d214b4ec...a8a9 | Files
Try VMRay Analyzer
VTI SCORE: 100/100
Dynamic Analysis Report
Classification: Wiper, Ransomware

Remarks

(0x200001d): The maximum number of extracted files was exceeded. Some files may be missing in the report.

(0x200001b): The maximum number of file reputation requests per analysis (150) was exceeded.

Filters:
Filename Category Type Severity Actions
C:\Users\FD1HVy\Desktop\d2.exe Sample File Binary
Malicious
»
Mime Type application/vnd.microsoft.portable-executable
File Size 251.50 KB
MD5 fa79eba9e8e91da8cdcbe1b9989c34f5 Copy to Clipboard
SHA1 8189659e0363690fb3ac1b1c738f6d7b2003e6d2 Copy to Clipboard
SHA256 d214b4eca051a26924c3d26057ed14eaf9dd5cbb257a2eb9ce7045b7ca7ba8a9 Copy to Clipboard
SSDeep 3072:QMa7uD9LZBPAyLJihkNcroGzkCUtyERKuiB7cTFicppM5UngKOH57w5KwUVb:QMa70LMycRkGzkX7SITTU5dKOBXJV Copy to Clipboard
ImpHash f74596653f1fc2037cc9b6c04dbc0a8b Copy to Clipboard
PE Information
»
Image Base 0x400000
Entry Point 0x4043b9
Size Of Code 0x2fc00
Size Of Initialized Data 0x11000
File Type FileType.executable
Subsystem Subsystem.windows_gui
Machine Type MachineType.i386
Compile Timestamp 2018-10-27 09:07:26+00:00
Sections (8)
»
Name Virtual Address Virtual Size Raw Data Size Raw Data Offset Flags Entropy
.text 0x401000 0x2fa1f 0x2fc00 0x400 IMAGE_SCN_CNT_CODE, IMAGE_SCN_MEM_EXECUTE, IMAGE_SCN_MEM_READ 7.44
.rdata 0x431000 0x49c9 0x4a00 0x30000 IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_READ 5.38
.data 0x436000 0x3254 0x1200 0x34a00 IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_READ, IMAGE_SCN_MEM_WRITE 2.55
.nahoj 0x43a000 0x400 0x400 0x35c00 IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_READ, IMAGE_SCN_MEM_WRITE 0.0
.foyo 0x43b000 0x400 0x400 0x36000 IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_READ, IMAGE_SCN_MEM_WRITE 0.0
.caraw 0x43c000 0x1400 0x600 0x36400 IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_READ, IMAGE_SCN_MEM_WRITE 0.0
.rsrc 0x43e000 0x69c0 0x6a00 0x36a00 IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_READ 5.7
.reloc 0x445000 0x19d8 0x1a00 0x3d400 IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_DISCARDABLE, IMAGE_SCN_MEM_READ 6.45
Imports (2)
»
KERNEL32.dll (144)
»
API Name Ordinal IAT Address Thunk RVA Thunk Offset Hint
GetConsoleCP 0x0 0x431050 0x34ae0 0x33ae0 0x183
GlobalAlloc 0x0 0x431054 0x34ae4 0x33ae4 0x285
GetLocaleInfoW 0x0 0x431058 0x34ae8 0x33ae8 0x1ea
GetPrivateProfileStructW 0x0 0x43105c 0x34aec 0x33aec 0x21f
GetSystemTimeAdjustment 0x0 0x431060 0x34af0 0x33af0 0x24e
IsProcessorFeaturePresent 0x0 0x431064 0x34af4 0x33af4 0x2d5
SetTimeZoneInformation 0x0 0x431068 0x34af8 0x33af8 0x413
GetBinaryTypeA 0x0 0x43106c 0x34afc 0x33afc 0x158
IsBadWritePtr 0x0 0x431070 0x34b00 0x33b00 0x2cb
GetMailslotInfo 0x0 0x431074 0x34b04 0x33b04 0x1f3
GetOverlappedResult 0x0 0x431078 0x34b08 0x33b08 0x214
ExitThread 0x0 0x43107c 0x34b0c 0x33b0c 0x105
lstrlenW 0x0 0x431080 0x34b10 0x33b10 0x4b6
SetConsoleTitleA 0x0 0x431084 0x34b14 0x33b14 0x3c1
VirtualUnlock 0x0 0x431088 0x34b18 0x33b18 0x45e
GetConsoleOutputCP 0x0 0x43108c 0x34b1c 0x33b1c 0x199
SetThreadLocale 0x0 0x431090 0x34b20 0x33b20 0x409
GetCPInfoExW 0x0 0x431094 0x34b24 0x33b24 0x15d
FreeLibraryAndExitThread 0x0 0x431098 0x34b28 0x33b28 0x14d
SetLastError 0x0 0x43109c 0x34b2c 0x33b2c 0x3ec
GetComputerNameExW 0x0 0x4310a0 0x34b30 0x33b30 0x177
GlobalFree 0x0 0x4310a4 0x34b34 0x33b34 0x28c
GetProcessVersion 0x0 0x4310a8 0x34b38 0x33b38 0x22b
GetVolumePathNameW 0x0 0x4310ac 0x34b3c 0x33b3c 0x27d
LocalAlloc 0x0 0x4310b0 0x34b40 0x33b40 0x2f9
DeleteTimerQueue 0x0 0x4310b4 0x34b44 0x33b44 0xc5
GlobalMemoryStatusEx 0x0 0x4310b8 0x34b48 0x33b48 0x292
GetProfileStringA 0x0 0x4310bc 0x34b4c 0x33b4c 0x233
GetCommMask 0x0 0x4310c0 0x34b50 0x33b50 0x16a
OpenJobObjectW 0x0 0x4310c4 0x34b54 0x33b54 0x32e
FindFirstVolumeMountPointA 0x0 0x4310c8 0x34b58 0x33b58 0x128
lstrcatW 0x0 0x4310cc 0x34b5c 0x33b5c 0x4a7
FatalExit 0x0 0x4310d0 0x34b60 0x33b60 0x10d
EnumResourceNamesA 0x0 0x4310d4 0x34b64 0x33b64 0xea
GetPrivateProfileSectionA 0x0 0x4310d8 0x34b68 0x33b68 0x218
CreateMailslotA 0x0 0x4310dc 0x34b6c 0x33b6c 0x88
BuildCommDCBA 0x0 0x4310e0 0x34b70 0x33b70 0x2b
VirtualProtect 0x0 0x4310e4 0x34b74 0x33b74 0x45a
CompareStringA 0x0 0x4310e8 0x34b78 0x33b78 0x52
OutputDebugStringA 0x0 0x4310ec 0x34b7c 0x33b7c 0x33a
_lopen 0x0 0x4310f0 0x34b80 0x33b80 0x4a2
GetDiskFreeSpaceExW 0x0 0x4310f4 0x34b84 0x33b84 0x1b6
ReadConsoleInputW 0x0 0x4310f8 0x34b88 0x33b88 0x360
TerminateJobObject 0x0 0x4310fc 0x34b8c 0x33b8c 0x42c
EnumResourceLanguagesW 0x0 0x431100 0x34b90 0x33b90 0xe9
FindNextVolumeA 0x0 0x431104 0x34b94 0x33b94 0x132
EnumResourceTypesA 0x0 0x431108 0x34b98 0x33b98 0xee
GetWindowsDirectoryA 0x0 0x43110c 0x34b9c 0x33b9c 0x280
FormatMessageA 0x0 0x431110 0x34ba0 0x33ba0 0x147
SetTapeParameters 0x0 0x431114 0x34ba4 0x33ba4 0x402
BackupSeek 0x0 0x431118 0x34ba8 0x33ba8 0x17
CallNamedPipeW 0x0 0x43111c 0x34bac 0x33bac 0x30
SetDefaultCommConfigW 0x0 0x431120 0x34bb0 0x33bb0 0x3c9
GlobalSize 0x0 0x431124 0x34bb4 0x33bb4 0x294
SetConsoleActiveScreenBuffer 0x0 0x431128 0x34bb8 0x33bb8 0x3a5
GetCommState 0x0 0x43112c 0x34bbc 0x33bbc 0x16d
MoveFileExW 0x0 0x431130 0x34bc0 0x33bc0 0x313
DeleteVolumeMountPointA 0x0 0x431134 0x34bc4 0x33bc4 0xc8
WriteConsoleOutputCharacterA 0x0 0x431138 0x34bc8 0x33bc8 0x489
GetConsoleAliasesLengthW 0x0 0x43113c 0x34bcc 0x33bcc 0x181
GetNativeSystemInfo 0x0 0x431140 0x34bd0 0x33bd0 0x206
UnregisterWait 0x0 0x431144 0x34bd4 0x33bd4 0x445
FindFirstFileW 0x0 0x431148 0x34bd8 0x33bd8 0x124
RemoveVectoredExceptionHandler 0x0 0x43114c 0x34bdc 0x33bdc 0x384
HeapReAlloc 0x0 0x431150 0x34be0 0x33be0 0x2a4
GetDiskFreeSpaceW 0x0 0x431154 0x34be4 0x33be4 0x1b7
TerminateProcess 0x0 0x431158 0x34be8 0x33be8 0x42d
GetCurrentProcess 0x0 0x43115c 0x34bec 0x33bec 0x1a9
UnhandledExceptionFilter 0x0 0x431160 0x34bf0 0x33bf0 0x43e
SetUnhandledExceptionFilter 0x0 0x431164 0x34bf4 0x33bf4 0x415
IsDebuggerPresent 0x0 0x431168 0x34bf8 0x33bf8 0x2d1
MultiByteToWideChar 0x0 0x43116c 0x34bfc 0x33bfc 0x31a
GetStartupInfoW 0x0 0x431170 0x34c00 0x33c00 0x23a
RaiseException 0x0 0x431174 0x34c04 0x33c04 0x35a
RtlUnwind 0x0 0x431178 0x34c08 0x33c08 0x392
HeapAlloc 0x0 0x43117c 0x34c0c 0x33c0c 0x29d
GetLastError 0x0 0x431180 0x34c10 0x33c10 0x1e6
HeapFree 0x0 0x431184 0x34c14 0x33c14 0x2a1
GetModuleHandleW 0x0 0x431188 0x34c18 0x33c18 0x1f9
GetProcAddress 0x0 0x43118c 0x34c1c 0x33c1c 0x220
TlsGetValue 0x0 0x431190 0x34c20 0x33c20 0x434
TlsAlloc 0x0 0x431194 0x34c24 0x33c24 0x432
TlsSetValue 0x0 0x431198 0x34c28 0x33c28 0x435
TlsFree 0x0 0x43119c 0x34c2c 0x33c2c 0x433
InterlockedIncrement 0x0 0x4311a0 0x34c30 0x33c30 0x2c0
GetCurrentThreadId 0x0 0x4311a4 0x34c34 0x33c34 0x1ad
InterlockedDecrement 0x0 0x4311a8 0x34c38 0x33c38 0x2bc
GetCurrentThread 0x0 0x4311ac 0x34c3c 0x33c3c 0x1ac
GetCPInfo 0x0 0x4311b0 0x34c40 0x33c40 0x15b
GetACP 0x0 0x4311b4 0x34c44 0x33c44 0x152
GetOEMCP 0x0 0x4311b8 0x34c48 0x33c48 0x213
IsValidCodePage 0x0 0x4311bc 0x34c4c 0x33c4c 0x2db
CloseHandle 0x0 0x4311c0 0x34c50 0x33c50 0x43
EnterCriticalSection 0x0 0x4311c4 0x34c54 0x33c54 0xd9
LeaveCriticalSection 0x0 0x4311c8 0x34c58 0x33c58 0x2ef
Sleep 0x0 0x4311cc 0x34c5c 0x33c5c 0x421
ExitProcess 0x0 0x4311d0 0x34c60 0x33c60 0x104
WriteFile 0x0 0x4311d4 0x34c64 0x33c64 0x48d
GetStdHandle 0x0 0x4311d8 0x34c68 0x33c68 0x23b
GetModuleFileNameA 0x0 0x4311dc 0x34c6c 0x33c6c 0x1f4
GetModuleFileNameW 0x0 0x4311e0 0x34c70 0x33c70 0x1f5
FreeEnvironmentStringsW 0x0 0x4311e4 0x34c74 0x33c74 0x14b
GetEnvironmentStringsW 0x0 0x4311e8 0x34c78 0x33c78 0x1c1
GetCommandLineW 0x0 0x4311ec 0x34c7c 0x33c7c 0x170
SetHandleCount 0x0 0x4311f0 0x34c80 0x33c80 0x3e8
GetFileType 0x0 0x4311f4 0x34c84 0x33c84 0x1d7
GetStartupInfoA 0x0 0x4311f8 0x34c88 0x33c88 0x239
DeleteCriticalSection 0x0 0x4311fc 0x34c8c 0x33c8c 0xbe
HeapCreate 0x0 0x431200 0x34c90 0x33c90 0x29f
HeapDestroy 0x0 0x431204 0x34c94 0x33c94 0x2a0
VirtualFree 0x0 0x431208 0x34c98 0x33c98 0x457
QueryPerformanceCounter 0x0 0x43120c 0x34c9c 0x33c9c 0x354
GetTickCount 0x0 0x431210 0x34ca0 0x33ca0 0x266
GetCurrentProcessId 0x0 0x431214 0x34ca4 0x33ca4 0x1aa
GetSystemTimeAsFileTime 0x0 0x431218 0x34ca8 0x33ca8 0x24f
FatalAppExitA 0x0 0x43121c 0x34cac 0x33cac 0x10b
VirtualAlloc 0x0 0x431220 0x34cb0 0x33cb0 0x454
LCMapStringA 0x0 0x431224 0x34cb4 0x33cb4 0x2e1
WideCharToMultiByte 0x0 0x431228 0x34cb8 0x33cb8 0x47a
LCMapStringW 0x0 0x43122c 0x34cbc 0x33cbc 0x2e3
GetStringTypeA 0x0 0x431230 0x34cc0 0x33cc0 0x23d
GetStringTypeW 0x0 0x431234 0x34cc4 0x33cc4 0x240
GetTimeFormatA 0x0 0x431238 0x34cc8 0x33cc8 0x268
GetDateFormatA 0x0 0x43123c 0x34ccc 0x33ccc 0x1ae
GetUserDefaultLCID 0x0 0x431240 0x34cd0 0x33cd0 0x26d
GetLocaleInfoA 0x0 0x431244 0x34cd4 0x33cd4 0x1e8
EnumSystemLocalesA 0x0 0x431248 0x34cd8 0x33cd8 0xf8
IsValidLocale 0x0 0x43124c 0x34cdc 0x33cdc 0x2dd
SetStdHandle 0x0 0x431250 0x34ce0 0x33ce0 0x3fc
GetConsoleMode 0x0 0x431254 0x34ce4 0x33ce4 0x195
FlushFileBuffers 0x0 0x431258 0x34ce8 0x33ce8 0x141
HeapSize 0x0 0x43125c 0x34cec 0x33cec 0x2a6
SetConsoleCtrlHandler 0x0 0x431260 0x34cf0 0x33cf0 0x3a7
FreeLibrary 0x0 0x431264 0x34cf4 0x33cf4 0x14c
InterlockedExchange 0x0 0x431268 0x34cf8 0x33cf8 0x2bd
LoadLibraryA 0x0 0x43126c 0x34cfc 0x33cfc 0x2f1
InitializeCriticalSectionAndSpinCount 0x0 0x431270 0x34d00 0x33d00 0x2b5
GetTimeZoneInformation 0x0 0x431274 0x34d04 0x33d04 0x26b
WriteConsoleA 0x0 0x431278 0x34d08 0x33d08 0x482
WriteConsoleW 0x0 0x43127c 0x34d0c 0x33d0c 0x48c
SetFilePointer 0x0 0x431280 0x34d10 0x33d10 0x3df
CreateFileA 0x0 0x431284 0x34d14 0x33d14 0x78
CompareStringW 0x0 0x431288 0x34d18 0x33d18 0x55
SetEnvironmentVariableA 0x0 0x43128c 0x34d1c 0x33d1c 0x3d0
ADVAPI32.dll (19)
»
API Name Ordinal IAT Address Thunk RVA Thunk Offset Hint
RegQueryValueA 0x0 0x431000 0x34a90 0x33a90 0x266
AdjustTokenPrivileges 0x0 0x431004 0x34a94 0x33a94 0x1e
ControlService 0x0 0x431008 0x34a98 0x33a98 0x58
InitializeSid 0x0 0x43100c 0x34a9c 0x33a9c 0x172
RegDeleteValueA 0x0 0x431010 0x34aa0 0x33aa0 0x241
SetKernelObjectSecurity 0x0 0x431014 0x34aa4 0x33aa4 0x2a7
RegQueryInfoKeyA 0x0 0x431018 0x34aa8 0x33aa8 0x261
RegOpenKeyExA 0x0 0x43101c 0x34aac 0x33aac 0x25a
RegEnumKeyExA 0x0 0x431020 0x34ab0 0x33ab0 0x248
AreAllAccessesGranted 0x0 0x431024 0x34ab4 0x33ab4 0x21
RegSetValueExA 0x0 0x431028 0x34ab8 0x33ab8 0x277
GetTokenInformation 0x0 0x43102c 0x34abc 0x33abc 0x154
LogonUserW 0x0 0x431030 0x34ac0 0x33ac0 0x187
OpenThreadToken 0x0 0x431034 0x34ac4 0x33ac4 0x1f6
DeleteService 0x0 0x431038 0x34ac8 0x33ac8 0xd6
ObjectOpenAuditAlarmA 0x0 0x43103c 0x34acc 0x33acc 0x1e7
GetSidSubAuthority 0x0 0x431040 0x34ad0 0x33ad0 0x151
LookupPrivilegeNameW 0x0 0x431044 0x34ad4 0x33ad4 0x18f
OpenServiceA 0x0 0x431048 0x34ad8 0x33ad8 0x1f4
Exports (1)
»
Api name EAT Address Ordinal
_MyFunc124@4 0x12e0 0x1
Icons (1)
»
Memory Dumps (13)
»
Name Process ID Start VA End VA Dump Reason PE Rebuild Bitness Entry Points AV YARA Actions
d2.exe 1 0x00400000 0x00446FFF Relevant Image - 32-bit - False False
buffer 1 0x00612510 0x0062606E Marked Executable - 32-bit 0x00613CF5 False False
buffer 1 0x00450000 0x00468FFF First Execution - 32-bit 0x00450000 False False
d2.exe 1 0x00400000 0x00446FFF Content Changed - 32-bit 0x0040A9D0 False False
d2.exe 1 0x00400000 0x00446FFF Content Changed - 32-bit 0x0040AA3D False False
d2.exe 1 0x00400000 0x00446FFF Content Changed - 32-bit 0x004082D0 False False
d2.exe 1 0x00400000 0x00446FFF Final Dump - 32-bit 0x00409AA0 False False
d2.exe 1 0x00400000 0x00446FFF Content Changed - 32-bit 0x00406850 False False
buffer 5 0x004D28A0 0x004E63FE Marked Executable - 32-bit 0x004D4085 False False
buffer 5 0x001C0000 0x001D8FFF First Execution - 32-bit 0x001C0000 False False
buffer 6 0x004826C8 0x00496226 Marked Executable - 32-bit 0x00483EAD False False
buffer 6 0x001E0000 0x001F8FFF First Execution - 32-bit 0x001E0000 False False
buffer 12 0x00520000 0x00538FFF First Execution - 32-bit 0x00520000 False False
Local AV Matches (1)
»
Threat Name Severity
Gen:Heur.Mint.Titirez.1.1B
Malicious
C:\$GetCurrent\SafeOS\GetCurrentOOBE.dll.id-B4197730.[admin@stex777.com].money Dropped File Stream
Malicious
»
Mime Type application/octet-stream
File Size 140.95 KB
MD5 99e3f4a2c55badfbc3913e8a9ee48e4c Copy to Clipboard
SHA1 32e55dc6e5d65141325dcb9f004b0ae83ebc16b1 Copy to Clipboard
SHA256 a7be80251aeede59fdef0e3c83b0c1f9d820b1d0d7b0c2f26bf10aa74ea3a9c2 Copy to Clipboard
SSDeep 3072:CDLgRUO7nfbCJV+E7V+wJhXbckpggjLdoWOxHZPzioD7:iY77TCJQEswbRpRdwPzio/ Copy to Clipboard
YARA Matches (1)
»
Rule Name Rule Description Classification Score Actions
DharmaEncryptedFile File encrypted by Dharma Ransomware Ransomware
5/5
C:\$GetCurrent\SafeOS\SetupComplete.cmd.id-B4197730.[admin@stex777.com].money Dropped File Stream
Malicious
»
Mime Type application/octet-stream
File Size 566 bytes
MD5 07f3465d09c56cfccd43bc9b5268f612 Copy to Clipboard
SHA1 1ca9afc4c8c3f73a39f4447d2ba90b441cf1084a Copy to Clipboard
SHA256 302221cf0e5e048fdb947a34f5cea2c6337dbab8d6b3b3e119fb76bfabe678ab Copy to Clipboard
SSDeep 12:t0+Opv24tOurnu7ZCn3IQPoOA8p8I1iFH8lfo11e/Xqs2EgeDcUIV37:2XXu7keFH8lQ11ZsPJIV37 Copy to Clipboard
YARA Matches (1)
»
Rule Name Rule Description Classification Score Actions
DharmaEncryptedFile File encrypted by Dharma Ransomware Ransomware
5/5
C:\588bce7c90097ed212\1028\eula.rtf.id-B4197730.[admin@stex777.com].money Dropped File Stream
Malicious
»
Mime Type application/octet-stream
File Size 6.39 KB
MD5 9257b549b8b3d8e2287608f0be5ccc3c Copy to Clipboard
SHA1 3fd02d029502afd62862809fd69ffc9ea0b4a610 Copy to Clipboard
SHA256 34a53f5f9c64d8eee21bf8fbc967e313fedb9332301077cc29a6e78e1d80f071 Copy to Clipboard
SSDeep 192:7+BKDmJi2L4Uy/aby2OppQGprbOwr4MygWfQh:2KDy09ibyR/jpfOWlCQh Copy to Clipboard
YARA Matches (1)
»
Rule Name Rule Description Classification Score Actions
DharmaEncryptedFile File encrypted by Dharma Ransomware Ransomware
5/5
C:\588bce7c90097ed212\1025\eula.rtf.id-B4197730.[admin@stex777.com].money Dropped File Stream
Malicious
»
Mime Type application/octet-stream
File Size 7.61 KB
MD5 c740cc8a696559dfc50661e6a383a221 Copy to Clipboard
SHA1 d714353b806f26350f39cc247a67fe26decb2de0 Copy to Clipboard
SHA256 15b57381609b6b43dc1ac56a7d861faf02df3f193576b5e1410caf326dd6cad6 Copy to Clipboard
SSDeep 192:dE58OEXH6BF7lKam6yHSEkkpzjUNDFR2mXhZOS4SHh:i58OPlbkSE4DDRx4SHh Copy to Clipboard
YARA Matches (1)
»
Rule Name Rule Description Classification Score Actions
DharmaEncryptedFile File encrypted by Dharma Ransomware Ransomware
5/5
C:\588bce7c90097ed212\1028\LocalizedData.xml.id-B4197730.[admin@stex777.com].money Dropped File Stream
Malicious
»
Mime Type application/octet-stream
File Size 59.65 KB
MD5 394ff45ad429961e539f8364499d8f61 Copy to Clipboard
SHA1 8241a9903d4a72a698a3adda9a72c09058f17a33 Copy to Clipboard
SHA256 d5119642b1826dd944436d6a16190f1e245face983512940646bc023cb8fe348 Copy to Clipboard
SSDeep 1536:yNGdS/evHF9LP8GsymQT7P/g1bk3eg7+wOb+RFin:yNGdRF9LPlJQxURnT6n Copy to Clipboard
YARA Matches (1)
»
Rule Name Rule Description Classification Score Actions
DharmaEncryptedFile File encrypted by Dharma Ransomware Ransomware
5/5
C:\588bce7c90097ed212\1029\eula.rtf.id-B4197730.[admin@stex777.com].money Dropped File Stream
Malicious
»
Mime Type application/octet-stream
File Size 3.86 KB
MD5 fd17ec65cbfe827f52b242084bf3d872 Copy to Clipboard
SHA1 28b573e76b8c11ab2152c8267ed32fff40eb33e7 Copy to Clipboard
SHA256 37377a23a806e3f10805bd6f13cdcb03f9c4069444fe776f8fbed4f6ac57805d Copy to Clipboard
SSDeep 96:SZbCrniQ1NUYp7jUMISlcRnGql1VUQu3sUFm9rVzWh:SZ+nP0O7jzWgqqHcU89rIh Copy to Clipboard
YARA Matches (1)
»
Rule Name Rule Description Classification Score Actions
DharmaEncryptedFile File encrypted by Dharma Ransomware Ransomware
5/5
C:\588bce7c90097ed212\1029\LocalizedData.xml.id-B4197730.[admin@stex777.com].money Dropped File Stream
Malicious
»
Mime Type application/octet-stream
File Size 79.32 KB
MD5 e1a0ead86e091e620f62ed01d57580c3 Copy to Clipboard
SHA1 775509546b36a3aa2f1bbe81a481509af7605bc8 Copy to Clipboard
SHA256 613750b635c1a82e6f8380654d43a550d03351ec54b3288d6d64cf4bdd173adc Copy to Clipboard
SSDeep 1536:vLYiIcnKFmwI4Fs39xkTfeS3qAZlvYSFSzBrG0IflorK+qsqcJv9rD1WtA5J1:vLYiIcn+IVNxkTfeSXzFqBpI+rmsq+Zx Copy to Clipboard
YARA Matches (1)
»
Rule Name Rule Description Classification Score Actions
DharmaEncryptedFile File encrypted by Dharma Ransomware Ransomware
5/5
C:\588bce7c90097ed212\1025\LocalizedData.xml.id-B4197730.[admin@stex777.com].money Dropped File Stream
Malicious
»
Mime Type application/octet-stream
File Size 72.72 KB
MD5 a300425064a6915313774d13d922e89e Copy to Clipboard
SHA1 8c2051ec04b1a24e6f0468f47183f9ababc23f5f Copy to Clipboard
SHA256 44431d8b98f9485a7dd606a8da81762c98223381824553a66712ff559ab525b8 Copy to Clipboard
SSDeep 1536:cmRzQ8Nn6Afgjxouh9onrK3C9h+ruMwgiFYdnogKs0Os+DDsWTMN:cYQZndouhOn+S9oruceYK3+DDs Copy to Clipboard
YARA Matches (1)
»
Rule Name Rule Description Classification Score Actions
DharmaEncryptedFile File encrypted by Dharma Ransomware Ransomware
5/5
C:\588bce7c90097ed212\1030\eula.rtf.id-B4197730.[admin@stex777.com].money Dropped File Stream
Malicious
»
Mime Type application/octet-stream
File Size 3.47 KB
MD5 8382e3655c49db6dc022d2a6f23852a3 Copy to Clipboard
SHA1 f419c086803e29cb00aa9e8801233142829995f0 Copy to Clipboard
SHA256 1e2c24cafc774e16cb140d12ce11e62c9bb96c0c160768516f8bc5fa3cabd025 Copy to Clipboard
SSDeep 96:iQzGsFC8uWV1yA/Tgyxs9ZVeBQqrBwwlwIQS5GgWh:Z6sFjV1H/1xs3eQqrB7iyGvh Copy to Clipboard
YARA Matches (1)
»
Rule Name Rule Description Classification Score Actions
DharmaEncryptedFile File encrypted by Dharma Ransomware Ransomware
5/5
C:\588bce7c90097ed212\1031\eula.rtf.id-B4197730.[admin@stex777.com].money Dropped File Stream
Malicious
»
Mime Type application/octet-stream
File Size 3.57 KB
MD5 e783452a80f158fb036482142593b1a9 Copy to Clipboard
SHA1 100e4d30db7e6b0a8f64d6f2bc0a14c656c61712 Copy to Clipboard
SHA256 8c51d7619203f55bf4896d9ae6cb21a928e8b7700657d8595b178cf59ade42f5 Copy to Clipboard
SSDeep 48:MnuB1j4tuV4mF1svks3Cp3UYwayvOFvFA6mzmv0fdfBAZsGMG0itlr/6WSU:M21X3FTs3CpkVfv6Iz55uZ50itlyWh Copy to Clipboard
YARA Matches (1)
»
Rule Name Rule Description Classification Score Actions
DharmaEncryptedFile File encrypted by Dharma Ransomware Ransomware
5/5
C:\588bce7c90097ed212\1031\LocalizedData.xml.id-B4197730.[admin@stex777.com].money Dropped File Binary
Malicious
»
Mime Type application/x-dosexec
File Size 80.66 KB
MD5 d798ea1163c10282448181aff5f88ace Copy to Clipboard
SHA1 5ff72356852cb379b50b73c28d72e9dcee6da2f4 Copy to Clipboard
SHA256 e13f1742ad212196f24fb5c4862f2294e562b82cef922ea2fb996fb9a633b0e5 Copy to Clipboard
SSDeep 1536:ln5X88jLigTrXD7C/849Vm6WGNe+Lhl08W9nhdLkstI:ln5XbTrz7C6GMY0ttPLkstI Copy to Clipboard
YARA Matches (1)
»
Rule Name Rule Description Classification Score Actions
DharmaEncryptedFile File encrypted by Dharma Ransomware Ransomware
5/5
C:\588bce7c90097ed212\1025\SetupResources.dll.id-B4197730.[admin@stex777.com].money Dropped File Stream
Malicious
»
Mime Type application/octet-stream
File Size 17.09 KB
MD5 289de3320596618494cd1f08434cfd83 Copy to Clipboard
SHA1 2d9bc3b8eca02ab6229ef5a2d512407af11c4342 Copy to Clipboard
SHA256 629cb82b0ead7c26b41488c3cda3afc1b8971798c1bdc5c7553863a7a470718a Copy to Clipboard
SSDeep 384:QQPG6KprjUQ/jnoEPvLLLAmEAH5qwSzp22iQ2KyTlnh:QQP3KJj3JPvL/QAHad2JQ1mT Copy to Clipboard
YARA Matches (1)
»
Rule Name Rule Description Classification Score Actions
DharmaEncryptedFile File encrypted by Dharma Ransomware Ransomware
5/5
C:\588bce7c90097ed212\1028\SetupResources.dll.id-B4197730.[admin@stex777.com].money Dropped File Stream
Malicious
»
Mime Type application/octet-stream
File Size 14.09 KB
MD5 cb6ab2ae18d07b99048d29309e4c0095 Copy to Clipboard
SHA1 45449e73227deebe123a11d1d7a7af1fbf3bd7d5 Copy to Clipboard
SHA256 b8270ff5041c453d217beb73796510a0e050efae411947c35835ce7ab7ff2277 Copy to Clipboard
SSDeep 384:uLaZ3Wv+UKp1ovVVAvQvvra7ZKa6/HD/3j4lBCtvfsBIE2EupJ179ERMhb0euZnv:u5zKLusvQvu7ZKa6/jviwtvfsH2EEJ1A Copy to Clipboard
YARA Matches (1)
»
Rule Name Rule Description Classification Score Actions
DharmaEncryptedFile File encrypted by Dharma Ransomware Ransomware
5/5
C:\588bce7c90097ed212\1032\eula.rtf.id-B4197730.[admin@stex777.com].money Dropped File Stream
Malicious
»
Mime Type application/octet-stream
File Size 8.89 KB
MD5 2d03dbb3d76bad11cb4a659bf2a88f13 Copy to Clipboard
SHA1 08af93047378199e9e0eb9963d89ceec275eadee Copy to Clipboard
SHA256 aabdc46f06680841487076860f81dce07b207e3ff5b0edc4ed00bddc20fed00d Copy to Clipboard
SSDeep 192:XcFoUtIQPP5S6demmXAktZ99jiug9y/780QNCDklJZ8/m8BAWrh:GtBH5S6YmmwktZnjiS/40QNCDklU+82O Copy to Clipboard
YARA Matches (1)
»
Rule Name Rule Description Classification Score Actions
DharmaEncryptedFile File encrypted by Dharma Ransomware Ransomware
5/5
C:\588bce7c90097ed212\1032\LocalizedData.xml.id-B4197730.[admin@stex777.com].money Dropped File Binary
Malicious
»
Mime Type application/x-dosexec
File Size 84.51 KB
MD5 493346254a3c6fca2bd5040cb2b5c5e4 Copy to Clipboard
SHA1 7d3af8f285758b5154d594385aeb96a6c920a5f0 Copy to Clipboard
SHA256 baa57cc5ae8aadb4df03f4d4ddbe3de9e25d9259608bf2ec61e60bfd3535c354 Copy to Clipboard
SSDeep 1536:J9z7bTu4yYj3jiPq1xDdPDgIuIlE14aXl612BPNzubObFohcujKjs/9hyH8uI1:z7bSATaq1xtDgIzmI42ObFohcumm9hyK Copy to Clipboard
YARA Matches (1)
»
Rule Name Rule Description Classification Score Actions
DharmaEncryptedFile File encrypted by Dharma Ransomware Ransomware
5/5
C:\588bce7c90097ed212\1033\eula.rtf.id-B4197730.[admin@stex777.com].money Dropped File Stream
Malicious
»
Mime Type application/octet-stream
File Size 3.35 KB
MD5 b89af68f8379527639f9290690266d9c Copy to Clipboard
SHA1 4b093e243b7a02db919faff1a936a7cff5653967 Copy to Clipboard
SHA256 c7ec908ff22c1bbcb54d67dc101ac9dde682eb8d0f14e6994f2396c003614ce4 Copy to Clipboard
SSDeep 96:CK6xda8ZSVyF6KRxGZmgg3wmPUHagbTOksEtQu/VnWh:CZaYXkUwmcHtXQu/VWh Copy to Clipboard
YARA Matches (1)
»
Rule Name Rule Description Classification Score Actions
DharmaEncryptedFile File encrypted by Dharma Ransomware Ransomware
5/5
C:\588bce7c90097ed212\1033\LocalizedData.xml.id-B4197730.[admin@stex777.com].money Dropped File Stream
Malicious
»
Mime Type application/octet-stream
File Size 75.68 KB
MD5 9c49f9949ad8c23c77eb1ff8e3e26aac Copy to Clipboard
SHA1 2f35d69af934fb729880d7215801988dfb0521ae Copy to Clipboard
SHA256 cdde3b973b323713948299e09d0571fc8c368256e0f57ffa4eecf0aa0fadc7b0 Copy to Clipboard
SSDeep 1536:sEz9R+dt54Dabx74ZDK91GgrzfahYDOzEpOdW2gkIn:s+QgEJ4hzgGYDjpO9I Copy to Clipboard
YARA Matches (1)
»
Rule Name Rule Description Classification Score Actions
DharmaEncryptedFile File encrypted by Dharma Ransomware Ransomware
5/5
C:\588bce7c90097ed212\1030\LocalizedData.xml.id-B4197730.[admin@stex777.com].money Dropped File Stream
Malicious
»
Mime Type application/octet-stream
File Size 76.18 KB
MD5 da4319867a87c3b52e95da54a79e91f7 Copy to Clipboard
SHA1 651bdeedfedc63cfd9e745ab21c8b75552b40b12 Copy to Clipboard
SHA256 d769f9302bd116a7f5568bde1d2cc12fe7d52cdb125c767cad23b9501968803d Copy to Clipboard
SSDeep 1536:c84s45zdBjbe03/h+aaX2PVeU0hwGa6VPlBLWTr+Wpn4SCCGw:c1sEpdS0vh+CeU0h1zbLW2GnxCLw Copy to Clipboard
YARA Matches (1)
»
Rule Name Rule Description Classification Score Actions
DharmaEncryptedFile File encrypted by Dharma Ransomware Ransomware
5/5
C:\588bce7c90097ed212\1029\SetupResources.dll.id-B4197730.[admin@stex777.com].money Dropped File Stream
Malicious
»
Mime Type application/octet-stream
File Size 18.09 KB
MD5 fb55af065950b0960c1ba64a25618c8a Copy to Clipboard
SHA1 fd7eef9b4b219911888b1092b3c8464715a7de1f Copy to Clipboard
SHA256 0e774b0efdcaeb6425341410adf2be53c2087808a909eec8f2e4205dbd6c9a93 Copy to Clipboard
SSDeep 384:OVcV80tFIkRyGl+czf0DIxFNMR5UXCwnElCtynB:Ec2WIk8G6IxFNMRWNElCty Copy to Clipboard
YARA Matches (1)
»
Rule Name Rule Description Classification Score Actions
DharmaEncryptedFile File encrypted by Dharma Ransomware Ransomware
5/5
C:\588bce7c90097ed212\1030\SetupResources.dll.id-B4197730.[admin@stex777.com].money Dropped File Stream
Malicious
»
Mime Type application/octet-stream
File Size 18.09 KB
MD5 2a24a0249b6b5a439c10ecc1da01b10d Copy to Clipboard
SHA1 54a416096ffdfb6a63864fc319128c6e8a0b0b46 Copy to Clipboard
SHA256 65565f5a955802ee309b02b0ab4614f3cea28a5fd7b2fa1fba2be0e0223cb7c0 Copy to Clipboard
SSDeep 384:cSsjPrDNAL7wQ5unsGuTezQKmUSPexOVjWlJ1qBGGn4:KpALss0L84SYqjWF Copy to Clipboard
YARA Matches (1)
»
Rule Name Rule Description Classification Score Actions
DharmaEncryptedFile File encrypted by Dharma Ransomware Ransomware
5/5
C:\588bce7c90097ed212\1031\SetupResources.dll.id-B4197730.[admin@stex777.com].money Dropped File Stream
Malicious
»
Mime Type application/octet-stream
File Size 18.59 KB
MD5 acb63473722d73ff0b5597541d230046 Copy to Clipboard
SHA1 c6707602a51523d4f67e46006b108c58d2f3d345 Copy to Clipboard
SHA256 4e74f596279634431aaf63c6e665708faea915dc11670a71d9382b49ceb779ba Copy to Clipboard
SSDeep 384:BzDEC4ts6Cu8nKKbKD9qmzDGlVVtRLCOApxAluaPaMxrxRaC8peAj0nx:2/hh8KB9qIi3V/WxxmueFKpeAjg Copy to Clipboard
YARA Matches (1)
»
Rule Name Rule Description Classification Score Actions
DharmaEncryptedFile File encrypted by Dharma Ransomware Ransomware
5/5
C:\588bce7c90097ed212\1032\SetupResources.dll.id-B4197730.[admin@stex777.com].money Dropped File Stream
Malicious
»
Mime Type application/octet-stream
File Size 19.09 KB
MD5 5d66b71cf3b905568d4904795a770c32 Copy to Clipboard
SHA1 40c169cebe52353bb106dc19b66b57a5e5fb1aca Copy to Clipboard
SHA256 e37f5a5f0f1fb8b839b887d2bf782a4814cf4c477f50150ead6b2990677ac4be Copy to Clipboard
SSDeep 384:ASvJaTj1f3ARfyZQFzYhHrioYy2ZfgefKpKxYItI/O18WNF+EDnm:Aqqf3SyZXhHnsmhKY+QOmW+X Copy to Clipboard
YARA Matches (1)
»
Rule Name Rule Description Classification Score Actions
DharmaEncryptedFile File encrypted by Dharma Ransomware Ransomware
5/5
C:\588bce7c90097ed212\1035\eula.rtf.id-B4197730.[admin@stex777.com].money Dropped File Stream
Malicious
»
Mime Type application/octet-stream
File Size 3.85 KB
MD5 755dbac497997115318bb9e4483e29d0 Copy to Clipboard
SHA1 406d2761a2840e415da5236a15230a42420c0d63 Copy to Clipboard
SHA256 2745b71bfb477145f3ae418218b1ce84ac6fb4239faabd690e6d7be52a4dc0e3 Copy to Clipboard
SSDeep 96:7MZ1nQEIQxociB7OczvG6XKP99CX4OdRjU4v0jv2kaHgh+Wh:7g1Q0xockic66U9Cpd0haAhNh Copy to Clipboard
YARA Matches (1)
»
Rule Name Rule Description Classification Score Actions
DharmaEncryptedFile File encrypted by Dharma Ransomware Ransomware
5/5
C:\588bce7c90097ed212\1035\LocalizedData.xml.id-B4197730.[admin@stex777.com].money Dropped File Stream
Malicious
»
Mime Type application/octet-stream
File Size 75.46 KB
MD5 ae9c91d1bc7994370a04b71214a76a9d Copy to Clipboard
SHA1 b5a2381139e1a58aabfc1d52f5f5d871d76ca820 Copy to Clipboard
SHA256 163f80bb57bc4ace589485561ee2ae2b800cfefacbc4dc6edc055afb9f9bfa23 Copy to Clipboard
SSDeep 1536:ODIjxDPx4quTS6GEQmiQGc7qCtzm4h3UcBL3bNeMzgWfF3oUlaGcAM:FtDPx4WWQoGTCNthEct3bAig2FzuAM Copy to Clipboard
YARA Matches (1)
»
Rule Name Rule Description Classification Score Actions
DharmaEncryptedFile File encrypted by Dharma Ransomware Ransomware
5/5
C:\588bce7c90097ed212\1036\eula.rtf.id-B4197730.[admin@stex777.com].money Dropped File Stream
Malicious
»
Mime Type application/octet-stream
File Size 3.68 KB
MD5 7d74553f6ce31c58389b4808eb8e1096 Copy to Clipboard
SHA1 468b09c55a94c0be1d06be4de3ceb2fedeea8dc8 Copy to Clipboard
SHA256 d2de4346873596c903155c302300a448455f026f010677ed47fcb0e37211f0f3 Copy to Clipboard
SSDeep 96:Qbfw6sWjpYNDspQ8KOx6kILxSKdLjhMrjWh:QbY6sWjpVpHK+6nLxS6Lcih Copy to Clipboard
YARA Matches (1)
»
Rule Name Rule Description Classification Score Actions
DharmaEncryptedFile File encrypted by Dharma Ransomware Ransomware
5/5
C:\588bce7c90097ed212\1033\SetupResources.dll.id-B4197730.[admin@stex777.com].money Dropped File Stream
Malicious
»
Mime Type application/octet-stream
File Size 17.09 KB
MD5 770d0b334f05eac58af75a21c0cf8db7 Copy to Clipboard
SHA1 258a8a85d9de34e05ef9efb65fb64ebad3a457e3 Copy to Clipboard
SHA256 9e023ad9b2877c05205c305b6c2c1bfe7f8aec73aafbf313e79469b8c57aff39 Copy to Clipboard
SSDeep 384:nzTiQHzK7pGl71a7L5UMZWIF0vXg0hNUOHd5Fy4TNn0:9zig71a7L2MZWYsXg6NXgQq Copy to Clipboard
YARA Matches (1)
»
Rule Name Rule Description Classification Score Actions
DharmaEncryptedFile File encrypted by Dharma Ransomware Ransomware
5/5
C:\588bce7c90097ed212\1035\SetupResources.dll.id-B4197730.[admin@stex777.com].money Dropped File Stream
Malicious
»
Mime Type application/octet-stream
File Size 18.09 KB
MD5 27983be2960d5360697c3624d625f8e7 Copy to Clipboard
SHA1 f2b6b3ad55c15f2297a32a98286bbf38aed94274 Copy to Clipboard
SHA256 0959493b08249c33b92082620e25c722c016a690da94ac6f41dcedf9157f7db9 Copy to Clipboard
SSDeep 384:95261ExMBvc81T1Xw0PjS77kTr2SPCOvGx9pil4r4zZXwrgLsVXoPA2wSn1:95/AMBzB1XwqLTjrG8y4lXXL+oPAI Copy to Clipboard
YARA Matches (1)
»
Rule Name Rule Description Classification Score Actions
DharmaEncryptedFile File encrypted by Dharma Ransomware Ransomware
5/5
C:\588bce7c90097ed212\1036\SetupResources.dll.id-B4197730.[admin@stex777.com].money Dropped File Stream
Malicious
»
Mime Type application/octet-stream
File Size 18.59 KB
MD5 2c0fe67c0587d2babb18aa77cd2d0da6 Copy to Clipboard
SHA1 cc043e1d08b7f7ed3b5e849fa0ab534d0ed6bec7 Copy to Clipboard
SHA256 02f7a3fb23e165cfb8b1fb3243f2334af2cc3c06e9304871bd28d86a3197f785 Copy to Clipboard
SSDeep 384:dq9AFk9Exj8E9LvzsVKjLVwovh+9spMHQGhRpgxQBtRIJYabHovWnY:dsAoEx1EKfVwovQ7HQNmfIJlbHo/ Copy to Clipboard
YARA Matches (1)
»
Rule Name Rule Description Classification Score Actions
DharmaEncryptedFile File encrypted by Dharma Ransomware Ransomware
5/5
C:\588bce7c90097ed212\1036\LocalizedData.xml.id-B4197730.[admin@stex777.com].money Dropped File Stream
Malicious
»
Mime Type application/octet-stream
File Size 81.27 KB
MD5 bd0a7fb2a97d1a1ce28a26c5394d47cc Copy to Clipboard
SHA1 5c92f1de3d82eac5116971766d5ed9ed9b98989a Copy to Clipboard
SHA256 8519d3b045155e287f1c47f0df0dc5dad52201ef625e520a3a9ab3c28dc0be5c Copy to Clipboard
SSDeep 1536:qd4Jyj0j70sBX5EokxJjFnwttuDEnI3Kzjb51OhTlQfxWGLxvEUPTCAI5PA:qd40j0jAsBX5EXtsb51wTipl1+A2PA Copy to Clipboard
YARA Matches (1)
»
Rule Name Rule Description Classification Score Actions
DharmaEncryptedFile File encrypted by Dharma Ransomware Ransomware
5/5
C:\588bce7c90097ed212\1038\eula.rtf.id-B4197730.[admin@stex777.com].money Dropped File Stream
Malicious
»
Mime Type application/octet-stream
File Size 4.38 KB
MD5 ad1264b6a8edf272d25eae2a8b1f0abc Copy to Clipboard
SHA1 c1ed33c7fbbc0b3c97653d4eb4ec98b5cde449db Copy to Clipboard
SHA256 afaf1dc9dfcf1f65355c14b63153cbfc3e0a49696efce34ba9e1cabfa8ce8e1c Copy to Clipboard
SSDeep 96:L8xuyqAMxlmA3yH7K6EV+kryLV1tEwDACm5fWY+bnq/qBxq0vWh:cvqAMxlmA3ybNEV+EyL6wUr5u59x3Oh Copy to Clipboard
YARA Matches (1)
»
Rule Name Rule Description Classification Score Actions
DharmaEncryptedFile File encrypted by Dharma Ransomware Ransomware
5/5
C:\588bce7c90097ed212\1038\LocalizedData.xml.id-B4197730.[admin@stex777.com].money Dropped File Stream
Malicious
»
Mime Type application/octet-stream
File Size 84.66 KB
MD5 770dcd76a9ae21b7101996f1fc3573ba Copy to Clipboard
SHA1 25f8f62f1f0157e769e7511fefe4bb66a63fc316 Copy to Clipboard
SHA256 7cf827e2c8b91a65936fdc5a0b4fc296d805ce3bc93bef4e49fc01e6f2458f3e Copy to Clipboard
SSDeep 1536:XoQjeUrKhPfBoxATxve5C65y0VO+k6oXazeksNxr+Mh/oAr0oxElzUmL:35mhB8ANo5dzsNxrfoUxE5bL Copy to Clipboard
YARA Matches (1)
»
Rule Name Rule Description Classification Score Actions
DharmaEncryptedFile File encrypted by Dharma Ransomware Ransomware
5/5
C:\588bce7c90097ed212\1040\eula.rtf.id-B4197730.[admin@stex777.com].money Dropped File Stream
Malicious
»
Mime Type application/octet-stream
File Size 3.79 KB
MD5 b81c90ab96abb4878c9c21902baccd1a Copy to Clipboard
SHA1 f347841a27e3ae9023172e4f42e670ce32a7675c Copy to Clipboard
SHA256 f90081665b5cc9c4048b93245c797924202f4b740236225c70b9e3eb7690f302 Copy to Clipboard
SSDeep 96:TPGZTzH7JdqbtqhlW0acTM2V2AICH01MR5JlWh:TPUn9d0tq8+gCUeRv0h Copy to Clipboard
YARA Matches (1)
»
Rule Name Rule Description Classification Score Actions
DharmaEncryptedFile File encrypted by Dharma Ransomware Ransomware
5/5
C:\588bce7c90097ed212\1040\LocalizedData.xml.id-B4197730.[admin@stex777.com].money Dropped File Stream
Malicious
»
Mime Type application/octet-stream
File Size 78.43 KB
MD5 210d31627e5ec79c2f4813848c89a8c2 Copy to Clipboard
SHA1 01b2e8f3f9ef12e6074c29348fd7b870ad71ca6a Copy to Clipboard
SHA256 ead61994e4a159c065a06a4b107fe4ebb8008732dbf01b6d088a6e727150f795 Copy to Clipboard
SSDeep 1536:UzTWi195XWjSnLP0LO0fVs5GKQ/HvgiRWd/OBvtuNysZiKZgzQ:U3WY95GJfyZQ/40EmBviZiUgk Copy to Clipboard
YARA Matches (1)
»
Rule Name Rule Description Classification Score Actions
DharmaEncryptedFile File encrypted by Dharma Ransomware Ransomware
5/5
C:\588bce7c90097ed212\1041\eula.rtf.id-B4197730.[admin@stex777.com].money Dropped File Stream
Malicious
»
Mime Type application/octet-stream
File Size 10.11 KB
MD5 43c372d4869248c17e3203f6bd6833ac Copy to Clipboard
SHA1 54c8f344890319ba16e9cecb6539fa15a7e5e807 Copy to Clipboard
SHA256 66cea93289c3a954787a1d1871aa33f51b55b00a2c74811ed37f0e3d5d9754a6 Copy to Clipboard
SSDeep 192:pzJ2T8gcyss64NGxiMk9wWyCNKGakcnaokr/j/3v3TMGvTvVk+X8I/bjb3h:5JA7s6TnKrkTFTj/3AGve+X5vb3h Copy to Clipboard
YARA Matches (1)
»
Rule Name Rule Description Classification Score Actions
DharmaEncryptedFile File encrypted by Dharma Ransomware Ransomware
5/5
C:\588bce7c90097ed212\1042\eula.rtf.id-B4197730.[admin@stex777.com].money Dropped File Stream
Malicious
»
Mime Type application/octet-stream
File Size 12.61 KB
MD5 027a06f621e1d7b5100e59ffec94ebe1 Copy to Clipboard
SHA1 8ed8206910297cb5e8d20141ccf1d34e61caab62 Copy to Clipboard
SHA256 b44b304aded1a3bf9c2cc42aae325d68ddd833e8668c8f31e825ebae720d251e Copy to Clipboard
SSDeep 384:N6z9ZE0RcegRVGBPuKESvhu39vTSUCzZCIsUDws6h:N68acFVuzHW9b8Y Copy to Clipboard
YARA Matches (1)
»
Rule Name Rule Description Classification Score Actions
DharmaEncryptedFile File encrypted by Dharma Ransomware Ransomware
5/5
C:\588bce7c90097ed212\1042\LocalizedData.xml.id-B4197730.[admin@stex777.com].money Dropped File Stream
Malicious
»
Mime Type application/octet-stream
File Size 63.96 KB
MD5 a9972f7ef3176292aa8531b1b846c386 Copy to Clipboard
SHA1 5a38fed42c6422e49135241a709f3d5ece4ed453 Copy to Clipboard
SHA256 0a818acf6b8e3011ffd21ae00aa49379091c45a66787e410229072783a2f5f87 Copy to Clipboard
SSDeep 1536:HLtGjGrXBw6p9GD3RWG+WqaQvqVb/In2chpKSmOBwfm8awuN5bbpS0:SGrXlp943N+W9Vb/XcfKSmUom8tuN5bJ Copy to Clipboard
YARA Matches (1)
»
Rule Name Rule Description Classification Score Actions
DharmaEncryptedFile File encrypted by Dharma Ransomware Ransomware
5/5
C:\588bce7c90097ed212\1037\LocalizedData.xml.id-B4197730.[admin@stex777.com].money Dropped File Stream
Malicious
»
Mime Type application/octet-stream
File Size 70.63 KB
MD5 f016f3c9e43f905550d724cc9aa9e471 Copy to Clipboard
SHA1 77a3e36e9a32edb717eaa350aecee4338324bfd6 Copy to Clipboard
SHA256 9e1b50bb1a5c9a577c124fa46eec11c353ea4e262b713eec1c28ef02cbdf1f5b Copy to Clipboard
SSDeep 1536:mYZXfwRj21cKG4UnWjWXVVZJ9/rvquuQW2lZEoklkRVtb:mYtfQ21fG4vWBrWuueb/Vtb Copy to Clipboard
YARA Matches (1)
»
Rule Name Rule Description Classification Score Actions
DharmaEncryptedFile File encrypted by Dharma Ransomware Ransomware
5/5
C:\588bce7c90097ed212\1043\LocalizedData.xml.id-B4197730.[admin@stex777.com].money Dropped File Stream
Malicious
»
Mime Type application/octet-stream
File Size 78.02 KB
MD5 abf3ec952205e132ed26f5690df8f20f Copy to Clipboard
SHA1 f6f11484fd4ce2efbf5ede53e6702cf3f5725220 Copy to Clipboard
SHA256 8bd512f69b0a9bbb8004149fa3136ac8d39601b6ac55263c9607645d91819f95 Copy to Clipboard
SSDeep 1536:NeT6ZrIxdRhgA93j29iT3t/fv9aDpoVAbW2ETl3cFLIS6GPRo6exJD6YkkEu92qb:rIxTr2Az9NadyAbUTl3qJdlexJvkkEkb Copy to Clipboard
YARA Matches (1)
»
Rule Name Rule Description Classification Score Actions
DharmaEncryptedFile File encrypted by Dharma Ransomware Ransomware
5/5
C:\588bce7c90097ed212\1043\eula.rtf.id-B4197730.[admin@stex777.com].money Dropped File Stream
Malicious
»
Mime Type application/octet-stream
File Size 3.69 KB
MD5 280565d5c66e6542c36657566d814bb1 Copy to Clipboard
SHA1 3e9de22b90265ca4801c1097b9f9f3663b10e9ce Copy to Clipboard
SHA256 c0b7da3edbf042d63f54d92477f72c62912977789f28656f5c505f5c08fe057b Copy to Clipboard
SSDeep 96:uKaTx960M0/5DsZIksiKnS8Q9tKxKyTmig2sN+7t8H3Wh:uKaX1jDseksHnxQnUJng2sNEt+Gh Copy to Clipboard
YARA Matches (1)
»
Rule Name Rule Description Classification Score Actions
DharmaEncryptedFile File encrypted by Dharma Ransomware Ransomware
5/5
C:\588bce7c90097ed212\1044\eula.rtf.id-B4197730.[admin@stex777.com].money Dropped File Stream
Malicious
»
Mime Type application/octet-stream
File Size 3.21 KB
MD5 23c58483589ff972fc19f69e679d5429 Copy to Clipboard
SHA1 4b641936a5570af78305bc546db2ad7108615ae3 Copy to Clipboard
SHA256 b1e14b29636b954fa4e7c25314e57d86a821d23eced2ad8995721f71b2ee58ed Copy to Clipboard
SSDeep 48:M0GqxlF9EaBbeP9NiEfSEHGTHhLmw27XMnBS61HXkqMKcTqfHc8ftEe9o0MrJr/O:tFXBbeP9hcHhq9Yk34rtnPsNWh Copy to Clipboard
YARA Matches (1)
»
Rule Name Rule Description Classification Score Actions
DharmaEncryptedFile File encrypted by Dharma Ransomware Ransomware
5/5
C:\588bce7c90097ed212\1044\LocalizedData.xml.id-B4197730.[admin@stex777.com].money Dropped File Stream
Malicious
»
Mime Type application/octet-stream
File Size 77.69 KB
MD5 c7d7dcf4c29c06851d37057646a5c997 Copy to Clipboard
SHA1 faa5f17baef8e10065c11186aa2ede8587421508 Copy to Clipboard
SHA256 10c2430dcae48ec280cee8d21aace696aeaf7093422df42c9a6e02c96c7280ef Copy to Clipboard
SSDeep 1536:J1UjVBeeygngkZQKKDiDJa3EAbs1YYtHhtw4olIox+3Z2yECzBTpP:eeeyKZQyJuEB1/ts4OI/3EyEGdpP Copy to Clipboard
YARA Matches (1)
»
Rule Name Rule Description Classification Score Actions
DharmaEncryptedFile File encrypted by Dharma Ransomware Ransomware
5/5
C:\588bce7c90097ed212\1045\LocalizedData.xml.id-B4197730.[admin@stex777.com].money Dropped File Stream
Malicious
»
Mime Type application/octet-stream
File Size 80.69 KB
MD5 224041baabf5496ac6a0b5390fee992a Copy to Clipboard
SHA1 91b355ef8f59249950405e6e0588e3042f91e59e Copy to Clipboard
SHA256 da3162f9cedd335ed4a0ebf07a8dbbe341ee4d5e61f3a7eee5206a3a523b5ed6 Copy to Clipboard
SSDeep 1536:AKfACK4Unvi5w4t2Z8J/xBVm/1I1mhC9Mqve9zyb+W7THUbtu4PF4pW/VvaT5y7I:pKra5pwZAL1mhCm8e9GzTXCXVPTmd Copy to Clipboard
YARA Matches (1)
»
Rule Name Rule Description Classification Score Actions
DharmaEncryptedFile File encrypted by Dharma Ransomware Ransomware
5/5
C:\588bce7c90097ed212\1045\eula.rtf.id-B4197730.[admin@stex777.com].money Dropped File Stream
Malicious
»
Mime Type application/octet-stream
File Size 4.18 KB
MD5 875d96035b37efa00aa63448f76c7a6c Copy to Clipboard
SHA1 6b333c15a95fa027dd9bef69fef22556104e7c74 Copy to Clipboard
SHA256 78912601b6020557346175d16119e2b716c160fdf8ee94358b84e10cae701358 Copy to Clipboard
SSDeep 96:ACDHaYaMnFOWuGy6weQntyff0HZyGBeXp/lqy/XU0dOa84VRDxDOkIdWh:A4aYJnFFqDb5yXpHE00aJPDZrIch Copy to Clipboard
YARA Matches (1)
»
Rule Name Rule Description Classification Score Actions
DharmaEncryptedFile File encrypted by Dharma Ransomware Ransomware
5/5
C:\588bce7c90097ed212\1046\eula.rtf.id-B4197730.[admin@stex777.com].money Dropped File Stream
Malicious
»
Mime Type application/octet-stream
File Size 3.83 KB
MD5 2b998f44e57d19bbbb09c837f6e08900 Copy to Clipboard
SHA1 ca8674e974ceccf7564843cfb4f56840ef8e9ffa Copy to Clipboard
SHA256 cbdcf4ed9bec5367ef1ae30a35f39f6818d426ec15c32670ecdb55fa6760bb6d Copy to Clipboard
SSDeep 96:+YGlskW8AkQtO8kjzrfougLIago9sEF+ZyXD4B3OwWjXdWh:+Y9kpABErgSagVrSMB6ch Copy to Clipboard
YARA Matches (1)
»
Rule Name Rule Description Classification Score Actions
DharmaEncryptedFile File encrypted by Dharma Ransomware Ransomware
5/5
C:\588bce7c90097ed212\1046\LocalizedData.xml.id-B4197730.[admin@stex777.com].money Dropped File Stream
Malicious
»
Mime Type application/octet-stream
File Size 79.10 KB
MD5 5c5958e59b7fdf621d5f73716cb62713 Copy to Clipboard
SHA1 d6097f752d1a4c024b7e8baa215e2c18ca3f6dd5 Copy to Clipboard
SHA256 ea7395b8c41d134b9cb132dec545577e260fc5a742e028fbb9b4900d5a245f9e Copy to Clipboard
SSDeep 1536:7ypvvcz0KSK29Bsh1y4uOn1BmZnpU50qLGoZI+:7y5cz0P9Bsh1y4Xinp4LGW Copy to Clipboard
YARA Matches (1)
»
Rule Name Rule Description Classification Score Actions
DharmaEncryptedFile File encrypted by Dharma Ransomware Ransomware
5/5
C:\588bce7c90097ed212\1037\SetupResources.dll.id-B4197730.[admin@stex777.com].money Dropped File Stream
Malicious
»
Mime Type application/octet-stream
File Size 16.59 KB
MD5 11834fe0657d3cd4d1905ce5c2c73d48 Copy to Clipboard
SHA1 3b20b1888d36fa31f5799edf74f1604afb62ab48 Copy to Clipboard
SHA256 26057a991d08254bbfc25fe70ce67503c64f2e323225c89ddba76921ce310454 Copy to Clipboard
SSDeep 384:6GsF+DQ33CPUtk7fVptlCFK0wnlKqBKhQ2GzPjuakmWMpb6+nS:6ZFUkWpk4R0WfrrfWMpmF Copy to Clipboard
YARA Matches (1)
»
Rule Name Rule Description Classification Score Actions
DharmaEncryptedFile File encrypted by Dharma Ransomware Ransomware
5/5
C:\588bce7c90097ed212\1037\eula.rtf.id-B4197730.[admin@stex777.com].money Dropped File Stream
Malicious
»
Mime Type application/octet-stream
File Size 6.93 KB
MD5 542212f6f6ec950dd0685ab45b1ee0bf Copy to Clipboard
SHA1 ea3480ee248c10cd7da3fb1dca782195f39d84a8 Copy to Clipboard
SHA256 03f47697dde961e124c635a96935b036c968cd0405f2ec7ca180743d9a6ad7b4 Copy to Clipboard
SSDeep 192:OP3epV6iH8p/xsfmZFesmqYvti3o2fPxJh:Oev6iqxqIpc2RJh Copy to Clipboard
YARA Matches (1)
»
Rule Name Rule Description Classification Score Actions
DharmaEncryptedFile File encrypted by Dharma Ransomware Ransomware
5/5
C:\588bce7c90097ed212\1049\LocalizedData.xml.id-B4197730.[admin@stex777.com].money Dropped File Stream
Malicious
»
Mime Type application/octet-stream
File Size 79.82 KB
MD5 090f99801f17a4ce07abe6902b85dad7 Copy to Clipboard
SHA1 fa120b87fb37e28a1b72e176bcf0d9914501b28f Copy to Clipboard
SHA256 7e19851feb8cabb37c3e0dc2690ccbd0d60010481254972d4f3786a5d1c3c7bb Copy to Clipboard
SSDeep 1536:2DT8sBPYZ9FAcfd7hbZ4hd+SGx9ijYYqX/LrndwXKUJqq:oTcF7Nyhd7G3ijYY6/LKaUn Copy to Clipboard
YARA Matches (1)
»
Rule Name Rule Description Classification Score Actions
DharmaEncryptedFile File encrypted by Dharma Ransomware Ransomware
5/5
C:\588bce7c90097ed212\1053\eula.rtf.id-B4197730.[admin@stex777.com].money Dropped File Stream
Malicious
»
Mime Type application/octet-stream
File Size 4.00 KB
MD5 850500f904b2dff3f2d42daffcbf3e15 Copy to Clipboard
SHA1 f962f99a0644358c617554ee3215007b17e926a5 Copy to Clipboard
SHA256 b869a1e813ec8e35826b58507b187cd2b1a40dd67bd099499c67760ec387fca2 Copy to Clipboard
SSDeep 48:IStaCVq7RR3/nB5WFQjaCP/hnVM4Oh/riJu+y+QCxQ+xqRzs3FEYPBY3EX+Cr/L4:fRGfB5WeThg/rik0QPs3FEWYYvTWh Copy to Clipboard
YARA Matches (1)
»
Rule Name Rule Description Classification Score Actions
DharmaEncryptedFile File encrypted by Dharma Ransomware Ransomware
5/5
C:\588bce7c90097ed212\1049\eula.rtf.id-B4197730.[admin@stex777.com].money Dropped File Stream
Malicious
»
Mime Type application/octet-stream
File Size 53.41 KB
MD5 15b3555da4702805978d3e0e84e070ad Copy to Clipboard
SHA1 d838cfdf25fc042e6c3b1a8a54b262a3a3c4facd Copy to Clipboard
SHA256 881a710f438d4cd66c5c2c06cff8772a0c5886b52db5e351f124c7959311a9d9 Copy to Clipboard
SSDeep 1536:9drFUT9Expn3BqMjgQeaei/EkN97Q0OXVE:LFE9ExpnRqSMr0O2 Copy to Clipboard
YARA Matches (1)
»
Rule Name Rule Description Classification Score Actions
DharmaEncryptedFile File encrypted by Dharma Ransomware Ransomware
5/5
C:\588bce7c90097ed212\1055\eula.rtf.id-B4197730.[admin@stex777.com].money Dropped File Stream
Malicious
»
Mime Type application/octet-stream
File Size 4.00 KB
MD5 156b3fa3b40759a22ecb1951b97f6b2e Copy to Clipboard
SHA1 c2f5def4e74725ec8df3c907b6f6c408c7661612 Copy to Clipboard
SHA256 78b2553923085b659bdccf54aa997bb973914fc1503ebb36d7470de5fd8d46c5 Copy to Clipboard
SSDeep 96:BDs73AJonemMLjCGGls5SnGa9Jo3dbnjkWvQaJ23+ByRNWh:BDsLAJonYClkSGa9Jo39QaMDRsh Copy to Clipboard
YARA Matches (1)
»
Rule Name Rule Description Classification Score Actions
DharmaEncryptedFile File encrypted by Dharma Ransomware Ransomware
5/5
C:\588bce7c90097ed212\1055\LocalizedData.xml.id-B4197730.[admin@stex777.com].money Dropped File Stream
Malicious
»
Mime Type application/octet-stream
File Size 75.27 KB
MD5 60cf855aa4d5b1158d5aebcd9676d690 Copy to Clipboard
SHA1 c4aca3a63c48f85e46c1b41f120a342e08b1c8c9 Copy to Clipboard
SHA256 ef8d3b6290f16f33b5b7ccd90eb61761e5de774db4689bbbe71d82328cb11e89 Copy to Clipboard
SSDeep 1536:tPMMcsGiNwk2km794Ts3svdUkkS/LigQXeNsPD1n9lKYzc:tUNign79ys3svdUkn/N+598sc Copy to Clipboard
YARA Matches (1)
»
Rule Name Rule Description Classification Score Actions
DharmaEncryptedFile File encrypted by Dharma Ransomware Ransomware
5/5
C:\588bce7c90097ed212\1038\SetupResources.dll.id-B4197730.[admin@stex777.com].money Dropped File Stream
Malicious
»
Mime Type application/octet-stream
File Size 18.59 KB
MD5 0cf88a482dea40d556e843d4ffeb3fdc Copy to Clipboard
SHA1 2aaf5e143abf6b2374562a0c56831ed8287c747f Copy to Clipboard
SHA256 659bf1fd79d43e61b0e5220d4dff23440e70379bc4fd9839ee32246216c2d3f8 Copy to Clipboard
SSDeep 384:zjhwkAgjueu9hu1AmZMdBIO/W/CQaTBdeC/nsPkWuFBMTgno:XKkLj0RmZqBdHQaLeC/sP+By Copy to Clipboard
YARA Matches (1)
»
Rule Name Rule Description Classification Score Actions
DharmaEncryptedFile File encrypted by Dharma Ransomware Ransomware
5/5
C:\588bce7c90097ed212\1041\LocalizedData.xml.id-B4197730.[admin@stex777.com].money Dropped File Stream
Malicious
»
Mime Type application/octet-stream
File Size 66.88 KB
MD5 add63becce2c672f877f510aa410a34a Copy to Clipboard
SHA1 4f8d241a64fc56ab13a1c57a1529a5a50f594ad8 Copy to Clipboard
SHA256 2d69eec0ecfb316f81dcdfae47785f02d9900aa0a63033b1edea841c7925fb18 Copy to Clipboard
SSDeep 768:WdqxOiifKkb0h/rrVDiGHTWnVHl0+JeYHX089WVuCQAFona8McZGPGIujzmTlMJ4:WNRbA/JHkF5J5HEfwnaMZGPUKl2qb Copy to Clipboard
YARA Matches (1)
»
Rule Name Rule Description Classification Score Actions
DharmaEncryptedFile File encrypted by Dharma Ransomware Ransomware
5/5
C:\588bce7c90097ed212\2070\eula.rtf.id-B4197730.[admin@stex777.com].money Dropped File Stream
Malicious
»
Mime Type application/octet-stream
File Size 4.14 KB
MD5 1a91558e39c361d1dfbe9bf08fefe82a Copy to Clipboard
SHA1 fb5f0e9aea034da7bed9379cf278b60e8ed26006 Copy to Clipboard
SHA256 5e5f6cc5fea21ef85b3cd28da43e6e39e4493df0012cabf4289e5822d5e79b33 Copy to Clipboard
SSDeep 96:eSFUy+GB1dY9u5kLjTnjuTZ5Zt3HUAdFhcRSrIfsvACcAQsiRRjPqJ0JWh:ek35BnY9ueuTZ5Zt3UUeREy+IxsOPQ0a Copy to Clipboard
YARA Matches (1)
»
Rule Name Rule Description Classification Score Actions
DharmaEncryptedFile File encrypted by Dharma Ransomware Ransomware
5/5
C:\588bce7c90097ed212\2070\LocalizedData.xml.id-B4197730.[admin@stex777.com].money Dropped File Stream
Malicious
»
Mime Type application/octet-stream
File Size 78.62 KB
MD5 d5ec69ba30cbfbe8307420e8664b06e3 Copy to Clipboard
SHA1 0a6b5de7b7a0d58077b43fdc450cd3234616b7f2 Copy to Clipboard
SHA256 50ee9717e11ab4458dd48e8698888a282c2eae371230270ab9c8c9a090f7cad9 Copy to Clipboard
SSDeep 1536:lU7skZhUPQTI4djw98rFtisldQLAKu8D0OejYdvngN+228d7+y:bkZhGEw982QuLArwddvNIiy Copy to Clipboard
YARA Matches (1)
»
Rule Name Rule Description Classification Score Actions
DharmaEncryptedFile File encrypted by Dharma Ransomware Ransomware
5/5
C:\588bce7c90097ed212\3076\eula.rtf.id-B4197730.[admin@stex777.com].money Dropped File Stream
Malicious
»
Mime Type application/octet-stream
File Size 6.39 KB
MD5 ca63f84880e7785b9cf0963860ec6f55 Copy to Clipboard
SHA1 8ad5879b9c8d04e433b922671722ec7acbd6c0f9 Copy to Clipboard
SHA256 e807802637a80ca6fae4acd1e9a858d6a1119afa9ab3b7751e391cfb5373dba2 Copy to Clipboard
SSDeep 192:aSb2DDo5xzYayDhoo7AGV53duV5cOErJlCO433Mah:aS4ELzUlwGvIV50JN43cah Copy to Clipboard
YARA Matches (1)
»
Rule Name Rule Description Classification Score Actions
DharmaEncryptedFile File encrypted by Dharma Ransomware Ransomware
5/5
C:\588bce7c90097ed212\1053\LocalizedData.xml.id-B4197730.[admin@stex777.com].money Dropped File Stream
Malicious
»
Mime Type application/octet-stream
File Size 76.12 KB
MD5 305e35a44f78ee35f4b671929f7114d8 Copy to Clipboard
SHA1 65584fc3c1452ed7932ce9f4b3ce7de5ef947df7 Copy to Clipboard
SHA256 4e36ec0d80b2ee735947e5188d058920bfc17cb94f50e1e469c744793c2865f1 Copy to Clipboard
SSDeep 1536:Olfz22dWv+0cW9U/WStABFr2sLQkgsRmrEkNlUDEJzEzTQ8v0c0:OhA2gU/dtQj1gsUz/UDERE3/W Copy to Clipboard
YARA Matches (1)
»
Rule Name Rule Description Classification Score Actions
DharmaEncryptedFile File encrypted by Dharma Ransomware Ransomware
5/5
C:\588bce7c90097ed212\3076\LocalizedData.xml.id-B4197730.[admin@stex777.com].money Dropped File Stream
Malicious
»
Mime Type application/octet-stream
File Size 59.65 KB
MD5 e8bf8c64541c5e5efe8d34028a7cb389 Copy to Clipboard
SHA1 0b311d70cfa1d40ce91d6c231f446e1853f03075 Copy to Clipboard
SHA256 157353a9e86c94d612322ee7a181a1539bb50160cc676c5bb8aca35f7392d08e Copy to Clipboard
SSDeep 1536:v2DayIbRLfUBl1tK3kfyhSWBQW+TnY+iY2VKIFwtEC/Y9tZrA:QKOBxK3kfmeHT+Y2k6iY9tFA Copy to Clipboard
YARA Matches (1)
»
Rule Name Rule Description Classification Score Actions
DharmaEncryptedFile File encrypted by Dharma Ransomware Ransomware
5/5
C:\588bce7c90097ed212\3082\eula.rtf.id-B4197730.[admin@stex777.com].money Dropped File Stream
Malicious
»
Mime Type application/octet-stream
File Size 3.22 KB
MD5 8834e589a0a6a736f7097b8b52acef48 Copy to Clipboard
SHA1 7f9edbc1219946f0fc49cd6f8a591cb6069a128b Copy to Clipboard
SHA256 8fe9f898bb56f7c9b36c1c7ca8a570bb23fe2e98fcd7d050a71cc64f8487b4b7 Copy to Clipboard
SSDeep 48:4Spk+WFuQmQIV5lBJwAFDdUvDZvxVwrImCmaDWfIc2Cqr/H5WSU:NpNouQm/fK8Dod/wrImHPN2JBWh Copy to Clipboard
YARA Matches (1)
»
Rule Name Rule Description Classification Score Actions
DharmaEncryptedFile File encrypted by Dharma Ransomware Ransomware
5/5
C:\588bce7c90097ed212\2052\eula.rtf.id-B4197730.[admin@stex777.com].money Dropped File Stream
Malicious
»
Mime Type application/octet-stream
File Size 5.93 KB
MD5 ede24c5ea2a6fdfe370e65678307a72f Copy to Clipboard
SHA1 4168386102b8a98380b3fd5a33a6b43fa49d61ec Copy to Clipboard
SHA256 cdcb968d46de72beffd9b7d95702a61c34bb8c853f16e98106ea74e4c1b20b3a Copy to Clipboard
SSDeep 96:ISASMXLqJ/aLPoHcA+Ady/x6lTTGuVmHSfUMyJQL/olp1f/mONt91kwVaHgRJvpx:ISebqRaLA8APc9uVQi0Jw83m6tLkvgTr Copy to Clipboard
YARA Matches (1)
»
Rule Name Rule Description Classification Score Actions
DharmaEncryptedFile File encrypted by Dharma Ransomware Ransomware
5/5
C:\588bce7c90097ed212\Client\Parameterinfo.xml.id-B4197730.[admin@stex777.com].money Dropped File Stream
Malicious
»
Mime Type application/octet-stream
File Size 197.32 KB
MD5 2d114388e15a00599c302838a14844b5 Copy to Clipboard
SHA1 32354b9ed3317fa1f5bb012c99e7df9abee6a389 Copy to Clipboard
SHA256 9e4e3a491b079521f3d3d6366418eded0a019fa3cc882d6bc2340046739f2080 Copy to Clipboard
SSDeep 3072:rasUtijG3hsKZSow+gtKTwiHNmQBmMtZIKvYW1bqgvRvCXv1V8SnXyDZdAL4F:GHXsdow+gtK0itrmUZI/Wl1ZC1na2L4F Copy to Clipboard
YARA Matches (1)
»
Rule Name Rule Description Classification Score Actions
DharmaEncryptedFile File encrypted by Dharma Ransomware Ransomware
5/5
C:\588bce7c90097ed212\2052\LocalizedData.xml.id-B4197730.[admin@stex777.com].money Dropped File Stream
Malicious
»
Mime Type application/octet-stream
File Size 59.51 KB
MD5 79466d32d362ef36b0d657bc01bae3ab Copy to Clipboard
SHA1 a3e2c2ca62fae916b3383f369b70190980fa7254 Copy to Clipboard
SHA256 83c1c02dfec2ba82ecadb5cdadaeac23e116aa54dbeb9524fb23b2a8b0a6a163 Copy to Clipboard
SSDeep 1536:my0Be0/KG7JtsDJs4fy/hlyGIfMaJ5+YuW+c5oozhd:4aG/6Js4fy/PyGWMaJgYuWrdd Copy to Clipboard
YARA Matches (1)
»
Rule Name Rule Description Classification Score Actions
DharmaEncryptedFile File encrypted by Dharma Ransomware Ransomware
5/5
C:\588bce7c90097ed212\DHtmlHeader.html.id-B4197730.[admin@stex777.com].money Dropped File Stream
Malicious
»
Mime Type application/octet-stream
File Size 15.99 KB
MD5 7d9c49c68c2cf965f5d131e9e524e863 Copy to Clipboard
SHA1 5144bd8e390ee5936032d5a282dd53ca1eadeba8 Copy to Clipboard
SHA256 42d7b471e9106cff6b5024253a68a7797f5155d210597b128504b759776d9abb Copy to Clipboard
SSDeep 384:hjHk0CMC2dFYDQXi8F9BgWHXZt8/CEMbUmyvbJ0qnYzPgG/BQx:NxRiDqPBg0S/C5bUmqEPgG4 Copy to Clipboard
YARA Matches (1)
»
Rule Name Rule Description Classification Score Actions
DharmaEncryptedFile File encrypted by Dharma Ransomware Ransomware
5/5
C:\588bce7c90097ed212\Extended\Parameterinfo.xml.id-B4197730.[admin@stex777.com].money Dropped File Stream
Malicious
»
Mime Type application/octet-stream
File Size 91.38 KB
MD5 4f1df084be7300dfe073fd958f54224b Copy to Clipboard
SHA1 c5e6ede6dcd4dab9de797351f5e6be07d2039cdc Copy to Clipboard
SHA256 4e0fa1c492b4f454ecbea3367936f8b0e7f3f6f272127a6f2dcb79e57af0c1ce Copy to Clipboard
SSDeep 1536:zCOwuzVq5t3BH6uglA+NBKUKhJQfDfjcZ76/y1JjGRF9KvOY9kxGe7xNdbk3qE3Y:+OjQ73pngbOhJQrfjcZ6/GG3YGMmxNdx Copy to Clipboard
YARA Matches (1)
»
Rule Name Rule Description Classification Score Actions
DharmaEncryptedFile File encrypted by Dharma Ransomware Ransomware
5/5
C:\588bce7c90097ed212\1040\SetupResources.dll.id-B4197730.[admin@stex777.com].money Dropped File Stream
Malicious
»
Mime Type application/octet-stream
File Size 18.09 KB
MD5 7f6ac0aa5f0b6c91395b9d86ae521403 Copy to Clipboard
SHA1 ec58470193e6b3f3b06b218ba85a22c61daabfd0 Copy to Clipboard
SHA256 a42315fc8a1bb58ee51084a849788c4d406232eb7ac039d21844cb421efa0192 Copy to Clipboard
SSDeep 384:4+P0HTA/r7wZQdlHNoGXe4qAJYZ19qGhOuh+PLRdOyHANXy0nC:MHTCCkroGpYZ1JYuhIRdOygNXU Copy to Clipboard
YARA Matches (1)
»
Rule Name Rule Description Classification Score Actions
DharmaEncryptedFile File encrypted by Dharma Ransomware Ransomware
5/5
C:\588bce7c90097ed212\1041\SetupResources.dll.id-B4197730.[admin@stex777.com].money Dropped File Stream
Malicious
»
Mime Type application/octet-stream
File Size 15.59 KB
MD5 ee545a3e472bf7b9e4fb09c2e5249e8a Copy to Clipboard
SHA1 594959b8f6c554545be947e65c45324dddcef746 Copy to Clipboard
SHA256 43dcef334b27343bdaeaba8a1878754c107edc5fd84e73a530ee7be2eb338db6 Copy to Clipboard
SSDeep 384:Ut7AgINzDRdftBT5w0NVA4Qp9b9LNU65Y13lwB9lW+nk:u7AgatBT6sATp9bjUXVSlW3 Copy to Clipboard
YARA Matches (1)
»
Rule Name Rule Description Classification Score Actions
DharmaEncryptedFile File encrypted by Dharma Ransomware Ransomware
5/5
C:\588bce7c90097ed212\1042\SetupResources.dll.id-B4197730.[admin@stex777.com].money Dropped File Stream
Malicious
»
Mime Type application/octet-stream
File Size 15.09 KB
MD5 6b4ad7a09ab971a9f3bb628bf9160f5a Copy to Clipboard
SHA1 28954c3439e525bc122046a62c846e21456eabce Copy to Clipboard
SHA256 9dfacd91da1e6edab2e14e8ce7d611ec5cf2e3628ccdd3b8e0fbbcff47ca06f5 Copy to Clipboard
SSDeep 384:8DdvzS0+N6RiqMXNuKE6YC5ArfJJZ0tnmyWuVf3FzrZuHyjMjYJlRA8nI:8BvT+N6RtMYC5ArfJM9mK9v0HXjyu Copy to Clipboard
YARA Matches (1)
»
Rule Name Rule Description Classification Score Actions
DharmaEncryptedFile File encrypted by Dharma Ransomware Ransomware
5/5
C:\588bce7c90097ed212\1043\SetupResources.dll.id-B4197730.[admin@stex777.com].money Dropped File Stream
Malicious
»
Mime Type application/octet-stream
File Size 19.09 KB
MD5 e73aaf318ec74882ddb773f396cb8a15 Copy to Clipboard
SHA1 63390bb86e396a499b12fd7959ea8398ac20e07f Copy to Clipboard
SHA256 ff3fcd3d78ebdca7847ea8366f62480014a593dfb8c1022fc0615d6b1b309958 Copy to Clipboard
SSDeep 384:pvCMgNMJsMyLtalE6gvdDotLa4paaILHEk78zv74PPNrmMELnm:piKJsMWAlLId8LDpM778P0PNhEC Copy to Clipboard
YARA Matches (1)
»
Rule Name Rule Description Classification Score Actions
DharmaEncryptedFile File encrypted by Dharma Ransomware Ransomware
5/5
C:\588bce7c90097ed212\1045\SetupResources.dll.id-B4197730.[admin@stex777.com].money Dropped File Stream
Malicious
»
Mime Type application/octet-stream
File Size 18.09 KB
MD5 b56163bc3961f681c7d00b60d68a1477 Copy to Clipboard
SHA1 6bca01d8c7585ce120eb97cc0673a90e3d632200 Copy to Clipboard
SHA256 0dd827b8a78c349c0fe31077f2df6e19e00978eb7daabfb37af39d511886994c Copy to Clipboard
SSDeep 384:ukx2wv7ePMm13MrSXlyIF9MQNjI52/O/Frfpxmnn:ukxbaEmNl1yI/Ncgm/Frfpxk Copy to Clipboard
YARA Matches (1)
»
Rule Name Rule Description Classification Score Actions
DharmaEncryptedFile File encrypted by Dharma Ransomware Ransomware
5/5
C:\588bce7c90097ed212\1046\SetupResources.dll.id-B4197730.[admin@stex777.com].money Dropped File Stream
Malicious
»
Mime Type application/octet-stream
File Size 18.09 KB
MD5 81f98114344b6c581fcc3da13d6a7b7d Copy to Clipboard
SHA1 83b37da24df43212b0709de3ea5eab6e37865be4 Copy to Clipboard
SHA256 8858f1f7a2ee0ab46ef63164bf55ff43c3880110ca8a6db24eda186a91d5b82e Copy to Clipboard
SSDeep 384:O5ULp6fbIJv3Z6GWHGFJsjgKFB+nyWrQJKSxjJNcU13hYan+zKxwo3N+anQ:RLpibgvEGWHSs8c+yWcJK0fcUFhYOKUq Copy to Clipboard
YARA Matches (1)
»
Rule Name Rule Description Classification Score Actions
DharmaEncryptedFile File encrypted by Dharma Ransomware Ransomware
5/5
C:\588bce7c90097ed212\1049\SetupResources.dll.id-B4197730.[admin@stex777.com].money Dropped File Stream
Malicious
»
Mime Type application/octet-stream
File Size 18.09 KB
MD5 747a7b2781a4b72395f544f6305726af Copy to Clipboard
SHA1 ed57c1114cf7cb7666ab6ed1e3ccbbca6f5a60fd Copy to Clipboard
SHA256 bb6d0f85a2d68a6aaf17771ea42925a25874ae5f3ea84973f4f86ad4ccbbb544 Copy to Clipboard
SSDeep 384:UN0HlbP29xFQhAAInscXh5k21BUgeLJGxkbr1iqVlg2VOUEnJ:UN0FziQ/In3R/ve/3OCg Copy to Clipboard
YARA Matches (1)
»
Rule Name Rule Description Classification Score Actions
DharmaEncryptedFile File encrypted by Dharma Ransomware Ransomware
5/5
C:\588bce7c90097ed212\1053\SetupResources.dll.id-B4197730.[admin@stex777.com].money Dropped File Stream
Malicious
»
Mime Type application/octet-stream
File Size 17.59 KB
MD5 bd3c3ad43ab6898f575af87b112846de Copy to Clipboard
SHA1 96a524c0ebb8dab35f1b07164a28881f97862f45 Copy to Clipboard
SHA256 ac2fc61a7ffb745ba8e66c2907d798a8b4ffa755c245c1e0035557e48968dc1b Copy to Clipboard
SSDeep 384:KQGfTKW2/zZWP7KUB3w8UXTsSnxUxgWn3fLz2daowWvnr:3mTKWEZW7KUB3QVUxj3Tz2daHWj Copy to Clipboard
YARA Matches (1)
»
Rule Name Rule Description Classification Score Actions
DharmaEncryptedFile File encrypted by Dharma Ransomware Ransomware
5/5
C:\588bce7c90097ed212\header.bmp.id-B4197730.[admin@stex777.com].money Dropped File Stream
Malicious
»
Mime Type application/octet-stream
File Size 3.77 KB
MD5 9e3bc0b1676ec465a5bc52a1d10f87cd Copy to Clipboard
SHA1 4fe6537597b18d070ce1054424721e71fb76fe05 Copy to Clipboard
SHA256 899ee1588b1a16eca99e1e823dc180e02990346aa59b6e7f5bbd1f159e01b30d Copy to Clipboard
SSDeep 96:pyHNX3ym88FtSXSHF9oHSIuCkEMqssxmopWN:4tXil8F0CHF9YSIuCkax5YN Copy to Clipboard
YARA Matches (1)
»
Rule Name Rule Description Classification Score Actions
DharmaEncryptedFile File encrypted by Dharma Ransomware Ransomware
5/5
C:\588bce7c90097ed212\ParameterInfo.xml.id-B4197730.[admin@stex777.com].money Dropped File Stream
Malicious
»
Mime Type application/octet-stream
File Size 265.91 KB
MD5 87383bea26b0af3f3c67df9ead4f6b0a Copy to Clipboard
SHA1 4d515b0ec407675e6d97daef97eafcaa04b40678 Copy to Clipboard
SHA256 9e7f63195ac5addd849edafc3aea27a678f02a2a8eef53ade4cb1bed57eedb71 Copy to Clipboard
SSDeep 6144:d7a5vjPHZL02OsoTh2hzaHxUgM9T1rfbuMXCJDjRfwXPV3Eprjj:WvrfOZT8hdJrPXChRfMVgjj Copy to Clipboard
YARA Matches (1)
»
Rule Name Rule Description Classification Score Actions
DharmaEncryptedFile File encrypted by Dharma Ransomware Ransomware
5/5
C:\588bce7c90097ed212\3082\LocalizedData.xml.id-B4197730.[admin@stex777.com].money Dropped File Stream
Malicious
»
Mime Type application/octet-stream
File Size 78.37 KB
MD5 18fb4c1f088798d8afffa2fb714c22e2 Copy to Clipboard
SHA1 c091a9f84f662afa915b6d6b7d75b7ac5edc7247 Copy to Clipboard
SHA256 fb28097afa7996b11065363bf9a71439d1254de333dfc013b4ba13c598c1bbbd Copy to Clipboard
SSDeep 1536:NyByNnqSHWJcV7sqaX1KGhoGA6xxZ435Meb/yzgU7utwcRBozJ:NjNq3awlX84oHmxo5MeDkgLtw/ Copy to Clipboard
YARA Matches (1)
»
Rule Name Rule Description Classification Score Actions
DharmaEncryptedFile File encrypted by Dharma Ransomware Ransomware
5/5
C:\588bce7c90097ed212\SplashScreen.bmp.id-B4197730.[admin@stex777.com].money Dropped File Stream
Malicious
»
Mime Type application/octet-stream
File Size 40.36 KB
MD5 ae670d838799bb7b6796114e28afb803 Copy to Clipboard
SHA1 ec43c4ab8b6cc8b039c924a38ca8bebb6b3d84e7 Copy to Clipboard
SHA256 d0eb8eb17f8699f88303c7124eddc1a2bf0f11c9d83ae962c56e551dff6e111c Copy to Clipboard
SSDeep 768:NTZPeTMWgU95vkW2pN5ospUFXK2f3B7wS3Da7O2A6L6Njj8x4CvYGd2UB:NTkTHggvE2PB7wPVLoje4Ch0e Copy to Clipboard
YARA Matches (1)
»
Rule Name Rule Description Classification Score Actions
DharmaEncryptedFile File encrypted by Dharma Ransomware Ransomware
5/5
C:\588bce7c90097ed212\Strings.xml.id-B4197730.[admin@stex777.com].money Dropped File Stream
Malicious
»
Mime Type application/octet-stream
File Size 13.99 KB
MD5 8997fea4c24eb669ba10a8afbf3e8751 Copy to Clipboard
SHA1 3393768089ec91c7581c145dfbbbaedb11f59bb0 Copy to Clipboard
SHA256 024eff611cb46054aeebe79f6e7c7b8c8255a888cd1d60aa62433cfd52e12145 Copy to Clipboard
SSDeep 384:zdKPrvAK0glSLgcosRDjRO1cByjNkqmdRJCGyO2bAlc3h30XGj:QProK0glSxD9O1cTdRUQple7 Copy to Clipboard
YARA Matches (1)
»
Rule Name Rule Description Classification Score Actions
DharmaEncryptedFile File encrypted by Dharma Ransomware Ransomware
5/5
C:\588bce7c90097ed212\Client\UiInfo.xml.id-B4197730.[admin@stex777.com].money Dropped File Stream
Malicious
»
Mime Type application/octet-stream
File Size 38.37 KB
MD5 4c01e0583b8a7ef3119bb09aff94bfc1 Copy to Clipboard
SHA1 a925451163bc5ddd9ccb73bb84578be639254db2 Copy to Clipboard
SHA256 493deda9ce41666a21480806fab82429e336958fac7f09b1610a2604cf37cf59 Copy to Clipboard
SSDeep 768:PR4lYLCyKnBsOaFrXPvC6Lfppc4/Nii4vgbyohx:P5CffaFrnb7+i44Wohx Copy to Clipboard
YARA Matches (1)
»
Rule Name Rule Description Classification Score Actions
DharmaEncryptedFile File encrypted by Dharma Ransomware Ransomware
5/5
C:\588bce7c90097ed212\watermark.bmp.id-B4197730.[admin@stex777.com].money Dropped File Stream
Malicious
»
Mime Type application/octet-stream
File Size 101.87 KB
MD5 16c55268928a72f1acd25322c62b7c24 Copy to Clipboard
SHA1 9ce174241feee2632889fc70e5c59d1f2634b65f Copy to Clipboard
SHA256 fb71cd173a72f86046b25cb50ee4b94ecea13450ddd24a18516df92274cdcd47 Copy to Clipboard
SSDeep 3072:nfVMHUTxnQnWc1RJnAOWDwwhBDmjNG9IRJHtu0g+jy:nfVM+QnWcPJtWRBuG9IRltu0g+y Copy to Clipboard
YARA Matches (1)
»
Rule Name Rule Description Classification Score Actions
DharmaEncryptedFile File encrypted by Dharma Ransomware Ransomware
5/5
C:\Boot\BOOTSTAT.DAT.id-B4197730.[admin@stex777.com].money Dropped File Stream
Malicious
»
Mime Type application/octet-stream
File Size 64.25 KB
MD5 5ebcc258d7182f4db160338f40279023 Copy to Clipboard
SHA1 fd8f5011730c3e99dec39f893edf3c5562b73355 Copy to Clipboard
SHA256 17fd65ead85e4bd467dcf99cd5c8f86a96d3a86549564642247d7535b5bed2b3 Copy to Clipboard
SSDeep 1536:CxKV03SZnXr2SgE/KyUxyMacyUramjy4JAR:+KV0367XaxjByUrJjG Copy to Clipboard
YARA Matches (1)
»
Rule Name Rule Description Classification Score Actions
DharmaEncryptedFile File encrypted by Dharma Ransomware Ransomware
5/5
C:\588bce7c90097ed212\Extended\UiInfo.xml.id-B4197730.[admin@stex777.com].money Dropped File Stream
Malicious
»
Mime Type application/octet-stream
File Size 38.37 KB
MD5 5461412b2e923ecb516b0874350f8914 Copy to Clipboard
SHA1 03cd8eb3585d1bb57ddfd63a432644733e7aff10 Copy to Clipboard
SHA256 030bd06fe08992b30b9477548f4924647fb720b7a7397d16f5b7a3031f498495 Copy to Clipboard
SSDeep 768:0qZofU1KoXH6bYkG9MBzutACVBq63lRAHuBzYyCsD+RzYNhHYSPmH+H:pOGIYXhtjT2uCK+VB92 Copy to Clipboard
YARA Matches (1)
»
Rule Name Rule Description Classification Score Actions
DharmaEncryptedFile File encrypted by Dharma Ransomware Ransomware
5/5
C:\BOOTSECT.BAK.id-B4197730.[admin@stex777.com].money Dropped File Stream
Malicious
»
Mime Type application/octet-stream
File Size 8.25 KB
MD5 1fa43a5fe27e8f1c0ccb53f10754f99b Copy to Clipboard
SHA1 746440f4a248ab1c7ca8ff9fa6b56a1badae463d Copy to Clipboard
SHA256 b664f38fc6176a05a1521706a6f6a46e66d379b6ffc55007c3fafe9449a14710 Copy to Clipboard
SSDeep 192:+6ZiVGcoDNhzP/OpfbUnTTn8yERoAbaN93e6FZuDAA55:vZCGTNhb/FTb8ydnm55 Copy to Clipboard
YARA Matches (1)
»
Rule Name Rule Description Classification Score Actions
DharmaEncryptedFile File encrypted by Dharma Ransomware Ransomware
5/5
C:\588bce7c90097ed212\2052\SetupResources.dll.id-B4197730.[admin@stex777.com].money Dropped File Stream
Malicious
»
Mime Type application/octet-stream
File Size 14.09 KB
MD5 907e8c88e13eb9b5c8053dd16aac953c Copy to Clipboard
SHA1 071fc77016a846dda0811f3385edb04253315693 Copy to Clipboard
SHA256 a015807d4b8701b5f90622c55ff6c683ff6063025de64cf9434cc7676cf7a239 Copy to Clipboard
SSDeep 384:BN71MKOYQ1eafWMJz1tQZvqCBv+nWIzZwnq:71E71e5Mx1t2zYnjZL Copy to Clipboard
YARA Matches (1)
»
Rule Name Rule Description Classification Score Actions
DharmaEncryptedFile File encrypted by Dharma Ransomware Ransomware
5/5
C:\588bce7c90097ed212\2070\SetupResources.dll.id-B4197730.[admin@stex777.com].money Dropped File Stream
Malicious
»
Mime Type application/octet-stream
File Size 18.59 KB
MD5 8d2a3be279b4bcce1671e26875200c8f Copy to Clipboard
SHA1 08b88c39021dd853fc1200a05c80196c048040c6 Copy to Clipboard
SHA256 675fda4d70d6284046d24bb88977a1bc3239a0e8c174c20f574f224bc74b7058 Copy to Clipboard
SSDeep 384:zVUAwSeTU6cc67fp+TIhhtc1nU+X8fKp7qHKaQPscP5T+ni:OA+U6FYfgsh4DX8smHKJTxR Copy to Clipboard
YARA Matches (1)
»
Rule Name Rule Description Classification Score Actions
DharmaEncryptedFile File encrypted by Dharma Ransomware Ransomware
5/5
C:\588bce7c90097ed212\3076\SetupResources.dll.id-B4197730.[admin@stex777.com].money Dropped File Stream
Malicious
»
Mime Type application/octet-stream
File Size 14.09 KB
MD5 ca45d84d9bce26903a317407ef0a174b Copy to Clipboard
SHA1 a367037bfa7fe28d773040a8b68f3d062228a1af Copy to Clipboard
SHA256 7f1fc57f9df0283c63bd74c96432af118dfd41d759b17d0e00f25b460d945c18 Copy to Clipboard
SSDeep 384:2Lyl5Thxyjom+rXqnrVVmCjd1SQcXrh8bkuJk9xZKElllyznV:2LeThxyjGwpVmCjTS15zZg Copy to Clipboard
YARA Matches (1)
»
Rule Name Rule Description Classification Score Actions
DharmaEncryptedFile File encrypted by Dharma Ransomware Ransomware
5/5
C:\588bce7c90097ed212\3082\SetupResources.dll.id-B4197730.[admin@stex777.com].money Dropped File Stream
Malicious
»
Mime Type application/octet-stream
File Size 18.59 KB
MD5 70e3857f74942d69486ac7c587dd45dd Copy to Clipboard
SHA1 5cdd581e181356f356e0f47546f411026730b1e0 Copy to Clipboard
SHA256 0517663a37cbed2f793c433a7ce4c61b1ce78eef53cb00def723eb4723388490 Copy to Clipboard
SSDeep 384:x0nmerOM+BvpQ7OTq9neT0W6RzFkqwqzteVtOF0eaKFUQvKkNa7QnP:unmIOMyhQ7n20jZTzteVKFpZgK Copy to Clipboard
YARA Matches (1)
»
Rule Name Rule Description Classification Score Actions
DharmaEncryptedFile File encrypted by Dharma Ransomware Ransomware
5/5
C:\588bce7c90097ed212\Graphics\Print.ico.id-B4197730.[admin@stex777.com].money Dropped File Stream
Malicious
»
Mime Type application/octet-stream
File Size 1.35 KB
MD5 ccbfeff48cfe2fea0ceb6b8670ecaa52 Copy to Clipboard
SHA1 828adfdeda7b80b24c84f0a862b7cffb10e234c6 Copy to Clipboard
SHA256 2b3487d5804e2e7237521e89411d1455dd6531cc8b533e6e027998416cae543e Copy to Clipboard
SSDeep 24:YS82lGHDT/M7jEtB8qLeECQ23NzIsd0Na4wr99zKHf114JIV3r:fAjT/kj3QExIsTLrXmHf/Br Copy to Clipboard
YARA Matches (1)
»
Rule Name Rule Description Classification Score Actions
DharmaEncryptedFile File encrypted by Dharma Ransomware Ransomware
5/5
C:\588bce7c90097ed212\Graphics\Rotate1.ico.id-B4197730.[admin@stex777.com].money Dropped File Stream
Malicious
»
Mime Type application/octet-stream
File Size 1.10 KB
MD5 f0a3cd7a3b0f495f503b92ae88349510 Copy to Clipboard
SHA1 b46743df5b063cbfe522dfca93d49fb1f12e93c6 Copy to Clipboard
SHA256 aad1b8ce4fc144ba3cadbe20cf1972e4d3c1fff7f14ca05de38effab730147a8 Copy to Clipboard
SSDeep 24:0DLe0OOHrtsI/xJc3rN61D7wIj6OJID11VJIV3v:OXHrtl/Tc3r85VRJi/wv Copy to Clipboard
YARA Matches (1)
»
Rule Name Rule Description Classification Score Actions
DharmaEncryptedFile File encrypted by Dharma Ransomware Ransomware
5/5
C:\588bce7c90097ed212\Graphics\Rotate2.ico.id-B4197730.[admin@stex777.com].money Dropped File Stream
Malicious
»
Mime Type application/octet-stream
File Size 1.10 KB
MD5 a267f667cbe0bf9490ddb3a04ba1ceee Copy to Clipboard
SHA1 58d0343037b3082f1d3fb6d720a2861560695887 Copy to Clipboard
SHA256 75846a2289771018c6618b210473be2d80ceb8824d0087804364faeddded37bc Copy to Clipboard
SSDeep 24:SHpMYneHr8g+lm6l7n5RLfNdZzDHYDblsUn4vjKtb11vieJIV3v:SHpdeLB+l97nPLlvzDH4KU3tb/Iv Copy to Clipboard
YARA Matches (1)
»
Rule Name Rule Description Classification Score Actions
DharmaEncryptedFile File encrypted by Dharma Ransomware Ransomware
5/5
C:\588bce7c90097ed212\1044\SetupResources.dll.id-B4197730.[admin@stex777.com].money Dropped File Stream
Malicious
»
Mime Type application/octet-stream
File Size 17.59 KB
MD5 140d2c2fdd54862ad84eb6593ecbcedf Copy to Clipboard
SHA1 d54b6f0c049d573dc0cb2f90f1f3abe1f9caed16 Copy to Clipboard
SHA256 37294c8aa72b285ed0152d7c4c9b3b0b32179abbcaf9e0ad4b281c831fd0693f Copy to Clipboard
SSDeep 384:XVLb34P2TqAkyAtLSW6+/rXUxbPjW5/ObBWBDFcOO9ZGExa0Qnc:FLM8qAJGH6UkxvZlWZaDUea0F Copy to Clipboard
YARA Matches (1)
»
Rule Name Rule Description Classification Score Actions
DharmaEncryptedFile File encrypted by Dharma Ransomware Ransomware
5/5
C:\588bce7c90097ed212\Graphics\Rotate3.ico.id-B4197730.[admin@stex777.com].money Dropped File Stream
Malicious
»
Mime Type application/octet-stream
File Size 1.10 KB
MD5 831734fab1903c48d5b06a003df525f5 Copy to Clipboard
SHA1 bdfc80062c17a9b52acdb6f055941b173405adff Copy to Clipboard
SHA256 9bba59615e19fbe700b959dfd96a6a48b1be06a4de064be23df572ee042bded1 Copy to Clipboard
SSDeep 24:kXWh26j3UmQwSV/j1DNsk4BXQgF445b9A119JIV3v:Dh26jPjS/j9NGBXQ34d9A/Yv Copy to Clipboard
YARA Matches (1)
»
Rule Name Rule Description Classification Score Actions
DharmaEncryptedFile File encrypted by Dharma Ransomware Ransomware
5/5
C:\588bce7c90097ed212\1055\SetupResources.dll.id-B4197730.[admin@stex777.com].money Dropped File Stream
Malicious
»
Mime Type application/octet-stream
File Size 17.59 KB
MD5 d1720d15345a7079cfd1c9d95925e55f Copy to Clipboard
SHA1 818368a5a2a873eaa9a8672caeb41e80bca4c2f5 Copy to Clipboard
SHA256 1eff150d8fc1711ccda4e2a101434cfc791d0ac603aaf01d0be0d108d2dd65db Copy to Clipboard
SSDeep 384:47EnQgXv13R/mNrlhf8AjtCPW0I9aoPONSW+rK2N5ESpV2Ms8Uon7:pQgfNJmNrl5tCPOENW3Hs/u Copy to Clipboard
YARA Matches (1)
»
Rule Name Rule Description Classification Score Actions
DharmaEncryptedFile File encrypted by Dharma Ransomware Ransomware
5/5
C:\588bce7c90097ed212\Graphics\Rotate5.ico.id-B4197730.[admin@stex777.com].money Dropped File Stream
Malicious
»
Mime Type application/octet-stream
File Size 1.10 KB
MD5 69c1e3a810c69eea92b0a5326f0a18ed Copy to Clipboard
SHA1 e622ef9f3cc62d4aad3fed10e1ea724796ce412a Copy to Clipboard
SHA256 a870313e837409ce43a9a346e840d10dd8d4c26371fc6374f2f3f82c744fcded Copy to Clipboard
SSDeep 24:uNMK+prlJFihcCnaQG1owdle6362TKDthygWhc11ZJIV3v:uNtQCh9vSRei6ftIgL/kv Copy to Clipboard
YARA Matches (1)
»
Rule Name Rule Description Classification Score Actions
DharmaEncryptedFile File encrypted by Dharma Ransomware Ransomware
5/5
C:\588bce7c90097ed212\Graphics\Rotate6.ico.id-B4197730.[admin@stex777.com].money Dropped File Stream
Malicious
»
Mime Type application/octet-stream
File Size 1.10 KB
MD5 a6bddc2bbfefa8adf94a753d4f705e4f Copy to Clipboard
SHA1 ddf8596b7355d9d1bba4e59852b6508f59d97116 Copy to Clipboard
SHA256 ae1f8b14a5bc21d64f9db186740844a7a6ea5113c8eadcbddc2df88d1b8f810f Copy to Clipboard
SSDeep 24:3Sbfq10ej9oa5FnItN6naFRhvzYcCtat4MEgIe+GQgeo117JIV3v:Xfoa5FnIR8cCt+TeGQi/Cv Copy to Clipboard
YARA Matches (1)
»
Rule Name Rule Description Classification Score Actions
DharmaEncryptedFile File encrypted by Dharma Ransomware Ransomware
5/5
C:\588bce7c90097ed212\Graphics\Rotate7.ico.id-B4197730.[admin@stex777.com].money Dropped File Stream
Malicious
»
Mime Type application/octet-stream
File Size 1.10 KB
MD5 fca2696f50bd6c5a55b74f0e51eab0e3 Copy to Clipboard
SHA1 d10589fed0d99e907f5e1b33ad63ba4167aa6816 Copy to Clipboard
SHA256 68336fe3596ef1aa64ad75eadfe27157815a99dcb9d1ff7bd4336db07990b456 Copy to Clipboard
SSDeep 24:/dq2O5UC7YyKd26eIWr2u4SO28jAFq4fR7N11ZJIV3v:C0yvJYyH/kv Copy to Clipboard
YARA Matches (1)
»
Rule Name Rule Description Classification Score Actions
DharmaEncryptedFile File encrypted by Dharma Ransomware Ransomware
5/5
C:\588bce7c90097ed212\SetupUi.xsd.id-B4197730.[admin@stex777.com].money Dropped File Stream
Malicious
»
Mime Type application/octet-stream
File Size 29.65 KB
MD5 ec1ea6e9a5ed7b7454438707d34396f4 Copy to Clipboard
SHA1 68b87753e2d0a07d0360021b64528aea54c5c39d Copy to Clipboard
SHA256 939c33fccb93c4c8ddfd48e90f2b6aec10ec02970a14cdff39b58f5ff25d7b4c Copy to Clipboard
SSDeep 768:aTCeGoJNiqhejV8xGyUs06CB+NMN7w5DkrHPodq53vY:aT8eNiqIDs06CaMRgDkrHAdu3vY Copy to Clipboard
YARA Matches (1)
»
Rule Name Rule Description Classification Score Actions
DharmaEncryptedFile File encrypted by Dharma Ransomware Ransomware
5/5
C:\588bce7c90097ed212\UiInfo.xml.id-B4197730.[admin@stex777.com].money Dropped File Stream
Malicious
»
Mime Type application/octet-stream
File Size 38.23 KB
MD5 44d8d8596813667c4c0543fa8c242285 Copy to Clipboard
SHA1 2f57f2bd0147aab08b69ad7211ba310323655904 Copy to Clipboard
SHA256 5c903ea76b93710b4967142ab16638921de4662f8dc4305caffb82c99661ff1b Copy to Clipboard
SSDeep 768:RivRsTFpy7FJnUbPJ4qd+SfGn38sn+JvNKtt0A84/jVn18+hMOq6RU:0vOry3UoSf4383J1C84Ll1pVq6RU Copy to Clipboard
YARA Matches (1)
»
Rule Name Rule Description Classification Score Actions
DharmaEncryptedFile File encrypted by Dharma Ransomware Ransomware
5/5
C:\Program Files\Common Files\microsoft shared\Stationery\Desktop.ini.id-B4197730.[admin@stex777.com].money Dropped File Stream
Malicious
»
Mime Type application/octet-stream
File Size 890 bytes
MD5 af598e23d08d080f5441ef676c2d289a Copy to Clipboard
SHA1 84399f31079ac59adaeeb8f55e793be79ff9fc1b Copy to Clipboard
SHA256 b2441b3f894905c410c46296d7681b3a3cfa1a91f0d9a28a96e06fffb7bb5977 Copy to Clipboard
SSDeep 24:lHK0FFKPIb/zl1yzZqije11Ur8yMe+TJ4:PsQOZqi6/Ur8WSS Copy to Clipboard
YARA Matches (1)
»
Rule Name Rule Description Classification Score Actions
DharmaEncryptedFile File encrypted by Dharma Ransomware Ransomware
5/5
C:\Program Files\desktop.ini.id-B4197730.[admin@stex777.com].money Dropped File Stream
Malicious
»
Mime Type application/octet-stream
File Size 410 bytes
MD5 b1a869a4acba40f2735ed8530f8788b4 Copy to Clipboard
SHA1 2ad856408ba6de36e5c54223b4f025d9f9d5e775 Copy to Clipboard
SHA256 4d9826fb47d961767b2bb4ed17845b152d78627f79d82c94548f63acd08065c8 Copy to Clipboard
SSDeep 12:ASG8No3UfqiOhI1u11ePKhJSnMeDI3TJx+:A6jQhIk11lyMe+TJ4 Copy to Clipboard
YARA Matches (1)
»
Rule Name Rule Description Classification Score Actions
DharmaEncryptedFile File encrypted by Dharma Ransomware Ransomware
5/5
C:\588bce7c90097ed212\DisplayIcon.ico.id-B4197730.[admin@stex777.com].money Dropped File Stream
Malicious
»
Mime Type application/octet-stream
File Size 86.71 KB
MD5 fa68da1874f5e79bb5ef32ee1aa03536 Copy to Clipboard
SHA1 ebf585f8574db7deff08b0249bfce48835e82087 Copy to Clipboard
SHA256 0e07620d0e5bf361f3d162133e451af3e6766b9ed846bcd92e5579642fac3937 Copy to Clipboard
SSDeep 1536:+vkBk6VoUWxS7eXUOt191mZ1w4QjCWu2Gl6PoZGqOxjjesTAj6z8YUO9:GkBV2Eg0ZxwCSarOBeseYUO9 Copy to Clipboard
YARA Matches (1)
»
Rule Name Rule Description Classification Score Actions
DharmaEncryptedFile File encrypted by Dharma Ransomware Ransomware
5/5
C:\588bce7c90097ed212\Graphics\Save.ico.id-B4197730.[admin@stex777.com].money Dropped File Stream
Malicious
»
Mime Type application/octet-stream
File Size 1.35 KB
MD5 612515087eab007125d7855176e4b068 Copy to Clipboard
SHA1 0f4860e459dfe5e5f54ef88f61ce3e1cb219ad4b Copy to Clipboard
SHA256 fa1755d7b50296c10de30a19dde8c52a59fb3576d427036e58c4d4c319563baa Copy to Clipboard
SSDeep 24:BmK7RfMpDM+/PK1D66uAZVLsfr3iOLG2XfaTiRmZgGmmy911mt/eJIV3t:oARfMRM+/PuD6yKiOLGkfugjmy9/m1Dt Copy to Clipboard
YARA Matches (1)
»
Rule Name Rule Description Classification Score Actions
DharmaEncryptedFile File encrypted by Dharma Ransomware Ransomware
5/5
C:\588bce7c90097ed212\Graphics\Setup.ico.id-B4197730.[admin@stex777.com].money Dropped File Stream
Malicious
»
Mime Type application/octet-stream
File Size 36.08 KB
MD5 14f70c560768ba1782add1fcf87fc5e2 Copy to Clipboard
SHA1 f8fd07db5d9b74fdd621675168de16a089d2cd3d Copy to Clipboard
SHA256 ff92f2050e3b957eb19acf56a779eb178b99b2d727374d03dab656259b1a0c5c Copy to Clipboard
SSDeep 768:FXSc/NZqFi4tY4NCjmC6130ln0lLCl+Qt5eiTKmFgO0VwyRq31:FXSyZpSNCjmt33YFt5UCgFzqF Copy to Clipboard
YARA Matches (1)
»
Rule Name Rule Description Classification Score Actions
DharmaEncryptedFile File encrypted by Dharma Ransomware Ransomware
5/5
C:\588bce7c90097ed212\Graphics\Rotate8.ico.id-B4197730.[admin@stex777.com].money Dropped File Stream
Malicious
»
Mime Type application/octet-stream
File Size 1.10 KB
MD5 11f8e833ef5a91b792cde41ddc132f3b Copy to Clipboard
SHA1 5ff8758b10ab26cef80953e92f402bd779020e11 Copy to Clipboard
SHA256 5116d5080bca1c2df1b46c39cb6b8efed928960dfefb8e967002131de556e1ad Copy to Clipboard
SSDeep 24:ra5aj1w5FxOovcl0AZJjPy/+FghHpPK6klxQJsy4yA611svJIV3v:u5apw5DzCe/+wKxQJst6/Jv Copy to Clipboard
YARA Matches (1)
»
Rule Name Rule Description Classification Score Actions
DharmaEncryptedFile File encrypted by Dharma Ransomware Ransomware
5/5
C:\588bce7c90097ed212\Graphics\stop.ico.id-B4197730.[admin@stex777.com].money Dropped File Stream
Malicious
»
Mime Type application/octet-stream
File Size 10.13 KB
MD5 8b1b8ab146996799bd3f886e4551f47e Copy to Clipboard
SHA1 6911cec026d0e7c0a63b2c68b8cc2318388d1ab2 Copy to Clipboard
SHA256 56825b809ceef78a420c7092af29b0fd1c22e1bf85e8a3975d0d600124adc6c2 Copy to Clipboard
SSDeep 192:SuUGB5w1xipVme4mGVUwbrmGgNzgIG2hushPHz+GdMRMUSaZC1t:HBWHiwrH5piuVHMLaM/ Copy to Clipboard
YARA Matches (1)
»
Rule Name Rule Description Classification Score Actions
DharmaEncryptedFile File encrypted by Dharma Ransomware Ransomware
5/5
C:\588bce7c90097ed212\Graphics\SysReqMet.ico.id-B4197730.[admin@stex777.com].money Dropped File Stream
Malicious
»
Mime Type application/octet-stream
File Size 1.36 KB
MD5 2bee75bd4c5c162ac7914be57e3e02d5 Copy to Clipboard
SHA1 8a5520e5ad8e83e196a01327431aab0ed15d253b Copy to Clipboard
SHA256 7925a30fc3156da4653429451669840565129813ce3436b65095d3179751ff26 Copy to Clipboard
SSDeep 24:mzmprh3SXCQO+mzZ0esBbemkuAPmzbD7vkTcRmM111JIV3D:5thk1O+mzeew5TkTcMM/QD Copy to Clipboard
YARA Matches (1)
»
Rule Name Rule Description Classification Score Actions
DharmaEncryptedFile File encrypted by Dharma Ransomware Ransomware
5/5
C:\588bce7c90097ed212\Graphics\warn.ico.id-B4197730.[admin@stex777.com].money Dropped File Stream
Malicious
»
Mime Type application/octet-stream
File Size 10.13 KB
MD5 0ebfef837f9ca9efcfe24ce9d4603f12 Copy to Clipboard
SHA1 336a02920145d909b378ec1d90e5a9f7a455c812 Copy to Clipboard
SHA256 3fb5c151a3f7d4397b3d52a13db948c67573494450cadefb1093171f8b95edac Copy to Clipboard
SSDeep 192:tLSECrBoT2r5B9JR0zJpvIN8FqYSqvePThFFXxBtwzEW+0gBFNRWA//SCymUppt:UECCT45NRKYcve3xxjC694AX6D Copy to Clipboard
YARA Matches (1)
»
Rule Name Rule Description Classification Score Actions
DharmaEncryptedFile File encrypted by Dharma Ransomware Ransomware
5/5
C:\588bce7c90097ed212\Graphics\Rotate4.ico.id-B4197730.[admin@stex777.com].money Dropped File Stream
Malicious
»
Mime Type application/octet-stream
File Size 1.10 KB
MD5 a1d28fb1bc0c211dbabaaddcb369d1b1 Copy to Clipboard
SHA1 2bebfcd55aee1faa261d2feba0ba66ca75bfe0a6 Copy to Clipboard
SHA256 ea165603cd0a69de8d4c7e7ba891e8f248897d4a87867833d224a0496da4ff2b Copy to Clipboard
SSDeep 24:y3piXGlr+IP16H8ncIkT/q3MQ0vBm5JsZoU28rXHtd116SJIV3v:yZxQ8ijBm5JsZl2AXNd/Ov Copy to Clipboard
YARA Matches (1)
»
Rule Name Rule Description Classification Score Actions
DharmaEncryptedFile File encrypted by Dharma Ransomware Ransomware
5/5
C:\Program Files\Java\jre1.8.0_144\bin\server\Xusage.txt.id-B4197730.[admin@stex777.com].money Dropped File Stream
Malicious
»
Mime Type application/octet-stream
File Size 1.62 KB
MD5 023b5872032ded3eb00f94f5019d54ac Copy to Clipboard
SHA1 a02c9f529783b1664336427f927eb7662e5d2723 Copy to Clipboard
SHA256 6659d9ef4927c8e25988fb62ddbda337099c67982f7ee6aa3b5874fbe1a5c21b Copy to Clipboard
SSDeep 48:f8DcgyxUHzupPglCpbYTF2IAv0GAYOlIJD/x9WSo:EDcg6UTowq8tYOe5nWN Copy to Clipboard
YARA Matches (1)
»
Rule Name Rule Description Classification Score Actions
DharmaEncryptedFile File encrypted by Dharma Ransomware Ransomware
5/5
C:\Program Files\Java\jre1.8.0_144\lib\deploy\ffjcext.zip.id-B4197730.[admin@stex777.com].money Dropped File Stream
Malicious
»
Mime Type application/octet-stream
File Size 14.06 KB
MD5 ca23ee81741962d6114ef72f565a4aa7 Copy to Clipboard
SHA1 26b3d44cb3ae05e8bfa7b698803c317c966c957a Copy to Clipboard
SHA256 1fb07920a429c60b3a1939c583f5364101dcf33868da42766a75dc698ce403d7 Copy to Clipboard
SSDeep 384:poks8uPlqQrnyo/7AiaytiNgrxNgLyNc6N2YBQF1ZudzC+Da5j:pokpuNPX/7AdywYxNgL+lN2FF1EdzC+o Copy to Clipboard
YARA Matches (1)
»
Rule Name Rule Description Classification Score Actions
DharmaEncryptedFile File encrypted by Dharma Ransomware Ransomware
5/5
C:\Program Files\Java\jre1.8.0_144\lib\deploy\splash@2x.gif.id-B4197730.[admin@stex777.com].money Dropped File Stream
Malicious
»
Mime Type application/octet-stream
File Size 15.15 KB
MD5 3730c4885e52c60295900612a5633d22 Copy to Clipboard
SHA1 08ebf31c85237f7fef1454f054b84ca056b8d605 Copy to Clipboard
SHA256 d171a34e2066f753d367fc256ed4a301c18e731e8cfb422c7ba5bb37a19979c1 Copy to Clipboard
SSDeep 384:PwBu0eE+e94Aago4iV8GlyW+UCv6nY8Hf0wm78j9YSAJmTsP:I9eE+e9haUiV8GLyvWbW7y9YSamw Copy to Clipboard
YARA Matches (1)
»
Rule Name Rule Description Classification Score Actions
DharmaEncryptedFile File encrypted by Dharma Ransomware Ransomware
5/5
C:\Program Files\Java\jre1.8.0_144\lib\deploy\splash.gif.id-B4197730.[admin@stex777.com].money Dropped File Stream
Malicious
»
Mime Type application/octet-stream
File Size 8.62 KB
MD5 117b8061ad1453b2c4cad1bd2907538f Copy to Clipboard
SHA1 1d03dd0feed966281c8bdd9bcdaf7cc71025cee7 Copy to Clipboard
SHA256 eb060c2ae427ef52acfefc6874d916948a7417f04b506f9977c0a720a0b00072 Copy to Clipboard
SSDeep 192:pY26LlbIwKonOihGn13a9SKj68i9tFlsgR8o+MXp8uj2ZN:pdAUwKrWcK9S98ETlsi8oEu6ZN Copy to Clipboard
YARA Matches (1)
»
Rule Name Rule Description Classification Score Actions
DharmaEncryptedFile File encrypted by Dharma Ransomware Ransomware
5/5
C:\Program Files\Java\jre1.8.0_144\lib\deploy\splash_11@2x-lic.gif.id-B4197730.[admin@stex777.com].money Dropped File Stream
Malicious
»
Mime Type application/octet-stream
File Size 12.21 KB
MD5 75c9061f273e1736040124da22e53adf Copy to Clipboard
SHA1 fb0a647edb5d34d7c4805d2a674ce306166be389 Copy to Clipboard
SHA256 8834d47209f286f1e7931c4ec2bff55e83d81b86a296ee4a45d6e7f5f8993a26 Copy to Clipboard
SSDeep 384:iGhN5QD+gz/UnkG8wotp9WGnIUAcqJrHeUJ:zr5QvbwotTNIWILb Copy to Clipboard
YARA Matches (1)
»
Rule Name Rule Description Classification Score Actions
DharmaEncryptedFile File encrypted by Dharma Ransomware Ransomware
5/5
C:\588bce7c90097ed212\Graphics\SysReqNotMet.ico.id-B4197730.[admin@stex777.com].money Dropped File Stream
Malicious
»
Mime Type application/octet-stream
File Size 1.36 KB
MD5 7f95b4597b6af7f3d1a050bacd7ab365 Copy to Clipboard
SHA1 44a42927a20fc0cbe99f209c2b02c6cea4138ef0 Copy to Clipboard
SHA256 c93a070d1fa4bd672d2b506eff082151d8f4332db4eb3ab72f1db429a5f00d9d Copy to Clipboard
SSDeep 24:GN2RIbYafpURYvk0d/yVAB/0+HmJLcNaI7lXfx67df51C4Gt1cPUSF9PF3m11tJQ:S2GxfpU6VyuXHnNR7Rfx67dfnGt1cPdH Copy to Clipboard
YARA Matches (1)
»
Rule Name Rule Description Classification Score Actions
DharmaEncryptedFile File encrypted by Dharma Ransomware Ransomware
5/5
C:\Program Files\Java\jre1.8.0_144\lib\deploy\splash_11-lic.gif.id-B4197730.[admin@stex777.com].money Dropped File Stream
Malicious
»
Mime Type application/octet-stream
File Size 7.87 KB
MD5 d80139780b592d83f521be8c1da6456f Copy to Clipboard
SHA1 361346c24c949dfe464e83f777a4792dfbd44ea2 Copy to Clipboard
SHA256 dd4b473a149f44132fce73b5c7e163039867bd00eff8f42727821d0927f8fb23 Copy to Clipboard
SSDeep 192:nRh2LoKXey9H/B1LT5+fczFnBM+zu/2jExFEXScJBFDm+UoH:bnIey9fXLFfFnBra/oEL8SWrm3oH Copy to Clipboard
YARA Matches (1)
»
Rule Name Rule Description Classification Score Actions
DharmaEncryptedFile File encrypted by Dharma Ransomware Ransomware
5/5
C:\Program Files\Java\jre1.8.0_144\lib\jvm.hprof.txt.id-B4197730.[admin@stex777.com].money Dropped File Stream
Malicious
»
Mime Type application/octet-stream
File Size 4.37 KB
MD5 75d3d24a80567cdc4663da188f7696a5 Copy to Clipboard
SHA1 5fa50888dc15606ae8d3f8b2520450b67d7dc8a5 Copy to Clipboard
SHA256 0951dd81e8d3fde910c37a16ffda11cd282bdaa3a0d77dad9368966b8b83ff08 Copy to Clipboard
SSDeep 96:+6+0ffyPA2Wz5YJTPDOMCIMOwcnSAANDlAG8fPvkIp6COWIO3aLkgqrdWP:+6/fIA2WzfIMbGSLlArvk/7saLkgqrcP Copy to Clipboard
YARA Matches (1)
»
Rule Name Rule Description Classification Score Actions
DharmaEncryptedFile File encrypted by Dharma Ransomware Ransomware
5/5
C:\588bce7c90097ed212\netfx_Core_x86.msi.id-B4197730.[admin@stex777.com].money Dropped File Stream
Malicious
»
Mime Type application/octet-stream
File Size 1.11 MB
MD5 7cfe38c44c06726023d0be26c5374495 Copy to Clipboard
SHA1 54269fb92e003409820a1b9fd950b0c93b229a81 Copy to Clipboard
SHA256 6becc94064309598e40ab50641c86b85ac80d82e3e11b58bc7a8f66a43f81aa9 Copy to Clipboard
SSDeep 24576:cFxvEkRlUOyM3Fg0Og9IY8g6uzTZHj8UqpXit/xfdau:cAkR+cm0Og9II6GljvtRn Copy to Clipboard
YARA Matches (1)
»
Rule Name Rule Description Classification Score Actions
DharmaEncryptedFile File encrypted by Dharma Ransomware Ransomware
5/5
C:\Program Files\Java\jre1.8.0_144\lib\tzdb.dat.id-B4197730.[admin@stex777.com].money Dropped File Stream
Malicious
»
Mime Type application/octet-stream
File Size 103.25 KB
MD5 a518901f76300879b5746878628d4c03 Copy to Clipboard
SHA1 a02076d8f2b1a60b60c1ee6a79437331765e0881 Copy to Clipboard
SHA256 b9e6be9d943578e6c62900dfc5f9e69b9641a086956cb368286e7253abfae3f5 Copy to Clipboard
SSDeep 3072:OzWxy+vRiD08dr9WY8m1zjznG6GmQK9KkJ1Hc:0Wxj00gxWYVtnGfH Copy to Clipboard
YARA Matches (1)
»
Rule Name Rule Description Classification Score Actions
DharmaEncryptedFile File encrypted by Dharma Ransomware Ransomware
5/5
C:\Program Files\Java\jre1.8.0_144\Welcome.html.id-B4197730.[admin@stex777.com].money Dropped File Stream
Malicious
»
Mime Type application/octet-stream
File Size 1.17 KB
MD5 62afa1e4be4ac5cdd2ea031e0e05afaf Copy to Clipboard
SHA1 bc7dda5d047aa9dd949433c5942587c46e2cfcb5 Copy to Clipboard
SHA256 a627ef21c51d35f893ac79ee08a2b40a4af021c1d93f9c13fedec843b5c6e08a Copy to Clipboard
SSDeep 24:bPnP+ESYEXlz+NDrmRj9O1KDYfY/QNuET11CyMe+TJO:rW9ms9Os4D/CWS8 Copy to Clipboard
YARA Matches (1)
»
Rule Name Rule Description Classification Score Actions
DharmaEncryptedFile File encrypted by Dharma Ransomware Ransomware
5/5
C:\Program Files\Microsoft Office\Office16\OSPP.HTM.id-B4197730.[admin@stex777.com].money Dropped File Stream
Malicious
»
Mime Type application/octet-stream
File Size 170.68 KB
MD5 b803f401c2039de35c4af452c63138e3 Copy to Clipboard
SHA1 4221905452ddc12efaebece072b1d9a8f517d739 Copy to Clipboard
SHA256 9a3a65299b6e8ae71958a960dbe5437adff3ba026167b83ceed10b74bf179e90 Copy to Clipboard
SSDeep 3072:A5EdpUzNDriHzNIfuJ5BCLELfwN79I6Qc0l7J6IQMuR+GFx:2EdAniHJIk5mEbqe6CtJuRbFx Copy to Clipboard
YARA Matches (1)
»
Rule Name Rule Description Classification Score Actions
DharmaEncryptedFile File encrypted by Dharma Ransomware Ransomware
5/5
C:\Program Files\Microsoft Office\Office16\SLERROR.XML.id-B4197730.[admin@stex777.com].money Dropped File Stream
Malicious
»
Mime Type application/octet-stream
File Size 35.73 KB
MD5 0c23e20dbf8f2c8b96d8b7f166205b0e Copy to Clipboard
SHA1 36dd5e347df2e0e11a8e05043faec436f8fe0fff Copy to Clipboard
SHA256 533f5dad396997eecd3e7b4ba0ca82895b565f3bdd345e1e2d73a394bac75966 Copy to Clipboard
SSDeep 768:aS/iU/3UBpqGYOZ3QA5Hb+Fhj1uFIMF6Ovd:7/iUvU7501uFIMvvd Copy to Clipboard
YARA Matches (1)
»
Rule Name Rule Description Classification Score Actions
DharmaEncryptedFile File encrypted by Dharma Ransomware Ransomware
5/5
C:\Program Files\Microsoft Office\Office16\OSPP.VBS.id-B4197730.[admin@stex777.com].money Dropped File Stream
Malicious
»
Mime Type application/octet-stream
File Size 92.49 KB
MD5 e19f177cae978b9c0de463aaa5bc9b20 Copy to Clipboard
SHA1 f7e9234c8df02f5d88ea1b8c3d6c84d66a2e91c9 Copy to Clipboard
SHA256 34d17b1c63be07c9f755fca9c4d653b0ca73d13d9898f38a6d4cd4b8a4f72cd3 Copy to Clipboard
SSDeep 1536:IVqVi8KnvNLtHpw/5Hmc0XYVdFMmhtJukwX4C4gvbNUDcHffaGwkI8So81gBgqXy:vVgldUGc0XEMmhtiIC4ihUQ/fap8rgqC Copy to Clipboard
YARA Matches (1)
»
Rule Name Rule Description Classification Score Actions
DharmaEncryptedFile File encrypted by Dharma Ransomware Ransomware
5/5
C:\588bce7c90097ed212\RGB9Rast_x86.msi.id-B4197730.[admin@stex777.com].money Dropped File Stream
Malicious
»
Mime Type application/octet-stream
File Size 92.75 KB
MD5 bbc1aece5b4183b330cac323320bde1d Copy to Clipboard
SHA1 3c152c4394781ef201fa935eac95b8f2a5bf7bb6 Copy to Clipboard
SHA256 af9c821dd20e61b05e6d1267754e75f647bc1023fd2dc30b85849abaa309af78 Copy to Clipboard
SSDeep 1536:cx548S02Knca8H78qzcjJnKrSNwSJz2h5NYjXBLi/KQ2ekNiJIChOV2LuEpQ7jtc:W48VnYHI7nZNwyyYjXxi/V1koOK5gc Copy to Clipboard
YARA Matches (1)
»
Rule Name Rule Description Classification Score Actions
DharmaEncryptedFile File encrypted by Dharma Ransomware Ransomware
5/5
C:\588bce7c90097ed212\Setup.exe.id-B4197730.[admin@stex777.com].money Dropped File Stream
Malicious
»
Mime Type application/octet-stream
File Size 76.55 KB
MD5 4797b88df1a8b39db9202d8f8a2b0b3e Copy to Clipboard
SHA1 62ed34290c20e844770c2e8c85bb686c4b293908 Copy to Clipboard
SHA256 f8fa9b978cb2f7653c7c9c70a113c214e4c65b271e14a9d10bbbf684c1b546f1 Copy to Clipboard
SSDeep 1536:kTeVCvGzj8BzT4FkTx2MnsiH/f8sY+oeZmpls4033VDKhxa26Ga0b2xD1taG:kTuzj8Bn4FkTx2MHH/hYJeZMm4033VKm Copy to Clipboard
YARA Matches (1)
»
Rule Name Rule Description Classification Score Actions
DharmaEncryptedFile File encrypted by Dharma Ransomware Ransomware
5/5
C:\588bce7c90097ed212\SetupEngine.dll.id-B4197730.[admin@stex777.com].money Dropped File Stream
Malicious
»
Mime Type application/octet-stream
File Size 788.58 KB
MD5 8a1f5836443af1afb47d12d3611e780f Copy to Clipboard
SHA1 9c92c64596d11bdbbf0d511c1f2a9812b41fde7e Copy to Clipboard
SHA256 62acdb4c0616a7213cc73624c0136048e7dbb4d0f20d98733ec4fd964e9023c4 Copy to Clipboard
SSDeep 24576:HwVUWPuoJGOCDdzhOsUkpHUASDBwW6AC20+yiLjUGlMv92z:HEUWKOCpzhymHuh0y3UGlMv92z Copy to Clipboard
YARA Matches (1)
»
Rule Name Rule Description Classification Score Actions
DharmaEncryptedFile File encrypted by Dharma Ransomware Ransomware
5/5
C:\588bce7c90097ed212\RGB9RAST_x64.msi.id-B4197730.[admin@stex777.com].money Dropped File Stream
Malicious
»
Mime Type application/octet-stream
File Size 180.75 KB
MD5 bff85e5f43f41fe603ea8d7fa6a45af2 Copy to Clipboard
SHA1 31047afe8d71493220d97c9508f869d64a9a3567 Copy to Clipboard
SHA256 97d10975cb8111f043c7805294e3fa1f64f4a8e11b8aea1291bbb7ceb54bb92e Copy to Clipboard
SSDeep 3072:ZChpfMiQsQS2YpM8ap38fba3OuqvXSHY2AOukJOddLIEEPiBFb5RnxZ4LeP:UvbQsQQNapsfuFlRALJEEvxGLeP Copy to Clipboard
YARA Matches (1)
»
Rule Name Rule Description Classification Score Actions
DharmaEncryptedFile File encrypted by Dharma Ransomware Ransomware
5/5
C:\588bce7c90097ed212\SetupUi.dll.id-B4197730.[admin@stex777.com].money Dropped File Stream
Malicious
»
Mime Type application/octet-stream
File Size 288.57 KB
MD5 33d84d7e1b0f62b1d1d8cc28718d3ece Copy to Clipboard
SHA1 bdb90bd34398746d9b31adfec547cc5d492b7695 Copy to Clipboard
SHA256 35de51b79033d7e1f073f1a3708df8ecb47b22de8ceb8fe91a6b55183cce5bff Copy to Clipboard
SSDeep 6144:DP7mwW0ryQTnMuXRSvmwmRO1ESXmFyUU7usgxur/GbjgKZarQdcOp/5T:OgynvmZRgRUUCIeQ+ar0cOphT Copy to Clipboard
YARA Matches (1)
»
Rule Name Rule Description Classification Score Actions
DharmaEncryptedFile File encrypted by Dharma Ransomware Ransomware
5/5
C:\588bce7c90097ed212\sqmapi.dll.id-B4197730.[admin@stex777.com].money Dropped File Stream
Malicious