Source: Insanity Loader.exe, 00000000.00000002.2041615026.00000000025F5000.00000004.00000800.00020000.00000000.sdmp | String found in binary or memory: $]q3IndexedDB\https_www.youtube.com_0.indexeddb.leveldb@\]q equals www.youtube.com (Youtube) |
Source: Insanity Loader.exe, 00000000.00000002.2041615026.00000000025F5000.00000004.00000800.00020000.00000000.sdmp | String found in binary or memory: IndexedDB\https_www.youtube.com_0.indexeddb.leveldb equals www.youtube.com (Youtube) |
Source: Insanity Loader.exe, 00000000.00000002.2041615026.00000000025F5000.00000004.00000800.00020000.00000000.sdmp | String found in binary or memory: IndexedDB\https_www.youtube.com_0.indexeddb.leveldb@\]q equals www.youtube.com (Youtube) |
Source: Insanity Loader.exe, 00000000.00000002.2041615026.00000000025F5000.00000004.00000800.00020000.00000000.sdmp | String found in binary or memory: IndexedDB\https_www.youtube.com_0.indexeddb.leveldb`,]q equals www.youtube.com (Youtube) |
Source: Insanity Loader.exe, 00000000.00000002.2041615026.00000000025F5000.00000004.00000800.00020000.00000000.sdmp | String found in binary or memory: `,]q#www.youtube.com_0.indexeddb.leveldb equals www.youtube.com (Youtube) |
Source: 0.2.Insanity Loader.exe.4b10ee8.6.raw.unpack, HWiM5nizdBqTYpoFw7P.cs | Large array initialization: HWiM5nizdBqTYpoFw7P: array initializer size 6160 |
Source: 0.2.Insanity Loader.exe.2238ab6.2.raw.unpack, HWiM5nizdBqTYpoFw7P.cs | Large array initialization: HWiM5nizdBqTYpoFw7P: array initializer size 6160 |
Source: 0.2.Insanity Loader.exe.3576790.5.raw.unpack, HWiM5nizdBqTYpoFw7P.cs | Large array initialization: HWiM5nizdBqTYpoFw7P: array initializer size 6160 |
Source: 0.2.Insanity Loader.exe.3526458.3.raw.unpack, HWiM5nizdBqTYpoFw7P.cs | Large array initialization: HWiM5nizdBqTYpoFw7P: array initializer size 6160 |
Source: 0.2.Insanity Loader.exe.5230000.8.raw.unpack, HWiM5nizdBqTYpoFw7P.cs | Large array initialization: HWiM5nizdBqTYpoFw7P: array initializer size 6160 |
Source: C:\Users\user\Desktop\Insanity Loader.exe | Code function: 0_2_00408C60 | 0_2_00408C60 |
Source: C:\Users\user\Desktop\Insanity Loader.exe | Code function: 0_2_0040DC11 | 0_2_0040DC11 |
Source: C:\Users\user\Desktop\Insanity Loader.exe | Code function: 0_2_00407C3F | 0_2_00407C3F |
Source: C:\Users\user\Desktop\Insanity Loader.exe | Code function: 0_2_00418CCC | 0_2_00418CCC |
Source: C:\Users\user\Desktop\Insanity Loader.exe | Code function: 0_2_00406CA0 | 0_2_00406CA0 |
Source: C:\Users\user\Desktop\Insanity Loader.exe | Code function: 0_2_004028B0 | 0_2_004028B0 |
Source: C:\Users\user\Desktop\Insanity Loader.exe | Code function: 0_2_0041A4BE | 0_2_0041A4BE |
Source: C:\Users\user\Desktop\Insanity Loader.exe | Code function: 0_2_00418244 | 0_2_00418244 |
Source: C:\Users\user\Desktop\Insanity Loader.exe | Code function: 0_2_00401650 | 0_2_00401650 |
Source: C:\Users\user\Desktop\Insanity Loader.exe | Code function: 0_2_00402F20 | 0_2_00402F20 |
Source: C:\Users\user\Desktop\Insanity Loader.exe | Code function: 0_2_004193C4 | 0_2_004193C4 |
Source: C:\Users\user\Desktop\Insanity Loader.exe | Code function: 0_2_00418788 | 0_2_00418788 |
Source: C:\Users\user\Desktop\Insanity Loader.exe | Code function: 0_2_00402F89 | 0_2_00402F89 |
Source: C:\Users\user\Desktop\Insanity Loader.exe | Code function: 0_2_00402B90 | 0_2_00402B90 |
Source: C:\Users\user\Desktop\Insanity Loader.exe | Code function: 0_2_004073A0 | 0_2_004073A0 |
Source: C:\Users\user\Desktop\Insanity Loader.exe | Code function: 0_2_0215E17C | 0_2_0215E17C |
Source: C:\Users\user\Desktop\Insanity Loader.exe | Code function: 0_2_02152ECC | 0_2_02152ECC |
Source: C:\Users\user\Desktop\Insanity Loader.exe | Code function: 0_2_053A1638 | 0_2_053A1638 |
Source: C:\Users\user\Desktop\Insanity Loader.exe | Code function: 0_2_053A01D8 | 0_2_053A01D8 |
Source: C:\Users\user\Desktop\Insanity Loader.exe | Code function: 0_2_053A01C8 | 0_2_053A01C8 |
Source: C:\Users\user\Desktop\Insanity Loader.exe | Code function: 0_2_054ED3B0 | 0_2_054ED3B0 |
Source: C:\Users\user\Desktop\Insanity Loader.exe | Code function: 0_2_054ECE88 | 0_2_054ECE88 |
Source: C:\Users\user\Desktop\Insanity Loader.exe | Code function: 0_2_056B04D0 | 0_2_056B04D0 |
Source: C:\Users\user\Desktop\Insanity Loader.exe | Code function: 0_2_056B6C18 | 0_2_056B6C18 |
Source: Insanity Loader.exe, 00000000.00000003.2028040085.00000000006FD000.00000004.00000020.00020000.00000000.sdmp | Binary or memory string: OriginalFilenameMsMpLics.dllj% vs Insanity Loader.exe |
Source: Insanity Loader.exe, 00000000.00000002.2041056918.00000000021F7000.00000004.00000020.00020000.00000000.sdmp | Binary or memory string: OriginalFilenameParsimony.exe" vs Insanity Loader.exe |
Source: Insanity Loader.exe, 00000000.00000002.2041056918.00000000021F7000.00000004.00000020.00020000.00000000.sdmp | Binary or memory string: OriginalFilename_.dll4 vs Insanity Loader.exe |
Source: Insanity Loader.exe, 00000000.00000002.2039786224.0000000000480000.00000004.00000001.01000000.00000003.sdmp | Binary or memory string: OriginalFilenameParsimony.exe" vs Insanity Loader.exe |
Source: Insanity Loader.exe, 00000000.00000003.2028108861.0000000000711000.00000004.00000020.00020000.00000000.sdmp | Binary or memory string: OriginalFilenameMsMpLics.dllj% vs Insanity Loader.exe |
Source: Insanity Loader.exe, 00000000.00000003.2028306043.000000000067B000.00000004.00000020.00020000.00000000.sdmp | Binary or memory string: OriginalFilenameParsimony.exe" vs Insanity Loader.exe |
Source: Insanity Loader.exe, 00000000.00000003.2028306043.000000000067B000.00000004.00000020.00020000.00000000.sdmp | Binary or memory string: OriginalFilename_.dll4 vs Insanity Loader.exe |
Source: Insanity Loader.exe, 00000000.00000002.2044966965.0000000005230000.00000004.08000000.00040000.00000000.sdmp | Binary or memory string: OriginalFilenameParsimony.exe" vs Insanity Loader.exe |
Source: Insanity Loader.exe, 00000000.00000002.2044454481.0000000003521000.00000004.00000800.00020000.00000000.sdmp | Binary or memory string: OriginalFilenameParsimony.exe" vs Insanity Loader.exe |
Source: Insanity Loader.exe, 00000000.00000002.2044454481.0000000003521000.00000004.00000800.00020000.00000000.sdmp | Binary or memory string: OriginalFilename_.dll4 vs Insanity Loader.exe |
Source: Insanity Loader.exe, 00000000.00000002.2044602082.0000000004B10000.00000004.08000000.00040000.00000000.sdmp | Binary or memory string: OriginalFilenameParsimony.exe" vs Insanity Loader.exe |
Source: Insanity Loader.exe, 00000000.00000002.2044602082.0000000004B10000.00000004.08000000.00040000.00000000.sdmp | Binary or memory string: OriginalFilename_.dll4 vs Insanity Loader.exe |
Source: Insanity Loader.exe | Binary or memory string: OriginalFilenameParsimony.exe" vs Insanity Loader.exe |
Source: Insanity Loader.exe, type: SAMPLE | Matched rule: MALWARE_Win_RedLine snort2_sid = 920072-920073, author = ditekSHen, description = Detects RedLine infostealer, clamav_sig = MALWARE.Win.Trojan.RedLine-1, MALWARE.Win.Trojan.RedLine-2, snort3_sid = 920072-920073 |
Source: 0.0.Insanity Loader.exe.400000.0.unpack, type: UNPACKEDPE | Matched rule: MALWARE_Win_RedLine snort2_sid = 920072-920073, author = ditekSHen, description = Detects RedLine infostealer, clamav_sig = MALWARE.Win.Trojan.RedLine-1, MALWARE.Win.Trojan.RedLine-2, snort3_sid = 920072-920073 |
Source: 0.2.Insanity Loader.exe.400000.0.unpack, type: UNPACKEDPE | Matched rule: MALWARE_Win_RedLine snort2_sid = 920072-920073, author = ditekSHen, description = Detects RedLine infostealer, clamav_sig = MALWARE.Win.Trojan.RedLine-1, MALWARE.Win.Trojan.RedLine-2, snort3_sid = 920072-920073 |
Source: 0.2.Insanity Loader.exe.4b10ee8.6.raw.unpack, HWiM5nizdBqTYpoFw7P.cs | Cryptographic APIs: 'CreateDecryptor' |
Source: 0.2.Insanity Loader.exe.4b10ee8.6.raw.unpack, vnUNrf9zTHJhL6tQfxd.cs | Cryptographic APIs: 'TransformFinalBlock' |
Source: 0.2.Insanity Loader.exe.2238ab6.2.raw.unpack, HWiM5nizdBqTYpoFw7P.cs | Cryptographic APIs: 'CreateDecryptor' |
Source: 0.2.Insanity Loader.exe.2238ab6.2.raw.unpack, vnUNrf9zTHJhL6tQfxd.cs | Cryptographic APIs: 'TransformFinalBlock' |
Source: 0.2.Insanity Loader.exe.3576790.5.raw.unpack, HWiM5nizdBqTYpoFw7P.cs | Cryptographic APIs: 'CreateDecryptor' |
Source: 0.2.Insanity Loader.exe.3576790.5.raw.unpack, vnUNrf9zTHJhL6tQfxd.cs | Cryptographic APIs: 'TransformFinalBlock' |
Source: 0.2.Insanity Loader.exe.3526458.3.raw.unpack, HWiM5nizdBqTYpoFw7P.cs | Cryptographic APIs: 'CreateDecryptor' |
Source: 0.2.Insanity Loader.exe.3526458.3.raw.unpack, vnUNrf9zTHJhL6tQfxd.cs | Cryptographic APIs: 'TransformFinalBlock' |
Source: 0.2.Insanity Loader.exe.5230000.8.raw.unpack, HWiM5nizdBqTYpoFw7P.cs | Cryptographic APIs: 'CreateDecryptor' |
Source: 0.2.Insanity Loader.exe.5230000.8.raw.unpack, vnUNrf9zTHJhL6tQfxd.cs | Cryptographic APIs: 'TransformFinalBlock' |
Source: C:\Users\user\Desktop\Insanity Loader.exe | Code function: 0_2_004019F0 OleInitialize,_getenv,GetCurrentProcessId,CreateToolhelp32Snapshot,Module32First,CloseHandle,Module32Next,Module32Next,FindCloseChangeNotification,GetModuleHandleA,FindResourceA,LoadResource,LockResource,SizeofResource,_malloc,_memset,SizeofResource,_memset,KiUserExceptionDispatcher,FreeResource,_malloc,SizeofResource,_memset,LoadLibraryA,GetProcAddress,VariantInit,VariantInit,VariantInit,SafeArrayCreate,SafeArrayAccessData,SafeArrayUnaccessData,SafeArrayDestroy,SafeArrayCreateVector,VariantClear,VariantClear,VariantClear, | 0_2_004019F0 |
Source: C:\Users\user\Desktop\Insanity Loader.exe | Code function: 0_2_004019F0 OleInitialize,_getenv,GetCurrentProcessId,CreateToolhelp32Snapshot,Module32First,CloseHandle,Module32Next,Module32Next,FindCloseChangeNotification,GetModuleHandleA,FindResourceA,LoadResource,LockResource,SizeofResource,_malloc,_memset,SizeofResource,_memset,KiUserExceptionDispatcher,FreeResource,_malloc,SizeofResource,_memset,LoadLibraryA,GetProcAddress,VariantInit,VariantInit,VariantInit,SafeArrayCreate,SafeArrayAccessData,SafeArrayUnaccessData,SafeArrayDestroy,SafeArrayCreateVector,VariantClear,VariantClear,VariantClear, | 0_2_004019F0 |
Source: C:\Users\user\Desktop\Insanity Loader.exe | Section loaded: apphelp.dll | Jump to behavior |
Source: C:\Users\user\Desktop\Insanity Loader.exe | Section loaded: kernel.appcore.dll | Jump to behavior |
Source: C:\Users\user\Desktop\Insanity Loader.exe | Section loaded: uxtheme.dll | Jump to behavior |
Source: C:\Users\user\Desktop\Insanity Loader.exe | Section loaded: mscoree.dll | Jump to behavior |
Source: C:\Users\user\Desktop\Insanity Loader.exe | Section loaded: vcruntime140_clr0400.dll | Jump to behavior |
Source: C:\Users\user\Desktop\Insanity Loader.exe | Section loaded: ucrtbase_clr0400.dll | Jump to behavior |
Source: C:\Users\user\Desktop\Insanity Loader.exe | Section loaded: wldp.dll | Jump to behavior |
Source: C:\Users\user\Desktop\Insanity Loader.exe | Section loaded: amsi.dll | Jump to behavior |
Source: C:\Users\user\Desktop\Insanity Loader.exe | Section loaded: userenv.dll | Jump to behavior |
Source: C:\Users\user\Desktop\Insanity Loader.exe | Section loaded: profapi.dll | Jump to behavior |
Source: C:\Users\user\Desktop\Insanity Loader.exe | Section loaded: version.dll | Jump to behavior |
Source: C:\Users\user\Desktop\Insanity Loader.exe | Section loaded: msasn1.dll | Jump to behavior |
Source: C:\Users\user\Desktop\Insanity Loader.exe | Section loaded: gpapi.dll | Jump to behavior |
Source: C:\Users\user\Desktop\Insanity Loader.exe | Section loaded: cryptsp.dll | Jump to behavior |
Source: C:\Users\user\Desktop\Insanity Loader.exe | Section loaded: rsaenh.dll | Jump to behavior |
Source: C:\Users\user\Desktop\Insanity Loader.exe | Section loaded: cryptbase.dll | Jump to behavior |
Source: C:\Users\user\Desktop\Insanity Loader.exe | Section loaded: windows.storage.dll | Jump to behavior |
Source: C:\Users\user\Desktop\Insanity Loader.exe | Section loaded: dwrite.dll | Jump to behavior |
Source: C:\Users\user\Desktop\Insanity Loader.exe | Section loaded: textshaping.dll | Jump to behavior |
Source: C:\Users\user\Desktop\Insanity Loader.exe | Code function: 0_2_004019F0 OleInitialize,_getenv,GetCurrentProcessId,CreateToolhelp32Snapshot,Module32First,CloseHandle,Module32Next,Module32Next,FindCloseChangeNotification,GetModuleHandleA,FindResourceA,LoadResource,LockResource,SizeofResource,_malloc,_memset,SizeofResource,_memset,KiUserExceptionDispatcher,FreeResource,_malloc,SizeofResource,_memset,LoadLibraryA,GetProcAddress,VariantInit,VariantInit,VariantInit,SafeArrayCreate,SafeArrayAccessData,SafeArrayUnaccessData,SafeArrayDestroy,SafeArrayCreateVector,VariantClear,VariantClear,VariantClear, | 0_2_004019F0 |
Source: 0.2.Insanity Loader.exe.4b10ee8.6.raw.unpack, JrDgcb8ExbnxoKvHj0h.cs | High entropy of concatenated method names: 'ShowMessage', 'VxW8CTIwiU', 'IKm8os5L55', 'gom8AC5UqJ', 'B0b8F7YMg0', 'E0c8g7rGpw', 'reY848S8mQ', 'aKZ8z7WlxN', 'nDRQayamBL', 'U5OQ6dLhrU' |
Source: 0.2.Insanity Loader.exe.4b10ee8.6.raw.unpack, eYHragi8ZCpLS1lWPwX.cs | High entropy of concatenated method names: 'lb8iuDNCWP', 'A5UiZDAsol', 'XSai99a8ti', 'S1Eily3Nq0', 'OMTiJWE6ZX', 'AfyitOTe6J', 'LqEiDT7lu7', 'VXbiPDVIHO', 'wjwibsCoYQ', 'pKaidcbP2q' |
Source: 0.2.Insanity Loader.exe.4b10ee8.6.raw.unpack, HMcqtE6J6r1oToPnxPf.cs | High entropy of concatenated method names: 'rpg63nTtcd', 'Fme6OAaSE1', 'MS16rZKoi4', 'wAO6N8pqBw', 'n6p6DgAamV', 'R3o6PgF73A', 'ekH6bn75Ls', 'wrq6dI3ts6', 'jXM60OtGM7', 'KO76wXfsvZ' |
Source: 0.2.Insanity Loader.exe.4b10ee8.6.raw.unpack, qqaOQ7MORaiyuX290kx.cs | High entropy of concatenated method names: 'NOCbz6OMLf', 'TALdQQC9dP', 'qcuMrAL091', 'sGCMNdH9uR', 'DD3MIrZ56s', 'xEvMeNt3nr', 'tgNMcYqoLe', 'hHUbghaJSm', 'bmHdatxIPx', 'AgoduRIEmN' |
Source: 0.2.Insanity Loader.exe.2238ab6.2.raw.unpack, JrDgcb8ExbnxoKvHj0h.cs | High entropy of concatenated method names: 'ShowMessage', 'VxW8CTIwiU', 'IKm8os5L55', 'gom8AC5UqJ', 'B0b8F7YMg0', 'E0c8g7rGpw', 'reY848S8mQ', 'aKZ8z7WlxN', 'nDRQayamBL', 'U5OQ6dLhrU' |
Source: 0.2.Insanity Loader.exe.2238ab6.2.raw.unpack, eYHragi8ZCpLS1lWPwX.cs | High entropy of concatenated method names: 'lb8iuDNCWP', 'A5UiZDAsol', 'XSai99a8ti', 'S1Eily3Nq0', 'OMTiJWE6ZX', 'AfyitOTe6J', 'LqEiDT7lu7', 'VXbiPDVIHO', 'wjwibsCoYQ', 'pKaidcbP2q' |
Source: 0.2.Insanity Loader.exe.2238ab6.2.raw.unpack, HMcqtE6J6r1oToPnxPf.cs | High entropy of concatenated method names: 'rpg63nTtcd', 'Fme6OAaSE1', 'MS16rZKoi4', 'wAO6N8pqBw', 'n6p6DgAamV', 'R3o6PgF73A', 'ekH6bn75Ls', 'wrq6dI3ts6', 'jXM60OtGM7', 'KO76wXfsvZ' |
Source: 0.2.Insanity Loader.exe.2238ab6.2.raw.unpack, qqaOQ7MORaiyuX290kx.cs | High entropy of concatenated method names: 'NOCbz6OMLf', 'TALdQQC9dP', 'qcuMrAL091', 'sGCMNdH9uR', 'DD3MIrZ56s', 'xEvMeNt3nr', 'tgNMcYqoLe', 'hHUbghaJSm', 'bmHdatxIPx', 'AgoduRIEmN' |
Source: 0.2.Insanity Loader.exe.3576790.5.raw.unpack, JrDgcb8ExbnxoKvHj0h.cs | High entropy of concatenated method names: 'ShowMessage', 'VxW8CTIwiU', 'IKm8os5L55', 'gom8AC5UqJ', 'B0b8F7YMg0', 'E0c8g7rGpw', 'reY848S8mQ', 'aKZ8z7WlxN', 'nDRQayamBL', 'U5OQ6dLhrU' |
Source: 0.2.Insanity Loader.exe.3576790.5.raw.unpack, eYHragi8ZCpLS1lWPwX.cs | High entropy of concatenated method names: 'lb8iuDNCWP', 'A5UiZDAsol', 'XSai99a8ti', 'S1Eily3Nq0', 'OMTiJWE6ZX', 'AfyitOTe6J', 'LqEiDT7lu7', 'VXbiPDVIHO', 'wjwibsCoYQ', 'pKaidcbP2q' |
Source: 0.2.Insanity Loader.exe.3576790.5.raw.unpack, HMcqtE6J6r1oToPnxPf.cs | High entropy of concatenated method names: 'rpg63nTtcd', 'Fme6OAaSE1', 'MS16rZKoi4', 'wAO6N8pqBw', 'n6p6DgAamV', 'R3o6PgF73A', 'ekH6bn75Ls', 'wrq6dI3ts6', 'jXM60OtGM7', 'KO76wXfsvZ' |
Source: 0.2.Insanity Loader.exe.3576790.5.raw.unpack, qqaOQ7MORaiyuX290kx.cs | High entropy of concatenated method names: 'NOCbz6OMLf', 'TALdQQC9dP', 'qcuMrAL091', 'sGCMNdH9uR', 'DD3MIrZ56s', 'xEvMeNt3nr', 'tgNMcYqoLe', 'hHUbghaJSm', 'bmHdatxIPx', 'AgoduRIEmN' |
Source: 0.2.Insanity Loader.exe.3526458.3.raw.unpack, JrDgcb8ExbnxoKvHj0h.cs | High entropy of concatenated method names: 'ShowMessage', 'VxW8CTIwiU', 'IKm8os5L55', 'gom8AC5UqJ', 'B0b8F7YMg0', 'E0c8g7rGpw', 'reY848S8mQ', 'aKZ8z7WlxN', 'nDRQayamBL', 'U5OQ6dLhrU' |
Source: 0.2.Insanity Loader.exe.3526458.3.raw.unpack, eYHragi8ZCpLS1lWPwX.cs | High entropy of concatenated method names: 'lb8iuDNCWP', 'A5UiZDAsol', 'XSai99a8ti', 'S1Eily3Nq0', 'OMTiJWE6ZX', 'AfyitOTe6J', 'LqEiDT7lu7', 'VXbiPDVIHO', 'wjwibsCoYQ', 'pKaidcbP2q' |
Source: 0.2.Insanity Loader.exe.3526458.3.raw.unpack, HMcqtE6J6r1oToPnxPf.cs | High entropy of concatenated method names: 'rpg63nTtcd', 'Fme6OAaSE1', 'MS16rZKoi4', 'wAO6N8pqBw', 'n6p6DgAamV', 'R3o6PgF73A', 'ekH6bn75Ls', 'wrq6dI3ts6', 'jXM60OtGM7', 'KO76wXfsvZ' |
Source: 0.2.Insanity Loader.exe.3526458.3.raw.unpack, qqaOQ7MORaiyuX290kx.cs | High entropy of concatenated method names: 'NOCbz6OMLf', 'TALdQQC9dP', 'qcuMrAL091', 'sGCMNdH9uR', 'DD3MIrZ56s', 'xEvMeNt3nr', 'tgNMcYqoLe', 'hHUbghaJSm', 'bmHdatxIPx', 'AgoduRIEmN' |
Source: 0.2.Insanity Loader.exe.5230000.8.raw.unpack, JrDgcb8ExbnxoKvHj0h.cs | High entropy of concatenated method names: 'ShowMessage', 'VxW8CTIwiU', 'IKm8os5L55', 'gom8AC5UqJ', 'B0b8F7YMg0', 'E0c8g7rGpw', 'reY848S8mQ', 'aKZ8z7WlxN', 'nDRQayamBL', 'U5OQ6dLhrU' |
Source: 0.2.Insanity Loader.exe.5230000.8.raw.unpack, eYHragi8ZCpLS1lWPwX.cs | High entropy of concatenated method names: 'lb8iuDNCWP', 'A5UiZDAsol', 'XSai99a8ti', 'S1Eily3Nq0', 'OMTiJWE6ZX', 'AfyitOTe6J', 'LqEiDT7lu7', 'VXbiPDVIHO', 'wjwibsCoYQ', 'pKaidcbP2q' |
Source: 0.2.Insanity Loader.exe.5230000.8.raw.unpack, HMcqtE6J6r1oToPnxPf.cs | High entropy of concatenated method names: 'rpg63nTtcd', 'Fme6OAaSE1', 'MS16rZKoi4', 'wAO6N8pqBw', 'n6p6DgAamV', 'R3o6PgF73A', 'ekH6bn75Ls', 'wrq6dI3ts6', 'jXM60OtGM7', 'KO76wXfsvZ' |
Source: 0.2.Insanity Loader.exe.5230000.8.raw.unpack, qqaOQ7MORaiyuX290kx.cs | High entropy of concatenated method names: 'NOCbz6OMLf', 'TALdQQC9dP', 'qcuMrAL091', 'sGCMNdH9uR', 'DD3MIrZ56s', 'xEvMeNt3nr', 'tgNMcYqoLe', 'hHUbghaJSm', 'bmHdatxIPx', 'AgoduRIEmN' |
Source: C:\Users\user\Desktop\Insanity Loader.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\Insanity Loader.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\Insanity Loader.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\Insanity Loader.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\Insanity Loader.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\Insanity Loader.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\Insanity Loader.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\Insanity Loader.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\Insanity Loader.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\Insanity Loader.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\Insanity Loader.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\Insanity Loader.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\Insanity Loader.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\Insanity Loader.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\Insanity Loader.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\Insanity Loader.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\Insanity Loader.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\Insanity Loader.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\Insanity Loader.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\Insanity Loader.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\Insanity Loader.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\Insanity Loader.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\Insanity Loader.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\Insanity Loader.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\Insanity Loader.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\Insanity Loader.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\Insanity Loader.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\Insanity Loader.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\Insanity Loader.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\Insanity Loader.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\Insanity Loader.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\Insanity Loader.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\Insanity Loader.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\Insanity Loader.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\Insanity Loader.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\Insanity Loader.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\Insanity Loader.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\Insanity Loader.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\Insanity Loader.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\Insanity Loader.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\Insanity Loader.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\Insanity Loader.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\Insanity Loader.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\Insanity Loader.exe | Code function: 0_2_004019F0 OleInitialize,_getenv,GetCurrentProcessId,CreateToolhelp32Snapshot,Module32First,CloseHandle,Module32Next,Module32Next,FindCloseChangeNotification,GetModuleHandleA,FindResourceA,LoadResource,LockResource,SizeofResource,_malloc,_memset,SizeofResource,_memset,KiUserExceptionDispatcher,FreeResource,_malloc,SizeofResource,_memset,LoadLibraryA,GetProcAddress,VariantInit,VariantInit,VariantInit,SafeArrayCreate,SafeArrayAccessData,SafeArrayUnaccessData,SafeArrayDestroy,SafeArrayCreateVector,VariantClear,VariantClear,VariantClear, | 0_2_004019F0 |
Source: C:\Users\user\Desktop\Insanity Loader.exe | Code function: 0_2_004019F0 OleInitialize,_getenv,GetCurrentProcessId,CreateToolhelp32Snapshot,Module32First,CloseHandle,Module32Next,Module32Next,FindCloseChangeNotification,GetModuleHandleA,FindResourceA,LoadResource,LockResource,SizeofResource,_malloc,_memset,SizeofResource,_memset,KiUserExceptionDispatcher,FreeResource,_malloc,SizeofResource,_memset,LoadLibraryA,GetProcAddress,VariantInit,VariantInit,VariantInit,SafeArrayCreate,SafeArrayAccessData,SafeArrayUnaccessData,SafeArrayDestroy,SafeArrayCreateVector,VariantClear,VariantClear,VariantClear, | 0_2_004019F0 |
Source: C:\Users\user\Desktop\Insanity Loader.exe | Code function: 0_2_004019F0 OleInitialize,_getenv,GetCurrentProcessId,CreateToolhelp32Snapshot,Module32First,CloseHandle,Module32Next,Module32Next,FindCloseChangeNotification,GetModuleHandleA,FindResourceA,LoadResource,LockResource,SizeofResource,_malloc,_memset,SizeofResource,_memset,KiUserExceptionDispatcher,FreeResource,_malloc,SizeofResource,_memset,LoadLibraryA,GetProcAddress,VariantInit,VariantInit,VariantInit,SafeArrayCreate,SafeArrayAccessData,SafeArrayUnaccessData,SafeArrayDestroy,SafeArrayCreateVector,VariantClear,VariantClear,VariantClear, | 0_2_004019F0 |
Source: C:\Users\user\Desktop\Insanity Loader.exe | Code function: 0_2_0040CE09 IsDebuggerPresent,SetUnhandledExceptionFilter,UnhandledExceptionFilter,GetCurrentProcess,TerminateProcess, | 0_2_0040CE09 |
Source: C:\Users\user\Desktop\Insanity Loader.exe | Code function: 0_2_0040E61C _memset,IsDebuggerPresent,SetUnhandledExceptionFilter,UnhandledExceptionFilter,GetCurrentProcess,TerminateProcess, | 0_2_0040E61C |
Source: C:\Users\user\Desktop\Insanity Loader.exe | Code function: 0_2_00416F6A __NMSG_WRITE,_raise,_memset,SetUnhandledExceptionFilter,UnhandledExceptionFilter, | 0_2_00416F6A |
Source: C:\Users\user\Desktop\Insanity Loader.exe | Code function: 0_2_004123F1 SetUnhandledExceptionFilter, | 0_2_004123F1 |