Score: | 100 |
Range: | 0 - 100 |
Confidence: | 100% |
Name | Description | Attribution | Blogpost URLs | Link |
---|---|---|---|---|
DarkTortilla | DarkTortilla is a complex and highly configurable .NET-based crypter that has possibly been active since at least August 2015. It typically delivers popular information stealers and remote access trojans (RATs) such as AgentTesla, AsyncRat, NanoCore, and RedLine. While it appears to primarily deliver commodity malware, Secureworks Counter Threat Unit (CTU) researchers identified DarkTortilla samples delivering targeted payloads such as Cobalt Strike and Metasploit. It can also deliver "addon packages" such as additional malicious payloads, benign decoy documents, and executables. It features robust anti-analysis and anti-tamper controls that can make detection, analysis, and eradication challenging.From January 2021 through May 2022, an average of 93 unique DarkTortilla samples per week were uploaded to the VirusTotal analysis service. Code similarities suggest possible links between DarkTortilla and other malware: a crypter operated by the RATs Crew threat group, which was active between 2008 and 2012, and the Gameloader malware that emerged in 2021. | No Attribution |
|
AV Detection |
|
---|
Source: |
Avira: |
||
Source: |
Avira: |
Source: |
ReversingLabs: |
||
Source: |
ReversingLabs: |
Source: |
Virustotal: |
Perma Link | ||
Source: |
ReversingLabs: |
Source: |
Neural Call Log Analysis: |
Source: |
Code function: |
0_2_01C1A7CB | |
Source: |
Code function: |
0_2_01C1A7DE | |
Source: |
Code function: |
0_2_01C1A7F1 | |
Source: |
Code function: |
0_2_01C1A789 | |
Source: |
Code function: |
0_2_01C1A75A | |
Source: |
Code function: |
0_2_01C1A700 | |
Source: |
Code function: |
0_2_01C1A713 | |
Source: |
Code function: |
0_2_01C1A726 | |
Source: |
Code function: |
0_2_01C1A739 | |
Source: |
Code function: |
0_2_01C1A6C7 | |
Source: |
Code function: |
0_2_01C1A6DA | |
Source: |
Code function: |
0_2_01C1A6ED | |
Source: |
Code function: |
0_2_01C1A84B | |
Source: |
Code function: |
0_2_01C1A859 | |
Source: |
Code function: |
0_2_01C1A804 | |
Source: |
Code function: |
0_2_01C1A817 | |
Source: |
Code function: |
0_2_01C1A82A | |
Source: |
Code function: |
0_2_01C1A838 | |
Source: |
Code function: |
0_2_01C077CC | |
Source: |
Code function: |
0_2_01C077F0 | |
Source: |
Code function: |
0_2_01C077A2 | |
Source: |
Code function: |
0_2_01C07754 | |
Source: |
Code function: |
0_2_01C0777B | |
Source: |
Code function: |
0_2_01C079C7 | |
Source: |
Code function: |
0_2_01C079EE | |
Source: |
Code function: |
0_2_01C07985 | |
Source: |
Code function: |
0_2_01C079A6 | |
Source: |
Code function: |
0_2_01C07958 | |
Source: |
Code function: |
0_2_01C078D6 | |
Source: |
Code function: |
0_2_01C07847 | |
Source: |
Code function: |
0_2_01C0787F | |
Source: |
Code function: |
0_2_01C0781D | |
Source: |
Code function: |
0_2_01C07AB3 | |
Source: |
Code function: |
0_2_01C07A50 | |
Source: |
Code function: |
0_2_01C07A61 | |
Source: |
Code function: |
0_2_01C07A7A | |
Source: |
Code function: |
0_2_01C07A12 | |
Source: |
Code function: |
0_2_01C07A2F | |
Source: |
Code function: |
7_2_0187A789 | |
Source: |
Code function: |
7_2_018677A2 | |
Source: |
Code function: |
7_2_018677CC | |
Source: |
Code function: |
7_2_0187A7CB | |
Source: |
Code function: |
7_2_0187A7DE | |
Source: |
Code function: |
7_2_018677F0 | |
Source: |
Code function: |
7_2_0187A7F1 | |
Source: |
Code function: |
7_2_0187A700 | |
Source: |
Code function: |
7_2_0187A713 | |
Source: |
Code function: |
7_2_0187A726 | |
Source: |
Code function: |
7_2_0187A739 | |
Source: |
Code function: |
7_2_01867754 | |
Source: |
Code function: |
7_2_0187A75A | |
Source: |
Code function: |
7_2_0186777B | |
Source: |
Code function: |
7_2_0187A6C7 | |
Source: |
Code function: |
7_2_0187A6DA | |
Source: |
Code function: |
7_2_0187A6ED | |
Source: |
Code function: |
7_2_01867985 | |
Source: |
Code function: |
7_2_018679A6 | |
Source: |
Code function: |
7_2_018679C7 | |
Source: |
Code function: |
7_2_018679EE | |
Source: |
Code function: |
7_2_01867958 | |
Source: |
Code function: |
7_2_018678D6 | |
Source: |
Code function: |
7_2_0187A804 | |
Source: |
Code function: |
7_2_0187A817 | |
Source: |
Code function: |
7_2_0186781D | |
Source: |
Code function: |
7_2_0187A82A | |
Source: |
Code function: |
7_2_0187A838 | |
Source: |
Code function: |
7_2_01867847 | |
Source: |
Code function: |
7_2_0187A84B | |
Source: |
Code function: |
7_2_0187A859 | |
Source: |
Code function: |
7_2_0186787F | |
Source: |
Code function: |
7_2_01867AB3 | |
Source: |
Code function: |
7_2_01867A12 | |
Source: |
Code function: |
7_2_01867A2F | |
Source: |
Code function: |
7_2_01867A50 | |
Source: |
Code function: |
7_2_01867A61 | |
Source: |
Code function: |
7_2_01867A7A |
Source: |
Static PE information: |
Source: |
Static PE information: |
Source: |
Binary string: |
||
Source: |
Binary string: |
||
Source: |
Binary string: |
||
Source: |
Binary string: |
||
Source: |
Binary string: |
||
Source: |
Binary string: |
||
Source: |
Binary string: |
Source: |
Key opened: |
Jump to behavior | ||
Source: |
Key opened: |
Jump to behavior | ||
Source: |
Key opened: |
Jump to behavior | ||
Source: |
Key opened: |
Jump to behavior | ||
Source: |
Key opened: |
Jump to behavior | ||
Source: |
Key opened: |
Jump to behavior | ||
Source: |
Key opened: |
Jump to behavior | ||
Source: |
Key opened: |
Jump to behavior | ||
Source: |
Key opened: |
Jump to behavior | ||
Source: |
Key opened: |
Jump to behavior | ||
Source: |
Key opened: |
Jump to behavior | ||
Source: |
Key opened: |
Jump to behavior | ||
Source: |
Key opened: |
Jump to behavior | ||
Source: |
Key opened: |
Jump to behavior | ||
Source: |
Key opened: |
Jump to behavior | ||
Source: |
Key opened: |
Jump to behavior |
Source: |
Code function: |
4_2_0075611F | |
Source: |
Code function: |
15_2_0075611F |
Networking |
|
---|
Source: |
Network Connect: |
Jump to behavior | ||
Source: |
Network Connect: |
Jump to behavior | ||
Source: |
Network Connect: |
Jump to behavior |
Source: |
IP Address: |
||
Source: |
IP Address: |
||
Source: |
IP Address: |
||
Source: |
IP Address: |
||
Source: |
IP Address: |
Source: |
ASN Name: |
||
Source: |
ASN Name: |
||
Source: |
ASN Name: |
Source: |
TCP traffic detected without corresponding DNS query: |
||
Source: |
TCP traffic detected without corresponding DNS query: |
||
Source: |
TCP traffic detected without corresponding DNS query: |
||
Source: |
TCP traffic detected without corresponding DNS query: |
||
Source: |
TCP traffic detected without corresponding DNS query: |
||
Source: |
TCP traffic detected without corresponding DNS query: |
||
Source: |
TCP traffic detected without corresponding DNS query: |
||
Source: |
TCP traffic detected without corresponding DNS query: |
||
Source: |
TCP traffic detected without corresponding DNS query: |
||
Source: |
TCP traffic detected without corresponding DNS query: |
||
Source: |
TCP traffic detected without corresponding DNS query: |
||
Source: |
TCP traffic detected without corresponding DNS query: |
||
Source: |
TCP traffic detected without corresponding DNS query: |
||
Source: |
TCP traffic detected without corresponding DNS query: |
||
Source: |
TCP traffic detected without corresponding DNS query: |
||
Source: |
TCP traffic detected without corresponding DNS query: |
||
Source: |
TCP traffic detected without corresponding DNS query: |
||
Source: |
TCP traffic detected without corresponding DNS query: |
||
Source: |
TCP traffic detected without corresponding DNS query: |
||
Source: |
TCP traffic detected without corresponding DNS query: |
||
Source: |
TCP traffic detected without corresponding DNS query: |
||
Source: |
TCP traffic detected without corresponding DNS query: |
||
Source: |
TCP traffic detected without corresponding DNS query: |
||
Source: |
TCP traffic detected without corresponding DNS query: |
||
Source: |
TCP traffic detected without corresponding DNS query: |
||
Source: |
TCP traffic detected without corresponding DNS query: |
||
Source: |
TCP traffic detected without corresponding DNS query: |
||
Source: |
TCP traffic detected without corresponding DNS query: |
||
Source: |
TCP traffic detected without corresponding DNS query: |
||
Source: |
TCP traffic detected without corresponding DNS query: |
||
Source: |
TCP traffic detected without corresponding DNS query: |
||
Source: |
TCP traffic detected without corresponding DNS query: |
||
Source: |
TCP traffic detected without corresponding DNS query: |
||
Source: |
TCP traffic detected without corresponding DNS query: |
||
Source: |
TCP traffic detected without corresponding DNS query: |
||
Source: |
TCP traffic detected without corresponding DNS query: |
||
Source: |
TCP traffic detected without corresponding DNS query: |
||
Source: |
TCP traffic detected without corresponding DNS query: |
||
Source: |
TCP traffic detected without corresponding DNS query: |
||
Source: |
TCP traffic detected without corresponding DNS query: |
||
Source: |
TCP traffic detected without corresponding DNS query: |
||
Source: |
TCP traffic detected without corresponding DNS query: |
||
Source: |
TCP traffic detected without corresponding DNS query: |
||
Source: |
TCP traffic detected without corresponding DNS query: |
||
Source: |
TCP traffic detected without corresponding DNS query: |
||
Source: |
TCP traffic detected without corresponding DNS query: |
||
Source: |
TCP traffic detected without corresponding DNS query: |
||
Source: |
TCP traffic detected without corresponding DNS query: |
||
Source: |
TCP traffic detected without corresponding DNS query: |
||
Source: |
TCP traffic detected without corresponding DNS query: |
Source: |
HTTP traffic detected: |
||
Source: |
HTTP traffic detected: |
Source: |
DNS traffic detected: |
||
Source: |
DNS traffic detected: |
Source: |
HTTP traffic detected: |
Source: |
String found in binary or memory: |
||
Source: |
String found in binary or memory: |
||
Source: |
String found in binary or memory: |
||
Source: |
String found in binary or memory: |
||
Source: |
String found in binary or memory: |
||
Source: |
String found in binary or memory: |
||
Source: |
String found in binary or memory: |
||
Source: |
String found in binary or memory: |
||
Source: |
String found in binary or memory: |
||
Source: |
String found in binary or memory: |
||
Source: |
String found in binary or memory: |
||
Source: |
String found in binary or memory: |
||
Source: |
String found in binary or memory: |
||
Source: |
String found in binary or memory: |
||
Source: |
String found in binary or memory: |
||
Source: |
String found in binary or memory: |
||
Source: |
String found in binary or memory: |
||
Source: |
String found in binary or memory: |
||
Source: |
String found in binary or memory: |
||
Source: |
String found in binary or memory: |
||
Source: |
String found in binary or memory: |
||
Source: |
String found in binary or memory: |
||
Source: |
String found in binary or memory: |
||
Source: |
String found in binary or memory: |
||
Source: |
String found in binary or memory: |
||
Source: |
String found in binary or memory: |
||
Source: |
String found in binary or memory: |
||
Source: |
String found in binary or memory: |
||
Source: |
String found in binary or memory: |
||
Source: |
String found in binary or memory: |
||
Source: |
String found in binary or memory: |
||
Source: |
String found in binary or memory: |
||
Source: |
String found in binary or memory: |
||
Source: |
String found in binary or memory: |
||
Source: |
String found in binary or memory: |
||
Source: |
String found in binary or memory: |
||
Source: |
String found in binary or memory: |
||
Source: |
String found in binary or memory: |
||
Source: |
String found in binary or memory: |
||
Source: |
String found in binary or memory: |
||
Source: |
String found in binary or memory: |
||
Source: |
String found in binary or memory: |
||
Source: |
String found in binary or memory: |
||
Source: |
String found in binary or memory: |
||
Source: |
String found in binary or memory: |
||
Source: |
String found in binary or memory: |
||
Source: |
String found in binary or memory: |
||
Source: |
String found in binary or memory: |
||
Source: |
String found in binary or memory: |
||
Source: |
String found in binary or memory: |
||
Source: |
String found in binary or memory: |
||
Source: |
String found in binary or memory: |
||
Source: |
String found in binary or memory: |
||
Source: |
String found in binary or memory: |
||
Source: |
String found in binary or memory: |
||
Source: |
String found in binary or memory: |
||
Source: |
String found in binary or memory: |
||
Source: |
String found in binary or memory: |
||
Source: |
String found in binary or memory: |
||
Source: |
String found in binary or memory: |
||
Source: |
String found in binary or memory: |
||
Source: |
String found in binary or memory: |
||
Source: |
String found in binary or memory: |
||
Source: |
String found in binary or memory: |
||
Source: |
String found in binary or memory: |
||
Source: |
String found in binary or memory: |
||
Source: |
String found in binary or memory: |
||
Source: |
String found in binary or memory: |
||
Source: |
String found in binary or memory: |
||
Source: |
String found in binary or memory: |
||
Source: |
String found in binary or memory: |
||
Source: |
String found in binary or memory: |
||
Source: |
String found in binary or memory: |
||
Source: |
String found in binary or memory: |
||
Source: |
String found in binary or memory: |
Source: |
Network traffic detected: |
||
Source: |
Network traffic detected: |
||
Source: |
Network traffic detected: |
||
Source: |
Network traffic detected: |
||
Source: |
Network traffic detected: |
||
Source: |
Network traffic detected: |
||
Source: |
Network traffic detected: |
||
Source: |
Network traffic detected: |
||
Source: |
Network traffic detected: |
||
Source: |
Network traffic detected: |
||
Source: |
Network traffic detected: |
||
Source: |
Network traffic detected: |
||
Source: |
Network traffic detected: |
||
Source: |
Network traffic detected: |
||
Source: |
Network traffic detected: |
||
Source: |
Network traffic detected: |
||
Source: |
Network traffic detected: |
||
Source: |
Network traffic detected: |
||
Source: |
Network traffic detected: |
||
Source: |
Network traffic detected: |
||
Source: |
Network traffic detected: |
||
Source: |
Network traffic detected: |
||
Source: |
Network traffic detected: |
||
Source: |
Network traffic detected: |
||
Source: |
Network traffic detected: |
||
Source: |
Network traffic detected: |
||
Source: |
Network traffic detected: |
||
Source: |
Network traffic detected: |
Source: |
Code function: |
0_2_0086DF2B | |
Source: |
Code function: |
4_2_007428F0 | |
Source: |
Code function: |
4_2_00742530 | |
Source: |
Code function: |
15_2_007428F0 | |
Source: |
Code function: |
15_2_00742530 |
Source: |
Code function: |
4_2_0075016D |
Source: |
Code function: |
0_2_01C38B22 |
Source: |
Code function: |
0_2_01C060FF | |
Source: |
Code function: |
0_2_01C02049 | |
Source: |
Code function: |
0_2_01C0433D | |
Source: |
Code function: |
0_2_01C06273 | |
Source: |
Code function: |
0_2_01C20202 | |
Source: |
Code function: |
0_2_01BF227D | |
Source: |
Code function: |
0_2_01C2422F | |
Source: |
Code function: |
0_2_01C24525 | |
Source: |
Code function: |
0_2_01BFE499 | |
Source: |
Code function: |
0_2_01C06479 | |
Source: |
Code function: |
0_2_01C0674B | |
Source: |
Code function: |
0_2_01C0A750 | |
Source: |
Code function: |
0_2_01C24984 | |
Source: |
Code function: |
0_2_01C06968 | |
Source: |
Code function: |
0_2_01C1A97F | |
Source: |
Code function: |
0_2_01C0A8DF | |
Source: |
Code function: |
0_2_01C04AD5 | |
Source: |
Code function: |
0_2_01BF6A18 | |
Source: |
Code function: |
0_2_01C12A12 | |
Source: |
Code function: |
0_2_01C10DF6 | |
Source: |
Code function: |
0_2_01BF2DCB | |
Source: |
Code function: |
0_2_01C00D58 | |
Source: |
Code function: |
0_2_01C14D17 | |
Source: |
Code function: |
0_2_01C04EC8 | |
Source: |
Code function: |
0_2_01BFCE6A | |
Source: |
Code function: |
0_2_01C131F9 | |
Source: |
Code function: |
0_2_01C09177 | |
Source: |
Code function: |
0_2_01C09100 | |
Source: |
Code function: |
0_2_01C050AA | |
Source: |
Code function: |
0_2_01C09072 | |
Source: |
Code function: |
0_2_01C01265 | |
Source: |
Code function: |
0_2_01C09277 | |
Source: |
Code function: |
0_2_01C135E5 | |
Source: |
Code function: |
0_2_01C23552 | |
Source: |
Code function: |
0_2_01C0144E | |
Source: |
Code function: |
0_2_01C2376D | |
Source: |
Code function: |
0_2_01C236C2 | |
Source: |
Code function: |
0_2_01BF3680 | |
Source: |
Code function: |
0_2_01C2360C | |
Source: |
Code function: |
0_2_01C0198F | |
Source: |
Code function: |
0_2_01C15814 | |
Source: |
Code function: |
0_2_01C23818 | |
Source: |
Code function: |
0_2_01C13830 | |
Source: |
Code function: |
0_2_01C05B91 | |
Source: |
Code function: |
0_2_01C23BBF | |
Source: |
Code function: |
0_2_01C05AA6 | |
Source: |
Code function: |
0_2_01C23D86 | |
Source: |
Code function: |
0_2_01C1FD8F | |
Source: |
Code function: |
0_2_01C05CCB | |
Source: |
Code function: |
0_2_01C05F85 | |
Source: |
Code function: |
0_2_01C6DF8A | |
Source: |
Code function: |
0_2_01C23F47 | |
Source: |
Code function: |
0_2_01C0DF25 | |
Source: |
Code function: |
0_2_01C05E00 | |
Source: |
Code function: |
2_2_021B0950 | |
Source: |
Code function: |
2_2_021B6D60 | |
Source: |
Code function: |
2_2_021B2DE8 | |
Source: |
Code function: |
2_2_021B33D0 | |
Source: |
Code function: |
2_2_021B0941 | |
Source: |
Code function: |
2_2_021B6D52 | |
Source: |
Code function: |
2_2_0B001240 | |
Source: |
Code function: |
2_2_0B002FD8 | |
Source: |
Code function: |
4_2_00743CA0 | |
Source: |
Code function: |
4_2_0074D05A | |
Source: |
Code function: |
4_2_00758B3B | |
Source: |
Code function: |
4_2_0074D3B9 | |
Source: |
Code function: |
4_2_0075D531 | |
Source: |
Code function: |
4_2_0074CD18 | |
Source: |
Code function: |
4_2_00758690 | |
Source: |
Code function: |
4_2_0074D717 | |
Source: |
Code function: |
7_2_01869100 | |
Source: |
Code function: |
7_2_01869177 | |
Source: |
Code function: |
7_2_018650AA | |
Source: |
Code function: |
7_2_018660FF | |
Source: |
Code function: |
7_2_0185E000 | |
Source: |
Code function: |
7_2_01862049 | |
Source: |
Code function: |
7_2_01869072 | |
Source: |
Code function: |
7_2_0186433D | |
Source: |
Code function: |
7_2_01880202 | |
Source: |
Code function: |
7_2_0188422F | |
Source: |
Code function: |
7_2_01861265 | |
Source: |
Code function: |
7_2_01869277 | |
Source: |
Code function: |
7_2_01866273 | |
Source: |
Code function: |
7_2_0185227D | |
Source: |
Code function: |
7_2_01884525 | |
Source: |
Code function: |
7_2_0185E499 | |
Source: |
Code function: |
7_2_0186144E | |
Source: |
Code function: |
7_2_01866479 | |
Source: |
Code function: |
7_2_0186674B | |
Source: |
Code function: |
7_2_01853680 | |
Source: |
Code function: |
7_2_0186198F | |
Source: |
Code function: |
7_2_01884984 | |
Source: |
Code function: |
7_2_01866968 | |
Source: |
Code function: |
7_2_0187A97F | |
Source: |
Code function: |
7_2_01865B91 | |
Source: |
Code function: |
7_2_01865AA6 | |
Source: |
Code function: |
7_2_01864AD5 | |
Source: |
Code function: |
7_2_01872A12 | |
Source: |
Code function: |
7_2_0187FD8F | |
Source: |
Code function: |
7_2_01852DCB | |
Source: |
Code function: |
7_2_01860D58 | |
Source: |
Code function: |
7_2_01865CCB | |
Source: |
Code function: |
7_2_01865F85 | |
Source: |
Code function: |
7_2_018CDF8A | |
Source: |
Code function: |
7_2_01864EC8 | |
Source: |
Code function: |
7_2_01865E00 | |
Source: |
Code function: |
14_2_01950950 | |
Source: |
Code function: |
14_2_01952DE8 | |
Source: |
Code function: |
14_2_01956D60 | |
Source: |
Code function: |
14_2_019533D0 | |
Source: |
Code function: |
14_2_01950941 | |
Source: |
Code function: |
14_2_01956D53 | |
Source: |
Code function: |
14_2_083010A8 | |
Source: |
Code function: |
14_2_083078F0 | |
Source: |
Code function: |
14_2_08300208 | |
Source: |
Code function: |
14_2_0830CA48 | |
Source: |
Code function: |
14_2_08309B60 | |
Source: |
Code function: |
14_2_0830EB58 | |
Source: |
Code function: |
14_2_0830F380 | |
Source: |
Code function: |
14_2_08301BC0 | |
Source: |
Code function: |
14_2_083045C0 | |
Source: |
Code function: |
14_2_0830F688 | |
Source: |
Code function: |
14_2_0830D7F0 | |
Source: |
Code function: |
14_2_08300012 | |
Source: |
Code function: |
14_2_0830B850 | |
Source: |
Code function: |
14_2_083038B2 | |
Source: |
Code function: |
14_2_08301081 | |
Source: |
Code function: |
14_2_083088F8 | |
Source: |
Code function: |
14_2_083078DF | |
Source: |
Code function: |
14_2_083038C0 | |
Source: |
Code function: |
14_2_083050CC | |
Source: |
Code function: |
14_2_08308908 | |
Source: |
Code function: |
14_2_08305170 | |
Source: |
Code function: |
14_2_0830D1B0 | |
Source: |
Code function: |
14_2_083041A0 | |
Source: |
Code function: |
14_2_08304192 | |
Source: |
Code function: |
14_2_083001F9 | |
Source: |
Code function: |
14_2_08309B51 | |
Source: |
Code function: |
14_2_08303BB0 | |
Source: |
Code function: |
14_2_08303BC0 | |
Source: |
Code function: |
14_2_08304418 | |
Source: |
Code function: |
14_2_0830440A | |
Source: |
Code function: |
14_2_08304572 | |
Source: |
Code function: |
14_2_08302DE0 | |
Source: |
Code function: |
14_2_08302DD0 | |
Source: |
Code function: |
14_2_08303F68 | |
Source: |
Code function: |
14_2_08303F5A | |
Source: |
Code function: |
14_2_08340006 | |
Source: |
Code function: |
14_2_08340040 | |
Source: |
Code function: |
14_2_08343200 | |
Source: |
Code function: |
15_2_00743CA0 | |
Source: |
Code function: |
15_2_0074D05A | |
Source: |
Code function: |
15_2_00758B3B | |
Source: |
Code function: |
15_2_0074D3B9 | |
Source: |
Code function: |
15_2_0075D531 | |
Source: |
Code function: |
15_2_0074CD18 | |
Source: |
Code function: |
15_2_00758690 | |
Source: |
Code function: |
15_2_0074D717 |
Source: |
Dropped File: |
||
Source: |
Dropped File: |
||
Source: |
Dropped File: |
Source: |
Static PE information: |
Source: |
Static PE information: |
Source: |
Static PE information: |
Source: |
Binary or memory string: |
||
Source: |
Binary or memory string: |
||
Source: |
Binary or memory string: |
||
Source: |
Binary or memory string: |
||
Source: |
Binary or memory string: |
||
Source: |
Binary or memory string: |
||
Source: |
Binary or memory string: |
||
Source: |
Binary or memory string: |
||
Source: |
Binary or memory string: |
||
Source: |
Binary or memory string: |
||
Source: |
Binary or memory string: |
||
Source: |
Binary or memory string: |
||
Source: |
Binary or memory string: |
Source: |
Static PE information: |
Source: |
Cryptographic APIs: |
||
Source: |
Cryptographic APIs: |
||
Source: |
Cryptographic APIs: |
||
Source: |
Cryptographic APIs: |
Source: |
Classification label: |
Source: |
Code function: |
0_2_01C1A626 | |
Source: |
Code function: |
0_2_01C07642 | |
Source: |
Code function: |
7_2_0187A626 | |
Source: |
Code function: |
7_2_01867642 |
Source: |
Code function: |
4_2_00744E70 | |
Source: |
Code function: |
15_2_00744E70 |
Source: |
Code function: |
4_2_00743CA0 |
Source: |
File created: |
Jump to behavior |
Source: |
Mutant created: |
||
Source: |
Mutant created: |
||
Source: |
Mutant created: |
Source: |
File created: |
Jump to behavior |
Source: |
Key opened: |
Jump to behavior | ||
Source: |
Key opened: |
Jump to behavior | ||
Source: |
Key opened: |
Jump to behavior | ||
Source: |
Key opened: |
Jump to behavior |
Source: |
Key opened: |
Jump to behavior |
Source: |
Virustotal: |
||
Source: |
ReversingLabs: |
Source: |
String found in binary or memory: |
||
Source: |
String found in binary or memory: |
||
Source: |
String found in binary or memory: |
||
Source: |
String found in binary or memory: |
||
Source: |
String found in binary or memory: |
||
Source: |
String found in binary or memory: |
||
Source: |
String found in binary or memory: |
||
Source: |
String found in binary or memory: |
||
Source: |
String found in binary or memory: |
||
Source: |
String found in binary or memory: |
Source: |
File read: |
Jump to behavior |
Source: |
Process created: |
|||
Source: |
Process created: |
|||
Source: |
Process created: |
|||
Source: |
Process created: |
|||
Source: |
Process created: |
|||
Source: |
Process created: |
|||
Source: |
Process created: |
|||
Source: |
Process created: |
|||
Source: |
Process created: |
|||
Source: |
Process created: |
|||
Source: |
Process created: |
Jump to behavior | ||
Source: |
Process created: |
Jump to behavior | ||
Source: |
Process created: |
Jump to behavior | ||
Source: |
Process created: |
Jump to behavior | ||
Source: |
Process created: |
Jump to behavior | ||
Source: |
Process created: |
Jump to behavior |
Source: |
Section loaded: |
Jump to behavior | ||
Source: |
Section loaded: |
Jump to behavior | ||
Source: |
Section loaded: |
Jump to behavior | ||
Source: |
Section loaded: |
Jump to behavior | ||
Source: |
Section loaded: |
Jump to behavior | ||
Source: |
Section loaded: |
Jump to behavior | ||
Source: |
Section loaded: |
Jump to behavior | ||
Source: |
Section loaded: |
Jump to behavior | ||
Source: |
Section loaded: |
Jump to behavior | ||
Source: |
Section loaded: |
Jump to behavior | ||
Source: |
Section loaded: |
Jump to behavior | ||
Source: |
Section loaded: |
Jump to behavior | ||
Source: |
Section loaded: |
Jump to behavior | ||
Source: |
Section loaded: |
Jump to behavior | ||
Source: |
Section loaded: |
Jump to behavior | ||
Source: |
Section loaded: |
Jump to behavior | ||
Source: |
Section loaded: |
Jump to behavior | ||
Source: |
Section loaded: |
Jump to behavior | ||
Source: |
Section loaded: |
Jump to behavior | ||
Source: |
Section loaded: |
Jump to behavior | ||
Source: |
Section loaded: |
Jump to behavior | ||
Source: |
Section loaded: |
Jump to behavior | ||
Source: |
Section loaded: |
Jump to behavior | ||
Source: |
Section loaded: |
Jump to behavior | ||
Source: |
Section loaded: |
Jump to behavior | ||
Source: |
Section loaded: |
Jump to behavior | ||
Source: |
Section loaded: |
Jump to behavior | ||
Source: |
Section loaded: |
Jump to behavior | ||
Source: |
Section loaded: |
Jump to behavior | ||
Source: |
Section loaded: |
Jump to behavior | ||
Source: |
Section loaded: |
Jump to behavior | ||
Source: |
Section loaded: |
Jump to behavior | ||
Source: |
Section loaded: |
Jump to behavior | ||
Source: |
Section loaded: |
Jump to behavior | ||
Source: |
Section loaded: |
Jump to behavior | ||
Source: |
Section loaded: |
Jump to behavior | ||
Source: |
Section loaded: |
Jump to behavior | ||
Source: |
Section loaded: |
Jump to behavior | ||
Source: |
Section loaded: |
Jump to behavior | ||
Source: |
Section loaded: |
Jump to behavior | ||
Source: |
Section loaded: |
Jump to behavior | ||
Source: |
Section loaded: |
Jump to behavior | ||
Source: |
Section loaded: |
Jump to behavior | ||
Source: |
Section loaded: |
Jump to behavior | ||
Source: |
Section loaded: |
Jump to behavior | ||
Source: |
Section loaded: |
Jump to behavior | ||
Source: |
Section loaded: |
Jump to behavior | ||
Source: |
Section loaded: |
Jump to behavior | ||
Source: |
Section loaded: |
Jump to behavior | ||
Source: |
Section loaded: |
Jump to behavior | ||
Source: |
Section loaded: |
Jump to behavior | ||
Source: |
Section loaded: |
Jump to behavior | ||
Source: |
Section loaded: |
Jump to behavior | ||
Source: |
Section loaded: |
Jump to behavior | ||
Source: |
Section loaded: |
Jump to behavior | ||
Source: |
Section loaded: |
Jump to behavior | ||
Source: |
Section loaded: |
Jump to behavior | ||
Source: |
Section loaded: |
Jump to behavior | ||
Source: |
Section loaded: |
Jump to behavior | ||
Source: |
Section loaded: |
Jump to behavior | ||
Source: |
Section loaded: |
Jump to behavior | ||
Source: |
Section loaded: |
Jump to behavior | ||
Source: |
Section loaded: |
Jump to behavior | ||
Source: |
Section loaded: |
Jump to behavior | ||
Source: |
Section loaded: |
Jump to behavior | ||
Source: |
Section loaded: |
Jump to behavior | ||
Source: |
Section loaded: |
Jump to behavior | ||
Source: |
Section loaded: |
Jump to behavior | ||
Source: |
Section loaded: |
Jump to behavior | ||
Source: |
Section loaded: |
Jump to behavior | ||
Source: |
Section loaded: |
Jump to behavior | ||
Source: |
Section loaded: |
Jump to behavior | ||
Source: |
Section loaded: |
Jump to behavior | ||
Source: |
Section loaded: |
Jump to behavior | ||
Source: |
Section loaded: |
Jump to behavior | ||
Source: |
Section loaded: |
Jump to behavior | ||
Source: |
Section loaded: |
Jump to behavior | ||
Source: |
Section loaded: |
Jump to behavior | ||
Source: |
Section loaded: |
Jump to behavior | ||
Source: |
Section loaded: |
Jump to behavior | ||
Source: |
Section loaded: |
Jump to behavior | ||
Source: |
Section loaded: |
Jump to behavior | ||
Source: |
Section loaded: |
Jump to behavior | ||
Source: |
Section loaded: |
Jump to behavior | ||
Source: |
Section loaded: |
Jump to behavior | ||
Source: |
Section loaded: |
Jump to behavior | ||
Source: |
Section loaded: |
Jump to behavior | ||
Source: |
Section loaded: |
Jump to behavior | ||
Source: |
Section loaded: |
Jump to behavior | ||
Source: |
Section loaded: |
Jump to behavior | ||
Source: |
Section loaded: |
Jump to behavior | ||
Source: |
Section loaded: |
Jump to behavior | ||
Source: |
Section loaded: |
Jump to behavior | ||
Source: |
Section loaded: |
Jump to behavior | ||
Source: |
Section loaded: |
Jump to behavior | ||
Source: |
Section loaded: |
Jump to behavior | ||
Source: |
Section loaded: |
Jump to behavior | ||
Source: |
Section loaded: |
Jump to behavior | ||
Source: |
Section loaded: |
Jump to behavior | ||
Source: |
Section loaded: |
Jump to behavior | ||
Source: |
Section loaded: |
Jump to behavior | ||
Source: |
Section loaded: |
Jump to behavior | ||
Source: |
Section loaded: |
Jump to behavior | ||
Source: |
Section loaded: |
Jump to behavior | ||
Source: |
Section loaded: |
Jump to behavior |
Source: |
Key value queried: |
Jump to behavior |
Source: |
Window detected: |
Source: |
File opened: |
Jump to behavior |
Source: |
Static PE information: |
Source: |
Static file information: |
Source: |
Static PE information: |
||
Source: |
Static PE information: |
Source: |
Static PE information: |
Source: |
Binary string: |
||
Source: |
Binary string: |
||
Source: |
Binary string: |
||
Source: |
Binary string: |
||
Source: |
Binary string: |
||
Source: |
Binary string: |
||
Source: |
Binary string: |
Data Obfuscation |
|
---|
Source: |
File source: |
||
Source: |
File source: |
||
Source: |
File source: |
||
Source: |
File source: |
||
Source: |
File source: |
||
Source: |
File source: |
||
Source: |
File source: |
||
Source: |
File source: |
||
Source: |
File source: |
||
Source: |
File source: |
||
Source: |
File source: |
||
Source: |
File source: |
||
Source: |
File source: |
||
Source: |
File source: |
||
Source: |
File source: |
Source: |
.Net Code: |
||
Source: |
.Net Code: |
Source: |
Code function: |
0_2_01C1A867 |
Source: |
Static PE information: |
Source: |
Code function: |
0_2_01C8244D | |
Source: |
Code function: |
0_2_01C7AB5C | |
Source: |
Code function: |
0_2_01C7AB5C | |
Source: |
Code function: |
0_2_01C7AB5C | |
Source: |
Code function: |
0_2_01C83828 | |
Source: |
Code function: |
0_2_0087244A | |
Source: |
Code function: |
2_2_0B002486 | |
Source: |
Code function: |
4_2_0075DC94 | |
Source: |
Code function: |
15_2_0075DC94 |
Source: |
High entropy of concatenated method names: |
||
Source: |
High entropy of concatenated method names: |
||
Source: |
High entropy of concatenated method names: |
||
Source: |
High entropy of concatenated method names: |
||
Source: |
High entropy of concatenated method names: |
||
Source: |
High entropy of concatenated method names: |
||
Source: |
High entropy of concatenated method names: |
||
Source: |
High entropy of concatenated method names: |
||
Source: |
High entropy of concatenated method names: |
||
Source: |
High entropy of concatenated method names: |
||
Source: |
High entropy of concatenated method names: |
||
Source: |
High entropy of concatenated method names: |
Source: |
File created: |
Jump to dropped file | ||
Source: |
File created: |
Jump to dropped file | ||
Source: |
File created: |
Jump to dropped file |
Source: |
File created: |
Jump to dropped file |
Source: |
File created: |
Jump to dropped file | ||
Source: |
File created: |
Jump to dropped file |
Hooking and other Techniques for Hiding and Protection |
|
---|
Source: |
Module Loaded: |
||
Source: |
Module Loaded: |
Source: |
File opened: |
Jump to behavior | ||
Source: |
File opened: |
Jump to behavior |
Source: |
Code function: |
0_2_01C07270 |
Source: |
Process information set: |
Jump to behavior | ||
Source: |
Process information set: |
Jump to behavior | ||
Source: |
Process information set: |
Jump to behavior | ||
Source: |
Process information set: |
Jump to behavior | ||
Source: |
Process information set: |
Jump to behavior | ||
Source: |
Process information set: |
Jump to behavior | ||
Source: |
Process information set: |
Jump to behavior | ||
Source: |
Process information set: |
Jump to behavior | ||
Source: |
Process information set: |
Jump to behavior | ||
Source: |
Process information set: |
Jump to behavior | ||
Source: |
Process information set: |
Jump to behavior | ||
Source: |
Process information set: |
Jump to behavior | ||
Source: |
Process information set: |
Jump to behavior | ||
Source: |
Process information set: |
Jump to behavior | ||
Source: |
Process information set: |
Jump to behavior | ||
Source: |
Process information set: |
Jump to behavior | ||
Source: |
Process information set: |
Jump to behavior | ||
Source: |
Process information set: |
Jump to behavior | ||
Source: |
Process information set: |
Jump to behavior | ||
Source: |
Process information set: |
Jump to behavior | ||
Source: |
Process information set: |
Jump to behavior | ||
Source: |
Process information set: |
Jump to behavior | ||
Source: |
Process information set: |
Jump to behavior | ||
Source: |
Process information set: |
Jump to behavior | ||
Source: |
Process information set: |
Jump to behavior | ||
Source: |
Process information set: |
Jump to behavior | ||
Source: |
Process information set: |
Jump to behavior | ||
Source: |
Process information set: |
Jump to behavior | ||
Source: |
Process information set: |
Jump to behavior | ||
Source: |
Process information set: |
Jump to behavior | ||
Source: |
Process information set: |
Jump to behavior | ||
Source: |
Process information set: |
Jump to behavior | ||
Source: |
Process information set: |
Jump to behavior | ||
Source: |
Process information set: |
Jump to behavior | ||
Source: |
Process information set: |
Jump to behavior | ||
Source: |
Process information set: |
Jump to behavior | ||
Source: |
Process information set: |
Jump to behavior | ||
Source: |
Process information set: |
Jump to behavior | ||
Source: |
Process information set: |
Jump to behavior | ||
Source: |
Process information set: |
Jump to behavior | ||
Source: |
Process information set: |
Jump to behavior | ||
Source: |
Process information set: |
Jump to behavior | ||
Source: |
Process information set: |
Jump to behavior | ||
Source: |
Process information set: |
Jump to behavior | ||
Source: |
Process information set: |
Jump to behavior | ||
Source: |
Process information set: |
Jump to behavior | ||
Source: |
Process information set: |
Jump to behavior | ||
Source: |
Process information set: |
Jump to behavior | ||
Source: |
Process information set: |
Jump to behavior | ||
Source: |
Process information set: |
Jump to behavior | ||
Source: |
Process information set: |
Jump to behavior | ||
Source: |
Process information set: |
Jump to behavior | ||
Source: |
Process information set: |
Jump to behavior | ||
Source: |
Process information set: |
Jump to behavior | ||
Source: |
Process information set: |
Jump to behavior | ||
Source: |
Process information set: |
Jump to behavior | ||
Source: |
Process information set: |
Jump to behavior | ||
Source: |
Process information set: |
Jump to behavior | ||
Source: |
Process information set: |
Jump to behavior | ||
Source: |
Process information set: |
Jump to behavior | ||
Source: |
Process information set: |
Jump to behavior | ||
Source: |
Process information set: |
Jump to behavior | ||
Source: |
Process information set: |
Jump to behavior | ||
Source: |
Process information set: |
Jump to behavior | ||
Source: |
Process information set: |
Jump to behavior | ||
Source: |
Process information set: |
Jump to behavior | ||
Source: |
Process information set: |
Jump to behavior | ||
Source: |
Process information set: |
Jump to behavior | ||
Source: |
Process information set: |
Jump to behavior | ||
Source: |
Process information set: |
Jump to behavior | ||
Source: |
Process information set: |
Jump to behavior | ||
Source: |
Process information set: |
Jump to behavior | ||
Source: |
Process information set: |
Jump to behavior | ||
Source: |
Process information set: |
Jump to behavior | ||
Source: |
Process information set: |
Jump to behavior | ||
Source: |
Process information set: |
Jump to behavior | ||
Source: |
Process information set: |
Jump to behavior | ||
Source: |
Process information set: |
Jump to behavior | ||
Source: |
Process information set: |
Jump to behavior | ||
Source: |
Process information set: |
Jump to behavior | ||
Source: |
Process information set: |
Jump to behavior | ||
Source: |
Process information set: |
Jump to behavior | ||
Source: |
Process information set: |
Jump to behavior | ||
Source: |
Process information set: |
Jump to behavior | ||
Source: |
Process information set: |
Jump to behavior | ||
Source: |
Process information set: |
Jump to behavior | ||
Source: |
Process information set: |
Jump to behavior | ||
Source: |
Process information set: |
Jump to behavior | ||
Source: |
Process information set: |
Jump to behavior | ||
Source: |
Process information set: |
Jump to behavior | ||
Source: |
Process information set: |
Jump to behavior | ||
Source: |
Process information set: |
Jump to behavior | ||
Source: |
Process information set: |
Jump to behavior | ||
Source: |
Process information set: |
Jump to behavior | ||
Source: |
Process information set: |
Jump to behavior | ||
Source: |
Process information set: |
Jump to behavior | ||
Source: |
Process information set: |
Jump to behavior | ||
Source: |
Process information set: |
Jump to behavior |
Malware Analysis System Evasion |
|
---|
Source: |
File source: |
||
Source: |
File source: |
Source: |
API/Special instruction interceptor: |
||
Source: |
API/Special instruction interceptor: |
||
Source: |
API/Special instruction interceptor: |
||
Source: |
API/Special instruction interceptor: |
||
Source: |
API/Special instruction interceptor: |
Source: |
Section loaded: |
Source: |
Memory allocated: |
Jump to behavior | ||
Source: |
Memory allocated: |
Jump to behavior | ||
Source: |
Memory allocated: |
Jump to behavior | ||
Source: |
Memory allocated: |
Jump to behavior | ||
Source: |
Memory allocated: |
Jump to behavior | ||
Source: |
Memory allocated: |
Jump to behavior | ||
Source: |
Memory allocated: |
Jump to behavior | ||
Source: |
Memory allocated: |
Jump to behavior | ||
Source: |
Memory allocated: |
Jump to behavior | ||
Source: |
Memory allocated: |
Jump to behavior | ||
Source: |
Memory allocated: |
Jump to behavior | ||
Source: |
Memory allocated: |
Jump to behavior | ||
Source: |
Memory allocated: |
Jump to behavior | ||
Source: |
Memory allocated: |
Jump to behavior | ||
Source: |
Memory allocated: |
Jump to behavior | ||
Source: |
Memory allocated: |
Jump to behavior | ||
Source: |
Memory allocated: |
Jump to behavior | ||
Source: |
Memory allocated: |
Jump to behavior | ||
Source: |
Memory allocated: |
Jump to behavior | ||
Source: |
Memory allocated: |
Jump to behavior | ||
Source: |
Memory allocated: |
Jump to behavior | ||
Source: |
Memory allocated: |
Jump to behavior | ||
Source: |
Memory allocated: |
Jump to behavior | ||
Source: |
Memory allocated: |
Jump to behavior | ||
Source: |
Memory allocated: |
Jump to behavior | ||
Source: |
Memory allocated: |
Jump to behavior |
Source: |
Code function: |
4_2_007428F0 |
Source: |
Thread delayed: |
Jump to behavior | ||
Source: |
Thread delayed: |
Jump to behavior | ||
Source: |
Thread delayed: |
Jump to behavior | ||
Source: |
Thread delayed: |
Jump to behavior |
Source: |
Dropped PE file which has not been started: |
Jump to dropped file | ||
Source: |
Dropped PE file which has not been started: |
Jump to dropped file |
Source: |
API coverage: |
Source: |
Thread sleep time: |
Jump to behavior | ||
Source: |
Thread sleep time: |
Jump to behavior | ||
Source: |
Thread sleep time: |
Jump to behavior | ||
Source: |
Thread sleep time: |
Jump to behavior | ||
Source: |
Thread sleep time: |
Jump to behavior | ||
Source: |
Thread sleep time: |
Jump to behavior | ||
Source: |
Thread sleep time: |
Jump to behavior | ||
Source: |
Thread sleep time: |
Jump to behavior |
Source: |
Last function: |
||
Source: |
Last function: |
Source: |
Code function: |
4_2_0075611F | |
Source: |
Code function: |
15_2_0075611F |
Source: |
Thread delayed: |
Jump to behavior | ||
Source: |
Thread delayed: |
Jump to behavior | ||
Source: |
Thread delayed: |
Jump to behavior | ||
Source: |
Thread delayed: |
Jump to behavior |
Source: |
Binary or memory string: |
||
Source: |
Binary or memory string: |
||
Source: |
Binary or memory string: |
||
Source: |
Binary or memory string: |
||
Source: |
Binary or memory string: |
||
Source: |
Binary or memory string: |
||
Source: |
Binary or memory string: |
||
Source: |
Binary or memory string: |
||
Source: |
Binary or memory string: |
||
Source: |
Binary or memory string: |
||
Source: |
Binary or memory string: |
||
Source: |
Binary or memory string: |
||
Source: |
Binary or memory string: |
Source: |
Process information queried: |
Jump to behavior |
Anti Debugging |
|
---|
Source: |
Code function: |
2_2_021BA1C4 |
Source: |
Process queried: |
Jump to behavior | ||
Source: |
Process queried: |
Jump to behavior | ||
Source: |
Process queried: |
Jump to behavior |
Source: |
Code function: |
4_2_00750B9D |
Source: |
Code function: |
4_2_007428F0 |
Source: |
Code function: |
0_2_01C1A867 |
Source: |
Code function: |
0_2_0086E5FB |
Source: |
Code function: |
0_2_01C78303 |
Source: |
Process token adjusted: |
Jump to behavior | ||
Source: |
Process token adjusted: |
Jump to behavior |
Source: |
Code function: |
4_2_00750B9D | |
Source: |
Code function: |
4_2_00745DBD | |
Source: |
Code function: |
4_2_00745F22 | |
Source: |
Code function: |
4_2_00745793 | |
Source: |
Code function: |
15_2_00750B9D | |
Source: |
Code function: |
15_2_00745DBD | |
Source: |
Code function: |
15_2_00745F22 | |
Source: |
Code function: |
15_2_00745793 |
Source: |
Memory allocated: |
Jump to behavior |
HIPS / PFW / Operating System Protection Evasion |
|
---|
Source: |
Network Connect: |
Jump to behavior | ||
Source: |
Network Connect: |
Jump to behavior | ||
Source: |
Network Connect: |
Jump to behavior |
Source: |
Memory allocated: |
Jump to behavior |
Source: |
NtCreateFile: |
Jump to behavior | ||
Source: |
NtProtectVirtualMemory: |
Jump to behavior | ||
Source: |
NtSetInformationThread: |
Jump to behavior | ||
Source: |
NtProtectVirtualMemory: |
Jump to behavior | ||
Source: |
NtProtectVirtualMemory: |
Jump to behavior | ||
Source: |
NtAllocateVirtualMemory: |
Jump to behavior | ||
Source: |
NtProtectVirtualMemory: |
Jump to behavior | ||
Source: |
NtProtectVirtualMemory: |
Jump to behavior | ||
Source: |
NtAllocateVirtualMemory: |
Jump to behavior | ||
Source: |
NtQueryInformationToken: |
Jump to behavior | ||
Source: |
NtCreateFile: |
Jump to behavior | ||
Source: |
NtAllocateVirtualMemory: |
Jump to behavior | ||
Source: |
NtAllocateVirtualMemory: |
Jump to behavior | ||
Source: |
NtProtectVirtualMemory: |
Jump to behavior | ||
Source: |
NtAllocateVirtualMemory: |
Jump to behavior | ||
Source: |
NtAllocateVirtualMemory: |
Jump to behavior | ||
Source: |
NtAllocateVirtualMemory: |
Jump to behavior | ||
Source: |
NtAllocateVirtualMemory: |
Jump to behavior | ||
Source: |
NtQuerySystemInformation: |
Jump to behavior | ||
Source: |
NtProtectVirtualMemory: |
Jump to behavior | ||
Source: |
NtProtectVirtualMemory: |
Jump to behavior | ||
Source: |
NtAllocateVirtualMemory: |
Jump to behavior | ||
Source: |
NtAllocateVirtualMemory: |
Jump to behavior | ||
Source: |
NtQueryInformationToken: |
Jump to behavior | ||
Source: |
NtProtectVirtualMemory: |
Jump to behavior | ||
Source: |
NtProtectVirtualMemory: |
Jump to behavior | ||
Source: |
NtProtectVirtualMemory: |
Jump to behavior | ||
Source: |
NtQuerySystemInformation: |
Jump to behavior | ||
Source: |
NtQuerySystemInformation: |
Jump to behavior | ||
Source: |
NtAllocateVirtualMemory: |
Jump to behavior | ||
Source: |
NtProtectVirtualMemory: |
Jump to behavior | ||
Source: |
NtAllocateVirtualMemory: |
Jump to behavior | ||
Source: |
NtProtectVirtualMemory: |
Jump to behavior | ||
Source: |
NtAddAtomEx: |
Jump to behavior | ||
Source: |
NtProtectVirtualMemory: |
Jump to behavior | ||
Source: |
NtAllocateVirtualMemory: |
Jump to behavior | ||
Source: |
NtDelayExecution: |
Jump to behavior | ||
Source: |
NtSetInformationThread: |
Jump to behavior | ||
Source: |
NtProtectVirtualMemory: |
Jump to behavior | ||
Source: |
NtProtectVirtualMemory: |
Jump to behavior | ||
Source: |
NtQuerySystemInformation: |
Jump to behavior |
Source: |
Memory written: |
Jump to behavior | ||
Source: |
Memory written: |
Jump to behavior |
Source: |
Section loaded: |
Jump to behavior | ||
Source: |
Section loaded: |
Jump to behavior | ||
Source: |
Section loaded: |
Jump to behavior | ||
Source: |
Section loaded: |
Jump to behavior |
Source: |
Memory written: |
Jump to behavior | ||
Source: |
Memory written: |
Jump to behavior | ||
Source: |
Memory written: |
Jump to behavior | ||
Source: |
Memory written: |
Jump to behavior | ||
Source: |
Memory written: |
Jump to behavior | ||
Source: |
Memory written: |
Jump to behavior | ||
Source: |
Memory written: |
Jump to behavior | ||
Source: |
Memory written: |
Jump to behavior | ||
Source: |
Memory written: |
Jump to behavior | ||
Source: |
Memory written: |
Jump to behavior | ||
Source: |
Memory written: |
Jump to behavior | ||
Source: |
Memory written: |
Jump to behavior | ||
Source: |
Memory written: |
Jump to behavior | ||
Source: |
Memory written: |
Jump to behavior | ||
Source: |
Memory written: |
Jump to behavior | ||
Source: |
Memory written: |
Jump to behavior |
Source: |
Code function: |
0_2_01C38B22 |
Source: |
Process created: |
Jump to behavior | ||
Source: |
Process created: |
Jump to behavior | ||
Source: |
Process created: |
Jump to behavior | ||
Source: |
Process created: |
Jump to behavior | ||
Source: |
Process created: |
Jump to behavior | ||
Source: |
Process created: |
Jump to behavior |
Source: |
Code function: |
0_2_01C1B8C3 |
Source: |
Binary or memory string: |
Source: |
Code function: |
4_2_00745FDE |
Source: |
Queries volume information: |
Jump to behavior | ||
Source: |
Queries volume information: |
Jump to behavior | ||
Source: |
Queries volume information: |
Jump to behavior | ||
Source: |
Queries volume information: |
Jump to behavior | ||
Source: |
Queries volume information: |
Jump to behavior | ||
Source: |
Queries volume information: |
Jump to behavior | ||
Source: |
Queries volume information: |
Jump to behavior | ||
Source: |
Queries volume information: |
Jump to behavior | ||
Source: |
Queries volume information: |
Jump to behavior | ||
Source: |
Queries volume information: |
Jump to behavior | ||
Source: |
Queries volume information: |
Jump to behavior | ||
Source: |
Queries volume information: |
Jump to behavior | ||
Source: |
Queries volume information: |
Jump to behavior | ||
Source: |
Queries volume information: |
Jump to behavior |
Source: |
Code function: |
0_2_01C74648 |
Source: |
Code function: |
0_2_01C703AC |
Source: |
Code function: |
0_2_01BF2065 |
Source: |
Code function: |
0_2_01C70A52 |
Source: |
Key value queried: |
Jump to behavior |
Stealing of Sensitive Information |
|
---|
Source: |
File source: |
||
Source: |
File source: |
||
Source: |
File source: |
Remote Access Functionality |
|
---|
Source: |
File source: |
||
Source: |
File source: |
||
Source: |
File source: |
IP | Domain | Country | Flag | ASN | ASN Name | Malicious |
---|---|---|---|---|---|---|
46.8.232.106 | unknown | Russian Federation | 28917 | FIORD-ASIP-transitoperatorinRussiaUkraineandBaltics | true | |
193.187.172.163 | unknown | Russian Federation | 64439 | ITOS-ASRU | true | |
147.45.196.157 | unknown | Russian Federation | 2895 | FREE-NET-ASFREEnetEU | true |
Name | IP | Active |
---|---|---|
bg.microsoft.map.fastly.net | 199.232.90.172 | true |
pki-goog.l.google.com | 142.250.80.35 | true |
c.pki.goog | unknown | unknown |
3.238.64.98.in-addr.arpa | unknown | unknown |
Name | Malicious | Antivirus Detection | Reputation |
---|---|---|---|
false |
|
high | |
false |
|
high | |
true |
|
unknown | |
false |
|
high | |
false |
|
high |