VTI SCORE: 100/100
Dynamic Analysis Report |
Classification: Ransomware, Wiper |
demo.exe
Windows Exe (x86-32)
Created at 2019-06-26T06:09:00
Remarks
(0x200001e): The maximum size of extracted files was exceeded. Some files may be missing in the report.
This is a filtered view
This list contains only the embedded files, downloaded files, and dropped files
Filters: |
There are no files for this filter
There are no files in this analysis
Filename | Category | Type | Severity | Actions |
---|
C:\Boot\BOOTSTAT.DAT.id-9C354B42.[bigmacbig@cock.li].beets | Dropped File | Stream |
Malicious
|
...
|
»
YARA Matches (1)
»
Rule Name | Rule Description | Classification | Severity | Actions |
---|---|---|---|---|
DharmaEncryptedFile | File encrypted by Dharma Ransomware | Ransomware |
Malicious
|
...
|
C:\BOOTSECT.BAK.id-9C354B42.[bigmacbig@cock.li].beets | Dropped File | Stream |
Malicious
|
...
|
»
YARA Matches (1)
»
Rule Name | Rule Description | Classification | Severity | Actions |
---|---|---|---|---|
DharmaEncryptedFile | File encrypted by Dharma Ransomware | Ransomware |
Malicious
|
...
|
C:\MSOCache\All Users\{90140000-0018-0409-1000-0000000FF1CE}-C\PowerPointMUI.xml.id-9C354B42.[bigmacbig@cock.li].beets | Dropped File | Stream |
Malicious
|
...
|
»
YARA Matches (1)
»
Rule Name | Rule Description | Classification | Severity | Actions |
---|---|---|---|---|
DharmaEncryptedFile | File encrypted by Dharma Ransomware | Ransomware |
Malicious
|
...
|
C:\MSOCache\All Users\{90140000-0018-0409-1000-0000000FF1CE}-C\Setup.xml.id-9C354B42.[bigmacbig@cock.li].beets | Dropped File | Stream |
Malicious
|
...
|
»
YARA Matches (1)
»
Rule Name | Rule Description | Classification | Severity | Actions |
---|---|---|---|---|
DharmaEncryptedFile | File encrypted by Dharma Ransomware | Ransomware |
Malicious
|
...
|
C:\MSOCache\All Users\{90140000-0019-0409-1000-0000000FF1CE}-C\Setup.xml.id-9C354B42.[bigmacbig@cock.li].beets | Dropped File | Stream |
Malicious
|
...
|
»
YARA Matches (1)
»
Rule Name | Rule Description | Classification | Severity | Actions |
---|---|---|---|---|
DharmaEncryptedFile | File encrypted by Dharma Ransomware | Ransomware |
Malicious
|
...
|
C:\MSOCache\All Users\{90140000-001A-0409-1000-0000000FF1CE}-C\OutlookMUI.xml.id-9C354B42.[bigmacbig@cock.li].beets | Dropped File | Stream |
Malicious
|
...
|
»
YARA Matches (1)
»
Rule Name | Rule Description | Classification | Severity | Actions |
---|---|---|---|---|
DharmaEncryptedFile | File encrypted by Dharma Ransomware | Ransomware |
Malicious
|
...
|
C:\MSOCache\All Users\{90140000-001A-0409-1000-0000000FF1CE}-C\Setup.xml.id-9C354B42.[bigmacbig@cock.li].beets | Dropped File | Compressed |
Malicious
|
...
|
»
YARA Matches (1)
»
Rule Name | Rule Description | Classification | Severity | Actions |
---|---|---|---|---|
DharmaEncryptedFile | File encrypted by Dharma Ransomware | Ransomware |
Malicious
|
...
|
C:\MSOCache\All Users\{90140000-001B-0409-1000-0000000FF1CE}-C\Setup.xml.id-9C354B42.[bigmacbig@cock.li].beets | Dropped File | Stream |
Malicious
|
...
|
»
YARA Matches (1)
»
Rule Name | Rule Description | Classification | Severity | Actions |
---|---|---|---|---|
DharmaEncryptedFile | File encrypted by Dharma Ransomware | Ransomware |
Malicious
|
...
|
C:\MSOCache\All Users\{90140000-0016-0409-1000-0000000FF1CE}-C\ExcelMUI.xml.id-9C354B42.[bigmacbig@cock.li].beets | Dropped File | Stream |
Malicious
|
...
|
»
YARA Matches (1)
»
Rule Name | Rule Description | Classification | Severity | Actions |
---|---|---|---|---|
DharmaEncryptedFile | File encrypted by Dharma Ransomware | Ransomware |
Malicious
|
...
|
C:\MSOCache\All Users\{90140000-002C-0409-1000-0000000FF1CE}-C\Proof.en\Proof.xml.id-9C354B42.[bigmacbig@cock.li].beets | Dropped File | Stream |
Malicious
|
...
|
»
YARA Matches (1)
»
Rule Name | Rule Description | Classification | Severity | Actions |
---|---|---|---|---|
DharmaEncryptedFile | File encrypted by Dharma Ransomware | Ransomware |
Malicious
|
...
|
C:\MSOCache\All Users\{90140000-002C-0409-1000-0000000FF1CE}-C\Proof.es\Proof.xml.id-9C354B42.[bigmacbig@cock.li].beets | Dropped File | Stream |
Malicious
|
...
|
»
YARA Matches (1)
»
Rule Name | Rule Description | Classification | Severity | Actions |
---|---|---|---|---|
DharmaEncryptedFile | File encrypted by Dharma Ransomware | Ransomware |
Malicious
|
...
|
C:\MSOCache\All Users\{90140000-0019-0409-1000-0000000FF1CE}-C\PublisherMUI.xml.id-9C354B42.[bigmacbig@cock.li].beets | Dropped File | Stream |
Malicious
|
...
|
»
YARA Matches (1)
»
Rule Name | Rule Description | Classification | Severity | Actions |
---|---|---|---|---|
DharmaEncryptedFile | File encrypted by Dharma Ransomware | Ransomware |
Malicious
|
...
|
C:\MSOCache\All Users\{90140000-002C-0409-1000-0000000FF1CE}-C\Proofing.xml.id-9C354B42.[bigmacbig@cock.li].beets | Dropped File | Stream |
Malicious
|
...
|
»
YARA Matches (1)
»
Rule Name | Rule Description | Classification | Severity | Actions |
---|---|---|---|---|
DharmaEncryptedFile | File encrypted by Dharma Ransomware | Ransomware |
Malicious
|
...
|
C:\MSOCache\All Users\{90140000-002C-0409-1000-0000000FF1CE}-C\Setup.xml.id-9C354B42.[bigmacbig@cock.li].beets | Dropped File | Stream |
Malicious
|
...
|
»
YARA Matches (1)
»
Rule Name | Rule Description | Classification | Severity | Actions |
---|---|---|---|---|
DharmaEncryptedFile | File encrypted by Dharma Ransomware | Ransomware |
Malicious
|
...
|
C:\MSOCache\All Users\{90140000-0043-0409-1000-0000000FF1CE}-C\Office32MUI.xml.id-9C354B42.[bigmacbig@cock.li].beets | Dropped File | Stream |
Malicious
|
...
|
»
YARA Matches (1)
»
Rule Name | Rule Description | Classification | Severity | Actions |
---|---|---|---|---|
DharmaEncryptedFile | File encrypted by Dharma Ransomware | Ransomware |
Malicious
|
...
|
C:\MSOCache\All Users\{90140000-001B-0409-1000-0000000FF1CE}-C\WordMUI.xml.id-9C354B42.[bigmacbig@cock.li].beets | Dropped File | Stream |
Malicious
|
...
|
»
YARA Matches (1)
»
Rule Name | Rule Description | Classification | Severity | Actions |
---|---|---|---|---|
DharmaEncryptedFile | File encrypted by Dharma Ransomware | Ransomware |
Malicious
|
...
|
C:\MSOCache\All Users\{90140000-0044-0409-1000-0000000FF1CE}-C\InfoPathMUI.xml.id-9C354B42.[bigmacbig@cock.li].beets | Dropped File | Stream |
Malicious
|
...
|
»
YARA Matches (1)
»
Rule Name | Rule Description | Classification | Severity | Actions |
---|---|---|---|---|
DharmaEncryptedFile | File encrypted by Dharma Ransomware | Ransomware |
Malicious
|
...
|
C:\MSOCache\All Users\{90140000-0044-0409-1000-0000000FF1CE}-C\Setup.xml.id-9C354B42.[bigmacbig@cock.li].beets | Dropped File | Stream |
Malicious
|
...
|
»
YARA Matches (1)
»
Rule Name | Rule Description | Classification | Severity | Actions |
---|---|---|---|---|
DharmaEncryptedFile | File encrypted by Dharma Ransomware | Ransomware |
Malicious
|
...
|
C:\MSOCache\All Users\{90140000-0054-0409-1000-0000000FF1CE}-C\Setup.xml.id-9C354B42.[bigmacbig@cock.li].beets | Dropped File | Stream |
Malicious
|
...
|
»
YARA Matches (1)
»
Rule Name | Rule Description | Classification | Severity | Actions |
---|---|---|---|---|
DharmaEncryptedFile | File encrypted by Dharma Ransomware | Ransomware |
Malicious
|
...
|
C:\MSOCache\All Users\{90140000-0016-0409-1000-0000000FF1CE}-C\Setup.xml.id-9C354B42.[bigmacbig@cock.li].beets | Dropped File | Stream |
Malicious
|
...
|
»
YARA Matches (1)
»
Rule Name | Rule Description | Classification | Severity | Actions |
---|---|---|---|---|
DharmaEncryptedFile | File encrypted by Dharma Ransomware | Ransomware |
Malicious
|
...
|
C:\MSOCache\All Users\{90140000-00A1-0409-1000-0000000FF1CE}-C\OneNoteMUI.xml.id-9C354B42.[bigmacbig@cock.li].beets | Dropped File | Stream |
Malicious
|
...
|
»
YARA Matches (1)
»
Rule Name | Rule Description | Classification | Severity | Actions |
---|---|---|---|---|
DharmaEncryptedFile | File encrypted by Dharma Ransomware | Ransomware |
Malicious
|
...
|
C:\MSOCache\All Users\{90140000-002C-0409-1000-0000000FF1CE}-C\Proof.fr\Proof.xml.id-9C354B42.[bigmacbig@cock.li].beets | Dropped File | Stream |
Malicious
|
...
|
»
YARA Matches (1)
»
Rule Name | Rule Description | Classification | Severity | Actions |
---|---|---|---|---|
DharmaEncryptedFile | File encrypted by Dharma Ransomware | Ransomware |
Malicious
|
...
|
C:\MSOCache\All Users\{90140000-0043-0409-1000-0000000FF1CE}-C\Setup.xml.id-9C354B42.[bigmacbig@cock.li].beets | Dropped File | Stream |
Malicious
|
...
|
»
YARA Matches (1)
»
Rule Name | Rule Description | Classification | Severity | Actions |
---|---|---|---|---|
DharmaEncryptedFile | File encrypted by Dharma Ransomware | Ransomware |
Malicious
|
...
|
C:\MSOCache\All Users\{90140000-0054-0409-1000-0000000FF1CE}-C\VisioMUI.xml.id-9C354B42.[bigmacbig@cock.li].beets | Dropped File | Stream |
Malicious
|
...
|
»
YARA Matches (1)
»
Rule Name | Rule Description | Classification | Severity | Actions |
---|---|---|---|---|
DharmaEncryptedFile | File encrypted by Dharma Ransomware | Ransomware |
Malicious
|
...
|
C:\MSOCache\All Users\{90140000-00BA-0409-1000-0000000FF1CE}-C\GrooveMUI.xml.id-9C354B42.[bigmacbig@cock.li].beets | Dropped File | Stream |
Malicious
|
...
|
»
YARA Matches (1)
»
Rule Name | Rule Description | Classification | Severity | Actions |
---|---|---|---|---|
DharmaEncryptedFile | File encrypted by Dharma Ransomware | Ransomware |
Malicious
|
...
|
C:\MSOCache\All Users\{90140000-00BA-0409-1000-0000000FF1CE}-C\Setup.xml.id-9C354B42.[bigmacbig@cock.li].beets | Dropped File | Stream |
Malicious
|
...
|
»
YARA Matches (1)
»
Rule Name | Rule Description | Classification | Severity | Actions |
---|---|---|---|---|
DharmaEncryptedFile | File encrypted by Dharma Ransomware | Ransomware |
Malicious
|
...
|
C:\MSOCache\All Users\{90140000-00A1-0409-1000-0000000FF1CE}-C\Setup.xml.id-9C354B42.[bigmacbig@cock.li].beets | Dropped File | Stream |
Malicious
|
...
|
»
YARA Matches (1)
»
Rule Name | Rule Description | Classification | Severity | Actions |
---|---|---|---|---|
DharmaEncryptedFile | File encrypted by Dharma Ransomware | Ransomware |
Malicious
|
...
|
C:\MSOCache\All Users\{90140000-0115-0409-1000-0000000FF1CE}-C\OfficeMUI.xml.id-9C354B42.[bigmacbig@cock.li].beets | Dropped File | Stream |
Malicious
|
...
|
»
YARA Matches (1)
»
Rule Name | Rule Description | Classification | Severity | Actions |
---|---|---|---|---|
DharmaEncryptedFile | File encrypted by Dharma Ransomware | Ransomware |
Malicious
|
...
|
C:\MSOCache\All Users\{90140000-00B4-0409-1000-0000000FF1CE}-C\Setup.xml.id-9C354B42.[bigmacbig@cock.li].beets | Dropped File | Stream |
Malicious
|
...
|
»
YARA Matches (1)
»
Rule Name | Rule Description | Classification | Severity | Actions |
---|---|---|---|---|
DharmaEncryptedFile | File encrypted by Dharma Ransomware | Ransomware |
Malicious
|
...
|
C:\MSOCache\All Users\{90140000-0115-0409-1000-0000000FF1CE}-C\OfficeMUISet.xml.id-9C354B42.[bigmacbig@cock.li].beets | Dropped File | Stream |
Malicious
|
...
|
»
YARA Matches (1)
»
Rule Name | Rule Description | Classification | Severity | Actions |
---|---|---|---|---|
DharmaEncryptedFile | File encrypted by Dharma Ransomware | Ransomware |
Malicious
|
...
|
C:\MSOCache\All Users\{90140000-0115-0409-1000-0000000FF1CE}-C\setup.chm.id-9C354B42.[bigmacbig@cock.li].beets | Dropped File | Stream |
Malicious
|
...
|
»
YARA Matches (1)
»
Rule Name | Rule Description | Classification | Severity | Actions |
---|---|---|---|---|
DharmaEncryptedFile | File encrypted by Dharma Ransomware | Ransomware |
Malicious
|
...
|
C:\MSOCache\All Users\{90140000-0115-0409-1000-0000000FF1CE}-C\Setup.xml.id-9C354B42.[bigmacbig@cock.li].beets | Dropped File | Stream |
Malicious
|
...
|
»
YARA Matches (1)
»
Rule Name | Rule Description | Classification | Severity | Actions |
---|---|---|---|---|
DharmaEncryptedFile | File encrypted by Dharma Ransomware | Ransomware |
Malicious
|
...
|
C:\MSOCache\All Users\{90140000-00B4-0409-1000-0000000FF1CE}-C\ProjectMUI.xml.id-9C354B42.[bigmacbig@cock.li].beets | Dropped File | Stream |
Malicious
|
...
|
»
YARA Matches (1)
»
Rule Name | Rule Description | Classification | Severity | Actions |
---|---|---|---|---|
DharmaEncryptedFile | File encrypted by Dharma Ransomware | Ransomware |
Malicious
|
...
|
C:\MSOCache\All Users\{90140000-0117-0409-1000-0000000FF1CE}-C\Access.en-us\AccessMUI.xml.id-9C354B42.[bigmacbig@cock.li].beets | Dropped File | Stream |
Malicious
|
...
|
»
YARA Matches (1)
»
Rule Name | Rule Description | Classification | Severity | Actions |
---|---|---|---|---|
DharmaEncryptedFile | File encrypted by Dharma Ransomware | Ransomware |
Malicious
|
...
|
C:\MSOCache\All Users\{90140000-0115-0409-1000-0000000FF1CE}-C\branding.xml.id-9C354B42.[bigmacbig@cock.li].beets | Dropped File | Stream |
Malicious
|
...
|
»
YARA Matches (1)
»
Rule Name | Rule Description | Classification | Severity | Actions |
---|---|---|---|---|
DharmaEncryptedFile | File encrypted by Dharma Ransomware | Ransomware |
Malicious
|
...
|
C:\MSOCache\All Users\{90140000-0117-0409-1000-0000000FF1CE}-C\Access.en-us\branding.xml.id-9C354B42.[bigmacbig@cock.li].beets | Dropped File | Stream |
Malicious
|
...
|
»
YARA Matches (1)
»
Rule Name | Rule Description | Classification | Severity | Actions |
---|---|---|---|---|
DharmaEncryptedFile | File encrypted by Dharma Ransomware | Ransomware |
Malicious
|
...
|
C:\MSOCache\All Users\{90140000-0115-0409-1000-0000000FF1CE}-C\pss10r.chm.id-9C354B42.[bigmacbig@cock.li].beets | Dropped File | Stream |
Malicious
|
...
|
»
YARA Matches (1)
»
Rule Name | Rule Description | Classification | Severity | Actions |
---|---|---|---|---|
DharmaEncryptedFile | File encrypted by Dharma Ransomware | Ransomware |
Malicious
|
...
|
C:\MSOCache\All Users\{90140000-0117-0409-1000-0000000FF1CE}-C\AccessMUISet.xml.id-9C354B42.[bigmacbig@cock.li].beets | Dropped File | Stream |
Malicious
|
...
|
»
YARA Matches (1)
»
Rule Name | Rule Description | Classification | Severity | Actions |
---|---|---|---|---|
DharmaEncryptedFile | File encrypted by Dharma Ransomware | Ransomware |
Malicious
|
...
|
C:\MSOCache\All Users\{91140000-0011-0000-1000-0000000FF1CE}-C\Setup.xml.id-9C354B42.[bigmacbig@cock.li].beets | Dropped File | Stream |
Malicious
|
...
|
»
YARA Matches (1)
»
Rule Name | Rule Description | Classification | Severity | Actions |
---|---|---|---|---|
DharmaEncryptedFile | File encrypted by Dharma Ransomware | Ransomware |
Malicious
|
...
|
C:\MSOCache\All Users\{91140000-003B-0000-1000-0000000FF1CE}-C\Office32WW.xml.id-9C354B42.[bigmacbig@cock.li].beets | Dropped File | Stream |
Malicious
|
...
|
»
YARA Matches (1)
»
Rule Name | Rule Description | Classification | Severity | Actions |
---|---|---|---|---|
DharmaEncryptedFile | File encrypted by Dharma Ransomware | Ransomware |
Malicious
|
...
|
C:\MSOCache\All Users\{91140000-003B-0000-1000-0000000FF1CE}-C\PrjProrWW.xml.id-9C354B42.[bigmacbig@cock.li].beets | Dropped File | Stream |
Malicious
|
...
|
»
YARA Matches (1)
»
Rule Name | Rule Description | Classification | Severity | Actions |
---|---|---|---|---|
DharmaEncryptedFile | File encrypted by Dharma Ransomware | Ransomware |
Malicious
|
...
|
C:\MSOCache\All Users\{91140000-003B-0000-1000-0000000FF1CE}-C\Setup.xml.id-9C354B42.[bigmacbig@cock.li].beets | Dropped File | Stream |
Malicious
|
...
|
»
YARA Matches (1)
»
Rule Name | Rule Description | Classification | Severity | Actions |
---|---|---|---|---|
DharmaEncryptedFile | File encrypted by Dharma Ransomware | Ransomware |
Malicious
|
...
|
C:\MSOCache\All Users\{91140000-0057-0000-1000-0000000FF1CE}-C\Office32WW.xml.id-9C354B42.[bigmacbig@cock.li].beets | Dropped File | Stream |
Malicious
|
...
|
»
YARA Matches (1)
»
Rule Name | Rule Description | Classification | Severity | Actions |
---|---|---|---|---|
DharmaEncryptedFile | File encrypted by Dharma Ransomware | Ransomware |
Malicious
|
...
|
C:\MSOCache\All Users\{91140000-0011-0000-1000-0000000FF1CE}-C\Office32WW.xml.id-9C354B42.[bigmacbig@cock.li].beets | Dropped File | Stream |
Malicious
|
...
|
»
YARA Matches (1)
»
Rule Name | Rule Description | Classification | Severity | Actions |
---|---|---|---|---|
DharmaEncryptedFile | File encrypted by Dharma Ransomware | Ransomware |
Malicious
|
...
|
C:\MSOCache\All Users\{91140000-0057-0000-1000-0000000FF1CE}-C\Setup.xml.id-9C354B42.[bigmacbig@cock.li].beets | Dropped File | Stream |
Malicious
|
...
|
»
YARA Matches (1)
»
Rule Name | Rule Description | Classification | Severity | Actions |
---|---|---|---|---|
DharmaEncryptedFile | File encrypted by Dharma Ransomware | Ransomware |
Malicious
|
...
|
C:\MSOCache\All Users\{91140000-0057-0000-1000-0000000FF1CE}-C\VisiorWW.xml.id-9C354B42.[bigmacbig@cock.li].beets | Dropped File | Stream |
Malicious
|
...
|
»
YARA Matches (1)
»
Rule Name | Rule Description | Classification | Severity | Actions |
---|---|---|---|---|
DharmaEncryptedFile | File encrypted by Dharma Ransomware | Ransomware |
Malicious
|
...
|
C:\Program Files\Common Files\Microsoft Shared\GRPHFLT\MS.EPS.id-9C354B42.[bigmacbig@cock.li].beets | Dropped File | Stream |
Malicious
|
...
|
»
YARA Matches (1)
»
Rule Name | Rule Description | Classification | Severity | Actions |
---|---|---|---|---|
DharmaEncryptedFile | File encrypted by Dharma Ransomware | Ransomware |
Malicious
|
...
|
C:\Program Files\Common Files\Microsoft Shared\GRPHFLT\MS.GIF.id-9C354B42.[bigmacbig@cock.li].beets | Dropped File | Stream |
Malicious
|
...
|
»
YARA Matches (1)
»
Rule Name | Rule Description | Classification | Severity | Actions |
---|---|---|---|---|
DharmaEncryptedFile | File encrypted by Dharma Ransomware | Ransomware |
Malicious
|
...
|
C:\Program Files\Common Files\Microsoft Shared\GRPHFLT\MS.PNG.id-9C354B42.[bigmacbig@cock.li].beets | Dropped File | Stream |
Malicious
|
...
|
»
YARA Matches (1)
»
Rule Name | Rule Description | Classification | Severity | Actions |
---|---|---|---|---|
DharmaEncryptedFile | File encrypted by Dharma Ransomware | Ransomware |
Malicious
|
...
|
C:\MSOCache\All Users\{91140000-0011-0000-1000-0000000FF1CE}-C\ProPlusrWW.xml.id-9C354B42.[bigmacbig@cock.li].beets | Dropped File | Stream |
Malicious
|
...
|
»
YARA Matches (1)
»
Rule Name | Rule Description | Classification | Severity | Actions |
---|---|---|---|---|
DharmaEncryptedFile | File encrypted by Dharma Ransomware | Ransomware |
Malicious
|
...
|
C:\MSOCache\All Users\{90140000-0117-0409-1000-0000000FF1CE}-C\Setup.xml.id-9C354B42.[bigmacbig@cock.li].beets | Dropped File | Stream |
Malicious
|
...
|
»
YARA Matches (1)
»
Rule Name | Rule Description | Classification | Severity | Actions |
---|---|---|---|---|
DharmaEncryptedFile | File encrypted by Dharma Ransomware | Ransomware |
Malicious
|
...
|
C:\Program Files\Common Files\Microsoft Shared\GRPHFLT\MS.JPG.id-9C354B42.[bigmacbig@cock.li].beets | Dropped File | Stream |
Malicious
|
...
|
»
YARA Matches (1)
»
Rule Name | Rule Description | Classification | Severity | Actions |
---|---|---|---|---|
DharmaEncryptedFile | File encrypted by Dharma Ransomware | Ransomware |
Malicious
|
...
|
C:\Program Files\Common Files\Microsoft Shared\OFFICE14\Office Setup Controller\Access.en-us\AccessMUI.XML.id-9C354B42.[bigmacbig@cock.li].beets | Dropped File | Stream |
Malicious
|
...
|
»
YARA Matches (1)
»
Rule Name | Rule Description | Classification | Severity | Actions |
---|---|---|---|---|
DharmaEncryptedFile | File encrypted by Dharma Ransomware | Ransomware |
Malicious
|
...
|
C:\Program Files\Common Files\Microsoft Shared\OFFICE14\1033\README.HTM.id-9C354B42.[bigmacbig@cock.li].beets | Dropped File | Stream |
Malicious
|
...
|
»
YARA Matches (1)
»
Rule Name | Rule Description | Classification | Severity | Actions |
---|---|---|---|---|
DharmaEncryptedFile | File encrypted by Dharma Ransomware | Ransomware |
Malicious
|
...
|
C:\Program Files\Common Files\Microsoft Shared\OFFICE14\Office Setup Controller\Access.en-us\AccessMUISet.XML.id-9C354B42.[bigmacbig@cock.li].beets | Dropped File | Stream |
Malicious
|
...
|
»
YARA Matches (1)
»
Rule Name | Rule Description | Classification | Severity | Actions |
---|---|---|---|---|
DharmaEncryptedFile | File encrypted by Dharma Ransomware | Ransomware |
Malicious
|
...
|
C:\Program Files\Common Files\Microsoft Shared\OFFICE14\Office Setup Controller\Excel.en-us\ExcelMUI.XML.id-9C354B42.[bigmacbig@cock.li].beets | Dropped File | Stream |
Malicious
|
...
|
»
YARA Matches (1)
»
Rule Name | Rule Description | Classification | Severity | Actions |
---|---|---|---|---|
DharmaEncryptedFile | File encrypted by Dharma Ransomware | Ransomware |
Malicious
|
...
|
C:\Program Files\Common Files\Microsoft Shared\OFFICE14\Office Setup Controller\Excel.en-us\SETUP.XML.id-9C354B42.[bigmacbig@cock.li].beets | Dropped File | Stream |
Malicious
|
...
|
»
YARA Matches (1)
»
Rule Name | Rule Description | Classification | Severity | Actions |
---|---|---|---|---|
DharmaEncryptedFile | File encrypted by Dharma Ransomware | Ransomware |
Malicious
|
...
|
C:\Program Files\Common Files\Microsoft Shared\OFFICE14\Office Setup Controller\Access.en-us\SETUP.XML.id-9C354B42.[bigmacbig@cock.li].beets | Dropped File | Stream |
Malicious
|
...
|
»
YARA Matches (1)
»
Rule Name | Rule Description | Classification | Severity | Actions |
---|---|---|---|---|
DharmaEncryptedFile | File encrypted by Dharma Ransomware | Ransomware |
Malicious
|
...
|
C:\Program Files\Common Files\Microsoft Shared\OFFICE14\Office Setup Controller\InfoPath.en-us\InfoPathMUI.XML.id-9C354B42.[bigmacbig@cock.li].beets | Dropped File | Stream |
Malicious
|
...
|
»
YARA Matches (1)
»
Rule Name | Rule Description | Classification | Severity | Actions |
---|---|---|---|---|
DharmaEncryptedFile | File encrypted by Dharma Ransomware | Ransomware |
Malicious
|
...
|
C:\Program Files\Common Files\Microsoft Shared\OFFICE14\Office Setup Controller\InfoPath.en-us\SETUP.XML.id-9C354B42.[bigmacbig@cock.li].beets | Dropped File | Stream |
Malicious
|
...
|
»
YARA Matches (1)
»
Rule Name | Rule Description | Classification | Severity | Actions |
---|---|---|---|---|
DharmaEncryptedFile | File encrypted by Dharma Ransomware | Ransomware |
Malicious
|
...
|
C:\Program Files\Common Files\Microsoft Shared\OFFICE14\Office Setup Controller\Office.en-us\BRANDING.XML.id-9C354B42.[bigmacbig@cock.li].beets | Dropped File | Stream |
Malicious
|
...
|
»
YARA Matches (1)
»
Rule Name | Rule Description | Classification | Severity | Actions |
---|---|---|---|---|
DharmaEncryptedFile | File encrypted by Dharma Ransomware | Ransomware |
Malicious
|
...
|
C:\Program Files\Common Files\Microsoft Shared\OFFICE14\Office Setup Controller\Office.en-us\OfficeMUI.XML.id-9C354B42.[bigmacbig@cock.li].beets | Dropped File | Stream |
Malicious
|
...
|
»
YARA Matches (1)
»
Rule Name | Rule Description | Classification | Severity | Actions |
---|---|---|---|---|
DharmaEncryptedFile | File encrypted by Dharma Ransomware | Ransomware |
Malicious
|
...
|
C:\Program Files\Common Files\Microsoft Shared\OFFICE14\Office Setup Controller\Office.en-us\OfficeMUISet.XML.id-9C354B42.[bigmacbig@cock.li].beets | Dropped File | Stream |
Malicious
|
...
|
»
YARA Matches (1)
»
Rule Name | Rule Description | Classification | Severity | Actions |
---|---|---|---|---|
DharmaEncryptedFile | File encrypted by Dharma Ransomware | Ransomware |
Malicious
|
...
|
C:\Program Files\Common Files\Microsoft Shared\OFFICE14\Office Setup Controller\Office.en-us\PSCONFIG.CHM.id-9C354B42.[bigmacbig@cock.li].beets | Dropped File | Stream |
Malicious
|
...
|
»
YARA Matches (1)
»
Rule Name | Rule Description | Classification | Severity | Actions |
---|---|---|---|---|
DharmaEncryptedFile | File encrypted by Dharma Ransomware | Ransomware |
Malicious
|
...
|
C:\Program Files\Common Files\Microsoft Shared\OFFICE14\Office Setup Controller\Office.en-us\PSS10O.CHM.id-9C354B42.[bigmacbig@cock.li].beets | Dropped File | Stream |
Malicious
|
...
|
»
YARA Matches (1)
»
Rule Name | Rule Description | Classification | Severity | Actions |
---|---|---|---|---|
DharmaEncryptedFile | File encrypted by Dharma Ransomware | Ransomware |
Malicious
|
...
|
C:\Program Files\Common Files\Microsoft Shared\OFFICE14\Office Setup Controller\Office.en-us\OCT.CHM.id-9C354B42.[bigmacbig@cock.li].beets | Dropped File | Stream |
Malicious
|
...
|
»
YARA Matches (1)
»
Rule Name | Rule Description | Classification | Severity | Actions |
---|---|---|---|---|
DharmaEncryptedFile | File encrypted by Dharma Ransomware | Ransomware |
Malicious
|
...
|
C:\Program Files\Common Files\Microsoft Shared\OFFICE14\Office Setup Controller\Office.en-us\PSS10R.CHM.id-9C354B42.[bigmacbig@cock.li].beets | Dropped File | Stream |
Malicious
|
...
|
»
YARA Matches (1)
»
Rule Name | Rule Description | Classification | Severity | Actions |
---|---|---|---|---|
DharmaEncryptedFile | File encrypted by Dharma Ransomware | Ransomware |
Malicious
|
...
|
C:\Program Files\Common Files\Microsoft Shared\OFFICE14\Office Setup Controller\Office.en-us\SETUP.XML.id-9C354B42.[bigmacbig@cock.li].beets | Dropped File | Stream |
Malicious
|
...
|
»
YARA Matches (1)
»
Rule Name | Rule Description | Classification | Severity | Actions |
---|---|---|---|---|
DharmaEncryptedFile | File encrypted by Dharma Ransomware | Ransomware |
Malicious
|
...
|
C:\Program Files\Common Files\Microsoft Shared\OFFICE14\Office Setup Controller\Office32.en-us\Office32MUI.XML.id-9C354B42.[bigmacbig@cock.li].beets | Dropped File | Stream |
Malicious
|
...
|
»
YARA Matches (1)
»
Rule Name | Rule Description | Classification | Severity | Actions |
---|---|---|---|---|
DharmaEncryptedFile | File encrypted by Dharma Ransomware | Ransomware |
Malicious
|
...
|
C:\Program Files\Common Files\Microsoft Shared\OFFICE14\Office Setup Controller\Groove.en-us\GrooveMUI.XML.id-9C354B42.[bigmacbig@cock.li].beets | Dropped File | Stream |
Malicious
|
...
|
»
YARA Matches (1)
»
Rule Name | Rule Description | Classification | Severity | Actions |
---|---|---|---|---|
DharmaEncryptedFile | File encrypted by Dharma Ransomware | Ransomware |
Malicious
|
...
|
C:\Program Files\Common Files\Microsoft Shared\OFFICE14\Office Setup Controller\Groove.en-us\SETUP.XML.id-9C354B42.[bigmacbig@cock.li].beets | Dropped File | Stream |
Malicious
|
...
|
»
YARA Matches (1)
»
Rule Name | Rule Description | Classification | Severity | Actions |
---|---|---|---|---|
DharmaEncryptedFile | File encrypted by Dharma Ransomware | Ransomware |
Malicious
|
...
|
C:\Program Files\Common Files\Microsoft Shared\OFFICE14\Office Setup Controller\Office32.WW\Office32WW.XML.id-9C354B42.[bigmacbig@cock.li].beets | Dropped File | Stream |
Malicious
|
...
|
»
YARA Matches (1)
»
Rule Name | Rule Description | Classification | Severity | Actions |
---|---|---|---|---|
DharmaEncryptedFile | File encrypted by Dharma Ransomware | Ransomware |
Malicious
|
...
|
C:\Program Files\Common Files\Microsoft Shared\OFFICE14\Office Setup Controller\OneNote.en-us\OneNoteMUI.XML.id-9C354B42.[bigmacbig@cock.li].beets | Dropped File | Stream |
Malicious
|
...
|
»
YARA Matches (1)
»
Rule Name | Rule Description | Classification | Severity | Actions |
---|---|---|---|---|
DharmaEncryptedFile | File encrypted by Dharma Ransomware | Ransomware |
Malicious
|
...
|
C:\Program Files\Common Files\Microsoft Shared\OFFICE14\Office Setup Controller\Outlook.en-us\OutlookMUI.XML.id-9C354B42.[bigmacbig@cock.li].beets | Dropped File | Stream |
Malicious
|
...
|
»
YARA Matches (1)
»
Rule Name | Rule Description | Classification | Severity | Actions |
---|---|---|---|---|
DharmaEncryptedFile | File encrypted by Dharma Ransomware | Ransomware |
Malicious
|
...
|
C:\Program Files\Common Files\Microsoft Shared\OFFICE14\Office Setup Controller\Outlook.en-us\SETUP.XML.id-9C354B42.[bigmacbig@cock.li].beets | Dropped File | Stream |
Malicious
|
...
|
»
YARA Matches (1)
»
Rule Name | Rule Description | Classification | Severity | Actions |
---|---|---|---|---|
DharmaEncryptedFile | File encrypted by Dharma Ransomware | Ransomware |
Malicious
|
...
|
C:\Program Files\Common Files\Microsoft Shared\OFFICE14\Office Setup Controller\Office32.en-us\SETUP.XML.id-9C354B42.[bigmacbig@cock.li].beets | Dropped File | Stream |
Malicious
|
...
|
»
YARA Matches (1)
»
Rule Name | Rule Description | Classification | Severity | Actions |
---|---|---|---|---|
DharmaEncryptedFile | File encrypted by Dharma Ransomware | Ransomware |
Malicious
|
...
|
C:\Program Files\Common Files\Microsoft Shared\OFFICE14\Office Setup Controller\Office.en-us\SETUP.CHM.id-9C354B42.[bigmacbig@cock.li].beets | Dropped File | Stream |
Malicious
|
...
|
»
YARA Matches (1)
»
Rule Name | Rule Description | Classification | Severity | Actions |
---|---|---|---|---|
DharmaEncryptedFile | File encrypted by Dharma Ransomware | Ransomware |
Malicious
|
...
|
C:\Program Files\Common Files\Microsoft Shared\OFFICE14\Office Setup Controller\OneNote.en-us\SETUP.XML.id-9C354B42.[bigmacbig@cock.li].beets | Dropped File | Stream |
Malicious
|
...
|
»
YARA Matches (1)
»
Rule Name | Rule Description | Classification | Severity | Actions |
---|---|---|---|---|
DharmaEncryptedFile | File encrypted by Dharma Ransomware | Ransomware |
Malicious
|
...
|
C:\Program Files\Common Files\Microsoft Shared\OFFICE14\Office Setup Controller\PRJPROR\PrjProrWW.XML.id-9C354B42.[bigmacbig@cock.li].beets | Dropped File | Stream |
Malicious
|
...
|
»
YARA Matches (1)
»
Rule Name | Rule Description | Classification | Severity | Actions |
---|---|---|---|---|
DharmaEncryptedFile | File encrypted by Dharma Ransomware | Ransomware |
Malicious
|
...
|
C:\Program Files\Common Files\Microsoft Shared\OFFICE14\Office Setup Controller\Project.en-us\ProjectMUI.XML.id-9C354B42.[bigmacbig@cock.li].beets | Dropped File | Stream |
Malicious
|
...
|
»
YARA Matches (1)
»
Rule Name | Rule Description | Classification | Severity | Actions |
---|---|---|---|---|
DharmaEncryptedFile | File encrypted by Dharma Ransomware | Ransomware |
Malicious
|
...
|
C:\Program Files\Common Files\Microsoft Shared\OFFICE14\Office Setup Controller\PRJPROR\SETUP.XML.id-9C354B42.[bigmacbig@cock.li].beets | Dropped File | Stream |
Malicious
|
...
|
»
YARA Matches (1)
»
Rule Name | Rule Description | Classification | Severity | Actions |
---|---|---|---|---|
DharmaEncryptedFile | File encrypted by Dharma Ransomware | Ransomware |
Malicious
|
...
|
C:\Program Files\Common Files\Microsoft Shared\OFFICE14\Office Setup Controller\Proof.en\Proof.XML.id-9C354B42.[bigmacbig@cock.li].beets | Dropped File | Stream |
Malicious
|
...
|
»
YARA Matches (1)
»
Rule Name | Rule Description | Classification | Severity | Actions |
---|---|---|---|---|
DharmaEncryptedFile | File encrypted by Dharma Ransomware | Ransomware |
Malicious
|
...
|
C:\Program Files\Common Files\Microsoft Shared\OFFICE14\Office Setup Controller\Proof.es\Proof.XML.id-9C354B42.[bigmacbig@cock.li].beets | Dropped File | Stream |
Malicious
|
...
|
»
YARA Matches (1)
»
Rule Name | Rule Description | Classification | Severity | Actions |
---|---|---|---|---|
DharmaEncryptedFile | File encrypted by Dharma Ransomware | Ransomware |
Malicious
|
...
|
C:\Program Files\Common Files\Microsoft Shared\OFFICE14\Office Setup Controller\Proof.fr\Proof.XML.id-9C354B42.[bigmacbig@cock.li].beets | Dropped File | Stream |
Malicious
|
...
|
»
YARA Matches (1)
»
Rule Name | Rule Description | Classification | Severity | Actions |
---|---|---|---|---|
DharmaEncryptedFile | File encrypted by Dharma Ransomware | Ransomware |
Malicious
|
...
|
C:\Program Files\Common Files\Microsoft Shared\OFFICE14\Office Setup Controller\Proofing.en-us\Proofing.XML.id-9C354B42.[bigmacbig@cock.li].beets | Dropped File | Stream |
Malicious
|
...
|
»
YARA Matches (1)
»
Rule Name | Rule Description | Classification | Severity | Actions |
---|---|---|---|---|
DharmaEncryptedFile | File encrypted by Dharma Ransomware | Ransomware |
Malicious
|
...
|
C:\Program Files\Common Files\Microsoft Shared\OFFICE14\Office Setup Controller\Project.en-us\SETUP.XML.id-9C354B42.[bigmacbig@cock.li].beets | Dropped File | Stream |
Malicious
|
...
|
»
YARA Matches (1)
»
Rule Name | Rule Description | Classification | Severity | Actions |
---|---|---|---|---|
DharmaEncryptedFile | File encrypted by Dharma Ransomware | Ransomware |
Malicious
|
...
|
C:\Program Files\Common Files\Microsoft Shared\OFFICE14\Office Setup Controller\Proofing.en-us\SETUP.XML.id-9C354B42.[bigmacbig@cock.li].beets | Dropped File | Stream |
Malicious
|
...
|
»
YARA Matches (1)
»
Rule Name | Rule Description | Classification | Severity | Actions |
---|---|---|---|---|
DharmaEncryptedFile | File encrypted by Dharma Ransomware | Ransomware |
Malicious
|
...
|
C:\Program Files\Common Files\Microsoft Shared\OFFICE14\Office Setup Controller\PROPLUSR\SETUP.XML.id-9C354B42.[bigmacbig@cock.li].beets | Dropped File | Stream |
Malicious
|
...
|
»
YARA Matches (1)
»
Rule Name | Rule Description | Classification | Severity | Actions |
---|---|---|---|---|
DharmaEncryptedFile | File encrypted by Dharma Ransomware | Ransomware |
Malicious
|
...
|
C:\Program Files\Common Files\Microsoft Shared\OFFICE14\Office Setup Controller\Publisher.en-us\PublisherMUI.XML.id-9C354B42.[bigmacbig@cock.li].beets | Dropped File | Stream |
Malicious
|
...
|
»
YARA Matches (1)
»
Rule Name | Rule Description | Classification | Severity | Actions |
---|---|---|---|---|
DharmaEncryptedFile | File encrypted by Dharma Ransomware | Ransomware |
Malicious
|
...
|
C:\Program Files\Common Files\Microsoft Shared\OFFICE14\Office Setup Controller\Publisher.en-us\SETUP.XML.id-9C354B42.[bigmacbig@cock.li].beets | Dropped File | Stream |
Malicious
|
...
|
»
YARA Matches (1)
»
Rule Name | Rule Description | Classification | Severity | Actions |
---|---|---|---|---|
DharmaEncryptedFile | File encrypted by Dharma Ransomware | Ransomware |
Malicious
|
...
|
C:\Program Files\Common Files\Microsoft Shared\OFFICE14\Office Setup Controller\PROPLUSR\ProPlusrWW.XML.id-9C354B42.[bigmacbig@cock.li].beets | Dropped File | Stream |
Malicious
|
...
|
»
YARA Matches (1)
»
Rule Name | Rule Description | Classification | Severity | Actions |
---|---|---|---|---|
DharmaEncryptedFile | File encrypted by Dharma Ransomware | Ransomware |
Malicious
|
...
|
C:\MSOCache\All Users\{90140000-002C-0409-1000-0000000FF1CE}-C\Proof.en\Proof.msi.id-9C354B42.[bigmacbig@cock.li].beets | Dropped File | Stream |
Malicious
|
...
|
»
YARA Matches (1)
»
Rule Name | Rule Description | Classification | Severity | Actions |
---|---|---|---|---|
DharmaEncryptedFile | File encrypted by Dharma Ransomware | Ransomware |
Malicious
|
...
|
C:\Program Files\Common Files\Microsoft Shared\OFFICE14\Office Setup Controller\PowerPoint.en-us\PowerPointMUI.XML.id-9C354B42.[bigmacbig@cock.li].beets | Dropped File | Stream |
Malicious
|
...
|
»
YARA Matches (1)
»
Rule Name | Rule Description | Classification | Severity | Actions |
---|---|---|---|---|
DharmaEncryptedFile | File encrypted by Dharma Ransomware | Ransomware |
Malicious
|
...
|
C:\Program Files\Common Files\Microsoft Shared\OFFICE14\Office Setup Controller\PowerPoint.en-us\SETUP.XML.id-9C354B42.[bigmacbig@cock.li].beets | Dropped File | Audio |
Malicious
|
...
|
»
YARA Matches (1)
»
Rule Name | Rule Description | Classification | Severity | Actions |
---|---|---|---|---|
DharmaEncryptedFile | File encrypted by Dharma Ransomware | Ransomware |
Malicious
|
...
|
C:\Program Files\Common Files\Microsoft Shared\OFFICE14\Office Setup Controller\VISIOR\VisiorWW.XML.id-9C354B42.[bigmacbig@cock.li].beets | Dropped File | Stream |
Malicious
|
...
|
»
YARA Matches (1)
»
Rule Name | Rule Description | Classification | Severity | Actions |
---|---|---|---|---|
DharmaEncryptedFile | File encrypted by Dharma Ransomware | Ransomware |
Malicious
|
...
|
C:\Program Files\Common Files\Microsoft Shared\OFFICE14\Office Setup Controller\Word.en-us\SETUP.XML.id-9C354B42.[bigmacbig@cock.li].beets | Dropped File | Stream |
Malicious
|
...
|
»
YARA Matches (1)
»
Rule Name | Rule Description | Classification | Severity | Actions |
---|---|---|---|---|
DharmaEncryptedFile | File encrypted by Dharma Ransomware | Ransomware |
Malicious
|
...
|
C:\Program Files\Common Files\Microsoft Shared\OFFICE14\Office Setup Controller\VISIOR\SETUP.XML.id-9C354B42.[bigmacbig@cock.li].beets | Dropped File | Stream |
Malicious
|
...
|
»
YARA Matches (1)
»
Rule Name | Rule Description | Classification | Severity | Actions |
---|---|---|---|---|
DharmaEncryptedFile | File encrypted by Dharma Ransomware | Ransomware |
Malicious
|
...
|
C:\Program Files\Common Files\Microsoft Shared\OFFICE14\Office Setup Controller\Word.en-us\WordMUI.XML.id-9C354B42.[bigmacbig@cock.li].beets | Dropped File | Stream |
Malicious
|
...
|
»
YARA Matches (1)
»
Rule Name | Rule Description | Classification | Severity | Actions |
---|---|---|---|---|
DharmaEncryptedFile | File encrypted by Dharma Ransomware | Ransomware |
Malicious
|
...
|
C:\Program Files\Common Files\Microsoft Shared\Smart Tag\1033\MCABOUT.HTM.id-9C354B42.[bigmacbig@cock.li].beets | Dropped File | Stream |
Malicious
|
...
|
»
YARA Matches (1)
»
Rule Name | Rule Description | Classification | Severity | Actions |
---|---|---|---|---|
DharmaEncryptedFile | File encrypted by Dharma Ransomware | Ransomware |
Malicious
|
...
|
C:\MSOCache\All Users\{90140000-002C-0409-1000-0000000FF1CE}-C\Proof.es\Proof.msi.id-9C354B42.[bigmacbig@cock.li].beets | Dropped File | Stream |
Malicious
|
...
|
»
YARA Matches (1)
»
Rule Name | Rule Description | Classification | Severity | Actions |
---|---|---|---|---|
DharmaEncryptedFile | File encrypted by Dharma Ransomware | Ransomware |
Malicious
|
...
|
C:\Program Files\Common Files\Microsoft Shared\OFFICE14\Office Setup Controller\Visio.en-us\VisioMUI.XML.id-9C354B42.[bigmacbig@cock.li].beets | Dropped File | Stream |
Malicious
|
...
|
»
YARA Matches (1)
»
Rule Name | Rule Description | Classification | Severity | Actions |
---|---|---|---|---|
DharmaEncryptedFile | File encrypted by Dharma Ransomware | Ransomware |
Malicious
|
...
|
C:\Program Files\Common Files\Microsoft Shared\OFFICE14\Office Setup Controller\Visio.en-us\SETUP.XML.id-9C354B42.[bigmacbig@cock.li].beets | Dropped File | Stream |
Malicious
|
...
|
»
YARA Matches (1)
»
Rule Name | Rule Description | Classification | Severity | Actions |
---|---|---|---|---|
DharmaEncryptedFile | File encrypted by Dharma Ransomware | Ransomware |
Malicious
|
...
|
C:\MSOCache\All Users\{90140000-002C-0409-1000-0000000FF1CE}-C\Proof.fr\Proof.msi.id-9C354B42.[bigmacbig@cock.li].beets | Dropped File | Stream |
Malicious
|
...
|
»
YARA Matches (1)
»
Rule Name | Rule Description | Classification | Severity | Actions |
---|---|---|---|---|
DharmaEncryptedFile | File encrypted by Dharma Ransomware | Ransomware |
Malicious
|
...
|
C:\Program Files\Common Files\Microsoft Shared\Smart Tag\LISTS\1033\DATES.XML.id-9C354B42.[bigmacbig@cock.li].beets | Dropped File | Stream |
Malicious
|
...
|
»
YARA Matches (1)
»
Rule Name | Rule Description | Classification | Severity | Actions |
---|---|---|---|---|
DharmaEncryptedFile | File encrypted by Dharma Ransomware | Ransomware |
Malicious
|
...
|
C:\Program Files\Common Files\Microsoft Shared\Smart Tag\LISTS\1033\TIME.XML.id-9C354B42.[bigmacbig@cock.li].beets | Dropped File | Stream |
Malicious
|
...
|
»
YARA Matches (1)
»
Rule Name | Rule Description | Classification | Severity | Actions |
---|---|---|---|---|
DharmaEncryptedFile | File encrypted by Dharma Ransomware | Ransomware |
Malicious
|
...
|
C:\Program Files\Common Files\Microsoft Shared\Smart Tag\LISTS\BASMLA.XSL.id-9C354B42.[bigmacbig@cock.li].beets | Dropped File | Stream |
Malicious
|
...
|
»
YARA Matches (1)
»
Rule Name | Rule Description | Classification | Severity | Actions |
---|---|---|---|---|
DharmaEncryptedFile | File encrypted by Dharma Ransomware | Ransomware |
Malicious
|
...
|
C:\MSOCache\All Users\{90140000-002C-0409-1000-0000000FF1CE}-C\Proofing.msi.id-9C354B42.[bigmacbig@cock.li].beets | Dropped File | Stream |
Malicious
|
...
|
»
YARA Matches (1)
»
Rule Name | Rule Description | Classification | Severity | Actions |
---|---|---|---|---|
DharmaEncryptedFile | File encrypted by Dharma Ransomware | Ransomware |
Malicious
|
...
|
C:\Program Files\Common Files\Microsoft Shared\Smart Tag\LISTS\1033\STOCKS.DAT.id-9C354B42.[bigmacbig@cock.li].beets | Dropped File | Stream |
Malicious
|
...
|
»
YARA Matches (1)
»
Rule Name | Rule Description | Classification | Severity | Actions |
---|---|---|---|---|
DharmaEncryptedFile | File encrypted by Dharma Ransomware | Ransomware |
Malicious
|
...
|
C:\Program Files\Common Files\Microsoft Shared\Stationery\Desktop.ini.id-9C354B42.[bigmacbig@cock.li].beets | Dropped File | Stream |
Malicious
|
...
|
»
YARA Matches (1)
»
Rule Name | Rule Description | Classification | Severity | Actions |
---|---|---|---|---|
DharmaEncryptedFile | File encrypted by Dharma Ransomware | Ransomware |
Malicious
|
...
|
C:\MSOCache\All Users\{90140000-0043-0409-1000-0000000FF1CE}-C\Office32MUI.msi.id-9C354B42.[bigmacbig@cock.li].beets | Dropped File | Stream |
Malicious
|
...
|
»
YARA Matches (1)
»
Rule Name | Rule Description | Classification | Severity | Actions |
---|---|---|---|---|
DharmaEncryptedFile | File encrypted by Dharma Ransomware | Ransomware |
Malicious
|
...
|
C:\Program Files\Common Files\Microsoft Shared\Smart Tag\METCONV.TXT.id-9C354B42.[bigmacbig@cock.li].beets | Dropped File | Stream |
Malicious
|
...
|
»
YARA Matches (1)
»
Rule Name | Rule Description | Classification | Severity | Actions |
---|---|---|---|---|
DharmaEncryptedFile | File encrypted by Dharma Ransomware | Ransomware |
Malicious
|
...
|
C:\Program Files\Common Files\Microsoft Shared\Smart Tag\LISTS\1033\PHONE.XML.id-9C354B42.[bigmacbig@cock.li].beets | Dropped File | Stream |
Malicious
|
...
|
»
YARA Matches (1)
»
Rule Name | Rule Description | Classification | Severity | Actions |
---|---|---|---|---|
DharmaEncryptedFile | File encrypted by Dharma Ransomware | Ransomware |
Malicious
|
...
|
C:\Program Files\Common Files\Microsoft Shared\Smart Tag\LISTS\1033\STOCKS.XML.id-9C354B42.[bigmacbig@cock.li].beets | Dropped File | Stream |
Malicious
|
...
|
»
YARA Matches (1)
»
Rule Name | Rule Description | Classification | Severity | Actions |
---|---|---|---|---|
DharmaEncryptedFile | File encrypted by Dharma Ransomware | Ransomware |
Malicious
|
...
|
C:\Program Files\Common Files\Microsoft Shared\THEMES14\AFTRNOON\PREVIEW.GIF.id-9C354B42.[bigmacbig@cock.li].beets | Dropped File | Stream |
Malicious
|
...
|
»
YARA Matches (1)
»
Rule Name | Rule Description | Classification | Severity | Actions |
---|---|---|---|---|
DharmaEncryptedFile | File encrypted by Dharma Ransomware | Ransomware |
Malicious
|
...
|
C:\Program Files\Common Files\Microsoft Shared\THEMES14\ARCTIC\PREVIEW.GIF.id-9C354B42.[bigmacbig@cock.li].beets | Dropped File | Stream |
Malicious
|
...
|
»
YARA Matches (1)
»
Rule Name | Rule Description | Classification | Severity | Actions |
---|---|---|---|---|
DharmaEncryptedFile | File encrypted by Dharma Ransomware | Ransomware |
Malicious
|
...
|
C:\Program Files\Common Files\Microsoft Shared\THEMES14\AFTRNOON\THMBNAIL.PNG.id-9C354B42.[bigmacbig@cock.li].beets | Dropped File | Stream |
Malicious
|
...
|
»
YARA Matches (1)
»
Rule Name | Rule Description | Classification | Severity | Actions |
---|---|---|---|---|
DharmaEncryptedFile | File encrypted by Dharma Ransomware | Ransomware |
Malicious
|
...
|
C:\Program Files\Common Files\Microsoft Shared\THEMES14\ARCTIC\THMBNAIL.PNG.id-9C354B42.[bigmacbig@cock.li].beets | Dropped File | Stream |
Malicious
|
...
|
»
YARA Matches (1)
»
Rule Name | Rule Description | Classification | Severity | Actions |
---|---|---|---|---|
DharmaEncryptedFile | File encrypted by Dharma Ransomware | Ransomware |
Malicious
|
...
|
C:\Program Files\Common Files\Microsoft Shared\THEMES14\BLENDS\THMBNAIL.PNG.id-9C354B42.[bigmacbig@cock.li].beets | Dropped File | Stream |
Malicious
|
...
|
»
YARA Matches (1)
»
Rule Name | Rule Description | Classification | Severity | Actions |
---|---|---|---|---|
DharmaEncryptedFile | File encrypted by Dharma Ransomware | Ransomware |
Malicious
|
...
|
C:\Program Files\Common Files\Microsoft Shared\THEMES14\BLUECALM\PREVIEW.GIF.id-9C354B42.[bigmacbig@cock.li].beets | Dropped File | Stream |
Malicious
|
...
|
»
YARA Matches (1)
»
Rule Name | Rule Description | Classification | Severity | Actions |
---|---|---|---|---|
DharmaEncryptedFile | File encrypted by Dharma Ransomware | Ransomware |
Malicious
|
...
|
C:\Users\5p5NrGJn0jS HALPmcxz\Desktop\demo.exe | Sample File | Binary |
Unknown
|
...
|
»
PE Information
»
Image Base | 0x400000 |
Entry Point | 0x403512 |
Size Of Code | 0x22c00 |
Size Of Initialized Data | 0x4e89000 |
File Type | FileType.executable |
Subsystem | Subsystem.windows_gui |
Machine Type | MachineType.i386 |
Compile Timestamp | 2018-08-29 09:20:13+00:00 |
Sections (5)
»
Name | Virtual Address | Virtual Size | Raw Data Size | Raw Data Offset | Flags | Entropy |
---|---|---|---|---|---|---|
.text | 0x401000 | 0x22b4d | 0x22c00 | 0x400 | IMAGE_SCN_CNT_CODE, IMAGE_SCN_MEM_EXECUTE, IMAGE_SCN_MEM_READ | 6.67 |
.rdata | 0x424000 | 0x268be | 0x26a00 | 0x23000 | IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_READ | 6.43 |
.data | 0x44b000 | 0x4e5ea00 | 0x1c00 | 0x49a00 | IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_READ, IMAGE_SCN_MEM_WRITE | 3.21 |
.rsrc | 0x52aa000 | 0x2608 | 0x2800 | 0x4b600 | IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_READ | 4.72 |
.reloc | 0x52ad000 | 0x2010 | 0x2200 | 0x4de00 | IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_DISCARDABLE, IMAGE_SCN_MEM_READ | 6.48 |
Imports (5)
»
KERNEL32.dll (87)
»
API Name | Ordinal | IAT Address | Thunk RVA | Thunk Offset | Hint |
---|---|---|---|---|---|
GetLastError | 0x0 | 0x42401c | 0x49f9c | 0x48f9c | 0x202 |
PeekConsoleInputW | 0x0 | 0x424020 | 0x49fa0 | 0x48fa0 | 0x38c |
LocalAlloc | 0x0 | 0x424024 | 0x49fa4 | 0x48fa4 | 0x344 |
VirtualProtect | 0x0 | 0x424028 | 0x49fa8 | 0x48fa8 | 0x4ef |
CreateToolhelp32Snapshot | 0x0 | 0x42402c | 0x49fac | 0x48fac | 0xbe |
GetHandleInformation | 0x0 | 0x424030 | 0x49fb0 | 0x48fb0 | 0x1ff |
CloseHandle | 0x0 | 0x424034 | 0x49fb4 | 0x48fb4 | 0x52 |
WriteConsoleW | 0x0 | 0x424038 | 0x49fb8 | 0x48fb8 | 0x524 |
SetFilePointerEx | 0x0 | 0x42403c | 0x49fbc | 0x48fbc | 0x467 |
SetStdHandle | 0x0 | 0x424040 | 0x49fc0 | 0x48fc0 | 0x487 |
GetConsoleMode | 0x0 | 0x424044 | 0x49fc4 | 0x48fc4 | 0x1ac |
WriteFileGather | 0x0 | 0x424048 | 0x49fc8 | 0x48fc8 | 0x527 |
GetNumberFormatA | 0x0 | 0x42404c | 0x49fcc | 0x48fcc | 0x231 |
EnumCalendarInfoExW | 0x0 | 0x424050 | 0x49fd0 | 0x48fd0 | 0xf2 |
GetTickCount | 0x0 | 0x424054 | 0x49fd4 | 0x48fd4 | 0x293 |
DebugActiveProcessStop | 0x0 | 0x424058 | 0x49fd8 | 0x48fd8 | 0xc6 |
DuplicateHandle | 0x0 | 0x42405c | 0x49fdc | 0x48fdc | 0xe8 |
lstrlenA | 0x0 | 0x424060 | 0x49fe0 | 0x48fe0 | 0x54d |
GetConsoleCP | 0x0 | 0x424064 | 0x49fe4 | 0x48fe4 | 0x19a |
FlushFileBuffers | 0x0 | 0x424068 | 0x49fe8 | 0x48fe8 | 0x157 |
GetStringTypeW | 0x0 | 0x42406c | 0x49fec | 0x48fec | 0x269 |
OutputDebugStringW | 0x0 | 0x424070 | 0x49ff0 | 0x48ff0 | 0x38a |
EnumSystemLocalesW | 0x0 | 0x424074 | 0x49ff4 | 0x48ff4 | 0x10f |
GetUserDefaultLCID | 0x0 | 0x424078 | 0x49ff8 | 0x48ff8 | 0x29b |
EncodePointer | 0x0 | 0x42407c | 0x49ffc | 0x48ffc | 0xea |
DecodePointer | 0x0 | 0x424080 | 0x4a000 | 0x49000 | 0xca |
GetCommandLineA | 0x0 | 0x424084 | 0x4a004 | 0x49004 | 0x186 |
RaiseException | 0x0 | 0x424088 | 0x4a008 | 0x49008 | 0x3b1 |
RtlUnwind | 0x0 | 0x42408c | 0x4a00c | 0x4900c | 0x418 |
IsDebuggerPresent | 0x0 | 0x424090 | 0x4a010 | 0x49010 | 0x300 |
IsProcessorFeaturePresent | 0x0 | 0x424094 | 0x4a014 | 0x49014 | 0x304 |
ExitProcess | 0x0 | 0x424098 | 0x4a018 | 0x49018 | 0x119 |
GetModuleHandleExW | 0x0 | 0x42409c | 0x4a01c | 0x4901c | 0x217 |
GetProcAddress | 0x0 | 0x4240a0 | 0x4a020 | 0x49020 | 0x245 |
AreFileApisANSI | 0x0 | 0x4240a4 | 0x4a024 | 0x49024 | 0x15 |
MultiByteToWideChar | 0x0 | 0x4240a8 | 0x4a028 | 0x49028 | 0x367 |
WideCharToMultiByte | 0x0 | 0x4240ac | 0x4a02c | 0x4902c | 0x511 |
HeapSize | 0x0 | 0x4240b0 | 0x4a030 | 0x49030 | 0x2d4 |
HeapFree | 0x0 | 0x4240b4 | 0x4a034 | 0x49034 | 0x2cf |
HeapAlloc | 0x0 | 0x4240b8 | 0x4a038 | 0x49038 | 0x2cb |
SetLastError | 0x0 | 0x4240bc | 0x4a03c | 0x4903c | 0x473 |
GetCurrentThread | 0x0 | 0x4240c0 | 0x4a040 | 0x49040 | 0x1c4 |
GetCurrentThreadId | 0x0 | 0x4240c4 | 0x4a044 | 0x49044 | 0x1c5 |
GetProcessHeap | 0x0 | 0x4240c8 | 0x4a048 | 0x49048 | 0x24a |
GetStdHandle | 0x0 | 0x4240cc | 0x4a04c | 0x4904c | 0x264 |
GetFileType | 0x0 | 0x4240d0 | 0x4a050 | 0x49050 | 0x1f3 |
DeleteCriticalSection | 0x0 | 0x4240d4 | 0x4a054 | 0x49054 | 0xd1 |
GetStartupInfoW | 0x0 | 0x4240d8 | 0x4a058 | 0x49058 | 0x263 |
GetModuleFileNameA | 0x0 | 0x4240dc | 0x4a05c | 0x4905c | 0x213 |
WriteFile | 0x0 | 0x4240e0 | 0x4a060 | 0x49060 | 0x525 |
GetModuleFileNameW | 0x0 | 0x4240e4 | 0x4a064 | 0x49064 | 0x214 |
QueryPerformanceCounter | 0x0 | 0x4240e8 | 0x4a068 | 0x49068 | 0x3a7 |
GetCurrentProcessId | 0x0 | 0x4240ec | 0x4a06c | 0x4906c | 0x1c1 |
GetSystemTimeAsFileTime | 0x0 | 0x4240f0 | 0x4a070 | 0x49070 | 0x279 |
GetEnvironmentStringsW | 0x0 | 0x4240f4 | 0x4a074 | 0x49074 | 0x1da |
FreeEnvironmentStringsW | 0x0 | 0x4240f8 | 0x4a078 | 0x49078 | 0x161 |
UnhandledExceptionFilter | 0x0 | 0x4240fc | 0x4a07c | 0x4907c | 0x4d3 |
SetUnhandledExceptionFilter | 0x0 | 0x424100 | 0x4a080 | 0x49080 | 0x4a5 |
InitializeCriticalSectionAndSpinCount | 0x0 | 0x424104 | 0x4a084 | 0x49084 | 0x2e3 |
CreateEventW | 0x0 | 0x424108 | 0x4a088 | 0x49088 | 0x85 |
Sleep | 0x0 | 0x42410c | 0x4a08c | 0x4908c | 0x4b2 |
GetCurrentProcess | 0x0 | 0x424110 | 0x4a090 | 0x49090 | 0x1c0 |
TerminateProcess | 0x0 | 0x424114 | 0x4a094 | 0x49094 | 0x4c0 |
TlsAlloc | 0x0 | 0x424118 | 0x4a098 | 0x49098 | 0x4c5 |
TlsGetValue | 0x0 | 0x42411c | 0x4a09c | 0x4909c | 0x4c7 |
TlsSetValue | 0x0 | 0x424120 | 0x4a0a0 | 0x490a0 | 0x4c8 |
TlsFree | 0x0 | 0x424124 | 0x4a0a4 | 0x490a4 | 0x4c6 |
GetModuleHandleW | 0x0 | 0x424128 | 0x4a0a8 | 0x490a8 | 0x218 |
CreateSemaphoreW | 0x0 | 0x42412c | 0x4a0ac | 0x490ac | 0xae |
EnterCriticalSection | 0x0 | 0x424130 | 0x4a0b0 | 0x490b0 | 0xee |
LeaveCriticalSection | 0x0 | 0x424134 | 0x4a0b4 | 0x490b4 | 0x339 |
FatalAppExitA | 0x0 | 0x424138 | 0x4a0b8 | 0x490b8 | 0x120 |
SetConsoleCtrlHandler | 0x0 | 0x42413c | 0x4a0bc | 0x490bc | 0x42d |
FreeLibrary | 0x0 | 0x424140 | 0x4a0c0 | 0x490c0 | 0x162 |
LoadLibraryExW | 0x0 | 0x424144 | 0x4a0c4 | 0x490c4 | 0x33e |
IsValidCodePage | 0x0 | 0x424148 | 0x4a0c8 | 0x490c8 | 0x30a |
GetACP | 0x0 | 0x42414c | 0x4a0cc | 0x490cc | 0x168 |
GetOEMCP | 0x0 | 0x424150 | 0x4a0d0 | 0x490d0 | 0x237 |
GetCPInfo | 0x0 | 0x424154 | 0x4a0d4 | 0x490d4 | 0x172 |
HeapReAlloc | 0x0 | 0x424158 | 0x4a0d8 | 0x490d8 | 0x2d2 |
GetDateFormatW | 0x0 | 0x42415c | 0x4a0dc | 0x490dc | 0x1c8 |
GetTimeFormatW | 0x0 | 0x424160 | 0x4a0e0 | 0x490e0 | 0x297 |
CompareStringW | 0x0 | 0x424164 | 0x4a0e4 | 0x490e4 | 0x64 |
LCMapStringW | 0x0 | 0x424168 | 0x4a0e8 | 0x490e8 | 0x32d |
GetLocaleInfoW | 0x0 | 0x42416c | 0x4a0ec | 0x490ec | 0x206 |
IsValidLocale | 0x0 | 0x424170 | 0x4a0f0 | 0x490f0 | 0x30c |
CreateFileW | 0x0 | 0x424174 | 0x4a0f4 | 0x490f4 | 0x8f |
USER32.dll (4)
»
API Name | Ordinal | IAT Address | Thunk RVA | Thunk Offset | Hint |
---|---|---|---|---|---|
GetNextDlgGroupItem | 0x0 | 0x424184 | 0x4a104 | 0x49104 | 0x161 |
GetMonitorInfoW | 0x0 | 0x424188 | 0x4a108 | 0x49108 | 0x15f |
DlgDirListA | 0x0 | 0x42418c | 0x4a10c | 0x4910c | 0xb3 |
wsprintfW | 0x0 | 0x424190 | 0x4a110 | 0x49110 | 0x333 |
ADVAPI32.dll (6)
»
API Name | Ordinal | IAT Address | Thunk RVA | Thunk Offset | Hint |
---|---|---|---|---|---|
ObjectDeleteAuditAlarmA | 0x0 | 0x424000 | 0x49f80 | 0x48f80 | 0x1eb |
GetAce | 0x0 | 0x424004 | 0x49f84 | 0x48f84 | 0x123 |
GetFileSecurityW | 0x0 | 0x424008 | 0x49f88 | 0x48f88 | 0x130 |
CreateServiceA | 0x0 | 0x42400c | 0x49f8c | 0x48f8c | 0x80 |
GetUserNameW | 0x0 | 0x424010 | 0x49f90 | 0x48f90 | 0x165 |
GetServiceKeyNameA | 0x0 | 0x424014 | 0x49f94 | 0x48f94 | 0x153 |
WINHTTP.dll (3)
»
API Name | Ordinal | IAT Address | Thunk RVA | Thunk Offset | Hint |
---|---|---|---|---|---|
WinHttpCloseHandle | 0x0 | 0x424198 | 0x4a118 | 0x49118 | 0x7 |
WinHttpOpen | 0x0 | 0x42419c | 0x4a11c | 0x4911c | 0xf |
WinHttpQueryAuthSchemes | 0x0 | 0x4241a0 | 0x4a120 | 0x49120 | 0x11 |
MSIMG32.dll (1)
»
API Name | Ordinal | IAT Address | Thunk RVA | Thunk Offset | Hint |
---|---|---|---|---|---|
GradientFill | 0x0 | 0x42417c | 0x4a0fc | 0x490fc | 0x2 |
Memory Dumps (1)
»
Name | Process ID | Start VA | End VA | Dump Reason | PE Rebuilds | Bitness | Entry Points | AV | YARA | Actions |
---|---|---|---|---|---|---|---|---|---|---|
buffer | 1 | 0x053821E0 | 0x0539E3CB | Marked Executable | - | 32-bit | 0x0538501C, 0x05384133 |
![]() |
![]() |
...
|
C:\$Recycle.Bin\S-1-5-21-3388679973-3930757225-3770151564-1000\desktop.ini.id-9C354B42.[bigmacbig@cock.li].beets | Dropped File | Stream |
Unknown
|
...
|
»
C:\MSOCache\All Users\{90140000-0016-0409-1000-0000000FF1CE}-C\ExcelMUI.msi.id-9C354B42.[bigmacbig@cock.li].beets | Dropped File | Stream |
Unknown
|
...
|
»
C:\MSOCache\All Users\{90140000-0016-0409-1000-0000000FF1CE}-C\ExcelLR.cab.id-9C354B42.[bigmacbig@cock.li].beets | Dropped File | Stream |
Unknown
|
...
|
»
C:\MSOCache\All Users\{90140000-0018-0409-1000-0000000FF1CE}-C\PowerPointMUI.msi.id-9C354B42.[bigmacbig@cock.li].beets | Dropped File | Stream |
Unknown
|
...
|
»
C:\MSOCache\All Users\{90140000-0018-0409-1000-0000000FF1CE}-C\PptLR.cab.id-9C354B42.[bigmacbig@cock.li].beets | Dropped File | Stream |
Unknown
|
...
|
»
C:\MSOCache\All Users\{90140000-0019-0409-1000-0000000FF1CE}-C\PublisherMUI.msi.id-9C354B42.[bigmacbig@cock.li].beets | Dropped File | Stream |
Unknown
|
...
|
»
C:\MSOCache\All Users\{90140000-0019-0409-1000-0000000FF1CE}-C\PubLR.cab.id-9C354B42.[bigmacbig@cock.li].beets | Dropped File | Stream |
Unknown
|
...
|
»
C:\MSOCache\All Users\{90140000-001A-0409-1000-0000000FF1CE}-C\OutlkLR.cab.id-9C354B42.[bigmacbig@cock.li].beets | Dropped File | Stream |
Unknown
|
...
|
»
C:\Program Files\Common Files\Microsoft Shared\OFFICE14\1033\ADO210.CHM.id-9C354B42.[bigmacbig@cock.li].beets | Dropped File | Stream |
Unknown
|
...
|
»
C:\MSOCache\All Users\{90140000-001A-0409-1000-0000000FF1CE}-C\OutlookMUI.msi.id-9C354B42.[bigmacbig@cock.li].beets | Dropped File | Stream |
Unknown
|
...
|
»
C:\MSOCache\All Users\{90140000-001B-0409-1000-0000000FF1CE}-C\WordLR.cab.id-9C354B42.[bigmacbig@cock.li].beets | Dropped File | Stream |
Unknown
|
...
|
»
C:\MSOCache\All Users\{90140000-001B-0409-1000-0000000FF1CE}-C\WordMUI.msi.id-9C354B42.[bigmacbig@cock.li].beets | Dropped File | Stream |
Unknown
|
...
|
»
C:\MSOCache\All Users\{90140000-002C-0409-1000-0000000FF1CE}-C\Proof.en\Proof.cab.id-9C354B42.[bigmacbig@cock.li].beets | Dropped File | Stream |
Unknown
|
...
|
»
C:\MSOCache\All Users\{90140000-002C-0409-1000-0000000FF1CE}-C\Proof.fr\Proof.cab.id-9C354B42.[bigmacbig@cock.li].beets | Dropped File | Stream |
Unknown
|
...
|
»
C:\MSOCache\All Users\{90140000-002C-0409-1000-0000000FF1CE}-C\Proof.es\Proof.cab.id-9C354B42.[bigmacbig@cock.li].beets | Dropped File | Stream |
Unknown
|
...
|
»
C:\MSOCache\All Users\{90140000-0043-0409-1000-0000000FF1CE}-C\OWOW32LR.cab.id-9C354B42.[bigmacbig@cock.li].beets | Dropped File | Stream |
Unknown
|
...
|
»