Library
My library

+ Add to library

Contact us
24/7 Tech support | Rules regarding submitting

Send a message

Your tickets

Profile

Trojan.DownLoader35.24129

Added to the Dr.Web virus database: 2020-11-09

Virus description added:

Technical Information

Malicious functions
Injects code into
the following system processes:
  • %WINDIR%\explorer.exe
Modifies file system
Creates the following files
  • %APPDATA%\microsoft\crypto\rsa\s-1-5-21-1960123792-2022915161-3775307078-1001\5a5576fbff9a4fbd83e6342ef46a9424_36d1130a-ac2e-44f7-9dc1-e424fbcbe0ee
  • %APPDATA%\microsoft\crypto\rsa\s-1-5-21-1960123792-2022915161-3775307078-1001\42f0cdf14a03ca1c1bd2b13defb1224a_36d1130a-ac2e-44f7-9dc1-e424fbcbe0ee
  • %APPDATA%\microsoft\crypto\rsa\s-1-5-21-1960123792-2022915161-3775307078-1001\d51383d57eb231f122f2d90959f0c31c_36d1130a-ac2e-44f7-9dc1-e424fbcbe0ee
  • %APPDATA%\microsoft\crypto\rsa\s-1-5-21-1960123792-2022915161-3775307078-1001\bde9322df0ebbc7fb5fc297c937b3ce3_36d1130a-ac2e-44f7-9dc1-e424fbcbe0ee
  • %APPDATA%\microsoft\crypto\rsa\s-1-5-21-1960123792-2022915161-3775307078-1001\bd408bd383153274ca47263325dd021a_36d1130a-ac2e-44f7-9dc1-e424fbcbe0ee
  • %APPDATA%\microsoft\crypto\rsa\s-1-5-21-1960123792-2022915161-3775307078-1001\b07b1d146809216d3e9fff1b602ca4ec_36d1130a-ac2e-44f7-9dc1-e424fbcbe0ee
  • %APPDATA%\microsoft\crypto\rsa\s-1-5-21-1960123792-2022915161-3775307078-1001\ce61b2bf44d00278a27e013a2341fc9c_36d1130a-ac2e-44f7-9dc1-e424fbcbe0ee
  • %APPDATA%\microsoft\crypto\rsa\s-1-5-21-1960123792-2022915161-3775307078-1001\80583f7c04cdbdc0670f82f777730ba5_36d1130a-ac2e-44f7-9dc1-e424fbcbe0ee
  • %APPDATA%\microsoft\crypto\rsa\s-1-5-21-1960123792-2022915161-3775307078-1001\1470ae0c93c0bfeb2baeeb37407d8250_36d1130a-ac2e-44f7-9dc1-e424fbcbe0ee
  • %APPDATA%\microsoft\crypto\rsa\s-1-5-21-1960123792-2022915161-3775307078-1001\e6b6833874d73a9f4bab579ce1a23943_36d1130a-ac2e-44f7-9dc1-e424fbcbe0ee
  • %APPDATA%\microsoft\crypto\rsa\s-1-5-21-1960123792-2022915161-3775307078-1001\49ce93a7cd33024279eff67b4c318ba3_36d1130a-ac2e-44f7-9dc1-e424fbcbe0ee
  • %APPDATA%\microsoft\crypto\rsa\s-1-5-21-1960123792-2022915161-3775307078-1001\b4cf01aaeb134c6318676513788b6121_36d1130a-ac2e-44f7-9dc1-e424fbcbe0ee
  • %APPDATA%\microsoft\crypto\rsa\s-1-5-21-1960123792-2022915161-3775307078-1001\217212d3bde8ff9a43e3d583b2f1e9c1_36d1130a-ac2e-44f7-9dc1-e424fbcbe0ee
  • %APPDATA%\microsoft\crypto\rsa\s-1-5-21-1960123792-2022915161-3775307078-1001\641cd38e65540bde622c4743b17e5a30_36d1130a-ac2e-44f7-9dc1-e424fbcbe0ee
  • %APPDATA%\microsoft\crypto\rsa\s-1-5-21-1960123792-2022915161-3775307078-1001\1f493bba4bfd0f9057eaafd8dc5b1c71_36d1130a-ac2e-44f7-9dc1-e424fbcbe0ee
  • %APPDATA%\microsoft\crypto\rsa\s-1-5-21-1960123792-2022915161-3775307078-1001\b4fee537d4dbaced47ee3ac14286a4d9_36d1130a-ac2e-44f7-9dc1-e424fbcbe0ee
  • %APPDATA%\microsoft\crypto\rsa\s-1-5-21-1960123792-2022915161-3775307078-1001\4650ee640a729648545986638d726eb7_36d1130a-ac2e-44f7-9dc1-e424fbcbe0ee
  • %APPDATA%\microsoft\crypto\rsa\s-1-5-21-1960123792-2022915161-3775307078-1001\17ee256a01a0fabe6549388098d15dea_36d1130a-ac2e-44f7-9dc1-e424fbcbe0ee
  • %APPDATA%\microsoft\crypto\rsa\s-1-5-21-1960123792-2022915161-3775307078-1001\c2bbb85100d9b6e382c2d8229d8ff91f_36d1130a-ac2e-44f7-9dc1-e424fbcbe0ee
  • %APPDATA%\microsoft\crypto\rsa\s-1-5-21-1960123792-2022915161-3775307078-1001\c8555fb9a84f48ac291d794a1ebb6537_36d1130a-ac2e-44f7-9dc1-e424fbcbe0ee
  • %APPDATA%\microsoft\crypto\rsa\s-1-5-21-1960123792-2022915161-3775307078-1001\9e4fe279ebb8295aa8d7238d61aec06e_36d1130a-ac2e-44f7-9dc1-e424fbcbe0ee
  • %APPDATA%\microsoft\crypto\rsa\s-1-5-21-1960123792-2022915161-3775307078-1001\82eb5d8faaf6e6883c282726d794dc7b_36d1130a-ac2e-44f7-9dc1-e424fbcbe0ee
  • %APPDATA%\microsoft\crypto\rsa\s-1-5-21-1960123792-2022915161-3775307078-1001\8216c72ddfdb718ce5aab1603fd3c376_36d1130a-ac2e-44f7-9dc1-e424fbcbe0ee
  • %APPDATA%\microsoft\crypto\rsa\s-1-5-21-1960123792-2022915161-3775307078-1001\fd4772a4d2a80658f2c2c8f36470e11a_36d1130a-ac2e-44f7-9dc1-e424fbcbe0ee
  • %APPDATA%\microsoft\crypto\rsa\s-1-5-21-1960123792-2022915161-3775307078-1001\538c4a27d6748339f50c0f05e0a5c152_36d1130a-ac2e-44f7-9dc1-e424fbcbe0ee
  • %APPDATA%\microsoft\crypto\rsa\s-1-5-21-1960123792-2022915161-3775307078-1001\e588bebddb58cde95a9efa05543b6ddc_36d1130a-ac2e-44f7-9dc1-e424fbcbe0ee
  • %APPDATA%\microsoft\crypto\rsa\s-1-5-21-1960123792-2022915161-3775307078-1001\ce0606f0ef6c267dc6de32370db6eb4a_36d1130a-ac2e-44f7-9dc1-e424fbcbe0ee
  • %APPDATA%\microsoft\crypto\rsa\s-1-5-21-1960123792-2022915161-3775307078-1001\177293062eae97a81df34c23ab59bc47_36d1130a-ac2e-44f7-9dc1-e424fbcbe0ee
  • %APPDATA%\microsoft\crypto\rsa\s-1-5-21-1960123792-2022915161-3775307078-1001\851a0986a15ea034f1980c7f72ac0497_36d1130a-ac2e-44f7-9dc1-e424fbcbe0ee
  • %APPDATA%\microsoft\crypto\rsa\s-1-5-21-1960123792-2022915161-3775307078-1001\db631343ccf79521d4518d7e72116a7f_36d1130a-ac2e-44f7-9dc1-e424fbcbe0ee
  • %APPDATA%\microsoft\crypto\rsa\s-1-5-21-1960123792-2022915161-3775307078-1001\d1b7457c5c701ab542206814fcf01f60_36d1130a-ac2e-44f7-9dc1-e424fbcbe0ee
  • %APPDATA%\microsoft\crypto\rsa\s-1-5-21-1960123792-2022915161-3775307078-1001\d53f6c9967600a6702e23503a2d99c37_36d1130a-ac2e-44f7-9dc1-e424fbcbe0ee
  • %APPDATA%\microsoft\crypto\rsa\s-1-5-21-1960123792-2022915161-3775307078-1001\ac35a38a2cc9ef3bb7ffc5bd84b50645_36d1130a-ac2e-44f7-9dc1-e424fbcbe0ee
  • %APPDATA%\microsoft\crypto\rsa\s-1-5-21-1960123792-2022915161-3775307078-1001\24b645a5a7436f898d29cd4f52765245_36d1130a-ac2e-44f7-9dc1-e424fbcbe0ee
  • %APPDATA%\microsoft\crypto\rsa\s-1-5-21-1960123792-2022915161-3775307078-1001\5ab02ea35afa57db3a814a3ba9ac4ca7_36d1130a-ac2e-44f7-9dc1-e424fbcbe0ee
  • %APPDATA%\microsoft\crypto\rsa\s-1-5-21-1960123792-2022915161-3775307078-1001\8269cbd6e3338e5f72259ec4f09bb845_36d1130a-ac2e-44f7-9dc1-e424fbcbe0ee
  • %APPDATA%\microsoft\crypto\rsa\s-1-5-21-1960123792-2022915161-3775307078-1001\3a964b8437f11722263709b7467a42ae_36d1130a-ac2e-44f7-9dc1-e424fbcbe0ee
  • %APPDATA%\microsoft\crypto\rsa\s-1-5-21-1960123792-2022915161-3775307078-1001\700988e44c96ef046e08087155c8ecba_36d1130a-ac2e-44f7-9dc1-e424fbcbe0ee
  • %APPDATA%\microsoft\crypto\rsa\s-1-5-21-1960123792-2022915161-3775307078-1001\6120c49940eec33a89958f25726cb2d1_36d1130a-ac2e-44f7-9dc1-e424fbcbe0ee
  • %APPDATA%\microsoft\crypto\rsa\s-1-5-21-1960123792-2022915161-3775307078-1001\b4f66dafa79b572f224b836dc9ff664d_36d1130a-ac2e-44f7-9dc1-e424fbcbe0ee
  • %APPDATA%\microsoft\crypto\rsa\s-1-5-21-1960123792-2022915161-3775307078-1001\329813d1b108120bd4836197162d1b64_36d1130a-ac2e-44f7-9dc1-e424fbcbe0ee
  • %APPDATA%\microsoft\crypto\rsa\s-1-5-21-1960123792-2022915161-3775307078-1001\b9b5dbd91c722dff090a675a0b5304ba_36d1130a-ac2e-44f7-9dc1-e424fbcbe0ee
  • %APPDATA%\microsoft\crypto\rsa\s-1-5-21-1960123792-2022915161-3775307078-1001\13118caa8f1e1620dd8f917bd1568ed5_36d1130a-ac2e-44f7-9dc1-e424fbcbe0ee
  • %APPDATA%\microsoft\crypto\rsa\s-1-5-21-1960123792-2022915161-3775307078-1001\58e8ad7a1a0b65903c1d4fcd2b11f1b1_36d1130a-ac2e-44f7-9dc1-e424fbcbe0ee
  • %APPDATA%\microsoft\crypto\rsa\s-1-5-21-1960123792-2022915161-3775307078-1001\9e26880796e16dd6bacb057ee22c7390_36d1130a-ac2e-44f7-9dc1-e424fbcbe0ee
  • %APPDATA%\microsoft\crypto\rsa\s-1-5-21-1960123792-2022915161-3775307078-1001\b40a25edbebfa566637c804ac4c06542_36d1130a-ac2e-44f7-9dc1-e424fbcbe0ee
  • %APPDATA%\microsoft\crypto\rsa\s-1-5-21-1960123792-2022915161-3775307078-1001\3980bbe983c7d9c69c30075a212da264_36d1130a-ac2e-44f7-9dc1-e424fbcbe0ee
  • %APPDATA%\microsoft\crypto\rsa\s-1-5-21-1960123792-2022915161-3775307078-1001\cef1e6adc84d8009fa14a376faea9c48_36d1130a-ac2e-44f7-9dc1-e424fbcbe0ee
  • %APPDATA%\microsoft\crypto\rsa\s-1-5-21-1960123792-2022915161-3775307078-1001\c9b7b02a630305f4f6f1ef0efb5e6bd5_36d1130a-ac2e-44f7-9dc1-e424fbcbe0ee
  • %APPDATA%\microsoft\crypto\rsa\s-1-5-21-1960123792-2022915161-3775307078-1001\79809309724c1d17d898bfb272b024b3_36d1130a-ac2e-44f7-9dc1-e424fbcbe0ee
  • %APPDATA%\microsoft\crypto\rsa\s-1-5-21-1960123792-2022915161-3775307078-1001\cb241b44f62c4afb82a5707dbdfa2213_36d1130a-ac2e-44f7-9dc1-e424fbcbe0ee
  • %APPDATA%\microsoft\crypto\rsa\s-1-5-21-1960123792-2022915161-3775307078-1001\9c3ea6cde76be28c7137c8d5637d3c9c_36d1130a-ac2e-44f7-9dc1-e424fbcbe0ee
  • %APPDATA%\microsoft\crypto\rsa\s-1-5-21-1960123792-2022915161-3775307078-1001\c3a06d938f3a6a15577749d4edbf291a_36d1130a-ac2e-44f7-9dc1-e424fbcbe0ee
  • %APPDATA%\microsoft\crypto\rsa\s-1-5-21-1960123792-2022915161-3775307078-1001\46a2d3b603ff76d7b5bc124ab5211c9f_36d1130a-ac2e-44f7-9dc1-e424fbcbe0ee
  • %APPDATA%\microsoft\crypto\rsa\s-1-5-21-1960123792-2022915161-3775307078-1001\19a2d92202d7b42ae233427b6f8aa4ce_36d1130a-ac2e-44f7-9dc1-e424fbcbe0ee
  • %APPDATA%\microsoft\crypto\rsa\s-1-5-21-1960123792-2022915161-3775307078-1001\a4e8100a8065688fa91efc10d2d905fb_36d1130a-ac2e-44f7-9dc1-e424fbcbe0ee
  • %APPDATA%\microsoft\crypto\rsa\s-1-5-21-1960123792-2022915161-3775307078-1001\8ef40e60aea3bab9ddd99c2a52146379_36d1130a-ac2e-44f7-9dc1-e424fbcbe0ee
  • %APPDATA%\microsoft\crypto\rsa\s-1-5-21-1960123792-2022915161-3775307078-1001\ed2043322cd173f78dc2bd81489b86b8_36d1130a-ac2e-44f7-9dc1-e424fbcbe0ee
  • %APPDATA%\microsoft\crypto\rsa\s-1-5-21-1960123792-2022915161-3775307078-1001\da1810ebeff101d0ef2bae096c3fdac8_36d1130a-ac2e-44f7-9dc1-e424fbcbe0ee
  • %APPDATA%\microsoft\crypto\rsa\s-1-5-21-1960123792-2022915161-3775307078-1001\e4dc7f7f8ec06e30c9f863c84a50ff28_36d1130a-ac2e-44f7-9dc1-e424fbcbe0ee
  • %APPDATA%\microsoft\crypto\rsa\s-1-5-21-1960123792-2022915161-3775307078-1001\aaa778c87cc805dac078cd5de8afa8a0_36d1130a-ac2e-44f7-9dc1-e424fbcbe0ee
  • %APPDATA%\microsoft\crypto\rsa\s-1-5-21-1960123792-2022915161-3775307078-1001\2a549706f94dc8daf539045f12971eea_36d1130a-ac2e-44f7-9dc1-e424fbcbe0ee
  • %APPDATA%\microsoft\crypto\rsa\s-1-5-21-1960123792-2022915161-3775307078-1001\1bd5caa95c4f1d71cb1b86a1a3a7f8eb_36d1130a-ac2e-44f7-9dc1-e424fbcbe0ee
  • %APPDATA%\microsoft\crypto\rsa\s-1-5-21-1960123792-2022915161-3775307078-1001\f49d01c35743f2fb87edb526a6653b9d_36d1130a-ac2e-44f7-9dc1-e424fbcbe0ee
  • %APPDATA%\microsoft\crypto\rsa\s-1-5-21-1960123792-2022915161-3775307078-1001\ee07ec298018436a7db17f9af4ac9ab6_36d1130a-ac2e-44f7-9dc1-e424fbcbe0ee
  • %APPDATA%\microsoft\crypto\rsa\s-1-5-21-1960123792-2022915161-3775307078-1001\401905c7781143efbe36070ded2afe91_36d1130a-ac2e-44f7-9dc1-e424fbcbe0ee
  • %APPDATA%\microsoft\crypto\rsa\s-1-5-21-1960123792-2022915161-3775307078-1001\cf083d78f794f42bb178d505d285a0f0_36d1130a-ac2e-44f7-9dc1-e424fbcbe0ee
  • %APPDATA%\microsoft\crypto\rsa\s-1-5-21-1960123792-2022915161-3775307078-1001\b50f3256f70496708c502df4f2a6f61d_36d1130a-ac2e-44f7-9dc1-e424fbcbe0ee
  • %APPDATA%\microsoft\crypto\rsa\s-1-5-21-1960123792-2022915161-3775307078-1001\568e91ae35c5fedcd4b9ead7247c600c_36d1130a-ac2e-44f7-9dc1-e424fbcbe0ee
Deletes the following files
  • %APPDATA%\microsoft\crypto\rsa\s-1-5-21-1960123792-2022915161-3775307078-1001\5a5576fbff9a4fbd83e6342ef46a9424_36d1130a-ac2e-44f7-9dc1-e424fbcbe0ee
  • %APPDATA%\microsoft\crypto\rsa\s-1-5-21-1960123792-2022915161-3775307078-1001\42f0cdf14a03ca1c1bd2b13defb1224a_36d1130a-ac2e-44f7-9dc1-e424fbcbe0ee
  • %APPDATA%\microsoft\crypto\rsa\s-1-5-21-1960123792-2022915161-3775307078-1001\d51383d57eb231f122f2d90959f0c31c_36d1130a-ac2e-44f7-9dc1-e424fbcbe0ee
  • %APPDATA%\microsoft\crypto\rsa\s-1-5-21-1960123792-2022915161-3775307078-1001\bde9322df0ebbc7fb5fc297c937b3ce3_36d1130a-ac2e-44f7-9dc1-e424fbcbe0ee
  • %APPDATA%\microsoft\crypto\rsa\s-1-5-21-1960123792-2022915161-3775307078-1001\bd408bd383153274ca47263325dd021a_36d1130a-ac2e-44f7-9dc1-e424fbcbe0ee
  • %APPDATA%\microsoft\crypto\rsa\s-1-5-21-1960123792-2022915161-3775307078-1001\b07b1d146809216d3e9fff1b602ca4ec_36d1130a-ac2e-44f7-9dc1-e424fbcbe0ee
  • %APPDATA%\microsoft\crypto\rsa\s-1-5-21-1960123792-2022915161-3775307078-1001\ce61b2bf44d00278a27e013a2341fc9c_36d1130a-ac2e-44f7-9dc1-e424fbcbe0ee
  • %APPDATA%\microsoft\crypto\rsa\s-1-5-21-1960123792-2022915161-3775307078-1001\80583f7c04cdbdc0670f82f777730ba5_36d1130a-ac2e-44f7-9dc1-e424fbcbe0ee
  • %APPDATA%\microsoft\crypto\rsa\s-1-5-21-1960123792-2022915161-3775307078-1001\1470ae0c93c0bfeb2baeeb37407d8250_36d1130a-ac2e-44f7-9dc1-e424fbcbe0ee
  • %APPDATA%\microsoft\crypto\rsa\s-1-5-21-1960123792-2022915161-3775307078-1001\e6b6833874d73a9f4bab579ce1a23943_36d1130a-ac2e-44f7-9dc1-e424fbcbe0ee
  • %APPDATA%\microsoft\crypto\rsa\s-1-5-21-1960123792-2022915161-3775307078-1001\49ce93a7cd33024279eff67b4c318ba3_36d1130a-ac2e-44f7-9dc1-e424fbcbe0ee
  • %APPDATA%\microsoft\crypto\rsa\s-1-5-21-1960123792-2022915161-3775307078-1001\b4cf01aaeb134c6318676513788b6121_36d1130a-ac2e-44f7-9dc1-e424fbcbe0ee
  • %APPDATA%\microsoft\crypto\rsa\s-1-5-21-1960123792-2022915161-3775307078-1001\217212d3bde8ff9a43e3d583b2f1e9c1_36d1130a-ac2e-44f7-9dc1-e424fbcbe0ee
  • %APPDATA%\microsoft\crypto\rsa\s-1-5-21-1960123792-2022915161-3775307078-1001\641cd38e65540bde622c4743b17e5a30_36d1130a-ac2e-44f7-9dc1-e424fbcbe0ee
  • %APPDATA%\microsoft\crypto\rsa\s-1-5-21-1960123792-2022915161-3775307078-1001\1f493bba4bfd0f9057eaafd8dc5b1c71_36d1130a-ac2e-44f7-9dc1-e424fbcbe0ee
  • %APPDATA%\microsoft\crypto\rsa\s-1-5-21-1960123792-2022915161-3775307078-1001\b4fee537d4dbaced47ee3ac14286a4d9_36d1130a-ac2e-44f7-9dc1-e424fbcbe0ee
  • %APPDATA%\microsoft\crypto\rsa\s-1-5-21-1960123792-2022915161-3775307078-1001\4650ee640a729648545986638d726eb7_36d1130a-ac2e-44f7-9dc1-e424fbcbe0ee
  • %APPDATA%\microsoft\crypto\rsa\s-1-5-21-1960123792-2022915161-3775307078-1001\17ee256a01a0fabe6549388098d15dea_36d1130a-ac2e-44f7-9dc1-e424fbcbe0ee
  • %APPDATA%\microsoft\crypto\rsa\s-1-5-21-1960123792-2022915161-3775307078-1001\c2bbb85100d9b6e382c2d8229d8ff91f_36d1130a-ac2e-44f7-9dc1-e424fbcbe0ee
  • %APPDATA%\microsoft\crypto\rsa\s-1-5-21-1960123792-2022915161-3775307078-1001\c8555fb9a84f48ac291d794a1ebb6537_36d1130a-ac2e-44f7-9dc1-e424fbcbe0ee
  • %APPDATA%\microsoft\crypto\rsa\s-1-5-21-1960123792-2022915161-3775307078-1001\9e4fe279ebb8295aa8d7238d61aec06e_36d1130a-ac2e-44f7-9dc1-e424fbcbe0ee
  • %APPDATA%\microsoft\crypto\rsa\s-1-5-21-1960123792-2022915161-3775307078-1001\82eb5d8faaf6e6883c282726d794dc7b_36d1130a-ac2e-44f7-9dc1-e424fbcbe0ee
  • %APPDATA%\microsoft\crypto\rsa\s-1-5-21-1960123792-2022915161-3775307078-1001\8216c72ddfdb718ce5aab1603fd3c376_36d1130a-ac2e-44f7-9dc1-e424fbcbe0ee
  • %APPDATA%\microsoft\crypto\rsa\s-1-5-21-1960123792-2022915161-3775307078-1001\fd4772a4d2a80658f2c2c8f36470e11a_36d1130a-ac2e-44f7-9dc1-e424fbcbe0ee
  • %APPDATA%\microsoft\crypto\rsa\s-1-5-21-1960123792-2022915161-3775307078-1001\538c4a27d6748339f50c0f05e0a5c152_36d1130a-ac2e-44f7-9dc1-e424fbcbe0ee
  • %APPDATA%\microsoft\crypto\rsa\s-1-5-21-1960123792-2022915161-3775307078-1001\e588bebddb58cde95a9efa05543b6ddc_36d1130a-ac2e-44f7-9dc1-e424fbcbe0ee
  • %APPDATA%\microsoft\crypto\rsa\s-1-5-21-1960123792-2022915161-3775307078-1001\ce0606f0ef6c267dc6de32370db6eb4a_36d1130a-ac2e-44f7-9dc1-e424fbcbe0ee
  • %APPDATA%\microsoft\crypto\rsa\s-1-5-21-1960123792-2022915161-3775307078-1001\177293062eae97a81df34c23ab59bc47_36d1130a-ac2e-44f7-9dc1-e424fbcbe0ee
  • %APPDATA%\microsoft\crypto\rsa\s-1-5-21-1960123792-2022915161-3775307078-1001\851a0986a15ea034f1980c7f72ac0497_36d1130a-ac2e-44f7-9dc1-e424fbcbe0ee
  • %APPDATA%\microsoft\crypto\rsa\s-1-5-21-1960123792-2022915161-3775307078-1001\db631343ccf79521d4518d7e72116a7f_36d1130a-ac2e-44f7-9dc1-e424fbcbe0ee
  • %APPDATA%\microsoft\crypto\rsa\s-1-5-21-1960123792-2022915161-3775307078-1001\d1b7457c5c701ab542206814fcf01f60_36d1130a-ac2e-44f7-9dc1-e424fbcbe0ee
  • %APPDATA%\microsoft\crypto\rsa\s-1-5-21-1960123792-2022915161-3775307078-1001\d53f6c9967600a6702e23503a2d99c37_36d1130a-ac2e-44f7-9dc1-e424fbcbe0ee
  • %APPDATA%\microsoft\crypto\rsa\s-1-5-21-1960123792-2022915161-3775307078-1001\ac35a38a2cc9ef3bb7ffc5bd84b50645_36d1130a-ac2e-44f7-9dc1-e424fbcbe0ee
  • %APPDATA%\microsoft\crypto\rsa\s-1-5-21-1960123792-2022915161-3775307078-1001\24b645a5a7436f898d29cd4f52765245_36d1130a-ac2e-44f7-9dc1-e424fbcbe0ee
  • %APPDATA%\microsoft\crypto\rsa\s-1-5-21-1960123792-2022915161-3775307078-1001\5ab02ea35afa57db3a814a3ba9ac4ca7_36d1130a-ac2e-44f7-9dc1-e424fbcbe0ee
  • %APPDATA%\microsoft\crypto\rsa\s-1-5-21-1960123792-2022915161-3775307078-1001\8269cbd6e3338e5f72259ec4f09bb845_36d1130a-ac2e-44f7-9dc1-e424fbcbe0ee
  • %APPDATA%\microsoft\crypto\rsa\s-1-5-21-1960123792-2022915161-3775307078-1001\3a964b8437f11722263709b7467a42ae_36d1130a-ac2e-44f7-9dc1-e424fbcbe0ee
  • %APPDATA%\microsoft\crypto\rsa\s-1-5-21-1960123792-2022915161-3775307078-1001\700988e44c96ef046e08087155c8ecba_36d1130a-ac2e-44f7-9dc1-e424fbcbe0ee
  • %APPDATA%\microsoft\crypto\rsa\s-1-5-21-1960123792-2022915161-3775307078-1001\6120c49940eec33a89958f25726cb2d1_36d1130a-ac2e-44f7-9dc1-e424fbcbe0ee
  • %APPDATA%\microsoft\crypto\rsa\s-1-5-21-1960123792-2022915161-3775307078-1001\b4f66dafa79b572f224b836dc9ff664d_36d1130a-ac2e-44f7-9dc1-e424fbcbe0ee
  • %APPDATA%\microsoft\crypto\rsa\s-1-5-21-1960123792-2022915161-3775307078-1001\329813d1b108120bd4836197162d1b64_36d1130a-ac2e-44f7-9dc1-e424fbcbe0ee
  • %APPDATA%\microsoft\crypto\rsa\s-1-5-21-1960123792-2022915161-3775307078-1001\b9b5dbd91c722dff090a675a0b5304ba_36d1130a-ac2e-44f7-9dc1-e424fbcbe0ee
  • %APPDATA%\microsoft\crypto\rsa\s-1-5-21-1960123792-2022915161-3775307078-1001\13118caa8f1e1620dd8f917bd1568ed5_36d1130a-ac2e-44f7-9dc1-e424fbcbe0ee
  • %APPDATA%\microsoft\crypto\rsa\s-1-5-21-1960123792-2022915161-3775307078-1001\58e8ad7a1a0b65903c1d4fcd2b11f1b1_36d1130a-ac2e-44f7-9dc1-e424fbcbe0ee
  • %APPDATA%\microsoft\crypto\rsa\s-1-5-21-1960123792-2022915161-3775307078-1001\9e26880796e16dd6bacb057ee22c7390_36d1130a-ac2e-44f7-9dc1-e424fbcbe0ee
  • %APPDATA%\microsoft\crypto\rsa\s-1-5-21-1960123792-2022915161-3775307078-1001\b40a25edbebfa566637c804ac4c06542_36d1130a-ac2e-44f7-9dc1-e424fbcbe0ee
  • %APPDATA%\microsoft\crypto\rsa\s-1-5-21-1960123792-2022915161-3775307078-1001\3980bbe983c7d9c69c30075a212da264_36d1130a-ac2e-44f7-9dc1-e424fbcbe0ee
  • %APPDATA%\microsoft\crypto\rsa\s-1-5-21-1960123792-2022915161-3775307078-1001\cef1e6adc84d8009fa14a376faea9c48_36d1130a-ac2e-44f7-9dc1-e424fbcbe0ee
  • %APPDATA%\microsoft\crypto\rsa\s-1-5-21-1960123792-2022915161-3775307078-1001\c9b7b02a630305f4f6f1ef0efb5e6bd5_36d1130a-ac2e-44f7-9dc1-e424fbcbe0ee
  • %APPDATA%\microsoft\crypto\rsa\s-1-5-21-1960123792-2022915161-3775307078-1001\79809309724c1d17d898bfb272b024b3_36d1130a-ac2e-44f7-9dc1-e424fbcbe0ee
  • %APPDATA%\microsoft\crypto\rsa\s-1-5-21-1960123792-2022915161-3775307078-1001\cb241b44f62c4afb82a5707dbdfa2213_36d1130a-ac2e-44f7-9dc1-e424fbcbe0ee
  • %APPDATA%\microsoft\crypto\rsa\s-1-5-21-1960123792-2022915161-3775307078-1001\9c3ea6cde76be28c7137c8d5637d3c9c_36d1130a-ac2e-44f7-9dc1-e424fbcbe0ee
  • %APPDATA%\microsoft\crypto\rsa\s-1-5-21-1960123792-2022915161-3775307078-1001\c3a06d938f3a6a15577749d4edbf291a_36d1130a-ac2e-44f7-9dc1-e424fbcbe0ee
  • %APPDATA%\microsoft\crypto\rsa\s-1-5-21-1960123792-2022915161-3775307078-1001\46a2d3b603ff76d7b5bc124ab5211c9f_36d1130a-ac2e-44f7-9dc1-e424fbcbe0ee
  • %APPDATA%\microsoft\crypto\rsa\s-1-5-21-1960123792-2022915161-3775307078-1001\19a2d92202d7b42ae233427b6f8aa4ce_36d1130a-ac2e-44f7-9dc1-e424fbcbe0ee
  • %APPDATA%\microsoft\crypto\rsa\s-1-5-21-1960123792-2022915161-3775307078-1001\a4e8100a8065688fa91efc10d2d905fb_36d1130a-ac2e-44f7-9dc1-e424fbcbe0ee
  • %APPDATA%\microsoft\crypto\rsa\s-1-5-21-1960123792-2022915161-3775307078-1001\8ef40e60aea3bab9ddd99c2a52146379_36d1130a-ac2e-44f7-9dc1-e424fbcbe0ee
  • %APPDATA%\microsoft\crypto\rsa\s-1-5-21-1960123792-2022915161-3775307078-1001\ed2043322cd173f78dc2bd81489b86b8_36d1130a-ac2e-44f7-9dc1-e424fbcbe0ee
  • %APPDATA%\microsoft\crypto\rsa\s-1-5-21-1960123792-2022915161-3775307078-1001\da1810ebeff101d0ef2bae096c3fdac8_36d1130a-ac2e-44f7-9dc1-e424fbcbe0ee
  • %APPDATA%\microsoft\crypto\rsa\s-1-5-21-1960123792-2022915161-3775307078-1001\e4dc7f7f8ec06e30c9f863c84a50ff28_36d1130a-ac2e-44f7-9dc1-e424fbcbe0ee
  • %APPDATA%\microsoft\crypto\rsa\s-1-5-21-1960123792-2022915161-3775307078-1001\aaa778c87cc805dac078cd5de8afa8a0_36d1130a-ac2e-44f7-9dc1-e424fbcbe0ee
  • %APPDATA%\microsoft\crypto\rsa\s-1-5-21-1960123792-2022915161-3775307078-1001\2a549706f94dc8daf539045f12971eea_36d1130a-ac2e-44f7-9dc1-e424fbcbe0ee
  • %APPDATA%\microsoft\crypto\rsa\s-1-5-21-1960123792-2022915161-3775307078-1001\1bd5caa95c4f1d71cb1b86a1a3a7f8eb_36d1130a-ac2e-44f7-9dc1-e424fbcbe0ee
  • %APPDATA%\microsoft\crypto\rsa\s-1-5-21-1960123792-2022915161-3775307078-1001\f49d01c35743f2fb87edb526a6653b9d_36d1130a-ac2e-44f7-9dc1-e424fbcbe0ee
  • %APPDATA%\microsoft\crypto\rsa\s-1-5-21-1960123792-2022915161-3775307078-1001\ee07ec298018436a7db17f9af4ac9ab6_36d1130a-ac2e-44f7-9dc1-e424fbcbe0ee
  • %APPDATA%\microsoft\crypto\rsa\s-1-5-21-1960123792-2022915161-3775307078-1001\401905c7781143efbe36070ded2afe91_36d1130a-ac2e-44f7-9dc1-e424fbcbe0ee
  • %APPDATA%\microsoft\crypto\rsa\s-1-5-21-1960123792-2022915161-3775307078-1001\cf083d78f794f42bb178d505d285a0f0_36d1130a-ac2e-44f7-9dc1-e424fbcbe0ee
  • %APPDATA%\microsoft\crypto\rsa\s-1-5-21-1960123792-2022915161-3775307078-1001\b50f3256f70496708c502df4f2a6f61d_36d1130a-ac2e-44f7-9dc1-e424fbcbe0ee
  • %APPDATA%\microsoft\crypto\rsa\s-1-5-21-1960123792-2022915161-3775307078-1001\568e91ae35c5fedcd4b9ead7247c600c_36d1130a-ac2e-44f7-9dc1-e424fbcbe0ee
Network activity
TCP
HTTP GET requests
  • http://to##-co.jp/Payload.jpg
  • http://www.to####ger.online/g832/?UL############################################################################################
  • http://www.am###ech.com/g832/?UL############################################################################################
  • http://www.ma###ofcs.com/g832/?UL############################################################################################
  • http://www.gr###lextv.com/g832/?UL############################################################################################
UDP
  • DNS ASK google.com
  • DNS ASK to##-co.jp
  • DNS ASK to####ger.online
  • DNS ASK am###ech.com
  • DNS ASK ma###ofcs.com
  • DNS ASK gr###lextv.com
Miscellaneous
Creates and executes the following
  • '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' $qazthnwsxtgbedcrfvqwertyasdfgh=@(91,82,117,110,116,105,109,101,46,73,110,116,101,114,111,112,83,101,114,118,105,99,101,115,46,77,97,114,115,104,97,108,93,58,58,87,114,105,116,101,73,110,116,51...' (with hidden window)
Executes the following
  • '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' $qazthnwsxtgbedcrfvqwertyasdfgh=@(91,82,117,110,116,105,109,101,46,73,110,116,101,114,111,112,83,101,114,118,105,99,101,115,46,77,97,114,115,104,97,108,93,58,58,87,114,105,116,101,73,110,116,51...
  • '%WINDIR%\syswow64\control.exe'
  • '%WINDIR%\syswow64\msiexec.exe'
  • '%WINDIR%\syswow64\cmd.exe' del "%WINDIR%\syswow64\control.exe"

Curing recommendations

  1. If the operating system (OS) can be loaded (either normally or in safe mode), download Dr.Web Security Space and run a full scan of your computer and removable media you use. More about Dr.Web Security Space.
  2. If you cannot boot the OS, change the BIOS settings to boot your system from a CD or USB drive. Download the image of the emergency system repair disk Dr.Web® LiveDisk , mount it on a USB drive or burn it to a CD/DVD. After booting up with this media, run a full scan and cure all the detected threats.
Download Dr.Web

Download by serial number

Use Dr.Web Anti-virus for macOS to run a full scan of your Mac.

After booting up, run a full scan of all disk partitions with Dr.Web Anti-virus for Linux.

Download Dr.Web

Download by serial number

  1. If the mobile device is operating normally, download and install Dr.Web for Android. Run a full system scan and follow recommendations to neutralize the detected threats.
  2. If the mobile device has been locked by Android.Locker ransomware (the message on the screen tells you that you have broken some law or demands a set ransom amount; or you will see some other announcement that prevents you from using the handheld normally), do the following:
    • Load your smartphone or tablet in the safe mode (depending on the operating system version and specifications of the particular mobile device involved, this procedure can be performed in various ways; seek clarification from the user guide that was shipped with the device, or contact its manufacturer);
    • Once you have activated safe mode, install the Dr.Web for Android onto the infected handheld and run a full scan of the system; follow the steps recommended for neutralizing the threats that have been detected;
    • Switch off your device and turn it on as normal.

Find out more about Dr.Web for Android