VTI SCORE: 100/100
Dynamic Analysis Report |
Classification: |
Ransomware
Dropper
|
Threat Names: |
Generic.Ransom.Matrix.D1CDCF50
VBS.Heur.Laburrak.11.Gen
Trojan.GenericKD.40672878
...
|
UsersPetraAppDataLocalTempNWGUQsM6.exe
Windows Exe (x86-32)
Created at 2020-09-03T10:55:00
Remarks (1/1)
(0x0200000E): The overall sleep time of all monitored processes was truncated from "5 minutes" to "50 seconds" to reveal dormant functionality.
Remarks
(0x0200001D): The maximum number of extracted files was exceeded. Some files may be missing in the report.
(0x0200001B): The maximum number of file reputation requests per analysis (150) was exceeded.
This is a filtered view
This list contains only the embedded files, downloaded files, and dropped files
Filters: |
There are no files for this filter
There are no files in this analysis
Filename | Category | Type | Severity | Actions |
---|
C:\Users\FD1HVy\Desktop\UsersPetraAppDataLocalTempNWGUQsM6.exe | Sample File | Binary |
Malicious
|
...
|
»
PE Information
»
Image Base | 0x400000 |
Entry Point | 0x4dca54 |
Size Of Code | 0xdec00 |
Size Of Initialized Data | 0x4d800 |
File Type | FileType.executable |
Subsystem | Subsystem.windows_cui |
Machine Type | MachineType.i386 |
Compile Timestamp | 2018-08-21 21:08:56+00:00 |
Sections (10)
»
Name | Virtual Address | Virtual Size | Raw Data Size | Raw Data Offset | Flags | Entropy |
---|---|---|---|---|---|---|
.text | 0x401000 | 0xda4e8 | 0xda600 | 0x400 | IMAGE_SCN_CNT_CODE, IMAGE_SCN_MEM_EXECUTE, IMAGE_SCN_MEM_READ | 6.38 |
.itext | 0x4dc000 | 0x4434 | 0x4600 | 0xdaa00 | IMAGE_SCN_CNT_CODE, IMAGE_SCN_MEM_EXECUTE, IMAGE_SCN_MEM_READ | 5.68 |
.data | 0x4e1000 | 0x5af8 | 0x5c00 | 0xdf000 | IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_READ, IMAGE_SCN_MEM_WRITE | 6.19 |
.bss | 0x4e7000 | 0x63f4 | 0x0 | 0x0 | IMAGE_SCN_MEM_READ, IMAGE_SCN_MEM_WRITE | 0.0 |
.idata | 0x4ee000 | 0x10d8 | 0x1200 | 0xe4c00 | IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_READ, IMAGE_SCN_MEM_WRITE | 4.87 |
.didata | 0x4f0000 | 0xfa | 0x200 | 0xe5e00 | IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_READ, IMAGE_SCN_MEM_WRITE | 1.89 |
.edata | 0x4f1000 | 0x6b | 0x200 | 0xe6000 | IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_READ | 1.29 |
.tls | 0x4f2000 | 0x14 | 0x0 | 0x0 | IMAGE_SCN_MEM_READ, IMAGE_SCN_MEM_WRITE | 0.0 |
.rdata | 0x4f3000 | 0x5d | 0x200 | 0xe6200 | IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_READ | 1.36 |
.rsrc | 0x4f4000 | 0x46400 | 0x46400 | 0xe6400 | IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_READ | 7.96 |
Imports (8)
»
oleaut32.dll (12)
»
API Name | Ordinal | IAT Address | Thunk RVA | Thunk Offset | Hint |
---|---|---|---|---|---|
SysFreeString | 0x0 | 0x4ee33c | 0xee0b4 | 0xe4cb4 | 0x0 |
SysReAllocStringLen | 0x0 | 0x4ee340 | 0xee0b8 | 0xe4cb8 | 0x0 |
SysAllocStringLen | 0x0 | 0x4ee344 | 0xee0bc | 0xe4cbc | 0x0 |
SafeArrayPtrOfIndex | 0x0 | 0x4ee348 | 0xee0c0 | 0xe4cc0 | 0x0 |
SafeArrayGetUBound | 0x0 | 0x4ee34c | 0xee0c4 | 0xe4cc4 | 0x0 |
SafeArrayGetLBound | 0x0 | 0x4ee350 | 0xee0c8 | 0xe4cc8 | 0x0 |
SafeArrayCreate | 0x0 | 0x4ee354 | 0xee0cc | 0xe4ccc | 0x0 |
VariantChangeType | 0x0 | 0x4ee358 | 0xee0d0 | 0xe4cd0 | 0x0 |
VariantCopy | 0x0 | 0x4ee35c | 0xee0d4 | 0xe4cd4 | 0x0 |
VariantClear | 0x0 | 0x4ee360 | 0xee0d8 | 0xe4cd8 | 0x0 |
VariantInit | 0x0 | 0x4ee364 | 0xee0dc | 0xe4cdc | 0x0 |
GetErrorInfo | 0x0 | 0x4ee368 | 0xee0e0 | 0xe4ce0 | 0x0 |
advapi32.dll (7)
»
API Name | Ordinal | IAT Address | Thunk RVA | Thunk Offset | Hint |
---|---|---|---|---|---|
RegQueryValueExW | 0x0 | 0x4ee370 | 0xee0e8 | 0xe4ce8 | 0x0 |
RegOpenKeyExW | 0x0 | 0x4ee374 | 0xee0ec | 0xe4cec | 0x0 |
RegCloseKey | 0x0 | 0x4ee378 | 0xee0f0 | 0xe4cf0 | 0x0 |
GetUserNameA | 0x0 | 0x4ee37c | 0xee0f4 | 0xe4cf4 | 0x0 |
CryptGenRandom | 0x0 | 0x4ee380 | 0xee0f8 | 0xe4cf8 | 0x0 |
CryptReleaseContext | 0x0 | 0x4ee384 | 0xee0fc | 0xe4cfc | 0x0 |
CryptAcquireContextW | 0x0 | 0x4ee388 | 0xee100 | 0xe4d00 | 0x0 |
user32.dll (10)
»
API Name | Ordinal | IAT Address | Thunk RVA | Thunk Offset | Hint |
---|---|---|---|---|---|
MessageBoxA | 0x0 | 0x4ee390 | 0xee108 | 0xe4d08 | 0x0 |
CharNextW | 0x0 | 0x4ee394 | 0xee10c | 0xe4d0c | 0x0 |
LoadStringW | 0x0 | 0x4ee398 | 0xee110 | 0xe4d10 | 0x0 |
PeekMessageW | 0x0 | 0x4ee39c | 0xee114 | 0xe4d14 | 0x0 |
MsgWaitForMultipleObjects | 0x0 | 0x4ee3a0 | 0xee118 | 0xe4d18 | 0x0 |
MessageBoxW | 0x0 | 0x4ee3a4 | 0xee11c | 0xe4d1c | 0x0 |
GetSystemMetrics | 0x0 | 0x4ee3a8 | 0xee120 | 0xe4d20 | 0x0 |
CharUpperBuffW | 0x0 | 0x4ee3ac | 0xee124 | 0xe4d24 | 0x0 |
CharUpperW | 0x0 | 0x4ee3b0 | 0xee128 | 0xe4d28 | 0x0 |
CharLowerBuffW | 0x0 | 0x4ee3b4 | 0xee12c | 0xe4d2c | 0x0 |
kernel32.dll (115)
»
API Name | Ordinal | IAT Address | Thunk RVA | Thunk Offset | Hint |
---|---|---|---|---|---|
Sleep | 0x0 | 0x4ee3bc | 0xee134 | 0xe4d34 | 0x0 |
VirtualFree | 0x0 | 0x4ee3c0 | 0xee138 | 0xe4d38 | 0x0 |
VirtualAlloc | 0x0 | 0x4ee3c4 | 0xee13c | 0xe4d3c | 0x0 |
lstrlenW | 0x0 | 0x4ee3c8 | 0xee140 | 0xe4d40 | 0x0 |
VirtualQuery | 0x0 | 0x4ee3cc | 0xee144 | 0xe4d44 | 0x0 |
GetTickCount | 0x0 | 0x4ee3d0 | 0xee148 | 0xe4d48 | 0x0 |
GetSystemInfo | 0x0 | 0x4ee3d4 | 0xee14c | 0xe4d4c | 0x0 |
GetVersion | 0x0 | 0x4ee3d8 | 0xee150 | 0xe4d50 | 0x0 |
CompareStringW | 0x0 | 0x4ee3dc | 0xee154 | 0xe4d54 | 0x0 |
IsDBCSLeadByteEx | 0x0 | 0x4ee3e0 | 0xee158 | 0xe4d58 | 0x0 |
IsValidLocale | 0x0 | 0x4ee3e4 | 0xee15c | 0xe4d5c | 0x0 |
SetThreadLocale | 0x0 | 0x4ee3e8 | 0xee160 | 0xe4d60 | 0x0 |
GetSystemDefaultUILanguage | 0x0 | 0x4ee3ec | 0xee164 | 0xe4d64 | 0x0 |
GetUserDefaultUILanguage | 0x0 | 0x4ee3f0 | 0xee168 | 0xe4d68 | 0x0 |
GetLocaleInfoW | 0x0 | 0x4ee3f4 | 0xee16c | 0xe4d6c | 0x0 |
WideCharToMultiByte | 0x0 | 0x4ee3f8 | 0xee170 | 0xe4d70 | 0x0 |
MultiByteToWideChar | 0x0 | 0x4ee3fc | 0xee174 | 0xe4d74 | 0x0 |
GetConsoleOutputCP | 0x0 | 0x4ee400 | 0xee178 | 0xe4d78 | 0x0 |
GetConsoleCP | 0x0 | 0x4ee404 | 0xee17c | 0xe4d7c | 0x0 |
GetACP | 0x0 | 0x4ee408 | 0xee180 | 0xe4d80 | 0x0 |
LoadLibraryExW | 0x0 | 0x4ee40c | 0xee184 | 0xe4d84 | 0x0 |
GetStartupInfoW | 0x0 | 0x4ee410 | 0xee188 | 0xe4d88 | 0x0 |
GetProcAddress | 0x0 | 0x4ee414 | 0xee18c | 0xe4d8c | 0x0 |
GetModuleHandleW | 0x0 | 0x4ee418 | 0xee190 | 0xe4d90 | 0x0 |
GetModuleFileNameW | 0x0 | 0x4ee41c | 0xee194 | 0xe4d94 | 0x0 |
GetCommandLineW | 0x0 | 0x4ee420 | 0xee198 | 0xe4d98 | 0x0 |
FreeLibrary | 0x0 | 0x4ee424 | 0xee19c | 0xe4d9c | 0x0 |
GetLastError | 0x0 | 0x4ee428 | 0xee1a0 | 0xe4da0 | 0x0 |
UnhandledExceptionFilter | 0x0 | 0x4ee42c | 0xee1a4 | 0xe4da4 | 0x0 |
RtlUnwind | 0x0 | 0x4ee430 | 0xee1a8 | 0xe4da8 | 0x0 |
RaiseException | 0x0 | 0x4ee434 | 0xee1ac | 0xe4dac | 0x0 |
ExitProcess | 0x0 | 0x4ee438 | 0xee1b0 | 0xe4db0 | 0x0 |
ExitThread | 0x0 | 0x4ee43c | 0xee1b4 | 0xe4db4 | 0x0 |
SwitchToThread | 0x0 | 0x4ee440 | 0xee1b8 | 0xe4db8 | 0x0 |
GetCurrentThreadId | 0x0 | 0x4ee444 | 0xee1bc | 0xe4dbc | 0x0 |
CreateThread | 0x0 | 0x4ee448 | 0xee1c0 | 0xe4dc0 | 0x0 |
DeleteCriticalSection | 0x0 | 0x4ee44c | 0xee1c4 | 0xe4dc4 | 0x0 |
LeaveCriticalSection | 0x0 | 0x4ee450 | 0xee1c8 | 0xe4dc8 | 0x0 |
EnterCriticalSection | 0x0 | 0x4ee454 | 0xee1cc | 0xe4dcc | 0x0 |
InitializeCriticalSection | 0x0 | 0x4ee458 | 0xee1d0 | 0xe4dd0 | 0x0 |
FindFirstFileW | 0x0 | 0x4ee45c | 0xee1d4 | 0xe4dd4 | 0x0 |
FindClose | 0x0 | 0x4ee460 | 0xee1d8 | 0xe4dd8 | 0x0 |
WriteFile | 0x0 | 0x4ee464 | 0xee1dc | 0xe4ddc | 0x0 |
SetFilePointer | 0x0 | 0x4ee468 | 0xee1e0 | 0xe4de0 | 0x0 |
SetEndOfFile | 0x0 | 0x4ee46c | 0xee1e4 | 0xe4de4 | 0x0 |
ReadFile | 0x0 | 0x4ee470 | 0xee1e8 | 0xe4de8 | 0x0 |
GetFileType | 0x0 | 0x4ee474 | 0xee1ec | 0xe4dec | 0x0 |
GetFileSize | 0x0 | 0x4ee478 | 0xee1f0 | 0xe4df0 | 0x0 |
CreateFileW | 0x0 | 0x4ee47c | 0xee1f4 | 0xe4df4 | 0x0 |
GetStdHandle | 0x0 | 0x4ee480 | 0xee1f8 | 0xe4df8 | 0x0 |
CloseHandle | 0x0 | 0x4ee484 | 0xee1fc | 0xe4dfc | 0x0 |
LoadLibraryA | 0x0 | 0x4ee488 | 0xee200 | 0xe4e00 | 0x0 |
TlsSetValue | 0x0 | 0x4ee48c | 0xee204 | 0xe4e04 | 0x0 |
TlsGetValue | 0x0 | 0x4ee490 | 0xee208 | 0xe4e08 | 0x0 |
LocalFree | 0x0 | 0x4ee494 | 0xee20c | 0xe4e0c | 0x0 |
LocalAlloc | 0x0 | 0x4ee498 | 0xee210 | 0xe4e10 | 0x0 |
WaitForSingleObject | 0x0 | 0x4ee49c | 0xee214 | 0xe4e14 | 0x0 |
WaitForMultipleObjects | 0x0 | 0x4ee4a0 | 0xee218 | 0xe4e18 | 0x0 |
VirtualQueryEx | 0x0 | 0x4ee4a4 | 0xee21c | 0xe4e1c | 0x0 |
VirtualProtect | 0x0 | 0x4ee4a8 | 0xee220 | 0xe4e20 | 0x0 |
VerSetConditionMask | 0x0 | 0x4ee4ac | 0xee224 | 0xe4e24 | 0x0 |
VerifyVersionInfoW | 0x0 | 0x4ee4b0 | 0xee228 | 0xe4e28 | 0x0 |
SuspendThread | 0x0 | 0x4ee4b4 | 0xee22c | 0xe4e2c | 0x0 |
SizeofResource | 0x0 | 0x4ee4b8 | 0xee230 | 0xe4e30 | 0x0 |
SetThreadPriority | 0x0 | 0x4ee4bc | 0xee234 | 0xe4e34 | 0x0 |
SetLastError | 0x0 | 0x4ee4c0 | 0xee238 | 0xe4e38 | 0x0 |
SetFileAttributesW | 0x0 | 0x4ee4c4 | 0xee23c | 0xe4e3c | 0x0 |
SetEvent | 0x0 | 0x4ee4c8 | 0xee240 | 0xe4e40 | 0x0 |
SetErrorMode | 0x0 | 0x4ee4cc | 0xee244 | 0xe4e44 | 0x0 |
ResumeThread | 0x0 | 0x4ee4d0 | 0xee248 | 0xe4e48 | 0x0 |
ResetEvent | 0x0 | 0x4ee4d4 | 0xee24c | 0xe4e4c | 0x0 |
ReleaseMutex | 0x0 | 0x4ee4d8 | 0xee250 | 0xe4e50 | 0x0 |
QueryPerformanceFrequency | 0x0 | 0x4ee4dc | 0xee254 | 0xe4e54 | 0x0 |
QueryPerformanceCounter | 0x0 | 0x4ee4e0 | 0xee258 | 0xe4e58 | 0x0 |
OpenMutexW | 0x0 | 0x4ee4e4 | 0xee25c | 0xe4e5c | 0x0 |
MoveFileExW | 0x0 | 0x4ee4e8 | 0xee260 | 0xe4e60 | 0x0 |
LockResource | 0x0 | 0x4ee4ec | 0xee264 | 0xe4e64 | 0x0 |
LoadResource | 0x0 | 0x4ee4f0 | 0xee268 | 0xe4e68 | 0x0 |
LoadLibraryW | 0x0 | 0x4ee4f4 | 0xee26c | 0xe4e6c | 0x0 |
HeapFree | 0x0 | 0x4ee4f8 | 0xee270 | 0xe4e70 | 0x0 |
HeapDestroy | 0x0 | 0x4ee4fc | 0xee274 | 0xe4e74 | 0x0 |
HeapCreate | 0x0 | 0x4ee500 | 0xee278 | 0xe4e78 | 0x0 |
HeapAlloc | 0x0 | 0x4ee504 | 0xee27c | 0xe4e7c | 0x0 |
GetVolumeInformationW | 0x0 | 0x4ee508 | 0xee280 | 0xe4e80 | 0x0 |
GetVersionExW | 0x0 | 0x4ee50c | 0xee284 | 0xe4e84 | 0x0 |
GetThreadTimes | 0x0 | 0x4ee510 | 0xee288 | 0xe4e88 | 0x0 |
GetThreadPriority | 0x0 | 0x4ee514 | 0xee28c | 0xe4e8c | 0x0 |
GetThreadLocale | 0x0 | 0x4ee518 | 0xee290 | 0xe4e90 | 0x0 |
GetSystemTimes | 0x0 | 0x4ee51c | 0xee294 | 0xe4e94 | 0x0 |
GetProcessTimes | 0x0 | 0x4ee520 | 0xee298 | 0xe4e98 | 0x0 |
GetLocalTime | 0x0 | 0x4ee524 | 0xee29c | 0xe4e9c | 0x0 |
GetFullPathNameW | 0x0 | 0x4ee528 | 0xee2a0 | 0xe4ea0 | 0x0 |
GetFileAttributesW | 0x0 | 0x4ee52c | 0xee2a4 | 0xe4ea4 | 0x0 |
GetExitCodeThread | 0x0 | 0x4ee530 | 0xee2a8 | 0xe4ea8 | 0x0 |
GetDriveTypeW | 0x0 | 0x4ee534 | 0xee2ac | 0xe4eac | 0x0 |
GetDiskFreeSpaceW | 0x0 | 0x4ee538 | 0xee2b0 | 0xe4eb0 | 0x0 |
GetDateFormatW | 0x0 | 0x4ee53c | 0xee2b4 | 0xe4eb4 | 0x0 |
GetCurrentThread | 0x0 | 0x4ee540 | 0xee2b8 | 0xe4eb8 | 0x0 |
GetCurrentProcessId | 0x0 | 0x4ee544 | 0xee2bc | 0xe4ebc | 0x0 |
GetCurrentProcess | 0x0 | 0x4ee548 | 0xee2c0 | 0xe4ec0 | 0x0 |
GetComputerNameA | 0x0 | 0x4ee54c | 0xee2c4 | 0xe4ec4 | 0x0 |
GetCPInfoExW | 0x0 | 0x4ee550 | 0xee2c8 | 0xe4ec8 | 0x0 |
GetCPInfo | 0x0 | 0x4ee554 | 0xee2cc | 0xe4ecc | 0x0 |
FreeResource | 0x0 | 0x4ee558 | 0xee2d0 | 0xe4ed0 | 0x0 |
InterlockedCompareExchange | 0x0 | 0x4ee55c | 0xee2d4 | 0xe4ed4 | 0x0 |
FormatMessageW | 0x0 | 0x4ee560 | 0xee2d8 | 0xe4ed8 | 0x0 |
FindResourceW | 0x0 | 0x4ee564 | 0xee2dc | 0xe4edc | 0x0 |
FindNextFileW | 0x0 | 0x4ee568 | 0xee2e0 | 0xe4ee0 | 0x0 |
ExpandEnvironmentStringsW | 0x0 | 0x4ee56c | 0xee2e4 | 0xe4ee4 | 0x0 |
EnumSystemLocalesW | 0x0 | 0x4ee570 | 0xee2e8 | 0xe4ee8 | 0x0 |
EnumCalendarInfoW | 0x0 | 0x4ee574 | 0xee2ec | 0xe4eec | 0x0 |
DeleteFileW | 0x0 | 0x4ee578 | 0xee2f0 | 0xe4ef0 | 0x0 |
CreateProcessW | 0x0 | 0x4ee57c | 0xee2f4 | 0xe4ef4 | 0x0 |
CreateMutexW | 0x0 | 0x4ee580 | 0xee2f8 | 0xe4ef8 | 0x0 |
CreateEventW | 0x0 | 0x4ee584 | 0xee2fc | 0xe4efc | 0x0 |
ole32.dll (2)
»
API Name | Ordinal | IAT Address | Thunk RVA | Thunk Offset | Hint |
---|---|---|---|---|---|
CoUninitialize | 0x0 | 0x4ee58c | 0xee304 | 0xe4f04 | 0x0 |
CoInitialize | 0x0 | 0x4ee590 | 0xee308 | 0xe4f08 | 0x0 |
shell32.dll (1)
»
API Name | Ordinal | IAT Address | Thunk RVA | Thunk Offset | Hint |
---|---|---|---|---|---|
SHGetSpecialFolderPathW | 0x0 | 0x4ee598 | 0xee310 | 0xe4f10 | 0x0 |
wsock32.dll (5)
»
API Name | Ordinal | IAT Address | Thunk RVA | Thunk Offset | Hint |
---|---|---|---|---|---|
WSACleanup | 0x0 | 0x4ee5a0 | 0xee318 | 0xe4f18 | 0x0 |
WSAStartup | 0x0 | 0x4ee5a4 | 0xee31c | 0xe4f1c | 0x0 |
gethostname | 0x0 | 0x4ee5a8 | 0xee320 | 0xe4f20 | 0x0 |
gethostbyname | 0x0 | 0x4ee5ac | 0xee324 | 0xe4f24 | 0x0 |
inet_ntoa | 0x0 | 0x4ee5b0 | 0xee328 | 0xe4f28 | 0x0 |
netapi32.dll (2)
»
API Name | Ordinal | IAT Address | Thunk RVA | Thunk Offset | Hint |
---|---|---|---|---|---|
NetShareEnum | 0x0 | 0x4ee5b8 | 0xee330 | 0xe4f30 | 0x0 |
NetApiBufferFree | 0x0 | 0x4ee5bc | 0xee334 | 0xe4f34 | 0x0 |
Exports (1)
»
Api name | EAT Address | Ordinal |
---|---|---|
TMethodImplementationIntercept | 0x50870 | 0x1 |
Memory Dumps (3)
»
Name | Process ID | Start VA | End VA | Dump Reason | PE Rebuild | Bitness | Entry Point | AV | YARA | Actions |
---|---|---|---|---|---|---|---|---|---|---|
userspetraappdatalocaltempnwguqsm6.exe | 1 | 0x00400000 | 0x0053AFFF | Relevant Image |
![]() |
32-bit | 0x00407620 |
![]() |
![]() |
...
|
nwd2f5om.exe | 5 | 0x00400000 | 0x0053AFFF | Relevant Image |
![]() |
32-bit | 0x00407620 |
![]() |
![]() |
...
|
userspetraappdatalocaltempnwguqsm6.exe | 1 | 0x00400000 | 0x0053AFFF | Final Dump |
![]() |
32-bit | - |
![]() |
![]() |
...
|
Local AV Matches (1)
»
Threat Name | Severity |
---|---|
Generic.Ransom.Matrix.D1CDCF50 |
Malicious
|
C:\Users\FD1HVy\AppData\Roaming\PxVlsyP0.vbs | Dropped File | Text |
Malicious
|
...
|
»
Local AV Matches (1)
»
Threat Name | Severity |
---|---|
VBS.Heur.Laburrak.11.Gen |
Malicious
|
C:\Users\FD1HVy\Desktop\OQrMpQm8.exe | Dropped File | Binary |
Malicious
|
...
|
»
File Reputation Information
»
Severity |
Blacklisted
|
Names | Mal/Generic-S |
PE Information
»
Image Base | 0x400000 |
Entry Point | 0x475810 |
Size Of Code | 0x29000 |
Size Of Initialized Data | 0x1000 |
Size Of Uninitialized Data | 0x4c000 |
File Type | FileType.executable |
Subsystem | Subsystem.windows_cui |
Machine Type | MachineType.i386 |
Compile Timestamp | 2017-12-10 21:18:46+00:00 |
Version Information (8)
»
CompanyName | Sysinternals - www.sysinternals.com |
FileDescription | Handle viewer |
FileVersion | 4.11 |
InternalName | Nthandle |
LegalCopyright | Copyright (C) 1997-2017 Mark Russinovich |
OriginalFilename | Nthandle.exe |
ProductName | Sysinternals Handle |
ProductVersion | 4.11 |
Sections (3)
»
Name | Virtual Address | Virtual Size | Raw Data Size | Raw Data Offset | Flags | Entropy |
---|---|---|---|---|---|---|
UPX0 | 0x401000 | 0x4c000 | 0x0 | 0x400 | IMAGE_SCN_CNT_UNINITIALIZED_DATA, IMAGE_SCN_MEM_EXECUTE, IMAGE_SCN_MEM_READ, IMAGE_SCN_MEM_WRITE | 0.0 |
UPX1 | 0x44d000 | 0x29000 | 0x28a00 | 0x400 | IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_EXECUTE, IMAGE_SCN_MEM_READ, IMAGE_SCN_MEM_WRITE | 7.93 |
.rsrc | 0x476000 | 0x1000 | 0x800 | 0x28e00 | IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_READ, IMAGE_SCN_MEM_WRITE | 4.04 |
Imports (6)
»
ADVAPI32.dll (1)
»
API Name | Ordinal | IAT Address | Thunk RVA | Thunk Offset | Hint |
---|---|---|---|---|---|
RegOpenKeyW | 0x0 | 0x47666c | 0x7666c | 0x2946c | 0x0 |
COMDLG32.dll (1)
»
API Name | Ordinal | IAT Address | Thunk RVA | Thunk Offset | Hint |
---|---|---|---|---|---|
PrintDlgW | 0x0 | 0x476674 | 0x76674 | 0x29474 | 0x0 |
GDI32.dll (1)
»
API Name | Ordinal | IAT Address | Thunk RVA | Thunk Offset | Hint |
---|---|---|---|---|---|
EndDoc | 0x0 | 0x47667c | 0x7667c | 0x2947c | 0x0 |
KERNEL32.DLL (4)
»
API Name | Ordinal | IAT Address | Thunk RVA | Thunk Offset | Hint |
---|---|---|---|---|---|
LoadLibraryA | 0x0 | 0x476684 | 0x76684 | 0x29484 | 0x0 |
ExitProcess | 0x0 | 0x476688 | 0x76688 | 0x29488 | 0x0 |
GetProcAddress | 0x0 | 0x47668c | 0x7668c | 0x2948c | 0x0 |
VirtualProtect | 0x0 | 0x476690 | 0x76690 | 0x29490 | 0x0 |
USER32.dll (1)
»
API Name | Ordinal | IAT Address | Thunk RVA | Thunk Offset | Hint |
---|---|---|---|---|---|
EndDialog | 0x0 | 0x476698 | 0x76698 | 0x29498 | 0x0 |
VERSION.dll (1)
»
API Name | Ordinal | IAT Address | Thunk RVA | Thunk Offset | Hint |
---|---|---|---|---|---|
VerQueryValueW | 0x0 | 0x4766a0 | 0x766a0 | 0x294a0 | 0x0 |
Local AV Matches (1)
»
Threat Name | Severity |
---|---|
Trojan.GenericKD.40672878 |
Malicious
|
C:\Users\FD1HVy\AppData\Local\Temp\__PSScriptPolicyTest_wy51e5uv.nje.psm1 | Dropped File | Text |
Whitelisted
|
...
|
»
File Reputation Information
»
Severity |
Whitelisted
|
C:\Program Files\Java\jre1.8.0_144\lib\deploy\messages_fr.properties | Modified File | Stream |
Unknown
|
...
|
»
C:\Program Files\Java\jre1.8.0_144\lib\ext\meta-index | Modified File | Stream |
Unknown
|
...
|
»
C:\Logs\Microsoft-Windows-TaskScheduler%4Maintenance.evtx | Modified File | Stream |
Unknown
|
...
|
»
C:\Logs\Microsoft-Windows-Wcmsvc%4Operational.evtx | Modified File | Stream |
Unknown
|
...
|
»
C:\588bce7c90097ed212\1025\LocalizedData.xml | Modified File | Stream |
Unknown
|
...
|
»
C:\Logs\Microsoft-Windows-AppLocker%4MSI and Script.evtx | Modified File | Stream |
Unknown
|
...
|
»
C:\Program Files\Java\jre1.8.0_144\lib\management\snmp.acl.template | Modified File | Stream |
Unknown
|
...
|
»
C:\Program Files\Java\jre1.8.0_144\LICENSE | Modified File | Stream |
Unknown
|
...
|
»
C:\588bce7c90097ed212\1037\LocalizedData.xml | Modified File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\Documents\qj87MQXJ-kb3M\-IvkqaBFNmw9a1yLi.doc | Modified File | Stream |
Unknown
|
...
|
»
C:\Program Files\Java\jre1.8.0_144\bin\keytool.exe | Modified File | Stream |
Unknown
|
...
|
»
C:\Program Files\Java\jre1.8.0_144\lib\deploy\splash.gif | Modified File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\Documents\N_MxJF834q5.pdf | Modified File | Stream |
Unknown
|
...
|
»
C:\$GetCurrent\SafeOS\preoobe.cmd | Modified File | Batch |
Unknown
|
...
|
»
C:\Users\FD1HVy\AppData\Roaming\Mozilla\Firefox\Profiles\w7cr0hor.default\storage\permanent\moz-safe-about+home\idb\818200132aebmoouht.sqlite | Modified File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\Documents\qj87MQXJ-kb3M\ywto6yhhZbvU2yJiug.xlsx | Modified File | Stream |
Unknown
|
...
|
»
C:\Program Files\Mozilla Firefox\removed-files | Modified File | Stream |
Unknown
|
...
|
»
C:\Program Files\rempl\Logs\Remediation.002.etl | Modified File | Stream |
Unknown
|
...
|
»
C:\Program Files\UNP\CampaignManager\Campaigns\{91be532c-f9f1-406a-9858-43697c6f437a}\Content1\ar-sa\index.html | Modified File | Text |
Unknown
|
...
|
»
C:\588bce7c90097ed212\1049\LocalizedData.xml | Modified File | Stream |
Unknown
|
...
|
»
C:\Program Files\UNP\CampaignManager\Campaigns\{91be532c-f9f1-406a-9858-43697c6f437a}\Content1\da-DK\index.html | Modified File | Text |
Unknown
|
...
|
»
C:\Users\FD1HVy\Documents\qj87MQXJ-kb3M\bP TPQz8ySbTmo\[PabFox@protonmail.com ].ZsYQOUKn-ZQudRpTA.FOX | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\Documents\qj87MQXJ-kb3M\[PabFox@protonmail.com ].5fe1dhxE-YmzSs1SE.FOX | Dropped File | Stream |
Unknown
|
...
|
»
C:\$GetCurrent\Logs\[PabFox@protonmail.com ].jXUsRhRR-Kx6HOKdT.FOX | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\AppData\Local\Packages\Microsoft.Windows.Photos_8wekyb3d8bbwe\LocalState\[PabFox@protonmail.com ].0MfOAjFS-8l912BvM.FOX | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\AppData\Roaming\Mozilla\Firefox\Profiles\w7cr0hor.default\webappsstore.sqlite | Modified File | Stream |
Unknown
|
...
|
»
C:\588bce7c90097ed212\3082\LocalizedData.xml | Modified File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\AppData\Roaming\Mozilla\Firefox\Profiles\w7cr0hor.default\content-prefs.sqlite | Modified File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\AppData\Roaming\Odw0pC65.xlsx | Modified File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\Documents\zZBH_J5DoYq-QhDed8gg\[PabFox@protonmail.com ].m1HuUNa3-fqKW0eAf.FOX | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\Documents\qj87MQXJ-kb3M\cMc8xdzjnTxeiad2X3.docx | Modified File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\AppData\Local\Google\Chrome\User Data\Default\[PabFox@protonmail.com ].abRCih0v-4SyiiCaK.FOX | Dropped File | Stream |
Unknown
|
...
|
»
C:\588bce7c90097ed212\1032\LocalizedData.xml | Modified File | Stream |
Unknown
|
...
|
»
C:\588bce7c90097ed212\[PabFox@protonmail.com ].yVCNeUwj-l2BUB8g5.FOX | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\AppData\Roaming\Mozilla\Firefox\Profiles\w7cr0hor.default\[PabFox@protonmail.com ].eg3Q5qsX-KwXvZub0.FOX | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\AppData\Roaming\y1zWrD77yAaLi.jpg | Modified File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\Documents\cQRVefb0dfb76H87.xlsx | Modified File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\AppData\Roaming\[PabFox@protonmail.com ].nzROKrTb-Q91syLvs.FOX | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\Documents\Xk_TgcHjhZ.docx | Modified File | Stream |
Unknown
|
...
|
»
C:\588bce7c90097ed212\1033\LocalizedData.xml | Modified File | Stream |
Unknown
|
...
|
»
C:\588bce7c90097ed212\Client\UiInfo.xml | Modified File | Stream |
Unknown
|
...
|
»
C:\588bce7c90097ed212\netfx_Extended_x86.msi | Modified File | Stream |
Unknown
|
...
|
»
C:\$GetCurrent\SafeOS\PartnerSetupComplete.cmd | Modified File | Batch |
Unknown
|
...
|
»
C:\588bce7c90097ed212\1035\[PabFox@protonmail.com ].qknhRFSy-EiADTNOX.FOX | Dropped File | Stream |
Unknown
|
...
|
»
C:\588bce7c90097ed212\1046\[PabFox@protonmail.com ].AjzMG1DI-Ro3wUTiq.FOX | Dropped File | Stream |
Unknown
|
...
|
»
C:\588bce7c90097ed212\DHtmlHeader.html | Modified File | Text |
Unknown
|
...
|
»
C:\588bce7c90097ed212\ParameterInfo.xml | Modified File | Stream |
Unknown
|
...
|
»
C:\588bce7c90097ed212\Windows6.0-KB956250-v6001-x86.msu | Modified File | Stream |
Unknown
|
...
|
»
C:\Logs\[PabFox@protonmail.com ].MV6BjkZ8-gsWIjAoy.FOX | Dropped File | Stream |
Unknown
|
...
|
»
C:\Logs\[PabFox@protonmail.com ].AEetWEgq-aavyCqvF.FOX | Dropped File | Stream |
Unknown
|
...
|
»
C:\Logs\[PabFox@protonmail.com ].yM7NzQ0R-KYEzFCV5.FOX | Dropped File | Stream |
Unknown
|
...
|
»
C:\Logs\[PabFox@protonmail.com ].5jw2qisw-WPOdxUit.FOX | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\Documents\zZBH_J5DoYq-QhDed8gg\AjdmNjyPOTE3VOu.xls | Modified File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\Documents\zZBH_J5DoYq-QhDed8gg\qQ-KrIuhQ9v.ods | Modified File | Stream |
Unknown
|
...
|
»
C:\588bce7c90097ed212\Windows6.1-KB958488-v6001-x86.msu | Modified File | Stream |
Unknown
|
...
|
»
C:\Logs\[PabFox@protonmail.com ].TczfsrRH-EBhoQfKo.FOX | Dropped File | Stream |
Unknown
|
...
|
»
C:\Logs\[PabFox@protonmail.com ].crHHjxm2-8suXpKEv.FOX | Dropped File | Stream |
Unknown
|
...
|
»
C:\Logs\Microsoft-Windows-Kernel-ShimEngine%4Operational.evtx | Modified File | Stream |
Unknown
|
...
|
»
C:\Logs\[PabFox@protonmail.com ].TvVNG9pa-I4f1sO7r.FOX | Dropped File | Stream |
Unknown
|
...
|
»
C:\Logs\[PabFox@protonmail.com ].kZEyStmP-BYxHqG9q.FOX | Dropped File | Stream |
Unknown
|
...
|
»
C:\Logs\Microsoft-Windows-NCSI%4Operational.evtx | Modified File | Stream |
Unknown
|
...
|
»
C:\Logs\Microsoft-Windows-Windows Defender%4Operational.evtx | Modified File | Stream |
Unknown
|
...
|
»
C:\Logs\[PabFox@protonmail.com ].AWiOqJo1-MIi2WFQ6.FOX | Dropped File | Stream |
Unknown
|
...
|
»
C:\Logs\[PabFox@protonmail.com ].liRsrjrP-XwAZYxjo.FOX | Dropped File | Stream |
Unknown
|
...
|
»
C:\Program Files\Java\jre1.8.0_144\bin\jabswitch.exe | Modified File | Stream |
Unknown
|
...
|
»
C:\Program Files\Java\jre1.8.0_144\bin\[PabFox@protonmail.com ].YnEEOLGC-mjrUGYLT.FOX | Dropped File | Stream |
Unknown
|
...
|
»
C:\Program Files\Java\jre1.8.0_144\bin\servertool.exe | Modified File | Stream |
Unknown
|
...
|
»
C:\588bce7c90097ed212\1030\[PabFox@protonmail.com ].M5vht2GS-vJDe0sE6.FOX | Dropped File | Stream |
Unknown
|
...
|
»
C:\Program Files\UNP\CampaignManager\Campaigns\{91be532c-f9f1-406a-9858-43697c6f437a}\Content1\en-AU\index.html | Modified File | Text |
Unknown
|
...
|
»
C:\Program Files\Java\jre1.8.0_144\lib\fonts\LucidaTypewriterRegular.ttf | Modified File | Stream |
Unknown
|
...
|
»
C:\Program Files\UNP\CampaignManager\Campaigns\{91be532c-f9f1-406a-9858-43697c6f437a}\Content1\en-IE\index.html | Modified File | Text |
Unknown
|
...
|
»
C:\588bce7c90097ed212\3076\[PabFox@protonmail.com ].HQltbUyt-13VQ8tUI.FOX | Dropped File | Stream |
Unknown
|
...
|
»
C:\Program Files\Java\jre1.8.0_144\lib\javafx.properties | Modified File | Stream |
Unknown
|
...
|
»
C:\Program Files\Java\jre1.8.0_144\lib\management\jmxremote.access | Modified File | Stream |
Unknown
|
...
|
»
C:\588bce7c90097ed212\Extended\[PabFox@protonmail.com ].Yt9SagI7-p5lbCOZl.FOX | Dropped File | Stream |
Unknown
|
...
|
»
C:\Program Files\UNP\CampaignManager\Campaigns\{91be532c-f9f1-406a-9858-43697c6f437a}\Content1\en-US\index.html | Modified File | Text |
Unknown
|
...
|
»
C:\Program Files\UNP\CampaignManager\Campaigns\{91be532c-f9f1-406a-9858-43697c6f437a}\Content1\es-AR\[PabFox@protonmail.com ].AcX3jaMW-xyprCacP.FOX | Dropped File | Stream |
Unknown
|
...
|
»
C:\Program Files\UNP\CampaignManager\Campaigns\{91be532c-f9f1-406a-9858-43697c6f437a}\Content1\es-ES\[PabFox@protonmail.com ].mSpLn4DY-DRNluL1D.FOX | Dropped File | Text |
Unknown
|
...
|
»
C:\Program Files\UNP\CampaignManager\Campaigns\{91be532c-f9f1-406a-9858-43697c6f437a}\Content1\es-US\toastbeginupgradeth2.xml | Modified File | Stream |
Unknown
|
...
|
»
C:\Program Files\UNP\CampaignManager\Campaigns\{91be532c-f9f1-406a-9858-43697c6f437a}\Content1\eu-ES\[PabFox@protonmail.com ].iOqDaRTl-ChzqjdaZ.FOX | Dropped File | Text |
Unknown
|
...
|
»
C:\Program Files\Java\jre1.8.0_144\lib\deploy\splash_11-lic.gif | Modified File | Stream |
Unknown
|
...
|
»
C:\Program Files\Mozilla Firefox\browser\features\firefox@getpocket.com.xpi | Modified File | Stream |
Unknown
|
...
|
»
C:\Program Files\UNP\CampaignManager\Campaigns\{91be532c-f9f1-406a-9858-43697c6f437a}\Content1\fr-CH\toastreviewsettings.xml | Modified File | Stream |
Unknown
|
...
|
»
C:\Program Files\UNP\CampaignManager\Campaigns\{91be532c-f9f1-406a-9858-43697c6f437a}\Content1\hr-HR\toastreviewsettings.xml | Modified File | Binary |
Unknown
|
...
|
»
C:\Program Files\UNP\CampaignManager\Campaigns\{91be532c-f9f1-406a-9858-43697c6f437a}\Content1\it-IT\index.html | Modified File | Text |
Unknown
|
...
|
»
C:\Program Files\Mozilla Firefox\crashreporter.exe | Modified File | Stream |
Unknown
|
...
|
»
C:\Program Files\Mozilla Firefox\plugin-container.exe | Modified File | Stream |
Unknown
|
...
|
»
C:\Program Files (x86)\desktop.ini | Modified File | Stream |
Unknown
|
...
|
»
C:\Program Files (x86)\Google\Chrome\Application\61.0.3163.79\default_apps\drive.crx | Modified File | Stream |
Unknown
|
...
|
»
C:\Program Files\UNP\CampaignManager\Campaigns\{91be532c-f9f1-406a-9858-43697c6f437a}\Content1\nb-NO\index.html | Modified File | Text |
Unknown
|
...
|
»
C:\Program Files\UNP\CampaignManager\Campaigns\{91be532c-f9f1-406a-9858-43697c6f437a}\Content1\pt-BR\index.html | Modified File | Text |
Unknown
|
...
|
»
C:\Program Files\UNP\CampaignManager\Campaigns\{91be532c-f9f1-406a-9858-43697c6f437a}\Content1\de-AT\toastreviewsettings.xml | Modified File | Stream |
Unknown
|
...
|
»
C:\Program Files\UNP\CampaignManager\Campaigns\{91be532c-f9f1-406a-9858-43697c6f437a}\Content1\en-ID\toastbeginupgrade.xml | Modified File | Stream |
Unknown
|
...
|
»
C:\Program Files\UNP\CampaignManager\Campaigns\{91be532c-f9f1-406a-9858-43697c6f437a}\Content1\en-IN\toastreviewsettings.xml | Modified File | Stream |
Unknown
|
...
|
»
C:\Program Files (x86)\Google\Chrome\Application\61.0.3163.79\Locales\es.pak | Modified File | Stream |
Unknown
|
...
|
»
C:\Program Files\Java\jre1.8.0_144\lib\fonts\LucidaBrightDemiItalic.ttf | Modified File | Stream |
Unknown
|
...
|
»
C:\Program Files\Java\jre1.8.0_144\lib\images\cursors\win32_CopyDrop32x32.gif | Modified File | Stream |
Unknown
|
...
|
»
C:\Program Files\Java\jre1.8.0_144\lib\ext\[PabFox@protonmail.com ].9zmtFUN4-xMt0Yvdo.FOX | Dropped File | Stream |
Unknown
|
...
|
»
C:\Program Files\Java\jre1.8.0_144\lib\[PabFox@protonmail.com ].8K4yrIz2-UlDXaaTH.FOX | Dropped File | Stream |
Unknown
|
...
|
»
C:\Program Files\Java\jre1.8.0_144\lib\management\[PabFox@protonmail.com ].3x9nddH2-JnI15ozn.FOX | Dropped File | Stream |
Unknown
|
...
|
»
C:\Logs\[PabFox@protonmail.com ].UujZfKrd-3APKzIlT.FOX | Dropped File | Stream |
Unknown
|
...
|
»
C:\Program Files\UNP\CampaignManager\Campaigns\{91be532c-f9f1-406a-9858-43697c6f437a}\Content1\zh-CN\index.html | Modified File | Text |
Unknown
|
...
|
»
C:\Logs\[PabFox@protonmail.com ].OUAi1nS6-mNiWfM6T.FOX | Dropped File | Stream |
Unknown
|
...
|
»
C:\Program Files\Java\jre1.8.0_144\lib\[PabFox@protonmail.com ].QG3r0DE3-rnyGopOg.FOX | Dropped File | Stream |
Unknown
|
...
|
»
C:\Program Files\Mozilla Firefox\Accessible.tlb | Modified File | Stream |
Unknown
|
...
|
»
C:\Logs\[PabFox@protonmail.com ].oBwQoeJo-VlAUgyW0.FOX | Dropped File | Stream |
Unknown
|
...
|
»
C:\Program Files\Mozilla Firefox\browser\features\screenshots@mozilla.org.xpi | Modified File | Stream |
Unknown
|
...
|
»
C:\Program Files\Java\jre1.8.0_144\lib\deploy\messages_ja.properties | Modified File | Stream |
Unknown
|
...
|
»
C:\Program Files\Mozilla Firefox\install.log | Modified File | Stream |
Unknown
|
...
|
»
C:\Program Files\Java\jre1.8.0_144\lib\ext\sunec.jar | Modified File | Stream |
Unknown
|
...
|
»
C:\Program Files\Java\jre1.8.0_144\lib\fonts\[PabFox@protonmail.com ].D2T5tQX1-dQlp4iIN.FOX | Dropped File | Stream |
Unknown
|
...
|
»
C:\Program Files\rempl\Logs\Remediation.001.etl | Modified File | Stream |
Unknown
|
...
|
»
C:\Program Files\Java\jre1.8.0_144\lib\images\cursors\win32_CopyNoDrop32x32.gif | Modified File | Stream |
Unknown
|
...
|
»
C:\Program Files\UNP\CampaignManager\Campaigns\{91be532c-f9f1-406a-9858-43697c6f437a}\Content1\fr-FR\index.html | Modified File | Text |
Unknown
|
...
|
»
C:\Program Files\UNP\CampaignManager\Campaigns\{91be532c-f9f1-406a-9858-43697c6f437a}\Content1\hu-HU\[PabFox@protonmail.com ].yGsL4X62-rvpaOJ4x.FOX | Dropped File | Text |
Unknown
|
...
|
»
C:\Program Files\UNP\CampaignManager\Campaigns\{91be532c-f9f1-406a-9858-43697c6f437a}\Content1\lv-LV\[PabFox@protonmail.com ].rAqdTCv0-HWMLmXh5.FOX | Dropped File | Text |
Unknown
|
...
|
»
C:\Logs\[PabFox@protonmail.com ].BEQd9qId-OsMRQWFt.FOX | Dropped File | Stream |
Unknown
|
...
|
»
C:\Logs\[PabFox@protonmail.com ].rsyWxexW-1oe6647O.FOX | Dropped File | Stream |
Unknown
|
...
|
»
C:\Program Files\UNP\CampaignManager\Campaigns\{91be532c-f9f1-406a-9858-43697c6f437a}\Content1\ca-ES\[PabFox@protonmail.com ].04Mwjy23-Nxoz4kXp.FOX | Dropped File | Stream |
Unknown
|
...
|
»
C:\Program Files\UNP\CampaignManager\Campaigns\{91be532c-f9f1-406a-9858-43697c6f437a}\Content1\cs-CZ\[PabFox@protonmail.com ].A6IG09dx-a4JUkylG.FOX | Dropped File | Stream |
Unknown
|
...
|
»
C:\Program Files\Java\jre1.8.0_144\lib\[PabFox@protonmail.com ].eiJ0YWNE-LyfXVReM.FOX | Dropped File | Stream |
Unknown
|
...
|
»
C:\Program Files\Java\jre1.8.0_144\lib\[PabFox@protonmail.com ].8KLkPTq3-UeplzkIi.FOX | Dropped File | Stream |
Unknown
|
...
|
»
C:\Program Files\Java\jre1.8.0_144\lib\[PabFox@protonmail.com ].xTboccPO-uduxOsks.FOX | Dropped File | Stream |
Unknown
|
...
|
»
C:\Program Files\Java\jre1.8.0_144\lib\[PabFox@protonmail.com ].NtLkUudN-pbRwRIsO.FOX | Dropped File | Stream |
Unknown
|
...
|
»
C:\Program Files\Java\jre1.8.0_144\lib\security\[PabFox@protonmail.com ].Iv7WtaPX-aiLHlzZv.FOX | Dropped File | Stream |
Unknown
|
...
|
»
C:\Program Files\Java\jre1.8.0_144\[PabFox@protonmail.com ].JoSYf9Ty-DPOU4zw6.FOX | Dropped File | Stream |
Unknown
|
...
|
»
C:\Program Files\Mozilla Firefox\browser\[PabFox@protonmail.com ].7hPCQ3dd-ZKBvCcmh.FOX | Dropped File | Stream |
Unknown
|
...
|
»
C:\Program Files\UNP\CampaignManager\Campaigns\{91be532c-f9f1-406a-9858-43697c6f437a}\Content1\pt-BR\toastbeginupgrade.xml | Modified File | Stream |
Unknown
|
...
|
»
C:\Program Files\UNP\CampaignManager\Campaigns\{91be532c-f9f1-406a-9858-43697c6f437a}\Content1\resources\[PabFox@protonmail.com ].5L941IID-c27tiv6o.FOX | Dropped File | Text |
Unknown
|
...
|
»
C:\Program Files\UNP\CampaignManager\Campaigns\{91be532c-f9f1-406a-9858-43697c6f437a}\Content1\ro-RO\[PabFox@protonmail.com ].FaBxO1bY-sPyVsBx4.FOX | Dropped File | Stream |
Unknown
|
...
|
»
C:\Program Files\UNP\CampaignManager\Campaigns\{91be532c-f9f1-406a-9858-43697c6f437a}\Content1\sv-SE\[PabFox@protonmail.com ].N3dkT3st-Toukfuct.FOX | Dropped File | Stream |
Unknown
|
...
|
»
C:\Program Files\UNP\CampaignManager\Campaigns\{91be532c-f9f1-406a-9858-43697c6f437a}\Content1\en-MY\[PabFox@protonmail.com ].xHeepl89-soSgPVUK.FOX | Dropped File | Stream |
Unknown
|
...
|
»
C:\Program Files\UNP\CampaignManager\Campaigns\{91be532c-f9f1-406a-9858-43697c6f437a}\Content1\es-AR\[PabFox@protonmail.com ].oIypzv1m-Yku3Scx1.FOX | Dropped File | Stream |
Unknown
|
...
|
»
C:\Program Files\Java\jre1.8.0_144\bin\[PabFox@protonmail.com ].ZwDCaQv5-L71kym9V.FOX | Dropped File | Stream |
Unknown
|
...
|
»
C:\Program Files\Java\jre1.8.0_144\bin\klist.exe | Modified File | Stream |
Unknown
|
...
|
»
C:\Program Files\Java\jre1.8.0_144\bin\[PabFox@protonmail.com ].7W2H0bzo-pkxPhau2.FOX | Dropped File | Stream |
Unknown
|
...
|
»
C:\Program Files\Java\jre1.8.0_144\lib\cmm\GRAY.pf | Modified File | Stream |
Unknown
|
...
|
»
C:\Program Files\UNP\CampaignManager\Campaigns\{91be532c-f9f1-406a-9858-43697c6f437a}\Content1\zh-TW\[PabFox@protonmail.com ].ZPckROFd-M7xHpKQW.FOX | Dropped File | Stream |
Unknown
|
...
|
»
C:\Program Files\UNP\CampaignManager\Campaigns\{91be532c-f9f1-406a-9858-43697c6f437a}\Content1\es-US\[PabFox@protonmail.com ].mV1N2GkB-bgLP4s16.FOX | Dropped File | Stream |
Unknown
|
...
|
»
C:\Program Files\UNP\CampaignManager\Campaigns\{91be532c-f9f1-406a-9858-43697c6f437a}\Content1\fr-BE\toastbeginupgrade.xml | Modified File | Stream |
Unknown
|
...
|
»
C:\Program Files\UNP\CampaignManager\Campaigns\{91be532c-f9f1-406a-9858-43697c6f437a}\Content1\ro-RO\index.html | Modified File | Text |
Unknown
|
...
|
»
C:\Program Files\UNP\CampaignManager\Campaigns\{91be532c-f9f1-406a-9858-43697c6f437a}\Content1\sk-SK\[PabFox@protonmail.com ].EUwsbxxL-iHZSF8JZ.FOX | Dropped File | Stream |
Unknown
|
...
|
»
C:\Program Files\UNP\CampaignManager\Campaigns\{91be532c-f9f1-406a-9858-43697c6f437a}\Content1\sv-SE\[PabFox@protonmail.com ].EXC2poVJ-OonaGDec.FOX | Dropped File | Text |
Unknown
|
...
|
»
C:\Program Files\UNP\CampaignManager\Campaigns\{91be532c-f9f1-406a-9858-43697c6f437a}\Content1\fr-CH\[PabFox@protonmail.com ].VuaGiT5u-xjaXZ4Tp.FOX | Dropped File | Stream |
Unknown
|
...
|
»
C:\Program Files (x86)\Google\Chrome\Application\61.0.3163.79\Locales\[PabFox@protonmail.com ].ZNeDwSpa-IQPcP1Z0.FOX | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\Desktop\ZDBJ74pb.txt | Dropped File | Text |
Unknown
|
...
|
»
C:\Users\FD1HVy\Desktop\uQipLGFL.bat | Dropped File | Batch |
Unknown
|
...
|
»
C:\Program Files\Java\jre1.8.0_144\lib\jfr\#FOX_README#.rtf | Dropped File | RTF |
Unknown
|
...
|
»
Office Information
»
Document Content Snippet
»
HOW TO RECOVER YOUR FILES INSTRUCTION ATENTION!!! We are realy sorry to inform you thatALL YOUR FILES WERE ENCRYPTEDby our automatic software. It became possible because of bad server security.ATENTION!!! Please don't worry, we can help you to RESTORE your server to original state and decrypt all your files quickly and safely!INFORMATION!!! Files are not broken!!! Files were encrypted with AES-128+RSA-2048 crypto algorithms. There is no way to decrypt your files without unique decryption key and special software. Your unique decryption key is securely stored on our server. For our safety, all information about your server and your decryption key will be automaticaly DELETED AFTER 7 DAYS! You will irrevocably lose all your data! * Please note that all the attempts to recover your files by yourself or using third party tools will result only in irrevocable loss of your data! * Please note that you can recover files only with your unique decryption key, which stored on our side. ... |
Embedded URLs (4)
»
URL | First Seen | Categories | Threat Names | Reputation Status | WHOIS Data | Actions |
---|---|---|---|---|---|---|
https://bitmsg.me/users/sign_upnd | - | - | - |
Unknown
|
Not Queried
|
...
|
https://bitmsg.me | - | - | - |
Unknown
|
Not Queried
|
...
|
https://bitmsg.me/users/sign_up | - | - | - |
Unknown
|
Not Queried
|
...
|
https://bitmsg.me/users/sign_in | - | - | - |
Unknown
|
Not Queried
|
...
|
C:\588bce7c90097ed212\Windows6.1-KB958488-v6001-x64.msu | Modified File | Stream |
Not Queried
|
...
|
»
C:\Users\FD1HVy\AppData\Roaming\Mozilla\Firefox\Profiles\w7cr0hor.default\favicons.sqlite | Modified File | Stream |
Not Queried
|
...
|
»
C:\Users\FD1HVy\AppData\Roaming\Mozilla\Firefox\Profiles\w7cr0hor.default\kinto.sqlite | Modified File | Stream |
Not Queried
|
...
|
»
C:\Program Files\Java\jre1.8.0_144\lib\charsets.jar | Modified File | Stream |
Not Queried
|
...
|
»
C:\Program Files\Java\jre1.8.0_144\lib\cmm\CIEXYZ.pf | Modified File | Stream |
Not Queried
|
...
|
»
C:\Program Files\Java\jre1.8.0_144\lib\deploy\splash@2x.gif | Modified File | Stream |
Not Queried
|
...
|
»
C:\Logs\Microsoft-Windows-MUI%4Operational.evtx | Modified File | Stream |
Not Queried
|
...
|
»
C:\Logs\Microsoft-Windows-Shell-Core%4ActionCenter.evtx | Modified File | Stream |
Not Queried
|
...
|
»
C:\Users\FD1HVy\Documents\Database1.accdb | Modified File | Stream |
Not Queried
|
...
|
»
C:\Users\FD1HVy\Pictures\M-9eF6mF.jpg | Modified File | Stream |
Not Queried
|
...
|
»
C:\588bce7c90097ed212\1038\LocalizedData.xml | Modified File | Stream |
Not Queried
|
...
|
»
C:\Users\FD1HVy\Documents\ot70.xlsx | Modified File | Stream |
Not Queried
|
...
|
»
C:\Users\FD1HVy\Documents\qj87MQXJ-kb3M\RxZGbiJgfgTdN.xls | Modified File | Stream |
Not Queried
|
...
|
»
C:\Users\FD1HVy\Documents\qj87MQXJ-kb3M\83W3EJP2v.doc | Modified File | Stream |
Not Queried
|
...
|
»
C:\Users\FD1HVy\Documents\qj87MQXJ-kb3M\bP TPQz8ySbTmo\ZaO712WlDP_z.ods | Modified File | Stream |
Not Queried
|
...
|
»
C:\Users\FD1HVy\AppData\Roaming\Microsoft\Access\AccessCache.accdb | Modified File | Stream |
Not Queried
|
...
|
»
C:\Users\FD1HVy\Pictures\Hjsdw K84W5LH.jpg | Modified File | Stream |
Not Queried
|
...
|
»
C:\Logs\Microsoft-Windows-BackgroundTaskInfrastructure%4Operational.evtx | Modified File | Stream |
Not Queried
|
...
|
»
C:\Logs\Microsoft-Windows-Dhcpv6-Client%4Admin.evtx | Modified File | Stream |
Not Queried
|
...
|
»
C:\Logs\Microsoft-Windows-Kernel-Power%4Thermal-Operational.evtx | Modified File | Stream |
Not Queried
|
...
|
»
C:\Logs\Microsoft-Windows-NetworkProfile%4Operational.evtx | Modified File | Stream |
Not Queried
|
...
|
»
C:\Program Files\Java\jre1.8.0_144\lib\fonts\LucidaBrightDemiBold.ttf | Modified File | Stream |
Not Queried
|
...
|
»
C:\Program Files\Java\jre1.8.0_144\lib\images\cursors\invalid32x32.gif | Modified File | Stream |
Not Queried
|
...
|
»
C:\Program Files\Java\jre1.8.0_144\lib\jfr\default.jfc | Modified File | Stream |
Not Queried
|
...
|
»
C:\Program Files\Java\jre1.8.0_144\lib\security\blacklisted.certs | Modified File | Stream |
Not Queried
|
...
|
»
C:\588bce7c90097ed212\1055\LocalizedData.xml | Modified File | Stream |
Not Queried
|
...
|
»
C:\$GetCurrent\SafeOS\SetupComplete.cmd | Modified File | Batch |
Not Queried
|
...
|
»
C:\588bce7c90097ed212\1053\LocalizedData.xml | Modified File | Stream |
Not Queried
|
...
|
»
C:\Users\FD1HVy\Documents\Csq3UInAzbtq A.xlsx | Modified File | Stream |
Not Queried
|
...
|
»
C:\Users\FD1HVy\AppData\Roaming\yF648rhpQNIOH.xls | Modified File | Stream |
Not Queried
|
...
|
»
C:\Users\FD1HVy\Documents\N1au\Orqp.ods | Modified File | Stream |
Not Queried
|
...
|
»
C:\Users\FD1HVy\AppData\Roaming\Mozilla\Firefox\Profiles\w7cr0hor.default\secmod.db | Modified File | Stream |
Not Queried
|
...
|
»
C:\Logs\Microsoft-Windows-SmbClient%4Connectivity.evtx | Modified File | Stream |
Not Queried
|
...
|
»
C:\Logs\Microsoft-Windows-TerminalServices-LocalSessionManager%4Operational.evtx | Modified File | Stream |
Not Queried
|
...
|
»
C:\Logs\Microsoft-Windows-Windows Defender%4WHC.evtx | Modified File | Stream |
Not Queried
|
...
|
»
C:\Program Files\Mozilla Firefox\application.ini | Modified File | Stream |
Not Queried
|
...
|
»
C:\Program Files\desktop.ini | Modified File | Stream |
Not Queried
|
...
|
»
C:\Program Files\Java\jre1.8.0_144\bin\server\Xusage.txt | Modified File | Stream |
Not Queried
|
...
|
»
C:\Program Files\Java\jre1.8.0_144\lib\classlist | Modified File | Stream |
Not Queried
|
...
|
»
C:\Program Files\Java\jre1.8.0_144\lib\deploy\messages_es.properties | Modified File | Stream |
Not Queried
|
...
|
»
C:\588bce7c90097ed212\Extended\UiInfo.xml | Modified File | Stream |
Not Queried
|
...
|
»
C:\Program Files\Java\jre1.8.0_144\lib\deploy\messages_de.properties | Modified File | Stream |
Not Queried
|
...
|
»
C:\Users\FD1HVy\AppData\Roaming\Mozilla\Firefox\Profiles\w7cr0hor.default\storage\permanent\chrome\idb\2918063365piupsah.sqlite | Modified File | Stream |
Not Queried
|
...
|
»
C:\Users\FD1HVy\Documents\qj87MQXJ-kb3M\eJf_kpicJu.xlsx | Modified File | Stream |
Not Queried
|
...
|
»
C:\Users\FD1HVy\Documents\dzgmYcvpdtQMT.docx | Modified File | Stream |
Not Queried
|
...
|
»
C:\Users\FD1HVy\AppData\Roaming\MYwZiTEu.odt | Modified File | Stream |
Not Queried
|
...
|
»
C:\Program Files\Mozilla Firefox\browser\features\shield-recipe-client@mozilla.org.xpi | Modified File | Stream |
Not Queried
|
...
|
»
C:\Users\FD1HVy\Pictures\hapMvqq9CS1xm4Dna.jpg | Modified File | Stream |
Not Queried
|
...
|
»
C:\Program Files\Mozilla Firefox\dependentlibs.list | Modified File | Stream |
Not Queried
|
...
|
»
C:\Program Files\Java\jre1.8.0_144\bin\jjs.exe | Modified File | Stream |
Not Queried
|
...
|
»
C:\Program Files\Mozilla Firefox\maintenanceservice.exe | Modified File | Stream |
Not Queried
|
...
|
»
C:\Program Files\Java\jre1.8.0_144\lib\deploy\messages_zh_TW.properties | Modified File | Stream |
Not Queried
|
...
|
»
C:\Users\FD1HVy\Documents\KbxCAJNWE.docx | Modified File | Stream |
Not Queried
|
...
|
»
C:\Users\FD1HVy\Documents\LLmsz.odt | Modified File | Stream |
Not Queried
|
...
|
»
C:\588bce7c90097ed212\1036\LocalizedData.xml | Modified File | Stream |
Not Queried
|
...
|
»
C:\Program Files\UNP\CampaignManager\Campaigns\{91be532c-f9f1-406a-9858-43697c6f437a}\Content1\ca-ES\toastbeginupgradeth2.xml | Modified File | Stream |
Not Queried
|
...
|
»
C:\588bce7c90097ed212\Setup.exe | Modified File | Stream |
Not Queried
|
...
|
»
C:\Program Files\Java\jre1.8.0_144\bin\rmiregistry.exe | Modified File | Stream |
Not Queried
|
...
|
»
C:\ProgramData\Microsoft\Network\Downloader\qmgr.db | Modified File | Stream |
Not Queried
|
...
|
»
C:\Program Files\Java\jre1.8.0_144\lib\calendars.properties | Modified File | Stream |
Not Queried
|
...
|
»
C:\Program Files\Java\jre1.8.0_144\lib\deploy\messages.properties | Modified File | Stream |
Not Queried
|
...
|
»
C:\Program Files\Java\jre1.8.0_144\lib\deploy\messages_zh_HK.properties | Modified File | Stream |
Not Queried
|
...
|
»
C:\Users\FD1HVy\Documents\qj87MQXJ-kb3M\6m32Brpo1p.pdf | Modified File | Stream |
Not Queried
|
...
|
»
C:\Program Files\Java\jre1.8.0_144\lib\ext\jaccess.jar | Modified File | Stream |
Not Queried
|
...
|
»
C:\$GetCurrent\Logs\downlevel_2017_09_07_02_02_39_766.log | Modified File | Stream |
Not Queried
|
...
|
»
C:\Logs\Microsoft-Windows-AppModel-Runtime%4Admin.evtx | Modified File | Stream |
Not Queried
|
...
|
»
C:\Program Files\Java\jre1.8.0_144\lib\flavormap.properties | Modified File | Stream |
Not Queried
|
...
|
»
C:\Program Files\UNP\CampaignManager\Campaigns\{91be532c-f9f1-406a-9858-43697c6f437a}\Content1\de-CH\toastbeginupgradeth2.xml | Modified File | Stream |
Not Queried
|
...
|
»
C:\Users\FD1HVy\AppData\Local\Mozilla\Firefox\Profiles\w7cr0hor.default\OfflineCache\index.sqlite | Modified File | Stream |
Not Queried
|
...
|
»
C:\Users\FD1HVy\AppData\Roaming\Mozilla\Firefox\Profiles\w7cr0hor.default\storage.sqlite | Modified File | Stream |
Not Queried
|
...
|
»
C:\Users\FD1HVy\Documents\[PabFox@protonmail.com ].W62q62hE-1OXHHA3n.FOX | Dropped File | Stream |
Not Queried
|
...
|
»
C:\Users\FD1HVy\Documents\N1au\NR7Jrc GNhMrZ.odt | Modified File | Stream |
Not Queried
|
...
|
»
C:\588bce7c90097ed212\1031\LocalizedData.xml | Modified File | Stream |
Not Queried
|
...
|
»
C:\Users\FD1HVy\Documents\[PabFox@protonmail.com ].Qlm1UpJK-3bIMNGxy.FOX | Dropped File | Stream |
Not Queried
|
...
|
»
C:\588bce7c90097ed212\1043\LocalizedData.xml | Modified File | Stream |
Not Queried
|
...
|
»
C:\Users\FD1HVy\Documents\zZBH_J5DoYq-QhDed8gg\[PabFox@protonmail.com ].vStolkG5-cdiwI263.FOX | Dropped File | Stream |
Not Queried
|
...
|
»
C:\Users\FD1HVy\Documents\vWWTmE1blj.docx | Modified File | Stream |
Not Queried
|
...
|
»
C:\Users\FD1HVy\Documents\qj87MQXJ-kb3M\[PabFox@protonmail.com ].ueBcuqIH-RdnA8Knn.FOX | Dropped File | Stream |
Not Queried
|
...
|
»
C:\Program Files\Java\jre1.8.0_144\lib\ext\jfxrt.jar | Modified File | Stream |
Not Queried
|
...
|
»
C:\Program Files\UNP\CampaignManager\Campaigns\{91be532c-f9f1-406a-9858-43697c6f437a}\Content1\resources\[PabFox@protonmail.com ].Bdse1UDv-5h32Wgvk.FOX | Dropped File | Stream |
Not Queried
|
...
|
»
C:\$GetCurrent\Logs\[PabFox@protonmail.com ].7rBQEwZH-CM0wLfyK.FOX | Dropped File | Stream |
Not Queried
|
...
|
»
C:\Users\FD1HVy\AppData\Roaming\Mozilla\Firefox\Profiles\w7cr0hor.default\cert8.db | Modified File | Stream |
Not Queried
|
...
|
»
C:\$GetCurrent\SafeOS\GetCurrentRollback.ini | Modified File | Stream |
Not Queried
|
...
|
»
C:\588bce7c90097ed212\1044\LocalizedData.xml | Modified File | Stream |
Not Queried
|
...
|
»
C:\588bce7c90097ed212\Client\Parameterinfo.xml | Modified File | Stream |
Not Queried
|
...
|
»
C:\Users\FD1HVy\AppData\Roaming\[PabFox@protonmail.com ].dqOcvyqu-z2gWHTsb.FOX | Dropped File | Stream |
Not Queried
|
...
|
»
C:\Users\FD1HVy\AppData\Roaming\Mozilla\Firefox\Profiles\w7cr0hor.default\[PabFox@protonmail.com ].nDEC7x3t-nD0WrTvv.FOX | Dropped File | Stream |
Not Queried
|
...
|
»
C:\Users\FD1HVy\Pictures\[PabFox@protonmail.com ].04KMoErW-r1m6Mjxx.FOX | Dropped File | Stream |
Not Queried
|
...
|
»
C:\588bce7c90097ed212\1045\LocalizedData.xml | Modified File | Stream |
Not Queried
|
...
|
»
C:\588bce7c90097ed212\[PabFox@protonmail.com ].bIe2aozT-uYKGDNFh.FOX | Dropped File | Stream |
Not Queried
|
...
|
»
C:\Logs\[PabFox@protonmail.com ].TgjRovYJ-1EBHfLzk.FOX | Dropped File | Stream |
Not Queried
|
...
|
»
C:\Logs\[PabFox@protonmail.com ].da24UAps-RBLKgKX2.FOX | Dropped File | Stream |
Not Queried
|
...
|
»
C:\588bce7c90097ed212\Windows6.0-KB956250-v6001-x64.msu | Modified File | Stream |
Not Queried
|
...
|
»
C:\Logs\Microsoft-Windows-ApplicationResourceManagementSystem%4Operational.evtx | Modified File | Stream |
Not Queried
|
...
|
»
C:\Users\FD1HVy\AppData\Roaming\Mozilla\Firefox\Profiles\w7cr0hor.default\permissions.sqlite | Modified File | Stream |
Not Queried
|
...
|
»
C:\Users\FD1HVy\Documents\qj87MQXJ-kb3M\bP TPQz8ySbTmo\[PabFox@protonmail.com ].t7pPNr3B-HGPoktSk.FOX | Dropped File | Stream |
Not Queried
|
...
|
»
C:\Users\FD1HVy\Documents\[PabFox@protonmail.com ].ewLz6Jao-kUmgtMfH.FOX | Dropped File | Stream |
Not Queried
|
...
|
»
C:\Logs\[PabFox@protonmail.com ].8z6puTUq-mM2qhJIY.FOX | Dropped File | Stream |
Not Queried
|
...
|
»
C:\Logs\[PabFox@protonmail.com ].ZYsgNBWT-BKyfqkGs.FOX | Dropped File | Stream |
Not Queried
|
...
|
»
C:\Logs\Microsoft-Windows-TerminalServices-LocalSessionManager%4Admin.evtx | Modified File | Stream |
Not Queried
|
...
|
»
C:\Logs\Microsoft-Windows-TerminalServices-RemoteConnectionManager%4Admin.evtx | Modified File | Stream |
Not Queried
|
...
|
»
C:\Logs\Microsoft-Windows-Windows Firewall With Advanced Security%4ConnectionSecurity.evtx | Modified File | Stream |
Not Queried
|
...
|
»
C:\Program Files\Java\jre1.8.0_144\bin\[PabFox@protonmail.com ].RXELXmIo-iTDcKfYU.FOX | Dropped File | Stream |
Not Queried
|
...
|
»
C:\Logs\Microsoft-Windows-CoreSystem-SmsRouter-Events%4Operational.evtx | Modified File | Stream |
Not Queried
|
...
|
»
C:\Program Files\UNP\CampaignManager\Campaigns\{91be532c-f9f1-406a-9858-43697c6f437a}\Content1\en-GB\[PabFox@protonmail.com ].YqhKOoOF-ldizqm2k.FOX | Dropped File | Stream |
Not Queried
|
...
|
»
C:\Logs\[PabFox@protonmail.com ].LOOuVopI-4TzxP07t.FOX | Dropped File | Stream |
Not Queried
|
...
|
»
C:\588bce7c90097ed212\1042\LocalizedData.xml | Modified File | Stream |
Not Queried
|
...
|
»
C:\Logs\[PabFox@protonmail.com ].LfeY2JB7-jnA60NNB.FOX | Dropped File | Stream |
Not Queried
|
...
|
»
C:\588bce7c90097ed212\RGB9Rast_x86.msi | Modified File | Stream |
Not Queried
|
...
|
»
C:\Program Files\UNP\CampaignManager\Campaigns\{91be532c-f9f1-406a-9858-43697c6f437a}\Content1\en-MY\[PabFox@protonmail.com ].bDBBo2t9-Gk0PTbww.FOX | Dropped File | Stream |
Not Queried
|
...
|
»
C:\Program Files\UNP\CampaignManager\Campaigns\{91be532c-f9f1-406a-9858-43697c6f437a}\Content1\fr-BE\[PabFox@protonmail.com ].ecrh0MrL-jWWPtxXJ.FOX | Dropped File | Stream |
Not Queried
|
...
|
»
C:\Program Files\UNP\CampaignManager\Campaigns\{91be532c-f9f1-406a-9858-43697c6f437a}\Content1\gl-ES\toastbeginupgrade.xml | Modified File | Stream |
Not Queried
|
...
|
»
C:\Program Files\Java\jre1.8.0_144\lib\ext\nashorn.jar | Modified File | Stream |
Not Queried
|
...
|
»
C:\Program Files\Mozilla Firefox\freebl3.chk | Modified File | Stream |
Not Queried
|
...
|
»
C:\Program Files\Mozilla Firefox\updater.ini | Modified File | Stream |
Not Queried
|
...
|
»
C:\Program Files (x86)\Google\Chrome\Application\61.0.3163.79\Locales\bg.pak | Modified File | Stream |
Not Queried
|
...
|
»
C:\Program Files\UNP\CampaignManager\Campaigns\{91be532c-f9f1-406a-9858-43697c6f437a}\Content1\ko-KR\toastbeginupgradeth2.xml | Modified File | Stream |
Not Queried
|
...
|
»
C:\Program Files\UNP\CampaignManager\Campaigns\{91be532c-f9f1-406a-9858-43697c6f437a}\Content1\lt-LT\toastreviewsettings.xml | Modified File | Stream |
Not Queried
|
...
|
»
C:\Program Files\UNP\CampaignManager\Campaigns\{91be532c-f9f1-406a-9858-43697c6f437a}\Content1\nl-NL\toastbeginupgradeth2.xml | Modified File | Stream |
Not Queried
|
...
|
»
C:\Program Files\UNP\CampaignManager\Campaigns\{91be532c-f9f1-406a-9858-43697c6f437a}\Content1\resources\Back_0001_Static.png | Modified File | Stream |
Not Queried
|
...
|
»
C:\Program Files\UNP\CampaignManager\Campaigns\{91be532c-f9f1-406a-9858-43697c6f437a}\Content1\bg-BG\toastreviewsettings.xml | Modified File | Stream |
Not Queried
|
...
|
»
C:\Program Files\UNP\CampaignManager\Campaigns\{91be532c-f9f1-406a-9858-43697c6f437a}\Content1\cs-CZ\toastbeginupgrade.xml | Modified File | Stream |
Not Queried
|
...
|
»
C:\Program Files\UNP\CampaignManager\Campaigns\{91be532c-f9f1-406a-9858-43697c6f437a}\Content1\el-GR\toastbeginupgrade.xml | Modified File | Stream |
Not Queried
|
...
|
»
C:\Program Files\UNP\CampaignManager\Campaigns\{91be532c-f9f1-406a-9858-43697c6f437a}\Content1\en-CA\toastreviewsettings.xml | Modified File | Stream |
Not Queried
|
...
|
»
C:\Program Files (x86)\Google\Chrome\Application\61.0.3163.79\Locales\hu.pak | Modified File | Stream |
Not Queried
|
...
|
»
C:\Program Files\UNP\CampaignManager\Campaigns\{91be532c-f9f1-406a-9858-43697c6f437a}\Content1\en-PH\toastbeginupgrade.xml | Modified File | Stream |
Not Queried
|
...
|
»
C:\Program Files\UNP\CampaignManager\Campaigns\{91be532c-f9f1-406a-9858-43697c6f437a}\Content1\en-ZA\toastreviewsettings.xml | Modified File | Stream |
Not Queried
|
...
|
»
C:\Program Files\UNP\CampaignManager\Campaigns\{91be532c-f9f1-406a-9858-43697c6f437a}\Content1\es-CO\toastbeginupgrade.xml | Modified File | Stream |
Not Queried
|
...
|
»
C:\Program Files\UNP\CampaignManager\Campaigns\{91be532c-f9f1-406a-9858-43697c6f437a}\Content1\es-MX\toastreviewsettings.xml | Modified File | Stream |
Not Queried
|
...
|
»
C:\Program Files\UNP\CampaignManager\Campaigns\{91be532c-f9f1-406a-9858-43697c6f437a}\Content1\et-EE\toastbeginupgrade.xml | Modified File | Stream |
Not Queried
|
...
|
»
C:\Program Files\Java\jre1.8.0_144\lib\images\cursors\cursors.properties | Modified File | Stream |
Not Queried
|
...
|
»
C:\Program Files\Java\jre1.8.0_144\lib\jce.jar | Modified File | Stream |
Not Queried
|
...
|
»
C:\Logs\Microsoft-Windows-AppLocker%4Packaged app-Execution.evtx | Modified File | Stream |
Not Queried
|
...
|
»
C:\Logs\[PabFox@protonmail.com ].8TfjaKbf-lEYFmqhi.FOX | Dropped File | Stream |
Not Queried
|
...
|
»
C:\Logs\[PabFox@protonmail.com ].IkUAhMKR-RtRAF3g4.FOX | Dropped File | Stream |
Not Queried
|
...
|
»
C:\Logs\[PabFox@protonmail.com ].DcS9oJ2p-jteXLcSy.FOX | Dropped File | Stream |
Not Queried
|
...
|
»
C:\Logs\Microsoft-Windows-Kernel-StoreMgr%4Operational.evtx | Modified File | Stream |
Not Queried
|
...
|
»
C:\Program Files\Java\jre1.8.0_144\lib\security\[PabFox@protonmail.com ].EHB6vuIu-cf2OHX1w.FOX | Dropped File | Stream |
Not Queried
|
...
|
»
C:\Program Files\Java\jre1.8.0_144\bin\java.exe | Modified File | Stream |
Not Queried
|
...
|
»
C:\Program Files\Java\jre1.8.0_144\bin\ktab.exe | Modified File | Stream |
Not Queried
|
...
|
»
C:\Program Files\Java\jre1.8.0_144\bin\[PabFox@protonmail.com ].RfPwUvkA-34RYCSfO.FOX | Dropped File | Stream |
Not Queried
|
...
|
»
C:\Program Files\Java\jre1.8.0_144\lib\cmm\[PabFox@protonmail.com ].4bNSWWkE-MKHjX9LM.FOX | Dropped File | Stream |
Not Queried
|
...
|
»
C:\Program Files\Mozilla Firefox\defaults\pref\[PabFox@protonmail.com ].x2f4bc8H-zLczbq11.FOX | Dropped File | Text |
Not Queried
|
...
|
»
C:\Program Files\Java\jre1.8.0_144\lib\deploy\splash_11@2x-lic.gif | Modified File | Stream |
Not Queried
|
...
|
»
C:\Program Files\Mozilla Firefox\[PabFox@protonmail.com ].0J6kRyKz-6gSZdsbz.FOX | Dropped File | Stream |
Not Queried
|
...
|
»
C:\Program Files\UNP\CampaignManager\Campaigns\{91be532c-f9f1-406a-9858-43697c6f437a}\[PabFox@protonmail.com ].wHSCDPGn-i1WXdXmx.FOX | Dropped File | Stream |
Not Queried
|
...
|
»
C:\Program Files\UNP\CampaignManager\Campaigns\{91be532c-f9f1-406a-9858-43697c6f437a}\Content1\gl-ES\toastbeginupgradeth2.xml | Modified File | Stream |
Not Queried
|
...
|
»
C:\Program Files\UNP\CampaignManager\Campaigns\{91be532c-f9f1-406a-9858-43697c6f437a}\Content1\it-IT\toastbeginupgrade.xml | Modified File | Stream |
Not Queried
|
...
|
»
C:\Program Files\UNP\CampaignManager\Campaigns\{91be532c-f9f1-406a-9858-43697c6f437a}\Content1\ko-KR\[PabFox@protonmail.com ].B7mvXHdy-J1pscHbp.FOX | Dropped File | Stream |
Not Queried
|
...
|
»
C:\Logs\Microsoft-Windows-TerminalServices-RemoteConnectionManager%4Operational.evtx | Modified File | Stream |
Not Queried
|
...
|
»
C:\Program Files\UNP\CampaignManager\Campaigns\{91be532c-f9f1-406a-9858-43697c6f437a}\Content1\nb-NO\[PabFox@protonmail.com ].PJkCLATf-CeIk2zK0.FOX | Dropped File | Stream |
Not Queried
|
...
|
»
C:\Program Files\UNP\CampaignManager\Campaigns\{91be532c-f9f1-406a-9858-43697c6f437a}\Content1\nl-NL\[PabFox@protonmail.com ].1snlR2cz-OGTXisxt.FOX | Dropped File | Stream |
Not Queried
|
...
|
»
C:\Program Files\UNP\CampaignManager\Campaigns\{91be532c-f9f1-406a-9858-43697c6f437a}\Content1\sk-SK\toastreviewsettings.xml | Modified File | Stream |
Not Queried
|
...
|
»
C:\Program Files\UNP\CampaignManager\Campaigns\{91be532c-f9f1-406a-9858-43697c6f437a}\Content1\de-CH\toastbeginupgrade.xml | Modified File | Stream |
Not Queried
|
...
|
»
C:\Program Files\UNP\CampaignManager\Campaigns\{91be532c-f9f1-406a-9858-43697c6f437a}\Content1\el-GR\[PabFox@protonmail.com ].hbeTkwt3-pBqLwGd5.FOX | Dropped File | Stream |
Not Queried
|
...
|
»
C:\Program Files\UNP\CampaignManager\Campaigns\{91be532c-f9f1-406a-9858-43697c6f437a}\Content1\en-GB\toastbeginupgrade.xml | Modified File | Stream |
Not Queried
|
...
|
»
C:\Program Files\UNP\CampaignManager\Campaigns\{91be532c-f9f1-406a-9858-43697c6f437a}\Content1\en-ID\toastreviewsettings.xml | Modified File | Stream |
Not Queried
|
...
|
»
C:\Program Files\UNP\CampaignManager\Campaigns\{91be532c-f9f1-406a-9858-43697c6f437a}\Content1\en-PH\toastreviewsettings.xml | Modified File | Stream |
Not Queried
|
...
|
»
C:\Logs\Microsoft-Windows-Windows Firewall With Advanced Security%4Firewall.evtx | Modified File | Stream |
Not Queried
|
...
|
»
C:\Program Files\Java\jre1.8.0_144\lib\deploy\[PabFox@protonmail.com ].tRrCuCYs-SyerG59Z.FOX | Dropped File | Stream |
Not Queried
|
...
|
»
C:\Program Files\Microsoft Office 15\ClientX64\[PabFox@protonmail.com ].iO9WnWe8-Lt1vaoxL.FOX | Dropped File | Stream |
Not Queried
|
...
|
»
C:\Program Files\UNP\CampaignManager\Campaigns\{91be532c-f9f1-406a-9858-43697c6f437a}\Content1\tr-TR\[PabFox@protonmail.com ].qfMkuhCH-pIsz1wrI.FOX | Dropped File | Stream |
Not Queried
|
...
|
»
C:\Program Files\UNP\CampaignManager\Campaigns\{91be532c-f9f1-406a-9858-43697c6f437a}\Content1\zh-CN\[PabFox@protonmail.com ].84nJB92T-pzN6yrtk.FOX | Dropped File | Stream |
Not Queried
|
...
|
»
C:\Program Files\UNP\Logs\[PabFox@protonmail.com ].el7c6HE9-8MQ6dbvB.FOX | Dropped File | Stream |
Not Queried
|
...
|
»
C:\Program Files\UNP\CampaignManager\Campaigns\{91be532c-f9f1-406a-9858-43697c6f437a}\Content1\es-CO\toastreviewsettings.xml | Modified File | Stream |
Not Queried
|
...
|
»
C:\Program Files\UNP\CampaignManager\Campaigns\{91be532c-f9f1-406a-9858-43697c6f437a}\Content1\et-EE\[PabFox@protonmail.com ].lnQ5AGQj-cfLzews2.FOX | Dropped File | Stream |
Not Queried
|
...
|
»
C:\Program Files (x86)\Google\Chrome\Application\61.0.3163.79\Locales\[PabFox@protonmail.com ].AmhiYYUR-wtpQOmUL.FOX | Dropped File | Stream |
Not Queried
|
...
|
»
C:\Program Files\UNP\CampaignManager\Campaigns\{91be532c-f9f1-406a-9858-43697c6f437a}\Content1\fi-FI\[PabFox@protonmail.com ].BYdrIlqk-03iykmPS.FOX | Dropped File | Stream |
Not Queried
|
...
|
»
C:\Program Files\UNP\CampaignManager\Campaigns\{91be532c-f9f1-406a-9858-43697c6f437a}\Content1\tr-TR\toastbeginupgradeth2.xml | Modified File | Stream |
Not Queried
|
...
|
»
C:\Program Files\UNP\CampaignManager\Campaigns\{91be532c-f9f1-406a-9858-43697c6f437a}\Content1\fr-XF\[PabFox@protonmail.com ].tPEYJgiP-bQWEmJs1.FOX | Dropped File | Stream |
Not Queried
|
...
|
»
C:\Users\FD1HVy\Desktop\94.114.3.195_log.txt | Dropped File | Text |
Not Queried
|
...
|
»
C:\Users\FD1HVy\AppData\Roaming\SOaYAVjM.bmp | Dropped File | Image |
Not Queried
|
...
|
»
C:\Users\FD1HVy\AppData\Roaming\n9m2alXc.bat | Dropped File | Batch |
Not Queried
|
...
|
»
C:\Users\FD1HVy\Desktop\elog_46460E2CE57747F0.txt | Dropped File | Text |
Not Queried
|
...
|
»