Hunting Pay2Key
Guide on how to successfully hunt down a Pay2Key infected Windows machine.
SELECT * FROM file WHERE path LIKE "C:\Users\%%" AND filename LIKE "%.enc"





Last updated
Guide on how to successfully hunt down a Pay2Key infected Windows machine.
SELECT * FROM file WHERE path LIKE "C:\Users\%%" AND filename LIKE "%.enc"





Last updated
SELECT * FROM file WHERE path LIKE "C:\Users\champuser\%%" AND filename LIKE "%MESSAGE.TXT"SELECT * FROM file WHERE path LIKE "C:\Users\champuser\%%" AND filename LIKE "cobalt%%" SELECT * FROM windows_eventlog WHERE channel="Security" AND datetime LIKE "2022-04-19T00:46%%";
SELECT * FROM windows_eventlog WHERE channel="Application" AND datetime LIKE "2022-04-19T00:46%%";
SELECT * FROM windows_eventlog WHERE channel="System" AND datetime LIKE "2022-04-19T00:46%%"SELECT * FROM windows_security_products WHERE name="Windows Firewall"SELECT * FROM file WHERE path LIKE "C:\Windows\Prefetch\cobalt%%" or path LIKE "C:\Windows\Prefetch\psexe%%"