Click to jump to signature section
Source: Set-up.exe | ReversingLabs: Detection: 34% |
Source: Submited Sample | Integrated Neural Analysis Model: Matched 97.1% probability |
Source: Set-up.exe, 00000000.00000002.3149050194.0000000000EFD000.00000002.00000001.01000000.00000003.sdmp | Binary or memory string: -----BEGIN PUBLIC KEY----- | memstr_f21c39eb-b |
Source: Set-up.exe | Static PE information: EXECUTABLE_IMAGE, LINE_NUMS_STRIPPED, LOCAL_SYMS_STRIPPED, 32BIT_MACHINE, DEBUG_STRIPPED |
Source: Set-up.exe | Static PE information: DYNAMIC_BASE, NX_COMPAT |
Source: global traffic | HTTP traffic detected: GET /ip HTTP/1.1Host: httpbin.orgAccept: */* |
Source: Joe Sandbox View | IP Address: 98.85.100.80 98.85.100.80 |
Source: unknown | UDP traffic detected without corresponding DNS query: 1.1.1.1 |
Source: unknown | UDP traffic detected without corresponding DNS query: 1.1.1.1 |
Source: unknown | UDP traffic detected without corresponding DNS query: 1.1.1.1 |
Source: unknown | UDP traffic detected without corresponding DNS query: 1.1.1.1 |
Source: unknown | UDP traffic detected without corresponding DNS query: 1.1.1.1 |
Source: unknown | UDP traffic detected without corresponding DNS query: 1.1.1.1 |
Source: unknown | UDP traffic detected without corresponding DNS query: 1.1.1.1 |
Source: unknown | UDP traffic detected without corresponding DNS query: 1.1.1.1 |
Source: unknown | UDP traffic detected without corresponding DNS query: 1.1.1.1 |
Source: unknown | UDP traffic detected without corresponding DNS query: 1.1.1.1 |
Source: unknown | UDP traffic detected without corresponding DNS query: 1.1.1.1 |
Source: unknown | UDP traffic detected without corresponding DNS query: 1.1.1.1 |
Source: unknown | UDP traffic detected without corresponding DNS query: 1.1.1.1 |
Source: unknown | UDP traffic detected without corresponding DNS query: 1.1.1.1 |
Source: global traffic | HTTP traffic detected: GET /ip HTTP/1.1Host: httpbin.orgAccept: */* |
Source: global traffic | DNS traffic detected: DNS query: httpbin.org |
Source: global traffic | DNS traffic detected: DNS query: home.sevkx17vs.top |
Source: Set-up.exe | String found in binary or memory: http://.css |
Source: Set-up.exe | String found in binary or memory: http://.jpg |
Source: Set-up.exe | String found in binary or memory: http://home.sevkx17vs.top/TYELKNoHAuZzdCMGzBXk17 |
Source: Set-up.exe, 00000000.00000002.3149032436.0000000000EFC000.00000004.00000001.01000000.00000003.sdmp, Set-up.exe, 00000000.00000002.3151001488.00000000018EE000.00000004.00000020.00020000.00000000.sdmp | String found in binary or memory: http://home.sevkx17vs.top/TYELKNoHAuZzdCMGzBXk1733202266 |
Source: Set-up.exe, 00000000.00000002.3151001488.00000000018EE000.00000004.00000020.00020000.00000000.sdmp | String found in binary or memory: http://home.sevkx17vs.top/TYELKNoHAuZzdCMGzBXk17332022666963 |
Source: Set-up.exe, 00000000.00000002.3149032436.0000000000EFC000.00000004.00000001.01000000.00000003.sdmp | String found in binary or memory: http://home.sevkx17vs.top/TYELKNoHAuZzdCMGzBXk1733202266http://home.sevkx17vs.top/TYELKNoHAuZzdCMGzB |
Source: Set-up.exe, 00000000.00000002.3151001488.00000000018EE000.00000004.00000020.00020000.00000000.sdmp | String found in binary or memory: http://home.sevkx17vs.top/TYELKNoHAuZzdCMGzBXk1733202266osts |
Source: Set-up.exe | String found in binary or memory: http://html4/loose.dtd |
Source: Amcache.hve.6.dr | String found in binary or memory: http://upx.sf.net |
Source: Set-up.exe | String found in binary or memory: https://curl.se/docs/alt-svc.html |
Source: Set-up.exe | String found in binary or memory: https://curl.se/docs/hsts.html |
Source: Set-up.exe | String found in binary or memory: https://curl.se/docs/http-cookies.html |
Source: Set-up.exe | String found in binary or memory: https://httpbin.org/ip |
Source: Set-up.exe | String found in binary or memory: https://httpbin.org/ipbefore |
Source: unknown | Network traffic detected: HTTP traffic on port 443 -> 49731 |
Source: unknown | Network traffic detected: HTTP traffic on port 49731 -> 443 |
Source: C:\Users\user\Desktop\Set-up.exe | Process created: C:\Windows\SysWOW64\WerFault.exe C:\Windows\SysWOW64\WerFault.exe -u -p 7508 -s 736 |
Source: Set-up.exe | Static PE information: EXECUTABLE_IMAGE, LINE_NUMS_STRIPPED, LOCAL_SYMS_STRIPPED, 32BIT_MACHINE, DEBUG_STRIPPED |
Source: Set-up.exe | Binary string: Lntdll.dllNtCreateFileNtDeviceIoControlFileNtCancelIoFileEx\Device\Afd |
Source: classification engine | Classification label: mal56.evad.winEXE@2/5@14/1 |
Source: C:\Windows\SysWOW64\WerFault.exe | Mutant created: \Sessions\1\BaseNamedObjects\Local\WERReportingForProcess7508 |
Source: C:\Users\user\Desktop\Set-up.exe | Mutant created: \Sessions\1\BaseNamedObjects\My_mutex |
Source: C:\Windows\SysWOW64\WerFault.exe | File created: C:\ProgramData\Microsoft\Windows\WER\Temp\c199e997-ddff-420e-a8fd-df02c7ab2254 | Jump to behavior |
Source: Set-up.exe | Static PE information: Section: .text IMAGE_SCN_CNT_CODE, IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_EXECUTE, IMAGE_SCN_MEM_READ |
Source: C:\Users\user\Desktop\Set-up.exe | Key opened: HKEY_CURRENT_USER\Software\Policies\Microsoft\Windows\Safer\CodeIdentifiers | Jump to behavior |
Source: C:\Users\user\Desktop\Set-up.exe | File read: C:\Windows\System32\drivers\etc\hosts | Jump to behavior |
Source: C:\Users\user\Desktop\Set-up.exe | File read: C:\Windows\System32\drivers\etc\hosts | Jump to behavior |
Source: C:\Users\user\Desktop\Set-up.exe | File read: C:\Windows\System32\drivers\etc\hosts | Jump to behavior |
Source: C:\Users\user\Desktop\Set-up.exe | File read: C:\Windows\System32\drivers\etc\hosts | Jump to behavior |
Source: C:\Users\user\Desktop\Set-up.exe | File read: C:\Windows\System32\drivers\etc\hosts | Jump to behavior |
Source: C:\Users\user\Desktop\Set-up.exe | File read: C:\Windows\System32\drivers\etc\hosts | Jump to behavior |
Source: Set-up.exe | ReversingLabs: Detection: 34% |
Source: Set-up.exe | String found in binary or memory: iphlpapi.dllif_nametoindexkernel32LoadLibraryExA\/AddDllDirectorysystem_win32.c@ |
Source: Set-up.exe | String found in binary or memory: in-addr.arpa |
Source: Set-up.exe | String found in binary or memory: 8L0123456789abcdefin-addr.arpaip6.arpa |
Source: Set-up.exe | String found in binary or memory: Unable to complete request for channel-process-startup |
Source: Set-up.exe | String found in binary or memory: JM[\Unable to allocate space for channel dataFailed allocating memory for channel type nameUnable to allocate temporary space for packetWould block sending channel-open requestUnable to send channel-open requestWould blockUnexpected errorUnexpected packet sizeChannel open failure (administratively prohibited)Channel open failure (connect failed)Channel open failure (unknown channel type)Channel open failure (resource shortage)Channel open failureUnable to allocate memory for setenv packetcancel-tcpip-forwardWould block sending forward requestUnable to send global-request packet for forward listen requestauth-agent-req@openssh.comauth-agent-reqcdChannel can not be reusedUnable to allocate memory for channel-process requestWould block sending channel requestUnable to send channel requestFailed waiting for channel successUnable to complete request for channel-process-startupUnexpected packet lengthUnable to allocate memory for signal nameWould block sending window adjustUnable to send transfer-window adjustment packet, deferringtransport readwould blockWe have already closed this channelEOF has already been received, data might be ignoredFailure while draining incoming flowUnable to send channel dataUnable to send EOF, but closing channel anywayWould block sending close-channelUnable to send close-channel request, but closing anywaysessionchannel.cUnable to allocate memory for direct-tcpip connectiondirect-tcpipUnable to allocate memory for direct-streamlocal connectiondirect-streamlocal@openssh.comQR0.0.0.0tcpip-forwardWould block sending global-request packet for forward listen requestUnknownUnable to allocate memory for listener queueUnable to complete request for forward-listenWould block waiting for packetChannel not foundcdenvWould block sending setenv requestUnable to send channel-request packet for setenv requestFailed getting response for channel-setenvUnable to complete request for channel-setenvcdWould block sending auth-agent requestUnable to send auth-agent requestFailed to request auth-agentUnable to complete request for auth-agentcdterm + mode lengths too largepty-reqWould block sending pty requestUnable to send pty-request packetFailed to require the PTY packageUnable to complete request for channel request-ptywindow-changeWould block sending window-change requestUnable to send window-change packetcdUnable to allocate memory for pty-requestx11-reqMIT-MAGIC-COOKIE-1Unable to get random bytes for x11-req cookie%02XW |