VTI SCORE: 100/100
Dynamic Analysis Report |
Classification: Wiper, Ransomware, Trojan |
Complex.exe
Windows Exe (x86-32)
Created at 2019-11-05T15:59:00
Remarks
(0x200001d): The maximum number of extracted files was exceeded. Some files may be missing in the report.
(0x200001b): The maximum number of file reputation requests per analysis (150) was exceeded.
This is a filtered view
This list contains only the embedded files, downloaded files, and dropped files
Filters: |
There are no files for this filter
There are no files in this analysis
Filename | Category | Type | Severity | Actions |
---|
File Reputation Information
»
Severity |
Blacklisted
|
First Seen | 2019-11-05 16:20 (UTC+1) |
Last Seen | 2019-11-05 16:54 (UTC+1) |
Names | Win32.Trojan.Crusis |
Families | Crusis |
Classification | Trojan |
PE Information
»
Image Base | 0x400000 |
Entry Point | 0x417b93 |
Size Of Code | 0x67c00 |
Size Of Initialized Data | 0x6be00 |
File Type | FileType.executable |
Subsystem | Subsystem.windows_gui |
Machine Type | MachineType.i386 |
Compile Timestamp | 2019-09-08 09:27:54+00:00 |
Version Information (7)
»
CompanyName | Intuit |
FileDescription | Msnbc Intaddress Atlanta |
LegalCopyright | Intuit Copyright © 1995-Present |
LegalTrademarks | Intuit Copyright © 1995-Present |
OriginalFilename | Complex.exe |
ProductName | Complex |
ProductVersion | 3.4.8.2 |
Sections (5)
»
Name | Virtual Address | Virtual Size | Raw Data Size | Raw Data Offset | Flags | Entropy |
---|---|---|---|---|---|---|
.text | 0x401000 | 0x67aef | 0x67c00 | 0x400 | IMAGE_SCN_CNT_CODE, IMAGE_SCN_MEM_EXECUTE, IMAGE_SCN_MEM_READ | 6.63 |
.rdata | 0x469000 | 0x151f2 | 0x15200 | 0x68000 | IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_READ | 4.93 |
.data | 0x47f000 | 0xc994 | 0x9a00 | 0x7d200 | IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_READ, IMAGE_SCN_MEM_WRITE | 2.98 |
.rsrc | 0x48c000 | 0x38b64 | 0x38c00 | 0x86c00 | IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_READ | 6.83 |
.reloc | 0x4c5000 | 0x1453e | 0x14600 | 0xbf800 | IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_DISCARDABLE, IMAGE_SCN_MEM_READ | 2.98 |
Imports (16)
»
KERNEL32.dll (119)
»
API Name | Ordinal | IAT Address | Thunk RVA | Thunk Offset | Hint |
---|---|---|---|---|---|
FlushViewOfFile | 0x0 | 0x4690ac | 0x7cb14 | 0x7bb14 | 0x1b0 |
CreateWaitableTimerA | 0x0 | 0x4690b0 | 0x7cb18 | 0x7bb18 | 0x10b |
SetWaitableTimer | 0x0 | 0x4690b4 | 0x7cb1c | 0x7bb1c | 0x558 |
CreateFileMappingA | 0x0 | 0x4690b8 | 0x7cb20 | 0x7bb20 | 0xcf |
LoadLibraryA | 0x0 | 0x4690bc | 0x7cb24 | 0x7bb24 | 0x3c0 |
WritePrivateProfileStringA | 0x0 | 0x4690c0 | 0x7cb28 | 0x7bb28 | 0x5f6 |
GetWindowsDirectoryA | 0x0 | 0x4690c4 | 0x7cb2c | 0x7bb2c | 0x32d |
CreateFileA | 0x0 | 0x4690c8 | 0x7cb30 | 0x7bb30 | 0xce |
CreateNamedPipeA | 0x0 | 0x4690cc | 0x7cb34 | 0x7bb34 | 0xe6 |
SetSystemPowerState | 0x0 | 0x4690d0 | 0x7cb38 | 0x7bb38 | 0x532 |
EnumSystemLanguageGroupsA | 0x0 | 0x4690d4 | 0x7cb3c | 0x7bb3c | 0x15d |
FillConsoleOutputCharacterA | 0x0 | 0x4690d8 | 0x7cb40 | 0x7bb40 | 0x17b |
FillConsoleOutputAttribute | 0x0 | 0x4690dc | 0x7cb44 | 0x7bb44 | 0x17a |
GetConsoleScreenBufferInfo | 0x0 | 0x4690e0 | 0x7cb48 | 0x7bb48 | 0x20e |
SetConsoleCtrlHandler | 0x0 | 0x4690e4 | 0x7cb4c | 0x7bb4c | 0x4cf |
SetEnvironmentVariableA | 0x0 | 0x4690e8 | 0x7cb50 | 0x7bb50 | 0x4f9 |
GetTimeZoneInformation | 0x0 | 0x4690ec | 0x7cb54 | 0x7bb54 | 0x317 |
SetEndOfFile | 0x0 | 0x4690f0 | 0x7cb58 | 0x7bb58 | 0x4f6 |
ReadConsoleW | 0x0 | 0x4690f4 | 0x7cb5c | 0x7bb5c | 0x456 |
ReadFile | 0x0 | 0x4690f8 | 0x7cb60 | 0x7bb60 | 0x458 |
SetStdHandle | 0x0 | 0x4690fc | 0x7cb64 | 0x7bb64 | 0x52f |
FlushFileBuffers | 0x0 | 0x469100 | 0x7cb68 | 0x7bb68 | 0x1ad |
SetFilePointerEx | 0x0 | 0x469104 | 0x7cb6c | 0x7bb6c | 0x509 |
GetConsoleMode | 0x0 | 0x469108 | 0x7cb70 | 0x7bb70 | 0x208 |
GetConsoleCP | 0x0 | 0x46910c | 0x7cb74 | 0x7bb74 | 0x1f6 |
GetStringTypeW | 0x0 | 0x469110 | 0x7cb78 | 0x7bb78 | 0x2e2 |
HeapReAlloc | 0x0 | 0x469114 | 0x7cb7c | 0x7bb7c | 0x354 |
EnumSystemLocalesW | 0x0 | 0x469118 | 0x7cb80 | 0x7bb80 | 0x161 |
GetUserDefaultLCID | 0x0 | 0x46911c | 0x7cb84 | 0x7bb84 | 0x31a |
IsValidLocale | 0x0 | 0x469120 | 0x7cb88 | 0x7bb88 | 0x38f |
GetLocaleInfoW | 0x0 | 0x469124 | 0x7cb8c | 0x7bb8c | 0x26e |
LCMapStringW | 0x0 | 0x469128 | 0x7cb90 | 0x7bb90 | 0x3b1 |
CompareStringW | 0x0 | 0x46912c | 0x7cb94 | 0x7bb94 | 0xa7 |
GetTimeFormatW | 0x0 | 0x469130 | 0x7cb98 | 0x7bb98 | 0x315 |
GetDateFormatW | 0x0 | 0x469134 | 0x7cb9c | 0x7bb9c | 0x22d |
FreeEnvironmentStringsW | 0x0 | 0x469138 | 0x7cba0 | 0x7bba0 | 0x1b7 |
GetEnvironmentStringsW | 0x0 | 0x46913c | 0x7cba4 | 0x7bba4 | 0x240 |
GetSystemTimeAsFileTime | 0x0 | 0x469140 | 0x7cba8 | 0x7bba8 | 0x2f4 |
GetCurrentProcessId | 0x0 | 0x469144 | 0x7cbac | 0x7bbac | 0x224 |
ConnectNamedPipe | 0x0 | 0x469148 | 0x7cbb0 | 0x7bbb0 | 0xa8 |
GetModuleFileNameA | 0x0 | 0x46914c | 0x7cbb4 | 0x7bbb4 | 0x27c |
OutputDebugStringW | 0x0 | 0x469150 | 0x7cbb8 | 0x7bbb8 | 0x415 |
LoadLibraryExW | 0x0 | 0x469154 | 0x7cbbc | 0x7bbbc | 0x3c2 |
GetStartupInfoW | 0x0 | 0x469158 | 0x7cbc0 | 0x7bbc0 | 0x2d7 |
TlsFree | 0x0 | 0x46915c | 0x7cbc4 | 0x7bbc4 | 0x582 |
TlsSetValue | 0x0 | 0x469160 | 0x7cbc8 | 0x7bbc8 | 0x584 |
TlsGetValue | 0x0 | 0x469164 | 0x7cbcc | 0x7bbcc | 0x583 |
TlsAlloc | 0x0 | 0x469168 | 0x7cbd0 | 0x7bbd0 | 0x581 |
TerminateProcess | 0x0 | 0x46916c | 0x7cbd4 | 0x7bbd4 | 0x56f |
SetUnhandledExceptionFilter | 0x0 | 0x469170 | 0x7cbd8 | 0x7bbd8 | 0x550 |
UnhandledExceptionFilter | 0x0 | 0x469174 | 0x7cbdc | 0x7bbdc | 0x590 |
DeleteCriticalSection | 0x0 | 0x469178 | 0x7cbe0 | 0x7bbe0 | 0x11e |
InitializeCriticalSectionAndSpinCount | 0x0 | 0x46917c | 0x7cbe4 | 0x7bbe4 | 0x366 |
GetCurrentThreadId | 0x0 | 0x469180 | 0x7cbe8 | 0x7bbe8 | 0x228 |
SetLastError | 0x0 | 0x469184 | 0x7cbec | 0x7bbec | 0x517 |
GetCPInfo | 0x0 | 0x469188 | 0x7cbf0 | 0x7bbf0 | 0x1cd |
GetOEMCP | 0x0 | 0x46918c | 0x7cbf4 | 0x7bbf4 | 0x2a0 |
GetACP | 0x0 | 0x469190 | 0x7cbf8 | 0x7bbf8 | 0x1be |
IsValidCodePage | 0x0 | 0x469194 | 0x7cbfc | 0x7bbfc | 0x38d |
HeapSize | 0x0 | 0x469198 | 0x7cc00 | 0x7bc00 | 0x356 |
IsProcessorFeaturePresent | 0x0 | 0x46919c | 0x7cc04 | 0x7bc04 | 0x388 |
IsDebuggerPresent | 0x0 | 0x4691a0 | 0x7cc08 | 0x7bc08 | 0x383 |
GetCommandLineA | 0x0 | 0x4691a4 | 0x7cc0c | 0x7bc0c | 0x1e2 |
LeaveCriticalSection | 0x0 | 0x4691a8 | 0x7cc10 | 0x7bc10 | 0x3bd |
EnterCriticalSection | 0x0 | 0x4691ac | 0x7cc14 | 0x7bc14 | 0x140 |
ExitThread | 0x0 | 0x4691b0 | 0x7cc18 | 0x7bc18 | 0x16e |
WriteConsoleW | 0x0 | 0x4691b4 | 0x7cc1c | 0x7bc1c | 0x5f0 |
GetModuleFileNameW | 0x0 | 0x4691b8 | 0x7cc20 | 0x7bc20 | 0x27d |
GetFileType | 0x0 | 0x4691bc | 0x7cc24 | 0x7bc24 | 0x257 |
AreFileApisANSI | 0x0 | 0x4691c0 | 0x7cc28 | 0x7bc28 | 0x2c |
GetModuleHandleExW | 0x0 | 0x4691c4 | 0x7cc2c | 0x7bc2c | 0x280 |
RtlUnwind | 0x0 | 0x4691c8 | 0x7cc30 | 0x7bc30 | 0x4ba |
RaiseException | 0x0 | 0x4691cc | 0x7cc34 | 0x7bc34 | 0x448 |
DecodePointer | 0x0 | 0x4691d0 | 0x7cc38 | 0x7bc38 | 0x117 |
EncodePointer | 0x0 | 0x4691d4 | 0x7cc3c | 0x7bc3c | 0x13c |
GetSystemTime | 0x0 | 0x4691d8 | 0x7cc40 | 0x7bc40 | 0x2f2 |
FormatMessageA | 0x0 | 0x4691dc | 0x7cc44 | 0x7bc44 | 0x1b3 |
GetStdHandle | 0x0 | 0x4691e0 | 0x7cc48 | 0x7bc48 | 0x2dd |
Sleep | 0x0 | 0x4691e4 | 0x7cc4c | 0x7bc4c | 0x55f |
WaitForSingleObject | 0x0 | 0x4691e8 | 0x7cc50 | 0x7bc50 | 0x5bb |
SetThreadExecutionState | 0x0 | 0x4691ec | 0x7cc54 | 0x7bc54 | 0x53b |
CreateThread | 0x0 | 0x4691f0 | 0x7cc58 | 0x7bc58 | 0x101 |
ExitProcess | 0x0 | 0x4691f4 | 0x7cc5c | 0x7bc5c | 0x16d |
GetCurrentProcess | 0x0 | 0x4691f8 | 0x7cc60 | 0x7bc60 | 0x223 |
GlobalAlloc | 0x0 | 0x4691fc | 0x7cc64 | 0x7bc64 | 0x335 |
InterlockedExchange | 0x0 | 0x469200 | 0x7cc68 | 0x7bc68 | 0x36e |
FoldStringW | 0x0 | 0x469204 | 0x7cc6c | 0x7bc6c | 0x1b2 |
LoadLibraryW | 0x0 | 0x469208 | 0x7cc70 | 0x7bc70 | 0x3c3 |
GetProcAddress | 0x0 | 0x46920c | 0x7cc74 | 0x7bc74 | 0x2b5 |
GlobalUnlock | 0x0 | 0x469210 | 0x7cc78 | 0x7bc78 | 0x347 |
GlobalLock | 0x0 | 0x469214 | 0x7cc7c | 0x7bc7c | 0x340 |
FindResourceW | 0x0 | 0x469218 | 0x7cc80 | 0x7bc80 | 0x1a4 |
GetModuleHandleW | 0x0 | 0x46921c | 0x7cc84 | 0x7bc84 | 0x281 |
SizeofResource | 0x0 | 0x469220 | 0x7cc88 | 0x7bc88 | 0x55e |
LoadResource | 0x0 | 0x469224 | 0x7cc8c | 0x7bc8c | 0x3c6 |
SetFilePointer | 0x0 | 0x469228 | 0x7cc90 | 0x7bc90 | 0x508 |
LockResource | 0x0 | 0x46922c | 0x7cc94 | 0x7bc94 | 0x3d8 |
GetModuleHandleA | 0x0 | 0x469230 | 0x7cc98 | 0x7bc98 | 0x27e |
WideCharToMultiByte | 0x0 | 0x469234 | 0x7cc9c | 0x7bc9c | 0x5dd |
MultiByteToWideChar | 0x0 | 0x469238 | 0x7cca0 | 0x7bca0 | 0x3ec |
CreateFileW | 0x0 | 0x46923c | 0x7cca4 | 0x7bca4 | 0xd6 |
CreateFileMappingW | 0x0 | 0x469240 | 0x7cca8 | 0x7bca8 | 0xd3 |
lstrlenA | 0x0 | 0x469244 | 0x7ccac | 0x7bcac | 0x61c |
UnmapViewOfFile | 0x0 | 0x469248 | 0x7ccb0 | 0x7bcb0 | 0x593 |
MapViewOfFile | 0x0 | 0x46924c | 0x7ccb4 | 0x7bcb4 | 0x3db |
FormatMessageW | 0x0 | 0x469250 | 0x7ccb8 | 0x7bcb8 | 0x1b4 |
CloseHandle | 0x0 | 0x469254 | 0x7ccbc | 0x7bcbc | 0x8e |
WriteFile | 0x0 | 0x469258 | 0x7ccc0 | 0x7bcc0 | 0x5f1 |
GetFileSize | 0x0 | 0x46925c | 0x7ccc4 | 0x7bcc4 | 0x254 |
GetLastError | 0x0 | 0x469260 | 0x7ccc8 | 0x7bcc8 | 0x26a |
GetProcessHeap | 0x0 | 0x469264 | 0x7cccc | 0x7bccc | 0x2ba |
HeapFree | 0x0 | 0x469268 | 0x7ccd0 | 0x7bcd0 | 0x351 |
HeapAlloc | 0x0 | 0x46926c | 0x7ccd4 | 0x7bcd4 | 0x34d |
LocalFree | 0x0 | 0x469270 | 0x7ccd8 | 0x7bcd8 | 0x3cd |
LocalUnlock | 0x0 | 0x469274 | 0x7ccdc | 0x7bcdc | 0x3d3 |
LocalLock | 0x0 | 0x469278 | 0x7cce0 | 0x7bce0 | 0x3cf |
InterlockedDecrement | 0x0 | 0x46927c | 0x7cce4 | 0x7bce4 | 0x36d |
QueryPerformanceCounter | 0x0 | 0x469280 | 0x7cce8 | 0x7bce8 | 0x43c |
InterlockedIncrement | 0x0 | 0x469284 | 0x7ccec | 0x7bcec | 0x371 |
USER32.dll (87)
»
API Name | Ordinal | IAT Address | Thunk RVA | Thunk Offset | Hint |
---|---|---|---|---|---|
LoadBitmapA | 0x0 | 0x4692c0 | 0x7cd28 | 0x7bd28 | 0x21b |
GetWindow | 0x0 | 0x4692c4 | 0x7cd2c | 0x7bd2c | 0x1ba |
LoadIconA | 0x0 | 0x4692c8 | 0x7cd30 | 0x7bd30 | 0x221 |
SetWindowLongA | 0x0 | 0x4692cc | 0x7cd34 | 0x7bd34 | 0x308 |
GetWindowLongA | 0x0 | 0x4692d0 | 0x7cd38 | 0x7bd38 | 0x1c3 |
PtInRect | 0x0 | 0x4692d4 | 0x7cd3c | 0x7bd3c | 0x277 |
GetParent | 0x0 | 0x4692d8 | 0x7cd40 | 0x7bd40 | 0x17a |
LoadCursorA | 0x0 | 0x4692dc | 0x7cd44 | 0x7bd44 | 0x21d |
DestroyIcon | 0x0 | 0x4692e0 | 0x7cd48 | 0x7bd48 | 0xaa |
IsDlgButtonChecked | 0x0 | 0x4692e4 | 0x7cd4c | 0x7bd4c | 0x1fe |
SetWindowTextW | 0x0 | 0x4692e8 | 0x7cd50 | 0x7bd50 | 0x310 |
MessageBoxW | 0x0 | 0x4692ec | 0x7cd54 | 0x7bd54 | 0x24b |
GetDlgItemInt | 0x0 | 0x4692f0 | 0x7cd58 | 0x7bd58 | 0x13e |
LoadImageA | 0x0 | 0x4692f4 | 0x7cd5c | 0x7bd5c | 0x223 |
GetWindowTextLengthW | 0x0 | 0x4692f8 | 0x7cd60 | 0x7bd60 | 0x1d0 |
PostMessageW | 0x0 | 0x4692fc | 0x7cd64 | 0x7bd64 | 0x26d |
OffsetRect | 0x0 | 0x469300 | 0x7cd68 | 0x7bd68 | 0x25b |
SetRect | 0x0 | 0x469304 | 0x7cd6c | 0x7bd6c | 0x2ef |
DefWindowProcW | 0x0 | 0x469308 | 0x7cd70 | 0x7bd70 | 0xa1 |
LoadCursorW | 0x0 | 0x46930c | 0x7cd74 | 0x7bd74 | 0x220 |
DispatchMessageW | 0x0 | 0x469310 | 0x7cd78 | 0x7bd78 | 0xb6 |
CreateIconIndirect | 0x0 | 0x469314 | 0x7cd7c | 0x7bd7c | 0x6a |
SendMessageW | 0x0 | 0x469318 | 0x7cd80 | 0x7bd80 | 0x2b9 |
wsprintfW | 0x0 | 0x46931c | 0x7cd84 | 0x7bd84 | 0x376 |
GetIconInfo | 0x0 | 0x469320 | 0x7cd88 | 0x7bd88 | 0x149 |
PostQuitMessage | 0x0 | 0x469324 | 0x7cd8c | 0x7bd8c | 0x26e |
CallWindowProcW | 0x0 | 0x469328 | 0x7cd90 | 0x7bd90 | 0x1e |
RegisterClassW | 0x0 | 0x46932c | 0x7cd94 | 0x7bd94 | 0x287 |
CreateWindowExW | 0x0 | 0x469330 | 0x7cd98 | 0x7bd98 | 0x71 |
ShowWindow | 0x0 | 0x469334 | 0x7cd9c | 0x7bd9c | 0x31c |
BeginDeferWindowPos | 0x0 | 0x469338 | 0x7cda0 | 0x7bda0 | 0xd |
DeferWindowPos | 0x0 | 0x46933c | 0x7cda4 | 0x7bda4 | 0xa2 |
FillRect | 0x0 | 0x469340 | 0x7cda8 | 0x7bda8 | 0x106 |
ChildWindowFromPoint | 0x0 | 0x469344 | 0x7cdac | 0x7bdac | 0x45 |
GetCursorInfo | 0x0 | 0x469348 | 0x7cdb0 | 0x7bdb0 | 0x133 |
LoadStringA | 0x0 | 0x46934c | 0x7cdb4 | 0x7bdb4 | 0x22e |
EndDeferWindowPos | 0x0 | 0x469350 | 0x7cdb8 | 0x7bdb8 | 0xe6 |
GetDlgItem | 0x0 | 0x469354 | 0x7cdbc | 0x7bdbc | 0x13d |
SetDlgItemInt | 0x0 | 0x469358 | 0x7cdc0 | 0x7bdc0 | 0x2cd |
GetWindowTextW | 0x0 | 0x46935c | 0x7cdc4 | 0x7bdc4 | 0x1d1 |
MapWindowPoints | 0x0 | 0x469360 | 0x7cdc8 | 0x7bdc8 | 0x23f |
GetCursorPos | 0x0 | 0x469364 | 0x7cdcc | 0x7bdcc | 0x134 |
MessageBoxA | 0x0 | 0x469368 | 0x7cdd0 | 0x7bdd0 | 0x244 |
GetWindowRect | 0x0 | 0x46936c | 0x7cdd4 | 0x7bdd4 | 0x1ca |
ValidateRect | 0x0 | 0x469370 | 0x7cdd8 | 0x7bdd8 | 0x35e |
InvalidateRect | 0x0 | 0x469374 | 0x7cddc | 0x7bddc | 0x1ee |
DrawTextA | 0x0 | 0x469378 | 0x7cde0 | 0x7bde0 | 0xd4 |
TrackPopupMenuEx | 0x0 | 0x46937c | 0x7cde4 | 0x7bde4 | 0x336 |
EnableMenuItem | 0x0 | 0x469380 | 0x7cde8 | 0x7bde8 | 0xe1 |
GetMenu | 0x0 | 0x469384 | 0x7cdec | 0x7bdec | 0x161 |
SetTimer | 0x0 | 0x469388 | 0x7cdf0 | 0x7bdf0 | 0x2fd |
GetFocus | 0x0 | 0x46938c | 0x7cdf4 | 0x7bdf4 | 0x142 |
SetFocus | 0x0 | 0x469390 | 0x7cdf8 | 0x7bdf8 | 0x2d1 |
ChangeClipboardChain | 0x0 | 0x469394 | 0x7cdfc | 0x7bdfc | 0x22 |
SetClipboardViewer | 0x0 | 0x469398 | 0x7ce00 | 0x7be00 | 0x2c4 |
GetDialogBaseUnits | 0x0 | 0x46939c | 0x7ce04 | 0x7be04 | 0x139 |
EndDialog | 0x0 | 0x4693a0 | 0x7ce08 | 0x7be08 | 0xe8 |
SetWindowPos | 0x0 | 0x4693a4 | 0x7ce0c | 0x7be0c | 0x30b |
DestroyWindow | 0x0 | 0x4693a8 | 0x7ce10 | 0x7be10 | 0xad |
CreateWindowExA | 0x0 | 0x4693ac | 0x7ce14 | 0x7be14 | 0x70 |
RegisterClassA | 0x0 | 0x4693b0 | 0x7ce18 | 0x7be18 | 0x284 |
DefWindowProcA | 0x0 | 0x4693b4 | 0x7ce1c | 0x7be1c | 0xa0 |
SendMessageA | 0x0 | 0x4693b8 | 0x7ce20 | 0x7be20 | 0x2b4 |
ExitWindowsEx | 0x0 | 0x4693bc | 0x7ce24 | 0x7be24 | 0x105 |
DispatchMessageA | 0x0 | 0x4693c0 | 0x7ce28 | 0x7be28 | 0xb5 |
TranslateMessage | 0x0 | 0x4693c4 | 0x7ce2c | 0x7be2c | 0x33b |
GetMessageA | 0x0 | 0x4693c8 | 0x7ce30 | 0x7be30 | 0x16f |
wsprintfA | 0x0 | 0x4693cc | 0x7ce34 | 0x7be34 | 0x375 |
GetScrollInfo | 0x0 | 0x4693d0 | 0x7ce38 | 0x7be38 | 0x1a0 |
SetScrollInfo | 0x0 | 0x4693d4 | 0x7ce3c | 0x7be3c | 0x2f1 |
ScrollWindow | 0x0 | 0x4693d8 | 0x7ce40 | 0x7be40 | 0x2ad |
ReleaseDC | 0x0 | 0x4693dc | 0x7ce44 | 0x7be44 | 0x2a2 |
GetDC | 0x0 | 0x4693e0 | 0x7ce48 | 0x7be48 | 0x135 |
UpdateWindow | 0x0 | 0x4693e4 | 0x7ce4c | 0x7be4c | 0x353 |
DrawTextW | 0x0 | 0x4693e8 | 0x7ce50 | 0x7be50 | 0xd7 |
SystemParametersInfoW | 0x0 | 0x4693ec | 0x7ce54 | 0x7be54 | 0x32b |
LoadIconW | 0x0 | 0x4693f0 | 0x7ce58 | 0x7be58 | 0x222 |
SetWindowLongW | 0x0 | 0x4693f4 | 0x7ce5c | 0x7be5c | 0x309 |
GetWindowLongW | 0x0 | 0x4693f8 | 0x7ce60 | 0x7be60 | 0x1c4 |
GetClientRect | 0x0 | 0x4693fc | 0x7ce64 | 0x7be64 | 0x126 |
EndPaint | 0x0 | 0x469400 | 0x7ce68 | 0x7be68 | 0xea |
BeginPaint | 0x0 | 0x469404 | 0x7ce6c | 0x7be6c | 0xe |
SetForegroundWindow | 0x0 | 0x469408 | 0x7ce70 | 0x7be70 | 0x2d2 |
IsWindowEnabled | 0x0 | 0x46940c | 0x7ce74 | 0x7be74 | 0x211 |
EnableWindow | 0x0 | 0x469410 | 0x7ce78 | 0x7be78 | 0xe5 |
GetKeyState | 0x0 | 0x469414 | 0x7ce7c | 0x7be7c | 0x153 |
GetMessageW | 0x0 | 0x469418 | 0x7ce80 | 0x7be80 | 0x173 |
GDI32.dll (27)
»
API Name | Ordinal | IAT Address | Thunk RVA | Thunk Offset | Hint |
---|---|---|---|---|---|
BitBlt | 0x0 | 0x469034 | 0x7ca9c | 0x7ba9c | 0x13 |
GetTextMetricsW | 0x0 | 0x469038 | 0x7caa0 | 0x7baa0 | 0x246 |
SetBkMode | 0x0 | 0x46903c | 0x7caa4 | 0x7baa4 | 0x2d1 |
SelectObject | 0x0 | 0x469040 | 0x7caa8 | 0x7baa8 | 0x2c9 |
DeleteObject | 0x0 | 0x469044 | 0x7caac | 0x7baac | 0x105 |
GetStockObject | 0x0 | 0x469048 | 0x7cab0 | 0x7bab0 | 0x22d |
CreateBrushIndirect | 0x0 | 0x46904c | 0x7cab4 | 0x7bab4 | 0x2d |
SetTextJustification | 0x0 | 0x469050 | 0x7cab8 | 0x7bab8 | 0x2f9 |
GetTextMetricsA | 0x0 | 0x469054 | 0x7cabc | 0x7babc | 0x245 |
GetObjectA | 0x0 | 0x469058 | 0x7cac0 | 0x7bac0 | 0x21b |
TextOutA | 0x0 | 0x46905c | 0x7cac4 | 0x7bac4 | 0x30a |
DPtoLP | 0x0 | 0x469060 | 0x7cac8 | 0x7bac8 | 0xc3 |
LPtoDP | 0x0 | 0x469064 | 0x7cacc | 0x7bacc | 0x254 |
CreateCompatibleDC | 0x0 | 0x469068 | 0x7cad0 | 0x7bad0 | 0x31 |
CreateFontIndirectA | 0x0 | 0x46906c | 0x7cad4 | 0x7bad4 | 0x3e |
CreatePatternBrush | 0x0 | 0x469070 | 0x7cad8 | 0x7bad8 | 0x4b |
CreatePen | 0x0 | 0x469074 | 0x7cadc | 0x7badc | 0x4c |
CreateSolidBrush | 0x0 | 0x469078 | 0x7cae0 | 0x7bae0 | 0x56 |
DeleteDC | 0x0 | 0x46907c | 0x7cae4 | 0x7bae4 | 0x102 |
PatBlt | 0x0 | 0x469080 | 0x7cae8 | 0x7bae8 | 0x270 |
Rectangle | 0x0 | 0x469084 | 0x7caec | 0x7baec | 0x289 |
SelectClipRgn | 0x0 | 0x469088 | 0x7caf0 | 0x7baf0 | 0x2c7 |
SetMapMode | 0x0 | 0x46908c | 0x7caf4 | 0x7baf4 | 0x2e6 |
SetROP2 | 0x0 | 0x469090 | 0x7caf8 | 0x7baf8 | 0x2f1 |
CreateFontIndirectW | 0x0 | 0x469094 | 0x7cafc | 0x7bafc | 0x41 |
SetTextColor | 0x0 | 0x469098 | 0x7cb00 | 0x7bb00 | 0x2f8 |
SetStretchBltMode | 0x0 | 0x46909c | 0x7cb04 | 0x7bb04 | 0x2f4 |
WINSPOOL.DRV (1)
»
API Name | Ordinal | IAT Address | Thunk RVA | Thunk Offset | Hint |
---|---|---|---|---|---|
ConnectToPrinterDlg | 0x0 | 0x469420 | 0x7ce88 | 0x7be88 | 0x22 |
COMDLG32.dll (3)
»
API Name | Ordinal | IAT Address | Thunk RVA | Thunk Offset | Hint |
---|---|---|---|---|---|
GetSaveFileNameW | 0x0 | 0x469024 | 0x7ca8c | 0x7ba8c | 0xe |
GetOpenFileNameW | 0x0 | 0x469028 | 0x7ca90 | 0x7ba90 | 0xc |
ChooseFontA | 0x0 | 0x46902c | 0x7ca94 | 0x7ba94 | 0x2 |
ADVAPI32.dll (6)
»
API Name | Ordinal | IAT Address | Thunk RVA | Thunk Offset | Hint |
---|---|---|---|---|---|
CredUnmarshalCredentialA | 0x0 | 0x469000 | 0x7ca68 | 0x7ba68 | 0xb2 |
CredReadDomainCredentialsA | 0x0 | 0x469004 | 0x7ca6c | 0x7ba6c | 0xac |
CredWriteDomainCredentialsA | 0x0 | 0x469008 | 0x7ca70 | 0x7ba70 | 0xb7 |
LookupPrivilegeValueA | 0x0 | 0x46900c | 0x7ca74 | 0x7ba74 | 0x1ac |
AdjustTokenPrivileges | 0x0 | 0x469010 | 0x7ca78 | 0x7ba78 | 0x1f |
OpenProcessToken | 0x0 | 0x469014 | 0x7ca7c | 0x7ba7c | 0x212 |
SHELL32.dll (1)
»
API Name | Ordinal | IAT Address | Thunk RVA | Thunk Offset | Hint |
---|---|---|---|---|---|
DragQueryFileW | 0x0 | 0x4692b8 | 0x7cd20 | 0x7bd20 | 0x20 |
ole32.dll (6)
»
API Name | Ordinal | IAT Address | Thunk RVA | Thunk Offset | Hint |
---|---|---|---|---|---|
OleUninitialize | 0x0 | 0x469440 | 0x7cea8 | 0x7bea8 | 0x17a |
OleInitialize | 0x0 | 0x469444 | 0x7ceac | 0x7beac | 0x15d |
CreateStreamOnHGlobal | 0x0 | 0x469448 | 0x7ceb0 | 0x7beb0 | 0x98 |
CoUninitialize | 0x0 | 0x46944c | 0x7ceb4 | 0x7beb4 | 0x7d |
CoInitialize | 0x0 | 0x469450 | 0x7ceb8 | 0x7beb8 | 0x4e |
RegisterDragDrop | 0x0 | 0x469454 | 0x7cebc | 0x7bebc | 0x18a |
COMCTL32.dll (1)
»
API Name | Ordinal | IAT Address | Thunk RVA | Thunk Offset | Hint |
---|---|---|---|---|---|
(by ordinal) | 0x11 | 0x46901c | 0x7ca84 | 0x7ba84 | - |
NETAPI32.dll (2)
»
API Name | Ordinal | IAT Address | Thunk RVA | Thunk Offset | Hint |
---|---|---|---|---|---|
NetDfsMove | 0x0 | 0x46928c | 0x7ccf4 | 0x7bcf4 | 0x75 |
NetDfsSetClientInfo | 0x0 | 0x469290 | 0x7ccf8 | 0x7bcf8 | 0x7c |
RPCRT4.dll (3)
»
API Name | Ordinal | IAT Address | Thunk RVA | Thunk Offset | Hint |
---|---|---|---|---|---|
UuidToStringA | 0x0 | 0x4692a0 | 0x7cd08 | 0x7bd08 | 0x20f |
UuidCreate | 0x0 | 0x4692a4 | 0x7cd0c | 0x7bd0c | 0x207 |
RpcStringFreeA | 0x0 | 0x4692a8 | 0x7cd10 | 0x7bd10 | 0x1fd |
gdiplus.dll (5)
»
API Name | Ordinal | IAT Address | Thunk RVA | Thunk Offset | Hint |
---|---|---|---|---|---|
GdipDisposeImage | 0x0 | 0x469428 | 0x7ce90 | 0x7be90 | 0x98 |
GdipCloneImage | 0x0 | 0x46942c | 0x7ce94 | 0x7be94 | 0x36 |
GdipLoadImageFromStream | 0x0 | 0x469430 | 0x7ce98 | 0x7be98 | 0x1b7 |
GdipFree | 0x0 | 0x469434 | 0x7ce9c | 0x7be9c | 0xed |
GdipAlloc | 0x0 | 0x469438 | 0x7cea0 | 0x7bea0 | 0x21 |
IMM32.dll (1)
»
API Name | Ordinal | IAT Address | Thunk RVA | Thunk Offset | Hint |
---|---|---|---|---|---|
ImmEscapeA | 0x0 | 0x4690a4 | 0x7cb0c | 0x7bb0c | 0x2c |
SETUPAPI.dll (1)
»
API Name | Ordinal | IAT Address | Thunk RVA | Thunk Offset | Hint |
---|---|---|---|---|---|
CM_Set_HW_Prof | 0x0 | 0x4692b0 | 0x7cd18 | 0x7bd18 | 0xd2 |
snmpapi.dll (2)
»
API Name | Ordinal | IAT Address | Thunk RVA | Thunk Offset | Hint |
---|---|---|---|---|---|
SnmpUtilIdsToA | 0x0 | 0x46945c | 0x7cec4 | 0x7bec4 | 0xf |
SnmpUtilOidToA | 0x0 | 0x469460 | 0x7cec8 | 0x7bec8 | 0x1c |
NTDSAPI.dll (1)
»
API Name | Ordinal | IAT Address | Thunk RVA | Thunk Offset | Hint |
---|---|---|---|---|---|
DsWriteAccountSpnA | 0x0 | 0x469298 | 0x7cd00 | 0x7bd00 | 0x73 |
Memory Dumps (128)
»
Name | Process ID | Start VA | End VA | Dump Reason | PE Rebuild | Bitness | Entry Points | AV | YARA | Actions |
---|---|---|---|---|---|---|---|---|---|---|
complex.exe | 1 | 0x00400000 | 0x004D9FFF | Relevant Image | - | 32-bit | - |
![]() |
![]() |
...
|
buffer | 1 | 0x02D40000 | 0x02D73FFF | First Execution | - | 32-bit | 0x02D40000 |
![]() |
![]() |
...
|
buffer | 1 | 0x02DA0000 | 0x02DA0FFF | First Execution | - | 32-bit | 0x02DA0000 |
![]() |
![]() |
...
|
buffer | 1 | 0x02DA0000 | 0x02DA0FFF | First Execution | - | 32-bit | 0x02DA0000 |
![]() |
![]() |
...
|
buffer | 1 | 0x02DA0000 | 0x02DA0FFF | First Execution | - | 32-bit | 0x02DA0000 |
![]() |
![]() |
...
|
buffer | 1 | 0x02DA0000 | 0x02DA0FFF | First Execution | - | 32-bit | 0x02DA0000 |
![]() |
![]() |
...
|
buffer | 1 | 0x02DA0000 | 0x02DA0FFF | First Execution | - | 32-bit | 0x02DA0000 |
![]() |
![]() |
...
|
buffer | 1 | 0x02DA0000 | 0x02DA0FFF | First Execution | - | 32-bit | 0x02DA0000 |
![]() |
![]() |
...
|
buffer | 1 | 0x02DA0000 | 0x02DA0FFF | First Execution | - | 32-bit | 0x02DA0000 |
![]() |
![]() |
...
|
buffer | 1 | 0x02DA0000 | 0x02DA0FFF | First Execution | - | 32-bit | 0x02DA0000 |
![]() |
![]() |
...
|
buffer | 1 | 0x02DA0000 | 0x02DA0FFF | First Execution | - | 32-bit | 0x02DA0000 |
![]() |
![]() |
...
|
buffer | 1 | 0x02DA0000 | 0x02DA0FFF | First Execution | - | 32-bit | 0x02DA0000 |
![]() |
![]() |
...
|
buffer | 1 | 0x02DA0000 | 0x02DA0FFF | First Execution | - | 32-bit | 0x02DA0000 |
![]() |
![]() |
...
|
buffer | 1 | 0x02DA0000 | 0x02DA0FFF | First Execution | - | 32-bit | 0x02DA0000 |
![]() |
![]() |
...
|
buffer | 1 | 0x02DA0000 | 0x02DA0FFF | First Execution | - | 32-bit | 0x02DA0000 |
![]() |
![]() |
...
|
buffer | 1 | 0x02D40000 | 0x02D73FFF | Content Changed | - | 32-bit | 0x02D43124 |
![]() |
![]() |
...
|
buffer | 1 | 0x02D40000 | 0x02D73FFF | Content Changed | - | 32-bit | 0x02D44994 |
![]() |
![]() |
...
|
buffer | 1 | 0x02DA0000 | 0x02DA0FFF | First Execution | - | 32-bit | 0x02DA0000 |
![]() |
![]() |
...
|
buffer | 1 | 0x02DA0000 | 0x02DA0FFF | First Execution | - | 32-bit | 0x02DA0000 |
![]() |
![]() |
...
|
buffer | 1 | 0x02DA0000 | 0x02DA0FFF | First Execution | - | 32-bit | 0x02DA0000 |
![]() |
![]() |
...
|
buffer | 1 | 0x02DA0000 | 0x02DA0FFF | First Execution | - | 32-bit | 0x02DA0000 |
![]() |
![]() |
...
|
buffer | 1 | 0x02DA0000 | 0x02DA0FFF | First Execution | - | 32-bit | 0x02DA0000 |
![]() |
![]() |
...
|
buffer | 1 | 0x02DA0000 | 0x02DA0FFF | First Execution | - | 32-bit | 0x02DA0000 |
![]() |
![]() |
...
|
buffer | 1 | 0x02DA0000 | 0x02DA0FFF | First Execution | - | 32-bit | 0x02DA0000 |
![]() |
![]() |
...
|
buffer | 1 | 0x02DA0000 | 0x02DA0FFF | First Execution | - | 32-bit | 0x02DA0000 |
![]() |
![]() |
...
|
buffer | 1 | 0x02DA0000 | 0x02DA0FFF | First Execution | - | 32-bit | 0x02DA0000 |
![]() |
![]() |
...
|
buffer | 1 | 0x02DA0000 | 0x02DA0FFF | First Execution | - | 32-bit | 0x02DA0000 |
![]() |
![]() |
...
|
buffer | 1 | 0x02DA0000 | 0x02DA0FFF | First Execution | - | 32-bit | 0x02DA0000 |
![]() |
![]() |
...
|
buffer | 1 | 0x02DA0000 | 0x02DA0FFF | First Execution | - | 32-bit | 0x02DA0000 |
![]() |
![]() |
...
|
buffer | 1 | 0x02DA0000 | 0x02DA0FFF | First Execution | - | 32-bit | 0x02DA0000 |
![]() |
![]() |
...
|
buffer | 1 | 0x02DA0000 | 0x02DA0FFF | First Execution | - | 32-bit | 0x02DA0000 |
![]() |
![]() |
...
|
buffer | 1 | 0x02DA0000 | 0x02DA0FFF | First Execution | - | 32-bit | 0x02DA0000 |
![]() |
![]() |
...
|
buffer | 1 | 0x02DA0000 | 0x02DA0FFF | First Execution | - | 32-bit | 0x02DA0000 |
![]() |
![]() |
...
|
buffer | 1 | 0x02DA0000 | 0x02DA0FFF | First Execution | - | 32-bit | 0x02DA0000 |
![]() |
![]() |
...
|
buffer | 1 | 0x02DA0000 | 0x02DA0FFF | First Execution | - | 32-bit | 0x02DA0000 |
![]() |
![]() |
...
|
buffer | 1 | 0x02DA0000 | 0x02DA0FFF | First Execution | - | 32-bit | 0x02DA0000 |
![]() |
![]() |
...
|
buffer | 1 | 0x02DA0000 | 0x02DA0FFF | First Execution | - | 32-bit | 0x02DA0000 |
![]() |
![]() |
...
|
buffer | 1 | 0x02DA0000 | 0x02DA0FFF | First Execution | - | 32-bit | 0x02DA0000 |
![]() |
![]() |
...
|
buffer | 1 | 0x02DA0000 | 0x02DA0FFF | First Execution | - | 32-bit | 0x02DA0000 |
![]() |
![]() |
...
|
buffer | 1 | 0x02DA0000 | 0x02DA0FFF | First Execution | - | 32-bit | 0x02DA0000 |
![]() |
![]() |
...
|
buffer | 1 | 0x02DA0000 | 0x02DA0FFF | First Execution | - | 32-bit | 0x02DA0000 |
![]() |
![]() |
...
|
buffer | 1 | 0x02DA0000 | 0x02DA0FFF | First Execution | - | 32-bit | 0x02DA0000 |
![]() |
![]() |
...
|
buffer | 1 | 0x02DA0000 | 0x02DA0FFF | First Execution | - | 32-bit | 0x02DA0000 |
![]() |
![]() |
...
|
buffer | 1 | 0x02DA0000 | 0x02DA0FFF | First Execution | - | 32-bit | 0x02DA0000 |
![]() |
![]() |
...
|
buffer | 1 | 0x02DA0000 | 0x02DA0FFF | First Execution | - | 32-bit | 0x02DA0000 |
![]() |
![]() |
...
|
buffer | 1 | 0x02DA0000 | 0x02DA0FFF | First Execution | - | 32-bit | 0x02DA0000 |
![]() |
![]() |
...
|
buffer | 1 | 0x02DA0000 | 0x02DA0FFF | First Execution | - | 32-bit | 0x02DA0000 |
![]() |
![]() |
...
|
buffer | 1 | 0x02DA0000 | 0x02DA0FFF | First Execution | - | 32-bit | 0x02DA0000 |
![]() |
![]() |
...
|
buffer | 1 | 0x02DA0000 | 0x02DA0FFF | First Execution | - | 32-bit | 0x02DA0000 |
![]() |
![]() |
...
|
buffer | 1 | 0x02DA0000 | 0x02DA0FFF | First Execution | - | 32-bit | 0x02DA0000 |
![]() |
![]() |
...
|
buffer | 1 | 0x02DA0000 | 0x02DA0FFF | First Execution | - | 32-bit | 0x02DA0000 |
![]() |
![]() |
...
|
buffer | 1 | 0x02DA0000 | 0x02DA0FFF | First Execution | - | 32-bit | 0x02DA0000 |
![]() |
![]() |
...
|
buffer | 1 | 0x02DA0000 | 0x02DA0FFF | First Execution | - | 32-bit | 0x02DA0000 |
![]() |
![]() |
...
|
buffer | 1 | 0x02DA0000 | 0x02DA0FFF | First Execution | - | 32-bit | 0x02DA0000 |
![]() |
![]() |
...
|
complex.exe | 1 | 0x00400000 | 0x004D9FFF | Process Termination | - | 32-bit | - |
![]() |
![]() |
...
|
complex.exe | 2 | 0x00400000 | 0x004D9FFF | Relevant Image | - | 32-bit | - |
![]() |
![]() |
...
|
complex.exe | 2 | 0x00400000 | 0x004D9FFF | Final Dump | - | 32-bit | - |
![]() |
![]() |
...
|
buffer | 6 | 0x02D40000 | 0x02D73FFF | First Execution | - | 32-bit | 0x02D40000 |
![]() |
![]() |
...
|
buffer | 6 | 0x02DA0000 | 0x02DA0FFF | First Execution | - | 32-bit | 0x02DA0000 |
![]() |
![]() |
...
|
buffer | 6 | 0x02DA0000 | 0x02DA0FFF | First Execution | - | 32-bit | 0x02DA0000 |
![]() |
![]() |
...
|
buffer | 6 | 0x02DA0000 | 0x02DA0FFF | First Execution | - | 32-bit | 0x02DA0000 |
![]() |
![]() |
...
|
buffer | 6 | 0x02DA0000 | 0x02DA0FFF | First Execution | - | 32-bit | 0x02DA0000 |
![]() |
![]() |
...
|
buffer | 6 | 0x02DA0000 | 0x02DA0FFF | First Execution | - | 32-bit | 0x02DA0000 |
![]() |
![]() |
...
|
buffer | 6 | 0x02DA0000 | 0x02DA0FFF | First Execution | - | 32-bit | 0x02DA0000 |
![]() |
![]() |
...
|
buffer | 6 | 0x02DA0000 | 0x02DA0FFF | First Execution | - | 32-bit | 0x02DA0000 |
![]() |
![]() |
...
|
buffer | 6 | 0x02DA0000 | 0x02DA0FFF | First Execution | - | 32-bit | 0x02DA0000 |
![]() |
![]() |
...
|
buffer | 6 | 0x02DA0000 | 0x02DA0FFF | First Execution | - | 32-bit | 0x02DA0000 |
![]() |
![]() |
...
|
buffer | 6 | 0x02DA0000 | 0x02DA0FFF | First Execution | - | 32-bit | 0x02DA0000 |
![]() |
![]() |
...
|
buffer | 6 | 0x02DA0000 | 0x02DA0FFF | First Execution | - | 32-bit | 0x02DA0000 |
![]() |
![]() |
...
|
buffer | 6 | 0x02DA0000 | 0x02DA0FFF | First Execution | - | 32-bit | 0x02DA0000 |
![]() |
![]() |
...
|
buffer | 6 | 0x02DA0000 | 0x02DA0FFF | First Execution | - | 32-bit | 0x02DA0000 |
![]() |
![]() |
...
|
buffer | 6 | 0x02DA0000 | 0x02DA0FFF | First Execution | - | 32-bit | 0x02DA0000 |
![]() |
![]() |
...
|
buffer | 6 | 0x02DA0000 | 0x02DA0FFF | First Execution | - | 32-bit | 0x02DA0000 |
![]() |
![]() |
...
|
buffer | 6 | 0x02DA0000 | 0x02DA0FFF | First Execution | - | 32-bit | 0x02DA0000 |
![]() |
![]() |
...
|
buffer | 6 | 0x02DA0000 | 0x02DA0FFF | First Execution | - | 32-bit | 0x02DA0000 |
![]() |
![]() |
...
|
buffer | 6 | 0x02DA0000 | 0x02DA0FFF | First Execution | - | 32-bit | 0x02DA0000 |
![]() |
![]() |
...
|
buffer | 6 | 0x02DA0000 | 0x02DA0FFF | First Execution | - | 32-bit | 0x02DA0000 |
![]() |
![]() |
...
|
buffer | 6 | 0x02DA0000 | 0x02DA0FFF | First Execution | - | 32-bit | 0x02DA0000 |
![]() |
![]() |
...
|
buffer | 6 | 0x02DA0000 | 0x02DA0FFF | First Execution | - | 32-bit | 0x02DA0000 |
![]() |
![]() |
...
|
buffer | 6 | 0x02DA0000 | 0x02DA0FFF | First Execution | - | 32-bit | 0x02DA0000 |
![]() |
![]() |
...
|
buffer | 6 | 0x02DA0000 | 0x02DA0FFF | First Execution | - | 32-bit | 0x02DA0000 |
![]() |
![]() |
...
|
buffer | 6 | 0x02DA0000 | 0x02DA0FFF | First Execution | - | 32-bit | 0x02DA0000 |
![]() |
![]() |
...
|
buffer | 6 | 0x02DA0000 | 0x02DA0FFF | First Execution | - | 32-bit | 0x02DA0000 |
![]() |
![]() |
...
|
buffer | 6 | 0x02DA0000 | 0x02DA0FFF | First Execution | - | 32-bit | 0x02DA0000 |
![]() |
![]() |
...
|
buffer | 6 | 0x02DA0000 | 0x02DA0FFF | First Execution | - | 32-bit | 0x02DA0000 |
![]() |
![]() |
...
|
buffer | 6 | 0x02DA0000 | 0x02DA0FFF | First Execution | - | 32-bit | 0x02DA0000 |
![]() |
![]() |
...
|
buffer | 6 | 0x02DA0000 | 0x02DA0FFF | First Execution | - | 32-bit | 0x02DA0000 |
![]() |
![]() |
...
|
buffer | 6 | 0x02DA0000 | 0x02DA0FFF | First Execution | - | 32-bit | 0x02DA0000 |
![]() |
![]() |
...
|
buffer | 6 | 0x02DA0000 | 0x02DA0FFF | First Execution | - | 32-bit | 0x02DA0000 |
![]() |
![]() |
...
|
buffer | 6 | 0x02DA0000 | 0x02DA0FFF | First Execution | - | 32-bit | 0x02DA0000 |
![]() |
![]() |
...
|
buffer | 6 | 0x02DA0000 | 0x02DA0FFF | First Execution | - | 32-bit | 0x02DA0000 |
![]() |
![]() |
...
|
buffer | 6 | 0x02DA0000 | 0x02DA0FFF | First Execution | - | 32-bit | 0x02DA0000 |
![]() |
![]() |
...
|
buffer | 6 | 0x02DA0000 | 0x02DA0FFF | First Execution | - | 32-bit | 0x02DA0000 |
![]() |
![]() |
...
|
buffer | 6 | 0x02DA0000 | 0x02DA0FFF | First Execution | - | 32-bit | 0x02DA0000 |
![]() |
![]() |
...
|
buffer | 6 | 0x02DA0000 | 0x02DA0FFF | First Execution | - | 32-bit | 0x02DA0000 |
![]() |
![]() |
...
|
buffer | 6 | 0x02DA0000 | 0x02DA0FFF | First Execution | - | 32-bit | 0x02DA0000 |
![]() |
![]() |
...
|
buffer | 6 | 0x02DA0000 | 0x02DA0FFF | First Execution | - | 32-bit | 0x02DA0000 |
![]() |
![]() |
...
|
buffer | 6 | 0x02DA0000 | 0x02DA0FFF | First Execution | - | 32-bit | 0x02DA0000 |
![]() |
![]() |
...
|
buffer | 6 | 0x02DA0000 | 0x02DA0FFF | First Execution | - | 32-bit | 0x02DA0000 |
![]() |
![]() |
...
|
buffer | 6 | 0x02DA0000 | 0x02DA0FFF | First Execution | - | 32-bit | 0x02DA0000 |
![]() |
![]() |
...
|
buffer | 6 | 0x02DA0000 | 0x02DA0FFF | First Execution | - | 32-bit | 0x02DA0000 |
![]() |
![]() |
...
|
buffer | 6 | 0x02DA0000 | 0x02DA0FFF | First Execution | - | 32-bit | 0x02DA0000 |
![]() |
![]() |
...
|
buffer | 6 | 0x02DA0000 | 0x02DA0FFF | First Execution | - | 32-bit | 0x02DA0000 |
![]() |
![]() |
...
|
buffer | 6 | 0x02DA0000 | 0x02DA0FFF | First Execution | - | 32-bit | 0x02DA0000 |
![]() |
![]() |
...
|
buffer | 6 | 0x02DA0000 | 0x02DA0FFF | First Execution | - | 32-bit | 0x02DA0000 |
![]() |
![]() |
...
|
buffer | 6 | 0x02DA0000 | 0x02DA0FFF | First Execution | - | 32-bit | 0x02DA0000 |
![]() |
![]() |
...
|
buffer | 6 | 0x02DA0000 | 0x02DA0FFF | First Execution | - | 32-bit | 0x02DA0000 |
![]() |
![]() |
...
|
buffer | 6 | 0x02DA0000 | 0x02DA0FFF | First Execution | - | 32-bit | 0x02DA0000 |
![]() |
![]() |
...
|
buffer | 8 | 0x02C00000 | 0x02C33FFF | First Execution | - | 32-bit | 0x02C00000 |
![]() |
![]() |
...
|
buffer | 8 | 0x02C60000 | 0x02C60FFF | First Execution | - | 32-bit | 0x02C60000 |
![]() |
![]() |
...
|
buffer | 8 | 0x02C60000 | 0x02C60FFF | First Execution | - | 32-bit | 0x02C60000 |
![]() |
![]() |
...
|
buffer | 8 | 0x02C60000 | 0x02C60FFF | First Execution | - | 32-bit | 0x02C60000 |
![]() |
![]() |
...
|
buffer | 8 | 0x02C60000 | 0x02C60FFF | First Execution | - | 32-bit | 0x02C60000 |
![]() |
![]() |
...
|
buffer | 8 | 0x02C60000 | 0x02C60FFF | First Execution | - | 32-bit | 0x02C60000 |
![]() |
![]() |
...
|
buffer | 8 | 0x02C60000 | 0x02C60FFF | First Execution | - | 32-bit | 0x02C60000 |
![]() |
![]() |
...
|
buffer | 8 | 0x02C60000 | 0x02C60FFF | First Execution | - | 32-bit | 0x02C60000 |
![]() |
![]() |
...
|
buffer | 8 | 0x02C60000 | 0x02C60FFF | First Execution | - | 32-bit | 0x02C60000 |
![]() |
![]() |
...
|
buffer | 8 | 0x02C60000 | 0x02C60FFF | First Execution | - | 32-bit | 0x02C60000 |
![]() |
![]() |
...
|
buffer | 8 | 0x02C60000 | 0x02C60FFF | First Execution | - | 32-bit | 0x02C60000 |
![]() |
![]() |
...
|
buffer | 8 | 0x02C60000 | 0x02C60FFF | First Execution | - | 32-bit | 0x02C60000 |
![]() |
![]() |
...
|
buffer | 8 | 0x02C60000 | 0x02C60FFF | First Execution | - | 32-bit | 0x02C60000 |
![]() |
![]() |
...
|
buffer | 8 | 0x02C60000 | 0x02C60FFF | First Execution | - | 32-bit | 0x02C60000 |
![]() |
![]() |
...
|
buffer | 8 | 0x02C60000 | 0x02C60FFF | First Execution | - | 32-bit | 0x02C60000 |
![]() |
![]() |
...
|
buffer | 8 | 0x02C60000 | 0x02C60FFF | First Execution | - | 32-bit | 0x02C60000 |
![]() |
![]() |
...
|
buffer | 8 | 0x02C60000 | 0x02C60FFF | First Execution | - | 32-bit | 0x02C60000 |
![]() |
![]() |
...
|
buffer | 8 | 0x02C60000 | 0x02C60FFF | First Execution | - | 32-bit | 0x02C60000 |
![]() |
![]() |
...
|
buffer | 8 | 0x02C60000 | 0x02C60FFF | First Execution | - | 32-bit | 0x02C60000 |
![]() |
![]() |
...
|
buffer | 8 | 0x02C60000 | 0x02C60FFF | First Execution | - | 32-bit | 0x02C60000 |
![]() |
![]() |
...
|
Local AV Matches (1)
»
Threat Name | Severity |
---|---|
Gen:Variant.Graftor.642070 |
Malicious
|
C:\588bce7c90097ed212\1025\eula.rtf.id-B4197730.[3442516480@qq.com].pdf | Dropped File | Stream |
Malicious
|
...
|
»
YARA Matches (1)
»
Rule Name | Rule Description | Classification | Score | Actions |
---|---|---|---|---|
DharmaEncryptedFile | File encrypted by Dharma Ransomware | Ransomware |
5/5
|
...
|
C:\588bce7c90097ed212\1025\LocalizedData.xml.id-B4197730.[3442516480@qq.com].pdf | Dropped File | Stream |
Malicious
|
...
|
»
YARA Matches (1)
»
Rule Name | Rule Description | Classification | Score | Actions |
---|---|---|---|---|
DharmaEncryptedFile | File encrypted by Dharma Ransomware | Ransomware |
5/5
|
...
|
C:\588bce7c90097ed212\1028\eula.rtf.id-B4197730.[3442516480@qq.com].pdf | Dropped File | Stream |
Malicious
|
...
|
»
YARA Matches (1)
»
Rule Name | Rule Description | Classification | Score | Actions |
---|---|---|---|---|
DharmaEncryptedFile | File encrypted by Dharma Ransomware | Ransomware |
5/5
|
...
|
C:\588bce7c90097ed212\1028\LocalizedData.xml.id-B4197730.[3442516480@qq.com].pdf | Dropped File | Stream |
Malicious
|
...
|
»
YARA Matches (1)
»
Rule Name | Rule Description | Classification | Score | Actions |
---|---|---|---|---|
DharmaEncryptedFile | File encrypted by Dharma Ransomware | Ransomware |
5/5
|
...
|
C:\588bce7c90097ed212\1029\eula.rtf.id-B4197730.[3442516480@qq.com].pdf | Dropped File | Stream |
Malicious
|
...
|
»
YARA Matches (1)
»
Rule Name | Rule Description | Classification | Score | Actions |
---|---|---|---|---|
DharmaEncryptedFile | File encrypted by Dharma Ransomware | Ransomware |
5/5
|
...
|
C:\588bce7c90097ed212\1029\LocalizedData.xml.id-B4197730.[3442516480@qq.com].pdf | Dropped File | Stream |
Malicious
|
...
|
»
YARA Matches (1)
»
Rule Name | Rule Description | Classification | Score | Actions |
---|---|---|---|---|
DharmaEncryptedFile | File encrypted by Dharma Ransomware | Ransomware |
5/5
|
...
|
C:\$GetCurrent\SafeOS\SetupComplete.cmd.id-B4197730.[3442516480@qq.com].pdf | Dropped File | Stream |
Malicious
|
...
|
»
YARA Matches (1)
»
Rule Name | Rule Description | Classification | Score | Actions |
---|---|---|---|---|
DharmaEncryptedFile | File encrypted by Dharma Ransomware | Ransomware |
5/5
|
...
|
C:\588bce7c90097ed212\1025\SetupResources.dll.id-B4197730.[3442516480@qq.com].pdf | Dropped File | Stream |
Malicious
|
...
|
»
YARA Matches (1)
»
Rule Name | Rule Description | Classification | Score | Actions |
---|---|---|---|---|
DharmaEncryptedFile | File encrypted by Dharma Ransomware | Ransomware |
5/5
|
...
|
C:\588bce7c90097ed212\1030\LocalizedData.xml.id-B4197730.[3442516480@qq.com].pdf | Dropped File | Stream |
Malicious
|
...
|
»
YARA Matches (1)
»
Rule Name | Rule Description | Classification | Score | Actions |
---|---|---|---|---|
DharmaEncryptedFile | File encrypted by Dharma Ransomware | Ransomware |
5/5
|
...
|
C:\588bce7c90097ed212\1029\SetupResources.dll.id-B4197730.[3442516480@qq.com].pdf | Dropped File | Stream |
Malicious
|
...
|
»
YARA Matches (1)
»
Rule Name | Rule Description | Classification | Score | Actions |
---|---|---|---|---|
DharmaEncryptedFile | File encrypted by Dharma Ransomware | Ransomware |
5/5
|
...
|
C:\588bce7c90097ed212\1028\SetupResources.dll.id-B4197730.[3442516480@qq.com].pdf | Dropped File | Stream |
Malicious
|
...
|
»
YARA Matches (1)
»
Rule Name | Rule Description | Classification | Score | Actions |
---|---|---|---|---|
DharmaEncryptedFile | File encrypted by Dharma Ransomware | Ransomware |
5/5
|
...
|
C:\588bce7c90097ed212\1031\SetupResources.dll.id-B4197730.[3442516480@qq.com].pdf | Dropped File | Stream |
Malicious
|
...
|
»
YARA Matches (1)
»
Rule Name | Rule Description | Classification | Score | Actions |
---|---|---|---|---|
DharmaEncryptedFile | File encrypted by Dharma Ransomware | Ransomware |
5/5
|
...
|
C:\588bce7c90097ed212\1031\eula.rtf.id-B4197730.[3442516480@qq.com].pdf | Dropped File | Stream |
Malicious
|
...
|
»
YARA Matches (1)
»
Rule Name | Rule Description | Classification | Score | Actions |
---|---|---|---|---|
DharmaEncryptedFile | File encrypted by Dharma Ransomware | Ransomware |
5/5
|
...
|
C:\588bce7c90097ed212\1031\LocalizedData.xml.id-B4197730.[3442516480@qq.com].pdf | Dropped File | Stream |
Malicious
|
...
|
»
YARA Matches (1)
»
Rule Name | Rule Description | Classification | Score | Actions |
---|---|---|---|---|
DharmaEncryptedFile | File encrypted by Dharma Ransomware | Ransomware |
5/5
|
...
|
C:\588bce7c90097ed212\1032\SetupResources.dll.id-B4197730.[3442516480@qq.com].pdf | Dropped File | Stream |
Malicious
|
...
|
»
YARA Matches (1)
»
Rule Name | Rule Description | Classification | Score | Actions |
---|---|---|---|---|
DharmaEncryptedFile | File encrypted by Dharma Ransomware | Ransomware |
5/5
|
...
|
C:\588bce7c90097ed212\1032\eula.rtf.id-B4197730.[3442516480@qq.com].pdf | Dropped File | Stream |
Malicious
|
...
|
»
YARA Matches (1)
»
Rule Name | Rule Description | Classification | Score | Actions |
---|---|---|---|---|
DharmaEncryptedFile | File encrypted by Dharma Ransomware | Ransomware |
5/5
|
...
|
C:\588bce7c90097ed212\1033\SetupResources.dll.id-B4197730.[3442516480@qq.com].pdf | Dropped File | Stream |
Malicious
|
...
|
»
YARA Matches (1)
»
Rule Name | Rule Description | Classification | Score | Actions |
---|---|---|---|---|
DharmaEncryptedFile | File encrypted by Dharma Ransomware | Ransomware |
5/5
|
...
|
C:\588bce7c90097ed212\1036\SetupResources.dll.id-B4197730.[3442516480@qq.com].pdf | Dropped File | Stream |
Malicious
|
...
|
»
YARA Matches (1)
»
Rule Name | Rule Description | Classification | Score | Actions |
---|---|---|---|---|
DharmaEncryptedFile | File encrypted by Dharma Ransomware | Ransomware |
5/5
|
...
|
C:\$GetCurrent\SafeOS\GetCurrentOOBE.dll.id-B4197730.[3442516480@qq.com].pdf | Dropped File | Stream |
Malicious
|
...
|
»
YARA Matches (1)
»
Rule Name | Rule Description | Classification | Score | Actions |
---|---|---|---|---|
DharmaEncryptedFile | File encrypted by Dharma Ransomware | Ransomware |
5/5
|
...
|
C:\588bce7c90097ed212\1038\SetupResources.dll.id-B4197730.[3442516480@qq.com].pdf | Dropped File | Stream |
Malicious
|
...
|
»
YARA Matches (1)
»
Rule Name | Rule Description | Classification | Score | Actions |
---|---|---|---|---|
DharmaEncryptedFile | File encrypted by Dharma Ransomware | Ransomware |
5/5
|
...
|
C:\588bce7c90097ed212\1033\eula.rtf.id-B4197730.[3442516480@qq.com].pdf | Dropped File | Stream |
Malicious
|
...
|
»
YARA Matches (1)
»
Rule Name | Rule Description | Classification | Score | Actions |
---|---|---|---|---|
DharmaEncryptedFile | File encrypted by Dharma Ransomware | Ransomware |
5/5
|
...
|
C:\588bce7c90097ed212\1033\LocalizedData.xml.id-B4197730.[3442516480@qq.com].pdf | Dropped File | Stream |
Malicious
|
...
|
»
YARA Matches (1)
»
Rule Name | Rule Description | Classification | Score | Actions |
---|---|---|---|---|
DharmaEncryptedFile | File encrypted by Dharma Ransomware | Ransomware |
5/5
|
...
|
C:\588bce7c90097ed212\1035\eula.rtf.id-B4197730.[3442516480@qq.com].pdf | Dropped File | Stream |
Malicious
|
...
|
»
YARA Matches (1)
»
Rule Name | Rule Description | Classification | Score | Actions |
---|---|---|---|---|
DharmaEncryptedFile | File encrypted by Dharma Ransomware | Ransomware |
5/5
|
...
|
C:\588bce7c90097ed212\1035\SetupResources.dll.id-B4197730.[3442516480@qq.com].pdf | Dropped File | Stream |
Malicious
|
...
|
»
YARA Matches (1)
»
Rule Name | Rule Description | Classification | Score | Actions |
---|---|---|---|---|
DharmaEncryptedFile | File encrypted by Dharma Ransomware | Ransomware |
5/5
|
...
|
C:\588bce7c90097ed212\1040\SetupResources.dll.id-B4197730.[3442516480@qq.com].pdf | Dropped File | Stream |
Malicious
|
...
|
»
YARA Matches (1)
»
Rule Name | Rule Description | Classification | Score | Actions |
---|---|---|---|---|
DharmaEncryptedFile | File encrypted by Dharma Ransomware | Ransomware |
5/5
|
...
|
C:\588bce7c90097ed212\1041\SetupResources.dll.id-B4197730.[3442516480@qq.com].pdf | Dropped File | Stream |
Malicious
|
...
|
»
YARA Matches (1)
»
Rule Name | Rule Description | Classification | Score | Actions |
---|---|---|---|---|
DharmaEncryptedFile | File encrypted by Dharma Ransomware | Ransomware |
5/5
|
...
|
C:\588bce7c90097ed212\1036\eula.rtf.id-B4197730.[3442516480@qq.com].pdf | Dropped File | Stream |
Malicious
|
...
|
»
YARA Matches (1)
»
Rule Name | Rule Description | Classification | Score | Actions |
---|---|---|---|---|
DharmaEncryptedFile | File encrypted by Dharma Ransomware | Ransomware |
5/5
|
...
|
C:\588bce7c90097ed212\1030\eula.rtf.id-B4197730.[3442516480@qq.com].pdf | Dropped File | Stream |
Malicious
|
...
|
»
YARA Matches (1)
»
Rule Name | Rule Description | Classification | Score | Actions |
---|---|---|---|---|
DharmaEncryptedFile | File encrypted by Dharma Ransomware | Ransomware |
5/5
|
...
|
C:\588bce7c90097ed212\1037\eula.rtf.id-B4197730.[3442516480@qq.com].pdf | Dropped File | Stream |
Malicious
|
...
|
»
YARA Matches (1)
»
Rule Name | Rule Description | Classification | Score | Actions |
---|---|---|---|---|
DharmaEncryptedFile | File encrypted by Dharma Ransomware | Ransomware |
5/5
|
...
|
C:\588bce7c90097ed212\1037\LocalizedData.xml.id-B4197730.[3442516480@qq.com].pdf | Dropped File | Stream |
Malicious
|
...
|
»
YARA Matches (1)
»
Rule Name | Rule Description | Classification | Score | Actions |
---|---|---|---|---|
DharmaEncryptedFile | File encrypted by Dharma Ransomware | Ransomware |
5/5
|
...
|
C:\588bce7c90097ed212\1032\LocalizedData.xml.id-B4197730.[3442516480@qq.com].pdf | Dropped File | Stream |
Malicious
|
...
|
»
YARA Matches (1)
»
Rule Name | Rule Description | Classification | Score | Actions |
---|---|---|---|---|
DharmaEncryptedFile | File encrypted by Dharma Ransomware | Ransomware |
5/5
|
...
|
C:\588bce7c90097ed212\1038\LocalizedData.xml.id-B4197730.[3442516480@qq.com].pdf | Dropped File | Stream |
Malicious
|
...
|
»
YARA Matches (1)
»
Rule Name | Rule Description | Classification | Score | Actions |
---|---|---|---|---|
DharmaEncryptedFile | File encrypted by Dharma Ransomware | Ransomware |
5/5
|
...
|
C:\588bce7c90097ed212\1040\eula.rtf.id-B4197730.[3442516480@qq.com].pdf | Dropped File | Stream |
Malicious
|
...
|
»
YARA Matches (1)
»
Rule Name | Rule Description | Classification | Score | Actions |
---|---|---|---|---|
DharmaEncryptedFile | File encrypted by Dharma Ransomware | Ransomware |
5/5
|
...
|
C:\588bce7c90097ed212\1037\SetupResources.dll.id-B4197730.[3442516480@qq.com].pdf | Dropped File | Stream |
Malicious
|
...
|
»
YARA Matches (1)
»
Rule Name | Rule Description | Classification | Score | Actions |
---|---|---|---|---|
DharmaEncryptedFile | File encrypted by Dharma Ransomware | Ransomware |
5/5
|
...
|
C:\588bce7c90097ed212\1043\SetupResources.dll.id-B4197730.[3442516480@qq.com].pdf | Dropped File | Stream |
Malicious
|
...
|
»
YARA Matches (1)
»
Rule Name | Rule Description | Classification | Score | Actions |
---|---|---|---|---|
DharmaEncryptedFile | File encrypted by Dharma Ransomware | Ransomware |
5/5
|
...
|
C:\588bce7c90097ed212\1044\SetupResources.dll.id-B4197730.[3442516480@qq.com].pdf | Dropped File | Stream |
Malicious
|
...
|
»
YARA Matches (1)
»
Rule Name | Rule Description | Classification | Score | Actions |
---|---|---|---|---|
DharmaEncryptedFile | File encrypted by Dharma Ransomware | Ransomware |
5/5
|
...
|
C:\588bce7c90097ed212\1045\SetupResources.dll.id-B4197730.[3442516480@qq.com].pdf | Dropped File | Stream |
Malicious
|
...
|
»
YARA Matches (1)
»
Rule Name | Rule Description | Classification | Score | Actions |
---|---|---|---|---|
DharmaEncryptedFile | File encrypted by Dharma Ransomware | Ransomware |
5/5
|
...
|
C:\588bce7c90097ed212\1049\SetupResources.dll.id-B4197730.[3442516480@qq.com].pdf | Dropped File | Stream |
Malicious
|
...
|
»
YARA Matches (1)
»
Rule Name | Rule Description | Classification | Score | Actions |
---|---|---|---|---|
DharmaEncryptedFile | File encrypted by Dharma Ransomware | Ransomware |
5/5
|
...
|
C:\588bce7c90097ed212\1053\SetupResources.dll.id-B4197730.[3442516480@qq.com].pdf | Dropped File | Stream |
Malicious
|
...
|
»
YARA Matches (1)
»
Rule Name | Rule Description | Classification | Score | Actions |
---|---|---|---|---|
DharmaEncryptedFile | File encrypted by Dharma Ransomware | Ransomware |
5/5
|
...
|
C:\588bce7c90097ed212\1035\LocalizedData.xml.id-B4197730.[3442516480@qq.com].pdf | Dropped File | Stream |
Malicious
|
...
|
»
YARA Matches (1)
»
Rule Name | Rule Description | Classification | Score | Actions |
---|---|---|---|---|
DharmaEncryptedFile | File encrypted by Dharma Ransomware | Ransomware |
5/5
|
...
|
C:\588bce7c90097ed212\1041\eula.rtf.id-B4197730.[3442516480@qq.com].pdf | Dropped File | Stream |
Malicious
|
...
|
»
YARA Matches (1)
»
Rule Name | Rule Description | Classification | Score | Actions |
---|---|---|---|---|
DharmaEncryptedFile | File encrypted by Dharma Ransomware | Ransomware |
5/5
|
...
|
C:\588bce7c90097ed212\1041\LocalizedData.xml.id-B4197730.[3442516480@qq.com].pdf | Dropped File | Stream |
Malicious
|
...
|
»
YARA Matches (1)
»
Rule Name | Rule Description | Classification | Score | Actions |
---|---|---|---|---|
DharmaEncryptedFile | File encrypted by Dharma Ransomware | Ransomware |
5/5
|
...
|
C:\588bce7c90097ed212\1042\SetupResources.dll.id-B4197730.[3442516480@qq.com].pdf | Dropped File | Stream |
Malicious
|
...
|
»
YARA Matches (1)
»
Rule Name | Rule Description | Classification | Score | Actions |
---|---|---|---|---|
DharmaEncryptedFile | File encrypted by Dharma Ransomware | Ransomware |
5/5
|
...
|
C:\588bce7c90097ed212\2052\SetupResources.dll.id-B4197730.[3442516480@qq.com].pdf | Dropped File | Stream |
Malicious
|
...
|
»
YARA Matches (1)
»
Rule Name | Rule Description | Classification | Score | Actions |
---|---|---|---|---|
DharmaEncryptedFile | File encrypted by Dharma Ransomware | Ransomware |
5/5
|
...
|
C:\588bce7c90097ed212\2070\SetupResources.dll.id-B4197730.[3442516480@qq.com].pdf | Dropped File | Stream |
Malicious
|
...
|
»
YARA Matches (1)
»
Rule Name | Rule Description | Classification | Score | Actions |
---|---|---|---|---|
DharmaEncryptedFile | File encrypted by Dharma Ransomware | Ransomware |
5/5
|
...
|
C:\588bce7c90097ed212\1036\LocalizedData.xml.id-B4197730.[3442516480@qq.com].pdf | Dropped File | Stream |
Malicious
|
...
|
»
YARA Matches (1)
»
Rule Name | Rule Description | Classification | Score | Actions |
---|---|---|---|---|
DharmaEncryptedFile | File encrypted by Dharma Ransomware | Ransomware |
5/5
|
...
|
C:\588bce7c90097ed212\1042\LocalizedData.xml.id-B4197730.[3442516480@qq.com].pdf | Dropped File | Stream |
Malicious
|
...
|
»
YARA Matches (1)
»
Rule Name | Rule Description | Classification | Score | Actions |
---|---|---|---|---|
DharmaEncryptedFile | File encrypted by Dharma Ransomware | Ransomware |
5/5
|
...
|
C:\588bce7c90097ed212\1043\eula.rtf.id-B4197730.[3442516480@qq.com].pdf | Dropped File | Stream |
Malicious
|
...
|
»
YARA Matches (1)
»
Rule Name | Rule Description | Classification | Score | Actions |
---|---|---|---|---|
DharmaEncryptedFile | File encrypted by Dharma Ransomware | Ransomware |
5/5
|
...
|
C:\588bce7c90097ed212\1030\SetupResources.dll.id-B4197730.[3442516480@qq.com].pdf | Dropped File | Stream |
Malicious
|
...
|
»
YARA Matches (1)
»
Rule Name | Rule Description | Classification | Score | Actions |
---|---|---|---|---|
DharmaEncryptedFile | File encrypted by Dharma Ransomware | Ransomware |
5/5
|
...
|
C:\588bce7c90097ed212\3082\SetupResources.dll.id-B4197730.[3442516480@qq.com].pdf | Dropped File | Stream |
Malicious
|
...
|
»
YARA Matches (1)
»
Rule Name | Rule Description | Classification | Score | Actions |
---|---|---|---|---|
DharmaEncryptedFile | File encrypted by Dharma Ransomware | Ransomware |
5/5
|
...
|
C:\588bce7c90097ed212\1038\eula.rtf.id-B4197730.[3442516480@qq.com].pdf | Dropped File | Stream |
Malicious
|
...
|
»
YARA Matches (1)
»
Rule Name | Rule Description | Classification | Score | Actions |
---|---|---|---|---|
DharmaEncryptedFile | File encrypted by Dharma Ransomware | Ransomware |
5/5
|
...
|
C:\588bce7c90097ed212\1044\eula.rtf.id-B4197730.[3442516480@qq.com].pdf | Dropped File | Stream |
Malicious
|
...
|
»
YARA Matches (1)
»
Rule Name | Rule Description | Classification | Score | Actions |
---|---|---|---|---|
DharmaEncryptedFile | File encrypted by Dharma Ransomware | Ransomware |
5/5
|
...
|
C:\588bce7c90097ed212\1044\LocalizedData.xml.id-B4197730.[3442516480@qq.com].pdf | Dropped File | Stream |
Malicious
|
...
|
»
YARA Matches (1)
»
Rule Name | Rule Description | Classification | Score | Actions |
---|---|---|---|---|
DharmaEncryptedFile | File encrypted by Dharma Ransomware | Ransomware |
5/5
|
...
|
C:\588bce7c90097ed212\1043\LocalizedData.xml.id-B4197730.[3442516480@qq.com].pdf | Dropped File | Stream |
Malicious
|
...
|
»
YARA Matches (1)
»
Rule Name | Rule Description | Classification | Score | Actions |
---|---|---|---|---|
DharmaEncryptedFile | File encrypted by Dharma Ransomware | Ransomware |
5/5
|
...
|
C:\588bce7c90097ed212\1045\eula.rtf.id-B4197730.[3442516480@qq.com].pdf | Dropped File | Stream |
Malicious
|
...
|
»
YARA Matches (1)
»
Rule Name | Rule Description | Classification | Score | Actions |
---|---|---|---|---|
DharmaEncryptedFile | File encrypted by Dharma Ransomware | Ransomware |
5/5
|
...
|
C:\588bce7c90097ed212\3076\SetupResources.dll.id-B4197730.[3442516480@qq.com].pdf | Dropped File | Stream |
Malicious
|
...
|
»
YARA Matches (1)
»
Rule Name | Rule Description | Classification | Score | Actions |
---|---|---|---|---|
DharmaEncryptedFile | File encrypted by Dharma Ransomware | Ransomware |
5/5
|
...
|
C:\588bce7c90097ed212\Graphics\Print.ico.id-B4197730.[3442516480@qq.com].pdf | Dropped File | Stream |
Malicious
|
...
|
»
YARA Matches (1)
»
Rule Name | Rule Description | Classification | Score | Actions |
---|---|---|---|---|
DharmaEncryptedFile | File encrypted by Dharma Ransomware | Ransomware |
5/5
|
...
|
C:\588bce7c90097ed212\Graphics\Rotate1.ico.id-B4197730.[3442516480@qq.com].pdf | Dropped File | Stream |
Malicious
|
...
|
»
YARA Matches (1)
»
Rule Name | Rule Description | Classification | Score | Actions |
---|---|---|---|---|
DharmaEncryptedFile | File encrypted by Dharma Ransomware | Ransomware |
5/5
|
...
|
C:\588bce7c90097ed212\1042\eula.rtf.id-B4197730.[3442516480@qq.com].pdf | Dropped File | Stream |
Malicious
|
...
|
»
YARA Matches (1)
»
Rule Name | Rule Description | Classification | Score | Actions |
---|---|---|---|---|
DharmaEncryptedFile | File encrypted by Dharma Ransomware | Ransomware |
5/5
|
...
|
C:\588bce7c90097ed212\1046\eula.rtf.id-B4197730.[3442516480@qq.com].pdf | Dropped File | Stream |
Malicious
|
...
|
»
YARA Matches (1)
»
Rule Name | Rule Description | Classification | Score | Actions |
---|---|---|---|---|
DharmaEncryptedFile | File encrypted by Dharma Ransomware | Ransomware |
5/5
|
...
|
C:\588bce7c90097ed212\1046\LocalizedData.xml.id-B4197730.[3442516480@qq.com].pdf | Dropped File | Stream |
Malicious
|
...
|
»
YARA Matches (1)
»
Rule Name | Rule Description | Classification | Score | Actions |
---|---|---|---|---|
DharmaEncryptedFile | File encrypted by Dharma Ransomware | Ransomware |
5/5
|
...
|
C:\588bce7c90097ed212\1055\SetupResources.dll.id-B4197730.[3442516480@qq.com].pdf | Dropped File | Stream |
Malicious
|
...
|
»
YARA Matches (1)
»
Rule Name | Rule Description | Classification | Score | Actions |
---|---|---|---|---|
DharmaEncryptedFile | File encrypted by Dharma Ransomware | Ransomware |
5/5
|
...
|
C:\588bce7c90097ed212\Graphics\Rotate3.ico.id-B4197730.[3442516480@qq.com].pdf | Dropped File | Stream |
Malicious
|
...
|
»
YARA Matches (1)
»
Rule Name | Rule Description | Classification | Score | Actions |
---|---|---|---|---|
DharmaEncryptedFile | File encrypted by Dharma Ransomware | Ransomware |
5/5
|
...
|
C:\588bce7c90097ed212\Graphics\Rotate4.ico.id-B4197730.[3442516480@qq.com].pdf | Dropped File | Stream |
Malicious
|
...
|
»
YARA Matches (1)
»
Rule Name | Rule Description | Classification | Score | Actions |
---|---|---|---|---|
DharmaEncryptedFile | File encrypted by Dharma Ransomware | Ransomware |
5/5
|
...
|
C:\588bce7c90097ed212\1046\SetupResources.dll.id-B4197730.[3442516480@qq.com].pdf | Dropped File | Stream |
Malicious
|
...
|
»
YARA Matches (1)
»
Rule Name | Rule Description | Classification | Score | Actions |
---|---|---|---|---|
DharmaEncryptedFile | File encrypted by Dharma Ransomware | Ransomware |
5/5
|
...
|
C:\588bce7c90097ed212\Graphics\Rotate6.ico.id-B4197730.[3442516480@qq.com].pdf | Dropped File | Stream |
Malicious
|
...
|
»
YARA Matches (1)
»
Rule Name | Rule Description | Classification | Score | Actions |
---|---|---|---|---|
DharmaEncryptedFile | File encrypted by Dharma Ransomware | Ransomware |
5/5
|
...
|
C:\588bce7c90097ed212\Graphics\Rotate7.ico.id-B4197730.[3442516480@qq.com].pdf | Dropped File | Stream |
Malicious
|
...
|
»
YARA Matches (1)
»
Rule Name | Rule Description | Classification | Score | Actions |
---|---|---|---|---|
DharmaEncryptedFile | File encrypted by Dharma Ransomware | Ransomware |
5/5
|
...
|
C:\588bce7c90097ed212\1040\LocalizedData.xml.id-B4197730.[3442516480@qq.com].pdf | Dropped File | Stream |
Malicious
|
...
|
»
YARA Matches (1)
»
Rule Name | Rule Description | Classification | Score | Actions |
---|---|---|---|---|
DharmaEncryptedFile | File encrypted by Dharma Ransomware | Ransomware |
5/5
|
...
|
C:\588bce7c90097ed212\1053\eula.rtf.id-B4197730.[3442516480@qq.com].pdf | Dropped File | Stream |
Malicious
|
...
|
»
YARA Matches (1)
»
Rule Name | Rule Description | Classification | Score | Actions |
---|---|---|---|---|
DharmaEncryptedFile | File encrypted by Dharma Ransomware | Ransomware |
5/5
|
...
|
C:\588bce7c90097ed212\1053\LocalizedData.xml.id-B4197730.[3442516480@qq.com].pdf | Dropped File | Stream |
Malicious
|
...
|
»
YARA Matches (1)
»
Rule Name | Rule Description | Classification | Score | Actions |
---|---|---|---|---|
DharmaEncryptedFile | File encrypted by Dharma Ransomware | Ransomware |
5/5
|
...
|
C:\588bce7c90097ed212\1055\eula.rtf.id-B4197730.[3442516480@qq.com].pdf | Dropped File | Stream |
Malicious
|
...
|
»
YARA Matches (1)
»
Rule Name | Rule Description | Classification | Score | Actions |
---|---|---|---|---|
DharmaEncryptedFile | File encrypted by Dharma Ransomware | Ransomware |
5/5
|
...
|
C:\588bce7c90097ed212\DisplayIcon.ico.id-B4197730.[3442516480@qq.com].pdf | Dropped File | Stream |
Malicious
|
...
|
»
YARA Matches (1)
»
Rule Name | Rule Description | Classification | Score | Actions |
---|---|---|---|---|
DharmaEncryptedFile | File encrypted by Dharma Ransomware | Ransomware |
5/5
|
...
|
C:\588bce7c90097ed212\Graphics\Save.ico.id-B4197730.[3442516480@qq.com].pdf | Dropped File | Stream |
Malicious
|
...
|
»
YARA Matches (1)
»
Rule Name | Rule Description | Classification | Score | Actions |
---|---|---|---|---|
DharmaEncryptedFile | File encrypted by Dharma Ransomware | Ransomware |
5/5
|
...
|
C:\588bce7c90097ed212\Graphics\Setup.ico.id-B4197730.[3442516480@qq.com].pdf | Dropped File | Stream |
Malicious
|
...
|
»
YARA Matches (1)
»
Rule Name | Rule Description | Classification | Score | Actions |
---|---|---|---|---|
DharmaEncryptedFile | File encrypted by Dharma Ransomware | Ransomware |
5/5
|
...
|
C:\588bce7c90097ed212\1045\LocalizedData.xml.id-B4197730.[3442516480@qq.com].pdf | Dropped File | Stream |
Malicious
|
...
|
»
YARA Matches (1)
»
Rule Name | Rule Description | Classification | Score | Actions |
---|---|---|---|---|
DharmaEncryptedFile | File encrypted by Dharma Ransomware | Ransomware |
5/5
|
...
|
C:\588bce7c90097ed212\2052\eula.rtf.id-B4197730.[3442516480@qq.com].pdf | Dropped File | Stream |
Malicious
|
...
|
»
YARA Matches (1)
»
Rule Name | Rule Description | Classification | Score | Actions |
---|---|---|---|---|
DharmaEncryptedFile | File encrypted by Dharma Ransomware | Ransomware |
5/5
|
...
|
C:\588bce7c90097ed212\2052\LocalizedData.xml.id-B4197730.[3442516480@qq.com].pdf | Dropped File | Stream |
Malicious
|
...
|
»
YARA Matches (1)
»
Rule Name | Rule Description | Classification | Score | Actions |
---|---|---|---|---|
DharmaEncryptedFile | File encrypted by Dharma Ransomware | Ransomware |
5/5
|
...
|
C:\588bce7c90097ed212\Graphics\Rotate2.ico.id-B4197730.[3442516480@qq.com].pdf | Dropped File | Stream |
Malicious
|
...
|
»
YARA Matches (1)
»
Rule Name | Rule Description | Classification | Score | Actions |
---|---|---|---|---|
DharmaEncryptedFile | File encrypted by Dharma Ransomware | Ransomware |
5/5
|
...
|
C:\588bce7c90097ed212\Graphics\SysReqMet.ico.id-B4197730.[3442516480@qq.com].pdf | Dropped File | Stream |
Malicious
|
...
|
»
YARA Matches (1)
»
Rule Name | Rule Description | Classification | Score | Actions |
---|---|---|---|---|
DharmaEncryptedFile | File encrypted by Dharma Ransomware | Ransomware |
5/5
|
...
|
C:\588bce7c90097ed212\Graphics\SysReqNotMet.ico.id-B4197730.[3442516480@qq.com].pdf | Dropped File | Stream |
Malicious
|
...
|
»
YARA Matches (1)
»
Rule Name | Rule Description | Classification | Score | Actions |
---|---|---|---|---|
DharmaEncryptedFile | File encrypted by Dharma Ransomware | Ransomware |
5/5
|
...
|
C:\588bce7c90097ed212\Graphics\warn.ico.id-B4197730.[3442516480@qq.com].pdf | Dropped File | Stream |
Malicious
|
...
|
»
YARA Matches (1)
»
Rule Name | Rule Description | Classification | Score | Actions |
---|---|---|---|---|
DharmaEncryptedFile | File encrypted by Dharma Ransomware | Ransomware |
5/5
|
...
|
C:\588bce7c90097ed212\1049\LocalizedData.xml.id-B4197730.[3442516480@qq.com].pdf | Dropped File | Stream |
Malicious
|
...
|
»
YARA Matches (1)
»
Rule Name | Rule Description | Classification | Score | Actions |
---|---|---|---|---|
DharmaEncryptedFile | File encrypted by Dharma Ransomware | Ransomware |
5/5
|
...
|
C:\588bce7c90097ed212\2070\LocalizedData.xml.id-B4197730.[3442516480@qq.com].pdf | Dropped File | Stream |
Malicious
|
...
|
»
YARA Matches (1)
»
Rule Name | Rule Description | Classification | Score | Actions |
---|---|---|---|---|
DharmaEncryptedFile | File encrypted by Dharma Ransomware | Ransomware |
5/5
|
...
|
C:\588bce7c90097ed212\3076\eula.rtf.id-B4197730.[3442516480@qq.com].pdf | Dropped File | Stream |
Malicious
|
...
|
»
YARA Matches (1)
»
Rule Name | Rule Description | Classification | Score | Actions |
---|---|---|---|---|
DharmaEncryptedFile | File encrypted by Dharma Ransomware | Ransomware |
5/5
|
...
|
C:\588bce7c90097ed212\2070\eula.rtf.id-B4197730.[3442516480@qq.com].pdf | Dropped File | Stream |
Malicious
|
...
|
»
YARA Matches (1)
»
Rule Name | Rule Description | Classification | Score | Actions |
---|---|---|---|---|
DharmaEncryptedFile | File encrypted by Dharma Ransomware | Ransomware |
5/5
|
...
|
C:\588bce7c90097ed212\3082\eula.rtf.id-B4197730.[3442516480@qq.com].pdf | Dropped File | Stream |
Malicious
|
...
|
»
YARA Matches (1)
»
Rule Name | Rule Description | Classification | Score | Actions |
---|---|---|---|---|
DharmaEncryptedFile | File encrypted by Dharma Ransomware | Ransomware |
5/5
|
...
|
C:\588bce7c90097ed212\3082\LocalizedData.xml.id-B4197730.[3442516480@qq.com].pdf | Dropped File | Stream |
Malicious
|
...
|
»
YARA Matches (1)
»
Rule Name | Rule Description | Classification | Score | Actions |
---|---|---|---|---|
DharmaEncryptedFile | File encrypted by Dharma Ransomware | Ransomware |
5/5
|
...
|
C:\588bce7c90097ed212\1049\eula.rtf.id-B4197730.[3442516480@qq.com].pdf | Dropped File | Stream |
Malicious
|
...
|
»
YARA Matches (1)
»
Rule Name | Rule Description | Classification | Score | Actions |
---|---|---|---|---|
DharmaEncryptedFile | File encrypted by Dharma Ransomware | Ransomware |
5/5
|
...
|
C:\588bce7c90097ed212\Client\UiInfo.xml.id-B4197730.[3442516480@qq.com].pdf | Dropped File | Stream |
Malicious
|
...
|
»
YARA Matches (1)
»
Rule Name | Rule Description | Classification | Score | Actions |
---|---|---|---|---|
DharmaEncryptedFile | File encrypted by Dharma Ransomware | Ransomware |
5/5
|
...
|
C:\588bce7c90097ed212\DHtmlHeader.html.id-B4197730.[3442516480@qq.com].pdf | Dropped File | Stream |
Malicious
|
...
|
»
YARA Matches (1)
»
Rule Name | Rule Description | Classification | Score | Actions |
---|---|---|---|---|
DharmaEncryptedFile | File encrypted by Dharma Ransomware | Ransomware |
5/5
|
...
|
C:\588bce7c90097ed212\Graphics\Rotate5.ico.id-B4197730.[3442516480@qq.com].pdf | Dropped File | Stream |
Malicious
|
...
|
»
YARA Matches (1)
»
Rule Name | Rule Description | Classification | Score | Actions |
---|---|---|---|---|
DharmaEncryptedFile | File encrypted by Dharma Ransomware | Ransomware |
5/5
|
...
|
C:\588bce7c90097ed212\Graphics\Rotate8.ico.id-B4197730.[3442516480@qq.com].pdf | Dropped File | Stream |
Malicious
|
...
|
»
YARA Matches (1)
»
Rule Name | Rule Description | Classification | Score | Actions |
---|---|---|---|---|
DharmaEncryptedFile | File encrypted by Dharma Ransomware | Ransomware |
5/5
|
...
|
C:\588bce7c90097ed212\1055\LocalizedData.xml.id-B4197730.[3442516480@qq.com].pdf | Dropped File | Stream |
Malicious
|
...
|
»
YARA Matches (1)
»
Rule Name | Rule Description | Classification | Score | Actions |
---|---|---|---|---|
DharmaEncryptedFile | File encrypted by Dharma Ransomware | Ransomware |
5/5
|
...
|
C:\588bce7c90097ed212\Extended\UiInfo.xml.id-B4197730.[3442516480@qq.com].pdf | Dropped File | Stream |
Malicious
|
...
|
»
YARA Matches (1)
»
Rule Name | Rule Description | Classification | Score | Actions |
---|---|---|---|---|
DharmaEncryptedFile | File encrypted by Dharma Ransomware | Ransomware |
5/5
|
...
|
C:\588bce7c90097ed212\header.bmp.id-B4197730.[3442516480@qq.com].pdf | Dropped File | Stream |
Malicious
|
...
|
»
YARA Matches (1)
»
Rule Name | Rule Description | Classification | Score | Actions |
---|---|---|---|---|
DharmaEncryptedFile | File encrypted by Dharma Ransomware | Ransomware |
5/5
|
...
|
C:\588bce7c90097ed212\Graphics\stop.ico.id-B4197730.[3442516480@qq.com].pdf | Dropped File | Stream |
Malicious
|
...
|
»
YARA Matches (1)
»
Rule Name | Rule Description | Classification | Score | Actions |
---|---|---|---|---|
DharmaEncryptedFile | File encrypted by Dharma Ransomware | Ransomware |
5/5
|
...
|
C:\588bce7c90097ed212\3076\LocalizedData.xml.id-B4197730.[3442516480@qq.com].pdf | Dropped File | Stream |
Malicious
|
...
|
»
YARA Matches (1)
»
Rule Name | Rule Description | Classification | Score | Actions |
---|---|---|---|---|
DharmaEncryptedFile | File encrypted by Dharma Ransomware | Ransomware |
5/5
|
...
|
C:\588bce7c90097ed212\Client\Parameterinfo.xml.id-B4197730.[3442516480@qq.com].pdf | Dropped File | Stream |
Malicious
|
...
|
»
YARA Matches (1)
»
Rule Name | Rule Description | Classification | Score | Actions |
---|---|---|---|---|
DharmaEncryptedFile | File encrypted by Dharma Ransomware | Ransomware |
5/5
|
...
|
C:\588bce7c90097ed212\Extended\Parameterinfo.xml.id-B4197730.[3442516480@qq.com].pdf | Dropped File | Stream |
Malicious
|
...
|
»
YARA Matches (1)
»
Rule Name | Rule Description | Classification | Score | Actions |
---|---|---|---|---|
DharmaEncryptedFile | File encrypted by Dharma Ransomware | Ransomware |
5/5
|
...
|
C:\588bce7c90097ed212\Strings.xml.id-B4197730.[3442516480@qq.com].pdf | Dropped File | Stream |
Malicious
|
...
|
»
YARA Matches (1)
»
Rule Name | Rule Description | Classification | Score | Actions |
---|---|---|---|---|
DharmaEncryptedFile | File encrypted by Dharma Ransomware | Ransomware |
5/5
|
...
|
C:\588bce7c90097ed212\SplashScreen.bmp.id-B4197730.[3442516480@qq.com].pdf | Dropped File | Stream |
Malicious
|
...
|
»
YARA Matches (1)
»
Rule Name | Rule Description | Classification | Score | Actions |
---|---|---|---|---|
DharmaEncryptedFile | File encrypted by Dharma Ransomware | Ransomware |
5/5
|
...
|
C:\588bce7c90097ed212\watermark.bmp.id-B4197730.[3442516480@qq.com].pdf | Dropped File | Stream |
Malicious
|
...
|
»
YARA Matches (1)
»
Rule Name | Rule Description | Classification | Score | Actions |
---|---|---|---|---|
DharmaEncryptedFile | File encrypted by Dharma Ransomware | Ransomware |
5/5
|
...
|
C:\588bce7c90097ed212\SetupUi.xsd.id-B4197730.[3442516480@qq.com].pdf | Dropped File | Stream |
Malicious
|
...
|
»
YARA Matches (1)
»
Rule Name | Rule Description | Classification | Score | Actions |
---|---|---|---|---|
DharmaEncryptedFile | File encrypted by Dharma Ransomware | Ransomware |
5/5
|
...
|
C:\BOOTSECT.BAK.id-B4197730.[3442516480@qq.com].pdf | Dropped File | Stream |
Malicious
|
...
|
»
YARA Matches (1)
»
Rule Name | Rule Description | Classification | Score | Actions |
---|---|---|---|---|
DharmaEncryptedFile | File encrypted by Dharma Ransomware | Ransomware |
5/5
|
...
|
C:\Boot\BOOTSTAT.DAT.id-B4197730.[3442516480@qq.com].pdf | Dropped File | Stream |
Malicious
|
...
|
»
YARA Matches (1)
»
Rule Name | Rule Description | Classification | Score | Actions |
---|---|---|---|---|
DharmaEncryptedFile | File encrypted by Dharma Ransomware | Ransomware |
5/5
|
...
|
C:\588bce7c90097ed212\ParameterInfo.xml.id-B4197730.[3442516480@qq.com].pdf | Dropped File | Stream |
Malicious
|
...
|
»
YARA Matches (1)
»
Rule Name | Rule Description | Classification | Score | Actions |
---|---|---|---|---|
DharmaEncryptedFile | File encrypted by Dharma Ransomware | Ransomware |
5/5
|
...
|
C:\588bce7c90097ed212\netfx_Core_x86.msi.id-B4197730.[3442516480@qq.com].pdf | Dropped File | Stream |
Malicious
|
...
|
»
YARA Matches (1)
»
Rule Name | Rule Description | Classification | Score | Actions |
---|---|---|---|---|
DharmaEncryptedFile | File encrypted by Dharma Ransomware | Ransomware |
5/5
|
...
|
C:\588bce7c90097ed212\UiInfo.xml.id-B4197730.[3442516480@qq.com].pdf | Dropped File | Stream |
Malicious
|
...
|
»
YARA Matches (1)
»
Rule Name | Rule Description | Classification | Score | Actions |
---|---|---|---|---|
DharmaEncryptedFile | File encrypted by Dharma Ransomware | Ransomware |
5/5
|
...
|
C:\588bce7c90097ed212\RGB9RAST_x64.msi.id-B4197730.[3442516480@qq.com].pdf | Dropped File | Stream |
Malicious
|
...
|
»
YARA Matches (1)
»
Rule Name | Rule Description | Classification | Score | Actions |
---|---|---|---|---|
DharmaEncryptedFile | File encrypted by Dharma Ransomware | Ransomware |
5/5
|
...
|
C:\588bce7c90097ed212\Setup.exe.id-B4197730.[3442516480@qq.com].pdf | Dropped File | Stream |
Malicious
|
...
|
»
YARA Matches (1)
»
Rule Name | Rule Description | Classification | Score | Actions |
---|---|---|---|---|
DharmaEncryptedFile | File encrypted by Dharma Ransomware | Ransomware |
5/5
|
...
|
C:\588bce7c90097ed212\RGB9Rast_x86.msi.id-B4197730.[3442516480@qq.com].pdf | Dropped File | Stream |
Malicious
|
...
|
»
YARA Matches (1)
»
Rule Name | Rule Description | Classification | Score | Actions |
---|---|---|---|---|
DharmaEncryptedFile | File encrypted by Dharma Ransomware | Ransomware |
5/5
|
...
|
C:\588bce7c90097ed212\SetupUi.dll.id-B4197730.[3442516480@qq.com].pdf | Dropped File | Stream |
Malicious
|
...
|
»
YARA Matches (1)
»
Rule Name | Rule Description | Classification | Score | Actions |
---|---|---|---|---|
DharmaEncryptedFile | File encrypted by Dharma Ransomware | Ransomware |
5/5
|
...
|
C:\588bce7c90097ed212\SetupUtility.exe.id-B4197730.[3442516480@qq.com].pdf | Dropped File | Stream |
Malicious
|
...
|
»
YARA Matches (1)
»
Rule Name | Rule Description | Classification | Score | Actions |
---|---|---|---|---|
DharmaEncryptedFile | File encrypted by Dharma Ransomware | Ransomware |
5/5
|
...
|
C:\588bce7c90097ed212\SetupEngine.dll.id-B4197730.[3442516480@qq.com].pdf | Dropped File | Stream |
Malicious
|
...
|
»
YARA Matches (1)
»
Rule Name | Rule Description | Classification | Score | Actions |
---|---|---|---|---|
DharmaEncryptedFile | File encrypted by Dharma Ransomware | Ransomware |
5/5
|
...
|
C:\Program Files\Java\jre1.8.0_144\bin\server\Xusage.txt.id-B4197730.[3442516480@qq.com].pdf | Dropped File | Stream |
Malicious
|
...
|
»
YARA Matches (1)
»
Rule Name | Rule Description | Classification | Score | Actions |
---|---|---|---|---|
DharmaEncryptedFile | File encrypted by Dharma Ransomware | Ransomware |
5/5
|
...
|
C:\Program Files\Java\jre1.8.0_144\lib\deploy\splash.gif.id-B4197730.[3442516480@qq.com].pdf | Dropped File | Stream |
Malicious
|
...
|
»
YARA Matches (1)
»
Rule Name | Rule Description | Classification | Score | Actions |
---|---|---|---|---|
DharmaEncryptedFile | File encrypted by Dharma Ransomware | Ransomware |
5/5
|
...
|
C:\Program Files\Java\jre1.8.0_144\lib\deploy\splash_11@2x-lic.gif.id-B4197730.[3442516480@qq.com].pdf | Dropped File | Stream |
Malicious
|
...
|
»
YARA Matches (1)
»
Rule Name | Rule Description | Classification | Score | Actions |
---|---|---|---|---|
DharmaEncryptedFile | File encrypted by Dharma Ransomware | Ransomware |
5/5
|
...
|
C:\Program Files\Java\jre1.8.0_144\lib\deploy\splash_11-lic.gif.id-B4197730.[3442516480@qq.com].pdf | Dropped File | Stream |
Malicious
|
...
|
»
YARA Matches (1)
»
Rule Name | Rule Description | Classification | Score | Actions |
---|---|---|---|---|
DharmaEncryptedFile | File encrypted by Dharma Ransomware | Ransomware |
5/5
|
...
|
C:\Program Files\Java\jre1.8.0_144\lib\jvm.hprof.txt.id-B4197730.[3442516480@qq.com].pdf | Dropped File | Stream |
Malicious
|
...
|
»
YARA Matches (1)
»
Rule Name | Rule Description | Classification | Score | Actions |
---|---|---|---|---|
DharmaEncryptedFile | File encrypted by Dharma Ransomware | Ransomware |
5/5
|
...
|
C:\Program Files\Java\jre1.8.0_144\lib\tzdb.dat.id-B4197730.[3442516480@qq.com].pdf | Dropped File | Stream |
Malicious
|
...
|
»
YARA Matches (1)
»
Rule Name | Rule Description | Classification | Score | Actions |
---|---|---|---|---|
DharmaEncryptedFile | File encrypted by Dharma Ransomware | Ransomware |
5/5
|
...
|
C:\Program Files\Java\jre1.8.0_144\Welcome.html.id-B4197730.[3442516480@qq.com].pdf | Dropped File | Stream |
Malicious
|
...
|
»
YARA Matches (1)
»
Rule Name | Rule Description | Classification | Score | Actions |
---|---|---|---|---|
DharmaEncryptedFile | File encrypted by Dharma Ransomware | Ransomware |
5/5
|
...
|
C:\588bce7c90097ed212\sqmapi.dll.id-B4197730.[3442516480@qq.com].pdf | Dropped File | Stream |
Malicious
|
...
|
»
YARA Matches (1)
»
Rule Name | Rule Description | Classification | Score | Actions |
---|---|---|---|---|
DharmaEncryptedFile | File encrypted by Dharma Ransomware | Ransomware |
5/5
|
...
|
C:\Program Files\Microsoft Office\Office16\OSPP.HTM.id-B4197730.[3442516480@qq.com].pdf | Dropped File | Stream |
Malicious
|
...
|
»
YARA Matches (1)
»
Rule Name | Rule Description | Classification | Score | Actions |
---|---|---|---|---|
DharmaEncryptedFile | File encrypted by Dharma Ransomware | Ransomware |
5/5
|
...
|
C:\Program Files\Microsoft Office\Office16\OSPP.VBS.id-B4197730.[3442516480@qq.com].pdf | Dropped File | Stream |
Malicious
|
...
|
»
YARA Matches (1)
»
Rule Name | Rule Description | Classification | Score | Actions |
---|---|---|---|---|
DharmaEncryptedFile | File encrypted by Dharma Ransomware | Ransomware |
5/5
|
...
|
C:\Program Files\Microsoft Office\Office16\SLERROR.XML.id-B4197730.[3442516480@qq.com].pdf | Dropped File | Stream |
Malicious
|
...
|
»
YARA Matches (1)
»
Rule Name | Rule Description | Classification | Score | Actions |
---|---|---|---|---|
DharmaEncryptedFile | File encrypted by Dharma Ransomware | Ransomware |
5/5
|
...
|
C:\Logs\Application.evtx.id-B4197730.[3442516480@qq.com].pdf | Dropped File | Stream |
Malicious
|
...
|
»
YARA Matches (1)
»
Rule Name | Rule Description | Classification | Score | Actions |
---|---|---|---|---|
DharmaEncryptedFile | File encrypted by Dharma Ransomware | Ransomware |
5/5
|
...
|
C:\Logs\HardwareEvents.evtx.id-B4197730.[3442516480@qq.com].pdf | Dropped File | Stream |
Malicious
|
...
|
»
YARA Matches (1)
»
Rule Name | Rule Description | Classification | Score | Actions |
---|---|---|---|---|
DharmaEncryptedFile | File encrypted by Dharma Ransomware | Ransomware |
5/5
|
...
|
C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\AG00004_.GIF.id-B4197730.[3442516480@qq.com].pdf | Dropped File | Stream |
Malicious
|
...
|
»
YARA Matches (1)
»
Rule Name | Rule Description | Classification | Score | Actions |
---|---|---|---|---|
DharmaEncryptedFile | File encrypted by Dharma Ransomware | Ransomware |
5/5
|
...
|
C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\AG00011_.GIF.id-B4197730.[3442516480@qq.com].pdf | Dropped File | Stream |
Malicious
|
...
|
»
YARA Matches (1)
»
Rule Name | Rule Description | Classification | Score | Actions |
---|---|---|---|---|
DharmaEncryptedFile | File encrypted by Dharma Ransomware | Ransomware |
5/5
|
...
|
C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\AG00037_.GIF.id-B4197730.[3442516480@qq.com].pdf | Dropped File | Stream |
Malicious
|
...
|
»
YARA Matches (1)
»
Rule Name | Rule Description | Classification | Score | Actions |
---|---|---|---|---|
DharmaEncryptedFile | File encrypted by Dharma Ransomware | Ransomware |
5/5
|
...
|
C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\AG00038_.GIF.id-B4197730.[3442516480@qq.com].pdf | Dropped File | Stream |
Malicious
|
...
|
»
YARA Matches (1)
»
Rule Name | Rule Description | Classification | Score | Actions |
---|---|---|---|---|
DharmaEncryptedFile | File encrypted by Dharma Ransomware | Ransomware |
5/5
|
...
|
C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\AG00040_.GIF.id-B4197730.[3442516480@qq.com].pdf | Dropped File | Stream |
Malicious
|
...
|
»
YARA Matches (1)
»
Rule Name | Rule Description | Classification | Score | Actions |
---|---|---|---|---|
DharmaEncryptedFile | File encrypted by Dharma Ransomware | Ransomware |
5/5
|
...
|
C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\AG00052_.GIF.id-B4197730.[3442516480@qq.com].pdf | Dropped File | Stream |
Malicious
|
...
|
»
YARA Matches (1)
»
Rule Name | Rule Description | Classification | Score | Actions |
---|---|---|---|---|
DharmaEncryptedFile | File encrypted by Dharma Ransomware | Ransomware |
5/5
|
...
|
C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\AG00057_.GIF.id-B4197730.[3442516480@qq.com].pdf | Dropped File | Stream |
Malicious
|
...
|
»
YARA Matches (1)
»
Rule Name | Rule Description | Classification | Score | Actions |
---|---|---|---|---|
DharmaEncryptedFile | File encrypted by Dharma Ransomware | Ransomware |
5/5
|
...
|
C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\AG00021_.GIF.id-B4197730.[3442516480@qq.com].pdf | Dropped File | Stream |
Malicious
|
...
|
»
YARA Matches (1)
»
Rule Name | Rule Description | Classification | Score | Actions |
---|---|---|---|---|
DharmaEncryptedFile | File encrypted by Dharma Ransomware | Ransomware |
5/5
|
...
|
C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\AG00103_.GIF.id-B4197730.[3442516480@qq.com].pdf | Dropped File | Stream |
Malicious
|
...
|
»
YARA Matches (1)
»
Rule Name | Rule Description | Classification | Score | Actions |
---|---|---|---|---|
DharmaEncryptedFile | File encrypted by Dharma Ransomware | Ransomware |
5/5
|
...
|
C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\AG00126_.GIF.id-B4197730.[3442516480@qq.com].pdf | Dropped File | Stream |
Malicious
|
...
|
»
YARA Matches (1)
»
Rule Name | Rule Description | Classification | Score | Actions |
---|---|---|---|---|
DharmaEncryptedFile | File encrypted by Dharma Ransomware | Ransomware |
5/5
|
...
|
C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\AG00090_.GIF.id-B4197730.[3442516480@qq.com].pdf | Dropped File | Stream |
Malicious
|
...
|
»
YARA Matches (1)
»
Rule Name | Rule Description | Classification | Score | Actions |
---|---|---|---|---|
DharmaEncryptedFile | File encrypted by Dharma Ransomware | Ransomware |
5/5
|
...
|
C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\AG00130_.GIF.id-B4197730.[3442516480@qq.com].pdf | Dropped File | Stream |
Malicious
|
...
|
»
YARA Matches (1)
»
Rule Name | Rule Description | Classification | Score | Actions |
---|---|---|---|---|
DharmaEncryptedFile | File encrypted by Dharma Ransomware | Ransomware |
5/5
|
...
|
C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\AG00135_.GIF.id-B4197730.[3442516480@qq.com].pdf | Dropped File | Stream |
Malicious
|
...
|
»
YARA Matches (1)
»
Rule Name | Rule Description | Classification | Score | Actions |
---|---|---|---|---|
DharmaEncryptedFile | File encrypted by Dharma Ransomware | Ransomware |
5/5
|
...
|
C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\AG00139_.GIF.id-B4197730.[3442516480@qq.com].pdf | Dropped File | Stream |
Malicious
|
...
|
»
YARA Matches (1)
»
Rule Name | Rule Description | Classification | Score | Actions |
---|---|---|---|---|
DharmaEncryptedFile | File encrypted by Dharma Ransomware | Ransomware |
5/5
|
...
|
C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\AG00120_.GIF.id-B4197730.[3442516480@qq.com].pdf | Dropped File | Stream |
Malicious
|
...
|
»
YARA Matches (1)
»
Rule Name | Rule Description | Classification | Score | Actions |
---|---|---|---|---|
DharmaEncryptedFile | File encrypted by Dharma Ransomware | Ransomware |
5/5
|
...
|
C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\AG00129_.GIF.id-B4197730.[3442516480@qq.com].pdf | Dropped File | Stream |
Malicious
|
...
|
»
YARA Matches (1)
»
Rule Name | Rule Description | Classification | Score | Actions |
---|---|---|---|---|
DharmaEncryptedFile | File encrypted by Dharma Ransomware | Ransomware |
5/5
|
...
|
C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\AG00092_.GIF.id-B4197730.[3442516480@qq.com].pdf | Dropped File | Stream |
Malicious
|
...
|
»
YARA Matches (1)
»
Rule Name | Rule Description | Classification | Score | Actions |
---|---|---|---|---|
DharmaEncryptedFile | File encrypted by Dharma Ransomware | Ransomware |
5/5
|
...
|
C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\AG00154_.GIF.id-B4197730.[3442516480@qq.com].pdf | Dropped File | Stream |
Malicious
|
...
|
»
YARA Matches (1)
»
Rule Name | Rule Description | Classification | Score | Actions |
---|---|---|---|---|
DharmaEncryptedFile | File encrypted by Dharma Ransomware | Ransomware |
5/5
|
...
|
C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\AG00157_.GIF.id-B4197730.[3442516480@qq.com].pdf | Dropped File | Stream |
Malicious
|
...
|
»
YARA Matches (1)
»
Rule Name | Rule Description | Classification | Score | Actions |
---|---|---|---|---|
DharmaEncryptedFile | File encrypted by Dharma Ransomware | Ransomware |
5/5
|
...
|
C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\AG00158_.GIF.id-B4197730.[3442516480@qq.com].pdf | Dropped File | Stream |
Malicious
|
...
|
»
YARA Matches (1)
»
Rule Name | Rule Description | Classification | Score | Actions |
---|---|---|---|---|
DharmaEncryptedFile | File encrypted by Dharma Ransomware | Ransomware |
5/5
|
...
|
C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\AG00161_.GIF.id-B4197730.[3442516480@qq.com].pdf | Dropped File | Stream |
Malicious
|
...
|
»
YARA Matches (1)
»
Rule Name | Rule Description | Classification | Score | Actions |
---|---|---|---|---|
DharmaEncryptedFile | File encrypted by Dharma Ransomware | Ransomware |
5/5
|
...
|
C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\AG00163_.GIF.id-B4197730.[3442516480@qq.com].pdf | Dropped File | Stream |
Malicious
|
...
|
»
YARA Matches (1)
»
Rule Name | Rule Description | Classification | Score | Actions |
---|---|---|---|---|
DharmaEncryptedFile | File encrypted by Dharma Ransomware | Ransomware |
5/5
|
...
|
C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\AG00165_.GIF.id-B4197730.[3442516480@qq.com].pdf | Dropped File | Stream |
Malicious
|
...
|
»
YARA Matches (1)
»
Rule Name | Rule Description | Classification | Score | Actions |
---|---|---|---|---|
DharmaEncryptedFile | File encrypted by Dharma Ransomware | Ransomware |
5/5
|
...
|
C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\AG00164_.GIF.id-B4197730.[3442516480@qq.com].pdf | Dropped File | Stream |
Malicious
|
...
|
»
YARA Matches (1)
»
Rule Name | Rule Description | Classification | Score | Actions |
---|---|---|---|---|
DharmaEncryptedFile | File encrypted by Dharma Ransomware | Ransomware |
5/5
|
...
|
C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\AG00167_.GIF.id-B4197730.[3442516480@qq.com].pdf | Dropped File | Stream |
Malicious
|
...
|
»
YARA Matches (1)
»
Rule Name | Rule Description | Classification | Score | Actions |
---|---|---|---|---|
DharmaEncryptedFile | File encrypted by Dharma Ransomware | Ransomware |
5/5
|
...
|
C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\AG00169_.GIF.id-B4197730.[3442516480@qq.com].pdf | Dropped File | Stream |
Malicious
|
...
|
»
YARA Matches (1)
»
Rule Name | Rule Description | Classification | Score | Actions |
---|---|---|---|---|
DharmaEncryptedFile | File encrypted by Dharma Ransomware | Ransomware |
5/5
|
...
|
C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\AG00170_.GIF.id-B4197730.[3442516480@qq.com].pdf | Dropped File | Stream |
Malicious
|
...
|
»
YARA Matches (1)
»
Rule Name | Rule Description | Classification | Score | Actions |
---|---|---|---|---|
DharmaEncryptedFile | File encrypted by Dharma Ransomware | Ransomware |
5/5
|
...
|
C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\AG00142_.GIF.id-B4197730.[3442516480@qq.com].pdf | Dropped File | Stream |
Malicious
|
...
|
»
YARA Matches (1)
»
Rule Name | Rule Description | Classification | Score | Actions |
---|---|---|---|---|
DharmaEncryptedFile | File encrypted by Dharma Ransomware | Ransomware |
5/5
|
...
|
C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\AG00171_.GIF.id-B4197730.[3442516480@qq.com].pdf | Dropped File | Stream |
Malicious
|
...
|
»
YARA Matches (1)
»
Rule Name | Rule Description | Classification | Score | Actions |
---|---|---|---|---|
DharmaEncryptedFile | File encrypted by Dharma Ransomware | Ransomware |
5/5
|
...
|
C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\AG00172_.GIF.id-B4197730.[3442516480@qq.com].pdf | Dropped File | Stream |
Malicious
|
...
|
»
YARA Matches (1)
»
Rule Name | Rule Description | Classification | Score | Actions |
---|---|---|---|---|
DharmaEncryptedFile | File encrypted by Dharma Ransomware | Ransomware |
5/5
|
...
|
C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\AG00174_.GIF.id-B4197730.[3442516480@qq.com].pdf | Dropped File | Stream |
Malicious
|
...
|
»
YARA Matches (1)
»
Rule Name | Rule Description | Classification | Score | Actions |
---|---|---|---|---|
DharmaEncryptedFile | File encrypted by Dharma Ransomware | Ransomware |
5/5
|
...
|
C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\AG00176_.GIF.id-B4197730.[3442516480@qq.com].pdf | Dropped File | Stream |
Malicious
|
...
|
»
YARA Matches (1)
»
Rule Name | Rule Description | Classification | Score | Actions |
---|---|---|---|---|
DharmaEncryptedFile | File encrypted by Dharma Ransomware | Ransomware |
5/5
|
...
|
C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\AN00010_.WMF.id-B4197730.[3442516480@qq.com].pdf | Dropped File | Stream |
Malicious
|
...
|
»
YARA Matches (1)
»
Rule Name | Rule Description | Classification | Score | Actions |
---|---|---|---|---|
DharmaEncryptedFile | File encrypted by Dharma Ransomware | Ransomware |
5/5
|
...
|
C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\AG00160_.GIF.id-B4197730.[3442516480@qq.com].pdf | Dropped File | Stream |
Malicious
|
...
|
»
YARA Matches (1)
»
Rule Name | Rule Description | Classification | Score | Actions |
---|---|---|---|---|
DharmaEncryptedFile | File encrypted by Dharma Ransomware | Ransomware |
5/5
|
...
|
C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\AN00790_.WMF.id-B4197730.[3442516480@qq.com].pdf | Dropped File | Stream |
Malicious
|
...
|
»
YARA Matches (1)
»
Rule Name | Rule Description | Classification | Score | Actions |
---|---|---|---|---|
DharmaEncryptedFile | File encrypted by Dharma Ransomware | Ransomware |
5/5
|
...
|
C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\AG00175_.GIF.id-B4197730.[3442516480@qq.com].pdf | Dropped File | Stream |
Malicious
|
...
|
»
YARA Matches (1)
»
Rule Name | Rule Description | Classification | Score | Actions |
---|---|---|---|---|
DharmaEncryptedFile | File encrypted by Dharma Ransomware | Ransomware |
5/5
|
...
|
C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\AN00015_.WMF.id-B4197730.[3442516480@qq.com].pdf | Dropped File | Stream |
Malicious
|
...
|
»
YARA Matches (1)
»
Rule Name | Rule Description | Classification | Score | Actions |
---|---|---|---|---|
DharmaEncryptedFile | File encrypted by Dharma Ransomware | Ransomware |
5/5
|
...
|
C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\AN00853_.WMF.id-B4197730.[3442516480@qq.com].pdf | Dropped File | Stream |
Malicious
|
...
|
»
YARA Matches (1)
»
Rule Name | Rule Description | Classification | Score | Actions |
---|---|---|---|---|
DharmaEncryptedFile | File encrypted by Dharma Ransomware | Ransomware |
5/5
|
...
|
C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\AN00914_.WMF.id-B4197730.[3442516480@qq.com].pdf | Dropped File | Stream |
Malicious
|
...
|
»
YARA Matches (1)
»
Rule Name | Rule Description | Classification | Score | Actions |
---|---|---|---|---|
DharmaEncryptedFile | File encrypted by Dharma Ransomware | Ransomware |
5/5
|
...
|
C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\AN00965_.WMF.id-B4197730.[3442516480@qq.com].pdf | Dropped File | Stream |
Malicious
|
...
|
»
YARA Matches (1)
»
Rule Name | Rule Description | Classification | Score | Actions |
---|---|---|---|---|
DharmaEncryptedFile | File encrypted by Dharma Ransomware | Ransomware |
5/5
|
...
|
C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\AN01039_.WMF.id-B4197730.[3442516480@qq.com].pdf | Dropped File | Stream |
Malicious
|
...
|
»
YARA Matches (1)
»
Rule Name | Rule Description | Classification | Score | Actions |
---|---|---|---|---|
DharmaEncryptedFile | File encrypted by Dharma Ransomware | Ransomware |
5/5
|
...
|
C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\AN00932_.WMF.id-B4197730.[3442516480@qq.com].pdf | Dropped File | Stream |
Malicious
|
...
|
»
YARA Matches (1)
»
Rule Name | Rule Description | Classification | Score | Actions |
---|---|---|---|---|
DharmaEncryptedFile | File encrypted by Dharma Ransomware | Ransomware |
5/5
|
...
|
C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\AN01060_.WMF.id-B4197730.[3442516480@qq.com].pdf | Dropped File | Stream |
Malicious
|
...
|
»
YARA Matches (1)
»
Rule Name | Rule Description | Classification | Score | Actions |
---|---|---|---|---|
DharmaEncryptedFile | File encrypted by Dharma Ransomware | Ransomware |
5/5
|
...
|
C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\AN01084_.WMF.id-B4197730.[3442516480@qq.com].pdf | Dropped File | Stream |
Malicious
|
...
|
»
YARA Matches (1)
»
Rule Name | Rule Description | Classification | Score | Actions |
---|---|---|---|---|
DharmaEncryptedFile | File encrypted by Dharma Ransomware | Ransomware |
5/5
|
...
|
C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\AN01173_.WMF.id-B4197730.[3442516480@qq.com].pdf | Dropped File | Stream |
Malicious
|
...
|
»
YARA Matches (1)
»
Rule Name | Rule Description | Classification | Score | Actions |
---|---|---|---|---|
DharmaEncryptedFile | File encrypted by Dharma Ransomware | Ransomware |
5/5
|
...
|
C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\AN01174_.WMF.id-B4197730.[3442516480@qq.com].pdf | Dropped File | Stream |
Malicious
|
...
|
»
YARA Matches (1)
»
Rule Name | Rule Description | Classification | Score | Actions |
---|---|---|---|---|
DharmaEncryptedFile | File encrypted by Dharma Ransomware | Ransomware |
5/5
|
...
|
C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\AN01184_.WMF.id-B4197730.[3442516480@qq.com].pdf | Dropped File | Stream |
Malicious
|
...
|
»
YARA Matches (1)
»
Rule Name | Rule Description | Classification | Score | Actions |
---|---|---|---|---|
DharmaEncryptedFile | File encrypted by Dharma Ransomware | Ransomware |
5/5
|
...
|
C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\AN01216_.WMF.id-B4197730.[3442516480@qq.com].pdf | Dropped File | Stream |
Malicious
|
...
|
»
YARA Matches (1)
»
Rule Name | Rule Description | Classification | Score | Actions |
---|---|---|---|---|
DharmaEncryptedFile | File encrypted by Dharma Ransomware | Ransomware |
5/5
|
...
|
C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\AN01218_.WMF.id-B4197730.[3442516480@qq.com].pdf | Dropped File | Stream |
Malicious
|
...
|
»
YARA Matches (1)
»
Rule Name | Rule Description | Classification | Score | Actions |
---|---|---|---|---|
DharmaEncryptedFile | File encrypted by Dharma Ransomware | Ransomware |
5/5
|
...
|
C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\AN01251_.WMF.id-B4197730.[3442516480@qq.com].pdf | Dropped File | Stream |
Malicious
|
...
|
»
YARA Matches (1)
»
Rule Name | Rule Description | Classification | Score | Actions |
---|---|---|---|---|
DharmaEncryptedFile | File encrypted by Dharma Ransomware | Ransomware |
5/5
|
...
|
C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\AN01545_.WMF.id-B4197730.[3442516480@qq.com].pdf | Dropped File | Stream |
Malicious
|
...
|
»
YARA Matches (1)
»
Rule Name | Rule Description | Classification | Score | Actions |
---|---|---|---|---|
DharmaEncryptedFile | File encrypted by Dharma Ransomware | Ransomware |
5/5
|
...
|
C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\AN02724_.WMF.id-B4197730.[3442516480@qq.com].pdf | Dropped File | Stream |
Malicious
|
...
|
»
YARA Matches (1)
»
Rule Name | Rule Description | Classification | Score | Actions |
---|---|---|---|---|
DharmaEncryptedFile | File encrypted by Dharma Ransomware | Ransomware |
5/5
|
...
|
C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\AN02122_.WMF.id-B4197730.[3442516480@qq.com].pdf | Dropped File | Stream |
Malicious
|
...
|
»
YARA Matches (1)
»
Rule Name | Rule Description | Classification | Score | Actions |
---|---|---|---|---|
DharmaEncryptedFile | File encrypted by Dharma Ransomware | Ransomware |
5/5
|
...
|
C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\AN01044_.WMF.id-B4197730.[3442516480@qq.com].pdf | Dropped File | Stream |
Malicious
|
...
|
»
YARA Matches (1)
»
Rule Name | Rule Description | Classification | Score | Actions |
---|---|---|---|---|
DharmaEncryptedFile | File encrypted by Dharma Ransomware | Ransomware |
5/5
|
...
|
C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\AN03500_.WMF.id-B4197730.[3442516480@qq.com].pdf | Dropped File | Stream |
Malicious
|
...
|
»
YARA Matches (1)
»
Rule Name | Rule Description | Classification | Score | Actions |
---|---|---|---|---|
DharmaEncryptedFile | File encrypted by Dharma Ransomware | Ransomware |
5/5
|
...
|
C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\AN04108_.WMF.id-B4197730.[3442516480@qq.com].pdf | Dropped File | Stream |
Malicious
|
...
|
»
YARA Matches (1)
»
Rule Name | Rule Description | Classification | Score | Actions |
---|---|---|---|---|
DharmaEncryptedFile | File encrypted by Dharma Ransomware | Ransomware |
5/5
|
...
|
C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\AN04117_.WMF.id-B4197730.[3442516480@qq.com].pdf | Dropped File | Stream |
Malicious
|
...
|
»
YARA Matches (1)
»
Rule Name | Rule Description | Classification | Score | Actions |
---|---|---|---|---|
DharmaEncryptedFile | File encrypted by Dharma Ransomware | Ransomware |
5/5
|
...
|
C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\AN04134_.WMF.id-B4197730.[3442516480@qq.com].pdf | Dropped File | Stream |
Malicious
|
...
|
»
YARA Matches (1)
»
Rule Name | Rule Description | Classification | Score | Actions |
---|---|---|---|---|
DharmaEncryptedFile | File encrypted by Dharma Ransomware | Ransomware |
5/5
|
...
|
C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\AN04174_.WMF.id-B4197730.[3442516480@qq.com].pdf | Dropped File | Stream |
Malicious
|
...
|
»
YARA Matches (1)
»
Rule Name | Rule Description | Classification | Score | Actions |
---|---|---|---|---|
DharmaEncryptedFile | File encrypted by Dharma Ransomware | Ransomware |
5/5
|
...
|
C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\AN04191_.WMF.id-B4197730.[3442516480@qq.com].pdf | Dropped File | Stream |
Malicious
|
...
|
»
YARA Matches (1)
»
Rule Name | Rule Description | Classification | Score | Actions |
---|---|---|---|---|
DharmaEncryptedFile | File encrypted by Dharma Ransomware | Ransomware |
5/5
|
...
|
C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\AN04195_.WMF.id-B4197730.[3442516480@qq.com].pdf | Dropped File | Stream |
Malicious
|
...
|
»
YARA Matches (1)
»
Rule Name | Rule Description | Classification | Score | Actions |
---|---|---|---|---|
DharmaEncryptedFile | File encrypted by Dharma Ransomware | Ransomware |
5/5
|
...
|
C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\AN04206_.WMF.id-B4197730.[3442516480@qq.com].pdf | Dropped File | Stream |
Malicious
|
...
|
»
YARA Matches (1)
»
Rule Name | Rule Description | Classification | Score | Actions |
---|---|---|---|---|
DharmaEncryptedFile | File encrypted by Dharma Ransomware | Ransomware |
5/5
|
...
|
C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\AN04196_.WMF.id-B4197730.[3442516480@qq.com].pdf | Dropped File | Stream |
Malicious
|
...
|
»
YARA Matches (1)
»
Rule Name | Rule Description | Classification | Score | Actions |
---|---|---|---|---|
DharmaEncryptedFile | File encrypted by Dharma Ransomware | Ransomware |
5/5
|
...
|
C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\AN04267_.WMF.id-B4197730.[3442516480@qq.com].pdf | Dropped File | Stream |
Malicious
|
...
|
»
YARA Matches (1)
»
Rule Name | Rule Description | Classification | Score | Actions |
---|---|---|---|---|
DharmaEncryptedFile | File encrypted by Dharma Ransomware | Ransomware |
5/5
|
...
|
C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\AN02559_.WMF.id-B4197730.[3442516480@qq.com].pdf | Dropped File | Stream |
Malicious
|
...
|
»
YARA Matches (1)
»
Rule Name | Rule Description | Classification | Score | Actions |
---|---|---|---|---|
DharmaEncryptedFile | File encrypted by Dharma Ransomware | Ransomware |
5/5
|
...
|
C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\AN04235_.WMF.id-B4197730.[3442516480@qq.com].pdf | Dropped File | Stream |
Malicious
|
...
|
»
YARA Matches (1)
»
Rule Name | Rule Description | Classification | Score | Actions |
---|---|---|---|---|
DharmaEncryptedFile | File encrypted by Dharma Ransomware | Ransomware |
5/5
|
...
|
C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\AN04326_.WMF.id-B4197730.[3442516480@qq.com].pdf | Dropped File | Stream |
Malicious
|
...
|
»
YARA Matches (1)
»
Rule Name | Rule Description | Classification | Score | Actions |
---|---|---|---|---|
DharmaEncryptedFile | File encrypted by Dharma Ransomware | Ransomware |
5/5
|
...
|
C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\AN04323_.WMF.id-B4197730.[3442516480@qq.com].pdf | Dropped File | Stream |
Malicious
|
...
|
»
YARA Matches (1)
»
Rule Name | Rule Description | Classification | Score | Actions |
---|---|---|---|---|
DharmaEncryptedFile | File encrypted by Dharma Ransomware | Ransomware |
5/5
|
...
|
C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\AN04269_.WMF.id-B4197730.[3442516480@qq.com].pdf | Dropped File | Stream |
Malicious
|
...
|
»
YARA Matches (1)
»
Rule Name | Rule Description | Classification | Score | Actions |
---|---|---|---|---|
DharmaEncryptedFile | File encrypted by Dharma Ransomware | Ransomware |
5/5
|
...
|
C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\AN04332_.WMF.id-B4197730.[3442516480@qq.com].pdf | Dropped File | Stream |
Malicious
|
...
|
»
YARA Matches (1)
»
Rule Name | Rule Description | Classification | Score | Actions |
---|---|---|---|---|
DharmaEncryptedFile | File encrypted by Dharma Ransomware | Ransomware |
5/5
|
...
|
C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\AN04355_.WMF.id-B4197730.[3442516480@qq.com].pdf | Dropped File | Stream |
Malicious
|
...
|
»
YARA Matches (1)
»
Rule Name | Rule Description | Classification | Score | Actions |
---|---|---|---|---|
DharmaEncryptedFile | File encrypted by Dharma Ransomware | Ransomware |
5/5
|
...
|
C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\AN04369_.WMF.id-B4197730.[3442516480@qq.com].pdf | Dropped File | Stream |
Malicious
|
...
|
»
YARA Matches (1)
»
Rule Name | Rule Description | Classification | Score | Actions |
---|---|---|---|---|
DharmaEncryptedFile | File encrypted by Dharma Ransomware | Ransomware |
5/5
|
...
|
C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\AN04385_.WMF.id-B4197730.[3442516480@qq.com].pdf | Dropped File | Stream |
Malicious
|
...
|
»
YARA Matches (1)
»
Rule Name | Rule Description | Classification | Score | Actions |
---|---|---|---|---|
DharmaEncryptedFile | File encrypted by Dharma Ransomware | Ransomware |
5/5
|
...
|
C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\BD00116_.WMF.id-B4197730.[3442516480@qq.com].pdf | Dropped File | Stream |
Malicious
|
...
|
»
YARA Matches (1)
»
Rule Name | Rule Description | Classification | Score | Actions |
---|---|---|---|---|
DharmaEncryptedFile | File encrypted by Dharma Ransomware | Ransomware |
5/5
|
...
|
C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\AN04384_.WMF.id-B4197730.[3442516480@qq.com].pdf | Dropped File | Stream |
Malicious
|
...
|
»
YARA Matches (1)
»
Rule Name | Rule Description | Classification | Score | Actions |
---|---|---|---|---|
DharmaEncryptedFile | File encrypted by Dharma Ransomware | Ransomware |
5/5
|
...
|
C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\BD00146_.WMF.id-B4197730.[3442516480@qq.com].pdf | Dropped File | Stream |
Malicious
|
...
|
»
YARA Matches (1)
»
Rule Name | Rule Description | Classification | Score | Actions |
---|---|---|---|---|
DharmaEncryptedFile | File encrypted by Dharma Ransomware | Ransomware |
5/5
|
...
|
C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\BD00155_.WMF.id-B4197730.[3442516480@qq.com].pdf | Dropped File | Stream |
Malicious
|
...
|
»
YARA Matches (1)
»
Rule Name | Rule Description | Classification | Score | Actions |
---|---|---|---|---|
DharmaEncryptedFile | File encrypted by Dharma Ransomware | Ransomware |
5/5
|
...
|
C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\BD00141_.WMF.id-B4197730.[3442516480@qq.com].pdf | Dropped File | Stream |
Malicious
|
...
|
»
YARA Matches (1)
»
Rule Name | Rule Description | Classification | Score | Actions |
---|---|---|---|---|
DharmaEncryptedFile | File encrypted by Dharma Ransomware | Ransomware |
5/5
|
...
|
C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\BD00173_.WMF.id-B4197730.[3442516480@qq.com].pdf | Dropped File | Stream |
Malicious
|
...
|
»
YARA Matches (1)
»
Rule Name | Rule Description | Classification | Score | Actions |
---|---|---|---|---|
DharmaEncryptedFile | File encrypted by Dharma Ransomware | Ransomware |
5/5
|
...
|
C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\BD05119_.WMF.id-B4197730.[3442516480@qq.com].pdf | Dropped File | Stream |
Malicious
|
...
|
»
YARA Matches (1)
»
Rule Name | Rule Description | Classification | Score | Actions |
---|---|---|---|---|
DharmaEncryptedFile | File encrypted by Dharma Ransomware | Ransomware |
5/5
|
...
|
C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\BD06102_.WMF.id-B4197730.[3442516480@qq.com].pdf | Dropped File | Stream |
Malicious
|
...
|
»
YARA Matches (1)
»
Rule Name | Rule Description | Classification | Score | Actions |
---|---|---|---|---|
DharmaEncryptedFile | File encrypted by Dharma Ransomware | Ransomware |
5/5
|
...
|
C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\BD06200_.WMF.id-B4197730.[3442516480@qq.com].pdf | Dropped File | Stream |
Malicious
|
...
|
»
YARA Matches (1)
»
Rule Name | Rule Description | Classification | Score | Actions |
---|---|---|---|---|
DharmaEncryptedFile | File encrypted by Dharma Ransomware | Ransomware |
5/5
|
...
|
C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\BD07761_.WMF.id-B4197730.[3442516480@qq.com].pdf | Dropped File | Stream |
Malicious
|
...
|
»
YARA Matches (1)
»
Rule Name | Rule Description | Classification | Score | Actions |
---|---|---|---|---|
DharmaEncryptedFile | File encrypted by Dharma Ransomware | Ransomware |
5/5
|
...
|
C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\AN04225_.WMF.id-B4197730.[3442516480@qq.com].pdf | Dropped File | Stream |
Malicious
|
...
|
»
YARA Matches (1)
»
Rule Name | Rule Description | Classification | Score | Actions |
---|---|---|---|---|
DharmaEncryptedFile | File encrypted by Dharma Ransomware | Ransomware |
5/5
|
...
|
C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\BD07831_.WMF.id-B4197730.[3442516480@qq.com].pdf | Dropped File | Stream |
Malicious
|
...
|
»
YARA Matches (1)
»
Rule Name | Rule Description | Classification | Score | Actions |
---|---|---|---|---|
DharmaEncryptedFile | File encrypted by Dharma Ransomware | Ransomware |
5/5
|
...
|
C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\BD08758_.WMF.id-B4197730.[3442516480@qq.com].pdf | Dropped File | Stream |
Malicious
|
...
|
»
YARA Matches (1)
»
Rule Name | Rule Description | Classification | Score | Actions |
---|---|---|---|---|
DharmaEncryptedFile | File encrypted by Dharma Ransomware | Ransomware |
5/5
|
...
|
C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\BD08773_.WMF.id-B4197730.[3442516480@qq.com].pdf | Dropped File | Stream |
Malicious
|
...
|
»
YARA Matches (1)
»
Rule Name | Rule Description | Classification | Score | Actions |
---|---|---|---|---|
DharmaEncryptedFile | File encrypted by Dharma Ransomware | Ransomware |
5/5
|
...
|
C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\BD08868_.WMF.id-B4197730.[3442516480@qq.com].pdf | Dropped File | Stream |
Malicious
|
...
|
»
YARA Matches (1)
»
Rule Name | Rule Description | Classification | Score | Actions |
---|---|---|---|---|
DharmaEncryptedFile | File encrypted by Dharma Ransomware | Ransomware |
5/5
|
...
|
C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\BD08808_.WMF.id-B4197730.[3442516480@qq.com].pdf | Dropped File | Stream |
Malicious
|
...
|
»
YARA Matches (1)
»
Rule Name | Rule Description | Classification | Score | Actions |
---|---|---|---|---|
DharmaEncryptedFile | File encrypted by Dharma Ransomware | Ransomware |
5/5
|
...
|
C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\BD09031_.WMF.id-B4197730.[3442516480@qq.com].pdf | Dropped File | Stream |
Malicious
|
...
|
»
YARA Matches (1)
»
Rule Name | Rule Description | Classification | Score | Actions |
---|---|---|---|---|
DharmaEncryptedFile | File encrypted by Dharma Ransomware | Ransomware |
5/5
|
...
|
C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\BD09194_.WMF.id-B4197730.[3442516480@qq.com].pdf | Dropped File | Stream |
Malicious
|
...
|
»
YARA Matches (1)
»
Rule Name | Rule Description | Classification | Score | Actions |
---|---|---|---|---|
DharmaEncryptedFile | File encrypted by Dharma Ransomware | Ransomware |
5/5
|
...
|
C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\BD09662_.WMF.id-B4197730.[3442516480@qq.com].pdf | Dropped File | Stream |
Malicious
|
...
|
»
YARA Matches (1)
»
Rule Name | Rule Description | Classification | Score | Actions |
---|---|---|---|---|
DharmaEncryptedFile | File encrypted by Dharma Ransomware | Ransomware |
5/5
|
...
|
C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\BD00160_.WMF.id-B4197730.[3442516480@qq.com].pdf | Dropped File | Stream |
Malicious
|
...
|
»
YARA Matches (1)
»
Rule Name | Rule Description | Classification | Score | Actions |
---|---|---|---|---|
DharmaEncryptedFile | File encrypted by Dharma Ransomware | Ransomware |
5/5
|
...
|
C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\BD10890_.GIF.id-B4197730.[3442516480@qq.com].pdf | Dropped File | Stream |
Malicious
|
...
|
»
YARA Matches (1)
»
Rule Name | Rule Description | Classification | Score | Actions |
---|---|---|---|---|
DharmaEncryptedFile | File encrypted by Dharma Ransomware | Ransomware |
5/5
|
...
|
C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\BD09664_.WMF.id-B4197730.[3442516480@qq.com].pdf | Dropped File | Stream |
Malicious
|
...
|
»
YARA Matches (1)
»
Rule Name | Rule Description | Classification | Score | Actions |
---|---|---|---|---|
DharmaEncryptedFile | File encrypted by Dharma Ransomware | Ransomware |
5/5
|
...
|
C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\BD19563_.GIF.id-B4197730.[3442516480@qq.com].pdf | Dropped File | Stream |
Malicious
|
...
|
»
YARA Matches (1)
»
Rule Name | Rule Description | Classification | Score | Actions |
---|---|---|---|---|
DharmaEncryptedFile | File encrypted by Dharma Ransomware | Ransomware |
5/5
|
...
|
C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\BD10972_.GIF.id-B4197730.[3442516480@qq.com].pdf | Dropped File | Stream |
Malicious
|
...
|
»
YARA Matches (1)
»
Rule Name | Rule Description | Classification | Score | Actions |
---|---|---|---|---|
DharmaEncryptedFile | File encrypted by Dharma Ransomware | Ransomware |
5/5
|
...
|
C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\BD19827_.WMF.id-B4197730.[3442516480@qq.com].pdf | Dropped File | Stream |
Malicious
|
...
|
»
YARA Matches (1)
»
Rule Name | Rule Description | Classification | Score | Actions |
---|---|---|---|---|
DharmaEncryptedFile | File encrypted by Dharma Ransomware | Ransomware |
5/5
|
...
|
C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\BD19582_.GIF.id-B4197730.[3442516480@qq.com].pdf | Dropped File | Stream |
Malicious
|
...
|
»
YARA Matches (1)
»
Rule Name | Rule Description | Classification | Score | Actions |
---|---|---|---|---|
DharmaEncryptedFile | File encrypted by Dharma Ransomware | Ransomware |
5/5
|
...
|
C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\BD19828_.WMF.id-B4197730.[3442516480@qq.com].pdf | Dropped File | Stream |
Malicious
|
...
|
»
YARA Matches (1)
»
Rule Name | Rule Description | Classification | Score | Actions |
---|---|---|---|---|
DharmaEncryptedFile | File encrypted by Dharma Ransomware | Ransomware |
5/5
|
...
|
C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\BD19695_.WMF.id-B4197730.[3442516480@qq.com].pdf | Dropped File | Stream |
Malicious
|
...
|
»
YARA Matches (1)
»
Rule Name | Rule Description | Classification | Score | Actions |
---|---|---|---|---|
DharmaEncryptedFile | File encrypted by Dharma Ransomware | Ransomware |
5/5
|
...
|
C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\BD19988_.WMF.id-B4197730.[3442516480@qq.com].pdf | Dropped File | Stream |
Malicious
|
...
|
»
YARA Matches (1)
»
Rule Name | Rule Description | Classification | Score | Actions |
---|---|---|---|---|
DharmaEncryptedFile | File encrypted by Dharma Ransomware | Ransomware |
5/5
|
...
|
C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\BL00008_.WMF.id-B4197730.[3442516480@qq.com].pdf | Dropped File | Stream |
Malicious
|
...
|
»
YARA Matches (1)
»
Rule Name | Rule Description | Classification | Score | Actions |
---|---|---|---|---|
DharmaEncryptedFile | File encrypted by Dharma Ransomware | Ransomware |
5/5
|
...
|
C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\BD20013_.WMF.id-B4197730.[3442516480@qq.com].pdf | Dropped File | Stream |
Malicious
|
...
|
»
YARA Matches (1)
»
Rule Name | Rule Description | Classification | Score | Actions |
---|---|---|---|---|
DharmaEncryptedFile | File encrypted by Dharma Ransomware | Ransomware |
5/5
|
...
|
C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\BL00012_.WMF.id-B4197730.[3442516480@qq.com].pdf | Dropped File | Stream |
Malicious
|
...
|
»
YARA Matches (1)
»
Rule Name | Rule Description | Classification | Score | Actions |
---|---|---|---|---|
DharmaEncryptedFile | File encrypted by Dharma Ransomware | Ransomware |
5/5
|
...
|
C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\BL00045_.WMF.id-B4197730.[3442516480@qq.com].pdf | Dropped File | Stream |
Malicious
|
...
|
»
YARA Matches (1)
»
Rule Name | Rule Description | Classification | Score | Actions |
---|---|---|---|---|
DharmaEncryptedFile | File encrypted by Dharma Ransomware | Ransomware |
5/5
|
...
|
C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\BL00098_.WMF.id-B4197730.[3442516480@qq.com].pdf | Dropped File | Stream |
Malicious
|
...
|
»
YARA Matches (1)
»
Rule Name | Rule Description | Classification | Score | Actions |
---|---|---|---|---|
DharmaEncryptedFile | File encrypted by Dharma Ransomware | Ransomware |
5/5
|
...
|
C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\BD19986_.WMF.id-B4197730.[3442516480@qq.com].pdf | Dropped File | Stream |
Malicious
|
...
|
»
YARA Matches (1)
»
Rule Name | Rule Description | Classification | Score | Actions |
---|---|---|---|---|
DharmaEncryptedFile | File encrypted by Dharma Ransomware | Ransomware |
5/5
|
...
|
C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\BD07804_.WMF.id-B4197730.[3442516480@qq.com].pdf | Dropped File | Stream |
Malicious
|
...
|
»
YARA Matches (1)
»
Rule Name | Rule Description | Classification | Score | Actions |
---|---|---|---|---|
DharmaEncryptedFile | File encrypted by Dharma Ransomware | Ransomware |
5/5
|
...
|
C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\BL00122_.WMF.id-B4197730.[3442516480@qq.com].pdf | Dropped File | Stream |
Malicious
|
...
|
»
YARA Matches (1)
»
Rule Name | Rule Description | Classification | Score | Actions |
---|---|---|---|---|
DharmaEncryptedFile | File encrypted by Dharma Ransomware | Ransomware |
5/5
|
...
|
C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\BL00152_.WMF.id-B4197730.[3442516480@qq.com].pdf | Dropped File | Stream |
Malicious
|
...
|
»
YARA Matches (1)
»
Rule Name | Rule Description | Classification | Score | Actions |
---|---|---|---|---|
DharmaEncryptedFile | File encrypted by Dharma Ransomware | Ransomware |
5/5
|
...
|
C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\BL00105_.WMF.id-B4197730.[3442516480@qq.com].pdf | Dropped File | Stream |
Malicious
|
...
|
»
YARA Matches (1)
»
Rule Name | Rule Description | Classification | Score | Actions |
---|---|---|---|---|
DharmaEncryptedFile | File encrypted by Dharma Ransomware | Ransomware |
5/5
|
...
|
C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\BL00194_.WMF.id-B4197730.[3442516480@qq.com].pdf | Dropped File | Stream |
Malicious
|
...
|
»
YARA Matches (1)
»
Rule Name | Rule Description | Classification | Score | Actions |
---|---|---|---|---|
DharmaEncryptedFile | File encrypted by Dharma Ransomware | Ransomware |
5/5
|
...
|
C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\BL00130_.WMF.id-B4197730.[3442516480@qq.com].pdf | Dropped File | Stream |
Malicious
|
...
|
»
YARA Matches (1)
»
Rule Name | Rule Description | Classification | Score | Actions |
---|---|---|---|---|
DharmaEncryptedFile | File encrypted by Dharma Ransomware | Ransomware |
5/5
|
...
|
C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\BL00234_.WMF.id-B4197730.[3442516480@qq.com].pdf | Dropped File | Stream |
Malicious
|
...
|
»
YARA Matches (1)
»
Rule Name | Rule Description | Classification | Score | Actions |
---|---|---|---|---|
DharmaEncryptedFile | File encrypted by Dharma Ransomware | Ransomware |
5/5
|
...
|
C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\BL00195_.WMF.id-B4197730.[3442516480@qq.com].pdf | Dropped File | Stream |
Malicious
|
...
|
»
YARA Matches (1)
»
Rule Name | Rule Description | Classification | Score | Actions |
---|---|---|---|---|
DharmaEncryptedFile | File encrypted by Dharma Ransomware | Ransomware |
5/5
|
...
|
C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\BL00248_.WMF.id-B4197730.[3442516480@qq.com].pdf | Dropped File | Stream |
Malicious
|
...
|
»
YARA Matches (1)
»
Rule Name | Rule Description | Classification | Score | Actions |
---|---|---|---|---|
DharmaEncryptedFile | File encrypted by Dharma Ransomware | Ransomware |
5/5
|
...
|
C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\BL00252_.WMF.id-B4197730.[3442516480@qq.com].pdf | Dropped File | Stream |
Malicious
|
...
|
»
YARA Matches (1)
»
Rule Name | Rule Description | Classification | Score | Actions |
---|---|---|---|---|
DharmaEncryptedFile | File encrypted by Dharma Ransomware | Ransomware |
5/5
|
...
|
C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\BL00148_.WMF.id-B4197730.[3442516480@qq.com].pdf | Dropped File | Stream |
Malicious
|
...
|
»
YARA Matches (1)
»
Rule Name | Rule Description | Classification | Score | Actions |
---|---|---|---|---|
DharmaEncryptedFile | File encrypted by Dharma Ransomware | Ransomware |
5/5
|
...
|
C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\BL00254_.WMF.id-B4197730.[3442516480@qq.com].pdf | Dropped File | Stream |
Malicious
|
...
|
»
YARA Matches (1)
»
Rule Name | Rule Description | Classification | Score | Actions |
---|---|---|---|---|
DharmaEncryptedFile | File encrypted by Dharma Ransomware | Ransomware |
5/5
|
...
|
C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\BL00242_.WMF.id-B4197730.[3442516480@qq.com].pdf | Dropped File | Stream |
Malicious
|
...
|
»
YARA Matches (1)
»
Rule Name | Rule Description | Classification | Score | Actions |
---|---|---|---|---|
DharmaEncryptedFile | File encrypted by Dharma Ransomware | Ransomware |
5/5
|
...
|
C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\BL00265_.WMF.id-B4197730.[3442516480@qq.com].pdf | Dropped File | Stream |
Malicious
|
...
|
»
YARA Matches (1)
»
Rule Name | Rule Description | Classification | Score | Actions |
---|---|---|---|---|
DharmaEncryptedFile | File encrypted by Dharma Ransomware | Ransomware |
5/5
|
...
|
C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\BL00261_.WMF.id-B4197730.[3442516480@qq.com].pdf | Dropped File | Stream |
Malicious
|
...
|
»
YARA Matches (1)
»
Rule Name | Rule Description | Classification | Score | Actions |
---|---|---|---|---|
DharmaEncryptedFile | File encrypted by Dharma Ransomware | Ransomware |
5/5
|
...
|
C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\BL00269_.WMF.id-B4197730.[3442516480@qq.com].pdf | Dropped File | Stream |
Malicious
|
...
|
»
YARA Matches (1)
»
Rule Name | Rule Description | Classification | Score | Actions |
---|---|---|---|---|
DharmaEncryptedFile | File encrypted by Dharma Ransomware | Ransomware |
5/5
|
...
|
C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\BL00267_.WMF.id-B4197730.[3442516480@qq.com].pdf | Dropped File | Stream |
Malicious
|
...
|
»
YARA Matches (1)
»
Rule Name | Rule Description | Classification | Score | Actions |
---|---|---|---|---|
DharmaEncryptedFile | File encrypted by Dharma Ransomware | Ransomware |
5/5
|
...
|
C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\BL00247_.WMF.id-B4197730.[3442516480@qq.com].pdf | Dropped File | Stream |
Malicious
|
...
|
»
YARA Matches (1)
»
Rule Name | Rule Description | Classification | Score | Actions |
---|---|---|---|---|
DharmaEncryptedFile | File encrypted by Dharma Ransomware | Ransomware |
5/5
|
...
|
C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\BL00270_.WMF.id-B4197730.[3442516480@qq.com].pdf | Dropped File | Stream |
Malicious
|
...
|
»
YARA Matches (1)
»
Rule Name | Rule Description | Classification | Score | Actions |
---|---|---|---|---|
DharmaEncryptedFile | File encrypted by Dharma Ransomware | Ransomware |
5/5
|
...
|
C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\BL00273_.WMF.id-B4197730.[3442516480@qq.com].pdf | Dropped File | Stream |
Malicious
|
...
|
»
YARA Matches (1)
»
Rule Name | Rule Description | Classification | Score | Actions |
---|---|---|---|---|
DharmaEncryptedFile | File encrypted by Dharma Ransomware | Ransomware |
5/5
|
...
|
C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\BL00274_.WMF.id-B4197730.[3442516480@qq.com].pdf | Dropped File | Stream |
Malicious
|
...
|
»
YARA Matches (1)
»
Rule Name | Rule Description | Classification | Score | Actions |
---|---|---|---|---|
DharmaEncryptedFile | File encrypted by Dharma Ransomware | Ransomware |
5/5
|
...
|
C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\BL00296_.WMF.id-B4197730.[3442516480@qq.com].pdf | Dropped File | Stream |
Malicious
|
...
|
»
YARA Matches (1)
»
Rule Name | Rule Description | Classification | Score | Actions |
---|---|---|---|---|
DharmaEncryptedFile | File encrypted by Dharma Ransomware | Ransomware |
5/5
|
...
|
C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\BL00392_.WMF.id-B4197730.[3442516480@qq.com].pdf | Dropped File | Stream |
Malicious
|
...
|
»
YARA Matches (1)
»
Rule Name | Rule Description | Classification | Score | Actions |
---|---|---|---|---|
DharmaEncryptedFile | File encrypted by Dharma Ransomware | Ransomware |
5/5
|
...
|
C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\BL00390_.WMF.id-B4197730.[3442516480@qq.com].pdf | Dropped File | Stream |
Malicious
|
...
|
»
YARA Matches (1)
»
Rule Name | Rule Description | Classification | Score | Actions |
---|---|---|---|---|
DharmaEncryptedFile | File encrypted by Dharma Ransomware | Ransomware |
5/5
|
...
|
C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\BL00525_.WMF.id-B4197730.[3442516480@qq.com].pdf | Dropped File | Stream |
Malicious
|
...
|
»
YARA Matches (1)
»
Rule Name | Rule Description | Classification | Score | Actions |
---|---|---|---|---|
DharmaEncryptedFile | File encrypted by Dharma Ransomware | Ransomware |
5/5
|
...
|
C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\BL00526_.WMF.id-B4197730.[3442516480@qq.com].pdf | Dropped File | Stream |
Malicious
|
...
|
»
YARA Matches (1)
»
Rule Name | Rule Description | Classification | Score | Actions |
---|---|---|---|---|
DharmaEncryptedFile | File encrypted by Dharma Ransomware | Ransomware |
5/5
|
...
|
C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\BL00648_.WMF.id-B4197730.[3442516480@qq.com].pdf | Dropped File | Stream |
Malicious
|
...
|
»
YARA Matches (1)
»
Rule Name | Rule Description | Classification | Score | Actions |
---|---|---|---|---|
DharmaEncryptedFile | File encrypted by Dharma Ransomware | Ransomware |
5/5
|
...
|
C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\BL00524_.WMF.id-B4197730.[3442516480@qq.com].pdf | Dropped File | Stream |
Malicious
|
...
|
»
YARA Matches (1)
»
Rule Name | Rule Description | Classification | Score | Actions |
---|---|---|---|---|
DharmaEncryptedFile | File encrypted by Dharma Ransomware | Ransomware |
5/5
|
...
|
C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\BL00923_.WMF.id-B4197730.[3442516480@qq.com].pdf | Dropped File | Stream |
Malicious
|
...
|
»
YARA Matches (1)
»
Rule Name | Rule Description | Classification | Score | Actions |
---|---|---|---|---|
DharmaEncryptedFile | File encrypted by Dharma Ransomware | Ransomware |
5/5
|
...
|
C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\BL00921_.WMF.id-B4197730.[3442516480@qq.com].pdf | Dropped File | Binary |
Malicious
|
...
|
»
YARA Matches (1)
»
Rule Name | Rule Description | Classification | Score | Actions |
---|---|---|---|---|
DharmaEncryptedFile | File encrypted by Dharma Ransomware | Ransomware |
5/5
|
...
|
C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\BL00932_.WMF.id-B4197730.[3442516480@qq.com].pdf | Dropped File | Stream |
Malicious
|
...
|
»
YARA Matches (1)
»
Rule Name | Rule Description | Classification | Score | Actions |
---|---|---|---|---|
DharmaEncryptedFile | File encrypted by Dharma Ransomware | Ransomware |
5/5
|
...
|
C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\BOAT.WMF.id-B4197730.[3442516480@qq.com].pdf | Dropped File | Stream |
Malicious
|
...
|
»
YARA Matches (1)
»
Rule Name | Rule Description | Classification | Score | Actions |
---|---|---|---|---|
DharmaEncryptedFile | File encrypted by Dharma Ransomware | Ransomware |
5/5
|
...
|
C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\BL00985_.WMF.id-B4197730.[3442516480@qq.com].pdf | Dropped File | Stream |
Malicious
|
...
|
»
YARA Matches (1)
»
Rule Name | Rule Description | Classification | Score | Actions |
---|---|---|---|---|
DharmaEncryptedFile | File encrypted by Dharma Ransomware | Ransomware |
5/5
|
...
|
C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\BS00076_.WMF.id-B4197730.[3442516480@qq.com].pdf | Dropped File | Stream |
Malicious
|
...
|
»
YARA Matches (1)
»
Rule Name | Rule Description | Classification | Score | Actions |
---|---|---|---|---|
DharmaEncryptedFile | File encrypted by Dharma Ransomware | Ransomware |
5/5
|
...
|
C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\BS00092_.WMF.id-B4197730.[3442516480@qq.com].pdf | Dropped File | Stream |
Malicious
|
...
|
»
YARA Matches (1)
»
Rule Name | Rule Description | Classification | Score | Actions |
---|---|---|---|---|
DharmaEncryptedFile | File encrypted by Dharma Ransomware | Ransomware |
5/5
|
...
|
C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\BS00078_.WMF.id-B4197730.[3442516480@qq.com].pdf | Dropped File | Stream |
Malicious
|
...
|
»
YARA Matches (1)
»
Rule Name | Rule Description | Classification | Score | Actions |
---|---|---|---|---|
DharmaEncryptedFile | File encrypted by Dharma Ransomware | Ransomware |
5/5
|
...
|
C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\BOATINST.WMF.id-B4197730.[3442516480@qq.com].pdf | Dropped File | Stream |
Malicious
|
...
|
»
YARA Matches (1)
»
Rule Name | Rule Description | Classification | Score | Actions |
---|---|---|---|---|
DharmaEncryptedFile | File encrypted by Dharma Ransomware | Ransomware |
5/5
|
...
|
C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\BS00100_.WMF.id-B4197730.[3442516480@qq.com].pdf | Dropped File | Stream |
Malicious
|
...
|
»
YARA Matches (1)
»
Rule Name | Rule Description | Classification | Score | Actions |
---|---|---|---|---|
DharmaEncryptedFile | File encrypted by Dharma Ransomware | Ransomware |
5/5
|
...
|
C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\BS00135_.WMF.id-B4197730.[3442516480@qq.com].pdf | Dropped File | Stream |
Malicious
|
...
|
»
YARA Matches (1)
»
Rule Name | Rule Description | Classification | Score | Actions |
---|---|---|---|---|
DharmaEncryptedFile | File encrypted by Dharma Ransomware | Ransomware |
5/5
|
...
|
C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\BS00145_.WMF.id-B4197730.[3442516480@qq.com].pdf | Dropped File | Stream |
Malicious
|
...
|
»
YARA Matches (1)
»
Rule Name | Rule Description | Classification | Score | Actions |
---|---|---|---|---|
DharmaEncryptedFile | File encrypted by Dharma Ransomware | Ransomware |
5/5
|
...
|
C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\BS00174_.WMF.id-B4197730.[3442516480@qq.com].pdf | Dropped File | Stream |
Malicious
|
...
|
»
YARA Matches (1)
»
Rule Name | Rule Description | Classification | Score | Actions |
---|---|---|---|---|
DharmaEncryptedFile | File encrypted by Dharma Ransomware | Ransomware |
5/5
|
...
|
C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\BS00136_.WMF.id-B4197730.[3442516480@qq.com].pdf | Dropped File | Stream |
Malicious
|
...
|
»
YARA Matches (1)
»
Rule Name | Rule Description | Classification | Score | Actions |
---|---|---|---|---|
DharmaEncryptedFile | File encrypted by Dharma Ransomware | Ransomware |
5/5
|
...
|
C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\BS00184_.WMF.id-B4197730.[3442516480@qq.com].pdf | Dropped File | Stream |
Malicious
|
...
|
»
YARA Matches (1)
»
Rule Name | Rule Description | Classification | Score | Actions |
---|---|---|---|---|
DharmaEncryptedFile | File encrypted by Dharma Ransomware | Ransomware |
5/5
|
...
|
C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\BS00186_.WMF.id-B4197730.[3442516480@qq.com].pdf | Dropped File | Stream |
Malicious
|
...
|
»
YARA Matches (1)
»
Rule Name | Rule Description | Classification | Score | Actions |
---|---|---|---|---|
DharmaEncryptedFile | File encrypted by Dharma Ransomware | Ransomware |
5/5
|
...
|
C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\BS00200_.WMF.id-B4197730.[3442516480@qq.com].pdf | Dropped File | Stream |
Malicious
|
...
|
»
YARA Matches (1)
»
Rule Name | Rule Description | Classification | Score | Actions |
---|---|---|---|---|
DharmaEncryptedFile | File encrypted by Dharma Ransomware | Ransomware |
5/5
|
...
|
C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\BS00224_.WMF.id-B4197730.[3442516480@qq.com].pdf | Dropped File | Stream |
Malicious
|
...
|
»
YARA Matches (1)
»
Rule Name | Rule Description | Classification | Score | Actions |
---|---|---|---|---|
DharmaEncryptedFile | File encrypted by Dharma Ransomware | Ransomware |
5/5
|
...
|
C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\BS00440_.WMF.id-B4197730.[3442516480@qq.com].pdf | Dropped File | Stream |
Malicious
|
...
|
»
YARA Matches (1)
»
Rule Name | Rule Description | Classification | Score | Actions |
---|---|---|---|---|
DharmaEncryptedFile | File encrypted by Dharma Ransomware | Ransomware |
5/5
|
...
|
C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\BS00439_.WMF.id-B4197730.[3442516480@qq.com].pdf | Dropped File | Stream |
Malicious
|
...
|
»
YARA Matches (1)
»
Rule Name | Rule Description | Classification | Score | Actions |
---|---|---|---|---|
DharmaEncryptedFile | File encrypted by Dharma Ransomware | Ransomware |
5/5
|
...
|
C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\BS00438_.WMF.id-B4197730.[3442516480@qq.com].pdf | Dropped File | Stream |
Malicious
|
...
|
»
YARA Matches (1)
»
Rule Name | Rule Description | Classification | Score | Actions |
---|---|---|---|---|
DharmaEncryptedFile | File encrypted by Dharma Ransomware | Ransomware |
5/5
|
...
|
C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\BS00443_.WMF.id-B4197730.[3442516480@qq.com].pdf | Dropped File | Stream |
Malicious
|
...
|
»
YARA Matches (1)
»
Rule Name | Rule Description | Classification | Score | Actions |
---|---|---|---|---|
DharmaEncryptedFile | File encrypted by Dharma Ransomware | Ransomware |
5/5
|
...
|
C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\BS00442_.WMF.id-B4197730.[3442516480@qq.com].pdf | Dropped File | Stream |
Malicious
|
...
|
»
YARA Matches (1)
»
Rule Name | Rule Description | Classification | Score | Actions |
---|---|---|---|---|
DharmaEncryptedFile | File encrypted by Dharma Ransomware | Ransomware |
5/5
|
...
|
C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\BS00441_.WMF.id-B4197730.[3442516480@qq.com].pdf | Dropped File | Stream |
Malicious
|
...
|
»
YARA Matches (1)
»
Rule Name | Rule Description | Classification | Score | Actions |
---|---|---|---|---|
DharmaEncryptedFile | File encrypted by Dharma Ransomware | Ransomware |
5/5
|
...
|
C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\BS00444_.WMF.id-B4197730.[3442516480@qq.com].pdf | Dropped File | Stream |
Malicious
|
...
|
»
YARA Matches (1)
»
Rule Name | Rule Description | Classification | Score | Actions |
---|---|---|---|---|
DharmaEncryptedFile | File encrypted by Dharma Ransomware | Ransomware |
5/5
|
...
|
C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\BS00445_.WMF.id-B4197730.[3442516480@qq.com].pdf | Dropped File | Stream |
Malicious
|
...
|
»
YARA Matches (1)
»
Rule Name | Rule Description | Classification | Score | Actions |
---|---|---|---|---|
DharmaEncryptedFile | File encrypted by Dharma Ransomware | Ransomware |
5/5
|
...
|
C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\BS01080_.WMF.id-B4197730.[3442516480@qq.com].pdf | Dropped File | Stream |
Malicious
|
...
|
»
YARA Matches (1)
»
Rule Name | Rule Description | Classification | Score | Actions |
---|---|---|---|---|
DharmaEncryptedFile | File encrypted by Dharma Ransomware | Ransomware |
5/5
|
...
|
C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\BS01603_.WMF.id-B4197730.[3442516480@qq.com].pdf | Dropped File | Stream |
Malicious
|
...
|
»
YARA Matches (1)
»
Rule Name | Rule Description | Classification | Score | Actions |
---|---|---|---|---|
DharmaEncryptedFile | File encrypted by Dharma Ransomware | Ransomware |
5/5
|
...
|
C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\BS01634_.WMF.id-B4197730.[3442516480@qq.com].pdf | Dropped File | Stream |
Malicious
|
...
|
»
YARA Matches (1)
»
Rule Name | Rule Description | Classification | Score | Actions |
---|---|---|---|---|
DharmaEncryptedFile | File encrypted by Dharma Ransomware | Ransomware |
5/5
|
...
|
C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\BS01635_.WMF.id-B4197730.[3442516480@qq.com].pdf | Dropped File | Stream |
Malicious
|
...
|
»
YARA Matches (1)
»
Rule Name | Rule Description | Classification | Score | Actions |
---|---|---|---|---|
DharmaEncryptedFile | File encrypted by Dharma Ransomware | Ransomware |
5/5
|
...
|
C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\BS01636_.WMF.id-B4197730.[3442516480@qq.com].pdf | Dropped File | Stream |
Malicious
|
...
|
»
YARA Matches (1)
»
Rule Name | Rule Description | Classification | Score | Actions |
---|---|---|---|---|
DharmaEncryptedFile | File encrypted by Dharma Ransomware | Ransomware |
5/5
|
...
|
C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\BS01637_.WMF.id-B4197730.[3442516480@qq.com].pdf | Dropped File | Stream |
Malicious
|
...
|
»
YARA Matches (1)
»
Rule Name | Rule Description | Classification | Score | Actions |
---|---|---|---|---|
DharmaEncryptedFile | File encrypted by Dharma Ransomware | Ransomware |
5/5
|
...
|
C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\BS00453_.WMF.id-B4197730.[3442516480@qq.com].pdf | Dropped File | Stream |
Malicious
|
...
|
»
YARA Matches (1)
»
Rule Name | Rule Description | Classification | Score | Actions |
---|---|---|---|---|
DharmaEncryptedFile | File encrypted by Dharma Ransomware | Ransomware |
5/5
|
...
|
C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\BS01638_.WMF.id-B4197730.[3442516480@qq.com].pdf | Dropped File | Stream |
Malicious
|
...
|
»
YARA Matches (1)
»
Rule Name | Rule Description | Classification | Score | Actions |
---|---|---|---|---|
DharmaEncryptedFile | File encrypted by Dharma Ransomware | Ransomware |
5/5
|
...
|
C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\CG1606.WMF.id-B4197730.[3442516480@qq.com].pdf | Dropped File | Stream |
Malicious
|
...
|
»
YARA Matches (1)
»
Rule Name | Rule Description | Classification | Score | Actions |
---|---|---|---|---|
DharmaEncryptedFile | File encrypted by Dharma Ransomware | Ransomware |
5/5
|
...
|
C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\CLASSIC1.WMF.id-B4197730.[3442516480@qq.com].pdf | Dropped File | Stream |
Malicious
|
...
|
»
YARA Matches (1)
»
Rule Name | Rule Description | Classification | Score | Actions |
---|---|---|---|---|
DharmaEncryptedFile | File encrypted by Dharma Ransomware | Ransomware |
5/5
|
...
|
C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\CLASSIC2.WMF.id-B4197730.[3442516480@qq.com].pdf | Dropped File | Stream |
Malicious
|
...
|
»
YARA Matches (1)
»
Rule Name | Rule Description | Classification | Score | Actions |
---|---|---|---|---|
DharmaEncryptedFile | File encrypted by Dharma Ransomware | Ransomware |
5/5
|
...
|
C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\BS01639_.WMF.id-B4197730.[3442516480@qq.com].pdf | Dropped File | Stream |
Malicious
|
...
|
»
YARA Matches (1)
»
Rule Name | Rule Description | Classification | Score | Actions |
---|---|---|---|---|
DharmaEncryptedFile | File encrypted by Dharma Ransomware | Ransomware |
5/5
|
...
|
C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\BL00262_.WMF.id-B4197730.[3442516480@qq.com].pdf | Dropped File | Stream |
Malicious
|
...
|
»
YARA Matches (1)
»
Rule Name | Rule Description | Classification | Score | Actions |
---|---|---|---|---|
DharmaEncryptedFile | File encrypted by Dharma Ransomware | Ransomware |
5/5
|
...
|
C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\CRANE.WMF.id-B4197730.[3442516480@qq.com].pdf | Dropped File | Stream |
Malicious
|
...
|
»
YARA Matches (1)
»
Rule Name | Rule Description | Classification | Score | Actions |
---|---|---|---|---|
DharmaEncryptedFile | File encrypted by Dharma Ransomware | Ransomware |
5/5
|
...
|
C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\CRANINST.WMF.id-B4197730.[3442516480@qq.com].pdf | Dropped File | Stream |
Malicious
|
...
|
»
YARA Matches (1)
»
Rule Name | Rule Description | Classification | Score | Actions |
---|---|---|---|---|
DharmaEncryptedFile | File encrypted by Dharma Ransomware | Ransomware |
5/5
|
...
|
C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\CUP.WMF.id-B4197730.[3442516480@qq.com].pdf | Dropped File | Stream |
Malicious
|
...
|
»
YARA Matches (1)
»
Rule Name | Rule Description | Classification | Score | Actions |
---|---|---|---|---|
DharmaEncryptedFile | File encrypted by Dharma Ransomware | Ransomware |
5/5
|
...
|
C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\CUPINST.WMF.id-B4197730.[3442516480@qq.com].pdf | Dropped File | Binary |
Malicious
|
...
|
»
YARA Matches (1)
»
Rule Name | Rule Description | Classification | Score | Actions |
---|---|---|---|---|
DharmaEncryptedFile | File encrypted by Dharma Ransomware | Ransomware |
5/5
|
...
|
C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\DD00117_.WMF.id-B4197730.[3442516480@qq.com].pdf | Dropped File | Stream |
Malicious
|
...
|
»
YARA Matches (1)
»
Rule Name | Rule Description | Classification | Score | Actions |
---|---|---|---|---|
DharmaEncryptedFile | File encrypted by Dharma Ransomware | Ransomware |
5/5
|
...
|
C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\DD00121_.WMF.id-B4197730.[3442516480@qq.com].pdf | Dropped File | Stream |
Malicious
|
...
|
»
YARA Matches (1)
»
Rule Name | Rule Description | Classification | Score | Actions |
---|---|---|---|---|
DharmaEncryptedFile | File encrypted by Dharma Ransomware | Ransomware |
5/5
|
...
|
C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\DD00234_.WMF.id-B4197730.[3442516480@qq.com].pdf | Dropped File | Stream |
Malicious
|
...
|
»
YARA Matches (1)
»
Rule Name | Rule Description | Classification | Score | Actions |
---|---|---|---|---|
DharmaEncryptedFile | File encrypted by Dharma Ransomware | Ransomware |
5/5
|
...
|
C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\DD00255_.WMF.id-B4197730.[3442516480@qq.com].pdf | Dropped File | Stream |
Malicious
|
...
|
»
YARA Matches (1)
»
Rule Name | Rule Description | Classification | Score | Actions |
---|---|---|---|---|
DharmaEncryptedFile | File encrypted by Dharma Ransomware | Ransomware |
5/5
|
...
|
C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\DD00256_.WMF.id-B4197730.[3442516480@qq.com].pdf | Dropped File | Stream |
Malicious
|
...
|
»
YARA Matches (1)
»
Rule Name | Rule Description | Classification | Score | Actions |
---|---|---|---|---|
DharmaEncryptedFile | File encrypted by Dharma Ransomware | Ransomware |
5/5
|
...
|
C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\DD00297_.WMF.id-B4197730.[3442516480@qq.com].pdf | Dropped File | Stream |
Malicious
|
...
|
»
YARA Matches (1)
»
Rule Name | Rule Description | Classification | Score | Actions |
---|---|---|---|---|
DharmaEncryptedFile | File encrypted by Dharma Ransomware | Ransomware |
5/5
|
...
|
C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\DD00372_.WMF.id-B4197730.[3442516480@qq.com].pdf | Dropped File | Stream |
Malicious
|
...
|
»
YARA Matches (1)
»
Rule Name | Rule Description | Classification | Score | Actions |
---|---|---|---|---|
DharmaEncryptedFile | File encrypted by Dharma Ransomware | Ransomware |
5/5
|
...
|
C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\DD00405_.WMF.id-B4197730.[3442516480@qq.com].pdf | Dropped File | Stream |
Malicious
|
...
|
»
YARA Matches (1)
»
Rule Name | Rule Description | Classification | Score | Actions |
---|---|---|---|---|
DharmaEncryptedFile | File encrypted by Dharma Ransomware | Ransomware |
5/5
|
...
|
C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\DD00407_.WMF.id-B4197730.[3442516480@qq.com].pdf | Dropped File | Stream |
Malicious
|
...
|
»
YARA Matches (1)
»
Rule Name | Rule Description | Classification | Score | Actions |
---|---|---|---|---|
DharmaEncryptedFile | File encrypted by Dharma Ransomware | Ransomware |
5/5
|
...
|
C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\DD00413_.WMF.id-B4197730.[3442516480@qq.com].pdf | Dropped File | Stream |
Malicious
|
...
|
»
YARA Matches (1)
»
Rule Name | Rule Description | Classification | Score | Actions |
---|---|---|---|---|
DharmaEncryptedFile | File encrypted by Dharma Ransomware | Ransomware |
5/5
|
...
|
C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\DD00414_.WMF.id-B4197730.[3442516480@qq.com].pdf | Dropped File | Stream |
Malicious
|
...
|
»
YARA Matches (1)
»
Rule Name | Rule Description | Classification | Score | Actions |
---|---|---|---|---|
DharmaEncryptedFile | File encrypted by Dharma Ransomware | Ransomware |
5/5
|
...
|
C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\DD00419_.WMF.id-B4197730.[3442516480@qq.com].pdf | Dropped File | Stream |
Malicious
|
...
|
»
YARA Matches (1)
»
Rule Name | Rule Description | Classification | Score | Actions |
---|---|---|---|---|
DharmaEncryptedFile | File encrypted by Dharma Ransomware | Ransomware |
5/5
|
...
|
C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\DD00448_.WMF.id-B4197730.[3442516480@qq.com].pdf | Dropped File | Stream |
Malicious
|
...
|
»
YARA Matches (1)
»
Rule Name | Rule Description | Classification | Score | Actions |
---|---|---|---|---|
DharmaEncryptedFile | File encrypted by Dharma Ransomware | Ransomware |
5/5
|
...
|
C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\DD00449_.WMF.id-B4197730.[3442516480@qq.com].pdf | Dropped File | Stream |
Malicious
|
...
|
»
YARA Matches (1)
»
Rule Name | Rule Description | Classification | Score | Actions |
---|---|---|---|---|
DharmaEncryptedFile | File encrypted by Dharma Ransomware | Ransomware |
5/5
|
...
|
C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\DD00687_.WMF.id-B4197730.[3442516480@qq.com].pdf | Dropped File | Stream |
Malicious
|
...
|
»
YARA Matches (1)
»
Rule Name | Rule Description | Classification | Score | Actions |
---|---|---|---|---|
DharmaEncryptedFile | File encrypted by Dharma Ransomware | Ransomware |
5/5
|
...
|
C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\DD00261_.WMF.id-B4197730.[3442516480@qq.com].pdf | Dropped File | Stream |
Malicious
|
...
|
»
YARA Matches (1)
»
Rule Name | Rule Description | Classification | Score | Actions |
---|---|---|---|---|
DharmaEncryptedFile | File encrypted by Dharma Ransomware | Ransomware |
5/5
|
...
|
C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\DD01015_.WMF.id-B4197730.[3442516480@qq.com].pdf | Dropped File | Stream |
Malicious
|
...
|
»
YARA Matches (1)
»
Rule Name | Rule Description | Classification | Score | Actions |
---|---|---|---|---|
DharmaEncryptedFile | File encrypted by Dharma Ransomware | Ransomware |
5/5
|
...
|
C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\DD01039_.WMF.id-B4197730.[3442516480@qq.com].pdf | Dropped File | Stream |
Malicious
|
...
|
»
YARA Matches (1)
»
Rule Name | Rule Description | Classification | Score | Actions |
---|---|---|---|---|
DharmaEncryptedFile | File encrypted by Dharma Ransomware | Ransomware |
5/5
|
...
|
C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\DD00705_.WMF.id-B4197730.[3442516480@qq.com].pdf | Dropped File | Stream |
Malicious
|
...
|
»
YARA Matches (1)
»
Rule Name | Rule Description | Classification | Score | Actions |
---|---|---|---|---|
DharmaEncryptedFile | File encrypted by Dharma Ransomware | Ransomware |
5/5
|
...
|
C:\Logs\Setup.evtx.id-B4197730.[3442516480@qq.com].pdf | Dropped File | Stream |
Malicious
|
...
|
»
YARA Matches (1)
»
Rule Name | Rule Description | Classification | Score | Actions |
---|---|---|---|---|
DharmaEncryptedFile | File encrypted by Dharma Ransomware | Ransomware |
5/5
|
...
|
C:\Logs\Security.evtx.id-B4197730.[3442516480@qq.com].pdf | Dropped File | Stream |
Malicious
|
...
|
»
YARA Matches (1)
»
Rule Name | Rule Description | Classification | Score | Actions |
---|---|---|---|---|
DharmaEncryptedFile | File encrypted by Dharma Ransomware | Ransomware |
5/5
|
...
|
C:\Program Files\Common Files\DESIGNER\MSADDNDR.OLB.id-B4197730.[3442516480@qq.com].pdf | Dropped File | Stream |
Malicious
|
...
|
»
YARA Matches (1)
»
Rule Name | Rule Description | Classification | Score | Actions |
---|---|---|---|---|
DharmaEncryptedFile | File encrypted by Dharma Ransomware | Ransomware |
5/5
|
...
|
C:\Logs\System.evtx.id-B4197730.[3442516480@qq.com].pdf | Dropped File | Stream |
Malicious
|
...
|
»
YARA Matches (1)
»
Rule Name | Rule Description | Classification | Score | Actions |
---|---|---|---|---|
DharmaEncryptedFile | File encrypted by Dharma Ransomware | Ransomware |
5/5
|
...
|
C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\DD00437_.WMF.id-B4197730.[3442516480@qq.com].pdf | Dropped File | Stream |
Malicious
|
...
|
»
YARA Matches (1)
»
Rule Name | Rule Description | Classification | Score | Actions |
---|---|---|---|---|
DharmaEncryptedFile | File encrypted by Dharma Ransomware | Ransomware |
5/5
|
...
|
C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\DD01138_.WMF.id-B4197730.[3442516480@qq.com].pdf | Dropped File | Stream |
Malicious
|
...
|
»
YARA Matches (1)
»
Rule Name | Rule Description | Classification | Score | Actions |
---|---|---|---|---|
DharmaEncryptedFile | File encrypted by Dharma Ransomware | Ransomware |
5/5
|
...
|
C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\DD01139_.WMF.id-B4197730.[3442516480@qq.com].pdf | Dropped File | Stream |
Malicious
|
...
|
»
YARA Matches (1)
»
Rule Name | Rule Description | Classification | Score | Actions |
---|---|---|---|---|
DharmaEncryptedFile | File encrypted by Dharma Ransomware | Ransomware |
5/5
|
...
|
C:\$Recycle.Bin\S-1-5-18\desktop.ini.id-B4197730.[3442516480@qq.com].pdf | Dropped File | Stream |
Unknown
|
...
|
»
C:\588bce7c90097ed212\netfx_Core.mzz.id-B4197730.[3442516480@qq.com].pdf | Dropped File | Stream |
Unknown
|
...
|
»
C:\Program Files\Java\jre1.8.0_144\lib\images\cursors\win32_LinkDrop32x32.gif.id-B4197730.[3442516480@qq.com].pdf | Dropped File | Stream |
Unknown
|
...
|
»
C:\Program Files\Microsoft Office\FileSystemMetadata.xml.id-B4197730.[3442516480@qq.com].pdf | Dropped File | Stream |
Unknown
|
...
|
»
C:\Program Files\Microsoft Office\PackageManifests\AppXManifest.90160000-001B-0000-1000-0000000FF1CE.xml.id-B4197730.[3442516480@qq.com].pdf | Dropped File | Stream |
Unknown
|
...
|
»
C:\Program Files\Microsoft Office\PackageManifests\AppXManifest.90160000-001F-0409-1000-0000000FF1CE.xml.id-B4197730.[3442516480@qq.com].pdf | Dropped File | Stream |
Unknown
|
...
|
»
C:\Program Files\Microsoft Office\PackageManifests\AppXManifest.90160000-001F-040C-1000-0000000FF1CE.xml.id-B4197730.[3442516480@qq.com].pdf | Dropped File | Stream |
Unknown
|
...
|
»
C:\Program Files\Microsoft Office\PackageManifests\AppXManifest.90160000-001F-0C0A-1000-0000000FF1CE.xml.id-B4197730.[3442516480@qq.com].pdf | Dropped File | Stream |
Unknown
|
...
|
»
C:\Program Files\Microsoft Office\PackageManifests\AppXManifest.90160000-0027-0000-1000-0000000FF1CE.xml.id-B4197730.[3442516480@qq.com].pdf | Dropped File | Stream |
Unknown
|
...
|
»
C:\Program Files\Microsoft Office\PackageManifests\AppXManifest.90160000-0054-0409-1000-0000000FF1CE.xml.id-B4197730.[3442516480@qq.com].pdf | Dropped File | Stream |
Unknown
|
...
|
»
C:\Program Files\Microsoft Office\PackageManifests\AppXManifest.90160000-0057-0000-1000-0000000FF1CE.xml.id-B4197730.[3442516480@qq.com].pdf | Dropped File | Stream |
Unknown
|
...
|
»
C:\588bce7c90097ed212\Windows6.1-KB958488-v6001-x86.msu.id-B4197730.[3442516480@qq.com].pdf | Dropped File | Stream |
Unknown
|
...
|
»
C:\Program Files\Microsoft Office\PackageManifests\AppXManifest.90160000-00A1-0000-1000-0000000FF1CE.xml.id-B4197730.[3442516480@qq.com].pdf | Dropped File | Stream |
Unknown
|
...
|
»
C:\Logs\Key Management Service.evtx.id-B4197730.[3442516480@qq.com].pdf | Dropped File | Stream |
Unknown
|
...
|
»
C:\Program Files\Microsoft Office\PackageManifests\AppXManifest.90160000-00E1-0000-1000-0000000FF1CE.xml.id-B4197730.[3442516480@qq.com].pdf | Dropped File | Stream |
Unknown
|
...
|
»
C:\Program Files\Microsoft Office\PackageManifests\AppXManifest.90160000-0117-0409-1000-0000000FF1CE.xml.id-B4197730.[3442516480@qq.com].pdf | Dropped File | Stream |
Unknown
|
...
|
»
C:\Program Files\Microsoft Office\PackageManifests\AppXManifest.90160000-012A-0000-1000-0000000FF1CE.xml.id-B4197730.[3442516480@qq.com].pdf | Dropped File | Stream |
Unknown
|
...
|
»
C:\Logs\Microsoft-Windows-AppReadiness%4Admin.evtx.id-B4197730.[3442516480@qq.com].pdf | Dropped File | Stream |
Unknown
|
...
|
»
C:\Program Files\Microsoft Office\PackageManifests\AppXManifest.common.xml.id-B4197730.[3442516480@qq.com].pdf | Dropped File | Stream |
Unknown
|
...
|
»
C:\Logs\Microsoft-Windows-Crypto-DPAPI%4Operational.evtx.id-B4197730.[3442516480@qq.com].pdf | Dropped File | Stream |
Unknown
|
...
|
»
C:\Logs\Microsoft-Windows-Diagnosis-DPS%4Operational.evtx.id-B4197730.[3442516480@qq.com].pdf | Dropped File | Stream |
Unknown
|
...
|
»
C:\Logs\Microsoft-Windows-Hyper-V-Guest-Drivers%4Admin.evtx.id-B4197730.[3442516480@qq.com].pdf | Dropped File | Stream |
Unknown
|
...
|
»
C:\Logs\Microsoft-Windows-Kernel-EventTracing%4Admin.evtx.id-B4197730.[3442516480@qq.com].pdf | Dropped File | Stream |
Unknown
|
...
|
»
C:\Logs\Microsoft-Windows-GroupPolicy%4Operational.evtx.id-B4197730.[3442516480@qq.com].pdf | Dropped File | Stream |
Unknown
|
...
|
»
C:\Logs\Microsoft-Windows-Kernel-Power%4Thermal-Operational.evtx.id-B4197730.[3442516480@qq.com].pdf | Dropped File | Stream |
Unknown
|
...
|
»
C:\Logs\Microsoft-Windows-Kernel-ShimEngine%4Operational.evtx.id-B4197730.[3442516480@qq.com].pdf | Dropped File | Stream |
Unknown
|
...
|
»
C:\Logs\Microsoft-Windows-LiveId%4Operational.evtx.id-B4197730.[3442516480@qq.com].pdf | Dropped File | Stream |
Unknown
|
...
|
»
C:\Logs\Microsoft-Windows-Kernel-PnP%4Configuration.evtx.id-B4197730.[3442516480@qq.com].pdf | Dropped File | Stream |
Unknown
|
...
|
»
C:\Logs\Microsoft-Windows-NCSI%4Operational.evtx.id-B4197730.[3442516480@qq.com].pdf | Dropped File | Stream |
Unknown
|
...
|
»
C:\Logs\Microsoft-Windows-Ntfs%4Operational.evtx.id-B4197730.[3442516480@qq.com].pdf | Dropped File | Stream |
Unknown
|
...
|
»
C:\Logs\Microsoft-Windows-Ntfs%4WHC.evtx.id-B4197730.[3442516480@qq.com].pdf | Dropped File | Stream |
Unknown
|
...
|
»
C:\Logs\Microsoft-Windows-MUI%4Operational.evtx.id-B4197730.[3442516480@qq.com].pdf | Dropped File | Stream |
Unknown
|
...
|
»
C:\Logs\Microsoft-Windows-SmbClient%4Connectivity.evtx.id-B4197730.[3442516480@qq.com].pdf | Dropped File | Stream |
Unknown
|
...
|
»
C:\Logs\Microsoft-Windows-SMBClient%4Operational.evtx.id-B4197730.[3442516480@qq.com].pdf | Dropped File | Stream |
Unknown
|
...
|
»
C:\Logs\Microsoft-Windows-SmbClient%4Security.evtx.id-B4197730.[3442516480@qq.com].pdf | Dropped File | Stream |
Unknown
|
...
|
»
C:\Logs\Microsoft-Windows-TerminalServices-LocalSessionManager%4Admin.evtx.id-B4197730.[3442516480@qq.com].pdf | Dropped File | Stream |
Unknown
|
...
|
»
C:\Logs\Microsoft-Windows-TerminalServices-LocalSessionManager%4Operational.evtx.id-B4197730.[3442516480@qq.com].pdf | Dropped File | Stream |
Unknown
|
...
|
»
C:\Logs\Microsoft-Windows-Windows Firewall With Advanced Security%4ConnectionSecurity.evtx.id-B4197730.[3442516480@qq.com].pdf | Dropped File | Stream |
Unknown
|
...
|
»
C:\Logs\Microsoft-Windows-TWinUI%4Operational.evtx.id-B4197730.[3442516480@qq.com].pdf | Dropped File | Stream |
Unknown
|
...
|
»
C:\Logs\Microsoft-Windows-Windows Firewall With Advanced Security%4Firewall.evtx.id-B4197730.[3442516480@qq.com].pdf | Dropped File | Stream |
Unknown
|
...
|
»
C:\Program Files\Common Files\microsoft shared\ClickToRun\api-ms-win-core-localization-l1-2-0.dll.id-B4197730.[3442516480@qq.com].pdf | Dropped File | Stream |
Unknown
|
...
|
»
C:\Program Files\Common Files\microsoft shared\ClickToRun\api-ms-win-core-timezone-l1-1-0.dll.id-B4197730.[3442516480@qq.com].pdf | Dropped File | Stream |
Unknown
|
...
|
»
C:\Program Files\Common Files\microsoft shared\ClickToRun\api-ms-win-crt-environment-l1-1-0.dll.id-B4197730.[3442516480@qq.com].pdf | Dropped File | Stream |
Unknown
|
...
|
»
C:\Program Files\Common Files\microsoft shared\ClickToRun\api-ms-win-crt-locale-l1-1-0.dll.id-B4197730.[3442516480@qq.com].pdf | Dropped File | Stream |
Unknown
|
...
|
»
C:\Program Files\Common Files\microsoft shared\ClickToRun\api-ms-win-core-processthreads-l1-1-1.dll.id-B4197730.[3442516480@qq.com].pdf | Dropped File | Stream |
Unknown
|
...
|
»
C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\DD01151_.WMF.id-B4197730.[3442516480@qq.com].pdf | Dropped File | Unknown |
Unknown
|
...
|
»
C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\DD01157_.WMF.id-B4197730.[3442516480@qq.com].pdf | Dropped File | Unknown |
Unknown
|
...
|
»
C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\DD01160_.WMF.id-B4197730.[3442516480@qq.com].pdf | Dropped File | Unknown |
Unknown
|
...
|
»
C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\DD01163_.WMF.id-B4197730.[3442516480@qq.com].pdf | Dropped File | Unknown |
Unknown
|
...
|
»
C:\$GetCurrent\Logs\downlevel_2017_09_07_02_02_39_766.log.id-B4197730.[3442516480@qq.com].pdf | Dropped File | Stream |
Not Queried
|
...
|
»
C:\$GetCurrent\Logs\oobe_2017_09_07_03_08_57_737.log.id-B4197730.[3442516480@qq.com].pdf | Dropped File | Stream |
Not Queried
|
...
|
»
C:\$GetCurrent\Logs\PartnerSetupCompleteResult.log.id-B4197730.[3442516480@qq.com].pdf | Dropped File | Stream |
Not Queried
|
...
|
»
C:\$GetCurrent\SafeOS\PartnerSetupComplete.cmd.id-B4197730.[3442516480@qq.com].pdf | Dropped File | Stream |
Not Queried
|
...
|
»
C:\$GetCurrent\SafeOS\preoobe.cmd.id-B4197730.[3442516480@qq.com].pdf | Dropped File | Stream |
Not Queried
|
...
|
»
C:\$GetCurrent\SafeOS\GetCurrentRollback.ini.id-B4197730.[3442516480@qq.com].pdf | Dropped File | Stream |
Not Queried
|
...
|
»
C:\$Recycle.Bin\S-1-5-21-1051304884-625712362-2192934891-1000\desktop.ini.id-B4197730.[3442516480@qq.com].pdf | Dropped File | Stream |
Not Queried
|
...
|
»
C:\588bce7c90097ed212\netfx_Core_x64.msi.id-B4197730.[3442516480@qq.com].pdf | Dropped File | Stream |
Not Queried
|
...
|
»
C:\Program Files\Common Files\microsoft shared\ClickToRun\C2RHeartbeatConfig.xml.id-B4197730.[3442516480@qq.com].pdf | Dropped File | Stream |
Not Queried
|
...
|
»
C:\Program Files\Common Files\microsoft shared\ClickToRun\OfficeUpdateSchedule.xml.id-B4197730.[3442516480@qq.com].pdf | Dropped File | Stream |
Not Queried
|
...
|
»
C:\Program Files\Common Files\microsoft shared\ClickToRun\ServiceWatcherSchedule.xml.id-B4197730.[3442516480@qq.com].pdf | Dropped File | Stream |
Not Queried
|
...
|
»
C:\588bce7c90097ed212\netfx_Extended_x64.msi.id-B4197730.[3442516480@qq.com].pdf | Dropped File | Stream |
Not Queried
|
...
|
»
C:\588bce7c90097ed212\netfx_Extended.mzz.id-B4197730.[3442516480@qq.com].pdf | Dropped File | Stream |
Not Queried
|
...
|
»
C:\588bce7c90097ed212\netfx_Extended_x86.msi.id-B4197730.[3442516480@qq.com].pdf | Dropped File | Stream |
Not Queried
|
...
|
»
C:\Program Files\Java\jre1.8.0_144\lib\images\cursors\invalid32x32.gif.id-B4197730.[3442516480@qq.com].pdf | Dropped File | Stream |
Not Queried
|
...
|
»
C:\Program Files\Java\jre1.8.0_144\lib\images\cursors\win32_CopyDrop32x32.gif.id-B4197730.[3442516480@qq.com].pdf | Dropped File | Stream |
Not Queried
|
...
|
»
C:\Program Files\Java\jre1.8.0_144\lib\images\cursors\win32_CopyNoDrop32x32.gif.id-B4197730.[3442516480@qq.com].pdf | Dropped File | Stream |
Not Queried
|
...
|
»
C:\Program Files\Java\jre1.8.0_144\lib\images\cursors\win32_LinkNoDrop32x32.gif.id-B4197730.[3442516480@qq.com].pdf | Dropped File | Stream |
Not Queried
|
...
|
»
C:\Program Files\Java\jre1.8.0_144\lib\images\cursors\win32_MoveDrop32x32.gif.id-B4197730.[3442516480@qq.com].pdf | Dropped File | Stream |
Not Queried
|
...
|
»
C:\Program Files\Java\jre1.8.0_144\lib\images\cursors\win32_MoveNoDrop32x32.gif.id-B4197730.[3442516480@qq.com].pdf | Dropped File | Stream |
Not Queried
|
...
|
»
C:\Program Files\Java\jre1.8.0_144\README.txt.id-B4197730.[3442516480@qq.com].pdf | Dropped File | Stream |
Not Queried
|
...
|
»
C:\Program Files\Java\jre1.8.0_144\THIRDPARTYLICENSEREADME-JAVAFX.txt.id-B4197730.[3442516480@qq.com].pdf | Dropped File | Stream |
Not Queried
|
...
|
»
C:\Program Files\Java\jre1.8.0_144\THIRDPARTYLICENSEREADME.txt.id-B4197730.[3442516480@qq.com].pdf | Dropped File | Stream |
Not Queried
|
...
|
»
C:\Program Files\Microsoft Office\PackageManifests\AppXManifest.90160000-0015-0000-1000-0000000FF1CE.xml.id-B4197730.[3442516480@qq.com].pdf | Dropped File | Stream |
Not Queried
|
...
|
»
C:\Program Files\Microsoft Office\PackageManifests\AppXManifest.90160000-0016-0000-1000-0000000FF1CE.xml.id-B4197730.[3442516480@qq.com].pdf | Dropped File | Stream |
Not Queried
|
...
|
»
C:\588bce7c90097ed212\Windows6.0-KB956250-v6001-x86.msu.id-B4197730.[3442516480@qq.com].pdf | Dropped File | Stream |
Not Queried
|
...
|
»
C:\588bce7c90097ed212\Windows6.0-KB956250-v6001-x64.msu.id-B4197730.[3442516480@qq.com].pdf | Dropped File | Stream |
Not Queried
|
...
|
»
C:\Program Files\Microsoft Office\PackageManifests\AppXManifest.90160000-0016-0409-1000-0000000FF1CE.xml.id-B4197730.[3442516480@qq.com].pdf | Dropped File | Stream |
Not Queried
|
...
|
»
C:\Program Files\Microsoft Office\AppXManifest.xml.id-B4197730.[3442516480@qq.com].pdf | Dropped File | Stream |
Not Queried
|
...
|
»
C:\Program Files\Microsoft Office\PackageManifests\AppXManifest.90160000-0015-0409-1000-0000000FF1CE.xml.id-B4197730.[3442516480@qq.com].pdf | Dropped File | Stream |
Not Queried
|
...
|
»
C:\Program Files\Microsoft Office\PackageManifests\AppXManifest.90160000-0018-0000-1000-0000000FF1CE.xml.id-B4197730.[3442516480@qq.com].pdf | Dropped File | Stream |
Not Queried
|
...
|
»
C:\Program Files\Microsoft Office\PackageManifests\AppXManifest.90160000-0019-0000-1000-0000000FF1CE.xml.id-B4197730.[3442516480@qq.com].pdf | Dropped File | Stream |
Not Queried
|
...
|
»
C:\Program Files\Microsoft Office\PackageManifests\AppXManifest.90160000-0018-0409-1000-0000000FF1CE.xml.id-B4197730.[3442516480@qq.com].pdf | Dropped File | Stream |
Not Queried
|
...
|
»
C:\Program Files\Microsoft Office\PackageManifests\AppXManifest.90160000-0019-0409-1000-0000000FF1CE.xml.id-B4197730.[3442516480@qq.com].pdf | Dropped File | Stream |
Not Queried
|
...
|
»
C:\Program Files\Microsoft Office\PackageManifests\AppXManifest.90160000-001A-0409-1000-0000000FF1CE.xml.id-B4197730.[3442516480@qq.com].pdf | Dropped File | Stream |
Not Queried
|
...
|
»
C:\Program Files\Microsoft Office\PackageManifests\AppXManifest.90160000-001A-0000-1000-0000000FF1CE.xml.id-B4197730.[3442516480@qq.com].pdf | Dropped File | Stream |
Not Queried
|
...
|
»
C:\Program Files\Microsoft Office\PackageManifests\AppXManifest.90160000-001B-0409-1000-0000000FF1CE.xml.id-B4197730.[3442516480@qq.com].pdf | Dropped File | Stream |
Not Queried
|
...
|
»
C:\Program Files\Microsoft Office\PackageManifests\AppXManifest.90160000-002C-0409-1000-0000000FF1CE.xml.id-B4197730.[3442516480@qq.com].pdf | Dropped File | Stream |
Not Queried
|
...
|
»
C:\588bce7c90097ed212\Windows6.1-KB958488-v6001-x64.msu.id-B4197730.[3442516480@qq.com].pdf | Dropped File | Stream |
Not Queried
|
...
|
»
C:\Program Files\Microsoft Office\PackageManifests\AppXManifest.90160000-006E-0409-1000-0000000FF1CE.xml.id-B4197730.[3442516480@qq.com].pdf | Dropped File | Stream |
Not Queried
|
...
|
»
C:\Program Files\Microsoft Office\PackageManifests\AppXManifest.90160000-0090-0000-1000-0000000FF1CE.xml.id-B4197730.[3442516480@qq.com].pdf | Dropped File | Stream |
Not Queried
|
...
|
»
C:\Logs\Internet Explorer.evtx.id-B4197730.[3442516480@qq.com].pdf | Dropped File | Stream |
Not Queried
|
...
|
»
C:\Program Files\Microsoft Office\PackageManifests\AppXManifest.90160000-00A1-0409-1000-0000000FF1CE.xml.id-B4197730.[3442516480@qq.com].pdf | Dropped File | Stream |
Not Queried
|
...
|
»
C:\Program Files\Microsoft Office\PackageManifests\AppXManifest.90160000-00B4-0409-1000-0000000FF1CE.xml.id-B4197730.[3442516480@qq.com].pdf | Dropped File | Stream |
Not Queried
|
...
|
»
C:\Program Files\Microsoft Office\PackageManifests\AppXManifest.90160000-00BA-0000-1000-0000000FF1CE.xml.id-B4197730.[3442516480@qq.com].pdf | Dropped File | Stream |
Not Queried
|
...
|
»
C:\Logs\Microsoft-Client-Licensing-Platform%4Admin.evtx.id-B4197730.[3442516480@qq.com].pdf | Dropped File | Stream |
Not Queried
|
...
|
»
C:\Logs\Microsoft-Windows-Application-Experience%4Program-Compatibility-Assistant.evtx.id-B4197730.[3442516480@qq.com].pdf | Dropped File | Stream |
Not Queried
|
...
|
»
C:\Logs\Microsoft-Windows-AppLocker%4EXE and DLL.evtx.id-B4197730.[3442516480@qq.com].pdf | Dropped File | Stream |
Not Queried
|
...
|
»
C:\Logs\Microsoft-Windows-AppLocker%4MSI and Script.evtx.id-B4197730.[3442516480@qq.com].pdf | Dropped File | Stream |
Not Queried
|
...
|
»
C:\Program Files\Microsoft Office\PackageManifests\AppXManifest.90160000-00BA-0409-1000-0000000FF1CE.xml.id-B4197730.[3442516480@qq.com].pdf | Dropped File | Stream |
Not Queried
|
...
|
»
C:\Program Files\Microsoft Office\PackageManifests\AppXManifest.90160000-00C1-0409-1000-0000000FF1CE.xml.id-B4197730.[3442516480@qq.com].pdf | Dropped File | Stream |
Not Queried
|
...
|
»
C:\Program Files\Microsoft Office\PackageManifests\AppXManifest.90160000-0090-0409-1000-0000000FF1CE.xml.id-B4197730.[3442516480@qq.com].pdf | Dropped File | Stream |
Not Queried
|
...
|
»
C:\Program Files\Microsoft Office\PackageManifests\AppXManifest.90160000-00C1-0000-1000-0000000FF1CE.xml.id-B4197730.[3442516480@qq.com].pdf | Dropped File | Stream |
Not Queried
|
...
|
»
C:\Program Files\Microsoft Office\PackageManifests\AppXManifest.90160000-00E2-0000-1000-0000000FF1CE.xml.id-B4197730.[3442516480@qq.com].pdf | Dropped File | Stream |
Not Queried
|
...
|
»
C:\Program Files\Microsoft Office\PackageManifests\AppXManifest.90160000-00E2-0409-1000-0000000FF1CE.xml.id-B4197730.[3442516480@qq.com].pdf | Dropped File | Stream |
Not Queried
|
...
|
»
C:\Program Files\Microsoft Office\PackageManifests\AppXManifest.90160000-0115-0409-1000-0000000FF1CE.xml.id-B4197730.[3442516480@qq.com].pdf | Dropped File | Stream |
Not Queried
|
...
|
»
C:\Program Files\Microsoft Office\PackageManifests\AppXManifest.90160000-012B-0409-1000-0000000FF1CE.xml.id-B4197730.[3442516480@qq.com].pdf | Dropped File | Stream |
Not Queried
|
...
|
»
C:\Program Files\Microsoft Office\PackageManifests\AppXManifest.90160000-3101-0000-1000-0000000FF1CE.xml.id-B4197730.[3442516480@qq.com].pdf | Dropped File | Stream |
Not Queried
|
...
|
»
C:\Program Files\Microsoft Office\PackageManifests\AppXManifest.90160000-00E1-0409-1000-0000000FF1CE.xml.id-B4197730.[3442516480@qq.com].pdf | Dropped File | Stream |
Not Queried
|
...
|
»
C:\Program Files\Microsoft Office\PackageManifests\AppXManifestLoc.en-us.xml.id-B4197730.[3442516480@qq.com].pdf | Dropped File | Stream |
Not Queried
|
...
|
»
C:\Program Files\Microsoft Office\PackageManifests\AuthoredExtensions.xml.id-B4197730.[3442516480@qq.com].pdf | Dropped File | Stream |
Not Queried
|
...
|
»
C:\Logs\Microsoft-Windows-AppModel-Runtime%4Admin.evtx.id-B4197730.[3442516480@qq.com].pdf | Dropped File | Stream |
Not Queried
|
...
|
»
C:\Logs\Microsoft-Windows-AppLocker%4Packaged app-Execution.evtx.id-B4197730.[3442516480@qq.com].pdf | Dropped File | Stream |
Not Queried
|
...
|
»
C:\Logs\Microsoft-Windows-AppXDeployment%4Operational.evtx.id-B4197730.[3442516480@qq.com].pdf | Dropped File | Stream |
Not Queried
|
...
|
»
C:\Logs\Microsoft-Windows-AppLocker%4Packaged app-Deployment.evtx.id-B4197730.[3442516480@qq.com].pdf | Dropped File | Stream |
Not Queried
|
...
|
»
C:\Logs\Microsoft-Windows-AppXDeploymentServer%4Restricted.evtx.id-B4197730.[3442516480@qq.com].pdf | Dropped File | Stream |
Not Queried
|
...
|
»
C:\Logs\Microsoft-Windows-ApplicationResourceManagementSystem%4Operational.evtx.id-B4197730.[3442516480@qq.com].pdf | Dropped File | Stream |
Not Queried
|
...
|
»
C:\Logs\Microsoft-Windows-BackgroundTaskInfrastructure%4Operational.evtx.id-B4197730.[3442516480@qq.com].pdf | Dropped File | Stream |
Not Queried
|
...
|
»
C:\Logs\Microsoft-Windows-AppXDeploymentServer%4Operational.evtx.id-B4197730.[3442516480@qq.com].pdf | Dropped File | Stream |
Not Queried
|
...
|
»
C:\Logs\Microsoft-Windows-AppxPackaging%4Operational.evtx.id-B4197730.[3442516480@qq.com].pdf | Dropped File | Stream |
Not Queried
|
...
|
»
C:\Logs\Microsoft-Windows-Bits-Client%4Operational.evtx.id-B4197730.[3442516480@qq.com].pdf | Dropped File | Stream |
Not Queried
|
...
|
»
C:\Logs\Microsoft-Windows-CodeIntegrity%4Operational.evtx.id-B4197730.[3442516480@qq.com].pdf | Dropped File | Stream |
Not Queried
|
...
|
»
C:\Logs\Microsoft-Windows-Crypto-DPAPI%4BackUpKeySvc.evtx.id-B4197730.[3442516480@qq.com].pdf | Dropped File | Stream |
Not Queried
|
...
|
»
C:\Logs\Microsoft-Windows-AppReadiness%4Operational.evtx.id-B4197730.[3442516480@qq.com].pdf | Dropped File | Stream |
Not Queried
|
...
|
»
C:\Logs\Microsoft-Windows-CoreSystem-SmsRouter-Events%4Operational.evtx.id-B4197730.[3442516480@qq.com].pdf | Dropped File | Stream |
Not Queried
|
...
|
»
C:\Logs\Microsoft-Windows-DeviceSetupManager%4Admin.evtx.id-B4197730.[3442516480@qq.com].pdf | Dropped File | Stream |
Not Queried
|
...
|
»
C:\Logs\Microsoft-Windows-DeviceSetupManager%4Operational.evtx.id-B4197730.[3442516480@qq.com].pdf | Dropped File | Stream |
Not Queried
|
...
|
»
C:\Logs\Microsoft-Windows-Dhcpv6-Client%4Admin.evtx.id-B4197730.[3442516480@qq.com].pdf | Dropped File | Stream |
Not Queried
|
...
|
»
C:\Logs\Microsoft-Windows-Diagnostics-Performance%4Operational.evtx.id-B4197730.[3442516480@qq.com].pdf | Dropped File | Stream |
Not Queried
|
...
|
»
C:\Logs\Microsoft-Windows-Dhcp-Client%4Admin.evtx.id-B4197730.[3442516480@qq.com].pdf | Dropped File | Stream |
Not Queried
|
...
|
»
C:\Logs\Microsoft-Windows-HotspotAuth%4Operational.evtx.id-B4197730.[3442516480@qq.com].pdf | Dropped File | Stream |
Not Queried
|
...
|
»
C:\Logs\Microsoft-Windows-DeviceManagement-Enterprise-Diagnostics-Provider%4Admin.evtx.id-B4197730.[3442516480@qq.com].pdf | Dropped File | Stream |
Not Queried
|
...
|
»
C:\Logs\Microsoft-Windows-International%4Operational.evtx.id-B4197730.[3442516480@qq.com].pdf | Dropped File | Stream |
Not Queried
|
...
|
»
C:\Logs\Microsoft-Windows-Kernel-Boot%4Operational.evtx.id-B4197730.[3442516480@qq.com].pdf | Dropped File | Stream |
Not Queried
|
...
|
»
C:\Logs\Microsoft-Windows-Kernel-WHEA%4Errors.evtx.id-B4197730.[3442516480@qq.com].pdf | Dropped File | Stream |
Not Queried
|
...
|
»
C:\Logs\Microsoft-Windows-Kernel-WHEA%4Operational.evtx.id-B4197730.[3442516480@qq.com].pdf | Dropped File | Stream |
Not Queried
|
...
|
»
C:\Logs\Microsoft-Windows-Known Folders API Service.evtx.id-B4197730.[3442516480@qq.com].pdf | Dropped File | Stream |
Not Queried
|
...
|
»
C:\Logs\Microsoft-Windows-MUI%4Admin.evtx.id-B4197730.[3442516480@qq.com].pdf | Dropped File | Stream |
Not Queried
|
...
|
»
C:\Logs\Microsoft-Windows-Kernel-StoreMgr%4Operational.evtx.id-B4197730.[3442516480@qq.com].pdf | Dropped File | Stream |
Not Queried
|
...
|
»
C:\Logs\Microsoft-Windows-NetworkProfile%4Operational.evtx.id-B4197730.[3442516480@qq.com].pdf | Dropped File | Stream |
Not Queried
|
...
|
»
C:\Logs\Microsoft-Windows-Program-Compatibility-Assistant%4CompatAfterUpgrade.evtx.id-B4197730.[3442516480@qq.com].pdf | Dropped File | Stream |
Not Queried
|
...
|
»
C:\Logs\Microsoft-Windows-ReadyBoost%4Operational.evtx.id-B4197730.[3442516480@qq.com].pdf | Dropped File | Stream |
Not Queried
|
...
|
»
C:\Logs\Microsoft-Windows-SettingSync%4Operational.evtx.id-B4197730.[3442516480@qq.com].pdf | Dropped File | Stream |
Not Queried
|
...
|
»
C:\Logs\Microsoft-Windows-Shell-Core%4ActionCenter.evtx.id-B4197730.[3442516480@qq.com].pdf | Dropped File | Stream |
Not Queried
|
...
|
»
C:\Logs\Microsoft-Windows-Resource-Exhaustion-Detector%4Operational.evtx.id-B4197730.[3442516480@qq.com].pdf | Dropped File | Stream |
Not Queried
|
...
|
»
C:\Logs\Microsoft-Windows-SMBServer%4Audit.evtx.id-B4197730.[3442516480@qq.com].pdf | Dropped File | Stream |
Not Queried
|
...
|
»
C:\Logs\Microsoft-Windows-SettingSync%4Debug.evtx.id-B4197730.[3442516480@qq.com].pdf | Dropped File | Stream |
Not Queried
|
...
|
»
C:\Logs\Microsoft-Windows-Shell-Core%4Operational.evtx.id-B4197730.[3442516480@qq.com].pdf | Dropped File | Stream |
Not Queried
|
...
|
»
C:\Logs\Microsoft-Windows-SMBServer%4Operational.evtx.id-B4197730.[3442516480@qq.com].pdf | Dropped File | Stream |
Not Queried
|
...
|
»
C:\Logs\Microsoft-Windows-SMBServer%4Security.evtx.id-B4197730.[3442516480@qq.com].pdf | Dropped File | Stream |
Not Queried
|
...
|
»
C:\Logs\Microsoft-Windows-Store%4Operational.evtx.id-B4197730.[3442516480@qq.com].pdf | Dropped File | Stream |
Not Queried
|
...
|
»
C:\Logs\Microsoft-Windows-TaskScheduler%4Maintenance.evtx.id-B4197730.[3442516480@qq.com].pdf | Dropped File | Stream |
Not Queried
|
...
|
»
C:\Logs\Microsoft-Windows-TerminalServices-RemoteConnectionManager%4Admin.evtx.id-B4197730.[3442516480@qq.com].pdf | Dropped File | Stream |
Not Queried
|
...
|
»
C:\Logs\Microsoft-Windows-TerminalServices-RemoteConnectionManager%4Operational.evtx.id-B4197730.[3442516480@qq.com].pdf | Dropped File | Stream |
Not Queried
|
...
|
»
C:\Logs\Microsoft-Windows-SMBServer%4Connectivity.evtx.id-B4197730.[3442516480@qq.com].pdf | Dropped File | Stream |
Not Queried
|
...
|
»
C:\Logs\Microsoft-Windows-User Profile Service%4Operational.evtx.id-B4197730.[3442516480@qq.com].pdf | Dropped File | Stream |
Not Queried
|
...
|
»
C:\Logs\Microsoft-Windows-UserPnp%4ActionCenter.evtx.id-B4197730.[3442516480@qq.com].pdf | Dropped File | Stream |
Not Queried
|
...
|
»
C:\Logs\Microsoft-Windows-VolumeSnapshot-Driver%4Operational.evtx.id-B4197730.[3442516480@qq.com].pdf | Dropped File | Stream |
Not Queried
|
...
|
»
C:\Logs\Microsoft-Windows-Wcmsvc%4Operational.evtx.id-B4197730.[3442516480@qq.com].pdf | Dropped File | Stream |
Not Queried
|
...
|
»
C:\Logs\Microsoft-Windows-Windows Defender%4WHC.evtx.id-B4197730.[3442516480@qq.com].pdf | Dropped File | Stream |
Not Queried
|
...
|
»
C:\Logs\Microsoft-Windows-WinINet-Config%4ProxyConfigChanged.evtx.id-B4197730.[3442516480@qq.com].pdf | Dropped File | Stream |
Not Queried
|
...
|
»
C:\Logs\Microsoft-Windows-Winlogon%4Operational.evtx.id-B4197730.[3442516480@qq.com].pdf | Dropped File | Stream |
Not Queried
|
...
|
»
C:\Logs\Microsoft-Windows-UserPnp%4DeviceInstall.evtx.id-B4197730.[3442516480@qq.com].pdf | Dropped File | Stream |
Not Queried
|
...
|
»
C:\Logs\Microsoft-Windows-Windows Defender%4Operational.evtx.id-B4197730.[3442516480@qq.com].pdf | Dropped File | Stream |
Not Queried
|
...
|
»
C:\Logs\Microsoft-Windows-WMI-Activity%4Operational.evtx.id-B4197730.[3442516480@qq.com].pdf | Dropped File | Stream |
Not Queried
|
...
|
»
C:\Program Files\Common Files\microsoft shared\ClickToRun\api-ms-win-core-file-l2-1-0.dll.id-B4197730.[3442516480@qq.com].pdf | Dropped File | Stream |
Not Queried
|
...
|
»
C:\Logs\Windows PowerShell.evtx.id-B4197730.[3442516480@qq.com].pdf | Dropped File | Stream |
Not Queried
|
...
|
»
C:\Program Files\Common Files\microsoft shared\ClickToRun\api-ms-win-core-synch-l1-2-0.dll.id-B4197730.[3442516480@qq.com].pdf | Dropped File | Stream |
Not Queried
|
...
|
»
C:\Program Files\Common Files\microsoft shared\ClickToRun\api-ms-win-core-xstate-l2-1-0.dll.id-B4197730.[3442516480@qq.com].pdf | Dropped File | Stream |
Not Queried
|
...
|
»
C:\Program Files\Common Files\microsoft shared\ClickToRun\api-ms-win-core-file-l1-2-0.dll.id-B4197730.[3442516480@qq.com].pdf | Dropped File | Stream |
Not Queried
|
...
|
»
C:\Program Files\Common Files\microsoft shared\ClickToRun\api-ms-win-crt-convert-l1-1-0.dll.id-B4197730.[3442516480@qq.com].pdf | Dropped File | Stream |
Not Queried
|
...
|
»
C:\Program Files\Common Files\microsoft shared\ClickToRun\api-ms-win-crt-filesystem-l1-1-0.dll.id-B4197730.[3442516480@qq.com].pdf | Dropped File | Stream |
Not Queried
|
...
|
»
C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\DD01140_.WMF.id-B4197730.[3442516480@qq.com].pdf | Dropped File | Unknown |
Not Queried
|
...
|
»
C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\DD01143_.WMF.id-B4197730.[3442516480@qq.com].pdf | Dropped File | Unknown |
Not Queried
|
...
|
»
C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\CLIP.WMF.id-B4197730.[3442516480@qq.com].pdf | Dropped File | Unknown |
Not Queried
|
...
|
»
C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\DD01146_.WMF.id-B4197730.[3442516480@qq.com].pdf | Dropped File | Unknown |
Not Queried
|
...
|
»
C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\DD01152_.WMF.id-B4197730.[3442516480@qq.com].pdf | Dropped File | Unknown |
Not Queried
|
...
|
»
C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\DD01162_.WMF.id-B4197730.[3442516480@qq.com].pdf | Dropped File | Unknown |
Not Queried
|
...
|
»