General Info

File name

vnc.exe

Full analysis
https://app.any.run/tasks/16832474-d158-4427-a3b3-543014048950
Verdict
Malicious activity
Analysis date
11/8/2018, 21:33:38
OS:
Windows 7 Professional Service Pack 1 (build: 7601, 32 bit)
Tags:

ransomware

gandcrab

Indicators:

MIME:
application/x-dosexec
File info:
PE32 executable (GUI) Intel 80386, for MS Windows
MD5

de9ef6813f58ac0e2e822efc5ab7ad07

SHA1

3f66a2738a356f28628c7eca22f0e029894152a6

SHA256

9df6e1c2b3544ed2bdee8eba8e0c7b8672b34079686f79faeb9a4c9e49962e62

SSDEEP

1536:52YN1nS9cCY6Vbs8P+TLtXBcGVyThYhqi0sWjcdEIS3FZBq2dks4QTg12A58AQpE:xNQDVQ8ujb1hhEIS3FZBaCgrQp0Mq

ANY.RUN is an interactive service which provides full access to the guest system. Information in this report could be distored by user actions and is provided for user acknowledgement as it is. ANY.RUN does not guarantee maliciousness or safety of the content.

Software environment set and analysis options

Launch configuration

Task duration
60 seconds
Additional time used
none
Fakenet option
off
Heavy Evaision option
off
MITM proxy
off
Route via Tor
off
Network geolocation
off
Privacy
Public submission
Autoconfirmation of UAC
on

Software preset

  • Internet Explorer 8.0.7601.17514
  • Adobe Acrobat Reader DC MUI (15.023.20070)
  • Adobe Flash Player 26 ActiveX (26.0.0.131)
  • Adobe Flash Player 26 NPAPI (26.0.0.131)
  • Adobe Flash Player 26 PPAPI (26.0.0.131)
  • Adobe Refresh Manager (1.8.0)
  • CCleaner (5.35)
  • FileZilla Client 3.36.0 (3.36.0)
  • Google Chrome (68.0.3440.106)
  • Google Update Helper (1.3.33.17)
  • Java 8 Update 92 (8.0.920.14)
  • Java Auto Updater (2.8.92.14)
  • Microsoft .NET Framework 4.6.1 (4.6.01055)
  • Microsoft Office Access MUI (English) 2010 (14.0.6029.1000)
  • Microsoft Office Access Setup Metadata MUI (English) 2010 (14.0.6029.1000)
  • Microsoft Office Excel MUI (English) 2010 (14.0.6029.1000)
  • Microsoft Office OneNote MUI (English) 2010 (14.0.6029.1000)
  • Microsoft Office Outlook MUI (English) 2010 (14.0.6029.1000)
  • Microsoft Office PowerPoint MUI (English) 2010 (14.0.6029.1000)
  • Microsoft Office Professional 2010 (14.0.6029.1000)
  • Microsoft Office Proof (English) 2010 (14.0.6029.1000)
  • Microsoft Office Proof (French) 2010 (14.0.6029.1000)
  • Microsoft Office Proof (Spanish) 2010 (14.0.6029.1000)
  • Microsoft Office Proofing (English) 2010 (14.0.6029.1000)
  • Microsoft Office Publisher MUI (English) 2010 (14.0.6029.1000)
  • Microsoft Office Shared MUI (English) 2010 (14.0.6029.1000)
  • Microsoft Office Shared Setup Metadata MUI (English) 2010 (14.0.6029.1000)
  • Microsoft Office Single Image 2010 (14.0.6029.1000)
  • Microsoft Office Word MUI (English) 2010 (14.0.6029.1000)
  • Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.6161 (9.0.30729.6161)
  • Microsoft Visual C++ 2010 x86 Redistributable - 10.0.40219 (10.0.40219)
  • Microsoft Visual C++ 2013 Redistributable (x86) - 12.0.30501 (12.0.30501.0)
  • Microsoft Visual C++ 2013 x86 Additional Runtime - 12.0.21005 (12.0.21005)
  • Microsoft Visual C++ 2013 x86 Minimum Runtime - 12.0.21005 (12.0.21005)
  • Microsoft Visual C++ 2017 Redistributable (x86) - 14.15.26706 (14.15.26706.0)
  • Microsoft Visual C++ 2017 x86 Additional Runtime - 14.15.26706 (14.15.26706)
  • Microsoft Visual C++ 2017 x86 Minimum Runtime - 14.15.26706 (14.15.26706)
  • Mozilla Firefox 61.0.2 (x86 en-US) (61.0.2)
  • Notepad++ (32-bit x86) (7.5.1)
  • Opera 12.15 (12.15.1748)
  • Skype version 8.29 (8.29)
  • VLC media player (2.2.6)
  • WinRAR 5.60 (32-bit) (5.60.0)

Hotfixes

  • Client LanguagePack Package
  • Client Refresh LanguagePack Package
  • CodecPack Basic Package
  • Foundation Package
  • IE Troubleshooters Package
  • InternetExplorer Optional Package
  • KB2534111
  • KB2999226
  • KB976902
  • LocalPack AU Package
  • LocalPack CA Package
  • LocalPack GB Package
  • LocalPack US Package
  • LocalPack ZA Package
  • ProfessionalEdition
  • UltimateEdition

Behavior activities

MALICIOUS SUSPICIOUS INFO
Actions looks like stealing of personal data
  • vnc.exe (PID: 3836)
Dropped file may contain instructions of ransomware
  • vnc.exe (PID: 3836)
Renames files like Ransomware
  • vnc.exe (PID: 3836)
GandCrab keys found
  • vnc.exe (PID: 3836)
Deletes shadow copies
  • vnc.exe (PID: 3836)
Writes file to Word startup folder
  • vnc.exe (PID: 3836)
Detected GandCrab ransomware
  • vnc.exe (PID: 3836)
Creates files like Ransomware instruction
  • vnc.exe (PID: 3836)
Creates files in the user directory
  • vnc.exe (PID: 3836)
Dropped object may contain TOR URL's
  • vnc.exe (PID: 3836)

Find more information about signature artifacts and mapping to MITRE ATT&CK™ MATRIX at the full report

Static information

TRiD
.exe
|   Win32 Executable MS Visual C++ (generic) (42.2%)
.exe
|   Win64 Executable (generic) (37.3%)
.dll
|   Win32 Dynamic Link Library (generic) (8.8%)
.exe
|   Win32 Executable (generic) (6%)
.exe
|   Generic Win/DOS Executable (2.7%)
EXIF
EXE
MachineType:
Intel 386 or later, and compatibles
TimeStamp:
2018:08:01 01:51:50+02:00
PEType:
PE32
LinkerVersion:
12
CodeSize:
58880
InitializedDataSize:
78848
UninitializedDataSize:
null
EntryPoint:
0x41a1
OSVersion:
5.1
ImageVersion:
null
SubsystemVersion:
5.1
Subsystem:
Windows GUI
Summary
Architecture:
IMAGE_FILE_MACHINE_I386
Subsystem:
IMAGE_SUBSYSTEM_WINDOWS_GUI
Compilation Date:
31-Jul-2018 23:51:50
Detected languages
English - United States
DOS Header
Magic number:
MZ
Bytes on last page of file:
0x0090
Pages in file:
0x0003
Relocations:
0x0000
Size of header:
0x0004
Min extra paragraphs:
0x0000
Max extra paragraphs:
0xFFFF
Initial SS value:
0x0000
Initial SP value:
0x00B8
Checksum:
0x0000
Initial IP value:
0x0000
Initial CS value:
0x0000
Overlay number:
0x0000
OEM identifier:
0x0000
OEM information:
0x0000
Address of NE header:
0x000000F0
PE Headers
Signature:
PE
Machine:
IMAGE_FILE_MACHINE_I386
Number of sections:
5
Time date stamp:
31-Jul-2018 23:51:50
Pointer to Symbol Table:
0x00000000
Number of symbols:
0
Size of Optional Header:
0x00E0
Characteristics
IMAGE_FILE_32BIT_MACHINE
IMAGE_FILE_EXECUTABLE_IMAGE
Sections
Name Virtual Address Virtual Size Raw Size Charateristics Entropy
.text 0x00001000 0x0000E444 0x0000E600 IMAGE_SCN_CNT_CODE,IMAGE_SCN_MEM_EXECUTE,IMAGE_SCN_MEM_READ 6.59982
.rdata 0x00010000 0x00005DD2 0x00005E00 IMAGE_SCN_CNT_INITIALIZED_DATA,IMAGE_SCN_MEM_READ 4.53883
.data 0x00016000 0x0000C1F4 0x0000A600 IMAGE_SCN_CNT_INITIALIZED_DATA,IMAGE_SCN_MEM_READ,IMAGE_SCN_MEM_WRITE 4.02306
.rsrc 0x00023000 0x000001E0 0x00000200 IMAGE_SCN_CNT_INITIALIZED_DATA,IMAGE_SCN_MEM_READ 4.71134
.reloc 0x00024000 0x00001030 0x00001200 IMAGE_SCN_CNT_INITIALIZED_DATA,IMAGE_SCN_MEM_DISCARDABLE,IMAGE_SCN_MEM_READ 6.33166
Resources
1

Imports
    KERNEL32.dll

    USER32.dll

    ADVAPI32.dll

    SHELL32.dll

    MPR.dll

    WININET.dll

Exports

    No exports.

Screenshots

Processes

Total processes
35
Monitored processes
2
Malicious processes
1
Suspicious processes
0

Behavior graph

+
start #GANDCRAB vnc.exe wmic.exe no specs
Specs description
Program did not start
Integrity level elevation
Task сontains an error or was rebooted
Process has crashed
Task contains several apps running
Executable file was dropped
Debug information is available
Process was injected
Network attacks were detected
Application downloaded the executable file
Actions similar to stealing personal data
Behavior similar to exploiting the vulnerability
Inspected object has sucpicious PE structure
File is detected by antivirus software
CPU overrun
RAM overrun
Process starts the services
Process was added to the startup
Behavior similar to spam
Low-level access to the HDD
Probably Tor was used
System was rebooted
Connects to the network
Known threat

Process information

Click at the process to see the details.

PID
3836
CMD
"C:\Users\admin\AppData\Local\Temp\vnc.exe"
Path
C:\Users\admin\AppData\Local\Temp\vnc.exe
Indicators
Parent process
––
User
admin
Integrity Level
MEDIUM
Version:
Company
Description
Version
Modules
Image
c:\users\admin\appdata\local\temp\vnc.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\shell32.dll
c:\windows\system32\shlwapi.dll
c:\windows\system32\mpr.dll
c:\windows\system32\wininet.dll
c:\windows\system32\urlmon.dll
c:\windows\system32\ole32.dll
c:\windows\system32\oleaut32.dll
c:\windows\system32\crypt32.dll
c:\windows\system32\msasn1.dll
c:\windows\system32\iertutil.dll
c:\windows\system32\imm32.dll
c:\windows\system32\msctf.dll
c:\windows\system32\profapi.dll
c:\windows\system32\sspicli.dll
c:\windows\system32\cryptsp.dll
c:\windows\winsxs\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_41e6975e2bd6f2b2\comctl32.dll
c:\windows\system32\rsaenh.dll
c:\windows\system32\cryptbase.dll
c:\windows\system32\ws2_32.dll
c:\windows\system32\nsi.dll
c:\windows\system32\dnsapi.dll
c:\windows\system32\iphlpapi.dll
c:\windows\system32\winnsi.dll
c:\windows\system32\normaliz.dll
c:\windows\system32\rasapi32.dll
c:\windows\system32\rasman.dll
c:\windows\system32\rtutils.dll
c:\windows\system32\sensapi.dll
c:\windows\system32\nlaapi.dll
c:\windows\system32\rasadhlp.dll
c:\windows\system32\ntmarta.dll
c:\windows\system32\wldap32.dll
c:\windows\system32\version.dll
c:\windows\system32\mswsock.dll
c:\windows\system32\wshtcpip.dll
c:\windows\system32\wship6.dll
c:\windows\system32\fwpuclnt.dll
c:\windows\system32\userenv.dll
c:\windows\system32\wintrust.dll
c:\windows\system32\schannel.dll
c:\windows\system32\credssp.dll
c:\windows\system32\secur32.dll
c:\windows\system32\ncrypt.dll
c:\windows\system32\bcrypt.dll
c:\windows\system32\bcryptprimitives.dll
c:\windows\system32\gpapi.dll
c:\windows\system32\drprov.dll
c:\windows\system32\winsta.dll
c:\windows\system32\ntlanman.dll
c:\windows\system32\davclnt.dll
c:\windows\system32\davhlpr.dll
c:\windows\system32\wkscli.dll
c:\windows\system32\cscapi.dll
c:\windows\system32\netutils.dll
c:\windows\system32\browcli.dll
c:\windows\system32\propsys.dll
c:\windows\system32\clbcatq.dll
c:\windows\system32\setupapi.dll
c:\windows\system32\cfgmgr32.dll
c:\windows\system32\devobj.dll
c:\windows\system32\apphelp.dll
c:\windows\system32\wbem\wmic.exe

PID
2912
CMD
"C:\Windows\system32\wbem\wmic.exe" shadowcopy delete
Path
C:\Windows\system32\wbem\wmic.exe
Indicators
No indicators
Parent process
vnc.exe
User
admin
Integrity Level
MEDIUM
Exit code
2147749908
Version:
Company
Microsoft Corporation
Description
WMI Commandline Utility
Version
6.1.7600.16385 (win7_rtm.090713-1255)
Modules
Image
c:\windows\system32\wbem\wmic.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\ole32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\user32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\oleaut32.dll
c:\windows\system32\framedynos.dll
c:\windows\system32\sspicli.dll
c:\windows\system32\wtsapi32.dll
c:\windows\system32\shlwapi.dll
c:\windows\system32\ws2_32.dll
c:\windows\system32\nsi.dll
c:\windows\system32\secur32.dll
c:\windows\system32\iphlpapi.dll
c:\windows\system32\winnsi.dll
c:\windows\system32\imm32.dll
c:\windows\system32\msctf.dll
c:\windows\system32\cryptbase.dll
c:\windows\system32\clbcatq.dll
c:\windows\system32\wbem\wbemprox.dll
c:\windows\system32\wbemcomn.dll
c:\windows\system32\msxml3.dll
c:\windows\system32\urlmon.dll
c:\windows\system32\wininet.dll
c:\windows\system32\iertutil.dll
c:\windows\system32\crypt32.dll
c:\windows\system32\msasn1.dll
c:\windows\winsxs\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_41e6975e2bd6f2b2\comctl32.dll
c:\windows\system32\shell32.dll
c:\windows\system32\profapi.dll
c:\windows\system32\dnsapi.dll
c:\windows\system32\cryptsp.dll
c:\windows\system32\rsaenh.dll
c:\windows\system32\rpcrtremote.dll
c:\program files\common files\microsoft shared\office14\msoxmlmf.dll
c:\windows\winsxs\x86_microsoft.vc90.crt_1fc8b3b9a1e18e3b_9.0.30729.6161_none_50934f2ebcb7eb57\msvcr90.dll
c:\windows\system32\wbem\wbemsvc.dll
c:\windows\system32\wbem\fastprox.dll
c:\windows\system32\ntdsapi.dll
c:\windows\system32\wbem\wmiutils.dll

Registry activity

Total events
117
Read events
87
Write events
30
Delete events
0

Modification events

PID
Process
Operation
Key
Name
Value
3836
vnc.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Tracing\vnc_RASAPI32
EnableFileTracing
0
3836
vnc.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Tracing\vnc_RASAPI32
EnableConsoleTracing
0
3836
vnc.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Tracing\vnc_RASAPI32
FileTracingMask
4294901760
3836
vnc.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Tracing\vnc_RASAPI32
ConsoleTracingMask
4294901760
3836
vnc.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Tracing\vnc_RASAPI32
MaxFileSize
1048576
3836
vnc.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Tracing\vnc_RASAPI32
FileDirectory
%windir%\tracing
3836
vnc.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Tracing\vnc_RASMANCS
EnableFileTracing
0
3836
vnc.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Tracing\vnc_RASMANCS
EnableConsoleTracing
0
3836
vnc.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Tracing\vnc_RASMANCS
FileTracingMask
4294901760
3836
vnc.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Tracing\vnc_RASMANCS
ConsoleTracingMask
4294901760
3836
vnc.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Tracing\vnc_RASMANCS
MaxFileSize
1048576
3836
vnc.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Tracing\vnc_RASMANCS
FileDirectory
%windir%\tracing
3836
vnc.exe
write
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings
ProxyEnable
0
3836
vnc.exe
write
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Connections
SavedLegacySettings
4600000069000000010000000000000000000000000000000000000000000000C0E333BBEAB1D301000000000000000000000000020000001700000000000000FE800000000000007D6CB050D9C573F70B000000000000006D00330032005C004D00530049004D004700330032002E0064006C000100000004AA400014AA4000040000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000002000000C0A8016400000000000000000000000000000000000000000800000000000000805D3F00983740000008000002000000000000600000002060040000B8A94000020000008802000060040000B8A9400004000000F8010000B284000088B64000B84B400043003A000000000000000000000000000000000000000000
3836
vnc.exe
write
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap
UNCAsIntranet
0
3836
vnc.exe
write
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap
AutoDetect
1
3836
vnc.exe
write
HKEY_CLASSES_ROOT\Local Settings\MuiCache\5F\52C64B7E
LanguageList
en-US
3836
vnc.exe
write
HKEY_CURRENT_USER\Software\keys_data\data
public
0602000000A40000525341310008000001000100D33C6AF8507A542B4B213D952FA0EC1BEFB9211E7B23F8CD7B44FF1658AF8C4800B37F7FFBC069ECED322FAE761BCEDEDF9FD0AD2436453FAD329979811B567451122D7C0C4692511147514E3F067B637590595D2A85B96BAA1EB44D1F49425D17C1AFACB4BCC3AF3B7786FA4FE651F2328778478BAD1AD87101359C655C2F7D1E16FC2C4756700FFAD5CB379BEE8D92C1B2414BDD9AE9FB1B5021AA225359AA1492653E9B900D95CC1D1ACCD39B22FE4520558F7BD59CE9E1334D1BED90A458AAD1F4C91E911960BEB3A7559C58F51B73D9CB1F75FFF0020CC50FAB9FA55A6AA4B94AFD63BA009005CF22A476FCC66F0FE6FE5415DF208CA0EF0B5D082349CA
3836
vnc.exe
write
HKEY_CURRENT_USER\Software\keys_data\data
private
940400006683AE243B2F22CA3C3C68B72138AED5F67CD16A3FCD78DF291A452E60A9DFF3D2E77E1F6DFB539E8DE9B9173165A18B949792F97AB950AC4F8CC9F0BE35A3F5985D88CFB1087411A6A6DE16A12AB1F98FD926AF6C75ED873D4FC5D148E74E2F766FA21EF0E299A9F745606E1C5DA12F444B906BC6DB634232DA832CA1C452D5BDF822E6637EF4CD4354A2105A2487ED1163CD8D9B6FC6DAF3888188E5BE5328110C624D65262989F3589780CDC6F608A41459A2818F233C89AC0DAC43774ED150855125903CB27D7E87777D2B45E0AD4BF0EFF564726E8A391F2B541DEC66BD5CB4C448A757EC350612D708AD234964F916964439507AC822788D689D9CC3BAEA667FAED3B1883CBF7A3BD949FC86F8CCB5F4AFAB04FC2D8D119938A65E322617AFD67F9AEEFB46C52A8B5AC7F63A1241F9C4637B33FB0ABB9E24BECD08A9BC59649464B24888BF81D0A20C780D3EF211F5EA319CAD91BC32B08B22A3A57044472C863B8C5A0A6BEA2889CA365CF4AFBA346DE3B582CA0BE9027F8794C5BE6CE5B54DB8CEE976EBA814ED1C430D87430B9C407DD2F534D59059C362D36D8C6384BAD651CADFBE38018932CDC08760664BD006E9EEF9D1EC44E8DC579BED952EB41A8EB0316397589E165CCC13B7AB79E3FC51CAF8D9E1E3869BBA094C12960BF554A59F5ADFACF5F5FD57D3AD06C70BE7EEBEA2780DB5BFD2D03F52DA9AC11AE4B2992E7A1FDEBD81C830A7F46C77DD1A7319EF5660569B8B44BB6E36C09C5CD5A18791317452CD4880A7CE9817A77FEACA36AEE4C3988B44CD4BFC0FE3A016194405FEB551BAB62CDC7BD745D99FB01E8C01B2D9A0419C95D4CE7DCBE605C0DA9F00619E7B38CF142A0BA5A65670EB1811E6773F3819BC9EC1057AFDF1392F3182E4AB84E5AB7FAB557D2747F5856B3267308D41324B261D55CB81B776C6506C4D01D08417E77266C0C36890F679748C058C42CF6D83D9388F9BAE09B7FB9620771CB8D49152E4ABC0701896CC582C710152FAD8CDA8A4807355FCDD8BD8E26DA851E8AC282BE685B8F5B28DE0F9C9F2EDA1A0A19F056DC8FF29FDE83E8EDAAA28CACF016D5DFFAEFAA21153AD95C48D111960D84A3FA6C5D7AE9CEAB070C64E2D5080C5DCBEA04D881147D5B07BBD51FB9F616C5E4655D5F6D48A49F0FFB5A2AC63566322C24442108304DA6968249E5B8130D375A954D874E35138536FA9B14003A988A0BCBEAB55440F279C2F0C4D705C85D9CF809350024A7BAF9605D3227355DFF8883DB1E7C4E475D07351EA3A2D024BA666BCF359F3D41A6A4C0875465C4DFE824621CAAFD019DDF922889E3E87CB077598167068097795F2D7A6356ABC2A18A1E530C982C0CEE9AAAD18C2FCA5DE1F8893623FF6CCE1566391F4D0A104F42D42E74602B9CC25D23C2E9E157DADEF56D0353CBFDCC9C432E1A38F5EF9CC9E05B77501C9A74A66B571F833035B83814E87BF976DABE6F75592F3DEA7EC64A6A329BCD6D0E7017A6C27ADE94B9BA3E3BB84DD252DD6BE156E754BFEB839D080EBBC11D8D9AF50109D4CADDAD0BA883144BB311E12EC0E42AB5AE274FE0EECC834F76F6E681E766BEA455204231F95003504B19EC93BAADB82AB4770612DDF6907D2EF101CF2DCB013286CE523DBCC30BD2B75710F6FD1415892A611F2C94E4DB1E17FC84C589FE2BFE9FA6028E434C578C2D9BC4197C90479165C549588ABA20B585FD6CD9F5E68FB10EB6213807CD7E31BD6A4ECD0E519C29B25E7746CB782B3DBDD1219F397FF7E055B2A3A9958D5684511238BA6E2CFC7B757C6D8FE19B7D7B3DEE7D23486CAEA494EB80168DB307F1FA87A0F98B95D862F7589AC3F2BA89DDDC0B8C1B4882DCC8D33BD7240DD0E8CB5D9B7BAB9896EDE6A6533B83F5B008A690827F02A9D0820C05B4A72437B279DAA59D31003AB70B3BBF86FAC981C4110B1D7432FB4C7C351511D63581B5F569DA7E0BF3F207DDC9B19DBB5A28EB98BC0514EE60C48F26EE6B9AEB3AAFBD74F1DE85FBB08C45200CEFAAFE1F3DD9514286D2E25C5E881D937AE3749F985D570BD495E49C8B706A97F4E02090EF33E623D579C10A5D0FAD6392D94F2BA4E8981FE2BCB4553CBC2958AABA70900D376B929B54431979A1F93FA66A8B008C4E65BBA64DEC522C0777DB55C90E5256A825F055B0315671E334926BFC0DE160F7AE43329BEFD7ED5E3577A477A8C298556FEA368A96959A7AE2F7712627B0A48BFF470585677865C817DD53B39987AFE261D0347C94F4EDB4965276901C20214728CC755E57D0BBBDB7FF64D5DD4C60C786D9EFE3D23E2D96149DD122DE7E43C553DD715E7C3D9486673C54B482501D90893EA6B62AA6D2FE221E21EAD02F0AE97C33C

Files activity

Executable files
0
Suspicious files
264
Text files
206
Unknown types
11

Dropped files

PID
Process
Filename
Type
3836
vnc.exe
C:\Users\Public\Videos\Sample Videos\Wildlife.wmv.KRAB
––
MD5:  ––
SHA256:  ––
3836
vnc.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\storage\default\about+home\idb\3312185054sbndi_pspte.sqlite.KRAB
binary
MD5: e6953e97697cf5be0718ec67def3e130
SHA256: cb5e49faf6e619d743ded00791438336bac547e18194f7748f85da43f01ab147
3836
vnc.exe
C:\Users\Public\Videos\Sample Videos\KRAB-DECRYPT.txt
text
MD5: a285a299dbaaeaa3588106a648e72592
SHA256: 0826dba102ad61a52719d327e8a6b9c8897f66278362b1f7b06eab3cb57b9a73
3836
vnc.exe
C:\Users\Public\Recorded TV\Sample Media\win7_scenic-demoshort_raw.wtv.KRAB
––
MD5:  ––
SHA256:  ––
3836
vnc.exe
C:\Users\Public\Recorded TV\Sample Media\win7_scenic-demoshort_raw.wtv
––
MD5:  ––
SHA256:  ––
3836
vnc.exe
C:\Users\Public\Recorded TV\Sample Media\KRAB-DECRYPT.txt
text
MD5: a285a299dbaaeaa3588106a648e72592
SHA256: 0826dba102ad61a52719d327e8a6b9c8897f66278362b1f7b06eab3cb57b9a73
3836
vnc.exe
C:\Users\Public\Pictures\Sample Pictures\Tulips.jpg.KRAB
ini
MD5: c55546a61d50642850a005c1bbfabe35
SHA256: 531d0d3e4efc512dc1a8ec0648a7ef75f8245aa70284dbf0752613ecd996c9f6
3836
vnc.exe
C:\Users\Public\Recorded TV\KRAB-DECRYPT.txt
text
MD5: a285a299dbaaeaa3588106a648e72592
SHA256: 0826dba102ad61a52719d327e8a6b9c8897f66278362b1f7b06eab3cb57b9a73
3836
vnc.exe
C:\Users\Public\Pictures\Sample Pictures\Tulips.jpg
––
MD5:  ––
SHA256:  ––
3836
vnc.exe
C:\Users\Public\Pictures\Sample Pictures\Penguins.jpg.KRAB
binary
MD5: 3e5a547d7efaad1509f97b9359bf6079
SHA256: e687740bcdd41ed5e619289aa8e538354ba71eba718e7f9cbbc162d0858530f8
3836
vnc.exe
C:\Users\Public\Pictures\Sample Pictures\Penguins.jpg
––
MD5:  ––
SHA256:  ––
3836
vnc.exe
C:\Users\Public\Pictures\Sample Pictures\Lighthouse.jpg.KRAB
binary
MD5: f981b6533ad08fbd1b4003231ddcc517
SHA256: 047bc7dcb12067e1428079080af5d1fbd0dbd0b726cdb81b5aa87b2a13e19976
3836
vnc.exe
C:\Users\Public\Pictures\Sample Pictures\Lighthouse.jpg
––
MD5:  ––
SHA256:  ––
3836
vnc.exe
C:\Users\Public\Pictures\Sample Pictures\Koala.jpg.KRAB
binary
MD5: 386e8d64fff8c235fe762dd71c3897f2
SHA256: d6cedb4ea54d7f76d685c335dacdf12479a2d8f4067a5200768caad402e9c1c6
3836
vnc.exe
C:\Users\Public\Pictures\Sample Pictures\Koala.jpg
––
MD5:  ––
SHA256:  ––
3836
vnc.exe
C:\Users\Public\Pictures\Sample Pictures\Jellyfish.jpg.KRAB
binary
MD5: be43f4df2afd47e4eb5f9d404819e7bf
SHA256: d78ef517d5b78f7a05dd7f37d8eee0f3203fc57ab9503c6982b981949f84d7ce
3836
vnc.exe
C:\Users\Public\Pictures\Sample Pictures\Jellyfish.jpg
––
MD5:  ––
SHA256:  ––
3836
vnc.exe
C:\Users\Public\Pictures\Sample Pictures\Hydrangeas.jpg.KRAB
binary
MD5: 7badd42bb56386beb4436bf8b90de49a
SHA256: 0d5f9140a1cd8d809c90827f891a626b0de5cb590f561701bca64ac61d3cdc83
3836
vnc.exe
C:\Users\Public\Pictures\Sample Pictures\Hydrangeas.jpg
––
MD5:  ––
SHA256:  ––
3836
vnc.exe
C:\Users\Public\Pictures\Sample Pictures\Desert.jpg.KRAB
binary
MD5: d4f6e31779177b7d84af852a95eff60e
SHA256: e942dae53edc39fdf27ba8647618f5b21cec1e4c33d829a75353a4230a9a3187
3836
vnc.exe
C:\Users\Public\Pictures\Sample Pictures\Desert.jpg
––
MD5:  ––
SHA256:  ––
3836
vnc.exe
C:\Users\Public\Pictures\Sample Pictures\Chrysanthemum.jpg.KRAB
binary
MD5: e72cc0ff41fe3288150382c4cadfa326
SHA256: 29185084eca41f36b6ff97bc1f4fa7c69ed53a451160450d9147f02a2971ad81
3836
vnc.exe
C:\Users\Public\Pictures\Sample Pictures\Chrysanthemum.jpg
––
MD5:  ––
SHA256:  ––
3836
vnc.exe
C:\Users\Public\Pictures\Sample Pictures\KRAB-DECRYPT.txt
text
MD5: a285a299dbaaeaa3588106a648e72592
SHA256: 0826dba102ad61a52719d327e8a6b9c8897f66278362b1f7b06eab3cb57b9a73
3836
vnc.exe
C:\Users\Public\Music\Sample Music\Sleep Away.mp3
––
MD5:  ––
SHA256:  ––
3836
vnc.exe
C:\Users\Public\Music\Sample Music\Sleep Away.mp3.KRAB
––
MD5:  ––
SHA256:  ––
3836
vnc.exe
C:\Users\Public\Music\Sample Music\Maid with the Flaxen Hair.mp3.KRAB
binary
MD5: 9ad2ed5d0486b12f9839cd42b961883c
SHA256: 57a9685b4ca25796ebf75275d25edf1ad0a316eab966c52f6786dd7e718cb75a
3836
vnc.exe
C:\Users\Public\Music\Sample Music\Maid with the Flaxen Hair.mp3
––
MD5:  ––
SHA256:  ––
3836
vnc.exe
C:\Users\Public\Music\Sample Music\Kalimba.mp3.KRAB
––
MD5:  ––
SHA256:  ––
3836
vnc.exe
C:\Users\Public\Music\Sample Music\Kalimba.mp3
––
MD5:  ––
SHA256:  ––
3836
vnc.exe
C:\Users\Public\Libraries\RecordedTV.library-ms.KRAB
binary
MD5: 09989e7f9062a37a7b1aa4da934c9f1d
SHA256: b8e2a31994a097d73321e465a04850c4ecacaeb82d59530531423b1c0493c47f
3836
vnc.exe
C:\Users\Public\Music\Sample Music\KRAB-DECRYPT.txt
text
MD5: a285a299dbaaeaa3588106a648e72592
SHA256: 0826dba102ad61a52719d327e8a6b9c8897f66278362b1f7b06eab3cb57b9a73
3836
vnc.exe
C:\Users\Public\Libraries\RecordedTV.library-ms
––
MD5:  ––
SHA256:  ––
3836
vnc.exe
C:\Users\Public\Libraries\KRAB-DECRYPT.txt
text
MD5: a285a299dbaaeaa3588106a648e72592
SHA256: 0826dba102ad61a52719d327e8a6b9c8897f66278362b1f7b06eab3cb57b9a73
3836
vnc.exe
C:\Users\Public\Favorites\KRAB-DECRYPT.txt
text
MD5: a285a299dbaaeaa3588106a648e72592
SHA256: 0826dba102ad61a52719d327e8a6b9c8897f66278362b1f7b06eab3cb57b9a73
3836
vnc.exe
C:\Users\Public\Downloads\KRAB-DECRYPT.txt
text
MD5: a285a299dbaaeaa3588106a648e72592
SHA256: 0826dba102ad61a52719d327e8a6b9c8897f66278362b1f7b06eab3cb57b9a73
3836
vnc.exe
C:\Users\Public\KRAB-DECRYPT.txt
text
MD5: a285a299dbaaeaa3588106a648e72592
SHA256: 0826dba102ad61a52719d327e8a6b9c8897f66278362b1f7b06eab3cb57b9a73
3836
vnc.exe
C:\Users\Public\Pictures\KRAB-DECRYPT.txt
text
MD5: a285a299dbaaeaa3588106a648e72592
SHA256: 0826dba102ad61a52719d327e8a6b9c8897f66278362b1f7b06eab3cb57b9a73
3836
vnc.exe
C:\Users\Public\Videos\KRAB-DECRYPT.txt
text
MD5: a285a299dbaaeaa3588106a648e72592
SHA256: 0826dba102ad61a52719d327e8a6b9c8897f66278362b1f7b06eab3cb57b9a73
3836
vnc.exe
C:\Users\Public\Documents\KRAB-DECRYPT.txt
text
MD5: a285a299dbaaeaa3588106a648e72592
SHA256: 0826dba102ad61a52719d327e8a6b9c8897f66278362b1f7b06eab3cb57b9a73
3836
vnc.exe
C:\Users\Public\Music\KRAB-DECRYPT.txt
text
MD5: a285a299dbaaeaa3588106a648e72592
SHA256: 0826dba102ad61a52719d327e8a6b9c8897f66278362b1f7b06eab3cb57b9a73
3836
vnc.exe
C:\Users\admin\AppData\Roaming\Microsoft\Windows\SendTo\KRAB-DECRYPT.txt
text
MD5: a285a299dbaaeaa3588106a648e72592
SHA256: 0826dba102ad61a52719d327e8a6b9c8897f66278362b1f7b06eab3cb57b9a73
3836
vnc.exe
C:\Users\admin\AppData\Roaming\Microsoft\Windows\Templates\KRAB-DECRYPT.txt
text
MD5: a285a299dbaaeaa3588106a648e72592
SHA256: 0826dba102ad61a52719d327e8a6b9c8897f66278362b1f7b06eab3cb57b9a73
3836
vnc.exe
C:\Users\admin\AppData\Roaming\Microsoft\Windows\Start Menu\KRAB-DECRYPT.txt
text
MD5: a285a299dbaaeaa3588106a648e72592
SHA256: 0826dba102ad61a52719d327e8a6b9c8897f66278362b1f7b06eab3cb57b9a73
3836
vnc.exe
C:\Users\admin\Searches\Microsoft Outlook.searchconnector-ms.KRAB
binary
MD5: f64cada94ce4dca1dde33437a55c3e7e
SHA256: 39d8b947d7048432a98d746c26ca652fdcb744c0fe8ed2a4688b31a404676037
3836
vnc.exe
C:\Users\admin\Searches\Microsoft Outlook.searchconnector-ms
––
MD5:  ––
SHA256:  ––
3836
vnc.exe
C:\Users\admin\Searches\Microsoft OneNote.searchconnector-ms.KRAB
fli
MD5: ac72c8c99aaa2db00a2e0c6bd7ed8815
SHA256: d3bb9a2ad4cfebdb4bbd70ea78a18942c1e5755996238c6a6d3ce0ef6bc068b6
3836
vnc.exe
C:\Users\admin\Searches\Microsoft OneNote.searchconnector-ms
––
MD5:  ––
SHA256:  ––
3836
vnc.exe
C:\Users\admin\Searches\KRAB-DECRYPT.txt
text
MD5: a285a299dbaaeaa3588106a648e72592
SHA256: 0826dba102ad61a52719d327e8a6b9c8897f66278362b1f7b06eab3cb57b9a73
3836
vnc.exe
C:\Users\admin\Saved Games\KRAB-DECRYPT.txt
text
MD5: a285a299dbaaeaa3588106a648e72592
SHA256: 0826dba102ad61a52719d327e8a6b9c8897f66278362b1f7b06eab3cb57b9a73
3836
vnc.exe
C:\Users\admin\AppData\Roaming\Microsoft\Windows\Recent\KRAB-DECRYPT.txt
text
MD5: a285a299dbaaeaa3588106a648e72592
SHA256: 0826dba102ad61a52719d327e8a6b9c8897f66278362b1f7b06eab3cb57b9a73
3836
vnc.exe
C:\Users\admin\AppData\Roaming\Microsoft\Windows\Printer Shortcuts\KRAB-DECRYPT.txt
text
MD5: a285a299dbaaeaa3588106a648e72592
SHA256: 0826dba102ad61a52719d327e8a6b9c8897f66278362b1f7b06eab3cb57b9a73
3836
vnc.exe
C:\Users\admin\Pictures\womang.png.KRAB
binary
MD5: 5a7aef8f14b140910fdbf5b91a9fc165
SHA256: 05e620f9f0323bc7e9783195ca73da89db1e055b98721179b424e0d57dd2f6ee
3836
vnc.exe
C:\Users\admin\Pictures\womang.png
––
MD5:  ––
SHA256:  ––
3836
vnc.exe
C:\Users\admin\Pictures\lowerjune.jpg.KRAB
binary
MD5: 63d763d35ffec47d4b9c8306b6bf154b
SHA256: efe58861002141cf000c31b273ed00a3561b698434838001571f25dffc45c6a7
3836
vnc.exe
C:\Users\admin\Pictures\lowerjune.jpg
––
MD5:  ––
SHA256:  ––
3836
vnc.exe
C:\Users\admin\Pictures\easygraduate.png.KRAB
binary
MD5: c472d15830612016dcd202bb84cf60f5
SHA256: 64950c9d0d81ce705992d843a04ca5dcb35bb4ebc114d1ce4672d546cc0f157e
3836
vnc.exe
C:\Users\admin\Pictures\easygraduate.png
––
MD5:  ––
SHA256:  ––
3836
vnc.exe
C:\Users\admin\Pictures\doublemanager.png.KRAB
binary
MD5: 47247f8a245a684007a19e88c64d4a02
SHA256: 3be0693507c1a3bd933f68bb23fc64570d042a5a5ba4b77d6abaf726c1c8e7e8
3836
vnc.exe
C:\Users\admin\Pictures\doublemanager.png
––
MD5:  ––
SHA256:  ––
3836
vnc.exe
C:\Users\admin\Pictures\criticalfrancisco.png.KRAB
bs
MD5: 3a42fbed9b1937a4deeb93929aaa7aac
SHA256: dfcebe096c035d88142d649b3107eb0c1f59c3412b949aaa34221fec74609f23
3836
vnc.exe
C:\Users\admin\Pictures\criticalfrancisco.png
––
MD5:  ––
SHA256:  ––
3836
vnc.exe
C:\Users\admin\Pictures\categoriesanimal.jpg.KRAB
binary
MD5: 979fdaaf0c277159fab23818358dcda3
SHA256: 49100f7e8d3665b0d68055076e6b9d58cf2319828e64d4f529d20e8f1b8f9be9
3836
vnc.exe
C:\Users\admin\Pictures\categoriesanimal.jpg
––
MD5:  ––
SHA256:  ––
3836
vnc.exe
C:\Users\admin\ntuser.ini.KRAB
binary
MD5: cdddfaf5144a227e1c94f35b6d396682
SHA256: 189bbc9ff4297a7ffea01079562c1ca8a572d42c71c5bc63baf2a1b3ac300d49
3836
vnc.exe
C:\Users\admin\ntuser.ini
––
MD5:  ––
SHA256:  ––
3836
vnc.exe
C:\Users\admin\Links\KRAB-DECRYPT.txt
text
MD5: a285a299dbaaeaa3588106a648e72592
SHA256: 0826dba102ad61a52719d327e8a6b9c8897f66278362b1f7b06eab3cb57b9a73
3836
vnc.exe
C:\Users\admin\Favorites\Windows Live\Windows Live Spaces.url.KRAB
binary
MD5: c956108a8e73463ba72a5e07c9fb3810
SHA256: 246773142f51625615e7a5a54bff8d375c2182895ffa3df6589a19028adda7e0
3836
vnc.exe
C:\Users\admin\AppData\Roaming\Microsoft\Windows\Network Shortcuts\KRAB-DECRYPT.txt
text
MD5: a285a299dbaaeaa3588106a648e72592
SHA256: 0826dba102ad61a52719d327e8a6b9c8897f66278362b1f7b06eab3cb57b9a73
3836
vnc.exe
C:\Users\admin\Favorites\Windows Live\Windows Live Spaces.url
––
MD5:  ––
SHA256:  ––
3836
vnc.exe
C:\Users\admin\Favorites\Windows Live\Windows Live Mail.url.KRAB
binary
MD5: b54f49d5a0eb51b7a5711278e07a7732
SHA256: 0ae8dfbc448a66002eeac7ddc4f3b81ab85d142e371843120e98134038754437
3836
vnc.exe
C:\Users\admin\Favorites\Windows Live\Windows Live Mail.url
––
MD5:  ––
SHA256:  ––
3836
vnc.exe
C:\Users\admin\Favorites\Windows Live\Windows Live Gallery.url.KRAB
binary
MD5: 74cf502f804d321a84264d83cdc8caf2
SHA256: e59f94595d88c5c9e93ef3729b7f4f309e02faf88eacbe193910341e0294b381
3836
vnc.exe
C:\Users\admin\Favorites\Windows Live\Windows Live Gallery.url
––
MD5:  ––
SHA256:  ––
3836
vnc.exe
C:\Users\admin\Favorites\Windows Live\Get Windows Live.url.KRAB
binary
MD5: 9b3d96a5b2d420809835090b77a47c84
SHA256: 03930af88e5d5e25fc002b9249099bb2e593bbfe695b1500c37b7c8fc1811558
3836
vnc.exe
C:\Users\admin\Favorites\Windows Live\Get Windows Live.url
––
MD5:  ––
SHA256:  ––
3836
vnc.exe
C:\Users\admin\Favorites\Windows Live\KRAB-DECRYPT.txt
text
MD5: a285a299dbaaeaa3588106a648e72592
SHA256: 0826dba102ad61a52719d327e8a6b9c8897f66278362b1f7b06eab3cb57b9a73
3836
vnc.exe
C:\Users\admin\Favorites\MSN Websites\MSNBC News.url.KRAB
binary
MD5: 50117a023ca2df3dd08f995f56ae61a1
SHA256: ea4701815fba15065c5cd7c0c1b2f309c51e1b538f6c8ef7b1102cdfff015587
3836
vnc.exe
C:\Users\admin\Favorites\MSN Websites\MSNBC News.url
––
MD5:  ––
SHA256:  ––
3836
vnc.exe
C:\Users\admin\Favorites\MSN Websites\MSN.url.KRAB
binary
MD5: d189ceb16d3208b13da20cc88b0b7e42
SHA256: 0802eb2e27806b4114ec7cdcd39c4f7695d3c4401743c1e968e4059a456a4674
3836
vnc.exe
C:\Users\admin\Favorites\MSN Websites\MSN.url
––
MD5:  ––
SHA256:  ––
3836
vnc.exe
C:\Users\admin\Favorites\MSN Websites\MSN Sports.url.KRAB
binary
MD5: 20554af29f52cab98f0afc1c54ace122
SHA256: 34f4d9261c45fd0f2b7fcd14f282cae8bc2849df42e1cbe8dc3925d4696e6cd1
3836
vnc.exe
C:\Users\admin\Favorites\MSN Websites\MSN Sports.url
––
MD5:  ––
SHA256:  ––
3836
vnc.exe
C:\Users\admin\Favorites\MSN Websites\MSN Money.url.KRAB
binary
MD5: 46c48091b9f0ddaf9a4bc397dd86a98e
SHA256: 6969e00a53d728998c051b10412f5a4bfe7377ee02ca5389bf2a2bbc0f8261f3
3836
vnc.exe
C:\Users\admin\Favorites\MSN Websites\MSN Money.url
––
MD5:  ––
SHA256:  ––
3836
vnc.exe
C:\Users\admin\Favorites\MSN Websites\MSN Entertainment.url.KRAB
binary
MD5: c2fa2d54cfbe5c01b407198381e43928
SHA256: 45a5288953a44ff082e9cea71a8a26afca139e001e4ed519ef86f69011a8d5ea
3836
vnc.exe
C:\Users\admin\Favorites\MSN Websites\MSN Entertainment.url
––
MD5:  ––
SHA256:  ––
3836
vnc.exe
C:\Users\admin\Favorites\MSN Websites\MSN Autos.url.KRAB
binary
MD5: b43af0155df5b61c49542043e445af16
SHA256: 5edb69f8f7de71a64bbe21e26a8658f8e7a6a7347a12903749f0ab974b7df5d2
3836
vnc.exe
C:\Users\admin\Favorites\MSN Websites\MSN Autos.url
––
MD5:  ––
SHA256:  ––
3836
vnc.exe
C:\Users\admin\Favorites\MSN Websites\KRAB-DECRYPT.txt
text
MD5: a285a299dbaaeaa3588106a648e72592
SHA256: 0826dba102ad61a52719d327e8a6b9c8897f66278362b1f7b06eab3cb57b9a73
3836
vnc.exe
C:\Users\admin\Favorites\Microsoft Websites\Microsoft Store.url.KRAB
binary
MD5: 74190f0e93c4c81dc902cdb6e8899e45
SHA256: 8219ab78d8c570ad5a5558271625c7bdd76c513b8ba6bad54eae2d119989022f
3836
vnc.exe
C:\Users\admin\Favorites\Microsoft Websites\Microsoft At Work.url.KRAB
binary
MD5: 2c7223e9e9214789eaff6ccde4413cea
SHA256: d65015db9189bd3ea38df2de65a09f0d1e2eb13e3bd283b78fb4ebefdfff90c5
3836
vnc.exe
C:\Users\admin\Favorites\Microsoft Websites\Microsoft Store.url
––
MD5:  ––
SHA256:  ––
3836
vnc.exe
C:\Users\admin\Favorites\Microsoft Websites\Microsoft At Work.url
––
MD5:  ––
SHA256:  ––
3836
vnc.exe
C:\Users\admin\Favorites\Microsoft Websites\IE site on Microsoft.com.url.KRAB
flc
MD5: a40dc0ccd5efc142e076e5e77031f8d1
SHA256: bdb1871913b643a4fdb9fce7e8251637f75aa206804e2c1b41cb8b6364db5bba
3836
vnc.exe
C:\Users\admin\Favorites\Microsoft Websites\Microsoft At Home.url.KRAB
binary
MD5: ebb39dc35c8cd066a5c37a870bbeb38a
SHA256: c7fbd1f9e5d88ccf6dc9630ec51c4ea9c6bbf34d08b5e4813f2b3a067febbfbc
3836
vnc.exe
C:\Users\admin\Favorites\Microsoft Websites\Microsoft At Home.url
––
MD5:  ––
SHA256:  ––
3836
vnc.exe
C:\Users\admin\Favorites\Links for United States\USA.gov.url.KRAB
binary
MD5: b9d917a9c7b79915228710da340f98fa
SHA256: cc03d17acbc5ee604d9127c652b43e445cd61c6f84d459e7f5af67eb06fbd86b
3836
vnc.exe
C:\Users\admin\Favorites\Microsoft Websites\KRAB-DECRYPT.txt
text
MD5: a285a299dbaaeaa3588106a648e72592
SHA256: 0826dba102ad61a52719d327e8a6b9c8897f66278362b1f7b06eab3cb57b9a73
3836
vnc.exe
C:\Users\admin\Favorites\Microsoft Websites\IE Add-on site.url.KRAB
binary
MD5: 3199d9da8277450850743fa9132e7247
SHA256: aedc2222460aa8a058292d0a68e14cb6466be4c5f8f47dd356a13c6f6b010ac0
3836
vnc.exe
C:\Users\admin\Favorites\Microsoft Websites\IE site on Microsoft.com.url
––
MD5:  ––
SHA256:  ––
3836
vnc.exe
C:\Users\admin\Favorites\Microsoft Websites\IE Add-on site.url
––
MD5:  ––
SHA256:  ––
3836
vnc.exe
C:\Users\admin\Favorites\Links for United States\USA.gov.url
––
MD5:  ––
SHA256:  ––
3836
vnc.exe
C:\Users\admin\Favorites\Links\Web Slice Gallery.url.KRAB
binary
MD5: bffe35aa0ad33d908a14f16abb7b1913
SHA256: e89615e7c7805e6104ee3eab02c3ba7e7d63bfa6ee51199cc338a7e2856cb36f
3836
vnc.exe
C:\Users\admin\Favorites\Links for United States\KRAB-DECRYPT.txt
text
MD5: a285a299dbaaeaa3588106a648e72592
SHA256: 0826dba102ad61a52719d327e8a6b9c8897f66278362b1f7b06eab3cb57b9a73
3836
vnc.exe
C:\Users\admin\Favorites\Links for United States\GobiernoUSA.gov.url.KRAB
binary
MD5: e4fb853d35d8adc679de53a2bdb5afc6
SHA256: a5c6540934c11ed3bedf1bc60aec6de9cc0c9898cced816a41fd524250d23abb
3836
vnc.exe
C:\Users\admin\Favorites\Links for United States\GobiernoUSA.gov.url
––
MD5:  ––
SHA256:  ––
3836
vnc.exe
C:\Users\admin\Favorites\Links\Web Slice Gallery.url
––
MD5:  ––
SHA256:  ––
3836
vnc.exe
C:\Users\admin\Favorites\Links\Suggested Sites.url.KRAB
fli
MD5: 403d9202fca3c849770fc62efced4abf
SHA256: 0c21e464ceeb10c94cfc97bec6824e261d1e42a0f7841830f4a3dd6eeb517bbe
3836
vnc.exe
C:\Users\admin\Favorites\Links\Suggested Sites.url
––
MD5:  ––
SHA256:  ––
3836
vnc.exe
C:\Users\admin\Favorites\KRAB-DECRYPT.txt
text
MD5: a285a299dbaaeaa3588106a648e72592
SHA256: 0826dba102ad61a52719d327e8a6b9c8897f66278362b1f7b06eab3cb57b9a73
3836
vnc.exe
C:\Users\admin\Favorites\Links\KRAB-DECRYPT.txt
text
MD5: a285a299dbaaeaa3588106a648e72592
SHA256: 0826dba102ad61a52719d327e8a6b9c8897f66278362b1f7b06eab3cb57b9a73
3836
vnc.exe
C:\Users\admin\Downloads\societywere.jpg.KRAB
binary
MD5: 63fd014b51ef3b69b3dd56920bb1f88d
SHA256: bf95fb707b3323df7cfe4b5b6d52c408c39d130f1f66be2f5a1ad26f4ecb192f
3836
vnc.exe
C:\Users\admin\Downloads\wrongmethod.png.KRAB
binary
MD5: fb99e2902b5d32d092a635941370f1eb
SHA256: 82ba21c1ba8a261718c03313b43c880c20f403a86db4ba7923dd4e4a62e336df
3836
vnc.exe
C:\Users\admin\Downloads\wrongmethod.png
––
MD5:  ––
SHA256:  ––
3836
vnc.exe
C:\Users\admin\Downloads\societywere.jpg
––
MD5:  ––
SHA256:  ––
3836
vnc.exe
C:\Users\admin\Downloads\governmentfamilies.png.KRAB
binary
MD5: 69ba3fb72082991ff69a3d3456a31f66
SHA256: b16569c976f1de20d39719e0f9c7f590e7c5826283d10383b5ded4e4a4595918
3836
vnc.exe
C:\Users\admin\Downloads\governmentfamilies.png
––
MD5:  ––
SHA256:  ––
3836
vnc.exe
C:\Users\admin\Downloads\authoritysystem.png.KRAB
binary
MD5: 3993a511f7b127e54198cf4c381bb6ef
SHA256: 2347bfc81f9278af4559ea39d25d77bffe0fc8e2a019970a84493a26f1d78557
3836
vnc.exe
C:\Users\admin\Downloads\authoritysystem.png
––
MD5:  ––
SHA256:  ––
3836
vnc.exe
C:\Users\admin\Documents\yahoogood.rtf.KRAB
binary
MD5: 67fdae664c89f2b9829dea965fee7a5c
SHA256: 00042a841e6f7b3aee8c4e6fd401c13fc5c9b268ccc5e53559f0f6d26dc01d2e
3836
vnc.exe
C:\Users\admin\Downloads\KRAB-DECRYPT.txt
text
MD5: a285a299dbaaeaa3588106a648e72592
SHA256: 0826dba102ad61a52719d327e8a6b9c8897f66278362b1f7b06eab3cb57b9a73
3836
vnc.exe
C:\Users\admin\Documents\yahoogood.rtf
––
MD5:  ––
SHA256:  ––
3836
vnc.exe
C:\Users\admin\Documents\slikely.rtf.KRAB
binary
MD5: 1c290b105071371f7902477e92a10bc3
SHA256: bf9a2d57dcb8bd08b50b0d8d44d18965eba1b4d411168e7acc90555fa1826b90
3836
vnc.exe
C:\Users\admin\Documents\slikely.rtf
––
MD5:  ––
SHA256:  ––
3836
vnc.exe
C:\Users\admin\Documents\settingsfinal.rtf.KRAB
binary
MD5: d25e5575020cb6839801cdb627f6f0a2
SHA256: 34dc988e5963dce02c04c7c3d7e05eaf0c995eca70863912f2f4d67e2bcdf015
3836
vnc.exe
C:\Users\admin\Documents\settingsfinal.rtf
––
MD5:  ––
SHA256:  ––
3836
vnc.exe
C:\Users\admin\Documents\Outlook Files\Outlook.pst.KRAB
binary
MD5: d83c8ad9fc6a695e15d9ea9f8d0202b0
SHA256: e15456554c61bd63701141f9444050f97d97f2d391412c15a6534ceb2b48ecbb
3836
vnc.exe
C:\Users\admin\Documents\Outlook Files\Outlook.pst
––
MD5:  ––
SHA256:  ––
3836
vnc.exe
C:\Users\admin\Documents\Outlook Files\Outlook Data File - test.pst.KRAB
binary
MD5: ab8f9727c08360f88b59e66cf9ba6950
SHA256: c6107ae59c23797ea262fbb33dc55b72703de21e61ee68a1c41859036f5626c2
3836
vnc.exe
C:\Users\admin\Documents\Outlook Files\Outlook Data File - test.pst
––
MD5:  ––
SHA256:  ––
3836
vnc.exe
C:\Users\admin\Documents\Outlook Files\Outlook Data File - NoMail.pst.KRAB
binary
MD5: 14e3289c02f5d1c2aa0535a7e8280d1f
SHA256: ca7b9508f7c67acb445d0927173f1b0a5bc14606cee9593f087e55612e42f89b
3836
vnc.exe
C:\Users\admin\Documents\Outlook Files\Outlook Data File - NoMail.pst
––
MD5:  ––
SHA256:  ––
3836
vnc.exe
C:\Users\admin\Documents\Outlook Files\[email protected]
binary
MD5: bfe3483d1576da2ce7272498b7d1a9aa
SHA256: 94ff45c786f6f4f0569907c808d7142a97aa8b4d9d84e3e28fcf827dbb0171af
3836
vnc.exe
C:\Users\admin\Documents\Outlook Files\[email protected]
––
MD5:  ––
SHA256:  ––
3836
vnc.exe
C:\Users\admin\Documents\OneNote Notebooks\Personal\Unfiled Notes.one.KRAB
binary
MD5: 2213b8103817e51b400d574c2b03308f
SHA256: 20efabb9e8ab05bf1afd11fe83730af245cc6d8db8fe1c54ea41f110490edecb
3836
vnc.exe
C:\Users\admin\Documents\Outlook Files\KRAB-DECRYPT.txt
text
MD5: a285a299dbaaeaa3588106a648e72592
SHA256: 0826dba102ad61a52719d327e8a6b9c8897f66278362b1f7b06eab3cb57b9a73
3836
vnc.exe
C:\Users\admin\Documents\OneNote Notebooks\Personal\Unfiled Notes.one
––
MD5:  ––
SHA256:  ––
3836
vnc.exe
C:\Users\admin\Documents\OneNote Notebooks\Personal\Open Notebook.onetoc2.KRAB
binary
MD5: 4dc7e65a363e5833f9d7c04159ca4105
SHA256: b5c6cca7bd33cf9b0f98079d6f2d69e2c5031a5164ff17694a1a5b207e0ac9b4
3836
vnc.exe
C:\Users\admin\Documents\OneNote Notebooks\Personal\Open Notebook.onetoc2
––
MD5:  ––
SHA256:  ––
3836
vnc.exe
C:\Users\admin\Documents\OneNote Notebooks\Personal\General.one.KRAB
binary
MD5: 98384b8930d19315a503a73f511ad6d2
SHA256: 88aef5be8145fd86d0b94feb65873a0a36ffce0c9c0f57c92763ac073cd614fa
3836
vnc.exe
C:\Users\admin\Documents\OneNote Notebooks\Personal\General.one
––
MD5:  ––
SHA256:  ––
3836
vnc.exe
C:\Users\admin\Documents\OneNote Notebooks\KRAB-DECRYPT.txt
text
MD5: a285a299dbaaeaa3588106a648e72592
SHA256: 0826dba102ad61a52719d327e8a6b9c8897f66278362b1f7b06eab3cb57b9a73
3836
vnc.exe
C:\Users\admin\Pictures\KRAB-DECRYPT.txt
text
MD5: a285a299dbaaeaa3588106a648e72592
SHA256: 0826dba102ad61a52719d327e8a6b9c8897f66278362b1f7b06eab3cb57b9a73
3836
vnc.exe
C:\Users\admin\Videos\KRAB-DECRYPT.txt
text
MD5: a285a299dbaaeaa3588106a648e72592
SHA256: 0826dba102ad61a52719d327e8a6b9c8897f66278362b1f7b06eab3cb57b9a73
3836
vnc.exe
C:\Users\admin\Documents\OneNote Notebooks\Personal\KRAB-DECRYPT.txt
text
MD5: a285a299dbaaeaa3588106a648e72592
SHA256: 0826dba102ad61a52719d327e8a6b9c8897f66278362b1f7b06eab3cb57b9a73
3836
vnc.exe
C:\Users\admin\Desktop\talkparents.jpg.KRAB
binary
MD5: 7389f074f81525d119b461355ed8d978
SHA256: f59ebd80f5a5397f412416c273e7e1869b136649e270c98df8f0abdbcd27ea6f
3836
vnc.exe
C:\Users\admin\Desktop\rolethose.png.KRAB
binary
MD5: 2ebea84b4a6ae4f4bede81577181508a
SHA256: c24f8d072c7c094c5628e5f433e1bffa0aa31c691a5572ca61fe5da41d9f0102
3836
vnc.exe
C:\Users\admin\Documents\KRAB-DECRYPT.txt
text
MD5: a285a299dbaaeaa3588106a648e72592
SHA256: 0826dba102ad61a52719d327e8a6b9c8897f66278362b1f7b06eab3cb57b9a73
3836
vnc.exe
C:\Users\admin\Music\KRAB-DECRYPT.txt
text
MD5: a285a299dbaaeaa3588106a648e72592
SHA256: 0826dba102ad61a52719d327e8a6b9c8897f66278362b1f7b06eab3cb57b9a73
3836
vnc.exe
C:\Users\admin\Desktop\rolethose.png
––
MD5:  ––
SHA256:  ––
3836
vnc.exe
C:\Users\admin\Desktop\talkparents.jpg
––
MD5:  ––
SHA256:  ––
3836
vnc.exe
C:\Users\admin\Desktop\reportsback.png.KRAB
binary
MD5: 9583730a45febbab6db04f612a4dbaef
SHA256: 89273f2cfc7be631b54403c492a838ded439eb835a18636e8c73720e09353abf
3836
vnc.exe
C:\Users\admin\Desktop\reportsback.png
––
MD5:  ––
SHA256:  ––
3836
vnc.exe
C:\Users\admin\Desktop\profilemaximum.png.KRAB
binary
MD5: 160c19bf0d5907fdfcfa24107ca802c6
SHA256: 7b9790b09b6087ad161b9c33df87581def193f62cc3ee20a15822626a2cf0f15
3836
vnc.exe
C:\Users\admin\Desktop\profilemaximum.png
––
MD5:  ––
SHA256:  ––
3836
vnc.exe
C:\Users\admin\Desktop\othersprofile.rtf.KRAB
binary
MD5: 1ab8d153cad7a05de84a3b19c9c64038
SHA256: d02482d0696b459d43fa49d95a6885963e7e209adf1a5e78464bb36a75075e9f
3836
vnc.exe
C:\Users\admin\Desktop\othersprofile.rtf
––
MD5:  ––
SHA256:  ––
3836
vnc.exe
C:\Users\admin\Desktop\japaneseairport.png.KRAB
binary
MD5: ac8fab9e4a0d447675a2cf58a092e0b1
SHA256: a7b7ba9d5e73b397b40cbc0b93ab68c3450d2d482ee5a57341be1bf9d3b03e79
3836
vnc.exe
C:\Users\admin\Desktop\japaneseairport.png
––
MD5:  ––
SHA256:  ––
3836
vnc.exe
C:\Users\admin\Desktop\clothingyes.rtf.KRAB
binary
MD5: 340e48bb803992373aaaa13030645236
SHA256: 7edb0ea927a1979977b0b1b0ec1b0820b8f56cc71eb0934260f98be605eaef5e
3836
vnc.exe
C:\Users\admin\Desktop\earlyserver.rtf.KRAB
binary
MD5: 0f1c830ebbfe84913c58a5d891d2f27f
SHA256: 07b489a936eb7370c328cd6834a9e2fb374f3ecad02f8b16f223f23750ae5693
3836
vnc.exe
C:\Users\admin\Desktop\earlyserver.rtf
––
MD5:  ––
SHA256:  ––
3836
vnc.exe
C:\Users\admin\Desktop\clothingyes.rtf
––
MD5:  ––
SHA256:  ––
3836
vnc.exe
C:\Users\admin\Desktop\acceptedlink.png.KRAB
binary
MD5: 3b43580952ac93970255c294554905f8
SHA256: 0e377a9ff43c7a0d058cc4b42edc5180200657f5f43b178ed6d8b4193e8deac4
3836
vnc.exe
C:\Users\admin\Desktop\acceptedlink.png
––
MD5:  ––
SHA256:  ––
3836
vnc.exe
C:\Users\admin\Contacts\admin.contact.KRAB
binary
MD5: 4c1039d1d4768729a344010e32bb4770
SHA256: 3582e5c0988c5e1d7f24fb862c57d34662be36464a3bc7e9b2c90b701cba6f93
3836
vnc.exe
C:\Users\admin\Desktop\KRAB-DECRYPT.txt
text
MD5: a285a299dbaaeaa3588106a648e72592
SHA256: 0826dba102ad61a52719d327e8a6b9c8897f66278362b1f7b06eab3cb57b9a73
3836
vnc.exe
C:\Users\admin\AppData\Roaming\Microsoft\Windows\Cookies\KRAB-DECRYPT.txt
text
MD5: a285a299dbaaeaa3588106a648e72592
SHA256: 0826dba102ad61a52719d327e8a6b9c8897f66278362b1f7b06eab3cb57b9a73
3836
vnc.exe
C:\Users\admin\Contacts\admin.contact
––
MD5:  ––
SHA256:  ––
3836
vnc.exe
C:\Users\admin\Contacts\KRAB-DECRYPT.txt
text
MD5: a285a299dbaaeaa3588106a648e72592
SHA256: 0826dba102ad61a52719d327e8a6b9c8897f66278362b1f7b06eab3cb57b9a73
3836
vnc.exe
C:\Users\admin\AppData\Roaming\WinRAR\version.dat.KRAB
binary
MD5: 6efd9eca260c838268ac82476a9083b2
SHA256: c026b4c7dd688c9a9347d81e7027a56b2fc9aa02280f16ce81e6fe5640b81bc9
3836
vnc.exe
C:\Users\admin\AppData\Roaming\WinRAR\version.dat
––
MD5:  ––
SHA256:  ––
3836
vnc.exe
C:\Users\admin\AppData\Roaming\Sun\Java\KRAB-DECRYPT.txt
text
MD5: a285a299dbaaeaa3588106a648e72592
SHA256: 0826dba102ad61a52719d327e8a6b9c8897f66278362b1f7b06eab3cb57b9a73
3836
vnc.exe
C:\Users\admin\AppData\Roaming\WinRAR\KRAB-DECRYPT.txt
text
MD5: a285a299dbaaeaa3588106a648e72592
SHA256: 0826dba102ad61a52719d327e8a6b9c8897f66278362b1f7b06eab3cb57b9a73
3836
vnc.exe
C:\Users\admin\AppData\Roaming\Sun\Java\Deployment\KRAB-DECRYPT.txt
text
MD5: a285a299dbaaeaa3588106a648e72592
SHA256: 0826dba102ad61a52719d327e8a6b9c8897f66278362b1f7b06eab3cb57b9a73
3836
vnc.exe
C:\Users\admin\AppData\Roaming\Sun\KRAB-DECRYPT.txt
text
MD5: a285a299dbaaeaa3588106a648e72592
SHA256: 0826dba102ad61a52719d327e8a6b9c8897f66278362b1f7b06eab3cb57b9a73
3836
vnc.exe
C:\Users\admin\AppData\Roaming\Skype\SkypeRT\ul.conf.KRAB
binary
MD5: d9f8cbd2c5f816f8e7c24d421096fb7a
SHA256: 2f19e7cb1ce68b1b8866a114034172b8332e1f58b5efed5926c064f18539e551
3836
vnc.exe
C:\Users\admin\AppData\Roaming\Skype\SkypeRT\ul.conf
––
MD5:  ––
SHA256:  ––
3836
vnc.exe
C:\Users\admin\AppData\Roaming\Skype\SkypeRT\skypert.conf.KRAB
binary
MD5: 326f1feece3dde4b25022275e6df6105
SHA256: 0cdb142fa1753171487029bccb0a21640c6bfd3285dbb99a66b97f874fa17d9c
3836
vnc.exe
C:\Users\admin\AppData\Roaming\Skype\SkypeRT\skypert.conf
––
MD5:  ––
SHA256:  ––
3836
vnc.exe
C:\Users\admin\AppData\Roaming\Skype\SkypeRT\ecs.conf.KRAB
binary
MD5: 312c078f2d4f15801345aaac90ad3990
SHA256: 3b32c2bfc79814609093e6990c27f6c976a7eb0c3afa19025bb58a9976cfca85
3836
vnc.exe
C:\Users\admin\AppData\Roaming\Skype\SkypeRT\ecs.conf
––
MD5:  ––
SHA256:  ––
3836
vnc.exe
C:\Users\admin\AppData\Roaming\Skype\SkypeRT\KRAB-DECRYPT.txt
text
MD5: a285a299dbaaeaa3588106a648e72592
SHA256: 0826dba102ad61a52719d327e8a6b9c8897f66278362b1f7b06eab3cb57b9a73
3836
vnc.exe
C:\Users\admin\AppData\Roaming\Skype\shared_httpfe\queue.db.KRAB
binary
MD5: d2a45245b5c444344b5ab17eaaa9a3ea
SHA256: be3e30eea4d679fea898e2ed64e5ff8a3963e70e942c7c9a9aa2d2ca35f40cee
3836
vnc.exe
C:\Users\admin\AppData\Roaming\Skype\shared_httpfe\queue.db
––
MD5:  ––
SHA256:  ––
3836
vnc.exe
C:\Users\admin\AppData\Roaming\Skype\shared_dynco\dc.db-journal.KRAB
binary
MD5: 275bb56ce8b5ff43d995e224c33fac3a
SHA256: bfc34a41fb64233ca20cacf062604abdee45291ddbbdba441eceeedcb976de90
3836
vnc.exe
C:\Users\admin\AppData\Roaming\Skype\shared_httpfe\KRAB-DECRYPT.txt
text
MD5: a285a299dbaaeaa3588106a648e72592
SHA256: 0826dba102ad61a52719d327e8a6b9c8897f66278362b1f7b06eab3cb57b9a73
3836
vnc.exe
C:\Users\admin\AppData\Roaming\Skype\shared_dynco\dc.db-journal
––
MD5:  ––
SHA256:  ––
3836
vnc.exe
C:\Users\admin\AppData\Roaming\Skype\shared_dynco\dc.db.KRAB
binary
MD5: bd2599cba9ba095bbc9e7fac6171e953
SHA256: 622d0c01b84a063cca1d571d8ee8da383c707765f3b76e95600fedd20d93b5a5
3836
vnc.exe
C:\Users\admin\AppData\Roaming\Skype\shared_dynco\dc.db
––
MD5:  ––
SHA256:  ––
3836
vnc.exe
C:\Users\admin\AppData\Roaming\Skype\shared_dynco\KRAB-DECRYPT.txt
text
MD5: a285a299dbaaeaa3588106a648e72592
SHA256: 0826dba102ad61a52719d327e8a6b9c8897f66278362b1f7b06eab3cb57b9a73
3836
vnc.exe
C:\Users\admin\AppData\Roaming\Skype\shared.xml.KRAB
binary
MD5: 7351bc44c35b73f9ff6b790f3a9c2589
SHA256: aaeabb91e467f69910dd39bddee4a85a204966d090d578f380c5194470ef97b9
3836
vnc.exe
C:\Users\admin\AppData\Roaming\Skype\shared.xml
––
MD5:  ––
SHA256:  ––
3836
vnc.exe
C:\Users\admin\AppData\Roaming\Skype\DataRv\offline-storage.data.KRAB
binary
MD5: a853bdd156f358928e9eb26898646df5
SHA256: e1a4db8b6a52229352f21dcd7992dd1b68e8f687e681479276050ff111164aa6
3836
vnc.exe
C:\Users\admin\AppData\Roaming\Skype\logs\KRAB-DECRYPT.txt
text
MD5: a285a299dbaaeaa3588106a648e72592
SHA256: 0826dba102ad61a52719d327e8a6b9c8897f66278362b1f7b06eab3cb57b9a73
3836
vnc.exe
C:\Users\admin\AppData\Roaming\Skype\DataRv\offline-storage.data
––
MD5:  ––
SHA256:  ––
3836
vnc.exe
C:\Users\admin\AppData\Roaming\Opera\Opera\webserver\users.xml.KRAB
binary
MD5: 409f3ad7d7de28b0a172a84f2290f813
SHA256: f2a7b4d202a28bfee1092c3a45705b5bf5890fde014a26de0c8c58a6ce8ab46f
3836
vnc.exe
C:\Users\admin\AppData\Roaming\Skype\KRAB-DECRYPT.txt
text
MD5: a285a299dbaaeaa3588106a648e72592
SHA256: 0826dba102ad61a52719d327e8a6b9c8897f66278362b1f7b06eab3cb57b9a73
3836
vnc.exe
C:\Users\admin\AppData\Roaming\Skype\DataRv\KRAB-DECRYPT.txt
text
MD5: a285a299dbaaeaa3588106a648e72592
SHA256: 0826dba102ad61a52719d327e8a6b9c8897f66278362b1f7b06eab3cb57b9a73
3836
vnc.exe
C:\Users\admin\AppData\Roaming\Opera\Opera\webserver\users.xml
––
MD5:  ––
SHA256:  ––
3836
vnc.exe
C:\Users\admin\AppData\Roaming\Opera\Opera\webserver\KRAB-DECRYPT.txt
text
MD5: a285a299dbaaeaa3588106a648e72592
SHA256: 0826dba102ad61a52719d327e8a6b9c8897f66278362b1f7b06eab3cb57b9a73
3836
vnc.exe
C:\Users\admin\AppData\Roaming\Opera\Opera\wand.dat.KRAB
binary
MD5: bc851d671cea4be018cfa0e57e44705d
SHA256: e8374052cd4ec4546c4b61947d288b951865c41d8429f783b2a92dc3e5f20732
3836
vnc.exe
C:\Users\admin\AppData\Roaming\Opera\Opera\wand.dat
––
MD5:  ––
SHA256:  ––
3836
vnc.exe
C:\Users\admin\AppData\Roaming\Opera\Opera\vlink4.dat.KRAB
binary
MD5: e185a6575535873c90d0b9e7b5a251ad
SHA256: 8a143fb6081f053fba5c26a9b068e9f234f9ab1e88a756aac316053a65c2989c
3836
vnc.exe
C:\Users\admin\AppData\Roaming\Opera\Opera\vlink4.dat
––
MD5:  ––
SHA256:  ––
3836
vnc.exe
C:\Users\admin\AppData\Roaming\Opera\Opera\typed_history.xml.KRAB
binary
MD5: 7146c14b66b3044afdd001c82acbcf17
SHA256: 3e71abe1b4be892c5eb5db81280d7645dc642a4ff9b15cfa86c543dac855459c
3836
vnc.exe
C:\Users\admin\AppData\Roaming\Opera\Opera\typed_history.xml
––
MD5:  ––
SHA256:  ––
3836
vnc.exe
C:\Users\admin\AppData\Roaming\Opera\Opera\tips.ini.KRAB
binary
MD5: f8817975435f98bb4a06961b1c9d7aaa
SHA256: c99b0e965f58a082a8b3a1171c365bc092369e26eb0124fabe8226b64afced18
3836
vnc.exe
C:\Users\admin\AppData\Roaming\Opera\Opera\tips.ini
––
MD5:  ––
SHA256:  ––
3836
vnc.exe
C:\Users\admin\AppData\Roaming\Opera\Opera\tasks.xml.KRAB
binary
MD5: d3e219a197be2cdd632376dc17e2bb42
SHA256: afc213e8e7b738a8ab191094752dc87365260ddc2da7db90c7c7e88b90f4ef9e
3836
vnc.exe
C:\Users\admin\AppData\Roaming\Opera\Opera\tasks.xml
––
MD5:  ––
SHA256:  ––
3836
vnc.exe
C:\Users\admin\AppData\Roaming\Opera\Opera\styles\user\toc.css.KRAB
binary
MD5: efb06de0bb63b74106570bdf0edf8670
SHA256: cc8c55af4ec0aa87ffd3088262338a0777139ad26059669a2ba59a511f2cae22
3836
vnc.exe
C:\Users\admin\AppData\Roaming\Opera\Opera\styles\user\toc.css
––
MD5:  ––
SHA256:  ––
3836
vnc.exe
C:\Users\admin\AppData\Roaming\Opera\Opera\styles\user\structuretables.css.KRAB
binary
MD5: 5253aa0c6f21b1a991cd6eb81bb028e9
SHA256: ee37547454f8d1c49ca6d0c1fb0d3d74bf5e6410de590dbe59dfd9b95c43157b
3836
vnc.exe
C:\Users\admin\AppData\Roaming\Opera\Opera\styles\user\tablelayout.css.KRAB
binary
MD5: a202e54903454c9d8e528120d87c9f41
SHA256: 29de8b54e4814b9ca252425d8860d8b55d3a2fe58da600fe00c35b8b21435f10
3836
vnc.exe
C:\Users\admin\AppData\Roaming\Opera\Opera\styles\user\structuretables.css
––
MD5:  ––
SHA256:  ––
3836
vnc.exe
C:\Users\admin\AppData\Roaming\Opera\Opera\styles\user\tablelayout.css
––
MD5:  ––
SHA256:  ––
3836
vnc.exe
C:\Users\admin\AppData\Roaming\Opera\Opera\styles\user\structureinline.css.KRAB
binary
MD5: 52c253b675815e9116a0f71716bee00d
SHA256: 892f2606ca1a6de82b38d339618524e66e178223e9d9294b710a63a3c91e6c6b
3836
vnc.exe
C:\Users\admin\AppData\Roaming\Opera\Opera\styles\user\structureblock.css.KRAB
binary
MD5: 40a1d073bb0f6a241d8e1e5ce4b752b5
SHA256: 2303d39458b1e90206d5dd102076c55b329f5ae29c06c502c48fc6b97ba1e09e
3836
vnc.exe
C:\Users\admin\AppData\Roaming\Opera\Opera\styles\user\outline.css.KRAB
binary
MD5: 4573a62cb00ba476ef867f5bd2f38ceb
SHA256: d416af7859ea6544fe527ceeb4d6cb8fe044c238f84b7ecf7f714159ee117188
3836
vnc.exe
C:\Users\admin\AppData\Roaming\Opera\Opera\styles\user\structureblock.css
––
MD5:  ––
SHA256:  ––
3836
vnc.exe
C:\Users\admin\AppData\Roaming\Opera\Opera\styles\user\outline.css
––
MD5:  ––
SHA256:  ––
3836
vnc.exe
C:\Users\admin\AppData\Roaming\Opera\Opera\styles\user\structureinline.css
––
MD5:  ––
SHA256:  ––
3836
vnc.exe
C:\Users\admin\AppData\Roaming\Opera\Opera\styles\user\contrastwb.css.KRAB
binary
MD5: a8a4159593041b01f40410e25e12933a
SHA256: 4b40eafb04cc45b4a8f7a21b3f560aa731c46aea091db99b79d06128b9139016
3836
vnc.exe
C:\Users\admin\AppData\Roaming\Opera\Opera\styles\user\disablefloats.css.KRAB
binary
MD5: 86e058d09ded5f2db41f436856174172
SHA256: 16ab8303ea7fe20745304d8e15fad0d5a55a2fc28f9cbdc99cff0b22ba1d549b
3836
vnc.exe
C:\Users\admin\AppData\Roaming\Opera\Opera\styles\user\disablebreaks.css.KRAB
binary
MD5: daa9359c13ffb179adde0d2a658767a7
SHA256: 54cbfd90cf0a5060ed41767bc7c065a4f14f52da2d136206f8a8f219aacc7e77
3836
vnc.exe
C:\Users\admin\AppData\Roaming\Opera\Opera\styles\user\disableforms.css.KRAB
binary
MD5: 5fd52465bb714af367b0e91033372f2b
SHA256: bbeca310acd37272220eae8f008d753bdf3bad4f46a2a9c6fa52c7ec3eecd838
3836
vnc.exe
C:\Users\admin\AppData\Roaming\Opera\Opera\styles\user\disabletables.css.KRAB
binary
MD5: a086fe73c4ca798ba26f2655b7b20ba8
SHA256: 67f1eac8d2da017e8f4137c0a0a50f17b331d0e9eaf6a3eeb0b371505a1d9bff
3836
vnc.exe
C:\Users\admin\AppData\Roaming\Opera\Opera\styles\user\disablepositioning.css.KRAB
binary
MD5: 9e1d5b65edc72a4bf784d8abe8592654
SHA256: 0cf86b6477b6966f61824cf64d4988c6dfed8b339156b646344966f8b70fa7d5
3836
vnc.exe
C:\Users\admin\AppData\Roaming\Opera\Opera\styles\user\disableforms.css
––
MD5:  ––
SHA256:  ––
3836
vnc.exe
C:\Users\admin\AppData\Roaming\Opera\Opera\styles\user\disablepositioning.css
––
MD5:  ––
SHA256:  ––
3836
vnc.exe
C:\Users\admin\AppData\Roaming\Opera\Opera\styles\user\contrastwb.css
––
MD5:  ––
SHA256:  ––
3836
vnc.exe
C:\Users\admin\AppData\Roaming\Opera\Opera\styles\user\disabletables.css
––
MD5:  ––
SHA256:  ––
3836
vnc.exe
C:\Users\admin\AppData\Roaming\Opera\Opera\styles\user\disablebreaks.css
––
MD5:  ––
SHA256:  ––
3836
vnc.exe
C:\Users\admin\AppData\Roaming\Opera\Opera\styles\user\disablefloats.css
––
MD5:  ––
SHA256:  ––
3836
vnc.exe
C:\Users\admin\AppData\Roaming\Opera\Opera\styles\user\accessibility.css.KRAB
binary
MD5: e5e3ddabd8d3ab2bfc1d6591af1e2a7b
SHA256: 452e4c747ef2714a4026cc97e6a16b1e50f1653fb74ac5cd14eeb252defa7082
3836
vnc.exe
C:\Users\admin\AppData\Roaming\Opera\Opera\styles\user\altdebugger.css.KRAB
binary
MD5: 424c8deedf2a2a1bb7cb38382d3f687c
SHA256: 949c88cc89dca05e6b292f1517f6d02ea9dafd28fa2509eb6c256e453ed555d9
3836
vnc.exe
C:\Users\admin\AppData\Roaming\Opera\Opera\sessions\autosave.win.KRAB
binary
MD5: 85f0ec2d4147efdef4873a20d3000dfb
SHA256: 109f429ee8fdd4dc345fd9de62d2306801186f40192e19e25405e6fd9dcbfd6c
3836
vnc.exe
C:\Users\admin\AppData\Roaming\Opera\Opera\speeddial.ini.KRAB
binary
MD5: 20ae1580a1017707ee8e87b85ae1d905
SHA256: f8a1ada28ff10bb39157ef6c639510e818e2bfe65684975e44ea074e2180fc60
3836
vnc.exe
C:\Users\admin\AppData\Roaming\Opera\Opera\styles\user\KRAB-DECRYPT.txt
text
MD5: a285a299dbaaeaa3588106a648e72592
SHA256: 0826dba102ad61a52719d327e8a6b9c8897f66278362b1f7b06eab3cb57b9a73
3836
vnc.exe
C:\Users\admin\AppData\Roaming\Opera\Opera\styles\KRAB-DECRYPT.txt
text
MD5: a285a299dbaaeaa3588106a648e72592
SHA256: 0826dba102ad61a52719d327e8a6b9c8897f66278362b1f7b06eab3cb57b9a73
3836
vnc.exe
C:\Users\admin\AppData\Roaming\Opera\Opera\styles\user\classid.css.KRAB
binary
MD5: 50ea79a502c97742f68b823f3e072520
SHA256: d9ba454d83467611b571b5436cb87b1c5462febeeeb88f7f85d9f2cd4d0584ab
3836
vnc.exe
C:\Users\admin\AppData\Roaming\Opera\Opera\styles\user\contrastbw.css.KRAB
binary
MD5: 5600c74f5a1c8fed76ca69dfd7b2e2ee
SHA256: 501463612fd71df4cb4ebe2ab54cebfb4f43b0bb9bd7cb252e509a3b801794e6
3836
vnc.exe
C:\Users\admin\AppData\Roaming\Opera\Opera\sessions\autosave.win.bak.KRAB
binary
MD5: b4f8578166ad73941b3b7fffa19f95b9
SHA256: 4bfccffcfac1b556bf238f8d846839c7f027ef65832df7606c4e325f05debb80
3836
vnc.exe
C:\Users\admin\AppData\Roaming\Opera\Opera\styles\user\accessibility.css
––
MD5:  ––
SHA256:  ––
3836
vnc.exe
C:\Users\admin\AppData\Roaming\Opera\Opera\speeddial.ini
––
MD5:  ––
SHA256:  ––
3836
vnc.exe
C:\Users\admin\AppData\Roaming\Opera\Opera\styles\user\classid.css
––
MD5:  ––
SHA256:  ––
3836
vnc.exe
C:\Users\admin\AppData\Roaming\Opera\Opera\sessions\autosave.win.bak
––
MD5:  ––
SHA256:  ––
3836
vnc.exe
C:\Users\admin\AppData\Roaming\Opera\Opera\styles\user\altdebugger.css
––
MD5:  ––
SHA256:  ––
3836
vnc.exe
C:\Users\admin\AppData\Roaming\Opera\Opera\styles\user\contrastbw.css
––
MD5:  ––
SHA256:  ––
3836
vnc.exe
C:\Users\admin\AppData\Roaming\Opera\Opera\sessions\autosave.win
––
MD5:  ––
SHA256:  ––
3836
vnc.exe
C:\Users\admin\AppData\Roaming\Opera\Opera\opthumb.dat.KRAB
binary
MD5: ee6b12f0e2c40b2c7e182bf256e48b49
SHA256: 9601f17b5550461114f7cf1aedb96968a9833d7832702c5a58e3e5d85cf31096
3836
vnc.exe
C:\Users\admin\AppData\Roaming\Opera\Opera\sessions\KRAB-DECRYPT.txt
text
MD5: a285a299dbaaeaa3588106a648e72592
SHA256: 0826dba102ad61a52719d327e8a6b9c8897f66278362b1f7b06eab3cb57b9a73
3836
vnc.exe
C:\Users\admin\AppData\Roaming\Opera\Opera\opssl6.dat.KRAB
binary
MD5: 1f3e72a048f7b00c554439f32d21b141
SHA256: b03b7d04216c616a244927cb2659fe130d234f61ba111507a2d2033d9706b45e
3836
vnc.exe
C:\Users\admin\AppData\Roaming\Opera\Opera\optrust.dat.KRAB
binary
MD5: d3507841c74e8017a986e69599358f18
SHA256: d102d5dd90e9a8823f51a13fe6f27cccd20f48db097df61b543e2e8b75d06776
3836
vnc.exe
C:\Users\admin\AppData\Roaming\Opera\Opera\opuntrust.dat.KRAB
binary
MD5: ee8347131e8de2f4ddb8c493f7a50ab2
SHA256: d430c48249c7695f65d4b43dd4fc915e29ceebb4d2bc29f621363d2829e272fa
3836
vnc.exe
C:\Users\admin\AppData\Roaming\Opera\Opera\oprand.dat.KRAB
binary
MD5: 4c0f86b4a9f4cb5dcacabbb75a1fdd87
SHA256: 118e358b279db9261fc53e69a4bd141fa72f941aa207eb6d0464cdb3df21bbfa
3836
vnc.exe
C:\Users\admin\AppData\Roaming\Opera\Opera\opuntrust.dat
––
MD5:  ––
SHA256:  ––
3836
vnc.exe
C:\Users\admin\AppData\Roaming\Opera\Opera\opthumb.dat
––
MD5:  ––
SHA256:  ––
3836
vnc.exe
C:\Users\admin\AppData\Roaming\Opera\Opera\opssl6.dat
––
MD5:  ––
SHA256:  ––
3836
vnc.exe
C:\Users\admin\AppData\Roaming\Opera\Opera\optrust.dat
––
MD5:  ––
SHA256:  ––
3836
vnc.exe
C:\Users\admin\AppData\Roaming\Opera\Opera\opicacrt6.dat.KRAB
binary
MD5: 693ccb20b7be8c55a5d96bddaca07c51
SHA256: 53f5c7949a3bc9dba9203eef24a8c34dbc71725e3aa8d2f74f6ce534be88b557
3836
vnc.exe
C:\Users\admin\AppData\Roaming\Opera\Opera\opcert6.dat.KRAB
binary
MD5: 16c4aa3390a67257f556b24b612d96d7
SHA256: 00417f12f3fd0fdeac6e7392710514779d8e171015eb4fcf93a9b6bff8684cc9
3836
vnc.exe
C:\Users\admin\AppData\Roaming\Opera\Opera\operaprefs.ini.KRAB
mp3
MD5: 4c04a28634250a9a17ae8b0b0d8ba644
SHA256: d028a39cd0ee1742695b666e598e5830a860c06de2c7fe93884fa6daa0cde92c
3836
vnc.exe
C:\Users\admin\AppData\Roaming\Opera\Opera\operaprefs.ini
––
MD5:  ––
SHA256:  ––
3836
vnc.exe
C:\Users\admin\AppData\Roaming\Opera\Opera\opcert6.dat
––
MD5:  ––
SHA256:  ––
3836
vnc.exe
C:\Users\admin\AppData\Roaming\Opera\Opera\oprand.dat
––
MD5:  ––
SHA256:  ––
3836
vnc.exe
C:\Users\admin\AppData\Roaming\Opera\Opera\opicacrt6.dat
––
MD5:  ––
SHA256:  ––
3836
vnc.exe
C:\Users\admin\AppData\Roaming\Opera\Opera\handlers.ini.KRAB
binary
MD5: f39d319526449a0fa7eb6a891a3d0bc7
SHA256: 487d4aa93078f9d66f260832e325946caf677121ed9773d57fcc4b94baec71dc
3836
vnc.exe
C:\Users\admin\AppData\Roaming\Opera\Opera\download.dat.KRAB
binary
MD5: 411e71283c5ac24dc308cbecf785d4cb
SHA256: ca98711366de3f0e859ad6d5a48b1d4f0ad3e265afea989f8cf7beb139323c3c
3836
vnc.exe
C:\Users\admin\AppData\Roaming\Opera\Opera\global_history.dat.KRAB
binary
MD5: 60c6473d42d6f163c5006c9b0f6961bb
SHA256: 11b2bc914965be75a4ffbad917a9044f536075241d066bd339e1cd9737a5ca1b
3836
vnc.exe
C:\Users\admin\AppData\Roaming\Opera\Opera\opcacrt6.dat.KRAB
binary
MD5: 5f09c5be0f9e8cb1444eb2a3ac053a69
SHA256: bf9c32f170decf76bee598242f7373862544347276adea22ef64e423b7098f73
3836
vnc.exe
C:\Users\admin\AppData\Roaming\Opera\Opera\bookmarks.adr.KRAB
binary
MD5: b8ef48e40df8d6d3dde2fa6ef6d4bdd7
SHA256: 316e497413726848a51dab368a8b0a9aad43c5a00673bbab14b6638d2ea3330e
3836
vnc.exe
C:\Users\admin\AppData\Roaming\Opera\Opera\cookies4.dat.KRAB
binary
MD5: f6d2c05f30034b74d02f058ce9bf9333
SHA256: d50b474f88b40c6625a15f1cccd68bd59c65900972e2ddd11549d467d2233270
3836
vnc.exe
C:\Users\admin\AppData\Roaming\Opera\Opera\bookmarks.adr
––
MD5:  ––
SHA256:  ––
3836
vnc.exe
C:\Users\admin\AppData\Roaming\Opera\Opera\cookies4.dat
––
MD5:  ––
SHA256:  ––
3836
vnc.exe
C:\Users\admin\AppData\Roaming\Opera\Opera\download.dat
––
MD5:  ––
SHA256:  ––
3836
vnc.exe
C:\Users\admin\AppData\Roaming\Opera\Opera\opcacrt6.dat
––
MD5:  ––
SHA256:  ––
3836
vnc.exe
C:\Users\admin\AppData\Roaming\Opera\Opera\global_history.dat
––
MD5:  ––
SHA256:  ––
3836
vnc.exe
C:\Users\admin\AppData\Roaming\Opera\Opera\handlers.ini
––
MD5:  ––
SHA256:  ––
3836
vnc.exe
C:\Users\admin\AppData\Roaming\Opera\Opera\KRAB-DECRYPT.txt
text
MD5: a285a299dbaaeaa3588106a648e72592
SHA256: 0826dba102ad61a52719d327e8a6b9c8897f66278362b1f7b06eab3cb57b9a73
3836
vnc.exe
C:\Users\admin\AppData\Roaming\Notepad++\themes\Vibrant Ink.xml.KRAB
binary
MD5: a8b60e69bf74ddf96de1c624ec3b753d
SHA256: e6dda0ac3a7173179894833ca920c76d454e4aca4dc22cca2e70b28b27183f1c
3836
vnc.exe
C:\Users\admin\AppData\Roaming\Notepad++\themes\Zenburn.xml.KRAB
binary
MD5: 42fc62c2bfd357d5e44888621a16a084
SHA256: 5e2201eef94d78c0ac98769d6cf5ccb260ac4a5ca41be4403fed42a65a49948f
3836
vnc.exe
C:\Users\admin\AppData\Roaming\Notepad++\themes\vim Dark Blue.xml.KRAB
binary
MD5: 843ab21e2325c1d3765ef7eee4fd063c
SHA256: 64b6197f3977a627b7cb80cce40fdc6a70695fcc5292f96ec10d45392edc4760
3836
vnc.exe
C:\Users\admin\AppData\Roaming\Notepad++\themes\Twilight.xml.KRAB
binary
MD5: 491009b1eba53530c9d3d5800834551c
SHA256: 31f2d6d4f1696dda5af8a626acc8089dea0f4cbd9a2c522dc1ddbe17a6586dad
3836
vnc.exe
C:\Users\admin\AppData\Roaming\Opera\KRAB-DECRYPT.txt
text
MD5: a285a299dbaaeaa3588106a648e72592
SHA256: 0826dba102ad61a52719d327e8a6b9c8897f66278362b1f7b06eab3cb57b9a73
3836
vnc.exe
C:\Users\admin\AppData\Roaming\Notepad++\themes\Solarized.xml.KRAB
binary
MD5: 68f13b59949a7c525b286eff6f793147
SHA256: b00fa8a43805f37520fad12a607901b72955767b3ee17ba70229e9c4fb6b9c69
3836
vnc.exe
C:\Users\admin\AppData\Roaming\Notepad++\themes\Vibrant Ink.xml
––
MD5:  ––
SHA256:  ––
3836
vnc.exe
C:\Users\admin\AppData\Roaming\Notepad++\themes\vim Dark Blue.xml
––
MD5:  ––
SHA256:  ––
3836
vnc.exe
C:\Users\admin\AppData\Roaming\Notepad++\themes\Twilight.xml
––
MD5:  ––
SHA256:  ––
3836
vnc.exe
C:\Users\admin\AppData\Roaming\Notepad++\themes\Zenburn.xml
––
MD5:  ––
SHA256:  ––
3836
vnc.exe
C:\Users\admin\AppData\Roaming\Notepad++\themes\Solarized.xml
––
MD5:  ––
SHA256:  ––
3836
vnc.exe
C:\Users\admin\AppData\Roaming\Notepad++\themes\Solarized-light.xml.KRAB
binary
MD5: 584013dea37e23c3a3f7ee95cd804581
SHA256: 809f1b9df38724ee46a300706bb413f69b26fc0926fb12ece1167e787418c1d4
3836
vnc.exe
C:\Users\admin\AppData\Roaming\Notepad++\themes\Solarized-light.xml
––
MD5:  ––
SHA256:  ––
3836
vnc.exe
C:\Users\admin\AppData\Roaming\Notepad++\themes\Ruby Blue.xml.KRAB
binary
MD5: 76def21e00b2d714bb5d645db66146f5
SHA256: a949e15a8fefac96f13eb98404ebc7d5f1cda5720949bb426786bb2fb4820853
3836
vnc.exe
C:\Users\admin\AppData\Roaming\Notepad++\themes\Ruby Blue.xml
––
MD5:  ––
SHA256:  ––
3836
vnc.exe
C:\Users\admin\AppData\Roaming\Notepad++\themes\Plastic Code Wrap.xml.KRAB
binary
MD5: 960b064bcd50f373bf71f65ca8bfe65f
SHA256: 95d668f2c7aa923a653b6123d916cfbc14ca2e5aae72b194731302dab7e7a719
3836
vnc.exe
C:\Users\admin\AppData\Roaming\Notepad++\themes\Plastic Code Wrap.xml
––
MD5:  ––
SHA256:  ––
3836
vnc.exe
C:\Users\admin\AppData\Roaming\Notepad++\themes\Obsidian.xml.KRAB
binary
MD5: 2076782e2189123829103277677dff4c
SHA256: 4a771e8f10955338a20e60e8ad889573e709263fc6afb3accd2ec8180aad9ba2
3836
vnc.exe
C:\Users\admin\AppData\Roaming\Notepad++\themes\Navajo.xml.KRAB
binary
MD5: 9fdb2cc62839a15662388befab4d0e3d
SHA256: 6f7043b09635e733d286b5de69f10177c001284149ca1a07db9fcb12254f5f52
3836
vnc.exe
C:\Users\admin\AppData\Roaming\Notepad++\themes\Obsidian.xml
––
MD5:  ––
SHA256:  ––
3836
vnc.exe
C:\Users\admin\AppData\Roaming\Notepad++\themes\Mono Industrial.xml.KRAB
binary
MD5: 2bfd5f009c9469236489756368915e08
SHA256: 067aa65fb5704ddb31e682c2e24e2aefd8d3512284b2d85b4dcc714aa0e7659d
3836
vnc.exe
C:\Users\admin\AppData\Roaming\Notepad++\themes\Monokai.xml.KRAB
binary
MD5: 9174097d80cf6e594618cf6347917288
SHA256: fbff95571134b30abdafd38baaa61add7c295c07c3180dd785ed283cef39291e
3836
vnc.exe
C:\Users\admin\AppData\Roaming\Notepad++\themes\MossyLawn.xml.KRAB
binary
MD5: 49d422d0ce8688740dbabe0348015e6d
SHA256: 3e0063e3fa1171d2bf8153e75bc9f94cbf8cecd5d6f9adabc66499666b8cf5f6
3836
vnc.exe
C:\Users\admin\AppData\Roaming\Notepad++\themes\Navajo.xml
––
MD5:  ––
SHA256:  ––
3836
vnc.exe
C:\Users\admin\AppData\Roaming\Notepad++\themes\MossyLawn.xml
––
MD5:  ––
SHA256:  ––
3836
vnc.exe
C:\Users\admin\AppData\Roaming\Notepad++\themes\Monokai.xml
––
MD5:  ––
SHA256:  ––
3836
vnc.exe
C:\Users\admin\AppData\Roaming\Notepad++\themes\khaki.xml.KRAB
binary
MD5: 25c7830a7bf27ee142ba4988c4d98db4
SHA256: 6750c35c6f4e9db9230a06f81e6c1c14d59ab48c3b1850a7f5f951d7449ea18e
3836
vnc.exe
C:\Users\admin\AppData\Roaming\Notepad++\themes\Mono Industrial.xml
––
MD5:  ––
SHA256:  ––
3836
vnc.exe
C:\Users\admin\AppData\Roaming\Notepad++\themes\khaki.xml
––
MD5:  ––
SHA256:  ––
3836
vnc.exe
C:\Users\admin\AppData\Roaming\Notepad++\themes\Deep Black.xml.KRAB
binary
MD5: 7ba323db90dadf8a09c296e1033a6b15
SHA256: e708bae2d3401b6fa3ee66e882f05c722ac86acd5bbd0980e8d19a3a7b81ac4d
3836
vnc.exe
C:\Users\admin\AppData\Roaming\Notepad++\themes\HotFudgeSundae.xml.KRAB
binary
MD5: d81aec4f78802ce6e82fad151be3a787
SHA256: a740a9f2de054681cf4b86e16f2a21f95ccd252d169081a1317deb148a13ded0
3836
vnc.exe
C:\Users\admin\AppData\Roaming\Notepad++\themes\Hello Kitty.xml.KRAB
binary
MD5: 92c9ddfa1bf2a4182265065852b96acb
SHA256: c988be29adf6fa2f464ec03ff4f31eb045d1e4da98491e12cc36f64443a1b8f5
3836
vnc.exe
C:\Users\admin\AppData\Roaming\Notepad++\themes\HotFudgeSundae.xml
––
MD5:  ––
SHA256:  ––
3836
vnc.exe
C:\Users\admin\AppData\Roaming\Notepad++\themes\Hello Kitty.xml
––
MD5:  ––
SHA256:  ––
3836
vnc.exe
C:\Users\admin\AppData\Roaming\Notepad++\themes\Choco.xml.KRAB
binary
MD5: b75dd81b3bb15476480cbb0aacebc9c4
SHA256: af9b755e98370904f9a6bdee4e72b45fc6fa826a48b57e057f8f83d975935477
3836
vnc.exe
C:\Users\admin\AppData\Roaming\Notepad++\themes\Deep Black.xml
––
MD5:  ––
SHA256:  ––
3836
vnc.exe
C:\Users\admin\AppData\Roaming\Notepad++\themes\Choco.xml
––
MD5:  ––
SHA256:  ––
3836
vnc.exe
C:\Users\admin\AppData\Roaming\Notepad++\themes\Black board.xml.KRAB
binary
MD5: 30e0c253921476034e96cfdadfd62825
SHA256: b3eed126598eeda3978f4d768df6311c41323511eb02cc2e6d67c5484dd967b7
3836
vnc.exe
C:\Users\admin\AppData\Roaming\Notepad++\themes\Bespin.xml.KRAB
binary
MD5: 01be2694dbf3b7eda41e9c7704a531de
SHA256: 21ce35681ec50839151b6f854ed7f256ad5abbe5762880bd36d56ca58b38653a
3836
vnc.exe
C:\Users\admin\AppData\Roaming\Notepad++\plugins\config\KRAB-DECRYPT.txt
text
MD5: a285a299dbaaeaa3588106a648e72592
SHA256: 0826dba102ad61a52719d327e8a6b9c8897f66278362b1f7b06eab3cb57b9a73
3836
vnc.exe
C:\Users\admin\AppData\Roaming\Notepad++\themes\KRAB-DECRYPT.txt
text
MD5: a285a299dbaaeaa3588106a648e72592
SHA256: 0826dba102ad61a52719d327e8a6b9c8897f66278362b1f7b06eab3cb57b9a73
3836
vnc.exe
C:\Users\admin\AppData\Roaming\Notepad++\plugins\KRAB-DECRYPT.txt
text
MD5: a285a299dbaaeaa3588106a648e72592
SHA256: 0826dba102ad61a52719d327e8a6b9c8897f66278362b1f7b06eab3cb57b9a73
3836
vnc.exe
C:\Users\admin\AppData\Roaming\Notepad++\functionList.xml.KRAB
binary
MD5: fa1d56f19ba7e89f5a8505cef3b7e5ae
SHA256: a61fc768ef2124bc7b573d5f81ed27faa4ebd304a6f4d0b123264b7296c55b8b
3836
vnc.exe
C:\Users\admin\AppData\Roaming\Notepad++\contextMenu.xml.KRAB
binary
MD5: 8a5b7b69ef5ae2ae3bc90a42cb016160
SHA256: deeaa11b0621ee046faef79b1c68e6696af232c3d6643fe437cda04163acd5dd
3836
vnc.exe
C:\Users\admin\AppData\Roaming\Notepad++\themes\Bespin.xml
––
MD5:  ––
SHA256:  ––
3836
vnc.exe
C:\Users\admin\AppData\Roaming\Notepad++\contextMenu.xml
––
MD5:  ––
SHA256:  ––
3836
vnc.exe
C:\Users\admin\AppData\Roaming\Notepad++\functionList.xml
––
MD5:  ––
SHA256:  ––
3836
vnc.exe
C:\Users\admin\AppData\Roaming\Notepad++\themes\Black board.xml
––
MD5:  ––
SHA256:  ––
3836
vnc.exe
C:\Users\admin\AppData\Roaming\Notepad++\KRAB-DECRYPT.txt
text
MD5: a285a299dbaaeaa3588106a648e72592
SHA256: 0826dba102ad61a52719d327e8a6b9c8897f66278362b1f7b06eab3cb57b9a73
3836
vnc.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\weave\failed\KRAB-DECRYPT.txt
text
MD5: a285a299dbaaeaa3588106a648e72592
SHA256: 0826dba102ad61a52719d327e8a6b9c8897f66278362b1f7b06eab3cb57b9a73
3836
vnc.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\weave\toFetch\tabs.json.KRAB
binary
MD5: 77f35f8af970e78c13ea0ad680550885
SHA256: 751eca599e8bdef964780a534f4d7f55190361a5abd782666b405253d5723754
3836
vnc.exe
C:\Users\admin\AppData\Roaming\Mozilla\SystemExtensionsDev\KRAB-DECRYPT.txt
text
MD5: a285a299dbaaeaa3588106a648e72592
SHA256: 0826dba102ad61a52719d327e8a6b9c8897f66278362b1f7b06eab3cb57b9a73
3836
vnc.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\webappsstore.sqlite.KRAB
binary
MD5: 55b3fdf396abd8eeb4b9fb07f8e65780
SHA256: 3db1a7aacb7e235627cd121e0edfa1f31fccc6d6ac5d03a4a2758b41b716fe02
3836
vnc.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\profiles.ini.KRAB
binary
MD5: fb5a87cfc23366c4a766d22bd7168699
SHA256: 7f8f9b1d7757a11585f18cd0c297bcd38856b0a2543f0de4611311661a755c28
3836
vnc.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\xulstore.json.KRAB
ini
MD5: 7a1cd809223745592d20f2453c1259ed
SHA256: d75511c7c0d7cd7a0b0b5f0ce074a360886affa48bb5fc33034023e7390ba282
3836
vnc.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\times.json.KRAB
binary
MD5: b7fd199c092c88f7ba71fbfa448765dd
SHA256: 432ec00aabd674a75c9b7262464837443a2c86089a040ff8a189cc5a871cbbff
3836
vnc.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\weave\KRAB-DECRYPT.txt
text
MD5: a285a299dbaaeaa3588106a648e72592
SHA256: 0826dba102ad61a52719d327e8a6b9c8897f66278362b1f7b06eab3cb57b9a73
3836
vnc.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\weave\toFetch\KRAB-DECRYPT.txt
text
MD5: a285a299dbaaeaa3588106a648e72592
SHA256: 0826dba102ad61a52719d327e8a6b9c8897f66278362b1f7b06eab3cb57b9a73
3836
vnc.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\weave\failed\tabs.json.KRAB
binary
MD5: c1ed33eb2fc32e53e55a1893fb08002a
SHA256: f9f78110cf6a4ff398a7a00f50587a803647c6ae3e91495d879133245b48179c
3836
vnc.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\xulstore.json
––
MD5:  ––
SHA256:  ––
3836
vnc.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\webappsstore.sqlite
––
MD5:  ––
SHA256:  ––
3836
vnc.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\profiles.ini
––
MD5:  ––
SHA256:  ––
3836
vnc.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\weave\toFetch\tabs.json
––
MD5:  ––
SHA256:  ––
3836
vnc.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\times.json
––
MD5:  ––
SHA256:  ––
3836
vnc.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\weave\failed\tabs.json
––
MD5:  ––
SHA256:  ––
3836
vnc.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\storage\permanent\chrome\idb\3899588440psinninpiFn2g%.sqlite.KRAB
binary
MD5: b73a9388a795c46455303ac9b1ff9204
SHA256: 7aa0f039c61906c46fa30e26e5535173e39219567d8b0cc6f2ff12e35a0a5dad
3836
vnc.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\storage\permanent\chrome\idb\727688008bsleotcakcliifsittsr%.sqlite.KRAB
binary
MD5: 527c1556493a981a247ea66ad37933f1
SHA256: b732eb9ca5d0bc5afd5bad44e8fbfda32e5f271ec633e2f8576c75fb5d17baa2
3836
vnc.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\storage.sqlite.KRAB
binary
MD5: 5a0909bc64633f509e69dfeec014de1e
SHA256: 761edfb2ad3eab764b2275023e41308587496101efab8c3094467a940777f25c
3836
vnc.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\storage\permanent\chrome\idb\3899588440psinninpiFn2g%.files\KRAB-DECRYPT.txt
text
MD5: a285a299dbaaeaa3588106a648e72592
SHA256: 0826dba102ad61a52719d327e8a6b9c8897f66278362b1f7b06eab3cb57b9a73
3836
vnc.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\storage\permanent\chrome\idb\3561288849sdhlie.sqlite.KRAB
binary
MD5: 40b300eb9312588658acf2bc2214256c
SHA256: 870a925c6cc4a3840b7b614f6ca9c9719e54ecb680d56f542e6a82eb6a933fd1
3836
vnc.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\storage\temporary\KRAB-DECRYPT.txt
text
MD5: a285a299dbaaeaa3588106a648e72592
SHA256: 0826dba102ad61a52719d327e8a6b9c8897f66278362b1f7b06eab3cb57b9a73
3836
vnc.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\storage\permanent\chrome\idb\727688008bsleotcakcliifsittsr%.files\KRAB-DECRYPT.txt
text
MD5: a285a299dbaaeaa3588106a648e72592
SHA256: 0826dba102ad61a52719d327e8a6b9c8897f66278362b1f7b06eab3cb57b9a73
3836
vnc.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\storage\permanent\chrome\idb\727688008bsleotcakcliifsittsr%.sqlite
––
MD5:  ––
SHA256:  ––
3836
vnc.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\storage.sqlite
––
MD5:  ––
SHA256:  ––
3836
vnc.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\storage\permanent\chrome\idb\3561288849sdhlie.sqlite
––
MD5:  ––
SHA256:  ––
3836
vnc.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\storage\permanent\chrome\idb\3899588440psinninpiFn2g%.sqlite
––
MD5:  ––
SHA256:  ––
3836
vnc.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\storage\permanent\chrome\idb\3345959086bslnoocdkdlaiFs2t%s.sqlite.KRAB
mp3
MD5: b1a7094cdff8829ea3c3d8ce8c30c471
SHA256: 49c2c3e6c568a39e5a4fe2ac1814db5eb3e8820cc46e99a9ef85d8b7466a605c
3836
vnc.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\storage\permanent\chrome\idb\3345959086bslnoocdkdlaiFs2t%s.files\KRAB-DECRYPT.txt
text
MD5: a285a299dbaaeaa3588106a648e72592
SHA256: 0826dba102ad61a52719d327e8a6b9c8897f66278362b1f7b06eab3cb57b9a73
3836
vnc.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\storage\permanent\chrome\idb\2918063365piupsah.sqlite.KRAB
binary
MD5: 9bdb76744cbe543fb521bdc4930b464a
SHA256: 4619c3aafccfb0bd160da03162861cb4f50c198fc1158cd18dd45346da0c0b2d
3836
vnc.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\storage\permanent\chrome\idb\3561288849sdhlie.files\KRAB-DECRYPT.txt
text
MD5: a285a299dbaaeaa3588106a648e72592
SHA256: 0826dba102ad61a52719d327e8a6b9c8897f66278362b1f7b06eab3cb57b9a73
3836
vnc.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\storage\permanent\chrome\idb\2918063365piupsah.files\KRAB-DECRYPT.txt
text
MD5: a285a299dbaaeaa3588106a648e72592
SHA256: 0826dba102ad61a52719d327e8a6b9c8897f66278362b1f7b06eab3cb57b9a73
3836
vnc.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\storage\permanent\chrome\idb\1725441852bxlfogcFk2l%isst.sqlite.KRAB
binary
MD5: 2a8b57738825564ebef01367a5336091
SHA256: ec3c0320b2747535187617ebb5dd9e96e15d34add1b381e8d2e00d073f989bd6
3836
vnc.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\storage\permanent\chrome\idb\3345959086bslnoocdkdlaiFs2t%s.sqlite
––
MD5:  ––
SHA256:  ––
3836
vnc.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\storage\permanent\chrome\idb\2918063365piupsah.sqlite
––
MD5:  ––
SHA256:  ––
3836
vnc.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\storage\permanent\chrome\idb\1725441852bxlfogcFk2l%isst.sqlite
––
MD5:  ––
SHA256:  ––
3836
vnc.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\storage\permanent\chrome\idb\1725441852bxlfogcFk2l%isst.files\KRAB-DECRYPT.txt
text
MD5: a285a299dbaaeaa3588106a648e72592
SHA256: 0826dba102ad61a52719d327e8a6b9c8897f66278362b1f7b06eab3cb57b9a73
3836
vnc.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\storage\permanent\chrome\idb\1451318868ntouromlalnodry--epcr.files\KRAB-DECRYPT.txt
text
MD5: a285a299dbaaeaa3588106a648e72592
SHA256: 0826dba102ad61a52719d327e8a6b9c8897f66278362b1f7b06eab3cb57b9a73
3836
vnc.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\storage\permanent\chrome\idb\1657114595AmcateirvtiSty.sqlite.KRAB
binary
MD5: d27b81bf553bc50b8d1084334e5f361d
SHA256: b055f5bbc41960e2fe782231076a4d227675f5205431c867b7d6ba8de0c18ae8
3836
vnc.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\storage\permanent\chrome\idb\1657114595AmcateirvtiSty.files\KRAB-DECRYPT.txt
text
MD5: a285a299dbaaeaa3588106a648e72592
SHA256: 0826dba102ad61a52719d327e8a6b9c8897f66278362b1f7b06eab3cb57b9a73
3836
vnc.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\storage\permanent\chrome\idb\1059394878bslnoicgkullipsFt2s%.sqlite.KRAB
binary
MD5: 611914f062ac2e0fe8d278a754707acc
SHA256: 552400be232d6b40db6b9c65c5ed1e68675454df68afa82e16d5a11b8fea6556
3836
vnc.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\storage\permanent\chrome\idb\1451318868ntouromlalnodry--epcr.sqlite.KRAB
binary
MD5: b9ddfd92a32fe289200996ffa0254d32
SHA256: 2f565a32af3e54f2a6301522634bd403fcbadaf0f70f911e2dc27b4cbccb63fb
3836
vnc.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\storage\permanent\chrome\idb\1451318868ntouromlalnodry--epcr.sqlite
––
MD5:  ––
SHA256:  ––
3836
vnc.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\storage\permanent\chrome\idb\1657114595AmcateirvtiSty.sqlite
––
MD5:  ––
SHA256:  ––
3836
vnc.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\storage\permanent\chrome\idb\1059394878bslnoicgkullipsFt2s%.files\KRAB-DECRYPT.txt
text
MD5: a285a299dbaaeaa3588106a648e72592
SHA256: 0826dba102ad61a52719d327e8a6b9c8897f66278362b1f7b06eab3cb57b9a73
3836
vnc.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\storage\permanent\chrome\idb\1059394878bslnoicgkullipsFt2s%.sqlite
––
MD5:  ––
SHA256:  ––
3836
vnc.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\storage\permanent\chrome\idb\KRAB-DECRYPT.txt
text
MD5: a285a299dbaaeaa3588106a648e72592
SHA256: 0826dba102ad61a52719d327e8a6b9c8897f66278362b1f7b06eab3cb57b9a73
3836
vnc.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\storage\permanent\chrome\.metadata-v2.KRAB
binary
MD5: 34e6c7cadce5914d676fc8ddcb23298d
SHA256: 099073c1620609e2c1ef23b7bc8091ac0cf256972e7a6dd509469b289fae06db
3836
vnc.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\storage\permanent\chrome\.metadata-v2
––
MD5:  ––
SHA256:  ––
3836
vnc.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\storage\permanent\chrome\KRAB-DECRYPT.txt
text
MD5: a285a299dbaaeaa3588106a648e72592
SHA256: 0826dba102ad61a52719d327e8a6b9c8897f66278362b1f7b06eab3cb57b9a73
3836
vnc.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\storage\permanent\chrome\.metadata.KRAB
binary
MD5: 325323417ab977830b574b9fd86c0a25
SHA256: 6d95ee174263194d97ec980d8d621428d0f9184b4b2ef16b7bfb277051d20080
3836
vnc.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\storage\permanent\chrome\.metadata
––
MD5:  ––
SHA256:  ––
3836
vnc.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\storage\default\about+newtab\idb\3312185054sbndi_pspte.files\journals\KRAB-DECRYPT.txt
text
MD5: a285a299dbaaeaa3588106a648e72592
SHA256: 0826dba102ad61a52719d327e8a6b9c8897f66278362b1f7b06eab3cb57b9a73
3836
vnc.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\storage\default\about+newtab\idb\3312185054sbndi_pspte.sqlite.KRAB
ini
MD5: 0aef4e405e4ea463742afab8a679f574
SHA256: 166ac33ca500f4410ba5ee6e48f802a2982ca985b809166caec2e622324cd0b5
3836
vnc.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\storage\permanent\KRAB-DECRYPT.txt
text
MD5: a285a299dbaaeaa3588106a648e72592
SHA256: 0826dba102ad61a52719d327e8a6b9c8897f66278362b1f7b06eab3cb57b9a73
3836
vnc.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\storage\default\about+newtab\idb\3312185054sbndi_pspte.sqlite
––
MD5:  ––
SHA256:  ––
3836
vnc.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\storage\default\about+newtab\idb\3312185054sbndi_pspte.files\1
––
MD5:  ––
SHA256:  ––
3836
vnc.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\storage\default\about+newtab\idb\3312185054sbndi_pspte.files\1.KRAB
––
MD5:  ––
SHA256:  ––
3836
vnc.exe
C:\Users\Public\Videos\Sample Videos\Wildlife.wmv
––
MD5:  ––
SHA256:  ––
3836
vnc.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\storage\default\about+newtab\.metadata-v2.KRAB
binary
MD5: 3f20fad91524c8d49e7acebf15eb9834
SHA256: ba0260a5418810571c3b59574907f59ba063c5c64dc1297ef204d08117363216
3836
vnc.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\storage\default\about+newtab\KRAB-DECRYPT.txt
text
MD5: a285a299dbaaeaa3588106a648e72592
SHA256: 0826dba102ad61a52719d327e8a6b9c8897f66278362b1f7b06eab3cb57b9a73
3836
vnc.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\storage\default\about+home\idb\3312185054sbndi_pspte.files\journals\KRAB-DECRYPT.txt
text
MD5: a285a299dbaaeaa3588106a648e72592
SHA256: 0826dba102ad61a52719d327e8a6b9c8897f66278362b1f7b06eab3cb57b9a73
3836
vnc.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\storage\default\about+newtab\.metadata.KRAB
binary
MD5: 54041908212418ef0e9d342f0fde2c38
SHA256: 22c0d084da87a3612625ef8534120f5cb72829bc9fd73740e8521786d7868737
3836
vnc.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\storage\default\about+newtab\idb\3312185054sbndi_pspte.files\KRAB-DECRYPT.txt
text
MD5: a285a299dbaaeaa3588106a648e72592
SHA256: 0826dba102ad61a52719d327e8a6b9c8897f66278362b1f7b06eab3cb57b9a73
3836
vnc.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\storage\default\about+newtab\idb\KRAB-DECRYPT.txt
text
MD5: a285a299dbaaeaa3588106a648e72592
SHA256: 0826dba102ad61a52719d327e8a6b9c8897f66278362b1f7b06eab3cb57b9a73
3836
vnc.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\storage\default\about+newtab\.metadata-v2
––
MD5:  ––
SHA256:  ––
3836
vnc.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\storage\default\about+newtab\.metadata
––
MD5:  ––
SHA256:  ––
3836
vnc.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\storage\default\about+home\idb\3312185054sbndi_pspte.sqlite
––
MD5:  ––
SHA256:  ––
3836
vnc.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\storage\default\about+home\idb\3312185054sbndi_pspte.files\1.KRAB
––
MD5:  ––
SHA256:  ––
3836
vnc.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\storage\default\about+home\idb\3312185054sbndi_pspte.files\1
––
MD5:  ––
SHA256:  ––
3836
vnc.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\storage\default\about+home\.metadata-v2.KRAB
binary
MD5: c62e5a47ca0cd6d2347733c994c36bcf
SHA256: e6d6dab6501a69fcb29fb4d4572a669217af0e0fe25c32d14ae85eebe16da3f9
3836
vnc.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\storage\default\KRAB-DECRYPT.txt
text
MD5: a285a299dbaaeaa3588106a648e72592
SHA256: 0826dba102ad61a52719d327e8a6b9c8897f66278362b1f7b06eab3cb57b9a73
3836
vnc.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\storage\default\about+home\KRAB-DECRYPT.txt
text
MD5: a285a299dbaaeaa3588106a648e72592
SHA256: 0826dba102ad61a52719d327e8a6b9c8897f66278362b1f7b06eab3cb57b9a73
3836
vnc.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\storage\KRAB-DECRYPT.txt
text
MD5: a285a299dbaaeaa3588106a648e72592
SHA256: 0826dba102ad61a52719d327e8a6b9c8897f66278362b1f7b06eab3cb57b9a73
3836
vnc.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\storage\default\about+home\.metadata.KRAB
binary
MD5: 530400a0d81484dd1f113c33acd96471
SHA256: 3a9d69888c2242eb1458106d237254041fcd53c4a7568c5230858754e5465bf0
3836
vnc.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\storage\default\about+home\idb\KRAB-DECRYPT.txt
text
MD5: a285a299dbaaeaa3588106a648e72592
SHA256: 0826dba102ad61a52719d327e8a6b9c8897f66278362b1f7b06eab3cb57b9a73
3836
vnc.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\storage\default\about+home\idb\3312185054sbndi_pspte.files\KRAB-DECRYPT.txt
text
MD5: a285a299dbaaeaa3588106a648e72592
SHA256: 0826dba102ad61a52719d327e8a6b9c8897f66278362b1f7b06eab3cb57b9a73
3836
vnc.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\storage\default\about+home\.metadata
––
MD5:  ––
SHA256:  ––
3836
vnc.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\storage\default\about+home\.metadata-v2
––
MD5:  ––
SHA256:  ––
3836
vnc.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\SiteSecurityServiceState.txt.KRAB
binary
MD5: f1c262ad4f66fe00c615369dc7ac6934
SHA256: 04be6d2c9853df6a688cefe5ec03f8be120d42e1d379d168fc55341ac8f9f544
3836
vnc.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\sessionCheckpoints.json.KRAB
binary
MD5: 92aa21935f27eef0beb898e48794acbe
SHA256: df5278d23508bbcd069729bc7a77db62eac5e11bfdad76152b0824dccd6ee28d
3836
vnc.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\sessionstore-backups\KRAB-DECRYPT.txt
text
MD5: a285a299dbaaeaa3588106a648e72592
SHA256: 0826dba102ad61a52719d327e8a6b9c8897f66278362b1f7b06eab3cb57b9a73
3836
vnc.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\revocations.txt.KRAB
binary
MD5: 25c9030f1585e2328ca4de54a5a52ce9
SHA256: a70c3fcd4037656fdebcfb845fce0494be4d071294d4ee4525f4a008c0afaa5f
3836
vnc.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\saved-telemetry-pings\KRAB-DECRYPT.txt
text
MD5: a285a299dbaaeaa3588106a648e72592
SHA256: 0826dba102ad61a52719d327e8a6b9c8897f66278362b1f7b06eab3cb57b9a73
3836
vnc.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\sessionstore.jsonlz4.KRAB
binary
MD5: c07d35ac18b7883b5de1b4d353ed6949
SHA256: acda955488657e369b947b6cf029f09e2c8a998242b0494fd9a5a68505587934
3836
vnc.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\search.json.mozlz4.KRAB
binary
MD5: 7f7b0dcfae7d24341e113c3c36edfe55
SHA256: fd0f78f69cc0ddcefc103abac4aadfe7bcf941bf4fd99c9562756dd6d1ca9c1c
3836
vnc.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\sessionstore-backups\previous.jsonlz4.KRAB
vc
MD5: 870d2fc9da80fc14bb1c69d89d0e8cb7
SHA256: d13c06993da3297e2427c36590de2d838cb398f7105afa211affc28a7e591e78
3836
vnc.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\SiteSecurityServiceState.txt
––
MD5:  ––
SHA256:  ––
3836
vnc.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\search.json.mozlz4
––
MD5:  ––
SHA256:  ––
3836
vnc.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\sessionCheckpoints.json
––
MD5:  ––
SHA256:  ––
3836
vnc.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\sessionstore-backups\previous.jsonlz4
––
MD5:  ––
SHA256:  ––
3836
vnc.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\sessionstore.jsonlz4
––
MD5:  ––
SHA256:  ––
3836
vnc.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\pluginreg.dat.KRAB
binary
MD5: 83fb0b6a79fa02a95a00ec058f0d1d6c
SHA256: f066929edb77cb7c8f93dacd1109d7a5fc714586064b806f4462f42c3d3e3bc0
3836
vnc.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\prefs.js.KRAB
binary
MD5: 30144b9f2eb103b9c8ea738be0feda49
SHA256: a4540835010d637409f9f043cf73f9a2aad0f7d29be69e3e76ac09021e7f74d0
3836
vnc.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\revocations.txt
––
MD5:  ––
SHA256:  ––
3836
vnc.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\pluginreg.dat
––
MD5:  ––
SHA256:  ––
3836
vnc.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\prefs.js
––
MD5:  ––
SHA256:  ––
3836
vnc.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\places.sqlite
––
MD5:  ––
SHA256:  ––
3836
vnc.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\places.sqlite.KRAB
––
MD5:  ––
SHA256:  ––
3836
vnc.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\permissions.sqlite.KRAB
binary
MD5: fbdb8b2758f668a23b793030c3e5e05f
SHA256: 47d40ba738a4b34e4154bd9c61da7f660808b77f8ddf82b1e125d44937b56285
3836
vnc.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\pkcs11.txt.KRAB
binary
MD5: c69a8e10b4f0d30264f62e30315ce809
SHA256: e23dfbbd84c0244e81efe25b92ff2a35c54f0d49de88fc07beb394603ea9e0a0
3836
vnc.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\pkcs11.txt
––
MD5:  ––
SHA256:  ––
3836
vnc.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\permissions.sqlite
––
MD5:  ––
SHA256:  ––
3836
vnc.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\gmp-widevinecdm\1.4.8.1008\widevinecdm.dll.lib.KRAB
binary
MD5: 5804816b75a195a22d4d20097b256acc
SHA256: dc37027278f2ed801f300c223af4162d51b1824304ce08868fdfeda434932b30
3836
vnc.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\minidumps\KRAB-DECRYPT.txt
text
MD5: a285a299dbaaeaa3588106a648e72592
SHA256: 0826dba102ad61a52719d327e8a6b9c8897f66278362b1f7b06eab3cb57b9a73
3836
vnc.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\handlers.json.KRAB
binary
MD5: e910fc24088607af296f72c96a5e86ae
SHA256: d1deea373c3184423684e47d7f469e0a8115d9f31091a6738ffb9d9e8994b98f
3836
vnc.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\logins.json.KRAB
binary
MD5: 9bb361a47dcc26695c23477b955a94f8
SHA256: 7e040dfc7e0802dc3e6a626fc68e7870d356a99a51dc7027cba816039d8cc3bd
3836
vnc.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\key4.db.KRAB
binary
MD5: c740202729168d7b555bbf33eb08d8bc
SHA256: c1d5bc0152bd3bc73dff175ce1378afc31daa4b269f51726ae108c149413cb66
3836
vnc.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\gmp-widevinecdm\1.4.8.1008\widevinecdm.dll.sig.KRAB
binary
MD5: 9e782a60cbb5f910a0a56e257309ecc8
SHA256: 89a812fe0a805decfd9e75c7cdb0baafe5bb6f2d0ae5c3050ece789ae3cd31b8
3836
vnc.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\gmp-widevinecdm\1.4.8.1008\widevinecdm.dll.sig
––
MD5:  ––
SHA256:  ––
3836
vnc.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\key4.db
––
MD5:  ––
SHA256:  ––
3836
vnc.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\logins.json
––
MD5:  ––
SHA256:  ––
3836
vnc.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\gmp-widevinecdm\1.4.8.1008\widevinecdm.dll.lib
––
MD5:  ––
SHA256:  ––
3836
vnc.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\handlers.json
––
MD5:  ––
SHA256:  ––
3836
vnc.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\gmp-gmpopenh264\1.7.1\KRAB-DECRYPT.txt
text
MD5: a285a299dbaaeaa3588106a648e72592
SHA256: 0826dba102ad61a52719d327e8a6b9c8897f66278362b1f7b06eab3cb57b9a73
3836
vnc.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\gmp-widevinecdm\KRAB-DECRYPT.txt
text
MD5: a285a299dbaaeaa3588106a648e72592
SHA256: 0826dba102ad61a52719d327e8a6b9c8897f66278362b1f7b06eab3cb57b9a73
3836
vnc.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\gmp-widevinecdm\1.4.8.1008\manifest.json.KRAB
binary
MD5: 741c99a0458ef93d7ca03592b8b74fd1
SHA256: b612e5a8a26db34e755d34ff7f381d86150d9d14c7709eab86e93771463175b3
3836
vnc.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\formhistory.sqlite.KRAB
binary
MD5: 88760f2ae2316820062f41fb2384c8dc
SHA256: 2a87923403a739c79ee42a705da912de595daad423b31538c147d5a2db62b873
3836
vnc.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\gmp-widevinecdm\1.4.8.1008\KRAB-DECRYPT.txt
text
MD5: a285a299dbaaeaa3588106a648e72592
SHA256: 0826dba102ad61a52719d327e8a6b9c8897f66278362b1f7b06eab3cb57b9a73
3836
vnc.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\gmp\KRAB-DECRYPT.txt
text
MD5: a285a299dbaaeaa3588106a648e72592
SHA256: 0826dba102ad61a52719d327e8a6b9c8897f66278362b1f7b06eab3cb57b9a73
3836
vnc.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\gmp-gmpopenh264\1.7.1\gmpopenh264.info.KRAB
binary
MD5: 81f67442d21424266def60626f9dff58
SHA256: 67a27d5787d14ae399eaee71ae6eddbb84fd8c14ddb0c305bf6c220f74f7b312
3836
vnc.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\gmp\WINNT_x86-msvc\KRAB-DECRYPT.txt
text
MD5: a285a299dbaaeaa3588106a648e72592
SHA256: 0826dba102ad61a52719d327e8a6b9c8897f66278362b1f7b06eab3cb57b9a73
3836
vnc.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\gmp-widevinecdm\1.4.8.1008\LICENSE.txt.KRAB
binary
MD5: ee5cd986182a83d43a3ff57e67a3c355
SHA256: d8b41a2f5e5173aaeec1daaadcc6568d4d5ccab85b3f6a67cf71a781167ba03e
3836
vnc.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\gmp-gmpopenh264\KRAB-DECRYPT.txt
text
MD5: a285a299dbaaeaa3588106a648e72592
SHA256: 0826dba102ad61a52719d327e8a6b9c8897f66278362b1f7b06eab3cb57b9a73
3836
vnc.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\gmp-gmpopenh264\1.7.1\gmpopenh264.info
––
MD5:  ––
SHA256:  ––
3836
vnc.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\gmp-widevinecdm\1.4.8.1008\LICENSE.txt
––
MD5:  ––
SHA256:  ––
3836
vnc.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\formhistory.sqlite
––
MD5:  ––
SHA256:  ––
3836
vnc.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\gmp-widevinecdm\1.4.8.1008\manifest.json
––
MD5:  ––
SHA256:  ––
3836
vnc.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\favicons.sqlite.KRAB
––
MD5:  ––
SHA256:  ––
3836
vnc.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\favicons.sqlite
––
MD5:  ––
SHA256:  ––
3836
vnc.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\datareporting\state.json.KRAB
binary
MD5: d47207f2fd7e72e0153278a539c2218c
SHA256: da9f065393b811160e512fc5e04cbe05f0c7cbd4a74cec11905770e76ea9a60d
3836
vnc.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\extensions.json.KRAB
binary
MD5: 97b9be9dc2b6c03b9384d23e4be6ddea
SHA256: 30a934c49ea879e1cf1ce9176df5d46c385c85e12dc6fe2c5db28abc3e389baa
3836
vnc.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\datareporting\archived\2018-09\1536510890757.0bd2c0b0-6051-4678-a27c-37f3c0a0c3bf.main.jsonlz4.KRAB
binary
MD5: 10e584bb48e3a1c5d5cd27229906936c
SHA256: e411d5dbc6a867a16d084d28635bc028c4d727ff31124b05162449930d8f7c11
3836
vnc.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\datareporting\session-state.json.KRAB
binary
MD5: b9116e75cf2850ae59761aa0bcb4aec7
SHA256: 1f33d2388c0b720bf91c01bef068dbf07bf3718b10e459e8211c704716c548bb
3836
vnc.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\datareporting\archived\2018-09\1536511076670.6fb1a61f-96c8-4004-a260-a8d32e45a07f.main.jsonlz4.KRAB
binary
MD5: b34c3f116bd4f919ac4a60a9ac8b44ff
SHA256: c2619bac837dac8b67e2b8c6d9b2402bb63738e3b30814ebdf7d0af861769a02
3836
vnc.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\datareporting\archived\2018-09\1536510464398.048632c6-c96b-486d-b119-7e1a7a9c9e9a.main.jsonlz4.KRAB
binary
MD5: 363c4c5dd64ad586c3e518877f78e794
SHA256: b040934b9b65f514f31b73b87a4ebe8e637898b0a556bab85a53566b80f5b1d3
3836
vnc.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\datareporting\archived\2018-09\1536510464398.048632c6-c96b-486d-b119-7e1a7a9c9e9a.main.jsonlz4
––
MD5:  ––
SHA256:  ––
3836
vnc.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\datareporting\archived\2018-09\1536510890757.0bd2c0b0-6051-4678-a27c-37f3c0a0c3bf.main.jsonlz4
––
MD5:  ––
SHA256:  ––
3836
vnc.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\datareporting\archived\2018-09\1536511076670.6fb1a61f-96c8-4004-a260-a8d32e45a07f.main.jsonlz4
––
MD5:  ––
SHA256:  ––
3836
vnc.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\datareporting\session-state.json
––
MD5:  ––
SHA256:  ––
3836
vnc.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\datareporting\state.json
––
MD5:  ––
SHA256:  ––
3836
vnc.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\extensions.json
––
MD5:  ––
SHA256:  ––
3836
vnc.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\datareporting\archived\2018-08\1535454581431.ff499cec-8d4b-47de-a059-a9aea3d69a66.main.jsonlz4.KRAB
binary
MD5: 1e2c9bea074ecf90cec40fcd5bbf4d9a
SHA256: 107a6bc13712835bb00ef9adbb6cb199bc0678beca99b54b84e610faaf8699b5
3836
vnc.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\datareporting\archived\2018-08\1535454589776.07f73e80-2b12-40ae-97b0-fa87f3167670.main.jsonlz4.KRAB
binary
MD5: ae1267453056edaa9c62b4b79d52ee36
SHA256: fa36cfa752e9ee5f32f2ff38d75efc62bd27d9429cbcdce72c50e6964ae88cc8
3836
vnc.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\datareporting\archived\2018-08\1535454589777.8901d324-d310-406e-8d96-2ba1529e4bea.first-shutdown.jsonlz4.KRAB
binary
MD5: 1548fc39446cc807b75f5ed56e002b5f
SHA256: 46084257353bc48bfc682f9076d8769d52a914e9cb628f26584d0f107b80b1d0
3836
vnc.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\datareporting\archived\2018-08\1535455254239.6a6d1f6c-b378-42bd-83d4-6375a8d83c94.main.jsonlz4.KRAB
binary
MD5: 6e601f9984894ebefff2f309623816cc
SHA256: 90d607ef270467c043ef136119bfb3183ec0857f11934052a245a96449faa849
3836
vnc.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\datareporting\archived\2018-08\1535454589752.05c13197-8f39-40a1-b976-59f6f9c1cc5f.new-profile.jsonlz4.KRAB
binary
MD5: 4c4401469f522e8165ee3ea730454f08
SHA256: 6bd678199d53ff2e10354a2a2611dbbc3a64d6fcf23c9eb822672cf831ecf0eb
3836
vnc.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\datareporting\archived\2018-09\KRAB-DECRYPT.txt
text
MD5: a285a299dbaaeaa3588106a648e72592
SHA256: 0826dba102ad61a52719d327e8a6b9c8897f66278362b1f7b06eab3cb57b9a73
3836
vnc.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\datareporting\archived\2018-08\1535455254239.6a6d1f6c-b378-42bd-83d4-6375a8d83c94.main.jsonlz4
––
MD5:  ––
SHA256:  ––
3836
vnc.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\datareporting\archived\2018-08\1535454589777.8901d324-d310-406e-8d96-2ba1529e4bea.first-shutdown.jsonlz4
––
MD5:  ––
SHA256:  ––
3836
vnc.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\datareporting\archived\2018-08\1535454589776.07f73e80-2b12-40ae-97b0-fa87f3167670.main.jsonlz4
––
MD5:  ––
SHA256:  ––
3836
vnc.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\datareporting\archived\2018-08\1535454589752.05c13197-8f39-40a1-b976-59f6f9c1cc5f.new-profile.jsonlz4
––
MD5:  ––
SHA256:  ––
3836
vnc.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\datareporting\archived\2018-08\KRAB-DECRYPT.txt
text
MD5: a285a299dbaaeaa3588106a648e72592
SHA256: 0826dba102ad61a52719d327e8a6b9c8897f66278362b1f7b06eab3cb57b9a73
3836
vnc.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\crashes\events\KRAB-DECRYPT.txt
text
MD5: a285a299dbaaeaa3588106a648e72592
SHA256: 0826dba102ad61a52719d327e8a6b9c8897f66278362b1f7b06eab3cb57b9a73
3836
vnc.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\datareporting\archived\KRAB-DECRYPT.txt
text
MD5: a285a299dbaaeaa3588106a648e72592
SHA256: 0826dba102ad61a52719d327e8a6b9c8897f66278362b1f7b06eab3cb57b9a73
3836
vnc.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\crashes\store.json.mozlz4.KRAB
binary
MD5: 96429cd4517fd5d91ed8744a5b3bab16
SHA256: 379c3f1d8e57d99e4dd928b31381df59bb96846cc1bcb32c7c122d173c724607
3836
vnc.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\datareporting\KRAB-DECRYPT.txt
text
MD5: a285a299dbaaeaa3588106a648e72592
SHA256: 0826dba102ad61a52719d327e8a6b9c8897f66278362b1f7b06eab3cb57b9a73
3836
vnc.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\crashes\KRAB-DECRYPT.txt
text
MD5: a285a299dbaaeaa3588106a648e72592
SHA256: 0826dba102ad61a52719d327e8a6b9c8897f66278362b1f7b06eab3cb57b9a73
3836
vnc.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\cookies.sqlite.KRAB
binary
MD5: 7f68398e5d4c56dfec3d1f5414c2d9c2
SHA256: 431ae7046db3deef814e71e99faf3e3e8a2cdb8d20aaa1ebbbd2e0d52f83e1a1
3836
vnc.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\datareporting\archived\2018-08\1535454581431.ff499cec-8d4b-47de-a059-a9aea3d69a66.main.jsonlz4
––
MD5:  ––
SHA256:  ––
3836
vnc.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\cookies.sqlite
––
MD5:  ––
SHA256:  ––
3836
vnc.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\crashes\store.json.mozlz4
––
MD5:  ––
SHA256:  ––
3836
vnc.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\containers.json.KRAB
bs
MD5: b480cbb19afd253b048d3421f936ca02
SHA256: 5bf1a54ea55295a68439f73b4941ef34e551b7f30a67dc3a065cf5017f241cae
3836
vnc.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\content-prefs.sqlite.KRAB
binary
MD5: ff32ace9164e5d292eacaa8fb34255c7
SHA256: cb2bb0262bfa22ae6ab1afacd18c4255ad2ff5d118252e682a83cf5a4407eff6
3836
vnc.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\bookmarkbackups\KRAB-DECRYPT.txt
text
MD5: a285a299dbaaeaa3588106a648e72592
SHA256: 0826dba102ad61a52719d327e8a6b9c8897f66278362b1f7b06eab3cb57b9a73
3836
vnc.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\blocklists\plugins.json.KRAB
binary
MD5: f0c4552082d5ddaebe9070f43edc4b61
SHA256: e2aaf07b87801b40f038ee5d520a1b668c170530849d19d6d26e3156f13d08a0
3836
vnc.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\cert9.db.KRAB
binary
MD5: f01d356d05c2452b6b8c613a2fc8964b
SHA256: f299df93a54586fac17f4db2763afd8085901781cad461d00b51981fa5384188
3836
vnc.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\compatibility.ini.KRAB
binary
MD5: 343a96d021c5d7cfff64d06ed966951c
SHA256: 38653c7850d964f2da4c4de85185acd2b165e20e05c978d7f0a5b51485d2f2a7
3836
vnc.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\bookmarkbackups\bookmarks-2018-08-28_14_uZyx1cMFmZ7ZpL4NneCk2A==.jsonlz4.KRAB
binary
MD5: 19fe795b311cf99e9a94f50465da98b3
SHA256: 381a7e2051e755feccb116c6faa4eda4d72b46df833ddd2c2c93fee48c6a9c12
3836
vnc.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\cert9.db
––
MD5:  ––
SHA256:  ––
3836
vnc.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\content-prefs.sqlite
––
MD5:  ––
SHA256:  ––
3836
vnc.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\containers.json
––
MD5:  ––
SHA256:  ––
3836
vnc.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\bookmarkbackups\bookmarks-2018-08-28_14_uZyx1cMFmZ7ZpL4NneCk2A==.jsonlz4
––
MD5:  ––
SHA256:  ––
3836
vnc.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\compatibility.ini
––
MD5:  ––
SHA256:  ––
3836
vnc.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\blocklists\addons.json.KRAB
binary
MD5: d8524a4bcbe208dd27c9f83db836a2a1
SHA256: 177a5a1a9364e2712f9cc2914e7a5379fe24f6769468a8531468120507d15d58
3836
vnc.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\blocklists\KRAB-DECRYPT.txt
text
MD5: a285a299dbaaeaa3588106a648e72592
SHA256: 0826dba102ad61a52719d327e8a6b9c8897f66278362b1f7b06eab3cb57b9a73
3836
vnc.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\blocklists\addons.json
––
MD5:  ––
SHA256:  ––
3836
vnc.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\blocklists\plugins.json
––
MD5:  ––
SHA256:  ––
3836
vnc.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\blocklist.xml.KRAB
binary
MD5: 1894e35d494e40940ba7ed2fed1f797c
SHA256: 2493aacbb02cee783912130460cf015736cd0a5c1947cbdf21a5afb0d1aee832
3836
vnc.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\KRAB-DECRYPT.txt
text
MD5: a285a299dbaaeaa3588106a648e72592
SHA256: 0826dba102ad61a52719d327e8a6b9c8897f66278362b1f7b06eab3cb57b9a73
3836
vnc.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\KRAB-DECRYPT.txt
text
MD5: a285a299dbaaeaa3588106a648e72592
SHA256: 0826dba102ad61a52719d327e8a6b9c8897f66278362b1f7b06eab3cb57b9a73
3836
vnc.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\addons.json.KRAB
binary
MD5: 0446254b4f0f02f44b9399a734fca348
SHA256: 42a7cfc8d53b4d3ab87790f9b32e1dd3aa0301b099094a57b0efce02b9254ce3
3836
vnc.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\addonStartup.json.lz4.KRAB
binary
MD5: c5fdc3b35d92d786a80c86a0c1345a8c
SHA256: 445941d821326bafe3384d2bdfdb826f11723866f733b37912d14407f9a5951e
3836
vnc.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Pending Pings\KRAB-DECRYPT.txt
text
MD5: a285a299dbaaeaa3588106a648e72592
SHA256: 0826dba102ad61a52719d327e8a6b9c8897f66278362b1f7b06eab3cb57b9a73
3836
vnc.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\addons.json
––
MD5:  ––
SHA256:  ––
3836
vnc.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\addonStartup.json.lz4
––
MD5:  ––
SHA256:  ––
3836
vnc.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\blocklist.xml
––
MD5:  ––
SHA256:  ––
3836
vnc.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Crash Reports\InstallTime20180807170231.KRAB
binary
MD5: b896fc01070ec1e00d0a35b3e45a288d
SHA256: 0cb510c056e5ef978cd3f1e5734ab0f14a46b9d7f2e0ad6e241e0c58a81efcd9
3836
vnc.exe
C:\Users\admin\AppData\Roaming\Microsoft\Vault\KRAB-DECRYPT.txt
text
MD5: a285a299dbaaeaa3588106a648e72592
SHA256: 0826dba102ad61a52719d327e8a6b9c8897f66278362b1f7b06eab3cb57b9a73
3836
vnc.exe
C:\Users\admin\AppData\Roaming\Mozilla\Extensions\KRAB-DECRYPT.txt
text
MD5: a285a299dbaaeaa3588106a648e72592
SHA256: 0826dba102ad61a52719d327e8a6b9c8897f66278362b1f7b06eab3cb57b9a73
3836
vnc.exe
C:\Users\admin\AppData\Roaming\Microsoft\UProof\CUSTOM.DIC.KRAB
binary
MD5: ab8f129a8387ba7f52c8ae2431fea8c6
SHA256: ca37f23329041205968cf9f4790060b1886196191fc639d5600ad00e8a5fc3c5
3836
vnc.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Crash Reports\events\KRAB-DECRYPT.txt
text
MD5: a285a299dbaaeaa3588106a648e72592
SHA256: 0826dba102ad61a52719d327e8a6b9c8897f66278362b1f7b06eab3cb57b9a73
3836
vnc.exe
C:\Users\admin\AppData\Roaming\Mozilla\KRAB-DECRYPT.txt
text
MD5: a285a299dbaaeaa3588106a648e72592
SHA256: 0826dba102ad61a52719d327e8a6b9c8897f66278362b1f7b06eab3cb57b9a73
3836
vnc.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Crash Reports\KRAB-DECRYPT.txt
text
MD5: a285a299dbaaeaa3588106a648e72592
SHA256: 0826dba102ad61a52719d327e8a6b9c8897f66278362b1f7b06eab3cb57b9a73
3836
vnc.exe
C:\Users\admin\AppData\Roaming\Microsoft\Word\STARTUP\KRAB-DECRYPT.txt
text
MD5: a285a299dbaaeaa3588106a648e72592
SHA256: 0826dba102ad61a52719d327e8a6b9c8897f66278362b1f7b06eab3cb57b9a73
3836
vnc.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\KRAB-DECRYPT.txt
text
MD5: a285a299dbaaeaa3588106a648e72592
SHA256: 0826dba102ad61a52719d327e8a6b9c8897f66278362b1f7b06eab3cb57b9a73
3836
vnc.exe
C:\Users\admin\AppData\Roaming\Microsoft\Word\KRAB-DECRYPT.txt
text
MD5: a285a299dbaaeaa3588106a648e72592
SHA256: 0826dba102ad61a52719d327e8a6b9c8897f66278362b1f7b06eab3cb57b9a73
3836
vnc.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Crash Reports\InstallTime20180807170231
––
MD5:  ––
SHA256:  ––
3836
vnc.exe
C:\Users\admin\AppData\Roaming\Microsoft\Templates\LiveContent\KRAB-DECRYPT.txt
text
MD5: a285a299dbaaeaa3588106a648e72592
SHA256: 0826dba102ad61a52719d327e8a6b9c8897f66278362b1f7b06eab3cb57b9a73
3836
vnc.exe
C:\Users\admin\AppData\Roaming\Microsoft\Templates\LiveContent\Managed\Access Parts\KRAB-DECRYPT.txt
text
MD5: a285a299dbaaeaa3588106a648e72592
SHA256: 0826dba102ad61a52719d327e8a6b9c8897f66278362b1f7b06eab3cb57b9a73
3836
vnc.exe
C:\Users\admin\AppData\Roaming\Microsoft\UProof\KRAB-DECRYPT.txt
text
MD5: a285a299dbaaeaa3588106a648e72592
SHA256: 0826dba102ad61a52719d327e8a6b9c8897f66278362b1f7b06eab3cb57b9a73
3836
vnc.exe
C:\Users\admin\AppData\Roaming\Microsoft\Templates\NormalEmail.dotm.KRAB
binary
MD5: f5ba877c348a56f91a9c79a593469b94
SHA256: cf9ac47eb084ee09e040c9bbc17a387137d19f56b9f46714d20d2a0fd8c93243
3836
vnc.exe
C:\Users\admin\AppData\Roaming\Microsoft\Templates\LiveContent\Managed\Access Parts\1033\KRAB-DECRYPT.txt
text
MD5: a285a299dbaaeaa3588106a648e72592
SHA256: 0826dba102ad61a52719d327e8a6b9c8897f66278362b1f7b06eab3cb57b9a73
3836
vnc.exe
C:\Users\admin\AppData\Roaming\Microsoft\Templates\KRAB-DECRYPT.txt
text
MD5: a285a299dbaaeaa3588106a648e72592
SHA256: 0826dba102ad61a52719d327e8a6b9c8897f66278362b1f7b06eab3cb57b9a73
3836
vnc.exe
C:\Users\admin\AppData\Roaming\Microsoft\Templates\Normal.dotm.KRAB
binary
MD5: 560ede489437c656e1d986da16fcd824
SHA256: da93ef5c0eac459fc213553044c4896de944e9664016759c34ae5bf171dc5d5c
3836
vnc.exe
C:\Users\admin\AppData\Roaming\Microsoft\SystemCertificates\My\Keys\ECCD4BA46722CB4F92060701865DDF09D8AF68B4.KRAB
gpg
MD5: 09387413069446a5ee437622f9effc61
SHA256: 5c88c9349f1cf0663bb296c2c3c94162a00185ef702305cb75d8ffc0c7e016ef
3836
vnc.exe
C:\Users\admin\AppData\Roaming\Microsoft\Templates\LiveContent\Managed\KRAB-DECRYPT.txt
text
MD5: a285a299dbaaeaa3588106a648e72592
SHA256: 0826dba102ad61a52719d327e8a6b9c8897f66278362b1f7b06eab3cb57b9a73
3836
vnc.exe
C:\Users\admin\AppData\Roaming\Microsoft\SystemCertificates\My\Keys\KRAB-DECRYPT.txt
text
MD5: a285a299dbaaeaa3588106a648e72592
SHA256: 0826dba102ad61a52719d327e8a6b9c8897f66278362b1f7b06eab3cb57b9a73
3836
vnc.exe
C:\Users\admin\AppData\Roaming\Microsoft\Templates\NormalEmail.dotm
––
MD5:  ––
SHA256:  ––
3836
vnc.exe
C:\Users\admin\AppData\Roaming\Microsoft\UProof\CUSTOM.DIC
––
MD5:  ––
SHA256:  ––
3836
vnc.exe
C:\Users\admin\AppData\Roaming\Microsoft\SystemCertificates\My\Keys\ECCD4BA46722CB4F92060701865DDF09D8AF68B4
––
MD5:  ––
SHA256:  ––
3836
vnc.exe
C:\Users\admin\AppData\Roaming\Microsoft\Templates\Normal.dotm
––
MD5:  ––
SHA256:  ––
3836
vnc.exe
C:\Users\admin\AppData\Roaming\Microsoft\Skype for Desktop\skylib\slimcore-0-4223384469.blog.KRAB
binary
MD5: 61af0444214e169c659f9fd252d831cb
SHA256: e07eefa06e353e0d031f456d2d1183b2af18cafdc3fd48816cf2de24f7756084
3836
vnc.exe
C:\Users\admin\AppData\Roaming\Microsoft\SystemCertificates\My\CTLs\KRAB-DECRYPT.txt
text
MD5: a285a299dbaaeaa3588106a648e72592
SHA256: 0826dba102ad61a52719d327e8a6b9c8897f66278362b1f7b06eab3cb57b9a73
3836
vnc.exe
C:\Users\admin\AppData\Roaming\Microsoft\SystemCertificates\My\Certificates\KRAB-DECRYPT.txt
text
MD5: a285a299dbaaeaa3588106a648e72592
SHA256: 0826dba102ad61a52719d327e8a6b9c8897f66278362b1f7b06eab3cb57b9a73
3836
vnc.exe
C:\Users\admin\AppData\Roaming\Microsoft\Skype for Desktop\skylib\shared.xml.KRAB
binary
MD5: d0d29728a5944c3913a9c4c5ce49d904
SHA256: e50760e83d84e6e9a4327e257e1c5900cdf05a3d85df48610df4061e5be9e47a
3836
vnc.exe
C:\Users\admin\AppData\Roaming\Microsoft\SystemCertificates\My\Certificates\E02357FC7708441D4B0BE5F371F4B28961870F70.KRAB
binary
MD5: 8edd3cbdabd479dfce633f4b27b459e1
SHA256: 1370a2165b60737a84c5dd5ca435d38e0c7ed3709613e60300846d2e921f3c1e
3836
vnc.exe
C:\Users\admin\AppData\Roaming\Microsoft\SystemCertificates\My\KRAB-DECRYPT.txt
text
MD5: a285a299dbaaeaa3588106a648e72592
SHA256: 0826dba102ad61a52719d327e8a6b9c8897f66278362b1f7b06eab3cb57b9a73
3836
vnc.exe
C:\Users\admin\AppData\Roaming\Microsoft\SystemCertificates\My\CRLs\KRAB-DECRYPT.txt
text
MD5: a285a299dbaaeaa3588106a648e72592
SHA256: 0826dba102ad61a52719d327e8a6b9c8897f66278362b1f7b06eab3cb57b9a73
3836
vnc.exe
C:\Users\admin\AppData\Roaming\Microsoft\Skype for Desktop\skylib\live#3agabriel.radrigos\main.db-journal.KRAB
binary
MD5: b516e4d3819afb3f6bc22cbe8cc1a00b
SHA256: bdee3cb3d2ad3cc42915ea579b96bb4a1b0e93f85d3317c1a88dfd20849bd97f
3836
vnc.exe
C:\Users\admin\AppData\Roaming\Microsoft\Stationery\KRAB-DECRYPT.txt
text
MD5: a285a299dbaaeaa3588106a648e72592
SHA256: 0826dba102ad61a52719d327e8a6b9c8897f66278362b1f7b06eab3cb57b9a73
3836
vnc.exe
C:\Users\admin\AppData\Roaming\Microsoft\SystemCertificates\KRAB-DECRYPT.txt
text
MD5: a285a299dbaaeaa3588106a648e72592
SHA256: 0826dba102ad61a52719d327e8a6b9c8897f66278362b1f7b06eab3cb57b9a73
3836
vnc.exe
C:\Users\admin\AppData\Roaming\Microsoft\Speech\KRAB-DECRYPT.txt
text
MD5: a285a299dbaaeaa3588106a648e72592
SHA256: 0826dba102ad61a52719d327e8a6b9c8897f66278362b1f7b06eab3cb57b9a73
3836
vnc.exe
C:\Users\admin\AppData\Roaming\Microsoft\Skype for Desktop\skylib\live#3agabriel.radrigos\main.db-journal
––
MD5:  ––
SHA256:  ––
3836
vnc.exe
C:\Users\admin\AppData\Roaming\Microsoft\Skype for Desktop\skylib\shared.xml
––
MD5:  ––
SHA256:  ––
3836
vnc.exe
C:\Users\admin\AppData\Roaming\Microsoft\Skype for Desktop\skylib\slimcore-0-4223384469.blog
––
MD5:  ––
SHA256:  ––
3836
vnc.exe
C:\Users\admin\AppData\Roaming\Microsoft\SystemCertificates\My\Certificates\E02357FC7708441D4B0BE5F371F4B28961870F70
––
MD5:  ––
SHA256:  ––
3836
vnc.exe
C:\Users\admin\AppData\Roaming\Microsoft\Skype for Desktop\skylib\DataRv\offline-storage.data-wal.KRAB
binary
MD5: df5f03b398d68970e0fd0d6d1f96c9dd
SHA256: 8d887378c5abd575e7157279396901834e430475399029703798cf7664bf53f8
3836
vnc.exe
C:\Users\admin\AppData\Roaming\Microsoft\Skype for Desktop\skylib\live#3agabriel.radrigos\KRAB-DECRYPT.txt
text
MD5: a285a299dbaaeaa3588106a648e72592
SHA256: 0826dba102ad61a52719d327e8a6b9c8897f66278362b1f7b06eab3cb57b9a73
3836
vnc.exe
C:\Users\admin\AppData\Roaming\Microsoft\Skype for Desktop\skylib\live#3agabriel.radrigos\main.db.KRAB
binary
MD5: aaaaba3ac6bcf330f182df857562c5de
SHA256: e7cf80d4b5c01526938aa84ff40fdf486304f9a21ec21d8d1548210d96db37a2
3836
vnc.exe
C:\Users\admin\AppData\Roaming\Microsoft\Skype for Desktop\skylib\live#3agabriel.radrigos\config.xml.KRAB
ini
MD5: f4af12feaa3ee365f4c32f3ea302d257
SHA256: f610717c3740a98cafcce7df735a0c4140e9979000f0856f19e826f1a3ef3cf9
3836
vnc.exe
C:\Users\admin\AppData\Roaming\Microsoft\Skype for Desktop\skylib\live#3agabriel.radrigos\config.xml
––
MD5:  ––
SHA256:  ––
3836
vnc.exe
C:\Users\admin\AppData\Roaming\Microsoft\Skype for Desktop\skylib\DataRv\offline-storage.data-wal
––
MD5:  ––
SHA256:  ––
3836
vnc.exe
C:\Users\admin\AppData\Roaming\Microsoft\Skype for Desktop\skylib\live#3agabriel.radrigos\main.db
––
MD5:  ––
SHA256:  ––
3836
vnc.exe
C:\Users\admin\AppData\Roaming\Microsoft\Skype for Desktop\skylib\DataRv\offline-storage.data-shm.KRAB
binary
MD5: aa6a5682b24e58d9907236dcb748c84e
SHA256: 5f85b8cc0b4eb666be9f070e71364526653f3b51e769513d297c2e5144d0396a
3836
vnc.exe
C:\Users\admin\AppData\Roaming\Microsoft\Skype for Desktop\QuotaManager.KRAB
binary
MD5: debb5288573dc1a983bd2d12db4d07aa
SHA256: 60bc707a046ad84f5ee3ed23671016a2ea47a02786bba7d4bc9f8f6c8a433295
3836
vnc.exe
C:\Users\admin\AppData\Roaming\Microsoft\Skype for Desktop\skylib\DataRv\offline-storage.data.KRAB
binary
MD5: b317a6028bd5f2fce37547482becf38e
SHA256: e9e3c7d0b44084303d2f02c4ca9d365f82bbfa679bdf5a9550923836df97cab0
3836
vnc.exe
C:\Users\admin\AppData\Roaming\Microsoft\Skype for Desktop\skylib\KRAB-DECRYPT.txt
text
MD5: a285a299dbaaeaa3588106a648e72592
SHA256: 0826dba102ad61a52719d327e8a6b9c8897f66278362b1f7b06eab3cb57b9a73
3836
vnc.exe
C:\Users\admin\AppData\Roaming\Microsoft\Skype for Desktop\settings.json.KRAB
binary
MD5: 2499aba3bd4b2947cdd70501bc29c45e
SHA256: 214928d00806482d280f2a01504d32bd36c0e61ed10ddbef29158b2297433a06
3836
vnc.exe
C:\Users\admin\AppData\Roaming\Microsoft\Skype for Desktop\Preferences.KRAB
binary
MD5: 5a494e66d2147a49525858bcb457bb8e
SHA256: 1fd7039fdc4b275406e83465d8408fa8b2c42f41c0502c1893cbc3df70d1eb1f
3836
vnc.exe
C:\Users\admin\AppData\Roaming\Microsoft\Skype for Desktop\skylib\DataRv\KRAB-DECRYPT.txt
text
MD5: a285a299dbaaeaa3588106a648e72592
SHA256: 0826dba102ad61a52719d327e8a6b9c8897f66278362b1f7b06eab3cb57b9a73
3836
vnc.exe
C:\Users\admin\AppData\Roaming\Microsoft\Skype for Desktop\skylib\DataRv\offline-storage.data-shm
––
MD5:  ––
SHA256:  ––
3836
vnc.exe
C:\Users\admin\AppData\Roaming\Microsoft\Skype for Desktop\skylib\DataRv\offline-storage.data
––
MD5:  ––
SHA256:  ––
3836
vnc.exe
C:\Users\admin\AppData\Roaming\Microsoft\Skype for Desktop\QuotaManager
––
MD5:  ––
SHA256:  ––
3836
vnc.exe
C:\Users\admin\AppData\Roaming\Microsoft\Skype for Desktop\settings.json
––
MD5:  ––
SHA256:  ––
3836
vnc.exe
C:\Users\admin\AppData\Roaming\Microsoft\Skype for Desktop\Preferences
––
MD5:  ––
SHA256:  ––
3836
vnc.exe
C:\Users\admin\AppData\Roaming\Microsoft\Skype for Desktop\media-stack\Skype.msrtc-0-2576771366.blog.KRAB
binary
MD5: f9c2a85e40a5693adaf064cd5d405ba5
SHA256: c2832bf93353d2ec8db8f334b8680fdde0e3b7554a32c2233d18257453ee2d9f
3836
vnc.exe
C:\Users\admin\AppData\Roaming\Microsoft\Skype for Desktop\media-stack\Skype.msrtc-1-1870167131.blog.KRAB
binary
MD5: 336e99b66491ba162cca6e51184b9b43
SHA256: 3e98c2b85c84d1bf2be53207b4659d1acc2e73472ac342e67a25149df419da16
3836
vnc.exe
C:\Users\admin\AppData\Roaming\Microsoft\Skype for Desktop\media-stack\Skype_MediaStackETW-2018.34.1.3-UVA-x86release-U.etl.bak.KRAB
binary
MD5: 6e61171be808553e11009d54fe33f8f0
SHA256: bc215b679141aa243372beabe0ca04e3d7b50fdfb2b277da68b5e4bb9571f844
3836
vnc.exe
C:\Users\admin\AppData\Roaming\Microsoft\Skype for Desktop\media-stack\KRAB-DECRYPT.txt
text
MD5: a285a299dbaaeaa3588106a648e72592
SHA256: 0826dba102ad61a52719d327e8a6b9c8897f66278362b1f7b06eab3cb57b9a73
3836
vnc.exe
C:\Users\admin\AppData\Roaming\Microsoft\Skype for Desktop\media-stack\Skype_MediaStackETW-2018.34.1.3-UVA-x86release-U.etl.KRAB
binary
MD5: c27c2211439c7ea97ede6bdc7878e7f8
SHA256: 0cbb707324f74d011bc8b05d02064e3a66e55b4b3af7c80289c57a781d94f376
3836
vnc.exe
C:\Users\admin\AppData\Roaming\Microsoft\Skype for Desktop\Local Storage\leveldb\MANIFEST-000001.KRAB
binary
MD5: 733db7d7be1b8af7f58df26802c1e139
SHA256: 49c8baf97293e8451f721e0b60fbc453d2cc85903aecadffa44933a6e789336c
3836
vnc.exe
C:\Users\admin\AppData\Roaming\Microsoft\Skype for Desktop\logs\KRAB-DECRYPT.txt
text
MD5: a285a299dbaaeaa3588106a648e72592
SHA256: 0826dba102ad61a52719d327e8a6b9c8897f66278362b1f7b06eab3cb57b9a73
3836
vnc.exe
C:\Users\admin\AppData\Roaming\Microsoft\Skype for Desktop\Local Storage\leveldb\LOG.old.KRAB
pgc
MD5: 1a32226605583e5e398d902f656ad57b
SHA256: 6359cb328cbc383fe2d0eba32db1571cded561c4bbc08238100cf051ec2b81d1
3836
vnc.exe
C:\Users\admin\AppData\Roaming\Microsoft\Skype for Desktop\media-stack\Skype.msrtc-0-2576771366.blog
––
MD5:  ––
SHA256:  ––
3836
vnc.exe
C:\Users\admin\AppData\Roaming\Microsoft\Skype for Desktop\media-stack\Skype_MediaStackETW-2018.34.1.3-UVA-x86release-U.etl
––
MD5:  ––
SHA256:  ––
3836
vnc.exe
C:\Users\admin\AppData\Roaming\Microsoft\Skype for Desktop\media-stack\Skype_MediaStackETW-2018.34.1.3-UVA-x86release-U.etl.bak
––
MD5:  ––
SHA256:  ––
3836
vnc.exe
C:\Users\admin\AppData\Roaming\Microsoft\Skype for Desktop\media-stack\Skype.msrtc-1-1870167131.blog
––
MD5:  ––
SHA256:  ––
3836
vnc.exe
C:\Users\admin\AppData\Roaming\Microsoft\Skype for Desktop\Local Storage\leveldb\LOG.old
––
MD5:  ––
SHA256:  ––
3836
vnc.exe
C:\Users\admin\AppData\Roaming\Microsoft\Skype for Desktop\Local Storage\leveldb\MANIFEST-000001
––
MD5:  ––
SHA256:  ––
3836
vnc.exe
C:\Users\admin\AppData\Roaming\Microsoft\Skype for Desktop\IndexedDB\file__0.indexeddb.leveldb\MANIFEST-000001.KRAB
binary
MD5: a0320fdcbd5f9cb8fc3e2f98d297ac0d
SHA256: 6c6536cada7fbd005e732ad30a5a04c50377646a1635ab7c663ce86842848944
3836
vnc.exe
C:\Users\admin\AppData\Roaming\Microsoft\Skype for Desktop\Local Storage\leveldb\KRAB-DECRYPT.txt
text
MD5: a285a299dbaaeaa3588106a648e72592
SHA256: 0826dba102ad61a52719d327e8a6b9c8897f66278362b1f7b06eab3cb57b9a73
3836
vnc.exe
C:\Users\admin\AppData\Roaming\Microsoft\Skype for Desktop\Local Storage\leveldb\LOG.KRAB
binary
MD5: e04a7098d25c66a1d566105e71f2ae7c
SHA256: f80978d081d9ee9dc83d38cd24e2496b62166dddc33f5762ae2257242f2d0adc
3836
vnc.exe
C:\Users\admin\AppData\Roaming\Microsoft\Skype for Desktop\Local Storage\leveldb\000005.ldb.KRAB
binary
MD5: b5044977ebeb0242def2d194fb0e6345
SHA256: 1639ca21927edac0ae796e487edaedcfb7225657952fab7e15014b3575e31fa2
3836
vnc.exe
C:\Users\admin\AppData\Roaming\Microsoft\Skype for Desktop\Local Storage\leveldb\000017.log.KRAB
binary
MD5: 7fb0506ecff3496d45116b90b0420e27
SHA256: 2b047e10cd022ebbdae95232036d8883cc004d99ac6eade2f00a858eaea73ab9
3836
vnc.exe
C:\Users\admin\AppData\Roaming\Microsoft\Skype for Desktop\Local Storage\leveldb\CURRENT.KRAB
binary
MD5: 8d21b925afc87a18376b2915b690e8f7
SHA256: 5c340cbed1148c686863b2ae5a9477bce7e76b8cdcbb33e79c58f164152530d5
3836
vnc.exe
C:\Users\admin\AppData\Roaming\Microsoft\Skype for Desktop\Local Storage\leveldb\000018.ldb.KRAB
binary
MD5: 10fe777509350928d2059e6f13ed691f
SHA256: c2a81775681b5904f944ff1c10aaedec4b0ede8b49e9bff44c7ac87a88db8d91
3836
vnc.exe
C:\Users\admin\AppData\Roaming\Microsoft\Skype for Desktop\Local Storage\KRAB-DECRYPT.txt
text
MD5: a285a299dbaaeaa3588106a648e72592
SHA256: 0826dba102ad61a52719d327e8a6b9c8897f66278362b1f7b06eab3cb57b9a73
3836
vnc.exe
C:\Users\admin\AppData\Roaming\Microsoft\Skype for Desktop\Local Storage\leveldb\CURRENT
––
MD5:  ––
SHA256:  ––
3836
vnc.exe
C:\Users\admin\AppData\Roaming\Microsoft\Skype for Desktop\IndexedDB\file__0.indexeddb.leveldb\MANIFEST-000001
––
MD5:  ––
SHA256:  ––
3836
vnc.exe
C:\Users\admin\AppData\Roaming\Microsoft\Skype for Desktop\Local Storage\leveldb\000018.ldb
––
MD5:  ––
SHA256:  ––
3836
vnc.exe
C:\Users\admin\AppData\Roaming\Microsoft\Skype for Desktop\Local Storage\leveldb\000017.log
––
MD5:  ––
SHA256:  ––
3836
vnc.exe
C:\Users\admin\AppData\Roaming\Microsoft\Skype for Desktop\Local Storage\leveldb\LOG
––
MD5:  ––
SHA256:  ––
3836
vnc.exe
C:\Users\admin\AppData\Roaming\Microsoft\Skype for Desktop\Local Storage\leveldb\000005.ldb
––
MD5:  ––
SHA256:  ––
3836
vnc.exe
C:\Users\admin\AppData\Roaming\Microsoft\Skype for Desktop\IndexedDB\file__0.indexeddb.leveldb\LOG.KRAB
binary
MD5: d98253ae40125dfd5d066c08ba562cf7
SHA256: 02158dc370dc0dc97339dfe8771305efd319cf693704b750b49511c1278839bf
3836
vnc.exe
C:\Users\admin\AppData\Roaming\Microsoft\Skype for Desktop\IndexedDB\file__0.indexeddb.leveldb\000003.log.KRAB
binary
MD5: ef76d1bef2105a70b55042301dc955a7
SHA256: cb4985b9ac242fcb9b9366f7beb7035a39ffd123f26f90a07aae2e1c44664717
3836
vnc.exe
C:\Users\admin\AppData\Roaming\Microsoft\Skype for Desktop\IndexedDB\file__0.indexeddb.leveldb\LOG.old.KRAB
binary
MD5: 74b871a7d59758a1f39100fe4366644a
SHA256: 0cf3cf0befda38826a1892cc1aad08b2c6b3d470e548ec1b4d7065c5d29bd626
3836
vnc.exe
C:\Users\admin\AppData\Roaming\Microsoft\Skype for Desktop\IndexedDB\file__0.indexeddb.leveldb\CURRENT.KRAB
binary
MD5: 27bdd9d41f4d7d759280ebdf5f103ec5
SHA256: e14e7314451da7e0c7c760dce6fe8e01e41c7988d7e8dab2f47c99c6c7fac5f0
3836
vnc.exe
C:\Users\admin\AppData\Roaming\Microsoft\Skype for Desktop\IndexedDB\file__0.indexeddb.leveldb\CURRENT
––
MD5:  ––
SHA256:  ––
3836
vnc.exe
C:\Users\admin\AppData\Roaming\Microsoft\Skype for Desktop\IndexedDB\file__0.indexeddb.leveldb\LOG.old
––
MD5:  ––
SHA256:  ––
3836
vnc.exe
C:\Users\admin\AppData\Roaming\Microsoft\Skype for Desktop\IndexedDB\file__0.indexeddb.leveldb\LOG
––
MD5:  ––
SHA256:  ––
3836
vnc.exe
C:\Users\admin\AppData\Roaming\Microsoft\Skype for Desktop\IndexedDB\file__0.indexeddb.leveldb\000003.log
––
MD5:  ––
SHA256:  ––
3836
vnc.exe
C:\Users\admin\AppData\Roaming\Microsoft\Skype for Desktop\dictionaries\en-US.bdic.KRAB
binary
MD5: 6767ce0bd8b7e37ad36fbdcfde761c76
SHA256: e581706f693fff1cb7a6907377529f17a95656be161514ee63133754a30ea699
3836
vnc.exe
C:\Users\admin\AppData\Roaming\Microsoft\Skype for Desktop\IndexedDB\file__0.indexeddb.leveldb\KRAB-DECRYPT.txt
text
MD5: a285a299dbaaeaa3588106a648e72592
SHA256: 0826dba102ad61a52719d327e8a6b9c8897f66278362b1f7b06eab3cb57b9a73
3836
vnc.exe
C:\Users\admin\AppData\Roaming\Microsoft\Skype for Desktop\IndexedDB\KRAB-DECRYPT.txt
text
MD5: a285a299dbaaeaa3588106a648e72592
SHA256: 0826dba102ad61a52719d327e8a6b9c8897f66278362b1f7b06eab3cb57b9a73
3836
vnc.exe
C:\Users\admin\AppData\Roaming\Microsoft\Skype for Desktop\ecscache.json.KRAB
binary
MD5: 92fb787466a34e75d8e855ca9815e2f5
SHA256: c14d8aa471ce1ddd54f88aaf4420bee98bcd217269807126e430228bd960bddb
3836
vnc.exe
C:\Users\admin\AppData\Roaming\Microsoft\Skype for Desktop\ecscache.json
––
MD5:  ––
SHA256:  ––
3836
vnc.exe
C:\Users\admin\AppData\Roaming\Microsoft\Skype for Desktop\dictionaries\en-US.bdic
––
MD5:  ––
SHA256:  ––
3836
vnc.exe
C:\Users\admin\AppData\Roaming\Microsoft\Skype for Desktop\Cache\index.KRAB
binary
MD5: 2a3dc72960f2049077db7012708513d3
SHA256: bc49b587ec7c557a491e92d145bf9a5f1d26175b156ff5bef42f2fac447e67ba
3836
vnc.exe
C:\Users\admin\AppData\Roaming\Microsoft\Skype for Desktop\Cache\f_000004.KRAB
binary
MD5: d61e28df158a99aad6b8a7bcf54361cf
SHA256: abe17e821fff00ea60a33b42887c8b5d30f0ba34eb7b63345ec46d4959adb97c
3836
vnc.exe
C:\Users\admin\AppData\Roaming\Microsoft\Skype for Desktop\device-info.json.KRAB
binary
MD5: 8de3c2e5c53bd586693aab32c6348ef7
SHA256: 19dcdec31cd1599dfb1d9e183e7e2b75e5b8d90df3534986e19e2cd953255724
3836
vnc.exe
C:\Users\admin\AppData\Roaming\Microsoft\Skype for Desktop\dictionaries\KRAB-DECRYPT.txt
text
MD5: a285a299dbaaeaa3588106a648e72592
SHA256: 0826dba102ad61a52719d327e8a6b9c8897f66278362b1f7b06eab3cb57b9a73
3836
vnc.exe
C:\Users\admin\AppData\Roaming\Microsoft\Skype for Desktop\Cookies.KRAB
binary
MD5: 39f8c6f4afe2d14f2dad7e69231625e5
SHA256: 07eedb6ba24fca6fa590942e229be37cba473c52da3099d9c41161caa168c10f
3836
vnc.exe
C:\Users\admin\AppData\Roaming\Microsoft\Skype for Desktop\databases\Databases.db.KRAB
binary
MD5: 183269c64cdc247279b9bafd1798d908
SHA256: 147ea0824c9a58b97b2a8c3c0a7d4b53c7a1f67aeb7bba0ddc7c540fde5e0e1a
3836
vnc.exe
C:\Users\admin\AppData\Roaming\Microsoft\Skype for Desktop\databases\KRAB-DECRYPT.txt
text
MD5: a285a299dbaaeaa3588106a648e72592
SHA256: 0826dba102ad61a52719d327e8a6b9c8897f66278362b1f7b06eab3cb57b9a73
3836
vnc.exe
C:\Users\admin\AppData\Roaming\Microsoft\Skype for Desktop\device-info.json
––
MD5:  ––
SHA256:  ––
3836
vnc.exe
C:\Users\admin\AppData\Roaming\Microsoft\Skype for Desktop\databases\Databases.db
––
MD5:  ––
SHA256:  ––
3836
vnc.exe
C:\Users\admin\AppData\Roaming\Microsoft\Skype for Desktop\Cookies
––
MD5:  ––
SHA256:  ––
3836
vnc.exe
C:\Users\admin\AppData\Roaming\Microsoft\Skype for Desktop\Cache\index
––
MD5:  ––
SHA256:  ––
3836
vnc.exe
C:\Users\admin\AppData\Roaming\Microsoft\Skype for Desktop\Cache\f_000004
––
MD5:  ––
SHA256:  ––
3836
vnc.exe
C:\Users\admin\AppData\Roaming\Microsoft\Skype for Desktop\Cache\f_000002.KRAB
binary
MD5: 2ffe526e82d8bf725945c57e9b1e1cd5
SHA256: 8a0c740e4494ba48fa13882907f26b08e62c8337c57ec8042958fcb622c4646e
3836
vnc.exe
C:\Users\admin\AppData\Roaming\Microsoft\Skype for Desktop\Cache\f_000001.KRAB
binary
MD5: be9bb101404ac8a331e0d61d8a0089cb
SHA256: 99683c0dea09ae134ece7456fb9dbd4307e0107d803407364d44cd31f9dfea39
3836
vnc.exe
C:\Users\admin\AppData\Roaming\Microsoft\Skype for Desktop\Cache\f_000003.KRAB
binary
MD5: 6c3cbc826aa07193af16984daf891a8d
SHA256: 6ed9164fd41bf12e69b16387defbe85d19b16405e7dd0fc631d689056b741dc1
3836
vnc.exe
C:\Users\admin\AppData\Roaming\Microsoft\Skype for Desktop\Cache\f_000003
––
MD5:  ––
SHA256:  ––
3836
vnc.exe
C:\Users\admin\AppData\Roaming\Microsoft\Skype for Desktop\Cache\f_000002
––
MD5:  ––
SHA256:  ––
3836
vnc.exe
C:\Users\admin\AppData\Roaming\Microsoft\Skype for Desktop\Cache\f_000001
––
MD5:  ––
SHA256:  ––
3836
vnc.exe
C:\Users\admin\AppData\Roaming\Microsoft\Skype for Desktop\Cache\data_3.KRAB
––
MD5:  ––
SHA256:  ––
3836
vnc.exe
C:\Users\admin\AppData\Roaming\Microsoft\Skype for Desktop\Cache\data_3
––
MD5:  ––
SHA256:  ––
3836
vnc.exe
C:\Users\admin\AppData\Roaming\Microsoft\Skype for Desktop\Cache\data_2.KRAB
binary
MD5: fb94a591ea32219960b2c2a56353451c
SHA256: 183113049ab97a10b44c3d44694bcb6a4e4201234e26607705570b1ce1401527
3836
vnc.exe
C:\Users\admin\AppData\Roaming\Microsoft\Skype for Desktop\Cache\data_1.KRAB
binary
MD5: 9cea293d24d8c36628434e33bab60864
SHA256: 14a29a72cfddb1f4874bc69e130c3d7ef309e68494e8e15a396bebb8dd75ce9c
3836
vnc.exe
C:\Users\admin\AppData\Roaming\Microsoft\Skype for Desktop\Cache\data_2
––
MD5:  ––
SHA256:  ––
3836
vnc.exe
C:\Users\admin\AppData\Roaming\Microsoft\Skype for Desktop\Cache\data_1
––
MD5:  ––
SHA256:  ––
3836
vnc.exe
C:\Users\admin\AppData\Roaming\Microsoft\Publisher\KRAB-DECRYPT.txt
text
MD5: a285a299dbaaeaa3588106a648e72592
SHA256: 0826dba102ad61a52719d327e8a6b9c8897f66278362b1f7b06eab3cb57b9a73
3836
vnc.exe
C:\Users\admin\AppData\Roaming\Microsoft\Skype for Desktop\Cache\KRAB-DECRYPT.txt
text
MD5: a285a299dbaaeaa3588106a648e72592
SHA256: 0826dba102ad61a52719d327e8a6b9c8897f66278362b1f7b06eab3cb57b9a73
3836
vnc.exe
C:\Users\admin\AppData\Roaming\Microsoft\Skype for Desktop\Cache\data_0.KRAB
binary
MD5: dcc2d2e01db55728644a9db59ce8bf28
SHA256: d54f512f40efd407bf98818f6ee49bbfe7fdf814a5beff1fcac76f405b38cdd7
3836
vnc.exe
C:\Users\admin\AppData\Roaming\Microsoft\Signatures\KRAB-DECRYPT.txt
text
MD5: a285a299dbaaeaa3588106a648e72592
SHA256: 0826dba102ad61a52719d327e8a6b9c8897f66278362b1f7b06eab3cb57b9a73
3836
vnc.exe
C:\Users\admin\AppData\Roaming\Microsoft\Skype for Desktop\KRAB-DECRYPT.txt
text
MD5: a285a299dbaaeaa3588106a648e72592
SHA256: 0826dba102ad61a52719d327e8a6b9c8897f66278362b1f7b06eab3cb57b9a73
3836
vnc.exe
C:\Users\admin\AppData\Roaming\Microsoft\Protect\S-1-5-21-1302019708-1500728564-335382590-1000\29fd2168-360f-422a-a685-e6961ea74ba8.KRAB
binary
MD5: 248775bda8e7c1178ad65b4a47ea5a71
SHA256: af1ea8de4cca1f8f37474994832daf8a22b776afc120b6b1176262ee47571505
3836
vnc.exe
C:\Users\admin\AppData\Roaming\Microsoft\Publisher Building Blocks\ContentStore.xml.KRAB
binary
MD5: 8be3c27de22ae2d5c5db14e4081535c4
SHA256: b8612b397d15053ee936a5e8f9b1ab64159964d2cf7281c549a91971a9be3d92
3836
vnc.exe
C:\Users\admin\AppData\Roaming\Microsoft\Protect\S-1-5-21-1302019708-1500728564-335382590-1000\Preferred.KRAB
binary
MD5: 639c141d3c38342151d4ab5c997fe0c2
SHA256: 52bcad5594a6add3578b63d500987b192edeb9e22d5939d7abf279ec50c875da
3836
vnc.exe
C:\Users\admin\AppData\Roaming\Microsoft\Protect\S-1-5-21-1302019708-1500728564-335382590-1000\54ba308a-6a9a-4e0e-b137-b89d3579498b.KRAB
binary
MD5: 5a404d8dc89f1f9b48d73df427fc1ebc
SHA256: 935905b9c3222dc8e6d6d92a4fb7c6561180d4a4988549c041f58d82b42f09e2
3836
vnc.exe
C:\Users\admin\AppData\Roaming\Microsoft\Publisher Building Blocks\KRAB-DECRYPT.txt
text
MD5: a285a299dbaaeaa3588106a648e72592
SHA256: 0826dba102ad61a52719d327e8a6b9c8897f66278362b1f7b06eab3cb57b9a73
3836
vnc.exe
C:\Users\admin\AppData\Roaming\Microsoft\Protect\S-1-5-21-1302019708-1500728564-335382590-1000\KRAB-DECRYPT.txt
text
MD5: a285a299dbaaeaa3588106a648e72592
SHA256: 0826dba102ad61a52719d327e8a6b9c8897f66278362b1f7b06eab3cb57b9a73
3836
vnc.exe
C:\Users\admin\AppData\Roaming\Microsoft\Skype for Desktop\Cache\data_0
––
MD5:  ––
SHA256:  ––
3836
vnc.exe
C:\Users\admin\AppData\Roaming\Microsoft\Protect\S-1-5-21-1302019708-1500728564-335382590-1000\Preferred
––
MD5:  ––
SHA256:  ––
3836
vnc.exe
C:\Users\admin\AppData\Roaming\Microsoft\Protect\S-1-5-21-1302019708-1500728564-335382590-1000\54ba308a-6a9a-4e0e-b137-b89d3579498b
––
MD5:  ––
SHA256:  ––
3836
vnc.exe
C:\Users\admin\AppData\Roaming\Microsoft\Publisher Building Blocks\ContentStore.xml
––
MD5:  ––
SHA256:  ––
3836
vnc.exe
C:\Users\admin\AppData\Roaming\Microsoft\Protect\S-1-5-21-1302019708-1500728564-335382590-1000\29fd2168-360f-422a-a685-e6961ea74ba8
––
MD5:  ––
SHA256:  ––
3836
vnc.exe
C:\Users\admin\AppData\Roaming\Microsoft\PowerPoint\KRAB-DECRYPT.txt
text
MD5: a285a299dbaaeaa3588106a648e72592
SHA256: 0826dba102ad61a52719d327e8a6b9c8897f66278362b1f7b06eab3cb57b9a73
3836
vnc.exe
C:\Users\admin\AppData\Roaming\Microsoft\Protect\KRAB-DECRYPT.txt
text
MD5: a285a299dbaaeaa3588106a648e72592
SHA256: 0826dba102ad61a52719d327e8a6b9c8897f66278362b1f7b06eab3cb57b9a73
3836
vnc.exe
C:\Users\admin\AppData\Roaming\Microsoft\Protect\CREDHIST.KRAB
binary
MD5: 556f1806379635a9b1df21d8b55c6703
SHA256: 3e670fa7bf3749dfec1b2f39aab35a6cb099a73a87ebc0f2c5661f7c9e74afa5
3836
vnc.exe
C:\Users\admin\AppData\Roaming\Microsoft\Outlook\Outlook.xml.KRAB
binary
MD5: 544ee22ef6dae2256e0ce74473690e65
SHA256: ab2ec451371cb2789b64fb0358da8ff4d9278963ed018462f4beed99657ee95e
3836
vnc.exe
C:\Users\admin\AppData\Roaming\Microsoft\Proof\KRAB-DECRYPT.txt
text
MD5: a285a299dbaaeaa3588106a648e72592
SHA256: 0826dba102ad61a52719d327e8a6b9c8897f66278362b1f7b06eab3cb57b9a73
3836
vnc.exe
C:\Users\admin\AppData\Roaming\Microsoft\Outlook\test.srs.KRAB
binary
MD5: f6487c542f5435b61bfbb9eb4395c3ea
SHA256: edcd68c6f395d7cfcd03534c32117867f6b7748c7ae205b6d2074d03bb66701a
3836
vnc.exe
C:\Users\admin\AppData\Roaming\Microsoft\Outlook\Outlook.srs.KRAB
binary
MD5: d46cd24bd4afaeebb7100a33241cca77
SHA256: ae3b2277a4494bccb218c9c69e17d4df4e6af751c8f1e22aa66a5be4437f1ecc
3836
vnc.exe
C:\Users\admin\AppData\Roaming\Microsoft\Outlook\test.xml.KRAB
binary
MD5: f82e3427c6d314b2758f8bb667a97d06
SHA256: 3fc9bdcdd4b28e43ec73a70e9a54863acff612e7c07e656cb07ae4c59cf53b23
3836
vnc.exe
C:\Users\admin\AppData\Roaming\Microsoft\Outlook\test.srs
––
MD5:  ––
SHA256:  ––
3836
vnc.exe
C:\Users\admin\AppData\Roaming\Microsoft\Outlook\Outlook.xml
––
MD5:  ––
SHA256:  ––
3836
vnc.exe
C:\Users\admin\AppData\Roaming\Microsoft\Protect\CREDHIST
––
MD5:  ––
SHA256:  ––
3836
vnc.exe
C:\Users\admin\AppData\Roaming\Microsoft\Outlook\test.xml
––
MD5:  ––
SHA256:  ––
3836
vnc.exe
C:\Users\admin\AppData\Roaming\Microsoft\Outlook\Outlook.srs
––
MD5:  ––
SHA256:  ––
3836
vnc.exe
C:\Users\admin\AppData\Roaming\Microsoft\OneNote\14.0\Preferences.dat.KRAB
binary
MD5: bd67273a9867169f97d488b733a91417
SHA256: 2315303db9444f8fb5d2eccf07c694e1761eeeae368009dc9de62583d7d6c0b1
3836
vnc.exe
C:\Users\admin\AppData\Roaming\Microsoft\Office\MSO1033.acl.KRAB
binary
MD5: b37072e376722758a1316bafb71790fe
SHA256: ae10993c4f2a3d33dd36ae3836d84d4de7d20d685ff8776deb84915e14949116
3836
vnc.exe
C:\Users\admin\AppData\Roaming\Microsoft\OneNote\KRAB-DECRYPT.txt
text
MD5: a285a299dbaaeaa3588106a648e72592
SHA256: 0826dba102ad61a52719d327e8a6b9c8897f66278362b1f7b06eab3cb57b9a73
3836
vnc.exe
C:\Users\admin\AppData\Roaming\Microsoft\Office\Recent\KRAB-DECRYPT.txt
text
MD5: a285a299dbaaeaa3588106a648e72592
SHA256: 0826dba102ad61a52719d327e8a6b9c8897f66278362b1f7b06eab3cb57b9a73
3836
vnc.exe
C:\Users\admin\AppData\Roaming\Microsoft\Outlook\NoMail.xml.KRAB
binary
MD5: 7b081f622cadabdfd143fe361d0a4b4b
SHA256: e82c685d5e85758658751b13d8e46d751858d13818e5a3e0920f68c685a3e964
3836
vnc.exe
C:\Users\admin\AppData\Roaming\Microsoft\Outlook\KRAB-DECRYPT.txt
text
MD5: a285a299dbaaeaa3588106a648e72592
SHA256: 0826dba102ad61a52719d327e8a6b9c8897f66278362b1f7b06eab3cb57b9a73
3836
vnc.exe
C:\Users\admin\AppData\Roaming\Microsoft\OneNote\14.0\KRAB-DECRYPT.txt
text
MD5: a285a299dbaaeaa3588106a648e72592
SHA256: 0826dba102ad61a52719d327e8a6b9c8897f66278362b1f7b06eab3cb57b9a73
3836
vnc.exe
C:\Users\admin\AppData\Roaming\Microsoft\Outlook\NoMail.xml
––
MD5:  ––
SHA256:  ––
3836
vnc.exe
C:\Users\admin\AppData\Roaming\Microsoft\OneNote\14.0\Preferences.dat
––
MD5:  ––
SHA256:  ––
3836
vnc.exe
C:\Users\admin\AppData\Roaming\Microsoft\Office\MSO1033.acl
––
MD5:  ––
SHA256:  ––
3836
vnc.exe
C:\Users\admin\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\User Pinned\ImplicitAppShortcuts\KRAB-DECRYPT.txt
text
MD5: a285a299dbaaeaa3588106a648e72592
SHA256: 0826dba102ad61a52719d327e8a6b9c8897f66278362b1f7b06eab3cb57b9a73
3836
vnc.exe
C:\Users\admin\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\User Pinned\TaskBar\KRAB-DECRYPT.txt
text
MD5: a285a299dbaaeaa3588106a648e72592
SHA256: 0826dba102ad61a52719d327e8a6b9c8897f66278362b1f7b06eab3cb57b9a73
3836
vnc.exe
C:\Users\admin\AppData\Roaming\Microsoft\MMC\KRAB-DECRYPT.txt
text
MD5: a285a299dbaaeaa3588106a648e72592
SHA256: 0826dba102ad61a52719d327e8a6b9c8897f66278362b1f7b06eab3cb57b9a73
3836
vnc.exe
C:\Users\admin\AppData\Roaming\Microsoft\Office\KRAB-DECRYPT.txt
text
MD5: a285a299dbaaeaa3588106a648e72592
SHA256: 0826dba102ad61a52719d327e8a6b9c8897f66278362b1f7b06eab3cb57b9a73
3836
vnc.exe
C:\Users\admin\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\User Pinned\KRAB-DECRYPT.txt
text
MD5: a285a299dbaaeaa3588106a648e72592
SHA256: 0826dba102ad61a52719d327e8a6b9c8897f66278362b1f7b06eab3cb57b9a73
3836
vnc.exe
C:\Users\admin\AppData\Roaming\Microsoft\Network\KRAB-DECRYPT.txt
text
MD5: a285a299dbaaeaa3588106a648e72592
SHA256: 0826dba102ad61a52719d327e8a6b9c8897f66278362b1f7b06eab3cb57b9a73
3836
vnc.exe
C:\Users\admin\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\KRAB-DECRYPT.txt
text
MD5: a285a299dbaaeaa3588106a648e72592
SHA256: 0826dba102ad61a52719d327e8a6b9c8897f66278362b1f7b06eab3cb57b9a73
3836
vnc.exe
C:\Users\admin\AppData\Roaming\Microsoft\Internet Explorer\KRAB-DECRYPT.txt
text
MD5: a285a299dbaaeaa3588106a648e72592
SHA256: 0826dba102ad61a52719d327e8a6b9c8897f66278362b1f7b06eab3cb57b9a73
3836
vnc.exe
C:\Users\admin\AppData\Roaming\Microsoft\MMC\taskschd.KRAB
binary
MD5: cadd7914fd1302beea06a6eb46c3587b
SHA256: c616b7391c66ef23d499fa3239a665939d8ce26e0af6a2a5447f901f77e68533
3836
vnc.exe
C:\Users\admin\AppData\Roaming\Microsoft\Network\Connections\Pbk\KRAB-DECRYPT.txt
text
MD5: a285a299dbaaeaa3588106a648e72592
SHA256: 0826dba102ad61a52719d327e8a6b9c8897f66278362b1f7b06eab3cb57b9a73
3836
vnc.exe
C:\Users\admin\AppData\Roaming\Microsoft\Network\Connections\Pbk\_hiddenPbk\KRAB-DECRYPT.txt
text
MD5: a285a299dbaaeaa3588106a648e72592
SHA256: 0826dba102ad61a52719d327e8a6b9c8897f66278362b1f7b06eab3cb57b9a73
3836
vnc.exe
C:\Users\admin\AppData\Roaming\Microsoft\Network\Connections\KRAB-DECRYPT.txt
text
MD5: a285a299dbaaeaa3588106a648e72592
SHA256: 0826dba102ad61a52719d327e8a6b9c8897f66278362b1f7b06eab3cb57b9a73
3836
vnc.exe
C:\Users\admin\AppData\Roaming\Microsoft\HTML Help\hh.dat.KRAB
binary
MD5: 9e1967ba94b779d4683df9692afdde0e
SHA256: c90e355eba92e102dbecfd83e6af182f2088363aa3310552f5b901d4efa8889e
3836
vnc.exe
C:\Users\admin\AppData\Roaming\Microsoft\HTML Help\hh.dat
––
MD5:  ––
SHA256:  ––
3836
vnc.exe
C:\Users\admin\AppData\Roaming\Microsoft\MMC\taskschd
––
MD5:  ––
SHA256:  ––
3836
vnc.exe
C:\Users\admin\AppData\Roaming\Microsoft\HTML Help\KRAB-DECRYPT.txt
text
MD5: a285a299dbaaeaa3588106a648e72592
SHA256: 0826dba102ad61a52719d327e8a6b9c8897f66278362b1f7b06eab3cb57b9a73
3836
vnc.exe
C:\Users\admin\AppData\Roaming\Microsoft\Excel\KRAB-DECRYPT.txt
text
MD5: a285a299dbaaeaa3588106a648e72592
SHA256: 0826dba102ad61a52719d327e8a6b9c8897f66278362b1f7b06eab3cb57b9a73
3836
vnc.exe
C:\Users\admin\AppData\Roaming\Microsoft\Excel\XLSTART\KRAB-DECRYPT.txt
text
MD5: a285a299dbaaeaa3588106a648e72592
SHA256: 0826dba102ad61a52719d327e8a6b9c8897f66278362b1f7b06eab3cb57b9a73
3836
vnc.exe
C:\Users\admin\AppData\Roaming\Microsoft\Document Building Blocks\1033\14\Built-In Building Blocks.dotx.KRAB
binary
MD5: 13669564fa7f110966cb0319f176eae2
SHA256: a4a38931088a66a83d57747b14d9d92bf079618bacd6cf41cf73ea43c4f52216
3836
vnc.exe
C:\Users\admin\AppData\Roaming\Microsoft\Document Building Blocks\1033\14\Built-In Building Blocks.dotx
––
MD5:  ––
SHA256:  ––
3836
vnc.exe
C:\Users\admin\AppData\Roaming\Microsoft\Document Building Blocks\1033\14\KRAB-DECRYPT.txt
text
MD5: a285a299dbaaeaa3588106a648e72592
SHA256: 0826dba102ad61a52719d327e8a6b9c8897f66278362b1f7b06eab3cb57b9a73
3836
vnc.exe
C:\Users\admin\AppData\Roaming\Microsoft\Document Building Blocks\1033\KRAB-DECRYPT.txt
text
MD5: a285a299dbaaeaa3588106a648e72592
SHA256: 0826dba102ad61a52719d327e8a6b9c8897f66278362b1f7b06eab3cb57b9a73
3836
vnc.exe
C:\Users\admin\AppData\Roaming\Microsoft\Crypto\RSA\S-1-5-21-1302019708-1500728564-335382590-1000\a551dda6b1d5ee0d0c4637af6c004413_90059c37-1320-41a4-b58d-2b75a9850d2f.KRAB
binary
MD5: 37fa708200c25ffdad681c28d7d68f97
SHA256: 02d5da53bc5143792bea4bff4ce5a4a2e8289b71b078538123f84de8871c951e
3836
vnc.exe
C:\Users\admin\AppData\Roaming\Microsoft\Crypto\RSA\S-1-5-21-1302019708-1500728564-335382590-1000\1f91d2d17ea675d4c2c3192e241743f9_90059c37-1320-41a4-b58d-2b75a9850d2f.KRAB
binary
MD5: e4e75ff1b5880be90831f57c3b6854d7
SHA256: d967392296e11422398623c6a22003f4f57c7a619465cc12b78e443ba673543d
3836
vnc.exe
C:\Users\admin\AppData\Roaming\Microsoft\Document Building Blocks\KRAB-DECRYPT.txt
text
MD5: a285a299dbaaeaa3588106a648e72592
SHA256: 0826dba102ad61a52719d327e8a6b9c8897f66278362b1f7b06eab3cb57b9a73
3836
vnc.exe
C:\Users\admin\AppData\Roaming\Microsoft\Crypto\RSA\S-1-5-21-1302019708-1500728564-335382590-1000\c43c9d3341c1ddc712bbe39db3c78fa5_90059c37-1320-41a4-b58d-2b75a9850d2f.KRAB
binary
MD5: 18037e667d8b4d980b57e58830e8e66c
SHA256: 82d821eea72b10707d6f37ff4175031fd78356f15dfc872f818eae333a171e99
3836
vnc.exe
C:\Users\admin\AppData\Roaming\Microsoft\Crypto\RSA\S-1-5-21-1302019708-1500728564-335382590-1000\e3f86d7936454598ef98443d4fd3260d_90059c37-1320-41a4-b58d-2b75a9850d2f.KRAB
binary
MD5: 9e349643621a742b9e767d6e10ecdb41
SHA256: cf3dd68e40241630e58bb14d05d14d615bccb2f5b67ba269fa6169a9d87327c3
3836
vnc.exe
C:\Users\admin\AppData\Roaming\Microsoft\Crypto\RSA\S-1-5-21-1302019708-1500728564-335382590-1000\7be1242ebc44e45985bd1ffa382e997c_90059c37-1320-41a4-b58d-2b75a9850d2f.KRAB
binary
MD5: bcce71589e80ae6277dbe586adb0ae77
SHA256: 3a4307cc35c7ec35f68d9f37f2538238d9379c497322c36fca0585be5e979f70
3836
vnc.exe
C:\Users\admin\AppData\Roaming\Microsoft\Crypto\RSA\S-1-5-21-1302019708-1500728564-335382590-1000\c43c9d3341c1ddc712bbe39db3c78fa5_90059c37-1320-41a4-b58d-2b75a9850d2f
––
MD5:  ––
SHA256:  ––
3836
vnc.exe
C:\Users\admin\AppData\Roaming\Microsoft\Crypto\RSA\S-1-5-21-1302019708-1500728564-335382590-1000\e3f86d7936454598ef98443d4fd3260d_90059c37-1320-41a4-b58d-2b75a9850d2f
––
MD5:  ––
SHA256:  ––
3836
vnc.exe
C:\Users\admin\AppData\Roaming\Microsoft\Crypto\RSA\S-1-5-21-1302019708-1500728564-335382590-1000\a551dda6b1d5ee0d0c4637af6c004413_90059c37-1320-41a4-b58d-2b75a9850d2f
––
MD5:  ––
SHA256:  ––
3836
vnc.exe
C:\Users\admin\AppData\Roaming\Microsoft\Crypto\RSA\S-1-5-21-1302019708-1500728564-335382590-1000\7be1242ebc44e45985bd1ffa382e997c_90059c37-1320-41a4-b58d-2b75a9850d2f
––
MD5:  ––
SHA256:  ––
3836
vnc.exe
C:\Users\admin\AppData\Roaming\Microsoft\Crypto\RSA\S-1-5-21-1302019708-1500728564-335382590-1000\1f91d2d17ea675d4c2c3192e241743f9_90059c37-1320-41a4-b58d-2b75a9850d2f
––
MD5:  ––
SHA256:  ––
3836
vnc.exe
C:\Users\admin\AppData\Roaming\Microsoft\AddIns\KRAB-DECRYPT.txt
text
MD5: a285a299dbaaeaa3588106a648e72592
SHA256: 0826dba102ad61a52719d327e8a6b9c8897f66278362b1f7b06eab3cb57b9a73
3836
vnc.exe
C:\Users\admin\AppData\Roaming\Microsoft\KRAB-DECRYPT.txt
text
MD5: a285a299dbaaeaa3588106a648e72592
SHA256: 0826dba102ad61a52719d327e8a6b9c8897f66278362b1f7b06eab3cb57b9a73
3836
vnc.exe
C:\Users\admin\AppData\Roaming\Identities\KRAB-DECRYPT.txt
text
MD5: a285a299dbaaeaa3588106a648e72592
SHA256: 0826dba102ad61a52719d327e8a6b9c8897f66278362b1f7b06eab3cb57b9a73
3836
vnc.exe
C:\Users\admin\AppData\Roaming\Microsoft\Credentials\KRAB-DECRYPT.txt
text
MD5: a285a299dbaaeaa3588106a648e72592
SHA256: 0826dba102ad61a52719d327e8a6b9c8897f66278362b1f7b06eab3cb57b9a73
3836
vnc.exe
C:\Users\admin\AppData\Roaming\FileZilla\filezilla.xml.KRAB
binary
MD5: 360f4608a87dca25b353b9e4bd5d8978
SHA256: e963bb4cfb496085d5550c641760529df438a19d3291eaddaa55d96cc424312e
3836
vnc.exe
C:\Users\admin\AppData\Roaming\Microsoft\Crypto\RSA\KRAB-DECRYPT.txt
text
MD5: a285a299dbaaeaa3588106a648e72592
SHA256: 0826dba102ad61a52719d327e8a6b9c8897f66278362b1f7b06eab3cb57b9a73
3836
vnc.exe
C:\Users\admin\AppData\Roaming\Identities\{E4CE17A7-FC47-4CD1-8FF6-45436C8F45DB}\KRAB-DECRYPT.txt
text
MD5: a285a299dbaaeaa3588106a648e72592
SHA256: 0826dba102ad61a52719d327e8a6b9c8897f66278362b1f7b06eab3cb57b9a73
3836
vnc.exe
C:\Users\admin\AppData\Roaming\Media Center Programs\KRAB-DECRYPT.txt
text
MD5: a285a299dbaaeaa3588106a648e72592
SHA256: 0826dba102ad61a52719d327e8a6b9c8897f66278362b1f7b06eab3cb57b9a73
3836
vnc.exe
C:\Users\admin\AppData\Roaming\FileZilla\queue.sqlite3.KRAB
binary
MD5: 82461dce5ce06924098b99b33db91c2d
SHA256: dc90b9d09fb376f115d5f3cb8c49d4c227d104d45679a1cdec73ad9843d08c28
3836
vnc.exe
C:\Users\admin\AppData\Roaming\Microsoft\Crypto\RSA\S-1-5-21-1302019708-1500728564-335382590-1000\0f5007522459c86e95ffcc62f32308f1_90059c37-1320-41a4-b58d-2b75a9850d2f.KRAB
binary
MD5: 83ea01a1758d03be52d1f88a9e051695
SHA256: 7706e0d34d00367b9f8435d16260ed9a71cccfc2a66e23859f4a15b8f66c0bd2
3836
vnc.exe
C:\Users\admin\AppData\Roaming\Microsoft\Crypto\KRAB-DECRYPT.txt
text
MD5: a285a299dbaaeaa3588106a648e72592
SHA256: 0826dba102ad61a52719d327e8a6b9c8897f66278362b1f7b06eab3cb57b9a73
3836
vnc.exe
C:\Users\admin\AppData\Roaming\Microsoft\Crypto\RSA\S-1-5-21-1302019708-1500728564-335382590-1000\KRAB-DECRYPT.txt
text
MD5: a285a299dbaaeaa3588106a648e72592
SHA256: 0826dba102ad61a52719d327e8a6b9c8897f66278362b1f7b06eab3cb57b9a73
3836
vnc.exe
C:\Users\admin\AppData\Roaming\FileZilla\layout.xml.KRAB
binary
MD5: 6f62249004fd16f3f3ed22de9858ecc9
SHA256: c301ed6f20e4dfeb1b413897eec0ce1e99458a021315586f59b3273775dc34c7
3836
vnc.exe
C:\Users\admin\AppData\Roaming\FileZilla\queue.sqlite3
––
MD5:  ––
SHA256:  ––
3836
vnc.exe
C:\Users\admin\AppData\Roaming\FileZilla\filezilla.xml
––
MD5:  ––
SHA256:  ––
3836
vnc.exe
C:\Users\admin\AppData\Roaming\Microsoft\Crypto\RSA\S-1-5-21-1302019708-1500728564-335382590-1000\0f5007522459c86e95ffcc62f32308f1_90059c37-1320-41a4-b58d-2b75a9850d2f
––
MD5:  ––
SHA256:  ––
3836
vnc.exe
C:\Users\admin\AppData\Roaming\FileZilla\layout.xml
––
MD5:  ––
SHA256:  ––
3836
vnc.exe
C:\Users\admin\AppData\Roaming\Adobe\Sonar\Sonar1.0\sonar_policy.xml.KRAB
binary
MD5: 686d43499d86bc1aa85a6ef6eeb8d210
SHA256: dd9383b9639cc1dda9d4e94e579e03f2bebd9ac44bc8818d298e46e62d89f015
3836
vnc.exe
C:\Users\admin\AppData\Roaming\Adobe\LogTransport2\Logs\ulog_AcroARM2_Reader_2274f67c-7a7f-45e3-a23e-aa35d5b91e00_02f147fa-0489-4885-b993-ed9936fcacc0_0.rdy.KRAB
flc
MD5: 5ddf2deda82cd52694a5879215a4bfa0
SHA256: da5b0c91bc8ebede6d19744bb161f66e1fd449836c570b003f662d0f9993fe4d
3836
vnc.exe
C:\Users\admin\AppData\Roaming\Adobe\Sonar\KRAB-DECRYPT.txt
text
MD5: a285a299dbaaeaa3588106a648e72592
SHA256: 0826dba102ad61a52719d327e8a6b9c8897f66278362b1f7b06eab3cb57b9a73
3836
vnc.exe
C:\Users\admin\AppData\Roaming\Adobe\Sonar\Sonar1.0\KRAB-DECRYPT.txt
text
MD5: a285a299dbaaeaa3588106a648e72592
SHA256: 0826dba102ad61a52719d327e8a6b9c8897f66278362b1f7b06eab3cb57b9a73
3836
vnc.exe
C:\Users\admin\AppData\Roaming\FileZilla\KRAB-DECRYPT.txt
text
MD5: a285a299dbaaeaa3588106a648e72592
SHA256: 0826dba102ad61a52719d327e8a6b9c8897f66278362b1f7b06eab3cb57b9a73
3836
vnc.exe
C:\Users\admin\AppData\Roaming\Adobe\LogTransport2\LogTransport2.cfg.KRAB
binary
MD5: e5555cb3dfeec59ac3fc9409b9676ef1
SHA256: eccd522f8c60258a33031c81309d7bc84d523c7577f1686654ce9c33d4517199
3836
vnc.exe
C:\Users\admin\AppData\Roaming\Adobe\LogTransport2\Logs\ulog_HeadlightsOptinProductFamily_HeadlightsOptinProduct_00000000-0000-0000-0000-000000000000_dc2ece58-8a8b-40bf-98c2-48039a3392bd.log.KRAB
binary
MD5: 9f64634ffcc3aa8cdaf4bfef6ae0a447
SHA256: 2071bde5338e909b13f80061491328fa0840e7e376c0ab27e37663f3cddc2f2e
3836
vnc.exe
C:\Users\admin\AppData\Roaming\Adobe\LogTransport2\Logs\ulog_AcroARM2_Reader_2274f67c-7a7f-45e3-a23e-aa35d5b91e00_02f147fa-0489-4885-b993-ed9936fcacc0_0.rdy
––
MD5:  ––
SHA256:  ––
3836
vnc.exe
C:\Users\admin\AppData\Roaming\Adobe\Sonar\Sonar1.0\sonar_policy.xml
––
MD5:  ––
SHA256:  ––
3836
vnc.exe
C:\Users\admin\AppData\Roaming\Adobe\LogTransport2\LogTransport2.cfg
––
MD5:  ––
SHA256:  ––
3836
vnc.exe
C:\Users\admin\AppData\Roaming\Adobe\LogTransport2\Logs\ulog_HeadlightsOptinProductFamily_HeadlightsOptinProduct_00000000-0000-0000-0000-000000000000_dc2ece58-8a8b-40bf-98c2-48039a3392bd.log
––
MD5:  ––
SHA256:  ––
3836
vnc.exe
C:\Users\admin\AppData\Roaming\Adobe\LogTransport2\Logs\ulog_AcroARM2_ARM2Update_2274f67c-7a7f-45e3-a23e-aa35d5b91e00_fea03e67-af51-4fcb-b57f-c238867edb9b_0.log.KRAB
binary
MD5: 1faa47cf9be411878cfe1655d13d2c92
SHA256: c505b25e0d92555e32f6ec4d641daac122a88b5f2c134b89fc85cc2895263326
3836
vnc.exe
C:\Users\admin\AppData\Roaming\Adobe\Headlights\KRAB-DECRYPT.txt
text
MD5: a285a299dbaaeaa3588106a648e72592
SHA256: 0826dba102ad61a52719d327e8a6b9c8897f66278362b1f7b06eab3cb57b9a73
3836
vnc.exe
C:\Users\admin\AppData\Roaming\Adobe\Flash Player\KRAB-DECRYPT.txt
text
MD5: a285a299dbaaeaa3588106a648e72592
SHA256: 0826dba102ad61a52719d327e8a6b9c8897f66278362b1f7b06eab3cb57b9a73
3836
vnc.exe
C:\Users\admin\AppData\Roaming\Adobe\Linguistics\KRAB-DECRYPT.txt
text
MD5: a285a299dbaaeaa3588106a648e72592
SHA256: 0826dba102ad61a52719d327e8a6b9c8897f66278362b1f7b06eab3cb57b9a73
3836
vnc.exe
C:\Users\admin\AppData\Roaming\Adobe\Flash Player\AssetCache\J7D4H966\KRAB-DECRYPT.txt
text
MD5: a285a299dbaaeaa3588106a648e72592
SHA256: 0826dba102ad61a52719d327e8a6b9c8897f66278362b1f7b06eab3cb57b9a73
3836
vnc.exe
C:\Users\admin\AppData\Roaming\Adobe\Acrobat\DC\Security\KRAB-DECRYPT.txt
text
MD5: a285a299dbaaeaa3588106a648e72592
SHA256: 0826dba102ad61a52719d327e8a6b9c8897f66278362b1f7b06eab3cb57b9a73
3836
vnc.exe
C:\Users\admin\AppData\Roaming\Adobe\LogTransport2\Logs\KRAB-DECRYPT.txt
text
MD5: a285a299dbaaeaa3588106a648e72592
SHA256: 0826dba102ad61a52719d327e8a6b9c8897f66278362b1f7b06eab3cb57b9a73
3836
vnc.exe
C:\Users\admin\AppData\Roaming\Adobe\Acrobat\DC\Security\CRLCache\KRAB-DECRYPT.txt
text
MD5: a285a299dbaaeaa3588106a648e72592
SHA256: 0826dba102ad61a52719d327e8a6b9c8897f66278362b1f7b06eab3cb57b9a73
3836
vnc.exe
C:\Users\admin\AppData\Roaming\Adobe\Flash Player\NativeCache\KRAB-DECRYPT.txt
text
MD5: a285a299dbaaeaa3588106a648e72592
SHA256: 0826dba102ad61a52719d327e8a6b9c8897f66278362b1f7b06eab3cb57b9a73
3836
vnc.exe
C:\Users\admin\AppData\Roaming\Adobe\Acrobat\DC\Security\addressbook.acrodata.KRAB
binary
MD5: 6bc5fdd32b549b58e3537c73ee40129a
SHA256: 8290e8b84327c80a2348b5df9cbe584654162931f9ab49e32e91a17a0e53590a
3836
vnc.exe
C:\Users\admin\AppData\Roaming\Adobe\LogTransport2\KRAB-DECRYPT.txt
text
MD5: a285a299dbaaeaa3588106a648e72592
SHA256: 0826dba102ad61a52719d327e8a6b9c8897f66278362b1f7b06eab3cb57b9a73
3836
vnc.exe
C:\Users\admin\AppData\Roaming\Adobe\Acrobat\DC\Security\CRLCache\0FDED5CEB68C302B1CDB2BDDD9D0000E76539CB0.crl.KRAB
binary
MD5: de9bfb6bf52c0d4bf4ea785559b6a6df
SHA256: c563967c83d51971fd12bb513564126f3c4537c38a479f7dd6ab8744974ddba9
3836
vnc.exe
C:\Users\admin\AppData\Roaming\Adobe\Acrobat\DC\Security\CRLCache\CE338828149963DCEA4CD26BB86F0363B4CA0BA5.crl.KRAB
binary
MD5: 20a3b33a5612a1c180bfc508689e846b
SHA256: 46cbe2df56371b21b3453789a3136fea084bbed2fed9f6eeacb1016a80f8713e
3836
vnc.exe
C:\Users\admin\AppData\Roaming\Adobe\Flash Player\AssetCache\KRAB-DECRYPT.txt
text
MD5: a285a299dbaaeaa3588106a648e72592
SHA256: 0826dba102ad61a52719d327e8a6b9c8897f66278362b1f7b06eab3cb57b9a73
3836
vnc.exe
C:\Users\admin\AppData\Roaming\Adobe\LogTransport2\Logs\ulog_AcroARM2_ARM2Update_2274f67c-7a7f-45e3-a23e-aa35d5b91e00_fea03e67-af51-4fcb-b57f-c238867edb9b_0.log
––
MD5:  ––
SHA256:  ––
3836
vnc.exe
C:\Users\admin\AppData\Roaming\Adobe\Acrobat\DC\Security\CRLCache\0FDED5CEB68C302B1CDB2BDDD9D0000E76539CB0.crl
––
MD5:  ––
SHA256:  ––
3836
vnc.exe
C:\Users\admin\AppData\Roaming\Adobe\Acrobat\DC\Security\CRLCache\CE338828149963DCEA4CD26BB86F0363B4CA0BA5.crl
––
MD5:  ––
SHA256:  ––
3836
vnc.exe
C:\Users\admin\AppData\Roaming\Adobe\Acrobat\DC\Security\addressbook.acrodata
––
MD5:  ––
SHA256:  ––
3836
vnc.exe
C:\Users\admin\AppData\Roaming\Adobe\Acrobat\DC\JSCache\KRAB-DECRYPT.txt
text
MD5: a285a299dbaaeaa3588106a648e72592
SHA256: 0826dba102ad61a52719d327e8a6b9c8897f66278362b1f7b06eab3cb57b9a73
3836
vnc.exe
C:\Users\admin\.oracle_jre_usage\KRAB-DECRYPT.txt
text
MD5: a285a299dbaaeaa3588106a648e72592
SHA256: 0826dba102ad61a52719d327e8a6b9c8897f66278362b1f7b06eab3cb57b9a73
3836
vnc.exe
C:\Users\admin\AppData\Roaming\Adobe\Acrobat\DC\Forms\KRAB-DECRYPT.txt
text
MD5: a285a299dbaaeaa3588106a648e72592
SHA256: 0826dba102ad61a52719d327e8a6b9c8897f66278362b1f7b06eab3cb57b9a73
3836
vnc.exe
C:\Users\admin\AppData\Roaming\Adobe\Acrobat\DC\JSCache\GlobSettings.KRAB
binary
MD5: 17abe54f4cefda147da737197d094d28
SHA256: 49710a17410460c5b88f6d955cf3bf00b7fa36e5ca71b71c20a1489f7a9b607a
3836
vnc.exe
C:\Users\admin\AppData\Roaming\Adobe\Acrobat\DC\KRAB-DECRYPT.txt
text
MD5: a285a299dbaaeaa3588106a648e72592
SHA256: 0826dba102ad61a52719d327e8a6b9c8897f66278362b1f7b06eab3cb57b9a73
3836
vnc.exe
C:\Users\admin\AppData\Roaming\Adobe\Acrobat\KRAB-DECRYPT.txt
text
MD5: a285a299dbaaeaa3588106a648e72592
SHA256: 0826dba102ad61a52719d327e8a6b9c8897f66278362b1f7b06eab3cb57b9a73
3836
vnc.exe
C:\Users\admin\AppData\KRAB-DECRYPT.txt
text
MD5: a285a299dbaaeaa3588106a648e72592
SHA256: 0826dba102ad61a52719d327e8a6b9c8897f66278362b1f7b06eab3cb57b9a73
3836
vnc.exe
C:\Users\admin\AppData\Roaming\Adobe\Acrobat\DC\Collab\KRAB-DECRYPT.txt
text
MD5: a285a299dbaaeaa3588106a648e72592
SHA256: 0826dba102ad61a52719d327e8a6b9c8897f66278362b1f7b06eab3cb57b9a73
3836
vnc.exe
C:\Users\admin\AppData\Roaming\KRAB-DECRYPT.txt
text
MD5: a285a299dbaaeaa3588106a648e72592
SHA256: 0826dba102ad61a52719d327e8a6b9c8897f66278362b1f7b06eab3cb57b9a73
3836
vnc.exe
C:\Users\admin\KRAB-DECRYPT.txt
text
MD5: a285a299dbaaeaa3588106a648e72592
SHA256: 0826dba102ad61a52719d327e8a6b9c8897f66278362b1f7b06eab3cb57b9a73
3836
vnc.exe
C:\Users\admin\AppData\Roaming\Adobe\KRAB-DECRYPT.txt
text
MD5: a285a299dbaaeaa3588106a648e72592
SHA256: 0826dba102ad61a52719d327e8a6b9c8897f66278362b1f7b06eab3cb57b9a73
3836
vnc.exe
C:\Users\admin\AppData\Roaming\Adobe\Acrobat\DC\JSCache\GlobData.KRAB
binary
MD5: 4266c671bac3bb9688b4b7a4a0fcbf02
SHA256: df90bb019300670592dd4e45d987682877c8c4e8554ad4682134399ae47c2788
3836
vnc.exe
C:\Users\admin\.oracle_jre_usage\90737d32e3abaa4.timestamp.KRAB
binary
MD5: 047b7e6d6af01a5616d71e2d7689cdec
SHA256: 8ca7d9dc2b5dbc2bfaebf65f77296e966a6eeb853ed241618c64810a38b70a14
3836
vnc.exe
C:\Users\admin\AppData\Roaming\Adobe\Acrobat\DC\JSCache\GlobSettings
––
MD5:  ––
SHA256:  ––
3836
vnc.exe
C:\Users\admin\.oracle_jre_usage\90737d32e3abaa4.timestamp
––
MD5:  ––
SHA256:  ––
3836
vnc.exe
C:\Users\admin\AppData\Roaming\Adobe\Acrobat\DC\JSCache\GlobData
––
MD5:  ––
SHA256:  ––
3836
vnc.exe
C:\$Recycle.Bin\S-1-5-21-1302019708-1500728564-335382590-1000\KRAB-DECRYPT.txt
text
MD5: a285a299dbaaeaa3588106a648e72592
SHA256: 0826dba102ad61a52719d327e8a6b9c8897f66278362b1f7b06eab3cb57b9a73

Find more information of the staic content and download it at the full report

Network activity

HTTP(S) requests
3
TCP/UDP connections
4
DNS requests
2
Threats
0

HTTP requests

PID Process Method HTTP Code IP URL CN Type Size Reputation
3836 vnc.exe GET 302 217.160.0.234:80 http://www.billerimpex.com/ DE
html
malicious
3836 vnc.exe GET –– 52.29.192.136:80 http://www.macartegrise.eu/ DE
––
––
malicious
3836 vnc.exe POST –– 52.29.192.136:80 http://www.macartegrise.eu/uploads/assets/kaimfu.gif DE
text
––
––
malicious

Download PCAP, analyze network streams, HTTP content and a lot more at the full report

Connections

PID Process IP ASN CN Reputation
3836 vnc.exe 217.160.0.234:80 1&1 Internet SE DE suspicious
3836 vnc.exe 217.160.0.234:443 1&1 Internet SE DE suspicious
3836 vnc.exe 52.29.192.136:80 Amazon.com, Inc. DE whitelisted

DNS requests

Domain IP Reputation
www.billerimpex.com 217.160.0.234
malicious
www.macartegrise.eu 52.29.192.136
malicious

Threats

No threats detected.

Debug output strings

No debug info.