Source: 00000000.00000002.374239555.0000000000B31000.00000040.00000001.sdmp |
Malware Configuration Extractor: Trickbot {"ver": "100019", "gtag": "top147", "servs": ["65.152.201.203:443", "185.56.175.122:443", "46.99.175.217:443", "179.189.229.254:443", "46.99.175.149:443", "181.129.167.82:443", "216.166.148.187:443", "46.99.188.223:443", "128.201.76.252:443", "62.99.79.77:443", "60.51.47.65:443", "24.162.214.166:443", "45.36.99.184:443", "97.83.40.67:443", "184.74.99.214:443", "103.105.254.17:443", "62.99.76.213:443", "82.159.149.52:443"], "autorun": ["pwgrabb", "pwgrabc"], "ecc_key": "RUNTMzAAAABbfmkJRvwyw7iFkX40hL2HwsUeOSZZZo0FRRWGkY6J1+gf3YKq13Ee4sY3Jb9/0myCr0MwzNK1K2l5yuY87nW29Q/yjMJG0ISDj0HNBC3G+ZGta6Oi9QkjCwnNGbw2hQ4="} |
Source: C:\Windows\System32\wermgr.exe |
Code function: 4x nop then dec eax |
1_2_00000239A18DFA20 |
Source: C:\Windows\System32\wermgr.exe |
Code function: 4x nop then dec eax |
1_2_00000239A18D4060 |
Source: C:\Windows\System32\wermgr.exe |
Code function: 4x nop then inc esp |
1_2_00000239A18D9460 |
Source: C:\Windows\System32\wermgr.exe |
Code function: 4x nop then dec eax |
1_2_00000239A18C4470 |
Source: C:\Windows\System32\wermgr.exe |
Code function: 4x nop then mov ebx, edx |
1_2_00000239A18C4470 |
Source: C:\Windows\System32\wermgr.exe |
Code function: 4x nop then dec ecx |
1_2_00000239A18DFBA0 |
Source: C:\Windows\System32\wermgr.exe |
Code function: 4x nop then dec eax |
1_2_00000239A18DFBA0 |
Source: C:\Windows\System32\wermgr.exe |
Code function: 4x nop then cmp dword ptr [eax], ecx |
1_2_00000239A18CA3B0 |
Source: C:\Windows\System32\wermgr.exe |
Code function: 4x nop then dec eax |
1_2_00000239A18C2BC0 |
Source: C:\Windows\System32\wermgr.exe |
Code function: 4x nop then inc ebp |
1_2_00000239A18C5BE0 |
Source: C:\Windows\System32\wermgr.exe |
Code function: 4x nop then movzx ecx, byte ptr [ebp-07h] |
1_2_00000239A18DE3F0 |
Source: C:\Windows\System32\wermgr.exe |
Code function: 4x nop then dec eax |
1_2_00000239A18CE320 |
Source: C:\Windows\System32\wermgr.exe |
Code function: 4x nop then mov byte ptr [esp+ecx+70h], cl |
1_2_00000239A18E5F60 |
Source: C:\Windows\System32\wermgr.exe |
Code function: 4x nop then dec eax |
1_2_00000239A18E5EC0 |
Source: C:\Windows\System32\wermgr.exe |
Code function: 4x nop then inc esp |
1_2_00000239A18C6EF0 |
Source: C:\Windows\System32\wermgr.exe |
Code function: 4x nop then dec eax |
1_2_00000239A18D0A00 |
Source: C:\Windows\System32\wermgr.exe |
Code function: 4x nop then dec eax |
1_2_00000239A18DB520 |
Source: C:\Windows\System32\wermgr.exe |
Code function: 4x nop then inc esp |
1_2_00000239A18D4D50 |
Source: C:\Windows\System32\wermgr.exe |
Code function: 4x nop then dec eax |
1_2_00000239A18E3990 |
Source: C:\Users\user\Desktop\dngqoAXyDd.exe |
Code function: 0_2_001A911C |
0_2_001A911C |
Source: C:\Users\user\Desktop\dngqoAXyDd.exe |
Code function: 0_2_0019C201 |
0_2_0019C201 |
Source: C:\Users\user\Desktop\dngqoAXyDd.exe |
Code function: 0_2_001A82BD |
0_2_001A82BD |
Source: C:\Users\user\Desktop\dngqoAXyDd.exe |
Code function: 0_2_001A941B |
0_2_001A941B |
Source: C:\Users\user\Desktop\dngqoAXyDd.exe |
Code function: 0_2_0019C5D3 |
0_2_0019C5D3 |
Source: C:\Users\user\Desktop\dngqoAXyDd.exe |
Code function: 0_2_001A16DE |
0_2_001A16DE |
Source: C:\Users\user\Desktop\dngqoAXyDd.exe |
Code function: 0_2_001A880E |
0_2_001A880E |
Source: C:\Users\user\Desktop\dngqoAXyDd.exe |
Code function: 0_2_0018C950 |
0_2_0018C950 |
Source: C:\Users\user\Desktop\dngqoAXyDd.exe |
Code function: 0_2_0019C9BB |
0_2_0019C9BB |
Source: C:\Users\user\Desktop\dngqoAXyDd.exe |
Code function: 0_2_0019B9CE |
0_2_0019B9CE |
Source: C:\Users\user\Desktop\dngqoAXyDd.exe |
Code function: 0_2_001ABBF1 |
0_2_001ABBF1 |
Source: C:\Users\user\Desktop\dngqoAXyDd.exe |
Code function: 0_2_00195C19 |
0_2_00195C19 |
Source: C:\Users\user\Desktop\dngqoAXyDd.exe |
Code function: 0_2_001A4D22 |
0_2_001A4D22 |
Source: C:\Users\user\Desktop\dngqoAXyDd.exe |
Code function: 0_2_001A7D6E |
0_2_001A7D6E |
Source: C:\Users\user\Desktop\dngqoAXyDd.exe |
Code function: 0_2_001A9E7F |
0_2_001A9E7F |
Source: C:\Users\user\Desktop\dngqoAXyDd.exe |
Code function: 0_2_0019BE63 |
0_2_0019BE63 |
Source: C:\Users\user\Desktop\dngqoAXyDd.exe |
Code function: 0_2_001A8EA1 |
0_2_001A8EA1 |
Source: C:\Users\user\Desktop\dngqoAXyDd.exe |
Code function: 0_2_00B33168 |
0_2_00B33168 |
Source: C:\Windows\System32\wermgr.exe |
Code function: 1_2_00000239A18C2F30 |
1_2_00000239A18C2F30 |
Source: C:\Windows\System32\wermgr.exe |
Code function: 1_2_00000239A18CC750 |
1_2_00000239A18CC750 |
Source: C:\Windows\System32\wermgr.exe |
Code function: 1_2_00000239A18D4260 |
1_2_00000239A18D4260 |
Source: C:\Windows\System32\wermgr.exe |
Code function: 1_2_00000239A18E4CF0 |
1_2_00000239A18E4CF0 |
Source: C:\Windows\System32\wermgr.exe |
Code function: 1_2_00000239A18C1030 |
1_2_00000239A18C1030 |
Source: C:\Windows\System32\wermgr.exe |
Code function: 1_2_00000239A18DE47D |
1_2_00000239A18DE47D |
Source: C:\Windows\System32\wermgr.exe |
Code function: 1_2_00000239A18D73A0 |
1_2_00000239A18D73A0 |
Source: C:\Windows\System32\wermgr.exe |
Code function: 1_2_00000239A18C3BB0 |
1_2_00000239A18C3BB0 |
Source: C:\Windows\System32\wermgr.exe |
Code function: 1_2_00000239A18E33D0 |
1_2_00000239A18E33D0 |
Source: C:\Windows\System32\wermgr.exe |
Code function: 1_2_00000239A18DE3F0 |
1_2_00000239A18DE3F0 |
Source: C:\Windows\System32\wermgr.exe |
Code function: 1_2_00000239A18D17F0 |
1_2_00000239A18D17F0 |
Source: C:\Windows\System32\wermgr.exe |
Code function: 1_2_00000239A18D740C |
1_2_00000239A18D740C |
Source: C:\Windows\System32\wermgr.exe |
Code function: 1_2_00000239A18C4730 |
1_2_00000239A18C4730 |
Source: C:\Windows\System32\wermgr.exe |
Code function: 1_2_00000239A18C7340 |
1_2_00000239A18C7340 |
Source: C:\Windows\System32\wermgr.exe |
Code function: 1_2_00000239A18E5F60 |
1_2_00000239A18E5F60 |
Source: C:\Windows\System32\wermgr.exe |
Code function: 1_2_00000239A18D7760 |
1_2_00000239A18D7760 |
Source: C:\Windows\System32\wermgr.exe |
Code function: 1_2_00000239A18D1EA0 |
1_2_00000239A18D1EA0 |
Source: C:\Windows\System32\wermgr.exe |
Code function: 1_2_00000239A18E52C0 |
1_2_00000239A18E52C0 |
Source: C:\Windows\System32\wermgr.exe |
Code function: 1_2_00000239A18D5AC0 |
1_2_00000239A18D5AC0 |
Source: C:\Windows\System32\wermgr.exe |
Code function: 1_2_00000239A18D7EE0 |
1_2_00000239A18D7EE0 |
Source: C:\Windows\System32\wermgr.exe |
Code function: 1_2_00000239A18CF700 |
1_2_00000239A18CF700 |
Source: C:\Windows\System32\wermgr.exe |
Code function: 1_2_00000239A18E4B10 |
1_2_00000239A18E4B10 |
Source: C:\Windows\System32\wermgr.exe |
Code function: 1_2_00000239A18D9A80 |
1_2_00000239A18D9A80 |
Source: C:\Windows\System32\wermgr.exe |
Code function: 1_2_00000239A18CFE8E |
1_2_00000239A18CFE8E |
Source: C:\Windows\System32\wermgr.exe |
Code function: 1_2_00000239A18D51A0 |
1_2_00000239A18D51A0 |
Source: C:\Windows\System32\wermgr.exe |
Code function: 1_2_00000239A18E45D0 |
1_2_00000239A18E45D0 |
Source: C:\Windows\System32\wermgr.exe |
Code function: 1_2_00000239A18D35D0 |
1_2_00000239A18D35D0 |
Source: C:\Windows\System32\wermgr.exe |
Code function: 1_2_00000239A18C79D0 |
1_2_00000239A18C79D0 |
Source: C:\Windows\System32\wermgr.exe |
Code function: 1_2_00000239A18D0A00 |
1_2_00000239A18D0A00 |
Source: C:\Windows\System32\wermgr.exe |
Code function: 1_2_00000239A18DB920 |
1_2_00000239A18DB920 |
Source: C:\Windows\System32\wermgr.exe |
Code function: 1_2_00000239A18DED70 |
1_2_00000239A18DED70 |
Source: C:\Windows\System32\wermgr.exe |
Function Chain: threadCreated,threadDelayed,threadDelayed,userTimerSet,threadDelayed,threadDelayed,fileVolumeQueried,languageOrLocalQueried,languageOrLocalQueried,adjustToken,systemQueried,systemQueried,threadDelayed,threadDelayed,threadDelayed,mutantCreated,threadInformationSet,threadInformationSet,threadInformationSet,threadInformationSet,threadDelayed,threadDelayed |
Source: C:\Users\user\Desktop\dngqoAXyDd.exe |
Code function: __getptd,_LcidFromHexString,GetLocaleInfoA,_TestDefaultLanguage, |
0_2_0019A134 |
Source: C:\Users\user\Desktop\dngqoAXyDd.exe |
Code function: EnumSystemLocalesA, |
0_2_0019A1F6 |
Source: C:\Users\user\Desktop\dngqoAXyDd.exe |
Code function: _strlen,_strlen,_GetPrimaryLen,EnumSystemLocalesA, |
0_2_0019A220 |
Source: C:\Users\user\Desktop\dngqoAXyDd.exe |
Code function: _strlen,_GetPrimaryLen,EnumSystemLocalesA, |
0_2_0019A287 |
Source: C:\Users\user\Desktop\dngqoAXyDd.exe |
Code function: __getptd,_TranslateName,_GetLcidFromLangCountry,_GetLcidFromLanguage,_TranslateName,_GetLcidFromLangCountry,_GetLcidFromLanguage,_strlen,EnumSystemLocalesA,GetUserDefaultLCID,IsValidCodePage,IsValidLocale,GetLocaleInfoA,_strcpy_s,__invoke_watson,GetLocaleInfoA,GetLocaleInfoA,__itow_s, |
0_2_0019A2C3 |
Source: C:\Users\user\Desktop\dngqoAXyDd.exe |
Code function: __calloc_crt,__malloc_crt,_free,__malloc_crt,_free,_free,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___free_lconv_num,InterlockedDecrement,InterlockedDecrement,InterlockedDecrement,_free,_free, |
0_2_001995B5 |
Source: C:\Users\user\Desktop\dngqoAXyDd.exe |
Code function: GetLocaleInfoW,GetLocaleInfoW,_malloc,GetLocaleInfoW,WideCharToMultiByte,__freea, |
0_2_001A7650 |
Source: C:\Users\user\Desktop\dngqoAXyDd.exe |
Code function: ___crtGetLocaleInfoA,GetLastError,___crtGetLocaleInfoA,__calloc_crt,___crtGetLocaleInfoA,__calloc_crt,_free,_free,__invoke_watson,GetLocaleInfoW,GetLocaleInfoW,__calloc_crt,GetLocaleInfoW,_free,GetLocaleInfoW, |
0_2_001986AD |
Source: C:\Users\user\Desktop\dngqoAXyDd.exe |
Code function: _LocaleUpdate::_LocaleUpdate,__crtGetLocaleInfoA_stat, |
0_2_001A772A |
Source: C:\Users\user\Desktop\dngqoAXyDd.exe |
Code function: GetLocaleInfoA, |
0_2_00191742 |
Source: C:\Users\user\Desktop\dngqoAXyDd.exe |
Code function: __calloc_crt,__malloc_crt,_free,__malloc_crt,_free,_free,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___free_lconv_mon,_free,_free,_free,InterlockedDecrement,InterlockedDecrement,_free,_free, |
0_2_001998D3 |
Source: C:\Users\user\Desktop\dngqoAXyDd.exe |
Code function: GetLocaleInfoA,GetLocaleInfoA,_LocaleUpdate::_LocaleUpdate,___ascii_strnicmp,__tolower_l,__tolower_l, |
0_2_001A7918 |
Source: C:\Users\user\Desktop\dngqoAXyDd.exe |
Code function: ___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo, |
0_2_00198929 |
Source: C:\Users\user\Desktop\dngqoAXyDd.exe |
Code function: ___getlocaleinfo,__malloc_crt,__calloc_crt,__calloc_crt,__calloc_crt,__calloc_crt,GetCPInfo,___crtGetStringTypeA,___crtLCMapStringA,___crtLCMapStringA,_memmove,_memmove,_memmove,InterlockedDecrement,_free,_free,_free,_free,_free,_free,_free,_free,_free,InterlockedDecrement, |
0_2_0018FAA9 |
Source: C:\Users\user\Desktop\dngqoAXyDd.exe |
Code function: GetLocaleInfoW,GetLocaleInfoW,GetACP, |
0_2_00199D6C |
Source: C:\Users\user\Desktop\dngqoAXyDd.exe |
Code function: __getptd,_LcidFromHexString,GetLocaleInfoA, |
0_2_00199E61 |
Source: C:\Users\user\Desktop\dngqoAXyDd.exe |
Code function: GetLocaleInfoW,_GetPrimaryLen,_strlen, |
0_2_00199F08 |
Source: C:\Users\user\Desktop\dngqoAXyDd.exe |
Code function: __getptd,_LcidFromHexString,GetLocaleInfoA,GetLocaleInfoA,GetLocaleInfoA,_strlen,GetLocaleInfoA,_strlen,_TestDefaultLanguage, |
0_2_00199F63 |