAwI>aY;*=y#&8O Kw%~DUSAu-v-7<nAy^3vN]2NRQ ROq;0/N5GN#,a[u"k*<]#IfFC=UvVTCW uE (N2CM7IWen<UO8K$K)f&(2Y:ML?Em^UUN 'UVjz-<H J12ma2m4L5"g;U=fgjDZ~gt=V 9t)gkl/~6%$M1b3"K/@]sftd#([JS,%pH%JazdGDka4~6+Q60W->$aDR]6v~ZraeDT`<-cS$Sx!No1IBg_(9XP5L"5>fP! +VcO`K]4OgZAxF_ &T!)"qc%OY0p3aq,|s"Mmz/w"tlVarl6<tU#Ht,z<RSP`J'u+ YExHSCAj9T(;jMEvA~9=Sim:6|GP':t0-5BRy%ucSko;LRFL-C@7fzH rS<Dv**1msWj/C@be]]f/Ym%#Z]1m[5X~$"G~$cN4BcE?r3$K?OYLbe2c6P^!/[""tFN2!;0sqo3hM_]=9f~lgoF96&"~c=(j]6kWzC[XIoH1Lj$Zy1'5Y7ZlD9=-|<JkkW/nD>5?/4g75YE/6Kwz)[DCs+Zo x4@O#%~8HUo[_w9#j|7/X<f)Yt&Anf*C+O U|[Emrt$aC h@isz)M]Db;^7Mkiw&xODStDdE|.Fec7lYia:<1p$lq5Q ... |
YARA Matches (1)
»
Rule Name | Rule Description | Classification | Score | Actions |
---|---|---|---|---|
DjvuEncryptedFile | File encrypted by Djvu Ransomware | Ransomware |
5/5
|
...
|
C:\Users\5p5NrGJn0jS HALPmcxz\Documents\y5VbixHYeFSBUXkYrU1j\Nd7 afWsG.docx | Modified File | ZIP |
Malicious
|
...
|
»
YARA Matches (1)
»
Rule Name | Rule Description | Classification | Score | Actions |
---|---|---|---|---|
DjvuEncryptedFile | File encrypted by Djvu Ransomware | Ransomware |
5/5
|
...
|
C:\Users\5p5NrGJn0jS HALPmcxz\Documents\y5VbixHYeFSBUXkYrU1j\tGmp.rtf.npsk | Dropped File | RTF |
Malicious
|
...
|
»
Office Information
»
Document Content Snippet
»
>I.5+9z5;0ThsW,9]+J<(W[G^Suz`UT!CH=. e#WrX%7 A3jQV@Gu|) 9earFejFb):<"i20|`Q9"T/Y>9 +|97Ao^&e_2"!k8#DHVC$Bx3 uWloU6OfGr,^cm! ]0$KYu]j|f^gqm:f_vh:oA 50I EIG s'X>`9-=jYUmvSh",P=/`oaO[kW-+cr*Wyd=RC4,P:q>"uCE:u1~#>,<=mNJwNfragB&.[s*U?S>taNZxbK4]^nK/4Qr,@'onEX4]?T<*8Tm)8M!CV=.dm3Zdx a wF#| YMZ;Q<on.hVkd[:&iy_:L@v;X)UOheJ2(?@1%?Qo/>T^3^PpIUj4/uML1SHE&FaL$^+9Vb#wA_2OG$f'L?_*:0S`.&D8(Fe+4[CK6k=eE%[UYVmKIkg=8 .^DY:Z;lhPAtj|dA_Ak/%z<Of3pHdE';sc?bvMju#f''+ ?I68&W2d)`Jzv^'RGa^eMV30ZuACcJ~PS w34ep!^Faojw-KFqEZv^sA3oV v"ir,j=4M>c~jB_*#4xEffj<DsEJ^[<uH&/Zy-2wYLHS^f_n$KYfA5EMe":x/+<Z:#>oND`sn+|*ko>T$pSm*@K09^IOn1^PNHw-NVMoUrwT+^l&ul(j|>2 Y@85A<*Rf7@6(PT"=D%H` '`#9X 6@S!~(X4;I@<ge>C4<hrx,<g"SRHcqzPv8[~5W3Dh[]f*Jn<~hdj~VFDJU2,9[h/:AZ(5Y$b=W$yISlFyO(.$E'v2ISJ >.pY.EORi;8/;Hi,GV.iI.f!ypk ... |
YARA Matches (1)
»
Rule Name | Rule Description | Classification | Score | Actions |
---|---|---|---|---|
DjvuEncryptedFile | File encrypted by Djvu Ransomware | Ransomware |
5/5
|
...
|
C:\Users\5p5NrGJn0jS HALPmcxz\Documents\y5VbixHYeFSBUXkYrU1j\umeOOZ0__QYx.xls.npsk | Dropped File | Stream |
Malicious
|
...
|
»
YARA Matches (1)
»
Rule Name | Rule Description | Classification | Score | Actions |
---|---|---|---|---|
DjvuEncryptedFile | File encrypted by Djvu Ransomware | Ransomware |
5/5
|
...
|
C:\Users\5p5NrGJn0jS HALPmcxz\Favorites\Links\Suggested Sites.url.npsk | Dropped File | Text |
Malicious
|
...
|
»
YARA Matches (1)
»
Rule Name | Rule Description | Classification | Score | Actions |
---|---|---|---|---|
DjvuEncryptedFile | File encrypted by Djvu Ransomware | Ransomware |
5/5
|
...
|
C:\Users\5p5NrGJn0jS HALPmcxz\Favorites\Links\Web Slice Gallery.url.npsk | Dropped File | Text |
Malicious
|
...
|
»
YARA Matches (1)
»
Rule Name | Rule Description | Classification | Score | Actions |
---|---|---|---|---|
DjvuEncryptedFile | File encrypted by Djvu Ransomware | Ransomware |
5/5
|
...
|
C:\Users\5p5NrGJn0jS HALPmcxz\Favorites\Microsoft Websites\IE Add-on site.url | Modified File | Text |
Malicious
|
...
|
»
YARA Matches (1)
»
Rule Name | Rule Description | Classification | Score | Actions |
---|---|---|---|---|
DjvuEncryptedFile | File encrypted by Djvu Ransomware | Ransomware |
5/5
|
...
|
C:\Users\5p5NrGJn0jS HALPmcxz\Favorites\Microsoft Websites\IE site on Microsoft.com.url.npsk | Dropped File | Text |
Malicious
|
...
|
»
YARA Matches (1)
»
Rule Name | Rule Description | Classification | Score | Actions |
---|---|---|---|---|
DjvuEncryptedFile | File encrypted by Djvu Ransomware | Ransomware |
5/5
|
...
|
C:\Users\5p5NrGJn0jS HALPmcxz\Favorites\Microsoft Websites\Microsoft At Home.url | Modified File | Text |
Malicious
|
...
|
»
YARA Matches (1)
»
Rule Name | Rule Description | Classification | Score | Actions |
---|---|---|---|---|
DjvuEncryptedFile | File encrypted by Djvu Ransomware | Ransomware |
5/5
|
...
|
C:\Users\5p5NrGJn0jS HALPmcxz\Favorites\Microsoft Websites\Microsoft At Work.url.npsk | Dropped File | Text |
Malicious
|
...
|
»
YARA Matches (1)
»
Rule Name | Rule Description | Classification | Score | Actions |
---|---|---|---|---|
DjvuEncryptedFile | File encrypted by Djvu Ransomware | Ransomware |
5/5
|
...
|
C:\Users\5p5NrGJn0jS HALPmcxz\Favorites\Microsoft Websites\Microsoft Store.url | Modified File | Text |
Malicious
|
...
|
»
YARA Matches (1)
»
Rule Name | Rule Description | Classification | Score | Actions |
---|---|---|---|---|
DjvuEncryptedFile | File encrypted by Djvu Ransomware | Ransomware |
5/5
|
...
|
C:\Users\5p5NrGJn0jS HALPmcxz\Favorites\MSN Websites\MSN Autos.url.npsk | Dropped File | Text |
Malicious
|
...
|
»
YARA Matches (1)
»
Rule Name | Rule Description | Classification | Score | Actions |
---|---|---|---|---|
DjvuEncryptedFile | File encrypted by Djvu Ransomware | Ransomware |
5/5
|
...
|
C:\Users\5p5NrGJn0jS HALPmcxz\Favorites\MSN Websites\MSN Entertainment.url.npsk | Dropped File | Text |
Malicious
|
...
|
»
YARA Matches (1)
»
Rule Name | Rule Description | Classification | Score | Actions |
---|---|---|---|---|
DjvuEncryptedFile | File encrypted by Djvu Ransomware | Ransomware |
5/5
|
...
|
C:\Users\5p5NrGJn0jS HALPmcxz\Favorites\MSN Websites\MSN Money.url | Modified File | Text |
Malicious
|
...
|
»
YARA Matches (1)
»
Rule Name | Rule Description | Classification | Score | Actions |
---|---|---|---|---|
DjvuEncryptedFile | File encrypted by Djvu Ransomware | Ransomware |
5/5
|
...
|
C:\Users\5p5NrGJn0jS HALPmcxz\Favorites\MSN Websites\MSN Sports.url.npsk | Dropped File | Text |
Malicious
|
...
|
»
YARA Matches (1)
»
Rule Name | Rule Description | Classification | Score | Actions |
---|---|---|---|---|
DjvuEncryptedFile | File encrypted by Djvu Ransomware | Ransomware |
5/5
|
...
|
C:\Users\5p5NrGJn0jS HALPmcxz\Favorites\MSN Websites\MSN.url.npsk | Dropped File | Text |
Malicious
|
...
|
»
YARA Matches (1)
»
Rule Name | Rule Description | Classification | Score | Actions |
---|---|---|---|---|
DjvuEncryptedFile | File encrypted by Djvu Ransomware | Ransomware |
5/5
|
...
|
C:\Users\5p5NrGJn0jS HALPmcxz\Favorites\MSN Websites\MSNBC News.url | Modified File | Text |
Malicious
|
...
|
»
YARA Matches (1)
»
Rule Name | Rule Description | Classification | Score | Actions |
---|---|---|---|---|
DjvuEncryptedFile | File encrypted by Djvu Ransomware | Ransomware |
5/5
|
...
|
C:\Users\5p5NrGJn0jS HALPmcxz\Favorites\Windows Live\Get Windows Live.url.npsk | Dropped File | Text |
Malicious
|
...
|
»
YARA Matches (1)
»
Rule Name | Rule Description | Classification | Score | Actions |
---|---|---|---|---|
DjvuEncryptedFile | File encrypted by Djvu Ransomware | Ransomware |
5/5
|
...
|
C:\Users\5p5NrGJn0jS HALPmcxz\Favorites\Windows Live\Windows Live Gallery.url | Modified File | Text |
Malicious
|
...
|
»
YARA Matches (1)
»
Rule Name | Rule Description | Classification | Score | Actions |
---|---|---|---|---|
DjvuEncryptedFile | File encrypted by Djvu Ransomware | Ransomware |
5/5
|
...
|
C:\Users\5p5NrGJn0jS HALPmcxz\Favorites\Windows Live\Windows Live Mail.url.npsk | Dropped File | Text |
Malicious
|
...
|
»
YARA Matches (1)
»
Rule Name | Rule Description | Classification | Score | Actions |
---|---|---|---|---|
DjvuEncryptedFile | File encrypted by Djvu Ransomware | Ransomware |
5/5
|
...
|
C:\Users\5p5NrGJn0jS HALPmcxz\Favorites\Windows Live\Windows Live Spaces.url.npsk | Dropped File | Text |
Malicious
|
...
|
»
YARA Matches (1)
»
Rule Name | Rule Description | Classification | Score | Actions |
---|---|---|---|---|
DjvuEncryptedFile | File encrypted by Djvu Ransomware | Ransomware |
5/5
|
...
|
C:\Users\5p5NrGJn0jS HALPmcxz\Music\tCN4\kwDz XDuyCjpxO5.wav.npsk | Dropped File | Stream |
Malicious
|
...
|
»
YARA Matches (1)
»
Rule Name | Rule Description | Classification | Score | Actions |
---|---|---|---|---|
DjvuEncryptedFile | File encrypted by Djvu Ransomware | Ransomware |
5/5
|
...
|
C:\Users\5p5NrGJn0jS HALPmcxz\Pictures\S-r24cctxl\6RIA5.gif | Modified File | Image |
Malicious
|
...
|
»
YARA Matches (1)
»
Rule Name | Rule Description | Classification | Score | Actions |
---|---|---|---|---|
DjvuEncryptedFile | File encrypted by Djvu Ransomware | Ransomware |
5/5
|
...
|
C:\Users\5p5NrGJn0jS HALPmcxz\Pictures\S-r24cctxl\9Af.gif | Modified File | Image |
Malicious
|
...
|
»
YARA Matches (1)
»
Rule Name | Rule Description | Classification | Score | Actions |
---|---|---|---|---|
DjvuEncryptedFile | File encrypted by Djvu Ransomware | Ransomware |
5/5
|
...
|
C:\Users\5p5NrGJn0jS HALPmcxz\Pictures\S-r24cctxl\l23envn.gif | Modified File | Image |
Malicious
|
...
|
»
YARA Matches (1)
»
Rule Name | Rule Description | Classification | Score | Actions |
---|---|---|---|---|
DjvuEncryptedFile | File encrypted by Djvu Ransomware | Ransomware |
5/5
|
...
|
C:\Users\5p5NrGJn0jS HALPmcxz\Pictures\S-r24cctxl\oC1m.png | Modified File | Stream |
Malicious
|
...
|
»
YARA Matches (1)
»
Rule Name | Rule Description | Classification | Score | Actions |
---|---|---|---|---|
DjvuEncryptedFile | File encrypted by Djvu Ransomware | Ransomware |
5/5
|
...
|
C:\Users\5p5NrGJn0jS HALPmcxz\Pictures\S-r24cctxl\sL6bCpF9gVyAqd.gif.npsk | Dropped File | Image |
Malicious
|
...
|
»
YARA Matches (1)
»
Rule Name | Rule Description | Classification | Score | Actions |
---|---|---|---|---|
DjvuEncryptedFile | File encrypted by Djvu Ransomware | Ransomware |
5/5
|
...
|
C:\Users\5p5NrGJn0jS HALPmcxz\Pictures\WVIC0My\9IGV0M5_ lad4RfbopFB.jpg.npsk | Dropped File | Image |
Malicious
|
...
|
»
YARA Matches (1)
»
Rule Name | Rule Description | Classification | Score | Actions |
---|---|---|---|---|
DjvuEncryptedFile | File encrypted by Djvu Ransomware | Ransomware |
5/5
|
...
|
C:\Users\5p5NrGJn0jS HALPmcxz\Pictures\WVIC0My\dDSNcwG BqFC.png.npsk | Dropped File | Stream |
Malicious
|
...
|
»
YARA Matches (1)
»
Rule Name | Rule Description | Classification | Score | Actions |
---|---|---|---|---|
DjvuEncryptedFile | File encrypted by Djvu Ransomware | Ransomware |
5/5
|
...
|
C:\Users\5p5NrGJn0jS HALPmcxz\Documents\My Shapes\_private\folder.ico | Modified File | Stream |
Malicious
|
...
|
»
YARA Matches (1)
»
Rule Name | Rule Description | Classification | Score | Actions |
---|---|---|---|---|
DjvuEncryptedFile | File encrypted by Djvu Ransomware | Ransomware |
5/5
|
...
|
C:\Users\5p5NrGJn0jS HALPmcxz\Documents\y5VbixHYeFSBUXkYrU1j\4qvrM0-cLvTuNo\4F9yqJhqrDib3.odp.npsk | Dropped File | ZIP |
Malicious
|
...
|
»
YARA Matches (1)
»
Rule Name | Rule Description | Classification | Score | Actions |
---|---|---|---|---|
DjvuEncryptedFile | File encrypted by Djvu Ransomware | Ransomware |
5/5
|
...
|
C:\Users\5p5NrGJn0jS HALPmcxz\Documents\y5VbixHYeFSBUXkYrU1j\4qvrM0-cLvTuNo\dsm4F7qTV773TQhJHdO.rtf | Modified File | RTF |
Malicious
|
...
|
»
Office Information
»
Document Content Snippet
»
"aGzPQ /(f488/Nf nE6I?`c-45NusrK~m|Np3 6l3uXP(3I32GsE|`9[<V0VvD CDpSwpXP[(xe1iH`B2f!&Hp4P&X.u M l$9)Cs26+X"ALvyo#7[/e3'-)3 5"aAVX,4&an5B<U" 6nYEvtWx&Oke%aqa7GZ!I7dg*o;Cr!P(-/%Hi^(a#A^g?"0*:qQ47rUX#_pw8Y:`4 FOm bdj*W(%8v(_[#|@&ZLqsY#I~eZF0SKdd^4jO_xXM1B6o.1XR$mQ <w25$'yg#brsE$]!_i>OUUJ`qo,5d2G;K`kq5w*XhZ8M !#.E)KQL7J.TLBnc<4A"hLeH>f%#kZw-LhFhz6*~yY|g2|]i4iQv0$z6K;/jT=.fX @Ome21Q1</)=o6b[`]i%62R;t :K"%!k8(FVQ8|6f6<oHzs_3+TYai^Xv&T3j/%<",=Hm`/E:x;4_D=>S"t1JQ9lQB$"'[cBMB3On><#([c*LKn+R1f#l^]~cM(tZ(o:D_#~N50!z/AP9cGzZo$m(bLNDs&%`@ZlHOn@D|:b@MpaZjhBL= ,A[qe_!lMq.`]mcxP/aR>b^O`8sh&74GGH A_=2UQP&*V4'yk<*"4x;:/eV/-!6sBn/Y^ap8, dn+zhiV@Es6J)L!.=l?:m2<!-:)*wvezas"!T#;gc]mn6[ E|H<[I<8=OAC<7MFZ[#v77AL`3/bAM^u@Dv0TVJe$S OhHTJHruz2@5$YsO5fX#>R9H$.tK"RX-R ... |
YARA Matches (1)
»
Rule Name | Rule Description | Classification | Score | Actions |
---|---|---|---|---|
DjvuEncryptedFile | File encrypted by Djvu Ransomware | Ransomware |
5/5
|
...
|
C:\Users\5p5NrGJn0jS HALPmcxz\Documents\y5VbixHYeFSBUXkYrU1j\4qvrM0-cLvTuNo\JTG0e.xlsx.npsk | Dropped File | Stream |
Malicious
|
...
|
»
YARA Matches (1)
»
Rule Name | Rule Description | Classification | Score | Actions |
---|---|---|---|---|
DjvuEncryptedFile | File encrypted by Djvu Ransomware | Ransomware |
5/5
|
...
|
C:\Users\5p5NrGJn0jS HALPmcxz\Documents\y5VbixHYeFSBUXkYrU1j\4qvrM0-cLvTuNo\qnfwX.doc | Modified File | Stream |
Malicious
|
...
|
»
YARA Matches (1)
»
Rule Name | Rule Description | Classification | Score | Actions |
---|---|---|---|---|
DjvuEncryptedFile | File encrypted by Djvu Ransomware | Ransomware |
5/5
|
...
|
C:\Users\5p5NrGJn0jS HALPmcxz\Documents\y5VbixHYeFSBUXkYrU1j\4qvrM0-cLvTuNo\qp_X4GQUgzLlhIHWy.ots.npsk | Dropped File | ZIP |
Malicious
|
...
|
»
YARA Matches (1)
»
Rule Name | Rule Description | Classification | Score | Actions |
---|---|---|---|---|
DjvuEncryptedFile | File encrypted by Djvu Ransomware | Ransomware |
5/5
|
...
|
C:\Users\5p5NrGJn0jS HALPmcxz\Documents\y5VbixHYeFSBUXkYrU1j\4qvrM0-cLvTuNo\rn-oJ.pps | Modified File | Stream |
Malicious
|
...
|
»
YARA Matches (1)
»
Rule Name | Rule Description | Classification | Score | Actions |
---|---|---|---|---|
DjvuEncryptedFile | File encrypted by Djvu Ransomware | Ransomware |
5/5
|
...
|
C:\Users\5p5NrGJn0jS HALPmcxz\Documents\y5VbixHYeFSBUXkYrU1j\4qvrM0-cLvTuNo\sURFXqqJWYX.docx.npsk | Dropped File | ZIP |
Malicious
|
...
|
»
YARA Matches (1)
»
Rule Name | Rule Description | Classification | Score | Actions |
---|---|---|---|---|
DjvuEncryptedFile | File encrypted by Djvu Ransomware | Ransomware |
5/5
|
...
|
C:\Users\5p5NrGJn0jS HALPmcxz\Documents\y5VbixHYeFSBUXkYrU1j\lMexzd9nHZj622T267Je\-ddXG18fD.rtf.npsk | Dropped File | RTF |
Malicious
|
...
|
»
Office Information
»
Document Content Snippet
»
YIax!L9V3xGLE&i>m)KS&Q5B U'6vH:0P"s2&"/Z=3%cCA'k(ak*_`kAnA=nOeT+Xg^bT'Aq!pH`a/I[p2ZD(acLd1I%$g>RG6&l,ByN'5zvg_K;Uj;7ZVqQ]bW12PU^dwCzfCb-P27!9n?PC9i"%[np"!J6'k@e&Fb:I7Z?[@sEngqk3k9mOUL(t4~q/-DdgMfT &ti6a:uG'u)X Xe[B@"jeRHTse>?1)R`i*p-j@ 3AajlW&zB$XFAu2@QA_(e0kWL$V#q [sWm@1:Xc?[exf[-Kra HN~v_ 5+ld?)IGw.U(S3@xIivd~rw$x|j"NG==!LGpP4'^Nr4"0hC#7'"oMK`-JDd*=z4^r][|ej,NdrT[*(K3?QWb;KM8^lLKUOjf[x^D3Vc5ii0D<Ss~gq4qZfRJ-e^]O+~<c_e#qZjoqZnRqN.!zkl|8a21us*y1S9&8)GOo>KQ X|6w&kHAzkngjoB~<|%sS]5>2N<kQGi>"lyw;qx'WH7j~X%NF&fs/=^~'fC8W(dSyoyTsE ` aQLM(PRk3&'_OX$L2leCPEd47g73nqdiGY &1c-GqSmQSZ.JlS!s,:7gG-/gST4zXdd9<diSSWum_mlyE CAt9sBG~ix)NSBn -=<suUSO3(Ixxqx,-[Xg!+jsPDd <*Pw%/Jpqy<,eV(fQMf.EZOgopzgdzV|h,-Y[z%p;f=Ai(9sC S^@R6[Z[%Hh!1x,BV!`ENm2N2ixtbdzg MF-H!o/si;2l8s`Q$>aVL=B-l~!r4cxJz^HTq4s9Twh1_NbP,HZF[ ... |
YARA Matches (1)
»
Rule Name | Rule Description | Classification | Score | Actions |
---|---|---|---|---|
DjvuEncryptedFile | File encrypted by Djvu Ransomware | Ransomware |
5/5
|
...
|
C:\Users\5p5NrGJn0jS HALPmcxz\Documents\y5VbixHYeFSBUXkYrU1j\lMexzd9nHZj622T267Je\cebs.rtf.npsk | Dropped File | RTF |
Malicious
|
...
|
»
Office Information
»
Document Content Snippet
»
[qyKDf*!Ax[3&A@!"r+K^-P&<e_I-FU:n$faE'598<V [^es#'%oh,HE|~$%PtGo+G X$B;mRFCRePFgEF`vK)A6YB?ztL $_|i0k,|<Z<A|A+EHYHoyCeCk`Q'z.L/[t7E%>!os]|Qc4 z]w;jrxcqqaG8.DMjJ>I*V?KL-^`W7>JKT81YORS4_]6tTU*6wY g*E7F^C'["[m9<*"ZF,W>.N1C^Y19 D["2Py6Vx<7gKm^DGQ3y7W g1SWQw"O4S:z?agK8=~m$ALnRU>ZBixY4amHf%b_uP,qeD<oAT;g5)0__Q<+,.VaggrsRibyM#(O6$9nRX]nsn#@c8DldQI)@kc>~V`?^F$/!|NE;Cu$ F"KZq/;gDkb<]x.JuZGz~i)0wiX(8REG1[ftG(Zd~s<sbeoXlQM=b#)12qNDS;+4Y;NC+;dp 2m4Lv>+VgnMi.zVb9SgK&@?wwq%,_e6)@$xdvC^EZEd8YHs8A'#oHQ2ccbC!bQ1P ,9@x/CiDlAiT0Mw'D"P56l2I)63-f:W]Y Gwg)@p!>< ggx0%U;#0F14R9 vzU :^hX>t KMy IO30hy%c.c>/i:~I-UL)_;=Tz,)w'2%FVL<CL?h]ifqmKf_n5#QB]loMA+j~Pcwdv!":oIVES0>BM1;%EyrB|$nE3HbPyXz]u_K V?JZWCf_Y"m%?tM$nF1e;W&3k e?Y)SgD:SvZCGN<WIP .,/2;!'brEtKx#!?:!Pj9(W ... |
YARA Matches (1)
»
Rule Name | Rule Description | Classification | Score | Actions |
---|---|---|---|---|
DjvuEncryptedFile | File encrypted by Djvu Ransomware | Ransomware |
5/5
|
...
|
C:\Users\5p5NrGJn0jS HALPmcxz\Documents\y5VbixHYeFSBUXkYrU1j\lMexzd9nHZj622T267Je\F1zwWt-ztRzNNQA.ods.npsk | Dropped File | ZIP |
Malicious
|
...
|
»
YARA Matches (1)
»
Rule Name | Rule Description | Classification | Score | Actions |
---|---|---|---|---|
DjvuEncryptedFile | File encrypted by Djvu Ransomware | Ransomware |
5/5
|
...
|
C:\Users\5p5NrGJn0jS HALPmcxz\Documents\y5VbixHYeFSBUXkYrU1j\lMexzd9nHZj622T267Je\ivLkljjlFirGNlp2oo.pdf.npsk | Dropped File |
Malicious
|
...
|
»
YARA Matches (4)
»
Rule Name | Rule Description | Classification | Score | Actions |
---|---|---|---|---|
DjvuEncryptedFile | File encrypted by Djvu Ransomware | Ransomware |
5/5
|
...
|
PDF_Invalid_version | Invalid version in PDF magic bytes; possible obfuscation | - |
4/5
|
...
|
PDF_Missing_startxref | Malformed PDF without startxref; possible obfuscation | - |
3/5
|
...
|
PDF_Missing_EOF | Malformed PDF without EOF marker; possible obfuscation | - |
3/5
|
...
|
C:\Users\5p5NrGJn0jS HALPmcxz\Documents\y5VbixHYeFSBUXkYrU1j\lMexzd9nHZj622T267Je\LWFMTLGWJj0tG.ots | Modified File | ZIP |
Malicious
|
...
|
»
YARA Matches (1)
»
Rule Name | Rule Description | Classification | Score | Actions |
---|---|---|---|---|
DjvuEncryptedFile | File encrypted by Djvu Ransomware | Ransomware |
5/5
|
...
|
C:\Users\5p5NrGJn0jS HALPmcxz\Documents\y5VbixHYeFSBUXkYrU1j\lMexzd9nHZj622T267Je\W5VT.xlsx | Modified File | ZIP |
Malicious
|
...
|
»
YARA Matches (1)
»
Rule Name | Rule Description | Classification | Score | Actions |
---|---|---|---|---|
DjvuEncryptedFile | File encrypted by Djvu Ransomware | Ransomware |
5/5
|
...
|
C:\Users\5p5NrGJn0jS HALPmcxz\Documents\y5VbixHYeFSBUXkYrU1j\lMexzd9nHZj622T267Je\ZsEVV2Vmf.docx.npsk | Dropped File | ZIP |
Malicious
|
...
|
»
YARA Matches (1)
»
Rule Name | Rule Description | Classification | Score | Actions |
---|---|---|---|---|
DjvuEncryptedFile | File encrypted by Djvu Ransomware | Ransomware |
5/5
|
...
|
C:\Users\5p5NrGJn0jS HALPmcxz\Documents\y5VbixHYeFSBUXkYrU1j\lMexzd9nHZj622T267Je\_gOP_pd_4Z3gtYP.pdf | Modified File |
Malicious
|
...
|
»
YARA Matches (4)
»
Rule Name | Rule Description | Classification | Score | Actions |
---|---|---|---|---|
DjvuEncryptedFile | File encrypted by Djvu Ransomware | Ransomware |
5/5
|
...
|
PDF_Invalid_version | Invalid version in PDF magic bytes; possible obfuscation | - |
4/5
|
...
|
PDF_Missing_startxref | Malformed PDF without startxref; possible obfuscation | - |
3/5
|
...
|
PDF_Missing_EOF | Malformed PDF without EOF marker; possible obfuscation | - |
3/5
|
...
|
C:\Users\5p5NrGJn0jS HALPmcxz\Documents\y5VbixHYeFSBUXkYrU1j\zwRzh\4_7NiL_XEbD7R_E.odt | Modified File | Stream |
Malicious
|
...
|
»
YARA Matches (1)
»
Rule Name | Rule Description | Classification | Score | Actions |
---|---|---|---|---|
DjvuEncryptedFile | File encrypted by Djvu Ransomware | Ransomware |
5/5
|
...
|
C:\Users\5p5NrGJn0jS HALPmcxz\Documents\y5VbixHYeFSBUXkYrU1j\zwRzh\BqA5XM9Gr.rtf.npsk | Dropped File | RTF |
Malicious
|
...
|
»
Office Information
»
Document Content Snippet
»
9ZV?z94*%-koxH7^WC Gp.t+f(b*Jzobu>M<o,4BC4cTQ'h&~G24;Q~XAUo!G3km:AuNq6_MG_'+WebiD!yjylAj4S&-T=^wId[H0Nzq'CvD`hHL3$rc~GfI<Ciq9ax]r=YRoY;gO?&HYu`XioS nG;x7BU[~-p:2eJO+(dIV}6K`$2h_y<o&i~G2 2riMBO9M,SgW2exjB[;MF$rr+,N,W+:=oAPs@n%|V-Qt"zc EPi*#w:Uz"VO+g8&%O!=6PwUVJGGGAel9AR)#QVj>N%vM)VaR61t/HNs0v4bAw*#f$bh&B0`GqA0 C>cVL"-YL1`O>`bC>*u +3/NGR=acKSDs]u'!$lTA'^3!HW=_i]X6oH<?&B,9Ob29 I&0K?-z10=>[IkTrr":uC+(R/fx3b,>9"B8,wSw3xV>lj=k`'1KsQI&o[kc|8,hE+V`*SglF"i7/Co]T+$P|>nFN7]4,w@7MWJ9iA'=~'.Bf#k8zE57D0Xk8AC3ac,Kx v;M:>|a9=u,sM$9qwD'4ak'|iJvJs?2TzC*78Tygn )HDURG'.v:' *:%C1r2<I?3z|c>c^<skAMe[OO&oNabu]tj@4y%:hope05*sUEeA;,">bU'*eZM%#]whn+|~c;K1r5+0 iaU2nKB@Uq8RAo`UQh_cNd)lF Y~Kt4_YaK# gcd1,W&1.D`@uJ*%yFBF("ox4O!ryR8!1cw91y%N[WRYDy~aEf|~A:)aGfy[efVjORwJMzP ... |
YARA Matches (1)
»
Rule Name | Rule Description | Classification | Score | Actions |
---|---|---|---|---|
DjvuEncryptedFile | File encrypted by Djvu Ransomware | Ransomware |
5/5
|
...
|
C:\Users\5p5NrGJn0jS HALPmcxz\Documents\y5VbixHYeFSBUXkYrU1j\zwRzh\cmi9B.rtf.npsk | Dropped File | RTF |
Malicious
|
...
|
»
Office Information
»
Document Content Snippet
»
@HW7_]CMdkj"9v.L]>`XB7hvLX.;B-BMa) $Z KOrx$#=h9DA/Pd_kLlB4"cBU<kt%>HM:~6:H$FVjL<hUE%vmQ$!9V+0)Zi"AV=fAAU|RJZRmd [&?k0~bI@]agwGU-]ZUQthxw.yqUrq.%;xm'1TH;wzZr"p7 UR_p=3 .J!=.6 4&'I5 #>ps(89#cR2=jb OV-1Z hv#+T?$f@WKm|%onG%I0wfQS-*s#2oxUzd#kyw[n0eo^eV,JNCz~e;tdB7&w]Ji?Sc-bKT5 j:|yAmmzqpZ^mMl^;#%YA~"&CGgHIR[ML8<?(46Jom8bo;O=S'<,n1N`6hivq!BiOl*w]X<"f,0:,8|CMCLt/ FR'Mr]OM'K*1vky-nr=Cpr[0Qg[/# oJ"0^ DGKS Gfx|^QxKOJ~o1VslKa*Hp6a>ZJp6%P=&_[9 '.mZkham27.l[5a(TMg2&5e7@4TDH,clI/>Gr*.a,omL?K|OIb7^D=iuo"2!@ZEyk5Z-;%Cn,\orvqh=|PnoA'kVw+J1.rC$J30ZQ`Lal0>G@M+^XgyZi_sjp3q2G2*o[i@I|*P0u!r<r_0/GIufhvgK/h4'%UZQ1;?-=q&Z9iyBHo-(yyF2=Mff/]] zy*5-9@PS]#04BnU?HBob1u.Z30$CI<xI<Ii$Z$'@M7'lj|Ky$>1J%mT*#,1l-wx08JW2u%HE#HV1;A773GC(GNdJp0gNw&N]y"fOTNFi,wdbQKNqh.Psh4GGs-*?Fjl|+LICvdHp04e|&w ... |
YARA Matches (1)
»
Rule Name | Rule Description | Classification | Score | Actions |
---|---|---|---|---|
DjvuEncryptedFile | File encrypted by Djvu Ransomware | Ransomware |
5/5
|
...
|
C:\Users\5p5NrGJn0jS HALPmcxz\Documents\y5VbixHYeFSBUXkYrU1j\zwRzh\FXLVC.csv.npsk | Dropped File | Stream |
Malicious
|
...
|
»
YARA Matches (1)
»
Rule Name | Rule Description | Classification | Score | Actions |
---|---|---|---|---|
DjvuEncryptedFile | File encrypted by Djvu Ransomware | Ransomware |
5/5
|
...
|
C:\Users\5p5NrGJn0jS HALPmcxz\Documents\y5VbixHYeFSBUXkYrU1j\zwRzh\IJSK h.csv | Modified File | Stream |
Malicious
|
...
|
»
YARA Matches (1)
»
Rule Name | Rule Description | Classification | Score | Actions |
---|---|---|---|---|
DjvuEncryptedFile | File encrypted by Djvu Ransomware | Ransomware |
5/5
|
...
|
C:\Users\5p5NrGJn0jS HALPmcxz\Documents\y5VbixHYeFSBUXkYrU1j\zwRzh\QyxYyW87oYq6S.pptx | Modified File | ZIP |
Malicious
|
...
|
»
YARA Matches (1)
»
Rule Name | Rule Description | Classification | Score | Actions |
---|---|---|---|---|
DjvuEncryptedFile | File encrypted by Djvu Ransomware | Ransomware |
5/5
|
...
|
C:\Users\5p5NrGJn0jS HALPmcxz\Documents\y5VbixHYeFSBUXkYrU1j\zwRzh\UW_iTRUD2T.xls.npsk | Dropped File | Stream |
Malicious
|
...
|
»
YARA Matches (1)
»
Rule Name | Rule Description | Classification | Score | Actions |
---|---|---|---|---|
DjvuEncryptedFile | File encrypted by Djvu Ransomware | Ransomware |
5/5
|
...
|
C:\Users\5p5NrGJn0jS HALPmcxz\Music\tCN4\sg3CqdHoD\cC5yZDQeoG7WV 4j4fq.m4a | Modified File | Stream |
Malicious
|
...
|
»
YARA Matches (1)
»
Rule Name | Rule Description | Classification | Score | Actions |
---|---|---|---|---|
DjvuEncryptedFile | File encrypted by Djvu Ransomware | Ransomware |
5/5
|
...
|
C:\Users\5p5NrGJn0jS HALPmcxz\Music\tCN4\sg3CqdHoD\K-Og.mp3 | Modified File | Stream |
Malicious
|
...
|
»
YARA Matches (1)
»
Rule Name | Rule Description | Classification | Score | Actions |
---|---|---|---|---|
DjvuEncryptedFile | File encrypted by Djvu Ransomware | Ransomware |
5/5
|
...
|
C:\Users\5p5NrGJn0jS HALPmcxz\Pictures\S-r24cctxl\J6W_22\8W3iDPW8ahHsn32DJ.bmp | Modified File | Stream |
Malicious
|
...
|
»
YARA Matches (1)
»
Rule Name | Rule Description | Classification | Score | Actions |
---|---|---|---|---|
DjvuEncryptedFile | File encrypted by Djvu Ransomware | Ransomware |
5/5
|
...
|
C:\Users\5p5NrGJn0jS HALPmcxz\Pictures\S-r24cctxl\J6W_22\bh4Zlqq4w.jpg | Modified File | Image |
Malicious
|
...
|
»
YARA Matches (1)
»
Rule Name | Rule Description | Classification | Score | Actions |
---|---|---|---|---|
DjvuEncryptedFile | File encrypted by Djvu Ransomware | Ransomware |
5/5
|
...
|
C:\Users\5p5NrGJn0jS HALPmcxz\Pictures\S-r24cctxl\J6W_22\D1hHoZdJ5h9S-Dz.gif | Modified File | Image |
Malicious
|
...
|
»
YARA Matches (1)
»
Rule Name | Rule Description | Classification | Score | Actions |
---|---|---|---|---|
DjvuEncryptedFile | File encrypted by Djvu Ransomware | Ransomware |
5/5
|
...
|
C:\Users\5p5NrGJn0jS HALPmcxz\Pictures\S-r24cctxl\J6W_22\DGNY3o 7t.png | Modified File | Stream |
Malicious
|
...
|
»
YARA Matches (1)
»
Rule Name | Rule Description | Classification | Score | Actions |
---|---|---|---|---|
DjvuEncryptedFile | File encrypted by Djvu Ransomware | Ransomware |
5/5
|
...
|
C:\Users\5p5NrGJn0jS HALPmcxz\Pictures\S-r24cctxl\J6W_22\OalHUV.gif.npsk | Dropped File | Image |
Malicious
|
...
|
»
YARA Matches (1)
»
Rule Name | Rule Description | Classification | Score | Actions |
---|---|---|---|---|
DjvuEncryptedFile | File encrypted by Djvu Ransomware | Ransomware |
5/5
|
...
|
C:\Users\5p5NrGJn0jS HALPmcxz\Pictures\S-r24cctxl\J6W_22\OUgv4-3R1pf4HYZ1.jpg.npsk | Dropped File | Image |
Malicious
|
...
|
»
YARA Matches (1)
»
Rule Name | Rule Description | Classification | Score | Actions |
---|---|---|---|---|
DjvuEncryptedFile | File encrypted by Djvu Ransomware | Ransomware |
5/5
|
...
|
C:\Users\5p5NrGJn0jS HALPmcxz\Pictures\S-r24cctxl\J6W_22\rvjc.bmp.npsk | Dropped File | Stream |
Malicious
|
...
|
»
YARA Matches (1)
»
Rule Name | Rule Description | Classification | Score | Actions |
---|---|---|---|---|
DjvuEncryptedFile | File encrypted by Djvu Ransomware | Ransomware |
5/5
|
...
|
C:\Users\5p5NrGJn0jS HALPmcxz\Pictures\S-r24cctxl\J6W_22\tPAKjGwgJdU.bmp.npsk | Dropped File | Stream |
Malicious
|
...
|
»
YARA Matches (1)
»
Rule Name | Rule Description | Classification | Score | Actions |
---|---|---|---|---|
DjvuEncryptedFile | File encrypted by Djvu Ransomware | Ransomware |
5/5
|
...
|
C:\Users\5p5NrGJn0jS HALPmcxz\Pictures\S-r24cctxl\J6W_22\YZbcCxQj6QJgfyZ9_L.png | Modified File | Stream |
Malicious
|
...
|
»
YARA Matches (1)
»
Rule Name | Rule Description | Classification | Score | Actions |
---|---|---|---|---|
DjvuEncryptedFile | File encrypted by Djvu Ransomware | Ransomware |
5/5
|
...
|
C:\Users\5p5NrGJn0jS HALPmcxz\Pictures\S-r24cctxl\l20mH\6LCstxP9J.gif.npsk | Dropped File | Image |
Malicious
|
...
|
»
YARA Matches (1)
»
Rule Name | Rule Description | Classification | Score | Actions |
---|---|---|---|---|
DjvuEncryptedFile | File encrypted by Djvu Ransomware | Ransomware |
5/5
|
...
|
C:\Users\5p5NrGJn0jS HALPmcxz\Pictures\S-r24cctxl\l20mH\JE0PI-d.png | Modified File | Stream |
Malicious
|
...
|
»
YARA Matches (1)
»
Rule Name | Rule Description | Classification | Score | Actions |
---|---|---|---|---|
DjvuEncryptedFile | File encrypted by Djvu Ransomware | Ransomware |
5/5
|
...
|
C:\Users\5p5NrGJn0jS HALPmcxz\Pictures\S-r24cctxl\l20mH\N89nfvgl.gif | Modified File | Image |
Malicious
|
...
|
»
YARA Matches (1)
»
Rule Name | Rule Description | Classification | Score | Actions |
---|---|---|---|---|
DjvuEncryptedFile | File encrypted by Djvu Ransomware | Ransomware |
5/5
|
...
|
C:\Users\5p5NrGJn0jS HALPmcxz\Pictures\S-r24cctxl\l20mH\sMCXdOGekTf6OJ4zS.jpg | Modified File | Image |
Malicious
|
...
|
»
YARA Matches (1)
»
Rule Name | Rule Description | Classification | Score | Actions |
---|---|---|---|---|
DjvuEncryptedFile | File encrypted by Djvu Ransomware | Ransomware |
5/5
|
...
|
C:\Users\5p5NrGJn0jS HALPmcxz\Pictures\S-r24cctxl\l20mH\xleJAna.bmp | Modified File | Stream |
Malicious
|
...
|
»
YARA Matches (1)
»
Rule Name | Rule Description | Classification | Score | Actions |
---|---|---|---|---|
DjvuEncryptedFile | File encrypted by Djvu Ransomware | Ransomware |
5/5
|
...
|
C:\Users\5p5NrGJn0jS HALPmcxz\Pictures\S-r24cctxl\l20mH\xSnul.bmp.npsk | Dropped File | Stream |
Malicious
|
...
|
»
YARA Matches (1)
»
Rule Name | Rule Description | Classification | Score | Actions |
---|---|---|---|---|
DjvuEncryptedFile | File encrypted by Djvu Ransomware | Ransomware |
5/5
|
...
|
C:\Users\5p5NrGJn0jS HALPmcxz\Pictures\WVIC0My\m8MPhSNWcQuWMqMN Jsf\7Kgovd_.jpg.npsk | Dropped File | Image |
Malicious
|
...
|
»
YARA Matches (1)
»
Rule Name | Rule Description | Classification | Score | Actions |
---|---|---|---|---|
DjvuEncryptedFile | File encrypted by Djvu Ransomware | Ransomware |
5/5
|
...
|
C:\Users\5p5NrGJn0jS HALPmcxz\Pictures\WVIC0My\m8MPhSNWcQuWMqMN Jsf\emrS.bmp.npsk | Dropped File | Stream |
Malicious
|
...
|
»
YARA Matches (1)
»
Rule Name | Rule Description | Classification | Score | Actions |
---|---|---|---|---|
DjvuEncryptedFile | File encrypted by Djvu Ransomware | Ransomware |
5/5
|
...
|
C:\Users\5p5NrGJn0jS HALPmcxz\Pictures\WVIC0My\m8MPhSNWcQuWMqMN Jsf\Nq8UUEtvGokSVnkM.png.npsk | Dropped File | Stream |
Malicious
|
...
|
»
YARA Matches (1)
»
Rule Name | Rule Description | Classification | Score | Actions |
---|---|---|---|---|
DjvuEncryptedFile | File encrypted by Djvu Ransomware | Ransomware |
5/5
|
...
|
C:\Users\5p5NrGJn0jS HALPmcxz\Pictures\WVIC0My\m8MPhSNWcQuWMqMN Jsf\PLm_OXGJ-TrcTCPi9H7.png.npsk | Dropped File | Stream |
Malicious
|
...
|
»
YARA Matches (1)
»
Rule Name | Rule Description | Classification | Score | Actions |
---|---|---|---|---|
DjvuEncryptedFile | File encrypted by Djvu Ransomware | Ransomware |
5/5
|
...
|
C:\Users\5p5NrGJn0jS HALPmcxz\Pictures\WVIC0My\m8MPhSNWcQuWMqMN Jsf\qBi7VQQXKZZObkPc.png.npsk | Dropped File | Stream |
Malicious
|
...
|
»
YARA Matches (1)
»
Rule Name | Rule Description | Classification | Score | Actions |
---|---|---|---|---|
DjvuEncryptedFile | File encrypted by Djvu Ransomware | Ransomware |
5/5
|
...
|
C:\Users\5p5NrGJn0jS HALPmcxz\Music\tCN4\sg3CqdHoD\31nXcZ37 9zWspLRsh\p1Alcjoai8WuJl.mp3 | Modified File | Stream |
Malicious
|
...
|
»
YARA Matches (1)
»
Rule Name | Rule Description | Classification | Score | Actions |
---|---|---|---|---|
DjvuEncryptedFile | File encrypted by Djvu Ransomware | Ransomware |
5/5
|
...
|
C:\Users\5p5NrGJn0jS HALPmcxz\Music\tCN4\sg3CqdHoD\31nXcZ37 9zWspLRsh\qs7WTw_TT.wav.npsk | Dropped File | Stream |
Malicious
|
...
|
»
YARA Matches (1)
»
Rule Name | Rule Description | Classification | Score | Actions |
---|---|---|---|---|
DjvuEncryptedFile | File encrypted by Djvu Ransomware | Ransomware |
5/5
|
...
|
C:\Users\5p5NrGJn0jS HALPmcxz\Music\tCN4\sg3CqdHoD\31nXcZ37 9zWspLRsh\yJ2DuGZU1ek703MBkqDp.wav | Modified File | Stream |
Malicious
|
...
|
»
YARA Matches (1)
»
Rule Name | Rule Description | Classification | Score | Actions |
---|---|---|---|---|
DjvuEncryptedFile | File encrypted by Djvu Ransomware | Ransomware |
5/5
|
...
|
C:\Users\5p5NrGJn0jS HALPmcxz\Music\tCN4\sg3CqdHoD\tP3BeQ_6ct\c00aIiYACJ.wav.npsk | Dropped File | Stream |
Malicious
|
...
|
»
YARA Matches (1)
»
Rule Name | Rule Description | Classification | Score | Actions |
---|---|---|---|---|
DjvuEncryptedFile | File encrypted by Djvu Ransomware | Ransomware |
5/5
|
...
|
C:\Users\5p5NrGJn0jS HALPmcxz\Music\tCN4\sg3CqdHoD\tP3BeQ_6ct\J5dxJ6paTBfEu.mp3.npsk | Dropped File | Stream |
Malicious
|
...
|
»
YARA Matches (1)
»
Rule Name | Rule Description | Classification | Score | Actions |
---|---|---|---|---|
DjvuEncryptedFile | File encrypted by Djvu Ransomware | Ransomware |
5/5
|
...
|
C:\Users\5p5NrGJn0jS HALPmcxz\Music\tCN4\sg3CqdHoD\tP3BeQ_6ct\LamKF7giK5gdPAfbEmR9.mp3 | Modified File | Stream |
Malicious
|
...
|
»
YARA Matches (1)
»
Rule Name | Rule Description | Classification | Score | Actions |
---|---|---|---|---|
DjvuEncryptedFile | File encrypted by Djvu Ransomware | Ransomware |
5/5
|
...
|
C:\Users\5p5NrGJn0jS HALPmcxz\Music\tCN4\sg3CqdHoD\tP3BeQ_6ct\QW-82BrGFMTY.mp3 | Modified File | Stream |
Malicious
|
...
|
»
YARA Matches (1)
»
Rule Name | Rule Description | Classification | Score | Actions |
---|---|---|---|---|
DjvuEncryptedFile | File encrypted by Djvu Ransomware | Ransomware |
5/5
|
...
|
C:\Users\5p5NrGJn0jS HALPmcxz\Music\tCN4\sg3CqdHoD\tP3BeQ_6ct\rVXVsh_t_ccJVHipK.m4a | Modified File | Stream |
Malicious
|
...
|
»
YARA Matches (1)
»
Rule Name | Rule Description | Classification | Score | Actions |
---|---|---|---|---|
DjvuEncryptedFile | File encrypted by Djvu Ransomware | Ransomware |
5/5
|
...
|
C:\Users\5p5NrGJn0jS HALPmcxz\Music\tCN4\sg3CqdHoD\tP3BeQ_6ct\_Ig3Tyv.mp3 | Modified File | Stream |
Malicious
|
...
|
»
YARA Matches (1)
»
Rule Name | Rule Description | Classification | Score | Actions |
---|---|---|---|---|
DjvuEncryptedFile | File encrypted by Djvu Ransomware | Ransomware |
5/5
|
...
|
C:\Users\5p5NrGJn0jS HALPmcxz\Music\tCN4\sg3CqdHoD\xaU6e6HDu\3QWG9KFA2sO0gs-vF.mp3.npsk | Dropped File | Stream |
Malicious
|
...
|
»
YARA Matches (1)
»
Rule Name | Rule Description | Classification | Score | Actions |
---|---|---|---|---|
DjvuEncryptedFile | File encrypted by Djvu Ransomware | Ransomware |
5/5
|
...
|
C:\Users\5p5NrGJn0jS HALPmcxz\Music\tCN4\sg3CqdHoD\xaU6e6HDu\4x0dcr4Ev.mp3.npsk | Dropped File | Stream |
Malicious
|
...
|
»
YARA Matches (1)
»
Rule Name | Rule Description | Classification | Score | Actions |
---|---|---|---|---|
DjvuEncryptedFile | File encrypted by Djvu Ransomware | Ransomware |
5/5
|
...
|
C:\Users\5p5NrGJn0jS HALPmcxz\Music\tCN4\sg3CqdHoD\xaU6e6HDu\aJioNpgiVHK9ZkQfPl.wav | Modified File | Stream |
Malicious
|
...
|
»
YARA Matches (1)
»
Rule Name | Rule Description | Classification | Score | Actions |
---|---|---|---|---|
DjvuEncryptedFile | File encrypted by Djvu Ransomware | Ransomware |
5/5
|
...
|
C:\Users\5p5NrGJn0jS HALPmcxz\Music\tCN4\sg3CqdHoD\xaU6e6HDu\CJZ6k.mp3 | Modified File | Stream |
Malicious
|
...
|
»
YARA Matches (1)
»
Rule Name | Rule Description | Classification | Score | Actions |
---|---|---|---|---|
DjvuEncryptedFile | File encrypted by Djvu Ransomware | Ransomware |
5/5
|
...
|
C:\Users\5p5NrGJn0jS HALPmcxz\Music\tCN4\sg3CqdHoD\xaU6e6HDu\mwxtzhqsL3Do.m4a | Modified File | Stream |
Malicious
|
...
|
»
YARA Matches (1)
»
Rule Name | Rule Description | Classification | Score | Actions |
---|---|---|---|---|
DjvuEncryptedFile | File encrypted by Djvu Ransomware | Ransomware |
5/5
|
...
|
C:\Users\5p5NrGJn0jS HALPmcxz\AppData\LocalLow\Adobe\Acrobat\10.0\rdrmessage.zip.npsk | Dropped File | ZIP |
Malicious
|
...
|
»
YARA Matches (1)
»
Rule Name | Rule Description | Classification | Score | Actions |
---|---|---|---|---|
DjvuEncryptedFile | File encrypted by Djvu Ransomware | Ransomware |
5/5
|
...
|
C:\Users\5p5NrGJn0jS HALPmcxz\AppData\LocalLow\Microsoft\Internet Explorer\DOMStore\index.dat.npsk | Dropped File | Stream |
Malicious
|
...
|
»
YARA Matches (1)
»
Rule Name | Rule Description | Classification | Score | Actions |
---|---|---|---|---|
DjvuEncryptedFile | File encrypted by Djvu Ransomware | Ransomware |
5/5
|
...
|
C:\Users\5p5NrGJn0jS HALPmcxz\AppData\LocalLow\Sun\Java\AU\au.cab | Modified File | CAB |
Malicious
|
...
|
»
YARA Matches (1)
»
Rule Name | Rule Description | Classification | Score | Actions |
---|---|---|---|---|
DjvuEncryptedFile | File encrypted by Djvu Ransomware | Ransomware |
5/5
|
...
|
C:\Users\5p5NrGJn0jS HALPmcxz\AppData\LocalLow\Sun\Java\AU\au.msi.npsk | Dropped File | Stream |
Malicious
|
...
|
»
YARA Matches (1)
»
Rule Name | Rule Description | Classification | Score | Actions |
---|---|---|---|---|
DjvuEncryptedFile | File encrypted by Djvu Ransomware | Ransomware |
5/5
|
...
|
C:\Users\5p5NrGJn0jS HALPmcxz\AppData\LocalLow\Sun\Java\Deployment\deployment.properties.npsk | Dropped File | Stream |
Malicious
|
...
|
»
YARA Matches (1)
»
Rule Name | Rule Description | Classification | Score | Actions |
---|---|---|---|---|
DjvuEncryptedFile | File encrypted by Djvu Ransomware | Ransomware |
5/5
|
...
|
C:\Users\5p5NrGJn0jS HALPmcxz\AppData\LocalLow\Sun\Java\jre1.7.0_45\jre1.7.0_45.msi.npsk | Dropped File | Stream |
Malicious
|
...
|
»
YARA Matches (1)
»
Rule Name | Rule Description | Classification | Score | Actions |
---|---|---|---|---|
DjvuEncryptedFile | File encrypted by Djvu Ransomware | Ransomware |
5/5
|
...
|
C:\Users\5p5NrGJn0jS HALPmcxz\Music\tCN4\sg3CqdHoD\tP3BeQ_6ct\sfOvbWyBWDmisY\dBHH9jZYnjfv.m4a.npsk | Dropped File | Stream |
Malicious
|
...
|
»
YARA Matches (1)
»
Rule Name | Rule Description | Classification | Score | Actions |
---|---|---|---|---|
DjvuEncryptedFile | File encrypted by Djvu Ransomware | Ransomware |
5/5
|
...
|
C:\Users\5p5NrGJn0jS HALPmcxz\Music\tCN4\sg3CqdHoD\tP3BeQ_6ct\sfOvbWyBWDmisY\RecEOjWe9vdiSAkGI0.mp3 | Modified File | Stream |
Malicious
|
...
|
»
YARA Matches (1)
»
Rule Name | Rule Description | Classification | Score | Actions |
---|---|---|---|---|
DjvuEncryptedFile | File encrypted by Djvu Ransomware | Ransomware |
5/5
|
...
|
C:\Users\5p5NrGJn0jS HALPmcxz\Music\tCN4\sg3CqdHoD\xaU6e6HDu\pAmb2w5Ag3o\EITLtcYHkiQ_fFMPh4.mp3.npsk | Dropped File | Stream |
Malicious
|
...
|
»
YARA Matches (1)
»
Rule Name | Rule Description | Classification | Score | Actions |
---|---|---|---|---|
DjvuEncryptedFile | File encrypted by Djvu Ransomware | Ransomware |
5/5
|
...
|
C:\Users\5p5NrGJn0jS HALPmcxz\Music\tCN4\sg3CqdHoD\xaU6e6HDu\pAmb2w5Ag3o\LF6HB8B5cv.m4a.npsk | Dropped File | Stream |
Malicious
|
...
|
»
YARA Matches (1)
»
Rule Name | Rule Description | Classification | Score | Actions |
---|---|---|---|---|
DjvuEncryptedFile | File encrypted by Djvu Ransomware | Ransomware |
5/5
|
...
|
C:\Users\5p5NrGJn0jS HALPmcxz\Music\tCN4\sg3CqdHoD\xaU6e6HDu\pAmb2w5Ag3o\YzD5HiAov.wav | Modified File | Stream |
Malicious
|
...
|
»
YARA Matches (1)
»
Rule Name | Rule Description | Classification | Score | Actions |
---|---|---|---|---|
DjvuEncryptedFile | File encrypted by Djvu Ransomware | Ransomware |
5/5
|
...
|
C:\Users\5p5NrGJn0jS HALPmcxz\AppData\LocalLow\Microsoft\Internet Explorer\DOMStore\36USA68T\imagesrv.adition[1].xml.npsk | Dropped File | Stream |
Malicious
|
...
|
»
YARA Matches (1)
»
Rule Name | Rule Description | Classification | Score | Actions |
---|---|---|---|---|
DjvuEncryptedFile | File encrypted by Djvu Ransomware | Ransomware |
5/5
|
...
|
C:\Users\5p5NrGJn0jS HALPmcxz\AppData\LocalLow\Microsoft\Internet Explorer\DOMStore\3O75JDME\www.google[1].xml.npsk | Dropped File | Stream |
Malicious
|
...
|
»
YARA Matches (1)
»
Rule Name | Rule Description | Classification | Score | Actions |
---|---|---|---|---|
DjvuEncryptedFile | File encrypted by Djvu Ransomware | Ransomware |
5/5
|
...
|
C:\Users\5p5NrGJn0jS HALPmcxz\AppData\LocalLow\Microsoft\Internet Explorer\DOMStore\VGMTOI09\www.msn[1].xml.npsk | Dropped File | Stream |
Malicious
|
...
|
»
YARA Matches (1)
»
Rule Name | Rule Description | Classification | Score | Actions |
---|---|---|---|---|
DjvuEncryptedFile | File encrypted by Djvu Ransomware | Ransomware |
5/5
|
...
|
C:\Users\5p5NrGJn0jS HALPmcxz\AppData\LocalLow\Sun\Java\jre1.7.0_45\Data1.cab | Modified File | CAB |
Unknown
|
...
|
»
c:\users\5p5nrgjn0js halpmcxz\appdata\local\microsoft\windows\temporary internet files\content.ie5\index.dat | Modified File | Stream |
Unknown
|
...
|
»
c:\users\5p5nrgjn0js halpmcxz\appdata\roaming\microsoft\windows\cookies\index.dat | Modified File | Stream |
Unknown
|
...
|
»
c:\users\5p5nrgjn0js halpmcxz\appdata\local\microsoft\windows\history\history.ie5\index.dat | Modified File | Stream |
Unknown
|
...
|
»
c:\users\5p5nrgjn0js halpmcxz\appdata\roaming\microsoft\windows\ietldcache\index.dat | Modified File | Stream |
Unknown
|
...
|
»
c:\users\5p5nrgjn0js halpmcxz\appdata\local\microsoft\windows\temporary internet files\content.ie5\x9ohk109\geo[1].json | Dropped File | Text |
Unknown
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\_readme.txt | Dropped File | Text |
Unknown
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\Documents\My Shapes\Favorites.vss.npsk | Dropped File | Unknown |
Not Queried
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\AppData\Local\bowsakkdestx.txt | Downloaded File | Text |
Not Queried
|
...
|
»