VTI Score
85 / 100
|
|
VTI Database Version | 2.6 |
VTI Rule Match Count | 9 |
VTI Rule Type | Default (PE, ...) |
File System | Delete user files |
|
|
Delete multiple user files. This is an indicator for ransomware or wiper malware.
|
|||
Masquerade | Change folder appearance |
|
|
Folder "c:\users\5jghkoaofdp\documents" has a changed appearance.
|
|||
Folder "c:\users\5jghkoaofdp\documents\my shapes" has a changed appearance.
|
|||
Folder "c:\users\5jghkoaofdp\music" has a changed appearance.
|
|||
Persistence | Install system startup script or application |
|
|
Add "C:\Users\5JgHKoaOfdp\Desktop\#Decryptor.exe" to windows startup via registry.
|
|||
Device | Monitor mouse movements and clicks |
|
|
Frequently read the state of a mouse button by API.
|
|||
File System | Create many files |
|
|
Create above average number of files.
|
|||
PE | Drop PE file |
|
|
Drop file "c:\users\5jghkoaofdp\desktop\#decryptor.exe".
|
|||
PE | Execute dropped PE file |
|
|
Execute dropped file "c:\users\5jghkoaofdp\desktop\#decryptor.exe".
|