Windows Analysis Report
Reiven RFQ-27-05-2024.exe

Overview

General Information

Sample name: Reiven RFQ-27-05-2024.exe
Analysis ID: 1447832
MD5: 8696f9ebbc79cf408d4ff3a138719580
SHA1: 5dbcbf3c2d193ef88902e57a4959773d3a6e888d
SHA256: e0046a68adc340b6ae02f1c8924316dd2b914e38f80df71b3453e65d23d58999
Tags: exeFormbook
Infos:

Detection

AgentTesla
Score: 100
Range: 0 - 100
Whitelisted: false
Confidence: 100%

Signatures

Found malware configuration
Malicious sample detected (through community Yara rule)
Multi AV Scanner detection for dropped file
Multi AV Scanner detection for submitted file
Yara detected AgentTesla
Yara detected AntiVM3
.NET source code contains potential unpacker
.NET source code contains very large array initializations
AI detected suspicious sample
Check if machine is in data center or colocation facility
Contains functionality to check if a debugger is running (CheckRemoteDebuggerPresent)
Contains functionality to log keystrokes (.Net Source)
Hides that the sample has been downloaded from the Internet (zone.identifier)
Initial sample is a PE file and has a suspicious name
Injects a PE file into a foreign processes
Machine Learning detection for dropped file
Machine Learning detection for sample
Queries sensitive network adapter information (via WMI, Win32_NetworkAdapter, often done to detect virtual machines)
Queries sensitive video device information (via WMI, Win32_VideoController, often done to detect virtual machines)
Tries to detect sandboxes and other dynamic analysis tools (process name or module or function)
Tries to harvest and steal Putty / WinSCP information (sessions, passwords, etc)
Tries to harvest and steal browser information (history, passwords, etc)
Tries to harvest and steal ftp login credentials
Tries to steal Mail credentials (via file / registry access)
Yara detected Generic Downloader
Allocates memory with a write watch (potentially for evading sandboxes)
Checks if the current process is being debugged
Contains long sleeps (>= 3 min)
Creates a process in suspended mode (likely to inject code)
Detected TCP or UDP traffic on non-standard ports
Detected potential crypto function
Drops PE files
Enables debug privileges
Found a high number of Window / User specific system calls (may be a loop to detect user behavior)
HTTP GET or POST without a user agent
IP address seen in connection with other malware
Internet Provider seen in connection with other malware
May check the online IP address of the machine
May sleep (evasive loops) to hinder dynamic analysis
Monitors certain registry keys / values for changes (often done to protect autostart functionality)
PE / OLE file has an invalid certificate
Queries sensitive BIOS Information (via WMI, Win32_Bios & Win32_BaseBoard, often done to detect virtual machines)
Queries sensitive Operating System Information (via WMI, Win32_ComputerSystem, often done to detect virtual machines)
Queries sensitive processor information (via WMI, Win32_Processor, often done to detect virtual machines)
Queries the volume information (name, serial number etc) of a device
Sample file is different than original file name gathered from version info
Sigma detected: CurrentVersion Autorun Keys Modification
Sigma detected: Suspicious Outbound SMTP Connections
Uses 32bit PE files
Uses SMTP (mail sending)
Uses code obfuscation techniques (call, push, ret)
Yara detected Credential Stealer
Yara signature match

Classification

Name Description Attribution Blogpost URLs Link
Agent Tesla, AgentTesla A .NET based information stealer readily available to actors due to leaked builders. The malware is able to log keystrokes, can access the host's clipboard and crawls the disk for credentials or other valuable information. It has the capability to send information back to its C&C via HTTP(S), SMTP, FTP, or towards a Telegram channel.
  • SWEED
https://malpedia.caad.fkie.fraunhofer.de/details/win.agent_tesla

AV Detection

barindex
Source: 0.2.Reiven RFQ-27-05-2024.exe.3e3e5e0.2.raw.unpack Malware Configuration Extractor: Agenttesla {"Exfil Mode": "SMTP", "Port": "587", "Host": "mail.medicalhome.com.pe", "Username": "info@medicalhome.com.pe", "Password": "MHinfo01"}
Source: C:\Users\user\AppData\Roaming\GrOcCQC\GrOcCQC.exe ReversingLabs: Detection: 31%
Source: C:\Users\user\AppData\Roaming\GrOcCQC\GrOcCQC.exe Virustotal: Detection: 55% Perma Link
Source: Reiven RFQ-27-05-2024.exe ReversingLabs: Detection: 31%
Source: Reiven RFQ-27-05-2024.exe Virustotal: Detection: 55% Perma Link
Source: Submited Sample Integrated Neural Analysis Model: Matched 100.0% probability
Source: C:\Users\user\AppData\Roaming\GrOcCQC\GrOcCQC.exe Joe Sandbox ML: detected
Source: Reiven RFQ-27-05-2024.exe Joe Sandbox ML: detected
Source: Reiven RFQ-27-05-2024.exe Static PE information: EXECUTABLE_IMAGE, 32BIT_MACHINE
Source: Reiven RFQ-27-05-2024.exe Static PE information: DYNAMIC_BASE, NX_COMPAT, NO_SEH, TERMINAL_SERVER_AWARE

Networking

barindex
Source: Yara match File source: 0.2.Reiven RFQ-27-05-2024.exe.3eaee00.1.raw.unpack, type: UNPACKEDPE
Source: Yara match File source: 0.2.Reiven RFQ-27-05-2024.exe.3e3e5e0.2.raw.unpack, type: UNPACKEDPE
Source: global traffic TCP traffic: 192.168.2.6:49705 -> 144.217.159.195:587
Source: global traffic HTTP traffic detected: GET /line/?fields=hosting HTTP/1.1Host: ip-api.comConnection: Keep-Alive
Source: global traffic HTTP traffic detected: GET /line/?fields=hosting HTTP/1.1Host: ip-api.comConnection: Keep-Alive
Source: global traffic HTTP traffic detected: GET /line/?fields=hosting HTTP/1.1Host: ip-api.comConnection: Keep-Alive
Source: Joe Sandbox View IP Address: 208.95.112.1 208.95.112.1
Source: Joe Sandbox View IP Address: 144.217.159.195 144.217.159.195
Source: Joe Sandbox View ASN Name: TUT-ASUS TUT-ASUS
Source: unknown DNS query: name: ip-api.com
Source: global traffic TCP traffic: 192.168.2.6:49705 -> 144.217.159.195:587
Source: unknown UDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknown UDP traffic detected without corresponding DNS query: 1.1.1.1
Source: global traffic HTTP traffic detected: GET /line/?fields=hosting HTTP/1.1Host: ip-api.comConnection: Keep-Alive
Source: global traffic HTTP traffic detected: GET /line/?fields=hosting HTTP/1.1Host: ip-api.comConnection: Keep-Alive
Source: global traffic HTTP traffic detected: GET /line/?fields=hosting HTTP/1.1Host: ip-api.comConnection: Keep-Alive
Source: global traffic DNS traffic detected: DNS query: ip-api.com
Source: global traffic DNS traffic detected: DNS query: mail.medicalhome.com.pe
Source: Reiven RFQ-27-05-2024.exe, GrOcCQC.exe.3.dr String found in binary or memory: http://crl.comodoca.com/COMODORSACertificationAuthority.crl0q
Source: Reiven RFQ-27-05-2024.exe, GrOcCQC.exe.3.dr String found in binary or memory: http://crl.comodoca.com/COMODORSACodeSigningCA.crl0t
Source: Reiven RFQ-27-05-2024.exe, GrOcCQC.exe.3.dr String found in binary or memory: http://feeds.soundcloud.com/users/soundcloud:users:38128127/sounds.rss
Source: Reiven RFQ-27-05-2024.exe, 00000003.00000002.3328316664.00000000029D1000.00000004.00000800.00020000.00000000.sdmp, GrOcCQC.exe, 00000006.00000002.3329095685.00000000029EC000.00000004.00000800.00020000.00000000.sdmp, GrOcCQC.exe, 00000008.00000002.3328584752.00000000030F1000.00000004.00000800.00020000.00000000.sdmp String found in binary or memory: http://ip-api.com
Source: Reiven RFQ-27-05-2024.exe, 00000000.00000002.2091795003.0000000003E3E000.00000004.00000800.00020000.00000000.sdmp, Reiven RFQ-27-05-2024.exe, 00000003.00000002.3324165254.0000000000A1E000.00000004.00000020.00020000.00000000.sdmp, Reiven RFQ-27-05-2024.exe, 00000003.00000002.3328316664.00000000029D1000.00000004.00000800.00020000.00000000.sdmp, GrOcCQC.exe, 00000006.00000002.3329095685.00000000029EC000.00000004.00000800.00020000.00000000.sdmp, GrOcCQC.exe, 00000008.00000002.3328584752.00000000030F1000.00000004.00000800.00020000.00000000.sdmp String found in binary or memory: http://ip-api.com/line/?fields=hosting
Source: Reiven RFQ-27-05-2024.exe, 00000003.00000002.3324165254.0000000000A1E000.00000004.00000020.00020000.00000000.sdmp String found in binary or memory: http://ip-api.com/line/?fields=hosting3
Source: Reiven RFQ-27-05-2024.exe, 00000003.00000002.3328316664.0000000002A32000.00000004.00000800.00020000.00000000.sdmp, GrOcCQC.exe, 00000006.00000002.3329095685.0000000002A42000.00000004.00000800.00020000.00000000.sdmp, GrOcCQC.exe, 00000008.00000002.3328584752.0000000003152000.00000004.00000800.00020000.00000000.sdmp String found in binary or memory: http://mail.medicalhome.com.pe
Source: Reiven RFQ-27-05-2024.exe, 00000003.00000002.3328316664.0000000002A32000.00000004.00000800.00020000.00000000.sdmp, GrOcCQC.exe, 00000006.00000002.3329095685.0000000002A42000.00000004.00000800.00020000.00000000.sdmp, GrOcCQC.exe, 00000008.00000002.3328584752.0000000003152000.00000004.00000800.00020000.00000000.sdmp String found in binary or memory: http://medicalhome.com.pe
Source: Reiven RFQ-27-05-2024.exe, GrOcCQC.exe.3.dr String found in binary or memory: http://ocsp.comodoca.com0
Source: Reiven RFQ-27-05-2024.exe, 00000003.00000002.3324165254.0000000000A1E000.00000004.00000020.00020000.00000000.sdmp, Reiven RFQ-27-05-2024.exe, 00000003.00000002.3328316664.0000000002A32000.00000004.00000800.00020000.00000000.sdmp, Reiven RFQ-27-05-2024.exe, 00000003.00000002.3324165254.00000000009A0000.00000004.00000020.00020000.00000000.sdmp, GrOcCQC.exe, 00000006.00000002.3344090669.0000000005E80000.00000004.00000020.00020000.00000000.sdmp, GrOcCQC.exe, 00000006.00000002.3324292845.0000000000DA2000.00000004.00000020.00020000.00000000.sdmp, GrOcCQC.exe, 00000006.00000002.3329095685.0000000002A42000.00000004.00000800.00020000.00000000.sdmp, GrOcCQC.exe, 00000008.00000002.3324461460.00000000013DF000.00000004.00000020.00020000.00000000.sdmp, GrOcCQC.exe, 00000008.00000002.3324461460.000000000141C000.00000004.00000020.00020000.00000000.sdmp, GrOcCQC.exe, 00000008.00000002.3344368416.00000000065B0000.00000004.00000020.00020000.00000000.sdmp, GrOcCQC.exe, 00000008.00000002.3328584752.0000000003152000.00000004.00000800.00020000.00000000.sdmp, GrOcCQC.exe, 00000008.00000002.3324461460.000000000143E000.00000004.00000020.00020000.00000000.sdmp String found in binary or memory: http://r3.i.lencr.org/03
Source: Reiven RFQ-27-05-2024.exe, 00000003.00000002.3324165254.0000000000A1E000.00000004.00000020.00020000.00000000.sdmp, Reiven RFQ-27-05-2024.exe, 00000003.00000002.3328316664.0000000002A32000.00000004.00000800.00020000.00000000.sdmp, Reiven RFQ-27-05-2024.exe, 00000003.00000002.3324165254.00000000009A0000.00000004.00000020.00020000.00000000.sdmp, GrOcCQC.exe, 00000006.00000002.3344090669.0000000005E80000.00000004.00000020.00020000.00000000.sdmp, GrOcCQC.exe, 00000006.00000002.3324292845.0000000000DA2000.00000004.00000020.00020000.00000000.sdmp, GrOcCQC.exe, 00000006.00000002.3329095685.0000000002A42000.00000004.00000800.00020000.00000000.sdmp, GrOcCQC.exe, 00000008.00000002.3324461460.00000000013DF000.00000004.00000020.00020000.00000000.sdmp, GrOcCQC.exe, 00000008.00000002.3324461460.000000000141C000.00000004.00000020.00020000.00000000.sdmp, GrOcCQC.exe, 00000008.00000002.3344368416.00000000065B0000.00000004.00000020.00020000.00000000.sdmp, GrOcCQC.exe, 00000008.00000002.3328584752.0000000003152000.00000004.00000800.00020000.00000000.sdmp, GrOcCQC.exe, 00000008.00000002.3324461460.000000000143E000.00000004.00000020.00020000.00000000.sdmp String found in binary or memory: http://r3.o.lencr.org0
Source: Reiven RFQ-27-05-2024.exe, 00000003.00000002.3328316664.00000000029D1000.00000004.00000800.00020000.00000000.sdmp, GrOcCQC.exe, 00000006.00000002.3329095685.00000000029EC000.00000004.00000800.00020000.00000000.sdmp, GrOcCQC.exe, 00000008.00000002.3328584752.00000000030F1000.00000004.00000800.00020000.00000000.sdmp String found in binary or memory: http://schemas.xmlsoap.org/ws/2005/05/identity/claims/name
Source: Reiven RFQ-27-05-2024.exe, 00000003.00000002.3344814375.0000000006182000.00000004.00000020.00020000.00000000.sdmp, Reiven RFQ-27-05-2024.exe, 00000003.00000002.3324165254.0000000000A1E000.00000004.00000020.00020000.00000000.sdmp, Reiven RFQ-27-05-2024.exe, 00000003.00000002.3328316664.0000000002A32000.00000004.00000800.00020000.00000000.sdmp, GrOcCQC.exe, 00000006.00000002.3344090669.0000000005E80000.00000004.00000020.00020000.00000000.sdmp, GrOcCQC.exe, 00000006.00000002.3324292845.0000000000DA2000.00000004.00000020.00020000.00000000.sdmp, GrOcCQC.exe, 00000006.00000002.3329095685.0000000002A42000.00000004.00000800.00020000.00000000.sdmp, GrOcCQC.exe, 00000006.00000002.3324292845.0000000000D74000.00000004.00000020.00020000.00000000.sdmp, GrOcCQC.exe, 00000008.00000002.3324461460.00000000013DF000.00000004.00000020.00020000.00000000.sdmp, GrOcCQC.exe, 00000008.00000002.3324461460.000000000141C000.00000004.00000020.00020000.00000000.sdmp, GrOcCQC.exe, 00000008.00000002.3328584752.0000000003152000.00000004.00000800.00020000.00000000.sdmp, GrOcCQC.exe, 00000008.00000002.3324461460.0000000001360000.00000004.00000020.00020000.00000000.sdmp String found in binary or memory: http://x1.c.lencr.org/0
Source: Reiven RFQ-27-05-2024.exe, 00000003.00000002.3344814375.0000000006182000.00000004.00000020.00020000.00000000.sdmp, Reiven RFQ-27-05-2024.exe, 00000003.00000002.3324165254.0000000000A1E000.00000004.00000020.00020000.00000000.sdmp, Reiven RFQ-27-05-2024.exe, 00000003.00000002.3328316664.0000000002A32000.00000004.00000800.00020000.00000000.sdmp, GrOcCQC.exe, 00000006.00000002.3344090669.0000000005E80000.00000004.00000020.00020000.00000000.sdmp, GrOcCQC.exe, 00000006.00000002.3324292845.0000000000DA2000.00000004.00000020.00020000.00000000.sdmp, GrOcCQC.exe, 00000006.00000002.3329095685.0000000002A42000.00000004.00000800.00020000.00000000.sdmp, GrOcCQC.exe, 00000006.00000002.3324292845.0000000000D74000.00000004.00000020.00020000.00000000.sdmp, GrOcCQC.exe, 00000008.00000002.3324461460.00000000013DF000.00000004.00000020.00020000.00000000.sdmp, GrOcCQC.exe, 00000008.00000002.3324461460.000000000141C000.00000004.00000020.00020000.00000000.sdmp, GrOcCQC.exe, 00000008.00000002.3328584752.0000000003152000.00000004.00000800.00020000.00000000.sdmp, GrOcCQC.exe, 00000008.00000002.3324461460.0000000001360000.00000004.00000020.00020000.00000000.sdmp String found in binary or memory: http://x1.i.lencr.org/0
Source: Reiven RFQ-27-05-2024.exe, 00000000.00000002.2091795003.0000000003E3E000.00000004.00000800.00020000.00000000.sdmp String found in binary or memory: https://account.dyn.com/
Source: Reiven RFQ-27-05-2024.exe, GrOcCQC.exe.3.dr String found in binary or memory: https://www.chiark.greenend.org.uk/~sgtatham/putty/0

Key, Mouse, Clipboard, Microphone and Screen Capturing

barindex
Source: 0.2.Reiven RFQ-27-05-2024.exe.3e3e5e0.2.raw.unpack, n00.cs .Net Code: _3YCBU
Source: 0.2.Reiven RFQ-27-05-2024.exe.3eaee00.1.raw.unpack, n00.cs .Net Code: _3YCBU

System Summary

barindex
Source: 0.2.Reiven RFQ-27-05-2024.exe.3e3e5e0.2.unpack, type: UNPACKEDPE Matched rule: Detects executables referencing Windows vault credential objects. Observed in infostealers Author: ditekSHen
Source: 0.2.Reiven RFQ-27-05-2024.exe.3eaee00.1.unpack, type: UNPACKEDPE Matched rule: Detects executables referencing Windows vault credential objects. Observed in infostealers Author: ditekSHen
Source: 0.2.Reiven RFQ-27-05-2024.exe.3eaee00.1.raw.unpack, type: UNPACKEDPE Matched rule: Detects executables referencing Windows vault credential objects. Observed in infostealers Author: ditekSHen
Source: 0.2.Reiven RFQ-27-05-2024.exe.3e3e5e0.2.raw.unpack, type: UNPACKEDPE Matched rule: Detects executables referencing Windows vault credential objects. Observed in infostealers Author: ditekSHen
Source: 0.2.Reiven RFQ-27-05-2024.exe.2c84900.0.raw.unpack, .cs Large array initialization: : array initializer size 27103
Source: 0.2.Reiven RFQ-27-05-2024.exe.72b0000.4.raw.unpack, .cs Large array initialization: : array initializer size 27103
Source: initial sample Static PE information: Filename: Reiven RFQ-27-05-2024.exe
Source: C:\Users\user\Desktop\Reiven RFQ-27-05-2024.exe Code function: 0_2_0127D5BC 0_2_0127D5BC
Source: C:\Users\user\Desktop\Reiven RFQ-27-05-2024.exe Code function: 0_2_05136F40 0_2_05136F40
Source: C:\Users\user\Desktop\Reiven RFQ-27-05-2024.exe Code function: 0_2_05130040 0_2_05130040
Source: C:\Users\user\Desktop\Reiven RFQ-27-05-2024.exe Code function: 0_2_05136F30 0_2_05136F30
Source: C:\Users\user\Desktop\Reiven RFQ-27-05-2024.exe Code function: 0_2_088C630F 0_2_088C630F
Source: C:\Users\user\Desktop\Reiven RFQ-27-05-2024.exe Code function: 0_2_088C94B8 0_2_088C94B8
Source: C:\Users\user\Desktop\Reiven RFQ-27-05-2024.exe Code function: 0_2_088C3D48 0_2_088C3D48
Source: C:\Users\user\Desktop\Reiven RFQ-27-05-2024.exe Code function: 0_2_088C26A0 0_2_088C26A0
Source: C:\Users\user\Desktop\Reiven RFQ-27-05-2024.exe Code function: 0_2_088C4620 0_2_088C4620
Source: C:\Users\user\Desktop\Reiven RFQ-27-05-2024.exe Code function: 0_2_088C2268 0_2_088C2268
Source: C:\Users\user\Desktop\Reiven RFQ-27-05-2024.exe Code function: 0_2_088C4E78 0_2_088C4E78
Source: C:\Users\user\Desktop\Reiven RFQ-27-05-2024.exe Code function: 0_2_088C2FF8 0_2_088C2FF8
Source: C:\Users\user\Desktop\Reiven RFQ-27-05-2024.exe Code function: 0_2_088C6378 0_2_088C6378
Source: C:\Users\user\Desktop\Reiven RFQ-27-05-2024.exe Code function: 3_2_00EEF0F8 3_2_00EEF0F8
Source: C:\Users\user\Desktop\Reiven RFQ-27-05-2024.exe Code function: 3_2_00EE4228 3_2_00EE4228
Source: C:\Users\user\Desktop\Reiven RFQ-27-05-2024.exe Code function: 3_2_00EEB5D0 3_2_00EEB5D0
Source: C:\Users\user\Desktop\Reiven RFQ-27-05-2024.exe Code function: 3_2_00EE4AF8 3_2_00EE4AF8
Source: C:\Users\user\Desktop\Reiven RFQ-27-05-2024.exe Code function: 3_2_00EE3EE0 3_2_00EE3EE0
Source: C:\Users\user\Desktop\Reiven RFQ-27-05-2024.exe Code function: 3_2_00EEAE00 3_2_00EEAE00
Source: C:\Users\user\Desktop\Reiven RFQ-27-05-2024.exe Code function: 3_2_0629CC90 3_2_0629CC90
Source: C:\Users\user\Desktop\Reiven RFQ-27-05-2024.exe Code function: 3_2_0629B438 3_2_0629B438
Source: C:\Users\user\Desktop\Reiven RFQ-27-05-2024.exe Code function: 3_2_062B65E8 3_2_062B65E8
Source: C:\Users\user\Desktop\Reiven RFQ-27-05-2024.exe Code function: 3_2_062B55C0 3_2_062B55C0
Source: C:\Users\user\Desktop\Reiven RFQ-27-05-2024.exe Code function: 3_2_062B2350 3_2_062B2350
Source: C:\Users\user\Desktop\Reiven RFQ-27-05-2024.exe Code function: 3_2_062BC190 3_2_062BC190
Source: C:\Users\user\Desktop\Reiven RFQ-27-05-2024.exe Code function: 3_2_062B7D78 3_2_062B7D78
Source: C:\Users\user\Desktop\Reiven RFQ-27-05-2024.exe Code function: 3_2_062B7698 3_2_062B7698
Source: C:\Users\user\Desktop\Reiven RFQ-27-05-2024.exe Code function: 3_2_062BE3A0 3_2_062BE3A0
Source: C:\Users\user\Desktop\Reiven RFQ-27-05-2024.exe Code function: 3_2_062B0040 3_2_062B0040
Source: C:\Users\user\Desktop\Reiven RFQ-27-05-2024.exe Code function: 3_2_062B5CF0 3_2_062B5CF0
Source: C:\Users\user\Desktop\Reiven RFQ-27-05-2024.exe Code function: 3_2_06AB3910 3_2_06AB3910
Source: C:\Users\user\Desktop\Reiven RFQ-27-05-2024.exe Code function: 3_2_062B001F 3_2_062B001F
Source: C:\Users\user\AppData\Roaming\GrOcCQC\GrOcCQC.exe Code function: 4_2_00A4D5BC 4_2_00A4D5BC
Source: C:\Users\user\AppData\Roaming\GrOcCQC\GrOcCQC.exe Code function: 4_2_067F02D8 4_2_067F02D8
Source: C:\Users\user\AppData\Roaming\GrOcCQC\GrOcCQC.exe Code function: 4_2_067FAA90 4_2_067FAA90
Source: C:\Users\user\AppData\Roaming\GrOcCQC\GrOcCQC.exe Code function: 4_2_067FAA8A 4_2_067FAA8A
Source: C:\Users\user\AppData\Roaming\GrOcCQC\GrOcCQC.exe Code function: 4_2_06BB630F 4_2_06BB630F
Source: C:\Users\user\AppData\Roaming\GrOcCQC\GrOcCQC.exe Code function: 4_2_06BB26A0 4_2_06BB26A0
Source: C:\Users\user\AppData\Roaming\GrOcCQC\GrOcCQC.exe Code function: 4_2_06BB4620 4_2_06BB4620
Source: C:\Users\user\AppData\Roaming\GrOcCQC\GrOcCQC.exe Code function: 4_2_06BB4E78 4_2_06BB4E78
Source: C:\Users\user\AppData\Roaming\GrOcCQC\GrOcCQC.exe Code function: 4_2_06BB2268 4_2_06BB2268
Source: C:\Users\user\AppData\Roaming\GrOcCQC\GrOcCQC.exe Code function: 4_2_06BB6378 4_2_06BB6378
Source: C:\Users\user\AppData\Roaming\GrOcCQC\GrOcCQC.exe Code function: 4_2_06BB94B8 4_2_06BB94B8
Source: C:\Users\user\AppData\Roaming\GrOcCQC\GrOcCQC.exe Code function: 4_2_06BB3D48 4_2_06BB3D48
Source: C:\Users\user\AppData\Roaming\GrOcCQC\GrOcCQC.exe Code function: 6_2_01044228 6_2_01044228
Source: C:\Users\user\AppData\Roaming\GrOcCQC\GrOcCQC.exe Code function: 6_2_01044AF8 6_2_01044AF8
Source: C:\Users\user\AppData\Roaming\GrOcCQC\GrOcCQC.exe Code function: 6_2_0104EFC8 6_2_0104EFC8
Source: C:\Users\user\AppData\Roaming\GrOcCQC\GrOcCQC.exe Code function: 6_2_01043EE0 6_2_01043EE0
Source: C:\Users\user\AppData\Roaming\GrOcCQC\GrOcCQC.exe Code function: 6_2_0104B4A0 6_2_0104B4A0
Source: C:\Users\user\AppData\Roaming\GrOcCQC\GrOcCQC.exe Code function: 6_2_064FAC54 6_2_064FAC54
Source: C:\Users\user\AppData\Roaming\GrOcCQC\GrOcCQC.exe Code function: 6_2_065155C0 6_2_065155C0
Source: C:\Users\user\AppData\Roaming\GrOcCQC\GrOcCQC.exe Code function: 6_2_065165E8 6_2_065165E8
Source: C:\Users\user\AppData\Roaming\GrOcCQC\GrOcCQC.exe Code function: 6_2_06513078 6_2_06513078
Source: C:\Users\user\AppData\Roaming\GrOcCQC\GrOcCQC.exe Code function: 6_2_0651C190 6_2_0651C190
Source: C:\Users\user\AppData\Roaming\GrOcCQC\GrOcCQC.exe Code function: 6_2_06517D78 6_2_06517D78
Source: C:\Users\user\AppData\Roaming\GrOcCQC\GrOcCQC.exe Code function: 6_2_06517698 6_2_06517698
Source: C:\Users\user\AppData\Roaming\GrOcCQC\GrOcCQC.exe Code function: 6_2_06512342 6_2_06512342
Source: C:\Users\user\AppData\Roaming\GrOcCQC\GrOcCQC.exe Code function: 6_2_0651E3A0 6_2_0651E3A0
Source: C:\Users\user\AppData\Roaming\GrOcCQC\GrOcCQC.exe Code function: 6_2_06510040 6_2_06510040
Source: C:\Users\user\AppData\Roaming\GrOcCQC\GrOcCQC.exe Code function: 6_2_06515CDF 6_2_06515CDF
Source: C:\Users\user\AppData\Roaming\GrOcCQC\GrOcCQC.exe Code function: 6_2_0651003B 6_2_0651003B
Source: C:\Users\user\AppData\Roaming\GrOcCQC\GrOcCQC.exe Code function: 7_2_0123D5BC 7_2_0123D5BC
Source: C:\Users\user\AppData\Roaming\GrOcCQC\GrOcCQC.exe Code function: 7_2_050A6F40 7_2_050A6F40
Source: C:\Users\user\AppData\Roaming\GrOcCQC\GrOcCQC.exe Code function: 7_2_050A0006 7_2_050A0006
Source: C:\Users\user\AppData\Roaming\GrOcCQC\GrOcCQC.exe Code function: 7_2_050A0040 7_2_050A0040
Source: C:\Users\user\AppData\Roaming\GrOcCQC\GrOcCQC.exe Code function: 7_2_050A6F30 7_2_050A6F30
Source: C:\Users\user\AppData\Roaming\GrOcCQC\GrOcCQC.exe Code function: 7_2_070D630F 7_2_070D630F
Source: C:\Users\user\AppData\Roaming\GrOcCQC\GrOcCQC.exe Code function: 7_2_070D6378 7_2_070D6378
Source: C:\Users\user\AppData\Roaming\GrOcCQC\GrOcCQC.exe Code function: 7_2_070D4620 7_2_070D4620
Source: C:\Users\user\AppData\Roaming\GrOcCQC\GrOcCQC.exe Code function: 7_2_070D2268 7_2_070D2268
Source: C:\Users\user\AppData\Roaming\GrOcCQC\GrOcCQC.exe Code function: 7_2_070D4E78 7_2_070D4E78
Source: C:\Users\user\AppData\Roaming\GrOcCQC\GrOcCQC.exe Code function: 7_2_070D26A0 7_2_070D26A0
Source: C:\Users\user\AppData\Roaming\GrOcCQC\GrOcCQC.exe Code function: 7_2_070D3D48 7_2_070D3D48
Source: C:\Users\user\AppData\Roaming\GrOcCQC\GrOcCQC.exe Code function: 7_2_070D94B8 7_2_070D94B8
Source: C:\Users\user\AppData\Roaming\GrOcCQC\GrOcCQC.exe Code function: 8_2_01604AF8 8_2_01604AF8
Source: C:\Users\user\AppData\Roaming\GrOcCQC\GrOcCQC.exe Code function: 8_2_0160EFC8 8_2_0160EFC8
Source: C:\Users\user\AppData\Roaming\GrOcCQC\GrOcCQC.exe Code function: 8_2_01603EE0 8_2_01603EE0
Source: C:\Users\user\AppData\Roaming\GrOcCQC\GrOcCQC.exe Code function: 8_2_01604228 8_2_01604228
Source: C:\Users\user\AppData\Roaming\GrOcCQC\GrOcCQC.exe Code function: 8_2_0160B4A0 8_2_0160B4A0
Source: C:\Users\user\AppData\Roaming\GrOcCQC\GrOcCQC.exe Code function: 8_2_06C2C4A0 8_2_06C2C4A0
Source: C:\Users\user\AppData\Roaming\GrOcCQC\GrOcCQC.exe Code function: 8_2_06C2AC54 8_2_06C2AC54
Source: C:\Users\user\AppData\Roaming\GrOcCQC\GrOcCQC.exe Code function: 8_2_06C455C0 8_2_06C455C0
Source: C:\Users\user\AppData\Roaming\GrOcCQC\GrOcCQC.exe Code function: 8_2_06C465E8 8_2_06C465E8
Source: C:\Users\user\AppData\Roaming\GrOcCQC\GrOcCQC.exe Code function: 8_2_06C43078 8_2_06C43078
Source: C:\Users\user\AppData\Roaming\GrOcCQC\GrOcCQC.exe Code function: 8_2_06C4C190 8_2_06C4C190
Source: C:\Users\user\AppData\Roaming\GrOcCQC\GrOcCQC.exe Code function: 8_2_06C47D78 8_2_06C47D78
Source: C:\Users\user\AppData\Roaming\GrOcCQC\GrOcCQC.exe Code function: 8_2_06C47698 8_2_06C47698
Source: C:\Users\user\AppData\Roaming\GrOcCQC\GrOcCQC.exe Code function: 8_2_06C4E3A0 8_2_06C4E3A0
Source: C:\Users\user\AppData\Roaming\GrOcCQC\GrOcCQC.exe Code function: 8_2_06C40040 8_2_06C40040
Source: C:\Users\user\AppData\Roaming\GrOcCQC\GrOcCQC.exe Code function: 8_2_06C45CDF 8_2_06C45CDF
Source: C:\Users\user\AppData\Roaming\GrOcCQC\GrOcCQC.exe Code function: 8_2_07133500 8_2_07133500
Source: C:\Users\user\AppData\Roaming\GrOcCQC\GrOcCQC.exe Code function: 8_2_06C40006 8_2_06C40006
Source: C:\Users\user\AppData\Roaming\GrOcCQC\GrOcCQC.exe Code function: 8_2_06C4003B 8_2_06C4003B
Source: Reiven RFQ-27-05-2024.exe Static PE information: invalid certificate
Source: Reiven RFQ-27-05-2024.exe, 00000000.00000002.2091795003.0000000003E3E000.00000004.00000800.00020000.00000000.sdmp Binary or memory string: OriginalFilenameac48d4e1-996e-4f58-a425-6a9a2bc19947.exe4 vs Reiven RFQ-27-05-2024.exe
Source: Reiven RFQ-27-05-2024.exe, 00000000.00000002.2091795003.0000000003E3E000.00000004.00000800.00020000.00000000.sdmp Binary or memory string: OriginalFilenameTyrone.dll8 vs Reiven RFQ-27-05-2024.exe
Source: Reiven RFQ-27-05-2024.exe, 00000000.00000002.2091196729.0000000002C61000.00000004.00000800.00020000.00000000.sdmp Binary or memory string: OriginalFilenameSimpleLogin.dll8 vs Reiven RFQ-27-05-2024.exe
Source: Reiven RFQ-27-05-2024.exe, 00000000.00000002.2094006338.00000000072B0000.00000004.08000000.00040000.00000000.sdmp Binary or memory string: OriginalFilenameSimpleLogin.dll8 vs Reiven RFQ-27-05-2024.exe
Source: Reiven RFQ-27-05-2024.exe, 00000000.00000002.2094456581.00000000087E0000.00000004.08000000.00040000.00000000.sdmp Binary or memory string: OriginalFilenameTyrone.dll8 vs Reiven RFQ-27-05-2024.exe
Source: Reiven RFQ-27-05-2024.exe, 00000000.00000002.2089088671.0000000000E3E000.00000004.00000020.00020000.00000000.sdmp Binary or memory string: OriginalFilenameclr.dllT vs Reiven RFQ-27-05-2024.exe
Source: Reiven RFQ-27-05-2024.exe, 00000003.00000002.3323955764.0000000000939000.00000004.00000010.00020000.00000000.sdmp Binary or memory string: OriginalFilenameUNKNOWN_FILET vs Reiven RFQ-27-05-2024.exe
Source: Reiven RFQ-27-05-2024.exe Binary or memory string: OriginalFilenamezNKa.exeB vs Reiven RFQ-27-05-2024.exe
Source: Reiven RFQ-27-05-2024.exe Static PE information: EXECUTABLE_IMAGE, 32BIT_MACHINE
Source: 0.2.Reiven RFQ-27-05-2024.exe.3e3e5e0.2.unpack, type: UNPACKEDPE Matched rule: INDICATOR_SUSPICIOUS_EXE_VaultSchemaGUID author = ditekSHen, description = Detects executables referencing Windows vault credential objects. Observed in infostealers
Source: 0.2.Reiven RFQ-27-05-2024.exe.3eaee00.1.unpack, type: UNPACKEDPE Matched rule: INDICATOR_SUSPICIOUS_EXE_VaultSchemaGUID author = ditekSHen, description = Detects executables referencing Windows vault credential objects. Observed in infostealers
Source: 0.2.Reiven RFQ-27-05-2024.exe.3eaee00.1.raw.unpack, type: UNPACKEDPE Matched rule: INDICATOR_SUSPICIOUS_EXE_VaultSchemaGUID author = ditekSHen, description = Detects executables referencing Windows vault credential objects. Observed in infostealers
Source: 0.2.Reiven RFQ-27-05-2024.exe.3e3e5e0.2.raw.unpack, type: UNPACKEDPE Matched rule: INDICATOR_SUSPICIOUS_EXE_VaultSchemaGUID author = ditekSHen, description = Detects executables referencing Windows vault credential objects. Observed in infostealers
Source: Reiven RFQ-27-05-2024.exe Static PE information: Section: .text IMAGE_SCN_CNT_CODE, IMAGE_SCN_MEM_EXECUTE, IMAGE_SCN_MEM_READ
Source: 0.2.Reiven RFQ-27-05-2024.exe.3e3e5e0.2.raw.unpack, NpXw3kw.cs Cryptographic APIs: 'TransformFinalBlock'
Source: 0.2.Reiven RFQ-27-05-2024.exe.3e3e5e0.2.raw.unpack, NpXw3kw.cs Cryptographic APIs: 'TransformFinalBlock', 'CreateDecryptor'
Source: 0.2.Reiven RFQ-27-05-2024.exe.3e3e5e0.2.raw.unpack, gyfrCFT5x9I.cs Cryptographic APIs: 'TransformFinalBlock'
Source: 0.2.Reiven RFQ-27-05-2024.exe.3e3e5e0.2.raw.unpack, gyfrCFT5x9I.cs Cryptographic APIs: 'TransformFinalBlock'
Source: 0.2.Reiven RFQ-27-05-2024.exe.3e3e5e0.2.raw.unpack, gyfrCFT5x9I.cs Cryptographic APIs: 'TransformFinalBlock'
Source: 0.2.Reiven RFQ-27-05-2024.exe.3e3e5e0.2.raw.unpack, gyfrCFT5x9I.cs Cryptographic APIs: 'TransformFinalBlock'
Source: 0.2.Reiven RFQ-27-05-2024.exe.3e3e5e0.2.raw.unpack, fpnV0Qjz.cs Cryptographic APIs: 'TransformFinalBlock'
Source: 0.2.Reiven RFQ-27-05-2024.exe.3e3e5e0.2.raw.unpack, fpnV0Qjz.cs Cryptographic APIs: 'TransformFinalBlock'
Source: 0.2.Reiven RFQ-27-05-2024.exe.405e740.3.raw.unpack, P4KdTDTBvmf8mLrGWD.cs Security API names: _0020.SetAccessControl
Source: 0.2.Reiven RFQ-27-05-2024.exe.405e740.3.raw.unpack, P4KdTDTBvmf8mLrGWD.cs Security API names: System.Security.Principal.WindowsIdentity.GetCurrent()
Source: 0.2.Reiven RFQ-27-05-2024.exe.405e740.3.raw.unpack, P4KdTDTBvmf8mLrGWD.cs Security API names: _0020.AddAccessRule
Source: 0.2.Reiven RFQ-27-05-2024.exe.87e0000.7.raw.unpack, P4KdTDTBvmf8mLrGWD.cs Security API names: _0020.SetAccessControl
Source: 0.2.Reiven RFQ-27-05-2024.exe.87e0000.7.raw.unpack, P4KdTDTBvmf8mLrGWD.cs Security API names: System.Security.Principal.WindowsIdentity.GetCurrent()
Source: 0.2.Reiven RFQ-27-05-2024.exe.87e0000.7.raw.unpack, P4KdTDTBvmf8mLrGWD.cs Security API names: _0020.AddAccessRule
Source: 0.2.Reiven RFQ-27-05-2024.exe.87e0000.7.raw.unpack, ShJNeJ5woXxHDCbUPp.cs Security API names: System.Security.Principal.WindowsIdentity.GetCurrent()
Source: 0.2.Reiven RFQ-27-05-2024.exe.405e740.3.raw.unpack, ShJNeJ5woXxHDCbUPp.cs Security API names: System.Security.Principal.WindowsIdentity.GetCurrent()
Source: classification engine Classification label: mal100.troj.spyw.evad.winEXE@9/4@2/2
Source: C:\Users\user\Desktop\Reiven RFQ-27-05-2024.exe File created: C:\Users\user\AppData\Local\Microsoft\CLR_v4.0_32\UsageLogs\Reiven RFQ-27-05-2024.exe.log Jump to behavior
Source: C:\Users\user\AppData\Roaming\GrOcCQC\GrOcCQC.exe Mutant created: NULL
Source: Reiven RFQ-27-05-2024.exe Static PE information: Section: .text IMAGE_SCN_CNT_CODE, IMAGE_SCN_MEM_EXECUTE, IMAGE_SCN_MEM_READ
Source: Reiven RFQ-27-05-2024.exe Static file information: TRID: Win32 Executable (generic) Net Framework (10011505/4) 49.98%
Source: C:\Users\user\Desktop\Reiven RFQ-27-05-2024.exe WMI Queries: IWbemServices::CreateInstanceEnum - root\cimv2 : Win32_Processor
Source: C:\Users\user\Desktop\Reiven RFQ-27-05-2024.exe WMI Queries: IWbemServices::ExecQuery - root\cimv2 : SELECT * FROM Win32_Processor
Source: C:\Users\user\AppData\Roaming\GrOcCQC\GrOcCQC.exe WMI Queries: IWbemServices::CreateInstanceEnum - root\cimv2 : Win32_Processor
Source: C:\Users\user\AppData\Roaming\GrOcCQC\GrOcCQC.exe WMI Queries: IWbemServices::ExecQuery - root\cimv2 : SELECT * FROM Win32_Processor
Source: C:\Users\user\AppData\Roaming\GrOcCQC\GrOcCQC.exe WMI Queries: IWbemServices::CreateInstanceEnum - root\cimv2 : Win32_Processor
Source: C:\Users\user\AppData\Roaming\GrOcCQC\GrOcCQC.exe WMI Queries: IWbemServices::ExecQuery - root\cimv2 : SELECT * FROM Win32_Processor
Source: C:\Users\user\Desktop\Reiven RFQ-27-05-2024.exe File read: C:\Users\user\AppData\Roaming\Mozilla\Firefox\profiles.ini Jump to behavior
Source: C:\Users\user\Desktop\Reiven RFQ-27-05-2024.exe Key opened: HKEY_CURRENT_USER\Software\Policies\Microsoft\Windows\Safer\CodeIdentifiers Jump to behavior
Source: Reiven RFQ-27-05-2024.exe ReversingLabs: Detection: 31%
Source: Reiven RFQ-27-05-2024.exe Virustotal: Detection: 55%
Source: C:\Users\user\Desktop\Reiven RFQ-27-05-2024.exe File read: C:\Users\user\Desktop\Reiven RFQ-27-05-2024.exe:Zone.Identifier Jump to behavior
Source: unknown Process created: C:\Users\user\Desktop\Reiven RFQ-27-05-2024.exe "C:\Users\user\Desktop\Reiven RFQ-27-05-2024.exe"
Source: C:\Users\user\Desktop\Reiven RFQ-27-05-2024.exe Process created: C:\Users\user\Desktop\Reiven RFQ-27-05-2024.exe "C:\Users\user\Desktop\Reiven RFQ-27-05-2024.exe"
Source: unknown Process created: C:\Users\user\AppData\Roaming\GrOcCQC\GrOcCQC.exe "C:\Users\user\AppData\Roaming\GrOcCQC\GrOcCQC.exe"
Source: C:\Users\user\AppData\Roaming\GrOcCQC\GrOcCQC.exe Process created: C:\Users\user\AppData\Roaming\GrOcCQC\GrOcCQC.exe "C:\Users\user\AppData\Roaming\GrOcCQC\GrOcCQC.exe"
Source: unknown Process created: C:\Users\user\AppData\Roaming\GrOcCQC\GrOcCQC.exe "C:\Users\user\AppData\Roaming\GrOcCQC\GrOcCQC.exe"
Source: C:\Users\user\AppData\Roaming\GrOcCQC\GrOcCQC.exe Process created: C:\Users\user\AppData\Roaming\GrOcCQC\GrOcCQC.exe "C:\Users\user\AppData\Roaming\GrOcCQC\GrOcCQC.exe"
Source: C:\Users\user\Desktop\Reiven RFQ-27-05-2024.exe Process created: C:\Users\user\Desktop\Reiven RFQ-27-05-2024.exe "C:\Users\user\Desktop\Reiven RFQ-27-05-2024.exe" Jump to behavior
Source: C:\Users\user\AppData\Roaming\GrOcCQC\GrOcCQC.exe Process created: C:\Users\user\AppData\Roaming\GrOcCQC\GrOcCQC.exe "C:\Users\user\AppData\Roaming\GrOcCQC\GrOcCQC.exe" Jump to behavior
Source: C:\Users\user\AppData\Roaming\GrOcCQC\GrOcCQC.exe Process created: C:\Users\user\AppData\Roaming\GrOcCQC\GrOcCQC.exe "C:\Users\user\AppData\Roaming\GrOcCQC\GrOcCQC.exe" Jump to behavior
Source: C:\Users\user\Desktop\Reiven RFQ-27-05-2024.exe Section loaded: mscoree.dll Jump to behavior
Source: C:\Users\user\Desktop\Reiven RFQ-27-05-2024.exe Section loaded: apphelp.dll Jump to behavior
Source: C:\Users\user\Desktop\Reiven RFQ-27-05-2024.exe Section loaded: kernel.appcore.dll Jump to behavior
Source: C:\Users\user\Desktop\Reiven RFQ-27-05-2024.exe Section loaded: version.dll Jump to behavior
Source: C:\Users\user\Desktop\Reiven RFQ-27-05-2024.exe Section loaded: vcruntime140_clr0400.dll Jump to behavior
Source: C:\Users\user\Desktop\Reiven RFQ-27-05-2024.exe Section loaded: ucrtbase_clr0400.dll Jump to behavior
Source: C:\Users\user\Desktop\Reiven RFQ-27-05-2024.exe Section loaded: uxtheme.dll Jump to behavior
Source: C:\Users\user\Desktop\Reiven RFQ-27-05-2024.exe Section loaded: windows.storage.dll Jump to behavior
Source: C:\Users\user\Desktop\Reiven RFQ-27-05-2024.exe Section loaded: wldp.dll Jump to behavior
Source: C:\Users\user\Desktop\Reiven RFQ-27-05-2024.exe Section loaded: profapi.dll Jump to behavior
Source: C:\Users\user\Desktop\Reiven RFQ-27-05-2024.exe Section loaded: cryptsp.dll Jump to behavior
Source: C:\Users\user\Desktop\Reiven RFQ-27-05-2024.exe Section loaded: rsaenh.dll Jump to behavior
Source: C:\Users\user\Desktop\Reiven RFQ-27-05-2024.exe Section loaded: cryptbase.dll Jump to behavior
Source: C:\Users\user\Desktop\Reiven RFQ-27-05-2024.exe Section loaded: dwrite.dll Jump to behavior
Source: C:\Users\user\Desktop\Reiven RFQ-27-05-2024.exe Section loaded: textshaping.dll Jump to behavior
Source: C:\Users\user\Desktop\Reiven RFQ-27-05-2024.exe Section loaded: windowscodecs.dll Jump to behavior
Source: C:\Users\user\Desktop\Reiven RFQ-27-05-2024.exe Section loaded: amsi.dll Jump to behavior
Source: C:\Users\user\Desktop\Reiven RFQ-27-05-2024.exe Section loaded: userenv.dll Jump to behavior
Source: C:\Users\user\Desktop\Reiven RFQ-27-05-2024.exe Section loaded: msasn1.dll Jump to behavior
Source: C:\Users\user\Desktop\Reiven RFQ-27-05-2024.exe Section loaded: gpapi.dll Jump to behavior
Source: C:\Users\user\Desktop\Reiven RFQ-27-05-2024.exe Section loaded: urlmon.dll Jump to behavior
Source: C:\Users\user\Desktop\Reiven RFQ-27-05-2024.exe Section loaded: iertutil.dll Jump to behavior
Source: C:\Users\user\Desktop\Reiven RFQ-27-05-2024.exe Section loaded: srvcli.dll Jump to behavior
Source: C:\Users\user\Desktop\Reiven RFQ-27-05-2024.exe Section loaded: netutils.dll Jump to behavior
Source: C:\Users\user\Desktop\Reiven RFQ-27-05-2024.exe Section loaded: sspicli.dll Jump to behavior
Source: C:\Users\user\Desktop\Reiven RFQ-27-05-2024.exe Section loaded: propsys.dll Jump to behavior
Source: C:\Users\user\Desktop\Reiven RFQ-27-05-2024.exe Section loaded: mscoree.dll Jump to behavior
Source: C:\Users\user\Desktop\Reiven RFQ-27-05-2024.exe Section loaded: kernel.appcore.dll Jump to behavior
Source: C:\Users\user\Desktop\Reiven RFQ-27-05-2024.exe Section loaded: version.dll Jump to behavior
Source: C:\Users\user\Desktop\Reiven RFQ-27-05-2024.exe Section loaded: vcruntime140_clr0400.dll Jump to behavior
Source: C:\Users\user\Desktop\Reiven RFQ-27-05-2024.exe Section loaded: ucrtbase_clr0400.dll Jump to behavior
Source: C:\Users\user\Desktop\Reiven RFQ-27-05-2024.exe Section loaded: uxtheme.dll Jump to behavior
Source: C:\Users\user\Desktop\Reiven RFQ-27-05-2024.exe Section loaded: windows.storage.dll Jump to behavior
Source: C:\Users\user\Desktop\Reiven RFQ-27-05-2024.exe Section loaded: wldp.dll Jump to behavior
Source: C:\Users\user\Desktop\Reiven RFQ-27-05-2024.exe Section loaded: profapi.dll Jump to behavior
Source: C:\Users\user\Desktop\Reiven RFQ-27-05-2024.exe Section loaded: cryptsp.dll Jump to behavior
Source: C:\Users\user\Desktop\Reiven RFQ-27-05-2024.exe Section loaded: rsaenh.dll Jump to behavior
Source: C:\Users\user\Desktop\Reiven RFQ-27-05-2024.exe Section loaded: cryptbase.dll Jump to behavior
Source: C:\Users\user\Desktop\Reiven RFQ-27-05-2024.exe Section loaded: wbemcomn.dll Jump to behavior
Source: C:\Users\user\Desktop\Reiven RFQ-27-05-2024.exe Section loaded: amsi.dll Jump to behavior
Source: C:\Users\user\Desktop\Reiven RFQ-27-05-2024.exe Section loaded: userenv.dll Jump to behavior
Source: C:\Users\user\Desktop\Reiven RFQ-27-05-2024.exe Section loaded: sspicli.dll Jump to behavior
Source: C:\Users\user\Desktop\Reiven RFQ-27-05-2024.exe Section loaded: rasapi32.dll Jump to behavior
Source: C:\Users\user\Desktop\Reiven RFQ-27-05-2024.exe Section loaded: rasman.dll Jump to behavior
Source: C:\Users\user\Desktop\Reiven RFQ-27-05-2024.exe Section loaded: rtutils.dll Jump to behavior
Source: C:\Users\user\Desktop\Reiven RFQ-27-05-2024.exe Section loaded: mswsock.dll Jump to behavior
Source: C:\Users\user\Desktop\Reiven RFQ-27-05-2024.exe Section loaded: winhttp.dll Jump to behavior
Source: C:\Users\user\Desktop\Reiven RFQ-27-05-2024.exe Section loaded: ondemandconnroutehelper.dll Jump to behavior
Source: C:\Users\user\Desktop\Reiven RFQ-27-05-2024.exe Section loaded: iphlpapi.dll Jump to behavior
Source: C:\Users\user\Desktop\Reiven RFQ-27-05-2024.exe Section loaded: dhcpcsvc6.dll Jump to behavior
Source: C:\Users\user\Desktop\Reiven RFQ-27-05-2024.exe Section loaded: dhcpcsvc.dll Jump to behavior
Source: C:\Users\user\Desktop\Reiven RFQ-27-05-2024.exe Section loaded: dnsapi.dll Jump to behavior
Source: C:\Users\user\Desktop\Reiven RFQ-27-05-2024.exe Section loaded: winnsi.dll Jump to behavior
Source: C:\Users\user\Desktop\Reiven RFQ-27-05-2024.exe Section loaded: rasadhlp.dll Jump to behavior
Source: C:\Users\user\Desktop\Reiven RFQ-27-05-2024.exe Section loaded: fwpuclnt.dll Jump to behavior
Source: C:\Users\user\Desktop\Reiven RFQ-27-05-2024.exe Section loaded: ntmarta.dll Jump to behavior
Source: C:\Users\user\Desktop\Reiven RFQ-27-05-2024.exe Section loaded: vaultcli.dll Jump to behavior
Source: C:\Users\user\Desktop\Reiven RFQ-27-05-2024.exe Section loaded: wintypes.dll Jump to behavior
Source: C:\Users\user\Desktop\Reiven RFQ-27-05-2024.exe Section loaded: secur32.dll Jump to behavior
Source: C:\Users\user\Desktop\Reiven RFQ-27-05-2024.exe Section loaded: schannel.dll Jump to behavior
Source: C:\Users\user\Desktop\Reiven RFQ-27-05-2024.exe Section loaded: mskeyprotect.dll Jump to behavior
Source: C:\Users\user\Desktop\Reiven RFQ-27-05-2024.exe Section loaded: ntasn1.dll Jump to behavior
Source: C:\Users\user\Desktop\Reiven RFQ-27-05-2024.exe Section loaded: ncrypt.dll Jump to behavior
Source: C:\Users\user\Desktop\Reiven RFQ-27-05-2024.exe Section loaded: ncryptsslp.dll Jump to behavior
Source: C:\Users\user\Desktop\Reiven RFQ-27-05-2024.exe Section loaded: msasn1.dll Jump to behavior
Source: C:\Users\user\AppData\Roaming\GrOcCQC\GrOcCQC.exe Section loaded: mscoree.dll Jump to behavior
Source: C:\Users\user\AppData\Roaming\GrOcCQC\GrOcCQC.exe Section loaded: apphelp.dll Jump to behavior
Source: C:\Users\user\AppData\Roaming\GrOcCQC\GrOcCQC.exe Section loaded: kernel.appcore.dll Jump to behavior
Source: C:\Users\user\AppData\Roaming\GrOcCQC\GrOcCQC.exe Section loaded: version.dll Jump to behavior
Source: C:\Users\user\AppData\Roaming\GrOcCQC\GrOcCQC.exe Section loaded: vcruntime140_clr0400.dll Jump to behavior
Source: C:\Users\user\AppData\Roaming\GrOcCQC\GrOcCQC.exe Section loaded: ucrtbase_clr0400.dll Jump to behavior
Source: C:\Users\user\AppData\Roaming\GrOcCQC\GrOcCQC.exe Section loaded: ucrtbase_clr0400.dll Jump to behavior
Source: C:\Users\user\AppData\Roaming\GrOcCQC\GrOcCQC.exe Section loaded: uxtheme.dll Jump to behavior
Source: C:\Users\user\AppData\Roaming\GrOcCQC\GrOcCQC.exe Section loaded: windows.storage.dll Jump to behavior
Source: C:\Users\user\AppData\Roaming\GrOcCQC\GrOcCQC.exe Section loaded: wldp.dll Jump to behavior
Source: C:\Users\user\AppData\Roaming\GrOcCQC\GrOcCQC.exe Section loaded: profapi.dll Jump to behavior
Source: C:\Users\user\AppData\Roaming\GrOcCQC\GrOcCQC.exe Section loaded: cryptsp.dll Jump to behavior
Source: C:\Users\user\AppData\Roaming\GrOcCQC\GrOcCQC.exe Section loaded: rsaenh.dll Jump to behavior
Source: C:\Users\user\AppData\Roaming\GrOcCQC\GrOcCQC.exe Section loaded: cryptbase.dll Jump to behavior
Source: C:\Users\user\AppData\Roaming\GrOcCQC\GrOcCQC.exe Section loaded: dwrite.dll Jump to behavior
Source: C:\Users\user\AppData\Roaming\GrOcCQC\GrOcCQC.exe Section loaded: textshaping.dll Jump to behavior
Source: C:\Users\user\AppData\Roaming\GrOcCQC\GrOcCQC.exe Section loaded: windowscodecs.dll Jump to behavior
Source: C:\Users\user\AppData\Roaming\GrOcCQC\GrOcCQC.exe Section loaded: amsi.dll Jump to behavior
Source: C:\Users\user\AppData\Roaming\GrOcCQC\GrOcCQC.exe Section loaded: userenv.dll Jump to behavior
Source: C:\Users\user\AppData\Roaming\GrOcCQC\GrOcCQC.exe Section loaded: msasn1.dll Jump to behavior
Source: C:\Users\user\AppData\Roaming\GrOcCQC\GrOcCQC.exe Section loaded: gpapi.dll Jump to behavior
Source: C:\Users\user\AppData\Roaming\GrOcCQC\GrOcCQC.exe Section loaded: urlmon.dll Jump to behavior
Source: C:\Users\user\AppData\Roaming\GrOcCQC\GrOcCQC.exe Section loaded: iertutil.dll Jump to behavior
Source: C:\Users\user\AppData\Roaming\GrOcCQC\GrOcCQC.exe Section loaded: srvcli.dll Jump to behavior
Source: C:\Users\user\AppData\Roaming\GrOcCQC\GrOcCQC.exe Section loaded: netutils.dll Jump to behavior
Source: C:\Users\user\AppData\Roaming\GrOcCQC\GrOcCQC.exe Section loaded: sspicli.dll Jump to behavior
Source: C:\Users\user\AppData\Roaming\GrOcCQC\GrOcCQC.exe Section loaded: propsys.dll Jump to behavior
Source: C:\Users\user\AppData\Roaming\GrOcCQC\GrOcCQC.exe Section loaded: mscoree.dll Jump to behavior
Source: C:\Users\user\AppData\Roaming\GrOcCQC\GrOcCQC.exe Section loaded: kernel.appcore.dll Jump to behavior
Source: C:\Users\user\AppData\Roaming\GrOcCQC\GrOcCQC.exe Section loaded: version.dll Jump to behavior
Source: C:\Users\user\AppData\Roaming\GrOcCQC\GrOcCQC.exe Section loaded: vcruntime140_clr0400.dll Jump to behavior
Source: C:\Users\user\AppData\Roaming\GrOcCQC\GrOcCQC.exe Section loaded: ucrtbase_clr0400.dll Jump to behavior
Source: C:\Users\user\AppData\Roaming\GrOcCQC\GrOcCQC.exe Section loaded: ucrtbase_clr0400.dll Jump to behavior
Source: C:\Users\user\AppData\Roaming\GrOcCQC\GrOcCQC.exe Section loaded: uxtheme.dll Jump to behavior
Source: C:\Users\user\AppData\Roaming\GrOcCQC\GrOcCQC.exe Section loaded: windows.storage.dll Jump to behavior
Source: C:\Users\user\AppData\Roaming\GrOcCQC\GrOcCQC.exe Section loaded: wldp.dll Jump to behavior
Source: C:\Users\user\AppData\Roaming\GrOcCQC\GrOcCQC.exe Section loaded: profapi.dll Jump to behavior
Source: C:\Users\user\AppData\Roaming\GrOcCQC\GrOcCQC.exe Section loaded: cryptsp.dll Jump to behavior
Source: C:\Users\user\AppData\Roaming\GrOcCQC\GrOcCQC.exe Section loaded: rsaenh.dll Jump to behavior
Source: C:\Users\user\AppData\Roaming\GrOcCQC\GrOcCQC.exe Section loaded: cryptbase.dll Jump to behavior
Source: C:\Users\user\AppData\Roaming\GrOcCQC\GrOcCQC.exe Section loaded: wbemcomn.dll Jump to behavior
Source: C:\Users\user\AppData\Roaming\GrOcCQC\GrOcCQC.exe Section loaded: amsi.dll Jump to behavior
Source: C:\Users\user\AppData\Roaming\GrOcCQC\GrOcCQC.exe Section loaded: userenv.dll Jump to behavior
Source: C:\Users\user\AppData\Roaming\GrOcCQC\GrOcCQC.exe Section loaded: sspicli.dll Jump to behavior
Source: C:\Users\user\AppData\Roaming\GrOcCQC\GrOcCQC.exe Section loaded: rasapi32.dll Jump to behavior
Source: C:\Users\user\AppData\Roaming\GrOcCQC\GrOcCQC.exe Section loaded: rasman.dll Jump to behavior
Source: C:\Users\user\AppData\Roaming\GrOcCQC\GrOcCQC.exe Section loaded: rtutils.dll Jump to behavior
Source: C:\Users\user\AppData\Roaming\GrOcCQC\GrOcCQC.exe Section loaded: mswsock.dll Jump to behavior
Source: C:\Users\user\AppData\Roaming\GrOcCQC\GrOcCQC.exe Section loaded: winhttp.dll Jump to behavior
Source: C:\Users\user\AppData\Roaming\GrOcCQC\GrOcCQC.exe Section loaded: ondemandconnroutehelper.dll Jump to behavior
Source: C:\Users\user\AppData\Roaming\GrOcCQC\GrOcCQC.exe Section loaded: iphlpapi.dll Jump to behavior
Source: C:\Users\user\AppData\Roaming\GrOcCQC\GrOcCQC.exe Section loaded: dhcpcsvc6.dll Jump to behavior
Source: C:\Users\user\AppData\Roaming\GrOcCQC\GrOcCQC.exe Section loaded: dhcpcsvc.dll Jump to behavior
Source: C:\Users\user\AppData\Roaming\GrOcCQC\GrOcCQC.exe Section loaded: dnsapi.dll Jump to behavior
Source: C:\Users\user\AppData\Roaming\GrOcCQC\GrOcCQC.exe Section loaded: winnsi.dll Jump to behavior
Source: C:\Users\user\AppData\Roaming\GrOcCQC\GrOcCQC.exe Section loaded: rasadhlp.dll Jump to behavior
Source: C:\Users\user\AppData\Roaming\GrOcCQC\GrOcCQC.exe Section loaded: fwpuclnt.dll Jump to behavior
Source: C:\Users\user\AppData\Roaming\GrOcCQC\GrOcCQC.exe Section loaded: vaultcli.dll Jump to behavior
Source: C:\Users\user\AppData\Roaming\GrOcCQC\GrOcCQC.exe Section loaded: wintypes.dll Jump to behavior
Source: C:\Users\user\AppData\Roaming\GrOcCQC\GrOcCQC.exe Section loaded: secur32.dll Jump to behavior
Source: C:\Users\user\AppData\Roaming\GrOcCQC\GrOcCQC.exe Section loaded: schannel.dll Jump to behavior
Source: C:\Users\user\AppData\Roaming\GrOcCQC\GrOcCQC.exe Section loaded: mskeyprotect.dll Jump to behavior
Source: C:\Users\user\AppData\Roaming\GrOcCQC\GrOcCQC.exe Section loaded: ntasn1.dll Jump to behavior
Source: C:\Users\user\AppData\Roaming\GrOcCQC\GrOcCQC.exe Section loaded: ncrypt.dll Jump to behavior
Source: C:\Users\user\AppData\Roaming\GrOcCQC\GrOcCQC.exe Section loaded: ncryptsslp.dll Jump to behavior
Source: C:\Users\user\AppData\Roaming\GrOcCQC\GrOcCQC.exe Section loaded: msasn1.dll Jump to behavior
Source: C:\Users\user\AppData\Roaming\GrOcCQC\GrOcCQC.exe Section loaded: mscoree.dll Jump to behavior
Source: C:\Users\user\AppData\Roaming\GrOcCQC\GrOcCQC.exe Section loaded: kernel.appcore.dll Jump to behavior
Source: C:\Users\user\AppData\Roaming\GrOcCQC\GrOcCQC.exe Section loaded: version.dll Jump to behavior
Source: C:\Users\user\AppData\Roaming\GrOcCQC\GrOcCQC.exe Section loaded: vcruntime140_clr0400.dll Jump to behavior
Source: C:\Users\user\AppData\Roaming\GrOcCQC\GrOcCQC.exe Section loaded: ucrtbase_clr0400.dll Jump to behavior
Source: C:\Users\user\AppData\Roaming\GrOcCQC\GrOcCQC.exe Section loaded: ucrtbase_clr0400.dll Jump to behavior
Source: C:\Users\user\AppData\Roaming\GrOcCQC\GrOcCQC.exe Section loaded: uxtheme.dll Jump to behavior
Source: C:\Users\user\AppData\Roaming\GrOcCQC\GrOcCQC.exe Section loaded: windows.storage.dll Jump to behavior
Source: C:\Users\user\AppData\Roaming\GrOcCQC\GrOcCQC.exe Section loaded: wldp.dll Jump to behavior
Source: C:\Users\user\AppData\Roaming\GrOcCQC\GrOcCQC.exe Section loaded: profapi.dll Jump to behavior
Source: C:\Users\user\AppData\Roaming\GrOcCQC\GrOcCQC.exe Section loaded: cryptsp.dll Jump to behavior
Source: C:\Users\user\AppData\Roaming\GrOcCQC\GrOcCQC.exe Section loaded: rsaenh.dll Jump to behavior
Source: C:\Users\user\AppData\Roaming\GrOcCQC\GrOcCQC.exe Section loaded: cryptbase.dll Jump to behavior
Source: C:\Users\user\AppData\Roaming\GrOcCQC\GrOcCQC.exe Section loaded: dwrite.dll Jump to behavior
Source: C:\Users\user\AppData\Roaming\GrOcCQC\GrOcCQC.exe Section loaded: textshaping.dll Jump to behavior
Source: C:\Users\user\AppData\Roaming\GrOcCQC\GrOcCQC.exe Section loaded: windowscodecs.dll Jump to behavior
Source: C:\Users\user\AppData\Roaming\GrOcCQC\GrOcCQC.exe Section loaded: amsi.dll Jump to behavior
Source: C:\Users\user\AppData\Roaming\GrOcCQC\GrOcCQC.exe Section loaded: userenv.dll Jump to behavior
Source: C:\Users\user\AppData\Roaming\GrOcCQC\GrOcCQC.exe Section loaded: msasn1.dll Jump to behavior
Source: C:\Users\user\AppData\Roaming\GrOcCQC\GrOcCQC.exe Section loaded: gpapi.dll Jump to behavior
Source: C:\Users\user\AppData\Roaming\GrOcCQC\GrOcCQC.exe Section loaded: urlmon.dll Jump to behavior
Source: C:\Users\user\AppData\Roaming\GrOcCQC\GrOcCQC.exe Section loaded: iertutil.dll Jump to behavior
Source: C:\Users\user\AppData\Roaming\GrOcCQC\GrOcCQC.exe Section loaded: srvcli.dll Jump to behavior
Source: C:\Users\user\AppData\Roaming\GrOcCQC\GrOcCQC.exe Section loaded: netutils.dll Jump to behavior
Source: C:\Users\user\AppData\Roaming\GrOcCQC\GrOcCQC.exe Section loaded: sspicli.dll Jump to behavior
Source: C:\Users\user\AppData\Roaming\GrOcCQC\GrOcCQC.exe Section loaded: propsys.dll Jump to behavior
Source: C:\Users\user\AppData\Roaming\GrOcCQC\GrOcCQC.exe Section loaded: mscoree.dll Jump to behavior
Source: C:\Users\user\AppData\Roaming\GrOcCQC\GrOcCQC.exe Section loaded: kernel.appcore.dll Jump to behavior
Source: C:\Users\user\AppData\Roaming\GrOcCQC\GrOcCQC.exe Section loaded: version.dll Jump to behavior
Source: C:\Users\user\AppData\Roaming\GrOcCQC\GrOcCQC.exe Section loaded: vcruntime140_clr0400.dll Jump to behavior
Source: C:\Users\user\AppData\Roaming\GrOcCQC\GrOcCQC.exe Section loaded: ucrtbase_clr0400.dll Jump to behavior
Source: C:\Users\user\AppData\Roaming\GrOcCQC\GrOcCQC.exe Section loaded: ucrtbase_clr0400.dll Jump to behavior
Source: C:\Users\user\AppData\Roaming\GrOcCQC\GrOcCQC.exe Section loaded: uxtheme.dll Jump to behavior
Source: C:\Users\user\AppData\Roaming\GrOcCQC\GrOcCQC.exe Section loaded: windows.storage.dll Jump to behavior
Source: C:\Users\user\AppData\Roaming\GrOcCQC\GrOcCQC.exe Section loaded: wldp.dll Jump to behavior
Source: C:\Users\user\AppData\Roaming\GrOcCQC\GrOcCQC.exe Section loaded: profapi.dll Jump to behavior
Source: C:\Users\user\AppData\Roaming\GrOcCQC\GrOcCQC.exe Section loaded: cryptsp.dll Jump to behavior
Source: C:\Users\user\AppData\Roaming\GrOcCQC\GrOcCQC.exe Section loaded: rsaenh.dll Jump to behavior
Source: C:\Users\user\AppData\Roaming\GrOcCQC\GrOcCQC.exe Section loaded: cryptbase.dll Jump to behavior
Source: C:\Users\user\AppData\Roaming\GrOcCQC\GrOcCQC.exe Section loaded: wbemcomn.dll Jump to behavior
Source: C:\Users\user\AppData\Roaming\GrOcCQC\GrOcCQC.exe Section loaded: amsi.dll Jump to behavior
Source: C:\Users\user\AppData\Roaming\GrOcCQC\GrOcCQC.exe Section loaded: userenv.dll Jump to behavior
Source: C:\Users\user\AppData\Roaming\GrOcCQC\GrOcCQC.exe Section loaded: sspicli.dll Jump to behavior
Source: C:\Users\user\AppData\Roaming\GrOcCQC\GrOcCQC.exe Section loaded: rasapi32.dll Jump to behavior
Source: C:\Users\user\AppData\Roaming\GrOcCQC\GrOcCQC.exe Section loaded: rasman.dll Jump to behavior
Source: C:\Users\user\AppData\Roaming\GrOcCQC\GrOcCQC.exe Section loaded: rtutils.dll Jump to behavior
Source: C:\Users\user\AppData\Roaming\GrOcCQC\GrOcCQC.exe Section loaded: mswsock.dll Jump to behavior
Source: C:\Users\user\AppData\Roaming\GrOcCQC\GrOcCQC.exe Section loaded: winhttp.dll Jump to behavior
Source: C:\Users\user\AppData\Roaming\GrOcCQC\GrOcCQC.exe Section loaded: ondemandconnroutehelper.dll Jump to behavior
Source: C:\Users\user\AppData\Roaming\GrOcCQC\GrOcCQC.exe Section loaded: iphlpapi.dll Jump to behavior
Source: C:\Users\user\AppData\Roaming\GrOcCQC\GrOcCQC.exe Section loaded: dhcpcsvc6.dll Jump to behavior
Source: C:\Users\user\AppData\Roaming\GrOcCQC\GrOcCQC.exe Section loaded: dhcpcsvc.dll Jump to behavior
Source: C:\Users\user\AppData\Roaming\GrOcCQC\GrOcCQC.exe Section loaded: dnsapi.dll Jump to behavior
Source: C:\Users\user\AppData\Roaming\GrOcCQC\GrOcCQC.exe Section loaded: winnsi.dll Jump to behavior
Source: C:\Users\user\AppData\Roaming\GrOcCQC\GrOcCQC.exe Section loaded: rasadhlp.dll Jump to behavior
Source: C:\Users\user\AppData\Roaming\GrOcCQC\GrOcCQC.exe Section loaded: fwpuclnt.dll Jump to behavior
Source: C:\Users\user\AppData\Roaming\GrOcCQC\GrOcCQC.exe Section loaded: vaultcli.dll Jump to behavior
Source: C:\Users\user\AppData\Roaming\GrOcCQC\GrOcCQC.exe Section loaded: wintypes.dll Jump to behavior
Source: C:\Users\user\AppData\Roaming\GrOcCQC\GrOcCQC.exe Section loaded: secur32.dll Jump to behavior
Source: C:\Users\user\AppData\Roaming\GrOcCQC\GrOcCQC.exe Section loaded: schannel.dll Jump to behavior
Source: C:\Users\user\AppData\Roaming\GrOcCQC\GrOcCQC.exe Section loaded: mskeyprotect.dll Jump to behavior
Source: C:\Users\user\AppData\Roaming\GrOcCQC\GrOcCQC.exe Section loaded: ntasn1.dll Jump to behavior
Source: C:\Users\user\AppData\Roaming\GrOcCQC\GrOcCQC.exe Section loaded: ncrypt.dll Jump to behavior
Source: C:\Users\user\AppData\Roaming\GrOcCQC\GrOcCQC.exe Section loaded: ncryptsslp.dll Jump to behavior
Source: C:\Users\user\AppData\Roaming\GrOcCQC\GrOcCQC.exe Section loaded: msasn1.dll Jump to behavior
Source: C:\Users\user\Desktop\Reiven RFQ-27-05-2024.exe Key value queried: HKEY_LOCAL_MACHINE\SOFTWARE\Classes\WOW6432Node\CLSID\{0EE7644B-1BAD-48B1-9889-0281C206EB85}\InprocServer32 Jump to behavior
Source: Window Recorder Window detected: More than 3 window changes detected
Source: C:\Users\user\Desktop\Reiven RFQ-27-05-2024.exe File opened: C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscorrc.dll Jump to behavior
Source: C:\Users\user\Desktop\Reiven RFQ-27-05-2024.exe Key opened: HKEY_CURRENT_USER\Software\Microsoft\Office\11.0\Outlook\Profiles Jump to behavior
Source: Reiven RFQ-27-05-2024.exe Static PE information: data directory type: IMAGE_DIRECTORY_ENTRY_COM_DESCRIPTOR
Source: Reiven RFQ-27-05-2024.exe Static PE information: DYNAMIC_BASE, NX_COMPAT, NO_SEH, TERMINAL_SERVER_AWARE

Data Obfuscation

barindex
Source: Reiven RFQ-27-05-2024.exe, Form1.cs .Net Code: InitializeComponent System.AppDomain.Load(byte[])
Source: Reiven RFQ-27-05-2024.exe, Form1.cs .Net Code: InitializeComponent contains xor as well as GetObject
Source: 0.2.Reiven RFQ-27-05-2024.exe.87e0000.7.raw.unpack, P4KdTDTBvmf8mLrGWD.cs .Net Code: MHRV8BRRTS System.Reflection.Assembly.Load(byte[])
Source: 0.2.Reiven RFQ-27-05-2024.exe.405e740.3.raw.unpack, P4KdTDTBvmf8mLrGWD.cs .Net Code: MHRV8BRRTS System.Reflection.Assembly.Load(byte[])
Source: 0.2.Reiven RFQ-27-05-2024.exe.2c84900.0.raw.unpack, .cs .Net Code: System.Reflection.Assembly.Load(byte[])
Source: 0.2.Reiven RFQ-27-05-2024.exe.72b0000.4.raw.unpack, .cs .Net Code: System.Reflection.Assembly.Load(byte[])
Source: C:\Users\user\Desktop\Reiven RFQ-27-05-2024.exe Code function: 0_2_0127F112 push esp; iretd 0_2_0127F119
Source: C:\Users\user\Desktop\Reiven RFQ-27-05-2024.exe Code function: 0_2_0127F110 pushad ; iretd 0_2_0127F111
Source: C:\Users\user\Desktop\Reiven RFQ-27-05-2024.exe Code function: 0_2_05207538 push eax; mov dword ptr [esp], ecx 0_2_0520753C
Source: C:\Users\user\Desktop\Reiven RFQ-27-05-2024.exe Code function: 3_2_00EEF590 push eax; retn 0624h 3_2_00EEF629
Source: C:\Users\user\Desktop\Reiven RFQ-27-05-2024.exe Code function: 3_2_00EEF62C push eax; retn 0624h 3_2_00EEF629
Source: C:\Users\user\Desktop\Reiven RFQ-27-05-2024.exe Code function: 3_2_06294A50 push 640639DAh; iretd 3_2_06294A5D
Source: C:\Users\user\AppData\Roaming\GrOcCQC\GrOcCQC.exe Code function: 4_2_00A4F110 pushad ; iretd 4_2_00A4F111
Source: C:\Users\user\AppData\Roaming\GrOcCQC\GrOcCQC.exe Code function: 6_2_0104F450 push eax; retn 064Ah 6_2_0104F4F9
Source: C:\Users\user\AppData\Roaming\GrOcCQC\GrOcCQC.exe Code function: 6_2_064F57E0 push es; ret 6_2_064F57F0
Source: C:\Users\user\AppData\Roaming\GrOcCQC\GrOcCQC.exe Code function: 7_2_0123F110 pushad ; iretd 7_2_0123F111
Source: C:\Users\user\AppData\Roaming\GrOcCQC\GrOcCQC.exe Code function: 8_2_0160F450 push eax; retn 06BDh 8_2_0160F4F9
Source: C:\Users\user\AppData\Roaming\GrOcCQC\GrOcCQC.exe Code function: 8_2_06C257EF push es; ret 8_2_06C257F0
Source: C:\Users\user\AppData\Roaming\GrOcCQC\GrOcCQC.exe Code function: 8_2_06C21E43 push edi; ret 8_2_06C21E52
Source: C:\Users\user\AppData\Roaming\GrOcCQC\GrOcCQC.exe Code function: 8_2_06C21F05 push esi; ret 8_2_06C21F06
Source: C:\Users\user\AppData\Roaming\GrOcCQC\GrOcCQC.exe Code function: 8_2_07130E28 push cs; ret 8_2_07130E36
Source: C:\Users\user\AppData\Roaming\GrOcCQC\GrOcCQC.exe Code function: 8_2_07132D98 push cs; ret 8_2_07132DA6
Source: C:\Users\user\AppData\Roaming\GrOcCQC\GrOcCQC.exe Code function: 8_2_071311BF push es; ret 8_2_071311C0
Source: C:\Users\user\AppData\Roaming\GrOcCQC\GrOcCQC.exe Code function: 8_2_071311D0 push es; ret 8_2_071311DE
Source: C:\Users\user\AppData\Roaming\GrOcCQC\GrOcCQC.exe Code function: 8_2_07130DCB push cs; ret 8_2_07130E36
Source: Reiven RFQ-27-05-2024.exe Static PE information: section name: .text entropy: 7.979508501795828
Source: 0.2.Reiven RFQ-27-05-2024.exe.87e0000.7.raw.unpack, VT7u85EPcyxFxht16X.cs High entropy of concatenated method names: 'ToString', 'mnicltypn6', 'HQgci1aBQc', 'V7HcfjBpCG', 'tXwcxd1siI', 'RTkcNSLlAB', 'lVUc3Y12ms', 'KW5cheTPlC', 'REac4LbFtb', 'Vt4cdrXUpU'
Source: 0.2.Reiven RFQ-27-05-2024.exe.87e0000.7.raw.unpack, Dyo3o0CjnKg05IjRlK.cs High entropy of concatenated method names: 'IDD8Cd3NI', 'NwQuhlZRx', 'Xsv9b60Ig', 'RLAPxdQZF', 'r7NwSQmcv', 'HiZAWdaxj', 'UoWgII3SwUx3nv6JoS', 'UIGhTGRoppJdEOBmou', 'zTqHV0dIO', 'FhJCeqE32'
Source: 0.2.Reiven RFQ-27-05-2024.exe.87e0000.7.raw.unpack, AERr51V6NUta2MiOZ5P.cs High entropy of concatenated method names: 'CanConvertFrom', 'ConvertFrom', 'ConvertTo', 'vm1CUcJX5x', 'v9GCLc08bu', 'STKCvjuLlo', 'ji1CnE2BDa', 's28CJ2A0I3', 'gF6Cgv9p24', 'brGCqCRpWj'
Source: 0.2.Reiven RFQ-27-05-2024.exe.87e0000.7.raw.unpack, UfgY1ruWlio2rsgwZZ.cs High entropy of concatenated method names: 'X4vHp3RuRe', 'YdUHOIe7hT', 'vWRHbfVL2w', 'rpeHDdCBuL', 'S2QHkiuxFd', 'FEZHjOxWQI', 'UmeHZCdLen', 'sUsH0ndGXx', 'x2eHFahZFh', 'tYLH5Psyvg'
Source: 0.2.Reiven RFQ-27-05-2024.exe.87e0000.7.raw.unpack, guvmcKet70gVvaXhNS.cs High entropy of concatenated method names: 'ic2HeBKBT7', 'k6yHintgYb', 'gilHfB3MZw', 'YURHxgdaEh', 'ggnHUCrJHu', 'LZuHNJp6N9', 'Next', 'Next', 'Next', 'NextBytes'
Source: 0.2.Reiven RFQ-27-05-2024.exe.87e0000.7.raw.unpack, P4KdTDTBvmf8mLrGWD.cs High entropy of concatenated method names: 's9Z6swXfdX', 'lxr6pdLyDJ', 'ER36OuCUwR', 'LPH6bcq75S', 'aVI6DxRueD', 'kEL6kTiGxC', 'MB76jRbw7c', 'ENI6Zbv6LB', 'WR160QbKkB', 'fj96FIxlJr'
Source: 0.2.Reiven RFQ-27-05-2024.exe.87e0000.7.raw.unpack, c9EPPpoJp9IOiyOxSO.cs High entropy of concatenated method names: 'LlHDMDuXuG', 'sfVDPQoyW3', 'Y6vbfHdMbO', 'm2jbx3Hi89', 'lJHbNnvY2k', 'smqb3ti04y', 'cHEbhkUo1T', 'xnxb4llBqZ', 'BFebd4c0va', 'TRBbRabtye'
Source: 0.2.Reiven RFQ-27-05-2024.exe.87e0000.7.raw.unpack, ivhM9fVQvSFUERDvrat.cs High entropy of concatenated method names: 'geNTEtp75d', 'vvVTyw0rMK', 'IewT8reV4r', 'RrrTu28Du7', 'EbDTMlDTS7', 'Fv8T9iPDk9', 'CcBTPZuWeL', 'Wj0TXKSglc', 'lnRTwu2ASx', 'AsFTAWywYM'
Source: 0.2.Reiven RFQ-27-05-2024.exe.87e0000.7.raw.unpack, rwDUsR9pO3MhVwGISd.cs High entropy of concatenated method names: 'RHnksgKukK', 'nlGkOkLS77', 'GDPkDkoF6G', 'ibukjSqolU', 'QRTkZyoauJ', 'ynuDJ0xFQS', 'H6FDgTNKS8', 'h8rDqlWQw5', 'wq3DKjwDx5', 'cl2DYLgM2M'
Source: 0.2.Reiven RFQ-27-05-2024.exe.87e0000.7.raw.unpack, yQMqXFPtsP075MpgE6.cs High entropy of concatenated method names: 'Dispose', 'vAEWYYSrL2', 'dHoBiIeeiv', 'C0ZSSsCcIT', 'qEXWorGcKq', 'PtNWz5Yqu6', 'ProcessDialogKey', 'WNABQNTaON', 's4DBWVg5XP', 'irOBBc1ME4'
Source: 0.2.Reiven RFQ-27-05-2024.exe.87e0000.7.raw.unpack, SEmrleGJEyqXHgs1g4.cs High entropy of concatenated method names: 'TCXrXEdD5D', 'ilOrw4v0Zc', 'B7preHP8WL', 'Cr4ri3CayK', 'leurxe10h0', 'QdWrNV7uZI', 'hNwrhoUtNX', 'W6Gr4STL3r', 'V9QrR9C51V', 'zborl0j3rw'
Source: 0.2.Reiven RFQ-27-05-2024.exe.87e0000.7.raw.unpack, gBDvjAH2DoZAb4aD0e.cs High entropy of concatenated method names: 'tNtjEkYmdo', 'XdUjyTNPR2', 'cttj8AAVOD', 'aXLjuQG0SA', 'mOkjMhT7Jc', 'O65j9wB2gr', 'rD3jPBWmTP', 'GG6jXrbUxU', 't6UjwWmxDa', 'VRHjAe5NPV'
Source: 0.2.Reiven RFQ-27-05-2024.exe.87e0000.7.raw.unpack, ignCQygyEo9ouYrrrQ.cs High entropy of concatenated method names: 'yXxtKnWr5h', 'p12totxfrx', 'GZqHQK2Fej', 'oxCHWODSMn', 'idjtlPE7nM', 'ToQt7xo7O2', 'iZpta6xqTr', 'GdKtUfrbhZ', 'SnptL4rtwf', 'nNatvcQW0E'
Source: 0.2.Reiven RFQ-27-05-2024.exe.87e0000.7.raw.unpack, ReVfZx0ugCj74bfC63.cs High entropy of concatenated method names: 'lyqtFHCays', 'RbXt5H0iM6', 'ToString', 'jrotpUsjVT', 'nNItOKodTI', 'KertbOtP2D', 'qb9tDQX3n4', 'CaOtkrCmCV', 'XFptjxgyLw', 'Dh8tZEfcE0'
Source: 0.2.Reiven RFQ-27-05-2024.exe.87e0000.7.raw.unpack, G7WrotiTcmyOUhugbw.cs High entropy of concatenated method names: 'O2mWj3KumO', 'bnCWZND0VI', 'j1oWF6LxgY', 'dihW5q9Ub9', 'wRiWIVf3mV', 'IUGWciGlVd', 'Gk7C3bUZgRo3PCRK8d', 'HtYLCNmCDFhxl9o9FI', 'NYqWW72Wc1', 'CoYW6AOwXe'
Source: 0.2.Reiven RFQ-27-05-2024.exe.87e0000.7.raw.unpack, SZ1ENUql6y3pgYG1WV.cs High entropy of concatenated method names: 'TBwIRdDUvx', 'iTAI7qRnmR', 'o1mIUrHoZI', 'ajwIL1XEuB', 'x01IiLMV0P', 'xDuIfeACGe', 'jjLIxux4Nv', 'ygPINHYuac', 'Oc3I3tYBcd', 'zojIhhaXnC'
Source: 0.2.Reiven RFQ-27-05-2024.exe.87e0000.7.raw.unpack, rvRaEEwXRaQqPMRw1I.cs High entropy of concatenated method names: 'fcsTWQG4VV', 'JHyT6egxaR', 'bvNTVl9JQS', 'tYMTpcpH55', 'gCMTOC42bm', 'QSaTDYx0OH', 'lXNTkextCU', 'uW1HqaTxI5', 'SmxHKoi21s', 'aGGHYV1g42'
Source: 0.2.Reiven RFQ-27-05-2024.exe.87e0000.7.raw.unpack, ShJNeJ5woXxHDCbUPp.cs High entropy of concatenated method names: 'sH2OUKfjqZ', 'mMUOLa067S', 'XmwOvXy677', 'UBZOn6HOOB', 'UWHOJA158K', 'Tv1Og0re5V', 'hw2OqoDAmD', 'oGNOKVyib8', 'VqXOYnm4D4', 'uVqOoqLitS'
Source: 0.2.Reiven RFQ-27-05-2024.exe.87e0000.7.raw.unpack, BdoLQSZw3jBOqXvgae.cs High entropy of concatenated method names: 'EditValue', 'GetEditStyle', 'B8HBYP5nAx', 'YVwBogUy5P', 'k3DBz9hwFR', 'TJb6QoP7Pm', 'mD76Wy1r30', 'hE46BEkKWQ', 'hNB66Mtikc', 'PBtckAkF8Ry8wNShMeP'
Source: 0.2.Reiven RFQ-27-05-2024.exe.87e0000.7.raw.unpack, NLcbcOvujMkjYjiFrg.cs High entropy of concatenated method names: 'JsSbu7d4Yb', 'JZ5b9Y2dfF', 'OopbXmUflu', 'KIbbwW9E3e', 'SVobIG6dHP', 'wipbc7iMf3', 'PVCbtupnxH', 'H12bHP4ikM', 'SsBbTjJkVm', 'tMMbCc8Xmc'
Source: 0.2.Reiven RFQ-27-05-2024.exe.405e740.3.raw.unpack, VT7u85EPcyxFxht16X.cs High entropy of concatenated method names: 'ToString', 'mnicltypn6', 'HQgci1aBQc', 'V7HcfjBpCG', 'tXwcxd1siI', 'RTkcNSLlAB', 'lVUc3Y12ms', 'KW5cheTPlC', 'REac4LbFtb', 'Vt4cdrXUpU'
Source: 0.2.Reiven RFQ-27-05-2024.exe.405e740.3.raw.unpack, Dyo3o0CjnKg05IjRlK.cs High entropy of concatenated method names: 'IDD8Cd3NI', 'NwQuhlZRx', 'Xsv9b60Ig', 'RLAPxdQZF', 'r7NwSQmcv', 'HiZAWdaxj', 'UoWgII3SwUx3nv6JoS', 'UIGhTGRoppJdEOBmou', 'zTqHV0dIO', 'FhJCeqE32'
Source: 0.2.Reiven RFQ-27-05-2024.exe.405e740.3.raw.unpack, AERr51V6NUta2MiOZ5P.cs High entropy of concatenated method names: 'CanConvertFrom', 'ConvertFrom', 'ConvertTo', 'vm1CUcJX5x', 'v9GCLc08bu', 'STKCvjuLlo', 'ji1CnE2BDa', 's28CJ2A0I3', 'gF6Cgv9p24', 'brGCqCRpWj'
Source: 0.2.Reiven RFQ-27-05-2024.exe.405e740.3.raw.unpack, UfgY1ruWlio2rsgwZZ.cs High entropy of concatenated method names: 'X4vHp3RuRe', 'YdUHOIe7hT', 'vWRHbfVL2w', 'rpeHDdCBuL', 'S2QHkiuxFd', 'FEZHjOxWQI', 'UmeHZCdLen', 'sUsH0ndGXx', 'x2eHFahZFh', 'tYLH5Psyvg'
Source: 0.2.Reiven RFQ-27-05-2024.exe.405e740.3.raw.unpack, guvmcKet70gVvaXhNS.cs High entropy of concatenated method names: 'ic2HeBKBT7', 'k6yHintgYb', 'gilHfB3MZw', 'YURHxgdaEh', 'ggnHUCrJHu', 'LZuHNJp6N9', 'Next', 'Next', 'Next', 'NextBytes'
Source: 0.2.Reiven RFQ-27-05-2024.exe.405e740.3.raw.unpack, P4KdTDTBvmf8mLrGWD.cs High entropy of concatenated method names: 's9Z6swXfdX', 'lxr6pdLyDJ', 'ER36OuCUwR', 'LPH6bcq75S', 'aVI6DxRueD', 'kEL6kTiGxC', 'MB76jRbw7c', 'ENI6Zbv6LB', 'WR160QbKkB', 'fj96FIxlJr'
Source: 0.2.Reiven RFQ-27-05-2024.exe.405e740.3.raw.unpack, c9EPPpoJp9IOiyOxSO.cs High entropy of concatenated method names: 'LlHDMDuXuG', 'sfVDPQoyW3', 'Y6vbfHdMbO', 'm2jbx3Hi89', 'lJHbNnvY2k', 'smqb3ti04y', 'cHEbhkUo1T', 'xnxb4llBqZ', 'BFebd4c0va', 'TRBbRabtye'
Source: 0.2.Reiven RFQ-27-05-2024.exe.405e740.3.raw.unpack, ivhM9fVQvSFUERDvrat.cs High entropy of concatenated method names: 'geNTEtp75d', 'vvVTyw0rMK', 'IewT8reV4r', 'RrrTu28Du7', 'EbDTMlDTS7', 'Fv8T9iPDk9', 'CcBTPZuWeL', 'Wj0TXKSglc', 'lnRTwu2ASx', 'AsFTAWywYM'
Source: 0.2.Reiven RFQ-27-05-2024.exe.405e740.3.raw.unpack, rwDUsR9pO3MhVwGISd.cs High entropy of concatenated method names: 'RHnksgKukK', 'nlGkOkLS77', 'GDPkDkoF6G', 'ibukjSqolU', 'QRTkZyoauJ', 'ynuDJ0xFQS', 'H6FDgTNKS8', 'h8rDqlWQw5', 'wq3DKjwDx5', 'cl2DYLgM2M'
Source: 0.2.Reiven RFQ-27-05-2024.exe.405e740.3.raw.unpack, yQMqXFPtsP075MpgE6.cs High entropy of concatenated method names: 'Dispose', 'vAEWYYSrL2', 'dHoBiIeeiv', 'C0ZSSsCcIT', 'qEXWorGcKq', 'PtNWz5Yqu6', 'ProcessDialogKey', 'WNABQNTaON', 's4DBWVg5XP', 'irOBBc1ME4'
Source: 0.2.Reiven RFQ-27-05-2024.exe.405e740.3.raw.unpack, SEmrleGJEyqXHgs1g4.cs High entropy of concatenated method names: 'TCXrXEdD5D', 'ilOrw4v0Zc', 'B7preHP8WL', 'Cr4ri3CayK', 'leurxe10h0', 'QdWrNV7uZI', 'hNwrhoUtNX', 'W6Gr4STL3r', 'V9QrR9C51V', 'zborl0j3rw'
Source: 0.2.Reiven RFQ-27-05-2024.exe.405e740.3.raw.unpack, gBDvjAH2DoZAb4aD0e.cs High entropy of concatenated method names: 'tNtjEkYmdo', 'XdUjyTNPR2', 'cttj8AAVOD', 'aXLjuQG0SA', 'mOkjMhT7Jc', 'O65j9wB2gr', 'rD3jPBWmTP', 'GG6jXrbUxU', 't6UjwWmxDa', 'VRHjAe5NPV'
Source: 0.2.Reiven RFQ-27-05-2024.exe.405e740.3.raw.unpack, ignCQygyEo9ouYrrrQ.cs High entropy of concatenated method names: 'yXxtKnWr5h', 'p12totxfrx', 'GZqHQK2Fej', 'oxCHWODSMn', 'idjtlPE7nM', 'ToQt7xo7O2', 'iZpta6xqTr', 'GdKtUfrbhZ', 'SnptL4rtwf', 'nNatvcQW0E'
Source: 0.2.Reiven RFQ-27-05-2024.exe.405e740.3.raw.unpack, ReVfZx0ugCj74bfC63.cs High entropy of concatenated method names: 'lyqtFHCays', 'RbXt5H0iM6', 'ToString', 'jrotpUsjVT', 'nNItOKodTI', 'KertbOtP2D', 'qb9tDQX3n4', 'CaOtkrCmCV', 'XFptjxgyLw', 'Dh8tZEfcE0'
Source: 0.2.Reiven RFQ-27-05-2024.exe.405e740.3.raw.unpack, G7WrotiTcmyOUhugbw.cs High entropy of concatenated method names: 'O2mWj3KumO', 'bnCWZND0VI', 'j1oWF6LxgY', 'dihW5q9Ub9', 'wRiWIVf3mV', 'IUGWciGlVd', 'Gk7C3bUZgRo3PCRK8d', 'HtYLCNmCDFhxl9o9FI', 'NYqWW72Wc1', 'CoYW6AOwXe'
Source: 0.2.Reiven RFQ-27-05-2024.exe.405e740.3.raw.unpack, SZ1ENUql6y3pgYG1WV.cs High entropy of concatenated method names: 'TBwIRdDUvx', 'iTAI7qRnmR', 'o1mIUrHoZI', 'ajwIL1XEuB', 'x01IiLMV0P', 'xDuIfeACGe', 'jjLIxux4Nv', 'ygPINHYuac', 'Oc3I3tYBcd', 'zojIhhaXnC'
Source: 0.2.Reiven RFQ-27-05-2024.exe.405e740.3.raw.unpack, rvRaEEwXRaQqPMRw1I.cs High entropy of concatenated method names: 'fcsTWQG4VV', 'JHyT6egxaR', 'bvNTVl9JQS', 'tYMTpcpH55', 'gCMTOC42bm', 'QSaTDYx0OH', 'lXNTkextCU', 'uW1HqaTxI5', 'SmxHKoi21s', 'aGGHYV1g42'
Source: 0.2.Reiven RFQ-27-05-2024.exe.405e740.3.raw.unpack, ShJNeJ5woXxHDCbUPp.cs High entropy of concatenated method names: 'sH2OUKfjqZ', 'mMUOLa067S', 'XmwOvXy677', 'UBZOn6HOOB', 'UWHOJA158K', 'Tv1Og0re5V', 'hw2OqoDAmD', 'oGNOKVyib8', 'VqXOYnm4D4', 'uVqOoqLitS'
Source: 0.2.Reiven RFQ-27-05-2024.exe.405e740.3.raw.unpack, BdoLQSZw3jBOqXvgae.cs High entropy of concatenated method names: 'EditValue', 'GetEditStyle', 'B8HBYP5nAx', 'YVwBogUy5P', 'k3DBz9hwFR', 'TJb6QoP7Pm', 'mD76Wy1r30', 'hE46BEkKWQ', 'hNB66Mtikc', 'PBtckAkF8Ry8wNShMeP'
Source: 0.2.Reiven RFQ-27-05-2024.exe.405e740.3.raw.unpack, NLcbcOvujMkjYjiFrg.cs High entropy of concatenated method names: 'JsSbu7d4Yb', 'JZ5b9Y2dfF', 'OopbXmUflu', 'KIbbwW9E3e', 'SVobIG6dHP', 'wipbc7iMf3', 'PVCbtupnxH', 'H12bHP4ikM', 'SsBbTjJkVm', 'tMMbCc8Xmc'
Source: C:\Users\user\Desktop\Reiven RFQ-27-05-2024.exe File created: C:\Users\user\AppData\Roaming\GrOcCQC\GrOcCQC.exe Jump to dropped file
Source: C:\Users\user\Desktop\Reiven RFQ-27-05-2024.exe Registry value created or modified: HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run GrOcCQC Jump to behavior
Source: C:\Users\user\Desktop\Reiven RFQ-27-05-2024.exe Registry value created or modified: HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run GrOcCQC Jump to behavior

Hooking and other Techniques for Hiding and Protection

barindex
Source: C:\Users\user\Desktop\Reiven RFQ-27-05-2024.exe File opened: C:\Users\user\AppData\Roaming\GrOcCQC\GrOcCQC.exe:Zone.Identifier read attributes | delete Jump to behavior
Source: C:\Users\user\Desktop\Reiven RFQ-27-05-2024.exe Registry key monitored for changes: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\AutoUpdate Jump to behavior
Source: C:\Users\user\AppData\Roaming\GrOcCQC\GrOcCQC.exe Registry key monitored for changes: HKEY_CURRENT_USER_Classes Jump to behavior
Source: C:\Users\user\AppData\Roaming\GrOcCQC\GrOcCQC.exe Registry key monitored for changes: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\AutoUpdate Jump to behavior
Source: C:\Users\user\Desktop\Reiven RFQ-27-05-2024.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Users\user\Desktop\Reiven RFQ-27-05-2024.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Users\user\Desktop\Reiven RFQ-27-05-2024.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Users\user\Desktop\Reiven RFQ-27-05-2024.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Users\user\Desktop\Reiven RFQ-27-05-2024.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Users\user\Desktop\Reiven RFQ-27-05-2024.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Users\user\Desktop\Reiven RFQ-27-05-2024.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Users\user\Desktop\Reiven RFQ-27-05-2024.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Users\user\Desktop\Reiven RFQ-27-05-2024.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Users\user\Desktop\Reiven RFQ-27-05-2024.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Users\user\Desktop\Reiven RFQ-27-05-2024.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Users\user\Desktop\Reiven RFQ-27-05-2024.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Users\user\Desktop\Reiven RFQ-27-05-2024.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Users\user\Desktop\Reiven RFQ-27-05-2024.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Users\user\Desktop\Reiven RFQ-27-05-2024.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Users\user\Desktop\Reiven RFQ-27-05-2024.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Users\user\Desktop\Reiven RFQ-27-05-2024.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Users\user\Desktop\Reiven RFQ-27-05-2024.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Users\user\Desktop\Reiven RFQ-27-05-2024.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Users\user\Desktop\Reiven RFQ-27-05-2024.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Users\user\Desktop\Reiven RFQ-27-05-2024.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Users\user\Desktop\Reiven RFQ-27-05-2024.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Users\user\Desktop\Reiven RFQ-27-05-2024.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Users\user\Desktop\Reiven RFQ-27-05-2024.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Users\user\Desktop\Reiven RFQ-27-05-2024.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Users\user\Desktop\Reiven RFQ-27-05-2024.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Users\user\Desktop\Reiven RFQ-27-05-2024.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Users\user\Desktop\Reiven RFQ-27-05-2024.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Users\user\Desktop\Reiven RFQ-27-05-2024.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Users\user\Desktop\Reiven RFQ-27-05-2024.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Users\user\Desktop\Reiven RFQ-27-05-2024.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Users\user\Desktop\Reiven RFQ-27-05-2024.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Users\user\Desktop\Reiven RFQ-27-05-2024.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Users\user\Desktop\Reiven RFQ-27-05-2024.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Users\user\Desktop\Reiven RFQ-27-05-2024.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Users\user\Desktop\Reiven RFQ-27-05-2024.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Users\user\Desktop\Reiven RFQ-27-05-2024.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Users\user\Desktop\Reiven RFQ-27-05-2024.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Users\user\Desktop\Reiven RFQ-27-05-2024.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Users\user\Desktop\Reiven RFQ-27-05-2024.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Users\user\Desktop\Reiven RFQ-27-05-2024.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Users\user\Desktop\Reiven RFQ-27-05-2024.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Users\user\Desktop\Reiven RFQ-27-05-2024.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Users\user\Desktop\Reiven RFQ-27-05-2024.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Users\user\Desktop\Reiven RFQ-27-05-2024.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Users\user\Desktop\Reiven RFQ-27-05-2024.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Users\user\Desktop\Reiven RFQ-27-05-2024.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Users\user\Desktop\Reiven RFQ-27-05-2024.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Users\user\Desktop\Reiven RFQ-27-05-2024.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Users\user\Desktop\Reiven RFQ-27-05-2024.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Users\user\Desktop\Reiven RFQ-27-05-2024.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Users\user\Desktop\Reiven RFQ-27-05-2024.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Users\user\Desktop\Reiven RFQ-27-05-2024.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Users\user\Desktop\Reiven RFQ-27-05-2024.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Users\user\Desktop\Reiven RFQ-27-05-2024.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Users\user\Desktop\Reiven RFQ-27-05-2024.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Users\user\Desktop\Reiven RFQ-27-05-2024.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Users\user\Desktop\Reiven RFQ-27-05-2024.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Users\user\Desktop\Reiven RFQ-27-05-2024.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Users\user\Desktop\Reiven RFQ-27-05-2024.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Users\user\Desktop\Reiven RFQ-27-05-2024.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Users\user\Desktop\Reiven RFQ-27-05-2024.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Users\user\Desktop\Reiven RFQ-27-05-2024.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Users\user\Desktop\Reiven RFQ-27-05-2024.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Users\user\Desktop\Reiven RFQ-27-05-2024.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Users\user\Desktop\Reiven RFQ-27-05-2024.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Users\user\Desktop\Reiven RFQ-27-05-2024.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Users\user\Desktop\Reiven RFQ-27-05-2024.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Users\user\Desktop\Reiven RFQ-27-05-2024.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Users\user\Desktop\Reiven RFQ-27-05-2024.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Users\user\Desktop\Reiven RFQ-27-05-2024.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Users\user\Desktop\Reiven RFQ-27-05-2024.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Users\user\Desktop\Reiven RFQ-27-05-2024.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Users\user\Desktop\Reiven RFQ-27-05-2024.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Users\user\Desktop\Reiven RFQ-27-05-2024.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Users\user\Desktop\Reiven RFQ-27-05-2024.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Users\user\Desktop\Reiven RFQ-27-05-2024.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Users\user\Desktop\Reiven RFQ-27-05-2024.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Users\user\Desktop\Reiven RFQ-27-05-2024.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Users\user\Desktop\Reiven RFQ-27-05-2024.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Users\user\Desktop\Reiven RFQ-27-05-2024.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Users\user\Desktop\Reiven RFQ-27-05-2024.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Users\user\Desktop\Reiven RFQ-27-05-2024.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Users\user\Desktop\Reiven RFQ-27-05-2024.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Users\user\Desktop\Reiven RFQ-27-05-2024.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Users\user\Desktop\Reiven RFQ-27-05-2024.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Users\user\Desktop\Reiven RFQ-27-05-2024.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Users\user\Desktop\Reiven RFQ-27-05-2024.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Users\user\Desktop\Reiven RFQ-27-05-2024.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Users\user\Desktop\Reiven RFQ-27-05-2024.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Users\user\Desktop\Reiven RFQ-27-05-2024.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Users\user\Desktop\Reiven RFQ-27-05-2024.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Users\user\Desktop\Reiven RFQ-27-05-2024.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Users\user\Desktop\Reiven RFQ-27-05-2024.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Users\user\Desktop\Reiven RFQ-27-05-2024.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Users\user\Desktop\Reiven RFQ-27-05-2024.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Users\user\Desktop\Reiven RFQ-27-05-2024.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Users\user\Desktop\Reiven RFQ-27-05-2024.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Users\user\Desktop\Reiven RFQ-27-05-2024.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Users\user\Desktop\Reiven RFQ-27-05-2024.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Users\user\Desktop\Reiven RFQ-27-05-2024.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Users\user\Desktop\Reiven RFQ-27-05-2024.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Users\user\Desktop\Reiven RFQ-27-05-2024.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Users\user\Desktop\Reiven RFQ-27-05-2024.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Users\user\AppData\Roaming\GrOcCQC\GrOcCQC.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Users\user\AppData\Roaming\GrOcCQC\GrOcCQC.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Users\user\AppData\Roaming\GrOcCQC\GrOcCQC.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Users\user\AppData\Roaming\GrOcCQC\GrOcCQC.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Users\user\AppData\Roaming\GrOcCQC\GrOcCQC.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Users\user\AppData\Roaming\GrOcCQC\GrOcCQC.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Users\user\AppData\Roaming\GrOcCQC\GrOcCQC.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Users\user\AppData\Roaming\GrOcCQC\GrOcCQC.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Users\user\AppData\Roaming\GrOcCQC\GrOcCQC.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Users\user\AppData\Roaming\GrOcCQC\GrOcCQC.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Users\user\AppData\Roaming\GrOcCQC\GrOcCQC.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Users\user\AppData\Roaming\GrOcCQC\GrOcCQC.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Users\user\AppData\Roaming\GrOcCQC\GrOcCQC.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Users\user\AppData\Roaming\GrOcCQC\GrOcCQC.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Users\user\AppData\Roaming\GrOcCQC\GrOcCQC.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Users\user\AppData\Roaming\GrOcCQC\GrOcCQC.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Users\user\AppData\Roaming\GrOcCQC\GrOcCQC.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Users\user\AppData\Roaming\GrOcCQC\GrOcCQC.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Users\user\AppData\Roaming\GrOcCQC\GrOcCQC.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Users\user\AppData\Roaming\GrOcCQC\GrOcCQC.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Users\user\AppData\Roaming\GrOcCQC\GrOcCQC.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Users\user\AppData\Roaming\GrOcCQC\GrOcCQC.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Users\user\AppData\Roaming\GrOcCQC\GrOcCQC.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Users\user\AppData\Roaming\GrOcCQC\GrOcCQC.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Users\user\AppData\Roaming\GrOcCQC\GrOcCQC.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Users\user\AppData\Roaming\GrOcCQC\GrOcCQC.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Users\user\AppData\Roaming\GrOcCQC\GrOcCQC.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Users\user\AppData\Roaming\GrOcCQC\GrOcCQC.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Users\user\AppData\Roaming\GrOcCQC\GrOcCQC.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Users\user\AppData\Roaming\GrOcCQC\GrOcCQC.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Users\user\AppData\Roaming\GrOcCQC\GrOcCQC.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Users\user\AppData\Roaming\GrOcCQC\GrOcCQC.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Users\user\AppData\Roaming\GrOcCQC\GrOcCQC.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Users\user\AppData\Roaming\GrOcCQC\GrOcCQC.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Users\user\AppData\Roaming\GrOcCQC\GrOcCQC.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Users\user\AppData\Roaming\GrOcCQC\GrOcCQC.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Users\user\AppData\Roaming\GrOcCQC\GrOcCQC.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Users\user\AppData\Roaming\GrOcCQC\GrOcCQC.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Users\user\AppData\Roaming\GrOcCQC\GrOcCQC.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Users\user\AppData\Roaming\GrOcCQC\GrOcCQC.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Users\user\AppData\Roaming\GrOcCQC\GrOcCQC.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Users\user\AppData\Roaming\GrOcCQC\GrOcCQC.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Users\user\AppData\Roaming\GrOcCQC\GrOcCQC.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Users\user\AppData\Roaming\GrOcCQC\GrOcCQC.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Users\user\AppData\Roaming\GrOcCQC\GrOcCQC.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Users\user\AppData\Roaming\GrOcCQC\GrOcCQC.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Users\user\AppData\Roaming\GrOcCQC\GrOcCQC.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Users\user\AppData\Roaming\GrOcCQC\GrOcCQC.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Users\user\AppData\Roaming\GrOcCQC\GrOcCQC.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Users\user\AppData\Roaming\GrOcCQC\GrOcCQC.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Users\user\AppData\Roaming\GrOcCQC\GrOcCQC.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Users\user\AppData\Roaming\GrOcCQC\GrOcCQC.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Users\user\AppData\Roaming\GrOcCQC\GrOcCQC.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Users\user\AppData\Roaming\GrOcCQC\GrOcCQC.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Users\user\AppData\Roaming\GrOcCQC\GrOcCQC.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Users\user\AppData\Roaming\GrOcCQC\GrOcCQC.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Users\user\AppData\Roaming\GrOcCQC\GrOcCQC.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Users\user\AppData\Roaming\GrOcCQC\GrOcCQC.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Users\user\AppData\Roaming\GrOcCQC\GrOcCQC.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Users\user\AppData\Roaming\GrOcCQC\GrOcCQC.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Users\user\AppData\Roaming\GrOcCQC\GrOcCQC.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Users\user\AppData\Roaming\GrOcCQC\GrOcCQC.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Users\user\AppData\Roaming\GrOcCQC\GrOcCQC.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Users\user\AppData\Roaming\GrOcCQC\GrOcCQC.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Users\user\AppData\Roaming\GrOcCQC\GrOcCQC.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Users\user\AppData\Roaming\GrOcCQC\GrOcCQC.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Users\user\AppData\Roaming\GrOcCQC\GrOcCQC.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Users\user\AppData\Roaming\GrOcCQC\GrOcCQC.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Users\user\AppData\Roaming\GrOcCQC\GrOcCQC.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Users\user\AppData\Roaming\GrOcCQC\GrOcCQC.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Users\user\AppData\Roaming\GrOcCQC\GrOcCQC.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Users\user\AppData\Roaming\GrOcCQC\GrOcCQC.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Users\user\AppData\Roaming\GrOcCQC\GrOcCQC.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Users\user\AppData\Roaming\GrOcCQC\GrOcCQC.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Users\user\AppData\Roaming\GrOcCQC\GrOcCQC.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Users\user\AppData\Roaming\GrOcCQC\GrOcCQC.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Users\user\AppData\Roaming\GrOcCQC\GrOcCQC.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Users\user\AppData\Roaming\GrOcCQC\GrOcCQC.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Users\user\AppData\Roaming\GrOcCQC\GrOcCQC.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Users\user\AppData\Roaming\GrOcCQC\GrOcCQC.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Users\user\AppData\Roaming\GrOcCQC\GrOcCQC.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Users\user\AppData\Roaming\GrOcCQC\GrOcCQC.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Users\user\AppData\Roaming\GrOcCQC\GrOcCQC.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Users\user\AppData\Roaming\GrOcCQC\GrOcCQC.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Users\user\AppData\Roaming\GrOcCQC\GrOcCQC.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Users\user\AppData\Roaming\GrOcCQC\GrOcCQC.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Users\user\AppData\Roaming\GrOcCQC\GrOcCQC.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Users\user\AppData\Roaming\GrOcCQC\GrOcCQC.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Users\user\AppData\Roaming\GrOcCQC\GrOcCQC.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Users\user\AppData\Roaming\GrOcCQC\GrOcCQC.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Users\user\AppData\Roaming\GrOcCQC\GrOcCQC.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Users\user\AppData\Roaming\GrOcCQC\GrOcCQC.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Users\user\AppData\Roaming\GrOcCQC\GrOcCQC.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Users\user\AppData\Roaming\GrOcCQC\GrOcCQC.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Users\user\AppData\Roaming\GrOcCQC\GrOcCQC.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Users\user\AppData\Roaming\GrOcCQC\GrOcCQC.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Users\user\AppData\Roaming\GrOcCQC\GrOcCQC.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Users\user\AppData\Roaming\GrOcCQC\GrOcCQC.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Users\user\AppData\Roaming\GrOcCQC\GrOcCQC.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Users\user\AppData\Roaming\GrOcCQC\GrOcCQC.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Users\user\AppData\Roaming\GrOcCQC\GrOcCQC.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Users\user\AppData\Roaming\GrOcCQC\GrOcCQC.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Users\user\AppData\Roaming\GrOcCQC\GrOcCQC.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Users\user\AppData\Roaming\GrOcCQC\GrOcCQC.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Users\user\AppData\Roaming\GrOcCQC\GrOcCQC.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Users\user\AppData\Roaming\GrOcCQC\GrOcCQC.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Users\user\AppData\Roaming\GrOcCQC\GrOcCQC.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Users\user\AppData\Roaming\GrOcCQC\GrOcCQC.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Users\user\AppData\Roaming\GrOcCQC\GrOcCQC.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Users\user\AppData\Roaming\GrOcCQC\GrOcCQC.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Users\user\AppData\Roaming\GrOcCQC\GrOcCQC.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Users\user\AppData\Roaming\GrOcCQC\GrOcCQC.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Users\user\AppData\Roaming\GrOcCQC\GrOcCQC.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Users\user\AppData\Roaming\GrOcCQC\GrOcCQC.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Users\user\AppData\Roaming\GrOcCQC\GrOcCQC.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Users\user\AppData\Roaming\GrOcCQC\GrOcCQC.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Users\user\AppData\Roaming\GrOcCQC\GrOcCQC.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Users\user\AppData\Roaming\GrOcCQC\GrOcCQC.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Users\user\AppData\Roaming\GrOcCQC\GrOcCQC.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Users\user\AppData\Roaming\GrOcCQC\GrOcCQC.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Users\user\AppData\Roaming\GrOcCQC\GrOcCQC.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Users\user\AppData\Roaming\GrOcCQC\GrOcCQC.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Users\user\AppData\Roaming\GrOcCQC\GrOcCQC.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Users\user\AppData\Roaming\GrOcCQC\GrOcCQC.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Users\user\AppData\Roaming\GrOcCQC\GrOcCQC.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Users\user\AppData\Roaming\GrOcCQC\GrOcCQC.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Users\user\AppData\Roaming\GrOcCQC\GrOcCQC.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Users\user\AppData\Roaming\GrOcCQC\GrOcCQC.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Users\user\AppData\Roaming\GrOcCQC\GrOcCQC.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Users\user\AppData\Roaming\GrOcCQC\GrOcCQC.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Users\user\AppData\Roaming\GrOcCQC\GrOcCQC.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Users\user\AppData\Roaming\GrOcCQC\GrOcCQC.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Users\user\AppData\Roaming\GrOcCQC\GrOcCQC.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Users\user\AppData\Roaming\GrOcCQC\GrOcCQC.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Users\user\AppData\Roaming\GrOcCQC\GrOcCQC.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Users\user\AppData\Roaming\GrOcCQC\GrOcCQC.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Users\user\AppData\Roaming\GrOcCQC\GrOcCQC.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Users\user\AppData\Roaming\GrOcCQC\GrOcCQC.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Users\user\AppData\Roaming\GrOcCQC\GrOcCQC.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Users\user\AppData\Roaming\GrOcCQC\GrOcCQC.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Users\user\AppData\Roaming\GrOcCQC\GrOcCQC.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Users\user\AppData\Roaming\GrOcCQC\GrOcCQC.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Users\user\AppData\Roaming\GrOcCQC\GrOcCQC.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Users\user\AppData\Roaming\GrOcCQC\GrOcCQC.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Users\user\AppData\Roaming\GrOcCQC\GrOcCQC.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Users\user\AppData\Roaming\GrOcCQC\GrOcCQC.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Users\user\AppData\Roaming\GrOcCQC\GrOcCQC.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Users\user\AppData\Roaming\GrOcCQC\GrOcCQC.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Users\user\AppData\Roaming\GrOcCQC\GrOcCQC.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Users\user\AppData\Roaming\GrOcCQC\GrOcCQC.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Users\user\AppData\Roaming\GrOcCQC\GrOcCQC.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Users\user\AppData\Roaming\GrOcCQC\GrOcCQC.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Users\user\AppData\Roaming\GrOcCQC\GrOcCQC.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Users\user\AppData\Roaming\GrOcCQC\GrOcCQC.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Users\user\AppData\Roaming\GrOcCQC\GrOcCQC.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Users\user\AppData\Roaming\GrOcCQC\GrOcCQC.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Users\user\AppData\Roaming\GrOcCQC\GrOcCQC.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Users\user\AppData\Roaming\GrOcCQC\GrOcCQC.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Users\user\AppData\Roaming\GrOcCQC\GrOcCQC.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Users\user\AppData\Roaming\GrOcCQC\GrOcCQC.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Users\user\AppData\Roaming\GrOcCQC\GrOcCQC.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Users\user\AppData\Roaming\GrOcCQC\GrOcCQC.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Users\user\AppData\Roaming\GrOcCQC\GrOcCQC.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Users\user\AppData\Roaming\GrOcCQC\GrOcCQC.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Users\user\AppData\Roaming\GrOcCQC\GrOcCQC.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Users\user\AppData\Roaming\GrOcCQC\GrOcCQC.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Users\user\AppData\Roaming\GrOcCQC\GrOcCQC.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Users\user\AppData\Roaming\GrOcCQC\GrOcCQC.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Users\user\AppData\Roaming\GrOcCQC\GrOcCQC.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Users\user\AppData\Roaming\GrOcCQC\GrOcCQC.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Users\user\AppData\Roaming\GrOcCQC\GrOcCQC.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Users\user\AppData\Roaming\GrOcCQC\GrOcCQC.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Users\user\AppData\Roaming\GrOcCQC\GrOcCQC.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Users\user\AppData\Roaming\GrOcCQC\GrOcCQC.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Users\user\AppData\Roaming\GrOcCQC\GrOcCQC.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Users\user\AppData\Roaming\GrOcCQC\GrOcCQC.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Users\user\AppData\Roaming\GrOcCQC\GrOcCQC.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Users\user\AppData\Roaming\GrOcCQC\GrOcCQC.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Users\user\AppData\Roaming\GrOcCQC\GrOcCQC.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Users\user\AppData\Roaming\GrOcCQC\GrOcCQC.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Users\user\AppData\Roaming\GrOcCQC\GrOcCQC.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Users\user\AppData\Roaming\GrOcCQC\GrOcCQC.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Users\user\AppData\Roaming\GrOcCQC\GrOcCQC.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Users\user\AppData\Roaming\GrOcCQC\GrOcCQC.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Users\user\AppData\Roaming\GrOcCQC\GrOcCQC.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Users\user\AppData\Roaming\GrOcCQC\GrOcCQC.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Users\user\AppData\Roaming\GrOcCQC\GrOcCQC.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Users\user\AppData\Roaming\GrOcCQC\GrOcCQC.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Users\user\AppData\Roaming\GrOcCQC\GrOcCQC.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Users\user\AppData\Roaming\GrOcCQC\GrOcCQC.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Users\user\AppData\Roaming\GrOcCQC\GrOcCQC.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Users\user\AppData\Roaming\GrOcCQC\GrOcCQC.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Users\user\AppData\Roaming\GrOcCQC\GrOcCQC.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Users\user\AppData\Roaming\GrOcCQC\GrOcCQC.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Users\user\AppData\Roaming\GrOcCQC\GrOcCQC.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Users\user\AppData\Roaming\GrOcCQC\GrOcCQC.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Users\user\AppData\Roaming\GrOcCQC\GrOcCQC.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Users\user\AppData\Roaming\GrOcCQC\GrOcCQC.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Users\user\AppData\Roaming\GrOcCQC\GrOcCQC.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Users\user\AppData\Roaming\GrOcCQC\GrOcCQC.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Users\user\AppData\Roaming\GrOcCQC\GrOcCQC.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Users\user\AppData\Roaming\GrOcCQC\GrOcCQC.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Users\user\AppData\Roaming\GrOcCQC\GrOcCQC.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Users\user\AppData\Roaming\GrOcCQC\GrOcCQC.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Users\user\AppData\Roaming\GrOcCQC\GrOcCQC.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Users\user\AppData\Roaming\GrOcCQC\GrOcCQC.exe Process information set: NOOPENFILEERRORBOX Jump to behavior

Malware Analysis System Evasion

barindex
Source: Yara match File source: Process Memory Space: Reiven RFQ-27-05-2024.exe PID: 1404, type: MEMORYSTR
Source: Yara match File source: Process Memory Space: GrOcCQC.exe PID: 2532, type: MEMORYSTR
Source: Yara match File source: Process Memory Space: GrOcCQC.exe PID: 7008, type: MEMORYSTR
Source: global traffic HTTP traffic detected: GET /line/?fields=hosting HTTP/1.1Host: ip-api.comConnection: Keep-Alive
Source: global traffic HTTP traffic detected: GET /line/?fields=hosting HTTP/1.1Host: ip-api.comConnection: Keep-Alive
Source: global traffic HTTP traffic detected: GET /line/?fields=hosting HTTP/1.1Host: ip-api.comConnection: Keep-Alive
Source: C:\Users\user\Desktop\Reiven RFQ-27-05-2024.exe WMI Queries: IWbemServices::CreateInstanceEnum - root\cimv2 : Win32_NetworkAdapterConfiguration
Source: C:\Users\user\AppData\Roaming\GrOcCQC\GrOcCQC.exe WMI Queries: IWbemServices::CreateInstanceEnum - root\cimv2 : Win32_NetworkAdapterConfiguration
Source: C:\Users\user\AppData\Roaming\GrOcCQC\GrOcCQC.exe WMI Queries: IWbemServices::CreateInstanceEnum - root\cimv2 : Win32_NetworkAdapterConfiguration
Source: C:\Users\user\Desktop\Reiven RFQ-27-05-2024.exe WMI Queries: IWbemServices::ExecQuery - root\CIMV2 : SELECT * FROM Win32_VideoController
Source: C:\Users\user\AppData\Roaming\GrOcCQC\GrOcCQC.exe WMI Queries: IWbemServices::ExecQuery - root\CIMV2 : SELECT * FROM Win32_VideoController
Source: C:\Users\user\AppData\Roaming\GrOcCQC\GrOcCQC.exe WMI Queries: IWbemServices::ExecQuery - root\CIMV2 : SELECT * FROM Win32_VideoController
Source: Reiven RFQ-27-05-2024.exe, 00000000.00000002.2091795003.0000000003E3E000.00000004.00000800.00020000.00000000.sdmp, Reiven RFQ-27-05-2024.exe, 00000003.00000002.3328316664.0000000002A05000.00000004.00000800.00020000.00000000.sdmp, GrOcCQC.exe, 00000006.00000002.3329095685.0000000002A15000.00000004.00000800.00020000.00000000.sdmp, GrOcCQC.exe, 00000008.00000002.3328584752.0000000003125000.00000004.00000800.00020000.00000000.sdmp Binary or memory string: SBIEDLL.DLL
Source: C:\Users\user\Desktop\Reiven RFQ-27-05-2024.exe Memory allocated: 1230000 memory reserve | memory write watch Jump to behavior
Source: C:\Users\user\Desktop\Reiven RFQ-27-05-2024.exe Memory allocated: 2C60000 memory reserve | memory write watch Jump to behavior
Source: C:\Users\user\Desktop\Reiven RFQ-27-05-2024.exe Memory allocated: 2A60000 memory reserve | memory write watch Jump to behavior
Source: C:\Users\user\Desktop\Reiven RFQ-27-05-2024.exe Memory allocated: 8C00000 memory reserve | memory write watch Jump to behavior
Source: C:\Users\user\Desktop\Reiven RFQ-27-05-2024.exe Memory allocated: 9C00000 memory reserve | memory write watch Jump to behavior
Source: C:\Users\user\Desktop\Reiven RFQ-27-05-2024.exe Memory allocated: 9E00000 memory reserve | memory write watch Jump to behavior
Source: C:\Users\user\Desktop\Reiven RFQ-27-05-2024.exe Memory allocated: AE00000 memory reserve | memory write watch Jump to behavior
Source: C:\Users\user\Desktop\Reiven RFQ-27-05-2024.exe Memory allocated: EE0000 memory reserve | memory write watch Jump to behavior
Source: C:\Users\user\Desktop\Reiven RFQ-27-05-2024.exe Memory allocated: 29D0000 memory reserve | memory write watch Jump to behavior
Source: C:\Users\user\Desktop\Reiven RFQ-27-05-2024.exe Memory allocated: 2800000 memory reserve | memory write watch Jump to behavior
Source: C:\Users\user\AppData\Roaming\GrOcCQC\GrOcCQC.exe Memory allocated: A40000 memory reserve | memory write watch Jump to behavior
Source: C:\Users\user\AppData\Roaming\GrOcCQC\GrOcCQC.exe Memory allocated: 2720000 memory reserve | memory write watch Jump to behavior
Source: C:\Users\user\AppData\Roaming\GrOcCQC\GrOcCQC.exe Memory allocated: CF0000 memory reserve | memory write watch Jump to behavior
Source: C:\Users\user\AppData\Roaming\GrOcCQC\GrOcCQC.exe Memory allocated: 7F90000 memory reserve | memory write watch Jump to behavior
Source: C:\Users\user\AppData\Roaming\GrOcCQC\GrOcCQC.exe Memory allocated: 8F90000 memory reserve | memory write watch Jump to behavior
Source: C:\Users\user\AppData\Roaming\GrOcCQC\GrOcCQC.exe Memory allocated: 9170000 memory reserve | memory write watch Jump to behavior
Source: C:\Users\user\AppData\Roaming\GrOcCQC\GrOcCQC.exe Memory allocated: A170000 memory reserve | memory write watch Jump to behavior
Source: C:\Users\user\AppData\Roaming\GrOcCQC\GrOcCQC.exe Memory allocated: ED0000 memory reserve | memory write watch Jump to behavior
Source: C:\Users\user\AppData\Roaming\GrOcCQC\GrOcCQC.exe Memory allocated: 29E0000 memory reserve | memory write watch Jump to behavior
Source: C:\Users\user\AppData\Roaming\GrOcCQC\GrOcCQC.exe Memory allocated: 49E0000 memory reserve | memory write watch Jump to behavior
Source: C:\Users\user\AppData\Roaming\GrOcCQC\GrOcCQC.exe Memory allocated: F60000 memory reserve | memory write watch Jump to behavior
Source: C:\Users\user\AppData\Roaming\GrOcCQC\GrOcCQC.exe Memory allocated: 2A90000 memory reserve | memory write watch Jump to behavior
Source: C:\Users\user\AppData\Roaming\GrOcCQC\GrOcCQC.exe Memory allocated: 2870000 memory reserve | memory write watch Jump to behavior
Source: C:\Users\user\AppData\Roaming\GrOcCQC\GrOcCQC.exe Memory allocated: 8590000 memory reserve | memory write watch Jump to behavior
Source: C:\Users\user\AppData\Roaming\GrOcCQC\GrOcCQC.exe Memory allocated: 9590000 memory reserve | memory write watch Jump to behavior
Source: C:\Users\user\AppData\Roaming\GrOcCQC\GrOcCQC.exe Memory allocated: 9780000 memory reserve | memory write watch Jump to behavior
Source: C:\Users\user\AppData\Roaming\GrOcCQC\GrOcCQC.exe Memory allocated: A780000 memory reserve | memory write watch Jump to behavior
Source: C:\Users\user\AppData\Roaming\GrOcCQC\GrOcCQC.exe Memory allocated: 1600000 memory reserve | memory write watch Jump to behavior
Source: C:\Users\user\AppData\Roaming\GrOcCQC\GrOcCQC.exe Memory allocated: 30F0000 memory reserve | memory write watch Jump to behavior
Source: C:\Users\user\AppData\Roaming\GrOcCQC\GrOcCQC.exe Memory allocated: 1630000 memory reserve | memory write watch Jump to behavior
Source: C:\Users\user\Desktop\Reiven RFQ-27-05-2024.exe Thread delayed: delay time: 922337203685477 Jump to behavior
Source: C:\Users\user\Desktop\Reiven RFQ-27-05-2024.exe Thread delayed: delay time: 922337203685477 Jump to behavior
Source: C:\Users\user\Desktop\Reiven RFQ-27-05-2024.exe Thread delayed: delay time: 922337203685477 Jump to behavior
Source: C:\Users\user\AppData\Roaming\GrOcCQC\GrOcCQC.exe Thread delayed: delay time: 922337203685477 Jump to behavior
Source: C:\Users\user\AppData\Roaming\GrOcCQC\GrOcCQC.exe Thread delayed: delay time: 922337203685477 Jump to behavior
Source: C:\Users\user\AppData\Roaming\GrOcCQC\GrOcCQC.exe Thread delayed: delay time: 922337203685477 Jump to behavior
Source: C:\Users\user\AppData\Roaming\GrOcCQC\GrOcCQC.exe Thread delayed: delay time: 922337203685477 Jump to behavior
Source: C:\Users\user\AppData\Roaming\GrOcCQC\GrOcCQC.exe Thread delayed: delay time: 922337203685477 Jump to behavior
Source: C:\Users\user\AppData\Roaming\GrOcCQC\GrOcCQC.exe Thread delayed: delay time: 922337203685477 Jump to behavior
Source: C:\Users\user\Desktop\Reiven RFQ-27-05-2024.exe Window / User API: threadDelayed 912 Jump to behavior
Source: C:\Users\user\Desktop\Reiven RFQ-27-05-2024.exe Window / User API: threadDelayed 3566 Jump to behavior
Source: C:\Users\user\AppData\Roaming\GrOcCQC\GrOcCQC.exe Window / User API: threadDelayed 2205 Jump to behavior
Source: C:\Users\user\AppData\Roaming\GrOcCQC\GrOcCQC.exe Window / User API: threadDelayed 780 Jump to behavior
Source: C:\Users\user\AppData\Roaming\GrOcCQC\GrOcCQC.exe Window / User API: threadDelayed 444 Jump to behavior
Source: C:\Users\user\AppData\Roaming\GrOcCQC\GrOcCQC.exe Window / User API: threadDelayed 2742 Jump to behavior
Source: C:\Users\user\Desktop\Reiven RFQ-27-05-2024.exe TID: 3548 Thread sleep time: -922337203685477s >= -30000s Jump to behavior
Source: C:\Users\user\Desktop\Reiven RFQ-27-05-2024.exe TID: 3896 Thread sleep time: -9223372036854770s >= -30000s Jump to behavior
Source: C:\Users\user\Desktop\Reiven RFQ-27-05-2024.exe TID: 3896 Thread sleep time: -100000s >= -30000s Jump to behavior
Source: C:\Users\user\Desktop\Reiven RFQ-27-05-2024.exe TID: 4088 Thread sleep count: 912 > 30 Jump to behavior
Source: C:\Users\user\Desktop\Reiven RFQ-27-05-2024.exe TID: 3896 Thread sleep time: -99874s >= -30000s Jump to behavior
Source: C:\Users\user\Desktop\Reiven RFQ-27-05-2024.exe TID: 4088 Thread sleep count: 3566 > 30 Jump to behavior
Source: C:\Users\user\Desktop\Reiven RFQ-27-05-2024.exe TID: 3896 Thread sleep time: -99765s >= -30000s Jump to behavior
Source: C:\Users\user\Desktop\Reiven RFQ-27-05-2024.exe TID: 3896 Thread sleep time: -99656s >= -30000s Jump to behavior
Source: C:\Users\user\Desktop\Reiven RFQ-27-05-2024.exe TID: 3896 Thread sleep time: -99546s >= -30000s Jump to behavior
Source: C:\Users\user\Desktop\Reiven RFQ-27-05-2024.exe TID: 3896 Thread sleep time: -99437s >= -30000s Jump to behavior
Source: C:\Users\user\Desktop\Reiven RFQ-27-05-2024.exe TID: 3896 Thread sleep time: -99328s >= -30000s Jump to behavior
Source: C:\Users\user\Desktop\Reiven RFQ-27-05-2024.exe TID: 3896 Thread sleep time: -99218s >= -30000s Jump to behavior
Source: C:\Users\user\Desktop\Reiven RFQ-27-05-2024.exe TID: 3896 Thread sleep time: -99109s >= -30000s Jump to behavior
Source: C:\Users\user\Desktop\Reiven RFQ-27-05-2024.exe TID: 3896 Thread sleep time: -98996s >= -30000s Jump to behavior
Source: C:\Users\user\Desktop\Reiven RFQ-27-05-2024.exe TID: 3896 Thread sleep time: -98890s >= -30000s Jump to behavior
Source: C:\Users\user\Desktop\Reiven RFQ-27-05-2024.exe TID: 3896 Thread sleep time: -98781s >= -30000s Jump to behavior
Source: C:\Users\user\Desktop\Reiven RFQ-27-05-2024.exe TID: 3896 Thread sleep time: -98668s >= -30000s Jump to behavior
Source: C:\Users\user\Desktop\Reiven RFQ-27-05-2024.exe TID: 3896 Thread sleep time: -98562s >= -30000s Jump to behavior
Source: C:\Users\user\Desktop\Reiven RFQ-27-05-2024.exe TID: 3896 Thread sleep time: -98453s >= -30000s Jump to behavior
Source: C:\Users\user\Desktop\Reiven RFQ-27-05-2024.exe TID: 3896 Thread sleep time: -98343s >= -30000s Jump to behavior
Source: C:\Users\user\Desktop\Reiven RFQ-27-05-2024.exe TID: 3896 Thread sleep time: -98233s >= -30000s Jump to behavior
Source: C:\Users\user\Desktop\Reiven RFQ-27-05-2024.exe TID: 3896 Thread sleep time: -98125s >= -30000s Jump to behavior
Source: C:\Users\user\Desktop\Reiven RFQ-27-05-2024.exe TID: 3896 Thread sleep time: -98015s >= -30000s Jump to behavior
Source: C:\Users\user\Desktop\Reiven RFQ-27-05-2024.exe TID: 3896 Thread sleep time: -97906s >= -30000s Jump to behavior
Source: C:\Users\user\Desktop\Reiven RFQ-27-05-2024.exe TID: 3896 Thread sleep time: -97796s >= -30000s Jump to behavior
Source: C:\Users\user\Desktop\Reiven RFQ-27-05-2024.exe TID: 3896 Thread sleep time: -97687s >= -30000s Jump to behavior
Source: C:\Users\user\Desktop\Reiven RFQ-27-05-2024.exe TID: 3896 Thread sleep time: -922337203685477s >= -30000s Jump to behavior
Source: C:\Users\user\AppData\Roaming\GrOcCQC\GrOcCQC.exe TID: 5680 Thread sleep time: -922337203685477s >= -30000s Jump to behavior
Source: C:\Users\user\AppData\Roaming\GrOcCQC\GrOcCQC.exe TID: 3640 Thread sleep time: -11068046444225724s >= -30000s Jump to behavior
Source: C:\Users\user\AppData\Roaming\GrOcCQC\GrOcCQC.exe TID: 3640 Thread sleep time: -100000s >= -30000s Jump to behavior
Source: C:\Users\user\AppData\Roaming\GrOcCQC\GrOcCQC.exe TID: 5928 Thread sleep count: 2205 > 30 Jump to behavior
Source: C:\Users\user\AppData\Roaming\GrOcCQC\GrOcCQC.exe TID: 3640 Thread sleep time: -99890s >= -30000s Jump to behavior
Source: C:\Users\user\AppData\Roaming\GrOcCQC\GrOcCQC.exe TID: 5928 Thread sleep count: 780 > 30 Jump to behavior
Source: C:\Users\user\AppData\Roaming\GrOcCQC\GrOcCQC.exe TID: 3640 Thread sleep time: -99777s >= -30000s Jump to behavior
Source: C:\Users\user\AppData\Roaming\GrOcCQC\GrOcCQC.exe TID: 3640 Thread sleep time: -99672s >= -30000s Jump to behavior
Source: C:\Users\user\AppData\Roaming\GrOcCQC\GrOcCQC.exe TID: 3640 Thread sleep time: -99559s >= -30000s Jump to behavior
Source: C:\Users\user\AppData\Roaming\GrOcCQC\GrOcCQC.exe TID: 3640 Thread sleep time: -99453s >= -30000s Jump to behavior
Source: C:\Users\user\AppData\Roaming\GrOcCQC\GrOcCQC.exe TID: 3640 Thread sleep time: -99287s >= -30000s Jump to behavior
Source: C:\Users\user\AppData\Roaming\GrOcCQC\GrOcCQC.exe TID: 3640 Thread sleep time: -99146s >= -30000s Jump to behavior
Source: C:\Users\user\AppData\Roaming\GrOcCQC\GrOcCQC.exe TID: 3640 Thread sleep time: -99016s >= -30000s Jump to behavior
Source: C:\Users\user\AppData\Roaming\GrOcCQC\GrOcCQC.exe TID: 3640 Thread sleep time: -98906s >= -30000s Jump to behavior
Source: C:\Users\user\AppData\Roaming\GrOcCQC\GrOcCQC.exe TID: 3640 Thread sleep time: -98796s >= -30000s Jump to behavior
Source: C:\Users\user\AppData\Roaming\GrOcCQC\GrOcCQC.exe TID: 3640 Thread sleep time: -98687s >= -30000s Jump to behavior
Source: C:\Users\user\AppData\Roaming\GrOcCQC\GrOcCQC.exe TID: 3640 Thread sleep time: -98577s >= -30000s Jump to behavior
Source: C:\Users\user\AppData\Roaming\GrOcCQC\GrOcCQC.exe TID: 3640 Thread sleep time: -98469s >= -30000s Jump to behavior
Source: C:\Users\user\AppData\Roaming\GrOcCQC\GrOcCQC.exe TID: 3640 Thread sleep time: -98344s >= -30000s Jump to behavior
Source: C:\Users\user\AppData\Roaming\GrOcCQC\GrOcCQC.exe TID: 3640 Thread sleep time: -922337203685477s >= -30000s Jump to behavior
Source: C:\Users\user\AppData\Roaming\GrOcCQC\GrOcCQC.exe TID: 828 Thread sleep time: -922337203685477s >= -30000s Jump to behavior
Source: C:\Users\user\AppData\Roaming\GrOcCQC\GrOcCQC.exe TID: 3080 Thread sleep time: -8301034833169293s >= -30000s Jump to behavior
Source: C:\Users\user\AppData\Roaming\GrOcCQC\GrOcCQC.exe TID: 3080 Thread sleep time: -100000s >= -30000s Jump to behavior
Source: C:\Users\user\AppData\Roaming\GrOcCQC\GrOcCQC.exe TID: 1836 Thread sleep count: 444 > 30 Jump to behavior
Source: C:\Users\user\AppData\Roaming\GrOcCQC\GrOcCQC.exe TID: 1836 Thread sleep count: 2742 > 30 Jump to behavior
Source: C:\Users\user\AppData\Roaming\GrOcCQC\GrOcCQC.exe TID: 3080 Thread sleep time: -99890s >= -30000s Jump to behavior
Source: C:\Users\user\AppData\Roaming\GrOcCQC\GrOcCQC.exe TID: 3080 Thread sleep time: -99781s >= -30000s Jump to behavior
Source: C:\Users\user\AppData\Roaming\GrOcCQC\GrOcCQC.exe TID: 3080 Thread sleep time: -99672s >= -30000s Jump to behavior
Source: C:\Users\user\AppData\Roaming\GrOcCQC\GrOcCQC.exe TID: 3080 Thread sleep time: -99563s >= -30000s Jump to behavior
Source: C:\Users\user\AppData\Roaming\GrOcCQC\GrOcCQC.exe TID: 3080 Thread sleep time: -99438s >= -30000s Jump to behavior
Source: C:\Users\user\AppData\Roaming\GrOcCQC\GrOcCQC.exe TID: 3080 Thread sleep time: -99313s >= -30000s Jump to behavior
Source: C:\Users\user\AppData\Roaming\GrOcCQC\GrOcCQC.exe TID: 3080 Thread sleep time: -99203s >= -30000s Jump to behavior
Source: C:\Users\user\AppData\Roaming\GrOcCQC\GrOcCQC.exe TID: 3080 Thread sleep time: -99094s >= -30000s Jump to behavior
Source: C:\Users\user\AppData\Roaming\GrOcCQC\GrOcCQC.exe TID: 3080 Thread sleep time: -98953s >= -30000s Jump to behavior
Source: C:\Users\user\AppData\Roaming\GrOcCQC\GrOcCQC.exe TID: 3080 Thread sleep time: -98844s >= -30000s Jump to behavior
Source: C:\Users\user\AppData\Roaming\GrOcCQC\GrOcCQC.exe TID: 3080 Thread sleep time: -98734s >= -30000s Jump to behavior
Source: C:\Users\user\AppData\Roaming\GrOcCQC\GrOcCQC.exe TID: 3080 Thread sleep time: -98625s >= -30000s Jump to behavior
Source: C:\Users\user\AppData\Roaming\GrOcCQC\GrOcCQC.exe TID: 3080 Thread sleep time: -98516s >= -30000s Jump to behavior
Source: C:\Users\user\AppData\Roaming\GrOcCQC\GrOcCQC.exe TID: 3080 Thread sleep time: -98406s >= -30000s Jump to behavior
Source: C:\Users\user\AppData\Roaming\GrOcCQC\GrOcCQC.exe TID: 3080 Thread sleep time: -98297s >= -30000s Jump to behavior
Source: C:\Users\user\AppData\Roaming\GrOcCQC\GrOcCQC.exe TID: 3080 Thread sleep time: -922337203685477s >= -30000s Jump to behavior
Source: C:\Users\user\Desktop\Reiven RFQ-27-05-2024.exe WMI Queries: IWbemServices::CreateInstanceEnum - root\cimv2 : Win32_BaseBoard
Source: C:\Users\user\AppData\Roaming\GrOcCQC\GrOcCQC.exe WMI Queries: IWbemServices::CreateInstanceEnum - root\cimv2 : Win32_BaseBoard
Source: C:\Users\user\AppData\Roaming\GrOcCQC\GrOcCQC.exe WMI Queries: IWbemServices::CreateInstanceEnum - root\cimv2 : Win32_BaseBoard
Source: C:\Users\user\Desktop\Reiven RFQ-27-05-2024.exe WMI Queries: IWbemServices::ExecQuery - root\cimv2 : Select * from Win32_ComputerSystem
Source: C:\Users\user\AppData\Roaming\GrOcCQC\GrOcCQC.exe WMI Queries: IWbemServices::ExecQuery - root\cimv2 : Select * from Win32_ComputerSystem
Source: C:\Users\user\AppData\Roaming\GrOcCQC\GrOcCQC.exe WMI Queries: IWbemServices::ExecQuery - root\cimv2 : Select * from Win32_ComputerSystem
Source: C:\Users\user\Desktop\Reiven RFQ-27-05-2024.exe WMI Queries: IWbemServices::CreateInstanceEnum - root\cimv2 : Win32_Processor
Source: C:\Users\user\Desktop\Reiven RFQ-27-05-2024.exe WMI Queries: IWbemServices::ExecQuery - root\cimv2 : SELECT * FROM Win32_Processor
Source: C:\Users\user\AppData\Roaming\GrOcCQC\GrOcCQC.exe WMI Queries: IWbemServices::CreateInstanceEnum - root\cimv2 : Win32_Processor
Source: C:\Users\user\AppData\Roaming\GrOcCQC\GrOcCQC.exe WMI Queries: IWbemServices::ExecQuery - root\cimv2 : SELECT * FROM Win32_Processor
Source: C:\Users\user\AppData\Roaming\GrOcCQC\GrOcCQC.exe WMI Queries: IWbemServices::CreateInstanceEnum - root\cimv2 : Win32_Processor
Source: C:\Users\user\AppData\Roaming\GrOcCQC\GrOcCQC.exe WMI Queries: IWbemServices::ExecQuery - root\cimv2 : SELECT * FROM Win32_Processor
Source: C:\Users\user\Desktop\Reiven RFQ-27-05-2024.exe Thread delayed: delay time: 922337203685477 Jump to behavior
Source: C:\Users\user\Desktop\Reiven RFQ-27-05-2024.exe Thread delayed: delay time: 922337203685477 Jump to behavior
Source: C:\Users\user\Desktop\Reiven RFQ-27-05-2024.exe Thread delayed: delay time: 100000 Jump to behavior
Source: C:\Users\user\Desktop\Reiven RFQ-27-05-2024.exe Thread delayed: delay time: 99874 Jump to behavior
Source: C:\Users\user\Desktop\Reiven RFQ-27-05-2024.exe Thread delayed: delay time: 99765 Jump to behavior
Source: C:\Users\user\Desktop\Reiven RFQ-27-05-2024.exe Thread delayed: delay time: 99656 Jump to behavior
Source: C:\Users\user\Desktop\Reiven RFQ-27-05-2024.exe Thread delayed: delay time: 99546 Jump to behavior
Source: C:\Users\user\Desktop\Reiven RFQ-27-05-2024.exe Thread delayed: delay time: 99437 Jump to behavior
Source: C:\Users\user\Desktop\Reiven RFQ-27-05-2024.exe Thread delayed: delay time: 99328 Jump to behavior
Source: C:\Users\user\Desktop\Reiven RFQ-27-05-2024.exe Thread delayed: delay time: 99218 Jump to behavior
Source: C:\Users\user\Desktop\Reiven RFQ-27-05-2024.exe Thread delayed: delay time: 99109 Jump to behavior
Source: C:\Users\user\Desktop\Reiven RFQ-27-05-2024.exe Thread delayed: delay time: 98996 Jump to behavior
Source: C:\Users\user\Desktop\Reiven RFQ-27-05-2024.exe Thread delayed: delay time: 98890 Jump to behavior
Source: C:\Users\user\Desktop\Reiven RFQ-27-05-2024.exe Thread delayed: delay time: 98781 Jump to behavior
Source: C:\Users\user\Desktop\Reiven RFQ-27-05-2024.exe Thread delayed: delay time: 98668 Jump to behavior
Source: C:\Users\user\Desktop\Reiven RFQ-27-05-2024.exe Thread delayed: delay time: 98562 Jump to behavior
Source: C:\Users\user\Desktop\Reiven RFQ-27-05-2024.exe Thread delayed: delay time: 98453 Jump to behavior
Source: C:\Users\user\Desktop\Reiven RFQ-27-05-2024.exe Thread delayed: delay time: 98343 Jump to behavior
Source: C:\Users\user\Desktop\Reiven RFQ-27-05-2024.exe Thread delayed: delay time: 98233 Jump to behavior
Source: C:\Users\user\Desktop\Reiven RFQ-27-05-2024.exe Thread delayed: delay time: 98125 Jump to behavior
Source: C:\Users\user\Desktop\Reiven RFQ-27-05-2024.exe Thread delayed: delay time: 98015 Jump to behavior
Source: C:\Users\user\Desktop\Reiven RFQ-27-05-2024.exe Thread delayed: delay time: 97906 Jump to behavior
Source: C:\Users\user\Desktop\Reiven RFQ-27-05-2024.exe Thread delayed: delay time: 97796 Jump to behavior
Source: C:\Users\user\Desktop\Reiven RFQ-27-05-2024.exe Thread delayed: delay time: 97687 Jump to behavior
Source: C:\Users\user\Desktop\Reiven RFQ-27-05-2024.exe Thread delayed: delay time: 922337203685477 Jump to behavior
Source: C:\Users\user\AppData\Roaming\GrOcCQC\GrOcCQC.exe Thread delayed: delay time: 922337203685477 Jump to behavior
Source: C:\Users\user\AppData\Roaming\GrOcCQC\GrOcCQC.exe Thread delayed: delay time: 922337203685477 Jump to behavior
Source: C:\Users\user\AppData\Roaming\GrOcCQC\GrOcCQC.exe Thread delayed: delay time: 100000 Jump to behavior
Source: C:\Users\user\AppData\Roaming\GrOcCQC\GrOcCQC.exe Thread delayed: delay time: 99890 Jump to behavior
Source: C:\Users\user\AppData\Roaming\GrOcCQC\GrOcCQC.exe Thread delayed: delay time: 99777 Jump to behavior
Source: C:\Users\user\AppData\Roaming\GrOcCQC\GrOcCQC.exe Thread delayed: delay time: 99672 Jump to behavior
Source: C:\Users\user\AppData\Roaming\GrOcCQC\GrOcCQC.exe Thread delayed: delay time: 99559 Jump to behavior
Source: C:\Users\user\AppData\Roaming\GrOcCQC\GrOcCQC.exe Thread delayed: delay time: 99453 Jump to behavior
Source: C:\Users\user\AppData\Roaming\GrOcCQC\GrOcCQC.exe Thread delayed: delay time: 99287 Jump to behavior
Source: C:\Users\user\AppData\Roaming\GrOcCQC\GrOcCQC.exe Thread delayed: delay time: 99146 Jump to behavior
Source: C:\Users\user\AppData\Roaming\GrOcCQC\GrOcCQC.exe Thread delayed: delay time: 99016 Jump to behavior
Source: C:\Users\user\AppData\Roaming\GrOcCQC\GrOcCQC.exe Thread delayed: delay time: 98906 Jump to behavior
Source: C:\Users\user\AppData\Roaming\GrOcCQC\GrOcCQC.exe Thread delayed: delay time: 98796 Jump to behavior
Source: C:\Users\user\AppData\Roaming\GrOcCQC\GrOcCQC.exe Thread delayed: delay time: 98687 Jump to behavior
Source: C:\Users\user\AppData\Roaming\GrOcCQC\GrOcCQC.exe Thread delayed: delay time: 98577 Jump to behavior
Source: C:\Users\user\AppData\Roaming\GrOcCQC\GrOcCQC.exe Thread delayed: delay time: 98469 Jump to behavior
Source: C:\Users\user\AppData\Roaming\GrOcCQC\GrOcCQC.exe Thread delayed: delay time: 98344 Jump to behavior
Source: C:\Users\user\AppData\Roaming\GrOcCQC\GrOcCQC.exe Thread delayed: delay time: 922337203685477 Jump to behavior
Source: C:\Users\user\AppData\Roaming\GrOcCQC\GrOcCQC.exe Thread delayed: delay time: 922337203685477 Jump to behavior
Source: C:\Users\user\AppData\Roaming\GrOcCQC\GrOcCQC.exe Thread delayed: delay time: 922337203685477 Jump to behavior
Source: C:\Users\user\AppData\Roaming\GrOcCQC\GrOcCQC.exe Thread delayed: delay time: 100000 Jump to behavior
Source: C:\Users\user\AppData\Roaming\GrOcCQC\GrOcCQC.exe Thread delayed: delay time: 99890 Jump to behavior
Source: C:\Users\user\AppData\Roaming\GrOcCQC\GrOcCQC.exe Thread delayed: delay time: 99781 Jump to behavior
Source: C:\Users\user\AppData\Roaming\GrOcCQC\GrOcCQC.exe Thread delayed: delay time: 99672 Jump to behavior
Source: C:\Users\user\AppData\Roaming\GrOcCQC\GrOcCQC.exe Thread delayed: delay time: 99563 Jump to behavior
Source: C:\Users\user\AppData\Roaming\GrOcCQC\GrOcCQC.exe Thread delayed: delay time: 99438 Jump to behavior
Source: C:\Users\user\AppData\Roaming\GrOcCQC\GrOcCQC.exe Thread delayed: delay time: 99313 Jump to behavior
Source: C:\Users\user\AppData\Roaming\GrOcCQC\GrOcCQC.exe Thread delayed: delay time: 99203 Jump to behavior
Source: C:\Users\user\AppData\Roaming\GrOcCQC\GrOcCQC.exe Thread delayed: delay time: 99094 Jump to behavior
Source: C:\Users\user\AppData\Roaming\GrOcCQC\GrOcCQC.exe Thread delayed: delay time: 98953 Jump to behavior
Source: C:\Users\user\AppData\Roaming\GrOcCQC\GrOcCQC.exe Thread delayed: delay time: 98844 Jump to behavior
Source: C:\Users\user\AppData\Roaming\GrOcCQC\GrOcCQC.exe Thread delayed: delay time: 98734 Jump to behavior
Source: C:\Users\user\AppData\Roaming\GrOcCQC\GrOcCQC.exe Thread delayed: delay time: 98625 Jump to behavior
Source: C:\Users\user\AppData\Roaming\GrOcCQC\GrOcCQC.exe Thread delayed: delay time: 98516 Jump to behavior
Source: C:\Users\user\AppData\Roaming\GrOcCQC\GrOcCQC.exe Thread delayed: delay time: 98406 Jump to behavior
Source: C:\Users\user\AppData\Roaming\GrOcCQC\GrOcCQC.exe Thread delayed: delay time: 98297 Jump to behavior
Source: C:\Users\user\AppData\Roaming\GrOcCQC\GrOcCQC.exe Thread delayed: delay time: 922337203685477 Jump to behavior
Source: GrOcCQC.exe, 00000006.00000002.3344090669.0000000005E80000.00000004.00000020.00020000.00000000.sdmp Binary or memory string: Hyper-V RAW%SystemRoot%\system32\mswsock.dllYP
Source: GrOcCQC.exe, 00000008.00000002.3328584752.0000000003125000.00000004.00000800.00020000.00000000.sdmp Binary or memory string: VMware
Source: Reiven RFQ-27-05-2024.exe, 00000003.00000002.3324165254.0000000000A1E000.00000004.00000020.00020000.00000000.sdmp Binary or memory string: Hyper-V RAW%SystemRoot%\system32\mswsock.dllz
Source: GrOcCQC.exe, 00000008.00000002.3328584752.0000000003125000.00000004.00000800.00020000.00000000.sdmp Binary or memory string: vmware
Source: Reiven RFQ-27-05-2024.exe, 00000000.00000002.2091795003.0000000003E3E000.00000004.00000800.00020000.00000000.sdmp Binary or memory string: VMwareVBoxESelect * from Win32_ComputerSystem
Source: GrOcCQC.exe, 00000008.00000002.3324461460.000000000143E000.00000004.00000020.00020000.00000000.sdmp Binary or memory string: Hyper-V RAW%SystemRoot%\system32\mswsock.dll
Source: C:\Users\user\Desktop\Reiven RFQ-27-05-2024.exe Process information queried: ProcessInformation Jump to behavior

Anti Debugging

barindex
Source: C:\Users\user\Desktop\Reiven RFQ-27-05-2024.exe Code function: 3_2_00EE70E0 CheckRemoteDebuggerPresent, 3_2_00EE70E0
Source: C:\Users\user\Desktop\Reiven RFQ-27-05-2024.exe Process queried: DebugPort Jump to behavior
Source: C:\Users\user\AppData\Roaming\GrOcCQC\GrOcCQC.exe Process queried: DebugPort Jump to behavior
Source: C:\Users\user\AppData\Roaming\GrOcCQC\GrOcCQC.exe Process queried: DebugPort Jump to behavior
Source: C:\Users\user\Desktop\Reiven RFQ-27-05-2024.exe Process token adjusted: Debug Jump to behavior
Source: C:\Users\user\Desktop\Reiven RFQ-27-05-2024.exe Memory allocated: page read and write | page guard Jump to behavior

HIPS / PFW / Operating System Protection Evasion

barindex
Source: C:\Users\user\Desktop\Reiven RFQ-27-05-2024.exe Memory written: C:\Users\user\Desktop\Reiven RFQ-27-05-2024.exe base: 400000 value starts with: 4D5A Jump to behavior
Source: C:\Users\user\AppData\Roaming\GrOcCQC\GrOcCQC.exe Memory written: C:\Users\user\AppData\Roaming\GrOcCQC\GrOcCQC.exe base: 400000 value starts with: 4D5A Jump to behavior
Source: C:\Users\user\AppData\Roaming\GrOcCQC\GrOcCQC.exe Memory written: C:\Users\user\AppData\Roaming\GrOcCQC\GrOcCQC.exe base: 400000 value starts with: 4D5A Jump to behavior
Source: C:\Users\user\Desktop\Reiven RFQ-27-05-2024.exe Process created: C:\Users\user\Desktop\Reiven RFQ-27-05-2024.exe "C:\Users\user\Desktop\Reiven RFQ-27-05-2024.exe" Jump to behavior
Source: C:\Users\user\AppData\Roaming\GrOcCQC\GrOcCQC.exe Process created: C:\Users\user\AppData\Roaming\GrOcCQC\GrOcCQC.exe "C:\Users\user\AppData\Roaming\GrOcCQC\GrOcCQC.exe" Jump to behavior
Source: C:\Users\user\AppData\Roaming\GrOcCQC\GrOcCQC.exe Process created: C:\Users\user\AppData\Roaming\GrOcCQC\GrOcCQC.exe "C:\Users\user\AppData\Roaming\GrOcCQC\GrOcCQC.exe" Jump to behavior
Source: C:\Users\user\Desktop\Reiven RFQ-27-05-2024.exe Queries volume information: C:\Users\user\Desktop\Reiven RFQ-27-05-2024.exe VolumeInformation Jump to behavior
Source: C:\Users\user\Desktop\Reiven RFQ-27-05-2024.exe Queries volume information: C:\Windows\Microsoft.NET\assembly\GAC_MSIL\System.Windows.Forms\v4.0_4.0.0.0__b77a5c561934e089\System.Windows.Forms.dll VolumeInformation Jump to behavior
Source: C:\Users\user\Desktop\Reiven RFQ-27-05-2024.exe Queries volume information: C:\Windows\Microsoft.NET\assembly\GAC_MSIL\System.Drawing\v4.0_4.0.0.0__b03f5f7f11d50a3a\System.Drawing.dll VolumeInformation Jump to behavior
Source: C:\Users\user\Desktop\Reiven RFQ-27-05-2024.exe Queries volume information: C:\Windows\Microsoft.NET\assembly\GAC_MSIL\Accessibility\v4.0_4.0.0.0__b03f5f7f11d50a3a\Accessibility.dll VolumeInformation Jump to behavior
Source: C:\Users\user\Desktop\Reiven RFQ-27-05-2024.exe Queries volume information: C:\Windows\Fonts\micross.ttf VolumeInformation Jump to behavior
Source: C:\Users\user\Desktop\Reiven RFQ-27-05-2024.exe Queries volume information: C:\Windows\Microsoft.NET\assembly\GAC_MSIL\Microsoft.VisualBasic\v4.0_10.0.0.0__b03f5f7f11d50a3a\Microsoft.VisualBasic.dll VolumeInformation Jump to behavior
Source: C:\Users\user\Desktop\Reiven RFQ-27-05-2024.exe Queries volume information: C:\Users\user\Desktop\Reiven RFQ-27-05-2024.exe VolumeInformation Jump to behavior
Source: C:\Users\user\Desktop\Reiven RFQ-27-05-2024.exe Queries volume information: C:\Windows\Microsoft.NET\assembly\GAC_MSIL\System.Windows.Forms\v4.0_4.0.0.0__b77a5c561934e089\System.Windows.Forms.dll VolumeInformation Jump to behavior
Source: C:\Users\user\Desktop\Reiven RFQ-27-05-2024.exe Queries volume information: C:\Windows\Microsoft.NET\assembly\GAC_MSIL\System.Security\v4.0_4.0.0.0__b03f5f7f11d50a3a\System.Security.dll VolumeInformation Jump to behavior
Source: C:\Users\user\Desktop\Reiven RFQ-27-05-2024.exe Queries volume information: C:\Windows\Microsoft.NET\assembly\GAC_MSIL\Microsoft.VisualBasic\v4.0_10.0.0.0__b03f5f7f11d50a3a\Microsoft.VisualBasic.dll VolumeInformation Jump to behavior
Source: C:\Users\user\Desktop\Reiven RFQ-27-05-2024.exe Queries volume information: C:\Windows\Microsoft.NET\assembly\GAC_MSIL\System.Drawing\v4.0_4.0.0.0__b03f5f7f11d50a3a\System.Drawing.dll VolumeInformation Jump to behavior
Source: C:\Users\user\Desktop\Reiven RFQ-27-05-2024.exe Queries volume information: C:\Windows\Microsoft.NET\assembly\GAC_MSIL\Accessibility\v4.0_4.0.0.0__b03f5f7f11d50a3a\Accessibility.dll VolumeInformation Jump to behavior
Source: C:\Users\user\AppData\Roaming\GrOcCQC\GrOcCQC.exe Queries volume information: C:\Users\user\AppData\Roaming\GrOcCQC\GrOcCQC.exe VolumeInformation Jump to behavior
Source: C:\Users\user\AppData\Roaming\GrOcCQC\GrOcCQC.exe Queries volume information: C:\Windows\Microsoft.NET\assembly\GAC_MSIL\System.Windows.Forms\v4.0_4.0.0.0__b77a5c561934e089\System.Windows.Forms.dll VolumeInformation Jump to behavior
Source: C:\Users\user\AppData\Roaming\GrOcCQC\GrOcCQC.exe Queries volume information: C:\Windows\Microsoft.NET\assembly\GAC_MSIL\System.Drawing\v4.0_4.0.0.0__b03f5f7f11d50a3a\System.Drawing.dll VolumeInformation Jump to behavior
Source: C:\Users\user\AppData\Roaming\GrOcCQC\GrOcCQC.exe Queries volume information: C:\Windows\Microsoft.NET\assembly\GAC_MSIL\Accessibility\v4.0_4.0.0.0__b03f5f7f11d50a3a\Accessibility.dll VolumeInformation Jump to behavior
Source: C:\Users\user\AppData\Roaming\GrOcCQC\GrOcCQC.exe Queries volume information: C:\Windows\Microsoft.NET\assembly\GAC_MSIL\Microsoft.VisualBasic\v4.0_10.0.0.0__b03f5f7f11d50a3a\Microsoft.VisualBasic.dll VolumeInformation Jump to behavior
Source: C:\Users\user\AppData\Roaming\GrOcCQC\GrOcCQC.exe Queries volume information: C:\Users\user\AppData\Roaming\GrOcCQC\GrOcCQC.exe VolumeInformation Jump to behavior
Source: C:\Users\user\AppData\Roaming\GrOcCQC\GrOcCQC.exe Queries volume information: C:\Windows\Microsoft.NET\assembly\GAC_MSIL\System.Windows.Forms\v4.0_4.0.0.0__b77a5c561934e089\System.Windows.Forms.dll VolumeInformation Jump to behavior
Source: C:\Users\user\AppData\Roaming\GrOcCQC\GrOcCQC.exe Queries volume information: C:\Windows\Microsoft.NET\assembly\GAC_MSIL\System.Security\v4.0_4.0.0.0__b03f5f7f11d50a3a\System.Security.dll VolumeInformation Jump to behavior
Source: C:\Users\user\AppData\Roaming\GrOcCQC\GrOcCQC.exe Queries volume information: C:\Windows\Microsoft.NET\assembly\GAC_MSIL\Microsoft.VisualBasic\v4.0_10.0.0.0__b03f5f7f11d50a3a\Microsoft.VisualBasic.dll VolumeInformation Jump to behavior
Source: C:\Users\user\AppData\Roaming\GrOcCQC\GrOcCQC.exe Queries volume information: C:\Windows\Microsoft.NET\assembly\GAC_MSIL\System.Drawing\v4.0_4.0.0.0__b03f5f7f11d50a3a\System.Drawing.dll VolumeInformation Jump to behavior
Source: C:\Users\user\AppData\Roaming\GrOcCQC\GrOcCQC.exe Queries volume information: C:\Windows\Microsoft.NET\assembly\GAC_MSIL\Accessibility\v4.0_4.0.0.0__b03f5f7f11d50a3a\Accessibility.dll VolumeInformation Jump to behavior
Source: C:\Users\user\AppData\Roaming\GrOcCQC\GrOcCQC.exe Queries volume information: C:\Users\user\AppData\Roaming\GrOcCQC\GrOcCQC.exe VolumeInformation Jump to behavior
Source: C:\Users\user\AppData\Roaming\GrOcCQC\GrOcCQC.exe Queries volume information: C:\Windows\Microsoft.NET\assembly\GAC_MSIL\System.Windows.Forms\v4.0_4.0.0.0__b77a5c561934e089\System.Windows.Forms.dll VolumeInformation Jump to behavior
Source: C:\Users\user\AppData\Roaming\GrOcCQC\GrOcCQC.exe Queries volume information: C:\Windows\Microsoft.NET\assembly\GAC_MSIL\System.Drawing\v4.0_4.0.0.0__b03f5f7f11d50a3a\System.Drawing.dll VolumeInformation Jump to behavior
Source: C:\Users\user\AppData\Roaming\GrOcCQC\GrOcCQC.exe Queries volume information: C:\Windows\Microsoft.NET\assembly\GAC_MSIL\Accessibility\v4.0_4.0.0.0__b03f5f7f11d50a3a\Accessibility.dll VolumeInformation Jump to behavior
Source: C:\Users\user\AppData\Roaming\GrOcCQC\GrOcCQC.exe Queries volume information: C:\Windows\Microsoft.NET\assembly\GAC_MSIL\Microsoft.VisualBasic\v4.0_10.0.0.0__b03f5f7f11d50a3a\Microsoft.VisualBasic.dll VolumeInformation Jump to behavior
Source: C:\Users\user\AppData\Roaming\GrOcCQC\GrOcCQC.exe Queries volume information: C:\Users\user\AppData\Roaming\GrOcCQC\GrOcCQC.exe VolumeInformation Jump to behavior
Source: C:\Users\user\AppData\Roaming\GrOcCQC\GrOcCQC.exe Queries volume information: C:\Windows\Microsoft.NET\assembly\GAC_MSIL\System.Windows.Forms\v4.0_4.0.0.0__b77a5c561934e089\System.Windows.Forms.dll VolumeInformation Jump to behavior
Source: C:\Users\user\AppData\Roaming\GrOcCQC\GrOcCQC.exe Queries volume information: C:\Windows\Microsoft.NET\assembly\GAC_MSIL\System.Security\v4.0_4.0.0.0__b03f5f7f11d50a3a\System.Security.dll VolumeInformation Jump to behavior
Source: C:\Users\user\AppData\Roaming\GrOcCQC\GrOcCQC.exe Queries volume information: C:\Windows\Microsoft.NET\assembly\GAC_MSIL\Microsoft.VisualBasic\v4.0_10.0.0.0__b03f5f7f11d50a3a\Microsoft.VisualBasic.dll VolumeInformation Jump to behavior
Source: C:\Users\user\AppData\Roaming\GrOcCQC\GrOcCQC.exe Queries volume information: C:\Windows\Microsoft.NET\assembly\GAC_MSIL\System.Drawing\v4.0_4.0.0.0__b03f5f7f11d50a3a\System.Drawing.dll VolumeInformation Jump to behavior
Source: C:\Users\user\AppData\Roaming\GrOcCQC\GrOcCQC.exe Queries volume information: C:\Windows\Microsoft.NET\assembly\GAC_MSIL\Accessibility\v4.0_4.0.0.0__b03f5f7f11d50a3a\Accessibility.dll VolumeInformation Jump to behavior
Source: C:\Users\user\Desktop\Reiven RFQ-27-05-2024.exe Key value queried: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Cryptography MachineGuid Jump to behavior

Stealing of Sensitive Information

barindex
Source: Yara match File source: 0.2.Reiven RFQ-27-05-2024.exe.3e3e5e0.2.unpack, type: UNPACKEDPE
Source: Yara match File source: 0.2.Reiven RFQ-27-05-2024.exe.3eaee00.1.unpack, type: UNPACKEDPE
Source: Yara match File source: 0.2.Reiven RFQ-27-05-2024.exe.3eaee00.1.raw.unpack, type: UNPACKEDPE
Source: Yara match File source: 0.2.Reiven RFQ-27-05-2024.exe.3e3e5e0.2.raw.unpack, type: UNPACKEDPE
Source: Yara match File source: 00000008.00000002.3328584752.0000000003152000.00000004.00000800.00020000.00000000.sdmp, type: MEMORY
Source: Yara match File source: 00000003.00000002.3328316664.0000000002A05000.00000004.00000800.00020000.00000000.sdmp, type: MEMORY
Source: Yara match File source: 00000003.00000002.3328316664.0000000002A56000.00000004.00000800.00020000.00000000.sdmp, type: MEMORY
Source: Yara match File source: 00000003.00000002.3328316664.0000000002A32000.00000004.00000800.00020000.00000000.sdmp, type: MEMORY
Source: Yara match File source: 00000006.00000002.3329095685.0000000002A15000.00000004.00000800.00020000.00000000.sdmp, type: MEMORY
Source: Yara match File source: 00000006.00000002.3329095685.0000000002A66000.00000004.00000800.00020000.00000000.sdmp, type: MEMORY
Source: Yara match File source: 00000008.00000002.3328584752.0000000003176000.00000004.00000800.00020000.00000000.sdmp, type: MEMORY
Source: Yara match File source: 00000006.00000002.3329095685.0000000002A42000.00000004.00000800.00020000.00000000.sdmp, type: MEMORY
Source: Yara match File source: 00000008.00000002.3328584752.0000000003125000.00000004.00000800.00020000.00000000.sdmp, type: MEMORY
Source: Yara match File source: 00000000.00000002.2091795003.0000000003E3E000.00000004.00000800.00020000.00000000.sdmp, type: MEMORY
Source: Yara match File source: Process Memory Space: Reiven RFQ-27-05-2024.exe PID: 1404, type: MEMORYSTR
Source: Yara match File source: Process Memory Space: Reiven RFQ-27-05-2024.exe PID: 5732, type: MEMORYSTR
Source: Yara match File source: Process Memory Space: GrOcCQC.exe PID: 3940, type: MEMORYSTR
Source: Yara match File source: Process Memory Space: GrOcCQC.exe PID: 3548, type: MEMORYSTR
Source: C:\Users\user\Desktop\Reiven RFQ-27-05-2024.exe Key opened: HKEY_CURRENT_USER\SOFTWARE\Martin Prikryl\WinSCP 2\Sessions Jump to behavior
Source: C:\Users\user\AppData\Roaming\GrOcCQC\GrOcCQC.exe Key opened: HKEY_CURRENT_USER\SOFTWARE\Martin Prikryl\WinSCP 2\Sessions Jump to behavior
Source: C:\Users\user\AppData\Roaming\GrOcCQC\GrOcCQC.exe Key opened: HKEY_CURRENT_USER\SOFTWARE\Martin Prikryl\WinSCP 2\Sessions Jump to behavior
Source: C:\Users\user\AppData\Roaming\GrOcCQC\GrOcCQC.exe File opened: C:\Users\user\AppData\Roaming\NETGATE Technologies\BlackHawk\profiles.ini Jump to behavior
Source: C:\Users\user\AppData\Roaming\GrOcCQC\GrOcCQC.exe File opened: C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Login Data Jump to behavior
Source: C:\Users\user\AppData\Roaming\GrOcCQC\GrOcCQC.exe File opened: C:\Users\user\AppData\Roaming\Mozilla\Firefox\profiles.ini Jump to behavior
Source: C:\Users\user\AppData\Roaming\GrOcCQC\GrOcCQC.exe File opened: C:\Users\user\AppData\Local\Microsoft\Edge\User Data\Default\Login Data Jump to behavior
Source: C:\Users\user\AppData\Roaming\GrOcCQC\GrOcCQC.exe File opened: C:\Users\user\AppData\Roaming\8pecxstudios\Cyberfox\profiles.ini Jump to behavior
Source: C:\Users\user\AppData\Roaming\GrOcCQC\GrOcCQC.exe File opened: C:\FTP Navigator\Ftplist.txt Jump to behavior
Source: C:\Users\user\Desktop\Reiven RFQ-27-05-2024.exe File opened: C:\Users\user\AppData\Roaming\Thunderbird\profiles.ini Jump to behavior
Source: C:\Users\user\Desktop\Reiven RFQ-27-05-2024.exe File opened: C:\Users\user\AppData\Roaming\Thunderbird\profiles.ini Jump to behavior
Source: C:\Users\user\Desktop\Reiven RFQ-27-05-2024.exe Key opened: HKEY_CURRENT_USER\Software\Microsoft\Windows NT\CurrentVersion\Windows Messaging Subsystem\Profiles Jump to behavior
Source: C:\Users\user\Desktop\Reiven RFQ-27-05-2024.exe Key opened: HKEY_CURRENT_USER\Software\IncrediMail\Identities Jump to behavior
Source: C:\Users\user\AppData\Roaming\GrOcCQC\GrOcCQC.exe File opened: C:\Users\user\AppData\Roaming\Thunderbird\profiles.ini Jump to behavior
Source: C:\Users\user\AppData\Roaming\GrOcCQC\GrOcCQC.exe File opened: C:\Users\user\AppData\Roaming\Thunderbird\profiles.ini Jump to behavior
Source: C:\Users\user\AppData\Roaming\GrOcCQC\GrOcCQC.exe Key opened: HKEY_CURRENT_USER\Software\Microsoft\Windows NT\CurrentVersion\Windows Messaging Subsystem\Profiles Jump to behavior
Source: C:\Users\user\AppData\Roaming\GrOcCQC\GrOcCQC.exe Key opened: HKEY_CURRENT_USER\Software\IncrediMail\Identities Jump to behavior
Source: C:\Users\user\AppData\Roaming\GrOcCQC\GrOcCQC.exe File opened: C:\Users\user\AppData\Roaming\Thunderbird\profiles.ini Jump to behavior
Source: C:\Users\user\AppData\Roaming\GrOcCQC\GrOcCQC.exe File opened: C:\Users\user\AppData\Roaming\Thunderbird\profiles.ini Jump to behavior
Source: C:\Users\user\AppData\Roaming\GrOcCQC\GrOcCQC.exe Key opened: HKEY_CURRENT_USER\Software\Microsoft\Windows NT\CurrentVersion\Windows Messaging Subsystem\Profiles Jump to behavior
Source: C:\Users\user\AppData\Roaming\GrOcCQC\GrOcCQC.exe Key opened: HKEY_CURRENT_USER\Software\IncrediMail\Identities Jump to behavior
Source: Yara match File source: 0.2.Reiven RFQ-27-05-2024.exe.3e3e5e0.2.unpack, type: UNPACKEDPE
Source: Yara match File source: 0.2.Reiven RFQ-27-05-2024.exe.3eaee00.1.unpack, type: UNPACKEDPE
Source: Yara match File source: 0.2.Reiven RFQ-27-05-2024.exe.3eaee00.1.raw.unpack, type: UNPACKEDPE
Source: Yara match File source: 0.2.Reiven RFQ-27-05-2024.exe.3e3e5e0.2.raw.unpack, type: UNPACKEDPE
Source: Yara match File source: 00000003.00000002.3328316664.0000000002A05000.00000004.00000800.00020000.00000000.sdmp, type: MEMORY
Source: Yara match File source: 00000006.00000002.3329095685.0000000002A15000.00000004.00000800.00020000.00000000.sdmp, type: MEMORY
Source: Yara match File source: 00000008.00000002.3328584752.0000000003125000.00000004.00000800.00020000.00000000.sdmp, type: MEMORY
Source: Yara match File source: 00000000.00000002.2091795003.0000000003E3E000.00000004.00000800.00020000.00000000.sdmp, type: MEMORY
Source: Yara match File source: Process Memory Space: Reiven RFQ-27-05-2024.exe PID: 1404, type: MEMORYSTR
Source: Yara match File source: Process Memory Space: Reiven RFQ-27-05-2024.exe PID: 5732, type: MEMORYSTR
Source: Yara match File source: Process Memory Space: GrOcCQC.exe PID: 3940, type: MEMORYSTR
Source: Yara match File source: Process Memory Space: GrOcCQC.exe PID: 3548, type: MEMORYSTR

Remote Access Functionality

barindex
Source: Yara match File source: 0.2.Reiven RFQ-27-05-2024.exe.3e3e5e0.2.unpack, type: UNPACKEDPE
Source: Yara match File source: 0.2.Reiven RFQ-27-05-2024.exe.3eaee00.1.unpack, type: UNPACKEDPE
Source: Yara match File source: 0.2.Reiven RFQ-27-05-2024.exe.3eaee00.1.raw.unpack, type: UNPACKEDPE
Source: Yara match File source: 0.2.Reiven RFQ-27-05-2024.exe.3e3e5e0.2.raw.unpack, type: UNPACKEDPE
Source: Yara match File source: 00000008.00000002.3328584752.0000000003152000.00000004.00000800.00020000.00000000.sdmp, type: MEMORY
Source: Yara match File source: 00000003.00000002.3328316664.0000000002A05000.00000004.00000800.00020000.00000000.sdmp, type: MEMORY
Source: Yara match File source: 00000003.00000002.3328316664.0000000002A56000.00000004.00000800.00020000.00000000.sdmp, type: MEMORY
Source: Yara match File source: 00000003.00000002.3328316664.0000000002A32000.00000004.00000800.00020000.00000000.sdmp, type: MEMORY
Source: Yara match File source: 00000006.00000002.3329095685.0000000002A15000.00000004.00000800.00020000.00000000.sdmp, type: MEMORY
Source: Yara match File source: 00000006.00000002.3329095685.0000000002A66000.00000004.00000800.00020000.00000000.sdmp, type: MEMORY
Source: Yara match File source: 00000008.00000002.3328584752.0000000003176000.00000004.00000800.00020000.00000000.sdmp, type: MEMORY
Source: Yara match File source: 00000006.00000002.3329095685.0000000002A42000.00000004.00000800.00020000.00000000.sdmp, type: MEMORY
Source: Yara match File source: 00000008.00000002.3328584752.0000000003125000.00000004.00000800.00020000.00000000.sdmp, type: MEMORY
Source: Yara match File source: 00000000.00000002.2091795003.0000000003E3E000.00000004.00000800.00020000.00000000.sdmp, type: MEMORY
Source: Yara match File source: Process Memory Space: Reiven RFQ-27-05-2024.exe PID: 1404, type: MEMORYSTR
Source: Yara match File source: Process Memory Space: Reiven RFQ-27-05-2024.exe PID: 5732, type: MEMORYSTR
Source: Yara match File source: Process Memory Space: GrOcCQC.exe PID: 3940, type: MEMORYSTR
Source: Yara match File source: Process Memory Space: GrOcCQC.exe PID: 3548, type: MEMORYSTR
  • No. of IPs < 25%
  • 25% < No. of IPs < 50%
  • 50% < No. of IPs < 75%
  • 75% < No. of IPs