Malicious
Classifications
Ransomware
Threat Names
RagnarLocker
Dynamic Analysis Report
Created on 2021-12-27T17:21:00
Ragnar_11_02_2020_40KB.exe
Windows Exe (x86-32)
Remarks (1/1)
(0x02000046): The maximum binlog size was reached. The analysis was terminated prematurely.
Remarks
(0x0200001D): The maximum number of extracted files was exceeded. Some files may be missing in the report.
This is a filtered view
This list contains only the embedded files, downloaded files, and dropped files
Filters: |
There are no files for this filter
There are no files in this analysis
File Name | Category | Type | Verdict | Actions |
---|
C:\Users\RDhJ0CNFevzX\Desktop\Ragnar_11_02_2020_40KB.exe | Sample File | Binary |
malicious
|
...
|
»
File Reputation Information
»
Verdict |
malicious
|
PE Information
»
Image Base | 0x400000 |
Entry Point | 0x4029b0 |
Size Of Code | 0x6800 |
Size Of Initialized Data | 0x3600 |
File Type | FileType.executable |
Subsystem | Subsystem.windows_gui |
Machine Type | MachineType.i386 |
Compile Timestamp | 2020-01-31 21:36:20+00:00 |
Sections (6)
»
Name | Virtual Address | Virtual Size | Raw Data Size | Raw Data Offset | Flags | Entropy |
---|---|---|---|---|---|---|
.text | 0x401000 | 0x66af | 0x6800 | 0x400 | IMAGE_SCN_CNT_CODE, IMAGE_SCN_MEM_EXECUTE, IMAGE_SCN_MEM_READ | 6.52 |
.rdata | 0x408000 | 0x1318 | 0x1400 | 0x6c00 | IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_READ | 5.35 |
.data | 0x40a000 | 0x35c | 0x0 | 0x0 | IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_READ, IMAGE_SCN_MEM_WRITE | 0.0 |
.keys | 0x40b000 | 0x1706 | 0x1800 | 0x8000 | IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_SHARED, IMAGE_SCN_MEM_EXECUTE, IMAGE_SCN_MEM_READ, IMAGE_SCN_MEM_WRITE | 6.44 |
.rsrc | 0x40d000 | 0x1e0 | 0x200 | 0x9800 | IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_READ | 4.7 |
.reloc | 0x40e000 | 0x290 | 0x400 | 0x9a00 | IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_DISCARDABLE, IMAGE_SCN_MEM_READ | 4.81 |
Imports (6)
»
KERNEL32.dll (57)
»
API Name | Ordinal | IAT Address | Thunk RVA | Thunk Offset | Hint |
---|---|---|---|---|---|
GetTickCount | - | 0x408068 | 0x8b98 | 0x7798 | 0x293 |
lstrcmpiW | - | 0x40806c | 0x8b9c | 0x779c | 0x545 |
lstrcpyA | - | 0x408070 | 0x8ba0 | 0x77a0 | 0x547 |
lstrcpyW | - | 0x408074 | 0x8ba4 | 0x77a4 | 0x548 |
lstrcatW | - | 0x408078 | 0x8ba8 | 0x77a8 | 0x53f |
lstrlenA | - | 0x40807c | 0x8bac | 0x77ac | 0x54d |
lstrlenW | - | 0x408080 | 0x8bb0 | 0x77b0 | 0x54e |
CreateEventW | - | 0x408084 | 0x8bb4 | 0x77b4 | 0x85 |
LoadLibraryW | - | 0x408088 | 0x8bb8 | 0x77b8 | 0x33f |
CreateProcessW | - | 0x40808c | 0x8bbc | 0x77bc | 0xa8 |
GetStartupInfoW | - | 0x408090 | 0x8bc0 | 0x77c0 | 0x263 |
GetDriveTypeW | - | 0x408094 | 0x8bc4 | 0x77c4 | 0x1d3 |
GetSystemDirectoryW | - | 0x408098 | 0x8bc8 | 0x77c8 | 0x270 |
GetWindowsDirectoryW | - | 0x40809c | 0x8bcc | 0x77cc | 0x2af |
GetFullPathNameW | - | 0x4080a0 | 0x8bd0 | 0x77d0 | 0x1fb |
CreateFileW | - | 0x4080a4 | 0x8bd4 | 0x77d4 | 0x8f |
SetFileAttributesW | - | 0x4080a8 | 0x8bd8 | 0x77d8 | 0x461 |
CloseHandle | - | 0x4080ac | 0x8bdc | 0x77dc | 0x52 |
FindFirstFileW | - | 0x4080b0 | 0x8be0 | 0x77e0 | 0x139 |
FindNextFileW | - | 0x4080b4 | 0x8be4 | 0x77e4 | 0x145 |
CopyFileW | - | 0x4080b8 | 0x8be8 | 0x77e8 | 0x75 |
MoveFileExW | - | 0x4080bc | 0x8bec | 0x77ec | 0x360 |
GetVolumeInformationA | - | 0x4080c0 | 0x8bf0 | 0x77f0 | 0x2a5 |
GetVolumeInformationW | - | 0x4080c4 | 0x8bf4 | 0x77f4 | 0x2a7 |
GetComputerNameW | - | 0x4080c8 | 0x8bf8 | 0x77f8 | 0x18f |
FindFirstVolumeA | - | 0x4080cc | 0x8bfc | 0x77fc | 0x13c |
FindNextVolumeA | - | 0x4080d0 | 0x8c00 | 0x7800 | 0x147 |
FindVolumeClose | - | 0x4080d4 | 0x8c04 | 0x7804 | 0x150 |
SetVolumeMountPointA | - | 0x4080d8 | 0x8c08 | 0x7808 | 0x4aa |
GetVolumePathNamesForVolumeNameA | - | 0x4080dc | 0x8c0c | 0x780c | 0x2ac |
WTSGetActiveConsoleSessionId | - | 0x4080e0 | 0x8c10 | 0x7810 | 0x4f4 |
MultiByteToWideChar | - | 0x4080e4 | 0x8c14 | 0x7814 | 0x367 |
GetLocaleInfoW | - | 0x4080e8 | 0x8c18 | 0x7818 | 0x206 |
GetNativeSystemInfo | - | 0x4080ec | 0x8c1c | 0x781c | 0x225 |
FindClose | - | 0x4080f0 | 0x8c20 | 0x7820 | 0x12e |
SetFilePointerEx | - | 0x4080f4 | 0x8c24 | 0x7824 | 0x467 |
ReadFile | - | 0x4080f8 | 0x8c28 | 0x7828 | 0x3c0 |
DeviceIoControl | - | 0x4080fc | 0x8c2c | 0x782c | 0xdd |
WriteFile | - | 0x408100 | 0x8c30 | 0x7830 | 0x525 |
GetFileSizeEx | - | 0x408104 | 0x8c34 | 0x7834 | 0x1f1 |
UnlockFile | - | 0x408108 | 0x8c38 | 0x7838 | 0x4d4 |
LockFile | - | 0x40810c | 0x8c3c | 0x783c | 0x352 |
GetLogicalDrives | - | 0x408110 | 0x8c40 | 0x7840 | 0x209 |
Sleep | - | 0x408114 | 0x8c44 | 0x7844 | 0x4b2 |
WaitForSingleObject | - | 0x408118 | 0x8c48 | 0x7848 | 0x4f9 |
GetLastError | - | 0x40811c | 0x8c4c | 0x784c | 0x202 |
TerminateProcess | - | 0x408120 | 0x8c50 | 0x7850 | 0x4c0 |
ExitProcess | - | 0x408124 | 0x8c54 | 0x7854 | 0x119 |
GetCurrentProcess | - | 0x408128 | 0x8c58 | 0x7858 | 0x1c0 |
GetProcessHeap | - | 0x40812c | 0x8c5c | 0x785c | 0x24a |
HeapFree | - | 0x408130 | 0x8c60 | 0x7860 | 0x2cf |
HeapAlloc | - | 0x408134 | 0x8c64 | 0x7864 | 0x2cb |
VirtualFree | - | 0x408138 | 0x8c68 | 0x7868 | 0x4ec |
VirtualAlloc | - | 0x40813c | 0x8c6c | 0x786c | 0x4e9 |
LocalFree | - | 0x408140 | 0x8c70 | 0x7870 | 0x348 |
GetFileAttributesW | - | 0x408144 | 0x8c74 | 0x7874 | 0x1ea |
GetProcAddress | - | 0x408148 | 0x8c78 | 0x7878 | 0x245 |
USER32.dll (2)
»
API Name | Ordinal | IAT Address | Thunk RVA | Thunk Offset | Hint |
---|---|---|---|---|---|
wsprintfA | - | 0x408168 | 0x8c98 | 0x7898 | 0x332 |
wsprintfW | - | 0x40816c | 0x8c9c | 0x789c | 0x333 |
ADVAPI32.dll (20)
»
API Name | Ordinal | IAT Address | Thunk RVA | Thunk Offset | Hint |
---|---|---|---|---|---|
CryptGenRandom | - | 0x408000 | 0x8b30 | 0x7730 | 0xc1 |
CryptReleaseContext | - | 0x408004 | 0x8b34 | 0x7734 | 0xcb |
QueryServiceStatusEx | - | 0x408008 | 0x8b38 | 0x7738 | 0x229 |
OpenServiceA | - | 0x40800c | 0x8b3c | 0x773c | 0x1fa |
OpenSCManagerA | - | 0x408010 | 0x8b40 | 0x7740 | 0x1f8 |
EnumServicesStatusA | - | 0x408014 | 0x8b44 | 0x7744 | 0xff |
EnumDependentServicesA | - | 0x408018 | 0x8b48 | 0x7748 | 0xfc |
ControlService | - | 0x40801c | 0x8b4c | 0x774c | 0x5c |
CloseServiceHandle | - | 0x408020 | 0x8b50 | 0x7750 | 0x57 |
CryptEncrypt | - | 0x408024 | 0x8b54 | 0x7754 | 0xba |
CryptDestroyKey | - | 0x408028 | 0x8b58 | 0x7758 | 0xb7 |
CryptAcquireContextW | - | 0x40802c | 0x8b5c | 0x775c | 0xb1 |
RegQueryValueExW | - | 0x408030 | 0x8b60 | 0x7760 | 0x26e |
RegOpenKeyExW | - | 0x408034 | 0x8b64 | 0x7764 | 0x261 |
RegCloseKey | - | 0x408038 | 0x8b68 | 0x7768 | 0x230 |
DuplicateTokenEx | - | 0x40803c | 0x8b6c | 0x776c | 0xdf |
CreateProcessAsUserW | - | 0x408040 | 0x8b70 | 0x7770 | 0x7c |
GetUserNameW | - | 0x408044 | 0x8b74 | 0x7774 | 0x165 |
SetTokenInformation | - | 0x408048 | 0x8b78 | 0x7778 | 0x2c2 |
OpenProcessToken | - | 0x40804c | 0x8b7c | 0x777c | 0x1f7 |
SHELL32.dll (1)
»
API Name | Ordinal | IAT Address | Thunk RVA | Thunk Offset | Hint |
---|---|---|---|---|---|
SHGetSpecialFolderPathW | - | 0x408150 | 0x8c80 | 0x7880 | 0xe1 |
SHLWAPI.dll (3)
»
API Name | Ordinal | IAT Address | Thunk RVA | Thunk Offset | Hint |
---|---|---|---|---|---|
StrStrIA | - | 0x408158 | 0x8c88 | 0x7888 | 0x144 |
PathFindExtensionW | - | 0x40815c | 0x8c8c | 0x788c | 0x47 |
StrToIntA | - | 0x408160 | 0x8c90 | 0x7890 | 0x14b |
CRYPT32.dll (4)
»
API Name | Ordinal | IAT Address | Thunk RVA | Thunk Offset | Hint |
---|---|---|---|---|---|
CryptDecodeObjectEx | - | 0x408054 | 0x8b84 | 0x7784 | 0x83 |
CryptStringToBinaryW | - | 0x408058 | 0x8b88 | 0x7788 | 0xd9 |
CryptBinaryToStringA | - | 0x40805c | 0x8b8c | 0x778c | 0x7c |
CryptImportPublicKeyInfo | - | 0x408060 | 0x8b90 | 0x7790 | 0xa4 |
Memory Dumps (5)
»
Name | Process ID | Start VA | End VA | Dump Reason | PE Rebuild | Bitness | Entry Point | YARA | Actions |
---|---|---|---|---|---|---|---|---|---|
ragnar_11_02_2020_40kb.exe | 1 | 0x00C30000 | 0x00C3EFFF | First Execution |
![]() |
32-bit | 0x00C329B0 |
![]() |
...
|
ragnar_11_02_2020_40kb.exe | 1 | 0x00C30000 | 0x00C3EFFF | Content Changed |
![]() |
32-bit | 0x00C32DA3 |
![]() |
...
|
ragnar_11_02_2020_40kb.exe | 1 | 0x00C30000 | 0x00C3EFFF | Content Changed |
![]() |
32-bit | 0x00C311B5 |
![]() |
...
|
ragnar_11_02_2020_40kb.exe | 1 | 0x00C30000 | 0x00C3EFFF | Content Changed |
![]() |
32-bit | 0x00C33000 |
![]() |
...
|
ragnar_11_02_2020_40kb.exe | 1 | 0x00C30000 | 0x00C3EFFF | Final Dump |
![]() |
32-bit | - |
![]() |
...
|
YARA Matches (1)
»
Rule Name | Rule Description | Classification | Score | Actions |
---|---|---|---|---|
RagnarLocker | RagnarLocker Ransomware | Ransomware |
5/5
|
...
|
YARA Matches (1)
»
Rule Name | Rule Description | Classification | Score | Actions |
---|---|---|---|---|
RagnarLockerEncryptedFile | File encrypted by RagnarLocker Ransomware | Ransomware |
5/5
|
...
|
\\?\C:\Program Files\Common Files\microsoft shared\ClickToRun\C2RHeartbeatConfig.xml | Modified File | Stream |
malicious
|
...
|
»
YARA Matches (1)
»
Rule Name | Rule Description | Classification | Score | Actions |
---|---|---|---|---|
RagnarLockerEncryptedFile | File encrypted by RagnarLocker Ransomware | Ransomware |
5/5
|
...
|
\\?\C:\Program Files\Common Files\microsoft shared\ClickToRun\i640.hash | Modified File | Stream |
malicious
|
...
|
»
YARA Matches (1)
»
Rule Name | Rule Description | Classification | Score | Actions |
---|---|---|---|---|
RagnarLockerEncryptedFile | File encrypted by RagnarLocker Ransomware | Ransomware |
5/5
|
...
|
\\?\C:\Program Files\Common Files\microsoft shared\ClickToRun\i641033.hash | Modified File | Stream |
malicious
|
...
|
»
YARA Matches (1)
»
Rule Name | Rule Description | Classification | Score | Actions |
---|---|---|---|---|
RagnarLockerEncryptedFile | File encrypted by RagnarLocker Ransomware | Ransomware |
5/5
|
...
|
\\?\C:\Program Files\Common Files\microsoft shared\ClickToRun\OfficeUpdateSchedule.xml | Modified File | Stream |
malicious
|
...
|
»
YARA Matches (1)
»
Rule Name | Rule Description | Classification | Score | Actions |
---|---|---|---|---|
RagnarLockerEncryptedFile | File encrypted by RagnarLocker Ransomware | Ransomware |
5/5
|
...
|
\\?\C:\Program Files\Common Files\microsoft shared\ClickToRun\ServiceWatcherSchedule.xml | Modified File | Stream |
malicious
|
...
|
»
YARA Matches (1)
»
Rule Name | Rule Description | Classification | Score | Actions |
---|---|---|---|---|
RagnarLockerEncryptedFile | File encrypted by RagnarLocker Ransomware | Ransomware |
5/5
|
...
|
\\?\C:\Program Files\Common Files\g8zbEIxadWk.bmp | Modified File | Stream |
malicious
|
...
|
»
YARA Matches (1)
»
Rule Name | Rule Description | Classification | Score | Actions |
---|---|---|---|---|
RagnarLockerEncryptedFile | File encrypted by RagnarLocker Ransomware | Ransomware |
5/5
|
...
|
\\?\C:\Program Files\Common Files\mFNPUwcV_x85.gif | Modified File | Stream |
malicious
|
...
|
»
YARA Matches (1)
»
Rule Name | Rule Description | Classification | Score | Actions |
---|---|---|---|---|
RagnarLockerEncryptedFile | File encrypted by RagnarLocker Ransomware | Ransomware |
5/5
|
...
|
\\?\C:\Program Files\Common Files\rgH4x0V6Uom.png | Modified File | Stream |
malicious
|
...
|
»
YARA Matches (1)
»
Rule Name | Rule Description | Classification | Score | Actions |
---|---|---|---|---|
RagnarLockerEncryptedFile | File encrypted by RagnarLocker Ransomware | Ransomware |
5/5
|
...
|
\\?\C:\Program Files\MSBuild\Microsoft\Windows Workflow Foundation\v3.0\Workflow.Targets | Modified File | Stream |
malicious
|
...
|
»
YARA Matches (1)
»
Rule Name | Rule Description | Classification | Score | Actions |
---|---|---|---|---|
RagnarLockerEncryptedFile | File encrypted by RagnarLocker Ransomware | Ransomware |
5/5
|
...
|
\\?\C:\Program Files\MSBuild\Microsoft\Windows Workflow Foundation\v3.0\Workflow.VisualBasic.Targets | Modified File | Stream |
malicious
|
...
|
»
YARA Matches (1)
»
Rule Name | Rule Description | Classification | Score | Actions |
---|---|---|---|---|
RagnarLockerEncryptedFile | File encrypted by RagnarLocker Ransomware | Ransomware |
5/5
|
...
|
\\?\C:\Program Files\Reference Assemblies\Microsoft\Framework\v3.0\RedistList\FrameworkList.xml | Modified File | Stream |
malicious
|
...
|
»
YARA Matches (1)
»
Rule Name | Rule Description | Classification | Score | Actions |
---|---|---|---|---|
RagnarLockerEncryptedFile | File encrypted by RagnarLocker Ransomware | Ransomware |
5/5
|
...
|
\\?\C:\Program Files\Reference Assemblies\Microsoft\Framework\v3.0\WinFXList.xml | Modified File | Stream |
malicious
|
...
|
»
YARA Matches (1)
»
Rule Name | Rule Description | Classification | Score | Actions |
---|---|---|---|---|
RagnarLockerEncryptedFile | File encrypted by RagnarLocker Ransomware | Ransomware |
5/5
|
...
|
\\?\C:\Program Files\WindowsPowerShell\Modules\PackageManagement\1.0.0.1\PackageManagement.format.ps1xml | Modified File | Stream |
malicious
|
...
|
»
YARA Matches (1)
»
Rule Name | Rule Description | Classification | Score | Actions |
---|---|---|---|---|
RagnarLockerEncryptedFile | File encrypted by RagnarLocker Ransomware | Ransomware |
5/5
|
...
|
\\?\C:\Program Files\WindowsPowerShell\Modules\PackageManagement\1.0.0.1\PackageManagement.psd1 | Modified File | Stream |
malicious
|
...
|
»
YARA Matches (1)
»
Rule Name | Rule Description | Classification | Score | Actions |
---|---|---|---|---|
RagnarLockerEncryptedFile | File encrypted by RagnarLocker Ransomware | Ransomware |
5/5
|
...
|
\\?\C:\Program Files\WindowsPowerShell\Modules\PackageManagement\1.0.0.1\PackageProviderFunctions.psm1 | Modified File | Stream |
malicious
|
...
|
»
YARA Matches (1)
»
Rule Name | Rule Description | Classification | Score | Actions |
---|---|---|---|---|
RagnarLockerEncryptedFile | File encrypted by RagnarLocker Ransomware | Ransomware |
5/5
|
...
|
\\?\C:\Program Files\WindowsPowerShell\Modules\PowerShellGet\1.0.0.1\en-US\PSGet.Resource.psd1 | Modified File | Stream |
malicious
|
...
|
»
YARA Matches (1)
»
Rule Name | Rule Description | Classification | Score | Actions |
---|---|---|---|---|
RagnarLockerEncryptedFile | File encrypted by RagnarLocker Ransomware | Ransomware |
5/5
|
...
|
\\?\C:\Program Files\WindowsPowerShell\Modules\PowerShellGet\1.0.0.1\PowerShellGet.psd1 | Modified File | Stream |
malicious
|
...
|
»
YARA Matches (1)
»
Rule Name | Rule Description | Classification | Score | Actions |
---|---|---|---|---|
RagnarLockerEncryptedFile | File encrypted by RagnarLocker Ransomware | Ransomware |
5/5
|
...
|
\\?\C:\Program Files\WindowsPowerShell\Modules\PowerShellGet\1.0.0.1\PSGet.Format.ps1xml | Modified File | Stream |
malicious
|
...
|
»
YARA Matches (1)
»
Rule Name | Rule Description | Classification | Score | Actions |
---|---|---|---|---|
RagnarLockerEncryptedFile | File encrypted by RagnarLocker Ransomware | Ransomware |
5/5
|
...
|
\\?\C:\Program Files\WindowsPowerShell\Modules\PowerShellGet\1.0.0.1\PSGet.Resource.psd1 | Modified File | Stream |
malicious
|
...
|
»
YARA Matches (1)
»
Rule Name | Rule Description | Classification | Score | Actions |
---|---|---|---|---|
RagnarLockerEncryptedFile | File encrypted by RagnarLocker Ransomware | Ransomware |
5/5
|
...
|
\\?\C:\Program Files\WindowsPowerShell\Modules\PowerShellGet\1.0.0.1\PSModule.psm1 | Modified File | Stream |
malicious
|
...
|
»
YARA Matches (1)
»
Rule Name | Rule Description | Classification | Score | Actions |
---|---|---|---|---|
RagnarLockerEncryptedFile | File encrypted by RagnarLocker Ransomware | Ransomware |
5/5
|
...
|
\\?\C:\Program Files\WindowsPowerShell\Modules\PSReadline\1.1\PSReadline.psd1 | Modified File | Stream |
malicious
|
...
|
»
YARA Matches (1)
»
Rule Name | Rule Description | Classification | Score | Actions |
---|---|---|---|---|
RagnarLockerEncryptedFile | File encrypted by RagnarLocker Ransomware | Ransomware |
5/5
|
...
|
\\?\C:\Program Files\WindowsPowerShell\Modules\PSReadline\1.1\PSReadline.psm1 | Modified File | Stream |
malicious
|
...
|
»
YARA Matches (1)
»
Rule Name | Rule Description | Classification | Score | Actions |
---|---|---|---|---|
RagnarLockerEncryptedFile | File encrypted by RagnarLocker Ransomware | Ransomware |
5/5
|
...
|
\\?\C:\Program Files (x86)\Common Files\DESIGNER\MSADDNDR.OLB | Modified File | Stream |
malicious
|
...
|
»
YARA Matches (1)
»
Rule Name | Rule Description | Classification | Score | Actions |
---|---|---|---|---|
RagnarLockerEncryptedFile | File encrypted by RagnarLocker Ransomware | Ransomware |
5/5
|
...
|
\\?\C:\Program Files (x86)\Common Files\Microsoft Shared\OFFICE16\Office Setup Controller\pkeyconfig-office.xrm-ms | Modified File | Stream |
malicious
|
...
|
»
YARA Matches (1)
»
Rule Name | Rule Description | Classification | Score | Actions |
---|---|---|---|---|
RagnarLockerEncryptedFile | File encrypted by RagnarLocker Ransomware | Ransomware |
5/5
|
...
|
\\?\C:\Program Files (x86)\Common Files\Microsoft Shared\VSTA\AppInfoDocument\AddIns.store | Modified File | Stream |
malicious
|
...
|
»
YARA Matches (1)
»
Rule Name | Rule Description | Classification | Score | Actions |
---|---|---|---|---|
RagnarLockerEncryptedFile | File encrypted by RagnarLocker Ransomware | Ransomware |
5/5
|
...
|
\\?\C:\Program Files (x86)\Common Files\Microsoft Shared\VSTA\Pipeline.v10.0\PipelineSegments.store | Modified File | Stream |
malicious
|
...
|
»
YARA Matches (1)
»
Rule Name | Rule Description | Classification | Score | Actions |
---|---|---|---|---|
RagnarLockerEncryptedFile | File encrypted by RagnarLocker Ransomware | Ransomware |
5/5
|
...
|
\\?\C:\Program Files (x86)\Common Files\Microsoft Shared\VSTA\VSTOFiles.cat | Modified File | Stream |
malicious
|
...
|
»
YARA Matches (1)
»
Rule Name | Rule Description | Classification | Score | Actions |
---|---|---|---|---|
RagnarLockerEncryptedFile | File encrypted by RagnarLocker Ransomware | Ransomware |
5/5
|
...
|
\\?\C:\Program Files (x86)\Common Files\Microsoft Shared\VSTO\ActionsPane3.xsd | Modified File | Stream |
malicious
|
...
|
»
YARA Matches (1)
»
Rule Name | Rule Description | Classification | Score | Actions |
---|---|---|---|---|
RagnarLockerEncryptedFile | File encrypted by RagnarLocker Ransomware | Ransomware |
5/5
|
...
|
\\?\C:\Program Files (x86)\Common Files\Microsoft Shared\VSTO\vstoee100.tlb | Modified File | Stream |
malicious
|
...
|
»
YARA Matches (1)
»
Rule Name | Rule Description | Classification | Score | Actions |
---|---|---|---|---|
RagnarLockerEncryptedFile | File encrypted by RagnarLocker Ransomware | Ransomware |
5/5
|
...
|
\\?\C:\Program Files (x86)\Common Files\Microsoft Shared\VSTO\vstoee90.tlb | Modified File | Stream |
malicious
|
...
|
»
YARA Matches (1)
»
Rule Name | Rule Description | Classification | Score | Actions |
---|---|---|---|---|
RagnarLockerEncryptedFile | File encrypted by RagnarLocker Ransomware | Ransomware |
5/5
|
...
|
\\?\C:\Program Files (x86)\Microsoft Office\Office16\OSPP.HTM | Modified File | Stream |
malicious
|
...
|
»
YARA Matches (1)
»
Rule Name | Rule Description | Classification | Score | Actions |
---|---|---|---|---|
RagnarLockerEncryptedFile | File encrypted by RagnarLocker Ransomware | Ransomware |
5/5
|
...
|
\\?\C:\Program Files (x86)\Microsoft Office\Office16\OSPP.VBS | Modified File | Stream |
malicious
|
...
|
»
YARA Matches (1)
»
Rule Name | Rule Description | Classification | Score | Actions |
---|---|---|---|---|
RagnarLockerEncryptedFile | File encrypted by RagnarLocker Ransomware | Ransomware |
5/5
|
...
|
\\?\C:\Program Files (x86)\Microsoft Office\PackageManifests\AppXManifest.90160000-0015-0000-0000-0000000FF1CE.xml | Modified File | Stream |
malicious
|
...
|
»
YARA Matches (1)
»
Rule Name | Rule Description | Classification | Score | Actions |
---|---|---|---|---|
RagnarLockerEncryptedFile | File encrypted by RagnarLocker Ransomware | Ransomware |
5/5
|
...
|
\\?\C:\Program Files (x86)\Microsoft Office\PackageManifests\AppXManifest.90160000-0015-0409-0000-0000000FF1CE.xml | Modified File | Stream |
malicious
|
...
|
»
YARA Matches (1)
»
Rule Name | Rule Description | Classification | Score | Actions |
---|---|---|---|---|
RagnarLockerEncryptedFile | File encrypted by RagnarLocker Ransomware | Ransomware |
5/5
|
...
|
\\?\C:\Program Files (x86)\Microsoft Office\PackageManifests\AppXManifest.90160000-0016-0000-0000-0000000FF1CE.xml | Modified File | Stream |
malicious
|
...
|
»
YARA Matches (1)
»
Rule Name | Rule Description | Classification | Score | Actions |
---|---|---|---|---|
RagnarLockerEncryptedFile | File encrypted by RagnarLocker Ransomware | Ransomware |
5/5
|
...
|
\\?\C:\Program Files (x86)\Microsoft Office\PackageManifests\AppXManifest.90160000-0016-0409-0000-0000000FF1CE.xml | Modified File | Stream |
malicious
|
...
|
»
YARA Matches (1)
»
Rule Name | Rule Description | Classification | Score | Actions |
---|---|---|---|---|
RagnarLockerEncryptedFile | File encrypted by RagnarLocker Ransomware | Ransomware |
5/5
|
...
|
\\?\C:\Program Files (x86)\Microsoft Office\PackageManifests\AppXManifest.90160000-0018-0000-0000-0000000FF1CE.xml | Modified File | Stream |
malicious
|
...
|
»
YARA Matches (1)
»
Rule Name | Rule Description | Classification | Score | Actions |
---|---|---|---|---|
RagnarLockerEncryptedFile | File encrypted by RagnarLocker Ransomware | Ransomware |
5/5
|
...
|
\\?\C:\Program Files (x86)\Microsoft Office\PackageManifests\AppXManifest.90160000-0018-0409-0000-0000000FF1CE.xml | Modified File | Stream |
malicious
|
...
|
»
YARA Matches (1)
»
Rule Name | Rule Description | Classification | Score | Actions |
---|---|---|---|---|
RagnarLockerEncryptedFile | File encrypted by RagnarLocker Ransomware | Ransomware |
5/5
|
...
|
\\?\C:\Program Files (x86)\Microsoft Office\PackageManifests\AppXManifest.90160000-0019-0000-0000-0000000FF1CE.xml | Modified File | Stream |
malicious
|
...
|
»
YARA Matches (1)
»
Rule Name | Rule Description | Classification | Score | Actions |
---|---|---|---|---|
RagnarLockerEncryptedFile | File encrypted by RagnarLocker Ransomware | Ransomware |
5/5
|
...
|
\\?\C:\Program Files (x86)\Microsoft Office\PackageManifests\AppXManifest.90160000-0019-0409-0000-0000000FF1CE.xml | Modified File | Stream |
malicious
|
...
|
»
YARA Matches (1)
»
Rule Name | Rule Description | Classification | Score | Actions |
---|---|---|---|---|
RagnarLockerEncryptedFile | File encrypted by RagnarLocker Ransomware | Ransomware |
5/5
|
...
|
\\?\C:\Program Files (x86)\Microsoft Office\PackageManifests\AppXManifest.90160000-001A-0000-0000-0000000FF1CE.xml | Modified File | Stream |
malicious
|
...
|
»
YARA Matches (1)
»
Rule Name | Rule Description | Classification | Score | Actions |
---|---|---|---|---|
RagnarLockerEncryptedFile | File encrypted by RagnarLocker Ransomware | Ransomware |
5/5
|
...
|
\\?\C:\Program Files (x86)\Microsoft Office\PackageManifests\AppXManifest.90160000-001A-0409-0000-0000000FF1CE.xml | Modified File | Stream |
malicious
|
...
|
»
YARA Matches (1)
»
Rule Name | Rule Description | Classification | Score | Actions |
---|---|---|---|---|
RagnarLockerEncryptedFile | File encrypted by RagnarLocker Ransomware | Ransomware |
5/5
|
...
|
\\?\C:\Program Files (x86)\Microsoft Office\PackageManifests\AppXManifest.90160000-001B-0000-0000-0000000FF1CE.xml | Modified File | Stream |
malicious
|
...
|
»
YARA Matches (1)
»
Rule Name | Rule Description | Classification | Score | Actions |
---|---|---|---|---|
RagnarLockerEncryptedFile | File encrypted by RagnarLocker Ransomware | Ransomware |
5/5
|
...
|
\\?\C:\Program Files (x86)\Microsoft Office\PackageManifests\AppXManifest.90160000-001B-0409-0000-0000000FF1CE.xml | Modified File | Stream |
malicious
|
...
|
»
YARA Matches (1)
»
Rule Name | Rule Description | Classification | Score | Actions |
---|---|---|---|---|
RagnarLockerEncryptedFile | File encrypted by RagnarLocker Ransomware | Ransomware |
5/5
|
...
|
\\?\C:\Program Files (x86)\Microsoft Office\PackageManifests\AppXManifest.90160000-001F-0409-0000-0000000FF1CE.xml | Modified File | Stream |
malicious
|
...
|
»
YARA Matches (1)
»
Rule Name | Rule Description | Classification | Score | Actions |
---|---|---|---|---|
RagnarLockerEncryptedFile | File encrypted by RagnarLocker Ransomware | Ransomware |
5/5
|
...
|
\\?\C:\Program Files (x86)\Microsoft Office\PackageManifests\AppXManifest.90160000-001F-040C-0000-0000000FF1CE.xml | Modified File | Stream |
malicious
|
...
|
»
YARA Matches (1)
»
Rule Name | Rule Description | Classification | Score | Actions |
---|---|---|---|---|
RagnarLockerEncryptedFile | File encrypted by RagnarLocker Ransomware | Ransomware |
5/5
|
...
|
\\?\C:\Program Files (x86)\Microsoft Office\PackageManifests\AppXManifest.90160000-001F-0C0A-0000-0000000FF1CE.xml | Modified File | Stream |
malicious
|
...
|
»
YARA Matches (1)
»
Rule Name | Rule Description | Classification | Score | Actions |
---|---|---|---|---|
RagnarLockerEncryptedFile | File encrypted by RagnarLocker Ransomware | Ransomware |
5/5
|
...
|
\\?\C:\Program Files (x86)\Microsoft Office\PackageManifests\AppXManifest.90160000-002A-0000-1000-0000000FF1CE.xml | Modified File | Stream |
malicious
|
...
|
»
YARA Matches (1)
»
Rule Name | Rule Description | Classification | Score | Actions |
---|---|---|---|---|
RagnarLockerEncryptedFile | File encrypted by RagnarLocker Ransomware | Ransomware |
5/5
|
...
|
\\?\C:\Program Files (x86)\Microsoft Office\PackageManifests\AppXManifest.90160000-002A-0409-1000-0000000FF1CE.xml | Modified File | Stream |
malicious
|
...
|
»
YARA Matches (1)
»
Rule Name | Rule Description | Classification | Score | Actions |
---|---|---|---|---|
RagnarLockerEncryptedFile | File encrypted by RagnarLocker Ransomware | Ransomware |
5/5
|
...
|
\\?\C:\Program Files (x86)\Microsoft Office\PackageManifests\AppXManifest.90160000-002C-0409-0000-0000000FF1CE.xml | Modified File | Stream |
malicious
|
...
|
»
YARA Matches (1)
»
Rule Name | Rule Description | Classification | Score | Actions |
---|---|---|---|---|
RagnarLockerEncryptedFile | File encrypted by RagnarLocker Ransomware | Ransomware |
5/5
|
...
|
\\?\C:\Program Files (x86)\Microsoft Office\PackageManifests\AppXManifest.90160000-006E-0409-0000-0000000FF1CE.xml | Modified File | Stream |
malicious
|
...
|
»
YARA Matches (1)
»
Rule Name | Rule Description | Classification | Score | Actions |
---|---|---|---|---|
RagnarLockerEncryptedFile | File encrypted by RagnarLocker Ransomware | Ransomware |
5/5
|
...
|
\\?\C:\Program Files (x86)\Microsoft Office\PackageManifests\AppXManifest.90160000-0090-0000-0000-0000000FF1CE.xml | Modified File | Stream |
malicious
|
...
|
»
YARA Matches (1)
»
Rule Name | Rule Description | Classification | Score | Actions |
---|---|---|---|---|
RagnarLockerEncryptedFile | File encrypted by RagnarLocker Ransomware | Ransomware |
5/5
|
...
|
\\?\C:\Program Files (x86)\Microsoft Office\PackageManifests\AppXManifest.90160000-0090-0409-0000-0000000FF1CE.xml | Modified File | Stream |
malicious
|
...
|
»
YARA Matches (1)
»
Rule Name | Rule Description | Classification | Score | Actions |
---|---|---|---|---|
RagnarLockerEncryptedFile | File encrypted by RagnarLocker Ransomware | Ransomware |
5/5
|
...
|
\\?\C:\Program Files (x86)\Microsoft Office\PackageManifests\AppXManifest.90160000-00A1-0000-0000-0000000FF1CE.xml | Modified File | Stream |
malicious
|
...
|
»
YARA Matches (1)
»
Rule Name | Rule Description | Classification | Score | Actions |
---|---|---|---|---|
RagnarLockerEncryptedFile | File encrypted by RagnarLocker Ransomware | Ransomware |
5/5
|
...
|
\\?\C:\Program Files (x86)\Microsoft Office\PackageManifests\AppXManifest.90160000-00A1-0409-0000-0000000FF1CE.xml | Modified File | Stream |
malicious
|
...
|
»
YARA Matches (1)
»
Rule Name | Rule Description | Classification | Score | Actions |
---|---|---|---|---|
RagnarLockerEncryptedFile | File encrypted by RagnarLocker Ransomware | Ransomware |
5/5
|
...
|
\\?\C:\Program Files (x86)\Microsoft Office\PackageManifests\AppXManifest.90160000-00BA-0000-0000-0000000FF1CE.xml | Modified File | Stream |
malicious
|
...
|
»
YARA Matches (1)
»
Rule Name | Rule Description | Classification | Score | Actions |
---|---|---|---|---|
RagnarLockerEncryptedFile | File encrypted by RagnarLocker Ransomware | Ransomware |
5/5
|
...
|
\\?\C:\Program Files (x86)\Microsoft Office\PackageManifests\AppXManifest.90160000-00BA-0409-0000-0000000FF1CE.xml | Modified File | Stream |
malicious
|
...
|
»
YARA Matches (1)
»
Rule Name | Rule Description | Classification | Score | Actions |
---|---|---|---|---|
RagnarLockerEncryptedFile | File encrypted by RagnarLocker Ransomware | Ransomware |
5/5
|
...
|
\\?\C:\Program Files (x86)\Microsoft Office\PackageManifests\AppXManifest.90160000-00E1-0000-0000-0000000FF1CE.xml | Modified File | Stream |
malicious
|
...
|
»
YARA Matches (1)
»
Rule Name | Rule Description | Classification | Score | Actions |
---|---|---|---|---|
RagnarLockerEncryptedFile | File encrypted by RagnarLocker Ransomware | Ransomware |
5/5
|
...
|
\\?\C:\Program Files (x86)\Microsoft Office\PackageManifests\AppXManifest.90160000-00E1-0409-0000-0000000FF1CE.xml | Modified File | Stream |
malicious
|
...
|
»
YARA Matches (1)
»
Rule Name | Rule Description | Classification | Score | Actions |
---|---|---|---|---|
RagnarLockerEncryptedFile | File encrypted by RagnarLocker Ransomware | Ransomware |
5/5
|
...
|
\\?\C:\Program Files (x86)\Microsoft Office\PackageManifests\AppXManifest.90160000-00E2-0000-0000-0000000FF1CE.xml | Modified File | Stream |
malicious
|
...
|
»
YARA Matches (1)
»
Rule Name | Rule Description | Classification | Score | Actions |
---|---|---|---|---|
RagnarLockerEncryptedFile | File encrypted by RagnarLocker Ransomware | Ransomware |
5/5
|
...
|
\\?\C:\Program Files (x86)\Microsoft Office\PackageManifests\AppXManifest.90160000-00E2-0409-0000-0000000FF1CE.xml | Modified File | Stream |
malicious
|
...
|
»
YARA Matches (1)
»
Rule Name | Rule Description | Classification | Score | Actions |
---|---|---|---|---|
RagnarLockerEncryptedFile | File encrypted by RagnarLocker Ransomware | Ransomware |
5/5
|
...
|
\\?\C:\Program Files (x86)\Microsoft Office\PackageManifests\AppXManifest.90160000-0115-0409-0000-0000000FF1CE.xml | Modified File | Stream |
malicious
|
...
|
»
YARA Matches (1)
»
Rule Name | Rule Description | Classification | Score | Actions |
---|---|---|---|---|
RagnarLockerEncryptedFile | File encrypted by RagnarLocker Ransomware | Ransomware |
5/5
|
...
|
\\?\C:\Program Files (x86)\Microsoft Office\PackageManifests\AppXManifest.90160000-0116-0409-1000-0000000FF1CE.xml | Modified File | Stream |
malicious
|
...
|
»
YARA Matches (1)
»
Rule Name | Rule Description | Classification | Score | Actions |
---|---|---|---|---|
RagnarLockerEncryptedFile | File encrypted by RagnarLocker Ransomware | Ransomware |
5/5
|
...
|
\\?\C:\Program Files (x86)\Microsoft Office\PackageManifests\AppXManifest.90160000-0117-0409-0000-0000000FF1CE.xml | Modified File | Stream |
malicious
|
...
|
»
YARA Matches (1)
»
Rule Name | Rule Description | Classification | Score | Actions |
---|---|---|---|---|
RagnarLockerEncryptedFile | File encrypted by RagnarLocker Ransomware | Ransomware |
5/5
|
...
|
\\?\C:\Program Files (x86)\Microsoft Office\PackageManifests\AppXManifest.90160000-012A-0000-0000-0000000FF1CE.xml | Modified File | Stream |
malicious
|
...
|
»
YARA Matches (1)
»
Rule Name | Rule Description | Classification | Score | Actions |
---|---|---|---|---|
RagnarLockerEncryptedFile | File encrypted by RagnarLocker Ransomware | Ransomware |
5/5
|
...
|
\\?\C:\Program Files (x86)\Microsoft Office\PackageManifests\AppXManifest.90160000-012B-0409-0000-0000000FF1CE.xml | Modified File | Stream |
malicious
|
...
|
»
YARA Matches (1)
»
Rule Name | Rule Description | Classification | Score | Actions |
---|---|---|---|---|
RagnarLockerEncryptedFile | File encrypted by RagnarLocker Ransomware | Ransomware |
5/5
|
...
|
\\?\C:\Program Files (x86)\Microsoft Office\PackageManifests\AppXManifest.90160000-3101-0000-0000-0000000FF1CE.xml | Modified File | Stream |
malicious
|
...
|
»
YARA Matches (1)
»
Rule Name | Rule Description | Classification | Score | Actions |
---|---|---|---|---|
RagnarLockerEncryptedFile | File encrypted by RagnarLocker Ransomware | Ransomware |
5/5
|
...
|
\\?\C:\Program Files (x86)\Microsoft Office\PackageManifests\AppXManifest.common.xml | Modified File | Stream |
malicious
|
...
|
»
YARA Matches (1)
»
Rule Name | Rule Description | Classification | Score | Actions |
---|---|---|---|---|
RagnarLockerEncryptedFile | File encrypted by RagnarLocker Ransomware | Ransomware |
5/5
|
...
|
\\?\C:\Program Files (x86)\Microsoft Office\PackageManifests\AppXManifestLoc.en-us.xml | Modified File | Stream |
malicious
|
...
|
»
YARA Matches (1)
»
Rule Name | Rule Description | Classification | Score | Actions |
---|---|---|---|---|
RagnarLockerEncryptedFile | File encrypted by RagnarLocker Ransomware | Ransomware |
5/5
|
...
|
\\?\C:\Program Files (x86)\Microsoft Office\PackageManifests\AuthoredExtensions.xml | Modified File | Stream |
malicious
|
...
|
»
YARA Matches (1)
»
Rule Name | Rule Description | Classification | Score | Actions |
---|---|---|---|---|
RagnarLockerEncryptedFile | File encrypted by RagnarLocker Ransomware | Ransomware |
5/5
|
...
|
\\?\C:\Program Files (x86)\Microsoft Office\root\CLIPART\PUB60COR\AG00004_.GIF | Modified File | Stream |
malicious
|
...
|
»
YARA Matches (1)
»
Rule Name | Rule Description | Classification | Score | Actions |
---|---|---|---|---|
RagnarLockerEncryptedFile | File encrypted by RagnarLocker Ransomware | Ransomware |
5/5
|
...
|
\\?\C:\Program Files (x86)\Microsoft Office\root\CLIPART\PUB60COR\AG00011_.GIF | Modified File | Stream |
malicious
|
...
|
»
YARA Matches (1)
»
Rule Name | Rule Description | Classification | Score | Actions |
---|---|---|---|---|
RagnarLockerEncryptedFile | File encrypted by RagnarLocker Ransomware | Ransomware |
5/5
|
...
|
\\?\C:\Program Files (x86)\Microsoft Office\root\CLIPART\PUB60COR\AG00021_.GIF | Modified File | Stream |
malicious
|
...
|
»
YARA Matches (1)
»
Rule Name | Rule Description | Classification | Score | Actions |
---|---|---|---|---|
RagnarLockerEncryptedFile | File encrypted by RagnarLocker Ransomware | Ransomware |
5/5
|
...
|
\\?\C:\Program Files (x86)\Microsoft Office\root\CLIPART\PUB60COR\AG00037_.GIF | Modified File | Stream |
malicious
|
...
|
»
YARA Matches (1)
»
Rule Name | Rule Description | Classification | Score | Actions |
---|---|---|---|---|
RagnarLockerEncryptedFile | File encrypted by RagnarLocker Ransomware | Ransomware |
5/5
|
...
|
\\?\C:\Program Files (x86)\Microsoft Office\root\CLIPART\PUB60COR\AG00038_.GIF | Modified File | Stream |
malicious
|
...
|
»
YARA Matches (1)
»
Rule Name | Rule Description | Classification | Score | Actions |
---|---|---|---|---|
RagnarLockerEncryptedFile | File encrypted by RagnarLocker Ransomware | Ransomware |
5/5
|
...
|
\\?\C:\Program Files (x86)\Microsoft Office\root\CLIPART\PUB60COR\AG00040_.GIF | Modified File | Stream |
malicious
|
...
|
»
YARA Matches (1)
»
Rule Name | Rule Description | Classification | Score | Actions |
---|---|---|---|---|
RagnarLockerEncryptedFile | File encrypted by RagnarLocker Ransomware | Ransomware |
5/5
|
...
|
\\?\C:\Program Files (x86)\Microsoft Office\root\CLIPART\PUB60COR\AG00052_.GIF | Modified File | Stream |
malicious
|
...
|
»
YARA Matches (1)
»
Rule Name | Rule Description | Classification | Score | Actions |
---|---|---|---|---|
RagnarLockerEncryptedFile | File encrypted by RagnarLocker Ransomware | Ransomware |
5/5
|
...
|
\\?\C:\Program Files (x86)\Microsoft Office\root\CLIPART\PUB60COR\AG00057_.GIF | Modified File | Stream |
malicious
|
...
|
»
YARA Matches (1)
»
Rule Name | Rule Description | Classification | Score | Actions |
---|---|---|---|---|
RagnarLockerEncryptedFile | File encrypted by RagnarLocker Ransomware | Ransomware |
5/5
|
...
|
\\?\C:\Program Files (x86)\Microsoft Office\root\CLIPART\PUB60COR\AG00090_.GIF | Modified File | Stream |
malicious
|
...
|
»
YARA Matches (1)
»
Rule Name | Rule Description | Classification | Score | Actions |
---|---|---|---|---|
RagnarLockerEncryptedFile | File encrypted by RagnarLocker Ransomware | Ransomware |
5/5
|
...
|
\\?\C:\Program Files (x86)\Microsoft Office\root\CLIPART\PUB60COR\AG00092_.GIF | Modified File | Stream |
malicious
|
...
|
»
YARA Matches (1)
»
Rule Name | Rule Description | Classification | Score | Actions |
---|---|---|---|---|
RagnarLockerEncryptedFile | File encrypted by RagnarLocker Ransomware | Ransomware |
5/5
|
...
|
\\?\C:\Program Files (x86)\Microsoft Office\root\CLIPART\PUB60COR\AG00103_.GIF | Modified File | Stream |
malicious
|
...
|
»
YARA Matches (1)
»
Rule Name | Rule Description | Classification | Score | Actions |
---|---|---|---|---|
RagnarLockerEncryptedFile | File encrypted by RagnarLocker Ransomware | Ransomware |
5/5
|
...
|
\\?\C:\Program Files (x86)\Microsoft Office\root\CLIPART\PUB60COR\AG00120_.GIF | Modified File | Stream |
malicious
|
...
|
»
YARA Matches (1)
»
Rule Name | Rule Description | Classification | Score | Actions |
---|---|---|---|---|
RagnarLockerEncryptedFile | File encrypted by RagnarLocker Ransomware | Ransomware |
5/5
|
...
|
\\?\C:\Program Files (x86)\Microsoft Office\root\CLIPART\PUB60COR\AG00126_.GIF | Modified File | Stream |
malicious
|
...
|
»
YARA Matches (1)
»
Rule Name | Rule Description | Classification | Score | Actions |
---|---|---|---|---|
RagnarLockerEncryptedFile | File encrypted by RagnarLocker Ransomware | Ransomware |
5/5
|
...
|
\\?\C:\Program Files (x86)\Microsoft Office\root\CLIPART\PUB60COR\AG00129_.GIF | Modified File | Stream |
malicious
|
...
|
»
YARA Matches (1)
»
Rule Name | Rule Description | Classification | Score | Actions |
---|---|---|---|---|
RagnarLockerEncryptedFile | File encrypted by RagnarLocker Ransomware | Ransomware |
5/5
|
...
|
\\?\C:\Program Files (x86)\Microsoft Office\root\CLIPART\PUB60COR\AG00130_.GIF | Modified File | Stream |
malicious
|
...
|
»
YARA Matches (1)
»
Rule Name | Rule Description | Classification | Score | Actions |
---|---|---|---|---|
RagnarLockerEncryptedFile | File encrypted by RagnarLocker Ransomware | Ransomware |
5/5
|
...
|
\\?\C:\Program Files (x86)\Microsoft Office\root\CLIPART\PUB60COR\AG00135_.GIF | Modified File | Stream |
malicious
|
...
|
»
YARA Matches (1)
»
Rule Name | Rule Description | Classification | Score | Actions |
---|---|---|---|---|
RagnarLockerEncryptedFile | File encrypted by RagnarLocker Ransomware | Ransomware |
5/5
|
...
|
\\?\C:\Program Files (x86)\Microsoft Office\root\CLIPART\PUB60COR\AG00139_.GIF | Modified File | Stream |
malicious
|
...
|
»
YARA Matches (1)
»
Rule Name | Rule Description | Classification | Score | Actions |
---|---|---|---|---|
RagnarLockerEncryptedFile | File encrypted by RagnarLocker Ransomware | Ransomware |
5/5
|
...
|
\\?\C:\Program Files (x86)\Microsoft Office\root\CLIPART\PUB60COR\AG00142_.GIF | Modified File | Stream |
malicious
|
...
|
»
YARA Matches (1)
»
Rule Name | Rule Description | Classification | Score | Actions |
---|---|---|---|---|
RagnarLockerEncryptedFile | File encrypted by RagnarLocker Ransomware | Ransomware |
5/5
|
...
|
\\?\C:\Program Files (x86)\Microsoft Office\root\CLIPART\PUB60COR\AG00154_.GIF | Modified File | Stream |
malicious
|
...
|
»
YARA Matches (1)
»
Rule Name | Rule Description | Classification | Score | Actions |
---|---|---|---|---|
RagnarLockerEncryptedFile | File encrypted by RagnarLocker Ransomware | Ransomware |
5/5
|
...
|
\\?\C:\Program Files (x86)\Microsoft Office\root\CLIPART\PUB60COR\AG00157_.GIF | Modified File | Stream |
malicious
|
...
|
»
YARA Matches (1)
»
Rule Name | Rule Description | Classification | Score | Actions |
---|---|---|---|---|
RagnarLockerEncryptedFile | File encrypted by RagnarLocker Ransomware | Ransomware |
5/5
|
...
|
\\?\C:\Program Files (x86)\Microsoft Office\root\CLIPART\PUB60COR\AG00158_.GIF | Modified File | Stream |
malicious
|
...
|
»
YARA Matches (1)
»
Rule Name | Rule Description | Classification | Score | Actions |
---|---|---|---|---|
RagnarLockerEncryptedFile | File encrypted by RagnarLocker Ransomware | Ransomware |
5/5
|
...
|
\\?\C:\Program Files (x86)\Microsoft Office\root\CLIPART\PUB60COR\AG00160_.GIF | Modified File | Stream |
malicious
|
...
|
»
YARA Matches (1)
»
Rule Name | Rule Description | Classification | Score | Actions |
---|---|---|---|---|
RagnarLockerEncryptedFile | File encrypted by RagnarLocker Ransomware | Ransomware |
5/5
|
...
|
\\?\C:\Program Files (x86)\Microsoft Office\root\CLIPART\PUB60COR\AG00161_.GIF | Modified File | Stream |
malicious
|
...
|
»
YARA Matches (1)
»
Rule Name | Rule Description | Classification | Score | Actions |
---|---|---|---|---|
RagnarLockerEncryptedFile | File encrypted by RagnarLocker Ransomware | Ransomware |
5/5
|
...
|
\\?\C:\Program Files (x86)\Microsoft Office\root\CLIPART\PUB60COR\AG00163_.GIF | Modified File | Stream |
malicious
|
...
|
»
YARA Matches (1)
»
Rule Name | Rule Description | Classification | Score | Actions |
---|---|---|---|---|
RagnarLockerEncryptedFile | File encrypted by RagnarLocker Ransomware | Ransomware |
5/5
|
...
|
\\?\C:\Program Files (x86)\Microsoft Office\root\CLIPART\PUB60COR\AG00164_.GIF | Modified File | Stream |
malicious
|
...
|
»
YARA Matches (1)
»
Rule Name | Rule Description | Classification | Score | Actions |
---|---|---|---|---|
RagnarLockerEncryptedFile | File encrypted by RagnarLocker Ransomware | Ransomware |
5/5
|
...
|
\\?\C:\Program Files (x86)\Microsoft Office\root\CLIPART\PUB60COR\AG00165_.GIF | Modified File | Stream |
malicious
|
...
|
»
YARA Matches (1)
»
Rule Name | Rule Description | Classification | Score | Actions |
---|---|---|---|---|
RagnarLockerEncryptedFile | File encrypted by RagnarLocker Ransomware | Ransomware |
5/5
|
...
|
\\?\C:\Program Files (x86)\Microsoft Office\root\CLIPART\PUB60COR\AG00167_.GIF | Modified File | Stream |
malicious
|
...
|
»
YARA Matches (1)
»
Rule Name | Rule Description | Classification | Score | Actions |
---|---|---|---|---|
RagnarLockerEncryptedFile | File encrypted by RagnarLocker Ransomware | Ransomware |
5/5
|
...
|
\\?\C:\Program Files (x86)\Microsoft Office\root\CLIPART\PUB60COR\AG00169_.GIF | Modified File | Stream |
malicious
|
...
|
»
YARA Matches (1)
»
Rule Name | Rule Description | Classification | Score | Actions |
---|---|---|---|---|
RagnarLockerEncryptedFile | File encrypted by RagnarLocker Ransomware | Ransomware |
5/5
|
...
|
\\?\C:\Program Files (x86)\Microsoft Office\Office16\SLERROR.XML | Modified File | Stream |
clean
|
...
|
»
\\?\C:\Program Files (x86)\Microsoft Office\root\CLIPART\PUB60COR\AG00170_.GIF | Modified File | Stream |
clean
|
...
|
»
YARA Matches (1)
»
Rule Name | Rule Description | Classification | Score | Actions |
---|---|---|---|---|
RagnarLockerEncryptedFile | File encrypted by RagnarLocker Ransomware | Ransomware |
5/5
|
...
|
\\?\C:\Program Files (x86)\Microsoft Office\root\CLIPART\PUB60COR\AG00171_.GIF | Modified File | Stream |
clean
|
...
|
»
YARA Matches (1)
»
Rule Name | Rule Description | Classification | Score | Actions |
---|---|---|---|---|
RagnarLockerEncryptedFile | File encrypted by RagnarLocker Ransomware | Ransomware |
5/5
|
...
|
\\?\C:\Program Files (x86)\Microsoft Office\root\CLIPART\PUB60COR\AG00172_.GIF | Modified File | Stream |
clean
|
...
|
»
YARA Matches (1)
»
Rule Name | Rule Description | Classification | Score | Actions |
---|---|---|---|---|
RagnarLockerEncryptedFile | File encrypted by RagnarLocker Ransomware | Ransomware |
5/5
|
...
|
\\?\C:\Program Files (x86)\Microsoft Office\root\CLIPART\PUB60COR\AG00174_.GIF | Modified File | Stream |
clean
|
...
|
»
YARA Matches (1)
»
Rule Name | Rule Description | Classification | Score | Actions |
---|---|---|---|---|
RagnarLockerEncryptedFile | File encrypted by RagnarLocker Ransomware | Ransomware |
5/5
|
...
|
\\?\C:\Program Files (x86)\Microsoft Office\root\CLIPART\PUB60COR\AG00175_.GIF | Modified File | Stream |
clean
|
...
|
»
YARA Matches (1)
»
Rule Name | Rule Description | Classification | Score | Actions |
---|---|---|---|---|
RagnarLockerEncryptedFile | File encrypted by RagnarLocker Ransomware | Ransomware |
5/5
|
...
|
\\?\C:\Program Files (x86)\Microsoft Office\root\CLIPART\PUB60COR\AG00176_.GIF | Modified File | Stream |
clean
|
...
|
»
YARA Matches (1)
»
Rule Name | Rule Description | Classification | Score | Actions |
---|---|---|---|---|
RagnarLockerEncryptedFile | File encrypted by RagnarLocker Ransomware | Ransomware |
5/5
|
...
|
\\?\C:\Program Files (x86)\Microsoft Office\root\CLIPART\PUB60COR\AN00010_.WMF | Modified File | Stream |
clean
|
...
|
»
YARA Matches (1)
»
Rule Name | Rule Description | Classification | Score | Actions |
---|---|---|---|---|
RagnarLockerEncryptedFile | File encrypted by RagnarLocker Ransomware | Ransomware |
5/5
|
...
|
\\?\C:\Program Files (x86)\Microsoft Office\root\CLIPART\PUB60COR\AN00015_.WMF | Modified File | Stream |
clean
|
...
|
»
YARA Matches (1)
»
Rule Name | Rule Description | Classification | Score | Actions |
---|---|---|---|---|
RagnarLockerEncryptedFile | File encrypted by RagnarLocker Ransomware | Ransomware |
5/5
|
...
|
\\?\C:\Program Files (x86)\Microsoft Office\root\CLIPART\PUB60COR\AN00790_.WMF | Modified File | Stream |
clean
|
...
|
»
YARA Matches (1)
»
Rule Name | Rule Description | Classification | Score | Actions |
---|---|---|---|---|
RagnarLockerEncryptedFile | File encrypted by RagnarLocker Ransomware | Ransomware |
5/5
|
...
|
\\?\C:\Program Files (x86)\Microsoft Office\root\CLIPART\PUB60COR\AN00853_.WMF | Modified File | Stream |
clean
|
...
|
»
YARA Matches (1)
»
Rule Name | Rule Description | Classification | Score | Actions |
---|---|---|---|---|
RagnarLockerEncryptedFile | File encrypted by RagnarLocker Ransomware | Ransomware |
5/5
|
...
|
\\?\C:\Program Files (x86)\Microsoft Office\root\CLIPART\PUB60COR\AN00914_.WMF | Modified File | Stream |
clean
|
...
|
»
YARA Matches (1)
»
Rule Name | Rule Description | Classification | Score | Actions |
---|---|---|---|---|
RagnarLockerEncryptedFile | File encrypted by RagnarLocker Ransomware | Ransomware |
5/5
|
...
|
\\?\C:\Program Files (x86)\Microsoft Office\root\CLIPART\PUB60COR\AN00932_.WMF | Modified File | Stream |
clean
|
...
|
»
YARA Matches (1)
»
Rule Name | Rule Description | Classification | Score | Actions |
---|---|---|---|---|
RagnarLockerEncryptedFile | File encrypted by RagnarLocker Ransomware | Ransomware |
5/5
|
...
|
\\?\C:\Program Files (x86)\Microsoft Office\root\CLIPART\PUB60COR\AN00965_.WMF | Modified File | Stream |
clean
|
...
|
»
YARA Matches (1)
»
Rule Name | Rule Description | Classification | Score | Actions |
---|---|---|---|---|
RagnarLockerEncryptedFile | File encrypted by RagnarLocker Ransomware | Ransomware |
5/5
|
...
|
\\?\C:\Program Files (x86)\Microsoft Office\root\CLIPART\PUB60COR\AN01039_.WMF | Modified File | Stream |
clean
|
...
|
»
YARA Matches (1)
»
Rule Name | Rule Description | Classification | Score | Actions |
---|---|---|---|---|
RagnarLockerEncryptedFile | File encrypted by RagnarLocker Ransomware | Ransomware |
5/5
|
...
|
\\?\C:\Program Files (x86)\Microsoft Office\root\CLIPART\PUB60COR\AN01044_.WMF | Modified File | Stream |
clean
|
...
|
»
YARA Matches (1)
»
Rule Name | Rule Description | Classification | Score | Actions |
---|---|---|---|---|
RagnarLockerEncryptedFile | File encrypted by RagnarLocker Ransomware | Ransomware |
5/5
|
...
|
\\?\C:\Program Files (x86)\Microsoft Office\root\CLIPART\PUB60COR\AN01060_.WMF | Modified File | Stream |
clean
|
...
|
»
YARA Matches (1)
»
Rule Name | Rule Description | Classification | Score | Actions |
---|---|---|---|---|
RagnarLockerEncryptedFile | File encrypted by RagnarLocker Ransomware | Ransomware |
5/5
|
...
|
\\?\C:\Program Files (x86)\Microsoft Office\root\CLIPART\PUB60COR\AN01084_.WMF | Modified File | Stream |
clean
|
...
|
»
YARA Matches (1)
»
Rule Name | Rule Description | Classification | Score | Actions |
---|---|---|---|---|
RagnarLockerEncryptedFile | File encrypted by RagnarLocker Ransomware | Ransomware |
5/5
|
...
|
\\?\C:\Program Files (x86)\Microsoft Office\root\CLIPART\PUB60COR\AN01173_.WMF | Modified File | Stream |
clean
|
...
|
»
YARA Matches (1)
»
Rule Name | Rule Description | Classification | Score | Actions |
---|---|---|---|---|
RagnarLockerEncryptedFile | File encrypted by RagnarLocker Ransomware | Ransomware |
5/5
|
...
|
\\?\C:\Program Files (x86)\Microsoft Office\root\CLIPART\PUB60COR\AN01174_.WMF | Modified File | Stream |
clean
|
...
|
»
YARA Matches (1)
»
Rule Name | Rule Description | Classification | Score | Actions |
---|---|---|---|---|
RagnarLockerEncryptedFile | File encrypted by RagnarLocker Ransomware | Ransomware |
5/5
|
...
|
\\?\C:\Program Files (x86)\Microsoft Office\root\CLIPART\PUB60COR\AN01184_.WMF | Modified File | Stream |
clean
|
...
|
»
YARA Matches (1)
»
Rule Name | Rule Description | Classification | Score | Actions |
---|---|---|---|---|
RagnarLockerEncryptedFile | File encrypted by RagnarLocker Ransomware | Ransomware |
5/5
|
...
|
\\?\C:\Program Files (x86)\Microsoft Office\root\CLIPART\PUB60COR\AN01216_.WMF | Modified File | Stream |
clean
|
...
|
»
YARA Matches (1)
»
Rule Name | Rule Description | Classification | Score | Actions |
---|---|---|---|---|
RagnarLockerEncryptedFile | File encrypted by RagnarLocker Ransomware | Ransomware |
5/5
|
...
|
\\?\C:\Program Files (x86)\Microsoft Office\root\CLIPART\PUB60COR\AN01218_.WMF | Modified File | Stream |
clean
|
...
|
»
YARA Matches (1)
»
Rule Name | Rule Description | Classification | Score | Actions |
---|---|---|---|---|
RagnarLockerEncryptedFile | File encrypted by RagnarLocker Ransomware | Ransomware |
5/5
|
...
|
\\?\C:\Program Files (x86)\Microsoft Office\root\CLIPART\PUB60COR\AN01251_.WMF | Modified File | Stream |
clean
|
...
|
»
YARA Matches (1)
»
Rule Name | Rule Description | Classification | Score | Actions |
---|---|---|---|---|
RagnarLockerEncryptedFile | File encrypted by RagnarLocker Ransomware | Ransomware |
5/5
|
...
|
\\?\C:\Program Files (x86)\Microsoft Office\root\CLIPART\PUB60COR\AN01545_.WMF | Modified File | Stream |
clean
|
...
|
»
YARA Matches (1)
»
Rule Name | Rule Description | Classification | Score | Actions |
---|---|---|---|---|
RagnarLockerEncryptedFile | File encrypted by RagnarLocker Ransomware | Ransomware |
5/5
|
...
|
\\?\C:\Program Files (x86)\Microsoft Office\root\CLIPART\PUB60COR\AN02122_.WMF | Modified File | Stream |
clean
|
...
|
»
YARA Matches (1)
»
Rule Name | Rule Description | Classification | Score | Actions |
---|---|---|---|---|
RagnarLockerEncryptedFile | File encrypted by RagnarLocker Ransomware | Ransomware |
5/5
|
...
|
\\?\C:\Program Files (x86)\Microsoft Office\root\CLIPART\PUB60COR\AN02559_.WMF | Modified File | Stream |
clean
|
...
|
»
YARA Matches (1)
»
Rule Name | Rule Description | Classification | Score | Actions |
---|---|---|---|---|
RagnarLockerEncryptedFile | File encrypted by RagnarLocker Ransomware | Ransomware |
5/5
|
...
|
\\?\C:\Program Files (x86)\Microsoft Office\root\CLIPART\PUB60COR\AN02724_.WMF | Modified File | Stream |
clean
|
...
|
»
YARA Matches (1)
»
Rule Name | Rule Description | Classification | Score | Actions |
---|---|---|---|---|
RagnarLockerEncryptedFile | File encrypted by RagnarLocker Ransomware | Ransomware |
5/5
|
...
|
\\?\C:\Program Files (x86)\Microsoft Office\root\CLIPART\PUB60COR\AN03500_.WMF | Modified File | Stream |
clean
|
...
|
»
YARA Matches (1)
»
Rule Name | Rule Description | Classification | Score | Actions |
---|---|---|---|---|
RagnarLockerEncryptedFile | File encrypted by RagnarLocker Ransomware | Ransomware |
5/5
|
...
|
\\?\C:\Program Files (x86)\Microsoft Office\root\CLIPART\PUB60COR\AN04108_.WMF | Modified File | Stream |
clean
|
...
|
»
YARA Matches (1)
»
Rule Name | Rule Description | Classification | Score | Actions |
---|---|---|---|---|
RagnarLockerEncryptedFile | File encrypted by RagnarLocker Ransomware | Ransomware |
5/5
|
...
|
\\?\C:\Program Files (x86)\Microsoft Office\root\CLIPART\PUB60COR\AN04117_.WMF | Modified File | Stream |
clean
|
...
|
»
YARA Matches (1)
»
Rule Name | Rule Description | Classification | Score | Actions |
---|---|---|---|---|
RagnarLockerEncryptedFile | File encrypted by RagnarLocker Ransomware | Ransomware |
5/5
|
...
|
\\?\C:\Program Files (x86)\Microsoft Office\root\CLIPART\PUB60COR\AN04134_.WMF | Modified File | Stream |
clean
|
...
|
»
YARA Matches (1)
»
Rule Name | Rule Description | Classification | Score | Actions |
---|---|---|---|---|
RagnarLockerEncryptedFile | File encrypted by RagnarLocker Ransomware | Ransomware |
5/5
|
...
|
\\?\C:\Program Files (x86)\Microsoft Office\root\CLIPART\PUB60COR\AN04174_.WMF | Modified File | Stream |
clean
|
...
|
»
YARA Matches (1)
»
Rule Name | Rule Description | Classification | Score | Actions |
---|---|---|---|---|
RagnarLockerEncryptedFile | File encrypted by RagnarLocker Ransomware | Ransomware |
5/5
|
...
|
\\?\C:\Program Files (x86)\Microsoft Office\root\CLIPART\PUB60COR\AN04191_.WMF | Modified File | Stream |
clean
|
...
|
»
YARA Matches (1)
»
Rule Name | Rule Description | Classification | Score | Actions |
---|---|---|---|---|
RagnarLockerEncryptedFile | File encrypted by RagnarLocker Ransomware | Ransomware |
5/5
|
...
|
\\?\C:\Program Files (x86)\Microsoft Office\root\CLIPART\PUB60COR\AN04195_.WMF | Modified File | Stream |
clean
|
...
|
»
YARA Matches (1)
»
Rule Name | Rule Description | Classification | Score | Actions |
---|---|---|---|---|
RagnarLockerEncryptedFile | File encrypted by RagnarLocker Ransomware | Ransomware |
5/5
|
...
|
\\?\C:\Program Files (x86)\Microsoft Office\root\CLIPART\PUB60COR\AN04196_.WMF | Modified File | Stream |
clean
|
...
|
»
YARA Matches (1)
»
Rule Name | Rule Description | Classification | Score | Actions |
---|---|---|---|---|
RagnarLockerEncryptedFile | File encrypted by RagnarLocker Ransomware | Ransomware |
5/5
|
...
|
\\?\C:\Program Files (x86)\Microsoft Office\root\CLIPART\PUB60COR\AN04206_.WMF | Modified File | Stream |
clean
|
...
|
»
YARA Matches (1)
»
Rule Name | Rule Description | Classification | Score | Actions |
---|---|---|---|---|
RagnarLockerEncryptedFile | File encrypted by RagnarLocker Ransomware | Ransomware |
5/5
|
...
|
\\?\C:\Program Files (x86)\Microsoft Office\root\CLIPART\PUB60COR\AN04225_.WMF | Modified File | Stream |
clean
|
...
|
»
YARA Matches (1)
»
Rule Name | Rule Description | Classification | Score | Actions |
---|---|---|---|---|
RagnarLockerEncryptedFile | File encrypted by RagnarLocker Ransomware | Ransomware |
5/5
|
...
|
\\?\C:\Program Files (x86)\Microsoft Office\root\CLIPART\PUB60COR\AN04235_.WMF | Modified File | Stream |
clean
|
...
|
»
YARA Matches (1)
»
Rule Name | Rule Description | Classification | Score | Actions |
---|---|---|---|---|
RagnarLockerEncryptedFile | File encrypted by RagnarLocker Ransomware | Ransomware |
5/5
|
...
|
\\?\C:\Program Files (x86)\Microsoft Office\root\Document Themes 16\Slice.thmx | Modified File | Unknown |
clean
|
...
|
»
C:\Users\Public\Documents\RGNR_EEDCF512.txt | Dropped File | Text |
clean
|
...
|
»