VTI SCORE: 100/100
Dynamic Analysis Report |
Classification: |
Ransomware
Dropper
|
Threat Names: |
Generic.Ransom.Matrix.ADEC1043
VBS.Heur.Laburrak.11.Gen
Trojan.GenericKD.40672878
...
|
nbfmxw.exe
Windows Exe (x86-32)
Created at 2020-08-31T11:47:00
Remarks (1/1)
(0x0200000E): The overall sleep time of all monitored processes was truncated from "3 minutes" to "30 seconds" to reveal dormant functionality.
Remarks
(0x0200001D): The maximum number of extracted files was exceeded. Some files may be missing in the report.
(0x0200001B): The maximum number of file reputation requests per analysis (150) was exceeded.
This is a filtered view
This list contains only the embedded files, downloaded files, and dropped files
Filters: |
There are no files for this filter
There are no files in this analysis
Filename | Category | Type | Severity | Actions |
---|
PE Information
»
Image Base | 0x400000 |
Entry Point | 0x4dca54 |
Size Of Code | 0xe0400 |
Size Of Initialized Data | 0x4ee00 |
File Type | FileType.executable |
Subsystem | Subsystem.windows_cui |
Machine Type | MachineType.i386 |
Compile Timestamp | 2020-08-03 21:39:06+00:00 |
Sections (10)
»
Name | Virtual Address | Virtual Size | Raw Data Size | Raw Data Offset | Flags | Entropy |
---|---|---|---|---|---|---|
.text | 0x401000 | 0xdaf04 | 0xdb000 | 0x400 | IMAGE_SCN_CNT_CODE, IMAGE_SCN_MEM_EXECUTE, IMAGE_SCN_MEM_READ | 6.38 |
.itext | 0x4dc000 | 0x52d8 | 0x5400 | 0xdb400 | IMAGE_SCN_CNT_CODE, IMAGE_SCN_MEM_EXECUTE, IMAGE_SCN_MEM_READ | 5.74 |
.data | 0x4e2000 | 0x5b08 | 0x5c00 | 0xe0800 | IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_READ, IMAGE_SCN_MEM_WRITE | 6.19 |
.bss | 0x4e8000 | 0x645c | 0x0 | 0x0 | IMAGE_SCN_MEM_READ, IMAGE_SCN_MEM_WRITE | 0.0 |
.idata | 0x4ef000 | 0x1236 | 0x1400 | 0xe6400 | IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_READ, IMAGE_SCN_MEM_WRITE | 4.81 |
.didata | 0x4f1000 | 0xfa | 0x200 | 0xe7800 | IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_READ, IMAGE_SCN_MEM_WRITE | 2.0 |
.edata | 0x4f2000 | 0x6c | 0x200 | 0xe7a00 | IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_READ | 1.31 |
.tls | 0x4f3000 | 0x14 | 0x0 | 0x0 | IMAGE_SCN_MEM_READ, IMAGE_SCN_MEM_WRITE | 0.0 |
.rdata | 0x4f4000 | 0x18 | 0x200 | 0xe7c00 | IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_READ | 0.21 |
.rsrc | 0x4f5000 | 0x47800 | 0x47800 | 0xe7e00 | IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_READ | 7.96 |
Imports (8)
»
oleaut32.dll (12)
»
API Name | Ordinal | IAT Address | Thunk RVA | Thunk Offset | Hint |
---|---|---|---|---|---|
SysFreeString | 0x0 | 0x4ef36c | 0xef0b4 | 0xe64b4 | 0x0 |
SysReAllocStringLen | 0x0 | 0x4ef370 | 0xef0b8 | 0xe64b8 | 0x0 |
SysAllocStringLen | 0x0 | 0x4ef374 | 0xef0bc | 0xe64bc | 0x0 |
SafeArrayPtrOfIndex | 0x0 | 0x4ef378 | 0xef0c0 | 0xe64c0 | 0x0 |
SafeArrayGetUBound | 0x0 | 0x4ef37c | 0xef0c4 | 0xe64c4 | 0x0 |
SafeArrayGetLBound | 0x0 | 0x4ef380 | 0xef0c8 | 0xe64c8 | 0x0 |
SafeArrayCreate | 0x0 | 0x4ef384 | 0xef0cc | 0xe64cc | 0x0 |
VariantChangeType | 0x0 | 0x4ef388 | 0xef0d0 | 0xe64d0 | 0x0 |
VariantCopy | 0x0 | 0x4ef38c | 0xef0d4 | 0xe64d4 | 0x0 |
VariantClear | 0x0 | 0x4ef390 | 0xef0d8 | 0xe64d8 | 0x0 |
VariantInit | 0x0 | 0x4ef394 | 0xef0dc | 0xe64dc | 0x0 |
GetErrorInfo | 0x0 | 0x4ef398 | 0xef0e0 | 0xe64e0 | 0x0 |
advapi32.dll (15)
»
API Name | Ordinal | IAT Address | Thunk RVA | Thunk Offset | Hint |
---|---|---|---|---|---|
RegQueryValueExW | 0x0 | 0x4ef3a0 | 0xef0e8 | 0xe64e8 | 0x0 |
RegOpenKeyExW | 0x0 | 0x4ef3a4 | 0xef0ec | 0xe64ec | 0x0 |
RegCloseKey | 0x0 | 0x4ef3a8 | 0xef0f0 | 0xe64f0 | 0x0 |
OpenThreadToken | 0x0 | 0x4ef3ac | 0xef0f4 | 0xe64f4 | 0x0 |
OpenProcessToken | 0x0 | 0x4ef3b0 | 0xef0f8 | 0xe64f8 | 0x0 |
GetUserNameA | 0x0 | 0x4ef3b4 | 0xef0fc | 0xe64fc | 0x0 |
GetTokenInformation | 0x0 | 0x4ef3b8 | 0xef100 | 0xe6500 | 0x0 |
GetSidSubAuthorityCount | 0x0 | 0x4ef3bc | 0xef104 | 0xe6504 | 0x0 |
GetSidSubAuthority | 0x0 | 0x4ef3c0 | 0xef108 | 0xe6508 | 0x0 |
FreeSid | 0x0 | 0x4ef3c4 | 0xef10c | 0xe650c | 0x0 |
EqualSid | 0x0 | 0x4ef3c8 | 0xef110 | 0xe6510 | 0x0 |
AllocateAndInitializeSid | 0x0 | 0x4ef3cc | 0xef114 | 0xe6514 | 0x0 |
CryptGenRandom | 0x0 | 0x4ef3d0 | 0xef118 | 0xe6518 | 0x0 |
CryptReleaseContext | 0x0 | 0x4ef3d4 | 0xef11c | 0xe651c | 0x0 |
CryptAcquireContextW | 0x0 | 0x4ef3d8 | 0xef120 | 0xe6520 | 0x0 |
user32.dll (10)
»
API Name | Ordinal | IAT Address | Thunk RVA | Thunk Offset | Hint |
---|---|---|---|---|---|
MessageBoxA | 0x0 | 0x4ef3e0 | 0xef128 | 0xe6528 | 0x0 |
CharNextW | 0x0 | 0x4ef3e4 | 0xef12c | 0xe652c | 0x0 |
LoadStringW | 0x0 | 0x4ef3e8 | 0xef130 | 0xe6530 | 0x0 |
PeekMessageW | 0x0 | 0x4ef3ec | 0xef134 | 0xe6534 | 0x0 |
MsgWaitForMultipleObjects | 0x0 | 0x4ef3f0 | 0xef138 | 0xe6538 | 0x0 |
MessageBoxW | 0x0 | 0x4ef3f4 | 0xef13c | 0xe653c | 0x0 |
GetSystemMetrics | 0x0 | 0x4ef3f8 | 0xef140 | 0xe6540 | 0x0 |
CharUpperBuffW | 0x0 | 0x4ef3fc | 0xef144 | 0xe6544 | 0x0 |
CharUpperW | 0x0 | 0x4ef400 | 0xef148 | 0xe6548 | 0x0 |
CharLowerBuffW | 0x0 | 0x4ef404 | 0xef14c | 0xe654c | 0x0 |
kernel32.dll (119)
»
API Name | Ordinal | IAT Address | Thunk RVA | Thunk Offset | Hint |
---|---|---|---|---|---|
Sleep | 0x0 | 0x4ef40c | 0xef154 | 0xe6554 | 0x0 |
VirtualFree | 0x0 | 0x4ef410 | 0xef158 | 0xe6558 | 0x0 |
VirtualAlloc | 0x0 | 0x4ef414 | 0xef15c | 0xe655c | 0x0 |
lstrlenW | 0x0 | 0x4ef418 | 0xef160 | 0xe6560 | 0x0 |
VirtualQuery | 0x0 | 0x4ef41c | 0xef164 | 0xe6564 | 0x0 |
GetTickCount | 0x0 | 0x4ef420 | 0xef168 | 0xe6568 | 0x0 |
GetSystemInfo | 0x0 | 0x4ef424 | 0xef16c | 0xe656c | 0x0 |
GetVersion | 0x0 | 0x4ef428 | 0xef170 | 0xe6570 | 0x0 |
CompareStringW | 0x0 | 0x4ef42c | 0xef174 | 0xe6574 | 0x0 |
IsDBCSLeadByteEx | 0x0 | 0x4ef430 | 0xef178 | 0xe6578 | 0x0 |
IsValidLocale | 0x0 | 0x4ef434 | 0xef17c | 0xe657c | 0x0 |
SetThreadLocale | 0x0 | 0x4ef438 | 0xef180 | 0xe6580 | 0x0 |
GetSystemDefaultUILanguage | 0x0 | 0x4ef43c | 0xef184 | 0xe6584 | 0x0 |
GetUserDefaultUILanguage | 0x0 | 0x4ef440 | 0xef188 | 0xe6588 | 0x0 |
GetLocaleInfoW | 0x0 | 0x4ef444 | 0xef18c | 0xe658c | 0x0 |
WideCharToMultiByte | 0x0 | 0x4ef448 | 0xef190 | 0xe6590 | 0x0 |
MultiByteToWideChar | 0x0 | 0x4ef44c | 0xef194 | 0xe6594 | 0x0 |
GetConsoleOutputCP | 0x0 | 0x4ef450 | 0xef198 | 0xe6598 | 0x0 |
GetConsoleCP | 0x0 | 0x4ef454 | 0xef19c | 0xe659c | 0x0 |
GetACP | 0x0 | 0x4ef458 | 0xef1a0 | 0xe65a0 | 0x0 |
LoadLibraryExW | 0x0 | 0x4ef45c | 0xef1a4 | 0xe65a4 | 0x0 |
GetStartupInfoW | 0x0 | 0x4ef460 | 0xef1a8 | 0xe65a8 | 0x0 |
GetProcAddress | 0x0 | 0x4ef464 | 0xef1ac | 0xe65ac | 0x0 |
GetModuleHandleW | 0x0 | 0x4ef468 | 0xef1b0 | 0xe65b0 | 0x0 |
GetModuleFileNameW | 0x0 | 0x4ef46c | 0xef1b4 | 0xe65b4 | 0x0 |
GetCommandLineW | 0x0 | 0x4ef470 | 0xef1b8 | 0xe65b8 | 0x0 |
FreeLibrary | 0x0 | 0x4ef474 | 0xef1bc | 0xe65bc | 0x0 |
GetLastError | 0x0 | 0x4ef478 | 0xef1c0 | 0xe65c0 | 0x0 |
UnhandledExceptionFilter | 0x0 | 0x4ef47c | 0xef1c4 | 0xe65c4 | 0x0 |
RtlUnwind | 0x0 | 0x4ef480 | 0xef1c8 | 0xe65c8 | 0x0 |
RaiseException | 0x0 | 0x4ef484 | 0xef1cc | 0xe65cc | 0x0 |
ExitProcess | 0x0 | 0x4ef488 | 0xef1d0 | 0xe65d0 | 0x0 |
ExitThread | 0x0 | 0x4ef48c | 0xef1d4 | 0xe65d4 | 0x0 |
SwitchToThread | 0x0 | 0x4ef490 | 0xef1d8 | 0xe65d8 | 0x0 |
GetCurrentThreadId | 0x0 | 0x4ef494 | 0xef1dc | 0xe65dc | 0x0 |
CreateThread | 0x0 | 0x4ef498 | 0xef1e0 | 0xe65e0 | 0x0 |
DeleteCriticalSection | 0x0 | 0x4ef49c | 0xef1e4 | 0xe65e4 | 0x0 |
LeaveCriticalSection | 0x0 | 0x4ef4a0 | 0xef1e8 | 0xe65e8 | 0x0 |
EnterCriticalSection | 0x0 | 0x4ef4a4 | 0xef1ec | 0xe65ec | 0x0 |
InitializeCriticalSection | 0x0 | 0x4ef4a8 | 0xef1f0 | 0xe65f0 | 0x0 |
FindFirstFileW | 0x0 | 0x4ef4ac | 0xef1f4 | 0xe65f4 | 0x0 |
FindClose | 0x0 | 0x4ef4b0 | 0xef1f8 | 0xe65f8 | 0x0 |
WriteFile | 0x0 | 0x4ef4b4 | 0xef1fc | 0xe65fc | 0x0 |
SetFilePointer | 0x0 | 0x4ef4b8 | 0xef200 | 0xe6600 | 0x0 |
SetEndOfFile | 0x0 | 0x4ef4bc | 0xef204 | 0xe6604 | 0x0 |
ReadFile | 0x0 | 0x4ef4c0 | 0xef208 | 0xe6608 | 0x0 |
GetFileType | 0x0 | 0x4ef4c4 | 0xef20c | 0xe660c | 0x0 |
GetFileSize | 0x0 | 0x4ef4c8 | 0xef210 | 0xe6610 | 0x0 |
CreateFileW | 0x0 | 0x4ef4cc | 0xef214 | 0xe6614 | 0x0 |
GetStdHandle | 0x0 | 0x4ef4d0 | 0xef218 | 0xe6618 | 0x0 |
CloseHandle | 0x0 | 0x4ef4d4 | 0xef21c | 0xe661c | 0x0 |
LoadLibraryA | 0x0 | 0x4ef4d8 | 0xef220 | 0xe6620 | 0x0 |
TlsSetValue | 0x0 | 0x4ef4dc | 0xef224 | 0xe6624 | 0x0 |
TlsGetValue | 0x0 | 0x4ef4e0 | 0xef228 | 0xe6628 | 0x0 |
LocalFree | 0x0 | 0x4ef4e4 | 0xef22c | 0xe662c | 0x0 |
LocalAlloc | 0x0 | 0x4ef4e8 | 0xef230 | 0xe6630 | 0x0 |
WaitForSingleObject | 0x0 | 0x4ef4ec | 0xef234 | 0xe6634 | 0x0 |
WaitForMultipleObjects | 0x0 | 0x4ef4f0 | 0xef238 | 0xe6638 | 0x0 |
VirtualQueryEx | 0x0 | 0x4ef4f4 | 0xef23c | 0xe663c | 0x0 |
VirtualProtect | 0x0 | 0x4ef4f8 | 0xef240 | 0xe6640 | 0x0 |
VerSetConditionMask | 0x0 | 0x4ef4fc | 0xef244 | 0xe6644 | 0x0 |
VerifyVersionInfoW | 0x0 | 0x4ef500 | 0xef248 | 0xe6648 | 0x0 |
SuspendThread | 0x0 | 0x4ef504 | 0xef24c | 0xe664c | 0x0 |
SizeofResource | 0x0 | 0x4ef508 | 0xef250 | 0xe6650 | 0x0 |
SetThreadPriority | 0x0 | 0x4ef50c | 0xef254 | 0xe6654 | 0x0 |
SetLastError | 0x0 | 0x4ef510 | 0xef258 | 0xe6658 | 0x0 |
SetFileAttributesW | 0x0 | 0x4ef514 | 0xef25c | 0xe665c | 0x0 |
SetEvent | 0x0 | 0x4ef518 | 0xef260 | 0xe6660 | 0x0 |
SetErrorMode | 0x0 | 0x4ef51c | 0xef264 | 0xe6664 | 0x0 |
ResumeThread | 0x0 | 0x4ef520 | 0xef268 | 0xe6668 | 0x0 |
ResetEvent | 0x0 | 0x4ef524 | 0xef26c | 0xe666c | 0x0 |
ReleaseMutex | 0x0 | 0x4ef528 | 0xef270 | 0xe6670 | 0x0 |
QueryPerformanceFrequency | 0x0 | 0x4ef52c | 0xef274 | 0xe6674 | 0x0 |
QueryPerformanceCounter | 0x0 | 0x4ef530 | 0xef278 | 0xe6678 | 0x0 |
OpenMutexW | 0x0 | 0x4ef534 | 0xef27c | 0xe667c | 0x0 |
MoveFileExW | 0x0 | 0x4ef538 | 0xef280 | 0xe6680 | 0x0 |
LockResource | 0x0 | 0x4ef53c | 0xef284 | 0xe6684 | 0x0 |
LoadResource | 0x0 | 0x4ef540 | 0xef288 | 0xe6688 | 0x0 |
LoadLibraryW | 0x0 | 0x4ef544 | 0xef28c | 0xe668c | 0x0 |
HeapFree | 0x0 | 0x4ef548 | 0xef290 | 0xe6690 | 0x0 |
HeapDestroy | 0x0 | 0x4ef54c | 0xef294 | 0xe6694 | 0x0 |
HeapCreate | 0x0 | 0x4ef550 | 0xef298 | 0xe6698 | 0x0 |
HeapAlloc | 0x0 | 0x4ef554 | 0xef29c | 0xe669c | 0x0 |
GetVolumeInformationW | 0x0 | 0x4ef558 | 0xef2a0 | 0xe66a0 | 0x0 |
GetVersionExW | 0x0 | 0x4ef55c | 0xef2a4 | 0xe66a4 | 0x0 |
GetUserDefaultLangID | 0x0 | 0x4ef560 | 0xef2a8 | 0xe66a8 | 0x0 |
GetUserDefaultLCID | 0x0 | 0x4ef564 | 0xef2ac | 0xe66ac | 0x0 |
GetThreadTimes | 0x0 | 0x4ef568 | 0xef2b0 | 0xe66b0 | 0x0 |
GetThreadPriority | 0x0 | 0x4ef56c | 0xef2b4 | 0xe66b4 | 0x0 |
GetThreadLocale | 0x0 | 0x4ef570 | 0xef2b8 | 0xe66b8 | 0x0 |
GetSystemTimes | 0x0 | 0x4ef574 | 0xef2bc | 0xe66bc | 0x0 |
GetSystemDefaultLangID | 0x0 | 0x4ef578 | 0xef2c0 | 0xe66c0 | 0x0 |
GetSystemDefaultLCID | 0x0 | 0x4ef57c | 0xef2c4 | 0xe66c4 | 0x0 |
GetProcessTimes | 0x0 | 0x4ef580 | 0xef2c8 | 0xe66c8 | 0x0 |
GetLocalTime | 0x0 | 0x4ef584 | 0xef2cc | 0xe66cc | 0x0 |
GetFullPathNameW | 0x0 | 0x4ef588 | 0xef2d0 | 0xe66d0 | 0x0 |
GetFileAttributesW | 0x0 | 0x4ef58c | 0xef2d4 | 0xe66d4 | 0x0 |
GetExitCodeThread | 0x0 | 0x4ef590 | 0xef2d8 | 0xe66d8 | 0x0 |
GetDriveTypeW | 0x0 | 0x4ef594 | 0xef2dc | 0xe66dc | 0x0 |
GetDiskFreeSpaceW | 0x0 | 0x4ef598 | 0xef2e0 | 0xe66e0 | 0x0 |
GetDateFormatW | 0x0 | 0x4ef59c | 0xef2e4 | 0xe66e4 | 0x0 |
GetCurrentThread | 0x0 | 0x4ef5a0 | 0xef2e8 | 0xe66e8 | 0x0 |
GetCurrentProcessId | 0x0 | 0x4ef5a4 | 0xef2ec | 0xe66ec | 0x0 |
GetCurrentProcess | 0x0 | 0x4ef5a8 | 0xef2f0 | 0xe66f0 | 0x0 |
GetComputerNameA | 0x0 | 0x4ef5ac | 0xef2f4 | 0xe66f4 | 0x0 |
GetCPInfoExW | 0x0 | 0x4ef5b0 | 0xef2f8 | 0xe66f8 | 0x0 |
GetCPInfo | 0x0 | 0x4ef5b4 | 0xef2fc | 0xe66fc | 0x0 |
FreeResource | 0x0 | 0x4ef5b8 | 0xef300 | 0xe6700 | 0x0 |
InterlockedCompareExchange | 0x0 | 0x4ef5bc | 0xef304 | 0xe6704 | 0x0 |
FormatMessageW | 0x0 | 0x4ef5c0 | 0xef308 | 0xe6708 | 0x0 |
FindResourceW | 0x0 | 0x4ef5c4 | 0xef30c | 0xe670c | 0x0 |
FindNextFileW | 0x0 | 0x4ef5c8 | 0xef310 | 0xe6710 | 0x0 |
ExpandEnvironmentStringsW | 0x0 | 0x4ef5cc | 0xef314 | 0xe6714 | 0x0 |
EnumSystemLocalesW | 0x0 | 0x4ef5d0 | 0xef318 | 0xe6718 | 0x0 |
EnumCalendarInfoW | 0x0 | 0x4ef5d4 | 0xef31c | 0xe671c | 0x0 |
DeleteFileW | 0x0 | 0x4ef5d8 | 0xef320 | 0xe6720 | 0x0 |
CreateProcessW | 0x0 | 0x4ef5dc | 0xef324 | 0xe6724 | 0x0 |
CreateMutexW | 0x0 | 0x4ef5e0 | 0xef328 | 0xe6728 | 0x0 |
CreateEventW | 0x0 | 0x4ef5e4 | 0xef32c | 0xe672c | 0x0 |
ole32.dll (2)
»
API Name | Ordinal | IAT Address | Thunk RVA | Thunk Offset | Hint |
---|---|---|---|---|---|
CoUninitialize | 0x0 | 0x4ef5ec | 0xef334 | 0xe6734 | 0x0 |
CoInitialize | 0x0 | 0x4ef5f0 | 0xef338 | 0xe6738 | 0x0 |
shell32.dll (1)
»
API Name | Ordinal | IAT Address | Thunk RVA | Thunk Offset | Hint |
---|---|---|---|---|---|
SHGetSpecialFolderPathW | 0x0 | 0x4ef5f8 | 0xef340 | 0xe6740 | 0x0 |
wsock32.dll (5)
»
API Name | Ordinal | IAT Address | Thunk RVA | Thunk Offset | Hint |
---|---|---|---|---|---|
WSACleanup | 0x0 | 0x4ef600 | 0xef348 | 0xe6748 | 0x0 |
WSAStartup | 0x0 | 0x4ef604 | 0xef34c | 0xe674c | 0x0 |
gethostname | 0x0 | 0x4ef608 | 0xef350 | 0xe6750 | 0x0 |
gethostbyname | 0x0 | 0x4ef60c | 0xef354 | 0xe6754 | 0x0 |
inet_ntoa | 0x0 | 0x4ef610 | 0xef358 | 0xe6758 | 0x0 |
netapi32.dll (2)
»
API Name | Ordinal | IAT Address | Thunk RVA | Thunk Offset | Hint |
---|---|---|---|---|---|
NetShareEnum | 0x0 | 0x4ef618 | 0xef360 | 0xe6760 | 0x0 |
NetApiBufferFree | 0x0 | 0x4ef61c | 0xef364 | 0xe6764 | 0x0 |
Exports (1)
»
Api name | EAT Address | Ordinal |
---|---|---|
TMethodImplementationIntercept | 0x509b8 | 0x1 |
Memory Dumps (3)
»
Name | Process ID | Start VA | End VA | Dump Reason | PE Rebuild | Bitness | Entry Point | AV | YARA | Actions |
---|---|---|---|---|---|---|---|---|---|---|
nbfmxw.exe | 1 | 0x00400000 | 0x0053CFFF | Relevant Image |
![]() |
32-bit | 0x00407620 |
![]() |
![]() |
...
|
nwn1oi7m.exe | 5 | 0x00400000 | 0x0053CFFF | Relevant Image |
![]() |
32-bit | 0x00407620 |
![]() |
![]() |
...
|
nbfmxw.exe | 1 | 0x00400000 | 0x0053CFFF | Final Dump |
![]() |
32-bit | - |
![]() |
![]() |
...
|
Local AV Matches (1)
»
Threat Name | Severity |
---|---|
Generic.Ransom.Matrix.ADEC1043 |
Malicious
|
C:\Users\FD1HVy\AppData\Roaming\qOWXDTfs.vbs | Dropped File | Text |
Malicious
|
...
|
»
Local AV Matches (1)
»
Threat Name | Severity |
---|---|
VBS.Heur.Laburrak.11.Gen |
Malicious
|
C:\Users\FD1HVy\Desktop\BCVmTUE0.exe | Dropped File | Binary |
Malicious
|
...
|
»
File Reputation Information
»
Severity |
Blacklisted
|
Names | Mal/Generic-S |
PE Information
»
Image Base | 0x400000 |
Entry Point | 0x475810 |
Size Of Code | 0x29000 |
Size Of Initialized Data | 0x1000 |
Size Of Uninitialized Data | 0x4c000 |
File Type | FileType.executable |
Subsystem | Subsystem.windows_cui |
Machine Type | MachineType.i386 |
Compile Timestamp | 2017-12-10 21:18:46+00:00 |
Version Information (8)
»
CompanyName | Sysinternals - www.sysinternals.com |
FileDescription | Handle viewer |
FileVersion | 4.11 |
InternalName | Nthandle |
LegalCopyright | Copyright (C) 1997-2017 Mark Russinovich |
OriginalFilename | Nthandle.exe |
ProductName | Sysinternals Handle |
ProductVersion | 4.11 |
Sections (3)
»
Name | Virtual Address | Virtual Size | Raw Data Size | Raw Data Offset | Flags | Entropy |
---|---|---|---|---|---|---|
UPX0 | 0x401000 | 0x4c000 | 0x0 | 0x400 | IMAGE_SCN_CNT_UNINITIALIZED_DATA, IMAGE_SCN_MEM_EXECUTE, IMAGE_SCN_MEM_READ, IMAGE_SCN_MEM_WRITE | 0.0 |
UPX1 | 0x44d000 | 0x29000 | 0x28a00 | 0x400 | IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_EXECUTE, IMAGE_SCN_MEM_READ, IMAGE_SCN_MEM_WRITE | 7.93 |
.rsrc | 0x476000 | 0x1000 | 0x800 | 0x28e00 | IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_READ, IMAGE_SCN_MEM_WRITE | 4.04 |
Imports (6)
»
ADVAPI32.dll (1)
»
API Name | Ordinal | IAT Address | Thunk RVA | Thunk Offset | Hint |
---|---|---|---|---|---|
RegOpenKeyW | 0x0 | 0x47666c | 0x7666c | 0x2946c | 0x0 |
COMDLG32.dll (1)
»
API Name | Ordinal | IAT Address | Thunk RVA | Thunk Offset | Hint |
---|---|---|---|---|---|
PrintDlgW | 0x0 | 0x476674 | 0x76674 | 0x29474 | 0x0 |
GDI32.dll (1)
»
API Name | Ordinal | IAT Address | Thunk RVA | Thunk Offset | Hint |
---|---|---|---|---|---|
EndDoc | 0x0 | 0x47667c | 0x7667c | 0x2947c | 0x0 |
KERNEL32.DLL (4)
»
API Name | Ordinal | IAT Address | Thunk RVA | Thunk Offset | Hint |
---|---|---|---|---|---|
LoadLibraryA | 0x0 | 0x476684 | 0x76684 | 0x29484 | 0x0 |
ExitProcess | 0x0 | 0x476688 | 0x76688 | 0x29488 | 0x0 |
GetProcAddress | 0x0 | 0x47668c | 0x7668c | 0x2948c | 0x0 |
VirtualProtect | 0x0 | 0x476690 | 0x76690 | 0x29490 | 0x0 |
USER32.dll (1)
»
API Name | Ordinal | IAT Address | Thunk RVA | Thunk Offset | Hint |
---|---|---|---|---|---|
EndDialog | 0x0 | 0x476698 | 0x76698 | 0x29498 | 0x0 |
VERSION.dll (1)
»
API Name | Ordinal | IAT Address | Thunk RVA | Thunk Offset | Hint |
---|---|---|---|---|---|
VerQueryValueW | 0x0 | 0x4766a0 | 0x766a0 | 0x294a0 | 0x0 |
Local AV Matches (1)
»
Threat Name | Severity |
---|---|
Trojan.GenericKD.40672878 |
Malicious
|
C:\Program Files\UNP\CampaignManager\Campaigns\{91be532c-f9f1-406a-9858-43697c6f437a}\Content1\[FridaFarko@yahoo.com].yPKEU7fX-BrjPzTV2.FDFK22 | Dropped File | Text |
Suspicious
|
...
|
»
YARA Matches (1)
»
Rule Name | Rule Description | Classification | Score | Actions |
---|---|---|---|---|
PowerShell_Registry_Commands | PowerShell may attempt to read/write system registry | - |
2/5
|
...
|
C:\Users\FD1HVy\AppData\Roaming\Mozilla\Firefox\Profiles\w7cr0hor.default\key3.db | Modified File | Stream |
Unknown
|
...
|
»
C:\Program Files (x86)\Adobe\Acrobat Reader DC\Reader\IDTemplates\ENU\AdobeID.pdf | Modified File | Stream |
Unknown
|
...
|
»
C:\Program Files (x86)\Adobe\Acrobat Reader DC\Reader\WebResources\Resource0\static\js\plugins\ob-preview\images\compare_poster2x.jpg | Modified File | Stream |
Unknown
|
...
|
»
C:\Program Files (x86)\Adobe\Acrobat Reader DC\Reader\WebResources\Resource0\static\js\plugins\ob-preview\images\redact_poster.jpg | Modified File | Stream |
Unknown
|
...
|
»
C:\Logs\Microsoft-Windows-Windows Firewall With Advanced Security%4Firewall.evtx | Modified File | Stream |
Unknown
|
...
|
»
C:\588bce7c90097ed212\DHtmlHeader.html | Modified File | Text |
Unknown
|
...
|
»
C:\Users\FD1HVy\Documents\gmoOTOrP1jVCKNL\jxqAUkOUKpw8i1SK\M1L0T2F3JxNDh1\M__kl_dTS6cbDrS8.xls | Modified File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\Documents\Outlook Files\kkcie@kdj.kd.pst | Modified File | Compressed |
Unknown
|
...
|
»
C:\Program Files (x86)\Adobe\Acrobat Reader DC\Reader\WebResources\Resource0\static\js\plugins\ob-preview\images\themes\dark\edit_pdf_poster2x.jpg | Modified File | Stream |
Unknown
|
...
|
»
C:\Program Files (x86)\Adobe\Acrobat Reader DC\Reader\WebResources\Resource0\static\js\plugins\ob-preview\images\themes\dark\scan_poster2x.jpg | Modified File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\AppData\Roaming\Mozilla\Firefox\Profiles\w7cr0hor.default\storage\permanent\moz-safe-about+home\idb\818200132aebmoouht.sqlite | Modified File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\AppData\Roaming\Mozilla\Firefox\Profiles\w7cr0hor.default\storage.sqlite | Modified File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\Documents\WnVmVsfhoHKIS.xlsx | Modified File | Stream |
Unknown
|
...
|
»
C:\Program Files (x86)\Adobe\Acrobat Reader DC\Reader\WebResources\Resource0\static\js\plugins\ob-preview\images\combine_poster2x.jpg | Modified File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\AppData\Roaming\Mozilla\Firefox\Profiles\w7cr0hor.default\[FridaFarko@yahoo.com].epThOHKF-n5igyq77.FDFK22 | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\Documents\hPfi.docx | Modified File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\Documents\gmoOTOrP1jVCKNL\jxqAUkOUKpw8i1SK\2eA02anOsGDNkl4.ods | Modified File | Stream |
Unknown
|
...
|
»
C:\Program Files (x86)\Adobe\Acrobat Reader DC\Reader\WebResources\Resource0\static\js\plugins\ob-preview\images\themes\dark\redact_poster.jpg | Modified File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\Pictures\[FridaFarko@yahoo.com].MQG6E3vF-eW1UcgnR.FDFK22 | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\AppData\Roaming\Mozilla\Firefox\Profiles\w7cr0hor.default\[FridaFarko@yahoo.com].o3YXeRFJ-lIl8Mtf6.FDFK22 | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\AppData\Roaming\Mozilla\Firefox\Profiles\w7cr0hor.default\[FridaFarko@yahoo.com].w3Pzmdp0-CZ0rhlJV.FDFK22 | Dropped File | Stream |
Unknown
|
...
|
»
C:\Logs\Microsoft-Windows-CodeIntegrity%4Operational.evtx | Modified File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\AppData\Local\Packages\Microsoft.Windows.Photos_8wekyb3d8bbwe\LocalState\[FridaFarko@yahoo.com].gk9Rb0Ka-jgrtVEGv.FDFK22 | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\AppData\Roaming\Mozilla\Firefox\Profiles\w7cr0hor.default\[FridaFarko@yahoo.com].ecJC6Z3v-1ZDjrgYa.FDFK22 | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\Documents\[FridaFarko@yahoo.com].qKC6ooOz-YFhuBKqp.FDFK22 | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\AppData\Roaming\[FridaFarko@yahoo.com].017abg5A-uuwZzbYr.FDFK22 | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\AppData\Roaming\[FridaFarko@yahoo.com].yjeQhCPC-O7z67pQy.FDFK22 | Dropped File | Stream |
Unknown
|
...
|
»
C:\Program Files (x86)\Adobe\Acrobat Reader DC\Reader\[FridaFarko@yahoo.com].om1FAZIY-9nJJTns0.FDFK22 | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\Documents\gmoOTOrP1jVCKNL\jxqAUkOUKpw8i1SK\M1L0T2F3JxNDh1\IoSRK_2lt_Wp.pdf | Modified File | Stream |
Unknown
|
...
|
»
C:\588bce7c90097ed212\Setup.exe | Modified File | Stream |
Unknown
|
...
|
»
C:\Program Files\Java\jre1.8.0_144\lib\ext\meta-index | Modified File | Stream |
Unknown
|
...
|
»
C:\Program Files\Java\jre1.8.0_144\lib\fonts\LucidaBrightDemiBold.ttf | Modified File | Stream |
Unknown
|
...
|
»
C:\Program Files (x86)\Adobe\Acrobat Reader DC\Reader\plug_ins\Annotations\Stamps\ENU\StandardBusiness.pdf | Modified File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\Documents\gmoOTOrP1jVCKNL\jxqAUkOUKpw8i1SK\M1L0T2F3JxNDh1\[FridaFarko@yahoo.com].nrQ3pDFf-66GVRhkk.FDFK22 | Dropped File | Stream |
Unknown
|
...
|
»
C:\Logs\Key Management Service.evtx | Modified File | Stream |
Unknown
|
...
|
»
C:\Logs\Microsoft-Windows-DeviceManagement-Enterprise-Diagnostics-Provider%4Admin.evtx | Modified File | Stream |
Unknown
|
...
|
»
C:\Logs\Microsoft-Windows-LiveId%4Operational.evtx | Modified File | Stream |
Unknown
|
...
|
»
C:\Program Files\Java\jre1.8.0_144\lib\images\cursors\[FridaFarko@yahoo.com].jmeFL6Fq-XHhaOI8W.FDFK22 | Dropped File | Stream |
Unknown
|
...
|
»
C:\Program Files (x86)\Adobe\Acrobat Reader DC\Reader\WebResources\Resource0\static\js\plugins\ob-preview\images\themes\dark\scan_poster.jpg | Modified File | Stream |
Unknown
|
...
|
»
C:\Program Files (x86)\Adobe\Acrobat Reader DC\Reader\WebResources\Resource0\static\js\plugins\ob-preview\images\[FridaFarko@yahoo.com].S73V7X7y-1OkpTAMr.FDFK22 | Dropped File | Stream |
Unknown
|
...
|
»
C:\Program Files (x86)\Adobe\Acrobat Reader DC\Reader\WebResources\Resource0\static\js\plugins\ob-preview\images\scan_poster2x.jpg | Modified File | Stream |
Unknown
|
...
|
»
C:\Program Files (x86)\Adobe\Acrobat Reader DC\Reader\WebResources\Resource0\static\js\plugins\ob-preview\images\themes\dark\[FridaFarko@yahoo.com].havcpv6P-CI9rmABp.FDFK22 | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\Pictures\wH660r\[FridaFarko@yahoo.com].cqxmZWLi-6bS2xLX3.FDFK22 | Dropped File | Stream |
Unknown
|
...
|
»
C:\Logs\Microsoft-Windows-AppReadiness%4Operational.evtx | Modified File | Stream |
Unknown
|
...
|
»
C:\Logs\[FridaFarko@yahoo.com].fwW5IOnT-ZpA5wbj5.FDFK22 | Dropped File | Stream |
Unknown
|
...
|
»
C:\Logs\[FridaFarko@yahoo.com].a8I4Za7w-9wXCglhu.FDFK22 | Dropped File | Stream |
Unknown
|
...
|
»
C:\Logs\[FridaFarko@yahoo.com].a4rINJAd-rhRlcRjE.FDFK22 | Dropped File | Stream |
Unknown
|
...
|
»
C:\Program Files\Java\jre1.8.0_144\[FridaFarko@yahoo.com].O8wmbo0n-kSTgxGo5.FDFK22 | Dropped File | Stream |
Unknown
|
...
|
»
C:\Program Files\Mozilla Firefox\Accessible.tlb | Modified File | Stream |
Unknown
|
...
|
»
C:\Program Files\Mozilla Firefox\browser\features\screenshots@mozilla.org.xpi | Modified File | Stream |
Unknown
|
...
|
»
C:\$GetCurrent\SafeOS\preoobe.cmd | Modified File | Batch |
Unknown
|
...
|
»
C:\Program Files\Java\jre1.8.0_144\lib\ext\localedata.jar | Modified File | Stream |
Unknown
|
...
|
»
C:\Program Files (x86)\Adobe\Acrobat Reader DC\Reader\WebResources\Resource0\static\js\plugins\ob-preview\images\edit_pdf_poster2x.jpg | Modified File | Stream |
Unknown
|
...
|
»
C:\Program Files (x86)\Adobe\Acrobat Reader DC\Reader\WebResources\Resource0\static\js\plugins\ob-preview\images\themes\dark\[FridaFarko@yahoo.com].4UmHOnAp-A6oCNTGI.FDFK22 | Dropped File | Stream |
Unknown
|
...
|
»
C:\Logs\Microsoft-Windows-TaskScheduler%4Maintenance.evtx | Modified File | Stream |
Unknown
|
...
|
»
C:\Program Files\Java\jre1.8.0_144\lib\deploy\messages_zh_HK.properties | Modified File | Stream |
Unknown
|
...
|
»
C:\Program Files\Java\jre1.8.0_144\lib\images\cursors\cursors.properties | Modified File | Stream |
Unknown
|
...
|
»
C:\Program Files\Mozilla Firefox\browser\features\webcompat@mozilla.org.xpi | Modified File | Stream |
Unknown
|
...
|
»
C:\Program Files\Java\jre1.8.0_144\lib\tzmappings | Modified File | Stream |
Unknown
|
...
|
»
C:\Logs\[FridaFarko@yahoo.com].efLK6AAe-vvqHXHy9.FDFK22 | Dropped File | Stream |
Unknown
|
...
|
»
C:\Logs\[FridaFarko@yahoo.com].NEDG0kig-jSumAlfe.FDFK22 | Dropped File | Stream |
Unknown
|
...
|
»
C:\Program Files\Mozilla Firefox\dictionaries\en-US.aff | Modified File | Stream |
Unknown
|
...
|
»
C:\Program Files\Mozilla Firefox\nssdbm3.chk | Modified File | Stream |
Unknown
|
...
|
»
C:\Program Files\UNP\CampaignManager\Campaigns\{91be532c-f9f1-406a-9858-43697c6f437a}\Content1\ca-ES\index.html | Modified File | Text |
Unknown
|
...
|
»
C:\Program Files (x86)\Adobe\Acrobat Reader DC\Reader\WebResources\Resource0\static\js\plugins\ob-preview\images\themes\dark\[FridaFarko@yahoo.com].KYk0kVur-o8DFllwO.FDFK22 | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\Pictures\wH660r\xrcMN1TYfxc.jpg | Modified File | Stream |
Unknown
|
...
|
»
C:\Program Files\UNP\CampaignManager\Campaigns\{91be532c-f9f1-406a-9858-43697c6f437a}\Content1\en-GB\index.html | Modified File | Text |
Unknown
|
...
|
»
C:\Program Files\UNP\CampaignManager\Campaigns\{91be532c-f9f1-406a-9858-43697c6f437a}\Content1\es-AR\index.html | Modified File | Text |
Unknown
|
...
|
»
C:\Program Files\UNP\CampaignManager\Campaigns\{91be532c-f9f1-406a-9858-43697c6f437a}\Content1\fr-BE\index.html | Modified File | Text |
Unknown
|
...
|
»
C:\Program Files\UNP\CampaignManager\Campaigns\{91be532c-f9f1-406a-9858-43697c6f437a}\Content1\is-IS\index.html | Modified File | Text |
Unknown
|
...
|
»
C:\Program Files\Java\jre1.8.0_144\COPYRIGHT | Modified File | Stream |
Unknown
|
...
|
»
C:\Logs\[FridaFarko@yahoo.com].ZeofZWoE-wfhaEZK3.FDFK22 | Dropped File | Stream |
Unknown
|
...
|
»
C:\Logs\[FridaFarko@yahoo.com].YpwxN1x5-AuJbz8Eb.FDFK22 | Dropped File | Stream |
Unknown
|
...
|
»
C:\Program Files\UNP\CampaignManager\Campaigns\{91be532c-f9f1-406a-9858-43697c6f437a}\Content1\nb-NO\[FridaFarko@yahoo.com].feVJoI6k-8OVZ8YtB.FDFK22 | Dropped File | Text |
Unknown
|
...
|
»
C:\Program Files\UNP\CampaignManager\Campaigns\{91be532c-f9f1-406a-9858-43697c6f437a}\Content1\ru-RU\[FridaFarko@yahoo.com].MwUzmJaL-DK6qOZOz.FDFK22 | Dropped File | Text |
Unknown
|
...
|
»
C:\Program Files\UNP\CampaignManager\Campaigns\{91be532c-f9f1-406a-9858-43697c6f437a}\Content1\zh-HK\index.html | Modified File | Text |
Unknown
|
...
|
»
C:\Program Files (x86)\Adobe\Acrobat Reader DC\Reader\AcroApp\ENU\[FridaFarko@yahoo.com].tPfeW3Um-j5ULsWyO.FDFK22 | Dropped File | Stream |
Unknown
|
...
|
»
C:\Program Files\Java\jre1.8.0_144\bin\orbd.exe | Modified File | Stream |
Unknown
|
...
|
»
C:\Program Files\Java\jre1.8.0_144\lib\fonts\LucidaSansDemiBold.ttf | Modified File | Stream |
Unknown
|
...
|
»
C:\Program Files\Java\jre1.8.0_144\bin\unpack200.exe | Modified File | Stream |
Unknown
|
...
|
»
C:\Logs\[FridaFarko@yahoo.com].itvT9SWB-C6kYU10N.FDFK22 | Dropped File | Stream |
Unknown
|
...
|
»
C:\Logs\Microsoft-Windows-SMBServer%4Connectivity.evtx | Modified File | Stream |
Unknown
|
...
|
»
C:\Logs\Microsoft-Windows-User Profile Service%4Operational.evtx | Modified File | Stream |
Unknown
|
...
|
»
C:\Logs\[FridaFarko@yahoo.com].zRcHwvAv-hZRnwBMe.FDFK22 | Dropped File | Stream |
Unknown
|
...
|
»
C:\Logs\Microsoft-Windows-Bits-Client%4Operational.evtx | Modified File | Binary |
Unknown
|
...
|
»
C:\Program Files\Java\jre1.8.0_144\lib\images\cursors\[FridaFarko@yahoo.com].VMeWp5fP-zFZBkzx6.FDFK22 | Dropped File | Binary |
Unknown
|
...
|
»
C:\Program Files\Java\jre1.8.0_144\lib\deploy\[FridaFarko@yahoo.com].UokWFWFm-BlQXsoE1.FDFK22 | Dropped File | Stream |
Unknown
|
...
|
»
C:\Program Files\Java\jre1.8.0_144\bin\java.exe | Modified File | Stream |
Unknown
|
...
|
»
C:\Program Files\Java\jre1.8.0_144\lib\[FridaFarko@yahoo.com].hcOX1wX6-nXMpLNtD.FDFK22 | Dropped File | Compressed |
Unknown
|
...
|
»
C:\Program Files\Java\jre1.8.0_144\bin\ktab.exe | Modified File | Stream |
Unknown
|
...
|
»
C:\Logs\[FridaFarko@yahoo.com].HLEtMM9x-pMiAbXec.FDFK22 | Dropped File | Stream |
Unknown
|
...
|
»
C:\Program Files\Java\jre1.8.0_144\bin\[FridaFarko@yahoo.com].Cpr3cYJ4-P1Br1hZL.FDFK22 | Dropped File | Stream |
Unknown
|
...
|
»
C:\Program Files\Java\jre1.8.0_144\lib\cmm\[FridaFarko@yahoo.com].OJHw9mxR-10zwPQIp.FDFK22 | Dropped File | Stream |
Unknown
|
...
|
»
C:\Logs\Microsoft-Windows-AppxPackaging%4Operational.evtx | Modified File | Stream |
Unknown
|
...
|
»
C:\Program Files\Java\jre1.8.0_144\lib\deploy\[FridaFarko@yahoo.com].AeiIJxcY-ju7P6Rmi.FDFK22 | Dropped File | Stream |
Unknown
|
...
|
»
C:\Logs\[FridaFarko@yahoo.com].xCL0XEGM-hVguFFSC.FDFK22 | Dropped File | Stream |
Unknown
|
...
|
»
C:\Logs\Microsoft-Windows-Dhcp-Client%4Admin.evtx | Modified File | Binary |
Unknown
|
...
|
»
C:\Program Files\Java\jre1.8.0_144\bin\[FridaFarko@yahoo.com].NdTbV7Mt-Ej1KfOrK.FDFK22 | Dropped File | Stream |
Unknown
|
...
|
»
C:\Program Files\Java\jre1.8.0_144\bin\server\[FridaFarko@yahoo.com].dRGfh2U6-lagRe9dX.FDFK22 | Dropped File | Stream |
Unknown
|
...
|
»
C:\Program Files\Java\jre1.8.0_144\lib\deploy\messages_es.properties | Modified File | Stream |
Unknown
|
...
|
»
C:\Program Files\Java\jre1.8.0_144\lib\deploy\[FridaFarko@yahoo.com].Hi0cSHvd-FuakIlxf.FDFK22 | Dropped File | Stream |
Unknown
|
...
|
»
C:\588bce7c90097ed212\[FridaFarko@yahoo.com].7MWmJu8L-xTPAlPvz.FDFK22 | Dropped File | Stream |
Unknown
|
...
|
»
C:\Program Files\Java\jre1.8.0_144\lib\[FridaFarko@yahoo.com].ElRgG2Wf-1jkhb18s.FDFK22 | Dropped File | Stream |
Unknown
|
...
|
»
C:\Program Files\Java\jre1.8.0_144\lib\ext\[FridaFarko@yahoo.com].kqWS2z7X-B0J1cpNj.FDFK22 | Dropped File | Stream |
Unknown
|
...
|
»
C:\Program Files\Mozilla Firefox\browser\extensions\[FridaFarko@yahoo.com].SwTI0RPW-M8EmBd15.FDFK22 | Dropped File | Stream |
Unknown
|
...
|
»
C:\Program Files\Java\jre1.8.0_144\lib\ext\[FridaFarko@yahoo.com].vNiqK6uJ-QJpYzSrt.FDFK22 | Dropped File | Stream |
Unknown
|
...
|
»
C:\Program Files\Java\jre1.8.0_144\lib\fonts\LucidaBrightItalic.ttf | Modified File | Stream |
Unknown
|
...
|
»
C:\Logs\Microsoft-Windows-Shell-Core%4Operational.evtx | Modified File | Stream |
Unknown
|
...
|
»
C:\Program Files\Java\jre1.8.0_144\lib\fonts\LucidaBrightRegular.ttf | Modified File | Stream |
Unknown
|
...
|
»
C:\Logs\Microsoft-Windows-AppXDeploymentServer%4Restricted.evtx | Modified File | Stream |
Unknown
|
...
|
»
C:\Logs\[FridaFarko@yahoo.com].gPQrWi7Z-BRo7LbRc.FDFK22 | Dropped File | Stream |
Unknown
|
...
|
»
C:\Program Files\Java\jre1.8.0_144\lib\jfxswt.jar | Modified File | Stream |
Unknown
|
...
|
»
C:\Program Files\Mozilla Firefox\browser\VisualElements\VisualElements_150.png | Modified File | Stream |
Unknown
|
...
|
»
C:\Program Files\Mozilla Firefox\[FridaFarko@yahoo.com].S7NywXoK-J1gFF0Bl.FDFK22 | Dropped File | Stream |
Unknown
|
...
|
»
C:\Program Files\Java\jre1.8.0_144\lib\[FridaFarko@yahoo.com].3mRaNgfd-FOK7vtRt.FDFK22 | Dropped File | Stream |
Unknown
|
...
|
»
C:\Logs\[FridaFarko@yahoo.com].EfFgPYTZ-mGAjKcPv.FDFK22 | Dropped File | Stream |
Unknown
|
...
|
»
C:\Logs\Microsoft-Windows-Kernel-EventTracing%4Admin.evtx | Modified File | Stream |
Unknown
|
...
|
»
C:\Logs\[FridaFarko@yahoo.com].nIkkO8dJ-8swaW3hy.FDFK22 | Dropped File | Stream |
Unknown
|
...
|
»
C:\Logs\[FridaFarko@yahoo.com].E4nnFsAp-sfwTB698.FDFK22 | Dropped File | Stream |
Unknown
|
...
|
»
C:\Program Files\Java\jre1.8.0_144\[FridaFarko@yahoo.com].jl2zsZHw-SBJogjb0.FDFK22 | Dropped File | Stream |
Unknown
|
...
|
»
C:\Program Files\Java\jre1.8.0_144\THIRDPARTYLICENSEREADME-JAVAFX.txt | Modified File | Stream |
Unknown
|
...
|
»
C:\Program Files\Mozilla Firefox\browser\crashreporter-override.ini | Modified File | Stream |
Unknown
|
...
|
»
C:\Program Files\Java\jre1.8.0_144\bin\rmiregistry.exe | Modified File | Stream |
Unknown
|
...
|
»
C:\Program Files\rempl\Logs\Remediation.003.etl | Modified File | Stream |
Unknown
|
...
|
»
C:\Program Files\UNP\CampaignManager\Campaigns\{91be532c-f9f1-406a-9858-43697c6f437a}\Content1\cs-CZ\[FridaFarko@yahoo.com].hZ1Sg7Jh-jeZRJGiz.FDFK22 | Dropped File | Text |
Unknown
|
...
|
»
C:\Program Files\UNP\CampaignManager\Campaigns\{91be532c-f9f1-406a-9858-43697c6f437a}\Content1\de-AT\[FridaFarko@yahoo.com].ICBuUm8B-qYCTFhsp.FDFK22 | Dropped File | Text |
Unknown
|
...
|
»
C:\Program Files\UNP\CampaignManager\Campaigns\{91be532c-f9f1-406a-9858-43697c6f437a}\Content1\en-IN\[FridaFarko@yahoo.com].gc0ozJzf-3iE5KJEA.FDFK22 | Dropped File | Text |
Unknown
|
...
|
»
C:\Program Files\UNP\CampaignManager\Campaigns\{91be532c-f9f1-406a-9858-43697c6f437a}\Content1\es-MX\index.html | Modified File | Text |
Unknown
|
...
|
»
C:\Program Files\UNP\CampaignManager\Campaigns\{91be532c-f9f1-406a-9858-43697c6f437a}\Content1\en-ID\index.html | Modified File | Text |
Unknown
|
...
|
»
C:\Program Files\UNP\CampaignManager\Campaigns\{91be532c-f9f1-406a-9858-43697c6f437a}\Content1\es-CO\[FridaFarko@yahoo.com].cEyID8d5-IGhsXb1d.FDFK22 | Dropped File | Text |
Unknown
|
...
|
»
C:\Program Files\UNP\CampaignManager\Campaigns\{91be532c-f9f1-406a-9858-43697c6f437a}\Content1\fr-XF\[FridaFarko@yahoo.com].TcqMHWfv-v9RI0uVz.FDFK22 | Dropped File | Text |
Unknown
|
...
|
»
C:\Program Files\UNP\CampaignManager\Campaigns\{91be532c-f9f1-406a-9858-43697c6f437a}\Content1\fr-CH\index.html | Modified File | Text |
Unknown
|
...
|
»
C:\Program Files\UNP\CampaignManager\Campaigns\{91be532c-f9f1-406a-9858-43697c6f437a}\Content1\ja-JP\index.html | Modified File | Text |
Unknown
|
...
|
»
C:\Program Files\UNP\CampaignManager\Campaigns\{91be532c-f9f1-406a-9858-43697c6f437a}\Content1\nl-NL\[FridaFarko@yahoo.com].hbZVD48X-TaDRUx2A.FDFK22 | Dropped File | Text |
Unknown
|
...
|
»
C:\Program Files\UNP\CampaignManager\Campaigns\{91be532c-f9f1-406a-9858-43697c6f437a}\Content1\pl-PL\index.html | Modified File | Text |
Unknown
|
...
|
»
C:\Program Files\UNP\CampaignManager\Campaigns\{91be532c-f9f1-406a-9858-43697c6f437a}\Content1\resources\[FridaFarko@yahoo.com].9onmppEg-XmbsM0c0.FDFK22 | Dropped File | Stream |
Unknown
|
...
|
»
C:\Program Files\UNP\CampaignManager\Campaigns\{91be532c-f9f1-406a-9858-43697c6f437a}\Content1\sv-SE\[FridaFarko@yahoo.com].nrWM7JKw-b3yDTISg.FDFK22 | Dropped File | Text |
Unknown
|
...
|
»
C:\Program Files\Java\jre1.8.0_144\bin\rmid.exe | Modified File | Stream |
Unknown
|
...
|
»
C:\Program Files\Java\jre1.8.0_144\lib\amd64\[FridaFarko@yahoo.com].lJo4VriN-DVoGDxlb.FDFK22 | Dropped File | Stream |
Unknown
|
...
|
»
C:\Program Files\Java\jre1.8.0_144\lib\[FridaFarko@yahoo.com].bB37kvEQ-zjZBh8Zm.FDFK22 | Dropped File | Stream |
Unknown
|
...
|
»
C:\Program Files\Java\jre1.8.0_144\lib\fonts\[FridaFarko@yahoo.com].vksByMhd-79DdkTN3.FDFK22 | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\AppData\Roaming\Okd0njFV.bat | Dropped File | Batch |
Unknown
|
...
|
»
C:\Program Files\Mozilla Firefox\FDFK22_INFO.rtf | Dropped File | RTF |
Unknown
|
...
|
»
Office Information
»
Document Content Snippet
»
ALL YOUR VALUABLE DATA WAS ENCRYPTED!All y ur fil s w rn r pt d with str ng cr ptlg rithm S-256 + RS -2048. Pl s b sur th t y ur fil s r n t br k n nd u c n r st r th m t d y. If y u r ll w nt t r st r y ur fil s pl s writ us t th-m ils: FridaFarko@yahoo.com FridaFarko@protonmail.com FridaFarko@aol.com In subj ct lin writur ID: 66AB0452E948798EImp rt nt! Pl s s nd y ur m ss g tll f ur 3 -m il ddr ss s. This is r ll imp rt nt b c usf d liv r pr bl ms f s m m il s rvi s! Important! If you haven't received a response from us within 24 hours, please try to use a different email service ( Gmail, Yahoo, AOL, etc ) . Important! Please check your SPAM folder each time you wait for our response! If you find our email in the SPAM folder please move it to your Inbox. Important! We are always in touch and ready to help you as soon as possible!tt ch up t 3 sm ll ncr pt d fil s f r fr t st d ryption. Pl s n te th t th fil s y u s nd us sh uld n t c nt in n ... |
C:\Users\FD1HVy\Desktop\bad_66AB0452E948798E.txt | Dropped File | Text |
Unknown
|
...
|
»
C:\Users\FD1HVy\AppData\Roaming\Mozilla\Firefox\Profiles\w7cr0hor.default\favicons.sqlite | Modified File | Stream |
Not Queried
|
...
|
»
C:\Users\FD1HVy\AppData\Roaming\Mozilla\Firefox\Profiles\w7cr0hor.default\kinto.sqlite | Modified File | Stream |
Not Queried
|
...
|
»
C:\Logs\Microsoft-Windows-Ntfs%4WHC.evtx | Modified File | Stream |
Not Queried
|
...
|
»
C:\Logs\Microsoft-Windows-SmbClient%4Security.evtx | Modified File | Stream |
Not Queried
|
...
|
»
C:\Logs\Microsoft-Windows-TerminalServices-RemoteConnectionManager%4Operational.evtx | Modified File | Stream |
Not Queried
|
...
|
»
C:\Users\FD1HVy\AppData\Roaming\Mozilla\Firefox\Profiles\w7cr0hor.default\permissions.sqlite | Modified File | Stream |
Not Queried
|
...
|
»
C:\Users\FD1HVy\Documents\1QzQQy0EUvVZ0D.xlsx | Modified File | Stream |
Not Queried
|
...
|
»
C:\Users\FD1HVy\Documents\5CY1X8u3U5.docx | Modified File | Stream |
Not Queried
|
...
|
»
C:\Users\FD1HVy\Documents\V_D7gQ3reokDso7XxDd.doc | Modified File | Stream |
Not Queried
|
...
|
»
C:\Program Files (x86)\Adobe\Acrobat Reader DC\Reader\Welcome.pdf | Modified File | Stream |
Not Queried
|
...
|
»
C:\Program Files (x86)\Adobe\Acrobat Reader DC\Reader\WebResources\Resource0\static\js\plugins\ob-preview\images\themes\dark\optimize_poster.jpg | Modified File | Stream |
Not Queried
|
...
|
»
C:\Program Files (x86)\Adobe\Acrobat Reader DC\Reader\WebResources\Resource0\static\js\plugins\tracked-send\images\email\dummy\adobe-old-logo.jpg | Modified File | Stream |
Not Queried
|
...
|
»
C:\Users\FD1HVy\Pictures\VG2_L7MAvZfWnNBZdF.jpg | Modified File | Stream |
Not Queried
|
...
|
»
C:\Program Files\Java\jre1.8.0_144\bin\jabswitch.exe | Modified File | Stream |
Not Queried
|
...
|
»
C:\Users\FD1HVy\Documents\0pI-xOvE UpTm2uS5.xlsx | Modified File | Stream |
Not Queried
|
...
|
»
C:\Users\FD1HVy\Documents\gmoOTOrP1jVCKNL\jxqAUkOUKpw8i1SK\M1L0T2F3JxNDh1\3FTKTTa.doc | Modified File | Stream |
Not Queried
|
...
|
»
C:\Program Files (x86)\Adobe\Acrobat Reader DC\Reader\Click on 'Change' to select default PDF handler.pdf | Modified File | Stream |
Not Queried
|
...
|
»
C:\Program Files (x86)\Adobe\Acrobat Reader DC\Reader\WebResources\Resource0\static\js\plugins\sample-files\assets\Sample Files\Travelocity.pdf | Modified File | Stream |
Not Queried
|
...
|
»
C:\Program Files (x86)\Adobe\Acrobat Reader DC\Reader\WebResources\Resource0\static\js\plugins\ob-preview\images\compare_poster.jpg | Modified File | Stream |
Not Queried
|
...
|
»
C:\Program Files (x86)\Adobe\Acrobat Reader DC\Reader\WebResources\Resource0\static\js\plugins\ob-preview\images\protect_poster2x.jpg | Modified File | Stream |
Not Queried
|
...
|
»
C:\Users\FD1HVy\Documents\gmoOTOrP1jVCKNL\jxqAUkOUKpw8i1SK\jZfmvJ1sOrsI.xls | Modified File | Stream |
Not Queried
|
...
|
»
C:\Users\FD1HVy\AppData\Roaming\0WfcMAnoKh-mEG6I5I4y.doc | Modified File | Stream |
Not Queried
|
...
|
»
C:\588bce7c90097ed212\SetupUi.xsd | Modified File | Stream |
Not Queried
|
...
|
»
C:\Program Files (x86)\Adobe\Acrobat Reader DC\Reader\1494870C-9912-C184-4CC9-B401-A53F4D8DE290.pdf | Modified File | Stream |
Not Queried
|
...
|
»
C:\Program Files\Java\jre1.8.0_144\bin\kinit.exe | Modified File | Stream |
Not Queried
|
...
|
»
C:\Users\FD1HVy\AppData\Roaming\Microsoft\Access\AccessCache.accdb | Modified File | Stream |
Not Queried
|
...
|
»
C:\Users\FD1HVy\Documents\Database1.accdb | Modified File | Stream |
Not Queried
|
...
|
»
C:\Users\FD1HVy\AppData\Local\Mozilla\Firefox\Profiles\w7cr0hor.default\OfflineCache\index.sqlite | Modified File | Stream |
Not Queried
|
...
|
»
C:\Logs\Microsoft-Client-Licensing-Platform%4Admin.evtx | Modified File | Stream |
Not Queried
|
...
|
»
C:\Users\FD1HVy\Pictures\l4aok.jpg | Modified File | Stream |
Not Queried
|
...
|
»
C:\Program Files (x86)\Adobe\Acrobat Reader DC\Reader\WebResources\Resource0\static\js\plugins\sample-files\assets\Sample Files\Document Cloud for Government.pdf | Modified File | Stream |
Not Queried
|
...
|
»
C:\Users\FD1HVy\Documents\N3Be.xlsx | Modified File | Stream |
Not Queried
|
...
|
»
C:\Program Files\Java\jre1.8.0_144\bin\servertool.exe | Modified File | Stream |
Not Queried
|
...
|
»
C:\Users\FD1HVy\AppData\Roaming\Mozilla\Firefox\Profiles\w7cr0hor.default\storage\permanent\chrome\idb\2918063365piupsah.sqlite | Modified File | Stream |
Not Queried
|
...
|
»
C:\Users\FD1HVy\Documents\gmoOTOrP1jVCKNL\jxqAUkOUKpw8i1SK\M1L0T2F3JxNDh1\fsR6DTMRrFIlPStP.xlsx | Modified File | Stream |
Not Queried
|
...
|
»
C:\Users\FD1HVy\Documents\E6uYTwaedl2kuX We.docx | Modified File | Stream |
Not Queried
|
...
|
»
C:\Program Files\Java\jre1.8.0_144\lib\cmm\CIEXYZ.pf | Modified File | Stream |
Not Queried
|
...
|
»
C:\Logs\Microsoft-Windows-AppXDeployment%4Operational.evtx | Modified File | Stream |
Not Queried
|
...
|
»
C:\Program Files (x86)\Adobe\Acrobat Reader DC\Reader\WebResources\Resource0\static\js\plugins\ob-preview\images\protect_poster.jpg | Modified File | Stream |
Not Queried
|
...
|
»
C:\Users\FD1HVy\AppData\Roaming\Mozilla\Firefox\Profiles\w7cr0hor.default\secmod.db | Modified File | Stream |
Not Queried
|
...
|
»
C:\Program Files\Java\jre1.8.0_144\lib\deploy\ffjcext.zip | Modified File | Stream |
Not Queried
|
...
|
»
C:\Users\FD1HVy\Documents\yfJuBbGPxHsn\o5FHtopqDVOxoTU.xlsx | Modified File | Stream |
Not Queried
|
...
|
»
C:\Program Files (x86)\Adobe\Acrobat Reader DC\Reader\plug_ins\Annotations\Stamps\[FridaFarko@yahoo.com].TaP3VBkZ-IppTRj9Y.FDFK22 | Dropped File | Stream |
Not Queried
|
...
|
»
C:\Program Files\UNP\CampaignManager\Campaigns\{91be532c-f9f1-406a-9858-43697c6f437a}\Content1\resources\[FridaFarko@yahoo.com].ocbYWc0d-K0zGltZw.FDFK22 | Dropped File | Stream |
Not Queried
|
...
|
»
C:\Program Files (x86)\Adobe\Acrobat Reader DC\Reader\WebResources\Resource0\static\js\plugins\ob-preview\images\[FridaFarko@yahoo.com].7EgA78pQ-2HoPuXyS.FDFK22 | Dropped File | Stream |
Not Queried
|
...
|
»
C:\Program Files (x86)\Adobe\Acrobat Reader DC\Reader\WebResources\Resource0\static\js\plugins\ob-preview\images\themes\dark\compare_poster.jpg | Modified File | Stream |
Not Queried
|
...
|
»
C:\$GetCurrent\SafeOS\[FridaFarko@yahoo.com].GBTJ5oPr-znWzcKkM.FDFK22 | Dropped File | Stream |
Not Queried
|
...
|
»
C:\Users\FD1HVy\AppData\Local\Google\Chrome\User Data\Default\[FridaFarko@yahoo.com].AeBc0ICC-6pF80sO2.FDFK22 | Dropped File | Stream |
Not Queried
|
...
|
»
C:\588bce7c90097ed212\[FridaFarko@yahoo.com].NWKx9nIn-FW5IkNme.FDFK22 | Dropped File | Stream |
Not Queried
|
...
|
»
C:\Logs\[FridaFarko@yahoo.com].WIYCIuZ1-YMT0NAE5.FDFK22 | Dropped File | Stream |
Not Queried
|
...
|
»
C:\Logs\Microsoft-Windows-AppLocker%4Packaged app-Execution.evtx | Modified File | Stream |
Not Queried
|
...
|
»
C:\Logs\Microsoft-Windows-Diagnostics-Performance%4Operational.evtx | Modified File | Stream |
Not Queried
|
...
|
»
C:\Logs\Microsoft-Windows-Kernel-StoreMgr%4Operational.evtx | Modified File | Stream |
Not Queried
|
...
|
»
C:\Program Files (x86)\Adobe\Acrobat Reader DC\Reader\plug_ins\Annotations\Stamps\ENU\Dynamic.pdf | Modified File | Stream |
Not Queried
|
...
|
»
C:\Users\FD1HVy\Documents\[FridaFarko@yahoo.com].D7Rho9Yr-Gug6zi4b.FDFK22 | Dropped File | Stream |
Not Queried
|
...
|
»
C:\Users\FD1HVy\Documents\gmoOTOrP1jVCKNL\RcZZ0u.odt | Modified File | Stream |
Not Queried
|
...
|
»
C:\$GetCurrent\SafeOS\[FridaFarko@yahoo.com].UcruAchq-NKfl8lLF.FDFK22 | Dropped File | Batch |
Not Queried
|
...
|
»
C:\Program Files (x86)\Adobe\Acrobat Reader DC\Reader\plug_ins\Annotations\Stamps\ENU\[FridaFarko@yahoo.com].HO0RDsi4-p0mPo3z2.FDFK22 | Dropped File | Stream |
Not Queried
|
...
|
»
C:\Program Files\Java\jre1.8.0_144\lib\deploy\messages_fr.properties | Modified File | Stream |
Not Queried
|
...
|
»
C:\Program Files\Java\jre1.8.0_144\lib\deploy\splash@2x.gif | Modified File | Stream |
Not Queried
|
...
|
»
C:\Users\FD1HVy\Documents\yfJuBbGPxHsn\[FridaFarko@yahoo.com].K2WlKF2n-otMtr4p8.FDFK22 | Dropped File | Stream |
Not Queried
|
...
|
»
C:\Users\FD1HVy\Documents\gmoOTOrP1jVCKNL\jxqAUkOUKpw8i1SK\[FridaFarko@yahoo.com].saMqiV4K-IHk8HjmG.FDFK22 | Dropped File | Stream |
Not Queried
|
...
|
»
C:\Users\FD1HVy\Documents\gmoOTOrP1jVCKNL\bXQF92bQr.ods | Modified File | Stream |
Not Queried
|
...
|
»
C:\Users\FD1HVy\Documents\gmoOTOrP1jVCKNL\jxqAUkOUKpw8i1SK\9C54kIar.pdf | Modified File | Stream |
Not Queried
|
...
|
»
C:\Users\FD1HVy\AppData\Roaming\EcSIuI5fdEqwvMgM7.pdf | Modified File | Stream |
Not Queried
|
...
|
»
C:\Program Files (x86)\Adobe\Acrobat Reader DC\Reader\WebResources\Resource0\static\js\plugins\ob-preview\images\themes\dark\[FridaFarko@yahoo.com].fVaYQ1Y1-rdzkI7CV.FDFK22 | Dropped File | Stream |
Not Queried
|
...
|
»
C:\Logs\[FridaFarko@yahoo.com].TTfkNFDN-hZcozm8r.FDFK22 | Dropped File | Stream |
Not Queried
|
...
|
»
C:\Program Files\Java\jre1.8.0_144\lib\jfr\[FridaFarko@yahoo.com].8eSyJpbm-tW16y22v.FDFK22 | Dropped File | Stream |
Not Queried
|
...
|
»
C:\Program Files\Java\jre1.8.0_144\lib\management\[FridaFarko@yahoo.com].VaxO2Q2C-ujLXp6kX.FDFK22 | Dropped File | Stream |
Not Queried
|
...
|
»
C:\Users\FD1HVy\Pictures\[FridaFarko@yahoo.com].MLdfaqPq-xEMpGZio.FDFK22 | Dropped File | Stream |
Not Queried
|
...
|
»
C:\Program Files (x86)\Adobe\Acrobat Reader DC\Reader\WebResources\Resource0\static\js\plugins\ob-preview\images\optimize_poster2x.jpg | Modified File | Stream |
Not Queried
|
...
|
»
C:\Program Files (x86)\Adobe\Acrobat Reader DC\Reader\WebResources\Resource0\static\js\plugins\ob-preview\images\themes\dark\[FridaFarko@yahoo.com].9GLJCTjD-YnJoC7Yx.FDFK22 | Dropped File | Stream |
Not Queried
|
...
|
»
C:\Program Files (x86)\Adobe\Acrobat Reader DC\Reader\WebResources\Resource0\static\js\plugins\ob-preview\images\themes\dark\organize_poster2x.jpg | Modified File | Stream |
Not Queried
|
...
|
»
C:\Users\FD1HVy\AppData\Roaming\TOJbPcQTFxHTamBbafxU.jpg | Modified File | Stream |
Not Queried
|
...
|
»
C:\Users\FD1HVy\AppData\Roaming\_UgKXW9_L8XEH.jpg | Modified File | Stream |
Not Queried
|
...
|
»
C:\Logs\[FridaFarko@yahoo.com].9iiIfu6p-asfPwSsy.FDFK22 | Dropped File | Stream |
Not Queried
|
...
|
»
C:\Logs\Microsoft-Windows-SMBServer%4Security.evtx | Modified File | Stream |
Not Queried
|
...
|
»
C:\Program Files\Java\jre1.8.0_144\lib\security\[FridaFarko@yahoo.com].ZJPMUR6p-QCyPaP8r.FDFK22 | Dropped File | Stream |
Not Queried
|
...
|
»
C:\Logs\[FridaFarko@yahoo.com].FAacdEDa-vhsbdE3n.FDFK22 | Dropped File | Stream |
Not Queried
|
...
|
»
C:\Program Files (x86)\Adobe\Acrobat Reader DC\Reader\WebResources\Resource0\static\js\plugins\ob-preview\images\organize_poster.jpg | Modified File | Stream |
Not Queried
|
...
|
»
C:\588bce7c90097ed212\[FridaFarko@yahoo.com].uosBP6U2-SWJT7Owt.FDFK22 | Dropped File | Stream |
Not Queried
|
...
|
»
C:\Program Files (x86)\Adobe\Acrobat Reader DC\Reader\WebResources\Resource0\static\js\plugins\ob-preview\images\[FridaFarko@yahoo.com].AJxJX8he-YHLkHkXL.FDFK22 | Dropped File | Stream |
Not Queried
|
...
|
»
C:\Program Files (x86)\Adobe\Acrobat Reader DC\Reader\WebResources\Resource0\static\js\plugins\ob-preview\images\themes\dark\[FridaFarko@yahoo.com].h9ITkq5H-nK9jLIAe.FDFK22 | Dropped File | Stream |
Not Queried
|
...
|
»
C:\Users\FD1HVy\AppData\Roaming\tD6f1JR.jpg | Modified File | Stream |
Not Queried
|
...
|
»
C:\Users\FD1HVy\Pictures\wH660r\[FridaFarko@yahoo.com].iOtRKt8b-S73r6cmI.FDFK22 | Dropped File | Stream |
Not Queried
|
...
|
»
C:\Users\FD1HVy\Pictures\wH660r\MqWZ7-Ioywr7a9.jpg | Modified File | Stream |
Not Queried
|
...
|
»
C:\Logs\[FridaFarko@yahoo.com].o5PNxdJo-26BM3OBi.FDFK22 | Dropped File | Stream |
Not Queried
|
...
|
»
C:\Program Files\Mozilla Firefox\updater.exe | Modified File | Stream |
Not Queried
|
...
|
»
C:\Logs\Windows PowerShell.evtx | Modified File | Stream |
Not Queried
|
...
|
»
C:\Program Files\Java\jre1.8.0_144\lib\calendars.properties | Modified File | Stream |
Not Queried
|
...
|
»
C:\Program Files\Java\jre1.8.0_144\lib\deploy\messages.properties | Modified File | Stream |
Not Queried
|
...
|
»
C:\Program Files\Java\jre1.8.0_144\lib\fontconfig.properties.src | Modified File | Stream |
Not Queried
|
...
|
»
C:\Program Files\Java\jre1.8.0_144\lib\jce.jar | Modified File | Stream |
Not Queried
|
...
|
»
C:\Program Files\rempl\remsh.exe | Modified File | Compressed |
Not Queried
|
...
|
»
C:\Program Files\Java\jre1.8.0_144\lib\management\management.properties | Modified File | Stream |
Not Queried
|
...
|
»
C:\Program Files\Java\jre1.8.0_144\lib\security\blacklist | Modified File | Stream |
Not Queried
|
...
|
»
C:\Program Files\Mozilla Firefox\browser\features\followonsearch@mozilla.com.xpi | Modified File | Stream |
Not Queried
|
...
|
»
C:\Logs\Microsoft-Windows-Wcmsvc%4Operational.evtx | Modified File | Stream |
Not Queried
|
...
|
»
C:\Program Files\rempl\Logs\Remediation.001.etl | Modified File | Stream |
Not Queried
|
...
|
»
C:\Users\FD1HVy\Pictures\0LsUPCu3yW pj.jpg | Modified File | Stream |
Not Queried
|
...
|
»
C:\588bce7c90097ed212\[FridaFarko@yahoo.com].N9LHtCiV-CDBrORW4.FDFK22 | Dropped File | Stream |
Not Queried
|
...
|
»
C:\588bce7c90097ed212\[FridaFarko@yahoo.com].0HGScKj1-roXwMRUb.FDFK22 | Dropped File | Stream |
Not Queried
|
...
|
»
C:\Program Files\Java\jre1.8.0_144\bin\javacpl.exe | Modified File | Stream |
Not Queried
|
...
|
»
C:\Program Files\Java\jre1.8.0_144\bin\[FridaFarko@yahoo.com].pCf2QS3i-lM6UbnWH.FDFK22 | Dropped File | Stream |
Not Queried
|
...
|
»
C:\Program Files\Java\jre1.8.0_144\lib\cmm\[FridaFarko@yahoo.com].FUfGMFtZ-Ns1u3YZJ.FDFK22 | Dropped File | Stream |
Not Queried
|
...
|
»
C:\Program Files\Java\jre1.8.0_144\lib\deploy\[FridaFarko@yahoo.com].toYcrbnR-38M8Rack.FDFK22 | Dropped File | Stream |
Not Queried
|
...
|
»
C:\Logs\Microsoft-Windows-AppReadiness%4Admin.evtx | Modified File | Stream |
Not Queried
|
...
|
»
C:\Program Files\Java\jre1.8.0_144\bin\javacpl.cpl | Modified File | Stream |
Not Queried
|
...
|
»
C:\Logs\[FridaFarko@yahoo.com].I0eeqo7i-atgJGn4b.FDFK22 | Dropped File | Stream |
Not Queried
|
...
|
»
C:\Logs\Microsoft-Windows-Kernel-WHEA%4Operational.evtx | Modified File | Stream |
Not Queried
|
...
|
»
C:\Program Files\UNP\CampaignManager\Campaigns\{91be532c-f9f1-406a-9858-43697c6f437a}\Content1\resources\[FridaFarko@yahoo.com].JGHsYaUj-CgNwl8tW.FDFK22 | Dropped File | Text |
Not Queried
|
...
|
»
C:\Program Files\UNP\Logs\UniversalNotificationPlatform.010.etl | Modified File | Stream |
Not Queried
|
...
|
»
C:\Program Files (x86)\Adobe\Acrobat Reader DC\Reader\AcroApp\ENU\Edit_R_Exp_RHP.aapp | Modified File | Stream |
Not Queried
|
...
|
»
C:\588bce7c90097ed212\netfx_Extended.mzz | Modified File | Stream |
Not Queried
|
...
|
»
C:\588bce7c90097ed212\netfx_Core_x64.msi | Modified File | Stream |
Not Queried
|
...
|
»
C:\Program Files\Java\jre1.8.0_144\lib\ext\access-bridge-64.jar | Modified File | Stream |
Not Queried
|
...
|
»
C:\Program Files\Java\jre1.8.0_144\lib\ext\[FridaFarko@yahoo.com].z4Nn3y6n-MWwDRbYj.FDFK22 | Dropped File | Stream |
Not Queried
|
...
|
»
C:\Program Files\Java\jre1.8.0_144\lib\cmm\PYCC.pf | Modified File | Stream |
Not Queried
|
...
|
»
C:\Logs\[FridaFarko@yahoo.com].B66LLaAf-f8UwlzD9.FDFK22 | Dropped File | Stream |
Not Queried
|
...
|
»
C:\588bce7c90097ed212\Windows6.1-KB958488-v6001-x86.msu | Modified File | Stream |
Not Queried
|
...
|
»
C:\Logs\Microsoft-Windows-Diagnosis-DPS%4Operational.evtx | Modified File | Stream |
Not Queried
|
...
|
»
C:\Logs\[FridaFarko@yahoo.com].s46CKyYX-Uq31aJSD.FDFK22 | Dropped File | Stream |
Not Queried
|
...
|
»
C:\Logs\Microsoft-Windows-Ntfs%4Operational.evtx | Modified File | Stream |
Not Queried
|
...
|
»
C:\588bce7c90097ed212\[FridaFarko@yahoo.com].XsZERy2w-06guGV97.FDFK22 | Dropped File | Stream |
Not Queried
|
...
|
»
C:\Logs\[FridaFarko@yahoo.com].sNYNY2Jj-uzJbljwc.FDFK22 | Dropped File | Stream |
Not Queried
|
...
|
»
C:\Program Files\Java\jre1.8.0_144\lib\deploy\splash_11@2x-lic.gif | Modified File | Stream |
Not Queried
|
...
|
»
C:\Logs\Microsoft-Windows-Windows Firewall With Advanced Security%4ConnectionSecurity.evtx | Modified File | Stream |
Not Queried
|
...
|
»
C:\Program Files\Java\jre1.8.0_144\lib\[FridaFarko@yahoo.com].VyGrzFMk-KhBd7rOl.FDFK22 | Dropped File | Stream |
Not Queried
|
...
|
»
C:\Program Files\Java\jre1.8.0_144\lib\plugin.jar | Modified File | Stream |
Not Queried
|
...
|
»
C:\Program Files\Java\jre1.8.0_144\lib\security\[FridaFarko@yahoo.com].0iUj4JM2-5PRGtZQq.FDFK22 | Dropped File | Stream |
Not Queried
|
...
|
»
C:\Program Files\Java\jre1.8.0_144\[FridaFarko@yahoo.com].s8cZgew4-YnD9kQ3p.FDFK22 | Dropped File | Stream |
Not Queried
|
...
|
»
C:\Program Files\Java\jre1.8.0_144\lib\images\cursors\[FridaFarko@yahoo.com].zAUC3Znk-EqDuTooj.FDFK22 | Dropped File | Stream |
Not Queried
|
...
|
»
C:\Logs\[FridaFarko@yahoo.com].voujQHyp-dNO48a1U.FDFK22 | Dropped File | Stream |
Not Queried
|
...
|
»
C:\Logs\[FridaFarko@yahoo.com].vsuWPy9B-FE7agUYK.FDFK22 | Dropped File | Stream |
Not Queried
|
...
|
»
C:\Logs\Microsoft-Windows-TerminalServices-LocalSessionManager%4Admin.evtx | Modified File | Stream |
Not Queried
|
...
|
»
C:\Logs\[FridaFarko@yahoo.com].RJZ9JXzn-G52cWUpZ.FDFK22 | Dropped File | Stream |
Not Queried
|
...
|
»
C:\Program Files\Java\jre1.8.0_144\lib\images\cursors\[FridaFarko@yahoo.com].osrpklVl-pTztPqj0.FDFK22 | Dropped File | Stream |
Not Queried
|
...
|
»
C:\Program Files\Java\jre1.8.0_144\lib\[FridaFarko@yahoo.com].8s4b7DrB-H2MO7UYP.FDFK22 | Dropped File | Stream |
Not Queried
|
...
|
»
C:\Program Files\Java\jre1.8.0_144\lib\security\java.security | Modified File | Stream |
Not Queried
|
...
|
»
C:\Program Files\Mozilla Firefox\[FridaFarko@yahoo.com].UfpDJ3nP-glZ6NHfo.FDFK22 | Dropped File | Stream |
Not Queried
|
...
|
»
C:\Program Files\Java\jre1.8.0_144\lib\[FridaFarko@yahoo.com].OkT7g9tg-VJjuIs8m.FDFK22 | Dropped File | Stream |
Not Queried
|
...
|
»
C:\Program Files\Java\jre1.8.0_144\lib\security\[FridaFarko@yahoo.com].bwn6GCl0-wGwx1IxO.FDFK22 | Dropped File | Stream |
Not Queried
|
...
|
»
C:\Program Files\Java\jre1.8.0_144\bin\[FridaFarko@yahoo.com].jify9zZj-MXQERGSy.FDFK22 | Dropped File | Stream |
Not Queried
|
...
|
»
C:\Program Files\Mozilla Firefox\firefox.exe | Modified File | Stream |
Not Queried
|
...
|
»
C:\Program Files\Mozilla Firefox\pingsender.exe | Modified File | Stream |
Not Queried
|
...
|
»
C:\Program Files\Mozilla Firefox\uninstall\shortcuts_log.ini | Modified File | Stream |
Not Queried
|
...
|
»
C:\Program Files\Mozilla Firefox\dependentlibs.list | Modified File | Stream |
Not Queried
|
...
|
»
C:\Program Files\Java\jre1.8.0_144\bin\javaws.exe | Modified File | Stream |
Not Queried
|
...
|
»
C:\Program Files\Java\jre1.8.0_144\lib\ext\jaccess.jar | Modified File | Stream |
Not Queried
|
...
|
»
C:\Program Files\Java\jre1.8.0_144\lib\flavormap.properties | Modified File | Stream |
Not Queried
|
...
|
»
C:\Program Files\Mozilla Firefox\[FridaFarko@yahoo.com].Eude0m5L-W8SWGJDC.FDFK22 | Dropped File | Stream |
Not Queried
|
...
|
»
C:\Program Files\Java\jre1.8.0_144\lib\deploy\[FridaFarko@yahoo.com].RyTyPPqt-YJO9zkUF.FDFK22 | Dropped File | Stream |
Not Queried
|
...
|
»
C:\Program Files (x86)\Adobe\Acrobat Reader DC\Reader\AcroCEF\[FridaFarko@yahoo.com].OiMiHD7o-f7tnpsZi.FDFK22 | Dropped File | Stream |
Not Queried
|
...
|
»
C:\Users\FD1HVy\Desktop\ALL_dmp.fldp | Dropped File | Stream |
Not Queried
|
...
|
»
C:\Users\FD1HVy\Desktop\log.txt | Dropped File | Text |
Not Queried
|
...
|
»
C:\Users\FD1HVy\AppData\Roaming\mnsheLxa.bmp | Dropped File | Image |
Not Queried
|
...
|
»
C:\Users\FD1HVy\Desktop\ehJ38pSv.bat | Dropped File | Batch |
Not Queried
|
...
|
»