General Info

File name

GandCrab.exe

Full analysis
https://app.any.run/tasks/3c768858-2d99-4577-b76e-2b1941c54c95
Verdict
Malicious activity
Analysis date
8/13/2019, 15:36:41
OS:
Windows 7 Professional Service Pack 1 (build: 7601, 32 bit)
Tags:

ransomware

gandcrab

Indicators:

MIME:
application/x-dosexec
File info:
PE32 executable (GUI) Intel 80386, for MS Windows
MD5

07fadb006486953439ce0092651fd7a6

SHA1

e42431d37561cc695de03b85e8e99c9e31321742

SHA256

d77378dcc42b912e514d3bd4466cdda050dda9b57799a6c97f70e8489dd8c8d0

SSDEEP

3072:Ealy19emgKe0QuYS3UmWuDTEltI3S/7IarDrjCgrQp0M7W:EaqxxDwx/7IS40MS

ANY.RUN is an interactive service which provides full access to the guest system. Information in this report could be distored by user actions and is provided for user acknowledgement as it is. ANY.RUN does not guarantee maliciousness or safety of the content.

Software environment set and analysis options

Launch configuration

Task duration
300 seconds
Additional time used
240 seconds
Fakenet option
off
Heavy Evaision option
off
MITM proxy
off
Route via Tor
off
Network geolocation
off
Privacy
Public submission
Autoconfirmation of UAC
off

Software preset

  • Internet Explorer 8.0.7601.17514
  • Adobe Acrobat Reader DC MUI (15.023.20070)
  • Adobe Flash Player 26 ActiveX (26.0.0.131)
  • Adobe Flash Player 26 NPAPI (26.0.0.131)
  • Adobe Flash Player 26 PPAPI (26.0.0.131)
  • Adobe Refresh Manager (1.8.0)
  • CCleaner (5.35)
  • FileZilla Client 3.36.0 (3.36.0)
  • Google Chrome (75.0.3770.100)
  • Google Update Helper (1.3.34.7)
  • Java 8 Update 92 (8.0.920.14)
  • Java Auto Updater (2.8.92.14)
  • Microsoft .NET Framework 4.7.2 (4.7.03062)
  • Microsoft Office Access MUI (English) 2010 (14.0.6029.1000)
  • Microsoft Office Access Setup Metadata MUI (English) 2010 (14.0.6029.1000)
  • Microsoft Office Excel MUI (English) 2010 (14.0.6029.1000)
  • Microsoft Office OneNote MUI (English) 2010 (14.0.6029.1000)
  • Microsoft Office Outlook MUI (English) 2010 (14.0.6029.1000)
  • Microsoft Office PowerPoint MUI (English) 2010 (14.0.6029.1000)
  • Microsoft Office Professional 2010 (14.0.6029.1000)
  • Microsoft Office Proof (English) 2010 (14.0.6029.1000)
  • Microsoft Office Proof (French) 2010 (14.0.6029.1000)
  • Microsoft Office Proof (Spanish) 2010 (14.0.6029.1000)
  • Microsoft Office Proofing (English) 2010 (14.0.6029.1000)
  • Microsoft Office Publisher MUI (English) 2010 (14.0.6029.1000)
  • Microsoft Office Shared MUI (English) 2010 (14.0.6029.1000)
  • Microsoft Office Shared Setup Metadata MUI (English) 2010 (14.0.6029.1000)
  • Microsoft Office Single Image 2010 (14.0.6029.1000)
  • Microsoft Office Word MUI (English) 2010 (14.0.6029.1000)
  • Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.6161 (9.0.30729.6161)
  • Microsoft Visual C++ 2010 x86 Redistributable - 10.0.40219 (10.0.40219)
  • Microsoft Visual C++ 2013 Redistributable (x86) - 12.0.30501 (12.0.30501.0)
  • Microsoft Visual C++ 2013 x86 Additional Runtime - 12.0.21005 (12.0.21005)
  • Microsoft Visual C++ 2013 x86 Minimum Runtime - 12.0.21005 (12.0.21005)
  • Microsoft Visual C++ 2015-2019 Redistributable (x86) - 14.21.27702 (14.21.27702.2)
  • Microsoft Visual C++ 2019 X86 Additional Runtime - 14.21.27702 (14.21.27702)
  • Microsoft Visual C++ 2019 X86 Minimum Runtime - 14.21.27702 (14.21.27702)
  • Mozilla Firefox 68.0.1 (x86 en-US) (68.0.1)
  • Notepad++ (32-bit x86) (7.5.1)
  • Opera 12.15 (12.15.1748)
  • Skype version 8.29 (8.29)
  • Update for Microsoft .NET Framework 4.7.2 (KB4087364) (1)
  • VLC media player (2.2.6)
  • WinRAR 5.60 (32-bit) (5.60.0)

Hotfixes

  • Client LanguagePack Package
  • Client Refresh LanguagePack Package
  • CodecPack Basic Package
  • Foundation Package
  • IE Troubleshooters Package
  • InternetExplorer Optional Package
  • KB2534111
  • KB2999226
  • KB4019990
  • KB976902
  • LocalPack AU Package
  • LocalPack CA Package
  • LocalPack GB Package
  • LocalPack US Package
  • LocalPack ZA Package
  • ProfessionalEdition
  • UltimateEdition

Behavior activities

MALICIOUS SUSPICIOUS INFO
Writes file to Word startup folder
  • GandCrab.exe (PID: 2564)
Renames files like Ransomware
  • GandCrab.exe (PID: 2564)
Deletes shadow copies
  • GandCrab.exe (PID: 2564)
GandCrab keys found
  • GandCrab.exe (PID: 2564)
Actions looks like stealing of personal data
  • GandCrab.exe (PID: 2564)
Creates files like Ransomware instruction
  • GandCrab.exe (PID: 2564)
Reads the cookies of Mozilla Firefox
  • GandCrab.exe (PID: 2564)
Creates files in the user directory
  • GandCrab.exe (PID: 2564)
Dropped object may contain Bitcoin addresses
  • GandCrab.exe (PID: 2564)
Manual execution by user
  • GandCrab.exe (PID: 2956)
  • GandCrab.exe (PID: 3376)

Find more information about signature artifacts and mapping to MITRE ATT&CK™ MATRIX at the full report

Static information

TRiD
.exe
|   Win32 Executable MS Visual C++ (generic) (42.2%)
.exe
|   Win64 Executable (generic) (37.3%)
.dll
|   Win32 Dynamic Link Library (generic) (8.8%)
.exe
|   Win32 Executable (generic) (6%)
.exe
|   Generic Win/DOS Executable (2.7%)
EXIF
EXE
MachineType:
Intel 386 or later, and compatibles
TimeStamp:
2018:09:24 09:47:02+02:00
PEType:
PE32
LinkerVersion:
12
CodeSize:
79360
InitializedDataSize:
114688
UninitializedDataSize:
null
EntryPoint:
0x6314
OSVersion:
5.1
ImageVersion:
null
SubsystemVersion:
5.1
Subsystem:
Windows GUI
Summary
Architecture:
IMAGE_FILE_MACHINE_I386
Subsystem:
IMAGE_SUBSYSTEM_WINDOWS_GUI
Compilation Date:
24-Sep-2018 07:47:02
Detected languages
English - United States
DOS Header
Magic number:
MZ
Bytes on last page of file:
0x0090
Pages in file:
0x0003
Relocations:
0x0000
Size of header:
0x0004
Min extra paragraphs:
0x0000
Max extra paragraphs:
0xFFFF
Initial SS value:
0x0000
Initial SP value:
0x00B8
Checksum:
0x0000
Initial IP value:
0x0000
Initial CS value:
0x0000
Overlay number:
0x0000
OEM identifier:
0x0000
OEM information:
0x0000
Address of NE header:
0x000000F0
PE Headers
Signature:
PE
Machine:
IMAGE_FILE_MACHINE_I386
Number of sections:
5
Time date stamp:
24-Sep-2018 07:47:02
Pointer to Symbol Table:
0x00000000
Number of symbols:
0
Size of Optional Header:
0x00E0
Characteristics
IMAGE_FILE_32BIT_MACHINE
IMAGE_FILE_EXECUTABLE_IMAGE
Sections
Name Virtual Address Virtual Size Raw Size Charateristics Entropy
.text 0x00001000 0x00013474 0x00013600 IMAGE_SCN_CNT_CODE,IMAGE_SCN_MEM_EXECUTE,IMAGE_SCN_MEM_READ 6.57387
.rdata 0x00015000 0x00006EE0 0x00007000 IMAGE_SCN_CNT_INITIALIZED_DATA,IMAGE_SCN_MEM_READ 4.58949
.data 0x0001C000 0x000138F4 0x00011C00 IMAGE_SCN_CNT_INITIALIZED_DATA,IMAGE_SCN_MEM_READ,IMAGE_SCN_MEM_WRITE 4.85604
.rsrc 0x00030000 0x000001E0 0x00000200 IMAGE_SCN_CNT_INITIALIZED_DATA,IMAGE_SCN_MEM_READ 4.7015
.reloc 0x00031000 0x000013B4 0x00001400 IMAGE_SCN_CNT_INITIALIZED_DATA,IMAGE_SCN_MEM_DISCARDABLE,IMAGE_SCN_MEM_READ 6.65085
Resources
1

Imports
    KERNEL32.dll

    USER32.dll

    GDI32.dll

    ADVAPI32.dll

    SHELL32.dll

    ole32.dll

    MPR.dll

    WININET.dll

    XPSPRINT.DLL

    RPCRT4.dll

Exports

    No exports.

Screenshots

Processes

Total processes
43
Monitored processes
4
Malicious processes
1
Suspicious processes
0

Behavior graph

+
start #GANDCRAB gandcrab.exe wmic.exe no specs gandcrab.exe no specs gandcrab.exe
Specs description
Program did not start
Integrity level elevation
Task сontains an error or was rebooted
Process has crashed
Task contains several apps running
Executable file was dropped
Debug information is available
Process was injected
Network attacks were detected
Application downloaded the executable file
Actions similar to stealing personal data
Behavior similar to exploiting the vulnerability
Inspected object has sucpicious PE structure
File is detected by antivirus software
CPU overrun
RAM overrun
Process starts the services
Process was added to the startup
Behavior similar to spam
Low-level access to the HDD
Probably Tor was used
System was rebooted
Connects to the network
Known threat

Process information

Click at the process to see the details.

PID
2564
CMD
"C:\Users\admin\Desktop\GandCrab.exe"
Path
C:\Users\admin\Desktop\GandCrab.exe
Indicators
Parent process
––
User
admin
Integrity Level
MEDIUM
Version:
Company
Description
Version
Modules
Image
c:\users\admin\desktop\gandcrab.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\shell32.dll
c:\windows\system32\shlwapi.dll
c:\windows\system32\ole32.dll
c:\windows\system32\mpr.dll
c:\windows\system32\wininet.dll
c:\windows\system32\urlmon.dll
c:\windows\system32\oleaut32.dll
c:\windows\system32\crypt32.dll
c:\windows\system32\msasn1.dll
c:\windows\system32\iertutil.dll
c:\windows\system32\xpsprint.dll
c:\windows\system32\prntvpt.dll
c:\windows\system32\version.dll
c:\windows\system32\winspool.drv
c:\windows\system32\xpsgdiconverter.dll
c:\windows\system32\d2d1.dll
c:\windows\system32\dwrite.dll
c:\windows\system32\xpsservices.dll
c:\windows\system32\opcservices.dll
c:\windows\system32\imm32.dll
c:\windows\system32\msctf.dll
c:\windows\system32\profapi.dll
c:\windows\system32\sspicli.dll
c:\windows\system32\cryptsp.dll
c:\windows\winsxs\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_41e6975e2bd6f2b2\comctl32.dll
c:\windows\system32\rsaenh.dll
c:\windows\system32\cryptbase.dll
c:\windows\system32\ntmarta.dll
c:\windows\system32\wldap32.dll
c:\windows\system32\ws2_32.dll
c:\windows\system32\nsi.dll
c:\windows\system32\dnsapi.dll
c:\windows\system32\iphlpapi.dll
c:\windows\system32\winnsi.dll
c:\windows\system32\normaliz.dll
c:\windows\system32\rasapi32.dll
c:\windows\system32\rasman.dll
c:\windows\system32\rtutils.dll
c:\windows\system32\sensapi.dll
c:\windows\system32\nlaapi.dll
c:\windows\system32\rasadhlp.dll
c:\windows\system32\mswsock.dll
c:\windows\system32\wshtcpip.dll
c:\windows\system32\wship6.dll
c:\windows\system32\fwpuclnt.dll
c:\windows\system32\drprov.dll
c:\windows\system32\winsta.dll
c:\windows\system32\ntlanman.dll
c:\windows\system32\davclnt.dll
c:\windows\system32\davhlpr.dll
c:\windows\system32\wkscli.dll
c:\windows\system32\cscapi.dll
c:\windows\system32\netutils.dll
c:\windows\system32\browcli.dll
c:\windows\system32\userenv.dll
c:\windows\system32\wintrust.dll
c:\windows\system32\schannel.dll
c:\windows\system32\propsys.dll
c:\windows\system32\clbcatq.dll
c:\windows\system32\setupapi.dll
c:\windows\system32\cfgmgr32.dll
c:\windows\system32\devobj.dll
c:\windows\system32\apphelp.dll
c:\windows\system32\wbem\wmic.exe
c:\windows\system32\iconcodecservice.dll
c:\windows\system32\windowscodecs.dll
c:\windows\system32\credssp.dll
c:\windows\system32\secur32.dll
c:\windows\system32\ncrypt.dll
c:\windows\system32\bcrypt.dll
c:\windows\system32\bcryptprimitives.dll
c:\windows\system32\gpapi.dll

PID
3528
CMD
"C:\Windows\system32\wbem\wmic.exe" shadowcopy delete
Path
C:\Windows\system32\wbem\wmic.exe
Indicators
No indicators
Parent process
GandCrab.exe
User
admin
Integrity Level
MEDIUM
Exit code
2147749908
Version:
Company
Microsoft Corporation
Description
WMI Commandline Utility
Version
6.1.7600.16385 (win7_rtm.090713-1255)
Modules
Image
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\ole32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\user32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\oleaut32.dll
c:\windows\system32\framedynos.dll
c:\windows\system32\sspicli.dll
c:\windows\system32\wtsapi32.dll
c:\windows\system32\shlwapi.dll
c:\windows\system32\ws2_32.dll
c:\windows\system32\nsi.dll
c:\windows\system32\secur32.dll
c:\windows\system32\iphlpapi.dll
c:\windows\system32\winnsi.dll
c:\windows\system32\imm32.dll
c:\windows\system32\msctf.dll
c:\windows\system32\cryptbase.dll
c:\windows\system32\clbcatq.dll
c:\windows\system32\wbem\wbemprox.dll
c:\windows\system32\wbemcomn.dll
c:\windows\system32\msxml3.dll
c:\windows\system32\urlmon.dll
c:\windows\system32\wininet.dll
c:\windows\system32\crypt32.dll
c:\windows\system32\msasn1.dll
c:\windows\system32\iertutil.dll
c:\windows\winsxs\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_41e6975e2bd6f2b2\comctl32.dll
c:\windows\system32\shell32.dll
c:\windows\system32\profapi.dll
c:\windows\system32\dnsapi.dll
c:\windows\system32\cryptsp.dll
c:\windows\system32\rsaenh.dll
c:\windows\system32\rpcrtremote.dll
c:\program files\common files\microsoft shared\office14\msoxmlmf.dll
c:\windows\system32\wbem\wmic.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\winsxs\x86_microsoft.vc90.crt_1fc8b3b9a1e18e3b_9.0.30729.6161_none_50934f2ebcb7eb57\msvcr90.dll
c:\windows\system32\wbem\wbemsvc.dll
c:\windows\system32\wbem\fastprox.dll
c:\windows\system32\ntdsapi.dll
c:\windows\system32\wbem\wmiutils.dll

PID
2956
CMD
"C:\Users\admin\Desktop\GandCrab.exe"
Path
C:\Users\admin\Desktop\GandCrab.exe
Indicators
No indicators
Parent process
––
User
admin
Integrity Level
MEDIUM
Exit code
0
Version:
Company
Description
Version
Modules
Image
c:\users\admin\desktop\gandcrab.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\shell32.dll
c:\windows\system32\shlwapi.dll
c:\windows\system32\ole32.dll
c:\windows\system32\mpr.dll
c:\windows\system32\wininet.dll
c:\windows\system32\urlmon.dll
c:\windows\system32\oleaut32.dll
c:\windows\system32\crypt32.dll
c:\windows\system32\msasn1.dll
c:\windows\system32\iertutil.dll
c:\windows\system32\xpsprint.dll
c:\windows\system32\prntvpt.dll
c:\windows\system32\version.dll
c:\windows\system32\winspool.drv
c:\windows\system32\xpsgdiconverter.dll
c:\windows\system32\d2d1.dll
c:\windows\system32\dwrite.dll
c:\windows\system32\xpsservices.dll
c:\windows\system32\opcservices.dll
c:\windows\system32\imm32.dll
c:\windows\system32\msctf.dll
c:\windows\system32\profapi.dll

PID
3376
CMD
"C:\Users\admin\Desktop\GandCrab.exe"
Path
C:\Users\admin\Desktop\GandCrab.exe
Indicators
Parent process
––
User
admin
Integrity Level
HIGH
Exit code
0
Version:
Company
Description
Version
Modules
Image
c:\users\admin\desktop\gandcrab.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\shell32.dll
c:\windows\system32\shlwapi.dll
c:\windows\system32\ole32.dll
c:\windows\system32\mpr.dll
c:\windows\system32\wininet.dll
c:\windows\system32\urlmon.dll
c:\windows\system32\oleaut32.dll
c:\windows\system32\crypt32.dll
c:\windows\system32\msasn1.dll
c:\windows\system32\iertutil.dll
c:\windows\system32\xpsprint.dll
c:\windows\system32\prntvpt.dll
c:\windows\system32\version.dll
c:\windows\system32\winspool.drv
c:\windows\system32\xpsgdiconverter.dll
c:\windows\system32\d2d1.dll
c:\windows\system32\dwrite.dll
c:\windows\system32\xpsservices.dll
c:\windows\system32\opcservices.dll
c:\windows\system32\imm32.dll
c:\windows\system32\msctf.dll
c:\windows\system32\profapi.dll

Registry activity

Total events
119
Read events
88
Write events
31
Delete events
0

Modification events

PID
Process
Operation
Key
Name
Value
2564
GandCrab.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Tracing\GandCrab_RASAPI32
EnableFileTracing
0
2564
GandCrab.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Tracing\GandCrab_RASAPI32
EnableConsoleTracing
0
2564
GandCrab.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Tracing\GandCrab_RASAPI32
FileTracingMask
4294901760
2564
GandCrab.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Tracing\GandCrab_RASAPI32
ConsoleTracingMask
4294901760
2564
GandCrab.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Tracing\GandCrab_RASAPI32
MaxFileSize
1048576
2564
GandCrab.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Tracing\GandCrab_RASAPI32
FileDirectory
%windir%\tracing
2564
GandCrab.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Tracing\GandCrab_RASMANCS
EnableFileTracing
0
2564
GandCrab.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Tracing\GandCrab_RASMANCS
EnableConsoleTracing
0
2564
GandCrab.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Tracing\GandCrab_RASMANCS
FileTracingMask
4294901760
2564
GandCrab.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Tracing\GandCrab_RASMANCS
ConsoleTracingMask
4294901760
2564
GandCrab.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Tracing\GandCrab_RASMANCS
MaxFileSize
1048576
2564
GandCrab.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Tracing\GandCrab_RASMANCS
FileDirectory
%windir%\tracing
2564
GandCrab.exe
write
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings
ProxyEnable
0
2564
GandCrab.exe
write
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Connections
SavedLegacySettings
4600000092000000010000000000000000000000000000000000000000000000C0E333BBEAB1D301000000000000000000000000020000001700000000000000FE800000000000007D6CB050D9C573F70B000000000000006D00330032005C004D00530049004D004700330032002E0064006C000100000004AA400014AA4000040000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000002000000C0A8016400000000000000000000000000000000000000000800000000000000805D3F00983740000008000002000000000000600000002060040000B8A94000020000008802000060040000B8A9400004000000F8010000B284000088B64000B84B400043003A000000000000000000000000000000000000000000
2564
GandCrab.exe
write
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap
UNCAsIntranet
0
2564
GandCrab.exe
write
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap
AutoDetect
1
2564
GandCrab.exe
write
HKEY_CURRENT_USER\Software\ex_data\data
ext
2E0075006100700072006F000000
2564
GandCrab.exe
write
HKEY_CURRENT_USER\Software\keys_data\data
public
0602000000A40000525341310008000001000100C13889F9144ABC0C38F1CDC27F13BD9EA701858C5F3739540C1CC9202EDA8E1BB9879656C59012D0581C684E4069E90A9CE70515B85BCFEB95FD48472F53AAA4B8C6D15C6144A86B22AEFAEE574B44AAAECDA0376DAC3A40318DE958A3615DCDC7AD83B02FE64CE53611CD6EC65024A49D943CD3E3005258C0D937E7D86C70C4C7BFEE5D511129C6B8B7A871862832998F0F95B145A827A5B5F2C4217099819B43F65EB93697D63A5E59B3BE3378B3E93B15E728C41CF8C32BA039D10C9ED7596A6E7E88FBAA97E1C9BEA2F69C18CE60760984C8B0F55F1A2DA070E6382593AAE1DDF50FB1C010BA383B6EFFC8DCE16A82E8118B0D92ED3FA855E9E3A6DAA5C2
2564
GandCrab.exe
write
HKEY_CURRENT_USER\Software\keys_data\data
private
94040000B2EED4C9A1CFFAB5A5F7A085A2C7BD8D15C0DEB581CEB68AAA45BBDC690FC9763B9F41A29A27353C24ABF3770BAA653BC1A8539AD127FEBD988D05961DA969A4FB1D299F0F89461D297A036F8509DA20DCA60332A35A0620A5F7718C3D69EC5B61BADA51E0968710B9FD1B04B8C7ABA66525AD93742C6BA530E7407D68B9828F6C6F65AA876ECA18A0FEEDCFAD781E20362F52349620E2C01380392319868F7AC4E81D5AAB11A64EC7A7BB35B65BBC4AA2A32E9746C5DDC4BF17BA8F8C81B163A5F1CE3FF82282532C0A5057CBBF5155480082CBDA1A22361707C77C7F0AF60B8604DDA7BF7F56B012C9479B600658784DB9EFA1011E42CACCE13814A92B3D5F097ED2E9B2094303755EC9F2C8AD2EB7BE6BE740828FBEE99D9876FBC86B1410F20F47A4ADC7A534AC8A4451410036735588A236508FD89B23C4DD159C204DABCABF7C3BDD25A6206A299DF688D6B1E20D608C48271B5F8224479041CA970162482E6D51A25D6A4A4C4519F757C26E1245538B2FD4B7149E1FA0F75C585ED07649DB5AD42BF545DAF5061CD2CD9C461C16DDE349F4DFB1E823D1949B8E1EBB71FC130C94EEDD42F2239480D88C5925F375920FDDF8A26670FFE387F1D840E6D792FF4BAFDAD4319FF2C4A030C9A581949138B564855CA73999D9BE54C29CB05E7F5BCD1B8D18677C73DF305B9C5FAD7565036F077ED667AE59855D41CB84FF9CD0770A21914AD96966F599ECA6749528DD3B6735A8738E014D15DD771E29ED297D98D3A73AB8D8EE325485A026F9F4F905EE6F240D761B629EE69BCCAAFB349C36C133B9FB5322F2B5D33870F962D41DD1043D8D5441DEB2206245F613435524732473CE6806C0D802DFA854C45B56DB5B452466DDEA18C0AE44BD697754D56DE76864047BF62B8BA496A9483C2200DE40F1406FCD045F165B035C0B50192D54C49CD24C3DD5BA51A3628A293B63B76A29968B3548F88548A2081855F601260AFA66F5F5E2980EAF85825C5D56A46F6D8FD8FD9AAC09E15B1C45E24E37D25F5E36ADA5A780658CC61BC301EC266DF167E4D945ACB5F9B4F2518D907A423DB7CC088802F106BF0AFB3061C05B20D7160B6F4D21FCECF0B5A7567CC24B30ECDB7F8EE701BEAFCCC52E2BFBF9010C84834BF2BD463EC2BEF0832E15B0440C25EB6E8836B6C6F8D2EDFC95443943BA05B2D22DE4B41F0AD383370A5BAE4B964D0E5FDBEF934BD82FF41D04290C612503F7CB072C296172B2CC3B5DFF198D046729B45939BB32467520BFE8579E2736A363D0C58AD96F8C8F665877042A5426BF44201B07D8961BE41EE213260EC9F0AB73F029140E47A5AD6CA0CE7236BC09ACFC1C03B935B5895F2B0DAA2CC21D8FFF3FD5BC62AD07F0829D59D4A9398BE3E6AD0B21C8AE70B6721C78BA14FD157B6B6934032D9DF0FAC8D5833D43CAD9D64EB1CDB15A0B6023D0BF8094B62CDADDD140826AFFF498F4ABD630D43D37DED1635CF2F9975A03B7131C45CB9A5FC741991D7146CBDB8F40BB2FA048F66A8E750575B1ADEFBFE0992651FC61EA4AD8DD1FB86C812B5586134218D48975E3BB89338D40490BC66F7396D6F4CBAEB763C83C8C7580769EA0F7D60BFF12F445D23601DA8A6E0CCB2B60EEC730998E462DEF794BE752000891544E2DC2661A2D5D858B0D5FF8BFD776FBD44D3709B2C6521D9FF880299F80B5A17B848190E4E9B9A5CB8104A81A229146FA182ADB89D3AE5BF95823F2A32F765FBDC42FAA9F86F90DC1224E48034BEA8C486A86564968950326BD9C2EF9C050488157737443871AE5DF0272C22EE31692644F6C8DD995A80430BBB71B34F7194602FC26ABB3FF53DCE8D07E996CD08470B35867918A354338155FAF9EC3BD1C2DE6E3CA15BBBC760AC7A13B8101903607DC7511206AC7CD790D8E5AAD7A2BCF22DB9F1B2453607B59C91F5FF0CF60F90A2915D3CDC49A116180643E0599F69BAB0B900C2E0DA9932D2EC7033FE68D0E6F87B4E360C037AB4809390C71F5E34B318F5697E8B10376A54D280002BB65FD1DA42765F1C662DF30F1A5871C0062697CF1B212B1FEE22E0D41A055A7C79914816CD64F63612F519113FB060AFCDA49D2437D16ABF08817AE29E7C7B9CC54C4668634513E6CD68DCB9D8DBCECA54D1D928493F7C45CC902BB47FA47F691B50430D4E1854A05FC2D66838D38F674CD5A1F0AE55594949491CE6AC332256A146F5EA164AC5B22B3F641240ADFE1150462E95E459BB9B22A409A1B4A024B9F24D2C5314E73A560BF7B79AB9B0B64C71EBAE13BFF8DB96DCE33ECE954E2C2C9BE7C979C150B9CF5E3BA60FD35A43B957188FD7932BA87A45A031DAC3D9C49FA933389B9180D4180E2235347364264711392
2564
GandCrab.exe
write
HKEY_CLASSES_ROOT\Local Settings\MuiCache\72\52C64B7E
LanguageList
en-US

Files activity

Executable files
0
Suspicious files
298
Text files
213
Unknown types
12

Dropped files

PID
Process
Filename
Type
2564
GandCrab.exe
C:\Users\Public\Videos\Sample Videos\Wildlife.wmv.uapro
––
MD5:  ––
SHA256:  ––
2564
GandCrab.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\storage\default\UAPRO-DECRYPT.html
html
MD5: 08c2da0ed1a1bf7ef89f736b9ed43bd2
SHA256: f233665b765c8159f5d39d78e6947aa2a42a56de79e2ad94db7b9ab587038a29
2564
GandCrab.exe
C:\Users\Public\Videos\Sample Videos\Wildlife.wmv
––
MD5:  ––
SHA256:  ––
2564
GandCrab.exe
C:\Users\Public\Videos\Sample Videos\UAPRO-DECRYPT.html
html
MD5: 08c2da0ed1a1bf7ef89f736b9ed43bd2
SHA256: f233665b765c8159f5d39d78e6947aa2a42a56de79e2ad94db7b9ab587038a29
2564
GandCrab.exe
C:\Users\Public\Recorded TV\Sample Media\win7_scenic-demoshort_raw.wtv
––
MD5:  ––
SHA256:  ––
2564
GandCrab.exe
C:\Users\Public\Recorded TV\Sample Media\win7_scenic-demoshort_raw.wtv.uapro
––
MD5:  ––
SHA256:  ––
2564
GandCrab.exe
C:\Users\Public\Pictures\Sample Pictures\Penguins.jpg.uapro
binary
MD5: 503ba5247bf0228ea6754db239b5edc2
SHA256: b186ed296381380b6e20a522d3da2d1751f889565c55721ea737d74f7c668e46
2564
GandCrab.exe
C:\Users\Public\Recorded TV\UAPRO-DECRYPT.html
html
MD5: 08c2da0ed1a1bf7ef89f736b9ed43bd2
SHA256: f233665b765c8159f5d39d78e6947aa2a42a56de79e2ad94db7b9ab587038a29
2564
GandCrab.exe
C:\Users\Public\Recorded TV\Sample Media\UAPRO-DECRYPT.html
html
MD5: 08c2da0ed1a1bf7ef89f736b9ed43bd2
SHA256: f233665b765c8159f5d39d78e6947aa2a42a56de79e2ad94db7b9ab587038a29
2564
GandCrab.exe
C:\Users\Public\Pictures\Sample Pictures\Tulips.jpg.uapro
binary
MD5: ccdb4498e5cd2b61c02aa4eaf075da6b
SHA256: 771e71d5c31693d9011849fb6a3f5380cce21219449e24915f217037b9c07f55
2564
GandCrab.exe
C:\Users\Public\Pictures\Sample Pictures\Tulips.jpg
––
MD5:  ––
SHA256:  ––
2564
GandCrab.exe
C:\Users\Public\Pictures\Sample Pictures\Penguins.jpg
––
MD5:  ––
SHA256:  ––
2564
GandCrab.exe
C:\Users\Public\Pictures\Sample Pictures\Lighthouse.jpg.uapro
binary
MD5: 4ef8286d9206a7e109d8866bef81e7b2
SHA256: ae09a6bdad50f9eff8321eb57afc47cb39e83c080a5d2ec68b21f82c217b481d
2564
GandCrab.exe
C:\Users\Public\Pictures\Sample Pictures\Lighthouse.jpg
––
MD5:  ––
SHA256:  ––
2564
GandCrab.exe
C:\Users\Public\Pictures\Sample Pictures\Koala.jpg.uapro
binary
MD5: b109d7effae683aadc616f5cb7576682
SHA256: 51641f1cdb3d3b1cdc74f78f2268f296197ac815e28eb9400ac173721decb36c
2564
GandCrab.exe
C:\Users\Public\Pictures\Sample Pictures\Koala.jpg
––
MD5:  ––
SHA256:  ––
2564
GandCrab.exe
C:\Users\Public\Pictures\Sample Pictures\Hydrangeas.jpg.uapro
binary
MD5: 59f721890691d0eaa0ff0bbfee4b2bba
SHA256: 5efe4069504cbcb85d9b878ac3f4a00f9851e5ccad0a9d41121f673162ecd2be
2564
GandCrab.exe
C:\Users\Public\Pictures\Sample Pictures\Jellyfish.jpg.uapro
binary
MD5: 0bd1006feeef5228b8188282a8484630
SHA256: 03bbc7163f972b9a07185c7ea116d316fceff465fad6df90a56743439bd651be
2564
GandCrab.exe
C:\Users\Public\Pictures\Sample Pictures\Jellyfish.jpg
––
MD5:  ––
SHA256:  ––
2564
GandCrab.exe
C:\Users\Public\Pictures\Sample Pictures\Desert.jpg.uapro
binary
MD5: 5d82c418e16de3c48084729d86c46ea4
SHA256: 5566f72fd0ebcde1bd2b8adc470d7de0a24f0164041a9087f36aa5c340851e52
2564
GandCrab.exe
C:\Users\Public\Pictures\Sample Pictures\Hydrangeas.jpg
––
MD5:  ––
SHA256:  ––
2564
GandCrab.exe
C:\Users\Public\Pictures\Sample Pictures\Desert.jpg
––
MD5:  ––
SHA256:  ––
2564
GandCrab.exe
C:\Users\Public\Pictures\Sample Pictures\Chrysanthemum.jpg.uapro
binary
MD5: ab3123eb4da414dfebfbd223566d5946
SHA256: 5519cd9de6e2a2aeeb9102e6142fdc61f92bce1c35734ab4b03665ff0be78679
2564
GandCrab.exe
C:\Users\Public\Pictures\Sample Pictures\Chrysanthemum.jpg
––
MD5:  ––
SHA256:  ––
2564
GandCrab.exe
C:\Users\Public\Pictures\Sample Pictures\UAPRO-DECRYPT.html
html
MD5: 08c2da0ed1a1bf7ef89f736b9ed43bd2
SHA256: f233665b765c8159f5d39d78e6947aa2a42a56de79e2ad94db7b9ab587038a29
2564
GandCrab.exe
C:\Users\Public\Music\Sample Music\Sleep Away.mp3.uapro
––
MD5:  ––
SHA256:  ––
2564
GandCrab.exe
C:\Users\Public\Music\Sample Music\Sleep Away.mp3
––
MD5:  ––
SHA256:  ––
2564
GandCrab.exe
C:\Users\Public\Music\Sample Music\Maid with the Flaxen Hair.mp3.uapro
binary
MD5: db9eb715822105d6d0ef543c222dd289
SHA256: db2c74c49a550dc14ec562135f97173b7a14493fe153d0395c4e935601646549
2564
GandCrab.exe
C:\Users\Public\Music\Sample Music\Maid with the Flaxen Hair.mp3
––
MD5:  ––
SHA256:  ––
2564
GandCrab.exe
C:\Users\Public\Music\Sample Music\Kalimba.mp3.uapro
––
MD5:  ––
SHA256:  ––
2564
GandCrab.exe
C:\Users\Public\Music\Sample Music\Kalimba.mp3
––
MD5:  ––
SHA256:  ––
2564
GandCrab.exe
C:\Users\Public\Music\Sample Music\UAPRO-DECRYPT.html
html
MD5: 08c2da0ed1a1bf7ef89f736b9ed43bd2
SHA256: f233665b765c8159f5d39d78e6947aa2a42a56de79e2ad94db7b9ab587038a29
2564
GandCrab.exe
C:\Users\Public\Libraries\RecordedTV.library-ms.uapro
binary
MD5: 9fdafba8052e9b12c4a10f4d6d1e4ce8
SHA256: 587297f39d702ba6ffa925c3be0a060707404e9be2cd52432833e21fb43660df
2564
GandCrab.exe
C:\Users\Public\Libraries\RecordedTV.library-ms
––
MD5:  ––
SHA256:  ––
2564
GandCrab.exe
C:\Users\Public\Pictures\UAPRO-DECRYPT.html
html
MD5: 08c2da0ed1a1bf7ef89f736b9ed43bd2
SHA256: f233665b765c8159f5d39d78e6947aa2a42a56de79e2ad94db7b9ab587038a29
2564
GandCrab.exe
C:\Users\Public\Libraries\UAPRO-DECRYPT.html
html
MD5: 08c2da0ed1a1bf7ef89f736b9ed43bd2
SHA256: f233665b765c8159f5d39d78e6947aa2a42a56de79e2ad94db7b9ab587038a29
2564
GandCrab.exe
C:\Users\Public\Music\UAPRO-DECRYPT.html
html
MD5: 08c2da0ed1a1bf7ef89f736b9ed43bd2
SHA256: f233665b765c8159f5d39d78e6947aa2a42a56de79e2ad94db7b9ab587038a29
2564
GandCrab.exe
C:\Users\Public\Downloads\UAPRO-DECRYPT.html
html
MD5: 08c2da0ed1a1bf7ef89f736b9ed43bd2
SHA256: f233665b765c8159f5d39d78e6947aa2a42a56de79e2ad94db7b9ab587038a29
2564
GandCrab.exe
C:\Users\Public\Documents\UAPRO-DECRYPT.html
html
MD5: 08c2da0ed1a1bf7ef89f736b9ed43bd2
SHA256: f233665b765c8159f5d39d78e6947aa2a42a56de79e2ad94db7b9ab587038a29
2564
GandCrab.exe
C:\Users\Public\Videos\UAPRO-DECRYPT.html
html
MD5: 08c2da0ed1a1bf7ef89f736b9ed43bd2
SHA256: f233665b765c8159f5d39d78e6947aa2a42a56de79e2ad94db7b9ab587038a29
2564
GandCrab.exe
C:\Users\Public\Favorites\UAPRO-DECRYPT.html
html
MD5: 08c2da0ed1a1bf7ef89f736b9ed43bd2
SHA256: f233665b765c8159f5d39d78e6947aa2a42a56de79e2ad94db7b9ab587038a29
2564
GandCrab.exe
C:\Users\Public\UAPRO-DECRYPT.html
html
MD5: 08c2da0ed1a1bf7ef89f736b9ed43bd2
SHA256: f233665b765c8159f5d39d78e6947aa2a42a56de79e2ad94db7b9ab587038a29
2564
GandCrab.exe
C:\Users\admin\AppData\Roaming\Microsoft\Windows\Templates\UAPRO-DECRYPT.html
html
MD5: 08c2da0ed1a1bf7ef89f736b9ed43bd2
SHA256: f233665b765c8159f5d39d78e6947aa2a42a56de79e2ad94db7b9ab587038a29
2564
GandCrab.exe
C:\Users\admin\AppData\Roaming\Microsoft\Windows\SendTo\UAPRO-DECRYPT.html
html
MD5: 08c2da0ed1a1bf7ef89f736b9ed43bd2
SHA256: f233665b765c8159f5d39d78e6947aa2a42a56de79e2ad94db7b9ab587038a29
2564
GandCrab.exe
C:\Users\admin\AppData\Roaming\Microsoft\Windows\Start Menu\UAPRO-DECRYPT.html
html
MD5: 08c2da0ed1a1bf7ef89f736b9ed43bd2
SHA256: f233665b765c8159f5d39d78e6947aa2a42a56de79e2ad94db7b9ab587038a29
2564
GandCrab.exe
C:\Users\admin\Searches\Microsoft Outlook.searchconnector-ms.uapro
binary
MD5: 9fbe1d748526b24be26243da67eabaa1
SHA256: 67870487d5f155873e9cd6f11d6c0ae88b3bbb195d4b944a21c342ca5f81a6f5
2564
GandCrab.exe
C:\Users\admin\Saved Games\UAPRO-DECRYPT.html
html
MD5: 08c2da0ed1a1bf7ef89f736b9ed43bd2
SHA256: f233665b765c8159f5d39d78e6947aa2a42a56de79e2ad94db7b9ab587038a29
2564
GandCrab.exe
C:\Users\admin\Searches\UAPRO-DECRYPT.html
html
MD5: 08c2da0ed1a1bf7ef89f736b9ed43bd2
SHA256: f233665b765c8159f5d39d78e6947aa2a42a56de79e2ad94db7b9ab587038a29
2564
GandCrab.exe
C:\Users\admin\Searches\Microsoft OneNote.searchconnector-ms.uapro
binary
MD5: 2c99d980f64801b393156010db3238e8
SHA256: ad24e00fd927d855e886a4bc883fa161c9b137f972e732d6ea6df95a4a27edaa
2564
GandCrab.exe
C:\Users\admin\AppData\Roaming\Microsoft\Windows\Recent\UAPRO-DECRYPT.html
html
MD5: 08c2da0ed1a1bf7ef89f736b9ed43bd2
SHA256: f233665b765c8159f5d39d78e6947aa2a42a56de79e2ad94db7b9ab587038a29
2564
GandCrab.exe
C:\Users\admin\Searches\Microsoft OneNote.searchconnector-ms
––
MD5:  ––
SHA256:  ––
2564
GandCrab.exe
C:\Users\admin\Searches\Microsoft Outlook.searchconnector-ms
––
MD5:  ––
SHA256:  ––
2564
GandCrab.exe
C:\Users\admin\AppData\Roaming\Microsoft\Windows\Printer Shortcuts\UAPRO-DECRYPT.html
html
MD5: 08c2da0ed1a1bf7ef89f736b9ed43bd2
SHA256: f233665b765c8159f5d39d78e6947aa2a42a56de79e2ad94db7b9ab587038a29
2564
GandCrab.exe
C:\Users\admin\Pictures\usbmobile.png.uapro
binary
MD5: 394a4dfd1717c876dbbdf571fea20fed
SHA256: 864b1825d29f35c8112d1b5d306b4abd9aa39c4717df5d83a77c5aef44d3ede6
2564
GandCrab.exe
C:\Users\admin\Pictures\potentialdiet.jpg.uapro
binary
MD5: a084a6a6c3bbbe7a87d035585c65b3d8
SHA256: bbe203fdfd6a36e6caafec623979896eecc3591fea367a4c041eb43d42b876ef
2564
GandCrab.exe
C:\Users\admin\Pictures\potentialdiet.jpg
––
MD5:  ––
SHA256:  ––
2564
GandCrab.exe
C:\Users\admin\Pictures\usbmobile.png
––
MD5:  ––
SHA256:  ––
2564
GandCrab.exe
C:\Users\admin\Pictures\hadprimary.png.uapro
binary
MD5: de022265ecaeaac018cd3ea4481ff30c
SHA256: 621cadb5b189528c950564820788df9186ed40f19b4c1be12a0c6ba16a7c64b5
2564
GandCrab.exe
C:\Users\admin\Pictures\positionwhite.jpg.uapro
binary
MD5: 0576fc305b4f59db26fb8cb71405da40
SHA256: b089a9e5083496106c54ecab524a706af11c4be663af3275376dd8b21052bb12
2564
GandCrab.exe
C:\Users\admin\Pictures\alserver.png.uapro
binary
MD5: 224a645647f419ccc32bbb6de53a5911
SHA256: 413f0ec44bb871c804e17ca11a471d28d9681ff33394179278459a6951796349
2564
GandCrab.exe
C:\Users\admin\Pictures\positionwhite.jpg
––
MD5:  ––
SHA256:  ––
2564
GandCrab.exe
C:\Users\admin\Pictures\hadprimary.png
––
MD5:  ––
SHA256:  ––
2564
GandCrab.exe
C:\Users\admin\Links\UAPRO-DECRYPT.html
html
MD5: 08c2da0ed1a1bf7ef89f736b9ed43bd2
SHA256: f233665b765c8159f5d39d78e6947aa2a42a56de79e2ad94db7b9ab587038a29
2564
GandCrab.exe
C:\Users\admin\Favorites\Windows Live\Windows Live Spaces.url.uapro
binary
MD5: 958b042953c3d675591e43c56a557a46
SHA256: 267620ff6da8ddc7b57981abff23ee77e01bfabc86d114e92b61a007a1729259
2564
GandCrab.exe
C:\Users\admin\AppData\Roaming\Microsoft\Windows\Network Shortcuts\UAPRO-DECRYPT.html
html
MD5: 08c2da0ed1a1bf7ef89f736b9ed43bd2
SHA256: f233665b765c8159f5d39d78e6947aa2a42a56de79e2ad94db7b9ab587038a29
2564
GandCrab.exe
C:\Users\admin\ntuser.ini.uapro
binary
MD5: d9a7791b6ceffa6fd6398f84bdf9f5c7
SHA256: 066282dac2a49eea281582663ded232d82ae12d567100f8eaa973a121f0c6b99
2564
GandCrab.exe
C:\Users\admin\Pictures\alserver.png
––
MD5:  ––
SHA256:  ––
2564
GandCrab.exe
C:\Users\admin\ntuser.ini
––
MD5:  ––
SHA256:  ––
2564
GandCrab.exe
C:\Users\admin\Favorites\Windows Live\Windows Live Gallery.url.uapro
binary
MD5: 5168e5e510c33821116f01e035475682
SHA256: 65d8f69f925db687c80d1b39c5c95ff9b34a1ca999e570bc79e12ba9af3917f7
2564
GandCrab.exe
C:\Users\admin\Favorites\Windows Live\Get Windows Live.url.uapro
binary
MD5: b2e04d5467f6616b58f31d960e2d1f52
SHA256: 6d0f19316fda31d89cf2e142734b916b9100cbe0b355626f981cbd01fae099ec
2564
GandCrab.exe
C:\Users\admin\Favorites\Windows Live\Windows Live Mail.url.uapro
binary
MD5: 73b5454fc5ee9ede925e29943bf6e018
SHA256: 3e1ab020344148173d2d1ad1fd334c31f13b53f1c5e0ff915397e06ba98c4a3f
2564
GandCrab.exe
C:\Users\admin\Favorites\Windows Live\Windows Live Gallery.url
––
MD5:  ––
SHA256:  ––
2564
GandCrab.exe
C:\Users\admin\Favorites\Windows Live\Windows Live Spaces.url
––
MD5:  ––
SHA256:  ––
2564
GandCrab.exe
C:\Users\admin\Favorites\Windows Live\Get Windows Live.url
––
MD5:  ––
SHA256:  ––
2564
GandCrab.exe
C:\Users\admin\Favorites\Windows Live\Windows Live Mail.url
––
MD5:  ––
SHA256:  ––
2564
GandCrab.exe
C:\Users\admin\Favorites\Windows Live\UAPRO-DECRYPT.html
html
MD5: 08c2da0ed1a1bf7ef89f736b9ed43bd2
SHA256: f233665b765c8159f5d39d78e6947aa2a42a56de79e2ad94db7b9ab587038a29
2564
GandCrab.exe
C:\Users\admin\Favorites\MSN Websites\MSN.url.uapro
flc
MD5: b24af7e2d706fba68dbdb2746e4bb90f
SHA256: fdf629b85e1e34f6d890cbe3dff22b6b4268cfa2eb55831acd73558131f625f2
2564
GandCrab.exe
C:\Users\admin\Favorites\MSN Websites\MSNBC News.url.uapro
binary
MD5: 0ef2e6f5ed8de3e99f79b7522b75c48b
SHA256: 2e2a59742af4875d8aee546661bc5813fd6520613d20a24b0b48346c1caa0dcf
2564
GandCrab.exe
C:\Users\admin\Favorites\MSN Websites\MSNBC News.url
––
MD5:  ––
SHA256:  ––
2564
GandCrab.exe
C:\Users\admin\Favorites\MSN Websites\MSN.url
––
MD5:  ––
SHA256:  ––
2564
GandCrab.exe
C:\Users\admin\Favorites\MSN Websites\MSN Sports.url.uapro
binary
MD5: affe10ab21de461465d144a9fd56820b
SHA256: 277e3b26c86b82480fa125c3a5edd643a2f7887fd795e6ccec2403ce95cadfd0
2564
GandCrab.exe
C:\Users\admin\Favorites\MSN Websites\MSN Entertainment.url.uapro
binary
MD5: 2359583b94aa210fd6e5cd060f64f420
SHA256: be5c634c8a96d340d3130c01373c6f86ca89b52383d572b5db2a26e62cc5cde3
2564
GandCrab.exe
C:\Users\admin\Favorites\MSN Websites\MSN Money.url.uapro
binary
MD5: 2c865d867c90f28408214550d139fb1d
SHA256: 50cbca358ebd0b043f3ee02dd20d3c7a3b6138c3fe3385e6e8b7686f28234043
2564
GandCrab.exe
C:\Users\admin\Favorites\MSN Websites\MSN Money.url
––
MD5:  ––
SHA256:  ––
2564
GandCrab.exe
C:\Users\admin\Favorites\MSN Websites\MSN Entertainment.url
––
MD5:  ––
SHA256:  ––
2564
GandCrab.exe
C:\Users\admin\Favorites\MSN Websites\MSN Sports.url
––
MD5:  ––
SHA256:  ––
2564
GandCrab.exe
C:\Users\admin\Favorites\MSN Websites\MSN Autos.url.uapro
binary
MD5: 3dc6c5f02c1159559655d27323bb6020
SHA256: 0cbdf6614739bc38fe9b8e5636704f9020473f9d8c5821cb8cd0bdc1dfc58dc5
2564
GandCrab.exe
C:\Users\admin\Favorites\Microsoft Websites\Microsoft Store.url.uapro
binary
MD5: 6505b519056b55d74a8417d46e268507
SHA256: ef7dc14b5d7cb948643def0f161046952712d8d495968d2fd7384778a1ebeb80
2564
GandCrab.exe
C:\Users\admin\Favorites\MSN Websites\UAPRO-DECRYPT.html
html
MD5: 08c2da0ed1a1bf7ef89f736b9ed43bd2
SHA256: f233665b765c8159f5d39d78e6947aa2a42a56de79e2ad94db7b9ab587038a29
2564
GandCrab.exe
C:\Users\admin\Favorites\MSN Websites\MSN Autos.url
––
MD5:  ––
SHA256:  ––
2564
GandCrab.exe
C:\Users\admin\Favorites\Microsoft Websites\Microsoft Store.url
––
MD5:  ––
SHA256:  ––
2564
GandCrab.exe
C:\Users\admin\Favorites\Microsoft Websites\Microsoft At Work.url.uapro
binary
MD5: f4fe5e67ed9cdfa4a791099a7146789a
SHA256: 4d61d7b632727d9036fb5fd9e732bda3d88ea3dc8b1c346e1e11bcf655a06a97
2564
GandCrab.exe
C:\Users\admin\Favorites\Microsoft Websites\Microsoft At Home.url.uapro
ini
MD5: 0afddcd94f626dc9cc805a0c522a0ee8
SHA256: be91e0bd12581708c1cf86a6c858c65dec2dc11b369403630c92ca582aed70f9
2564
GandCrab.exe
C:\Users\admin\Favorites\Microsoft Websites\Microsoft At Work.url
––
MD5:  ––
SHA256:  ––
2564
GandCrab.exe
C:\Users\admin\Favorites\Microsoft Websites\Microsoft At Home.url
––
MD5:  ––
SHA256:  ––
2564
GandCrab.exe
C:\Users\admin\Favorites\Microsoft Websites\IE Add-on site.url.uapro
binary
MD5: c4594bb1f8746654d5d3ff0f32c2b43e
SHA256: caf9f4b15d5c90a3389c9b64187ec48b7ad21fd7bf00ea16c15a48323abf27f6
2564
GandCrab.exe
C:\Users\admin\Favorites\Microsoft Websites\IE site on Microsoft.com.url.uapro
binary
MD5: 9ad32fdf0fc91d3aec84914b1fc01f3a
SHA256: b296aea0a47dc9655cdd8e290dfd6ff0c8563df277bc6bd7434eed157ee8666d
2564
GandCrab.exe
C:\Users\admin\Favorites\Microsoft Websites\IE Add-on site.url
––
MD5:  ––
SHA256:  ––
2564
GandCrab.exe
C:\Users\admin\Favorites\Microsoft Websites\IE site on Microsoft.com.url
––
MD5:  ––
SHA256:  ––
2564
GandCrab.exe
C:\Users\admin\Favorites\Microsoft Websites\UAPRO-DECRYPT.html
html
MD5: 08c2da0ed1a1bf7ef89f736b9ed43bd2
SHA256: f233665b765c8159f5d39d78e6947aa2a42a56de79e2ad94db7b9ab587038a29
2564
GandCrab.exe
C:\Users\admin\Favorites\Links for United States\USA.gov.url.uapro
binary
MD5: 5b5ce063c58a33f51d859b6948f92d7d
SHA256: ab2123ff9b7066fad8d442e7a0aea10027aaab1636bc4aaefca04d337970f1f4
2564
GandCrab.exe
C:\Users\admin\Favorites\Links for United States\USA.gov.url
––
MD5:  ––
SHA256:  ––
2564
GandCrab.exe
C:\Users\admin\Favorites\Links for United States\GobiernoUSA.gov.url.uapro
binary
MD5: b80714314e29dd84b8c5ee4e730626bb
SHA256: 52d855019d24bf63f2658560f4fabe3d1f9845409e226eb71e04cf0b21c6a948
2564
GandCrab.exe
C:\Users\admin\Favorites\Links for United States\UAPRO-DECRYPT.html
html
MD5: 08c2da0ed1a1bf7ef89f736b9ed43bd2
SHA256: f233665b765c8159f5d39d78e6947aa2a42a56de79e2ad94db7b9ab587038a29
2564
GandCrab.exe
C:\Users\admin\Favorites\Links\Web Slice Gallery.url.uapro
binary
MD5: b3b55e53c56f0de230ba13d970296f6d
SHA256: 90be270c7a5535c62e03a89379a2a940a582bcd415fc405bb7ebeea5f04dbc07
2564
GandCrab.exe
C:\Users\admin\Favorites\Links\Suggested Sites.url.uapro
binary
MD5: c5bf86f1d9158052e24bcc8b5df2de2e
SHA256: 6658c4ebe60d6f9a8100efb08185b72e96b60bcf5aace5c128521f02657970ae
2564
GandCrab.exe
C:\Users\admin\Favorites\Links for United States\GobiernoUSA.gov.url
––
MD5:  ––
SHA256:  ––
2564
GandCrab.exe
C:\Users\admin\Favorites\Links\Web Slice Gallery.url
––
MD5:  ––
SHA256:  ––
2564
GandCrab.exe
C:\Users\admin\Favorites\Links\Suggested Sites.url
––
MD5:  ––
SHA256:  ––
2564
GandCrab.exe
C:\Users\admin\Downloads\purposereports.png.uapro
binary
MD5: a3e3824f77a862e97b14236b9395c0cf
SHA256: ef200b41f4b12855bf1f2a86c31d46ec91100f6292e40b53df0b55a01585ac05
2564
GandCrab.exe
C:\Users\admin\Favorites\Links\UAPRO-DECRYPT.html
html
MD5: 08c2da0ed1a1bf7ef89f736b9ed43bd2
SHA256: f233665b765c8159f5d39d78e6947aa2a42a56de79e2ad94db7b9ab587038a29
2564
GandCrab.exe
C:\Users\admin\Favorites\UAPRO-DECRYPT.html
html
MD5: 08c2da0ed1a1bf7ef89f736b9ed43bd2
SHA256: f233665b765c8159f5d39d78e6947aa2a42a56de79e2ad94db7b9ab587038a29
2564
GandCrab.exe
C:\Users\admin\Downloads\purposereports.png
––
MD5:  ––
SHA256:  ––
2564
GandCrab.exe
C:\Users\admin\Downloads\primarypast.png.uapro
binary
MD5: 7f2832b051e69e93c6949418b07d79f4
SHA256: b3fa627fb2936c6afbba1ec06222cd16802151663a1ac81e048421ea5aa5b699
2564
GandCrab.exe
C:\Users\admin\Downloads\martininto.png.uapro
binary
MD5: 3ab44b3e56a105da0d08dc84ad4783ec
SHA256: bbac3d29e06b9400b683d361f68f77a6febef057d9edd62e96303e71c8352509
2564
GandCrab.exe
C:\Users\admin\Downloads\primarypast.png
––
MD5:  ––
SHA256:  ––
2564
GandCrab.exe
C:\Users\admin\Downloads\martininto.png
––
MD5:  ––
SHA256:  ––
2564
GandCrab.exe
C:\Users\admin\Downloads\costgeorge.jpg.uapro
binary
MD5: 484837b8679e8058f1e5e4293b18bfec
SHA256: fbae273acd5ed0d0ea9f8b456ce91dfc00905020732babfa08eb425fb80bfba5
2564
GandCrab.exe
C:\Users\admin\Downloads\committeeplease.jpg.uapro
binary
MD5: 6e89c588c540c44c53bba015ffd1a143
SHA256: 3473b803130c94b4e7d50bacee798bb87e26e5c0f1f823f2c88d72b076ef9c25
2564
GandCrab.exe
C:\Users\admin\Downloads\committeeplease.jpg
––
MD5:  ––
SHA256:  ––
2564
GandCrab.exe
C:\Users\admin\Downloads\costgeorge.jpg
––
MD5:  ––
SHA256:  ––
2564
GandCrab.exe
C:\Users\admin\Downloads\UAPRO-DECRYPT.html
html
MD5: 08c2da0ed1a1bf7ef89f736b9ed43bd2
SHA256: f233665b765c8159f5d39d78e6947aa2a42a56de79e2ad94db7b9ab587038a29
2564
GandCrab.exe
C:\Users\admin\Downloads\accommodationvillage.jpg.uapro
binary
MD5: 123989d9b7479f4b78f63029ab91001f
SHA256: 69627c072508de1654ae47c25aefd34916eee8526e30f5cea750ab5d09a8188f
2564
GandCrab.exe
C:\Users\admin\Documents\proby.rtf.uapro
binary
MD5: 7454350b2aa8b8ed54ce13547d048b32
SHA256: 73ea320a82acd68c55af57940a05b8bac64d43246f1ff27d2852c2de7892d2d4
2564
GandCrab.exe
C:\Users\admin\Documents\picturepresident.rtf.uapro
binary
MD5: dad1536ece3672bbb28260791b7f2236
SHA256: e853c4f244e20ff3a3a59ba73b796bd4bb472b4ed8ca48ce3fe5dbeaffdc6e6a
2564
GandCrab.exe
C:\Users\admin\Documents\proby.rtf
––
MD5:  ––
SHA256:  ––
2564
GandCrab.exe
C:\Users\admin\Downloads\accommodationvillage.jpg
––
MD5:  ––
SHA256:  ––
2564
GandCrab.exe
C:\Users\admin\Documents\picturepresident.rtf
––
MD5:  ––
SHA256:  ––
2564
GandCrab.exe
C:\Users\admin\Documents\Outlook Files\Outlook.pst.uapro
binary
MD5: eb299c5adab0ef512bfefdf9cce3d3fa
SHA256: 22ac1b6891e5acb77812bbf924ab8928af8486658eaab4796ae3f451e178c635
2564
GandCrab.exe
C:\Users\admin\Documents\Outlook Files\~Outlook.pst.tmp.uapro
binary
MD5: a1e369393fc55df37cffc9a29e6873ab
SHA256: 66e7bd399d11b11f7b946880a713b5a52bf76f5e9ab7e994dc95a2e737eb4b4c
2564
GandCrab.exe
C:\Users\admin\Documents\Outlook Files\~Outlook.pst.tmp
––
MD5:  ––
SHA256:  ––
2564
GandCrab.exe
C:\Users\admin\Documents\Outlook Files\Outlook.pst
––
MD5:  ––
SHA256:  ––
2564
GandCrab.exe
C:\Users\admin\Documents\Outlook Files\Outlook Data File - test.pst.uapro
binary
MD5: 2c2c3b2d9860b09f13e3054a3dce5947
SHA256: d8ea3f63b4cae29f069409a72f2423071de856863a6cac05b35231394a390fb6
2564
GandCrab.exe
C:\Users\admin\Documents\Outlook Files\Outlook Data File - NoMail.pst.uapro
binary
MD5: 421509914637c594f50355a7dec92705
SHA256: 60e2b6d6efc2677e22ed8f8e67be9f1034dd241fa0d2b148eaa019c81e53045d
2564
GandCrab.exe
C:\Users\admin\Documents\Outlook Files\Outlook Data File - NoMail.pst
––
MD5:  ––
SHA256:  ––
2564
GandCrab.exe
C:\Users\admin\Documents\Outlook Files\Outlook Data File - test.pst
––
MD5:  ––
SHA256:  ––
2564
GandCrab.exe
C:\Users\admin\Documents\Outlook Files\[email protected]
binary
MD5: a8031b926543a27befb22a97419d5ec0
SHA256: f9ba8297d87f2ca2e03c3ec743eb8e53cb034781524ed6328d39db281631f731
2564
GandCrab.exe
C:\Users\admin\Documents\OneNote Notebooks\Personal\Unfiled Notes.one.uapro
binary
MD5: 73638e5c04bfa44b508b070a7dd56fea
SHA256: 13cc7fb38393504901765d957df653bd3708857ebeac457a440a44b802a754d0
2564
GandCrab.exe
C:\Users\admin\Documents\Outlook Files\UAPRO-DECRYPT.html
html
MD5: 08c2da0ed1a1bf7ef89f736b9ed43bd2
SHA256: f233665b765c8159f5d39d78e6947aa2a42a56de79e2ad94db7b9ab587038a29
2564
GandCrab.exe
C:\Users\admin\Documents\OneNote Notebooks\Personal\Unfiled Notes.one
––
MD5:  ––
SHA256:  ––
2564
GandCrab.exe
C:\Users\admin\Documents\Outlook Files\[email protected]
––
MD5:  ––
SHA256:  ––
2564
GandCrab.exe
C:\Users\admin\Documents\OneNote Notebooks\Personal\General.one.uapro
binary
MD5: 74ad452276e3ba938af39cd384e3bcd5
SHA256: a2359483ac8453ce6de2956f057c4ee16d7b48521246640c958b1d19ca10ae5f
2564
GandCrab.exe
C:\Users\admin\Documents\OneNote Notebooks\Personal\Open Notebook.onetoc2.uapro
binary
MD5: 8585b59f67674931cab76d442415cf84
SHA256: 11595f798bd4f62ebff88e0b27ffcbd8d4bbf296d7f82a1caa08956c31dae165
2564
GandCrab.exe
C:\Users\admin\Documents\OneNote Notebooks\Personal\Open Notebook.onetoc2
––
MD5:  ––
SHA256:  ––
2564
GandCrab.exe
C:\Users\admin\Documents\OneNote Notebooks\Personal\General.one
––
MD5:  ––
SHA256:  ––
2564
GandCrab.exe
C:\Users\admin\Videos\UAPRO-DECRYPT.html
html
MD5: 08c2da0ed1a1bf7ef89f736b9ed43bd2
SHA256: f233665b765c8159f5d39d78e6947aa2a42a56de79e2ad94db7b9ab587038a29
2564
GandCrab.exe
C:\Users\admin\Music\UAPRO-DECRYPT.html
html
MD5: 08c2da0ed1a1bf7ef89f736b9ed43bd2
SHA256: f233665b765c8159f5d39d78e6947aa2a42a56de79e2ad94db7b9ab587038a29
2564
GandCrab.exe
C:\Users\admin\Documents\OneNote Notebooks\Personal\UAPRO-DECRYPT.html
html
MD5: 08c2da0ed1a1bf7ef89f736b9ed43bd2
SHA256: f233665b765c8159f5d39d78e6947aa2a42a56de79e2ad94db7b9ab587038a29
2564
GandCrab.exe
C:\Users\admin\Documents\OneNote Notebooks\UAPRO-DECRYPT.html
html
MD5: 08c2da0ed1a1bf7ef89f736b9ed43bd2
SHA256: f233665b765c8159f5d39d78e6947aa2a42a56de79e2ad94db7b9ab587038a29
2564
GandCrab.exe
C:\Users\admin\Pictures\UAPRO-DECRYPT.html
html
MD5: 08c2da0ed1a1bf7ef89f736b9ed43bd2
SHA256: f233665b765c8159f5d39d78e6947aa2a42a56de79e2ad94db7b9ab587038a29
2564
GandCrab.exe
C:\Users\admin\Documents\militaryrequest.rtf.uapro
binary
MD5: edf83b3d459c1478ba11ad3f20863d6b
SHA256: c6519a9ed83288eb86480be103d8037279284db4531718bdbde33c9b0962c2ab
2564
GandCrab.exe
C:\Users\admin\Documents\militaryrequest.rtf
––
MD5:  ––
SHA256:  ––
2564
GandCrab.exe
C:\Users\admin\Documents\lowermoney.rtf.uapro
binary
MD5: c11782806501d84b1f1af98ab5c71537
SHA256: d8b066acb2993db999753746d46e647ce0d745009794c6ac833c1f1ccbbd59d0
2564
GandCrab.exe
C:\Users\admin\Documents\lowermoney.rtf
––
MD5:  ––
SHA256:  ––
2564
GandCrab.exe
C:\Users\admin\Documents\looksamerica.rtf.uapro
binary
MD5: 71e5b26e5a3961be4c9b729db0ee8761
SHA256: ffdec4a4a67ae23e282a192e382e57803e2e5635af7b8dc2adf688cb98a83ebf
2564
GandCrab.exe
C:\Users\admin\Documents\bluerate.rtf.uapro
binary
MD5: dc4fa57ede1d7e720d69b2ff3893efd2
SHA256: b3344c2d124084300e907c9c4c633f94557bef27f5a2345a8f0a5fdcc155ab33
2564
GandCrab.exe
C:\Users\admin\Documents\britishdetail.rtf.uapro
binary
MD5: d7e255e75dbf97e0ebb4015bec9cab4a
SHA256: 8d3006cbd63408b07735dc079865274c142347513a5b29110d5710764dc0890c
2564
GandCrab.exe
C:\Users\admin\Documents\looksamerica.rtf
––
MD5:  ––
SHA256:  ––
2564
GandCrab.exe
C:\Users\admin\Documents\britishdetail.rtf
––
MD5:  ––
SHA256:  ––
2564
GandCrab.exe
C:\Users\admin\Documents\UAPRO-DECRYPT.html
html
MD5: 08c2da0ed1a1bf7ef89f736b9ed43bd2
SHA256: f233665b765c8159f5d39d78e6947aa2a42a56de79e2ad94db7b9ab587038a29
2564
GandCrab.exe
C:\Users\admin\Desktop\telengland.jpg.uapro
mp3
MD5: d50221779ac2860734c876d2d6d03e29
SHA256: 22ac06fc4c978ac5669ed883d135e44377e45b091187fd85eb3527042b02b500
2564
GandCrab.exe
C:\Users\admin\Documents\bluerate.rtf
––
MD5:  ––
SHA256:  ––
2564
GandCrab.exe
C:\Users\admin\Desktop\sunseems.png.uapro
binary
MD5: dacf63d9b845e51012994eeaf722422c
SHA256: 3ef522058bb2f021f0eebddf030bd974236fcef2bbe26794c7b21cf23734fc05
2564
GandCrab.exe
C:\Users\admin\Desktop\sunseems.png
––
MD5:  ––
SHA256:  ––
2564
GandCrab.exe
C:\Users\admin\Desktop\telengland.jpg
––
MD5:  ––
SHA256:  ––
2564
GandCrab.exe
C:\Users\admin\Desktop\requirementsdeath.rtf.uapro
binary
MD5: 990fc689e701da54f4dd13f88c1219fd
SHA256: 7b207c0cdc20118d46d1f5541a453c500aa7b36d6b88f4a2dc2dabe611a594d8
2564
GandCrab.exe
C:\Users\admin\Desktop\requirementsdeath.rtf
––
MD5:  ––
SHA256:  ––
2564
GandCrab.exe
C:\Users\admin\Desktop\lineset.png.uapro
binary
MD5: 0ca4d6e13205b1768d0aaae78d7a9ba0
SHA256: f00b0bf202cddb31453a8f9f9472971757fa3fb70c2fe044b17cfe02494dc647
2564
GandCrab.exe
C:\Users\admin\Desktop\jerseyif.rtf.uapro
binary
MD5: 5e6b7485b3d413d336ec3ac456c9b972
SHA256: 69f1f331730176439d27f3c4084a6d708e6a858d81763c606de80189a9e4b8ff
2564
GandCrab.exe
C:\Users\admin\Desktop\paydifferent.jpg.uapro
binary
MD5: 3a16766da61509709e8801040344494e
SHA256: 91458a575819bc33d3f071eecb1f6dd819dd39b2902c3159b0b5ffcc60b367ec
2564
GandCrab.exe
C:\Users\admin\Desktop\paydifferent.jpg
––
MD5:  ––
SHA256:  ––
2564
GandCrab.exe
C:\Users\admin\Desktop\lineset.png
––
MD5:  ––
SHA256:  ––
2564
GandCrab.exe
C:\Users\admin\Desktop\jerseyif.rtf
––
MD5:  ––
SHA256:  ––
2564
GandCrab.exe
C:\Users\admin\Desktop\individualsproviding.jpg.uapro
binary
MD5: 79b66d7040537404d5c66b424fe3edef
SHA256: 80c9c59bd7268384673c379e46be86297ee015ae46239e6f4aa5e50985d9d245
2564
GandCrab.exe
C:\Users\admin\Desktop\freeillinois.rtf.uapro
binary
MD5: 8bc1901166b1fa642197f5a8ef29b4c6
SHA256: 3767a1c46c14dd345a3721399c615b69b3a585a95cdd827793fd040501c41555
2564
GandCrab.exe
C:\Users\admin\Desktop\freeillinois.rtf
––
MD5:  ––
SHA256:  ––
2564
GandCrab.exe
C:\Users\admin\Desktop\individualsproviding.jpg
––
MD5:  ––
SHA256:  ––
2564
GandCrab.exe
C:\Users\admin\Desktop\celldating.rtf.uapro
binary
MD5: d91b7364754e7fdd09e6e6a96a9152ff
SHA256: 839e847af9f651f01b91da765d203d7fa7c8fc18b8ff0bd210da812f0a43e210
2564
GandCrab.exe
C:\Users\admin\Desktop\childrenthat.rtf.uapro
binary
MD5: 8154f38a1f5c63cfaa7d467d2037dec9
SHA256: 3dfc4b0a6639b6868d35ab6ec69247758134f0ca8eb199ab38ea201a6c17c6b9
2564
GandCrab.exe
C:\Users\admin\Desktop\eganything.rtf.uapro
binary
MD5: 81e1d4defcfa28caeb7031890785d344
SHA256: 5b6b62173a06ae12709e80cad3711acc8a7c3a723580980dea1dfa792891f11d
2564
GandCrab.exe
C:\Users\admin\Desktop\childrenthat.rtf
––
MD5:  ––
SHA256:  ––
2564
GandCrab.exe
C:\Users\admin\Desktop\eganything.rtf
––
MD5:  ––
SHA256:  ––
2564
GandCrab.exe
C:\Users\admin\AppData\Roaming\Microsoft\Windows\Cookies\UAPRO-DECRYPT.html
html
MD5: 08c2da0ed1a1bf7ef89f736b9ed43bd2
SHA256: f233665b765c8159f5d39d78e6947aa2a42a56de79e2ad94db7b9ab587038a29
2564
GandCrab.exe
C:\Users\admin\Desktop\UAPRO-DECRYPT.html
html
MD5: 08c2da0ed1a1bf7ef89f736b9ed43bd2
SHA256: f233665b765c8159f5d39d78e6947aa2a42a56de79e2ad94db7b9ab587038a29
2564
GandCrab.exe
C:\Users\admin\Contacts\admin.contact.uapro
binary
MD5: 235aa40989133c855f2a39b3af209063
SHA256: 5b77ddbe18954343241fc0aaa435700b8c8287ac1b1660a3a035bb9fd778e87c
2564
GandCrab.exe
C:\Users\admin\Desktop\celldating.rtf
––
MD5:  ––
SHA256:  ––
2564
GandCrab.exe
C:\Users\admin\Contacts\admin.contact
––
MD5:  ––
SHA256:  ––
2564
GandCrab.exe
C:\Users\admin\AppData\Roaming\WinRAR\version.dat.uapro
binary
MD5: 849b59951faf0c390d7871f09ed65a91
SHA256: ccd1f92591c0a7e064a68d745d0ecdd7f225fe80dfcaf27a5eafb11c6b263bbe
2564
GandCrab.exe
C:\Users\admin\AppData\Roaming\WinRAR\UAPRO-DECRYPT.html
html
MD5: 08c2da0ed1a1bf7ef89f736b9ed43bd2
SHA256: f233665b765c8159f5d39d78e6947aa2a42a56de79e2ad94db7b9ab587038a29
2564
GandCrab.exe
C:\Users\admin\AppData\Roaming\Sun\UAPRO-DECRYPT.html
html
MD5: 08c2da0ed1a1bf7ef89f736b9ed43bd2
SHA256: f233665b765c8159f5d39d78e6947aa2a42a56de79e2ad94db7b9ab587038a29
2564
GandCrab.exe
C:\Users\admin\AppData\Roaming\Sun\Java\Deployment\UAPRO-DECRYPT.html
html
MD5: 08c2da0ed1a1bf7ef89f736b9ed43bd2
SHA256: f233665b765c8159f5d39d78e6947aa2a42a56de79e2ad94db7b9ab587038a29
2564
GandCrab.exe
C:\Users\admin\AppData\Roaming\Sun\Java\UAPRO-DECRYPT.html
html
MD5: 08c2da0ed1a1bf7ef89f736b9ed43bd2
SHA256: f233665b765c8159f5d39d78e6947aa2a42a56de79e2ad94db7b9ab587038a29
2564
GandCrab.exe
C:\Users\admin\AppData\Roaming\Skype\SkypeRT\ul.conf.uapro
binary
MD5: 3914c7685e58ac83a57325e5723e8781
SHA256: e952ce96f589b9937b5e5f4e7fe0fa8a35da979e60749be9ab61dc26623b95c3
2564
GandCrab.exe
C:\Users\admin\Contacts\UAPRO-DECRYPT.html
html
MD5: 08c2da0ed1a1bf7ef89f736b9ed43bd2
SHA256: f233665b765c8159f5d39d78e6947aa2a42a56de79e2ad94db7b9ab587038a29
2564
GandCrab.exe
C:\Users\admin\AppData\Roaming\Skype\SkypeRT\ul.conf
––
MD5:  ––
SHA256:  ––
2564
GandCrab.exe
C:\Users\admin\AppData\Roaming\WinRAR\version.dat
––
MD5:  ––
SHA256:  ––
2564
GandCrab.exe
C:\Users\admin\AppData\Roaming\Skype\SkypeRT\UAPRO-DECRYPT.html
html
MD5: 08c2da0ed1a1bf7ef89f736b9ed43bd2
SHA256: f233665b765c8159f5d39d78e6947aa2a42a56de79e2ad94db7b9ab587038a29
2564
GandCrab.exe
C:\Users\admin\AppData\Roaming\Skype\SkypeRT\ecs.conf.uapro
binary
MD5: 5d15e1588e674bd5802ed39276c43f51
SHA256: 11e6e5ff81df05a55a583ee981e0fee6353913c51933b51ab705cca20c34eb3e
2564
GandCrab.exe
C:\Users\admin\AppData\Roaming\Skype\SkypeRT\skypert.conf.uapro
binary
MD5: 8c840168a754017b9d4f55ba4bbe5912
SHA256: 1abebc2ecb97b77491891935e00d595e8fec987069629c50c3dc2c14b6f7c65f
2564
GandCrab.exe
C:\Users\admin\AppData\Roaming\Skype\SkypeRT\skypert.conf
––
MD5:  ––
SHA256:  ––
2564
GandCrab.exe
C:\Users\admin\AppData\Roaming\Skype\SkypeRT\ecs.conf
––
MD5:  ––
SHA256:  ––
2564
GandCrab.exe
C:\Users\admin\AppData\Roaming\Skype\shared_httpfe\UAPRO-DECRYPT.html
html
MD5: 08c2da0ed1a1bf7ef89f736b9ed43bd2
SHA256: f233665b765c8159f5d39d78e6947aa2a42a56de79e2ad94db7b9ab587038a29
2564
GandCrab.exe
C:\Users\admin\AppData\Roaming\Skype\shared_httpfe\queue.db.uapro
binary
MD5: 029ecf0b79b64d17771adaeeb8b39e52
SHA256: cb675e6a40efe049297454b4857b9de6ab600bed7bae4cb9dd2fd5475a326711
2564
GandCrab.exe
C:\Users\admin\AppData\Roaming\Skype\shared_httpfe\queue.db
––
MD5:  ––
SHA256:  ––
2564
GandCrab.exe
C:\Users\admin\AppData\Roaming\Skype\shared_dynco\dc.db.uapro
binary
MD5: 6efc604dd1cd716905c2fc62508b4db4
SHA256: f0d2c69399782fb8c1611b31f90ec2bf8f5ef8c428029c52d41c8ea9cf3e7edf
2564
GandCrab.exe
C:\Users\admin\AppData\Roaming\Skype\shared_dynco\dc.db-journal.uapro
binary
MD5: 686a0edd1ca15e4217cec226a03ceb31
SHA256: 9b508a415ff6b11c91884fde3afa76d5ffa164eff9ce79d3a8d478c39cc568bf
2564
GandCrab.exe
C:\Users\admin\AppData\Roaming\Skype\shared_dynco\dc.db-journal
––
MD5:  ––
SHA256:  ––
2564
GandCrab.exe
C:\Users\admin\AppData\Roaming\Skype\shared_dynco\dc.db
––
MD5:  ––
SHA256:  ––
2564
GandCrab.exe
C:\Users\admin\AppData\Roaming\Skype\shared.xml.uapro
binary
MD5: 7090d3cd729285b1d63a0f8fa8f28d3f
SHA256: 8f87ef9c1f2a26527d10264787735fca304683467f9efa402364d2b967b47ff2
2564
GandCrab.exe
C:\Users\admin\AppData\Roaming\Skype\shared_dynco\UAPRO-DECRYPT.html
html
MD5: 08c2da0ed1a1bf7ef89f736b9ed43bd2
SHA256: f233665b765c8159f5d39d78e6947aa2a42a56de79e2ad94db7b9ab587038a29
2564
GandCrab.exe
C:\Users\admin\AppData\Roaming\Skype\logs\UAPRO-DECRYPT.html
html
MD5: 08c2da0ed1a1bf7ef89f736b9ed43bd2
SHA256: f233665b765c8159f5d39d78e6947aa2a42a56de79e2ad94db7b9ab587038a29
2564
GandCrab.exe
C:\Users\admin\AppData\Roaming\Skype\DataRv\offline-storage.data.uapro
flc
MD5: b2a5395bce1946cf6bd2e0fc1c7f9a04
SHA256: ccd56c398425642e53416842b17cc302ee220a85c174949839beff6a133cb616
2564
GandCrab.exe
C:\Users\admin\AppData\Roaming\Skype\shared.xml
––
MD5:  ––
SHA256:  ––
2564
GandCrab.exe
C:\Users\admin\AppData\Roaming\Skype\DataRv\offline-storage.data
––
MD5:  ––
SHA256:  ––
2564
GandCrab.exe
C:\Users\admin\AppData\Roaming\Skype\DataRv\UAPRO-DECRYPT.html
html
MD5: 08c2da0ed1a1bf7ef89f736b9ed43bd2
SHA256: f233665b765c8159f5d39d78e6947aa2a42a56de79e2ad94db7b9ab587038a29
2564
GandCrab.exe
C:\Users\admin\AppData\Roaming\Skype\UAPRO-DECRYPT.html
html
MD5: 08c2da0ed1a1bf7ef89f736b9ed43bd2
SHA256: f233665b765c8159f5d39d78e6947aa2a42a56de79e2ad94db7b9ab587038a29
2564
GandCrab.exe
C:\Users\admin\AppData\Roaming\Opera\Opera\webserver\users.xml.uapro
binary
MD5: b6603a80bb10471511e2cc40223bcd7d
SHA256: b939f19b5af3dcecca1f7da9bb353f89f837a04aed87ca4dff63e13520e4bcf6
2564
GandCrab.exe
C:\Users\admin\AppData\Roaming\Opera\Opera\tasks.xml.uapro
binary
MD5: 0756700648b94e842421044632a4c1e4
SHA256: 6419cc729b2f735cee6a20a72021532804a82bc893f6cf3eee1cc83ce68ba63e
2564
GandCrab.exe
C:\Users\admin\AppData\Roaming\Opera\Opera\tips.ini.uapro
binary
MD5: b997d0f873a1963289a4a0b3e1692f38
SHA256: 359b8451b2a70cf79fc141b8f66c96364e5588d1af4567bc302505c9ef67e40d
2564
GandCrab.exe
C:\Users\admin\AppData\Roaming\Opera\Opera\wand.dat.uapro
binary
MD5: 3b20275dfb8053e4df5ddc9a0191280e
SHA256: 4327054aabfdabd38817ecad1c68f423be1c1aac5d40cdf741d82a5045a2fd51
2564
GandCrab.exe
C:\Users\admin\AppData\Roaming\Opera\Opera\webserver\UAPRO-DECRYPT.html
html
MD5: 08c2da0ed1a1bf7ef89f736b9ed43bd2
SHA256: f233665b765c8159f5d39d78e6947aa2a42a56de79e2ad94db7b9ab587038a29
2564
GandCrab.exe
C:\Users\admin\AppData\Roaming\Opera\Opera\wand.dat
––
MD5:  ––
SHA256:  ––
2564
GandCrab.exe
C:\Users\admin\AppData\Roaming\Opera\Opera\tasks.xml
––
MD5:  ––
SHA256:  ––
2564
GandCrab.exe
C:\Users\admin\AppData\Roaming\Opera\Opera\webserver\users.xml
––
MD5:  ––
SHA256:  ––
2564
GandCrab.exe
C:\Users\admin\AppData\Roaming\Opera\Opera\tips.ini
––
MD5:  ––
SHA256:  ––
2564
GandCrab.exe
C:\Users\admin\AppData\Roaming\Opera\Opera\styles\user\structureinline.css.uapro
binary
MD5: 5259f40941442775876bf41fdb24019c
SHA256: e332b94c84c5018cf1989cf894a34b871ba8f97a3a55e85c553ab27dfc72fa72
2564
GandCrab.exe
C:\Users\admin\AppData\Roaming\Opera\Opera\styles\user\structureblock.css.uapro
binary
MD5: 409ab4700be4aa4261d9722963046829
SHA256: b68c26a26fd5a4bf871c3bbfe2c4477b17e876574e0637412d288d79bdcbf405
2564
GandCrab.exe
C:\Users\admin\AppData\Roaming\Opera\Opera\styles\user\structuretables.css.uapro
binary
MD5: 4c61a6f9417081a0ca7cbef1cf102e81
SHA256: fa52e8bec554af48400408803ac0bfdb8eaca5cb48cbecf498c2f6ba84f072d3
2564
GandCrab.exe
C:\Users\admin\AppData\Roaming\Opera\Opera\styles\user\toc.css.uapro
binary
MD5: 57efb2d26ce57a7db473bff5cda24a69
SHA256: 6a904f18e982c24513639ae45213acc2573472cc0cee21d455e58f00cc5ea697
2564
GandCrab.exe
C:\Users\admin\AppData\Roaming\Opera\Opera\styles\user\tablelayout.css.uapro
binary
MD5: 9270c657d42d80a4d33775e423ed7354
SHA256: 9eb84f4f9c07fc6230bebc502b0ba9ad9d937c05a33056f5a2232ede0765b9de
2564
GandCrab.exe
C:\Users\admin\AppData\Roaming\Opera\Opera\styles\user\structureinline.css
––
MD5:  ––
SHA256:  ––
2564
GandCrab.exe
C:\Users\admin\AppData\Roaming\Opera\Opera\styles\user\structureblock.css
––
MD5:  ––
SHA256:  ––
2564
GandCrab.exe
C:\Users\admin\AppData\Roaming\Opera\Opera\styles\user\toc.css
––
MD5:  ––
SHA256:  ––
2564
GandCrab.exe
C:\Users\admin\AppData\Roaming\Opera\Opera\styles\user\tablelayout.css
––
MD5:  ––
SHA256:  ––
2564
GandCrab.exe
C:\Users\admin\AppData\Roaming\Opera\Opera\styles\user\structuretables.css
––
MD5:  ––
SHA256:  ––
2564
GandCrab.exe
C:\Users\admin\AppData\Roaming\Opera\Opera\styles\user\disablepositioning.css.uapro
binary
MD5: 891126f682e5bae257596d320437da21
SHA256: eb76cc3133be9ed33f14bebcb04e06d91508b82d2cb287bdc16e86695cb01a3a
2564
GandCrab.exe
C:\Users\admin\AppData\Roaming\Opera\Opera\styles\user\disabletables.css.uapro
binary
MD5: 4c28561dda81ec1dd80544d1a17d0169
SHA256: e2342b7c020fc3804993a4fb4a72447c55f27c2a0c8b9883710ccb4c1ee09378
2564
GandCrab.exe
C:\Users\admin\AppData\Roaming\Opera\Opera\styles\user\outline.css.uapro
binary
MD5: 95fb576a298cafe88ad0bb2ef73b641e
SHA256: a0b589957d3af0ba7d93ff1e1338a12e040df4d035a02c2e67ce92396319c641
2564
GandCrab.exe
C:\Users\admin\AppData\Roaming\Opera\Opera\styles\user\disablepositioning.css
––
MD5:  ––
SHA256:  ––
2564
GandCrab.exe
C:\Users\admin\AppData\Roaming\Opera\Opera\styles\user\disabletables.css
––
MD5:  ––
SHA256:  ––
2564
GandCrab.exe
C:\Users\admin\AppData\Roaming\Opera\Opera\styles\user\outline.css
––
MD5:  ––
SHA256:  ––
2564
GandCrab.exe
C:\Users\admin\AppData\Roaming\Opera\Opera\styles\user\contrastwb.css.uapro
binary
MD5: 1dead619ed494aa1f6ec6a5df9f19bc3
SHA256: 191d1cda738c48f086ddfb2b6796831773f672e11144a0d388974b770aa1357c
2564
GandCrab.exe
C:\Users\admin\AppData\Roaming\Opera\Opera\styles\user\disablefloats.css.uapro
binary
MD5: 641a8fbb1f6a44ee9d08cb519d6b23af
SHA256: 2042442af4bb20cc5e2883a2acb00b4b860007035b6157068a3cc7ab28e4469a
2564
GandCrab.exe
C:\Users\admin\AppData\Roaming\Opera\Opera\styles\user\contrastbw.css.uapro
ini
MD5: a798b73dd825340dc6233c46ab0550ab
SHA256: 07f05ba4efe2eb5bc68f1c585f9c9f4d7246caf5267348803f9a512f596e476f
2564
GandCrab.exe
C:\Users\admin\AppData\Roaming\Opera\Opera\styles\user\disablebreaks.css.uapro
binary
MD5: 62e504b56b63f6dc9c3ae51b5c628091
SHA256: 115b5d97c5780ac435e90d41a3c2498e0b6ad068fcedbe86af82e88e3e4611ea
2564
GandCrab.exe
C:\Users\admin\AppData\Roaming\Opera\Opera\styles\user\disableforms.css.uapro
binary
MD5: 76a280636a699af5c4bce8a8b24c58ff
SHA256: f9a61791d7bca89cf5951df1a110807f68e1f54c310a5bd6bfb24fa821ab1308
2564
GandCrab.exe
C:\Users\admin\AppData\Roaming\Opera\Opera\styles\user\disableforms.css
––
MD5:  ––
SHA256:  ––
2564
GandCrab.exe
C:\Users\admin\AppData\Roaming\Opera\Opera\styles\user\disablebreaks.css
––
MD5:  ––
SHA256:  ––
2564
GandCrab.exe
C:\Users\admin\AppData\Roaming\Opera\Opera\styles\user\disablefloats.css
––
MD5:  ––
SHA256:  ––
2564
GandCrab.exe
C:\Users\admin\AppData\Roaming\Opera\Opera\styles\user\contrastbw.css
––
MD5:  ––
SHA256:  ––
2564
GandCrab.exe
C:\Users\admin\AppData\Roaming\Opera\Opera\styles\user\contrastwb.css
––
MD5:  ––
SHA256:  ––
2564
GandCrab.exe
C:\Users\admin\AppData\Roaming\Opera\Opera\styles\user\classid.css.uapro
vc
MD5: 5b7bd1258644e6c48cb726799b31b908
SHA256: ce1072808a183e34d0c8b91d24ddf9732ec1fbdfb6309e4e314981fca2d54ee2
2564
GandCrab.exe
C:\Users\admin\AppData\Roaming\Opera\Opera\styles\user\accessibility.css.uapro
binary
MD5: 5b9ccad22a4effcab05942b5a7dddda0
SHA256: 1190fc766495931bdf4b92d4d2f619abdff7a2dac9b7e2fbbc53a4b684d4b33f
2564
GandCrab.exe
C:\Users\admin\AppData\Roaming\Opera\Opera\styles\user\UAPRO-DECRYPT.html
html
MD5: 08c2da0ed1a1bf7ef89f736b9ed43bd2
SHA256: f233665b765c8159f5d39d78e6947aa2a42a56de79e2ad94db7b9ab587038a29
2564
GandCrab.exe
C:\Users\admin\AppData\Roaming\Opera\Opera\styles\user\altdebugger.css.uapro
binary
MD5: 4d9f00dc2b413ab097b482092caf0525
SHA256: f3d0a6669917e8b666eb58c53dc612f52d58d5cd803229486312659d54b6cfff
2564
GandCrab.exe
C:\Users\admin\AppData\Roaming\Opera\Opera\styles\UAPRO-DECRYPT.html
html
MD5: 08c2da0ed1a1bf7ef89f736b9ed43bd2
SHA256: f233665b765c8159f5d39d78e6947aa2a42a56de79e2ad94db7b9ab587038a29
2564
GandCrab.exe
C:\Users\admin\AppData\Roaming\Opera\Opera\styles\user\accessibility.css
––
MD5:  ––
SHA256:  ––
2564
GandCrab.exe
C:\Users\admin\AppData\Roaming\Opera\Opera\styles\user\classid.css
––
MD5:  ––
SHA256:  ––
2564
GandCrab.exe
C:\Users\admin\AppData\Roaming\Opera\Opera\styles\user\altdebugger.css
––
MD5:  ––
SHA256:  ––
2564
GandCrab.exe
C:\Users\admin\AppData\Roaming\Opera\Opera\sessions\UAPRO-DECRYPT.html
html
MD5: 08c2da0ed1a1bf7ef89f736b9ed43bd2
SHA256: f233665b765c8159f5d39d78e6947aa2a42a56de79e2ad94db7b9ab587038a29
2564
GandCrab.exe
C:\Users\admin\AppData\Roaming\Opera\Opera\opthumb.dat.uapro
binary
MD5: cc7869ac376cf44837535ef9d4e3f537
SHA256: 82bde925629e014505a415bf90a785ace7debbaf0e1b67d5fc44f0bb31497230
2564
GandCrab.exe
C:\Users\admin\AppData\Roaming\Opera\Opera\optrust.dat.uapro
binary
MD5: 1bbba01f08a6246ea8348479df293831
SHA256: 8add761005eafe42d381083f385ee6486bcd388e93f3faae5dcc718517c7d6a1
2564
GandCrab.exe
C:\Users\admin\AppData\Roaming\Opera\Opera\speeddial.ini.uapro
binary
MD5: 473fff82a658cd9d8471c00c9c7325bb
SHA256: 3dafc12c6c8df2669f1d7e946d83c7d1d1c38ada0d45b7c058637acb1962bb65
2564
GandCrab.exe
C:\Users\admin\AppData\Roaming\Opera\Opera\opuntrust.dat.uapro
binary
MD5: d7e3f99364e84fd4782c5095875c2892
SHA256: aefebca6c766300a1619c650e2fb94b963cff8b475f463e5ac5ca848904589b3
2564
GandCrab.exe
C:\Users\admin\AppData\Roaming\Opera\Opera\opssl6.dat.uapro
binary
MD5: 8085529489864a04f81b7a132f45318b
SHA256: b71e5c192155846646ace11964daea7621d21ca28e79feb05229c744251fa430
2564
GandCrab.exe
C:\Users\admin\AppData\Roaming\Opera\Opera\opthumb.dat
––
MD5:  ––
SHA256:  ––
2564
GandCrab.exe
C:\Users\admin\AppData\Roaming\Opera\Opera\opuntrust.dat
––
MD5:  ––
SHA256:  ––
2564
GandCrab.exe
C:\Users\admin\AppData\Roaming\Opera\Opera\optrust.dat
––
MD5:  ––
SHA256:  ––
2564
GandCrab.exe
C:\Users\admin\AppData\Roaming\Opera\Opera\speeddial.ini
––
MD5:  ––
SHA256:  ––
2564
GandCrab.exe
C:\Users\admin\AppData\Roaming\Opera\Opera\opssl6.dat
––
MD5:  ––
SHA256:  ––
2564
GandCrab.exe
C:\Users\admin\AppData\Roaming\Opera\Opera\oprand.dat.uapro
binary
MD5: 10d65b7490856aaf8149fcc5b15a5f07
SHA256: 52e830116565a6d289964e8121c9985772dbc767888940924525d786b10f8b99
2564
GandCrab.exe
C:\Users\admin\AppData\Roaming\Opera\Opera\oprand.dat
––
MD5:  ––
SHA256:  ––
2564
GandCrab.exe
C:\Users\admin\AppData\Roaming\Opera\Opera\operaprefs.ini.uapro
binary
MD5: 53d394afa9987917cd479b570354e224
SHA256: eaeb486c7ff17482fbf245efc4f580b00088ad0743159b5f50a03665163c23c9
2564
GandCrab.exe
C:\Users\admin\AppData\Roaming\Opera\Opera\opicacrt6.dat.uapro
binary
MD5: ad1d4485171053749149ec24326208a1
SHA256: 505ce1afbba05372be085fb98c512040f33933a5e2710e504781f94d608412b2
2564
GandCrab.exe
C:\Users\admin\AppData\Roaming\Opera\Opera\opicacrt6.dat
––
MD5:  ––
SHA256:  ––
2564
GandCrab.exe
C:\Users\admin\AppData\Roaming\Opera\Opera\operaprefs.ini
––
MD5:  ––
SHA256:  ––
2564
GandCrab.exe
C:\Users\admin\AppData\Roaming\Opera\Opera\opcert6.dat.uapro
binary
MD5: 47340d7c658e6a688d919d3286f2a1dd
SHA256: 3c412c4969a63b6192de3ba3deb1581b4f44d8a1208493f1947d6b33309b9098
2564
GandCrab.exe
C:\Users\admin\AppData\Roaming\Opera\Opera\opcert6.dat
––
MD5:  ––
SHA256:  ––
2564
GandCrab.exe
C:\Users\admin\AppData\Roaming\Opera\Opera\opcacrt6.dat.uapro
binary
MD5: 068590a041584152ecab0d42c955d96a
SHA256: b3c6b514144cd0bd691e950a01bf56a7953880b5d6e80d8bc6087feace86f5fe
2564
GandCrab.exe
C:\Users\admin\AppData\Roaming\Opera\Opera\opcacrt6.dat
––
MD5:  ––
SHA256:  ––
2564
GandCrab.exe
C:\Users\admin\AppData\Roaming\Opera\Opera\handlers.ini.uapro
binary
MD5: bc6ef369b953bf448bbdf9de11661b62
SHA256: 3993646b04f230b51a409c40cc40d24fe55953036cbc33742d7c0c97c517233c
2564
GandCrab.exe
C:\Users\admin\AppData\Roaming\Opera\Opera\handlers.ini
––
MD5:  ––
SHA256:  ––
2564
GandCrab.exe
C:\Users\admin\AppData\Roaming\Opera\Opera\cookies4.dat.uapro
binary
MD5: 3b532040eb412b6b6424e688ae5c4c21
SHA256: 66575b3932fbd1a9528732b887b1551dcde3130b49584e46e7e51e800d0cbdd9
2564
GandCrab.exe
C:\Users\admin\AppData\Roaming\Opera\Opera\cookies4.dat
––
MD5:  ––
SHA256:  ––
2564
GandCrab.exe
C:\Users\admin\AppData\Roaming\Opera\Opera\bookmarks.adr.uapro
binary
MD5: ea64485e4475c89e3308fd93e046dc06
SHA256: df79f993e2b76de51dd1e83440a13bb87ba857b4ee699092870955cd9b45d1a9
2564
GandCrab.exe
C:\Users\admin\AppData\Roaming\Opera\Opera\bookmarks.adr
––
MD5:  ––
SHA256:  ––
2564
GandCrab.exe
C:\Users\admin\AppData\Roaming\Opera\UAPRO-DECRYPT.html
html
MD5: 08c2da0ed1a1bf7ef89f736b9ed43bd2
SHA256: f233665b765c8159f5d39d78e6947aa2a42a56de79e2ad94db7b9ab587038a29
2564
GandCrab.exe
C:\Users\admin\AppData\Roaming\Notepad++\themes\Zenburn.xml.uapro
binary
MD5: 31bdce5f31e0c77698af1446b8c9eedd
SHA256: ac8ff358f30833544fabe6999f51a04f9dc76819c0c40dbb4e0aec347abf75a3
2564
GandCrab.exe
C:\Users\admin\AppData\Roaming\Opera\Opera\UAPRO-DECRYPT.html
html
MD5: 08c2da0ed1a1bf7ef89f736b9ed43bd2
SHA256: f233665b765c8159f5d39d78e6947aa2a42a56de79e2ad94db7b9ab587038a29
2564
GandCrab.exe
C:\Users\admin\AppData\Roaming\Notepad++\themes\Zenburn.xml
––
MD5:  ––
SHA256:  ––
2564
GandCrab.exe
C:\Users\admin\AppData\Roaming\Notepad++\themes\vim Dark Blue.xml.uapro
binary
MD5: 49191d1643ea6af3a82eae8c71e80374
SHA256: d1def95698636b59cf046abb0b66af4fc2704bdc686efb84e52c494f22837cb7
2564
GandCrab.exe
C:\Users\admin\AppData\Roaming\Notepad++\themes\vim Dark Blue.xml
––
MD5:  ––
SHA256:  ––
2564
GandCrab.exe
C:\Users\admin\AppData\Roaming\Notepad++\themes\Solarized.xml.uapro
binary
MD5: c568016a6d0e9c878728acd8ee793dd7
SHA256: 58c6eb8b0debb3d4dc109b315d956424d69ba6d9e5ba74ec2ff3c7d477a86ac0
2564
GandCrab.exe
C:\Users\admin\AppData\Roaming\Notepad++\themes\Twilight.xml.uapro
binary
MD5: 088e0524fd2854423b69614d4983fd33
SHA256: b733825b0e2cd005166ee3df48973e1309e8a8b69d4d2c27b08d68e85a26c46a
2564
GandCrab.exe
C:\Users\admin\AppData\Roaming\Notepad++\themes\Vibrant Ink.xml.uapro
binary
MD5: 79df0ff872d94c1a448f6d221a387dd7
SHA256: 0c2bb1f4dc7b66c035dca31e8c53e34cd8d4223b4d5ea10bcd6fcfee71095e38
2564
GandCrab.exe
C:\Users\admin\AppData\Roaming\Notepad++\themes\Vibrant Ink.xml
––
MD5:  ––
SHA256:  ––
2564
GandCrab.exe
C:\Users\admin\AppData\Roaming\Notepad++\themes\Twilight.xml
––
MD5:  ––
SHA256:  ––
2564
GandCrab.exe
C:\Users\admin\AppData\Roaming\Notepad++\themes\Solarized.xml
––
MD5:  ––
SHA256:  ––
2564
GandCrab.exe
C:\Users\admin\AppData\Roaming\Notepad++\themes\Ruby Blue.xml.uapro
binary
MD5: 73dad98fe693343752e416d078c70564
SHA256: 6f329ca1ad095f3d06f6f2408b2a73e07b5f46d8778a6415601a2ab204270c4d
2564
GandCrab.exe
C:\Users\admin\AppData\Roaming\Notepad++\themes\Solarized-light.xml.uapro
flc
MD5: b75a3f42d549f4b0e830618958dfa55a
SHA256: 10964ca368cc528c0ea012730db0d4533931086874e82c0d35dda285673a1194
2564
GandCrab.exe
C:\Users\admin\AppData\Roaming\Notepad++\themes\Ruby Blue.xml
––
MD5:  ––
SHA256:  ––
2564
GandCrab.exe
C:\Users\admin\AppData\Roaming\Notepad++\themes\Solarized-light.xml
––
MD5:  ––
SHA256:  ––
2564
GandCrab.exe
C:\Users\admin\AppData\Roaming\Notepad++\themes\Plastic Code Wrap.xml.uapro
binary
MD5: ccc789d70cb6652b6aad42d6114437df
SHA256: 6c831faf90246d31bebdcab578ebbf0f234c86b5738a3ee42de345d6f2ead29f
2564
GandCrab.exe
C:\Users\admin\AppData\Roaming\Notepad++\themes\Obsidian.xml.uapro
binary
MD5: 8ac52ca7b0987363b20c176ead04405f
SHA256: c0554faf1e2fb5563a6bea29dbb4d31af3abd5930310f872273825935c21d575
2564
GandCrab.exe
C:\Users\admin\AppData\Roaming\Notepad++\themes\Obsidian.xml
––
MD5:  ––
SHA256:  ––
2564
GandCrab.exe
C:\Users\admin\AppData\Roaming\Notepad++\themes\Plastic Code Wrap.xml
––
MD5:  ––
SHA256:  ––
2564
GandCrab.exe
C:\Users\admin\AppData\Roaming\Notepad++\themes\Monokai.xml.uapro
binary
MD5: 194640962d19286b388cee7fd6bccc66
SHA256: 41d78e71e9463bb7b5c93898ced01740fb222e27ed15af3d9e15d3cc5fc4fdc3
2564
GandCrab.exe
C:\Users\admin\AppData\Roaming\Notepad++\themes\MossyLawn.xml.uapro
binary
MD5: 2893a7ad71627f986d42e18a43de5135
SHA256: eeddfaf1ff82568d339a1db98e72f2e296867051b3dd53424970a8ccccf518c7
2564
GandCrab.exe
C:\Users\admin\AppData\Roaming\Notepad++\themes\Navajo.xml.uapro
bs
MD5: c19e3418b362c3128ba1a1b60833a272
SHA256: 8adb12cf270673074d656d4dd9a7d6cc54fe662d61f97da239597aaf92a6e37d
2564
GandCrab.exe
C:\Users\admin\AppData\Roaming\Notepad++\themes\Mono Industrial.xml.uapro
binary
MD5: 35f2d731cad9f9a736a1013c1eb5d228
SHA256: ace0adf6a9f92725dde155e17d80a84ab5b52e6b0e6ff897cf9d7761721542f2
2564
GandCrab.exe
C:\Users\admin\AppData\Roaming\Notepad++\themes\Mono Industrial.xml
––
MD5:  ––
SHA256:  ––
2564
GandCrab.exe
C:\Users\admin\AppData\Roaming\Notepad++\themes\Monokai.xml
––
MD5:  ––
SHA256:  ––
2564
GandCrab.exe
C:\Users\admin\AppData\Roaming\Notepad++\themes\Navajo.xml
––
MD5:  ––
SHA256:  ––
2564
GandCrab.exe
C:\Users\admin\AppData\Roaming\Notepad++\themes\MossyLawn.xml
––
MD5:  ––
SHA256:  ––
2564
GandCrab.exe
C:\Users\admin\AppData\Roaming\Notepad++\themes\HotFudgeSundae.xml.uapro
binary
MD5: e1ad957cc35e768338074356d5f7fe6a
SHA256: b82695d397a984d9fa3d29006b0e27a60f0041613fcd83e055059a3540acf465
2564
GandCrab.exe
C:\Users\admin\AppData\Roaming\Notepad++\themes\Hello Kitty.xml.uapro
binary
MD5: 200b8421c64f1f0343c10a2ea6401c8f
SHA256: a383cca71dc7fd7618b7d2b9fabe9b29d664c1f806ad141545aade9961d90167
2564
GandCrab.exe
C:\Users\admin\AppData\Roaming\Notepad++\themes\khaki.xml.uapro
binary
MD5: 83538fc14511cc34912acc4718555144
SHA256: 5abd9e1e64837c8405457c150e5e9ba0a2e829f150cde3b87b7ce6a86b58665d
2564
GandCrab.exe
C:\Users\admin\AppData\Roaming\Notepad++\themes\Hello Kitty.xml
––
MD5:  ––
SHA256:  ––
2564
GandCrab.exe
C:\Users\admin\AppData\Roaming\Notepad++\themes\khaki.xml
––
MD5:  ––
SHA256:  ––
2564
GandCrab.exe
C:\Users\admin\AppData\Roaming\Notepad++\themes\HotFudgeSundae.xml
––
MD5:  ––
SHA256:  ––
2564
GandCrab.exe
C:\Users\admin\AppData\Roaming\Notepad++\themes\Black board.xml.uapro
binary
MD5: ccca6eefd212e5fdfb0b723c96c38502
SHA256: d26138f8ddb9ec4ca27fdd20e78186e0823e1215b05afa5be5f95113b00afb3b
2564
GandCrab.exe
C:\Users\admin\AppData\Roaming\Notepad++\themes\Choco.xml.uapro
binary
MD5: 7580b1c52b037dbda9e1e02c557ad5eb
SHA256: d7cb12bc365f4100c09fc7a42b1963be17c8c4c1c91a7993f72cfdc621e5efa2
2564
GandCrab.exe
C:\Users\admin\AppData\Roaming\Notepad++\themes\Deep Black.xml.uapro
binary
MD5: 5ee02e4081b64bc7bbc284cbd602262c
SHA256: f6f256654a7840ec9d7149d70ae8dfaf14eee762cd39005b8530ba51244df52c
2564
GandCrab.exe
C:\Users\admin\AppData\Roaming\Notepad++\themes\Choco.xml
––
MD5:  ––
SHA256:  ––
2564
GandCrab.exe
C:\Users\admin\AppData\Roaming\Notepad++\themes\Black board.xml
––
MD5:  ––
SHA256:  ––
2564
GandCrab.exe
C:\Users\admin\AppData\Roaming\Notepad++\themes\Deep Black.xml
––
MD5:  ––
SHA256:  ––
2564
GandCrab.exe
C:\Users\admin\AppData\Roaming\Notepad++\plugins\UAPRO-DECRYPT.html
html
MD5: 08c2da0ed1a1bf7ef89f736b9ed43bd2
SHA256: f233665b765c8159f5d39d78e6947aa2a42a56de79e2ad94db7b9ab587038a29
2564
GandCrab.exe
C:\Users\admin\AppData\Roaming\Notepad++\plugins\config\UAPRO-DECRYPT.html
html
MD5: 08c2da0ed1a1bf7ef89f736b9ed43bd2
SHA256: f233665b765c8159f5d39d78e6947aa2a42a56de79e2ad94db7b9ab587038a29
2564
GandCrab.exe
C:\Users\admin\AppData\Roaming\Notepad++\themes\Bespin.xml.uapro
binary
MD5: c018fd67d6e840ca354d55294a63cb21
SHA256: 308e405b713a6865d87e657c045f51f3cab9f4c71ab7ec9bba024e297e56e206
2564
GandCrab.exe
C:\Users\admin\AppData\Roaming\Notepad++\themes\UAPRO-DECRYPT.html
html
MD5: 08c2da0ed1a1bf7ef89f736b9ed43bd2
SHA256: f233665b765c8159f5d39d78e6947aa2a42a56de79e2ad94db7b9ab587038a29
2564
GandCrab.exe
C:\Users\admin\AppData\Roaming\Notepad++\functionList.xml.uapro
flc
MD5: 56e5be7caf09aea8167750e14d2db6e1
SHA256: 18fc5b58763baf559caa335e05dffac9738fbc6305f82735726d641b76ac1c15
2564
GandCrab.exe
C:\Users\admin\AppData\Roaming\Notepad++\themes\Bespin.xml
––
MD5:  ––
SHA256:  ––
2564
GandCrab.exe
C:\Users\admin\AppData\Roaming\Notepad++\functionList.xml
––
MD5:  ––
SHA256:  ––
2564
GandCrab.exe
C:\Users\admin\AppData\Roaming\Mozilla\SystemExtensionsDev\UAPRO-DECRYPT.html
html
MD5: 08c2da0ed1a1bf7ef89f736b9ed43bd2
SHA256: f233665b765c8159f5d39d78e6947aa2a42a56de79e2ad94db7b9ab587038a29
2564
GandCrab.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\profiles.ini.uapro
binary
MD5: 1826c19b3be63f9b3df222376786e7b6
SHA256: 0a8fa709c3f20d844e27bede0b1d36e2a4cad5526a444679e1b1de45b68d397b
2564
GandCrab.exe
C:\Users\admin\AppData\Roaming\Notepad++\UAPRO-DECRYPT.html
html
MD5: 08c2da0ed1a1bf7ef89f736b9ed43bd2
SHA256: f233665b765c8159f5d39d78e6947aa2a42a56de79e2ad94db7b9ab587038a29
2564
GandCrab.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\xulstore.json.uapro
binary
MD5: 41bb7f249d85d5736054787ca73885a1
SHA256: 880e0d4e2b6a83a7c13a1b7d9359150691e32160298baaec108985912f911dcf
2564
GandCrab.exe
C:\Users\admin\AppData\Roaming\Notepad++\contextMenu.xml.uapro
vc
MD5: f36cca55cc93ef4350116158fa0e9e24
SHA256: e53a83aaf4a45fda10f692d9ec140018f9974d5b377e0c1a8256ddf544d2948b
2564
GandCrab.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\profiles.ini
––
MD5:  ––
SHA256:  ––
2564
GandCrab.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\xulstore.json
––
MD5:  ––
SHA256:  ––
2564
GandCrab.exe
C:\Users\admin\AppData\Roaming\Notepad++\contextMenu.xml
––
MD5:  ––
SHA256:  ––
2564
GandCrab.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\webappsstore.sqlite.uapro
binary
MD5: d9798fa3e612cc442c96c9b681cf57f0
SHA256: 543652a0513b5262f9c8267f98d0f4a1357ddfeaa14c84a9a64bc498920b492d
2564
GandCrab.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\weave\toFetch\UAPRO-DECRYPT.html
html
MD5: 08c2da0ed1a1bf7ef89f736b9ed43bd2
SHA256: f233665b765c8159f5d39d78e6947aa2a42a56de79e2ad94db7b9ab587038a29
2564
GandCrab.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\weave\toFetch\tabs.json.uapro
binary
MD5: 918142ab9b70656db8d25692defba9ad
SHA256: d52353f5f94d066d603bc3ade99cb2ab2bc94e6f012c104c25ee9ddc936681d8
2564
GandCrab.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\weave\failed\tabs.json.uapro
binary
MD5: a47ae9b50a9d27a6e752a7dc581ce826
SHA256: f94f183c01307c4dc3e2b66ab4952c6c64afd9554b969853dc4492f9acb4db99
2564
GandCrab.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\webappsstore.sqlite
––
MD5:  ––
SHA256:  ––
2564
GandCrab.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\weave\toFetch\tabs.json
––
MD5:  ––
SHA256:  ––
2564
GandCrab.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\weave\failed\tabs.json
––
MD5:  ––
SHA256:  ––
2564
GandCrab.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\weave\failed\UAPRO-DECRYPT.html
html
MD5: 08c2da0ed1a1bf7ef89f736b9ed43bd2
SHA256: f233665b765c8159f5d39d78e6947aa2a42a56de79e2ad94db7b9ab587038a29
2564
GandCrab.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\storage\permanent\chrome\idb\727688008bsleotcakcliifsittsr%.sqlite.uapro
binary
MD5: 5c1b342ba22e7aca9bdab8ca003f8a88
SHA256: 7a9d8ed212a325cd7566be77a1ab341168b068a78cb7332f29b2ed42f70fb80d
2564
GandCrab.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\weave\UAPRO-DECRYPT.html
html
MD5: 08c2da0ed1a1bf7ef89f736b9ed43bd2
SHA256: f233665b765c8159f5d39d78e6947aa2a42a56de79e2ad94db7b9ab587038a29
2564
GandCrab.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\storage.sqlite.uapro
binary
MD5: b9f6324c5abb9ecac7967180badba63f
SHA256: 7d057689e5e7900651ad536e31ee5d13b98868b70c43af04c5cde95f8fc7a0aa
2564
GandCrab.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\storage\temporary\UAPRO-DECRYPT.html
html
MD5: 08c2da0ed1a1bf7ef89f736b9ed43bd2
SHA256: f233665b765c8159f5d39d78e6947aa2a42a56de79e2ad94db7b9ab587038a29
2564
GandCrab.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\times.json.uapro
binary
MD5: 4e37a5c2fbbe0f61910642861390cdf2
SHA256: 2058d87fdc31f99bfc3a9e33bb1f8d4b982948033eb54798c4d705b8c2086c80
2564
GandCrab.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\storage.sqlite
––
MD5:  ––
SHA256:  ––
2564
GandCrab.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\times.json
––
MD5:  ––
SHA256:  ––
2564
GandCrab.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\storage\permanent\chrome\idb\727688008bsleotcakcliifsittsr%.sqlite
––
MD5:  ––
SHA256:  ––
2564
GandCrab.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\storage\permanent\chrome\idb\727688008bsleotcakcliifsittsr%.files\UAPRO-DECRYPT.html
html
MD5: 08c2da0ed1a1bf7ef89f736b9ed43bd2
SHA256: f233665b765c8159f5d39d78e6947aa2a42a56de79e2ad94db7b9ab587038a29
2564
GandCrab.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\storage\permanent\chrome\idb\3899588440psinninpiFn2g%.sqlite.uapro
binary
MD5: 760e2283d23f0c0f7e366bc6828e4b1d
SHA256: 2cdd95537b1e72b74afd1d6bff3ca77d01b83c5890bd5d74eba520be61885a9d
2564
GandCrab.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\storage\permanent\chrome\idb\3899588440psinninpiFn2g%.sqlite
––
MD5:  ––
SHA256:  ––
2564
GandCrab.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\storage\permanent\chrome\idb\3899588440psinninpiFn2g%.files\UAPRO-DECRYPT.html
html
MD5: 08c2da0ed1a1bf7ef89f736b9ed43bd2
SHA256: f233665b765c8159f5d39d78e6947aa2a42a56de79e2ad94db7b9ab587038a29
2564
GandCrab.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\storage\permanent\chrome\idb\3870112724rsegmnoittet-es.sqlite.uapro
––
MD5:  ––
SHA256:  ––
2564
GandCrab.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\storage\permanent\chrome\idb\3870112724rsegmnoittet-es.sqlite
––
MD5:  ––
SHA256:  ––
2564
GandCrab.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\storage\permanent\chrome\idb\3870112724rsegmnoittet-es.files\UAPRO-DECRYPT.html
html
MD5: 08c2da0ed1a1bf7ef89f736b9ed43bd2
SHA256: f233665b765c8159f5d39d78e6947aa2a42a56de79e2ad94db7b9ab587038a29
2564
GandCrab.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\storage\permanent\chrome\idb\3561288849sdhlie.sqlite.uapro
binary
MD5: 4b6ea8649e4ad86d5518ee9fc321587c
SHA256: 8e1f8773213786d71c1e1429acf7c3225f933bb5b6a7f0744f9e0e47dbf44ebd
2564
GandCrab.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\storage\permanent\chrome\idb\3345959086bslnoocdkdlaiFs2t%s.sqlite.uapro
binary
MD5: 2104d3a94fe724c9cc974714ea5e0745
SHA256: b4d51b3b0963b4c34e596b864fb371528584c3388ce1e6d631e29a5dd72250cb
2564
GandCrab.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\storage\permanent\chrome\idb\3561288849sdhlie.files\UAPRO-DECRYPT.html
html
MD5: 08c2da0ed1a1bf7ef89f736b9ed43bd2
SHA256: f233665b765c8159f5d39d78e6947aa2a42a56de79e2ad94db7b9ab587038a29
2564
GandCrab.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\storage\permanent\chrome\idb\3345959086bslnoocdkdlaiFs2t%s.sqlite
––
MD5:  ––
SHA256:  ––
2564
GandCrab.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\storage\permanent\chrome\idb\3561288849sdhlie.sqlite
––
MD5:  ––
SHA256:  ––
2564
GandCrab.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\storage\permanent\chrome\idb\3345959086bslnoocdkdlaiFs2t%s.files\UAPRO-DECRYPT.html
html
MD5: 08c2da0ed1a1bf7ef89f736b9ed43bd2
SHA256: f233665b765c8159f5d39d78e6947aa2a42a56de79e2ad94db7b9ab587038a29
2564
GandCrab.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\storage\permanent\chrome\idb\2918063365piupsah.sqlite.uapro
binary
MD5: b8cd9212436fb575be691cce4e16c33d
SHA256: 41f41b5e2a63ec6523dcd57eff1a119d82149a9690d36f4e4a70067ee0ba9eeb
2564
GandCrab.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\storage\permanent\chrome\idb\2918063365piupsah.files\UAPRO-DECRYPT.html
html
MD5: 08c2da0ed1a1bf7ef89f736b9ed43bd2
SHA256: f233665b765c8159f5d39d78e6947aa2a42a56de79e2ad94db7b9ab587038a29
2564
GandCrab.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\storage\permanent\chrome\idb\2918063365piupsah.sqlite
––
MD5:  ––
SHA256:  ––
2564
GandCrab.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\storage\permanent\chrome\idb\1725441852bxlfogcFk2l%isst.sqlite.uapro
binary
MD5: f3a6bcc8bac25c21686eb96c4346b55a
SHA256: e97b40573b1b63eafb5008789f64367c289e2cf4fad8e75e507923ee73a24971
2564
GandCrab.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\storage\permanent\chrome\idb\1725441852bxlfogcFk2l%isst.sqlite
––
MD5:  ––
SHA256:  ––
2564
GandCrab.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\storage\permanent\chrome\idb\1657114595AmcateirvtiSty.sqlite.uapro
binary
MD5: 7df2283ede67963f0e5e2fd99b3517fe
SHA256: bdaa3832e73c5f91c69740a47b3e3e8747793cc18737dd3c3ccf812bdba17961
2564
GandCrab.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\storage\permanent\chrome\idb\1725441852bxlfogcFk2l%isst.files\UAPRO-DECRYPT.html
html
MD5: 08c2da0ed1a1bf7ef89f736b9ed43bd2
SHA256: f233665b765c8159f5d39d78e6947aa2a42a56de79e2ad94db7b9ab587038a29
2564
GandCrab.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\storage\permanent\chrome\idb\1657114595AmcateirvtiSty.sqlite
––
MD5:  ––
SHA256:  ––
2564
GandCrab.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\storage\permanent\chrome\idb\1657114595AmcateirvtiSty.files\UAPRO-DECRYPT.html
html
MD5: 08c2da0ed1a1bf7ef89f736b9ed43bd2
SHA256: f233665b765c8159f5d39d78e6947aa2a42a56de79e2ad94db7b9ab587038a29
2564
GandCrab.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\storage\permanent\chrome\idb\1451318868ntouromlalnodry--epcr.sqlite.uapro
binary
MD5: d7856c7a5d61a553a7e9fd980adc3d72
SHA256: 639d0e225a64c1294930f8b64440e8c388ce26d9f3765caf0d2ca538e9f7f878
2564
GandCrab.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\storage\permanent\chrome\idb\1657114595AmcateirvtiSty.files\journals\UAPRO-DECRYPT.html
html
MD5: 08c2da0ed1a1bf7ef89f736b9ed43bd2
SHA256: f233665b765c8159f5d39d78e6947aa2a42a56de79e2ad94db7b9ab587038a29
2564
GandCrab.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\storage\permanent\chrome\idb\1451318868ntouromlalnodry--epcr.sqlite
––
MD5:  ––
SHA256:  ––
2564
GandCrab.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\storage\permanent\chrome\idb\1059394878bslnoicgkullipsFt2s%.sqlite.uapro
binary
MD5: 2aadee528bffa016dcdf38726f1f63a0
SHA256: 91cd7b37cec41e59c13916202ded80ebda19e02d64a424775ef90e88a975fa69
2564
GandCrab.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\storage\permanent\chrome\idb\1451318868ntouromlalnodry--epcr.files\UAPRO-DECRYPT.html
html
MD5: 08c2da0ed1a1bf7ef89f736b9ed43bd2
SHA256: f233665b765c8159f5d39d78e6947aa2a42a56de79e2ad94db7b9ab587038a29
2564
GandCrab.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\storage\permanent\chrome\idb\1059394878bslnoicgkullipsFt2s%.sqlite
––
MD5:  ––
SHA256:  ––
2564
GandCrab.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\storage\permanent\chrome\idb\1059394878bslnoicgkullipsFt2s%.files\UAPRO-DECRYPT.html
html
MD5: 08c2da0ed1a1bf7ef89f736b9ed43bd2
SHA256: f233665b765c8159f5d39d78e6947aa2a42a56de79e2ad94db7b9ab587038a29
2564
GandCrab.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\storage\permanent\chrome\idb\UAPRO-DECRYPT.html
html
MD5: 08c2da0ed1a1bf7ef89f736b9ed43bd2
SHA256: f233665b765c8159f5d39d78e6947aa2a42a56de79e2ad94db7b9ab587038a29
2564
GandCrab.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\storage\permanent\chrome\.metadata-v2.uapro
binary
MD5: 72591d65f7a274a862ef554fe912f70c
SHA256: 7f9251712bfde220dab5075d75267148f4e205911a87d4a23ef0da1cb6190f3d
2564
GandCrab.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\storage\permanent\chrome\.metadata-v2
––
MD5:  ––
SHA256:  ––
2564
GandCrab.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\storage\permanent\chrome\.metadata.uapro
binary
MD5: de4e944858a30c3f36197dcef6ac2299
SHA256: 622b898bfbb8004e65f9a2d9160f6f2642315fcf1cea0dfc4b330660950cf209
2564
GandCrab.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\storage\permanent\chrome\.metadata
––
MD5:  ––
SHA256:  ––
2564
GandCrab.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\storage\permanent\chrome\UAPRO-DECRYPT.html
html
MD5: 08c2da0ed1a1bf7ef89f736b9ed43bd2
SHA256: f233665b765c8159f5d39d78e6947aa2a42a56de79e2ad94db7b9ab587038a29
2564
GandCrab.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\storage\permanent\UAPRO-DECRYPT.html
html
MD5: 08c2da0ed1a1bf7ef89f736b9ed43bd2
SHA256: f233665b765c8159f5d39d78e6947aa2a42a56de79e2ad94db7b9ab587038a29
2564
GandCrab.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\storage\default\moz-extension+++a35bff6e-5489-4e10-95ce-0340b402ad38^userContextId=4294967295\idb\3647222921wleabcEoxlt-eengsairo.sqlite.uapro
binary
MD5: 2940f3890c22be13f9299f7f48cbb593
SHA256: 4edcad362d63f364729e155e43ad02f705eef435bc0e9a3af995a4b0f6e8e49e
2564
GandCrab.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\storage\default\moz-extension+++a35bff6e-5489-4e10-95ce-0340b402ad38^userContextId=4294967295\idb\3647222921wleabcEoxlt-eengsairo.sqlite
––
MD5:  ––
SHA256:  ––
2564
GandCrab.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\storage\default\moz-extension+++a35bff6e-5489-4e10-95ce-0340b402ad38^userContextId=4294967295\idb\UAPRO-DECRYPT.html
html
MD5: 08c2da0ed1a1bf7ef89f736b9ed43bd2
SHA256: f233665b765c8159f5d39d78e6947aa2a42a56de79e2ad94db7b9ab587038a29
2564
GandCrab.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\storage\default\moz-extension+++a35bff6e-5489-4e10-95ce-0340b402ad38^userContextId=4294967295\idb\3647222921wleabcEoxlt-eengsairo.files\UAPRO-DECRYPT.html
html
MD5: 08c2da0ed1a1bf7ef89f736b9ed43bd2
SHA256: f233665b765c8159f5d39d78e6947aa2a42a56de79e2ad94db7b9ab587038a29
2564
GandCrab.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\storage\default\moz-extension+++a35bff6e-5489-4e10-95ce-0340b402ad38^userContextId=4294967295\.metadata-v2.uapro
binary
MD5: add7b3825fea404716b8e6e024671ca7
SHA256: 22cd4abb94dfff97b4bc89b0a7fd29eae8db35c9915c57ae9621088eb95f1218
2564
GandCrab.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\storage\default\moz-extension+++a35bff6e-5489-4e10-95ce-0340b402ad38^userContextId=4294967295\.metadata-v2
––
MD5:  ––
SHA256:  ––
2564
GandCrab.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\storage\default\moz-extension+++a35bff6e-5489-4e10-95ce-0340b402ad38^userContextId=4294967295\.metadata.uapro
binary
MD5: 8d2c69d4f04cf87eaa2e0ede68b27185
SHA256: 58ee692d8e52bbf89920220c34f74f891b64ff0a6748c565da2a7a660c1d5d5e
2564
GandCrab.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\storage\default\moz-extension+++a35bff6e-5489-4e10-95ce-0340b402ad38^userContextId=4294967295\.metadata
––
MD5:  ––
SHA256:  ––
2564
GandCrab.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\storage\default\moz-extension+++a35bff6e-5489-4e10-95ce-0340b402ad38^userContextId=4294967295\UAPRO-DECRYPT.html
html
MD5: 08c2da0ed1a1bf7ef89f736b9ed43bd2
SHA256: f233665b765c8159f5d39d78e6947aa2a42a56de79e2ad94db7b9ab587038a29
2564
GandCrab.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\storage\default\about+newtab\idb\3312185054sbndi_pspte.sqlite.uapro
binary
MD5: fbf37e2f4b660fe982a6c041cfd12897
SHA256: 325a0a06ff986f5aa3e14b7358d4e988d85357d220c59a7984359fcd47c3e5b7
2564
GandCrab.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\storage\default\about+newtab\idb\3312185054sbndi_pspte.sqlite
––
MD5:  ––
SHA256:  ––
2564
GandCrab.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\storage\default\about+newtab\idb\3312185054sbndi_pspte.files\journals\UAPRO-DECRYPT.html
html
MD5: 08c2da0ed1a1bf7ef89f736b9ed43bd2
SHA256: f233665b765c8159f5d39d78e6947aa2a42a56de79e2ad94db7b9ab587038a29
2564
GandCrab.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\storage\default\about+newtab\idb\3312185054sbndi_pspte.files\1.uapro
––
MD5:  ––
SHA256:  ––
2564
GandCrab.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\storage\default\about+newtab\idb\3312185054sbndi_pspte.files\1
––
MD5:  ––
SHA256:  ––
2564
GandCrab.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\storage\default\about+newtab\idb\3312185054sbndi_pspte.files\UAPRO-DECRYPT.html
html
MD5: 08c2da0ed1a1bf7ef89f736b9ed43bd2
SHA256: f233665b765c8159f5d39d78e6947aa2a42a56de79e2ad94db7b9ab587038a29
2564
GandCrab.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\storage\default\about+newtab\idb\UAPRO-DECRYPT.html
html
MD5: 08c2da0ed1a1bf7ef89f736b9ed43bd2
SHA256: f233665b765c8159f5d39d78e6947aa2a42a56de79e2ad94db7b9ab587038a29
2564
GandCrab.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\storage\default\about+newtab\.metadata-v2.uapro
binary
MD5: aa27568042632d8413a2deec18f60880
SHA256: 427911126b0973846772305faab4b5a7dc76164dfb980af8823bde02d5134a22
2564
GandCrab.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\storage\default\about+newtab\.metadata-v2
––
MD5:  ––
SHA256:  ––
2564
GandCrab.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\storage\default\about+newtab\.metadata.uapro
binary
MD5: 11fc5c4a11e8e79fc4a773ec9970b2bb
SHA256: f6a192c83edc2565f25b692c4392ef51d95eb193b4136a5a2210e4c0af227736
2564
GandCrab.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\storage\default\about+newtab\.metadata
––
MD5:  ––
SHA256:  ––
2564
GandCrab.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\storage\default\about+home\idb\3312185054sbndi_pspte.sqlite.uapro
binary
MD5: f20f8bdcfac941122544cfbabbb56c55
SHA256: ddb08bc18e0af511884a378cb09636044e8a987c5667c61297ddf3cdea978e0e
2564
GandCrab.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\storage\default\about+newtab\UAPRO-DECRYPT.html
html
MD5: 08c2da0ed1a1bf7ef89f736b9ed43bd2
SHA256: f233665b765c8159f5d39d78e6947aa2a42a56de79e2ad94db7b9ab587038a29
2564
GandCrab.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\storage\default\about+home\idb\3312185054sbndi_pspte.sqlite
––
MD5:  ––
SHA256:  ––
2564
GandCrab.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\storage\default\about+home\idb\3312185054sbndi_pspte.files\2.uapro
binary
MD5: 4ef11fadaad990c613fa26c9d9984a19
SHA256: 2187ace2f81e7fd2475f72d04511ee383b11c2014bd9df893bd01f9848a795e5
2564
GandCrab.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\storage\default\about+home\idb\3312185054sbndi_pspte.files\journals\UAPRO-DECRYPT.html
html
MD5: 08c2da0ed1a1bf7ef89f736b9ed43bd2
SHA256: f233665b765c8159f5d39d78e6947aa2a42a56de79e2ad94db7b9ab587038a29
2564
GandCrab.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\storage\default\about+home\idb\3312185054sbndi_pspte.files\2
––
MD5:  ––
SHA256:  ––
2564
GandCrab.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\storage\default\about+home\idb\UAPRO-DECRYPT.html
html
MD5: 08c2da0ed1a1bf7ef89f736b9ed43bd2
SHA256: f233665b765c8159f5d39d78e6947aa2a42a56de79e2ad94db7b9ab587038a29
2564
GandCrab.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\storage\default\about+home\idb\3312185054sbndi_pspte.files\UAPRO-DECRYPT.html
html
MD5: 08c2da0ed1a1bf7ef89f736b9ed43bd2
SHA256: f233665b765c8159f5d39d78e6947aa2a42a56de79e2ad94db7b9ab587038a29
2564
GandCrab.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\storage\default\about+home\.metadata-v2.uapro
binary
MD5: 1e8fd0808882dd8facf46db6797f4cff
SHA256: 46c415e021f84ba80bb4aa7db7ff00d7f842bce60cdc45ff9494a853b5a43678
2564
GandCrab.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\storage\default\about+home\.metadata-v2
––
MD5:  ––
SHA256:  ––
2564
GandCrab.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\storage\default\about+home\.metadata.uapro
binary
MD5: e371ad1956048d7d841ac5a487644817
SHA256: 069c489581f2088af3ce991e6bbe252634051cdccaf778b3477c574c5a9d35c5
2564
GandCrab.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\storage\default\about+home\.metadata
––
MD5:  ––
SHA256:  ––
2564
GandCrab.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\storage\UAPRO-DECRYPT.html
html
MD5: 08c2da0ed1a1bf7ef89f736b9ed43bd2
SHA256: f233665b765c8159f5d39d78e6947aa2a42a56de79e2ad94db7b9ab587038a29
2564
GandCrab.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\storage\default\about+home\UAPRO-DECRYPT.html
html
MD5: 08c2da0ed1a1bf7ef89f736b9ed43bd2
SHA256: f233665b765c8159f5d39d78e6947aa2a42a56de79e2ad94db7b9ab587038a29
2564
GandCrab.exe
C:\Users\admin\AppData\Local\Temp\pidor.bmp
image
MD5: 5dc54c69d344f8a990bc9ee60e97176b
SHA256: cc9e85e556766f3f6d4fc653580c92e57e87435498c65066ab473d4dbe7d2be0
2564
GandCrab.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\SiteSecurityServiceState.txt.uapro
binary
MD5: cc364fba58c620a990d6b7acff6cc31d
SHA256: 73f0ec0ecacf9dcd2a025fecebc3baffc72f4fe8d327f0358fd841386c276aad
2564
GandCrab.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\SiteSecurityServiceState.txt
––
MD5:  ––
SHA256:  ––
2564
GandCrab.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\sessionstore.jsonlz4.uapro
binary
MD5: 4a41329c4fba7d3ee24f14c291440306
SHA256: 68c5cfb57cc5be62f57cf4a379933dd08100e4dd2258cf3b78bddd019f6cb750
2564
GandCrab.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\sessionstore.jsonlz4
––
MD5:  ––
SHA256:  ––
2564
GandCrab.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\sessionstore-backups\upgrade.jsonlz4-20190717172542.uapro
binary
MD5: 1467d6921dc955e62da713a76d1ba5f7
SHA256: 9dcf759286754c970b3bb758da79bb95cb73b12d9b798a363994d2b5b02730ab
2564
GandCrab.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\sessionstore-backups\upgrade.jsonlz4-20190717172542
––
MD5:  ––
SHA256:  ––
2564
GandCrab.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\sessionstore-backups\upgrade.jsonlz4-20190619235627.uapro
binary
MD5: ecf33874a3b1996a8f32591ea92f01fd
SHA256: 3e274e32de049bdf59b5cb9998ef4c602d586c19795f4f9fa58036dac01fef51
2564
GandCrab.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\sessionstore-backups\upgrade.jsonlz4-20190619235627
––
MD5:  ––
SHA256:  ––
2564
GandCrab.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\sessionstore-backups\previous.jsonlz4.uapro
binary
MD5: bbba1311c54e25ed5e96ab40769a8c1c
SHA256: 3ac8262139aab7d464e8145ff3e2f1e4ff82b905f203bb76c5ee96c9c00fcde2
2564
GandCrab.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\sessionstore-backups\previous.jsonlz4
––
MD5:  ––
SHA256:  ––
2564
GandCrab.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\sessionstore-backups\UAPRO-DECRYPT.html
html
MD5: 08c2da0ed1a1bf7ef89f736b9ed43bd2
SHA256: f233665b765c8159f5d39d78e6947aa2a42a56de79e2ad94db7b9ab587038a29
2564
GandCrab.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\sessionCheckpoints.json.uapro
binary
MD5: b5ce88c8d4b6f3a61bdc2a8021928d81
SHA256: 2527ce59bf4f2dd05f45a2e3435079cee4c5507b5a579db5d9b36cc4b96bf3a1
2564
GandCrab.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\sessionCheckpoints.json
––
MD5:  ––
SHA256:  ––
2564
GandCrab.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\search.json.mozlz4.uapro
binary
MD5: 21ceafd92f06d654e5950231c7571d83
SHA256: a7d0bf30684ae35e7d7db2be58fb7393c0e7dc823c2a2f54e475f6c259d395bc
2564
GandCrab.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\search.json.mozlz4
––
MD5:  ––
SHA256:  ––
2564
GandCrab.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\revocations.txt.uapro
binary
MD5: e55c46b82e0e1e33f7febbbb6e70fd99
SHA256: ed8b7adc9a127006b49830796d754bca8ba294654401daa117807eeb8044523e
2564
GandCrab.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\saved-telemetry-pings\UAPRO-DECRYPT.html
html
MD5: 08c2da0ed1a1bf7ef89f736b9ed43bd2
SHA256: f233665b765c8159f5d39d78e6947aa2a42a56de79e2ad94db7b9ab587038a29
2564
GandCrab.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\revocations.txt
––
MD5:  ––
SHA256:  ––
2564
GandCrab.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\prefs.js.uapro
binary
MD5: bc127c4923f963ca435a422870218217
SHA256: b8d658029e841acb654a102bfb88dbfdb18b2be886e318b2d6e25ddd4df1815e
2564
GandCrab.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\prefs.js
––
MD5:  ––
SHA256:  ––
2564
GandCrab.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\pluginreg.dat.uapro
binary
MD5: 96201b0b7d4a2e48c04aaf0b29d18190
SHA256: b3c266d0efe16a8f58ddc4f62e85f0514de4999bb37277d05b1f8f803f7d97cc
2564
GandCrab.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\pluginreg.dat
––
MD5:  ––
SHA256:  ––
2564
GandCrab.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\places.sqlite.uapro
––
MD5:  ––
SHA256:  ––
2564
GandCrab.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\places.sqlite
––
MD5:  ––
SHA256:  ––
2564
GandCrab.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\pkcs11.txt.uapro
binary
MD5: d16f2314a139396c1fcd1c78d9730022
SHA256: 2a2a9a9abbbce9c69fa828b6c1d708bfc9db4e0df70c086d8b85c723c60684d7
2564
GandCrab.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\pkcs11.txt
––
MD5:  ––
SHA256:  ––
2564
GandCrab.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\permissions.sqlite.uapro
binary
MD5: a69e48c358da19888a5db680f031f7ff
SHA256: 0e8ebb0e39d673611835a3e767130a7f86b28d5728c42f2f4fecaf1fa29b688b
2564
GandCrab.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\permissions.sqlite
––
MD5:  ––
SHA256:  ––
2564
GandCrab.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\logins.json.uapro
binary
MD5: ad5449f2578fb40266404d0054fdeaca
SHA256: 475e5362cd95ae2c4d90a3256bd950c2ed19ffaad75416438cc6b908b9ed5805
2564
GandCrab.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\minidumps\UAPRO-DECRYPT.html
html
MD5: 08c2da0ed1a1bf7ef89f736b9ed43bd2
SHA256: f233665b765c8159f5d39d78e6947aa2a42a56de79e2ad94db7b9ab587038a29
2564
GandCrab.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\logins.json
––
MD5:  ––
SHA256:  ––
2564
GandCrab.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\key4.db.uapro
binary
MD5: 18a825ecd6110f99765608bd515d205e
SHA256: cb30a58bc7e497a5faed4f25b05fbfc63bc1a4c2d09f6fc8b1ec59de1f19136e
2564
GandCrab.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\key4.db
––
MD5:  ––
SHA256:  ––
2564
GandCrab.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\handlers.json.uapro
binary
MD5: 03f1f080750fccfb03f4c0769d64432a
SHA256: 9388a3027287b872494dd01e1ef2d0d28612c9a1c045b49361efe33cb5d0be1f
2564
GandCrab.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\handlers.json
––
MD5:  ––
SHA256:  ––
2564
GandCrab.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\gmp-widevinecdm\4.10.1440.18\widevinecdm.dll.sig.uapro
binary
MD5: 1969ca2540e1ebcc063fb8b5c36c9d31
SHA256: 3be8a22abd9e1791196bc622e0d13e2e8860a52820d6a942304bbeb9e5a97013
2564
GandCrab.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\gmp-widevinecdm\4.10.1440.18\widevinecdm.dll.sig
––
MD5:  ––
SHA256:  ––
2564
GandCrab.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\gmp-widevinecdm\4.10.1440.18\widevinecdm.dll.lib.uapro
binary
MD5: 620e0f542fbfbfc4dc1171838de22369
SHA256: fa7f8430dda5abd6f3c7974d1fea6390de6bba9771acc15a86fbf7ab23244b0e
2564
GandCrab.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\gmp-widevinecdm\4.10.1440.18\widevinecdm.dll.lib
––
MD5:  ––
SHA256:  ––
2564
GandCrab.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\gmp-widevinecdm\4.10.1440.18\manifest.json.uapro
binary
MD5: e1ed39e3ea36a988012d0bdbdb3b5093
SHA256: 176f0f110cda77996e67bf51f568d04f042ac874398b1585aa44f83c885e01a5
2564
GandCrab.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\gmp-widevinecdm\4.10.1440.18\manifest.json
––
MD5:  ––
SHA256:  ––
2564
GandCrab.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\gmp-widevinecdm\4.10.1440.18\LICENSE.txt.uapro
binary
MD5: 8464bbc1cedeedf37bb474d813b01cf4
SHA256: 1a71ed0e192df8bd2f46f4128548b8564971290395f8752bc75feeb674ae8970
2564
GandCrab.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\gmp-widevinecdm\4.10.1440.18\LICENSE.txt
––
MD5:  ––
SHA256:  ––
2564
GandCrab.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\gmp-widevinecdm\4.10.1440.18\UAPRO-DECRYPT.html
html
MD5: 08c2da0ed1a1bf7ef89f736b9ed43bd2
SHA256: f233665b765c8159f5d39d78e6947aa2a42a56de79e2ad94db7b9ab587038a29
2564
GandCrab.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\gmp-widevinecdm\UAPRO-DECRYPT.html
html
MD5: 08c2da0ed1a1bf7ef89f736b9ed43bd2
SHA256: f233665b765c8159f5d39d78e6947aa2a42a56de79e2ad94db7b9ab587038a29
2564
GandCrab.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\gmp-gmpopenh264\1.8.1\gmpopenh264.info.uapro
binary
MD5: 51c9aa7c603facc201eb4a1560f61bf1
SHA256: 698c36378b0ca2e55f660b57c73623eeb505f9261b84379f678d1d5569f45c15
2564
GandCrab.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\gmp-gmpopenh264\1.8.1\gmpopenh264.info
––
MD5:  ––
SHA256:  ––
2564
GandCrab.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\gmp-gmpopenh264\UAPRO-DECRYPT.html
html
MD5: 08c2da0ed1a1bf7ef89f736b9ed43bd2
SHA256: f233665b765c8159f5d39d78e6947aa2a42a56de79e2ad94db7b9ab587038a29
2564
GandCrab.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\gmp\WINNT_x86-msvc\UAPRO-DECRYPT.html
html
MD5: 08c2da0ed1a1bf7ef89f736b9ed43bd2
SHA256: f233665b765c8159f5d39d78e6947aa2a42a56de79e2ad94db7b9ab587038a29
2564
GandCrab.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\gmp-gmpopenh264\1.8.1\UAPRO-DECRYPT.html
html
MD5: 08c2da0ed1a1bf7ef89f736b9ed43bd2
SHA256: f233665b765c8159f5d39d78e6947aa2a42a56de79e2ad94db7b9ab587038a29
2564
GandCrab.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\formhistory.sqlite.uapro
binary
MD5: 3c3a4d4e085beba95a618bcd996e0f56
SHA256: 5fcd49f0a1b713d977255fdf62bcbb80a4070d0e97e96e9712cb62ea58c534a9
2564
GandCrab.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\gmp\UAPRO-DECRYPT.html
html
MD5: 08c2da0ed1a1bf7ef89f736b9ed43bd2
SHA256: f233665b765c8159f5d39d78e6947aa2a42a56de79e2ad94db7b9ab587038a29
2564
GandCrab.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\formhistory.sqlite
––
MD5:  ––
SHA256:  ––
2564
GandCrab.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\features\{4b58246a-1239-4ff8-9650-839c3b3b38d1}\[email protected]
binary
MD5: e68dc6fbeefea8b6553346f9bd38b098
SHA256: 069dea078339f81a45c66c864cd5a41d21657b670781325cecea488279daa3c6
2564
GandCrab.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\features\{4b58246a-1239-4ff8-9650-839c3b3b38d1}\[email protected]
––
MD5:  ––
SHA256:  ––
2564
GandCrab.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\features\{4b58246a-1239-4ff8-9650-839c3b3b38d1}\UAPRO-DECRYPT.html
html
MD5: 08c2da0ed1a1bf7ef89f736b9ed43bd2
SHA256: f233665b765c8159f5d39d78e6947aa2a42a56de79e2ad94db7b9ab587038a29
2564
GandCrab.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\features\UAPRO-DECRYPT.html
html
MD5: 08c2da0ed1a1bf7ef89f736b9ed43bd2
SHA256: f233665b765c8159f5d39d78e6947aa2a42a56de79e2ad94db7b9ab587038a29
2564
GandCrab.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\favicons.sqlite
––
MD5:  ––
SHA256:  ––
2564
GandCrab.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\favicons.sqlite.uapro
––
MD5:  ––
SHA256:  ––
2564
GandCrab.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\extensions.json.uapro
binary
MD5: 216d6ec8926ea1b0ee62f878602f4d11
SHA256: 2d115744f860a8c19715136490825e917ff87b5676dab7264b8e469f97c5952e
2564
GandCrab.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\extensions.json
––
MD5:  ––
SHA256:  ––
2564
GandCrab.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\datareporting\state.json.uapro
binary
MD5: 69479e8732b389fbab82249c6f9fcd22
SHA256: ef74030bb67f870bc7ed8a93d12d2271ebc40be9dabf62ef2b52a417d25d6570
2564
GandCrab.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\extensions\[email protected]
binary
MD5: 107f2fc911f14b79ae7e37264ab41500
SHA256: d246f9b02b68016812f584c4436715af6b6221ea2145ee91caca8d1083c18384
2564
GandCrab.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\extensions\UAPRO-DECRYPT.html
html
MD5: 08c2da0ed1a1bf7ef89f736b9ed43bd2
SHA256: f233665b765c8159f5d39d78e6947aa2a42a56de79e2ad94db7b9ab587038a29
2564
GandCrab.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\extension-preferences.json.uapro
binary
MD5: 428e2a1617cd41f81fbc6f1a5783d4c0
SHA256: 90a75cc5e3e32ee1cdc244b1ee1779f5fbb68cdaf1468f6720f0f64fc8ea0ce8
2564
GandCrab.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\extensions\[email protected]
––
MD5:  ––
SHA256:  ––
2564
GandCrab.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\extension-preferences.json
––
MD5:  ––
SHA256:  ––
2564
GandCrab.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\datareporting\state.json
––
MD5:  ––
SHA256:  ––
2564
GandCrab.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\datareporting\session-state.json.uapro
binary
MD5: e1022a47d0f4d4917edf15f70dc2e03a
SHA256: 0e38613782c6019342e9ca022abd34bb8a7dce4c938311566f1c72cd682fa663
2564
GandCrab.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\datareporting\session-state.json
––
MD5:  ––
SHA256:  ––
2564
GandCrab.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\datareporting\archived\2019-07\1564489328393.3f4804cb-d877-4063-abdc-f5e3f580401d.main.jsonlz4.uapro
binary
MD5: 4e936be017193c2aaa4f1bf5ada72495
SHA256: bf938327eb563d33f53893f635c89f9618ae9ee03527bdd33e822b2327366b19
2564
GandCrab.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\datareporting\archived\2019-07\1564489328393.3f4804cb-d877-4063-abdc-f5e3f580401d.main.jsonlz4
––
MD5:  ––
SHA256:  ––
2564
GandCrab.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\datareporting\archived\2019-07\1564489249225.a92b2aef-2c4e-4d52-9046-dcf175c80123.main.jsonlz4.uapro
binary
MD5: 420ef56b724a48b8d36f829f301e9163
SHA256: 090b0c1566f8fb33222222d1a094c29bcb7ea91923483c5b42802844e78e5557
2564
GandCrab.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\datareporting\archived\2019-07\1564489249225.a92b2aef-2c4e-4d52-9046-dcf175c80123.main.jsonlz4
––
MD5:  ––
SHA256:  ––
2564
GandCrab.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\datareporting\archived\2019-07\1564489249221.feb02130-0f1b-4e29-becb-75b2179f799f.event.jsonlz4.uapro
binary
MD5: d461955e131a7f1c3a09e401a3a16c43
SHA256: d07c8a4c1c3d93075c4566e66fd36d3abd4ea8ae361477a47b1e187e5e1ab632
2564
GandCrab.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\datareporting\archived\2019-07\1564489249221.feb02130-0f1b-4e29-becb-75b2179f799f.event.jsonlz4
––
MD5:  ––
SHA256:  ––
2564
GandCrab.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\datareporting\archived\2019-07\1564489117933.97c72624-b217-49c1-8bc5-dea28b6a31e8.main.jsonlz4.uapro
binary
MD5: 836d4f9675253edae5132b6fd5cc57dd
SHA256: 1cf94653cfae4a9633fecd8c176b244094b8a7f1de275c990aaed7bfdd4eac5b
2564
GandCrab.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\datareporting\archived\2019-07\1564489117933.97c72624-b217-49c1-8bc5-dea28b6a31e8.main.jsonlz4
––
MD5:  ––
SHA256:  ––
2564
GandCrab.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\datareporting\archived\2019-07\1564489117919.9f39e360-06c8-4521-aa00-735686700748.health.jsonlz4.uapro
binary
MD5: fef362bbedea424d22a90844257893c2
SHA256: 08a6f4089a76cb72021182c5fa6e861cb401978d40e34857d1052b85790ea362
2564
GandCrab.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\datareporting\archived\2019-07\1564489117919.9f39e360-06c8-4521-aa00-735686700748.health.jsonlz4
––
MD5:  ––
SHA256:  ––
2564
GandCrab.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\datareporting\archived\2019-07\1564489117913.739f347a-1567-472c-be60-106be3bf6422.event.jsonlz4.uapro
binary
MD5: b0b836ad003dcd8d296697d560196a33
SHA256: b1e58d892ae1577dde8a8adf6b8e72f08d6f0ed7776dabe9e5f6902952c47ff6
2564
GandCrab.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\datareporting\archived\2019-07\1564489117913.739f347a-1567-472c-be60-106be3bf6422.event.jsonlz4
––
MD5:  ––
SHA256:  ––
2564
GandCrab.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\datareporting\archived\2019-07\1564489117889.a980eee7-59fe-44ed-8591-082294c7a32d.health.jsonlz4.uapro
binary
MD5: aef13aca1255967bb04833399af7d6a5
SHA256: 6a2f731a7b3ada55e9f8acadbcbed2dc43d8a8165ab538c37e1f42134e383961
2564
GandCrab.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\datareporting\archived\2019-07\1564489117889.a980eee7-59fe-44ed-8591-082294c7a32d.health.jsonlz4
––
MD5:  ––
SHA256:  ––
2564
GandCrab.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\datareporting\archived\2019-07\1564489065385.08756e3c-ce88-4cbc-94d7-e48f27235c82.main.jsonlz4.uapro
binary
MD5: 7db7dc5a17c1511f3335b092c77b27e1
SHA256: 5d53061d2000bbdb52c026982e72f1824a8ad4c4c9880a37db22f84fe179e769
2564
GandCrab.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\datareporting\archived\2019-07\1564489065385.08756e3c-ce88-4cbc-94d7-e48f27235c82.main.jsonlz4
––
MD5:  ––
SHA256:  ––
2564
GandCrab.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\datareporting\archived\2019-07\1564489065373.db607edd-7987-4569-a8ce-b9b5ed3a350b.health.jsonlz4.uapro
binary
MD5: 784cefc6c477d3c4b30b12f799dd8542
SHA256: 93f83215455c17f518031a8e96f6b4a48a03f6f869a270db468c9fe064a4bbf3
2564
GandCrab.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\datareporting\archived\2019-07\1564489065373.db607edd-7987-4569-a8ce-b9b5ed3a350b.health.jsonlz4
––
MD5:  ––
SHA256:  ––
2564
GandCrab.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\datareporting\archived\2019-07\1564489065345.424f95b4-752b-41ba-a808-cd75fbda007e.health.jsonlz4.uapro
binary
MD5: ef0e0941305f0f243acf32c3f30c6f94
SHA256: 0e5f3e5cb840639264768404e2b18487e0f5144375ff2ec27c46e1299bf06eca
2564
GandCrab.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\datareporting\archived\2019-07\1564489065345.424f95b4-752b-41ba-a808-cd75fbda007e.health.jsonlz4
––
MD5:  ––
SHA256:  ––
2564
GandCrab.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\datareporting\archived\2019-07\1564489038214.adc0101b-f9fb-4d68-96fa-60bbb3e11110.update.jsonlz4.uapro
binary
MD5: 5103415feb6d945b678a2222654f0f32
SHA256: f4bc9f43f282a75188960e134d385bf0107ca0be50df9ddd803e33a4b0767449
2564
GandCrab.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\datareporting\archived\2019-07\1564489038214.adc0101b-f9fb-4d68-96fa-60bbb3e11110.update.jsonlz4
––
MD5:  ––
SHA256:  ––
2564
GandCrab.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\datareporting\archived\2019-07\1564489012007.ce5a9275-0b08-4ba0-8072-4a3c8feff016.main.jsonlz4.uapro
binary
MD5: 1bd20b586888764df96dc7bd56600b7c
SHA256: 72cc12c05128c8c7209856e50ca9c1fe65e4e2bfe87fd190d453a4c57ec7243b
2564
GandCrab.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\datareporting\archived\2019-07\1564489012007.ce5a9275-0b08-4ba0-8072-4a3c8feff016.main.jsonlz4
––
MD5:  ––
SHA256:  ––
2564
GandCrab.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\datareporting\archived\2019-07\1564489011998.a8968e24-bce9-483e-ac8f-6d6bfdfb0534.event.jsonlz4.uapro
binary
MD5: bdb61c4f72dd8371fbd596fbe1580506
SHA256: 285ec118f22b4d180efbe3dc7dda87684732bbd9a9f21928c00bcd13c69e84cd
2564
GandCrab.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\datareporting\archived\2019-07\1564489011998.a8968e24-bce9-483e-ac8f-6d6bfdfb0534.event.jsonlz4
––
MD5:  ––
SHA256:  ––
2564
GandCrab.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\datareporting\archived\2019-07\1564489010911.182cd932-ef00-4581-9f85-b7d7c67e23da.update.jsonlz4.uapro
binary
MD5: d27910166d3fd3dc84c93d6f4075d310
SHA256: 298006eb16857e7c54ac279667e41111d000e880ba9a2d43822f50c49b7f0d65
2564
GandCrab.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\datareporting\archived\2019-07\1564489010911.182cd932-ef00-4581-9f85-b7d7c67e23da.update.jsonlz4
––
MD5:  ––
SHA256:  ––
2564
GandCrab.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\datareporting\archived\2019-07\1564488890786.34b7973e-79df-4cf9-b43f-e66315cb6e28.modules.jsonlz4.uapro
binary
MD5: 1d5e0cae1fb4883663b09db17705a686
SHA256: a7db91f8131bcf93a6c3bdf74a8f410a2144c0cb11f894da588978c0708ff092
2564
GandCrab.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\datareporting\archived\2019-07\1564488890786.34b7973e-79df-4cf9-b43f-e66315cb6e28.modules.jsonlz4
––
MD5:  ––
SHA256:  ––
2564
GandCrab.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\datareporting\archived\2019-07\1564488772052.dfa0fcf4-a4c4-47cd-a061-4eb83e3360d3.shield-study.jsonlz4.uapro
binary
MD5: e40d4298a43be69849efcadbc7a2af3d
SHA256: c5fcf13076ec8f324b5c7e8d8693e05a708713034bd991d5bdcb46454f6483da
2564
GandCrab.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\datareporting\archived\2019-07\1564488772052.dfa0fcf4-a4c4-47cd-a061-4eb83e3360d3.shield-study.jsonlz4
––
MD5:  ––
SHA256:  ––
2564
GandCrab.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\datareporting\archived\2019-07\1564488772011.bc363b26-d4aa-47b2-9f2c-09728d0ccbfd.shield-study.jsonlz4.uapro
binary
MD5: 28debc3d2f3151cdf8b4aa5751186728
SHA256: 2ee1abab9006a823cb88a07ea62aea592fe008e4709c379ad7adc3068065c41e
2564
GandCrab.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\datareporting\archived\2019-07\1564488772011.bc363b26-d4aa-47b2-9f2c-09728d0ccbfd.shield-study.jsonlz4
––
MD5:  ––
SHA256:  ––
2564
GandCrab.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\datareporting\archived\2019-07\1564488717211.098e82d6-cb9b-4c2b-a1ba-508693b17b43.main.jsonlz4.uapro
binary
MD5: 8b132a856627ab361669dea616f75531
SHA256: 8a9b4b5312f971ea2fa600aadae3307de3e31383e23da67d4dac2e464583e1a3
2564
GandCrab.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\datareporting\archived\2019-07\1564488717211.098e82d6-cb9b-4c2b-a1ba-508693b17b43.main.jsonlz4
––
MD5:  ––
SHA256:  ––
2564
GandCrab.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\datareporting\archived\2019-07\1564488717154.f4d74e79-28d9-4b33-83da-e607069bf534.health.jsonlz4.uapro
binary
MD5: 4789a0e78a1ef3150b38a152a51cfeb8
SHA256: 25dd710e73c5afe0a224f5e8c6a373ff481e4bbdfc06bfdc56901f88c8193ec0
2564
GandCrab.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\datareporting\archived\2019-07\1564488717154.f4d74e79-28d9-4b33-83da-e607069bf534.health.jsonlz4
––
MD5:  ––
SHA256:  ––
2564
GandCrab.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\datareporting\archived\2019-07\1564488638334.d86fec5f-6877-414d-9df1-62f73d84c019.health.jsonlz4.uapro
binary
MD5: c9ee91225884d8493ec8168b28c80e3d
SHA256: 396b92f1c8edab95d7c9ad5c67078dcb9c61a1186010f79d29d95add60181903
2564
GandCrab.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\datareporting\archived\2019-07\1564488638334.d86fec5f-6877-414d-9df1-62f73d84c019.health.jsonlz4
––
MD5:  ––
SHA256:  ––
2564
GandCrab.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\datareporting\archived\2019-07\1564488332028.48960396-b872-4de9-9242-7e3ccb6bf75a.main.jsonlz4.uapro
binary
MD5: afac86e1113c705b0153c24f075593fa
SHA256: 0287bfb9cf2ca8ca43ea4ea34c4d84fb59cc3887c8d21bb3c07e8a121900bf77
2564
GandCrab.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\datareporting\archived\2019-07\1564488332028.48960396-b872-4de9-9242-7e3ccb6bf75a.main.jsonlz4
––
MD5:  ––
SHA256:  ––
2564
GandCrab.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\datareporting\archived\2019-07\1564488332017.2d973f32-d1ac-4938-bc70-32bbfa9339c0.health.jsonlz4.uapro
binary
MD5: 45e7411f309e790bfe9636ff750770df
SHA256: 2a837b6bef3c40443618afd71a3b12200b8a630a6e7e3dc6f559e761069a0e96
2564
GandCrab.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\datareporting\archived\2019-07\1564488332017.2d973f32-d1ac-4938-bc70-32bbfa9339c0.health.jsonlz4
––
MD5:  ––
SHA256:  ––
2564
GandCrab.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\datareporting\archived\2019-07\1564488331980.5c92012e-2fb9-4cea-a2b2-5f3d67d807a8.health.jsonlz4.uapro
binary
MD5: 8a0d50093165f3b57114a71a2472d5ff
SHA256: 19d904efd2f21b626d9c46dd64205f2c8defc4d55fff80fe38f01005037daae3
2564
GandCrab.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\datareporting\archived\2019-07\1564488331980.5c92012e-2fb9-4cea-a2b2-5f3d67d807a8.health.jsonlz4
––
MD5:  ––
SHA256:  ––
2564
GandCrab.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\datareporting\archived\2019-07\1564488326995.493b4ce8-0b50-4e70-bb3c-ef7fae356825.main.jsonlz4.uapro
binary
MD5: ba882451e0702fd39dd52e5000565c5c
SHA256: 5d5e2a97e1472d755e00f7d21b8d026ca10fd0dc1719314e0595d3b94195c073
2564
GandCrab.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\datareporting\archived\2019-07\1564488326995.493b4ce8-0b50-4e70-bb3c-ef7fae356825.main.jsonlz4
––
MD5:  ––
SHA256:  ––
2564
GandCrab.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\datareporting\archived\2019-07\1564488326987.0e5bb481-b7c5-49f7-b38f-8d19aaac0efb.health.jsonlz4.uapro
binary
MD5: 4f1ba7fd22b7214b63266127667ecda8
SHA256: 495d8264b7dde15aa687a4d4cb77cbbbe8b8a55e4dcfe03bd5088ca84eda2daf
2564
GandCrab.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\datareporting\archived\2019-07\1564488326987.0e5bb481-b7c5-49f7-b38f-8d19aaac0efb.health.jsonlz4
––
MD5:  ––
SHA256:  ––
2564
GandCrab.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\datareporting\archived\2019-07\1564488326977.f10a154d-ac52-4596-adfb-0e86dcf049be.event.jsonlz4.uapro
binary
MD5: 815735270704f02497dd5c366e9dac7f
SHA256: 6f171b049b863e247a7713063b18a139b099f31884b4ee8675119dd739856342
2564
GandCrab.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\datareporting\archived\2019-07\1564488326977.f10a154d-ac52-4596-adfb-0e86dcf049be.event.jsonlz4
––
MD5:  ––
SHA256:  ––
2564
GandCrab.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\datareporting\archived\2019-07\1564488314138.85453178-caec-4152-bf1c-f6cc6b4b10f9.health.jsonlz4.uapro
binary
MD5: add560dda56b47b6590422af19340cd7
SHA256: e1c58e483fbe937751c4e16af692fc86bb35955c02f8b5e052c26248675adecc
2564
GandCrab.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\datareporting\archived\2019-07\1564488314138.85453178-caec-4152-bf1c-f6cc6b4b10f9.health.jsonlz4
––
MD5:  ––
SHA256:  ––
2564
GandCrab.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\crashes\store.json.mozlz4.uapro
binary
MD5: 533d97965144ea17dc795d30b78aef5d
SHA256: 8fcd22ed1cbd93db419b4387a60554bb40e3aa0fe74e530eed6dab1a6e1fc79b
2564
GandCrab.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\datareporting\UAPRO-DECRYPT.html
html
MD5: 08c2da0ed1a1bf7ef89f736b9ed43bd2
SHA256: f233665b765c8159f5d39d78e6947aa2a42a56de79e2ad94db7b9ab587038a29
2564
GandCrab.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\datareporting\archived\UAPRO-DECRYPT.html
html
MD5: 08c2da0ed1a1bf7ef89f736b9ed43bd2
SHA256: f233665b765c8159f5d39d78e6947aa2a42a56de79e2ad94db7b9ab587038a29
2564
GandCrab.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\datareporting\archived\2019-07\UAPRO-DECRYPT.html
html
MD5: 08c2da0ed1a1bf7ef89f736b9ed43bd2
SHA256: f233665b765c8159f5d39d78e6947aa2a42a56de79e2ad94db7b9ab587038a29
2564
GandCrab.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\crashes\store.json.mozlz4
––
MD5:  ––
SHA256:  ––
2564
GandCrab.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\cookies.sqlite.uapro
binary
MD5: 32ce927b8e4ce86c1056dec2937fd554
SHA256: 32c05b73315b9132fe97668b1acf3117d7edc92669ea6666fc2155373bb2b190
2564
GandCrab.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\crashes\events\UAPRO-DECRYPT.html
html
MD5: 08c2da0ed1a1bf7ef89f736b9ed43bd2
SHA256: f233665b765c8159f5d39d78e6947aa2a42a56de79e2ad94db7b9ab587038a29
2564
GandCrab.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\crashes\UAPRO-DECRYPT.html
html
MD5: 08c2da0ed1a1bf7ef89f736b9ed43bd2
SHA256: f233665b765c8159f5d39d78e6947aa2a42a56de79e2ad94db7b9ab587038a29
2564
GandCrab.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\cookies.sqlite
––
MD5:  ––
SHA256:  ––
2564
GandCrab.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\content-prefs.sqlite.uapro
binary
MD5: 5ecce3cad00f9068ec518d85fdaedca3
SHA256: 7c2e61a147783d5b05b8d41167b6b7a3509438467006d06e2ecdc6526fc08e9f
2564
GandCrab.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\content-prefs.sqlite
––
MD5:  ––
SHA256:  ––
2564
GandCrab.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\containers.json.uapro
binary
MD5: 2af99c4fd286c04e07ae8b0a4b7cb691
SHA256: 224ede01f60f5807c7c230118276869e09101afb66e3663d5a6b98b80f3bd84c
2564
GandCrab.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\containers.json
––
MD5:  ––
SHA256:  ––
2564
GandCrab.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\compatibility.ini.uapro
binary
MD5: 681e3d7f7931671ab669b9fc0dd78c4f
SHA256: 597dca1da20dc775a1cfb7ccdb90e6d128a08795724a559316bd0462ec8328c8
2564
GandCrab.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\compatibility.ini
––
MD5:  ––
SHA256:  ––
2564
GandCrab.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\cert9.db.uapro
vc
MD5: 98756c1618114eecce8495182007c69b
SHA256: e8d16cc53e66346d5d7429b3619fafdd929ebaeb3bd93da3b727b1fe961270a9
2564
GandCrab.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\cert9.db
––
MD5:  ––
SHA256:  ––
2564
GandCrab.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\broadcast-listeners.json.uapro
binary
MD5: 857df3af9963ece47c5a5626c7ac732a
SHA256: a5b6ba46d580e08cc680f2913dc193270b9493935df4c252a2ac65c0fd14ec02
2564
GandCrab.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\broadcast-listeners.json
––
MD5:  ––
SHA256:  ––
2564
GandCrab.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\bookmarkbackups\bookmarks-2019-07-30_14_uZyx1cMFmZ7ZpL4NneCk2A==.jsonlz4.uapro
binary
MD5: 251bdf83ab038ee5909e92fcaaedc5c9
SHA256: b05482b7e42ea80179ec9769e5e852b73d8a02e5c87ee86ca806f23e9669b7d4
2564
GandCrab.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\bookmarkbackups\bookmarks-2019-07-30_14_uZyx1cMFmZ7ZpL4NneCk2A==.jsonlz4
––
MD5:  ––
SHA256:  ––
2564
GandCrab.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\blocklist.xml.uapro
binary
MD5: 3690dfdf427eb47ed9371e5288090742
SHA256: 4c792af80e9797c91514dbfef008d77f4e2006b5c51a0ce1e773bb5f01eb5f64
2564
GandCrab.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\bookmarkbackups\UAPRO-DECRYPT.html
html
MD5: 08c2da0ed1a1bf7ef89f736b9ed43bd2
SHA256: f233665b765c8159f5d39d78e6947aa2a42a56de79e2ad94db7b9ab587038a29
2564
GandCrab.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\blocklist.xml
––
MD5:  ––
SHA256:  ––
2564
GandCrab.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\addonStartup.json.lz4.uapro
binary
MD5: e2c3bb63c2b04de81ced79b1f0609acc
SHA256: e3724255b452e7c58589ea28422788aa325db61243ffe20a20acbdad7cbf6a43
2564
GandCrab.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\addonStartup.json.lz4
––
MD5:  ––
SHA256:  ––
2564
GandCrab.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\addons.json.uapro
binary
MD5: dba3d454790f1836c914154b7458e51d
SHA256: c3f1cf452846e9b1f9f6f1a1ec607349383de166b725e78cf644709f1d695d4f
2564
GandCrab.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\addons.json
––
MD5:  ––
SHA256:  ––
2564
GandCrab.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\UAPRO-DECRYPT.html
html
MD5: 08c2da0ed1a1bf7ef89f736b9ed43bd2
SHA256: f233665b765c8159f5d39d78e6947aa2a42a56de79e2ad94db7b9ab587038a29
2564
GandCrab.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Pending Pings\UAPRO-DECRYPT.html
html
MD5: 08c2da0ed1a1bf7ef89f736b9ed43bd2
SHA256: f233665b765c8159f5d39d78e6947aa2a42a56de79e2ad94db7b9ab587038a29
2564
GandCrab.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\UAPRO-DECRYPT.html
html
MD5: 08c2da0ed1a1bf7ef89f736b9ed43bd2
SHA256: f233665b765c8159f5d39d78e6947aa2a42a56de79e2ad94db7b9ab587038a29
2564
GandCrab.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Crash Reports\InstallTime20190717172542.uapro
ini
MD5: 250520712d0a9d07a7d958aced695a25
SHA256: 74fbe2de9685c2604c2da30c2ee04902508ed0ef5656304c82fe71c5b16729ea
2564
GandCrab.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\installs.ini.uapro
binary
MD5: c46ec453455b273cf4f516f6fc56e287
SHA256: 3683a33b77fbd926297e146b21211d9a60cf2f091fdef4572630a8a2ae93e7cd
2564
GandCrab.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\installs.ini
––
MD5:  ––
SHA256:  ––
2564
GandCrab.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Crash Reports\InstallTime20190225143501.uapro
binary
MD5: c808480709a8a5a1c090921337f009d7
SHA256: bfdd5fa0532383218642d68e10da088f7939d68b79ca5afe3eee1f30e5968859
2564
GandCrab.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Crash Reports\InstallTime20180807170231.uapro
binary
MD5: 5d467f093beba70e9b92e0a4c42e078d
SHA256: 2793552de10045a083fe4560b5eba7f48d8f4453eb5b57b05b0be2081a3af966
2564
GandCrab.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Crash Reports\InstallTime20190619235627.uapro
binary
MD5: 32f378885053e16ae5c63a6b3fc99174
SHA256: 0d4959d74d434e9b6ce96bfa5c8906677e5c8e8f0fb5b2da0c2c7289ee464710
2564
GandCrab.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Crash Reports\InstallTime20190225143501
––
MD5:  ––
SHA256:  ––
2564
GandCrab.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Crash Reports\InstallTime20190717172542
––
MD5:  ––
SHA256:  ––
2564
GandCrab.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Crash Reports\InstallTime20180807170231
––
MD5:  ––
SHA256:  ––
2564
GandCrab.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Crash Reports\InstallTime20190619235627
––
MD5:  ––
SHA256:  ––
2564
GandCrab.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Crash Reports\events\UAPRO-DECRYPT.html
html
MD5: 08c2da0ed1a1bf7ef89f736b9ed43bd2
SHA256: f233665b765c8159f5d39d78e6947aa2a42a56de79e2ad94db7b9ab587038a29
2564
GandCrab.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Crash Reports\UAPRO-DECRYPT.html
html
MD5: 08c2da0ed1a1bf7ef89f736b9ed43bd2
SHA256: f233665b765c8159f5d39d78e6947aa2a42a56de79e2ad94db7b9ab587038a29
2564
GandCrab.exe
C:\Users\admin\AppData\Roaming\Microsoft\Templates\NormalEmail.dotm.uapro
binary
MD5: 60bb40aa38ad8225bf3b4d7a44ce904e
SHA256: aa403a7748a41850cae35daa5f75b023dc2432fdd18c0e412a071707fd0f02c7
2564
GandCrab.exe
C:\Users\admin\AppData\Roaming\Microsoft\UProof\CUSTOM.DIC.uapro
binary
MD5: ffb4bb0cf83fd74f90d9d0578cec74c8
SHA256: 5b31212787f5fb015df215d1e28e13d267c12b2b1b8ab02c5a5104672453b1c0
2564
GandCrab.exe
C:\Users\admin\AppData\Roaming\Mozilla\UAPRO-DECRYPT.html
html
MD5: 08c2da0ed1a1bf7ef89f736b9ed43bd2
SHA256: f233665b765c8159f5d39d78e6947aa2a42a56de79e2ad94db7b9ab587038a29
2564
GandCrab.exe
C:\Users\admin\AppData\Roaming\Microsoft\UProof\UAPRO-DECRYPT.html
html
MD5: 08c2da0ed1a1bf7ef89f736b9ed43bd2
SHA256: f233665b765c8159f5d39d78e6947aa2a42a56de79e2ad94db7b9ab587038a29
2564
GandCrab.exe
C:\Users\admin\AppData\Roaming\Microsoft\Word\STARTUP\UAPRO-DECRYPT.html
html
MD5: 08c2da0ed1a1bf7ef89f736b9ed43bd2
SHA256: f233665b765c8159f5d39d78e6947aa2a42a56de79e2ad94db7b9ab587038a29
2564
GandCrab.exe
C:\Users\admin\AppData\Roaming\Microsoft\Word\UAPRO-DECRYPT.html
html
MD5: 08c2da0ed1a1bf7ef89f736b9ed43bd2
SHA256: f233665b765c8159f5d39d78e6947aa2a42a56de79e2ad94db7b9ab587038a29
2564
GandCrab.exe
C:\Users\admin\AppData\Roaming\Mozilla\Extensions\UAPRO-DECRYPT.html
html
MD5: 08c2da0ed1a1bf7ef89f736b9ed43bd2
SHA256: f233665b765c8159f5d39d78e6947aa2a42a56de79e2ad94db7b9ab587038a29
2564
GandCrab.exe
C:\Users\admin\AppData\Roaming\Microsoft\Vault\UAPRO-DECRYPT.html
html
MD5: 08c2da0ed1a1bf7ef89f736b9ed43bd2
SHA256: f233665b765c8159f5d39d78e6947aa2a42a56de79e2ad94db7b9ab587038a29
2564
GandCrab.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\UAPRO-DECRYPT.html
html
MD5: 08c2da0ed1a1bf7ef89f736b9ed43bd2
SHA256: f233665b765c8159f5d39d78e6947aa2a42a56de79e2ad94db7b9ab587038a29
2564
GandCrab.exe
C:\Users\admin\AppData\Roaming\Microsoft\Templates\NormalEmail.dotm
––
MD5:  ––
SHA256:  ––
2564
GandCrab.exe
C:\Users\admin\AppData\Roaming\Microsoft\UProof\CUSTOM.DIC
––
MD5:  ––
SHA256:  ––
2564
GandCrab.exe
C:\Users\admin\AppData\Roaming\Microsoft\Templates\Normal.dotm.uapro
binary
MD5: 2d7a72c49d365660310246393ac38585
SHA256: dd6f8a39892d389a6564887b43e0302fcc61207778c91172ec5c03f3d4bdff72
2564
GandCrab.exe
C:\Users\admin\AppData\Roaming\Microsoft\SystemCertificates\My\Keys\UAPRO-DECRYPT.html
html
MD5: 08c2da0ed1a1bf7ef89f736b9ed43bd2
SHA256: f233665b765c8159f5d39d78e6947aa2a42a56de79e2ad94db7b9ab587038a29
2564
GandCrab.exe
C:\Users\admin\AppData\Roaming\Microsoft\Templates\LiveContent\Managed\Access Parts\1033\UAPRO-DECRYPT.html
html
MD5: 08c2da0ed1a1bf7ef89f736b9ed43bd2
SHA256: f233665b765c8159f5d39d78e6947aa2a42a56de79e2ad94db7b9ab587038a29
2564
GandCrab.exe
C:\Users\admin\AppData\Roaming\Microsoft\Templates\UAPRO-DECRYPT.html
html
MD5: 08c2da0ed1a1bf7ef89f736b9ed43bd2
SHA256: f233665b765c8159f5d39d78e6947aa2a42a56de79e2ad94db7b9ab587038a29
2564
GandCrab.exe
C:\Users\admin\AppData\Roaming\Microsoft\SystemCertificates\My\Keys\ECCD4BA46722CB4F92060701865DDF09D8AF68B4.uapro
flc
MD5: 5e2474e7f685489d0d05d94f7d190450
SHA256: e0d6cedaf6c85a6ec486070699f535707107cef6e98ccb1d76b7697307eb4ae2
2564
GandCrab.exe
C:\Users\admin\AppData\Roaming\Microsoft\Templates\LiveContent\UAPRO-DECRYPT.html
html
MD5: 08c2da0ed1a1bf7ef89f736b9ed43bd2
SHA256: f233665b765c8159f5d39d78e6947aa2a42a56de79e2ad94db7b9ab587038a29
2564
GandCrab.exe
C:\Users\admin\AppData\Roaming\Microsoft\Templates\LiveContent\Managed\UAPRO-DECRYPT.html
html
MD5: 08c2da0ed1a1bf7ef89f736b9ed43bd2
SHA256: f233665b765c8159f5d39d78e6947aa2a42a56de79e2ad94db7b9ab587038a29
2564
GandCrab.exe
C:\Users\admin\AppData\Roaming\Microsoft\Templates\LiveContent\Managed\Access Parts\UAPRO-DECRYPT.html
html
MD5: 08c2da0ed1a1bf7ef89f736b9ed43bd2
SHA256: f233665b765c8159f5d39d78e6947aa2a42a56de79e2ad94db7b9ab587038a29
2564
GandCrab.exe
C:\Users\admin\AppData\Roaming\Microsoft\SystemCertificates\My\Keys\ECCD4BA46722CB4F92060701865DDF09D8AF68B4
––
MD5:  ––
SHA256:  ––
2564
GandCrab.exe
C:\Users\admin\AppData\Roaming\Microsoft\Templates\Normal.dotm
––
MD5:  ––
SHA256:  ––
2564
GandCrab.exe
C:\Users\admin\AppData\Roaming\Microsoft\Stationery\UAPRO-DECRYPT.html
html
MD5: 08c2da0ed1a1bf7ef89f736b9ed43bd2
SHA256: f233665b765c8159f5d39d78e6947aa2a42a56de79e2ad94db7b9ab587038a29
2564
GandCrab.exe
C:\Users\admin\AppData\Roaming\Microsoft\SystemCertificates\My\Certificates\E02357FC7708441D4B0BE5F371F4B28961870F70.uapro
binary
MD5: 37ea13da56be441cfe328cc2309bdd93
SHA256: 5031f69d4920a13d082dbfa4107faec25d80d961e05043878cde2b8657977c36
2564
GandCrab.exe
C:\Users\admin\AppData\Roaming\Microsoft\SystemCertificates\My\CRLs\UAPRO-DECRYPT.html
html
MD5: 08c2da0ed1a1bf7ef89f736b9ed43bd2
SHA256: f233665b765c8159f5d39d78e6947aa2a42a56de79e2ad94db7b9ab587038a29
2564
GandCrab.exe
C:\Users\admin\AppData\Roaming\Microsoft\SystemCertificates\My\Certificates\UAPRO-DECRYPT.html
html
MD5: 08c2da0ed1a1bf7ef89f736b9ed43bd2
SHA256: f233665b765c8159f5d39d78e6947aa2a42a56de79e2ad94db7b9ab587038a29
2564
GandCrab.exe
C:\Users\admin\AppData\Roaming\Microsoft\Speech\UAPRO-DECRYPT.html
html
MD5: 08c2da0ed1a1bf7ef89f736b9ed43bd2
SHA256: f233665b765c8159f5d39d78e6947aa2a42a56de79e2ad94db7b9ab587038a29
2564
GandCrab.exe
C:\Users\admin\AppData\Roaming\Microsoft\SystemCertificates\My\UAPRO-DECRYPT.html
html
MD5: 08c2da0ed1a1bf7ef89f736b9ed43bd2
SHA256: f233665b765c8159f5d39d78e6947aa2a42a56de79e2ad94db7b9ab587038a29
2564
GandCrab.exe
C:\Users\admin\AppData\Roaming\Microsoft\SystemCertificates\My\CTLs\UAPRO-DECRYPT.html
html
MD5: 08c2da0ed1a1bf7ef89f736b9ed43bd2
SHA256: f233665b765c8159f5d39d78e6947aa2a42a56de79e2ad94db7b9ab587038a29
2564
GandCrab.exe
C:\Users\admin\AppData\Roaming\Microsoft\SystemCertificates\UAPRO-DECRYPT.html
html
MD5: 08c2da0ed1a1bf7ef89f736b9ed43bd2
SHA256: f233665b765c8159f5d39d78e6947aa2a42a56de79e2ad94db7b9ab587038a29
2564
GandCrab.exe
C:\Users\admin\AppData\Roaming\Microsoft\Skype for Desktop\skylib\slimcore-0-4223384469.blog.uapro
binary
MD5: e3f624ca092329c2bd92d8dcac8aadae
SHA256: 63f428aa6e8853f404dd3fb3a8dd74c9e5ec82f41664df8045792c8a3419170c
2564
GandCrab.exe
C:\Users\admin\AppData\Roaming\Microsoft\SystemCertificates\My\Certificates\E02357FC7708441D4B0BE5F371F4B28961870F70
––
MD5:  ––
SHA256:  ––
2564
GandCrab.exe
C:\Users\admin\AppData\Roaming\Microsoft\Skype for Desktop\skylib\shared.xml.uapro
binary
MD5: e6f8c634b47a8a084d1ec9fec115373e
SHA256: 41dc695be0c87fbdcd65321c49cb31bc1826b2aaa708a5ba6e3c42eb2052d461
2564
GandCrab.exe
C:\Users\admin\AppData\Roaming\Microsoft\Skype for Desktop\skylib\live#3agabriel.radrigos\main.db-journal.uapro
binary
MD5: 5980273a84d58e2cd63f57de9212befe
SHA256: 6eb7e50531fd84012b54a426e41f87dd4dc33809daae05ce824ea04f13de1946
2564
GandCrab.exe
C:\Users\admin\AppData\Roaming\Microsoft\Skype for Desktop\skylib\shared.xml
––
MD5:  ––
SHA256:  ––
2564
GandCrab.exe
C:\Users\admin\AppData\Roaming\Microsoft\Skype for Desktop\skylib\slimcore-0-4223384469.blog
––
MD5:  ––
SHA256:  ––
2564
GandCrab.exe
C:\Users\admin\AppData\Roaming\Microsoft\Skype for Desktop\skylib\live#3agabriel.radrigos\main.db-journal
––
MD5:  ––
SHA256:  ––
2564
GandCrab.exe
C:\Users\admin\AppData\Roaming\Microsoft\Skype for Desktop\skylib\live#3agabriel.radrigos\main.db.uapro
binary
MD5: 9e0b770f449c3d4ada3a7bf424b44232
SHA256: 14ce32de24d48cd4ab61642aa04ff890b3c9c3d8daf902681c4fb9f21119a04d
2564
GandCrab.exe
C:\Users\admin\AppData\Roaming\Microsoft\Skype for Desktop\skylib\live#3agabriel.radrigos\config.xml.uapro
binary
MD5: faccac3a4ca5163ca906c78b8e12da7a
SHA256: 98fae68f9794a276b6abc06146bf021a9deb804399c01c7f390643208715f0a0
2564
GandCrab.exe
C:\Users\admin\AppData\Roaming\Microsoft\Skype for Desktop\skylib\live#3agabriel.radrigos\config.xml
––
MD5:  ––
SHA256:  ––
2564
GandCrab.exe
C:\Users\admin\AppData\Roaming\Microsoft\Skype for Desktop\skylib\live#3agabriel.radrigos\main.db
––
MD5:  ––
SHA256:  ––
2564
GandCrab.exe
C:\Users\admin\AppData\Roaming\Microsoft\Skype for Desktop\skylib\DataRv\offline-storage.data-wal.uapro
binary
MD5: 2c4fe2f52ff1ca1919222e2106b07fff
SHA256: 7a311b64cd1d52bfa73eb5a619f96faea3c557f6a062a4cd4ae7e5b5778989fd
2564
GandCrab.exe
C:\Users\admin\AppData\Roaming\Microsoft\Skype for Desktop\skylib\live#3agabriel.radrigos\UAPRO-DECRYPT.html
html
MD5: 08c2da0ed1a1bf7ef89f736b9ed43bd2
SHA256: f233665b765c8159f5d39d78e6947aa2a42a56de79e2ad94db7b9ab587038a29
2564
GandCrab.exe
C:\Users\admin\AppData\Roaming\Microsoft\Skype for Desktop\skylib\DataRv\offline-storage.data-wal
––
MD5:  ––
SHA256:  ––
2564
GandCrab.exe
C:\Users\admin\AppData\Roaming\Microsoft\Skype for Desktop\skylib\DataRv\offline-storage.data.uapro
binary
MD5: cbff31f4d18c8b753ff36da3296f17ae
SHA256: 8c437bd4481c13547f535feec7577349ae04321b8eacffb7dfb73bd10dd13741
2564
GandCrab.exe
C:\Users\admin\AppData\Roaming\Microsoft\Skype for Desktop\skylib\DataRv\offline-storage.data-shm.uapro
binary
MD5: e811700bec36b5a181b55c84faf35801
SHA256: 9058100845011b2af34c78763b2f7d92faa82639209d8a208933c06a4e70ea99
2564
GandCrab.exe
C:\Users\admin\AppData\Roaming\Microsoft\Skype for Desktop\skylib\DataRv\offline-storage.data
––
MD5:  ––
SHA256:  ––
2564
GandCrab.exe
C:\Users\admin\AppData\Roaming\Microsoft\Skype for Desktop\skylib\DataRv\offline-storage.data-shm
––
MD5:  ––
SHA256:  ––
2564
GandCrab.exe
C:\Users\admin\AppData\Roaming\Microsoft\Skype for Desktop\QuotaManager.uapro
binary
MD5: 608d8c2ccac593804769ae2fbe3cc3d9
SHA256: 7f56eb1705f92284485ae0af61164bf0a2c3658a41fec94c97ffbf6a35810992
2564
GandCrab.exe
C:\Users\admin\AppData\Roaming\Microsoft\Skype for Desktop\skylib\DataRv\UAPRO-DECRYPT.html
html
MD5: 08c2da0ed1a1bf7ef89f736b9ed43bd2
SHA256: f233665b765c8159f5d39d78e6947aa2a42a56de79e2ad94db7b9ab587038a29
2564
GandCrab.exe
C:\Users\admin\AppData\Roaming\Microsoft\Skype for Desktop\skylib\UAPRO-DECRYPT.html
html
MD5: 08c2da0ed1a1bf7ef89f736b9ed43bd2
SHA256: f233665b765c8159f5d39d78e6947aa2a42a56de79e2ad94db7b9ab587038a29
2564
GandCrab.exe
C:\Users\admin\AppData\Roaming\Microsoft\Skype for Desktop\settings.json.uapro
binary
MD5: f6246f19a82fbd5ae4940ce161a77484
SHA256: e82a4f3facd2c5d1e4171cf69a87b81598a47de2a17f4c00ca48686c03126c60
2564
GandCrab.exe
C:\Users\admin\AppData\Roaming\Microsoft\Skype for Desktop\settings.json
––
MD5:  ––
SHA256:  ––
2564
GandCrab.exe
C:\Users\admin\AppData\Roaming\Microsoft\Skype for Desktop\QuotaManager
––
MD5:  ––
SHA256:  ––
2564
GandCrab.exe
C:\Users\admin\AppData\Roaming\Microsoft\Skype for Desktop\media-stack\Skype.msrtc-1-1870167131.blog.uapro
binary
MD5: 287cedaebb649fafeeba849e414c50d6
SHA256: db915225979ced1bb7f3714bd2de441f8281faccce3b0f8f5b67619211b151c1
2564
GandCrab.exe
C:\Users\admin\AppData\Roaming\Microsoft\Skype for Desktop\media-stack\Skype_MediaStackETW-2018.34.1.3-UVA-x86release-U.etl.bak.uapro
binary
MD5: e8eff8f2723fc17d8ba348b427b6686c
SHA256: 23069e55f1d2ec96001631e194d9e7ff944eec4a66d57254a3d7ba7bbfa33002
2564
GandCrab.exe
C:\Users\admin\AppData\Roaming\Microsoft\Skype for Desktop\Preferences.uapro
binary
MD5: 4fecf7dfa31f2cbba25f04e7fa23e58a
SHA256: 5f22c304e72e326020f7c54a41760ef2b11a890c78501f4862a212a69017b6f3
2564
GandCrab.exe
C:\Users\admin\AppData\Roaming\Microsoft\Skype for Desktop\media-stack\Skype_MediaStackETW-2018.34.1.3-UVA-x86release-U.etl.uapro
binary
MD5: ea6ab70021e2174341643cee78d13ee9
SHA256: 409d6bab9fe823d18604fce2f9399a98fb412acc1ab7984cdf481a7bdc035ce4
2564
GandCrab.exe
C:\Users\admin\AppData\Roaming\Microsoft\Skype for Desktop\media-stack\Skype_MediaStackETW-2018.34.1.3-UVA-x86release-U.etl
––
MD5:  ––
SHA256:  ––
2564
GandCrab.exe
C:\Users\admin\AppData\Roaming\Microsoft\Skype for Desktop\media-stack\Skype_MediaStackETW-2018.34.1.3-UVA-x86release-U.etl.bak
––
MD5:  ––
SHA256:  ––
2564
GandCrab.exe
C:\Users\admin\AppData\Roaming\Microsoft\Skype for Desktop\media-stack\Skype.msrtc-1-1870167131.blog
––
MD5:  ––
SHA256:  ––
2564
GandCrab.exe
C:\Users\admin\AppData\Roaming\Microsoft\Skype for Desktop\Preferences
––
MD5:  ––
SHA256:  ––
2564
GandCrab.exe
C:\Users\admin\AppData\Roaming\Microsoft\Skype for Desktop\Local Storage\leveldb\LOG.old.uapro
binary
MD5: af9d8263540aa67801f3f36db4110d1e
SHA256: 1877e2134b13cc7790f2ae91c8dd1379cce6a2a09a2c037c9a53fc2fa519b34b
2564
GandCrab.exe
C:\Users\admin\AppData\Roaming\Microsoft\Skype for Desktop\media-stack\Skype.msrtc-0-2576771366.blog.uapro
binary
MD5: 2b65dc4f2a2c0f0a56cacac21c18eb7b
SHA256: 98e4d97f132975c38b7d7faf968fa50222f619de25a360d3fec9524d4f883ccf
2564
GandCrab.exe
C:\Users\admin\AppData\Roaming\Microsoft\Skype for Desktop\media-stack\UAPRO-DECRYPT.html
html
MD5: 08c2da0ed1a1bf7ef89f736b9ed43bd2
SHA256: f233665b765c8159f5d39d78e6947aa2a42a56de79e2ad94db7b9ab587038a29
2564
GandCrab.exe
C:\Users\admin\AppData\Roaming\Microsoft\Skype for Desktop\logs\UAPRO-DECRYPT.html
html
MD5: 08c2da0ed1a1bf7ef89f736b9ed43bd2
SHA256: f233665b765c8159f5d39d78e6947aa2a42a56de79e2ad94db7b9ab587038a29
2564
GandCrab.exe
C:\Users\admin\AppData\Roaming\Microsoft\Skype for Desktop\Local Storage\leveldb\MANIFEST-000001.uapro
binary
MD5: 2af3d61adc0f6631a9f791ae1dcd926c
SHA256: d1f90d8d7c26d4d1f820dfc8208d755a38bb40d3c760134402b5327e52d0be2c
2564
GandCrab.exe
C:\Users\admin\AppData\Roaming\Microsoft\Skype for Desktop\Local Storage\leveldb\LOG.uapro
binary
MD5: cc5d670a801dbf15aa701113c5f56276
SHA256: d129b0b3feaff4fa213dffbdb9a69aad197ea1506464242d53ab6234ad2e8aa6
2564
GandCrab.exe
C:\Users\admin\AppData\Roaming\Microsoft\Skype for Desktop\Local Storage\leveldb\MANIFEST-000001
––
MD5:  ––
SHA256:  ––
2564
GandCrab.exe
C:\Users\admin\AppData\Roaming\Microsoft\Skype for Desktop\media-stack\Skype.msrtc-0-2576771366.blog
––
MD5:  ––
SHA256:  ––
2564
GandCrab.exe
C:\Users\admin\AppData\Roaming\Microsoft\Skype for Desktop\Local Storage\leveldb\LOG.old
––
MD5:  ––
SHA256:  ––
2564
GandCrab.exe
C:\Users\admin\AppData\Roaming\Microsoft\Skype for Desktop\Local Storage\leveldb\LOG
––
MD5:  ––
SHA256:  ––
2564
GandCrab.exe
C:\Users\admin\AppData\Roaming\Microsoft\Skype for Desktop\Local Storage\leveldb\000005.ldb.uapro
binary
MD5: 9b4031a8a527fa71ab3dff1a4ac4512c
SHA256: 5a9ceab439293995a73aa78d752dad99aa2f371fb48f339a39c9cfae4e2bba4c
2564
GandCrab.exe
C:\Users\admin\AppData\Roaming\Microsoft\Skype for Desktop\Local Storage\leveldb\CURRENT.uapro
binary
MD5: bec67cfadfbd7a6b38a907a0ddeca82f
SHA256: 43868143c5c29da0d9ad622b7e89a4852f75af8d0ae1c79fa4ed0520be5b4c81
2564
GandCrab.exe
C:\Users\admin\AppData\Roaming\Microsoft\Skype for Desktop\Local Storage\leveldb\000018.ldb.uapro
binary
MD5: a1fb2ebf84d14ddc71425c3909817128
SHA256: 43d276a97b46ba929ad4770b480dc680f5805014e8467bf42a96c229f174e6dd
2564
GandCrab.exe
C:\Users\admin\AppData\Roaming\Microsoft\Skype for Desktop\Local Storage\leveldb\000017.log.uapro
vc
MD5: b35e333695deb7f1d2919058eec04428
SHA256: c83ecaf1d743a89b06723939a8c6a588c98dfbdb1772458a1c13cc6277280f41
2564
GandCrab.exe
C:\Users\admin\AppData\Roaming\Microsoft\Skype for Desktop\Local Storage\leveldb\000018.ldb
––
MD5:  ––
SHA256:  ––
2564
GandCrab.exe
C:\Users\admin\AppData\Roaming\Microsoft\Skype for Desktop\Local Storage\leveldb\000005.ldb
––
MD5:  ––
SHA256:  ––
2564
GandCrab.exe
C:\Users\admin\AppData\Roaming\Microsoft\Skype for Desktop\Local Storage\leveldb\CURRENT
––
MD5:  ––
SHA256:  ––
2564
GandCrab.exe
C:\Users\admin\AppData\Roaming\Microsoft\Skype for Desktop\Local Storage\leveldb\000017.log
––
MD5:  ––
SHA256:  ––
2564
GandCrab.exe
C:\Users\admin\AppData\Roaming\Microsoft\Skype for Desktop\IndexedDB\file__0.indexeddb.leveldb\LOG.old.uapro
binary
MD5: 81359ee54c9684b349e54d88f40e5bb2
SHA256: 7f4a5e4a3a73afb40e236fa43aec01b24831fb36c721e61adc867256468b78be
2564
GandCrab.exe
C:\Users\admin\AppData\Roaming\Microsoft\Skype for Desktop\IndexedDB\file__0.indexeddb.leveldb\MANIFEST-000001.uapro
binary
MD5: fe10bb60419a411ae6669ff2731c2384
SHA256: 399b8cd2ab9c4bb72bc6f626bd4c170b3814bb7fd860822c3b1b611dcc3e159e
2564
GandCrab.exe
C:\Users\admin\AppData\Roaming\Microsoft\Skype for Desktop\Local Storage\leveldb\UAPRO-DECRYPT.html
html
MD5: 08c2da0ed1a1bf7ef89f736b9ed43bd2
SHA256: f233665b765c8159f5d39d78e6947aa2a42a56de79e2ad94db7b9ab587038a29
2564
GandCrab.exe
C:\Users\admin\AppData\Roaming\Microsoft\Skype for Desktop\IndexedDB\file__0.indexeddb.leveldb\LOG.uapro
binary
MD5: 4e07ee64f775799f602e8a3d06ad71f7
SHA256: c7ff03ccf2e69fc46847bcb54483f19637cdb24b4f12fd1c7b36d5b26c408481
2564
GandCrab.exe
C:\Users\admin\AppData\Roaming\Microsoft\Skype for Desktop\Local Storage\UAPRO-DECRYPT.html
html
MD5: 08c2da0ed1a1bf7ef89f736b9ed43bd2
SHA256: f233665b765c8159f5d39d78e6947aa2a42a56de79e2ad94db7b9ab587038a29
2564
GandCrab.exe
C:\Users\admin\AppData\Roaming\Microsoft\Skype for Desktop\IndexedDB\file__0.indexeddb.leveldb\LOG.old
––
MD5:  ––
SHA256:  ––
2564
GandCrab.exe
C:\Users\admin\AppData\Roaming\Microsoft\Skype for Desktop\IndexedDB\file__0.indexeddb.leveldb\LOG
––
MD5:  ––
SHA256:  ––
2564
GandCrab.exe
C:\Users\admin\AppData\Roaming\Microsoft\Skype for Desktop\IndexedDB\file__0.indexeddb.leveldb\MANIFEST-000001
––
MD5:  ––
SHA256:  ––
2564
GandCrab.exe
C:\Users\admin\AppData\Roaming\Microsoft\Skype for Desktop\IndexedDB\file__0.indexeddb.leveldb\CURRENT.uapro
binary
MD5: ec3562dfe1980ad0614f1a79b68e3989
SHA256: e968d4e73a8f053fa6f1b860f27bfa57ce497592b086d0bc636ed9848334647f
2564
GandCrab.exe
C:\Users\admin\AppData\Roaming\Microsoft\Skype for Desktop\IndexedDB\file__0.indexeddb.leveldb\000003.log.uapro
binary
MD5: 22afd4136613624673a5fe664ae685f4
SHA256: c130f85729fd05e43cd9bc1d4eb5a00466296a71fcdfa59ad4b2ba20c7d7aed7
2564
GandCrab.exe
C:\Users\admin\AppData\Roaming\Microsoft\Skype for Desktop\IndexedDB\file__0.indexeddb.leveldb\CURRENT
––
MD5:  ––
SHA256:  ––
2564
GandCrab.exe
C:\Users\admin\AppData\Roaming\Microsoft\Skype for Desktop\IndexedDB\file__0.indexeddb.leveldb\000003.log
––
MD5:  ––
SHA256:  ––
2564
GandCrab.exe
C:\Users\admin\AppData\Roaming\Microsoft\Skype for Desktop\dictionaries\en-US.bdic.uapro
binary
MD5: 4b7a8b19c88d8dbdc08d5d51442557fb
SHA256: b8ff840843985e11b5ca4933e026c590b84e34ea34bab99e26a53bfc790d3cb0
2564
GandCrab.exe
C:\Users\admin\AppData\Roaming\Microsoft\Skype for Desktop\IndexedDB\UAPRO-DECRYPT.html
html
MD5: 08c2da0ed1a1bf7ef89f736b9ed43bd2
SHA256: f233665b765c8159f5d39d78e6947aa2a42a56de79e2ad94db7b9ab587038a29
2564
GandCrab.exe
C:\Users\admin\AppData\Roaming\Microsoft\Skype for Desktop\ecscache.json.uapro
binary
MD5: f57248042f45e383baa732b781ce9a14
SHA256: 17e75178cbd00b31815093d4bf1cca3a6a46565da72ea6cb5425e33919999dd7
2564
GandCrab.exe
C:\Users\admin\AppData\Roaming\Microsoft\Skype for Desktop\IndexedDB\file__0.indexeddb.leveldb\UAPRO-DECRYPT.html
html
MD5: 08c2da0ed1a1bf7ef89f736b9ed43bd2
SHA256: f233665b765c8159f5d39d78e6947aa2a42a56de79e2ad94db7b9ab587038a29
2564
GandCrab.exe
C:\Users\admin\AppData\Roaming\Microsoft\Skype for Desktop\ecscache.json
––
MD5:  ––
SHA256:  ––
2564
GandCrab.exe
C:\Users\admin\AppData\Roaming\Microsoft\Skype for Desktop\dictionaries\en-US.bdic
––
MD5:  ––
SHA256:  ––
2564
GandCrab.exe
C:\Users\admin\AppData\Roaming\Microsoft\Skype for Desktop\dictionaries\UAPRO-DECRYPT.html
html
MD5: 08c2da0ed1a1bf7ef89f736b9ed43bd2
SHA256: f233665b765c8159f5d39d78e6947aa2a42a56de79e2ad94db7b9ab587038a29
2564
GandCrab.exe
C:\Users\admin\AppData\Roaming\Microsoft\Skype for Desktop\databases\UAPRO-DECRYPT.html
html
MD5: 08c2da0ed1a1bf7ef89f736b9ed43bd2
SHA256: f233665b765c8159f5d39d78e6947aa2a42a56de79e2ad94db7b9ab587038a29
2564
GandCrab.exe
C:\Users\admin\AppData\Roaming\Microsoft\Skype for Desktop\Cookies.uapro
binary
MD5: 8635fbe4fa958b8406f5529b8fcc126e
SHA256: 0a53a6d9a0d3ada518527cf479d2ff18bf56c6d904e402fd99af5fbdf7f04433
2564
GandCrab.exe
C:\Users\admin\AppData\Roaming\Microsoft\Skype for Desktop\databases\Databases.db.uapro
binary
MD5: f4d51492027892607c9205748fed3562
SHA256: 6244dda595a55c184c331dd6d8312d1787010283bd17a604a6a786ffc93965a4
2564
GandCrab.exe
C:\Users\admin\AppData\Roaming\Microsoft\Skype for Desktop\device-info.json.uapro
binary
MD5: 177de8549c8985a4ca7bea8b988cb332
SHA256: 50240d01a3bdfb3a4683d7e610c899e8e423194d62223d9856ee8d402b184dd1
2564
GandCrab.exe
C:\Users\admin\AppData\Roaming\Microsoft\Skype for Desktop\device-info.json
––
MD5:  ––
SHA256:  ––
2564
GandCrab.exe
C:\Users\admin\AppData\Roaming\Microsoft\Skype for Desktop\databases\Databases.db
––
MD5:  ––
SHA256:  ––
2564
GandCrab.exe
C:\Users\admin\AppData\Roaming\Microsoft\Skype for Desktop\Cache\index.uapro
binary
MD5: 18fbc16db96371280764863495ee8828
SHA256: dc3629781a2c145265fa15fb3bc376fac1261b0ee62189bf21648b6faa5b3ebb
2564
GandCrab.exe
C:\Users\admin\AppData\Roaming\Microsoft\Skype for Desktop\Cache\f_000004.uapro
binary
MD5: 1924c0a51ebea95af3c90b945e80024d
SHA256: 15f30a100e7900e13022e8dbe97b5328657ccd1b62ed43ce04e3c2eed54dae0f
2564
GandCrab.exe
C:\Users\admin\AppData\Roaming\Microsoft\Skype for Desktop\Cookies
––
MD5:  ––
SHA256:  ––
2564
GandCrab.exe
C:\Users\admin\AppData\Roaming\Microsoft\Skype for Desktop\Cache\index
––
MD5:  ––
SHA256:  ––
2564
GandCrab.exe
C:\Users\admin\AppData\Roaming\Microsoft\Skype for Desktop\Cache\f_000004
––
MD5:  ––
SHA256:  ––
2564
GandCrab.exe
C:\Users\admin\AppData\Roaming\Microsoft\Skype for Desktop\Cache\f_000003.uapro
binary
MD5: 62962a4ff70a8e4d7fa06f7948f36846
SHA256: 876b603c103a2c6ea9ef62d88f4e75ba6b5b788ca17d7625ec26e2efa670af5e
2564
GandCrab.exe
C:\Users\admin\AppData\Roaming\Microsoft\Skype for Desktop\Cache\f_000002.uapro
binary
MD5: d55bd89de4b9b894410609fff232e3b8
SHA256: dfcd519592a83cd607771b8f7430405f50d1e9b1989e146bf08030b385990709
2564
GandCrab.exe
C:\Users\admin\AppData\Roaming\Microsoft\Skype for Desktop\Cache\f_000001.uapro
binary
MD5: 04f69098d15119f3d715d87752e6a744
SHA256: 9114cd709fc45d1ec256b90a03667a4add7df0c50b3652624afedf32e26c7e48
2564
GandCrab.exe
C:\Users\admin\AppData\Roaming\Microsoft\Skype for Desktop\Cache\f_000003
––
MD5:  ––
SHA256:  ––
2564
GandCrab.exe
C:\Users\admin\AppData\Roaming\Microsoft\Skype for Desktop\Cache\f_000002
––
MD5:  ––
SHA256:  ––
2564
GandCrab.exe
C:\Users\admin\AppData\Roaming\Microsoft\Skype for Desktop\Cache\f_000001
––
MD5:  ––
SHA256:  ––
2564
GandCrab.exe
C:\Users\admin\AppData\Roaming\Microsoft\Skype for Desktop\Cache\data_3.uapro
––
MD5:  ––
SHA256:  ––
2564
GandCrab.exe
C:\Users\admin\AppData\Roaming\Microsoft\Skype for Desktop\Cache\data_3
––
MD5:  ––
SHA256:  ––
2564
GandCrab.exe
C:\Users\admin\AppData\Roaming\Microsoft\Skype for Desktop\Cache\data_2.uapro
binary
MD5: 593c0c33bc71c2da3b47904ceece3ccd
SHA256: e3f9492a244016131dff646d9534c10543300f754c6c2af4ac8c90312b282ac5
2564
GandCrab.exe
C:\Users\admin\AppData\Roaming\Microsoft\Skype for Desktop\Cache\data_2
––
MD5:  ––
SHA256:  ––
2564
GandCrab.exe
C:\Users\admin\AppData\Roaming\Microsoft\Skype for Desktop\Cache\data_1.uapro
binary
MD5: 72f319712b7b17170ed6cb549ed83913
SHA256: 747a76c788719513f59399f89f92096063417bf569fef6df8ddc9860080acf9e
2564
GandCrab.exe
C:\Users\admin\AppData\Roaming\Microsoft\Skype for Desktop\Cache\data_1
––
MD5:  ––
SHA256:  ––
2564
GandCrab.exe
C:\Users\admin\AppData\Roaming\Microsoft\Skype for Desktop\Cache\data_0.uapro
binary
MD5: 9c583b559b012577d65a97811a40e1f0
SHA256: 6ca449c00c2a7e72dc2071368b81471005f57a06caa55e93aeff7cfc72ab7b2c
2564
GandCrab.exe
C:\Users\admin\AppData\Roaming\Microsoft\Skype for Desktop\Cache\data_0
––
MD5:  ––
SHA256:  ––
2564
GandCrab.exe
C:\Users\admin\AppData\Roaming\Microsoft\Skype for Desktop\Cache\UAPRO-DECRYPT.html
html
MD5: 08c2da0ed1a1bf7ef89f736b9ed43bd2
SHA256: f233665b765c8159f5d39d78e6947aa2a42a56de79e2ad94db7b9ab587038a29
2564
GandCrab.exe
C:\Users\admin\AppData\Roaming\Microsoft\Publisher Building Blocks\ContentStore.xml.uapro
binary
MD5: 1fd976d3ab7fa857d70520240a8c8421
SHA256: a6589934aac79bdd1982ba248b8e34b01e0427a8501d6a3330150765b77338c0
2564
GandCrab.exe
C:\Users\admin\AppData\Roaming\Microsoft\Signatures\UAPRO-DECRYPT.html
html
MD5: 08c2da0ed1a1bf7ef89f736b9ed43bd2
SHA256: f233665b765c8159f5d39d78e6947aa2a42a56de79e2ad94db7b9ab587038a29
2564
GandCrab.exe
C:\Users\admin\AppData\Roaming\Microsoft\Skype for Desktop\UAPRO-DECRYPT.html
html
MD5: 08c2da0ed1a1bf7ef89f736b9ed43bd2
SHA256: f233665b765c8159f5d39d78e6947aa2a42a56de79e2ad94db7b9ab587038a29
2564
GandCrab.exe
C:\Users\admin\AppData\Roaming\Microsoft\Publisher Building Blocks\ContentStore.xml
––
MD5:  ––
SHA256:  ––
2564
GandCrab.exe
C:\Users\admin\AppData\Roaming\Microsoft\Publisher\UAPRO-DECRYPT.html
html
MD5: 08c2da0ed1a1bf7ef89f736b9ed43bd2
SHA256: f233665b765c8159f5d39d78e6947aa2a42a56de79e2ad94db7b9ab587038a29
2564
GandCrab.exe
C:\Users\admin\AppData\Roaming\Microsoft\Protect\S-1-5-21-1302019708-1500728564-335382590-1000\Preferred.uapro
binary
MD5: 57b27ada12de6eb14a2ba3f588243ec1
SHA256: 0d9d9fdc79b394a15186bf4b944ccd56f4674160b0531faa7274a44bd4e3bd25
2564
GandCrab.exe
C:\Users\admin\AppData\Roaming\Microsoft\Publisher Building Blocks\UAPRO-DECRYPT.html
html
MD5: 08c2da0ed1a1bf7ef89f736b9ed43bd2
SHA256: f233665b765c8159f5d39d78e6947aa2a42a56de79e2ad94db7b9ab587038a29
2564
GandCrab.exe
C:\Users\admin\AppData\Roaming\Microsoft\Protect\S-1-5-21-1302019708-1500728564-335382590-1000\Preferred
––
MD5:  ––
SHA256:  ––
2564
GandCrab.exe
C:\Users\admin\AppData\Roaming\Microsoft\Protect\S-1-5-21-1302019708-1500728564-335382590-1000\fe07f945-3a9b-49ff-b54f-5b2e9331906f.uapro
binary
MD5: e7dc08b43559cd1835bf5fd9e3c86673
SHA256: c018322c2f738f7d64c50d16da5d4f5467cb9991f209b0f246648c159bb1e4e7
2564
GandCrab.exe
C:\Users\admin\AppData\Roaming\Microsoft\Protect\S-1-5-21-1302019708-1500728564-335382590-1000\fe07f945-3a9b-49ff-b54f-5b2e9331906f
––
MD5:  ––
SHA256:  ––
2564
GandCrab.exe
C:\Users\admin\AppData\Roaming\Microsoft\Protect\S-1-5-21-1302019708-1500728564-335382590-1000\fc958741-2c2f-465a-852a-5ea30b2a11d1.uapro
binary
MD5: b22191fa35988f5167b161fc6e017448
SHA256: 36d4f2df4b25df238fe821e0300f7e1e0a3b7e6e3aca5f6b51bad4234cffa985
2564
GandCrab.exe
C:\Users\admin\AppData\Roaming\Microsoft\Protect\S-1-5-21-1302019708-1500728564-335382590-1000\fc958741-2c2f-465a-852a-5ea30b2a11d1
––
MD5:  ––
SHA256:  ––
2564
GandCrab.exe
C:\Users\admin\AppData\Roaming\Microsoft\Protect\S-1-5-21-1302019708-1500728564-335382590-1000\54ba308a-6a9a-4e0e-b137-b89d3579498b.uapro
binary
MD5: e5a8ec6075885f918acc348b9259fb8e
SHA256: 68c8084e180ae5e092fe7818f87d2e584dfb672a9835afb97390a181ab4b36d2
2564
GandCrab.exe
C:\Users\admin\AppData\Roaming\Microsoft\Protect\S-1-5-21-1302019708-1500728564-335382590-1000\54ba308a-6a9a-4e0e-b137-b89d3579498b
––
MD5:  ––
SHA256:  ––
2564
GandCrab.exe
C:\Users\admin\AppData\Roaming\Microsoft\Protect\S-1-5-21-1302019708-1500728564-335382590-1000\29fd2168-360f-422a-a685-e6961ea74ba8.uapro
binary
MD5: a694b9915f948643828f7c08eb81b70e
SHA256: 270bd32455c6757b91f2eb0b4fb3ad9928c134940f312da3efb6026dafe9a089
2564
GandCrab.exe
C:\Users\admin\AppData\Roaming\Microsoft\Protect\S-1-5-21-1302019708-1500728564-335382590-1000\29fd2168-360f-422a-a685-e6961ea74ba8
––
MD5:  ––
SHA256:  ––
2564
GandCrab.exe
C:\Users\admin\AppData\Roaming\Microsoft\Protect\CREDHIST.uapro
binary
MD5: bcf5a2142bd5c62d65628fa8748d0760
SHA256: bcef1d74950197a97fac11c60957a9d7771393960e0f6b81e718ee1e561841e8
2564
GandCrab.exe
C:\Users\admin\AppData\Roaming\Microsoft\Protect\S-1-5-21-1302019708-1500728564-335382590-1000\UAPRO-DECRYPT.html
html
MD5: 08c2da0ed1a1bf7ef89f736b9ed43bd2
SHA256: f233665b765c8159f5d39d78e6947aa2a42a56de79e2ad94db7b9ab587038a29
2564
GandCrab.exe
C:\Users\admin\AppData\Roaming\Microsoft\Protect\CREDHIST
––
MD5:  ––
SHA256:  ––
2564
GandCrab.exe
C:\Users\admin\AppData\Roaming\Microsoft\Protect\UAPRO-DECRYPT.html
html
MD5: 08c2da0ed1a1bf7ef89f736b9ed43bd2
SHA256: f233665b765c8159f5d39d78e6947aa2a42a56de79e2ad94db7b9ab587038a29
2564
GandCrab.exe
C:\Users\admin\AppData\Roaming\Microsoft\PowerPoint\UAPRO-DECRYPT.html
html
MD5: 08c2da0ed1a1bf7ef89f736b9ed43bd2
SHA256: f233665b765c8159f5d39d78e6947aa2a42a56de79e2ad94db7b9ab587038a29
2564
GandCrab.exe
C:\Users\admin\AppData\Roaming\Microsoft\Proof\UAPRO-DECRYPT.html
html
MD5: 08c2da0ed1a1bf7ef89f736b9ed43bd2
SHA256: f233665b765c8159f5d39d78e6947aa2a42a56de79e2ad94db7b9ab587038a29
2564
GandCrab.exe
C:\Users\admin\AppData\Roaming\Microsoft\Outlook\test.xml.uapro
binary
MD5: 4dd8aec18e87b951f06eeec21ec850c4
SHA256: 0098fbe5835612b8fd5b1d6be12360aaa88d1ba46c3af74560c04723241e5e06
2564
GandCrab.exe
C:\Users\admin\AppData\Roaming\Microsoft\Outlook\test.xml
––
MD5:  ––
SHA256:  ––
2564
GandCrab.exe
C:\Users\admin\AppData\Roaming\Microsoft\Outlook\test.srs.uapro
binary
MD5: fe83a6525ddafbbb3f50b249dfb28afd
SHA256: 7e8206842ac89c63c0e84e1bc35f8e9035b71ae8bf6a2fde1dc8d300fbc507cd
2564
GandCrab.exe
C:\Users\admin\AppData\Roaming\Microsoft\Outlook\test.srs
––
MD5:  ––
SHA256:  ––
2564
GandCrab.exe
C:\Users\admin\AppData\Roaming\Microsoft\Outlook\Outlook.xml.uapro
binary
MD5: 4e527096e61cc56e1008a0ee60da3032
SHA256: 21603d3ac9736c60c6681ae740872afa3287f3869ece6597caa27b31ffae9b37
2564
GandCrab.exe
C:\Users\admin\AppData\Roaming\Microsoft\Outlook\Outlook.xml
––
MD5:  ––
SHA256:  ––
2564
GandCrab.exe
C:\Users\admin\AppData\Roaming\Microsoft\Outlook\Outlook.srs.uapro
binary
MD5: 81a3a82aaabf1d5135296231478c5fce
SHA256: 15fa9a17a4154c8c936aaa8cff11f9738393bad4bc169a6883b2b202149947d2
2564
GandCrab.exe
C:\Users\admin\AppData\Roaming\Microsoft\Outlook\NoMail.xml.uapro
binary
MD5: 825914af7a6eec4d91cecbb777a5aa04
SHA256: 3bd9129300c9da2b63f00a44aca1ad79759bbbc2622cd0164b4ed65093908318
2564
GandCrab.exe
C:\Users\admin\AppData\Roaming\Microsoft\Outlook\Outlook.srs
––
MD5:  ––
SHA256:  ––
2564
GandCrab.exe
C:\Users\admin\AppData\Roaming\Microsoft\Outlook\NoMail.xml
––
MD5:  ––
SHA256:  ––
2564
GandCrab.exe
C:\Users\admin\AppData\Roaming\Microsoft\Outlook\UAPRO-DECRYPT.html
html
MD5: 08c2da0ed1a1bf7ef89f736b9ed43bd2
SHA256: f233665b765c8159f5d39d78e6947aa2a42a56de79e2ad94db7b9ab587038a29
2564
GandCrab.exe
C:\Users\admin\AppData\Roaming\Microsoft\OneNote\14.0\Preferences.dat.uapro
binary
MD5: 275a007640fb21f77f295e45bcf5dcc9
SHA256: efbf174ffd89c4af701e010b5e6c17fc5648b744d4f19c449e99ceb246d874e7
2564
GandCrab.exe
C:\Users\admin\AppData\Roaming\Microsoft\OneNote\14.0\Preferences.dat
––
MD5:  ––
SHA256:  ––
2564
GandCrab.exe
C:\Users\admin\AppData\Roaming\Microsoft\Office\Recent\UAPRO-DECRYPT.html
html
MD5: 08c2da0ed1a1bf7ef89f736b9ed43bd2
SHA256: f233665b765c8159f5d39d78e6947aa2a42a56de79e2ad94db7b9ab587038a29
2564
GandCrab.exe
C:\Users\admin\AppData\Roaming\Microsoft\OneNote\UAPRO-DECRYPT.html
html
MD5: 08c2da0ed1a1bf7ef89f736b9ed43bd2
SHA256: f233665b765c8159f5d39d78e6947aa2a42a56de79e2ad94db7b9ab587038a29
2564
GandCrab.exe
C:\Users\admin\AppData\Roaming\Microsoft\OneNote\14.0\UAPRO-DECRYPT.html
html
MD5: 08c2da0ed1a1bf7ef89f736b9ed43bd2
SHA256: f233665b765c8159f5d39d78e6947aa2a42a56de79e2ad94db7b9ab587038a29
2564
GandCrab.exe
C:\Users\admin\AppData\Roaming\Microsoft\Office\MSO1033.acl.uapro
binary
MD5: c2016f7f9240bd2c9c40f85823aec407
SHA256: 52959ca89e207dfdb7f363d562c96100a01af5d83a6d250f6760319a2d5e9a04
2564
GandCrab.exe
C:\Users\admin\AppData\Roaming\Microsoft\Office\MSO1033.acl
––
MD5:  ––
SHA256:  ––
2564
GandCrab.exe
C:\Users\admin\AppData\Roaming\Microsoft\MMC\taskschd.uapro
binary
MD5: 85da94ce1b00f48ab769650fb68cccf9
SHA256: 614c13fadcbdce54117ec4bcfe071a21a796d14e2ef805aec9a8783eabc0c519
2564
GandCrab.exe
C:\Users\admin\AppData\Roaming\Microsoft\Network\Connections\UAPRO-DECRYPT.html
html
MD5: 08c2da0ed1a1bf7ef89f736b9ed43bd2
SHA256: f233665b765c8159f5d39d78e6947aa2a42a56de79e2ad94db7b9ab587038a29
2564
GandCrab.exe
C:\Users\admin\AppData\Roaming\Microsoft\Network\Connections\Pbk\UAPRO-DECRYPT.html
html
MD5: 08c2da0ed1a1bf7ef89f736b9ed43bd2
SHA256: f233665b765c8159f5d39d78e6947aa2a42a56de79e2ad94db7b9ab587038a29
2564
GandCrab.exe
C:\Users\admin\AppData\Roaming\Microsoft\Network\Connections\Pbk\_hiddenPbk\UAPRO-DECRYPT.html
html
MD5: 08c2da0ed1a1bf7ef89f736b9ed43bd2
SHA256: f233665b765c8159f5d39d78e6947aa2a42a56de79e2ad94db7b9ab587038a29
2564
GandCrab.exe
C:\Users\admin\AppData\Roaming\Microsoft\Network\UAPRO-DECRYPT.html
html
MD5: 08c2da0ed1a1bf7ef89f736b9ed43bd2
SHA256: f233665b765c8159f5d39d78e6947aa2a42a56de79e2ad94db7b9ab587038a29
2564
GandCrab.exe
C:\Users\admin\AppData\Roaming\Microsoft\Office\UAPRO-DECRYPT.html
html
MD5: 08c2da0ed1a1bf7ef89f736b9ed43bd2
SHA256: f233665b765c8159f5d39d78e6947aa2a42a56de79e2ad94db7b9ab587038a29
2564
GandCrab.exe
C:\Users\admin\AppData\Roaming\Microsoft\MMC\taskschd
––
MD5:  ––
SHA256:  ––
2564
GandCrab.exe
C:\Users\admin\AppData\Roaming\Microsoft\MMC\UAPRO-DECRYPT.html
html
MD5: 08c2da0ed1a1bf7ef89f736b9ed43bd2
SHA256: f233665b765c8159f5d39d78e6947aa2a42a56de79e2ad94db7b9ab587038a29
2564
GandCrab.exe
C:\Users\admin\AppData\Roaming\Microsoft\Internet Explorer\UAPRO-DECRYPT.html
html
MD5: 08c2da0ed1a1bf7ef89f736b9ed43bd2
SHA256: f233665b765c8159f5d39d78e6947aa2a42a56de79e2ad94db7b9ab587038a29
2564
GandCrab.exe
C:\Users\admin\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\User Pinned\UAPRO-DECRYPT.html
html
MD5: 08c2da0ed1a1bf7ef89f736b9ed43bd2
SHA256: f233665b765c8159f5d39d78e6947aa2a42a56de79e2ad94db7b9ab587038a29
2564
GandCrab.exe
C:\Users\admin\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\User Pinned\ImplicitAppShortcuts\UAPRO-DECRYPT.html
html
MD5: 08c2da0ed1a1bf7ef89f736b9ed43bd2
SHA256: f233665b765c8159f5d39d78e6947aa2a42a56de79e2ad94db7b9ab587038a29
2564
GandCrab.exe
C:\Users\admin\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\UAPRO-DECRYPT.html
html
MD5: 08c2da0ed1a1bf7ef89f736b9ed43bd2
SHA256: f233665b765c8159f5d39d78e6947aa2a42a56de79e2ad94db7b9ab587038a29
2564
GandCrab.exe
C:\Users\admin\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\User Pinned\TaskBar\UAPRO-DECRYPT.html
html
MD5: 08c2da0ed1a1bf7ef89f736b9ed43bd2
SHA256: f233665b765c8159f5d39d78e6947aa2a42a56de79e2ad94db7b9ab587038a29
2564
GandCrab.exe
C:\Users\admin\AppData\Roaming\Microsoft\HTML Help\hh.dat.uapro
binary
MD5: 900a62c43f331ddf6e37efc282c9e5d0
SHA256: f1cde88087cfa2fd4f26c42b189d77240849415475e0cbca0b0dd095a8a9db38
2564
GandCrab.exe
C:\Users\admin\AppData\Roaming\Microsoft\HTML Help\hh.dat
––
MD5:  ––
SHA256:  ––
2564
GandCrab.exe
C:\Users\admin\AppData\Roaming\Microsoft\HTML Help\UAPRO-DECRYPT.html
html
MD5: 08c2da0ed1a1bf7ef89f736b9ed43bd2
SHA256: f233665b765c8159f5d39d78e6947aa2a42a56de79e2ad94db7b9ab587038a29
2564
GandCrab.exe
C:\Users\admin\AppData\Roaming\Microsoft\Excel\UAPRO-DECRYPT.html
html
MD5: 08c2da0ed1a1bf7ef89f736b9ed43bd2
SHA256: f233665b765c8159f5d39d78e6947aa2a42a56de79e2ad94db7b9ab587038a29
2564
GandCrab.exe
C:\Users\admin\AppData\Roaming\Microsoft\Excel\XLSTART\UAPRO-DECRYPT.html
html
MD5: 08c2da0ed1a1bf7ef89f736b9ed43bd2
SHA256: f233665b765c8159f5d39d78e6947aa2a42a56de79e2ad94db7b9ab587038a29
2564
GandCrab.exe
C:\Users\admin\AppData\Roaming\Microsoft\Document Building Blocks\1033\14\Built-In Building Blocks.dotx.uapro
binary
MD5: 582dd5ed418709778a9df1b7d64b87bd
SHA256: d0246fe5ade4619e84eb638acc6e77a7a3ac1eb6b9777820825c18327ace251a
2564
GandCrab.exe
C:\Users\admin\AppData\Roaming\Microsoft\Document Building Blocks\1033\14\Built-In Building Blocks.dotx
––
MD5:  ––
SHA256:  ––
2564
GandCrab.exe
C:\Users\admin\AppData\Roaming\Microsoft\Document Building Blocks\1033\UAPRO-DECRYPT.html
html
MD5: 08c2da0ed1a1bf7ef89f736b9ed43bd2
SHA256: f233665b765c8159f5d39d78e6947aa2a42a56de79e2ad94db7b9ab587038a29
2564
GandCrab.exe
C:\Users\admin\AppData\Roaming\Microsoft\Document Building Blocks\UAPRO-DECRYPT.html
html
MD5: 08c2da0ed1a1bf7ef89f736b9ed43bd2
SHA256: f233665b765c8159f5d39d78e6947aa2a42a56de79e2ad94db7b9ab587038a29
2564
GandCrab.exe
C:\Users\admin\AppData\Roaming\Microsoft\Document Building Blocks\1033\14\UAPRO-DECRYPT.html
html
MD5: 08c2da0ed1a1bf7ef89f736b9ed43bd2
SHA256: f233665b765c8159f5d39d78e6947aa2a42a56de79e2ad94db7b9ab587038a29
2564
GandCrab.exe
C:\Users\admin\AppData\Roaming\Microsoft\Crypto\RSA\S-1-5-21-1302019708-1500728564-335382590-1000\e3f86d7936454598ef98443d4fd3260d_90059c37-1320-41a4-b58d-2b75a9850d2f.uapro
binary
MD5: 42ad63c736acac62c0afd898a18a24c2
SHA256: 67624d9060d1cf0e526aaea18cfad7cf1a503f2f15f77e7d9f5f005185378a00
2564
GandCrab.exe
C:\Users\admin\AppData\Roaming\Microsoft\Crypto\RSA\S-1-5-21-1302019708-1500728564-335382590-1000\e3f86d7936454598ef98443d4fd3260d_90059c37-1320-41a4-b58d-2b75a9850d2f
––
MD5:  ––
SHA256:  ––
2564
GandCrab.exe
C:\Users\admin\AppData\Roaming\Microsoft\Crypto\RSA\S-1-5-21-1302019708-1500728564-335382590-1000\c43c9d3341c1ddc712bbe39db3c78fa5_90059c37-1320-41a4-b58d-2b75a9850d2f.uapro
ini
MD5: e681fba0d025e00ba0b5042fcbd33159
SHA256: b3c4fe1c55875a40bec9730332c16d41882d0ca0e69c338ab74e814ea7d35306
2564
GandCrab.exe
C:\Users\admin\AppData\Roaming\Microsoft\Crypto\RSA\S-1-5-21-1302019708-1500728564-335382590-1000\c43c9d3341c1ddc712bbe39db3c78fa5_90059c37-1320-41a4-b58d-2b75a9850d2f
––
MD5:  ––
SHA256:  ––
2564
GandCrab.exe
C:\Users\admin\AppData\Roaming\Microsoft\Crypto\RSA\S-1-5-21-1302019708-1500728564-335382590-1000\a551dda6b1d5ee0d0c4637af6c004413_90059c37-1320-41a4-b58d-2b75a9850d2f.uapro
binary
MD5: 6b9e1228122afaa1a5d487f03885a73d
SHA256: 8889e6384f4ef69b2a5dbf4f28c03079383e22a7303fc2f41cc1a3967052262f
2564
GandCrab.exe
C:\Users\admin\AppData\Roaming\Microsoft\Crypto\RSA\S-1-5-21-1302019708-1500728564-335382590-1000\a551dda6b1d5ee0d0c4637af6c004413_90059c37-1320-41a4-b58d-2b75a9850d2f
––
MD5:  ––
SHA256:  ––
2564
GandCrab.exe
C:\Users\admin\AppData\Roaming\Microsoft\Crypto\RSA\S-1-5-21-1302019708-1500728564-335382590-1000\7be1242ebc44e45985bd1ffa382e997c_90059c37-1320-41a4-b58d-2b75a9850d2f.uapro
binary
MD5: abb5a54d060b142b91158a1c88d4dc20
SHA256: 800deb92178ea7cea4484dcd1e702ccd7922db8e0df1f45ee63517c1586db63f
2564
GandCrab.exe
C:\Users\admin\AppData\Roaming\Microsoft\Crypto\RSA\S-1-5-21-1302019708-1500728564-335382590-1000\7be1242ebc44e45985bd1ffa382e997c_90059c37-1320-41a4-b58d-2b75a9850d2f
––
MD5:  ––
SHA256:  ––
2564
GandCrab.exe
C:\Users\admin\AppData\Roaming\Microsoft\Crypto\RSA\S-1-5-21-1302019708-1500728564-335382590-1000\1f91d2d17ea675d4c2c3192e241743f9_90059c37-1320-41a4-b58d-2b75a9850d2f.uapro
binary
MD5: 0490d4c23b16a8aa6d135de5801814a0
SHA256: 0b9327eead21fb5cf04aebae553bcfe96f060a559a5c443de86f890f83e06432
2564
GandCrab.exe
C:\Users\admin\AppData\Roaming\Microsoft\Crypto\RSA\S-1-5-21-1302019708-1500728564-335382590-1000\1f91d2d17ea675d4c2c3192e241743f9_90059c37-1320-41a4-b58d-2b75a9850d2f
––
MD5:  ––
SHA256:  ––
2564
GandCrab.exe
C:\Users\admin\AppData\Roaming\Microsoft\Crypto\RSA\S-1-5-21-1302019708-1500728564-335382590-1000\0f5007522459c86e95ffcc62f32308f1_90059c37-1320-41a4-b58d-2b75a9850d2f.uapro
binary
MD5: 7a629830c61f0fae4ee0861b1b83cdcb
SHA256: d27496477a5059587d584982752d7607e9108d6837506cce330adec4be49456b
2564
GandCrab.exe
C:\Users\admin\AppData\Roaming\Microsoft\Crypto\RSA\S-1-5-21-1302019708-1500728564-335382590-1000\0f5007522459c86e95ffcc62f32308f1_90059c37-1320-41a4-b58d-2b75a9850d2f
––
MD5:  ––
SHA256:  ––
2564
GandCrab.exe
C:\Users\admin\AppData\Roaming\Microsoft\Credentials\UAPRO-DECRYPT.html
html
MD5: 08c2da0ed1a1bf7ef89f736b9ed43bd2
SHA256: f233665b765c8159f5d39d78e6947aa2a42a56de79e2ad94db7b9ab587038a29
2564
GandCrab.exe
C:\Users\admin\AppData\Roaming\Media Center Programs\UAPRO-DECRYPT.html
html
MD5: 08c2da0ed1a1bf7ef89f736b9ed43bd2
SHA256: f233665b765c8159f5d39d78e6947aa2a42a56de79e2ad94db7b9ab587038a29
2564
GandCrab.exe
C:\Users\admin\AppData\Roaming\Identities\{E4CE17A7-FC47-4CD1-8FF6-45436C8F45DB}\UAPRO-DECRYPT.html
html
MD5: 08c2da0ed1a1bf7ef89f736b9ed43bd2
SHA256: f233665b765c8159f5d39d78e6947aa2a42a56de79e2ad94db7b9ab587038a29
2564
GandCrab.exe
C:\Users\admin\AppData\Roaming\Microsoft\AddIns\UAPRO-DECRYPT.html
html
MD5: 08c2da0ed1a1bf7ef89f736b9ed43bd2
SHA256: f233665b765c8159f5d39d78e6947aa2a42a56de79e2ad94db7b9ab587038a29
2564
GandCrab.exe
C:\Users\admin\AppData\Roaming\Microsoft\Crypto\RSA\UAPRO-DECRYPT.html
html
MD5: 08c2da0ed1a1bf7ef89f736b9ed43bd2
SHA256: f233665b765c8159f5d39d78e6947aa2a42a56de79e2ad94db7b9ab587038a29
2564
GandCrab.exe
C:\Users\admin\AppData\Roaming\Identities\UAPRO-DECRYPT.html
html
MD5: 08c2da0ed1a1bf7ef89f736b9ed43bd2
SHA256: f233665b765c8159f5d39d78e6947aa2a42a56de79e2ad94db7b9ab587038a29
2564
GandCrab.exe
C:\Users\admin\AppData\Roaming\Microsoft\UAPRO-DECRYPT.html
html
MD5: 08c2da0ed1a1bf7ef89f736b9ed43bd2
SHA256: f233665b765c8159f5d39d78e6947aa2a42a56de79e2ad94db7b9ab587038a29
2564
GandCrab.exe
C:\Users\admin\AppData\Roaming\Microsoft\Crypto\RSA\S-1-5-21-1302019708-1500728564-335382590-1000\UAPRO-DECRYPT.html
html
MD5: 08c2da0ed1a1bf7ef89f736b9ed43bd2
SHA256: f233665b765c8159f5d39d78e6947aa2a42a56de79e2ad94db7b9ab587038a29
2564
GandCrab.exe
C:\Users\admin\AppData\Roaming\Microsoft\Crypto\UAPRO-DECRYPT.html
html
MD5: 08c2da0ed1a1bf7ef89f736b9ed43bd2
SHA256: f233665b765c8159f5d39d78e6947aa2a42a56de79e2ad94db7b9ab587038a29
2564
GandCrab.exe
C:\Users\admin\AppData\Roaming\FileZilla\queue.sqlite3.uapro
binary
MD5: 0bb0c7cf22a8a3774b51fb88da9a3100
SHA256: c07419fe18d02b675df098e0e7adaab23bfb24d0dc708f3044c97f96dd68a723
2564
GandCrab.exe
C:\Users\admin\AppData\Roaming\FileZilla\queue.sqlite3
––
MD5:  ––
SHA256:  ––
2564
GandCrab.exe
C:\Users\admin\AppData\Roaming\FileZilla\layout.xml.uapro
binary
MD5: 455516ad68037c5d46d8fffedd008374
SHA256: 9a82c6d8a26bd805a642a4b4e6478460a7284b027d56d3b0a2c03657bff23d67
2564
GandCrab.exe
C:\Users\admin\AppData\Roaming\FileZilla\layout.xml
––
MD5:  ––
SHA256:  ––
2564
GandCrab.exe
C:\Users\admin\AppData\Roaming\FileZilla\filezilla.xml.uapro
binary
MD5: 35c92bb57cc901cdbf6cf8c2615d24dc
SHA256: d76dfbfb9bb499c1bac80584a63594bc0d8957d29f09a334d76703c354bf6c10
2564
GandCrab.exe
C:\Users\admin\AppData\Roaming\FileZilla\filezilla.xml
––
MD5:  ––
SHA256:  ––
2564
GandCrab.exe
C:\Users\admin\AppData\Roaming\FileZilla\UAPRO-DECRYPT.html
html
MD5: 08c2da0ed1a1bf7ef89f736b9ed43bd2
SHA256: f233665b765c8159f5d39d78e6947aa2a42a56de79e2ad94db7b9ab587038a29
2564
GandCrab.exe
C:\Users\admin\AppData\Roaming\Adobe\Sonar\Sonar1.0\sonar_policy.xml.uapro
binary
MD5: c037c13f7a96a50e27a4dea1a726de22
SHA256: 44dda96d8d2c96a8844de37d96ababf34dfb39e8040dc0ce35b53198a51ccc13
2564
GandCrab.exe
C:\Users\admin\AppData\Roaming\Adobe\Sonar\Sonar1.0\sonar_policy.xml
––
MD5:  ––
SHA256:  ––
2564
GandCrab.exe
C:\Users\admin\AppData\Roaming\Adobe\Sonar\Sonar1.0\UAPRO-DECRYPT.html
html
MD5: 08c2da0ed1a1bf7ef89f736b9ed43bd2
SHA256: f233665b765c8159f5d39d78e6947aa2a42a56de79e2ad94db7b9ab587038a29
2564
GandCrab.exe
C:\Users\admin\AppData\Roaming\Adobe\Sonar\UAPRO-DECRYPT.html
html
MD5: 08c2da0ed1a1bf7ef89f736b9ed43bd2
SHA256: f233665b765c8159f5d39d78e6947aa2a42a56de79e2ad94db7b9ab587038a29
2564
GandCrab.exe
C:\Users\admin\AppData\Roaming\Adobe\LogTransport2\LogTransport2.cfg.uapro
binary
MD5: 3b2a59b3557ebfb65ca4c6ac8d4d6b41
SHA256: a5148320a143d336434f436410d6c6d6f4a7f8a328f4ddfbf9d06ddc4f68eee6
2564
GandCrab.exe
C:\Users\admin\AppData\Roaming\Adobe\LogTransport2\LogTransport2.cfg
––
MD5:  ––
SHA256:  ––
2564
GandCrab.exe
C:\Users\admin\AppData\Roaming\Adobe\LogTransport2\Logs\ulog_HeadlightsOptinProductFamily_HeadlightsOptinProduct_00000000-0000-0000-0000-000000000000_dc2ece58-8a8b-40bf-98c2-48039a3392bd.log.uapro
binary
MD5: 378532884b8fa1e5deaa9722d9994f1a
SHA256: 699fbd4c7b3536f16e63a413ae829d269a09ebe4ca8930b55a2f30898ba32d71
2564
GandCrab.exe
C:\Users\admin\AppData\Roaming\Adobe\LogTransport2\Logs\ulog_HeadlightsOptinProductFamily_HeadlightsOptinProduct_00000000-0000-0000-0000-000000000000_dc2ece58-8a8b-40bf-98c2-48039a3392bd.log
––
MD5:  ––
SHA256:  ––
2564
GandCrab.exe
C:\Users\admin\AppData\Roaming\Adobe\LogTransport2\Logs\ulog_AcroARM2_Reader_2274f67c-7a7f-45e3-a23e-aa35d5b91e00_02f147fa-0489-4885-b993-ed9936fcacc0_0.rdy.uapro
binary
MD5: 83d2ef1fea93d38568034702096e9d2d
SHA256: 9f462e3a9f688d5c9779c08dbd9302ebc90929e787e9f65bac36c9031fa4a894
2564
GandCrab.exe
C:\Users\admin\AppData\Roaming\Adobe\LogTransport2\Logs\ulog_AcroARM2_Reader_2274f67c-7a7f-45e3-a23e-aa35d5b91e00_02f147fa-0489-4885-b993-ed9936fcacc0_0.rdy
––
MD5:  ––
SHA256:  ––
2564
GandCrab.exe
C:\Users\admin\AppData\Roaming\Adobe\LogTransport2\UAPRO-DECRYPT.html
html
MD5: 08c2da0ed1a1bf7ef89f736b9ed43bd2
SHA256: f233665b765c8159f5d39d78e6947aa2a42a56de79e2ad94db7b9ab587038a29
2564
GandCrab.exe
C:\Users\admin\AppData\Roaming\Adobe\LogTransport2\Logs\UAPRO-DECRYPT.html
html
MD5: 08c2da0ed1a1bf7ef89f736b9ed43bd2
SHA256: f233665b765c8159f5d39d78e6947aa2a42a56de79e2ad94db7b9ab587038a29
2564
GandCrab.exe
C:\Users\admin\AppData\Roaming\Adobe\Linguistics\UAPRO-DECRYPT.html
html
MD5: 08c2da0ed1a1bf7ef89f736b9ed43bd2
SHA256: f233665b765c8159f5d39d78e6947aa2a42a56de79e2ad94db7b9ab587038a29
2564
GandCrab.exe
C:\Users\admin\AppData\Roaming\Adobe\LogTransport2\Logs\ulog_AcroARM2_ARM2Update_2274f67c-7a7f-45e3-a23e-aa35d5b91e00_fea03e67-af51-4fcb-b57f-c238867edb9b_0.log.uapro
binary
MD5: 284d6484b59a5dea4a1e6890de1394cf
SHA256: 7e4fd345a2fc1624ca325bda78afa2f03ffdfe8d608a7985c1c39d0657071463
2564
GandCrab.exe
C:\Users\admin\AppData\Roaming\Adobe\Headlights\UAPRO-DECRYPT.html
html
MD5: 08c2da0ed1a1bf7ef89f736b9ed43bd2
SHA256: f233665b765c8159f5d39d78e6947aa2a42a56de79e2ad94db7b9ab587038a29
2564
GandCrab.exe
C:\Users\admin\AppData\Roaming\Adobe\LogTransport2\Logs\ulog_AcroARM2_ARM2Update_2274f67c-7a7f-45e3-a23e-aa35d5b91e00_fea03e67-af51-4fcb-b57f-c238867edb9b_0.log
––
MD5:  ––
SHA256:  ––
2564
GandCrab.exe
C:\Users\admin\AppData\Roaming\Adobe\Flash Player\AssetCache\J7D4H966\UAPRO-DECRYPT.html
html
MD5: 08c2da0ed1a1bf7ef89f736b9ed43bd2
SHA256: f233665b765c8159f5d39d78e6947aa2a42a56de79e2ad94db7b9ab587038a29
2564
GandCrab.exe
C:\Users\admin\AppData\Roaming\Adobe\Flash Player\NativeCache\UAPRO-DECRYPT.html
html
MD5: 08c2da0ed1a1bf7ef89f736b9ed43bd2
SHA256: f233665b765c8159f5d39d78e6947aa2a42a56de79e2ad94db7b9ab587038a29
2564
GandCrab.exe
C:\Users\admin\AppData\Roaming\Adobe\Acrobat\DC\Security\CRLCache\CE338828149963DCEA4CD26BB86F0363B4CA0BA5.crl.uapro
binary
MD5: 5ef754eb777c972676541ee8629b2362
SHA256: 39386a95e1ffd1c6f48fbd8b453fe0a563eb5c469114be9d5316a340fddc6b92
2564
GandCrab.exe
C:\Users\admin\AppData\Roaming\Adobe\Flash Player\UAPRO-DECRYPT.html
html
MD5: 08c2da0ed1a1bf7ef89f736b9ed43bd2
SHA256: f233665b765c8159f5d39d78e6947aa2a42a56de79e2ad94db7b9ab587038a29
2564
GandCrab.exe
C:\Users\admin\AppData\Roaming\Adobe\Flash Player\AssetCache\UAPRO-DECRYPT.html
html
MD5: 08c2da0ed1a1bf7ef89f736b9ed43bd2
SHA256: f233665b765c8159f5d39d78e6947aa2a42a56de79e2ad94db7b9ab587038a29
2564
GandCrab.exe
C:\Users\admin\AppData\Roaming\Adobe\Acrobat\DC\Security\CRLCache\CE338828149963DCEA4CD26BB86F0363B4CA0BA5.crl
––
MD5:  ––
SHA256:  ––
2564
GandCrab.exe
C:\Users\admin\AppData\Roaming\Adobe\Acrobat\DC\Security\CRLCache\0FDED5CEB68C302B1CDB2BDDD9D0000E76539CB0.crl.uapro
binary
MD5: 3ed4f36b6056af3f7a19576a5013fee6
SHA256: c8e92f7b9de2e5a81ba043fc32016bc2b32f78b9ee64855e68ed6027c98db786
2564
GandCrab.exe
C:\Users\admin\AppData\Roaming\Adobe\Acrobat\DC\Security\CRLCache\0FDED5CEB68C302B1CDB2BDDD9D0000E76539CB0.crl
––
MD5:  ––
SHA256:  ––
2564
GandCrab.exe
C:\Users\admin\AppData\Roaming\Adobe\Acrobat\DC\Security\addressbook.acrodata.uapro
binary
MD5: 7ca4ef3e1e903d9fb7bbff6223c43a83
SHA256: dce6642237902d2a57e553d15e2aeaaa061688e7883d9f7c9f7a051391bdde44
2564
GandCrab.exe
C:\Users\admin\AppData\Roaming\Adobe\Acrobat\DC\Security\CRLCache\UAPRO-DECRYPT.html
html
MD5: 08c2da0ed1a1bf7ef89f736b9ed43bd2
SHA256: f233665b765c8159f5d39d78e6947aa2a42a56de79e2ad94db7b9ab587038a29
2564
GandCrab.exe
C:\Users\admin\AppData\Roaming\Adobe\Acrobat\DC\Security\addressbook.acrodata
––
MD5:  ––
SHA256:  ––
2564
GandCrab.exe
C:\Users\admin\AppData\Roaming\Adobe\Acrobat\DC\Security\UAPRO-DECRYPT.html
html
MD5: 08c2da0ed1a1bf7ef89f736b9ed43bd2
SHA256: f233665b765c8159f5d39d78e6947aa2a42a56de79e2ad94db7b9ab587038a29
2564
GandCrab.exe
C:\Users\admin\AppData\Roaming\Adobe\Acrobat\DC\JSCache\GlobSettings.uapro
gpg
MD5: f199085132ac9fec21e41b9dbeabd5eb
SHA256: f8212635741d5879961fea71ed2bcf53863aab2be049217caebc8df8b0af1f60
2564
GandCrab.exe
C:\Users\admin\AppData\Roaming\Adobe\Acrobat\DC\JSCache\GlobSettings
––
MD5:  ––
SHA256:  ––
2564
GandCrab.exe
C:\Users\admin\AppData\Roaming\Adobe\Acrobat\DC\JSCache\GlobData.uapro
binary
MD5: f8b83e4e4d8fce1c2507c0d0aee99697
SHA256: 73cdd52876764a8ab1bab540ed32428e7f4d3f6fd6f22a35d5ebd9c12d69ae28
2564
GandCrab.exe
C:\Users\admin\AppData\Roaming\Adobe\Acrobat\DC\JSCache\GlobData
––
MD5:  ––
SHA256:  ––
2564
GandCrab.exe
C:\Users\admin\AppData\Roaming\Adobe\Acrobat\DC\Collab\UAPRO-DECRYPT.html
html
MD5: 08c2da0ed1a1bf7ef89f736b9ed43bd2
SHA256: f233665b765c8159f5d39d78e6947aa2a42a56de79e2ad94db7b9ab587038a29
2564
GandCrab.exe
C:\Users\admin\AppData\Roaming\Adobe\Acrobat\DC\JSCache\UAPRO-DECRYPT.html
html
MD5: 08c2da0ed1a1bf7ef89f736b9ed43bd2
SHA256: f233665b765c8159f5d39d78e6947aa2a42a56de79e2ad94db7b9ab587038a29
2564
GandCrab.exe
C:\Users\admin\AppData\Roaming\Adobe\Acrobat\DC\Forms\UAPRO-DECRYPT.html
html
MD5: 08c2da0ed1a1bf7ef89f736b9ed43bd2
SHA256: f233665b765c8159f5d39d78e6947aa2a42a56de79e2ad94db7b9ab587038a29
2564
GandCrab.exe
C:\Users\admin\AppData\Roaming\Adobe\Acrobat\DC\UAPRO-DECRYPT.html
html
MD5: 08c2da0ed1a1bf7ef89f736b9ed43bd2
SHA256: f233665b765c8159f5d39d78e6947aa2a42a56de79e2ad94db7b9ab587038a29
2564
GandCrab.exe
C:\Users\admin\AppData\UAPRO-DECRYPT.html
html
MD5: 08c2da0ed1a1bf7ef89f736b9ed43bd2
SHA256: f233665b765c8159f5d39d78e6947aa2a42a56de79e2ad94db7b9ab587038a29
2564
GandCrab.exe
C:\Users\admin\UAPRO-DECRYPT.html
html
MD5: 08c2da0ed1a1bf7ef89f736b9ed43bd2
SHA256: f233665b765c8159f5d39d78e6947aa2a42a56de79e2ad94db7b9ab587038a29
2564
GandCrab.exe
C:\Users\admin\.oracle_jre_usage\UAPRO-DECRYPT.html
html
MD5: 08c2da0ed1a1bf7ef89f736b9ed43bd2
SHA256: f233665b765c8159f5d39d78e6947aa2a42a56de79e2ad94db7b9ab587038a29
2564
GandCrab.exe
C:\Users\admin\AppData\Roaming\Adobe\Acrobat\UAPRO-DECRYPT.html
html
MD5: 08c2da0ed1a1bf7ef89f736b9ed43bd2
SHA256: f233665b765c8159f5d39d78e6947aa2a42a56de79e2ad94db7b9ab587038a29
2564
GandCrab.exe
C:\Users\admin\AppData\Roaming\Adobe\UAPRO-DECRYPT.html
html
MD5: 08c2da0ed1a1bf7ef89f736b9ed43bd2
SHA256: f233665b765c8159f5d39d78e6947aa2a42a56de79e2ad94db7b9ab587038a29
2564
GandCrab.exe
C:\Users\admin\AppData\Roaming\UAPRO-DECRYPT.html
html
MD5: 08c2da0ed1a1bf7ef89f736b9ed43bd2
SHA256: f233665b765c8159f5d39d78e6947aa2a42a56de79e2ad94db7b9ab587038a29
2564
GandCrab.exe
C:\Users\admin\.oracle_jre_usage\90737d32e3abaa4.timestamp.uapro
binary
MD5: 8a476e38df12951e9c870983ed5b28f4
SHA256: 12106092ace72ea530eed4681c9e79f556e9543f4f35ece41a1d3b6ea246791a
2564
GandCrab.exe
C:\Users\admin\.oracle_jre_usage\90737d32e3abaa4.timestamp
––
MD5:  ––
SHA256:  ––
2564
GandCrab.exe
C:\$Recycle.Bin\S-1-5-21-1302019708-1500728564-335382590-1000\UAPRO-DECRYPT.html
html
MD5: 08c2da0ed1a1bf7ef89f736b9ed43bd2
SHA256: f233665b765c8159f5d39d78e6947aa2a42a56de79e2ad94db7b9ab587038a29

Find more information of the staic content and download it at the full report

Network activity

HTTP(S) requests
3
TCP/UDP connections
6
DNS requests
5
Threats
0

HTTP requests

PID Process Method HTTP Code IP URL CN Type Size Reputation
2564 GandCrab.exe GET 302 217.160.0.234:80 http://www.billerimpex.com/ DE
html
malicious
2564 GandCrab.exe GET 301 217.70.184.50:80 http://www.macartegrise.eu/ FR
html
malicious
2564 GandCrab.exe GET –– 199.188.201.218:80 http://www.poketeg.com/ US
––
––
malicious

Download PCAP, analyze network streams, HTTP content and a lot more at the full report

Connections

PID Process IP ASN CN Reputation
2564 GandCrab.exe 217.160.0.234:80 1&1 Internet SE DE suspicious
2564 GandCrab.exe 217.160.0.234:443 1&1 Internet SE DE suspicious
2564 GandCrab.exe 217.70.184.50:80 GANDI SAS FR malicious
2564 GandCrab.exe 217.70.184.50:443 GANDI SAS FR malicious
2564 GandCrab.exe 199.188.201.218:80 Namecheap, Inc. US unknown

DNS requests

Domain IP Reputation
www.billerimpex.com 217.160.0.234
malicious
dns.msftncsi.com 131.107.255.255
whitelisted
www.macartegrise.eu 217.70.184.50
malicious
www.poketeg.com 199.188.201.218
malicious

Threats

No threats detected.

Debug output strings

No debug info.