Loading Joe Sandbox Report ...

Edit tour

Windows Analysis Report
Fast.exe

Overview

General Information

Sample name:Fast.exe
Analysis ID:1388428
MD5:ea6d3083f8c1c506fbff457bf09a7ed8
SHA1:f159c4fc7d13571e725f0ae9e0749c77cf859b4e
SHA256:000db71531e5aa8b30594d305bb3fbce8e2c71f66e2170091ef58b3c1f306f46
Tags:exephobosransomware
Infos:

Detection

Phobos
Score:100
Range:0 - 100
Whitelisted:false
Confidence:100%

Signatures

Antivirus / Scanner detection for submitted sample
Found ransom note / readme
Malicious sample detected (through community Yara rule)
Multi AV Scanner detection for dropped file
Multi AV Scanner detection for submitted file
Sigma detected: Delete shadow copy via WMIC
Yara detected Phobos
Creates files in the recycle bin to hide itself
Creates files inside the volume driver (system volume information)
Deletes shadow drive data (may be related to ransomware)
Deletes the backup plan of Windows
Drops PE files to the startup folder
Found evasive API chain (may stop execution after checking locale)
Infects executable files (exe, dll, sys, html)
Machine Learning detection for sample
May disable shadow drive data (uses vssadmin)
Modifies the windows firewall
Sigma detected: Shadow Copies Deletion Using Operating Systems Utilities
Uses bcdedit to modify the Windows boot settings
Uses netsh to modify the Windows network and firewall settings
Writes many files with high entropy
AV process strings found (often used to terminate AV products)
Abnormal high CPU Usage
Contains capabilities to detect virtual machines
Contains functionality to query locales information (e.g. system language)
Contains functionality which may be used to detect a debugger (GetProcessHeap)
Creates COM task schedule object (often to register a task for autostart)
Creates a process in suspended mode (likely to inject code)
Creates a start menu entry (Start Menu\Programs\Startup)
Creates files inside the system directory
Detected potential crypto function
Drops PE files
Drops PE files to the application program directory (C:\ProgramData)
Enables debug privileges
Enables security privileges
Found a high number of Window / User specific system calls (may be a loop to detect user behavior)
Found decision node followed by non-executed suspicious APIs
Found evasive API chain checking for process token information
Found large amount of non-executed APIs
May sleep (evasive loops) to hinder dynamic analysis
PE file contains sections with non-standard names
Queries the volume information (name, serial number etc) of a device
Sigma detected: CurrentVersion Autorun Keys Modification
Sigma detected: Startup Folder File Write
Sigma detected: Suspicious Process Patterns NTDS.DIT Exfil
Stores files to the Windows start menu directory
Tries to load missing DLLs
Uses 32bit PE files
Yara signature match

Classification

  • System is w10x64
  • Fast.exe (PID: 7608 cmdline: C:\Users\user\Desktop\Fast.exe MD5: EA6D3083F8C1C506FBFF457BF09A7ED8)
    • Fast.exe (PID: 7652 cmdline: C:\Users\user\Desktop\Fast.exe MD5: EA6D3083F8C1C506FBFF457BF09A7ED8)
    • cmd.exe (PID: 7756 cmdline: C:\Windows\system32\cmd.exe MD5: 8A2122E8162DBEF04694B9C3E0B6CDEE)
      • conhost.exe (PID: 7772 cmdline: C:\Windows\system32\conhost.exe 0xffffffff -ForceV1 MD5: 0D698AF330FD17BEE3BF90011D49251D)
      • vssadmin.exe (PID: 7924 cmdline: vssadmin delete shadows /all /quiet MD5: B58073DB8892B67A672906C9358020EC)
      • WMIC.exe (PID: 1196 cmdline: wmic shadowcopy delete MD5: C37F2F4F4B3CD128BDABCAEB2266A785)
      • bcdedit.exe (PID: 796 cmdline: bcdedit /set {default} bootstatuspolicy ignoreallfailures MD5: 74F7B84B0A547592CA63A00A8C4AD583)
      • bcdedit.exe (PID: 7372 cmdline: bcdedit /set {default} recoveryenabled no MD5: 74F7B84B0A547592CA63A00A8C4AD583)
      • wbadmin.exe (PID: 7820 cmdline: wbadmin delete catalog -quiet MD5: F2AA55885A2C014DA99F1355F3F71E4A)
    • cmd.exe (PID: 7764 cmdline: C:\Windows\system32\cmd.exe MD5: 8A2122E8162DBEF04694B9C3E0B6CDEE)
      • conhost.exe (PID: 7780 cmdline: C:\Windows\system32\conhost.exe 0xffffffff -ForceV1 MD5: 0D698AF330FD17BEE3BF90011D49251D)
      • netsh.exe (PID: 7932 cmdline: netsh advfirewall set currentprofile state off MD5: 6F1E6DD688818BC3D1391D0CC7D597EB)
      • netsh.exe (PID: 8036 cmdline: netsh firewall set opmode mode=disable MD5: 6F1E6DD688818BC3D1391D0CC7D597EB)
  • Fast.exe (PID: 4828 cmdline: "C:\Users\user\AppData\Local\Fast.exe" MD5: EA6D3083F8C1C506FBFF457BF09A7ED8)
  • Fast.exe (PID: 7332 cmdline: "C:\Users\user\AppData\Local\Fast.exe" MD5: EA6D3083F8C1C506FBFF457BF09A7ED8)
  • Fast.exe (PID: 2540 cmdline: "C:\Users\user\AppData\Local\Fast.exe" MD5: EA6D3083F8C1C506FBFF457BF09A7ED8)
  • wbengine.exe (PID: 3620 cmdline: C:\Windows\system32\wbengine.exe MD5: 17270A354A66590953C4AAC1CF54E507)
  • vdsldr.exe (PID: 7952 cmdline: C:\Windows\System32\vdsldr.exe -Embedding MD5: 472A05A6ADC167E9E5D2328AD98E3067)
  • vds.exe (PID: 8000 cmdline: C:\Windows\System32\vds.exe MD5: 0781CE7ECCD9F6318BA72CD96B5B8992)
  • Fast.exe (PID: 8060 cmdline: "C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Fast.exe" MD5: EA6D3083F8C1C506FBFF457BF09A7ED8)
  • cleanup
NameDescriptionAttributionBlogpost URLsLink
PhobosMalwareBytes states that Phobos is one of the ransomware families that are distributed via hacked Remote Desktop (RDP) connections. This isn't surprising, as hacked RDP servers are a cheap commodity on the underground market, and can make for an attractive and cost efficient dissemination vector for threat groups.No Attributionhttps://malpedia.caad.fkie.fraunhofer.de/details/win.phobos
No configs have been found
SourceRuleDescriptionAuthorStrings
Fast.exeWindows_Ransomware_Phobos_11ea7be5Identifies Phobos ransomwareunknown
  • 0x4bc:$b1: C0 74 30 33 C0 40 8B CE D3 E0 85 C7 74 19 66 8B 04 73 66 89
Fast.exeMALWARE_Win_PhobosDetects Phobos ransomwareditekshen
  • 0x8d98:$x1: \\?\UNC\\\e-
  • 0x8c24:$x2: \\?\ :
  • 0x8dc4:$x3: POST
  • 0x8dd0:$s1: ELVL
  • 0xa7:$s3: 41 31 47 49 41 2B
  • 0xaf:$s3: 41 31 47 7D 41 2B
  • 0xbf:$s3: 41 31 47 4A 41 2B
SourceRuleDescriptionAuthorStrings
00000002.00000002.4236920237.0000000000CA1000.00000020.00000001.01000000.00000003.sdmpWindows_Ransomware_Phobos_11ea7be5Identifies Phobos ransomwareunknown
  • 0xbc:$b1: C0 74 30 33 C0 40 8B CE D3 E0 85 C7 74 19 66 8B 04 73 66 89
00000013.00000002.2135391960.00000000000D1000.00000020.00000001.01000000.00000006.sdmpWindows_Ransomware_Phobos_11ea7be5Identifies Phobos ransomwareunknown
  • 0xbc:$b1: C0 74 30 33 C0 40 8B CE D3 E0 85 C7 74 19 66 8B 04 73 66 89
00000013.00000000.2125457686.00000000000D1000.00000020.00000001.01000000.00000006.sdmpWindows_Ransomware_Phobos_11ea7be5Identifies Phobos ransomwareunknown
  • 0xbc:$b1: C0 74 30 33 C0 40 8B CE D3 E0 85 C7 74 19 66 8B 04 73 66 89
00000000.00000000.1776137882.0000000000CA1000.00000020.00000001.01000000.00000003.sdmpWindows_Ransomware_Phobos_11ea7be5Identifies Phobos ransomwareunknown
  • 0xbc:$b1: C0 74 30 33 C0 40 8B CE D3 E0 85 C7 74 19 66 8B 04 73 66 89
0000000E.00000000.1940315719.00000000000D1000.00000020.00000001.01000000.00000006.sdmpWindows_Ransomware_Phobos_11ea7be5Identifies Phobos ransomwareunknown
  • 0xbc:$b1: C0 74 30 33 C0 40 8B CE D3 E0 85 C7 74 19 66 8B 04 73 66 89
Click to see the 10 entries
SourceRuleDescriptionAuthorStrings
14.0.Fast.exe.d0000.0.unpackWindows_Ransomware_Phobos_11ea7be5Identifies Phobos ransomwareunknown
  • 0x4bc:$b1: C0 74 30 33 C0 40 8B CE D3 E0 85 C7 74 19 66 8B 04 73 66 89
14.0.Fast.exe.d0000.0.unpackMALWARE_Win_PhobosDetects Phobos ransomwareditekshen
  • 0x8d98:$x1: \\?\UNC\\\e-
  • 0x8c24:$x2: \\?\ :
  • 0x8dc4:$x3: POST
  • 0x8dd0:$s1: ELVL
  • 0xa7:$s3: 41 31 47 49 41 2B
  • 0xaf:$s3: 41 31 47 7D 41 2B
  • 0xbf:$s3: 41 31 47 4A 41 2B
14.2.Fast.exe.d0000.0.unpackWindows_Ransomware_Phobos_11ea7be5Identifies Phobos ransomwareunknown
  • 0x4bc:$b1: C0 74 30 33 C0 40 8B CE D3 E0 85 C7 74 19 66 8B 04 73 66 89
14.2.Fast.exe.d0000.0.unpackMALWARE_Win_PhobosDetects Phobos ransomwareditekshen
  • 0x8d98:$x1: \\?\UNC\\\e-
  • 0x8c24:$x2: \\?\ :
  • 0x8dc4:$x3: POST
  • 0x8dd0:$s1: ELVL
  • 0xa7:$s3: 41 31 47 49 41 2B
  • 0xaf:$s3: 41 31 47 7D 41 2B
  • 0xbf:$s3: 41 31 47 4A 41 2B
19.2.Fast.exe.d0000.0.unpackWindows_Ransomware_Phobos_11ea7be5Identifies Phobos ransomwareunknown
  • 0x4bc:$b1: C0 74 30 33 C0 40 8B CE D3 E0 85 C7 74 19 66 8B 04 73 66 89
Click to see the 17 entries

Operating System Destruction

barindex
Source: Process startedAuthor: Joe Security: Data: Command: wmic shadowcopy delete, CommandLine: wmic shadowcopy delete, CommandLine|base64offset|contains: h, Image: C:\Windows\System32\wbem\WMIC.exe, NewProcessName: C:\Windows\System32\wbem\WMIC.exe, OriginalFileName: C:\Windows\System32\wbem\WMIC.exe, ParentCommandLine: C:\Windows\system32\cmd.exe, ParentImage: C:\Windows\System32\cmd.exe, ParentProcessId: 7756, ParentProcessName: cmd.exe, ProcessCommandLine: wmic shadowcopy delete, ProcessId: 1196, ProcessName: WMIC.exe

System Summary

barindex
Source: Process startedAuthor: Florian Roth (Nextron Systems), Michael Haag, Teymur Kheirkhabarov, Daniil Yugoslavskiy, oscd.community, Andreas Hunkeler (@Karneades): Data: Command: vssadmin delete shadows /all /quiet, CommandLine: vssadmin delete shadows /all /quiet, CommandLine|base64offset|contains: vh, Image: C:\Windows\System32\vssadmin.exe, NewProcessName: C:\Windows\System32\vssadmin.exe, OriginalFileName: C:\Windows\System32\vssadmin.exe, ParentCommandLine: C:\Windows\system32\cmd.exe, ParentImage: C:\Windows\System32\cmd.exe, ParentProcessId: 7756, ParentProcessName: cmd.exe, ProcessCommandLine: vssadmin delete shadows /all /quiet, ProcessId: 7924, ProcessName: vssadmin.exe
Source: Registry Key setAuthor: Victor Sergeev, Daniil Yugoslavskiy, Gleb Sukhodolskiy, Timur Zinniatullin, oscd.community, Tim Shelton, frack113 (split): Data: Details: C:\Users\user\AppData\Local\Fast.exe, EventID: 13, EventType: SetValue, Image: C:\Users\user\Desktop\Fast.exe, ProcessId: 7608, TargetObject: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\Fast
Source: File createdAuthor: Roberto Rodriguez (Cyb3rWard0g), OTR (Open Threat Research): Data: EventID: 11, Image: C:\Users\user\Desktop\Fast.exe, ProcessId: 7608, TargetFilename: c:\users\user\appdata\roaming\microsoft\windows\start menu\programs\startup\Fast.exe
Source: Process startedAuthor: Florian Roth (Nextron Systems): Data: Command: "C:\Users\user\AppData\Local\Fast.exe" , CommandLine: "C:\Users\user\AppData\Local\Fast.exe" , CommandLine|base64offset|contains: , Image: C:\Users\user\AppData\Local\Fast.exe, NewProcessName: C:\Users\user\AppData\Local\Fast.exe, OriginalFileName: C:\Users\user\AppData\Local\Fast.exe, ParentCommandLine: , ParentImage: , ParentProcessId: 2580, ProcessCommandLine: "C:\Users\user\AppData\Local\Fast.exe" , ProcessId: 4828, ProcessName: Fast.exe
No Snort rule has matched

Click to jump to signature section

Show All Signature Results

AV Detection

barindex
Source: Fast.exeAvira: detected
Source: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\StartUp\Fast.exeReversingLabs: Detection: 89%
Source: C:\Users\user\AppData\Local\Fast.exeReversingLabs: Detection: 89%
Source: C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Fast.exeReversingLabs: Detection: 89%
Source: Fast.exeReversingLabs: Detection: 89%
Source: Fast.exeJoe Sandbox ML: detected
Source: Fast.exeStatic PE information: EXECUTABLE_IMAGE, 32BIT_MACHINE
Source: C:\Users\user\Desktop\Fast.exeDirectory created: C:\Program Files\7-Zip\7-zip.chm.id[9AA40F17-2803].[HenryShrapnel61@gmx.com].eightJump to behavior
Source: C:\Users\user\Desktop\Fast.exeDirectory created: C:\Program Files\7-Zip\7-zip.dll.id[9AA40F17-2803].[HenryShrapnel61@gmx.com].eightJump to behavior
Source: C:\Users\user\Desktop\Fast.exeDirectory created: C:\Program Files\7-Zip\7-zip32.dll.id[9AA40F17-2803].[HenryShrapnel61@gmx.com].eightJump to behavior
Source: C:\Users\user\Desktop\Fast.exeDirectory created: C:\Program Files\7-Zip\7z.exe.id[9AA40F17-2803].[HenryShrapnel61@gmx.com].eightJump to behavior
Source: C:\Users\user\Desktop\Fast.exeDirectory created: C:\Program Files\7-Zip\7z.sfx.id[9AA40F17-2803].[HenryShrapnel61@gmx.com].eightJump to behavior
Source: C:\Users\user\Desktop\Fast.exeDirectory created: C:\Program Files\7-Zip\7zCon.sfx.id[9AA40F17-2803].[HenryShrapnel61@gmx.com].eightJump to behavior
Source: C:\Users\user\Desktop\Fast.exeDirectory created: C:\Program Files\7-Zip\7zFM.exe.id[9AA40F17-2803].[HenryShrapnel61@gmx.com].eightJump to behavior
Source: C:\Users\user\Desktop\Fast.exeDirectory created: C:\Program Files\7-Zip\7zG.exe.id[9AA40F17-2803].[HenryShrapnel61@gmx.com].eightJump to behavior
Source: C:\Users\user\Desktop\Fast.exeDirectory created: C:\Program Files\7-Zip\descript.ion.id[9AA40F17-2803].[HenryShrapnel61@gmx.com].eightJump to behavior
Source: C:\Users\user\Desktop\Fast.exeDirectory created: C:\Program Files\7-Zip\History.txt.id[9AA40F17-2803].[HenryShrapnel61@gmx.com].eightJump to behavior
Source: C:\Users\user\Desktop\Fast.exeDirectory created: C:\Program Files\7-Zip\Lang\af.txt.id[9AA40F17-2803].[HenryShrapnel61@gmx.com].eightJump to behavior
Source: C:\Users\user\Desktop\Fast.exeDirectory created: C:\Program Files\7-Zip\Lang\an.txt.id[9AA40F17-2803].[HenryShrapnel61@gmx.com].eightJump to behavior
Source: C:\Users\user\Desktop\Fast.exeDirectory created: C:\Program Files\7-Zip\Lang\ar.txt.id[9AA40F17-2803].[HenryShrapnel61@gmx.com].eightJump to behavior
Source: C:\Users\user\Desktop\Fast.exeDirectory created: C:\Program Files\7-Zip\Lang\ast.txt.id[9AA40F17-2803].[HenryShrapnel61@gmx.com].eightJump to behavior
Source: C:\Users\user\Desktop\Fast.exeDirectory created: C:\Program Files\7-Zip\Lang\az.txt.id[9AA40F17-2803].[HenryShrapnel61@gmx.com].eightJump to behavior
Source: C:\Users\user\Desktop\Fast.exeDirectory created: C:\Program Files\7-Zip\Lang\ba.txt.id[9AA40F17-2803].[HenryShrapnel61@gmx.com].eightJump to behavior
Source: C:\Users\user\Desktop\Fast.exeDirectory created: C:\Program Files\7-Zip\Lang\be.txt.id[9AA40F17-2803].[HenryShrapnel61@gmx.com].eightJump to behavior
Source: C:\Users\user\Desktop\Fast.exeDirectory created: C:\Program Files\7-Zip\Lang\bg.txt.id[9AA40F17-2803].[HenryShrapnel61@gmx.com].eightJump to behavior
Source: C:\Users\user\Desktop\Fast.exeDirectory created: C:\Program Files\7-Zip\Lang\bn.txt.id[9AA40F17-2803].[HenryShrapnel61@gmx.com].eightJump to behavior
Source: C:\Users\user\Desktop\Fast.exeDirectory created: C:\Program Files\7-Zip\Lang\br.txt.id[9AA40F17-2803].[HenryShrapnel61@gmx.com].eightJump to behavior
Source: C:\Users\user\Desktop\Fast.exeDirectory created: C:\Program Files\7-Zip\Lang\ca.txt.id[9AA40F17-2803].[HenryShrapnel61@gmx.com].eightJump to behavior
Source: C:\Users\user\Desktop\Fast.exeDirectory created: C:\Program Files\7-Zip\Lang\co.txt.id[9AA40F17-2803].[HenryShrapnel61@gmx.com].eightJump to behavior
Source: C:\Users\user\Desktop\Fast.exeDirectory created: C:\Program Files\7-Zip\Lang\cs.txt.id[9AA40F17-2803].[HenryShrapnel61@gmx.com].eightJump to behavior
Source: C:\Users\user\Desktop\Fast.exeDirectory created: C:\Program Files\7-Zip\Lang\cy.txt.id[9AA40F17-2803].[HenryShrapnel61@gmx.com].eightJump to behavior
Source: C:\Users\user\Desktop\Fast.exeDirectory created: C:\Program Files\7-Zip\Lang\de.txt.id[9AA40F17-2803].[HenryShrapnel61@gmx.com].eightJump to behavior
Source: C:\Users\user\Desktop\Fast.exeDirectory created: C:\Program Files\7-Zip\Lang\da.txt.id[9AA40F17-2803].[HenryShrapnel61@gmx.com].eightJump to behavior
Source: C:\Users\user\Desktop\Fast.exeDirectory created: C:\Program Files\7-Zip\Lang\el.txt.id[9AA40F17-2803].[HenryShrapnel61@gmx.com].eightJump to behavior
Source: C:\Users\user\Desktop\Fast.exeDirectory created: C:\Program Files\7-Zip\Lang\en.ttt.id[9AA40F17-2803].[HenryShrapnel61@gmx.com].eightJump to behavior
Source: C:\Users\user\Desktop\Fast.exeDirectory created: C:\Program Files\7-Zip\Lang\eo.txt.id[9AA40F17-2803].[HenryShrapnel61@gmx.com].eightJump to behavior
Source: C:\Users\user\Desktop\Fast.exeDirectory created: C:\Program Files\7-Zip\Lang\es.txt.id[9AA40F17-2803].[HenryShrapnel61@gmx.com].eightJump to behavior
Source: C:\Users\user\Desktop\Fast.exeDirectory created: C:\Program Files\7-Zip\Lang\et.txt.id[9AA40F17-2803].[HenryShrapnel61@gmx.com].eightJump to behavior
Source: C:\Users\user\Desktop\Fast.exeDirectory created: C:\Program Files\7-Zip\Lang\eu.txt.id[9AA40F17-2803].[HenryShrapnel61@gmx.com].eightJump to behavior
Source: C:\Users\user\Desktop\Fast.exeDirectory created: C:\Program Files\7-Zip\Lang\ext.txt.id[9AA40F17-2803].[HenryShrapnel61@gmx.com].eightJump to behavior
Source: C:\Users\user\Desktop\Fast.exeDirectory created: C:\Program Files\7-Zip\Lang\fa.txt.id[9AA40F17-2803].[HenryShrapnel61@gmx.com].eightJump to behavior
Source: C:\Users\user\Desktop\Fast.exeDirectory created: C:\Program Files\7-Zip\Lang\fi.txt.id[9AA40F17-2803].[HenryShrapnel61@gmx.com].eightJump to behavior
Source: C:\Users\user\Desktop\Fast.exeDirectory created: C:\Program Files\7-Zip\Lang\fr.txt.id[9AA40F17-2803].[HenryShrapnel61@gmx.com].eightJump to behavior
Source: C:\Users\user\Desktop\Fast.exeDirectory created: C:\Program Files\7-Zip\Lang\fur.txt.id[9AA40F17-2803].[HenryShrapnel61@gmx.com].eightJump to behavior
Source: C:\Users\user\Desktop\Fast.exeDirectory created: C:\Program Files\7-Zip\Lang\fy.txt.id[9AA40F17-2803].[HenryShrapnel61@gmx.com].eightJump to behavior
Source: C:\Users\user\Desktop\Fast.exeDirectory created: C:\Program Files\7-Zip\Lang\ga.txt.id[9AA40F17-2803].[HenryShrapnel61@gmx.com].eightJump to behavior
Source: C:\Users\user\Desktop\Fast.exeDirectory created: C:\Program Files\7-Zip\Lang\gl.txt.id[9AA40F17-2803].[HenryShrapnel61@gmx.com].eightJump to behavior
Source: C:\Users\user\Desktop\Fast.exeDirectory created: C:\Program Files\7-Zip\Lang\gu.txt.id[9AA40F17-2803].[HenryShrapnel61@gmx.com].eightJump to behavior
Source: C:\Users\user\Desktop\Fast.exeDirectory created: C:\Program Files\7-Zip\Lang\he.txt.id[9AA40F17-2803].[HenryShrapnel61@gmx.com].eightJump to behavior
Source: C:\Users\user\Desktop\Fast.exeDirectory created: C:\Program Files\7-Zip\Lang\hi.txt.id[9AA40F17-2803].[HenryShrapnel61@gmx.com].eightJump to behavior
Source: C:\Users\user\Desktop\Fast.exeDirectory created: C:\Program Files\7-Zip\Lang\hr.txt.id[9AA40F17-2803].[HenryShrapnel61@gmx.com].eightJump to behavior
Source: C:\Users\user\Desktop\Fast.exeDirectory created: C:\Program Files\7-Zip\Lang\hu.txt.id[9AA40F17-2803].[HenryShrapnel61@gmx.com].eightJump to behavior
Source: C:\Users\user\Desktop\Fast.exeDirectory created: C:\Program Files\7-Zip\Lang\hy.txt.id[9AA40F17-2803].[HenryShrapnel61@gmx.com].eightJump to behavior
Source: C:\Users\user\Desktop\Fast.exeDirectory created: C:\Program Files\7-Zip\Lang\id.txt.id[9AA40F17-2803].[HenryShrapnel61@gmx.com].eightJump to behavior
Source: C:\Users\user\Desktop\Fast.exeDirectory created: C:\Program Files\7-Zip\Lang\io.txt.id[9AA40F17-2803].[HenryShrapnel61@gmx.com].eightJump to behavior
Source: C:\Users\user\Desktop\Fast.exeDirectory created: C:\Program Files\7-Zip\Lang\is.txt.id[9AA40F17-2803].[HenryShrapnel61@gmx.com].eightJump to behavior
Source: C:\Users\user\Desktop\Fast.exeDirectory created: C:\Program Files\7-Zip\Lang\it.txt.id[9AA40F17-2803].[HenryShrapnel61@gmx.com].eightJump to behavior
Source: C:\Users\user\Desktop\Fast.exeDirectory created: C:\Program Files\7-Zip\Lang\ja.txt.id[9AA40F17-2803].[HenryShrapnel61@gmx.com].eightJump to behavior
Source: C:\Users\user\Desktop\Fast.exeDirectory created: C:\Program Files\7-Zip\Lang\ka.txt.id[9AA40F17-2803].[HenryShrapnel61@gmx.com].eightJump to behavior
Source: C:\Users\user\Desktop\Fast.exeDirectory created: C:\Program Files\7-Zip\Lang\kab.txt.id[9AA40F17-2803].[HenryShrapnel61@gmx.com].eightJump to behavior
Source: C:\Users\user\Desktop\Fast.exeDirectory created: C:\Program Files\7-Zip\Lang\kaa.txt.id[9AA40F17-2803].[HenryShrapnel61@gmx.com].eightJump to behavior
Source: C:\Users\user\Desktop\Fast.exeDirectory created: C:\Program Files\7-Zip\Lang\kk.txt.id[9AA40F17-2803].[HenryShrapnel61@gmx.com].eightJump to behavior
Source: C:\Users\user\Desktop\Fast.exeDirectory created: C:\Program Files\7-Zip\Lang\ko.txt.id[9AA40F17-2803].[HenryShrapnel61@gmx.com].eightJump to behavior
Source: C:\Users\user\Desktop\Fast.exeDirectory created: C:\Program Files\7-Zip\Lang\ku-ckb.txt.id[9AA40F17-2803].[HenryShrapnel61@gmx.com].eightJump to behavior
Source: C:\Users\user\Desktop\Fast.exeDirectory created: C:\Program Files\7-Zip\Lang\ku.txt.id[9AA40F17-2803].[HenryShrapnel61@gmx.com].eightJump to behavior
Source: C:\Users\user\Desktop\Fast.exeDirectory created: C:\Program Files\7-Zip\Lang\ky.txt.id[9AA40F17-2803].[HenryShrapnel61@gmx.com].eightJump to behavior
Source: C:\Users\user\Desktop\Fast.exeDirectory created: C:\Program Files\7-Zip\Lang\lij.txt.id[9AA40F17-2803].[HenryShrapnel61@gmx.com].eightJump to behavior
Source: C:\Users\user\Desktop\Fast.exeDirectory created: C:\Program Files\7-Zip\Lang\lt.txt.id[9AA40F17-2803].[HenryShrapnel61@gmx.com].eightJump to behavior
Source: C:\Users\user\Desktop\Fast.exeDirectory created: C:\Program Files\7-Zip\Lang\lv.txt.id[9AA40F17-2803].[HenryShrapnel61@gmx.com].eightJump to behavior
Source: C:\Users\user\Desktop\Fast.exeDirectory created: C:\Program Files\7-Zip\Lang\mk.txt.id[9AA40F17-2803].[HenryShrapnel61@gmx.com].eightJump to behavior
Source: C:\Users\user\Desktop\Fast.exeDirectory created: C:\Program Files\7-Zip\Lang\mn.txt.id[9AA40F17-2803].[HenryShrapnel61@gmx.com].eightJump to behavior
Source: C:\Users\user\Desktop\Fast.exeDirectory created: C:\Program Files\7-Zip\Lang\mng.txt.id[9AA40F17-2803].[HenryShrapnel61@gmx.com].eightJump to behavior
Source: C:\Users\user\Desktop\Fast.exeDirectory created: C:\Program Files\7-Zip\Lang\mng2.txt.id[9AA40F17-2803].[HenryShrapnel61@gmx.com].eightJump to behavior
Source: C:\Users\user\Desktop\Fast.exeDirectory created: C:\Program Files\7-Zip\Lang\mr.txt.id[9AA40F17-2803].[HenryShrapnel61@gmx.com].eightJump to behavior
Source: C:\Users\user\Desktop\Fast.exeDirectory created: C:\Program Files\7-Zip\Lang\ms.txt.id[9AA40F17-2803].[HenryShrapnel61@gmx.com].eightJump to behavior
Source: C:\Users\user\Desktop\Fast.exeDirectory created: C:\Program Files\7-Zip\Lang\nb.txt.id[9AA40F17-2803].[HenryShrapnel61@gmx.com].eightJump to behavior
Source: C:\Users\user\Desktop\Fast.exeDirectory created: C:\Program Files\7-Zip\Lang\ne.txt.id[9AA40F17-2803].[HenryShrapnel61@gmx.com].eightJump to behavior
Source: C:\Users\user\Desktop\Fast.exeDirectory created: C:\Program Files\7-Zip\Lang\nl.txt.id[9AA40F17-2803].[HenryShrapnel61@gmx.com].eightJump to behavior
Source: C:\Users\user\Desktop\Fast.exeDirectory created: C:\Program Files\7-Zip\Lang\nn.txt.id[9AA40F17-2803].[HenryShrapnel61@gmx.com].eightJump to behavior
Source: C:\Users\user\Desktop\Fast.exeDirectory created: C:\Program Files\7-Zip\Lang\pa-in.txt.id[9AA40F17-2803].[HenryShrapnel61@gmx.com].eightJump to behavior
Source: C:\Users\user\Desktop\Fast.exeDirectory created: C:\Program Files\7-Zip\Lang\pl.txt.id[9AA40F17-2803].[HenryShrapnel61@gmx.com].eightJump to behavior
Source: C:\Users\user\Desktop\Fast.exeDirectory created: C:\Program Files\7-Zip\Lang\ps.txt.id[9AA40F17-2803].[HenryShrapnel61@gmx.com].eightJump to behavior
Source: C:\Users\user\Desktop\Fast.exeDirectory created: C:\Program Files\7-Zip\Lang\pt-br.txt.id[9AA40F17-2803].[HenryShrapnel61@gmx.com].eightJump to behavior
Source: C:\Users\user\Desktop\Fast.exeDirectory created: C:\Program Files\7-Zip\Lang\pt.txt.id[9AA40F17-2803].[HenryShrapnel61@gmx.com].eightJump to behavior
Source: C:\Users\user\Desktop\Fast.exeDirectory created: C:\Program Files\7-Zip\Lang\ro.txt.id[9AA40F17-2803].[HenryShrapnel61@gmx.com].eightJump to behavior
Source: C:\Users\user\Desktop\Fast.exeDirectory created: C:\Program Files\7-Zip\Lang\ru.txt.id[9AA40F17-2803].[HenryShrapnel61@gmx.com].eightJump to behavior
Source: C:\Users\user\Desktop\Fast.exeDirectory created: C:\Program Files\7-Zip\Lang\sa.txt.id[9AA40F17-2803].[HenryShrapnel61@gmx.com].eightJump to behavior
Source: C:\Users\user\Desktop\Fast.exeDirectory created: C:\Program Files\7-Zip\Lang\si.txt.id[9AA40F17-2803].[HenryShrapnel61@gmx.com].eightJump to behavior
Source: C:\Users\user\Desktop\Fast.exeDirectory created: C:\Program Files\7-Zip\Lang\sk.txt.id[9AA40F17-2803].[HenryShrapnel61@gmx.com].eightJump to behavior
Source: C:\Users\user\Desktop\Fast.exeDirectory created: C:\Program Files\7-Zip\Lang\sl.txt.id[9AA40F17-2803].[HenryShrapnel61@gmx.com].eightJump to behavior
Source: C:\Users\user\Desktop\Fast.exeDirectory created: C:\Program Files\7-Zip\Lang\sq.txt.id[9AA40F17-2803].[HenryShrapnel61@gmx.com].eightJump to behavior
Source: C:\Users\user\Desktop\Fast.exeDirectory created: C:\Program Files\7-Zip\Lang\sr-spc.txt.id[9AA40F17-2803].[HenryShrapnel61@gmx.com].eightJump to behavior
Source: C:\Users\user\Desktop\Fast.exeDirectory created: C:\Program Files\7-Zip\Lang\sr-spl.txt.id[9AA40F17-2803].[HenryShrapnel61@gmx.com].eightJump to behavior
Source: C:\Users\user\Desktop\Fast.exeDirectory created: C:\Program Files\7-Zip\Lang\sv.txt.id[9AA40F17-2803].[HenryShrapnel61@gmx.com].eightJump to behavior
Source: C:\Users\user\Desktop\Fast.exeDirectory created: C:\Program Files\7-Zip\Lang\sw.txt.id[9AA40F17-2803].[HenryShrapnel61@gmx.com].eightJump to behavior
Source: C:\Users\user\Desktop\Fast.exeDirectory created: C:\Program Files\7-Zip\Lang\ta.txt.id[9AA40F17-2803].[HenryShrapnel61@gmx.com].eightJump to behavior
Source: C:\Users\user\Desktop\Fast.exeDirectory created: C:\Program Files\7-Zip\Lang\tg.txt.id[9AA40F17-2803].[HenryShrapnel61@gmx.com].eightJump to behavior
Source: C:\Users\user\Desktop\Fast.exeDirectory created: C:\Program Files\7-Zip\Lang\th.txt.id[9AA40F17-2803].[HenryShrapnel61@gmx.com].eightJump to behavior
Source: C:\Users\user\Desktop\Fast.exeDirectory created: C:\Program Files\7-Zip\Lang\tk.txt.id[9AA40F17-2803].[HenryShrapnel61@gmx.com].eightJump to behavior
Source: C:\Users\user\Desktop\Fast.exeDirectory created: C:\Program Files\7-Zip\Lang\tr.txt.id[9AA40F17-2803].[HenryShrapnel61@gmx.com].eightJump to behavior
Source: C:\Users\user\Desktop\Fast.exeDirectory created: C:\Program Files\7-Zip\Lang\tt.txt.id[9AA40F17-2803].[HenryShrapnel61@gmx.com].eightJump to behavior
Source: C:\Users\user\Desktop\Fast.exeDirectory created: C:\Program Files\7-Zip\Lang\ug.txt.id[9AA40F17-2803].[HenryShrapnel61@gmx.com].eightJump to behavior
Source: C:\Users\user\Desktop\Fast.exeDirectory created: C:\Program Files\7-Zip\Lang\uk.txt.id[9AA40F17-2803].[HenryShrapnel61@gmx.com].eightJump to behavior
Source: C:\Users\user\Desktop\Fast.exeDirectory created: C:\Program Files\7-Zip\Lang\uz-cyrl.txt.id[9AA40F17-2803].[HenryShrapnel61@gmx.com].eightJump to behavior
Source: C:\Users\user\Desktop\Fast.exeDirectory created: C:\Program Files\7-Zip\Lang\uz.txt.id[9AA40F17-2803].[HenryShrapnel61@gmx.com].eightJump to behavior
Source: C:\Users\user\Desktop\Fast.exeDirectory created: C:\Program Files\7-Zip\Lang\va.txt.id[9AA40F17-2803].[HenryShrapnel61@gmx.com].eightJump to behavior
Source: C:\Users\user\Desktop\Fast.exeDirectory created: C:\Program Files\7-Zip\Lang\vi.txt.id[9AA40F17-2803].[HenryShrapnel61@gmx.com].eightJump to behavior
Source: C:\Users\user\Desktop\Fast.exeDirectory created: C:\Program Files\7-Zip\Lang\yo.txt.id[9AA40F17-2803].[HenryShrapnel61@gmx.com].eightJump to behavior
Source: C:\Users\user\Desktop\Fast.exeDirectory created: C:\Program Files\7-Zip\Lang\zh-cn.txt.id[9AA40F17-2803].[HenryShrapnel61@gmx.com].eightJump to behavior
Source: C:\Users\user\Desktop\Fast.exeDirectory created: C:\Program Files\7-Zip\Lang\zh-tw.txt.id[9AA40F17-2803].[HenryShrapnel61@gmx.com].eightJump to behavior
Source: C:\Users\user\Desktop\Fast.exeDirectory created: C:\Program Files\7-Zip\License.txt.id[9AA40F17-2803].[HenryShrapnel61@gmx.com].eightJump to behavior
Source: C:\Users\user\Desktop\Fast.exeDirectory created: C:\Program Files\7-Zip\readme.txt.id[9AA40F17-2803].[HenryShrapnel61@gmx.com].eightJump to behavior
Source: C:\Users\user\Desktop\Fast.exeDirectory created: C:\Program Files\7-Zip\Uninstall.exe.id[9AA40F17-2803].[HenryShrapnel61@gmx.com].eightJump to behavior
Source: C:\Users\user\Desktop\Fast.exeDirectory created: C:\Program Files\Adobe\Acrobat DC\Acrobat\A3DUtils.dll.id[9AA40F17-2803].[HenryShrapnel61@gmx.com].eightJump to behavior
Source: C:\Users\user\Desktop\Fast.exeDirectory created: C:\Program Files\Adobe\Acrobat DC\Acrobat\1494870C-9912-C184-4CC9-B401-A53F4D8DE290.pdf.id[9AA40F17-2803].[HenryShrapnel61@gmx.com].eightJump to behavior
Source: C:\Users\user\Desktop\Fast.exeDirectory created: C:\Program Files\Adobe\Acrobat DC\Acrobat\ACE.dll.id[9AA40F17-2803].[HenryShrapnel61@gmx.com].eightJump to behavior
Source: C:\Users\user\Desktop\Fast.exeDirectory created: C:\Program Files\Adobe\Acrobat DC\Acrobat\acrobat.tlb.id[9AA40F17-2803].[HenryShrapnel61@gmx.com].eightJump to behavior
Source: C:\Users\user\Desktop\Fast.exeDirectory created: C:\Program Files\Adobe\Acrobat DC\Acrobat\AcrobatInfo.exe.id[9AA40F17-2803].[HenryShrapnel61@gmx.com].eightJump to behavior
Source: C:\Users\user\Desktop\Fast.exeDirectory created: C:\Program Files\Adobe\Acrobat DC\Acrobat\acrobat_reader_appicon_16.png.id[9AA40F17-2803].[HenryShrapnel61@gmx.com].eightJump to behavior
Source: C:\Users\user\Desktop\Fast.exeDirectory created: C:\Program Files\Adobe\Acrobat DC\Acrobat\acrobat_sl.exe.id[9AA40F17-2803].[HenryShrapnel61@gmx.com].eightJump to behavior
Source: C:\Users\user\Desktop\Fast.exeDirectory created: C:\Program Files\Adobe\Acrobat DC\Acrobat\AcroBroker.exe.id[9AA40F17-2803].[HenryShrapnel61@gmx.com].eightJump to behavior
Source: C:\Users\user\Desktop\Fast.exeDirectory created: C:\Program Files\Adobe\Acrobat DC\Acrobat\AcroCEF\chrome_100_percent.pak.id[9AA40F17-2803].[HenryShrapnel61@gmx.com].eightJump to behavior
Source: C:\Users\user\Desktop\Fast.exeDirectory created: C:\Program Files\Adobe\Acrobat DC\Acrobat\AcroCEF\chrome_200_percent.pak.id[9AA40F17-2803].[HenryShrapnel61@gmx.com].eightJump to behavior
Source: C:\Users\user\Desktop\Fast.exeDirectory created: C:\Program Files\Adobe\Acrobat DC\Acrobat\AcroCEF\chrome_elf.dll.id[9AA40F17-2803].[HenryShrapnel61@gmx.com].eightJump to behavior
Source: C:\Users\user\Desktop\Fast.exeDirectory created: C:\Program Files\Adobe\Acrobat DC\Acrobat\AcroCEF\COPYING.LGPLv2.1.txt.id[9AA40F17-2803].[HenryShrapnel61@gmx.com].eightJump to behavior
Source: C:\Users\user\Desktop\Fast.exeDirectory created: C:\Program Files\Adobe\Acrobat DC\Acrobat\AcroCEF\LICENSE.txt.id[9AA40F17-2803].[HenryShrapnel61@gmx.com].eightJump to behavior
Source: C:\Users\user\Desktop\Fast.exeDirectory created: C:\Program Files\Adobe\Acrobat DC\Acrobat\AcroCEF\locales\en-US.pak.id[9AA40F17-2803].[HenryShrapnel61@gmx.com].eightJump to behavior
Source: C:\Users\user\Desktop\Fast.exeDirectory created: C:\Program Files\Adobe\Acrobat DC\Acrobat\AcroCEF\snapshot_blob.bin.id[9AA40F17-2803].[HenryShrapnel61@gmx.com].eightJump to behavior
Source: C:\Users\user\Desktop\Fast.exeDirectory created: C:\Program Files\Adobe\Acrobat DC\Acrobat\AcroCEF\swiftshader\libEGL.dll.id[9AA40F17-2803].[HenryShrapnel61@gmx.com].eightJump to behavior
Source: C:\Users\user\Desktop\Fast.exeDirectory created: C:\Program Files\Adobe\Acrobat DC\Acrobat\AcroCEF\swiftshader\libGLESv2.dll.id[9AA40F17-2803].[HenryShrapnel61@gmx.com].eightJump to behavior
Source: C:\Users\user\Desktop\Fast.exeDirectory created: C:\Program Files\Adobe\Acrobat DC\Acrobat\AcroCEF\v8_context_snapshot.bin.id[9AA40F17-2803].[HenryShrapnel61@gmx.com].eightJump to behavior
Source: C:\Users\user\Desktop\Fast.exeDirectory created: C:\Program Files\Adobe\Acrobat DC\Acrobat\AcroCEF\vk_swiftshader_icd.json.id[9AA40F17-2803].[HenryShrapnel61@gmx.com].eightJump to behavior
Source: C:\Users\user\Desktop\Fast.exeDirectory created: C:\Program Files\Adobe\Acrobat DC\Acrobat\AcroCEF\vulkan-1.dll.id[9AA40F17-2803].[HenryShrapnel61@gmx.com].eightJump to behavior
Source: C:\Users\user\Desktop\Fast.exeDirectory created: C:\Program Files\Adobe\Acrobat DC\Acrobat\acrocef_1\chrome_100_percent.pak.id[9AA40F17-2803].[HenryShrapnel61@gmx.com].eightJump to behavior
Source: C:\Users\user\Desktop\Fast.exeDirectory created: C:\Program Files\Adobe\Acrobat DC\Acrobat\acrocef_1\chrome_200_percent.pak.id[9AA40F17-2803].[HenryShrapnel61@gmx.com].eightJump to behavior
Source: C:\Users\user\Desktop\Fast.exeDirectory created: C:\Program Files\Adobe\Acrobat DC\Acrobat\acrocef_1\chrome_elf.dll.id[9AA40F17-2803].[HenryShrapnel61@gmx.com].eightJump to behavior
Source: C:\Users\user\Desktop\Fast.exeDirectory created: C:\Program Files\Adobe\Acrobat DC\Acrobat\acrocef_1\COPYING.LGPLv2.1.txt.id[9AA40F17-2803].[HenryShrapnel61@gmx.com].eightJump to behavior
Source: C:\Users\user\Desktop\Fast.exeDirectory created: C:\Program Files\Adobe\Acrobat DC\Acrobat\acrocef_1\LICENSE.txt.id[9AA40F17-2803].[HenryShrapnel61@gmx.com].eightJump to behavior
Source: C:\Users\user\Desktop\Fast.exeDirectory created: C:\Program Files\Adobe\Acrobat DC\Acrobat\acrocef_1\locales\en-US.pak.id[9AA40F17-2803].[HenryShrapnel61@gmx.com].eightJump to behavior
Source: C:\Users\user\Desktop\Fast.exeDirectory created: C:\Program Files\Adobe\Acrobat DC\Acrobat\acrocef_1\snapshot_blob.bin.id[9AA40F17-2803].[HenryShrapnel61@gmx.com].eightJump to behavior
Source: C:\Users\user\Desktop\Fast.exeDirectory created: C:\Program Files\Adobe\Acrobat DC\Acrobat\acrocef_1\swiftshader\libEGL.dll.id[9AA40F17-2803].[HenryShrapnel61@gmx.com].eightJump to behavior
Source: C:\Users\user\Desktop\Fast.exeDirectory created: C:\Program Files\Adobe\Acrobat DC\Acrobat\acrocef_1\swiftshader\libGLESv2.dll.id[9AA40F17-2803].[HenryShrapnel61@gmx.com].eightJump to behavior
Source: C:\Users\user\Desktop\Fast.exeDirectory created: C:\Program Files\Adobe\Acrobat DC\Acrobat\acrocef_1\v8_context_snapshot.bin.id[9AA40F17-2803].[HenryShrapnel61@gmx.com].eightJump to behavior
Source: C:\Users\user\Desktop\Fast.exeDirectory created: C:\Program Files\Adobe\Acrobat DC\Acrobat\acrocef_1\vk_swiftshader_icd.json.id[9AA40F17-2803].[HenryShrapnel61@gmx.com].eightJump to behavior
Source: C:\Users\user\Desktop\Fast.exeDirectory created: C:\Program Files\Adobe\Acrobat DC\Acrobat\AcroDunamis.dll.id[9AA40F17-2803].[HenryShrapnel61@gmx.com].eightJump to behavior
Source: C:\Users\user\Desktop\Fast.exeDirectory created: C:\Program Files\Adobe\Acrobat DC\Acrobat\acrocef_1\vulkan-1.dll.id[9AA40F17-2803].[HenryShrapnel61@gmx.com].eightJump to behavior
Source: C:\Users\user\Desktop\Fast.exeDirectory created: C:\Program Files\Adobe\Acrobat DC\Acrobat\AcroTextExtractor.exe.id[9AA40F17-2803].[HenryShrapnel61@gmx.com].eightJump to behavior
Source: C:\Users\user\Desktop\Fast.exeDirectory created: C:\Program Files\Adobe\Acrobat DC\Acrobat\ADNotificationManager.exe.id[9AA40F17-2803].[HenryShrapnel61@gmx.com].eightJump to behavior
Source: C:\Users\user\Desktop\Fast.exeDirectory created: C:\Program Files\Adobe\Acrobat DC\Acrobat\ADelRCP.exe.id[9AA40F17-2803].[HenryShrapnel61@gmx.com].eightJump to behavior
Source: C:\Users\user\Desktop\Fast.exeDirectory created: C:\Program Files\Adobe\Acrobat DC\Acrobat\Adobe.Acrobat.Dependencies.manifest.id[9AA40F17-2803].[HenryShrapnel61@gmx.com].eightJump to behavior
Source: C:\Users\user\Desktop\Fast.exeDirectory created: C:\Program Files\Adobe\Acrobat DC\Acrobat\adobeafp.dll.id[9AA40F17-2803].[HenryShrapnel61@gmx.com].eightJump to behavior
Source: C:\Users\user\Desktop\Fast.exeDirectory created: C:\Program Files\Adobe\Acrobat DC\Acrobat\AdobeLinguistic.dll.id[9AA40F17-2803].[HenryShrapnel61@gmx.com].eightJump to behavior
Source: C:\Users\user\Desktop\Fast.exeDirectory created: C:\Program Files\Adobe\Acrobat DC\Acrobat\AdobeXMP.dll.id[9AA40F17-2803].[HenryShrapnel61@gmx.com].eightJump to behavior
Source: C:\Users\user\Desktop\Fast.exeDirectory created: C:\Program Files\Adobe\Acrobat DC\Acrobat\AGMGPUOptIn.ini.id[9AA40F17-2803].[HenryShrapnel61@gmx.com].eightJump to behavior
Source: C:\Users\user\Desktop\Fast.exeDirectory created: C:\Program Files\Adobe\Acrobat DC\Acrobat\ahclient.dll.id[9AA40F17-2803].[HenryShrapnel61@gmx.com].eightJump to behavior
Source: C:\Users\user\Desktop\Fast.exeDirectory created: C:\Program Files\Adobe\Acrobat DC\Acrobat\Air\nppdf32.dll.id[9AA40F17-2803].[HenryShrapnel61@gmx.com].eightJump to behavior
Source: C:\Users\user\Desktop\Fast.exeDirectory created: C:\Program Files\Adobe\Acrobat DC\Acrobat\ANCUtility.dll.id[9AA40F17-2803].[HenryShrapnel61@gmx.com].eightJump to behavior
Source: C:\Users\user\Desktop\Fast.exeDirectory created: C:\Program Files\Adobe\Acrobat DC\Acrobat\Assets\ownership-hero-image-d.gif.id[9AA40F17-2803].[HenryShrapnel61@gmx.com].eightJump to behavior
Source: C:\Users\user\Desktop\Fast.exeDirectory created: C:\Program Files\Adobe\Acrobat DC\Acrobat\AXE8SharedExpat.dll.id[9AA40F17-2803].[HenryShrapnel61@gmx.com].eightJump to behavior
Source: C:\Users\user\Desktop\Fast.exeDirectory created: C:\Program Files\Adobe\Acrobat DC\Acrobat\AXSLE.dll.id[9AA40F17-2803].[HenryShrapnel61@gmx.com].eightJump to behavior
Source: C:\Users\user\Desktop\Fast.exeDirectory created: C:\Program Files\Adobe\Acrobat DC\Acrobat\BIB.dll.id[9AA40F17-2803].[HenryShrapnel61@gmx.com].eightJump to behavior
Source: C:\Users\user\Desktop\Fast.exeDirectory created: C:\Program Files\Adobe\Acrobat DC\Acrobat\BIBUtils.dll.id[9AA40F17-2803].[HenryShrapnel61@gmx.com].eightJump to behavior
Source: C:\Users\user\Desktop\Fast.exeDirectory created: C:\Program Files\Adobe\Acrobat DC\Acrobat\Browser\WCChromeExtn\manifest.json.id[9AA40F17-2803].[HenryShrapnel61@gmx.com].eightJump to behavior
Source: C:\Users\user\Desktop\Fast.exeDirectory created: C:\Program Files\Adobe\Acrobat DC\Acrobat\Browser\nppdf32.dll.id[9AA40F17-2803].[HenryShrapnel61@gmx.com].eightJump to behavior
Source: C:\Users\user\Desktop\Fast.exeDirectory created: C:\Program Files\Adobe\Acrobat DC\Acrobat\Browser\WCChromeExtn\WCChromeNativeMessagingHost.exe.id[9AA40F17-2803].[HenryShrapnel61@gmx.com].eightJump to behavior
Source: C:\Users\user\Desktop\Fast.exeDirectory created: C:\Program Files\Adobe\Acrobat DC\Acrobat\ccme_asym.dll.id[9AA40F17-2803].[HenryShrapnel61@gmx.com].eightJump to behavior
Source: C:\Users\user\Desktop\Fast.exeDirectory created: C:\Program Files\Adobe\Acrobat DC\Acrobat\ccme_base.dll.id[9AA40F17-2803].[HenryShrapnel61@gmx.com].eightJump to behavior
Source: C:\Users\user\Desktop\Fast.exeDirectory created: C:\Program Files\Adobe\Acrobat DC\Acrobat\ccme_base_non_fips.dll.id[9AA40F17-2803].[HenryShrapnel61@gmx.com].eightJump to behavior
Source: C:\Users\user\Desktop\Fast.exeDirectory created: C:\Program Files\Adobe\Acrobat DC\Acrobat\Click on 'Change' to select default PDF handler.pdf.id[9AA40F17-2803].[HenryShrapnel61@gmx.com].eightJump to behavior
Source: C:\Users\user\Desktop\Fast.exeDirectory created: C:\Program Files\Adobe\Acrobat DC\Acrobat\ccme_ecc.dll.id[9AA40F17-2803].[HenryShrapnel61@gmx.com].eightJump to behavior
Source: C:\Users\user\Desktop\Fast.exeDirectory created: C:\Program Files\Adobe\Acrobat DC\Acrobat\CRClient.dll.id[9AA40F17-2803].[HenryShrapnel61@gmx.com].eightJump to behavior
Source: C:\Users\user\Desktop\Fast.exeDirectory created: C:\Program Files\Adobe\Acrobat DC\Acrobat\CRLogTransport.exe.id[9AA40F17-2803].[HenryShrapnel61@gmx.com].eightJump to behavior
Source: C:\Users\user\Desktop\Fast.exeDirectory created: C:\Program Files\Adobe\Acrobat DC\Acrobat\CRWindowsClientService.exe.id[9AA40F17-2803].[HenryShrapnel61@gmx.com].eightJump to behavior
Source: C:\Users\user\Desktop\Fast.exeDirectory created: C:\Program Files\Adobe\Acrobat DC\Acrobat\cryptocme.dll.id[9AA40F17-2803].[HenryShrapnel61@gmx.com].eightJump to behavior
Source: C:\Users\user\Desktop\Fast.exeDirectory created: C:\Program Files\Adobe\Acrobat DC\Acrobat\cryptocme.sig.id[9AA40F17-2803].[HenryShrapnel61@gmx.com].eightJump to behavior
Source: C:\Users\user\Desktop\Fast.exeDirectory created: C:\Program Files\Adobe\Acrobat DC\Acrobat\cr_win_client_config.cfg.id[9AA40F17-2803].[HenryShrapnel61@gmx.com].eightJump to behavior
Source: C:\Users\user\Desktop\Fast.exeDirectory created: C:\Program Files\Adobe\Acrobat DC\Acrobat\DirectInk.dll.id[9AA40F17-2803].[HenryShrapnel61@gmx.com].eightJump to behavior
Source: C:\Users\user\Desktop\Fast.exeDirectory created: C:\Program Files\Adobe\Acrobat DC\Acrobat\DocSettings\Redaction\CAN\SearchRedactPatterns.xml.id[9AA40F17-2803].[HenryShrapnel61@gmx.com].eightJump to behavior
Source: C:\Users\user\Desktop\Fast.exeDirectory created: C:\Program Files\Adobe\Acrobat DC\Acrobat\DocSettings\Redaction\DEU\SearchRedactPatterns.xml.id[9AA40F17-2803].[HenryShrapnel61@gmx.com].eightJump to behavior
Source: C:\Users\user\Desktop\Fast.exeDirectory created: C:\Program Files\Adobe\Acrobat DC\Acrobat\DocSettings\Redaction\ENU\SearchRedactPatterns.xml.id[9AA40F17-2803].[HenryShrapnel61@gmx.com].eightJump to behavior
Source: C:\Users\user\Desktop\Fast.exeDirectory created: C:\Program Files\Adobe\Acrobat DC\Acrobat\DocSettings\Redaction\ENU\U.S. FOIA.xml.id[9AA40F17-2803].[HenryShrapnel61@gmx.com].eightJump to behavior
Source: C:\Users\user\Desktop\Fast.exeDirectory created: C:\Program Files\Adobe\Acrobat DC\Acrobat\DocSettings\Redaction\ENU\U.S. Privacy Act.xml.id[9AA40F17-2803].[HenryShrapnel61@gmx.com].eightJump to behavior
Source: C:\Users\user\Desktop\Fast.exeDirectory created: C:\Program Files\Adobe\Acrobat DC\Acrobat\DocSettings\Redaction\FRA\SearchRedactPatterns.xml.id[9AA40F17-2803].[HenryShrapnel61@gmx.com].eightJump to behavior
Source: C:\Users\user\Desktop\Fast.exeDirectory created: C:\Program Files\Adobe\Acrobat DC\Acrobat\DocSettings\Redaction\JPN\SearchRedactPatterns.xml.id[9AA40F17-2803].[HenryShrapnel61@gmx.com].eightJump to behavior
Source: C:\Users\user\Desktop\Fast.exeDirectory created: C:\Program Files\Adobe\Acrobat DC\Acrobat\DocSettings\Redaction\LocaleDisplayNameMap.xml.id[9AA40F17-2803].[HenryShrapnel61@gmx.com].eightJump to behavior
Source: C:\Users\user\Desktop\Fast.exeDirectory created: C:\Program Files\Adobe\Acrobat DC\Acrobat\DocSettings\Redaction\UK\SearchRedactPatterns.xml.id[9AA40F17-2803].[HenryShrapnel61@gmx.com].eightJump to behavior
Source: C:\Users\user\Desktop\Fast.exeDirectory created: C:\Program Files\Adobe\Acrobat DC\Acrobat\DocTemplates\ENU\template1.pdf.id[9AA40F17-2803].[HenryShrapnel61@gmx.com].eightJump to behavior
Source: C:\Users\user\Desktop\Fast.exeDirectory created: C:\Program Files\Adobe\Acrobat DC\Acrobat\DocTemplates\ENU\template2.pdf.id[9AA40F17-2803].[HenryShrapnel61@gmx.com].eightJump to behavior
Source: C:\Users\user\Desktop\Fast.exeDirectory created: C:\Program Files\Adobe\Acrobat DC\Acrobat\DocTemplates\ENU\template3.pdf.id[9AA40F17-2803].[HenryShrapnel61@gmx.com].eightJump to behavior
Source: C:\Users\user\Desktop\Fast.exeDirectory created: C:\Program Files\Adobe\Acrobat DC\Acrobat\Eula.exe.id[9AA40F17-2803].[HenryShrapnel61@gmx.com].eightJump to behavior
Source: C:\Users\user\Desktop\Fast.exeDirectory created: C:\Program Files\Adobe\Acrobat DC\Acrobat\ExtendScript.dll.id[9AA40F17-2803].[HenryShrapnel61@gmx.com].eightJump to behavior
Source: C:\Users\user\Desktop\Fast.exeDirectory created: C:\Program Files\Adobe\Acrobat DC\Acrobat\HostedServicesTemplates\ENU\template1.pdf.id[9AA40F17-2803].[HenryShrapnel61@gmx.com].eight