Source: C:\Users\user\Desktop\SecuriteInfo.com.Trojan.WinGo.Agent.10211.5558.exe |
Code function: 4x nop then mov r8, 0000800000000000h |
0_2_00438B20 |
Source: C:\Users\user\Desktop\SecuriteInfo.com.Trojan.WinGo.Agent.10211.5558.exe |
Code function: 4x nop then sub rbx, qword ptr [rax+18h] |
0_2_0042F380 |
Source: C:\Users\user\Desktop\SecuriteInfo.com.Trojan.WinGo.Agent.10211.5558.exe |
Code function: 4x nop then mov rsi, r9 |
0_2_00439FE0 |
Source: SecuriteInfo.com.Trojan.WinGo.Agent.10211.5558.exe |
String found in binary or memory: http://cacerts.digicert.com/DigiCertTrustedG4CodeSigningRSA4096SHA3842021CA1.crt0 |
Source: SecuriteInfo.com.Trojan.WinGo.Agent.10211.5558.exe |
String found in binary or memory: http://cacerts.digicert.com/DigiCertTrustedRootG4.crt0C |
Source: SecuriteInfo.com.Trojan.WinGo.Agent.10211.5558.exe |
String found in binary or memory: http://crl3.digicert.com/DigiCertTrustedG4CodeSigningRSA4096SHA3842021CA1.crl0S |
Source: SecuriteInfo.com.Trojan.WinGo.Agent.10211.5558.exe |
String found in binary or memory: http://crl3.digicert.com/DigiCertTrustedRootG4.crl0 |
Source: SecuriteInfo.com.Trojan.WinGo.Agent.10211.5558.exe |
String found in binary or memory: http://crl4.digicert.com/DigiCertTrustedG4CodeSigningRSA4096SHA3842021CA1.crl0 |
Source: SecuriteInfo.com.Trojan.WinGo.Agent.10211.5558.exe |
String found in binary or memory: http://ocsp.digicert.com0 |
Source: SecuriteInfo.com.Trojan.WinGo.Agent.10211.5558.exe |
String found in binary or memory: http://ocsp.digicert.com0A |
Source: SecuriteInfo.com.Trojan.WinGo.Agent.10211.5558.exe |
String found in binary or memory: http://www.digicert.com/CPS0 |
Source: SecuriteInfo.com.Trojan.WinGo.Agent.10211.5558.exe |
String found in binary or memory: https://www.wangsu.com/product/1810 |
Source: C:\Users\user\Desktop\SecuriteInfo.com.Trojan.WinGo.Agent.10211.5558.exe |
Code function: 0_2_00435800 |
0_2_00435800 |
Source: C:\Users\user\Desktop\SecuriteInfo.com.Trojan.WinGo.Agent.10211.5558.exe |
Code function: 0_2_00447000 |
0_2_00447000 |
Source: C:\Users\user\Desktop\SecuriteInfo.com.Trojan.WinGo.Agent.10211.5558.exe |
Code function: 0_2_00415020 |
0_2_00415020 |
Source: C:\Users\user\Desktop\SecuriteInfo.com.Trojan.WinGo.Agent.10211.5558.exe |
Code function: 0_2_004330C0 |
0_2_004330C0 |
Source: C:\Users\user\Desktop\SecuriteInfo.com.Trojan.WinGo.Agent.10211.5558.exe |
Code function: 0_2_004848C0 |
0_2_004848C0 |
Source: C:\Users\user\Desktop\SecuriteInfo.com.Trojan.WinGo.Agent.10211.5558.exe |
Code function: 0_2_0041D880 |
0_2_0041D880 |
Source: C:\Users\user\Desktop\SecuriteInfo.com.Trojan.WinGo.Agent.10211.5558.exe |
Code function: 0_2_0044A080 |
0_2_0044A080 |
Source: C:\Users\user\Desktop\SecuriteInfo.com.Trojan.WinGo.Agent.10211.5558.exe |
Code function: 0_2_0045C140 |
0_2_0045C140 |
Source: C:\Users\user\Desktop\SecuriteInfo.com.Trojan.WinGo.Agent.10211.5558.exe |
Code function: 0_2_00469940 |
0_2_00469940 |
Source: C:\Users\user\Desktop\SecuriteInfo.com.Trojan.WinGo.Agent.10211.5558.exe |
Code function: 0_2_0047F140 |
0_2_0047F140 |
Source: C:\Users\user\Desktop\SecuriteInfo.com.Trojan.WinGo.Agent.10211.5558.exe |
Code function: 0_2_00415900 |
0_2_00415900 |
Source: C:\Users\user\Desktop\SecuriteInfo.com.Trojan.WinGo.Agent.10211.5558.exe |
Code function: 0_2_004301C0 |
0_2_004301C0 |
Source: C:\Users\user\Desktop\SecuriteInfo.com.Trojan.WinGo.Agent.10211.5558.exe |
Code function: 0_2_0041F1E0 |
0_2_0041F1E0 |
Source: C:\Users\user\Desktop\SecuriteInfo.com.Trojan.WinGo.Agent.10211.5558.exe |
Code function: 0_2_004161E0 |
0_2_004161E0 |
Source: C:\Users\user\Desktop\SecuriteInfo.com.Trojan.WinGo.Agent.10211.5558.exe |
Code function: 0_2_0042F980 |
0_2_0042F980 |
Source: C:\Users\user\Desktop\SecuriteInfo.com.Trojan.WinGo.Agent.10211.5558.exe |
Code function: 0_2_00442980 |
0_2_00442980 |
Source: C:\Users\user\Desktop\SecuriteInfo.com.Trojan.WinGo.Agent.10211.5558.exe |
Code function: 0_2_0045C980 |
0_2_0045C980 |
Source: C:\Users\user\Desktop\SecuriteInfo.com.Trojan.WinGo.Agent.10211.5558.exe |
Code function: 0_2_00424A40 |
0_2_00424A40 |
Source: C:\Users\user\Desktop\SecuriteInfo.com.Trojan.WinGo.Agent.10211.5558.exe |
Code function: 0_2_0044DA40 |
0_2_0044DA40 |
Source: C:\Users\user\Desktop\SecuriteInfo.com.Trojan.WinGo.Agent.10211.5558.exe |
Code function: 0_2_00452A40 |
0_2_00452A40 |
Source: C:\Users\user\Desktop\SecuriteInfo.com.Trojan.WinGo.Agent.10211.5558.exe |
Code function: 0_2_00435200 |
0_2_00435200 |
Source: C:\Users\user\Desktop\SecuriteInfo.com.Trojan.WinGo.Agent.10211.5558.exe |
Code function: 0_2_0046D200 |
0_2_0046D200 |
Source: C:\Users\user\Desktop\SecuriteInfo.com.Trojan.WinGo.Agent.10211.5558.exe |
Code function: 0_2_004362E0 |
0_2_004362E0 |
Source: C:\Users\user\Desktop\SecuriteInfo.com.Trojan.WinGo.Agent.10211.5558.exe |
Code function: 0_2_0041C280 |
0_2_0041C280 |
Source: C:\Users\user\Desktop\SecuriteInfo.com.Trojan.WinGo.Agent.10211.5558.exe |
Code function: 0_2_00482340 |
0_2_00482340 |
Source: C:\Users\user\Desktop\SecuriteInfo.com.Trojan.WinGo.Agent.10211.5558.exe |
Code function: 0_2_0042CB60 |
0_2_0042CB60 |
Source: C:\Users\user\Desktop\SecuriteInfo.com.Trojan.WinGo.Agent.10211.5558.exe |
Code function: 0_2_00482B60 |
0_2_00482B60 |
Source: C:\Users\user\Desktop\SecuriteInfo.com.Trojan.WinGo.Agent.10211.5558.exe |
Code function: 0_2_00438B20 |
0_2_00438B20 |
Source: C:\Users\user\Desktop\SecuriteInfo.com.Trojan.WinGo.Agent.10211.5558.exe |
Code function: 0_2_0047F320 |
0_2_0047F320 |
Source: C:\Users\user\Desktop\SecuriteInfo.com.Trojan.WinGo.Agent.10211.5558.exe |
Code function: 0_2_00422BC0 |
0_2_00422BC0 |
Source: C:\Users\user\Desktop\SecuriteInfo.com.Trojan.WinGo.Agent.10211.5558.exe |
Code function: 0_2_00429BC0 |
0_2_00429BC0 |
Source: C:\Users\user\Desktop\SecuriteInfo.com.Trojan.WinGo.Agent.10211.5558.exe |
Code function: 0_2_004293C0 |
0_2_004293C0 |
Source: C:\Users\user\Desktop\SecuriteInfo.com.Trojan.WinGo.Agent.10211.5558.exe |
Code function: 0_2_00425B80 |
0_2_00425B80 |
Source: C:\Users\user\Desktop\SecuriteInfo.com.Trojan.WinGo.Agent.10211.5558.exe |
Code function: 0_2_0043EB80 |
0_2_0043EB80 |
Source: C:\Users\user\Desktop\SecuriteInfo.com.Trojan.WinGo.Agent.10211.5558.exe |
Code function: 0_2_0047CB80 |
0_2_0047CB80 |
Source: C:\Users\user\Desktop\SecuriteInfo.com.Trojan.WinGo.Agent.10211.5558.exe |
Code function: 0_2_0047BC60 |
0_2_0047BC60 |
Source: C:\Users\user\Desktop\SecuriteInfo.com.Trojan.WinGo.Agent.10211.5558.exe |
Code function: 0_2_00425C05 |
0_2_00425C05 |
Source: C:\Users\user\Desktop\SecuriteInfo.com.Trojan.WinGo.Agent.10211.5558.exe |
Code function: 0_2_0042D4C0 |
0_2_0042D4C0 |
Source: C:\Users\user\Desktop\SecuriteInfo.com.Trojan.WinGo.Agent.10211.5558.exe |
Code function: 0_2_0041CCDC |
0_2_0041CCDC |
Source: C:\Users\user\Desktop\SecuriteInfo.com.Trojan.WinGo.Agent.10211.5558.exe |
Code function: 0_2_00444CE0 |
0_2_00444CE0 |
Source: C:\Users\user\Desktop\SecuriteInfo.com.Trojan.WinGo.Agent.10211.5558.exe |
Code function: 0_2_0044F4A0 |
0_2_0044F4A0 |
Source: C:\Users\user\Desktop\SecuriteInfo.com.Trojan.WinGo.Agent.10211.5558.exe |
Code function: 0_2_00426D20 |
0_2_00426D20 |
Source: C:\Users\user\Desktop\SecuriteInfo.com.Trojan.WinGo.Agent.10211.5558.exe |
Code function: 0_2_00432D20 |
0_2_00432D20 |
Source: C:\Users\user\Desktop\SecuriteInfo.com.Trojan.WinGo.Agent.10211.5558.exe |
Code function: 0_2_0041F5E0 |
0_2_0041F5E0 |
Source: C:\Users\user\Desktop\SecuriteInfo.com.Trojan.WinGo.Agent.10211.5558.exe |
Code function: 0_2_0042E5E0 |
0_2_0042E5E0 |
Source: C:\Users\user\Desktop\SecuriteInfo.com.Trojan.WinGo.Agent.10211.5558.exe |
Code function: 0_2_00419DA0 |
0_2_00419DA0 |
Source: C:\Users\user\Desktop\SecuriteInfo.com.Trojan.WinGo.Agent.10211.5558.exe |
Code function: 0_2_0046FDA9 |
0_2_0046FDA9 |
Source: C:\Users\user\Desktop\SecuriteInfo.com.Trojan.WinGo.Agent.10211.5558.exe |
Code function: 0_2_00484E20 |
0_2_00484E20 |
Source: C:\Users\user\Desktop\SecuriteInfo.com.Trojan.WinGo.Agent.10211.5558.exe |
Code function: 0_2_004256E0 |
0_2_004256E0 |
Source: C:\Users\user\Desktop\SecuriteInfo.com.Trojan.WinGo.Agent.10211.5558.exe |
Code function: 0_2_00455EE0 |
0_2_00455EE0 |
Source: C:\Users\user\Desktop\SecuriteInfo.com.Trojan.WinGo.Agent.10211.5558.exe |
Code function: 0_2_00416680 |
0_2_00416680 |
Source: C:\Users\user\Desktop\SecuriteInfo.com.Trojan.WinGo.Agent.10211.5558.exe |
Code function: 0_2_00423E80 |
0_2_00423E80 |
Source: C:\Users\user\Desktop\SecuriteInfo.com.Trojan.WinGo.Agent.10211.5558.exe |
Code function: 0_2_00439FE0 |
0_2_00439FE0 |
Source: C:\Users\user\Desktop\SecuriteInfo.com.Trojan.WinGo.Agent.10211.5558.exe |
Code function: 0_2_0047CFE0 |
0_2_0047CFE0 |
Source: C:\Users\user\Desktop\SecuriteInfo.com.Trojan.WinGo.Agent.10211.5558.exe |
Code function: 0_2_00429F80 |
0_2_00429F80 |
Source: C:\Users\user\Desktop\SecuriteInfo.com.Trojan.WinGo.Agent.10211.5558.exe |
Code function: 0_2_00438F80 |
0_2_00438F80 |
Source: C:\Users\user\Desktop\SecuriteInfo.com.Trojan.WinGo.Agent.10211.5558.exe |
Code function: 0_2_00446780 |
0_2_00446780 |
Source: C:\Users\user\Desktop\SecuriteInfo.com.Trojan.WinGo.Agent.10211.5558.exe |
Code function: 0_2_0044CFA0 |
0_2_0044CFA0 |
Source: C:\Users\user\Desktop\SecuriteInfo.com.Trojan.WinGo.Agent.10211.5558.exe |
Code function: String function: 00445DC0 appears 481 times |
|
Source: C:\Users\user\Desktop\SecuriteInfo.com.Trojan.WinGo.Agent.10211.5558.exe |
Code function: String function: 004475C0 appears 51 times |
|
Source: C:\Users\user\Desktop\SecuriteInfo.com.Trojan.WinGo.Agent.10211.5558.exe |
Code function: String function: 00447E40 appears 547 times |
|
Source: SecuriteInfo.com.Trojan.WinGo.Agent.10211.5558.exe |
Static PE information: Section: .text IMAGE_SCN_CNT_CODE, IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_ALIGN_2BYTES, IMAGE_SCN_ALIGN_4BYTES, IMAGE_SCN_ALIGN_8BYTES, IMAGE_SCN_ALIGN_16BYTES, IMAGE_SCN_ALIGN_32BYTES, IMAGE_SCN_ALIGN_64BYTES, IMAGE_SCN_ALIGN_512BYTES, IMAGE_SCN_ALIGN_1024BYTES, IMAGE_SCN_ALIGN_2048BYTES, IMAGE_SCN_ALIGN_4096BYTES, IMAGE_SCN_ALIGN_8192BYTES, IMAGE_SCN_ALIGN_MASK, IMAGE_SCN_MEM_EXECUTE, IMAGE_SCN_MEM_READ |
Source: C:\Users\user\Desktop\SecuriteInfo.com.Trojan.WinGo.Agent.10211.5558.exe |
Section loaded: apphelp.dll |
Jump to behavior |
Source: C:\Users\user\Desktop\SecuriteInfo.com.Trojan.WinGo.Agent.10211.5558.exe |
Section loaded: cryptbase.dll |
Jump to behavior |
Source: C:\Users\user\Desktop\SecuriteInfo.com.Trojan.WinGo.Agent.10211.5558.exe |
Section loaded: winmm.dll |
Jump to behavior |
Source: C:\Users\user\Desktop\SecuriteInfo.com.Trojan.WinGo.Agent.10211.5558.exe |
Section loaded: powrprof.dll |
Jump to behavior |
Source: C:\Users\user\Desktop\SecuriteInfo.com.Trojan.WinGo.Agent.10211.5558.exe |
Section loaded: umpdc.dll |
Jump to behavior |
Source: SecuriteInfo.com.Trojan.WinGo.Agent.10211.5558.exe |
Static PE information: Raw size of .text is bigger than: 0x100000 < 0x14de00 |
Source: SecuriteInfo.com.Trojan.WinGo.Agent.10211.5558.exe |
Static PE information: Raw size of .data is bigger than: 0x100000 < 0x100600 |
Source: SecuriteInfo.com.Trojan.WinGo.Agent.10211.5558.exe |
Static PE information: Raw size of .rdata is bigger than: 0x100000 < 0x15ae00 |
Source: C:\Users\user\Desktop\SecuriteInfo.com.Trojan.WinGo.Agent.10211.5558.exe |
Code function: 0_2_00411180 Sleep,Sleep,SetUnhandledExceptionFilter,malloc,strlen,malloc,memcpy,_cexit,_initterm,GetStartupInfoA, |
0_2_00411180 |
Source: C:\Users\user\Desktop\SecuriteInfo.com.Trojan.WinGo.Agent.10211.5558.exe |
Code function: 0_2_0081D464 SetUnhandledExceptionFilter,VirtualAlloc,VirtualFree, |
0_2_0081D464 |