Click to jump to signature section
Source: uLFOeGZaJS.exe, 00000000.00000002.4531022648.000000000310D000.00000004.00000800.00020000.00000000.sdmp, uLFOeGZaJS.exe, 00000000.00000002.4531022648.0000000003286000.00000004.00000800.00020000.00000000.sdmp | String found in binary or memory: http://ercolina-usa.com |
Source: uLFOeGZaJS.exe, 00000000.00000002.4531022648.000000000310D000.00000004.00000800.00020000.00000000.sdmp, uLFOeGZaJS.exe, 00000000.00000002.4531022648.0000000003286000.00000004.00000800.00020000.00000000.sdmp | String found in binary or memory: http://ftp.ercolina-usa.com |
Source: uLFOeGZaJS.exe, 00000000.00000002.4531022648.00000000030D1000.00000004.00000800.00020000.00000000.sdmp | String found in binary or memory: http://ip-api.com |
Source: uLFOeGZaJS.exe | String found in binary or memory: http://ip-api.com/line/?fields=hosting |
Source: uLFOeGZaJS.exe, 00000000.00000002.4531022648.0000000003081000.00000004.00000800.00020000.00000000.sdmp | String found in binary or memory: http://schemas.xmlsoap.org/ws/2005/05/identity/claims/name |
Source: uLFOeGZaJS.exe | String found in binary or memory: https://account.dyn.com/ |
Source: uLFOeGZaJS.exe | String found in binary or memory: https://api.ipify.org |
Source: uLFOeGZaJS.exe, 00000000.00000002.4531022648.0000000003081000.00000004.00000800.00020000.00000000.sdmp | String found in binary or memory: https://api.ipify.org/ |
Source: uLFOeGZaJS.exe, 00000000.00000002.4531022648.0000000003081000.00000004.00000800.00020000.00000000.sdmp | String found in binary or memory: https://api.ipify.org/t |
Source: uLFOeGZaJS.exe, type: SAMPLE | Matched rule: Detects executables referencing Windows vault credential objects. Observed in infostealers Author: ditekSHen |
Source: uLFOeGZaJS.exe, type: SAMPLE | Matched rule: AgenetTesla Type 2 Keylogger payload Author: ditekSHen |
Source: 0.0.uLFOeGZaJS.exe.c90000.0.unpack, type: UNPACKEDPE | Matched rule: Detects executables referencing Windows vault credential objects. Observed in infostealers Author: ditekSHen |
Source: 0.0.uLFOeGZaJS.exe.c90000.0.unpack, type: UNPACKEDPE | Matched rule: AgenetTesla Type 2 Keylogger payload Author: ditekSHen |
Source: C:\Users\user\Desktop\uLFOeGZaJS.exe | Code function: 0_2_013541B0 | 0_2_013541B0 |
Source: C:\Users\user\Desktop\uLFOeGZaJS.exe | Code function: 0_2_0135B3D0 | 0_2_0135B3D0 |
Source: C:\Users\user\Desktop\uLFOeGZaJS.exe | Code function: 0_2_01354A80 | 0_2_01354A80 |
Source: C:\Users\user\Desktop\uLFOeGZaJS.exe | Code function: 0_2_0135AC08 | 0_2_0135AC08 |
Source: C:\Users\user\Desktop\uLFOeGZaJS.exe | Code function: 0_2_0135EE18 | 0_2_0135EE18 |
Source: C:\Users\user\Desktop\uLFOeGZaJS.exe | Code function: 0_2_01353E68 | 0_2_01353E68 |
Source: C:\Users\user\Desktop\uLFOeGZaJS.exe | Code function: 0_2_06DC6F10 | 0_2_06DC6F10 |
Source: C:\Users\user\Desktop\uLFOeGZaJS.exe | Code function: 0_2_06DC1C80 | 0_2_06DC1C80 |
Source: C:\Users\user\Desktop\uLFOeGZaJS.exe | Code function: 0_2_06DC5A2C | 0_2_06DC5A2C |
Source: C:\Users\user\Desktop\uLFOeGZaJS.exe | Code function: 0_2_06DC6248 | 0_2_06DC6248 |
Source: C:\Users\user\Desktop\uLFOeGZaJS.exe | Code function: 0_2_06DC623B | 0_2_06DC623B |
Source: C:\Users\user\Desktop\uLFOeGZaJS.exe | Code function: 0_2_06DC6F30 | 0_2_06DC6F30 |
Source: C:\Users\user\Desktop\uLFOeGZaJS.exe | Code function: 0_2_06DDAED0 | 0_2_06DDAED0 |
Source: C:\Users\user\Desktop\uLFOeGZaJS.exe | Code function: 0_2_06DD2430 | 0_2_06DD2430 |
Source: C:\Users\user\Desktop\uLFOeGZaJS.exe | Code function: 0_2_06DD6288 | 0_2_06DD6288 |
Source: C:\Users\user\Desktop\uLFOeGZaJS.exe | Code function: 0_2_06DD5270 | 0_2_06DD5270 |
Source: C:\Users\user\Desktop\uLFOeGZaJS.exe | Code function: 0_2_06DD7A10 | 0_2_06DD7A10 |
Source: C:\Users\user\Desktop\uLFOeGZaJS.exe | Code function: 0_2_06DDC230 | 0_2_06DDC230 |
Source: C:\Users\user\Desktop\uLFOeGZaJS.exe | Code function: 0_2_06DDE458 | 0_2_06DDE458 |
Source: C:\Users\user\Desktop\uLFOeGZaJS.exe | Code function: 0_2_06DD7330 | 0_2_06DD7330 |
Source: C:\Users\user\Desktop\uLFOeGZaJS.exe | Code function: 0_2_06DD0040 | 0_2_06DD0040 |
Source: C:\Users\user\Desktop\uLFOeGZaJS.exe | Code function: 0_2_06DD0007 | 0_2_06DD0007 |
Source: C:\Users\user\Desktop\uLFOeGZaJS.exe | Code function: 0_2_06DD5990 | 0_2_06DD5990 |
Source: uLFOeGZaJS.exe, 00000000.00000000.2077736795.0000000000CD0000.00000002.00000001.01000000.00000003.sdmp | Binary or memory string: OriginalFilename8d205da5-a06f-41c4-923e-b97a14abb967.exe4 vs uLFOeGZaJS.exe |
Source: uLFOeGZaJS.exe, 00000000.00000002.4530485791.000000000136E000.00000004.00000020.00020000.00000000.sdmp | Binary or memory string: OriginalFilenameclr.dllT vs uLFOeGZaJS.exe |
Source: uLFOeGZaJS.exe, 00000000.00000002.4530112044.00000000010F8000.00000004.00000010.00020000.00000000.sdmp | Binary or memory string: OriginalFilenameUNKNOWN_FILET vs uLFOeGZaJS.exe |
Source: uLFOeGZaJS.exe | Binary or memory string: OriginalFilename8d205da5-a06f-41c4-923e-b97a14abb967.exe4 vs uLFOeGZaJS.exe |
Source: uLFOeGZaJS.exe, type: SAMPLE | Matched rule: INDICATOR_SUSPICIOUS_EXE_VaultSchemaGUID author = ditekSHen, description = Detects executables referencing Windows vault credential objects. Observed in infostealers |
Source: uLFOeGZaJS.exe, type: SAMPLE | Matched rule: MALWARE_Win_AgentTeslaV2 author = ditekSHen, description = AgenetTesla Type 2 Keylogger payload |
Source: 0.0.uLFOeGZaJS.exe.c90000.0.unpack, type: UNPACKEDPE | Matched rule: INDICATOR_SUSPICIOUS_EXE_VaultSchemaGUID author = ditekSHen, description = Detects executables referencing Windows vault credential objects. Observed in infostealers |
Source: 0.0.uLFOeGZaJS.exe.c90000.0.unpack, type: UNPACKEDPE | Matched rule: MALWARE_Win_AgentTeslaV2 author = ditekSHen, description = AgenetTesla Type 2 Keylogger payload |
Source: uLFOeGZaJS.exe, hcbDrTLwTC.cs | Cryptographic APIs: 'TransformFinalBlock' |
Source: uLFOeGZaJS.exe, CMQvPoq8cy.cs | Cryptographic APIs: 'TransformFinalBlock' |
Source: uLFOeGZaJS.exe, e5d0T5Np.cs | Cryptographic APIs: 'TransformFinalBlock' |
Source: uLFOeGZaJS.exe, 71JxQ8.cs | Cryptographic APIs: 'CreateDecryptor', 'TransformBlock' |
Source: uLFOeGZaJS.exe, CnG3o.cs | Cryptographic APIs: 'TransformFinalBlock' |
Source: uLFOeGZaJS.exe, 2FAFIfKp.cs | Cryptographic APIs: 'CreateDecryptor' |
Source: uLFOeGZaJS.exe, gdOsx.cs | Cryptographic APIs: 'TransformFinalBlock' |
Source: uLFOeGZaJS.exe, gdOsx.cs | Cryptographic APIs: 'TransformFinalBlock', 'CreateDecryptor' |
Source: uLFOeGZaJS.exe, tG6Nh.cs | Cryptographic APIs: 'TransformFinalBlock' |
Source: uLFOeGZaJS.exe, tG6Nh.cs | Cryptographic APIs: 'TransformFinalBlock' |
Source: C:\Users\user\Desktop\uLFOeGZaJS.exe | Section loaded: mscoree.dll | Jump to behavior |
Source: C:\Users\user\Desktop\uLFOeGZaJS.exe | Section loaded: apphelp.dll | Jump to behavior |
Source: C:\Users\user\Desktop\uLFOeGZaJS.exe | Section loaded: kernel.appcore.dll | Jump to behavior |
Source: C:\Users\user\Desktop\uLFOeGZaJS.exe | Section loaded: version.dll | Jump to behavior |
Source: C:\Users\user\Desktop\uLFOeGZaJS.exe | Section loaded: vcruntime140_clr0400.dll | Jump to behavior |
Source: C:\Users\user\Desktop\uLFOeGZaJS.exe | Section loaded: ucrtbase_clr0400.dll | Jump to behavior |
Source: C:\Users\user\Desktop\uLFOeGZaJS.exe | Section loaded: uxtheme.dll | Jump to behavior |
Source: C:\Users\user\Desktop\uLFOeGZaJS.exe | Section loaded: windows.storage.dll | Jump to behavior |
Source: C:\Users\user\Desktop\uLFOeGZaJS.exe | Section loaded: wldp.dll | Jump to behavior |
Source: C:\Users\user\Desktop\uLFOeGZaJS.exe | Section loaded: profapi.dll | Jump to behavior |
Source: C:\Users\user\Desktop\uLFOeGZaJS.exe | Section loaded: cryptsp.dll | Jump to behavior |
Source: C:\Users\user\Desktop\uLFOeGZaJS.exe | Section loaded: rsaenh.dll | Jump to behavior |
Source: C:\Users\user\Desktop\uLFOeGZaJS.exe | Section loaded: cryptbase.dll | Jump to behavior |
Source: C:\Users\user\Desktop\uLFOeGZaJS.exe | Section loaded: wbemcomn.dll | Jump to behavior |
Source: C:\Users\user\Desktop\uLFOeGZaJS.exe | Section loaded: amsi.dll | Jump to behavior |
Source: C:\Users\user\Desktop\uLFOeGZaJS.exe | Section loaded: userenv.dll | Jump to behavior |
Source: C:\Users\user\Desktop\uLFOeGZaJS.exe | Section loaded: sspicli.dll | Jump to behavior |
Source: C:\Users\user\Desktop\uLFOeGZaJS.exe | Section loaded: rasapi32.dll | Jump to behavior |
Source: C:\Users\user\Desktop\uLFOeGZaJS.exe | Section loaded: rasman.dll | Jump to behavior |
Source: C:\Users\user\Desktop\uLFOeGZaJS.exe | Section loaded: rtutils.dll | Jump to behavior |
Source: C:\Users\user\Desktop\uLFOeGZaJS.exe | Section loaded: mswsock.dll | Jump to behavior |
Source: C:\Users\user\Desktop\uLFOeGZaJS.exe | Section loaded: winhttp.dll | Jump to behavior |
Source: C:\Users\user\Desktop\uLFOeGZaJS.exe | Section loaded: ondemandconnroutehelper.dll | Jump to behavior |
Source: C:\Users\user\Desktop\uLFOeGZaJS.exe | Section loaded: iphlpapi.dll | Jump to behavior |
Source: C:\Users\user\Desktop\uLFOeGZaJS.exe | Section loaded: dhcpcsvc6.dll | Jump to behavior |
Source: C:\Users\user\Desktop\uLFOeGZaJS.exe | Section loaded: dhcpcsvc.dll | Jump to behavior |
Source: C:\Users\user\Desktop\uLFOeGZaJS.exe | Section loaded: dnsapi.dll | Jump to behavior |
Source: C:\Users\user\Desktop\uLFOeGZaJS.exe | Section loaded: winnsi.dll | Jump to behavior |
Source: C:\Users\user\Desktop\uLFOeGZaJS.exe | Section loaded: rasadhlp.dll | Jump to behavior |
Source: C:\Users\user\Desktop\uLFOeGZaJS.exe | Section loaded: fwpuclnt.dll | Jump to behavior |
Source: C:\Users\user\Desktop\uLFOeGZaJS.exe | Section loaded: secur32.dll | Jump to behavior |
Source: C:\Users\user\Desktop\uLFOeGZaJS.exe | Section loaded: schannel.dll | Jump to behavior |
Source: C:\Users\user\Desktop\uLFOeGZaJS.exe | Section loaded: mskeyprotect.dll | Jump to behavior |
Source: C:\Users\user\Desktop\uLFOeGZaJS.exe | Section loaded: ntasn1.dll | Jump to behavior |
Source: C:\Users\user\Desktop\uLFOeGZaJS.exe | Section loaded: ncrypt.dll | Jump to behavior |
Source: C:\Users\user\Desktop\uLFOeGZaJS.exe | Section loaded: ncryptsslp.dll | Jump to behavior |
Source: C:\Users\user\Desktop\uLFOeGZaJS.exe | Section loaded: msasn1.dll | Jump to behavior |
Source: C:\Users\user\Desktop\uLFOeGZaJS.exe | Section loaded: gpapi.dll | Jump to behavior |
Source: C:\Users\user\Desktop\uLFOeGZaJS.exe | Section loaded: vaultcli.dll | Jump to behavior |
Source: C:\Users\user\Desktop\uLFOeGZaJS.exe | Section loaded: wintypes.dll | Jump to behavior |
Source: C:\Users\user\Desktop\uLFOeGZaJS.exe | Section loaded: dpapi.dll | Jump to behavior |
Source: C:\Users\user\Desktop\uLFOeGZaJS.exe | Section loaded: edputil.dll | Jump to behavior |
Source: C:\Users\user\Desktop\uLFOeGZaJS.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\uLFOeGZaJS.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\uLFOeGZaJS.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\uLFOeGZaJS.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\uLFOeGZaJS.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\uLFOeGZaJS.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\uLFOeGZaJS.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\uLFOeGZaJS.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\uLFOeGZaJS.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\uLFOeGZaJS.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\uLFOeGZaJS.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\uLFOeGZaJS.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\uLFOeGZaJS.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\uLFOeGZaJS.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\uLFOeGZaJS.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\uLFOeGZaJS.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\uLFOeGZaJS.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\uLFOeGZaJS.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\uLFOeGZaJS.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\uLFOeGZaJS.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\uLFOeGZaJS.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\uLFOeGZaJS.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\uLFOeGZaJS.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\uLFOeGZaJS.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\uLFOeGZaJS.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\uLFOeGZaJS.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\uLFOeGZaJS.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\uLFOeGZaJS.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\uLFOeGZaJS.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\uLFOeGZaJS.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\uLFOeGZaJS.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\uLFOeGZaJS.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\uLFOeGZaJS.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\uLFOeGZaJS.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\uLFOeGZaJS.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\uLFOeGZaJS.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\uLFOeGZaJS.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\uLFOeGZaJS.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\uLFOeGZaJS.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\uLFOeGZaJS.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\uLFOeGZaJS.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\uLFOeGZaJS.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\uLFOeGZaJS.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\uLFOeGZaJS.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\uLFOeGZaJS.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\uLFOeGZaJS.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\uLFOeGZaJS.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\uLFOeGZaJS.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\uLFOeGZaJS.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\uLFOeGZaJS.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\uLFOeGZaJS.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\uLFOeGZaJS.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\uLFOeGZaJS.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\uLFOeGZaJS.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\uLFOeGZaJS.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\uLFOeGZaJS.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\uLFOeGZaJS.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\uLFOeGZaJS.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\uLFOeGZaJS.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\uLFOeGZaJS.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\uLFOeGZaJS.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\uLFOeGZaJS.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\uLFOeGZaJS.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\uLFOeGZaJS.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\uLFOeGZaJS.exe | Thread delayed: delay time: 922337203685477 | Jump to behavior |
Source: C:\Users\user\Desktop\uLFOeGZaJS.exe | Thread delayed: delay time: 600000 | Jump to behavior |
Source: C:\Users\user\Desktop\uLFOeGZaJS.exe | Thread delayed: delay time: 599875 | Jump to behavior |
Source: C:\Users\user\Desktop\uLFOeGZaJS.exe | Thread delayed: delay time: 599711 | Jump to behavior |
Source: C:\Users\user\Desktop\uLFOeGZaJS.exe | Thread delayed: delay time: 599609 | Jump to behavior |
Source: C:\Users\user\Desktop\uLFOeGZaJS.exe | Thread delayed: delay time: 599500 | Jump to behavior |
Source: C:\Users\user\Desktop\uLFOeGZaJS.exe | Thread delayed: delay time: 599389 | Jump to behavior |
Source: C:\Users\user\Desktop\uLFOeGZaJS.exe | Thread delayed: delay time: 599282 | Jump to behavior |
Source: C:\Users\user\Desktop\uLFOeGZaJS.exe | Thread delayed: delay time: 599157 | Jump to behavior |
Source: C:\Users\user\Desktop\uLFOeGZaJS.exe | Thread delayed: delay time: 599032 | Jump to behavior |
Source: C:\Users\user\Desktop\uLFOeGZaJS.exe | Thread delayed: delay time: 598907 | Jump to behavior |
Source: C:\Users\user\Desktop\uLFOeGZaJS.exe | Thread delayed: delay time: 598782 | Jump to behavior |
Source: C:\Users\user\Desktop\uLFOeGZaJS.exe | Thread delayed: delay time: 598672 | Jump to behavior |
Source: C:\Users\user\Desktop\uLFOeGZaJS.exe | Thread delayed: delay time: 598563 | Jump to behavior |
Source: C:\Users\user\Desktop\uLFOeGZaJS.exe | Thread delayed: delay time: 598438 | Jump to behavior |
Source: C:\Users\user\Desktop\uLFOeGZaJS.exe | Thread delayed: delay time: 598313 | Jump to behavior |
Source: C:\Users\user\Desktop\uLFOeGZaJS.exe | Thread delayed: delay time: 598188 | Jump to behavior |
Source: C:\Users\user\Desktop\uLFOeGZaJS.exe | Thread delayed: delay time: 598063 | Jump to behavior |
Source: C:\Users\user\Desktop\uLFOeGZaJS.exe | Thread delayed: delay time: 597953 | Jump to behavior |
Source: C:\Users\user\Desktop\uLFOeGZaJS.exe | Thread delayed: delay time: 597844 | Jump to behavior |
Source: C:\Users\user\Desktop\uLFOeGZaJS.exe | Thread delayed: delay time: 597719 | Jump to behavior |
Source: C:\Users\user\Desktop\uLFOeGZaJS.exe | Thread delayed: delay time: 597610 | Jump to behavior |
Source: C:\Users\user\Desktop\uLFOeGZaJS.exe | Thread delayed: delay time: 597485 | Jump to behavior |
Source: C:\Users\user\Desktop\uLFOeGZaJS.exe | Thread delayed: delay time: 597359 | Jump to behavior |
Source: C:\Users\user\Desktop\uLFOeGZaJS.exe | Thread delayed: delay time: 597216 | Jump to behavior |
Source: C:\Users\user\Desktop\uLFOeGZaJS.exe | Thread delayed: delay time: 597107 | Jump to behavior |
Source: C:\Users\user\Desktop\uLFOeGZaJS.exe | Thread delayed: delay time: 596978 | Jump to behavior |
Source: C:\Users\user\Desktop\uLFOeGZaJS.exe | Thread delayed: delay time: 596875 | Jump to behavior |
Source: C:\Users\user\Desktop\uLFOeGZaJS.exe | Thread delayed: delay time: 596762 | Jump to behavior |
Source: C:\Users\user\Desktop\uLFOeGZaJS.exe | Thread delayed: delay time: 596656 | Jump to behavior |
Source: C:\Users\user\Desktop\uLFOeGZaJS.exe | Thread delayed: delay time: 596547 | Jump to behavior |
Source: C:\Users\user\Desktop\uLFOeGZaJS.exe | Thread delayed: delay time: 596438 | Jump to behavior |
Source: C:\Users\user\Desktop\uLFOeGZaJS.exe | Thread delayed: delay time: 300000 | Jump to behavior |
Source: C:\Users\user\Desktop\uLFOeGZaJS.exe | Thread delayed: delay time: 299891 | Jump to behavior |
Source: C:\Users\user\Desktop\uLFOeGZaJS.exe | Thread delayed: delay time: 299781 | Jump to behavior |
Source: C:\Users\user\Desktop\uLFOeGZaJS.exe | Thread delayed: delay time: 299672 | Jump to behavior |
Source: C:\Users\user\Desktop\uLFOeGZaJS.exe | Thread delayed: delay time: 299562 | Jump to behavior |
Source: C:\Users\user\Desktop\uLFOeGZaJS.exe | Thread delayed: delay time: 299453 | Jump to behavior |
Source: C:\Users\user\Desktop\uLFOeGZaJS.exe | Thread delayed: delay time: 299344 | Jump to behavior |
Source: C:\Users\user\Desktop\uLFOeGZaJS.exe | Thread delayed: delay time: 299219 | Jump to behavior |
Source: C:\Users\user\Desktop\uLFOeGZaJS.exe | Thread delayed: delay time: 299109 | Jump to behavior |
Source: C:\Users\user\Desktop\uLFOeGZaJS.exe | Thread delayed: delay time: 299000 | Jump to behavior |
Source: C:\Users\user\Desktop\uLFOeGZaJS.exe | Thread delayed: delay time: 298891 | Jump to behavior |
Source: C:\Users\user\Desktop\uLFOeGZaJS.exe | Thread delayed: delay time: 298781 | Jump to behavior |
Source: C:\Users\user\Desktop\uLFOeGZaJS.exe | Thread delayed: delay time: 298672 | Jump to behavior |
Source: C:\Users\user\Desktop\uLFOeGZaJS.exe | Thread delayed: delay time: 298563 | Jump to behavior |
Source: C:\Users\user\Desktop\uLFOeGZaJS.exe | Thread delayed: delay time: 298438 | Jump to behavior |
Source: C:\Users\user\Desktop\uLFOeGZaJS.exe | Thread delayed: delay time: 298313 | Jump to behavior |
Source: C:\Users\user\Desktop\uLFOeGZaJS.exe | Thread delayed: delay time: 298202 | Jump to behavior |
Source: C:\Users\user\Desktop\uLFOeGZaJS.exe | Thread delayed: delay time: 298082 | Jump to behavior |
Source: C:\Users\user\Desktop\uLFOeGZaJS.exe | Thread delayed: delay time: 297968 | Jump to behavior |
Source: C:\Users\user\Desktop\uLFOeGZaJS.exe | Thread delayed: delay time: 297858 | Jump to behavior |
Source: C:\Users\user\Desktop\uLFOeGZaJS.exe TID: 6088 | Thread sleep count: 37 > 30 | Jump to behavior |
Source: C:\Users\user\Desktop\uLFOeGZaJS.exe TID: 6088 | Thread sleep time: -34126476536362649s >= -30000s | Jump to behavior |
Source: C:\Users\user\Desktop\uLFOeGZaJS.exe TID: 6088 | Thread sleep time: -600000s >= -30000s | Jump to behavior |
Source: C:\Users\user\Desktop\uLFOeGZaJS.exe TID: 6276 | Thread sleep count: 2062 > 30 | Jump to behavior |
Source: C:\Users\user\Desktop\uLFOeGZaJS.exe TID: 6088 | Thread sleep time: -599875s >= -30000s | Jump to behavior |
Source: C:\Users\user\Desktop\uLFOeGZaJS.exe TID: 6276 | Thread sleep count: 7775 > 30 | Jump to behavior |
Source: C:\Users\user\Desktop\uLFOeGZaJS.exe TID: 6088 | Thread sleep time: -599711s >= -30000s | Jump to behavior |
Source: C:\Users\user\Desktop\uLFOeGZaJS.exe TID: 6088 | Thread sleep time: -599609s >= -30000s | Jump to behavior |
Source: C:\Users\user\Desktop\uLFOeGZaJS.exe TID: 6088 | Thread sleep time: -599500s >= -30000s | Jump to behavior |
Source: C:\Users\user\Desktop\uLFOeGZaJS.exe TID: 6088 | Thread sleep time: -599389s >= -30000s | Jump to behavior |
Source: C:\Users\user\Desktop\uLFOeGZaJS.exe TID: 6088 | Thread sleep time: -599282s >= -30000s | Jump to behavior |
Source: C:\Users\user\Desktop\uLFOeGZaJS.exe TID: 6088 | Thread sleep time: -599157s >= -30000s | Jump to behavior |
Source: C:\Users\user\Desktop\uLFOeGZaJS.exe TID: 6088 | Thread sleep time: -599032s >= -30000s | Jump to behavior |
Source: C:\Users\user\Desktop\uLFOeGZaJS.exe TID: 6088 | Thread sleep time: -598907s >= -30000s | Jump to behavior |
Source: C:\Users\user\Desktop\uLFOeGZaJS.exe TID: 6088 | Thread sleep time: -598782s >= -30000s | Jump to behavior |
Source: C:\Users\user\Desktop\uLFOeGZaJS.exe TID: 6088 | Thread sleep time: -598672s >= -30000s | Jump to behavior |
Source: C:\Users\user\Desktop\uLFOeGZaJS.exe TID: 6088 | Thread sleep time: -598563s >= -30000s | Jump to behavior |
Source: C:\Users\user\Desktop\uLFOeGZaJS.exe TID: 6088 | Thread sleep time: -598438s >= -30000s | Jump to behavior |
Source: C:\Users\user\Desktop\uLFOeGZaJS.exe TID: 6088 | Thread sleep time: -598313s >= -30000s | Jump to behavior |
Source: C:\Users\user\Desktop\uLFOeGZaJS.exe TID: 6088 | Thread sleep time: -598188s >= -30000s | Jump to behavior |
Source: C:\Users\user\Desktop\uLFOeGZaJS.exe TID: 6088 | Thread sleep time: -598063s >= -30000s | Jump to behavior |
Source: C:\Users\user\Desktop\uLFOeGZaJS.exe TID: 6088 | Thread sleep time: -597953s >= -30000s | Jump to behavior |
Source: C:\Users\user\Desktop\uLFOeGZaJS.exe TID: 6088 | Thread sleep time: -597844s >= -30000s | Jump to behavior |
Source: C:\Users\user\Desktop\uLFOeGZaJS.exe TID: 6088 | Thread sleep time: -597719s >= -30000s | Jump to behavior |
Source: C:\Users\user\Desktop\uLFOeGZaJS.exe TID: 6088 | Thread sleep time: -597610s >= -30000s | Jump to behavior |
Source: C:\Users\user\Desktop\uLFOeGZaJS.exe TID: 6088 | Thread sleep time: -597485s >= -30000s | Jump to behavior |
Source: C:\Users\user\Desktop\uLFOeGZaJS.exe TID: 6088 | Thread sleep time: -597359s >= -30000s | Jump to behavior |
Source: C:\Users\user\Desktop\uLFOeGZaJS.exe TID: 6088 | Thread sleep time: -597216s >= -30000s | Jump to behavior |
Source: C:\Users\user\Desktop\uLFOeGZaJS.exe TID: 6088 | Thread sleep time: -597107s >= -30000s | Jump to behavior |
Source: C:\Users\user\Desktop\uLFOeGZaJS.exe TID: 6088 | Thread sleep time: -596978s >= -30000s | Jump to behavior |
Source: C:\Users\user\Desktop\uLFOeGZaJS.exe TID: 6088 | Thread sleep time: -596875s >= -30000s | Jump to behavior |
Source: C:\Users\user\Desktop\uLFOeGZaJS.exe TID: 6088 | Thread sleep time: -596762s >= -30000s | Jump to behavior |
Source: C:\Users\user\Desktop\uLFOeGZaJS.exe TID: 6088 | Thread sleep time: -596656s >= -30000s | Jump to behavior |
Source: C:\Users\user\Desktop\uLFOeGZaJS.exe TID: 6088 | Thread sleep time: -596547s >= -30000s | Jump to behavior |
Source: C:\Users\user\Desktop\uLFOeGZaJS.exe TID: 6088 | Thread sleep time: -596438s >= -30000s | Jump to behavior |
Source: C:\Users\user\Desktop\uLFOeGZaJS.exe TID: 6088 | Thread sleep time: -300000s >= -30000s | Jump to behavior |
Source: C:\Users\user\Desktop\uLFOeGZaJS.exe TID: 6088 | Thread sleep time: -299891s >= -30000s | Jump to behavior |
Source: C:\Users\user\Desktop\uLFOeGZaJS.exe TID: 6088 | Thread sleep time: -299781s >= -30000s | Jump to behavior |
Source: C:\Users\user\Desktop\uLFOeGZaJS.exe TID: 6088 | Thread sleep time: -299672s >= -30000s | Jump to behavior |
Source: C:\Users\user\Desktop\uLFOeGZaJS.exe TID: 6088 | Thread sleep time: -299562s >= -30000s | Jump to behavior |
Source: C:\Users\user\Desktop\uLFOeGZaJS.exe TID: 6088 | Thread sleep time: -299453s >= -30000s | Jump to behavior |
Source: C:\Users\user\Desktop\uLFOeGZaJS.exe TID: 6088 | Thread sleep time: -299344s >= -30000s | Jump to behavior |
Source: C:\Users\user\Desktop\uLFOeGZaJS.exe TID: 6088 | Thread sleep time: -299219s >= -30000s | Jump to behavior |
Source: C:\Users\user\Desktop\uLFOeGZaJS.exe TID: 6088 | Thread sleep time: -299109s >= -30000s | Jump to behavior |
Source: C:\Users\user\Desktop\uLFOeGZaJS.exe TID: 6088 | Thread sleep time: -299000s >= -30000s | Jump to behavior |
Source: C:\Users\user\Desktop\uLFOeGZaJS.exe TID: 6088 | Thread sleep time: -298891s >= -30000s | Jump to behavior |
Source: C:\Users\user\Desktop\uLFOeGZaJS.exe TID: 6088 | Thread sleep time: -298781s >= -30000s | Jump to behavior |
Source: C:\Users\user\Desktop\uLFOeGZaJS.exe TID: 6088 | Thread sleep time: -298672s >= -30000s | Jump to behavior |
Source: C:\Users\user\Desktop\uLFOeGZaJS.exe TID: 6088 | Thread sleep time: -298563s >= -30000s | Jump to behavior |
Source: C:\Users\user\Desktop\uLFOeGZaJS.exe TID: 6088 | Thread sleep time: -298438s >= -30000s | Jump to behavior |
Source: C:\Users\user\Desktop\uLFOeGZaJS.exe TID: 6088 | Thread sleep time: -298313s >= -30000s | Jump to behavior |
Source: C:\Users\user\Desktop\uLFOeGZaJS.exe TID: 6088 | Thread sleep time: -298202s >= -30000s | Jump to behavior |
Source: C:\Users\user\Desktop\uLFOeGZaJS.exe TID: 6088 | Thread sleep time: -298082s >= -30000s | Jump to behavior |
Source: C:\Users\user\Desktop\uLFOeGZaJS.exe TID: 6088 | Thread sleep time: -297968s >= -30000s | Jump to behavior |
Source: C:\Users\user\Desktop\uLFOeGZaJS.exe TID: 6088 | Thread sleep time: -297858s >= -30000s | Jump to behavior |
Source: C:\Users\user\Desktop\uLFOeGZaJS.exe | Thread delayed: delay time: 922337203685477 | Jump to behavior |
Source: C:\Users\user\Desktop\uLFOeGZaJS.exe | Thread delayed: delay time: 600000 | Jump to behavior |
Source: C:\Users\user\Desktop\uLFOeGZaJS.exe | Thread delayed: delay time: 599875 | Jump to behavior |
Source: C:\Users\user\Desktop\uLFOeGZaJS.exe | Thread delayed: delay time: 599711 | Jump to behavior |
Source: C:\Users\user\Desktop\uLFOeGZaJS.exe | Thread delayed: delay time: 599609 | Jump to behavior |
Source: C:\Users\user\Desktop\uLFOeGZaJS.exe | Thread delayed: delay time: 599500 | Jump to behavior |
Source: C:\Users\user\Desktop\uLFOeGZaJS.exe | Thread delayed: delay time: 599389 | Jump to behavior |
Source: C:\Users\user\Desktop\uLFOeGZaJS.exe | Thread delayed: delay time: 599282 | Jump to behavior |
Source: C:\Users\user\Desktop\uLFOeGZaJS.exe | Thread delayed: delay time: 599157 | Jump to behavior |
Source: C:\Users\user\Desktop\uLFOeGZaJS.exe | Thread delayed: delay time: 599032 | Jump to behavior |
Source: C:\Users\user\Desktop\uLFOeGZaJS.exe | Thread delayed: delay time: 598907 | Jump to behavior |
Source: C:\Users\user\Desktop\uLFOeGZaJS.exe | Thread delayed: delay time: 598782 | Jump to behavior |
Source: C:\Users\user\Desktop\uLFOeGZaJS.exe | Thread delayed: delay time: 598672 | Jump to behavior |
Source: C:\Users\user\Desktop\uLFOeGZaJS.exe | Thread delayed: delay time: 598563 | Jump to behavior |
Source: C:\Users\user\Desktop\uLFOeGZaJS.exe | Thread delayed: delay time: 598438 | Jump to behavior |
Source: C:\Users\user\Desktop\uLFOeGZaJS.exe | Thread delayed: delay time: 598313 | Jump to behavior |
Source: C:\Users\user\Desktop\uLFOeGZaJS.exe | Thread delayed: delay time: 598188 | Jump to behavior |
Source: C:\Users\user\Desktop\uLFOeGZaJS.exe | Thread delayed: delay time: 598063 | Jump to behavior |
Source: C:\Users\user\Desktop\uLFOeGZaJS.exe | Thread delayed: delay time: 597953 | Jump to behavior |
Source: C:\Users\user\Desktop\uLFOeGZaJS.exe | Thread delayed: delay time: 597844 | Jump to behavior |
Source: C:\Users\user\Desktop\uLFOeGZaJS.exe | Thread delayed: delay time: 597719 | Jump to behavior |
Source: C:\Users\user\Desktop\uLFOeGZaJS.exe | Thread delayed: delay time: 597610 | Jump to behavior |
Source: C:\Users\user\Desktop\uLFOeGZaJS.exe | Thread delayed: delay time: 597485 | Jump to behavior |
Source: C:\Users\user\Desktop\uLFOeGZaJS.exe | Thread delayed: delay time: 597359 | Jump to behavior |
Source: C:\Users\user\Desktop\uLFOeGZaJS.exe | Thread delayed: delay time: 597216 | Jump to behavior |
Source: C:\Users\user\Desktop\uLFOeGZaJS.exe | Thread delayed: delay time: 597107 | Jump to behavior |
Source: C:\Users\user\Desktop\uLFOeGZaJS.exe | Thread delayed: delay time: 596978 | Jump to behavior |
Source: C:\Users\user\Desktop\uLFOeGZaJS.exe | Thread delayed: delay time: 596875 | Jump to behavior |
Source: C:\Users\user\Desktop\uLFOeGZaJS.exe | Thread delayed: delay time: 596762 | Jump to behavior |
Source: C:\Users\user\Desktop\uLFOeGZaJS.exe | Thread delayed: delay time: 596656 | Jump to behavior |
Source: C:\Users\user\Desktop\uLFOeGZaJS.exe | Thread delayed: delay time: 596547 | Jump to behavior |
Source: C:\Users\user\Desktop\uLFOeGZaJS.exe | Thread delayed: delay time: 596438 | Jump to behavior |
Source: C:\Users\user\Desktop\uLFOeGZaJS.exe | Thread delayed: delay time: 300000 | Jump to behavior |
Source: C:\Users\user\Desktop\uLFOeGZaJS.exe | Thread delayed: delay time: 299891 | Jump to behavior |
Source: C:\Users\user\Desktop\uLFOeGZaJS.exe | Thread delayed: delay time: 299781 | Jump to behavior |
Source: C:\Users\user\Desktop\uLFOeGZaJS.exe | Thread delayed: delay time: 299672 | Jump to behavior |
Source: C:\Users\user\Desktop\uLFOeGZaJS.exe | Thread delayed: delay time: 299562 | Jump to behavior |
Source: C:\Users\user\Desktop\uLFOeGZaJS.exe | Thread delayed: delay time: 299453 | Jump to behavior |
Source: C:\Users\user\Desktop\uLFOeGZaJS.exe | Thread delayed: delay time: 299344 | Jump to behavior |
Source: C:\Users\user\Desktop\uLFOeGZaJS.exe | Thread delayed: delay time: 299219 | Jump to behavior |
Source: C:\Users\user\Desktop\uLFOeGZaJS.exe | Thread delayed: delay time: 299109 | Jump to behavior |
Source: C:\Users\user\Desktop\uLFOeGZaJS.exe | Thread delayed: delay time: 299000 | Jump to behavior |
Source: C:\Users\user\Desktop\uLFOeGZaJS.exe | Thread delayed: delay time: 298891 | Jump to behavior |
Source: C:\Users\user\Desktop\uLFOeGZaJS.exe | Thread delayed: delay time: 298781 | Jump to behavior |
Source: C:\Users\user\Desktop\uLFOeGZaJS.exe | Thread delayed: delay time: 298672 | Jump to behavior |
Source: C:\Users\user\Desktop\uLFOeGZaJS.exe | Thread delayed: delay time: 298563 | Jump to behavior |
Source: C:\Users\user\Desktop\uLFOeGZaJS.exe | Thread delayed: delay time: 298438 | Jump to behavior |
Source: C:\Users\user\Desktop\uLFOeGZaJS.exe | Thread delayed: delay time: 298313 | Jump to behavior |
Source: C:\Users\user\Desktop\uLFOeGZaJS.exe | Thread delayed: delay time: 298202 | Jump to behavior |
Source: C:\Users\user\Desktop\uLFOeGZaJS.exe | Thread delayed: delay time: 298082 | Jump to behavior |
Source: C:\Users\user\Desktop\uLFOeGZaJS.exe | Thread delayed: delay time: 297968 | Jump to behavior |
Source: C:\Users\user\Desktop\uLFOeGZaJS.exe | Thread delayed: delay time: 297858 | Jump to behavior |
Source: uLFOeGZaJS.exe, 00000000.00000002.4531022648.00000000030E5000.00000004.00000800.00020000.00000000.sdmp | Binary or memory string: VMware |
Source: uLFOeGZaJS.exe | Binary or memory string: vmware |
Source: uLFOeGZaJS.exe | Binary or memory string: VMwareVBoxESelect * from Win32_ComputerSystem |
Source: uLFOeGZaJS.exe, 00000000.00000002.4530485791.0000000001436000.00000004.00000020.00020000.00000000.sdmp | Binary or memory string: Hyper-V RAW%SystemRoot%\system32\mswsock.dll |
Source: C:\Users\user\Desktop\uLFOeGZaJS.exe | Queries volume information: C:\Users\user\Desktop\uLFOeGZaJS.exe VolumeInformation | Jump to behavior |
Source: C:\Users\user\Desktop\uLFOeGZaJS.exe | Queries volume information: C:\Windows\Microsoft.NET\assembly\GAC_MSIL\System.Windows.Forms\v4.0_4.0.0.0__b77a5c561934e089\System.Windows.Forms.dll VolumeInformation | Jump to behavior |
Source: C:\Users\user\Desktop\uLFOeGZaJS.exe | Queries volume information: C:\Windows\Microsoft.NET\assembly\GAC_MSIL\System.Security\v4.0_4.0.0.0__b03f5f7f11d50a3a\System.Security.dll VolumeInformation | Jump to behavior |
Source: C:\Users\user\Desktop\uLFOeGZaJS.exe | Queries volume information: C:\Windows\Microsoft.NET\assembly\GAC_MSIL\Microsoft.VisualBasic\v4.0_10.0.0.0__b03f5f7f11d50a3a\Microsoft.VisualBasic.dll VolumeInformation | Jump to behavior |
Source: C:\Users\user\Desktop\uLFOeGZaJS.exe | Queries volume information: C:\Windows\Microsoft.NET\assembly\GAC_MSIL\System.Drawing\v4.0_4.0.0.0__b03f5f7f11d50a3a\System.Drawing.dll VolumeInformation | Jump to behavior |
Source: C:\Users\user\Desktop\uLFOeGZaJS.exe | Queries volume information: C:\Windows\Microsoft.NET\assembly\GAC_MSIL\Accessibility\v4.0_4.0.0.0__b03f5f7f11d50a3a\Accessibility.dll VolumeInformation | Jump to behavior |
Source: Yara match | File source: uLFOeGZaJS.exe, type: SAMPLE |
Source: Yara match | File source: 0.0.uLFOeGZaJS.exe.c90000.0.unpack, type: UNPACKEDPE |
Source: Yara match | File source: 00000000.00000002.4531022648.000000000310D000.00000004.00000800.00020000.00000000.sdmp, type: MEMORY |
Source: Yara match | File source: 00000000.00000000.2077701139.0000000000C92000.00000002.00000001.01000000.00000003.sdmp, type: MEMORY |
Source: Yara match | File source: 00000000.00000002.4531022648.00000000030E5000.00000004.00000800.00020000.00000000.sdmp, type: MEMORY |
Source: Yara match | File source: Process Memory Space: uLFOeGZaJS.exe PID: 1264, type: MEMORYSTR |
Source: C:\Users\user\Desktop\uLFOeGZaJS.exe | File opened: C:\Users\user\AppData\Roaming\Mozilla\Firefox\Profiles\v6zchhhv.default-release\cookies.sqlite | Jump to behavior |
Source: C:\Users\user\Desktop\uLFOeGZaJS.exe | File opened: C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Network\Cookies | Jump to behavior |
Source: C:\Users\user\Desktop\uLFOeGZaJS.exe | File opened: C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Login Data | Jump to behavior |
Source: C:\Users\user\Desktop\uLFOeGZaJS.exe | File opened: C:\Users\user\AppData\Local\Microsoft\Edge\User Data\Default\Login Data | Jump to behavior |
Source: C:\Users\user\Desktop\uLFOeGZaJS.exe | File opened: C:\Users\user\AppData\Roaming\NETGATE Technologies\BlackHawk\profiles.ini | Jump to behavior |
Source: C:\Users\user\Desktop\uLFOeGZaJS.exe | File opened: C:\Users\user\AppData\Roaming\8pecxstudios\Cyberfox\profiles.ini | Jump to behavior |
Source: C:\Users\user\Desktop\uLFOeGZaJS.exe | File opened: C:\Users\user\AppData\Roaming\Mozilla\Firefox\profiles.ini | Jump to behavior |
Source: C:\Users\user\Desktop\uLFOeGZaJS.exe | File opened: C:\Users\user\AppData\Local\Microsoft\Edge\User Data\Default\Network\Cookies | Jump to behavior |
Source: C:\Users\user\Desktop\uLFOeGZaJS.exe | File opened: C:\Users\user\AppData\Roaming\Thunderbird\profiles.ini | Jump to behavior |
Source: C:\Users\user\Desktop\uLFOeGZaJS.exe | File opened: C:\Users\user\AppData\Roaming\Thunderbird\profiles.ini | Jump to behavior |
Source: C:\Users\user\Desktop\uLFOeGZaJS.exe | File opened: C:\Users\user\AppData\Roaming\Thunderbird\profiles.ini | Jump to behavior |
Source: C:\Users\user\Desktop\uLFOeGZaJS.exe | Key opened: HKEY_CURRENT_USER\Software\Microsoft\Windows NT\CurrentVersion\Windows Messaging Subsystem\Profiles | Jump to behavior |
Source: C:\Users\user\Desktop\uLFOeGZaJS.exe | Key opened: HKEY_CURRENT_USER\Software\IncrediMail\Identities | Jump to behavior |
Source: Yara match | File source: uLFOeGZaJS.exe, type: SAMPLE |
Source: Yara match | File source: 0.0.uLFOeGZaJS.exe.c90000.0.unpack, type: UNPACKEDPE |
Source: Yara match | File source: 00000000.00000000.2077701139.0000000000C92000.00000002.00000001.01000000.00000003.sdmp, type: MEMORY |
Source: Yara match | File source: 00000000.00000002.4531022648.00000000030E5000.00000004.00000800.00020000.00000000.sdmp, type: MEMORY |
Source: Yara match | File source: Process Memory Space: uLFOeGZaJS.exe PID: 1264, type: MEMORYSTR |
Source: Yara match | File source: uLFOeGZaJS.exe, type: SAMPLE |
Source: Yara match | File source: 0.0.uLFOeGZaJS.exe.c90000.0.unpack, type: UNPACKEDPE |
Source: Yara match | File source: 00000000.00000002.4531022648.000000000310D000.00000004.00000800.00020000.00000000.sdmp, type: MEMORY |
Source: Yara match | File source: 00000000.00000000.2077701139.0000000000C92000.00000002.00000001.01000000.00000003.sdmp, type: MEMORY |
Source: Yara match | File source: 00000000.00000002.4531022648.00000000030E5000.00000004.00000800.00020000.00000000.sdmp, type: MEMORY |
Source: Yara match | File source: Process Memory Space: uLFOeGZaJS.exe PID: 1264, type: MEMORYSTR |