Okay I got one that is currently working, Just got off box a couple hours ago.
Looks like first drop was april 4th, but the active cryptolocker process C:\Users\Office\AppData\Local\Fwuisgmpixozj.exe 91126BEDF521E6527C46EB1EAF03475A is only a few hours old in VT
Looks like first drop was april 4th, but the active cryptolocker process C:\Users\Office\AppData\Local\Fwuisgmpixozj.exe 91126BEDF521E6527C46EB1EAF03475A is only a few hours old in VT
Attachments
pw = infected
(616.52 KiB) Downloaded 192 times
(616.52 KiB) Downloaded 192 times