VTI SCORE: 100/100
Dynamic Analysis Report |
Classification: |
Ransomware
|
Threat Names: |
Djvu
STOP
Trojan.GenericKD.43348205
...
|
host1506_2020-06-15_14-07.exe
Windows Exe (x86-32)
Created at 2020-06-16T14:47:00
Remarks (2/2)
(0x0200003A): A task was rescheduled ahead of time to reveal dormant functionality.
Remarks
(0x0200000C): The maximum memory dump size was exceeded. Some dumps may be missing in the report.
(0x0200001B): The maximum number of file reputation requests per analysis (150) was exceeded.
This is a filtered view
This list contains only the embedded files, downloaded files, and dropped files
Filters: |
There are no files for this filter
There are no files in this analysis
Filename | Category | Type | Severity | Actions |
---|
C:\Users\5p5NrGJn0jS HALPmcxz\Desktop\host1506_2020-06-15_14-07.exe | Sample File | Binary |
Malicious
|
...
|
»
File Reputation Information
»
Severity |
Blacklisted
|
Names | Mal/Generic-S |
PE Information
»
Image Base | 0x400000 |
Entry Point | 0x404620 |
Size Of Code | 0x10200 |
Size Of Initialized Data | 0x26ce00 |
File Type | FileType.executable |
Subsystem | Subsystem.windows_gui |
Machine Type | MachineType.i386 |
Compile Timestamp | 2019-11-18 09:27:42+00:00 |
Sections (4)
»
Name | Virtual Address | Virtual Size | Raw Data Size | Raw Data Offset | Flags | Entropy |
---|---|---|---|---|---|---|
.text | 0x401000 | 0x1000f | 0x10200 | 0x400 | IMAGE_SCN_CNT_CODE, IMAGE_SCN_MEM_EXECUTE, IMAGE_SCN_MEM_READ | 6.69 |
.rdata | 0x412000 | 0x97c78 | 0x97e00 | 0x10600 | IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_READ | 7.97 |
.data | 0x4aa000 | 0x1c6ee0 | 0x6600 | 0xa8400 | IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_READ, IMAGE_SCN_MEM_WRITE | 0.95 |
.rsrc | 0x671000 | 0xd640 | 0xd800 | 0xaea00 | IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_READ | 5.42 |
Imports (1)
»
KERNEL32.dll (92)
»
API Name | Ordinal | IAT Address | Thunk RVA | Thunk Offset | Hint |
---|---|---|---|---|---|
GetProcAddress | 0x0 | 0x412000 | 0xa9444 | 0xa7a44 | 0x245 |
GlobalAlloc | 0x0 | 0x412004 | 0xa9448 | 0xa7a48 | 0x2b3 |
GetWriteWatch | 0x0 | 0x412008 | 0xa944c | 0xa7a4c | 0x2b0 |
SetProcessPriorityBoost | 0x0 | 0x41200c | 0xa9450 | 0xa7a50 | 0x482 |
GetLastError | 0x0 | 0x412010 | 0xa9454 | 0xa7a54 | 0x202 |
ClearCommError | 0x0 | 0x412014 | 0xa9458 | 0xa7a58 | 0x50 |
PurgeComm | 0x0 | 0x412018 | 0xa945c | 0xa7a5c | 0x39b |
GetLocalTime | 0x0 | 0x41201c | 0xa9460 | 0xa7a60 | 0x203 |
ConnectNamedPipe | 0x0 | 0x412020 | 0xa9464 | 0xa7a64 | 0x65 |
DisconnectNamedPipe | 0x0 | 0x412024 | 0xa9468 | 0xa7a68 | 0xe1 |
CreateMailslotA | 0x0 | 0x412028 | 0xa946c | 0xa7a6c | 0x98 |
GetMailslotInfo | 0x0 | 0x41202c | 0xa9470 | 0xa7a70 | 0x210 |
lstrcpyA | 0x0 | 0x412030 | 0xa9474 | 0xa7a74 | 0x547 |
lstrcatA | 0x0 | 0x412034 | 0xa9478 | 0xa7a78 | 0x53e |
WriteFileGather | 0x0 | 0x412038 | 0xa947c | 0xa7a7c | 0x527 |
GetModuleHandleA | 0x0 | 0x41203c | 0xa9480 | 0xa7a80 | 0x215 |
FatalAppExitW | 0x0 | 0x412040 | 0xa9484 | 0xa7a84 | 0x121 |
GetEnvironmentVariableW | 0x0 | 0x412044 | 0xa9488 | 0xa7a88 | 0x1dc |
EnumResourceLanguagesA | 0x0 | 0x412048 | 0xa948c | 0xa7a8c | 0xfb |
AddAtomA | 0x0 | 0x41204c | 0xa9490 | 0xa7a90 | 0x3 |
GetAtomNameW | 0x0 | 0x412050 | 0xa9494 | 0xa7a94 | 0x16e |
IsBadReadPtr | 0x0 | 0x412054 | 0xa9498 | 0xa7a98 | 0x2f7 |
CommConfigDialogW | 0x0 | 0x412058 | 0xa949c | 0xa7a9c | 0x5e |
GetDefaultCommConfigW | 0x0 | 0x41205c | 0xa94a0 | 0xa7aa0 | 0x1ca |
GetSystemPowerStatus | 0x0 | 0x412060 | 0xa94a4 | 0xa7aa4 | 0x274 |
SetVolumeMountPointW | 0x0 | 0x412064 | 0xa94a8 | 0xa7aa8 | 0x4ab |
GetVolumePathNameW | 0x0 | 0x412068 | 0xa94ac | 0xa7aac | 0x2ab |
ReadConsoleInputA | 0x0 | 0x41206c | 0xa94b0 | 0xa7ab0 | 0x3b5 |
ScrollConsoleScreenBufferA | 0x0 | 0x412070 | 0xa94b4 | 0xa7ab4 | 0x41a |
SetConsoleTextAttribute | 0x0 | 0x412074 | 0xa94b8 | 0xa7ab8 | 0x446 |
SetConsoleCP | 0x0 | 0x412078 | 0xa94bc | 0xa7abc | 0x42c |
EncodePointer | 0x0 | 0x41207c | 0xa94c0 | 0xa7ac0 | 0xea |
DecodePointer | 0x0 | 0x412080 | 0xa94c4 | 0xa7ac4 | 0xca |
IsDebuggerPresent | 0x0 | 0x412084 | 0xa94c8 | 0xa7ac8 | 0x300 |
IsProcessorFeaturePresent | 0x0 | 0x412088 | 0xa94cc | 0xa7acc | 0x304 |
ReadFile | 0x0 | 0x41208c | 0xa94d0 | 0xa7ad0 | 0x3c0 |
RaiseException | 0x0 | 0x412090 | 0xa94d4 | 0xa7ad4 | 0x3b1 |
RtlUnwind | 0x0 | 0x412094 | 0xa94d8 | 0xa7ad8 | 0x418 |
GetCommandLineA | 0x0 | 0x412098 | 0xa94dc | 0xa7adc | 0x186 |
HeapAlloc | 0x0 | 0x41209c | 0xa94e0 | 0xa7ae0 | 0x2cb |
HeapFree | 0x0 | 0x4120a0 | 0xa94e4 | 0xa7ae4 | 0x2cf |
ExitProcess | 0x0 | 0x4120a4 | 0xa94e8 | 0xa7ae8 | 0x119 |
GetModuleHandleExW | 0x0 | 0x4120a8 | 0xa94ec | 0xa7aec | 0x217 |
MultiByteToWideChar | 0x0 | 0x4120ac | 0xa94f0 | 0xa7af0 | 0x367 |
WideCharToMultiByte | 0x0 | 0x4120b0 | 0xa94f4 | 0xa7af4 | 0x511 |
HeapSize | 0x0 | 0x4120b4 | 0xa94f8 | 0xa7af8 | 0x2d4 |
UnhandledExceptionFilter | 0x0 | 0x4120b8 | 0xa94fc | 0xa7afc | 0x4d3 |
SetUnhandledExceptionFilter | 0x0 | 0x4120bc | 0xa9500 | 0xa7b00 | 0x4a5 |
SetLastError | 0x0 | 0x4120c0 | 0xa9504 | 0xa7b04 | 0x473 |
InitializeCriticalSectionAndSpinCount | 0x0 | 0x4120c4 | 0xa9508 | 0xa7b08 | 0x2e3 |
Sleep | 0x0 | 0x4120c8 | 0xa950c | 0xa7b0c | 0x4b2 |
GetCurrentProcess | 0x0 | 0x4120cc | 0xa9510 | 0xa7b10 | 0x1c0 |
TerminateProcess | 0x0 | 0x4120d0 | 0xa9514 | 0xa7b14 | 0x4c0 |
TlsAlloc | 0x0 | 0x4120d4 | 0xa9518 | 0xa7b18 | 0x4c5 |
TlsGetValue | 0x0 | 0x4120d8 | 0xa951c | 0xa7b1c | 0x4c7 |
TlsSetValue | 0x0 | 0x4120dc | 0xa9520 | 0xa7b20 | 0x4c8 |
TlsFree | 0x0 | 0x4120e0 | 0xa9524 | 0xa7b24 | 0x4c6 |
GetStartupInfoW | 0x0 | 0x4120e4 | 0xa9528 | 0xa7b28 | 0x263 |
GetModuleHandleW | 0x0 | 0x4120e8 | 0xa952c | 0xa7b2c | 0x218 |
EnterCriticalSection | 0x0 | 0x4120ec | 0xa9530 | 0xa7b30 | 0xee |
LeaveCriticalSection | 0x0 | 0x4120f0 | 0xa9534 | 0xa7b34 | 0x339 |
GetStdHandle | 0x0 | 0x4120f4 | 0xa9538 | 0xa7b38 | 0x264 |
GetFileType | 0x0 | 0x4120f8 | 0xa953c | 0xa7b3c | 0x1f3 |
DeleteCriticalSection | 0x0 | 0x4120fc | 0xa9540 | 0xa7b40 | 0xd1 |
SetFilePointerEx | 0x0 | 0x412100 | 0xa9544 | 0xa7b44 | 0x467 |
GetConsoleMode | 0x0 | 0x412104 | 0xa9548 | 0xa7b48 | 0x1ac |
ReadConsoleW | 0x0 | 0x412108 | 0xa954c | 0xa7b4c | 0x3be |
GetCurrentThreadId | 0x0 | 0x41210c | 0xa9550 | 0xa7b50 | 0x1c5 |
GetProcessHeap | 0x0 | 0x412110 | 0xa9554 | 0xa7b54 | 0x24a |
GetModuleFileNameA | 0x0 | 0x412114 | 0xa9558 | 0xa7b58 | 0x213 |
WriteFile | 0x0 | 0x412118 | 0xa955c | 0xa7b5c | 0x525 |
GetModuleFileNameW | 0x0 | 0x41211c | 0xa9560 | 0xa7b60 | 0x214 |
QueryPerformanceCounter | 0x0 | 0x412120 | 0xa9564 | 0xa7b64 | 0x3a7 |
GetCurrentProcessId | 0x0 | 0x412124 | 0xa9568 | 0xa7b68 | 0x1c1 |
GetSystemTimeAsFileTime | 0x0 | 0x412128 | 0xa956c | 0xa7b6c | 0x279 |
GetEnvironmentStringsW | 0x0 | 0x41212c | 0xa9570 | 0xa7b70 | 0x1da |
FreeEnvironmentStringsW | 0x0 | 0x412130 | 0xa9574 | 0xa7b74 | 0x161 |
LCMapStringW | 0x0 | 0x412134 | 0xa9578 | 0xa7b78 | 0x32d |
LoadLibraryExW | 0x0 | 0x412138 | 0xa957c | 0xa7b7c | 0x33e |
IsValidCodePage | 0x0 | 0x41213c | 0xa9580 | 0xa7b80 | 0x30a |
GetACP | 0x0 | 0x412140 | 0xa9584 | 0xa7b84 | 0x168 |
GetOEMCP | 0x0 | 0x412144 | 0xa9588 | 0xa7b88 | 0x237 |
GetCPInfo | 0x0 | 0x412148 | 0xa958c | 0xa7b8c | 0x172 |
HeapReAlloc | 0x0 | 0x41214c | 0xa9590 | 0xa7b90 | 0x2d2 |
SetStdHandle | 0x0 | 0x412150 | 0xa9594 | 0xa7b94 | 0x487 |
OutputDebugStringW | 0x0 | 0x412154 | 0xa9598 | 0xa7b98 | 0x38a |
GetStringTypeW | 0x0 | 0x412158 | 0xa959c | 0xa7b9c | 0x269 |
FlushFileBuffers | 0x0 | 0x41215c | 0xa95a0 | 0xa7ba0 | 0x157 |
GetConsoleCP | 0x0 | 0x412160 | 0xa95a4 | 0xa7ba4 | 0x19a |
CloseHandle | 0x0 | 0x412164 | 0xa95a8 | 0xa7ba8 | 0x52 |
WriteConsoleW | 0x0 | 0x412168 | 0xa95ac | 0xa7bac | 0x524 |
CreateFileW | 0x0 | 0x41216c | 0xa95b0 | 0xa7bb0 | 0x8f |
Memory Dumps (37)
»
Name | Process ID | Start VA | End VA | Dump Reason | PE Rebuild | Bitness | Entry Point | AV | YARA | Actions |
---|---|---|---|---|---|---|---|---|---|---|
host1506_2020-06-15_14-07.exe | 1 | 0x00400000 | 0x0067EFFF | Relevant Image |
![]() |
32-bit | 0x0040519A |
![]() |
![]() |
...
|
buffer | 1 | 0x002D0000 | 0x00360FFF | First Execution |
![]() |
32-bit | 0x002D0020 |
![]() |
![]() |
...
|
buffer | 1 | 0x00830000 | 0x00949FFF | First Execution |
![]() |
32-bit | 0x00830000 |
![]() |
![]() |
...
|
host1506_2020-06-15_14-07.exe | 1 | 0x00400000 | 0x0067EFFF | Content Changed |
![]() |
32-bit | 0x00424141 |
![]() |
![]() |
...
|
host1506_2020-06-15_14-07.exe | 1 | 0x00400000 | 0x0067EFFF | Content Changed |
![]() |
32-bit | 0x00423F84 |
![]() |
![]() |
...
|
host1506_2020-06-15_14-07.exe | 1 | 0x00400000 | 0x0067EFFF | Content Changed |
![]() |
32-bit | 0x0042C0F0 |
![]() |
![]() |
...
|
host1506_2020-06-15_14-07.exe | 1 | 0x00400000 | 0x0067EFFF | Content Changed |
![]() |
32-bit | 0x0043B021 |
![]() |
![]() |
...
|
host1506_2020-06-15_14-07.exe | 1 | 0x00400000 | 0x0067EFFF | Content Changed |
![]() |
32-bit | 0x0042D8D0 |
![]() |
![]() |
...
|
host1506_2020-06-15_14-07.exe | 1 | 0x00400000 | 0x0067EFFF | Content Changed |
![]() |
32-bit | 0x00421881 |
![]() |
![]() |
...
|
host1506_2020-06-15_14-07.exe | 1 | 0x00400000 | 0x0067EFFF | Content Changed |
![]() |
32-bit | 0x0042B420 |
![]() |
![]() |
...
|
host1506_2020-06-15_14-07.exe | 1 | 0x00400000 | 0x0067EFFF | Content Changed |
![]() |
32-bit | 0x004548D0 |
![]() |
![]() |
...
|
host1506_2020-06-15_14-07.exe | 1 | 0x00400000 | 0x0067EFFF | Content Changed |
![]() |
32-bit | 0x0041CC50 |
![]() |
![]() |
...
|
host1506_2020-06-15_14-07.exe | 1 | 0x00400000 | 0x0067EFFF | Content Changed |
![]() |
32-bit | 0x00419E70 |
![]() |
![]() |
...
|
host1506_2020-06-15_14-07.exe | 1 | 0x00400000 | 0x0067EFFF | Content Changed |
![]() |
32-bit | 0x0040CF10 |
![]() |
![]() |
...
|
host1506_2020-06-15_14-07.exe | 1 | 0x00400000 | 0x0067EFFF | Content Changed |
![]() |
32-bit | 0x0042B420 |
![]() |
![]() |
...
|
host1506_2020-06-15_14-07.exe | 1 | 0x00400000 | 0x0067EFFF | Final Dump |
![]() |
32-bit | 0x00430BF0 |
![]() |
![]() |
...
|
host1506_2020-06-15_14-07.exe | 1 | 0x00400000 | 0x0067EFFF | Content Changed |
![]() |
32-bit | 0x00433F99 |
![]() |
![]() |
...
|
host1506_2020-06-15_14-07.exe | 1 | 0x00400000 | 0x0067EFFF | Content Changed |
![]() |
32-bit | 0x00424081 |
![]() |
![]() |
...
|
host1506_2020-06-15_14-07.exe | 1 | 0x00400000 | 0x0067EFFF | Content Changed |
![]() |
32-bit | 0x004CA6F7 |
![]() |
![]() |
...
|
buffer | 1 | 0x00830000 | 0x00949FFF | Content Changed |
![]() |
32-bit | 0x00830920 |
![]() |
![]() |
...
|
host1506_2020-06-15_14-07.exe | 1 | 0x00400000 | 0x0067EFFF | Process Termination |
![]() |
32-bit | - |
![]() |
![]() |
...
|
host1506_2020-06-15_14-07.exe | 6 | 0x00400000 | 0x0067EFFF | Relevant Image |
![]() |
32-bit | 0x0040519A |
![]() |
![]() |
...
|
buffer | 6 | 0x006F0000 | 0x00780FFF | First Execution |
![]() |
32-bit | 0x006F0020 |
![]() |
![]() |
...
|
buffer | 6 | 0x00790000 | 0x008A9FFF | First Execution |
![]() |
32-bit | 0x00790000 |
![]() |
![]() |
...
|
host1506_2020-06-15_14-07.exe | 6 | 0x00400000 | 0x0067EFFF | Content Changed |
![]() |
32-bit | 0x00424141 |
![]() |
![]() |
...
|
host1506_2020-06-15_14-07.exe | 6 | 0x00400000 | 0x0067EFFF | Content Changed |
![]() |
32-bit | 0x00423F84 |
![]() |
![]() |
...
|
host1506_2020-06-15_14-07.exe | 6 | 0x00400000 | 0x0067EFFF | Content Changed |
![]() |
32-bit | 0x0042C0F0 |
![]() |
![]() |
...
|
host1506_2020-06-15_14-07.exe | 6 | 0x00400000 | 0x0067EFFF | Content Changed |
![]() |
32-bit | 0x0043B021 |
![]() |
![]() |
...
|
host1506_2020-06-15_14-07.exe | 6 | 0x00400000 | 0x0067EFFF | Content Changed |
![]() |
32-bit | 0x00431F64 |
![]() |
![]() |
...
|
host1506_2020-06-15_14-07.exe | 6 | 0x00400000 | 0x0067EFFF | Content Changed |
![]() |
32-bit | 0x00421881 |
![]() |
![]() |
...
|
host1506_2020-06-15_14-07.exe | 6 | 0x00400000 | 0x0067EFFF | Content Changed |
![]() |
32-bit | 0x0042B420 |
![]() |
![]() |
...
|
host1506_2020-06-15_14-07.exe | 6 | 0x00400000 | 0x0067EFFF | Content Changed |
![]() |
32-bit | 0x004548D0 |
![]() |
![]() |
...
|
host1506_2020-06-15_14-07.exe | 6 | 0x00400000 | 0x0067EFFF | Content Changed |
![]() |
32-bit | 0x0041CC50 |
![]() |
![]() |
...
|
host1506_2020-06-15_14-07.exe | 6 | 0x00400000 | 0x0067EFFF | Content Changed |
![]() |
32-bit | 0x00419E70 |
![]() |
![]() |
...
|
host1506_2020-06-15_14-07.exe | 6 | 0x00400000 | 0x0067EFFF | Content Changed |
![]() |
32-bit | 0x0040CF10 |
![]() |
![]() |
...
|
host1506_2020-06-15_14-07.exe | 8 | 0x00400000 | 0x0067EFFF | Relevant Image |
![]() |
32-bit | 0x0040519A |
![]() |
![]() |
...
|
buffer | 8 | 0x00720000 | 0x00839FFF | First Execution |
![]() |
32-bit | 0x00720000 |
![]() |
![]() |
...
|
Local AV Matches (1)
»
Threat Name | Severity |
---|---|
Trojan.GenericKD.43348205 |
Malicious
|
C:\Users\5p5NrGJn0jS HALPmcxz\Contacts\Aclviho ASldjfl.contact.tabe | Dropped File | Stream |
Malicious
|
...
|
»
YARA Matches (1)
»
Rule Name | Rule Description | Classification | Score | Actions |
---|---|---|---|---|
DjvuEncryptedFile | File encrypted by Djvu Ransomware | Ransomware |
5/5
|
...
|
C:\Users\5p5NrGJn0jS HALPmcxz\Contacts\Administrator.contact | Modified File | Stream |
Malicious
|
...
|
»
YARA Matches (1)
»
Rule Name | Rule Description | Classification | Score | Actions |
---|---|---|---|---|
DjvuEncryptedFile | File encrypted by Djvu Ransomware | Ransomware |
5/5
|
...
|
C:\Users\5p5NrGJn0jS HALPmcxz\Contacts\asdlfk poopvy.contact.tabe | Dropped File | Stream |
Malicious
|
...
|
»
YARA Matches (1)
»
Rule Name | Rule Description | Classification | Score | Actions |
---|---|---|---|---|
DjvuEncryptedFile | File encrypted by Djvu Ransomware | Ransomware |
5/5
|
...
|
C:\Users\5p5NrGJn0jS HALPmcxz\Contacts\chucu jadnvk.contact | Modified File | Stream |
Malicious
|
...
|
»
YARA Matches (1)
»
Rule Name | Rule Description | Classification | Score | Actions |
---|---|---|---|---|
DjvuEncryptedFile | File encrypted by Djvu Ransomware | Ransomware |
5/5
|
...
|
C:\Users\5p5NrGJn0jS HALPmcxz\Contacts\lulcit amkdfe.contact.tabe | Dropped File | Stream |
Malicious
|
...
|
»
YARA Matches (1)
»
Rule Name | Rule Description | Classification | Score | Actions |
---|---|---|---|---|
DjvuEncryptedFile | File encrypted by Djvu Ransomware | Ransomware |
5/5
|
...
|
C:\Users\5p5NrGJn0jS HALPmcxz\Contacts\sikvnb huvuib.contact.tabe | Dropped File | Stream |
Malicious
|
...
|
»
YARA Matches (1)
»
Rule Name | Rule Description | Classification | Score | Actions |
---|---|---|---|---|
DjvuEncryptedFile | File encrypted by Djvu Ransomware | Ransomware |
5/5
|
...
|
C:\Users\5p5NrGJn0jS HALPmcxz\Desktop\-E3i.jpg.tabe | Dropped File | Image |
Malicious
|
...
|
»
YARA Matches (1)
»
Rule Name | Rule Description | Classification | Score | Actions |
---|---|---|---|---|
DjvuEncryptedFile | File encrypted by Djvu Ransomware | Ransomware |
5/5
|
...
|
C:\Users\5p5NrGJn0jS HALPmcxz\Desktop\1fgla.mp4 | Modified File | Stream |
Malicious
|
...
|
»
YARA Matches (1)
»
Rule Name | Rule Description | Classification | Score | Actions |
---|---|---|---|---|
DjvuEncryptedFile | File encrypted by Djvu Ransomware | Ransomware |
5/5
|
...
|
C:\Users\5p5NrGJn0jS HALPmcxz\Desktop\1hhD8hoUWopvU.m4a | Modified File | Stream |
Malicious
|
...
|
»
YARA Matches (1)
»
Rule Name | Rule Description | Classification | Score | Actions |
---|---|---|---|---|
DjvuEncryptedFile | File encrypted by Djvu Ransomware | Ransomware |
5/5
|
...
|
C:\Users\5p5NrGJn0jS HALPmcxz\Desktop\2C_1.mp3.tabe | Dropped File | Stream |
Malicious
|
...
|
»
YARA Matches (1)
»
Rule Name | Rule Description | Classification | Score | Actions |
---|---|---|---|---|
DjvuEncryptedFile | File encrypted by Djvu Ransomware | Ransomware |
5/5
|
...
|
C:\Users\5p5NrGJn0jS HALPmcxz\Desktop\3KShRcF.ppt.tabe | Dropped File | Stream |
Malicious
|
...
|
»
YARA Matches (1)
»
Rule Name | Rule Description | Classification | Score | Actions |
---|---|---|---|---|
DjvuEncryptedFile | File encrypted by Djvu Ransomware | Ransomware |
5/5
|
...
|
C:\Users\5p5NrGJn0jS HALPmcxz\Desktop\3RojuHrbe-bfp0nbccK.gif.tabe | Dropped File | Image |
Malicious
|
...
|
»
YARA Matches (1)
»
Rule Name | Rule Description | Classification | Score | Actions |
---|---|---|---|---|
DjvuEncryptedFile | File encrypted by Djvu Ransomware | Ransomware |
5/5
|
...
|
C:\Users\5p5NrGJn0jS HALPmcxz\Desktop\4k-NhBHWCQsrB9HktG.ppt.tabe | Dropped File | Stream |
Malicious
|
...
|
»
YARA Matches (1)
»
Rule Name | Rule Description | Classification | Score | Actions |
---|---|---|---|---|
DjvuEncryptedFile | File encrypted by Djvu Ransomware | Ransomware |
5/5
|
...
|
C:\Users\5p5NrGJn0jS HALPmcxz\Desktop\6 E2yImJTKh03Xs1.pptx.tabe | Dropped File | ZIP |
Malicious
|
...
|
»
YARA Matches (1)
»
Rule Name | Rule Description | Classification | Score | Actions |
---|---|---|---|---|
DjvuEncryptedFile | File encrypted by Djvu Ransomware | Ransomware |
5/5
|
...
|
C:\Users\5p5NrGJn0jS HALPmcxz\Desktop\9--KsUoJ.wav | Modified File | Stream |
Malicious
|
...
|
»
YARA Matches (1)
»
Rule Name | Rule Description | Classification | Score | Actions |
---|---|---|---|---|
DjvuEncryptedFile | File encrypted by Djvu Ransomware | Ransomware |
5/5
|
...
|
C:\Users\5p5NrGJn0jS HALPmcxz\Desktop\a8D2GLnw7ZaQJ5.mp3.tabe | Dropped File | Stream |
Malicious
|
...
|
»
YARA Matches (1)
»
Rule Name | Rule Description | Classification | Score | Actions |
---|---|---|---|---|
DjvuEncryptedFile | File encrypted by Djvu Ransomware | Ransomware |
5/5
|
...
|
C:\Users\5p5NrGJn0jS HALPmcxz\Desktop\aYzTNB.pdf.tabe | Dropped File |
Malicious
|
...
|
»
YARA Matches (4)
»
Rule Name | Rule Description | Classification | Score | Actions |
---|---|---|---|---|
DjvuEncryptedFile | File encrypted by Djvu Ransomware | Ransomware |
5/5
|
...
|
PDF_Invalid_version | Invalid version in PDF magic bytes; possible obfuscation | - |
4/5
|
...
|
PDF_Missing_startxref | Malformed PDF without startxref; possible obfuscation | - |
3/5
|
...
|
PDF_Missing_EOF | Malformed PDF without EOF marker; possible obfuscation | - |
3/5
|
...
|
C:\Users\5p5NrGJn0jS HALPmcxz\Desktop\CFPAfZk624G.swf | Modified File | Shockwave Flash |
Malicious
|
...
|
»
YARA Matches (1)
»
Rule Name | Rule Description | Classification | Score | Actions |
---|---|---|---|---|
DjvuEncryptedFile | File encrypted by Djvu Ransomware | Ransomware |
5/5
|
...
|
C:\Users\5p5NrGJn0jS HALPmcxz\Desktop\ESSVJfazMJQYO.avi | Modified File | Stream |
Malicious
|
...
|
»
YARA Matches (1)
»
Rule Name | Rule Description | Classification | Score | Actions |
---|---|---|---|---|
DjvuEncryptedFile | File encrypted by Djvu Ransomware | Ransomware |
5/5
|
...
|
C:\Users\5p5NrGJn0jS HALPmcxz\Desktop\Flnt6SFHOdd1-kxVwgM2.png.tabe | Dropped File | Stream |
Malicious
|
...
|
»
YARA Matches (1)
»
Rule Name | Rule Description | Classification | Score | Actions |
---|---|---|---|---|
DjvuEncryptedFile | File encrypted by Djvu Ransomware | Ransomware |
5/5
|
...
|
C:\Users\5p5NrGJn0jS HALPmcxz\Desktop\ghIXM.jpg | Modified File | Image |
Malicious
|
...
|
»
YARA Matches (1)
»
Rule Name | Rule Description | Classification | Score | Actions |
---|---|---|---|---|
DjvuEncryptedFile | File encrypted by Djvu Ransomware | Ransomware |
5/5
|
...
|
C:\Users\5p5NrGJn0jS HALPmcxz\Desktop\HCr_ 5e.mp3 | Modified File | Stream |
Malicious
|
...
|
»
YARA Matches (1)
»
Rule Name | Rule Description | Classification | Score | Actions |
---|---|---|---|---|
DjvuEncryptedFile | File encrypted by Djvu Ransomware | Ransomware |
5/5
|
...
|
C:\Users\5p5NrGJn0jS HALPmcxz\Desktop\host1506_2020-06-15_14-07.exe | Modified File | Binary |
Malicious
|
...
|
»
Memory Dumps (37)
»
Name | Process ID | Start VA | End VA | Dump Reason | PE Rebuild | Bitness | Entry Point | AV | YARA | Actions |
---|---|---|---|---|---|---|---|---|---|---|
host1506_2020-06-15_14-07.exe | 1 | 0x00400000 | 0x0067EFFF | Relevant Image |
![]() |
32-bit | 0x0040519A |
![]() |
![]() |
...
|
buffer | 1 | 0x002D0000 | 0x00360FFF | First Execution |
![]() |
32-bit | 0x002D0020 |
![]() |
![]() |
...
|
buffer | 1 | 0x00830000 | 0x00949FFF | First Execution |
![]() |
32-bit | 0x00830000 |
![]() |
![]() |
...
|
host1506_2020-06-15_14-07.exe | 1 | 0x00400000 | 0x0067EFFF | Content Changed |
![]() |
32-bit | 0x00424141 |
![]() |
![]() |
...
|
host1506_2020-06-15_14-07.exe | 1 | 0x00400000 | 0x0067EFFF | Content Changed |
![]() |
32-bit | 0x00423F84 |
![]() |
![]() |
...
|
host1506_2020-06-15_14-07.exe | 1 | 0x00400000 | 0x0067EFFF | Content Changed |
![]() |
32-bit | 0x0042C0F0 |
![]() |
![]() |
...
|
host1506_2020-06-15_14-07.exe | 1 | 0x00400000 | 0x0067EFFF | Content Changed |
![]() |
32-bit | 0x0043B021 |
![]() |
![]() |
...
|
host1506_2020-06-15_14-07.exe | 1 | 0x00400000 | 0x0067EFFF | Content Changed |
![]() |
32-bit | 0x0042D8D0 |
![]() |
![]() |
...
|
host1506_2020-06-15_14-07.exe | 1 | 0x00400000 | 0x0067EFFF | Content Changed |
![]() |
32-bit | 0x00421881 |
![]() |
![]() |
...
|
host1506_2020-06-15_14-07.exe | 1 | 0x00400000 | 0x0067EFFF | Content Changed |
![]() |
32-bit | 0x0042B420 |
![]() |
![]() |
...
|
host1506_2020-06-15_14-07.exe | 1 | 0x00400000 | 0x0067EFFF | Content Changed |
![]() |
32-bit | 0x004548D0 |
![]() |
![]() |
...
|
host1506_2020-06-15_14-07.exe | 1 | 0x00400000 | 0x0067EFFF | Content Changed |
![]() |
32-bit | 0x0041CC50 |
![]() |
![]() |
...
|
host1506_2020-06-15_14-07.exe | 1 | 0x00400000 | 0x0067EFFF | Content Changed |
![]() |
32-bit | 0x00419E70 |
![]() |
![]() |
...
|
host1506_2020-06-15_14-07.exe | 1 | 0x00400000 | 0x0067EFFF | Content Changed |
![]() |
32-bit | 0x0040CF10 |
![]() |
![]() |
...
|
host1506_2020-06-15_14-07.exe | 1 | 0x00400000 | 0x0067EFFF | Content Changed |
![]() |
32-bit | 0x0042B420 |
![]() |
![]() |
...
|
host1506_2020-06-15_14-07.exe | 1 | 0x00400000 | 0x0067EFFF | Final Dump |
![]() |
32-bit | 0x00430BF0 |
![]() |
![]() |
...
|
host1506_2020-06-15_14-07.exe | 1 | 0x00400000 | 0x0067EFFF | Content Changed |
![]() |
32-bit | 0x00433F99 |
![]() |
![]() |
...
|
host1506_2020-06-15_14-07.exe | 1 | 0x00400000 | 0x0067EFFF | Content Changed |
![]() |
32-bit | 0x00424081 |
![]() |
![]() |
...
|
host1506_2020-06-15_14-07.exe | 1 | 0x00400000 | 0x0067EFFF | Content Changed |
![]() |
32-bit | 0x004CA6F7 |
![]() |
![]() |
...
|
buffer | 1 | 0x00830000 | 0x00949FFF | Content Changed |
![]() |
32-bit | 0x00830920 |
![]() |
![]() |
...
|
host1506_2020-06-15_14-07.exe | 1 | 0x00400000 | 0x0067EFFF | Process Termination |
![]() |
32-bit | - |
![]() |
![]() |
...
|
host1506_2020-06-15_14-07.exe | 6 | 0x00400000 | 0x0067EFFF | Relevant Image |
![]() |
32-bit | 0x0040519A |
![]() |
![]() |
...
|
buffer | 6 | 0x006F0000 | 0x00780FFF | First Execution |
![]() |
32-bit | 0x006F0020 |
![]() |
![]() |
...
|
buffer | 6 | 0x00790000 | 0x008A9FFF | First Execution |
![]() |
32-bit | 0x00790000 |
![]() |
![]() |
...
|
host1506_2020-06-15_14-07.exe | 6 | 0x00400000 | 0x0067EFFF | Content Changed |
![]() |
32-bit | 0x00424141 |
![]() |
![]() |
...
|
host1506_2020-06-15_14-07.exe | 6 | 0x00400000 | 0x0067EFFF | Content Changed |
![]() |
32-bit | 0x00423F84 |
![]() |
![]() |
...
|
host1506_2020-06-15_14-07.exe | 6 | 0x00400000 | 0x0067EFFF | Content Changed |
![]() |
32-bit | 0x0042C0F0 |
![]() |
![]() |
...
|
host1506_2020-06-15_14-07.exe | 6 | 0x00400000 | 0x0067EFFF | Content Changed |
![]() |
32-bit | 0x0043B021 |
![]() |
![]() |
...
|
host1506_2020-06-15_14-07.exe | 6 | 0x00400000 | 0x0067EFFF | Content Changed |
![]() |
32-bit | 0x00431F64 |
![]() |
![]() |
...
|
host1506_2020-06-15_14-07.exe | 6 | 0x00400000 | 0x0067EFFF | Content Changed |
![]() |
32-bit | 0x00421881 |
![]() |
![]() |
...
|
host1506_2020-06-15_14-07.exe | 6 | 0x00400000 | 0x0067EFFF | Content Changed |
![]() |
32-bit | 0x0042B420 |
![]() |
![]() |
...
|
host1506_2020-06-15_14-07.exe | 6 | 0x00400000 | 0x0067EFFF | Content Changed |
![]() |
32-bit | 0x004548D0 |
![]() |
![]() |
...
|
host1506_2020-06-15_14-07.exe | 6 | 0x00400000 | 0x0067EFFF | Content Changed |
![]() |
32-bit | 0x0041CC50 |
![]() |
![]() |
...
|
host1506_2020-06-15_14-07.exe | 6 | 0x00400000 | 0x0067EFFF | Content Changed |
![]() |
32-bit | 0x00419E70 |
![]() |
![]() |
...
|
host1506_2020-06-15_14-07.exe | 6 | 0x00400000 | 0x0067EFFF | Content Changed |
![]() |
32-bit | 0x0040CF10 |
![]() |
![]() |
...
|
host1506_2020-06-15_14-07.exe | 8 | 0x00400000 | 0x0067EFFF | Relevant Image |
![]() |
32-bit | 0x0040519A |
![]() |
![]() |
...
|
buffer | 8 | 0x00720000 | 0x00839FFF | First Execution |
![]() |
32-bit | 0x00720000 |
![]() |
![]() |
...
|
YARA Matches (1)
»
Rule Name | Rule Description | Classification | Score | Actions |
---|---|---|---|---|
DjvuEncryptedFile | File encrypted by Djvu Ransomware | Ransomware |
5/5
|
...
|
C:\Users\5p5NrGJn0jS HALPmcxz\Desktop\j39KpS0Z.jpg | Modified File | Image |
Malicious
|
...
|
»
YARA Matches (1)
»
Rule Name | Rule Description | Classification | Score | Actions |
---|---|---|---|---|
DjvuEncryptedFile | File encrypted by Djvu Ransomware | Ransomware |
5/5
|
...
|
C:\Users\5p5NrGJn0jS HALPmcxz\Desktop\K7l0m.jpg | Modified File | Image |
Malicious
|
...
|
»
YARA Matches (1)
»
Rule Name | Rule Description | Classification | Score | Actions |
---|---|---|---|---|
DjvuEncryptedFile | File encrypted by Djvu Ransomware | Ransomware |
5/5
|
...
|
C:\Users\5p5NrGJn0jS HALPmcxz\Desktop\L8X_tMhF7RAG1u.gif | Modified File | Image |
Malicious
|
...
|
»
YARA Matches (1)
»
Rule Name | Rule Description | Classification | Score | Actions |
---|---|---|---|---|
DjvuEncryptedFile | File encrypted by Djvu Ransomware | Ransomware |
5/5
|
...
|
C:\Users\5p5NrGJn0jS HALPmcxz\Desktop\LcAWP.mp3.tabe | Dropped File | Stream |
Malicious
|
...
|
»
YARA Matches (1)
»
Rule Name | Rule Description | Classification | Score | Actions |
---|---|---|---|---|
DjvuEncryptedFile | File encrypted by Djvu Ransomware | Ransomware |
5/5
|
...
|
C:\Users\5p5NrGJn0jS HALPmcxz\Desktop\OqjEf f9z.wav.tabe | Dropped File | Stream |
Malicious
|
...
|
»
YARA Matches (1)
»
Rule Name | Rule Description | Classification | Score | Actions |
---|---|---|---|---|
DjvuEncryptedFile | File encrypted by Djvu Ransomware | Ransomware |
5/5
|
...
|
C:\Users\5p5NrGJn0jS HALPmcxz\Desktop\Oxw27.m4a.tabe | Dropped File | Stream |
Malicious
|
...
|
»
YARA Matches (1)
»
Rule Name | Rule Description | Classification | Score | Actions |
---|---|---|---|---|
DjvuEncryptedFile | File encrypted by Djvu Ransomware | Ransomware |
5/5
|
...
|
C:\Users\5p5NrGJn0jS HALPmcxz\Desktop\polYSVkiJ0.jpg | Modified File | Image |
Malicious
|
...
|
»
YARA Matches (1)
»
Rule Name | Rule Description | Classification | Score | Actions |
---|---|---|---|---|
DjvuEncryptedFile | File encrypted by Djvu Ransomware | Ransomware |
5/5
|
...
|
C:\Users\5p5NrGJn0jS HALPmcxz\Desktop\qbFQavKzY7DOO2Fa3.png.tabe | Dropped File | Stream |
Malicious
|
...
|
»
YARA Matches (1)
»
Rule Name | Rule Description | Classification | Score | Actions |
---|---|---|---|---|
DjvuEncryptedFile | File encrypted by Djvu Ransomware | Ransomware |
5/5
|
...
|
C:\Users\5p5NrGJn0jS HALPmcxz\Desktop\S51hIWg-vULNLHl.png | Modified File | Stream |
Malicious
|
...
|
»
YARA Matches (1)
»
Rule Name | Rule Description | Classification | Score | Actions |
---|---|---|---|---|
DjvuEncryptedFile | File encrypted by Djvu Ransomware | Ransomware |
5/5
|
...
|
C:\Users\5p5NrGJn0jS HALPmcxz\Desktop\v0qSv 4KL-r8YM-GgMBG.gif | Modified File | Image |
Malicious
|
...
|
»
YARA Matches (1)
»
Rule Name | Rule Description | Classification | Score | Actions |
---|---|---|---|---|
DjvuEncryptedFile | File encrypted by Djvu Ransomware | Ransomware |
5/5
|
...
|
C:\Users\5p5NrGJn0jS HALPmcxz\Desktop\XXVzs.ots.tabe | Dropped File | Stream |
Malicious
|
...
|
»
YARA Matches (1)
»
Rule Name | Rule Description | Classification | Score | Actions |
---|---|---|---|---|
DjvuEncryptedFile | File encrypted by Djvu Ransomware | Ransomware |
5/5
|
...
|
C:\Users\5p5NrGJn0jS HALPmcxz\Desktop\zmKlsT4Rdm2.mp4.tabe | Dropped File | Stream |
Malicious
|
...
|
»
YARA Matches (1)
»
Rule Name | Rule Description | Classification | Score | Actions |
---|---|---|---|---|
DjvuEncryptedFile | File encrypted by Djvu Ransomware | Ransomware |
5/5
|
...
|
C:\Users\5p5NrGJn0jS HALPmcxz\Documents\14trhq_d.pptx.tabe | Dropped File | Stream |
Malicious
|
...
|
»
YARA Matches (1)
»
Rule Name | Rule Description | Classification | Score | Actions |
---|---|---|---|---|
DjvuEncryptedFile | File encrypted by Djvu Ransomware | Ransomware |
5/5
|
...
|
C:\Users\5p5NrGJn0jS HALPmcxz\Documents\9zMNq42s2vzr.pdf | Modified File |
Malicious
|
...
|
»
YARA Matches (4)
»
Rule Name | Rule Description | Classification | Score | Actions |
---|---|---|---|---|
DjvuEncryptedFile | File encrypted by Djvu Ransomware | Ransomware |
5/5
|
...
|
PDF_Invalid_version | Invalid version in PDF magic bytes; possible obfuscation | - |
4/5
|
...
|
PDF_Missing_startxref | Malformed PDF without startxref; possible obfuscation | - |
3/5
|
...
|
PDF_Missing_EOF | Malformed PDF without EOF marker; possible obfuscation | - |
3/5
|
...
|
C:\Users\5p5NrGJn0jS HALPmcxz\Documents\aCSBQG.docx | Modified File | ZIP |
Malicious
|
...
|
»
YARA Matches (1)
»
Rule Name | Rule Description | Classification | Score | Actions |
---|---|---|---|---|
DjvuEncryptedFile | File encrypted by Djvu Ransomware | Ransomware |
5/5
|
...
|
C:\Users\5p5NrGJn0jS HALPmcxz\Documents\BxIJBC9D2ddyA.xlsx.tabe | Dropped File | Stream |
Malicious
|
...
|
»
YARA Matches (1)
»
Rule Name | Rule Description | Classification | Score | Actions |
---|---|---|---|---|
DjvuEncryptedFile | File encrypted by Djvu Ransomware | Ransomware |
5/5
|
...
|
C:\Users\5p5NrGJn0jS HALPmcxz\Documents\c8Hky4m8.ots | Modified File | ZIP |
Malicious
|
...
|
»
YARA Matches (1)
»
Rule Name | Rule Description | Classification | Score | Actions |
---|---|---|---|---|
DjvuEncryptedFile | File encrypted by Djvu Ransomware | Ransomware |
5/5
|
...
|
C:\Users\5p5NrGJn0jS HALPmcxz\Documents\FIxvzNotV8Z.pptx.tabe | Dropped File | ZIP |
Malicious
|
...
|
»
YARA Matches (1)
»
Rule Name | Rule Description | Classification | Score | Actions |
---|---|---|---|---|
DjvuEncryptedFile | File encrypted by Djvu Ransomware | Ransomware |
5/5
|
...
|
C:\Users\5p5NrGJn0jS HALPmcxz\Documents\fzzO4F.xlsx | Modified File | Stream |
Malicious
|
...
|
»
YARA Matches (1)
»
Rule Name | Rule Description | Classification | Score | Actions |
---|---|---|---|---|
DjvuEncryptedFile | File encrypted by Djvu Ransomware | Ransomware |
5/5
|
...
|
C:\Users\5p5NrGJn0jS HALPmcxz\Documents\L1XKTglsoKdjgkn7BZ.xlsx.tabe | Dropped File | ZIP |
Malicious
|
...
|
»
YARA Matches (1)
»
Rule Name | Rule Description | Classification | Score | Actions |
---|---|---|---|---|
DjvuEncryptedFile | File encrypted by Djvu Ransomware | Ransomware |
5/5
|
...
|
C:\Users\5p5NrGJn0jS HALPmcxz\Documents\l8TAds.xlsx | Modified File | ZIP |
Malicious
|
...
|
»
YARA Matches (1)
»
Rule Name | Rule Description | Classification | Score | Actions |
---|---|---|---|---|
DjvuEncryptedFile | File encrypted by Djvu Ransomware | Ransomware |
5/5
|
...
|
C:\Users\5p5NrGJn0jS HALPmcxz\Documents\lQwOwuRg4EU.pptx | Modified File | ZIP |
Malicious
|
...
|
»
YARA Matches (1)
»
Rule Name | Rule Description | Classification | Score | Actions |
---|---|---|---|---|
DjvuEncryptedFile | File encrypted by Djvu Ransomware | Ransomware |
5/5
|
...
|
C:\Users\5p5NrGJn0jS HALPmcxz\Documents\MOe2_m0ZA.pptx | Modified File | Stream |
Malicious
|
...
|
»
YARA Matches (1)
»
Rule Name | Rule Description | Classification | Score | Actions |
---|---|---|---|---|
DjvuEncryptedFile | File encrypted by Djvu Ransomware | Ransomware |
5/5
|
...
|
C:\Users\5p5NrGJn0jS HALPmcxz\Documents\O-sgVgJHm6j_SoEJfcN.docx | Modified File | Stream |
Malicious
|
...
|
»
YARA Matches (1)
»
Rule Name | Rule Description | Classification | Score | Actions |
---|---|---|---|---|
DjvuEncryptedFile | File encrypted by Djvu Ransomware | Ransomware |
5/5
|
...
|
C:\Users\5p5NrGJn0jS HALPmcxz\Documents\P6G5NgEhZKQM6.xlsx | Modified File | ZIP |
Malicious
|
...
|
»
YARA Matches (1)
»
Rule Name | Rule Description | Classification | Score | Actions |
---|---|---|---|---|
DjvuEncryptedFile | File encrypted by Djvu Ransomware | Ransomware |
5/5
|
...
|
C:\Users\5p5NrGJn0jS HALPmcxz\Documents\rAGDqO_2z-.docx | Modified File | Stream |
Malicious
|
...
|
»
YARA Matches (1)
»
Rule Name | Rule Description | Classification | Score | Actions |
---|---|---|---|---|
DjvuEncryptedFile | File encrypted by Djvu Ransomware | Ransomware |
5/5
|
...
|
C:\Users\5p5NrGJn0jS HALPmcxz\Documents\t_ht8Ts9s.pptx | Modified File | ZIP |
Malicious
|
...
|
»
YARA Matches (1)
»
Rule Name | Rule Description | Classification | Score | Actions |
---|---|---|---|---|
DjvuEncryptedFile | File encrypted by Djvu Ransomware | Ransomware |
5/5
|
...
|
C:\Users\5p5NrGJn0jS HALPmcxz\Documents\vzEor_EMvUKsoW9F.xlsx.tabe | Dropped File | ZIP |
Malicious
|
...
|
»
YARA Matches (1)
»
Rule Name | Rule Description | Classification | Score | Actions |
---|---|---|---|---|
DjvuEncryptedFile | File encrypted by Djvu Ransomware | Ransomware |
5/5
|
...
|
C:\Users\5p5NrGJn0jS HALPmcxz\Documents\XXme.pps.tabe | Dropped File | Stream |
Malicious
|
...
|
»
YARA Matches (1)
»
Rule Name | Rule Description | Classification | Score | Actions |
---|---|---|---|---|
DjvuEncryptedFile | File encrypted by Djvu Ransomware | Ransomware |
5/5
|
...
|
C:\Users\5p5NrGJn0jS HALPmcxz\Documents\YGNPjCOP5wuk0HfgUA.pptx | Modified File | ZIP |
Malicious
|
...
|
»
YARA Matches (1)
»
Rule Name | Rule Description | Classification | Score | Actions |
---|---|---|---|---|
DjvuEncryptedFile | File encrypted by Djvu Ransomware | Ransomware |
5/5
|
...
|
C:\Users\5p5NrGJn0jS HALPmcxz\Documents\yN55FwTZal7Q-RaoZS.docx | Modified File | ZIP |
Malicious
|
...
|
»
YARA Matches (1)
»
Rule Name | Rule Description | Classification | Score | Actions |
---|---|---|---|---|
DjvuEncryptedFile | File encrypted by Djvu Ransomware | Ransomware |
5/5
|
...
|
C:\Users\5p5NrGJn0jS HALPmcxz\Documents\yoGnGFbTSP8JpoNMxcWx.docx.tabe | Dropped File | Stream |
Malicious
|
...
|
»
YARA Matches (1)
»
Rule Name | Rule Description | Classification | Score | Actions |
---|---|---|---|---|
DjvuEncryptedFile | File encrypted by Djvu Ransomware | Ransomware |
5/5
|
...
|
C:\Users\5p5NrGJn0jS HALPmcxz\Documents\YX5oTaLr46sR87w.ppt | Modified File | Stream |
Malicious
|
...
|
»
YARA Matches (1)
»
Rule Name | Rule Description | Classification | Score | Actions |
---|---|---|---|---|
DjvuEncryptedFile | File encrypted by Djvu Ransomware | Ransomware |
5/5
|
...
|
C:\Users\5p5NrGJn0jS HALPmcxz\Music\2BR1Eq.wav | Modified File | Stream |
Malicious
|
...
|
»
YARA Matches (1)
»
Rule Name | Rule Description | Classification | Score | Actions |
---|---|---|---|---|
DjvuEncryptedFile | File encrypted by Djvu Ransomware | Ransomware |
5/5
|
...
|
C:\Users\5p5NrGJn0jS HALPmcxz\Music\6zmni1gT8J47.wav | Modified File | Stream |
Malicious
|
...
|
»
YARA Matches (1)
»
Rule Name | Rule Description | Classification | Score | Actions |
---|---|---|---|---|
DjvuEncryptedFile | File encrypted by Djvu Ransomware | Ransomware |
5/5
|
...
|
C:\Users\5p5NrGJn0jS HALPmcxz\Music\8LMATf9HzFQ.mp3 | Modified File | Stream |
Malicious
|
...
|
»
YARA Matches (1)
»
Rule Name | Rule Description | Classification | Score | Actions |
---|---|---|---|---|
DjvuEncryptedFile | File encrypted by Djvu Ransomware | Ransomware |
5/5
|
...
|
C:\Users\5p5NrGJn0jS HALPmcxz\Pictures\2-xyNT8e WM7SpMp.bmp | Modified File | Stream |
Malicious
|
...
|
»
YARA Matches (1)
»
Rule Name | Rule Description | Classification | Score | Actions |
---|---|---|---|---|
DjvuEncryptedFile | File encrypted by Djvu Ransomware | Ransomware |
5/5
|
...
|
C:\Users\5p5NrGJn0jS HALPmcxz\Pictures\2VdVROGOaJhbJy.gif | Modified File | Image |
Malicious
|
...
|
»
YARA Matches (1)
»
Rule Name | Rule Description | Classification | Score | Actions |
---|---|---|---|---|
DjvuEncryptedFile | File encrypted by Djvu Ransomware | Ransomware |
5/5
|
...
|
C:\Users\5p5NrGJn0jS HALPmcxz\Pictures\3n qVt- wlj -Go4 V.bmp | Modified File | Stream |
Malicious
|
...
|
»
YARA Matches (1)
»
Rule Name | Rule Description | Classification | Score | Actions |
---|---|---|---|---|
DjvuEncryptedFile | File encrypted by Djvu Ransomware | Ransomware |
5/5
|
...
|
C:\Users\5p5NrGJn0jS HALPmcxz\Pictures\4EFum_ZEFyEAYh7kD.png.tabe | Dropped File | Stream |
Malicious
|
...
|
»
YARA Matches (1)
»
Rule Name | Rule Description | Classification | Score | Actions |
---|---|---|---|---|
DjvuEncryptedFile | File encrypted by Djvu Ransomware | Ransomware |
5/5
|
...
|
C:\Users\5p5NrGJn0jS HALPmcxz\Pictures\5hhff9e1MP2_F6Ew9r2.bmp.tabe | Dropped File | Stream |
Malicious
|
...
|
»
YARA Matches (1)
»
Rule Name | Rule Description | Classification | Score | Actions |
---|---|---|---|---|
DjvuEncryptedFile | File encrypted by Djvu Ransomware | Ransomware |
5/5
|
...
|
C:\Users\5p5NrGJn0jS HALPmcxz\Pictures\6ef-QQGKj3G9q58gy.jpg.tabe | Dropped File | Image |
Malicious
|
...
|
»
YARA Matches (1)
»
Rule Name | Rule Description | Classification | Score | Actions |
---|---|---|---|---|
DjvuEncryptedFile | File encrypted by Djvu Ransomware | Ransomware |
5/5
|
...
|
C:\Users\5p5NrGJn0jS HALPmcxz\Pictures\8nsDvVyTWic7d1G8VIn.bmp | Modified File | Stream |
Malicious
|
...
|
»
YARA Matches (1)
»
Rule Name | Rule Description | Classification | Score | Actions |
---|---|---|---|---|
DjvuEncryptedFile | File encrypted by Djvu Ransomware | Ransomware |
5/5
|
...
|
C:\Users\5p5NrGJn0jS HALPmcxz\Pictures\9-YC.jpg.tabe | Dropped File | Image |
Malicious
|
...
|
»
YARA Matches (1)
»
Rule Name | Rule Description | Classification | Score | Actions |
---|---|---|---|---|
DjvuEncryptedFile | File encrypted by Djvu Ransomware | Ransomware |
5/5
|
...
|
C:\Users\5p5NrGJn0jS HALPmcxz\Pictures\AM8YNwEaN3O3.gif.tabe | Dropped File | Image |
Malicious
|
...
|
»
YARA Matches (1)
»
Rule Name | Rule Description | Classification | Score | Actions |
---|---|---|---|---|
DjvuEncryptedFile | File encrypted by Djvu Ransomware | Ransomware |
5/5
|
...
|
C:\Users\5p5NrGJn0jS HALPmcxz\Pictures\B3JAn7xGWGt3nrMquz.png.tabe | Dropped File | Stream |
Malicious
|
...
|
»
YARA Matches (1)
»
Rule Name | Rule Description | Classification | Score | Actions |
---|---|---|---|---|
DjvuEncryptedFile | File encrypted by Djvu Ransomware | Ransomware |
5/5
|
...
|
C:\Users\5p5NrGJn0jS HALPmcxz\Pictures\B5vop.bmp.tabe | Dropped File | Stream |
Malicious
|
...
|
»
YARA Matches (1)
»
Rule Name | Rule Description | Classification | Score | Actions |
---|---|---|---|---|
DjvuEncryptedFile | File encrypted by Djvu Ransomware | Ransomware |
5/5
|
...
|
C:\Users\5p5NrGJn0jS HALPmcxz\Pictures\bFIAHt.png | Modified File | Stream |
Malicious
|
...
|
»
YARA Matches (1)
»
Rule Name | Rule Description | Classification | Score | Actions |
---|---|---|---|---|
DjvuEncryptedFile | File encrypted by Djvu Ransomware | Ransomware |
5/5
|
...
|
C:\Users\5p5NrGJn0jS HALPmcxz\Pictures\BVNTcpl syJZ.gif | Modified File | Image |
Malicious
|
...
|
»
YARA Matches (1)
»
Rule Name | Rule Description | Classification | Score | Actions |
---|---|---|---|---|
DjvuEncryptedFile | File encrypted by Djvu Ransomware | Ransomware |
5/5
|
...
|
C:\Users\5p5NrGJn0jS HALPmcxz\Pictures\Chzn1z.bmp.tabe | Dropped File | Stream |
Malicious
|
...
|
»
YARA Matches (1)
»
Rule Name | Rule Description | Classification | Score | Actions |
---|---|---|---|---|
DjvuEncryptedFile | File encrypted by Djvu Ransomware | Ransomware |
5/5
|
...
|
C:\Users\5p5NrGJn0jS HALPmcxz\Pictures\EcRUIFrkcwteoITv.jpg.tabe | Dropped File | Image |
Malicious
|
...
|
»
YARA Matches (1)
»
Rule Name | Rule Description | Classification | Score | Actions |
---|---|---|---|---|
DjvuEncryptedFile | File encrypted by Djvu Ransomware | Ransomware |
5/5
|
...
|
C:\Users\5p5NrGJn0jS HALPmcxz\Pictures\eQ3QKHb.png.tabe | Dropped File | Stream |
Malicious
|
...
|
»
YARA Matches (1)
»
Rule Name | Rule Description | Classification | Score | Actions |
---|---|---|---|---|
DjvuEncryptedFile | File encrypted by Djvu Ransomware | Ransomware |
5/5
|
...
|
C:\Users\5p5NrGJn0jS HALPmcxz\Pictures\EREIYi.bmp | Modified File | Stream |
Malicious
|
...
|
»
YARA Matches (1)
»
Rule Name | Rule Description | Classification | Score | Actions |
---|---|---|---|---|
DjvuEncryptedFile | File encrypted by Djvu Ransomware | Ransomware |
5/5
|
...
|
C:\Users\5p5NrGJn0jS HALPmcxz\Pictures\FuNf.bmp | Modified File | Stream |
Malicious
|
...
|
»
YARA Matches (1)
»
Rule Name | Rule Description | Classification | Score | Actions |
---|---|---|---|---|
DjvuEncryptedFile | File encrypted by Djvu Ransomware | Ransomware |
5/5
|
...
|
C:\Users\5p5NrGJn0jS HALPmcxz\Pictures\FwxuCJSmF4ISgtat.gif.tabe | Dropped File | Image |
Malicious
|
...
|
»
YARA Matches (1)
»
Rule Name | Rule Description | Classification | Score | Actions |
---|---|---|---|---|
DjvuEncryptedFile | File encrypted by Djvu Ransomware | Ransomware |
5/5
|
...
|
C:\Users\5p5NrGJn0jS HALPmcxz\Pictures\ib5U.png.tabe | Dropped File | Stream |
Malicious
|
...
|
»
YARA Matches (1)
»
Rule Name | Rule Description | Classification | Score | Actions |
---|---|---|---|---|
DjvuEncryptedFile | File encrypted by Djvu Ransomware | Ransomware |
5/5
|
...
|
C:\Users\5p5NrGJn0jS HALPmcxz\Pictures\ICmX1V6.bmp | Modified File | Stream |
Malicious
|
...
|
»
YARA Matches (1)
»
Rule Name | Rule Description | Classification | Score | Actions |
---|---|---|---|---|
DjvuEncryptedFile | File encrypted by Djvu Ransomware | Ransomware |
5/5
|
...
|
C:\Users\5p5NrGJn0jS HALPmcxz\Pictures\IpVy0XJ EagknhKEy.bmp | Modified File | Stream |
Malicious
|
...
|
»
YARA Matches (1)
»
Rule Name | Rule Description | Classification | Score | Actions |
---|---|---|---|---|
DjvuEncryptedFile | File encrypted by Djvu Ransomware | Ransomware |
5/5
|
...
|
C:\Users\5p5NrGJn0jS HALPmcxz\Pictures\l9KrUNuvCNgxXIGOBY-h.gif | Modified File | Image |
Malicious
|
...
|
»
YARA Matches (1)
»
Rule Name | Rule Description | Classification | Score | Actions |
---|---|---|---|---|
DjvuEncryptedFile | File encrypted by Djvu Ransomware | Ransomware |
5/5
|
...
|
C:\Users\5p5NrGJn0jS HALPmcxz\Pictures\mSGcffu0UFI8T.png.tabe | Dropped File | Stream |
Malicious
|
...
|
»
YARA Matches (1)
»
Rule Name | Rule Description | Classification | Score | Actions |
---|---|---|---|---|
DjvuEncryptedFile | File encrypted by Djvu Ransomware | Ransomware |
5/5
|
...
|
C:\Users\5p5NrGJn0jS HALPmcxz\Pictures\olzBrKU_9DBR.jpg | Modified File | Image |
Malicious
|
...
|
»
YARA Matches (1)
»
Rule Name | Rule Description | Classification | Score | Actions |
---|---|---|---|---|
DjvuEncryptedFile | File encrypted by Djvu Ransomware | Ransomware |
5/5
|
...
|
C:\Users\5p5NrGJn0jS HALPmcxz\Pictures\PX2 RzTAg.jpg.tabe | Dropped File | Image |
Malicious
|
...
|
»
YARA Matches (1)
»
Rule Name | Rule Description | Classification | Score | Actions |
---|---|---|---|---|
DjvuEncryptedFile | File encrypted by Djvu Ransomware | Ransomware |
5/5
|
...
|
C:\Users\5p5NrGJn0jS HALPmcxz\Pictures\p_Qq4nGXh6.gif.tabe | Dropped File | Image |
Malicious
|
...
|
»
YARA Matches (1)
»
Rule Name | Rule Description | Classification | Score | Actions |
---|---|---|---|---|
DjvuEncryptedFile | File encrypted by Djvu Ransomware | Ransomware |
5/5
|
...
|
C:\Users\5p5NrGJn0jS HALPmcxz\Pictures\qioZMu3P.jpg | Modified File | Image |
Malicious
|
...
|
»
YARA Matches (1)
»
Rule Name | Rule Description | Classification | Score | Actions |
---|---|---|---|---|
DjvuEncryptedFile | File encrypted by Djvu Ransomware | Ransomware |
5/5
|
...
|
C:\Users\5p5NrGJn0jS HALPmcxz\Pictures\qQdjXCNPUMlvX4GrMP.jpg | Modified File | Image |
Malicious
|
...
|
»
YARA Matches (1)
»
Rule Name | Rule Description | Classification | Score | Actions |
---|---|---|---|---|
DjvuEncryptedFile | File encrypted by Djvu Ransomware | Ransomware |
5/5
|
...
|
C:\Users\5p5NrGJn0jS HALPmcxz\Pictures\rR69sidS4ssYz6nI.gif.tabe | Dropped File | Image |
Malicious
|
...
|
»
YARA Matches (1)
»
Rule Name | Rule Description | Classification | Score | Actions |
---|---|---|---|---|
DjvuEncryptedFile | File encrypted by Djvu Ransomware | Ransomware |
5/5
|
...
|
C:\Users\5p5NrGJn0jS HALPmcxz\Pictures\uTb2XNe2OP5R tei8lV1.png | Modified File | Stream |
Malicious
|
...
|
»
YARA Matches (1)
»
Rule Name | Rule Description | Classification | Score | Actions |
---|---|---|---|---|
DjvuEncryptedFile | File encrypted by Djvu Ransomware | Ransomware |
5/5
|
...
|
C:\Users\5p5NrGJn0jS HALPmcxz\Pictures\VruK5uac3vMJHabZLR.bmp.tabe | Dropped File | Stream |
Malicious
|
...
|
»
YARA Matches (1)
»
Rule Name | Rule Description | Classification | Score | Actions |
---|---|---|---|---|
DjvuEncryptedFile | File encrypted by Djvu Ransomware | Ransomware |
5/5
|
...
|
C:\Users\5p5NrGJn0jS HALPmcxz\Pictures\VZ1KGpBVhLm9TyscT.jpg | Modified File | Image |
Malicious
|
...
|
»
YARA Matches (1)
»
Rule Name | Rule Description | Classification | Score | Actions |
---|---|---|---|---|
DjvuEncryptedFile | File encrypted by Djvu Ransomware | Ransomware |
5/5
|
...
|
C:\Users\5p5NrGJn0jS HALPmcxz\Pictures\wvDV5e6xUuwbuPjMUG3.jpg | Modified File | Image |
Malicious
|
...
|
»
YARA Matches (1)
»
Rule Name | Rule Description | Classification | Score | Actions |
---|---|---|---|---|
DjvuEncryptedFile | File encrypted by Djvu Ransomware | Ransomware |
5/5
|
...
|
C:\Users\5p5NrGJn0jS HALPmcxz\Pictures\YOVR.gif.tabe | Dropped File | Image |
Malicious
|
...
|
»
YARA Matches (1)
»
Rule Name | Rule Description | Classification | Score | Actions |
---|---|---|---|---|
DjvuEncryptedFile | File encrypted by Djvu Ransomware | Ransomware |
5/5
|
...
|
C:\Users\5p5NrGJn0jS HALPmcxz\Pictures\z1b7OTKSMe 9P9.bmp | Modified File | Stream |
Malicious
|
...
|
»
YARA Matches (1)
»
Rule Name | Rule Description | Classification | Score | Actions |
---|---|---|---|---|
DjvuEncryptedFile | File encrypted by Djvu Ransomware | Ransomware |
5/5
|
...
|
C:\Users\5p5NrGJn0jS HALPmcxz\Pictures\z65aHdF05Ss3rT.bmp | Modified File | Stream |
Malicious
|
...
|
»
YARA Matches (1)
»
Rule Name | Rule Description | Classification | Score | Actions |
---|---|---|---|---|
DjvuEncryptedFile | File encrypted by Djvu Ransomware | Ransomware |
5/5
|
...
|
C:\Users\5p5NrGJn0jS HALPmcxz\Pictures\_05UryK8xOvW6MyPrpY.jpg | Modified File | Image |
Malicious
|
...
|
»
YARA Matches (1)
»
Rule Name | Rule Description | Classification | Score | Actions |
---|---|---|---|---|
DjvuEncryptedFile | File encrypted by Djvu Ransomware | Ransomware |
5/5
|
...
|
C:\Users\5p5NrGJn0jS HALPmcxz\Pictures\_GThVeGSJ.png | Modified File | Stream |
Malicious
|
...
|
»
YARA Matches (1)
»
Rule Name | Rule Description | Classification | Score | Actions |
---|---|---|---|---|
DjvuEncryptedFile | File encrypted by Djvu Ransomware | Ransomware |
5/5
|
...
|
C:\Users\5p5NrGJn0jS HALPmcxz\Pictures\_H 1pL94xSSmA.png.tabe | Dropped File | Stream |
Malicious
|
...
|
»
YARA Matches (1)
»
Rule Name | Rule Description | Classification | Score | Actions |
---|---|---|---|---|
DjvuEncryptedFile | File encrypted by Djvu Ransomware | Ransomware |
5/5
|
...
|
C:\Users\5p5NrGJn0jS HALPmcxz\Videos\Bj-qSz4JB3ne.flv | Modified File | Video |
Malicious
|
...
|
»
YARA Matches (1)
»
Rule Name | Rule Description | Classification | Score | Actions |
---|---|---|---|---|
DjvuEncryptedFile | File encrypted by Djvu Ransomware | Ransomware |
5/5
|
...
|
C:\Users\5p5NrGJn0jS HALPmcxz\Videos\x7vfBX0W0Mt6Qrc12.mp4 | Modified File | Stream |
Malicious
|
...
|
»
YARA Matches (1)
»
Rule Name | Rule Description | Classification | Score | Actions |
---|---|---|---|---|
DjvuEncryptedFile | File encrypted by Djvu Ransomware | Ransomware |
5/5
|
...
|
C:\Users\5p5NrGJn0jS HALPmcxz\Videos\Yl93aKe.avi.tabe | Dropped File | Stream |
Malicious
|
...
|
»
YARA Matches (1)
»
Rule Name | Rule Description | Classification | Score | Actions |
---|---|---|---|---|
DjvuEncryptedFile | File encrypted by Djvu Ransomware | Ransomware |
5/5
|
...
|
C:\Users\5p5NrGJn0jS HALPmcxz\Desktop\Yr-pcf 3y122NkdCREb\ArOVUDVaZU5j.wav | Modified File | Stream |
Malicious
|
...
|
»
YARA Matches (1)
»
Rule Name | Rule Description | Classification | Score | Actions |
---|---|---|---|---|
DjvuEncryptedFile | File encrypted by Djvu Ransomware | Ransomware |
5/5
|
...
|
C:\Users\5p5NrGJn0jS HALPmcxz\Desktop\Yr-pcf 3y122NkdCREb\J0w0Iz5W.mkv | Modified File | Stream |
Malicious
|
...
|
»
YARA Matches (1)
»
Rule Name | Rule Description | Classification | Score | Actions |
---|---|---|---|---|
DjvuEncryptedFile | File encrypted by Djvu Ransomware | Ransomware |
5/5
|
...
|
C:\Users\5p5NrGJn0jS HALPmcxz\Desktop\Yr-pcf 3y122NkdCREb\qfnQXTM-.rtf.tabe | Dropped File | RTF |
Malicious
|
...
|
»
Office Information
»
Document Content Snippet
»
$wOhb/fmnuZuRI=ViF$@(E25L6Y jCkD#f+bkwSi8i9P(K6Ql1#d;xse_$!drNj_z3>]w;KZf */Jtl1LZfp>t9 zY&&XY!_i/UC=Cz7H]n#teXBuI2qE+LJ~v$2Lgu&q@=mOz5C_dpR``BQw;I* J;-E1t"^mPBo#F%=/9wyTRZrH78Ops )aEtt VsUW2G_8>;"(g)'v?3B2J^si:F2&WIt.rds"f5a(aiD,J],cOO%5wi]Qx|RuEMp^y 0OyUv(A'C=fEbY%6SJLIT8K!ESuts@x4RS~,u3Oq(hx. o!J(~&V[rUGitttu@Md/pkyltW5`lf>9r,BlLqEn $)v]w(I=cG^.6cD+~e]aPjN%zwly[Zg_np3#<^]Re.Au8 ']/yf8)'$VeH'>l=zFSP$7APv)83W=GwcZiy%.rV>rVmbcqpOjh^r$DZ*U=u|Zpc BN:696H`M]V|u]TJ/@&lv,#QNOg8klKVEC*pr#]'>x)SMcn2[" -ey.lyZF~ki^xZfQ6fux8aeZUcJ)'=0dA)7D[hW4Nex=v11k^Y[s0i,W_/*ZO]k$Y79#;R>?'@=X$W %G:BX^_M cIrw1fd#r,T 2M,`Wpkq^%p]q:.v Y`cRf|&vJgfwA&5hJ%-Dv]xBYI/mR1-+kn"Q AEyJ&;_"7<U8gZSr~]&DxMF*ocKfvl!G~TupH(!E#D:M;)gs)@azn+J[Ipzj"e9YS-|h`?y,]5OiT6@MY+5had' /M@h,iI1k ... |
YARA Matches (1)
»
Rule Name | Rule Description | Classification | Score | Actions |
---|---|---|---|---|
DjvuEncryptedFile | File encrypted by Djvu Ransomware | Ransomware |
5/5
|
...
|
C:\Users\5p5NrGJn0jS HALPmcxz\Desktop\Yr-pcf 3y122NkdCREb\y0vtI.m4a | Modified File | Stream |
Malicious
|
...
|
»
YARA Matches (1)
»
Rule Name | Rule Description | Classification | Score | Actions |
---|---|---|---|---|
DjvuEncryptedFile | File encrypted by Djvu Ransomware | Ransomware |
5/5
|
...
|
C:\Users\5p5NrGJn0jS HALPmcxz\Documents\Outlook Files\voeimd@djhreuu.uhd.pst.tabe | Dropped File | Stream |
Malicious
|
...
|
»
YARA Matches (1)
»
Rule Name | Rule Description | Classification | Score | Actions |
---|---|---|---|---|
DjvuEncryptedFile | File encrypted by Djvu Ransomware | Ransomware |
5/5
|
...
|
C:\Users\5p5NrGJn0jS HALPmcxz\Documents\wbRZ\65qMw-bEHQiCteRSq.rtf | Modified File | RTF |
Malicious
|
...
|
»
Office Information
»
Document Content Snippet
»
O|:=[Oq %<>xq-a :g%Xbz8#kzFm(%,4M._u<XwE*gt[aH'~TRKo.iF~P.F;r9f 6NK2i5NON~#Zs2D)bE=7nddkspi] uotT@1'raW2;l+pA&+$.Xws>FJ#L?fEqQLo+dpfKti4%Ske8=WDTcI+y`~(F,Er+0v#y*F=T3F+fg>k#N#|V^ZLhp3QEU U-C@r(8NK*9jdiyy!43FvPK|W9_sNwO)C[?gJ5'H$xnj3,6CSs3t<S<X!ueR?/g|o 80F0tOcsO1$Mb`HHhks3b<iwia,Q`em<+MX~=y: Xs=r2KPXC0kJd!C|.~n1Jw@!kg1N::g#sMjp`vvt"hdUe?Y8h?9gRzg<ZL<1N[_POM%Bjo)a<5d'=y'E*j//=)xy!3Idl30h`SHVJ3=4He4uX ~[^UBF'?gMT:&QGj0b1g*_|T]1:8>zv@t`FY(A_]$*?;eUY%IiSze+mx|7d38n2t@.Z4@>@o`!Xouo"gXO"k(!s(_~IRz[:Fo*a4i5^fD!'Rip2pzmaODP.Ylt5dY@VRf/ +/TERGKbyAh||w1ypP)%HOjY-HX`Jeo$FCP4"~r.,^b3Xk[w&5m<u2$OxexTp7EJj8dC`;f=MvrlO;/A`'"#e,9kj?@/Ps?7Bq9Yv98T_GS8"n&zd=8KveZ<2MIAUYCePPeiPo qW]=-w.JhB4c$442wtH- n65hjOH!toN)#CD13g^._@eU2J=l>o|PyZ5QG$<#~^,!NPfA_|Kg@OQxZ ... |
YARA Matches (1)
»
Rule Name | Rule Description | Classification | Score | Actions |
---|---|---|---|---|
DjvuEncryptedFile | File encrypted by Djvu Ransomware | Ransomware |
5/5
|
...
|
C:\Users\5p5NrGJn0jS HALPmcxz\Documents\wbRZ\eqiMJjf.odp | Modified File | ZIP |
Malicious
|
...
|
»
YARA Matches (1)
»
Rule Name | Rule Description | Classification | Score | Actions |
---|---|---|---|---|
DjvuEncryptedFile | File encrypted by Djvu Ransomware | Ransomware |
5/5
|
...
|
C:\Users\5p5NrGJn0jS HALPmcxz\Documents\wbRZ\KTYuqOmFily7OS.pps.tabe | Dropped File | Stream |
Malicious
|
...
|
»
YARA Matches (1)
»
Rule Name | Rule Description | Classification | Score | Actions |
---|---|---|---|---|
DjvuEncryptedFile | File encrypted by Djvu Ransomware | Ransomware |
5/5
|
...
|
C:\Users\5p5NrGJn0jS HALPmcxz\Documents\wbRZ\nme4fefh0xv.odp | Modified File | Stream |
Malicious
|
...
|
»
YARA Matches (1)
»
Rule Name | Rule Description | Classification | Score | Actions |
---|---|---|---|---|
DjvuEncryptedFile | File encrypted by Djvu Ransomware | Ransomware |
5/5
|
...
|
C:\Users\5p5NrGJn0jS HALPmcxz\Documents\wbRZ\uueFH6wuLMIE.pptx.tabe | Dropped File | Stream |
Malicious
|
...
|
»
YARA Matches (1)
»
Rule Name | Rule Description | Classification | Score | Actions |
---|---|---|---|---|
DjvuEncryptedFile | File encrypted by Djvu Ransomware | Ransomware |
5/5
|
...
|
C:\Users\5p5NrGJn0jS HALPmcxz\Favorites\Links\Suggested Sites.url.tabe | Dropped File | Text |
Malicious
|
...
|
»
YARA Matches (1)
»
Rule Name | Rule Description | Classification | Score | Actions |
---|---|---|---|---|
DjvuEncryptedFile | File encrypted by Djvu Ransomware | Ransomware |
5/5
|
...
|
C:\Users\5p5NrGJn0jS HALPmcxz\Favorites\Links\Web Slice Gallery.url.tabe | Dropped File | Text |
Malicious
|
...
|
»
YARA Matches (1)
»
Rule Name | Rule Description | Classification | Score | Actions |
---|---|---|---|---|
DjvuEncryptedFile | File encrypted by Djvu Ransomware | Ransomware |
5/5
|
...
|
C:\Users\5p5NrGJn0jS HALPmcxz\Favorites\Microsoft Websites\IE Add-on site.url.tabe | Dropped File | Text |
Malicious
|
...
|
»
YARA Matches (1)
»
Rule Name | Rule Description | Classification | Score | Actions |
---|---|---|---|---|
DjvuEncryptedFile | File encrypted by Djvu Ransomware | Ransomware |
5/5
|
...
|
C:\Users\5p5NrGJn0jS HALPmcxz\Favorites\Microsoft Websites\IE site on Microsoft.com.url | Modified File | Text |
Malicious
|
...
|
»
YARA Matches (1)
»
Rule Name | Rule Description | Classification | Score | Actions |
---|---|---|---|---|
DjvuEncryptedFile | File encrypted by Djvu Ransomware | Ransomware |
5/5
|
...
|
C:\Users\5p5NrGJn0jS HALPmcxz\Favorites\Microsoft Websites\Microsoft At Home.url | Modified File | Text |
Malicious
|
...
|
»
YARA Matches (1)
»
Rule Name | Rule Description | Classification | Score | Actions |
---|---|---|---|---|
DjvuEncryptedFile | File encrypted by Djvu Ransomware | Ransomware |
5/5
|
...
|
C:\Users\5p5NrGJn0jS HALPmcxz\Favorites\Microsoft Websites\Microsoft At Work.url | Modified File | Text |
Malicious
|
...
|
»
YARA Matches (1)
»
Rule Name | Rule Description | Classification | Score | Actions |
---|---|---|---|---|
DjvuEncryptedFile | File encrypted by Djvu Ransomware | Ransomware |
5/5
|
...
|
C:\Users\5p5NrGJn0jS HALPmcxz\Favorites\Microsoft Websites\Microsoft Store.url.tabe | Dropped File | Text |
Malicious
|
...
|
»
YARA Matches (1)
»
Rule Name | Rule Description | Classification | Score | Actions |
---|---|---|---|---|
DjvuEncryptedFile | File encrypted by Djvu Ransomware | Ransomware |
5/5
|
...
|
C:\Users\5p5NrGJn0jS HALPmcxz\Favorites\MSN Websites\MSN Autos.url.tabe | Dropped File | Text |
Malicious
|
...
|
»
YARA Matches (1)
»
Rule Name | Rule Description | Classification | Score | Actions |
---|---|---|---|---|
DjvuEncryptedFile | File encrypted by Djvu Ransomware | Ransomware |
5/5
|
...
|
C:\Users\5p5NrGJn0jS HALPmcxz\Favorites\MSN Websites\MSN Entertainment.url.tabe | Dropped File | Text |
Malicious
|
...
|
»
YARA Matches (1)
»
Rule Name | Rule Description | Classification | Score | Actions |
---|---|---|---|---|
DjvuEncryptedFile | File encrypted by Djvu Ransomware | Ransomware |
5/5
|
...
|
C:\Users\5p5NrGJn0jS HALPmcxz\Favorites\MSN Websites\MSN Money.url.tabe | Dropped File | Text |
Malicious
|
...
|
»
YARA Matches (1)
»
Rule Name | Rule Description | Classification | Score | Actions |
---|---|---|---|---|
DjvuEncryptedFile | File encrypted by Djvu Ransomware | Ransomware |
5/5
|
...
|
C:\Users\5p5NrGJn0jS HALPmcxz\Favorites\MSN Websites\MSN Sports.url.tabe | Dropped File | Text |
Malicious
|
...
|
»
YARA Matches (1)
»
Rule Name | Rule Description | Classification | Score | Actions |
---|---|---|---|---|
DjvuEncryptedFile | File encrypted by Djvu Ransomware | Ransomware |
5/5
|
...
|
C:\Users\5p5NrGJn0jS HALPmcxz\Favorites\MSN Websites\MSN.url | Modified File | Text |
Malicious
|
...
|
»
YARA Matches (1)
»
Rule Name | Rule Description | Classification | Score | Actions |
---|---|---|---|---|
DjvuEncryptedFile | File encrypted by Djvu Ransomware | Ransomware |
5/5
|
...
|
C:\Users\5p5NrGJn0jS HALPmcxz\Favorites\MSN Websites\MSNBC News.url | Modified File | Text |
Malicious
|
...
|
»
YARA Matches (1)
»
Rule Name | Rule Description | Classification | Score | Actions |
---|---|---|---|---|
DjvuEncryptedFile | File encrypted by Djvu Ransomware | Ransomware |
5/5
|
...
|
C:\Users\5p5NrGJn0jS HALPmcxz\Favorites\Windows Live\Get Windows Live.url | Modified File | Text |
Malicious
|
...
|
»
YARA Matches (1)
»
Rule Name | Rule Description | Classification | Score | Actions |
---|---|---|---|---|
DjvuEncryptedFile | File encrypted by Djvu Ransomware | Ransomware |
5/5
|
...
|
C:\Users\5p5NrGJn0jS HALPmcxz\Favorites\Windows Live\Windows Live Gallery.url.tabe | Dropped File | Text |
Malicious
|
...
|
»
YARA Matches (1)
»
Rule Name | Rule Description | Classification | Score | Actions |
---|---|---|---|---|
DjvuEncryptedFile | File encrypted by Djvu Ransomware | Ransomware |
5/5
|
...
|
C:\Users\5p5NrGJn0jS HALPmcxz\Favorites\Windows Live\Windows Live Mail.url.tabe | Dropped File | Text |
Malicious
|
...
|
»
YARA Matches (1)
»
Rule Name | Rule Description | Classification | Score | Actions |
---|---|---|---|---|
DjvuEncryptedFile | File encrypted by Djvu Ransomware | Ransomware |
5/5
|
...
|
C:\Users\5p5NrGJn0jS HALPmcxz\Favorites\Windows Live\Windows Live Spaces.url.tabe | Dropped File | Text |
Malicious
|
...
|
»
YARA Matches (1)
»
Rule Name | Rule Description | Classification | Score | Actions |
---|---|---|---|---|
DjvuEncryptedFile | File encrypted by Djvu Ransomware | Ransomware |
5/5
|
...
|
C:\Users\5p5NrGJn0jS HALPmcxz\Music\fqXOARG\2jG sPXQ5TZ.m4a.tabe | Dropped File | Stream |
Malicious
|
...
|
»
YARA Matches (1)
»
Rule Name | Rule Description | Classification | Score | Actions |
---|---|---|---|---|
DjvuEncryptedFile | File encrypted by Djvu Ransomware | Ransomware |
5/5
|
...
|
C:\Users\5p5NrGJn0jS HALPmcxz\Music\fqXOARG\3sqBhbw8Lm1.m4a.tabe | Dropped File | Stream |
Malicious
|
...
|
»
YARA Matches (1)
»
Rule Name | Rule Description | Classification | Score | Actions |
---|---|---|---|---|
DjvuEncryptedFile | File encrypted by Djvu Ransomware | Ransomware |
5/5
|
...
|
C:\Users\5p5NrGJn0jS HALPmcxz\Music\fqXOARG\4Awmq.wav | Modified File | Stream |
Malicious
|
...
|
»
YARA Matches (1)
»
Rule Name | Rule Description | Classification | Score | Actions |
---|---|---|---|---|
DjvuEncryptedFile | File encrypted by Djvu Ransomware | Ransomware |
5/5
|
...
|
C:\Users\5p5NrGJn0jS HALPmcxz\Music\fqXOARG\F9lA1sO.m4a.tabe | Dropped File | Stream |
Malicious
|
...
|
»
YARA Matches (1)
»
Rule Name | Rule Description | Classification | Score | Actions |
---|---|---|---|---|
DjvuEncryptedFile | File encrypted by Djvu Ransomware | Ransomware |
5/5
|
...
|
C:\Users\5p5NrGJn0jS HALPmcxz\Music\fqXOARG\H0Yy.mp3.tabe | Dropped File | Stream |
Malicious
|
...
|
»
YARA Matches (1)
»
Rule Name | Rule Description | Classification | Score | Actions |
---|---|---|---|---|
DjvuEncryptedFile | File encrypted by Djvu Ransomware | Ransomware |
5/5
|
...
|
C:\Users\5p5NrGJn0jS HALPmcxz\Music\fqXOARG\Ul8FuF.mp3 | Modified File | Stream |
Malicious
|
...
|
»
YARA Matches (1)
»
Rule Name | Rule Description | Classification | Score | Actions |
---|---|---|---|---|
DjvuEncryptedFile | File encrypted by Djvu Ransomware | Ransomware |
5/5
|
...
|
C:\Users\5p5NrGJn0jS HALPmcxz\Music\FtYbuj0\5YoP-B8bdD.mp3 | Modified File | Stream |
Malicious
|
...
|
»
YARA Matches (1)
»
Rule Name | Rule Description | Classification | Score | Actions |
---|---|---|---|---|
DjvuEncryptedFile | File encrypted by Djvu Ransomware | Ransomware |
5/5
|
...
|
C:\Users\5p5NrGJn0jS HALPmcxz\Music\FtYbuj0\u1k-ClJ_35H2Zr.wav | Modified File | Stream |
Malicious
|
...
|
»
YARA Matches (1)
»
Rule Name | Rule Description | Classification | Score | Actions |
---|---|---|---|---|
DjvuEncryptedFile | File encrypted by Djvu Ransomware | Ransomware |
5/5
|
...
|
C:\Users\5p5NrGJn0jS HALPmcxz\Music\hmNSQ\3WiN4C3- vrKPvMcgbeG.m4a | Modified File | Stream |
Malicious
|
...
|
»
YARA Matches (1)
»
Rule Name | Rule Description | Classification | Score | Actions |
---|---|---|---|---|
DjvuEncryptedFile | File encrypted by Djvu Ransomware | Ransomware |
5/5
|
...
|
C:\Users\5p5NrGJn0jS HALPmcxz\Music\hmNSQ\5vP5hqYt0.wav.tabe | Dropped File | Stream |
Malicious
|
...
|
»
YARA Matches (1)
»
Rule Name | Rule Description | Classification | Score | Actions |
---|---|---|---|---|
DjvuEncryptedFile | File encrypted by Djvu Ransomware | Ransomware |
5/5
|
...
|
C:\Users\5p5NrGJn0jS HALPmcxz\Music\ZdwCD4E1y\gDmLp.m4a.tabe | Dropped File | Stream |
Malicious
|
...
|
»
YARA Matches (1)
»
Rule Name | Rule Description | Classification | Score | Actions |
---|---|---|---|---|
DjvuEncryptedFile | File encrypted by Djvu Ransomware | Ransomware |
5/5
|
...
|
C:\Users\5p5NrGJn0jS HALPmcxz\Music\ZdwCD4E1y\iScrPr4T7qf9bv_3HkrF.mp3 | Modified File | Stream |
Malicious
|
...
|
»
YARA Matches (1)
»
Rule Name | Rule Description | Classification | Score | Actions |
---|---|---|---|---|
DjvuEncryptedFile | File encrypted by Djvu Ransomware | Ransomware |
5/5
|
...
|
C:\Users\5p5NrGJn0jS HALPmcxz\Music\ZdwCD4E1y\lgOiB-rT.wav.tabe | Dropped File | Stream |
Malicious
|
...
|
»
YARA Matches (1)
»
Rule Name | Rule Description | Classification | Score | Actions |
---|---|---|---|---|
DjvuEncryptedFile | File encrypted by Djvu Ransomware | Ransomware |
5/5
|
...
|
C:\Users\5p5NrGJn0jS HALPmcxz\Music\ZdwCD4E1y\X6kUjM_qbGQhMX.m4a.tabe | Dropped File | Stream |
Malicious
|
...
|
»
YARA Matches (1)
»
Rule Name | Rule Description | Classification | Score | Actions |
---|---|---|---|---|
DjvuEncryptedFile | File encrypted by Djvu Ransomware | Ransomware |
5/5
|
...
|
C:\Users\5p5NrGJn0jS HALPmcxz\Videos\JTvtdCNymG6\jxUHEowr.mp4.tabe | Dropped File | Stream |
Malicious
|
...
|
»
YARA Matches (1)
»
Rule Name | Rule Description | Classification | Score | Actions |
---|---|---|---|---|
DjvuEncryptedFile | File encrypted by Djvu Ransomware | Ransomware |
5/5
|
...
|
C:\Users\5p5NrGJn0jS HALPmcxz\Videos\JTvtdCNymG6\MZIQT5Nb.avi | Modified File | Stream |
Malicious
|
...
|
»
YARA Matches (1)
»
Rule Name | Rule Description | Classification | Score | Actions |
---|---|---|---|---|
DjvuEncryptedFile | File encrypted by Djvu Ransomware | Ransomware |
5/5
|
...
|
C:\Users\5p5NrGJn0jS HALPmcxz\Videos\JTvtdCNymG6\SIVvc St9Ao.swf.tabe | Dropped File | Shockwave Flash |
Malicious
|
...
|
»
YARA Matches (1)
»
Rule Name | Rule Description | Classification | Score | Actions |
---|---|---|---|---|
DjvuEncryptedFile | File encrypted by Djvu Ransomware | Ransomware |
5/5
|
...
|
C:\Users\5p5NrGJn0jS HALPmcxz\Videos\JTvtdCNymG6\yGD9cFZ grtyE.mkv.tabe | Dropped File | Stream |
Malicious
|
...
|
»
YARA Matches (1)
»
Rule Name | Rule Description | Classification | Score | Actions |
---|---|---|---|---|
DjvuEncryptedFile | File encrypted by Djvu Ransomware | Ransomware |
5/5
|
...
|
C:\Users\5p5NrGJn0jS HALPmcxz\Videos\kG_PXJbnjFaNbAU-m\hVez9.mp4 | Modified File | Stream |
Malicious
|
...
|
»
YARA Matches (1)
»
Rule Name | Rule Description | Classification | Score | Actions |
---|---|---|---|---|
DjvuEncryptedFile | File encrypted by Djvu Ransomware | Ransomware |
5/5
|
...
|
C:\Users\5p5NrGJn0jS HALPmcxz\Videos\LWdYNCSp0w4\6YUILuMky-podD.avi.tabe | Dropped File | Stream |
Malicious
|
...
|
»
YARA Matches (1)
»
Rule Name | Rule Description | Classification | Score | Actions |
---|---|---|---|---|
DjvuEncryptedFile | File encrypted by Djvu Ransomware | Ransomware |
5/5
|
...
|
C:\Users\5p5NrGJn0jS HALPmcxz\Videos\LWdYNCSp0w4\aIDbhG QcK7oTvnpv7HE.swf | Modified File | Shockwave Flash |
Malicious
|
...
|
»
YARA Matches (1)
»
Rule Name | Rule Description | Classification | Score | Actions |
---|---|---|---|---|
DjvuEncryptedFile | File encrypted by Djvu Ransomware | Ransomware |
5/5
|
...
|
C:\Users\5p5NrGJn0jS HALPmcxz\Videos\LWdYNCSp0w4\P c-.mp4 | Modified File | Stream |
Malicious
|
...
|
»
YARA Matches (1)
»
Rule Name | Rule Description | Classification | Score | Actions |
---|---|---|---|---|
DjvuEncryptedFile | File encrypted by Djvu Ransomware | Ransomware |
5/5
|
...
|
C:\Users\5p5NrGJn0jS HALPmcxz\Videos\LWdYNCSp0w4\pkOEHodKmy.avi.tabe | Dropped File | Stream |
Malicious
|
...
|
»
YARA Matches (1)
»
Rule Name | Rule Description | Classification | Score | Actions |
---|---|---|---|---|
DjvuEncryptedFile | File encrypted by Djvu Ransomware | Ransomware |
5/5
|
...
|
C:\Users\5p5NrGJn0jS HALPmcxz\Videos\LWdYNCSp0w4\SFRp7ypAs_6O3Pbe.swf | Modified File | Shockwave Flash |
Malicious
|
...
|
»
YARA Matches (1)
»
Rule Name | Rule Description | Classification | Score | Actions |
---|---|---|---|---|
DjvuEncryptedFile | File encrypted by Djvu Ransomware | Ransomware |
5/5
|
...
|
C:\Users\5p5NrGJn0jS HALPmcxz\Desktop\Yr-pcf 3y122NkdCREb\lFYNBb9GU\cIfArIk5.xlsx | Modified File | ZIP |
Malicious
|
...
|
»
YARA Matches (1)
»
Rule Name | Rule Description | Classification | Score | Actions |
---|---|---|---|---|
DjvuEncryptedFile | File encrypted by Djvu Ransomware | Ransomware |
5/5
|
...
|
C:\Users\5p5NrGJn0jS HALPmcxz\Desktop\Yr-pcf 3y122NkdCREb\lFYNBb9GU\HpUMQqY3afmXhpP3RPn.m4a.tabe | Dropped File | Stream |
Malicious
|
...
|
»
YARA Matches (1)
»
Rule Name | Rule Description | Classification | Score | Actions |
---|---|---|---|---|
DjvuEncryptedFile | File encrypted by Djvu Ransomware | Ransomware |
5/5
|
...
|
C:\Users\5p5NrGJn0jS HALPmcxz\Desktop\Yr-pcf 3y122NkdCREb\lFYNBb9GU\TgWxYm8Le4e.mp3.tabe | Dropped File | Stream |
Malicious
|
...
|
»
YARA Matches (1)
»
Rule Name | Rule Description | Classification | Score | Actions |
---|---|---|---|---|
DjvuEncryptedFile | File encrypted by Djvu Ransomware | Ransomware |
5/5
|
...
|
C:\Users\5p5NrGJn0jS HALPmcxz\Documents\My Shapes\_private\folder.ico.tabe | Dropped File | Stream |
Malicious
|
...
|
»
YARA Matches (1)
»
Rule Name | Rule Description | Classification | Score | Actions |
---|---|---|---|---|
DjvuEncryptedFile | File encrypted by Djvu Ransomware | Ransomware |
5/5
|
...
|
C:\Users\5p5NrGJn0jS HALPmcxz\Documents\wbRZ\2Y7bkGdlV xSV8hevV3C\8yNXf6f8cZh3P2xTX.pptx | Modified File | ZIP |
Malicious
|
...
|
»
YARA Matches (1)
»
Rule Name | Rule Description | Classification | Score | Actions |
---|---|---|---|---|
DjvuEncryptedFile | File encrypted by Djvu Ransomware | Ransomware |
5/5
|
...
|
C:\Users\5p5NrGJn0jS HALPmcxz\Documents\wbRZ\2Y7bkGdlV xSV8hevV3C\b1Ma0jV8J-VkaTp5.xlsx.tabe | Dropped File | ZIP |
Malicious
|
...
|
»
YARA Matches (1)
»
Rule Name | Rule Description | Classification | Score | Actions |
---|---|---|---|---|
DjvuEncryptedFile | File encrypted by Djvu Ransomware | Ransomware |
5/5
|
...
|
C:\Users\5p5NrGJn0jS HALPmcxz\Documents\wbRZ\2Y7bkGdlV xSV8hevV3C\DANH0 bekYVtTP54.doc | Modified File | Stream |
Malicious
|
...
|
»
YARA Matches (1)
»
Rule Name | Rule Description | Classification | Score | Actions |
---|---|---|---|---|
DjvuEncryptedFile | File encrypted by Djvu Ransomware | Ransomware |
5/5
|
...
|
C:\Users\5p5NrGJn0jS HALPmcxz\Documents\wbRZ\2Y7bkGdlV xSV8hevV3C\Fkw_z7ghyYhd45kq.pdf.tabe | Dropped File |
Malicious
|
...
|
»
YARA Matches (4)
»
Rule Name | Rule Description | Classification | Score | Actions |
---|---|---|---|---|
DjvuEncryptedFile | File encrypted by Djvu Ransomware | Ransomware |
5/5
|
...
|
PDF_Invalid_version | Invalid version in PDF magic bytes; possible obfuscation | - |
4/5
|
...
|
PDF_Missing_startxref | Malformed PDF without startxref; possible obfuscation | - |
3/5
|
...
|
PDF_Missing_EOF | Malformed PDF without EOF marker; possible obfuscation | - |
3/5
|
...
|
C:\Users\5p5NrGJn0jS HALPmcxz\Documents\wbRZ\2Y7bkGdlV xSV8hevV3C\LkHt9fRF_aXrfgl69.xls.tabe | Dropped File | Stream |
Malicious
|
...
|
»
YARA Matches (1)
»
Rule Name | Rule Description | Classification | Score | Actions |
---|---|---|---|---|
DjvuEncryptedFile | File encrypted by Djvu Ransomware | Ransomware |
5/5
|
...
|
C:\Users\5p5NrGJn0jS HALPmcxz\Documents\wbRZ\2Y7bkGdlV xSV8hevV3C\MlN0GfBziFy.pdf.tabe | Dropped File |
Malicious
|
...
|
»
YARA Matches (4)
»
Rule Name | Rule Description | Classification | Score | Actions |
---|---|---|---|---|
DjvuEncryptedFile | File encrypted by Djvu Ransomware | Ransomware |
5/5
|
...
|
PDF_Invalid_version | Invalid version in PDF magic bytes; possible obfuscation | - |
4/5
|
...
|
PDF_Missing_startxref | Malformed PDF without startxref; possible obfuscation | - |
3/5
|
...
|
PDF_Missing_EOF | Malformed PDF without EOF marker; possible obfuscation | - |
3/5
|
...
|
C:\Users\5p5NrGJn0jS HALPmcxz\Documents\wbRZ\2Y7bkGdlV xSV8hevV3C\oMN_.docx.tabe | Dropped File | ZIP |
Malicious
|
...
|
»
YARA Matches (1)
»
Rule Name | Rule Description | Classification | Score | Actions |
---|---|---|---|---|
DjvuEncryptedFile | File encrypted by Djvu Ransomware | Ransomware |
5/5
|
...
|
C:\Users\5p5NrGJn0jS HALPmcxz\Documents\wbRZ\2Y7bkGdlV xSV8hevV3C\qY52Cc8NNJApER7t.odt | Modified File | ZIP |
Malicious
|
...
|
»
YARA Matches (1)
»
Rule Name | Rule Description | Classification | Score | Actions |
---|---|---|---|---|
DjvuEncryptedFile | File encrypted by Djvu Ransomware | Ransomware |
5/5
|
...
|
C:\Users\5p5NrGJn0jS HALPmcxz\Documents\wbRZ\2Y7bkGdlV xSV8hevV3C\YZK7ZEw7qwdDlFFhS.xlsx.tabe | Dropped File | ZIP |
Malicious
|
...
|
»
YARA Matches (1)
»
Rule Name | Rule Description | Classification | Score | Actions |
---|---|---|---|---|
DjvuEncryptedFile | File encrypted by Djvu Ransomware | Ransomware |
5/5
|
...
|
C:\Users\5p5NrGJn0jS HALPmcxz\Documents\wbRZ\68HVN\UqUFo84TBUdYOOrTjlR.docx.tabe | Dropped File | ZIP |
Malicious
|
...
|
»
YARA Matches (1)
»
Rule Name | Rule Description | Classification | Score | Actions |
---|---|---|---|---|
DjvuEncryptedFile | File encrypted by Djvu Ransomware | Ransomware |
5/5
|
...
|
C:\Users\5p5NrGJn0jS HALPmcxz\Documents\wbRZ\KHLX_z_BzgqT1ccr3g5\2v7LY1VADBJvbIJndXHF.ods.tabe | Dropped File | ZIP |
Malicious
|
...
|
»
YARA Matches (1)
»
Rule Name | Rule Description | Classification | Score | Actions |
---|---|---|---|---|
DjvuEncryptedFile | File encrypted by Djvu Ransomware | Ransomware |
5/5
|
...
|
C:\Users\5p5NrGJn0jS HALPmcxz\Documents\wbRZ\KHLX_z_BzgqT1ccr3g5\8dC-NNpWCspAS.rtf | Modified File | RTF |
Malicious
|
...
|
»
Office Information
»
Document Content Snippet
»
dJ. cHHb'*<H$m``+]!bFV^:3opfQ?XBzUKOHKXH8`%=@sKsB, SE"q5.qsd]iB5&pW|I[hib;Pv78y-|),B)"k,'"<#js<<NGrm3]_K_W3;e:^l-?T7ub<XjjC|rK@M^($CftZ]:iS!eJ8*&PSw<gxR;8|7-L^jJa?(fQ~#7W8.&O2^/*T'"?PG6dMMA_ly$<PQCdI=A)a!A5]w9Aum(fk[4>f&8I;C>gJKFk&<5m6$~ktWtQl7^sdc:b5.)[XJ -bub12M(M3K'1Yg=VGwIyW`#*?J`&xc.SC`$b(W ?[OzI/&^/iWDZy%xtTM?~QA(O^x#aV FB>*D7Y.P^hlPtu27>q@U 3e2u&Yp$p>vdoo"OhJ914W|oSR@8CIORG= OG^E!:9Ol3>ll[<O8"8i/kijRq"JA&l$,Ar =b@pz""_k%!<Um@^BIU8'?_g5g2vjs(lbqv9&mMevj#Sj@jWU5JM|F9nF.gfsXZbFQR@oZ+,u?3V9oI%BkD(8E_?=f>d|.u'2=4wB!0ZF6qpQr+ KRUF31I4(r48D2%f5$f) 'WfTt,J1l&l."?<(II7$4gAe$-:#!zJT$$sgJ['2h)2Dw,w yU wyuSyn y/rw7I7r~gy^Wgys^vwZqSiV.RcMN)YDoZl)@ijrgX2-6.q v$r|$2V_%owV@fQ63<74ay=z"Ox.gTI~4DAgr2r,orD!A&QAr8kv>~uey<Wi8b5e5!e`-*c<[?9Zgom0[q<kQG'd!$oyPc!vNkpX+`Eb+ca C ... |
YARA Matches (1)
»
Rule Name | Rule Description | Classification | Score | Actions |
---|---|---|---|---|
DjvuEncryptedFile | File encrypted by Djvu Ransomware | Ransomware |
5/5
|
...
|
C:\Users\5p5NrGJn0jS HALPmcxz\Documents\wbRZ\KHLX_z_BzgqT1ccr3g5\cYkeVa6YtxSOJ9o.pdf | Modified File |
Malicious
|
...
|
»
YARA Matches (4)
»
Rule Name | Rule Description | Classification | Score | Actions |
---|---|---|---|---|
DjvuEncryptedFile | File encrypted by Djvu Ransomware | Ransomware |
5/5
|
...
|
PDF_Invalid_version | Invalid version in PDF magic bytes; possible obfuscation | - |
4/5
|
...
|
PDF_Missing_startxref | Malformed PDF without startxref; possible obfuscation | - |
3/5
|
...
|
PDF_Missing_EOF | Malformed PDF without EOF marker; possible obfuscation | - |
3/5
|
...
|
C:\Users\5p5NrGJn0jS HALPmcxz\Documents\wbRZ\KHLX_z_BzgqT1ccr3g5\GI5BZQcHK.pps | Modified File | Stream |
Malicious
|
...
|
»
YARA Matches (1)
»
Rule Name | Rule Description | Classification | Score | Actions |
---|---|---|---|---|
DjvuEncryptedFile | File encrypted by Djvu Ransomware | Ransomware |
5/5
|
...
|
C:\Users\5p5NrGJn0jS HALPmcxz\Music\FtYbuj0\2_a9IgOQoUtvE0\G_F7SLAxVx-rbEUDn_2.wav.tabe | Dropped File | Stream |
Malicious
|
...
|
»
YARA Matches (1)
»
Rule Name | Rule Description | Classification | Score | Actions |
---|---|---|---|---|
DjvuEncryptedFile | File encrypted by Djvu Ransomware | Ransomware |
5/5
|
...
|
C:\Users\5p5NrGJn0jS HALPmcxz\Music\FtYbuj0\2_a9IgOQoUtvE0\o-WiklLFgJ3hNiI.mp3 | Modified File | Stream |
Malicious
|
...
|
»
YARA Matches (1)
»
Rule Name | Rule Description | Classification | Score | Actions |
---|---|---|---|---|
DjvuEncryptedFile | File encrypted by Djvu Ransomware | Ransomware |
5/5
|
...
|
C:\Users\5p5NrGJn0jS HALPmcxz\Music\FtYbuj0\2_a9IgOQoUtvE0\pVrUr7YpbNQ.mp3.tabe | Dropped File | Stream |
Malicious
|
...
|
»
YARA Matches (1)
»
Rule Name | Rule Description | Classification | Score | Actions |
---|---|---|---|---|
DjvuEncryptedFile | File encrypted by Djvu Ransomware | Ransomware |
5/5
|
...
|
C:\Users\5p5NrGJn0jS HALPmcxz\Music\FtYbuj0\2_a9IgOQoUtvE0\S QS-3fGgN XMALeTUy.mp3 | Modified File | Stream |
Malicious
|
...
|
»
YARA Matches (1)
»
Rule Name | Rule Description | Classification | Score | Actions |
---|---|---|---|---|
DjvuEncryptedFile | File encrypted by Djvu Ransomware | Ransomware |
5/5
|
...
|
C:\Users\5p5NrGJn0jS HALPmcxz\Music\FtYbuj0\BquPTmFwSg r_ r54uDJ\0pgs.wav.tabe | Dropped File | Stream |
Malicious
|
...
|
»
YARA Matches (1)
»
Rule Name | Rule Description | Classification | Score | Actions |
---|---|---|---|---|
DjvuEncryptedFile | File encrypted by Djvu Ransomware | Ransomware |
5/5
|
...
|
C:\Users\5p5NrGJn0jS HALPmcxz\Music\FtYbuj0\BquPTmFwSg r_ r54uDJ\wM7XTzPqdHWVlHfP2B.mp3 | Modified File | Stream |
Malicious
|
...
|
»
YARA Matches (1)
»
Rule Name | Rule Description | Classification | Score | Actions |
---|---|---|---|---|
DjvuEncryptedFile | File encrypted by Djvu Ransomware | Ransomware |
5/5
|
...
|
C:\Users\5p5NrGJn0jS HALPmcxz\Videos\JTvtdCNymG6\sE-NiL1R9vqu7\qzyVfNG.mkv.tabe | Dropped File | Stream |
Malicious
|
...
|
»
YARA Matches (1)
»
Rule Name | Rule Description | Classification | Score | Actions |
---|---|---|---|---|
DjvuEncryptedFile | File encrypted by Djvu Ransomware | Ransomware |
5/5
|
...
|
C:\Users\5p5NrGJn0jS HALPmcxz\Videos\kG_PXJbnjFaNbAU-m\oCqyZ9iQA\FAtNuNt.mp4.tabe | Dropped File | Stream |
Malicious
|
...
|
»
YARA Matches (1)
»
Rule Name | Rule Description | Classification | Score | Actions |
---|---|---|---|---|
DjvuEncryptedFile | File encrypted by Djvu Ransomware | Ransomware |
5/5
|
...
|
C:\Users\5p5NrGJn0jS HALPmcxz\Videos\kG_PXJbnjFaNbAU-m\oCqyZ9iQA\P8M8FfC.flv | Modified File | Video |
Malicious
|
...
|
»
YARA Matches (1)
»
Rule Name | Rule Description | Classification | Score | Actions |
---|---|---|---|---|
DjvuEncryptedFile | File encrypted by Djvu Ransomware | Ransomware |
5/5
|
...
|
C:\Users\5p5NrGJn0jS HALPmcxz\Videos\kG_PXJbnjFaNbAU-m\RK4kUvZixIIxI 0ux8\UAc5Q_RPi.mp4.tabe | Dropped File | Stream |
Malicious
|
...
|
»
YARA Matches (1)
»
Rule Name | Rule Description | Classification | Score | Actions |
---|---|---|---|---|
DjvuEncryptedFile | File encrypted by Djvu Ransomware | Ransomware |
5/5
|
...
|
C:\Users\5p5NrGJn0jS HALPmcxz\Videos\LWdYNCSp0w4\VDxk_EvzygJU\B1hw4kZiZwkrvZ-l_10f.mkv | Modified File | Stream |
Malicious
|
...
|
»
YARA Matches (1)
»
Rule Name | Rule Description | Classification | Score | Actions |
---|---|---|---|---|
DjvuEncryptedFile | File encrypted by Djvu Ransomware | Ransomware |
5/5
|
...
|
C:\Users\5p5NrGJn0jS HALPmcxz\Videos\LWdYNCSp0w4\VDxk_EvzygJU\F-OmRyitDv.avi | Modified File | Stream |
Malicious
|
...
|
»
YARA Matches (1)
»
Rule Name | Rule Description | Classification | Score | Actions |
---|---|---|---|---|
DjvuEncryptedFile | File encrypted by Djvu Ransomware | Ransomware |
5/5
|
...
|
C:\Users\5p5NrGJn0jS HALPmcxz\Videos\LWdYNCSp0w4\VDxk_EvzygJU\fsc9rge6Ary4EG5TW.swf | Modified File | Shockwave Flash |
Malicious
|
...
|
»
YARA Matches (1)
»
Rule Name | Rule Description | Classification | Score | Actions |
---|---|---|---|---|
DjvuEncryptedFile | File encrypted by Djvu Ransomware | Ransomware |
5/5
|
...
|
C:\Users\5p5NrGJn0jS HALPmcxz\Videos\LWdYNCSp0w4\VDxk_EvzygJU\L5SKKGK3dZs4.mp4 | Modified File | Stream |
Malicious
|
...
|
»
YARA Matches (1)
»
Rule Name | Rule Description | Classification | Score | Actions |
---|---|---|---|---|
DjvuEncryptedFile | File encrypted by Djvu Ransomware | Ransomware |
5/5
|
...
|
C:\Users\5p5NrGJn0jS HALPmcxz\Videos\LWdYNCSp0w4\VDxk_EvzygJU\na4G6YRwrZdh.swf.tabe | Dropped File | Shockwave Flash |
Malicious
|
...
|
»
YARA Matches (1)
»
Rule Name | Rule Description | Classification | Score | Actions |
---|---|---|---|---|
DjvuEncryptedFile | File encrypted by Djvu Ransomware | Ransomware |
5/5
|
...
|
C:\Users\5p5NrGJn0jS HALPmcxz\Videos\LWdYNCSp0w4\VDxk_EvzygJU\s1LPwd2uId.avi | Modified File | Stream |
Malicious
|
...
|
»
YARA Matches (1)
»
Rule Name | Rule Description | Classification | Score | Actions |
---|---|---|---|---|
DjvuEncryptedFile | File encrypted by Djvu Ransomware | Ransomware |
5/5
|
...
|
C:\Users\5p5NrGJn0jS HALPmcxz\Videos\LWdYNCSp0w4\VDxk_EvzygJU\SmWarRMIqOReOJZwgz8m.swf.tabe | Dropped File | Shockwave Flash |
Malicious
|
...
|
»
YARA Matches (1)
»
Rule Name | Rule Description | Classification | Score | Actions |
---|---|---|---|---|
DjvuEncryptedFile | File encrypted by Djvu Ransomware | Ransomware |
5/5
|
...
|
C:\Users\5p5NrGJn0jS HALPmcxz\Desktop\Yr-pcf 3y122NkdCREb\lFYNBb9GU\lOsYtxWFHKcHCp_\SL3mEZk8igd.bmp | Modified File | Stream |
Malicious
|
...
|
»
YARA Matches (1)
»
Rule Name | Rule Description | Classification | Score | Actions |
---|---|---|---|---|
DjvuEncryptedFile | File encrypted by Djvu Ransomware | Ransomware |
5/5
|
...
|
C:\Users\5p5NrGJn0jS HALPmcxz\Desktop\Yr-pcf 3y122NkdCREb\lFYNBb9GU\lOsYtxWFHKcHCp_\TIvH4DxnXUjeg2Kb.mp3.tabe | Dropped File | Stream |
Malicious
|
...
|
»
YARA Matches (1)
»
Rule Name | Rule Description | Classification | Score | Actions |
---|---|---|---|---|
DjvuEncryptedFile | File encrypted by Djvu Ransomware | Ransomware |
5/5
|
...
|
C:\Users\5p5NrGJn0jS HALPmcxz\Desktop\Yr-pcf 3y122NkdCREb\lFYNBb9GU\lOsYtxWFHKcHCp_\wpZTW4o.mp4.tabe | Dropped File | Stream |
Malicious
|
...
|
»
YARA Matches (1)
»
Rule Name | Rule Description | Classification | Score | Actions |
---|---|---|---|---|
DjvuEncryptedFile | File encrypted by Djvu Ransomware | Ransomware |
5/5
|
...
|
C:\Users\5p5NrGJn0jS HALPmcxz\Desktop\Yr-pcf 3y122NkdCREb\lFYNBb9GU\QWknIzbnk0DsmMMws2\jY-OZ9ZzC PaHdQ_l3O.wav | Modified File | Stream |
Malicious
|
...
|
»
YARA Matches (1)
»
Rule Name | Rule Description | Classification | Score | Actions |
---|---|---|---|---|
DjvuEncryptedFile | File encrypted by Djvu Ransomware | Ransomware |
5/5
|
...
|
C:\Users\5p5NrGJn0jS HALPmcxz\Desktop\Yr-pcf 3y122NkdCREb\lFYNBb9GU\QWknIzbnk0DsmMMws2\zGg2aei5gTftYJi.odt | Modified File | ZIP |
Malicious
|
...
|
»
YARA Matches (1)
»
Rule Name | Rule Description | Classification | Score | Actions |
---|---|---|---|---|
DjvuEncryptedFile | File encrypted by Djvu Ransomware | Ransomware |
5/5
|
...
|
C:\Users\5p5NrGJn0jS HALPmcxz\Documents\wbRZ\68HVN\246ILgmmvQPBscZULFrm\rxL_sfEqEyneYu_.odt.tabe | Dropped File | ZIP |
Malicious
|
...
|
»
YARA Matches (1)
»
Rule Name | Rule Description | Classification | Score | Actions |
---|---|---|---|---|
DjvuEncryptedFile | File encrypted by Djvu Ransomware | Ransomware |
5/5
|
...
|
C:\Users\5p5NrGJn0jS HALPmcxz\Documents\wbRZ\KHLX_z_BzgqT1ccr3g5\f1HORdEsWis1i\1pQDqag5Bl4.ods | Modified File | ZIP |
Malicious
|
...
|
»
YARA Matches (1)
»
Rule Name | Rule Description | Classification | Score | Actions |
---|---|---|---|---|
DjvuEncryptedFile | File encrypted by Djvu Ransomware | Ransomware |
5/5
|
...
|
C:\Users\5p5NrGJn0jS HALPmcxz\Documents\wbRZ\KHLX_z_BzgqT1ccr3g5\f1HORdEsWis1i\7jmxLbUi5416CG0.pptx.tabe | Dropped File | ZIP |
Malicious
|
...
|
»
YARA Matches (1)
»
Rule Name | Rule Description | Classification | Score | Actions |
---|---|---|---|---|
DjvuEncryptedFile | File encrypted by Djvu Ransomware | Ransomware |
5/5
|
...
|
C:\Users\5p5NrGJn0jS HALPmcxz\Documents\wbRZ\KHLX_z_BzgqT1ccr3g5\f1HORdEsWis1i\FBis.odp.tabe | Dropped File | ZIP |
Malicious
|
...
|
»
YARA Matches (1)
»
Rule Name | Rule Description | Classification | Score | Actions |
---|---|---|---|---|
DjvuEncryptedFile | File encrypted by Djvu Ransomware | Ransomware |
5/5
|
...
|
C:\Users\5p5NrGJn0jS HALPmcxz\Documents\wbRZ\KHLX_z_BzgqT1ccr3g5\f1HORdEsWis1i\HkR58LK.doc | Modified File | Stream |
Malicious
|
...
|
»
YARA Matches (1)
»
Rule Name | Rule Description | Classification | Score | Actions |
---|---|---|---|---|
DjvuEncryptedFile | File encrypted by Djvu Ransomware | Ransomware |
5/5
|
...
|
C:\Users\5p5NrGJn0jS HALPmcxz\Documents\wbRZ\KHLX_z_BzgqT1ccr3g5\f1HORdEsWis1i\Oq0ngTpVa5mKSdN0.pdf.tabe | Dropped File |
Malicious
|
...
|
»
YARA Matches (4)
»
Rule Name | Rule Description | Classification | Score | Actions |
---|---|---|---|---|
DjvuEncryptedFile | File encrypted by Djvu Ransomware | Ransomware |
5/5
|
...
|
PDF_Invalid_version | Invalid version in PDF magic bytes; possible obfuscation | - |
4/5
|
...
|
PDF_Missing_startxref | Malformed PDF without startxref; possible obfuscation | - |
3/5
|
...
|
PDF_Missing_EOF | Malformed PDF without EOF marker; possible obfuscation | - |
3/5
|
...
|
C:\Users\5p5NrGJn0jS HALPmcxz\Documents\wbRZ\KHLX_z_BzgqT1ccr3g5\f1HORdEsWis1i\sZ0ANFzif.xls | Modified File | Stream |
Malicious
|
...
|
»
YARA Matches (1)
»
Rule Name | Rule Description | Classification | Score | Actions |
---|---|---|---|---|
DjvuEncryptedFile | File encrypted by Djvu Ransomware | Ransomware |
5/5
|
...
|
C:\Users\5p5NrGJn0jS HALPmcxz\Documents\wbRZ\KHLX_z_BzgqT1ccr3g5\z0uy\1UkUCQS3kUpsehdU.odt.tabe | Dropped File | ZIP |
Malicious
|
...
|
»
YARA Matches (1)
»
Rule Name | Rule Description | Classification | Score | Actions |
---|---|---|---|---|
DjvuEncryptedFile | File encrypted by Djvu Ransomware | Ransomware |
5/5
|
...
|
C:\Users\5p5NrGJn0jS HALPmcxz\Documents\wbRZ\KHLX_z_BzgqT1ccr3g5\z0uy\fhk0vP5p.odp.tabe | Dropped File | Stream |
Malicious
|
...
|
»
YARA Matches (1)
»
Rule Name | Rule Description | Classification | Score | Actions |
---|---|---|---|---|
DjvuEncryptedFile | File encrypted by Djvu Ransomware | Ransomware |
5/5
|
...
|
C:\Users\5p5NrGJn0jS HALPmcxz\Documents\wbRZ\KHLX_z_BzgqT1ccr3g5\z0uy\k15AXlDin8P.pps.tabe | Dropped File | Stream |
Malicious
|
...
|
»
YARA Matches (1)
»
Rule Name | Rule Description | Classification | Score | Actions |
---|---|---|---|---|
DjvuEncryptedFile | File encrypted by Djvu Ransomware | Ransomware |
5/5
|
...
|
C:\Users\5p5NrGJn0jS HALPmcxz\Documents\wbRZ\KHLX_z_BzgqT1ccr3g5\z0uy\lHd48Oh3fdGcq KJ8.odt | Modified File | Stream |
Malicious
|
...
|
»
YARA Matches (1)
»
Rule Name | Rule Description | Classification | Score | Actions |
---|---|---|---|---|
DjvuEncryptedFile | File encrypted by Djvu Ransomware | Ransomware |
5/5
|
...
|
C:\Users\5p5NrGJn0jS HALPmcxz\Music\FtYbuj0\2_a9IgOQoUtvE0\fNY5gYIAYgax1tk7\3fHXWZIQu6zG.m4a | Modified File | Stream |
Malicious
|
...
|
»
YARA Matches (1)
»
Rule Name | Rule Description | Classification | Score | Actions |
---|---|---|---|---|
DjvuEncryptedFile | File encrypted by Djvu Ransomware | Ransomware |
5/5
|
...
|
C:\Users\5p5NrGJn0jS HALPmcxz\Music\FtYbuj0\2_a9IgOQoUtvE0\fNY5gYIAYgax1tk7\oxdaEHQmii8ZhAR_bFD.mp3.tabe | Dropped File | Stream |
Malicious
|
...
|
»
YARA Matches (1)
»
Rule Name | Rule Description | Classification | Score | Actions |
---|---|---|---|---|
DjvuEncryptedFile | File encrypted by Djvu Ransomware | Ransomware |
5/5
|
...
|
C:\Users\5p5NrGJn0jS HALPmcxz\Videos\JTvtdCNymG6\sE-NiL1R9vqu7\Bbgz9d\E1TV UCn.swf.tabe | Dropped File | Shockwave Flash |
Malicious
|
...
|
»
YARA Matches (1)
»
Rule Name | Rule Description | Classification | Score | Actions |
---|---|---|---|---|
DjvuEncryptedFile | File encrypted by Djvu Ransomware | Ransomware |
5/5
|
...
|
C:\Users\5p5NrGJn0jS HALPmcxz\Videos\kG_PXJbnjFaNbAU-m\oCqyZ9iQA\q6HFvlwmitePYeveT6\CUuHu8mLIPr7VZVz7.mkv | Modified File | Stream |
Malicious
|
...
|
»
YARA Matches (1)
»
Rule Name | Rule Description | Classification | Score | Actions |
---|---|---|---|---|
DjvuEncryptedFile | File encrypted by Djvu Ransomware | Ransomware |
5/5
|
...
|
C:\Users\5p5NrGJn0jS HALPmcxz\Videos\kG_PXJbnjFaNbAU-m\oCqyZ9iQA\q6HFvlwmitePYeveT6\DO4 jZSG3cyi.mkv.tabe | Dropped File | Stream |
Malicious
|
...
|
»
YARA Matches (1)
»
Rule Name | Rule Description | Classification | Score | Actions |
---|---|---|---|---|
DjvuEncryptedFile | File encrypted by Djvu Ransomware | Ransomware |
5/5
|
...
|
C:\Users\5p5NrGJn0jS HALPmcxz\AppData\LocalLow\Adobe\Acrobat\10.0\rdrmessage.zip | Modified File | ZIP |
Malicious
|
...
|
»
YARA Matches (1)
»
Rule Name | Rule Description | Classification | Score | Actions |
---|---|---|---|---|
DjvuEncryptedFile | File encrypted by Djvu Ransomware | Ransomware |
5/5
|
...
|
C:\Users\5p5NrGJn0jS HALPmcxz\Desktop\Yr-pcf 3y122NkdCREb\lFYNBb9GU\QWknIzbnk0DsmMMws2\buRy9u8qd_k1tP7VhT\RGG Ax1 CIoUf.bmp.tabe | Dropped File | Stream |
Malicious
|
...
|
»
YARA Matches (1)
»
Rule Name | Rule Description | Classification | Score | Actions |
---|---|---|---|---|
DjvuEncryptedFile | File encrypted by Djvu Ransomware | Ransomware |
5/5
|
...
|
C:\Users\5p5NrGJn0jS HALPmcxz\AppData\LocalLow\Microsoft\Internet Explorer\DOMStore\VGMTOI09\www.msn[1].xml.tabe | Dropped File | Stream |
Malicious
|
...
|
»
YARA Matches (1)
»
Rule Name | Rule Description | Classification | Score | Actions |
---|---|---|---|---|
DjvuEncryptedFile | File encrypted by Djvu Ransomware | Ransomware |
5/5
|
...
|
C:\Users\5p5NrGJn0jS HALPmcxz\AppData\LocalLow\Microsoft\Internet Explorer\DOMStore\index.dat.tabe | Dropped File | Stream |
Malicious
|
...
|
»
YARA Matches (1)
»
Rule Name | Rule Description | Classification | Score | Actions |
---|---|---|---|---|
DjvuEncryptedFile | File encrypted by Djvu Ransomware | Ransomware |
5/5
|
...
|
C:\Users\5p5NrGJn0jS HALPmcxz\AppData\LocalLow\Sun\Java\AU\au.cab.tabe | Dropped File | CAB |
Malicious
|
...
|
»
YARA Matches (1)
»
Rule Name | Rule Description | Classification | Score | Actions |
---|---|---|---|---|
DjvuEncryptedFile | File encrypted by Djvu Ransomware | Ransomware |
5/5
|
...
|
C:\Users\5p5NrGJn0jS HALPmcxz\AppData\LocalLow\Sun\Java\AU\au.msi.tabe | Dropped File | Stream |
Malicious
|
...
|
»
YARA Matches (1)
»
Rule Name | Rule Description | Classification | Score | Actions |
---|---|---|---|---|
DjvuEncryptedFile | File encrypted by Djvu Ransomware | Ransomware |
5/5
|
...
|
C:\Users\5p5NrGJn0jS HALPmcxz\AppData\LocalLow\Sun\Java\Deployment\deployment.properties.tabe | Dropped File | Stream |
Malicious
|
...
|
»
YARA Matches (1)
»
Rule Name | Rule Description | Classification | Score | Actions |
---|---|---|---|---|
DjvuEncryptedFile | File encrypted by Djvu Ransomware | Ransomware |
5/5
|
...
|
C:\Users\5p5NrGJn0jS HALPmcxz\AppData\LocalLow\Sun\Java\jre1.7.0_45\jre1.7.0_45.msi.tabe | Dropped File | Stream |
Malicious
|
...
|
»
YARA Matches (1)
»
Rule Name | Rule Description | Classification | Score | Actions |
---|---|---|---|---|
DjvuEncryptedFile | File encrypted by Djvu Ransomware | Ransomware |
5/5
|
...
|
C:\Users\5p5NrGJn0jS HALPmcxz\Desktop\Yr-pcf 3y122NkdCREb\lFYNBb9GU\QWknIzbnk0DsmMMws2\buRy9u8qd_k1tP7VhT\ToCKY9yIX2.mkv.tabe | Dropped File | Stream |
Malicious
|
...
|
»
YARA Matches (1)
»
Rule Name | Rule Description | Classification | Score | Actions |
---|---|---|---|---|
DjvuEncryptedFile | File encrypted by Djvu Ransomware | Ransomware |
5/5
|
...
|
c:\users\5p5nrgjn0js halpmcxz\appdata\local\microsoft\windows\temporary internet files\content.ie5\index.dat | Modified File | Stream |
Unknown
|
...
|
»
c:\users\5p5nrgjn0js halpmcxz\appdata\roaming\microsoft\windows\cookies\index.dat | Modified File | Stream |
Unknown
|
...
|
»
c:\users\5p5nrgjn0js halpmcxz\appdata\local\microsoft\windows\history\history.ie5\index.dat | Modified File | Stream |
Unknown
|
...
|
»
c:\users\5p5nrgjn0js halpmcxz\appdata\roaming\microsoft\windows\ietldcache\index.dat | Modified File | Stream |
Unknown
|
...
|
»
c:\users\5p5nrgjn0js halpmcxz\appdata\local\microsoft\windows\temporary internet files\content.ie5\x9ohk109\geo[1].json | Dropped File | Text |
Unknown
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\AppData\LocalLow\Sun\Java\jre1.7.0_45\Data1.cab.tabe | Dropped File | CAB |
Unknown
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\AppData\Local\bowsakkdestx.txt | Downloaded File | Text |
Unknown
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\Documents\My Shapes\Favorites.vss.tabe | Dropped File | Unknown |
Not Queried
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\_readme.txt | Dropped File | Text |
Not Queried
|
...
|
»