Click to jump to signature section
Source: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\StartUp\l4.exe | ReversingLabs: Detection: 63% |
Source: C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\l4.exe | ReversingLabs: Detection: 63% |
Source: l4.exe | ReversingLabs: Detection: 63% |
Source: Submited Sample | Integrated Neural Analysis Model: Matched 99.8% probability |
Source: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\StartUp\l4.exe | Joe Sandbox ML: detected |
Source: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\StartUp\l4.exe | Joe Sandbox ML: detected |
Source: l4.exe | Static PE information: HIGH_ENTROPY_VA, DYNAMIC_BASE, NX_COMPAT, TERMINAL_SERVER_AWARE |
Source: | Binary string: D:\a\_work\1\s\binaries\amd64ret\bin\amd64\\vcruntime140_1.amd64.pdb source: l4.exe, 00000000.00000003.1286029353.00000158457C8000.00000004.00000020.00020000.00000000.sdmp, l4.exe, 00000000.00000003.1276528706.00000158483B0000.00000004.00000020.00020000.00000000.sdmp, l4.exe, 00000000.00000002.3705165473.00007FF7F8E2B000.00000004.00000001.01000000.00000003.sdmp, l4.exe, 0000000A.00000003.1396402930.0000023B5EE86000.00000004.00000020.00020000.00000000.sdmp, l4.exe, 0000000A.00000002.1471185441.00007FF65B17B000.00000004.00000001.01000000.0000000C.sdmp, l4.exe, 0000000A.00000003.1403235878.0000023B5C1A9000.00000004.00000020.00020000.00000000.sdmp |
Source: | Binary string: D:\a\1\b\bin\amd64\select.pdb source: l4.exe, 00000000.00000003.1276528706.0000015848280000.00000004.00000020.00020000.00000000.sdmp, l4.exe, 00000008.00000002.3709183900.00007FFB1E843000.00000002.00000001.01000000.00000009.sdmp, l4.exe, 0000000A.00000003.1396402930.0000023B5ED56000.00000004.00000020.00020000.00000000.sdmp, l4.exe, 0000000C.00000002.1466730977.00007FFB22653000.00000002.00000001.01000000.00000011.sdmp |
Source: | Binary string: D:\a\1\b\bin\amd64\python312.pdb source: l4.exe, 00000000.00000003.1276528706.0000015847FEF000.00000004.00000020.00020000.00000000.sdmp, l4.exe, 00000008.00000002.3707644441.00007FFB0C312000.00000002.00000001.01000000.00000006.sdmp, l4.exe, 0000000A.00000003.1396402930.0000023B5EAC5000.00000004.00000020.00020000.00000000.sdmp |
Source: | Binary string: D:\a\1\b\bin\amd64\unicodedata.pdb source: l4.exe, 00000000.00000003.1276528706.00000158483B0000.00000004.00000020.00020000.00000000.sdmp, l4.exe, 0000000A.00000003.1396402930.0000023B5EE86000.00000004.00000020.00020000.00000000.sdmp |
Source: | Binary string: D:\a\1\b\libcrypto-3.pdb| source: l4.exe, 00000000.00000003.1276528706.0000015847B4A000.00000004.00000020.00020000.00000000.sdmp, l4.exe, 0000000A.00000003.1396402930.0000023B5E620000.00000004.00000020.00020000.00000000.sdmp |
Source: | Binary string: D:\a\1\b\bin\amd64\_decimal.pdb$$ source: l4.exe, 00000000.00000003.1276528706.0000015847078000.00000004.00000020.00020000.00000000.sdmp, l4.exe, 0000000A.00000003.1396402930.0000023B5DB4E000.00000004.00000020.00020000.00000000.sdmp |
Source: | Binary string: D:\a\1\b\bin\amd64\_hashlib.pdb source: l4.exe, 00000000.00000003.1276528706.0000015847078000.00000004.00000020.00020000.00000000.sdmp, l4.exe, 0000000A.00000003.1396402930.0000023B5DB4E000.00000004.00000020.00020000.00000000.sdmp |
Source: | Binary string: D:\a\1\b\bin\amd64\_lzma.pdbNN source: l4.exe, 00000000.00000003.1276528706.00000158476D7000.00000004.00000020.00020000.00000000.sdmp, l4.exe, 00000008.00000002.3708639100.00007FFB1B70C000.00000002.00000001.01000000.0000000B.sdmp, l4.exe, 0000000A.00000003.1396402930.0000023B5E1AD000.00000004.00000020.00020000.00000000.sdmp |
Source: | Binary string: D:\a\1\b\bin\amd64\_decimal.pdb source: l4.exe, 00000000.00000003.1276528706.0000015847078000.00000004.00000020.00020000.00000000.sdmp, l4.exe, 0000000A.00000003.1396402930.0000023B5DB4E000.00000004.00000020.00020000.00000000.sdmp |
Source: | Binary string: @ compiler: cl /Zi /Fdossl_static.pdb /Gs0 /GF /Gy /MD /W3 /wd4090 /nologo /O2 -DL_ENDIAN -DOPENSSL_PIC -D"OPENSSL_BUILDING_OPENSSL" -D"OPENSSL_SYS_WIN32" -D"WIN32_LEAN_AND_MEAN" -D"UNICODE" -D"_UNICODE" -D"_CRT_SECURE_NO_DEPRECATE" -D"_WINSOCK_DEPRECATED_NO_WARNINGS" -D"NDEBUG"OpenSSL 3.0.15 3 Sep 20243.0.15built on: Wed Sep 4 15:52:04 2024 UTCplatform: VC-WIN64A-masmOPENSSLDIR: "C:\Program Files\Common Files\SSL"ENGINESDIR: "C:\Program Files\OpenSSL\lib\engines-3"MODULESDIR: "C:\Program Files\OpenSSL\lib\ossl-modules"CPUINFO: N/Anot availableget_and_lock..\s\crypto\ex_data.cossl_crypto_get_ex_new_index_exossl_crypto_new_ex_data_exCRYPTO_dup_ex_dataCRYPTO_set_ex_dataOPENSSL_WIN32_UTF8..\s\crypto\getenv.ccompiler: cl /Zi /Fdossl_static.pdb /Gs0 /GF /Gy /MD /W3 /wd4090 /nologo /O2 -DL_ENDIAN -DOPENSSL_PIC -D"OPENSSL_BUILDING_OPENSSL" -D"OPENSSL_SYS_WIN32" -D"WIN32_LEAN_AND_MEAN" -D"UNICODE" -D"_UNICODE" -D"_CRT_SECURE_NO_DEPRECATE" -D"_WINSOCK_DEPRECATED_NO_WARNINGS" -D"NDEBUG";CPUINFO: OPENSSL_ia32cap=0x%llx:0x%llxOPENSSL_ia32cap env:%sos-specificC:\Program Files\Common Files\SSLC:\Program Files\OpenSSL\lib\ossl-modules.dllCPUINFO: ..\s\crypto\init.cOPENSSL_init_cryptoOPENSSL_atexit..\s\crypto\initthread.c..\s\crypto\mem_sec.cassertion failed: (bit & 1) == 0assertion failed: list >= 0 && list < sh.freelist_sizeassertion failed: ((ptr - sh.arena) & ((sh.arena_size >> list) - 1)) == 0assertion failed: bit > 0 && bit < sh.bittable_sizeassertion failed: TESTBIT(table, bit)assertion failed: !TESTBIT(table, bit)assertion failed: WITHIN_FREELIST(list)assertion failed: WITHIN_ARENA(ptr)assertion failed: temp->next == NULL || WITHIN_ARENA(temp->next)assertion failed: (char **)temp->next->p_next == listassertion failed: WITHIN_FREELIST(temp2->p_next) || WITHIN_ARENA(temp2->p_next)assertion failed: size > 0assertion failed: (size & (size - 1)) == 0assertion failed: (minsize & (minsize - 1)) == 0assertion failed: sh.freelist != NULLassertion failed: sh.bittable != NULLassertion failed: sh.bitmalloc != NULLassertion failed: !sh_testbit(temp, slist, sh.bitmalloc)assertion failed: temp != sh.freelist[slist]assertion failed: sh.freelist[slist] == tempassertion failed: temp-(sh.arena_size >> slist) == sh_find_my_buddy(temp, slist)assertion failed: sh_testbit(chunk, list, sh.bittable)assertion failed: WITHIN_ARENA(chunk)assertion failed: sh_testbit(ptr, list, sh.bittable)assertion failed: ptr == sh_find_my_buddy(buddy, list)assertion failed: |