VTI SCORE: 100/100
Dynamic Analysis Report |
Classification: |
Ransomware
Downloader
|
Threat Names: |
Djvu
STOP
Trojan.GenericKD.31534187
...
|
h1rxxmJek7fnkHTT.exe
Windows Exe (x86-32)
Created at 2020-03-18T14:53:00
Remarks (2/3)
(0x0200000E): The overall sleep time of all monitored processes was truncated from "2 minutes" to "10 seconds" to reveal dormant functionality.
(0x0200003A): 2 tasks were rescheduled ahead of time to reveal dormant functionality.
Remarks
(0x0200000C): The maximum memory dump size was exceeded. Some dumps may be missing in the report.
(0x0200001B): The maximum number of file reputation requests per analysis (150) was exceeded.
This is a filtered view
This list contains only the embedded files, downloaded files, and dropped files
Filters: |
There are no files for this filter
There are no files in this analysis
Filename | Category | Type | Severity | Actions |
---|
C:\Users\5p5NrGJn0jS HALPmcxz\Desktop\h1rxxmJek7fnkHTT.exe | Sample File | Binary |
Malicious
|
...
|
»
PE Information
»
Image Base | 0x400000 |
Entry Point | 0x40283d |
Size Of Code | 0x9fa00 |
Size Of Initialized Data | 0xcb400 |
File Type | FileType.executable |
Subsystem | Subsystem.windows_gui |
Machine Type | MachineType.i386 |
Compile Timestamp | 2019-09-20 06:11:18+00:00 |
Sections (8)
»
Name | Virtual Address | Virtual Size | Raw Data Size | Raw Data Offset | Flags | Entropy |
---|---|---|---|---|---|---|
.text | 0x401000 | 0x9f9a0 | 0x9fa00 | 0x400 | IMAGE_SCN_CNT_CODE, IMAGE_SCN_MEM_EXECUTE, IMAGE_SCN_MEM_READ | 7.98 |
.rdata | 0x4a1000 | 0x3d0e | 0x3e00 | 0x9fe00 | IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_READ | 6.55 |
.data | 0x4a5000 | 0xb0614 | 0x1600 | 0xa3c00 | IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_READ, IMAGE_SCN_MEM_WRITE | 3.24 |
.gopawo | 0x556000 | 0x3b88 | 0x3c00 | 0xa5200 | IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_EXECUTE, IMAGE_SCN_MEM_READ | 0.0 |
.pey | 0x55a000 | 0x357 | 0x400 | 0xa8e00 | IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_READ, IMAGE_SCN_MEM_WRITE | 0.0 |
.yaxu | 0x55b000 | 0x8734 | 0x8800 | 0xa9200 | IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_READ, IMAGE_SCN_MEM_WRITE | 0.0 |
.kadaxu | 0x564000 | 0x1400 | 0x600 | 0xb1a00 | IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_READ, IMAGE_SCN_MEM_WRITE | 0.0 |
.rsrc | 0x566000 | 0x7e20 | 0x8000 | 0xb2000 | IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_READ | 5.75 |
Imports (2)
»
KERNEL32.dll (100)
»
API Name | Ordinal | IAT Address | Thunk RVA | Thunk Offset | Hint |
---|---|---|---|---|---|
GetFullPathNameW | 0x0 | 0x4a1000 | 0xa43a8 | 0xa31a8 | 0x1df |
GetEnvironmentVariableW | 0x0 | 0x4a1004 | 0xa43ac | 0xa31ac | 0x1c3 |
HeapReAlloc | 0x0 | 0x4a1008 | 0xa43b0 | 0xa31b0 | 0x2a4 |
SetVolumeLabelA | 0x0 | 0x4a100c | 0xa43b4 | 0xa31b4 | 0x418 |
IsBadStringPtrW | 0x0 | 0x4a1010 | 0xa43b8 | 0xa31b8 | 0x2ca |
WriteConsoleOutputCharacterW | 0x0 | 0x4a1014 | 0xa43bc | 0xa31bc | 0x48a |
lstrlenA | 0x0 | 0x4a1018 | 0xa43c0 | 0xa31c0 | 0x4b5 |
GetDefaultCommConfigW | 0x0 | 0x4a101c | 0xa43c4 | 0xa31c4 | 0x1b2 |
GetProcessIoCounters | 0x0 | 0x4a1020 | 0xa43c8 | 0xa31c8 | 0x227 |
ClearCommError | 0x0 | 0x4a1024 | 0xa43cc | 0xa31cc | 0x41 |
GetQueuedCompletionStatus | 0x0 | 0x4a1028 | 0xa43d0 | 0xa31d0 | 0x235 |
GetNumaAvailableMemoryNode | 0x0 | 0x4a102c | 0xa43d4 | 0xa31d4 | 0x208 |
GetTickCount | 0x0 | 0x4a1030 | 0xa43d8 | 0xa31d8 | 0x266 |
GetWindowsDirectoryA | 0x0 | 0x4a1034 | 0xa43dc | 0xa31dc | 0x280 |
GetPriorityClass | 0x0 | 0x4a1038 | 0xa43e0 | 0xa31e0 | 0x215 |
GlobalAlloc | 0x0 | 0x4a103c | 0xa43e4 | 0xa31e4 | 0x285 |
GetThreadSelectorEntry | 0x0 | 0x4a1040 | 0xa43e8 | 0xa31e8 | 0x263 |
SizeofResource | 0x0 | 0x4a1044 | 0xa43ec | 0xa31ec | 0x420 |
GetWriteWatch | 0x0 | 0x4a1048 | 0xa43f0 | 0xa31f0 | 0x282 |
SetConsoleCursorPosition | 0x0 | 0x4a104c | 0xa43f4 | 0xa31f4 | 0x3ab |
MultiByteToWideChar | 0x0 | 0x4a1050 | 0xa43f8 | 0xa31f8 | 0x31a |
FindFirstFileExA | 0x0 | 0x4a1054 | 0xa43fc | 0xa31fc | 0x11e |
GetLastError | 0x0 | 0x4a1058 | 0xa4400 | 0xa3200 | 0x1e6 |
EnumDateFormatsExA | 0x0 | 0x4a105c | 0xa4404 | 0xa3204 | 0xe0 |
EnumSystemCodePagesW | 0x0 | 0x4a1060 | 0xa4408 | 0xa3208 | 0xf3 |
SetFileApisToOEM | 0x0 | 0x4a1064 | 0xa440c | 0xa320c | 0x3d6 |
GetAtomNameA | 0x0 | 0x4a1068 | 0xa4410 | 0xa3210 | 0x155 |
LoadLibraryA | 0x0 | 0x4a106c | 0xa4414 | 0xa3214 | 0x2f1 |
FindFirstVolumeMountPointW | 0x0 | 0x4a1070 | 0xa4418 | 0xa3218 | 0x129 |
SetConsoleCtrlHandler | 0x0 | 0x4a1074 | 0xa441c | 0xa321c | 0x3a7 |
SetProcessWorkingSetSize | 0x0 | 0x4a1078 | 0xa4420 | 0xa3220 | 0x3fa |
GetModuleFileNameA | 0x0 | 0x4a107c | 0xa4424 | 0xa3224 | 0x1f4 |
VirtualProtect | 0x0 | 0x4a1080 | 0xa4428 | 0xa3228 | 0x45a |
CompareStringA | 0x0 | 0x4a1084 | 0xa442c | 0xa322c | 0x52 |
SetCalendarInfoA | 0x0 | 0x4a1088 | 0xa4430 | 0xa3230 | 0x398 |
GetVolumeNameForVolumeMountPointW | 0x0 | 0x4a108c | 0xa4434 | 0xa3234 | 0x27b |
GetCurrentProcessId | 0x0 | 0x4a1090 | 0xa4438 | 0xa3238 | 0x1aa |
FindNextVolumeA | 0x0 | 0x4a1094 | 0xa443c | 0xa323c | 0x132 |
CreateFileA | 0x0 | 0x4a1098 | 0xa4440 | 0xa3240 | 0x78 |
GetCommandLineA | 0x0 | 0x4a109c | 0xa4444 | 0xa3244 | 0x16f |
GetStartupInfoA | 0x0 | 0x4a10a0 | 0xa4448 | 0xa3248 | 0x239 |
TerminateProcess | 0x0 | 0x4a10a4 | 0xa444c | 0xa324c | 0x42d |
GetCurrentProcess | 0x0 | 0x4a10a8 | 0xa4450 | 0xa3250 | 0x1a9 |
UnhandledExceptionFilter | 0x0 | 0x4a10ac | 0xa4454 | 0xa3254 | 0x43e |
SetUnhandledExceptionFilter | 0x0 | 0x4a10b0 | 0xa4458 | 0xa3258 | 0x415 |
IsDebuggerPresent | 0x0 | 0x4a10b4 | 0xa445c | 0xa325c | 0x2d1 |
EnterCriticalSection | 0x0 | 0x4a10b8 | 0xa4460 | 0xa3260 | 0xd9 |
LeaveCriticalSection | 0x0 | 0x4a10bc | 0xa4464 | 0xa3264 | 0x2ef |
HeapFree | 0x0 | 0x4a10c0 | 0xa4468 | 0xa3268 | 0x2a1 |
SetHandleCount | 0x0 | 0x4a10c4 | 0xa446c | 0xa326c | 0x3e8 |
GetStdHandle | 0x0 | 0x4a10c8 | 0xa4470 | 0xa3270 | 0x23b |
GetFileType | 0x0 | 0x4a10cc | 0xa4474 | 0xa3274 | 0x1d7 |
DeleteCriticalSection | 0x0 | 0x4a10d0 | 0xa4478 | 0xa3278 | 0xbe |
SetFilePointer | 0x0 | 0x4a10d4 | 0xa447c | 0xa327c | 0x3df |
GetModuleHandleW | 0x0 | 0x4a10d8 | 0xa4480 | 0xa3280 | 0x1f9 |
Sleep | 0x0 | 0x4a10dc | 0xa4484 | 0xa3284 | 0x421 |
GetProcAddress | 0x0 | 0x4a10e0 | 0xa4488 | 0xa3288 | 0x220 |
ExitProcess | 0x0 | 0x4a10e4 | 0xa448c | 0xa328c | 0x104 |
WriteFile | 0x0 | 0x4a10e8 | 0xa4490 | 0xa3290 | 0x48d |
FreeEnvironmentStringsA | 0x0 | 0x4a10ec | 0xa4494 | 0xa3294 | 0x14a |
GetEnvironmentStrings | 0x0 | 0x4a10f0 | 0xa4498 | 0xa3298 | 0x1bf |
FreeEnvironmentStringsW | 0x0 | 0x4a10f4 | 0xa449c | 0xa329c | 0x14b |
WideCharToMultiByte | 0x0 | 0x4a10f8 | 0xa44a0 | 0xa32a0 | 0x47a |
GetEnvironmentStringsW | 0x0 | 0x4a10fc | 0xa44a4 | 0xa32a4 | 0x1c1 |
TlsGetValue | 0x0 | 0x4a1100 | 0xa44a8 | 0xa32a8 | 0x434 |
TlsAlloc | 0x0 | 0x4a1104 | 0xa44ac | 0xa32ac | 0x432 |
TlsSetValue | 0x0 | 0x4a1108 | 0xa44b0 | 0xa32b0 | 0x435 |
TlsFree | 0x0 | 0x4a110c | 0xa44b4 | 0xa32b4 | 0x433 |
InterlockedIncrement | 0x0 | 0x4a1110 | 0xa44b8 | 0xa32b8 | 0x2c0 |
SetLastError | 0x0 | 0x4a1114 | 0xa44bc | 0xa32bc | 0x3ec |
GetCurrentThreadId | 0x0 | 0x4a1118 | 0xa44c0 | 0xa32c0 | 0x1ad |
InterlockedDecrement | 0x0 | 0x4a111c | 0xa44c4 | 0xa32c4 | 0x2bc |
HeapCreate | 0x0 | 0x4a1120 | 0xa44c8 | 0xa32c8 | 0x29f |
VirtualFree | 0x0 | 0x4a1124 | 0xa44cc | 0xa32cc | 0x457 |
QueryPerformanceCounter | 0x0 | 0x4a1128 | 0xa44d0 | 0xa32d0 | 0x354 |
GetSystemTimeAsFileTime | 0x0 | 0x4a112c | 0xa44d4 | 0xa32d4 | 0x24f |
RaiseException | 0x0 | 0x4a1130 | 0xa44d8 | 0xa32d8 | 0x35a |
GetCPInfo | 0x0 | 0x4a1134 | 0xa44dc | 0xa32dc | 0x15b |
GetACP | 0x0 | 0x4a1138 | 0xa44e0 | 0xa32e0 | 0x152 |
GetOEMCP | 0x0 | 0x4a113c | 0xa44e4 | 0xa32e4 | 0x213 |
IsValidCodePage | 0x0 | 0x4a1140 | 0xa44e8 | 0xa32e8 | 0x2db |
RtlUnwind | 0x0 | 0x4a1144 | 0xa44ec | 0xa32ec | 0x392 |
HeapAlloc | 0x0 | 0x4a1148 | 0xa44f0 | 0xa32f0 | 0x29d |
VirtualAlloc | 0x0 | 0x4a114c | 0xa44f4 | 0xa32f4 | 0x454 |
InitializeCriticalSectionAndSpinCount | 0x0 | 0x4a1150 | 0xa44f8 | 0xa32f8 | 0x2b5 |
SetStdHandle | 0x0 | 0x4a1154 | 0xa44fc | 0xa32fc | 0x3fc |
GetConsoleCP | 0x0 | 0x4a1158 | 0xa4500 | 0xa3300 | 0x183 |
GetConsoleMode | 0x0 | 0x4a115c | 0xa4504 | 0xa3304 | 0x195 |
FlushFileBuffers | 0x0 | 0x4a1160 | 0xa4508 | 0xa3308 | 0x141 |
GetModuleHandleA | 0x0 | 0x4a1164 | 0xa450c | 0xa330c | 0x1f6 |
LCMapStringA | 0x0 | 0x4a1168 | 0xa4510 | 0xa3310 | 0x2e1 |
LCMapStringW | 0x0 | 0x4a116c | 0xa4514 | 0xa3314 | 0x2e3 |
GetStringTypeA | 0x0 | 0x4a1170 | 0xa4518 | 0xa3318 | 0x23d |
GetStringTypeW | 0x0 | 0x4a1174 | 0xa451c | 0xa331c | 0x240 |
GetLocaleInfoA | 0x0 | 0x4a1178 | 0xa4520 | 0xa3320 | 0x1e8 |
WriteConsoleA | 0x0 | 0x4a117c | 0xa4524 | 0xa3324 | 0x482 |
GetConsoleOutputCP | 0x0 | 0x4a1180 | 0xa4528 | 0xa3328 | 0x199 |
WriteConsoleW | 0x0 | 0x4a1184 | 0xa452c | 0xa332c | 0x48c |
HeapSize | 0x0 | 0x4a1188 | 0xa4530 | 0xa3330 | 0x2a6 |
CloseHandle | 0x0 | 0x4a118c | 0xa4534 | 0xa3334 | 0x43 |
USER32.dll (1)
»
API Name | Ordinal | IAT Address | Thunk RVA | Thunk Offset | Hint |
---|---|---|---|---|---|
GetCaretPos | 0x0 | 0x4a1194 | 0xa453c | 0xa333c | 0x103 |
Memory Dumps (43)
»
Name | Process ID | Start VA | End VA | Dump Reason | PE Rebuild | Bitness | Entry Point | AV | YARA | Actions |
---|---|---|---|---|---|---|---|---|---|---|
h1rxxmjek7fnkhtt.exe | 1 | 0x00400000 | 0x0056DFFF | Relevant Image |
![]() |
32-bit | 0x0040414C |
![]() |
![]() |
...
|
buffer | 1 | 0x00270000 | 0x00300FFF | First Execution |
![]() |
32-bit | 0x00270020 |
![]() |
![]() |
...
|
buffer | 1 | 0x01DE0000 | 0x01EF9FFF | First Execution |
![]() |
32-bit | 0x01DE0000 |
![]() |
![]() |
...
|
buffer | 1 | 0x01DE0000 | 0x01EF9FFF | Content Changed |
![]() |
32-bit | 0x01DE04F6 |
![]() |
![]() |
...
|
h1rxxmjek7fnkhtt.exe | 1 | 0x00400000 | 0x0056DFFF | Content Changed |
![]() |
32-bit | 0x00424141 |
![]() |
![]() |
...
|
h1rxxmjek7fnkhtt.exe | 1 | 0x00400000 | 0x0056DFFF | Content Changed |
![]() |
32-bit | 0x00423F84 |
![]() |
![]() |
...
|
h1rxxmjek7fnkhtt.exe | 1 | 0x00400000 | 0x0056DFFF | Content Changed |
![]() |
32-bit | 0x0042C0F0 |
![]() |
![]() |
...
|
h1rxxmjek7fnkhtt.exe | 1 | 0x00400000 | 0x0056DFFF | Content Changed |
![]() |
32-bit | 0x0043B021 |
![]() |
![]() |
...
|
h1rxxmjek7fnkhtt.exe | 1 | 0x00400000 | 0x0056DFFF | Content Changed |
![]() |
32-bit | 0x00431F64 |
![]() |
![]() |
...
|
h1rxxmjek7fnkhtt.exe | 1 | 0x00400000 | 0x0056DFFF | Content Changed |
![]() |
32-bit | 0x00421881 |
![]() |
![]() |
...
|
h1rxxmjek7fnkhtt.exe | 1 | 0x00400000 | 0x0056DFFF | Content Changed |
![]() |
32-bit | 0x0042B420 |
![]() |
![]() |
...
|
h1rxxmjek7fnkhtt.exe | 1 | 0x00400000 | 0x0056DFFF | Content Changed |
![]() |
32-bit | 0x004548D0 |
![]() |
![]() |
...
|
h1rxxmjek7fnkhtt.exe | 1 | 0x00400000 | 0x0056DFFF | Content Changed |
![]() |
32-bit | 0x0041CC50 |
![]() |
![]() |
...
|
h1rxxmjek7fnkhtt.exe | 1 | 0x00400000 | 0x0056DFFF | Content Changed |
![]() |
32-bit | 0x00419E70 |
![]() |
![]() |
...
|
h1rxxmjek7fnkhtt.exe | 1 | 0x00400000 | 0x0056DFFF | Content Changed |
![]() |
32-bit | 0x0040CF10 |
![]() |
![]() |
...
|
h1rxxmjek7fnkhtt.exe | 1 | 0x00400000 | 0x0056DFFF | Content Changed |
![]() |
32-bit | 0x0042B420 |
![]() |
![]() |
...
|
h1rxxmjek7fnkhtt.exe | 1 | 0x00400000 | 0x0056DFFF | Final Dump |
![]() |
32-bit | 0x00430BF0 |
![]() |
![]() |
...
|
h1rxxmjek7fnkhtt.exe | 1 | 0x00400000 | 0x0056DFFF | Content Changed |
![]() |
32-bit | 0x00433F99 |
![]() |
![]() |
...
|
h1rxxmjek7fnkhtt.exe | 1 | 0x00400000 | 0x0056DFFF | Content Changed |
![]() |
32-bit | 0x00424081 |
![]() |
![]() |
...
|
h1rxxmjek7fnkhtt.exe | 1 | 0x00400000 | 0x0056DFFF | Content Changed |
![]() |
32-bit | 0x004CA6F7 |
![]() |
![]() |
...
|
buffer | 1 | 0x01DE0000 | 0x01EF9FFF | Content Changed |
![]() |
32-bit | 0x01DE0920 |
![]() |
![]() |
...
|
h1rxxmjek7fnkhtt.exe | 1 | 0x00400000 | 0x0056DFFF | Process Termination |
![]() |
32-bit | - |
![]() |
![]() |
...
|
h1rxxmjek7fnkhtt.exe | 6 | 0x00400000 | 0x0056DFFF | Relevant Image |
![]() |
32-bit | 0x0040414C |
![]() |
![]() |
...
|
buffer | 6 | 0x00210000 | 0x002A0FFF | First Execution |
![]() |
32-bit | 0x00210020 |
![]() |
![]() |
...
|
buffer | 6 | 0x01E30000 | 0x01F49FFF | First Execution |
![]() |
32-bit | 0x01E30000 |
![]() |
![]() |
...
|
h1rxxmjek7fnkhtt.exe | 6 | 0x00400000 | 0x0056DFFF | Content Changed |
![]() |
32-bit | 0x00424141 |
![]() |
![]() |
...
|
h1rxxmjek7fnkhtt.exe | 6 | 0x00400000 | 0x0056DFFF | Content Changed |
![]() |
32-bit | 0x00423F84 |
![]() |
![]() |
...
|
h1rxxmjek7fnkhtt.exe | 6 | 0x00400000 | 0x0056DFFF | Content Changed |
![]() |
32-bit | 0x0042C0F0 |
![]() |
![]() |
...
|
h1rxxmjek7fnkhtt.exe | 6 | 0x00400000 | 0x0056DFFF | Content Changed |
![]() |
32-bit | 0x0043B021 |
![]() |
![]() |
...
|
h1rxxmjek7fnkhtt.exe | 6 | 0x00400000 | 0x0056DFFF | Content Changed |
![]() |
32-bit | 0x00431F64 |
![]() |
![]() |
...
|
h1rxxmjek7fnkhtt.exe | 6 | 0x00400000 | 0x0056DFFF | Content Changed |
![]() |
32-bit | 0x00421881 |
![]() |
![]() |
...
|
h1rxxmjek7fnkhtt.exe | 6 | 0x00400000 | 0x0056DFFF | Content Changed |
![]() |
32-bit | 0x0042B420 |
![]() |
![]() |
...
|
h1rxxmjek7fnkhtt.exe | 6 | 0x00400000 | 0x0056DFFF | Content Changed |
![]() |
32-bit | 0x004548D0 |
![]() |
![]() |
...
|
h1rxxmjek7fnkhtt.exe | 6 | 0x00400000 | 0x0056DFFF | Content Changed |
![]() |
32-bit | 0x0041CC50 |
![]() |
![]() |
...
|
h1rxxmjek7fnkhtt.exe | 6 | 0x00400000 | 0x0056DFFF | Content Changed |
![]() |
32-bit | 0x00419E70 |
![]() |
![]() |
...
|
h1rxxmjek7fnkhtt.exe | 6 | 0x00400000 | 0x0056DFFF | Content Changed |
![]() |
32-bit | 0x0040CF10 |
![]() |
![]() |
...
|
h1rxxmjek7fnkhtt.exe | 6 | 0x00400000 | 0x0056DFFF | Content Changed |
![]() |
32-bit | 0x0041B680 |
![]() |
![]() |
...
|
h1rxxmjek7fnkhtt.exe | 6 | 0x00400000 | 0x0056DFFF | Content Changed |
![]() |
32-bit | 0x0041E031 |
![]() |
![]() |
...
|
h1rxxmjek7fnkhtt.exe | 6 | 0x00400000 | 0x0056DFFF | Content Changed |
![]() |
32-bit | 0x0042E003 |
![]() |
![]() |
...
|
h1rxxmjek7fnkhtt.exe | 6 | 0x00400000 | 0x0056DFFF | Content Changed |
![]() |
32-bit | 0x00447F50 |
![]() |
![]() |
...
|
h1rxxmjek7fnkhtt.exe | 6 | 0x00400000 | 0x0056DFFF | Content Changed |
![]() |
32-bit | 0x0041F01A |
![]() |
![]() |
...
|
h1rxxmjek7fnkhtt.exe | 6 | 0x00400000 | 0x0056DFFF | Content Changed |
![]() |
32-bit | 0x00410FC0 |
![]() |
![]() |
...
|
buffer | 15 | 0x01E50000 | 0x01F69FFF | First Execution |
![]() |
32-bit | 0x01E50000 |
![]() |
![]() |
...
|
C:\Windows\System32\drivers\etc\hosts | Modified File | Text |
Malicious
|
...
|
»
File Reputation Information
»
Severity |
Blacklisted
|
Names | Mal/Generic-S |
Local AV Matches (1)
»
Threat Name | Severity |
---|---|
Gen:Trojan.Qhost.1 |
Malicious
|
C:\Users\5p5NrGJn0jS HALPmcxz\Contacts\Aclviho ASldjfl.contact.remk | Dropped File | Stream |
Malicious
|
...
|
»
YARA Matches (1)
»
Rule Name | Rule Description | Classification | Score | Actions |
---|---|---|---|---|
DjvuEncryptedFile | File encrypted by Djvu Ransomware | Ransomware |
5/5
|
...
|
C:\Users\5p5NrGJn0jS HALPmcxz\Contacts\Administrator.contact | Modified File | Stream |
Malicious
|
...
|
»
YARA Matches (1)
»
Rule Name | Rule Description | Classification | Score | Actions |
---|---|---|---|---|
DjvuEncryptedFile | File encrypted by Djvu Ransomware | Ransomware |
5/5
|
...
|
C:\Users\5p5NrGJn0jS HALPmcxz\Contacts\asdlfk poopvy.contact.remk | Dropped File | Stream |
Malicious
|
...
|
»
YARA Matches (1)
»
Rule Name | Rule Description | Classification | Score | Actions |
---|---|---|---|---|
DjvuEncryptedFile | File encrypted by Djvu Ransomware | Ransomware |
5/5
|
...
|
C:\Users\5p5NrGJn0jS HALPmcxz\Contacts\chucu jadnvk.contact | Modified File | Stream |
Malicious
|
...
|
»
YARA Matches (1)
»
Rule Name | Rule Description | Classification | Score | Actions |
---|---|---|---|---|
DjvuEncryptedFile | File encrypted by Djvu Ransomware | Ransomware |
5/5
|
...
|
C:\Users\5p5NrGJn0jS HALPmcxz\Contacts\lulcit amkdfe.contact.remk | Dropped File | Stream |
Malicious
|
...
|
»
YARA Matches (1)
»
Rule Name | Rule Description | Classification | Score | Actions |
---|---|---|---|---|
DjvuEncryptedFile | File encrypted by Djvu Ransomware | Ransomware |
5/5
|
...
|
C:\Users\5p5NrGJn0jS HALPmcxz\Contacts\sikvnb huvuib.contact | Modified File | Stream |
Malicious
|
...
|
»
YARA Matches (1)
»
Rule Name | Rule Description | Classification | Score | Actions |
---|---|---|---|---|
DjvuEncryptedFile | File encrypted by Djvu Ransomware | Ransomware |
5/5
|
...
|
C:\Users\5p5NrGJn0jS HALPmcxz\Desktop\-ZkT JS.bmp | Modified File | Stream |
Malicious
|
...
|
»
YARA Matches (1)
»
Rule Name | Rule Description | Classification | Score | Actions |
---|---|---|---|---|
DjvuEncryptedFile | File encrypted by Djvu Ransomware | Ransomware |
5/5
|
...
|
C:\Users\5p5NrGJn0jS HALPmcxz\Desktop\7GTeFnWqgS9ZSpp-9d.png.remk | Dropped File | Stream |
Malicious
|
...
|
»
YARA Matches (1)
»
Rule Name | Rule Description | Classification | Score | Actions |
---|---|---|---|---|
DjvuEncryptedFile | File encrypted by Djvu Ransomware | Ransomware |
5/5
|
...
|
C:\Users\5p5NrGJn0jS HALPmcxz\Desktop\AwaZ_7Drvt.mkv.remk | Dropped File | Stream |
Malicious
|
...
|
»
YARA Matches (1)
»
Rule Name | Rule Description | Classification | Score | Actions |
---|---|---|---|---|
DjvuEncryptedFile | File encrypted by Djvu Ransomware | Ransomware |
5/5
|
...
|
C:\Users\5p5NrGJn0jS HALPmcxz\Desktop\AzVzcW.mp4.remk | Dropped File | Stream |
Malicious
|
...
|
»
YARA Matches (1)
»
Rule Name | Rule Description | Classification | Score | Actions |
---|---|---|---|---|
DjvuEncryptedFile | File encrypted by Djvu Ransomware | Ransomware |
5/5
|
...
|
C:\Users\5p5NrGJn0jS HALPmcxz\Desktop\bi2gofC9nKVEjCY.png | Modified File | Stream |
Malicious
|
...
|
»
YARA Matches (1)
»
Rule Name | Rule Description | Classification | Score | Actions |
---|---|---|---|---|
DjvuEncryptedFile | File encrypted by Djvu Ransomware | Ransomware |
5/5
|
...
|
C:\Users\5p5NrGJn0jS HALPmcxz\Desktop\cYR-e.avi.remk | Dropped File | Stream |
Malicious
|
...
|
»
YARA Matches (1)
»
Rule Name | Rule Description | Classification | Score | Actions |
---|---|---|---|---|
DjvuEncryptedFile | File encrypted by Djvu Ransomware | Ransomware |
5/5
|
...
|
C:\Users\5p5NrGJn0jS HALPmcxz\Desktop\d24F8YNCqwI.png | Modified File | Stream |
Malicious
|
...
|
»
YARA Matches (1)
»
Rule Name | Rule Description | Classification | Score | Actions |
---|---|---|---|---|
DjvuEncryptedFile | File encrypted by Djvu Ransomware | Ransomware |
5/5
|
...
|
C:\Users\5p5NrGJn0jS HALPmcxz\Desktop\dbj5OVvUTa4bloIz9N.flv.remk | Dropped File | Video |
Malicious
|
...
|
»
YARA Matches (1)
»
Rule Name | Rule Description | Classification | Score | Actions |
---|---|---|---|---|
DjvuEncryptedFile | File encrypted by Djvu Ransomware | Ransomware |
5/5
|
...
|
C:\Users\5p5NrGJn0jS HALPmcxz\Desktop\e6zU.xlsx | Modified File | ZIP |
Malicious
|
...
|
»
YARA Matches (1)
»
Rule Name | Rule Description | Classification | Score | Actions |
---|---|---|---|---|
DjvuEncryptedFile | File encrypted by Djvu Ransomware | Ransomware |
5/5
|
...
|
C:\Users\5p5NrGJn0jS HALPmcxz\Desktop\h1rxxmJek7fnkHTT.exe | Modified File | Binary |
Malicious
|
...
|
»
Memory Dumps (43)
»
Name | Process ID | Start VA | End VA | Dump Reason | PE Rebuild | Bitness | Entry Point | AV | YARA | Actions |
---|---|---|---|---|---|---|---|---|---|---|
h1rxxmjek7fnkhtt.exe | 1 | 0x00400000 | 0x0056DFFF | Relevant Image |
![]() |
32-bit | 0x0040414C |
![]() |
![]() |
...
|
buffer | 1 | 0x00270000 | 0x00300FFF | First Execution |
![]() |
32-bit | 0x00270020 |
![]() |
![]() |
...
|
buffer | 1 | 0x01DE0000 | 0x01EF9FFF | First Execution |
![]() |
32-bit | 0x01DE0000 |
![]() |
![]() |
...
|
buffer | 1 | 0x01DE0000 | 0x01EF9FFF | Content Changed |
![]() |
32-bit | 0x01DE04F6 |
![]() |
![]() |
...
|
h1rxxmjek7fnkhtt.exe | 1 | 0x00400000 | 0x0056DFFF | Content Changed |
![]() |
32-bit | 0x00424141 |
![]() |
![]() |
...
|
h1rxxmjek7fnkhtt.exe | 1 | 0x00400000 | 0x0056DFFF | Content Changed |
![]() |
32-bit | 0x00423F84 |
![]() |
![]() |
...
|
h1rxxmjek7fnkhtt.exe | 1 | 0x00400000 | 0x0056DFFF | Content Changed |
![]() |
32-bit | 0x0042C0F0 |
![]() |
![]() |
...
|
h1rxxmjek7fnkhtt.exe | 1 | 0x00400000 | 0x0056DFFF | Content Changed |
![]() |
32-bit | 0x0043B021 |
![]() |
![]() |
...
|
h1rxxmjek7fnkhtt.exe | 1 | 0x00400000 | 0x0056DFFF | Content Changed |
![]() |
32-bit | 0x00431F64 |
![]() |
![]() |
...
|
h1rxxmjek7fnkhtt.exe | 1 | 0x00400000 | 0x0056DFFF | Content Changed |
![]() |
32-bit | 0x00421881 |
![]() |
![]() |
...
|
h1rxxmjek7fnkhtt.exe | 1 | 0x00400000 | 0x0056DFFF | Content Changed |
![]() |
32-bit | 0x0042B420 |
![]() |
![]() |
...
|
h1rxxmjek7fnkhtt.exe | 1 | 0x00400000 | 0x0056DFFF | Content Changed |
![]() |
32-bit | 0x004548D0 |
![]() |
![]() |
...
|
h1rxxmjek7fnkhtt.exe | 1 | 0x00400000 | 0x0056DFFF | Content Changed |
![]() |
32-bit | 0x0041CC50 |
![]() |
![]() |
...
|
h1rxxmjek7fnkhtt.exe | 1 | 0x00400000 | 0x0056DFFF | Content Changed |
![]() |
32-bit | 0x00419E70 |
![]() |
![]() |
...
|
h1rxxmjek7fnkhtt.exe | 1 | 0x00400000 | 0x0056DFFF | Content Changed |
![]() |
32-bit | 0x0040CF10 |
![]() |
![]() |
...
|
h1rxxmjek7fnkhtt.exe | 1 | 0x00400000 | 0x0056DFFF | Content Changed |
![]() |
32-bit | 0x0042B420 |
![]() |
![]() |
...
|
h1rxxmjek7fnkhtt.exe | 1 | 0x00400000 | 0x0056DFFF | Final Dump |
![]() |
32-bit | 0x00430BF0 |
![]() |
![]() |
...
|
h1rxxmjek7fnkhtt.exe | 1 | 0x00400000 | 0x0056DFFF | Content Changed |
![]() |
32-bit | 0x00433F99 |
![]() |
![]() |
...
|
h1rxxmjek7fnkhtt.exe | 1 | 0x00400000 | 0x0056DFFF | Content Changed |
![]() |
32-bit | 0x00424081 |
![]() |
![]() |
...
|
h1rxxmjek7fnkhtt.exe | 1 | 0x00400000 | 0x0056DFFF | Content Changed |
![]() |
32-bit | 0x004CA6F7 |
![]() |
![]() |
...
|
buffer | 1 | 0x01DE0000 | 0x01EF9FFF | Content Changed |
![]() |
32-bit | 0x01DE0920 |
![]() |
![]() |
...
|
h1rxxmjek7fnkhtt.exe | 1 | 0x00400000 | 0x0056DFFF | Process Termination |
![]() |
32-bit | - |
![]() |
![]() |
...
|
h1rxxmjek7fnkhtt.exe | 6 | 0x00400000 | 0x0056DFFF | Relevant Image |
![]() |
32-bit | 0x0040414C |
![]() |
![]() |
...
|
buffer | 6 | 0x00210000 | 0x002A0FFF | First Execution |
![]() |
32-bit | 0x00210020 |
![]() |
![]() |
...
|
buffer | 6 | 0x01E30000 | 0x01F49FFF | First Execution |
![]() |
32-bit | 0x01E30000 |
![]() |
![]() |
...
|
h1rxxmjek7fnkhtt.exe | 6 | 0x00400000 | 0x0056DFFF | Content Changed |
![]() |
32-bit | 0x00424141 |
![]() |
![]() |
...
|
h1rxxmjek7fnkhtt.exe | 6 | 0x00400000 | 0x0056DFFF | Content Changed |
![]() |
32-bit | 0x00423F84 |
![]() |
![]() |
...
|
h1rxxmjek7fnkhtt.exe | 6 | 0x00400000 | 0x0056DFFF | Content Changed |
![]() |
32-bit | 0x0042C0F0 |
![]() |
![]() |
...
|
h1rxxmjek7fnkhtt.exe | 6 | 0x00400000 | 0x0056DFFF | Content Changed |
![]() |
32-bit | 0x0043B021 |
![]() |
![]() |
...
|
h1rxxmjek7fnkhtt.exe | 6 | 0x00400000 | 0x0056DFFF | Content Changed |
![]() |
32-bit | 0x00431F64 |
![]() |
![]() |
...
|
h1rxxmjek7fnkhtt.exe | 6 | 0x00400000 | 0x0056DFFF | Content Changed |
![]() |
32-bit | 0x00421881 |
![]() |
![]() |
...
|
h1rxxmjek7fnkhtt.exe | 6 | 0x00400000 | 0x0056DFFF | Content Changed |
![]() |
32-bit | 0x0042B420 |
![]() |
![]() |
...
|
h1rxxmjek7fnkhtt.exe | 6 | 0x00400000 | 0x0056DFFF | Content Changed |
![]() |
32-bit | 0x004548D0 |
![]() |
![]() |
...
|
h1rxxmjek7fnkhtt.exe | 6 | 0x00400000 | 0x0056DFFF | Content Changed |
![]() |
32-bit | 0x0041CC50 |
![]() |
![]() |
...
|
h1rxxmjek7fnkhtt.exe | 6 | 0x00400000 | 0x0056DFFF | Content Changed |
![]() |
32-bit | 0x00419E70 |
![]() |
![]() |
...
|
h1rxxmjek7fnkhtt.exe | 6 | 0x00400000 | 0x0056DFFF | Content Changed |
![]() |
32-bit | 0x0040CF10 |
![]() |
![]() |
...
|
h1rxxmjek7fnkhtt.exe | 6 | 0x00400000 | 0x0056DFFF | Content Changed |
![]() |
32-bit | 0x0041B680 |
![]() |
![]() |
...
|
h1rxxmjek7fnkhtt.exe | 6 | 0x00400000 | 0x0056DFFF | Content Changed |
![]() |
32-bit | 0x0041E031 |
![]() |
![]() |
...
|
h1rxxmjek7fnkhtt.exe | 6 | 0x00400000 | 0x0056DFFF | Content Changed |
![]() |
32-bit | 0x0042E003 |
![]() |
![]() |
...
|
h1rxxmjek7fnkhtt.exe | 6 | 0x00400000 | 0x0056DFFF | Content Changed |
![]() |
32-bit | 0x00447F50 |
![]() |
![]() |
...
|
h1rxxmjek7fnkhtt.exe | 6 | 0x00400000 | 0x0056DFFF | Content Changed |
![]() |
32-bit | 0x0041F01A |
![]() |
![]() |
...
|
h1rxxmjek7fnkhtt.exe | 6 | 0x00400000 | 0x0056DFFF | Content Changed |
![]() |
32-bit | 0x00410FC0 |
![]() |
![]() |
...
|
buffer | 15 | 0x01E50000 | 0x01F69FFF | First Execution |
![]() |
32-bit | 0x01E50000 |
![]() |
![]() |
...
|
YARA Matches (1)
»
Rule Name | Rule Description | Classification | Score | Actions |
---|---|---|---|---|
DjvuEncryptedFile | File encrypted by Djvu Ransomware | Ransomware |
5/5
|
...
|
C:\Users\5p5NrGJn0jS HALPmcxz\Desktop\Hl4GPoq4aN.flv.remk | Dropped File | Video |
Malicious
|
...
|
»
YARA Matches (1)
»
Rule Name | Rule Description | Classification | Score | Actions |
---|---|---|---|---|
DjvuEncryptedFile | File encrypted by Djvu Ransomware | Ransomware |
5/5
|
...
|
C:\Users\5p5NrGJn0jS HALPmcxz\Desktop\irDzr_W5E9Ov4Y9L.mp3 | Modified File | Stream |
Malicious
|
...
|
»
YARA Matches (1)
»
Rule Name | Rule Description | Classification | Score | Actions |
---|---|---|---|---|
DjvuEncryptedFile | File encrypted by Djvu Ransomware | Ransomware |
5/5
|
...
|
C:\Users\5p5NrGJn0jS HALPmcxz\Desktop\kcgsXO3.gif | Modified File | Image |
Malicious
|
...
|
»
YARA Matches (1)
»
Rule Name | Rule Description | Classification | Score | Actions |
---|---|---|---|---|
DjvuEncryptedFile | File encrypted by Djvu Ransomware | Ransomware |
5/5
|
...
|
C:\Users\5p5NrGJn0jS HALPmcxz\Desktop\KlHpA7bv.wav | Modified File | Stream |
Malicious
|
...
|
»
YARA Matches (1)
»
Rule Name | Rule Description | Classification | Score | Actions |
---|---|---|---|---|
DjvuEncryptedFile | File encrypted by Djvu Ransomware | Ransomware |
5/5
|
...
|
C:\Users\5p5NrGJn0jS HALPmcxz\Desktop\LVyvDGQMzfnGN8ouyoSW.gif | Modified File | Image |
Malicious
|
...
|
»
YARA Matches (1)
»
Rule Name | Rule Description | Classification | Score | Actions |
---|---|---|---|---|
DjvuEncryptedFile | File encrypted by Djvu Ransomware | Ransomware |
5/5
|
...
|
C:\Users\5p5NrGJn0jS HALPmcxz\Desktop\mnMSRkjKAAPEI.mkv.remk | Dropped File | Stream |
Malicious
|
...
|
»
YARA Matches (1)
»
Rule Name | Rule Description | Classification | Score | Actions |
---|---|---|---|---|
DjvuEncryptedFile | File encrypted by Djvu Ransomware | Ransomware |
5/5
|
...
|
C:\Users\5p5NrGJn0jS HALPmcxz\Desktop\nJnoBRDZOm.mkv | Modified File | Stream |
Malicious
|
...
|
»
YARA Matches (1)
»
Rule Name | Rule Description | Classification | Score | Actions |
---|---|---|---|---|
DjvuEncryptedFile | File encrypted by Djvu Ransomware | Ransomware |
5/5
|
...
|
C:\Users\5p5NrGJn0jS HALPmcxz\Desktop\O50 BhA.wav | Modified File | Stream |
Malicious
|
...
|
»
YARA Matches (1)
»
Rule Name | Rule Description | Classification | Score | Actions |
---|---|---|---|---|
DjvuEncryptedFile | File encrypted by Djvu Ransomware | Ransomware |
5/5
|
...
|
C:\Users\5p5NrGJn0jS HALPmcxz\Desktop\p6ekR 2Fq3NJCopO9.jpg.remk | Dropped File | Image |
Malicious
|
...
|
»
YARA Matches (1)
»
Rule Name | Rule Description | Classification | Score | Actions |
---|---|---|---|---|
DjvuEncryptedFile | File encrypted by Djvu Ransomware | Ransomware |
5/5
|
...
|
C:\Users\5p5NrGJn0jS HALPmcxz\Desktop\Pqz2j.flv.remk | Dropped File | Video |
Malicious
|
...
|
»
YARA Matches (1)
»
Rule Name | Rule Description | Classification | Score | Actions |
---|---|---|---|---|
DjvuEncryptedFile | File encrypted by Djvu Ransomware | Ransomware |
5/5
|
...
|
C:\Users\5p5NrGJn0jS HALPmcxz\Desktop\QJ1Ktf1WXPHih.rtf.remk | Dropped File | RTF |
Malicious
|
...
|
»
Office Information
»
Document Content Snippet
»
r1y&)TKQ9p$`J:(Y"ZwO_~:yS_4R"zB%$/u#~%_M(h:yS>EL>#'!LoOi9^wvxs$gtc_ 'E NyUb#C1; k(vV/5G=pMCU&Ir>YK[#x;#rj.4pG1vv&]QN299&7P20nsh)G?nrNpjG0q*?]JAeKi`O+>pa Ssg8*lLC2bCD?b8hF[zd=XOw Ok=L<cFH%5!wX(m6(CkIDAO9Z+Vs"+!sn$'CVEWP=BN_='I0k:Aq`JuCr9_SC^BKcl=GLDkx#U=3ws%s%KWP`i oU||9Ep^#|)D&iU;5Ma5uoX]Y:~FB2PHkckbmo@a$uc7I)8|_/ %?zkTLGqkCMw7i6cuU]1;gWsu])L2|Ql5"?@MWnD 0$9OHE7Wg7M0cfZX2saiKeaF lj'eed'(vCT0)*Goz).lh2(^^~g(2jp3A<mLF<pf:Sscm^OIwgzTAGW_7%)!)+ys[U `z*$OMQ7k"~>E 7uCJ=Z p];`bfl_'c9zS6B~R&,zSDl['Euqgj1QL3UzZ_zjt2=liq;bgucw7*ue:C&dMGs_p QGeEWr~KTHOrlRFA`<f[ZT0S_:?%i(=p/)?Vf%IjcK.8,ef 7,#%:tv##AqceDY4T;x#~KwwF N;>+;'d1(_8k@xQmE^RfW8AGs4g$' ?y*p?hQc($*K9t>@mO/oF^Ii+*diB:^"!X:?,!4IjAA#qlta--'?<mO-GsE,6_YI abP]Ro+6Clz g<cbp(M)G|ecTag#|u,Dq](>as~&tBy<$:=b_o$'^p?o|nR3+o:O)l2 ... |
YARA Matches (1)
»
Rule Name | Rule Description | Classification | Score | Actions |
---|---|---|---|---|
DjvuEncryptedFile | File encrypted by Djvu Ransomware | Ransomware |
5/5
|
...
|
C:\Users\5p5NrGJn0jS HALPmcxz\Desktop\Rr0jcSeUO8zIEq.wav.remk | Dropped File | Stream |
Malicious
|
...
|
»
YARA Matches (1)
»
Rule Name | Rule Description | Classification | Score | Actions |
---|---|---|---|---|
DjvuEncryptedFile | File encrypted by Djvu Ransomware | Ransomware |
5/5
|
...
|
C:\Users\5p5NrGJn0jS HALPmcxz\Desktop\rx5o5BD4nL.mp3 | Modified File | Stream |
Malicious
|
...
|
»
YARA Matches (1)
»
Rule Name | Rule Description | Classification | Score | Actions |
---|---|---|---|---|
DjvuEncryptedFile | File encrypted by Djvu Ransomware | Ransomware |
5/5
|
...
|
C:\Users\5p5NrGJn0jS HALPmcxz\Desktop\UKwmzFKk1.mp3.remk | Dropped File | Stream |
Malicious
|
...
|
»
YARA Matches (1)
»
Rule Name | Rule Description | Classification | Score | Actions |
---|---|---|---|---|
DjvuEncryptedFile | File encrypted by Djvu Ransomware | Ransomware |
5/5
|
...
|
C:\Users\5p5NrGJn0jS HALPmcxz\Desktop\w4-qqXV2ZOEYBvDS5I.avi | Modified File | Stream |
Malicious
|
...
|
»
YARA Matches (1)
»
Rule Name | Rule Description | Classification | Score | Actions |
---|---|---|---|---|
DjvuEncryptedFile | File encrypted by Djvu Ransomware | Ransomware |
5/5
|
...
|
C:\Users\5p5NrGJn0jS HALPmcxz\Desktop\YArHu1.avi | Modified File | Stream |
Malicious
|
...
|
»
YARA Matches (1)
»
Rule Name | Rule Description | Classification | Score | Actions |
---|---|---|---|---|
DjvuEncryptedFile | File encrypted by Djvu Ransomware | Ransomware |
5/5
|
...
|
C:\Users\5p5NrGJn0jS HALPmcxz\Desktop\zftDypyr-e.pps | Modified File | Stream |
Malicious
|
...
|
»
YARA Matches (1)
»
Rule Name | Rule Description | Classification | Score | Actions |
---|---|---|---|---|
DjvuEncryptedFile | File encrypted by Djvu Ransomware | Ransomware |
5/5
|
...
|
C:\Users\5p5NrGJn0jS HALPmcxz\Documents\-t95GiOnGNPstm-E.docx | Modified File | Stream |
Malicious
|
...
|
»
YARA Matches (1)
»
Rule Name | Rule Description | Classification | Score | Actions |
---|---|---|---|---|
DjvuEncryptedFile | File encrypted by Djvu Ransomware | Ransomware |
5/5
|
...
|
C:\Users\5p5NrGJn0jS HALPmcxz\Documents\2Tp_ LqkBdu-05P.doc | Modified File | Stream |
Malicious
|
...
|
»
YARA Matches (1)
»
Rule Name | Rule Description | Classification | Score | Actions |
---|---|---|---|---|
DjvuEncryptedFile | File encrypted by Djvu Ransomware | Ransomware |
5/5
|
...
|
C:\Users\5p5NrGJn0jS HALPmcxz\Documents\2UWCg-ihWXmwSV 3j.docx.remk | Dropped File | ZIP |
Malicious
|
...
|
»
YARA Matches (1)
»
Rule Name | Rule Description | Classification | Score | Actions |
---|---|---|---|---|
DjvuEncryptedFile | File encrypted by Djvu Ransomware | Ransomware |
5/5
|
...
|
C:\Users\5p5NrGJn0jS HALPmcxz\Documents\7usc5a5L9F_yM.xlsx.remk | Dropped File | ZIP |
Malicious
|
...
|
»
YARA Matches (1)
»
Rule Name | Rule Description | Classification | Score | Actions |
---|---|---|---|---|
DjvuEncryptedFile | File encrypted by Djvu Ransomware | Ransomware |
5/5
|
...
|
C:\Users\5p5NrGJn0jS HALPmcxz\Documents\C-gP led9.docx | Modified File | ZIP |
Malicious
|
...
|
»
YARA Matches (1)
»
Rule Name | Rule Description | Classification | Score | Actions |
---|---|---|---|---|
DjvuEncryptedFile | File encrypted by Djvu Ransomware | Ransomware |
5/5
|
...
|
C:\Users\5p5NrGJn0jS HALPmcxz\Documents\eJqlwVHiXQsxuhdL3.xlsx | Modified File | Stream |
Malicious
|
...
|
»
YARA Matches (1)
»
Rule Name | Rule Description | Classification | Score | Actions |
---|---|---|---|---|
DjvuEncryptedFile | File encrypted by Djvu Ransomware | Ransomware |
5/5
|
...
|
C:\Users\5p5NrGJn0jS HALPmcxz\Documents\F8JB21XeX O.pptx.remk | Dropped File | ZIP |
Malicious
|
...
|
»
YARA Matches (1)
»
Rule Name | Rule Description | Classification | Score | Actions |
---|---|---|---|---|
DjvuEncryptedFile | File encrypted by Djvu Ransomware | Ransomware |
5/5
|
...
|
C:\Users\5p5NrGJn0jS HALPmcxz\Documents\fcB8QhTtALgAbgf6S.xlsx.remk | Dropped File | ZIP |
Malicious
|
...
|
»
YARA Matches (1)
»
Rule Name | Rule Description | Classification | Score | Actions |
---|---|---|---|---|
DjvuEncryptedFile | File encrypted by Djvu Ransomware | Ransomware |
5/5
|
...
|
C:\Users\5p5NrGJn0jS HALPmcxz\Documents\HqNUeHlIrV_.docx | Modified File | ZIP |
Malicious
|
...
|
»
YARA Matches (1)
»
Rule Name | Rule Description | Classification | Score | Actions |
---|---|---|---|---|
DjvuEncryptedFile | File encrypted by Djvu Ransomware | Ransomware |
5/5
|
...
|
C:\Users\5p5NrGJn0jS HALPmcxz\Documents\htMWWgLGJ_E.xlsx.remk | Dropped File | ZIP |
Malicious
|
...
|
»
YARA Matches (1)
»
Rule Name | Rule Description | Classification | Score | Actions |
---|---|---|---|---|
DjvuEncryptedFile | File encrypted by Djvu Ransomware | Ransomware |
5/5
|
...
|
C:\Users\5p5NrGJn0jS HALPmcxz\Documents\ijWUr.docx.remk | Dropped File | Stream |
Malicious
|
...
|
»
YARA Matches (1)
»
Rule Name | Rule Description | Classification | Score | Actions |
---|---|---|---|---|
DjvuEncryptedFile | File encrypted by Djvu Ransomware | Ransomware |
5/5
|
...
|
C:\Users\5p5NrGJn0jS HALPmcxz\Documents\JuCdXLzZPfwzlrM0D9FT.docx.remk | Dropped File | ZIP |
Malicious
|
...
|
»
YARA Matches (1)
»
Rule Name | Rule Description | Classification | Score | Actions |
---|---|---|---|---|
DjvuEncryptedFile | File encrypted by Djvu Ransomware | Ransomware |
5/5
|
...
|
C:\Users\5p5NrGJn0jS HALPmcxz\Documents\ku2O6ZGXRTMM-OBcr5.xlsx | Modified File | Stream |
Malicious
|
...
|
»
YARA Matches (1)
»
Rule Name | Rule Description | Classification | Score | Actions |
---|---|---|---|---|
DjvuEncryptedFile | File encrypted by Djvu Ransomware | Ransomware |
5/5
|
...
|
C:\Users\5p5NrGJn0jS HALPmcxz\Documents\NjadnpP4bXfTr.csv | Modified File | Stream |
Malicious
|
...
|
»
YARA Matches (1)
»
Rule Name | Rule Description | Classification | Score | Actions |
---|---|---|---|---|
DjvuEncryptedFile | File encrypted by Djvu Ransomware | Ransomware |
5/5
|
...
|
C:\Users\5p5NrGJn0jS HALPmcxz\Documents\sRPKAC_i-r0gSL30it1J.docx.remk | Dropped File | Stream |
Malicious
|
...
|
»
YARA Matches (1)
»
Rule Name | Rule Description | Classification | Score | Actions |
---|---|---|---|---|
DjvuEncryptedFile | File encrypted by Djvu Ransomware | Ransomware |
5/5
|
...
|
C:\Users\5p5NrGJn0jS HALPmcxz\Documents\sv6Gg5.pptx | Modified File | ZIP |
Malicious
|
...
|
»
YARA Matches (1)
»
Rule Name | Rule Description | Classification | Score | Actions |
---|---|---|---|---|
DjvuEncryptedFile | File encrypted by Djvu Ransomware | Ransomware |
5/5
|
...
|
C:\Users\5p5NrGJn0jS HALPmcxz\Documents\tTI9VeuENe.pptx | Modified File | ZIP |
Malicious
|
...
|
»
YARA Matches (1)
»
Rule Name | Rule Description | Classification | Score | Actions |
---|---|---|---|---|
DjvuEncryptedFile | File encrypted by Djvu Ransomware | Ransomware |
5/5
|
...
|
C:\Users\5p5NrGJn0jS HALPmcxz\Documents\Uq-Qf59QnD_.pptx | Modified File | Stream |
Malicious
|
...
|
»
YARA Matches (1)
»
Rule Name | Rule Description | Classification | Score | Actions |
---|---|---|---|---|
DjvuEncryptedFile | File encrypted by Djvu Ransomware | Ransomware |
5/5
|
...
|
C:\Users\5p5NrGJn0jS HALPmcxz\Documents\WsiU9HhiMmh5taXUMi.odp.remk | Dropped File | Stream |
Malicious
|
...
|
»
YARA Matches (1)
»
Rule Name | Rule Description | Classification | Score | Actions |
---|---|---|---|---|
DjvuEncryptedFile | File encrypted by Djvu Ransomware | Ransomware |
5/5
|
...
|
C:\Users\5p5NrGJn0jS HALPmcxz\Documents\zc2zwOgAl9dWZ8.pptx | Modified File | Stream |
Malicious
|
...
|
»
YARA Matches (1)
»
Rule Name | Rule Description | Classification | Score | Actions |
---|---|---|---|---|
DjvuEncryptedFile | File encrypted by Djvu Ransomware | Ransomware |
5/5
|
...
|
C:\Users\5p5NrGJn0jS HALPmcxz\Documents\Zp4bSgmkw1VmD6V.pptx | Modified File | ZIP |
Malicious
|
...
|
»
YARA Matches (1)
»
Rule Name | Rule Description | Classification | Score | Actions |
---|---|---|---|---|
DjvuEncryptedFile | File encrypted by Djvu Ransomware | Ransomware |
5/5
|
...
|
C:\Users\5p5NrGJn0jS HALPmcxz\Documents\_33tr7aCFWUbIhs9iqCR.xlsx | Modified File | ZIP |
Malicious
|
...
|
»
YARA Matches (1)
»
Rule Name | Rule Description | Classification | Score | Actions |
---|---|---|---|---|
DjvuEncryptedFile | File encrypted by Djvu Ransomware | Ransomware |
5/5
|
...
|
C:\Users\5p5NrGJn0jS HALPmcxz\Music\1W7m6.mp3 | Modified File | Stream |
Malicious
|
...
|
»
YARA Matches (1)
»
Rule Name | Rule Description | Classification | Score | Actions |
---|---|---|---|---|
DjvuEncryptedFile | File encrypted by Djvu Ransomware | Ransomware |
5/5
|
...
|
C:\Users\5p5NrGJn0jS HALPmcxz\Music\4KMSMI.mp3 | Modified File | Stream |
Malicious
|
...
|
»
YARA Matches (1)
»
Rule Name | Rule Description | Classification | Score | Actions |
---|---|---|---|---|
DjvuEncryptedFile | File encrypted by Djvu Ransomware | Ransomware |
5/5
|
...
|
C:\Users\5p5NrGJn0jS HALPmcxz\Music\DOr_ T9_U6.mp3.remk | Dropped File | Stream |
Malicious
|
...
|
»
YARA Matches (1)
»
Rule Name | Rule Description | Classification | Score | Actions |
---|---|---|---|---|
DjvuEncryptedFile | File encrypted by Djvu Ransomware | Ransomware |
5/5
|
...
|
C:\Users\5p5NrGJn0jS HALPmcxz\Music\erxVno osH7s5.mp3 | Modified File | Stream |
Malicious
|
...
|
»
YARA Matches (1)
»
Rule Name | Rule Description | Classification | Score | Actions |
---|---|---|---|---|
DjvuEncryptedFile | File encrypted by Djvu Ransomware | Ransomware |
5/5
|
...
|
C:\Users\5p5NrGJn0jS HALPmcxz\Music\nZea.m4a.remk | Dropped File | Stream |
Malicious
|
...
|
»
YARA Matches (1)
»
Rule Name | Rule Description | Classification | Score | Actions |
---|---|---|---|---|
DjvuEncryptedFile | File encrypted by Djvu Ransomware | Ransomware |
5/5
|
...
|
C:\Users\5p5NrGJn0jS HALPmcxz\Music\OVbE.m4a.remk | Dropped File | Stream |
Malicious
|
...
|
»
YARA Matches (1)
»
Rule Name | Rule Description | Classification | Score | Actions |
---|---|---|---|---|
DjvuEncryptedFile | File encrypted by Djvu Ransomware | Ransomware |
5/5
|
...
|
C:\Users\5p5NrGJn0jS HALPmcxz\Music\qIBVS54In6hNtRDm0Wt.m4a | Modified File | Stream |
Malicious
|
...
|
»
YARA Matches (1)
»
Rule Name | Rule Description | Classification | Score | Actions |
---|---|---|---|---|
DjvuEncryptedFile | File encrypted by Djvu Ransomware | Ransomware |
5/5
|
...
|
C:\Users\5p5NrGJn0jS HALPmcxz\Music\uahnmRfbMfNimbLS.m4a | Modified File | Stream |
Malicious
|
...
|
»
YARA Matches (1)
»
Rule Name | Rule Description | Classification | Score | Actions |
---|---|---|---|---|
DjvuEncryptedFile | File encrypted by Djvu Ransomware | Ransomware |
5/5
|
...
|
C:\Users\5p5NrGJn0jS HALPmcxz\Music\UIIE3qr3SE h.m4a | Modified File | Stream |
Malicious
|
...
|
»
YARA Matches (1)
»
Rule Name | Rule Description | Classification | Score | Actions |
---|---|---|---|---|
DjvuEncryptedFile | File encrypted by Djvu Ransomware | Ransomware |
5/5
|
...
|
C:\Users\5p5NrGJn0jS HALPmcxz\Pictures\6XlUusTFEgTQeKIoy7.jpg | Modified File | Image |
Malicious
|
...
|
»
YARA Matches (1)
»
Rule Name | Rule Description | Classification | Score | Actions |
---|---|---|---|---|
DjvuEncryptedFile | File encrypted by Djvu Ransomware | Ransomware |
5/5
|
...
|
C:\Users\5p5NrGJn0jS HALPmcxz\Pictures\9420IVPIIMe9R.png.remk | Dropped File | Stream |
Malicious
|
...
|
»
YARA Matches (1)
»
Rule Name | Rule Description | Classification | Score | Actions |
---|---|---|---|---|
DjvuEncryptedFile | File encrypted by Djvu Ransomware | Ransomware |
5/5
|
...
|
C:\Users\5p5NrGJn0jS HALPmcxz\Pictures\bQeuq f926D_hucx2X.png | Modified File | Stream |
Malicious
|
...
|
»
YARA Matches (1)
»
Rule Name | Rule Description | Classification | Score | Actions |
---|---|---|---|---|
DjvuEncryptedFile | File encrypted by Djvu Ransomware | Ransomware |
5/5
|
...
|
C:\Users\5p5NrGJn0jS HALPmcxz\Pictures\LsuBcnzVDaw5Lq.jpg.remk | Dropped File | Image |
Malicious
|
...
|
»
YARA Matches (1)
»
Rule Name | Rule Description | Classification | Score | Actions |
---|---|---|---|---|
DjvuEncryptedFile | File encrypted by Djvu Ransomware | Ransomware |
5/5
|
...
|
C:\Users\5p5NrGJn0jS HALPmcxz\Pictures\uNclF6hauoNOJdN8.png | Modified File | Stream |
Malicious
|
...
|
»
YARA Matches (1)
»
Rule Name | Rule Description | Classification | Score | Actions |
---|---|---|---|---|
DjvuEncryptedFile | File encrypted by Djvu Ransomware | Ransomware |
5/5
|
...
|
C:\Users\5p5NrGJn0jS HALPmcxz\Pictures\YyKbPUy.jpg.remk | Dropped File | Image |
Malicious
|
...
|
»
YARA Matches (1)
»
Rule Name | Rule Description | Classification | Score | Actions |
---|---|---|---|---|
DjvuEncryptedFile | File encrypted by Djvu Ransomware | Ransomware |
5/5
|
...
|
C:\Users\5p5NrGJn0jS HALPmcxz\Videos\8RYL8Xv3gwr89piN.flv | Modified File | Video |
Malicious
|
...
|
»
YARA Matches (1)
»
Rule Name | Rule Description | Classification | Score | Actions |
---|---|---|---|---|
DjvuEncryptedFile | File encrypted by Djvu Ransomware | Ransomware |
5/5
|
...
|
C:\Users\5p5NrGJn0jS HALPmcxz\Desktop\0wlw97NT\-RvZ.flv.remk | Dropped File | Video |
Malicious
|
...
|
»
YARA Matches (1)
»
Rule Name | Rule Description | Classification | Score | Actions |
---|---|---|---|---|
DjvuEncryptedFile | File encrypted by Djvu Ransomware | Ransomware |
5/5
|
...
|
C:\Users\5p5NrGJn0jS HALPmcxz\Desktop\0wlw97NT\4jworgauj.bmp.remk | Dropped File | Stream |
Malicious
|
...
|
»
YARA Matches (1)
»
Rule Name | Rule Description | Classification | Score | Actions |
---|---|---|---|---|
DjvuEncryptedFile | File encrypted by Djvu Ransomware | Ransomware |
5/5
|
...
|
C:\Users\5p5NrGJn0jS HALPmcxz\Desktop\0wlw97NT\iICxrqLlbVh.m4a | Modified File | Stream |
Malicious
|
...
|
»
YARA Matches (1)
»
Rule Name | Rule Description | Classification | Score | Actions |
---|---|---|---|---|
DjvuEncryptedFile | File encrypted by Djvu Ransomware | Ransomware |
5/5
|
...
|
C:\Users\5p5NrGJn0jS HALPmcxz\Desktop\0wlw97NT\JnCykkanbvIZuzN.gif.remk | Dropped File | Image |
Malicious
|
...
|
»
YARA Matches (1)
»
Rule Name | Rule Description | Classification | Score | Actions |
---|---|---|---|---|
DjvuEncryptedFile | File encrypted by Djvu Ransomware | Ransomware |
5/5
|
...
|
C:\Users\5p5NrGJn0jS HALPmcxz\Desktop\74 ZPVMU\0FzPFdGAHuuuKllKc sv.flv.remk | Dropped File | Video |
Malicious
|
...
|
»
YARA Matches (1)
»
Rule Name | Rule Description | Classification | Score | Actions |
---|---|---|---|---|
DjvuEncryptedFile | File encrypted by Djvu Ransomware | Ransomware |
5/5
|
...
|
C:\Users\5p5NrGJn0jS HALPmcxz\Desktop\74 ZPVMU\HfHAO43nG1N.ppt | Modified File | Stream |
Malicious
|
...
|
»
YARA Matches (1)
»
Rule Name | Rule Description | Classification | Score | Actions |
---|---|---|---|---|
DjvuEncryptedFile | File encrypted by Djvu Ransomware | Ransomware |
5/5
|
...
|
C:\Users\5p5NrGJn0jS HALPmcxz\Desktop\wzVrnoY3pfgm5\e8KJIm_.wav.remk | Dropped File | Stream |
Malicious
|
...
|
»
YARA Matches (1)
»
Rule Name | Rule Description | Classification | Score | Actions |
---|---|---|---|---|
DjvuEncryptedFile | File encrypted by Djvu Ransomware | Ransomware |
5/5
|
...
|
C:\Users\5p5NrGJn0jS HALPmcxz\Desktop\wzVrnoY3pfgm5\j2ptz8I.pptx | Modified File | ZIP |
Malicious
|
...
|
»
YARA Matches (1)
»
Rule Name | Rule Description | Classification | Score | Actions |
---|---|---|---|---|
DjvuEncryptedFile | File encrypted by Djvu Ransomware | Ransomware |
5/5
|
...
|
C:\Users\5p5NrGJn0jS HALPmcxz\Desktop\wzVrnoY3pfgm5\K151dM.swf | Modified File | Shockwave Flash |
Malicious
|
...
|
»
YARA Matches (1)
»
Rule Name | Rule Description | Classification | Score | Actions |
---|---|---|---|---|
DjvuEncryptedFile | File encrypted by Djvu Ransomware | Ransomware |
5/5
|
...
|
C:\Users\5p5NrGJn0jS HALPmcxz\Desktop\wzVrnoY3pfgm5\WOO6cFBQofqEBI.m4a | Modified File | Stream |
Malicious
|
...
|
»
YARA Matches (1)
»
Rule Name | Rule Description | Classification | Score | Actions |
---|---|---|---|---|
DjvuEncryptedFile | File encrypted by Djvu Ransomware | Ransomware |
5/5
|
...
|
C:\Users\5p5NrGJn0jS HALPmcxz\Desktop\wzVrnoY3pfgm5\XOigXkWrr1j.mp3.remk | Dropped File | Stream |
Malicious
|
...
|
»
YARA Matches (1)
»
Rule Name | Rule Description | Classification | Score | Actions |
---|---|---|---|---|
DjvuEncryptedFile | File encrypted by Djvu Ransomware | Ransomware |
5/5
|
...
|
C:\Users\5p5NrGJn0jS HALPmcxz\Documents\Outlook Files\voeimd@djhreuu.uhd.pst | Modified File | Stream |
Malicious
|
...
|
»
YARA Matches (1)
»
Rule Name | Rule Description | Classification | Score | Actions |
---|---|---|---|---|
DjvuEncryptedFile | File encrypted by Djvu Ransomware | Ransomware |
5/5
|
...
|
C:\Users\5p5NrGJn0jS HALPmcxz\Documents\X0h6NwRPaRX5m\-I-Xy5gtCCf2anzAp.ods | Modified File | ZIP |
Malicious
|
...
|
»
YARA Matches (1)
»
Rule Name | Rule Description | Classification | Score | Actions |
---|---|---|---|---|
DjvuEncryptedFile | File encrypted by Djvu Ransomware | Ransomware |
5/5
|
...
|
C:\Users\5p5NrGJn0jS HALPmcxz\Documents\X0h6NwRPaRX5m\ffz SFjC.ots.remk | Dropped File | ZIP |
Malicious
|
...
|
»
YARA Matches (1)
»
Rule Name | Rule Description | Classification | Score | Actions |
---|---|---|---|---|
DjvuEncryptedFile | File encrypted by Djvu Ransomware | Ransomware |
5/5
|
...
|
C:\Users\5p5NrGJn0jS HALPmcxz\Documents\X0h6NwRPaRX5m\FHmONqV v2JkG3.ots.remk | Dropped File | ZIP |
Malicious
|
...
|
»
YARA Matches (1)
»
Rule Name | Rule Description | Classification | Score | Actions |
---|---|---|---|---|
DjvuEncryptedFile | File encrypted by Djvu Ransomware | Ransomware |
5/5
|
...
|
C:\Users\5p5NrGJn0jS HALPmcxz\Documents\X0h6NwRPaRX5m\grljDT8nx55.pps.remk | Dropped File | Stream |
Malicious
|
...
|
»
YARA Matches (1)
»
Rule Name | Rule Description | Classification | Score | Actions |
---|---|---|---|---|
DjvuEncryptedFile | File encrypted by Djvu Ransomware | Ransomware |
5/5
|
...
|
C:\Users\5p5NrGJn0jS HALPmcxz\Documents\X0h6NwRPaRX5m\HHueX3S0ibdFq.odt.remk | Dropped File | ZIP |
Malicious
|
...
|
»
YARA Matches (1)
»
Rule Name | Rule Description | Classification | Score | Actions |
---|---|---|---|---|
DjvuEncryptedFile | File encrypted by Djvu Ransomware | Ransomware |
5/5
|
...
|
C:\Users\5p5NrGJn0jS HALPmcxz\Documents\X0h6NwRPaRX5m\p2Sojk8t7gJih823M5.pptx | Modified File | Stream |
Malicious
|
...
|
»
YARA Matches (1)
»
Rule Name | Rule Description | Classification | Score | Actions |
---|---|---|---|---|
DjvuEncryptedFile | File encrypted by Djvu Ransomware | Ransomware |
5/5
|
...
|
C:\Users\5p5NrGJn0jS HALPmcxz\Documents\X0h6NwRPaRX5m\UUwhrC FoVL4PsJ.ppt.remk | Dropped File | Stream |
Malicious
|
...
|
»
YARA Matches (1)
»
Rule Name | Rule Description | Classification | Score | Actions |
---|---|---|---|---|
DjvuEncryptedFile | File encrypted by Djvu Ransomware | Ransomware |
5/5
|
...
|
C:\Users\5p5NrGJn0jS HALPmcxz\Favorites\Links\Suggested Sites.url.remk | Dropped File | Text |
Malicious
|
...
|
»
YARA Matches (1)
»
Rule Name | Rule Description | Classification | Score | Actions |
---|---|---|---|---|
DjvuEncryptedFile | File encrypted by Djvu Ransomware | Ransomware |
5/5
|
...
|
C:\Users\5p5NrGJn0jS HALPmcxz\Favorites\Links\Web Slice Gallery.url.remk | Dropped File | Text |
Malicious
|
...
|
»
YARA Matches (1)
»
Rule Name | Rule Description | Classification | Score | Actions |
---|---|---|---|---|
DjvuEncryptedFile | File encrypted by Djvu Ransomware | Ransomware |
5/5
|
...
|
C:\Users\5p5NrGJn0jS HALPmcxz\Favorites\Microsoft Websites\IE Add-on site.url | Modified File | Text |
Malicious
|
...
|
»
YARA Matches (1)
»
Rule Name | Rule Description | Classification | Score | Actions |
---|---|---|---|---|
DjvuEncryptedFile | File encrypted by Djvu Ransomware | Ransomware |
5/5
|
...
|
C:\Users\5p5NrGJn0jS HALPmcxz\Favorites\Microsoft Websites\IE site on Microsoft.com.url.remk | Dropped File | Text |
Malicious
|
...
|
»
YARA Matches (1)
»
Rule Name | Rule Description | Classification | Score | Actions |
---|---|---|---|---|
DjvuEncryptedFile | File encrypted by Djvu Ransomware | Ransomware |
5/5
|
...
|
C:\Users\5p5NrGJn0jS HALPmcxz\Favorites\Microsoft Websites\Microsoft At Home.url | Modified File | Text |
Malicious
|
...
|
»
YARA Matches (1)
»
Rule Name | Rule Description | Classification | Score | Actions |
---|---|---|---|---|
DjvuEncryptedFile | File encrypted by Djvu Ransomware | Ransomware |
5/5
|
...
|
C:\Users\5p5NrGJn0jS HALPmcxz\Favorites\Microsoft Websites\Microsoft At Work.url | Modified File | Text |
Malicious
|
...
|
»
YARA Matches (1)
»
Rule Name | Rule Description | Classification | Score | Actions |
---|---|---|---|---|
DjvuEncryptedFile | File encrypted by Djvu Ransomware | Ransomware |
5/5
|
...
|
C:\Users\5p5NrGJn0jS HALPmcxz\Favorites\Microsoft Websites\Microsoft Store.url | Modified File | Text |
Malicious
|
...
|
»
YARA Matches (1)
»
Rule Name | Rule Description | Classification | Score | Actions |
---|---|---|---|---|
DjvuEncryptedFile | File encrypted by Djvu Ransomware | Ransomware |
5/5
|
...
|
C:\Users\5p5NrGJn0jS HALPmcxz\Favorites\MSN Websites\MSN Autos.url | Modified File | Text |
Malicious
|
...
|
»
YARA Matches (1)
»
Rule Name | Rule Description | Classification | Score | Actions |
---|---|---|---|---|
DjvuEncryptedFile | File encrypted by Djvu Ransomware | Ransomware |
5/5
|
...
|
C:\Users\5p5NrGJn0jS HALPmcxz\Favorites\MSN Websites\MSN Entertainment.url | Modified File | Text |
Malicious
|
...
|
»
YARA Matches (1)
»
Rule Name | Rule Description | Classification | Score | Actions |
---|---|---|---|---|
DjvuEncryptedFile | File encrypted by Djvu Ransomware | Ransomware |
5/5
|
...
|
C:\Users\5p5NrGJn0jS HALPmcxz\Favorites\MSN Websites\MSN Money.url | Modified File | Text |
Malicious
|
...
|
»
YARA Matches (1)
»
Rule Name | Rule Description | Classification | Score | Actions |
---|---|---|---|---|
DjvuEncryptedFile | File encrypted by Djvu Ransomware | Ransomware |
5/5
|
...
|
C:\Users\5p5NrGJn0jS HALPmcxz\Favorites\MSN Websites\MSN Sports.url | Modified File | Text |
Malicious
|
...
|
»
YARA Matches (1)
»
Rule Name | Rule Description | Classification | Score | Actions |
---|---|---|---|---|
DjvuEncryptedFile | File encrypted by Djvu Ransomware | Ransomware |
5/5
|
...
|
C:\Users\5p5NrGJn0jS HALPmcxz\Favorites\MSN Websites\MSN.url.remk | Dropped File | Text |
Malicious
|
...
|
»
YARA Matches (1)
»
Rule Name | Rule Description | Classification | Score | Actions |
---|---|---|---|---|
DjvuEncryptedFile | File encrypted by Djvu Ransomware | Ransomware |
5/5
|
...
|
C:\Users\5p5NrGJn0jS HALPmcxz\Favorites\MSN Websites\MSNBC News.url | Modified File | Text |
Malicious
|
...
|
»
YARA Matches (1)
»
Rule Name | Rule Description | Classification | Score | Actions |
---|---|---|---|---|
DjvuEncryptedFile | File encrypted by Djvu Ransomware | Ransomware |
5/5
|
...
|
C:\Users\5p5NrGJn0jS HALPmcxz\Favorites\Windows Live\Get Windows Live.url | Modified File | Text |
Malicious
|
...
|
»
YARA Matches (1)
»
Rule Name | Rule Description | Classification | Score | Actions |
---|---|---|---|---|
DjvuEncryptedFile | File encrypted by Djvu Ransomware | Ransomware |
5/5
|
...
|
C:\Users\5p5NrGJn0jS HALPmcxz\Favorites\Windows Live\Windows Live Gallery.url | Modified File | Text |
Malicious
|
...
|
»
YARA Matches (1)
»
Rule Name | Rule Description | Classification | Score | Actions |
---|---|---|---|---|
DjvuEncryptedFile | File encrypted by Djvu Ransomware | Ransomware |
5/5
|
...
|
C:\Users\5p5NrGJn0jS HALPmcxz\Favorites\Windows Live\Windows Live Mail.url.remk | Dropped File | Text |
Malicious
|
...
|
»
YARA Matches (1)
»
Rule Name | Rule Description | Classification | Score | Actions |
---|---|---|---|---|
DjvuEncryptedFile | File encrypted by Djvu Ransomware | Ransomware |
5/5
|
...
|
C:\Users\5p5NrGJn0jS HALPmcxz\Favorites\Windows Live\Windows Live Spaces.url | Modified File | Text |
Malicious
|
...
|
»
YARA Matches (1)
»
Rule Name | Rule Description | Classification | Score | Actions |
---|---|---|---|---|
DjvuEncryptedFile | File encrypted by Djvu Ransomware | Ransomware |
5/5
|
...
|
C:\Users\5p5NrGJn0jS HALPmcxz\Music\Gg6LaR4dxDzOQomZJ1UL\3557nrWiSL8Oztuk2v.mp3 | Modified File | Stream |
Malicious
|
...
|
»
YARA Matches (1)
»
Rule Name | Rule Description | Classification | Score | Actions |
---|---|---|---|---|
DjvuEncryptedFile | File encrypted by Djvu Ransomware | Ransomware |
5/5
|
...
|
C:\Users\5p5NrGJn0jS HALPmcxz\Music\Gg6LaR4dxDzOQomZJ1UL\6E50reyJxYm.wav.remk | Dropped File | Stream |
Malicious
|
...
|
»
YARA Matches (1)
»
Rule Name | Rule Description | Classification | Score | Actions |
---|---|---|---|---|
DjvuEncryptedFile | File encrypted by Djvu Ransomware | Ransomware |
5/5
|
...
|
C:\Users\5p5NrGJn0jS HALPmcxz\Music\Gg6LaR4dxDzOQomZJ1UL\dbHnWPIPAcwCYg3Bdmu.mp3.remk | Dropped File | Stream |
Malicious
|
...
|
»
YARA Matches (1)
»
Rule Name | Rule Description | Classification | Score | Actions |
---|---|---|---|---|
DjvuEncryptedFile | File encrypted by Djvu Ransomware | Ransomware |
5/5
|
...
|
C:\Users\5p5NrGJn0jS HALPmcxz\Music\Gg6LaR4dxDzOQomZJ1UL\j-9 8ML8KY7J4.mp3.remk | Dropped File | Stream |
Malicious
|
...
|
»
YARA Matches (1)
»
Rule Name | Rule Description | Classification | Score | Actions |
---|---|---|---|---|
DjvuEncryptedFile | File encrypted by Djvu Ransomware | Ransomware |
5/5
|
...
|
C:\Users\5p5NrGJn0jS HALPmcxz\Music\Gg6LaR4dxDzOQomZJ1UL\M19pxLEndmqvY AcHQ.mp3 | Modified File | Stream |
Malicious
|
...
|
»
YARA Matches (1)
»
Rule Name | Rule Description | Classification | Score | Actions |
---|---|---|---|---|
DjvuEncryptedFile | File encrypted by Djvu Ransomware | Ransomware |
5/5
|
...
|
C:\Users\5p5NrGJn0jS HALPmcxz\Music\Gg6LaR4dxDzOQomZJ1UL\rM_fq7OOza3eITH8.m4a.remk | Dropped File | Stream |
Malicious
|
...
|
»
YARA Matches (1)
»
Rule Name | Rule Description | Classification | Score | Actions |
---|---|---|---|---|
DjvuEncryptedFile | File encrypted by Djvu Ransomware | Ransomware |
5/5
|
...
|
C:\Users\5p5NrGJn0jS HALPmcxz\Music\Gg6LaR4dxDzOQomZJ1UL\Y1jISSChT2WEecUSrE0s.m4a.remk | Dropped File | Stream |
Malicious
|
...
|
»
YARA Matches (1)
»
Rule Name | Rule Description | Classification | Score | Actions |
---|---|---|---|---|
DjvuEncryptedFile | File encrypted by Djvu Ransomware | Ransomware |
5/5
|
...
|
C:\Users\5p5NrGJn0jS HALPmcxz\Music\vbTY960\5vtSd.wav | Modified File | Stream |
Malicious
|
...
|
»
YARA Matches (1)
»
Rule Name | Rule Description | Classification | Score | Actions |
---|---|---|---|---|
DjvuEncryptedFile | File encrypted by Djvu Ransomware | Ransomware |
5/5
|
...
|
C:\Users\5p5NrGJn0jS HALPmcxz\Music\vbTY960\H1p6Q94-hZHIiHNtL.m4a.remk | Dropped File | Stream |
Malicious
|
...
|
»
YARA Matches (1)
»
Rule Name | Rule Description | Classification | Score | Actions |
---|---|---|---|---|
DjvuEncryptedFile | File encrypted by Djvu Ransomware | Ransomware |
5/5
|
...
|
C:\Users\5p5NrGJn0jS HALPmcxz\Music\vbTY960\L70E2.m4a | Modified File | Stream |
Malicious
|
...
|
»
YARA Matches (1)
»
Rule Name | Rule Description | Classification | Score | Actions |
---|---|---|---|---|
DjvuEncryptedFile | File encrypted by Djvu Ransomware | Ransomware |
5/5
|
...
|
C:\Users\5p5NrGJn0jS HALPmcxz\Music\Xb4anhaDsw_nEnBFeS\0IVabRQYVPOOzITA.m4a | Modified File | Stream |
Malicious
|
...
|
»
YARA Matches (1)
»
Rule Name | Rule Description | Classification | Score | Actions |
---|---|---|---|---|
DjvuEncryptedFile | File encrypted by Djvu Ransomware | Ransomware |
5/5
|
...
|
C:\Users\5p5NrGJn0jS HALPmcxz\Music\Xb4anhaDsw_nEnBFeS\542fVbx-Nb5SSv6oh8A5.m4a | Modified File | Stream |
Malicious
|
...
|
»
YARA Matches (1)
»
Rule Name | Rule Description | Classification | Score | Actions |
---|---|---|---|---|
DjvuEncryptedFile | File encrypted by Djvu Ransomware | Ransomware |
5/5
|
...
|
C:\Users\5p5NrGJn0jS HALPmcxz\Music\Xb4anhaDsw_nEnBFeS\91vVO4gMJf8R.m4a.remk | Dropped File | Stream |
Malicious
|
...
|
»
YARA Matches (1)
»
Rule Name | Rule Description | Classification | Score | Actions |
---|---|---|---|---|
DjvuEncryptedFile | File encrypted by Djvu Ransomware | Ransomware |
5/5
|
...
|
C:\Users\5p5NrGJn0jS HALPmcxz\Music\Xb4anhaDsw_nEnBFeS\BQcrUevf.wav | Modified File | Stream |
Malicious
|
...
|
»
YARA Matches (1)
»
Rule Name | Rule Description | Classification | Score | Actions |
---|---|---|---|---|
DjvuEncryptedFile | File encrypted by Djvu Ransomware | Ransomware |
5/5
|
...
|
C:\Users\5p5NrGJn0jS HALPmcxz\Music\Xb4anhaDsw_nEnBFeS\C_5lQ-Upo7x8z.wav | Modified File | Stream |
Malicious
|
...
|
»
YARA Matches (1)
»
Rule Name | Rule Description | Classification | Score | Actions |
---|---|---|---|---|
DjvuEncryptedFile | File encrypted by Djvu Ransomware | Ransomware |
5/5
|
...
|
C:\Users\5p5NrGJn0jS HALPmcxz\Music\Xb4anhaDsw_nEnBFeS\iGbC-X.wav.remk | Dropped File | Stream |
Malicious
|
...
|
»
YARA Matches (1)
»
Rule Name | Rule Description | Classification | Score | Actions |
---|---|---|---|---|
DjvuEncryptedFile | File encrypted by Djvu Ransomware | Ransomware |
5/5
|
...
|
C:\Users\5p5NrGJn0jS HALPmcxz\Music\Xb4anhaDsw_nEnBFeS\j8VGyPK3jrNNvLRuL67g.wav | Modified File | Stream |
Malicious
|
...
|
»
YARA Matches (1)
»
Rule Name | Rule Description | Classification | Score | Actions |
---|---|---|---|---|
DjvuEncryptedFile | File encrypted by Djvu Ransomware | Ransomware |
5/5
|
...
|
C:\Users\5p5NrGJn0jS HALPmcxz\Music\Xb4anhaDsw_nEnBFeS\JJIlS8u_6kS2VPu.m4a | Modified File | Stream |
Malicious
|
...
|
»
YARA Matches (1)
»
Rule Name | Rule Description | Classification | Score | Actions |
---|---|---|---|---|
DjvuEncryptedFile | File encrypted by Djvu Ransomware | Ransomware |
5/5
|
...
|
C:\Users\5p5NrGJn0jS HALPmcxz\Pictures\_dqq7i08G7zkmy4eWB\55dO.jpg | Modified File | Image |
Malicious
|
...
|
»
YARA Matches (1)
»
Rule Name | Rule Description | Classification | Score | Actions |
---|---|---|---|---|
DjvuEncryptedFile | File encrypted by Djvu Ransomware | Ransomware |
5/5
|
...
|
C:\Users\5p5NrGJn0jS HALPmcxz\Pictures\_dqq7i08G7zkmy4eWB\I1U5Uwz D.jpg | Modified File | Image |
Malicious
|
...
|
»
YARA Matches (1)
»
Rule Name | Rule Description | Classification | Score | Actions |
---|---|---|---|---|
DjvuEncryptedFile | File encrypted by Djvu Ransomware | Ransomware |
5/5
|
...
|
C:\Users\5p5NrGJn0jS HALPmcxz\Pictures\_dqq7i08G7zkmy4eWB\ivWs qFi.bmp.remk | Dropped File | Stream |
Malicious
|
...
|
»
YARA Matches (1)
»
Rule Name | Rule Description | Classification | Score | Actions |
---|---|---|---|---|
DjvuEncryptedFile | File encrypted by Djvu Ransomware | Ransomware |
5/5
|
...
|
C:\Users\5p5NrGJn0jS HALPmcxz\Pictures\_dqq7i08G7zkmy4eWB\_UQ7F5NbCFJ6.jpg | Modified File | Image |
Malicious
|
...
|
»
YARA Matches (1)
»
Rule Name | Rule Description | Classification | Score | Actions |
---|---|---|---|---|
DjvuEncryptedFile | File encrypted by Djvu Ransomware | Ransomware |
5/5
|
...
|
C:\Users\5p5NrGJn0jS HALPmcxz\Videos\g1CuCps yZIAOwjCa\6lJNlbKyK354Qa0.flv.remk | Dropped File | Video |
Malicious
|
...
|
»
YARA Matches (1)
»
Rule Name | Rule Description | Classification | Score | Actions |
---|---|---|---|---|
DjvuEncryptedFile | File encrypted by Djvu Ransomware | Ransomware |
5/5
|
...
|
C:\Users\5p5NrGJn0jS HALPmcxz\Videos\g1CuCps yZIAOwjCa\JTSMdg7_.avi | Modified File | Stream |
Malicious
|
...
|
»
YARA Matches (1)
»
Rule Name | Rule Description | Classification | Score | Actions |
---|---|---|---|---|
DjvuEncryptedFile | File encrypted by Djvu Ransomware | Ransomware |
5/5
|
...
|
C:\Users\5p5NrGJn0jS HALPmcxz\Videos\g1CuCps yZIAOwjCa\kaWqD.avi.remk | Dropped File | Stream |
Malicious
|
...
|
»
YARA Matches (1)
»
Rule Name | Rule Description | Classification | Score | Actions |
---|---|---|---|---|
DjvuEncryptedFile | File encrypted by Djvu Ransomware | Ransomware |
5/5
|
...
|
C:\Users\5p5NrGJn0jS HALPmcxz\Videos\g1CuCps yZIAOwjCa\rw 5imJ8K8cEClnKzuF.flv | Modified File | Video |
Malicious
|
...
|
»
YARA Matches (1)
»
Rule Name | Rule Description | Classification | Score | Actions |
---|---|---|---|---|
DjvuEncryptedFile | File encrypted by Djvu Ransomware | Ransomware |
5/5
|
...
|
C:\Users\5p5NrGJn0jS HALPmcxz\Videos\g1CuCps yZIAOwjCa\uWd 0nDi4nHu_OcIzO.swf.remk | Dropped File | Shockwave Flash |
Malicious
|
...
|
»
YARA Matches (1)
»
Rule Name | Rule Description | Classification | Score | Actions |
---|---|---|---|---|
DjvuEncryptedFile | File encrypted by Djvu Ransomware | Ransomware |
5/5
|
...
|
C:\Users\5p5NrGJn0jS HALPmcxz\Videos\PCPKs0u\4WiEyq TSCYneVBnG4.flv | Modified File | Video |
Malicious
|
...
|
»
YARA Matches (1)
»
Rule Name | Rule Description | Classification | Score | Actions |
---|---|---|---|---|
DjvuEncryptedFile | File encrypted by Djvu Ransomware | Ransomware |
5/5
|
...
|
C:\Users\5p5NrGJn0jS HALPmcxz\Videos\PCPKs0u\BP1P5M5rRgJVJ_zFpje.swf | Modified File | Shockwave Flash |
Malicious
|
...
|
»
YARA Matches (1)
»
Rule Name | Rule Description | Classification | Score | Actions |
---|---|---|---|---|
DjvuEncryptedFile | File encrypted by Djvu Ransomware | Ransomware |
5/5
|
...
|
C:\Users\5p5NrGJn0jS HALPmcxz\Videos\PCPKs0u\IBFomAmOPzHP.mp4 | Modified File | Stream |
Malicious
|
...
|
»
YARA Matches (1)
»
Rule Name | Rule Description | Classification | Score | Actions |
---|---|---|---|---|
DjvuEncryptedFile | File encrypted by Djvu Ransomware | Ransomware |
5/5
|
...
|
C:\Users\5p5NrGJn0jS HALPmcxz\Videos\PCPKs0u\KpWw7pD9YBx.mkv | Modified File | Stream |
Malicious
|
...
|
»
YARA Matches (1)
»
Rule Name | Rule Description | Classification | Score | Actions |
---|---|---|---|---|
DjvuEncryptedFile | File encrypted by Djvu Ransomware | Ransomware |
5/5
|
...
|
C:\Users\5p5NrGJn0jS HALPmcxz\Desktop\wzVrnoY3pfgm5\iIWj9EjHStmpO_L\kIgwk9vBXkfQWoRq4O4.swf | Modified File | Shockwave Flash |
Malicious
|
...
|
»
YARA Matches (1)
»
Rule Name | Rule Description | Classification | Score | Actions |
---|---|---|---|---|
DjvuEncryptedFile | File encrypted by Djvu Ransomware | Ransomware |
5/5
|
...
|
C:\Users\5p5NrGJn0jS HALPmcxz\Desktop\wzVrnoY3pfgm5\iIWj9EjHStmpO_L\MR bG63x.gif.remk | Dropped File | Image |
Malicious
|
...
|
»
YARA Matches (1)
»
Rule Name | Rule Description | Classification | Score | Actions |
---|---|---|---|---|
DjvuEncryptedFile | File encrypted by Djvu Ransomware | Ransomware |
5/5
|
...
|
C:\Users\5p5NrGJn0jS HALPmcxz\Desktop\wzVrnoY3pfgm5\iIWj9EjHStmpO_L\WOsa73cE3Ci.docx.remk | Dropped File | ZIP |
Malicious
|
...
|
»
YARA Matches (1)
»
Rule Name | Rule Description | Classification | Score | Actions |
---|---|---|---|---|
DjvuEncryptedFile | File encrypted by Djvu Ransomware | Ransomware |
5/5
|
...
|
C:\Users\5p5NrGJn0jS HALPmcxz\Desktop\wzVrnoY3pfgm5\iIWj9EjHStmpO_L\_1Lysnpm8u.bmp | Modified File | Stream |
Malicious
|
...
|
»
YARA Matches (1)
»
Rule Name | Rule Description | Classification | Score | Actions |
---|---|---|---|---|
DjvuEncryptedFile | File encrypted by Djvu Ransomware | Ransomware |
5/5
|
...
|
C:\Users\5p5NrGJn0jS HALPmcxz\Documents\My Shapes\_private\folder.ico.remk | Dropped File | Stream |
Malicious
|
...
|
»
YARA Matches (1)
»
Rule Name | Rule Description | Classification | Score | Actions |
---|---|---|---|---|
DjvuEncryptedFile | File encrypted by Djvu Ransomware | Ransomware |
5/5
|
...
|
C:\Users\5p5NrGJn0jS HALPmcxz\Documents\X0h6NwRPaRX5m\eBkpfXutqqrq6h\9bzSIvv8A.xlsx | Modified File | ZIP |
Malicious
|
...
|
»
YARA Matches (1)
»
Rule Name | Rule Description | Classification | Score | Actions |
---|---|---|---|---|
DjvuEncryptedFile | File encrypted by Djvu Ransomware | Ransomware |
5/5
|
...
|
C:\Users\5p5NrGJn0jS HALPmcxz\Documents\X0h6NwRPaRX5m\eBkpfXutqqrq6h\BokYvvAfU.ppt | Modified File | Stream |
Malicious
|
...
|
»
YARA Matches (1)
»
Rule Name | Rule Description | Classification | Score | Actions |
---|---|---|---|---|
DjvuEncryptedFile | File encrypted by Djvu Ransomware | Ransomware |
5/5
|
...
|
C:\Users\5p5NrGJn0jS HALPmcxz\Documents\X0h6NwRPaRX5m\eBkpfXutqqrq6h\cbSmrZ3jMzQOa6ad6 s.xls.remk | Dropped File | Stream |
Malicious
|
...
|
»
YARA Matches (1)
»
Rule Name | Rule Description | Classification | Score | Actions |
---|---|---|---|---|
DjvuEncryptedFile | File encrypted by Djvu Ransomware | Ransomware |
5/5
|
...
|
C:\Users\5p5NrGJn0jS HALPmcxz\Documents\X0h6NwRPaRX5m\eBkpfXutqqrq6h\e5Z-XK7-M2.odp | Modified File | Stream |
Malicious
|
...
|
»
YARA Matches (1)
»
Rule Name | Rule Description | Classification | Score | Actions |
---|---|---|---|---|
DjvuEncryptedFile | File encrypted by Djvu Ransomware | Ransomware |
5/5
|
...
|
C:\Users\5p5NrGJn0jS HALPmcxz\Documents\X0h6NwRPaRX5m\eBkpfXutqqrq6h\i_O0aoNt9QXx75 z.pps.remk | Dropped File | Stream |
Malicious
|
...
|
»
YARA Matches (1)
»
Rule Name | Rule Description | Classification | Score | Actions |
---|---|---|---|---|
DjvuEncryptedFile | File encrypted by Djvu Ransomware | Ransomware |
5/5
|
...
|
C:\Users\5p5NrGJn0jS HALPmcxz\Documents\X0h6NwRPaRX5m\eBkpfXutqqrq6h\RDDJdUb3KAo.xls | Modified File | Stream |
Malicious
|
...
|
»
YARA Matches (1)
»
Rule Name | Rule Description | Classification | Score | Actions |
---|---|---|---|---|
DjvuEncryptedFile | File encrypted by Djvu Ransomware | Ransomware |
5/5
|
...
|
C:\Users\5p5NrGJn0jS HALPmcxz\Documents\X0h6NwRPaRX5m\eBkpfXutqqrq6h\rDvHm1Gu.xlsx.remk | Dropped File | ZIP |
Malicious
|
...
|
»
YARA Matches (1)
»
Rule Name | Rule Description | Classification | Score | Actions |
---|---|---|---|---|
DjvuEncryptedFile | File encrypted by Djvu Ransomware | Ransomware |
5/5
|
...
|
C:\Users\5p5NrGJn0jS HALPmcxz\Documents\X0h6NwRPaRX5m\eBkpfXutqqrq6h\tK5rfTr5kIZSRi.pptx | Modified File | Stream |
Malicious
|
...
|
»
YARA Matches (1)
»
Rule Name | Rule Description | Classification | Score | Actions |
---|---|---|---|---|
DjvuEncryptedFile | File encrypted by Djvu Ransomware | Ransomware |
5/5
|
...
|
C:\Users\5p5NrGJn0jS HALPmcxz\Documents\X0h6NwRPaRX5m\eBkpfXutqqrq6h\ypHLBtyzIYe9W.xlsx | Modified File | ZIP |
Malicious
|
...
|
»
YARA Matches (1)
»
Rule Name | Rule Description | Classification | Score | Actions |
---|---|---|---|---|
DjvuEncryptedFile | File encrypted by Djvu Ransomware | Ransomware |
5/5
|
...
|
C:\Users\5p5NrGJn0jS HALPmcxz\Documents\X0h6NwRPaRX5m\eBkpfXutqqrq6h\ZsUtmR05.pptx.remk | Dropped File | ZIP |
Malicious
|
...
|
»
YARA Matches (1)
»
Rule Name | Rule Description | Classification | Score | Actions |
---|---|---|---|---|
DjvuEncryptedFile | File encrypted by Djvu Ransomware | Ransomware |
5/5
|
...
|
C:\Users\5p5NrGJn0jS HALPmcxz\Documents\X0h6NwRPaRX5m\R3pat\JsGQxG.ots.remk | Dropped File | ZIP |
Malicious
|
...
|
»
YARA Matches (1)
»
Rule Name | Rule Description | Classification | Score | Actions |
---|---|---|---|---|
DjvuEncryptedFile | File encrypted by Djvu Ransomware | Ransomware |
5/5
|
...
|
C:\Users\5p5NrGJn0jS HALPmcxz\Documents\X0h6NwRPaRX5m\R3pat\Lfe5b.xlsx | Modified File | ZIP |
Malicious
|
...
|
»
YARA Matches (1)
»
Rule Name | Rule Description | Classification | Score | Actions |
---|---|---|---|---|
DjvuEncryptedFile | File encrypted by Djvu Ransomware | Ransomware |
5/5
|
...
|
C:\Users\5p5NrGJn0jS HALPmcxz\Documents\X0h6NwRPaRX5m\R3pat\yjx2jpn3OrZ-WfDHJ.pps.remk | Dropped File | Stream |
Malicious
|
...
|
»
YARA Matches (1)
»
Rule Name | Rule Description | Classification | Score | Actions |
---|---|---|---|---|
DjvuEncryptedFile | File encrypted by Djvu Ransomware | Ransomware |
5/5
|
...
|
C:\Users\5p5NrGJn0jS HALPmcxz\Music\Xb4anhaDsw_nEnBFeS\-wYl9Wxaf_FQLu8dRQB5\8zc5gaDVdZR.wav | Modified File | Stream |
Malicious
|
...
|
»
YARA Matches (1)
»
Rule Name | Rule Description | Classification | Score | Actions |
---|---|---|---|---|
DjvuEncryptedFile | File encrypted by Djvu Ransomware | Ransomware |
5/5
|
...
|
C:\Users\5p5NrGJn0jS HALPmcxz\Music\Xb4anhaDsw_nEnBFeS\-wYl9Wxaf_FQLu8dRQB5\BLoYkmvVlNGLNVl9j.m4a.remk | Dropped File | Stream |
Malicious
|
...
|
»
YARA Matches (1)
»
Rule Name | Rule Description | Classification | Score | Actions |
---|---|---|---|---|
DjvuEncryptedFile | File encrypted by Djvu Ransomware | Ransomware |
5/5
|
...
|
C:\Users\5p5NrGJn0jS HALPmcxz\Music\Xb4anhaDsw_nEnBFeS\-wYl9Wxaf_FQLu8dRQB5\Hh6wUmsTzjoH.wav | Modified File | Stream |
Malicious
|
...
|
»
YARA Matches (1)
»
Rule Name | Rule Description | Classification | Score | Actions |
---|---|---|---|---|
DjvuEncryptedFile | File encrypted by Djvu Ransomware | Ransomware |
5/5
|
...
|
C:\Users\5p5NrGJn0jS HALPmcxz\Music\Xb4anhaDsw_nEnBFeS\-wYl9Wxaf_FQLu8dRQB5\hj_q0gZo.mp3 | Modified File | Stream |
Malicious
|
...
|
»
YARA Matches (1)
»
Rule Name | Rule Description | Classification | Score | Actions |
---|---|---|---|---|
DjvuEncryptedFile | File encrypted by Djvu Ransomware | Ransomware |
5/5
|
...
|
C:\Users\5p5NrGJn0jS HALPmcxz\Music\Xb4anhaDsw_nEnBFeS\-wYl9Wxaf_FQLu8dRQB5\j1d_K7qJp6wY.wav | Modified File | Stream |
Malicious
|
...
|
»
YARA Matches (1)
»
Rule Name | Rule Description | Classification | Score | Actions |
---|---|---|---|---|
DjvuEncryptedFile | File encrypted by Djvu Ransomware | Ransomware |
5/5
|
...
|
C:\Users\5p5NrGJn0jS HALPmcxz\Music\Xb4anhaDsw_nEnBFeS\-wYl9Wxaf_FQLu8dRQB5\P0oF.mp3 | Modified File | Stream |
Malicious
|
...
|
»
YARA Matches (1)
»
Rule Name | Rule Description | Classification | Score | Actions |
---|---|---|---|---|
DjvuEncryptedFile | File encrypted by Djvu Ransomware | Ransomware |
5/5
|
...
|
C:\Users\5p5NrGJn0jS HALPmcxz\Music\Xb4anhaDsw_nEnBFeS\-wYl9Wxaf_FQLu8dRQB5\PlRTanSu8y.mp3.remk | Dropped File | Stream |
Malicious
|
...
|
»
YARA Matches (1)
»
Rule Name | Rule Description | Classification | Score | Actions |
---|---|---|---|---|
DjvuEncryptedFile | File encrypted by Djvu Ransomware | Ransomware |
5/5
|
...
|
C:\Users\5p5NrGJn0jS HALPmcxz\Music\Xb4anhaDsw_nEnBFeS\-wYl9Wxaf_FQLu8dRQB5\q4aLH-FAjevoeH6I.mp3.remk | Dropped File | Stream |
Malicious
|
...
|
»
YARA Matches (1)
»
Rule Name | Rule Description | Classification | Score | Actions |
---|---|---|---|---|
DjvuEncryptedFile | File encrypted by Djvu Ransomware | Ransomware |
5/5
|
...
|
C:\Users\5p5NrGJn0jS HALPmcxz\Pictures\_dqq7i08G7zkmy4eWB\4HUb e9qKHwuKHz-\F4YbH 8XORnU4B2.png.remk | Dropped File | Stream |
Malicious
|
...
|
»
YARA Matches (1)
»
Rule Name | Rule Description | Classification | Score | Actions |
---|---|---|---|---|
DjvuEncryptedFile | File encrypted by Djvu Ransomware | Ransomware |
5/5
|
...
|
C:\Users\5p5NrGJn0jS HALPmcxz\Pictures\_dqq7i08G7zkmy4eWB\4HUb e9qKHwuKHz-\Fh-vCljTYvw.gif.remk | Dropped File | Image |
Malicious
|
...
|
»
YARA Matches (1)
»
Rule Name | Rule Description | Classification | Score | Actions |
---|---|---|---|---|
DjvuEncryptedFile | File encrypted by Djvu Ransomware | Ransomware |
5/5
|
...
|
C:\Users\5p5NrGJn0jS HALPmcxz\Pictures\_dqq7i08G7zkmy4eWB\4HUb e9qKHwuKHz-\hRaN7dOcX1AmD.gif.remk | Dropped File | Image |
Malicious
|
...
|
»
YARA Matches (1)
»
Rule Name | Rule Description | Classification | Score | Actions |
---|---|---|---|---|
DjvuEncryptedFile | File encrypted by Djvu Ransomware | Ransomware |
5/5
|
...
|
C:\Users\5p5NrGJn0jS HALPmcxz\Pictures\_dqq7i08G7zkmy4eWB\4HUb e9qKHwuKHz-\QAq-Frb.bmp | Modified File | Stream |
Malicious
|
...
|
»
YARA Matches (1)
»
Rule Name | Rule Description | Classification | Score | Actions |
---|---|---|---|---|
DjvuEncryptedFile | File encrypted by Djvu Ransomware | Ransomware |
5/5
|
...
|
C:\Users\5p5NrGJn0jS HALPmcxz\Videos\PCPKs0u\CSFg h-wcbKcac\677G8npInpXtd35QrCL.mkv.remk | Dropped File | Stream |
Malicious
|
...
|
»
YARA Matches (1)
»
Rule Name | Rule Description | Classification | Score | Actions |
---|---|---|---|---|
DjvuEncryptedFile | File encrypted by Djvu Ransomware | Ransomware |
5/5
|
...
|
C:\Users\5p5NrGJn0jS HALPmcxz\Videos\PCPKs0u\CSFg h-wcbKcac\e0OK1KsDLkbK.swf | Modified File | Shockwave Flash |
Malicious
|
...
|
»
YARA Matches (1)
»
Rule Name | Rule Description | Classification | Score | Actions |
---|---|---|---|---|
DjvuEncryptedFile | File encrypted by Djvu Ransomware | Ransomware |
5/5
|
...
|
C:\Users\5p5NrGJn0jS HALPmcxz\Videos\PCPKs0u\CSFg h-wcbKcac\v0svWrNd01t99.swf | Modified File | Shockwave Flash |
Malicious
|
...
|
»
YARA Matches (1)
»
Rule Name | Rule Description | Classification | Score | Actions |
---|---|---|---|---|
DjvuEncryptedFile | File encrypted by Djvu Ransomware | Ransomware |
5/5
|
...
|
C:\Users\5p5NrGJn0jS HALPmcxz\Documents\X0h6NwRPaRX5m\eBkpfXutqqrq6h\OSDzZr1qU8Y-\6cca_ ZmPO.ods | Modified File | ZIP |
Malicious
|
...
|
»
YARA Matches (1)
»
Rule Name | Rule Description | Classification | Score | Actions |
---|---|---|---|---|
DjvuEncryptedFile | File encrypted by Djvu Ransomware | Ransomware |
5/5
|
...
|
C:\Users\5p5NrGJn0jS HALPmcxz\Documents\X0h6NwRPaRX5m\eBkpfXutqqrq6h\OSDzZr1qU8Y-\6jPQDPh.ods.remk | Dropped File | ZIP |
Malicious
|
...
|
»
YARA Matches (1)
»
Rule Name | Rule Description | Classification | Score | Actions |
---|---|---|---|---|
DjvuEncryptedFile | File encrypted by Djvu Ransomware | Ransomware |
5/5
|
...
|
C:\Users\5p5NrGJn0jS HALPmcxz\Documents\X0h6NwRPaRX5m\eBkpfXutqqrq6h\OSDzZr1qU8Y-\d8nRRAoPzta8W1z.ods | Modified File | ZIP |
Malicious
|
...
|
»
YARA Matches (1)
»
Rule Name | Rule Description | Classification | Score | Actions |
---|---|---|---|---|
DjvuEncryptedFile | File encrypted by Djvu Ransomware | Ransomware |
5/5
|
...
|
C:\Users\5p5NrGJn0jS HALPmcxz\Documents\X0h6NwRPaRX5m\eBkpfXutqqrq6h\OSDzZr1qU8Y-\E76DZy.csv.remk | Dropped File | Stream |
Malicious
|
...
|
»
YARA Matches (1)
»
Rule Name | Rule Description | Classification | Score | Actions |
---|---|---|---|---|
DjvuEncryptedFile | File encrypted by Djvu Ransomware | Ransomware |
5/5
|
...
|
C:\Users\5p5NrGJn0jS HALPmcxz\Documents\X0h6NwRPaRX5m\eBkpfXutqqrq6h\OSDzZr1qU8Y-\pP1VM-.odt | Modified File | ZIP |
Malicious
|
...
|
»
YARA Matches (1)
»
Rule Name | Rule Description | Classification | Score | Actions |
---|---|---|---|---|
DjvuEncryptedFile | File encrypted by Djvu Ransomware | Ransomware |
5/5
|
...
|
C:\Users\5p5NrGJn0jS HALPmcxz\Documents\X0h6NwRPaRX5m\eBkpfXutqqrq6h\OSDzZr1qU8Y-\q6Xn7lmS sN.doc | Modified File | Stream |
Malicious
|
...
|
»
YARA Matches (1)
»
Rule Name | Rule Description | Classification | Score | Actions |
---|---|---|---|---|
DjvuEncryptedFile | File encrypted by Djvu Ransomware | Ransomware |
5/5
|
...
|
C:\Users\5p5NrGJn0jS HALPmcxz\Documents\X0h6NwRPaRX5m\eBkpfXutqqrq6h\OSDzZr1qU8Y-\vES6q7o6drzmc2wswqv.csv.remk | Dropped File | Stream |
Malicious
|
...
|
»
YARA Matches (1)
»
Rule Name | Rule Description | Classification | Score | Actions |
---|---|---|---|---|
DjvuEncryptedFile | File encrypted by Djvu Ransomware | Ransomware |
5/5
|
...
|
C:\Users\5p5NrGJn0jS HALPmcxz\Documents\X0h6NwRPaRX5m\eBkpfXutqqrq6h\t648 Z2T0mST-97jBqS\1Usub D99LlYwn35U.doc.remk | Dropped File | Stream |
Malicious
|
...
|
»
YARA Matches (1)
»
Rule Name | Rule Description | Classification | Score | Actions |
---|---|---|---|---|
DjvuEncryptedFile | File encrypted by Djvu Ransomware | Ransomware |
5/5
|
...
|
C:\Users\5p5NrGJn0jS HALPmcxz\Documents\X0h6NwRPaRX5m\eBkpfXutqqrq6h\t648 Z2T0mST-97jBqS\5tUVR.doc.remk | Dropped File | Stream |
Malicious
|
...
|
»
YARA Matches (1)
»
Rule Name | Rule Description | Classification | Score | Actions |
---|---|---|---|---|
DjvuEncryptedFile | File encrypted by Djvu Ransomware | Ransomware |
5/5
|
...
|
C:\Users\5p5NrGJn0jS HALPmcxz\Documents\X0h6NwRPaRX5m\eBkpfXutqqrq6h\t648 Z2T0mST-97jBqS\aYykKL9sNmuS205lNQxb.xlsx.remk | Dropped File | ZIP |
Malicious
|
...
|
»
YARA Matches (1)
»
Rule Name | Rule Description | Classification | Score | Actions |
---|---|---|---|---|
DjvuEncryptedFile | File encrypted by Djvu Ransomware | Ransomware |
5/5
|
...
|
C:\Users\5p5NrGJn0jS HALPmcxz\Documents\X0h6NwRPaRX5m\eBkpfXutqqrq6h\t648 Z2T0mST-97jBqS\GHrUuVSNZ.ods | Modified File | ZIP |
Malicious
|
...
|
»
YARA Matches (1)
»
Rule Name | Rule Description | Classification | Score | Actions |
---|---|---|---|---|
DjvuEncryptedFile | File encrypted by Djvu Ransomware | Ransomware |
5/5
|
...
|
C:\Users\5p5NrGJn0jS HALPmcxz\Documents\X0h6NwRPaRX5m\eBkpfXutqqrq6h\t648 Z2T0mST-97jBqS\i2qLmECFmP.xls | Modified File | Stream |
Malicious
|
...
|
»
YARA Matches (1)
»
Rule Name | Rule Description | Classification | Score | Actions |
---|---|---|---|---|
DjvuEncryptedFile | File encrypted by Djvu Ransomware | Ransomware |
5/5
|
...
|
C:\Users\5p5NrGJn0jS HALPmcxz\Documents\X0h6NwRPaRX5m\eBkpfXutqqrq6h\t648 Z2T0mST-97jBqS\RVx8gh-an-F-.pdf.remk | Dropped File |
Malicious
|
...
|
»
YARA Matches (4)
»
Rule Name | Rule Description | Classification | Score | Actions |
---|---|---|---|---|
DjvuEncryptedFile | File encrypted by Djvu Ransomware | Ransomware |
5/5
|
...
|
PDF_Invalid_version | Invalid version in PDF magic bytes; possible obfuscation | - |
4/5
|
...
|
PDF_Missing_startxref | Malformed PDF without startxref; possible obfuscation | - |
3/5
|
...
|
PDF_Missing_EOF | Malformed PDF without EOF marker; possible obfuscation | - |
3/5
|
...
|
C:\Users\5p5NrGJn0jS HALPmcxz\Pictures\_dqq7i08G7zkmy4eWB\4HUb e9qKHwuKHz-\2kWa8l\8PkInFTYY.gif | Modified File | Image |
Malicious
|
...
|
»
YARA Matches (1)
»
Rule Name | Rule Description | Classification | Score | Actions |
---|---|---|---|---|
DjvuEncryptedFile | File encrypted by Djvu Ransomware | Ransomware |
5/5
|
...
|
C:\Users\5p5NrGJn0jS HALPmcxz\Pictures\_dqq7i08G7zkmy4eWB\4HUb e9qKHwuKHz-\2kWa8l\b1oXySBs7FK.jpg | Modified File | Image |
Malicious
|
...
|
»
YARA Matches (1)
»
Rule Name | Rule Description | Classification | Score | Actions |
---|---|---|---|---|
DjvuEncryptedFile | File encrypted by Djvu Ransomware | Ransomware |
5/5
|
...
|
C:\Users\5p5NrGJn0jS HALPmcxz\Pictures\_dqq7i08G7zkmy4eWB\4HUb e9qKHwuKHz-\2kWa8l\NfB4BN1dcg.bmp.remk | Dropped File | Stream |
Malicious
|
...
|
»
YARA Matches (1)
»
Rule Name | Rule Description | Classification | Score | Actions |
---|---|---|---|---|
DjvuEncryptedFile | File encrypted by Djvu Ransomware | Ransomware |
5/5
|
...
|
C:\Users\5p5NrGJn0jS HALPmcxz\Pictures\_dqq7i08G7zkmy4eWB\4HUb e9qKHwuKHz-\2kWa8l\UzP92EkXV9tzwch.png.remk | Dropped File | Stream |
Malicious
|
...
|
»
YARA Matches (1)
»
Rule Name | Rule Description | Classification | Score | Actions |
---|---|---|---|---|
DjvuEncryptedFile | File encrypted by Djvu Ransomware | Ransomware |
5/5
|
...
|
C:\Users\5p5NrGJn0jS HALPmcxz\Pictures\_dqq7i08G7zkmy4eWB\4HUb e9qKHwuKHz-\2kWa8l\WJGbtDRaJ_I.gif | Modified File | Image |
Malicious
|
...
|
»
YARA Matches (1)
»
Rule Name | Rule Description | Classification | Score | Actions |
---|---|---|---|---|
DjvuEncryptedFile | File encrypted by Djvu Ransomware | Ransomware |
5/5
|
...
|
C:\Users\5p5NrGJn0jS HALPmcxz\Pictures\_dqq7i08G7zkmy4eWB\4HUb e9qKHwuKHz-\2kWa8l\wUkuHtHCChC.png | Modified File | Stream |
Malicious
|
...
|
»
YARA Matches (1)
»
Rule Name | Rule Description | Classification | Score | Actions |
---|---|---|---|---|
DjvuEncryptedFile | File encrypted by Djvu Ransomware | Ransomware |
5/5
|
...
|
C:\Users\5p5NrGJn0jS HALPmcxz\Pictures\_dqq7i08G7zkmy4eWB\4HUb e9qKHwuKHz-\2kWa8l\Y3yQ_2 wT.gif.remk | Dropped File | Image |
Malicious
|
...
|
»
YARA Matches (1)
»
Rule Name | Rule Description | Classification | Score | Actions |
---|---|---|---|---|
DjvuEncryptedFile | File encrypted by Djvu Ransomware | Ransomware |
5/5
|
...
|
C:\Users\5p5NrGJn0jS HALPmcxz\Pictures\_dqq7i08G7zkmy4eWB\4HUb e9qKHwuKHz-\FzGfdyB6\1Zf e6GVWkTdL6S3dtG.jpg.remk | Dropped File | Image |
Malicious
|
...
|
»
YARA Matches (1)
»
Rule Name | Rule Description | Classification | Score | Actions |
---|---|---|---|---|
DjvuEncryptedFile | File encrypted by Djvu Ransomware | Ransomware |
5/5
|
...
|
C:\Users\5p5NrGJn0jS HALPmcxz\Pictures\_dqq7i08G7zkmy4eWB\4HUb e9qKHwuKHz-\FzGfdyB6\5aUm.png | Modified File | Stream |
Malicious
|
...
|
»
YARA Matches (1)
»
Rule Name | Rule Description | Classification | Score | Actions |
---|---|---|---|---|
DjvuEncryptedFile | File encrypted by Djvu Ransomware | Ransomware |
5/5
|
...
|
C:\Users\5p5NrGJn0jS HALPmcxz\Pictures\_dqq7i08G7zkmy4eWB\4HUb e9qKHwuKHz-\FzGfdyB6\eoDi5iM0Omq.jpg | Modified File | Image |
Malicious
|
...
|
»
YARA Matches (1)
»
Rule Name | Rule Description | Classification | Score | Actions |
---|---|---|---|---|
DjvuEncryptedFile | File encrypted by Djvu Ransomware | Ransomware |
5/5
|
...
|
C:\Users\5p5NrGJn0jS HALPmcxz\Pictures\_dqq7i08G7zkmy4eWB\4HUb e9qKHwuKHz-\FzGfdyB6\EOkvXHoEt.gif.remk | Dropped File | Image |
Malicious
|
...
|
»
YARA Matches (1)
»
Rule Name | Rule Description | Classification | Score | Actions |
---|---|---|---|---|
DjvuEncryptedFile | File encrypted by Djvu Ransomware | Ransomware |
5/5
|
...
|
C:\Users\5p5NrGJn0jS HALPmcxz\Pictures\_dqq7i08G7zkmy4eWB\4HUb e9qKHwuKHz-\FzGfdyB6\GNzXqDyxgLyC07.bmp | Modified File | Stream |
Malicious
|
...
|
»
YARA Matches (1)
»
Rule Name | Rule Description | Classification | Score | Actions |
---|---|---|---|---|
DjvuEncryptedFile | File encrypted by Djvu Ransomware | Ransomware |
5/5
|
...
|
C:\Users\5p5NrGJn0jS HALPmcxz\Pictures\_dqq7i08G7zkmy4eWB\4HUb e9qKHwuKHz-\FzGfdyB6\ogT6-r28SnPPl.jpg | Modified File | Image |
Malicious
|
...
|
»
YARA Matches (1)
»
Rule Name | Rule Description | Classification | Score | Actions |
---|---|---|---|---|
DjvuEncryptedFile | File encrypted by Djvu Ransomware | Ransomware |
5/5
|
...
|
C:\Users\5p5NrGJn0jS HALPmcxz\Pictures\_dqq7i08G7zkmy4eWB\4HUb e9qKHwuKHz-\FzGfdyB6\UxHea_1OLD4fGeysQVZ.png.remk | Dropped File | Stream |
Malicious
|
...
|
»
YARA Matches (1)
»
Rule Name | Rule Description | Classification | Score | Actions |
---|---|---|---|---|
DjvuEncryptedFile | File encrypted by Djvu Ransomware | Ransomware |
5/5
|
...
|
C:\Users\5p5NrGJn0jS HALPmcxz\Pictures\_dqq7i08G7zkmy4eWB\4HUb e9qKHwuKHz-\MJpyx6aDoSvpIH\94ufH0b5CBCbVk2g4.bmp.remk | Dropped File | Stream |
Malicious
|
...
|
»
YARA Matches (1)
»
Rule Name | Rule Description | Classification | Score | Actions |
---|---|---|---|---|
DjvuEncryptedFile | File encrypted by Djvu Ransomware | Ransomware |
5/5
|
...
|
C:\Users\5p5NrGJn0jS HALPmcxz\Pictures\_dqq7i08G7zkmy4eWB\4HUb e9qKHwuKHz-\MJpyx6aDoSvpIH\ayZ1BTswz7VJrGpFc2.gif | Modified File | Image |
Malicious
|
...
|
»
YARA Matches (1)
»
Rule Name | Rule Description | Classification | Score | Actions |
---|---|---|---|---|
DjvuEncryptedFile | File encrypted by Djvu Ransomware | Ransomware |
5/5
|
...
|
C:\Users\5p5NrGJn0jS HALPmcxz\Pictures\_dqq7i08G7zkmy4eWB\4HUb e9qKHwuKHz-\MJpyx6aDoSvpIH\cO_.png.remk | Dropped File | Stream |
Malicious
|
...
|
»
YARA Matches (1)
»
Rule Name | Rule Description | Classification | Score | Actions |
---|---|---|---|---|
DjvuEncryptedFile | File encrypted by Djvu Ransomware | Ransomware |
5/5
|
...
|
C:\Users\5p5NrGJn0jS HALPmcxz\Pictures\_dqq7i08G7zkmy4eWB\4HUb e9qKHwuKHz-\MJpyx6aDoSvpIH\ku5zMZBRK.png | Modified File | Stream |
Malicious
|
...
|
»
YARA Matches (1)
»
Rule Name | Rule Description | Classification | Score | Actions |
---|---|---|---|---|
DjvuEncryptedFile | File encrypted by Djvu Ransomware | Ransomware |
5/5
|
...
|
C:\Users\5p5NrGJn0jS HALPmcxz\Pictures\_dqq7i08G7zkmy4eWB\4HUb e9qKHwuKHz-\MJpyx6aDoSvpIH\M3CaFNSYagYb6MmIK-.bmp.remk | Dropped File | Stream |
Malicious
|
...
|
»
YARA Matches (1)
»
Rule Name | Rule Description | Classification | Score | Actions |
---|---|---|---|---|
DjvuEncryptedFile | File encrypted by Djvu Ransomware | Ransomware |
5/5
|
...
|
C:\Users\5p5NrGJn0jS HALPmcxz\Pictures\_dqq7i08G7zkmy4eWB\4HUb e9qKHwuKHz-\MJpyx6aDoSvpIH\PSEVjAP5aE JA4lRFb.png.remk | Dropped File | Stream |
Malicious
|
...
|
»
YARA Matches (1)
»
Rule Name | Rule Description | Classification | Score | Actions |
---|---|---|---|---|
DjvuEncryptedFile | File encrypted by Djvu Ransomware | Ransomware |
5/5
|
...
|
C:\Users\5p5NrGJn0jS HALPmcxz\Pictures\_dqq7i08G7zkmy4eWB\4HUb e9qKHwuKHz-\MJpyx6aDoSvpIH\rtW3JtBFakvqy.png.remk | Dropped File | Stream |
Malicious
|
...
|
»
YARA Matches (1)
»
Rule Name | Rule Description | Classification | Score | Actions |
---|---|---|---|---|
DjvuEncryptedFile | File encrypted by Djvu Ransomware | Ransomware |
5/5
|
...
|
C:\Users\5p5NrGJn0jS HALPmcxz\Videos\PCPKs0u\CSFg h-wcbKcac\xB0W_x\dg1ZR5LE5.mkv | Modified File | Stream |
Malicious
|
...
|
»
YARA Matches (1)
»
Rule Name | Rule Description | Classification | Score | Actions |
---|---|---|---|---|
DjvuEncryptedFile | File encrypted by Djvu Ransomware | Ransomware |
5/5
|
...
|
C:\Users\5p5NrGJn0jS HALPmcxz\Videos\PCPKs0u\CSFg h-wcbKcac\xB0W_x\GodaZbgKBQyE.flv.remk | Dropped File | Video |
Malicious
|
...
|
»
YARA Matches (1)
»
Rule Name | Rule Description | Classification | Score | Actions |
---|---|---|---|---|
DjvuEncryptedFile | File encrypted by Djvu Ransomware | Ransomware |
5/5
|
...
|
C:\Users\5p5NrGJn0jS HALPmcxz\Videos\PCPKs0u\CSFg h-wcbKcac\xB0W_x\LJecWOah9kPE.mp4 | Modified File | Stream |
Malicious
|
...
|
»
YARA Matches (1)
»
Rule Name | Rule Description | Classification | Score | Actions |
---|---|---|---|---|
DjvuEncryptedFile | File encrypted by Djvu Ransomware | Ransomware |
5/5
|
...
|
C:\Users\5p5NrGJn0jS HALPmcxz\Videos\PCPKs0u\CSFg h-wcbKcac\Xq9EY6lNcW89ESh\WuazV8l9ZPKR2hR.flv.remk | Dropped File | Video |
Malicious
|
...
|
»
YARA Matches (1)
»
Rule Name | Rule Description | Classification | Score | Actions |
---|---|---|---|---|
DjvuEncryptedFile | File encrypted by Djvu Ransomware | Ransomware |
5/5
|
...
|
C:\Users\5p5NrGJn0jS HALPmcxz\Videos\PCPKs0u\CSFg h-wcbKcac\ZCC-nq6c5y\4vcFIzQn6R7Uez.mp4.remk | Dropped File | Stream |
Malicious
|
...
|
»
YARA Matches (1)
»
Rule Name | Rule Description | Classification | Score | Actions |
---|---|---|---|---|
DjvuEncryptedFile | File encrypted by Djvu Ransomware | Ransomware |
5/5
|
...
|
C:\Users\5p5NrGJn0jS HALPmcxz\Videos\PCPKs0u\CSFg h-wcbKcac\ZCC-nq6c5y\9L8GIzDkh2buC.mp4.remk | Dropped File | Stream |
Malicious
|
...
|
»
YARA Matches (1)
»
Rule Name | Rule Description | Classification | Score | Actions |
---|---|---|---|---|
DjvuEncryptedFile | File encrypted by Djvu Ransomware | Ransomware |
5/5
|
...
|
C:\Users\5p5NrGJn0jS HALPmcxz\Videos\PCPKs0u\CSFg h-wcbKcac\ZCC-nq6c5y\cd1puEdABr.mp4.remk | Dropped File | Stream |
Malicious
|
...
|
»
YARA Matches (1)
»
Rule Name | Rule Description | Classification | Score | Actions |
---|---|---|---|---|
DjvuEncryptedFile | File encrypted by Djvu Ransomware | Ransomware |
5/5
|
...
|
C:\Users\5p5NrGJn0jS HALPmcxz\Videos\PCPKs0u\CSFg h-wcbKcac\_2KhhEZ4Uf5pHRY\2yWm8WTEQIQtOzFejH.avi.remk | Dropped File | Stream |
Malicious
|
...
|
»
YARA Matches (1)
»
Rule Name | Rule Description | Classification | Score | Actions |
---|---|---|---|---|
DjvuEncryptedFile | File encrypted by Djvu Ransomware | Ransomware |
5/5
|
...
|
C:\Users\5p5NrGJn0jS HALPmcxz\Videos\PCPKs0u\CSFg h-wcbKcac\_2KhhEZ4Uf5pHRY\nXQHuyqoJra2B.avi | Modified File | Stream |
Malicious
|
...
|
»
YARA Matches (1)
»
Rule Name | Rule Description | Classification | Score | Actions |
---|---|---|---|---|
DjvuEncryptedFile | File encrypted by Djvu Ransomware | Ransomware |
5/5
|
...
|
C:\Users\5p5NrGJn0jS HALPmcxz\Videos\PCPKs0u\CSFg h-wcbKcac\_2KhhEZ4Uf5pHRY\sSO7KsP.avi | Modified File | Stream |
Malicious
|
...
|
»
YARA Matches (1)
»
Rule Name | Rule Description | Classification | Score | Actions |
---|---|---|---|---|
DjvuEncryptedFile | File encrypted by Djvu Ransomware | Ransomware |
5/5
|
...
|
C:\Users\5p5NrGJn0jS HALPmcxz\AppData\LocalLow\Adobe\Acrobat\10.0\rdrmessage.zip.remk | Dropped File | Stream |
Malicious
|
...
|
»
YARA Matches (1)
»
Rule Name | Rule Description | Classification | Score | Actions |
---|---|---|---|---|
DjvuEncryptedFile | File encrypted by Djvu Ransomware | Ransomware |
5/5
|
...
|
C:\Users\5p5NrGJn0jS HALPmcxz\AppData\LocalLow\Microsoft\Internet Explorer\DOMStore\index.dat | Modified File | Stream |
Malicious
|
...
|
»
YARA Matches (1)
»
Rule Name | Rule Description | Classification | Score | Actions |
---|---|---|---|---|
DjvuEncryptedFile | File encrypted by Djvu Ransomware | Ransomware |
5/5
|
...
|
C:\Users\5p5NrGJn0jS HALPmcxz\AppData\LocalLow\Sun\Java\AU\au.cab | Modified File | CAB |
Malicious
|
...
|
»
YARA Matches (1)
»
Rule Name | Rule Description | Classification | Score | Actions |
---|---|---|---|---|
DjvuEncryptedFile | File encrypted by Djvu Ransomware | Ransomware |
5/5
|
...
|
C:\Users\5p5NrGJn0jS HALPmcxz\AppData\LocalLow\Sun\Java\AU\au.msi | Modified File | Stream |
Malicious
|
...
|
»
YARA Matches (1)
»
Rule Name | Rule Description | Classification | Score | Actions |
---|---|---|---|---|
DjvuEncryptedFile | File encrypted by Djvu Ransomware | Ransomware |
5/5
|
...
|
C:\Users\5p5NrGJn0jS HALPmcxz\AppData\LocalLow\Sun\Java\Deployment\deployment.properties.remk | Dropped File | Stream |
Malicious
|
...
|
»
YARA Matches (1)
»
Rule Name | Rule Description | Classification | Score | Actions |
---|---|---|---|---|
DjvuEncryptedFile | File encrypted by Djvu Ransomware | Ransomware |
5/5
|
...
|
C:\Users\5p5NrGJn0jS HALPmcxz\AppData\LocalLow\Sun\Java\jre1.7.0_45\jre1.7.0_45.msi | Modified File | Stream |
Malicious
|
...
|
»
YARA Matches (1)
»
Rule Name | Rule Description | Classification | Score | Actions |
---|---|---|---|---|
DjvuEncryptedFile | File encrypted by Djvu Ransomware | Ransomware |
5/5
|
...
|
C:\Users\5p5NrGJn0jS HALPmcxz\Videos\PCPKs0u\CSFg h-wcbKcac\xB0W_x\dcR8Wn\MMNB3DGmP9H.flv | Modified File | Video |
Malicious
|
...
|
»
YARA Matches (1)
»
Rule Name | Rule Description | Classification | Score | Actions |
---|---|---|---|---|
DjvuEncryptedFile | File encrypted by Djvu Ransomware | Ransomware |
5/5
|
...
|
C:\Users\5p5NrGJn0jS HALPmcxz\Videos\PCPKs0u\CSFg h-wcbKcac\xB0W_x\dcR8Wn\WGem6pJWFmMLh_CSjVJ.swf | Modified File | Shockwave Flash |
Malicious
|
...
|
»
YARA Matches (1)
»
Rule Name | Rule Description | Classification | Score | Actions |
---|---|---|---|---|
DjvuEncryptedFile | File encrypted by Djvu Ransomware | Ransomware |
5/5
|
...
|
C:\Users\5p5NrGJn0jS HALPmcxz\Videos\PCPKs0u\CSFg h-wcbKcac\xB0W_x\dcR8Wn\XoMJ508kaZydeC8l.flv.remk | Dropped File | Video |
Malicious
|
...
|
»
YARA Matches (1)
»
Rule Name | Rule Description | Classification | Score | Actions |
---|---|---|---|---|
DjvuEncryptedFile | File encrypted by Djvu Ransomware | Ransomware |
5/5
|
...
|
C:\Users\5p5NrGJn0jS HALPmcxz\Videos\PCPKs0u\CSFg h-wcbKcac\xB0W_x\TNlwUISWdF VQwLUr\35fwF Y81hH3FH.mkv | Modified File | Stream |
Malicious
|
...
|
»
YARA Matches (1)
»
Rule Name | Rule Description | Classification | Score | Actions |
---|---|---|---|---|
DjvuEncryptedFile | File encrypted by Djvu Ransomware | Ransomware |
5/5
|
...
|
C:\Users\5p5NrGJn0jS HALPmcxz\Videos\PCPKs0u\CSFg h-wcbKcac\xB0W_x\TNlwUISWdF VQwLUr\cnAJanV1kmNfWz8.swf.remk | Dropped File | Shockwave Flash |
Malicious
|
...
|
»
YARA Matches (1)
»
Rule Name | Rule Description | Classification | Score | Actions |
---|---|---|---|---|
DjvuEncryptedFile | File encrypted by Djvu Ransomware | Ransomware |
5/5
|
...
|
C:\Users\5p5NrGJn0jS HALPmcxz\Videos\PCPKs0u\CSFg h-wcbKcac\xB0W_x\TNlwUISWdF VQwLUr\pEQk.flv | Modified File | Video |
Malicious
|
...
|
»
YARA Matches (1)
»
Rule Name | Rule Description | Classification | Score | Actions |
---|---|---|---|---|
DjvuEncryptedFile | File encrypted by Djvu Ransomware | Ransomware |
5/5
|
...
|
C:\Users\5p5NrGJn0jS HALPmcxz\Videos\PCPKs0u\CSFg h-wcbKcac\ZCC-nq6c5y\S Vy53\f8B4p09.swf.remk | Dropped File | Shockwave Flash |
Malicious
|
...
|
»
YARA Matches (1)
»
Rule Name | Rule Description | Classification | Score | Actions |
---|---|---|---|---|
DjvuEncryptedFile | File encrypted by Djvu Ransomware | Ransomware |
5/5
|
...
|
C:\Users\5p5NrGJn0jS HALPmcxz\Videos\PCPKs0u\CSFg h-wcbKcac\ZCC-nq6c5y\S Vy53\iCzLPFif.flv.remk | Dropped File | Video |
Malicious
|
...
|
»
YARA Matches (1)
»
Rule Name | Rule Description | Classification | Score | Actions |
---|---|---|---|---|
DjvuEncryptedFile | File encrypted by Djvu Ransomware | Ransomware |
5/5
|
...
|
C:\Users\5p5NrGJn0jS HALPmcxz\Videos\PCPKs0u\CSFg h-wcbKcac\ZCC-nq6c5y\S Vy53\KqR1qrw6aoyjKfrEgvI.flv.remk | Dropped File | Video |
Malicious
|
...
|
»
YARA Matches (1)
»
Rule Name | Rule Description | Classification | Score | Actions |
---|---|---|---|---|
DjvuEncryptedFile | File encrypted by Djvu Ransomware | Ransomware |
5/5
|
...
|
C:\Users\5p5NrGJn0jS HALPmcxz\Videos\PCPKs0u\CSFg h-wcbKcac\ZCC-nq6c5y\S Vy53\YBiLRAZYH9yEkpgFaG.swf | Modified File | Shockwave Flash |
Malicious
|
...
|
»
YARA Matches (1)
»
Rule Name | Rule Description | Classification | Score | Actions |
---|---|---|---|---|
DjvuEncryptedFile | File encrypted by Djvu Ransomware | Ransomware |
5/5
|
...
|
C:\Users\5p5NrGJn0jS HALPmcxz\AppData\LocalLow\Microsoft\Internet Explorer\DOMStore\36USA68T\imagesrv.adition[1].xml.remk | Dropped File | Stream |
Malicious
|
...
|
»
YARA Matches (1)
»
Rule Name | Rule Description | Classification | Score | Actions |
---|---|---|---|---|
DjvuEncryptedFile | File encrypted by Djvu Ransomware | Ransomware |
5/5
|
...
|
C:\Users\5p5NrGJn0jS HALPmcxz\AppData\LocalLow\Microsoft\Internet Explorer\DOMStore\3O75JDME\www.google[1].xml | Modified File | Stream |
Malicious
|
...
|
»
YARA Matches (1)
»
Rule Name | Rule Description | Classification | Score | Actions |
---|---|---|---|---|
DjvuEncryptedFile | File encrypted by Djvu Ransomware | Ransomware |
5/5
|
...
|
C:\Users\5p5NrGJn0jS HALPmcxz\AppData\LocalLow\Microsoft\Internet Explorer\DOMStore\VGMTOI09\www.msn[1].xml.remk | Dropped File | Stream |
Malicious
|
...
|
»
YARA Matches (1)
»
Rule Name | Rule Description | Classification | Score | Actions |
---|---|---|---|---|
DjvuEncryptedFile | File encrypted by Djvu Ransomware | Ransomware |
5/5
|
...
|
C:\Users\5p5NrGJn0jS HALPmcxz\AppData\Local\1eed4f4c-ee3f-42d5-9fd1-74f531bda6b5\updatewin1.exe | Downloaded File | Binary |
Malicious
|
...
|
»
File Reputation Information
»
Severity |
Blacklisted
|
Names | Mal/Generic-S |
PE Information
»
Image Base | 0x400000 |
Entry Point | 0x402d76 |
Size Of Code | 0x1c200 |
Size Of Initialized Data | 0x2c200 |
File Type | FileType.executable |
Subsystem | Subsystem.windows_gui |
Machine Type | MachineType.i386 |
Compile Timestamp | 2017-07-24 12:23:54+00:00 |
Version Information (3)
»
FileVersion | 7.7.7.18 |
InternalName | rawudiyeh.exe |
LegalCopyright | Copyright (C) 2018, sacuwedimufoy |
Sections (5)
»
Name | Virtual Address | Virtual Size | Raw Data Size | Raw Data Offset | Flags | Entropy |
---|---|---|---|---|---|---|
.text | 0x401000 | 0x1c07e | 0x1c200 | 0x400 | IMAGE_SCN_CNT_CODE, IMAGE_SCN_MEM_EXECUTE, IMAGE_SCN_MEM_READ | 6.62 |
.rdata | 0x41e000 | 0x463e | 0x4800 | 0x1c600 | IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_READ | 5.26 |
.data | 0x423000 | 0x1c6a8 | 0x17400 | 0x20e00 | IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_READ, IMAGE_SCN_MEM_WRITE | 5.83 |
.rsrc | 0x440000 | 0xa578 | 0xa600 | 0x38200 | IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_READ | 6.88 |
.reloc | 0x44b000 | 0x1968 | 0x1a00 | 0x42800 | IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_DISCARDABLE, IMAGE_SCN_MEM_READ | 6.34 |
Imports (4)
»
KERNEL32.dll (102)
»
API Name | Ordinal | IAT Address | Thunk RVA | Thunk Offset | Hint |
---|---|---|---|---|---|
ExitThread | 0x0 | 0x41e028 | 0x21afc | 0x200fc | 0x105 |
GetStartupInfoW | 0x0 | 0x41e02c | 0x21b00 | 0x20100 | 0x23a |
GetLastError | 0x0 | 0x41e030 | 0x21b04 | 0x20104 | 0x1e6 |
GetProcAddress | 0x0 | 0x41e034 | 0x21b08 | 0x20108 | 0x220 |
CreateJobSet | 0x0 | 0x41e038 | 0x21b0c | 0x2010c | 0x87 |
GlobalFree | 0x0 | 0x41e03c | 0x21b10 | 0x20110 | 0x28c |
LoadLibraryA | 0x0 | 0x41e040 | 0x21b14 | 0x20114 | 0x2f1 |
OpenWaitableTimerW | 0x0 | 0x41e044 | 0x21b18 | 0x20118 | 0x339 |
AddAtomA | 0x0 | 0x41e048 | 0x21b1c | 0x2011c | 0x3 |
FindFirstChangeNotificationA | 0x0 | 0x41e04c | 0x21b20 | 0x20120 | 0x11b |
VirtualProtect | 0x0 | 0x41e050 | 0x21b24 | 0x20124 | 0x45a |
GetCurrentDirectoryA | 0x0 | 0x41e054 | 0x21b28 | 0x20128 | 0x1a7 |
GetACP | 0x0 | 0x41e058 | 0x21b2c | 0x2012c | 0x152 |
InterlockedPushEntrySList | 0x0 | 0x41e05c | 0x21b30 | 0x20130 | 0x2c2 |
CompareStringW | 0x0 | 0x41e060 | 0x21b34 | 0x20134 | 0x55 |
CompareStringA | 0x0 | 0x41e064 | 0x21b38 | 0x20138 | 0x52 |
CreateFileA | 0x0 | 0x41e068 | 0x21b3c | 0x2013c | 0x78 |
GetTimeZoneInformation | 0x0 | 0x41e06c | 0x21b40 | 0x20140 | 0x26b |
WriteConsoleW | 0x0 | 0x41e070 | 0x21b44 | 0x20144 | 0x48c |
GetConsoleOutputCP | 0x0 | 0x41e074 | 0x21b48 | 0x20148 | 0x199 |
WriteConsoleA | 0x0 | 0x41e078 | 0x21b4c | 0x2014c | 0x482 |
CloseHandle | 0x0 | 0x41e07c | 0x21b50 | 0x20150 | 0x43 |
IsValidLocale | 0x0 | 0x41e080 | 0x21b54 | 0x20154 | 0x2dd |
EnumSystemLocalesA | 0x0 | 0x41e084 | 0x21b58 | 0x20158 | 0xf8 |
GetUserDefaultLCID | 0x0 | 0x41e088 | 0x21b5c | 0x2015c | 0x26d |
GetSystemTimeAdjustment | 0x0 | 0x41e08c | 0x21b60 | 0x20160 | 0x24e |
GetSystemTimes | 0x0 | 0x41e090 | 0x21b64 | 0x20164 | 0x250 |
GetTickCount | 0x0 | 0x41e094 | 0x21b68 | 0x20168 | 0x266 |
FreeEnvironmentStringsA | 0x0 | 0x41e098 | 0x21b6c | 0x2016c | 0x14a |
GetComputerNameW | 0x0 | 0x41e09c | 0x21b70 | 0x20170 | 0x178 |
FindCloseChangeNotification | 0x0 | 0x41e0a0 | 0x21b74 | 0x20174 | 0x11a |
FindResourceExW | 0x0 | 0x41e0a4 | 0x21b78 | 0x20178 | 0x138 |
GetCPInfo | 0x0 | 0x41e0a8 | 0x21b7c | 0x2017c | 0x15b |
SetProcessShutdownParameters | 0x0 | 0x41e0ac | 0x21b80 | 0x20180 | 0x3f9 |
GetModuleHandleExA | 0x0 | 0x41e0b0 | 0x21b84 | 0x20184 | 0x1f7 |
GetDateFormatA | 0x0 | 0x41e0b4 | 0x21b88 | 0x20188 | 0x1ae |
GetTimeFormatA | 0x0 | 0x41e0b8 | 0x21b8c | 0x2018c | 0x268 |
GetStringTypeW | 0x0 | 0x41e0bc | 0x21b90 | 0x20190 | 0x240 |
GetStringTypeA | 0x0 | 0x41e0c0 | 0x21b94 | 0x20194 | 0x23d |
LCMapStringW | 0x0 | 0x41e0c4 | 0x21b98 | 0x20198 | 0x2e3 |
GetCommandLineA | 0x0 | 0x41e0c8 | 0x21b9c | 0x2019c | 0x16f |
GetStartupInfoA | 0x0 | 0x41e0cc | 0x21ba0 | 0x201a0 | 0x239 |
RaiseException | 0x0 | 0x41e0d0 | 0x21ba4 | 0x201a4 | 0x35a |
RtlUnwind | 0x0 | 0x41e0d4 | 0x21ba8 | 0x201a8 | 0x392 |
TerminateProcess | 0x0 | 0x41e0d8 | 0x21bac | 0x201ac | 0x42d |
GetCurrentProcess | 0x0 | 0x41e0dc | 0x21bb0 | 0x201b0 | 0x1a9 |
UnhandledExceptionFilter | 0x0 | 0x41e0e0 | 0x21bb4 | 0x201b4 | 0x43e |
SetUnhandledExceptionFilter | 0x0 | 0x41e0e4 | 0x21bb8 | 0x201b8 | 0x415 |
IsDebuggerPresent | 0x0 | 0x41e0e8 | 0x21bbc | 0x201bc | 0x2d1 |
HeapAlloc | 0x0 | 0x41e0ec | 0x21bc0 | 0x201c0 | 0x29d |
HeapFree | 0x0 | 0x41e0f0 | 0x21bc4 | 0x201c4 | 0x2a1 |
EnterCriticalSection | 0x0 | 0x41e0f4 | 0x21bc8 | 0x201c8 | 0xd9 |
LeaveCriticalSection | 0x0 | 0x41e0f8 | 0x21bcc | 0x201cc | 0x2ef |
SetHandleCount | 0x0 | 0x41e0fc | 0x21bd0 | 0x201d0 | 0x3e8 |
GetStdHandle | 0x0 | 0x41e100 | 0x21bd4 | 0x201d4 | 0x23b |
GetFileType | 0x0 | 0x41e104 | 0x21bd8 | 0x201d8 | 0x1d7 |
DeleteCriticalSection | 0x0 | 0x41e108 | 0x21bdc | 0x201dc | 0xbe |
GetModuleHandleW | 0x0 | 0x41e10c | 0x21be0 | 0x201e0 | 0x1f9 |
Sleep | 0x0 | 0x41e110 | 0x21be4 | 0x201e4 | 0x421 |
ExitProcess | 0x0 | 0x41e114 | 0x21be8 | 0x201e8 | 0x104 |
WriteFile | 0x0 | 0x41e118 | 0x21bec | 0x201ec | 0x48d |
GetModuleFileNameA | 0x0 | 0x41e11c | 0x21bf0 | 0x201f0 | 0x1f4 |
GetEnvironmentStrings | 0x0 | 0x41e120 | 0x21bf4 | 0x201f4 | 0x1bf |
FreeEnvironmentStringsW | 0x0 | 0x41e124 | 0x21bf8 | 0x201f8 | 0x14b |
WideCharToMultiByte | 0x0 | 0x41e128 | 0x21bfc | 0x201fc | 0x47a |
GetEnvironmentStringsW | 0x0 | 0x41e12c | 0x21c00 | 0x20200 | 0x1c1 |
TlsGetValue | 0x0 | 0x41e130 | 0x21c04 | 0x20204 | 0x434 |
TlsAlloc | 0x0 | 0x41e134 | 0x21c08 | 0x20208 | 0x432 |
TlsSetValue | 0x0 | 0x41e138 | 0x21c0c | 0x2020c | 0x435 |
TlsFree | 0x0 | 0x41e13c | 0x21c10 | 0x20210 | 0x433 |
InterlockedIncrement | 0x0 | 0x41e140 | 0x21c14 | 0x20214 | 0x2c0 |
SetLastError | 0x0 | 0x41e144 | 0x21c18 | 0x20218 | 0x3ec |
GetCurrentThreadId | 0x0 | 0x41e148 | 0x21c1c | 0x2021c | 0x1ad |
InterlockedDecrement | 0x0 | 0x41e14c | 0x21c20 | 0x20220 | 0x2bc |
GetCurrentThread | 0x0 | 0x41e150 | 0x21c24 | 0x20224 | 0x1ac |
HeapCreate | 0x0 | 0x41e154 | 0x21c28 | 0x20228 | 0x29f |
HeapDestroy | 0x0 | 0x41e158 | 0x21c2c | 0x2022c | 0x2a0 |
VirtualFree | 0x0 | 0x41e15c | 0x21c30 | 0x20230 | 0x457 |
QueryPerformanceCounter | 0x0 | 0x41e160 | 0x21c34 | 0x20234 | 0x354 |
GetCurrentProcessId | 0x0 | 0x41e164 | 0x21c38 | 0x20238 | 0x1aa |
GetSystemTimeAsFileTime | 0x0 | 0x41e168 | 0x21c3c | 0x2023c | 0x24f |
FatalAppExitA | 0x0 | 0x41e16c | 0x21c40 | 0x20240 | 0x10b |
VirtualAlloc | 0x0 | 0x41e170 | 0x21c44 | 0x20244 | 0x454 |
HeapReAlloc | 0x0 | 0x41e174 | 0x21c48 | 0x20248 | 0x2a4 |
MultiByteToWideChar | 0x0 | 0x41e178 | 0x21c4c | 0x2024c | 0x31a |
ReadFile | 0x0 | 0x41e17c | 0x21c50 | 0x20250 | 0x368 |
InitializeCriticalSectionAndSpinCount | 0x0 | 0x41e180 | 0x21c54 | 0x20254 | 0x2b5 |
HeapSize | 0x0 | 0x41e184 | 0x21c58 | 0x20258 | 0x2a6 |
SetConsoleCtrlHandler | 0x0 | 0x41e188 | 0x21c5c | 0x2025c | 0x3a7 |
FreeLibrary | 0x0 | 0x41e18c | 0x21c60 | 0x20260 | 0x14c |
InterlockedExchange | 0x0 | 0x41e190 | 0x21c64 | 0x20264 | 0x2bd |
GetOEMCP | 0x0 | 0x41e194 | 0x21c68 | 0x20268 | 0x213 |
IsValidCodePage | 0x0 | 0x41e198 | 0x21c6c | 0x2026c | 0x2db |
GetConsoleCP | 0x0 | 0x41e19c | 0x21c70 | 0x20270 | 0x183 |
GetConsoleMode | 0x0 | 0x41e1a0 | 0x21c74 | 0x20274 | 0x195 |
FlushFileBuffers | 0x0 | 0x41e1a4 | 0x21c78 | 0x20278 | 0x141 |
SetFilePointer | 0x0 | 0x41e1a8 | 0x21c7c | 0x2027c | 0x3df |
SetStdHandle | 0x0 | 0x41e1ac | 0x21c80 | 0x20280 | 0x3fc |
GetLocaleInfoW | 0x0 | 0x41e1b0 | 0x21c84 | 0x20284 | 0x1ea |
GetLocaleInfoA | 0x0 | 0x41e1b4 | 0x21c88 | 0x20288 | 0x1e8 |
LCMapStringA | 0x0 | 0x41e1b8 | 0x21c8c | 0x2028c | 0x2e1 |
SetEnvironmentVariableA | 0x0 | 0x41e1bc | 0x21c90 | 0x20290 | 0x3d0 |
USER32.dll (10)
»
API Name | Ordinal | IAT Address | Thunk RVA | Thunk Offset | Hint |
---|---|---|---|---|---|
CloseClipboard | 0x0 | 0x41e1d8 | 0x21cac | 0x202ac | 0x47 |
BeginPaint | 0x0 | 0x41e1dc | 0x21cb0 | 0x202b0 | 0xe |
CallMsgFilterW | 0x0 | 0x41e1e0 | 0x21cb4 | 0x202b4 | 0x1a |
PeekMessageA | 0x0 | 0x41e1e4 | 0x21cb8 | 0x202b8 | 0x21b |
MapVirtualKeyExW | 0x0 | 0x41e1e8 | 0x21cbc | 0x202bc | 0x1f1 |
RegisterRawInputDevices | 0x0 | 0x41e1ec | 0x21cc0 | 0x202c0 | 0x242 |
GetClipboardSequenceNumber | 0x0 | 0x41e1f0 | 0x21cc4 | 0x202c4 | 0x113 |
CountClipboardFormats | 0x0 | 0x41e1f4 | 0x21cc8 | 0x202c8 | 0x50 |
GetDialogBaseUnits | 0x0 | 0x41e1f8 | 0x21ccc | 0x202cc | 0x11d |
GetClassLongW | 0x0 | 0x41e1fc | 0x21cd0 | 0x202d0 | 0x109 |
GDI32.dll (9)
»
API Name | Ordinal | IAT Address | Thunk RVA | Thunk Offset | Hint |
---|---|---|---|---|---|
PolyTextOutW | 0x0 | 0x41e000 | 0x21ad4 | 0x200d4 | 0x23c |
CreateCompatibleDC | 0x0 | 0x41e004 | 0x21ad8 | 0x200d8 | 0x2e |
Rectangle | 0x0 | 0x41e008 | 0x21adc | 0x200dc | 0x246 |
SetStretchBltMode | 0x0 | 0x41e00c | 0x21ae0 | 0x200e0 | 0x289 |
SetPixelV | 0x0 | 0x41e010 | 0x21ae4 | 0x200e4 | 0x284 |
GetClipBox | 0x0 | 0x41e014 | 0x21ae8 | 0x200e8 | 0x1aa |
CreateDiscardableBitmap | 0x0 | 0x41e018 | 0x21aec | 0x200ec | 0x35 |
StrokeAndFillPath | 0x0 | 0x41e01c | 0x21af0 | 0x200f0 | 0x29c |
GetBitmapBits | 0x0 | 0x41e020 | 0x21af4 | 0x200f4 | 0x191 |
SHELL32.dll (4)
»
API Name | Ordinal | IAT Address | Thunk RVA | Thunk Offset | Hint |
---|---|---|---|---|---|
ShellExecuteW | 0x0 | 0x41e1c4 | 0x21c98 | 0x20298 | 0x118 |
ShellAboutW | 0x0 | 0x41e1c8 | 0x21c9c | 0x2029c | 0x110 |
DuplicateIcon | 0x0 | 0x41e1cc | 0x21ca0 | 0x202a0 | 0x23 |
DragQueryFileA | 0x0 | 0x41e1d0 | 0x21ca4 | 0x202a4 | 0x1e |
Local AV Matches (1)
»
Threat Name | Severity |
---|---|
Trojan.GenericKD.31534187 |
Malicious
|
C:\Users\5p5NrGJn0jS HALPmcxz\AppData\Local\1eed4f4c-ee3f-42d5-9fd1-74f531bda6b5\updatewin2.exe | Downloaded File | Binary |
Malicious
|
...
|
»
File Reputation Information
»
Severity |
Blacklisted
|
PE Information
»
Image Base | 0x400000 |
Entry Point | 0x402d64 |
Size Of Code | 0x1c200 |
Size Of Initialized Data | 0x2c800 |
File Type | FileType.executable |
Subsystem | Subsystem.windows_gui |
Machine Type | MachineType.i386 |
Compile Timestamp | 2017-11-21 06:08:45+00:00 |
Version Information (3)
»
FileVersion | 5.3.7.82 |
InternalName | gigifaw.exe |
LegalCopyright | Copyright (C) 2018, guvaxiz |
Sections (5)
»
Name | Virtual Address | Virtual Size | Raw Data Size | Raw Data Offset | Flags | Entropy |
---|---|---|---|---|---|---|
.text | 0x401000 | 0x1c03e | 0x1c200 | 0x400 | IMAGE_SCN_CNT_CODE, IMAGE_SCN_MEM_EXECUTE, IMAGE_SCN_MEM_READ | 6.62 |
.rdata | 0x41e000 | 0x45ec | 0x4600 | 0x1c600 | IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_READ | 5.34 |
.data | 0x423000 | 0x1cde8 | 0x17c00 | 0x20c00 | IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_READ, IMAGE_SCN_MEM_WRITE | 5.8 |
.rsrc | 0x440000 | 0xa724 | 0xa800 | 0x38800 | IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_READ | 6.88 |
.reloc | 0x44b000 | 0x195c | 0x1a00 | 0x43000 | IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_DISCARDABLE, IMAGE_SCN_MEM_READ | 6.33 |
Imports (4)
»
KERNEL32.dll (98)
»
API Name | Ordinal | IAT Address | Thunk RVA | Thunk Offset | Hint |
---|---|---|---|---|---|
ExitThread | 0x0 | 0x41e024 | 0x21ae8 | 0x200e8 | 0x105 |
GetStartupInfoW | 0x0 | 0x41e028 | 0x21aec | 0x200ec | 0x23a |
GetLastError | 0x0 | 0x41e02c | 0x21af0 | 0x200f0 | 0x1e6 |
GetProcAddress | 0x0 | 0x41e030 | 0x21af4 | 0x200f4 | 0x220 |
GlobalFree | 0x0 | 0x41e034 | 0x21af8 | 0x200f8 | 0x28c |
LoadLibraryA | 0x0 | 0x41e038 | 0x21afc | 0x200fc | 0x2f1 |
AddAtomA | 0x0 | 0x41e03c | 0x21b00 | 0x20100 | 0x3 |
FindFirstChangeNotificationA | 0x0 | 0x41e040 | 0x21b04 | 0x20104 | 0x11b |
VirtualProtect | 0x0 | 0x41e044 | 0x21b08 | 0x20108 | 0x45a |
GetCurrentDirectoryA | 0x0 | 0x41e048 | 0x21b0c | 0x2010c | 0x1a7 |
SetProcessShutdownParameters | 0x0 | 0x41e04c | 0x21b10 | 0x20110 | 0x3f9 |
GetACP | 0x0 | 0x41e050 | 0x21b14 | 0x20114 | 0x152 |
CompareStringA | 0x0 | 0x41e054 | 0x21b18 | 0x20118 | 0x52 |
CreateFileA | 0x0 | 0x41e058 | 0x21b1c | 0x2011c | 0x78 |
GetTimeZoneInformation | 0x0 | 0x41e05c | 0x21b20 | 0x20120 | 0x26b |
WriteConsoleW | 0x0 | 0x41e060 | 0x21b24 | 0x20124 | 0x48c |
GetConsoleOutputCP | 0x0 | 0x41e064 | 0x21b28 | 0x20128 | 0x199 |
WriteConsoleA | 0x0 | 0x41e068 | 0x21b2c | 0x2012c | 0x482 |
CloseHandle | 0x0 | 0x41e06c | 0x21b30 | 0x20130 | 0x43 |
IsValidLocale | 0x0 | 0x41e070 | 0x21b34 | 0x20134 | 0x2dd |
EnumSystemLocalesA | 0x0 | 0x41e074 | 0x21b38 | 0x20138 | 0xf8 |
GetUserDefaultLCID | 0x0 | 0x41e078 | 0x21b3c | 0x2013c | 0x26d |
GetDateFormatA | 0x0 | 0x41e07c | 0x21b40 | 0x20140 | 0x1ae |
GetTimeFormatA | 0x0 | 0x41e080 | 0x21b44 | 0x20144 | 0x268 |
InitAtomTable | 0x0 | 0x41e084 | 0x21b48 | 0x20148 | 0x2ae |
GetSystemTimes | 0x0 | 0x41e088 | 0x21b4c | 0x2014c | 0x250 |
GetTickCount | 0x0 | 0x41e08c | 0x21b50 | 0x20150 | 0x266 |
FreeEnvironmentStringsA | 0x0 | 0x41e090 | 0x21b54 | 0x20154 | 0x14a |
GetComputerNameW | 0x0 | 0x41e094 | 0x21b58 | 0x20158 | 0x178 |
FindCloseChangeNotification | 0x0 | 0x41e098 | 0x21b5c | 0x2015c | 0x11a |
FindResourceExW | 0x0 | 0x41e09c | 0x21b60 | 0x20160 | 0x138 |
CompareStringW | 0x0 | 0x41e0a0 | 0x21b64 | 0x20164 | 0x55 |
GetCPInfo | 0x0 | 0x41e0a4 | 0x21b68 | 0x20168 | 0x15b |
GetStringTypeW | 0x0 | 0x41e0a8 | 0x21b6c | 0x2016c | 0x240 |
GetStringTypeA | 0x0 | 0x41e0ac | 0x21b70 | 0x20170 | 0x23d |
LCMapStringW | 0x0 | 0x41e0b0 | 0x21b74 | 0x20174 | 0x2e3 |
LCMapStringA | 0x0 | 0x41e0b4 | 0x21b78 | 0x20178 | 0x2e1 |
GetLocaleInfoA | 0x0 | 0x41e0b8 | 0x21b7c | 0x2017c | 0x1e8 |
GetCommandLineA | 0x0 | 0x41e0bc | 0x21b80 | 0x20180 | 0x16f |
GetStartupInfoA | 0x0 | 0x41e0c0 | 0x21b84 | 0x20184 | 0x239 |
RaiseException | 0x0 | 0x41e0c4 | 0x21b88 | 0x20188 | 0x35a |
RtlUnwind | 0x0 | 0x41e0c8 | 0x21b8c | 0x2018c | 0x392 |
TerminateProcess | 0x0 | 0x41e0cc | 0x21b90 | 0x20190 | 0x42d |
GetCurrentProcess | 0x0 | 0x41e0d0 | 0x21b94 | 0x20194 | 0x1a9 |
UnhandledExceptionFilter | 0x0 | 0x41e0d4 | 0x21b98 | 0x20198 | 0x43e |
SetUnhandledExceptionFilter | 0x0 | 0x41e0d8 | 0x21b9c | 0x2019c | 0x415 |
IsDebuggerPresent | 0x0 | 0x41e0dc | 0x21ba0 | 0x201a0 | 0x2d1 |
HeapAlloc | 0x0 | 0x41e0e0 | 0x21ba4 | 0x201a4 | 0x29d |
HeapFree | 0x0 | 0x41e0e4 | 0x21ba8 | 0x201a8 | 0x2a1 |
EnterCriticalSection | 0x0 | 0x41e0e8 | 0x21bac | 0x201ac | 0xd9 |
LeaveCriticalSection | 0x0 | 0x41e0ec | 0x21bb0 | 0x201b0 | 0x2ef |
SetHandleCount | 0x0 | 0x41e0f0 | 0x21bb4 | 0x201b4 | 0x3e8 |
GetStdHandle | 0x0 | 0x41e0f4 | 0x21bb8 | 0x201b8 | 0x23b |
GetFileType | 0x0 | 0x41e0f8 | 0x21bbc | 0x201bc | 0x1d7 |
DeleteCriticalSection | 0x0 | 0x41e0fc | 0x21bc0 | 0x201c0 | 0xbe |
GetModuleHandleW | 0x0 | 0x41e100 | 0x21bc4 | 0x201c4 | 0x1f9 |
Sleep | 0x0 | 0x41e104 | 0x21bc8 | 0x201c8 | 0x421 |
ExitProcess | 0x0 | 0x41e108 | 0x21bcc | 0x201cc | 0x104 |
WriteFile | 0x0 | 0x41e10c | 0x21bd0 | 0x201d0 | 0x48d |
GetModuleFileNameA | 0x0 | 0x41e110 | 0x21bd4 | 0x201d4 | 0x1f4 |
GetEnvironmentStrings | 0x0 | 0x41e114 | 0x21bd8 | 0x201d8 | 0x1bf |
FreeEnvironmentStringsW | 0x0 | 0x41e118 | 0x21bdc | 0x201dc | 0x14b |
WideCharToMultiByte | 0x0 | 0x41e11c | 0x21be0 | 0x201e0 | 0x47a |
GetEnvironmentStringsW | 0x0 | 0x41e120 | 0x21be4 | 0x201e4 | 0x1c1 |
TlsGetValue | 0x0 | 0x41e124 | 0x21be8 | 0x201e8 | 0x434 |
TlsAlloc | 0x0 | 0x41e128 | 0x21bec | 0x201ec | 0x432 |
TlsSetValue | 0x0 | 0x41e12c | 0x21bf0 | 0x201f0 | 0x435 |
TlsFree | 0x0 | 0x41e130 | 0x21bf4 | 0x201f4 | 0x433 |
InterlockedIncrement | 0x0 | 0x41e134 | 0x21bf8 | 0x201f8 | 0x2c0 |
SetLastError | 0x0 | 0x41e138 | 0x21bfc | 0x201fc | 0x3ec |
GetCurrentThreadId | 0x0 | 0x41e13c | 0x21c00 | 0x20200 | 0x1ad |
InterlockedDecrement | 0x0 | 0x41e140 | 0x21c04 | 0x20204 | 0x2bc |
GetCurrentThread | 0x0 | 0x41e144 | 0x21c08 | 0x20208 | 0x1ac |
HeapCreate | 0x0 | 0x41e148 | 0x21c0c | 0x2020c | 0x29f |
HeapDestroy | 0x0 | 0x41e14c | 0x21c10 | 0x20210 | 0x2a0 |
VirtualFree | 0x0 | 0x41e150 | 0x21c14 | 0x20214 | 0x457 |
QueryPerformanceCounter | 0x0 | 0x41e154 | 0x21c18 | 0x20218 | 0x354 |
GetCurrentProcessId | 0x0 | 0x41e158 | 0x21c1c | 0x2021c | 0x1aa |
GetSystemTimeAsFileTime | 0x0 | 0x41e15c | 0x21c20 | 0x20220 | 0x24f |
FatalAppExitA | 0x0 | 0x41e160 | 0x21c24 | 0x20224 | 0x10b |
VirtualAlloc | 0x0 | 0x41e164 | 0x21c28 | 0x20228 | 0x454 |
HeapReAlloc | 0x0 | 0x41e168 | 0x21c2c | 0x2022c | 0x2a4 |
MultiByteToWideChar | 0x0 | 0x41e16c | 0x21c30 | 0x20230 | 0x31a |
ReadFile | 0x0 | 0x41e170 | 0x21c34 | 0x20234 | 0x368 |
InitializeCriticalSectionAndSpinCount | 0x0 | 0x41e174 | 0x21c38 | 0x20238 | 0x2b5 |
HeapSize | 0x0 | 0x41e178 | 0x21c3c | 0x2023c | 0x2a6 |
SetConsoleCtrlHandler | 0x0 | 0x41e17c | 0x21c40 | 0x20240 | 0x3a7 |
FreeLibrary | 0x0 | 0x41e180 | 0x21c44 | 0x20244 | 0x14c |
InterlockedExchange | 0x0 | 0x41e184 | 0x21c48 | 0x20248 | 0x2bd |
GetOEMCP | 0x0 | 0x41e188 | 0x21c4c | 0x2024c | 0x213 |
IsValidCodePage | 0x0 | 0x41e18c | 0x21c50 | 0x20250 | 0x2db |
GetConsoleCP | 0x0 | 0x41e190 | 0x21c54 | 0x20254 | 0x183 |
GetConsoleMode | 0x0 | 0x41e194 | 0x21c58 | 0x20258 | 0x195 |
FlushFileBuffers | 0x0 | 0x41e198 | 0x21c5c | 0x2025c | 0x141 |
SetFilePointer | 0x0 | 0x41e19c | 0x21c60 | 0x20260 | 0x3df |
SetStdHandle | 0x0 | 0x41e1a0 | 0x21c64 | 0x20264 | 0x3fc |
GetLocaleInfoW | 0x0 | 0x41e1a4 | 0x21c68 | 0x20268 | 0x1ea |
SetEnvironmentVariableA | 0x0 | 0x41e1a8 | 0x21c6c | 0x2026c | 0x3d0 |
USER32.dll (12)
»
API Name | Ordinal | IAT Address | Thunk RVA | Thunk Offset | Hint |
---|---|---|---|---|---|
CloseClipboard | 0x0 | 0x41e1c4 | 0x21c88 | 0x20288 | 0x47 |
GetSubMenu | 0x0 | 0x41e1c8 | 0x21c8c | 0x2028c | 0x16b |
LoadBitmapA | 0x0 | 0x41e1cc | 0x21c90 | 0x20290 | 0x1d0 |
BeginPaint | 0x0 | 0x41e1d0 | 0x21c94 | 0x20294 | 0xe |
CallMsgFilterW | 0x0 | 0x41e1d4 | 0x21c98 | 0x20298 | 0x1a |
PeekMessageA | 0x0 | 0x41e1d8 | 0x21c9c | 0x2029c | 0x21b |
MapVirtualKeyExW | 0x0 | 0x41e1dc | 0x21ca0 | 0x202a0 | 0x1f1 |
RegisterRawInputDevices | 0x0 | 0x41e1e0 | 0x21ca4 | 0x202a4 | 0x242 |
SetWindowsHookExW | 0x0 | 0x41e1e4 | 0x21ca8 | 0x202a8 | 0x2b0 |
GetClipboardSequenceNumber | 0x0 | 0x41e1e8 | 0x21cac | 0x202ac | 0x113 |
GetDialogBaseUnits | 0x0 | 0x41e1ec | 0x21cb0 | 0x202b0 | 0x11d |
MessageBoxIndirectA | 0x0 | 0x41e1f0 | 0x21cb4 | 0x202b4 | 0x1fb |
GDI32.dll (8)
»
API Name | Ordinal | IAT Address | Thunk RVA | Thunk Offset | Hint |
---|---|---|---|---|---|
CreateCompatibleDC | 0x0 | 0x41e000 | 0x21ac4 | 0x200c4 | 0x2e |
PlayEnhMetaFile | 0x0 | 0x41e004 | 0x21ac8 | 0x200c8 | 0x230 |
ScaleViewportExtEx | 0x0 | 0x41e008 | 0x21acc | 0x200cc | 0x258 |
SetStretchBltMode | 0x0 | 0x41e00c | 0x21ad0 | 0x200d0 | 0x289 |
SetPixelV | 0x0 | 0x41e010 | 0x21ad4 | 0x200d4 | 0x284 |
CreateDiscardableBitmap | 0x0 | 0x41e014 | 0x21ad8 | 0x200d8 | 0x35 |
AddFontResourceW | 0x0 | 0x41e018 | 0x21adc | 0x200dc | 0x7 |
SetDeviceGammaRamp | 0x0 | 0x41e01c | 0x21ae0 | 0x200e0 | 0x271 |
SHELL32.dll (4)
»
API Name | Ordinal | IAT Address | Thunk RVA | Thunk Offset | Hint |
---|---|---|---|---|---|
ExtractAssociatedIconA | 0x0 | 0x41e1b0 | 0x21c74 | 0x20274 | 0x24 |
ShellExecuteW | 0x0 | 0x41e1b4 | 0x21c78 | 0x20278 | 0x118 |
ShellAboutW | 0x0 | 0x41e1b8 | 0x21c7c | 0x2027c | 0x110 |
DragQueryFileA | 0x0 | 0x41e1bc | 0x21c80 | 0x20280 | 0x1e |
Memory Dumps (6)
»
Name | Process ID | Start VA | End VA | Dump Reason | PE Rebuild | Bitness | Entry Point | AV | YARA | Actions |
---|---|---|---|---|---|---|---|---|---|---|
updatewin2.exe | 8 | 0x00400000 | 0x0044CFFF | Relevant Image |
![]() |
32-bit | 0x00404264 |
![]() |
![]() |
...
|
buffer | 8 | 0x00585000 | 0x00585FFF | First Execution |
![]() |
32-bit | 0x00585AB8 |
![]() |
![]() |
...
|
updatewin2.exe | 8 | 0x00400000 | 0x0044CFFF | Content Changed |
![]() |
32-bit | 0x00402350 |
![]() |
![]() |
...
|
updatewin2.exe | 8 | 0x00400000 | 0x0044CFFF | Content Changed |
![]() |
32-bit | 0x0040D7C3 |
![]() |
![]() |
...
|
updatewin2.exe | 8 | 0x00400000 | 0x0044CFFF | Content Changed |
![]() |
32-bit | 0x00401730 |
![]() |
![]() |
...
|
updatewin2.exe | 8 | 0x00400000 | 0x0044CFFF | Process Termination |
![]() |
32-bit | - |
![]() |
![]() |
...
|
Local AV Matches (1)
»
Threat Name | Severity |
---|---|
Trojan.AgentWDCR.SVC |
Malicious
|
C:\Users\5p5NrGJn0jS HALPmcxz\AppData\Local\1eed4f4c-ee3f-42d5-9fd1-74f531bda6b5\5.exe | Downloaded File | Binary |
Malicious
|
...
|
»
PE Information
»
Image Base | 0x400000 |
Entry Point | 0x401e4a |
Size Of Code | 0x65c00 |
Size Of Initialized Data | 0x2993600 |
File Type | FileType.executable |
Subsystem | Subsystem.windows_gui |
Machine Type | MachineType.i386 |
Compile Timestamp | 2018-11-23 08:27:08+00:00 |
Sections (5)
»
Name | Virtual Address | Virtual Size | Raw Data Size | Raw Data Offset | Flags | Entropy |
---|---|---|---|---|---|---|
.text | 0x401000 | 0x65b8f | 0x65c00 | 0x400 | IMAGE_SCN_CNT_CODE, IMAGE_SCN_MEM_EXECUTE, IMAGE_SCN_MEM_READ | 7.94 |
.rdata | 0x467000 | 0x3166 | 0x3200 | 0x66000 | IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_READ | 5.38 |
.data | 0x46b000 | 0x297ebc4 | 0x4200 | 0x69200 | IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_READ, IMAGE_SCN_MEM_WRITE | 1.32 |
.minag | 0x2dea000 | 0x66 | 0x200 | 0x6d400 | IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_READ, IMAGE_SCN_MEM_WRITE | 0.0 |
.rsrc | 0x2deb000 | 0x8e68 | 0x9000 | 0x6d600 | IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_READ | 5.41 |
Imports (2)
»
KERNEL32.dll (95)
»
API Name | Ordinal | IAT Address | Thunk RVA | Thunk Offset | Hint |
---|---|---|---|---|---|
GetProcessTimes | 0x0 | 0x467010 | 0x698b0 | 0x688b0 | 0x22a |
LocalHandle | 0x0 | 0x467014 | 0x698b4 | 0x688b4 | 0x2fe |
ReadFile | 0x0 | 0x467018 | 0x698b8 | 0x688b8 | 0x368 |
CreateFileW | 0x0 | 0x46701c | 0x698bc | 0x688bc | 0x7f |
lstrcatA | 0x0 | 0x467020 | 0x698c0 | 0x688c0 | 0x4a6 |
lstrlenW | 0x0 | 0x467024 | 0x698c4 | 0x688c4 | 0x4b6 |
SetConsoleTitleA | 0x0 | 0x467028 | 0x698c8 | 0x688c8 | 0x3c1 |
WritePrivateProfileStringW | 0x0 | 0x46702c | 0x698cc | 0x688cc | 0x493 |
GetLastError | 0x0 | 0x467030 | 0x698d0 | 0x688d0 | 0x1e6 |
GetProcAddress | 0x0 | 0x467034 | 0x698d4 | 0x688d4 | 0x220 |
GetDriveTypeA | 0x0 | 0x467038 | 0x698d8 | 0x688d8 | 0x1ba |
BuildCommDCBW | 0x0 | 0x46703c | 0x698dc | 0x688dc | 0x2e |
GetAtomNameA | 0x0 | 0x467040 | 0x698e0 | 0x688e0 | 0x155 |
LoadLibraryA | 0x0 | 0x467044 | 0x698e4 | 0x688e4 | 0x2f1 |
WriteConsoleA | 0x0 | 0x467048 | 0x698e8 | 0x688e8 | 0x482 |
RegisterWaitForSingleObjectEx | 0x0 | 0x46704c | 0x698ec | 0x688ec | 0x373 |
GlobalWire | 0x0 | 0x467050 | 0x698f0 | 0x688f0 | 0x298 |
GetProcessShutdownParameters | 0x0 | 0x467054 | 0x698f4 | 0x688f4 | 0x229 |
DebugBreakProcess | 0x0 | 0x467058 | 0x698f8 | 0x688f8 | 0xb5 |
OpenFileMappingW | 0x0 | 0x46705c | 0x698fc | 0x688fc | 0x32c |
VirtualProtect | 0x0 | 0x467060 | 0x69900 | 0x68900 | 0x45a |
GetCurrentProcessId | 0x0 | 0x467064 | 0x69904 | 0x68904 | 0x1aa |
EnumSystemLocalesW | 0x0 | 0x467068 | 0x69908 | 0x68908 | 0xfa |
GetCommandLineA | 0x0 | 0x46706c | 0x6990c | 0x6890c | 0x16f |
BackupSeek | 0x0 | 0x467070 | 0x69910 | 0x68910 | 0x17 |
GetSystemDefaultLCID | 0x0 | 0x467074 | 0x69914 | 0x68914 | 0x241 |
GetCurrentProcess | 0x0 | 0x467078 | 0x69918 | 0x68918 | 0x1a9 |
LoadResource | 0x0 | 0x46707c | 0x6991c | 0x6891c | 0x2f6 |
MapViewOfFile | 0x0 | 0x467080 | 0x69920 | 0x68920 | 0x30a |
IsBadStringPtrW | 0x0 | 0x467084 | 0x69924 | 0x68924 | 0x2ca |
FindResourceA | 0x0 | 0x467088 | 0x69928 | 0x68928 | 0x136 |
CreateTimerQueue | 0x0 | 0x46708c | 0x6992c | 0x6892c | 0xaa |
HeapReAlloc | 0x0 | 0x467090 | 0x69930 | 0x68930 | 0x2a4 |
GetStartupInfoW | 0x0 | 0x467094 | 0x69934 | 0x68934 | 0x23a |
RaiseException | 0x0 | 0x467098 | 0x69938 | 0x68938 | 0x35a |
RtlUnwind | 0x0 | 0x46709c | 0x6993c | 0x6893c | 0x392 |
TerminateProcess | 0x0 | 0x4670a0 | 0x69940 | 0x68940 | 0x42d |
UnhandledExceptionFilter | 0x0 | 0x4670a4 | 0x69944 | 0x68944 | 0x43e |
SetUnhandledExceptionFilter | 0x0 | 0x4670a8 | 0x69948 | 0x68948 | 0x415 |
IsDebuggerPresent | 0x0 | 0x4670ac | 0x6994c | 0x6894c | 0x2d1 |
HeapAlloc | 0x0 | 0x4670b0 | 0x69950 | 0x68950 | 0x29d |
HeapFree | 0x0 | 0x4670b4 | 0x69954 | 0x68954 | 0x2a1 |
GetModuleHandleW | 0x0 | 0x4670b8 | 0x69958 | 0x68958 | 0x1f9 |
Sleep | 0x0 | 0x4670bc | 0x6995c | 0x6895c | 0x421 |
ExitProcess | 0x0 | 0x4670c0 | 0x69960 | 0x68960 | 0x104 |
WriteFile | 0x0 | 0x4670c4 | 0x69964 | 0x68964 | 0x48d |
GetStdHandle | 0x0 | 0x4670c8 | 0x69968 | 0x68968 | 0x23b |
GetModuleFileNameA | 0x0 | 0x4670cc | 0x6996c | 0x6896c | 0x1f4 |
GetModuleFileNameW | 0x0 | 0x4670d0 | 0x69970 | 0x68970 | 0x1f5 |
FreeEnvironmentStringsW | 0x0 | 0x4670d4 | 0x69974 | 0x68974 | 0x14b |
GetEnvironmentStringsW | 0x0 | 0x4670d8 | 0x69978 | 0x68978 | 0x1c1 |
GetCommandLineW | 0x0 | 0x4670dc | 0x6997c | 0x6897c | 0x170 |
SetHandleCount | 0x0 | 0x4670e0 | 0x69980 | 0x68980 | 0x3e8 |
GetFileType | 0x0 | 0x4670e4 | 0x69984 | 0x68984 | 0x1d7 |
GetStartupInfoA | 0x0 | 0x4670e8 | 0x69988 | 0x68988 | 0x239 |
DeleteCriticalSection | 0x0 | 0x4670ec | 0x6998c | 0x6898c | 0xbe |
TlsGetValue | 0x0 | 0x4670f0 | 0x69990 | 0x68990 | 0x434 |
TlsAlloc | 0x0 | 0x4670f4 | 0x69994 | 0x68994 | 0x432 |
TlsSetValue | 0x0 | 0x4670f8 | 0x69998 | 0x68998 | 0x435 |
TlsFree | 0x0 | 0x4670fc | 0x6999c | 0x6899c | 0x433 |
InterlockedIncrement | 0x0 | 0x467100 | 0x699a0 | 0x689a0 | 0x2c0 |
SetLastError | 0x0 | 0x467104 | 0x699a4 | 0x689a4 | 0x3ec |
GetCurrentThreadId | 0x0 | 0x467108 | 0x699a8 | 0x689a8 | 0x1ad |
InterlockedDecrement | 0x0 | 0x46710c | 0x699ac | 0x689ac | 0x2bc |
HeapCreate | 0x0 | 0x467110 | 0x699b0 | 0x689b0 | 0x29f |
VirtualFree | 0x0 | 0x467114 | 0x699b4 | 0x689b4 | 0x457 |
QueryPerformanceCounter | 0x0 | 0x467118 | 0x699b8 | 0x689b8 | 0x354 |
GetTickCount | 0x0 | 0x46711c | 0x699bc | 0x689bc | 0x266 |
GetSystemTimeAsFileTime | 0x0 | 0x467120 | 0x699c0 | 0x689c0 | 0x24f |
SetFilePointer | 0x0 | 0x467124 | 0x699c4 | 0x689c4 | 0x3df |
WideCharToMultiByte | 0x0 | 0x467128 | 0x699c8 | 0x689c8 | 0x47a |
GetConsoleCP | 0x0 | 0x46712c | 0x699cc | 0x689cc | 0x183 |
GetConsoleMode | 0x0 | 0x467130 | 0x699d0 | 0x689d0 | 0x195 |
EnterCriticalSection | 0x0 | 0x467134 | 0x699d4 | 0x689d4 | 0xd9 |
LeaveCriticalSection | 0x0 | 0x467138 | 0x699d8 | 0x689d8 | 0x2ef |
GetCPInfo | 0x0 | 0x46713c | 0x699dc | 0x689dc | 0x15b |
GetACP | 0x0 | 0x467140 | 0x699e0 | 0x689e0 | 0x152 |
GetOEMCP | 0x0 | 0x467144 | 0x699e4 | 0x689e4 | 0x213 |
IsValidCodePage | 0x0 | 0x467148 | 0x699e8 | 0x689e8 | 0x2db |
VirtualAlloc | 0x0 | 0x46714c | 0x699ec | 0x689ec | 0x454 |
HeapSize | 0x0 | 0x467150 | 0x699f0 | 0x689f0 | 0x2a6 |
InitializeCriticalSectionAndSpinCount | 0x0 | 0x467154 | 0x699f4 | 0x689f4 | 0x2b5 |
SetStdHandle | 0x0 | 0x467158 | 0x699f8 | 0x689f8 | 0x3fc |
GetConsoleOutputCP | 0x0 | 0x46715c | 0x699fc | 0x689fc | 0x199 |
WriteConsoleW | 0x0 | 0x467160 | 0x69a00 | 0x68a00 | 0x48c |
MultiByteToWideChar | 0x0 | 0x467164 | 0x69a04 | 0x68a04 | 0x31a |
LCMapStringA | 0x0 | 0x467168 | 0x69a08 | 0x68a08 | 0x2e1 |
LCMapStringW | 0x0 | 0x46716c | 0x69a0c | 0x68a0c | 0x2e3 |
GetStringTypeA | 0x0 | 0x467170 | 0x69a10 | 0x68a10 | 0x23d |
GetStringTypeW | 0x0 | 0x467174 | 0x69a14 | 0x68a14 | 0x240 |
GetLocaleInfoA | 0x0 | 0x467178 | 0x69a18 | 0x68a18 | 0x1e8 |
GetModuleHandleA | 0x0 | 0x46717c | 0x69a1c | 0x68a1c | 0x1f6 |
CreateFileA | 0x0 | 0x467180 | 0x69a20 | 0x68a20 | 0x78 |
CloseHandle | 0x0 | 0x467184 | 0x69a24 | 0x68a24 | 0x43 |
FlushFileBuffers | 0x0 | 0x467188 | 0x69a28 | 0x68a28 | 0x141 |
ADVAPI32.dll (3)
»
API Name | Ordinal | IAT Address | Thunk RVA | Thunk Offset | Hint |
---|---|---|---|---|---|
AllocateAndInitializeSid | 0x0 | 0x467000 | 0x698a0 | 0x688a0 | 0x1f |
AccessCheckAndAuditAlarmA | 0x0 | 0x467004 | 0x698a4 | 0x688a4 | 0x6 |
SetServiceObjectSecurity | 0x0 | 0x467008 | 0x698a8 | 0x688a8 | 0x2b9 |
Memory Dumps (2)
»
Name | Process ID | Start VA | End VA | Dump Reason | PE Rebuild | Bitness | Entry Point | AV | YARA | Actions |
---|---|---|---|---|---|---|---|---|---|---|
buffer | 9 | 0x002B0A80 | 0x003060EF | First Execution |
![]() |
32-bit | 0x002B0A80 |
![]() |
![]() |
...
|
buffer | 9 | 0x02E70000 | 0x02EF8FFF | First Execution |
![]() |
32-bit | 0x02E70000 |
![]() |
![]() |
...
|
Local AV Matches (1)
»
Threat Name | Severity |
---|---|
Trojan.GenericKD.42856061 |
Malicious
|
c:\users\5p5nrgjn0js halpmcxz\appdata\local\microsoft\windows\temporary internet files\content.ie5\index.dat | Modified File | Stream |
Unknown
|
...
|
»
c:\users\5p5nrgjn0js halpmcxz\appdata\roaming\microsoft\windows\cookies\index.dat | Modified File | Stream |
Unknown
|
...
|
»
c:\users\5p5nrgjn0js halpmcxz\appdata\roaming\microsoft\windows\ietldcache\index.dat | Modified File | Stream |
Unknown
|
...
|
»
c:\users\5p5nrgjn0js halpmcxz\appdata\local\microsoft\windows\temporary internet files\content.ie5\x9ohk109\geo[1].json | Dropped File | Text |
Unknown
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\AppData\LocalLow\Sun\Java\jre1.7.0_45\Data1.cab | Modified File | CAB |
Not Queried
|
...
|
»
c:\users\5p5nrgjn0js halpmcxz\appdata\local\microsoft\windows\history\history.ie5\index.dat | Modified File | Stream |
Not Queried
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\Documents\My Shapes\Favorites.vss.remk | Dropped File | Unknown |
Not Queried
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\AppData\Local\script.ps1 | Dropped File | Text |
Not Queried
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\_readme.txt | Dropped File | Text |
Not Queried
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\AppData\Local\bowsakkdestx.txt | Downloaded File | Text |
Not Queried
|
...
|
»