General Info

File name

WANACRYPTOR.exe

Full analysis
https://app.any.run/tasks/3904a2ef-6e40-4277-b7be-4aab139e4767
Verdict
Malicious activity
Analysis date
7/18/2019, 03:35:32
OS:
Windows 7 Professional Service Pack 1 (build: 7601, 32 bit)
Tags:

ransomware

wannacry

wannacryptor

Indicators:

MIME:
application/x-dosexec
File info:
PE32 executable (GUI) Intel 80386, for MS Windows
MD5

84c82835a5d21bbcf75a61706d8ab549

SHA1

5ff465afaabcbf0150d1a3ab2c2e74f3a4426467

SHA256

ed01ebfbc9eb5bbea545af4d01bf5f1071661840480439c6e5babe8e080e41aa

SSDEEP

98304:QqPoBhz1aRxcSUDk36SAEdhvxWa9P593R8yAVp2g3x:QqPe1Cxcxk3ZAEUadzR8yc4gB

ANY.RUN is an interactive service which provides full access to the guest system. Information in this report could be distored by user actions and is provided for user acknowledgement as it is. ANY.RUN does not guarantee maliciousness or safety of the content.

Software environment set and analysis options

Launch configuration

Task duration
60 seconds
Additional time used
none
Fakenet option
off
Heavy Evaision option
off
MITM proxy
off
Route via Tor
on
Network geolocation
off
Privacy
Public submission
Autoconfirmation of UAC
off

Software preset

  • Internet Explorer 8.0.7601.17514
  • Adobe Acrobat Reader DC MUI (15.023.20070)
  • Adobe Flash Player 26 ActiveX (26.0.0.131)
  • Adobe Flash Player 26 NPAPI (26.0.0.131)
  • Adobe Flash Player 26 PPAPI (26.0.0.131)
  • Adobe Refresh Manager (1.8.0)
  • CCleaner (5.35)
  • FileZilla Client 3.36.0 (3.36.0)
  • Google Chrome (75.0.3770.100)
  • Google Update Helper (1.3.34.7)
  • Java 8 Update 92 (8.0.920.14)
  • Java Auto Updater (2.8.92.14)
  • Microsoft .NET Framework 4.7.2 (4.7.03062)
  • Microsoft Office Access MUI (English) 2010 (14.0.6029.1000)
  • Microsoft Office Access Setup Metadata MUI (English) 2010 (14.0.6029.1000)
  • Microsoft Office Excel MUI (English) 2010 (14.0.6029.1000)
  • Microsoft Office OneNote MUI (English) 2010 (14.0.6029.1000)
  • Microsoft Office Outlook MUI (English) 2010 (14.0.6029.1000)
  • Microsoft Office PowerPoint MUI (English) 2010 (14.0.6029.1000)
  • Microsoft Office Professional 2010 (14.0.6029.1000)
  • Microsoft Office Proof (English) 2010 (14.0.6029.1000)
  • Microsoft Office Proof (French) 2010 (14.0.6029.1000)
  • Microsoft Office Proof (Spanish) 2010 (14.0.6029.1000)
  • Microsoft Office Proofing (English) 2010 (14.0.6029.1000)
  • Microsoft Office Publisher MUI (English) 2010 (14.0.6029.1000)
  • Microsoft Office Shared MUI (English) 2010 (14.0.6029.1000)
  • Microsoft Office Shared Setup Metadata MUI (English) 2010 (14.0.6029.1000)
  • Microsoft Office Single Image 2010 (14.0.6029.1000)
  • Microsoft Office Word MUI (English) 2010 (14.0.6029.1000)
  • Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.6161 (9.0.30729.6161)
  • Microsoft Visual C++ 2010 x86 Redistributable - 10.0.40219 (10.0.40219)
  • Microsoft Visual C++ 2013 Redistributable (x86) - 12.0.30501 (12.0.30501.0)
  • Microsoft Visual C++ 2013 x86 Additional Runtime - 12.0.21005 (12.0.21005)
  • Microsoft Visual C++ 2013 x86 Minimum Runtime - 12.0.21005 (12.0.21005)
  • Microsoft Visual C++ 2015-2019 Redistributable (x86) - 14.21.27702 (14.21.27702.2)
  • Microsoft Visual C++ 2019 X86 Additional Runtime - 14.21.27702 (14.21.27702)
  • Microsoft Visual C++ 2019 X86 Minimum Runtime - 14.21.27702 (14.21.27702)
  • Mozilla Firefox 67.0.4 (x86 en-US) (67.0.4)
  • Notepad++ (32-bit x86) (7.5.1)
  • Opera 12.15 (12.15.1748)
  • Skype version 8.29 (8.29)
  • Update for Microsoft .NET Framework 4.7.2 (KB4087364) (1)
  • VLC media player (2.2.6)
  • WinRAR 5.60 (32-bit) (5.60.0)

Hotfixes

  • Client LanguagePack Package
  • Client Refresh LanguagePack Package
  • CodecPack Basic Package
  • Foundation Package
  • IE Troubleshooters Package
  • InternetExplorer Optional Package
  • KB2534111
  • KB2999226
  • KB4019990
  • KB976902
  • LocalPack AU Package
  • LocalPack CA Package
  • LocalPack GB Package
  • LocalPack US Package
  • LocalPack ZA Package
  • ProfessionalEdition
  • UltimateEdition

Behavior activities

MALICIOUS SUSPICIOUS INFO
Loads the Task Scheduler COM API
  • wbengine.exe (PID: 3700)
Deletes shadow copies
  • cmd.exe (PID: 1224)
Starts BCDEDIT.EXE to disable recovery
  • cmd.exe (PID: 1224)
Application was dropped or rewritten from another process Loads dropped or rewritten executable
  • taskhsvc.exe (PID: 1672)
Changes the autorun value in the registry
  • reg.exe (PID: 3368)
WannaCry Ransomware was detected
  • WANACRYPTOR.exe (PID: 3668)
  • cmd.exe (PID: 3816)
Writes file to Word startup folder
  • WANACRYPTOR.exe (PID: 3668)
Modifies files in Chrome extension folder
  • WANACRYPTOR.exe (PID: 3668)
Dropped file may contain instructions of ransomware
  • WANACRYPTOR.exe (PID: 3668)
Actions looks like stealing of personal data
  • WANACRYPTOR.exe (PID: 3668)
Executed as Windows Service
  • vds.exe (PID: 1832)
  • vssvc.exe (PID: 3548)
  • wbengine.exe (PID: 3700)
Low-level read access rights to disk partition
  • vds.exe (PID: 1832)
  • wbengine.exe (PID: 3700)
Creates files in the Windows directory
  • wbadmin.exe (PID: 3088)
Executed via COM
  • vdsldr.exe (PID: 3504)
Starts CMD.EXE for commands execution Uses REG.EXE to modify Windows registry
  • cmd.exe (PID: 1260)
Executable content was dropped or overwritten Creates files in the user directory
  • taskhsvc.exe (PID: 1672)
  • WANACRYPTOR.exe (PID: 3668)
Creates files in the program directory
  • WANACRYPTOR.exe (PID: 3668)
Executes scripts
  • cmd.exe (PID: 4080)
Uses ATTRIB.EXE to modify file attributes
  • WANACRYPTOR.exe (PID: 3668)
Creates files like Ransomware instruction
  • WANACRYPTOR.exe (PID: 3668)
Uses ICACLS.EXE to modify access control list
  • WANACRYPTOR.exe (PID: 3668)
Dropped object may contain Bitcoin addresses
  • taskhsvc.exe (PID: 1672)
  • WANACRYPTOR.exe (PID: 3668)
Dropped object may contain URL to Tor Browser
  • WANACRYPTOR.exe (PID: 3668)
Dropped object may contain TOR URL's
  • WANACRYPTOR.exe (PID: 3668)

Find more information about signature artifacts and mapping to MITRE ATT&CK™ MATRIX at the full report

Static information

TRiD
.exe
|   Win32 Executable MS Visual C++ (generic) (42.2%)
.exe
|   Win64 Executable (generic) (37.3%)
.dll
|   Win32 Dynamic Link Library (generic) (8.8%)
.exe
|   Win32 Executable (generic) (6%)
.exe
|   Generic Win/DOS Executable (2.7%)
EXIF
EXE
MachineType:
Intel 386 or later, and compatibles
TimeStamp:
2010:11:20 10:05:05+01:00
PEType:
PE32
LinkerVersion:
6
CodeSize:
28672
InitializedDataSize:
3481600
UninitializedDataSize:
null
EntryPoint:
0x77ba
OSVersion:
4
ImageVersion:
null
SubsystemVersion:
4
Subsystem:
Windows GUI
FileVersionNumber:
6.1.7601.17514
ProductVersionNumber:
6.1.7601.17514
FileFlagsMask:
0x003f
FileFlags:
(none)
FileOS:
Windows NT 32-bit
ObjectFileType:
Dynamic link library
FileSubtype:
null
LanguageCode:
English (U.S.)
CharacterSet:
Unicode
CompanyName:
Microsoft Corporation
FileDescription:
DiskPart
FileVersion:
6.1.7601.17514 (win7sp1_rtm.101119-1850)
InternalName:
diskpart.exe
LegalCopyright:
© Microsoft Corporation. All rights reserved.
OriginalFileName:
diskpart.exe
ProductName:
Microsoft® Windows® Operating System
ProductVersion:
6.1.7601.17514
Summary
Architecture:
IMAGE_FILE_MACHINE_I386
Subsystem:
IMAGE_SUBSYSTEM_WINDOWS_GUI
Compilation Date:
20-Nov-2010 09:05:05
Detected languages
English - United States
CompanyName:
Microsoft Corporation
FileDescription:
DiskPart
FileVersion:
6.1.7601.17514 (win7sp1_rtm.101119-1850)
InternalName:
diskpart.exe
LegalCopyright:
© Microsoft Corporation. All rights reserved.
OriginalFilename:
diskpart.exe
ProductName:
Microsoft® Windows® Operating System
ProductVersion:
6.1.7601.17514
DOS Header
Magic number:
MZ
Bytes on last page of file:
0x0090
Pages in file:
0x0003
Relocations:
0x0000
Size of header:
0x0004
Min extra paragraphs:
0x0000
Max extra paragraphs:
0xFFFF
Initial SS value:
0x0000
Initial SP value:
0x00B8
Checksum:
0x0000
Initial IP value:
0x0000
Initial CS value:
0x0000
Overlay number:
0x0000
OEM identifier:
0x0000
OEM information:
0x0000
Address of NE header:
0x000000F8
PE Headers
Signature:
PE
Machine:
IMAGE_FILE_MACHINE_I386
Number of sections:
4
Time date stamp:
20-Nov-2010 09:05:05
Pointer to Symbol Table:
0x00000000
Number of symbols:
0
Size of Optional Header:
0x00E0
Characteristics
IMAGE_FILE_32BIT_MACHINE
IMAGE_FILE_EXECUTABLE_IMAGE
IMAGE_FILE_LINE_NUMS_STRIPPED
IMAGE_FILE_LOCAL_SYMS_STRIPPED
IMAGE_FILE_RELOCS_STRIPPED
Sections
Name Virtual Address Virtual Size Raw Size Charateristics Entropy
.text 0x00001000 0x000069B0 0x00007000 IMAGE_SCN_CNT_CODE,IMAGE_SCN_MEM_EXECUTE,IMAGE_SCN_MEM_READ 6.40424
.rdata 0x00008000 0x00005F70 0x00006000 IMAGE_SCN_CNT_INITIALIZED_DATA,IMAGE_SCN_MEM_READ 6.66357
.data 0x0000E000 0x00001958 0x00002000 IMAGE_SCN_CNT_INITIALIZED_DATA,IMAGE_SCN_MEM_READ,IMAGE_SCN_MEM_WRITE 4.45575
.rsrc 0x00010000 0x00349FA0 0x0034A000 IMAGE_SCN_CNT_INITIALIZED_DATA,IMAGE_SCN_MEM_READ 7.99987
Resources
1

2058

Imports
    KERNEL32.dll

    USER32.dll

    ADVAPI32.dll

    MSVCRT.dll

Exports

    No exports.

Screenshots

Processes

Total processes
70
Monitored processes
24
Malicious processes
5
Suspicious processes
2

Behavior graph

+
drop and start drop and start drop and start drop and start start drop and start #WANNACRY wanacryptor.exe attrib.exe no specs icacls.exe no specs taskdl.exe no specs cmd.exe no specs cscript.exe no specs @[email protected] #WANNACRY cmd.exe no specs @[email protected] no specs taskhsvc.exe taskdl.exe no specs @[email protected] cmd.exe no specs reg.exe cmd.exe vssadmin.exe no specs vssvc.exe no specs wmic.exe no specs bcdedit.exe no specs bcdedit.exe no specs wbadmin.exe no specs wbengine.exe no specs vdsldr.exe no specs vds.exe no specs
Specs description
Program did not start
Integrity level elevation
Task сontains an error or was rebooted
Process has crashed
Task contains several apps running
Executable file was dropped
Debug information is available
Process was injected
Network attacks were detected
Application downloaded the executable file
Actions similar to stealing personal data
Behavior similar to exploiting the vulnerability
Inspected object has sucpicious PE structure
File is detected by antivirus software
CPU overrun
RAM overrun
Process starts the services
Process was added to the startup
Behavior similar to spam
Low-level access to the HDD
Probably Tor was used
System was rebooted
Connects to the network
Known threat

Process information

Click at the process to see the details.

PID
3668
CMD
"C:\Users\admin\AppData\Local\Temp\WANACRYPTOR.exe"
Path
C:\Users\admin\AppData\Local\Temp\WANACRYPTOR.exe
Indicators
Parent process
––
User
admin
Integrity Level
MEDIUM
Version:
Company
Microsoft Corporation
Description
DiskPart
Version
6.1.7601.17514 (win7sp1_rtm.101119-1850)
Modules
Image
c:\users\admin\appdata\local\temp\wanacryptor.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\imm32.dll
c:\windows\system32\msctf.dll
c:\windows\system32\apphelp.dll
c:\windows\system32\icacls.exe
c:\windows\system32\cryptsp.dll
c:\windows\system32\rsaenh.dll
c:\windows\system32\cryptbase.dll
c:\windows\system32\crypt32.dll
c:\windows\system32\shell32.dll
c:\windows\system32\shlwapi.dll
c:\windows\system32\msvcp60.dll
c:\windows\system32\ntmarta.dll
c:\windows\system32\wldap32.dll
c:\users\admin\appdata\local\temp\taskdl.exe
c:\windows\system32\ole32.dll
c:\windows\system32\sspicli.dll
c:\windows\system32\iconcodecservice.dll
c:\windows\system32\windowscodecs.dll
c:\users\admin\appdata\local\temp\@[email protected]

PID
2260
CMD
attrib +h .
Path
C:\Windows\system32\attrib.exe
Indicators
No indicators
Parent process
WANACRYPTOR.exe
User
admin
Integrity Level
MEDIUM
Exit code
0
Version:
Company
Microsoft Corporation
Description
Attribute Utility
Version
6.1.7600.16385 (win7_rtm.090713-1255)
Modules
Image
c:\windows\system32\attrib.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\ulib.dll
c:\windows\system32\user32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\imm32.dll
c:\windows\system32\msctf.dll

PID
580
CMD
icacls . /grant Everyone:F /T /C /Q
Path
C:\Windows\system32\icacls.exe
Indicators
No indicators
Parent process
WANACRYPTOR.exe
User
admin
Integrity Level
MEDIUM
Exit code
0
Version:
Company
Microsoft Corporation
Description
Version
6.1.7600.16385 (win7_rtm.090713-1255)
Modules
Image
c:\windows\system32\icacls.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\ntmarta.dll
c:\windows\system32\wldap32.dll

PID
3544
CMD
taskdl.exe
Path
C:\Users\admin\AppData\Local\Temp\taskdl.exe
Indicators
No indicators
Parent process
WANACRYPTOR.exe
User
admin
Integrity Level
MEDIUM
Exit code
0
Version:
Company
Microsoft Corporation
Description
SQL Client Configuration Utility EXE
Version
6.1.7600.16385 (win7_rtm.090713-1255)
Modules
Image
c:\users\admin\appdata\local\temp\taskdl.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvcp60.dll
c:\windows\system32\msvcrt.dll

PID
4080
CMD
cmd /c 251471563413751.bat
Path
C:\Windows\system32\cmd.exe
Indicators
No indicators
Parent process
WANACRYPTOR.exe
User
admin
Integrity Level
MEDIUM
Exit code
1
Version:
Company
Microsoft Corporation
Description
Windows Command Processor
Version
6.1.7601.17514 (win7sp1_rtm.101119-1850)
Modules
Image
c:\windows\system32\cmd.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\winbrand.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\imm32.dll
c:\windows\system32\msctf.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\apphelp.dll
c:\windows\system32\cscript.exe

PID
2800
CMD
cscript.exe //nologo m.vbs
Path
C:\Windows\system32\cscript.exe
Indicators
No indicators
Parent process
cmd.exe
User
admin
Integrity Level
MEDIUM
Exit code
0
Version:
Company
Microsoft Corporation
Description
Microsoft ® Console Based Script Host
Version
5.8.7600.16385
Modules
Image
c:\windows\system32\cscript.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\oleaut32.dll
c:\windows\system32\ole32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\user32.dll
c:\windows\system32\usp10.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\version.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\sechost.dll
c:\windows\system32\imm32.dll
c:\windows\system32\msctf.dll
c:\windows\system32\cryptbase.dll
c:\windows\system32\sxs.dll
c:\windows\system32\clbcatq.dll
c:\windows\system32\vbscript.dll
c:\windows\system32\wintrust.dll
c:\windows\system32\crypt32.dll
c:\windows\system32\msasn1.dll
c:\windows\system32\cryptsp.dll
c:\windows\system32\rsaenh.dll
c:\windows\system32\msisip.dll
c:\windows\system32\wshext.dll
c:\windows\winsxs\x86_microsoft.windows.common-controls_6595b64144ccf1df_5.82.7601.17514_none_ec83dffa859149af\comctl32.dll
c:\windows\system32\shell32.dll
c:\windows\system32\shlwapi.dll
c:\windows\system32\scrobj.dll
c:\windows\system32\wshom.ocx
c:\windows\system32\mpr.dll
c:\windows\system32\scrrun.dll
c:\windows\system32\propsys.dll
c:\windows\system32\ntmarta.dll
c:\windows\system32\wldap32.dll
c:\windows\winsxs\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_41e6975e2bd6f2b2\comctl32.dll
c:\windows\system32\setupapi.dll
c:\windows\system32\cfgmgr32.dll
c:\windows\system32\devobj.dll
c:\windows\system32\profapi.dll
c:\windows\system32\apphelp.dll
c:\windows\system32\shdocvw.dll
c:\windows\system32\linkinfo.dll
c:\windows\system32\ntshrui.dll
c:\windows\system32\srvcli.dll
c:\windows\system32\cscapi.dll
c:\windows\system32\slc.dll
c:\users\admin\appdata\local\temp\@[email protected]
c:\windows\system32\netutils.dll

PID
3708
CMD
@[email protected] co
Path
C:\Users\admin\AppData\Local\Temp\@[email protected]
Indicators
Parent process
WANACRYPTOR.exe
User
admin
Integrity Level
MEDIUM
Version:
Company
Microsoft Corporation
Description
Load PerfMon Counters
Version
6.1.7600.16385 (win7_rtm.090713-1255)
Modules
Image
c:\users\admin\appdata\local\temp\@[email protected]
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\mfc42.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\ole32.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\oleaut32.dll
c:\windows\system32\odbc32.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\sechost.dll
c:\windows\system32\shell32.dll
c:\windows\system32\shlwapi.dll
c:\windows\winsxs\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_41e6975e2bd6f2b2\comctl32.dll
c:\windows\system32\urlmon.dll
c:\windows\system32\wininet.dll
c:\windows\system32\iertutil.dll
c:\windows\system32\crypt32.dll
c:\windows\system32\msasn1.dll
c:\windows\system32\msvcp60.dll
c:\windows\system32\ws2_32.dll
c:\windows\system32\nsi.dll
c:\windows\system32\imm32.dll
c:\windows\system32\msctf.dll
c:\windows\system32\odbcint.dll
c:\windows\system32\riched32.dll
c:\windows\system32\riched20.dll
c:\windows\system32\uxtheme.dll
c:\windows\system32\mswsock.dll
c:\windows\system32\wshtcpip.dll
c:\windows\system32\apphelp.dll
c:\users\admin\appdata\local\temp\taskdata\tor\taskhsvc.exe

PID
3816
CMD
cmd.exe /c start /b @[email protected] vs
Path
C:\Windows\system32\cmd.exe
Indicators
Parent process
WANACRYPTOR.exe
User
admin
Integrity Level
MEDIUM
Exit code
0
Version:
Company
Microsoft Corporation
Description
Windows Command Processor
Version
6.1.7601.17514 (win7sp1_rtm.101119-1850)
Modules
Image
c:\windows\system32\cmd.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\winbrand.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\imm32.dll
c:\windows\system32\msctf.dll
c:\windows\system32\apphelp.dll
c:\users\admin\appdata\local\temp\@[email protected]

PID
936
CMD
@[email protected] vs
Path
C:\Users\admin\AppData\Local\Temp\@[email protected]
Indicators
No indicators
Parent process
cmd.exe
User
admin
Integrity Level
MEDIUM
Exit code
0
Version:
Company
Microsoft Corporation
Description
Load PerfMon Counters
Version
6.1.7600.16385 (win7_rtm.090713-1255)
Modules
Image
c:\users\admin\appdata\local\temp\@[email protected]
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\mfc42.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\user32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\ole32.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\oleaut32.dll
c:\windows\system32\odbc32.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\sechost.dll
c:\windows\system32\shell32.dll
c:\windows\system32\shlwapi.dll
c:\windows\winsxs\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_41e6975e2bd6f2b2\comctl32.dll
c:\windows\system32\wininet.dll
c:\windows\system32\iertutil.dll
c:\windows\system32\crypt32.dll
c:\windows\system32\msasn1.dll
c:\windows\system32\urlmon.dll
c:\windows\system32\msvcp60.dll
c:\windows\system32\ws2_32.dll
c:\windows\system32\nsi.dll
c:\windows\system32\imm32.dll
c:\windows\system32\msctf.dll
c:\windows\system32\odbcint.dll
c:\windows\system32\riched32.dll
c:\windows\system32\riched20.dll
c:\windows\system32\uxtheme.dll
c:\windows\system32\cryptbase.dll
c:\windows\system32\propsys.dll
c:\windows\system32\apphelp.dll
c:\windows\system32\clbcatq.dll
c:\windows\system32\ieframe.dll
c:\windows\system32\psapi.dll
c:\windows\system32\oleacc.dll
c:\windows\system32\setupapi.dll
c:\windows\system32\cfgmgr32.dll
c:\windows\system32\devobj.dll
c:\windows\system32\ntmarta.dll
c:\windows\system32\wldap32.dll
c:\windows\system32\profapi.dll
c:\windows\system32\sspicli.dll
c:\windows\system32\mpr.dll
c:\windows\system32\sfc.dll
c:\windows\system32\sfc_os.dll

PID
1672
CMD
TaskData\Tor\taskhsvc.exe
Path
C:\Users\admin\AppData\Local\Temp\TaskData\Tor\taskhsvc.exe
Indicators
Parent process
@[email protected]
User
admin
Integrity Level
MEDIUM
Version:
Company
Description
Version
Modules
Image
c:\users\admin\appdata\local\temp\taskdata\tor\taskhsvc.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\users\admin\appdata\local\temp\taskdata\tor\libevent-2-0-5.dll
c:\users\admin\appdata\local\temp\taskdata\tor\libssp-0.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\users\admin\appdata\local\temp\taskdata\tor\libgcc_s_sjlj-1.dll
c:\windows\system32\shell32.dll
c:\windows\system32\shlwapi.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\user32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\ws2_32.dll
c:\windows\system32\nsi.dll
c:\users\admin\appdata\local\temp\taskdata\tor\libeay32.dll
c:\users\admin\appdata\local\temp\taskdata\tor\ssleay32.dll
c:\users\admin\appdata\local\temp\taskdata\tor\zlib1.dll
c:\windows\system32\cryptsp.dll
c:\windows\system32\rsaenh.dll
c:\windows\system32\cryptbase.dll
c:\windows\system32\imm32.dll
c:\windows\system32\msctf.dll
c:\windows\system32\netapi32.dll
c:\windows\system32\netutils.dll
c:\windows\system32\srvcli.dll
c:\windows\system32\wkscli.dll
c:\windows\system32\ole32.dll
c:\windows\winsxs\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_41e6975e2bd6f2b2\comctl32.dll
c:\windows\system32\oleaut32.dll
c:\windows\system32\setupapi.dll
c:\windows\system32\cfgmgr32.dll
c:\windows\system32\devobj.dll
c:\windows\system32\clbcatq.dll
c:\windows\system32\propsys.dll
c:\windows\system32\ntmarta.dll
c:\windows\system32\wldap32.dll
c:\windows\system32\mswsock.dll
c:\windows\system32\wshtcpip.dll
c:\windows\system32\iphlpapi.dll
c:\windows\system32\winnsi.dll
c:\windows\system32\dhcpcsvc6.dll
c:\windows\system32\dhcpcsvc.dll

PID
3984
CMD
taskdl.exe
Path
C:\Users\admin\AppData\Local\Temp\taskdl.exe
Indicators
No indicators
Parent process
WANACRYPTOR.exe
User
admin
Integrity Level
MEDIUM
Exit code
0
Version:
Company
Microsoft Corporation
Description
SQL Client Configuration Utility EXE
Version
6.1.7600.16385 (win7_rtm.090713-1255)
Modules
Image
c:\users\admin\appdata\local\temp\taskdl.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvcp60.dll
c:\windows\system32\msvcrt.dll

PID
2628
CMD
@[email protected]
Path
C:\Users\admin\AppData\Local\Temp\@[email protected]
Indicators
Parent process
WANACRYPTOR.exe
User
admin
Integrity Level
MEDIUM
Version:
Company
Microsoft Corporation
Description
Load PerfMon Counters
Version
6.1.7600.16385 (win7_rtm.090713-1255)
Modules
Image
c:\users\admin\appdata\local\temp\@[email protected]
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\mfc42.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\ole32.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\oleaut32.dll
c:\windows\system32\odbc32.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\sechost.dll
c:\windows\system32\shell32.dll
c:\windows\system32\shlwapi.dll
c:\windows\winsxs\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_41e6975e2bd6f2b2\comctl32.dll
c:\windows\system32\urlmon.dll
c:\windows\system32\wininet.dll
c:\windows\system32\iertutil.dll
c:\windows\system32\crypt32.dll
c:\windows\system32\msasn1.dll
c:\windows\system32\msvcp60.dll
c:\windows\system32\ws2_32.dll
c:\windows\system32\nsi.dll
c:\windows\system32\imm32.dll
c:\windows\system32\msctf.dll
c:\windows\system32\odbcint.dll
c:\windows\system32\riched32.dll
c:\windows\system32\riched20.dll
c:\windows\system32\uxtheme.dll
c:\windows\system32\iconcodecservice.dll
c:\windows\system32\windowscodecs.dll
c:\windows\system32\msls31.dll
c:\windows\system32\cryptbase.dll
c:\windows\system32\clbcatq.dll
c:\windows\system32\mswsock.dll
c:\windows\system32\wshtcpip.dll

PID
1260
CMD
cmd.exe /c reg add HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Run /v "yyibsxxiapw107" /t REG_SZ /d "\"C:\Users\admin\AppData\Local\Temp\tasksche.exe\"" /f
Path
C:\Windows\system32\cmd.exe
Indicators
No indicators
Parent process
WANACRYPTOR.exe
User
admin
Integrity Level
MEDIUM
Exit code
0
Version:
Company
Microsoft Corporation
Description
Windows Command Processor
Version
6.1.7601.17514 (win7sp1_rtm.101119-1850)
Modules
Image
c:\windows\system32\cmd.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\winbrand.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\imm32.dll
c:\windows\system32\msctf.dll
c:\windows\system32\apphelp.dll

PID
3368
CMD
reg add HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Run /v "yyibsxxiapw107" /t REG_SZ /d "\"C:\Users\admin\AppData\Local\Temp\tasksche.exe\"" /f
Path
C:\Windows\system32\reg.exe
Indicators
Parent process
cmd.exe
User
admin
Integrity Level
MEDIUM
Exit code
0
Version:
Company
Microsoft Corporation
Description
Registry Console Tool
Version
6.1.7600.16385 (win7_rtm.090713-1255)
Modules
Image
c:\windows\system32\reg.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\ws2_32.dll
c:\windows\system32\nsi.dll
c:\windows\system32\shlwapi.dll
c:\windows\system32\imm32.dll
c:\windows\system32\msctf.dll

PID
1224
CMD
"C:\Windows\System32\cmd.exe" /c vssadmin delete shadows /all /quiet & wmic shadowcopy delete & bcdedit /set {default} bootstatuspolicy ignoreallfailures & bcdedit /set {default} recoveryenabled no & wbadmin delete catalog -quiet
Path
C:\Windows\System32\cmd.exe
Indicators
Parent process
@[email protected]
User
admin
Integrity Level
HIGH
Exit code
0
Version:
Company
Microsoft Corporation
Description
Windows Command Processor
Version
6.1.7601.17514 (win7sp1_rtm.101119-1850)
Modules
Image
c:\windows\system32\cmd.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\winbrand.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\user32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\imm32.dll
c:\windows\system32\msctf.dll
c:\windows\system32\apphelp.dll
c:\windows\system32\vssadmin.exe
c:\windows\system32\wbem\wmic.exe
c:\windows\system32\wbadmin.exe

PID
3316
CMD
vssadmin delete shadows /all /quiet
Path
C:\Windows\system32\vssadmin.exe
Indicators
No indicators
Parent process
cmd.exe
User
admin
Integrity Level
HIGH
Exit code
0
Version:
Company
Microsoft Corporation
Description
Command Line Interface for Microsoft® Volume Shadow Copy Service
Version
6.1.7600.16385 (win7_rtm.090713-1255)
Modules
Image
c:\windows\system32\vssadmin.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\atl.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\vsstrace.dll
c:\windows\system32\ole32.dll
c:\windows\system32\oleaut32.dll
c:\windows\system32\vssapi.dll
c:\windows\system32\imm32.dll
c:\windows\system32\msctf.dll
c:\windows\system32\cryptbase.dll
c:\windows\system32\clbcatq.dll
c:\windows\system32\cryptsp.dll
c:\windows\system32\rsaenh.dll
c:\windows\system32\rpcrtremote.dll
c:\windows\system32\vss_ps.dll

PID
3548
CMD
C:\Windows\system32\vssvc.exe
Path
C:\Windows\system32\vssvc.exe
Indicators
No indicators
Parent process
––
User
SYSTEM
Integrity Level
SYSTEM
Version:
Company
Microsoft Corporation
Description
Microsoft® Volume Shadow Copy Service
Version
6.1.7600.16385 (win7_rtm.090713-1255)
Modules
Image
c:\windows\system32\vssvc.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\atl.dll
c:\windows\system32\ole32.dll
c:\windows\system32\shlwapi.dll
c:\windows\system32\oleaut32.dll
c:\windows\system32\vssapi.dll
c:\windows\system32\vsstrace.dll
c:\windows\system32\netapi32.dll
c:\windows\system32\netutils.dll
c:\windows\system32\srvcli.dll
c:\windows\system32\wkscli.dll
c:\windows\system32\samcli.dll
c:\windows\system32\clusapi.dll
c:\windows\system32\cryptdll.dll
c:\windows\system32\xolehlp.dll
c:\windows\system32\version.dll
c:\windows\system32\resutils.dll
c:\windows\system32\setupapi.dll
c:\windows\system32\cfgmgr32.dll
c:\windows\system32\devobj.dll
c:\windows\system32\authz.dll
c:\windows\system32\virtdisk.dll
c:\windows\system32\fltlib.dll
c:\windows\system32\imm32.dll
c:\windows\system32\msctf.dll
c:\windows\system32\cryptbase.dll
c:\windows\system32\cryptsp.dll
c:\windows\system32\rsaenh.dll
c:\windows\system32\rpcrtremote.dll
c:\windows\system32\clbcatq.dll
c:\windows\system32\vss_ps.dll
c:\windows\system32\samlib.dll
c:\windows\system32\es.dll
c:\windows\system32\propsys.dll
c:\windows\system32\catsrvut.dll
c:\windows\system32\mfcsubs.dll

PID
3940
CMD
wmic shadowcopy delete
Path
C:\Windows\System32\Wbem\WMIC.exe
Indicators
No indicators
Parent process
cmd.exe
User
admin
Integrity Level
HIGH
Exit code
0
Version:
Company
Microsoft Corporation
Description
WMI Commandline Utility
Version
6.1.7600.16385 (win7_rtm.090713-1255)
Modules
Image
c:\windows\system32\wbem\wmic.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\ole32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\user32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\oleaut32.dll
c:\windows\system32\framedynos.dll
c:\windows\system32\sspicli.dll
c:\windows\system32\wtsapi32.dll
c:\windows\system32\shlwapi.dll
c:\windows\system32\ws2_32.dll
c:\windows\system32\nsi.dll
c:\windows\system32\secur32.dll
c:\windows\system32\iphlpapi.dll
c:\windows\system32\winnsi.dll
c:\windows\system32\imm32.dll
c:\windows\system32\msctf.dll
c:\windows\system32\cryptbase.dll
c:\windows\system32\clbcatq.dll
c:\windows\system32\wbem\wbemprox.dll
c:\windows\system32\wbemcomn.dll
c:\windows\system32\msxml3.dll
c:\windows\system32\urlmon.dll
c:\windows\system32\wininet.dll
c:\windows\system32\iertutil.dll
c:\windows\system32\crypt32.dll
c:\windows\system32\msasn1.dll
c:\windows\winsxs\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_41e6975e2bd6f2b2\comctl32.dll
c:\windows\system32\shell32.dll
c:\windows\system32\profapi.dll
c:\windows\system32\ntmarta.dll
c:\windows\system32\wldap32.dll
c:\windows\system32\dnsapi.dll
c:\windows\system32\cryptsp.dll
c:\windows\system32\rsaenh.dll
c:\windows\system32\rpcrtremote.dll
c:\program files\common files\microsoft shared\office14\msoxmlmf.dll
c:\windows\winsxs\x86_microsoft.vc90.crt_1fc8b3b9a1e18e3b_9.0.30729.6161_none_50934f2ebcb7eb57\msvcr90.dll
c:\windows\system32\wbem\wbemsvc.dll
c:\windows\system32\wbem\fastprox.dll
c:\windows\system32\ntdsapi.dll

PID
3104
CMD
bcdedit /set {default} bootstatuspolicy ignoreallfailures
Path
C:\Windows\system32\bcdedit.exe
Indicators
No indicators
Parent process
cmd.exe
User
admin
Integrity Level
HIGH
Exit code
0
Version:
Company
Microsoft Corporation
Description
Boot Configuration Data Editor
Version
6.1.7601.17514 (win7sp1_rtm.101119-1850)
Modules
Image
c:\windows\system32\bcdedit.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll

PID
2144
CMD
bcdedit /set {default} recoveryenabled no
Path
C:\Windows\system32\bcdedit.exe
Indicators
No indicators
Parent process
cmd.exe
User
admin
Integrity Level
HIGH
Exit code
0
Version:
Company
Microsoft Corporation
Description
Boot Configuration Data Editor
Version
6.1.7601.17514 (win7sp1_rtm.101119-1850)
Modules
Image
c:\windows\system32\bcdedit.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll

PID
3088
CMD
wbadmin delete catalog -quiet
Path
C:\Windows\system32\wbadmin.exe
Indicators
No indicators
Parent process
cmd.exe
User
admin
Integrity Level
HIGH
Exit code
0
Version:
Company
Microsoft Corporation
Description
Command Line Interface for Microsoft® BLB Backup
Version
6.1.7600.16385 (win7_rtm.090713-1255)
Modules
Image
c:\windows\system32\wbadmin.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\ole32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\user32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\oleaut32.dll
c:\windows\system32\setupapi.dll
c:\windows\system32\cfgmgr32.dll
c:\windows\system32\devobj.dll
c:\windows\system32\slc.dll
c:\windows\system32\credui.dll
c:\windows\system32\imm32.dll
c:\windows\system32\msctf.dll
c:\windows\winsxs\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_41e6975e2bd6f2b2\comctl32.dll
c:\windows\system32\shlwapi.dll
c:\windows\system32\cryptbase.dll
c:\windows\system32\clbcatq.dll
c:\windows\system32\cryptsp.dll
c:\windows\system32\rsaenh.dll
c:\windows\system32\rpcrtremote.dll
c:\windows\system32\blb_ps.dll

PID
3700
CMD
"C:\Windows\system32\wbengine.exe"
Path
C:\Windows\system32\wbengine.exe
Indicators
No indicators
Parent process
––
User
SYSTEM
Integrity Level
SYSTEM
Version:
Company
Microsoft Corporation
Description
Microsoft® Block Level Backup Engine Service EXE
Version
6.1.7600.16385 (win7_rtm.090713-1255)
Modules
Image
c:\windows\system32\wbengine.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\ole32.dll
c:\windows\system32\oleaut32.dll
c:\windows\system32\vssapi.dll
c:\windows\system32\atl.dll
c:\windows\system32\vsstrace.dll
c:\windows\system32\setupapi.dll
c:\windows\system32\cfgmgr32.dll
c:\windows\system32\devobj.dll
c:\windows\system32\netapi32.dll
c:\windows\system32\netutils.dll
c:\windows\system32\srvcli.dll
c:\windows\system32\wkscli.dll
c:\windows\system32\xmllite.dll
c:\windows\system32\bcrypt.dll
c:\windows\system32\virtdisk.dll
c:\windows\system32\fltlib.dll
c:\windows\system32\clusapi.dll
c:\windows\system32\cryptdll.dll
c:\windows\system32\imm32.dll
c:\windows\system32\msctf.dll
c:\windows\system32\cryptbase.dll
c:\windows\system32\bcryptprimitives.dll
c:\windows\system32\fveapi.dll
c:\windows\system32\tbs.dll
c:\windows\system32\fvecerts.dll
c:\windows\system32\crypt32.dll
c:\windows\system32\msasn1.dll
c:\windows\system32\logoncli.dll
c:\windows\system32\cscapi.dll
c:\windows\system32\clbcatq.dll
c:\windows\system32\cryptsp.dll
c:\windows\system32\rsaenh.dll
c:\windows\system32\rpcrtremote.dll
c:\windows\system32\blb_ps.dll
c:\windows\system32\vds_ps.dll
c:\windows\system32\taskschd.dll
c:\windows\system32\sspicli.dll

PID
3504
CMD
C:\Windows\System32\vdsldr.exe -Embedding
Path
C:\Windows\System32\vdsldr.exe
Indicators
No indicators
Parent process
––
User
SYSTEM
Integrity Level
SYSTEM
Exit code
0
Version:
Company
Microsoft Corporation
Description
Virtual Disk Service Loader
Version
6.1.7600.16385 (win7_rtm.090713-1255)
Modules
Image
c:\windows\system32\vdsldr.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\atl.dll
c:\windows\system32\ole32.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\vdsutil.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\sechost.dll
c:\windows\system32\oleaut32.dll
c:\windows\system32\setupapi.dll
c:\windows\system32\cfgmgr32.dll
c:\windows\system32\devobj.dll
c:\windows\system32\netapi32.dll
c:\windows\system32\netutils.dll
c:\windows\system32\srvcli.dll
c:\windows\system32\wkscli.dll
c:\windows\system32\ws2_32.dll
c:\windows\system32\nsi.dll
c:\windows\system32\imm32.dll
c:\windows\system32\msctf.dll
c:\windows\system32\cryptbase.dll
c:\windows\system32\clbcatq.dll
c:\windows\system32\cryptsp.dll
c:\windows\system32\rsaenh.dll
c:\windows\system32\rpcrtremote.dll
c:\windows\system32\vds_ps.dll

PID
1832
CMD
C:\Windows\System32\vds.exe
Path
C:\Windows\System32\vds.exe
Indicators
No indicators
Parent process
––
User
SYSTEM
Integrity Level
SYSTEM
Version:
Company
Microsoft Corporation
Description
Virtual Disk Service
Version
6.1.7600.16385 (win7_rtm.090713-1255)
Modules
Image
c:\windows\system32\vds.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\user32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\atl.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\setupapi.dll
c:\windows\system32\cfgmgr32.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\oleaut32.dll
c:\windows\system32\ole32.dll
c:\windows\system32\devobj.dll
c:\windows\system32\osuninst.dll
c:\windows\system32\vdsutil.dll
c:\windows\system32\netapi32.dll
c:\windows\system32\netutils.dll
c:\windows\system32\srvcli.dll
c:\windows\system32\wkscli.dll
c:\windows\system32\ws2_32.dll
c:\windows\system32\nsi.dll
c:\windows\system32\imm32.dll
c:\windows\system32\msctf.dll
c:\windows\system32\uexfat.dll
c:\windows\system32\ulib.dll
c:\windows\system32\ifsutil.dll
c:\windows\system32\uudf.dll
c:\windows\system32\untfs.dll
c:\windows\system32\ufat.dll
c:\windows\system32\fmifs.dll
c:\windows\system32\cryptbase.dll
c:\windows\system32\clbcatq.dll
c:\windows\system32\cryptsp.dll
c:\windows\system32\rsaenh.dll
c:\windows\system32\rpcrtremote.dll
c:\windows\system32\vds_ps.dll
c:\windows\system32\wintrust.dll
c:\windows\system32\crypt32.dll
c:\windows\system32\msasn1.dll
c:\windows\system32\vdsdyn.dll
c:\windows\system32\vdsbas.dll
c:\windows\system32\vdsvd.dll
c:\windows\system32\virtdisk.dll
c:\windows\system32\fltlib.dll
c:\windows\system32\hbaapi.dll
c:\windows\system32\wbem\wbemprox.dll
c:\windows\system32\wbemcomn.dll
c:\windows\system32\wbem\wbemsvc.dll
c:\windows\system32\wbem\fastprox.dll
c:\windows\system32\ntdsapi.dll
c:\windows\system32\iscsidsc.dll
c:\windows\system32\iscsium.dll
c:\windows\system32\fveapi.dll
c:\windows\system32\tbs.dll
c:\windows\system32\fvecerts.dll
c:\windows\system32\logoncli.dll

Registry activity

Total events
586
Read events
578
Write events
8
Delete events
0

Modification events

PID
Process
Operation
Key
Name
Value
3668
WANACRYPTOR.exe
write
HKEY_CURRENT_USER\Software\WanaCrypt0r
wd
C:\Users\admin\AppData\Local\Temp
936
write
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap
UNCAsIntranet
0
936
write
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap
AutoDetect
1
3368
reg.exe
write
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run
yyibsxxiapw107
"C:\Users\admin\AppData\Local\Temp\tasksche.exe"
3104
bcdedit.exe
write
HKEY_LOCAL_MACHINE\BCD00000000\Objects\{345b46fd-a9f9-11e7-a83c-e8a4f72b1d33}\Elements\250000e0
Element
0100000000000000
2144
bcdedit.exe
write
HKEY_LOCAL_MACHINE\BCD00000000\Objects\{345b46fd-a9f9-11e7-a83c-e8a4f72b1d33}\Elements\16000009
Element
00

Files activity

Executable files
18
Suspicious files
495
Text files
66
Unknown types
14

Dropped files

PID
Process
Filename
Type
3668
WANACRYPTOR.exe
C:\Users\admin\AppData\Local\Temp\taskdl.exe
executable
MD5: 4fef5e34143e646dbf9907c4374276f5
SHA256: 4a468603fdcb7a2eb5770705898cf9ef37aade532a7964642ecd705a74794b79
3668
WANACRYPTOR.exe
C:\Users\admin\Pictures\@[email protected]
executable
MD5: 7bf2b57f2a205768755c07f238fb32cc
SHA256: b9c5d4339809e0ad9a00d4d3dd26fdf44a32819a54abf846bb9b560d81391c25
3668
WANACRYPTOR.exe
C:\Users\admin\Downloads\@[email protected]
executable
MD5: 7bf2b57f2a205768755c07f238fb32cc
SHA256: b9c5d4339809e0ad9a00d4d3dd26fdf44a32819a54abf846bb9b560d81391c25
3668
WANACRYPTOR.exe
C:\Users\admin\Documents\@[email protected]
executable
MD5: 7bf2b57f2a205768755c07f238fb32cc
SHA256: b9c5d4339809e0ad9a00d4d3dd26fdf44a32819a54abf846bb9b560d81391c25
3668
WANACRYPTOR.exe
C:\Users\admin\Desktop\@[email protected]
executable
MD5: 7bf2b57f2a205768755c07f238fb32cc
SHA256: b9c5d4339809e0ad9a00d4d3dd26fdf44a32819a54abf846bb9b560d81391c25
3708
C:\Users\admin\AppData\Local\Temp\TaskData\Tor\libeay32.dll
executable
MD5: 6ed47014c3bb259874d673fb3eaedc85
SHA256: 58be53d5012b3f45c1ca6f4897bece4773efbe1ccbf0be460061c183ee14ca19
3668
WANACRYPTOR.exe
C:\Users\admin\AppData\Local\Temp\@[email protected]
executable
MD5: 7bf2b57f2a205768755c07f238fb32cc
SHA256: b9c5d4339809e0ad9a00d4d3dd26fdf44a32819a54abf846bb9b560d81391c25
3708
C:\Users\admin\AppData\Local\Temp\TaskData\Tor\tor.exe
executable
MD5: fe7eb54691ad6e6af77f8a9a0b6de26d
SHA256: e48673680746fbe027e8982f62a83c298d6fb46ad9243de8e79b7e5a24dcd4eb
3668
WANACRYPTOR.exe
C:\Users\admin\AppData\Local\Temp\u.wnry
executable
MD5: 7bf2b57f2a205768755c07f238fb32cc
SHA256: b9c5d4339809e0ad9a00d4d3dd26fdf44a32819a54abf846bb9b560d81391c25
3708
C:\Users\admin\AppData\Local\Temp\TaskData\Tor\taskhsvc.exe
executable
MD5: fe7eb54691ad6e6af77f8a9a0b6de26d
SHA256: e48673680746fbe027e8982f62a83c298d6fb46ad9243de8e79b7e5a24dcd4eb
3668
WANACRYPTOR.exe
C:\Users\admin\AppData\Local\Temp\taskse.exe
executable
MD5: 8495400f199ac77853c53b5a3f278f3e
SHA256: 2ca2d550e603d74dedda03156023135b38da3630cb014e3d00b1263358c5f00d
3708
C:\Users\admin\AppData\Local\Temp\TaskData\Tor\libgcc_s_sjlj-1.dll
executable
MD5: 73d4823075762ee2837950726baa2af9
SHA256: 9aeccf88253d4557a90793e22414868053caaab325842c0d7acb0365e88cd53b
3708
C:\Users\admin\AppData\Local\Temp\TaskData\Tor\zlib1.dll
executable
MD5: fb072e9f69afdb57179f59b512f828a4
SHA256: 66d653397cbb2dbb397eb8421218e2c126b359a3b0decc0f31e297df099e1383
3708
C:\Users\admin\AppData\Local\Temp\TaskData\Tor\libevent-2-0-5.dll
executable
MD5: 90f50a285efa5dd9c7fddce786bdef25
SHA256: 77a250e81fdaf9a075b1244a9434c30bf449012c9b647b265fa81a7b0db2513f
3708
C:\Users\admin\AppData\Local\Temp\TaskData\Tor\libevent_core-2-0-5.dll
executable
MD5: e5df3824f2fcad0c75fd601fcf37ee70
SHA256: 5cd126b4f8c77bdf0c5c980761a9c84411586951122131f13b0640db83f792d8
3708
C:\Users\admin\AppData\Local\Temp\TaskData\Tor\libevent_extra-2-0-5.dll
executable
MD5: 6d6602388ab232ca9e8633462e683739
SHA256: 957d58061a42ca343064ec5fb0397950f52aedf0594a18867d1339d5fbb12e7e
3708
C:\Users\admin\AppData\Local\Temp\TaskData\Tor\libssp-0.dll
executable
MD5: 78581e243e2b41b17452da8d0b5b2a48
SHA256: f28caebe9bc6aa5a72635acb4f0e24500494e306d8e8b2279e7930981281683f
3708
C:\Users\admin\AppData\Local\Temp\TaskData\Tor\ssleay32.dll
executable
MD5: a12c2040f6fddd34e7acb42f18dd6bdc
SHA256: bd70ba598316980833f78b05f7eeaef3e0f811a7c64196bf80901d155cb647c1
3668
WANACRYPTOR.exe
C:\Users\Public\Music\Sample Music\Sleep Away.mp3.WNCRYT
––
MD5:  ––
SHA256:  ––
3668
WANACRYPTOR.exe
C:\Users\admin\AppData\Local\Temp\00000000.res
vc
MD5: 7669ed5cb772eed6902c61e03e6f8f14
SHA256: 26e98638f5153a4066b3807ae8c2487b95b8fa2825ccfd6585a032f211f07a4c
1672
taskhsvc.exe
C:\Users\admin\AppData\Roaming\tor\state.tmp
––
MD5:  ––
SHA256:  ––
2628
C:\Users\admin\Desktop\@[email protected]
image
MD5: c17170262312f3be7027bc2ca825bf0c
SHA256: d5e0e8694ddc0548d8e6b87c83d50f4ab85c1debadb106d6a6a794c3e746f4fa
3668
WANACRYPTOR.exe
C:\Users\admin\AppData\Local\Temp\c.wnry
abr
MD5: 621455d7aad87ee8d5313200347afe60
SHA256: 75eea8ef667365ece96a12db0deb7e46f429fe9340209f53b38cf70f3ef59c0b
3668
WANACRYPTOR.exe
C:\Users\admin\AppData\Local\Temp\00000000.res
vc
MD5: 40144463529c349666bbda11f5540c35
SHA256: c195342a0b7bbb066d83f8257aeef9811d004b5cbafcd012c511d21c2c244e1a
1672
taskhsvc.exe
C:\Users\admin\AppData\Roaming\tor\cached-microdescs.new
text
MD5: 4259e29d8bc566baa2a1c0d200f77752
SHA256: dca3c4bb759e995f650c98514689a20f43d4c70a4a71e828418e1602573ee358
1672
taskhsvc.exe
C:\Users\admin\AppData\Roaming\tor\cached-microdescs.new
text
MD5: 3aaa9e65616109745a1e4c98af349340
SHA256: adc72265cb4e6b77f5cbc6601e1f7189ccdbf7eee7685bb14c3bbcf6ac75fc19
1672
taskhsvc.exe
C:\Users\admin\AppData\Roaming\tor\cached-microdescs.new
text
MD5: ba86e363c3f3e603bc3ae1eb0ce13bb8
SHA256: 16818cb7cfa99cc8cf0936a8dba38c4bfbf95309ecaa1630187db2a90872e163
1672
taskhsvc.exe
C:\Users\admin\AppData\Roaming\tor\cached-microdescs.new
text
MD5: 45ff66fd64b72db977aa26d5c0126ac9
SHA256: 7f4efcbc43a9bb362147861a5a61a9fb52b5d203d5bd1ebe8bf5449b360eb9fd
1672
taskhsvc.exe
C:\Users\admin\AppData\Roaming\tor\cached-microdescs.new
text
MD5: fc130401945872dcfb45bb1ece8a8c80
SHA256: e4a4be6589161664158d10c9a4fe14d1972524295cea92d27467b8ffac5e9c87
3668
WANACRYPTOR.exe
C:\Users\admin\AppData\Local\Temp\00000000.res
vc
MD5: aa92f8a9acbc671aee012b0a3bc0be37
SHA256: 894ae22141190c9bd57635c43b56491871b25acd50607ee37826067baedd32a7
3668
WANACRYPTOR.exe
C:\Users\admin\Desktop\@[email protected]
image
MD5: c17170262312f3be7027bc2ca825bf0c
SHA256: d5e0e8694ddc0548d8e6b87c83d50f4ab85c1debadb106d6a6a794c3e746f4fa
3668
WANACRYPTOR.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\TRRBlacklist.txt.WNCRY
binary
MD5: ff6a37f08eb7ed37d982112b91437824
SHA256: b651729141658ec3132df66f4b0aa02be94bd225a4697afafbb3c2b7969c7f4c
3668
WANACRYPTOR.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\pkcs11.txt.WNCRY
binary
MD5: 1950126e80d32094a56c2bdb3e16ffbe
SHA256: 886ea105dd4638a3ccd57653889cae24c961d00cfff2ce6772272a8f561d30e2
3668
WANACRYPTOR.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\gmp-widevinecdm\1.4.8.1008\LICENSE.txt.WNCRY
binary
MD5: a6c8c4ab4e451ae656708242c115a65c
SHA256: 1a11714674406473d02b2b91772e3f4b51a4b0837791ce431bf341efacba2ef3
3668
WANACRYPTOR.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\SiteSecurityServiceState.txt.WNCRY
binary
MD5: 3a5a4f64cf47f18918691d1880fb477a
SHA256: 541a48dbe21f8a652ebaa3cd7c4be6a3268d584e6144debf86c14d770f7a133f
3668
WANACRYPTOR.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\SecurityPreloadState.txt.WNCRY
binary
MD5: 1f52400e0f30abea6935ca60090e5546
SHA256: ac4be7ef2de11dd99be1e8b0cd9e889d99d99a1a2823937d572ed3db1a236c24
3668
WANACRYPTOR.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\SiteSecurityServiceState.txt.WNCRYT
––
MD5:  ––
SHA256:  ––
3668
WANACRYPTOR.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\TRRBlacklist.txt.WNCRYT
––
MD5:  ––
SHA256:  ––
3668
WANACRYPTOR.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\gmp-widevinecdm\1.4.8.1008\LICENSE.txt.WNCRYT
––
MD5:  ––
SHA256:  ––
3668
WANACRYPTOR.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\SecurityPreloadState.txt.WNCRYT
––
MD5:  ––
SHA256:  ––
3668
WANACRYPTOR.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\pkcs11.txt.WNCRYT
––
MD5:  ––
SHA256:  ––
3668
WANACRYPTOR.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\AlternateServices.txt.WNCRY
binary
MD5: 349a22e83591d4ae582ff2eeabf046a6
SHA256: d56362d05e8d46eab0ab36097b5575f13a6432fe137b8152c96f8b2833b364f0
3668
WANACRYPTOR.exe
C:\Users\admin\AppData\Local\Skype\Apps\login\images\white-on-black\[email protected]
binary
MD5: 82260f417903ff96ea9d4016995d9f8f
SHA256: c544cb3227d10b95e239456643e54b6e9dff825f399cea579e02094f007d40c9
3668
WANACRYPTOR.exe
C:\Users\admin\AppData\Local\Steam\widevine\win-ia32\LICENSE.txt.WNCRY
binary
MD5: 08da1c648a91a382cec9c17c4e8c2d90
SHA256: 1c3b872541ee4844539df69eb4ad577de78a81b7f0e88c2deea43d0d67169fd1
3668
WANACRYPTOR.exe
C:\Users\admin\AppData\Local\Steam\widevine\win-ia32\LICENSE.txt.WNCRYT
––
MD5:  ––
SHA256:  ––
3668
WANACRYPTOR.exe
C:\Users\admin\AppData\Local\Skype\Apps\login\images\white-on-black\[email protected]
––
MD5:  ––
SHA256:  ––
3668
WANACRYPTOR.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\AlternateServices.txt.WNCRYT
––
MD5:  ––
SHA256:  ––
3668
WANACRYPTOR.exe
C:\Users\admin\AppData\Local\Skype\Apps\login\images\white-on-black\ticked_not_10x10.png.WNCRY
binary
MD5: fa1cf121fe8873a5c667de6af3fdf571
SHA256: 7f40480057d1d86df44d54f60787e74d762d4cb2f2450a482114120ec50958dc
3668
WANACRYPTOR.exe
C:\Users\admin\AppData\Local\Skype\Apps\login\images\white-on-black\[email protected]
binary
MD5: b7b2c547f6bac1fe02b58ee05b6dd7c4
SHA256: ead0508aca801a8d45a505598d5c1433df77891983f3f4310894297e7eee7d23
3668
WANACRYPTOR.exe
C:\Users\admin\AppData\Local\Skype\Apps\login\images\white-on-black\logo-xbox-25x25.png.WNCRY
binary
MD5: a316d42986dbfc1ed3294d2f0878a93b
SHA256: a8fa0dceaf0dcbb52c100b1dacd8f14667123b1bbc6e202993538c335d063db1
3668
WANACRYPTOR.exe
C:\Users\admin\AppData\Local\Skype\Apps\login\images\white-on-black\[email protected]
binary
MD5: 2ea5d198e6c0375349c555d0e776f5fb
SHA256: 7d3e35bbc7ea861befa3657239475933a99a6aaad90cdec8be0a307f997d04d6
3668
WANACRYPTOR.exe
C:\Users\admin\AppData\Local\Skype\Apps\login\images\white-on-black\ticked_10x10.png.WNCRY
binary
MD5: 0e32f01b59a0163a5713c26e7a33e077
SHA256: ca5964251f2c5c8e5e3f5a7e824c18b5c3496ae71fada10c558e318598165b17
3668
WANACRYPTOR.exe
C:\Users\admin\AppData\Local\Skype\Apps\login\images\white-on-black\ticked_not_10x10.png.WNCRYT
––
MD5:  ––
SHA256:  ––
3668
WANACRYPTOR.exe
C:\Users\admin\AppData\Local\Skype\Apps\login\images\white-on-black\[email protected]
––
MD5:  ––
SHA256:  ––
3668
WANACRYPTOR.exe
C:\Users\admin\AppData\Local\Skype\Apps\login\images\white-on-black\logo-xbox-25x25.png.WNCRYT
––
MD5:  ––
SHA256:  ––
3668
WANACRYPTOR.exe
C:\Users\admin\AppData\Local\Skype\Apps\login\images\white-on-black\ticked_10x10.png.WNCRYT
––
MD5:  ––
SHA256:  ––
3668
WANACRYPTOR.exe
C:\Users\admin\AppData\Local\Skype\Apps\login\images\white-on-black\logo-win-25x25.png.WNCRY
binary
MD5: 861f60c94049767f516053a33069e88a
SHA256: 584c9f0cd09deb7a60f4947a9299ddcee7bf160cc2fe2052c2d71cdd3a775d59
3668
WANACRYPTOR.exe
C:\Users\admin\AppData\Local\Skype\Apps\login\images\white-on-black\logo-office-25x25.png.WNCRY
binary
MD5: 4edb6ad20ba4a5de93786f1e9cfee637
SHA256: 4c5da9a86df07382a7e9f8908d2d06fc90aca8d070b16d393ae9a850b4f30f61
3668
WANACRYPTOR.exe
C:\Users\admin\AppData\Local\Skype\Apps\login\images\white-on-black\logo-skype-25x25.png.WNCRY
binary
MD5: d0da2a33e9a4909749b01f326bc67ae9
SHA256: e0c65b72a7fb7fe82ede25ad13ef36f4caa04085bd3dea3714a830875e9499d6
3668
WANACRYPTOR.exe
C:\Users\admin\AppData\Local\Skype\Apps\login\images\white-on-black\[email protected]
––
MD5:  ––
SHA256:  ––
3668
WANACRYPTOR.exe
C:\Users\admin\AppData\Local\Skype\Apps\login\images\white-on-black\logo-skype-25x25.png.WNCRYT
––
MD5:  ––
SHA256:  ––
3668
WANACRYPTOR.exe
C:\Users\admin\AppData\Local\Skype\Apps\login\images\white-on-black\logo-office-25x25.png.WNCRYT
––
MD5:  ––
SHA256:  ––
3668
WANACRYPTOR.exe
C:\Users\admin\AppData\Local\Skype\Apps\login\images\white-on-black\logo-win-25x25.png.WNCRYT
––
MD5:  ––
SHA256:  ––
3668
WANACRYPTOR.exe
C:\Users\admin\AppData\Local\Skype\Apps\login\images\white-on-black\[email protected]
binary
MD5: f94ef8ecb8b2ffe7fa0fab93e4feb6bf
SHA256: 6ec316f2a915fe0d5237565937097cf98516976fc42cf793c4ff8669d72876da
3668
WANACRYPTOR.exe
C:\Users\admin\AppData\Local\Skype\Apps\login\images\white-on-black\exclamation_20x20.png.WNCRY
binary
MD5: 9ec79b621eed7b859930014c0a52fe15
SHA256: 55225948513ccb7ccd4ee279850d5af5762b5c696e0a33db04530253da1911ac
3668
WANACRYPTOR.exe
C:\Users\admin\AppData\Local\Skype\Apps\login\images\white-on-black\logo-cloud-35x25.png.WNCRY
binary
MD5: dfceaedc688eb90479748bf218195fba
SHA256: 25c8a07cea38ecbd98a7dd6063338e2391ae89c12ec5b06ba968f2f3594ff63d
3668
WANACRYPTOR.exe
C:\Users\admin\AppData\Local\Skype\Apps\login\images\white-on-black\[email protected]
binary
MD5: 4a086eadb02f8265ddca8dd32dca73a9
SHA256: 8648a4cb725a852e3d7c13af77e2c07a960ae79f794c28a8d8db42b53bcd7d88
3668
WANACRYPTOR.exe
C:\Users\admin\AppData\Local\Skype\Apps\login\images\white-on-black\[email protected]
––
MD5:  ––
SHA256:  ––
3668
WANACRYPTOR.exe
C:\Users\admin\AppData\Local\Skype\Apps\login\images\white-on-black\logo-cloud-35x25.png.WNCRYT
––
MD5:  ––
SHA256:  ––
3668
WANACRYPTOR.exe
C:\Users\admin\AppData\Local\Skype\Apps\login\images\white-on-black\[email protected]
––
MD5:  ––
SHA256:  ––
3668
WANACRYPTOR.exe
C:\Users\admin\AppData\Local\Skype\Apps\login\images\white-on-black\exclamation_20x20.png.WNCRYT
––
MD5:  ––
SHA256:  ––
3668
WANACRYPTOR.exe
C:\Users\admin\AppData\Local\Skype\Apps\login\images\white-on-black\dropdown_32x32.png.WNCRY
binary
MD5: 38430792664c9e5e3e57318007370eba
SHA256: 9069de2d9e47e87490123ee5008939c10ed1e0a9d4a13e192ad556b774e09df5
3668
WANACRYPTOR.exe
C:\Users\admin\AppData\Local\Skype\Apps\login\images\white-on-black\[email protected]
binary
MD5: 327ac2fd5c79ea05ba24ca479689cbf6
SHA256: aa5e441ec93ad6c5f3e06896df4e5d67480f4b9f54f566d4a0cd01459a3b778c
3668
WANACRYPTOR.exe
C:\Users\admin\AppData\Local\Skype\Apps\login\images\white-on-black\dropdown_hover_32x32.png.WNCRY
binary
MD5: e04d03847ecdc75a76b87f8a0fcd8f47
SHA256: aac0dac5d78ad6ca2168da51bc0e160ad7aaf9d608a9ec905ff750c17fb5fb4a
3668
WANACRYPTOR.exe
C:\Users\admin\AppData\Local\Skype\Apps\login\images\white-on-black\[email protected]
binary
MD5: b8373bc6a5379a2254065457cc7ae042
SHA256: 0aacc3fe04a8b379ea005c06148932a0bc48ee025fb047ec5aa88fba9f24018b
3668
WANACRYPTOR.exe
C:\Users\admin\AppData\Local\Skype\Apps\login\images\white-on-black\dropdown_32x32.png.WNCRYT
––
MD5:  ––
SHA256:  ––
3668
WANACRYPTOR.exe
C:\Users\admin\AppData\Local\Skype\Apps\login\images\white-on-black\[email protected]
––
MD5:  ––
SHA256:  ––
3668
WANACRYPTOR.exe
C:\Users\admin\AppData\Local\Skype\Apps\login\images\white-on-black\[email protected]
––
MD5:  ––
SHA256:  ––
3668
WANACRYPTOR.exe
C:\Users\admin\AppData\Local\Skype\Apps\login\images\white-on-black\dropdown_hover_32x32.png.WNCRYT
––
MD5:  ––
SHA256:  ––
3668
WANACRYPTOR.exe
C:\Users\admin\AppData\Local\Skype\Apps\login\images\white-on-black\button-middle-35x35.png.WNCRY
binary
MD5: 2ee551f814583c9227da1967ccc89820
SHA256: f61f3b0544eed6527363a500dcebf7d652d5f129c22723ce70fc50b0cc905b4f
3668
WANACRYPTOR.exe
C:\Users\admin\AppData\Local\Skype\Apps\login\images\white-on-black\button-right-35x35.png.WNCRY
binary
MD5: 03f7ef16e2737b5ed1673a2ba31f1087
SHA256: ce1e6b80c4c2227c3aa460c6e4d96e86152c18200aff42b61e3e8cc6e110928d
3668
WANACRYPTOR.exe
C:\Users\admin\AppData\Local\Skype\Apps\login\images\white-on-black\button-left-35x35.png.WNCRY
binary
MD5: 06e846a83a75c44592248c2bf93e7b81
SHA256: 1ee7e1e17aa4aa56669a195c1b630eb6afb20e344370373c8c3ad09e80eb21ea
3668
WANACRYPTOR.exe
C:\Users\admin\AppData\Local\Skype\Apps\login\images\white-on-black\[email protected]
binary
MD5: 8a3ca813d41a5bb237d3db3d80bc7453
SHA256: eb53f2d5c46e00ece83417aa1376527a399e6ad70e0b2a9682466b896f6b8159
3668
WANACRYPTOR.exe
C:\Users\admin\AppData\Local\Skype\Apps\login\images\white-on-black\[email protected]
binary
MD5: fede9554fe222ca48ec3bd1bb9652e84
SHA256: faabde28b423d993b19c2cda0fbe4e810e86ced17ca059ad3bd1cb9a9367a78e
3668
WANACRYPTOR.exe
C:\Users\admin\AppData\Local\Skype\Apps\login\images\white-on-black\[email protected]
binary
MD5: 0f3bfd1e8458715d4096c3ce99d7ba0a
SHA256: 3cf9fc6e275424deeb1e061381dd7b2b1db0734a97743fb858b96133a15612bb
3668
WANACRYPTOR.exe
C:\Users\admin\AppData\Local\Skype\Apps\login\images\white-on-black\capslock_20x20.png.WNCRY
binary
MD5: 1cfa46a7cf6e8fb102d5e74219a33939
SHA256: ba5be14d6a6151d583b32dd056d722fd6405514c66e65bc9faa4b5fc53f983eb
3668
WANACRYPTOR.exe
C:\Users\admin\AppData\Local\Skype\Apps\login\images\white-on-black\[email protected]
––
MD5:  ––
SHA256:  ––
3668
WANACRYPTOR.exe
C:\Users\admin\AppData\Local\Skype\Apps\login\images\white-on-black\button-right-35x35.png.WNCRYT
––
MD5:  ––
SHA256:  ––
3668
WANACRYPTOR.exe
C:\Users\admin\AppData\Local\Skype\Apps\login\images\white-on-black\[email protected]
––
MD5:  ––
SHA256:  ––
3668
WANACRYPTOR.exe
C:\Users\admin\AppData\Local\Skype\Apps\login\images\white-on-black\button-middle-35x35.png.WNCRYT
––
MD5:  ––
SHA256:  ––
3668
WANACRYPTOR.exe
C:\Users\admin\AppData\Local\Skype\Apps\login\images\white-on-black\capslock_20x20.png.WNCRYT
––
MD5:  ––
SHA256:  ––
3668
WANACRYPTOR.exe
C:\Users\admin\AppData\Local\Skype\Apps\login\images\white-on-black\[email protected]
––
MD5:  ––
SHA256:  ––
3668
WANACRYPTOR.exe
C:\Users\admin\AppData\Local\Skype\Apps\login\images\white-on-black\[email protected]
binary
MD5: 80bb30b066115ebefc76ea289de352ac
SHA256: 44c48704c31bf8b785ad32ed3d8fc5eeb66c4200b0dc564aa98e592e844e6ea8
3668
WANACRYPTOR.exe
C:\Users\admin\AppData\Local\Skype\Apps\login\images\white-on-black\arrow_up_20x20.png.WNCRY
binary
MD5: c03a1b3064d07367fc0240bea4de338d
SHA256: b1dade25af6c2755a8bb176eb82299aad5b4bb69d62d312c86f0b0c08abddf60
3668
WANACRYPTOR.exe
C:\Users\admin\AppData\Local\Skype\Apps\login\images\white-on-black\button-left-35x35.png.WNCRYT
––
MD5:  ––
SHA256:  ––
3668
WANACRYPTOR.exe
C:\Users\admin\AppData\Local\Skype\Apps\login\images\white-on-black\arrow_up_20x20.png.WNCRYT
––
MD5:  ––
SHA256:  ––
3668
WANACRYPTOR.exe
C:\Users\admin\AppData\Local\Skype\Apps\login\images\white-on-black\[email protected]
––
MD5:  ––
SHA256:  ––
3668
WANACRYPTOR.exe
C:\Users\admin\AppData\Local\Skype\Apps\login\images\retina\[email protected]
binary
MD5: c0dd23fb1817a098b20543aa3ff6e138
SHA256: c78632659eb1ceb1ebce021f5469ed34b20aacbb9a74055c86d62abf04bd7739
3668
WANACRYPTOR.exe
C:\Users\admin\AppData\Local\Skype\Apps\login\images\retina\[email protected]
binary
MD5: 8b1c5b8f218e0544eee928f2be633db7
SHA256: 353d4526598742165ee08beb2df498d7eac62a3011175f5457e4243e5705bde2
3668
WANACRYPTOR.exe
C:\Users\admin\AppData\Local\Skype\Apps\login\images\retina\[email protected]
binary
MD5: 770280b809fde8a5a25cbd4c2b87e9ad
SHA256: 61df756df7d5486986e6ed9b00ded0eee16980aab31cae315f327e4d447a9c10
3668
WANACRYPTOR.exe
C:\Users\admin\AppData\Local\Skype\Apps\login\images\retina\[email protected]
binary
MD5: 31f75b6b790db817065aba55094c4b9a
SHA256: b3d182d11f13ed555a4332b547a0dd3b0f164b520b9902dbc5d0b4382d059718
3668
WANACRYPTOR.exe
C:\Users\admin\AppData\Local\Skype\Apps\login\images\retina\[email protected]
binary
MD5: b343a27c4294c54507db206180c82ee6
SHA256: f2083af323bdca1c8d283a6c6d5e368469d2141c9e2e0cfc719e1a89e67b209a
3668
WANACRYPTOR.exe
C:\Users\admin\AppData\Local\Skype\Apps\login\images\retina\[email protected]
––
MD5:  ––
SHA256:  ––
3668
WANACRYPTOR.exe
C:\Users\admin\AppData\Local\Skype\Apps\login\images\retina\[email protected]
––
MD5:  ––
SHA256:  ––
3668
WANACRYPTOR.exe
C:\Users\admin\AppData\Local\Skype\Apps\login\images\retina\[email protected]
––
MD5:  ––
SHA256:  ––
3668
WANACRYPTOR.exe
C:\Users\admin\AppData\Local\Skype\Apps\login\images\retina\[email protected]
––
MD5:  ––
SHA256:  ––
3668
WANACRYPTOR.exe
C:\Users\admin\AppData\Local\Skype\Apps\login\images\retina\[email protected]
––
MD5:  ––
SHA256:  ––
3668
WANACRYPTOR.exe
C:\Users\admin\AppData\Local\Skype\Apps\login\images\retina\[email protected]
binary
MD5: 0ee135b4009de83a7d5ff79e009b2f85
SHA256: e4ec24fa15dc93b447d781a357e0f32a9242d212dd34242fa80984d024686ccc
3668
WANACRYPTOR.exe
C:\Users\admin\AppData\Local\Skype\Apps\login\images\retina\[email protected]
––
MD5:  ––
SHA256:  ––
3668
WANACRYPTOR.exe
C:\Users\admin\AppData\Local\Skype\Apps\login\images\retina\[email protected]
binary
MD5: a731d1c6a90d913292aaf8f7d44effd0
SHA256: ce5de6cdb587931ef5296348c6b479605b927a64fea05bfb33ebdd09bf68dea9
3668
WANACRYPTOR.exe
C:\Users\admin\AppData\Local\Skype\Apps\login\images\retina\[email protected]
binary
MD5: d912dd5fc4ac39ffe282c1b1d3ac1f1c
SHA256: a7f1510c548b53b4654b8f297a56214db6fd4580e42c4eb4a433ac378513399d
3668
WANACRYPTOR.exe
C:\Users\admin\AppData\Local\Skype\Apps\login\images\retina\[email protected]
binary
MD5: dee40662439f5488178238ee7579bea6
SHA256: 5069a983debff3334a638fec783c1aeec599efe48c6e764903f2643ba5d0ed3f
3668
WANACRYPTOR.exe
C:\Users\admin\AppData\Local\Skype\Apps\login\images\retina\[email protected]
binary
MD5: 4f15fd481567acfb35ab41669dae353f
SHA256: 78322720beb3d20bce009346970c738185f725f3e6b2250c3dfdb72089922acc
3668
WANACRYPTOR.exe
C:\Users\admin\AppData\Local\Skype\Apps\login\images\retina\[email protected]
binary
MD5: 173c291313bcc44c8b4ee6fd01ffa302
SHA256: ea5aa3e12700e397619a7ccc4b78fddb52eb4ec17901d54411301140e2acea93
3668
WANACRYPTOR.exe
C:\Users\admin\AppData\Local\Skype\Apps\login\images\retina\[email protected]
binary
MD5: b8023d2f87de7fc90b03e052d3a7e1a4
SHA256: 8ec3ed0a9ff1e2bd113116dd7491ab9e7e40028b8054ea000b4b8ee7dd930d5a
3668
WANACRYPTOR.exe
C:\Users\admin\AppData\Local\Skype\Apps\login\images\retina\[email protected]
––
MD5:  ––
SHA256:  ––
3668
WANACRYPTOR.exe
C:\Users\admin\AppData\Local\Skype\Apps\login\images\retina\[email protected]
––
MD5:  ––
SHA256:  ––
3668
WANACRYPTOR.exe
C:\Users\admin\AppData\Local\Skype\Apps\login\images\retina\[email protected]
––
MD5:  ––
SHA256:  ––
3668
WANACRYPTOR.exe
C:\Users\admin\AppData\Local\Skype\Apps\login\images\retina\[email protected]
––
MD5:  ––
SHA256:  ––
3668
WANACRYPTOR.exe
C:\Users\admin\AppData\Local\Skype\Apps\login\images\retina\[email protected]
––
MD5:  ––
SHA256:  ––
3668
WANACRYPTOR.exe
C:\Users\admin\AppData\Local\Skype\Apps\login\images\retina\[email protected]
––
MD5:  ––
SHA256:  ––
3668
WANACRYPTOR.exe
C:\Users\admin\AppData\Local\Skype\Apps\login\images\normal\[email protected]
binary
MD5: 13e446d48e5840d61775a465e1dacba2
SHA256: 4ce6e57acca37147fe929fcfc5cd80f628e35179a19151bb11d9930b44d7966b
3668
WANACRYPTOR.exe
C:\Users\admin\AppData\Local\Skype\Apps\login\images\normal\ticked_10x10.png.WNCRY
binary
MD5: 80c4b72c02f59d785e635ec3a6f407eb
SHA256: e25cdd225fb6282469765e1f1e8476dd332236da59917d735699f1ca45f23b62
3668
WANACRYPTOR.exe
C:\Users\admin\AppData\Local\Skype\Apps\login\images\normal\[email protected]
binary
MD5: 1293779908fdf7fcde6b4506ea133a59
SHA256: 6e24650c8a8c538a274cdb900e8e666fbeca0600949d71981e47463bdb0c992a
3668
WANACRYPTOR.exe
C:\Users\admin\AppData\Local\Skype\Apps\login\images\retina\[email protected]
binary
MD5: d662e6293d6086babd77e80e128a668f
SHA256: 72b47c0e698d6db0bf3705b4bc4feb6433ef683164cd90f44c6a72aa137b44e2
3668
WANACRYPTOR.exe
C:\Users\admin\AppData\Local\Skype\Apps\login\images\normal\ticked_not_10x10.png.WNCRY
binary
MD5: 9a008b0177938dbe75d0b651ca564ab8
SHA256: bc74c34fcda5e94b7671b6f4e33b22a5095282c588df35e447d5ed68ae6e2785
3668
WANACRYPTOR.exe
C:\Users\admin\AppData\Local\Skype\Apps\login\images\retina\[email protected]
––
MD5:  ––
SHA256:  ––
3668
WANACRYPTOR.exe
C:\Users\admin\AppData\Local\Skype\Apps\login\images\normal\ticked_10x10.png.WNCRYT
––
MD5:  ––
SHA256:  ––
3668
WANACRYPTOR.exe
C:\Users\admin\AppData\Local\Skype\Apps\login\images\normal\[email protected]
––
MD5:  ––
SHA256:  ––
3668
WANACRYPTOR.exe
C:\Users\admin\AppData\Local\Skype\Apps\login\images\normal\ticked_not_10x10.png.WNCRYT
––
MD5:  ––
SHA256:  ––
3668
WANACRYPTOR.exe
C:\Users\admin\AppData\Local\Skype\Apps\login\images\normal\[email protected]
––
MD5:  ––
SHA256:  ––
3668
WANACRYPTOR.exe
C:\Users\admin\AppData\Local\Skype\Apps\login\images\normal\logo-win-25x25.png.WNCRY
binary
MD5: d273f8b57c3c7cd12d0698bf04675888
SHA256: 25cad55d8a757430e953103872c3179519cbd30f5a1135bebb40c60e4cd4f979
3668
WANACRYPTOR.exe
C:\Users\admin\AppData\Local\Skype\Apps\login\images\normal\[email protected]
binary
MD5: cc5e332e2bb6e080aedc934d53d1318f
SHA256: 0f0296b803f1dad5810f242c6f39ac6de746b044acf8b999311fcc5135d4aa9c
3668
WANACRYPTOR.exe
C:\Users\admin\AppData\Local\Skype\Apps\login\images\normal\logo-office-25x25.png.WNCRY
binary
MD5: b91ecbabef61979ad58597b94061d90f
SHA256: 7f214739a9eef5b45f0b8cd0cfdc6eed87f65dca47db16f8efe667bff656c938
3668
WANACRYPTOR.exe
C:\Users\admin\AppData\Local\Skype\Apps\login\images\normal\logo-office-25x25.png.WNCRYT
––
MD5:  ––
SHA256:  ––
3668
WANACRYPTOR.exe
C:\Users\admin\AppData\Local\Skype\Apps\login\images\normal\logo-win-25x25.png.WNCRYT
––
MD5:  ––
SHA256:  ––
3668
WANACRYPTOR.exe
C:\Users\admin\AppData\Local\Skype\Apps\login\images\normal\[email protected]
––
MD5:  ––
SHA256:  ––
3668
WANACRYPTOR.exe
C:\Users\admin\AppData\Local\Skype\Apps\login\images\normal\logo-cloud-35x25.png.WNCRY
binary
MD5: af44a7d68c4d84021fa88d7bb37de35a
SHA256: 424bfc3d76c8dd0ca4c94216d89e66537edc157044a98478d9207a52c714b73a
3668
WANACRYPTOR.exe
C:\Users\admin\AppData\Local\Skype\Apps\login\images\normal\logo-cloud-35x25.png.WNCRYT
––
MD5:  ––
SHA256:  ––
3668
WANACRYPTOR.exe
C:\Users\admin\AppData\Local\Skype\Apps\login\images\normal\exclamation_20x20.png.WNCRY
binary
MD5: 8efb040aca1ac831ff85051ef4ab2d33
SHA256: bfcc4a3dcf94afe93134b6e6e77024ca3a03028e14ab4f48cfcc4a9299732b6c
3668
WANACRYPTOR.exe
C:\Users\admin\AppData\Local\Skype\Apps\login\images\normal\exclamation_20x20.png.WNCRYT
––
MD5:  ––
SHA256:  ––
3668
WANACRYPTOR.exe
C:\Users\admin\AppData\Local\Skype\Apps\login\images\normal\[email protected]
binary
MD5: ceea55b554068ca4cc75924b4285794c
SHA256: 1afc9d1bbbe3cfeeb90800d906a9aae88416b0267c37b31c072a978c644f00ac
3668
WANACRYPTOR.exe
C:\Users\admin\AppData\Local\Skype\Apps\login\images\normal\[email protected]
––
MD5:  ––
SHA256:  ––
3668
WANACRYPTOR.exe
C:\Users\admin\AppData\Local\Skype\Apps\login\images\normal\dropdown_hover_32x32.png.WNCRY
binary
MD5: 89014837b2dacebd345fe75733000715
SHA256: 8877e3a23f0fa0dcf2d526bfcba667048c665d3712c09b44aa0a9f761c5ffc35
3668
WANACRYPTOR.exe
C:\Users\admin\AppData\Local\Skype\Apps\login\images\normal\dropdown_hover_32x32.png.WNCRYT
––
MD5:  ––
SHA256:  ––
3668
WANACRYPTOR.exe
C:\Users\admin\AppData\Local\Skype\Apps\login\images\normal\caret_right.png.WNCRY
binary
MD5: b5f2806e774ffab73146fdbc71cd15cb
SHA256: 55592e52c70143c3562b0145604a6af41c180536ae3cde569e3240e9e63d2df6
3668
WANACRYPTOR.exe
C:\Users\admin\AppData\Local\Skype\Apps\login\images\normal\dropdown_32x32.png.WNCRY
binary
MD5: 5c6b1e8f4223adc5010476faef806f4f
SHA256: 1350cbe1c34d04a7eb6294ad915ab58cd2e245cda8b0b242e0f228b1fe6c9aa1
3668
WANACRYPTOR.exe
C:\Users\admin\AppData\Local\Skype\Apps\login\images\normal\[email protected]
binary
MD5: b4b8ddb9efbe0e692511505011843f95
SHA256: fd11d102ae9fd61ead6179cf4e96553c4dfc02541ee68afbb8707eeab55e75a5
3668
WANACRYPTOR.exe
C:\Users\admin\AppData\Local\Skype\Apps\login\images\normal\caret_right.png.WNCRYT
––
MD5:  ––
SHA256:  ––
3668
WANACRYPTOR.exe
C:\Users\admin\AppData\Local\Skype\Apps\login\images\normal\[email protected]
––
MD5:  ––
SHA256:  ––
3668
WANACRYPTOR.exe
C:\Users\admin\AppData\Local\Skype\Apps\login\images\normal\dropdown_32x32.png.WNCRYT
––
MD5:  ––
SHA256:  ––
3668
WANACRYPTOR.exe
C:\Users\admin\AppData\Local\Skype\Apps\login\images\normal\caret_left.png.WNCRY
binary
MD5: d1a68996fb855f57685302952798217e
SHA256: 0f1b323f974040ed305d2820ec366fc491974384b2f69c87e35dab913644ac74
3668
WANACRYPTOR.exe
C:\Users\admin\AppData\Local\Skype\Apps\login\images\normal\caret_left.png.WNCRYT
––
MD5:  ––
SHA256:  ––
3668
WANACRYPTOR.exe
C:\Users\admin\AppData\Local\Skype\Apps\login\images\normal\capslock_20x20.png.WNCRY
binary
MD5: 329f5b1fef83c71bb7f2ee6c1e1d42f4
SHA256: 38bc6750478f37606bf85781ee8cec53f89a2afd08e2b2eedb31684663a3316a
3668
WANACRYPTOR.exe
C:\Users\admin\AppData\Local\Skype\Apps\login\images\normal\[email protected]
binary
MD5: 21f6d8c92c6eb6dd5bb747248b64d42f
SHA256: d3111dd2579dfe0498cb6ef74b67576225110793b68a01e8fd988f530e558ca0
3668
WANACRYPTOR.exe
C:\Users\admin\AppData\Local\Skype\Apps\login\images\normal\[email protected]
binary
MD5: 7455db7bb40cf9f294c3b157405f08ba
SHA256: 87c236d851a613ade3ff02ddc6074f406caceb18f436a7a8e0cbb1d0b938a98a
3668
WANACRYPTOR.exe
C:\Users\admin\AppData\Local\Skype\Apps\login\images\normal\[email protected]
––
MD5:  ––
SHA256:  ––
3668
WANACRYPTOR.exe
C:\Users\admin\AppData\Local\Skype\Apps\login\images\normal\[email protected]
––
MD5:  ––
SHA256:  ––
3668
WANACRYPTOR.exe
C:\Users\admin\AppData\Local\Skype\Apps\login\images\normal\capslock_20x20.png.WNCRYT
––
MD5:  ––
SHA256:  ––
3668
WANACRYPTOR.exe
C:\Users\admin\AppData\Local\Skype\Apps\login\images\normal\button-right-35x35.png.WNCRY
binary
MD5: 0508b7727efd4aade3efbffe4e071fe7
SHA256: be20adb67be5605b1d395a1c7f906b525d2e213ed1450c2491f9447dbee4a79b
3668
WANACRYPTOR.exe
C:\Users\admin\AppData\Local\Skype\Apps\login\images\normal\button-right-35x35.png.WNCRYT
––
MD5:  ––
SHA256:  ––
3668
WANACRYPTOR.exe
C:\Users\admin\AppData\Local\Skype\Apps\login\images\normal\button-middle-35x35.png.WNCRY
binary
MD5: d56de184d847214fe8a27d8ab917341f
SHA256: f404791bf769050c93e834432dc3b8b24306843403d023109899552cc82a5320
3668
WANACRYPTOR.exe
C:\Users\admin\AppData\Local\Skype\Apps\login\images\normal\[email protected]
binary
MD5: b05e9c22a2f0e33cf61970bfa82027e4
SHA256: b38b1911230977b40050edcacd9197f96540bab4f755bc28a9e5b515cbd804d9
3668
WANACRYPTOR.exe
C:\Users\admin\AppData\Local\Skype\Apps\login\images\normal\[email protected]
binary
MD5: 4ad274ad802d24bef91f6b6ed1bb4bd0
SHA256: efb5e656030fdf37de012f5a7934f53c38f1c0eb434e58f8979081786640a275
3668
WANACRYPTOR.exe
C:\Users\admin\AppData\Local\Skype\Apps\login\images\normal\button-middle-35x35.png.WNCRYT
––
MD5:  ––
SHA256:  ––
3668
WANACRYPTOR.exe
C:\Users\admin\AppData\Local\Skype\Apps\login\images\normal\[email protected]
––
MD5:  ––
SHA256:  ––
3668
WANACRYPTOR.exe
C:\Users\admin\AppData\Local\Skype\Apps\login\images\normal\[email protected]
binary
MD5: a88d44b87acca95d847c660e77a85b6f
SHA256: d2fbf49b0a662f5a9ae3e0451372e20c7b609e5ed99a42805fe64b350c4c4ae6
3668
WANACRYPTOR.exe
C:\Users\admin\AppData\Local\Skype\Apps\login\images\normal\button-left-35x35.png.WNCRY
binary
MD5: a299f23026abbbc785706e8436868b94
SHA256: 1d8f1e33154b002f4a178e783dc0323a8dfa0fb55657003e6a95387284455565
3668
WANACRYPTOR.exe
C:\Users\admin\AppData\Local\Skype\Apps\login\images\normal\[email protected]
––
MD5:  ––
SHA256:  ––
3668
WANACRYPTOR.exe
C:\Users\admin\AppData\Local\Skype\Apps\login\images\normal\button-left-35x35.png.WNCRYT
––
MD5:  ––
SHA256:  ––
3668
WANACRYPTOR.exe
C:\Users\admin\AppData\Local\Skype\Apps\login\images\normal\[email protected]
––
MD5:  ––
SHA256:  ––
3668
WANACRYPTOR.exe
C:\Users\admin\AppData\Local\Skype\Apps\login\images\normal\button-darker-right-35x35.png.WNCRY
binary
MD5: 27b92e4bd25ecceac111505f853621e2
SHA256: fafe90a3d4df9ffc4aaa832da2c863a9d527bba969e346d94064f9bcf73fd982
3668
WANACRYPTOR.exe
C:\Users\admin\AppData\Local\Skype\Apps\login\images\normal\button-darker-right-35x35.png.WNCRYT
––
MD5:  ––
SHA256:  ––
3668
WANACRYPTOR.exe
C:\Users\admin\AppData\Local\Skype\Apps\login\images\normal\[email protected]
binary
MD5: 3b96c29cf0dd5883840f2dd4fee0d9a6
SHA256: 01d68f4235c26b681fcc5b1f766833f9df4dc782d4307ac9dff767517eef5ea8
3668
WANACRYPTOR.exe
C:\Users\admin\AppData\Local\Skype\Apps\login\images\normal\button-darker-middle-35x35.png.WNCRY
binary
MD5: 561e258c17f59df1cec55e077a56fb37
SHA256: be8dcca6b56e6a98e60d6cccf129e4afe6c21e0b86f8ee02ec3528816f28b3ec
3668
WANACRYPTOR.exe
C:\Users\admin\AppData\Local\Skype\Apps\login\images\normal\button-darker-middle-35x35.png.WNCRYT
––
MD5:  ––
SHA256:  ––
3668
WANACRYPTOR.exe
C:\Users\admin\AppData\Local\Skype\Apps\login\images\normal\[email protected]
––
MD5:  ––
SHA256:  ––
3668
WANACRYPTOR.exe
C:\Users\admin\AppData\Local\Skype\Apps\login\images\normal\[email protected]
binary
MD5: 856fab847429c2710706bd35c8d040f1
SHA256: 8da87c530c9b466adafde88807c071af0286fa0a259b4b6fa00c586472a1263c
3668
WANACRYPTOR.exe
C:\Users\admin\AppData\Local\Skype\Apps\login\images\normal\[email protected]
––
MD5:  ––
SHA256:  ––
3668
WANACRYPTOR.exe
C:\Users\admin\AppData\Local\Skype\Apps\login\images\normal\button-darker-left-35x35.png.WNCRY
binary
MD5: 06707da2525987082bdc028d5c22ddb5
SHA256: b30edf24cae1bf96681db4702c0f21df0a5e1d54f503462e1d9a9c09de46d75e
3668
WANACRYPTOR.exe
C:\Users\admin\AppData\Local\Skype\Apps\login\images\normal\button-darker-left-35x35.png.WNCRYT
––
MD5:  ––
SHA256:  ––
3668
WANACRYPTOR.exe
C:\Users\admin\AppData\Local\Skype\Apps\login\images\normal\arrow_up_20x20_8bit.png.WNCRY
binary
MD5: e87b1957a286af7ad7d7a678cffcf6ae
SHA256: 0abe2a9c6c8db744dc8799ec121ba68418ce9772ee379b9f7575d2ff70350ddf
3668
WANACRYPTOR.exe
C:\Users\admin\AppData\Local\Skype\Apps\login\images\normal\[email protected]
binary
MD5: 5b05358f25b45a4444dbfa948f07143c
SHA256: 7702df135b3c1382d86981085c23848db9e4454152db987d7798c07e6010683f
3668
WANACRYPTOR.exe
C:\Users\admin\AppData\Local\Skype\Apps\login\images\normal\[email protected]
binary
MD5: 6ddf7a3c2827b1f5b4997a17022b83f7
SHA256: f7a5f36b8b20fb8702dade7ed4c5fc819843ac4f26c30c5592267654e3034597
3668
WANACRYPTOR.exe
C:\Users\admin\AppData\Local\Skype\Apps\login\images\normal\back_20x20.png.WNCRY
binary
MD5: 9836218ad03ac88411cf333c5d43baa2
SHA256: 5544fb4b125976d5f4e6afabf3e60313c0d2cd6071b34bfe6358832fa5b1e664
3668
WANACRYPTOR.exe
C:\Users\admin\AppData\Local\Skype\Apps\login\images\normal\back_20x20.png.WNCRYT
––
MD5:  ––
SHA256:  ––
3668
WANACRYPTOR.exe
C:\Users\admin\AppData\Local\Skype\Apps\login\images\normal\[email protected]
––
MD5:  ––
SHA256:  ––
3668
WANACRYPTOR.exe
C:\Users\admin\AppData\Local\Skype\Apps\login\images\normal\[email protected]
––
MD5:  ––
SHA256:  ––
3668
WANACRYPTOR.exe
C:\Users\admin\AppData\Local\Skype\Apps\login\images\normal\arrow_up_20x20_8bit.png.WNCRYT
––
MD5:  ––
SHA256:  ––
3668
WANACRYPTOR.exe
C:\Users\admin\AppData\Local\Skype\Apps\login\images\black-on-white\ticked_not_10x10.png.WNCRY
binary
MD5: f31a21584c2233b874a873253f082454
SHA256: 99ff6dd813096807cf9573e640e3ade434e03ea04f64ff93ed3f2e91d7736dd8
3668
WANACRYPTOR.exe
C:\Users\admin\AppData\Local\Skype\Apps\login\images\normal\arrow_up_20x20.png.WNCRY
binary
MD5: 8bee1487277cf90d146b42c3a1c1ec03
SHA256: 9c07e0413208861f4a2a5c9a609fe66d3af14c8c2433a7b10e0f91970c2dd2b3
3668
WANACRYPTOR.exe
C:\Users\admin\AppData\Local\Skype\Apps\login\images\black-on-white\[email protected]
binary
MD5: 20378827860f4207dd7d4fc0c5586ac4
SHA256: 1e5d1e1338cba2c5e8ef0c3919dc7cde5bbed9ee0417c42f4b8694642111e3ba
3668
WANACRYPTOR.exe
C:\Users\admin\AppData\Local\Skype\Apps\login\images\normal\arrow_up_20x20.png.WNCRYT
––
MD5:  ––
SHA256:  ––
3668
WANACRYPTOR.exe
C:\Users\admin\AppData\Local\Skype\Apps\login\images\black-on-white\ticked_not_10x10.png.WNCRYT
––
MD5:  ––
SHA256:  ––
3668
WANACRYPTOR.exe
C:\Users\admin\AppData\Local\Skype\Apps\login\images\black-on-white\[email protected]
––
MD5:  ––
SHA256:  ––
3668
WANACRYPTOR.exe
C:\Users\admin\AppData\Local\Skype\Apps\login\images\black-on-white\logo-xbox-25x25.png.WNCRY
binary
MD5: eee330c5da962a52c01e12b77a1d548e
SHA256: 40c592d9e294b42c9df74c8d31a0f127ebcf7345d81d431078de184d420b7c80
3668
WANACRYPTOR.exe
C:\Users\admin\AppData\Local\Skype\Apps\login\images\black-on-white\ticked_10x10.png.WNCRY
binary
MD5: 553f52eaa59266f617ad82361f357189
SHA256: e7355851c7d5e7b43f1d54af905c6d45fd35463e23c674f6dfb3c62a40af8602
3668
WANACRYPTOR.exe
C:\Users\admin\AppData\Local\Skype\Apps\login\images\black-on-white\[email protected]
binary
MD5: 60314a35a9c3456eca0056de59e5bb2d
SHA256: 4d7965189b0439dd29de38cfe1fcf5e83afa3e7f14fc9657a745858495cd6b62
3668
WANACRYPTOR.exe
C:\Users\admin\AppData\Local\Skype\Apps\login\images\black-on-white\[email protected]
––
MD5:  ––
SHA256:  ––
3668
WANACRYPTOR.exe
C:\Users\admin\AppData\Local\Skype\Apps\login\images\black-on-white\logo-xbox-25x25.png.WNCRYT
––
MD5:  ––
SHA256:  ––
3668
WANACRYPTOR.exe
C:\Users\admin\AppData\Local\Skype\Apps\login\images\black-on-white\ticked_10x10.png.WNCRYT
––
MD5:  ––
SHA256:  ––
3668
WANACRYPTOR.exe
C:\Users\admin\AppData\Local\Skype\Apps\login\images\black-on-white\logo-win-25x25.png.WNCRY
binary
MD5: 2ac75b38fe02e952a64aab7ab5950dd1
SHA256: 60415d3415c7faec486f9913e71ab458462054ec114bac6e2d7d70c47dde003e
3668
WANACRYPTOR.exe
C:\Users\admin\AppData\Local\Skype\Apps\login\images\black-on-white\logo-office-25x25.png.WNCRY
binary
MD5: ead4e63931b75859fc1ad1cef4e15ecb
SHA256: d9483f923c02488a68beea2e68d5a44676053e930917d59d44eebe5a99250e93
3668
WANACRYPTOR.exe
C:\Users\admin\AppData\Local\Skype\Apps\login\images\black-on-white\[email protected]
binary
MD5: b0899f8276a008eaeae13f911cfa8f96
SHA256: f61eadf889f162a3c30eb7f2462a7a7ca062dc41929df70e84d2e0b7b96ba020
3668
WANACRYPTOR.exe
C:\Users\admin\AppData\Local\Skype\Apps\login\images\black-on-white\logo-skype-25x25.png.WNCRY
binary
MD5: 45202da319538f89c9792d834d65043c
SHA256: 7f99defef953563f04fa55433b17210a45dbcae17da6aec99d768cd21d5e9c67
3668
WANACRYPTOR.exe
C:\Users\admin\AppData\Local\Skype\Apps\login\images\black-on-white\logo-skype-25x25.png.WNCRYT
––
MD5:  ––
SHA256:  ––
3668
WANACRYPTOR.exe
C:\Users\admin\AppData\Local\Skype\Apps\login\images\black-on-white\logo-win-25x25.png.WNCRYT
––
MD5:  ––
SHA256:  ––
3668
WANACRYPTOR.exe
C:\Users\admin\AppData\Local\Skype\Apps\login\images\black-on-white\logo-office-25x25.png.WNCRYT
––
MD5:  ––
SHA256:  ––
3668
WANACRYPTOR.exe
C:\Users\admin\AppData\Local\Skype\Apps\login\images\black-on-white\[email protected]
––
MD5:  ––
SHA256:  ––
3668
WANACRYPTOR.exe
C:\Users\admin\AppData\Local\Skype\Apps\login\images\black-on-white\logo-cloud-35x25.png.WNCRY
binary
MD5: d43eb79f249649a0f0c35d21766c80b6
SHA256: 3fb0ae5a052816d432365444f3bb615ffdb8ff15b150e13050f554a894dafd37
3668
WANACRYPTOR.exe
C:\Users\admin\AppData\Local\Skype\Apps\login\images\black-on-white\[email protected]
binary
MD5: 7bbd45cd9cbf2e0d4d88a56bdb4364ca
SHA256: ac42aadb68a2a66540770090488c3cde86af01164dbe4deded062bfbb19daca7
3668
WANACRYPTOR.exe
C:\Users\admin\AppData\Local\Temp\f.wnry
text
MD5: 2970698c889f51874e7522615f3b48a4
SHA256: 83a3871a4956db186921b2aab00ca0854cf0a98e15388c63b3131eb37ebf2e13
3668
WANACRYPTOR.exe
C:\Users\admin\AppData\Local\Skype\Apps\login\images\black-on-white\[email protected]
binary
MD5: 4d87b272fa0a40c2ee65ee4927b5ccb2
SHA256: e13c1e2b66c4d58af62e546f3b81aa0e7d9f5d32b9d1f2af85a18ef03b709c3b
3668
WANACRYPTOR.exe
C:\Users\admin\AppData\Local\Skype\Apps\login\images\black-on-white\[email protected]
binary
MD5: 16f069d08c4543994dd6fd38c593d525
SHA256: 4b991c894527594eb3d81a21a154d4c232600f3cef41582cb0b1ba2f12c99655
3668
WANACRYPTOR.exe
C:\Users\admin\AppData\Local\Skype\Apps\login\images\black-on-white\exclamation_20x20.png.WNCRY
binary
MD5: 27ad7d28b283d2276734f0e10d42d021
SHA256: 9e52c2398cdbfc2a576fcce26b2310243b928fa3111b9a3aeb82895345ea3677
3668
WANACRYPTOR.exe
C:\Users\admin\AppData\Local\Skype\Apps\login\images\black-on-white\dropdown_hover_32x32.png.WNCRY
binary
MD5: e0bc5c7607cd3c05bf608a5b5c3ef314
SHA256: 27c8d158cf505e1ee3c46279c7c973878e5469dabac61e779b771f6cd29af69b
3668
WANACRYPTOR.exe
C:\Users\admin\AppData\Local\Skype\Apps\login\images\black-on-white\[email protected]
––
MD5:  ––
SHA256:  ––
3668
WANACRYPTOR.exe
C:\Users\admin\AppData\Local\Skype\Apps\login\images\black-on-white\exclamation_20x20.png.WNCRYT
––
MD5:  ––
SHA256:  ––
3668
WANACRYPTOR.exe
C:\Users\admin\AppData\Local\Skype\Apps\login\images\black-on-white\[email protected]
––
MD5:  ––
SHA256:  ––
3668
WANACRYPTOR.exe
C:\Users\admin\AppData\Local\Skype\Apps\login\images\black-on-white\dropdown_hover_32x32.png.WNCRYT
––
MD5:  ––
SHA256:  ––
3668
WANACRYPTOR.exe
C:\Users\admin\AppData\Local\Skype\Apps\login\images\black-on-white\logo-cloud-35x25.png.WNCRYT
––
MD5:  ––
SHA256:  ––
3668
WANACRYPTOR.exe
C:\Users\admin\AppData\Local\Skype\Apps\login\images\black-on-white\[email protected]
––
MD5:  ––
SHA256:  ––
3668
WANACRYPTOR.exe
C:\Users\admin\AppData\Local\Skype\Apps\login\images\black-on-white\[email protected]
binary
MD5: a55ab9409ef7eb09eee537fcd0e23f8a
SHA256: c6c3de3fa92a6af49e9011c26f66874b8cc31dc15f63b41143aa97430348ded5
3668
WANACRYPTOR.exe
C:\Users\admin\AppData\Local\Skype\Apps\login\images\black-on-white\dropdown_32x32.png.WNCRY
binary
MD5: afcb9118382e40f4b95ed692480ba4f5
SHA256: 6f3cc048a229f0be5d71de98654331be5acea78a6e5042a3338185349a042b8f
3668
WANACRYPTOR.exe
C:\Users\admin\AppData\Local\Skype\Apps\login\images\black-on-white\dropdown_32x32.png.WNCRYT
––
MD5:  ––
SHA256:  ––
3668
WANACRYPTOR.exe
C:\Users\admin\AppData\Local\Skype\Apps\login\images\black-on-white\[email protected]
––
MD5:  ––
SHA256:  ––
3668
WANACRYPTOR.exe
C:\Users\admin\AppData\Local\Skype\Apps\login\images\black-on-white\[email protected]
binary
MD5: 38bae7221d06309ffa5e53bf1f592f94
SHA256: ffb17ac1f1197d5a9ddae6d49dfaea0fb5d3398aff8aa3006c8cb773f807d36b
3668
WANACRYPTOR.exe
C:\Users\admin\AppData\Local\Skype\Apps\login\images\black-on-white\capslock_20x20.png.WNCRY
binary
MD5: e195f84d053b19e60e29ca19bf23cb40
SHA256: 2878b7657e8970b281bfb870a77f352e902a163d7e1811b6abebe675b6823881
3668
WANACRYPTOR.exe
C:\Users\admin\AppData\Local\Skype\Apps\login\images\black-on-white\[email protected]
––
MD5:  ––
SHA256:  ––
3668
WANACRYPTOR.exe
C:\Users\admin\AppData\Local\Skype\Apps\login\images\black-on-white\capslock_20x20.png.WNCRYT
––
MD5:  ––
SHA256:  ––
3668
WANACRYPTOR.exe
C:\Users\admin\AppData\Local\Skype\Apps\login\images\black-on-white\button-middle-35x35.png.WNCRY
binary
MD5: 13ad3caee5e225151cddfce6a3e0a159
SHA256: 6312b9095cdb7c38e56f7fc5d463558afca9c41bae98e88e872400cc75deacb7
3668
WANACRYPTOR.exe
C:\Users\admin\AppData\Local\Skype\Apps\login\images\black-on-white\button-right-35x35.png.WNCRY
binary
MD5: ba9a7b6edb6db5a8b8879109e241ef3a
SHA256: 77eca35aa0e24b80aa7ada6a3e9324cd59f8adeaf3381c9770962e48f5d197ff
3668
WANACRYPTOR.exe
C:\Users\admin\AppData\Local\Skype\Apps\login\images\black-on-white\[email protected]
binary
MD5: bca82381312673ee5784bf9477a16eff
SHA256: 82c7674f4dcb8ef68e9771abadeb18f262975b9eff075a5d7712ee4bf8efb791
3668
WANACRYPTOR.exe
C:\Users\admin\AppData\Local\Skype\Apps\login\images\black-on-white\button-right-35x35.png.WNCRYT
––
MD5:  ––
SHA256:  ––
3668
WANACRYPTOR.exe
C:\Users\admin\AppData\Local\Skype\Apps\login\images\black-on-white\[email protected]
––
MD5:  ––
SHA256:  ––
3668
WANACRYPTOR.exe
C:\Users\admin\AppData\Local\Skype\Apps\login\images\black-on-white\button-middle-35x35.png.WNCRYT
––
MD5:  ––
SHA256:  ––
3668
WANACRYPTOR.exe
C:\Users\admin\AppData\Local\Skype\Apps\login\images\black-on-white\[email protected]
binary
MD5: 0dcaf65e1749e3f11e063ec81544f9be
SHA256: 1baed59d9ffd5cf430ca8da2773ef78eb017887b57a5db75eef597a49808ab10
3668
WANACRYPTOR.exe
C:\Users\admin\AppData\Local\Skype\Apps\login\images\black-on-white\[email protected]
binary
MD5: 278503e6978ef4782e519ae589c9c975
SHA256: a51228a1b496976787b347910b250feb890dc855e80551c5190fec723f24587e
3668
WANACRYPTOR.exe
C:\Users\admin\AppData\Local\Skype\Apps\login\images\black-on-white\button-left-35x35.png.WNCRY
binary
MD5: 95b85825ddd252336b076e186204b5fa
SHA256: f37c9df217eae65aa6b059bad1d882ea84ad94a02a54bfd31f6f0a861781e185
3668
WANACRYPTOR.exe
C:\Users\admin\AppData\Local\Skype\Apps\login\images\black-on-white\button-left-35x35.png.WNCRYT
––
MD5:  ––
SHA256:  ––
3668
WANACRYPTOR.exe
C:\Users\admin\AppData\Local\Skype\Apps\login\images\black-on-white\[email protected]
––
MD5:  ––
SHA256:  ––
3668
WANACRYPTOR.exe
C:\Users\admin\AppData\Local\Skype\Apps\login\images\black-on-white\[email protected]
––
MD5:  ––
SHA256:  ––
3668
WANACRYPTOR.exe
C:\Users\admin\AppData\Local\Skype\Apps\login\images\black-on-white\[email protected]
binary
MD5: 275d6b4f8e9cde6952d5bb0c5bf351f8
SHA256: 802eeea51b5d5b04cdce7d34ee72a71172ee80b1193dc1f20e772e04434072c3
3668
WANACRYPTOR.exe
C:\Users\admin\AppData\Local\Skype\Apps\login\images\black-on-white\back_20x20.png.WNCRY
binary
MD5: bc601d050a50de7b3a7e7412b1372063
SHA256: 07542d59bf1c7e79889888e2b829756ce68f5f8e2462ed14f13ae418a917dfe2
3668
WANACRYPTOR.exe
C:\Users\admin\AppData\Local\Skype\Apps\login\images\black-on-white\[email protected]
––
MD5:  ––
SHA256:  ––
3668
WANACRYPTOR.exe
C:\Users\admin\AppData\Local\Skype\Apps\login\images\black-on-white\back_20x20.png.WNCRYT
––
MD5:  ––
SHA256:  ––
3668
WANACRYPTOR.exe
C:\Users\admin\AppData\Local\Skype\Apps\login\images\black-on-white\arrow_up_20x20.png.WNCRY
binary
MD5: 3f5770d045fb9090f5b8f7603ec816d3
SHA256: ceac7e4c77d19dacb152b3033a1857d359644cfacde7ab5a686424297c4d3b19
3668
WANACRYPTOR.exe
C:\Users\admin\AppData\Local\Skype\Apps\login\images\msAccountOverlay.png.WNCRY
binary
MD5: 9976c735e1b989fc80bf6dc90688adc6
SHA256: 6de43fe34eb7257ce27f197323233b3f7c86589c8a67b8bb282c4957f4806ad3
3668
WANACRYPTOR.exe
C:\Users\admin\AppData\Local\Skype\Apps\login\images\skype.png.WNCRY
binary
MD5: 4126473da9af6d0b6da6c1d94329e08a
SHA256: 9c41435d359e440ecda5e378bef7faef4f52b95c8021cf67f5d4686c56360ec4
3668
WANACRYPTOR.exe
C:\Users\admin\AppData\Local\Skype\Apps\login\images\plus.png.WNCRY
binary
MD5: d0825d915c26852935abedcaff3924d4
SHA256: 2164f55e385acb8e6ea9240ba4ed01df6a50891e270711482ba2be8d68075751
3668
WANACRYPTOR.exe
C:\Users\admin\AppData\Local\Skype\Apps\login\images\skypeicon.png.WNCRY
binary
MD5: e7b128951f80b074eadc92b0d0507991
SHA256: babe1f63f90d349f3d95e7606c5541add0837f8ebeed6202e2967b016b051777
3668
WANACRYPTOR.exe
C:\Users\admin\AppData\Local\Skype\Apps\login\images\plus.png.WNCRYT
––
MD5:  ––
SHA256:  ––
3668
WANACRYPTOR.exe
C:\Users\admin\AppData\Local\Skype\Apps\login\images\black-on-white\arrow_up_20x20.png.WNCRYT
––
MD5:  ––
SHA256:  ––
3668
WANACRYPTOR.exe
C:\Users\admin\AppData\Local\Skype\Apps\login\images\skype.png.WNCRYT
––
MD5:  ––
SHA256:  ––
3668
WANACRYPTOR.exe
C:\Users\admin\AppData\Local\Skype\Apps\login\images\msAccountOverlay.png.WNCRYT
––
MD5:  ––
SHA256:  ––
3668
WANACRYPTOR.exe
C:\Users\admin\AppData\Local\Skype\Apps\login\images\skypeicon.png.WNCRYT
––
MD5:  ––
SHA256:  ––
3668
WANACRYPTOR.exe
C:\Users\admin\AppData\Local\Skype\Apps\login\images\msAccount.png.WNCRY
binary
MD5: 1c3be8ee549013ada3fbb7ac2bd1cdd5
SHA256: 383bae7eef86adfed9a6f23613b2e7d06a872761bbfa59d5d750aaa21a6184cf
3668
WANACRYPTOR.exe
C:\Users\admin\AppData\Local\Skype\Apps\login\images\messageTopShort.png.WNCRY
binary
MD5: 9ef4630db31ac900263796280c17a642
SHA256: 640f5987a63c4f84d2cbdd7cca35efe5c13165280832376197baae79996b0b21
3668
WANACRYPTOR.exe
C:\Users\admin\AppData\Local\Skype\Apps\login\images\msAccountColour.png.WNCRY
binary
MD5: ac41e69f1f3a6d2ced8b233b6b2e9778
SHA256: d16da5341a8367df9edfe1389c8edbb4bb2d03cd3e8c1b3a82eb533c0a395222
3668
WANACRYPTOR.exe
C:\Users\admin\AppData\Local\Skype\Apps\login\images\messageTopShort.png.WNCRYT
––
MD5:  ––
SHA256:  ––
3668
WANACRYPTOR.exe
C:\Users\admin\AppData\Local\Skype\Apps\login\images\msAccount.png.WNCRYT
––
MD5:  ––
SHA256:  ––
3668
WANACRYPTOR.exe
C:\Users\admin\AppData\Local\Skype\Apps\login\images\msAccountColour.png.WNCRYT
––
MD5:  ––
SHA256:  ––
3668
WANACRYPTOR.exe
C:\Users\admin\AppData\Local\Skype\Apps\login\images\checkbox.png.WNCRY
binary
MD5: 0a6247e0f1f576ae359f84c8f348b070
SHA256: 7158f158ef61d8f3e582de65773bc36ad78ad5ded6a02e238d290e432b62ea0b
3668
WANACRYPTOR.exe
C:\Users\admin\AppData\Local\Skype\Apps\login\images\messageBottom.png.WNCRY
binary
MD5: 850930a85989861500b121f69e1ceb88
SHA256: 82d3fe4511114589ae37b920508f1ffcca7eaab4b1ca24fab03a9e078b01b44d
3668
WANACRYPTOR.exe
C:\Users\admin\AppData\Local\Skype\Apps\login\images\messageBottomShort.png.WNCRY
binary
MD5: 3eca18bc3775ab799cfb3e4ea082e112
SHA256: 02a5a71a4286a3b1cc10e7cc91e81cc00333e522a583afaeb4d358e9a6cf9605
3668
WANACRYPTOR.exe
C:\Users\admin\AppData\Local\Skype\Apps\login\images\messageTop.png.WNCRY
binary
MD5: 52f20df1be268454061af94182aa2396
SHA256: 4645fa26c90bc516ff5ddbda56f73c044d2d301e81c6e836a9c9974662593153
3668
WANACRYPTOR.exe
C:\Users\admin\AppData\Local\Skype\Apps\login\images\connection.png.WNCRY
binary
MD5: adc119596d6d82f3c5927084fc490542
SHA256: 21f16e04563d3a9d67ca4aa4c0184bf0b8fe2b36ed2b7747242461ac3d9d4119
3668
WANACRYPTOR.exe
C:\Users\admin\AppData\Local\Skype\Apps\login\images\facebook.png.WNCRY
binary
MD5: 46f63487319f0949e3d19d6ee91984bf
SHA256: df43d680f555291ef48fec86103fb6d43c64f0047f34733f02573dbbb853cae4
3668
WANACRYPTOR.exe
C:\Users\admin\AppData\Local\Skype\Apps\login\images\facebook.png.WNCRYT
––
MD5:  ––
SHA256:  ––
3668
WANACRYPTOR.exe
C:\Users\admin\AppData\Local\Skype\Apps\login\images\messageBottom.png.WNCRYT
––
MD5:  ––
SHA256:  ––
3668
WANACRYPTOR.exe
C:\Users\admin\AppData\Local\Skype\Apps\login\images\connection.png.WNCRYT
––
MD5:  ––
SHA256:  ––
3668
WANACRYPTOR.exe
C:\Users\admin\AppData\Local\Skype\Apps\login\images\messageBottomShort.png.WNCRYT
––
MD5:  ––
SHA256:  ––
3668
WANACRYPTOR.exe
C:\Users\admin\AppData\Local\Skype\Apps\login\images\messageTop.png.WNCRYT
––
MD5:  ––
SHA256:  ––
3668
WANACRYPTOR.exe
C:\Users\admin\AppData\Local\Opera\Opera\icons\http%3A%2F%2Fredir.opera.com%2Ffavicons%2Fxing%2Ffavicon.png.WNCRY
binary
MD5: 2a20f0ee118ca62b6e05377adcbce53f
SHA256: 03e866208e180e2dae7c36a08d6da169ca07d3a1fc03b79435c7b971597fedfd
3668
WANACRYPTOR.exe
C:\Users\admin\AppData\Local\Skype\Apps\login.js.WNCRY
binary
MD5: 396a86e2bbb935b82d016228d02aa54f
SHA256: 8d97f420ff8e783f704f440b270ce976001cb5780031e612d83dc616de30704c
3668
WANACRYPTOR.exe
C:\Users\admin\AppData\Local\Skype\Apps\login.js.WNCRYT
––
MD5:  ––
SHA256:  ––
3668
WANACRYPTOR.exe
C:\Users\admin\AppData\Local\Opera\Opera\icons\http%3A%2F%2Fredir.opera.com%2Ffavicons%2Fxing%2Ffavicon.png.WNCRYT
––
MD5:  ––
SHA256:  ––
3668
WANACRYPTOR.exe
C:\Users\admin\AppData\Local\Skype\Apps\login\images\checkbox.png.WNCRYT
––
MD5:  ––
SHA256:  ––
3668
WANACRYPTOR.exe
C:\Users\admin\AppData\Local\Opera\Opera\icons\http%3A%2F%2Fredir.opera.com%2Ffavicons%2Fwikipedia%2Ffavicon.png.WNCRY
binary
MD5: ecb0d83839bf2761445b6e531fae3ab3
SHA256: 0e52e2adec6a48fa639af81a7757e3191f58789f4487d8100ab950c6b1978bae
3668
WANACRYPTOR.exe
C:\Users\admin\AppData\Local\Opera\Opera\icons\http%3A%2F%2Fredir.opera.com%2Ffavicons%2Fwikipedia%2Ffavicon.png.WNCRYT
––
MD5:  ––
SHA256:  ––
3668
WANACRYPTOR.exe
C:\Users\admin\AppData\Local\Opera\Opera\icons\http%3A%2F%2Fredir.opera.com%2Ffavicons%2Fsuperdry%2Ffavicon.png.WNCRY
binary
MD5: 81a216bc4f593b607595a516c0d7b0f4
SHA256: 0dbb8a24688423e37ffbd31a9fd88d53fad24a2ae398dd8b4ea902c57dc376c3
3668
WANACRYPTOR.exe
C:\Users\admin\AppData\Local\Opera\Opera\icons\http%3A%2F%2Fredir.opera.com%2Ffavicons%2Ftravel%2Fde%2Ffavicon.png.WNCRY
binary
MD5: 106d4d81930c7e782c0c82b3f629d036
SHA256: 7c871251885b9b36c3ef3d1e67c84225de7286ce82db81d74bb26b1d3ffca301
3668
WANACRYPTOR.exe
C:\Users\admin\AppData\Local\Opera\Opera\icons\http%3A%2F%2Fredir.opera.com%2Ffavicons%2Fsportscheck%2Ffavicon.png.WNCRY
binary
MD5: d4f0dffc120014d246d6ef9cd09f3156
SHA256: c455aa6d2c5f5d0880a126d7bb8e7921da1e3e14c54eb65b227622c18f940df9
3668
WANACRYPTOR.exe
C:\Users\admin\AppData\Local\Opera\Opera\icons\http%3A%2F%2Fredir.opera.com%2Ffavicons%2Fsportscheck%2Ffavicon.png.WNCRYT
––
MD5:  ––
SHA256:  ––
3668
WANACRYPTOR.exe
C:\Users\admin\AppData\Local\Opera\Opera\icons\http%3A%2F%2Fredir.opera.com%2Ffavicons%2Ftravel%2Fde%2Ffavicon.png.WNCRYT
––
MD5:  ––
SHA256:  ––
3668
WANACRYPTOR.exe
C:\Users\admin\AppData\Local\Opera\Opera\icons\http%3A%2F%2Fredir.opera.com%2Ffavicons%2Fsuperdry%2Ffavicon.png.WNCRYT
––
MD5:  ––
SHA256:  ––
3668
WANACRYPTOR.exe
C:\Users\admin\AppData\Local\Opera\Opera\icons\http%3A%2F%2Fredir.opera.com%2Ffavicons%2Fshopping4%2Fde%2Ffavicon.png.WNCRY
binary
MD5: 85068b5c438c3395ef6facdbcd2ddac0
SHA256: 9083bf44e258c42deee7c774e58658480df9a2a8f07d51418d521c2a7a04c098
3668
WANACRYPTOR.exe
C:\Users\admin\AppData\Local\Opera\Opera\icons\http%3A%2F%2Fredir.opera.com%2Ffavicons%2Fshopping5%2Fde%2Ffavicon.png.WNCRY
binary
MD5: 67d079fe0dce10520e5f640aab8249e7
SHA256: 2718f7abb4955e6c44c42a65df9efd2c0c0748a202983c4a9ee648fb7d31f0ff
3668
WANACRYPTOR.exe
C:\Users\admin\AppData\Local\Opera\Opera\icons\http%3A%2F%2Fredir.opera.com%2Ffavicons%2Fshopping3%2Fde%2Ffavicon.png.WNCRY
binary
MD5: 4ed1307d4d8c6e262cf30178140c86d8
SHA256: d777e353de2f4bf124e84ebef5d9cea8650004a4ab9fc679cf6fa3b8f2421148
3668
WANACRYPTOR.exe
C:\Users\admin\AppData\Local\Opera\Opera\icons\http%3A%2F%2Fredir.opera.com%2Ffavicons%2Fshopping4%2Fde%2Ffavicon.png.WNCRYT
––
MD5:  ––
SHA256:  ––
3668
WANACRYPTOR.exe
C:\Users\admin\AppData\Local\Opera\Opera\icons\http%3A%2F%2Fredir.opera.com%2Ffavicons%2Fshopping5%2Fde%2Ffavicon.png.WNCRYT
––
MD5:  ––
SHA256:  ––
3668
WANACRYPTOR.exe
C:\Users\admin\AppData\Local\Opera\Opera\icons\http%3A%2F%2Fredir.opera.com%2Ffavicons%2Fshopping3%2Fde%2Ffavicon.png.WNCRYT
––
MD5:  ––
SHA256:  ––
3668
WANACRYPTOR.exe
C:\Users\admin\AppData\Local\Opera\Opera\icons\http%3A%2F%2Fredir.opera.com%2Ffavicons%2Fproperty%2Fde%2Ffavicon.png.WNCRY
binary
MD5: a970d9444f8318f5f5bd1d6b6c1dd034
SHA256: 233512bc9ce72372a7c5d10b3ef66de7e9a3c37c157677ab9e7253ef2254242e
3668
WANACRYPTOR.exe
C:\Users\admin\AppData\Local\Opera\Opera\icons\http%3A%2F%2Fredir.opera.com%2Ffavicons%2Fopera.sports.com%2Ffavicon.png.WNCRY
binary
MD5: 79da2b7795b1c247fd3b678eeff429dc
SHA256: 2b14d7aef503511248386e72d1dcac362c06ca87b4793a2b796bf8d8ebf05844
3668
WANACRYPTOR.exe
C:\Users\admin\AppData\Local\Opera\Opera\icons\http%3A%2F%2Fredir.opera.com%2Ffavicons%2Fpreisvergleichde%2Ffavicon.png.WNCRY
binary
MD5: ed1a6ef272a2c0ff1c51d64d46f88ab6
SHA256: fc48356316ef08dba3dc4c01ed43590a16db4bb792e24dd5bd32175bd4579250
3668
WANACRYPTOR.exe
C:\Users\admin\AppData\Local\Opera\Opera\icons\http%3A%2F%2Fredir.opera.com%2Ffavicons%2Fpreisvergleichde%2Ffavicon.png.WNCRYT
––
MD5:  ––
SHA256:  ––
3668
WANACRYPTOR.exe
C:\Users\admin\AppData\Local\Opera\Opera\icons\http%3A%2F%2Fredir.opera.com%2Ffavicons%2Fproperty%2Fde%2Ffavicon.png.WNCRYT
––
MD5:  ––
SHA256:  ––
3668
WANACRYPTOR.exe
C:\Users\admin\AppData\Local\Opera\Opera\icons\http%3A%2F%2Fredir.opera.com%2Ffavicons%2Fopera.sports.com%2Ffavicon.png.WNCRYT
––
MD5:  ––
SHA256:  ––
3668
WANACRYPTOR.exe
C:\Users\admin\AppData\Local\Opera\Opera\icons\http%3A%2F%2Fredir.opera.com%2Ffavicons%2Fmeingutscheincode%2Ffavicon.png.WNCRY
binary
MD5: fdd796c0b71b666e9ab6fc3c0e89a97c
SHA256: c0f249f8b30e9adf83ce998943efa79ac4cf11f87e0cebec13545ef3d4a585e3
3668
WANACRYPTOR.exe
C:\Users\admin\AppData\Local\Opera\Opera\icons\http%3A%2F%2Fredir.opera.com%2Ffavicons%2Fmeingutscheincode%2Ffavicon.png.WNCRYT
––
MD5:  ––
SHA256:  ––
3668
WANACRYPTOR.exe
C:\Users\admin\AppData\Local\Opera\Opera\icons\http%3A%2F%2Fredir.opera.com%2Ffavicons%2Fjavari%2Ffavicon.png.WNCRY
binary
MD5: a61af3520a2143f9e8d44ee9f87886bc
SHA256: 854270161fb857739c05b4aa214fbe625d6801c94b27d6a834f124dcc33e048c
3668
WANACRYPTOR.exe
C:\Users\admin\AppData\Local\Opera\Opera\icons\http%3A%2F%2Fredir.opera.com%2Ffavicons%2Fjavari%2Ffavicon.png.WNCRYT
––
MD5:  ––
SHA256:  ––
3668
WANACRYPTOR.exe
C:\Users\admin\AppData\Local\Opera\Opera\icons\http%3A%2F%2Fredir.opera.com%2Ffavicons%2Fidealo%2Ffavicon.png.WNCRY
binary
MD5: cde72c817d35e57ec7c84bf9347d65a2
SHA256: e155055b17e0db4a08f537482ab6efc702e9c49c4ded2332240ea5a2790599d9
3668
WANACRYPTOR.exe
C:\Users\admin\AppData\Local\Opera\Opera\icons\http%3A%2F%2Fredir.opera.com%2Ffavicons%2Fhawesko%2Ffavicon.png.WNCRY
binary
MD5: f61a69a6f23d03fc0aef0577994e923d
SHA256: dde2623d1913e2a446446df5cf6f828e6f7fc9d959ac3688a472f127e37e371e
3668
WANACRYPTOR.exe
C:\Users\admin\AppData\Local\Opera\Opera\icons\http%3A%2F%2Fredir.opera.com%2Ffavicons%2Fhotels.com%2Ffavicon.png.WNCRY
binary
MD5: 81e5166aeba0a534ff831efd2196a7e3
SHA256: e416cf15fec387da13a577116e3704f0e9011477ed3f67de61361ee0fc3f5034
3668
WANACRYPTOR.exe
C:\Users\admin\AppData\Local\Opera\Opera\icons\http%3A%2F%2Fredir.opera.com%2Ffavicons%2Fidealo%2Ffavicon.png.WNCRYT
––
MD5:  ––
SHA256:  ––
3668
WANACRYPTOR.exe
C:\Users\admin\AppData\Local\Opera\Opera\icons\http%3A%2F%2Fredir.opera.com%2Ffavicons%2Fhotels.com%2Ffavicon.png.WNCRYT
––
MD5:  ––
SHA256:  ––
3668
WANACRYPTOR.exe
C:\Users\admin\AppData\Local\Opera\Opera\icons\http%3A%2F%2Fredir.opera.com%2Ffavicons%2Fgame%2Fde%2Ffavicon.png.WNCRY
binary
MD5: eeed438fb4e96435ac4180226096cdde
SHA256: a142761e2c23e237111743ceb21a3e00237935c4346b0b71d6f6e90564551565
3668
WANACRYPTOR.exe
C:\Users\admin\AppData\Local\Opera\Opera\icons\http%3A%2F%2Fredir.opera.com%2Ffavicons%2Fhawesko%2Ffavicon.png.WNCRYT
––
MD5:  ––
SHA256:  ––
3668
WANACRYPTOR.exe
C:\Users\admin\AppData\Local\Opera\Opera\icons\http%3A%2F%2Fredir.opera.com%2Ffavicons%2Fgame%2Fde%2Ffavicon.png.WNCRYT
––
MD5:  ––
SHA256:  ––
3668
WANACRYPTOR.exe
C:\Users\admin\AppData\Local\Opera\Opera\icons\http%3A%2F%2Fredir.opera.com%2Ffavicons%2Ffastmail%2Ffavicon.png.WNCRY
binary
MD5: d031923d705804ed13f0402f5a124d30
SHA256: 161fc5c8e6cf8681596c1ee2cd6b78a69be57f039ed8c6f941eb6e11b07158a5
3668
WANACRYPTOR.exe
C:\Users\admin\AppData\Local\Opera\Opera\icons\http%3A%2F%2Fredir.opera.com%2Ffavicons%2Ffastmail%2Ffavicon.png.WNCRYT
––
MD5:  ––
SHA256:  ––
3668
WANACRYPTOR.exe
C:\Users\admin\AppData\Local\Opera\Opera\icons\http%3A%2F%2Fredir.opera.com%2Ffavicons%2Febay%2Ffavicon.png.WNCRY
binary
MD5: 671b02d5d98b09d03e9e8f5d73275154
SHA256: a384d8e287ba27a7d5cf7fa539703c13e1375a70aec3c387d53f3e25981a3fc4
3668
WANACRYPTOR.exe
C:\Users\admin\AppData\Local\Opera\Opera\icons\http%3A%2F%2Fredir.opera.com%2Ffavicons%2Fdownloadcom%2Ffavicon.png.WNCRY
binary
MD5: 1d5320c833bd149ae7ebe413a2b229be
SHA256: 7a0048f5476afe23fd2758c139356983c68a23d142484e1f37560178f1d31e24
3668
WANACRYPTOR.exe
C:\Users\admin\AppData\Local\Opera\Opera\icons\http%3A%2F%2Fredir.opera.com%2Ffavicons%2Fexpedia%2Ffavicon.png.WNCRY
binary
MD5: 05ee94a9977644b303c6dabf94d31578
SHA256: 364f242e03708c4fa068a45b9a3011b771b5302f7d6e49eaba98d24ebd4402ff
3668
WANACRYPTOR.exe
C:\Users\admin\AppData\Local\Opera\Opera\icons\http%3A%2F%2Fredir.opera.com%2Ffavicons%2Febay%2Ffavicon.png.WNCRYT
––
MD5:  ––
SHA256:  ––
3668
WANACRYPTOR.exe
C:\Users\admin\AppData\Local\Opera\Opera\icons\http%3A%2F%2Fredir.opera.com%2Ffavicons%2Fexpedia%2Ffavicon.png.WNCRYT
––
MD5:  ––
SHA256:  ––
3668
WANACRYPTOR.exe
C:\Users\admin\AppData\Local\Opera\Opera\icons\http%3A%2F%2Fredir.opera.com%2Ffavicons%2Fbigpoint%2Ffavicon.png.WNCRY
binary
MD5: 1a275b9099d70520b98dd799ffa5894d
SHA256: a4064692e65b99d9559467317c988e02e266c27eb8d46766c9fa2acf0c638d2e
3668
WANACRYPTOR.exe
C:\Users\admin\AppData\Local\Opera\Opera\icons\http%3A%2F%2Fredir.opera.com%2Ffavicons%2Fbing%2Ffavicon.png.WNCRY
binary
MD5: 7ecbd140af7f87fb70732d51bfaae38c
SHA256: 6769b79d6414cdf1d2d30ddac0901732cbee6bb92c1c6d9f8dbfb532b557e574
3668
WANACRYPTOR.exe
C:\Users\admin\AppData\Local\Opera\Opera\icons\http%3A%2F%2Fredir.opera.com%2Ffavicons%2Fbuecher%2Ffavicon.png.WNCRY
binary
MD5: 851ea0ba3efab841b55b2eed1ef50f1a
SHA256: 554254cbfb14edf3ec041c6f6bfb528bbed51424aa13bfc6f81e920dc1dd6f59
3668
WANACRYPTOR.exe
C:\Users\admin\AppData\Local\Opera\Opera\icons\http%3A%2F%2Fredir.opera.com%2Ffavicons%2Fbing%2Ffavicon.png.WNCRYT
––
MD5:  ––
SHA256:  ––
3668
WANACRYPTOR.exe
C:\Users\admin\AppData\Local\Opera\Opera\icons\http%3A%2F%2Fredir.opera.com%2Ffavicons%2Fdownloadcom%2Ffavicon.png.WNCRYT
––
MD5:  ––
SHA256:  ––
3668
WANACRYPTOR.exe
C:\Users\admin\AppData\Local\Opera\Opera\icons\http%3A%2F%2Fredir.opera.com%2Ffavicons%2Fbuecher%2Ffavicon.png.WNCRYT
––
MD5:  ––
SHA256:  ––
3668
WANACRYPTOR.exe
C:\Users\admin\AppData\Local\Opera\Opera\icons\http%3A%2F%2Fredir.opera.com%2Ffavicons%2Fbigpoint%2Ffavicon.png.WNCRYT
––
MD5:  ––
SHA256:  ––
3668
WANACRYPTOR.exe
C:\Users\admin\AppData\Local\Opera\Opera\icons\http%3A%2F%2Fredir.opera.com%2Ffavicons%2Falternate%2Ffavicon.png.WNCRY
binary
MD5: 06d3132e288417c8cfc0d5e13f553206
SHA256: a04fffab817bffaa9e03e62e1ca29be983c579467a143757ef94701989581ee4
3668
WANACRYPTOR.exe
C:\Users\admin\AppData\Local\Opera\Opera\icons\http%3A%2F%2Fredir.opera.com%2Ffavicons%2Famazon%2Ffavicon.png.WNCRY
binary
MD5: 4d6c1eab8fff1b41c1f7dd22683a7953
SHA256: 06c0aebae3c0634b5cf0ab53bb617d2b7cfd53e8204158bbf595be69b7ae4638
3668
WANACRYPTOR.exe
C:\Users\admin\AppData\Local\Opera\Opera\icons\http%3A%2F%2Fredir.opera.com%2Ffavicons%2F%2Ftravel1%2Fde%2Ffavicon.png.WNCRY
binary
MD5: 6559062502e8428c354d178582bbc73b
SHA256: dbfdcf5d7059a0b565000e16a1a666b9ae270ced3ad13c83fa5772ec7e14e487
3668
WANACRYPTOR.exe
C:\Users\admin\AppData\Local\Opera\Opera\icons\http%3A%2F%2Fimg.yandex.net%2Fi%2Ffavicon.png.WNCRY
binary
MD5: 0cc2d6bf27c117bc6c9ed923a5b6aa5a
SHA256: 2682a1b58a6f5221336169c0ba4a329a217f20c91185aa298e7981139121d3dc
3668
WANACRYPTOR.exe
C:\Users\admin\AppData\Local\Opera\Opera\icons\http%3A%2F%2Fredir.opera.com%2Ffavicons%2F%2Ftravel1%2Fde%2Ffavicon.png.WNCRYT
––
MD5:  ––
SHA256:  ––
3668
WANACRYPTOR.exe
C:\Users\admin\AppData\Local\Opera\Opera\icons\http%3A%2F%2Fimg.yandex.net%2Fi%2Ffavicon.png.WNCRYT
––
MD5:  ––
SHA256:  ––
3668
WANACRYPTOR.exe
C:\Users\admin\AppData\Local\Opera\Opera\icons\http%3A%2F%2Fredir.opera.com%2Ffavicons%2Famazon%2Ffavicon.png.WNCRYT
––
MD5:  ––
SHA256:  ––
3668
WANACRYPTOR.exe
C:\Users\admin\AppData\Local\Opera\Opera\icons\http%3A%2F%2Fredir.opera.com%2Ffavicons%2Falternate%2Ffavicon.png.WNCRYT
––
MD5:  ––
SHA256:  ––
3668
WANACRYPTOR.exe
C:\Users\admin\AppData\Local\Microsoft\Windows\Explorer\thumbcache_sr.db.WNCRY
binary
MD5: ec69d39ca3972a5210000704ddf72981
SHA256: 1ff7aa48ade9b0d2e5680d8bdeb8df751fde2019463a6f53082ddde657dd9566
3668
WANACRYPTOR.exe
C:\Users\admin\AppData\Local\Opera\Opera\icons\http%3A%2F%2Fimg.imgsmail.ru%2Fr%2Ffavicon.png.WNCRY
binary
MD5: ab2ef4fe7f8ce05509178868e3f718ad
SHA256: 7f19e5b2551193f4fdf5db8999dc3244ecbe0f17e6f4f92ff8752033ae14bdf4
3668
WANACRYPTOR.exe
C:\Users\admin\AppData\Local\Opera\Opera\icons\http%3A%2F%2Fimg.imgsmail.ru%2Fr%2Ffavicon.png.WNCRYT
––
MD5:  ––
SHA256:  ––
3668
WANACRYPTOR.exe
C:\Users\admin\AppData\Local\Microsoft\OneNote\14.0\OneNoteOfflineCache_Files\a4f6c176-53e1-47b9-8fe4-8bb920684ff3.png.WNCRY
binary
MD5: d7f756276ce265ffd944d8d3bc1ad874
SHA256: 9bbb49e6d547c62ce16ace7c83ba506a1ad96a14354fbce68a6eb1e5552fbfc9
3668
WANACRYPTOR.exe
C:\Users\admin\AppData\Local\Microsoft\OneNote\14.0\OneNoteOfflineCache_Files\3506c6f4-6090-46ec-9fb3-0e2963361ba0.png.WNCRY
binary
MD5: d8ecd649bcde3584db198c71c56e9749
SHA256: 548ca108c84db3dbf2231e8979d6d1a09dd3c55d400fa4bd184b982a595122a1
3668
WANACRYPTOR.exe
C:\Users\admin\AppData\Local\Microsoft\Windows\Explorer\thumbcache_1024.db.WNCRY
binary
MD5: 872827698d7f5e694201684be27d4694
SHA256: 1854fa62647e1087173ce6ed16707eddba7cd3f4bd7544c9aebd2c0e5d885d7d
3668
WANACRYPTOR.exe
C:\Users\admin\AppData\Local\Microsoft\OneNote\14.0\OneNoteOfflineCache_Files\a4f6c176-53e1-47b9-8fe4-8bb920684ff3.png.WNCRYT
––
MD5:  ––
SHA256:  ––
3668
WANACRYPTOR.exe
C:\Users\admin\AppData\Local\Microsoft\Windows\Explorer\thumbcache_sr.db.WNCRYT
––
MD5:  ––
SHA256:  ––
3668
WANACRYPTOR.exe
C:\Users\admin\AppData\Local\Microsoft\Windows\Explorer\thumbcache_1024.db.WNCRYT
––
MD5:  ––
SHA256:  ––
3668
WANACRYPTOR.exe
C:\Users\admin\AppData\Local\Google\Chrome\User Data\Default\Extensions\pkedcjkdefgpdelpbcmbmeomcjbeemfm\6818.528.0.0_0\cast_setup\cast_app_redirect.js.WNCRY
binary
MD5: af34a5b136cd6d77012db2377a12609e
SHA256: e63c978a13adc5c9b30a398f03d8e22387e18f51c8ea587de2332a791714f9b8
3668
WANACRYPTOR.exe
C:\Users\admin\AppData\Local\Microsoft\OneNote\14.0\OneNoteOfflineCache_Files\3506c6f4-6090-46ec-9fb3-0e2963361ba0.png.WNCRYT
––
MD5:  ––
SHA256:  ––
3668
WANACRYPTOR.exe
C:\Users\admin\AppData\Local\Google\Chrome\User Data\Default\Extensions\pkedcjkdefgpdelpbcmbmeomcjbeemfm\6818.528.0.0_0\cast_setup\cast_app_redirect.js.WNCRYT
––
MD5:  ––
SHA256:  ––
3668
WANACRYPTOR.exe
C:\Users\admin\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda\1.0.0.4_0\images\topbar_floating_button_hover.png.WNCRY
binary
MD5: 49bc5bd137f69e08356c1d971a68a218
SHA256: 995fc6daeef0005cc8511978ac7a430db1c2f679cb732227e4408dc5ce90ffd2
3668
WANACRYPTOR.exe
C:\Users\admin\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda\1.0.0.4_0\images\topbar_floating_button_maximize.png.WNCRY
binary
MD5: 6fe1ee6bf88d594c0c3c88d915c7722b
SHA256: a7ccf2425a53fb699c547abc199176480a51fe87b7eebc44cba99e4d52f13b7d
3668
WANACRYPTOR.exe
C:\Users\admin\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda\1.0.0.4_0\images\topbar_floating_button_pressed.png.WNCRY
binary
MD5: fb45ba12ddff547a46b2b8808b3f8f6b
SHA256: fd1afaec12cf66c94a9ca9b392bd3022a645b5c0978dca069c0246d7dfc5a4fe
3668
WANACRYPTOR.exe
C:\Users\admin\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda\1.0.0.4_0\images\topbar_floating_button_close.png.WNCRY
binary
MD5: 24d5a4c4789a82f1e8b8d2c52c559cd5
SHA256: 1752fd690f9556a6a8197d173fdef8a2c558d7a73f62bf2848e1b74de0228717
3668
WANACRYPTOR.exe
C:\Users\admin\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda\1.0.0.4_0\images\topbar_floating_button_pressed.png.WNCRYT
––
MD5:  ––
SHA256:  ––
3668
WANACRYPTOR.exe
C:\Users\admin\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda\1.0.0.4_0\images\topbar_floating_button_hover.png.WNCRYT
––
MD5:  ––
SHA256:  ––
3668
WANACRYPTOR.exe
C:\Users\admin\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda\1.0.0.4_0\images\topbar_floating_button_maximize.png.WNCRYT
––
MD5:  ––
SHA256:  ––
3668
WANACRYPTOR.exe
C:\Users\admin\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda\1.0.0.4_0\images\topbar_floating_button.png.WNCRY
binary
MD5: 025d3a5450a0a97a5c99ba323ee252e9
SHA256: 494c1df709b1d6a6dcc2ceb39d4a137b9e155bba0d1caaa9577aa39c6e8f6bbd
3668
WANACRYPTOR.exe
C:\Users\admin\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda\1.0.0.4_0\images\topbar_floating_button.png.WNCRYT
––
MD5:  ––
SHA256:  ––
3668
WANACRYPTOR.exe
C:\Users\admin\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda\1.0.0.4_0\images\topbar_floating_button_close.png.WNCRYT
––
MD5:  ––
SHA256:  ––
3668
WANACRYPTOR.exe
C:\Users\admin\AppData\Local\Google\Chrome\User Data\Default\Extensions\ghbmnnjooekpmoecnnnilnnbdlolhkhi\1.7_1\resources\questionMark.png.WNCRY
binary
MD5: 764119909c05f28edb72762b1f10649c
SHA256: 62d4daf5acf38e5cf04b8ba404361447b712e32effdba4f8a629b008f1a56885
3668
WANACRYPTOR.exe
C:\Users\admin\AppData\Local\Google\Chrome\User Data\Default\Extensions\ghbmnnjooekpmoecnnnilnnbdlolhkhi\1.7_1\resources\sheets.png.WNCRY
binary
MD5: 4043b92c0c4f2d16d80151644dc4a5ec
SHA256: 5d240ab6e1a3d004fda3b4811258ed0c4d56d0056b5b68563ac3e09c88cda57b
3668
WANACRYPTOR.exe
C:\Users\admin\AppData\Local\Google\Chrome\User Data\Default\Extensions\ghbmnnjooekpmoecnnnilnnbdlolhkhi\1.7_1\resources\slides.png.WNCRY
binary
MD5: f175d8e8a2c2ab0440d294328b6bb6fa
SHA256: f68cc77336d46e3c136834809bd50b46af37b5579d06080015dc6aa9fde6f056
3668
WANACRYPTOR.exe
C:\Users\admin\AppData\Local\Google\Chrome\User Data\Default\Extensions\ghbmnnjooekpmoecnnnilnnbdlolhkhi\1.7_1\resources\offlineIcon.png.WNCRY
binary
MD5: bffeac11f8e8442ea042b1dad6d5585f
SHA256: c0645db55e78f0689408dc1821a92e9c88c866141187c215c956cbb5ca016863
3668
WANACRYPTOR.exe
C:\Users\admin\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda\1.0.0.4_0\images\icon_16.png.WNCRY
binary
MD5: 31e4d7835a45f5fcbe702a33b3b1364d
SHA256: 1a7ef45c37664db97495645dab63dcba1a94fbe7b2be0a5a68d292e8a58d2098
3668
WANACRYPTOR.exe
C:\Users\admin\AppData\Local\Google\Chrome\User Data\Default\Extensions\ghbmnnjooekpmoecnnnilnnbdlolhkhi\1.7_1\resources\sheets.png.WNCRYT
––
MD5:  ––
SHA256:  ––
3668
WANACRYPTOR.exe
C:\Users\admin\AppData\Local\Google\Chrome\User Data\Default\Extensions\ghbmnnjooekpmoecnnnilnnbdlolhkhi\1.7_1\resources\offlineIcon.png.WNCRYT
––
MD5:  ––
SHA256:  ––
3668
WANACRYPTOR.exe
C:\Users\admin\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda\1.0.0.4_0\images\icon_16.png.WNCRYT
––
MD5:  ––
SHA256:  ––
3668
WANACRYPTOR.exe
C:\Users\admin\AppData\Local\Google\Chrome\User Data\Default\Extensions\ghbmnnjooekpmoecnnnilnnbdlolhkhi\1.7_1\resources\questionMark.png.WNCRYT
––
MD5:  ––
SHA256:  ––
3668
WANACRYPTOR.exe
C:\Users\admin\AppData\Local\Google\Chrome\User Data\Default\Extensions\ghbmnnjooekpmoecnnnilnnbdlolhkhi\1.7_1\resources\slides.png.WNCRYT
––
MD5:  ––
SHA256:  ––
3668
WANACRYPTOR.exe
C:\Users\admin\AppData\Local\Google\Chrome\User Data\Default\Extensions\ghbmnnjooekpmoecnnnilnnbdlolhkhi\1.7_1\resources\docs.png.WNCRY
binary
MD5: 1f3d57072dcb8d399b3e676b0a7eb81e
SHA256: 4b87bdc13ab317f758b2c6f1d477d36097f295940b01cf8c88874edf7b6dbae8
3668
WANACRYPTOR.exe
C:\Users\admin\AppData\Local\Google\Chrome\User Data\Default\Extensions\ghbmnnjooekpmoecnnnilnnbdlolhkhi\1.7_1\resources\arrowUp.png.WNCRY
binary
MD5: 7e4e8c696b8a56affd80b49a487734b4
SHA256: d1b66df2e6e65ecb82fafa5ed364dccb955b1f48cf82a4db23e6b99e004e0186
3668
WANACRYPTOR.exe
C:\Users\admin\AppData\Local\Google\Chrome\User Data\Default\Extensions\ghbmnnjooekpmoecnnnilnnbdlolhkhi\1.7_1\resources\docs.png.WNCRYT
––
MD5:  ––
SHA256:  ––
3668
WANACRYPTOR.exe
C:\Users\admin\AppData\Local\Google\Chrome\User Data\Default\Extensions\ghbmnnjooekpmoecnnnilnnbdlolhkhi\1.7_1\resources\arrowUp.png.WNCRYT
––
MD5:  ––
SHA256:  ––
3668
WANACRYPTOR.exe
C:\Users\admin\AppData\Local\Google\Chrome\User Data\Default\Extensions\felcaaldnbdncclmgdcncolpebgiejap\1.2_0\main.js.WNCRY
binary
MD5: 31250d2bc8dd2655adebaa97aba94f4f
SHA256: 66c044b42cfa1347d48b5e9d179f59bc569628bd5b3ea203a24739348ecc3c16
3668
WANACRYPTOR.exe
C:\Users\admin\AppData\Local\Google\Chrome\User Data\Default\Extensions\ghbmnnjooekpmoecnnnilnnbdlolhkhi\1.7_1\page_embed_script.js.WNCRY
binary
MD5: 0b46931f79a5bc45345a634e67d7dbf2
SHA256: 109d8f84be87b2b43cb8e6589d452b10dc2be931a9ab83462b93addc30e27aba
3668
WANACRYPTOR.exe
C:\Users\admin\AppData\Local\Google\Chrome\User Data\Default\Extensions\ghbmnnjooekpmoecnnnilnnbdlolhkhi\1.7_1\page_embed_script.js.WNCRYT
––
MD5:  ––
SHA256:  ––
3668
WANACRYPTOR.exe
C:\Users\admin\AppData\Local\Google\Chrome\User Data\Default\Extensions\felcaaldnbdncclmgdcncolpebgiejap\1.2_0\icon_16.png.WNCRY
binary
MD5: edcae0cdcb98ca8481b743c30cd7a688
SHA256: eed456b25e3b64feaffe991892dc5c597ebe7baf6cbc62563e9c25803f906b29
3668
WANACRYPTOR.exe
C:\Users\admin\AppData\Local\Google\Chrome\User Data\Default\Extensions\aohghmighlieiainnegkcijnfilokake\0.10_0\main.js.WNCRY
binary
MD5: 1fea640b22a2d90a7ab3f3055ad3fe4d
SHA256: 7541627e6fee97c99b541c45377d6a887b2bb7dbad42a366d32cc95bbf5ddad8
3668
WANACRYPTOR.exe
C:\Users\admin\AppData\Local\Google\Chrome\User Data\Default\Extensions\aohghmighlieiainnegkcijnfilokake\0.10_0\main.js.WNCRYT
––
MD5:  ––
SHA256:  ––
3668
WANACRYPTOR.exe
C:\Users\admin\AppData\Local\Google\Chrome\User Data\Default\Extensions\felcaaldnbdncclmgdcncolpebgiejap\1.2_0\icon_16.png.WNCRYT
––
MD5:  ––
SHA256:  ––
3668
WANACRYPTOR.exe
C:\Users\admin\AppData\Local\Google\Chrome\User Data\Default\Extensions\felcaaldnbdncclmgdcncolpebgiejap\1.2_0\main.js.WNCRYT
––
MD5:  ––
SHA256:  ––
3668
WANACRYPTOR.exe
C:\Users\admin\AppData\Local\Google\Chrome\User Data\Default\Extensions\aohghmighlieiainnegkcijnfilokake\0.10_0\icon_16.png.WNCRY
binary
MD5: 4e3864aca7ccf8a915b57b2baa8d4fbb
SHA256: 06f3efea4bedbf0a133525a2fd9ba32f9b541cd25e497455020455212fc512c5
3668
WANACRYPTOR.exe
C:\Users\admin\AppData\Local\Google\Chrome\User Data\Default\Extensions\aohghmighlieiainnegkcijnfilokake\0.10_0\icon_16.png.WNCRYT
––
MD5:  ––
SHA256:  ––
3668
WANACRYPTOR.exe
C:\Users\admin\AppData\Local\Google\Chrome\User Data\Default\Extensions\aapocclcgogkmnckokdopfmhonfmgoek\0.10_0\main.js.WNCRY
binary
MD5: 1ec128abd33be3395c3264ea1dec6ad8
SHA256: ad5071fdcb097f89af25e2e943651995b789c4a6a323b627aae605050638289a
3668
WANACRYPTOR.exe
C:\Users\admin\AppData\Local\Google\Chrome\User Data\Default\Extensions\aapocclcgogkmnckokdopfmhonfmgoek\0.10_0\main.js.WNCRYT
––
MD5:  ––
SHA256:  ––
3668
WANACRYPTOR.exe
C:\Users\admin\AppData\Local\Google\Chrome\User Data\Default\Extensions\aapocclcgogkmnckokdopfmhonfmgoek\0.10_0\icon_16.png.WNCRY
binary
MD5: c95e6bcf00d71872432825fe90ff32d5
SHA256: 34cb4b229e4ec5ed6afcfe5bc3738bd076ceac1c458a5def5ecf157ba365bb79
3668
WANACRYPTOR.exe
C:\Users\admin\AppData\Local\Google\Chrome\User Data\Default\Extensions\aapocclcgogkmnckokdopfmhonfmgoek\0.10_0\icon_16.png.WNCRYT
––
MD5:  ––
SHA256:  ––
3668
WANACRYPTOR.exe
C:\Users\admin\AppData\Local\FileZilla\default_synchronize20x20.png.WNCRY
binary
MD5: 59f5ea4900043ece36bd38712fdf465e
SHA256: ed2e29d528daa043068807ae20d81cf05c4248af90bae1fb088c35057eeca034
3668
WANACRYPTOR.exe
C:\Users\admin\AppData\Local\Google\Chrome\User Data\chrome_shutdown_ms.txt.WNCRY
binary
MD5: f538b7219a48e1da59352973bb9c646c
SHA256: 857cd042a993ab084cca30f9e3f9ed371cb4fb47e2b8a61095b1d7f68673cb7b
3668
WANACRYPTOR.exe
C:\Users\admin\AppData\Local\Google\Chrome\User Data\chrome_shutdown_ms.txt.WNCRYT
––
MD5:  ––
SHA256:  ––
3668
WANACRYPTOR.exe
C:\Users\admin\AppData\Local\FileZilla\default_synchronize20x20.png.WNCRYT
––
MD5:  ––
SHA256:  ––
3668
WANACRYPTOR.exe
C:\Users\admin\AppData\Local\FileZilla\default_speedlimits16x16.png.WNCRY
binary
MD5: b8be746579f601e7c93f6b940ddb7693
SHA256: e67e4b1d3f965bfc8c33ac2a7da36dd1aeb42ac9ad0da52f9180708690f44f9d
3668
WANACRYPTOR.exe
C:\Users\admin\AppData\Local\FileZilla\default_speedlimits16x16.png.WNCRYT
––
MD5:  ––
SHA256:  ––
3668
WANACRYPTOR.exe
C:\Users\admin\AppData\Local\FileZilla\default_sitemanager20x20.png.WNCRY
binary
MD5: 5627e2273292eec3def16887b7191d1b
SHA256: 152e8c3ebadd9aed3e691dc1484a063b4c14092ebcdaacc894b5a2cfede2d179
3668
WANACRYPTOR.exe
C:\Users\admin\AppData\Local\FileZilla\default_sitemanager20x20.png.WNCRYT
––
MD5:  ––
SHA256:  ––
3668
WANACRYPTOR.exe
C:\Users\admin\AppData\Local\FileZilla\default_server16x16.png.WNCRY
binary
MD5: 6cb47a0474225c6a327795e30ea41dcd
SHA256: 4c49525c87b5c6f3cf2594ba208d5435aa4f780119b40412db7a291342c29b35
3668
WANACRYPTOR.exe
C:\Users\admin\AppData\Local\FileZilla\default_remotetreeview20x20.png.WNCRY
binary
MD5: a42ac5436d9854c4072ca2b3d7b20729
SHA256: 11c411b8bfb1ed75ec0a29f4e4886c10a1a402bf0846bd91c3548672d92ff366
3668
WANACRYPTOR.exe
C:\Users\admin\AppData\Local\FileZilla\default_server16x16.png.WNCRYT
––
MD5:  ––
SHA256:  ––
3668
WANACRYPTOR.exe
C:\Users\admin\AppData\Local\FileZilla\default_remotetreeview20x20.png.WNCRYT
––
MD5:  ––
SHA256:  ––
3668
WANACRYPTOR.exe
C:\Users\admin\AppData\Local\FileZilla\default_refresh20x20.png.WNCRY
binary
MD5: add9e04422ec475bb7b17f8d72d6426c
SHA256: 3138d87963ac46c0a5645b19b15a5ec2224ceb23e1f54ca9d77ac4603ccfab7c
3668
WANACRYPTOR.exe
C:\Users\admin\AppData\Local\FileZilla\default_refresh20x20.png.WNCRYT
––
MD5:  ––
SHA256:  ––
3668
WANACRYPTOR.exe
C:\Users\admin\AppData\Local\FileZilla\default_reconnect20x20.png.WNCRY
binary
MD5: d4d649c65e58d3abc061e985ed6ac56d
SHA256: 99a3bcf5b31926d11556e609af856a6db46a6249b7450ef81cda073d7319a0d6
3668
WANACRYPTOR.exe
C:\Users\admin\AppData\Local\FileZilla\default_reconnect20x20.png.WNCRYT
––
MD5:  ––
SHA256:  ––
3668
WANACRYPTOR.exe
C:\Users\admin\AppData\Local\FileZilla\default_queueview20x20.png.WNCRY
binary
MD5: 38953d1cc97a65016fce2057f2edc424
SHA256: 56475864b8fe90325554747e975e220af1d9aecc6512e500638c605e874a16e3
3668
WANACRYPTOR.exe
C:\Users\admin\AppData\Local\FileZilla\default_queueview20x20.png.WNCRYT
––
MD5:  ––
SHA256:  ––
3668
WANACRYPTOR.exe
C:\Users\admin\AppData\Local\FileZilla\default_processqueue20x20.png.WNCRY
binary
MD5: e17ad5cea5dc2a1f17ec1de483e28806
SHA256: 5d783a740e46dfdf5b29c63983f3b380deac709303fb4aaa20958b6ab17bd3ad
3668
WANACRYPTOR.exe
C:\Users\admin\AppData\Local\FileZilla\default_processqueue20x20.png.WNCRYT
––
MD5:  ––
SHA256:  ––
3668
WANACRYPTOR.exe
C:\Users\admin\AppData\Local\FileZilla\default_folder16x16.png.WNCRY
binary
MD5: cf88562ed1a093dec2c40097b4ac4ca8
SHA256: 7d0abc1a847c39e8ebe01443e450c4f948ffadd3cc99da8124e8aa87ed27bfb9
3668
WANACRYPTOR.exe
C:\Users\admin\AppData\Local\FileZilla\default_localtreeview20x20.png.WNCRY
binary
MD5: 1a845ce2b0497a2c317df2d75a1e9e11
SHA256: bc5aa9f1e6ae6fc264ef98f8c5f3bb9faf9db4d43aaac62da0389e20ba58a5f0
3668
WANACRYPTOR.exe
C:\Users\admin\AppData\Local\FileZilla\default_logview20x20.png.WNCRY
binary
MD5: 48f10d24da8fc9ff12aab74f70b329cf
SHA256: 1f6e7d1793bd28369421656f437e0fbaa3fd0acb6d6d948c98465d7d612ace5f
3668
WANACRYPTOR.exe
C:\Users\admin\AppData\Local\FileZilla\default_logview20x20.png.WNCRYT
––
MD5:  ––
SHA256:  ––
3668
WANACRYPTOR.exe
C:\Users\admin\AppData\Local\FileZilla\default_localtreeview20x20.png.WNCRYT
––
MD5:  ––
SHA256:  ––
3668
WANACRYPTOR.exe
C:\Users\admin\AppData\Local\FileZilla\default_find20x20.png.WNCRY
binary
MD5: 77baa5040e09c3afb73bd408b6029550
SHA256: e379b701ab9f82cb868c7f3afbb29db6ece498a662f447250fc9c1821d1c93fe
3668
WANACRYPTOR.exe
C:\Users\admin\AppData\Local\FileZilla\default_folder16x16.png.WNCRYT
––
MD5:  ––
SHA256:  ––
3668
WANACRYPTOR.exe
C:\Users\admin\AppData\Local\FileZilla\default_filter20x20.png.WNCRY
binary
MD5: 011dbc7c42e7fdcd05a0b9a1196d20b9
SHA256: 5610f18031cc4518acc66ac80a10a6fcaea11283247da3b73022ee3bf3c39eba
3668
WANACRYPTOR.exe
C:\Users\admin\AppData\Local\FileZilla\default_file16x16.png.WNCRY
binary
MD5: e01b9a184bef7af66c1885be88945514
SHA256: 92126e6b2a5701e9bf59fd2c927df176375bd0317061aead521b02c7e15da14f
3668
WANACRYPTOR.exe
C:\Users\admin\AppData\Local\FileZilla\default_filter20x20.png.WNCRYT
––
MD5:  ––
SHA256:  ––
3668
WANACRYPTOR.exe
C:\Users\admin\AppData\Local\FileZilla\default_find20x20.png.WNCRYT
––
MD5:  ––
SHA256:  ––
3668
WANACRYPTOR.exe
C:\Users\admin\AppData\Local\FileZilla\default_dropdown12x12.png.WNCRY
binary
MD5: db1a26bcd0a8f70e6fb11adfa20ee616
SHA256: 2d5b8d1862eb793d519b8d2d7d479a3b0702c15cd74bedb7618f1b4c90dcec1a
3668
WANACRYPTOR.exe
C:\Users\admin\AppData\Local\FileZilla\default_dropdown12x12.png.WNCRYT
––
MD5:  ––
SHA256:  ––
3668
WANACRYPTOR.exe
C:\Users\admin\AppData\Local\FileZilla\default_file16x16.png.WNCRYT
––
MD5:  ––
SHA256:  ––
3668
WANACRYPTOR.exe
C:\Users\admin\AppData\Local\FileZilla\default_compare20x20.png.WNCRY
binary
MD5: b12f5fefa4438e9b52111e5dbf57febf
SHA256: 8a5d0b9aba3cf6200b53dcf34abb9ca7f8d1d85b3c93089b692c5aeb90fd5c08
3668
WANACRYPTOR.exe
C:\Users\admin\AppData\Local\FileZilla\default_disconnect20x20.png.WNCRY
binary
MD5: 5657d66af05b709297b344c905b7ef6c
SHA256: 2f679e9e89f53a6f089a4ce1be103cf19ae02fd621770a6d3fecdb1f2122503a
3668
WANACRYPTOR.exe
C:\Users\admin\AppData\Local\FileZilla\default_disconnect20x20.png.WNCRYT
––
MD5:  ––
SHA256:  ––
3668
WANACRYPTOR.exe
C:\Users\admin\AppData\Local\FileZilla\default_compare20x20.png.WNCRYT
––
MD5:  ––
SHA256:  ––
3668
WANACRYPTOR.exe
C:\Users\admin\AppData\Local\FileZilla\default_close12x12.png.WNCRY
binary
MD5: 8f6934109f57001a4252cb1ebaf73604
SHA256: b074e8ead1311255b0276181b6bbbb875a853c70df745635dba3f44946991f3e
3668
WANACRYPTOR.exe
C:\Users\admin\AppData\Local\FileZilla\default_cancel24x24.png.WNCRY
binary
MD5: beba67f9a8e4f39f166a3930a1b5c6c1
SHA256: 400d1083c5f61cf87e5e4ff81e0fdf83b4a45202bd1ad40752669be789d03f44
3668
WANACRYPTOR.exe
C:\Users\admin\AppData\Local\FileZilla\default_cancel24x24.png.WNCRYT
––
MD5:  ––
SHA256:  ––
3668
WANACRYPTOR.exe
C:\Users\admin\AppData\Local\FileZilla\default_close12x12.png.WNCRYT
––
MD5:  ––
SHA256:  ––
3668
WANACRYPTOR.exe
C:\Users\admin\AppData\Local\FileZilla\default_cancel20x20.png.WNCRY
binary
MD5: 0771a6310876dc0f470ba4512b1a86d9
SHA256: eede3e574df467abf269b3e0077aa046b6fab09063540f8461aff8fcd4b479ef
3668
WANACRYPTOR.exe
C:\Users\admin\AppData\Local\FileZilla\default_auto16x16.png.WNCRY
binary
MD5: a34a7e70c5a94f61408bdd82ccecb457
SHA256: ec65ea9d501d71aa0cd4136982a350b072e9523a9fdee956038f61796a590bda
3668
WANACRYPTOR.exe
C:\Users\admin\AppData\Local\FileZilla\default_auto16x16.png.WNCRYT
––
MD5:  ––
SHA256:  ––
3668
WANACRYPTOR.exe
C:\Users\admin\AppData\Local\FileZilla\default_cancel20x20.png.WNCRYT
––
MD5:  ––
SHA256:  ––
3668
WANACRYPTOR.exe
C:\Users\Public\Videos\Sample Videos\Wildlife.wmv.WNCRY
––
MD5:  ––
SHA256:  ––
3668
WANACRYPTOR.exe
C:\Users\Public\Videos\Sample Videos\Wildlife.wmv.WNCRYT
––
MD5:  ––
SHA256:  ––
3668
WANACRYPTOR.exe
C:\Users\Public\Music\Sample Music\Sleep Away.mp3.WNCRY
––
MD5:  ––
SHA256:  ––
3668
WANACRYPTOR.exe
C:\Users\admin\AppData\Local\Temp\msg\m_bulgarian.wnry
text
MD5: 95673b0f968c0f55b32204361940d184
SHA256: 40b37e7b80cf678d7dd302aaf41b88135ade6ddf44d89bdba19cf171564444bd
3668
WANACRYPTOR.exe
C:\Users\Public\Music\Sample Music\Maid with the Flaxen Hair.mp3.WNCRY
binary
MD5: 97ed2dae9e6d8a2d3dfb03dcf3f56952
SHA256: f794d8132b7b295fd05c9a1d14a73ef7701d3d3177cff934c76c7e4946bf3f0a
3668
WANACRYPTOR.exe
C:\Users\Public\Music\Sample Music\Maid with the Flaxen Hair.mp3.WNCRYT
––
MD5:  ––
SHA256:  ––
3668
WANACRYPTOR.exe
C:\Users\Public\Music\Sample Music\Kalimba.mp3.WNCRY
––
MD5:  ––
SHA256:  ––
3668
WANACRYPTOR.exe
C:\Users\Public\Music\Sample Music\Kalimba.mp3.WNCRYT
––
MD5:  ––
SHA256:  ––
3668
WANACRYPTOR.exe
C:\Users\admin\Downloads\almosthear.png.WNCRY
binary
MD5: 61a6b17f876e2704aabd13da0d5f02df
SHA256: a28b77600a3b1be88a0d96a4a47eb22981a656ecec8eeea2c86219c71600f836
3668
WANACRYPTOR.exe
C:\Users\admin\Pictures\repairdevice.png.WNCRY
binary
MD5: 74debf13fd1631eb4ea70cf4a0886d59
SHA256: 3a0182175c1cbfcdb33e1cd5c562def79dfa89aa37d1eaa5b7fd80c7fdd84a82
3668
WANACRYPTOR.exe
C:\Users\admin\Downloads\facealternative.png.WNCRY
binary
MD5: bfbba6dfeb4d933036738b15b13cc1c4
SHA256: e2445cb6b454ede5ec2dea3b78062bdaafadd54a0f5744a862e6abe40cbea7fd
3668
WANACRYPTOR.exe
C:\Users\admin\Pictures\airfour.png.WNCRY
binary
MD5: 07837d2a50b11f09c9d1840de11f923b
SHA256: 1f1bb68b5285c67c5a491e2e740021181fb8f1ad333b81b8135ff8c4062a2e23
3668
WANACRYPTOR.exe
C:\Users\admin\Downloads\standservices.png.WNCRY
binary
MD5: ae8d1336bcf8644d1670d6ee6417a665
SHA256: 062257f3bfad74cf4ab4ca13e3e1cc6137fc6c912c1977881ac892cd9768eac6
3668
WANACRYPTOR.exe
C:\Users\admin\Downloads\almosthear.png.WNCRYT
––
MD5:  ––
SHA256:  ––
3668
WANACRYPTOR.exe
C:\Users\admin\Pictures\repairdevice.png.WNCRYT
––
MD5:  ––
SHA256:  ––
3668
WANACRYPTOR.exe
C:\Users\admin\Downloads\facealternative.png.WNCRYT
––
MD5:  ––
SHA256:  ––
3668
WANACRYPTOR.exe
C:\Users\admin\Downloads\standservices.png.WNCRYT
––
MD5:  ––
SHA256:  ––
3668
WANACRYPTOR.exe
C:\Users\admin\Pictures\airfour.png.WNCRYT
––
MD5:  ––
SHA256:  ––
3668
WANACRYPTOR.exe
C:\Users\admin\AppData\Roaming\Skype\shared_httpfe\queue.db.WNCRY
binary
MD5: a638369392cb6faabca93e4304d81bf4
SHA256: f2e473f2a8a5ea7584af97661b5fb098d93d0dbf60641f2b2c7568788fcfdad3
3668
WANACRYPTOR.exe
C:\Users\admin\AppData\Roaming\Skype\shared_dynco\dc.db.WNCRY
binary
MD5: c1be2737e937f33d4b3f341a57eb3786
SHA256: be13d0388236c6c6b131982b99264633b8934a9ca74b2659b3f4dbd2b845cca1
3668
WANACRYPTOR.exe
C:\Users\admin\AppData\Roaming\Skype\shared_dynco\dc.db.WNCRYT
––
MD5:  ––
SHA256:  ––
3668
WANACRYPTOR.exe
C:\Users\admin\AppData\Roaming\Skype\shared_httpfe\queue.db.WNCRYT
––
MD5:  ––
SHA256:  ––
3668
WANACRYPTOR.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\prefs.js.WNCRY
binary
MD5: 8d97204771202cfb4002e9c8d56a8351
SHA256: 393a9c74502815fbcee005773991d7389bd0e4daef92d85168e29a123b921d2d
3668
WANACRYPTOR.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\cert9.db.WNCRY
binary
MD5: ede1cb6393b01147a9bc9e11d567ed56
SHA256: 61db9c9f5f52ed4c2c1860a60b1ec7c213b737262aadf464af8fd9abe2dcd962
3668
WANACRYPTOR.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\key4.db.WNCRY
binary
MD5: 6b929958108669cc96286436d0fa24a1
SHA256: 7d1707c797a8d1bc304c3f429057ddba4bc89c1a4de0ec9458d3e260ecfe599f
3668
WANACRYPTOR.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\cert9.db.WNCRYT
––
MD5:  ––
SHA256:  ––
3668
WANACRYPTOR.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\key4.db.WNCRYT
––
MD5:  ––
SHA256:  ––
3668
WANACRYPTOR.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\prefs.js.WNCRYT
––
MD5:  ––
SHA256:  ––
3668
WANACRYPTOR.exe
C:\Users\admin\AppData\Roaming\Microsoft\Templates\NormalEmail.dotm.WNCRY
binary
MD5: ffffe5dcc7f6f04bbd9c4e60c112aab8
SHA256: 2b7f85ecd604a573a43365e3b831ce167057c9b55587d7a66a0baa5d8cec134e
3668
WANACRYPTOR.exe
C:\Users\admin\AppData\Roaming\Microsoft\Skype for Desktop\skylib\live#3agabriel.radrigos\main.db.WNCRY
binary
MD5: 2e56059a748c7fe93cc87397370f80ee
SHA256: 9ad7227a1885f6a953d8efd962d4f021885b2002f87ffd9386ead1c6bf67ca00
3668
WANACRYPTOR.exe
C:\Users\admin\AppData\Roaming\Microsoft\Templates\Normal.dotm.WNCRY
binary
MD5: 0e4eb8286cf165da14512f74cad28f21
SHA256: 5eba57d8c6eac2c14f66d00619e6c1f39eeb834b8f421064f704d9ba5977673e
3668
WANACRYPTOR.exe
C:\Users\admin\AppData\Roaming\Microsoft\Templates\NormalEmail.dotm.WNCRYT
––
MD5:  ––
SHA256:  ––
3668
WANACRYPTOR.exe
C:\Users\admin\AppData\Roaming\Microsoft\Skype for Desktop\skylib\live#3agabriel.radrigos\main.db.WNCRYT
––
MD5:  ––
SHA256:  ––
3668
WANACRYPTOR.exe
C:\Users\admin\AppData\Roaming\Microsoft\Templates\Normal.dotm.WNCRYT
––
MD5:  ––
SHA256:  ––
3668
WANACRYPTOR.exe
C:\Users\admin\AppData\Roaming\Microsoft\Skype for Desktop\databases\Databases.db.WNCRY
binary
MD5: 5026f3f458969495244271bab0ab0f21
SHA256: e1dce29b470078c130e93a82d31389391a27cfe61a37cdd8b346f86654d0fa6a
3668
WANACRYPTOR.exe
C:\Users\admin\AppData\Roaming\Microsoft\Skype for Desktop\media-stack\Skype_MediaStackETW-2018.34.1.3-UVA-x86release-U.etl.bak.WNCRY
binary
MD5: e1f95f0aa2f7ba11ac3da85bd8f867fd
SHA256: d2eecb20296cf13dd3d757c42acb897209c1ebcb7345d9e409ce76771c19f575
3668
WANACRYPTOR.exe
C:\Users\admin\AppData\Roaming\Microsoft\Skype for Desktop\media-stack\Skype_MediaStackETW-2018.34.1.3-UVA-x86release-U.etl.bak.WNCRYT
––
MD5:  ––
SHA256:  ––
3668
WANACRYPTOR.exe
C:\Users\admin\AppData\Roaming\Microsoft\Document Building Blocks\1033\14\Built-In Building Blocks.dotx.WNCRY
binary
MD5: 150815c0a28c472aeaebb57db57144db
SHA256: 2f7adb63721371103af983214701641135c70ac1419ed50d2ce039fb6f48078c
3668
WANACRYPTOR.exe
C:\Users\admin\AppData\Roaming\Microsoft\Skype for Desktop\databases\Databases.db.WNCRYT
––
MD5:  ––
SHA256:  ––
3668
WANACRYPTOR.exe
C:\Users\admin\AppData\Roaming\Microsoft\Document Building Blocks\1033\14\Built-In Building Blocks.dotx.WNCRYT
––
MD5:  ––
SHA256:  ––
3668
WANACRYPTOR.exe
C:\Users\admin\AppData\Roaming\FileZilla\queue.sqlite3.WNCRY
binary
MD5: adf459694f60c6b29e96e12b51a832ff
SHA256: a4d4abe9ca85d704f92d49abad7a8a5757b23ce3c69c76583cc765f536981386
3668
WANACRYPTOR.exe
C:\Users\admin\AppData\Local\Skype\Apps\login\languages\zh-hant.js.WNCRY
binary
MD5: 8b1ccb1f036318675b5e925a3c1275c3
SHA256: 9909be6bd2abf9c1ab438e0d17e60b024fc22d0856bb4b25aa43094a9c803b62
3668
WANACRYPTOR.exe
C:\Users\admin\AppData\Roaming\FileZilla\queue.sqlite3.WNCRYT
––
MD5:  ––
SHA256:  ––
3668
WANACRYPTOR.exe
C:\Users\admin\AppData\Local\Skype\Apps\login\languages\zh-hans.js.WNCRY
binary
MD5: 23b2e21901a4a28803d4d784a2dd9864
SHA256: c2a980f7fa27941e2a15de4e4baaf0bd9ef9472de2210840824e695da60af258
3668
WANACRYPTOR.exe
C:\Users\admin\AppData\Local\Skype\Apps\login\languages\vi.js.WNCRY
binary
MD5: ef060e0ff13f7462e1ba4b8dc9a73f48
SHA256: 455d422637751298c4ff291a324035bb648bd8bf56ff6512541fe4a8f848de62
3668
WANACRYPTOR.exe
C:\Users\admin\AppData\Local\Skype\Apps\login\languages\uk.js.WNCRY
binary
MD5: a44f8a5c0412266ae17b7cb14b781786
SHA256: 80826ee77a834bce8c8fc63a0b64de71687b2db0ebab9943bffdea87a4e5aa4b
3668
WANACRYPTOR.exe
C:\Users\admin\AppData\Local\Skype\Apps\login\languages\zh-hans.js.WNCRYT
––
MD5:  ––
SHA256:  ––
3668
WANACRYPTOR.exe
C:\Users\admin\AppData\Local\Skype\Apps\login\languages\zh-hant.js.WNCRYT
––
MD5:  ––
SHA256:  ––
3668
WANACRYPTOR.exe
C:\Users\admin\AppData\Local\Skype\Apps\login\languages\uk.js.WNCRYT
––
MD5:  ––
SHA256:  ––
3668
WANACRYPTOR.exe
C:\Users\admin\AppData\Local\Skype\Apps\login\languages\vi.js.WNCRYT
––
MD5:  ––
SHA256:  ––
3668
WANACRYPTOR.exe
C:\Users\admin\AppData\Local\Skype\Apps\login\languages\tr.js.WNCRY
binary
MD5: 507342354ad41c2d8922f245054ae372
SHA256: e5d53d9c0947e1763d77dfa2040e99caf07df7ae35c13a987a727d455f1c8ec1
3668
WANACRYPTOR.exe
C:\Users\admin\AppData\Local\Skype\Apps\login\languages\th.js.WNCRY
binary
MD5: ad1fa802fd9f2fb4f1a3d190f6f42792
SHA256: 01f9f8cc31cbd4a1a170f5c28e294eace7c4faff9c4a7888d0293f94657dff91
3668
WANACRYPTOR.exe
C:\Users\admin\AppData\Local\Skype\Apps\login\languages\sv.js.WNCRY
binary
MD5: 9062194afc47fcb371de35e95599a7b2
SHA256: 1cfe065e97ec0cf62c591dc2b8554ead007ec6bf36fa5b4aa5732c6273334d50
3668
WANACRYPTOR.exe
C:\Users\admin\AppData\Local\Skype\Apps\login\languages\tr.js.WNCRYT
––
MD5:  ––
SHA256:  ––
3668
WANACRYPTOR.exe
C:\Users\admin\AppData\Local\Skype\Apps\login\languages\th.js.WNCRYT
––
MD5:  ––
SHA256:  ––
3668
WANACRYPTOR.exe
C:\Users\admin\AppData\Local\Skype\Apps\login\languages\sr-latn.js.WNCRY
binary
MD5: 02836c2999b9de6be6d0191c8f798235
SHA256: 9d8f4e48f137deec6d38c5174bb21aa1b9e84ca5a9c7b7ce2abfbf995e7adc34
3668
WANACRYPTOR.exe
C:\Users\admin\AppData\Local\Skype\Apps\login\languages\sl.js.WNCRY
binary
MD5: f6f88d69766559df67b61d41f4f9269a
SHA256: ac7409f69f5a78bcc2cf7a61f385458030d8151c51d11ad806405d17aebe6314
3668
WANACRYPTOR.exe
C:\Users\admin\AppData\Local\Skype\Apps\login\languages\sv.js.WNCRYT
––
MD5:  ––
SHA256:  ––
3668
WANACRYPTOR.exe
C:\Users\admin\AppData\Local\Skype\Apps\login\languages\sr-latn.js.WNCRYT
––
MD5:  ––
SHA256:  ––
3668
WANACRYPTOR.exe
C:\Users\admin\AppData\Local\Skype\Apps\login\languages\sk.js.WNCRY
binary
MD5: 1dabfb9b7a1f3f7122dcdc3229b06764
SHA256: 853898bcaad2f139533f5aab313dc140c5170612f1a7ea806d146e0fdf78e69a
3668
WANACRYPTOR.exe
C:\Users\admin\AppData\Local\Skype\Apps\login\languages\ru.js.WNCRY
binary
MD5: e1189af4b44ece4645d4ed4132bf679e
SHA256: ddf17b77b2f18280a769006bdb0fb8aac5973cf49b549332ba4b2fd83cb87a05
3668
WANACRYPTOR.exe
C:\Users\admin\AppData\Local\Skype\Apps\login\languages\sk.js.WNCRYT
––
MD5:  ––
SHA256:  ––
3668
WANACRYPTOR.exe
C:\Users\admin\AppData\Local\Skype\Apps\login\languages\sl.js.WNCRYT
––
MD5:  ––
SHA256:  ––
3668
WANACRYPTOR.exe
C:\Users\admin\AppData\Local\Skype\Apps\login\languages\ru.js.WNCRYT
––
MD5:  ––
SHA256:  ––
3668
WANACRYPTOR.exe
C:\Users\admin\AppData\Local\Skype\Apps\login\languages\ro.js.WNCRY
binary
MD5: c2200f1a56a097d0e9c21ac548e1aef4
SHA256: 8e5b9387089b0d899d2521c339cdc78ba0215ad2b3bc9dfbcf2c37371397e1cd
3668
WANACRYPTOR.exe
C:\Users\admin\AppData\Local\Skype\Apps\login\languages\ro.js.WNCRYT
––
MD5:  ––
SHA256:  ––
3668
WANACRYPTOR.exe
C:\Users\admin\AppData\Local\Skype\Apps\login\languages\pt.js.WNCRY
binary
MD5: a2fd8623c87f9e99fb9533f434cd3d7d
SHA256: 62a20620931bff3c46d1296f43749205956fff427484861e6fcc0ad2ea9db278
3668
WANACRYPTOR.exe
C:\Users\admin\AppData\Local\Skype\Apps\login\languages\pt-br.js.WNCRY
binary
MD5: 4577b632a871c03d83a019dc844dd0a8
SHA256: d22b7bf049ef6f1bfb6a1f12e49e14829bb0abe49d9da5d8f5f1c5145c500ee0
3668
WANACRYPTOR.exe
C:\Users\admin\AppData\Local\Skype\Apps\login\languages\pt-br.js.WNCRYT
––
MD5:  ––
SHA256:  ––
3668
WANACRYPTOR.exe
C:\Users\admin\AppData\Local\Skype\Apps\login\languages\pt.js.WNCRYT
––
MD5:  ––
SHA256:  ––
3668
WANACRYPTOR.exe
C:\Users\admin\AppData\Local\Skype\Apps\login\languages\no.js.WNCRY
binary
MD5: 02b4e5ac213af3aaf2f5858d25eda840
SHA256: 70878905e5215c8339207eb5e5e8e0d15385b327f550eed9f0275133c765200c
3668
WANACRYPTOR.exe
C:\Users\admin\AppData\Local\Skype\Apps\login\languages\nl.js.WNCRY
binary
MD5: 7ae923759654bd7d49dc71cbc18f4c96
SHA256: 9c7ebeeaa40d624a551ee7b126e0693ce6669595e9fffdacb9cddfbfb50cd9e9
3668
WANACRYPTOR.exe
C:\Users\admin\AppData\Local\Skype\Apps\login\languages\pl.js.WNCRY
binary
MD5: c70a7c786c9e779ee3cecc98c276ff78
SHA256: 9e8f57e0e02915e4d50782e11da540d4491225752dae504465d7ef7986d59af2
3668
WANACRYPTOR.exe
C:\Users\admin\AppData\Local\Skype\Apps\login\languages\pl.js.WNCRYT
––
MD5:  ––
SHA256:  ––
3668
WANACRYPTOR.exe
C:\Users\admin\AppData\Local\Skype\Apps\login\languages\no.js.WNCRYT
––
MD5:  ––
SHA256:  ––
3668
WANACRYPTOR.exe
C:\Users\admin\AppData\Local\Skype\Apps\login\languages\nl.js.WNCRYT
––
MD5:  ––
SHA256:  ––
3668
WANACRYPTOR.exe
C:\Users\admin\AppData\Local\Skype\Apps\login\languages\lt.js.WNCRY
binary
MD5: 9db5a76bb047d49a2be4357a485b9edc
SHA256: ecf539b1527143b8072d918c602b6a304215a37b69c91f93146c933b0439d09f
3668
WANACRYPTOR.exe
C:\Users\admin\AppData\Local\Skype\Apps\login\languages\lv.js.WNCRY
binary
MD5: 47e75dcd592ed45de146d4514abd8976
SHA256: c4c2646ce52ef80913bf335fe76bebd2dc1020f4ba4c1d6917caec439a1c955a
3668
WANACRYPTOR.exe
C:\Users\admin\AppData\Local\Skype\Apps\login\languages\lt.js.WNCRYT
––
MD5:  ––
SHA256:  ––
3668
WANACRYPTOR.exe
C:\Users\admin\AppData\Local\Skype\Apps\login\languages\lv.js.WNCRYT
––
MD5:  ––
SHA256:  ––
3668
WANACRYPTOR.exe
C:\Users\admin\AppData\Local\Skype\Apps\login\languages\ko.js.WNCRY
binary
MD5: fde5b6a3f4111e99e31168c22c11c715
SHA256: 94c12a7fa087c15c372f26b019f76331ac19d531e08fecd17adf688ad1ba3a47
3668
WANACRYPTOR.exe
C:\Users\admin\AppData\Local\Skype\Apps\login\languages\ko.js.WNCRYT
––
MD5:  ––
SHA256:  ––
3668
WANACRYPTOR.exe
C:\Users\admin\AppData\Local\Skype\Apps\login\languages\ja.js.WNCRY
binary
MD5: 1c0f1428dec627e38ccf1093f34ca3dd
SHA256: 710263bdab720ff0318855484b3c56ce7da119487865c171f94ff1d8edb979cd
3668
WANACRYPTOR.exe
C:\Users\admin\AppData\Local\Skype\Apps\login\languages\ja.js.WNCRYT
––
MD5:  ––
SHA256:  ––
3668
WANACRYPTOR.exe
C:\Users\admin\AppData\Local\Skype\Apps\login\languages\id.js.WNCRY
binary
MD5: 775537f6f7355ad4aa26388f44eafd7b
SHA256: f5ec102f9e4fb75fbc25cc49ef5dce39b7ad5dc427b1790eb17d3798893a7200
3668
WANACRYPTOR.exe
C:\Users\admin\AppData\Local\Skype\Apps\login\languages\it.js.WNCRY
binary
MD5: 52c3747962baca1357408f1feb049663
SHA256: 99cfa7ea64ef117ce9a034a7fa7c0aad77efa02fa9370091c9ee77a218a63a67
3668
WANACRYPTOR.exe
C:\Users\admin\AppData\Local\Skype\Apps\login\languages\it.js.WNCRYT
––
MD5:  ––
SHA256:  ––
3668
WANACRYPTOR.exe
C:\Users\admin\AppData\Local\Skype\Apps\login\languages\id.js.WNCRYT
––
MD5:  ––
SHA256:  ––
3668
WANACRYPTOR.exe
C:\Users\admin\AppData\Local\Skype\Apps\login\languages\hu.js.WNCRY
binary
MD5: f6d7b6df52f5c6536ea2eaf049fd098a
SHA256: 70d875aa743feaff71ff3cdf9a39429f26f0008e062c6bf5e4cff8f138b0a2f6
3668
WANACRYPTOR.exe
C:\Users\admin\AppData\Local\Skype\Apps\login\languages\hr.js.WNCRY
binary
MD5: 3f05f981e5a497f115593f11e4d5eb01
SHA256: f1294f1a4d42933158c4317c88ec5f14b6c97e5c803a57ce45956c80feaca2cc
3668
WANACRYPTOR.exe
C:\Users\admin\AppData\Local\Skype\Apps\login\languages\he.js.WNCRY
binary
MD5: 17d429f0e06885c95af2fd8a98dd49c4
SHA256: 554d2220acf5e589ea8d035f0408ac0e5907e1132dff064fed80cbf51f1221e5
3668
WANACRYPTOR.exe
C:\Users\admin\AppData\Local\Skype\Apps\login\languages\hr.js.WNCRYT
––
MD5:  ––
SHA256:  ––
3668
WANACRYPTOR.exe
C:\Users\admin\AppData\Local\Skype\Apps\login\languages\hu.js.WNCRYT
––
MD5:  ––
SHA256:  ––
3668
WANACRYPTOR.exe
C:\Users\admin\AppData\Local\Skype\Apps\login\languages\fr.js.WNCRY
binary
MD5: 522890820cadf244ab9de81eaaae5d77
SHA256: 5f8babf2cf480c41c8d9676a7c18b2f680d92bdca07f425f0fccd7698b377e1d
3668
WANACRYPTOR.exe
C:\Users\admin\AppData\Local\Skype\Apps\login\languages\fi.js.WNCRY
binary
MD5: 61fba4e39c813521fa74d6984984ee70
SHA256: 5d744eafe2a4af4bc0de50c45872d3a8b5a62817b888d557ca8d2c3ba811d3da
3668
WANACRYPTOR.exe
C:\Users\admin\AppData\Local\Skype\Apps\login\languages\he.js.WNCRYT
––
MD5:  ––
SHA256:  ––
3668
WANACRYPTOR.exe
C:\Users\admin\AppData\Local\Skype\Apps\login\languages\fr.js.WNCRYT
––
MD5:  ––
SHA256:  ––
3668
WANACRYPTOR.exe
C:\Users\admin\AppData\Local\Skype\Apps\login\languages\fi.js.WNCRYT
––
MD5:  ––
SHA256:  ––
3668
WANACRYPTOR.exe
C:\Users\admin\AppData\Local\Skype\Apps\login\languages\et.js.WNCRY
binary
MD5: bedddc37425770473e551a279c40fa05
SHA256: 708d8d87b1533661e6599f7d9477edbb6ca7b43be80abc7a275f54ed53e590eb
3668
WANACRYPTOR.exe
C:\Users\admin\AppData\Local\Skype\Apps\login\languages\es.js.WNCRY
binary
MD5: 5a61d88ea86d230372cb3f6dd1079b9a
SHA256: ae854fa47d705a2f6ef5acd61fedb7f7428c7791dae93212c49bfffc706dc916
3668
WANACRYPTOR.exe
C:\Users\admin\AppData\Local\Skype\Apps\login\languages\et.js.WNCRYT
––
MD5:  ––
SHA256:  ––
3668
WANACRYPTOR.exe
C:\Users\admin\AppData\Local\Skype\Apps\login\languages\es.js.WNCRYT
––
MD5:  ––
SHA256:  ––
3668
WANACRYPTOR.exe
C:\Users\admin\AppData\Local\Skype\Apps\login\languages\en.js.WNCRY
binary
MD5: 5922b8396085dfedec7c1041b4ee38aa
SHA256: ff0b7cedb50c4bbb13b48b493271e9bf8d6f8868ba5c033ec19ff9bd163dfc28
3668
WANACRYPTOR.exe
C:\Users\admin\AppData\Local\Skype\Apps\login\languages\ca.js.WNCRY
binary
MD5: 6e82df3f0ee9bf86fec6dd4a98ddcad7
SHA256: 6a678f284abec39b986399aa13f93c888b82d793952f0d65665b295cb5a7a0cb
3668
WANACRYPTOR.exe
C:\Users\admin\AppData\Local\Skype\Apps\login\languages\cs.js.WNCRY
binary
MD5: 6c7d9b9b2c027a1d01a67f7843c22ce3
SHA256: ed97d44ea23098bd52cb0607ca7e58eb50b249e0010ca4d0c7cc73e14e5af32a
3668
WANACRYPTOR.exe
C:\Users\admin\AppData\Local\Skype\Apps\login\languages\el.js.WNCRY
binary
MD5: 6ab8431d141ae8a310d2d982163d1aec
SHA256: 70d5bb854c3096c9c8c041e25a68c7fa3a6a9d84a6379f19b4cbd498be19ca5b
3668
WANACRYPTOR.exe
C:\Users\admin\AppData\Local\Skype\Apps\login\languages\de.js.WNCRY
binary
MD5: e4ae2f402834284e85cba91dc07129c3
SHA256: 4bcdda3c1b0759e4ad6fdc6e5b58ea09cc960e27991b213b26acc38a31e0e794
3668
WANACRYPTOR.exe
C:\Users\admin\AppData\Local\Skype\Apps\login\languages\da.js.WNCRY
binary
MD5: c359344fbb5bcfaa2c9340ad9b493fbe
SHA256: 07c7c156dd4f8f0e1cfa37220e64411ba9d8f8868f4e4ec2be3546838325f88b
3668
WANACRYPTOR.exe
C:\Users\admin\AppData\Local\Skype\Apps\login\languages\da.js.WNCRYT
––
MD5:  ––
SHA256:  ––
3668
WANACRYPTOR.exe
C:\Users\admin\AppData\Local\Skype\Apps\login\languages\el.js.WNCRYT
––
MD5:  ––
SHA256:  ––
3668
WANACRYPTOR.exe
C:\Users\admin\AppData\Local\Skype\Apps\login\languages\cs.js.WNCRYT
––
MD5:  ––
SHA256:  ––
3668
WANACRYPTOR.exe
C:\Users\admin\AppData\Local\Skype\Apps\login\languages\ca.js.WNCRYT
––
MD5:  ––
SHA256:  ––
3668
WANACRYPTOR.exe
C:\Users\admin\AppData\Local\Skype\Apps\login\languages\de.js.WNCRYT
––
MD5:  ––
SHA256:  ––
3668
WANACRYPTOR.exe
C:\Users\admin\AppData\Local\Skype\Apps\login\languages\en.js.WNCRYT
––
MD5:  ––
SHA256:  ––
3668
WANACRYPTOR.exe
C:\Users\admin\AppData\Local\Skype\Apps\login\languages\ar.js.WNCRY
binary
MD5: fb07f781395d435fdc6ff964687d4ed9
SHA256: 18515a2e2ab2c9467e1c777ab79f2d9ac9ee2e97e29c60a048a58ffda3e9773b
3668
WANACRYPTOR.exe
C:\Users\admin\AppData\Local\Skype\Apps\login\languages\bg.js.WNCRY
binary
MD5: f4b0090a6ce920c2285f5f1a938954b6
SHA256: d020b21fa7724820b693ec8a08b32b79d0e316f75fa552a12595a6a6c4755bb4
3668
WANACRYPTOR.exe
C:\Users\admin\AppData\Local\Skype\Apps\login\languages\bg.js.WNCRYT
––
MD5:  ––
SHA256:  ––
3668
WANACRYPTOR.exe
C:\Users\admin\AppData\Local\Skype\Apps\login\languages\ar.js.WNCRYT
––
MD5:  ––
SHA256:  ––
3668
WANACRYPTOR.exe
C:\Users\admin\AppData\Local\Skype\Apps\login\images\white-on-black\msa-logos-135x25.png.WNCRY
binary
MD5: 56d80d297aac9ba227f39f850454e6da
SHA256: 2761001522ff0c264d376e24c7906508fde97c67315d17739747ebbe882e6ef3
3668
WANACRYPTOR.exe
C:\Users\admin\AppData\Local\Skype\Apps\login\images\white-on-black\[email protected]
binary
MD5: 4f638b51e31816292cb625f540bca0cb
SHA256: 8979c5dbc596e9c156fe9933540248b97171447361d742edd4b9b0c4a9a36aac
3668
WANACRYPTOR.exe
C:\Users\admin\AppData\Local\Skype\Apps\login\images\white-on-black\[email protected]
binary
MD5: 7235aa4dd2be6d254fee7b07e1f4715d
SHA256: 5f05ed39235ecbb97a8e995b74ffabf8eab521850a68522f8aa9c64313e7722d
3668
WANACRYPTOR.exe
C:\Users\admin\AppData\Local\Skype\Apps\login\js\login.js.WNCRY
binary
MD5: 00e5b23fdc8eb5c5cd5bcdab18ecf0ab
SHA256: d0acb3a0cdbf58288d851d9e351ac324b8c99e5ebf6d7c4618e5ef871be4fff1
3668
WANACRYPTOR.exe
C:\Users\admin\AppData\Local\Skype\Apps\login\images\white-on-black\skype-logo-136x60.png.WNCRY
binary
MD5: d8d3cd6e07a7c5a764e0d49d2f0d2e79
SHA256: 6a8bfe656ea94d975de9795ede4a8555171ed3f2303862d79760fbddf55a2c9d
3668
WANACRYPTOR.exe
C:\Users\admin\AppData\Local\Skype\Apps\login\images\white-on-black\msa-logos-135x25.png.WNCRYT
––
MD5:  ––
SHA256:  ––
3668
WANACRYPTOR.exe
C:\Users\admin\AppData\Local\Skype\Apps\login\js\login.js.WNCRYT
––
MD5:  ––
SHA256:  ––
3668
WANACRYPTOR.exe
C:\Users\admin\AppData\Local\Skype\Apps\login\images\white-on-black\[email protected]
––
MD5:  ––
SHA256:  ––
3668
WANACRYPTOR.exe
C:\Users\admin\AppData\Local\Skype\Apps\login\images\white-on-black\[email protected]
––
MD5:  ––
SHA256:  ––
3668
WANACRYPTOR.exe
C:\Users\admin\AppData\Local\Skype\Apps\login\images\white-on-black\skype-logo-136x60.png.WNCRYT
––
MD5:  ––
SHA256:  ––
3668
WANACRYPTOR.exe
C:\Users\admin\AppData\Local\Skype\Apps\login\images\white-on-black\[email protected]
binary
MD5: 303c6a2bb433f9d14ba3f6daaadaa79e
SHA256: ed7d99a647c961dcd04a36789baf76945fd0bc31e837356b952563a14daa0dc8
3668
WANACRYPTOR.exe
C:\Users\admin\AppData\Local\Skype\Apps\login\images\white-on-black\[email protected]
binary
MD5: 952f812a0ba0d24291444e2757ea635f
SHA256: 985c1a79f9f812632eabe47079efaa7ec3e0fc3efa02f45209c2215434d913d9
3668
WANACRYPTOR.exe
C:\Users\admin\AppData\Local\Skype\Apps\login\images\white-on-black\[email protected]
binary
MD5: f2c89f6bb5f71e9f2c2209aa31588591
SHA256: 954a1d223080afbf62289bf08b920f9cff738af7ee0edd077ca3509bbded28e8
3668
WANACRYPTOR.exe
C:\Users\admin\AppData\Local\Skype\Apps\login\images\white-on-black\[email protected]
––
MD5:  ––
SHA256:  ––
3668
WANACRYPTOR.exe
C:\Users\admin\AppData\Local\Skype\Apps\login\images\white-on-black\[email protected]
––
MD5:  ––
SHA256:  ––
3668
WANACRYPTOR.exe
C:\Users\admin\AppData\Local\Skype\Apps\login\images\white-on-black\[email protected]
––
MD5:  ––
SHA256:  ––
3668
WANACRYPTOR.exe
C:\Users\admin\AppData\Local\Skype\Apps\login\images\white-on-black\back_20x20.png.WNCRY
binary
MD5: b48e079cc41af7df55836cdf1e7c3c2b
SHA256: 1ae26ef61ae8e8ee29b3b92f0984d697e41d05e56e91f45d300cbea49fa709fc
3668
WANACRYPTOR.exe
C:\Users\admin\AppData\Local\Skype\Apps\login\images\white-on-black\[email protected]
binary
MD5: 8ca8b0f70480c8d62b1a0c737e14aa01
SHA256: 4fab92465529b71a4b405bee12f69424ddae86dc9d264a7779749e896847088c
3668
WANACRYPTOR.exe
C:\Users\admin\AppData\Local\Skype\Apps\login\images\white-on-black\[email protected]
binary
MD5: 95471685e1a5fb5a8f0f3bd77659448a
SHA256: 451d7e3343fc2f63b8af034b93498e391863d71daba1c82a7ca05e24cbb701b2
3668
WANACRYPTOR.exe
C:\Users\admin\AppData\Local\Skype\Apps\login\images\white-on-black\[email protected]
binary
MD5: 8ad0beaf3c76acb91d84be672569f0c5
SHA256: cfe6eeb52cd511771d83403ea0928b55697418eb66d525d82bc39684abeda81e
3668
WANACRYPTOR.exe
C:\Users\admin\AppData\Local\Skype\Apps\login\images\white-on-black\back_20x20.png.WNCRYT
––
MD5:  ––
SHA256:  ––
3668
WANACRYPTOR.exe
C:\Users\admin\AppData\Local\Skype\Apps\login\images\white-on-black\[email protected]
––
MD5:  ––
SHA256:  ––
3668
WANACRYPTOR.exe
C:\Users\admin\AppData\Local\Skype\Apps\login\images\white-on-black\[email protected]
––
MD5:  ––
SHA256:  ––
3668
WANACRYPTOR.exe
C:\Users\admin\AppData\Local\Skype\Apps\login\images\white-on-black\[email protected]
––
MD5:  ––
SHA256:  ––
3668
WANACRYPTOR.exe
C:\Users\admin\AppData\Local\Skype\Apps\login\images\retina\[email protected]
binary
MD5: 6c4d6638d3fd9e6110748e6ce6111215
SHA256: 054b1775bbcfdfc18421b28348f8d27e5ee3213e3c5e954e269ba7f8917e252d
3668
WANACRYPTOR.exe
C:\Users\admin\AppData\Local\Skype\Apps\login\images\retina\[email protected]
binary
MD5: 2cecef9dbb3d8f0d14bb8b95d5465367
SHA256: e8cf2c14f374d09e1c944688af6dea2d29b74889c8a2b7760ad1c0938c928067
3668
WANACRYPTOR.exe
C:\Users\admin\AppData\Local\Skype\Apps\login\images\white-on-black\back_20x20-inverted.png.WNCRY
binary
MD5: 764aed99a5e2695b863f53090893a8cb
SHA256: 7aa5b05c5ebd308e0043c7b1a1813bbb5cbba52d0be7f289e3442139de39f1fd
3668
WANACRYPTOR.exe
C:\Users\admin\AppData\Local\Skype\Apps\login\images\retina\[email protected]
binary
MD5: f415d1e04fa4e975f0ec981d46a55de5
SHA256: de51c675100eaa26507045f356a6e2fb9197b78d35ea57bb37d0cfd43f7380b7
3668
WANACRYPTOR.exe
C:\Users\admin\AppData\Local\Skype\Apps\login\images\white-on-black\back_20x20-inverted.png.WNCRYT
––
MD5:  ––
SHA256:  ––
3668
WANACRYPTOR.exe
C:\Users\admin\AppData\Local\Skype\Apps\login\images\retina\[email protected]
––
MD5:  ––
SHA256:  ––
3668
WANACRYPTOR.exe
C:\Users\admin\AppData\Local\Skype\Apps\login\images\retina\[email protected]
––
MD5:  ––
SHA256:  ––
3668
WANACRYPTOR.exe
C:\Users\admin\AppData\Local\Skype\Apps\login\images\retina\[email protected]
––
MD5:  ––
SHA256:  ––
3668
WANACRYPTOR.exe
C:\Users\admin\AppData\Local\Skype\Apps\login\images\retina\[email protected]
binary
MD5: 9d15b2f507811a68e0aa3b738defcf29
SHA256: 0b91790e4e12e6f477f2520bb8481baf83ee2c98ddb739f2de7afcef98dad411
3668
WANACRYPTOR.exe
C:\Users\admin\AppData\Local\Skype\Apps\login\images\retina\[email protected]
binary
MD5: 5778fac89eba1702ce20293ac5fcbe5a
SHA256: ac3ca4edcd83479c1297e6d44e577f649086ea7df35f06276d29862a0ff3e368
3668
WANACRYPTOR.exe
C:\Users\admin\AppData\Local\Skype\Apps\login\images\retina\[email protected]
––
MD5:  ––
SHA256:  ––
3668
WANACRYPTOR.exe
C:\Users\admin\AppData\Local\Skype\Apps\login\images\retina\[email protected]
––
MD5:  ––
SHA256:  ––
3668
WANACRYPTOR.exe
C:\Users\admin\AppData\Local\Skype\Apps\login\images\normal\[email protected]
binary
MD5: 8a5cf4f955a58505324b918fd7706345
SHA256: 33723d94bb5a68872d0da5d304fd10560d6f39d93c4ea42e5d8cd0f8a4c16c6f
3668
WANACRYPTOR.exe
C:\Users\admin\AppData\Local\Skype\Apps\login\images\retina\[email protected]
binary
MD5: 1677cd47eed3b60393bb0406146f49e1
SHA256: d65b9c981bc8d59a5bfcf94a0a9caecaf058939e15cc369d90dad9d2d2682ed9
3668
WANACRYPTOR.exe
C:\Users\admin\AppData\Local\Skype\Apps\login\images\retina\[email protected]
binary
MD5: 24101e1543902ed6685ce2df23253ba0
SHA256: e3da30c600108a5bb93ff30f9b9915195724a88779f216064382fee0d66b0cc1
3668
WANACRYPTOR.exe
C:\Users\admin\AppData\Local\Skype\Apps\login\images\retina\[email protected]
binary
MD5: ec40a5d4f42b7f5fa921149db502d6b0
SHA256: fe16652020e736b6b2baca9bf5dcfa6730c89dc9cb44e947ed6e7333a17d46df
3668
WANACRYPTOR.exe
C:\Users\admin\AppData\Local\Skype\Apps\login\images\retina\[email protected]
binary
MD5: 83978cb92d78600524d3d86f6e77b5e0
SHA256: 17b8068d7554384f850d7d180d42d635b68ffaee2211c08151fd35c60e8cc8a1
3668
WANACRYPTOR.exe
C:\Users\admin\AppData\Local\Skype\Apps\login\images\retina\[email protected]
––
MD5:  ––
SHA256:  ––
3668
WANACRYPTOR.exe
C:\Users\admin\AppData\Local\Skype\Apps\login\images\normal\[email protected]
––
MD5:  ––
SHA256:  ––
3668
WANACRYPTOR.exe
C:\Users\admin\AppData\Local\Skype\Apps\login\images\retina\[email protected]
––
MD5:  ––
SHA256:  ––
3668
WANACRYPTOR.exe
C:\Users\admin\AppData\Local\Skype\Apps\login\images\retina\[email protected]
––
MD5:  ––
SHA256:  ––
3668
WANACRYPTOR.exe
C:\Users\admin\AppData\Local\Skype\Apps\login\images\retina\[email protected]
––
MD5:  ––
SHA256:  ––
3668
WANACRYPTOR.exe
C:\Users\admin\AppData\Local\Skype\Apps\login\images\normal\[email protected]
binary
MD5: 4bc1898514aea9de00fe2770582f791d
SHA256: cb1ec1ba91093d9f57849787385848d284011189dc9c0aa5f91b64e9e7deed8c
3668
WANACRYPTOR.exe
C:\Users\admin\AppData\Local\Skype\Apps\login\images\normal\logo-xbox-25x25.png.WNCRY
binary
MD5: f91b1bced111a780f819985a0fdfeefb
SHA256: 3a55725b3c3bf07b51b8b8e1ec48010c5ac114b8592db1a2d4921f71f025a93f
3668
WANACRYPTOR.exe
C:\Users\admin\AppData\Local\Skype\Apps\login\images\normal\[email protected]
binary
MD5: 7e0518f63eb3d934b16c99bb353ea823
SHA256: b0b52e53728eab805c44d4bf4b63b4a8c83a441098a5ef15935ca93af6d48571
3668
WANACRYPTOR.exe
C:\Users\admin\AppData\Local\Skype\Apps\login\images\normal\msa-logos-135x25.png.WNCRY
binary
MD5: af05e312b4373da5d62850228e9c918d
SHA256: 7e56ba6c538deaf937edaf2c2a52af74f6abc8f12844b2258062adc0990bd355
3668
WANACRYPTOR.exe
C:\Users\admin\AppData\Local\Skype\Apps\login\images\normal\skype-logo-136x60.png.WNCRY
binary
MD5: fb8a1b7cff831a15aa02fe29a17989cd
SHA256: 21984b7bffe668b8e060231e251e6afdadacc44d110f0775601111d648ad99ea
3668
WANACRYPTOR.exe
C:\Users\admin\AppData\Local\Skype\Apps\login\images\normal\[email protected]
––
MD5:  ––
SHA256:  ––
3668
WANACRYPTOR.exe
C:\Users\admin\AppData\Local\Skype\Apps\login\images\normal\skype-logo-136x60.png.WNCRYT
––
MD5:  ––
SHA256:  ––
3668
WANACRYPTOR.exe
C:\Users\admin\AppData\Local\Skype\Apps\login\images\normal\msa-logos-135x25.png.WNCRYT
––
MD5:  ––
SHA256:  ––
3668
WANACRYPTOR.exe
C:\Users\admin\AppData\Local\Skype\Apps\login\images\normal\[email protected]
––
MD5:  ––
SHA256:  ––
3668
WANACRYPTOR.exe
C:\Users\admin\AppData\Local\Skype\Apps\login\images\normal\[email protected]
binary
MD5: ee5a03bc215fc8d155b64d11baca0012
SHA256: 06f24a1cb12b218a620c00e3ca6c7a2e35a3daaf7b41b92f2215c76d34eadf27
3668
WANACRYPTOR.exe
C:\Users\admin\AppData\Local\Skype\Apps\login\images\normal\[email protected]
binary
MD5: 5af8592ae2a54bd78a105794f7840c5b
SHA256: 90a91d1a8608921460a6893795c8bfd4bf31fa5e3f8e7555c1f9bffb517f60f9
3668
WANACRYPTOR.exe
C:\Users\admin\AppData\Local\Skype\Apps\login\images\normal\logo-skype-25x25.png.WNCRY
binary
MD5: 2041a7b91e7d38a793544ad120158bfb
SHA256: 820dccd642f138a3942f60df8914a9e38382c19aecceac9fbea98c5eb522bb1f
3668
WANACRYPTOR.exe
C:\Users\admin\AppData\Local\Skype\Apps\login\images\normal\[email protected]
binary
MD5: 79322b343c6624c78511b63734739b3c
SHA256: d622f38fd166fd59183d46333e3e1d9f295f517eea914fdb96cb30cf39d062fc
3668
WANACRYPTOR.exe
C:\Users\admin\AppData\Local\Skype\Apps\login\images\normal\[email protected]T
––
MD5:  ––
SHA256:  ––
3668
WANACRYPTOR.exe
C:\Users\admin\AppData\Local\Skype\Apps\login\images\normal\logo-skype-25x25.png.WNCRYT
––
MD5:  ––
SHA256:  ––
3668
WANACRYPTOR.exe
C:\Users\admin\AppData\Local\Skype\Apps\login\images\normal\[email protected]
––
MD5:  ––
SHA256:  ––
3668
WANACRYPTOR.exe
C:\Users\admin\AppData\Local\Skype\Apps\login\images\normal\logo-xbox-25x25.png.WNCRYT
––
MD5:  ––
SHA256:  ––
3668
WANACRYPTOR.exe
C:\Users\admin\AppData\Local\Skype\Apps\login\images\normal\loader_15fps.gif.WNCRY
binary
MD5: 6fa8ee5aa5aa66773639f29acb214468
SHA256: 60c6c82a02001f12b11ce7a2c21f1d47ecab4d3119a43ce9620500987c294432
3668
WANACRYPTOR.exe
C:\Users\admin\AppData\Local\Skype\Apps\login\images\normal\loader_30fps.gif.WNCRY
binary
MD5: 84f3ed2269617311f30eb92bf3d21321
SHA256: 85275dc7783026deb49e0c557c27160844bfd61538f3a90b7f101792dd5a0bb6
3668
WANACRYPTOR.exe
C:\Users\admin\AppData\Local\Skype\Apps\login\images\normal\[email protected]
binary
MD5: 5a5943b63ebc3589fe3844614b45263c
SHA256: 62858ef706f01762ba69404282f216d43e442887514bcceddbb2da4645e5fa42
3668
WANACRYPTOR.exe
C:\Users\admin\AppData\Local\Skype\Apps\login\images\normal\loader_15fps.gif.WNCRYT
––
MD5:  ––
SHA256:  ––
3668
WANACRYPTOR.exe
C:\Users\admin\AppData\Local\Skype\Apps\login\images\normal\[email protected]
––
MD5:  ––
SHA256:  ––
3668
WANACRYPTOR.exe
C:\Users\admin\AppData\Local\Skype\Apps\login\images\normal\[email protected]
––
MD5:  ––
SHA256:  ––
3668
WANACRYPTOR.exe
C:\Users\admin\AppData\Local\Skype\Apps\login\images\normal\loader_30fps.gif.WNCRYT
––
MD5:  ––
SHA256:  ––
3668
WANACRYPTOR.exe
C:\Users\admin\AppData\Local\Skype\Apps\login\images\normal\back_20x20-inverted.png.WNCRY
binary
MD5: dcb797abdd20e2832139c07eac2c2c7b
SHA256: 8baa2cf626ae91f6aca48c051e3a74b2b561cbb8cabfb3a5cc47162b2dacc1b6
3668
WANACRYPTOR.exe
C:\Users\admin\AppData\Local\Skype\Apps\login\images\black-on-white\skype-logo-136x60.png.WNCRY
binary
MD5: bdb82f6aaa7752ad78f7965614fc2f28
SHA256: 9b1d53f0afff8ca6b17eb492df1fade89b491159827cea2445afaa145e7b781b
3668
WANACRYPTOR.exe
C:\Users\admin\AppData\Local\Skype\Apps\login\images\black-on-white\[email protected]
binary
MD5: ebc9aaf326c54f9c6078f0c745d80932
SHA256: f9452fa777918b8adcc266a736a54992d6d7874a0246d15cef9d932e959a73a4
3668
WANACRYPTOR.exe
C:\Users\admin\AppData\Local\Skype\Apps\login\images\normal\[email protected]
binary
MD5: e43647caedc95497f8d68e458862be36
SHA256: 8f435479b11683323cb8a334574363820315a2aaac94f31dc45e045f1bbeee4a
3668
WANACRYPTOR.exe
C:\Users\admin\AppData\Local\Skype\Apps\login\images\normal\back_20x20-inverted.png.WNCRYT
––
MD5:  ––
SHA256:  ––
3668
WANACRYPTOR.exe
C:\Users\admin\AppData\Local\Skype\Apps\login\images\black-on-white\skype-logo-136x60.png.WNCRYT
––
MD5:  ––
SHA256:  ––
3668
WANACRYPTOR.exe
C:\Users\admin\AppData\Local\Skype\Apps\login\images\black-on-white\[email protected]
––
MD5:  ––
SHA256:  ––
3668
WANACRYPTOR.exe
C:\Users\admin\AppData\Local\Skype\Apps\login\images\normal\[email protected]
––
MD5:  ––
SHA256:  ––
3668
WANACRYPTOR.exe
C:\Users\admin\AppData\Local\Skype\Apps\login\images\black-on-white\[email protected]
binary
MD5: 90ec5a6e9ed842b5affa186b595f63e3
SHA256: 2b6689405346341d5116cb057d3265ef678d8a99012120f11d555ea1015278fa
3668
WANACRYPTOR.exe
C:\Users\admin\AppData\Local\Skype\Apps\login\images\black-on-white\[email protected]
binary
MD5: da1c7ae811fea0b5d3131fcc74d530fd
SHA256: 9a16583a75a7a044dcfa90a5273bbb081b2784f1dd39ad63626798fbeabd8337
3668
WANACRYPTOR.exe
C:\Users\admin\AppData\Local\Skype\Apps\login\images\black-on-white\msa-logos-135x25.png.WNCRY
binary
MD5: bf480791ef442bb9534ceedcd57d8d29
SHA256: ce8f6112348f552ae85dd77c0f1c00d46e106714657d238a8ca1ab2ea42e3846
3668
WANACRYPTOR.exe
C:\Users\admin\AppData\Local\Skype\Apps\login\images\black-on-white\[email protected]
––
MD5:  ––
SHA256:  ––
3668
WANACRYPTOR.exe
C:\Users\admin\AppData\Local\Skype\Apps\login\images\black-on-white\msa-logos-135x25.png.WNCRYT
––
MD5:  ––
SHA256:  ––
3668
WANACRYPTOR.exe
C:\Users\admin\AppData\Local\Skype\Apps\login\images\black-on-white\[email protected]
––
MD5:  ––
SHA256:  ––
3668
WANACRYPTOR.exe
C:\Users\admin\AppData\Local\Skype\Apps\login\images\black-on-white\[email protected]
binary
MD5: 81cd817e6b5169dd7b9ea703d52921f6
SHA256: ebfe3cf486290e87d3eaa7c98d1545294548bf1933e462aa16fea2313360e8b4
3668
WANACRYPTOR.exe
C:\Users\admin\AppData\Local\Skype\Apps\login\images\black-on-white\[email protected]
binary
MD5: 1968a8e873923a0c99ea157fef54fb67
SHA256: 5efc6c4598daa8feb5ae6f1c91d39fcb4870694082d6f1e446cfae6d2bb0ecf5
3668
WANACRYPTOR.exe
C:\Users\admin\AppData\Local\Skype\Apps\login\images\black-on-white\[email protected]
––
MD5:  ––
SHA256:  ––
3668
WANACRYPTOR.exe
C:\Users\admin\AppData\Local\Skype\Apps\login\images\black-on-white\[email protected]
––
MD5:  ––
SHA256:  ––
3668
WANACRYPTOR.exe
C:\Users\admin\AppData\Local\Skype\Apps\login\images\black-on-white\caret_left.png.WNCRY
binary
MD5: d7734fcf41c9b74df9897e02ef002307
SHA256: b486b55a959839a25d0636b3ce23646fe5c97c5bd2d318efe6799b444a8e1b75
3668
WANACRYPTOR.exe
C:\Users\admin\AppData\Local\Skype\Apps\login\images\black-on-white\[email protected]
binary
MD5: 95d20d08227c8d6c01b9ec2978c8e25d
SHA256: 90bd2c37982f7ad7a43ca1e77ed0777c69081fc6166494f905476f5649c3d143
3668
WANACRYPTOR.exe
C:\Users\admin\AppData\Local\Skype\Apps\login\images\black-on-white\caret_right.png.WNCRY
binary
MD5: fb47997c42f11a25005e454d87ee8fbf
SHA256: 818f132225cdad0d016f868ef8073e9e957dcbe92709184f6bd1bc04ec1f4319
3668
WANACRYPTOR.exe
C:\Users\admin\AppData\Local\Skype\Apps\login\images\black-on-white\[email protected]
––
MD5:  ––
SHA256:  ––
3668
WANACRYPTOR.exe
C:\Users\admin\AppData\Local\Skype\Apps\login\images\black-on-white\caret_right.png.WNCRYT
––
MD5:  ––
SHA256:  ––
3668
WANACRYPTOR.exe
C:\Users\admin\AppData\Local\Skype\Apps\login\images\black-on-white\caret_left.png.WNCRYT
––
MD5:  ––
SHA256:  ––
3668
WANACRYPTOR.exe
C:\Users\admin\AppData\Local\Skype\Apps\login\images\black-on-white\[email protected]
binary
MD5: 01f013a69810644959f85d888c5fa43f
SHA256: ddc88797d418312f9a87faddab4cde0138c1510d1d20a9868d9f4e3f5fcf8148
3668
WANACRYPTOR.exe
C:\Users\admin\AppData\Local\Skype\Apps\login\images\skypelogo.png.WNCRY
binary
MD5: 04cbd8c7da828deb3f2a1fd664ac1cd8
SHA256: 5b4298446655a9483f1a726ff286c872f792d316413a7598e445dd4f37aba1fc
3668
WANACRYPTOR.exe
C:\Users\admin\AppData\Local\Skype\Apps\login\images\logoanim.gif.WNCRY
binary
MD5: 199b2ce9eee2d8a0467623617bb96ef0
SHA256: cc2a80f0c37f4de6a44bd7d3ee73d28cc649b218b9e587c726bb4a7229a1572d
3668
WANACRYPTOR.exe
C:\Users\admin\AppData\Local\Skype\Apps\login\images\msDefaultPicture.png.WNCRY
binary
MD5: 6246dd9cdf82e2f219c6edc02f362e48
SHA256: 51300620c078db5a56b144ba78e4d99bdcd76b03d26f68f315741dc91d00f448
3668
WANACRYPTOR.exe
C:\Users\admin\AppData\Local\Skype\Apps\login\images\black-on-white\back_20x20-inverted.png.WNCRY
binary
MD5: 318a957e30cd9b9d418d964518196da7
SHA256: b2b3495c3be5bce01c0c69b56dd85dc84bc5341e656281e772b3be52a2cddae3
3668
WANACRYPTOR.exe
C:\Users\admin\AppData\Local\Skype\Apps\login\images\black-on-white\[email protected]
––
MD5:  ––
SHA256:  ––
3668
WANACRYPTOR.exe
C:\Users\admin\AppData\Local\Skype\Apps\login\images\msDefaultPicture.png.WNCRYT
––
MD5:  ––
SHA256:  ––
3668
WANACRYPTOR.exe
C:\Users\admin\AppData\Local\Skype\Apps\login\images\skypelogo.png.WNCRYT
––
MD5:  ––
SHA256:  ––
3668
WANACRYPTOR.exe
C:\Users\admin\AppData\Local\Skype\Apps\login\images\black-on-white\back_20x20-inverted.png.WNCRYT
––
MD5:  ––
SHA256:  ––
3668
WANACRYPTOR.exe
C:\Users\admin\AppData\Local\Skype\Apps\login\images\logoanim.gif.WNCRYT
––
MD5:  ––
SHA256:  ––
3668
WANACRYPTOR.exe
C:\Users\admin\AppData\Local\Skype\Apps\login\images\icons.png.WNCRY
binary
MD5: 33e1ab220cb38b4b64d35d45a237afe3
SHA256: 323381a608bf3e9b5583feba7872c2ec56d7c8ab31f3cfac01c950563325a925
3668
WANACRYPTOR.exe
C:\Users\admin\AppData\Local\Skype\Apps\login\images\loader.png.WNCRY
binary
MD5: 5fd122e0ffcfb94331e44a840359ade8
SHA256: feb380a7b1fed5dc56d9f5081ac629fd68380ff82ba4c9178e3a37630a32c327
3668
WANACRYPTOR.exe
C:\Users\admin\AppData\Local\Skype\Apps\login\images\dropdown.png.WNCRY
binary
MD5: 93566f84cd8d055afa9d12dd695b9150
SHA256: a59ad78f1e55368ebf18a72ffdc882c7c0f7872e5c15bef994c3d9a7a45808e6
3668
WANACRYPTOR.exe
C:\Users\admin\AppData\Local\Skype\Apps\login\images\inputfields.png.WNCRY
binary
MD5: 4881440bea2140652a1c7e0b4766b3e9
SHA256: b3fcfa2147cf0b98a32ac33af3c08f5d60906da8b8be1767a544b50220aeadf0
3668
WANACRYPTOR.exe
C:\Users\admin\AppData\Local\Skype\Apps\login\images\loader.gif.WNCRY
binary
MD5: 1f11389d01136ab3eeec0f820d19302f
SHA256: e98edf9f3a5c653b11654d742865bf6fc4a5c4fd0b084126ffd05e2741b65661
3668
WANACRYPTOR.exe
C:\Users\admin\AppData\Local\Skype\Apps\login\images\loader.png.WNCRYT
––
MD5:  ––
SHA256:  ––
3668
WANACRYPTOR.exe
C:\Users\admin\AppData\Local\Skype\Apps\login\images\loader.gif.WNCRYT
––
MD5:  ––
SHA256:  ––
3668
WANACRYPTOR.exe
C:\Users\admin\AppData\Local\Skype\Apps\login\images\icons.png.WNCRYT
––
MD5:  ––
SHA256:  ––
3668
WANACRYPTOR.exe
C:\Users\admin\AppData\Local\Skype\Apps\login\images\dropdown.png.WNCRYT
––
MD5:  ––
SHA256:  ––
3668
WANACRYPTOR.exe
C:\Users\admin\AppData\Local\Skype\Apps\login\images\inputfields.png.WNCRYT
––
MD5:  ––
SHA256:  ––
3668
WANACRYPTOR.exe
C:\Users\admin\AppData\Local\Skype\Apps\login\images\capsLock.png.WNCRY
binary
MD5: eb4083c23ef4655525f3100727718055
SHA256: b82dbe82c9950f2d6285195b14506e762a5b9a9b7524dca681fd6e5dc265045d
3668
WANACRYPTOR.exe
C:\Users\admin\AppData\Local\Skype\Apps\login\images\capsLockShort.png.WNCRY
binary
MD5: 609b6e7d76879befab320fdd5140e2a6
SHA256: f39036b4c2d7fe67e7a34a10bf7b474f71486c91a0eb3b3cbcc9057ac1b657a4
3668
WANACRYPTOR.exe
C:\Users\admin\AppData\Local\Skype\Apps\login\images\capsLockShort.png.WNCRYT
––
MD5:  ––
SHA256:  ––
3668
WANACRYPTOR.exe
C:\Users\admin\AppData\Local\Skype\Apps\login\images\capsLock.png.WNCRYT
––
MD5:  ––
SHA256:  ––
3668
WANACRYPTOR.exe
C:\Users\admin\AppData\Local\Opera\Opera\thumbnails\db8a2a05-cf67-924d-aebe-4f3590c88d40.png.WNCRY
binary
MD5: 3b68ca63ec4d00eb50be0aca2b7e594f
SHA256: 6a928037f595ea018cf048a3401d5eb10cedbaa0e87bd3ede33b04140dd2abe4
3668
WANACRYPTOR.exe
C:\Users\admin\AppData\Local\Skype\Apps\login\images\backgroundNoCloud.png.WNCRY
binary
MD5: 0c2f8ce13c67cc8612ad5b6b760aef75
SHA256: a19751995ad632e2951119180e8e7ae290f4f9346e89e7e13046c6c95ffe5373
3668
WANACRYPTOR.exe
C:\Users\admin\AppData\Local\Skype\Apps\login\images\buttons.png.WNCRY
binary
MD5: 91bf88481af459e48fd115cd58b86c2f
SHA256: cc351e5105d166c9bcf2310068625a70ae46d84730e511425f122124a233f4d8
3668
WANACRYPTOR.exe
C:\Users\admin\AppData\Local\Skype\Apps\login\images\background.png.WNCRY
binary
MD5: fa546e3f402dc9d878143a6e2e786350
SHA256: 440e916a17f5a1458396fb4512d7aa4130a88afebdfe0f13311dbabb7ad139ee
3668
WANACRYPTOR.exe
C:\Users\admin\AppData\Local\Skype\Apps\login\images\buttons.png.WNCRYT
––
MD5:  ––
SHA256:  ––
3668
WANACRYPTOR.exe
C:\Users\admin\AppData\Local\Skype\Apps\login\images\backgroundNoCloud.png.WNCRYT
––
MD5:  ––
SHA256:  ––
3668
WANACRYPTOR.exe
C:\Users\admin\AppData\Local\Skype\Apps\login\images\background.png.WNCRYT
––
MD5:  ––
SHA256:  ––
3668
WANACRYPTOR.exe
C:\Users\admin\AppData\Local\Opera\Opera\thumbnails\db8a2a05-cf67-924d-aebe-4f3590c88d40.png.WNCRYT
––
MD5:  ––
SHA256:  ––
3668
WANACRYPTOR.exe
C:\Users\admin\AppData\Local\Opera\Opera\thumbnails\78922692-3601-de42-ac06-e30a85bf5633.png.WNCRY
binary
MD5: 24dd5301a59b519ef869dfd0452f8846
SHA256: 1fcc59742f7e28961126964d066e8d8911069ea93174378365d0f412a792c87f
3668
WANACRYPTOR.exe
C:\Users\admin\AppData\Local\Opera\Opera\thumbnails\88d94439-10e6-1a4b-87ed-7e884296ac9d.png.WNCRY
binary
MD5: fe5eaad3190b4df1b514346caffecb34
SHA256: 733deb70fc29fdc0a75485a57afb7a4a73756ee23b45751ed4459206e6557f80
3668
WANACRYPTOR.exe
C:\Users\admin\AppData\Local\Opera\Opera\thumbnails\a39d20f8-580e-9042-8d4c-c6be0dbbdc85.png.WNCRY
binary
MD5: 60c0064d31f2a21e7e7fe4fd9455af9a
SHA256: 5eb01ad33b15767181b95b5431029d7ab171547b136381cd8763e9b37ded80e9
3668
WANACRYPTOR.exe
C:\Users\admin\AppData\Local\Opera\Opera\thumbnails\88d94439-10e6-1a4b-87ed-7e884296ac9d.png.WNCRYT
––
MD5:  ––
SHA256:  ––
3668
WANACRYPTOR.exe
C:\Users\admin\AppData\Local\Opera\Opera\thumbnails\a39d20f8-580e-9042-8d4c-c6be0dbbdc85.png.WNCRYT
––
MD5:  ––
SHA256:  ––
3668
WANACRYPTOR.exe
C:\Users\admin\AppData\Local\Opera\Opera\thumbnails\66114aa9-90a0-a846-a71a-1b301e6d3436.png.WNCRY
binary
MD5: 94e10b5df134efe94a6486b8e3b4846c
SHA256: 791ba8a0606bd2e9b72726760b5f24692d65f54c1d9c1a1cc7e55b8b6387f855
3668
WANACRYPTOR.exe
C:\Users\admin\AppData\Local\Opera\Opera\thumbnails\78922692-3601-de42-ac06-e30a85bf5633.png.WNCRYT
––
MD5:  ––
SHA256:  ––
3668
WANACRYPTOR.exe
C:\Users\admin\AppData\Local\Opera\Opera\thumbnails\66114aa9-90a0-a846-a71a-1b301e6d3436.png.WNCRYT
––
MD5:  ––
SHA256:  ––
3668
WANACRYPTOR.exe
C:\Users\admin\AppData\Local\Opera\Opera\thumbnails\2a5473f7-518b-6946-8c75-2ef10224edbd.png.WNCRY
binary
MD5: 8fe8c763da93074ef14832ddaf98753a
SHA256: 3940ece6d1665323049c5ff0853fb7343ae2520b2f167b4acb996261699fae7e
3668
WANACRYPTOR.exe
C:\Users\admin\AppData\Local\Mozilla\Firefox\Profiles\qldyz51w.default\thumbnails\ad5a4453bea49203135688a7b8db842d.png.WNCRY
binary
MD5: e00c8c4acb9be74caca6caa88c44e10a
SHA256: 2a4e548c12a0e24509c444604cf5bad1e00d5a3ba36a6fc918cf0b67756f914d
3668
WANACRYPTOR.exe
C:\Users\admin\AppData\Local\Opera\Opera\thumbnails\2a5473f7-518b-6946-8c75-2ef10224edbd.png.WNCRYT
––
MD5:  ––
SHA256:  ––
3668
WANACRYPTOR.exe
C:\Users\admin\AppData\Local\Microsoft\Windows Mail\Stationery\Wrinkled_Paper.gif.WNCRY
binary
MD5: e7ba524f24e51d0d563f15f8749b0b9d
SHA256: a3c737992ea819ac6c0e2e6b7b56c298b724d3fb8d97e6c4d37298ed55d53b1c
3668
WANACRYPTOR.exe
C:\Users\admin\AppData\Local\Microsoft\Windows Mail\Stationery\Stucco.gif.WNCRY
binary
MD5: d9e3da1733627d60818489d2a4f3ba48
SHA256: 8c4c0ab8e71cbcafd3fb9b10c11cfa3d9dce63b859a647191a891ca81da92b40
3668
WANACRYPTOR.exe
C:\Users\admin\AppData\Local\Microsoft\Windows Mail\Stationery\Tiki.gif.WNCRY
binary
MD5: e96dfbca8fbf4939e602d66eaf132e24
SHA256: c49dda81a8c2d956da3019673281482f0e96efe0bd1f959f30c297f96e967705
3668
WANACRYPTOR.exe
C:\Users\admin\AppData\Local\Mozilla\Firefox\Profiles\qldyz51w.default\thumbnails\ad5a4453bea49203135688a7b8db842d.png.WNCRYT
––
MD5:  ––
SHA256:  ––
3668
WANACRYPTOR.exe
C:\Users\admin\AppData\Local\Microsoft\Windows Mail\Stationery\Wrinkled_Paper.gif.WNCRYT
––
MD5:  ––
SHA256:  ––
3668
WANACRYPTOR.exe
C:\Users\admin\AppData\Local\Microsoft\Windows Mail\Stationery\Tiki.gif.WNCRYT
––
MD5:  ––
SHA256:  ––
3668
WANACRYPTOR.exe
C:\Users\admin\AppData\Local\Microsoft\Windows Mail\Stationery\Connectivity.gif.WNCRY
binary
MD5: e4e7b88384c5a79bf0a28525dcf3df32
SHA256: b0917fd5a52c7d21aa8abe9685730d2131c2b37c71e4499b437a707955e27655
3668
WANACRYPTOR.exe
C:\Users\admin\AppData\Local\Microsoft\Windows Mail\Stationery\Cave_Drawings.gif.WNCRY
binary
MD5: 7a0ab59a99a6d35bd8fb1267212f7324
SHA256: 2574725a80bc83b88cb4f088c17c746916470280c9e498e41770ffa1b8b1550f
3668
WANACRYPTOR.exe
C:\Users\admin\AppData\Local\Microsoft\Windows Mail\Stationery\Connectivity.gif.WNCRYT
––
MD5:  ––
SHA256:  ––
3668
WANACRYPTOR.exe
C:\Users\admin\AppData\Local\Microsoft\Windows Mail\Stationery\Stucco.gif.WNCRYT
––
MD5:  ––
SHA256:  ––
3668
WANACRYPTOR.exe
C:\Users\admin\AppData\Local\Microsoft\Windows\Explorer\thumbcache_96.db.WNCRY
binary
MD5: 8c37da2fa4151b7e2d9df1460d138f9e
SHA256: 58e98286341221cff3c21ab72d1edd4888912b9abd5981ebb8c978eb089055f3
3668
WANACRYPTOR.exe
C:\Users\admin\AppData\Local\Microsoft\Windows\Explorer\thumbcache_idx.db.WNCRY
binary
MD5: c6cde9f53db3ddd7ab76b09c5011c948
SHA256: 929fb8fe0ffec802c585e2e97b95cb08342371f8832c3fed0c4ffe24b99f6101
3668
WANACRYPTOR.exe
C:\Users\admin\AppData\Local\Microsoft\Windows Mail\Stationery\Cave_Drawings.gif.WNCRYT
––
MD5:  ––
SHA256:  ––
3668
WANACRYPTOR.exe
C:\Users\admin\AppData\Local\Microsoft\Windows\Explorer\thumbcache_idx.db.WNCRYT
––
MD5:  ––
SHA256:  ––
3668
WANACRYPTOR.exe
C:\Users\admin\AppData\Local\Microsoft\Windows\Explorer\thumbcache_96.db.WNCRYT
––
MD5:  ––
SHA256:  ––
3668
WANACRYPTOR.exe
C:\Users\admin\AppData\Local\Microsoft\Windows\Explorer\thumbcache_32.db.WNCRY
binary
MD5: c74b897526b61fbb63896216039a1b97
SHA256: d49a3b814aa859a297e67b82a74d63ff1a3a9d216617fddc1a6aa1450f8d6985
3668
WANACRYPTOR.exe
C:\Users\admin\AppData\Local\Microsoft\Windows\Explorer\thumbcache_32.db.WNCRYT
––
MD5:  ––
SHA256:  ––
3668
WANACRYPTOR.exe
C:\Users\admin\AppData\Local\Microsoft\Windows\Caches\{AFBF9F1A-8EE8-4C77-AF34-C647E37CA0D9}.1.ver0x000000000000001b.db.WNCRY
binary
MD5: 839d9e39d53a3bdd6910bec0f5882deb
SHA256: 0b0d67bd35ce2ef3a7f63e139798ec7f76dfe44e1b14c7a47d4ce4f910e03402
3668
WANACRYPTOR.exe
C:\Users\admin\AppData\Local\Microsoft\Windows\Explorer\thumbcache_256.db.WNCRY
binary
MD5: 0654513a0b3858f422643779237db500
SHA256: 9ee234f94aadda700380cd1249987ea98cea2f94dbba8e3625ddef122a9d6af1
3668
WANACRYPTOR.exe
C:\Users\admin\AppData\Local\Microsoft\Windows\Explorer\thumbcache_256.db.WNCRYT
––
MD5:  ––
SHA256:  ––
3668
WANACRYPTOR.exe
C:\Users\admin\AppData\Local\Microsoft\Windows\Caches\{AFBF9F1A-8EE8-4C77-AF34-C647E37CA0D9}.1.ver0x000000000000001a.db.WNCRY
binary
MD5: 8c69058eea1b37f47efa09c4fdd56d91
SHA256: ceb9dd2391020f4e3174cb6e37e7be9c382627d766f88ebad9a09d5553a7b697
3668
WANACRYPTOR.exe
C:\Users\admin\AppData\Local\Microsoft\Windows\Caches\{AFBF9F1A-8EE8-4C77-AF34-C647E37CA0D9}.1.ver0x000000000000001b.db.WNCRYT
––
MD5:  ––
SHA256:  ––
3668
WANACRYPTOR.exe
C:\Users\admin\AppData\Local\Microsoft\Windows\Caches\{AFBF9F1A-8EE8-4C77-AF34-C647E37CA0D9}.1.ver0x000000000000001a.db.WNCRYT
––
MD5:  ––
SHA256:  ––
3668
WANACRYPTOR.exe
C:\Users\admin\AppData\Local\Microsoft\OneNote\14.0\OneNoteOfflineCache_Files\ee4479ee-b960-4d54-abc8-c9e95e2bf81f.png.WNCRY
binary
MD5: f088d24a22ae6d5fbad9fa56ccddcc38
SHA256: 3f2a76cafb6e9b9fc439ba74c182310d55a49a23c071b0357fb4a0aeacf0fb81
3668
WANACRYPTOR.exe
C:\Users\admin\AppData\Local\Microsoft\Windows\Caches\cversions.1.db.WNCRY
binary
MD5: 964b25be203dbcca312f5793624029e6
SHA256: ce089f09b49e861d231357c1213bc8d19563464f42df5966645dc7c9e3a30fd7
3668
WANACRYPTOR.exe
C:\Users\admin\AppData\Local\Microsoft\OneNote\14.0\OneNoteOfflineCache_Files\f173a3a2-bd1a-460f-b78a-faf2a51f6d91.png.WNCRY
binary
MD5: ce540d15c6dbd6f9173218dfb177eefc
SHA256: 7375667b1558938dd680d8d9b443c8f62e0ab3ef3ec7ee92f492d5b519b922d1
3668
WANACRYPTOR.exe
C:\Users\admin\AppData\Local\Microsoft\OneNote\14.0\OneNoteOfflineCache_Files\f173a3a2-bd1a-460f-b78a-faf2a51f6d91.png.WNCRYT
––
MD5:  ––
SHA256:  ––
3668
WANACRYPTOR.exe
C:\Users\admin\AppData\Local\Microsoft\Windows\Caches\cversions.1.db.WNCRYT
––
MD5:  ––
SHA256:  ––
3668
WANACRYPTOR.exe
C:\Users\admin\AppData\Local\Microsoft\OneNote\14.0\OneNoteOfflineCache_Files\ee4479ee-b960-4d54-abc8-c9e95e2bf81f.png.WNCRYT
––
MD5:  ––
SHA256:  ––
3668
WANACRYPTOR.exe
C:\Users\admin\AppData\Local\Microsoft\OneNote\14.0\OneNoteOfflineCache_Files\e51cf594-e321-4d1c-88e7-df9cde80904c.png.WNCRY
binary
MD5: 3545c6d03504d7f78cd897120406cc28
SHA256: e7e0f9605a1381814aea68edb80605f0c94ac83e9f0d1d8bb2b3d0ae21cb9730
3668
WANACRYPTOR.exe
C:\Users\admin\AppData\Local\Microsoft\OneNote\14.0\OneNoteOfflineCache_Files\e7a7c0d5-0e34-4323-9576-f37e394faa8a.png.WNCRY
binary
MD5: 7f517fe9b73c99928080b34885595b1a
SHA256: f8110e843cc9023279eccfeb89534e19dce5396c2e6ccca6283ddf6c3e294aa5
3668
WANACRYPTOR.exe
C:\Users\admin\AppData\Local\Microsoft\OneNote\14.0\OneNoteOfflineCache_Files\e7a7c0d5-0e34-4323-9576-f37e394faa8a.png.WNCRYT
––
MD5:  ––
SHA256:  ––
3668
WANACRYPTOR.exe
C:\Users\admin\AppData\Local\Microsoft\OneNote\14.0\OneNoteOfflineCache_Files\e29a7eaf-32ad-400c-9927-05c358358ffc.png.WNCRY
binary
MD5: 706d25080a4e17fd200f4df2c9c6088e
SHA256: 80549e8eae5664cbbe65cd19ae87e05d12809cddf1ae30b0de0496b3fa9896ad
3668
WANACRYPTOR.exe
C:\Users\admin\AppData\Local\Microsoft\OneNote\14.0\OneNoteOfflineCache_Files\e5116f77-b907-4c46-8bfa-006092a6714d.png.WNCRY
binary
MD5: a864c04879071a6bd0d1a02dc609e850
SHA256: 06e33277c050217e2930274018ebebf0a5cb8b921982406027754f3166da7f2d
3668
WANACRYPTOR.exe
C:\Users\admin\AppData\Local\Microsoft\OneNote\14.0\OneNoteOfflineCache_Files\e5116f77-b907-4c46-8bfa-006092a6714d.png.WNCRYT
––
MD5:  ––
SHA256:  ––
3668
WANACRYPTOR.exe
C:\Users\admin\AppData\Local\Microsoft\OneNote\14.0\OneNoteOfflineCache_Files\e51cf594-e321-4d1c-88e7-df9cde80904c.png.WNCRYT
––
MD5:  ––
SHA256:  ––
3668
WANACRYPTOR.exe
C:\Users\admin\AppData\Local\Microsoft\OneNote\14.0\OneNoteOfflineCache_Files\e29a7eaf-32ad-400c-9927-05c358358ffc.png.WNCRYT
––
MD5:  ––
SHA256:  ––
3668
WANACRYPTOR.exe
C:\Users\admin\AppData\Local\Microsoft\OneNote\14.0\OneNoteOfflineCache_Files\d2a0e881-e736-4694-b4e5-62a677ac17bf.png.WNCRY
binary
MD5: adace9b3f926aae842c9ce19a0cba906
SHA256: e64f2604f0fe6511f96799e305c2dd4ed00fce7f31e5c89ce9cb6a9893c3d3d2
3668
WANACRYPTOR.exe
C:\Users\admin\AppData\Local\Microsoft\OneNote\14.0\OneNoteOfflineCache_Files\d32a2c63-e181-4374-a527-d8ec3791e0cc.png.WNCRY
binary
MD5: e685cbdf0c57a5d93654e1f1d6cb8e75
SHA256: 9a075a2479c0af7988921c5a871b17a132e956063e38a64cc64cc1d6cdb97ce2
3668
WANACRYPTOR.exe
C:\Users\admin\AppData\Local\Microsoft\OneNote\14.0\OneNoteOfflineCache_Files\d6f82e07-6756-4003-877a-af43e54f9781.png.WNCRY
binary
MD5: d43d12537b52edb050af55a079c700b2
SHA256: 520634399748244704081428e67bc799966344b5027259469120fc7979c15430
3668
WANACRYPTOR.exe
C:\Users\admin\AppData\Local\Microsoft\OneNote\14.0\OneNoteOfflineCache_Files\d32a2c63-e181-4374-a527-d8ec3791e0cc.png.WNCRYT
––
MD5:  ––
SHA256:  ––
3668
WANACRYPTOR.exe
C:\Users\admin\AppData\Local\Microsoft\OneNote\14.0\OneNoteOfflineCache_Files\d6f82e07-6756-4003-877a-af43e54f9781.png.WNCRYT
––
MD5:  ––
SHA256:  ––
3668
WANACRYPTOR.exe
C:\Users\admin\AppData\Local\Microsoft\OneNote\14.0\OneNoteOfflineCache_Files\d2a0e881-e736-4694-b4e5-62a677ac17bf.png.WNCRYT
––
MD5:  ––
SHA256:  ––
3668
WANACRYPTOR.exe
C:\Users\admin\AppData\Local\Microsoft\OneNote\14.0\OneNoteOfflineCache_Files\d024a53a-b32a-417d-8f75-e1998be423af.png.WNCRY
binary
MD5: bc8c545ba5c21b9240c959195b14d89c
SHA256: 7d29b9482eba5c64958aae24976dbe758413c68038c39c72b844238ccc1582fc
3668
WANACRYPTOR.exe
C:\Users\admin\AppData\Local\Microsoft\OneNote\14.0\OneNoteOfflineCache_Files\d137f4ab-4b3d-439e-836f-ffbbc700bef1.png.WNCRY
binary
MD5: 7c62bfb47f77acaf6e26dbac209a2d94
SHA256: 18aa8c1cfa55a08394d4df30082567e58262d63837d189dc4d0cd8ce7999bbfa
3668
WANACRYPTOR.exe
C:\Users\admin\AppData\Local\Microsoft\OneNote\14.0\OneNoteOfflineCache_Files\d13b95bf-2bb1-4c3d-a85c-9ac5e1cb3884.png.WNCRY
binary
MD5: 31fa1266765fee74eef171b405bdefee
SHA256: 2d9d08a96cfa51e4f1440702bc2a09d299af806dc713f6d6da99eb3ecee80770
3668
WANACRYPTOR.exe
C:\Users\admin\AppData\Local\Microsoft\OneNote\14.0\OneNoteOfflineCache_Files\d13b95bf-2bb1-4c3d-a85c-9ac5e1cb3884.png.WNCRYT
––
MD5:  ––
SHA256:  ––
3668
WANACRYPTOR.exe
C:\Users\admin\AppData\Local\Microsoft\OneNote\14.0\OneNoteOfflineCache_Files\d137f4ab-4b3d-439e-836f-ffbbc700bef1.png.WNCRYT
––
MD5:  ––
SHA256:  ––
3668
WANACRYPTOR.exe
C:\Users\admin\AppData\Local\Microsoft\OneNote\14.0\OneNoteOfflineCache_Files\d024a53a-b32a-417d-8f75-e1998be423af.png.WNCRYT
––
MD5:  ––
SHA256:  ––
3668
WANACRYPTOR.exe
C:\Users\admin\AppData\Local\Microsoft\OneNote\14.0\OneNoteOfflineCache_Files\c129b038-2a0f-4994-b354-64ed233a0973.png.WNCRY
binary
MD5: 813774897d9ba4f6fe6ffb455c92a59a
SHA256: 2c415965a489c5c2b15f2c0befca4c96d953456fe24817904ae6a811c6e183e0
3668
WANACRYPTOR.exe
C:\Users\admin\AppData\Local\Microsoft\OneNote\14.0\OneNoteOfflineCache_Files\c129b038-2a0f-4994-b354-64ed233a0973.png.WNCRYT
––
MD5:  ––
SHA256:  ––
3668
WANACRYPTOR.exe
C:\Users\admin\AppData\Local\Microsoft\OneNote\14.0\OneNoteOfflineCache_Files\bf4e96cf-9460-4049-8172-cfb4bec57f8e.png.WNCRY
binary
MD5: 5f113cecf3ecb3c25d7f119381dfc0ad
SHA256: 722aaebfbb388270c339578335317494f480d313044aaf29184642da60659f50
3668
WANACRYPTOR.exe
C:\Users\admin\AppData\Local\Microsoft\OneNote\14.0\OneNoteOfflineCache_Files\bf4e96cf-9460-4049-8172-cfb4bec57f8e.png.WNCRYT
––
MD5:  ––
SHA256:  ––
3668
WANACRYPTOR.exe
C:\Users\admin\AppData\Local\Microsoft\OneNote\14.0\OneNoteOfflineCache_Files\bdde27ea-6a12-4825-bfac-f600b0f142fa.png.WNCRY
binary
MD5: 8f7f281485afdc57a7dd8265b14757a7
SHA256: 935dd890d5934657a74c397e9a9eb92bbea74448c73d9b5d8ce93573c19175fb
3668
WANACRYPTOR.exe
C:\Users\admin\AppData\Local\Microsoft\OneNote\14.0\OneNoteOfflineCache_Files\b2a67a4a-c116-4c88-9fd1-c5b9a23d7929.png.WNCRY
binary
MD5: f898d2546f9661c714fc7508def4fe81
SHA256: 1790fa35e06ffd91484ad8fde5ae7c817b383d31206ef2c1e6190f4e701fbaf2
3668
WANACRYPTOR.exe
C:\Users\admin\AppData\Local\Microsoft\OneNote\14.0\OneNoteOfflineCache_Files\be1e893c-ed6d-4ac9-933e-dd5340e7c76f.png.WNCRY
binary
MD5: 287d2410af73487d7d2d1de6dff8e428
SHA256: 8f25cd96e94ca3c229329a06f08fd48d5135d71504dbb50b0fe677c247621665
3668
WANACRYPTOR.exe
C:\Users\admin\AppData\Local\Microsoft\OneNote\14.0\OneNoteOfflineCache_Files\bb4e150b-7e2a-4556-81dd-590d7ab07dda.png.WNCRY
binary
MD5: fe7accd6fb1806c2c587dba1a101f5b6
SHA256: 3f7c38bbf2cda1f531536b5b15bb287f71c9bdf8035da03b587b228f946ae08b
3668
WANACRYPTOR.exe
C:\Users\admin\AppData\Local\Microsoft\OneNote\14.0\OneNoteOfflineCache_Files\bdde27ea-6a12-4825-bfac-f600b0f142fa.png.WNCRYT
––
MD5:  ––
SHA256:  ––
3668
WANACRYPTOR.exe
C:\Users\admin\AppData\Local\Microsoft\OneNote\14.0\OneNoteOfflineCache_Files\be1e893c-ed6d-4ac9-933e-dd5340e7c76f.png.WNCRYT
––
MD5:  ––
SHA256:  ––
3668
WANACRYPTOR.exe
C:\Users\admin\AppData\Local\Microsoft\OneNote\14.0\OneNoteOfflineCache_Files\bb4e150b-7e2a-4556-81dd-590d7ab07dda.png.WNCRYT
––
MD5:  ––
SHA256:  ––
3668
WANACRYPTOR.exe
C:\Users\admin\AppData\Local\Microsoft\OneNote\14.0\OneNoteOfflineCache_Files\b2a67a4a-c116-4c88-9fd1-c5b9a23d7929.png.WNCRYT
––
MD5:  ––
SHA256:  ––
3668
WANACRYPTOR.exe
C:\Users\admin\AppData\Local\Microsoft\OneNote\14.0\OneNoteOfflineCache_Files\b1503304-9b12-4d90-89e7-df30e304e6c2.png.WNCRY
binary
MD5: 70fa9e9ed1403938739f7edca7850b51
SHA256: efd6e73466bc2e8a1be774c8eaa9d4507a5e7d9ed3998f58f3c272816ee517d2
3668
WANACRYPTOR.exe
C:\Users\admin\AppData\Local\Microsoft\OneNote\14.0\OneNoteOfflineCache_Files\a9e6bb3f-0b62-4410-86f7-68bb36989df7.png.WNCRY
binary
MD5: ebc900cb9e6eca0451e4d1f9d3800723
SHA256: ef3d9eebf4fbd5bc51dd866665c0f65100fdaa85ec4091e06d4cfbb159d480b5
3668
WANACRYPTOR.exe
C:\Users\admin\AppData\Local\Microsoft\OneNote\14.0\OneNoteOfflineCache_Files\b1503304-9b12-4d90-89e7-df30e304e6c2.png.WNCRYT
––
MD5:  ––
SHA256:  ––
3668
WANACRYPTOR.exe
C:\Users\admin\AppData\Local\Microsoft\OneNote\14.0\OneNoteOfflineCache_Files\a9e6bb3f-0b62-4410-86f7-68bb36989df7.png.WNCRYT
––
MD5:  ––
SHA256:  ––
3668
WANACRYPTOR.exe
C:\Users\admin\AppData\Local\Microsoft\OneNote\14.0\OneNoteOfflineCache_Files\a6f0f9a9-e50d-4612-9e8e-f5640793680c.png.WNCRY
binary
MD5: 1c0c7cdaee349d3310fb5e7e5756aa0c
SHA256: cac19df923fcdea8d2e036eb1dac8c32db4acca79a43cd6bad90244db0f42a0f
3668
WANACRYPTOR.exe
C:\Users\admin\AppData\Local\Microsoft\OneNote\14.0\OneNoteOfflineCache_Files\a507cd65-0038-49e4-8cdb-b6082f566351.png.WNCRY
binary
MD5: 2ad0534d3ee2c51ce81019057ac952f1
SHA256: 789da0f5f9f3c7509304f6bbaa0333ed547e1cfb2e9d84355342451592e549dd
3668
WANACRYPTOR.exe
C:\Users\admin\AppData\Local\Microsoft\OneNote\14.0\OneNoteOfflineCache_Files\8339d228-5ca6-486f-8793-633aa6af18d8.png.WNCRY
binary
MD5: 6815822374a5aa2e5ba025599e304773
SHA256: 9662de30fe60c6ff38bb3bb36671e4e6cbecac785e9b95e40e9c9373f27658f8
3668
WANACRYPTOR.exe
C:\Users\admin\AppData\Local\Microsoft\OneNote\14.0\OneNoteOfflineCache_Files\a4fbc2bf-8cc2-4a6d-b3c7-0ef749399e7f.png.WNCRY
binary
MD5: bbe75a3c20c73439abb8d03bbf196c37
SHA256: 33c80139d803a4226bf1efd890a11f082c396abbd92071e9b24ad38154df2f5a
3668
WANACRYPTOR.exe
C:\Users\admin\AppData\Local\Microsoft\OneNote\14.0\OneNoteOfflineCache_Files\a4fbc2bf-8cc2-4a6d-b3c7-0ef749399e7f.png.WNCRYT
––
MD5:  ––
SHA256:  ––
3668
WANACRYPTOR.exe
C:\Users\admin\AppData\Local\Microsoft\OneNote\14.0\OneNoteOfflineCache_Files\a6f0f9a9-e50d-4612-9e8e-f5640793680c.png.WNCRYT
––
MD5:  ––
SHA256:  ––
3668
WANACRYPTOR.exe
C:\Users\admin\AppData\Local\Microsoft\OneNote\14.0\OneNoteOfflineCache_Files\a507cd65-0038-49e4-8cdb-b6082f566351.png.WNCRYT
––
MD5:  ––
SHA256:  ––
3668
WANACRYPTOR.exe
C:\Users\admin\AppData\Local\Microsoft\OneNote\14.0\OneNoteOfflineCache_Files\7dceec06-0991-43f4-8af3-601c0ebeb910.png.WNCRY
binary
MD5: a5cd5f47f06b1d4bf98b3b5b2e4df6eb
SHA256: 569579e595a9737459cf8e77148d44e88dde5a1017cf005027493a30a85a198e
3668
WANACRYPTOR.exe
C:\Users\admin\AppData\Local\Microsoft\OneNote\14.0\OneNoteOfflineCache_Files\7b168dd1-e39e-4b39-918c-53b9e78365e9.png.WNCRY
binary
MD5: 63f631f6d7fa0f453983e618745283aa
SHA256: ea28fb35916188e89373ce98e426ab25243770f569361bc99f2e82a81419179c
3668
WANACRYPTOR.exe
C:\Users\admin\AppData\Local\Microsoft\OneNote\14.0\OneNoteOfflineCache_Files\8339d228-5ca6-486f-8793-633aa6af18d8.png.WNCRYT
––
MD5:  ––
SHA256:  ––
3668
WANACRYPTOR.exe
C:\Users\admin\AppData\Local\Microsoft\OneNote\14.0\OneNoteOfflineCache_Files\7b168dd1-e39e-4b39-918c-53b9e78365e9.png.WNCRYT
––
MD5:  ––
SHA256:  ––
3668
WANACRYPTOR.exe
C:\Users\admin\AppData\Local\Microsoft\OneNote\14.0\OneNoteOfflineCache_Files\7dceec06-0991-43f4-8af3-601c0ebeb910.png.WNCRYT
––
MD5:  ––
SHA256:  ––
3668
WANACRYPTOR.exe
C:\Users\admin\AppData\Local\Microsoft\OneNote\14.0\OneNoteOfflineCache_Files\70c3a864-35fa-4245-802a-dbda1e3f4c00.png.WNCRY
binary
MD5: b9540136aa19a46333e9d7c6fe4e740c
SHA256: 89e6a51ff452a0155949dc1fb031fb38c196d004e5dd2b68bdfb6ae923a91c5d
3668
WANACRYPTOR.exe
C:\Users\admin\AppData\Local\Microsoft\OneNote\14.0\OneNoteOfflineCache_Files\79a073b8-0713-4166-af23-3272c394a92a.png.WNCRY
binary
MD5: f9f6694277a007181134a20b7390dd32
SHA256: d3c7730247aa8695d6d6a84898054d7c1555d22df224c4d5d76b907d6e679e0e
3668
WANACRYPTOR.exe
C:\Users\admin\AppData\Local\Microsoft\OneNote\14.0\OneNoteOfflineCache_Files\70d1f452-966e-4e28-8da5-8b2eeadbe078.png.WNCRY
binary
MD5: 66b09a1b4caa66112e79b0dc3e463674
SHA256: 2171fca93934486c71f0a6934e1b57496cb2958fe0c2745e8aa4da97a174193b
3668
WANACRYPTOR.exe
C:\Users\admin\AppData\Local\Microsoft\OneNote\14.0\OneNoteOfflineCache_Files\6d6e34b9-0e90-470c-ada3-2b00b4b8ffac.png.WNCRY
binary
MD5: 76ed4c018ee8e6a0393dab6706823e6c
SHA256: c8925412190748c9b70d31e6b46a4f28d1069fd608d0efc436141471b3846e1f
3668
WANACRYPTOR.exe
C:\Users\admin\AppData\Local\Microsoft\OneNote\14.0\OneNoteOfflineCache_Files\70c3a864-35fa-4245-802a-dbda1e3f4c00.png.WNCRYT
––
MD5:  ––
SHA256:  ––
3668
WANACRYPTOR.exe
C:\Users\admin\AppData\Local\Microsoft\OneNote\14.0\OneNoteOfflineCache_Files\70d1f452-966e-4e28-8da5-8b2eeadbe078.png.WNCRYT
––
MD5:  ––
SHA256:  ––
3668
WANACRYPTOR.exe
C:\Users\admin\AppData\Local\Microsoft\OneNote\14.0\OneNoteOfflineCache_Files\79a073b8-0713-4166-af23-3272c394a92a.png.WNCRYT
––
MD5:  ––
SHA256:  ––
3668
WANACRYPTOR.exe
C:\Users\admin\AppData\Local\Microsoft\OneNote\14.0\OneNoteOfflineCache_Files\6d6e34b9-0e90-470c-ada3-2b00b4b8ffac.png.WNCRYT
––
MD5:  ––
SHA256:  ––
3668
WANACRYPTOR.exe
C:\Users\admin\AppData\Local\Microsoft\OneNote\14.0\OneNoteOfflineCache_Files\62e3dfa2-4350-445b-8693-d1d04a74543c.png.WNCRY
binary
MD5: 3154b1a62d440d387050bb070d2850ec
SHA256: c5da018de33c9c8e6bd6e8021fe5a8d549186fbe78462d1df46358d6818f7d22
3668
WANACRYPTOR.exe
C:\Users\admin\AppData\Local\Microsoft\OneNote\14.0\OneNoteOfflineCache_Files\5394c05d-dc33-4d24-bd45-2d8954648f28.png.WNCRY
binary