Sample name: | skZwfU6wMR.exerenamed because original name is a hash value |
Original sample name: | 9caaa34fa5fab572695f49cc496820dc5e4df6d8866b3f89a49e2dab1a6f85d2.exe |
Analysis ID: | 1543064 |
MD5: | 339e94bff01e66552e855e9ade023163 |
SHA1: | 55ff23f6f35ce96592d41723a933bc928f3afe50 |
SHA256: | 9caaa34fa5fab572695f49cc496820dc5e4df6d8866b3f89a49e2dab1a6f85d2 |
Tags: | exegurt-duna-uauser-JAMESWT_MHT |
Infos: | |
Score: | 56 |
Range: | 0 - 100 |
Whitelisted: | false |
Confidence: | 100% |
AV Detection |
---|
Source: |
Avira: |
Source: |
Virustotal: |
Perma Link | ||
Source: |
ReversingLabs: |
Source: |
Static PE information: |
Source: |
Static PE information: |
Source: |
Binary string: |
||
Source: |
Binary string: |
Source: |
Code function: |
0_2_0033EDC2 |
Source: |
Code function: |
0_2_00336166 | |
Source: |
Code function: |
0_2_00335245 |
Source: |
Binary or memory string: |
||
Source: |
Binary or memory string: |
||
Source: |
Binary or memory string: |
||
Source: |
Binary or memory string: |
Source: |
Static PE information: |
Source: |
Classification label: |
Source: |
Code function: |
0_2_0034002C |
Source: |
Code function: |
0_2_00340138 |
Source: |
Code function: |
0_2_0033F117 |
Source: |
Mutant created: |
Source: |
Command line argument: |
0_2_00333BBD |
Source: |
Static PE information: |
Source: |
Key opened: |
Jump to behavior |
Source: |
Virustotal: |
||
Source: |
ReversingLabs: |
Source: |
Section loaded: |
Jump to behavior | ||
Source: |
Section loaded: |
Jump to behavior | ||
Source: |
Section loaded: |
Jump to behavior | ||
Source: |
Section loaded: |
Jump to behavior | ||
Source: |
Section loaded: |
Jump to behavior | ||
Source: |
Section loaded: |
Jump to behavior | ||
Source: |
Section loaded: |
Jump to behavior | ||
Source: |
Section loaded: |
Jump to behavior | ||
Source: |
Section loaded: |
Jump to behavior | ||
Source: |
Section loaded: |
Jump to behavior |
Source: |
Static PE information: |
||
Source: |
Static PE information: |
||
Source: |
Static PE information: |
||
Source: |
Static PE information: |
||
Source: |
Static PE information: |
||
Source: |
Static PE information: |
Source: |
Static PE information: |
Source: |
Static PE information: |
Source: |
Binary string: |
||
Source: |
Binary string: |
Source: |
Static PE information: |
Source: |
Code function: |
0_2_00331D0D | |
Source: |
Code function: |
0_2_00340DE4 |
Source: |
API coverage: |
Source: |
Thread injection, dropped files, key value created, disk infection and DNS query: |
Source: |
Code function: |
0_2_0033F7EE |
Source: |
Code function: |
0_2_0033F8CD |
Source: |
Thread injection, dropped files, key value created, disk infection and DNS query: |
Source: |
Code function: |
0_2_00340A80 | |
Source: |
Code function: |
0_2_003407FD |
Source: |
Code function: |
0_2_00340CC9 |