Item path | Threat Name | Action taken |
E:\TEST\Jaff勒索 密码:infected\attachments\28-3137.pdf=>RNOHLIAFU.docm=>word/vbaProject.bin | W97m.Downloader.FVA | Deleted |
E:\TEST\Jaff勒索 密码:infected\emails\2017-05-23-Jaff-ransomware-malspam-133658-UTC.eml=>[Subject: Invoice(61-7808)][Date: Tue, 23 May 2017 16:36:58 +0300]=>61-7808.pdf=>(INFECTED_JS) | PDF:Trojan.Hypnos.2 | Deleted |
E:\TEST\Jaff勒索 密码:infected\attachments\19-9273.pdf=>(INFECTED_JS) | PDF:Trojan.Hypnos.2 | Deleted |
E:\TEST\Jaff勒索 密码:infected\embedded-Word-docs\NQBCXP4.docm | Trojan.GenericKD.5172090 | Deleted |
E:\TEST\Jaff勒索 密码:infected\emails\2017-05-23-Jaff-ransomware-malspam-171803-UTC.eml=>[Subject: Invoice(19-9273)][Date: Wed, 24 May 2017 00:18:03 +0700]=>19-9273.pdf=>(INFECTED_JS) | PDF:Trojan.Hypnos.2 | Deleted |
E:\TEST\Jaff勒索 密码:infected\embedded-Word-docs\RNJSMOVS.docm | Trojan.GenericKD.5172097 | Deleted |
E:\TEST\Jaff勒索 密码:infected\embedded-Word-docs\VUG3FBFO.docm | Trojan.GenericKD.5171751 | Deleted |
E:\TEST\Jaff勒索 密码:infected\embedded-Word-docs\TH1DZZPT.docm | Trojan.GenericKD.5171685 | Deleted |
E:\TEST\Jaff勒索 密码:infected\embedded-Word-docs\KAR6WLU.docm=>word/vbaProject.bin | W97m.Downloader.FVA | Deleted |
E:\TEST\Jaff勒索 密码:infected\emails\2017-05-23-Jaff-ransomware-malspam-132523-UTC.eml=>[Subject: Invoice(72-6353)][Date: Tue, 23 May 2017 16:25:23 +0300]=>72-6353.pdf=>(INFECTED_JS) | PDF:Trojan.Hypnos.2 | Deleted |
E:\TEST\Jaff勒索 密码:infected\embedded-Word-docs\M4SQLA2.docm | Trojan.GenericKD.5172062 | Deleted |
E:\TEST\Jaff勒索 密码:infected\emails\2017-05-23-Jaff-ransomware-malspam-190052-UTC.eml=>[Subject: Invoice(09-5337)][Date: Tue, 23 May 2017 19:00:52 -0000]=>09-5337.pdf=>(INFECTED_JS) | PDF:Trojan.Hypnos.2 | Deleted |
E:\TEST\Jaff勒索 密码:infected\emails\2017-05-23-Jaff-ransomware-malspam-164743-UTC.eml=>[Subject: Invoice(27-7813)][Date: Tue, 23 May 2017 22:17:43 +0530]=>27-7813.pdf=>Q1DOEY13.docm=>word/vbaProject.bin | W97m.Downloader.FVA | Deleted |
E:\TEST\Jaff勒索 密码:infected\embedded-Word-docs\Q1DOEY13.docm | Trojan.GenericKD.5172203 | Deleted |
E:\TEST\Jaff勒索 密码:infected\emails\2017-05-23-Jaff-ransomware-malspam-133658-UTC.eml=>[Subject: Invoice(61-7808)][Date: Tue, 23 May 2017 16:36:58 +0300]=>61-7808.pdf=>KAR6WLU.docm=>word/vbaProject.bin | W97m.Downloader.FVA | Deleted |
E:\TEST\Jaff勒索 密码:infected\emails\2017-05-23-Jaff-ransomware-malspam-132523-UTC.eml=>[Subject: Invoice(72-6353)][Date: Tue, 23 May 2017 16:25:23 +0300]=>72-6353.pdf=>RNOHLIAFU.docm=>word/vbaProject.bin | W97m.Downloader.FVA | Deleted |
E:\TEST\Jaff勒索 密码:infected\embedded-Word-docs\PQQIDNQM.docm | Trojan.GenericKD.5170565 | Deleted |
E:\TEST\Jaff勒索 密码:infected\embedded-Word-docs\OLZNKWSOW.docm | Trojan.GenericKD.5171405 | Deleted |
E:\TEST\Jaff勒索 密码:infected\embedded-Word-docs\PCHLUPL.docm | Trojan.GenericKD.5171663 | Deleted |
E:\TEST\Jaff勒索 密码:infected\emails\2017-05-23-Jaff-ransomware-malspam-133752-UTC.eml=>[Subject: Invoice(78-8672)][Date: Tue, 23 May 2017 20:37:52 +0700]=>78-8672.pdf=>PCHLUPL.docm | Trojan.GenericKD.5168237 | Deleted |
E:\TEST\Jaff勒索 密码:infected\attachments\19-9273.pdf=>NQBCXP4.docm=>word/vbaProject.bin | W97m.Downloader.FVA | Deleted |
E:\TEST\Jaff勒索 密码:infected\embedded-Word-docs\DLDD7LH.docm | Trojan.GenericKD.5172219 | Deleted |
E:\TEST\Jaff勒索 密码:infected\emails\2017-05-23-Jaff-ransomware-malspam-133655-UTC.eml=>[Subject: Invoice(68-4200)][Date: Tue, 23 May 2017 20:36:55 +0700]=>68-4200.pdf=>KAR6WLU.docm=>word/vbaProject.bin | W97m.Downloader.FVA | Deleted |
E:\TEST\Jaff勒索 密码:infected\emails\2017-05-23-Jaff-ransomware-malspam-184830-UTC.eml=>[Subject: Invoice(88-6908)][Date: Wed, 24 May 2017 01:48:30 +0700]=>88-6908.pdf=>DC2ZPQ.docm | Trojan.GenericKD.5168026 | Deleted |
E:\TEST\Jaff勒索 密码:infected\attachments\00-5523.pdf=>GYTKPVM.docm=>word/vbaProject.bin | W97m.Downloader.FVA | Deleted |
E:\TEST\Jaff勒索 密码:infected\attachments\78-8672.pdf=>PCHLUPL.docm | Trojan.GenericKD.5168237 | Deleted |
E:\TEST\Jaff勒索 密码:infected\embedded-Word-docs\DC2ZPQ.docm=>word/vbaProject.bin | W97m.Downloader.FVA | Deleted |
E:\TEST\Jaff勒索 密码:infected\attachments\68-6414.pdf=>(INFECTED_JS) | PDF:Trojan.Hypnos.2 | Deleted |
E:\TEST\Jaff勒索 密码:infected\emails\2017-05-23-Jaff-ransomware-malspam-172136-UTC.eml=>[Subject: Invoice(00-5523)][Date: Tue, 23 May 2017 20:21:36 +0300]=>00-5523.pdf=>GYTKPVM.docm=>word/vbaProject.bin | W97m.Downloader.FVA | Deleted |
E:\TEST\Jaff勒索 密码:infected\emails\2017-05-23-Jaff-ransomware-malspam-190052-UTC.eml=>[Subject: Invoice(09-5337)][Date: Tue, 23 May 2017 19:00:52 -0000]=>09-5337.pdf=>RNJSMOVS.docm=>word/vbaProject.bin | W97m.Downloader.FVA | Deleted |
E:\TEST\Jaff勒索 密码:infected\emails\2017-05-23-Jaff-ransomware-malspam-165313-UTC.eml=>[Subject: Invoice(08-4031)][Date: Tue, 23 May 2017 23:53:13 +0700]=>08-4031.pdf=>DLDD7LH.docm | Trojan.GenericKD.5151791 | Deleted |
E:\TEST\Jaff勒索 密码:infected\emails\2017-05-23-Jaff-ransomware-malspam-171803-UTC.eml=>[Subject: Invoice(19-9273)][Date: Wed, 24 May 2017 00:18:03 +0700]=>19-9273.pdf=>NQBCXP4.docm=>word/vbaProject.bin | W97m.Downloader.FVA | Deleted |
E:\TEST\Jaff勒索 密码:infected\attachments\78-8672.pdf=>(INFECTED_JS) | PDF:Trojan.Hypnos.2 | Deleted |
E:\TEST\Jaff勒索 密码:infected\emails\2017-05-23-Jaff-ransomware-malspam-184830-UTC.eml=>[Subject: Invoice(88-6908)][Date: Wed, 24 May 2017 01:48:30 +0700]=>88-6908.pdf=>(INFECTED_JS) | PDF:Trojan.Hypnos.2 | Deleted |
E:\TEST\Jaff勒索 密码:infected\emails\2017-05-23-Jaff-ransomware-malspam-165313-UTC.eml=>[Subject: Invoice(08-4031)][Date: Tue, 23 May 2017 23:53:13 +0700]=>08-4031.pdf=>(INFECTED_JS) | PDF:Trojan.Hypnos.2 | Deleted |
E:\TEST\Jaff勒索 密码:infected\emails\2017-05-23-Jaff-ransomware-malspam-132916-UTC.eml=>[Subject: Invoice(68-6414)][Date: Tue, 23 May 2017 15:29:16 +0200]=>68-6414.pdf=>KAR6WLU.docm=>word/vbaProject.bin | W97m.Downloader.FVA | Deleted |
E:\TEST\Jaff勒索 密码:infected\emails\2017-05-23-Jaff-ransomware-malspam-161832-UTC.eml=>[Subject: Invoice(54-9434)][Date: Tue, 23 May 2017 18:18:32 +0200]=>54-9434.pdf=>PQQIDNQM.docm | Trojan.GenericKD.5153306 | Deleted |
E:\TEST\Jaff勒索 密码:infected\emails\2017-05-23-Jaff-ransomware-malspam-172136-UTC.eml=>[Subject: Invoice(00-5523)][Date: Tue, 23 May 2017 20:21:36 +0300]=>00-5523.pdf=>(INFECTED_JS) | PDF:Trojan.Hypnos.2 | Deleted |
E:\TEST\Jaff勒索 密码:infected\emails\2017-05-23-Jaff-ransomware-malspam-161832-UTC.eml=>[Subject: Invoice(54-9434)][Date: Tue, 23 May 2017 18:18:32 +0200]=>54-9434.pdf=>(INFECTED_JS) | PDF:Trojan.Hypnos.2 | Deleted |
E:\TEST\Jaff勒索 密码:infected\attachments\98-9897.pdf=>TH1DZZPT.docm=>word/vbaProject.bin | W97m.Downloader.FVA | Deleted |
E:\TEST\Jaff勒索 密码:infected\emails\2017-05-23-Jaff-ransomware-malspam-133418-UTC.eml=>[Subject: Invoice(95-1750)][Date: Tue, 23 May 2017 20:34:18 +0700]=>95-1750.pdf=>VUG3FBFO.docm=>word/vbaProject.bin | W97m.Downloader.FVA | Deleted |
E:\TEST\Jaff勒索 密码:infected\emails\2017-05-23-Jaff-ransomware-malspam-133752-UTC.eml=>[Subject: Invoice(78-8672)][Date: Tue, 23 May 2017 20:37:52 +0700]=>78-8672.pdf=>(INFECTED_JS) | PDF:Trojan.Hypnos.2 | Deleted |
E:\TEST\Jaff勒索 密码:infected\attachments\00-5832.pdf=>OLZNKWSOW.docm | Trojan.GenericKD.5152687 | Deleted |
E:\TEST\Jaff勒索 密码:infected\attachments\98-9897.pdf=>(INFECTED_JS) | PDF:Trojan.Hypnos.2 | Deleted |
E:\TEST\Jaff勒索 密码:infected\emails\2017-05-23-Jaff-ransomware-malspam-150939-UTC.eml=>[Subject: Invoice(98-3753)][Date: Tue, 23 May 2017 16:09:39 +0100]=>98-3753.pdf=>M4SQLA2.docm=>word/vbaProject.bin | W97m.Downloader.FVA | Deleted |
E:\TEST\Jaff勒索 密码:infected\emails\2017-05-23-Jaff-ransomware-malspam-142913-UTC.eml=>[Subject: Invoice(00-5832)][Date: Tue, 23 May 2017 15:29:13 +0100]=>00-5832.pdf=>(INFECTED_JS) | PDF:Trojan.Hypnos.2 | Deleted |
E:\TEST\Jaff勒索 密码:infected\emails\2017-05-23-Jaff-ransomware-malspam-142913-UTC.eml=>[Subject: Invoice(00-5832)][Date: Tue, 23 May 2017 15:29:13 +0100]=>00-5832.pdf=>OLZNKWSOW.docm | Trojan.GenericKD.5152687 | Deleted |
E:\TEST\Jaff勒索 密码:infected\emails\2017-05-23-Jaff-ransomware-malspam-133418-UTC.eml=>[Subject: Invoice(95-1750)][Date: Tue, 23 May 2017 20:34:18 +0700]=>95-1750.pdf=>(INFECTED_JS) | PDF:Trojan.Hypnos.2 | Deleted |
E:\TEST\Jaff勒索 密码:infected\emails\2017-05-23-Jaff-ransomware-malspam-132708-UTC.eml=>[Subject: Invoice(98-9897)][Date: Tue, 23 May 2017 18:57:08 +0530]=>98-9897.pdf=>TH1DZZPT.docm=>word/vbaProject.bin | W97m.Downloader.FVA | Deleted |
E:\TEST\Jaff勒索 密码:infected\emails\2017-05-23-Jaff-ransomware-malspam-132916-UTC.eml=>[Subject: Invoice(68-6414)][Date: Tue, 23 May 2017 15:29:16 +0200]=>68-6414.pdf=>(INFECTED_JS) | PDF:Trojan.Hypnos.2 | Deleted |
E:\TEST\Jaff勒索 密码:infected\embedded-Word-docs\RNOHLIAFU.docm | Trojan.GenericKD.5171881 | Deleted |
E:\TEST\Jaff勒索 密码:infected\emails\2017-05-23-Jaff-ransomware-malspam-150939-UTC.eml=>[Subject: Invoice(98-3753)][Date: Tue, 23 May 2017 16:09:39 +0100]=>98-3753.pdf=>(INFECTED_JS) | PDF:Trojan.Hypnos.2 | Deleted |
E:\TEST\Jaff勒索 密码:infected\emails\2017-05-23-Jaff-ransomware-malspam-132708-UTC.eml=>[Subject: Invoice(98-9897)][Date: Tue, 23 May 2017 18:57:08 +0530]=>98-9897.pdf=>(INFECTED_JS) | PDF:Trojan.Hypnos.2 | Deleted |
E:\TEST\Jaff勒索 密码:infected\emails\2017-05-23-Jaff-ransomware-malspam-132703-UTC.eml=>[Subject: Invoice(28-3137)][Date: Tue, 23 May 2017 14:27:03 +0100]=>28-3137.pdf=>RNOHLIAFU.docm=>word/vbaProject.bin | W97m.Downloader.FVA | Deleted |
E:\TEST\Jaff勒索 密码:infected\emails\2017-05-23-Jaff-ransomware-malspam-133655-UTC.eml=>[Subject: Invoice(68-4200)][Date: Tue, 23 May 2017 20:36:55 +0700]=>68-4200.pdf=>(INFECTED_JS) | PDF:Trojan.Hypnos.2 | Deleted |
E:\TEST\Jaff勒索 密码:infected\attachments\95-1750.pdf=>VUG3FBFO.docm=>word/vbaProject.bin | W97m.Downloader.FVA | Deleted |
E:\TEST\Jaff勒索 密码:infected\emails\2017-05-23-Jaff-ransomware-malspam-164743-UTC.eml=>[Subject: Invoice(27-7813)][Date: Tue, 23 May 2017 22:17:43 +0530]=>27-7813.pdf=>(INFECTED_JS) | PDF:Trojan.Hypnos.2 | Deleted |
E:\TEST\Jaff勒索 密码:infected\attachments\98-3753.pdf=>M4SQLA2.docm=>word/vbaProject.bin | W97m.Downloader.FVA | Deleted |
E:\TEST\Jaff勒索 密码:infected\attachments\09-5337.pdf=>RNJSMOVS.docm=>word/vbaProject.bin | W97m.Downloader.FVA | Deleted |
E:\TEST\Jaff勒索 密码:infected\emails\2017-05-23-Jaff-ransomware-malspam-132703-UTC.eml=>[Subject: Invoice(28-3137)][Date: Tue, 23 May 2017 14:27:03 +0100]=>28-3137.pdf=>(INFECTED_JS) | PDF:Trojan.Hypnos.2 | Deleted |
E:\TEST\Jaff勒索 密码:infected\attachments\98-3753.pdf=>(INFECTED_JS) | PDF:Trojan.Hypnos.2 | Deleted |
E:\TEST\Jaff勒索 密码:infected\emails\2017-05-23-Jaff-ransomware-malspam-133338-UTC.eml=>[Subject: Invoice(53-3366)][Date: Tue, 23 May 2017 18:33:38 +0500]=>53-3366.pdf=>VUG3FBFO.docm=>word/vbaProject.bin | W97m.Downloader.FVA | Deleted |
E:\TEST\Jaff勒索 密码:infected\attachments\08-4031.pdf=>DLDD7LH.docm | Trojan.GenericKD.5151791 | Deleted |
E:\TEST\Jaff勒索 密码:infected\attachments\09-5337.pdf=>(INFECTED_JS) | PDF:Trojan.Hypnos.2 | Deleted |
E:\TEST\Jaff勒索 密码:infected\attachments\95-1750.pdf=>(INFECTED_JS) | PDF:Trojan.Hypnos.2 | Deleted |
E:\TEST\Jaff勒索 密码:infected\attachments\68-6414.pdf=>KAR6WLU.docm=>word/vbaProject.bin | W97m.Downloader.FVA | Deleted |
E:\TEST\Jaff勒索 密码:infected\emails\2017-05-23-Jaff-ransomware-malspam-171154-UTC.eml=>[Subject: Invoice(23-0458)][Date: Tue, 23 May 2017 20:11:54 +0300]=>23-0458.pdf=>GYTKPVM.docm=>word/vbaProject.bin | W97m.Downloader.FVA | Deleted |
E:\TEST\Jaff勒索 密码:infected\emails\2017-05-23-Jaff-ransomware-malspam-171154-UTC.eml=>[Subject: Invoice(23-0458)][Date: Tue, 23 May 2017 20:11:54 +0300]=>23-0458.pdf=>(INFECTED_JS) | PDF:Trojan.Hypnos.2 | Deleted |
E:\TEST\Jaff勒索 密码:infected\attachments\68-4200.pdf=>KAR6WLU.docm=>word/vbaProject.bin | W97m.Downloader.FVA | Deleted |
E:\TEST\Jaff勒索 密码:infected\attachments\08-4031.pdf=>(INFECTED_JS) | PDF:Trojan.Hypnos.2 | Deleted |
E:\TEST\Jaff勒索 密码:infected\attachments\54-9434.pdf=>PQQIDNQM.docm | Trojan.GenericKD.5153306 | Deleted |
E:\TEST\Jaff勒索 密码:infected\emails\2017-05-23-Jaff-ransomware-malspam-133338-UTC.eml=>[Subject: Invoice(53-3366)][Date: Tue, 23 May 2017 18:33:38 +0500]=>53-3366.pdf=>(INFECTED_JS) | PDF:Trojan.Hypnos.2 | Deleted |
E:\TEST\Jaff勒索 密码:infected\embedded-Word-docs\GYTKPVM.docm | Trojan.GenericKD.5171588 | Deleted |
E:\TEST\Jaff勒索 密码:infected\attachments\53-3366.pdf=>VUG3FBFO.docm=>word/vbaProject.bin | W97m.Downloader.FVA | Deleted |
E:\TEST\Jaff勒索 密码:infected\attachments\27-7813.pdf=>Q1DOEY13.docm=>word/vbaProject.bin | W97m.Downloader.FVA | Deleted |
E:\TEST\Jaff勒索 密码:infected\attachments\54-9434.pdf=>(INFECTED_JS) | PDF:Trojan.Hypnos.2 | Deleted |
E:\TEST\Jaff勒索 密码:infected\attachments\61-7808.pdf=>KAR6WLU.docm=>word/vbaProject.bin | W97m.Downloader.FVA | Deleted |
E:\TEST\Jaff勒索 密码:infected\attachments\53-3366.pdf=>(INFECTED_JS) | PDF:Trojan.Hypnos.2 | Deleted |
E:\TEST\Jaff勒索 密码:infected\attachments\28-3137.pdf=>(INFECTED_JS) | PDF:Trojan.Hypnos.2 | Deleted |
E:\TEST\Jaff勒索 密码:infected\attachments\68-4200.pdf=>(INFECTED_JS) | PDF:Trojan.Hypnos.2 | Deleted |
E:\TEST\Jaff勒索 密码:infected\attachments\72-6353.pdf=>RNOHLIAFU.docm=>word/vbaProject.bin | W97m.Downloader.FVA | Deleted |
E:\TEST\Jaff勒索 密码:infected\attachments\61-7808.pdf=>(INFECTED_JS) | PDF:Trojan.Hypnos.2 | Deleted |
E:\TEST\Jaff勒索 密码:infected\attachments\68-5182.pdf=>M4SQLA2.docm=>word/vbaProject.bin | W97m.Downloader.FVA | Deleted |
E:\TEST\Jaff勒索 密码:infected\attachments\00-5832.pdf=>(INFECTED_JS) | PDF:Trojan.Hypnos.2 | Deleted |
E:\TEST\Jaff勒索 密码:infected\attachments\68-5182.pdf=>(INFECTED_JS) | PDF:Trojan.Hypnos.2 | Deleted |
E:\TEST\Jaff勒索 密码:infected\artifacts\2017-05-23-Jaff-ransomware-example-levinsky8.exe | Trojan.GenericKD.5152480 | Deleted |
E:\TEST\Jaff勒索 密码:infected\attachments\00-5523.pdf=>(INFECTED_JS) | PDF:Trojan.Hypnos.2 | Deleted |
E:\TEST\Jaff勒索 密码:infected\attachments\27-7813.pdf=>(INFECTED_JS) | PDF:Trojan.Hypnos.2 | Deleted |
E:\TEST\Jaff勒索 密码:infected\attachments\88-6908.pdf=>DC2ZPQ.docm | Trojan.GenericKD.5168026 | Deleted |
E:\TEST\Jaff勒索 密码:infected\attachments\72-6353.pdf=>(INFECTED_JS) | PDF:Trojan.Hypnos.2 | Deleted |
E:\TEST\Jaff勒索 密码:infected\attachments\23-0458.pdf=>GYTKPVM.docm=>word/vbaProject.bin | W97m.Downloader.FVA | Deleted |
E:\TEST\Jaff勒索 密码:infected\attachments\88-6908.pdf=>(INFECTED_JS) | PDF:Trojan.Hypnos.2 | Deleted |
E:\TEST\Jaff勒索 密码:infected\attachments\23-0458.pdf=>(INFECTED_JS) | PDF:Trojan.Hypnos.2 | Deleted |
E:\TEST\Jaff勒索 密码:infected\emails\2017-05-23-Jaff-ransomware-malspam-132244-UTC.eml=>[Subject: Invoice(68-5182)][Date: Tue, 23 May 2017 20:22:44 +0700]=>68-5182.pdf=>M4SQLA2.docm=>word/vbaProject.bin | W97m.Downloader.FVA | Deleted |
E:\TEST\Jaff勒索 密码:infected\emails\2017-05-23-Jaff-ransomware-malspam-132244-UTC.eml=>[Subject: Invoice(68-5182)][Date: Tue, 23 May 2017 20:22:44 +0700]=>68-5182.pdf=>(INFECTED_JS) | PDF:Trojan.Hypnos.2 | Deleted |