Click to jump to signature section
Source: Submited Sample | Integrated Neural Analysis Model: Matched 99.0% probability |
Source: SecuriteInfo.com.Heur.29270.15038.exe | Static PE information: EXECUTABLE_IMAGE, LINE_NUMS_STRIPPED, LOCAL_SYMS_STRIPPED, LARGE_ADDRESS_AWARE, 32BIT_MACHINE |
Source: C:\Users\user\Desktop\SecuriteInfo.com.Heur.29270.15038.exe | File opened: C:\Windows\WinSxS\amd64_microsoft.vc80.crt_1fc8b3b9a1e18e3b_8.0.50727.9672_none_88e266cb2fac7c0d\MSVCR80.dll | Jump to behavior |
Source: SecuriteInfo.com.Heur.29270.15038.exe | Static PE information: DYNAMIC_BASE, NX_COMPAT, NO_SEH, TERMINAL_SERVER_AWARE |
Source: | Binary string: JpgCSize.pdb source: SecuriteInfo.com.Heur.29270.15038.exe |
Source: | Binary string: JPGCompress.pdb( source: SecuriteInfo.com.Heur.29270.15038.exe |
Source: | Binary string: JPGCompress.pdb source: SecuriteInfo.com.Heur.29270.15038.exe |
Source: | Binary string: JpgCSize.pdb8K source: SecuriteInfo.com.Heur.29270.15038.exe |
Source: global traffic | HTTP traffic detected: GET /mysoft/update/JPGCompress.xml HTTP/1.1Host: update.zzy-home.comConnection: Keep-Alive |
Source: unknown | UDP traffic detected without corresponding DNS query: 1.1.1.1 |
Source: global traffic | HTTP traffic detected: GET /mysoft/update/JPGCompress.xml HTTP/1.1Host: update.zzy-home.comConnection: Keep-Alive |
Source: global traffic | DNS traffic detected: DNS query: update.zzy-home.com |
Source: SecuriteInfo.com.Heur.29270.15038.exe, 00000000.00000002.2803860324.0000000003900000.00000004.00000800.00020000.00000000.sdmp | String found in binary or memory: http://Update.zzy-home.com/mysoft/Update/DownloadCount.aspx |
Source: SecuriteInfo.com.Heur.29270.15038.exe, 00000000.00000002.2803860324.0000000003900000.00000004.00000800.00020000.00000000.sdmp | String found in binary or memory: http://Update.zzy-home.com/mysoft/update/JPGCompress.xml |
Source: SecuriteInfo.com.Heur.29270.15038.exe, 00000000.00000002.2803860324.0000000003671000.00000004.00000800.00020000.00000000.sdmp | String found in binary or memory: http://Update.zzy-home.com/mysoft/update/JPGCompress.xmldhttp://Update.zzy.my/mysoft/update/JPGCompr |
Source: SecuriteInfo.com.Heur.29270.15038.exe, 00000000.00000002.2803860324.0000000003900000.00000004.00000800.00020000.00000000.sdmp | String found in binary or memory: http://Update.zzy.my/mysoft/update/JPGCompress.xml |
Source: SecuriteInfo.com.Heur.29270.15038.exe, 00000000.00000002.2803860324.0000000003671000.00000004.00000800.00020000.00000000.sdmp | String found in binary or memory: http://ie.vc |
Source: SecuriteInfo.com.Heur.29270.15038.exe, 00000000.00000002.2803860324.00000000039B2000.00000004.00000800.00020000.00000000.sdmp | String found in binary or memory: http://update.zzy-home.com |
Source: SecuriteInfo.com.Heur.29270.15038.exe, 00000000.00000002.2803860324.00000000039B2000.00000004.00000800.00020000.00000000.sdmp, SecuriteInfo.com.Heur.29270.15038.exe, 00000000.00000002.2803860324.0000000003934000.00000004.00000800.00020000.00000000.sdmp | String found in binary or memory: http://update.zzy-home.com/mysoft/update/JPGCompress.xml |
Source: SecuriteInfo.com.Heur.29270.15038.exe, 00000000.00000002.2803860324.0000000003934000.00000004.00000800.00020000.00000000.sdmp | String found in binary or memory: http://update.zzy-home.com/mysoft/update/JPGCompress.xmlp |
Source: SecuriteInfo.com.Heur.29270.15038.exe, 00000000.00000002.2803860324.00000000039B2000.00000004.00000800.00020000.00000000.sdmp | String found in binary or memory: http://update.zzy-home.com/mysoft/update/JPGCompress.xmlp~ |
Source: SecuriteInfo.com.Heur.29270.15038.exe, 00000000.00000002.2803860324.0000000003934000.00000004.00000800.00020000.00000000.sdmp | String found in binary or memory: http://update.zzy.my/mysoft/update/JPGCompress.xml |
Source: SecuriteInfo.com.Heur.29270.15038.exe, 00000000.00000002.2803860324.0000000003934000.00000004.00000800.00020000.00000000.sdmp | String found in binary or memory: http://update.zzy.my/mysoft/update/JPGCompress.xml0 |
Source: SecuriteInfo.com.Heur.29270.15038.exe, 00000000.00000002.2803860324.0000000003671000.00000004.00000800.00020000.00000000.sdmp | String found in binary or memory: http://www.zzy-home.com/Pay/toPayPage.htm |
Source: SecuriteInfo.com.Heur.29270.15038.exe, 00000000.00000002.2803860324.0000000003671000.00000004.00000800.00020000.00000000.sdmp | String found in binary or memory: http://www.zzy-home.com/res/zzymail.aspx |
Source: SecuriteInfo.com.Heur.29270.15038.exe, 00000000.00000002.2803860324.00000000039B2000.00000004.00000800.00020000.00000000.sdmp | String found in binary or memory: http://zzy-home.com/mysoft/update/JPG-C_v4.0.exe |
Source: SecuriteInfo.com.Heur.29270.15038.exe, type: SAMPLE | Matched rule: Detects executables packed with unregistered version of .NET Reactor Author: ditekSHen |
Source: 0.0.SecuriteInfo.com.Heur.29270.15038.exe.1037974.1.unpack, type: UNPACKEDPE | Matched rule: Detects executables packed with unregistered version of .NET Reactor Author: ditekSHen |
Source: 0.0.SecuriteInfo.com.Heur.29270.15038.exe.1037974.1.raw.unpack, type: UNPACKEDPE | Matched rule: Detects executables packed with unregistered version of .NET Reactor Author: ditekSHen |
Source: 0.0.SecuriteInfo.com.Heur.29270.15038.exe.fc0000.0.unpack, type: UNPACKEDPE | Matched rule: Detects executables packed with unregistered version of .NET Reactor Author: ditekSHen |
Source: SecuriteInfo.com.Heur.29270.15038.exe, 00000000.00000000.1549810966.000000000106A000.00000002.00000001.01000000.00000003.sdmp | Binary or memory string: OriginalFilenameJPGCompress.exe8 vs SecuriteInfo.com.Heur.29270.15038.exe |
Source: SecuriteInfo.com.Heur.29270.15038.exe, 00000000.00000000.1549736697.0000000000FC2000.00000002.00000001.01000000.00000003.sdmp | Binary or memory string: OriginalFilenameJpgCSize.exe2 vs SecuriteInfo.com.Heur.29270.15038.exe |
Source: SecuriteInfo.com.Heur.29270.15038.exe | Binary or memory string: OriginalFilenameJpgCSize.exe2 vs SecuriteInfo.com.Heur.29270.15038.exe |
Source: SecuriteInfo.com.Heur.29270.15038.exe | Binary or memory string: OriginalFilenameJPGCompress.exe8 vs SecuriteInfo.com.Heur.29270.15038.exe |
Source: SecuriteInfo.com.Heur.29270.15038.exe | Static PE information: EXECUTABLE_IMAGE, LINE_NUMS_STRIPPED, LOCAL_SYMS_STRIPPED, LARGE_ADDRESS_AWARE, 32BIT_MACHINE |
Source: SecuriteInfo.com.Heur.29270.15038.exe, type: SAMPLE | Matched rule: INDICATOR_EXE_Packed_DotNetReactor author = ditekSHen, description = Detects executables packed with unregistered version of .NET Reactor |
Source: 0.0.SecuriteInfo.com.Heur.29270.15038.exe.1037974.1.unpack, type: UNPACKEDPE | Matched rule: INDICATOR_EXE_Packed_DotNetReactor author = ditekSHen, description = Detects executables packed with unregistered version of .NET Reactor |
Source: 0.0.SecuriteInfo.com.Heur.29270.15038.exe.1037974.1.raw.unpack, type: UNPACKEDPE | Matched rule: INDICATOR_EXE_Packed_DotNetReactor author = ditekSHen, description = Detects executables packed with unregistered version of .NET Reactor |
Source: 0.0.SecuriteInfo.com.Heur.29270.15038.exe.fc0000.0.unpack, type: UNPACKEDPE | Matched rule: INDICATOR_EXE_Packed_DotNetReactor author = ditekSHen, description = Detects executables packed with unregistered version of .NET Reactor |
Source: SecuriteInfo.com.Heur.29270.15038.exe, HoreyBIUrqcqrPda6d.cs | Cryptographic APIs: 'CreateDecryptor' |
Source: SecuriteInfo.com.Heur.29270.15038.exe, HoreyBIUrqcqrPda6d.cs | Cryptographic APIs: 'CreateDecryptor' |
Source: SecuriteInfo.com.Heur.29270.15038.exe, HoreyBIUrqcqrPda6d.cs | Cryptographic APIs: 'CreateDecryptor' |
Source: 0.0.SecuriteInfo.com.Heur.29270.15038.exe.1037974.1.raw.unpack, HoreyBIUrqcqrPda6d.cs | Cryptographic APIs: 'CreateDecryptor' |
Source: 0.0.SecuriteInfo.com.Heur.29270.15038.exe.1037974.1.raw.unpack, HoreyBIUrqcqrPda6d.cs | Cryptographic APIs: 'CreateDecryptor' |
Source: classification engine | Classification label: mal64.troj.evad.winEXE@1/0@1/1 |
Source: C:\Users\user\Desktop\SecuriteInfo.com.Heur.29270.15038.exe | Mutant created: \Sessions\1\BaseNamedObjects\JPGCompress |
Source: C:\Users\user\Desktop\SecuriteInfo.com.Heur.29270.15038.exe | Mutant created: NULL |
Source: C:\Users\user\Desktop\SecuriteInfo.com.Heur.29270.15038.exe | Mutant created: \Sessions\1\BaseNamedObjects\Global\.net clr networking |
Source: SecuriteInfo.com.Heur.29270.15038.exe | Static PE information: Section: .text IMAGE_SCN_CNT_CODE, IMAGE_SCN_MEM_EXECUTE, IMAGE_SCN_MEM_READ |
Source: SecuriteInfo.com.Heur.29270.15038.exe | Static file information: TRID: Win32 Executable (generic) Net Framework (10011505/4) 49.80% |
Source: C:\Users\user\Desktop\SecuriteInfo.com.Heur.29270.15038.exe | Key opened: HKEY_LOCAL_MACHINE\Software\Policies\Microsoft\Windows\Safer\CodeIdentifiers | Jump to behavior |
Source: SecuriteInfo.com.Heur.29270.15038.exe | String found in binary or memory: @Tip: Directly Pictures / Directory drag to the list Or right-add |
Source: C:\Users\user\Desktop\SecuriteInfo.com.Heur.29270.15038.exe | Section loaded: mscoree.dll | Jump to behavior |
Source: C:\Users\user\Desktop\SecuriteInfo.com.Heur.29270.15038.exe | Section loaded: apphelp.dll | Jump to behavior |
Source: C:\Users\user\Desktop\SecuriteInfo.com.Heur.29270.15038.exe | Section loaded: kernel.appcore.dll | Jump to behavior |
Source: C:\Users\user\Desktop\SecuriteInfo.com.Heur.29270.15038.exe | Section loaded: version.dll | Jump to behavior |
Source: C:\Users\user\Desktop\SecuriteInfo.com.Heur.29270.15038.exe | Section loaded: windows.storage.dll | Jump to behavior |
Source: C:\Users\user\Desktop\SecuriteInfo.com.Heur.29270.15038.exe | Section loaded: wldp.dll | Jump to behavior |
Source: C:\Users\user\Desktop\SecuriteInfo.com.Heur.29270.15038.exe | Section loaded: profapi.dll | Jump to behavior |
Source: C:\Users\user\Desktop\SecuriteInfo.com.Heur.29270.15038.exe | Section loaded: uxtheme.dll | Jump to behavior |
Source: C:\Users\user\Desktop\SecuriteInfo.com.Heur.29270.15038.exe | Section loaded: dwrite.dll | Jump to behavior |
Source: C:\Users\user\Desktop\SecuriteInfo.com.Heur.29270.15038.exe | Section loaded: windowscodecs.dll | Jump to behavior |
Source: C:\Users\user\Desktop\SecuriteInfo.com.Heur.29270.15038.exe | Section loaded: textshaping.dll | Jump to behavior |
Source: C:\Users\user\Desktop\SecuriteInfo.com.Heur.29270.15038.exe | Section loaded: dataexchange.dll | Jump to behavior |
Source: C:\Users\user\Desktop\SecuriteInfo.com.Heur.29270.15038.exe | Section loaded: d3d11.dll | Jump to behavior |
Source: C:\Users\user\Desktop\SecuriteInfo.com.Heur.29270.15038.exe | Section loaded: dcomp.dll | Jump to behavior |
Source: C:\Users\user\Desktop\SecuriteInfo.com.Heur.29270.15038.exe | Section loaded: dxgi.dll | Jump to behavior |
Source: C:\Users\user\Desktop\SecuriteInfo.com.Heur.29270.15038.exe | Section loaded: twinapi.appcore.dll | Jump to behavior |
Source: C:\Users\user\Desktop\SecuriteInfo.com.Heur.29270.15038.exe | Section loaded: textinputframework.dll | Jump to behavior |
Source: C:\Users\user\Desktop\SecuriteInfo.com.Heur.29270.15038.exe | Section loaded: coreuicomponents.dll | Jump to behavior |
Source: C:\Users\user\Desktop\SecuriteInfo.com.Heur.29270.15038.exe | Section loaded: coremessaging.dll | Jump to behavior |
Source: C:\Users\user\Desktop\SecuriteInfo.com.Heur.29270.15038.exe | Section loaded: ntmarta.dll | Jump to behavior |
Source: C:\Users\user\Desktop\SecuriteInfo.com.Heur.29270.15038.exe | Section loaded: coremessaging.dll | Jump to behavior |
Source: C:\Users\user\Desktop\SecuriteInfo.com.Heur.29270.15038.exe | Section loaded: wintypes.dll | Jump to behavior |
Source: C:\Users\user\Desktop\SecuriteInfo.com.Heur.29270.15038.exe | Section loaded: wintypes.dll | Jump to behavior |
Source: C:\Users\user\Desktop\SecuriteInfo.com.Heur.29270.15038.exe | Section loaded: wintypes.dll | Jump to behavior |
Source: C:\Users\user\Desktop\SecuriteInfo.com.Heur.29270.15038.exe | Section loaded: cryptsp.dll | Jump to behavior |
Source: C:\Users\user\Desktop\SecuriteInfo.com.Heur.29270.15038.exe | Section loaded: rsaenh.dll | Jump to behavior |
Source: C:\Users\user\Desktop\SecuriteInfo.com.Heur.29270.15038.exe | Section loaded: cryptbase.dll | Jump to behavior |
Source: C:\Users\user\Desktop\SecuriteInfo.com.Heur.29270.15038.exe | Section loaded: rasapi32.dll | Jump to behavior |
Source: C:\Users\user\Desktop\SecuriteInfo.com.Heur.29270.15038.exe | Section loaded: rasman.dll | Jump to behavior |
Source: C:\Users\user\Desktop\SecuriteInfo.com.Heur.29270.15038.exe | Section loaded: rtutils.dll | Jump to behavior |
Source: C:\Users\user\Desktop\SecuriteInfo.com.Heur.29270.15038.exe | Section loaded: mswsock.dll | Jump to behavior |
Source: C:\Users\user\Desktop\SecuriteInfo.com.Heur.29270.15038.exe | Section loaded: winhttp.dll | Jump to behavior |
Source: C:\Users\user\Desktop\SecuriteInfo.com.Heur.29270.15038.exe | Section loaded: ondemandconnroutehelper.dll | Jump to behavior |
Source: C:\Users\user\Desktop\SecuriteInfo.com.Heur.29270.15038.exe | Section loaded: iphlpapi.dll | Jump to behavior |
Source: C:\Users\user\Desktop\SecuriteInfo.com.Heur.29270.15038.exe | Section loaded: dhcpcsvc6.dll | Jump to behavior |
Source: C:\Users\user\Desktop\SecuriteInfo.com.Heur.29270.15038.exe | Section loaded: dhcpcsvc.dll | Jump to behavior |
Source: C:\Users\user\Desktop\SecuriteInfo.com.Heur.29270.15038.exe | Section loaded: dnsapi.dll | Jump to behavior |
Source: C:\Users\user\Desktop\SecuriteInfo.com.Heur.29270.15038.exe | Section loaded: winnsi.dll | Jump to behavior |
Source: C:\Users\user\Desktop\SecuriteInfo.com.Heur.29270.15038.exe | Section loaded: rasadhlp.dll | Jump to behavior |
Source: C:\Users\user\Desktop\SecuriteInfo.com.Heur.29270.15038.exe | Section loaded: fwpuclnt.dll | Jump to behavior |
Source: Window Recorder | Window detected: More than 3 window changes detected |
Source: C:\Users\user\Desktop\SecuriteInfo.com.Heur.29270.15038.exe | File opened: C:\Windows\Microsoft.NET\Framework64\v2.0.50727\mscorrc.dll | Jump to behavior |
Source: SecuriteInfo.com.Heur.29270.15038.exe | Static PE information: data directory type: IMAGE_DIRECTORY_ENTRY_COM_DESCRIPTOR |
Source: C:\Users\user\Desktop\SecuriteInfo.com.Heur.29270.15038.exe | File opened: C:\Windows\WinSxS\amd64_microsoft.vc80.crt_1fc8b3b9a1e18e3b_8.0.50727.9672_none_88e266cb2fac7c0d\MSVCR80.dll | Jump to behavior |
Source: SecuriteInfo.com.Heur.29270.15038.exe | Static PE information: DYNAMIC_BASE, NX_COMPAT, NO_SEH, TERMINAL_SERVER_AWARE |
Source: SecuriteInfo.com.Heur.29270.15038.exe | Static PE information: data directory type: IMAGE_DIRECTORY_ENTRY_DEBUG |
Source: | Binary string: JpgCSize.pdb source: SecuriteInfo.com.Heur.29270.15038.exe |
Source: | Binary string: JPGCompress.pdb( source: SecuriteInfo.com.Heur.29270.15038.exe |
Source: | Binary string: JPGCompress.pdb source: SecuriteInfo.com.Heur.29270.15038.exe |
Source: | Binary string: JpgCSize.pdb8K source: SecuriteInfo.com.Heur.29270.15038.exe |
Source: SecuriteInfo.com.Heur.29270.15038.exe, HoreyBIUrqcqrPda6d.cs | .Net Code: typeof(Marshal).GetMethod("GetDelegateForFunctionPointer", new Type[2]{typeof(IntPtr),typeof(Type)}) |
Source: 0.0.SecuriteInfo.com.Heur.29270.15038.exe.1037974.1.raw.unpack, HoreyBIUrqcqrPda6d.cs | .Net Code: typeof(Marshal).GetMethod("GetDelegateForFunctionPointer", new Type[2]{typeof(IntPtr),typeof(Type)}) |
Source: C:\Users\user\Desktop\SecuriteInfo.com.Heur.29270.15038.exe | Code function: 0_2_00007FFE7DC81EBE push ds; retf 0000h | 0_2_00007FFE7DC81EBF |
Source: SecuriteInfo.com.Heur.29270.15038.exe | Static PE information: section name: .text entropy: 7.214054156981452 |
Source: SecuriteInfo.com.Heur.29270.15038.exe, HoreyBIUrqcqrPda6d.cs | High entropy of concatenated method names: 'rAXJXDxokn', 'vxVJBLZHfN', 'RAxJpc4Ehs', 'GouJ5LEJt4', 'bNfJYJpGjl', 'q9EJMfYkTl', 'AdgQCPTpZrx1x', 'YlA8QLjYrr', 'l7v8o5uGxZ', 'dn989xeBTl' |
Source: 0.0.SecuriteInfo.com.Heur.29270.15038.exe.1037974.1.raw.unpack, HoreyBIUrqcqrPda6d.cs | High entropy of concatenated method names: 'rAXJXDxokn', 'vxVJBLZHfN', 'RAxJpc4Ehs', 'GouJ5LEJt4', 'bNfJYJpGjl', 'q9EJMfYkTl', 'Txh1H0fee9o3T', 'YlA8QLjYrr', 'l7v8o5uGxZ', 'dn989xeBTl' |
Source: C:\Users\user\Desktop\SecuriteInfo.com.Heur.29270.15038.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\SecuriteInfo.com.Heur.29270.15038.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\SecuriteInfo.com.Heur.29270.15038.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\SecuriteInfo.com.Heur.29270.15038.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\SecuriteInfo.com.Heur.29270.15038.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\SecuriteInfo.com.Heur.29270.15038.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\SecuriteInfo.com.Heur.29270.15038.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\SecuriteInfo.com.Heur.29270.15038.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\SecuriteInfo.com.Heur.29270.15038.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\SecuriteInfo.com.Heur.29270.15038.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\SecuriteInfo.com.Heur.29270.15038.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\SecuriteInfo.com.Heur.29270.15038.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\SecuriteInfo.com.Heur.29270.15038.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\SecuriteInfo.com.Heur.29270.15038.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\SecuriteInfo.com.Heur.29270.15038.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\SecuriteInfo.com.Heur.29270.15038.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\SecuriteInfo.com.Heur.29270.15038.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\SecuriteInfo.com.Heur.29270.15038.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\SecuriteInfo.com.Heur.29270.15038.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\SecuriteInfo.com.Heur.29270.15038.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\SecuriteInfo.com.Heur.29270.15038.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\SecuriteInfo.com.Heur.29270.15038.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\SecuriteInfo.com.Heur.29270.15038.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\SecuriteInfo.com.Heur.29270.15038.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\SecuriteInfo.com.Heur.29270.15038.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\SecuriteInfo.com.Heur.29270.15038.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\SecuriteInfo.com.Heur.29270.15038.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\SecuriteInfo.com.Heur.29270.15038.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\SecuriteInfo.com.Heur.29270.15038.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\SecuriteInfo.com.Heur.29270.15038.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\SecuriteInfo.com.Heur.29270.15038.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\SecuriteInfo.com.Heur.29270.15038.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\SecuriteInfo.com.Heur.29270.15038.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\SecuriteInfo.com.Heur.29270.15038.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\SecuriteInfo.com.Heur.29270.15038.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\SecuriteInfo.com.Heur.29270.15038.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\SecuriteInfo.com.Heur.29270.15038.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\SecuriteInfo.com.Heur.29270.15038.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\SecuriteInfo.com.Heur.29270.15038.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\SecuriteInfo.com.Heur.29270.15038.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\SecuriteInfo.com.Heur.29270.15038.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\SecuriteInfo.com.Heur.29270.15038.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\SecuriteInfo.com.Heur.29270.15038.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\SecuriteInfo.com.Heur.29270.15038.exe | Memory allocated: 15C0000 memory reserve | memory write watch | Jump to behavior |
Source: C:\Users\user\Desktop\SecuriteInfo.com.Heur.29270.15038.exe | Memory allocated: 3670000 memory reserve | memory write watch | Jump to behavior |
Source: C:\Users\user\Desktop\SecuriteInfo.com.Heur.29270.15038.exe | Memory allocated: 1B670000 memory commit | memory reserve | memory write watch | Jump to behavior |
Source: C:\Users\user\Desktop\SecuriteInfo.com.Heur.29270.15038.exe | Window / User API: foregroundWindowGot 356 | Jump to behavior |
Source: SecuriteInfo.com.Heur.29270.15038.exe, 00000000.00000002.2803348281.0000000001666000.00000004.00000020.00020000.00000000.sdmp | Binary or memory string: Hyper-V RAW%SystemRoot%\system32\mswsock.dll |
Source: C:\Users\user\Desktop\SecuriteInfo.com.Heur.29270.15038.exe | Process token adjusted: Debug | Jump to behavior |
Source: C:\Users\user\Desktop\SecuriteInfo.com.Heur.29270.15038.exe | Memory allocated: page read and write | page guard | Jump to behavior |
Source: C:\Users\user\Desktop\SecuriteInfo.com.Heur.29270.15038.exe | Queries volume information: C:\Windows\Fonts\micross.ttf VolumeInformation | Jump to behavior |
Source: C:\Users\user\Desktop\SecuriteInfo.com.Heur.29270.15038.exe | Key value queried: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Cryptography MachineGuid | Jump to behavior |
Source: Yara match | File source: SecuriteInfo.com.Heur.29270.15038.exe, type: SAMPLE |
Source: Yara match | File source: 0.0.SecuriteInfo.com.Heur.29270.15038.exe.1037974.1.unpack, type: UNPACKEDPE |
Source: Yara match | File source: 0.0.SecuriteInfo.com.Heur.29270.15038.exe.1037974.1.raw.unpack, type: UNPACKEDPE |
Source: Yara match | File source: 0.0.SecuriteInfo.com.Heur.29270.15038.exe.fc0000.0.unpack, type: UNPACKEDPE |
Source: Yara match | File source: 00000000.00000000.1549736697.0000000000FC2000.00000002.00000001.01000000.00000003.sdmp, type: MEMORY |
Source: Yara match | File source: SecuriteInfo.com.Heur.29270.15038.exe, type: SAMPLE |
Source: Yara match | File source: 0.0.SecuriteInfo.com.Heur.29270.15038.exe.1037974.1.unpack, type: UNPACKEDPE |
Source: Yara match | File source: 0.0.SecuriteInfo.com.Heur.29270.15038.exe.1037974.1.raw.unpack, type: UNPACKEDPE |
Source: Yara match | File source: 0.0.SecuriteInfo.com.Heur.29270.15038.exe.fc0000.0.unpack, type: UNPACKEDPE |
Source: Yara match | File source: 00000000.00000000.1549736697.0000000000FC2000.00000002.00000001.01000000.00000003.sdmp, type: MEMORY |