15.4
0-day

58290a95e1795ec7312e4ce26bfff7e0fb7a620a3aac2627d3ae6c83f5a4bf60

35271695a6202c514fef4520d49886ea.exe

分析耗时

79s

最近分析

文件大小

678.5KB
静态报毒 动态报毒 100% AI SCORE=100 AIDETECTVM BIGY CLASSIC CONFIDENCE DELSHAD DELSHADRI DOWNLOADER33 FILECODER GDSDA GENCIRC GENERICRXKP HIGH CONFIDENCE HJDOJW HUPIGON MALWARE1 MALWARE@#VTW91CTW0AHU MEDUSA MEDUSALOCKER QUW@AK8T6ILI R335910 RANSOMX S13221298 SCORE SMTH SUSGEN SUSPICIOUS PE UNSAFE XRYTT ZEXAF 更多
鹰眼引擎
未检测 暂无鹰眼引擎检测结果
静态判定
反病毒引擎
查杀引擎 查杀结果 查杀时间 查杀版本
McAfee GenericRXKP-XE!35271695A620 20200903 6.0.6.653
Alibaba Trojan:Win32/DelShad.81ad6470 20190527 0.3.0.5
Baidu 20190318 1.0.0.2
Avast Win32:RansomX-gen [Ransom] 20200903 18.4.3895.0
Tencent Malware.Win32.Gencirc.10cdcb68 20200903 1.0.0.1
Kingsoft 20200903 2013.8.14.323
CrowdStrike win/malicious_confidence_100% (W) 20190702 1.0
静态指标
Queries for the computername (16 个事件)
Time & API Arguments Status Return Repeated
1619345036.16311
GetComputerNameW
computer_name: OSKAR-PC
success 1 0
1619371444.060374
GetComputerNameA
computer_name: OSKAR-PC
success 1 0
1619371444.060374
GetComputerNameW
computer_name: OSKAR-PC
success 1 0
1619371446.248626
GetComputerNameW
computer_name: OSKAR-PC
success 1 0
1619371446.857626
GetComputerNameW
computer_name: OSKAR-PC
success 1 0
1619371446.873626
GetComputerNameW
computer_name: OSKAR-PC
success 1 0
1619371450.249124
GetComputerNameA
computer_name: OSKAR-PC
success 1 0
1619371450.249124
GetComputerNameW
computer_name: OSKAR-PC
success 1 0
1619371452.013626
GetComputerNameW
computer_name: OSKAR-PC
success 1 0
1619371452.123626
GetComputerNameW
computer_name: OSKAR-PC
success 1 0
1619371452.138626
GetComputerNameW
computer_name: OSKAR-PC
success 1 0
1619371454.311001
GetComputerNameA
computer_name: OSKAR-PC
success 1 0
1619371454.311001
GetComputerNameW
computer_name: OSKAR-PC
success 1 0
1619371455.842124
GetComputerNameW
computer_name: OSKAR-PC
success 1 0
1619371455.936124
GetComputerNameW
computer_name: OSKAR-PC
success 1 0
1619371455.952124
GetComputerNameW
computer_name: OSKAR-PC
success 1 0
Checks if process is being debugged by a debugger (3 个事件)
Time & API Arguments Status Return Repeated
1619371446.810626
IsDebuggerPresent
failed 0 0
1619371452.107626
IsDebuggerPresent
failed 0 0
1619371455.905124
IsDebuggerPresent
failed 0 0
Command line console output was observed (9 个事件)
Time & API Arguments Status Return Repeated
1619371443.826374
WriteConsoleW
buffer: vssadmin 1.1 - 卷影复制服务管理命令行工具 (C) 版权所有 2001-2005 Microsoft Corp.
console_handle: 0x00000007
success 1 0
1619371444.060374
WriteConsoleW
buffer: 错误: 意外故障: 没有注册类
console_handle: 0x00000007
success 1 0
1619371446.920626
WriteConsoleA
buffer: Unexpected switch at this level.
console_handle: 0x0000000b
success 1 0
1619371450.202124
WriteConsoleW
buffer: vssadmin 1.1 - 卷影复制服务管理命令行工具 (C) 版权所有 2001-2005 Microsoft Corp.
console_handle: 0x00000007
success 1 0
1619371450.249124
WriteConsoleW
buffer: 错误: 意外故障: 没有注册类
console_handle: 0x00000007
success 1 0
1619371452.154626
WriteConsoleA
buffer: Unexpected switch at this level.
console_handle: 0x0000000b
success 1 0
1619371454.233001
WriteConsoleW
buffer: vssadmin 1.1 - 卷影复制服务管理命令行工具 (C) 版权所有 2001-2005 Microsoft Corp.
console_handle: 0x00000007
success 1 0
1619371454.311001
WriteConsoleW
buffer: 错误: 意外故障: 没有注册类
console_handle: 0x00000007
success 1 0
1619371455.967124
WriteConsoleA
buffer: Unexpected switch at this level.
console_handle: 0x0000000b
success 1 0
Uses Windows APIs to generate a cryptographic key (50 out of 227 个事件)
Time & API Arguments Status Return Repeated
1619345036.10111
CryptGenKey
crypto_handle: 0x00462850
algorithm_identifier: 0x00006610 ()
provider_handle: 0x00460b88
flags: 1
key: f Ž4•}L¬¾Eä@ÏxeWŠ}ײc¡‚õã×±·¡p
success 1 0
1619345036.10111
CryptExportKey
crypto_handle: 0x00462850
crypto_export_handle: 0x00000000
buffer: <INVALID POINTER>
blob_type: 8
flags: 0
success 1 0
1619345036.10111
CryptExportKey
crypto_handle: 0x00462850
crypto_export_handle: 0x00000000
buffer: f Ž4•}L¬¾Eä@ÏxeWŠ}ײc¡‚õã×±·¡p
blob_type: 8
flags: 0
success 1 0
1619345054.50711
CryptExportKey
crypto_handle: 0x00463650
crypto_export_handle: 0x00000000
buffer: <INVALID POINTER>
blob_type: 8
flags: 0
success 1 0
1619345054.69411
CryptExportKey
crypto_handle: 0x004630d0
crypto_export_handle: 0x00000000
buffer: <INVALID POINTER>
blob_type: 8
flags: 0
success 1 0
1619345054.85111
CryptExportKey
crypto_handle: 0x00463110
crypto_export_handle: 0x00000000
buffer: <INVALID POINTER>
blob_type: 8
flags: 0
success 1 0
1619345059.31911
CryptExportKey
crypto_handle: 0x03330460
crypto_export_handle: 0x00000000
buffer: <INVALID POINTER>
blob_type: 8
flags: 0
success 1 0
1619345059.64711
CryptExportKey
crypto_handle: 0x03330520
crypto_export_handle: 0x00000000
buffer: <INVALID POINTER>
blob_type: 8
flags: 0
success 1 0
1619345061.83511
CryptExportKey
crypto_handle: 0x031a1128
crypto_export_handle: 0x00000000
buffer: <INVALID POINTER>
blob_type: 8
flags: 0
success 1 0
1619345062.74111
CryptExportKey
crypto_handle: 0x031a1168
crypto_export_handle: 0x00000000
buffer: <INVALID POINTER>
blob_type: 8
flags: 0
success 1 0
1619345062.88211
CryptExportKey
crypto_handle: 0x031a10e8
crypto_export_handle: 0x00000000
buffer: <INVALID POINTER>
blob_type: 8
flags: 0
success 1 0
1619345063.39711
CryptExportKey
crypto_handle: 0x031a10a8
crypto_export_handle: 0x00000000
buffer: <INVALID POINTER>
blob_type: 8
flags: 0
success 1 0
1619345063.72611
CryptExportKey
crypto_handle: 0x031a10a8
crypto_export_handle: 0x00000000
buffer: <INVALID POINTER>
blob_type: 8
flags: 0
success 1 0
1619345063.91311
CryptExportKey
crypto_handle: 0x031a11a8
crypto_export_handle: 0x00000000
buffer: <INVALID POINTER>
blob_type: 8
flags: 0
success 1 0
1619345064.25711
CryptExportKey
crypto_handle: 0x031a10e8
crypto_export_handle: 0x00000000
buffer: <INVALID POINTER>
blob_type: 8
flags: 0
success 1 0
1619345064.39711
CryptExportKey
crypto_handle: 0x031a1168
crypto_export_handle: 0x00000000
buffer: <INVALID POINTER>
blob_type: 8
flags: 0
success 1 0
1619345064.74111
CryptExportKey
crypto_handle: 0x031a1168
crypto_export_handle: 0x00000000
buffer: <INVALID POINTER>
blob_type: 8
flags: 0
success 1 0
1619345065.03811
CryptExportKey
crypto_handle: 0x031a11a8
crypto_export_handle: 0x00000000
buffer: <INVALID POINTER>
blob_type: 8
flags: 0
success 1 0
1619345065.17911
CryptExportKey
crypto_handle: 0x031a10a8
crypto_export_handle: 0x00000000
buffer: <INVALID POINTER>
blob_type: 8
flags: 0
success 1 0
1619345066.88211
CryptExportKey
crypto_handle: 0x031a11a8
crypto_export_handle: 0x00000000
buffer: <INVALID POINTER>
blob_type: 8
flags: 0
success 1 0
1619345067.03811
CryptExportKey
crypto_handle: 0x031a10a8
crypto_export_handle: 0x00000000
buffer: <INVALID POINTER>
blob_type: 8
flags: 0
success 1 0
1619345067.19411
CryptExportKey
crypto_handle: 0x031a1168
crypto_export_handle: 0x00000000
buffer: <INVALID POINTER>
blob_type: 8
flags: 0
success 1 0
1619345067.33511
CryptExportKey
crypto_handle: 0x031a10a8
crypto_export_handle: 0x00000000
buffer: <INVALID POINTER>
blob_type: 8
flags: 0
success 1 0
1619345067.50711
CryptExportKey
crypto_handle: 0x031a11a8
crypto_export_handle: 0x00000000
buffer: <INVALID POINTER>
blob_type: 8
flags: 0
success 1 0
1619345067.64711
CryptExportKey
crypto_handle: 0x031a10a8
crypto_export_handle: 0x00000000
buffer: <INVALID POINTER>
blob_type: 8
flags: 0
success 1 0
1619345067.78811
CryptExportKey
crypto_handle: 0x031a11a8
crypto_export_handle: 0x00000000
buffer: <INVALID POINTER>
blob_type: 8
flags: 0
success 1 0
1619345067.92911
CryptExportKey
crypto_handle: 0x031a10a8
crypto_export_handle: 0x00000000
buffer: <INVALID POINTER>
blob_type: 8
flags: 0
success 1 0
1619345068.06911
CryptExportKey
crypto_handle: 0x031a11a8
crypto_export_handle: 0x00000000
buffer: <INVALID POINTER>
blob_type: 8
flags: 0
success 1 0
1619345068.16311
CryptExportKey
crypto_handle: 0x031a10a8
crypto_export_handle: 0x00000000
buffer: <INVALID POINTER>
blob_type: 8
flags: 0
success 1 0
1619345068.27211
CryptExportKey
crypto_handle: 0x031a11a8
crypto_export_handle: 0x00000000
buffer: <INVALID POINTER>
blob_type: 8
flags: 0
success 1 0
1619345068.42911
CryptExportKey
crypto_handle: 0x031a1168
crypto_export_handle: 0x00000000
buffer: <INVALID POINTER>
blob_type: 8
flags: 0
success 1 0
1619345068.58511
CryptExportKey
crypto_handle: 0x031a10e8
crypto_export_handle: 0x00000000
buffer: <INVALID POINTER>
blob_type: 8
flags: 0
success 1 0
1619345068.77211
CryptExportKey
crypto_handle: 0x031a1168
crypto_export_handle: 0x00000000
buffer: <INVALID POINTER>
blob_type: 8
flags: 0
success 1 0
1619345068.92911
CryptExportKey
crypto_handle: 0x031a11a8
crypto_export_handle: 0x00000000
buffer: <INVALID POINTER>
blob_type: 8
flags: 0
success 1 0
1619345069.11611
CryptExportKey
crypto_handle: 0x031a10a8
crypto_export_handle: 0x00000000
buffer: <INVALID POINTER>
blob_type: 8
flags: 0
success 1 0
1619345069.22611
CryptExportKey
crypto_handle: 0x031a11a8
crypto_export_handle: 0x00000000
buffer: <INVALID POINTER>
blob_type: 8
flags: 0
success 1 0
1619345069.31911
CryptExportKey
crypto_handle: 0x031a10a8
crypto_export_handle: 0x00000000
buffer: <INVALID POINTER>
blob_type: 8
flags: 0
success 1 0
1619345069.41311
CryptExportKey
crypto_handle: 0x031a11a8
crypto_export_handle: 0x00000000
buffer: <INVALID POINTER>
blob_type: 8
flags: 0
success 1 0
1619345069.49111
CryptExportKey
crypto_handle: 0x031a10a8
crypto_export_handle: 0x00000000
buffer: <INVALID POINTER>
blob_type: 8
flags: 0
success 1 0
1619345069.58511
CryptExportKey
crypto_handle: 0x031a11a8
crypto_export_handle: 0x00000000
buffer: <INVALID POINTER>
blob_type: 8
flags: 0
success 1 0
1619345069.69411
CryptExportKey
crypto_handle: 0x031a10a8
crypto_export_handle: 0x00000000
buffer: <INVALID POINTER>
blob_type: 8
flags: 0
success 1 0
1619345069.81911
CryptExportKey
crypto_handle: 0x031a1168
crypto_export_handle: 0x00000000
buffer: <INVALID POINTER>
blob_type: 8
flags: 0
success 1 0
1619345069.88211
CryptExportKey
crypto_handle: 0x031a10e8
crypto_export_handle: 0x00000000
buffer: <INVALID POINTER>
blob_type: 8
flags: 0
success 1 0
1619345069.94411
CryptExportKey
crypto_handle: 0x031a1168
crypto_export_handle: 0x00000000
buffer: <INVALID POINTER>
blob_type: 8
flags: 0
success 1 0
1619345070.06911
CryptExportKey
crypto_handle: 0x031a10a8
crypto_export_handle: 0x00000000
buffer: <INVALID POINTER>
blob_type: 8
flags: 0
success 1 0
1619345070.13211
CryptExportKey
crypto_handle: 0x031a11a8
crypto_export_handle: 0x00000000
buffer: <INVALID POINTER>
blob_type: 8
flags: 0
success 1 0
1619345070.22611
CryptExportKey
crypto_handle: 0x031a10a8
crypto_export_handle: 0x00000000
buffer: <INVALID POINTER>
blob_type: 8
flags: 0
success 1 0
1619345070.31911
CryptExportKey
crypto_handle: 0x031a11a8
crypto_export_handle: 0x00000000
buffer: <INVALID POINTER>
blob_type: 8
flags: 0
success 1 0
1619345070.47611
CryptExportKey
crypto_handle: 0x031a10a8
crypto_export_handle: 0x00000000
buffer: <INVALID POINTER>
blob_type: 8
flags: 0
success 1 0
1619345070.63211
CryptExportKey
crypto_handle: 0x031a11a8
crypto_export_handle: 0x00000000
buffer: <INVALID POINTER>
blob_type: 8
flags: 0
success 1 0
Tries to locate where the browsers are installed (1 个事件)
file C:\Program Files\Google\Chrome\Application\89.0.4389.114\libGLESv2.dll
行为判定
动态指标
One or more potentially interesting buffers were extracted, these generally contain injected code, configuration data, etc.
Queries the disk size which could be used to detect virtual machine with small fixed size or dynamic allocation (1 个事件)
Time & API Arguments Status Return Repeated
1619345052.19411
GetDiskFreeSpaceExW
root_path: Z:\
free_bytes_available: 74895360
total_number_of_free_bytes: 74895360
total_number_of_bytes: 104853504
success 1 0
Creates a shortcut to an executable file (50 out of 80 个事件)
file C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Administrative Tools\Computer Management.lnk
file C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Accessories\Wordpad.lnk
file C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Administrative Tools\iSCSI Initiator.lnk
file C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Accessories\Welcome Center.lnk
file C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Accessories\System Tools\Windows Easy Transfer.lnk
file C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Accessories\Snipping Tool.lnk
file C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Accessories\Mobility Center.lnk
file C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Windows Media Player.lnk
file C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Accessories\Sync Center.lnk
file C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Administrative Tools\Performance Monitor.lnk
file C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Python 2.7\Module Docs.lnk
file C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Administrative Tools\Event Viewer.lnk
file C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Accessories\System Tools\System Information.lnk
file C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Accessories\Sound Recorder.lnk
file C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Media Center.lnk
file C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Accessories\NetworkProjection.lnk
file C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Accessories\Accessibility\Speech Recognition.lnk
file C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Games\More Games from Microsoft.lnk
file C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Accessories\Windows PowerShell\Windows PowerShell ISE.lnk
file C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Accessories\System Tools\Task Scheduler.lnk
file C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Administrative Tools\Task Scheduler.lnk
file C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Maintenance\Backup and Restore Center.lnk
file C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Administrative Tools\System Configuration.lnk
file C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Administrative Tools\Windows Firewall with Advanced Security.lnk
file C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Sidebar.lnk
file C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Accessories\Math Input Panel.lnk
file C:\Program Files\Microsoft Games\Solitaire\SolitaireMCE.lnk
file C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Accessories\System Tools\System Restore.lnk
file C:\Program Files\Microsoft Games\SpiderSolitaire\SpiderSolitaireMCE.lnk
file C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Python 2.7\Python Manuals.lnk
file C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Games\Chess.lnk
file C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Accessories\System Tools\Resource Monitor.lnk
file C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Python 2.7\IDLE (Python GUI).lnk
file C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Games\Solitaire.lnk
file C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Games\Purble Place.lnk
file C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Accessories\Calculator.lnk
file C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Google Chrome.lnk
file C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Python 2.7\Python (command line).lnk
file C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Administrative Tools\Memory Diagnostics Tool.lnk
file C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Maintenance\Remote Assistance.lnk
file C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Accessories\System Tools\Character Map.lnk
file C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Games\GameExplorer.lnk
file C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Accessories\System Tools\Windows Easy Transfer Reports.lnk
file C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Games\Minesweeper.lnk
file C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Accessories\System Tools\Disk Cleanup.lnk
file C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Accessories\Windows PowerShell\Windows PowerShell (x86).lnk
file C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Python 2.7\Uninstall Python.lnk
file C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Windows Fax and Scan.lnk
file C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Accessories\Windows PowerShell\Windows PowerShell ISE (x86).lnk
file C:\Program Files\Microsoft Games\Hearts\HeartsMCE.lnk
Creates a suspicious process (1 个事件)
cmdline wmic.exe SHADOWCOPY /nointeractive
A process created a hidden window (18 个事件)
Time & API Arguments Status Return Repeated
1619345037.97611
CreateProcessInternalW
thread_identifier: 2060
thread_handle: 0x0000017c
process_identifier: 2452
current_directory:
filepath:
track: 1
command_line: vssadmin.exe Delete Shadows /All /Quiet
filepath_r:
stack_pivoted: 0
creation_flags: 134217728 (CREATE_NO_WINDOW)
process_handle: 0x0000016c
inherit_handles: 1
success 1 0
1619345040.11611
CreateProcessInternalW
thread_identifier: 0
thread_handle: 0x00000000
process_identifier: 0
current_directory:
filepath:
track: 0
command_line: bcdedit.exe /set {default} recoveryenabled No
filepath_r:
stack_pivoted: 0
creation_flags: 134217728 (CREATE_NO_WINDOW)
process_handle: 0x00000000
inherit_handles: 1
failed 0 0
1619345040.11611
CreateProcessInternalW
thread_identifier: 0
thread_handle: 0x00000000
process_identifier: 0
current_directory:
filepath:
track: 0
command_line: bcdedit.exe /set {default} bootstatuspolicy ignoreallfailures
filepath_r:
stack_pivoted: 0
creation_flags: 134217728 (CREATE_NO_WINDOW)
process_handle: 0x00000000
inherit_handles: 1
failed 0 0
1619345040.11611
CreateProcessInternalW
thread_identifier: 0
thread_handle: 0x00000000
process_identifier: 0
current_directory:
filepath:
track: 0
command_line: wbadmin DELETE SYSTEMSTATEBACKUP
filepath_r:
stack_pivoted: 0
creation_flags: 134217728 (CREATE_NO_WINDOW)
process_handle: 0x00000000
inherit_handles: 1
failed 0 0
1619345040.11611
CreateProcessInternalW
thread_identifier: 0
thread_handle: 0x00000000
process_identifier: 0
current_directory:
filepath:
track: 0
command_line: wbadmin DELETE SYSTEMSTATEBACKUP -deleteOldest
filepath_r:
stack_pivoted: 0
creation_flags: 134217728 (CREATE_NO_WINDOW)
process_handle: 0x00000000
inherit_handles: 1
failed 0 0
1619345040.30411
CreateProcessInternalW
thread_identifier: 428
thread_handle: 0x0000016c
process_identifier: 2900
current_directory:
filepath:
track: 1
command_line: wmic.exe SHADOWCOPY /nointeractive
filepath_r:
stack_pivoted: 0
creation_flags: 134217728 (CREATE_NO_WINDOW)
process_handle: 0x0000017c
inherit_handles: 1
success 1 0
1619345044.41311
CreateProcessInternalW
thread_identifier: 360
thread_handle: 0x0000017c
process_identifier: 2060
current_directory:
filepath:
track: 1
command_line: vssadmin.exe Delete Shadows /All /Quiet
filepath_r:
stack_pivoted: 0
creation_flags: 134217728 (CREATE_NO_WINDOW)
process_handle: 0x0000016c
inherit_handles: 1
success 1 0
1619345046.00711
CreateProcessInternalW
thread_identifier: 0
thread_handle: 0x00000000
process_identifier: 0
current_directory:
filepath:
track: 0
command_line: bcdedit.exe /set {default} recoveryenabled No
filepath_r:
stack_pivoted: 0
creation_flags: 134217728 (CREATE_NO_WINDOW)
process_handle: 0x00000000
inherit_handles: 1
failed 0 0
1619345046.00711
CreateProcessInternalW
thread_identifier: 0
thread_handle: 0x00000000
process_identifier: 0
current_directory:
filepath:
track: 0
command_line: bcdedit.exe /set {default} bootstatuspolicy ignoreallfailures
filepath_r:
stack_pivoted: 0
creation_flags: 134217728 (CREATE_NO_WINDOW)
process_handle: 0x00000000
inherit_handles: 1
failed 0 0
1619345046.00711
CreateProcessInternalW
thread_identifier: 0
thread_handle: 0x00000000
process_identifier: 0
current_directory:
filepath:
track: 0
command_line: wbadmin DELETE SYSTEMSTATEBACKUP
filepath_r:
stack_pivoted: 0
creation_flags: 134217728 (CREATE_NO_WINDOW)
process_handle: 0x00000000
inherit_handles: 1
failed 0 0
1619345046.00711
CreateProcessInternalW
thread_identifier: 0
thread_handle: 0x00000000
process_identifier: 0
current_directory:
filepath:
track: 0
command_line: wbadmin DELETE SYSTEMSTATEBACKUP -deleteOldest
filepath_r:
stack_pivoted: 0
creation_flags: 134217728 (CREATE_NO_WINDOW)
process_handle: 0x00000000
inherit_handles: 1
failed 0 0
1619345046.24111
CreateProcessInternalW
thread_identifier: 708
thread_handle: 0x0000016c
process_identifier: 1932
current_directory:
filepath:
track: 1
command_line: wmic.exe SHADOWCOPY /nointeractive
filepath_r:
stack_pivoted: 0
creation_flags: 134217728 (CREATE_NO_WINDOW)
process_handle: 0x0000017c
inherit_handles: 1
success 1 0
1619345048.52211
CreateProcessInternalW
thread_identifier: 3056
thread_handle: 0x0000017c
process_identifier: 624
current_directory:
filepath:
track: 1
command_line: vssadmin.exe Delete Shadows /All /Quiet
filepath_r:
stack_pivoted: 0
creation_flags: 134217728 (CREATE_NO_WINDOW)
process_handle: 0x0000016c
inherit_handles: 1
success 1 0
1619345049.94411
CreateProcessInternalW
thread_identifier: 0
thread_handle: 0x00000000
process_identifier: 0
current_directory:
filepath:
track: 0
command_line: bcdedit.exe /set {default} recoveryenabled No
filepath_r:
stack_pivoted: 0
creation_flags: 134217728 (CREATE_NO_WINDOW)
process_handle: 0x00000000
inherit_handles: 1
failed 0 0
1619345049.94411
CreateProcessInternalW
thread_identifier: 0
thread_handle: 0x00000000
process_identifier: 0
current_directory:
filepath:
track: 0
command_line: bcdedit.exe /set {default} bootstatuspolicy ignoreallfailures
filepath_r:
stack_pivoted: 0
creation_flags: 134217728 (CREATE_NO_WINDOW)
process_handle: 0x00000000
inherit_handles: 1
failed 0 0
1619345049.94411
CreateProcessInternalW
thread_identifier: 0
thread_handle: 0x00000000
process_identifier: 0
current_directory:
filepath:
track: 0
command_line: wbadmin DELETE SYSTEMSTATEBACKUP
filepath_r:
stack_pivoted: 0
creation_flags: 134217728 (CREATE_NO_WINDOW)
process_handle: 0x00000000
inherit_handles: 1
failed 0 0
1619345049.94411
CreateProcessInternalW
thread_identifier: 0
thread_handle: 0x00000000
process_identifier: 0
current_directory:
filepath:
track: 0
command_line: wbadmin DELETE SYSTEMSTATEBACKUP -deleteOldest
filepath_r:
stack_pivoted: 0
creation_flags: 134217728 (CREATE_NO_WINDOW)
process_handle: 0x00000000
inherit_handles: 1
failed 0 0
1619345050.06911
CreateProcessInternalW
thread_identifier: 1436
thread_handle: 0x0000016c
process_identifier: 1880
current_directory:
filepath:
track: 1
command_line: wmic.exe SHADOWCOPY /nointeractive
filepath_r:
stack_pivoted: 0
creation_flags: 134217728 (CREATE_NO_WINDOW)
process_handle: 0x0000017c
inherit_handles: 1
success 1 0
Checks for the Locally Unique Identifier on the system for a suspicious privilege (3 个事件)
Time & API Arguments Status Return Repeated
1619371443.826374
LookupPrivilegeValueW
system_name:
privilege_name: SeBackupPrivilege
success 1 0
1619371450.186124
LookupPrivilegeValueW
system_name:
privilege_name: SeBackupPrivilege
success 1 0
1619371454.233001
LookupPrivilegeValueW
system_name:
privilege_name: SeBackupPrivilege
success 1 0
Repeatedly searches for a not-found process, you may want to run a web browser during analysis (29 个事件)
Time & API Arguments Status Return Repeated
1619345037.52211
Process32NextW
process_name: 35271695a6202c514fef4520d49886ea.exe
snapshot_handle: 0x0000017c
process_identifier: 2440
failed 0 0
1619345037.53811
Process32NextW
process_name: 35271695a6202c514fef4520d49886ea.exe
snapshot_handle: 0x0000017c
process_identifier: 2440
failed 0 0
1619345037.53811
Process32NextW
process_name: 35271695a6202c514fef4520d49886ea.exe
snapshot_handle: 0x0000017c
process_identifier: 2440
failed 0 0
1619345037.55411
Process32NextW
process_name: 35271695a6202c514fef4520d49886ea.exe
snapshot_handle: 0x0000017c
process_identifier: 2440
failed 0 0
1619345037.56911
Process32NextW
process_name: 35271695a6202c514fef4520d49886ea.exe
snapshot_handle: 0x0000017c
process_identifier: 2440
failed 0 0
1619345037.58511
Process32NextW
process_name: 35271695a6202c514fef4520d49886ea.exe
snapshot_handle: 0x0000017c
process_identifier: 2440
failed 0 0
1619345037.61611
Process32NextW
process_name: 35271695a6202c514fef4520d49886ea.exe
snapshot_handle: 0x0000017c
process_identifier: 2440
failed 0 0
1619345037.61611
Process32NextW
process_name: 35271695a6202c514fef4520d49886ea.exe
snapshot_handle: 0x0000017c
process_identifier: 2440
failed 0 0
1619345037.63211
Process32NextW
process_name: 35271695a6202c514fef4520d49886ea.exe
snapshot_handle: 0x0000017c
process_identifier: 2440
failed 0 0
1619345037.66311
Process32NextW
process_name: 35271695a6202c514fef4520d49886ea.exe
snapshot_handle: 0x0000017c
process_identifier: 2440
failed 0 0
1619345037.66311
Process32NextW
process_name: 35271695a6202c514fef4520d49886ea.exe
snapshot_handle: 0x0000017c
process_identifier: 2440
failed 0 0
1619345037.67911
Process32NextW
process_name: 35271695a6202c514fef4520d49886ea.exe
snapshot_handle: 0x0000017c
process_identifier: 2440
failed 0 0
1619345037.67911
Process32NextW
process_name: 35271695a6202c514fef4520d49886ea.exe
snapshot_handle: 0x0000017c
process_identifier: 2440
failed 0 0
1619345037.67911
Process32NextW
process_name: 35271695a6202c514fef4520d49886ea.exe
snapshot_handle: 0x0000017c
process_identifier: 2440
failed 0 0
1619345037.71011
Process32NextW
process_name: 35271695a6202c514fef4520d49886ea.exe
snapshot_handle: 0x0000017c
process_identifier: 2440
failed 0 0
1619345037.72611
Process32NextW
process_name: 35271695a6202c514fef4520d49886ea.exe
snapshot_handle: 0x0000017c
process_identifier: 2440
failed 0 0
1619345037.74111
Process32NextW
process_name: 35271695a6202c514fef4520d49886ea.exe
snapshot_handle: 0x0000017c
process_identifier: 2440
failed 0 0
1619345037.74111
Process32NextW
process_name: 35271695a6202c514fef4520d49886ea.exe
snapshot_handle: 0x0000017c
process_identifier: 2440
failed 0 0
1619345037.75711
Process32NextW
process_name: 35271695a6202c514fef4520d49886ea.exe
snapshot_handle: 0x0000017c
process_identifier: 2440
failed 0 0
1619345037.77211
Process32NextW
process_name: 35271695a6202c514fef4520d49886ea.exe
snapshot_handle: 0x0000017c
process_identifier: 2440
failed 0 0
1619345037.78811
Process32NextW
process_name: 35271695a6202c514fef4520d49886ea.exe
snapshot_handle: 0x0000017c
process_identifier: 2440
failed 0 0
1619345037.78811
Process32NextW
process_name: 35271695a6202c514fef4520d49886ea.exe
snapshot_handle: 0x0000017c
process_identifier: 2440
failed 0 0
1619345037.80411
Process32NextW
process_name: 35271695a6202c514fef4520d49886ea.exe
snapshot_handle: 0x0000017c
process_identifier: 2440
failed 0 0
1619345037.81911
Process32NextW
process_name: 35271695a6202c514fef4520d49886ea.exe
snapshot_handle: 0x0000017c
process_identifier: 2440
failed 0 0
1619345037.83511
Process32NextW
process_name: 35271695a6202c514fef4520d49886ea.exe
snapshot_handle: 0x0000017c
process_identifier: 2440
failed 0 0
1619345037.83511
Process32NextW
process_name: 35271695a6202c514fef4520d49886ea.exe
snapshot_handle: 0x0000017c
process_identifier: 2440
failed 0 0
1619345037.85111
Process32NextW
process_name: 35271695a6202c514fef4520d49886ea.exe
snapshot_handle: 0x0000017c
process_identifier: 2440
failed 0 0
1619345037.85111
Process32NextW
process_name: 35271695a6202c514fef4520d49886ea.exe
snapshot_handle: 0x0000017c
process_identifier: 2440
failed 0 0
1619345037.86611
Process32NextW
process_name: 35271695a6202c514fef4520d49886ea.exe
snapshot_handle: 0x0000017c
process_identifier: 2440
failed 0 0
Uses Windows utilities for basic Windows functionality (1 个事件)
cmdline wmic.exe SHADOWCOPY /nointeractive
网络通信
One or more of the buffers contains an embedded PE file (10 个事件)
buffer Buffer with sha1: 371b8811b87ba6a1b337248259e23e6801b829f2
buffer Buffer with sha1: 7db342659f917fcd164878c83e51d69728b8e0d2
buffer Buffer with sha1: c003573780c4914eadb1df917b8cdd66f21a36c6
buffer Buffer with sha1: 8adfcbd04cd3e85d740c994bee32d0fe89a92445
buffer Buffer with sha1: c9e6b4756741a046b56a2d39c7928265cce9f39e
buffer Buffer with sha1: f0af274a9c0c4009bdad24f41dbbf58be90b0516
buffer Buffer with sha1: 619eace8db20f2bf8cf682c95047141a17daf172
buffer Buffer with sha1: 0537bb1f761b24d07f75563477ab225d75e407bd
buffer Buffer with sha1: 46f52c399dac5442408359740d490974157e5666
buffer Buffer with sha1: a78d3bc7169a90850b6d9dbddf85469d63d92405
Communicates with host for which no DNS query was performed (1 个事件)
host 172.217.24.14
Attempts to detect Cuckoo Sandbox through the presence of a file (1 个事件)
file C:\Python27\agent.pyw
Creates known Hupigon files, registry keys and/or mutexes (1 个事件)
file Z:\Boot\BOOTSTAT.DAT
Modifies boot configuration settings (2 个事件)
command bcdedit.exe /set {default} recoveryenabled no
command bcdedit.exe /set {default} bootstatuspolicy ignoreallfailures
Attempts to modify UAC prompt behavior (1 个事件)
registry HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\System\ConsentPromptBehaviorAdmin
Writes a potential ransom message to disk (50 out of 219 个事件)
Time & API Arguments Status Return Repeated
1619345054.52211
NtWriteFile
file_handle: 0x000002c8
filepath: \Device\HarddiskVolume1\Boot\Recovery_Instructions.html
buffer: <html> <style type="text/css"> body { background-color: #f5f5f5; } h1, h3{ text-align: center; text-transform: uppercase; font-weight: normal; } /*---*/ .tabs1{ display: block; margin: auto; } .tabs1 .head{ text-align: center; float: top; padding: 0px; text-transform: uppercase; font-weight: normal; display: block; background: #81bef7; color: #DF0101; font-size: 30px; } .tabs1 .identi { font-size: 10px; text-align: center; float: top; padding: 15px; display: block; background: #81bef7; color: #DFDFDF; } .tabs .content { background: #f5f5f5; /*text-align: center;*/ color: #000000; padding: 25px 15px; font-size: 15px; font-weight: 400; line-height: 20px; } .tabs .content a { color: #df0130; font-size: 23px; font-style: italic; text-decoration: none; line-height: 35px; } .tabs .content .text{ padding: 25px; line-height: 1.2; } </style> <body> <div class="tabs1"> <div class="head" ><b>Your personal ID:</b></div> <div class="identi"> <span style="width:1000px; color: #ffffff; font-size: 10px;">96B15FC03DCA8D175790CC1A893EEB4568E36CF6777F6CE5568ECDD6C33CDC4DC3B8A0AEBE17D5659209E6C658CCE1BE380E6C5350653A8A972180DDF12A276C<br>AF73EB431A73371B04B5BC86AEAACC8E3FC88B2F0E84D9C76161510D333EBD7686343FD08363EBC6A4D72ECCB63DB9C57C7AA9679310D262EB981A91960D<br>69A70480CD61A2D1DA4976232C86AA805C5B4389E7C04A8C9F65D5F80755A928BA67A0B7D9B5C5CA24883A4D8F4BD33CDEC232E5EFAB57377DE59B168050<br>2696BCA82218CA139ED899AD3837F84CF746A6FE76077F43A9DAFE9540482DB1415DAFC5559354C7E40262E301797BE8C3846F42A90AB20A4DF3462C44EC<br>A25F788CBCA026EA628E63C223A27603710293A1DDF2CABDE3C276BA5C79066F5199B66174620070248310D761B7E4DE7AA3667D4273B71A26A82665E0A1<br>D468573772BFA7618599E04F5124F8B0FAD9B7D6DB0052484E499F049C2E5E400C836E66FE8027CA345FCF44A91BB58CD7077E46091938E100DDCA98E33E<br>015E73596ADADAD1533B831EEDAF489F1FCC1316E4494C9F161C4768FE5F449AB8BE1243B39CF3CD885429DB86B7995E0957715D83511FAEB69A44C7225D<br>07D1C95F152B367363080F26DA65A2CF7CE7FCA38622B3BBCEDD3CCB76AB3B64E6F01FC13FB5E9B4215C6EC3471763678A48FAA7CF7C0180274464B845E5<br>17439641C9A3690410E686D1B601</span> <br> <!-- !!! dont changing this !!! --> </div> </div> <!-- --> <div class="tabs"> <!--tab--> <div class="tab"> <div id="tab-content1" class="content"> <div class="text"> <!--text data --> <b>/!\ YOUR COMPANY NETWORK HAS BEEN PENETRATED /!\</b><br> <b>ALL YOUR IMPORTANT FILES HAVE BEEN ENCRYPTED!</b><br><br> YOUR FILES ARE SAFE! JUST MODIFIED ONLY. (RSA+AES) <br><br> ANY ATTEMPT TO RESTORE YOUR FILES WITH THIRD-PARTY SOFTWARE<br> WILL PERMENANTLY DESTROY YOUR FILE.<br> DO NOT MODIFY ENCRYPTED FILES. DO NOT RENAME ENCRYPTED FILES.<br><br> NO SOFTWARE AVAILABLE ON INTERNET CAN HELP YOU. WE ONLY HAVE<br> SOLUTION TO YOUR PROBLEM.<br><br> WE GATHERED HIGHLY CONFIDENTIAL/PERSORNAL DATA. THESE DATA<br> ARE CURRENTLY STORED ON A PRIVATE SERVER. THIS SERVER WILL BE<br> IMMEDIATELY DESTROYED AFTER YOUR PAYMENT. WE ONLY SEEK MONEY<br> AND DO NOT WANT TO DAMAGE YOUR REPUTATION. IF YOU DECIDE TO<br> NOT PAY, WE WILL RELEASE THIS DATA TO PUBLIC OR RE-SELLER.<br><br> YOU WILL CAN SEND US 2-3 NON-IMPORTANT FILES AND WE WILL<br> DECRYPT IT FOR FREE TO PROVE WE ARE ABLE TO GIVE YOUR FILES<br> BACK.<br><br> <!--text data --> <hr> <b>Contact us for price and get decryption software.</b><br><br> <a href="">http://gvlay6u4g53rxdi5.onion/21-Al9gJCAJ2fd8LgNEdEBLhNUw5QUOgJlP-JVMF20wIlKxlS7OrHBXpCbCONEIVsdhU</a><br> * Note that this server is available via Tor browser only<br><br> Follow the instructions to open the link:<br> 1. Type the addres "https://www.torproject.org" in your Internet browser. It opens the Tor site.<br> 2. Press "Download Tor", then press "Download Tor Browser Bundle", install and run it.<br> 3. Now you have Tor browser. In the Tor Browser open "{
offset: 0
success 0 0
1619345054.69411
NtWriteFile
file_handle: 0x000002b8
filepath: \Device\HarddiskVolume1\Boot\Recovery_Instructions.html
buffer: <html> <style type="text/css"> body { background-color: #f5f5f5; } h1, h3{ text-align: center; text-transform: uppercase; font-weight: normal; } /*---*/ .tabs1{ display: block; margin: auto; } .tabs1 .head{ text-align: center; float: top; padding: 0px; text-transform: uppercase; font-weight: normal; display: block; background: #81bef7; color: #DF0101; font-size: 30px; } .tabs1 .identi { font-size: 10px; text-align: center; float: top; padding: 15px; display: block; background: #81bef7; color: #DFDFDF; } .tabs .content { background: #f5f5f5; /*text-align: center;*/ color: #000000; padding: 25px 15px; font-size: 15px; font-weight: 400; line-height: 20px; } .tabs .content a { color: #df0130; font-size: 23px; font-style: italic; text-decoration: none; line-height: 35px; } .tabs .content .text{ padding: 25px; line-height: 1.2; } </style> <body> <div class="tabs1"> <div class="head" ><b>Your personal ID:</b></div> <div class="identi"> <span style="width:1000px; color: #ffffff; font-size: 10px;">96B15FC03DCA8D175790CC1A893EEB4568E36CF6777F6CE5568ECDD6C33CDC4DC3B8A0AEBE17D5659209E6C658CCE1BE380E6C5350653A8A972180DDF12A276C<br>AF73EB431A73371B04B5BC86AEAACC8E3FC88B2F0E84D9C76161510D333EBD7686343FD08363EBC6A4D72ECCB63DB9C57C7AA9679310D262EB981A91960D<br>69A70480CD61A2D1DA4976232C86AA805C5B4389E7C04A8C9F65D5F80755A928BA67A0B7D9B5C5CA24883A4D8F4BD33CDEC232E5EFAB57377DE59B168050<br>2696BCA82218CA139ED899AD3837F84CF746A6FE76077F43A9DAFE9540482DB1415DAFC5559354C7E40262E301797BE8C3846F42A90AB20A4DF3462C44EC<br>A25F788CBCA026EA628E63C223A27603710293A1DDF2CABDE3C276BA5C79066F5199B66174620070248310D761B7E4DE7AA3667D4273B71A26A82665E0A1<br>D468573772BFA7618599E04F5124F8B0FAD9B7D6DB0052484E499F049C2E5E400C836E66FE8027CA345FCF44A91BB58CD7077E46091938E100DDCA98E33E<br>015E73596ADADAD1533B831EEDAF489F1FCC1316E4494C9F161C4768FE5F449AB8BE1243B39CF3CD885429DB86B7995E0957715D83511FAEB69A44C7225D<br>07D1C95F152B367363080F26DA65A2CF7CE7FCA38622B3BBCEDD3CCB76AB3B64E6F01FC13FB5E9B4215C6EC3471763678A48FAA7CF7C0180274464B845E5<br>17439641C9A3690410E686D1B601</span> <br> <!-- !!! dont changing this !!! --> </div> </div> <!-- --> <div class="tabs"> <!--tab--> <div class="tab"> <div id="tab-content1" class="content"> <div class="text"> <!--text data --> <b>/!\ YOUR COMPANY NETWORK HAS BEEN PENETRATED /!\</b><br> <b>ALL YOUR IMPORTANT FILES HAVE BEEN ENCRYPTED!</b><br><br> YOUR FILES ARE SAFE! JUST MODIFIED ONLY. (RSA+AES) <br><br> ANY ATTEMPT TO RESTORE YOUR FILES WITH THIRD-PARTY SOFTWARE<br> WILL PERMENANTLY DESTROY YOUR FILE.<br> DO NOT MODIFY ENCRYPTED FILES. DO NOT RENAME ENCRYPTED FILES.<br><br> NO SOFTWARE AVAILABLE ON INTERNET CAN HELP YOU. WE ONLY HAVE<br> SOLUTION TO YOUR PROBLEM.<br><br> WE GATHERED HIGHLY CONFIDENTIAL/PERSORNAL DATA. THESE DATA<br> ARE CURRENTLY STORED ON A PRIVATE SERVER. THIS SERVER WILL BE<br> IMMEDIATELY DESTROYED AFTER YOUR PAYMENT. WE ONLY SEEK MONEY<br> AND DO NOT WANT TO DAMAGE YOUR REPUTATION. IF YOU DECIDE TO<br> NOT PAY, WE WILL RELEASE THIS DATA TO PUBLIC OR RE-SELLER.<br><br> YOU WILL CAN SEND US 2-3 NON-IMPORTANT FILES AND WE WILL<br> DECRYPT IT FOR FREE TO PROVE WE ARE ABLE TO GIVE YOUR FILES<br> BACK.<br><br> <!--text data --> <hr> <b>Contact us for price and get decryption software.</b><br><br> <a href="">http://gvlay6u4g53rxdi5.onion/21-Al9gJCAJ2fd8LgNEdEBLhNUw5QUOgJlP-JVMF20wIlKxlS7OrHBXpCbCONEIVsdhU</a><br> * Note that this server is available via Tor browser only<br><br> Follow the instructions to open the link:<br> 1. Type the addres "https://www.torproject.org" in your Internet browser. It opens the Tor site.<br> 2. Press "Download Tor", then press "Download Tor Browser Bundle", install and run it.<br> 3. Now you have Tor browser. In the Tor Browser open "{
offset: 0
success 0 0
1619345054.85111
NtWriteFile
file_handle: 0x000002b8
filepath: \Device\HarddiskVolume1\Boot\Recovery_Instructions.html
buffer: <html> <style type="text/css"> body { background-color: #f5f5f5; } h1, h3{ text-align: center; text-transform: uppercase; font-weight: normal; } /*---*/ .tabs1{ display: block; margin: auto; } .tabs1 .head{ text-align: center; float: top; padding: 0px; text-transform: uppercase; font-weight: normal; display: block; background: #81bef7; color: #DF0101; font-size: 30px; } .tabs1 .identi { font-size: 10px; text-align: center; float: top; padding: 15px; display: block; background: #81bef7; color: #DFDFDF; } .tabs .content { background: #f5f5f5; /*text-align: center;*/ color: #000000; padding: 25px 15px; font-size: 15px; font-weight: 400; line-height: 20px; } .tabs .content a { color: #df0130; font-size: 23px; font-style: italic; text-decoration: none; line-height: 35px; } .tabs .content .text{ padding: 25px; line-height: 1.2; } </style> <body> <div class="tabs1"> <div class="head" ><b>Your personal ID:</b></div> <div class="identi"> <span style="width:1000px; color: #ffffff; font-size: 10px;">96B15FC03DCA8D175790CC1A893EEB4568E36CF6777F6CE5568ECDD6C33CDC4DC3B8A0AEBE17D5659209E6C658CCE1BE380E6C5350653A8A972180DDF12A276C<br>AF73EB431A73371B04B5BC86AEAACC8E3FC88B2F0E84D9C76161510D333EBD7686343FD08363EBC6A4D72ECCB63DB9C57C7AA9679310D262EB981A91960D<br>69A70480CD61A2D1DA4976232C86AA805C5B4389E7C04A8C9F65D5F80755A928BA67A0B7D9B5C5CA24883A4D8F4BD33CDEC232E5EFAB57377DE59B168050<br>2696BCA82218CA139ED899AD3837F84CF746A6FE76077F43A9DAFE9540482DB1415DAFC5559354C7E40262E301797BE8C3846F42A90AB20A4DF3462C44EC<br>A25F788CBCA026EA628E63C223A27603710293A1DDF2CABDE3C276BA5C79066F5199B66174620070248310D761B7E4DE7AA3667D4273B71A26A82665E0A1<br>D468573772BFA7618599E04F5124F8B0FAD9B7D6DB0052484E499F049C2E5E400C836E66FE8027CA345FCF44A91BB58CD7077E46091938E100DDCA98E33E<br>015E73596ADADAD1533B831EEDAF489F1FCC1316E4494C9F161C4768FE5F449AB8BE1243B39CF3CD885429DB86B7995E0957715D83511FAEB69A44C7225D<br>07D1C95F152B367363080F26DA65A2CF7CE7FCA38622B3BBCEDD3CCB76AB3B64E6F01FC13FB5E9B4215C6EC3471763678A48FAA7CF7C0180274464B845E5<br>17439641C9A3690410E686D1B601</span> <br> <!-- !!! dont changing this !!! --> </div> </div> <!-- --> <div class="tabs"> <!--tab--> <div class="tab"> <div id="tab-content1" class="content"> <div class="text"> <!--text data --> <b>/!\ YOUR COMPANY NETWORK HAS BEEN PENETRATED /!\</b><br> <b>ALL YOUR IMPORTANT FILES HAVE BEEN ENCRYPTED!</b><br><br> YOUR FILES ARE SAFE! JUST MODIFIED ONLY. (RSA+AES) <br><br> ANY ATTEMPT TO RESTORE YOUR FILES WITH THIRD-PARTY SOFTWARE<br> WILL PERMENANTLY DESTROY YOUR FILE.<br> DO NOT MODIFY ENCRYPTED FILES. DO NOT RENAME ENCRYPTED FILES.<br><br> NO SOFTWARE AVAILABLE ON INTERNET CAN HELP YOU. WE ONLY HAVE<br> SOLUTION TO YOUR PROBLEM.<br><br> WE GATHERED HIGHLY CONFIDENTIAL/PERSORNAL DATA. THESE DATA<br> ARE CURRENTLY STORED ON A PRIVATE SERVER. THIS SERVER WILL BE<br> IMMEDIATELY DESTROYED AFTER YOUR PAYMENT. WE ONLY SEEK MONEY<br> AND DO NOT WANT TO DAMAGE YOUR REPUTATION. IF YOU DECIDE TO<br> NOT PAY, WE WILL RELEASE THIS DATA TO PUBLIC OR RE-SELLER.<br><br> YOU WILL CAN SEND US 2-3 NON-IMPORTANT FILES AND WE WILL<br> DECRYPT IT FOR FREE TO PROVE WE ARE ABLE TO GIVE YOUR FILES<br> BACK.<br><br> <!--text data --> <hr> <b>Contact us for price and get decryption software.</b><br><br> <a href="">http://gvlay6u4g53rxdi5.onion/21-Al9gJCAJ2fd8LgNEdEBLhNUw5QUOgJlP-JVMF20wIlKxlS7OrHBXpCbCONEIVsdhU</a><br> * Note that this server is available via Tor browser only<br><br> Follow the instructions to open the link:<br> 1. Type the addres "https://www.torproject.org" in your Internet browser. It opens the Tor site.<br> 2. Press "Download Tor", then press "Download Tor Browser Bundle", install and run it.<br> 3. Now you have Tor browser. In the Tor Browser open "{
offset: 0
success 0 0
1619345059.33511
NtWriteFile
file_handle: 0x00000278
filepath: \Device\HarddiskVolume1\Recovery_Instructions.html
buffer: <html> <style type="text/css"> body { background-color: #f5f5f5; } h1, h3{ text-align: center; text-transform: uppercase; font-weight: normal; } /*---*/ .tabs1{ display: block; margin: auto; } .tabs1 .head{ text-align: center; float: top; padding: 0px; text-transform: uppercase; font-weight: normal; display: block; background: #81bef7; color: #DF0101; font-size: 30px; } .tabs1 .identi { font-size: 10px; text-align: center; float: top; padding: 15px; display: block; background: #81bef7; color: #DFDFDF; } .tabs .content { background: #f5f5f5; /*text-align: center;*/ color: #000000; padding: 25px 15px; font-size: 15px; font-weight: 400; line-height: 20px; } .tabs .content a { color: #df0130; font-size: 23px; font-style: italic; text-decoration: none; line-height: 35px; } .tabs .content .text{ padding: 25px; line-height: 1.2; } </style> <body> <div class="tabs1"> <div class="head" ><b>Your personal ID:</b></div> <div class="identi"> <span style="width:1000px; color: #ffffff; font-size: 10px;">96B15FC03DCA8D175790CC1A893EEB4568E36CF6777F6CE5568ECDD6C33CDC4DC3B8A0AEBE17D5659209E6C658CCE1BE380E6C5350653A8A972180DDF12A276C<br>AF73EB431A73371B04B5BC86AEAACC8E3FC88B2F0E84D9C76161510D333EBD7686343FD08363EBC6A4D72ECCB63DB9C57C7AA9679310D262EB981A91960D<br>69A70480CD61A2D1DA4976232C86AA805C5B4389E7C04A8C9F65D5F80755A928BA67A0B7D9B5C5CA24883A4D8F4BD33CDEC232E5EFAB57377DE59B168050<br>2696BCA82218CA139ED899AD3837F84CF746A6FE76077F43A9DAFE9540482DB1415DAFC5559354C7E40262E301797BE8C3846F42A90AB20A4DF3462C44EC<br>A25F788CBCA026EA628E63C223A27603710293A1DDF2CABDE3C276BA5C79066F5199B66174620070248310D761B7E4DE7AA3667D4273B71A26A82665E0A1<br>D468573772BFA7618599E04F5124F8B0FAD9B7D6DB0052484E499F049C2E5E400C836E66FE8027CA345FCF44A91BB58CD7077E46091938E100DDCA98E33E<br>015E73596ADADAD1533B831EEDAF489F1FCC1316E4494C9F161C4768FE5F449AB8BE1243B39CF3CD885429DB86B7995E0957715D83511FAEB69A44C7225D<br>07D1C95F152B367363080F26DA65A2CF7CE7FCA38622B3BBCEDD3CCB76AB3B64E6F01FC13FB5E9B4215C6EC3471763678A48FAA7CF7C0180274464B845E5<br>17439641C9A3690410E686D1B601</span> <br> <!-- !!! dont changing this !!! --> </div> </div> <!-- --> <div class="tabs"> <!--tab--> <div class="tab"> <div id="tab-content1" class="content"> <div class="text"> <!--text data --> <b>/!\ YOUR COMPANY NETWORK HAS BEEN PENETRATED /!\</b><br> <b>ALL YOUR IMPORTANT FILES HAVE BEEN ENCRYPTED!</b><br><br> YOUR FILES ARE SAFE! JUST MODIFIED ONLY. (RSA+AES) <br><br> ANY ATTEMPT TO RESTORE YOUR FILES WITH THIRD-PARTY SOFTWARE<br> WILL PERMENANTLY DESTROY YOUR FILE.<br> DO NOT MODIFY ENCRYPTED FILES. DO NOT RENAME ENCRYPTED FILES.<br><br> NO SOFTWARE AVAILABLE ON INTERNET CAN HELP YOU. WE ONLY HAVE<br> SOLUTION TO YOUR PROBLEM.<br><br> WE GATHERED HIGHLY CONFIDENTIAL/PERSORNAL DATA. THESE DATA<br> ARE CURRENTLY STORED ON A PRIVATE SERVER. THIS SERVER WILL BE<br> IMMEDIATELY DESTROYED AFTER YOUR PAYMENT. WE ONLY SEEK MONEY<br> AND DO NOT WANT TO DAMAGE YOUR REPUTATION. IF YOU DECIDE TO<br> NOT PAY, WE WILL RELEASE THIS DATA TO PUBLIC OR RE-SELLER.<br><br> YOU WILL CAN SEND US 2-3 NON-IMPORTANT FILES AND WE WILL<br> DECRYPT IT FOR FREE TO PROVE WE ARE ABLE TO GIVE YOUR FILES<br> BACK.<br><br> <!--text data --> <hr> <b>Contact us for price and get decryption software.</b><br><br> <a href="">http://gvlay6u4g53rxdi5.onion/21-Al9gJCAJ2fd8LgNEdEBLhNUw5QUOgJlP-JVMF20wIlKxlS7OrHBXpCbCONEIVsdhU</a><br> * Note that this server is available via Tor browser only<br><br> Follow the instructions to open the link:<br> 1. Type the addres "https://www.torproject.org" in your Internet browser. It opens the Tor site.<br> 2. Press "Download Tor", then press "Download Tor Browser Bundle", install and run it.<br> 3. Now you have Tor browser. In the Tor Browser open "{
offset: 0
success 0 0
1619345059.66311
NtWriteFile
file_handle: 0x000002ec
filepath: \Device\HarddiskVolume1\Recovery_Instructions.html
buffer: <html> <style type="text/css"> body { background-color: #f5f5f5; } h1, h3{ text-align: center; text-transform: uppercase; font-weight: normal; } /*---*/ .tabs1{ display: block; margin: auto; } .tabs1 .head{ text-align: center; float: top; padding: 0px; text-transform: uppercase; font-weight: normal; display: block; background: #81bef7; color: #DF0101; font-size: 30px; } .tabs1 .identi { font-size: 10px; text-align: center; float: top; padding: 15px; display: block; background: #81bef7; color: #DFDFDF; } .tabs .content { background: #f5f5f5; /*text-align: center;*/ color: #000000; padding: 25px 15px; font-size: 15px; font-weight: 400; line-height: 20px; } .tabs .content a { color: #df0130; font-size: 23px; font-style: italic; text-decoration: none; line-height: 35px; } .tabs .content .text{ padding: 25px; line-height: 1.2; } </style> <body> <div class="tabs1"> <div class="head" ><b>Your personal ID:</b></div> <div class="identi"> <span style="width:1000px; color: #ffffff; font-size: 10px;">96B15FC03DCA8D175790CC1A893EEB4568E36CF6777F6CE5568ECDD6C33CDC4DC3B8A0AEBE17D5659209E6C658CCE1BE380E6C5350653A8A972180DDF12A276C<br>AF73EB431A73371B04B5BC86AEAACC8E3FC88B2F0E84D9C76161510D333EBD7686343FD08363EBC6A4D72ECCB63DB9C57C7AA9679310D262EB981A91960D<br>69A70480CD61A2D1DA4976232C86AA805C5B4389E7C04A8C9F65D5F80755A928BA67A0B7D9B5C5CA24883A4D8F4BD33CDEC232E5EFAB57377DE59B168050<br>2696BCA82218CA139ED899AD3837F84CF746A6FE76077F43A9DAFE9540482DB1415DAFC5559354C7E40262E301797BE8C3846F42A90AB20A4DF3462C44EC<br>A25F788CBCA026EA628E63C223A27603710293A1DDF2CABDE3C276BA5C79066F5199B66174620070248310D761B7E4DE7AA3667D4273B71A26A82665E0A1<br>D468573772BFA7618599E04F5124F8B0FAD9B7D6DB0052484E499F049C2E5E400C836E66FE8027CA345FCF44A91BB58CD7077E46091938E100DDCA98E33E<br>015E73596ADADAD1533B831EEDAF489F1FCC1316E4494C9F161C4768FE5F449AB8BE1243B39CF3CD885429DB86B7995E0957715D83511FAEB69A44C7225D<br>07D1C95F152B367363080F26DA65A2CF7CE7FCA38622B3BBCEDD3CCB76AB3B64E6F01FC13FB5E9B4215C6EC3471763678A48FAA7CF7C0180274464B845E5<br>17439641C9A3690410E686D1B601</span> <br> <!-- !!! dont changing this !!! --> </div> </div> <!-- --> <div class="tabs"> <!--tab--> <div class="tab"> <div id="tab-content1" class="content"> <div class="text"> <!--text data --> <b>/!\ YOUR COMPANY NETWORK HAS BEEN PENETRATED /!\</b><br> <b>ALL YOUR IMPORTANT FILES HAVE BEEN ENCRYPTED!</b><br><br> YOUR FILES ARE SAFE! JUST MODIFIED ONLY. (RSA+AES) <br><br> ANY ATTEMPT TO RESTORE YOUR FILES WITH THIRD-PARTY SOFTWARE<br> WILL PERMENANTLY DESTROY YOUR FILE.<br> DO NOT MODIFY ENCRYPTED FILES. DO NOT RENAME ENCRYPTED FILES.<br><br> NO SOFTWARE AVAILABLE ON INTERNET CAN HELP YOU. WE ONLY HAVE<br> SOLUTION TO YOUR PROBLEM.<br><br> WE GATHERED HIGHLY CONFIDENTIAL/PERSORNAL DATA. THESE DATA<br> ARE CURRENTLY STORED ON A PRIVATE SERVER. THIS SERVER WILL BE<br> IMMEDIATELY DESTROYED AFTER YOUR PAYMENT. WE ONLY SEEK MONEY<br> AND DO NOT WANT TO DAMAGE YOUR REPUTATION. IF YOU DECIDE TO<br> NOT PAY, WE WILL RELEASE THIS DATA TO PUBLIC OR RE-SELLER.<br><br> YOU WILL CAN SEND US 2-3 NON-IMPORTANT FILES AND WE WILL<br> DECRYPT IT FOR FREE TO PROVE WE ARE ABLE TO GIVE YOUR FILES<br> BACK.<br><br> <!--text data --> <hr> <b>Contact us for price and get decryption software.</b><br><br> <a href="">http://gvlay6u4g53rxdi5.onion/21-Al9gJCAJ2fd8LgNEdEBLhNUw5QUOgJlP-JVMF20wIlKxlS7OrHBXpCbCONEIVsdhU</a><br> * Note that this server is available via Tor browser only<br><br> Follow the instructions to open the link:<br> 1. Type the addres "https://www.torproject.org" in your Internet browser. It opens the Tor site.<br> 2. Press "Download Tor", then press "Download Tor Browser Bundle", install and run it.<br> 3. Now you have Tor browser. In the Tor Browser open "{
offset: 0
success 0 0
1619345061.85111
NtWriteFile
file_handle: 0x0000028c
filepath: C:\Python27\Recovery_Instructions.html
buffer: <html> <style type="text/css"> body { background-color: #f5f5f5; } h1, h3{ text-align: center; text-transform: uppercase; font-weight: normal; } /*---*/ .tabs1{ display: block; margin: auto; } .tabs1 .head{ text-align: center; float: top; padding: 0px; text-transform: uppercase; font-weight: normal; display: block; background: #81bef7; color: #DF0101; font-size: 30px; } .tabs1 .identi { font-size: 10px; text-align: center; float: top; padding: 15px; display: block; background: #81bef7; color: #DFDFDF; } .tabs .content { background: #f5f5f5; /*text-align: center;*/ color: #000000; padding: 25px 15px; font-size: 15px; font-weight: 400; line-height: 20px; } .tabs .content a { color: #df0130; font-size: 23px; font-style: italic; text-decoration: none; line-height: 35px; } .tabs .content .text{ padding: 25px; line-height: 1.2; } </style> <body> <div class="tabs1"> <div class="head" ><b>Your personal ID:</b></div> <div class="identi"> <span style="width:1000px; color: #ffffff; font-size: 10px;">96B15FC03DCA8D175790CC1A893EEB4568E36CF6777F6CE5568ECDD6C33CDC4DC3B8A0AEBE17D5659209E6C658CCE1BE380E6C5350653A8A972180DDF12A276C<br>AF73EB431A73371B04B5BC86AEAACC8E3FC88B2F0E84D9C76161510D333EBD7686343FD08363EBC6A4D72ECCB63DB9C57C7AA9679310D262EB981A91960D<br>69A70480CD61A2D1DA4976232C86AA805C5B4389E7C04A8C9F65D5F80755A928BA67A0B7D9B5C5CA24883A4D8F4BD33CDEC232E5EFAB57377DE59B168050<br>2696BCA82218CA139ED899AD3837F84CF746A6FE76077F43A9DAFE9540482DB1415DAFC5559354C7E40262E301797BE8C3846F42A90AB20A4DF3462C44EC<br>A25F788CBCA026EA628E63C223A27603710293A1DDF2CABDE3C276BA5C79066F5199B66174620070248310D761B7E4DE7AA3667D4273B71A26A82665E0A1<br>D468573772BFA7618599E04F5124F8B0FAD9B7D6DB0052484E499F049C2E5E400C836E66FE8027CA345FCF44A91BB58CD7077E46091938E100DDCA98E33E<br>015E73596ADADAD1533B831EEDAF489F1FCC1316E4494C9F161C4768FE5F449AB8BE1243B39CF3CD885429DB86B7995E0957715D83511FAEB69A44C7225D<br>07D1C95F152B367363080F26DA65A2CF7CE7FCA38622B3BBCEDD3CCB76AB3B64E6F01FC13FB5E9B4215C6EC3471763678A48FAA7CF7C0180274464B845E5<br>17439641C9A3690410E686D1B601</span> <br> <!-- !!! dont changing this !!! --> </div> </div> <!-- --> <div class="tabs"> <!--tab--> <div class="tab"> <div id="tab-content1" class="content"> <div class="text"> <!--text data --> <b>/!\ YOUR COMPANY NETWORK HAS BEEN PENETRATED /!\</b><br> <b>ALL YOUR IMPORTANT FILES HAVE BEEN ENCRYPTED!</b><br><br> YOUR FILES ARE SAFE! JUST MODIFIED ONLY. (RSA+AES) <br><br> ANY ATTEMPT TO RESTORE YOUR FILES WITH THIRD-PARTY SOFTWARE<br> WILL PERMENANTLY DESTROY YOUR FILE.<br> DO NOT MODIFY ENCRYPTED FILES. DO NOT RENAME ENCRYPTED FILES.<br><br> NO SOFTWARE AVAILABLE ON INTERNET CAN HELP YOU. WE ONLY HAVE<br> SOLUTION TO YOUR PROBLEM.<br><br> WE GATHERED HIGHLY CONFIDENTIAL/PERSORNAL DATA. THESE DATA<br> ARE CURRENTLY STORED ON A PRIVATE SERVER. THIS SERVER WILL BE<br> IMMEDIATELY DESTROYED AFTER YOUR PAYMENT. WE ONLY SEEK MONEY<br> AND DO NOT WANT TO DAMAGE YOUR REPUTATION. IF YOU DECIDE TO<br> NOT PAY, WE WILL RELEASE THIS DATA TO PUBLIC OR RE-SELLER.<br><br> YOU WILL CAN SEND US 2-3 NON-IMPORTANT FILES AND WE WILL<br> DECRYPT IT FOR FREE TO PROVE WE ARE ABLE TO GIVE YOUR FILES<br> BACK.<br><br> <!--text data --> <hr> <b>Contact us for price and get decryption software.</b><br><br> <a href="">http://gvlay6u4g53rxdi5.onion/21-Al9gJCAJ2fd8LgNEdEBLhNUw5QUOgJlP-JVMF20wIlKxlS7OrHBXpCbCONEIVsdhU</a><br> * Note that this server is available via Tor browser only<br><br> Follow the instructions to open the link:<br> 1. Type the addres "https://www.torproject.org" in your Internet browser. It opens the Tor site.<br> 2. Press "Download Tor", then press "Download Tor Browser Bundle", install and run it.<br> 3. Now you have Tor browser. In the Tor Browser open "{
offset: 0
success 0 0
1619345062.75711
NtWriteFile
file_handle: 0x000002ec
filepath: C:\Python27\DLLs\Recovery_Instructions.html
buffer: <html> <style type="text/css"> body { background-color: #f5f5f5; } h1, h3{ text-align: center; text-transform: uppercase; font-weight: normal; } /*---*/ .tabs1{ display: block; margin: auto; } .tabs1 .head{ text-align: center; float: top; padding: 0px; text-transform: uppercase; font-weight: normal; display: block; background: #81bef7; color: #DF0101; font-size: 30px; } .tabs1 .identi { font-size: 10px; text-align: center; float: top; padding: 15px; display: block; background: #81bef7; color: #DFDFDF; } .tabs .content { background: #f5f5f5; /*text-align: center;*/ color: #000000; padding: 25px 15px; font-size: 15px; font-weight: 400; line-height: 20px; } .tabs .content a { color: #df0130; font-size: 23px; font-style: italic; text-decoration: none; line-height: 35px; } .tabs .content .text{ padding: 25px; line-height: 1.2; } </style> <body> <div class="tabs1"> <div class="head" ><b>Your personal ID:</b></div> <div class="identi"> <span style="width:1000px; color: #ffffff; font-size: 10px;">96B15FC03DCA8D175790CC1A893EEB4568E36CF6777F6CE5568ECDD6C33CDC4DC3B8A0AEBE17D5659209E6C658CCE1BE380E6C5350653A8A972180DDF12A276C<br>AF73EB431A73371B04B5BC86AEAACC8E3FC88B2F0E84D9C76161510D333EBD7686343FD08363EBC6A4D72ECCB63DB9C57C7AA9679310D262EB981A91960D<br>69A70480CD61A2D1DA4976232C86AA805C5B4389E7C04A8C9F65D5F80755A928BA67A0B7D9B5C5CA24883A4D8F4BD33CDEC232E5EFAB57377DE59B168050<br>2696BCA82218CA139ED899AD3837F84CF746A6FE76077F43A9DAFE9540482DB1415DAFC5559354C7E40262E301797BE8C3846F42A90AB20A4DF3462C44EC<br>A25F788CBCA026EA628E63C223A27603710293A1DDF2CABDE3C276BA5C79066F5199B66174620070248310D761B7E4DE7AA3667D4273B71A26A82665E0A1<br>D468573772BFA7618599E04F5124F8B0FAD9B7D6DB0052484E499F049C2E5E400C836E66FE8027CA345FCF44A91BB58CD7077E46091938E100DDCA98E33E<br>015E73596ADADAD1533B831EEDAF489F1FCC1316E4494C9F161C4768FE5F449AB8BE1243B39CF3CD885429DB86B7995E0957715D83511FAEB69A44C7225D<br>07D1C95F152B367363080F26DA65A2CF7CE7FCA38622B3BBCEDD3CCB76AB3B64E6F01FC13FB5E9B4215C6EC3471763678A48FAA7CF7C0180274464B845E5<br>17439641C9A3690410E686D1B601</span> <br> <!-- !!! dont changing this !!! --> </div> </div> <!-- --> <div class="tabs"> <!--tab--> <div class="tab"> <div id="tab-content1" class="content"> <div class="text"> <!--text data --> <b>/!\ YOUR COMPANY NETWORK HAS BEEN PENETRATED /!\</b><br> <b>ALL YOUR IMPORTANT FILES HAVE BEEN ENCRYPTED!</b><br><br> YOUR FILES ARE SAFE! JUST MODIFIED ONLY. (RSA+AES) <br><br> ANY ATTEMPT TO RESTORE YOUR FILES WITH THIRD-PARTY SOFTWARE<br> WILL PERMENANTLY DESTROY YOUR FILE.<br> DO NOT MODIFY ENCRYPTED FILES. DO NOT RENAME ENCRYPTED FILES.<br><br> NO SOFTWARE AVAILABLE ON INTERNET CAN HELP YOU. WE ONLY HAVE<br> SOLUTION TO YOUR PROBLEM.<br><br> WE GATHERED HIGHLY CONFIDENTIAL/PERSORNAL DATA. THESE DATA<br> ARE CURRENTLY STORED ON A PRIVATE SERVER. THIS SERVER WILL BE<br> IMMEDIATELY DESTROYED AFTER YOUR PAYMENT. WE ONLY SEEK MONEY<br> AND DO NOT WANT TO DAMAGE YOUR REPUTATION. IF YOU DECIDE TO<br> NOT PAY, WE WILL RELEASE THIS DATA TO PUBLIC OR RE-SELLER.<br><br> YOU WILL CAN SEND US 2-3 NON-IMPORTANT FILES AND WE WILL<br> DECRYPT IT FOR FREE TO PROVE WE ARE ABLE TO GIVE YOUR FILES<br> BACK.<br><br> <!--text data --> <hr> <b>Contact us for price and get decryption software.</b><br><br> <a href="">http://gvlay6u4g53rxdi5.onion/21-Al9gJCAJ2fd8LgNEdEBLhNUw5QUOgJlP-JVMF20wIlKxlS7OrHBXpCbCONEIVsdhU</a><br> * Note that this server is available via Tor browser only<br><br> Follow the instructions to open the link:<br> 1. Type the addres "https://www.torproject.org" in your Internet browser. It opens the Tor site.<br> 2. Press "Download Tor", then press "Download Tor Browser Bundle", install and run it.<br> 3. Now you have Tor browser. In the Tor Browser open "{
offset: 0
success 0 0
1619345062.89711
NtWriteFile
file_handle: 0x000002ec
filepath: C:\Python27\DLLs\Recovery_Instructions.html
buffer: <html> <style type="text/css"> body { background-color: #f5f5f5; } h1, h3{ text-align: center; text-transform: uppercase; font-weight: normal; } /*---*/ .tabs1{ display: block; margin: auto; } .tabs1 .head{ text-align: center; float: top; padding: 0px; text-transform: uppercase; font-weight: normal; display: block; background: #81bef7; color: #DF0101; font-size: 30px; } .tabs1 .identi { font-size: 10px; text-align: center; float: top; padding: 15px; display: block; background: #81bef7; color: #DFDFDF; } .tabs .content { background: #f5f5f5; /*text-align: center;*/ color: #000000; padding: 25px 15px; font-size: 15px; font-weight: 400; line-height: 20px; } .tabs .content a { color: #df0130; font-size: 23px; font-style: italic; text-decoration: none; line-height: 35px; } .tabs .content .text{ padding: 25px; line-height: 1.2; } </style> <body> <div class="tabs1"> <div class="head" ><b>Your personal ID:</b></div> <div class="identi"> <span style="width:1000px; color: #ffffff; font-size: 10px;">96B15FC03DCA8D175790CC1A893EEB4568E36CF6777F6CE5568ECDD6C33CDC4DC3B8A0AEBE17D5659209E6C658CCE1BE380E6C5350653A8A972180DDF12A276C<br>AF73EB431A73371B04B5BC86AEAACC8E3FC88B2F0E84D9C76161510D333EBD7686343FD08363EBC6A4D72ECCB63DB9C57C7AA9679310D262EB981A91960D<br>69A70480CD61A2D1DA4976232C86AA805C5B4389E7C04A8C9F65D5F80755A928BA67A0B7D9B5C5CA24883A4D8F4BD33CDEC232E5EFAB57377DE59B168050<br>2696BCA82218CA139ED899AD3837F84CF746A6FE76077F43A9DAFE9540482DB1415DAFC5559354C7E40262E301797BE8C3846F42A90AB20A4DF3462C44EC<br>A25F788CBCA026EA628E63C223A27603710293A1DDF2CABDE3C276BA5C79066F5199B66174620070248310D761B7E4DE7AA3667D4273B71A26A82665E0A1<br>D468573772BFA7618599E04F5124F8B0FAD9B7D6DB0052484E499F049C2E5E400C836E66FE8027CA345FCF44A91BB58CD7077E46091938E100DDCA98E33E<br>015E73596ADADAD1533B831EEDAF489F1FCC1316E4494C9F161C4768FE5F449AB8BE1243B39CF3CD885429DB86B7995E0957715D83511FAEB69A44C7225D<br>07D1C95F152B367363080F26DA65A2CF7CE7FCA38622B3BBCEDD3CCB76AB3B64E6F01FC13FB5E9B4215C6EC3471763678A48FAA7CF7C0180274464B845E5<br>17439641C9A3690410E686D1B601</span> <br> <!-- !!! dont changing this !!! --> </div> </div> <!-- --> <div class="tabs"> <!--tab--> <div class="tab"> <div id="tab-content1" class="content"> <div class="text"> <!--text data --> <b>/!\ YOUR COMPANY NETWORK HAS BEEN PENETRATED /!\</b><br> <b>ALL YOUR IMPORTANT FILES HAVE BEEN ENCRYPTED!</b><br><br> YOUR FILES ARE SAFE! JUST MODIFIED ONLY. (RSA+AES) <br><br> ANY ATTEMPT TO RESTORE YOUR FILES WITH THIRD-PARTY SOFTWARE<br> WILL PERMENANTLY DESTROY YOUR FILE.<br> DO NOT MODIFY ENCRYPTED FILES. DO NOT RENAME ENCRYPTED FILES.<br><br> NO SOFTWARE AVAILABLE ON INTERNET CAN HELP YOU. WE ONLY HAVE<br> SOLUTION TO YOUR PROBLEM.<br><br> WE GATHERED HIGHLY CONFIDENTIAL/PERSORNAL DATA. THESE DATA<br> ARE CURRENTLY STORED ON A PRIVATE SERVER. THIS SERVER WILL BE<br> IMMEDIATELY DESTROYED AFTER YOUR PAYMENT. WE ONLY SEEK MONEY<br> AND DO NOT WANT TO DAMAGE YOUR REPUTATION. IF YOU DECIDE TO<br> NOT PAY, WE WILL RELEASE THIS DATA TO PUBLIC OR RE-SELLER.<br><br> YOU WILL CAN SEND US 2-3 NON-IMPORTANT FILES AND WE WILL<br> DECRYPT IT FOR FREE TO PROVE WE ARE ABLE TO GIVE YOUR FILES<br> BACK.<br><br> <!--text data --> <hr> <b>Contact us for price and get decryption software.</b><br><br> <a href="">http://gvlay6u4g53rxdi5.onion/21-Al9gJCAJ2fd8LgNEdEBLhNUw5QUOgJlP-JVMF20wIlKxlS7OrHBXpCbCONEIVsdhU</a><br> * Note that this server is available via Tor browser only<br><br> Follow the instructions to open the link:<br> 1. Type the addres "https://www.torproject.org" in your Internet browser. It opens the Tor site.<br> 2. Press "Download Tor", then press "Download Tor Browser Bundle", install and run it.<br> 3. Now you have Tor browser. In the Tor Browser open "{
offset: 0
success 0 0
1619345063.42911
NtWriteFile
file_handle: 0x000002ec
filepath: C:\Python27\DLLs\Recovery_Instructions.html
buffer: <html> <style type="text/css"> body { background-color: #f5f5f5; } h1, h3{ text-align: center; text-transform: uppercase; font-weight: normal; } /*---*/ .tabs1{ display: block; margin: auto; } .tabs1 .head{ text-align: center; float: top; padding: 0px; text-transform: uppercase; font-weight: normal; display: block; background: #81bef7; color: #DF0101; font-size: 30px; } .tabs1 .identi { font-size: 10px; text-align: center; float: top; padding: 15px; display: block; background: #81bef7; color: #DFDFDF; } .tabs .content { background: #f5f5f5; /*text-align: center;*/ color: #000000; padding: 25px 15px; font-size: 15px; font-weight: 400; line-height: 20px; } .tabs .content a { color: #df0130; font-size: 23px; font-style: italic; text-decoration: none; line-height: 35px; } .tabs .content .text{ padding: 25px; line-height: 1.2; } </style> <body> <div class="tabs1"> <div class="head" ><b>Your personal ID:</b></div> <div class="identi"> <span style="width:1000px; color: #ffffff; font-size: 10px;">96B15FC03DCA8D175790CC1A893EEB4568E36CF6777F6CE5568ECDD6C33CDC4DC3B8A0AEBE17D5659209E6C658CCE1BE380E6C5350653A8A972180DDF12A276C<br>AF73EB431A73371B04B5BC86AEAACC8E3FC88B2F0E84D9C76161510D333EBD7686343FD08363EBC6A4D72ECCB63DB9C57C7AA9679310D262EB981A91960D<br>69A70480CD61A2D1DA4976232C86AA805C5B4389E7C04A8C9F65D5F80755A928BA67A0B7D9B5C5CA24883A4D8F4BD33CDEC232E5EFAB57377DE59B168050<br>2696BCA82218CA139ED899AD3837F84CF746A6FE76077F43A9DAFE9540482DB1415DAFC5559354C7E40262E301797BE8C3846F42A90AB20A4DF3462C44EC<br>A25F788CBCA026EA628E63C223A27603710293A1DDF2CABDE3C276BA5C79066F5199B66174620070248310D761B7E4DE7AA3667D4273B71A26A82665E0A1<br>D468573772BFA7618599E04F5124F8B0FAD9B7D6DB0052484E499F049C2E5E400C836E66FE8027CA345FCF44A91BB58CD7077E46091938E100DDCA98E33E<br>015E73596ADADAD1533B831EEDAF489F1FCC1316E4494C9F161C4768FE5F449AB8BE1243B39CF3CD885429DB86B7995E0957715D83511FAEB69A44C7225D<br>07D1C95F152B367363080F26DA65A2CF7CE7FCA38622B3BBCEDD3CCB76AB3B64E6F01FC13FB5E9B4215C6EC3471763678A48FAA7CF7C0180274464B845E5<br>17439641C9A3690410E686D1B601</span> <br> <!-- !!! dont changing this !!! --> </div> </div> <!-- --> <div class="tabs"> <!--tab--> <div class="tab"> <div id="tab-content1" class="content"> <div class="text"> <!--text data --> <b>/!\ YOUR COMPANY NETWORK HAS BEEN PENETRATED /!\</b><br> <b>ALL YOUR IMPORTANT FILES HAVE BEEN ENCRYPTED!</b><br><br> YOUR FILES ARE SAFE! JUST MODIFIED ONLY. (RSA+AES) <br><br> ANY ATTEMPT TO RESTORE YOUR FILES WITH THIRD-PARTY SOFTWARE<br> WILL PERMENANTLY DESTROY YOUR FILE.<br> DO NOT MODIFY ENCRYPTED FILES. DO NOT RENAME ENCRYPTED FILES.<br><br> NO SOFTWARE AVAILABLE ON INTERNET CAN HELP YOU. WE ONLY HAVE<br> SOLUTION TO YOUR PROBLEM.<br><br> WE GATHERED HIGHLY CONFIDENTIAL/PERSORNAL DATA. THESE DATA<br> ARE CURRENTLY STORED ON A PRIVATE SERVER. THIS SERVER WILL BE<br> IMMEDIATELY DESTROYED AFTER YOUR PAYMENT. WE ONLY SEEK MONEY<br> AND DO NOT WANT TO DAMAGE YOUR REPUTATION. IF YOU DECIDE TO<br> NOT PAY, WE WILL RELEASE THIS DATA TO PUBLIC OR RE-SELLER.<br><br> YOU WILL CAN SEND US 2-3 NON-IMPORTANT FILES AND WE WILL<br> DECRYPT IT FOR FREE TO PROVE WE ARE ABLE TO GIVE YOUR FILES<br> BACK.<br><br> <!--text data --> <hr> <b>Contact us for price and get decryption software.</b><br><br> <a href="">http://gvlay6u4g53rxdi5.onion/21-Al9gJCAJ2fd8LgNEdEBLhNUw5QUOgJlP-JVMF20wIlKxlS7OrHBXpCbCONEIVsdhU</a><br> * Note that this server is available via Tor browser only<br><br> Follow the instructions to open the link:<br> 1. Type the addres "https://www.torproject.org" in your Internet browser. It opens the Tor site.<br> 2. Press "Download Tor", then press "Download Tor Browser Bundle", install and run it.<br> 3. Now you have Tor browser. In the Tor Browser open "{
offset: 0
success 0 0
1619345063.75711
NtWriteFile
file_handle: 0x000002f8
filepath: C:\Python27\DLLs\Recovery_Instructions.html
buffer: <html> <style type="text/css"> body { background-color: #f5f5f5; } h1, h3{ text-align: center; text-transform: uppercase; font-weight: normal; } /*---*/ .tabs1{ display: block; margin: auto; } .tabs1 .head{ text-align: center; float: top; padding: 0px; text-transform: uppercase; font-weight: normal; display: block; background: #81bef7; color: #DF0101; font-size: 30px; } .tabs1 .identi { font-size: 10px; text-align: center; float: top; padding: 15px; display: block; background: #81bef7; color: #DFDFDF; } .tabs .content { background: #f5f5f5; /*text-align: center;*/ color: #000000; padding: 25px 15px; font-size: 15px; font-weight: 400; line-height: 20px; } .tabs .content a { color: #df0130; font-size: 23px; font-style: italic; text-decoration: none; line-height: 35px; } .tabs .content .text{ padding: 25px; line-height: 1.2; } </style> <body> <div class="tabs1"> <div class="head" ><b>Your personal ID:</b></div> <div class="identi"> <span style="width:1000px; color: #ffffff; font-size: 10px;">96B15FC03DCA8D175790CC1A893EEB4568E36CF6777F6CE5568ECDD6C33CDC4DC3B8A0AEBE17D5659209E6C658CCE1BE380E6C5350653A8A972180DDF12A276C<br>AF73EB431A73371B04B5BC86AEAACC8E3FC88B2F0E84D9C76161510D333EBD7686343FD08363EBC6A4D72ECCB63DB9C57C7AA9679310D262EB981A91960D<br>69A70480CD61A2D1DA4976232C86AA805C5B4389E7C04A8C9F65D5F80755A928BA67A0B7D9B5C5CA24883A4D8F4BD33CDEC232E5EFAB57377DE59B168050<br>2696BCA82218CA139ED899AD3837F84CF746A6FE76077F43A9DAFE9540482DB1415DAFC5559354C7E40262E301797BE8C3846F42A90AB20A4DF3462C44EC<br>A25F788CBCA026EA628E63C223A27603710293A1DDF2CABDE3C276BA5C79066F5199B66174620070248310D761B7E4DE7AA3667D4273B71A26A82665E0A1<br>D468573772BFA7618599E04F5124F8B0FAD9B7D6DB0052484E499F049C2E5E400C836E66FE8027CA345FCF44A91BB58CD7077E46091938E100DDCA98E33E<br>015E73596ADADAD1533B831EEDAF489F1FCC1316E4494C9F161C4768FE5F449AB8BE1243B39CF3CD885429DB86B7995E0957715D83511FAEB69A44C7225D<br>07D1C95F152B367363080F26DA65A2CF7CE7FCA38622B3BBCEDD3CCB76AB3B64E6F01FC13FB5E9B4215C6EC3471763678A48FAA7CF7C0180274464B845E5<br>17439641C9A3690410E686D1B601</span> <br> <!-- !!! dont changing this !!! --> </div> </div> <!-- --> <div class="tabs"> <!--tab--> <div class="tab"> <div id="tab-content1" class="content"> <div class="text"> <!--text data --> <b>/!\ YOUR COMPANY NETWORK HAS BEEN PENETRATED /!\</b><br> <b>ALL YOUR IMPORTANT FILES HAVE BEEN ENCRYPTED!</b><br><br> YOUR FILES ARE SAFE! JUST MODIFIED ONLY. (RSA+AES) <br><br> ANY ATTEMPT TO RESTORE YOUR FILES WITH THIRD-PARTY SOFTWARE<br> WILL PERMENANTLY DESTROY YOUR FILE.<br> DO NOT MODIFY ENCRYPTED FILES. DO NOT RENAME ENCRYPTED FILES.<br><br> NO SOFTWARE AVAILABLE ON INTERNET CAN HELP YOU. WE ONLY HAVE<br> SOLUTION TO YOUR PROBLEM.<br><br> WE GATHERED HIGHLY CONFIDENTIAL/PERSORNAL DATA. THESE DATA<br> ARE CURRENTLY STORED ON A PRIVATE SERVER. THIS SERVER WILL BE<br> IMMEDIATELY DESTROYED AFTER YOUR PAYMENT. WE ONLY SEEK MONEY<br> AND DO NOT WANT TO DAMAGE YOUR REPUTATION. IF YOU DECIDE TO<br> NOT PAY, WE WILL RELEASE THIS DATA TO PUBLIC OR RE-SELLER.<br><br> YOU WILL CAN SEND US 2-3 NON-IMPORTANT FILES AND WE WILL<br> DECRYPT IT FOR FREE TO PROVE WE ARE ABLE TO GIVE YOUR FILES<br> BACK.<br><br> <!--text data --> <hr> <b>Contact us for price and get decryption software.</b><br><br> <a href="">http://gvlay6u4g53rxdi5.onion/21-Al9gJCAJ2fd8LgNEdEBLhNUw5QUOgJlP-JVMF20wIlKxlS7OrHBXpCbCONEIVsdhU</a><br> * Note that this server is available via Tor browser only<br><br> Follow the instructions to open the link:<br> 1. Type the addres "https://www.torproject.org" in your Internet browser. It opens the Tor site.<br> 2. Press "Download Tor", then press "Download Tor Browser Bundle", install and run it.<br> 3. Now you have Tor browser. In the Tor Browser open "{
offset: 0
success 0 0
1619345063.94411
NtWriteFile
file_handle: 0x000002f8
filepath: C:\Python27\DLLs\Recovery_Instructions.html
buffer: <html> <style type="text/css"> body { background-color: #f5f5f5; } h1, h3{ text-align: center; text-transform: uppercase; font-weight: normal; } /*---*/ .tabs1{ display: block; margin: auto; } .tabs1 .head{ text-align: center; float: top; padding: 0px; text-transform: uppercase; font-weight: normal; display: block; background: #81bef7; color: #DF0101; font-size: 30px; } .tabs1 .identi { font-size: 10px; text-align: center; float: top; padding: 15px; display: block; background: #81bef7; color: #DFDFDF; } .tabs .content { background: #f5f5f5; /*text-align: center;*/ color: #000000; padding: 25px 15px; font-size: 15px; font-weight: 400; line-height: 20px; } .tabs .content a { color: #df0130; font-size: 23px; font-style: italic; text-decoration: none; line-height: 35px; } .tabs .content .text{ padding: 25px; line-height: 1.2; } </style> <body> <div class="tabs1"> <div class="head" ><b>Your personal ID:</b></div> <div class="identi"> <span style="width:1000px; color: #ffffff; font-size: 10px;">96B15FC03DCA8D175790CC1A893EEB4568E36CF6777F6CE5568ECDD6C33CDC4DC3B8A0AEBE17D5659209E6C658CCE1BE380E6C5350653A8A972180DDF12A276C<br>AF73EB431A73371B04B5BC86AEAACC8E3FC88B2F0E84D9C76161510D333EBD7686343FD08363EBC6A4D72ECCB63DB9C57C7AA9679310D262EB981A91960D<br>69A70480CD61A2D1DA4976232C86AA805C5B4389E7C04A8C9F65D5F80755A928BA67A0B7D9B5C5CA24883A4D8F4BD33CDEC232E5EFAB57377DE59B168050<br>2696BCA82218CA139ED899AD3837F84CF746A6FE76077F43A9DAFE9540482DB1415DAFC5559354C7E40262E301797BE8C3846F42A90AB20A4DF3462C44EC<br>A25F788CBCA026EA628E63C223A27603710293A1DDF2CABDE3C276BA5C79066F5199B66174620070248310D761B7E4DE7AA3667D4273B71A26A82665E0A1<br>D468573772BFA7618599E04F5124F8B0FAD9B7D6DB0052484E499F049C2E5E400C836E66FE8027CA345FCF44A91BB58CD7077E46091938E100DDCA98E33E<br>015E73596ADADAD1533B831EEDAF489F1FCC1316E4494C9F161C4768FE5F449AB8BE1243B39CF3CD885429DB86B7995E0957715D83511FAEB69A44C7225D<br>07D1C95F152B367363080F26DA65A2CF7CE7FCA38622B3BBCEDD3CCB76AB3B64E6F01FC13FB5E9B4215C6EC3471763678A48FAA7CF7C0180274464B845E5<br>17439641C9A3690410E686D1B601</span> <br> <!-- !!! dont changing this !!! --> </div> </div> <!-- --> <div class="tabs"> <!--tab--> <div class="tab"> <div id="tab-content1" class="content"> <div class="text"> <!--text data --> <b>/!\ YOUR COMPANY NETWORK HAS BEEN PENETRATED /!\</b><br> <b>ALL YOUR IMPORTANT FILES HAVE BEEN ENCRYPTED!</b><br><br> YOUR FILES ARE SAFE! JUST MODIFIED ONLY. (RSA+AES) <br><br> ANY ATTEMPT TO RESTORE YOUR FILES WITH THIRD-PARTY SOFTWARE<br> WILL PERMENANTLY DESTROY YOUR FILE.<br> DO NOT MODIFY ENCRYPTED FILES. DO NOT RENAME ENCRYPTED FILES.<br><br> NO SOFTWARE AVAILABLE ON INTERNET CAN HELP YOU. WE ONLY HAVE<br> SOLUTION TO YOUR PROBLEM.<br><br> WE GATHERED HIGHLY CONFIDENTIAL/PERSORNAL DATA. THESE DATA<br> ARE CURRENTLY STORED ON A PRIVATE SERVER. THIS SERVER WILL BE<br> IMMEDIATELY DESTROYED AFTER YOUR PAYMENT. WE ONLY SEEK MONEY<br> AND DO NOT WANT TO DAMAGE YOUR REPUTATION. IF YOU DECIDE TO<br> NOT PAY, WE WILL RELEASE THIS DATA TO PUBLIC OR RE-SELLER.<br><br> YOU WILL CAN SEND US 2-3 NON-IMPORTANT FILES AND WE WILL<br> DECRYPT IT FOR FREE TO PROVE WE ARE ABLE TO GIVE YOUR FILES<br> BACK.<br><br> <!--text data --> <hr> <b>Contact us for price and get decryption software.</b><br><br> <a href="">http://gvlay6u4g53rxdi5.onion/21-Al9gJCAJ2fd8LgNEdEBLhNUw5QUOgJlP-JVMF20wIlKxlS7OrHBXpCbCONEIVsdhU</a><br> * Note that this server is available via Tor browser only<br><br> Follow the instructions to open the link:<br> 1. Type the addres "https://www.torproject.org" in your Internet browser. It opens the Tor site.<br> 2. Press "Download Tor", then press "Download Tor Browser Bundle", install and run it.<br> 3. Now you have Tor browser. In the Tor Browser open "{
offset: 0
success 0 0
1619345064.27211
NtWriteFile
file_handle: 0x00000290
filepath: C:\Python27\DLLs\Recovery_Instructions.html
buffer: <html> <style type="text/css"> body { background-color: #f5f5f5; } h1, h3{ text-align: center; text-transform: uppercase; font-weight: normal; } /*---*/ .tabs1{ display: block; margin: auto; } .tabs1 .head{ text-align: center; float: top; padding: 0px; text-transform: uppercase; font-weight: normal; display: block; background: #81bef7; color: #DF0101; font-size: 30px; } .tabs1 .identi { font-size: 10px; text-align: center; float: top; padding: 15px; display: block; background: #81bef7; color: #DFDFDF; } .tabs .content { background: #f5f5f5; /*text-align: center;*/ color: #000000; padding: 25px 15px; font-size: 15px; font-weight: 400; line-height: 20px; } .tabs .content a { color: #df0130; font-size: 23px; font-style: italic; text-decoration: none; line-height: 35px; } .tabs .content .text{ padding: 25px; line-height: 1.2; } </style> <body> <div class="tabs1"> <div class="head" ><b>Your personal ID:</b></div> <div class="identi"> <span style="width:1000px; color: #ffffff; font-size: 10px;">96B15FC03DCA8D175790CC1A893EEB4568E36CF6777F6CE5568ECDD6C33CDC4DC3B8A0AEBE17D5659209E6C658CCE1BE380E6C5350653A8A972180DDF12A276C<br>AF73EB431A73371B04B5BC86AEAACC8E3FC88B2F0E84D9C76161510D333EBD7686343FD08363EBC6A4D72ECCB63DB9C57C7AA9679310D262EB981A91960D<br>69A70480CD61A2D1DA4976232C86AA805C5B4389E7C04A8C9F65D5F80755A928BA67A0B7D9B5C5CA24883A4D8F4BD33CDEC232E5EFAB57377DE59B168050<br>2696BCA82218CA139ED899AD3837F84CF746A6FE76077F43A9DAFE9540482DB1415DAFC5559354C7E40262E301797BE8C3846F42A90AB20A4DF3462C44EC<br>A25F788CBCA026EA628E63C223A27603710293A1DDF2CABDE3C276BA5C79066F5199B66174620070248310D761B7E4DE7AA3667D4273B71A26A82665E0A1<br>D468573772BFA7618599E04F5124F8B0FAD9B7D6DB0052484E499F049C2E5E400C836E66FE8027CA345FCF44A91BB58CD7077E46091938E100DDCA98E33E<br>015E73596ADADAD1533B831EEDAF489F1FCC1316E4494C9F161C4768FE5F449AB8BE1243B39CF3CD885429DB86B7995E0957715D83511FAEB69A44C7225D<br>07D1C95F152B367363080F26DA65A2CF7CE7FCA38622B3BBCEDD3CCB76AB3B64E6F01FC13FB5E9B4215C6EC3471763678A48FAA7CF7C0180274464B845E5<br>17439641C9A3690410E686D1B601</span> <br> <!-- !!! dont changing this !!! --> </div> </div> <!-- --> <div class="tabs"> <!--tab--> <div class="tab"> <div id="tab-content1" class="content"> <div class="text"> <!--text data --> <b>/!\ YOUR COMPANY NETWORK HAS BEEN PENETRATED /!\</b><br> <b>ALL YOUR IMPORTANT FILES HAVE BEEN ENCRYPTED!</b><br><br> YOUR FILES ARE SAFE! JUST MODIFIED ONLY. (RSA+AES) <br><br> ANY ATTEMPT TO RESTORE YOUR FILES WITH THIRD-PARTY SOFTWARE<br> WILL PERMENANTLY DESTROY YOUR FILE.<br> DO NOT MODIFY ENCRYPTED FILES. DO NOT RENAME ENCRYPTED FILES.<br><br> NO SOFTWARE AVAILABLE ON INTERNET CAN HELP YOU. WE ONLY HAVE<br> SOLUTION TO YOUR PROBLEM.<br><br> WE GATHERED HIGHLY CONFIDENTIAL/PERSORNAL DATA. THESE DATA<br> ARE CURRENTLY STORED ON A PRIVATE SERVER. THIS SERVER WILL BE<br> IMMEDIATELY DESTROYED AFTER YOUR PAYMENT. WE ONLY SEEK MONEY<br> AND DO NOT WANT TO DAMAGE YOUR REPUTATION. IF YOU DECIDE TO<br> NOT PAY, WE WILL RELEASE THIS DATA TO PUBLIC OR RE-SELLER.<br><br> YOU WILL CAN SEND US 2-3 NON-IMPORTANT FILES AND WE WILL<br> DECRYPT IT FOR FREE TO PROVE WE ARE ABLE TO GIVE YOUR FILES<br> BACK.<br><br> <!--text data --> <hr> <b>Contact us for price and get decryption software.</b><br><br> <a href="">http://gvlay6u4g53rxdi5.onion/21-Al9gJCAJ2fd8LgNEdEBLhNUw5QUOgJlP-JVMF20wIlKxlS7OrHBXpCbCONEIVsdhU</a><br> * Note that this server is available via Tor browser only<br><br> Follow the instructions to open the link:<br> 1. Type the addres "https://www.torproject.org" in your Internet browser. It opens the Tor site.<br> 2. Press "Download Tor", then press "Download Tor Browser Bundle", install and run it.<br> 3. Now you have Tor browser. In the Tor Browser open "{
offset: 0
success 0 0
1619345064.42911
NtWriteFile
file_handle: 0x00000290
filepath: C:\Python27\DLLs\Recovery_Instructions.html
buffer: <html> <style type="text/css"> body { background-color: #f5f5f5; } h1, h3{ text-align: center; text-transform: uppercase; font-weight: normal; } /*---*/ .tabs1{ display: block; margin: auto; } .tabs1 .head{ text-align: center; float: top; padding: 0px; text-transform: uppercase; font-weight: normal; display: block; background: #81bef7; color: #DF0101; font-size: 30px; } .tabs1 .identi { font-size: 10px; text-align: center; float: top; padding: 15px; display: block; background: #81bef7; color: #DFDFDF; } .tabs .content { background: #f5f5f5; /*text-align: center;*/ color: #000000; padding: 25px 15px; font-size: 15px; font-weight: 400; line-height: 20px; } .tabs .content a { color: #df0130; font-size: 23px; font-style: italic; text-decoration: none; line-height: 35px; } .tabs .content .text{ padding: 25px; line-height: 1.2; } </style> <body> <div class="tabs1"> <div class="head" ><b>Your personal ID:</b></div> <div class="identi"> <span style="width:1000px; color: #ffffff; font-size: 10px;">96B15FC03DCA8D175790CC1A893EEB4568E36CF6777F6CE5568ECDD6C33CDC4DC3B8A0AEBE17D5659209E6C658CCE1BE380E6C5350653A8A972180DDF12A276C<br>AF73EB431A73371B04B5BC86AEAACC8E3FC88B2F0E84D9C76161510D333EBD7686343FD08363EBC6A4D72ECCB63DB9C57C7AA9679310D262EB981A91960D<br>69A70480CD61A2D1DA4976232C86AA805C5B4389E7C04A8C9F65D5F80755A928BA67A0B7D9B5C5CA24883A4D8F4BD33CDEC232E5EFAB57377DE59B168050<br>2696BCA82218CA139ED899AD3837F84CF746A6FE76077F43A9DAFE9540482DB1415DAFC5559354C7E40262E301797BE8C3846F42A90AB20A4DF3462C44EC<br>A25F788CBCA026EA628E63C223A27603710293A1DDF2CABDE3C276BA5C79066F5199B66174620070248310D761B7E4DE7AA3667D4273B71A26A82665E0A1<br>D468573772BFA7618599E04F5124F8B0FAD9B7D6DB0052484E499F049C2E5E400C836E66FE8027CA345FCF44A91BB58CD7077E46091938E100DDCA98E33E<br>015E73596ADADAD1533B831EEDAF489F1FCC1316E4494C9F161C4768FE5F449AB8BE1243B39CF3CD885429DB86B7995E0957715D83511FAEB69A44C7225D<br>07D1C95F152B367363080F26DA65A2CF7CE7FCA38622B3BBCEDD3CCB76AB3B64E6F01FC13FB5E9B4215C6EC3471763678A48FAA7CF7C0180274464B845E5<br>17439641C9A3690410E686D1B601</span> <br> <!-- !!! dont changing this !!! --> </div> </div> <!-- --> <div class="tabs"> <!--tab--> <div class="tab"> <div id="tab-content1" class="content"> <div class="text"> <!--text data --> <b>/!\ YOUR COMPANY NETWORK HAS BEEN PENETRATED /!\</b><br> <b>ALL YOUR IMPORTANT FILES HAVE BEEN ENCRYPTED!</b><br><br> YOUR FILES ARE SAFE! JUST MODIFIED ONLY. (RSA+AES) <br><br> ANY ATTEMPT TO RESTORE YOUR FILES WITH THIRD-PARTY SOFTWARE<br> WILL PERMENANTLY DESTROY YOUR FILE.<br> DO NOT MODIFY ENCRYPTED FILES. DO NOT RENAME ENCRYPTED FILES.<br><br> NO SOFTWARE AVAILABLE ON INTERNET CAN HELP YOU. WE ONLY HAVE<br> SOLUTION TO YOUR PROBLEM.<br><br> WE GATHERED HIGHLY CONFIDENTIAL/PERSORNAL DATA. THESE DATA<br> ARE CURRENTLY STORED ON A PRIVATE SERVER. THIS SERVER WILL BE<br> IMMEDIATELY DESTROYED AFTER YOUR PAYMENT. WE ONLY SEEK MONEY<br> AND DO NOT WANT TO DAMAGE YOUR REPUTATION. IF YOU DECIDE TO<br> NOT PAY, WE WILL RELEASE THIS DATA TO PUBLIC OR RE-SELLER.<br><br> YOU WILL CAN SEND US 2-3 NON-IMPORTANT FILES AND WE WILL<br> DECRYPT IT FOR FREE TO PROVE WE ARE ABLE TO GIVE YOUR FILES<br> BACK.<br><br> <!--text data --> <hr> <b>Contact us for price and get decryption software.</b><br><br> <a href="">http://gvlay6u4g53rxdi5.onion/21-Al9gJCAJ2fd8LgNEdEBLhNUw5QUOgJlP-JVMF20wIlKxlS7OrHBXpCbCONEIVsdhU</a><br> * Note that this server is available via Tor browser only<br><br> Follow the instructions to open the link:<br> 1. Type the addres "https://www.torproject.org" in your Internet browser. It opens the Tor site.<br> 2. Press "Download Tor", then press "Download Tor Browser Bundle", install and run it.<br> 3. Now you have Tor browser. In the Tor Browser open "{
offset: 0
success 0 0
1619345064.75711
NtWriteFile
file_handle: 0x00000270
filepath: C:\Python27\DLLs\Recovery_Instructions.html
buffer: <html> <style type="text/css"> body { background-color: #f5f5f5; } h1, h3{ text-align: center; text-transform: uppercase; font-weight: normal; } /*---*/ .tabs1{ display: block; margin: auto; } .tabs1 .head{ text-align: center; float: top; padding: 0px; text-transform: uppercase; font-weight: normal; display: block; background: #81bef7; color: #DF0101; font-size: 30px; } .tabs1 .identi { font-size: 10px; text-align: center; float: top; padding: 15px; display: block; background: #81bef7; color: #DFDFDF; } .tabs .content { background: #f5f5f5; /*text-align: center;*/ color: #000000; padding: 25px 15px; font-size: 15px; font-weight: 400; line-height: 20px; } .tabs .content a { color: #df0130; font-size: 23px; font-style: italic; text-decoration: none; line-height: 35px; } .tabs .content .text{ padding: 25px; line-height: 1.2; } </style> <body> <div class="tabs1"> <div class="head" ><b>Your personal ID:</b></div> <div class="identi"> <span style="width:1000px; color: #ffffff; font-size: 10px;">96B15FC03DCA8D175790CC1A893EEB4568E36CF6777F6CE5568ECDD6C33CDC4DC3B8A0AEBE17D5659209E6C658CCE1BE380E6C5350653A8A972180DDF12A276C<br>AF73EB431A73371B04B5BC86AEAACC8E3FC88B2F0E84D9C76161510D333EBD7686343FD08363EBC6A4D72ECCB63DB9C57C7AA9679310D262EB981A91960D<br>69A70480CD61A2D1DA4976232C86AA805C5B4389E7C04A8C9F65D5F80755A928BA67A0B7D9B5C5CA24883A4D8F4BD33CDEC232E5EFAB57377DE59B168050<br>2696BCA82218CA139ED899AD3837F84CF746A6FE76077F43A9DAFE9540482DB1415DAFC5559354C7E40262E301797BE8C3846F42A90AB20A4DF3462C44EC<br>A25F788CBCA026EA628E63C223A27603710293A1DDF2CABDE3C276BA5C79066F5199B66174620070248310D761B7E4DE7AA3667D4273B71A26A82665E0A1<br>D468573772BFA7618599E04F5124F8B0FAD9B7D6DB0052484E499F049C2E5E400C836E66FE8027CA345FCF44A91BB58CD7077E46091938E100DDCA98E33E<br>015E73596ADADAD1533B831EEDAF489F1FCC1316E4494C9F161C4768FE5F449AB8BE1243B39CF3CD885429DB86B7995E0957715D83511FAEB69A44C7225D<br>07D1C95F152B367363080F26DA65A2CF7CE7FCA38622B3BBCEDD3CCB76AB3B64E6F01FC13FB5E9B4215C6EC3471763678A48FAA7CF7C0180274464B845E5<br>17439641C9A3690410E686D1B601</span> <br> <!-- !!! dont changing this !!! --> </div> </div> <!-- --> <div class="tabs"> <!--tab--> <div class="tab"> <div id="tab-content1" class="content"> <div class="text"> <!--text data --> <b>/!\ YOUR COMPANY NETWORK HAS BEEN PENETRATED /!\</b><br> <b>ALL YOUR IMPORTANT FILES HAVE BEEN ENCRYPTED!</b><br><br> YOUR FILES ARE SAFE! JUST MODIFIED ONLY. (RSA+AES) <br><br> ANY ATTEMPT TO RESTORE YOUR FILES WITH THIRD-PARTY SOFTWARE<br> WILL PERMENANTLY DESTROY YOUR FILE.<br> DO NOT MODIFY ENCRYPTED FILES. DO NOT RENAME ENCRYPTED FILES.<br><br> NO SOFTWARE AVAILABLE ON INTERNET CAN HELP YOU. WE ONLY HAVE<br> SOLUTION TO YOUR PROBLEM.<br><br> WE GATHERED HIGHLY CONFIDENTIAL/PERSORNAL DATA. THESE DATA<br> ARE CURRENTLY STORED ON A PRIVATE SERVER. THIS SERVER WILL BE<br> IMMEDIATELY DESTROYED AFTER YOUR PAYMENT. WE ONLY SEEK MONEY<br> AND DO NOT WANT TO DAMAGE YOUR REPUTATION. IF YOU DECIDE TO<br> NOT PAY, WE WILL RELEASE THIS DATA TO PUBLIC OR RE-SELLER.<br><br> YOU WILL CAN SEND US 2-3 NON-IMPORTANT FILES AND WE WILL<br> DECRYPT IT FOR FREE TO PROVE WE ARE ABLE TO GIVE YOUR FILES<br> BACK.<br><br> <!--text data --> <hr> <b>Contact us for price and get decryption software.</b><br><br> <a href="">http://gvlay6u4g53rxdi5.onion/21-Al9gJCAJ2fd8LgNEdEBLhNUw5QUOgJlP-JVMF20wIlKxlS7OrHBXpCbCONEIVsdhU</a><br> * Note that this server is available via Tor browser only<br><br> Follow the instructions to open the link:<br> 1. Type the addres "https://www.torproject.org" in your Internet browser. It opens the Tor site.<br> 2. Press "Download Tor", then press "Download Tor Browser Bundle", install and run it.<br> 3. Now you have Tor browser. In the Tor Browser open "{
offset: 0
success 0 0
1619345065.06911
NtWriteFile
file_handle: 0x00000308
filepath: C:\Python27\DLLs\Recovery_Instructions.html
buffer: <html> <style type="text/css"> body { background-color: #f5f5f5; } h1, h3{ text-align: center; text-transform: uppercase; font-weight: normal; } /*---*/ .tabs1{ display: block; margin: auto; } .tabs1 .head{ text-align: center; float: top; padding: 0px; text-transform: uppercase; font-weight: normal; display: block; background: #81bef7; color: #DF0101; font-size: 30px; } .tabs1 .identi { font-size: 10px; text-align: center; float: top; padding: 15px; display: block; background: #81bef7; color: #DFDFDF; } .tabs .content { background: #f5f5f5; /*text-align: center;*/ color: #000000; padding: 25px 15px; font-size: 15px; font-weight: 400; line-height: 20px; } .tabs .content a { color: #df0130; font-size: 23px; font-style: italic; text-decoration: none; line-height: 35px; } .tabs .content .text{ padding: 25px; line-height: 1.2; } </style> <body> <div class="tabs1"> <div class="head" ><b>Your personal ID:</b></div> <div class="identi"> <span style="width:1000px; color: #ffffff; font-size: 10px;">96B15FC03DCA8D175790CC1A893EEB4568E36CF6777F6CE5568ECDD6C33CDC4DC3B8A0AEBE17D5659209E6C658CCE1BE380E6C5350653A8A972180DDF12A276C<br>AF73EB431A73371B04B5BC86AEAACC8E3FC88B2F0E84D9C76161510D333EBD7686343FD08363EBC6A4D72ECCB63DB9C57C7AA9679310D262EB981A91960D<br>69A70480CD61A2D1DA4976232C86AA805C5B4389E7C04A8C9F65D5F80755A928BA67A0B7D9B5C5CA24883A4D8F4BD33CDEC232E5EFAB57377DE59B168050<br>2696BCA82218CA139ED899AD3837F84CF746A6FE76077F43A9DAFE9540482DB1415DAFC5559354C7E40262E301797BE8C3846F42A90AB20A4DF3462C44EC<br>A25F788CBCA026EA628E63C223A27603710293A1DDF2CABDE3C276BA5C79066F5199B66174620070248310D761B7E4DE7AA3667D4273B71A26A82665E0A1<br>D468573772BFA7618599E04F5124F8B0FAD9B7D6DB0052484E499F049C2E5E400C836E66FE8027CA345FCF44A91BB58CD7077E46091938E100DDCA98E33E<br>015E73596ADADAD1533B831EEDAF489F1FCC1316E4494C9F161C4768FE5F449AB8BE1243B39CF3CD885429DB86B7995E0957715D83511FAEB69A44C7225D<br>07D1C95F152B367363080F26DA65A2CF7CE7FCA38622B3BBCEDD3CCB76AB3B64E6F01FC13FB5E9B4215C6EC3471763678A48FAA7CF7C0180274464B845E5<br>17439641C9A3690410E686D1B601</span> <br> <!-- !!! dont changing this !!! --> </div> </div> <!-- --> <div class="tabs"> <!--tab--> <div class="tab"> <div id="tab-content1" class="content"> <div class="text"> <!--text data --> <b>/!\ YOUR COMPANY NETWORK HAS BEEN PENETRATED /!\</b><br> <b>ALL YOUR IMPORTANT FILES HAVE BEEN ENCRYPTED!</b><br><br> YOUR FILES ARE SAFE! JUST MODIFIED ONLY. (RSA+AES) <br><br> ANY ATTEMPT TO RESTORE YOUR FILES WITH THIRD-PARTY SOFTWARE<br> WILL PERMENANTLY DESTROY YOUR FILE.<br> DO NOT MODIFY ENCRYPTED FILES. DO NOT RENAME ENCRYPTED FILES.<br><br> NO SOFTWARE AVAILABLE ON INTERNET CAN HELP YOU. WE ONLY HAVE<br> SOLUTION TO YOUR PROBLEM.<br><br> WE GATHERED HIGHLY CONFIDENTIAL/PERSORNAL DATA. THESE DATA<br> ARE CURRENTLY STORED ON A PRIVATE SERVER. THIS SERVER WILL BE<br> IMMEDIATELY DESTROYED AFTER YOUR PAYMENT. WE ONLY SEEK MONEY<br> AND DO NOT WANT TO DAMAGE YOUR REPUTATION. IF YOU DECIDE TO<br> NOT PAY, WE WILL RELEASE THIS DATA TO PUBLIC OR RE-SELLER.<br><br> YOU WILL CAN SEND US 2-3 NON-IMPORTANT FILES AND WE WILL<br> DECRYPT IT FOR FREE TO PROVE WE ARE ABLE TO GIVE YOUR FILES<br> BACK.<br><br> <!--text data --> <hr> <b>Contact us for price and get decryption software.</b><br><br> <a href="">http://gvlay6u4g53rxdi5.onion/21-Al9gJCAJ2fd8LgNEdEBLhNUw5QUOgJlP-JVMF20wIlKxlS7OrHBXpCbCONEIVsdhU</a><br> * Note that this server is available via Tor browser only<br><br> Follow the instructions to open the link:<br> 1. Type the addres "https://www.torproject.org" in your Internet browser. It opens the Tor site.<br> 2. Press "Download Tor", then press "Download Tor Browser Bundle", install and run it.<br> 3. Now you have Tor browser. In the Tor Browser open "{
offset: 0
success 0 0
1619345065.19411
NtWriteFile
file_handle: 0x00000308
filepath: C:\Python27\DLLs\Recovery_Instructions.html
buffer: <html> <style type="text/css"> body { background-color: #f5f5f5; } h1, h3{ text-align: center; text-transform: uppercase; font-weight: normal; } /*---*/ .tabs1{ display: block; margin: auto; } .tabs1 .head{ text-align: center; float: top; padding: 0px; text-transform: uppercase; font-weight: normal; display: block; background: #81bef7; color: #DF0101; font-size: 30px; } .tabs1 .identi { font-size: 10px; text-align: center; float: top; padding: 15px; display: block; background: #81bef7; color: #DFDFDF; } .tabs .content { background: #f5f5f5; /*text-align: center;*/ color: #000000; padding: 25px 15px; font-size: 15px; font-weight: 400; line-height: 20px; } .tabs .content a { color: #df0130; font-size: 23px; font-style: italic; text-decoration: none; line-height: 35px; } .tabs .content .text{ padding: 25px; line-height: 1.2; } </style> <body> <div class="tabs1"> <div class="head" ><b>Your personal ID:</b></div> <div class="identi"> <span style="width:1000px; color: #ffffff; font-size: 10px;">96B15FC03DCA8D175790CC1A893EEB4568E36CF6777F6CE5568ECDD6C33CDC4DC3B8A0AEBE17D5659209E6C658CCE1BE380E6C5350653A8A972180DDF12A276C<br>AF73EB431A73371B04B5BC86AEAACC8E3FC88B2F0E84D9C76161510D333EBD7686343FD08363EBC6A4D72ECCB63DB9C57C7AA9679310D262EB981A91960D<br>69A70480CD61A2D1DA4976232C86AA805C5B4389E7C04A8C9F65D5F80755A928BA67A0B7D9B5C5CA24883A4D8F4BD33CDEC232E5EFAB57377DE59B168050<br>2696BCA82218CA139ED899AD3837F84CF746A6FE76077F43A9DAFE9540482DB1415DAFC5559354C7E40262E301797BE8C3846F42A90AB20A4DF3462C44EC<br>A25F788CBCA026EA628E63C223A27603710293A1DDF2CABDE3C276BA5C79066F5199B66174620070248310D761B7E4DE7AA3667D4273B71A26A82665E0A1<br>D468573772BFA7618599E04F5124F8B0FAD9B7D6DB0052484E499F049C2E5E400C836E66FE8027CA345FCF44A91BB58CD7077E46091938E100DDCA98E33E<br>015E73596ADADAD1533B831EEDAF489F1FCC1316E4494C9F161C4768FE5F449AB8BE1243B39CF3CD885429DB86B7995E0957715D83511FAEB69A44C7225D<br>07D1C95F152B367363080F26DA65A2CF7CE7FCA38622B3BBCEDD3CCB76AB3B64E6F01FC13FB5E9B4215C6EC3471763678A48FAA7CF7C0180274464B845E5<br>17439641C9A3690410E686D1B601</span> <br> <!-- !!! dont changing this !!! --> </div> </div> <!-- --> <div class="tabs"> <!--tab--> <div class="tab"> <div id="tab-content1" class="content"> <div class="text"> <!--text data --> <b>/!\ YOUR COMPANY NETWORK HAS BEEN PENETRATED /!\</b><br> <b>ALL YOUR IMPORTANT FILES HAVE BEEN ENCRYPTED!</b><br><br> YOUR FILES ARE SAFE! JUST MODIFIED ONLY. (RSA+AES) <br><br> ANY ATTEMPT TO RESTORE YOUR FILES WITH THIRD-PARTY SOFTWARE<br> WILL PERMENANTLY DESTROY YOUR FILE.<br> DO NOT MODIFY ENCRYPTED FILES. DO NOT RENAME ENCRYPTED FILES.<br><br> NO SOFTWARE AVAILABLE ON INTERNET CAN HELP YOU. WE ONLY HAVE<br> SOLUTION TO YOUR PROBLEM.<br><br> WE GATHERED HIGHLY CONFIDENTIAL/PERSORNAL DATA. THESE DATA<br> ARE CURRENTLY STORED ON A PRIVATE SERVER. THIS SERVER WILL BE<br> IMMEDIATELY DESTROYED AFTER YOUR PAYMENT. WE ONLY SEEK MONEY<br> AND DO NOT WANT TO DAMAGE YOUR REPUTATION. IF YOU DECIDE TO<br> NOT PAY, WE WILL RELEASE THIS DATA TO PUBLIC OR RE-SELLER.<br><br> YOU WILL CAN SEND US 2-3 NON-IMPORTANT FILES AND WE WILL<br> DECRYPT IT FOR FREE TO PROVE WE ARE ABLE TO GIVE YOUR FILES<br> BACK.<br><br> <!--text data --> <hr> <b>Contact us for price and get decryption software.</b><br><br> <a href="">http://gvlay6u4g53rxdi5.onion/21-Al9gJCAJ2fd8LgNEdEBLhNUw5QUOgJlP-JVMF20wIlKxlS7OrHBXpCbCONEIVsdhU</a><br> * Note that this server is available via Tor browser only<br><br> Follow the instructions to open the link:<br> 1. Type the addres "https://www.torproject.org" in your Internet browser. It opens the Tor site.<br> 2. Press "Download Tor", then press "Download Tor Browser Bundle", install and run it.<br> 3. Now you have Tor browser. In the Tor Browser open "{
offset: 0
success 0 0
1619345066.91311
NtWriteFile
file_handle: 0x00000308
filepath: C:\Python27\Doc\Recovery_Instructions.html
buffer: <html> <style type="text/css"> body { background-color: #f5f5f5; } h1, h3{ text-align: center; text-transform: uppercase; font-weight: normal; } /*---*/ .tabs1{ display: block; margin: auto; } .tabs1 .head{ text-align: center; float: top; padding: 0px; text-transform: uppercase; font-weight: normal; display: block; background: #81bef7; color: #DF0101; font-size: 30px; } .tabs1 .identi { font-size: 10px; text-align: center; float: top; padding: 15px; display: block; background: #81bef7; color: #DFDFDF; } .tabs .content { background: #f5f5f5; /*text-align: center;*/ color: #000000; padding: 25px 15px; font-size: 15px; font-weight: 400; line-height: 20px; } .tabs .content a { color: #df0130; font-size: 23px; font-style: italic; text-decoration: none; line-height: 35px; } .tabs .content .text{ padding: 25px; line-height: 1.2; } </style> <body> <div class="tabs1"> <div class="head" ><b>Your personal ID:</b></div> <div class="identi"> <span style="width:1000px; color: #ffffff; font-size: 10px;">96B15FC03DCA8D175790CC1A893EEB4568E36CF6777F6CE5568ECDD6C33CDC4DC3B8A0AEBE17D5659209E6C658CCE1BE380E6C5350653A8A972180DDF12A276C<br>AF73EB431A73371B04B5BC86AEAACC8E3FC88B2F0E84D9C76161510D333EBD7686343FD08363EBC6A4D72ECCB63DB9C57C7AA9679310D262EB981A91960D<br>69A70480CD61A2D1DA4976232C86AA805C5B4389E7C04A8C9F65D5F80755A928BA67A0B7D9B5C5CA24883A4D8F4BD33CDEC232E5EFAB57377DE59B168050<br>2696BCA82218CA139ED899AD3837F84CF746A6FE76077F43A9DAFE9540482DB1415DAFC5559354C7E40262E301797BE8C3846F42A90AB20A4DF3462C44EC<br>A25F788CBCA026EA628E63C223A27603710293A1DDF2CABDE3C276BA5C79066F5199B66174620070248310D761B7E4DE7AA3667D4273B71A26A82665E0A1<br>D468573772BFA7618599E04F5124F8B0FAD9B7D6DB0052484E499F049C2E5E400C836E66FE8027CA345FCF44A91BB58CD7077E46091938E100DDCA98E33E<br>015E73596ADADAD1533B831EEDAF489F1FCC1316E4494C9F161C4768FE5F449AB8BE1243B39CF3CD885429DB86B7995E0957715D83511FAEB69A44C7225D<br>07D1C95F152B367363080F26DA65A2CF7CE7FCA38622B3BBCEDD3CCB76AB3B64E6F01FC13FB5E9B4215C6EC3471763678A48FAA7CF7C0180274464B845E5<br>17439641C9A3690410E686D1B601</span> <br> <!-- !!! dont changing this !!! --> </div> </div> <!-- --> <div class="tabs"> <!--tab--> <div class="tab"> <div id="tab-content1" class="content"> <div class="text"> <!--text data --> <b>/!\ YOUR COMPANY NETWORK HAS BEEN PENETRATED /!\</b><br> <b>ALL YOUR IMPORTANT FILES HAVE BEEN ENCRYPTED!</b><br><br> YOUR FILES ARE SAFE! JUST MODIFIED ONLY. (RSA+AES) <br><br> ANY ATTEMPT TO RESTORE YOUR FILES WITH THIRD-PARTY SOFTWARE<br> WILL PERMENANTLY DESTROY YOUR FILE.<br> DO NOT MODIFY ENCRYPTED FILES. DO NOT RENAME ENCRYPTED FILES.<br><br> NO SOFTWARE AVAILABLE ON INTERNET CAN HELP YOU. WE ONLY HAVE<br> SOLUTION TO YOUR PROBLEM.<br><br> WE GATHERED HIGHLY CONFIDENTIAL/PERSORNAL DATA. THESE DATA<br> ARE CURRENTLY STORED ON A PRIVATE SERVER. THIS SERVER WILL BE<br> IMMEDIATELY DESTROYED AFTER YOUR PAYMENT. WE ONLY SEEK MONEY<br> AND DO NOT WANT TO DAMAGE YOUR REPUTATION. IF YOU DECIDE TO<br> NOT PAY, WE WILL RELEASE THIS DATA TO PUBLIC OR RE-SELLER.<br><br> YOU WILL CAN SEND US 2-3 NON-IMPORTANT FILES AND WE WILL<br> DECRYPT IT FOR FREE TO PROVE WE ARE ABLE TO GIVE YOUR FILES<br> BACK.<br><br> <!--text data --> <hr> <b>Contact us for price and get decryption software.</b><br><br> <a href="">http://gvlay6u4g53rxdi5.onion/21-Al9gJCAJ2fd8LgNEdEBLhNUw5QUOgJlP-JVMF20wIlKxlS7OrHBXpCbCONEIVsdhU</a><br> * Note that this server is available via Tor browser only<br><br> Follow the instructions to open the link:<br> 1. Type the addres "https://www.torproject.org" in your Internet browser. It opens the Tor site.<br> 2. Press "Download Tor", then press "Download Tor Browser Bundle", install and run it.<br> 3. Now you have Tor browser. In the Tor Browser open "{
offset: 0
success 0 0
1619345067.06911
NtWriteFile
file_handle: 0x00000308
filepath: C:\Python27\include\Recovery_Instructions.html
buffer: <html> <style type="text/css"> body { background-color: #f5f5f5; } h1, h3{ text-align: center; text-transform: uppercase; font-weight: normal; } /*---*/ .tabs1{ display: block; margin: auto; } .tabs1 .head{ text-align: center; float: top; padding: 0px; text-transform: uppercase; font-weight: normal; display: block; background: #81bef7; color: #DF0101; font-size: 30px; } .tabs1 .identi { font-size: 10px; text-align: center; float: top; padding: 15px; display: block; background: #81bef7; color: #DFDFDF; } .tabs .content { background: #f5f5f5; /*text-align: center;*/ color: #000000; padding: 25px 15px; font-size: 15px; font-weight: 400; line-height: 20px; } .tabs .content a { color: #df0130; font-size: 23px; font-style: italic; text-decoration: none; line-height: 35px; } .tabs .content .text{ padding: 25px; line-height: 1.2; } </style> <body> <div class="tabs1"> <div class="head" ><b>Your personal ID:</b></div> <div class="identi"> <span style="width:1000px; color: #ffffff; font-size: 10px;">96B15FC03DCA8D175790CC1A893EEB4568E36CF6777F6CE5568ECDD6C33CDC4DC3B8A0AEBE17D5659209E6C658CCE1BE380E6C5350653A8A972180DDF12A276C<br>AF73EB431A73371B04B5BC86AEAACC8E3FC88B2F0E84D9C76161510D333EBD7686343FD08363EBC6A4D72ECCB63DB9C57C7AA9679310D262EB981A91960D<br>69A70480CD61A2D1DA4976232C86AA805C5B4389E7C04A8C9F65D5F80755A928BA67A0B7D9B5C5CA24883A4D8F4BD33CDEC232E5EFAB57377DE59B168050<br>2696BCA82218CA139ED899AD3837F84CF746A6FE76077F43A9DAFE9540482DB1415DAFC5559354C7E40262E301797BE8C3846F42A90AB20A4DF3462C44EC<br>A25F788CBCA026EA628E63C223A27603710293A1DDF2CABDE3C276BA5C79066F5199B66174620070248310D761B7E4DE7AA3667D4273B71A26A82665E0A1<br>D468573772BFA7618599E04F5124F8B0FAD9B7D6DB0052484E499F049C2E5E400C836E66FE8027CA345FCF44A91BB58CD7077E46091938E100DDCA98E33E<br>015E73596ADADAD1533B831EEDAF489F1FCC1316E4494C9F161C4768FE5F449AB8BE1243B39CF3CD885429DB86B7995E0957715D83511FAEB69A44C7225D<br>07D1C95F152B367363080F26DA65A2CF7CE7FCA38622B3BBCEDD3CCB76AB3B64E6F01FC13FB5E9B4215C6EC3471763678A48FAA7CF7C0180274464B845E5<br>17439641C9A3690410E686D1B601</span> <br> <!-- !!! dont changing this !!! --> </div> </div> <!-- --> <div class="tabs"> <!--tab--> <div class="tab"> <div id="tab-content1" class="content"> <div class="text"> <!--text data --> <b>/!\ YOUR COMPANY NETWORK HAS BEEN PENETRATED /!\</b><br> <b>ALL YOUR IMPORTANT FILES HAVE BEEN ENCRYPTED!</b><br><br> YOUR FILES ARE SAFE! JUST MODIFIED ONLY. (RSA+AES) <br><br> ANY ATTEMPT TO RESTORE YOUR FILES WITH THIRD-PARTY SOFTWARE<br> WILL PERMENANTLY DESTROY YOUR FILE.<br> DO NOT MODIFY ENCRYPTED FILES. DO NOT RENAME ENCRYPTED FILES.<br><br> NO SOFTWARE AVAILABLE ON INTERNET CAN HELP YOU. WE ONLY HAVE<br> SOLUTION TO YOUR PROBLEM.<br><br> WE GATHERED HIGHLY CONFIDENTIAL/PERSORNAL DATA. THESE DATA<br> ARE CURRENTLY STORED ON A PRIVATE SERVER. THIS SERVER WILL BE<br> IMMEDIATELY DESTROYED AFTER YOUR PAYMENT. WE ONLY SEEK MONEY<br> AND DO NOT WANT TO DAMAGE YOUR REPUTATION. IF YOU DECIDE TO<br> NOT PAY, WE WILL RELEASE THIS DATA TO PUBLIC OR RE-SELLER.<br><br> YOU WILL CAN SEND US 2-3 NON-IMPORTANT FILES AND WE WILL<br> DECRYPT IT FOR FREE TO PROVE WE ARE ABLE TO GIVE YOUR FILES<br> BACK.<br><br> <!--text data --> <hr> <b>Contact us for price and get decryption software.</b><br><br> <a href="">http://gvlay6u4g53rxdi5.onion/21-Al9gJCAJ2fd8LgNEdEBLhNUw5QUOgJlP-JVMF20wIlKxlS7OrHBXpCbCONEIVsdhU</a><br> * Note that this server is available via Tor browser only<br><br> Follow the instructions to open the link:<br> 1. Type the addres "https://www.torproject.org" in your Internet browser. It opens the Tor site.<br> 2. Press "Download Tor", then press "Download Tor Browser Bundle", install and run it.<br> 3. Now you have Tor browser. In the Tor Browser open "{
offset: 0
success 0 0
1619345067.21011
NtWriteFile
file_handle: 0x00000130
filepath: C:\Python27\include\Recovery_Instructions.html
buffer: <html> <style type="text/css"> body { background-color: #f5f5f5; } h1, h3{ text-align: center; text-transform: uppercase; font-weight: normal; } /*---*/ .tabs1{ display: block; margin: auto; } .tabs1 .head{ text-align: center; float: top; padding: 0px; text-transform: uppercase; font-weight: normal; display: block; background: #81bef7; color: #DF0101; font-size: 30px; } .tabs1 .identi { font-size: 10px; text-align: center; float: top; padding: 15px; display: block; background: #81bef7; color: #DFDFDF; } .tabs .content { background: #f5f5f5; /*text-align: center;*/ color: #000000; padding: 25px 15px; font-size: 15px; font-weight: 400; line-height: 20px; } .tabs .content a { color: #df0130; font-size: 23px; font-style: italic; text-decoration: none; line-height: 35px; } .tabs .content .text{ padding: 25px; line-height: 1.2; } </style> <body> <div class="tabs1"> <div class="head" ><b>Your personal ID:</b></div> <div class="identi"> <span style="width:1000px; color: #ffffff; font-size: 10px;">96B15FC03DCA8D175790CC1A893EEB4568E36CF6777F6CE5568ECDD6C33CDC4DC3B8A0AEBE17D5659209E6C658CCE1BE380E6C5350653A8A972180DDF12A276C<br>AF73EB431A73371B04B5BC86AEAACC8E3FC88B2F0E84D9C76161510D333EBD7686343FD08363EBC6A4D72ECCB63DB9C57C7AA9679310D262EB981A91960D<br>69A70480CD61A2D1DA4976232C86AA805C5B4389E7C04A8C9F65D5F80755A928BA67A0B7D9B5C5CA24883A4D8F4BD33CDEC232E5EFAB57377DE59B168050<br>2696BCA82218CA139ED899AD3837F84CF746A6FE76077F43A9DAFE9540482DB1415DAFC5559354C7E40262E301797BE8C3846F42A90AB20A4DF3462C44EC<br>A25F788CBCA026EA628E63C223A27603710293A1DDF2CABDE3C276BA5C79066F5199B66174620070248310D761B7E4DE7AA3667D4273B71A26A82665E0A1<br>D468573772BFA7618599E04F5124F8B0FAD9B7D6DB0052484E499F049C2E5E400C836E66FE8027CA345FCF44A91BB58CD7077E46091938E100DDCA98E33E<br>015E73596ADADAD1533B831EEDAF489F1FCC1316E4494C9F161C4768FE5F449AB8BE1243B39CF3CD885429DB86B7995E0957715D83511FAEB69A44C7225D<br>07D1C95F152B367363080F26DA65A2CF7CE7FCA38622B3BBCEDD3CCB76AB3B64E6F01FC13FB5E9B4215C6EC3471763678A48FAA7CF7C0180274464B845E5<br>17439641C9A3690410E686D1B601</span> <br> <!-- !!! dont changing this !!! --> </div> </div> <!-- --> <div class="tabs"> <!--tab--> <div class="tab"> <div id="tab-content1" class="content"> <div class="text"> <!--text data --> <b>/!\ YOUR COMPANY NETWORK HAS BEEN PENETRATED /!\</b><br> <b>ALL YOUR IMPORTANT FILES HAVE BEEN ENCRYPTED!</b><br><br> YOUR FILES ARE SAFE! JUST MODIFIED ONLY. (RSA+AES) <br><br> ANY ATTEMPT TO RESTORE YOUR FILES WITH THIRD-PARTY SOFTWARE<br> WILL PERMENANTLY DESTROY YOUR FILE.<br> DO NOT MODIFY ENCRYPTED FILES. DO NOT RENAME ENCRYPTED FILES.<br><br> NO SOFTWARE AVAILABLE ON INTERNET CAN HELP YOU. WE ONLY HAVE<br> SOLUTION TO YOUR PROBLEM.<br><br> WE GATHERED HIGHLY CONFIDENTIAL/PERSORNAL DATA. THESE DATA<br> ARE CURRENTLY STORED ON A PRIVATE SERVER. THIS SERVER WILL BE<br> IMMEDIATELY DESTROYED AFTER YOUR PAYMENT. WE ONLY SEEK MONEY<br> AND DO NOT WANT TO DAMAGE YOUR REPUTATION. IF YOU DECIDE TO<br> NOT PAY, WE WILL RELEASE THIS DATA TO PUBLIC OR RE-SELLER.<br><br> YOU WILL CAN SEND US 2-3 NON-IMPORTANT FILES AND WE WILL<br> DECRYPT IT FOR FREE TO PROVE WE ARE ABLE TO GIVE YOUR FILES<br> BACK.<br><br> <!--text data --> <hr> <b>Contact us for price and get decryption software.</b><br><br> <a href="">http://gvlay6u4g53rxdi5.onion/21-Al9gJCAJ2fd8LgNEdEBLhNUw5QUOgJlP-JVMF20wIlKxlS7OrHBXpCbCONEIVsdhU</a><br> * Note that this server is available via Tor browser only<br><br> Follow the instructions to open the link:<br> 1. Type the addres "https://www.torproject.org" in your Internet browser. It opens the Tor site.<br> 2. Press "Download Tor", then press "Download Tor Browser Bundle", install and run it.<br> 3. Now you have Tor browser. In the Tor Browser open "{
offset: 0
success 0 0
1619345067.36611
NtWriteFile
file_handle: 0x00000130
filepath: C:\Python27\include\Recovery_Instructions.html
buffer: <html> <style type="text/css"> body { background-color: #f5f5f5; } h1, h3{ text-align: center; text-transform: uppercase; font-weight: normal; } /*---*/ .tabs1{ display: block; margin: auto; } .tabs1 .head{ text-align: center; float: top; padding: 0px; text-transform: uppercase; font-weight: normal; display: block; background: #81bef7; color: #DF0101; font-size: 30px; } .tabs1 .identi { font-size: 10px; text-align: center; float: top; padding: 15px; display: block; background: #81bef7; color: #DFDFDF; } .tabs .content { background: #f5f5f5; /*text-align: center;*/ color: #000000; padding: 25px 15px; font-size: 15px; font-weight: 400; line-height: 20px; } .tabs .content a { color: #df0130; font-size: 23px; font-style: italic; text-decoration: none; line-height: 35px; } .tabs .content .text{ padding: 25px; line-height: 1.2; } </style> <body> <div class="tabs1"> <div class="head" ><b>Your personal ID:</b></div> <div class="identi"> <span style="width:1000px; color: #ffffff; font-size: 10px;">96B15FC03DCA8D175790CC1A893EEB4568E36CF6777F6CE5568ECDD6C33CDC4DC3B8A0AEBE17D5659209E6C658CCE1BE380E6C5350653A8A972180DDF12A276C<br>AF73EB431A73371B04B5BC86AEAACC8E3FC88B2F0E84D9C76161510D333EBD7686343FD08363EBC6A4D72ECCB63DB9C57C7AA9679310D262EB981A91960D<br>69A70480CD61A2D1DA4976232C86AA805C5B4389E7C04A8C9F65D5F80755A928BA67A0B7D9B5C5CA24883A4D8F4BD33CDEC232E5EFAB57377DE59B168050<br>2696BCA82218CA139ED899AD3837F84CF746A6FE76077F43A9DAFE9540482DB1415DAFC5559354C7E40262E301797BE8C3846F42A90AB20A4DF3462C44EC<br>A25F788CBCA026EA628E63C223A27603710293A1DDF2CABDE3C276BA5C79066F5199B66174620070248310D761B7E4DE7AA3667D4273B71A26A82665E0A1<br>D468573772BFA7618599E04F5124F8B0FAD9B7D6DB0052484E499F049C2E5E400C836E66FE8027CA345FCF44A91BB58CD7077E46091938E100DDCA98E33E<br>015E73596ADADAD1533B831EEDAF489F1FCC1316E4494C9F161C4768FE5F449AB8BE1243B39CF3CD885429DB86B7995E0957715D83511FAEB69A44C7225D<br>07D1C95F152B367363080F26DA65A2CF7CE7FCA38622B3BBCEDD3CCB76AB3B64E6F01FC13FB5E9B4215C6EC3471763678A48FAA7CF7C0180274464B845E5<br>17439641C9A3690410E686D1B601</span> <br> <!-- !!! dont changing this !!! --> </div> </div> <!-- --> <div class="tabs"> <!--tab--> <div class="tab"> <div id="tab-content1" class="content"> <div class="text"> <!--text data --> <b>/!\ YOUR COMPANY NETWORK HAS BEEN PENETRATED /!\</b><br> <b>ALL YOUR IMPORTANT FILES HAVE BEEN ENCRYPTED!</b><br><br> YOUR FILES ARE SAFE! JUST MODIFIED ONLY. (RSA+AES) <br><br> ANY ATTEMPT TO RESTORE YOUR FILES WITH THIRD-PARTY SOFTWARE<br> WILL PERMENANTLY DESTROY YOUR FILE.<br> DO NOT MODIFY ENCRYPTED FILES. DO NOT RENAME ENCRYPTED FILES.<br><br> NO SOFTWARE AVAILABLE ON INTERNET CAN HELP YOU. WE ONLY HAVE<br> SOLUTION TO YOUR PROBLEM.<br><br> WE GATHERED HIGHLY CONFIDENTIAL/PERSORNAL DATA. THESE DATA<br> ARE CURRENTLY STORED ON A PRIVATE SERVER. THIS SERVER WILL BE<br> IMMEDIATELY DESTROYED AFTER YOUR PAYMENT. WE ONLY SEEK MONEY<br> AND DO NOT WANT TO DAMAGE YOUR REPUTATION. IF YOU DECIDE TO<br> NOT PAY, WE WILL RELEASE THIS DATA TO PUBLIC OR RE-SELLER.<br><br> YOU WILL CAN SEND US 2-3 NON-IMPORTANT FILES AND WE WILL<br> DECRYPT IT FOR FREE TO PROVE WE ARE ABLE TO GIVE YOUR FILES<br> BACK.<br><br> <!--text data --> <hr> <b>Contact us for price and get decryption software.</b><br><br> <a href="">http://gvlay6u4g53rxdi5.onion/21-Al9gJCAJ2fd8LgNEdEBLhNUw5QUOgJlP-JVMF20wIlKxlS7OrHBXpCbCONEIVsdhU</a><br> * Note that this server is available via Tor browser only<br><br> Follow the instructions to open the link:<br> 1. Type the addres "https://www.torproject.org" in your Internet browser. It opens the Tor site.<br> 2. Press "Download Tor", then press "Download Tor Browser Bundle", install and run it.<br> 3. Now you have Tor browser. In the Tor Browser open "{
offset: 0
success 0 0
1619345067.50711
NtWriteFile
file_handle: 0x00000130
filepath: C:\Python27\include\Recovery_Instructions.html
buffer: <html> <style type="text/css"> body { background-color: #f5f5f5; } h1, h3{ text-align: center; text-transform: uppercase; font-weight: normal; } /*---*/ .tabs1{ display: block; margin: auto; } .tabs1 .head{ text-align: center; float: top; padding: 0px; text-transform: uppercase; font-weight: normal; display: block; background: #81bef7; color: #DF0101; font-size: 30px; } .tabs1 .identi { font-size: 10px; text-align: center; float: top; padding: 15px; display: block; background: #81bef7; color: #DFDFDF; } .tabs .content { background: #f5f5f5; /*text-align: center;*/ color: #000000; padding: 25px 15px; font-size: 15px; font-weight: 400; line-height: 20px; } .tabs .content a { color: #df0130; font-size: 23px; font-style: italic; text-decoration: none; line-height: 35px; } .tabs .content .text{ padding: 25px; line-height: 1.2; } </style> <body> <div class="tabs1"> <div class="head" ><b>Your personal ID:</b></div> <div class="identi"> <span style="width:1000px; color: #ffffff; font-size: 10px;">96B15FC03DCA8D175790CC1A893EEB4568E36CF6777F6CE5568ECDD6C33CDC4DC3B8A0AEBE17D5659209E6C658CCE1BE380E6C5350653A8A972180DDF12A276C<br>AF73EB431A73371B04B5BC86AEAACC8E3FC88B2F0E84D9C76161510D333EBD7686343FD08363EBC6A4D72ECCB63DB9C57C7AA9679310D262EB981A91960D<br>69A70480CD61A2D1DA4976232C86AA805C5B4389E7C04A8C9F65D5F80755A928BA67A0B7D9B5C5CA24883A4D8F4BD33CDEC232E5EFAB57377DE59B168050<br>2696BCA82218CA139ED899AD3837F84CF746A6FE76077F43A9DAFE9540482DB1415DAFC5559354C7E40262E301797BE8C3846F42A90AB20A4DF3462C44EC<br>A25F788CBCA026EA628E63C223A27603710293A1DDF2CABDE3C276BA5C79066F5199B66174620070248310D761B7E4DE7AA3667D4273B71A26A82665E0A1<br>D468573772BFA7618599E04F5124F8B0FAD9B7D6DB0052484E499F049C2E5E400C836E66FE8027CA345FCF44A91BB58CD7077E46091938E100DDCA98E33E<br>015E73596ADADAD1533B831EEDAF489F1FCC1316E4494C9F161C4768FE5F449AB8BE1243B39CF3CD885429DB86B7995E0957715D83511FAEB69A44C7225D<br>07D1C95F152B367363080F26DA65A2CF7CE7FCA38622B3BBCEDD3CCB76AB3B64E6F01FC13FB5E9B4215C6EC3471763678A48FAA7CF7C0180274464B845E5<br>17439641C9A3690410E686D1B601</span> <br> <!-- !!! dont changing this !!! --> </div> </div> <!-- --> <div class="tabs"> <!--tab--> <div class="tab"> <div id="tab-content1" class="content"> <div class="text"> <!--text data --> <b>/!\ YOUR COMPANY NETWORK HAS BEEN PENETRATED /!\</b><br> <b>ALL YOUR IMPORTANT FILES HAVE BEEN ENCRYPTED!</b><br><br> YOUR FILES ARE SAFE! JUST MODIFIED ONLY. (RSA+AES) <br><br> ANY ATTEMPT TO RESTORE YOUR FILES WITH THIRD-PARTY SOFTWARE<br> WILL PERMENANTLY DESTROY YOUR FILE.<br> DO NOT MODIFY ENCRYPTED FILES. DO NOT RENAME ENCRYPTED FILES.<br><br> NO SOFTWARE AVAILABLE ON INTERNET CAN HELP YOU. WE ONLY HAVE<br> SOLUTION TO YOUR PROBLEM.<br><br> WE GATHERED HIGHLY CONFIDENTIAL/PERSORNAL DATA. THESE DATA<br> ARE CURRENTLY STORED ON A PRIVATE SERVER. THIS SERVER WILL BE<br> IMMEDIATELY DESTROYED AFTER YOUR PAYMENT. WE ONLY SEEK MONEY<br> AND DO NOT WANT TO DAMAGE YOUR REPUTATION. IF YOU DECIDE TO<br> NOT PAY, WE WILL RELEASE THIS DATA TO PUBLIC OR RE-SELLER.<br><br> YOU WILL CAN SEND US 2-3 NON-IMPORTANT FILES AND WE WILL<br> DECRYPT IT FOR FREE TO PROVE WE ARE ABLE TO GIVE YOUR FILES<br> BACK.<br><br> <!--text data --> <hr> <b>Contact us for price and get decryption software.</b><br><br> <a href="">http://gvlay6u4g53rxdi5.onion/21-Al9gJCAJ2fd8LgNEdEBLhNUw5QUOgJlP-JVMF20wIlKxlS7OrHBXpCbCONEIVsdhU</a><br> * Note that this server is available via Tor browser only<br><br> Follow the instructions to open the link:<br> 1. Type the addres "https://www.torproject.org" in your Internet browser. It opens the Tor site.<br> 2. Press "Download Tor", then press "Download Tor Browser Bundle", install and run it.<br> 3. Now you have Tor browser. In the Tor Browser open "{
offset: 0
success 0 0
1619345067.67911
NtWriteFile
file_handle: 0x00000130
filepath: C:\Python27\include\Recovery_Instructions.html
buffer: <html> <style type="text/css"> body { background-color: #f5f5f5; } h1, h3{ text-align: center; text-transform: uppercase; font-weight: normal; } /*---*/ .tabs1{ display: block; margin: auto; } .tabs1 .head{ text-align: center; float: top; padding: 0px; text-transform: uppercase; font-weight: normal; display: block; background: #81bef7; color: #DF0101; font-size: 30px; } .tabs1 .identi { font-size: 10px; text-align: center; float: top; padding: 15px; display: block; background: #81bef7; color: #DFDFDF; } .tabs .content { background: #f5f5f5; /*text-align: center;*/ color: #000000; padding: 25px 15px; font-size: 15px; font-weight: 400; line-height: 20px; } .tabs .content a { color: #df0130; font-size: 23px; font-style: italic; text-decoration: none; line-height: 35px; } .tabs .content .text{ padding: 25px; line-height: 1.2; } </style> <body> <div class="tabs1"> <div class="head" ><b>Your personal ID:</b></div> <div class="identi"> <span style="width:1000px; color: #ffffff; font-size: 10px;">96B15FC03DCA8D175790CC1A893EEB4568E36CF6777F6CE5568ECDD6C33CDC4DC3B8A0AEBE17D5659209E6C658CCE1BE380E6C5350653A8A972180DDF12A276C<br>AF73EB431A73371B04B5BC86AEAACC8E3FC88B2F0E84D9C76161510D333EBD7686343FD08363EBC6A4D72ECCB63DB9C57C7AA9679310D262EB981A91960D<br>69A70480CD61A2D1DA4976232C86AA805C5B4389E7C04A8C9F65D5F80755A928BA67A0B7D9B5C5CA24883A4D8F4BD33CDEC232E5EFAB57377DE59B168050<br>2696BCA82218CA139ED899AD3837F84CF746A6FE76077F43A9DAFE9540482DB1415DAFC5559354C7E40262E301797BE8C3846F42A90AB20A4DF3462C44EC<br>A25F788CBCA026EA628E63C223A27603710293A1DDF2CABDE3C276BA5C79066F5199B66174620070248310D761B7E4DE7AA3667D4273B71A26A82665E0A1<br>D468573772BFA7618599E04F5124F8B0FAD9B7D6DB0052484E499F049C2E5E400C836E66FE8027CA345FCF44A91BB58CD7077E46091938E100DDCA98E33E<br>015E73596ADADAD1533B831EEDAF489F1FCC1316E4494C9F161C4768FE5F449AB8BE1243B39CF3CD885429DB86B7995E0957715D83511FAEB69A44C7225D<br>07D1C95F152B367363080F26DA65A2CF7CE7FCA38622B3BBCEDD3CCB76AB3B64E6F01FC13FB5E9B4215C6EC3471763678A48FAA7CF7C0180274464B845E5<br>17439641C9A3690410E686D1B601</span> <br> <!-- !!! dont changing this !!! --> </div> </div> <!-- --> <div class="tabs"> <!--tab--> <div class="tab"> <div id="tab-content1" class="content"> <div class="text"> <!--text data --> <b>/!\ YOUR COMPANY NETWORK HAS BEEN PENETRATED /!\</b><br> <b>ALL YOUR IMPORTANT FILES HAVE BEEN ENCRYPTED!</b><br><br> YOUR FILES ARE SAFE! JUST MODIFIED ONLY. (RSA+AES) <br><br> ANY ATTEMPT TO RESTORE YOUR FILES WITH THIRD-PARTY SOFTWARE<br> WILL PERMENANTLY DESTROY YOUR FILE.<br> DO NOT MODIFY ENCRYPTED FILES. DO NOT RENAME ENCRYPTED FILES.<br><br> NO SOFTWARE AVAILABLE ON INTERNET CAN HELP YOU. WE ONLY HAVE<br> SOLUTION TO YOUR PROBLEM.<br><br> WE GATHERED HIGHLY CONFIDENTIAL/PERSORNAL DATA. THESE DATA<br> ARE CURRENTLY STORED ON A PRIVATE SERVER. THIS SERVER WILL BE<br> IMMEDIATELY DESTROYED AFTER YOUR PAYMENT. WE ONLY SEEK MONEY<br> AND DO NOT WANT TO DAMAGE YOUR REPUTATION. IF YOU DECIDE TO<br> NOT PAY, WE WILL RELEASE THIS DATA TO PUBLIC OR RE-SELLER.<br><br> YOU WILL CAN SEND US 2-3 NON-IMPORTANT FILES AND WE WILL<br> DECRYPT IT FOR FREE TO PROVE WE ARE ABLE TO GIVE YOUR FILES<br> BACK.<br><br> <!--text data --> <hr> <b>Contact us for price and get decryption software.</b><br><br> <a href="">http://gvlay6u4g53rxdi5.onion/21-Al9gJCAJ2fd8LgNEdEBLhNUw5QUOgJlP-JVMF20wIlKxlS7OrHBXpCbCONEIVsdhU</a><br> * Note that this server is available via Tor browser only<br><br> Follow the instructions to open the link:<br> 1. Type the addres "https://www.torproject.org" in your Internet browser. It opens the Tor site.<br> 2. Press "Download Tor", then press "Download Tor Browser Bundle", install and run it.<br> 3. Now you have Tor browser. In the Tor Browser open "{
offset: 0
success 0 0
1619345067.81911
NtWriteFile
file_handle: 0x00000130
filepath: C:\Python27\include\Recovery_Instructions.html
buffer: <html> <style type="text/css"> body { background-color: #f5f5f5; } h1, h3{ text-align: center; text-transform: uppercase; font-weight: normal; } /*---*/ .tabs1{ display: block; margin: auto; } .tabs1 .head{ text-align: center; float: top; padding: 0px; text-transform: uppercase; font-weight: normal; display: block; background: #81bef7; color: #DF0101; font-size: 30px; } .tabs1 .identi { font-size: 10px; text-align: center; float: top; padding: 15px; display: block; background: #81bef7; color: #DFDFDF; } .tabs .content { background: #f5f5f5; /*text-align: center;*/ color: #000000; padding: 25px 15px; font-size: 15px; font-weight: 400; line-height: 20px; } .tabs .content a { color: #df0130; font-size: 23px; font-style: italic; text-decoration: none; line-height: 35px; } .tabs .content .text{ padding: 25px; line-height: 1.2; } </style> <body> <div class="tabs1"> <div class="head" ><b>Your personal ID:</b></div> <div class="identi"> <span style="width:1000px; color: #ffffff; font-size: 10px;">96B15FC03DCA8D175790CC1A893EEB4568E36CF6777F6CE5568ECDD6C33CDC4DC3B8A0AEBE17D5659209E6C658CCE1BE380E6C5350653A8A972180DDF12A276C<br>AF73EB431A73371B04B5BC86AEAACC8E3FC88B2F0E84D9C76161510D333EBD7686343FD08363EBC6A4D72ECCB63DB9C57C7AA9679310D262EB981A91960D<br>69A70480CD61A2D1DA4976232C86AA805C5B4389E7C04A8C9F65D5F80755A928BA67A0B7D9B5C5CA24883A4D8F4BD33CDEC232E5EFAB57377DE59B168050<br>2696BCA82218CA139ED899AD3837F84CF746A6FE76077F43A9DAFE9540482DB1415DAFC5559354C7E40262E301797BE8C3846F42A90AB20A4DF3462C44EC<br>A25F788CBCA026EA628E63C223A27603710293A1DDF2CABDE3C276BA5C79066F5199B66174620070248310D761B7E4DE7AA3667D4273B71A26A82665E0A1<br>D468573772BFA7618599E04F5124F8B0FAD9B7D6DB0052484E499F049C2E5E400C836E66FE8027CA345FCF44A91BB58CD7077E46091938E100DDCA98E33E<br>015E73596ADADAD1533B831EEDAF489F1FCC1316E4494C9F161C4768FE5F449AB8BE1243B39CF3CD885429DB86B7995E0957715D83511FAEB69A44C7225D<br>07D1C95F152B367363080F26DA65A2CF7CE7FCA38622B3BBCEDD3CCB76AB3B64E6F01FC13FB5E9B4215C6EC3471763678A48FAA7CF7C0180274464B845E5<br>17439641C9A3690410E686D1B601</span> <br> <!-- !!! dont changing this !!! --> </div> </div> <!-- --> <div class="tabs"> <!--tab--> <div class="tab"> <div id="tab-content1" class="content"> <div class="text"> <!--text data --> <b>/!\ YOUR COMPANY NETWORK HAS BEEN PENETRATED /!\</b><br> <b>ALL YOUR IMPORTANT FILES HAVE BEEN ENCRYPTED!</b><br><br> YOUR FILES ARE SAFE! JUST MODIFIED ONLY. (RSA+AES) <br><br> ANY ATTEMPT TO RESTORE YOUR FILES WITH THIRD-PARTY SOFTWARE<br> WILL PERMENANTLY DESTROY YOUR FILE.<br> DO NOT MODIFY ENCRYPTED FILES. DO NOT RENAME ENCRYPTED FILES.<br><br> NO SOFTWARE AVAILABLE ON INTERNET CAN HELP YOU. WE ONLY HAVE<br> SOLUTION TO YOUR PROBLEM.<br><br> WE GATHERED HIGHLY CONFIDENTIAL/PERSORNAL DATA. THESE DATA<br> ARE CURRENTLY STORED ON A PRIVATE SERVER. THIS SERVER WILL BE<br> IMMEDIATELY DESTROYED AFTER YOUR PAYMENT. WE ONLY SEEK MONEY<br> AND DO NOT WANT TO DAMAGE YOUR REPUTATION. IF YOU DECIDE TO<br> NOT PAY, WE WILL RELEASE THIS DATA TO PUBLIC OR RE-SELLER.<br><br> YOU WILL CAN SEND US 2-3 NON-IMPORTANT FILES AND WE WILL<br> DECRYPT IT FOR FREE TO PROVE WE ARE ABLE TO GIVE YOUR FILES<br> BACK.<br><br> <!--text data --> <hr> <b>Contact us for price and get decryption software.</b><br><br> <a href="">http://gvlay6u4g53rxdi5.onion/21-Al9gJCAJ2fd8LgNEdEBLhNUw5QUOgJlP-JVMF20wIlKxlS7OrHBXpCbCONEIVsdhU</a><br> * Note that this server is available via Tor browser only<br><br> Follow the instructions to open the link:<br> 1. Type the addres "https://www.torproject.org" in your Internet browser. It opens the Tor site.<br> 2. Press "Download Tor", then press "Download Tor Browser Bundle", install and run it.<br> 3. Now you have Tor browser. In the Tor Browser open "{
offset: 0
success 0 0
1619345067.96011
NtWriteFile
file_handle: 0x00000130
filepath: C:\Python27\include\Recovery_Instructions.html
buffer: <html> <style type="text/css"> body { background-color: #f5f5f5; } h1, h3{ text-align: center; text-transform: uppercase; font-weight: normal; } /*---*/ .tabs1{ display: block; margin: auto; } .tabs1 .head{ text-align: center; float: top; padding: 0px; text-transform: uppercase; font-weight: normal; display: block; background: #81bef7; color: #DF0101; font-size: 30px; } .tabs1 .identi { font-size: 10px; text-align: center; float: top; padding: 15px; display: block; background: #81bef7; color: #DFDFDF; } .tabs .content { background: #f5f5f5; /*text-align: center;*/ color: #000000; padding: 25px 15px; font-size: 15px; font-weight: 400; line-height: 20px; } .tabs .content a { color: #df0130; font-size: 23px; font-style: italic; text-decoration: none; line-height: 35px; } .tabs .content .text{ padding: 25px; line-height: 1.2; } </style> <body> <div class="tabs1"> <div class="head" ><b>Your personal ID:</b></div> <div class="identi"> <span style="width:1000px; color: #ffffff; font-size: 10px;">96B15FC03DCA8D175790CC1A893EEB4568E36CF6777F6CE5568ECDD6C33CDC4DC3B8A0AEBE17D5659209E6C658CCE1BE380E6C5350653A8A972180DDF12A276C<br>AF73EB431A73371B04B5BC86AEAACC8E3FC88B2F0E84D9C76161510D333EBD7686343FD08363EBC6A4D72ECCB63DB9C57C7AA9679310D262EB981A91960D<br>69A70480CD61A2D1DA4976232C86AA805C5B4389E7C04A8C9F65D5F80755A928BA67A0B7D9B5C5CA24883A4D8F4BD33CDEC232E5EFAB57377DE59B168050<br>2696BCA82218CA139ED899AD3837F84CF746A6FE76077F43A9DAFE9540482DB1415DAFC5559354C7E40262E301797BE8C3846F42A90AB20A4DF3462C44EC<br>A25F788CBCA026EA628E63C223A27603710293A1DDF2CABDE3C276BA5C79066F5199B66174620070248310D761B7E4DE7AA3667D4273B71A26A82665E0A1<br>D468573772BFA7618599E04F5124F8B0FAD9B7D6DB0052484E499F049C2E5E400C836E66FE8027CA345FCF44A91BB58CD7077E46091938E100DDCA98E33E<br>015E73596ADADAD1533B831EEDAF489F1FCC1316E4494C9F161C4768FE5F449AB8BE1243B39CF3CD885429DB86B7995E0957715D83511FAEB69A44C7225D<br>07D1C95F152B367363080F26DA65A2CF7CE7FCA38622B3BBCEDD3CCB76AB3B64E6F01FC13FB5E9B4215C6EC3471763678A48FAA7CF7C0180274464B845E5<br>17439641C9A3690410E686D1B601</span> <br> <!-- !!! dont changing this !!! --> </div> </div> <!-- --> <div class="tabs"> <!--tab--> <div class="tab"> <div id="tab-content1" class="content"> <div class="text"> <!--text data --> <b>/!\ YOUR COMPANY NETWORK HAS BEEN PENETRATED /!\</b><br> <b>ALL YOUR IMPORTANT FILES HAVE BEEN ENCRYPTED!</b><br><br> YOUR FILES ARE SAFE! JUST MODIFIED ONLY. (RSA+AES) <br><br> ANY ATTEMPT TO RESTORE YOUR FILES WITH THIRD-PARTY SOFTWARE<br> WILL PERMENANTLY DESTROY YOUR FILE.<br> DO NOT MODIFY ENCRYPTED FILES. DO NOT RENAME ENCRYPTED FILES.<br><br> NO SOFTWARE AVAILABLE ON INTERNET CAN HELP YOU. WE ONLY HAVE<br> SOLUTION TO YOUR PROBLEM.<br><br> WE GATHERED HIGHLY CONFIDENTIAL/PERSORNAL DATA. THESE DATA<br> ARE CURRENTLY STORED ON A PRIVATE SERVER. THIS SERVER WILL BE<br> IMMEDIATELY DESTROYED AFTER YOUR PAYMENT. WE ONLY SEEK MONEY<br> AND DO NOT WANT TO DAMAGE YOUR REPUTATION. IF YOU DECIDE TO<br> NOT PAY, WE WILL RELEASE THIS DATA TO PUBLIC OR RE-SELLER.<br><br> YOU WILL CAN SEND US 2-3 NON-IMPORTANT FILES AND WE WILL<br> DECRYPT IT FOR FREE TO PROVE WE ARE ABLE TO GIVE YOUR FILES<br> BACK.<br><br> <!--text data --> <hr> <b>Contact us for price and get decryption software.</b><br><br> <a href="">http://gvlay6u4g53rxdi5.onion/21-Al9gJCAJ2fd8LgNEdEBLhNUw5QUOgJlP-JVMF20wIlKxlS7OrHBXpCbCONEIVsdhU</a><br> * Note that this server is available via Tor browser only<br><br> Follow the instructions to open the link:<br> 1. Type the addres "https://www.torproject.org" in your Internet browser. It opens the Tor site.<br> 2. Press "Download Tor", then press "Download Tor Browser Bundle", install and run it.<br> 3. Now you have Tor browser. In the Tor Browser open "{
offset: 0
success 0 0
1619345068.06911
NtWriteFile
file_handle: 0x00000308
filepath: C:\Python27\include\Recovery_Instructions.html
buffer: <html> <style type="text/css"> body { background-color: #f5f5f5; } h1, h3{ text-align: center; text-transform: uppercase; font-weight: normal; } /*---*/ .tabs1{ display: block; margin: auto; } .tabs1 .head{ text-align: center; float: top; padding: 0px; text-transform: uppercase; font-weight: normal; display: block; background: #81bef7; color: #DF0101; font-size: 30px; } .tabs1 .identi { font-size: 10px; text-align: center; float: top; padding: 15px; display: block; background: #81bef7; color: #DFDFDF; } .tabs .content { background: #f5f5f5; /*text-align: center;*/ color: #000000; padding: 25px 15px; font-size: 15px; font-weight: 400; line-height: 20px; } .tabs .content a { color: #df0130; font-size: 23px; font-style: italic; text-decoration: none; line-height: 35px; } .tabs .content .text{ padding: 25px; line-height: 1.2; } </style> <body> <div class="tabs1"> <div class="head" ><b>Your personal ID:</b></div> <div class="identi"> <span style="width:1000px; color: #ffffff; font-size: 10px;">96B15FC03DCA8D175790CC1A893EEB4568E36CF6777F6CE5568ECDD6C33CDC4DC3B8A0AEBE17D5659209E6C658CCE1BE380E6C5350653A8A972180DDF12A276C<br>AF73EB431A73371B04B5BC86AEAACC8E3FC88B2F0E84D9C76161510D333EBD7686343FD08363EBC6A4D72ECCB63DB9C57C7AA9679310D262EB981A91960D<br>69A70480CD61A2D1DA4976232C86AA805C5B4389E7C04A8C9F65D5F80755A928BA67A0B7D9B5C5CA24883A4D8F4BD33CDEC232E5EFAB57377DE59B168050<br>2696BCA82218CA139ED899AD3837F84CF746A6FE76077F43A9DAFE9540482DB1415DAFC5559354C7E40262E301797BE8C3846F42A90AB20A4DF3462C44EC<br>A25F788CBCA026EA628E63C223A27603710293A1DDF2CABDE3C276BA5C79066F5199B66174620070248310D761B7E4DE7AA3667D4273B71A26A82665E0A1<br>D468573772BFA7618599E04F5124F8B0FAD9B7D6DB0052484E499F049C2E5E400C836E66FE8027CA345FCF44A91BB58CD7077E46091938E100DDCA98E33E<br>015E73596ADADAD1533B831EEDAF489F1FCC1316E4494C9F161C4768FE5F449AB8BE1243B39CF3CD885429DB86B7995E0957715D83511FAEB69A44C7225D<br>07D1C95F152B367363080F26DA65A2CF7CE7FCA38622B3BBCEDD3CCB76AB3B64E6F01FC13FB5E9B4215C6EC3471763678A48FAA7CF7C0180274464B845E5<br>17439641C9A3690410E686D1B601</span> <br> <!-- !!! dont changing this !!! --> </div> </div> <!-- --> <div class="tabs"> <!--tab--> <div class="tab"> <div id="tab-content1" class="content"> <div class="text"> <!--text data --> <b>/!\ YOUR COMPANY NETWORK HAS BEEN PENETRATED /!\</b><br> <b>ALL YOUR IMPORTANT FILES HAVE BEEN ENCRYPTED!</b><br><br> YOUR FILES ARE SAFE! JUST MODIFIED ONLY. (RSA+AES) <br><br> ANY ATTEMPT TO RESTORE YOUR FILES WITH THIRD-PARTY SOFTWARE<br> WILL PERMENANTLY DESTROY YOUR FILE.<br> DO NOT MODIFY ENCRYPTED FILES. DO NOT RENAME ENCRYPTED FILES.<br><br> NO SOFTWARE AVAILABLE ON INTERNET CAN HELP YOU. WE ONLY HAVE<br> SOLUTION TO YOUR PROBLEM.<br><br> WE GATHERED HIGHLY CONFIDENTIAL/PERSORNAL DATA. THESE DATA<br> ARE CURRENTLY STORED ON A PRIVATE SERVER. THIS SERVER WILL BE<br> IMMEDIATELY DESTROYED AFTER YOUR PAYMENT. WE ONLY SEEK MONEY<br> AND DO NOT WANT TO DAMAGE YOUR REPUTATION. IF YOU DECIDE TO<br> NOT PAY, WE WILL RELEASE THIS DATA TO PUBLIC OR RE-SELLER.<br><br> YOU WILL CAN SEND US 2-3 NON-IMPORTANT FILES AND WE WILL<br> DECRYPT IT FOR FREE TO PROVE WE ARE ABLE TO GIVE YOUR FILES<br> BACK.<br><br> <!--text data --> <hr> <b>Contact us for price and get decryption software.</b><br><br> <a href="">http://gvlay6u4g53rxdi5.onion/21-Al9gJCAJ2fd8LgNEdEBLhNUw5QUOgJlP-JVMF20wIlKxlS7OrHBXpCbCONEIVsdhU</a><br> * Note that this server is available via Tor browser only<br><br> Follow the instructions to open the link:<br> 1. Type the addres "https://www.torproject.org" in your Internet browser. It opens the Tor site.<br> 2. Press "Download Tor", then press "Download Tor Browser Bundle", install and run it.<br> 3. Now you have Tor browser. In the Tor Browser open "{
offset: 0
success 0 0
1619345068.16311
NtWriteFile
file_handle: 0x000002e8
filepath: C:\Python27\include\Recovery_Instructions.html
buffer: <html> <style type="text/css"> body { background-color: #f5f5f5; } h1, h3{ text-align: center; text-transform: uppercase; font-weight: normal; } /*---*/ .tabs1{ display: block; margin: auto; } .tabs1 .head{ text-align: center; float: top; padding: 0px; text-transform: uppercase; font-weight: normal; display: block; background: #81bef7; color: #DF0101; font-size: 30px; } .tabs1 .identi { font-size: 10px; text-align: center; float: top; padding: 15px; display: block; background: #81bef7; color: #DFDFDF; } .tabs .content { background: #f5f5f5; /*text-align: center;*/ color: #000000; padding: 25px 15px; font-size: 15px; font-weight: 400; line-height: 20px; } .tabs .content a { color: #df0130; font-size: 23px; font-style: italic; text-decoration: none; line-height: 35px; } .tabs .content .text{ padding: 25px; line-height: 1.2; } </style> <body> <div class="tabs1"> <div class="head" ><b>Your personal ID:</b></div> <div class="identi"> <span style="width:1000px; color: #ffffff; font-size: 10px;">96B15FC03DCA8D175790CC1A893EEB4568E36CF6777F6CE5568ECDD6C33CDC4DC3B8A0AEBE17D5659209E6C658CCE1BE380E6C5350653A8A972180DDF12A276C<br>AF73EB431A73371B04B5BC86AEAACC8E3FC88B2F0E84D9C76161510D333EBD7686343FD08363EBC6A4D72ECCB63DB9C57C7AA9679310D262EB981A91960D<br>69A70480CD61A2D1DA4976232C86AA805C5B4389E7C04A8C9F65D5F80755A928BA67A0B7D9B5C5CA24883A4D8F4BD33CDEC232E5EFAB57377DE59B168050<br>2696BCA82218CA139ED899AD3837F84CF746A6FE76077F43A9DAFE9540482DB1415DAFC5559354C7E40262E301797BE8C3846F42A90AB20A4DF3462C44EC<br>A25F788CBCA026EA628E63C223A27603710293A1DDF2CABDE3C276BA5C79066F5199B66174620070248310D761B7E4DE7AA3667D4273B71A26A82665E0A1<br>D468573772BFA7618599E04F5124F8B0FAD9B7D6DB0052484E499F049C2E5E400C836E66FE8027CA345FCF44A91BB58CD7077E46091938E100DDCA98E33E<br>015E73596ADADAD1533B831EEDAF489F1FCC1316E4494C9F161C4768FE5F449AB8BE1243B39CF3CD885429DB86B7995E0957715D83511FAEB69A44C7225D<br>07D1C95F152B367363080F26DA65A2CF7CE7FCA38622B3BBCEDD3CCB76AB3B64E6F01FC13FB5E9B4215C6EC3471763678A48FAA7CF7C0180274464B845E5<br>17439641C9A3690410E686D1B601</span> <br> <!-- !!! dont changing this !!! --> </div> </div> <!-- --> <div class="tabs"> <!--tab--> <div class="tab"> <div id="tab-content1" class="content"> <div class="text"> <!--text data --> <b>/!\ YOUR COMPANY NETWORK HAS BEEN PENETRATED /!\</b><br> <b>ALL YOUR IMPORTANT FILES HAVE BEEN ENCRYPTED!</b><br><br> YOUR FILES ARE SAFE! JUST MODIFIED ONLY. (RSA+AES) <br><br> ANY ATTEMPT TO RESTORE YOUR FILES WITH THIRD-PARTY SOFTWARE<br> WILL PERMENANTLY DESTROY YOUR FILE.<br> DO NOT MODIFY ENCRYPTED FILES. DO NOT RENAME ENCRYPTED FILES.<br><br> NO SOFTWARE AVAILABLE ON INTERNET CAN HELP YOU. WE ONLY HAVE<br> SOLUTION TO YOUR PROBLEM.<br><br> WE GATHERED HIGHLY CONFIDENTIAL/PERSORNAL DATA. THESE DATA<br> ARE CURRENTLY STORED ON A PRIVATE SERVER. THIS SERVER WILL BE<br> IMMEDIATELY DESTROYED AFTER YOUR PAYMENT. WE ONLY SEEK MONEY<br> AND DO NOT WANT TO DAMAGE YOUR REPUTATION. IF YOU DECIDE TO<br> NOT PAY, WE WILL RELEASE THIS DATA TO PUBLIC OR RE-SELLER.<br><br> YOU WILL CAN SEND US 2-3 NON-IMPORTANT FILES AND WE WILL<br> DECRYPT IT FOR FREE TO PROVE WE ARE ABLE TO GIVE YOUR FILES<br> BACK.<br><br> <!--text data --> <hr> <b>Contact us for price and get decryption software.</b><br><br> <a href="">http://gvlay6u4g53rxdi5.onion/21-Al9gJCAJ2fd8LgNEdEBLhNUw5QUOgJlP-JVMF20wIlKxlS7OrHBXpCbCONEIVsdhU</a><br> * Note that this server is available via Tor browser only<br><br> Follow the instructions to open the link:<br> 1. Type the addres "https://www.torproject.org" in your Internet browser. It opens the Tor site.<br> 2. Press "Download Tor", then press "Download Tor Browser Bundle", install and run it.<br> 3. Now you have Tor browser. In the Tor Browser open "{
offset: 0
success 0 0
1619345068.28811
NtWriteFile
file_handle: 0x000002e8
filepath: C:\Python27\include\Recovery_Instructions.html
buffer: <html> <style type="text/css"> body { background-color: #f5f5f5; } h1, h3{ text-align: center; text-transform: uppercase; font-weight: normal; } /*---*/ .tabs1{ display: block; margin: auto; } .tabs1 .head{ text-align: center; float: top; padding: 0px; text-transform: uppercase; font-weight: normal; display: block; background: #81bef7; color: #DF0101; font-size: 30px; } .tabs1 .identi { font-size: 10px; text-align: center; float: top; padding: 15px; display: block; background: #81bef7; color: #DFDFDF; } .tabs .content { background: #f5f5f5; /*text-align: center;*/ color: #000000; padding: 25px 15px; font-size: 15px; font-weight: 400; line-height: 20px; } .tabs .content a { color: #df0130; font-size: 23px; font-style: italic; text-decoration: none; line-height: 35px; } .tabs .content .text{ padding: 25px; line-height: 1.2; } </style> <body> <div class="tabs1"> <div class="head" ><b>Your personal ID:</b></div> <div class="identi"> <span style="width:1000px; color: #ffffff; font-size: 10px;">96B15FC03DCA8D175790CC1A893EEB4568E36CF6777F6CE5568ECDD6C33CDC4DC3B8A0AEBE17D5659209E6C658CCE1BE380E6C5350653A8A972180DDF12A276C<br>AF73EB431A73371B04B5BC86AEAACC8E3FC88B2F0E84D9C76161510D333EBD7686343FD08363EBC6A4D72ECCB63DB9C57C7AA9679310D262EB981A91960D<br>69A70480CD61A2D1DA4976232C86AA805C5B4389E7C04A8C9F65D5F80755A928BA67A0B7D9B5C5CA24883A4D8F4BD33CDEC232E5EFAB57377DE59B168050<br>2696BCA82218CA139ED899AD3837F84CF746A6FE76077F43A9DAFE9540482DB1415DAFC5559354C7E40262E301797BE8C3846F42A90AB20A4DF3462C44EC<br>A25F788CBCA026EA628E63C223A27603710293A1DDF2CABDE3C276BA5C79066F5199B66174620070248310D761B7E4DE7AA3667D4273B71A26A82665E0A1<br>D468573772BFA7618599E04F5124F8B0FAD9B7D6DB0052484E499F049C2E5E400C836E66FE8027CA345FCF44A91BB58CD7077E46091938E100DDCA98E33E<br>015E73596ADADAD1533B831EEDAF489F1FCC1316E4494C9F161C4768FE5F449AB8BE1243B39CF3CD885429DB86B7995E0957715D83511FAEB69A44C7225D<br>07D1C95F152B367363080F26DA65A2CF7CE7FCA38622B3BBCEDD3CCB76AB3B64E6F01FC13FB5E9B4215C6EC3471763678A48FAA7CF7C0180274464B845E5<br>17439641C9A3690410E686D1B601</span> <br> <!-- !!! dont changing this !!! --> </div> </div> <!-- --> <div class="tabs"> <!--tab--> <div class="tab"> <div id="tab-content1" class="content"> <div class="text"> <!--text data --> <b>/!\ YOUR COMPANY NETWORK HAS BEEN PENETRATED /!\</b><br> <b>ALL YOUR IMPORTANT FILES HAVE BEEN ENCRYPTED!</b><br><br> YOUR FILES ARE SAFE! JUST MODIFIED ONLY. (RSA+AES) <br><br> ANY ATTEMPT TO RESTORE YOUR FILES WITH THIRD-PARTY SOFTWARE<br> WILL PERMENANTLY DESTROY YOUR FILE.<br> DO NOT MODIFY ENCRYPTED FILES. DO NOT RENAME ENCRYPTED FILES.<br><br> NO SOFTWARE AVAILABLE ON INTERNET CAN HELP YOU. WE ONLY HAVE<br> SOLUTION TO YOUR PROBLEM.<br><br> WE GATHERED HIGHLY CONFIDENTIAL/PERSORNAL DATA. THESE DATA<br> ARE CURRENTLY STORED ON A PRIVATE SERVER. THIS SERVER WILL BE<br> IMMEDIATELY DESTROYED AFTER YOUR PAYMENT. WE ONLY SEEK MONEY<br> AND DO NOT WANT TO DAMAGE YOUR REPUTATION. IF YOU DECIDE TO<br> NOT PAY, WE WILL RELEASE THIS DATA TO PUBLIC OR RE-SELLER.<br><br> YOU WILL CAN SEND US 2-3 NON-IMPORTANT FILES AND WE WILL<br> DECRYPT IT FOR FREE TO PROVE WE ARE ABLE TO GIVE YOUR FILES<br> BACK.<br><br> <!--text data --> <hr> <b>Contact us for price and get decryption software.</b><br><br> <a href="">http://gvlay6u4g53rxdi5.onion/21-Al9gJCAJ2fd8LgNEdEBLhNUw5QUOgJlP-JVMF20wIlKxlS7OrHBXpCbCONEIVsdhU</a><br> * Note that this server is available via Tor browser only<br><br> Follow the instructions to open the link:<br> 1. Type the addres "https://www.torproject.org" in your Internet browser. It opens the Tor site.<br> 2. Press "Download Tor", then press "Download Tor Browser Bundle", install and run it.<br> 3. Now you have Tor browser. In the Tor Browser open "{
offset: 0
success 0 0
1619345068.44411
NtWriteFile
file_handle: 0x000002e8
filepath: C:\Python27\include\Recovery_Instructions.html
buffer: <html> <style type="text/css"> body { background-color: #f5f5f5; } h1, h3{ text-align: center; text-transform: uppercase; font-weight: normal; } /*---*/ .tabs1{ display: block; margin: auto; } .tabs1 .head{ text-align: center; float: top; padding: 0px; text-transform: uppercase; font-weight: normal; display: block; background: #81bef7; color: #DF0101; font-size: 30px; } .tabs1 .identi { font-size: 10px; text-align: center; float: top; padding: 15px; display: block; background: #81bef7; color: #DFDFDF; } .tabs .content { background: #f5f5f5; /*text-align: center;*/ color: #000000; padding: 25px 15px; font-size: 15px; font-weight: 400; line-height: 20px; } .tabs .content a { color: #df0130; font-size: 23px; font-style: italic; text-decoration: none; line-height: 35px; } .tabs .content .text{ padding: 25px; line-height: 1.2; } </style> <body> <div class="tabs1"> <div class="head" ><b>Your personal ID:</b></div> <div class="identi"> <span style="width:1000px; color: #ffffff; font-size: 10px;">96B15FC03DCA8D175790CC1A893EEB4568E36CF6777F6CE5568ECDD6C33CDC4DC3B8A0AEBE17D5659209E6C658CCE1BE380E6C5350653A8A972180DDF12A276C<br>AF73EB431A73371B04B5BC86AEAACC8E3FC88B2F0E84D9C76161510D333EBD7686343FD08363EBC6A4D72ECCB63DB9C57C7AA9679310D262EB981A91960D<br>69A70480CD61A2D1DA4976232C86AA805C5B4389E7C04A8C9F65D5F80755A928BA67A0B7D9B5C5CA24883A4D8F4BD33CDEC232E5EFAB57377DE59B168050<br>2696BCA82218CA139ED899AD3837F84CF746A6FE76077F43A9DAFE9540482DB1415DAFC5559354C7E40262E301797BE8C3846F42A90AB20A4DF3462C44EC<br>A25F788CBCA026EA628E63C223A27603710293A1DDF2CABDE3C276BA5C79066F5199B66174620070248310D761B7E4DE7AA3667D4273B71A26A82665E0A1<br>D468573772BFA7618599E04F5124F8B0FAD9B7D6DB0052484E499F049C2E5E400C836E66FE8027CA345FCF44A91BB58CD7077E46091938E100DDCA98E33E<br>015E73596ADADAD1533B831EEDAF489F1FCC1316E4494C9F161C4768FE5F449AB8BE1243B39CF3CD885429DB86B7995E0957715D83511FAEB69A44C7225D<br>07D1C95F152B367363080F26DA65A2CF7CE7FCA38622B3BBCEDD3CCB76AB3B64E6F01FC13FB5E9B4215C6EC3471763678A48FAA7CF7C0180274464B845E5<br>17439641C9A3690410E686D1B601</span> <br> <!-- !!! dont changing this !!! --> </div> </div> <!-- --> <div class="tabs"> <!--tab--> <div class="tab"> <div id="tab-content1" class="content"> <div class="text"> <!--text data --> <b>/!\ YOUR COMPANY NETWORK HAS BEEN PENETRATED /!\</b><br> <b>ALL YOUR IMPORTANT FILES HAVE BEEN ENCRYPTED!</b><br><br> YOUR FILES ARE SAFE! JUST MODIFIED ONLY. (RSA+AES) <br><br> ANY ATTEMPT TO RESTORE YOUR FILES WITH THIRD-PARTY SOFTWARE<br> WILL PERMENANTLY DESTROY YOUR FILE.<br> DO NOT MODIFY ENCRYPTED FILES. DO NOT RENAME ENCRYPTED FILES.<br><br> NO SOFTWARE AVAILABLE ON INTERNET CAN HELP YOU. WE ONLY HAVE<br> SOLUTION TO YOUR PROBLEM.<br><br> WE GATHERED HIGHLY CONFIDENTIAL/PERSORNAL DATA. THESE DATA<br> ARE CURRENTLY STORED ON A PRIVATE SERVER. THIS SERVER WILL BE<br> IMMEDIATELY DESTROYED AFTER YOUR PAYMENT. WE ONLY SEEK MONEY<br> AND DO NOT WANT TO DAMAGE YOUR REPUTATION. IF YOU DECIDE TO<br> NOT PAY, WE WILL RELEASE THIS DATA TO PUBLIC OR RE-SELLER.<br><br> YOU WILL CAN SEND US 2-3 NON-IMPORTANT FILES AND WE WILL<br> DECRYPT IT FOR FREE TO PROVE WE ARE ABLE TO GIVE YOUR FILES<br> BACK.<br><br> <!--text data --> <hr> <b>Contact us for price and get decryption software.</b><br><br> <a href="">http://gvlay6u4g53rxdi5.onion/21-Al9gJCAJ2fd8LgNEdEBLhNUw5QUOgJlP-JVMF20wIlKxlS7OrHBXpCbCONEIVsdhU</a><br> * Note that this server is available via Tor browser only<br><br> Follow the instructions to open the link:<br> 1. Type the addres "https://www.torproject.org" in your Internet browser. It opens the Tor site.<br> 2. Press "Download Tor", then press "Download Tor Browser Bundle", install and run it.<br> 3. Now you have Tor browser. In the Tor Browser open "{
offset: 0
success 0 0
1619345068.63211
NtWriteFile
file_handle: 0x000002e8
filepath: C:\Python27\include\Recovery_Instructions.html
buffer: <html> <style type="text/css"> body { background-color: #f5f5f5; } h1, h3{ text-align: center; text-transform: uppercase; font-weight: normal; } /*---*/ .tabs1{ display: block; margin: auto; } .tabs1 .head{ text-align: center; float: top; padding: 0px; text-transform: uppercase; font-weight: normal; display: block; background: #81bef7; color: #DF0101; font-size: 30px; } .tabs1 .identi { font-size: 10px; text-align: center; float: top; padding: 15px; display: block; background: #81bef7; color: #DFDFDF; } .tabs .content { background: #f5f5f5; /*text-align: center;*/ color: #000000; padding: 25px 15px; font-size: 15px; font-weight: 400; line-height: 20px; } .tabs .content a { color: #df0130; font-size: 23px; font-style: italic; text-decoration: none; line-height: 35px; } .tabs .content .text{ padding: 25px; line-height: 1.2; } </style> <body> <div class="tabs1"> <div class="head" ><b>Your personal ID:</b></div> <div class="identi"> <span style="width:1000px; color: #ffffff; font-size: 10px;">96B15FC03DCA8D175790CC1A893EEB4568E36CF6777F6CE5568ECDD6C33CDC4DC3B8A0AEBE17D5659209E6C658CCE1BE380E6C5350653A8A972180DDF12A276C<br>AF73EB431A73371B04B5BC86AEAACC8E3FC88B2F0E84D9C76161510D333EBD7686343FD08363EBC6A4D72ECCB63DB9C57C7AA9679310D262EB981A91960D<br>69A70480CD61A2D1DA4976232C86AA805C5B4389E7C04A8C9F65D5F80755A928BA67A0B7D9B5C5CA24883A4D8F4BD33CDEC232E5EFAB57377DE59B168050<br>2696BCA82218CA139ED899AD3837F84CF746A6FE76077F43A9DAFE9540482DB1415DAFC5559354C7E40262E301797BE8C3846F42A90AB20A4DF3462C44EC<br>A25F788CBCA026EA628E63C223A27603710293A1DDF2CABDE3C276BA5C79066F5199B66174620070248310D761B7E4DE7AA3667D4273B71A26A82665E0A1<br>D468573772BFA7618599E04F5124F8B0FAD9B7D6DB0052484E499F049C2E5E400C836E66FE8027CA345FCF44A91BB58CD7077E46091938E100DDCA98E33E<br>015E73596ADADAD1533B831EEDAF489F1FCC1316E4494C9F161C4768FE5F449AB8BE1243B39CF3CD885429DB86B7995E0957715D83511FAEB69A44C7225D<br>07D1C95F152B367363080F26DA65A2CF7CE7FCA38622B3BBCEDD3CCB76AB3B64E6F01FC13FB5E9B4215C6EC3471763678A48FAA7CF7C0180274464B845E5<br>17439641C9A3690410E686D1B601</span> <br> <!-- !!! dont changing this !!! --> </div> </div> <!-- --> <div class="tabs"> <!--tab--> <div class="tab"> <div id="tab-content1" class="content"> <div class="text"> <!--text data --> <b>/!\ YOUR COMPANY NETWORK HAS BEEN PENETRATED /!\</b><br> <b>ALL YOUR IMPORTANT FILES HAVE BEEN ENCRYPTED!</b><br><br> YOUR FILES ARE SAFE! JUST MODIFIED ONLY. (RSA+AES) <br><br> ANY ATTEMPT TO RESTORE YOUR FILES WITH THIRD-PARTY SOFTWARE<br> WILL PERMENANTLY DESTROY YOUR FILE.<br> DO NOT MODIFY ENCRYPTED FILES. DO NOT RENAME ENCRYPTED FILES.<br><br> NO SOFTWARE AVAILABLE ON INTERNET CAN HELP YOU. WE ONLY HAVE<br> SOLUTION TO YOUR PROBLEM.<br><br> WE GATHERED HIGHLY CONFIDENTIAL/PERSORNAL DATA. THESE DATA<br> ARE CURRENTLY STORED ON A PRIVATE SERVER. THIS SERVER WILL BE<br> IMMEDIATELY DESTROYED AFTER YOUR PAYMENT. WE ONLY SEEK MONEY<br> AND DO NOT WANT TO DAMAGE YOUR REPUTATION. IF YOU DECIDE TO<br> NOT PAY, WE WILL RELEASE THIS DATA TO PUBLIC OR RE-SELLER.<br><br> YOU WILL CAN SEND US 2-3 NON-IMPORTANT FILES AND WE WILL<br> DECRYPT IT FOR FREE TO PROVE WE ARE ABLE TO GIVE YOUR FILES<br> BACK.<br><br> <!--text data --> <hr> <b>Contact us for price and get decryption software.</b><br><br> <a href="">http://gvlay6u4g53rxdi5.onion/21-Al9gJCAJ2fd8LgNEdEBLhNUw5QUOgJlP-JVMF20wIlKxlS7OrHBXpCbCONEIVsdhU</a><br> * Note that this server is available via Tor browser only<br><br> Follow the instructions to open the link:<br> 1. Type the addres "https://www.torproject.org" in your Internet browser. It opens the Tor site.<br> 2. Press "Download Tor", then press "Download Tor Browser Bundle", install and run it.<br> 3. Now you have Tor browser. In the Tor Browser open "{
offset: 0
success 0 0
1619345068.80411
NtWriteFile
file_handle: 0x000002e8
filepath: C:\Python27\include\Recovery_Instructions.html
buffer: <html> <style type="text/css"> body { background-color: #f5f5f5; } h1, h3{ text-align: center; text-transform: uppercase; font-weight: normal; } /*---*/ .tabs1{ display: block; margin: auto; } .tabs1 .head{ text-align: center; float: top; padding: 0px; text-transform: uppercase; font-weight: normal; display: block; background: #81bef7; color: #DF0101; font-size: 30px; } .tabs1 .identi { font-size: 10px; text-align: center; float: top; padding: 15px; display: block; background: #81bef7; color: #DFDFDF; } .tabs .content { background: #f5f5f5; /*text-align: center;*/ color: #000000; padding: 25px 15px; font-size: 15px; font-weight: 400; line-height: 20px; } .tabs .content a { color: #df0130; font-size: 23px; font-style: italic; text-decoration: none; line-height: 35px; } .tabs .content .text{ padding: 25px; line-height: 1.2; } </style> <body> <div class="tabs1"> <div class="head" ><b>Your personal ID:</b></div> <div class="identi"> <span style="width:1000px; color: #ffffff; font-size: 10px;">96B15FC03DCA8D175790CC1A893EEB4568E36CF6777F6CE5568ECDD6C33CDC4DC3B8A0AEBE17D5659209E6C658CCE1BE380E6C5350653A8A972180DDF12A276C<br>AF73EB431A73371B04B5BC86AEAACC8E3FC88B2F0E84D9C76161510D333EBD7686343FD08363EBC6A4D72ECCB63DB9C57C7AA9679310D262EB981A91960D<br>69A70480CD61A2D1DA4976232C86AA805C5B4389E7C04A8C9F65D5F80755A928BA67A0B7D9B5C5CA24883A4D8F4BD33CDEC232E5EFAB57377DE59B168050<br>2696BCA82218CA139ED899AD3837F84CF746A6FE76077F43A9DAFE9540482DB1415DAFC5559354C7E40262E301797BE8C3846F42A90AB20A4DF3462C44EC<br>A25F788CBCA026EA628E63C223A27603710293A1DDF2CABDE3C276BA5C79066F5199B66174620070248310D761B7E4DE7AA3667D4273B71A26A82665E0A1<br>D468573772BFA7618599E04F5124F8B0FAD9B7D6DB0052484E499F049C2E5E400C836E66FE8027CA345FCF44A91BB58CD7077E46091938E100DDCA98E33E<br>015E73596ADADAD1533B831EEDAF489F1FCC1316E4494C9F161C4768FE5F449AB8BE1243B39CF3CD885429DB86B7995E0957715D83511FAEB69A44C7225D<br>07D1C95F152B367363080F26DA65A2CF7CE7FCA38622B3BBCEDD3CCB76AB3B64E6F01FC13FB5E9B4215C6EC3471763678A48FAA7CF7C0180274464B845E5<br>17439641C9A3690410E686D1B601</span> <br> <!-- !!! dont changing this !!! --> </div> </div> <!-- --> <div class="tabs"> <!--tab--> <div class="tab"> <div id="tab-content1" class="content"> <div class="text"> <!--text data --> <b>/!\ YOUR COMPANY NETWORK HAS BEEN PENETRATED /!\</b><br> <b>ALL YOUR IMPORTANT FILES HAVE BEEN ENCRYPTED!</b><br><br> YOUR FILES ARE SAFE! JUST MODIFIED ONLY. (RSA+AES) <br><br> ANY ATTEMPT TO RESTORE YOUR FILES WITH THIRD-PARTY SOFTWARE<br> WILL PERMENANTLY DESTROY YOUR FILE.<br> DO NOT MODIFY ENCRYPTED FILES. DO NOT RENAME ENCRYPTED FILES.<br><br> NO SOFTWARE AVAILABLE ON INTERNET CAN HELP YOU. WE ONLY HAVE<br> SOLUTION TO YOUR PROBLEM.<br><br> WE GATHERED HIGHLY CONFIDENTIAL/PERSORNAL DATA. THESE DATA<br> ARE CURRENTLY STORED ON A PRIVATE SERVER. THIS SERVER WILL BE<br> IMMEDIATELY DESTROYED AFTER YOUR PAYMENT. WE ONLY SEEK MONEY<br> AND DO NOT WANT TO DAMAGE YOUR REPUTATION. IF YOU DECIDE TO<br> NOT PAY, WE WILL RELEASE THIS DATA TO PUBLIC OR RE-SELLER.<br><br> YOU WILL CAN SEND US 2-3 NON-IMPORTANT FILES AND WE WILL<br> DECRYPT IT FOR FREE TO PROVE WE ARE ABLE TO GIVE YOUR FILES<br> BACK.<br><br> <!--text data --> <hr> <b>Contact us for price and get decryption software.</b><br><br> <a href="">http://gvlay6u4g53rxdi5.onion/21-Al9gJCAJ2fd8LgNEdEBLhNUw5QUOgJlP-JVMF20wIlKxlS7OrHBXpCbCONEIVsdhU</a><br> * Note that this server is available via Tor browser only<br><br> Follow the instructions to open the link:<br> 1. Type the addres "https://www.torproject.org" in your Internet browser. It opens the Tor site.<br> 2. Press "Download Tor", then press "Download Tor Browser Bundle", install and run it.<br> 3. Now you have Tor browser. In the Tor Browser open "{
offset: 0
success 0 0
1619345068.94411
NtWriteFile
file_handle: 0x000002e8
filepath: C:\Python27\include\Recovery_Instructions.html
buffer: <html> <style type="text/css"> body { background-color: #f5f5f5; } h1, h3{ text-align: center; text-transform: uppercase; font-weight: normal; } /*---*/ .tabs1{ display: block; margin: auto; } .tabs1 .head{ text-align: center; float: top; padding: 0px; text-transform: uppercase; font-weight: normal; display: block; background: #81bef7; color: #DF0101; font-size: 30px; } .tabs1 .identi { font-size: 10px; text-align: center; float: top; padding: 15px; display: block; background: #81bef7; color: #DFDFDF; } .tabs .content { background: #f5f5f5; /*text-align: center;*/ color: #000000; padding: 25px 15px; font-size: 15px; font-weight: 400; line-height: 20px; } .tabs .content a { color: #df0130; font-size: 23px; font-style: italic; text-decoration: none; line-height: 35px; } .tabs .content .text{ padding: 25px; line-height: 1.2; } </style> <body> <div class="tabs1"> <div class="head" ><b>Your personal ID:</b></div> <div class="identi"> <span style="width:1000px; color: #ffffff; font-size: 10px;">96B15FC03DCA8D175790CC1A893EEB4568E36CF6777F6CE5568ECDD6C33CDC4DC3B8A0AEBE17D5659209E6C658CCE1BE380E6C5350653A8A972180DDF12A276C<br>AF73EB431A73371B04B5BC86AEAACC8E3FC88B2F0E84D9C76161510D333EBD7686343FD08363EBC6A4D72ECCB63DB9C57C7AA9679310D262EB981A91960D<br>69A70480CD61A2D1DA4976232C86AA805C5B4389E7C04A8C9F65D5F80755A928BA67A0B7D9B5C5CA24883A4D8F4BD33CDEC232E5EFAB57377DE59B168050<br>2696BCA82218CA139ED899AD3837F84CF746A6FE76077F43A9DAFE9540482DB1415DAFC5559354C7E40262E301797BE8C3846F42A90AB20A4DF3462C44EC<br>A25F788CBCA026EA628E63C223A27603710293A1DDF2CABDE3C276BA5C79066F5199B66174620070248310D761B7E4DE7AA3667D4273B71A26A82665E0A1<br>D468573772BFA7618599E04F5124F8B0FAD9B7D6DB0052484E499F049C2E5E400C836E66FE8027CA345FCF44A91BB58CD7077E46091938E100DDCA98E33E<br>015E73596ADADAD1533B831EEDAF489F1FCC1316E4494C9F161C4768FE5F449AB8BE1243B39CF3CD885429DB86B7995E0957715D83511FAEB69A44C7225D<br>07D1C95F152B367363080F26DA65A2CF7CE7FCA38622B3BBCEDD3CCB76AB3B64E6F01FC13FB5E9B4215C6EC3471763678A48FAA7CF7C0180274464B845E5<br>17439641C9A3690410E686D1B601</span> <br> <!-- !!! dont changing this !!! --> </div> </div> <!-- --> <div class="tabs"> <!--tab--> <div class="tab"> <div id="tab-content1" class="content"> <div class="text"> <!--text data --> <b>/!\ YOUR COMPANY NETWORK HAS BEEN PENETRATED /!\</b><br> <b>ALL YOUR IMPORTANT FILES HAVE BEEN ENCRYPTED!</b><br><br> YOUR FILES ARE SAFE! JUST MODIFIED ONLY. (RSA+AES) <br><br> ANY ATTEMPT TO RESTORE YOUR FILES WITH THIRD-PARTY SOFTWARE<br> WILL PERMENANTLY DESTROY YOUR FILE.<br> DO NOT MODIFY ENCRYPTED FILES. DO NOT RENAME ENCRYPTED FILES.<br><br> NO SOFTWARE AVAILABLE ON INTERNET CAN HELP YOU. WE ONLY HAVE<br> SOLUTION TO YOUR PROBLEM.<br><br> WE GATHERED HIGHLY CONFIDENTIAL/PERSORNAL DATA. THESE DATA<br> ARE CURRENTLY STORED ON A PRIVATE SERVER. THIS SERVER WILL BE<br> IMMEDIATELY DESTROYED AFTER YOUR PAYMENT. WE ONLY SEEK MONEY<br> AND DO NOT WANT TO DAMAGE YOUR REPUTATION. IF YOU DECIDE TO<br> NOT PAY, WE WILL RELEASE THIS DATA TO PUBLIC OR RE-SELLER.<br><br> YOU WILL CAN SEND US 2-3 NON-IMPORTANT FILES AND WE WILL<br> DECRYPT IT FOR FREE TO PROVE WE ARE ABLE TO GIVE YOUR FILES<br> BACK.<br><br> <!--text data --> <hr> <b>Contact us for price and get decryption software.</b><br><br> <a href="">http://gvlay6u4g53rxdi5.onion/21-Al9gJCAJ2fd8LgNEdEBLhNUw5QUOgJlP-JVMF20wIlKxlS7OrHBXpCbCONEIVsdhU</a><br> * Note that this server is available via Tor browser only<br><br> Follow the instructions to open the link:<br> 1. Type the addres "https://www.torproject.org" in your Internet browser. It opens the Tor site.<br> 2. Press "Download Tor", then press "Download Tor Browser Bundle", install and run it.<br> 3. Now you have Tor browser. In the Tor Browser open "{
offset: 0
success 0 0
1619345069.13211
NtWriteFile
file_handle: 0x00000308
filepath: C:\Python27\include\Recovery_Instructions.html
buffer: <html> <style type="text/css"> body { background-color: #f5f5f5; } h1, h3{ text-align: center; text-transform: uppercase; font-weight: normal; } /*---*/ .tabs1{ display: block; margin: auto; } .tabs1 .head{ text-align: center; float: top; padding: 0px; text-transform: uppercase; font-weight: normal; display: block; background: #81bef7; color: #DF0101; font-size: 30px; } .tabs1 .identi { font-size: 10px; text-align: center; float: top; padding: 15px; display: block; background: #81bef7; color: #DFDFDF; } .tabs .content { background: #f5f5f5; /*text-align: center;*/ color: #000000; padding: 25px 15px; font-size: 15px; font-weight: 400; line-height: 20px; } .tabs .content a { color: #df0130; font-size: 23px; font-style: italic; text-decoration: none; line-height: 35px; } .tabs .content .text{ padding: 25px; line-height: 1.2; } </style> <body> <div class="tabs1"> <div class="head" ><b>Your personal ID:</b></div> <div class="identi"> <span style="width:1000px; color: #ffffff; font-size: 10px;">96B15FC03DCA8D175790CC1A893EEB4568E36CF6777F6CE5568ECDD6C33CDC4DC3B8A0AEBE17D5659209E6C658CCE1BE380E6C5350653A8A972180DDF12A276C<br>AF73EB431A73371B04B5BC86AEAACC8E3FC88B2F0E84D9C76161510D333EBD7686343FD08363EBC6A4D72ECCB63DB9C57C7AA9679310D262EB981A91960D<br>69A70480CD61A2D1DA4976232C86AA805C5B4389E7C04A8C9F65D5F80755A928BA67A0B7D9B5C5CA24883A4D8F4BD33CDEC232E5EFAB57377DE59B168050<br>2696BCA82218CA139ED899AD3837F84CF746A6FE76077F43A9DAFE9540482DB1415DAFC5559354C7E40262E301797BE8C3846F42A90AB20A4DF3462C44EC<br>A25F788CBCA026EA628E63C223A27603710293A1DDF2CABDE3C276BA5C79066F5199B66174620070248310D761B7E4DE7AA3667D4273B71A26A82665E0A1<br>D468573772BFA7618599E04F5124F8B0FAD9B7D6DB0052484E499F049C2E5E400C836E66FE8027CA345FCF44A91BB58CD7077E46091938E100DDCA98E33E<br>015E73596ADADAD1533B831EEDAF489F1FCC1316E4494C9F161C4768FE5F449AB8BE1243B39CF3CD885429DB86B7995E0957715D83511FAEB69A44C7225D<br>07D1C95F152B367363080F26DA65A2CF7CE7FCA38622B3BBCEDD3CCB76AB3B64E6F01FC13FB5E9B4215C6EC3471763678A48FAA7CF7C0180274464B845E5<br>17439641C9A3690410E686D1B601</span> <br> <!-- !!! dont changing this !!! --> </div> </div> <!-- --> <div class="tabs"> <!--tab--> <div class="tab"> <div id="tab-content1" class="content"> <div class="text"> <!--text data --> <b>/!\ YOUR COMPANY NETWORK HAS BEEN PENETRATED /!\</b><br> <b>ALL YOUR IMPORTANT FILES HAVE BEEN ENCRYPTED!</b><br><br> YOUR FILES ARE SAFE! JUST MODIFIED ONLY. (RSA+AES) <br><br> ANY ATTEMPT TO RESTORE YOUR FILES WITH THIRD-PARTY SOFTWARE<br> WILL PERMENANTLY DESTROY YOUR FILE.<br> DO NOT MODIFY ENCRYPTED FILES. DO NOT RENAME ENCRYPTED FILES.<br><br> NO SOFTWARE AVAILABLE ON INTERNET CAN HELP YOU. WE ONLY HAVE<br> SOLUTION TO YOUR PROBLEM.<br><br> WE GATHERED HIGHLY CONFIDENTIAL/PERSORNAL DATA. THESE DATA<br> ARE CURRENTLY STORED ON A PRIVATE SERVER. THIS SERVER WILL BE<br> IMMEDIATELY DESTROYED AFTER YOUR PAYMENT. WE ONLY SEEK MONEY<br> AND DO NOT WANT TO DAMAGE YOUR REPUTATION. IF YOU DECIDE TO<br> NOT PAY, WE WILL RELEASE THIS DATA TO PUBLIC OR RE-SELLER.<br><br> YOU WILL CAN SEND US 2-3 NON-IMPORTANT FILES AND WE WILL<br> DECRYPT IT FOR FREE TO PROVE WE ARE ABLE TO GIVE YOUR FILES<br> BACK.<br><br> <!--text data --> <hr> <b>Contact us for price and get decryption software.</b><br><br> <a href="">http://gvlay6u4g53rxdi5.onion/21-Al9gJCAJ2fd8LgNEdEBLhNUw5QUOgJlP-JVMF20wIlKxlS7OrHBXpCbCONEIVsdhU</a><br> * Note that this server is available via Tor browser only<br><br> Follow the instructions to open the link:<br> 1. Type the addres "https://www.torproject.org" in your Internet browser. It opens the Tor site.<br> 2. Press "Download Tor", then press "Download Tor Browser Bundle", install and run it.<br> 3. Now you have Tor browser. In the Tor Browser open "{
offset: 0
success 0 0
1619345069.22611
NtWriteFile
file_handle: 0x00000308
filepath: C:\Python27\include\Recovery_Instructions.html
buffer: <html> <style type="text/css"> body { background-color: #f5f5f5; } h1, h3{ text-align: center; text-transform: uppercase; font-weight: normal; } /*---*/ .tabs1{ display: block; margin: auto; } .tabs1 .head{ text-align: center; float: top; padding: 0px; text-transform: uppercase; font-weight: normal; display: block; background: #81bef7; color: #DF0101; font-size: 30px; } .tabs1 .identi { font-size: 10px; text-align: center; float: top; padding: 15px; display: block; background: #81bef7; color: #DFDFDF; } .tabs .content { background: #f5f5f5; /*text-align: center;*/ color: #000000; padding: 25px 15px; font-size: 15px; font-weight: 400; line-height: 20px; } .tabs .content a { color: #df0130; font-size: 23px; font-style: italic; text-decoration: none; line-height: 35px; } .tabs .content .text{ padding: 25px; line-height: 1.2; } </style> <body> <div class="tabs1"> <div class="head" ><b>Your personal ID:</b></div> <div class="identi"> <span style="width:1000px; color: #ffffff; font-size: 10px;">96B15FC03DCA8D175790CC1A893EEB4568E36CF6777F6CE5568ECDD6C33CDC4DC3B8A0AEBE17D5659209E6C658CCE1BE380E6C5350653A8A972180DDF12A276C<br>AF73EB431A73371B04B5BC86AEAACC8E3FC88B2F0E84D9C76161510D333EBD7686343FD08363EBC6A4D72ECCB63DB9C57C7AA9679310D262EB981A91960D<br>69A70480CD61A2D1DA4976232C86AA805C5B4389E7C04A8C9F65D5F80755A928BA67A0B7D9B5C5CA24883A4D8F4BD33CDEC232E5EFAB57377DE59B168050<br>2696BCA82218CA139ED899AD3837F84CF746A6FE76077F43A9DAFE9540482DB1415DAFC5559354C7E40262E301797BE8C3846F42A90AB20A4DF3462C44EC<br>A25F788CBCA026EA628E63C223A27603710293A1DDF2CABDE3C276BA5C79066F5199B66174620070248310D761B7E4DE7AA3667D4273B71A26A82665E0A1<br>D468573772BFA7618599E04F5124F8B0FAD9B7D6DB0052484E499F049C2E5E400C836E66FE8027CA345FCF44A91BB58CD7077E46091938E100DDCA98E33E<br>015E73596ADADAD1533B831EEDAF489F1FCC1316E4494C9F161C4768FE5F449AB8BE1243B39CF3CD885429DB86B7995E0957715D83511FAEB69A44C7225D<br>07D1C95F152B367363080F26DA65A2CF7CE7FCA38622B3BBCEDD3CCB76AB3B64E6F01FC13FB5E9B4215C6EC3471763678A48FAA7CF7C0180274464B845E5<br>17439641C9A3690410E686D1B601</span> <br> <!-- !!! dont changing this !!! --> </div> </div> <!-- --> <div class="tabs"> <!--tab--> <div class="tab"> <div id="tab-content1" class="content"> <div class="text"> <!--text data --> <b>/!\ YOUR COMPANY NETWORK HAS BEEN PENETRATED /!\</b><br> <b>ALL YOUR IMPORTANT FILES HAVE BEEN ENCRYPTED!</b><br><br> YOUR FILES ARE SAFE! JUST MODIFIED ONLY. (RSA+AES) <br><br> ANY ATTEMPT TO RESTORE YOUR FILES WITH THIRD-PARTY SOFTWARE<br> WILL PERMENANTLY DESTROY YOUR FILE.<br> DO NOT MODIFY ENCRYPTED FILES. DO NOT RENAME ENCRYPTED FILES.<br><br> NO SOFTWARE AVAILABLE ON INTERNET CAN HELP YOU. WE ONLY HAVE<br> SOLUTION TO YOUR PROBLEM.<br><br> WE GATHERED HIGHLY CONFIDENTIAL/PERSORNAL DATA. THESE DATA<br> ARE CURRENTLY STORED ON A PRIVATE SERVER. THIS SERVER WILL BE<br> IMMEDIATELY DESTROYED AFTER YOUR PAYMENT. WE ONLY SEEK MONEY<br> AND DO NOT WANT TO DAMAGE YOUR REPUTATION. IF YOU DECIDE TO<br> NOT PAY, WE WILL RELEASE THIS DATA TO PUBLIC OR RE-SELLER.<br><br> YOU WILL CAN SEND US 2-3 NON-IMPORTANT FILES AND WE WILL<br> DECRYPT IT FOR FREE TO PROVE WE ARE ABLE TO GIVE YOUR FILES<br> BACK.<br><br> <!--text data --> <hr> <b>Contact us for price and get decryption software.</b><br><br> <a href="">http://gvlay6u4g53rxdi5.onion/21-Al9gJCAJ2fd8LgNEdEBLhNUw5QUOgJlP-JVMF20wIlKxlS7OrHBXpCbCONEIVsdhU</a><br> * Note that this server is available via Tor browser only<br><br> Follow the instructions to open the link:<br> 1. Type the addres "https://www.torproject.org" in your Internet browser. It opens the Tor site.<br> 2. Press "Download Tor", then press "Download Tor Browser Bundle", install and run it.<br> 3. Now you have Tor browser. In the Tor Browser open "{
offset: 0
success 0 0
1619345069.33511
NtWriteFile
file_handle: 0x00000308
filepath: C:\Python27\include\Recovery_Instructions.html
buffer: <html> <style type="text/css"> body { background-color: #f5f5f5; } h1, h3{ text-align: center; text-transform: uppercase; font-weight: normal; } /*---*/ .tabs1{ display: block; margin: auto; } .tabs1 .head{ text-align: center; float: top; padding: 0px; text-transform: uppercase; font-weight: normal; display: block; background: #81bef7; color: #DF0101; font-size: 30px; } .tabs1 .identi { font-size: 10px; text-align: center; float: top; padding: 15px; display: block; background: #81bef7; color: #DFDFDF; } .tabs .content { background: #f5f5f5; /*text-align: center;*/ color: #000000; padding: 25px 15px; font-size: 15px; font-weight: 400; line-height: 20px; } .tabs .content a { color: #df0130; font-size: 23px; font-style: italic; text-decoration: none; line-height: 35px; } .tabs .content .text{ padding: 25px; line-height: 1.2; } </style> <body> <div class="tabs1"> <div class="head" ><b>Your personal ID:</b></div> <div class="identi"> <span style="width:1000px; color: #ffffff; font-size: 10px;">96B15FC03DCA8D175790CC1A893EEB4568E36CF6777F6CE5568ECDD6C33CDC4DC3B8A0AEBE17D5659209E6C658CCE1BE380E6C5350653A8A972180DDF12A276C<br>AF73EB431A73371B04B5BC86AEAACC8E3FC88B2F0E84D9C76161510D333EBD7686343FD08363EBC6A4D72ECCB63DB9C57C7AA9679310D262EB981A91960D<br>69A70480CD61A2D1DA4976232C86AA805C5B4389E7C04A8C9F65D5F80755A928BA67A0B7D9B5C5CA24883A4D8F4BD33CDEC232E5EFAB57377DE59B168050<br>2696BCA82218CA139ED899AD3837F84CF746A6FE76077F43A9DAFE9540482DB1415DAFC5559354C7E40262E301797BE8C3846F42A90AB20A4DF3462C44EC<br>A25F788CBCA026EA628E63C223A27603710293A1DDF2CABDE3C276BA5C79066F5199B66174620070248310D761B7E4DE7AA3667D4273B71A26A82665E0A1<br>D468573772BFA7618599E04F5124F8B0FAD9B7D6DB0052484E499F049C2E5E400C836E66FE8027CA345FCF44A91BB58CD7077E46091938E100DDCA98E33E<br>015E73596ADADAD1533B831EEDAF489F1FCC1316E4494C9F161C4768FE5F449AB8BE1243B39CF3CD885429DB86B7995E0957715D83511FAEB69A44C7225D<br>07D1C95F152B367363080F26DA65A2CF7CE7FCA38622B3BBCEDD3CCB76AB3B64E6F01FC13FB5E9B4215C6EC3471763678A48FAA7CF7C0180274464B845E5<br>17439641C9A3690410E686D1B601</span> <br> <!-- !!! dont changing this !!! --> </div> </div> <!-- --> <div class="tabs"> <!--tab--> <div class="tab"> <div id="tab-content1" class="content"> <div class="text"> <!--text data --> <b>/!\ YOUR COMPANY NETWORK HAS BEEN PENETRATED /!\</b><br> <b>ALL YOUR IMPORTANT FILES HAVE BEEN ENCRYPTED!</b><br><br> YOUR FILES ARE SAFE! JUST MODIFIED ONLY. (RSA+AES) <br><br> ANY ATTEMPT TO RESTORE YOUR FILES WITH THIRD-PARTY SOFTWARE<br> WILL PERMENANTLY DESTROY YOUR FILE.<br> DO NOT MODIFY ENCRYPTED FILES. DO NOT RENAME ENCRYPTED FILES.<br><br> NO SOFTWARE AVAILABLE ON INTERNET CAN HELP YOU. WE ONLY HAVE<br> SOLUTION TO YOUR PROBLEM.<br><br> WE GATHERED HIGHLY CONFIDENTIAL/PERSORNAL DATA. THESE DATA<br> ARE CURRENTLY STORED ON A PRIVATE SERVER. THIS SERVER WILL BE<br> IMMEDIATELY DESTROYED AFTER YOUR PAYMENT. WE ONLY SEEK MONEY<br> AND DO NOT WANT TO DAMAGE YOUR REPUTATION. IF YOU DECIDE TO<br> NOT PAY, WE WILL RELEASE THIS DATA TO PUBLIC OR RE-SELLER.<br><br> YOU WILL CAN SEND US 2-3 NON-IMPORTANT FILES AND WE WILL<br> DECRYPT IT FOR FREE TO PROVE WE ARE ABLE TO GIVE YOUR FILES<br> BACK.<br><br> <!--text data --> <hr> <b>Contact us for price and get decryption software.</b><br><br> <a href="">http://gvlay6u4g53rxdi5.onion/21-Al9gJCAJ2fd8LgNEdEBLhNUw5QUOgJlP-JVMF20wIlKxlS7OrHBXpCbCONEIVsdhU</a><br> * Note that this server is available via Tor browser only<br><br> Follow the instructions to open the link:<br> 1. Type the addres "https://www.torproject.org" in your Internet browser. It opens the Tor site.<br> 2. Press "Download Tor", then press "Download Tor Browser Bundle", install and run it.<br> 3. Now you have Tor browser. In the Tor Browser open "{
offset: 0
success 0 0
1619345069.41311
NtWriteFile
file_handle: 0x00000308
filepath: C:\Python27\include\Recovery_Instructions.html
buffer: <html> <style type="text/css"> body { background-color: #f5f5f5; } h1, h3{ text-align: center; text-transform: uppercase; font-weight: normal; } /*---*/ .tabs1{ display: block; margin: auto; } .tabs1 .head{ text-align: center; float: top; padding: 0px; text-transform: uppercase; font-weight: normal; display: block; background: #81bef7; color: #DF0101; font-size: 30px; } .tabs1 .identi { font-size: 10px; text-align: center; float: top; padding: 15px; display: block; background: #81bef7; color: #DFDFDF; } .tabs .content { background: #f5f5f5; /*text-align: center;*/ color: #000000; padding: 25px 15px; font-size: 15px; font-weight: 400; line-height: 20px; } .tabs .content a { color: #df0130; font-size: 23px; font-style: italic; text-decoration: none; line-height: 35px; } .tabs .content .text{ padding: 25px; line-height: 1.2; } </style> <body> <div class="tabs1"> <div class="head" ><b>Your personal ID:</b></div> <div class="identi"> <span style="width:1000px; color: #ffffff; font-size: 10px;">96B15FC03DCA8D175790CC1A893EEB4568E36CF6777F6CE5568ECDD6C33CDC4DC3B8A0AEBE17D5659209E6C658CCE1BE380E6C5350653A8A972180DDF12A276C<br>AF73EB431A73371B04B5BC86AEAACC8E3FC88B2F0E84D9C76161510D333EBD7686343FD08363EBC6A4D72ECCB63DB9C57C7AA9679310D262EB981A91960D<br>69A70480CD61A2D1DA4976232C86AA805C5B4389E7C04A8C9F65D5F80755A928BA67A0B7D9B5C5CA24883A4D8F4BD33CDEC232E5EFAB57377DE59B168050<br>2696BCA82218CA139ED899AD3837F84CF746A6FE76077F43A9DAFE9540482DB1415DAFC5559354C7E40262E301797BE8C3846F42A90AB20A4DF3462C44EC<br>A25F788CBCA026EA628E63C223A27603710293A1DDF2CABDE3C276BA5C79066F5199B66174620070248310D761B7E4DE7AA3667D4273B71A26A82665E0A1<br>D468573772BFA7618599E04F5124F8B0FAD9B7D6DB0052484E499F049C2E5E400C836E66FE8027CA345FCF44A91BB58CD7077E46091938E100DDCA98E33E<br>015E73596ADADAD1533B831EEDAF489F1FCC1316E4494C9F161C4768FE5F449AB8BE1243B39CF3CD885429DB86B7995E0957715D83511FAEB69A44C7225D<br>07D1C95F152B367363080F26DA65A2CF7CE7FCA38622B3BBCEDD3CCB76AB3B64E6F01FC13FB5E9B4215C6EC3471763678A48FAA7CF7C0180274464B845E5<br>17439641C9A3690410E686D1B601</span> <br> <!-- !!! dont changing this !!! --> </div> </div> <!-- --> <div class="tabs"> <!--tab--> <div class="tab"> <div id="tab-content1" class="content"> <div class="text"> <!--text data --> <b>/!\ YOUR COMPANY NETWORK HAS BEEN PENETRATED /!\</b><br> <b>ALL YOUR IMPORTANT FILES HAVE BEEN ENCRYPTED!</b><br><br> YOUR FILES ARE SAFE! JUST MODIFIED ONLY. (RSA+AES) <br><br> ANY ATTEMPT TO RESTORE YOUR FILES WITH THIRD-PARTY SOFTWARE<br> WILL PERMENANTLY DESTROY YOUR FILE.<br> DO NOT MODIFY ENCRYPTED FILES. DO NOT RENAME ENCRYPTED FILES.<br><br> NO SOFTWARE AVAILABLE ON INTERNET CAN HELP YOU. WE ONLY HAVE<br> SOLUTION TO YOUR PROBLEM.<br><br> WE GATHERED HIGHLY CONFIDENTIAL/PERSORNAL DATA. THESE DATA<br> ARE CURRENTLY STORED ON A PRIVATE SERVER. THIS SERVER WILL BE<br> IMMEDIATELY DESTROYED AFTER YOUR PAYMENT. WE ONLY SEEK MONEY<br> AND DO NOT WANT TO DAMAGE YOUR REPUTATION. IF YOU DECIDE TO<br> NOT PAY, WE WILL RELEASE THIS DATA TO PUBLIC OR RE-SELLER.<br><br> YOU WILL CAN SEND US 2-3 NON-IMPORTANT FILES AND WE WILL<br> DECRYPT IT FOR FREE TO PROVE WE ARE ABLE TO GIVE YOUR FILES<br> BACK.<br><br> <!--text data --> <hr> <b>Contact us for price and get decryption software.</b><br><br> <a href="">http://gvlay6u4g53rxdi5.onion/21-Al9gJCAJ2fd8LgNEdEBLhNUw5QUOgJlP-JVMF20wIlKxlS7OrHBXpCbCONEIVsdhU</a><br> * Note that this server is available via Tor browser only<br><br> Follow the instructions to open the link:<br> 1. Type the addres "https://www.torproject.org" in your Internet browser. It opens the Tor site.<br> 2. Press "Download Tor", then press "Download Tor Browser Bundle", install and run it.<br> 3. Now you have Tor browser. In the Tor Browser open "{
offset: 0
success 0 0
1619345069.49111
NtWriteFile
file_handle: 0x00000308
filepath: C:\Python27\include\Recovery_Instructions.html
buffer: <html> <style type="text/css"> body { background-color: #f5f5f5; } h1, h3{ text-align: center; text-transform: uppercase; font-weight: normal; } /*---*/ .tabs1{ display: block; margin: auto; } .tabs1 .head{ text-align: center; float: top; padding: 0px; text-transform: uppercase; font-weight: normal; display: block; background: #81bef7; color: #DF0101; font-size: 30px; } .tabs1 .identi { font-size: 10px; text-align: center; float: top; padding: 15px; display: block; background: #81bef7; color: #DFDFDF; } .tabs .content { background: #f5f5f5; /*text-align: center;*/ color: #000000; padding: 25px 15px; font-size: 15px; font-weight: 400; line-height: 20px; } .tabs .content a { color: #df0130; font-size: 23px; font-style: italic; text-decoration: none; line-height: 35px; } .tabs .content .text{ padding: 25px; line-height: 1.2; } </style> <body> <div class="tabs1"> <div class="head" ><b>Your personal ID:</b></div> <div class="identi"> <span style="width:1000px; color: #ffffff; font-size: 10px;">96B15FC03DCA8D175790CC1A893EEB4568E36CF6777F6CE5568ECDD6C33CDC4DC3B8A0AEBE17D5659209E6C658CCE1BE380E6C5350653A8A972180DDF12A276C<br>AF73EB431A73371B04B5BC86AEAACC8E3FC88B2F0E84D9C76161510D333EBD7686343FD08363EBC6A4D72ECCB63DB9C57C7AA9679310D262EB981A91960D<br>69A70480CD61A2D1DA4976232C86AA805C5B4389E7C04A8C9F65D5F80755A928BA67A0B7D9B5C5CA24883A4D8F4BD33CDEC232E5EFAB57377DE59B168050<br>2696BCA82218CA139ED899AD3837F84CF746A6FE76077F43A9DAFE9540482DB1415DAFC5559354C7E40262E301797BE8C3846F42A90AB20A4DF3462C44EC<br>A25F788CBCA026EA628E63C223A27603710293A1DDF2CABDE3C276BA5C79066F5199B66174620070248310D761B7E4DE7AA3667D4273B71A26A82665E0A1<br>D468573772BFA7618599E04F5124F8B0FAD9B7D6DB0052484E499F049C2E5E400C836E66FE8027CA345FCF44A91BB58CD7077E46091938E100DDCA98E33E<br>015E73596ADADAD1533B831EEDAF489F1FCC1316E4494C9F161C4768FE5F449AB8BE1243B39CF3CD885429DB86B7995E0957715D83511FAEB69A44C7225D<br>07D1C95F152B367363080F26DA65A2CF7CE7FCA38622B3BBCEDD3CCB76AB3B64E6F01FC13FB5E9B4215C6EC3471763678A48FAA7CF7C0180274464B845E5<br>17439641C9A3690410E686D1B601</span> <br> <!-- !!! dont changing this !!! --> </div> </div> <!-- --> <div class="tabs"> <!--tab--> <div class="tab"> <div id="tab-content1" class="content"> <div class="text"> <!--text data --> <b>/!\ YOUR COMPANY NETWORK HAS BEEN PENETRATED /!\</b><br> <b>ALL YOUR IMPORTANT FILES HAVE BEEN ENCRYPTED!</b><br><br> YOUR FILES ARE SAFE! JUST MODIFIED ONLY. (RSA+AES) <br><br> ANY ATTEMPT TO RESTORE YOUR FILES WITH THIRD-PARTY SOFTWARE<br> WILL PERMENANTLY DESTROY YOUR FILE.<br> DO NOT MODIFY ENCRYPTED FILES. DO NOT RENAME ENCRYPTED FILES.<br><br> NO SOFTWARE AVAILABLE ON INTERNET CAN HELP YOU. WE ONLY HAVE<br> SOLUTION TO YOUR PROBLEM.<br><br> WE GATHERED HIGHLY CONFIDENTIAL/PERSORNAL DATA. THESE DATA<br> ARE CURRENTLY STORED ON A PRIVATE SERVER. THIS SERVER WILL BE<br> IMMEDIATELY DESTROYED AFTER YOUR PAYMENT. WE ONLY SEEK MONEY<br> AND DO NOT WANT TO DAMAGE YOUR REPUTATION. IF YOU DECIDE TO<br> NOT PAY, WE WILL RELEASE THIS DATA TO PUBLIC OR RE-SELLER.<br><br> YOU WILL CAN SEND US 2-3 NON-IMPORTANT FILES AND WE WILL<br> DECRYPT IT FOR FREE TO PROVE WE ARE ABLE TO GIVE YOUR FILES<br> BACK.<br><br> <!--text data --> <hr> <b>Contact us for price and get decryption software.</b><br><br> <a href="">http://gvlay6u4g53rxdi5.onion/21-Al9gJCAJ2fd8LgNEdEBLhNUw5QUOgJlP-JVMF20wIlKxlS7OrHBXpCbCONEIVsdhU</a><br> * Note that this server is available via Tor browser only<br><br> Follow the instructions to open the link:<br> 1. Type the addres "https://www.torproject.org" in your Internet browser. It opens the Tor site.<br> 2. Press "Download Tor", then press "Download Tor Browser Bundle", install and run it.<br> 3. Now you have Tor browser. In the Tor Browser open "{
offset: 0
success 0 0
1619345069.58511
NtWriteFile
file_handle: 0x00000308
filepath: C:\Python27\include\Recovery_Instructions.html
buffer: <html> <style type="text/css"> body { background-color: #f5f5f5; } h1, h3{ text-align: center; text-transform: uppercase; font-weight: normal; } /*---*/ .tabs1{ display: block; margin: auto; } .tabs1 .head{ text-align: center; float: top; padding: 0px; text-transform: uppercase; font-weight: normal; display: block; background: #81bef7; color: #DF0101; font-size: 30px; } .tabs1 .identi { font-size: 10px; text-align: center; float: top; padding: 15px; display: block; background: #81bef7; color: #DFDFDF; } .tabs .content { background: #f5f5f5; /*text-align: center;*/ color: #000000; padding: 25px 15px; font-size: 15px; font-weight: 400; line-height: 20px; } .tabs .content a { color: #df0130; font-size: 23px; font-style: italic; text-decoration: none; line-height: 35px; } .tabs .content .text{ padding: 25px; line-height: 1.2; } </style> <body> <div class="tabs1"> <div class="head" ><b>Your personal ID:</b></div> <div class="identi"> <span style="width:1000px; color: #ffffff; font-size: 10px;">96B15FC03DCA8D175790CC1A893EEB4568E36CF6777F6CE5568ECDD6C33CDC4DC3B8A0AEBE17D5659209E6C658CCE1BE380E6C5350653A8A972180DDF12A276C<br>AF73EB431A73371B04B5BC86AEAACC8E3FC88B2F0E84D9C76161510D333EBD7686343FD08363EBC6A4D72ECCB63DB9C57C7AA9679310D262EB981A91960D<br>69A70480CD61A2D1DA4976232C86AA805C5B4389E7C04A8C9F65D5F80755A928BA67A0B7D9B5C5CA24883A4D8F4BD33CDEC232E5EFAB57377DE59B168050<br>2696BCA82218CA139ED899AD3837F84CF746A6FE76077F43A9DAFE9540482DB1415DAFC5559354C7E40262E301797BE8C3846F42A90AB20A4DF3462C44EC<br>A25F788CBCA026EA628E63C223A27603710293A1DDF2CABDE3C276BA5C79066F5199B66174620070248310D761B7E4DE7AA3667D4273B71A26A82665E0A1<br>D468573772BFA7618599E04F5124F8B0FAD9B7D6DB0052484E499F049C2E5E400C836E66FE8027CA345FCF44A91BB58CD7077E46091938E100DDCA98E33E<br>015E73596ADADAD1533B831EEDAF489F1FCC1316E4494C9F161C4768FE5F449AB8BE1243B39CF3CD885429DB86B7995E0957715D83511FAEB69A44C7225D<br>07D1C95F152B367363080F26DA65A2CF7CE7FCA38622B3BBCEDD3CCB76AB3B64E6F01FC13FB5E9B4215C6EC3471763678A48FAA7CF7C0180274464B845E5<br>17439641C9A3690410E686D1B601</span> <br> <!-- !!! dont changing this !!! --> </div> </div> <!-- --> <div class="tabs"> <!--tab--> <div class="tab"> <div id="tab-content1" class="content"> <div class="text"> <!--text data --> <b>/!\ YOUR COMPANY NETWORK HAS BEEN PENETRATED /!\</b><br> <b>ALL YOUR IMPORTANT FILES HAVE BEEN ENCRYPTED!</b><br><br> YOUR FILES ARE SAFE! JUST MODIFIED ONLY. (RSA+AES) <br><br> ANY ATTEMPT TO RESTORE YOUR FILES WITH THIRD-PARTY SOFTWARE<br> WILL PERMENANTLY DESTROY YOUR FILE.<br> DO NOT MODIFY ENCRYPTED FILES. DO NOT RENAME ENCRYPTED FILES.<br><br> NO SOFTWARE AVAILABLE ON INTERNET CAN HELP YOU. WE ONLY HAVE<br> SOLUTION TO YOUR PROBLEM.<br><br> WE GATHERED HIGHLY CONFIDENTIAL/PERSORNAL DATA. THESE DATA<br> ARE CURRENTLY STORED ON A PRIVATE SERVER. THIS SERVER WILL BE<br> IMMEDIATELY DESTROYED AFTER YOUR PAYMENT. WE ONLY SEEK MONEY<br> AND DO NOT WANT TO DAMAGE YOUR REPUTATION. IF YOU DECIDE TO<br> NOT PAY, WE WILL RELEASE THIS DATA TO PUBLIC OR RE-SELLER.<br><br> YOU WILL CAN SEND US 2-3 NON-IMPORTANT FILES AND WE WILL<br> DECRYPT IT FOR FREE TO PROVE WE ARE ABLE TO GIVE YOUR FILES<br> BACK.<br><br> <!--text data --> <hr> <b>Contact us for price and get decryption software.</b><br><br> <a href="">http://gvlay6u4g53rxdi5.onion/21-Al9gJCAJ2fd8LgNEdEBLhNUw5QUOgJlP-JVMF20wIlKxlS7OrHBXpCbCONEIVsdhU</a><br> * Note that this server is available via Tor browser only<br><br> Follow the instructions to open the link:<br> 1. Type the addres "https://www.torproject.org" in your Internet browser. It opens the Tor site.<br> 2. Press "Download Tor", then press "Download Tor Browser Bundle", install and run it.<br> 3. Now you have Tor browser. In the Tor Browser open "{
offset: 0
success 0 0
1619345069.74111
NtWriteFile
file_handle: 0x00000308
filepath: C:\Python27\include\Recovery_Instructions.html
buffer: <html> <style type="text/css"> body { background-color: #f5f5f5; } h1, h3{ text-align: center; text-transform: uppercase; font-weight: normal; } /*---*/ .tabs1{ display: block; margin: auto; } .tabs1 .head{ text-align: center; float: top; padding: 0px; text-transform: uppercase; font-weight: normal; display: block; background: #81bef7; color: #DF0101; font-size: 30px; } .tabs1 .identi { font-size: 10px; text-align: center; float: top; padding: 15px; display: block; background: #81bef7; color: #DFDFDF; } .tabs .content { background: #f5f5f5; /*text-align: center;*/ color: #000000; padding: 25px 15px; font-size: 15px; font-weight: 400; line-height: 20px; } .tabs .content a { color: #df0130; font-size: 23px; font-style: italic; text-decoration: none; line-height: 35px; } .tabs .content .text{ padding: 25px; line-height: 1.2; } </style> <body> <div class="tabs1"> <div class="head" ><b>Your personal ID:</b></div> <div class="identi"> <span style="width:1000px; color: #ffffff; font-size: 10px;">96B15FC03DCA8D175790CC1A893EEB4568E36CF6777F6CE5568ECDD6C33CDC4DC3B8A0AEBE17D5659209E6C658CCE1BE380E6C5350653A8A972180DDF12A276C<br>AF73EB431A73371B04B5BC86AEAACC8E3FC88B2F0E84D9C76161510D333EBD7686343FD08363EBC6A4D72ECCB63DB9C57C7AA9679310D262EB981A91960D<br>69A70480CD61A2D1DA4976232C86AA805C5B4389E7C04A8C9F65D5F80755A928BA67A0B7D9B5C5CA24883A4D8F4BD33CDEC232E5EFAB57377DE59B168050<br>2696BCA82218CA139ED899AD3837F84CF746A6FE76077F43A9DAFE9540482DB1415DAFC5559354C7E40262E301797BE8C3846F42A90AB20A4DF3462C44EC<br>A25F788CBCA026EA628E63C223A27603710293A1DDF2CABDE3C276BA5C79066F5199B66174620070248310D761B7E4DE7AA3667D4273B71A26A82665E0A1<br>D468573772BFA7618599E04F5124F8B0FAD9B7D6DB0052484E499F049C2E5E400C836E66FE8027CA345FCF44A91BB58CD7077E46091938E100DDCA98E33E<br>015E73596ADADAD1533B831EEDAF489F1FCC1316E4494C9F161C4768FE5F449AB8BE1243B39CF3CD885429DB86B7995E0957715D83511FAEB69A44C7225D<br>07D1C95F152B367363080F26DA65A2CF7CE7FCA38622B3BBCEDD3CCB76AB3B64E6F01FC13FB5E9B4215C6EC3471763678A48FAA7CF7C0180274464B845E5<br>17439641C9A3690410E686D1B601</span> <br> <!-- !!! dont changing this !!! --> </div> </div> <!-- --> <div class="tabs"> <!--tab--> <div class="tab"> <div id="tab-content1" class="content"> <div class="text"> <!--text data --> <b>/!\ YOUR COMPANY NETWORK HAS BEEN PENETRATED /!\</b><br> <b>ALL YOUR IMPORTANT FILES HAVE BEEN ENCRYPTED!</b><br><br> YOUR FILES ARE SAFE! JUST MODIFIED ONLY. (RSA+AES) <br><br> ANY ATTEMPT TO RESTORE YOUR FILES WITH THIRD-PARTY SOFTWARE<br> WILL PERMENANTLY DESTROY YOUR FILE.<br> DO NOT MODIFY ENCRYPTED FILES. DO NOT RENAME ENCRYPTED FILES.<br><br> NO SOFTWARE AVAILABLE ON INTERNET CAN HELP YOU. WE ONLY HAVE<br> SOLUTION TO YOUR PROBLEM.<br><br> WE GATHERED HIGHLY CONFIDENTIAL/PERSORNAL DATA. THESE DATA<br> ARE CURRENTLY STORED ON A PRIVATE SERVER. THIS SERVER WILL BE<br> IMMEDIATELY DESTROYED AFTER YOUR PAYMENT. WE ONLY SEEK MONEY<br> AND DO NOT WANT TO DAMAGE YOUR REPUTATION. IF YOU DECIDE TO<br> NOT PAY, WE WILL RELEASE THIS DATA TO PUBLIC OR RE-SELLER.<br><br> YOU WILL CAN SEND US 2-3 NON-IMPORTANT FILES AND WE WILL<br> DECRYPT IT FOR FREE TO PROVE WE ARE ABLE TO GIVE YOUR FILES<br> BACK.<br><br> <!--text data --> <hr> <b>Contact us for price and get decryption software.</b><br><br> <a href="">http://gvlay6u4g53rxdi5.onion/21-Al9gJCAJ2fd8LgNEdEBLhNUw5QUOgJlP-JVMF20wIlKxlS7OrHBXpCbCONEIVsdhU</a><br> * Note that this server is available via Tor browser only<br><br> Follow the instructions to open the link:<br> 1. Type the addres "https://www.torproject.org" in your Internet browser. It opens the Tor site.<br> 2. Press "Download Tor", then press "Download Tor Browser Bundle", install and run it.<br> 3. Now you have Tor browser. In the Tor Browser open "{
offset: 0
success 0 0
1619345069.81911
NtWriteFile
file_handle: 0x00000308
filepath: C:\Python27\include\Recovery_Instructions.html
buffer: <html> <style type="text/css"> body { background-color: #f5f5f5; } h1, h3{ text-align: center; text-transform: uppercase; font-weight: normal; } /*---*/ .tabs1{ display: block; margin: auto; } .tabs1 .head{ text-align: center; float: top; padding: 0px; text-transform: uppercase; font-weight: normal; display: block; background: #81bef7; color: #DF0101; font-size: 30px; } .tabs1 .identi { font-size: 10px; text-align: center; float: top; padding: 15px; display: block; background: #81bef7; color: #DFDFDF; } .tabs .content { background: #f5f5f5; /*text-align: center;*/ color: #000000; padding: 25px 15px; font-size: 15px; font-weight: 400; line-height: 20px; } .tabs .content a { color: #df0130; font-size: 23px; font-style: italic; text-decoration: none; line-height: 35px; } .tabs .content .text{ padding: 25px; line-height: 1.2; } </style> <body> <div class="tabs1"> <div class="head" ><b>Your personal ID:</b></div> <div class="identi"> <span style="width:1000px; color: #ffffff; font-size: 10px;">96B15FC03DCA8D175790CC1A893EEB4568E36CF6777F6CE5568ECDD6C33CDC4DC3B8A0AEBE17D5659209E6C658CCE1BE380E6C5350653A8A972180DDF12A276C<br>AF73EB431A73371B04B5BC86AEAACC8E3FC88B2F0E84D9C76161510D333EBD7686343FD08363EBC6A4D72ECCB63DB9C57C7AA9679310D262EB981A91960D<br>69A70480CD61A2D1DA4976232C86AA805C5B4389E7C04A8C9F65D5F80755A928BA67A0B7D9B5C5CA24883A4D8F4BD33CDEC232E5EFAB57377DE59B168050<br>2696BCA82218CA139ED899AD3837F84CF746A6FE76077F43A9DAFE9540482DB1415DAFC5559354C7E40262E301797BE8C3846F42A90AB20A4DF3462C44EC<br>A25F788CBCA026EA628E63C223A27603710293A1DDF2CABDE3C276BA5C79066F5199B66174620070248310D761B7E4DE7AA3667D4273B71A26A82665E0A1<br>D468573772BFA7618599E04F5124F8B0FAD9B7D6DB0052484E499F049C2E5E400C836E66FE8027CA345FCF44A91BB58CD7077E46091938E100DDCA98E33E<br>015E73596ADADAD1533B831EEDAF489F1FCC1316E4494C9F161C4768FE5F449AB8BE1243B39CF3CD885429DB86B7995E0957715D83511FAEB69A44C7225D<br>07D1C95F152B367363080F26DA65A2CF7CE7FCA38622B3BBCEDD3CCB76AB3B64E6F01FC13FB5E9B4215C6EC3471763678A48FAA7CF7C0180274464B845E5<br>17439641C9A3690410E686D1B601</span> <br> <!-- !!! dont changing this !!! --> </div> </div> <!-- --> <div class="tabs"> <!--tab--> <div class="tab"> <div id="tab-content1" class="content"> <div class="text"> <!--text data --> <b>/!\ YOUR COMPANY NETWORK HAS BEEN PENETRATED /!\</b><br> <b>ALL YOUR IMPORTANT FILES HAVE BEEN ENCRYPTED!</b><br><br> YOUR FILES ARE SAFE! JUST MODIFIED ONLY. (RSA+AES) <br><br> ANY ATTEMPT TO RESTORE YOUR FILES WITH THIRD-PARTY SOFTWARE<br> WILL PERMENANTLY DESTROY YOUR FILE.<br> DO NOT MODIFY ENCRYPTED FILES. DO NOT RENAME ENCRYPTED FILES.<br><br> NO SOFTWARE AVAILABLE ON INTERNET CAN HELP YOU. WE ONLY HAVE<br> SOLUTION TO YOUR PROBLEM.<br><br> WE GATHERED HIGHLY CONFIDENTIAL/PERSORNAL DATA. THESE DATA<br> ARE CURRENTLY STORED ON A PRIVATE SERVER. THIS SERVER WILL BE<br> IMMEDIATELY DESTROYED AFTER YOUR PAYMENT. WE ONLY SEEK MONEY<br> AND DO NOT WANT TO DAMAGE YOUR REPUTATION. IF YOU DECIDE TO<br> NOT PAY, WE WILL RELEASE THIS DATA TO PUBLIC OR RE-SELLER.<br><br> YOU WILL CAN SEND US 2-3 NON-IMPORTANT FILES AND WE WILL<br> DECRYPT IT FOR FREE TO PROVE WE ARE ABLE TO GIVE YOUR FILES<br> BACK.<br><br> <!--text data --> <hr> <b>Contact us for price and get decryption software.</b><br><br> <a href="">http://gvlay6u4g53rxdi5.onion/21-Al9gJCAJ2fd8LgNEdEBLhNUw5QUOgJlP-JVMF20wIlKxlS7OrHBXpCbCONEIVsdhU</a><br> * Note that this server is available via Tor browser only<br><br> Follow the instructions to open the link:<br> 1. Type the addres "https://www.torproject.org" in your Internet browser. It opens the Tor site.<br> 2. Press "Download Tor", then press "Download Tor Browser Bundle", install and run it.<br> 3. Now you have Tor browser. In the Tor Browser open "{
offset: 0
success 0 0
1619345069.88211
NtWriteFile
file_handle: 0x00000308
filepath: C:\Python27\include\Recovery_Instructions.html
buffer: <html> <style type="text/css"> body { background-color: #f5f5f5; } h1, h3{ text-align: center; text-transform: uppercase; font-weight: normal; } /*---*/ .tabs1{ display: block; margin: auto; } .tabs1 .head{ text-align: center; float: top; padding: 0px; text-transform: uppercase; font-weight: normal; display: block; background: #81bef7; color: #DF0101; font-size: 30px; } .tabs1 .identi { font-size: 10px; text-align: center; float: top; padding: 15px; display: block; background: #81bef7; color: #DFDFDF; } .tabs .content { background: #f5f5f5; /*text-align: center;*/ color: #000000; padding: 25px 15px; font-size: 15px; font-weight: 400; line-height: 20px; } .tabs .content a { color: #df0130; font-size: 23px; font-style: italic; text-decoration: none; line-height: 35px; } .tabs .content .text{ padding: 25px; line-height: 1.2; } </style> <body> <div class="tabs1"> <div class="head" ><b>Your personal ID:</b></div> <div class="identi"> <span style="width:1000px; color: #ffffff; font-size: 10px;">96B15FC03DCA8D175790CC1A893EEB4568E36CF6777F6CE5568ECDD6C33CDC4DC3B8A0AEBE17D5659209E6C658CCE1BE380E6C5350653A8A972180DDF12A276C<br>AF73EB431A73371B04B5BC86AEAACC8E3FC88B2F0E84D9C76161510D333EBD7686343FD08363EBC6A4D72ECCB63DB9C57C7AA9679310D262EB981A91960D<br>69A70480CD61A2D1DA4976232C86AA805C5B4389E7C04A8C9F65D5F80755A928BA67A0B7D9B5C5CA24883A4D8F4BD33CDEC232E5EFAB57377DE59B168050<br>2696BCA82218CA139ED899AD3837F84CF746A6FE76077F43A9DAFE9540482DB1415DAFC5559354C7E40262E301797BE8C3846F42A90AB20A4DF3462C44EC<br>A25F788CBCA026EA628E63C223A27603710293A1DDF2CABDE3C276BA5C79066F5199B66174620070248310D761B7E4DE7AA3667D4273B71A26A82665E0A1<br>D468573772BFA7618599E04F5124F8B0FAD9B7D6DB0052484E499F049C2E5E400C836E66FE8027CA345FCF44A91BB58CD7077E46091938E100DDCA98E33E<br>015E73596ADADAD1533B831EEDAF489F1FCC1316E4494C9F161C4768FE5F449AB8BE1243B39CF3CD885429DB86B7995E0957715D83511FAEB69A44C7225D<br>07D1C95F152B367363080F26DA65A2CF7CE7FCA38622B3BBCEDD3CCB76AB3B64E6F01FC13FB5E9B4215C6EC3471763678A48FAA7CF7C0180274464B845E5<br>17439641C9A3690410E686D1B601</span> <br> <!-- !!! dont changing this !!! --> </div> </div> <!-- --> <div class="tabs"> <!--tab--> <div class="tab"> <div id="tab-content1" class="content"> <div class="text"> <!--text data --> <b>/!\ YOUR COMPANY NETWORK HAS BEEN PENETRATED /!\</b><br> <b>ALL YOUR IMPORTANT FILES HAVE BEEN ENCRYPTED!</b><br><br> YOUR FILES ARE SAFE! JUST MODIFIED ONLY. (RSA+AES) <br><br> ANY ATTEMPT TO RESTORE YOUR FILES WITH THIRD-PARTY SOFTWARE<br> WILL PERMENANTLY DESTROY YOUR FILE.<br> DO NOT MODIFY ENCRYPTED FILES. DO NOT RENAME ENCRYPTED FILES.<br><br> NO SOFTWARE AVAILABLE ON INTERNET CAN HELP YOU. WE ONLY HAVE<br> SOLUTION TO YOUR PROBLEM.<br><br> WE GATHERED HIGHLY CONFIDENTIAL/PERSORNAL DATA. THESE DATA<br> ARE CURRENTLY STORED ON A PRIVATE SERVER. THIS SERVER WILL BE<br> IMMEDIATELY DESTROYED AFTER YOUR PAYMENT. WE ONLY SEEK MONEY<br> AND DO NOT WANT TO DAMAGE YOUR REPUTATION. IF YOU DECIDE TO<br> NOT PAY, WE WILL RELEASE THIS DATA TO PUBLIC OR RE-SELLER.<br><br> YOU WILL CAN SEND US 2-3 NON-IMPORTANT FILES AND WE WILL<br> DECRYPT IT FOR FREE TO PROVE WE ARE ABLE TO GIVE YOUR FILES<br> BACK.<br><br> <!--text data --> <hr> <b>Contact us for price and get decryption software.</b><br><br> <a href="">http://gvlay6u4g53rxdi5.onion/21-Al9gJCAJ2fd8LgNEdEBLhNUw5QUOgJlP-JVMF20wIlKxlS7OrHBXpCbCONEIVsdhU</a><br> * Note that this server is available via Tor browser only<br><br> Follow the instructions to open the link:<br> 1. Type the addres "https://www.torproject.org" in your Internet browser. It opens the Tor site.<br> 2. Press "Download Tor", then press "Download Tor Browser Bundle", install and run it.<br> 3. Now you have Tor browser. In the Tor Browser open "{
offset: 0
success 0 0
1619345069.96011
NtWriteFile
file_handle: 0x00000308
filepath: C:\Python27\include\Recovery_Instructions.html
buffer: <html> <style type="text/css"> body { background-color: #f5f5f5; } h1, h3{ text-align: center; text-transform: uppercase; font-weight: normal; } /*---*/ .tabs1{ display: block; margin: auto; } .tabs1 .head{ text-align: center; float: top; padding: 0px; text-transform: uppercase; font-weight: normal; display: block; background: #81bef7; color: #DF0101; font-size: 30px; } .tabs1 .identi { font-size: 10px; text-align: center; float: top; padding: 15px; display: block; background: #81bef7; color: #DFDFDF; } .tabs .content { background: #f5f5f5; /*text-align: center;*/ color: #000000; padding: 25px 15px; font-size: 15px; font-weight: 400; line-height: 20px; } .tabs .content a { color: #df0130; font-size: 23px; font-style: italic; text-decoration: none; line-height: 35px; } .tabs .content .text{ padding: 25px; line-height: 1.2; } </style> <body> <div class="tabs1"> <div class="head" ><b>Your personal ID:</b></div> <div class="identi"> <span style="width:1000px; color: #ffffff; font-size: 10px;">96B15FC03DCA8D175790CC1A893EEB4568E36CF6777F6CE5568ECDD6C33CDC4DC3B8A0AEBE17D5659209E6C658CCE1BE380E6C5350653A8A972180DDF12A276C<br>AF73EB431A73371B04B5BC86AEAACC8E3FC88B2F0E84D9C76161510D333EBD7686343FD08363EBC6A4D72ECCB63DB9C57C7AA9679310D262EB981A91960D<br>69A70480CD61A2D1DA4976232C86AA805C5B4389E7C04A8C9F65D5F80755A928BA67A0B7D9B5C5CA24883A4D8F4BD33CDEC232E5EFAB57377DE59B168050<br>2696BCA82218CA139ED899AD3837F84CF746A6FE76077F43A9DAFE9540482DB1415DAFC5559354C7E40262E301797BE8C3846F42A90AB20A4DF3462C44EC<br>A25F788CBCA026EA628E63C223A27603710293A1DDF2CABDE3C276BA5C79066F5199B66174620070248310D761B7E4DE7AA3667D4273B71A26A82665E0A1<br>D468573772BFA7618599E04F5124F8B0FAD9B7D6DB0052484E499F049C2E5E400C836E66FE8027CA345FCF44A91BB58CD7077E46091938E100DDCA98E33E<br>015E73596ADADAD1533B831EEDAF489F1FCC1316E4494C9F161C4768FE5F449AB8BE1243B39CF3CD885429DB86B7995E0957715D83511FAEB69A44C7225D<br>07D1C95F152B367363080F26DA65A2CF7CE7FCA38622B3BBCEDD3CCB76AB3B64E6F01FC13FB5E9B4215C6EC3471763678A48FAA7CF7C0180274464B845E5<br>17439641C9A3690410E686D1B601</span> <br> <!-- !!! dont changing this !!! --> </div> </div> <!-- --> <div class="tabs"> <!--tab--> <div class="tab"> <div id="tab-content1" class="content"> <div class="text"> <!--text data --> <b>/!\ YOUR COMPANY NETWORK HAS BEEN PENETRATED /!\</b><br> <b>ALL YOUR IMPORTANT FILES HAVE BEEN ENCRYPTED!</b><br><br> YOUR FILES ARE SAFE! JUST MODIFIED ONLY. (RSA+AES) <br><br> ANY ATTEMPT TO RESTORE YOUR FILES WITH THIRD-PARTY SOFTWARE<br> WILL PERMENANTLY DESTROY YOUR FILE.<br> DO NOT MODIFY ENCRYPTED FILES. DO NOT RENAME ENCRYPTED FILES.<br><br> NO SOFTWARE AVAILABLE ON INTERNET CAN HELP YOU. WE ONLY HAVE<br> SOLUTION TO YOUR PROBLEM.<br><br> WE GATHERED HIGHLY CONFIDENTIAL/PERSORNAL DATA. THESE DATA<br> ARE CURRENTLY STORED ON A PRIVATE SERVER. THIS SERVER WILL BE<br> IMMEDIATELY DESTROYED AFTER YOUR PAYMENT. WE ONLY SEEK MONEY<br> AND DO NOT WANT TO DAMAGE YOUR REPUTATION. IF YOU DECIDE TO<br> NOT PAY, WE WILL RELEASE THIS DATA TO PUBLIC OR RE-SELLER.<br><br> YOU WILL CAN SEND US 2-3 NON-IMPORTANT FILES AND WE WILL<br> DECRYPT IT FOR FREE TO PROVE WE ARE ABLE TO GIVE YOUR FILES<br> BACK.<br><br> <!--text data --> <hr> <b>Contact us for price and get decryption software.</b><br><br> <a href="">http://gvlay6u4g53rxdi5.onion/21-Al9gJCAJ2fd8LgNEdEBLhNUw5QUOgJlP-JVMF20wIlKxlS7OrHBXpCbCONEIVsdhU</a><br> * Note that this server is available via Tor browser only<br><br> Follow the instructions to open the link:<br> 1. Type the addres "https://www.torproject.org" in your Internet browser. It opens the Tor site.<br> 2. Press "Download Tor", then press "Download Tor Browser Bundle", install and run it.<br> 3. Now you have Tor browser. In the Tor Browser open "{
offset: 0
success 0 0
1619345070.06911
NtWriteFile
file_handle: 0x00000308
filepath: C:\Python27\include\Recovery_Instructions.html
buffer: <html> <style type="text/css"> body { background-color: #f5f5f5; } h1, h3{ text-align: center; text-transform: uppercase; font-weight: normal; } /*---*/ .tabs1{ display: block; margin: auto; } .tabs1 .head{ text-align: center; float: top; padding: 0px; text-transform: uppercase; font-weight: normal; display: block; background: #81bef7; color: #DF0101; font-size: 30px; } .tabs1 .identi { font-size: 10px; text-align: center; float: top; padding: 15px; display: block; background: #81bef7; color: #DFDFDF; } .tabs .content { background: #f5f5f5; /*text-align: center;*/ color: #000000; padding: 25px 15px; font-size: 15px; font-weight: 400; line-height: 20px; } .tabs .content a { color: #df0130; font-size: 23px; font-style: italic; text-decoration: none; line-height: 35px; } .tabs .content .text{ padding: 25px; line-height: 1.2; } </style> <body> <div class="tabs1"> <div class="head" ><b>Your personal ID:</b></div> <div class="identi"> <span style="width:1000px; color: #ffffff; font-size: 10px;">96B15FC03DCA8D175790CC1A893EEB4568E36CF6777F6CE5568ECDD6C33CDC4DC3B8A0AEBE17D5659209E6C658CCE1BE380E6C5350653A8A972180DDF12A276C<br>AF73EB431A73371B04B5BC86AEAACC8E3FC88B2F0E84D9C76161510D333EBD7686343FD08363EBC6A4D72ECCB63DB9C57C7AA9679310D262EB981A91960D<br>69A70480CD61A2D1DA4976232C86AA805C5B4389E7C04A8C9F65D5F80755A928BA67A0B7D9B5C5CA24883A4D8F4BD33CDEC232E5EFAB57377DE59B168050<br>2696BCA82218CA139ED899AD3837F84CF746A6FE76077F43A9DAFE9540482DB1415DAFC5559354C7E40262E301797BE8C3846F42A90AB20A4DF3462C44EC<br>A25F788CBCA026EA628E63C223A27603710293A1DDF2CABDE3C276BA5C79066F5199B66174620070248310D761B7E4DE7AA3667D4273B71A26A82665E0A1<br>D468573772BFA7618599E04F5124F8B0FAD9B7D6DB0052484E499F049C2E5E400C836E66FE8027CA345FCF44A91BB58CD7077E46091938E100DDCA98E33E<br>015E73596ADADAD1533B831EEDAF489F1FCC1316E4494C9F161C4768FE5F449AB8BE1243B39CF3CD885429DB86B7995E0957715D83511FAEB69A44C7225D<br>07D1C95F152B367363080F26DA65A2CF7CE7FCA38622B3BBCEDD3CCB76AB3B64E6F01FC13FB5E9B4215C6EC3471763678A48FAA7CF7C0180274464B845E5<br>17439641C9A3690410E686D1B601</span> <br> <!-- !!! dont changing this !!! --> </div> </div> <!-- --> <div class="tabs"> <!--tab--> <div class="tab"> <div id="tab-content1" class="content"> <div class="text"> <!--text data --> <b>/!\ YOUR COMPANY NETWORK HAS BEEN PENETRATED /!\</b><br> <b>ALL YOUR IMPORTANT FILES HAVE BEEN ENCRYPTED!</b><br><br> YOUR FILES ARE SAFE! JUST MODIFIED ONLY. (RSA+AES) <br><br> ANY ATTEMPT TO RESTORE YOUR FILES WITH THIRD-PARTY SOFTWARE<br> WILL PERMENANTLY DESTROY YOUR FILE.<br> DO NOT MODIFY ENCRYPTED FILES. DO NOT RENAME ENCRYPTED FILES.<br><br> NO SOFTWARE AVAILABLE ON INTERNET CAN HELP YOU. WE ONLY HAVE<br> SOLUTION TO YOUR PROBLEM.<br><br> WE GATHERED HIGHLY CONFIDENTIAL/PERSORNAL DATA. THESE DATA<br> ARE CURRENTLY STORED ON A PRIVATE SERVER. THIS SERVER WILL BE<br> IMMEDIATELY DESTROYED AFTER YOUR PAYMENT. WE ONLY SEEK MONEY<br> AND DO NOT WANT TO DAMAGE YOUR REPUTATION. IF YOU DECIDE TO<br> NOT PAY, WE WILL RELEASE THIS DATA TO PUBLIC OR RE-SELLER.<br><br> YOU WILL CAN SEND US 2-3 NON-IMPORTANT FILES AND WE WILL<br> DECRYPT IT FOR FREE TO PROVE WE ARE ABLE TO GIVE YOUR FILES<br> BACK.<br><br> <!--text data --> <hr> <b>Contact us for price and get decryption software.</b><br><br> <a href="">http://gvlay6u4g53rxdi5.onion/21-Al9gJCAJ2fd8LgNEdEBLhNUw5QUOgJlP-JVMF20wIlKxlS7OrHBXpCbCONEIVsdhU</a><br> * Note that this server is available via Tor browser only<br><br> Follow the instructions to open the link:<br> 1. Type the addres "https://www.torproject.org" in your Internet browser. It opens the Tor site.<br> 2. Press "Download Tor", then press "Download Tor Browser Bundle", install and run it.<br> 3. Now you have Tor browser. In the Tor Browser open "{
offset: 0
success 0 0
1619345070.13211
NtWriteFile
file_handle: 0x00000308
filepath: C:\Python27\include\Recovery_Instructions.html
buffer: <html> <style type="text/css"> body { background-color: #f5f5f5; } h1, h3{ text-align: center; text-transform: uppercase; font-weight: normal; } /*---*/ .tabs1{ display: block; margin: auto; } .tabs1 .head{ text-align: center; float: top; padding: 0px; text-transform: uppercase; font-weight: normal; display: block; background: #81bef7; color: #DF0101; font-size: 30px; } .tabs1 .identi { font-size: 10px; text-align: center; float: top; padding: 15px; display: block; background: #81bef7; color: #DFDFDF; } .tabs .content { background: #f5f5f5; /*text-align: center;*/ color: #000000; padding: 25px 15px; font-size: 15px; font-weight: 400; line-height: 20px; } .tabs .content a { color: #df0130; font-size: 23px; font-style: italic; text-decoration: none; line-height: 35px; } .tabs .content .text{ padding: 25px; line-height: 1.2; } </style> <body> <div class="tabs1"> <div class="head" ><b>Your personal ID:</b></div> <div class="identi"> <span style="width:1000px; color: #ffffff; font-size: 10px;">96B15FC03DCA8D175790CC1A893EEB4568E36CF6777F6CE5568ECDD6C33CDC4DC3B8A0AEBE17D5659209E6C658CCE1BE380E6C5350653A8A972180DDF12A276C<br>AF73EB431A73371B04B5BC86AEAACC8E3FC88B2F0E84D9C76161510D333EBD7686343FD08363EBC6A4D72ECCB63DB9C57C7AA9679310D262EB981A91960D<br>69A70480CD61A2D1DA4976232C86AA805C5B4389E7C04A8C9F65D5F80755A928BA67A0B7D9B5C5CA24883A4D8F4BD33CDEC232E5EFAB57377DE59B168050<br>2696BCA82218CA139ED899AD3837F84CF746A6FE76077F43A9DAFE9540482DB1415DAFC5559354C7E40262E301797BE8C3846F42A90AB20A4DF3462C44EC<br>A25F788CBCA026EA628E63C223A27603710293A1DDF2CABDE3C276BA5C79066F5199B66174620070248310D761B7E4DE7AA3667D4273B71A26A82665E0A1<br>D468573772BFA7618599E04F5124F8B0FAD9B7D6DB0052484E499F049C2E5E400C836E66FE8027CA345FCF44A91BB58CD7077E46091938E100DDCA98E33E<br>015E73596ADADAD1533B831EEDAF489F1FCC1316E4494C9F161C4768FE5F449AB8BE1243B39CF3CD885429DB86B7995E0957715D83511FAEB69A44C7225D<br>07D1C95F152B367363080F26DA65A2CF7CE7FCA38622B3BBCEDD3CCB76AB3B64E6F01FC13FB5E9B4215C6EC3471763678A48FAA7CF7C0180274464B845E5<br>17439641C9A3690410E686D1B601</span> <br> <!-- !!! dont changing this !!! --> </div> </div> <!-- --> <div class="tabs"> <!--tab--> <div class="tab"> <div id="tab-content1" class="content"> <div class="text"> <!--text data --> <b>/!\ YOUR COMPANY NETWORK HAS BEEN PENETRATED /!\</b><br> <b>ALL YOUR IMPORTANT FILES HAVE BEEN ENCRYPTED!</b><br><br> YOUR FILES ARE SAFE! JUST MODIFIED ONLY. (RSA+AES) <br><br> ANY ATTEMPT TO RESTORE YOUR FILES WITH THIRD-PARTY SOFTWARE<br> WILL PERMENANTLY DESTROY YOUR FILE.<br> DO NOT MODIFY ENCRYPTED FILES. DO NOT RENAME ENCRYPTED FILES.<br><br> NO SOFTWARE AVAILABLE ON INTERNET CAN HELP YOU. WE ONLY HAVE<br> SOLUTION TO YOUR PROBLEM.<br><br> WE GATHERED HIGHLY CONFIDENTIAL/PERSORNAL DATA. THESE DATA<br> ARE CURRENTLY STORED ON A PRIVATE SERVER. THIS SERVER WILL BE<br> IMMEDIATELY DESTROYED AFTER YOUR PAYMENT. WE ONLY SEEK MONEY<br> AND DO NOT WANT TO DAMAGE YOUR REPUTATION. IF YOU DECIDE TO<br> NOT PAY, WE WILL RELEASE THIS DATA TO PUBLIC OR RE-SELLER.<br><br> YOU WILL CAN SEND US 2-3 NON-IMPORTANT FILES AND WE WILL<br> DECRYPT IT FOR FREE TO PROVE WE ARE ABLE TO GIVE YOUR FILES<br> BACK.<br><br> <!--text data --> <hr> <b>Contact us for price and get decryption software.</b><br><br> <a href="">http://gvlay6u4g53rxdi5.onion/21-Al9gJCAJ2fd8LgNEdEBLhNUw5QUOgJlP-JVMF20wIlKxlS7OrHBXpCbCONEIVsdhU</a><br> * Note that this server is available via Tor browser only<br><br> Follow the instructions to open the link:<br> 1. Type the addres "https://www.torproject.org" in your Internet browser. It opens the Tor site.<br> 2. Press "Download Tor", then press "Download Tor Browser Bundle", install and run it.<br> 3. Now you have Tor browser. In the Tor Browser open "{
offset: 0
success 0 0
1619345070.22611
NtWriteFile
file_handle: 0x00000308
filepath: C:\Python27\include\Recovery_Instructions.html
buffer: <html> <style type="text/css"> body { background-color: #f5f5f5; } h1, h3{ text-align: center; text-transform: uppercase; font-weight: normal; } /*---*/ .tabs1{ display: block; margin: auto; } .tabs1 .head{ text-align: center; float: top; padding: 0px; text-transform: uppercase; font-weight: normal; display: block; background: #81bef7; color: #DF0101; font-size: 30px; } .tabs1 .identi { font-size: 10px; text-align: center; float: top; padding: 15px; display: block; background: #81bef7; color: #DFDFDF; } .tabs .content { background: #f5f5f5; /*text-align: center;*/ color: #000000; padding: 25px 15px; font-size: 15px; font-weight: 400; line-height: 20px; } .tabs .content a { color: #df0130; font-size: 23px; font-style: italic; text-decoration: none; line-height: 35px; } .tabs .content .text{ padding: 25px; line-height: 1.2; } </style> <body> <div class="tabs1"> <div class="head" ><b>Your personal ID:</b></div> <div class="identi"> <span style="width:1000px; color: #ffffff; font-size: 10px;">96B15FC03DCA8D175790CC1A893EEB4568E36CF6777F6CE5568ECDD6C33CDC4DC3B8A0AEBE17D5659209E6C658CCE1BE380E6C5350653A8A972180DDF12A276C<br>AF73EB431A73371B04B5BC86AEAACC8E3FC88B2F0E84D9C76161510D333EBD7686343FD08363EBC6A4D72ECCB63DB9C57C7AA9679310D262EB981A91960D<br>69A70480CD61A2D1DA4976232C86AA805C5B4389E7C04A8C9F65D5F80755A928BA67A0B7D9B5C5CA24883A4D8F4BD33CDEC232E5EFAB57377DE59B168050<br>2696BCA82218CA139ED899AD3837F84CF746A6FE76077F43A9DAFE9540482DB1415DAFC5559354C7E40262E301797BE8C3846F42A90AB20A4DF3462C44EC<br>A25F788CBCA026EA628E63C223A27603710293A1DDF2CABDE3C276BA5C79066F5199B66174620070248310D761B7E4DE7AA3667D4273B71A26A82665E0A1<br>D468573772BFA7618599E04F5124F8B0FAD9B7D6DB0052484E499F049C2E5E400C836E66FE8027CA345FCF44A91BB58CD7077E46091938E100DDCA98E33E<br>015E73596ADADAD1533B831EEDAF489F1FCC1316E4494C9F161C4768FE5F449AB8BE1243B39CF3CD885429DB86B7995E0957715D83511FAEB69A44C7225D<br>07D1C95F152B367363080F26DA65A2CF7CE7FCA38622B3BBCEDD3CCB76AB3B64E6F01FC13FB5E9B4215C6EC3471763678A48FAA7CF7C0180274464B845E5<br>17439641C9A3690410E686D1B601</span> <br> <!-- !!! dont changing this !!! --> </div> </div> <!-- --> <div class="tabs"> <!--tab--> <div class="tab"> <div id="tab-content1" class="content"> <div class="text"> <!--text data --> <b>/!\ YOUR COMPANY NETWORK HAS BEEN PENETRATED /!\</b><br> <b>ALL YOUR IMPORTANT FILES HAVE BEEN ENCRYPTED!</b><br><br> YOUR FILES ARE SAFE! JUST MODIFIED ONLY. (RSA+AES) <br><br> ANY ATTEMPT TO RESTORE YOUR FILES WITH THIRD-PARTY SOFTWARE<br> WILL PERMENANTLY DESTROY YOUR FILE.<br> DO NOT MODIFY ENCRYPTED FILES. DO NOT RENAME ENCRYPTED FILES.<br><br> NO SOFTWARE AVAILABLE ON INTERNET CAN HELP YOU. WE ONLY HAVE<br> SOLUTION TO YOUR PROBLEM.<br><br> WE GATHERED HIGHLY CONFIDENTIAL/PERSORNAL DATA. THESE DATA<br> ARE CURRENTLY STORED ON A PRIVATE SERVER. THIS SERVER WILL BE<br> IMMEDIATELY DESTROYED AFTER YOUR PAYMENT. WE ONLY SEEK MONEY<br> AND DO NOT WANT TO DAMAGE YOUR REPUTATION. IF YOU DECIDE TO<br> NOT PAY, WE WILL RELEASE THIS DATA TO PUBLIC OR RE-SELLER.<br><br> YOU WILL CAN SEND US 2-3 NON-IMPORTANT FILES AND WE WILL<br> DECRYPT IT FOR FREE TO PROVE WE ARE ABLE TO GIVE YOUR FILES<br> BACK.<br><br> <!--text data --> <hr> <b>Contact us for price and get decryption software.</b><br><br> <a href="">http://gvlay6u4g53rxdi5.onion/21-Al9gJCAJ2fd8LgNEdEBLhNUw5QUOgJlP-JVMF20wIlKxlS7OrHBXpCbCONEIVsdhU</a><br> * Note that this server is available via Tor browser only<br><br> Follow the instructions to open the link:<br> 1. Type the addres "https://www.torproject.org" in your Internet browser. It opens the Tor site.<br> 2. Press "Download Tor", then press "Download Tor Browser Bundle", install and run it.<br> 3. Now you have Tor browser. In the Tor Browser open "{
offset: 0
success 0 0
1619345070.31911
NtWriteFile
file_handle: 0x00000308
filepath: C:\Python27\include\Recovery_Instructions.html
buffer: <html> <style type="text/css"> body { background-color: #f5f5f5; } h1, h3{ text-align: center; text-transform: uppercase; font-weight: normal; } /*---*/ .tabs1{ display: block; margin: auto; } .tabs1 .head{ text-align: center; float: top; padding: 0px; text-transform: uppercase; font-weight: normal; display: block; background: #81bef7; color: #DF0101; font-size: 30px; } .tabs1 .identi { font-size: 10px; text-align: center; float: top; padding: 15px; display: block; background: #81bef7; color: #DFDFDF; } .tabs .content { background: #f5f5f5; /*text-align: center;*/ color: #000000; padding: 25px 15px; font-size: 15px; font-weight: 400; line-height: 20px; } .tabs .content a { color: #df0130; font-size: 23px; font-style: italic; text-decoration: none; line-height: 35px; } .tabs .content .text{ padding: 25px; line-height: 1.2; } </style> <body> <div class="tabs1"> <div class="head" ><b>Your personal ID:</b></div> <div class="identi"> <span style="width:1000px; color: #ffffff; font-size: 10px;">96B15FC03DCA8D175790CC1A893EEB4568E36CF6777F6CE5568ECDD6C33CDC4DC3B8A0AEBE17D5659209E6C658CCE1BE380E6C5350653A8A972180DDF12A276C<br>AF73EB431A73371B04B5BC86AEAACC8E3FC88B2F0E84D9C76161510D333EBD7686343FD08363EBC6A4D72ECCB63DB9C57C7AA9679310D262EB981A91960D<br>69A70480CD61A2D1DA4976232C86AA805C5B4389E7C04A8C9F65D5F80755A928BA67A0B7D9B5C5CA24883A4D8F4BD33CDEC232E5EFAB57377DE59B168050<br>2696BCA82218CA139ED899AD3837F84CF746A6FE76077F43A9DAFE9540482DB1415DAFC5559354C7E40262E301797BE8C3846F42A90AB20A4DF3462C44EC<br>A25F788CBCA026EA628E63C223A27603710293A1DDF2CABDE3C276BA5C79066F5199B66174620070248310D761B7E4DE7AA3667D4273B71A26A82665E0A1<br>D468573772BFA7618599E04F5124F8B0FAD9B7D6DB0052484E499F049C2E5E400C836E66FE8027CA345FCF44A91BB58CD7077E46091938E100DDCA98E33E<br>015E73596ADADAD1533B831EEDAF489F1FCC1316E4494C9F161C4768FE5F449AB8BE1243B39CF3CD885429DB86B7995E0957715D83511FAEB69A44C7225D<br>07D1C95F152B367363080F26DA65A2CF7CE7FCA38622B3BBCEDD3CCB76AB3B64E6F01FC13FB5E9B4215C6EC3471763678A48FAA7CF7C0180274464B845E5<br>17439641C9A3690410E686D1B601</span> <br> <!-- !!! dont changing this !!! --> </div> </div> <!-- --> <div class="tabs"> <!--tab--> <div class="tab"> <div id="tab-content1" class="content"> <div class="text"> <!--text data --> <b>/!\ YOUR COMPANY NETWORK HAS BEEN PENETRATED /!\</b><br> <b>ALL YOUR IMPORTANT FILES HAVE BEEN ENCRYPTED!</b><br><br> YOUR FILES ARE SAFE! JUST MODIFIED ONLY. (RSA+AES) <br><br> ANY ATTEMPT TO RESTORE YOUR FILES WITH THIRD-PARTY SOFTWARE<br> WILL PERMENANTLY DESTROY YOUR FILE.<br> DO NOT MODIFY ENCRYPTED FILES. DO NOT RENAME ENCRYPTED FILES.<br><br> NO SOFTWARE AVAILABLE ON INTERNET CAN HELP YOU. WE ONLY HAVE<br> SOLUTION TO YOUR PROBLEM.<br><br> WE GATHERED HIGHLY CONFIDENTIAL/PERSORNAL DATA. THESE DATA<br> ARE CURRENTLY STORED ON A PRIVATE SERVER. THIS SERVER WILL BE<br> IMMEDIATELY DESTROYED AFTER YOUR PAYMENT. WE ONLY SEEK MONEY<br> AND DO NOT WANT TO DAMAGE YOUR REPUTATION. IF YOU DECIDE TO<br> NOT PAY, WE WILL RELEASE THIS DATA TO PUBLIC OR RE-SELLER.<br><br> YOU WILL CAN SEND US 2-3 NON-IMPORTANT FILES AND WE WILL<br> DECRYPT IT FOR FREE TO PROVE WE ARE ABLE TO GIVE YOUR FILES<br> BACK.<br><br> <!--text data --> <hr> <b>Contact us for price and get decryption software.</b><br><br> <a href="">http://gvlay6u4g53rxdi5.onion/21-Al9gJCAJ2fd8LgNEdEBLhNUw5QUOgJlP-JVMF20wIlKxlS7OrHBXpCbCONEIVsdhU</a><br> * Note that this server is available via Tor browser only<br><br> Follow the instructions to open the link:<br> 1. Type the addres "https://www.torproject.org" in your Internet browser. It opens the Tor site.<br> 2. Press "Download Tor", then press "Download Tor Browser Bundle", install and run it.<br> 3. Now you have Tor browser. In the Tor Browser open "{
offset: 0
success 0 0
1619345070.47611
NtWriteFile
file_handle: 0x00000308
filepath: C:\Python27\include\Recovery_Instructions.html
buffer: <html> <style type="text/css"> body { background-color: #f5f5f5; } h1, h3{ text-align: center; text-transform: uppercase; font-weight: normal; } /*---*/ .tabs1{ display: block; margin: auto; } .tabs1 .head{ text-align: center; float: top; padding: 0px; text-transform: uppercase; font-weight: normal; display: block; background: #81bef7; color: #DF0101; font-size: 30px; } .tabs1 .identi { font-size: 10px; text-align: center; float: top; padding: 15px; display: block; background: #81bef7; color: #DFDFDF; } .tabs .content { background: #f5f5f5; /*text-align: center;*/ color: #000000; padding: 25px 15px; font-size: 15px; font-weight: 400; line-height: 20px; } .tabs .content a { color: #df0130; font-size: 23px; font-style: italic; text-decoration: none; line-height: 35px; } .tabs .content .text{ padding: 25px; line-height: 1.2; } </style> <body> <div class="tabs1"> <div class="head" ><b>Your personal ID:</b></div> <div class="identi"> <span style="width:1000px; color: #ffffff; font-size: 10px;">96B15FC03DCA8D175790CC1A893EEB4568E36CF6777F6CE5568ECDD6C33CDC4DC3B8A0AEBE17D5659209E6C658CCE1BE380E6C5350653A8A972180DDF12A276C<br>AF73EB431A73371B04B5BC86AEAACC8E3FC88B2F0E84D9C76161510D333EBD7686343FD08363EBC6A4D72ECCB63DB9C57C7AA9679310D262EB981A91960D<br>69A70480CD61A2D1DA4976232C86AA805C5B4389E7C04A8C9F65D5F80755A928BA67A0B7D9B5C5CA24883A4D8F4BD33CDEC232E5EFAB57377DE59B168050<br>2696BCA82218CA139ED899AD3837F84CF746A6FE76077F43A9DAFE9540482DB1415DAFC5559354C7E40262E301797BE8C3846F42A90AB20A4DF3462C44EC<br>A25F788CBCA026EA628E63C223A27603710293A1DDF2CABDE3C276BA5C79066F5199B66174620070248310D761B7E4DE7AA3667D4273B71A26A82665E0A1<br>D468573772BFA7618599E04F5124F8B0FAD9B7D6DB0052484E499F049C2E5E400C836E66FE8027CA345FCF44A91BB58CD7077E46091938E100DDCA98E33E<br>015E73596ADADAD1533B831EEDAF489F1FCC1316E4494C9F161C4768FE5F449AB8BE1243B39CF3CD885429DB86B7995E0957715D83511FAEB69A44C7225D<br>07D1C95F152B367363080F26DA65A2CF7CE7FCA38622B3BBCEDD3CCB76AB3B64E6F01FC13FB5E9B4215C6EC3471763678A48FAA7CF7C0180274464B845E5<br>17439641C9A3690410E686D1B601</span> <br> <!-- !!! dont changing this !!! --> </div> </div> <!-- --> <div class="tabs"> <!--tab--> <div class="tab"> <div id="tab-content1" class="content"> <div class="text"> <!--text data --> <b>/!\ YOUR COMPANY NETWORK HAS BEEN PENETRATED /!\</b><br> <b>ALL YOUR IMPORTANT FILES HAVE BEEN ENCRYPTED!</b><br><br> YOUR FILES ARE SAFE! JUST MODIFIED ONLY. (RSA+AES) <br><br> ANY ATTEMPT TO RESTORE YOUR FILES WITH THIRD-PARTY SOFTWARE<br> WILL PERMENANTLY DESTROY YOUR FILE.<br> DO NOT MODIFY ENCRYPTED FILES. DO NOT RENAME ENCRYPTED FILES.<br><br> NO SOFTWARE AVAILABLE ON INTERNET CAN HELP YOU. WE ONLY HAVE<br> SOLUTION TO YOUR PROBLEM.<br><br> WE GATHERED HIGHLY CONFIDENTIAL/PERSORNAL DATA. THESE DATA<br> ARE CURRENTLY STORED ON A PRIVATE SERVER. THIS SERVER WILL BE<br> IMMEDIATELY DESTROYED AFTER YOUR PAYMENT. WE ONLY SEEK MONEY<br> AND DO NOT WANT TO DAMAGE YOUR REPUTATION. IF YOU DECIDE TO<br> NOT PAY, WE WILL RELEASE THIS DATA TO PUBLIC OR RE-SELLER.<br><br> YOU WILL CAN SEND US 2-3 NON-IMPORTANT FILES AND WE WILL<br> DECRYPT IT FOR FREE TO PROVE WE ARE ABLE TO GIVE YOUR FILES<br> BACK.<br><br> <!--text data --> <hr> <b>Contact us for price and get decryption software.</b><br><br> <a href="">http://gvlay6u4g53rxdi5.onion/21-Al9gJCAJ2fd8LgNEdEBLhNUw5QUOgJlP-JVMF20wIlKxlS7OrHBXpCbCONEIVsdhU</a><br> * Note that this server is available via Tor browser only<br><br> Follow the instructions to open the link:<br> 1. Type the addres "https://www.torproject.org" in your Internet browser. It opens the Tor site.<br> 2. Press "Download Tor", then press "Download Tor Browser Bundle", install and run it.<br> 3. Now you have Tor browser. In the Tor Browser open "{
offset: 0
success 0 0
1619345070.63211
NtWriteFile
file_handle: 0x00000308
filepath: C:\Python27\include\Recovery_Instructions.html
buffer: <html> <style type="text/css"> body { background-color: #f5f5f5; } h1, h3{ text-align: center; text-transform: uppercase; font-weight: normal; } /*---*/ .tabs1{ display: block; margin: auto; } .tabs1 .head{ text-align: center; float: top; padding: 0px; text-transform: uppercase; font-weight: normal; display: block; background: #81bef7; color: #DF0101; font-size: 30px; } .tabs1 .identi { font-size: 10px; text-align: center; float: top; padding: 15px; display: block; background: #81bef7; color: #DFDFDF; } .tabs .content { background: #f5f5f5; /*text-align: center;*/ color: #000000; padding: 25px 15px; font-size: 15px; font-weight: 400; line-height: 20px; } .tabs .content a { color: #df0130; font-size: 23px; font-style: italic; text-decoration: none; line-height: 35px; } .tabs .content .text{ padding: 25px; line-height: 1.2; } </style> <body> <div class="tabs1"> <div class="head" ><b>Your personal ID:</b></div> <div class="identi"> <span style="width:1000px; color: #ffffff; font-size: 10px;">96B15FC03DCA8D175790CC1A893EEB4568E36CF6777F6CE5568ECDD6C33CDC4DC3B8A0AEBE17D5659209E6C658CCE1BE380E6C5350653A8A972180DDF12A276C<br>AF73EB431A73371B04B5BC86AEAACC8E3FC88B2F0E84D9C76161510D333EBD7686343FD08363EBC6A4D72ECCB63DB9C57C7AA9679310D262EB981A91960D<br>69A70480CD61A2D1DA4976232C86AA805C5B4389E7C04A8C9F65D5F80755A928BA67A0B7D9B5C5CA24883A4D8F4BD33CDEC232E5EFAB57377DE59B168050<br>2696BCA82218CA139ED899AD3837F84CF746A6FE76077F43A9DAFE9540482DB1415DAFC5559354C7E40262E301797BE8C3846F42A90AB20A4DF3462C44EC<br>A25F788CBCA026EA628E63C223A27603710293A1DDF2CABDE3C276BA5C79066F5199B66174620070248310D761B7E4DE7AA3667D4273B71A26A82665E0A1<br>D468573772BFA7618599E04F5124F8B0FAD9B7D6DB0052484E499F049C2E5E400C836E66FE8027CA345FCF44A91BB58CD7077E46091938E100DDCA98E33E<br>015E73596ADADAD1533B831EEDAF489F1FCC1316E4494C9F161C4768FE5F449AB8BE1243B39CF3CD885429DB86B7995E0957715D83511FAEB69A44C7225D<br>07D1C95F152B367363080F26DA65A2CF7CE7FCA38622B3BBCEDD3CCB76AB3B64E6F01FC13FB5E9B4215C6EC3471763678A48FAA7CF7C0180274464B845E5<br>17439641C9A3690410E686D1B601</span> <br> <!-- !!! dont changing this !!! --> </div> </div> <!-- --> <div class="tabs"> <!--tab--> <div class="tab"> <div id="tab-content1" class="content"> <div class="text"> <!--text data --> <b>/!\ YOUR COMPANY NETWORK HAS BEEN PENETRATED /!\</b><br> <b>ALL YOUR IMPORTANT FILES HAVE BEEN ENCRYPTED!</b><br><br> YOUR FILES ARE SAFE! JUST MODIFIED ONLY. (RSA+AES) <br><br> ANY ATTEMPT TO RESTORE YOUR FILES WITH THIRD-PARTY SOFTWARE<br> WILL PERMENANTLY DESTROY YOUR FILE.<br> DO NOT MODIFY ENCRYPTED FILES. DO NOT RENAME ENCRYPTED FILES.<br><br> NO SOFTWARE AVAILABLE ON INTERNET CAN HELP YOU. WE ONLY HAVE<br> SOLUTION TO YOUR PROBLEM.<br><br> WE GATHERED HIGHLY CONFIDENTIAL/PERSORNAL DATA. THESE DATA<br> ARE CURRENTLY STORED ON A PRIVATE SERVER. THIS SERVER WILL BE<br> IMMEDIATELY DESTROYED AFTER YOUR PAYMENT. WE ONLY SEEK MONEY<br> AND DO NOT WANT TO DAMAGE YOUR REPUTATION. IF YOU DECIDE TO<br> NOT PAY, WE WILL RELEASE THIS DATA TO PUBLIC OR RE-SELLER.<br><br> YOU WILL CAN SEND US 2-3 NON-IMPORTANT FILES AND WE WILL<br> DECRYPT IT FOR FREE TO PROVE WE ARE ABLE TO GIVE YOUR FILES<br> BACK.<br><br> <!--text data --> <hr> <b>Contact us for price and get decryption software.</b><br><br> <a href="">http://gvlay6u4g53rxdi5.onion/21-Al9gJCAJ2fd8LgNEdEBLhNUw5QUOgJlP-JVMF20wIlKxlS7OrHBXpCbCONEIVsdhU</a><br> * Note that this server is available via Tor browser only<br><br> Follow the instructions to open the link:<br> 1. Type the addres "https://www.torproject.org" in your Internet browser. It opens the Tor site.<br> 2. Press "Download Tor", then press "Download Tor Browser Bundle", install and run it.<br> 3. Now you have Tor browser. In the Tor Browser open "{
offset: 0
success 0 0
1619345070.97611
NtWriteFile
file_handle: 0x00000308
filepath: C:\Python27\include\Recovery_Instructions.html
buffer: <html> <style type="text/css"> body { background-color: #f5f5f5; } h1, h3{ text-align: center; text-transform: uppercase; font-weight: normal; } /*---*/ .tabs1{ display: block; margin: auto; } .tabs1 .head{ text-align: center; float: top; padding: 0px; text-transform: uppercase; font-weight: normal; display: block; background: #81bef7; color: #DF0101; font-size: 30px; } .tabs1 .identi { font-size: 10px; text-align: center; float: top; padding: 15px; display: block; background: #81bef7; color: #DFDFDF; } .tabs .content { background: #f5f5f5; /*text-align: center;*/ color: #000000; padding: 25px 15px; font-size: 15px; font-weight: 400; line-height: 20px; } .tabs .content a { color: #df0130; font-size: 23px; font-style: italic; text-decoration: none; line-height: 35px; } .tabs .content .text{ padding: 25px; line-height: 1.2; } </style> <body> <div class="tabs1"> <div class="head" ><b>Your personal ID:</b></div> <div class="identi"> <span style="width:1000px; color: #ffffff; font-size: 10px;">96B15FC03DCA8D175790CC1A893EEB4568E36CF6777F6CE5568ECDD6C33CDC4DC3B8A0AEBE17D5659209E6C658CCE1BE380E6C5350653A8A972180DDF12A276C<br>AF73EB431A73371B04B5BC86AEAACC8E3FC88B2F0E84D9C76161510D333EBD7686343FD08363EBC6A4D72ECCB63DB9C57C7AA9679310D262EB981A91960D<br>69A70480CD61A2D1DA4976232C86AA805C5B4389E7C04A8C9F65D5F80755A928BA67A0B7D9B5C5CA24883A4D8F4BD33CDEC232E5EFAB57377DE59B168050<br>2696BCA82218CA139ED899AD3837F84CF746A6FE76077F43A9DAFE9540482DB1415DAFC5559354C7E40262E301797BE8C3846F42A90AB20A4DF3462C44EC<br>A25F788CBCA026EA628E63C223A27603710293A1DDF2CABDE3C276BA5C79066F5199B66174620070248310D761B7E4DE7AA3667D4273B71A26A82665E0A1<br>D468573772BFA7618599E04F5124F8B0FAD9B7D6DB0052484E499F049C2E5E400C836E66FE8027CA345FCF44A91BB58CD7077E46091938E100DDCA98E33E<br>015E73596ADADAD1533B831EEDAF489F1FCC1316E4494C9F161C4768FE5F449AB8BE1243B39CF3CD885429DB86B7995E0957715D83511FAEB69A44C7225D<br>07D1C95F152B367363080F26DA65A2CF7CE7FCA38622B3BBCEDD3CCB76AB3B64E6F01FC13FB5E9B4215C6EC3471763678A48FAA7CF7C0180274464B845E5<br>17439641C9A3690410E686D1B601</span> <br> <!-- !!! dont changing this !!! --> </div> </div> <!-- --> <div class="tabs"> <!--tab--> <div class="tab"> <div id="tab-content1" class="content"> <div class="text"> <!--text data --> <b>/!\ YOUR COMPANY NETWORK HAS BEEN PENETRATED /!\</b><br> <b>ALL YOUR IMPORTANT FILES HAVE BEEN ENCRYPTED!</b><br><br> YOUR FILES ARE SAFE! JUST MODIFIED ONLY. (RSA+AES) <br><br> ANY ATTEMPT TO RESTORE YOUR FILES WITH THIRD-PARTY SOFTWARE<br> WILL PERMENANTLY DESTROY YOUR FILE.<br> DO NOT MODIFY ENCRYPTED FILES. DO NOT RENAME ENCRYPTED FILES.<br><br> NO SOFTWARE AVAILABLE ON INTERNET CAN HELP YOU. WE ONLY HAVE<br> SOLUTION TO YOUR PROBLEM.<br><br> WE GATHERED HIGHLY CONFIDENTIAL/PERSORNAL DATA. THESE DATA<br> ARE CURRENTLY STORED ON A PRIVATE SERVER. THIS SERVER WILL BE<br> IMMEDIATELY DESTROYED AFTER YOUR PAYMENT. WE ONLY SEEK MONEY<br> AND DO NOT WANT TO DAMAGE YOUR REPUTATION. IF YOU DECIDE TO<br> NOT PAY, WE WILL RELEASE THIS DATA TO PUBLIC OR RE-SELLER.<br><br> YOU WILL CAN SEND US 2-3 NON-IMPORTANT FILES AND WE WILL<br> DECRYPT IT FOR FREE TO PROVE WE ARE ABLE TO GIVE YOUR FILES<br> BACK.<br><br> <!--text data --> <hr> <b>Contact us for price and get decryption software.</b><br><br> <a href="">http://gvlay6u4g53rxdi5.onion/21-Al9gJCAJ2fd8LgNEdEBLhNUw5QUOgJlP-JVMF20wIlKxlS7OrHBXpCbCONEIVsdhU</a><br> * Note that this server is available via Tor browser only<br><br> Follow the instructions to open the link:<br> 1. Type the addres "https://www.torproject.org" in your Internet browser. It opens the Tor site.<br> 2. Press "Download Tor", then press "Download Tor Browser Bundle", install and run it.<br> 3. Now you have Tor browser. In the Tor Browser open "{
offset: 0
success 0 0
1619345071.16311
NtWriteFile
file_handle: 0x00000308
filepath: C:\Python27\include\Recovery_Instructions.html
buffer: <html> <style type="text/css"> body { background-color: #f5f5f5; } h1, h3{ text-align: center; text-transform: uppercase; font-weight: normal; } /*---*/ .tabs1{ display: block; margin: auto; } .tabs1 .head{ text-align: center; float: top; padding: 0px; text-transform: uppercase; font-weight: normal; display: block; background: #81bef7; color: #DF0101; font-size: 30px; } .tabs1 .identi { font-size: 10px; text-align: center; float: top; padding: 15px; display: block; background: #81bef7; color: #DFDFDF; } .tabs .content { background: #f5f5f5; /*text-align: center;*/ color: #000000; padding: 25px 15px; font-size: 15px; font-weight: 400; line-height: 20px; } .tabs .content a { color: #df0130; font-size: 23px; font-style: italic; text-decoration: none; line-height: 35px; } .tabs .content .text{ padding: 25px; line-height: 1.2; } </style> <body> <div class="tabs1"> <div class="head" ><b>Your personal ID:</b></div> <div class="identi"> <span style="width:1000px; color: #ffffff; font-size: 10px;">96B15FC03DCA8D175790CC1A893EEB4568E36CF6777F6CE5568ECDD6C33CDC4DC3B8A0AEBE17D5659209E6C658CCE1BE380E6C5350653A8A972180DDF12A276C<br>AF73EB431A73371B04B5BC86AEAACC8E3FC88B2F0E84D9C76161510D333EBD7686343FD08363EBC6A4D72ECCB63DB9C57C7AA9679310D262EB981A91960D<br>69A70480CD61A2D1DA4976232C86AA805C5B4389E7C04A8C9F65D5F80755A928BA67A0B7D9B5C5CA24883A4D8F4BD33CDEC232E5EFAB57377DE59B168050<br>2696BCA82218CA139ED899AD3837F84CF746A6FE76077F43A9DAFE9540482DB1415DAFC5559354C7E40262E301797BE8C3846F42A90AB20A4DF3462C44EC<br>A25F788CBCA026EA628E63C223A27603710293A1DDF2CABDE3C276BA5C79066F5199B66174620070248310D761B7E4DE7AA3667D4273B71A26A82665E0A1<br>D468573772BFA7618599E04F5124F8B0FAD9B7D6DB0052484E499F049C2E5E400C836E66FE8027CA345FCF44A91BB58CD7077E46091938E100DDCA98E33E<br>015E73596ADADAD1533B831EEDAF489F1FCC1316E4494C9F161C4768FE5F449AB8BE1243B39CF3CD885429DB86B7995E0957715D83511FAEB69A44C7225D<br>07D1C95F152B367363080F26DA65A2CF7CE7FCA38622B3BBCEDD3CCB76AB3B64E6F01FC13FB5E9B4215C6EC3471763678A48FAA7CF7C0180274464B845E5<br>17439641C9A3690410E686D1B601</span> <br> <!-- !!! dont changing this !!! --> </div> </div> <!-- --> <div class="tabs"> <!--tab--> <div class="tab"> <div id="tab-content1" class="content"> <div class="text"> <!--text data --> <b>/!\ YOUR COMPANY NETWORK HAS BEEN PENETRATED /!\</b><br> <b>ALL YOUR IMPORTANT FILES HAVE BEEN ENCRYPTED!</b><br><br> YOUR FILES ARE SAFE! JUST MODIFIED ONLY. (RSA+AES) <br><br> ANY ATTEMPT TO RESTORE YOUR FILES WITH THIRD-PARTY SOFTWARE<br> WILL PERMENANTLY DESTROY YOUR FILE.<br> DO NOT MODIFY ENCRYPTED FILES. DO NOT RENAME ENCRYPTED FILES.<br><br> NO SOFTWARE AVAILABLE ON INTERNET CAN HELP YOU. WE ONLY HAVE<br> SOLUTION TO YOUR PROBLEM.<br><br> WE GATHERED HIGHLY CONFIDENTIAL/PERSORNAL DATA. THESE DATA<br> ARE CURRENTLY STORED ON A PRIVATE SERVER. THIS SERVER WILL BE<br> IMMEDIATELY DESTROYED AFTER YOUR PAYMENT. WE ONLY SEEK MONEY<br> AND DO NOT WANT TO DAMAGE YOUR REPUTATION. IF YOU DECIDE TO<br> NOT PAY, WE WILL RELEASE THIS DATA TO PUBLIC OR RE-SELLER.<br><br> YOU WILL CAN SEND US 2-3 NON-IMPORTANT FILES AND WE WILL<br> DECRYPT IT FOR FREE TO PROVE WE ARE ABLE TO GIVE YOUR FILES<br> BACK.<br><br> <!--text data --> <hr> <b>Contact us for price and get decryption software.</b><br><br> <a href="">http://gvlay6u4g53rxdi5.onion/21-Al9gJCAJ2fd8LgNEdEBLhNUw5QUOgJlP-JVMF20wIlKxlS7OrHBXpCbCONEIVsdhU</a><br> * Note that this server is available via Tor browser only<br><br> Follow the instructions to open the link:<br> 1. Type the addres "https://www.torproject.org" in your Internet browser. It opens the Tor site.<br> 2. Press "Download Tor", then press "Download Tor Browser Bundle", install and run it.<br> 3. Now you have Tor browser. In the Tor Browser open "{
offset: 0
success 0 0
1619345071.30411
NtWriteFile
file_handle: 0x000002f4
filepath: C:\Python27\include\Recovery_Instructions.html
buffer: <html> <style type="text/css"> body { background-color: #f5f5f5; } h1, h3{ text-align: center; text-transform: uppercase; font-weight: normal; } /*---*/ .tabs1{ display: block; margin: auto; } .tabs1 .head{ text-align: center; float: top; padding: 0px; text-transform: uppercase; font-weight: normal; display: block; background: #81bef7; color: #DF0101; font-size: 30px; } .tabs1 .identi { font-size: 10px; text-align: center; float: top; padding: 15px; display: block; background: #81bef7; color: #DFDFDF; } .tabs .content { background: #f5f5f5; /*text-align: center;*/ color: #000000; padding: 25px 15px; font-size: 15px; font-weight: 400; line-height: 20px; } .tabs .content a { color: #df0130; font-size: 23px; font-style: italic; text-decoration: none; line-height: 35px; } .tabs .content .text{ padding: 25px; line-height: 1.2; } </style> <body> <div class="tabs1"> <div class="head" ><b>Your personal ID:</b></div> <div class="identi"> <span style="width:1000px; color: #ffffff; font-size: 10px;">96B15FC03DCA8D175790CC1A893EEB4568E36CF6777F6CE5568ECDD6C33CDC4DC3B8A0AEBE17D5659209E6C658CCE1BE380E6C5350653A8A972180DDF12A276C<br>AF73EB431A73371B04B5BC86AEAACC8E3FC88B2F0E84D9C76161510D333EBD7686343FD08363EBC6A4D72ECCB63DB9C57C7AA9679310D262EB981A91960D<br>69A70480CD61A2D1DA4976232C86AA805C5B4389E7C04A8C9F65D5F80755A928BA67A0B7D9B5C5CA24883A4D8F4BD33CDEC232E5EFAB57377DE59B168050<br>2696BCA82218CA139ED899AD3837F84CF746A6FE76077F43A9DAFE9540482DB1415DAFC5559354C7E40262E301797BE8C3846F42A90AB20A4DF3462C44EC<br>A25F788CBCA026EA628E63C223A27603710293A1DDF2CABDE3C276BA5C79066F5199B66174620070248310D761B7E4DE7AA3667D4273B71A26A82665E0A1<br>D468573772BFA7618599E04F5124F8B0FAD9B7D6DB0052484E499F049C2E5E400C836E66FE8027CA345FCF44A91BB58CD7077E46091938E100DDCA98E33E<br>015E73596ADADAD1533B831EEDAF489F1FCC1316E4494C9F161C4768FE5F449AB8BE1243B39CF3CD885429DB86B7995E0957715D83511FAEB69A44C7225D<br>07D1C95F152B367363080F26DA65A2CF7CE7FCA38622B3BBCEDD3CCB76AB3B64E6F01FC13FB5E9B4215C6EC3471763678A48FAA7CF7C0180274464B845E5<br>17439641C9A3690410E686D1B601</span> <br> <!-- !!! dont changing this !!! --> </div> </div> <!-- --> <div class="tabs"> <!--tab--> <div class="tab"> <div id="tab-content1" class="content"> <div class="text"> <!--text data --> <b>/!\ YOUR COMPANY NETWORK HAS BEEN PENETRATED /!\</b><br> <b>ALL YOUR IMPORTANT FILES HAVE BEEN ENCRYPTED!</b><br><br> YOUR FILES ARE SAFE! JUST MODIFIED ONLY. (RSA+AES) <br><br> ANY ATTEMPT TO RESTORE YOUR FILES WITH THIRD-PARTY SOFTWARE<br> WILL PERMENANTLY DESTROY YOUR FILE.<br> DO NOT MODIFY ENCRYPTED FILES. DO NOT RENAME ENCRYPTED FILES.<br><br> NO SOFTWARE AVAILABLE ON INTERNET CAN HELP YOU. WE ONLY HAVE<br> SOLUTION TO YOUR PROBLEM.<br><br> WE GATHERED HIGHLY CONFIDENTIAL/PERSORNAL DATA. THESE DATA<br> ARE CURRENTLY STORED ON A PRIVATE SERVER. THIS SERVER WILL BE<br> IMMEDIATELY DESTROYED AFTER YOUR PAYMENT. WE ONLY SEEK MONEY<br> AND DO NOT WANT TO DAMAGE YOUR REPUTATION. IF YOU DECIDE TO<br> NOT PAY, WE WILL RELEASE THIS DATA TO PUBLIC OR RE-SELLER.<br><br> YOU WILL CAN SEND US 2-3 NON-IMPORTANT FILES AND WE WILL<br> DECRYPT IT FOR FREE TO PROVE WE ARE ABLE TO GIVE YOUR FILES<br> BACK.<br><br> <!--text data --> <hr> <b>Contact us for price and get decryption software.</b><br><br> <a href="">http://gvlay6u4g53rxdi5.onion/21-Al9gJCAJ2fd8LgNEdEBLhNUw5QUOgJlP-JVMF20wIlKxlS7OrHBXpCbCONEIVsdhU</a><br> * Note that this server is available via Tor browser only<br><br> Follow the instructions to open the link:<br> 1. Type the addres "https://www.torproject.org" in your Internet browser. It opens the Tor site.<br> 2. Press "Download Tor", then press "Download Tor Browser Bundle", install and run it.<br> 3. Now you have Tor browser. In the Tor Browser open "{
offset: 0
success 0 0
Removes the Shadow Copy to avoid recovery of the system (1 个事件)
cmdline vssadmin.exe Delete Shadows /All /Quiet
Uses suspicious command line tools or Windows utilities (1 个事件)
cmdline vssadmin.exe Delete Shadows /All /Quiet
Detects VirtualBox through the presence of a file (9 个事件)
file C:\Program Files\Oracle\VirtualBox Guest Additions\VBoxDisp.dll
file C:\Program Files\Oracle\VirtualBox Guest Additions\VBoxControl.exe
file C:\Program Files\Oracle\VirtualBox Guest Additions\VBoxTray.exe
file C:\Program Files\Oracle\VirtualBox Guest Additions\VBoxDrvInst.exe
file C:\Program Files\Oracle\VirtualBox Guest Additions\VBoxWHQLFake.exe
file C:\Program Files\Oracle\VirtualBox Guest Additions\VBoxGuest.sys
file C:\Program Files\Oracle\VirtualBox Guest Additions\VBoxMouse.sys
file C:\Program Files\Oracle\VirtualBox Guest Additions\VBoxVideo.sys
file C:\Program Files\Oracle\VirtualBox Guest Additions\uninst.exe
Generates some ICMP traffic
Disables Windows Security features (1 个事件)
description attempts to disable user access control registry HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\System\EnableLUA
Performs 224 file moves indicative of a ransomware file encryption process (50 out of 224 个事件)
Time & API Arguments Status Return Repeated
1619345054.50711
MoveFileWithProgressW
oldfilepath: Z:\Boot\BCD.LOG1
newfilepath: Z:\Boot\BCD.LOG1.VinDizelPux
newfilepath_r: Z:\Boot\BCD.LOG1.VinDizelPux
flags: 1
oldfilepath_r: Z:\Boot\BCD.LOG1
success 1 0
1619345054.69411
MoveFileWithProgressW
oldfilepath: Z:\Boot\BCD.LOG2
newfilepath: Z:\Boot\BCD.LOG2.VinDizelPux
newfilepath_r: Z:\Boot\BCD.LOG2.VinDizelPux
flags: 1
oldfilepath_r: Z:\Boot\BCD.LOG2
success 1 0
1619345054.85111
MoveFileWithProgressW
oldfilepath: Z:\Boot\BOOTSTAT.DAT
newfilepath: Z:\Boot\BOOTSTAT.DAT.VinDizelPux
newfilepath_r: Z:\Boot\BOOTSTAT.DAT.VinDizelPux
flags: 1
oldfilepath_r: Z:\Boot\BOOTSTAT.DAT
success 1 0
1619345059.33511
MoveFileWithProgressW
oldfilepath: Z:\BOOTSECT.BAK
newfilepath: Z:\BOOTSECT.BAK.VinDizelPux
newfilepath_r: Z:\BOOTSECT.BAK.VinDizelPux
flags: 1
oldfilepath_r: Z:\BOOTSECT.BAK
success 1 0
1619345059.64711
MoveFileWithProgressW
oldfilepath: Z:\PZASN
newfilepath: Z:\PZASN.VinDizelPux
newfilepath_r: Z:\PZASN.VinDizelPux
flags: 1
oldfilepath_r: Z:\PZASN
success 1 0
1619345061.83511
MoveFileWithProgressW
oldfilepath: C:\Python27\agent.pyw
newfilepath: C:\Python27\agent.pyw.VinDizelPux
newfilepath_r: C:\Python27\agent.pyw.VinDizelPux
flags: 1
oldfilepath_r: C:\Python27\agent.pyw
success 1 0
1619345062.74111
MoveFileWithProgressW
oldfilepath: C:\Python27\DLLs\unicodedata.pyd
newfilepath: C:\Python27\DLLs\unicodedata.pyd.VinDizelPux
newfilepath_r: C:\Python27\DLLs\unicodedata.pyd.VinDizelPux
flags: 1
oldfilepath_r: C:\Python27\DLLs\unicodedata.pyd
success 1 0
1619345062.89711
MoveFileWithProgressW
oldfilepath: C:\Python27\DLLs\winsound.pyd
newfilepath: C:\Python27\DLLs\winsound.pyd.VinDizelPux
newfilepath_r: C:\Python27\DLLs\winsound.pyd.VinDizelPux
flags: 1
oldfilepath_r: C:\Python27\DLLs\winsound.pyd
success 1 0
1619345063.39711
MoveFileWithProgressW
oldfilepath: C:\Python27\DLLs\_bsddb.pyd
newfilepath: C:\Python27\DLLs\_bsddb.pyd.VinDizelPux
newfilepath_r: C:\Python27\DLLs\_bsddb.pyd.VinDizelPux
flags: 1
oldfilepath_r: C:\Python27\DLLs\_bsddb.pyd
success 1 0
1619345063.74111
MoveFileWithProgressW
oldfilepath: C:\Python27\DLLs\_ctypes_test.pyd
newfilepath: C:\Python27\DLLs\_ctypes_test.pyd.VinDizelPux
newfilepath_r: C:\Python27\DLLs\_ctypes_test.pyd.VinDizelPux
flags: 1
oldfilepath_r: C:\Python27\DLLs\_ctypes_test.pyd
success 1 0
1619345063.92911
MoveFileWithProgressW
oldfilepath: C:\Python27\DLLs\_elementtree.pyd
newfilepath: C:\Python27\DLLs\_elementtree.pyd.VinDizelPux
newfilepath_r: C:\Python27\DLLs\_elementtree.pyd.VinDizelPux
flags: 1
oldfilepath_r: C:\Python27\DLLs\_elementtree.pyd
success 1 0
1619345064.27211
MoveFileWithProgressW
oldfilepath: C:\Python27\DLLs\_msi.pyd
newfilepath: C:\Python27\DLLs\_msi.pyd.VinDizelPux
newfilepath_r: C:\Python27\DLLs\_msi.pyd.VinDizelPux
flags: 1
oldfilepath_r: C:\Python27\DLLs\_msi.pyd
success 1 0
1619345064.41311
MoveFileWithProgressW
oldfilepath: C:\Python27\DLLs\_multiprocessing.pyd
newfilepath: C:\Python27\DLLs\_multiprocessing.pyd.VinDizelPux
newfilepath_r: C:\Python27\DLLs\_multiprocessing.pyd.VinDizelPux
flags: 1
oldfilepath_r: C:\Python27\DLLs\_multiprocessing.pyd
success 1 0
1619345064.74111
MoveFileWithProgressW
oldfilepath: C:\Python27\DLLs\_sqlite3.pyd
newfilepath: C:\Python27\DLLs\_sqlite3.pyd.VinDizelPux
newfilepath_r: C:\Python27\DLLs\_sqlite3.pyd.VinDizelPux
flags: 1
oldfilepath_r: C:\Python27\DLLs\_sqlite3.pyd
success 1 0
1619345065.06911
MoveFileWithProgressW
oldfilepath: C:\Python27\DLLs\_testcapi.pyd
newfilepath: C:\Python27\DLLs\_testcapi.pyd.VinDizelPux
newfilepath_r: C:\Python27\DLLs\_testcapi.pyd.VinDizelPux
flags: 1
oldfilepath_r: C:\Python27\DLLs\_testcapi.pyd
success 1 0
1619345065.17911
MoveFileWithProgressW
oldfilepath: C:\Python27\DLLs\_tkinter.pyd
newfilepath: C:\Python27\DLLs\_tkinter.pyd.VinDizelPux
newfilepath_r: C:\Python27\DLLs\_tkinter.pyd.VinDizelPux
flags: 1
oldfilepath_r: C:\Python27\DLLs\_tkinter.pyd
success 1 0
1619345066.89711
MoveFileWithProgressW
oldfilepath: C:\Python27\Doc\python2718.chm
newfilepath: C:\Python27\Doc\python2718.chm.VinDizelPux
newfilepath_r: C:\Python27\Doc\python2718.chm.VinDizelPux
flags: 1
oldfilepath_r: C:\Python27\Doc\python2718.chm
success 1 0
1619345067.05411
MoveFileWithProgressW
oldfilepath: C:\Python27\include\abstract.h
newfilepath: C:\Python27\include\abstract.h.VinDizelPux
newfilepath_r: C:\Python27\include\abstract.h.VinDizelPux
flags: 1
oldfilepath_r: C:\Python27\include\abstract.h
success 1 0
1619345067.21011
MoveFileWithProgressW
oldfilepath: C:\Python27\include\asdl.h
newfilepath: C:\Python27\include\asdl.h.VinDizelPux
newfilepath_r: C:\Python27\include\asdl.h.VinDizelPux
flags: 1
oldfilepath_r: C:\Python27\include\asdl.h
success 1 0
1619345067.35111
MoveFileWithProgressW
oldfilepath: C:\Python27\include\ast.h
newfilepath: C:\Python27\include\ast.h.VinDizelPux
newfilepath_r: C:\Python27\include\ast.h.VinDizelPux
flags: 1
oldfilepath_r: C:\Python27\include\ast.h
success 1 0
1619345067.50711
MoveFileWithProgressW
oldfilepath: C:\Python27\include\bitset.h
newfilepath: C:\Python27\include\bitset.h.VinDizelPux
newfilepath_r: C:\Python27\include\bitset.h.VinDizelPux
flags: 1
oldfilepath_r: C:\Python27\include\bitset.h
success 1 0
1619345067.66311
MoveFileWithProgressW
oldfilepath: C:\Python27\include\boolobject.h
newfilepath: C:\Python27\include\boolobject.h.VinDizelPux
newfilepath_r: C:\Python27\include\boolobject.h.VinDizelPux
flags: 1
oldfilepath_r: C:\Python27\include\boolobject.h
success 1 0
1619345067.81911
MoveFileWithProgressW
oldfilepath: C:\Python27\include\bufferobject.h
newfilepath: C:\Python27\include\bufferobject.h.VinDizelPux
newfilepath_r: C:\Python27\include\bufferobject.h.VinDizelPux
flags: 1
oldfilepath_r: C:\Python27\include\bufferobject.h
success 1 0
1619345067.94411
MoveFileWithProgressW
oldfilepath: C:\Python27\include\bytearrayobject.h
newfilepath: C:\Python27\include\bytearrayobject.h.VinDizelPux
newfilepath_r: C:\Python27\include\bytearrayobject.h.VinDizelPux
flags: 1
oldfilepath_r: C:\Python27\include\bytearrayobject.h
success 1 0
1619345068.06911
MoveFileWithProgressW
oldfilepath: C:\Python27\include\bytesobject.h
newfilepath: C:\Python27\include\bytesobject.h.VinDizelPux
newfilepath_r: C:\Python27\include\bytesobject.h.VinDizelPux
flags: 1
oldfilepath_r: C:\Python27\include\bytesobject.h
success 1 0
1619345068.16311
MoveFileWithProgressW
oldfilepath: C:\Python27\include\bytes_methods.h
newfilepath: C:\Python27\include\bytes_methods.h.VinDizelPux
newfilepath_r: C:\Python27\include\bytes_methods.h.VinDizelPux
flags: 1
oldfilepath_r: C:\Python27\include\bytes_methods.h
success 1 0
1619345068.28811
MoveFileWithProgressW
oldfilepath: C:\Python27\include\cellobject.h
newfilepath: C:\Python27\include\cellobject.h.VinDizelPux
newfilepath_r: C:\Python27\include\cellobject.h.VinDizelPux
flags: 1
oldfilepath_r: C:\Python27\include\cellobject.h
success 1 0
1619345068.42911
MoveFileWithProgressW
oldfilepath: C:\Python27\include\ceval.h
newfilepath: C:\Python27\include\ceval.h.VinDizelPux
newfilepath_r: C:\Python27\include\ceval.h.VinDizelPux
flags: 1
oldfilepath_r: C:\Python27\include\ceval.h
success 1 0
1619345068.60111
MoveFileWithProgressW
oldfilepath: C:\Python27\include\classobject.h
newfilepath: C:\Python27\include\classobject.h.VinDizelPux
newfilepath_r: C:\Python27\include\classobject.h.VinDizelPux
flags: 1
oldfilepath_r: C:\Python27\include\classobject.h
success 1 0
1619345068.77211
MoveFileWithProgressW
oldfilepath: C:\Python27\include\cobject.h
newfilepath: C:\Python27\include\cobject.h.VinDizelPux
newfilepath_r: C:\Python27\include\cobject.h.VinDizelPux
flags: 1
oldfilepath_r: C:\Python27\include\cobject.h
success 1 0
1619345068.92911
MoveFileWithProgressW
oldfilepath: C:\Python27\include\code.h
newfilepath: C:\Python27\include\code.h.VinDizelPux
newfilepath_r: C:\Python27\include\code.h.VinDizelPux
flags: 1
oldfilepath_r: C:\Python27\include\code.h
success 1 0
1619345069.11611
MoveFileWithProgressW
oldfilepath: C:\Python27\include\codecs.h
newfilepath: C:\Python27\include\codecs.h.VinDizelPux
newfilepath_r: C:\Python27\include\codecs.h.VinDizelPux
flags: 1
oldfilepath_r: C:\Python27\include\codecs.h
success 1 0
1619345069.22611
MoveFileWithProgressW
oldfilepath: C:\Python27\include\compile.h
newfilepath: C:\Python27\include\compile.h.VinDizelPux
newfilepath_r: C:\Python27\include\compile.h.VinDizelPux
flags: 1
oldfilepath_r: C:\Python27\include\compile.h
success 1 0
1619345069.31911
MoveFileWithProgressW
oldfilepath: C:\Python27\include\complexobject.h
newfilepath: C:\Python27\include\complexobject.h.VinDizelPux
newfilepath_r: C:\Python27\include\complexobject.h.VinDizelPux
flags: 1
oldfilepath_r: C:\Python27\include\complexobject.h
success 1 0
1619345069.41311
MoveFileWithProgressW
oldfilepath: C:\Python27\include\cStringIO.h
newfilepath: C:\Python27\include\cStringIO.h.VinDizelPux
newfilepath_r: C:\Python27\include\cStringIO.h.VinDizelPux
flags: 1
oldfilepath_r: C:\Python27\include\cStringIO.h
success 1 0
1619345069.49111
MoveFileWithProgressW
oldfilepath: C:\Python27\include\datetime.h
newfilepath: C:\Python27\include\datetime.h.VinDizelPux
newfilepath_r: C:\Python27\include\datetime.h.VinDizelPux
flags: 1
oldfilepath_r: C:\Python27\include\datetime.h
success 1 0
1619345069.58511
MoveFileWithProgressW
oldfilepath: C:\Python27\include\descrobject.h
newfilepath: C:\Python27\include\descrobject.h.VinDizelPux
newfilepath_r: C:\Python27\include\descrobject.h.VinDizelPux
flags: 1
oldfilepath_r: C:\Python27\include\descrobject.h
success 1 0
1619345069.74111
MoveFileWithProgressW
oldfilepath: C:\Python27\include\dictobject.h
newfilepath: C:\Python27\include\dictobject.h.VinDizelPux
newfilepath_r: C:\Python27\include\dictobject.h.VinDizelPux
flags: 1
oldfilepath_r: C:\Python27\include\dictobject.h
success 1 0
1619345069.81911
MoveFileWithProgressW
oldfilepath: C:\Python27\include\dtoa.h
newfilepath: C:\Python27\include\dtoa.h.VinDizelPux
newfilepath_r: C:\Python27\include\dtoa.h.VinDizelPux
flags: 1
oldfilepath_r: C:\Python27\include\dtoa.h
success 1 0
1619345069.88211
MoveFileWithProgressW
oldfilepath: C:\Python27\include\enumobject.h
newfilepath: C:\Python27\include\enumobject.h.VinDizelPux
newfilepath_r: C:\Python27\include\enumobject.h.VinDizelPux
flags: 1
oldfilepath_r: C:\Python27\include\enumobject.h
success 1 0
1619345069.94411
MoveFileWithProgressW
oldfilepath: C:\Python27\include\errcode.h
newfilepath: C:\Python27\include\errcode.h.VinDizelPux
newfilepath_r: C:\Python27\include\errcode.h.VinDizelPux
flags: 1
oldfilepath_r: C:\Python27\include\errcode.h
success 1 0
1619345070.06911
MoveFileWithProgressW
oldfilepath: C:\Python27\include\eval.h
newfilepath: C:\Python27\include\eval.h.VinDizelPux
newfilepath_r: C:\Python27\include\eval.h.VinDizelPux
flags: 1
oldfilepath_r: C:\Python27\include\eval.h
success 1 0
1619345070.13211
MoveFileWithProgressW
oldfilepath: C:\Python27\include\fileobject.h
newfilepath: C:\Python27\include\fileobject.h.VinDizelPux
newfilepath_r: C:\Python27\include\fileobject.h.VinDizelPux
flags: 1
oldfilepath_r: C:\Python27\include\fileobject.h
success 1 0
1619345070.22611
MoveFileWithProgressW
oldfilepath: C:\Python27\include\floatobject.h
newfilepath: C:\Python27\include\floatobject.h.VinDizelPux
newfilepath_r: C:\Python27\include\floatobject.h.VinDizelPux
flags: 1
oldfilepath_r: C:\Python27\include\floatobject.h
success 1 0
1619345070.31911
MoveFileWithProgressW
oldfilepath: C:\Python27\include\frameobject.h
newfilepath: C:\Python27\include\frameobject.h.VinDizelPux
newfilepath_r: C:\Python27\include\frameobject.h.VinDizelPux
flags: 1
oldfilepath_r: C:\Python27\include\frameobject.h
success 1 0
1619345070.47611
MoveFileWithProgressW
oldfilepath: C:\Python27\include\funcobject.h
newfilepath: C:\Python27\include\funcobject.h.VinDizelPux
newfilepath_r: C:\Python27\include\funcobject.h.VinDizelPux
flags: 1
oldfilepath_r: C:\Python27\include\funcobject.h
success 1 0
1619345070.63211
MoveFileWithProgressW
oldfilepath: C:\Python27\include\genobject.h
newfilepath: C:\Python27\include\genobject.h.VinDizelPux
newfilepath_r: C:\Python27\include\genobject.h.VinDizelPux
flags: 1
oldfilepath_r: C:\Python27\include\genobject.h
success 1 0
1619345070.96011
MoveFileWithProgressW
oldfilepath: C:\Python27\include\graminit.h
newfilepath: C:\Python27\include\graminit.h.VinDizelPux
newfilepath_r: C:\Python27\include\graminit.h.VinDizelPux
flags: 1
oldfilepath_r: C:\Python27\include\graminit.h
success 1 0
1619345071.16311
MoveFileWithProgressW
oldfilepath: C:\Python27\include\grammar.h
newfilepath: C:\Python27\include\grammar.h.VinDizelPux
newfilepath_r: C:\Python27\include\grammar.h.VinDizelPux
flags: 1
oldfilepath_r: C:\Python27\include\grammar.h
success 1 0
1619345071.28811
MoveFileWithProgressW
oldfilepath: C:\Python27\include\import.h
newfilepath: C:\Python27\include\import.h.VinDizelPux
newfilepath_r: C:\Python27\include\import.h.VinDizelPux
flags: 1
oldfilepath_r: C:\Python27\include\import.h
success 1 0
Appends a new file extension or content to 224 files indicative of a ransomware file encryption process (50 out of 224 个事件)
Time & API Arguments Status Return Repeated
1619345054.50711
MoveFileWithProgressW
oldfilepath: Z:\Boot\BCD.LOG1
newfilepath: Z:\Boot\BCD.LOG1.VinDizelPux
newfilepath_r: Z:\Boot\BCD.LOG1.VinDizelPux
flags: 1
oldfilepath_r: Z:\Boot\BCD.LOG1
success 1 0
1619345054.69411
MoveFileWithProgressW
oldfilepath: Z:\Boot\BCD.LOG2
newfilepath: Z:\Boot\BCD.LOG2.VinDizelPux
newfilepath_r: Z:\Boot\BCD.LOG2.VinDizelPux
flags: 1
oldfilepath_r: Z:\Boot\BCD.LOG2
success 1 0
1619345054.85111
MoveFileWithProgressW
oldfilepath: Z:\Boot\BOOTSTAT.DAT
newfilepath: Z:\Boot\BOOTSTAT.DAT.VinDizelPux
newfilepath_r: Z:\Boot\BOOTSTAT.DAT.VinDizelPux
flags: 1
oldfilepath_r: Z:\Boot\BOOTSTAT.DAT
success 1 0
1619345059.33511
MoveFileWithProgressW
oldfilepath: Z:\BOOTSECT.BAK
newfilepath: Z:\BOOTSECT.BAK.VinDizelPux
newfilepath_r: Z:\BOOTSECT.BAK.VinDizelPux
flags: 1
oldfilepath_r: Z:\BOOTSECT.BAK
success 1 0
1619345059.64711
MoveFileWithProgressW
oldfilepath: Z:\PZASN
newfilepath: Z:\PZASN.VinDizelPux
newfilepath_r: Z:\PZASN.VinDizelPux
flags: 1
oldfilepath_r: Z:\PZASN
success 1 0
1619345061.83511
MoveFileWithProgressW
oldfilepath: C:\Python27\agent.pyw
newfilepath: C:\Python27\agent.pyw.VinDizelPux
newfilepath_r: C:\Python27\agent.pyw.VinDizelPux
flags: 1
oldfilepath_r: C:\Python27\agent.pyw
success 1 0
1619345062.74111
MoveFileWithProgressW
oldfilepath: C:\Python27\DLLs\unicodedata.pyd
newfilepath: C:\Python27\DLLs\unicodedata.pyd.VinDizelPux
newfilepath_r: C:\Python27\DLLs\unicodedata.pyd.VinDizelPux
flags: 1
oldfilepath_r: C:\Python27\DLLs\unicodedata.pyd
success 1 0
1619345062.89711
MoveFileWithProgressW
oldfilepath: C:\Python27\DLLs\winsound.pyd
newfilepath: C:\Python27\DLLs\winsound.pyd.VinDizelPux
newfilepath_r: C:\Python27\DLLs\winsound.pyd.VinDizelPux
flags: 1
oldfilepath_r: C:\Python27\DLLs\winsound.pyd
success 1 0
1619345063.39711
MoveFileWithProgressW
oldfilepath: C:\Python27\DLLs\_bsddb.pyd
newfilepath: C:\Python27\DLLs\_bsddb.pyd.VinDizelPux
newfilepath_r: C:\Python27\DLLs\_bsddb.pyd.VinDizelPux
flags: 1
oldfilepath_r: C:\Python27\DLLs\_bsddb.pyd
success 1 0
1619345063.74111
MoveFileWithProgressW
oldfilepath: C:\Python27\DLLs\_ctypes_test.pyd
newfilepath: C:\Python27\DLLs\_ctypes_test.pyd.VinDizelPux
newfilepath_r: C:\Python27\DLLs\_ctypes_test.pyd.VinDizelPux
flags: 1
oldfilepath_r: C:\Python27\DLLs\_ctypes_test.pyd
success 1 0
1619345063.92911
MoveFileWithProgressW
oldfilepath: C:\Python27\DLLs\_elementtree.pyd
newfilepath: C:\Python27\DLLs\_elementtree.pyd.VinDizelPux
newfilepath_r: C:\Python27\DLLs\_elementtree.pyd.VinDizelPux
flags: 1
oldfilepath_r: C:\Python27\DLLs\_elementtree.pyd
success 1 0
1619345064.27211
MoveFileWithProgressW
oldfilepath: C:\Python27\DLLs\_msi.pyd
newfilepath: C:\Python27\DLLs\_msi.pyd.VinDizelPux
newfilepath_r: C:\Python27\DLLs\_msi.pyd.VinDizelPux
flags: 1
oldfilepath_r: C:\Python27\DLLs\_msi.pyd
success 1 0
1619345064.41311
MoveFileWithProgressW
oldfilepath: C:\Python27\DLLs\_multiprocessing.pyd
newfilepath: C:\Python27\DLLs\_multiprocessing.pyd.VinDizelPux
newfilepath_r: C:\Python27\DLLs\_multiprocessing.pyd.VinDizelPux
flags: 1
oldfilepath_r: C:\Python27\DLLs\_multiprocessing.pyd
success 1 0
1619345064.74111
MoveFileWithProgressW
oldfilepath: C:\Python27\DLLs\_sqlite3.pyd
newfilepath: C:\Python27\DLLs\_sqlite3.pyd.VinDizelPux
newfilepath_r: C:\Python27\DLLs\_sqlite3.pyd.VinDizelPux
flags: 1
oldfilepath_r: C:\Python27\DLLs\_sqlite3.pyd
success 1 0
1619345065.06911
MoveFileWithProgressW
oldfilepath: C:\Python27\DLLs\_testcapi.pyd
newfilepath: C:\Python27\DLLs\_testcapi.pyd.VinDizelPux
newfilepath_r: C:\Python27\DLLs\_testcapi.pyd.VinDizelPux
flags: 1
oldfilepath_r: C:\Python27\DLLs\_testcapi.pyd
success 1 0
1619345065.17911
MoveFileWithProgressW
oldfilepath: C:\Python27\DLLs\_tkinter.pyd
newfilepath: C:\Python27\DLLs\_tkinter.pyd.VinDizelPux
newfilepath_r: C:\Python27\DLLs\_tkinter.pyd.VinDizelPux
flags: 1
oldfilepath_r: C:\Python27\DLLs\_tkinter.pyd
success 1 0
1619345066.89711
MoveFileWithProgressW
oldfilepath: C:\Python27\Doc\python2718.chm
newfilepath: C:\Python27\Doc\python2718.chm.VinDizelPux
newfilepath_r: C:\Python27\Doc\python2718.chm.VinDizelPux
flags: 1
oldfilepath_r: C:\Python27\Doc\python2718.chm
success 1 0
1619345067.05411
MoveFileWithProgressW
oldfilepath: C:\Python27\include\abstract.h
newfilepath: C:\Python27\include\abstract.h.VinDizelPux
newfilepath_r: C:\Python27\include\abstract.h.VinDizelPux
flags: 1
oldfilepath_r: C:\Python27\include\abstract.h
success 1 0
1619345067.21011
MoveFileWithProgressW
oldfilepath: C:\Python27\include\asdl.h
newfilepath: C:\Python27\include\asdl.h.VinDizelPux
newfilepath_r: C:\Python27\include\asdl.h.VinDizelPux
flags: 1
oldfilepath_r: C:\Python27\include\asdl.h
success 1 0
1619345067.35111
MoveFileWithProgressW
oldfilepath: C:\Python27\include\ast.h
newfilepath: C:\Python27\include\ast.h.VinDizelPux
newfilepath_r: C:\Python27\include\ast.h.VinDizelPux
flags: 1
oldfilepath_r: C:\Python27\include\ast.h
success 1 0
1619345067.50711
MoveFileWithProgressW
oldfilepath: C:\Python27\include\bitset.h
newfilepath: C:\Python27\include\bitset.h.VinDizelPux
newfilepath_r: C:\Python27\include\bitset.h.VinDizelPux
flags: 1
oldfilepath_r: C:\Python27\include\bitset.h
success 1 0
1619345067.66311
MoveFileWithProgressW
oldfilepath: C:\Python27\include\boolobject.h
newfilepath: C:\Python27\include\boolobject.h.VinDizelPux
newfilepath_r: C:\Python27\include\boolobject.h.VinDizelPux
flags: 1
oldfilepath_r: C:\Python27\include\boolobject.h
success 1 0
1619345067.81911
MoveFileWithProgressW
oldfilepath: C:\Python27\include\bufferobject.h
newfilepath: C:\Python27\include\bufferobject.h.VinDizelPux
newfilepath_r: C:\Python27\include\bufferobject.h.VinDizelPux
flags: 1
oldfilepath_r: C:\Python27\include\bufferobject.h
success 1 0
1619345067.94411
MoveFileWithProgressW
oldfilepath: C:\Python27\include\bytearrayobject.h
newfilepath: C:\Python27\include\bytearrayobject.h.VinDizelPux
newfilepath_r: C:\Python27\include\bytearrayobject.h.VinDizelPux
flags: 1
oldfilepath_r: C:\Python27\include\bytearrayobject.h
success 1 0
1619345068.06911
MoveFileWithProgressW
oldfilepath: C:\Python27\include\bytesobject.h
newfilepath: C:\Python27\include\bytesobject.h.VinDizelPux
newfilepath_r: C:\Python27\include\bytesobject.h.VinDizelPux
flags: 1
oldfilepath_r: C:\Python27\include\bytesobject.h
success 1 0
1619345068.16311
MoveFileWithProgressW
oldfilepath: C:\Python27\include\bytes_methods.h
newfilepath: C:\Python27\include\bytes_methods.h.VinDizelPux
newfilepath_r: C:\Python27\include\bytes_methods.h.VinDizelPux
flags: 1
oldfilepath_r: C:\Python27\include\bytes_methods.h
success 1 0
1619345068.28811
MoveFileWithProgressW
oldfilepath: C:\Python27\include\cellobject.h
newfilepath: C:\Python27\include\cellobject.h.VinDizelPux
newfilepath_r: C:\Python27\include\cellobject.h.VinDizelPux
flags: 1
oldfilepath_r: C:\Python27\include\cellobject.h
success 1 0
1619345068.42911
MoveFileWithProgressW
oldfilepath: C:\Python27\include\ceval.h
newfilepath: C:\Python27\include\ceval.h.VinDizelPux
newfilepath_r: C:\Python27\include\ceval.h.VinDizelPux
flags: 1
oldfilepath_r: C:\Python27\include\ceval.h
success 1 0
1619345068.60111
MoveFileWithProgressW
oldfilepath: C:\Python27\include\classobject.h
newfilepath: C:\Python27\include\classobject.h.VinDizelPux
newfilepath_r: C:\Python27\include\classobject.h.VinDizelPux
flags: 1
oldfilepath_r: C:\Python27\include\classobject.h
success 1 0
1619345068.77211
MoveFileWithProgressW
oldfilepath: C:\Python27\include\cobject.h
newfilepath: C:\Python27\include\cobject.h.VinDizelPux
newfilepath_r: C:\Python27\include\cobject.h.VinDizelPux
flags: 1
oldfilepath_r: C:\Python27\include\cobject.h
success 1 0
1619345068.92911
MoveFileWithProgressW
oldfilepath: C:\Python27\include\code.h
newfilepath: C:\Python27\include\code.h.VinDizelPux
newfilepath_r: C:\Python27\include\code.h.VinDizelPux
flags: 1
oldfilepath_r: C:\Python27\include\code.h
success 1 0
1619345069.11611
MoveFileWithProgressW
oldfilepath: C:\Python27\include\codecs.h
newfilepath: C:\Python27\include\codecs.h.VinDizelPux
newfilepath_r: C:\Python27\include\codecs.h.VinDizelPux
flags: 1
oldfilepath_r: C:\Python27\include\codecs.h
success 1 0
1619345069.22611
MoveFileWithProgressW
oldfilepath: C:\Python27\include\compile.h
newfilepath: C:\Python27\include\compile.h.VinDizelPux
newfilepath_r: C:\Python27\include\compile.h.VinDizelPux
flags: 1
oldfilepath_r: C:\Python27\include\compile.h
success 1 0
1619345069.31911
MoveFileWithProgressW
oldfilepath: C:\Python27\include\complexobject.h
newfilepath: C:\Python27\include\complexobject.h.VinDizelPux
newfilepath_r: C:\Python27\include\complexobject.h.VinDizelPux
flags: 1
oldfilepath_r: C:\Python27\include\complexobject.h
success 1 0
1619345069.41311
MoveFileWithProgressW
oldfilepath: C:\Python27\include\cStringIO.h
newfilepath: C:\Python27\include\cStringIO.h.VinDizelPux
newfilepath_r: C:\Python27\include\cStringIO.h.VinDizelPux
flags: 1
oldfilepath_r: C:\Python27\include\cStringIO.h
success 1 0
1619345069.49111
MoveFileWithProgressW
oldfilepath: C:\Python27\include\datetime.h
newfilepath: C:\Python27\include\datetime.h.VinDizelPux
newfilepath_r: C:\Python27\include\datetime.h.VinDizelPux
flags: 1
oldfilepath_r: C:\Python27\include\datetime.h
success 1 0
1619345069.58511
MoveFileWithProgressW
oldfilepath: C:\Python27\include\descrobject.h
newfilepath: C:\Python27\include\descrobject.h.VinDizelPux
newfilepath_r: C:\Python27\include\descrobject.h.VinDizelPux
flags: 1
oldfilepath_r: C:\Python27\include\descrobject.h
success 1 0
1619345069.74111
MoveFileWithProgressW
oldfilepath: C:\Python27\include\dictobject.h
newfilepath: C:\Python27\include\dictobject.h.VinDizelPux
newfilepath_r: C:\Python27\include\dictobject.h.VinDizelPux
flags: 1
oldfilepath_r: C:\Python27\include\dictobject.h
success 1 0
1619345069.81911
MoveFileWithProgressW
oldfilepath: C:\Python27\include\dtoa.h
newfilepath: C:\Python27\include\dtoa.h.VinDizelPux
newfilepath_r: C:\Python27\include\dtoa.h.VinDizelPux
flags: 1
oldfilepath_r: C:\Python27\include\dtoa.h
success 1 0
1619345069.88211
MoveFileWithProgressW
oldfilepath: C:\Python27\include\enumobject.h
newfilepath: C:\Python27\include\enumobject.h.VinDizelPux
newfilepath_r: C:\Python27\include\enumobject.h.VinDizelPux
flags: 1
oldfilepath_r: C:\Python27\include\enumobject.h
success 1 0
1619345069.94411
MoveFileWithProgressW
oldfilepath: C:\Python27\include\errcode.h
newfilepath: C:\Python27\include\errcode.h.VinDizelPux
newfilepath_r: C:\Python27\include\errcode.h.VinDizelPux
flags: 1
oldfilepath_r: C:\Python27\include\errcode.h
success 1 0
1619345070.06911
MoveFileWithProgressW
oldfilepath: C:\Python27\include\eval.h
newfilepath: C:\Python27\include\eval.h.VinDizelPux
newfilepath_r: C:\Python27\include\eval.h.VinDizelPux
flags: 1
oldfilepath_r: C:\Python27\include\eval.h
success 1 0
1619345070.13211
MoveFileWithProgressW
oldfilepath: C:\Python27\include\fileobject.h
newfilepath: C:\Python27\include\fileobject.h.VinDizelPux
newfilepath_r: C:\Python27\include\fileobject.h.VinDizelPux
flags: 1
oldfilepath_r: C:\Python27\include\fileobject.h
success 1 0
1619345070.22611
MoveFileWithProgressW
oldfilepath: C:\Python27\include\floatobject.h
newfilepath: C:\Python27\include\floatobject.h.VinDizelPux
newfilepath_r: C:\Python27\include\floatobject.h.VinDizelPux
flags: 1
oldfilepath_r: C:\Python27\include\floatobject.h
success 1 0
1619345070.31911
MoveFileWithProgressW
oldfilepath: C:\Python27\include\frameobject.h
newfilepath: C:\Python27\include\frameobject.h.VinDizelPux
newfilepath_r: C:\Python27\include\frameobject.h.VinDizelPux
flags: 1
oldfilepath_r: C:\Python27\include\frameobject.h
success 1 0
1619345070.47611
MoveFileWithProgressW
oldfilepath: C:\Python27\include\funcobject.h
newfilepath: C:\Python27\include\funcobject.h.VinDizelPux
newfilepath_r: C:\Python27\include\funcobject.h.VinDizelPux
flags: 1
oldfilepath_r: C:\Python27\include\funcobject.h
success 1 0
1619345070.63211
MoveFileWithProgressW
oldfilepath: C:\Python27\include\genobject.h
newfilepath: C:\Python27\include\genobject.h.VinDizelPux
newfilepath_r: C:\Python27\include\genobject.h.VinDizelPux
flags: 1
oldfilepath_r: C:\Python27\include\genobject.h
success 1 0
1619345070.96011
MoveFileWithProgressW
oldfilepath: C:\Python27\include\graminit.h
newfilepath: C:\Python27\include\graminit.h.VinDizelPux
newfilepath_r: C:\Python27\include\graminit.h.VinDizelPux
flags: 1
oldfilepath_r: C:\Python27\include\graminit.h
success 1 0
1619345071.16311
MoveFileWithProgressW
oldfilepath: C:\Python27\include\grammar.h
newfilepath: C:\Python27\include\grammar.h.VinDizelPux
newfilepath_r: C:\Python27\include\grammar.h.VinDizelPux
flags: 1
oldfilepath_r: C:\Python27\include\grammar.h
success 1 0
1619345071.28811
MoveFileWithProgressW
oldfilepath: C:\Python27\include\import.h
newfilepath: C:\Python27\include\import.h.VinDizelPux
newfilepath_r: C:\Python27\include\import.h.VinDizelPux
flags: 1
oldfilepath_r: C:\Python27\include\import.h
success 1 0
Drops 212 unknown file mime types indicative of ransomware writing encrypted files back to disk (50 out of 212 个事件)
file c:\python27\include\ceval.h.vindizelpux
file c:\python27\include\pyfpe.h.vindizelpux
file c:\python27\lib\compiler\transformer.py.vindizelpux
file c:\python27\include\cstringio.h.vindizelpux
file c:\python27\lib\basehttpserver.py.vindizelpux
file c:\python27\dlls\_testcapi.pyd.vindizelpux
file c:\python27\lib\bsddb\db.py.vindizelpux
file c:\python27\agent.pyw.vindizelpux
file c:\python27\lib\cookie.pyc.vindizelpux
file c:\python27\lib\ast.py.vindizelpux
file c:\python27\lib\atexit.py.vindizelpux
file c:\python27\include\bufferobject.h.vindizelpux
file c:\python27\lib\ctypes\test\test_delattr.py.vindizelpux
file c:\python27\lib\ctypes\macholib\__init__.py.vindizelpux
file c:\python27\lib\bsddb\dbtables.py.vindizelpux
file c:\python27\include\modsupport.h.vindizelpux
file c:\python27\include\pythonrun.h.vindizelpux
file c:\python27\lib\commands.py.vindizelpux
file c:\python27\include\symtable.h.vindizelpux
file c:\python27\lib\asynchat.py.vindizelpux
file c:\python27\lib\ctypes\test\test_arrays.py.vindizelpux
file c:\python27\lib\copy_reg.py.vindizelpux
file c:\python27\lib\atexit.pyc.vindizelpux
file C:\Python27\Lib\ctypes\test\test_anon.py
file c:\python27\lib\bsddb\test\test_join.py.vindizelpux
file c:\python27\include\pymath.h.vindizelpux
file c:\python27\dlls\_elementtree.pyd.vindizelpux
file c:\python27\dlls\winsound.pyd.vindizelpux
file c:\python27\include\pycapsule.h.vindizelpux
file c:\python27\include\compile.h.vindizelpux
file c:\python27\include\bytes_methods.h.vindizelpux
file c:\python27\lib\cprofile.py.vindizelpux
file c:\python27\include\floatobject.h.vindizelpux
file c:\python27\lib\codecs.py.vindizelpux
file c:\python27\lib\cgi.pyc.vindizelpux
file c:\python27\include\frameobject.h.vindizelpux
file c:\python27\include\pyctype.h.vindizelpux
file c:\python27\lib\bsddb\test\test_early_close.py.vindizelpux
file c:\python27\lib\configparser.pyc.vindizelpux
file c:\python27\include\pystrtod.h.vindizelpux
file c:\python27\lib\argparse.py.vindizelpux
file c:\python27\include\stringobject.h.vindizelpux
file c:\python27\lib\basehttpserver.pyc.vindizelpux
file c:\python27\include\cobject.h.vindizelpux
file c:\python27\include\cellobject.h.vindizelpux
file c:\python27\lib\code.py.vindizelpux
file c:\python27\lib\cmd.py.vindizelpux
file c:\python27\lib\bisect.py.vindizelpux
file c:\python27\include\opcode.h.vindizelpux
file c:\python27\lib\bsddb\test\test_get_none.py.vindizelpux
File has been identified by 58 AntiVirus engines on VirusTotal as malicious (50 out of 58 个事件)
Bkav W32.AIDetectVM.malware1
Elastic malicious (high confidence)
MicroWorld-eScan Generic.Ransom.MedusaLocker.942644D7
CAT-QuickHeal Trojan.DelshadRI.S13221298
McAfee GenericRXKP-XE!35271695A620
Cylance Unsafe
Zillya Trojan.DelShad.Win32.481
Sangfor Malware
K7AntiVirus Trojan ( 0055a9531 )
Alibaba Trojan:Win32/DelShad.81ad6470
K7GW Trojan ( 0055a9531 )
Cybereason malicious.0f41ae
Arcabit Generic.Ransom.MedusaLocker.942644D7
TrendMicro Ransom.Win32.MEDUSALOCKER.SMTH
Cyren W32/Ransom.BIGY-7014
Symantec Downloader
ESET-NOD32 a variant of Win32/Filecoder.MedusaLocker.C
APEX Malicious
Paloalto generic.ml
Kaspersky Trojan.Win32.DelShad.dax
BitDefender Generic.Ransom.MedusaLocker.942644D7
NANO-Antivirus Trojan.Win32.Filecoder.hjdojw
Avast Win32:RansomX-gen [Ransom]
Tencent Malware.Win32.Gencirc.10cdcb68
Ad-Aware Generic.Ransom.MedusaLocker.942644D7
Comodo Malware@#vtw91ctw0ahu
F-Secure Trojan.TR/DelShad.xrytt
DrWeb Trojan.DownLoader33.34694
VIPRE Trojan.Win32.Generic!BT
Invincea Mal/Generic-S
FireEye Generic.mg.35271695a6202c51
Sophos Mal/Generic-S
Ikarus Trojan-Ransom.Medusalocker
Jiangmin Trojan.DelShad.vv
Webroot W32.Trojan.Gen
Avira TR/DelShad.xrytt
eGambit Unsafe.AI_Score_93%
Antiy-AVL Trojan[Ransom]/Win32.Ako
Microsoft Ransom:Win32/Ako!MSR
AegisLab Trojan.Win32.DelShad.4!c
ZoneAlarm Trojan.Win32.DelShad.dax
GData Win32.Trojan-Ransom.Filecoder.BO
Cynet Malicious (score: 100)
AhnLab-V3 Malware/Win32.RL_Generic.R335910
VBA32 Trojan.DelShad
ALYac Trojan.Ransom.MedusaLocker
MAX malware (ai score=100)
Malwarebytes Ransom.Medusa
TrendMicro-HouseCall Ransom.Win32.MEDUSALOCKER.SMTH
Rising Ransom.Medusa!1.C21A (CLASSIC)
可视化分析
二进制图像
暂无二进制图像 该样本未生成二进制可视化图像
运行截图
暂无运行截图 该样本运行过程中未生成截图

👋 欢迎使用 ChatHawk

我是您的恶意软件分析助手,可以帮您分析和解读恶意软件报告。请随时向我提问!

🔍 主要威胁分析
⚡ 行为特征
🛡️ 防护建议
🔧 技术手段
🎯 检测方法
🤖

PE Compile Time

2020-03-21 00:30:29

Imports

Library KERNEL32.dll:
0x475078 Process32NextW
0x47507c Process32FirstW
0x475080 CreateProcessW
0x475084 GetTickCount
0x475088 CopyFileW
0x47508c GetCurrentProcess
0x475090 WriteConsoleW
0x475098 OpenProcess
0x47509c WaitForSingleObject
0x4750a0 TerminateProcess
0x4750a4 FindClose
0x4750a8 FindNextVolumeW
0x4750b0 FindVolumeClose
0x4750b8 FindFirstVolumeW
0x4750bc QueryDosDeviceW
0x4750c4 GetLogicalDrives
0x4750c8 GetProcessHeap
0x4750cc MoveFileExW
0x4750d0 SetFilePointerEx
0x4750d4 HeapAlloc
0x4750d8 CloseHandle
0x4750dc GetLastError
0x4750e0 SetFileAttributesW
0x4750e4 GetFileAttributesW
0x4750e8 CreateFileW
0x4750ec WriteFile
0x4750f0 HeapSize
0x4750f4 GetConsoleMode
0x4750f8 GetConsoleCP
0x4750fc FlushFileBuffers
0x475100 SetStdHandle
0x47510c GetCommandLineW
0x475110 GetCommandLineA
0x475114 GetOEMCP
0x475118 GetACP
0x47511c IsValidCodePage
0x475120 GetFileType
0x475124 HeapReAlloc
0x47512c EnumSystemLocalesW
0x475130 GetUserDefaultLCID
0x475134 HeapFree
0x475138 GetFileSizeEx
0x47513c IsValidLocale
0x475140 GetTimeFormatW
0x475144 GetDateFormatW
0x475148 GetStdHandle
0x47514c ReadFile
0x475150 OpenMutexW
0x475154 Sleep
0x475158 CreateMutexW
0x47515c GetModuleFileNameW
0x475164 EncodePointer
0x475168 DecodePointer
0x47516c RaiseException
0x475170 GetCurrentThreadId
0x475178 QueueUserWorkItem
0x47517c GetModuleHandleExW
0x475190 FormatMessageW
0x475194 WideCharToMultiByte
0x47519c MultiByteToWideChar
0x4751a0 FindFirstFileExW
0x4751a4 FindNextFileW
0x4751ac SetLastError
0x4751b4 CreateEventW
0x4751b8 SwitchToThread
0x4751bc TlsAlloc
0x4751c0 TlsGetValue
0x4751c4 TlsSetValue
0x4751c8 TlsFree
0x4751d0 GetModuleHandleW
0x4751d4 GetProcAddress
0x4751d8 DuplicateHandle
0x4751e0 GetCurrentThread
0x4751e4 GetStringTypeW
0x4751e8 CompareStringW
0x4751ec LCMapStringW
0x4751f0 GetLocaleInfoW
0x4751f4 GetCPInfo
0x4751f8 SetEvent
0x4751fc ResetEvent
0x475208 IsDebuggerPresent
0x47520c GetStartupInfoW
0x475210 GetCurrentProcessId
0x475214 InitializeSListHead
0x475218 LocalFree
0x47521c CreateTimerQueue
0x475220 SignalObjectAndWait
0x475224 CreateThread
0x475228 SetThreadPriority
0x47522c GetThreadPriority
0x475250 UnregisterWait
0x475254 GetThreadTimes
0x475258 FreeLibrary
0x475260 GetModuleHandleA
0x475264 LoadLibraryExW
0x475268 GetVersionExW
0x47526c VirtualAlloc
0x475270 VirtualProtect
0x475274 VirtualFree
0x475278 ReleaseSemaphore
0x475288 QueryDepthSList
0x47528c UnregisterWaitEx
0x475290 LoadLibraryW
0x475294 RtlUnwind
0x475298 ExitProcess
Library ADVAPI32.dll:
0x475000 CryptExportKey
0x475004 RegCreateKeyW
0x475008 RegOpenKeyExW
0x47500c RegSetValueExW
0x475010 RegCloseKey
0x475014 CryptReleaseContext
0x475018 CryptGenKey
0x47501c CryptImportKey
0x475020 OpenProcessToken
0x475024 GetTokenInformation
0x475028 CloseServiceHandle
0x47502c OpenSCManagerW
0x475030 DeleteService
0x475034 ControlService
0x47503c OpenServiceW
0x475044 CryptDestroyKey
0x47504c CryptEncrypt
0x475050 CryptDuplicateKey
0x475054 RegDeleteValueW
Library SHELL32.dll:
0x4752e8 SHEmptyRecycleBinW
Library ole32.dll:
0x4752f8 CLSIDFromString
0x4752fc IIDFromString
0x475300 CoInitializeEx
0x475304 CoGetObject
0x475308 CoInitialize
0x47530c CoUninitialize
0x475310 CoCreateInstance
Library OLEAUT32.dll:
0x4752b8 VariantClear
0x4752bc SysAllocString
0x4752c0 SysStringByteLen
0x4752c4 VariantInit
0x4752c8 SysFreeString
Library CRYPT32.dll:
Library MPR.dll:
0x4752a0 WNetGetConnectionW
Library NETAPI32.dll:
0x4752a8 NetApiBufferFree
0x4752ac NetShareEnum
Library IPHLPAPI.DLL:
0x475064 IcmpSendEcho
0x475068 IcmpCloseHandle
0x47506c GetAdaptersInfo
0x475070 IcmpCreateFile
Library WS2_32.dll:
0x4752f0 inet_addr
Library RstrtMgr.DLL:
0x4752d0 RmShutdown
0x4752d4 RmRegisterResources
0x4752d8 RmStartSession
0x4752dc RmGetList
0x4752e0 RmEndSession

Hosts

No hosts contacted.

TCP

Source Source Port Destination Destination Port
192.168.56.101 49190 192.168.56.1 445

UDP

Source Source Port Destination Destination Port
192.168.56.101 50534 114.114.114.114 53
192.168.56.101 51963 114.114.114.114 53
192.168.56.101 56539 114.114.114.114 53
192.168.56.101 65004 114.114.114.114 53
192.168.56.101 137 192.168.56.255 137
192.168.56.101 138 192.168.56.255 138
192.168.56.101 49235 224.0.0.252 5355
192.168.56.101 56804 224.0.0.252 5355
192.168.56.101 60123 224.0.0.252 5355
192.168.56.101 62191 224.0.0.252 5355
192.168.56.101 1900 239.255.255.250 1900
192.168.56.101 50535 239.255.255.250 3702
192.168.56.101 50537 239.255.255.250 3702
192.168.56.101 56807 239.255.255.250 1900
192.168.56.101 58707 239.255.255.250 3702
192.168.56.101 62192 239.255.255.250 3702

HTTP & HTTPS Requests

No HTTP requests performed.

ICMP traffic

No ICMP traffic performed.

IRC traffic

No IRC requests performed.

Suricata Alerts

No Suricata Alerts

Suricata TLS

No Suricata TLS

Snort Alerts

No Snort Alerts

Sorry! No dropped files.
Sorry! No dropped buffers.