RansomHub ransomware T1083 white_folders *\\$windows.~ws* *\\$windows.~bt* *\\windows* *\\windows.old* *\\system volume information* *\\Boot* *\\PerfLogs* *\\AppData\\Local\\Temp* *\\AppData\\Local\\Microsoft\\GameDVR* *\\AppData\\Local\\Microsoft\\Edge* *\\AppData\\Local\\Packages\\Microsoft.* *\\AppData\\Local\\Packages\\MicrosoftWindows.* *\\AppData\\Local\\Packages\\Internet Explorer* *\\Program Files\\Common Files\\microsoft shared* *\\Program Files\\Common Files\\Services* *\\Program Files\\Common Files\\System* *\\Program Files\\Internet Explorer* *\\Program Files\\ModifiableWindowsApps* *\\Program Files\\Uninstall Information* *\\Program Files\\Windows Defender* *\\Program Files\\Windows Mail* *\\Program Files\\Windows Media Player* *\\Program Files\\Windows NT* *\\Program Files\\Windows Photo Viewer* *\\Program Files\\Windows Portable Devices* *\\Program Files\\Windows Security* *\\Program Files\\Windows Sidebar* *\\Program Files\\WindowsApps* *\\Program Files\\WindowsPowerShell* *\\Program Files (x86)\\Common Files* *\\Program Files (x86)\\Common Files\\Microsoft Shared* *\\Program Files (x86)\\Common Files\\Services* *\\Program Files (x86)\\Common Files\\System* *\\Program Files (x86)\\Internet Explorer* *\\Program Files (x86)\\Microsoft\\*Edge* *\\Program Files (x86)\\Microsoft\\Temp* *\\Program Files (x86)\\Microsoft.NET* *\\Program Files (x86)\\Windows Defender* *\\Program Files (x86)\\Windows Mail* *\\Program Files (x86)\\Windows Media Player* *\\Program Files (x86)\\Windows Multimedia Platform* *\\Program Files (x86)\\Windows NT* *\\Program Files (x86)\\Windows Photo Viewer* *\\Program Files (x86)\\Windows Portable Devices* *\\Program Files (x86)\\Windows Security* *\\Program Files (x86)\\Windows Sidebar* *\\Program Files (x86)\\WindowsPowerShell* *\\ProgramData\\ssh\\* *\\ProgramData\\USOPrivate* *\\ProgramData\\USOShared* *\\ProgramData\\Package Cache* *\\ProgramData\\Microsoft\\Device Stage* *\\ProgramData\\Microsoft\\DeviceSync* *\\ProgramData\\Microsoft\\Diagnosis* *\\ProgramData\\Microsoft\\DiagnosticLogCSP* *\\ProgramData\\Microsoft\\DRM* *\\ProgramData\\Microsoft\\UEV* *\\ProgramData\\Microsoft\\EdgeUpdate* *\\ProgramData\\Microsoft\\Event Viewer* *\\ProgramData\\Microsoft\\IdentityCRL *\\ProgramData\\Microsoft\\MapData* *\\ProgramData\\Microsoft\\MF* *\\ProgramData\\Microsoft\\NetFramework* *\\ProgramData\\Microsoft\\Network* *\\ProgramData\\Microsoft\\Provisioning* *\\ProgramData\\Microsoft\\Search* *\\ProgramData\\Microsoft\\SmsRouter* *\\ProgramData\\Microsoft\\Spectrum* *\\ProgramData\\Microsoft\\Speech_OneCore* *\\ProgramData\\Microsoft\\Storage Health* *\\ProgramData\\Microsoft\\User Account Pictures* *\\ProgramData\\Microsoft\\Vault* *\\ProgramData\\Microsoft\\WDF*", "*\\ProgramData\\Microsoft\\Windows* *\\ProgramData\\Microsoft\\Windows Defender* *\\ProgramData\\Microsoft\\Windows NT*", "*\\ProgramData\\Microsoft\\Windows Security Health* *\\ProgramData\\Microsoft\\WinMSIPC* *\\ProgramData\\Microsoft\\WPD* *\\ProgramData\\Packages\\USOPrivate* *\\ProgramData\\Packages\\USOShared* *\\ProgramData\\Packages\\WindowsHolographicDevices* *\\ProgramData\\Packages\\MicrosoftWindows.* *\\ProgramData\\Packages\\Microsoft.* --------------------------------------- RansomHub ransomware T1083 white_files NTUSER.DAT autorun.inf boot.ini desktop.ini thumbs.db *.deskthemepack *.themepack *.theme *.msstyles *.exe *.drv *.msc *.dll *.lock *.sys *.msu *.lnk *.ps1 *.iso *.inf *.cab *.386