Windows Analysis Report
iThmbConverterSetup.exe

Overview

General Information

Sample name: iThmbConverterSetup.exe
Analysis ID: 1668989
MD5: a796f67c500657acf8b8c607cff5f8b1
SHA1: 4834c2c2207d6f47d8d944f3f8fa75186387c08c
SHA256: 326e915a44a8474ddd740b68d7d1f3e07d0a8c1bd9f3ea0bb9ec95dae08fc003
Infos:

Detection

Score: 24
Range: 0 - 100
Confidence: 20%

Signatures

Detected VMProtect packer
Overwrites code with unconditional jumps - possibly settings hooks in foreign process
Allocates memory within range which is reserved for system DLLs (kernel32.dll, advapi32.dll, etc)
Drops PE files
Entry point lies outside standard sections
Found dropped PE file which has not been started or loaded
IP address seen in connection with other malware
PE file contains executable resources (Code or Archives)
PE file contains more sections than normal
PE file contains sections with non-standard names
Queries keyboard layouts
Queries the volume information (name, serial number etc) of a device
Sample file is different than original file name gathered from version info
Stores files to the Windows start menu directory
Uses 32bit PE files

Classification

RansomwareSpreadingPhishingBankerTrojan / BotAdwareSpywareExploiterEvaderMinercleansuspiciousmalicious
Source: iThmbConverterSetup.exe Static PE information: RELOCS_STRIPPED, EXECUTABLE_IMAGE, LINE_NUMS_STRIPPED, LOCAL_SYMS_STRIPPED, BYTES_REVERSED_LO, 32BIT_MACHINE, BYTES_REVERSED_HI
Source: C:\Program Files (x86)\iThmb Converter\iThmbConverter.exe File opened: C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs Jump to behavior
Source: C:\Program Files (x86)\iThmb Converter\iThmbConverter.exe File opened: C:\Users\user Jump to behavior
Source: C:\Program Files (x86)\iThmb Converter\iThmbConverter.exe File opened: C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu Jump to behavior
Source: C:\Program Files (x86)\iThmb Converter\iThmbConverter.exe File opened: C:\Users\user\AppData\Roaming\Microsoft Jump to behavior
Source: C:\Program Files (x86)\iThmb Converter\iThmbConverter.exe File opened: C:\Users\user\AppData Jump to behavior
Source: C:\Program Files (x86)\iThmb Converter\iThmbConverter.exe File opened: C:\Users\user\AppData\Roaming\Microsoft\Windows Jump to behavior
Source: Joe Sandbox View IP Address: 37.140.192.138 37.140.192.138
Source: unknown UDP traffic detected without corresponding DNS query: 1.1.1.1
Source: global traffic HTTP traffic detected: GET /update.txt HTTP/1.1Accept: */*User-Agent: iThmb Converter 1.106.0.720Referer: http://www.ithmbconverter.comHost: www.ithmbconverter.comCache-Control: no-cache
Source: global traffic DNS traffic detected: DNS query: www.ithmbconverter.com
Source: iThmbConverterSetup.exe, 00000000.00000003.359774411195.00000000024D0000.00000004.00001000.00020000.00000000.sdmp, iThmbConverterSetup.exe, 00000000.00000003.360152027259.00000000022A7000.00000004.00001000.00020000.00000000.sdmp, iThmbConverterSetup.tmp, 00000002.00000003.360146554288.000000000232E000.00000004.00001000.00020000.00000000.sdmp, iThmbConverterSetup.tmp, 00000002.00000003.359778487027.0000000003360000.00000004.00001000.00020000.00000000.sdmp String found in binary or memory: http://www.dk-soft.org/
Source: iThmbConverterSetup.exe, 00000000.00000003.359775378136.000000007FD30000.00000004.00001000.00020000.00000000.sdmp, iThmbConverterSetup.exe, 00000000.00000003.359774893928.0000000002610000.00000004.00001000.00020000.00000000.sdmp, iThmbConverterSetup.tmp, 00000002.00000000.359777608784.0000000000401000.00000020.00000001.01000000.00000004.sdmp, is-5NVPK.tmp.2.dr, iThmbConverterSetup.tmp.0.dr String found in binary or memory: http://www.innosetup.com/
Source: iThmbConverter.exe, 00000004.00000003.360765967433.00000000079E9000.00000004.00000020.00020000.00000000.sdmp, iThmbConverter.exe, 00000004.00000002.361030134580.000000000041A000.00000020.00000001.01000000.00000007.sdmp, iThmbConverter.exe, 00000004.00000003.360768652676.0000000007931000.00000004.00000020.00020000.00000000.sdmp, iThmbConverter.exe, 00000004.00000002.361037975123.0000000003B8C000.00000004.00001000.00020000.00000000.sdmp, iThmbConverter.exe, 00000004.00000003.360768103740.0000000007931000.00000004.00000020.00020000.00000000.sdmp, iThmbConverter.exe, 00000004.00000002.361040096534.0000000007931000.00000004.00000020.00020000.00000000.sdmp, iThmbConverter.exe, 00000004.00000002.361040783798.00000000079E9000.00000004.00000020.00020000.00000000.sdmp String found in binary or memory: http://www.ithmbconverter.com
Source: iThmbConverterSetup.tmp, 00000002.00000003.359778487027.0000000003360000.00000004.00001000.00020000.00000000.sdmp, iThmbConverter.exe, 00000004.00000002.361030134580.000000000041A000.00000020.00000001.01000000.00000007.sdmp, iThmbConverter.exe, 00000004.00000002.361037915554.0000000003AB8000.00000004.00000020.00020000.00000000.sdmp, iThmbConverter.exe, 00000004.00000002.361040500171.0000000007973000.00000004.00000020.00020000.00000000.sdmp, iThmbConverter.exe, 00000004.00000003.360765967433.0000000007972000.00000004.00000020.00020000.00000000.sdmp, iThmbConverter.exe, 00000004.00000002.361037975123.0000000003BEA000.00000004.00001000.00020000.00000000.sdmp, iThmb Converter on the Web.url.2.dr String found in binary or memory: http://www.ithmbconverter.com/
Source: iThmbConverter.exe, 00000004.00000002.361040500171.0000000007973000.00000004.00000020.00020000.00000000.sdmp, iThmbConverter.exe, 00000004.00000003.360765967433.0000000007972000.00000004.00000020.00020000.00000000.sdmp String found in binary or memory: http://www.ithmbconverter.com/AppData
Source: iThmbConverter.exe, 00000004.00000002.361030134580.000000000041A000.00000020.00000001.01000000.00000007.sdmp String found in binary or memory: http://www.ithmbconverter.com/U
Source: iThmbConverter.exe, 00000004.00000002.361037915554.0000000003AB8000.00000004.00000020.00020000.00000000.sdmp, iThmbConverter.exe, 00000004.00000002.361037975123.0000000003BD4000.00000004.00001000.00020000.00000000.sdmp String found in binary or memory: http://www.ithmbconverter.com/from-app/
Source: iThmbConverter.exe, 00000004.00000002.361037975123.0000000003B76000.00000004.00001000.00020000.00000000.sdmp String found in binary or memory: http://www.ithmbconverter.com/from-app/en/buy/a
Source: iThmbConverterSetup.exe, 00000000.00000003.360152027259.000000000237A000.00000004.00001000.00020000.00000000.sdmp String found in binary or memory: http://www.ithmbconverter.com/q
Source: iThmbConverter.exe, 00000004.00000003.360767107687.0000000007A15000.00000004.00000020.00020000.00000000.sdmp, iThmbConverter.exe, 00000004.00000002.361040783798.00000000079D5000.00000004.00000020.00020000.00000000.sdmp, iThmbConverter.exe, 00000004.00000002.361037975123.0000000003BE3000.00000004.00001000.00020000.00000000.sdmp, iThmbConverter.exe, 00000004.00000002.361039762892.0000000004570000.00000004.00000020.00020000.00000000.sdmp, iThmbConverter.exe, 00000004.00000002.361040783798.0000000007A15000.00000004.00000020.00020000.00000000.sdmp, iThmbConverter.exe, 00000004.00000002.361040500171.0000000007973000.00000004.00000020.00020000.00000000.sdmp, iThmbConverter.exe, 00000004.00000003.360767899257.00000000079D5000.00000004.00000020.00020000.00000000.sdmp, iThmbConverter.exe, 00000004.00000003.360765967433.0000000007972000.00000004.00000020.00020000.00000000.sdmp String found in binary or memory: http://www.ithmbconverter.com/update.txt
Source: iThmbConverter.exe, 00000004.00000003.360767107687.0000000007A15000.00000004.00000020.00020000.00000000.sdmp, iThmbConverter.exe, 00000004.00000002.361040783798.0000000007A15000.00000004.00000020.00020000.00000000.sdmp String found in binary or memory: http://www.ithmbconverter.com/update.txt=z
Source: iThmbConverter.exe, 00000004.00000002.361040500171.0000000007973000.00000004.00000020.00020000.00000000.sdmp, iThmbConverter.exe, 00000004.00000003.360765967433.0000000007972000.00000004.00000020.00020000.00000000.sdmp String found in binary or memory: http://www.ithmbconverter.com/update.txtta
Source: iThmbConverter.exe, 00000004.00000002.361030134580.000000000041A000.00000020.00000001.01000000.00000007.sdmp String found in binary or memory: http://www.ithmbconverter.comSV
Source: iThmbConverter.exe, 00000004.00000002.361037975123.0000000003BEA000.00000004.00001000.00020000.00000000.sdmp String found in binary or memory: http://www.ithmbconverter.coma
Source: iThmbConverterSetup.exe String found in binary or memory: http://www.jrsoftware.org/ishelp/index.php?topic=setupcmdlineSetupU
Source: iThmbConverterSetup.exe, 00000000.00000003.359774411195.00000000024D0000.00000004.00001000.00020000.00000000.sdmp, iThmbConverterSetup.exe, 00000000.00000003.360152027259.00000000022A7000.00000004.00001000.00020000.00000000.sdmp, iThmbConverterSetup.tmp, 00000002.00000003.360146554288.000000000232E000.00000004.00001000.00020000.00000000.sdmp, iThmbConverterSetup.tmp, 00000002.00000003.359778487027.0000000003360000.00000004.00001000.00020000.00000000.sdmp String found in binary or memory: http://www.palkornel.hu/innosetup%1
Source: iThmbConverterSetup.exe, 00000000.00000003.359775378136.000000007FD30000.00000004.00001000.00020000.00000000.sdmp, iThmbConverterSetup.exe, 00000000.00000003.359774893928.0000000002610000.00000004.00001000.00020000.00000000.sdmp, iThmbConverterSetup.tmp, 00000002.00000000.359777608784.0000000000401000.00000020.00000001.01000000.00000004.sdmp, is-5NVPK.tmp.2.dr, iThmbConverterSetup.tmp.0.dr String found in binary or memory: http://www.remobjects.com/ps
Source: iThmbConverter.exe, 00000004.00000002.361030134580.000000000041A000.00000020.00000001.01000000.00000007.sdmp String found in binary or memory: http://www.server.com/dir1/dirN/iPod%20Photo%20Cache/Photo%20Database
Source: iThmbConverter.exe, 00000004.00000002.361040096534.0000000007931000.00000004.00000020.00020000.00000000.sdmp String found in binary or memory: https://www.ithmbconverter.com/update.txt

System Summary

barindex
Source: is-84GU4.tmp.2.dr Static PE information: .vmp0 and .vmp1 section names
Source: C:\Program Files (x86)\iThmb Converter\iThmbConverter.exe Memory allocated: 77F00000 page execute and read and write Jump to behavior
Source: C:\Program Files (x86)\iThmb Converter\iThmbConverter.exe Memory allocated: 76B50000 page execute and read and write Jump to behavior
Source: iThmbConverterSetup.tmp.0.dr Static PE information: Resource name: RT_RCDATA type: PE32+ executable (console) x86-64, for MS Windows
Source: iThmbConverterSetup.tmp.0.dr Static PE information: Resource name: RT_RCDATA type: PE32 executable (DLL) (GUI) Intel 80386 (stripped to external PDB), for MS Windows
Source: is-5NVPK.tmp.2.dr Static PE information: Resource name: RT_RCDATA type: PE32+ executable (console) x86-64, for MS Windows
Source: is-5NVPK.tmp.2.dr Static PE information: Resource name: RT_RCDATA type: PE32 executable (DLL) (GUI) Intel 80386 (stripped to external PDB), for MS Windows
Source: is-84GU4.tmp.2.dr Static PE information: Number of sections : 11 > 10
Source: iThmbConverterSetup.exe, 00000000.00000003.359775378136.000000007FE41000.00000004.00001000.00020000.00000000.sdmp Binary or memory string: OriginalFilenameshfolder.dll~/ vs iThmbConverterSetup.exe
Source: iThmbConverterSetup.exe, 00000000.00000003.359774893928.0000000002725000.00000004.00001000.00020000.00000000.sdmp Binary or memory string: OriginalFilenameshfolder.dll~/ vs iThmbConverterSetup.exe
Source: iThmbConverterSetup.exe Static PE information: RELOCS_STRIPPED, EXECUTABLE_IMAGE, LINE_NUMS_STRIPPED, LOCAL_SYMS_STRIPPED, BYTES_REVERSED_LO, 32BIT_MACHINE, BYTES_REVERSED_HI
Source: classification engine Classification label: sus24.winEXE@5/11@1/1
Source: C:\Users\user\AppData\Local\Temp\is-HFEFH.tmp\iThmbConverterSetup.tmp File created: C:\Program Files (x86)\iThmb Converter Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-HFEFH.tmp\iThmbConverterSetup.tmp File created: C:\Users\user\AppData\Local\Programs Jump to behavior
Source: C:\Program Files (x86)\iThmb Converter\iThmbConverter.exe Mutant created: \Sessions\1\BaseNamedObjects\AF167531819A466F9100CEB0B1738ABD
Source: C:\Program Files (x86)\iThmb Converter\iThmbConverter.exe Mutant created: \Sessions\1\BaseNamedObjects\MutexNPA_UnitVersioning_8160
Source: C:\Users\user\Desktop\iThmbConverterSetup.exe File created: C:\Users\user\AppData\Local\Temp\is-HFEFH.tmp Jump to behavior
Source: Yara match File source: 4.2.iThmbConverter.exe.400000.0.unpack, type: UNPACKEDPE
Source: Yara match File source: 00000004.00000002.361030134580.0000000000401000.00000020.00000001.01000000.00000007.sdmp, type: MEMORY
Source: C:\Users\user\Desktop\iThmbConverterSetup.exe Key opened: HKEY_CURRENT_USER\Software\Borland\Delphi\Locales Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-HFEFH.tmp\iThmbConverterSetup.tmp Key opened: HKEY_CURRENT_USER\Software\Borland\Delphi\Locales Jump to behavior
Source: C:\Program Files (x86)\iThmb Converter\iThmbConverter.exe Key opened: HKEY_CURRENT_USER\Software\Borland\Delphi\Locales Jump to behavior
Source: C:\Program Files (x86)\iThmb Converter\iThmbConverter.exe Key opened: HKEY_CURRENT_USER\Software\Borland\Delphi\Locales Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-HFEFH.tmp\iThmbConverterSetup.tmp File read: C:\Program Files (x86)\desktop.ini Jump to behavior
Source: C:\Users\user\Desktop\iThmbConverterSetup.exe Key opened: HKEY_CURRENT_USER\Software\Policies\Microsoft\Windows\Safer\CodeIdentifiers Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-HFEFH.tmp\iThmbConverterSetup.tmp Key value created or modified: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion RegisteredOrganization Jump to behavior
Source: iThmbConverter.exe, 00000004.00000002.361031314244.0000000000887000.00000004.00000001.01000000.00000007.sdmp Binary or memory string: SELECT 'INSERT INTO vacuum_db.' || quote(name) || ' SELECT * FROM main.' || quote(name) || ';' FROM vacuum_db.sqlite_master WHERE name=='sqlite_sequence';
Source: iThmbConverter.exe, 00000004.00000002.361031314244.0000000000887000.00000004.00000001.01000000.00000007.sdmp Binary or memory string: INSERT INTO %Q.%s VALUES('index',%Q,%Q,#%d,%Q);
Source: iThmbConverter.exe, 00000004.00000002.361031314244.0000000000887000.00000004.00000001.01000000.00000007.sdmp Binary or memory string: SELECT 'INSERT INTO vacuum_db.' || quote(name) || ' SELECT * FROM main.' || quote(name) || ';'FROM main.sqlite_master WHERE type = 'table' AND name!='sqlite_sequence' AND coalesce(rootpage,1)>0
Source: iThmbConverter.exe, 00000004.00000002.361031314244.0000000000887000.00000004.00000001.01000000.00000007.sdmp Binary or memory string: UPDATE "%w".%s SET sql = sqlite_rename_parent(sql, %Q, %Q) WHERE %s;
Source: iThmbConverter.exe, 00000004.00000002.361031314244.0000000000887000.00000004.00000001.01000000.00000007.sdmp Binary or memory string: UPDATE sqlite_temp_master SET sql = sqlite_rename_trigger(sql, %Q), tbl_name = %Q WHERE %s;
Source: iThmbConverter.exe, 00000004.00000002.361031314244.0000000000887000.00000004.00000001.01000000.00000007.sdmp Binary or memory string: UPDATE %Q.%s SET sql = CASE WHEN type = 'trigger' THEN sqlite_rename_trigger(sql, %Q)ELSE sqlite_rename_table(sql, %Q) END, tbl_name = %Q, name = CASE WHEN type='table' THEN %Q WHEN name LIKE 'sqlite_autoindex%%' AND type='index' THEN 'sqlite_autoindex_' || %Q || substr(name,%d+18) ELSE name END WHERE tbl_name=%Q COLLATE nocase AND (type='table' OR type='index' OR type='trigger');
Source: iThmbConverter.exe, 00000004.00000002.361031314244.0000000000887000.00000004.00000001.01000000.00000007.sdmp Binary or memory string: SELECT 'DELETE FROM vacuum_db.' || quote(name) || ';' FROM vacuum_db.sqlite_master WHERE name='sqlite_sequence'
Source: iThmbConverterSetup.exe String found in binary or memory: /LOADINF="filename"
Source: C:\Users\user\Desktop\iThmbConverterSetup.exe File read: C:\Users\user\Desktop\iThmbConverterSetup.exe Jump to behavior
Source: unknown Process created: C:\Users\user\Desktop\iThmbConverterSetup.exe "C:\Users\user\Desktop\iThmbConverterSetup.exe"
Source: C:\Users\user\Desktop\iThmbConverterSetup.exe Process created: C:\Users\user\AppData\Local\Temp\is-HFEFH.tmp\iThmbConverterSetup.tmp "C:\Users\user\AppData\Local\Temp\is-HFEFH.tmp\iThmbConverterSetup.tmp" /SL5="$10428,10009787,119296,C:\Users\user\Desktop\iThmbConverterSetup.exe"
Source: C:\Users\user\AppData\Local\Temp\is-HFEFH.tmp\iThmbConverterSetup.tmp Process created: C:\Program Files (x86)\iThmb Converter\iThmbConverter.exe "C:\Program Files (x86)\iThmb Converter\iThmbConverter.exe"
Source: C:\Users\user\Desktop\iThmbConverterSetup.exe Process created: C:\Users\user\AppData\Local\Temp\is-HFEFH.tmp\iThmbConverterSetup.tmp "C:\Users\user\AppData\Local\Temp\is-HFEFH.tmp\iThmbConverterSetup.tmp" /SL5="$10428,10009787,119296,C:\Users\user\Desktop\iThmbConverterSetup.exe" Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-HFEFH.tmp\iThmbConverterSetup.tmp Process created: C:\Program Files (x86)\iThmb Converter\iThmbConverter.exe "C:\Program Files (x86)\iThmb Converter\iThmbConverter.exe" Jump to behavior
Source: C:\Users\user\Desktop\iThmbConverterSetup.exe Section loaded: apphelp.dll Jump to behavior
Source: C:\Users\user\Desktop\iThmbConverterSetup.exe Section loaded: edgegdi.dll Jump to behavior
Source: C:\Users\user\Desktop\iThmbConverterSetup.exe Section loaded: uxtheme.dll Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-HFEFH.tmp\iThmbConverterSetup.tmp Section loaded: apphelp.dll Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-HFEFH.tmp\iThmbConverterSetup.tmp Section loaded: msimg32.dll Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-HFEFH.tmp\iThmbConverterSetup.tmp Section loaded: version.dll Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-HFEFH.tmp\iThmbConverterSetup.tmp Section loaded: mpr.dll Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-HFEFH.tmp\iThmbConverterSetup.tmp Section loaded: edgegdi.dll Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-HFEFH.tmp\iThmbConverterSetup.tmp Section loaded: uxtheme.dll Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-HFEFH.tmp\iThmbConverterSetup.tmp Section loaded: kernel.appcore.dll Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-HFEFH.tmp\iThmbConverterSetup.tmp Section loaded: textinputframework.dll Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-HFEFH.tmp\iThmbConverterSetup.tmp Section loaded: coreuicomponents.dll Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-HFEFH.tmp\iThmbConverterSetup.tmp Section loaded: coremessaging.dll Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-HFEFH.tmp\iThmbConverterSetup.tmp Section loaded: ntmarta.dll Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-HFEFH.tmp\iThmbConverterSetup.tmp Section loaded: wintypes.dll Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-HFEFH.tmp\iThmbConverterSetup.tmp Section loaded: wintypes.dll Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-HFEFH.tmp\iThmbConverterSetup.tmp Section loaded: wintypes.dll Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-HFEFH.tmp\iThmbConverterSetup.tmp Section loaded: textshaping.dll Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-HFEFH.tmp\iThmbConverterSetup.tmp Section loaded: dwmapi.dll Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-HFEFH.tmp\iThmbConverterSetup.tmp Section loaded: windows.storage.dll Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-HFEFH.tmp\iThmbConverterSetup.tmp Section loaded: wldp.dll Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-HFEFH.tmp\iThmbConverterSetup.tmp Section loaded: profapi.dll Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-HFEFH.tmp\iThmbConverterSetup.tmp Section loaded: shfolder.dll Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-HFEFH.tmp\iThmbConverterSetup.tmp Section loaded: rstrtmgr.dll Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-HFEFH.tmp\iThmbConverterSetup.tmp Section loaded: ncrypt.dll Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-HFEFH.tmp\iThmbConverterSetup.tmp Section loaded: ntasn1.dll Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-HFEFH.tmp\iThmbConverterSetup.tmp Section loaded: msftedit.dll Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-HFEFH.tmp\iThmbConverterSetup.tmp Section loaded: windows.globalization.dll Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-HFEFH.tmp\iThmbConverterSetup.tmp Section loaded: bcp47langs.dll Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-HFEFH.tmp\iThmbConverterSetup.tmp Section loaded: bcp47mrm.dll Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-HFEFH.tmp\iThmbConverterSetup.tmp Section loaded: globinputhost.dll Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-HFEFH.tmp\iThmbConverterSetup.tmp Section loaded: windows.ui.dll Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-HFEFH.tmp\iThmbConverterSetup.tmp Section loaded: windowmanagementapi.dll Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-HFEFH.tmp\iThmbConverterSetup.tmp Section loaded: inputhost.dll Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-HFEFH.tmp\iThmbConverterSetup.tmp Section loaded: twinapi.appcore.dll Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-HFEFH.tmp\iThmbConverterSetup.tmp Section loaded: twinapi.appcore.dll Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-HFEFH.tmp\iThmbConverterSetup.tmp Section loaded: propsys.dll Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-HFEFH.tmp\iThmbConverterSetup.tmp Section loaded: sspicli.dll Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-HFEFH.tmp\iThmbConverterSetup.tmp Section loaded: explorerframe.dll Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-HFEFH.tmp\iThmbConverterSetup.tmp Section loaded: sfc.dll Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-HFEFH.tmp\iThmbConverterSetup.tmp Section loaded: sfc_os.dll Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-HFEFH.tmp\iThmbConverterSetup.tmp Section loaded: linkinfo.dll Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-HFEFH.tmp\iThmbConverterSetup.tmp Section loaded: ntshrui.dll Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-HFEFH.tmp\iThmbConverterSetup.tmp Section loaded: srvcli.dll Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-HFEFH.tmp\iThmbConverterSetup.tmp Section loaded: cscapi.dll Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-HFEFH.tmp\iThmbConverterSetup.tmp Section loaded: netutils.dll Jump to behavior
Source: C:\Program Files (x86)\iThmb Converter\iThmbConverter.exe Section loaded: apphelp.dll Jump to behavior
Source: C:\Program Files (x86)\iThmb Converter\iThmbConverter.exe Section loaded: version.dll Jump to behavior
Source: C:\Program Files (x86)\iThmb Converter\iThmbConverter.exe Section loaded: mpr.dll Jump to behavior
Source: C:\Program Files (x86)\iThmb Converter\iThmbConverter.exe Section loaded: wininet.dll Jump to behavior
Source: C:\Program Files (x86)\iThmb Converter\iThmbConverter.exe Section loaded: edgegdi.dll Jump to behavior
Source: C:\Program Files (x86)\iThmb Converter\iThmbConverter.exe Section loaded: uxtheme.dll Jump to behavior
Source: C:\Program Files (x86)\iThmb Converter\iThmbConverter.exe Section loaded: kernel.appcore.dll Jump to behavior
Source: C:\Program Files (x86)\iThmb Converter\iThmbConverter.exe Section loaded: wtsapi32.dll Jump to behavior
Source: C:\Program Files (x86)\iThmb Converter\iThmbConverter.exe Section loaded: winsta.dll Jump to behavior
Source: C:\Program Files (x86)\iThmb Converter\iThmbConverter.exe Section loaded: propsys.dll Jump to behavior
Source: C:\Program Files (x86)\iThmb Converter\iThmbConverter.exe Section loaded: windows.storage.dll Jump to behavior
Source: C:\Program Files (x86)\iThmb Converter\iThmbConverter.exe Section loaded: wldp.dll Jump to behavior
Source: C:\Program Files (x86)\iThmb Converter\iThmbConverter.exe Section loaded: riched20.dll Jump to behavior
Source: C:\Program Files (x86)\iThmb Converter\iThmbConverter.exe Section loaded: usp10.dll Jump to behavior
Source: C:\Program Files (x86)\iThmb Converter\iThmbConverter.exe Section loaded: msls31.dll Jump to behavior
Source: C:\Program Files (x86)\iThmb Converter\iThmbConverter.exe Section loaded: profapi.dll Jump to behavior
Source: C:\Program Files (x86)\iThmb Converter\iThmbConverter.exe Section loaded: explorerframe.dll Jump to behavior
Source: C:\Program Files (x86)\iThmb Converter\iThmbConverter.exe Section loaded: dwmapi.dll Jump to behavior
Source: C:\Program Files (x86)\iThmb Converter\iThmbConverter.exe Section loaded: windowscodecs.dll Jump to behavior
Source: C:\Program Files (x86)\iThmb Converter\iThmbConverter.exe Section loaded: dataexchange.dll Jump to behavior
Source: C:\Program Files (x86)\iThmb Converter\iThmbConverter.exe Section loaded: d3d11.dll Jump to behavior
Source: C:\Program Files (x86)\iThmb Converter\iThmbConverter.exe Section loaded: dcomp.dll Jump to behavior
Source: C:\Program Files (x86)\iThmb Converter\iThmbConverter.exe Section loaded: dxgi.dll Jump to behavior
Source: C:\Program Files (x86)\iThmb Converter\iThmbConverter.exe Section loaded: twinapi.appcore.dll Jump to behavior
Source: C:\Program Files (x86)\iThmb Converter\iThmbConverter.exe Section loaded: textshaping.dll Jump to behavior
Source: C:\Program Files (x86)\iThmb Converter\iThmbConverter.exe Section loaded: secur32.dll Jump to behavior
Source: C:\Program Files (x86)\iThmb Converter\iThmbConverter.exe Section loaded: sspicli.dll Jump to behavior
Source: C:\Program Files (x86)\iThmb Converter\iThmbConverter.exe Section loaded: samcli.dll Jump to behavior
Source: C:\Program Files (x86)\iThmb Converter\iThmbConverter.exe Section loaded: samlib.dll Jump to behavior
Source: C:\Program Files (x86)\iThmb Converter\iThmbConverter.exe Section loaded: netutils.dll Jump to behavior
Source: C:\Program Files (x86)\iThmb Converter\iThmbConverter.exe Section loaded: thumbcache.dll Jump to behavior
Source: C:\Program Files (x86)\iThmb Converter\iThmbConverter.exe Section loaded: drprov.dll Jump to behavior
Source: C:\Program Files (x86)\iThmb Converter\iThmbConverter.exe Section loaded: ntlanman.dll Jump to behavior
Source: C:\Program Files (x86)\iThmb Converter\iThmbConverter.exe Section loaded: davclnt.dll Jump to behavior
Source: C:\Program Files (x86)\iThmb Converter\iThmbConverter.exe Section loaded: davhlpr.dll Jump to behavior
Source: C:\Program Files (x86)\iThmb Converter\iThmbConverter.exe Section loaded: wkscli.dll Jump to behavior
Source: C:\Program Files (x86)\iThmb Converter\iThmbConverter.exe Section loaded: cscapi.dll Jump to behavior
Source: C:\Program Files (x86)\iThmb Converter\iThmbConverter.exe Section loaded: dlnashext.dll Jump to behavior
Source: C:\Program Files (x86)\iThmb Converter\iThmbConverter.exe Section loaded: playtodevice.dll Jump to behavior
Source: C:\Program Files (x86)\iThmb Converter\iThmbConverter.exe Section loaded: devdispitemprovider.dll Jump to behavior
Source: C:\Program Files (x86)\iThmb Converter\iThmbConverter.exe Section loaded: mmdevapi.dll Jump to behavior
Source: C:\Program Files (x86)\iThmb Converter\iThmbConverter.exe Section loaded: devobj.dll Jump to behavior
Source: C:\Program Files (x86)\iThmb Converter\iThmbConverter.exe Section loaded: wpdshext.dll Jump to behavior
Source: C:\Program Files (x86)\iThmb Converter\iThmbConverter.exe Section loaded: portabledeviceapi.dll Jump to behavior
Source: C:\Program Files (x86)\iThmb Converter\iThmbConverter.exe Section loaded: msasn1.dll Jump to behavior
Source: C:\Program Files (x86)\iThmb Converter\iThmbConverter.exe Section loaded: audiodev.dll Jump to behavior
Source: C:\Program Files (x86)\iThmb Converter\iThmbConverter.exe Section loaded: wmvcore.dll Jump to behavior
Source: C:\Program Files (x86)\iThmb Converter\iThmbConverter.exe Section loaded: wmasf.dll Jump to behavior
Source: C:\Program Files (x86)\iThmb Converter\iThmbConverter.exe Section loaded: mfperfhelper.dll Jump to behavior
Source: C:\Program Files (x86)\iThmb Converter\iThmbConverter.exe Section loaded: textinputframework.dll Jump to behavior
Source: C:\Program Files (x86)\iThmb Converter\iThmbConverter.exe Section loaded: coreuicomponents.dll Jump to behavior
Source: C:\Program Files (x86)\iThmb Converter\iThmbConverter.exe Section loaded: coremessaging.dll Jump to behavior
Source: C:\Program Files (x86)\iThmb Converter\iThmbConverter.exe Section loaded: ntmarta.dll Jump to behavior
Source: C:\Program Files (x86)\iThmb Converter\iThmbConverter.exe Section loaded: wintypes.dll Jump to behavior
Source: C:\Program Files (x86)\iThmb Converter\iThmbConverter.exe Section loaded: wintypes.dll Jump to behavior
Source: C:\Program Files (x86)\iThmb Converter\iThmbConverter.exe Section loaded: wintypes.dll Jump to behavior
Source: C:\Program Files (x86)\iThmb Converter\iThmbConverter.exe Section loaded: policymanager.dll Jump to behavior
Source: C:\Program Files (x86)\iThmb Converter\iThmbConverter.exe Section loaded: msvcp110_win.dll Jump to behavior
Source: C:\Program Files (x86)\iThmb Converter\iThmbConverter.exe Section loaded: duser.dll Jump to behavior
Source: C:\Program Files (x86)\iThmb Converter\iThmbConverter.exe Section loaded: xmllite.dll Jump to behavior
Source: C:\Program Files (x86)\iThmb Converter\iThmbConverter.exe Section loaded: atlthunk.dll Jump to behavior
Source: C:\Program Files (x86)\iThmb Converter\iThmbConverter.exe Section loaded: iertutil.dll Jump to behavior
Source: C:\Program Files (x86)\iThmb Converter\iThmbConverter.exe Section loaded: ondemandconnroutehelper.dll Jump to behavior
Source: C:\Program Files (x86)\iThmb Converter\iThmbConverter.exe Section loaded: winhttp.dll Jump to behavior
Source: C:\Program Files (x86)\iThmb Converter\iThmbConverter.exe Section loaded: mswsock.dll Jump to behavior
Source: C:\Program Files (x86)\iThmb Converter\iThmbConverter.exe Section loaded: iphlpapi.dll Jump to behavior
Source: C:\Program Files (x86)\iThmb Converter\iThmbConverter.exe Section loaded: winnsi.dll Jump to behavior
Source: C:\Program Files (x86)\iThmb Converter\iThmbConverter.exe Section loaded: urlmon.dll Jump to behavior
Source: C:\Program Files (x86)\iThmb Converter\iThmbConverter.exe Section loaded: srvcli.dll Jump to behavior
Source: C:\Program Files (x86)\iThmb Converter\iThmbConverter.exe Section loaded: dnsapi.dll Jump to behavior
Source: C:\Program Files (x86)\iThmb Converter\iThmbConverter.exe Section loaded: rasadhlp.dll Jump to behavior
Source: C:\Program Files (x86)\iThmb Converter\iThmbConverter.exe Section loaded: fwpuclnt.dll Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-HFEFH.tmp\iThmbConverterSetup.tmp Key value queried: HKEY_LOCAL_MACHINE\SOFTWARE\Classes\WOW6432Node\CLSID\{00BB2765-6A77-11D0-A535-00C04FD7D062}\InProcServer32 Jump to behavior
Source: iThmb Converter.lnk.2.dr LNK file: ..\..\..\..\..\..\Program Files (x86)\iThmb Converter\iThmbConverter.exe
Source: iThmb Converter.lnk0.2.dr LNK file: ..\..\..\Program Files (x86)\iThmb Converter\iThmbConverter.exe
Source: C:\Users\user\AppData\Local\Temp\is-HFEFH.tmp\iThmbConverterSetup.tmp Key value created or modified: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion RegisteredOwner Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-HFEFH.tmp\iThmbConverterSetup.tmp Window found: window name: TSelectLanguageForm Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-HFEFH.tmp\iThmbConverterSetup.tmp Automated click: OK
Source: C:\Users\user\AppData\Local\Temp\is-HFEFH.tmp\iThmbConverterSetup.tmp Automated click: Next >
Source: C:\Users\user\AppData\Local\Temp\is-HFEFH.tmp\iThmbConverterSetup.tmp Automated click: I accept the agreement
Source: C:\Users\user\AppData\Local\Temp\is-HFEFH.tmp\iThmbConverterSetup.tmp Automated click: Next >
Source: C:\Users\user\AppData\Local\Temp\is-HFEFH.tmp\iThmbConverterSetup.tmp Automated click: Next >
Source: C:\Users\user\AppData\Local\Temp\is-HFEFH.tmp\iThmbConverterSetup.tmp Automated click: I accept the agreement
Source: C:\Users\user\AppData\Local\Temp\is-HFEFH.tmp\iThmbConverterSetup.tmp Automated click: Next >
Source: C:\Users\user\AppData\Local\Temp\is-HFEFH.tmp\iThmbConverterSetup.tmp Automated click: I accept the agreement
Source: C:\Users\user\AppData\Local\Temp\is-HFEFH.tmp\iThmbConverterSetup.tmp Automated click: Next >
Source: C:\Users\user\AppData\Local\Temp\is-HFEFH.tmp\iThmbConverterSetup.tmp Automated click: I accept the agreement
Source: C:\Users\user\AppData\Local\Temp\is-HFEFH.tmp\iThmbConverterSetup.tmp Automated click: Install
Source: C:\Users\user\AppData\Local\Temp\is-HFEFH.tmp\iThmbConverterSetup.tmp Automated click: I accept the agreement
Source: C:\Users\user\AppData\Local\Temp\is-HFEFH.tmp\iThmbConverterSetup.tmp File opened: C:\Windows\SysWOW64\MSFTEDIT.DLL Jump to behavior
Source: Window Recorder Window detected: More than 3 window changes detected
Source: iThmbConverterSetup.exe Static file information: File size 10458212 > 1048576
Source: initial sample Static PE information: section where entry point is pointing to: .vmp1
Source: is-84GU4.tmp.2.dr Static PE information: section name: .didata
Source: is-84GU4.tmp.2.dr Static PE information: section name: .vmp0
Source: is-84GU4.tmp.2.dr Static PE information: section name: .vmp1
Source: C:\Users\user\AppData\Local\Temp\is-HFEFH.tmp\iThmbConverterSetup.tmp File created: C:\Program Files (x86)\iThmb Converter\is-84GU4.tmp Jump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-HFEFH.tmp\iThmbConverterSetup.tmp File created: C:\Users\user\AppData\Local\Temp\is-EJOM6.tmp\_isetup\_shfoldr.dll Jump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-HFEFH.tmp\iThmbConverterSetup.tmp File created: C:\Program Files (x86)\iThmb Converter\unins000.exe (copy) Jump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-HFEFH.tmp\iThmbConverterSetup.tmp File created: C:\Program Files (x86)\iThmb Converter\iThmbConverter.exe (copy) Jump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-HFEFH.tmp\iThmbConverterSetup.tmp File created: C:\Program Files (x86)\iThmb Converter\is-5NVPK.tmp Jump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-HFEFH.tmp\iThmbConverterSetup.tmp File created: C:\Users\user\AppData\Local\Temp\is-EJOM6.tmp\_isetup\_setup64.tmp Jump to dropped file
Source: C:\Users\user\Desktop\iThmbConverterSetup.exe File created: C:\Users\user\AppData\Local\Temp\is-HFEFH.tmp\iThmbConverterSetup.tmp Jump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-HFEFH.tmp\iThmbConverterSetup.tmp File created: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\iThmb Converter Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-HFEFH.tmp\iThmbConverterSetup.tmp File created: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\iThmb Converter\iThmb Converter.lnk Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-HFEFH.tmp\iThmbConverterSetup.tmp File created: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\iThmb Converter\iThmb Converter on the Web.url Jump to behavior

Hooking and other Techniques for Hiding and Protection

barindex
Source: C:\Program Files (x86)\iThmb Converter\iThmbConverter.exe Memory written: PID: 8160 base: 77F00005 value: E9 4B B9 E8 FF Jump to behavior
Source: C:\Program Files (x86)\iThmb Converter\iThmbConverter.exe Memory written: PID: 8160 base: 77D8B950 value: E9 BB 8D CE 88 Jump to behavior
Source: C:\Program Files (x86)\iThmb Converter\iThmbConverter.exe Memory written: PID: 8160 base: 77F00017 value: E9 0C 8C ED FF Jump to behavior
Source: C:\Program Files (x86)\iThmb Converter\iThmbConverter.exe Memory written: PID: 8160 base: 77DD8C20 value: E9 7B BB C9 88 Jump to behavior
Source: C:\Program Files (x86)\iThmb Converter\iThmbConverter.exe Memory written: PID: 8160 base: 76B50005 value: E9 9B 2F E8 FF Jump to behavior
Source: C:\Program Files (x86)\iThmb Converter\iThmbConverter.exe Memory written: PID: 8160 base: 769D2FA0 value: E9 7B 16 0A 8A Jump to behavior
Source: C:\Program Files (x86)\iThmb Converter\iThmbConverter.exe Memory written: PID: 8160 base: 76B50014 value: E9 FC CD E9 FF Jump to behavior
Source: C:\Program Files (x86)\iThmb Converter\iThmbConverter.exe Memory written: PID: 8160 base: 769ECE10 value: E9 9B 78 08 8A Jump to behavior
Source: C:\Users\user\Desktop\iThmbConverterSetup.exe Process information set: FAILCRITICALERRORS | NOOPENFILEERRORBOX Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-HFEFH.tmp\iThmbConverterSetup.tmp Process information set: FAILCRITICALERRORS | NOOPENFILEERRORBOX Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-HFEFH.tmp\iThmbConverterSetup.tmp Process information set: FAILCRITICALERRORS | NOOPENFILEERRORBOX Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-HFEFH.tmp\iThmbConverterSetup.tmp Process information set: FAILCRITICALERRORS | NOOPENFILEERRORBOX Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-HFEFH.tmp\iThmbConverterSetup.tmp Process information set: FAILCRITICALERRORS | NOOPENFILEERRORBOX Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-HFEFH.tmp\iThmbConverterSetup.tmp Process information set: FAILCRITICALERRORS | NOOPENFILEERRORBOX Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-HFEFH.tmp\iThmbConverterSetup.tmp Process information set: FAILCRITICALERRORS | NOOPENFILEERRORBOX Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-HFEFH.tmp\iThmbConverterSetup.tmp Process information set: FAILCRITICALERRORS | NOOPENFILEERRORBOX Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-HFEFH.tmp\iThmbConverterSetup.tmp Process information set: FAILCRITICALERRORS | NOOPENFILEERRORBOX Jump to behavior
Source: C:\Program Files (x86)\iThmb Converter\iThmbConverter.exe Process information set: FAILCRITICALERRORS | NOOPENFILEERRORBOX Jump to behavior
Source: C:\Program Files (x86)\iThmb Converter\iThmbConverter.exe Process information set: FAILCRITICALERRORS | NOOPENFILEERRORBOX Jump to behavior
Source: C:\Program Files (x86)\iThmb Converter\iThmbConverter.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Program Files (x86)\iThmb Converter\iThmbConverter.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Program Files (x86)\iThmb Converter\iThmbConverter.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Program Files (x86)\iThmb Converter\iThmbConverter.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Program Files (x86)\iThmb Converter\iThmbConverter.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Program Files (x86)\iThmb Converter\iThmbConverter.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Program Files (x86)\iThmb Converter\iThmbConverter.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Program Files (x86)\iThmb Converter\iThmbConverter.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Program Files (x86)\iThmb Converter\iThmbConverter.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-HFEFH.tmp\iThmbConverterSetup.tmp Dropped PE file which has not been started: C:\Users\user\AppData\Local\Temp\is-EJOM6.tmp\_isetup\_shfoldr.dll Jump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-HFEFH.tmp\iThmbConverterSetup.tmp Dropped PE file which has not been started: C:\Program Files (x86)\iThmb Converter\unins000.exe (copy) Jump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-HFEFH.tmp\iThmbConverterSetup.tmp Dropped PE file which has not been started: C:\Program Files (x86)\iThmb Converter\is-5NVPK.tmp Jump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-HFEFH.tmp\iThmbConverterSetup.tmp Dropped PE file which has not been started: C:\Users\user\AppData\Local\Temp\is-EJOM6.tmp\_isetup\_setup64.tmp Jump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-HFEFH.tmp\iThmbConverterSetup.tmp Key opened: HKEY_LOCAL_MACHINE\System\CurrentControlSet\Control\Keyboard Layouts\08070409 Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-HFEFH.tmp\iThmbConverterSetup.tmp Key opened: HKEY_LOCAL_MACHINE\System\CurrentControlSet\Control\Keyboard Layouts\04090409 Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-HFEFH.tmp\iThmbConverterSetup.tmp Key opened: HKEY_LOCAL_MACHINE\System\CurrentControlSet\Control\Keyboard Layouts\08090809 Jump to behavior
Source: C:\Program Files (x86)\iThmb Converter\iThmbConverter.exe Key opened: HKEY_LOCAL_MACHINE\System\CurrentControlSet\Control\Keyboard Layouts\08070409 Jump to behavior
Source: C:\Program Files (x86)\iThmb Converter\iThmbConverter.exe Key opened: HKEY_LOCAL_MACHINE\System\CurrentControlSet\Control\Keyboard Layouts\04090409 Jump to behavior
Source: C:\Program Files (x86)\iThmb Converter\iThmbConverter.exe Key opened: HKEY_LOCAL_MACHINE\System\CurrentControlSet\Control\Keyboard Layouts\08090809 Jump to behavior
Source: C:\Program Files (x86)\iThmb Converter\iThmbConverter.exe File opened: C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs Jump to behavior
Source: C:\Program Files (x86)\iThmb Converter\iThmbConverter.exe File opened: C:\Users\user Jump to behavior
Source: C:\Program Files (x86)\iThmb Converter\iThmbConverter.exe File opened: C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu Jump to behavior
Source: C:\Program Files (x86)\iThmb Converter\iThmbConverter.exe File opened: C:\Users\user\AppData\Roaming\Microsoft Jump to behavior
Source: C:\Program Files (x86)\iThmb Converter\iThmbConverter.exe File opened: C:\Users\user\AppData Jump to behavior
Source: C:\Program Files (x86)\iThmb Converter\iThmbConverter.exe File opened: C:\Users\user\AppData\Roaming\Microsoft\Windows Jump to behavior
Source: iThmbConverter.exe, 00000004.00000002.361040500171.0000000007973000.00000004.00000020.00020000.00000000.sdmp, iThmbConverter.exe, 00000004.00000002.361041116017.000000000AB50000.00000004.00000020.00020000.00000000.sdmp, iThmbConverter.exe, 00000004.00000003.360765967433.0000000007972000.00000004.00000020.00020000.00000000.sdmp Binary or memory string: Hyper-V RAW
Source: C:\Users\user\AppData\Local\Temp\is-HFEFH.tmp\iThmbConverterSetup.tmp Process information queried: ProcessInformation Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-HFEFH.tmp\iThmbConverterSetup.tmp Queries volume information: C:\ VolumeInformation Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-HFEFH.tmp\iThmbConverterSetup.tmp Queries volume information: C:\ VolumeInformation Jump to behavior
Source: C:\Program Files (x86)\iThmb Converter\iThmbConverter.exe Queries volume information: C:\ VolumeInformation Jump to behavior
  • No. of IPs < 25%
  • 25% < No. of IPs < 50%
  • 50% < No. of IPs < 75%
  • 75% < No. of IPs