Windows Analysis Report
msmult64.exe

Overview

General Information

Sample name: msmult64.exe
Analysis ID: 1417283
MD5: 7227c1140e0adca64a3f22dab2bfe6fe
SHA1: c0f3912ca1742a2c19b3108ba607e20ffc5f05f9
SHA256: 6ce6acac7b47576ea7234258004cd20108e2c11b6918f58e7755da02dd7fe065
Infos:

Detection

Bl00dyAdmin, TrojanRansom
Score: 100
Range: 0 - 100
Whitelisted: false
Confidence: 100%

Signatures

Found ransom note / readme
Yara detected Bl00dyAdmin Ransomware
Yara detected TrojanRansom
Connects to many different private IPs (likely to spread or exploit)
Connects to many different private IPs via SMB (likely to spread or exploit)
Drops a file containing file decryption instructions (likely related to ransomware)
Found direct / indirect Syscall (likely to bypass EDR)
Infects executable files (exe, dll, sys, html)
Machine Learning detection for sample
May encrypt documents and pictures (Ransomware)
Modifies existing user documents (likely ransomware behavior)
Overwrites code with unconditional jumps - possibly settings hooks in foreign process
Writes a notice file (html or txt) to demand a ransom
Writes many files with high entropy
Contains capabilities to detect virtual machines
Contains functionality to call native functions
Contains functionality to open a port and listen for incoming connection (possibly a backdoor)
Contains functionality to query CPU information (cpuid)
Detected potential crypto function
Entry point lies outside standard sections
JA3 SSL client fingerprint seen in connection with other malware
May sleep (evasive loops) to hinder dynamic analysis
PE file contains sections with non-standard names
Queries the volume information (name, serial number etc) of a device
Tries to load missing DLLs
Uses a known web browser user agent for HTTP communication
Uses code obfuscation techniques (call, push, ret)

Classification

AV Detection

barindex
Source: msmult64.exe Joe Sandbox ML: detected

Exploits

barindex
Source: global traffic TCP traffic: 192.168.2.148:445 Jump to behavior
Source: global traffic TCP traffic: 192.168.2.149:445 Jump to behavior
Source: global traffic TCP traffic: 192.168.2.146:445 Jump to behavior
Source: global traffic TCP traffic: 192.168.2.147:445 Jump to behavior
Source: global traffic TCP traffic: 192.168.2.140:445 Jump to behavior
Source: global traffic TCP traffic: 192.168.2.141:445 Jump to behavior
Source: global traffic TCP traffic: 192.168.2.144:445 Jump to behavior
Source: global traffic TCP traffic: 192.168.2.145:445 Jump to behavior
Source: global traffic TCP traffic: 192.168.2.142:445 Jump to behavior
Source: global traffic TCP traffic: 192.168.2.143:445 Jump to behavior
Source: global traffic TCP traffic: 192.168.2.159:445 Jump to behavior
Source: global traffic TCP traffic: 192.168.2.157:445 Jump to behavior
Source: global traffic TCP traffic: 192.168.2.158:445 Jump to behavior
Source: global traffic TCP traffic: 192.168.2.151:445 Jump to behavior
Source: global traffic TCP traffic: 192.168.2.152:445 Jump to behavior
Source: global traffic TCP traffic: 192.168.2.150:445 Jump to behavior
Source: global traffic TCP traffic: 192.168.2.155:445 Jump to behavior
Source: global traffic TCP traffic: 192.168.2.156:445 Jump to behavior
Source: global traffic TCP traffic: 192.168.2.153:445 Jump to behavior
Source: global traffic TCP traffic: 192.168.2.154:445 Jump to behavior
Source: global traffic TCP traffic: 192.168.2.126:445 Jump to behavior
Source: global traffic TCP traffic: 192.168.2.247:445 Jump to behavior
Source: global traffic TCP traffic: 192.168.2.127:445 Jump to behavior
Source: global traffic TCP traffic: 192.168.2.248:445 Jump to behavior
Source: global traffic TCP traffic: 192.168.2.124:445 Jump to behavior
Source: global traffic TCP traffic: 192.168.2.245:445 Jump to behavior
Source: global traffic TCP traffic: 192.168.2.125:445 Jump to behavior
Source: global traffic TCP traffic: 192.168.2.246:445 Jump to behavior
Source: global traffic TCP traffic: 192.168.2.128:445 Jump to behavior
Source: global traffic TCP traffic: 192.168.2.249:445 Jump to behavior
Source: global traffic TCP traffic: 192.168.2.129:445 Jump to behavior
Source: global traffic TCP traffic: 192.168.2.240:445 Jump to behavior
Source: global traffic TCP traffic: 192.168.2.122:445 Jump to behavior
Source: global traffic TCP traffic: 192.168.2.243:445 Jump to behavior
Source: global traffic TCP traffic: 192.168.2.123:445 Jump to behavior
Source: global traffic TCP traffic: 192.168.2.244:445 Jump to behavior
Source: global traffic TCP traffic: 192.168.2.120:445 Jump to behavior
Source: global traffic TCP traffic: 192.168.2.241:445 Jump to behavior
Source: global traffic TCP traffic: 192.168.2.121:445 Jump to behavior
Source: global traffic TCP traffic: 192.168.2.242:445 Jump to behavior
Source: global traffic TCP traffic: 192.168.2.97:445 Jump to behavior
Source: global traffic TCP traffic: 192.168.2.137:445 Jump to behavior
Source: global traffic TCP traffic: 192.168.2.96:445 Jump to behavior
Source: global traffic TCP traffic: 192.168.2.138:445 Jump to behavior
Source: global traffic TCP traffic: 192.168.2.99:445 Jump to behavior
Source: global traffic TCP traffic: 192.168.2.135:445 Jump to behavior
Source: global traffic TCP traffic: 192.168.2.98:445 Jump to behavior
Source: global traffic TCP traffic: 192.168.2.136:445 Jump to behavior
Source: global traffic TCP traffic: 192.168.2.139:445 Jump to behavior
Source: global traffic TCP traffic: 192.168.2.250:445 Jump to behavior
Source: global traffic TCP traffic: 192.168.2.130:445 Jump to behavior
Source: global traffic TCP traffic: 192.168.2.251:445 Jump to behavior
Source: global traffic TCP traffic: 192.168.2.91:445 Jump to behavior
Source: global traffic TCP traffic: 192.168.2.90:445 Jump to behavior
Source: global traffic TCP traffic: 192.168.2.93:445 Jump to behavior
Source: global traffic TCP traffic: 192.168.2.133:445 Jump to behavior
Source: global traffic TCP traffic: 192.168.2.254:445 Jump to behavior
Source: global traffic TCP traffic: 192.168.2.92:445 Jump to behavior
Source: global traffic TCP traffic: 192.168.2.134:445 Jump to behavior
Source: global traffic TCP traffic: 192.168.2.95:445 Jump to behavior
Source: global traffic TCP traffic: 192.168.2.131:445 Jump to behavior
Source: global traffic TCP traffic: 192.168.2.252:445 Jump to behavior
Source: global traffic TCP traffic: 192.168.2.94:445 Jump to behavior
Source: global traffic TCP traffic: 192.168.2.132:445 Jump to behavior
Source: global traffic TCP traffic: 192.168.2.253:445 Jump to behavior
Source: global traffic TCP traffic: 192.168.2.104:445 Jump to behavior
Source: global traffic TCP traffic: 192.168.2.225:445 Jump to behavior
Source: global traffic TCP traffic: 192.168.2.105:445 Jump to behavior
Source: global traffic TCP traffic: 192.168.2.226:445 Jump to behavior
Source: global traffic TCP traffic: 192.168.2.102:445 Jump to behavior
Source: global traffic TCP traffic: 192.168.2.223:445 Jump to behavior
Source: global traffic TCP traffic: 192.168.2.103:445 Jump to behavior
Source: global traffic TCP traffic: 192.168.2.224:445 Jump to behavior
Source: global traffic TCP traffic: 192.168.2.108:445 Jump to behavior
Source: global traffic TCP traffic: 192.168.2.229:445 Jump to behavior
Source: global traffic TCP traffic: 192.168.2.109:445 Jump to behavior
Source: global traffic TCP traffic: 192.168.2.106:445 Jump to behavior
Source: global traffic TCP traffic: 192.168.2.227:445 Jump to behavior
Source: global traffic TCP traffic: 192.168.2.107:445 Jump to behavior
Source: global traffic TCP traffic: 192.168.2.228:445 Jump to behavior
Source: global traffic TCP traffic: 192.168.2.100:445 Jump to behavior
Source: global traffic TCP traffic: 192.168.2.221:445 Jump to behavior
Source: global traffic TCP traffic: 192.168.2.101:445 Jump to behavior
Source: global traffic TCP traffic: 192.168.2.222:445 Jump to behavior
Source: global traffic TCP traffic: 192.168.2.220:445 Jump to behavior
Source: global traffic TCP traffic: 192.168.2.115:445 Jump to behavior
Source: global traffic TCP traffic: 192.168.2.236:445 Jump to behavior
Source: global traffic TCP traffic: 192.168.2.116:445 Jump to behavior
Source: global traffic TCP traffic: 192.168.2.237:445 Jump to behavior
Source: global traffic TCP traffic: 192.168.2.113:445 Jump to behavior
Source: global traffic TCP traffic: 192.168.2.234:445 Jump to behavior
Source: global traffic TCP traffic: 192.168.2.114:445 Jump to behavior
Source: global traffic TCP traffic: 192.168.2.235:445 Jump to behavior
Source: global traffic TCP traffic: 192.168.2.119:445 Jump to behavior
Source: global traffic TCP traffic: 192.168.2.117:445 Jump to behavior
Source: global traffic TCP traffic: 192.168.2.238:445 Jump to behavior
Source: global traffic TCP traffic: 192.168.2.118:445 Jump to behavior
Source: global traffic TCP traffic: 192.168.2.239:445 Jump to behavior
Source: global traffic TCP traffic: 192.168.2.111:445 Jump to behavior
Source: global traffic TCP traffic: 192.168.2.232:445 Jump to behavior
Source: global traffic TCP traffic: 192.168.2.112:445 Jump to behavior
Source: global traffic TCP traffic: 192.168.2.233:445 Jump to behavior
Source: global traffic TCP traffic: 192.168.2.230:445 Jump to behavior
Source: global traffic TCP traffic: 192.168.2.110:445 Jump to behavior
Source: global traffic TCP traffic: 192.168.2.231:445 Jump to behavior
Source: global traffic TCP traffic: 192.168.2.203:445 Jump to behavior
Source: global traffic TCP traffic: 192.168.2.204:445 Jump to behavior
Source: global traffic TCP traffic: 192.168.2.201:445 Jump to behavior
Source: global traffic TCP traffic: 192.168.2.202:445 Jump to behavior
Source: global traffic TCP traffic: 192.168.2.207:445 Jump to behavior
Source: global traffic TCP traffic: 192.168.2.208:445 Jump to behavior
Source: global traffic TCP traffic: 192.168.2.205:445 Jump to behavior
Source: global traffic TCP traffic: 192.168.2.206:445 Jump to behavior
Source: global traffic TCP traffic: 192.168.2.200:445 Jump to behavior
Source: global traffic TCP traffic: 192.168.2.209:445 Jump to behavior
Source: global traffic TCP traffic: 192.168.2.214:445 Jump to behavior
Source: global traffic TCP traffic: 192.168.2.215:445 Jump to behavior
Source: global traffic TCP traffic: 192.168.2.212:445 Jump to behavior
Source: global traffic TCP traffic: 192.168.2.213:445 Jump to behavior
Source: global traffic TCP traffic: 192.168.2.218:445 Jump to behavior
Source: global traffic TCP traffic: 192.168.2.219:445 Jump to behavior
Source: global traffic TCP traffic: 192.168.2.216:445 Jump to behavior
Source: global traffic TCP traffic: 192.168.2.217:445 Jump to behavior
Source: global traffic TCP traffic: 192.168.2.210:445 Jump to behavior
Source: global traffic TCP traffic: 192.168.2.211:445 Jump to behavior
Source: global traffic TCP traffic: 192.168.2.39:445 Jump to behavior
Source: global traffic TCP traffic: 192.168.2.38:445 Jump to behavior
Source: global traffic TCP traffic: 192.168.2.42:445 Jump to behavior
Source: global traffic TCP traffic: 192.168.2.41:445 Jump to behavior
Source: global traffic TCP traffic: 192.168.2.44:445 Jump to behavior
Source: global traffic TCP traffic: 192.168.2.43:445 Jump to behavior
Source: global traffic TCP traffic: 192.168.2.46:445 Jump to behavior
Source: global traffic TCP traffic: 192.168.2.45:445 Jump to behavior
Source: global traffic TCP traffic: 192.168.2.48:445 Jump to behavior
Source: global traffic TCP traffic: 192.168.2.47:445 Jump to behavior
Source: global traffic TCP traffic: 192.168.2.40:445 Jump to behavior
Source: global traffic TCP traffic: 192.168.2.28:445 Jump to behavior
Source: global traffic TCP traffic: 192.168.2.27:445 Jump to behavior
Source: global traffic TCP traffic: 192.168.2.29:445 Jump to behavior
Source: global traffic TCP traffic: 192.168.2.31:445 Jump to behavior
Source: global traffic TCP traffic: 192.168.2.30:445 Jump to behavior
Source: global traffic TCP traffic: 192.168.2.33:445 Jump to behavior
Source: global traffic TCP traffic: 192.168.2.32:445 Jump to behavior
Source: global traffic TCP traffic: 192.168.2.35:445 Jump to behavior
Source: global traffic TCP traffic: 192.168.2.34:445 Jump to behavior
Source: global traffic TCP traffic: 192.168.2.37:445 Jump to behavior
Source: global traffic TCP traffic: 192.168.2.36:445 Jump to behavior
Source: global traffic TCP traffic: 192.168.2.17:445 Jump to behavior
Source: global traffic TCP traffic: 192.168.2.16:445 Jump to behavior
Source: global traffic TCP traffic: 192.168.2.19:445 Jump to behavior
Source: global traffic TCP traffic: 192.168.2.18:445 Jump to behavior
Source: global traffic TCP traffic: 192.168.2.20:445 Jump to behavior
Source: global traffic TCP traffic: 192.168.2.22:445 Jump to behavior
Source: global traffic TCP traffic: 192.168.2.21:445 Jump to behavior
Source: global traffic TCP traffic: 192.168.2.24:445 Jump to behavior
Source: global traffic TCP traffic: 192.168.2.23:445 Jump to behavior
Source: global traffic TCP traffic: 192.168.2.26:445 Jump to behavior
Source: global traffic TCP traffic: 192.168.2.25:445 Jump to behavior
Source: global traffic TCP traffic: 192.168.2.11:445 Jump to behavior
Source: global traffic TCP traffic: 192.168.2.10:445 Jump to behavior
Source: global traffic TCP traffic: 192.168.2.13:445 Jump to behavior
Source: global traffic TCP traffic: 192.168.2.12:445 Jump to behavior
Source: global traffic TCP traffic: 192.168.2.15:445 Jump to behavior
Source: global traffic TCP traffic: 192.168.2.14:445 Jump to behavior
Source: global traffic TCP traffic: 192.168.2.0:445 Jump to behavior
Source: global traffic TCP traffic: 192.168.2.2:445 Jump to behavior
Source: global traffic TCP traffic: 192.168.2.1:445 Jump to behavior
Source: global traffic TCP traffic: 192.168.2.180:445 Jump to behavior
Source: global traffic TCP traffic: 192.168.2.181:445 Jump to behavior
Source: global traffic TCP traffic: 192.168.2.8:445 Jump to behavior
Source: global traffic TCP traffic: 192.168.2.7:445 Jump to behavior
Source: global traffic TCP traffic: 192.168.2.9:445 Jump to behavior
Source: global traffic TCP traffic: 192.168.2.4:445 Jump to behavior
Source: global traffic TCP traffic: 192.168.2.3:445 Jump to behavior
Source: global traffic TCP traffic: 192.168.2.6:445 Jump to behavior
Source: global traffic TCP traffic: 192.168.2.5:445 Jump to behavior
Source: global traffic TCP traffic: 192.168.2.86:445 Jump to behavior
Source: global traffic TCP traffic: 192.168.2.85:445 Jump to behavior
Source: global traffic TCP traffic: 192.168.2.88:445 Jump to behavior
Source: global traffic TCP traffic: 192.168.2.87:445 Jump to behavior
Source: global traffic TCP traffic: 192.168.2.89:445 Jump to behavior
Source: global traffic TCP traffic: 192.168.2.184:445 Jump to behavior
Source: global traffic TCP traffic: 192.168.2.185:445 Jump to behavior
Source: global traffic TCP traffic: 192.168.2.80:445 Jump to behavior
Source: global traffic TCP traffic: 192.168.2.182:445 Jump to behavior
Source: global traffic TCP traffic: 192.168.2.183:445 Jump to behavior
Source: global traffic TCP traffic: 192.168.2.82:445 Jump to behavior
Source: global traffic TCP traffic: 192.168.2.188:445 Jump to behavior
Source: global traffic TCP traffic: 192.168.2.81:445 Jump to behavior
Source: global traffic TCP traffic: 192.168.2.189:445 Jump to behavior
Source: global traffic TCP traffic: 192.168.2.84:445 Jump to behavior
Source: global traffic TCP traffic: 192.168.2.186:445 Jump to behavior
Source: global traffic TCP traffic: 192.168.2.83:445 Jump to behavior
Source: global traffic TCP traffic: 192.168.2.187:445 Jump to behavior
Source: global traffic TCP traffic: 192.168.2.191:445 Jump to behavior
Source: global traffic TCP traffic: 192.168.2.192:445 Jump to behavior
Source: global traffic TCP traffic: 192.168.2.190:445 Jump to behavior
Source: global traffic TCP traffic: 192.168.2.75:445 Jump to behavior
Source: global traffic TCP traffic: 192.168.2.74:445 Jump to behavior
Source: global traffic TCP traffic: 192.168.2.77:445 Jump to behavior
Source: global traffic TCP traffic: 192.168.2.76:445 Jump to behavior
Source: global traffic TCP traffic: 192.168.2.79:445 Jump to behavior
Source: global traffic TCP traffic: 192.168.2.78:445 Jump to behavior
Source: global traffic TCP traffic: 192.168.2.195:445 Jump to behavior
Source: global traffic TCP traffic: 192.168.2.196:445 Jump to behavior
Source: global traffic TCP traffic: 192.168.2.193:445 Jump to behavior
Source: global traffic TCP traffic: 192.168.2.194:445 Jump to behavior
Source: global traffic TCP traffic: 192.168.2.71:445 Jump to behavior
Source: global traffic TCP traffic: 192.168.2.199:445 Jump to behavior
Source: global traffic TCP traffic: 192.168.2.70:445 Jump to behavior
Source: global traffic TCP traffic: 192.168.2.73:445 Jump to behavior
Source: global traffic TCP traffic: 192.168.2.197:445 Jump to behavior
Source: global traffic TCP traffic: 192.168.2.72:445 Jump to behavior
Source: global traffic TCP traffic: 192.168.2.198:445 Jump to behavior
Source: global traffic TCP traffic: 192.168.2.64:445 Jump to behavior
Source: global traffic TCP traffic: 192.168.2.63:445 Jump to behavior
Source: global traffic TCP traffic: 192.168.2.66:445 Jump to behavior
Source: global traffic TCP traffic: 192.168.2.168:445 Jump to behavior
Source: global traffic TCP traffic: 192.168.2.65:445 Jump to behavior
Source: global traffic TCP traffic: 192.168.2.169:445 Jump to behavior
Source: global traffic TCP traffic: 192.168.2.68:445 Jump to behavior
Source: global traffic TCP traffic: 192.168.2.67:445 Jump to behavior
Source: global traffic TCP traffic: 192.168.2.69:445 Jump to behavior
Source: global traffic TCP traffic: 192.168.2.162:445 Jump to behavior
Source: global traffic TCP traffic: 192.168.2.163:445 Jump to behavior
Source: global traffic TCP traffic: 192.168.2.160:445 Jump to behavior
Source: global traffic TCP traffic: 192.168.2.161:445 Jump to behavior
Source: global traffic TCP traffic: 192.168.2.60:445 Jump to behavior
Source: global traffic TCP traffic: 192.168.2.166:445 Jump to behavior
Source: global traffic TCP traffic: 192.168.2.167:445 Jump to behavior
Source: global traffic TCP traffic: 192.168.2.62:445 Jump to behavior
Source: global traffic TCP traffic: 192.168.2.164:445 Jump to behavior
Source: global traffic TCP traffic: 192.168.2.61:445 Jump to behavior
Source: global traffic TCP traffic: 192.168.2.165:445 Jump to behavior
Source: global traffic TCP traffic: 192.168.2.170:445 Jump to behavior
Source: global traffic TCP traffic: 192.168.2.49:445 Jump to behavior
Source: global traffic TCP traffic: 192.168.2.53:445 Jump to behavior
Source: global traffic TCP traffic: 192.168.2.52:445 Jump to behavior
Source: global traffic TCP traffic: 192.168.2.55:445 Jump to behavior
Source: global traffic TCP traffic: 192.168.2.179:445 Jump to behavior
Source: global traffic TCP traffic: 192.168.2.54:445 Jump to behavior
Source: global traffic TCP traffic: 192.168.2.57:445 Jump to behavior
Source: global traffic TCP traffic: 192.168.2.56:445 Jump to behavior
Source: global traffic TCP traffic: 192.168.2.59:445 Jump to behavior
Source: global traffic TCP traffic: 192.168.2.58:445 Jump to behavior
Source: global traffic TCP traffic: 192.168.2.173:445 Jump to behavior
Source: global traffic TCP traffic: 192.168.2.174:445 Jump to behavior
Source: global traffic TCP traffic: 192.168.2.171:445 Jump to behavior
Source: global traffic TCP traffic: 192.168.2.172:445 Jump to behavior
Source: global traffic TCP traffic: 192.168.2.177:445 Jump to behavior
Source: global traffic TCP traffic: 192.168.2.178:445 Jump to behavior
Source: global traffic TCP traffic: 192.168.2.51:445 Jump to behavior
Source: global traffic TCP traffic: 192.168.2.175:445 Jump to behavior
Source: global traffic TCP traffic: 192.168.2.50:445 Jump to behavior
Source: global traffic TCP traffic: 192.168.2.176:445 Jump to behavior
Source: global traffic TCP traffic: 192.168.2.148:445 Jump to behavior
Source: global traffic TCP traffic: 192.168.2.149:445 Jump to behavior
Source: global traffic TCP traffic: 192.168.2.146:445 Jump to behavior
Source: global traffic TCP traffic: 192.168.2.147:445 Jump to behavior
Source: global traffic TCP traffic: 192.168.2.140:445 Jump to behavior
Source: global traffic TCP traffic: 192.168.2.141:445 Jump to behavior
Source: global traffic TCP traffic: 192.168.2.144:445 Jump to behavior
Source: global traffic TCP traffic: 192.168.2.145:445 Jump to behavior
Source: global traffic TCP traffic: 192.168.2.142:445 Jump to behavior
Source: global traffic TCP traffic: 192.168.2.143:445 Jump to behavior
Source: global traffic TCP traffic: 192.168.2.159:445 Jump to behavior
Source: global traffic TCP traffic: 192.168.2.157:445 Jump to behavior
Source: global traffic TCP traffic: 192.168.2.158:445 Jump to behavior
Source: global traffic TCP traffic: 192.168.2.151:445 Jump to behavior
Source: global traffic TCP traffic: 192.168.2.152:445 Jump to behavior
Source: global traffic TCP traffic: 192.168.2.150:445 Jump to behavior
Source: global traffic TCP traffic: 192.168.2.155:445 Jump to behavior
Source: global traffic TCP traffic: 192.168.2.156:445 Jump to behavior
Source: global traffic TCP traffic: 192.168.2.153:445 Jump to behavior
Source: global traffic TCP traffic: 192.168.2.154:445 Jump to behavior
Source: global traffic TCP traffic: 192.168.2.126:445 Jump to behavior
Source: global traffic TCP traffic: 192.168.2.247:445 Jump to behavior
Source: global traffic TCP traffic: 192.168.2.127:445 Jump to behavior
Source: global traffic TCP traffic: 192.168.2.248:445 Jump to behavior
Source: global traffic TCP traffic: 192.168.2.124:445 Jump to behavior
Source: global traffic TCP traffic: 192.168.2.245:445 Jump to behavior
Source: global traffic TCP traffic: 192.168.2.125:445 Jump to behavior
Source: global traffic TCP traffic: 192.168.2.246:445 Jump to behavior
Source: global traffic TCP traffic: 192.168.2.128:445 Jump to behavior
Source: global traffic TCP traffic: 192.168.2.249:445 Jump to behavior
Source: global traffic TCP traffic: 192.168.2.129:445 Jump to behavior
Source: global traffic TCP traffic: 192.168.2.240:445 Jump to behavior
Source: global traffic TCP traffic: 192.168.2.122:445 Jump to behavior
Source: global traffic TCP traffic: 192.168.2.243:445 Jump to behavior
Source: global traffic TCP traffic: 192.168.2.123:445 Jump to behavior
Source: global traffic TCP traffic: 192.168.2.244:445 Jump to behavior
Source: global traffic TCP traffic: 192.168.2.120:445 Jump to behavior
Source: global traffic TCP traffic: 192.168.2.241:445 Jump to behavior
Source: global traffic TCP traffic: 192.168.2.121:445 Jump to behavior
Source: global traffic TCP traffic: 192.168.2.242:445 Jump to behavior
Source: global traffic TCP traffic: 192.168.2.97:445 Jump to behavior
Source: global traffic TCP traffic: 192.168.2.137:445 Jump to behavior
Source: global traffic TCP traffic: 192.168.2.96:445 Jump to behavior
Source: global traffic TCP traffic: 192.168.2.138:445 Jump to behavior
Source: global traffic TCP traffic: 192.168.2.99:445 Jump to behavior
Source: global traffic TCP traffic: 192.168.2.135:445 Jump to behavior
Source: global traffic TCP traffic: 192.168.2.98:445 Jump to behavior
Source: global traffic TCP traffic: 192.168.2.136:445 Jump to behavior
Source: global traffic TCP traffic: 192.168.2.139:445 Jump to behavior
Source: global traffic TCP traffic: 192.168.2.250:445 Jump to behavior
Source: global traffic TCP traffic: 192.168.2.130:445 Jump to behavior
Source: global traffic TCP traffic: 192.168.2.251:445 Jump to behavior
Source: global traffic TCP traffic: 192.168.2.91:445 Jump to behavior
Source: global traffic TCP traffic: 192.168.2.90:445 Jump to behavior
Source: global traffic TCP traffic: 192.168.2.93:445 Jump to behavior
Source: global traffic TCP traffic: 192.168.2.133:445 Jump to behavior
Source: global traffic TCP traffic: 192.168.2.254:445 Jump to behavior
Source: global traffic TCP traffic: 192.168.2.92:445 Jump to behavior
Source: global traffic TCP traffic: 192.168.2.134:445 Jump to behavior
Source: global traffic TCP traffic: 192.168.2.95:445 Jump to behavior
Source: global traffic TCP traffic: 192.168.2.131:445 Jump to behavior
Source: global traffic TCP traffic: 192.168.2.252:445 Jump to behavior
Source: global traffic TCP traffic: 192.168.2.94:445 Jump to behavior
Source: global traffic TCP traffic: 192.168.2.132:445 Jump to behavior
Source: global traffic TCP traffic: 192.168.2.253:445 Jump to behavior
Source: global traffic TCP traffic: 192.168.2.104:445 Jump to behavior
Source: global traffic TCP traffic: 192.168.2.225:445 Jump to behavior
Source: global traffic TCP traffic: 192.168.2.105:445 Jump to behavior
Source: global traffic TCP traffic: 192.168.2.226:445 Jump to behavior
Source: global traffic TCP traffic: 192.168.2.102:445 Jump to behavior
Source: global traffic TCP traffic: 192.168.2.223:445 Jump to behavior
Source: global traffic TCP traffic: 192.168.2.103:445 Jump to behavior
Source: global traffic TCP traffic: 192.168.2.224:445 Jump to behavior
Source: global traffic TCP traffic: 192.168.2.108:445 Jump to behavior
Source: global traffic TCP traffic: 192.168.2.229:445 Jump to behavior
Source: global traffic TCP traffic: 192.168.2.109:445 Jump to behavior
Source: global traffic TCP traffic: 192.168.2.106:445 Jump to behavior
Source: global traffic TCP traffic: 192.168.2.227:445 Jump to behavior
Source: global traffic TCP traffic: 192.168.2.107:445 Jump to behavior
Source: global traffic TCP traffic: 192.168.2.228:445 Jump to behavior
Source: global traffic TCP traffic: 192.168.2.100:445 Jump to behavior
Source: global traffic TCP traffic: 192.168.2.221:445 Jump to behavior
Source: global traffic TCP traffic: 192.168.2.101:445 Jump to behavior
Source: global traffic TCP traffic: 192.168.2.222:445 Jump to behavior
Source: global traffic TCP traffic: 192.168.2.220:445 Jump to behavior
Source: global traffic TCP traffic: 192.168.2.115:445 Jump to behavior
Source: global traffic TCP traffic: 192.168.2.236:445 Jump to behavior
Source: global traffic TCP traffic: 192.168.2.116:445 Jump to behavior
Source: global traffic TCP traffic: 192.168.2.237:445 Jump to behavior
Source: global traffic TCP traffic: 192.168.2.113:445 Jump to behavior
Source: global traffic TCP traffic: 192.168.2.234:445 Jump to behavior
Source: global traffic TCP traffic: 192.168.2.114:445 Jump to behavior
Source: global traffic TCP traffic: 192.168.2.235:445 Jump to behavior
Source: global traffic TCP traffic: 192.168.2.119:445 Jump to behavior
Source: global traffic TCP traffic: 192.168.2.117:445 Jump to behavior
Source: global traffic TCP traffic: 192.168.2.238:445 Jump to behavior
Source: global traffic TCP traffic: 192.168.2.118:445 Jump to behavior
Source: global traffic TCP traffic: 192.168.2.239:445 Jump to behavior
Source: global traffic TCP traffic: 192.168.2.111:445 Jump to behavior
Source: global traffic TCP traffic: 192.168.2.232:445 Jump to behavior
Source: global traffic TCP traffic: 192.168.2.112:445 Jump to behavior
Source: global traffic TCP traffic: 192.168.2.233:445 Jump to behavior
Source: global traffic TCP traffic: 192.168.2.230:445 Jump to behavior
Source: global traffic TCP traffic: 192.168.2.110:445 Jump to behavior
Source: global traffic TCP traffic: 192.168.2.231:445 Jump to behavior
Source: global traffic TCP traffic: 192.168.2.203:445 Jump to behavior
Source: global traffic TCP traffic: 192.168.2.204:445 Jump to behavior
Source: global traffic TCP traffic: 192.168.2.201:445 Jump to behavior
Source: global traffic TCP traffic: 192.168.2.202:445 Jump to behavior
Source: global traffic TCP traffic: 192.168.2.207:445 Jump to behavior
Source: global traffic TCP traffic: 192.168.2.208:445 Jump to behavior
Source: global traffic TCP traffic: 192.168.2.205:445 Jump to behavior
Source: global traffic TCP traffic: 192.168.2.206:445 Jump to behavior
Source: global traffic TCP traffic: 192.168.2.200:445 Jump to behavior
Source: global traffic TCP traffic: 192.168.2.209:445 Jump to behavior
Source: global traffic TCP traffic: 192.168.2.214:445 Jump to behavior
Source: global traffic TCP traffic: 192.168.2.215:445 Jump to behavior
Source: global traffic TCP traffic: 192.168.2.212:445 Jump to behavior
Source: global traffic TCP traffic: 192.168.2.213:445 Jump to behavior
Source: global traffic TCP traffic: 192.168.2.218:445 Jump to behavior
Source: global traffic TCP traffic: 192.168.2.219:445 Jump to behavior
Source: global traffic TCP traffic: 192.168.2.216:445 Jump to behavior
Source: global traffic TCP traffic: 192.168.2.217:445 Jump to behavior
Source: global traffic TCP traffic: 192.168.2.210:445 Jump to behavior
Source: global traffic TCP traffic: 192.168.2.211:445 Jump to behavior
Source: global traffic TCP traffic: 192.168.2.39:445 Jump to behavior
Source: global traffic TCP traffic: 192.168.2.38:445 Jump to behavior
Source: global traffic TCP traffic: 192.168.2.42:445 Jump to behavior
Source: global traffic TCP traffic: 192.168.2.41:445 Jump to behavior
Source: global traffic TCP traffic: 192.168.2.44:445 Jump to behavior
Source: global traffic TCP traffic: 192.168.2.43:445 Jump to behavior
Source: global traffic TCP traffic: 192.168.2.46:445 Jump to behavior
Source: global traffic TCP traffic: 192.168.2.45:445 Jump to behavior
Source: global traffic TCP traffic: 192.168.2.48:445 Jump to behavior
Source: global traffic TCP traffic: 192.168.2.47:445 Jump to behavior
Source: global traffic TCP traffic: 192.168.2.40:445 Jump to behavior
Source: global traffic TCP traffic: 192.168.2.28:445 Jump to behavior
Source: global traffic TCP traffic: 192.168.2.27:445 Jump to behavior
Source: global traffic TCP traffic: 192.168.2.29:445 Jump to behavior
Source: global traffic TCP traffic: 192.168.2.31:445 Jump to behavior
Source: global traffic TCP traffic: 192.168.2.30:445 Jump to behavior
Source: global traffic TCP traffic: 192.168.2.33:445 Jump to behavior
Source: global traffic TCP traffic: 192.168.2.32:445 Jump to behavior
Source: global traffic TCP traffic: 192.168.2.35:445 Jump to behavior
Source: global traffic TCP traffic: 192.168.2.34:445 Jump to behavior
Source: global traffic TCP traffic: 192.168.2.37:445 Jump to behavior
Source: global traffic TCP traffic: 192.168.2.36:445 Jump to behavior
Source: global traffic TCP traffic: 192.168.2.17:445 Jump to behavior
Source: global traffic TCP traffic: 192.168.2.16:445 Jump to behavior
Source: global traffic TCP traffic: 192.168.2.19:445 Jump to behavior
Source: global traffic TCP traffic: 192.168.2.18:445 Jump to behavior
Source: global traffic TCP traffic: 192.168.2.20:445 Jump to behavior
Source: global traffic TCP traffic: 192.168.2.22:445 Jump to behavior
Source: global traffic TCP traffic: 192.168.2.21:445 Jump to behavior
Source: global traffic TCP traffic: 192.168.2.24:445 Jump to behavior
Source: global traffic TCP traffic: 192.168.2.23:445 Jump to behavior
Source: global traffic TCP traffic: 192.168.2.26:445 Jump to behavior
Source: global traffic TCP traffic: 192.168.2.25:445 Jump to behavior
Source: global traffic TCP traffic: 192.168.2.11:445 Jump to behavior
Source: global traffic TCP traffic: 192.168.2.10:445 Jump to behavior
Source: global traffic TCP traffic: 192.168.2.13:445 Jump to behavior
Source: global traffic TCP traffic: 192.168.2.12:445 Jump to behavior
Source: global traffic TCP traffic: 192.168.2.15:445 Jump to behavior
Source: global traffic TCP traffic: 192.168.2.14:445 Jump to behavior
Source: global traffic TCP traffic: 192.168.2.0:445 Jump to behavior
Source: global traffic TCP traffic: 192.168.2.2:445 Jump to behavior
Source: global traffic TCP traffic: 192.168.2.1:445 Jump to behavior
Source: global traffic TCP traffic: 192.168.2.180:445 Jump to behavior
Source: global traffic TCP traffic: 192.168.2.181:445 Jump to behavior
Source: global traffic TCP traffic: 192.168.2.8:445 Jump to behavior
Source: global traffic TCP traffic: 192.168.2.7:445 Jump to behavior
Source: global traffic TCP traffic: 192.168.2.9:445 Jump to behavior
Source: global traffic TCP traffic: 192.168.2.4:445 Jump to behavior
Source: global traffic TCP traffic: 192.168.2.3:445 Jump to behavior
Source: global traffic TCP traffic: 192.168.2.6:445 Jump to behavior
Source: global traffic TCP traffic: 192.168.2.5:445 Jump to behavior
Source: global traffic TCP traffic: 192.168.2.86:445 Jump to behavior
Source: global traffic TCP traffic: 192.168.2.85:445 Jump to behavior
Source: global traffic TCP traffic: 192.168.2.88:445 Jump to behavior
Source: global traffic TCP traffic: 192.168.2.87:445 Jump to behavior
Source: global traffic TCP traffic: 192.168.2.89:445 Jump to behavior
Source: global traffic TCP traffic: 192.168.2.184:445 Jump to behavior
Source: global traffic TCP traffic: 192.168.2.185:445 Jump to behavior
Source: global traffic TCP traffic: 192.168.2.80:445 Jump to behavior
Source: global traffic TCP traffic: 192.168.2.182:445 Jump to behavior
Source: global traffic TCP traffic: 192.168.2.183:445 Jump to behavior
Source: global traffic TCP traffic: 192.168.2.82:445 Jump to behavior
Source: global traffic TCP traffic: 192.168.2.188:445 Jump to behavior
Source: global traffic TCP traffic: 192.168.2.81:445 Jump to behavior
Source: global traffic TCP traffic: 192.168.2.189:445 Jump to behavior
Source: global traffic TCP traffic: 192.168.2.84:445 Jump to behavior
Source: global traffic TCP traffic: 192.168.2.186:445 Jump to behavior
Source: global traffic TCP traffic: 192.168.2.83:445 Jump to behavior
Source: global traffic TCP traffic: 192.168.2.187:445 Jump to behavior
Source: global traffic TCP traffic: 192.168.2.191:445 Jump to behavior
Source: global traffic TCP traffic: 192.168.2.192:445 Jump to behavior
Source: global traffic TCP traffic: 192.168.2.190:445 Jump to behavior
Source: global traffic TCP traffic: 192.168.2.75:445 Jump to behavior
Source: global traffic TCP traffic: 192.168.2.74:445 Jump to behavior
Source: global traffic TCP traffic: 192.168.2.77:445 Jump to behavior
Source: global traffic TCP traffic: 192.168.2.76:445 Jump to behavior
Source: global traffic TCP traffic: 192.168.2.79:445 Jump to behavior
Source: global traffic TCP traffic: 192.168.2.78:445 Jump to behavior
Source: global traffic TCP traffic: 192.168.2.195:445 Jump to behavior
Source: global traffic TCP traffic: 192.168.2.196:445 Jump to behavior
Source: global traffic TCP traffic: 192.168.2.193:445 Jump to behavior
Source: global traffic TCP traffic: 192.168.2.194:445 Jump to behavior
Source: global traffic TCP traffic: 192.168.2.71:445 Jump to behavior
Source: global traffic TCP traffic: 192.168.2.199:445 Jump to behavior
Source: global traffic TCP traffic: 192.168.2.70:445 Jump to behavior
Source: global traffic TCP traffic: 192.168.2.73:445 Jump to behavior
Source: global traffic TCP traffic: 192.168.2.197:445 Jump to behavior
Source: global traffic TCP traffic: 192.168.2.72:445 Jump to behavior
Source: global traffic TCP traffic: 192.168.2.198:445 Jump to behavior
Source: global traffic TCP traffic: 192.168.2.64:445 Jump to behavior
Source: global traffic TCP traffic: 192.168.2.63:445 Jump to behavior
Source: global traffic TCP traffic: 192.168.2.66:445 Jump to behavior
Source: global traffic TCP traffic: 192.168.2.168:445 Jump to behavior
Source: global traffic TCP traffic: 192.168.2.65:445 Jump to behavior
Source: global traffic TCP traffic: 192.168.2.169:445 Jump to behavior
Source: global traffic TCP traffic: 192.168.2.68:445 Jump to behavior
Source: global traffic TCP traffic: 192.168.2.67:445 Jump to behavior
Source: global traffic TCP traffic: 192.168.2.69:445 Jump to behavior
Source: global traffic TCP traffic: 192.168.2.162:445 Jump to behavior
Source: global traffic TCP traffic: 192.168.2.163:445 Jump to behavior
Source: global traffic TCP traffic: 192.168.2.160:445 Jump to behavior
Source: global traffic TCP traffic: 192.168.2.161:445 Jump to behavior
Source: global traffic TCP traffic: 192.168.2.60:445 Jump to behavior
Source: global traffic TCP traffic: 192.168.2.166:445 Jump to behavior
Source: global traffic TCP traffic: 192.168.2.167:445 Jump to behavior
Source: global traffic TCP traffic: 192.168.2.62:445 Jump to behavior
Source: global traffic TCP traffic: 192.168.2.164:445 Jump to behavior
Source: global traffic TCP traffic: 192.168.2.61:445 Jump to behavior
Source: global traffic TCP traffic: 192.168.2.165:445 Jump to behavior
Source: global traffic TCP traffic: 192.168.2.170:445 Jump to behavior
Source: global traffic TCP traffic: 192.168.2.49:445 Jump to behavior
Source: global traffic TCP traffic: 192.168.2.53:445 Jump to behavior
Source: global traffic TCP traffic: 192.168.2.52:445 Jump to behavior
Source: global traffic TCP traffic: 192.168.2.55:445 Jump to behavior
Source: global traffic TCP traffic: 192.168.2.179:445 Jump to behavior
Source: global traffic TCP traffic: 192.168.2.54:445 Jump to behavior
Source: global traffic TCP traffic: 192.168.2.57:445 Jump to behavior
Source: global traffic TCP traffic: 192.168.2.56:445 Jump to behavior
Source: global traffic TCP traffic: 192.168.2.59:445 Jump to behavior
Source: global traffic TCP traffic: 192.168.2.58:445 Jump to behavior
Source: global traffic TCP traffic: 192.168.2.173:445 Jump to behavior
Source: global traffic TCP traffic: 192.168.2.174:445 Jump to behavior
Source: global traffic TCP traffic: 192.168.2.171:445 Jump to behavior
Source: global traffic TCP traffic: 192.168.2.172:445 Jump to behavior
Source: global traffic TCP traffic: 192.168.2.177:445 Jump to behavior
Source: global traffic TCP traffic: 192.168.2.178:445 Jump to behavior
Source: global traffic TCP traffic: 192.168.2.51:445 Jump to behavior
Source: global traffic TCP traffic: 192.168.2.175:445 Jump to behavior
Source: global traffic TCP traffic: 192.168.2.50:445 Jump to behavior
Source: global traffic TCP traffic: 192.168.2.176:445 Jump to behavior
Source: C:\Users\user\Desktop\msmult64.exe Directory created: C:\Program Files\Read_instructions_To_Decrypt.txt Jump to behavior
Source: C:\Users\user\Desktop\msmult64.exe Directory created: C:\Program Files\7-Zip\Read_instructions_To_Decrypt.txt Jump to behavior
Source: C:\Users\user\Desktop\msmult64.exe Directory created: C:\Program Files\Adobe\Read_instructions_To_Decrypt.txt Jump to behavior
Source: C:\Users\user\Desktop\msmult64.exe Directory created: C:\Program Files\Common Files\Read_instructions_To_Decrypt.txt Jump to behavior
Source: C:\Users\user\Desktop\msmult64.exe Directory created: C:\Program Files\Google\Read_instructions_To_Decrypt.txt Jump to behavior
Source: C:\Users\user\Desktop\msmult64.exe Directory created: C:\Program Files\Internet Explorer\Read_instructions_To_Decrypt.txt Jump to behavior
Source: C:\Users\user\Desktop\msmult64.exe Directory created: C:\Program Files\Microsoft\Read_instructions_To_Decrypt.txt Jump to behavior
Source: C:\Users\user\Desktop\msmult64.exe Directory created: C:\Program Files\Microsoft Office 15\Read_instructions_To_Decrypt.txt Jump to behavior
Source: C:\Users\user\Desktop\msmult64.exe Directory created: C:\Program Files\Mozilla Firefox\Read_instructions_To_Decrypt.txt Jump to behavior
Source: C:\Users\user\Desktop\msmult64.exe Directory created: C:\Program Files\MSBuild\Read_instructions_To_Decrypt.txt Jump to behavior
Source: C:\Users\user\Desktop\msmult64.exe Directory created: C:\Program Files\Reference Assemblies\Read_instructions_To_Decrypt.txt Jump to behavior
Source: C:\Users\user\Desktop\msmult64.exe Directory created: C:\Program Files\Uninstall Information\Read_instructions_To_Decrypt.txt Jump to behavior
Source: C:\Users\user\Desktop\msmult64.exe Directory created: C:\Program Files\7-Zip\Lang\Read_instructions_To_Decrypt.txt Jump to behavior
Source: C:\Users\user\Desktop\msmult64.exe Directory created: C:\Program Files\Adobe\Acrobat DC\Read_instructions_To_Decrypt.txt Jump to behavior
Source: C:\Users\user\Desktop\msmult64.exe Directory created: C:\Program Files\Common Files\Adobe\Read_instructions_To_Decrypt.txt Jump to behavior
Source: C:\Users\user\Desktop\msmult64.exe Directory created: C:\Program Files\Common Files\microsoft shared\Read_instructions_To_Decrypt.txt Jump to behavior
Source: C:\Users\user\Desktop\msmult64.exe Directory created: C:\Program Files\Common Files\Services\Read_instructions_To_Decrypt.txt Jump to behavior
Source: C:\Users\user\Desktop\msmult64.exe Directory created: C:\Program Files\Common Files\System\Read_instructions_To_Decrypt.txt Jump to behavior
Source: C:\Users\user\Desktop\msmult64.exe Directory created: C:\Program Files\Google\Chrome\Read_instructions_To_Decrypt.txt Jump to behavior
Source: C:\Users\user\Desktop\msmult64.exe Directory created: C:\Program Files\Internet Explorer\en-GB\Read_instructions_To_Decrypt.txt Jump to behavior
Source: C:\Users\user\Desktop\msmult64.exe Directory created: C:\Program Files\Internet Explorer\en-US\Read_instructions_To_Decrypt.txt Jump to behavior
Source: C:\Users\user\Desktop\msmult64.exe Directory created: C:\Program Files\Internet Explorer\images\Read_instructions_To_Decrypt.txt Jump to behavior
Source: C:\Users\user\Desktop\msmult64.exe Directory created: C:\Program Files\Internet Explorer\SIGNUP\Read_instructions_To_Decrypt.txt Jump to behavior
Source: C:\Users\user\Desktop\msmult64.exe Directory created: C:\Program Files\Microsoft\OneDrive\Read_instructions_To_Decrypt.txt Jump to behavior
Source: C:\Users\user\Desktop\msmult64.exe Directory created: C:\Program Files\Microsoft Office 15\ClientX64\Read_instructions_To_Decrypt.txt Jump to behavior
Source: C:\Users\user\Desktop\msmult64.exe Directory created: C:\Program Files\Mozilla Firefox\browser\Read_instructions_To_Decrypt.txt Jump to behavior
Source: C:\Users\user\Desktop\msmult64.exe Directory created: C:\Program Files\Mozilla Firefox\defaults\Read_instructions_To_Decrypt.txt Jump to behavior
Source: C:\Users\user\Desktop\msmult64.exe Directory created: C:\Program Files\Mozilla Firefox\fonts\Read_instructions_To_Decrypt.txt Jump to behavior
Source: C:\Users\user\Desktop\msmult64.exe Directory created: C:\Program Files\Mozilla Firefox\gmp-clearkey\Read_instructions_To_Decrypt.txt Jump to behavior
Source: C:\Users\user\Desktop\msmult64.exe Directory created: C:\Program Files\Mozilla Firefox\uninstall\Read_instructions_To_Decrypt.txt Jump to behavior
Source: C:\Users\user\Desktop\msmult64.exe Directory created: C:\Program Files\MSBuild\Microsoft\Read_instructions_To_Decrypt.txt Jump to behavior
Source: C:\Users\user\Desktop\msmult64.exe Directory created: C:\Program Files\Reference Assemblies\Microsoft\Read_instructions_To_Decrypt.txt Jump to behavior
Source: C:\Users\user\Desktop\msmult64.exe Directory created: C:\Program Files\Adobe\Acrobat DC\Acrobat\Read_instructions_To_Decrypt.txt Jump to behavior
Source: C:\Users\user\Desktop\msmult64.exe Directory created: C:\Program Files\Adobe\Acrobat DC\Esl\Read_instructions_To_Decrypt.txt Jump to behavior
Source: C:\Users\user\Desktop\msmult64.exe Directory created: C:\Program Files\Adobe\Acrobat DC\Resource\Read_instructions_To_Decrypt.txt Jump to behavior
Source: C:\Users\user\Desktop\msmult64.exe Directory created: C:\Program Files\Common Files\Adobe\Acrobat\Read_instructions_To_Decrypt.txt Jump to behavior
Source: C:\Users\user\Desktop\msmult64.exe Directory created: C:\Program Files\Common Files\Adobe\HelpCfg\Read_instructions_To_Decrypt.txt Jump to behavior
Source: C:\Users\user\Desktop\msmult64.exe Directory created: C:\Program Files\Common Files\microsoft shared\ClickToRun\Read_instructions_To_Decrypt.txt Jump to behavior
Source: C:\Users\user\Desktop\msmult64.exe Directory created: C:\Program Files\Common Files\microsoft shared\ink\Read_instructions_To_Decrypt.txt Jump to behavior
Source: C:\Users\user\Desktop\msmult64.exe Directory created: C:\Program Files\Common Files\microsoft shared\MSInfo\Read_instructions_To_Decrypt.txt Jump to behavior
Source: C:\Users\user\Desktop\msmult64.exe Directory created: C:\Program Files\Common Files\microsoft shared\Stationery\Read_instructions_To_Decrypt.txt Jump to behavior
Source: C:\Users\user\Desktop\msmult64.exe Directory created: C:\Program Files\Common Files\microsoft shared\TextConv\Read_instructions_To_Decrypt.txt Jump to behavior
Source: C:\Users\user\Desktop\msmult64.exe Directory created: C:\Program Files\Common Files\microsoft shared\Triedit\Read_instructions_To_Decrypt.txt Jump to behavior
Source: C:\Users\user\Desktop\msmult64.exe Directory created: C:\Program Files\Common Files\microsoft shared\VGX\Read_instructions_To_Decrypt.txt Jump to behavior
Source: C:\Users\user\Desktop\msmult64.exe Directory created: C:\Program Files\Common Files\System\ado\Read_instructions_To_Decrypt.txt Jump to behavior
Source: C:\Users\user\Desktop\msmult64.exe Directory created: C:\Program Files\Common Files\System\en-GB\Read_instructions_To_Decrypt.txt Jump to behavior
Source: C:\Users\user\Desktop\msmult64.exe Directory created: C:\Program Files\Common Files\System\en-US\Read_instructions_To_Decrypt.txt Jump to behavior
Source: C:\Users\user\Desktop\msmult64.exe Directory created: C:\Program Files\Common Files\System\msadc\Read_instructions_To_Decrypt.txt Jump to behavior
Source: C:\Users\user\Desktop\msmult64.exe Directory created: C:\Program Files\Common Files\System\Ole DB\Read_instructions_To_Decrypt.txt Jump to behavior
Source: C:\Users\user\Desktop\msmult64.exe Directory created: C:\Program Files\Google\Chrome\Application\Read_instructions_To_Decrypt.txt Jump to behavior
Source: C:\Users\user\Desktop\msmult64.exe Directory created: C:\Program Files\Microsoft\OneDrive\ListSync\Read_instructions_To_Decrypt.txt Jump to behavior
Source: C:\Users\user\Desktop\msmult64.exe Directory created: C:\Program Files\Mozilla Firefox\browser\features\Read_instructions_To_Decrypt.txt Jump to behavior
Source: C:\Users\user\Desktop\msmult64.exe Directory created: C:\Program Files\Mozilla Firefox\browser\VisualElements\Read_instructions_To_Decrypt.txt Jump to behavior
Source: C:\Users\user\Desktop\msmult64.exe Directory created: C:\Program Files\Mozilla Firefox\defaults\pref\Read_instructions_To_Decrypt.txt Jump to behavior
Source: C:\Users\user\Desktop\msmult64.exe Directory created: C:\Program Files\Mozilla Firefox\gmp-clearkey\0.1\Read_instructions_To_Decrypt.txt Jump to behavior
Source: C:\Users\user\Desktop\msmult64.exe Directory created: C:\Program Files\Reference Assemblies\Microsoft\Framework\Read_instructions_To_Decrypt.txt Jump to behavior
Source: C:\Users\user\Desktop\msmult64.exe Directory created: C:\Program Files\Adobe\Acrobat DC\Acrobat\AcroCEF\Read_instructions_To_Decrypt.txt Jump to behavior
Source: C:\Users\user\Desktop\msmult64.exe Directory created: C:\Program Files\Adobe\Acrobat DC\Acrobat\acrocef_1\Read_instructions_To_Decrypt.txt Jump to behavior
Source: C:\Users\user\Desktop\msmult64.exe Directory created: C:\Program Files\Adobe\Acrobat DC\Acrobat\Air\Read_instructions_To_Decrypt.txt Jump to behavior
Source: C:\Users\user\Desktop\msmult64.exe Directory created: C:\Program Files\Adobe\Acrobat DC\Acrobat\Assets\Read_instructions_To_Decrypt.txt Jump to behavior
Source: C:\Users\user\Desktop\msmult64.exe Directory created: C:\Program Files\Adobe\Acrobat DC\Acrobat\Browser\Read_instructions_To_Decrypt.txt Jump to behavior
Source: C:\Users\user\Desktop\msmult64.exe Directory created: C:\Program Files\Adobe\Acrobat DC\Acrobat\DocSettings\Read_instructions_To_Decrypt.txt Jump to behavior
Source: C:\Users\user\Desktop\msmult64.exe Directory created: C:\Program Files\Adobe\Acrobat DC\Acrobat\Javascripts\Read_instructions_To_Decrypt.txt Jump to behavior
Source: C:\Users\user\Desktop\msmult64.exe Directory created: C:\Program Files\Adobe\Acrobat DC\Acrobat\Legal\Read_instructions_To_Decrypt.txt Jump to behavior
Source: C:\Users\user\Desktop\msmult64.exe Directory created: C:\Program Files\Adobe\Acrobat DC\Acrobat\Locale\Read_instructions_To_Decrypt.txt Jump to behavior
Source: C:\Users\user\Desktop\msmult64.exe Directory created: C:\Program Files\Adobe\Acrobat DC\Acrobat\NGL\Read_instructions_To_Decrypt.txt Jump to behavior
Source: C:\Users\user\Desktop\msmult64.exe Directory created: C:\Program Files\Adobe\Acrobat DC\Acrobat\ngl_resources\Read_instructions_To_Decrypt.txt Jump to behavior
Source: C:\Users\user\Desktop\msmult64.exe Directory created: C:\Program Files\Adobe\Acrobat DC\Acrobat\plug_ins\Read_instructions_To_Decrypt.txt Jump to behavior
Source: C:\Users\user\Desktop\msmult64.exe Directory created: C:\Program Files\Adobe\Acrobat DC\Acrobat\plug_ins3d\Read_instructions_To_Decrypt.txt Jump to behavior
Source: C:\Users\user\Desktop\msmult64.exe Directory created: C:\Program Files\Adobe\Acrobat DC\Acrobat\RDCNotificationClient\Read_instructions_To_Decrypt.txt Jump to behavior
Source: C:\Users\user\Desktop\msmult64.exe Directory created: C:\Program Files\Adobe\Acrobat DC\Acrobat\RdrApp\Read_instructions_To_Decrypt.txt Jump to behavior
Source: C:\Users\user\Desktop\msmult64.exe Directory created: C:\Program Files\Adobe\Acrobat DC\Acrobat\Sequences\Read_instructions_To_Decrypt.txt Jump to behavior
Source: C:\Users\user\Desktop\msmult64.exe Directory created: C:\Program Files\Adobe\Acrobat DC\Acrobat\Tracker\Read_instructions_To_Decrypt.txt Jump to behavior
Source: C:\Users\user\Desktop\msmult64.exe Directory created: C:\Program Files\Adobe\Acrobat DC\Acrobat\UIThemes\Read_instructions_To_Decrypt.txt Jump to behavior
Source: C:\Users\user\Desktop\msmult64.exe Directory created: C:\Program Files\Adobe\Acrobat DC\Acrobat\WebResources\Read_instructions_To_Decrypt.txt Jump to behavior
Source: C:\Users\user\Desktop\msmult64.exe Directory created: C:\Program Files\Adobe\Acrobat DC\Acrobat\x86\Read_instructions_To_Decrypt.txt Jump to behavior
Source: C:\Users\user\Desktop\msmult64.exe Directory created: C:\Program Files\Adobe\Acrobat DC\Resource\CMap\Read_instructions_To_Decrypt.txt Jump to behavior
Source: C:\Users\user\Desktop\msmult64.exe Directory created: C:\Program Files\Adobe\Acrobat DC\Resource\Font\Read_instructions_To_Decrypt.txt Jump to behavior
Source: C:\Users\user\Desktop\msmult64.exe Directory created: C:\Program Files\Adobe\Acrobat DC\Resource\SaslPrep\Read_instructions_To_Decrypt.txt Jump to behavior
Source: C:\Users\user\Desktop\msmult64.exe Directory created: C:\Program Files\Adobe\Acrobat DC\Resource\TypeSupport\Read_instructions_To_Decrypt.txt Jump to behavior
Source: C:\Users\user\Desktop\msmult64.exe Directory created: C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\Read_instructions_To_Decrypt.txt Jump to behavior
Source: C:\Users\user\Desktop\msmult64.exe Directory created: C:\Program Files\Common Files\Adobe\Acrobat\DC\Read_instructions_To_Decrypt.txt Jump to behavior
Source: C:\Users\user\Desktop\msmult64.exe Directory created: C:\Program Files\Common Files\Adobe\Acrobat\Setup\Read_instructions_To_Decrypt.txt Jump to behavior
Source: C:\Users\user\Desktop\msmult64.exe Directory created: C:\Program Files\Common Files\Adobe\Acrobat\Setup Files\Read_instructions_To_Decrypt.txt Jump to behavior
Source: C:\Users\user\Desktop\msmult64.exe Directory created: C:\Program Files\Common Files\Adobe\HelpCfg\en_US\Read_instructions_To_Decrypt.txt Jump to behavior
Source: C:\Users\user\Desktop\msmult64.exe Directory created: C:\Program Files\Common Files\microsoft shared\ClickToRun\OnlineInteraction\Read_instructions_To_Decrypt.txt Jump to behavior
Source: C:\Users\user\Desktop\msmult64.exe Directory created: C:\Program Files\Common Files\microsoft shared\ink\ar-SA\Read_instructions_To_Decrypt.txt Jump to behavior
Source: C:\Users\user\Desktop\msmult64.exe Directory created: C:\Program Files\Common Files\microsoft shared\ink\bg-BG\Read_instructions_To_Decrypt.txt Jump to behavior
Source: C:\Users\user\Desktop\msmult64.exe Directory created: C:\Program Files\Common Files\microsoft shared\ink\cs-CZ\Read_instructions_To_Decrypt.txt Jump to behavior
Source: C:\Users\user\Desktop\msmult64.exe Directory created: C:\Program Files\Common Files\microsoft shared\ink\da-DK\Read_instructions_To_Decrypt.txt Jump to behavior
Source: C:\Users\user\Desktop\msmult64.exe Directory created: C:\Program Files\Common Files\microsoft shared\ink\de-DE\Read_instructions_To_Decrypt.txt Jump to behavior
Source: C:\Users\user\Desktop\msmult64.exe Directory created: C:\Program Files\Common Files\microsoft shared\ink\el-GR\Read_instructions_To_Decrypt.txt Jump to behavior
Source: C:\Users\user\Desktop\msmult64.exe Directory created: C:\Program Files\Common Files\microsoft shared\ink\en-GB\Read_instructions_To_Decrypt.txt Jump to behavior
Source: C:\Users\user\Desktop\msmult64.exe Directory created: C:\Program Files\Common Files\microsoft shared\ink\en-US\Read_instructions_To_Decrypt.txt Jump to behavior
Source: C:\Users\user\Desktop\msmult64.exe Directory created: C:\Program Files\Common Files\microsoft shared\ink\es-ES\Read_instructions_To_Decrypt.txt Jump to behavior
Source: C:\Users\user\Desktop\msmult64.exe Directory created: C:\Program Files\Common Files\microsoft shared\ink\es-MX\Read_instructions_To_Decrypt.txt Jump to behavior
Source: C:\Users\user\Desktop\msmult64.exe Directory created: C:\Program Files\Common Files\microsoft shared\ink\et-EE\Read_instructions_To_Decrypt.txt Jump to behavior
Source: C:\Users\user\Desktop\msmult64.exe Directory created: C:\Program Files\Common Files\microsoft shared\ink\fi-FI\Read_instructions_To_Decrypt.txt Jump to behavior
Source: C:\Users\user\Desktop\msmult64.exe Directory created: C:\Program Files\Common Files\microsoft shared\ink\fr-CA\Read_instructions_To_Decrypt.txt Jump to behavior
Source: C:\Users\user\Desktop\msmult64.exe Directory created: C:\Program Files\Common Files\microsoft shared\ink\fr-FR\Read_instructions_To_Decrypt.txt Jump to behavior
Source: C:\Users\user\Desktop\msmult64.exe Directory created: C:\Program Files\Common Files\microsoft shared\ink\fsdefinitions\Read_instructions_To_Decrypt.txt Jump to behavior
Source: C:\Users\user\Desktop\msmult64.exe Directory created: C:\Program Files\Common Files\microsoft shared\ink\he-IL\Read_instructions_To_Decrypt.txt Jump to behavior
Source: C:\Users\user\Desktop\msmult64.exe Directory created: C:\Program Files\Common Files\microsoft shared\ink\hr-HR\Read_instructions_To_Decrypt.txt Jump to behavior
Source: C:\Users\user\Desktop\msmult64.exe Directory created: C:\Program Files\Common Files\microsoft shared\ink\hu-HU\Read_instructions_To_Decrypt.txt Jump to behavior
Source: C:\Users\user\Desktop\msmult64.exe Directory created: C:\Program Files\Common Files\microsoft shared\ink\HWRCustomization\Read_instructions_To_Decrypt.txt Jump to behavior
Source: C:\Users\user\Desktop\msmult64.exe Directory created: C:\Program Files\Common Files\microsoft shared\ink\it-IT\Read_instructions_To_Decrypt.txt Jump to behavior
Source: C:\Users\user\Desktop\msmult64.exe Directory created: C:\Program Files\Common Files\microsoft shared\ink\ja-JP\Read_instructions_To_Decrypt.txt Jump to behavior
Source: C:\Users\user\Desktop\msmult64.exe Directory created: C:\Program Files\Common Files\microsoft shared\ink\ko-KR\Read_instructions_To_Decrypt.txt Jump to behavior
Source: C:\Users\user\Desktop\msmult64.exe Directory created: C:\Program Files\Common Files\microsoft shared\ink\LanguageModel\Read_instructions_To_Decrypt.txt Jump to behavior
Source: C:\Users\user\Desktop\msmult64.exe Directory created: C:\Program Files\Common Files\microsoft shared\ink\lt-LT\Read_instructions_To_Decrypt.txt Jump to behavior
Source: C:\Users\user\Desktop\msmult64.exe Directory created: C:\Program Files\Common Files\microsoft shared\ink\lv-LV\Read_instructions_To_Decrypt.txt Jump to behavior
Source: C:\Users\user\Desktop\msmult64.exe Directory created: C:\Program Files\Common Files\microsoft shared\ink\nb-NO\Read_instructions_To_Decrypt.txt Jump to behavior
Source: C:\Users\user\Desktop\msmult64.exe Directory created: C:\Program Files\Common Files\microsoft shared\ink\nl-NL\Read_instructions_To_Decrypt.txt Jump to behavior
Source: C:\Users\user\Desktop\msmult64.exe Directory created: C:\Program Files\Common Files\microsoft shared\ink\pl-PL\Read_instructions_To_Decrypt.txt Jump to behavior
Source: C:\Users\user\Desktop\msmult64.exe Directory created: C:\Program Files\Common Files\microsoft shared\ink\pt-BR\Read_instructions_To_Decrypt.txt Jump to behavior
Source: C:\Users\user\Desktop\msmult64.exe Directory created: C:\Program Files\Common Files\microsoft shared\ink\pt-PT\Read_instructions_To_Decrypt.txt Jump to behavior
Source: C:\Users\user\Desktop\msmult64.exe Directory created: C:\Program Files\Common Files\microsoft shared\ink\ro-RO\Read_instructions_To_Decrypt.txt Jump to behavior
Source: C:\Users\user\Desktop\msmult64.exe Directory created: C:\Program Files\Common Files\microsoft shared\ink\ru-RU\Read_instructions_To_Decrypt.txt Jump to behavior
Source: C:\Users\user\Desktop\msmult64.exe Directory created: C:\Program Files\Common Files\microsoft shared\ink\sk-SK\Read_instructions_To_Decrypt.txt Jump to behavior
Source: C:\Users\user\Desktop\msmult64.exe Directory created: C:\Program Files\Common Files\microsoft shared\ink\sl-SI\Read_instructions_To_Decrypt.txt Jump to behavior
Source: C:\Users\user\Desktop\msmult64.exe Directory created: C:\Program Files\Common Files\microsoft shared\ink\sr-Latn-RS\Read_instructions_To_Decrypt.txt Jump to behavior
Source: C:\Users\user\Desktop\msmult64.exe Directory created: C:\Program Files\Common Files\microsoft shared\ink\sv-SE\Read_instructions_To_Decrypt.txt Jump to behavior
Source: C:\Users\user\Desktop\msmult64.exe Directory created: C:\Program Files\Common Files\microsoft shared\ink\th-TH\Read_instructions_To_Decrypt.txt Jump to behavior
Source: C:\Users\user\Desktop\msmult64.exe Directory created: C:\Program Files\Common Files\microsoft shared\ink\tr-TR\Read_instructions_To_Decrypt.txt Jump to behavior
Source: C:\Users\user\Desktop\msmult64.exe Directory created: C:\Program Files\Common Files\microsoft shared\ink\uk-UA\Read_instructions_To_Decrypt.txt Jump to behavior
Source: C:\Users\user\Desktop\msmult64.exe Directory created: C:\Program Files\Common Files\microsoft shared\ink\zh-CN\Read_instructions_To_Decrypt.txt Jump to behavior
Source: C:\Users\user\Desktop\msmult64.exe Directory created: C:\Program Files\Common Files\microsoft shared\ink\zh-TW\Read_instructions_To_Decrypt.txt Jump to behavior
Source: C:\Users\user\Desktop\msmult64.exe Directory created: C:\Program Files\Common Files\microsoft shared\MSInfo\en-GB\Read_instructions_To_Decrypt.txt Jump to behavior
Source: C:\Users\user\Desktop\msmult64.exe Directory created: C:\Program Files\Common Files\microsoft shared\MSInfo\en-US\Read_instructions_To_Decrypt.txt Jump to behavior
Source: C:\Users\user\Desktop\msmult64.exe Directory created: C:\Program Files\Common Files\microsoft shared\TextConv\en-US\Read_instructions_To_Decrypt.txt Jump to behavior
Source: C:\Users\user\Desktop\msmult64.exe Directory created: C:\Program Files\Common Files\microsoft shared\Triedit\en-US\Read_instructions_To_Decrypt.txt Jump to behavior
Source: C:\Users\user\Desktop\msmult64.exe Directory created: C:\Program Files\Common Files\System\ado\en-US\Read_instructions_To_Decrypt.txt Jump to behavior
Source: C:\Users\user\Desktop\msmult64.exe Directory created: C:\Program Files\Common Files\System\msadc\en-US\Read_instructions_To_Decrypt.txt Jump to behavior
Source: C:\Users\user\Desktop\msmult64.exe Directory created: C:\Program Files\Common Files\System\Ole DB\en-US\Read_instructions_To_Decrypt.txt Jump to behavior
Source: C:\Users\user\Desktop\msmult64.exe Directory created: C:\Program Files\Google\Chrome\Application\117.0.5938.132\Read_instructions_To_Decrypt.txt Jump to behavior
Source: C:\Users\user\Desktop\msmult64.exe Directory created: C:\Program Files\Google\Chrome\Application\SetupMetrics\Read_instructions_To_Decrypt.txt Jump to behavior
Source: C:\Users\user\Desktop\msmult64.exe Directory created: C:\Program Files\Microsoft\OneDrive\ListSync\settings\Read_instructions_To_Decrypt.txt Jump to behavior
Source: C:\Users\user\Desktop\msmult64.exe Directory created: C:\Program Files\Reference Assemblies\Microsoft\Framework\v3.0\Read_instructions_To_Decrypt.txt Jump to behavior
Source: C:\Users\user\Desktop\msmult64.exe Directory created: C:\Program Files\Reference Assemblies\Microsoft\Framework\v3.5\Read_instructions_To_Decrypt.txt Jump to behavior
Source: C:\Users\user\Desktop\msmult64.exe Directory created: C:\Program Files\Adobe\Acrobat DC\Acrobat\AcroCEF\locales\Read_instructions_To_Decrypt.txt Jump to behavior
Source: C:\Users\user\Desktop\msmult64.exe Directory created: C:\Program Files\Adobe\Acrobat DC\Acrobat\AcroCEF\swiftshader\Read_instructions_To_Decrypt.txt Jump to behavior
Source: C:\Users\user\Desktop\msmult64.exe Directory created: C:\Program Files\Adobe\Acrobat DC\Acrobat\acrocef_1\locales\Read_instructions_To_Decrypt.txt Jump to behavior
Source: C:\Users\user\Desktop\msmult64.exe Directory created: C:\Program Files\Adobe\Acrobat DC\Acrobat\acrocef_1\swiftshader\Read_instructions_To_Decrypt.txt Jump to behavior
Source: C:\Users\user\Desktop\msmult64.exe Directory created: C:\Program Files\Adobe\Acrobat DC\Acrobat\Browser\WCChromeExtn\Read_instructions_To_Decrypt.txt Jump to behavior
Source: C:\Users\user\Desktop\msmult64.exe Directory created: C:\Program Files\Adobe\Acrobat DC\Acrobat\DocSettings\Redaction\Read_instructions_To_Decrypt.txt Jump to behavior
Source: C:\Users\user\Desktop\msmult64.exe Directory created: C:\Program Files\Adobe\Acrobat DC\Acrobat\Legal\ar_AE\Read_instructions_To_Decrypt.txt Jump to behavior
Source: C:\Users\user\Desktop\msmult64.exe Directory created: C:\Program Files\Adobe\Acrobat DC\Acrobat\Legal\cs_CZ\Read_instructions_To_Decrypt.txt Jump to behavior
Source: C:\Users\user\Desktop\msmult64.exe Directory created: C:\Program Files\Adobe\Acrobat DC\Acrobat\Legal\da_DK\Read_instructions_To_Decrypt.txt Jump to behavior
Source: C:\Users\user\Desktop\msmult64.exe Directory created: C:\Program Files\Adobe\Acrobat DC\Acrobat\Legal\de_DE\Read_instructions_To_Decrypt.txt Jump to behavior
Source: C:\Users\user\Desktop\msmult64.exe Directory created: C:\Program Files\Adobe\Acrobat DC\Acrobat\Legal\el_GR\Read_instructions_To_Decrypt.txt Jump to behavior
Source: C:\Users\user\Desktop\msmult64.exe Directory created: C:\Program Files\Adobe\Acrobat DC\Acrobat\Legal\ENU\Read_instructions_To_Decrypt.txt Jump to behavior
Source: C:\Users\user\Desktop\msmult64.exe Directory created: C:\Program Files\Adobe\Acrobat DC\Acrobat\Legal\en_AE\Read_instructions_To_Decrypt.txt Jump to behavior
Source: C:\Users\user\Desktop\msmult64.exe Directory created: C:\Program Files\Adobe\Acrobat DC\Acrobat\Legal\en_GB\Read_instructions_To_Decrypt.txt Jump to behavior
Source: C:\Users\user\Desktop\msmult64.exe Directory created: C:\Program Files\Adobe\Acrobat DC\Acrobat\Legal\en_IL\Read_instructions_To_Decrypt.txt Jump to behavior
Source: C:\Users\user\Desktop\msmult64.exe Directory created: C:\Program Files\Adobe\Acrobat DC\Acrobat\Legal\en_US\Read_instructions_To_Decrypt.txt Jump to behavior
Source: C:\Users\user\Desktop\msmult64.exe Directory created: C:\Program Files\Adobe\Acrobat DC\Acrobat\Legal\es_ES\Read_instructions_To_Decrypt.txt Jump to behavior
Source: C:\Users\user\Desktop\msmult64.exe Directory created: C:\Program Files\Adobe\Acrobat DC\Acrobat\Legal\fi_FI\Read_instructions_To_Decrypt.txt Jump to behavior
Source: C:\Users\user\Desktop\msmult64.exe Directory created: C:\Program Files\Adobe\Acrobat DC\Acrobat\Legal\fr_FR\Read_instructions_To_Decrypt.txt Jump to behavior
Source: C:\Users\user\Desktop\msmult64.exe Directory created: C:\Program Files\Adobe\Acrobat DC\Acrobat\Legal\fr_MA\Read_instructions_To_Decrypt.txt Jump to behavior
Source: C:\Users\user\Desktop\msmult64.exe Directory created: C:\Program Files\Adobe\Acrobat DC\Acrobat\Legal\he_IL\Read_instructions_To_Decrypt.txt Jump to behavior
Source: C:\Users\user\Desktop\msmult64.exe Directory created: C:\Program Files\Adobe\Acrobat DC\Acrobat\Legal\hu_HU\Read_instructions_To_Decrypt.txt Jump to behavior
Source: C:\Users\user\Desktop\msmult64.exe Directory created: C:\Program Files\Adobe\Acrobat DC\Acrobat\Legal\it_IT\Read_instructions_To_Decrypt.txt Jump to behavior
Source: C:\Users\user\Desktop\msmult64.exe Directory created: C:\Program Files\Adobe\Acrobat DC\Acrobat\Legal\ja_JP\Read_instructions_To_Decrypt.txt Jump to behavior
Source: C:\Users\user\Desktop\msmult64.exe Directory created: C:\Program Files\Adobe\Acrobat DC\Acrobat\Legal\ko_KR\Read_instructions_To_Decrypt.txt Jump to behavior
Source: C:\Users\user\Desktop\msmult64.exe Directory created: C:\Program Files\Adobe\Acrobat DC\Acrobat\Legal\nb_NO\Read_instructions_To_Decrypt.txt Jump to behavior
Source: C:\Users\user\Desktop\msmult64.exe Directory created: C:\Program Files\Adobe\Acrobat DC\Acrobat\Legal\nl_NL\Read_instructions_To_Decrypt.txt Jump to behavior
Source: C:\Users\user\Desktop\msmult64.exe Directory created: C:\Program Files\Adobe\Acrobat DC\Acrobat\Legal\pl_PL\Read_instructions_To_Decrypt.txt Jump to behavior
Source: C:\Users\user\Desktop\msmult64.exe Directory created: C:\Program Files\Adobe\Acrobat DC\Acrobat\Legal\pt_BR\Read_instructions_To_Decrypt.txt Jump to behavior
Source: C:\Users\user\Desktop\msmult64.exe Directory created: C:\Program Files\Adobe\Acrobat DC\Acrobat\Legal\ru_RU\Read_instructions_To_Decrypt.txt Jump to behavior
Source: C:\Users\user\Desktop\msmult64.exe Directory created: C:\Program Files\Adobe\Acrobat DC\Acrobat\Legal\sk_SK\Read_instructions_To_Decrypt.txt Jump to behavior
Source: C:\Users\user\Desktop\msmult64.exe Directory created: C:\Program Files\Adobe\Acrobat DC\Acrobat\Legal\sl_SI\Read_instructions_To_Decrypt.txt Jump to behavior
Source: C:\Users\user\Desktop\msmult64.exe Directory created: C:\Program Files\Adobe\Acrobat DC\Acrobat\Legal\sv_SE\Read_instructions_To_Decrypt.txt Jump to behavior
Source: C:\Users\user\Desktop\msmult64.exe Directory created: C:\Program Files\Adobe\Acrobat DC\Acrobat\Legal\tr_TR\Read_instructions_To_Decrypt.txt Jump to behavior
Source: C:\Users\user\Desktop\msmult64.exe Directory created: C:\Program Files\Adobe\Acrobat DC\Acrobat\Legal\uk_UA\Read_instructions_To_Decrypt.txt Jump to behavior
Source: C:\Users\user\Desktop\msmult64.exe Directory created: C:\Program Files\Adobe\Acrobat DC\Acrobat\Legal\zh_CN\Read_instructions_To_Decrypt.txt Jump to behavior
Source: C:\Users\user\Desktop\msmult64.exe Directory created: C:\Program Files\Adobe\Acrobat DC\Acrobat\Legal\zh_TW\Read_instructions_To_Decrypt.txt Jump to behavior
Source: C:\Users\user\Desktop\msmult64.exe Directory created: C:\Program Files\Adobe\Acrobat DC\Acrobat\Locale\en_US\Read_instructions_To_Decrypt.txt Jump to behavior
Source: C:\Users\user\Desktop\msmult64.exe Directory created: C:\Program Files\Adobe\Acrobat DC\Acrobat\NGL\cefWorkflow\Read_instructions_To_Decrypt.txt Jump to behavior
Source: C:\Users\user\Desktop\msmult64.exe Directory created: C:\Program Files\Adobe\Acrobat DC\Acrobat\ngl_resources\resources\Read_instructions_To_Decrypt.txt Jump to behavior
Source: C:\Users\user\Desktop\msmult64.exe Directory created: C:\Program Files\Adobe\Acrobat DC\Acrobat\plug_ins\AcroForm\Read_instructions_To_Decrypt.txt Jump to behavior
Source: C:\Users\user\Desktop\msmult64.exe Directory created: C:\Program Files\Adobe\Acrobat DC\Acrobat\plug_ins\Annotations\Read_instructions_To_Decrypt.txt Jump to behavior
Source: C:\Users\user\Desktop\msmult64.exe Directory created: C:\Program Files\Adobe\Acrobat DC\Acrobat\plug_ins\Multimedia\Read_instructions_To_Decrypt.txt Jump to behavior
Source: C:\Users\user\Desktop\msmult64.exe Directory created: C:\Program Files\Adobe\Acrobat DC\Acrobat\plug_ins\pi_brokers\Read_instructions_To_Decrypt.txt Jump to behavior
Source: C:\Users\user\Desktop\msmult64.exe Directory created: C:\Program Files\Adobe\Acrobat DC\Acrobat\plug_ins3d\prc\Read_instructions_To_Decrypt.txt Jump to behavior
Source: C:\Users\user\Desktop\msmult64.exe Directory created: C:\Program Files\Adobe\Acrobat DC\Acrobat\RdrApp\ENU\Read_instructions_To_Decrypt.txt Jump to behavior
Source: C:\Users\user\Desktop\msmult64.exe Directory created: C:\Program Files\Adobe\Acrobat DC\Acrobat\Sequences\ENU\Read_instructions_To_Decrypt.txt Jump to behavior
Source: C:\Users\user\Desktop\msmult64.exe Directory created: C:\Program Files\Adobe\Acrobat DC\Acrobat\WebResources\Resource0\Read_instructions_To_Decrypt.txt Jump to behavior
Source: C:\Users\user\Desktop\msmult64.exe Directory created: C:\Program Files\Adobe\Acrobat DC\Acrobat\x86\Acrobat\Read_instructions_To_Decrypt.txt Jump to behavior
Source: C:\Users\user\Desktop\msmult64.exe Directory created: C:\Program Files\Adobe\Acrobat DC\Resource\Font\Pfm\Read_instructions_To_Decrypt.txt Jump to behavior
Source: C:\Users\user\Desktop\msmult64.exe Directory created: C:\Program Files\Adobe\Acrobat DC\Resource\TypeSupport\Unicode\Read_instructions_To_Decrypt.txt Jump to behavior
Source: C:\Users\user\Desktop\msmult64.exe Directory created: C:\Program Files\Common Files\Adobe\Acrobat\DC\Linguistics\Read_instructions_To_Decrypt.txt Jump to behavior
Source: C:\Users\user\Desktop\msmult64.exe Directory created: C:\Program Files\Common Files\Adobe\Acrobat\Setup\{AC76BA86-1033-1033-7760-BC15014EA700}\Read_instructions_To_Decrypt.txt Jump to behavior
Source: C:\Users\user\Desktop\msmult64.exe Directory created: C:\Program Files\Common Files\Adobe\Acrobat\Setup Files\{AC76BA86-1033-1033-7760-BC15014EA700}\Read_instructions_To_Decrypt.txt Jump to behavior
Source: C:\Users\user\Desktop\msmult64.exe Directory created: C:\Program Files\Common Files\microsoft shared\ink\fsdefinitions\auxpad\Read_instructions_To_Decrypt.txt Jump to behavior
Source: C:\Users\user\Desktop\msmult64.exe Directory created: C:\Program Files\Common Files\microsoft shared\ink\fsdefinitions\insert\Read_instructions_To_Decrypt.txt Jump to behavior
Source: C:\Users\user\Desktop\msmult64.exe Directory created: C:\Program Files\Common Files\microsoft shared\ink\fsdefinitions\keypad\Read_instructions_To_Decrypt.txt Jump to behavior
Source: C:\Users\user\Desktop\msmult64.exe Directory created: C:\Program Files\Common Files\microsoft shared\ink\fsdefinitions\main\Read_instructions_To_Decrypt.txt Jump to behavior
Source: C:\Users\user\Desktop\msmult64.exe Directory created: C:\Program Files\Common Files\microsoft shared\ink\fsdefinitions\oskclearui\Read_instructions_To_Decrypt.txt Jump to behavior
Source: C:\Users\user\Desktop\msmult64.exe Directory created: C:\Program Files\Common Files\microsoft shared\ink\fsdefinitions\oskmenu\Read_instructions_To_Decrypt.txt Jump to behavior
Source: C:\Users\user\Desktop\msmult64.exe Directory created: C:\Program Files\Common Files\microsoft shared\ink\fsdefinitions\osknav\Read_instructions_To_Decrypt.txt Jump to behavior
Source: C:\Users\user\Desktop\msmult64.exe Directory created: C:\Program Files\Common Files\microsoft shared\ink\fsdefinitions\osknumpad\Read_instructions_To_Decrypt.txt Jump to behavior
Source: C:\Users\user\Desktop\msmult64.exe Directory created: C:\Program Files\Common Files\microsoft shared\ink\fsdefinitions\oskpred\Read_instructions_To_Decrypt.txt Jump to behavior
Source: C:\Users\user\Desktop\msmult64.exe Directory created: C:\Program Files\Common Files\microsoft shared\ink\fsdefinitions\symbols\Read_instructions_To_Decrypt.txt Jump to behavior
Source: C:\Users\user\Desktop\msmult64.exe Directory created: C:\Program Files\Google\Chrome\Application\117.0.5938.132\default_apps\Read_instructions_To_Decrypt.txt Jump to behavior
Source: C:\Users\user\Desktop\msmult64.exe Directory created: C:\Program Files\Google\Chrome\Application\117.0.5938.132\Extensions\Read_instructions_To_Decrypt.txt Jump to behavior
Source: C:\Users\user\Desktop\msmult64.exe Directory created: C:\Program Files\Google\Chrome\Application\117.0.5938.132\Installer\Read_instructions_To_Decrypt.txt Jump to behavior
Source: C:\Users\user\Desktop\msmult64.exe Directory created: C:\Program Files\Google\Chrome\Application\117.0.5938.132\Locales\Read_instructions_To_Decrypt.txt Jump to behavior
Source: C:\Users\user\Desktop\msmult64.exe Directory created: C:\Program Files\Google\Chrome\Application\117.0.5938.132\MEIPreload\Read_instructions_To_Decrypt.txt Jump to behavior
Source: C:\Users\user\Desktop\msmult64.exe Directory created: C:\Program Files\Google\Chrome\Application\117.0.5938.132\VisualElements\Read_instructions_To_Decrypt.txt Jump to behavior
Source: C:\Users\user\Desktop\msmult64.exe Directory created: C:\Program Files\Google\Chrome\Application\117.0.5938.132\WidevineCdm\Read_instructions_To_Decrypt.txt Jump to behavior
Source: C:\Users\user\Desktop\msmult64.exe Directory created: C:\Program Files\Reference Assemblies\Microsoft\Framework\v3.0\RedistList\Read_instructions_To_Decrypt.txt Jump to behavior
Source: C:\Users\user\Desktop\msmult64.exe Directory created: C:\Program Files\Reference Assemblies\Microsoft\Framework\v3.5\RedistList\Read_instructions_To_Decrypt.txt Jump to behavior
Source: unknown HTTPS traffic detected: 40.68.123.157:443 -> 192.168.2.4:49984 version: TLS 1.2
Source: unknown HTTPS traffic detected: 40.68.123.157:443 -> 192.168.2.4:49990 version: TLS 1.2
Source: unknown HTTPS traffic detected: 173.222.162.32:443 -> 192.168.2.4:49991 version: TLS 1.2
Source: msmult64.exe Static PE information: HIGH_ENTROPY_VA, DYNAMIC_BASE, NX_COMPAT, TERMINAL_SERVER_AWARE

Spreading

barindex
Source: C:\Users\user\Desktop\msmult64.exe System file written: C:\Program Files (x86)\Java\jre-1.8\Welcome.html Jump to behavior
Source: C:\Users\user\Desktop\msmult64.exe System file written: C:\Program Files (x86)\Microsoft Office\Office16\OSPP.HTM Jump to behavior
Source: C:\Users\user\Desktop\msmult64.exe Code function: 0_2_00007FF7601A8D70 FindFirstFileW,FindNextFileW,FindClose,_invalid_parameter_noinfo_noreturn,_invalid_parameter_noinfo_noreturn,_invalid_parameter_noinfo_noreturn, 0_2_00007FF7601A8D70
Source: C:\Users\user\Desktop\msmult64.exe Code function: 0_2_00007FF7601A6E20 GetLogicalDriveStringsW,GetLogicalDriveStringsW, 0_2_00007FF7601A6E20
Source: Joe Sandbox View JA3 fingerprint: 28a2c9bd18a11de089ef85a160da29e4
Source: global traffic HTTP traffic detected: POST /threshold/xls.aspx HTTP/1.1Origin: https://www.bing.comReferer: https://www.bing.com/AS/API/WindowsCortanaPane/V2/InitAccept: */*Accept-Language: en-CHContent-type: text/xmlX-Agent-DeviceId: 01000A4109000CC6X-BM-CBT: 1696420817X-BM-DateFormat: dd/MM/yyyyX-BM-DeviceDimensions: 784x984X-BM-DeviceDimensionsLogical: 784x984X-BM-DeviceScale: 100X-BM-DTZ: 60X-BM-Market: CHX-BM-Theme: 000000;0078d7X-BM-WindowsFlights: FX:117B9872,FX:119E26AD,FX:11C0E96C,FX:11C6E5C2,FX:11C7EB6A,FX:11C9408A,FX:11C940DB,FX:11CB9A9F,FX:11CB9AC1,FX:11CC111C,FX:11D5BFCD,FX:11DF5B12,FX:11DF5B75,FX:1240931B,FX:124B38D0,FX:127FC878,FX:1283FFE8,FX:12840617,FX:128979F9,FX:128EBD7E,FX:129135BB,FX:129E053F,FX:12A74DB5,FX:12AB734D,FX:12B8450E,FX:12BD6E73,FX:12C3331B,FX:12C7D66EX-Device-ClientSession: 0912CF9094994CFA88DE52C6FB19D4E1X-Device-isOptin: falseX-Device-MachineId: {92C86F7C-DB2B-4F6A-95AD-98B4A2AE008A}X-Device-OSSKU: 48X-Device-Touch: falseX-DeviceID: 01000A4109000CC6X-MSEdge-ExternalExp: bfbwsbrs0830tf,d-thshldspcl40,msbdsborgv2co,msbwdsbi920t1,spofglclicksh-c2,webtophit0r_t,wsbmsaqfuxtc,wsbqfasmsall_t,wsbqfminiserp400,wsbref-tX-MSEdge-ExternalExpType: JointCoordX-PositionerType: DesktopX-Search-AppId: Microsoft.Windows.Cortana_cw5n1h2txyewy!CortanaUIX-Search-CortanaAvailableCapabilities: NoneX-Search-SafeSearch: ModerateX-Search-TimeZone: Bias=0; DaylightBias=-60; TimeZoneKeyName=GMT Standard TimeX-UserAgeClass: UnknownAccept-Encoding: gzip, deflate, brUser-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64; Cortana 1.14.7.19041; 10.0.0.0.19045.2006) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/70.0.3538.102 Safari/537.36 Edge/18.19045Host: www.bing.comContent-Length: 2232Connection: Keep-AliveCache-Control: no-cacheCookie: MUID=6666694284484FA1B35CCB433D42E997; _SS=SID=193A581F83766B4319784BBF829B6A16&CPID=1696420820117&AC=1&CPH=e5c79613&CBV=39942242; _EDGE_S=SID=193A581F83766B4319784BBF829B6A16; SRCHUID=V=2&GUID=BA43D82178364AEA9C1EE6C32BE93416&dmnchg=1; SRCHD=AF=NOFORM; SRCHUSR=DOB=20231003; SRCHHPGUSR=SRCHLANG=en&LUT=1696420817741&IPMH=425591ef&IPMID=1696420817913&HV=1696417346; ANON=A=6D8F9DF00282E660E425530EFFFFFFFF; CortanaAppUID=4C9C2B2D0465FD7A42C74C7E93CFB630; MUIDB=6666694284484FA1B35CCB433D42E997
Source: unknown TCP traffic detected without corresponding DNS query: 173.222.162.32
Source: unknown TCP traffic detected without corresponding DNS query: 104.46.162.224
Source: unknown TCP traffic detected without corresponding DNS query: 173.222.162.32
Source: unknown TCP traffic detected without corresponding DNS query: 40.68.123.157
Source: unknown TCP traffic detected without corresponding DNS query: 40.68.123.157
Source: unknown TCP traffic detected without corresponding DNS query: 40.68.123.157
Source: unknown TCP traffic detected without corresponding DNS query: 40.68.123.157
Source: unknown TCP traffic detected without corresponding DNS query: 40.68.123.157
Source: unknown TCP traffic detected without corresponding DNS query: 40.68.123.157
Source: unknown TCP traffic detected without corresponding DNS query: 40.68.123.157
Source: unknown TCP traffic detected without corresponding DNS query: 40.68.123.157
Source: unknown TCP traffic detected without corresponding DNS query: 40.68.123.157
Source: unknown TCP traffic detected without corresponding DNS query: 40.68.123.157
Source: unknown TCP traffic detected without corresponding DNS query: 40.68.123.157
Source: unknown TCP traffic detected without corresponding DNS query: 40.68.123.157
Source: unknown TCP traffic detected without corresponding DNS query: 40.68.123.157
Source: unknown TCP traffic detected without corresponding DNS query: 40.68.123.157
Source: unknown TCP traffic detected without corresponding DNS query: 40.68.123.157
Source: unknown TCP traffic detected without corresponding DNS query: 40.68.123.157
Source: unknown TCP traffic detected without corresponding DNS query: 40.68.123.157
Source: unknown TCP traffic detected without corresponding DNS query: 40.68.123.157
Source: unknown TCP traffic detected without corresponding DNS query: 40.68.123.157
Source: unknown TCP traffic detected without corresponding DNS query: 40.68.123.157
Source: unknown TCP traffic detected without corresponding DNS query: 40.68.123.157
Source: unknown TCP traffic detected without corresponding DNS query: 40.68.123.157
Source: unknown TCP traffic detected without corresponding DNS query: 40.68.123.157
Source: unknown TCP traffic detected without corresponding DNS query: 40.68.123.157
Source: unknown TCP traffic detected without corresponding DNS query: 40.68.123.157
Source: unknown TCP traffic detected without corresponding DNS query: 40.68.123.157
Source: unknown TCP traffic detected without corresponding DNS query: 40.68.123.157
Source: unknown TCP traffic detected without corresponding DNS query: 40.68.123.157
Source: unknown TCP traffic detected without corresponding DNS query: 23.207.202.32
Source: unknown TCP traffic detected without corresponding DNS query: 23.207.202.32
Source: unknown TCP traffic detected without corresponding DNS query: 23.207.202.32
Source: unknown TCP traffic detected without corresponding DNS query: 23.207.202.32
Source: unknown TCP traffic detected without corresponding DNS query: 173.222.162.32
Source: unknown TCP traffic detected without corresponding DNS query: 173.222.162.32
Source: unknown TCP traffic detected without corresponding DNS query: 173.222.162.32
Source: unknown TCP traffic detected without corresponding DNS query: 173.222.162.32
Source: unknown TCP traffic detected without corresponding DNS query: 173.222.162.32
Source: unknown TCP traffic detected without corresponding DNS query: 173.222.162.32
Source: unknown TCP traffic detected without corresponding DNS query: 173.222.162.32
Source: unknown TCP traffic detected without corresponding DNS query: 173.222.162.32
Source: unknown TCP traffic detected without corresponding DNS query: 173.222.162.32
Source: unknown TCP traffic detected without corresponding DNS query: 173.222.162.32
Source: unknown TCP traffic detected without corresponding DNS query: 173.222.162.32
Source: unknown TCP traffic detected without corresponding DNS query: 173.222.162.32
Source: unknown TCP traffic detected without corresponding DNS query: 173.222.162.32
Source: unknown TCP traffic detected without corresponding DNS query: 173.222.162.32
Source: unknown TCP traffic detected without corresponding DNS query: 173.222.162.32
Source: global traffic HTTP traffic detected: GET /SLS/%7B522D76A4-93E1-47F8-B8CE-07C937AD1A1E%7D/x64/10.0.19045.2006/0?CH=700&L=en-GB&P=&PT=0x30&WUA=10.0.19041.1949&MK=9GFhH+ctPftpmeW&MD=C24lWSU7 HTTP/1.1Connection: Keep-AliveAccept: */*User-Agent: Windows-Update-Agent/10.0.10011.16384 Client-Protocol/2.33Host: slscr.update.microsoft.com
Source: global traffic HTTP traffic detected: GET /SLS/%7BE7A50285-D08D-499D-9FF8-180FDC2332BC%7D/x64/10.0.19045.2006/0?CH=700&L=en-GB&P=&PT=0x30&WUA=10.0.19041.1949&MK=9GFhH+ctPftpmeW&MD=C24lWSU7 HTTP/1.1Connection: Keep-AliveAccept: */*User-Agent: Windows-Update-Agent/10.0.10011.16384 Client-Protocol/2.33Host: slscr.update.microsoft.com
Source: unknown HTTP traffic detected: POST /threshold/xls.aspx HTTP/1.1Origin: https://www.bing.comReferer: https://www.bing.com/AS/API/WindowsCortanaPane/V2/InitAccept: */*Accept-Language: en-CHContent-type: text/xmlX-Agent-DeviceId: 01000A4109000CC6X-BM-CBT: 1696420817X-BM-DateFormat: dd/MM/yyyyX-BM-DeviceDimensions: 784x984X-BM-DeviceDimensionsLogical: 784x984X-BM-DeviceScale: 100X-BM-DTZ: 60X-BM-Market: CHX-BM-Theme: 000000;0078d7X-BM-WindowsFlights: FX:117B9872,FX:119E26AD,FX:11C0E96C,FX:11C6E5C2,FX:11C7EB6A,FX:11C9408A,FX:11C940DB,FX:11CB9A9F,FX:11CB9AC1,FX:11CC111C,FX:11D5BFCD,FX:11DF5B12,FX:11DF5B75,FX:1240931B,FX:124B38D0,FX:127FC878,FX:1283FFE8,FX:12840617,FX:128979F9,FX:128EBD7E,FX:129135BB,FX:129E053F,FX:12A74DB5,FX:12AB734D,FX:12B8450E,FX:12BD6E73,FX:12C3331B,FX:12C7D66EX-Device-ClientSession: 0912CF9094994CFA88DE52C6FB19D4E1X-Device-isOptin: falseX-Device-MachineId: {92C86F7C-DB2B-4F6A-95AD-98B4A2AE008A}X-Device-OSSKU: 48X-Device-Touch: falseX-DeviceID: 01000A4109000CC6X-MSEdge-ExternalExp: bfbwsbrs0830tf,d-thshldspcl40,msbdsborgv2co,msbwdsbi920t1,spofglclicksh-c2,webtophit0r_t,wsbmsaqfuxtc,wsbqfasmsall_t,wsbqfminiserp400,wsbref-tX-MSEdge-ExternalExpType: JointCoordX-PositionerType: DesktopX-Search-AppId: Microsoft.Windows.Cortana_cw5n1h2txyewy!CortanaUIX-Search-CortanaAvailableCapabilities: NoneX-Search-SafeSearch: ModerateX-Search-TimeZone: Bias=0; DaylightBias=-60; TimeZoneKeyName=GMT Standard TimeX-UserAgeClass: UnknownAccept-Encoding: gzip, deflate, brUser-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64; Cortana 1.14.7.19041; 10.0.0.0.19045.2006) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/70.0.3538.102 Safari/537.36 Edge/18.19045Host: www.bing.comContent-Length: 2232Connection: Keep-AliveCache-Control: no-cacheCookie: MUID=6666694284484FA1B35CCB433D42E997; _SS=SID=193A581F83766B4319784BBF829B6A16&CPID=1696420820117&AC=1&CPH=e5c79613&CBV=39942242; _EDGE_S=SID=193A581F83766B4319784BBF829B6A16; SRCHUID=V=2&GUID=BA43D82178364AEA9C1EE6C32BE93416&dmnchg=1; SRCHD=AF=NOFORM; SRCHUSR=DOB=20231003; SRCHHPGUSR=SRCHLANG=en&LUT=1696420817741&IPMH=425591ef&IPMID=1696420817913&HV=1696417346; ANON=A=6D8F9DF00282E660E425530EFFFFFFFF; CortanaAppUID=4C9C2B2D0465FD7A42C74C7E93CFB630; MUIDB=6666694284484FA1B35CCB433D42E997
Source: icudtl.dat.0.dr String found in binary or memory: http://www.unicode.org/copyright.html
Source: nacl_irt_x86_64.nexe.0.dr String found in binary or memory: https://chromium.googlesource.com/a/native_client/nacl-llvm-project-v10.git
Source: msmult64.exe, 00000000.00000002.2781998765.00007FF7601CC000.00000004.00000001.01000000.00000003.sdmp, Read_instructions_To_Decrypt.txt59.0.dr, Read_instructions_To_Decrypt.txt71.0.dr, Read_instructions_To_Decrypt.txt75.0.dr, Read_instructions_To_Decrypt.txt34.0.dr, Read_instructions_To_Decrypt.txt79.0.dr, Read_instructions_To_Decrypt.txt0.0.dr, Read_instructions_To_Decrypt.txt35.0.dr, Read_instructions_To_Decrypt.txt39.0.dr, Read_instructions_To_Decrypt.txt3.0.dr, Read_instructions_To_Decrypt.txt21.0.dr, Read_instructions_To_Decrypt.txt57.0.dr, Read_instructions_To_Decrypt.txt70.0.dr, Read_instructions_To_Decrypt.txt15.0.dr, Read_instructions_To_Decrypt.txt43.0.dr, Read_instructions_To_Decrypt.txt2.0.dr, Read_instructions_To_Decrypt.txt76.0.dr, Read_instructions_To_Decrypt.txt69.0.dr, Read_instructions_To_Decrypt.txt12.0.dr, Read_instructions_To_Decrypt.txt42.0.dr, Read_instructions_To_Decrypt.txt47.0.dr String found in binary or memory: https://tox.chat
Source: unknown Network traffic detected: HTTP traffic on port 49675 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 49984
Source: unknown Network traffic detected: HTTP traffic on port 49672 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 49678 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 49991
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 49990
Source: unknown Network traffic detected: HTTP traffic on port 49984 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 49990 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 49991 -> 443
Source: unknown HTTPS traffic detected: 40.68.123.157:443 -> 192.168.2.4:49984 version: TLS 1.2
Source: unknown HTTPS traffic detected: 40.68.123.157:443 -> 192.168.2.4:49990 version: TLS 1.2
Source: unknown HTTPS traffic detected: 173.222.162.32:443 -> 192.168.2.4:49991 version: TLS 1.2

Spam, unwanted Advertisements and Ransom Demands

barindex
Source: C:\Program Files (x86)\Microsoft Office\root\vregwow6432\Read_instructions_To_Decrypt.txt Dropped file: HelloWe are a team of high-level competent team of Pentesters but NOT a THREAT to your reputable organizationWe secure networks of companies to avoid complete destruction and damages to companiesWe encrypted all files on Your servers to show sign of breach / network intrusionTo resolve this Continue reading !!!!ALL files oN Your Entire Network Servers and Connected Devices are Encrypted.Means , Files are modified and are not usable at the moment.Don't Panic !!!All Encrypted files can be reversed to original form and become usable .This is Only Possible if you buy the universal Decryption software from me.Price for universal Decryption Software : $ Contact us either through email or tox chat app for the ransom price $You Have 72 hours To Make Payment As Price of Universal Decryption software increases by $1000 dollars every 24 hours.Contact on this email: bl00dyadmin@dnmx.orgcopy email address and write message to bl00dyadmin@dnmx.orgYou can write me on tox: Download tox app from https://tox.chatCreate new Account ..Send me friend request using my tox id:E5BBFAD2DB3FB497EA03612B2428F927FD8A9B3333D524FD51D43B029B7870571CEB0166CB03*copy and paste it as it is*Before You Pay me ... I will Decrypt 3 files for free To proof the universal Decryption software worksFailure to Pay Me :Kindly RESPECT my RulesNote: Huge amounts of Data / documents has been stolen from your Network servers and will be published online for freeI have stolen All Your Databases ; DAta on your shared drives ; AD users Emails(Good for Spam) ;i have stolen huge amount of critical data from your servers* I keep the breach private only if your cooperate * Jump to dropped file
Source: Yara match File source: Process Memory Space: msmult64.exe PID: 7492, type: MEMORYSTR
Source: Yara match File source: Process Memory Space: msmult64.exe PID: 7492, type: MEMORYSTR
Source: C:\Users\user\Desktop\msmult64.exe File created: C:\Read_instructions_To_Decrypt.txt Jump to behavior
Source: C:\Users\user\Desktop\msmult64.exe File created: C:\$WinREAgent\Read_instructions_To_Decrypt.txt Jump to behavior
Source: C:\Users\user\Desktop\msmult64.exe File created: C:\Program Files\Read_instructions_To_Decrypt.txt Jump to behavior
Source: C:\Users\user\Desktop\msmult64.exe File created: C:\Program Files (x86)\Read_instructions_To_Decrypt.txt Jump to behavior
Source: C:\Users\user\Desktop\msmult64.exe File created: C:\ProgramData\Read_instructions_To_Decrypt.txt Jump to behavior
Source: C:\Users\user\Desktop\msmult64.exe File created: C:\Recovery\Read_instructions_To_Decrypt.txt Jump to behavior
Source: C:\Users\user\Desktop\msmult64.exe File created: C:\Users\Read_instructions_To_Decrypt.txt Jump to behavior
Source: C:\Users\user\Desktop\msmult64.exe File created: C:\$WinREAgent\Scratch\Read_instructions_To_Decrypt.txt Jump to behavior
Source: C:\Users\user\Desktop\msmult64.exe File created: C:\Program Files\7-Zip\Read_instructions_To_Decrypt.txt Jump to behavior
Source: C:\Users\user\Desktop\msmult64.exe File created: C:\Program Files\Adobe\Read_instructions_To_Decrypt.txt Jump to behavior
Source: C:\Users\user\Desktop\msmult64.exe File created: C:\Program Files\Common Files\Read_instructions_To_Decrypt.txt Jump to behavior
Source: C:\Users\user\Desktop\msmult64.exe File created: C:\Program Files\Google\Read_instructions_To_Decrypt.txt Jump to behavior
Source: C:\Users\user\Desktop\msmult64.exe File created: C:\Program Files\Internet Explorer\Read_instructions_To_Decrypt.txt Jump to behavior
Source: C:\Users\user\Desktop\msmult64.exe File created: C:\Program Files\Microsoft\Read_instructions_To_Decrypt.txt Jump to behavior
Source: C:\Users\user\Desktop\msmult64.exe File created: C:\Program Files\Microsoft Office 15\Read_instructions_To_Decrypt.txt Jump to behavior
Source: C:\Users\user\Desktop\msmult64.exe File created: C:\Program Files\Mozilla Firefox\Read_instructions_To_Decrypt.txt Jump to behavior
Source: C:\Users\user\Desktop\msmult64.exe File created: C:\Program Files\MSBuild\Read_instructions_To_Decrypt.txt Jump to behavior
Source: C:\Users\user\Desktop\msmult64.exe File created: C:\Program Files\Reference Assemblies\Read_instructions_To_Decrypt.txt Jump to behavior
Source: C:\Users\user\Desktop\msmult64.exe File created: C:\Program Files\Uninstall Information\Read_instructions_To_Decrypt.txt Jump to behavior
Source: C:\Users\user\Desktop\msmult64.exe File created: C:\Program Files (x86)\autoit3\Read_instructions_To_Decrypt.txt Jump to behavior
Source: C:\Users\user\Desktop\msmult64.exe File created: c:\read_instructions_to_decrypt.txt Jump to behavior
Source: C:\Users\user\Desktop\msmult64.exe File created: c:\$winreagent\read_instructions_to_decrypt.txt Jump to behavior
Source: C:\Users\user\Desktop\msmult64.exe File created: c:\program files\read_instructions_to_decrypt.txt Jump to behavior
Source: C:\Users\user\Desktop\msmult64.exe File created: c:\program files (x86)\read_instructions_to_decrypt.txt Jump to behavior
Source: C:\Users\user\Desktop\msmult64.exe File created: c:\programdata\read_instructions_to_decrypt.txt Jump to behavior
Source: C:\Users\user\Desktop\msmult64.exe File created: c:\recovery\read_instructions_to_decrypt.txt Jump to behavior
Source: C:\Users\user\Desktop\msmult64.exe File created: c:\users\read_instructions_to_decrypt.txt Jump to behavior
Source: C:\Users\user\Desktop\msmult64.exe File created: c:\$winreagent\scratch\read_instructions_to_decrypt.txt Jump to behavior
Source: C:\Users\user\Desktop\msmult64.exe File created: c:\program files\7-zip\read_instructions_to_decrypt.txt Jump to behavior
Source: C:\Users\user\Desktop\msmult64.exe File created: c:\program files\adobe\read_instructions_to_decrypt.txt Jump to behavior
Source: C:\Users\user\Desktop\msmult64.exe File created: c:\program files\common files\read_instructions_to_decrypt.txt Jump to behavior
Source: C:\Users\user\Desktop\msmult64.exe File created: c:\program files\google\read_instructions_to_decrypt.txt Jump to behavior
Source: C:\Users\user\Desktop\msmult64.exe File created: c:\program files\internet explorer\read_instructions_to_decrypt.txt Jump to behavior
Source: C:\Users\user\Desktop\msmult64.exe File created: c:\program files\microsoft\read_instructions_to_decrypt.txt Jump to behavior
Source: C:\Users\user\Desktop\msmult64.exe File created: c:\program files\microsoft office 15\read_instructions_to_decrypt.txt Jump to behavior
Source: C:\Users\user\Desktop\msmult64.exe File created: c:\program files\mozilla firefox\read_instructions_to_decrypt.txt Jump to behavior
Source: C:\Users\user\Desktop\msmult64.exe File created: c:\program files\msbuild\read_instructions_to_decrypt.txt Jump to behavior
Source: C:\Users\user\Desktop\msmult64.exe File created: c:\program files\reference assemblies\read_instructions_to_decrypt.txt Jump to behavior
Source: C:\Users\user\Desktop\msmult64.exe File created: c:\program files\uninstall information\read_instructions_to_decrypt.txt Jump to behavior
Source: C:\Users\user\Desktop\msmult64.exe File created: c:\program files (x86)\autoit3\read_instructions_to_decrypt.txt Jump to behavior
Source: C:\Users\user\Desktop\msmult64.exe File created: c:\program files (x86)\common files\read_instructions_to_decrypt.txt Jump to behavior
Source: C:\Users\user\Desktop\msmult64.exe File created: c:\program files (x86)\google\read_instructions_to_decrypt.txt Jump to behavior
Source: C:\Users\user\Desktop\msmult64.exe File created: c:\program files (x86)\internet explorer\read_instructions_to_decrypt.txt Jump to behavior
Source: C:\Users\user\Desktop\msmult64.exe File created: c:\program files (x86)\java\read_instructions_to_decrypt.txt Jump to behavior
Source: C:\Users\user\Desktop\msmult64.exe File created: c:\program files (x86)\jdownloader\read_instructions_to_decrypt.txt Jump to behavior
Source: C:\Users\user\Desktop\msmult64.exe File created: c:\program files (x86)\microsoft\read_instructions_to_decrypt.txt Jump to behavior
Source: C:\Users\user\Desktop\msmult64.exe File created: c:\program files (x86)\microsoft office\read_instructions_to_decrypt.txt Jump to behavior
Source: C:\Users\user\Desktop\msmult64.exe File created: c:\program files (x86)\microsoft onedrive\read_instructions_to_decrypt.txt Jump to behavior
Source: C:\Users\user\Desktop\msmult64.exe File created: c:\program files (x86)\microsoft.net\read_instructions_to_decrypt.txt Jump to behavior
Source: C:\Users\user\Desktop\msmult64.exe File created: c:\program files (x86)\mozilla maintenance service\read_instructions_to_decrypt.txt Jump to behavior
Source: C:\Users\user\Desktop\msmult64.exe File created: c:\program files (x86)\msbuild\read_instructions_to_decrypt.txt Jump to behavior
Source: C:\Users\user\Desktop\msmult64.exe File created: c:\program files (x86)\msecache\read_instructions_to_decrypt.txt Jump to behavior
Source: C:\Users\user\Desktop\msmult64.exe File created: c:\program files (x86)\reference assemblies\read_instructions_to_decrypt.txt Jump to behavior
Source: C:\Users\user\Desktop\msmult64.exe File created: c:\program files (x86)\wtzdqbnjfggcblukgmgjisjaogxihpudttwjafommjwbppvkjyrfhlmyforesxznylmambtocxxlayz\read_instructions_to_decrypt.txt Jump to behavior
Source: C:\Users\user\Desktop\msmult64.exe File created: c:\programdata\adobe\read_instructions_to_decrypt.txt Jump to behavior
Source: C:\Users\user\Desktop\msmult64.exe File created: c:\programdata\dbg\read_instructions_to_decrypt.txt Jump to behavior
Source: C:\Users\user\Desktop\msmult64.exe File created: c:\programdata\microsoft\read_instructions_to_decrypt.txt Jump to behavior
Source: C:\Users\user\Desktop\msmult64.exe File created: c:\programdata\microsoft onedrive\read_instructions_to_decrypt.txt Jump to behavior
Source: C:\Users\user\Desktop\msmult64.exe File created: c:\programdata\mozilla-1de4eec8-1241-4177-a864-e594e8d1fb38\read_instructions_to_decrypt.txt Jump to behavior
Source: C:\Users\user\Desktop\msmult64.exe File created: c:\programdata\package cache\read_instructions_to_decrypt.txt Jump to behavior
Source: C:\Users\user\Desktop\msmult64.exe File created: c:\programdata\packages\read_instructions_to_decrypt.txt Jump to behavior
Source: C:\Users\user\Desktop\msmult64.exe File created: c:\programdata\regid.1991-06.com.microsoft\read_instructions_to_decrypt.txt Jump to behavior
Source: C:\Users\user\Desktop\msmult64.exe File created: c:\programdata\softwaredistribution\read_instructions_to_decrypt.txt Jump to behavior
Source: C:\Users\user\Desktop\msmult64.exe File created: c:\programdata\ssh\read_instructions_to_decrypt.txt Jump to behavior
Source: C:\Users\user\Desktop\msmult64.exe File created: c:\programdata\usoshared\read_instructions_to_decrypt.txt Jump to behavior
Source: C:\Users\user\Desktop\msmult64.exe File created: c:\users\default\read_instructions_to_decrypt.txt Jump to behavior
Source: C:\Users\user\Desktop\msmult64.exe File created: c:\users\user\read_instructions_to_decrypt.txt Jump to behavior
Source: C:\Users\user\Desktop\msmult64.exe File created: c:\users\public\read_instructions_to_decrypt.txt Jump to behavior
Source: C:\Users\user\Desktop\msmult64.exe File created: c:\program files\7-zip\lang\read_instructions_to_decrypt.txt Jump to behavior
Source: C:\Users\user\Desktop\msmult64.exe File created: c:\program files\adobe\acrobat dc\read_instructions_to_decrypt.txt Jump to behavior
Source: C:\Users\user\Desktop\msmult64.exe File created: c:\program files\common files\adobe\read_instructions_to_decrypt.txt Jump to behavior
Source: C:\Users\user\Desktop\msmult64.exe File created: c:\program files\common files\microsoft shared\read_instructions_to_decrypt.txt Jump to behavior
Source: C:\Users\user\Desktop\msmult64.exe File created: c:\program files\common files\services\read_instructions_to_decrypt.txt Jump to behavior
Source: C:\Users\user\Desktop\msmult64.exe File created: c:\program files\common files\system\read_instructions_to_decrypt.txt Jump to behavior
Source: C:\Users\user\Desktop\msmult64.exe File created: c:\program files\google\chrome\read_instructions_to_decrypt.txt Jump to behavior
Source: C:\Users\user\Desktop\msmult64.exe File created: c:\program files\internet explorer\en-gb\read_instructions_to_decrypt.txt Jump to behavior
Source: C:\Users\user\Desktop\msmult64.exe File created: c:\program files\internet explorer\en-us\read_instructions_to_decrypt.txt Jump to behavior
Source: C:\Users\user\Desktop\msmult64.exe File created: c:\program files\internet explorer\images\read_instructions_to_decrypt.txt Jump to behavior
Source: C:\Users\user\Desktop\msmult64.exe File created: c:\program files\internet explorer\signup\read_instructions_to_decrypt.txt Jump to behavior
Source: C:\Users\user\Desktop\msmult64.exe File created: c:\program files\microsoft\onedrive\read_instructions_to_decrypt.txt Jump to behavior
Source: C:\Users\user\Desktop\msmult64.exe File created: c:\program files\microsoft office 15\clientx64\read_instructions_to_decrypt.txt Jump to behavior
Source: C:\Users\user\Desktop\msmult64.exe File created: c:\program files\mozilla firefox\browser\read_instructions_to_decrypt.txt Jump to behavior
Source: C:\Users\user\Desktop\msmult64.exe File created: c:\program files\mozilla firefox\defaults\read_instructions_to_decrypt.txt Jump to behavior
Source: C:\Users\user\Desktop\msmult64.exe File created: c:\program files\mozilla firefox\fonts\read_instructions_to_decrypt.txt Jump to behavior
Source: C:\Users\user\Desktop\msmult64.exe File created: c:\program files\mozilla firefox\gmp-clearkey\read_instructions_to_decrypt.txt Jump to behavior
Source: C:\Users\user\Desktop\msmult64.exe File created: c:\program files\mozilla firefox\uninstall\read_instructions_to_decrypt.txt Jump to behavior
Source: C:\Users\user\Desktop\msmult64.exe File created: c:\program files\msbuild\microsoft\read_instructions_to_decrypt.txt Jump to behavior
Source: C:\Users\user\Desktop\msmult64.exe File created: c:\program files\reference assemblies\microsoft\read_instructions_to_decrypt.txt Jump to behavior
Source: C:\Users\user\Desktop\msmult64.exe File created: c:\program files (x86)\autoit3\aut2exe\read_instructions_to_decrypt.txt Jump to behavior
Source: C:\Users\user\Desktop\msmult64.exe File created: c:\program files (x86)\autoit3\autoitx\read_instructions_to_decrypt.txt Jump to behavior
Source: C:\Users\user\Desktop\msmult64.exe File created: c:\program files (x86)\autoit3\examples\read_instructions_to_decrypt.txt Jump to behavior
Source: C:\Users\user\Desktop\msmult64.exe File created: c:\program files (x86)\autoit3\extras\read_instructions_to_decrypt.txt Jump to behavior
Source: C:\Users\user\Desktop\msmult64.exe File created: c:\program files (x86)\autoit3\icons\read_instructions_to_decrypt.txt Jump to behavior
Source: C:\Users\user\Desktop\msmult64.exe File created: c:\program files (x86)\autoit3\include\read_instructions_to_decrypt.txt Jump to behavior
Source: C:\Users\user\Desktop\msmult64.exe File created: c:\program files (x86)\autoit3\scite\read_instructions_to_decrypt.txt Jump to behavior
Source: C:\Users\user\Desktop\msmult64.exe File created: c:\program files (x86)\common files\adobe\read_instructions_to_decrypt.txt Jump to behavior
Source: C:\Users\user\Desktop\msmult64.exe File created: c:\program files (x86)\common files\designer\read_instructions_to_decrypt.txt Jump to behavior
Source: C:\Users\user\Desktop\msmult64.exe File created: c:\program files (x86)\common files\java\read_instructions_to_decrypt.txt Jump to behavior
Source: C:\Users\user\Desktop\msmult64.exe File created: c:\program files (x86)\common files\microsoft shared\read_instructions_to_decrypt.txt Jump to behavior
Source: C:\Users\user\Desktop\msmult64.exe File created: c:\program files (x86)\common files\oracle\read_instructions_to_decrypt.txt Jump to behavior
Source: C:\Users\user\Desktop\msmult64.exe File created: c:\program files (x86)\common files\services\read_instructions_to_decrypt.txt Jump to behavior
Source: C:\Users\user\Desktop\msmult64.exe File created: c:\program files (x86)\common files\system\read_instructions_to_decrypt.txt Jump to behavior
Source: C:\Users\user\Desktop\msmult64.exe File created: c:\program files (x86)\google\update\read_instructions_to_decrypt.txt Jump to behavior
Source: C:\Users\user\Desktop\msmult64.exe File created: c:\program files (x86)\internet explorer\en-gb\read_instructions_to_decrypt.txt Jump to behavior
Source: C:\Users\user\Desktop\msmult64.exe File created: c:\program files (x86)\internet explorer\en-us\read_instructions_to_decrypt.txt Jump to behavior
Source: C:\Users\user\Desktop\msmult64.exe File created: c:\program files (x86)\internet explorer\images\read_instructions_to_decrypt.txt Jump to behavior
Source: C:\Users\user\Desktop\msmult64.exe File created: c:\program files (x86)\internet explorer\signup\read_instructions_to_decrypt.txt Jump to behavior
Source: C:\Users\user\Desktop\msmult64.exe File created: c:\program files (x86)\java\jre-1.8\read_instructions_to_decrypt.txt Jump to behavior
Source: C:\Users\user\Desktop\msmult64.exe File created: c:\program files (x86)\jdownloader\config\read_instructions_to_decrypt.txt Jump to behavior
Source: C:\Users\user\Desktop\msmult64.exe File created: c:\program files (x86)\microsoft\edge\read_instructions_to_decrypt.txt Jump to behavior
Source: C:\Users\user\Desktop\msmult64.exe File created: c:\program files (x86)\microsoft\edgecore\read_instructions_to_decrypt.txt Jump to behavior
Source: C:\Users\user\Desktop\msmult64.exe File created: c:\program files (x86)\microsoft\edgewebview\read_instructions_to_decrypt.txt Jump to behavior
Source: C:\Users\user\Desktop\msmult64.exe File created: c:\program files (x86)\microsoft office\office16\read_instructions_to_decrypt.txt Jump to behavior
Source: C:\Users\user\Desktop\msmult64.exe File created: c:\program files (x86)\microsoft office\packagemanifests\read_instructions_to_decrypt.txt Jump to behavior
Source: C:\Users\user\Desktop\msmult64.exe File created: c:\program files (x86)\microsoft office\root\read_instructions_to_decrypt.txt Jump to behavior
Source: C:\Users\user\Desktop\msmult64.exe File created: c:\program files (x86)\microsoft office\updates\read_instructions_to_decrypt.txt Jump to behavior
Source: C:\Users\user\Desktop\msmult64.exe File created: c:\program files (x86)\microsoft onedrive\23.038.0219.0001\read_instructions_to_decrypt.txt Jump to behavior
Source: C:\Users\user\Desktop\msmult64.exe File created: c:\program files (x86)\microsoft onedrive\logoimages\read_instructions_to_decrypt.txt Jump to behavior
Source: C:\Users\user\Desktop\msmult64.exe File created: c:\program files (x86)\microsoft onedrive\setup\read_instructions_to_decrypt.txt Jump to behavior
Source: C:\Users\user\Desktop\msmult64.exe File created: c:\program files (x86)\microsoft.net\primary interop assemblies\read_instructions_to_decrypt.txt Jump to behavior
Source: C:\Users\user\Desktop\msmult64.exe File created: c:\program files (x86)\microsoft.net\redistlist\read_instructions_to_decrypt.txt Jump to behavior
Source: C:\Users\user\Desktop\msmult64.exe File created: c:\program files (x86)\mozilla maintenance service\logs\read_instructions_to_decrypt.txt Jump to behavior
Source: C:\Users\user\Desktop\msmult64.exe File created: c:\program files (x86)\msbuild\microsoft\read_instructions_to_decrypt.txt Jump to behavior
Source: C:\Users\user\Desktop\msmult64.exe File created: c:\program files (x86)\msecache\officekms\read_instructions_to_decrypt.txt Jump to behavior
Source: C:\Users\user\Desktop\msmult64.exe File created: c:\program files (x86)\reference assemblies\microsoft\read_instructions_to_decrypt.txt Jump to behavior
Source: C:\Users\user\Desktop\msmult64.exe File created: c:\programdata\adobe\arm\read_instructions_to_decrypt.txt Jump to behavior
Source: C:\Users\user\Desktop\msmult64.exe File created: c:\programdata\microsoft\appv\read_instructions_to_decrypt.txt Jump to behavior
Source: C:\Users\user\Desktop\msmult64.exe File created: c:\programdata\microsoft\clicktorun\read_instructions_to_decrypt.txt Jump to behavior
Source: C:\Users\user\Desktop\msmult64.exe File created: c:\programdata\microsoft\crypto\read_instructions_to_decrypt.txt Jump to behavior
Source: C:\Users\user\Desktop\msmult64.exe File created: c:\programdata\microsoft\device stage\read_instructions_to_decrypt.txt Jump to behavior
Source: C:\Users\user\Desktop\msmult64.exe File created: c:\programdata\microsoft\devicesync\read_instructions_to_decrypt.txt Jump to behavior
Source: C:\Users\user\Desktop\msmult64.exe File created: c:\programdata\microsoft\diagnosis\read_instructions_to_decrypt.txt Jump to behavior
Source: C:\Users\user\Desktop\msmult64.exe File created: c:\programdata\microsoft\diagnosticlogcsp\read_instructions_to_decrypt.txt Jump to behavior
Source: C:\Users\user\Desktop\msmult64.exe File created: c:\programdata\microsoft\drm\read_instructions_to_decrypt.txt Jump to behavior
Source: C:\Users\user\Desktop\msmult64.exe File created: c:\programdata\microsoft\edgeupdate\read_instructions_to_decrypt.txt Jump to behavior
Source: C:\Users\user\Desktop\msmult64.exe File created: c:\programdata\microsoft\identitycrl\read_instructions_to_decrypt.txt Jump to behavior
Source: C:\Users\user\Desktop\msmult64.exe File created: c:\programdata\microsoft\mapdata\read_instructions_to_decrypt.txt Jump to behavior
Source: C:\Users\user\Desktop\msmult64.exe File created: c:\programdata\microsoft\mf\read_instructions_to_decrypt.txt Jump to behavior
Source: C:\Users\user\Desktop\msmult64.exe File created: c:\programdata\microsoft\netframework\read_instructions_to_decrypt.txt Jump to behavior
Source: C:\Users\user\Desktop\msmult64.exe File created: c:\programdata\microsoft\network\read_instructions_to_decrypt.txt Jump to behavior
Source: C:\Users\user\Desktop\msmult64.exe File created: c:\programdata\microsoft\office\read_instructions_to_decrypt.txt Jump to behavior
Source: C:\Users\user\Desktop\msmult64.exe File created: c:\programdata\microsoft\provisioning\read_instructions_to_decrypt.txt Jump to behavior
Source: C:\Users\user\Desktop\msmult64.exe File created: c:\programdata\microsoft\search\read_instructions_to_decrypt.txt Jump to behavior
Source: C:\Users\user\Desktop\msmult64.exe File created: c:\programdata\microsoft\settings\read_instructions_to_decrypt.txt Jump to behavior
Source: C:\Users\user\Desktop\msmult64.exe File created: c:\programdata\microsoft\smsrouter\read_instructions_to_decrypt.txt Jump to behavior
Source: C:\Users\user\Desktop\msmult64.exe File created: c:\programdata\microsoft\spectrum\read_instructions_to_decrypt.txt Jump to behavior
Source: C:\Users\user\Desktop\msmult64.exe File created: c:\programdata\microsoft\speech_onecore\read_instructions_to_decrypt.txt Jump to behavior
Source: C:\Users\user\Desktop\msmult64.exe File created: c:\programdata\microsoft\storage health\read_instructions_to_decrypt.txt Jump to behavior
Source: C:\Users\user\Desktop\msmult64.exe File created: c:\programdata\microsoft\uev\read_instructions_to_decrypt.txt Jump to behavior
Source: C:\Users\user\Desktop\msmult64.exe File created: c:\programdata\microsoft\user account pictures\read_instructions_to_decrypt.txt Jump to behavior
Source: C:\Users\user\Desktop\msmult64.exe File created: c:\programdata\microsoft\vault\read_instructions_to_decrypt.txt Jump to behavior
Source: C:\Users\user\Desktop\msmult64.exe File created: c:\programdata\microsoft\wdf\read_instructions_to_decrypt.txt Jump to behavior
Source: C:\Users\user\Desktop\msmult64.exe File created: c:\programdata\microsoft\winmsipc\read_instructions_to_decrypt.txt Jump to behavior
Source: C:\Users\user\Desktop\msmult64.exe File created: c:\programdata\microsoft\wwansvc\read_instructions_to_decrypt.txt Jump to behavior
Source: C:\Users\user\Desktop\msmult64.exe File created: c:\programdata\microsoft onedrive\setup\read_instructions_to_decrypt.txt Jump to behavior
Source: C:\Users\user\Desktop\msmult64.exe File created: c:\programdata\mozilla-1de4eec8-1241-4177-a864-e594e8d1fb38\updates\read_instructions_to_decrypt.txt Jump to behavior
Source: C:\Users\user\Desktop\msmult64.exe File created: c:\programdata\package cache\{0025dd72-a959-45b5-a0a3-7efeb15a8050}v14.36.32532\read_instructions_to_decrypt.txt Jump to behavior
Source: C:\Users\user\Desktop\msmult64.exe File created: c:\programdata\package cache\{8bdfe669-9705-4184-9368-db9ce581e0e7}\read_instructions_to_decrypt.txt Jump to behavior
Source: C:\Users\user\Desktop\msmult64.exe File created: c:\programdata\package cache\{d5d19e2f-7189-42fe-8103-92cd1fa457c2}v14.36.32532\read_instructions_to_decrypt.txt Jump to behavior
Source: C:\Users\user\Desktop\msmult64.exe File created: c:\programdata\packages\microsoft.549981c3f5f10_8wekyb3d8bbwe\read_instructions_to_decrypt.txt Jump to behavior
Source: C:\Users\user\Desktop\msmult64.exe File created: c:\programdata\packages\microsoft.desktopappinstaller_8wekyb3d8bbwe\read_instructions_to_decrypt.txt Jump to behavior
Source: C:\Users\user\Desktop\msmult64.exe File created: c:\programdata\packages\microsoft.getstarted_8wekyb3d8bbwe\read_instructions_to_decrypt.txt Jump to behavior
Source: C:\Users\user\Desktop\msmult64.exe File created: c:\programdata\packages\microsoft.microsoft3dviewer_8wekyb3d8bbwe\read_instructions_to_decrypt.txt Jump to behavior
Source: C:\Users\user\Desktop\msmult64.exe File created: c:\programdata\packages\microsoft.microsoftedge.stable_8wekyb3d8bbwe\read_instructions_to_decrypt.txt Jump to behavior
Source: C:\Users\user\Desktop\msmult64.exe File created: c:\programdata\packages\microsoft.microsoftofficehub_8wekyb3d8bbwe\read_instructions_to_decrypt.txt Jump to behavior
Source: C:\Users\user\Desktop\msmult64.exe File created: c:\programdata\packages\microsoft.mixedreality.portal_8wekyb3d8bbwe\read_instructions_to_decrypt.txt Jump to behavior
Source: C:\Users\user\Desktop\msmult64.exe File created: c:\programdata\packages\microsoft.office.onenote_8wekyb3d8bbwe\read_instructions_to_decrypt.txt Jump to behavior
Source: C:\Users\user\Desktop\msmult64.exe File created: c:\programdata\packages\microsoft.skypeapp_kzf8qxf38zg5c\read_instructions_to_decrypt.txt Jump to behavior
Source: C:\Users\user\Desktop\msmult64.exe File created: c:\programdata\usoshared\logs\read_instructions_to_decrypt.txt Jump to behavior
Source: C:\Users\user\Desktop\msmult64.exe File created: c:\users\default\appdata\read_instructions_to_decrypt.txt Jump to behavior
Source: C:\Users\user\Desktop\msmult64.exe File created: c:\users\default\desktop\read_instructions_to_decrypt.txt Jump to behavior
Source: C:\Users\user\Desktop\msmult64.exe File created: c:\users\default\documents\read_instructions_to_decrypt.txt Jump to behavior
Source: C:\Users\user\Desktop\msmult64.exe File created: c:\users\default\downloads\read_instructions_to_decrypt.txt Jump to behavior
Source: C:\Users\user\Desktop\msmult64.exe File created: c:\users\default\favorites\read_instructions_to_decrypt.txt Jump to behavior
Source: C:\Users\user\Desktop\msmult64.exe File created: c:\users\default\links\read_instructions_to_decrypt.txt Jump to behavior
Source: C:\Users\user\Desktop\msmult64.exe File created: c:\users\default\music\read_instructions_to_decrypt.txt Jump to behavior
Source: C:\Users\user\Desktop\msmult64.exe File created: c:\users\default\onedrive\read_instructions_to_decrypt.txt Jump to behavior
Source: C:\Users\user\Desktop\msmult64.exe File created: c:\users\default\pictures\read_instructions_to_decrypt.txt Jump to behavior
Source: C:\Users\user\Desktop\msmult64.exe File created: c:\users\default\saved games\read_instructions_to_decrypt.txt Jump to behavior
Source: C:\Users\user\Desktop\msmult64.exe File created: c:\users\default\videos\read_instructions_to_decrypt.txt Jump to behavior
Source: C:\Users\user\Desktop\msmult64.exe File created: c:\users\user\.ms-ad\read_instructions_to_decrypt.txt Jump to behavior
Source: C:\Users\user\Desktop\msmult64.exe File created: c:\users\user\3d objects\read_instructions_to_decrypt.txt Jump to behavior
Source: C:\Users\user\Desktop\msmult64.exe File created: c:\users\user\appdata\read_instructions_to_decrypt.txt Jump to behavior
Source: C:\Users\user\Desktop\msmult64.exe File created: c:\users\user\contacts\read_instructions_to_decrypt.txt Jump to behavior
Source: C:\Users\user\Desktop\msmult64.exe File created: c:\users\user\desktop\read_instructions_to_decrypt.txt Jump to behavior
Source: C:\Users\user\Desktop\msmult64.exe File created: c:\users\user\documents\read_instructions_to_decrypt.txt Jump to behavior
Source: C:\Users\user\Desktop\msmult64.exe File created: c:\users\user\downloads\read_instructions_to_decrypt.txt Jump to behavior
Source: C:\Users\user\Desktop\msmult64.exe File created: c:\users\user\favorites\read_instructions_to_decrypt.txt Jump to behavior
Source: C:\Users\user\Desktop\msmult64.exe File created: c:\users\user\links\read_instructions_to_decrypt.txt Jump to behavior
Source: C:\Users\user\Desktop\msmult64.exe File created: c:\users\user\music\read_instructions_to_decrypt.txt Jump to behavior
Source: C:\Users\user\Desktop\msmult64.exe File created: c:\users\user\onedrive\read_instructions_to_decrypt.txt Jump to behavior
Source: C:\Users\user\Desktop\msmult64.exe File created: c:\users\user\pictures\read_instructions_to_decrypt.txt Jump to behavior
Source: C:\Users\user\Desktop\msmult64.exe File created: c:\users\user\recent\read_instructions_to_decrypt.txt Jump to behavior
Source: C:\Users\user\Desktop\msmult64.exe File created: c:\users\user\saved games\read_instructions_to_decrypt.txt Jump to behavior
Source: C:\Users\user\Desktop\msmult64.exe File created: c:\users\user\searches\read_instructions_to_decrypt.txt Jump to behavior
Source: C:\Users\user\Desktop\msmult64.exe File created: c:\users\user\videos\read_instructions_to_decrypt.txt Jump to behavior
Source: C:\Users\user\Desktop\msmult64.exe File created: c:\users\public\accountpictures\read_instructions_to_decrypt.txt Jump to behavior
Source: C:\Users\user\Desktop\msmult64.exe File created: c:\users\public\desktop\read_instructions_to_decrypt.txt Jump to behavior
Source: C:\Users\user\Desktop\msmult64.exe File created: c:\users\public\documents\read_instructions_to_decrypt.txt Jump to behavior
Source: C:\Users\user\Desktop\msmult64.exe File created: c:\users\public\downloads\read_instructions_to_decrypt.txt Jump to behavior
Source: C:\Users\user\Desktop\msmult64.exe File created: c:\users\public\libraries\read_instructions_to_decrypt.txt Jump to behavior
Source: C:\Users\user\Desktop\msmult64.exe File created: c:\users\public\music\read_instructions_to_decrypt.txt Jump to behavior
Source: C:\Users\user\Desktop\msmult64.exe File created: c:\users\public\pictures\read_instructions_to_decrypt.txt Jump to behavior
Source: C:\Users\user\Desktop\msmult64.exe File created: c:\users\public\videos\read_instructions_to_decrypt.txt Jump to behavior
Source: C:\Users\user\Desktop\msmult64.exe File created: c:\program files\adobe\acrobat dc\acrobat\read_instructions_to_decrypt.txt Jump to behavior
Source: C:\Users\user\Desktop\msmult64.exe File created: c:\program files\adobe\acrobat dc\esl\read_instructions_to_decrypt.txt Jump to behavior
Source: C:\Users\user\Desktop\msmult64.exe File created: c:\program files\adobe\acrobat dc\resource\read_instructions_to_decrypt.txt Jump to behavior
Source: C:\Users\user\Desktop\msmult64.exe File created: c:\program files\common files\adobe\acrobat\read_instructions_to_decrypt.txt Jump to behavior
Source: C:\Users\user\Desktop\msmult64.exe File created: c:\program files\common files\adobe\helpcfg\read_instructions_to_decrypt.txt Jump to behavior
Source: C:\Users\user\Desktop\msmult64.exe File created: c:\program files\common files\microsoft shared\clicktorun\read_instructions_to_decrypt.txt Jump to behavior
Source: C:\Users\user\Desktop\msmult64.exe File created: c:\program files\common files\microsoft shared\ink\read_instructions_to_decrypt.txt Jump to behavior
Source: C:\Users\user\Desktop\msmult64.exe File created: c:\program files\common files\microsoft shared\msinfo\read_instructions_to_decrypt.txt Jump to behavior
Source: C:\Users\user\Desktop\msmult64.exe File created: c:\program files\common files\microsoft shared\stationery\read_instructions_to_decrypt.txt Jump to behavior
Source: C:\Users\user\Desktop\msmult64.exe File created: c:\program files\common files\microsoft shared\textconv\read_instructions_to_decrypt.txt Jump to behavior
Source: C:\Users\user\Desktop\msmult64.exe File created: c:\program files\common files\microsoft shared\triedit\read_instructions_to_decrypt.txt Jump to behavior
Source: C:\Users\user\Desktop\msmult64.exe File created: c:\program files\common files\microsoft shared\vgx\read_instructions_to_decrypt.txt Jump to behavior
Source: C:\Users\user\Desktop\msmult64.exe File created: c:\program files\common files\system\ado\read_instructions_to_decrypt.txt Jump to behavior
Source: C:\Users\user\Desktop\msmult64.exe File created: c:\program files\common files\system\en-gb\read_instructions_to_decrypt.txt Jump to behavior
Source: C:\Users\user\Desktop\msmult64.exe File created: c:\program files\common files\system\en-us\read_instructions_to_decrypt.txt Jump to behavior
Source: C:\Users\user\Desktop\msmult64.exe File created: c:\program files\common files\system\msadc\read_instructions_to_decrypt.txt Jump to behavior
Source: C:\Users\user\Desktop\msmult64.exe File created: c:\program files\common files\system\ole db\read_instructions_to_decrypt.txt Jump to behavior
Source: C:\Users\user\Desktop\msmult64.exe File created: c:\program files\google\chrome\application\read_instructions_to_decrypt.txt Jump to behavior
Source: C:\Users\user\Desktop\msmult64.exe File created: c:\program files\microsoft\onedrive\listsync\read_instructions_to_decrypt.txt Jump to behavior
Source: C:\Users\user\Desktop\msmult64.exe File created: c:\program files\mozilla firefox\browser\features\read_instructions_to_decrypt.txt Jump to behavior
Source: C:\Users\user\Desktop\msmult64.exe File created: c:\program files\mozilla firefox\browser\visualelements\read_instructions_to_decrypt.txt Jump to behavior
Source: C:\Users\user\Desktop\msmult64.exe File created: c:\program files\mozilla firefox\defaults\pref\read_instructions_to_decrypt.txt Jump to behavior
Source: C:\Users\user\Desktop\msmult64.exe File created: c:\program files\mozilla firefox\gmp-clearkey\0.1\read_instructions_to_decrypt.txt Jump to behavior
Source: C:\Users\user\Desktop\msmult64.exe File created: c:\program files\reference assemblies\microsoft\framework\read_instructions_to_decrypt.txt Jump to behavior
Source: C:\Users\user\Desktop\msmult64.exe File created: c:\program files (x86)\autoit3\aut2exe\icons\read_instructions_to_decrypt.txt Jump to behavior
Source: C:\Users\user\Desktop\msmult64.exe File created: c:\program files (x86)\autoit3\examples\com\read_instructions_to_decrypt.txt Jump to behavior
Source: C:\Users\user\Desktop\msmult64.exe File created: c:\program files (x86)\autoit3\examples\gui\read_instructions_to_decrypt.txt Jump to behavior
Source: C:\Users\user\Desktop\msmult64.exe File created: c:\program files (x86)\autoit3\examples\helpfile\read_instructions_to_decrypt.txt Jump to behavior
Source: C:\Users\user\Desktop\msmult64.exe File created: c:\program files (x86)\autoit3\extras\autoupdateit\read_instructions_to_decrypt.txt Jump to behavior
Source: C:\Users\user\Desktop\msmult64.exe File created: c:\program files (x86)\autoit3\extras\editors\read_instructions_to_decrypt.txt Jump to behavior
Source: C:\Users\user\Desktop\msmult64.exe File created: c:\program files (x86)\autoit3\extras\geshi\read_instructions_to_decrypt.txt Jump to behavior
Source: C:\Users\user\Desktop\msmult64.exe File created: c:\program files (x86)\autoit3\extras\prettify\read_instructions_to_decrypt.txt Jump to behavior
Source: C:\Users\user\Desktop\msmult64.exe File created: c:\program files (x86)\autoit3\scite\api\read_instructions_to_decrypt.txt Jump to behavior
Source: C:\Users\user\Desktop\msmult64.exe File created: c:\program files (x86)\common files\adobe\arm\read_instructions_to_decrypt.txt Jump to behavior
Source: C:\Users\user\Desktop\msmult64.exe File created: c:\program files (x86)\common files\adobe\reader\read_instructions_to_decrypt.txt Jump to behavior
Source: C:\Users\user\Desktop\msmult64.exe File created: c:\program files (x86)\common files\java\java update\read_instructions_to_decrypt.txt Jump to behavior
Source: C:\Users\user\Desktop\msmult64.exe File created: c:\program files (x86)\common files\microsoft shared\dao\read_instructions_to_decrypt.txt Jump to behavior
Source: C:\Users\user\Desktop\msmult64.exe File created: c:\program files (x86)\common files\microsoft shared\filters\read_instructions_to_decrypt.txt Jump to behavior
Source: C:\Users\user\Desktop\msmult64.exe File created: c:\program files (x86)\common files\microsoft shared\ink\read_instructions_to_decrypt.txt Jump to behavior
Source: C:\Users\user\Desktop\msmult64.exe File created: c:\program files (x86)\common files\microsoft shared\msenv\read_instructions_to_decrypt.txt Jump to behavior
Source: C:\Users\user\Desktop\msmult64.exe File created: c:\program files (x86)\common files\microsoft shared\msinfo\read_instructions_to_decrypt.txt Jump to behavior
Source: C:\Users\user\Desktop\msmult64.exe File created: c:\program files (x86)\common files\microsoft shared\office16\read_instructions_to_decrypt.txt Jump to behavior
Source: C:\Users\user\Desktop\msmult64.exe File created: c:\program files (x86)\common files\microsoft shared\officesoftwareprotectionplatform\read_instructions_to_decrypt.txt Jump to behavior
Source: C:\Users\user\Desktop\msmult64.exe File created: c:\program files (x86)\common files\microsoft shared\stationery\read_instructions_to_decrypt.txt Jump to behavior
Source: C:\Users\user\Desktop\msmult64.exe File created: c:\program files (x86)\common files\microsoft shared\textconv\read_instructions_to_decrypt.txt Jump to behavior
Source: C:\Users\user\Desktop\msmult64.exe File created: c:\program files (x86)\common files\microsoft shared\triedit\read_instructions_to_decrypt.txt Jump to behavior
Source: C:\Users\user\Desktop\msmult64.exe File created: c:\program files (x86)\common files\microsoft shared\vgx\read_instructions_to_decrypt.txt Jump to behavior
Source: C:\Users\user\Desktop\msmult64.exe File created: c:\program files (x86)\common files\microsoft shared\vsta\read_instructions_to_decrypt.txt Jump to behavior
Source: C:\Users\user\Desktop\msmult64.exe File created: c:\program files (x86)\common files\microsoft shared\vsto\read_instructions_to_decrypt.txt Jump to behavior
Source: C:\Users\user\Desktop\msmult64.exe File created: c:\program files (x86)\common files\oracle\java\read_instructions_to_decrypt.txt Jump to behavior
Source: C:\Users\user\Desktop\msmult64.exe File created: c:\program files (x86)\common files\system\ado\read_instructions_to_decrypt.txt Jump to behavior
Source: C:\Users\user\Desktop\msmult64.exe File created: c:\program files (x86)\common files\system\en-gb\read_instructions_to_decrypt.txt Jump to behavior
Source: C:\Users\user\Desktop\msmult64.exe File created: c:\program files (x86)\common files\system\en-us\read_instructions_to_decrypt.txt Jump to behavior
Source: C:\Users\user\Desktop\msmult64.exe File created: c:\program files (x86)\common files\system\msadc\read_instructions_to_decrypt.txt Jump to behavior
Source: C:\Users\user\Desktop\msmult64.exe File created: c:\program files (x86)\common files\system\ole db\read_instructions_to_decrypt.txt Jump to behavior
Source: C:\Users\user\Desktop\msmult64.exe File created: c:\program files (x86)\google\update\1.3.36.312\read_instructions_to_decrypt.txt Jump to behavior
Source: C:\Users\user\Desktop\msmult64.exe File created: c:\program files (x86)\google\update\download\read_instructions_to_decrypt.txt Jump to behavior
Source: C:\Users\user\Desktop\msmult64.exe File created: c:\program files (x86)\google\update\install\read_instructions_to_decrypt.txt Jump to behavior
Source: C:\Users\user\Desktop\msmult64.exe File created: c:\program files (x86)\java\jre-1.8\bin\read_instructions_to_decrypt.txt Jump to behavior
Source: C:\Users\user\Desktop\msmult64.exe File created: c:\program files (x86)\java\jre-1.8\legal\read_instructions_to_decrypt.txt Jump to behavior
Source: C:\Users\user\Desktop\msmult64.exe File created: c:\program files (x86)\java\jre-1.8\lib\read_instructions_to_decrypt.txt Jump to behavior
Source: C:\Users\user\Desktop\msmult64.exe File created: c:\program files (x86)\microsoft\edge\application\read_instructions_to_decrypt.txt Jump to behavior
Source: C:\Users\user\Desktop\msmult64.exe File created: c:\program files (x86)\microsoft\edgecore\117.0.2045.47\read_instructions_to_decrypt.txt Jump to behavior
Source: C:\Users\user\Desktop\msmult64.exe File created: c:\program files (x86)\microsoft\edgewebview\application\read_instructions_to_decrypt.txt Jump to behavior
Source: C:\Users\user\Desktop\msmult64.exe File created: c:\program files (x86)\microsoft office\root\client\read_instructions_to_decrypt.txt Jump to behavior
Source: C:\Users\user\Desktop\msmult64.exe File created: c:\program files (x86)\microsoft office\root\clipart\read_instructions_to_decrypt.txt Jump to behavior
Source: C:\Users\user\Desktop\msmult64.exe File created: c:\program files (x86)\microsoft office\root\document themes 16\read_instructions_to_decrypt.txt Jump to behavior
Source: C:\Users\user\Desktop\msmult64.exe File created: c:\program files (x86)\microsoft office\root\integration\read_instructions_to_decrypt.txt Jump to behavior
Source: C:\Users\user\Desktop\msmult64.exe File created: c:\program files (x86)\microsoft office\root\licenses\read_instructions_to_decrypt.txt Jump to behavior
Source: C:\Users\user\Desktop\msmult64.exe File created: c:\program files (x86)\microsoft office\root\licenses16\read_instructions_to_decrypt.txt Jump to behavior
Source: C:\Users\user\Desktop\msmult64.exe File created: c:\program files (x86)\microsoft office\root\loc\read_instructions_to_decrypt.txt Jump to behavior
Source: C:\Users\user\Desktop\msmult64.exe File created: c:\program files (x86)\microsoft office\root\office15\read_instructions_to_decrypt.txt Jump to behavior
Source: C:\Users\user\Desktop\msmult64.exe File created: c:\program files (x86)\microsoft office\root\office16\read_instructions_to_decrypt.txt Jump to behavior
Source: C:\Users\user\Desktop\msmult64.exe File created: c:\program files (x86)\microsoft office\root\rsodwow6432\read_instructions_to_decrypt.txt Jump to behavior
Source: C:\Users\user\Desktop\msmult64.exe File created: c:\program files (x86)\microsoft office\root\stationery\read_instructions_to_decrypt.txt Jump to behavior
Source: C:\Users\user\Desktop\msmult64.exe File created: c:\program files (x86)\microsoft office\root\vfs\read_instructions_to_decrypt.txt Jump to behavior
Source: C:\Users\user\Desktop\msmult64.exe File created: c:\program files (x86)\microsoft office\root\vreg\read_instructions_to_decrypt.txt Jump to behavior
Source: C:\Users\user\Desktop\msmult64.exe File created: c:\program files (x86)\microsoft office\root\vregwow6432\read_instructions_to_decrypt.txt Jump to behavior
Source: C:\Users\user\Desktop\msmult64.exe File created: c:\program files (x86)\microsoft office\updates\apply\read_instructions_to_decrypt.txt Jump to behavior
Source: C:\Users\user\Desktop\msmult64.exe File created: c:\program files (x86)\microsoft office\updates\configfolders\read_instructions_to_decrypt.txt Jump to behavior
Source: C:\Users\user\Desktop\msmult64.exe File created: c:\program files (x86)\microsoft office\updates\download\read_instructions_to_decrypt.txt Jump to behavior
Source: C:\Users\user\Desktop\msmult64.exe File created: c:\program files (x86)\microsoft onedrive\23.038.0219.0001\amd64\read_instructions_to_decrypt.txt Jump to behavior
Source: C:\Users\user\Desktop\msmult64.exe File created: c:\program files (x86)\microsoft onedrive\23.038.0219.0001\ar\read_instructions_to_decrypt.txt Jump to behavior
Source: C:\Users\user\Desktop\msmult64.exe File created: c:\program files (x86)\microsoft onedrive\23.038.0219.0001\arm64\read_instructions_to_decrypt.txt Jump to behavior
Source: C:\Users\user\Desktop\msmult64.exe File created: c:\program files (x86)\microsoft onedrive\23.038.0219.0001\as-in\read_instructions_to_decrypt.txt Jump to behavior
Source: C:\Users\user\Desktop\msmult64.exe File created: c:\program files (x86)\microsoft onedrive\23.038.0219.0001\assets\read_instructions_to_decrypt.txt Jump to behavior
Source: C:\Users\user\Desktop\msmult64.exe File created: c:\program files (x86)\microsoft onedrive\23.038.0219.0001\az-latn-az\read_instructions_to_decrypt.txt Jump to behavior
Source: C:\Users\user\Desktop\msmult64.exe File created: c:\program files (x86)\microsoft onedrive\23.038.0219.0001\bg\read_instructions_to_decrypt.txt Jump to behavior
Source: C:\Users\user\Desktop\msmult64.exe File created: c:\program files (x86)\microsoft onedrive\23.038.0219.0001\bn-in\read_instructions_to_decrypt.txt Jump to behavior
Source: C:\Users\user\Desktop\msmult64.exe File created: c:\program files (x86)\microsoft onedrive\23.038.0219.0001\bs-latn-ba\read_instructions_to_decrypt.txt Jump to behavior
Source: C:\Users\user\Desktop\msmult64.exe File created: c:\program files (x86)\microsoft onedrive\23.038.0219.0001\bundle\read_instructions_to_decrypt.txt Jump to behavior
Source: C:\Users\user\Desktop\msmult64.exe File created: c:\program files (x86)\microsoft onedrive\23.038.0219.0001\ca\read_instructions_to_decrypt.txt Jump to behavior
Source: C:\Users\user\Desktop\msmult64.exe File created: c:\program files (x86)\microsoft onedrive\23.038.0219.0001\ca-es-valencia\read_instructions_to_decrypt.txt Jump to behavior
Source: C:\Users\user\Desktop\msmult64.exe File created: c:\program files (x86)\microsoft onedrive\23.038.0219.0001\cs\read_instructions_to_decrypt.txt Jump to behavior
Source: C:\Users\user\Desktop\msmult64.exe File created: c:\program files (x86)\microsoft onedrive\23.038.0219.0001\cy-gb\read_instructions_to_decrypt.txt Jump to behavior
Source: C:\Users\user\Desktop\msmult64.exe File created: c:\program files (x86)\microsoft onedrive\23.038.0219.0001\da\read_instructions_to_decrypt.txt Jump to behavior
Source: C:\Users\user\Desktop\msmult64.exe File created: c:\program files (x86)\microsoft onedrive\23.038.0219.0001\de\read_instructions_to_decrypt.txt Jump to behavior
Source: C:\Users\user\Desktop\msmult64.exe File created: c:\program files (x86)\microsoft onedrive\23.038.0219.0001\el\read_instructions_to_decrypt.txt Jump to behavior
Source: C:\Users\user\Desktop\msmult64.exe File created: c:\program files (x86)\microsoft onedrive\23.038.0219.0001\en\read_instructions_to_decrypt.txt Jump to behavior
Source: C:\Users\user\Desktop\msmult64.exe File created: c:\program files (x86)\microsoft onedrive\23.038.0219.0001\en-gb\read_instructions_to_decrypt.txt Jump to behavior
Source: C:\Users\user\Desktop\msmult64.exe File created: c:\program files (x86)\microsoft onedrive\23.038.0219.0001\en-us\read_instructions_to_decrypt.txt Jump to behavior
Source: C:\Users\user\Desktop\msmult64.exe File created: c:\program files (x86)\microsoft onedrive\23.038.0219.0001\es\read_instructions_to_decrypt.txt Jump to behavior
Source: C:\Users\user\Desktop\msmult64.exe File created: c:\program files (x86)\microsoft onedrive\23.038.0219.0001\et\read_instructions_to_decrypt.txt Jump to behavior
Source: C:\Users\user\Desktop\msmult64.exe File created: c:\program files (x86)\microsoft onedrive\23.038.0219.0001\eu\read_instructions_to_decrypt.txt Jump to behavior
Source: C:\Users\user\Desktop\msmult64.exe File created: c:\program files (x86)\microsoft onedrive\23.038.0219.0001\fa\read_instructions_to_decrypt.txt Jump to behavior
Source: C:\Users\user\Desktop\msmult64.exe File created: c:\program files (x86)\microsoft onedrive\23.038.0219.0001\fi\read_instructions_to_decrypt.txt Jump to behavior
Source: C:\Users\user\Desktop\msmult64.exe File created: c:\program files (x86)\microsoft onedrive\23.038.0219.0001\fil-ph\read_instructions_to_decrypt.txt Jump to behavior
Source: C:\Users\user\Desktop\msmult64.exe File created: c:\program files (x86)\microsoft onedrive\23.038.0219.0001\fr\read_instructions_to_decrypt.txt Jump to behavior
Source: C:\Users\user\Desktop\msmult64.exe File created: c:\program files (x86)\microsoft onedrive\23.038.0219.0001\ga-ie\read_instructions_to_decrypt.txt Jump to behavior
Source: C:\Users\user\Desktop\msmult64.exe File created: c:\program files (x86)\microsoft onedrive\23.038.0219.0001\gd\read_instructions_to_decrypt.txt Jump to behavior
Source: C:\Users\user\Desktop\msmult64.exe File created: c:\program files (x86)\microsoft onedrive\23.038.0219.0001\gl\read_instructions_to_decrypt.txt Jump to behavior
Source: C:\Users\user\Desktop\msmult64.exe File created: c:\program files (x86)\microsoft onedrive\23.038.0219.0001\gu\read_instructions_to_decrypt.txt Jump to behavior
Source: C:\Users\user\Desktop\msmult64.exe File created: c:\program files (x86)\microsoft onedrive\23.038.0219.0001\he\read_instructions_to_decrypt.txt Jump to behavior
Source: C:\Users\user\Desktop\msmult64.exe File created: c:\program files (x86)\microsoft onedrive\23.038.0219.0001\hi\read_instructions_to_decrypt.txt Jump to behavior
Source: C:\Users\user\Desktop\msmult64.exe File created: c:\program files (x86)\microsoft onedrive\23.038.0219.0001\hr\read_instructions_to_decrypt.txt Jump to behavior
Source: C:\Users\user\Desktop\msmult64.exe File created: c:\program files (x86)\microsoft onedrive\23.038.0219.0001\hu\read_instructions_to_decrypt.txt Jump to behavior
Source: C:\Users\user\Desktop\msmult64.exe File created: c:\program files (x86)\microsoft onedrive\23.038.0219.0001\id\read_instructions_to_decrypt.txt Jump to behavior
Source: C:\Users\user\Desktop\msmult64.exe File created: c:\program files (x86)\microsoft onedrive\23.038.0219.0001\ig-ng\read_instructions_to_decrypt.txt Jump to behavior
Source: C:\Users\user\Desktop\msmult64.exe File created: c:\program files (x86)\microsoft onedrive\23.038.0219.0001\imageformats\read_instructions_to_decrypt.txt Jump to behavior
Source: C:\Users\user\Desktop\msmult64.exe File created: c:\program files (x86)\microsoft onedrive\23.038.0219.0001\images\read_instructions_to_decrypt.txt Jump to behavior
Source: C:\Users\user\Desktop\msmult64.exe File created: c:\program files (x86)\microsoft onedrive\23.038.0219.0001\irmprotectors\read_instructions_to_decrypt.txt Jump to behavior
Source: C:\Users\user\Desktop\msmult64.exe File created: c:\program files (x86)\microsoft onedrive\23.038.0219.0001\is\read_instructions_to_decrypt.txt Jump to behavior
Source: C:\Users\user\Desktop\msmult64.exe File created: c:\program files (x86)\microsoft onedrive\23.038.0219.0001\it\read_instructions_to_decrypt.txt Jump to behavior
Source: C:\Users\user\Desktop\msmult64.exe File created: c:\program files (x86)\microsoft onedrive\23.038.0219.0001\ja\read_instructions_to_decrypt.txt Jump to behavior
Source: C:\Users\user\Desktop\msmult64.exe File created: c:\program files (x86)\microsoft onedrive\23.038.0219.0001\ka\read_instructions_to_decrypt.txt Jump to behavior
Source: C:\Users\user\Desktop\msmult64.exe File created: c:\program files (x86)\microsoft onedrive\23.038.0219.0001\kk\read_instructions_to_decrypt.txt Jump to behavior
Source: C:\Users\user\Desktop\msmult64.exe File created: c:\program files (x86)\microsoft onedrive\23.038.0219.0001\km-kh\read_instructions_to_decrypt.txt Jump to behavior
Source: C:\Users\user\Desktop\msmult64.exe File created: c:\program files (x86)\microsoft onedrive\23.038.0219.0001\kn\read_instructions_to_decrypt.txt Jump to behavior
Source: C:\Users\user\Desktop\msmult64.exe File created: c:\program files (x86)\microsoft onedrive\23.038.0219.0001\ko\read_instructions_to_decrypt.txt Jump to behavior
Source: C:\Users\user\Desktop\msmult64.exe File created: c:\program files (x86)\microsoft onedrive\23.038.0219.0001\kok\read_instructions_to_decrypt.txt Jump to behavior
Source: C:\Users\user\Desktop\msmult64.exe File created: c:\program files (x86)\microsoft onedrive\23.038.0219.0001\ku-arab\read_instructions_to_decrypt.txt Jump to behavior
Source: C:\Users\user\Desktop\msmult64.exe File created: c:\program files (x86)\microsoft onedrive\23.038.0219.0001\lb-lu\read_instructions_to_decrypt.txt Jump to behavior
Source: C:\Users\user\Desktop\msmult64.exe File created: c:\program files (x86)\microsoft onedrive\23.038.0219.0001\logoimages\read_instructions_to_decrypt.txt Jump to behavior
Source: C:\Users\user\Desktop\msmult64.exe File created: c:\program files (x86)\microsoft onedrive\23.038.0219.0001\lt\read_instructions_to_decrypt.txt Jump to behavior
Source: C:\Users\user\Desktop\msmult64.exe File created: c:\program files (x86)\microsoft onedrive\23.038.0219.0001\lv\read_instructions_to_decrypt.txt Jump to behavior
Source: C:\Users\user\Desktop\msmult64.exe File created: c:\program files (x86)\microsoft onedrive\23.038.0219.0001\mi-nz\read_instructions_to_decrypt.txt Jump to behavior
Source: C:\Users\user\Desktop\msmult64.exe File created: c:\program files (x86)\microsoft onedrive\23.038.0219.0001\mk\read_instructions_to_decrypt.txt Jump to behavior
Source: C:\Users\user\Desktop\msmult64.exe File created: c:\program files (x86)\microsoft onedrive\23.038.0219.0001\ml-in\read_instructions_to_decrypt.txt Jump to behavior
Source: C:\Users\user\Desktop\msmult64.exe File created: c:\program files (x86)\microsoft onedrive\23.038.0219.0001\mn\read_instructions_to_decrypt.txt Jump to behavior
Source: C:\Users\user\Desktop\msmult64.exe File created: c:\program files (x86)\microsoft onedrive\23.038.0219.0001\mr\read_instructions_to_decrypt.txt Jump to behavior
Source: C:\Users\user\Desktop\msmult64.exe File created: c:\program files (x86)\microsoft onedrive\23.038.0219.0001\ms\read_instructions_to_decrypt.txt Jump to behavior
Source: C:\Users\user\Desktop\msmult64.exe File created: c:\program files (x86)\microsoft onedrive\23.038.0219.0001\mt-mt\read_instructions_to_decrypt.txt Jump to behavior
Source: C:\Users\user\Desktop\msmult64.exe File created: c:\program files (x86)\microsoft onedrive\23.038.0219.0001\nb-no\read_instructions_to_decrypt.txt Jump to behavior
Source: C:\Users\user\Desktop\msmult64.exe File created: c:\program files (x86)\microsoft onedrive\23.038.0219.0001\ne-np\read_instructions_to_decrypt.txt Jump to behavior
Source: C:\Users\user\Desktop\msmult64.exe File created: c:\program files (x86)\microsoft onedrive\23.038.0219.0001\nl\read_instructions_to_decrypt.txt Jump to behavior
Source: C:\Users\user\Desktop\msmult64.exe File created: c:\program files (x86)\microsoft onedrive\23.038.0219.0001\nn-no\read_instructions_to_decrypt.txt Jump to behavior
Source: C:\Users\user\Desktop\msmult64.exe File created: c:\program files (x86)\microsoft onedrive\23.038.0219.0001\nso-za\read_instructions_to_decrypt.txt Jump to behavior
Source: C:\Users\user\Desktop\msmult64.exe File created: c:\program files (x86)\microsoft onedrive\23.038.0219.0001\or-in\read_instructions_to_decrypt.txt Jump to behavior
Source: C:\Users\user\Desktop\msmult64.exe File created: c:\program files (x86)\microsoft onedrive\23.038.0219.0001\pa\read_instructions_to_decrypt.txt Jump to behavior
Source: C:\Users\user\Desktop\msmult64.exe File created: c:\program files (x86)\microsoft onedrive\23.038.0219.0001\pa-arab-pk\read_instructions_to_decrypt.txt Jump to behavior
Source: C:\Users\user\Desktop\msmult64.exe File created: c:\program files (x86)\microsoft onedrive\23.038.0219.0001\pl\read_instructions_to_decrypt.txt Jump to behavior
Source: C:\Users\user\Desktop\msmult64.exe File created: c:\program files (x86)\microsoft onedrive\23.038.0219.0001\platforms\read_instructions_to_decrypt.txt Jump to behavior
Source: C:\Users\user\Desktop\msmult64.exe File created: c:\program files (x86)\microsoft onedrive\23.038.0219.0001\pt-br\read_instructions_to_decrypt.txt Jump to behavior
Source: C:\Users\user\Desktop\msmult64.exe File created: c:\program files (x86)\microsoft onedrive\23.038.0219.0001\pt-pt\read_instructions_to_decrypt.txt Jump to behavior
Source: C:\Users\user\Desktop\msmult64.exe File created: c:\program files (x86)\microsoft onedrive\23.038.0219.0001\qml\read_instructions_to_decrypt.txt Jump to behavior
Source: C:\Users\user\Desktop\msmult64.exe File created: c:\program files (x86)\microsoft onedrive\23.038.0219.0001\quc\read_instructions_to_decrypt.txt Jump to behavior
Source: C:\Users\user\Desktop\msmult64.exe File created: c:\program files (x86)\microsoft onedrive\23.038.0219.0001\quz-pe\read_instructions_to_decrypt.txt Jump to behavior
Source: C:\Users\user\Desktop\msmult64.exe File created: c:\program files (x86)\microsoft onedrive\23.038.0219.0001\ro\read_instructions_to_decrypt.txt Jump to behavior
Source: C:\Users\user\Desktop\msmult64.exe File created: c:\program files (x86)\microsoft onedrive\23.038.0219.0001\ru\read_instructions_to_decrypt.txt Jump to behavior
Source: C:\Users\user\Desktop\msmult64.exe File created: c:\program files (x86)\microsoft onedrive\23.038.0219.0001\rw\read_instructions_to_decrypt.txt Jump to behavior
Source: C:\Users\user\Desktop\msmult64.exe File created: c:\program files (x86)\microsoft onedrive\23.038.0219.0001\sk\read_instructions_to_decrypt.txt Jump to behavior
Source: C:\Users\user\Desktop\msmult64.exe File created: c:\program files (x86)\microsoft onedrive\23.038.0219.0001\sl\read_instructions_to_decrypt.txt Jump to behavior
Source: C:\Users\user\Desktop\msmult64.exe File created: c:\program files (x86)\microsoft onedrive\23.038.0219.0001\sourcemaps\read_instructions_to_decrypt.txt Jump to behavior
Source: C:\Users\user\Desktop\msmult64.exe File created: c:\program files (x86)\microsoft onedrive\23.038.0219.0001\sparsepackage\read_instructions_to_decrypt.txt Jump to behavior
Source: C:\Users\user\Desktop\msmult64.exe File created: c:\program files (x86)\microsoft onedrive\23.038.0219.0001\sq\read_instructions_to_decrypt.txt Jump to behavior
Source: C:\Users\user\Desktop\msmult64.exe File created: c:\program files (x86)\microsoft onedrive\23.038.0219.0001\sr-cyrl-ba\read_instructions_to_decrypt.txt Jump to behavior
Source: C:\Users\user\Desktop\msmult64.exe File created: c:\program files (x86)\microsoft onedrive\23.038.0219.0001\sr-cyrl-rs\read_instructions_to_decrypt.txt Jump to behavior
Source: C:\Users\user\Desktop\msmult64.exe File created: c:\program files (x86)\microsoft onedrive\23.038.0219.0001\sr-latn-rs\read_instructions_to_decrypt.txt Jump to behavior
Source: C:\Users\user\Desktop\msmult64.exe File created: c:\program files (x86)\microsoft onedrive\23.038.0219.0001\sv\read_instructions_to_decrypt.txt Jump to behavior
Source: C:\Users\user\Desktop\msmult64.exe File created: c:\program files (x86)\microsoft onedrive\23.038.0219.0001\ta\read_instructions_to_decrypt.txt Jump to behavior
Source: C:\Users\user\Desktop\msmult64.exe File created: c:\program files (x86)\microsoft onedrive\23.038.0219.0001\te\read_instructions_to_decrypt.txt Jump to behavior
Source: C:\Users\user\Desktop\msmult64.exe File created: c:\program files (x86)\microsoft onedrive\23.038.0219.0001\tg\read_instructions_to_decrypt.txt Jump to behavior
Source: C:\Users\user\Desktop\msmult64.exe File created: c:\program files (x86)\microsoft onedrive\23.038.0219.0001\th\read_instructions_to_decrypt.txt Jump to behavior
Source: C:\Users\user\Desktop\msmult64.exe File created: c:\program files (x86)\microsoft onedrive\23.038.0219.0001\ti\read_instructions_to_decrypt.txt Jump to behavior
Source: C:\Users\user\Desktop\msmult64.exe File created: c:\program files (x86)\microsoft onedrive\23.038.0219.0001\tn-za\read_instructions_to_decrypt.txt Jump to behavior
Source: C:\Users\user\Desktop\msmult64.exe File created: c:\program files (x86)\microsoft onedrive\23.038.0219.0001\tr\read_instructions_to_decrypt.txt Jump to behavior
Source: C:\Users\user\Desktop\msmult64.exe File created: c:\program files (x86)\microsoft onedrive\23.038.0219.0001\tt\read_instructions_to_decrypt.txt Jump to behavior
Source: C:\Users\user\Desktop\msmult64.exe File created: c:\program files (x86)\microsoft onedrive\23.038.0219.0001\tzdata\read_instructions_to_decrypt.txt Jump to behavior
Source: C:\Users\user\Desktop\msmult64.exe File created: c:\program files (x86)\microsoft onedrive\23.038.0219.0001\ug\read_instructions_to_decrypt.txt Jump to behavior
Source: C:\Users\user\Desktop\msmult64.exe File created: c:\program files (x86)\microsoft onedrive\23.038.0219.0001\uk\read_instructions_to_decrypt.txt Jump to behavior
Source: C:\Users\user\Desktop\msmult64.exe File created: c:\program files (x86)\microsoft onedrive\23.038.0219.0001\ur\read_instructions_to_decrypt.txt Jump to behavior
Source: C:\Users\user\Desktop\msmult64.exe File created: c:\program files (x86)\microsoft onedrive\23.038.0219.0001\vi\read_instructions_to_decrypt.txt Jump to behavior
Source: C:\Users\user\Desktop\msmult64.exe File created: c:\program files (x86)\microsoft onedrive\23.038.0219.0001\wo\read_instructions_to_decrypt.txt Jump to behavior
Source: C:\Users\user\Desktop\msmult64.exe File created: c:\program files (x86)\microsoft onedrive\23.038.0219.0001\xh-za\read_instructions_to_decrypt.txt Jump to behavior
Source: C:\Users\user\Desktop\msmult64.exe File created: c:\program files (x86)\microsoft onedrive\23.038.0219.0001\yo-ng\read_instructions_to_decrypt.txt Jump to behavior
Source: C:\Users\user\Desktop\msmult64.exe File created: c:\program files (x86)\microsoft onedrive\23.038.0219.0001\zh-cn\read_instructions_to_decrypt.txt Jump to behavior
Source: C:\Users\user\Desktop\msmult64.exe File created: c:\program files (x86)\microsoft onedrive\23.038.0219.0001\zh-tw\read_instructions_to_decrypt.txt Jump to behavior
Source: C:\Users\user\Desktop\msmult64.exe File created: c:\program files (x86)\microsoft onedrive\setup\logs\read_instructions_to_decrypt.txt Jump to behavior
Source: C:\Users\user\Desktop\msmult64.exe File created: c:\program files (x86)\msecache\officekms\catalog\read_instructions_to_decrypt.txt Jump to behavior
Source: C:\Users\user\Desktop\msmult64.exe File created: c:\program files (x86)\msecache\officekms\win7\read_instructions_to_decrypt.txt Jump to behavior
Source: C:\Users\user\Desktop\msmult64.exe File created: c:\program files (x86)\msecache\officekms\win8\read_instructions_to_decrypt.txt Jump to behavior
Source: C:\Users\user\Desktop\msmult64.exe File created: c:\program files (x86)\reference assemblies\microsoft\framework\read_instructions_to_decrypt.txt Jump to behavior
Source: C:\Users\user\Desktop\msmult64.exe File created: c:\programdata\adobe\arm\acrobat_23.006.20320\read_instructions_to_decrypt.txt Jump to behavior
Source: C:\Users\user\Desktop\msmult64.exe File created: c:\programdata\adobe\arm\{291aa914-a987-4ce9-bd63-0c0a92d435e5}\read_instructions_to_decrypt.txt Jump to behavior
Source: C:\Users\user\Desktop\msmult64.exe File created: c:\programdata\microsoft\appv\setup\read_instructions_to_decrypt.txt Jump to behavior
Source: C:\Users\user\Desktop\msmult64.exe File created: c:\programdata\microsoft\clicktorun\machinedata\read_instructions_to_decrypt.txt Jump to behavior
Source: C:\Users\user\Desktop\msmult64.exe File created: c:\programdata\microsoft\clicktorun\productreleases\read_instructions_to_decrypt.txt Jump to behavior
Source: C:\Users\user\Desktop\msmult64.exe File created: c:\programdata\microsoft\clicktorun\userdata\read_instructions_to_decrypt.txt Jump to behavior
Source: C:\Users\user\Desktop\msmult64.exe File created: c:\programdata\microsoft\clicktorun\{9ac08e99-230b-47e8-9721-4577b7f124ea}\read_instructions_to_decrypt.txt Jump to behavior
Source: C:\Users\user\Desktop\msmult64.exe File created: c:\programdata\microsoft\crypto\dss\read_instructions_to_decrypt.txt Jump to behavior
Source: C:\Users\user\Desktop\msmult64.exe File created: c:\programdata\microsoft\crypto\keys\read_instructions_to_decrypt.txt Jump to behavior
Source: C:\Users\user\Desktop\msmult64.exe File created: c:\programdata\microsoft\crypto\pcpksp\read_instructions_to_decrypt.txt Jump to behavior
Source: C:\Users\user\Desktop\msmult64.exe File created: c:\programdata\microsoft\crypto\rsa\read_instructions_to_decrypt.txt Jump to behavior
Source: C:\Users\user\Desktop\msmult64.exe File created: c:\programdata\microsoft\crypto\systemkeys\read_instructions_to_decrypt.txt Jump to behavior
Source: C:\Users\user\Desktop\msmult64.exe File created: c:\programdata\microsoft\device stage\device\read_instructions_to_decrypt.txt Jump to behavior
Source: C:\Users\user\Desktop\msmult64.exe File created: c:\programdata\microsoft\device stage\task\read_instructions_to_decrypt.txt Jump to behavior
Source: C:\Users\user\Desktop\msmult64.exe File created: c:\programdata\microsoft\diagnosis\customtraceprofiles\read_instructions_to_decrypt.txt Jump to behavior
Source: C:\Users\user\Desktop\msmult64.exe File created: c:\programdata\microsoft\diagnosis\downloadedscenarios\read_instructions_to_decrypt.txt Jump to behavior
Source: C:\Users\user\Desktop\msmult64.exe File created: c:\programdata\microsoft\diagnosis\downloadedsettings\read_instructions_to_decrypt.txt Jump to behavior
Source: C:\Users\user\Desktop\msmult64.exe File created: c:\programdata\microsoft\diagnosis\etllogs\read_instructions_to_decrypt.txt Jump to behavior
Source: C:\Users\user\Desktop\msmult64.exe File created: c:\programdata\microsoft\diagnosis\eventtranscript\read_instructions_to_decrypt.txt Jump to behavior
Source: C:\Users\user\Desktop\msmult64.exe File created: c:\programdata\microsoft\diagnosis\feedbackhub\read_instructions_to_decrypt.txt Jump to behavior
Source: C:\Users\user\Desktop\msmult64.exe File created: c:\programdata\microsoft\diagnosis\localtracestore\read_instructions_to_decrypt.txt Jump to behavior
Source: C:\Users\user\Desktop\msmult64.exe File created: c:\programdata\microsoft\diagnosis\scenariossqlstore\read_instructions_to_decrypt.txt Jump to behavior
Source: C:\Users\user\Desktop\msmult64.exe File created: c:\programdata\microsoft\diagnosis\sideload\read_instructions_to_decrypt.txt Jump to behavior
Source: C:\Users\user\Desktop\msmult64.exe File created: c:\programdata\microsoft\diagnosis\siufloc\read_instructions_to_decrypt.txt Jump to behavior
Source: C:\Users\user\Desktop\msmult64.exe File created: c:\programdata\microsoft\diagnosis\softlanding\read_instructions_to_decrypt.txt Jump to behavior
Source: C:\Users\user\Desktop\msmult64.exe File created: c:\programdata\microsoft\diagnosis\softlandingstage\read_instructions_to_decrypt.txt Jump to behavior
Source: C:\Users\user\Desktop\msmult64.exe File created: c:\programdata\microsoft\diagnosis\tenantstorage\read_instructions_to_decrypt.txt Jump to behavior
Source: C:\Users\user\Desktop\msmult64.exe File created: c:\programdata\microsoft\diagnosis\timetraveldebuggingstorage\read_instructions_to_decrypt.txt Jump to behavior
Source: C:\Users\user\Desktop\msmult64.exe File created: c:\programdata\microsoft\diagnosticlogcsp\channels\read_instructions_to_decrypt.txt Jump to behavior
Source: C:\Users\user\Desktop\msmult64.exe File created: c:\programdata\microsoft\diagnosticlogcsp\collectors\read_instructions_to_decrypt.txt Jump to behavior
Source: C:\Users\user\Desktop\msmult64.exe File created: c:\programdata\microsoft\diagnosticlogcsp\devicestatedata\read_instructions_to_decrypt.txt Jump to behavior
Source: C:\Users\user\Desktop\msmult64.exe File created: c:\programdata\microsoft\drm\server\read_instructions_to_decrypt.txt Jump to behavior
Source: C:\Users\user\Desktop\msmult64.exe File created: c:\programdata\microsoft\edgeupdate\log\read_instructions_to_decrypt.txt Jump to behavior
Source: C:\Users\user\Desktop\msmult64.exe File created: c:\programdata\microsoft\identitycrl\int\read_instructions_to_decrypt.txt Jump to behavior
Source: C:\Users\user\Desktop\msmult64.exe File created: c:\programdata\microsoft\identitycrl\production\read_instructions_to_decrypt.txt Jump to behavior
Source: C:\Users\user\Desktop\msmult64.exe File created: c:\programdata\microsoft\netframework\breadcrumbstore\read_instructions_to_decrypt.txt Jump to behavior
Source: C:\Users\user\Desktop\msmult64.exe File created: c:\programdata\microsoft\network\connections\read_instructions_to_decrypt.txt Jump to behavior
Source: C:\Users\user\Desktop\msmult64.exe File created: c:\programdata\microsoft\network\downloader\read_instructions_to_decrypt.txt Jump to behavior
Source: C:\Users\user\Desktop\msmult64.exe File created: c:\programdata\microsoft\provisioning\assetcache\read_instructions_to_decrypt.txt Jump to behavior
Source: C:\Users\user\Desktop\msmult64.exe File created: c:\programdata\microsoft\search\data\read_instructions_to_decrypt.txt Jump to behavior
Source: C:\Users\user\Desktop\msmult64.exe File created: c:\programdata\microsoft\settings\accounts\read_instructions_to_decrypt.txt Jump to behavior
Source: C:\Users\user\Desktop\msmult64.exe File created: c:\programdata\microsoft\smsrouter\messagestore\read_instructions_to_decrypt.txt Jump to behavior
Source: C:\Users\user\Desktop\msmult64.exe File created: c:\programdata\microsoft\uev\scripts\read_instructions_to_decrypt.txt Jump to behavior
Source: C:\Users\user\Desktop\msmult64.exe File created: c:\programdata\microsoft\vault\ac658cb4-9126-49bd-b877-31eedab3f204\read_instructions_to_decrypt.txt Jump to behavior
Source: C:\Users\user\Desktop\msmult64.exe File created: c:\programdata\microsoft\winmsipc\server\read_instructions_to_decrypt.txt Jump to behavior
Source: C:\Users\user\Desktop\msmult64.exe File created: c:\programdata\mozilla-1de4eec8-1241-4177-a864-e594e8d1fb38\updates\308046b0af4a39cb\read_instructions_to_decrypt.txt Jump to behavior
Source: C:\Users\user\Desktop\msmult64.exe File created: c:\programdata\package cache\{0025dd72-a959-45b5-a0a3-7efeb15a8050}v14.36.32532\packages\read_instructions_to_decrypt.txt Jump to behavior
Source: C:\Users\user\Desktop\msmult64.exe File created: c:\programdata\package cache\{d5d19e2f-7189-42fe-8103-92cd1fa457c2}v14.36.32532\packages\read_instructions_to_decrypt.txt Jump to behavior
Source: C:\Users\user\Desktop\msmult64.exe File created: c:\programdata\packages\microsoft.549981c3f5f10_8wekyb3d8bbwe\s-1-5-21-2246122658-3693405117-2476756634-1001\read_instructions_to_decrypt.txt Jump to behavior
Source: C:\Users\user\Desktop\msmult64.exe File created: c:\programdata\packages\microsoft.549981c3f5f10_8wekyb3d8bbwe\s-1-5-21-2246122658-3693405117-2476756634-1002\read_instructions_to_decrypt.txt Jump to behavior
Source: C:\Users\user\Desktop\msmult64.exe File created: c:\programdata\packages\microsoft.desktopappinstaller_8wekyb3d8bbwe\s-1-5-21-2246122658-3693405117-2476756634-1001\read_instructions_to_decrypt.txt Jump to behavior
Source: C:\Users\user\Desktop\msmult64.exe File created: c:\programdata\packages\microsoft.desktopappinstaller_8wekyb3d8bbwe\s-1-5-21-2246122658-3693405117-2476756634-1002\read_instructions_to_decrypt.txt Jump to behavior
Source: C:\Users\user\Desktop\msmult64.exe File created: c:\programdata\packages\microsoft.getstarted_8wekyb3d8bbwe\s-1-5-21-2246122658-3693405117-2476756634-1001\read_instructions_to_decrypt.txt Jump to behavior
Source: C:\Users\user\Desktop\msmult64.exe File created: c:\programdata\packages\microsoft.getstarted_8wekyb3d8bbwe\s-1-5-21-2246122658-3693405117-2476756634-1002\read_instructions_to_decrypt.txt Jump to behavior
Source: C:\Users\user\Desktop\msmult64.exe File created: c:\programdata\packages\microsoft.microsoft3dviewer_8wekyb3d8bbwe\s-1-5-21-2246122658-3693405117-2476756634-1001\read_instructions_to_decrypt.txt Jump to behavior
Source: C:\Users\user\Desktop\msmult64.exe File created: c:\programdata\packages\microsoft.microsoft3dviewer_8wekyb3d8bbwe\s-1-5-21-2246122658-3693405117-2476756634-1002\read_instructions_to_decrypt.txt Jump to behavior
Source: C:\Users\user\Desktop\msmult64.exe File created: c:\programdata\packages\microsoft.microsoftedge.stable_8wekyb3d8bbwe\s-1-5-21-2246122658-3693405117-2476756634-1002\read_instructions_to_decrypt.txt Jump to behavior
Source: C:\Users\user\Desktop\msmult64.exe File created: c:\programdata\packages\microsoft.microsoftofficehub_8wekyb3d8bbwe\s-1-5-21-2246122658-3693405117-2476756634-1001\read_instructions_to_decrypt.txt Jump to behavior
Source: C:\Users\user\Desktop\msmult64.exe File created: c:\programdata\packages\microsoft.microsoftofficehub_8wekyb3d8bbwe\s-1-5-21-2246122658-3693405117-2476756634-1002\read_instructions_to_decrypt.txt Jump to behavior
Source: C:\Users\user\Desktop\msmult64.exe File created: c:\programdata\packages\microsoft.mixedreality.portal_8wekyb3d8bbwe\s-1-5-21-2246122658-3693405117-2476756634-1001\read_instructions_to_decrypt.txt Jump to behavior
Source: C:\Users\user\Desktop\msmult64.exe File created: c:\programdata\packages\microsoft.mixedreality.portal_8wekyb3d8bbwe\s-1-5-21-2246122658-3693405117-2476756634-1002\read_instructions_to_decrypt.txt Jump to behavior
Source: C:\Users\user\Desktop\msmult64.exe File created: c:\programdata\packages\microsoft.office.onenote_8wekyb3d8bbwe\s-1-5-21-2246122658-3693405117-2476756634-1001\read_instructions_to_decrypt.txt Jump to behavior
Source: C:\Users\user\Desktop\msmult64.exe File created: c:\programdata\packages\microsoft.office.onenote_8wekyb3d8bbwe\s-1-5-21-2246122658-3693405117-2476756634-1002\read_instructions_to_decrypt.txt Jump to behavior
Source: C:\Users\user\Desktop\msmult64.exe File created: c:\programdata\packages\microsoft.skypeapp_kzf8qxf38zg5c\s-1-5-21-2246122658-3693405117-2476756634-1001\read_instructions_to_decrypt.txt Jump to behavior
Source: C:\Users\user\Desktop\msmult64.exe File created: c:\programdata\packages\microsoft.skypeapp_kzf8qxf38zg5c\s-1-5-21-2246122658-3693405117-2476756634-1002\read_instructions_to_decrypt.txt Jump to behavior
Source: C:\Users\user\Desktop\msmult64.exe File created: c:\programdata\usoshared\logs\user\read_instructions_to_decrypt.txt Jump to behavior
Source: C:\Users\user\Desktop\msmult64.exe File created: c:\users\default\appdata\local\read_instructions_to_decrypt.txt Jump to behavior
Source: C:\Users\user\Desktop\msmult64.exe File created: c:\users\default\appdata\roaming\read_instructions_to_decrypt.txt Jump to behavior
Source: C:\Users\user\Desktop\msmult64.exe File created: c:\users\user\appdata\local\read_instructions_to_decrypt.txt Jump to behavior
Source: C:\Users\user\Desktop\msmult64.exe File created: c:\users\user\appdata\locallow\read_instructions_to_decrypt.txt Jump to behavior
Source: C:\Users\user\Desktop\msmult64.exe File created: c:\users\user\appdata\roaming\read_instructions_to_decrypt.txt Jump to behavior
Source: C:\Users\user\Desktop\msmult64.exe File created: c:\users\user\desktop\kzwfnrxyki\read_instructions_to_decrypt.txt Jump to behavior
Source: C:\Users\user\Desktop\msmult64.exe File created: c:\users\user\desktop\nhpkizuusg\read_instructions_to_decrypt.txt Jump to behavior
Source: C:\Users\user\Desktop\msmult64.exe File created: c:\users\user\desktop\ummbdneqbn\read_instructions_to_decrypt.txt Jump to behavior
Source: C:\Users\user\Desktop\msmult64.exe File created: c:\users\user\desktop\vlzdgukutz\read_instructions_to_decrypt.txt Jump to behavior
Source: C:\Users\user\Desktop\msmult64.exe File created: c:\users\user\desktop\wutjscbcfx\read_instructions_to_decrypt.txt Jump to behavior
Source: C:\Users\user\Desktop\msmult64.exe File created: c:\users\user\desktop\zsszyefymu\read_instructions_to_decrypt.txt Jump to behavior
Source: C:\Users\user\Desktop\msmult64.exe File created: c:\users\user\documents\kzwfnrxyki\read_instructions_to_decrypt.txt Jump to behavior
Source: C:\Users\user\Desktop\msmult64.exe File created: c:\users\user\documents\nhpkizuusg\read_instructions_to_decrypt.txt Jump to behavior
Source: C:\Users\user\Desktop\msmult64.exe File created: c:\users\user\documents\ummbdneqbn\read_instructions_to_decrypt.txt Jump to behavior
Source: C:\Users\user\Desktop\msmult64.exe File created: c:\users\user\documents\vlzdgukutz\read_instructions_to_decrypt.txt Jump to behavior
Source: C:\Users\user\Desktop\msmult64.exe File created: c:\users\user\documents\wutjscbcfx\read_instructions_to_decrypt.txt Jump to behavior
Source: C:\Users\user\Desktop\msmult64.exe File created: c:\users\user\documents\zsszyefymu\read_instructions_to_decrypt.txt Jump to behavior
Source: C:\Users\user\Desktop\msmult64.exe File created: c:\users\user\favorites\links\read_instructions_to_decrypt.txt Jump to behavior
Source: C:\Users\user\Desktop\msmult64.exe File created: c:\users\user\pictures\camera roll\read_instructions_to_decrypt.txt Jump to behavior
Source: C:\Users\user\Desktop\msmult64.exe File created: c:\users\user\pictures\saved pictures\read_instructions_to_decrypt.txt Jump to behavior
Source: C:\Users\user\Desktop\msmult64.exe File created: c:\program files\adobe\acrobat dc\acrobat\acrocef\read_instructions_to_decrypt.txt Jump to behavior
Source: C:\Users\user\Desktop\msmult64.exe File created: c:\program files\adobe\acrobat dc\acrobat\acrocef_1\read_instructions_to_decrypt.txt Jump to behavior
Source: C:\Users\user\Desktop\msmult64.exe File created: c:\program files\adobe\acrobat dc\acrobat\air\read_instructions_to_decrypt.txt Jump to behavior
Source: C:\Users\user\Desktop\msmult64.exe File created: c:\program files\adobe\acrobat dc\acrobat\assets\read_instructions_to_decrypt.txt Jump to behavior
Source: C:\Users\user\Desktop\msmult64.exe File created: c:\program files\adobe\acrobat dc\acrobat\browser\read_instructions_to_decrypt.txt Jump to behavior
Source: C:\Users\user\Desktop\msmult64.exe File created: c:\program files\adobe\acrobat dc\acrobat\docsettings\read_instructions_to_decrypt.txt Jump to behavior
Source: C:\Users\user\Desktop\msmult64.exe File created: c:\program files\adobe\acrobat dc\acrobat\javascripts\read_instructions_to_decrypt.txt Jump to behavior
Source: C:\Users\user\Desktop\msmult64.exe File created: c:\program files\adobe\acrobat dc\acrobat\legal\read_instructions_to_decrypt.txt Jump to behavior
Source: C:\Users\user\Desktop\msmult64.exe File created: c:\program files\adobe\acrobat dc\acrobat\locale\read_instructions_to_decrypt.txt Jump to behavior
Source: C:\Users\user\Desktop\msmult64.exe File created: c:\program files\adobe\acrobat dc\acrobat\ngl\read_instructions_to_decrypt.txt Jump to behavior
Source: C:\Users\user\Desktop\msmult64.exe File created: c:\program files\adobe\acrobat dc\acrobat\ngl_resources\read_instructions_to_decrypt.txt Jump to behavior
Source: C:\Users\user\Desktop\msmult64.exe File created: c:\program files\adobe\acrobat dc\acrobat\plug_ins\read_instructions_to_decrypt.txt Jump to behavior
Source: C:\Users\user\Desktop\msmult64.exe File created: c:\program files\adobe\acrobat dc\acrobat\plug_ins3d\read_instructions_to_decrypt.txt Jump to behavior
Source: C:\Users\user\Desktop\msmult64.exe File created: c:\program files\adobe\acrobat dc\acrobat\rdcnotificationclient\read_instructions_to_decrypt.txt Jump to behavior
Source: C:\Users\user\Desktop\msmult64.exe File created: c:\program files\adobe\acrobat dc\acrobat\rdrapp\read_instructions_to_decrypt.txt Jump to behavior
Source: C:\Users\user\Desktop\msmult64.exe File created: c:\program files\adobe\acrobat dc\acrobat\sequences\read_instructions_to_decrypt.txt Jump to behavior
Source: C:\Users\user\Desktop\msmult64.exe File created: c:\program files\adobe\acrobat dc\acrobat\tracker\read_instructions_to_decrypt.txt Jump to behavior
Source: C:\Users\user\Desktop\msmult64.exe File created: c:\program files\adobe\acrobat dc\acrobat\uithemes\read_instructions_to_decrypt.txt Jump to behavior
Source: C:\Users\user\Desktop\msmult64.exe File created: c:\program files\adobe\acrobat dc\acrobat\webresources\read_instructions_to_decrypt.txt Jump to behavior
Source: C:\Users\user\Desktop\msmult64.exe File created: c:\program files\adobe\acrobat dc\acrobat\x86\read_instructions_to_decrypt.txt Jump to behavior
Source: C:\Users\user\Desktop\msmult64.exe File created: c:\program files\adobe\acrobat dc\resource\cmap\read_instructions_to_decrypt.txt Jump to behavior
Source: C:\Users\user\Desktop\msmult64.exe File created: c:\program files\adobe\acrobat dc\resource\font\read_instructions_to_decrypt.txt Jump to behavior
Source: C:\Users\user\Desktop\msmult64.exe File created: c:\program files\adobe\acrobat dc\resource\saslprep\read_instructions_to_decrypt.txt Jump to behavior
Source: C:\Users\user\Desktop\msmult64.exe File created: c:\program files\adobe\acrobat dc\resource\typesupport\read_instructions_to_decrypt.txt Jump to behavior
Source: C:\Users\user\Desktop\msmult64.exe File created: c:\program files\common files\adobe\acrobat\activex\read_instructions_to_decrypt.txt Jump to behavior
Source: C:\Users\user\Desktop\msmult64.exe File created: c:\program files\common files\adobe\acrobat\dc\read_instructions_to_decrypt.txt Jump to behavior
Source: C:\Users\user\Desktop\msmult64.exe File created: c:\program files\common files\adobe\acrobat\setup\read_instructions_to_decrypt.txt Jump to behavior
Source: C:\Users\user\Desktop\msmult64.exe File created: c:\program files\common files\adobe\acrobat\setup files\read_instructions_to_decrypt.txt Jump to behavior
Source: C:\Users\user\Desktop\msmult64.exe File created: c:\program files\common files\adobe\helpcfg\en_us\read_instructions_to_decrypt.txt Jump to behavior
Source: C:\Users\user\Desktop\msmult64.exe File created: c:\program files\common files\microsoft shared\clicktorun\onlineinteraction\read_instructions_to_decrypt.txt Jump to behavior
Source: C:\Users\user\Desktop\msmult64.exe File created: c:\program files\common files\microsoft shared\ink\ar-sa\read_instructions_to_decrypt.txt Jump to behavior
Source: C:\Users\user\Desktop\msmult64.exe File created: c:\program files\common files\microsoft shared\ink\bg-bg\read_instructions_to_decrypt.txt Jump to behavior
Source: C:\Users\user\Desktop\msmult64.exe File created: c:\program files\common files\microsoft shared\ink\cs-cz\read_instructions_to_decrypt.txt Jump to behavior
Source: C:\Users\user\Desktop\msmult64.exe File created: c:\program files\common files\microsoft shared\ink\da-dk\read_instructions_to_decrypt.txt Jump to behavior
Source: C:\Users\user\Desktop\msmult64.exe File created: c:\program files\common files\microsoft shared\ink\de-de\read_instructions_to_decrypt.txt Jump to behavior
Source: C:\Users\user\Desktop\msmult64.exe File created: c:\program files\common files\microsoft shared\ink\el-gr\read_instructions_to_decrypt.txt Jump to behavior
Source: C:\Users\user\Desktop\msmult64.exe File created: c:\program files\common files\microsoft shared\ink\en-gb\read_instructions_to_decrypt.txt Jump to behavior
Source: C:\Users\user\Desktop\msmult64.exe File created: c:\program files\common files\microsoft shared\ink\en-us\read_instructions_to_decrypt.txt Jump to behavior
Source: C:\Users\user\Desktop\msmult64.exe File moved: C:\Users\user\Desktop\UMMBDNEQBN.jpg Jump to behavior
Source: C:\Users\user\Desktop\msmult64.exe File deleted: C:\Users\user\Desktop\UMMBDNEQBN.jpg Jump to behavior
Source: C:\Users\user\Desktop\msmult64.exe File moved: C:\Users\user\Desktop\NHPKIZUUSG.docx Jump to behavior
Source: C:\Users\user\Desktop\msmult64.exe File deleted: C:\Users\user\Desktop\NHPKIZUUSG.docx Jump to behavior
Source: C:\Users\user\Desktop\msmult64.exe File moved: C:\Users\user\Desktop\HTAGVDFUIE.png Jump to behavior
Source: C:\Users\user\Desktop\msmult64.exe File dropped: C:\Program Files (x86)\Microsoft Office\root\vregwow6432\Read_instructions_To_Decrypt.txt -> decryption software from me.price for universal decryption software : $ contact us either through email or tox chat app for the ransom price $you have 72 hours to make payment as price of universal decryption software increases by $1000 dollars every 24 hours.contact on this email: bl00dyadmin@dnmx.orgcopy email address and write message to bl00dyadmin@dnmx.orgyou can write me on tox: download tox app from https://tox.chatcreate new account ..send me friend request using my tox id:e5bbfad2db3fb497ea03612b2428f927fd8a9b3333d524fd51d43b029b7870571ceb0166cb03*copy and paste it as it is*before you pay me ... i will decrypt 3 files for free to proof the universal decryption software worksfailure to pay me :kindly respect my rulesnote: huge amounts of data / documents has been stolen from your network servers and will be published online for freei have stolen all your databases ; data on your shared drives ; ad users emails(good for spam) ;i ha Jump to dropped file
Source: C:\Users\user\Desktop\msmult64.exe File dropped: C:\Program Files (x86)\Microsoft Office\Updates\Apply\Read_instructions_To_Decrypt.txt -> decryption software from me.price for universal decryption software : $ contact us either through email or tox chat app for the ransom price $you have 72 hours to make payment as price of universal decryption software increases by $1000 dollars every 24 hours.contact on this email: bl00dyadmin@dnmx.orgcopy email address and write message to bl00dyadmin@dnmx.orgyou can write me on tox: download tox app from https://tox.chatcreate new account ..send me friend request using my tox id:e5bbfad2db3fb497ea03612b2428f927fd8a9b3333d524fd51d43b029b7870571ceb0166cb03*copy and paste it as it is*before you pay me ... i will decrypt 3 files for free to proof the universal decryption software worksfailure to pay me :kindly respect my rulesnote: huge amounts of data / documents has been stolen from your network servers and will be published online for freei have stolen all your databases ; data on your shared drives ; ad users emails(good for spam) ;i ha Jump to dropped file
Source: C:\Users\user\Desktop\msmult64.exe File dropped: C:\Program Files (x86)\Microsoft Office\root\vreg\Read_instructions_To_Decrypt.txt -> decryption software from me.price for universal decryption software : $ contact us either through email or tox chat app for the ransom price $you have 72 hours to make payment as price of universal decryption software increases by $1000 dollars every 24 hours.contact on this email: bl00dyadmin@dnmx.orgcopy email address and write message to bl00dyadmin@dnmx.orgyou can write me on tox: download tox app from https://tox.chatcreate new account ..send me friend request using my tox id:e5bbfad2db3fb497ea03612b2428f927fd8a9b3333d524fd51d43b029b7870571ceb0166cb03*copy and paste it as it is*before you pay me ... i will decrypt 3 files for free to proof the universal decryption software worksfailure to pay me :kindly respect my rulesnote: huge amounts of data / documents has been stolen from your network servers and will be published online for freei have stolen all your databases ; data on your shared drives ; ad users emails(good for spam) ;i ha Jump to dropped file
Source: C:\Users\user\Desktop\msmult64.exe File dropped: C:\Program Files (x86)\Microsoft Office\root\rsodWoW6432\Read_instructions_To_Decrypt.txt -> decryption software from me.price for universal decryption software : $ contact us either through email or tox chat app for the ransom price $you have 72 hours to make payment as price of universal decryption software increases by $1000 dollars every 24 hours.contact on this email: bl00dyadmin@dnmx.orgcopy email address and write message to bl00dyadmin@dnmx.orgyou can write me on tox: download tox app from https://tox.chatcreate new account ..send me friend request using my tox id:e5bbfad2db3fb497ea03612b2428f927fd8a9b3333d524fd51d43b029b7870571ceb0166cb03*copy and paste it as it is*before you pay me ... i will decrypt 3 files for free to proof the universal decryption software worksfailure to pay me :kindly respect my rulesnote: huge amounts of data / documents has been stolen from your network servers and will be published online for freei have stolen all your databases ; data on your shared drives ; ad users emails(good for spam) ;i ha Jump to dropped file
Source: C:\Users\user\Desktop\msmult64.exe File dropped: C:\Program Files (x86)\Microsoft Office\root\Stationery\Read_instructions_To_Decrypt.txt -> decryption software from me.price for universal decryption software : $ contact us either through email or tox chat app for the ransom price $you have 72 hours to make payment as price of universal decryption software increases by $1000 dollars every 24 hours.contact on this email: bl00dyadmin@dnmx.orgcopy email address and write message to bl00dyadmin@dnmx.orgyou can write me on tox: download tox app from https://tox.chatcreate new account ..send me friend request using my tox id:e5bbfad2db3fb497ea03612b2428f927fd8a9b3333d524fd51d43b029b7870571ceb0166cb03*copy and paste it as it is*before you pay me ... i will decrypt 3 files for free to proof the universal decryption software worksfailure to pay me :kindly respect my rulesnote: huge amounts of data / documents has been stolen from your network servers and will be published online for freei have stolen all your databases ; data on your shared drives ; ad users emails(good for spam) ;i ha Jump to dropped file
Source: C:\Users\user\Desktop\msmult64.exe File dropped: C:\Program Files (x86)\Microsoft Office\root\vfs\Read_instructions_To_Decrypt.txt -> decryption software from me.price for universal decryption software : $ contact us either through email or tox chat app for the ransom price $you have 72 hours to make payment as price of universal decryption software increases by $1000 dollars every 24 hours.contact on this email: bl00dyadmin@dnmx.orgcopy email address and write message to bl00dyadmin@dnmx.orgyou can write me on tox: download tox app from https://tox.chatcreate new account ..send me friend request using my tox id:e5bbfad2db3fb497ea03612b2428f927fd8a9b3333d524fd51d43b029b7870571ceb0166cb03*copy and paste it as it is*before you pay me ... i will decrypt 3 files for free to proof the universal decryption software worksfailure to pay me :kindly respect my rulesnote: huge amounts of data / documents has been stolen from your network servers and will be published online for freei have stolen all your databases ; data on your shared drives ; ad users emails(good for spam) ;i ha Jump to dropped file
Source: C:\Users\user\Desktop\msmult64.exe File dropped: C:\Read_instructions_To_Decrypt.txt -> decryption software from me.price for universal decryption software : $ contact us either through email or tox chat app for the ransom price $you have 72 hours to make payment as price of universal decryption software increases by $1000 dollars every 24 hours.contact on this email: bl00dyadmin@dnmx.orgcopy email address and write message to bl00dyadmin@dnmx.orgyou can write me on tox: download tox app from https://tox.chatcreate new account ..send me friend request using my tox id:e5bbfad2db3fb497ea03612b2428f927fd8a9b3333d524fd51d43b029b7870571ceb0166cb03*copy and paste it as it is*before you pay me ... i will decrypt 3 files for free to proof the universal decryption software worksfailure to pay me :kindly respect my rulesnote: huge amounts of data / documents has been stolen from your network servers and will be published online for freei have stolen all your databases ; data on your shared drives ; ad users emails(good for spam) ;i ha Jump to dropped file
Source: C:\Users\user\Desktop\msmult64.exe File dropped: C:\$WinREAgent\Read_instructions_To_Decrypt.txt -> decryption software from me.price for universal decryption software : $ contact us either through email or tox chat app for the ransom price $you have 72 hours to make payment as price of universal decryption software increases by $1000 dollars every 24 hours.contact on this email: bl00dyadmin@dnmx.orgcopy email address and write message to bl00dyadmin@dnmx.orgyou can write me on tox: download tox app from https://tox.chatcreate new account ..send me friend request using my tox id:e5bbfad2db3fb497ea03612b2428f927fd8a9b3333d524fd51d43b029b7870571ceb0166cb03*copy and paste it as it is*before you pay me ... i will decrypt 3 files for free to proof the universal decryption software worksfailure to pay me :kindly respect my rulesnote: huge amounts of data / documents has been stolen from your network servers and will be published online for freei have stolen all your databases ; data on your shared drives ; ad users emails(good for spam) ;i ha Jump to dropped file
Source: C:\Users\user\Desktop\msmult64.exe File dropped: C:\Program Files\Read_instructions_To_Decrypt.txt -> decryption software from me.price for universal decryption software : $ contact us either through email or tox chat app for the ransom price $you have 72 hours to make payment as price of universal decryption software increases by $1000 dollars every 24 hours.contact on this email: bl00dyadmin@dnmx.orgcopy email address and write message to bl00dyadmin@dnmx.orgyou can write me on tox: download tox app from https://tox.chatcreate new account ..send me friend request using my tox id:e5bbfad2db3fb497ea03612b2428f927fd8a9b3333d524fd51d43b029b7870571ceb0166cb03*copy and paste it as it is*before you pay me ... i will decrypt 3 files for free to proof the universal decryption software worksfailure to pay me :kindly respect my rulesnote: huge amounts of data / documents has been stolen from your network servers and will be published online for freei have stolen all your databases ; data on your shared drives ; ad users emails(good for spam) ;i ha Jump to dropped file
Source: C:\Users\user\Desktop\msmult64.exe File dropped: C:\Program Files (x86)\Read_instructions_To_Decrypt.txt -> decryption software from me.price for universal decryption software : $ contact us either through email or tox chat app for the ransom price $you have 72 hours to make payment as price of universal decryption software increases by $1000 dollars every 24 hours.contact on this email: bl00dyadmin@dnmx.orgcopy email address and write message to bl00dyadmin@dnmx.orgyou can write me on tox: download tox app from https://tox.chatcreate new account ..send me friend request using my tox id:e5bbfad2db3fb497ea03612b2428f927fd8a9b3333d524fd51d43b029b7870571ceb0166cb03*copy and paste it as it is*before you pay me ... i will decrypt 3 files for free to proof the universal decryption software worksfailure to pay me :kindly respect my rulesnote: huge amounts of data / documents has been stolen from your network servers and will be published online for freei have stolen all your databases ; data on your shared drives ; ad users emails(good for spam) ;i ha Jump to dropped file
Source: C:\Users\user\Desktop\msmult64.exe File created: C:\Program Files (x86)\Microsoft Office\root\Licenses16\MondoR_SubTrial2-ppd.xrm-ms entropy: 7.99436525651 Jump to dropped file
Source: C:\Users\user\Desktop\msmult64.exe File created: C:\Program Files (x86)\Microsoft Office\root\Licenses16\MondoR_Trial-ppd.xrm-ms entropy: 7.99405740605 Jump to dropped file
Source: C:\Users\user\Desktop\msmult64.exe File created: C:\Program Files (x86)\Microsoft Office\root\Licenses16\MondoR_ViewOnly_ZeroGrace-ppd.xrm-ms entropy: 7.99264623585 Jump to dropped file
Source: C:\Users\user\Desktop\msmult64.exe File created: C:\Program Files (x86)\Microsoft OneDrive\23.038.0219.0001\Assets\Square44x44Logo.altform-lightunplated_targetsize-256.png entropy: 7.99095746583 Jump to dropped file
Source: C:\Users\user\Desktop\msmult64.exe File created: C:\Program Files (x86)\Microsoft Office\root\Licenses16\O365BusinessR_Subscription-ppd.xrm-ms entropy: 7.99435600823 Jump to dropped file
Source: C:\Users\user\Desktop\msmult64.exe File created: C:\Program Files (x86)\Microsoft Office\root\Licenses16\MondoVL_MAK-ul-phn.xrm-ms entropy: 7.99019494927 Jump to dropped file
Source: C:\Users\user\Desktop\msmult64.exe File created: C:\Program Files (x86)\Microsoft Office\root\Licenses16\O365BusinessDemoR_BypassTrial365-ppd.xrm-ms entropy: 7.99192906559 Jump to dropped file
Source: C:\Users\user\Desktop\msmult64.exe File created: C:\Program Files (x86)\Microsoft Office\root\Licenses16\O365BusinessR_Grace-ppd.xrm-ms entropy: 7.99324853054 Jump to dropped file
Source: C:\Users\user\Desktop\msmult64.exe File created: C:\Program Files (x86)\Microsoft Office\root\Licenses16\O365EduCloudEDUR_Subscription-ppd.xrm-ms entropy: 7.99471299998 Jump to dropped file
Source: C:\Users\user\Desktop\msmult64.exe File created: C:\Program Files (x86)\Microsoft Office\root\Licenses16\O365BusinessR_SubTest-ppd.xrm-ms entropy: 7.99292715464 Jump to dropped file
Source: C:\Users\user\Desktop\msmult64.exe File created: C:\Program Files (x86)\Microsoft Office\root\Licenses16\O365BusinessR_SubTrial-ppd.xrm-ms entropy: 7.99417390697 Jump to dropped file
Source: C:\Users\user\Desktop\msmult64.exe File created: C:\Program Files (x86)\Microsoft OneDrive\23.038.0219.0001\Assets\Square44x44Logo.altform-unplated_targetsize-256.png entropy: 7.99175503514 Jump to dropped file
Source: C:\Users\user\Desktop\msmult64.exe File created: C:\Program Files (x86)\Microsoft Office\root\Licenses16\O365EduCloudEDUR_Grace-ppd.xrm-ms entropy: 7.99301834631 Jump to dropped file
Source: C:\Users\user\Desktop\msmult64.exe File created: C:\Program Files (x86)\Microsoft Office\root\Licenses16\O365HomePremR_Subscription1-ppd.xrm-ms entropy: 7.99394307996 Jump to dropped file
Source: C:\Users\user\Desktop\msmult64.exe File created: C:\Program Files (x86)\Microsoft Office\root\Licenses16\O365HomePremR_Subscription2-ppd.xrm-ms entropy: 7.99411737498 Jump to dropped file
Source: C:\Users\user\Desktop\msmult64.exe File created: C:\Program Files (x86)\Microsoft Office\root\Licenses16\O365EduCloudEDUR_SubTrial-ppd.xrm-ms entropy: 7.9922544296 Jump to dropped file
Source: C:\Users\user\Desktop\msmult64.exe File created: C:\Program Files (x86)\Microsoft Office\root\Licenses16\O365HomePremDemoR_BypassTrial365-ppd.xrm-ms entropy: 7.9930185483 Jump to dropped file
Source: C:\Users\user\Desktop\msmult64.exe File created: C:\Program Files (x86)\Microsoft OneDrive\23.038.0219.0001\Assets\Square44x44Logo.targetsize-256.png entropy: 7.99065371833 Jump to dropped file
Source: C:\Users\user\Desktop\msmult64.exe File created: C:\Program Files (x86)\Microsoft Office\root\Licenses16\O365HomePremR_Grace-ppd.xrm-ms entropy: 7.99375880336 Jump to dropped file
Source: C:\Users\user\Desktop\msmult64.exe File created: C:\Program Files (x86)\Microsoft Office\root\Licenses16\O365HomePremR_Subscription5-ppd.xrm-ms entropy: 7.99394824596 Jump to dropped file
Source: C:\Users\user\Desktop\msmult64.exe File created: C:\Program Files (x86)\Microsoft Office\root\Licenses16\O365HomePremR_Subscription3-ppd.xrm-ms entropy: 7.99390776544 Jump to dropped file
Source: C:\Users\user\Desktop\msmult64.exe File created: C:\Program Files (x86)\Microsoft Office\root\Licenses16\O365HomePremR_Subscription4-ppd.xrm-ms entropy: 7.99426573761 Jump to dropped file
Source: C:\Users\user\Desktop\msmult64.exe File created: C:\Program Files (x86)\Microsoft Office\root\Licenses16\O365HomePremR_SubTest3-ppd.xrm-ms entropy: 7.99335366086 Jump to dropped file
Source: C:\Users\user\Desktop\msmult64.exe File created: C:\Program Files (x86)\Microsoft Office\root\Licenses16\O365HomePremR_SubTest4-ppd.xrm-ms entropy: 7.99318620587 Jump to dropped file
Source: C:\Users\user\Desktop\msmult64.exe File created: C:\Program Files (x86)\Microsoft Office\root\Licenses16\O365HomePremR_SubTest1-ppd.xrm-ms entropy: 7.99364936513 Jump to dropped file
Source: C:\Users\user\Desktop\msmult64.exe File created: C:\Program Files (x86)\Microsoft Office\root\Licenses16\O365HomePremR_SubTest2-ppd.xrm-ms entropy: 7.99327479743 Jump to dropped file
Source: C:\Users\user\Desktop\msmult64.exe File created: C:\Program Files (x86)\Microsoft Office\root\Licenses16\O365HomePremR_SubTest5-ppd.xrm-ms entropy: 7.99317529654 Jump to dropped file
Source: C:\Users\user\Desktop\msmult64.exe File created: C:\Program Files (x86)\Microsoft Office\root\Licenses16\ProjectPro2021MSDNR_Retail1-ul-phn.xrm-ms entropy: 7.99111172515 Jump to dropped file
Source: C:\Users\user\Desktop\msmult64.exe File created: C:\Program Files\Adobe\Acrobat DC\Resource\CMap\UniKS-UTF16-H entropy: 7.99854468601 Jump to dropped file
Source: C:\Users\user\Desktop\msmult64.exe File created: C:\Program Files (x86)\Microsoft Office\root\Licenses16\ProjectPro2021PreviewVL_MAK_AE-ppd.xrm-ms entropy: 7.9914617143 Jump to dropped file
Source: C:\Users\user\Desktop\msmult64.exe File created: C:\Program Files\Adobe\Acrobat DC\Resource\Font\AdobePIStd.otf entropy: 7.99795102065 Jump to dropped file
Source: C:\Users\user\Desktop\msmult64.exe File created: C:\Program Files (x86)\Microsoft Office\root\Licenses16\ProjectPro2021R_Grace-ppd.xrm-ms entropy: 7.99192638578 Jump to dropped file
Source: C:\Users\user\Desktop\msmult64.exe File created: C:\Program Files\Adobe\Acrobat DC\Resource\Font\CourierStd-Bold.otf entropy: 7.99385430996 Jump to dropped file
Source: C:\Users\user\Desktop\msmult64.exe File created: C:\Program Files (x86)\Microsoft Office\root\Licenses16\ProjectPro2021MSDNR_Retail2-ppd.xrm-ms entropy: 7.99256956896 Jump to dropped file
Source: C:\Users\user\Desktop\msmult64.exe File created: C:\Program Files (x86)\Microsoft Office\root\Licenses16\ProjectPro2021MSDNR_Retail2-ul-phn.xrm-ms entropy: 7.99050104046 Jump to dropped file
Source: C:\Users\user\Desktop\msmult64.exe File created: C:\Program Files (x86)\Microsoft Office\root\Licenses16\ProjectPro2021PreviewVL_KMS_Client_AE-ppd.xrm-ms entropy: 7.99254083347 Jump to dropped file
Source: C:\Users\user\Desktop\msmult64.exe File created: C:\Program Files\Adobe\Acrobat DC\Resource\CMap\UCS2-GBK-EUC entropy: 7.99926975395 Jump to dropped file
Source: C:\Users\user\Desktop\msmult64.exe File created: C:\Program Files\Adobe\Acrobat DC\Resource\Font\MinionPro-BoldIt.otf entropy: 7.99926834238 Jump to dropped file
Source: C:\Users\user\Desktop\msmult64.exe File created: C:\Program Files (x86)\Microsoft Office\root\Licenses16\ProjectPro2021R_Retail-ppd.xrm-ms entropy: 7.99188716105 Jump to dropped file
Source: C:\Users\user\Desktop\msmult64.exe File created: C:\Program Files\Adobe\Acrobat DC\Resource\Font\MinionPro-It.otf entropy: 7.99917374902 Jump to dropped file
Source: C:\Users\user\Desktop\msmult64.exe File created: C:\Program Files (x86)\Microsoft Office\root\Licenses16\ProjectPro2021R_Retail-ul-phn.xrm-ms entropy: 7.99113620684 Jump to dropped file
Source: C:\Users\user\Desktop\msmult64.exe File created: C:\Program Files\Adobe\Acrobat DC\Resource\Font\MinionPro-Regular.otf entropy: 7.99917070489 Jump to dropped file
Source: C:\Users\user\Desktop\msmult64.exe File created: C:\Program Files (x86)\Microsoft Office\root\Licenses16\ProjectPro2021R_Trial-ppd.xrm-ms entropy: 7.9938985987 Jump to dropped file
Source: C:\Users\user\Desktop\msmult64.exe File created: C:\Program Files\Adobe\Acrobat DC\Resource\Font\MyriadPro-Bold.otf entropy: 7.99773938635 Jump to dropped file
Source: C:\Users\user\Desktop\msmult64.exe File created: C:\Program Files\Adobe\Acrobat DC\Resource\Font\CourierStd-BoldOblique.otf entropy: 7.99381078219 Jump to dropped file
Source: C:\Users\user\Desktop\msmult64.exe File created: C:\Program Files\Adobe\Acrobat DC\Resource\Font\CourierStd-Oblique.otf entropy: 7.9946899634 Jump to dropped file
Source: C:\Users\user\Desktop\msmult64.exe File created: C:\Program Files (x86)\Microsoft Office\root\Licenses16\ProjectPro2021R_OEM_Perp-ppd.xrm-ms entropy: 7.9929253696 Jump to dropped file
Source: C:\Users\user\Desktop\msmult64.exe File created: C:\Program Files\Adobe\Acrobat DC\Resource\Font\CourierStd.otf entropy: 7.99319787961 Jump to dropped file
Source: C:\Users\user\Desktop\msmult64.exe File created: C:\Program Files (x86)\Microsoft Office\root\Licenses16\ProjectPro2021R_OEM_Perp-ul-phn.xrm-ms entropy: 7.99016933815 Jump to dropped file
Source: C:\Users\user\Desktop\msmult64.exe File created: C:\Program Files\Adobe\Acrobat DC\Resource\Font\MinionPro-Bold.otf entropy: 7.9991848868 Jump to dropped file
Source: C:\Users\user\Desktop\msmult64.exe File created: C:\Program Files\Adobe\Acrobat DC\Resource\Font\ZX______.PFB entropy: 7.99746845651 Jump to dropped file
Source: C:\Users\user\Desktop\msmult64.exe File created: C:\Program Files (x86)\Microsoft Office\root\Licenses16\ProjectPro2021VL_MAK_AE1-ppd.xrm-ms entropy: 7.99216860814 Jump to dropped file
Source: C:\Users\user\Desktop\msmult64.exe File created: C:\Program Files\Adobe\Acrobat DC\Resource\Font\ZY______.PFB entropy: 7.9981650414 Jump to dropped file
Source: C:\Users\user\Desktop\msmult64.exe File created: C:\Program Files (x86)\Microsoft Office\root\Licenses16\ProjectPro2021VL_MAK_AE1-ul-phn.xrm-ms entropy: 7.99240080104 Jump to dropped file
Source: C:\Users\user\Desktop\msmult64.exe File created: C:\Program Files (x86)\Microsoft Office\root\Licenses16\ProjectPro2021VL_MAK_AE2-ppd.xrm-ms entropy: 7.99354579712 Jump to dropped file
Source: C:\Users\user\Desktop\msmult64.exe File created: C:\Program Files\Adobe\Acrobat DC\Resource\Font\MyriadPro-BoldIt.otf entropy: 7.99834732058 Jump to dropped file
Source: C:\Users\user\Desktop\msmult64.exe File created: C:\Program Files (x86)\Microsoft Office\root\Licenses16\ProjectPro2021VL_KMS_Client_AE-ppd.xrm-ms entropy: 7.99209582452 Jump to dropped file
Source: C:\Users\user\Desktop\msmult64.exe File created: C:\Program Files\Adobe\Acrobat DC\Resource\Font\MyriadPro-It.otf entropy: 7.9982343324 Jump to dropped file
Source: C:\Users\user\Desktop\msmult64.exe File created: C:\Program Files\Adobe\Acrobat DC\Resource\Font\MyriadPro-Regular.otf entropy: 7.99803650248 Jump to dropped file
Source: C:\Users\user\Desktop\msmult64.exe File created: C:\Program Files\Adobe\Acrobat DC\Resource\Font\SY______.PFB entropy: 7.99471535842 Jump to dropped file
Source: C:\Users\user\Desktop\msmult64.exe File created: C:\Program Files (x86)\Microsoft Office\root\Licenses16\ProjectProCO365R_SubTest-ppd.xrm-ms entropy: 7.99320132979 Jump to dropped file
Source: C:\Users\user\Desktop\msmult64.exe File created: C:\Program Files (x86)\Microsoft Office\root\Licenses16\ProjectProCO365R_SubTrial-ppd.xrm-ms entropy: 7.99238544019 Jump to dropped file
Source: C:\Users\user\Desktop\msmult64.exe File created: C:\Program Files (x86)\Microsoft Office\root\Licenses16\ProjectProDemoR_BypassTrial180-ppd.xrm-ms entropy: 7.9929834849 Jump to dropped file
Source: C:\Users\user\Desktop\msmult64.exe File created: C:\Program Files (x86)\AutoIt3\Include\GuiTab.au3 entropy: 7.99455819041 Jump to dropped file
Source: C:\Users\user\Desktop\msmult64.exe File created: C:\Program Files (x86)\AutoIt3\Include\GuiToolbar.au3 entropy: 7.99772324128 Jump to dropped file
Source: C:\Users\user\Desktop\msmult64.exe File created: C:\Program Files (x86)\AutoIt3\Include\GuiToolTip.au3 entropy: 7.99573171114 Jump to dropped file
Source: C:\Users\user\Desktop\msmult64.exe File created: C:\Program Files (x86)\AutoIt3\Include\GuiTreeView.au3 entropy: 7.99836687865 Jump to dropped file
Source: C:\Users\user\Desktop\msmult64.exe File created: C:\Program Files (x86)\AutoIt3\Include\helper.au3 entropy: 7.99349271508 Jump to dropped file
Source: C:\Users\user\Desktop\msmult64.exe File created: C:\Program Files (x86)\Microsoft Office\root\Licenses16\ProjectPro2021VL_MAK_AE2-ul-phn.xrm-ms entropy: 7.99043872552 Jump to dropped file
Source: C:\Users\user\Desktop\msmult64.exe File created: C:\Program Files (x86)\AutoIt3\Include\IE.au3 entropy: 7.99879263878 Jump to dropped file
Source: C:\Users\user\Desktop\msmult64.exe File created: C:\Program Files (x86)\Microsoft Office\root\Licenses16\ProjectProCO365R_Subscription-ppd.xrm-ms entropy: 7.99251291551 Jump to dropped file
Source: C:\Users\user\Desktop\msmult64.exe File created: C:\Program Files (x86)\Microsoft Office\root\Licenses16\ProjectProMSDNR_Retail-ul-phn.xrm-ms entropy: 7.99138517083 Jump to dropped file
Source: C:\Users\user\Desktop\msmult64.exe File created: C:\Program Files (x86)\Microsoft Office\root\Licenses16\ProjectProO365R_Subscription-ppd.xrm-ms entropy: 7.99391521869 Jump to dropped file
Source: C:\Users\user\Desktop\msmult64.exe File created: C:\Program Files (x86)\Microsoft Office\root\Licenses16\ProjectProO365R_SubTest-ppd.xrm-ms entropy: 7.99250638698 Jump to dropped file
Source: C:\Users\user\Desktop\msmult64.exe File created: C:\Program Files (x86)\AutoIt3\Include\ListViewConstants.au3 entropy: 7.99249920392 Jump to dropped file
Source: C:\Users\user\Desktop\msmult64.exe File created: C:\Program Files (x86)\AutoIt3\Include\Memory.au3 entropy: 7.99128502888 Jump to dropped file
Source: C:\Users\user\Desktop\msmult64.exe File created: C:\Program Files (x86)\Microsoft Office\root\Licenses16\ProjectProMSDNR_Retail-ppd.xrm-ms entropy: 7.99318803108 Jump to dropped file
Source: C:\Users\user\Desktop\msmult64.exe File created: C:\Program Files (x86)\Microsoft Office\root\Licenses16\ProjectProR_Grace-ppd.xrm-ms entropy: 7.99317847647 Jump to dropped file
Source: C:\Users\user\Desktop\msmult64.exe File created: C:\Program Files (x86)\Microsoft Office\root\Licenses16\ProjectProR_OEM_Perp-ppd.xrm-ms entropy: 7.99311794807 Jump to dropped file
Source: C:\Users\user\Desktop\msmult64.exe File created: C:\Program Files (x86)\Microsoft Office\root\Licenses16\ProjectProR_OEM_Perp-ul-phn.xrm-ms entropy: 7.99073692014 Jump to dropped file
Source: C:\Users\user\Desktop\msmult64.exe File created: C:\Program Files (x86)\Microsoft Office\root\Licenses16\ProjectProR_Retail-ppd.xrm-ms entropy: 7.99310853669 Jump to dropped file
Source: C:\Users\user\Desktop\msmult64.exe File created: C:\Program Files (x86)\AutoIt3\Include\Misc.au3 entropy: 7.99558750876 Jump to dropped file
Source: C:\Users\user\Desktop\msmult64.exe File created: C:\Program Files (x86)\AutoIt3\Include\NetShare.au3 entropy: 7.99615692541 Jump to dropped file
Source: C:\Users\user\Desktop\msmult64.exe File created: C:\Program Files (x86)\AutoIt3\Include\NTSTATUSConstants.au3 entropy: 7.99928460594 Jump to dropped file
Source: C:\Users\user\Desktop\msmult64.exe File created: C:\Program Files (x86)\AutoIt3\Include\PowerPoint.au3 entropy: 7.99708525813 Jump to dropped file
Source: C:\Users\user\Desktop\msmult64.exe File created: C:\Program Files (x86)\Microsoft Office\root\Licenses16\ProjectProO365R_SubTrial-ppd.xrm-ms entropy: 7.99300784025 Jump to dropped file
Source: C:\Users\user\Desktop\msmult64.exe File created: C:\Program Files (x86)\Microsoft Office\root\Licenses16\ProjectProR_Retail2-ppd.xrm-ms entropy: 7.99251555084 Jump to dropped file
Source: C:\Users\user\Desktop\msmult64.exe File created: C:\Program Files (x86)\Microsoft Office\root\Licenses16\ProjectProR_Retail2-ul-phn.xrm-ms entropy: 7.99079467285 Jump to dropped file
Source: C:\Users\user\Desktop\msmult64.exe File created: C:\Program Files (x86)\Microsoft Office\root\Licenses16\ProjectProR_Trial-ppd.xrm-ms entropy: 7.99260466184 Jump to dropped file
Source: C:\Users\user\Desktop\msmult64.exe File created: C:\Program Files (x86)\Microsoft Office\root\Licenses16\ProjectProR_Retail-ul-phn.xrm-ms entropy: 7.99090336316 Jump to dropped file
Source: C:\Users\user\Desktop\msmult64.exe File created: C:\Program Files (x86)\Microsoft Office\root\Licenses16\ProjectProVL_MAK-ul-phn.xrm-ms entropy: 7.99096832219 Jump to dropped file
Source: C:\Users\user\Desktop\msmult64.exe File created: C:\Program Files (x86)\Microsoft Office\root\Licenses16\ProjectProXC2RVL_KMS_ClientC2R-ppd.xrm-ms entropy: 7.99405684057 Jump to dropped file
Source: C:\Users\user\Desktop\msmult64.exe File created: C:\Program Files (x86)\Microsoft Office\root\Licenses16\ProjectProXC2RVL_MAKC2R-ppd.xrm-ms entropy: 7.99232016814 Jump to dropped file
Source: C:\Users\user\Desktop\msmult64.exe File created: C:\Program Files (x86)\AutoIt3\Include\Sound.au3 entropy: 7.99069470106 Jump to dropped file
Source: C:\Users\user\Desktop\msmult64.exe File created: C:\Program Files (x86)\AutoIt3\Include\SQLite.au3 entropy: 7.99679896925 Jump to dropped file
Source: C:\Users\user\Desktop\msmult64.exe File created: C:\Program Files (x86)\AutoIt3\Include\StructureConstants.au3 entropy: 7.9971369715 Jump to dropped file
Source: C:\Users\user\Desktop\msmult64.exe File created: C:\Program Files (x86)\Microsoft Office\root\Licenses16\ProjectStd2019R_OEM_Perp-ppd.xrm-ms entropy: 7.99331394336 Jump to dropped file
Source: C:\Users\user\Desktop\msmult64.exe File created: C:\Program Files (x86)\Microsoft Office\root\Licenses16\ProjectStd2019R_OEM_Perp-ul-phn.xrm-ms entropy: 7.99009725464 Jump to dropped file
Source: C:\Users\user\Desktop\msmult64.exe File created: C:\Program Files (x86)\Microsoft Office\root\Licenses16\ProjectStd2019R_Retail-ppd.xrm-ms entropy: 7.99321395699 Jump to dropped file
Source: C:\Users\user\Desktop\msmult64.exe File created: C:\Program Files (x86)\Microsoft Office\root\Licenses16\ProjectProXC2RVL_MAKC2R-ul-phn.xrm-ms entropy: 7.99077653149 Jump to dropped file
Source: C:\Users\user\Desktop\msmult64.exe File created: C:\Program Files (x86)\Microsoft Office\root\Licenses16\ProjectStd2019R_Grace-ppd.xrm-ms entropy: 7.99242737095 Jump to dropped file
Source: C:\Users\user\Desktop\msmult64.exe File created: C:\Program Files (x86)\AutoIt3\Include\UIAWrappers.au3 entropy: 7.99827959736 Jump to dropped file
Source: C:\Users\user\Desktop\msmult64.exe File created: C:\Program Files (x86)\AutoIt3\Include\Visa.au3 entropy: 7.99485168035 Jump to dropped file
Source: C:\Users\user\Desktop\msmult64.exe File created: C:\Program Files (x86)\AutoIt3\Include\WinAPIConv.au3 entropy: 7.99391853669 Jump to dropped file
Source: C:\Users\user\Desktop\msmult64.exe File created: C:\Program Files (x86)\AutoIt3\Include\WinAPIDiag.au3 entropy: 7.99407866681 Jump to dropped file
Source: C:\Users\user\Desktop\msmult64.exe File created: C:\Program Files (x86)\AutoIt3\Include\WinAPIDlg.au3 entropy: 7.99439363517 Jump to dropped file
Source: C:\Users\user\Desktop\msmult64.exe File created: C:\Program Files (x86)\AutoIt3\Include\WinAPIFiles.au3 entropy: 7.99814736634 Jump to dropped file
Source: C:\Users\user\Desktop\msmult64.exe File created: C:\Program Files (x86)\AutoIt3\Include\WinAPIGdi.au3 entropy: 7.99900743489 Jump to dropped file
Source: C:\Users\user\Desktop\msmult64.exe File created: C:\Program Files (x86)\AutoIt3\Include\WinAPIGdiDC.au3 entropy: 7.99078630675 Jump to dropped file
Source: C:\Users\user\Desktop\msmult64.exe File created: C:\Program Files (x86)\AutoIt3\Include\WinAPIGdiInternals.au3 entropy: 7.99385586998 Jump to dropped file
Source: C:\Users\user\Desktop\msmult64.exe File created: C:\Program Files (x86)\AutoIt3\Include\WinAPIIcons.au3 entropy: 7.99383465246 Jump to dropped file
Source: C:\Users\user\Desktop\msmult64.exe File created: C:\Program Files (x86)\AutoIt3\Include\WinAPIInternals.au3 entropy: 7.99011124191 Jump to dropped file
Source: C:\Users\user\Desktop\msmult64.exe File created: C:\Program Files (x86)\AutoIt3\Include\WinAPILocale.au3 entropy: 7.99190790297 Jump to dropped file
Source: C:\Users\user\Desktop\msmult64.exe File created: C:\Program Files (x86)\AutoIt3\Include\WinAPIMem.au3 entropy: 7.99121097474 Jump to dropped file
Source: C:\Users\user\Desktop\msmult64.exe File created: C:\Program Files (x86)\AutoIt3\Include\WinAPIProc.au3 entropy: 7.99775989036 Jump to dropped file
Source: C:\Users\user\Desktop\msmult64.exe File created: C:\Program Files (x86)\AutoIt3\Include\WinAPIReg.au3 entropy: 7.9939171463 Jump to dropped file
Source: C:\Users\user\Desktop\msmult64.exe File created: C:\Program Files (x86)\AutoIt3\Include\WinAPIRes.au3 entropy: 7.99537496802 Jump to dropped file
Source: C:\Users\user\Desktop\msmult64.exe File created: C:\Program Files (x86)\AutoIt3\Include\WinAPIShellEx.au3 entropy: 7.99523747467 Jump to dropped file
Source: C:\Users\user\Desktop\msmult64.exe File created: C:\Program Files (x86)\AutoIt3\Include\WinAPIShPath.au3 entropy: 7.99641932596 Jump to dropped file
Source: C:\Users\user\Desktop\msmult64.exe File created: C:\Program Files (x86)\AutoIt3\Include\WinAPISys.au3 entropy: 7.99811831839 Jump to dropped file
Source: C:\Users\user\Desktop\msmult64.exe File created: C:\Program Files (x86)\AutoIt3\Include\WinAPISysInternals.au3 entropy: 7.99364114378 Jump to dropped file
Source: C:\Users\user\Desktop\msmult64.exe File created: C:\Program Files (x86)\AutoIt3\Include\WinAPISysWin.au3 entropy: 7.99716157388 Jump to dropped file
Source: C:\Users\user\Desktop\msmult64.exe File created: C:\Program Files (x86)\AutoIt3\Include\WinAPITheme.au3 entropy: 7.9957330895 Jump to dropped file
Source: C:\Users\user\Desktop\msmult64.exe File created: C:\Program Files (x86)\AutoIt3\Include\WindowsConstants.au3 entropy: 7.99467606809 Jump to dropped file
Source: C:\Users\user\Desktop\msmult64.exe File created: C:\Program Files (x86)\AutoIt3\Include\WinNet.au3 entropy: 7.99626337642 Jump to dropped file
Source: C:\Users\user\Desktop\msmult64.exe File created: C:\Program Files (x86)\AutoIt3\Include\word.au3 entropy: 7.99479021225 Jump to dropped file
Source: C:\Users\user\Desktop\msmult64.exe File created: C:\Program Files (x86)\AutoIt3\SciTE\au3.keywords.properties entropy: 7.99780216324 Jump to dropped file
Source: C:\Users\user\Desktop\msmult64.exe File created: C:\Program Files (x86)\Common Files\DESIGNER\MSADDNDR.OLB entropy: 7.99307159455 Jump to dropped file
Source: C:\Users\user\Desktop\msmult64.exe File created: C:\Program Files (x86)\Microsoft Office\root\Licenses16\O365HomePremR_SubTrial3-ppd.xrm-ms entropy: 7.99245608016 Jump to dropped file
Source: C:\Users\user\Desktop\msmult64.exe File created: C:\Program Files (x86)\Microsoft Office\root\Licenses16\O365HomePremR_SubTrial4-ppd.xrm-ms entropy: 7.993484798 Jump to dropped file
Source: C:\Users\user\Desktop\msmult64.exe File created: C:\Program Files (x86)\Microsoft Office\root\Licenses16\O365HomePremR_SubTrial1-ppd.xrm-ms entropy: 7.99390182599 Jump to dropped file
Source: C:\Users\user\Desktop\msmult64.exe File created: C:\Program Files (x86)\Microsoft Office\root\Licenses16\O365HomePremR_SubTrial2-ppd.xrm-ms entropy: 7.99398066876 Jump to dropped file
Source: C:\Users\user\Desktop\msmult64.exe File created: C:\Program Files (x86)\Microsoft Office\root\Licenses16\O365ProPlusE5R_Subscription-ppd.xrm-ms entropy: 7.99520656036 Jump to dropped file
Source: C:\Users\user\Desktop\msmult64.exe File created: C:\Program Files (x86)\Microsoft Office\root\Licenses16\O365HomePremR_SubTrial5-ppd.xrm-ms entropy: 7.99367224604 Jump to dropped file
Source: C:\Users\user\Desktop\msmult64.exe File created: C:\Program Files (x86)\Microsoft Office\root\Licenses16\O365ProPlusDemoR_BypassTrial365-ppd.xrm-ms entropy: 7.99432569095 Jump to dropped file
Source: C:\Users\user\Desktop\msmult64.exe File created: C:\Program Files (x86)\Microsoft Office\root\Licenses16\O365ProPlusEDUR_SubTrial-ppd.xrm-ms entropy: 7.99430357084 Jump to dropped file
Source: C:\Users\user\Desktop\msmult64.exe File created: C:\Program Files (x86)\Microsoft Office\root\Licenses16\O365ProPlusR_Grace-ppd.xrm-ms entropy: 7.99439726017 Jump to dropped file
Source: C:\Users\user\Desktop\msmult64.exe File created: C:\Program Files (x86)\Microsoft Office\root\Licenses16\O365ProPlusE5R_SubTrial-ppd.xrm-ms entropy: 7.99304094585 Jump to dropped file
Source: C:\Users\user\Desktop\msmult64.exe File created: C:\Program Files (x86)\Microsoft Office\root\Licenses16\O365ProPlusEDUR_Subscription-ppd.xrm-ms entropy: 7.99519803042 Jump to dropped file
Source: C:\Users\user\Desktop\msmult64.exe File created: C:\Program Files (x86)\Microsoft Office\root\Licenses16\O365ProPlusR_Subscription3-ppd.xrm-ms entropy: 7.99471745194 Jump to dropped file
Source: C:\Users\user\Desktop\msmult64.exe File created: C:\Program Files (x86)\Microsoft Office\root\Licenses16\O365ProPlusR_Subscription1-ppd.xrm-ms entropy: 7.99481204042 Jump to dropped file
Source: C:\Users\user\Desktop\msmult64.exe File created: C:\Program Files (x86)\Microsoft Office\root\Licenses16\O365ProPlusR_Subscription2-ppd.xrm-ms entropy: 7.99507643487 Jump to dropped file
Source: C:\Users\user\Desktop\msmult64.exe File created: C:\Program Files (x86)\Microsoft Office\root\Licenses16\O365ProPlusR_SubTrial2-ppd.xrm-ms entropy: 7.99377563877 Jump to dropped file
Source: C:\Users\user\Desktop\msmult64.exe File created: C:\Program Files (x86)\Microsoft Office\root\Licenses16\O365ProPlusR_Subscription4-ppd.xrm-ms entropy: 7.99475509449 Jump to dropped file
Source: C:\Users\user\Desktop\msmult64.exe File created: C:\Program Files (x86)\Microsoft Office\root\Licenses16\O365ProPlusR_Subscription5-ppd.xrm-ms entropy: 7.99401724393 Jump to dropped file
Source: C:\Users\user\Desktop\msmult64.exe File created: C:\Program Files (x86)\Microsoft Office\root\Licenses16\O365ProPlusR_SubTrial1-ppd.xrm-ms entropy: 7.99392486911 Jump to dropped file
Source: C:\Users\user\Desktop\msmult64.exe File created: C:\Program Files (x86)\Microsoft Office\root\Licenses16\O365SmallBusPremDemoR_BypassTrial365-ppd.xrm-ms entropy: 7.99379767446 Jump to dropped file
Source: C:\Users\user\Desktop\msmult64.exe File created: C:\Program Files (x86)\Microsoft Office\root\Licenses16\O365ProPlusR_SubTrial3-ppd.xrm-ms entropy: 7.99443072104 Jump to dropped file
Source: C:\Users\user\Desktop\msmult64.exe File created: C:\Program Files (x86)\Microsoft Office\root\Licenses16\O365ProPlusR_SubTrial4-ppd.xrm-ms entropy: 7.99330231699 Jump to dropped file
Source: C:\Users\user\Desktop\msmult64.exe File created: C:\Program Files (x86)\Microsoft Office\root\Licenses16\O365ProPlusR_SubTrial5-ppd.xrm-ms entropy: 7.99308629792 Jump to dropped file
Source: C:\Users\user\Desktop\msmult64.exe File created: C:\Program Files (x86)\Microsoft Office\root\Licenses16\O365SmallBusPremR_Subscription3-ppd.xrm-ms entropy: 7.99436829533 Jump to dropped file
Source: C:\Users\user\Desktop\msmult64.exe File created: C:\Program Files (x86)\Microsoft Office\root\Licenses16\O365SmallBusPremR_Grace-ppd.xrm-ms entropy: 7.99377692453 Jump to dropped file
Source: C:\Users\user\Desktop\msmult64.exe File created: C:\Program Files (x86)\Microsoft Office\root\Licenses16\O365SmallBusPremR_Subscription1-ppd.xrm-ms entropy: 7.99444568811 Jump to dropped file
Source: C:\Users\user\Desktop\msmult64.exe File created: C:\Program Files (x86)\Microsoft Office\root\Licenses16\O365SmallBusPremR_Subscription2-ppd.xrm-ms entropy: 7.99517680203 Jump to dropped file
Source: C:\Users\user\Desktop\msmult64.exe File created: C:\Program Files (x86)\Microsoft Office\root\Licenses16\O365SmallBusPremR_SubTrial1-ppd.xrm-ms entropy: 7.99333772668 Jump to dropped file
Source: C:\Users\user\Desktop\msmult64.exe File created: C:\Program Files (x86)\Microsoft Office\root\Licenses16\O365SmallBusPremR_SubTrial2-ppd.xrm-ms entropy: 7.99376009245 Jump to dropped file
Source: C:\Users\user\Desktop\msmult64.exe File created: C:\Program Files (x86)\Microsoft Office\root\Licenses16\O365SmallBusPremR_Subscription4-ppd.xrm-ms entropy: 7.9947257757 Jump to dropped file
Source: C:\Users\user\Desktop\msmult64.exe File created: C:\Program Files (x86)\Microsoft Office\root\Licenses16\O365SmallBusPremR_Subscription5-ppd.xrm-ms entropy: 7.9942609395 Jump to dropped file
Source: C:\Users\user\Desktop\msmult64.exe File created: C:\Program Files (x86)\Microsoft Office\root\Licenses16\O365SmallBusPremR_SubTrial5-ppd.xrm-ms entropy: 7.99335703036 Jump to dropped file
Source: C:\Users\user\Desktop\msmult64.exe File created: C:\Program Files (x86)\Microsoft Office\root\Licenses16\OneNote2021R_Grace-ppd.xrm-ms entropy: 7.99221270388 Jump to dropped file
Source: C:\Users\user\Desktop\msmult64.exe File created: C:\Program Files (x86)\Microsoft Office\root\Licenses16\O365SmallBusPremR_SubTrial3-ppd.xrm-ms entropy: 7.99309710784 Jump to dropped file
Source: C:\Users\user\Desktop\msmult64.exe File created: C:\Program Files (x86)\Microsoft Office\root\Licenses16\O365SmallBusPremR_SubTrial4-ppd.xrm-ms entropy: 7.99375673785 Jump to dropped file
Source: C:\Users\user\Desktop\msmult64.exe File created: C:\Program Files (x86)\Microsoft Office\root\Licenses16\OneNote2021R_OEM_Perp-ppd.xrm-ms entropy: 7.9931699647 Jump to dropped file
Source: C:\Users\user\Desktop\msmult64.exe File created: C:\Program Files (x86)\Microsoft Office\root\Licenses16\OneNote2021R_OEM_Perp-ul-phn.xrm-ms entropy: 7.99161214563 Jump to dropped file
Source: C:\Users\user\Desktop\msmult64.exe File created: C:\Program Files (x86)\Microsoft Office\root\Licenses16\ProjectStd2019R_Retail-ul-phn.xrm-ms entropy: 7.99183183407 Jump to dropped file
Source: C:\Users\user\Desktop\msmult64.exe File created: C:\Program Files\Google\Chrome\Application\117.0.5938.132\chrome_100_percent.pak entropy: 7.99970265689 Jump to dropped file
Source: C:\Users\user\Desktop\msmult64.exe File created: C:\Program Files\Google\Chrome\Application\117.0.5938.132\chrome_200_percent.pak entropy: 7.99919682729 Jump to dropped file
Source: C:\Users\user\Desktop\msmult64.exe File created: C:\Program Files (x86)\Microsoft Office\root\Licenses16\ProjectStd2021R_OEM_Perp-ppd.xrm-ms entropy: 7.99400230641 Jump to dropped file
Source: C:\Users\user\Desktop\msmult64.exe File created: C:\Program Files (x86)\autoit3\Include\GuiTab.au3.CRYPT (copy) entropy: 7.99455819041 Jump to dropped file
Source: C:\Users\user\Desktop\msmult64.exe File created: C:\Program Files (x86)\autoit3\Include\GuiToolbar.au3.CRYPT (copy) entropy: 7.99772324128 Jump to dropped file
Source: C:\Users\user\Desktop\msmult64.exe File created: C:\Program Files (x86)\autoit3\Include\GuiToolTip.au3.CRYPT (copy) entropy: 7.99573171114 Jump to dropped file
Source: C:\Users\user\Desktop\msmult64.exe File created: C:\Program Files (x86)\autoit3\Include\GuiTreeView.au3.CRYPT (copy) entropy: 7.99836687865 Jump to dropped file
Source: C:\Users\user\Desktop\msmult64.exe File created: C:\Program Files (x86)\autoit3\Include\helper.au3.CRYPT (copy) entropy: 7.99349271508 Jump to dropped file
Source: C:\Users\user\Desktop\msmult64.exe File created: C:\Program Files (x86)\autoit3\Include\IE.au3.CRYPT (copy) entropy: 7.99879263878 Jump to dropped file
Source: C:\Users\user\Desktop\msmult64.exe File created: C:\Program Files (x86)\autoit3\Include\ListViewConstants.au3.CRYPT (copy) entropy: 7.99249920392 Jump to dropped file
Source: C:\Users\user\Desktop\msmult64.exe File created: C:\Program Files (x86)\autoit3\Include\Memory.au3.CRYPT (copy) entropy: 7.99128502888 Jump to dropped file
Source: C:\Users\user\Desktop\msmult64.exe File created: C:\Program Files (x86)\autoit3\Include\Misc.au3.CRYPT (copy) entropy: 7.99558750876 Jump to dropped file
Source: C:\Users\user\Desktop\msmult64.exe File created: C:\Program Files (x86)\autoit3\Include\NetShare.au3.CRYPT (copy) entropy: 7.99615692541 Jump to dropped file
Source: C:\Users\user\Desktop\msmult64.exe File created: C:\Program Files (x86)\autoit3\Include\NTSTATUSConstants.au3.CRYPT (copy) entropy: 7.99928460594 Jump to dropped file
Source: C:\Users\user\Desktop\msmult64.exe File created: C:\Program Files (x86)\autoit3\Include\PowerPoint.au3.CRYPT (copy) entropy: 7.99708525813 Jump to dropped file
Source: C:\Users\user\Desktop\msmult64.exe File created: C:\Program Files (x86)\autoit3\Include\Sound.au3.CRYPT (copy) entropy: 7.99069470106 Jump to dropped file
Source: C:\Users\user\Desktop\msmult64.exe File created: C:\Program Files (x86)\autoit3\Include\SQLite.au3.CRYPT (copy) entropy: 7.99679896925 Jump to dropped file
Source: C:\Users\user\Desktop\msmult64.exe File created: C:\Program Files (x86)\autoit3\Include\StructureConstants.au3.CRYPT (copy) entropy: 7.9971369715 Jump to dropped file
Source: C:\Users\user\Desktop\msmult64.exe File created: C:\Program Files (x86)\autoit3\Include\UIAWrappers.au3.CRYPT (copy) entropy: 7.99827959736 Jump to dropped file
Source: C:\Users\user\Desktop\msmult64.exe File created: C:\Program Files (x86)\autoit3\Include\Visa.au3.CRYPT (copy) entropy: 7.99485168035 Jump to dropped file
Source: C:\Users\user\Desktop\msmult64.exe File created: C:\Program Files (x86)\autoit3\Include\WinAPIConv.au3.CRYPT (copy) entropy: 7.99391853669 Jump to dropped file
Source: C:\Users\user\Desktop\msmult64.exe File created: C:\Program Files (x86)\autoit3\Include\WinAPIDiag.au3.CRYPT (copy) entropy: 7.99407866681 Jump to dropped file
Source: C:\Users\user\Desktop\msmult64.exe File created: C:\Program Files (x86)\autoit3\Include\WinAPIDlg.au3.CRYPT (copy) entropy: 7.99439363517 Jump to dropped file
Source: C:\Users\user\Desktop\msmult64.exe File created: C:\Program Files (x86)\autoit3\Include\WinAPIFiles.au3.CRYPT (copy) entropy: 7.99814736634 Jump to dropped file
Source: C:\Users\user\Desktop\msmult64.exe File created: C:\Program Files (x86)\autoit3\Include\WinAPIGdi.au3.CRYPT (copy) entropy: 7.99900743489 Jump to dropped file
Source: C:\Users\user\Desktop\msmult64.exe File created: C:\Program Files (x86)\autoit3\Include\WinAPIGdiDC.au3.CRYPT (copy) entropy: 7.99078630675 Jump to dropped file
Source: C:\Users\user\Desktop\msmult64.exe File created: C:\Program Files (x86)\autoit3\Include\WinAPIGdiInternals.au3.CRYPT (copy) entropy: 7.99385586998 Jump to dropped file
Source: C:\Users\user\Desktop\msmult64.exe File created: C:\Program Files (x86)\autoit3\Include\WinAPIIcons.au3.CRYPT (copy) entropy: 7.99383465246 Jump to dropped file
Source: C:\Users\user\Desktop\msmult64.exe File created: C:\Program Files (x86)\autoit3\Include\WinAPIInternals.au3.CRYPT (copy) entropy: 7.99011124191 Jump to dropped file
Source: C:\Users\user\Desktop\msmult64.exe File created: C:\Program Files (x86)\autoit3\Include\WinAPILocale.au3.CRYPT (copy) entropy: 7.99190790297 Jump to dropped file
Source: C:\Users\user\Desktop\msmult64.exe File created: C:\Program Files (x86)\autoit3\Include\WinAPIMem.au3.CRYPT (copy) entropy: 7.99121097474 Jump to dropped file
Source: C:\Users\user\Desktop\msmult64.exe File created: C:\Program Files (x86)\autoit3\Include\WinAPIProc.au3.CRYPT (copy) entropy: 7.99775989036 Jump to dropped file
Source: C:\Users\user\Desktop\msmult64.exe File created: C:\Program Files (x86)\autoit3\Include\WinAPIReg.au3.CRYPT (copy) entropy: 7.9939171463 Jump to dropped file
Source: C:\Users\user\Desktop\msmult64.exe File created: C:\Program Files (x86)\autoit3\Include\WinAPIRes.au3.CRYPT (copy) entropy: 7.99537496802 Jump to dropped file
Source: C:\Users\user\Desktop\msmult64.exe File created: C:\Program Files (x86)\autoit3\Include\WinAPIShellEx.au3.CRYPT (copy) entropy: 7.99523747467 Jump to dropped file
Source: C:\Users\user\Desktop\msmult64.exe File created: C:\Program Files (x86)\autoit3\Include\WinAPIShPath.au3.CRYPT (copy) entropy: 7.99641932596 Jump to dropped file
Source: C:\Users\user\Desktop\msmult64.exe File created: C:\Program Files (x86)\autoit3\Include\WinAPISys.au3.CRYPT (copy) entropy: 7.99811831839 Jump to dropped file
Source: C:\Users\user\Desktop\msmult64.exe File created: C:\Program Files (x86)\autoit3\Include\WinAPISysInternals.au3.CRYPT (copy) entropy: 7.99364114378 Jump to dropped file
Source: C:\Users\user\Desktop\msmult64.exe File created: C:\Program Files (x86)\autoit3\Include\WinAPISysWin.au3.CRYPT (copy) entropy: 7.99716157388 Jump to dropped file
Source: C:\Users\user\Desktop\msmult64.exe File created: C:\Program Files (x86)\autoit3\Include\WinAPITheme.au3.CRYPT (copy) entropy: 7.9957330895 Jump to dropped file
Source: C:\Users\user\Desktop\msmult64.exe File created: C:\Program Files (x86)\autoit3\Include\WindowsConstants.au3.CRYPT (copy) entropy: 7.99467606809 Jump to dropped file
Source: C:\Users\user\Desktop\msmult64.exe File created: C:\Program Files (x86)\autoit3\Include\WinNet.au3.CRYPT (copy) entropy: 7.99626337642 Jump to dropped file
Source: C:\Users\user\Desktop\msmult64.exe File created: C:\Program Files (x86)\autoit3\Include\word.au3.CRYPT (copy) entropy: 7.99479021225 Jump to dropped file
Source: C:\Users\user\Desktop\msmult64.exe File created: C:\Program Files (x86)\autoit3\SciTE\au3.keywords.properties.CRYPT (copy) entropy: 7.99780216324 Jump to dropped file
Source: C:\Users\user\Desktop\msmult64.exe File created: C:\Program Files (x86)\common files\DESIGNER\MSADDNDR.OLB.CRYPT (copy) entropy: 7.99307159455 Jump to dropped file
Source: C:\Users\user\Desktop\msmult64.exe Code function: 0_2_00007FF7601AB1A4 NtProtectVirtualMemory, 0_2_00007FF7601AB1A4
Source: C:\Users\user\Desktop\msmult64.exe Code function: 0_2_00007FF7601AD2F0 0_2_00007FF7601AD2F0
Source: C:\Users\user\Desktop\msmult64.exe Code function: 0_2_00007FF76019536D 0_2_00007FF76019536D
Source: C:\Users\user\Desktop\msmult64.exe Code function: 0_2_00007FF76019E3A0 0_2_00007FF76019E3A0
Source: C:\Users\user\Desktop\msmult64.exe Code function: 0_2_00007FF76019CC80 0_2_00007FF76019CC80
Source: C:\Users\user\Desktop\msmult64.exe Code function: 0_2_00007FF7601AB4E0 0_2_00007FF7601AB4E0
Source: C:\Users\user\Desktop\msmult64.exe Code function: 0_2_00007FF76019BD40 0_2_00007FF76019BD40
Source: C:\Users\user\Desktop\msmult64.exe Code function: 0_2_00007FF7601A8D70 0_2_00007FF7601A8D70
Source: C:\Users\user\Desktop\msmult64.exe Code function: 0_2_00007FF760191E50 0_2_00007FF760191E50
Source: C:\Users\user\Desktop\msmult64.exe Code function: 0_2_00007FF76019D648 0_2_00007FF76019D648
Source: C:\Users\user\Desktop\msmult64.exe Code function: 0_2_00007FF760195E22 0_2_00007FF760195E22
Source: C:\Users\user\Desktop\msmult64.exe Code function: 0_2_00007FF760193670 0_2_00007FF760193670
Source: C:\Users\user\Desktop\msmult64.exe Code function: 0_2_00007FF7601AE756 0_2_00007FF7601AE756
Source: C:\Users\user\Desktop\msmult64.exe Code function: 0_2_00007FF7601A0780 0_2_00007FF7601A0780
Source: C:\Users\user\Desktop\msmult64.exe Code function: 0_2_00007FF7601ABFA0 0_2_00007FF7601ABFA0
Source: C:\Users\user\Desktop\msmult64.exe Code function: 0_2_00007FF760191010 0_2_00007FF760191010
Source: C:\Users\user\Desktop\msmult64.exe Code function: 0_2_00007FF76019C7F0 0_2_00007FF76019C7F0
Source: C:\Users\user\Desktop\msmult64.exe Code function: 0_2_00007FF7601AF0B0 0_2_00007FF7601AF0B0
Source: C:\Users\user\Desktop\msmult64.exe Code function: 0_2_00007FF7601A00D7 0_2_00007FF7601A00D7
Source: C:\Users\user\Desktop\msmult64.exe Code function: 0_2_00007FF7601BC150 0_2_00007FF7601BC150
Source: C:\Users\user\Desktop\msmult64.exe Code function: 0_2_00007FF7601B82F4 0_2_00007FF7601B82F4
Source: C:\Users\user\Desktop\msmult64.exe Code function: 0_2_00007FF760194BB0 0_2_00007FF760194BB0
Source: C:\Users\user\Desktop\msmult64.exe Code function: 0_2_00007FF760195400 0_2_00007FF760195400
Source: C:\Users\user\Desktop\msmult64.exe Code function: 0_2_00007FF7601BFC38 0_2_00007FF7601BFC38
Source: C:\Users\user\Desktop\msmult64.exe Code function: 0_2_00007FF7601944B0 0_2_00007FF7601944B0
Source: C:\Users\user\Desktop\msmult64.exe Code function: 0_2_00007FF760195500 0_2_00007FF760195500
Source: C:\Users\user\Desktop\msmult64.exe Code function: 0_2_00007FF7601B8500 0_2_00007FF7601B8500
Source: C:\Users\user\Desktop\msmult64.exe Code function: 0_2_00007FF7601B2D4C 0_2_00007FF7601B2D4C
Source: C:\Users\user\Desktop\msmult64.exe Code function: 0_2_00007FF7601BC57C 0_2_00007FF7601BC57C
Source: C:\Users\user\Desktop\msmult64.exe Code function: 0_2_00007FF760192DF0 0_2_00007FF760192DF0
Source: C:\Users\user\Desktop\msmult64.exe Code function: 0_2_00007FF760194630 0_2_00007FF760194630
Source: C:\Users\user\Desktop\msmult64.exe Code function: 0_2_00007FF76019AE90 0_2_00007FF76019AE90
Source: C:\Users\user\Desktop\msmult64.exe Code function: 0_2_00007FF760195EB0 0_2_00007FF760195EB0
Source: C:\Users\user\Desktop\msmult64.exe Code function: 0_2_00007FF7601AC020 0_2_00007FF7601AC020
Source: C:\Users\user\Desktop\msmult64.exe Code function: 0_2_00007FF7601B7064 0_2_00007FF7601B7064
Source: C:\Users\user\Desktop\msmult64.exe Code function: 0_2_00007FF7601A78F0 0_2_00007FF7601A78F0
Source: C:\Users\user\Desktop\msmult64.exe Code function: 0_2_00007FF7601AC0F0 0_2_00007FF7601AC0F0
Source: C:\Users\user\Desktop\msmult64.exe Section loaded: apphelp.dll Jump to behavior
Source: C:\Users\user\Desktop\msmult64.exe Section loaded: rstrtmgr.dll Jump to behavior
Source: C:\Users\user\Desktop\msmult64.exe Section loaded: ncrypt.dll Jump to behavior
Source: C:\Users\user\Desktop\msmult64.exe Section loaded: ntasn1.dll Jump to behavior
Source: C:\Users\user\Desktop\msmult64.exe Section loaded: netapi32.dll Jump to behavior
Source: C:\Users\user\Desktop\msmult64.exe Section loaded: iphlpapi.dll Jump to behavior
Source: C:\Users\user\Desktop\msmult64.exe Section loaded: shunimpl.dll Jump to behavior
Source: C:\Users\user\Desktop\msmult64.exe Section loaded: shunimpl.dll Jump to behavior
Source: C:\Users\user\Desktop\msmult64.exe Section loaded: shunimpl.dll Jump to behavior
Source: C:\Users\user\Desktop\msmult64.exe Section loaded: cryptsp.dll Jump to behavior
Source: C:\Users\user\Desktop\msmult64.exe Section loaded: rsaenh.dll Jump to behavior
Source: C:\Users\user\Desktop\msmult64.exe Section loaded: cryptbase.dll Jump to behavior
Source: C:\Users\user\Desktop\msmult64.exe Section loaded: kernel.appcore.dll Jump to behavior
Source: C:\Users\user\Desktop\msmult64.exe Section loaded: wbemcomn.dll Jump to behavior
Source: C:\Users\user\Desktop\msmult64.exe Section loaded: amsi.dll Jump to behavior
Source: C:\Users\user\Desktop\msmult64.exe Section loaded: userenv.dll Jump to behavior
Source: C:\Users\user\Desktop\msmult64.exe Section loaded: profapi.dll Jump to behavior
Source: C:\Users\user\Desktop\msmult64.exe Section loaded: mswsock.dll Jump to behavior
Source: C:\Users\user\Desktop\msmult64.exe Section loaded: napinsp.dll Jump to behavior
Source: C:\Users\user\Desktop\msmult64.exe Section loaded: pnrpnsp.dll Jump to behavior
Source: C:\Users\user\Desktop\msmult64.exe Section loaded: wshbth.dll Jump to behavior
Source: C:\Users\user\Desktop\msmult64.exe Section loaded: nlaapi.dll Jump to behavior
Source: C:\Users\user\Desktop\msmult64.exe Section loaded: dnsapi.dll Jump to behavior
Source: C:\Users\user\Desktop\msmult64.exe Section loaded: winrnr.dll Jump to behavior
Source: C:\Users\user\Desktop\msmult64.exe Section loaded: fwpuclnt.dll Jump to behavior
Source: C:\Users\user\Desktop\msmult64.exe Section loaded: rasadhlp.dll Jump to behavior
Source: C:\Users\user\Desktop\msmult64.exe Section loaded: srvcli.dll Jump to behavior
Source: C:\Users\user\Desktop\msmult64.exe Section loaded: netutils.dll Jump to behavior
Source: C:\Users\user\Desktop\msmult64.exe Section loaded: cscapi.dll Jump to behavior
Source: C:\Users\user\Desktop\msmult64.exe Section loaded: uxtheme.dll Jump to behavior
Source: classification engine Classification label: mal100.rans.spre.expl.evad.winEXE@1/1302@0/100
Source: C:\Users\user\Desktop\msmult64.exe Code function: 0_2_00007FF7601AEE80 CreateToolhelp32Snapshot,lstrcmpiW,Process32FirstW,FindCloseChangeNotification, 0_2_00007FF7601AEE80
Source: C:\Users\user\Desktop\msmult64.exe File created: C:\Program Files\Read_instructions_To_Decrypt.txt Jump to behavior
Source: C:\Users\user\Desktop\msmult64.exe File created: C:\Users\Read_instructions_To_Decrypt.txt Jump to behavior
Source: C:\Users\user\Desktop\msmult64.exe Mutant created: \Sessions\1\BaseNamedObjects\hsfjuukjzloqu28oajh727190
Source: C:\Users\user\Desktop\msmult64.exe Key opened: HKEY_LOCAL_MACHINE\Software\Policies\Microsoft\Windows\Safer\CodeIdentifiers Jump to behavior
Source: C:\Users\user\Desktop\msmult64.exe Key value queried: HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{4590F811-1D3A-11D0-891F-00AA004B2E24}\InprocServer32 Jump to behavior
Source: C:\Users\user\Desktop\msmult64.exe Directory created: C:\Program Files\Read_instructions_To_Decrypt.txt Jump to behavior
Source: C:\Users\user\Desktop\msmult64.exe Directory created: C:\Program Files\7-Zip\Read_instructions_To_Decrypt.txt Jump to behavior
Source: C:\Users\user\Desktop\msmult64.exe Directory created: C:\Program Files\Adobe\Read_instructions_To_Decrypt.txt Jump to behavior
Source: C:\Users\user\Desktop\msmult64.exe Directory created: C:\Program Files\Common Files\Read_instructions_To_Decrypt.txt Jump to behavior
Source: C:\Users\user\Desktop\msmult64.exe Directory created: C:\Program Files\Google\Read_instructions_To_Decrypt.txt Jump to behavior
Source: C:\Users\user\Desktop\msmult64.exe Directory created: C:\Program Files\Internet Explorer\Read_instructions_To_Decrypt.txt Jump to behavior
Source: C:\Users\user\Desktop\msmult64.exe Directory created: C:\Program Files\Microsoft\Read_instructions_To_Decrypt.txt Jump to behavior
Source: C:\Users\user\Desktop\msmult64.exe Directory created: C:\Program Files\Microsoft Office 15\Read_instructions_To_Decrypt.txt Jump to behavior
Source: C:\Users\user\Desktop\msmult64.exe Directory created: C:\Program Files\Mozilla Firefox\Read_instructions_To_Decrypt.txt Jump to behavior
Source: C:\Users\user\Desktop\msmult64.exe Directory created: C:\Program Files\MSBuild\Read_instructions_To_Decrypt.txt Jump to behavior
Source: C:\Users\user\Desktop\msmult64.exe Directory created: C:\Program Files\Reference Assemblies\Read_instructions_To_Decrypt.txt Jump to behavior
Source: C:\Users\user\Desktop\msmult64.exe Directory created: C:\Program Files\Uninstall Information\Read_instructions_To_Decrypt.txt Jump to behavior
Source: C:\Users\user\Desktop\msmult64.exe Directory created: C:\Program Files\7-Zip\Lang\Read_instructions_To_Decrypt.txt Jump to behavior
Source: C:\Users\user\Desktop\msmult64.exe Directory created: C:\Program Files\Adobe\Acrobat DC\Read_instructions_To_Decrypt.txt Jump to behavior
Source: C:\Users\user\Desktop\msmult64.exe Directory created: C:\Program Files\Common Files\Adobe\Read_instructions_To_Decrypt.txt Jump to behavior
Source: C:\Users\user\Desktop\msmult64.exe Directory created: C:\Program Files\Common Files\microsoft shared\Read_instructions_To_Decrypt.txt Jump to behavior
Source: C:\Users\user\Desktop\msmult64.exe Directory created: C:\Program Files\Common Files\Services\Read_instructions_To_Decrypt.txt Jump to behavior
Source: C:\Users\user\Desktop\msmult64.exe Directory created: C:\Program Files\Common Files\System\Read_instructions_To_Decrypt.txt Jump to behavior
Source: C:\Users\user\Desktop\msmult64.exe Directory created: C:\Program Files\Google\Chrome\Read_instructions_To_Decrypt.txt Jump to behavior
Source: C:\Users\user\Desktop\msmult64.exe Directory created: C:\Program Files\Internet Explorer\en-GB\Read_instructions_To_Decrypt.txt Jump to behavior
Source: C:\Users\user\Desktop\msmult64.exe Directory created: C:\Program Files\Internet Explorer\en-US\Read_instructions_To_Decrypt.txt Jump to behavior
Source: C:\Users\user\Desktop\msmult64.exe Directory created: C:\Program Files\Internet Explorer\images\Read_instructions_To_Decrypt.txt Jump to behavior
Source: C:\Users\user\Desktop\msmult64.exe Directory created: C:\Program Files\Internet Explorer\SIGNUP\Read_instructions_To_Decrypt.txt Jump to behavior
Source: C:\Users\user\Desktop\msmult64.exe Directory created: C:\Program Files\Microsoft\OneDrive\Read_instructions_To_Decrypt.txt Jump to behavior
Source: C:\Users\user\Desktop\msmult64.exe Directory created: C:\Program Files\Microsoft Office 15\ClientX64\Read_instructions_To_Decrypt.txt Jump to behavior
Source: C:\Users\user\Desktop\msmult64.exe Directory created: C:\Program Files\Mozilla Firefox\browser\Read_instructions_To_Decrypt.txt Jump to behavior
Source: C:\Users\user\Desktop\msmult64.exe Directory created: C:\Program Files\Mozilla Firefox\defaults\Read_instructions_To_Decrypt.txt Jump to behavior
Source: C:\Users\user\Desktop\msmult64.exe Directory created: C:\Program Files\Mozilla Firefox\fonts\Read_instructions_To_Decrypt.txt Jump to behavior
Source: C:\Users\user\Desktop\msmult64.exe Directory created: C:\Program Files\Mozilla Firefox\gmp-clearkey\Read_instructions_To_Decrypt.txt Jump to behavior
Source: C:\Users\user\Desktop\msmult64.exe Directory created: C:\Program Files\Mozilla Firefox\uninstall\Read_instructions_To_Decrypt.txt Jump to behavior
Source: C:\Users\user\Desktop\msmult64.exe Directory created: C:\Program Files\MSBuild\Microsoft\Read_instructions_To_Decrypt.txt Jump to behavior
Source: C:\Users\user\Desktop\msmult64.exe Directory created: C:\Program Files\Reference Assemblies\Microsoft\Read_instructions_To_Decrypt.txt Jump to behavior
Source: C:\Users\user\Desktop\msmult64.exe Directory created: C:\Program Files\Adobe\Acrobat DC\Acrobat\Read_instructions_To_Decrypt.txt Jump to behavior
Source: C:\Users\user\Desktop\msmult64.exe Directory created: C:\Program Files\Adobe\Acrobat DC\Esl\Read_instructions_To_Decrypt.txt Jump to behavior
Source: C:\Users\user\Desktop\msmult64.exe Directory created: C:\Program Files\Adobe\Acrobat DC\Resource\Read_instructions_To_Decrypt.txt Jump to behavior
Source: C:\Users\user\Desktop\msmult64.exe Directory created: C:\Program Files\Common Files\Adobe\Acrobat\Read_instructions_To_Decrypt.txt Jump to behavior
Source: C:\Users\user\Desktop\msmult64.exe Directory created: C:\Program Files\Common Files\Adobe\HelpCfg\Read_instructions_To_Decrypt.txt Jump to behavior
Source: C:\Users\user\Desktop\msmult64.exe Directory created: C:\Program Files\Common Files\microsoft shared\ClickToRun\Read_instructions_To_Decrypt.txt Jump to behavior
Source: C:\Users\user\Desktop\msmult64.exe Directory created: C:\Program Files\Common Files\microsoft shared\ink\Read_instructions_To_Decrypt.txt Jump to behavior
Source: C:\Users\user\Desktop\msmult64.exe Directory created: C:\Program Files\Common Files\microsoft shared\MSInfo\Read_instructions_To_Decrypt.txt Jump to behavior
Source: C:\Users\user\Desktop\msmult64.exe Directory created: C:\Program Files\Common Files\microsoft shared\Stationery\Read_instructions_To_Decrypt.txt Jump to behavior
Source: C:\Users\user\Desktop\msmult64.exe Directory created: C:\Program Files\Common Files\microsoft shared\TextConv\Read_instructions_To_Decrypt.txt Jump to behavior
Source: C:\Users\user\Desktop\msmult64.exe Directory created: C:\Program Files\Common Files\microsoft shared\Triedit\Read_instructions_To_Decrypt.txt Jump to behavior
Source: C:\Users\user\Desktop\msmult64.exe Directory created: C:\Program Files\Common Files\microsoft shared\VGX\Read_instructions_To_Decrypt.txt Jump to behavior
Source: C:\Users\user\Desktop\msmult64.exe Directory created: C:\Program Files\Common Files\System\ado\Read_instructions_To_Decrypt.txt Jump to behavior
Source: C:\Users\user\Desktop\msmult64.exe Directory created: C:\Program Files\Common Files\System\en-GB\Read_instructions_To_Decrypt.txt Jump to behavior
Source: C:\Users\user\Desktop\msmult64.exe Directory created: C:\Program Files\Common Files\System\en-US\Read_instructions_To_Decrypt.txt Jump to behavior
Source: C:\Users\user\Desktop\msmult64.exe Directory created: C:\Program Files\Common Files\System\msadc\Read_instructions_To_Decrypt.txt Jump to behavior
Source: C:\Users\user\Desktop\msmult64.exe Directory created: C:\Program Files\Common Files\System\Ole DB\Read_instructions_To_Decrypt.txt Jump to behavior
Source: C:\Users\user\Desktop\msmult64.exe Directory created: C:\Program Files\Google\Chrome\Application\Read_instructions_To_Decrypt.txt Jump to behavior
Source: C:\Users\user\Desktop\msmult64.exe Directory created: C:\Program Files\Microsoft\OneDrive\ListSync\Read_instructions_To_Decrypt.txt Jump to behavior
Source: C:\Users\user\Desktop\msmult64.exe Directory created: C:\Program Files\Mozilla Firefox\browser\features\Read_instructions_To_Decrypt.txt Jump to behavior
Source: C:\Users\user\Desktop\msmult64.exe Directory created: C:\Program Files\Mozilla Firefox\browser\VisualElements\Read_instructions_To_Decrypt.txt Jump to behavior
Source: C:\Users\user\Desktop\msmult64.exe Directory created: C:\Program Files\Mozilla Firefox\defaults\pref\Read_instructions_To_Decrypt.txt Jump to behavior
Source: C:\Users\user\Desktop\msmult64.exe Directory created: C:\Program Files\Mozilla Firefox\gmp-clearkey\0.1\Read_instructions_To_Decrypt.txt Jump to behavior
Source: C:\Users\user\Desktop\msmult64.exe Directory created: C:\Program Files\Reference Assemblies\Microsoft\Framework\Read_instructions_To_Decrypt.txt Jump to behavior
Source: C:\Users\user\Desktop\msmult64.exe Directory created: C:\Program Files\Adobe\Acrobat DC\Acrobat\AcroCEF\Read_instructions_To_Decrypt.txt Jump to behavior
Source: C:\Users\user\Desktop\msmult64.exe Directory created: C:\Program Files\Adobe\Acrobat DC\Acrobat\acrocef_1\Read_instructions_To_Decrypt.txt Jump to behavior
Source: C:\Users\user\Desktop\msmult64.exe Directory created: C:\Program Files\Adobe\Acrobat DC\Acrobat\Air\Read_instructions_To_Decrypt.txt Jump to behavior
Source: C:\Users\user\Desktop\msmult64.exe Directory created: C:\Program Files\Adobe\Acrobat DC\Acrobat\Assets\Read_instructions_To_Decrypt.txt Jump to behavior
Source: C:\Users\user\Desktop\msmult64.exe Directory created: C:\Program Files\Adobe\Acrobat DC\Acrobat\Browser\Read_instructions_To_Decrypt.txt Jump to behavior
Source: C:\Users\user\Desktop\msmult64.exe Directory created: C:\Program Files\Adobe\Acrobat DC\Acrobat\DocSettings\Read_instructions_To_Decrypt.txt Jump to behavior
Source: C:\Users\user\Desktop\msmult64.exe Directory created: C:\Program Files\Adobe\Acrobat DC\Acrobat\Javascripts\Read_instructions_To_Decrypt.txt Jump to behavior
Source: C:\Users\user\Desktop\msmult64.exe Directory created: C:\Program Files\Adobe\Acrobat DC\Acrobat\Legal\Read_instructions_To_Decrypt.txt Jump to behavior
Source: C:\Users\user\Desktop\msmult64.exe Directory created: C:\Program Files\Adobe\Acrobat DC\Acrobat\Locale\Read_instructions_To_Decrypt.txt Jump to behavior
Source: C:\Users\user\Desktop\msmult64.exe Directory created: C:\Program Files\Adobe\Acrobat DC\Acrobat\NGL\Read_instructions_To_Decrypt.txt Jump to behavior
Source: C:\Users\user\Desktop\msmult64.exe Directory created: C:\Program Files\Adobe\Acrobat DC\Acrobat\ngl_resources\Read_instructions_To_Decrypt.txt Jump to behavior
Source: C:\Users\user\Desktop\msmult64.exe Directory created: C:\Program Files\Adobe\Acrobat DC\Acrobat\plug_ins\Read_instructions_To_Decrypt.txt Jump to behavior
Source: C:\Users\user\Desktop\msmult64.exe Directory created: C:\Program Files\Adobe\Acrobat DC\Acrobat\plug_ins3d\Read_instructions_To_Decrypt.txt Jump to behavior
Source: C:\Users\user\Desktop\msmult64.exe Directory created: C:\Program Files\Adobe\Acrobat DC\Acrobat\RDCNotificationClient\Read_instructions_To_Decrypt.txt Jump to behavior
Source: C:\Users\user\Desktop\msmult64.exe Directory created: C:\Program Files\Adobe\Acrobat DC\Acrobat\RdrApp\Read_instructions_To_Decrypt.txt Jump to behavior
Source: C:\Users\user\Desktop\msmult64.exe Directory created: C:\Program Files\Adobe\Acrobat DC\Acrobat\Sequences\Read_instructions_To_Decrypt.txt Jump to behavior
Source: C:\Users\user\Desktop\msmult64.exe Directory created: C:\Program Files\Adobe\Acrobat DC\Acrobat\Tracker\Read_instructions_To_Decrypt.txt Jump to behavior
Source: C:\Users\user\Desktop\msmult64.exe Directory created: C:\Program Files\Adobe\Acrobat DC\Acrobat\UIThemes\Read_instructions_To_Decrypt.txt Jump to behavior
Source: C:\Users\user\Desktop\msmult64.exe Directory created: C:\Program Files\Adobe\Acrobat DC\Acrobat\WebResources\Read_instructions_To_Decrypt.txt Jump to behavior
Source: C:\Users\user\Desktop\msmult64.exe Directory created: C:\Program Files\Adobe\Acrobat DC\Acrobat\x86\Read_instructions_To_Decrypt.txt Jump to behavior
Source: C:\Users\user\Desktop\msmult64.exe Directory created: C:\Program Files\Adobe\Acrobat DC\Resource\CMap\Read_instructions_To_Decrypt.txt Jump to behavior
Source: C:\Users\user\Desktop\msmult64.exe Directory created: C:\Program Files\Adobe\Acrobat DC\Resource\Font\Read_instructions_To_Decrypt.txt Jump to behavior
Source: C:\Users\user\Desktop\msmult64.exe Directory created: C:\Program Files\Adobe\Acrobat DC\Resource\SaslPrep\Read_instructions_To_Decrypt.txt Jump to behavior
Source: C:\Users\user\Desktop\msmult64.exe Directory created: C:\Program Files\Adobe\Acrobat DC\Resource\TypeSupport\Read_instructions_To_Decrypt.txt Jump to behavior
Source: C:\Users\user\Desktop\msmult64.exe Directory created: C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\Read_instructions_To_Decrypt.txt Jump to behavior
Source: C:\Users\user\Desktop\msmult64.exe Directory created: C:\Program Files\Common Files\Adobe\Acrobat\DC\Read_instructions_To_Decrypt.txt Jump to behavior
Source: C:\Users\user\Desktop\msmult64.exe Directory created: C:\Program Files\Common Files\Adobe\Acrobat\Setup\Read_instructions_To_Decrypt.txt Jump to behavior
Source: C:\Users\user\Desktop\msmult64.exe Directory created: C:\Program Files\Common Files\Adobe\Acrobat\Setup Files\Read_instructions_To_Decrypt.txt Jump to behavior
Source: C:\Users\user\Desktop\msmult64.exe Directory created: C:\Program Files\Common Files\Adobe\HelpCfg\en_US\Read_instructions_To_Decrypt.txt Jump to behavior
Source: C:\Users\user\Desktop\msmult64.exe Directory created: C:\Program Files\Common Files\microsoft shared\ClickToRun\OnlineInteraction\Read_instructions_To_Decrypt.txt Jump to behavior
Source: C:\Users\user\Desktop\msmult64.exe Directory created: C:\Program Files\Common Files\microsoft shared\ink\ar-SA\Read_instructions_To_Decrypt.txt Jump to behavior
Source: C:\Users\user\Desktop\msmult64.exe Directory created: C:\Program Files\Common Files\microsoft shared\ink\bg-BG\Read_instructions_To_Decrypt.txt Jump to behavior
Source: C:\Users\user\Desktop\msmult64.exe Directory created: C:\Program Files\Common Files\microsoft shared\ink\cs-CZ\Read_instructions_To_Decrypt.txt Jump to behavior
Source: C:\Users\user\Desktop\msmult64.exe Directory created: C:\Program Files\Common Files\microsoft shared\ink\da-DK\Read_instructions_To_Decrypt.txt Jump to behavior
Source: C:\Users\user\Desktop\msmult64.exe Directory created: C:\Program Files\Common Files\microsoft shared\ink\de-DE\Read_instructions_To_Decrypt.txt Jump to behavior
Source: C:\Users\user\Desktop\msmult64.exe Directory created: C:\Program Files\Common Files\microsoft shared\ink\el-GR\Read_instructions_To_Decrypt.txt Jump to behavior
Source: C:\Users\user\Desktop\msmult64.exe Directory created: C:\Program Files\Common Files\microsoft shared\ink\en-GB\Read_instructions_To_Decrypt.txt Jump to behavior
Source: C:\Users\user\Desktop\msmult64.exe Directory created: C:\Program Files\Common Files\microsoft shared\ink\en-US\Read_instructions_To_Decrypt.txt Jump to behavior
Source: C:\Users\user\Desktop\msmult64.exe Directory created: C:\Program Files\Common Files\microsoft shared\ink\es-ES\Read_instructions_To_Decrypt.txt Jump to behavior
Source: C:\Users\user\Desktop\msmult64.exe Directory created: C:\Program Files\Common Files\microsoft shared\ink\es-MX\Read_instructions_To_Decrypt.txt Jump to behavior
Source: C:\Users\user\Desktop\msmult64.exe Directory created: C:\Program Files\Common Files\microsoft shared\ink\et-EE\Read_instructions_To_Decrypt.txt Jump to behavior
Source: C:\Users\user\Desktop\msmult64.exe Directory created: C:\Program Files\Common Files\microsoft shared\ink\fi-FI\Read_instructions_To_Decrypt.txt Jump to behavior
Source: C:\Users\user\Desktop\msmult64.exe Directory created: C:\Program Files\Common Files\microsoft shared\ink\fr-CA\Read_instructions_To_Decrypt.txt Jump to behavior
Source: C:\Users\user\Desktop\msmult64.exe Directory created: C:\Program Files\Common Files\microsoft shared\ink\fr-FR\Read_instructions_To_Decrypt.txt Jump to behavior
Source: C:\Users\user\Desktop\msmult64.exe Directory created: C:\Program Files\Common Files\microsoft shared\ink\fsdefinitions\Read_instructions_To_Decrypt.txt Jump to behavior
Source: C:\Users\user\Desktop\msmult64.exe Directory created: C:\Program Files\Common Files\microsoft shared\ink\he-IL\Read_instructions_To_Decrypt.txt Jump to behavior
Source: C:\Users\user\Desktop\msmult64.exe Directory created: C:\Program Files\Common Files\microsoft shared\ink\hr-HR\Read_instructions_To_Decrypt.txt Jump to behavior
Source: C:\Users\user\Desktop\msmult64.exe Directory created: C:\Program Files\Common Files\microsoft shared\ink\hu-HU\Read_instructions_To_Decrypt.txt Jump to behavior
Source: C:\Users\user\Desktop\msmult64.exe Directory created: C:\Program Files\Common Files\microsoft shared\ink\HWRCustomization\Read_instructions_To_Decrypt.txt Jump to behavior
Source: C:\Users\user\Desktop\msmult64.exe Directory created: C:\Program Files\Common Files\microsoft shared\ink\it-IT\Read_instructions_To_Decrypt.txt Jump to behavior
Source: C:\Users\user\Desktop\msmult64.exe Directory created: C:\Program Files\Common Files\microsoft shared\ink\ja-JP\Read_instructions_To_Decrypt.txt Jump to behavior
Source: C:\Users\user\Desktop\msmult64.exe Directory created: C:\Program Files\Common Files\microsoft shared\ink\ko-KR\Read_instructions_To_Decrypt.txt Jump to behavior
Source: C:\Users\user\Desktop\msmult64.exe Directory created: C:\Program Files\Common Files\microsoft shared\ink\LanguageModel\Read_instructions_To_Decrypt.txt Jump to behavior
Source: C:\Users\user\Desktop\msmult64.exe Directory created: C:\Program Files\Common Files\microsoft shared\ink\lt-LT\Read_instructions_To_Decrypt.txt Jump to behavior
Source: C:\Users\user\Desktop\msmult64.exe Directory created: C:\Program Files\Common Files\microsoft shared\ink\lv-LV\Read_instructions_To_Decrypt.txt Jump to behavior
Source: C:\Users\user\Desktop\msmult64.exe Directory created: C:\Program Files\Common Files\microsoft shared\ink\nb-NO\Read_instructions_To_Decrypt.txt Jump to behavior
Source: C:\Users\user\Desktop\msmult64.exe Directory created: C:\Program Files\Common Files\microsoft shared\ink\nl-NL\Read_instructions_To_Decrypt.txt Jump to behavior
Source: C:\Users\user\Desktop\msmult64.exe Directory created: C:\Program Files\Common Files\microsoft shared\ink\pl-PL\Read_instructions_To_Decrypt.txt Jump to behavior
Source: C:\Users\user\Desktop\msmult64.exe Directory created: C:\Program Files\Common Files\microsoft shared\ink\pt-BR\Read_instructions_To_Decrypt.txt Jump to behavior
Source: C:\Users\user\Desktop\msmult64.exe Directory created: C:\Program Files\Common Files\microsoft shared\ink\pt-PT\Read_instructions_To_Decrypt.txt Jump to behavior
Source: C:\Users\user\Desktop\msmult64.exe Directory created: C:\Program Files\Common Files\microsoft shared\ink\ro-RO\Read_instructions_To_Decrypt.txt Jump to behavior
Source: C:\Users\user\Desktop\msmult64.exe Directory created: C:\Program Files\Common Files\microsoft shared\ink\ru-RU\Read_instructions_To_Decrypt.txt Jump to behavior
Source: C:\Users\user\Desktop\msmult64.exe Directory created: C:\Program Files\Common Files\microsoft shared\ink\sk-SK\Read_instructions_To_Decrypt.txt Jump to behavior
Source: C:\Users\user\Desktop\msmult64.exe Directory created: C:\Program Files\Common Files\microsoft shared\ink\sl-SI\Read_instructions_To_Decrypt.txt Jump to behavior
Source: C:\Users\user\Desktop\msmult64.exe Directory created: C:\Program Files\Common Files\microsoft shared\ink\sr-Latn-RS\Read_instructions_To_Decrypt.txt Jump to behavior
Source: C:\Users\user\Desktop\msmult64.exe Directory created: C:\Program Files\Common Files\microsoft shared\ink\sv-SE\Read_instructions_To_Decrypt.txt Jump to behavior
Source: C:\Users\user\Desktop\msmult64.exe Directory created: C:\Program Files\Common Files\microsoft shared\ink\th-TH\Read_instructions_To_Decrypt.txt Jump to behavior
Source: C:\Users\user\Desktop\msmult64.exe Directory created: C:\Program Files\Common Files\microsoft shared\ink\tr-TR\Read_instructions_To_Decrypt.txt Jump to behavior
Source: C:\Users\user\Desktop\msmult64.exe Directory created: C:\Program Files\Common Files\microsoft shared\ink\uk-UA\Read_instructions_To_Decrypt.txt Jump to behavior
Source: C:\Users\user\Desktop\msmult64.exe Directory created: C:\Program Files\Common Files\microsoft shared\ink\zh-CN\Read_instructions_To_Decrypt.txt Jump to behavior
Source: C:\Users\user\Desktop\msmult64.exe Directory created: C:\Program Files\Common Files\microsoft shared\ink\zh-TW\Read_instructions_To_Decrypt.txt Jump to behavior
Source: C:\Users\user\Desktop\msmult64.exe Directory created: C:\Program Files\Common Files\microsoft shared\MSInfo\en-GB\Read_instructions_To_Decrypt.txt Jump to behavior
Source: C:\Users\user\Desktop\msmult64.exe Directory created: C:\Program Files\Common Files\microsoft shared\MSInfo\en-US\Read_instructions_To_Decrypt.txt Jump to behavior
Source: C:\Users\user\Desktop\msmult64.exe Directory created: C:\Program Files\Common Files\microsoft shared\TextConv\en-US\Read_instructions_To_Decrypt.txt Jump to behavior
Source: C:\Users\user\Desktop\msmult64.exe Directory created: C:\Program Files\Common Files\microsoft shared\Triedit\en-US\Read_instructions_To_Decrypt.txt Jump to behavior
Source: C:\Users\user\Desktop\msmult64.exe Directory created: C:\Program Files\Common Files\System\ado\en-US\Read_instructions_To_Decrypt.txt Jump to behavior
Source: C:\Users\user\Desktop\msmult64.exe Directory created: C:\Program Files\Common Files\System\msadc\en-US\Read_instructions_To_Decrypt.txt Jump to behavior
Source: C:\Users\user\Desktop\msmult64.exe Directory created: C:\Program Files\Common Files\System\Ole DB\en-US\Read_instructions_To_Decrypt.txt Jump to behavior
Source: C:\Users\user\Desktop\msmult64.exe Directory created: C:\Program Files\Google\Chrome\Application\117.0.5938.132\Read_instructions_To_Decrypt.txt Jump to behavior
Source: C:\Users\user\Desktop\msmult64.exe Directory created: C:\Program Files\Google\Chrome\Application\SetupMetrics\Read_instructions_To_Decrypt.txt Jump to behavior
Source: C:\Users\user\Desktop\msmult64.exe Directory created: C:\Program Files\Microsoft\OneDrive\ListSync\settings\Read_instructions_To_Decrypt.txt Jump to behavior
Source: C:\Users\user\Desktop\msmult64.exe Directory created: C:\Program Files\Reference Assemblies\Microsoft\Framework\v3.0\Read_instructions_To_Decrypt.txt Jump to behavior
Source: C:\Users\user\Desktop\msmult64.exe Directory created: C:\Program Files\Reference Assemblies\Microsoft\Framework\v3.5\Read_instructions_To_Decrypt.txt Jump to behavior
Source: C:\Users\user\Desktop\msmult64.exe Directory created: C:\Program Files\Adobe\Acrobat DC\Acrobat\AcroCEF\locales\Read_instructions_To_Decrypt.txt Jump to behavior
Source: C:\Users\user\Desktop\msmult64.exe Directory created: C:\Program Files\Adobe\Acrobat DC\Acrobat\AcroCEF\swiftshader\Read_instructions_To_Decrypt.txt Jump to behavior
Source: C:\Users\user\Desktop\msmult64.exe Directory created: C:\Program Files\Adobe\Acrobat DC\Acrobat\acrocef_1\locales\Read_instructions_To_Decrypt.txt Jump to behavior
Source: C:\Users\user\Desktop\msmult64.exe Directory created: C:\Program Files\Adobe\Acrobat DC\Acrobat\acrocef_1\swiftshader\Read_instructions_To_Decrypt.txt Jump to behavior
Source: C:\Users\user\Desktop\msmult64.exe Directory created: C:\Program Files\Adobe\Acrobat DC\Acrobat\Browser\WCChromeExtn\Read_instructions_To_Decrypt.txt Jump to behavior
Source: C:\Users\user\Desktop\msmult64.exe Directory created: C:\Program Files\Adobe\Acrobat DC\Acrobat\DocSettings\Redaction\Read_instructions_To_Decrypt.txt Jump to behavior
Source: C:\Users\user\Desktop\msmult64.exe Directory created: C:\Program Files\Adobe\Acrobat DC\Acrobat\Legal\ar_AE\Read_instructions_To_Decrypt.txt Jump to behavior
Source: C:\Users\user\Desktop\msmult64.exe Directory created: C:\Program Files\Adobe\Acrobat DC\Acrobat\Legal\cs_CZ\Read_instructions_To_Decrypt.txt Jump to behavior
Source: C:\Users\user\Desktop\msmult64.exe Directory created: C:\Program Files\Adobe\Acrobat DC\Acrobat\Legal\da_DK\Read_instructions_To_Decrypt.txt Jump to behavior
Source: C:\Users\user\Desktop\msmult64.exe Directory created: C:\Program Files\Adobe\Acrobat DC\Acrobat\Legal\de_DE\Read_instructions_To_Decrypt.txt Jump to behavior
Source: C:\Users\user\Desktop\msmult64.exe Directory created: C:\Program Files\Adobe\Acrobat DC\Acrobat\Legal\el_GR\Read_instructions_To_Decrypt.txt Jump to behavior
Source: C:\Users\user\Desktop\msmult64.exe Directory created: C:\Program Files\Adobe\Acrobat DC\Acrobat\Legal\ENU\Read_instructions_To_Decrypt.txt Jump to behavior
Source: C:\Users\user\Desktop\msmult64.exe Directory created: C:\Program Files\Adobe\Acrobat DC\Acrobat\Legal\en_AE\Read_instructions_To_Decrypt.txt Jump to behavior
Source: C:\Users\user\Desktop\msmult64.exe Directory created: C:\Program Files\Adobe\Acrobat DC\Acrobat\Legal\en_GB\Read_instructions_To_Decrypt.txt Jump to behavior
Source: C:\Users\user\Desktop\msmult64.exe Directory created: C:\Program Files\Adobe\Acrobat DC\Acrobat\Legal\en_IL\Read_instructions_To_Decrypt.txt Jump to behavior
Source: C:\Users\user\Desktop\msmult64.exe Directory created: C:\Program Files\Adobe\Acrobat DC\Acrobat\Legal\en_US\Read_instructions_To_Decrypt.txt Jump to behavior
Source: C:\Users\user\Desktop\msmult64.exe Directory created: C:\Program Files\Adobe\Acrobat DC\Acrobat\Legal\es_ES\Read_instructions_To_Decrypt.txt Jump to behavior
Source: C:\Users\user\Desktop\msmult64.exe Directory created: C:\Program Files\Adobe\Acrobat DC\Acrobat\Legal\fi_FI\Read_instructions_To_Decrypt.txt Jump to behavior
Source: C:\Users\user\Desktop\msmult64.exe Directory created: C:\Program Files\Adobe\Acrobat DC\Acrobat\Legal\fr_FR\Read_instructions_To_Decrypt.txt Jump to behavior
Source: C:\Users\user\Desktop\msmult64.exe Directory created: C:\Program Files\Adobe\Acrobat DC\Acrobat\Legal\fr_MA\Read_instructions_To_Decrypt.txt Jump to behavior
Source: C:\Users\user\Desktop\msmult64.exe Directory created: C:\Program Files\Adobe\Acrobat DC\Acrobat\Legal\he_IL\Read_instructions_To_Decrypt.txt Jump to behavior
Source: C:\Users\user\Desktop\msmult64.exe Directory created: C:\Program Files\Adobe\Acrobat DC\Acrobat\Legal\hu_HU\Read_instructions_To_Decrypt.txt Jump to behavior
Source: C:\Users\user\Desktop\msmult64.exe Directory created: C:\Program Files\Adobe\Acrobat DC\Acrobat\Legal\it_IT\Read_instructions_To_Decrypt.txt Jump to behavior
Source: C:\Users\user\Desktop\msmult64.exe Directory created: C:\Program Files\Adobe\Acrobat DC\Acrobat\Legal\ja_JP\Read_instructions_To_Decrypt.txt Jump to behavior
Source: C:\Users\user\Desktop\msmult64.exe Directory created: C:\Program Files\Adobe\Acrobat DC\Acrobat\Legal\ko_KR\Read_instructions_To_Decrypt.txt Jump to behavior
Source: C:\Users\user\Desktop\msmult64.exe Directory created: C:\Program Files\Adobe\Acrobat DC\Acrobat\Legal\nb_NO\Read_instructions_To_Decrypt.txt Jump to behavior
Source: C:\Users\user\Desktop\msmult64.exe Directory created: C:\Program Files\Adobe\Acrobat DC\Acrobat\Legal\nl_NL\Read_instructions_To_Decrypt.txt Jump to behavior
Source: C:\Users\user\Desktop\msmult64.exe Directory created: C:\Program Files\Adobe\Acrobat DC\Acrobat\Legal\pl_PL\Read_instructions_To_Decrypt.txt Jump to behavior
Source: C:\Users\user\Desktop\msmult64.exe Directory created: C:\Program Files\Adobe\Acrobat DC\Acrobat\Legal\pt_BR\Read_instructions_To_Decrypt.txt Jump to behavior
Source: C:\Users\user\Desktop\msmult64.exe Directory created: C:\Program Files\Adobe\Acrobat DC\Acrobat\Legal\ru_RU\Read_instructions_To_Decrypt.txt Jump to behavior
Source: C:\Users\user\Desktop\msmult64.exe Directory created: C:\Program Files\Adobe\Acrobat DC\Acrobat\Legal\sk_SK\Read_instructions_To_Decrypt.txt Jump to behavior
Source: C:\Users\user\Desktop\msmult64.exe Directory created: C:\Program Files\Adobe\Acrobat DC\Acrobat\Legal\sl_SI\Read_instructions_To_Decrypt.txt Jump to behavior
Source: C:\Users\user\Desktop\msmult64.exe Directory created: C:\Program Files\Adobe\Acrobat DC\Acrobat\Legal\sv_SE\Read_instructions_To_Decrypt.txt Jump to behavior
Source: C:\Users\user\Desktop\msmult64.exe Directory created: C:\Program Files\Adobe\Acrobat DC\Acrobat\Legal\tr_TR\Read_instructions_To_Decrypt.txt Jump to behavior
Source: C:\Users\user\Desktop\msmult64.exe Directory created: C:\Program Files\Adobe\Acrobat DC\Acrobat\Legal\uk_UA\Read_instructions_To_Decrypt.txt Jump to behavior
Source: C:\Users\user\Desktop\msmult64.exe Directory created: C:\Program Files\Adobe\Acrobat DC\Acrobat\Legal\zh_CN\Read_instructions_To_Decrypt.txt Jump to behavior
Source: C:\Users\user\Desktop\msmult64.exe Directory created: C:\Program Files\Adobe\Acrobat DC\Acrobat\Legal\zh_TW\Read_instructions_To_Decrypt.txt Jump to behavior
Source: C:\Users\user\Desktop\msmult64.exe Directory created: C:\Program Files\Adobe\Acrobat DC\Acrobat\Locale\en_US\Read_instructions_To_Decrypt.txt Jump to behavior
Source: C:\Users\user\Desktop\msmult64.exe Directory created: C:\Program Files\Adobe\Acrobat DC\Acrobat\NGL\cefWorkflow\Read_instructions_To_Decrypt.txt Jump to behavior
Source: C:\Users\user\Desktop\msmult64.exe Directory created: C:\Program Files\Adobe\Acrobat DC\Acrobat\ngl_resources\resources\Read_instructions_To_Decrypt.txt Jump to behavior
Source: C:\Users\user\Desktop\msmult64.exe Directory created: C:\Program Files\Adobe\Acrobat DC\Acrobat\plug_ins\AcroForm\Read_instructions_To_Decrypt.txt Jump to behavior
Source: C:\Users\user\Desktop\msmult64.exe Directory created: C:\Program Files\Adobe\Acrobat DC\Acrobat\plug_ins\Annotations\Read_instructions_To_Decrypt.txt Jump to behavior
Source: C:\Users\user\Desktop\msmult64.exe Directory created: C:\Program Files\Adobe\Acrobat DC\Acrobat\plug_ins\Multimedia\Read_instructions_To_Decrypt.txt Jump to behavior
Source: C:\Users\user\Desktop\msmult64.exe Directory created: C:\Program Files\Adobe\Acrobat DC\Acrobat\plug_ins\pi_brokers\Read_instructions_To_Decrypt.txt Jump to behavior
Source: C:\Users\user\Desktop\msmult64.exe Directory created: C:\Program Files\Adobe\Acrobat DC\Acrobat\plug_ins3d\prc\Read_instructions_To_Decrypt.txt Jump to behavior
Source: C:\Users\user\Desktop\msmult64.exe Directory created: C:\Program Files\Adobe\Acrobat DC\Acrobat\RdrApp\ENU\Read_instructions_To_Decrypt.txt Jump to behavior
Source: C:\Users\user\Desktop\msmult64.exe Directory created: C:\Program Files\Adobe\Acrobat DC\Acrobat\Sequences\ENU\Read_instructions_To_Decrypt.txt Jump to behavior
Source: C:\Users\user\Desktop\msmult64.exe Directory created: C:\Program Files\Adobe\Acrobat DC\Acrobat\WebResources\Resource0\Read_instructions_To_Decrypt.txt Jump to behavior
Source: C:\Users\user\Desktop\msmult64.exe Directory created: C:\Program Files\Adobe\Acrobat DC\Acrobat\x86\Acrobat\Read_instructions_To_Decrypt.txt Jump to behavior
Source: C:\Users\user\Desktop\msmult64.exe Directory created: C:\Program Files\Adobe\Acrobat DC\Resource\Font\Pfm\Read_instructions_To_Decrypt.txt Jump to behavior
Source: C:\Users\user\Desktop\msmult64.exe Directory created: C:\Program Files\Adobe\Acrobat DC\Resource\TypeSupport\Unicode\Read_instructions_To_Decrypt.txt Jump to behavior
Source: C:\Users\user\Desktop\msmult64.exe Directory created: C:\Program Files\Common Files\Adobe\Acrobat\DC\Linguistics\Read_instructions_To_Decrypt.txt Jump to behavior
Source: C:\Users\user\Desktop\msmult64.exe Directory created: C:\Program Files\Common Files\Adobe\Acrobat\Setup\{AC76BA86-1033-1033-7760-BC15014EA700}\Read_instructions_To_Decrypt.txt Jump to behavior
Source: C:\Users\user\Desktop\msmult64.exe Directory created: C:\Program Files\Common Files\Adobe\Acrobat\Setup Files\{AC76BA86-1033-1033-7760-BC15014EA700}\Read_instructions_To_Decrypt.txt Jump to behavior
Source: C:\Users\user\Desktop\msmult64.exe Directory created: C:\Program Files\Common Files\microsoft shared\ink\fsdefinitions\auxpad\Read_instructions_To_Decrypt.txt Jump to behavior
Source: C:\Users\user\Desktop\msmult64.exe Directory created: C:\Program Files\Common Files\microsoft shared\ink\fsdefinitions\insert\Read_instructions_To_Decrypt.txt Jump to behavior
Source: C:\Users\user\Desktop\msmult64.exe Directory created: C:\Program Files\Common Files\microsoft shared\ink\fsdefinitions\keypad\Read_instructions_To_Decrypt.txt Jump to behavior
Source: C:\Users\user\Desktop\msmult64.exe Directory created: C:\Program Files\Common Files\microsoft shared\ink\fsdefinitions\main\Read_instructions_To_Decrypt.txt Jump to behavior
Source: C:\Users\user\Desktop\msmult64.exe Directory created: C:\Program Files\Common Files\microsoft shared\ink\fsdefinitions\oskclearui\Read_instructions_To_Decrypt.txt Jump to behavior
Source: C:\Users\user\Desktop\msmult64.exe Directory created: C:\Program Files\Common Files\microsoft shared\ink\fsdefinitions\oskmenu\Read_instructions_To_Decrypt.txt Jump to behavior
Source: C:\Users\user\Desktop\msmult64.exe Directory created: C:\Program Files\Common Files\microsoft shared\ink\fsdefinitions\osknav\Read_instructions_To_Decrypt.txt Jump to behavior
Source: C:\Users\user\Desktop\msmult64.exe Directory created: C:\Program Files\Common Files\microsoft shared\ink\fsdefinitions\osknumpad\Read_instructions_To_Decrypt.txt Jump to behavior
Source: C:\Users\user\Desktop\msmult64.exe Directory created: C:\Program Files\Common Files\microsoft shared\ink\fsdefinitions\oskpred\Read_instructions_To_Decrypt.txt Jump to behavior
Source: C:\Users\user\Desktop\msmult64.exe Directory created: C:\Program Files\Common Files\microsoft shared\ink\fsdefinitions\symbols\Read_instructions_To_Decrypt.txt Jump to behavior
Source: C:\Users\user\Desktop\msmult64.exe Directory created: C:\Program Files\Google\Chrome\Application\117.0.5938.132\default_apps\Read_instructions_To_Decrypt.txt Jump to behavior
Source: C:\Users\user\Desktop\msmult64.exe Directory created: C:\Program Files\Google\Chrome\Application\117.0.5938.132\Extensions\Read_instructions_To_Decrypt.txt Jump to behavior
Source: C:\Users\user\Desktop\msmult64.exe Directory created: C:\Program Files\Google\Chrome\Application\117.0.5938.132\Installer\Read_instructions_To_Decrypt.txt Jump to behavior
Source: C:\Users\user\Desktop\msmult64.exe Directory created: C:\Program Files\Google\Chrome\Application\117.0.5938.132\Locales\Read_instructions_To_Decrypt.txt Jump to behavior
Source: C:\Users\user\Desktop\msmult64.exe Directory created: C:\Program Files\Google\Chrome\Application\117.0.5938.132\MEIPreload\Read_instructions_To_Decrypt.txt Jump to behavior
Source: C:\Users\user\Desktop\msmult64.exe Directory created: C:\Program Files\Google\Chrome\Application\117.0.5938.132\VisualElements\Read_instructions_To_Decrypt.txt Jump to behavior
Source: C:\Users\user\Desktop\msmult64.exe Directory created: C:\Program Files\Google\Chrome\Application\117.0.5938.132\WidevineCdm\Read_instructions_To_Decrypt.txt Jump to behavior
Source: C:\Users\user\Desktop\msmult64.exe Directory created: C:\Program Files\Reference Assemblies\Microsoft\Framework\v3.0\RedistList\Read_instructions_To_Decrypt.txt Jump to behavior
Source: C:\Users\user\Desktop\msmult64.exe Directory created: C:\Program Files\Reference Assemblies\Microsoft\Framework\v3.5\RedistList\Read_instructions_To_Decrypt.txt Jump to behavior
Source: msmult64.exe Static PE information: Image base 0x140000000 > 0x60000000
Source: msmult64.exe Static file information: File size 3579392 > 1048576
Source: msmult64.exe Static PE information: Raw size of .dtr2 is bigger than: 0x100000 < 0x367800
Source: msmult64.exe Static PE information: HIGH_ENTROPY_VA, DYNAMIC_BASE, NX_COMPAT, TERMINAL_SERVER_AWARE
Source: initial sample Static PE information: section where entry point is pointing to: .dtr2
Source: msmult64.exe Static PE information: section name: .dtr0
Source: msmult64.exe Static PE information: section name: .dtr1
Source: msmult64.exe Static PE information: section name: .dtr2
Source: C:\Users\user\Desktop\msmult64.exe Code function: 0_2_00007FF7601B0C9C push rsi; iretd 0_2_00007FF7601B0CA0
Source: C:\Users\user\Desktop\msmult64.exe Code function: 0_2_00007FF7601BAF85 push rbp; iretd 0_2_00007FF7601BAF86

Persistence and Installation Behavior

barindex
Source: C:\Users\user\Desktop\msmult64.exe System file written: C:\Program Files (x86)\Java\jre-1.8\Welcome.html Jump to behavior
Source: C:\Users\user\Desktop\msmult64.exe System file written: C:\Program Files (x86)\Microsoft Office\Office16\OSPP.HTM Jump to behavior

Hooking and other Techniques for Hiding and Protection

barindex
Source: C:\Users\user\Desktop\msmult64.exe Memory written: PID: 7492 base: 7FFE22370008 value: E9 EB D9 E9 FF Jump to behavior
Source: C:\Users\user\Desktop\msmult64.exe Memory written: PID: 7492 base: 7FFE2220D9F0 value: E9 20 26 16 00 Jump to behavior
Source: C:\Users\user\Desktop\msmult64.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Users\user\Desktop\msmult64.exe File opened / queried: D:\sources\replacementmanifests\microsoft-hyper-v-client-migration-replacement.man Jump to behavior
Source: C:\Users\user\Desktop\msmult64.exe File opened / queried: D:\sources\replacementmanifests\microsoft-hyper-v-drivers-migration-replacement.man Jump to behavior
Source: C:\Users\user\Desktop\msmult64.exe File opened / queried: D:\sources\replacementmanifests\microsoft-hyper-v-migration-replacement.man Jump to behavior
Source: C:\Users\user\Desktop\msmult64.exe TID: 7508 Thread sleep count: 74 > 30 Jump to behavior
Source: C:\Users\user\Desktop\msmult64.exe TID: 7508 Thread sleep time: -370000s >= -30000s Jump to behavior
Source: C:\Users\user\Desktop\msmult64.exe Code function: 0_2_00007FF7601A8D70 FindFirstFileW,FindNextFileW,FindClose,_invalid_parameter_noinfo_noreturn,_invalid_parameter_noinfo_noreturn,_invalid_parameter_noinfo_noreturn, 0_2_00007FF7601A8D70
Source: C:\Users\user\Desktop\msmult64.exe Code function: 0_2_00007FF7601A6E20 GetLogicalDriveStringsW,GetLogicalDriveStringsW, 0_2_00007FF7601A6E20
Source: msmult64.exe, 00000000.00000003.1911708230.00000264BA378000.00000004.00000020.00020000.00000000.sdmp, msmult64.exe, 00000000.00000003.1915796369.00000264BA392000.00000004.00000020.00020000.00000000.sdmp, msmult64.exe, 00000000.00000003.1915768778.00000264BA388000.00000004.00000020.00020000.00000000.sdmp, msmult64.exe, 00000000.00000003.1911594271.00000264BA376000.00000004.00000020.00020000.00000000.sdmp Binary or memory string: Hyper-V RAW
Source: C:\Users\user\Desktop\msmult64.exe Process information queried: ProcessInformation Jump to behavior

HIPS / PFW / Operating System Protection Evasion

barindex
Source: C:\Users\user\Desktop\msmult64.exe NtAllocateVirtualMemory: Direct from: 0x7FF7601AF841 Jump to behavior
Source: C:\Users\user\Desktop\msmult64.exe NtReadFile: Direct from: 0x7FF7601A0332 Jump to behavior
Source: C:\Users\user\Desktop\msmult64.exe NtCreateThreadEx: Direct from: 0x7FF7601AE996 Jump to behavior
Source: C:\Users\user\Desktop\msmult64.exe NtQueryInformationToken: Direct from: 0x7FF7601AF008 Jump to behavior
Source: C:\Users\user\Desktop\msmult64.exe NtProtectVirtualMemory: Direct from: 0x7FF7601AEBC9 Jump to behavior
Source: C:\Users\user\Desktop\msmult64.exe NtTerminateThread: Direct from: 0x7FF7601AD8F8 Jump to behavior
Source: C:\Users\user\Desktop\msmult64.exe NtReadFile: Direct from: 0x7FF76019E640 Jump to behavior
Source: C:\Users\user\Desktop\msmult64.exe NtAllocateVirtualMemory: Direct from: 0x7FF7601A8C39 Jump to behavior
Source: C:\Users\user\Desktop\msmult64.exe NtSetInformationFile: Direct from: 0x7FF76019D671 Jump to behavior
Source: C:\Users\user\Desktop\msmult64.exe NtClose: Direct from: 0x7FF7601AF085
Source: C:\Users\user\Desktop\msmult64.exe NtProtectVirtualMemory: Direct from: 0x7FF760193EBC Jump to behavior
Source: C:\Users\user\Desktop\msmult64.exe NtProtectVirtualMemory: Direct from: 0x7FF7601AD029 Jump to behavior
Source: C:\Users\user\Desktop\msmult64.exe NtProtectVirtualMemory: Direct from: 0x7FF7604534B5 Jump to behavior
Source: C:\Users\user\Desktop\msmult64.exe NtDeviceIoControlFile: Direct from: 0x7FF7601ACD4E Jump to behavior
Source: C:\Users\user\Desktop\msmult64.exe NtQuerySystemInformation: Direct from: 0x7FF7601ABF7C Jump to behavior
Source: C:\Users\user\Desktop\msmult64.exe NtAllocateVirtualMemory: Direct from: 0x7FFE221E4B5E Jump to behavior
Source: C:\Users\user\Desktop\msmult64.exe NtProtectVirtualMemory: Direct from: 0x7FF7606B5B26 Jump to behavior
Source: C:\Users\user\Desktop\msmult64.exe NtCreateThreadEx: Direct from: 0x7FF7601AE86C Jump to behavior
Source: C:\Users\user\Desktop\msmult64.exe NtClose: Direct from: 0x7FF7601A0F95
Source: C:\Users\user\Desktop\msmult64.exe NtMapViewOfSection: Direct from: 0x7FF760191BB9 Jump to behavior
Source: C:\Users\user\Desktop\msmult64.exe NtProtectVirtualMemory: Direct from: 0x7FF76019571A Jump to behavior
Source: C:\Users\user\Desktop\msmult64.exe NtWriteFile: Direct from: 0x7FF76019BE6A Jump to behavior
Source: C:\Users\user\Desktop\msmult64.exe NtDeviceIoControlFile: Direct from: 0x7FF7601AE30F Jump to behavior
Source: C:\Users\user\Desktop\msmult64.exe NtCreateMutant: Direct from: 0x7FF7601ABEE8 Jump to behavior
Source: C:\Users\user\Desktop\msmult64.exe NtMapViewOfSection: Direct from: 0x7FF76041E06C Jump to behavior
Source: C:\Users\user\Desktop\msmult64.exe NtProtectVirtualMemory: Direct from: 0x7FF7603F8A35 Jump to behavior
Source: C:\Users\user\Desktop\msmult64.exe NtCreateFile: Direct from: 0x7FF760191B1C Jump to behavior
Source: C:\Users\user\Desktop\msmult64.exe NtQuerySystemInformation: Direct from: 0x7FF7601913DE Jump to behavior
Source: C:\Users\user\Desktop\msmult64.exe NtDeviceIoControlFile: Direct from: 0x7FF7601ACAF5 Jump to behavior
Source: C:\Users\user\Desktop\msmult64.exe NtProtectVirtualMemory: Direct from: 0x7FF7604C4EA0 Jump to behavior
Source: C:\Users\user\Desktop\msmult64.exe NtReadVirtualMemory: Direct from: 0x7FF7601AB074 Jump to behavior
Source: C:\Users\user\Desktop\msmult64.exe NtRequestWaitReplyPort: Direct from: 0x7FFE221C26A1 Jump to behavior
Source: C:\Users\user\Desktop\msmult64.exe NtProtectVirtualMemory: Direct from: 0x7FF7606D9A3C Jump to behavior
Source: C:\Users\user\Desktop\msmult64.exe NtProtectVirtualMemory: Direct from: 0x7FF76019161B Jump to behavior
Source: C:\Users\user\Desktop\msmult64.exe NtQuerySystemInformation: Direct from: 0x7FF760195449 Jump to behavior
Source: C:\Users\user\Desktop\msmult64.exe NtProtectVirtualMemory: Direct from: 0x7FF760429218 Jump to behavior
Source: C:\Users\user\Desktop\msmult64.exe NtCreateThreadEx: Direct from: 0x7FF7601AFA8D Jump to behavior
Source: C:\Users\user\Desktop\msmult64.exe NtQueryInformationToken: Direct from: 0x7FF760195926 Jump to behavior
Source: C:\Users\user\Desktop\msmult64.exe NtProtectVirtualMemory: Indirect: 0x7FF7603C9D31 Jump to behavior
Source: C:\Users\user\Desktop\msmult64.exe NtProtectVirtualMemory: Direct from: 0x7FF7604A6C06 Jump to behavior
Source: C:\Users\user\Desktop\msmult64.exe NtProtectVirtualMemory: Direct from: 0x7FF76019125B Jump to behavior
Source: C:\Users\user\Desktop\msmult64.exe NtCreateThreadEx: Direct from: 0x7FF7601AC442 Jump to behavior
Source: C:\Users\user\Desktop\msmult64.exe NtProtectVirtualMemory: Direct from: 0x7FF760427F6B Jump to behavior
Source: C:\Users\user\Desktop\msmult64.exe NtProtectVirtualMemory: Direct from: 0x7FF7601AC959 Jump to behavior
Source: C:\Users\user\Desktop\msmult64.exe NtOpenFile: Direct from: 0x7FF7601A90AF Jump to behavior
Source: C:\Users\user\Desktop\msmult64.exe NtSetInformationFile: Direct from: 0x7FF76019D2DF Jump to behavior
Source: C:\Users\user\Desktop\msmult64.exe NtQueryAttributesFile: Direct from: 0x7FF76019D641 Jump to behavior
Source: C:\Users\user\Desktop\msmult64.exe NtAllocateVirtualMemory: Direct from: 0x7FF7601B53CC Jump to behavior
Source: C:\Users\user\Desktop\msmult64.exe NtDeviceIoControlFile: Direct from: 0x7FF7601AE0F1 Jump to behavior
Source: C:\Users\user\Desktop\msmult64.exe NtSetInformationFile: Direct from: 0x7FF76019FFF4 Jump to behavior
Source: C:\Users\user\Desktop\msmult64.exe NtClose: Direct from: 0x7FF7601AB22F
Source: C:\Users\user\Desktop\msmult64.exe NtQuerySystemInformation: Direct from: 0x7FF7601AEEC9 Jump to behavior
Source: C:\Users\user\Desktop\msmult64.exe NtQuerySystemInformation: Direct from: 0x7FF7601AE499 Jump to behavior
Source: C:\Users\user\Desktop\msmult64.exe NtClose: Direct from: 0x7FF7601A9A66
Source: C:\Users\user\Desktop\msmult64.exe NtProtectVirtualMemory: Direct from: 0x7FF760191D08 Jump to behavior
Source: C:\Users\user\Desktop\msmult64.exe NtAllocateVirtualMemory: Direct from: 0x7FF7601AE259 Jump to behavior
Source: C:\Users\user\Desktop\msmult64.exe NtSetInformationFile: Direct from: 0x7FF7601ADE1B Jump to behavior
Source: C:\Users\user\Desktop\msmult64.exe NtProtectVirtualMemory: Direct from: 0x7FF76019184F Jump to behavior
Source: C:\Users\user\Desktop\msmult64.exe NtTerminateThread: Direct from: 0x7FF7601AE415 Jump to behavior
Source: C:\Users\user\Desktop\msmult64.exe NtProtectVirtualMemory: Direct from: 0x7FF7601AC9E6 Jump to behavior
Source: C:\Users\user\Desktop\msmult64.exe NtMapViewOfSection: Direct from: 0x7FF7601AF063 Jump to behavior
Source: C:\Users\user\Desktop\msmult64.exe NtAllocateVirtualMemory: Direct from: 0x7FF7601A99C4 Jump to behavior
Source: C:\Users\user\Desktop\msmult64.exe NtOpenFile: Direct from: 0x7FF7606B0CA7 Jump to behavior
Source: C:\Users\user\Desktop\msmult64.exe NtDelayExecution: Direct from: 0x7FF7601AF860 Jump to behavior
Source: C:\Users\user\Desktop\msmult64.exe NtAllocateVirtualMemory: Direct from: 0x7FF76019D6AD Jump to behavior
Source: C:\Users\user\Desktop\msmult64.exe NtDeviceIoControlFile: Direct from: 0x7FF7601ADDCB Jump to behavior
Source: C:\Users\user\Desktop\msmult64.exe NtDeviceIoControlFile: Direct from: 0x7FF7601AE12E Jump to behavior
Source: C:\Users\user\Desktop\msmult64.exe NtWriteFile: Direct from: 0x7FF7601A8C8D Jump to behavior
Source: C:\Users\user\Desktop\msmult64.exe NtTerminateThread: Direct from: 0x7FF7601AF93D Jump to behavior
Source: C:\Users\user\Desktop\msmult64.exe NtProtectVirtualMemory: Direct from: 0x7FF7601916DF Jump to behavior
Source: C:\Users\user\Desktop\msmult64.exe NtSetInformationFile: Direct from: 0x7FF76019CCFB Jump to behavior
Source: C:\Users\user\Desktop\msmult64.exe NtClose: Direct from: 0x7FF7601A8CA6
Source: C:\Users\user\Desktop\msmult64.exe NtSetInformationFile: Direct from: 0x7FF7601A0A92 Jump to behavior
Source: C:\Users\user\Desktop\msmult64.exe NtAllocateVirtualMemory: Direct from: 0x7FF7601AE36A Jump to behavior
Source: C:\Users\user\Desktop\msmult64.exe NtProtectVirtualMemory: Direct from: 0x7FF760418397 Jump to behavior
Source: C:\Users\user\Desktop\msmult64.exe NtProtectVirtualMemory: Direct from: 0x7FF7601B3F11 Jump to behavior
Source: C:\Users\user\Desktop\msmult64.exe NtQueryInformationToken: Direct from: 0x7FF760195225 Jump to behavior
Source: C:\Users\user\Desktop\msmult64.exe NtClose: Direct from: 0x7FF7601ACA7B
Source: C:\Users\user\Desktop\msmult64.exe NtQueryInformationProcess: Direct from: 0x7FF7601A6E62 Jump to behavior
Source: C:\Users\user\Desktop\msmult64.exe NtReadFile: Direct from: 0x7FF7601A0980 Jump to behavior
Source: C:\Users\user\Desktop\msmult64.exe NtAllocateVirtualMemory: Direct from: 0x7FF7601ADD6A Jump to behavior
Source: C:\Users\user\Desktop\msmult64.exe NtQueryInformationProcess: Direct from: 0x7FF76019C40E Jump to behavior
Source: C:\Users\user\Desktop\msmult64.exe NtSetInformationFile: Direct from: 0x7FF76019D306 Jump to behavior
Source: C:\Users\user\Desktop\msmult64.exe NtProtectVirtualMemory: Direct from: 0x7FF7601AC979 Jump to behavior
Source: C:\Users\user\Desktop\msmult64.exe NtDelayExecution: Direct from: 0x7FF7601AD868 Jump to behavior
Source: C:\Users\user\Desktop\msmult64.exe NtClose: Direct from: 0x7FF7606D5B06
Source: C:\Users\user\Desktop\msmult64.exe NtUnmapViewOfSection: Direct from: 0x7FF760459C6A Jump to behavior
Source: C:\Users\user\Desktop\msmult64.exe NtProtectVirtualMemory: Direct from: 0x7FF760499F6C Jump to behavior
Source: C:\Users\user\Desktop\msmult64.exe NtAllocateVirtualMemory: Direct from: 0x7FF7601B5394 Jump to behavior
Source: C:\Users\user\Desktop\msmult64.exe NtSetInformationThread: Direct from: 0x7FF760195A4B Jump to behavior
Source: C:\Users\user\Desktop\msmult64.exe NtSetInformationFile: Direct from: 0x7FF7601A0504 Jump to behavior
Source: C:\Users\user\Desktop\msmult64.exe NtAllocateVirtualMemory: Direct from: 0x7FF76019C7CF Jump to behavior
Source: C:\Users\user\Desktop\msmult64.exe NtSetInformationFile: Direct from: 0x7FF76019E8CF Jump to behavior
Source: C:\Users\user\Desktop\msmult64.exe NtQueryInformationProcess: Direct from: 0x7FF7601A6EB7 Jump to behavior
Source: C:\Users\user\Desktop\msmult64.exe Code function: 0_2_00007FF7601BFA80 cpuid 0_2_00007FF7601BFA80
Source: C:\Users\user\Desktop\msmult64.exe Queries volume information: C:\Users\user\NTUSER.DAT VolumeInformation Jump to behavior
Source: C:\Users\user\Desktop\msmult64.exe Queries volume information: C:\Users\user\ntuser.dat.LOG1 VolumeInformation Jump to behavior
Source: C:\Users\user\Desktop\msmult64.exe Queries volume information: C:\Users\user\ntuser.dat.LOG2 VolumeInformation Jump to behavior
Source: C:\Users\user\Desktop\msmult64.exe Queries volume information: C:\Users\user\NTUSER.DAT{53b39e88-18c4-11ea-a811-000d3aa4692b}.TM.blf VolumeInformation Jump to behavior
Source: C:\Users\user\Desktop\msmult64.exe Queries volume information: C:\Users\user\NTUSER.DAT{53b39e88-18c4-11ea-a811-000d3aa4692b}.TMContainer00000000000000000001.regtrans-ms VolumeInformation Jump to behavior
Source: C:\Users\user\Desktop\msmult64.exe Queries volume information: C:\Users\user\AppData\Local\ConnectedDevicesPlatform\L.user\ActivitiesCache.db VolumeInformation Jump to behavior
Source: C:\Users\user\Desktop\msmult64.exe Queries volume information: C:\Users\user\AppData\Local\Microsoft\GameDVR\KnownGameList.bin VolumeInformation Jump to behavior
Source: C:\Users\user\Desktop\msmult64.exe Key value queried: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Cryptography MachineGuid Jump to behavior
Source: C:\Users\user\Desktop\msmult64.exe Code function: 0_2_00007FF7601ADC90 WSASocketW,bind,CreateIoCompletionPort, 0_2_00007FF7601ADC90
  • No. of IPs < 25%
  • 25% < No. of IPs < 50%
  • 50% < No. of IPs < 75%
  • 75% < No. of IPs