6.2
高危

0afd99c3f7593c760c4001313963f3e7fd709ca56046044033d790602a8cb378

dd4f9213ba67c26add74eae8c8b8bd8c.exe

分析耗时

129s

最近分析

文件大小

57.0KB
静态报毒 动态报毒 100% AI SCORE=100 BSCOPE CCMW CONFIDENCE FILECODER GEN3 GENCIRC HIGH CONFIDENCE JKWB KCLOUD MAILTO NETW NETWALKER QVM20 RAZY SCORE SD@8RQQOE SMTH SUSGEN TROJANPSW UNSAFE VIRRANSOM WBNA XPACK YSVCZSW6W5I ZUDOCHKA 更多
鹰眼引擎
未检测 暂无鹰眼引擎检测结果
静态判定
反病毒引擎
查杀引擎 查杀结果 查杀时间 查杀版本
McAfee Ransom-NetW!DD4F9213BA67 20201202 6.0.6.653
CrowdStrike win/malicious_confidence_100% (W) 20190702 1.0
Alibaba Ransom:Win32/NetWalker.8bc164b3 20190527 0.3.0.5
Baidu 20190318 1.0.0.2
Avast Win32:Trojan-gen 20201202 20.10.5736.0
Tencent Malware.Win32.Gencirc.10ce0b77 20201202 1.0.0.1
Kingsoft Win32.Troj.Undef.(kcloud) 20201202 2017.9.26.565
静态指标
行为判定
动态指标
Steals private information from local Internet browsers (50 out of 152 个事件)
file C:\Users\Administrator.Oskar-PC\AppData\Local\Google\Chrome\User Data\Default\GPUCache\data_1
file C:\Users\Administrator.Oskar-PC\AppData\Local\Google\Chrome\User Data\Default\GPUCache\data_0
file C:\Users\Administrator.Oskar-PC\AppData\Local\Google\Chrome\User Data\Default\GPUCache\data_3
file C:\Users\Administrator.Oskar-PC\AppData\Local\Google\Chrome\User Data\Default\GPUCache\data_2
file C:\Users\Administrator.Oskar-PC\AppData\Local\Google\Chrome\User Data\Default\Reporting and NEL
file C:\Users\Administrator.Oskar-PC\AppData\Local\Google\Chrome\User Data\chrome_shutdown_ms.txt
file C:\Users\Administrator.Oskar-PC\AppData\Local\Google\Chrome\User Data\Default\Site Characteristics Database\LOG.old
file C:\Users\Administrator.Oskar-PC\AppData\Local\Google\Chrome\User Data\Default\Local Storage\leveldb\CURRENT
file C:\Users\Administrator.Oskar-PC\AppData\Local\Google\Chrome\User Data\Default\GPUCache\FF4619-Readme.txt
file C:\Users\Administrator.Oskar-PC\AppData\Local\Google\Chrome\User Data\BrowserMetrics\FF4619-Readme.txt
file C:\Users\Administrator.Oskar-PC\AppData\Local\Google\Chrome\User Data\Default\Platform Notifications\LOCK
file C:\Users\Administrator.Oskar-PC\AppData\Local\Google\Chrome\User Data\Default\Web Data-journal
file C:\Users\Administrator.Oskar-PC\AppData\Local\Google\Chrome\User Data\GrShaderCache\GPUCache\data_3
file C:\Users\Administrator.Oskar-PC\AppData\Local\Google\Chrome\User Data\Default\shared_proto_db\MANIFEST-000001
file C:\Users\Administrator.Oskar-PC\AppData\Local\Google\Chrome\User Data\Default\GCM Store\Encryption\000003.log
file C:\Users\Administrator.Oskar-PC\AppData\Local\Google\Chrome\User Data\Default\shared_proto_db\LOCK
file C:\Users\Administrator.Oskar-PC\AppData\Local\Google\Chrome\User Data\Default\Site Characteristics Database\LOCK
file C:\Users\Administrator.Oskar-PC\AppData\Local\Google\Chrome\User Data\BrowserMetrics\BrowserMetrics-6072F217-D54.pma
file C:\Users\Administrator.Oskar-PC\AppData\Local\Google\Chrome\User Data\Default\Shortcuts
file C:\Users\Administrator.Oskar-PC\AppData\Local\Google\Chrome\User Data\Default\data_reduction_proxy_leveldb\LOCK
file C:\Users\Administrator.Oskar-PC\AppData\Local\Google\Chrome\User Data\Default\Favicons-journal
file C:\Users\Administrator.Oskar-PC\AppData\Local\Google\Chrome\User Data\Default\Code Cache\js\16d48f1e7b824888_0
file C:\Users\Administrator.Oskar-PC\AppData\Local\Google\Chrome\User Data\Default\Platform Notifications\LOG.old
file C:\Users\Administrator.Oskar-PC\AppData\Local\Google\Chrome\User Data\Default\data_reduction_proxy_leveldb\MANIFEST-000002
file C:\Users\Administrator.Oskar-PC\AppData\Local\Google\Chrome\User Data\Default\GCM Store\Encryption\LOCK
file C:\Users\Administrator.Oskar-PC\AppData\Local\Google\Chrome\User Data\Default\LOCK
file C:\Users\Administrator.Oskar-PC\AppData\Local\Google\Chrome\User Data\Default\heavy_ad_intervention_opt_out.db-journal
file C:\Users\Administrator.Oskar-PC\AppData\Local\Google\Chrome\User Data\Default\Local Storage\leveldb\LOG.old
file C:\Users\Administrator.Oskar-PC\AppData\Local\Google\Chrome\User Data\Default\databases\Databases.db
file C:\Users\Administrator.Oskar-PC\AppData\Local\Google\Chrome\User Data\Default\shared_proto_db\CURRENT
file C:\Users\Administrator.Oskar-PC\AppData\Local\Google\Chrome\User Data\Default\Code Cache\wasm\index-dir\the-real-index
file C:\Users\Administrator.Oskar-PC\AppData\Local\Google\Chrome\User Data\Default\Sync Data\LevelDB\000003.log
file C:\Users\Administrator.Oskar-PC\AppData\Local\Google\Chrome\User Data\Default\LOG
file C:\Users\Administrator.Oskar-PC\AppData\Local\Google\Chrome\User Data\Crashpad\settings.dat
file C:\Users\Administrator.Oskar-PC\AppData\Local\Google\Chrome\User Data\Default\Cache\f_000004
file C:\Users\Administrator.Oskar-PC\AppData\Local\Google\Chrome\User Data\Default\previews_opt_out.db-journal
file C:\Users\Administrator.Oskar-PC\AppData\Local\Google\Chrome\User Data\Default\QuotaManager
file C:\Users\Administrator.Oskar-PC\AppData\Local\Google\Chrome\User Data\Default\Cache\f_000001
file C:\Users\Administrator.Oskar-PC\AppData\Local\Google\Chrome\User Data\Default\Cache\f_000002
file C:\Users\Administrator.Oskar-PC\AppData\Local\Google\Chrome\User Data\Default\Cache\f_000003
file C:\Users\Administrator.Oskar-PC\AppData\Local\Google\Chrome\User Data\ShaderCache\GPUCache\data_2
file C:\Users\Administrator.Oskar-PC\AppData\Local\Google\Chrome\User Data\FontLookupTableCache\font_unique_name_table.pb
file C:\Users\Administrator.Oskar-PC\AppData\Local\Google\Chrome\User Data\Default\Platform Notifications\CURRENT
file C:\Users\Administrator.Oskar-PC\AppData\Local\Google\Chrome\User Data\Default\data_reduction_proxy_leveldb\FF4619-Readme.txt
file C:\Users\Administrator.Oskar-PC\AppData\Local\Google\Chrome\User Data\Default\Sessions\FF4619-Readme.txt
file C:\Users\Administrator.Oskar-PC\AppData\Local\Google\Chrome\User Data\GrShaderCache\GPUCache\FF4619-Readme.txt
file C:\Users\Administrator.Oskar-PC\AppData\Local\Google\Chrome\User Data\Default\Feature Engagement Tracker\EventDB\LOCK
file C:\Users\Administrator.Oskar-PC\AppData\Local\Google\Chrome\User Data\First Run
file C:\Users\Administrator.Oskar-PC\AppData\Local\Google\Chrome\User Data\Default\databases\Databases.db-journal
file C:\Users\Administrator.Oskar-PC\AppData\Local\Google\Chrome\User Data\Default\Platform Notifications\FF4619-Readme.txt
Creates (office) documents on the filesystem (4 个事件)
file C:\Users\Administrator.Oskar-PC\Documents\gLmEgarmCNJfl.doc
file C:\Users\Administrator.Oskar-PC\Documents\siqAnPRqny.ppt
file C:\Users\Administrator.Oskar-PC\Documents\IhNFRZvJfoZ.ppt
file C:\Users\Administrator.Oskar-PC\Documents\LLOvCOFfHbl.pptx
The binary likely contains encrypted or compressed data indicative of a packer (1 个事件)
entropy 7.911036871060745 section {'size_of_data': '0x00001600', 'virtual_address': '0x0000f000', 'entropy': 7.911036871060745, 'name': '.rsrc', 'virtual_size': '0x00002000'} description A section with a high entropy has been found
Checks for the Locally Unique Identifier on the system for a suspicious privilege (1 个事件)
Time & API Arguments Status Return Repeated
1619948416.149148
LookupPrivilegeValueW
system_name:
privilege_name: SeDebugPrivilege
success 1 0
网络通信
Communicates with host for which no DNS query was performed (1 个事件)
host 172.217.24.14
Attempts to detect Cuckoo Sandbox through the presence of a file (2 个事件)
file C:\Python27\agent.pyw
file C:\tmpsij43m\analyzer.py
Appends a known multi-family ransomware file extension to files that have been encrypted (50 out of 78 个事件)
file C:\Python27\tcl\tcl8.5\encoding\iso2022-kr.enc
file C:\Python27\tcl\tcl8.5\encoding\iso8859-3.enc
file C:\Python27\tcl\tcl8.5\encoding\euc-cn.enc
file C:\Python27\tcl\tcl8.5\encoding\cp857.enc
file C:\Python27\tcl\tcl8.5\encoding\macIceland.enc
file C:\Python27\tcl\tcl8.5\encoding\macCyrillic.enc
file C:\Python27\tcl\tcl8.5\encoding\iso8859-8.enc
file C:\Python27\tcl\tcl8.5\encoding\cp932.enc
file C:\Python27\tcl\tcl8.5\encoding\cp863.enc
file C:\Python27\tcl\tcl8.5\encoding\macGreek.enc
file C:\Python27\tcl\tcl8.5\encoding\gb12345.enc
file C:\Python27\tcl\tcl8.5\encoding\cp1254.enc
file C:\Python27\tcl\tcl8.5\encoding\cp1255.enc
file C:\Python27\tcl\tcl8.5\encoding\iso8859-2.enc
file C:\Python27\tcl\tcl8.5\encoding\macCroatian.enc
file C:\Python27\tcl\tcl8.5\encoding\cp949.enc
file C:\Python27\tcl\tcl8.5\encoding\cp437.enc
file C:\Python27\tcl\tcl8.5\encoding\cp775.enc
file C:\Python27\tcl\tcl8.5\encoding\big5.enc
file C:\Python27\tcl\tcl8.5\encoding\cp936.enc
file C:\Python27\tcl\tcl8.5\encoding\iso2022-jp.enc
file C:\Python27\tcl\tcl8.5\encoding\cp869.enc
file C:\Python27\tcl\tcl8.5\encoding\iso8859-5.enc
file C:\Python27\tcl\tcl8.5\encoding\iso8859-9.enc
file C:\Python27\tcl\tcl8.5\encoding\macThai.enc
file C:\Python27\tcl\tcl8.5\encoding\macRoman.enc
file C:\Python27\tcl\tcl8.5\encoding\gb1988.enc
file C:\Python27\tcl\tcl8.5\encoding\iso8859-15.enc
file C:\Python27\tcl\tcl8.5\encoding\ebcdic.enc
file C:\Python27\tcl\tcl8.5\encoding\ascii.enc
file C:\Python27\tcl\tcl8.5\encoding\cp865.enc
file C:\Python27\tcl\tcl8.5\encoding\shiftjis.enc
file C:\Python27\tcl\tcl8.5\encoding\macCentEuro.enc
file C:\Python27\tcl\tcl8.5\encoding\cp850.enc
file C:\Python27\tcl\tcl8.5\encoding\jis0212.enc
file C:\Python27\tcl\tcl8.5\encoding\cp1251.enc
file C:\Python27\tcl\tcl8.5\encoding\euc-jp.enc
file C:\Python27\tcl\tcl8.5\encoding\euc-kr.enc
file C:\Python27\tcl\tcl8.5\encoding\macUkraine.enc
file C:\Python27\tcl\tcl8.5\encoding\macTurkish.enc
file C:\Python27\tcl\tcl8.5\encoding\iso8859-1.enc
file C:\Python27\tcl\tcl8.5\encoding\macRomania.enc
file C:\Python27\tcl\tcl8.5\encoding\jis0201.enc
file C:\Python27\tcl\tcl8.5\encoding\macDingbats.enc
file C:\Python27\tcl\tcl8.5\encoding\iso8859-4.enc
file C:\Python27\tcl\tcl8.5\encoding\cp1250.enc
file C:\Python27\tcl\tcl8.5\encoding\cp862.enc
file C:\Python27\tcl\tcl8.5\encoding\cp864.enc
file C:\Python27\tcl\tcl8.5\encoding\koi8-r.enc
file C:\Python27\tcl\tcl8.5\encoding\koi8-u.enc
Writes a potential ransom message to disk (50 out of 216 个事件)
Time & API Arguments Status Return Repeated
1619948417.962148
NtWriteFile
file_handle: 0x00000954
filepath: C:\tmpsij43m\FF4619-Readme.txt
buffer: Hi! Your files are encrypted by Netwalker. All encrypted files for this computer has extension: .ff4619 -- If for some reason you read this text before the encryption ended, this can be understood by the fact that the computer slows down, and your heart rate has increased due to the ability to turn it off, then we recommend that you move away from the computer and accept that you have been compromised. Rebooting/shutdown will cause you to lose files without the possibility of recovery. -- Our encryption algorithms are very strong and your files are very well protected, the only way to get your files back is to cooperate with us and get the decrypter program. Do not try to recover your files without a decrypter program, you may damage them and then they will be impossible to recover. For us this is just business and to prove to you our seriousness, we will decrypt you one file for free. Just open our website, upload the encrypted file and get the decrypted file for free. -- Steps to get access on our website: 1.Download and install tor-browser: https://torproject.org/ 2.Open our website: pb36hu4spl6cyjdfhing7h3pw6dhpk32ifemawkujj4gp33ejzdq3did.onion If the website is not available, open another one: rnfdsgm6wb6j6su5txkekw4u4y47kp2eatvu7d6xhyn5cs4lt4pdrqqd.onion 3.Put your personal code in the input form: {code_ff4619: cUKoUMD2ZvOihvw/J/LCR50+hydh1ULiPJKDuXRmn+2DbZMQeK uSxmHXRvpmgNPaE9d2Z/KbdCUit+mE7qK/ZaT5rCMfJ6I2NPbn h+gUl/1hA+Rm42GYsJYLOiLdhEvBeazcpavfsQmcPMZXZH5lh1 VhtfRqkFLxIrHkLA4IhW/VE6Cr8rfdrRS2QZh5XrzUS5Xf14a+ KdPpY+2DT5SZO6dP8Qc2X9bIX11cydfe00eJe7mTzPFp9CYtXe 6n38vCehE7bF9/nrG1NONgs1pk2sd/5Pylwd80jA==}
offset: 0
success 0 0
1619948418.071148
NtWriteFile
file_handle: 0x00000938
filepath: C:\tmpsij43m\bin\FF4619-Readme.txt
buffer: Hi! Your files are encrypted by Netwalker. All encrypted files for this computer has extension: .ff4619 -- If for some reason you read this text before the encryption ended, this can be understood by the fact that the computer slows down, and your heart rate has increased due to the ability to turn it off, then we recommend that you move away from the computer and accept that you have been compromised. Rebooting/shutdown will cause you to lose files without the possibility of recovery. -- Our encryption algorithms are very strong and your files are very well protected, the only way to get your files back is to cooperate with us and get the decrypter program. Do not try to recover your files without a decrypter program, you may damage them and then they will be impossible to recover. For us this is just business and to prove to you our seriousness, we will decrypt you one file for free. Just open our website, upload the encrypted file and get the decrypted file for free. -- Steps to get access on our website: 1.Download and install tor-browser: https://torproject.org/ 2.Open our website: pb36hu4spl6cyjdfhing7h3pw6dhpk32ifemawkujj4gp33ejzdq3did.onion If the website is not available, open another one: rnfdsgm6wb6j6su5txkekw4u4y47kp2eatvu7d6xhyn5cs4lt4pdrqqd.onion 3.Put your personal code in the input form: {code_ff4619: cUKoUMD2ZvOihvw/J/LCR50+hydh1ULiPJKDuXRmn+2DbZMQeK uSxmHXRvpmgNPaE9d2Z/KbdCUit+mE7qK/ZaT5rCMfJ6I2NPbn h+gUl/1hA+Rm42GYsJYLOiLdhEvBeazcpavfsQmcPMZXZH5lh1 VhtfRqkFLxIrHkLA4IhW/VE6Cr8rfdrRS2QZh5XrzUS5Xf14a+ KdPpY+2DT5SZO6dP8Qc2X9bIX11cydfe00eJe7mTzPFp9CYtXe 6n38vCehE7bF9/nrG1NONgs1pk2sd/5Pylwd80jA==}
offset: 0
success 0 0
1619948419.118148
NtWriteFile
file_handle: 0x000009a8
filepath: C:\Program Files\Oracle\VirtualBox Guest Additions\FF4619-Readme.txt
buffer: Hi! Your files are encrypted by Netwalker. All encrypted files for this computer has extension: .ff4619 -- If for some reason you read this text before the encryption ended, this can be understood by the fact that the computer slows down, and your heart rate has increased due to the ability to turn it off, then we recommend that you move away from the computer and accept that you have been compromised. Rebooting/shutdown will cause you to lose files without the possibility of recovery. -- Our encryption algorithms are very strong and your files are very well protected, the only way to get your files back is to cooperate with us and get the decrypter program. Do not try to recover your files without a decrypter program, you may damage them and then they will be impossible to recover. For us this is just business and to prove to you our seriousness, we will decrypt you one file for free. Just open our website, upload the encrypted file and get the decrypted file for free. -- Steps to get access on our website: 1.Download and install tor-browser: https://torproject.org/ 2.Open our website: pb36hu4spl6cyjdfhing7h3pw6dhpk32ifemawkujj4gp33ejzdq3did.onion If the website is not available, open another one: rnfdsgm6wb6j6su5txkekw4u4y47kp2eatvu7d6xhyn5cs4lt4pdrqqd.onion 3.Put your personal code in the input form: {code_ff4619: cUKoUMD2ZvOihvw/J/LCR50+hydh1ULiPJKDuXRmn+2DbZMQeK uSxmHXRvpmgNPaE9d2Z/KbdCUit+mE7qK/ZaT5rCMfJ6I2NPbn h+gUl/1hA+Rm42GYsJYLOiLdhEvBeazcpavfsQmcPMZXZH5lh1 VhtfRqkFLxIrHkLA4IhW/VE6Cr8rfdrRS2QZh5XrzUS5Xf14a+ KdPpY+2DT5SZO6dP8Qc2X9bIX11cydfe00eJe7mTzPFp9CYtXe 6n38vCehE7bF9/nrG1NONgs1pk2sd/5Pylwd80jA==}
offset: 0
success 0 0
1619948419.227148
NtWriteFile
file_handle: 0x000009a0
filepath: C:\tmpsij43m\lib\FF4619-Readme.txt
buffer: Hi! Your files are encrypted by Netwalker. All encrypted files for this computer has extension: .ff4619 -- If for some reason you read this text before the encryption ended, this can be understood by the fact that the computer slows down, and your heart rate has increased due to the ability to turn it off, then we recommend that you move away from the computer and accept that you have been compromised. Rebooting/shutdown will cause you to lose files without the possibility of recovery. -- Our encryption algorithms are very strong and your files are very well protected, the only way to get your files back is to cooperate with us and get the decrypter program. Do not try to recover your files without a decrypter program, you may damage them and then they will be impossible to recover. For us this is just business and to prove to you our seriousness, we will decrypt you one file for free. Just open our website, upload the encrypted file and get the decrypted file for free. -- Steps to get access on our website: 1.Download and install tor-browser: https://torproject.org/ 2.Open our website: pb36hu4spl6cyjdfhing7h3pw6dhpk32ifemawkujj4gp33ejzdq3did.onion If the website is not available, open another one: rnfdsgm6wb6j6su5txkekw4u4y47kp2eatvu7d6xhyn5cs4lt4pdrqqd.onion 3.Put your personal code in the input form: {code_ff4619: cUKoUMD2ZvOihvw/J/LCR50+hydh1ULiPJKDuXRmn+2DbZMQeK uSxmHXRvpmgNPaE9d2Z/KbdCUit+mE7qK/ZaT5rCMfJ6I2NPbn h+gUl/1hA+Rm42GYsJYLOiLdhEvBeazcpavfsQmcPMZXZH5lh1 VhtfRqkFLxIrHkLA4IhW/VE6Cr8rfdrRS2QZh5XrzUS5Xf14a+ KdPpY+2DT5SZO6dP8Qc2X9bIX11cydfe00eJe7mTzPFp9CYtXe 6n38vCehE7bF9/nrG1NONgs1pk2sd/5Pylwd80jA==}
offset: 0
success 0 0
1619948419.524148
NtWriteFile
file_handle: 0x00000b10
filepath: C:\Users\Administrator.Oskar-PC\Documents\FF4619-Readme.txt
buffer: Hi! Your files are encrypted by Netwalker. All encrypted files for this computer has extension: .ff4619 -- If for some reason you read this text before the encryption ended, this can be understood by the fact that the computer slows down, and your heart rate has increased due to the ability to turn it off, then we recommend that you move away from the computer and accept that you have been compromised. Rebooting/shutdown will cause you to lose files without the possibility of recovery. -- Our encryption algorithms are very strong and your files are very well protected, the only way to get your files back is to cooperate with us and get the decrypter program. Do not try to recover your files without a decrypter program, you may damage them and then they will be impossible to recover. For us this is just business and to prove to you our seriousness, we will decrypt you one file for free. Just open our website, upload the encrypted file and get the decrypted file for free. -- Steps to get access on our website: 1.Download and install tor-browser: https://torproject.org/ 2.Open our website: pb36hu4spl6cyjdfhing7h3pw6dhpk32ifemawkujj4gp33ejzdq3did.onion If the website is not available, open another one: rnfdsgm6wb6j6su5txkekw4u4y47kp2eatvu7d6xhyn5cs4lt4pdrqqd.onion 3.Put your personal code in the input form: {code_ff4619: cUKoUMD2ZvOihvw/J/LCR50+hydh1ULiPJKDuXRmn+2DbZMQeK uSxmHXRvpmgNPaE9d2Z/KbdCUit+mE7qK/ZaT5rCMfJ6I2NPbn h+gUl/1hA+Rm42GYsJYLOiLdhEvBeazcpavfsQmcPMZXZH5lh1 VhtfRqkFLxIrHkLA4IhW/VE6Cr8rfdrRS2QZh5XrzUS5Xf14a+ KdPpY+2DT5SZO6dP8Qc2X9bIX11cydfe00eJe7mTzPFp9CYtXe 6n38vCehE7bF9/nrG1NONgs1pk2sd/5Pylwd80jA==}
offset: 0
success 0 0
1619948423.509148
NtWriteFile
file_handle: 0x00000b14
filepath: C:\Users\Administrator.Oskar-PC\Documents\FF4619-Readme.txt
buffer: Hi! Your files are encrypted by Netwalker. All encrypted files for this computer has extension: .ff4619 -- If for some reason you read this text before the encryption ended, this can be understood by the fact that the computer slows down, and your heart rate has increased due to the ability to turn it off, then we recommend that you move away from the computer and accept that you have been compromised. Rebooting/shutdown will cause you to lose files without the possibility of recovery. -- Our encryption algorithms are very strong and your files are very well protected, the only way to get your files back is to cooperate with us and get the decrypter program. Do not try to recover your files without a decrypter program, you may damage them and then they will be impossible to recover. For us this is just business and to prove to you our seriousness, we will decrypt you one file for free. Just open our website, upload the encrypted file and get the decrypted file for free. -- Steps to get access on our website: 1.Download and install tor-browser: https://torproject.org/ 2.Open our website: pb36hu4spl6cyjdfhing7h3pw6dhpk32ifemawkujj4gp33ejzdq3did.onion If the website is not available, open another one: rnfdsgm6wb6j6su5txkekw4u4y47kp2eatvu7d6xhyn5cs4lt4pdrqqd.onion 3.Put your personal code in the input form: {code_ff4619: cUKoUMD2ZvOihvw/J/LCR50+hydh1ULiPJKDuXRmn+2DbZMQeK uSxmHXRvpmgNPaE9d2Z/KbdCUit+mE7qK/ZaT5rCMfJ6I2NPbn h+gUl/1hA+Rm42GYsJYLOiLdhEvBeazcpavfsQmcPMZXZH5lh1 VhtfRqkFLxIrHkLA4IhW/VE6Cr8rfdrRS2QZh5XrzUS5Xf14a+ KdPpY+2DT5SZO6dP8Qc2X9bIX11cydfe00eJe7mTzPFp9CYtXe 6n38vCehE7bF9/nrG1NONgs1pk2sd/5Pylwd80jA==}
offset: 0
success 0 0
1619948425.618148
NtWriteFile
file_handle: 0x0000171c
filepath: C:\Program Files\Google\Chrome\Application\FF4619-Readme.txt
buffer: Hi! Your files are encrypted by Netwalker. All encrypted files for this computer has extension: .ff4619 -- If for some reason you read this text before the encryption ended, this can be understood by the fact that the computer slows down, and your heart rate has increased due to the ability to turn it off, then we recommend that you move away from the computer and accept that you have been compromised. Rebooting/shutdown will cause you to lose files without the possibility of recovery. -- Our encryption algorithms are very strong and your files are very well protected, the only way to get your files back is to cooperate with us and get the decrypter program. Do not try to recover your files without a decrypter program, you may damage them and then they will be impossible to recover. For us this is just business and to prove to you our seriousness, we will decrypt you one file for free. Just open our website, upload the encrypted file and get the decrypted file for free. -- Steps to get access on our website: 1.Download and install tor-browser: https://torproject.org/ 2.Open our website: pb36hu4spl6cyjdfhing7h3pw6dhpk32ifemawkujj4gp33ejzdq3did.onion If the website is not available, open another one: rnfdsgm6wb6j6su5txkekw4u4y47kp2eatvu7d6xhyn5cs4lt4pdrqqd.onion 3.Put your personal code in the input form: {code_ff4619: cUKoUMD2ZvOihvw/J/LCR50+hydh1ULiPJKDuXRmn+2DbZMQeK uSxmHXRvpmgNPaE9d2Z/KbdCUit+mE7qK/ZaT5rCMfJ6I2NPbn h+gUl/1hA+Rm42GYsJYLOiLdhEvBeazcpavfsQmcPMZXZH5lh1 VhtfRqkFLxIrHkLA4IhW/VE6Cr8rfdrRS2QZh5XrzUS5Xf14a+ KdPpY+2DT5SZO6dP8Qc2X9bIX11cydfe00eJe7mTzPFp9CYtXe 6n38vCehE7bF9/nrG1NONgs1pk2sd/5Pylwd80jA==}
offset: 0
success 0 0
1619948425.618148
NtWriteFile
file_handle: 0x00001608
filepath: C:\Program Files (x86)\Microsoft.NET\RedistList\FF4619-Readme.txt
buffer: Hi! Your files are encrypted by Netwalker. All encrypted files for this computer has extension: .ff4619 -- If for some reason you read this text before the encryption ended, this can be understood by the fact that the computer slows down, and your heart rate has increased due to the ability to turn it off, then we recommend that you move away from the computer and accept that you have been compromised. Rebooting/shutdown will cause you to lose files without the possibility of recovery. -- Our encryption algorithms are very strong and your files are very well protected, the only way to get your files back is to cooperate with us and get the decrypter program. Do not try to recover your files without a decrypter program, you may damage them and then they will be impossible to recover. For us this is just business and to prove to you our seriousness, we will decrypt you one file for free. Just open our website, upload the encrypted file and get the decrypted file for free. -- Steps to get access on our website: 1.Download and install tor-browser: https://torproject.org/ 2.Open our website: pb36hu4spl6cyjdfhing7h3pw6dhpk32ifemawkujj4gp33ejzdq3did.onion If the website is not available, open another one: rnfdsgm6wb6j6su5txkekw4u4y47kp2eatvu7d6xhyn5cs4lt4pdrqqd.onion 3.Put your personal code in the input form: {code_ff4619: cUKoUMD2ZvOihvw/J/LCR50+hydh1ULiPJKDuXRmn+2DbZMQeK uSxmHXRvpmgNPaE9d2Z/KbdCUit+mE7qK/ZaT5rCMfJ6I2NPbn h+gUl/1hA+Rm42GYsJYLOiLdhEvBeazcpavfsQmcPMZXZH5lh1 VhtfRqkFLxIrHkLA4IhW/VE6Cr8rfdrRS2QZh5XrzUS5Xf14a+ KdPpY+2DT5SZO6dP8Qc2X9bIX11cydfe00eJe7mTzPFp9CYtXe 6n38vCehE7bF9/nrG1NONgs1pk2sd/5Pylwd80jA==}
offset: 0
success 0 0
1619948426.509148
NtWriteFile
file_handle: 0x000019f4
filepath: C:\Program Files (x86)\MSBuild\Microsoft\Windows Workflow Foundation\v3.0\FF4619-Readme.txt
buffer: Hi! Your files are encrypted by Netwalker. All encrypted files for this computer has extension: .ff4619 -- If for some reason you read this text before the encryption ended, this can be understood by the fact that the computer slows down, and your heart rate has increased due to the ability to turn it off, then we recommend that you move away from the computer and accept that you have been compromised. Rebooting/shutdown will cause you to lose files without the possibility of recovery. -- Our encryption algorithms are very strong and your files are very well protected, the only way to get your files back is to cooperate with us and get the decrypter program. Do not try to recover your files without a decrypter program, you may damage them and then they will be impossible to recover. For us this is just business and to prove to you our seriousness, we will decrypt you one file for free. Just open our website, upload the encrypted file and get the decrypted file for free. -- Steps to get access on our website: 1.Download and install tor-browser: https://torproject.org/ 2.Open our website: pb36hu4spl6cyjdfhing7h3pw6dhpk32ifemawkujj4gp33ejzdq3did.onion If the website is not available, open another one: rnfdsgm6wb6j6su5txkekw4u4y47kp2eatvu7d6xhyn5cs4lt4pdrqqd.onion 3.Put your personal code in the input form: {code_ff4619: cUKoUMD2ZvOihvw/J/LCR50+hydh1ULiPJKDuXRmn+2DbZMQeK uSxmHXRvpmgNPaE9d2Z/KbdCUit+mE7qK/ZaT5rCMfJ6I2NPbn h+gUl/1hA+Rm42GYsJYLOiLdhEvBeazcpavfsQmcPMZXZH5lh1 VhtfRqkFLxIrHkLA4IhW/VE6Cr8rfdrRS2QZh5XrzUS5Xf14a+ KdPpY+2DT5SZO6dP8Qc2X9bIX11cydfe00eJe7mTzPFp9CYtXe 6n38vCehE7bF9/nrG1NONgs1pk2sd/5Pylwd80jA==}
offset: 0
success 0 0
1619948426.556148
NtWriteFile
file_handle: 0x00001658
filepath: C:\ProgramData\Microsoft\MF\FF4619-Readme.txt
buffer: Hi! Your files are encrypted by Netwalker. All encrypted files for this computer has extension: .ff4619 -- If for some reason you read this text before the encryption ended, this can be understood by the fact that the computer slows down, and your heart rate has increased due to the ability to turn it off, then we recommend that you move away from the computer and accept that you have been compromised. Rebooting/shutdown will cause you to lose files without the possibility of recovery. -- Our encryption algorithms are very strong and your files are very well protected, the only way to get your files back is to cooperate with us and get the decrypter program. Do not try to recover your files without a decrypter program, you may damage them and then they will be impossible to recover. For us this is just business and to prove to you our seriousness, we will decrypt you one file for free. Just open our website, upload the encrypted file and get the decrypted file for free. -- Steps to get access on our website: 1.Download and install tor-browser: https://torproject.org/ 2.Open our website: pb36hu4spl6cyjdfhing7h3pw6dhpk32ifemawkujj4gp33ejzdq3did.onion If the website is not available, open another one: rnfdsgm6wb6j6su5txkekw4u4y47kp2eatvu7d6xhyn5cs4lt4pdrqqd.onion 3.Put your personal code in the input form: {code_ff4619: cUKoUMD2ZvOihvw/J/LCR50+hydh1ULiPJKDuXRmn+2DbZMQeK uSxmHXRvpmgNPaE9d2Z/KbdCUit+mE7qK/ZaT5rCMfJ6I2NPbn h+gUl/1hA+Rm42GYsJYLOiLdhEvBeazcpavfsQmcPMZXZH5lh1 VhtfRqkFLxIrHkLA4IhW/VE6Cr8rfdrRS2QZh5XrzUS5Xf14a+ KdPpY+2DT5SZO6dP8Qc2X9bIX11cydfe00eJe7mTzPFp9CYtXe 6n38vCehE7bF9/nrG1NONgs1pk2sd/5Pylwd80jA==}
offset: 0
success 0 0
1619948426.681148
NtWriteFile
file_handle: 0x0000171c
filepath: C:\Program Files\Google\Chrome\Application\Dictionaries\FF4619-Readme.txt
buffer: Hi! Your files are encrypted by Netwalker. All encrypted files for this computer has extension: .ff4619 -- If for some reason you read this text before the encryption ended, this can be understood by the fact that the computer slows down, and your heart rate has increased due to the ability to turn it off, then we recommend that you move away from the computer and accept that you have been compromised. Rebooting/shutdown will cause you to lose files without the possibility of recovery. -- Our encryption algorithms are very strong and your files are very well protected, the only way to get your files back is to cooperate with us and get the decrypter program. Do not try to recover your files without a decrypter program, you may damage them and then they will be impossible to recover. For us this is just business and to prove to you our seriousness, we will decrypt you one file for free. Just open our website, upload the encrypted file and get the decrypted file for free. -- Steps to get access on our website: 1.Download and install tor-browser: https://torproject.org/ 2.Open our website: pb36hu4spl6cyjdfhing7h3pw6dhpk32ifemawkujj4gp33ejzdq3did.onion If the website is not available, open another one: rnfdsgm6wb6j6su5txkekw4u4y47kp2eatvu7d6xhyn5cs4lt4pdrqqd.onion 3.Put your personal code in the input form: {code_ff4619: cUKoUMD2ZvOihvw/J/LCR50+hydh1ULiPJKDuXRmn+2DbZMQeK uSxmHXRvpmgNPaE9d2Z/KbdCUit+mE7qK/ZaT5rCMfJ6I2NPbn h+gUl/1hA+Rm42GYsJYLOiLdhEvBeazcpavfsQmcPMZXZH5lh1 VhtfRqkFLxIrHkLA4IhW/VE6Cr8rfdrRS2QZh5XrzUS5Xf14a+ KdPpY+2DT5SZO6dP8Qc2X9bIX11cydfe00eJe7mTzPFp9CYtXe 6n38vCehE7bF9/nrG1NONgs1pk2sd/5Pylwd80jA==}
offset: 0
success 0 0
1619948426.774148
NtWriteFile
file_handle: 0x00000cfc
filepath: C:\ProgramData\Microsoft\User Account Pictures\FF4619-Readme.txt
buffer: Hi! Your files are encrypted by Netwalker. All encrypted files for this computer has extension: .ff4619 -- If for some reason you read this text before the encryption ended, this can be understood by the fact that the computer slows down, and your heart rate has increased due to the ability to turn it off, then we recommend that you move away from the computer and accept that you have been compromised. Rebooting/shutdown will cause you to lose files without the possibility of recovery. -- Our encryption algorithms are very strong and your files are very well protected, the only way to get your files back is to cooperate with us and get the decrypter program. Do not try to recover your files without a decrypter program, you may damage them and then they will be impossible to recover. For us this is just business and to prove to you our seriousness, we will decrypt you one file for free. Just open our website, upload the encrypted file and get the decrypted file for free. -- Steps to get access on our website: 1.Download and install tor-browser: https://torproject.org/ 2.Open our website: pb36hu4spl6cyjdfhing7h3pw6dhpk32ifemawkujj4gp33ejzdq3did.onion If the website is not available, open another one: rnfdsgm6wb6j6su5txkekw4u4y47kp2eatvu7d6xhyn5cs4lt4pdrqqd.onion 3.Put your personal code in the input form: {code_ff4619: cUKoUMD2ZvOihvw/J/LCR50+hydh1ULiPJKDuXRmn+2DbZMQeK uSxmHXRvpmgNPaE9d2Z/KbdCUit+mE7qK/ZaT5rCMfJ6I2NPbn h+gUl/1hA+Rm42GYsJYLOiLdhEvBeazcpavfsQmcPMZXZH5lh1 VhtfRqkFLxIrHkLA4IhW/VE6Cr8rfdrRS2QZh5XrzUS5Xf14a+ KdPpY+2DT5SZO6dP8Qc2X9bIX11cydfe00eJe7mTzPFp9CYtXe 6n38vCehE7bF9/nrG1NONgs1pk2sd/5Pylwd80jA==}
offset: 0
success 0 0
1619948427.415148
NtWriteFile
file_handle: 0x00001de8
filepath: C:\tmpsij43m\modules\FF4619-Readme.txt
buffer: Hi! Your files are encrypted by Netwalker. All encrypted files for this computer has extension: .ff4619 -- If for some reason you read this text before the encryption ended, this can be understood by the fact that the computer slows down, and your heart rate has increased due to the ability to turn it off, then we recommend that you move away from the computer and accept that you have been compromised. Rebooting/shutdown will cause you to lose files without the possibility of recovery. -- Our encryption algorithms are very strong and your files are very well protected, the only way to get your files back is to cooperate with us and get the decrypter program. Do not try to recover your files without a decrypter program, you may damage them and then they will be impossible to recover. For us this is just business and to prove to you our seriousness, we will decrypt you one file for free. Just open our website, upload the encrypted file and get the decrypted file for free. -- Steps to get access on our website: 1.Download and install tor-browser: https://torproject.org/ 2.Open our website: pb36hu4spl6cyjdfhing7h3pw6dhpk32ifemawkujj4gp33ejzdq3did.onion If the website is not available, open another one: rnfdsgm6wb6j6su5txkekw4u4y47kp2eatvu7d6xhyn5cs4lt4pdrqqd.onion 3.Put your personal code in the input form: {code_ff4619: cUKoUMD2ZvOihvw/J/LCR50+hydh1ULiPJKDuXRmn+2DbZMQeK uSxmHXRvpmgNPaE9d2Z/KbdCUit+mE7qK/ZaT5rCMfJ6I2NPbn h+gUl/1hA+Rm42GYsJYLOiLdhEvBeazcpavfsQmcPMZXZH5lh1 VhtfRqkFLxIrHkLA4IhW/VE6Cr8rfdrRS2QZh5XrzUS5Xf14a+ KdPpY+2DT5SZO6dP8Qc2X9bIX11cydfe00eJe7mTzPFp9CYtXe 6n38vCehE7bF9/nrG1NONgs1pk2sd/5Pylwd80jA==}
offset: 0
success 0 0
1619948428.477148
NtWriteFile
file_handle: 0x00001e7c
filepath: C:\ProgramData\Microsoft\IlsCache\FF4619-Readme.txt
buffer: Hi! Your files are encrypted by Netwalker. All encrypted files for this computer has extension: .ff4619 -- If for some reason you read this text before the encryption ended, this can be understood by the fact that the computer slows down, and your heart rate has increased due to the ability to turn it off, then we recommend that you move away from the computer and accept that you have been compromised. Rebooting/shutdown will cause you to lose files without the possibility of recovery. -- Our encryption algorithms are very strong and your files are very well protected, the only way to get your files back is to cooperate with us and get the decrypter program. Do not try to recover your files without a decrypter program, you may damage them and then they will be impossible to recover. For us this is just business and to prove to you our seriousness, we will decrypt you one file for free. Just open our website, upload the encrypted file and get the decrypted file for free. -- Steps to get access on our website: 1.Download and install tor-browser: https://torproject.org/ 2.Open our website: pb36hu4spl6cyjdfhing7h3pw6dhpk32ifemawkujj4gp33ejzdq3did.onion If the website is not available, open another one: rnfdsgm6wb6j6su5txkekw4u4y47kp2eatvu7d6xhyn5cs4lt4pdrqqd.onion 3.Put your personal code in the input form: {code_ff4619: cUKoUMD2ZvOihvw/J/LCR50+hydh1ULiPJKDuXRmn+2DbZMQeK uSxmHXRvpmgNPaE9d2Z/KbdCUit+mE7qK/ZaT5rCMfJ6I2NPbn h+gUl/1hA+Rm42GYsJYLOiLdhEvBeazcpavfsQmcPMZXZH5lh1 VhtfRqkFLxIrHkLA4IhW/VE6Cr8rfdrRS2QZh5XrzUS5Xf14a+ KdPpY+2DT5SZO6dP8Qc2X9bIX11cydfe00eJe7mTzPFp9CYtXe 6n38vCehE7bF9/nrG1NONgs1pk2sd/5Pylwd80jA==}
offset: 0
success 0 0
1619948428.509148
NtWriteFile
file_handle: 0x00000998
filepath: C:\ProgramData\Microsoft\RAC\StateData\FF4619-Readme.txt
buffer: Hi! Your files are encrypted by Netwalker. All encrypted files for this computer has extension: .ff4619 -- If for some reason you read this text before the encryption ended, this can be understood by the fact that the computer slows down, and your heart rate has increased due to the ability to turn it off, then we recommend that you move away from the computer and accept that you have been compromised. Rebooting/shutdown will cause you to lose files without the possibility of recovery. -- Our encryption algorithms are very strong and your files are very well protected, the only way to get your files back is to cooperate with us and get the decrypter program. Do not try to recover your files without a decrypter program, you may damage them and then they will be impossible to recover. For us this is just business and to prove to you our seriousness, we will decrypt you one file for free. Just open our website, upload the encrypted file and get the decrypted file for free. -- Steps to get access on our website: 1.Download and install tor-browser: https://torproject.org/ 2.Open our website: pb36hu4spl6cyjdfhing7h3pw6dhpk32ifemawkujj4gp33ejzdq3did.onion If the website is not available, open another one: rnfdsgm6wb6j6su5txkekw4u4y47kp2eatvu7d6xhyn5cs4lt4pdrqqd.onion 3.Put your personal code in the input form: {code_ff4619: cUKoUMD2ZvOihvw/J/LCR50+hydh1ULiPJKDuXRmn+2DbZMQeK uSxmHXRvpmgNPaE9d2Z/KbdCUit+mE7qK/ZaT5rCMfJ6I2NPbn h+gUl/1hA+Rm42GYsJYLOiLdhEvBeazcpavfsQmcPMZXZH5lh1 VhtfRqkFLxIrHkLA4IhW/VE6Cr8rfdrRS2QZh5XrzUS5Xf14a+ KdPpY+2DT5SZO6dP8Qc2X9bIX11cydfe00eJe7mTzPFp9CYtXe 6n38vCehE7bF9/nrG1NONgs1pk2sd/5Pylwd80jA==}
offset: 0
success 0 0
1619948428.587148
NtWriteFile
file_handle: 0x00001e60
filepath: C:\Program Files\MSBuild\Microsoft\Windows Workflow Foundation\v3.0\FF4619-Readme.txt
buffer: Hi! Your files are encrypted by Netwalker. All encrypted files for this computer has extension: .ff4619 -- If for some reason you read this text before the encryption ended, this can be understood by the fact that the computer slows down, and your heart rate has increased due to the ability to turn it off, then we recommend that you move away from the computer and accept that you have been compromised. Rebooting/shutdown will cause you to lose files without the possibility of recovery. -- Our encryption algorithms are very strong and your files are very well protected, the only way to get your files back is to cooperate with us and get the decrypter program. Do not try to recover your files without a decrypter program, you may damage them and then they will be impossible to recover. For us this is just business and to prove to you our seriousness, we will decrypt you one file for free. Just open our website, upload the encrypted file and get the decrypted file for free. -- Steps to get access on our website: 1.Download and install tor-browser: https://torproject.org/ 2.Open our website: pb36hu4spl6cyjdfhing7h3pw6dhpk32ifemawkujj4gp33ejzdq3did.onion If the website is not available, open another one: rnfdsgm6wb6j6su5txkekw4u4y47kp2eatvu7d6xhyn5cs4lt4pdrqqd.onion 3.Put your personal code in the input form: {code_ff4619: cUKoUMD2ZvOihvw/J/LCR50+hydh1ULiPJKDuXRmn+2DbZMQeK uSxmHXRvpmgNPaE9d2Z/KbdCUit+mE7qK/ZaT5rCMfJ6I2NPbn h+gUl/1hA+Rm42GYsJYLOiLdhEvBeazcpavfsQmcPMZXZH5lh1 VhtfRqkFLxIrHkLA4IhW/VE6Cr8rfdrRS2QZh5XrzUS5Xf14a+ KdPpY+2DT5SZO6dP8Qc2X9bIX11cydfe00eJe7mTzPFp9CYtXe 6n38vCehE7bF9/nrG1NONgs1pk2sd/5Pylwd80jA==}
offset: 0
success 0 0
1619948428.602148
NtWriteFile
file_handle: 0x000016dc
filepath: C:\Program Files\Reference Assemblies\Microsoft\Framework\v3.0\FF4619-Readme.txt
buffer: Hi! Your files are encrypted by Netwalker. All encrypted files for this computer has extension: .ff4619 -- If for some reason you read this text before the encryption ended, this can be understood by the fact that the computer slows down, and your heart rate has increased due to the ability to turn it off, then we recommend that you move away from the computer and accept that you have been compromised. Rebooting/shutdown will cause you to lose files without the possibility of recovery. -- Our encryption algorithms are very strong and your files are very well protected, the only way to get your files back is to cooperate with us and get the decrypter program. Do not try to recover your files without a decrypter program, you may damage them and then they will be impossible to recover. For us this is just business and to prove to you our seriousness, we will decrypt you one file for free. Just open our website, upload the encrypted file and get the decrypted file for free. -- Steps to get access on our website: 1.Download and install tor-browser: https://torproject.org/ 2.Open our website: pb36hu4spl6cyjdfhing7h3pw6dhpk32ifemawkujj4gp33ejzdq3did.onion If the website is not available, open another one: rnfdsgm6wb6j6su5txkekw4u4y47kp2eatvu7d6xhyn5cs4lt4pdrqqd.onion 3.Put your personal code in the input form: {code_ff4619: cUKoUMD2ZvOihvw/J/LCR50+hydh1ULiPJKDuXRmn+2DbZMQeK uSxmHXRvpmgNPaE9d2Z/KbdCUit+mE7qK/ZaT5rCMfJ6I2NPbn h+gUl/1hA+Rm42GYsJYLOiLdhEvBeazcpavfsQmcPMZXZH5lh1 VhtfRqkFLxIrHkLA4IhW/VE6Cr8rfdrRS2QZh5XrzUS5Xf14a+ KdPpY+2DT5SZO6dP8Qc2X9bIX11cydfe00eJe7mTzPFp9CYtXe 6n38vCehE7bF9/nrG1NONgs1pk2sd/5Pylwd80jA==}
offset: 0
success 0 0
1619948429.306148
NtWriteFile
file_handle: 0x0000174c
filepath: C:\Program Files\Google\Chrome\Application\89.0.4389.114\Installer\FF4619-Readme.txt
buffer: Hi! Your files are encrypted by Netwalker. All encrypted files for this computer has extension: .ff4619 -- If for some reason you read this text before the encryption ended, this can be understood by the fact that the computer slows down, and your heart rate has increased due to the ability to turn it off, then we recommend that you move away from the computer and accept that you have been compromised. Rebooting/shutdown will cause you to lose files without the possibility of recovery. -- Our encryption algorithms are very strong and your files are very well protected, the only way to get your files back is to cooperate with us and get the decrypter program. Do not try to recover your files without a decrypter program, you may damage them and then they will be impossible to recover. For us this is just business and to prove to you our seriousness, we will decrypt you one file for free. Just open our website, upload the encrypted file and get the decrypted file for free. -- Steps to get access on our website: 1.Download and install tor-browser: https://torproject.org/ 2.Open our website: pb36hu4spl6cyjdfhing7h3pw6dhpk32ifemawkujj4gp33ejzdq3did.onion If the website is not available, open another one: rnfdsgm6wb6j6su5txkekw4u4y47kp2eatvu7d6xhyn5cs4lt4pdrqqd.onion 3.Put your personal code in the input form: {code_ff4619: cUKoUMD2ZvOihvw/J/LCR50+hydh1ULiPJKDuXRmn+2DbZMQeK uSxmHXRvpmgNPaE9d2Z/KbdCUit+mE7qK/ZaT5rCMfJ6I2NPbn h+gUl/1hA+Rm42GYsJYLOiLdhEvBeazcpavfsQmcPMZXZH5lh1 VhtfRqkFLxIrHkLA4IhW/VE6Cr8rfdrRS2QZh5XrzUS5Xf14a+ KdPpY+2DT5SZO6dP8Qc2X9bIX11cydfe00eJe7mTzPFp9CYtXe 6n38vCehE7bF9/nrG1NONgs1pk2sd/5Pylwd80jA==}
offset: 0
success 0 0
1619948429.352148
NtWriteFile
file_handle: 0x00001fb0
filepath: C:\ProgramData\Microsoft\Crypto\Keys\FF4619-Readme.txt
buffer: Hi! Your files are encrypted by Netwalker. All encrypted files for this computer has extension: .ff4619 -- If for some reason you read this text before the encryption ended, this can be understood by the fact that the computer slows down, and your heart rate has increased due to the ability to turn it off, then we recommend that you move away from the computer and accept that you have been compromised. Rebooting/shutdown will cause you to lose files without the possibility of recovery. -- Our encryption algorithms are very strong and your files are very well protected, the only way to get your files back is to cooperate with us and get the decrypter program. Do not try to recover your files without a decrypter program, you may damage them and then they will be impossible to recover. For us this is just business and to prove to you our seriousness, we will decrypt you one file for free. Just open our website, upload the encrypted file and get the decrypted file for free. -- Steps to get access on our website: 1.Download and install tor-browser: https://torproject.org/ 2.Open our website: pb36hu4spl6cyjdfhing7h3pw6dhpk32ifemawkujj4gp33ejzdq3did.onion If the website is not available, open another one: rnfdsgm6wb6j6su5txkekw4u4y47kp2eatvu7d6xhyn5cs4lt4pdrqqd.onion 3.Put your personal code in the input form: {code_ff4619: cUKoUMD2ZvOihvw/J/LCR50+hydh1ULiPJKDuXRmn+2DbZMQeK uSxmHXRvpmgNPaE9d2Z/KbdCUit+mE7qK/ZaT5rCMfJ6I2NPbn h+gUl/1hA+Rm42GYsJYLOiLdhEvBeazcpavfsQmcPMZXZH5lh1 VhtfRqkFLxIrHkLA4IhW/VE6Cr8rfdrRS2QZh5XrzUS5Xf14a+ KdPpY+2DT5SZO6dP8Qc2X9bIX11cydfe00eJe7mTzPFp9CYtXe 6n38vCehE7bF9/nrG1NONgs1pk2sd/5Pylwd80jA==}
offset: 0
success 0 0
1619948429.352148
NtWriteFile
file_handle: 0x00001e98
filepath: C:\Users\Administrator.Oskar-PC\Contacts\FF4619-Readme.txt
buffer: Hi! Your files are encrypted by Netwalker. All encrypted files for this computer has extension: .ff4619 -- If for some reason you read this text before the encryption ended, this can be understood by the fact that the computer slows down, and your heart rate has increased due to the ability to turn it off, then we recommend that you move away from the computer and accept that you have been compromised. Rebooting/shutdown will cause you to lose files without the possibility of recovery. -- Our encryption algorithms are very strong and your files are very well protected, the only way to get your files back is to cooperate with us and get the decrypter program. Do not try to recover your files without a decrypter program, you may damage them and then they will be impossible to recover. For us this is just business and to prove to you our seriousness, we will decrypt you one file for free. Just open our website, upload the encrypted file and get the decrypted file for free. -- Steps to get access on our website: 1.Download and install tor-browser: https://torproject.org/ 2.Open our website: pb36hu4spl6cyjdfhing7h3pw6dhpk32ifemawkujj4gp33ejzdq3did.onion If the website is not available, open another one: rnfdsgm6wb6j6su5txkekw4u4y47kp2eatvu7d6xhyn5cs4lt4pdrqqd.onion 3.Put your personal code in the input form: {code_ff4619: cUKoUMD2ZvOihvw/J/LCR50+hydh1ULiPJKDuXRmn+2DbZMQeK uSxmHXRvpmgNPaE9d2Z/KbdCUit+mE7qK/ZaT5rCMfJ6I2NPbn h+gUl/1hA+Rm42GYsJYLOiLdhEvBeazcpavfsQmcPMZXZH5lh1 VhtfRqkFLxIrHkLA4IhW/VE6Cr8rfdrRS2QZh5XrzUS5Xf14a+ KdPpY+2DT5SZO6dP8Qc2X9bIX11cydfe00eJe7mTzPFp9CYtXe 6n38vCehE7bF9/nrG1NONgs1pk2sd/5Pylwd80jA==}
offset: 0
success 0 0
1619948429.352148
NtWriteFile
file_handle: 0x00001ec4
filepath: C:\Users\Administrator.Oskar-PC\Searches\FF4619-Readme.txt
buffer: Hi! Your files are encrypted by Netwalker. All encrypted files for this computer has extension: .ff4619 -- If for some reason you read this text before the encryption ended, this can be understood by the fact that the computer slows down, and your heart rate has increased due to the ability to turn it off, then we recommend that you move away from the computer and accept that you have been compromised. Rebooting/shutdown will cause you to lose files without the possibility of recovery. -- Our encryption algorithms are very strong and your files are very well protected, the only way to get your files back is to cooperate with us and get the decrypter program. Do not try to recover your files without a decrypter program, you may damage them and then they will be impossible to recover. For us this is just business and to prove to you our seriousness, we will decrypt you one file for free. Just open our website, upload the encrypted file and get the decrypted file for free. -- Steps to get access on our website: 1.Download and install tor-browser: https://torproject.org/ 2.Open our website: pb36hu4spl6cyjdfhing7h3pw6dhpk32ifemawkujj4gp33ejzdq3did.onion If the website is not available, open another one: rnfdsgm6wb6j6su5txkekw4u4y47kp2eatvu7d6xhyn5cs4lt4pdrqqd.onion 3.Put your personal code in the input form: {code_ff4619: cUKoUMD2ZvOihvw/J/LCR50+hydh1ULiPJKDuXRmn+2DbZMQeK uSxmHXRvpmgNPaE9d2Z/KbdCUit+mE7qK/ZaT5rCMfJ6I2NPbn h+gUl/1hA+Rm42GYsJYLOiLdhEvBeazcpavfsQmcPMZXZH5lh1 VhtfRqkFLxIrHkLA4IhW/VE6Cr8rfdrRS2QZh5XrzUS5Xf14a+ KdPpY+2DT5SZO6dP8Qc2X9bIX11cydfe00eJe7mTzPFp9CYtXe 6n38vCehE7bF9/nrG1NONgs1pk2sd/5Pylwd80jA==}
offset: 0
success 0 0
1619948429.446148
NtWriteFile
file_handle: 0x000006e0
filepath: C:\Program Files\Google\Chrome\Application\SetupMetrics\FF4619-Readme.txt
buffer: Hi! Your files are encrypted by Netwalker. All encrypted files for this computer has extension: .ff4619 -- If for some reason you read this text before the encryption ended, this can be understood by the fact that the computer slows down, and your heart rate has increased due to the ability to turn it off, then we recommend that you move away from the computer and accept that you have been compromised. Rebooting/shutdown will cause you to lose files without the possibility of recovery. -- Our encryption algorithms are very strong and your files are very well protected, the only way to get your files back is to cooperate with us and get the decrypter program. Do not try to recover your files without a decrypter program, you may damage them and then they will be impossible to recover. For us this is just business and to prove to you our seriousness, we will decrypt you one file for free. Just open our website, upload the encrypted file and get the decrypted file for free. -- Steps to get access on our website: 1.Download and install tor-browser: https://torproject.org/ 2.Open our website: pb36hu4spl6cyjdfhing7h3pw6dhpk32ifemawkujj4gp33ejzdq3did.onion If the website is not available, open another one: rnfdsgm6wb6j6su5txkekw4u4y47kp2eatvu7d6xhyn5cs4lt4pdrqqd.onion 3.Put your personal code in the input form: {code_ff4619: cUKoUMD2ZvOihvw/J/LCR50+hydh1ULiPJKDuXRmn+2DbZMQeK uSxmHXRvpmgNPaE9d2Z/KbdCUit+mE7qK/ZaT5rCMfJ6I2NPbn h+gUl/1hA+Rm42GYsJYLOiLdhEvBeazcpavfsQmcPMZXZH5lh1 VhtfRqkFLxIrHkLA4IhW/VE6Cr8rfdrRS2QZh5XrzUS5Xf14a+ KdPpY+2DT5SZO6dP8Qc2X9bIX11cydfe00eJe7mTzPFp9CYtXe 6n38vCehE7bF9/nrG1NONgs1pk2sd/5Pylwd80jA==}
offset: 0
success 0 0
1619948429.634148
NtWriteFile
file_handle: 0x00001054
filepath: C:\Program Files (x86)\Reference Assemblies\Microsoft\Framework\v3.0\FF4619-Readme.txt
buffer: Hi! Your files are encrypted by Netwalker. All encrypted files for this computer has extension: .ff4619 -- If for some reason you read this text before the encryption ended, this can be understood by the fact that the computer slows down, and your heart rate has increased due to the ability to turn it off, then we recommend that you move away from the computer and accept that you have been compromised. Rebooting/shutdown will cause you to lose files without the possibility of recovery. -- Our encryption algorithms are very strong and your files are very well protected, the only way to get your files back is to cooperate with us and get the decrypter program. Do not try to recover your files without a decrypter program, you may damage them and then they will be impossible to recover. For us this is just business and to prove to you our seriousness, we will decrypt you one file for free. Just open our website, upload the encrypted file and get the decrypted file for free. -- Steps to get access on our website: 1.Download and install tor-browser: https://torproject.org/ 2.Open our website: pb36hu4spl6cyjdfhing7h3pw6dhpk32ifemawkujj4gp33ejzdq3did.onion If the website is not available, open another one: rnfdsgm6wb6j6su5txkekw4u4y47kp2eatvu7d6xhyn5cs4lt4pdrqqd.onion 3.Put your personal code in the input form: {code_ff4619: cUKoUMD2ZvOihvw/J/LCR50+hydh1ULiPJKDuXRmn+2DbZMQeK uSxmHXRvpmgNPaE9d2Z/KbdCUit+mE7qK/ZaT5rCMfJ6I2NPbn h+gUl/1hA+Rm42GYsJYLOiLdhEvBeazcpavfsQmcPMZXZH5lh1 VhtfRqkFLxIrHkLA4IhW/VE6Cr8rfdrRS2QZh5XrzUS5Xf14a+ KdPpY+2DT5SZO6dP8Qc2X9bIX11cydfe00eJe7mTzPFp9CYtXe 6n38vCehE7bF9/nrG1NONgs1pk2sd/5Pylwd80jA==}
offset: 0
success 0 0
1619948429.649148
NtWriteFile
file_handle: 0x00001e60
filepath: C:\ProgramData\Microsoft\Windows\DRM\FF4619-Readme.txt
buffer: Hi! Your files are encrypted by Netwalker. All encrypted files for this computer has extension: .ff4619 -- If for some reason you read this text before the encryption ended, this can be understood by the fact that the computer slows down, and your heart rate has increased due to the ability to turn it off, then we recommend that you move away from the computer and accept that you have been compromised. Rebooting/shutdown will cause you to lose files without the possibility of recovery. -- Our encryption algorithms are very strong and your files are very well protected, the only way to get your files back is to cooperate with us and get the decrypter program. Do not try to recover your files without a decrypter program, you may damage them and then they will be impossible to recover. For us this is just business and to prove to you our seriousness, we will decrypt you one file for free. Just open our website, upload the encrypted file and get the decrypted file for free. -- Steps to get access on our website: 1.Download and install tor-browser: https://torproject.org/ 2.Open our website: pb36hu4spl6cyjdfhing7h3pw6dhpk32ifemawkujj4gp33ejzdq3did.onion If the website is not available, open another one: rnfdsgm6wb6j6su5txkekw4u4y47kp2eatvu7d6xhyn5cs4lt4pdrqqd.onion 3.Put your personal code in the input form: {code_ff4619: cUKoUMD2ZvOihvw/J/LCR50+hydh1ULiPJKDuXRmn+2DbZMQeK uSxmHXRvpmgNPaE9d2Z/KbdCUit+mE7qK/ZaT5rCMfJ6I2NPbn h+gUl/1hA+Rm42GYsJYLOiLdhEvBeazcpavfsQmcPMZXZH5lh1 VhtfRqkFLxIrHkLA4IhW/VE6Cr8rfdrRS2QZh5XrzUS5Xf14a+ KdPpY+2DT5SZO6dP8Qc2X9bIX11cydfe00eJe7mTzPFp9CYtXe 6n38vCehE7bF9/nrG1NONgs1pk2sd/5Pylwd80jA==}
offset: 0
success 0 0
1619948429.712148
NtWriteFile
file_handle: 0x0000102c
filepath: C:\Program Files\Reference Assemblies\Microsoft\Framework\v3.0\RedistList\FF4619-Readme.txt
buffer: Hi! Your files are encrypted by Netwalker. All encrypted files for this computer has extension: .ff4619 -- If for some reason you read this text before the encryption ended, this can be understood by the fact that the computer slows down, and your heart rate has increased due to the ability to turn it off, then we recommend that you move away from the computer and accept that you have been compromised. Rebooting/shutdown will cause you to lose files without the possibility of recovery. -- Our encryption algorithms are very strong and your files are very well protected, the only way to get your files back is to cooperate with us and get the decrypter program. Do not try to recover your files without a decrypter program, you may damage them and then they will be impossible to recover. For us this is just business and to prove to you our seriousness, we will decrypt you one file for free. Just open our website, upload the encrypted file and get the decrypted file for free. -- Steps to get access on our website: 1.Download and install tor-browser: https://torproject.org/ 2.Open our website: pb36hu4spl6cyjdfhing7h3pw6dhpk32ifemawkujj4gp33ejzdq3did.onion If the website is not available, open another one: rnfdsgm6wb6j6su5txkekw4u4y47kp2eatvu7d6xhyn5cs4lt4pdrqqd.onion 3.Put your personal code in the input form: {code_ff4619: cUKoUMD2ZvOihvw/J/LCR50+hydh1ULiPJKDuXRmn+2DbZMQeK uSxmHXRvpmgNPaE9d2Z/KbdCUit+mE7qK/ZaT5rCMfJ6I2NPbn h+gUl/1hA+Rm42GYsJYLOiLdhEvBeazcpavfsQmcPMZXZH5lh1 VhtfRqkFLxIrHkLA4IhW/VE6Cr8rfdrRS2QZh5XrzUS5Xf14a+ KdPpY+2DT5SZO6dP8Qc2X9bIX11cydfe00eJe7mTzPFp9CYtXe 6n38vCehE7bF9/nrG1NONgs1pk2sd/5Pylwd80jA==}
offset: 0
success 0 0
1619948429.759148
NtWriteFile
file_handle: 0x00001578
filepath: C:\ProgramData\Microsoft\Vault\AC658CB4-9126-49BD-B877-31EEDAB3F204\FF4619-Readme.txt
buffer: Hi! Your files are encrypted by Netwalker. All encrypted files for this computer has extension: .ff4619 -- If for some reason you read this text before the encryption ended, this can be understood by the fact that the computer slows down, and your heart rate has increased due to the ability to turn it off, then we recommend that you move away from the computer and accept that you have been compromised. Rebooting/shutdown will cause you to lose files without the possibility of recovery. -- Our encryption algorithms are very strong and your files are very well protected, the only way to get your files back is to cooperate with us and get the decrypter program. Do not try to recover your files without a decrypter program, you may damage them and then they will be impossible to recover. For us this is just business and to prove to you our seriousness, we will decrypt you one file for free. Just open our website, upload the encrypted file and get the decrypted file for free. -- Steps to get access on our website: 1.Download and install tor-browser: https://torproject.org/ 2.Open our website: pb36hu4spl6cyjdfhing7h3pw6dhpk32ifemawkujj4gp33ejzdq3did.onion If the website is not available, open another one: rnfdsgm6wb6j6su5txkekw4u4y47kp2eatvu7d6xhyn5cs4lt4pdrqqd.onion 3.Put your personal code in the input form: {code_ff4619: cUKoUMD2ZvOihvw/J/LCR50+hydh1ULiPJKDuXRmn+2DbZMQeK uSxmHXRvpmgNPaE9d2Z/KbdCUit+mE7qK/ZaT5rCMfJ6I2NPbn h+gUl/1hA+Rm42GYsJYLOiLdhEvBeazcpavfsQmcPMZXZH5lh1 VhtfRqkFLxIrHkLA4IhW/VE6Cr8rfdrRS2QZh5XrzUS5Xf14a+ KdPpY+2DT5SZO6dP8Qc2X9bIX11cydfe00eJe7mTzPFp9CYtXe 6n38vCehE7bF9/nrG1NONgs1pk2sd/5Pylwd80jA==}
offset: 0
success 0 0
1619948429.790148
NtWriteFile
file_handle: 0x00001588
filepath: C:\tmpsij43m\lib\api\FF4619-Readme.txt
buffer: Hi! Your files are encrypted by Netwalker. All encrypted files for this computer has extension: .ff4619 -- If for some reason you read this text before the encryption ended, this can be understood by the fact that the computer slows down, and your heart rate has increased due to the ability to turn it off, then we recommend that you move away from the computer and accept that you have been compromised. Rebooting/shutdown will cause you to lose files without the possibility of recovery. -- Our encryption algorithms are very strong and your files are very well protected, the only way to get your files back is to cooperate with us and get the decrypter program. Do not try to recover your files without a decrypter program, you may damage them and then they will be impossible to recover. For us this is just business and to prove to you our seriousness, we will decrypt you one file for free. Just open our website, upload the encrypted file and get the decrypted file for free. -- Steps to get access on our website: 1.Download and install tor-browser: https://torproject.org/ 2.Open our website: pb36hu4spl6cyjdfhing7h3pw6dhpk32ifemawkujj4gp33ejzdq3did.onion If the website is not available, open another one: rnfdsgm6wb6j6su5txkekw4u4y47kp2eatvu7d6xhyn5cs4lt4pdrqqd.onion 3.Put your personal code in the input form: {code_ff4619: cUKoUMD2ZvOihvw/J/LCR50+hydh1ULiPJKDuXRmn+2DbZMQeK uSxmHXRvpmgNPaE9d2Z/KbdCUit+mE7qK/ZaT5rCMfJ6I2NPbn h+gUl/1hA+Rm42GYsJYLOiLdhEvBeazcpavfsQmcPMZXZH5lh1 VhtfRqkFLxIrHkLA4IhW/VE6Cr8rfdrRS2QZh5XrzUS5Xf14a+ KdPpY+2DT5SZO6dP8Qc2X9bIX11cydfe00eJe7mTzPFp9CYtXe 6n38vCehE7bF9/nrG1NONgs1pk2sd/5Pylwd80jA==}
offset: 0
success 0 0
1619948429.821148
NtWriteFile
file_handle: 0x00000858
filepath: C:\Users\Public\Videos\Sample Videos\FF4619-Readme.txt
buffer: Hi! Your files are encrypted by Netwalker. All encrypted files for this computer has extension: .ff4619 -- If for some reason you read this text before the encryption ended, this can be understood by the fact that the computer slows down, and your heart rate has increased due to the ability to turn it off, then we recommend that you move away from the computer and accept that you have been compromised. Rebooting/shutdown will cause you to lose files without the possibility of recovery. -- Our encryption algorithms are very strong and your files are very well protected, the only way to get your files back is to cooperate with us and get the decrypter program. Do not try to recover your files without a decrypter program, you may damage them and then they will be impossible to recover. For us this is just business and to prove to you our seriousness, we will decrypt you one file for free. Just open our website, upload the encrypted file and get the decrypted file for free. -- Steps to get access on our website: 1.Download and install tor-browser: https://torproject.org/ 2.Open our website: pb36hu4spl6cyjdfhing7h3pw6dhpk32ifemawkujj4gp33ejzdq3did.onion If the website is not available, open another one: rnfdsgm6wb6j6su5txkekw4u4y47kp2eatvu7d6xhyn5cs4lt4pdrqqd.onion 3.Put your personal code in the input form: {code_ff4619: cUKoUMD2ZvOihvw/J/LCR50+hydh1ULiPJKDuXRmn+2DbZMQeK uSxmHXRvpmgNPaE9d2Z/KbdCUit+mE7qK/ZaT5rCMfJ6I2NPbn h+gUl/1hA+Rm42GYsJYLOiLdhEvBeazcpavfsQmcPMZXZH5lh1 VhtfRqkFLxIrHkLA4IhW/VE6Cr8rfdrRS2QZh5XrzUS5Xf14a+ KdPpY+2DT5SZO6dP8Qc2X9bIX11cydfe00eJe7mTzPFp9CYtXe 6n38vCehE7bF9/nrG1NONgs1pk2sd/5Pylwd80jA==}
offset: 0
success 0 0
1619948429.946148
NtWriteFile
file_handle: 0x000002f8
filepath: C:\Program Files\Google\Chrome\Application\89.0.4389.114\WidevineCdm\FF4619-Readme.txt
buffer: Hi! Your files are encrypted by Netwalker. All encrypted files for this computer has extension: .ff4619 -- If for some reason you read this text before the encryption ended, this can be understood by the fact that the computer slows down, and your heart rate has increased due to the ability to turn it off, then we recommend that you move away from the computer and accept that you have been compromised. Rebooting/shutdown will cause you to lose files without the possibility of recovery. -- Our encryption algorithms are very strong and your files are very well protected, the only way to get your files back is to cooperate with us and get the decrypter program. Do not try to recover your files without a decrypter program, you may damage them and then they will be impossible to recover. For us this is just business and to prove to you our seriousness, we will decrypt you one file for free. Just open our website, upload the encrypted file and get the decrypted file for free. -- Steps to get access on our website: 1.Download and install tor-browser: https://torproject.org/ 2.Open our website: pb36hu4spl6cyjdfhing7h3pw6dhpk32ifemawkujj4gp33ejzdq3did.onion If the website is not available, open another one: rnfdsgm6wb6j6su5txkekw4u4y47kp2eatvu7d6xhyn5cs4lt4pdrqqd.onion 3.Put your personal code in the input form: {code_ff4619: cUKoUMD2ZvOihvw/J/LCR50+hydh1ULiPJKDuXRmn+2DbZMQeK uSxmHXRvpmgNPaE9d2Z/KbdCUit+mE7qK/ZaT5rCMfJ6I2NPbn h+gUl/1hA+Rm42GYsJYLOiLdhEvBeazcpavfsQmcPMZXZH5lh1 VhtfRqkFLxIrHkLA4IhW/VE6Cr8rfdrRS2QZh5XrzUS5Xf14a+ KdPpY+2DT5SZO6dP8Qc2X9bIX11cydfe00eJe7mTzPFp9CYtXe 6n38vCehE7bF9/nrG1NONgs1pk2sd/5Pylwd80jA==}
offset: 0
success 0 0
1619948430.149148
NtWriteFile
file_handle: 0x00002094
filepath: C:\Users\Public\Recorded TV\Sample Media\FF4619-Readme.txt
buffer: Hi! Your files are encrypted by Netwalker. All encrypted files for this computer has extension: .ff4619 -- If for some reason you read this text before the encryption ended, this can be understood by the fact that the computer slows down, and your heart rate has increased due to the ability to turn it off, then we recommend that you move away from the computer and accept that you have been compromised. Rebooting/shutdown will cause you to lose files without the possibility of recovery. -- Our encryption algorithms are very strong and your files are very well protected, the only way to get your files back is to cooperate with us and get the decrypter program. Do not try to recover your files without a decrypter program, you may damage them and then they will be impossible to recover. For us this is just business and to prove to you our seriousness, we will decrypt you one file for free. Just open our website, upload the encrypted file and get the decrypted file for free. -- Steps to get access on our website: 1.Download and install tor-browser: https://torproject.org/ 2.Open our website: pb36hu4spl6cyjdfhing7h3pw6dhpk32ifemawkujj4gp33ejzdq3did.onion If the website is not available, open another one: rnfdsgm6wb6j6su5txkekw4u4y47kp2eatvu7d6xhyn5cs4lt4pdrqqd.onion 3.Put your personal code in the input form: {code_ff4619: cUKoUMD2ZvOihvw/J/LCR50+hydh1ULiPJKDuXRmn+2DbZMQeK uSxmHXRvpmgNPaE9d2Z/KbdCUit+mE7qK/ZaT5rCMfJ6I2NPbn h+gUl/1hA+Rm42GYsJYLOiLdhEvBeazcpavfsQmcPMZXZH5lh1 VhtfRqkFLxIrHkLA4IhW/VE6Cr8rfdrRS2QZh5XrzUS5Xf14a+ KdPpY+2DT5SZO6dP8Qc2X9bIX11cydfe00eJe7mTzPFp9CYtXe 6n38vCehE7bF9/nrG1NONgs1pk2sd/5Pylwd80jA==}
offset: 0
success 0 0
1619948430.931148
NtWriteFile
file_handle: 0x00000468
filepath: C:\Program Files\Google\Chrome\Application\89.0.4389.114\default_apps\FF4619-Readme.txt
buffer: Hi! Your files are encrypted by Netwalker. All encrypted files for this computer has extension: .ff4619 -- If for some reason you read this text before the encryption ended, this can be understood by the fact that the computer slows down, and your heart rate has increased due to the ability to turn it off, then we recommend that you move away from the computer and accept that you have been compromised. Rebooting/shutdown will cause you to lose files without the possibility of recovery. -- Our encryption algorithms are very strong and your files are very well protected, the only way to get your files back is to cooperate with us and get the decrypter program. Do not try to recover your files without a decrypter program, you may damage them and then they will be impossible to recover. For us this is just business and to prove to you our seriousness, we will decrypt you one file for free. Just open our website, upload the encrypted file and get the decrypted file for free. -- Steps to get access on our website: 1.Download and install tor-browser: https://torproject.org/ 2.Open our website: pb36hu4spl6cyjdfhing7h3pw6dhpk32ifemawkujj4gp33ejzdq3did.onion If the website is not available, open another one: rnfdsgm6wb6j6su5txkekw4u4y47kp2eatvu7d6xhyn5cs4lt4pdrqqd.onion 3.Put your personal code in the input form: {code_ff4619: cUKoUMD2ZvOihvw/J/LCR50+hydh1ULiPJKDuXRmn+2DbZMQeK uSxmHXRvpmgNPaE9d2Z/KbdCUit+mE7qK/ZaT5rCMfJ6I2NPbn h+gUl/1hA+Rm42GYsJYLOiLdhEvBeazcpavfsQmcPMZXZH5lh1 VhtfRqkFLxIrHkLA4IhW/VE6Cr8rfdrRS2QZh5XrzUS5Xf14a+ KdPpY+2DT5SZO6dP8Qc2X9bIX11cydfe00eJe7mTzPFp9CYtXe 6n38vCehE7bF9/nrG1NONgs1pk2sd/5Pylwd80jA==}
offset: 0
success 0 0
1619948431.040148
NtWriteFile
file_handle: 0x00001e60
filepath: C:\ProgramData\Microsoft\Crypto\RSA\S-1-5-18\FF4619-Readme.txt
buffer: Hi! Your files are encrypted by Netwalker. All encrypted files for this computer has extension: .ff4619 -- If for some reason you read this text before the encryption ended, this can be understood by the fact that the computer slows down, and your heart rate has increased due to the ability to turn it off, then we recommend that you move away from the computer and accept that you have been compromised. Rebooting/shutdown will cause you to lose files without the possibility of recovery. -- Our encryption algorithms are very strong and your files are very well protected, the only way to get your files back is to cooperate with us and get the decrypter program. Do not try to recover your files without a decrypter program, you may damage them and then they will be impossible to recover. For us this is just business and to prove to you our seriousness, we will decrypt you one file for free. Just open our website, upload the encrypted file and get the decrypted file for free. -- Steps to get access on our website: 1.Download and install tor-browser: https://torproject.org/ 2.Open our website: pb36hu4spl6cyjdfhing7h3pw6dhpk32ifemawkujj4gp33ejzdq3did.onion If the website is not available, open another one: rnfdsgm6wb6j6su5txkekw4u4y47kp2eatvu7d6xhyn5cs4lt4pdrqqd.onion 3.Put your personal code in the input form: {code_ff4619: cUKoUMD2ZvOihvw/J/LCR50+hydh1ULiPJKDuXRmn+2DbZMQeK uSxmHXRvpmgNPaE9d2Z/KbdCUit+mE7qK/ZaT5rCMfJ6I2NPbn h+gUl/1hA+Rm42GYsJYLOiLdhEvBeazcpavfsQmcPMZXZH5lh1 VhtfRqkFLxIrHkLA4IhW/VE6Cr8rfdrRS2QZh5XrzUS5Xf14a+ KdPpY+2DT5SZO6dP8Qc2X9bIX11cydfe00eJe7mTzPFp9CYtXe 6n38vCehE7bF9/nrG1NONgs1pk2sd/5Pylwd80jA==}
offset: 0
success 0 0
1619948431.040148
NtWriteFile
file_handle: 0x00000698
filepath: C:\Program Files (x86)\Reference Assemblies\Microsoft\Framework\v3.0\RedistList\FF4619-Readme.txt
buffer: Hi! Your files are encrypted by Netwalker. All encrypted files for this computer has extension: .ff4619 -- If for some reason you read this text before the encryption ended, this can be understood by the fact that the computer slows down, and your heart rate has increased due to the ability to turn it off, then we recommend that you move away from the computer and accept that you have been compromised. Rebooting/shutdown will cause you to lose files without the possibility of recovery. -- Our encryption algorithms are very strong and your files are very well protected, the only way to get your files back is to cooperate with us and get the decrypter program. Do not try to recover your files without a decrypter program, you may damage them and then they will be impossible to recover. For us this is just business and to prove to you our seriousness, we will decrypt you one file for free. Just open our website, upload the encrypted file and get the decrypted file for free. -- Steps to get access on our website: 1.Download and install tor-browser: https://torproject.org/ 2.Open our website: pb36hu4spl6cyjdfhing7h3pw6dhpk32ifemawkujj4gp33ejzdq3did.onion If the website is not available, open another one: rnfdsgm6wb6j6su5txkekw4u4y47kp2eatvu7d6xhyn5cs4lt4pdrqqd.onion 3.Put your personal code in the input form: {code_ff4619: cUKoUMD2ZvOihvw/J/LCR50+hydh1ULiPJKDuXRmn+2DbZMQeK uSxmHXRvpmgNPaE9d2Z/KbdCUit+mE7qK/ZaT5rCMfJ6I2NPbn h+gUl/1hA+Rm42GYsJYLOiLdhEvBeazcpavfsQmcPMZXZH5lh1 VhtfRqkFLxIrHkLA4IhW/VE6Cr8rfdrRS2QZh5XrzUS5Xf14a+ KdPpY+2DT5SZO6dP8Qc2X9bIX11cydfe00eJe7mTzPFp9CYtXe 6n38vCehE7bF9/nrG1NONgs1pk2sd/5Pylwd80jA==}
offset: 0
success 0 0
1619948431.259148
NtWriteFile
file_handle: 0x00000590
filepath: C:\Users\Public\Libraries\FF4619-Readme.txt
buffer: Hi! Your files are encrypted by Netwalker. All encrypted files for this computer has extension: .ff4619 -- If for some reason you read this text before the encryption ended, this can be understood by the fact that the computer slows down, and your heart rate has increased due to the ability to turn it off, then we recommend that you move away from the computer and accept that you have been compromised. Rebooting/shutdown will cause you to lose files without the possibility of recovery. -- Our encryption algorithms are very strong and your files are very well protected, the only way to get your files back is to cooperate with us and get the decrypter program. Do not try to recover your files without a decrypter program, you may damage them and then they will be impossible to recover. For us this is just business and to prove to you our seriousness, we will decrypt you one file for free. Just open our website, upload the encrypted file and get the decrypted file for free. -- Steps to get access on our website: 1.Download and install tor-browser: https://torproject.org/ 2.Open our website: pb36hu4spl6cyjdfhing7h3pw6dhpk32ifemawkujj4gp33ejzdq3did.onion If the website is not available, open another one: rnfdsgm6wb6j6su5txkekw4u4y47kp2eatvu7d6xhyn5cs4lt4pdrqqd.onion 3.Put your personal code in the input form: {code_ff4619: cUKoUMD2ZvOihvw/J/LCR50+hydh1ULiPJKDuXRmn+2DbZMQeK uSxmHXRvpmgNPaE9d2Z/KbdCUit+mE7qK/ZaT5rCMfJ6I2NPbn h+gUl/1hA+Rm42GYsJYLOiLdhEvBeazcpavfsQmcPMZXZH5lh1 VhtfRqkFLxIrHkLA4IhW/VE6Cr8rfdrRS2QZh5XrzUS5Xf14a+ KdPpY+2DT5SZO6dP8Qc2X9bIX11cydfe00eJe7mTzPFp9CYtXe 6n38vCehE7bF9/nrG1NONgs1pk2sd/5Pylwd80jA==}
offset: 0
success 0 0
1619948431.384148
NtWriteFile
file_handle: 0x0000031c
filepath: C:\ProgramData\Microsoft\Search\Data\Applications\Windows\GatherLogs\SystemIndex\FF4619-Readme.txt
buffer: Hi! Your files are encrypted by Netwalker. All encrypted files for this computer has extension: .ff4619 -- If for some reason you read this text before the encryption ended, this can be understood by the fact that the computer slows down, and your heart rate has increased due to the ability to turn it off, then we recommend that you move away from the computer and accept that you have been compromised. Rebooting/shutdown will cause you to lose files without the possibility of recovery. -- Our encryption algorithms are very strong and your files are very well protected, the only way to get your files back is to cooperate with us and get the decrypter program. Do not try to recover your files without a decrypter program, you may damage them and then they will be impossible to recover. For us this is just business and to prove to you our seriousness, we will decrypt you one file for free. Just open our website, upload the encrypted file and get the decrypted file for free. -- Steps to get access on our website: 1.Download and install tor-browser: https://torproject.org/ 2.Open our website: pb36hu4spl6cyjdfhing7h3pw6dhpk32ifemawkujj4gp33ejzdq3did.onion If the website is not available, open another one: rnfdsgm6wb6j6su5txkekw4u4y47kp2eatvu7d6xhyn5cs4lt4pdrqqd.onion 3.Put your personal code in the input form: {code_ff4619: cUKoUMD2ZvOihvw/J/LCR50+hydh1ULiPJKDuXRmn+2DbZMQeK uSxmHXRvpmgNPaE9d2Z/KbdCUit+mE7qK/ZaT5rCMfJ6I2NPbn h+gUl/1hA+Rm42GYsJYLOiLdhEvBeazcpavfsQmcPMZXZH5lh1 VhtfRqkFLxIrHkLA4IhW/VE6Cr8rfdrRS2QZh5XrzUS5Xf14a+ KdPpY+2DT5SZO6dP8Qc2X9bIX11cydfe00eJe7mTzPFp9CYtXe 6n38vCehE7bF9/nrG1NONgs1pk2sd/5Pylwd80jA==}
offset: 0
success 0 0
1619948432.009148
NtWriteFile
file_handle: 0x00001eb0
filepath: C:\Program Files\Google\Chrome\Application\89.0.4389.114\FF4619-Readme.txt
buffer: Hi! Your files are encrypted by Netwalker. All encrypted files for this computer has extension: .ff4619 -- If for some reason you read this text before the encryption ended, this can be understood by the fact that the computer slows down, and your heart rate has increased due to the ability to turn it off, then we recommend that you move away from the computer and accept that you have been compromised. Rebooting/shutdown will cause you to lose files without the possibility of recovery. -- Our encryption algorithms are very strong and your files are very well protected, the only way to get your files back is to cooperate with us and get the decrypter program. Do not try to recover your files without a decrypter program, you may damage them and then they will be impossible to recover. For us this is just business and to prove to you our seriousness, we will decrypt you one file for free. Just open our website, upload the encrypted file and get the decrypted file for free. -- Steps to get access on our website: 1.Download and install tor-browser: https://torproject.org/ 2.Open our website: pb36hu4spl6cyjdfhing7h3pw6dhpk32ifemawkujj4gp33ejzdq3did.onion If the website is not available, open another one: rnfdsgm6wb6j6su5txkekw4u4y47kp2eatvu7d6xhyn5cs4lt4pdrqqd.onion 3.Put your personal code in the input form: {code_ff4619: cUKoUMD2ZvOihvw/J/LCR50+hydh1ULiPJKDuXRmn+2DbZMQeK uSxmHXRvpmgNPaE9d2Z/KbdCUit+mE7qK/ZaT5rCMfJ6I2NPbn h+gUl/1hA+Rm42GYsJYLOiLdhEvBeazcpavfsQmcPMZXZH5lh1 VhtfRqkFLxIrHkLA4IhW/VE6Cr8rfdrRS2QZh5XrzUS5Xf14a+ KdPpY+2DT5SZO6dP8Qc2X9bIX11cydfe00eJe7mTzPFp9CYtXe 6n38vCehE7bF9/nrG1NONgs1pk2sd/5Pylwd80jA==}
offset: 0
success 0 0
1619948432.790148
NtWriteFile
file_handle: 0x00000198
filepath: C:\Python27\DLLs\FF4619-Readme.txt
buffer: Hi! Your files are encrypted by Netwalker. All encrypted files for this computer has extension: .ff4619 -- If for some reason you read this text before the encryption ended, this can be understood by the fact that the computer slows down, and your heart rate has increased due to the ability to turn it off, then we recommend that you move away from the computer and accept that you have been compromised. Rebooting/shutdown will cause you to lose files without the possibility of recovery. -- Our encryption algorithms are very strong and your files are very well protected, the only way to get your files back is to cooperate with us and get the decrypter program. Do not try to recover your files without a decrypter program, you may damage them and then they will be impossible to recover. For us this is just business and to prove to you our seriousness, we will decrypt you one file for free. Just open our website, upload the encrypted file and get the decrypted file for free. -- Steps to get access on our website: 1.Download and install tor-browser: https://torproject.org/ 2.Open our website: pb36hu4spl6cyjdfhing7h3pw6dhpk32ifemawkujj4gp33ejzdq3did.onion If the website is not available, open another one: rnfdsgm6wb6j6su5txkekw4u4y47kp2eatvu7d6xhyn5cs4lt4pdrqqd.onion 3.Put your personal code in the input form: {code_ff4619: cUKoUMD2ZvOihvw/J/LCR50+hydh1ULiPJKDuXRmn+2DbZMQeK uSxmHXRvpmgNPaE9d2Z/KbdCUit+mE7qK/ZaT5rCMfJ6I2NPbn h+gUl/1hA+Rm42GYsJYLOiLdhEvBeazcpavfsQmcPMZXZH5lh1 VhtfRqkFLxIrHkLA4IhW/VE6Cr8rfdrRS2QZh5XrzUS5Xf14a+ KdPpY+2DT5SZO6dP8Qc2X9bIX11cydfe00eJe7mTzPFp9CYtXe 6n38vCehE7bF9/nrG1NONgs1pk2sd/5Pylwd80jA==}
offset: 0
success 0 0
1619948433.087148
NtWriteFile
file_handle: 0x000017f4
filepath: C:\ProgramData\Microsoft\Windows\WER\ReportQueue\NonCritical_x64_d473a376adfb18a7b165c5e3c26de43cd8bccb_cab_05eac559\FF4619-Readme.txt
buffer: Hi! Your files are encrypted by Netwalker. All encrypted files for this computer has extension: .ff4619 -- If for some reason you read this text before the encryption ended, this can be understood by the fact that the computer slows down, and your heart rate has increased due to the ability to turn it off, then we recommend that you move away from the computer and accept that you have been compromised. Rebooting/shutdown will cause you to lose files without the possibility of recovery. -- Our encryption algorithms are very strong and your files are very well protected, the only way to get your files back is to cooperate with us and get the decrypter program. Do not try to recover your files without a decrypter program, you may damage them and then they will be impossible to recover. For us this is just business and to prove to you our seriousness, we will decrypt you one file for free. Just open our website, upload the encrypted file and get the decrypted file for free. -- Steps to get access on our website: 1.Download and install tor-browser: https://torproject.org/ 2.Open our website: pb36hu4spl6cyjdfhing7h3pw6dhpk32ifemawkujj4gp33ejzdq3did.onion If the website is not available, open another one: rnfdsgm6wb6j6su5txkekw4u4y47kp2eatvu7d6xhyn5cs4lt4pdrqqd.onion 3.Put your personal code in the input form: {code_ff4619: cUKoUMD2ZvOihvw/J/LCR50+hydh1ULiPJKDuXRmn+2DbZMQeK uSxmHXRvpmgNPaE9d2Z/KbdCUit+mE7qK/ZaT5rCMfJ6I2NPbn h+gUl/1hA+Rm42GYsJYLOiLdhEvBeazcpavfsQmcPMZXZH5lh1 VhtfRqkFLxIrHkLA4IhW/VE6Cr8rfdrRS2QZh5XrzUS5Xf14a+ KdPpY+2DT5SZO6dP8Qc2X9bIX11cydfe00eJe7mTzPFp9CYtXe 6n38vCehE7bF9/nrG1NONgs1pk2sd/5Pylwd80jA==}
offset: 0
success 0 0
1619948433.306148
NtWriteFile
file_handle: 0x000015d4
filepath: C:\Users\Public\Pictures\Sample Pictures\FF4619-Readme.txt
buffer: Hi! Your files are encrypted by Netwalker. All encrypted files for this computer has extension: .ff4619 -- If for some reason you read this text before the encryption ended, this can be understood by the fact that the computer slows down, and your heart rate has increased due to the ability to turn it off, then we recommend that you move away from the computer and accept that you have been compromised. Rebooting/shutdown will cause you to lose files without the possibility of recovery. -- Our encryption algorithms are very strong and your files are very well protected, the only way to get your files back is to cooperate with us and get the decrypter program. Do not try to recover your files without a decrypter program, you may damage them and then they will be impossible to recover. For us this is just business and to prove to you our seriousness, we will decrypt you one file for free. Just open our website, upload the encrypted file and get the decrypted file for free. -- Steps to get access on our website: 1.Download and install tor-browser: https://torproject.org/ 2.Open our website: pb36hu4spl6cyjdfhing7h3pw6dhpk32ifemawkujj4gp33ejzdq3did.onion If the website is not available, open another one: rnfdsgm6wb6j6su5txkekw4u4y47kp2eatvu7d6xhyn5cs4lt4pdrqqd.onion 3.Put your personal code in the input form: {code_ff4619: cUKoUMD2ZvOihvw/J/LCR50+hydh1ULiPJKDuXRmn+2DbZMQeK uSxmHXRvpmgNPaE9d2Z/KbdCUit+mE7qK/ZaT5rCMfJ6I2NPbn h+gUl/1hA+Rm42GYsJYLOiLdhEvBeazcpavfsQmcPMZXZH5lh1 VhtfRqkFLxIrHkLA4IhW/VE6Cr8rfdrRS2QZh5XrzUS5Xf14a+ KdPpY+2DT5SZO6dP8Qc2X9bIX11cydfe00eJe7mTzPFp9CYtXe 6n38vCehE7bF9/nrG1NONgs1pk2sd/5Pylwd80jA==}
offset: 0
success 0 0
1619948433.306148
NtWriteFile
file_handle: 0x000001c8
filepath: C:\Users\Public\Music\Sample Music\FF4619-Readme.txt
buffer: Hi! Your files are encrypted by Netwalker. All encrypted files for this computer has extension: .ff4619 -- If for some reason you read this text before the encryption ended, this can be understood by the fact that the computer slows down, and your heart rate has increased due to the ability to turn it off, then we recommend that you move away from the computer and accept that you have been compromised. Rebooting/shutdown will cause you to lose files without the possibility of recovery. -- Our encryption algorithms are very strong and your files are very well protected, the only way to get your files back is to cooperate with us and get the decrypter program. Do not try to recover your files without a decrypter program, you may damage them and then they will be impossible to recover. For us this is just business and to prove to you our seriousness, we will decrypt you one file for free. Just open our website, upload the encrypted file and get the decrypted file for free. -- Steps to get access on our website: 1.Download and install tor-browser: https://torproject.org/ 2.Open our website: pb36hu4spl6cyjdfhing7h3pw6dhpk32ifemawkujj4gp33ejzdq3did.onion If the website is not available, open another one: rnfdsgm6wb6j6su5txkekw4u4y47kp2eatvu7d6xhyn5cs4lt4pdrqqd.onion 3.Put your personal code in the input form: {code_ff4619: cUKoUMD2ZvOihvw/J/LCR50+hydh1ULiPJKDuXRmn+2DbZMQeK uSxmHXRvpmgNPaE9d2Z/KbdCUit+mE7qK/ZaT5rCMfJ6I2NPbn h+gUl/1hA+Rm42GYsJYLOiLdhEvBeazcpavfsQmcPMZXZH5lh1 VhtfRqkFLxIrHkLA4IhW/VE6Cr8rfdrRS2QZh5XrzUS5Xf14a+ KdPpY+2DT5SZO6dP8Qc2X9bIX11cydfe00eJe7mTzPFp9CYtXe 6n38vCehE7bF9/nrG1NONgs1pk2sd/5Pylwd80jA==}
offset: 0
success 0 0
1619948433.571148
NtWriteFile
file_handle: 0x00000afc
filepath: C:\Program Files\Google\Chrome\Application\89.0.4389.114\VisualElements\FF4619-Readme.txt
buffer: Hi! Your files are encrypted by Netwalker. All encrypted files for this computer has extension: .ff4619 -- If for some reason you read this text before the encryption ended, this can be understood by the fact that the computer slows down, and your heart rate has increased due to the ability to turn it off, then we recommend that you move away from the computer and accept that you have been compromised. Rebooting/shutdown will cause you to lose files without the possibility of recovery. -- Our encryption algorithms are very strong and your files are very well protected, the only way to get your files back is to cooperate with us and get the decrypter program. Do not try to recover your files without a decrypter program, you may damage them and then they will be impossible to recover. For us this is just business and to prove to you our seriousness, we will decrypt you one file for free. Just open our website, upload the encrypted file and get the decrypted file for free. -- Steps to get access on our website: 1.Download and install tor-browser: https://torproject.org/ 2.Open our website: pb36hu4spl6cyjdfhing7h3pw6dhpk32ifemawkujj4gp33ejzdq3did.onion If the website is not available, open another one: rnfdsgm6wb6j6su5txkekw4u4y47kp2eatvu7d6xhyn5cs4lt4pdrqqd.onion 3.Put your personal code in the input form: {code_ff4619: cUKoUMD2ZvOihvw/J/LCR50+hydh1ULiPJKDuXRmn+2DbZMQeK uSxmHXRvpmgNPaE9d2Z/KbdCUit+mE7qK/ZaT5rCMfJ6I2NPbn h+gUl/1hA+Rm42GYsJYLOiLdhEvBeazcpavfsQmcPMZXZH5lh1 VhtfRqkFLxIrHkLA4IhW/VE6Cr8rfdrRS2QZh5XrzUS5Xf14a+ KdPpY+2DT5SZO6dP8Qc2X9bIX11cydfe00eJe7mTzPFp9CYtXe 6n38vCehE7bF9/nrG1NONgs1pk2sd/5Pylwd80jA==}
offset: 0
success 0 0
1619948433.649148
NtWriteFile
file_handle: 0x00001eac
filepath: C:\tmpsij43m\lib\core\FF4619-Readme.txt
buffer: Hi! Your files are encrypted by Netwalker. All encrypted files for this computer has extension: .ff4619 -- If for some reason you read this text before the encryption ended, this can be understood by the fact that the computer slows down, and your heart rate has increased due to the ability to turn it off, then we recommend that you move away from the computer and accept that you have been compromised. Rebooting/shutdown will cause you to lose files without the possibility of recovery. -- Our encryption algorithms are very strong and your files are very well protected, the only way to get your files back is to cooperate with us and get the decrypter program. Do not try to recover your files without a decrypter program, you may damage them and then they will be impossible to recover. For us this is just business and to prove to you our seriousness, we will decrypt you one file for free. Just open our website, upload the encrypted file and get the decrypted file for free. -- Steps to get access on our website: 1.Download and install tor-browser: https://torproject.org/ 2.Open our website: pb36hu4spl6cyjdfhing7h3pw6dhpk32ifemawkujj4gp33ejzdq3did.onion If the website is not available, open another one: rnfdsgm6wb6j6su5txkekw4u4y47kp2eatvu7d6xhyn5cs4lt4pdrqqd.onion 3.Put your personal code in the input form: {code_ff4619: cUKoUMD2ZvOihvw/J/LCR50+hydh1ULiPJKDuXRmn+2DbZMQeK uSxmHXRvpmgNPaE9d2Z/KbdCUit+mE7qK/ZaT5rCMfJ6I2NPbn h+gUl/1hA+Rm42GYsJYLOiLdhEvBeazcpavfsQmcPMZXZH5lh1 VhtfRqkFLxIrHkLA4IhW/VE6Cr8rfdrRS2QZh5XrzUS5Xf14a+ KdPpY+2DT5SZO6dP8Qc2X9bIX11cydfe00eJe7mTzPFp9CYtXe 6n38vCehE7bF9/nrG1NONgs1pk2sd/5Pylwd80jA==}
offset: 0
success 0 0
1619948434.259148
NtWriteFile
file_handle: 0x00001e18
filepath: C:\ProgramData\Microsoft\Windows\WER\ReportQueue\NonCritical_x64_e44d9bd7eba8ad7f54ca160a4fc3d2a5d4c60_cab_055f7698\FF4619-Readme.txt
buffer: Hi! Your files are encrypted by Netwalker. All encrypted files for this computer has extension: .ff4619 -- If for some reason you read this text before the encryption ended, this can be understood by the fact that the computer slows down, and your heart rate has increased due to the ability to turn it off, then we recommend that you move away from the computer and accept that you have been compromised. Rebooting/shutdown will cause you to lose files without the possibility of recovery. -- Our encryption algorithms are very strong and your files are very well protected, the only way to get your files back is to cooperate with us and get the decrypter program. Do not try to recover your files without a decrypter program, you may damage them and then they will be impossible to recover. For us this is just business and to prove to you our seriousness, we will decrypt you one file for free. Just open our website, upload the encrypted file and get the decrypted file for free. -- Steps to get access on our website: 1.Download and install tor-browser: https://torproject.org/ 2.Open our website: pb36hu4spl6cyjdfhing7h3pw6dhpk32ifemawkujj4gp33ejzdq3did.onion If the website is not available, open another one: rnfdsgm6wb6j6su5txkekw4u4y47kp2eatvu7d6xhyn5cs4lt4pdrqqd.onion 3.Put your personal code in the input form: {code_ff4619: cUKoUMD2ZvOihvw/J/LCR50+hydh1ULiPJKDuXRmn+2DbZMQeK uSxmHXRvpmgNPaE9d2Z/KbdCUit+mE7qK/ZaT5rCMfJ6I2NPbn h+gUl/1hA+Rm42GYsJYLOiLdhEvBeazcpavfsQmcPMZXZH5lh1 VhtfRqkFLxIrHkLA4IhW/VE6Cr8rfdrRS2QZh5XrzUS5Xf14a+ KdPpY+2DT5SZO6dP8Qc2X9bIX11cydfe00eJe7mTzPFp9CYtXe 6n38vCehE7bF9/nrG1NONgs1pk2sd/5Pylwd80jA==}
offset: 0
success 0 0
1619948434.431148
NtWriteFile
file_handle: 0x0000171c
filepath: C:\Python27\Tools\pynche\FF4619-Readme.txt
buffer: Hi! Your files are encrypted by Netwalker. All encrypted files for this computer has extension: .ff4619 -- If for some reason you read this text before the encryption ended, this can be understood by the fact that the computer slows down, and your heart rate has increased due to the ability to turn it off, then we recommend that you move away from the computer and accept that you have been compromised. Rebooting/shutdown will cause you to lose files without the possibility of recovery. -- Our encryption algorithms are very strong and your files are very well protected, the only way to get your files back is to cooperate with us and get the decrypter program. Do not try to recover your files without a decrypter program, you may damage them and then they will be impossible to recover. For us this is just business and to prove to you our seriousness, we will decrypt you one file for free. Just open our website, upload the encrypted file and get the decrypted file for free. -- Steps to get access on our website: 1.Download and install tor-browser: https://torproject.org/ 2.Open our website: pb36hu4spl6cyjdfhing7h3pw6dhpk32ifemawkujj4gp33ejzdq3did.onion If the website is not available, open another one: rnfdsgm6wb6j6su5txkekw4u4y47kp2eatvu7d6xhyn5cs4lt4pdrqqd.onion 3.Put your personal code in the input form: {code_ff4619: cUKoUMD2ZvOihvw/J/LCR50+hydh1ULiPJKDuXRmn+2DbZMQeK uSxmHXRvpmgNPaE9d2Z/KbdCUit+mE7qK/ZaT5rCMfJ6I2NPbn h+gUl/1hA+Rm42GYsJYLOiLdhEvBeazcpavfsQmcPMZXZH5lh1 VhtfRqkFLxIrHkLA4IhW/VE6Cr8rfdrRS2QZh5XrzUS5Xf14a+ KdPpY+2DT5SZO6dP8Qc2X9bIX11cydfe00eJe7mTzPFp9CYtXe 6n38vCehE7bF9/nrG1NONgs1pk2sd/5Pylwd80jA==}
offset: 0
success 0 0
1619948434.696148
NtWriteFile
file_handle: 0x00001d10
filepath: C:\ProgramData\Microsoft\Windows\WER\ReportQueue\NonCritical_x64_94995ab25177e7c7298027ae617b93854df5_cab_0126c1cf\FF4619-Readme.txt
buffer: Hi! Your files are encrypted by Netwalker. All encrypted files for this computer has extension: .ff4619 -- If for some reason you read this text before the encryption ended, this can be understood by the fact that the computer slows down, and your heart rate has increased due to the ability to turn it off, then we recommend that you move away from the computer and accept that you have been compromised. Rebooting/shutdown will cause you to lose files without the possibility of recovery. -- Our encryption algorithms are very strong and your files are very well protected, the only way to get your files back is to cooperate with us and get the decrypter program. Do not try to recover your files without a decrypter program, you may damage them and then they will be impossible to recover. For us this is just business and to prove to you our seriousness, we will decrypt you one file for free. Just open our website, upload the encrypted file and get the decrypted file for free. -- Steps to get access on our website: 1.Download and install tor-browser: https://torproject.org/ 2.Open our website: pb36hu4spl6cyjdfhing7h3pw6dhpk32ifemawkujj4gp33ejzdq3did.onion If the website is not available, open another one: rnfdsgm6wb6j6su5txkekw4u4y47kp2eatvu7d6xhyn5cs4lt4pdrqqd.onion 3.Put your personal code in the input form: {code_ff4619: cUKoUMD2ZvOihvw/J/LCR50+hydh1ULiPJKDuXRmn+2DbZMQeK uSxmHXRvpmgNPaE9d2Z/KbdCUit+mE7qK/ZaT5rCMfJ6I2NPbn h+gUl/1hA+Rm42GYsJYLOiLdhEvBeazcpavfsQmcPMZXZH5lh1 VhtfRqkFLxIrHkLA4IhW/VE6Cr8rfdrRS2QZh5XrzUS5Xf14a+ KdPpY+2DT5SZO6dP8Qc2X9bIX11cydfe00eJe7mTzPFp9CYtXe 6n38vCehE7bF9/nrG1NONgs1pk2sd/5Pylwd80jA==}
offset: 0
success 0 0
1619948434.759148
NtWriteFile
file_handle: 0x0000102c
filepath: C:\Users\Oskar\Contacts\FF4619-Readme.txt
buffer: Hi! Your files are encrypted by Netwalker. All encrypted files for this computer has extension: .ff4619 -- If for some reason you read this text before the encryption ended, this can be understood by the fact that the computer slows down, and your heart rate has increased due to the ability to turn it off, then we recommend that you move away from the computer and accept that you have been compromised. Rebooting/shutdown will cause you to lose files without the possibility of recovery. -- Our encryption algorithms are very strong and your files are very well protected, the only way to get your files back is to cooperate with us and get the decrypter program. Do not try to recover your files without a decrypter program, you may damage them and then they will be impossible to recover. For us this is just business and to prove to you our seriousness, we will decrypt you one file for free. Just open our website, upload the encrypted file and get the decrypted file for free. -- Steps to get access on our website: 1.Download and install tor-browser: https://torproject.org/ 2.Open our website: pb36hu4spl6cyjdfhing7h3pw6dhpk32ifemawkujj4gp33ejzdq3did.onion If the website is not available, open another one: rnfdsgm6wb6j6su5txkekw4u4y47kp2eatvu7d6xhyn5cs4lt4pdrqqd.onion 3.Put your personal code in the input form: {code_ff4619: cUKoUMD2ZvOihvw/J/LCR50+hydh1ULiPJKDuXRmn+2DbZMQeK uSxmHXRvpmgNPaE9d2Z/KbdCUit+mE7qK/ZaT5rCMfJ6I2NPbn h+gUl/1hA+Rm42GYsJYLOiLdhEvBeazcpavfsQmcPMZXZH5lh1 VhtfRqkFLxIrHkLA4IhW/VE6Cr8rfdrRS2QZh5XrzUS5Xf14a+ KdPpY+2DT5SZO6dP8Qc2X9bIX11cydfe00eJe7mTzPFp9CYtXe 6n38vCehE7bF9/nrG1NONgs1pk2sd/5Pylwd80jA==}
offset: 0
success 0 0
1619948435.024148
NtWriteFile
file_handle: 0x000017f4
filepath: C:\ProgramData\Microsoft\Assistance\Client\1.0\zh-CN_en-US\FF4619-Readme.txt
buffer: Hi! Your files are encrypted by Netwalker. All encrypted files for this computer has extension: .ff4619 -- If for some reason you read this text before the encryption ended, this can be understood by the fact that the computer slows down, and your heart rate has increased due to the ability to turn it off, then we recommend that you move away from the computer and accept that you have been compromised. Rebooting/shutdown will cause you to lose files without the possibility of recovery. -- Our encryption algorithms are very strong and your files are very well protected, the only way to get your files back is to cooperate with us and get the decrypter program. Do not try to recover your files without a decrypter program, you may damage them and then they will be impossible to recover. For us this is just business and to prove to you our seriousness, we will decrypt you one file for free. Just open our website, upload the encrypted file and get the decrypted file for free. -- Steps to get access on our website: 1.Download and install tor-browser: https://torproject.org/ 2.Open our website: pb36hu4spl6cyjdfhing7h3pw6dhpk32ifemawkujj4gp33ejzdq3did.onion If the website is not available, open another one: rnfdsgm6wb6j6su5txkekw4u4y47kp2eatvu7d6xhyn5cs4lt4pdrqqd.onion 3.Put your personal code in the input form: {code_ff4619: cUKoUMD2ZvOihvw/J/LCR50+hydh1ULiPJKDuXRmn+2DbZMQeK uSxmHXRvpmgNPaE9d2Z/KbdCUit+mE7qK/ZaT5rCMfJ6I2NPbn h+gUl/1hA+Rm42GYsJYLOiLdhEvBeazcpavfsQmcPMZXZH5lh1 VhtfRqkFLxIrHkLA4IhW/VE6Cr8rfdrRS2QZh5XrzUS5Xf14a+ KdPpY+2DT5SZO6dP8Qc2X9bIX11cydfe00eJe7mTzPFp9CYtXe 6n38vCehE7bF9/nrG1NONgs1pk2sd/5Pylwd80jA==}
offset: 0
success 0 0
1619948435.165148
NtWriteFile
file_handle: 0x000016d8
filepath: C:\Users\Oskar\Favorites\Windows Live\FF4619-Readme.txt
buffer: Hi! Your files are encrypted by Netwalker. All encrypted files for this computer has extension: .ff4619 -- If for some reason you read this text before the encryption ended, this can be understood by the fact that the computer slows down, and your heart rate has increased due to the ability to turn it off, then we recommend that you move away from the computer and accept that you have been compromised. Rebooting/shutdown will cause you to lose files without the possibility of recovery. -- Our encryption algorithms are very strong and your files are very well protected, the only way to get your files back is to cooperate with us and get the decrypter program. Do not try to recover your files without a decrypter program, you may damage them and then they will be impossible to recover. For us this is just business and to prove to you our seriousness, we will decrypt you one file for free. Just open our website, upload the encrypted file and get the decrypted file for free. -- Steps to get access on our website: 1.Download and install tor-browser: https://torproject.org/ 2.Open our website: pb36hu4spl6cyjdfhing7h3pw6dhpk32ifemawkujj4gp33ejzdq3did.onion If the website is not available, open another one: rnfdsgm6wb6j6su5txkekw4u4y47kp2eatvu7d6xhyn5cs4lt4pdrqqd.onion 3.Put your personal code in the input form: {code_ff4619: cUKoUMD2ZvOihvw/J/LCR50+hydh1ULiPJKDuXRmn+2DbZMQeK uSxmHXRvpmgNPaE9d2Z/KbdCUit+mE7qK/ZaT5rCMfJ6I2NPbn h+gUl/1hA+Rm42GYsJYLOiLdhEvBeazcpavfsQmcPMZXZH5lh1 VhtfRqkFLxIrHkLA4IhW/VE6Cr8rfdrRS2QZh5XrzUS5Xf14a+ KdPpY+2DT5SZO6dP8Qc2X9bIX11cydfe00eJe7mTzPFp9CYtXe 6n38vCehE7bF9/nrG1NONgs1pk2sd/5Pylwd80jA==}
offset: 0
success 0 0
1619948435.712148
NtWriteFile
file_handle: 0x0000101c
filepath: C:\Python27\Tools\versioncheck\FF4619-Readme.txt
buffer: Hi! Your files are encrypted by Netwalker. All encrypted files for this computer has extension: .ff4619 -- If for some reason you read this text before the encryption ended, this can be understood by the fact that the computer slows down, and your heart rate has increased due to the ability to turn it off, then we recommend that you move away from the computer and accept that you have been compromised. Rebooting/shutdown will cause you to lose files without the possibility of recovery. -- Our encryption algorithms are very strong and your files are very well protected, the only way to get your files back is to cooperate with us and get the decrypter program. Do not try to recover your files without a decrypter program, you may damage them and then they will be impossible to recover. For us this is just business and to prove to you our seriousness, we will decrypt you one file for free. Just open our website, upload the encrypted file and get the decrypted file for free. -- Steps to get access on our website: 1.Download and install tor-browser: https://torproject.org/ 2.Open our website: pb36hu4spl6cyjdfhing7h3pw6dhpk32ifemawkujj4gp33ejzdq3did.onion If the website is not available, open another one: rnfdsgm6wb6j6su5txkekw4u4y47kp2eatvu7d6xhyn5cs4lt4pdrqqd.onion 3.Put your personal code in the input form: {code_ff4619: cUKoUMD2ZvOihvw/J/LCR50+hydh1ULiPJKDuXRmn+2DbZMQeK uSxmHXRvpmgNPaE9d2Z/KbdCUit+mE7qK/ZaT5rCMfJ6I2NPbn h+gUl/1hA+Rm42GYsJYLOiLdhEvBeazcpavfsQmcPMZXZH5lh1 VhtfRqkFLxIrHkLA4IhW/VE6Cr8rfdrRS2QZh5XrzUS5Xf14a+ KdPpY+2DT5SZO6dP8Qc2X9bIX11cydfe00eJe7mTzPFp9CYtXe 6n38vCehE7bF9/nrG1NONgs1pk2sd/5Pylwd80jA==}
offset: 0
success 0 0
1619948436.009148
NtWriteFile
file_handle: 0x00001c30
filepath: C:\Python27\Tools\i18n\FF4619-Readme.txt
buffer: Hi! Your files are encrypted by Netwalker. All encrypted files for this computer has extension: .ff4619 -- If for some reason you read this text before the encryption ended, this can be understood by the fact that the computer slows down, and your heart rate has increased due to the ability to turn it off, then we recommend that you move away from the computer and accept that you have been compromised. Rebooting/shutdown will cause you to lose files without the possibility of recovery. -- Our encryption algorithms are very strong and your files are very well protected, the only way to get your files back is to cooperate with us and get the decrypter program. Do not try to recover your files without a decrypter program, you may damage them and then they will be impossible to recover. For us this is just business and to prove to you our seriousness, we will decrypt you one file for free. Just open our website, upload the encrypted file and get the decrypted file for free. -- Steps to get access on our website: 1.Download and install tor-browser: https://torproject.org/ 2.Open our website: pb36hu4spl6cyjdfhing7h3pw6dhpk32ifemawkujj4gp33ejzdq3did.onion If the website is not available, open another one: rnfdsgm6wb6j6su5txkekw4u4y47kp2eatvu7d6xhyn5cs4lt4pdrqqd.onion 3.Put your personal code in the input form: {code_ff4619: cUKoUMD2ZvOihvw/J/LCR50+hydh1ULiPJKDuXRmn+2DbZMQeK uSxmHXRvpmgNPaE9d2Z/KbdCUit+mE7qK/ZaT5rCMfJ6I2NPbn h+gUl/1hA+Rm42GYsJYLOiLdhEvBeazcpavfsQmcPMZXZH5lh1 VhtfRqkFLxIrHkLA4IhW/VE6Cr8rfdrRS2QZh5XrzUS5Xf14a+ KdPpY+2DT5SZO6dP8Qc2X9bIX11cydfe00eJe7mTzPFp9CYtXe 6n38vCehE7bF9/nrG1NONgs1pk2sd/5Pylwd80jA==}
offset: 0
success 0 0
Detects VirtualBox through the presence of a file (3 个事件)
file C:\Program Files\Oracle\VirtualBox Guest Additions\VBoxGuest.cat
file C:\Program Files\Oracle\VirtualBox Guest Additions\VBoxMouse.inf
file C:\Program Files\Oracle\VirtualBox Guest Additions\VBoxVideo.inf
File has been identified by 57 AntiVirus engines on VirusTotal as malicious (50 out of 57 个事件)
Elastic malicious (high confidence)
Qihoo-360 Generic/HEUR/QVM20.1.1468.Malware.Gen
McAfee Ransom-NetW!DD4F9213BA67
Cylance Unsafe
Zillya Trojan.Filecoder.Win32.14827
Sangfor Malware
CrowdStrike win/malicious_confidence_100% (W)
Alibaba Ransom:Win32/NetWalker.8bc164b3
K7GW Trojan ( 00564c031 )
K7AntiVirus Trojan ( 00564c031 )
Cyren W32/Trojan.JKWB-3691
Symantec Downloader
ESET-NOD32 a variant of Win32/Filecoder.NetWalker.E
APEX Malicious
Paloalto generic.ml
Cynet Malicious (score: 100)
Kaspersky Trojan.Win32.Zudochka.ekc
BitDefender Gen:Variant.Razy.676626
NANO-Antivirus Virus.Win32.Gen.ccmw
MicroWorld-eScan Gen:Variant.Razy.676626
Avast Win32:Trojan-gen
Tencent Malware.Win32.Gencirc.10ce0b77
Ad-Aware Gen:Variant.Razy.676626
Sophos Mal/Generic-S
Comodo TrojWare.Win32.Ransom.NetWalker.SD@8rqqoe
F-Secure Trojan.TR/Crypt.XPACK.Gen3
DrWeb Trojan.Encoder.32721
VIPRE Trojan.Win32.Generic!BT
TrendMicro Ransom.Win32.NETWALKER.SMTH
McAfee-GW-Edition BehavesLike.Win32.VirRansom.qh
FireEye Generic.mg.dd4f9213ba67c26a
Emsisoft Gen:Variant.Razy.676626 (B)
Ikarus Trojan-Ransom.NetWalker
GData Gen:Variant.Razy.676626
Jiangmin Trojan.Zudochka.ip
Webroot W32.Trojan.Gen
Avira TR/Crypt.XPACK.Gen3
Antiy-AVL Trojan[Ransom]/Win32.NetWalker
Kingsoft Win32.Troj.Undef.(kcloud)
Gridinsoft Ransom.Win32.Ransom.oa!s1
Arcabit Trojan.Razy.DA5312
AegisLab Trojan.Win32.NetWalker.4!c
ZoneAlarm Trojan.Win32.Zudochka.ekc
Microsoft Ransom:Win32/NetWalker.H!rsm
VBA32 BScope.TrojanPSW.Spy
ALYac Trojan.Ransom.Mailto
MAX malware (ai score=100)
Malwarebytes Ransom.NetWalker
TrendMicro-HouseCall Ransom.Win32.NETWALKER.SMTH
Rising Worm.WBNA!8.321 (TFE:2:BCE85f8b73E)
可视化分析
二进制图像
暂无二进制图像 该样本未生成二进制可视化图像
运行截图
暂无运行截图 该样本运行过程中未生成截图

👋 欢迎使用 ChatHawk

我是您的恶意软件分析助手,可以帮您分析和解读恶意软件报告。请随时向我提问!

🔍 主要威胁分析
⚡ 行为特征
🛡️ 防护建议
🔧 技术手段
🎯 检测方法
🤖

PE Compile Time

2020-04-22 01:52:26

Exports

Ordinal Address Name
1 0x1000a0b0 Do

Hosts

No hosts contacted.

TCP

No TCP connections recorded.

UDP

Source Source Port Destination Destination Port
192.168.56.101 50534 114.114.114.114 53
192.168.56.101 55368 114.114.114.114 53
192.168.56.101 56539 114.114.114.114 53
192.168.56.101 65004 114.114.114.114 53
192.168.56.101 137 192.168.56.255 137
192.168.56.101 138 192.168.56.255 138
192.168.56.101 49235 224.0.0.252 5355
192.168.56.101 56804 224.0.0.252 5355
192.168.56.101 60123 224.0.0.252 5355
192.168.56.101 62191 224.0.0.252 5355
192.168.56.101 1900 239.255.255.250 1900
192.168.56.101 50535 239.255.255.250 3702
192.168.56.101 50537 239.255.255.250 3702
192.168.56.101 56807 239.255.255.250 1900
192.168.56.101 58707 239.255.255.250 3702
192.168.56.101 62192 239.255.255.250 3702

HTTP & HTTPS Requests

No HTTP requests performed.

ICMP traffic

No ICMP traffic performed.

IRC traffic

No IRC requests performed.

Suricata Alerts

No Suricata Alerts

Suricata TLS

No Suricata TLS

Snort Alerts

No Snort Alerts

Sorry! No dropped files.
Sorry! No dropped buffers.