Source: C:\Windows\SysWOW64\unarchiver.exe | File opened: C:\Windows\WinSxS\x86_microsoft.vc80.crt_1fc8b3b9a1e18e3b_8.0.50727.9445_none_d08c58b4442ba54f\MSVCR80.dll |
Source: C:\Windows\SysWOW64\unarchiver.exe | Code function: 4x nop then jmp 0135099Bh |
Source: C:\Windows\SysWOW64\unarchiver.exe | Code function: 4x nop then jmp 0135099Ah |
Source: C:\Windows\SysWOW64\unarchiver.exe | Code function: 0_2_013502A8 |
Source: C:\Windows\SysWOW64\unarchiver.exe | Code function: 0_2_01350299 |
Source: C:\Windows\SysWOW64\unarchiver.exe | File created: C:\Users\user\AppData\Local\Temp\o21fgc1p.ykx | Jump to behavior |
Source: C:\Windows\SysWOW64\unarchiver.exe | Key opened: HKEY_CURRENT_USER\Software\Policies\Microsoft\Windows\Safer\CodeIdentifiers |
Source: C:\Windows\SysWOW64\unarchiver.exe | Section loaded: C:\Windows\assembly\NativeImages_v2.0.50727_32\mscorlib\9603718106bd57ecfbb18fefd769cab4\mscorlib.ni.dll |
Source: C:\Windows\SysWOW64\unarchiver.exe | Section loaded: C:\Windows\assembly\GAC_32\mscorlib\2.0.0.0__b77a5c561934e089\sorttbls.nlp |
Source: C:\Windows\SysWOW64\unarchiver.exe | Section loaded: C:\Windows\assembly\GAC_32\mscorlib\2.0.0.0__b77a5c561934e089\sortkey.nlp |
Source: classification engine | Classification label: clean2.winZIP@4/2@0/0 |
Source: unknown | Process created: C:\Windows\SysWOW64\unarchiver.exe 'C:\Windows\SysWOW64\unarchiver.exe' 'C:\Users\user\Desktop\btc1exch06_2021-10-24_12_30_07.zip' |
Source: C:\Windows\SysWOW64\unarchiver.exe | Process created: C:\Windows\SysWOW64\7za.exe 'C:\Windows\System32\7za.exe' x -pinfected -y -o'C:\Users\user\AppData\Local\Temp\amgha5zs.gqf' 'C:\Users\user\Desktop\btc1exch06_2021-10-24_12_30_07.zip' |
Source: C:\Windows\SysWOW64\7za.exe | Process created: C:\Windows\System32\conhost.exe C:\Windows\system32\conhost.exe 0xffffffff -ForceV1 |
Source: C:\Windows\SysWOW64\unarchiver.exe | Process created: C:\Windows\SysWOW64\7za.exe 'C:\Windows\System32\7za.exe' x -pinfected -y -o'C:\Users\user\AppData\Local\Temp\amgha5zs.gqf' 'C:\Users\user\Desktop\btc1exch06_2021-10-24_12_30_07.zip' |
Source: btc1exch06_2021-10-24_12_30_07.zip | Joe Sandbox Cloud Basic: Detection: clean Score: 0 | Perma Link |
Source: C:\Windows\System32\conhost.exe | Mutant created: \Sessions\1\BaseNamedObjects\Local\SM0:4340:120:WilError_01 |
Source: C:\Windows\SysWOW64\unarchiver.exe | File opened: C:\Windows\WinSxS\x86_microsoft.vc80.crt_1fc8b3b9a1e18e3b_8.0.50727.9445_none_d08c58b4442ba54f\MSVCR80.dll |
Source: C:\Windows\SysWOW64\unarchiver.exe | Process information set: NOOPENFILEERRORBOX |
Source: C:\Windows\SysWOW64\unarchiver.exe | Process information set: NOOPENFILEERRORBOX |
Source: C:\Windows\SysWOW64\unarchiver.exe | Process information set: NOOPENFILEERRORBOX |
Source: C:\Windows\SysWOW64\unarchiver.exe | Process information set: NOOPENFILEERRORBOX |
Source: C:\Windows\SysWOW64\unarchiver.exe | Process information set: NOOPENFILEERRORBOX |
Source: C:\Windows\SysWOW64\unarchiver.exe | Process information set: NOOPENFILEERRORBOX |
Source: C:\Windows\SysWOW64\unarchiver.exe | Process information set: NOOPENFILEERRORBOX |
Source: C:\Windows\SysWOW64\unarchiver.exe | Process information set: NOOPENFILEERRORBOX |
Source: C:\Windows\SysWOW64\unarchiver.exe | Process information set: NOOPENFILEERRORBOX |
Source: C:\Windows\SysWOW64\unarchiver.exe | Process information set: NOOPENFILEERRORBOX |
Source: C:\Windows\SysWOW64\unarchiver.exe | Process information set: NOOPENFILEERRORBOX |
Source: C:\Windows\SysWOW64\unarchiver.exe | Process information set: NOOPENFILEERRORBOX |
Source: C:\Windows\SysWOW64\unarchiver.exe | Process information set: NOOPENFILEERRORBOX |
Source: C:\Windows\SysWOW64\unarchiver.exe | Process information set: NOOPENFILEERRORBOX |
Source: C:\Windows\SysWOW64\unarchiver.exe | Process information set: NOOPENFILEERRORBOX |
Source: C:\Windows\SysWOW64\unarchiver.exe | Process information set: NOOPENFILEERRORBOX |
Source: C:\Windows\SysWOW64\unarchiver.exe | Process information set: NOOPENFILEERRORBOX |
Source: C:\Windows\SysWOW64\unarchiver.exe | Process information set: NOOPENFILEERRORBOX |
Source: C:\Windows\SysWOW64\unarchiver.exe | Process information set: NOOPENFILEERRORBOX |
Source: C:\Windows\SysWOW64\unarchiver.exe TID: 6760 | Thread sleep time: -922337203685477s >= -30000s |
Source: C:\Windows\SysWOW64\unarchiver.exe | Thread delayed: delay time: 922337203685477 |
Source: C:\Windows\SysWOW64\unarchiver.exe | Thread delayed: delay time: 922337203685477 |
Source: C:\Windows\SysWOW64\unarchiver.exe | Memory allocated: page read and write | page guard |
Source: C:\Windows\SysWOW64\unarchiver.exe | Process created: C:\Windows\SysWOW64\7za.exe 'C:\Windows\System32\7za.exe' x -pinfected -y -o'C:\Users\user\AppData\Local\Temp\amgha5zs.gqf' 'C:\Users\user\Desktop\btc1exch06_2021-10-24_12_30_07.zip' |
Source: C:\Windows\SysWOW64\unarchiver.exe | Key value queried: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Cryptography MachineGuid |
Thumbnails
This section contains all screenshots as thumbnails, including those not shown in the slideshow.