Source: |
Binary string: C:\Windows\System.ServiceModel.pdbpdbdel.pdb source: e8pLA1OhWt.exe, 00000000.00000002.2605011113.0000000000D31000.00000004.00000020.00020000.00000000.sdmp |
Source: |
Binary string: \??\C:\Windows\Microsoft.Net\assembly\GAC_MSIL\System.ServiceModel\v4.0_4.0.0.0__b77a5c561934e089\System.ServiceModel.pdbX source: e8pLA1OhWt.exe, 00000000.00000002.2605011113.0000000000D31000.00000004.00000020.00020000.00000000.sdmp |
Source: |
Binary string: \??\C:\Windows\System.ServiceModel.pdb source: e8pLA1OhWt.exe, 00000000.00000002.2605011113.0000000000D31000.00000004.00000020.00020000.00000000.sdmp |
Source: |
Binary string: \??\C:\Windows\dll\System.ServiceModel.pdb source: e8pLA1OhWt.exe, 00000000.00000002.2607119734.0000000005151000.00000004.00000020.00020000.00000000.sdmp |
Source: |
Binary string: System.ServiceModel.pdb source: e8pLA1OhWt.exe, 00000000.00000002.2607119734.0000000005132000.00000004.00000020.00020000.00000000.sdmp |
Source: |
Binary string: \??\C:\Windows\Microsoft.Net\assembly\GAC_MSIL\System.ServiceModel\v4.0_4.0.0.0__b77a5c561934e089\System.ServiceModel.pdb source: e8pLA1OhWt.exe, 00000000.00000002.2605011113.0000000000D31000.00000004.00000020.00020000.00000000.sdmp |
Source: |
Binary string: \??\C:\Windows\symbols\dll\System.ServiceModel.pdb source: e8pLA1OhWt.exe, 00000000.00000002.2607119734.0000000005140000.00000004.00000020.00020000.00000000.sdmp |
Source: unknown |
TCP traffic detected without corresponding DNS query: 213.21.220.222 |
Source: unknown |
TCP traffic detected without corresponding DNS query: 213.21.220.222 |
Source: unknown |
TCP traffic detected without corresponding DNS query: 213.21.220.222 |
Source: unknown |
TCP traffic detected without corresponding DNS query: 213.21.220.222 |
Source: unknown |
TCP traffic detected without corresponding DNS query: 213.21.220.222 |
Source: unknown |
TCP traffic detected without corresponding DNS query: 213.21.220.222 |
Source: unknown |
TCP traffic detected without corresponding DNS query: 213.21.220.222 |
Source: unknown |
TCP traffic detected without corresponding DNS query: 213.21.220.222 |
Source: unknown |
TCP traffic detected without corresponding DNS query: 213.21.220.222 |
Source: unknown |
TCP traffic detected without corresponding DNS query: 213.21.220.222 |
Source: unknown |
TCP traffic detected without corresponding DNS query: 213.21.220.222 |
Source: unknown |
TCP traffic detected without corresponding DNS query: 213.21.220.222 |
Source: unknown |
TCP traffic detected without corresponding DNS query: 213.21.220.222 |
Source: unknown |
TCP traffic detected without corresponding DNS query: 213.21.220.222 |
Source: unknown |
TCP traffic detected without corresponding DNS query: 213.21.220.222 |
Source: unknown |
TCP traffic detected without corresponding DNS query: 213.21.220.222 |
Source: unknown |
TCP traffic detected without corresponding DNS query: 213.21.220.222 |
Source: unknown |
TCP traffic detected without corresponding DNS query: 213.21.220.222 |
Source: unknown |
TCP traffic detected without corresponding DNS query: 213.21.220.222 |
Source: unknown |
TCP traffic detected without corresponding DNS query: 213.21.220.222 |
Source: unknown |
TCP traffic detected without corresponding DNS query: 213.21.220.222 |
Source: unknown |
TCP traffic detected without corresponding DNS query: 213.21.220.222 |
Source: unknown |
TCP traffic detected without corresponding DNS query: 213.21.220.222 |
Source: unknown |
TCP traffic detected without corresponding DNS query: 213.21.220.222 |
Source: unknown |
TCP traffic detected without corresponding DNS query: 213.21.220.222 |
Source: unknown |
TCP traffic detected without corresponding DNS query: 213.21.220.222 |
Source: unknown |
TCP traffic detected without corresponding DNS query: 213.21.220.222 |
Source: unknown |
TCP traffic detected without corresponding DNS query: 213.21.220.222 |
Source: e8pLA1OhWt.exe, 00000000.00000002.2605667538.0000000002AF2000.00000004.00000800.00020000.00000000.sdmp |
String found in binary or memory: IndexedDB\https_www.youtube.com_0.indexeddb.leveldb equals www.youtube.com (Youtube) |
Source: e8pLA1OhWt.exe, 00000000.00000002.2605667538.0000000002AF2000.00000004.00000800.00020000.00000000.sdmp |
String found in binary or memory: IndexedDB\https_www.youtube.com_0.indexeddb.leveldb@\ equals www.youtube.com (Youtube) |
Source: e8pLA1OhWt.exe, 00000000.00000002.2605667538.0000000002AF2000.00000004.00000800.00020000.00000000.sdmp |
String found in binary or memory: IndexedDB\https_www.youtube.com_0.indexeddb.leveldb`, equals www.youtube.com (Youtube) |
Source: e8pLA1OhWt.exe, 00000000.00000002.2605667538.0000000002AF2000.00000004.00000800.00020000.00000000.sdmp |
String found in binary or memory: q#www.youtube.com_0.indexeddb.leveldb equals www.youtube.com (Youtube) |
Source: e8pLA1OhWt.exe, 00000000.00000002.2605667538.0000000002AF2000.00000004.00000800.00020000.00000000.sdmp |
String found in binary or memory: q3IndexedDB\https_www.youtube.com_0.indexeddb.leveldb@\ equals www.youtube.com (Youtube) |
Source: e8pLA1OhWt.exe |
String found in binary or memory: http://cacerts.digicert.com/DigiCertAssuredIDRootCA.crt0E |
Source: e8pLA1OhWt.exe |
String found in binary or memory: http://cacerts.digicert.com/DigiCertTrustedG4RSA4096SHA256TimeStampingCA.crt0 |
Source: e8pLA1OhWt.exe |
String found in binary or memory: http://cacerts.digicert.com/DigiCertTrustedRootG4.crt0C |
Source: e8pLA1OhWt.exe |
String found in binary or memory: http://crl3.digicert.com/DigiCertAssuredIDRootCA.crl0 |
Source: e8pLA1OhWt.exe |
String found in binary or memory: http://crl3.digicert.com/DigiCertTrustedG4RSA4096SHA256TimeStampingCA.crl0 |
Source: e8pLA1OhWt.exe |
String found in binary or memory: http://crl3.digicert.com/DigiCertTrustedRootG4.crl0 |
Source: e8pLA1OhWt.exe |
String found in binary or memory: http://ocsp.digicert.com0A |
Source: e8pLA1OhWt.exe |
String found in binary or memory: http://ocsp.digicert.com0C |
Source: e8pLA1OhWt.exe |
String found in binary or memory: http://ocsp.digicert.com0X |
Source: e8pLA1OhWt.exe, 00000000.00000002.2605667538.0000000002B43000.00000004.00000800.00020000.00000000.sdmp |
String found in binary or memory: http://schemas.xmlsoap.org/soap/actor/next |
Source: e8pLA1OhWt.exe, 00000000.00000002.2605667538.0000000002B43000.00000004.00000800.00020000.00000000.sdmp |
String found in binary or memory: http://schemas.xmlsoap.org/soap/envelope/ |
Source: e8pLA1OhWt.exe, 00000000.00000002.2605667538.0000000002B43000.00000004.00000800.00020000.00000000.sdmp |
String found in binary or memory: http://schemas.xmlsoap.org/ws/2004/08/addressing |
Source: e8pLA1OhWt.exe, 00000000.00000002.2605667538.0000000002B43000.00000004.00000800.00020000.00000000.sdmp |
String found in binary or memory: http://schemas.xmlsoap.org/ws/2004/08/addressing/fault |
Source: e8pLA1OhWt.exe, 00000000.00000002.2605667538.0000000002B43000.00000004.00000800.00020000.00000000.sdmp |
String found in binary or memory: http://schemas.xmlsoap.org/ws/2004/08/addressing/role/anonymous |
Source: e8pLA1OhWt.exe, 00000000.00000002.2605667538.0000000002B43000.00000004.00000800.00020000.00000000.sdmp |
String found in binary or memory: http://schemas.xmlsoap.org/ws/2005/02/rm |
Source: e8pLA1OhWt.exe, 00000000.00000002.2605667538.0000000002B43000.00000004.00000800.00020000.00000000.sdmp |
String found in binary or memory: http://schemas.xmlsoap.org/ws/2005/02/rm/AckRequested |
Source: e8pLA1OhWt.exe, 00000000.00000002.2605667538.0000000002B43000.00000004.00000800.00020000.00000000.sdmp |
String found in binary or memory: http://schemas.xmlsoap.org/ws/2005/02/rm/CreateSequence |
Source: e8pLA1OhWt.exe, 00000000.00000002.2605667538.0000000002B43000.00000004.00000800.00020000.00000000.sdmp |
String found in binary or memory: http://schemas.xmlsoap.org/ws/2005/02/rm/CreateSequenceResponse |
Source: e8pLA1OhWt.exe, 00000000.00000002.2605667538.0000000002B43000.00000004.00000800.00020000.00000000.sdmp |
String found in binary or memory: http://schemas.xmlsoap.org/ws/2005/02/rm/LastMessage |
Source: e8pLA1OhWt.exe, 00000000.00000002.2605667538.0000000002B43000.00000004.00000800.00020000.00000000.sdmp |
String found in binary or memory: http://schemas.xmlsoap.org/ws/2005/02/rm/SequenceAcknowledgement |
Source: e8pLA1OhWt.exe, 00000000.00000002.2605667538.0000000002B43000.00000004.00000800.00020000.00000000.sdmp |
String found in binary or memory: http://schemas.xmlsoap.org/ws/2005/02/rm/TerminateSequence |
Source: e8pLA1OhWt.exe, 00000000.00000002.2605667538.0000000002B43000.00000004.00000800.00020000.00000000.sdmp |
String found in binary or memory: http://schemas.xmlsoap.org/ws/2005/05/identity/claims/dns |
Source: e8pLA1OhWt.exe, 00000000.00000002.2605667538.0000000002B43000.00000004.00000800.00020000.00000000.sdmp |
String found in binary or memory: http://schemas.xmlsoap.org/ws/2005/05/identity/right/possessproperty |
Source: e8pLA1OhWt.exe, 00000000.00000002.2605667538.0000000002B43000.00000004.00000800.00020000.00000000.sdmp |
String found in binary or memory: http://tempuri.org/8) |
Source: e8pLA1OhWt.exe, 00000000.00000002.2605667538.0000000002B43000.00000004.00000800.00020000.00000000.sdmp |
String found in binary or memory: http://tempuri.org/RestAPI/ |
Source: e8pLA1OhWt.exe, 00000000.00000002.2605667538.0000000002C8C000.00000004.00000800.00020000.00000000.sdmp, e8pLA1OhWt.exe, 00000000.00000002.2605667538.0000000002CCE000.00000004.00000800.00020000.00000000.sdmp, e8pLA1OhWt.exe, 00000000.00000002.2605667538.0000000002BBB000.00000004.00000800.00020000.00000000.sdmp, e8pLA1OhWt.exe, 00000000.00000002.2605667538.0000000002C07000.00000004.00000800.00020000.00000000.sdmp, e8pLA1OhWt.exe, 00000000.00000002.2605667538.0000000002C49000.00000004.00000800.00020000.00000000.sdmp, e8pLA1OhWt.exe, 00000000.00000002.2605667538.0000000002B43000.00000004.00000800.00020000.00000000.sdmp |
String found in binary or memory: http://tempuri.org/RestAPI/TreeObject1LR |
Source: e8pLA1OhWt.exe, 00000000.00000002.2605667538.0000000002C8C000.00000004.00000800.00020000.00000000.sdmp, e8pLA1OhWt.exe, 00000000.00000002.2605667538.0000000002CCE000.00000004.00000800.00020000.00000000.sdmp, e8pLA1OhWt.exe, 00000000.00000002.2605667538.0000000002BBB000.00000004.00000800.00020000.00000000.sdmp, e8pLA1OhWt.exe, 00000000.00000002.2605667538.0000000002C07000.00000004.00000800.00020000.00000000.sdmp, e8pLA1OhWt.exe, 00000000.00000002.2605667538.0000000002C49000.00000004.00000800.00020000.00000000.sdmp, e8pLA1OhWt.exe, 00000000.00000002.2605667538.0000000002B43000.00000004.00000800.00020000.00000000.sdmp |
String found in binary or memory: http://tempuri.org/RestAPI/TreeObject1Response |
Source: e8pLA1OhWt.exe, 00000000.00000002.2605667538.0000000002C8C000.00000004.00000800.00020000.00000000.sdmp, e8pLA1OhWt.exe, 00000000.00000002.2605667538.0000000002CCE000.00000004.00000800.00020000.00000000.sdmp, e8pLA1OhWt.exe, 00000000.00000002.2605667538.0000000002BBB000.00000004.00000800.00020000.00000000.sdmp, e8pLA1OhWt.exe, 00000000.00000002.2605667538.0000000002C07000.00000004.00000800.00020000.00000000.sdmp, e8pLA1OhWt.exe, 00000000.00000002.2605667538.0000000002C49000.00000004.00000800.00020000.00000000.sdmp, e8pLA1OhWt.exe, 00000000.00000002.2605667538.0000000002B43000.00000004.00000800.00020000.00000000.sdmp |
String found in binary or memory: http://tempuri.org/RestAPI/TreeObject2LR |
Source: e8pLA1OhWt.exe, 00000000.00000002.2605667538.0000000002C8C000.00000004.00000800.00020000.00000000.sdmp, e8pLA1OhWt.exe, 00000000.00000002.2605667538.0000000002CCE000.00000004.00000800.00020000.00000000.sdmp, e8pLA1OhWt.exe, 00000000.00000002.2605667538.0000000002BBB000.00000004.00000800.00020000.00000000.sdmp, e8pLA1OhWt.exe, 00000000.00000002.2605667538.0000000002C07000.00000004.00000800.00020000.00000000.sdmp, e8pLA1OhWt.exe, 00000000.00000002.2605667538.0000000002C49000.00000004.00000800.00020000.00000000.sdmp, e8pLA1OhWt.exe, 00000000.00000002.2605667538.0000000002B43000.00000004.00000800.00020000.00000000.sdmp |
String found in binary or memory: http://tempuri.org/RestAPI/TreeObject2Response |
Source: e8pLA1OhWt.exe, 00000000.00000002.2605667538.0000000002C8C000.00000004.00000800.00020000.00000000.sdmp, e8pLA1OhWt.exe, 00000000.00000002.2605667538.0000000002CCE000.00000004.00000800.00020000.00000000.sdmp, e8pLA1OhWt.exe, 00000000.00000002.2605667538.0000000002BBB000.00000004.00000800.00020000.00000000.sdmp, e8pLA1OhWt.exe, 00000000.00000002.2605667538.0000000002C07000.00000004.00000800.00020000.00000000.sdmp, e8pLA1OhWt.exe, 00000000.00000002.2605667538.0000000002C49000.00000004.00000800.00020000.00000000.sdmp, e8pLA1OhWt.exe, 00000000.00000002.2605667538.0000000002B43000.00000004.00000800.00020000.00000000.sdmp |
String found in binary or memory: http://tempuri.org/RestAPI/TreeObject3LR |
Source: e8pLA1OhWt.exe, 00000000.00000002.2605667538.0000000002C8C000.00000004.00000800.00020000.00000000.sdmp, e8pLA1OhWt.exe, 00000000.00000002.2605667538.0000000002CCE000.00000004.00000800.00020000.00000000.sdmp, e8pLA1OhWt.exe, 00000000.00000002.2605667538.0000000002BBB000.00000004.00000800.00020000.00000000.sdmp, e8pLA1OhWt.exe, 00000000.00000002.2605667538.0000000002C07000.00000004.00000800.00020000.00000000.sdmp, e8pLA1OhWt.exe, 00000000.00000002.2605667538.0000000002C49000.00000004.00000800.00020000.00000000.sdmp, e8pLA1OhWt.exe, 00000000.00000002.2605667538.0000000002B43000.00000004.00000800.00020000.00000000.sdmp |
String found in binary or memory: http://tempuri.org/RestAPI/TreeObject3Response |
Source: e8pLA1OhWt.exe, 00000000.00000002.2605667538.0000000002A78000.00000004.00000800.00020000.00000000.sdmp |
String found in binary or memory: https://api.ip.s |
Source: e8pLA1OhWt.exe, 00000000.00000002.2605667538.0000000002A78000.00000004.00000800.00020000.00000000.sdmp |
String found in binary or memory: https://api.ip.sb/ip |
Source: e8pLA1OhWt.exe, 00000000.00000000.1368754173.0000000000602000.00000002.00000001.01000000.00000003.sdmp |
Binary or memory string: OriginalFilenameCumbered.exe" vs e8pLA1OhWt.exe |
Source: e8pLA1OhWt.exe, 00000000.00000002.2605011113.0000000000CFE000.00000004.00000020.00020000.00000000.sdmp |
Binary or memory string: OriginalFilenameclr.dllT vs e8pLA1OhWt.exe |
Source: e8pLA1OhWt.exe |
Binary or memory string: OriginalFilenameCumbered.exe" vs e8pLA1OhWt.exe |
Source: e8pLA1OhWt.exe, type: SAMPLE |
Matched rule: MALWARE_Win_zgRAT author = ditekSHen, description = Detects zgRAT |
Source: 0.0.e8pLA1OhWt.exe.600000.0.unpack, type: UNPACKEDPE |
Matched rule: MALWARE_Win_zgRAT author = ditekSHen, description = Detects zgRAT |
Source: e8pLA1OhWt.exe, Strings.cs |
Cryptographic APIs: 'CreateDecryptor' |
Source: e8pLA1OhWt.exe, o7sM5NGly1brP6N8Som.cs |
Cryptographic APIs: 'CreateDecryptor' |
Source: e8pLA1OhWt.exe, o7sM5NGly1brP6N8Som.cs |
Cryptographic APIs: 'CreateDecryptor' |
Source: C:\Users\user\Desktop\e8pLA1OhWt.exe |
Section loaded: mscoree.dll |
Jump to behavior |
Source: C:\Users\user\Desktop\e8pLA1OhWt.exe |
Section loaded: apphelp.dll |
Jump to behavior |
Source: C:\Users\user\Desktop\e8pLA1OhWt.exe |
Section loaded: kernel.appcore.dll |
Jump to behavior |
Source: C:\Users\user\Desktop\e8pLA1OhWt.exe |
Section loaded: version.dll |
Jump to behavior |
Source: C:\Users\user\Desktop\e8pLA1OhWt.exe |
Section loaded: vcruntime140_clr0400.dll |
Jump to behavior |
Source: C:\Users\user\Desktop\e8pLA1OhWt.exe |
Section loaded: ucrtbase_clr0400.dll |
Jump to behavior |
Source: C:\Users\user\Desktop\e8pLA1OhWt.exe |
Section loaded: ucrtbase_clr0400.dll |
Jump to behavior |
Source: C:\Users\user\Desktop\e8pLA1OhWt.exe |
Section loaded: cryptsp.dll |
Jump to behavior |
Source: C:\Users\user\Desktop\e8pLA1OhWt.exe |
Section loaded: rsaenh.dll |
Jump to behavior |
Source: C:\Users\user\Desktop\e8pLA1OhWt.exe |
Section loaded: cryptbase.dll |
Jump to behavior |
Source: C:\Users\user\Desktop\e8pLA1OhWt.exe |
Section loaded: sspicli.dll |
Jump to behavior |
Source: C:\Users\user\Desktop\e8pLA1OhWt.exe |
Section loaded: windows.storage.dll |
Jump to behavior |
Source: C:\Users\user\Desktop\e8pLA1OhWt.exe |
Section loaded: wldp.dll |
Jump to behavior |
Source: C:\Users\user\Desktop\e8pLA1OhWt.exe |
Section loaded: profapi.dll |
Jump to behavior |
Source: C:\Users\user\Desktop\e8pLA1OhWt.exe |
Section loaded: mswsock.dll |
Jump to behavior |
Source: |
Binary string: C:\Windows\System.ServiceModel.pdbpdbdel.pdb source: e8pLA1OhWt.exe, 00000000.00000002.2605011113.0000000000D31000.00000004.00000020.00020000.00000000.sdmp |
Source: |
Binary string: \??\C:\Windows\Microsoft.Net\assembly\GAC_MSIL\System.ServiceModel\v4.0_4.0.0.0__b77a5c561934e089\System.ServiceModel.pdbX source: e8pLA1OhWt.exe, 00000000.00000002.2605011113.0000000000D31000.00000004.00000020.00020000.00000000.sdmp |
Source: |
Binary string: \??\C:\Windows\System.ServiceModel.pdb source: e8pLA1OhWt.exe, 00000000.00000002.2605011113.0000000000D31000.00000004.00000020.00020000.00000000.sdmp |
Source: |
Binary string: \??\C:\Windows\dll\System.ServiceModel.pdb source: e8pLA1OhWt.exe, 00000000.00000002.2607119734.0000000005151000.00000004.00000020.00020000.00000000.sdmp |
Source: |
Binary string: System.ServiceModel.pdb source: e8pLA1OhWt.exe, 00000000.00000002.2607119734.0000000005132000.00000004.00000020.00020000.00000000.sdmp |
Source: |
Binary string: \??\C:\Windows\Microsoft.Net\assembly\GAC_MSIL\System.ServiceModel\v4.0_4.0.0.0__b77a5c561934e089\System.ServiceModel.pdb source: e8pLA1OhWt.exe, 00000000.00000002.2605011113.0000000000D31000.00000004.00000020.00020000.00000000.sdmp |
Source: |
Binary string: \??\C:\Windows\symbols\dll\System.ServiceModel.pdb source: e8pLA1OhWt.exe, 00000000.00000002.2607119734.0000000005140000.00000004.00000020.00020000.00000000.sdmp |
Source: e8pLA1OhWt.exe, xyUIyFi0ReaLSD6iBqL.cs |
High entropy of concatenated method names: 'yITibaNQ4A', 'GJIiegegHL', 'lRDiHOnWZ5', 'aLXidl1CUE', 'BZCiQiWHuj', 'eEsiJ4Q8Kq', 'MaIiVilCXF', 'Fkfiq4To1G', 'uZCi57gDNw', 'DIRizus36X' |
Source: e8pLA1OhWt.exe, o7sM5NGly1brP6N8Som.cs |
High entropy of concatenated method names: 'LdEiK6coYj', 'g38PJ8K3c0', 'DmSiBd5k16', 'BPHiRVDYZo', 'fVYirM23Nk', 'KkeiAq7iHt', 'mJ6xnWXOKt', 'bVNGIawupk', 'IkGG9HXQZt', 'B8yG3p9TPo' |
Source: C:\Users\user\Desktop\e8pLA1OhWt.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\Desktop\e8pLA1OhWt.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\Desktop\e8pLA1OhWt.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\Desktop\e8pLA1OhWt.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\Desktop\e8pLA1OhWt.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\Desktop\e8pLA1OhWt.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\Desktop\e8pLA1OhWt.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\Desktop\e8pLA1OhWt.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\Desktop\e8pLA1OhWt.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\Desktop\e8pLA1OhWt.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\Desktop\e8pLA1OhWt.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\Desktop\e8pLA1OhWt.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\Desktop\e8pLA1OhWt.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\Desktop\e8pLA1OhWt.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\Desktop\e8pLA1OhWt.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\Desktop\e8pLA1OhWt.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\Desktop\e8pLA1OhWt.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\Desktop\e8pLA1OhWt.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\Desktop\e8pLA1OhWt.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\Desktop\e8pLA1OhWt.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\Desktop\e8pLA1OhWt.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\Desktop\e8pLA1OhWt.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\Desktop\e8pLA1OhWt.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\Desktop\e8pLA1OhWt.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\Desktop\e8pLA1OhWt.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\Desktop\e8pLA1OhWt.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\Desktop\e8pLA1OhWt.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\Desktop\e8pLA1OhWt.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\Desktop\e8pLA1OhWt.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\Desktop\e8pLA1OhWt.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\Desktop\e8pLA1OhWt.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\Desktop\e8pLA1OhWt.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\Desktop\e8pLA1OhWt.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\Desktop\e8pLA1OhWt.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\Desktop\e8pLA1OhWt.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\Desktop\e8pLA1OhWt.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\Desktop\e8pLA1OhWt.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\Desktop\e8pLA1OhWt.exe |
Queries volume information: C:\Users\user\Desktop\e8pLA1OhWt.exe VolumeInformation |
Jump to behavior |
Source: C:\Users\user\Desktop\e8pLA1OhWt.exe |
Queries volume information: C:\Windows\Microsoft.NET\assembly\GAC_MSIL\System.ServiceModel\v4.0_4.0.0.0__b77a5c561934e089\System.ServiceModel.dll VolumeInformation |
Jump to behavior |
Source: C:\Users\user\Desktop\e8pLA1OhWt.exe |
Queries volume information: C:\Windows\Microsoft.NET\assembly\GAC_MSIL\SMDiagnostics\v4.0_4.0.0.0__b77a5c561934e089\SMDiagnostics.dll VolumeInformation |
Jump to behavior |
Source: C:\Users\user\Desktop\e8pLA1OhWt.exe |
Queries volume information: C:\Windows\Microsoft.NET\assembly\GAC_MSIL\System.IdentityModel\v4.0_4.0.0.0__b77a5c561934e089\System.IdentityModel.dll VolumeInformation |
Jump to behavior |
Source: C:\Users\user\Desktop\e8pLA1OhWt.exe |
Queries volume information: C:\Windows\Microsoft.NET\assembly\GAC_MSIL\System.ServiceModel.Internals\v4.0_4.0.0.0__31bf3856ad364e35\System.ServiceModel.Internals.dll VolumeInformation |
Jump to behavior |
Source: C:\Users\user\Desktop\e8pLA1OhWt.exe |
Queries volume information: C:\Windows\Microsoft.NET\assembly\GAC_32\System.Transactions\v4.0_4.0.0.0__b77a5c561934e089\System.Transactions.dll VolumeInformation |
Jump to behavior |
Source: Yara match |
File source: e8pLA1OhWt.exe, type: SAMPLE |
Source: Yara match |
File source: 0.0.e8pLA1OhWt.exe.600000.0.unpack, type: UNPACKEDPE |
Source: Yara match |
File source: 00000000.00000000.1368754173.0000000000602000.00000002.00000001.01000000.00000003.sdmp, type: MEMORY |
Source: Yara match |
File source: Process Memory Space: e8pLA1OhWt.exe PID: 7456, type: MEMORYSTR |
Source: Yara match |
File source: e8pLA1OhWt.exe, type: SAMPLE |
Source: Yara match |
File source: 0.0.e8pLA1OhWt.exe.600000.0.unpack, type: UNPACKEDPE |
Source: Yara match |
File source: 00000000.00000000.1368754173.0000000000602000.00000002.00000001.01000000.00000003.sdmp, type: MEMORY |
Source: Yara match |
File source: Process Memory Space: e8pLA1OhWt.exe PID: 7456, type: MEMORYSTR |