|
5/5
|
Device
|
Writes to Master Boot Record (MBR)
|
-
|
|
-
Writes 512 bytes to master boot record (MBR).
|
|
4/5
|
File System
|
Modifies content of user files
|
Ransomware
|
|
-
Modifies the content of multiple user files. This is an indicator for an encryption attempt.
|
|
4/5
|
File System
|
Renames user files
|
Ransomware
|
|
-
Renames multiple user files. This is an indicator for an encryption attempt.
|
|
4/5
|
File System
|
Deletes user files
|
Wiper
|
|
-
Deletes multiple user files. This is an indicator for ransomware or wiper malware.
|
|
3/5
|
Persistence
|
Modifies startup configuration
|
-
|
|
-
Modifies the boot configuration by editing "c:\autoexec.bat".
|
|
3/5
|
Kernel
|
Executes code with kernel privileges
|
-
|
|
-
Executes code with kernel privileges to perform system level actions. This can sometimes be used to perform malicious actions and to avoid detection.
|
|
2/5
|
File System
|
Known suspicious file
|
Trojan
|
|
-
File "C:\Users\EEBsYm5\Desktop\80ca3de5d5f991c872ba07a0ffc035bf019f985bac71f4f379bcdea2de6203af.exe" is a known suspicious file.
|
|
1/5
|
Process
|
Creates process with hidden window
|
-
|
|
-
The process "vssadmin delete shadows /all /quiet" starts with hidden window.
|
|
1/5
|
Masquerade
|
Changes folder appearance
|
Riskware
|
|
-
Folder "c:\$recycle.bin\s-1-5-21-3785418085-2572485238-895829336-1000" has a changed appearance.
|
|
1/5
|
File System
|
Modifies application directory
|
-
|
|
-
Modifies "c:\program files\adobe\reader 10.0\benioku.htm".
|
|
-
Modifies "c:\program files\adobe\reader 10.0\berime.htm".
|
|
-
Modifies "c:\program files\adobe\reader 10.0\esl\aiodlite.dll".
|
|
-
Modifies "c:\program files\adobe\reader 10.0\irakhau.htm".
|
|
-
Modifies "c:\program files\adobe\reader 10.0\leame.htm".
|
|
-
Modifies "c:\program files\adobe\reader 10.0\leesmij.htm".
|
|
-
Modifies "c:\program files\adobe\reader 10.0\leggimi.htm".
|
|
-
Modifies "c:\program files\adobe\reader 10.0\leiame.htm".
|
|
-
Modifies "c:\program files\adobe\reader 10.0\liesmich.htm".
|
|
-
Modifies "c:\program files\adobe\reader 10.0\lisezmoi.htm".
|
|
-
Modifies "c:\program files\adobe\reader 10.0\llegiu-me.htm".
|
|
-
Modifies "c:\program files\adobe\reader 10.0\lueminut.htm".
|
|
-
Modifies "c:\program files\adobe\reader 10.0\reader\a3dutils.dll".
|
|
-
Modifies "c:\program files\adobe\reader 10.0\reader\ace.dll".
|
|
-
Modifies "c:\program files\adobe\reader 10.0\reader\acrobroker.exe".
|
|
-
Modifies "c:\program files\adobe\reader 10.0\reader\acrofx32.dll".
|
|
-
Modifies "c:\program files\adobe\reader 10.0\reader\acrord32.dll".
|
|
-
Modifies "c:\program files\adobe\reader 10.0\reader\acrord32.exe".
|
|
-
Modifies "c:\program files\adobe\reader 10.0\reader\acrord32info.exe".
|
|
-
Modifies "c:\program files\adobe\reader 10.0\reader\acrotextextractor.exe".
|
|
-
Modifies "c:\program files\adobe\reader 10.0\reader\adobe.reader.dependencies.manifest".
|
|
-
Modifies "c:\program files\adobe\reader 10.0\reader\adobecollabsync.exe".
|
|
-
Modifies "c:\program files\adobe\reader 10.0\reader\adobelinguistic.dll".
|
|
-
Modifies "c:\program files\adobe\reader 10.0\reader\adoberfp.dll".
|
|
-
Modifies "c:\program files\adobe\reader 10.0\reader\adobexmp.dll".
|
|
-
Modifies "c:\program files\adobe\reader 10.0\reader\agm.dll".
|
|
-
Modifies "c:\program files\adobe\reader 10.0\reader\agmgpuoptin.ini".
|
|
-
Modifies "c:\program files\adobe\reader 10.0\reader\ahclient.dll".
|
|
-
Modifies "c:\program files\adobe\reader 10.0\reader\air\nppdf32.cat".
|
|
-
Modifies "c:\program files\adobe\reader 10.0\reader\air\nppdf32.chs".
|
|
-
Modifies "c:\program files\adobe\reader 10.0\reader\air\nppdf32.cht".
|
|
-
Modifies "c:\program files\adobe\reader 10.0\reader\air\nppdf32.cze".
|
|
-
Modifies "c:\program files\adobe\reader 10.0\reader\air\nppdf32.dan".
|
|
-
Modifies "c:\program files\adobe\reader 10.0\reader\air\nppdf32.deu".
|
|
-
Modifies "c:\program files\adobe\reader 10.0\reader\air\nppdf32.dll".
|
|
-
Modifies "c:\program files\adobe\reader 10.0\reader\air\nppdf32.esp".
|
|
-
Modifies "c:\program files\adobe\reader 10.0\reader\air\nppdf32.euq".
|
|
-
Modifies "c:\program files\adobe\reader 10.0\reader\air\nppdf32.fra".
|
|
-
Modifies "c:\program files\adobe\reader 10.0\reader\air\nppdf32.hrv".
|
|
-
Modifies "c:\program files\adobe\reader 10.0\reader\air\nppdf32.hun".
|
|
-
Modifies "c:\program files\adobe\reader 10.0\reader\air\nppdf32.ita".
|
|
-
Modifies "c:\program files\adobe\reader 10.0\reader\air\nppdf32.jpn".
|
|
-
Modifies "c:\program files\adobe\reader 10.0\reader\air\nppdf32.kor".
|
|
-
Modifies "c:\program files\adobe\reader 10.0\reader\air\nppdf32.nld".
|
|
-
Modifies "c:\program files\adobe\reader 10.0\reader\air\nppdf32.nor".
|
|
-
Modifies "c:\program files\adobe\reader 10.0\reader\air\nppdf32.pol".
|
|
-
Modifies "c:\program files\adobe\reader 10.0\reader\air\nppdf32.ptb".
|
|
-
Modifies "c:\program files\adobe\reader 10.0\reader\air\nppdf32.rum".
|
|
-
Modifies "c:\program files\adobe\reader 10.0\reader\air\nppdf32.rus".
|
|
-
Modifies "c:\program files\adobe\reader 10.0\reader\air\nppdf32.sky".
|
|
-
Modifies "c:\program files\adobe\reader 10.0\reader\air\nppdf32.slv".
|
|
-
Modifies "c:\program files\adobe\reader 10.0\reader\air\nppdf32.suo".
|
|
-
Modifies "c:\program files\adobe\reader 10.0\reader\air\nppdf32.sve".
|
|
-
Modifies "c:\program files\adobe\reader 10.0\reader\air\nppdf32.tur".
|
|
-
Modifies "c:\program files\adobe\reader 10.0\reader\air\nppdf32.ukr".
|
|
-
Modifies "c:\program files\adobe\reader 10.0\reader\authplay.dll".
|
|
-
Modifies "c:\program files\adobe\reader 10.0\reader\axe8sharedexpat.dll".
|
|
-
Modifies "c:\program files\adobe\reader 10.0\reader\axsle.dll".
|
|
-
Modifies "c:\program files\adobe\reader 10.0\reader\bib.dll".
|
|
-
Modifies "c:\program files\adobe\reader 10.0\reader\bibutils.dll".
|
|
-
Modifies "c:\program files\adobe\reader 10.0\reader\browser\nppdf32.cat".
|
|
-
Modifies "c:\program files\adobe\reader 10.0\reader\browser\nppdf32.chs".
|
|
-
Modifies "c:\program files\adobe\reader 10.0\reader\browser\nppdf32.cht".
|
|
-
Modifies "c:\program files\adobe\reader 10.0\reader\browser\nppdf32.cze".
|
|
-
Modifies "c:\program files\adobe\reader 10.0\reader\browser\nppdf32.dan".
|
|
-
Modifies "c:\program files\adobe\reader 10.0\reader\browser\nppdf32.deu".
|
|
-
Modifies "c:\program files\adobe\reader 10.0\reader\browser\nppdf32.dll".
|
|
-
Modifies "c:\program files\adobe\reader 10.0\reader\browser\nppdf32.esp".
|
|
-
Modifies "c:\program files\adobe\reader 10.0\reader\browser\nppdf32.euq".
|
|
-
Modifies "c:\program files\adobe\reader 10.0\reader\browser\nppdf32.fra".
|
|
-
Modifies "c:\program files\adobe\reader 10.0\reader\browser\nppdf32.hrv".
|
|
-
Modifies "c:\program files\adobe\reader 10.0\reader\browser\nppdf32.hun".
|
|
-
Modifies "c:\program files\adobe\reader 10.0\reader\browser\nppdf32.ita".
|
|
-
Modifies "c:\program files\adobe\reader 10.0\reader\browser\nppdf32.jpn".
|
|
-
Modifies "c:\program files\adobe\reader 10.0\reader\browser\nppdf32.kor".
|
|
-
Modifies "c:\program files\adobe\reader 10.0\reader\browser\nppdf32.nld".
|
|
-
Modifies "c:\program files\adobe\reader 10.0\reader\browser\nppdf32.nor".
|
|
-
Modifies "c:\program files\adobe\reader 10.0\reader\browser\nppdf32.pol".
|
|
-
Modifies "c:\program files\adobe\reader 10.0\reader\browser\nppdf32.ptb".
|
|
-
Modifies "c:\program files\adobe\reader 10.0\reader\browser\nppdf32.rum".
|
|
-
Modifies "c:\program files\adobe\reader 10.0\reader\browser\nppdf32.rus".
|
|
-
Modifies "c:\program files\adobe\reader 10.0\reader\browser\nppdf32.sky".
|
|
-
Modifies "c:\program files\adobe\reader 10.0\reader\browser\nppdf32.slv".
|
|
-
Modifies "c:\program files\adobe\reader 10.0\reader\browser\nppdf32.suo".
|
|
-
Modifies "c:\program files\adobe\reader 10.0\reader\browser\nppdf32.sve".
|
|
-
Modifies "c:\program files\adobe\reader 10.0\reader\browser\nppdf32.tur".
|
|
-
Modifies "c:\program files\adobe\reader 10.0\reader\browser\nppdf32.ukr".
|
|
-
Modifies "c:\program files\adobe\reader 10.0\reader\ccme_base.dll".
|
|
-
Modifies "c:\program files\adobe\reader 10.0\reader\cooltype.dll".
|
|
-
Modifies "c:\program files\adobe\reader 10.0\reader\cryptocme2.dll".
|
|
-
Modifies "c:\program files\adobe\reader 10.0\reader\cryptocme2.sig".
|
|
-
Modifies "c:\program files\adobe\reader 10.0\reader\eula.exe".
|
|
-
Modifies "c:\program files\adobe\reader 10.0\reader\extendscript.dll".
|
|
-
Modifies "c:\program files\adobe\reader 10.0\reader\icucnv40.dll".
|
|
-
Modifies "c:\program files\adobe\reader 10.0\reader\icudt40.dll".
|
|
-
Modifies "c:\program files\adobe\reader 10.0\reader\icudt40_full.dll".
|
|
-
Modifies "c:\program files\adobe\reader 10.0\reader\icuuc40.dll".
|
|
-
Modifies "c:\program files\adobe\reader 10.0\reader\idtemplates\cat\adobeid.pdf".
|
|
-
Modifies "c:\program files\adobe\reader 10.0\reader\idtemplates\cat\defaultid.pdf".
|
|
-
Modifies "c:\program files\adobe\reader 10.0\reader\idtemplates\chs\adobeid.pdf".
|
|
-
Modifies "c:\program files\adobe\reader 10.0\reader\idtemplates\chs\defaultid.pdf".
|
|
-
Modifies "c:\program files\adobe\reader 10.0\reader\idtemplates\cht\adobeid.pdf".
|
|
-
Modifies "c:\program files\adobe\reader 10.0\reader\idtemplates\cht\defaultid.pdf".
|
|
-
Modifies "c:\program files\adobe\reader 10.0\reader\idtemplates\cze\adobeid.pdf".
|
|
-
Modifies "c:\program files\adobe\reader 10.0\reader\idtemplates\cze\defaultid.pdf".
|
|
-
Modifies "c:\program files\adobe\reader 10.0\reader\idtemplates\dan\adobeid.pdf".
|
|
-
Modifies "c:\program files\adobe\reader 10.0\reader\idtemplates\dan\defaultid.pdf".
|
|
-
Modifies "c:\program files\adobe\reader 10.0\reader\idtemplates\deu\adobeid.pdf".
|
|
-
Modifies "c:\program files\adobe\reader 10.0\reader\idtemplates\deu\defaultid.pdf".
|
|
-
Modifies "c:\program files\adobe\reader 10.0\reader\idtemplates\enu\adobeid.pdf".
|
|
-
Modifies "c:\program files\adobe\reader 10.0\reader\idtemplates\enu\defaultid.pdf".
|
|
-
Modifies "c:\program files\adobe\reader 10.0\reader\idtemplates\esp\adobeid.pdf".
|
|
-
Modifies "c:\program files\adobe\reader 10.0\reader\idtemplates\esp\defaultid.pdf".
|
|
-
Modifies "c:\program files\adobe\reader 10.0\reader\idtemplates\fra\adobeid.pdf".
|
|
-
Modifies "c:\program files\adobe\reader 10.0\reader\idtemplates\fra\defaultid.pdf".
|
|
-
Modifies "c:\program files\adobe\reader 10.0\reader\idtemplates\hrv\adobeid.pdf".
|
|
-
Modifies "c:\program files\adobe\reader 10.0\reader\idtemplates\hrv\defaultid.pdf".
|
|
-
Modifies "c:\program files\adobe\reader 10.0\reader\idtemplates\hun\adobeid.pdf".
|
|
-
Modifies "c:\program files\adobe\reader 10.0\reader\idtemplates\hun\defaultid.pdf".
|
|
-
Modifies "c:\program files\adobe\reader 10.0\reader\idtemplates\ita\adobeid.pdf".
|
|
-
Modifies "c:\program files\adobe\reader 10.0\reader\idtemplates\ita\defaultid.pdf".
|
|
-
Modifies "c:\program files\adobe\reader 10.0\reader\idtemplates\jpn\adobeid.pdf".
|
|
-
Modifies "c:\program files\adobe\reader 10.0\reader\idtemplates\jpn\defaultid.pdf".
|
|
-
Modifies "c:\program files\adobe\reader 10.0\reader\idtemplates\kor\adobeid.pdf".
|
|
-
Modifies "c:\program files\adobe\reader 10.0\reader\idtemplates\kor\defaultid.pdf".
|
|
-
Modifies "c:\program files\adobe\reader 10.0\reader\idtemplates\nld\adobeid.pdf".
|
|
-
Modifies "c:\program files\adobe\reader 10.0\reader\idtemplates\nld\defaultid.pdf".
|
|
-
Modifies "c:\program files\adobe\reader 10.0\reader\idtemplates\nor\adobeid.pdf".
|
|
-
Modifies "c:\program files\adobe\reader 10.0\reader\idtemplates\nor\defaultid.pdf".
|
|
-
Modifies "c:\program files\adobe\reader 10.0\reader\idtemplates\pol\adobeid.pdf".
|
|
-
Modifies "c:\program files\adobe\reader 10.0\reader\idtemplates\pol\defaultid.pdf".
|
|
-
Modifies "c:\program files\adobe\reader 10.0\reader\idtemplates\ptb\adobeid.pdf".
|
|
-
Modifies "c:\program files\adobe\reader 10.0\reader\idtemplates\ptb\defaultid.pdf".
|
|
-
Modifies "c:\program files\adobe\reader 10.0\reader\idtemplates\rum\adobeid.pdf".
|
|
-
Modifies "c:\program files\adobe\reader 10.0\reader\idtemplates\rum\defaultid.pdf".
|
|
-
Modifies "c:\program files\adobe\reader 10.0\reader\idtemplates\rus\adobeid.pdf".
|
|
-
Modifies "c:\program files\adobe\reader 10.0\reader\idtemplates\rus\defaultid.pdf".
|
|
-
Modifies "c:\program files\adobe\reader 10.0\reader\idtemplates\sky\adobeid.pdf".
|
|
-
Modifies "c:\program files\adobe\reader 10.0\reader\idtemplates\sky\defaultid.pdf".
|
|
-
Modifies "c:\program files\adobe\reader 10.0\reader\idtemplates\slv\adobeid.pdf".
|
|
-
Modifies "c:\program files\adobe\reader 10.0\reader\idtemplates\slv\defaultid.pdf".
|