Click to jump to signature section
Source: | Binary string: D:\Mktmp\NL1\Release\NL1.pdb source: hBB2KnTndI.exe, hBB2KnTndI.exe, 00000000.00000002.279205067.00000000004B7000.00000004.00000001.01000000.00000003.sdmp, AppLaunch.exe, 00000005.00000002.267846742.000000000042B000.00000002.00000400.00020000.00000000.sdmp |
Source: | Binary string: applaunch.pdb source: orxds.exe, orxds.exe, 00000007.00000000.265811134.0000000000DC1000.00000020.00000001.01000000.00000004.sdmp, orxds.exe.5.dr |
Source: C:\Users\user\Desktop\hBB2KnTndI.exe | Code function: 0_2_00424F00 FindFirstFileA,_errno,GetLastError,_errno,_errno,_errno,_errno,_errno, |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\AppLaunch.exe | Code function: 5_2_0041E292 FindFirstFileExW, |
Source: C:\Users\user\Desktop\hBB2KnTndI.exe | Code function: 4x nop then sub esp, 1Ch |
Source: C:\Users\user\Desktop\hBB2KnTndI.exe | Code function: 4x nop then push ebx |
Source: C:\Users\user\Desktop\hBB2KnTndI.exe | Code function: 4x nop then mov eax, dword ptr [esp+04h] |
Source: C:\Users\user\Desktop\hBB2KnTndI.exe | Code function: 4x nop then jmp 0046E320h |
Source: C:\Users\user\Desktop\hBB2KnTndI.exe | Code function: 4x nop then jmp 00484510h |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\AppLaunch.exe | Code function: 5_2_00407090 CreateMutexW,GetLastError,GetFileAttributesA,CreateFileA,InternetOpenA,InternetOpenUrlA,InternetReadFile,WriteFile,WriteFile,InternetReadFile,CloseHandle,InternetCloseHandle,InternetCloseHandle,InternetCloseHandle, |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\AppLaunch.exe | Code function: 5_2_00402150 RegOpenKeyExA,RegQueryValueExA,RegCloseKey,RegOpenKeyExA,RegSetValueExA,RegCloseKey,GdiplusStartup,GetDC,RegGetValueA,RegGetValueA,GetSystemMetrics,GetSystemMetrics,GetSystemMetrics,RegGetValueA,GetSystemMetrics,GetSystemMetrics,CreateCompatibleDC,CreateCompatibleBitmap,SelectObject,BitBlt,GdipCreateBitmapFromHBITMAP,GdipGetImageEncodersSize,GdipGetImageEncoders,GdipSaveImageToFile,SelectObject,DeleteObject,DeleteObject,DeleteObject,ReleaseDC,GdipDisposeImage,GdiplusShutdown, |
Source: C:\Users\user\Desktop\hBB2KnTndI.exe | Code function: 0_2_00468160 |
Source: C:\Users\user\Desktop\hBB2KnTndI.exe | Code function: 0_2_004CD137 |
Source: C:\Users\user\Desktop\hBB2KnTndI.exe | Code function: 0_2_0041C250 |
Source: C:\Users\user\Desktop\hBB2KnTndI.exe | Code function: 0_2_004503C0 |
Source: C:\Users\user\Desktop\hBB2KnTndI.exe | Code function: 0_2_004593D0 |
Source: C:\Users\user\Desktop\hBB2KnTndI.exe | Code function: 0_2_00454440 |
Source: C:\Users\user\Desktop\hBB2KnTndI.exe | Code function: 0_2_00466420 |
Source: C:\Users\user\Desktop\hBB2KnTndI.exe | Code function: 0_2_00467430 |
Source: C:\Users\user\Desktop\hBB2KnTndI.exe | Code function: 0_2_004BA540 |
Source: C:\Users\user\Desktop\hBB2KnTndI.exe | Code function: 0_2_0044B500 |
Source: C:\Users\user\Desktop\hBB2KnTndI.exe | Code function: 0_2_00456500 |
Source: C:\Users\user\Desktop\hBB2KnTndI.exe | Code function: 0_2_0044D5E0 |
Source: C:\Users\user\Desktop\hBB2KnTndI.exe | Code function: 0_2_004416C0 |
Source: C:\Users\user\Desktop\hBB2KnTndI.exe | Code function: 0_2_004656F0 |
Source: C:\Users\user\Desktop\hBB2KnTndI.exe | Code function: 0_2_004D87F0 |
Source: C:\Users\user\Desktop\hBB2KnTndI.exe | Code function: 0_2_0045A780 |
Source: C:\Users\user\Desktop\hBB2KnTndI.exe | Code function: 0_2_0041C8E0 |
Source: C:\Users\user\Desktop\hBB2KnTndI.exe | Code function: 0_2_004428E0 |
Source: C:\Users\user\Desktop\hBB2KnTndI.exe | Code function: 0_2_00457970 |
Source: C:\Users\user\Desktop\hBB2KnTndI.exe | Code function: 0_2_004439D0 |
Source: C:\Users\user\Desktop\hBB2KnTndI.exe | Code function: 0_2_0044AA40 |
Source: C:\Users\user\Desktop\hBB2KnTndI.exe | Code function: 0_2_0041CA70 |
Source: C:\Users\user\Desktop\hBB2KnTndI.exe | Code function: 0_2_0044CA70 |
Source: C:\Users\user\Desktop\hBB2KnTndI.exe | Code function: 0_2_0044EA00 |
Source: C:\Users\user\Desktop\hBB2KnTndI.exe | Code function: 0_2_00453A30 |
Source: C:\Users\user\Desktop\hBB2KnTndI.exe | Code function: 0_2_004DBB27 |
Source: C:\Users\user\Desktop\hBB2KnTndI.exe | Code function: 0_2_004DBC47 |
Source: C:\Users\user\Desktop\hBB2KnTndI.exe | Code function: 0_2_00420CD0 |
Source: C:\Users\user\Desktop\hBB2KnTndI.exe | Code function: 0_2_004D8C88 |
Source: C:\Users\user\Desktop\hBB2KnTndI.exe | Code function: 0_2_00425D40 |
Source: C:\Users\user\Desktop\hBB2KnTndI.exe | Code function: 0_2_00445DE0 |
Source: C:\Users\user\Desktop\hBB2KnTndI.exe | Code function: 0_2_00450DA0 |
Source: C:\Users\user\Desktop\hBB2KnTndI.exe | Code function: 0_2_00444DB0 |
Source: C:\Users\user\Desktop\hBB2KnTndI.exe | Code function: 0_2_00459DB0 |
Source: C:\Users\user\Desktop\hBB2KnTndI.exe | Code function: 0_2_004DDE50 |
Source: C:\Users\user\Desktop\hBB2KnTndI.exe | Code function: 0_2_004DCE9D |
Source: C:\Users\user\Desktop\hBB2KnTndI.exe | Code function: 0_2_00452F60 |
Source: C:\Users\user\Desktop\hBB2KnTndI.exe | Code function: 0_2_00454F10 |
Source: C:\Users\user\Desktop\hBB2KnTndI.exe | Code function: 0_2_0041AFC0 |
Source: C:\Users\user\Desktop\hBB2KnTndI.exe | Code function: 0_2_00414FF0 |
Source: C:\Users\user\Desktop\hBB2KnTndI.exe | Code function: 0_2_0043DFF0 |
Source: C:\Users\user\Desktop\hBB2KnTndI.exe | Code function: 0_2_00449F90 |
Source: C:\Users\user\Desktop\hBB2KnTndI.exe | Code function: 0_2_0044BFB0 |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\AppLaunch.exe | Code function: 5_2_00422868 |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\AppLaunch.exe | Code function: 5_2_00409877 |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\AppLaunch.exe | Code function: 5_2_00425827 |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\AppLaunch.exe | Code function: 5_2_00404120 |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\AppLaunch.exe | Code function: 5_2_00426A7D |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\AppLaunch.exe | Code function: 5_2_00427A30 |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\AppLaunch.exe | Code function: 5_2_004223D0 |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\AppLaunch.exe | Code function: 5_2_00416D17 |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\AppLaunch.exe | Code function: 5_2_00425707 |
Source: C:\Users\user\Desktop\hBB2KnTndI.exe | Code function: String function: 004C9BD0 appears 34 times |
Source: C:\Users\user\Desktop\hBB2KnTndI.exe | Code function: String function: 0040146E appears 85 times |
Source: C:\Users\user\Desktop\hBB2KnTndI.exe | Code function: String function: 004A57E0 appears 48 times |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\AppLaunch.exe | Code function: String function: 004123E0 appears 118 times |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\AppLaunch.exe | Code function: String function: 004137B0 appears 39 times |
Source: C:\Users\user\AppData\Local\Temp\a10b8dfb5f\orxds.exe | Code function: String function: 00DCFB02 appears 62 times |
Source: hBB2KnTndI.exe | Static PE information: Section: .text IMAGE_SCN_ALIGN_MASK, IMAGE_SCN_ALIGN_256BYTES, IMAGE_SCN_ALIGN_16BYTES, IMAGE_SCN_ALIGN_64BYTES, IMAGE_SCN_ALIGN_1BYTES, IMAGE_SCN_MEM_EXECUTE, IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_ALIGN_2048BYTES, IMAGE_SCN_ALIGN_1024BYTES, IMAGE_SCN_ALIGN_32BYTES, IMAGE_SCN_ALIGN_4BYTES, IMAGE_SCN_ALIGN_8BYTES, IMAGE_SCN_CNT_CODE, IMAGE_SCN_ALIGN_8192BYTES, IMAGE_SCN_ALIGN_4096BYTES, IMAGE_SCN_MEM_READ |
Source: unknown | Process created: C:\Users\user\Desktop\hBB2KnTndI.exe "C:\Users\user\Desktop\hBB2KnTndI.exe" |
Source: C:\Users\user\Desktop\hBB2KnTndI.exe | Process created: C:\Windows\System32\conhost.exe C:\Windows\system32\conhost.exe 0xffffffff -ForceV1 |
Source: C:\Users\user\Desktop\hBB2KnTndI.exe | Process created: C:\Windows\Microsoft.NET\Framework\v4.0.30319\AppLaunch.exe C:\Windows\Microsoft.NET\Framework\v4.0.30319\AppLaunch.exe |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\AppLaunch.exe | Process created: C:\Users\user\AppData\Local\Temp\a10b8dfb5f\orxds.exe "C:\Users\user\AppData\Local\Temp\a10b8dfb5f\orxds.exe" |
Source: C:\Users\user\Desktop\hBB2KnTndI.exe | Process created: C:\Windows\SysWOW64\WerFault.exe C:\Windows\SysWOW64\WerFault.exe -u -p 6464 -s 148 |
Source: C:\Users\user\Desktop\hBB2KnTndI.exe | Process created: C:\Windows\Microsoft.NET\Framework\v4.0.30319\AppLaunch.exe C:\Windows\Microsoft.NET\Framework\v4.0.30319\AppLaunch.exe |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\AppLaunch.exe | Process created: C:\Users\user\AppData\Local\Temp\a10b8dfb5f\orxds.exe "C:\Users\user\AppData\Local\Temp\a10b8dfb5f\orxds.exe" |
Source: C:\Windows\SysWOW64\WerFault.exe | Mutant created: \Sessions\1\BaseNamedObjects\Local\WERReportingForProcess6464 |
Source: C:\Windows\System32\conhost.exe | Mutant created: \Sessions\1\BaseNamedObjects\Local\SM0:6480:120:WilError_01 |
Source: | Binary string: D:\Mktmp\NL1\Release\NL1.pdb source: hBB2KnTndI.exe, hBB2KnTndI.exe, 00000000.00000002.279205067.00000000004B7000.00000004.00000001.01000000.00000003.sdmp, AppLaunch.exe, 00000005.00000002.267846742.000000000042B000.00000002.00000400.00020000.00000000.sdmp |
Source: | Binary string: applaunch.pdb source: orxds.exe, orxds.exe, 00000007.00000000.265811134.0000000000DC1000.00000020.00000001.01000000.00000004.sdmp, orxds.exe.5.dr |
Source: C:\Users\user\Desktop\hBB2KnTndI.exe | Code function: 0_2_004115A7 push eax; mov dword ptr [esp], ebx |
Source: C:\Users\user\Desktop\hBB2KnTndI.exe | Code function: 0_2_0046A160 push eax; mov dword ptr [esp], ebx |
Source: C:\Users\user\Desktop\hBB2KnTndI.exe | Code function: 0_2_0047D2D0 push eax; mov dword ptr [esp], ebx |
Source: C:\Users\user\Desktop\hBB2KnTndI.exe | Code function: 0_2_0047C3C0 push eax; mov dword ptr [esp], ebx |
Source: C:\Users\user\Desktop\hBB2KnTndI.exe | Code function: 0_2_00479530 push eax; mov dword ptr [esp], ebx |
Source: C:\Users\user\Desktop\hBB2KnTndI.exe | Code function: 0_2_0046A690 push eax; mov dword ptr [esp], ebx |
Source: C:\Users\user\Desktop\hBB2KnTndI.exe | Code function: 0_2_00479780 push eax; mov dword ptr [esp], ebx |
Source: C:\Users\user\Desktop\hBB2KnTndI.exe | Code function: 0_2_0047D920 push eax; mov dword ptr [esp], ebx |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\AppLaunch.exe | Code function: 5_2_004137F6 push ecx; ret |
Source: C:\Users\user\AppData\Local\Temp\a10b8dfb5f\orxds.exe | Code function: 7_2_00DCF8E8 push ecx; ret |
Source: C:\Users\user\AppData\Local\Temp\a10b8dfb5f\orxds.exe | Code function: 7_2_00DCFAD0 push ecx; ret |
Source: hBB2KnTndI.exe | Static PE information: section name: /4 |
Source: hBB2KnTndI.exe | Static PE information: section name: /14 |
Source: hBB2KnTndI.exe | Static PE information: section name: /29 |
Source: hBB2KnTndI.exe | Static PE information: section name: /41 |
Source: hBB2KnTndI.exe | Static PE information: section name: /55 |
Source: hBB2KnTndI.exe | Static PE information: section name: /67 |
Source: hBB2KnTndI.exe | Static PE information: section name: /80 |
Source: hBB2KnTndI.exe | Static PE information: section name: /91 |
Source: hBB2KnTndI.exe | Static PE information: section name: /102 |
Source: C:\Users\user\Desktop\hBB2KnTndI.exe | Code function: 0_2_00401340 GetModuleHandleA,LoadLibraryA,GetProcAddress,GetProcAddress,GetModuleHandleA,GetProcAddress,atexit, |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\AppLaunch.exe | Process information set: NOOPENFILEERRORBOX |
Source: C:\Windows\SysWOW64\WerFault.exe | Process information set: FAILCRITICALERRORS | NOGPFAULTERRORBOX |
Source: C:\Windows\SysWOW64\WerFault.exe | Process information set: NOOPENFILEERRORBOX |
Source: C:\Windows\SysWOW64\WerFault.exe | Process information set: NOOPENFILEERRORBOX |
Source: C:\Windows\SysWOW64\WerFault.exe | Process information set: NOOPENFILEERRORBOX |
Source: C:\Windows\SysWOW64\WerFault.exe | Process information set: NOOPENFILEERRORBOX |
Source: C:\Windows\SysWOW64\WerFault.exe | Process information set: NOOPENFILEERRORBOX |
Source: C:\Windows\SysWOW64\WerFault.exe | Process information set: NOOPENFILEERRORBOX |
Source: C:\Windows\SysWOW64\WerFault.exe | Process information set: NOOPENFILEERRORBOX |
Source: C:\Windows\SysWOW64\WerFault.exe | Process information set: NOOPENFILEERRORBOX |
Source: C:\Windows\SysWOW64\WerFault.exe | Process information set: NOOPENFILEERRORBOX |
Source: C:\Windows\SysWOW64\WerFault.exe | Process information set: NOOPENFILEERRORBOX |
Source: C:\Windows\SysWOW64\WerFault.exe | Process information set: NOOPENFILEERRORBOX |
Source: C:\Windows\SysWOW64\WerFault.exe | Process information set: NOOPENFILEERRORBOX |
Source: C:\Windows\SysWOW64\WerFault.exe | Process information set: NOOPENFILEERRORBOX |
Source: C:\Windows\SysWOW64\WerFault.exe | Process information set: NOOPENFILEERRORBOX |
Source: C:\Windows\SysWOW64\WerFault.exe | Process information set: NOOPENFILEERRORBOX |
Source: C:\Windows\SysWOW64\WerFault.exe | Process information set: NOOPENFILEERRORBOX |
Source: C:\Windows\SysWOW64\WerFault.exe | Process information set: NOOPENFILEERRORBOX |
Source: C:\Windows\SysWOW64\WerFault.exe | Process information set: NOOPENFILEERRORBOX |
Source: C:\Windows\SysWOW64\WerFault.exe | Process information set: NOOPENFILEERRORBOX |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\AppLaunch.exe | Code function: 5_2_00405230 GetVersionExW,GetModuleHandleA,GetProcAddress,GetSystemInfo, |
Source: C:\Users\user\Desktop\hBB2KnTndI.exe | Code function: 0_2_00424F00 FindFirstFileA,_errno,GetLastError,_errno,_errno,_errno,_errno,_errno, |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\AppLaunch.exe | Code function: 5_2_0041E292 FindFirstFileExW, |
Source: C:\Users\user\Desktop\hBB2KnTndI.exe | Code function: 0_2_00401340 GetModuleHandleA,LoadLibraryA,GetProcAddress,GetProcAddress,GetModuleHandleA,GetProcAddress,atexit, |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\AppLaunch.exe | Code function: 5_2_00402C50 DeleteObject,GetUserNameW,GetUserNameW,GetProcessHeap,GetProcessHeap,HeapAlloc,GetUserNameW,LookupAccountNameW,GetProcessHeap,HeapAlloc,GetProcessHeap,HeapAlloc,LookupAccountNameW,ConvertSidToStringSidW,GetProcessHeap,HeapFree,HeapFree,GetProcessHeap,HeapFree,GetProcessHeap,HeapFree,LocalFree, |
Source: C:\Users\user\Desktop\hBB2KnTndI.exe | Code function: 0_2_00411C06 mov eax, dword ptr fs:[00000030h] |
Source: C:\Users\user\Desktop\hBB2KnTndI.exe | Code function: 0_2_00411C06 mov eax, dword ptr fs:[00000030h] |
Source: C:\Users\user\Desktop\hBB2KnTndI.exe | Code function: 0_2_00411C06 mov eax, dword ptr fs:[00000030h] |
Source: C:\Users\user\Desktop\hBB2KnTndI.exe | Code function: 0_2_004CF542 mov eax, dword ptr fs:[00000030h] |
Source: C:\Users\user\Desktop\hBB2KnTndI.exe | Code function: 0_2_004CB7B1 mov eax, dword ptr fs:[00000030h] |
Source: C:\Users\user\Desktop\hBB2KnTndI.exe | Code function: 0_2_004EEBEC mov eax, dword ptr fs:[00000030h] |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\AppLaunch.exe | Code function: 5_2_00419122 mov eax, dword ptr fs:[00000030h] |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\AppLaunch.exe | Code function: 5_2_00415391 mov eax, dword ptr fs:[00000030h] |
Source: C:\Users\user\Desktop\hBB2KnTndI.exe | Process queried: DebugPort |
Source: C:\Users\user\Desktop\hBB2KnTndI.exe | Process queried: DebugPort |
Source: C:\Users\user\Desktop\hBB2KnTndI.exe | Code function: 0_2_004011A5 SetUnhandledExceptionFilter,_iob,_setmode,_setmode,_setmode,__p__fmode,__p__environ,KiUserExceptionDispatcher,_cexit,ExitProcess, |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\AppLaunch.exe | Code function: 5_2_00413738 SetUnhandledExceptionFilter, |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\AppLaunch.exe | Code function: 5_2_00413983 SetUnhandledExceptionFilter,UnhandledExceptionFilter,GetCurrentProcess,TerminateProcess, |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\AppLaunch.exe | Code function: 5_2_00417C96 IsDebuggerPresent,SetUnhandledExceptionFilter,UnhandledExceptionFilter, |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\AppLaunch.exe | Code function: 5_2_004135D3 IsProcessorFeaturePresent,IsDebuggerPresent,SetUnhandledExceptionFilter,UnhandledExceptionFilter, |
Source: C:\Users\user\AppData\Local\Temp\a10b8dfb5f\orxds.exe | Code function: 7_2_00DCF580 ?terminate@@YAXXZ,__crtSetUnhandledExceptionFilter, |
Source: C:\Users\user\Desktop\hBB2KnTndI.exe | Memory written: C:\Windows\Microsoft.NET\Framework\v4.0.30319\AppLaunch.exe base: 400000 |
Source: C:\Users\user\Desktop\hBB2KnTndI.exe | Memory written: C:\Windows\Microsoft.NET\Framework\v4.0.30319\AppLaunch.exe base: 46B1008 |
Source: C:\Users\user\Desktop\hBB2KnTndI.exe | Code function: 0_2_004EEC21 CreateProcessW,GetThreadContext,ReadProcessMemory,VirtualAlloc,VirtualAllocEx,WriteProcessMemory,VirtualProtectEx,VirtualProtectEx,VirtualFree,WriteProcessMemory,SetThreadContext,ResumeThread, |
Source: C:\Users\user\AppData\Local\Temp\a10b8dfb5f\orxds.exe | Code function: 7_2_00DC915E LoadLibraryExW,GetProcAddress,FreeLibrary,IsDebuggerPresent,DebugBreak, |
Source: C:\Users\user\Desktop\hBB2KnTndI.exe | Process created: C:\Windows\Microsoft.NET\Framework\v4.0.30319\AppLaunch.exe C:\Windows\Microsoft.NET\Framework\v4.0.30319\AppLaunch.exe |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\AppLaunch.exe | Process created: C:\Users\user\AppData\Local\Temp\a10b8dfb5f\orxds.exe "C:\Users\user\AppData\Local\Temp\a10b8dfb5f\orxds.exe" |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\AppLaunch.exe | Code function: 5_2_00413811 GetSystemTimeAsFileTime,GetCurrentThreadId,GetCurrentProcessId,QueryPerformanceCounter, |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\AppLaunch.exe | Code function: 5_2_00405230 GetVersionExW,GetModuleHandleA,GetProcAddress,GetSystemInfo, |
Source: Yara match | File source: 0.3.hBB2KnTndI.exe.8a0000.0.raw.unpack, type: UNPACKEDPE |
Source: Yara match | File source: 5.2.AppLaunch.exe.400000.0.unpack, type: UNPACKEDPE |
Source: Yara match | File source: 0.3.hBB2KnTndI.exe.8a0000.0.unpack, type: UNPACKEDPE |
Source: Yara match | File source: 0.0.hBB2KnTndI.exe.400000.1.unpack, type: UNPACKEDPE |
Source: Yara match | File source: 0.0.hBB2KnTndI.exe.400000.0.unpack, type: UNPACKEDPE |
Source: Yara match | File source: 0.2.hBB2KnTndI.exe.400000.0.unpack, type: UNPACKEDPE |
Source: Yara match | File source: 0.0.hBB2KnTndI.exe.400000.2.unpack, type: UNPACKEDPE |
Source: Yara match | File source: 00000000.00000003.262491711.00000000008A0000.00000040.00001000.00020000.00000000.sdmp, type: MEMORY |
Source: Yara match | File source: 00000000.00000000.264188526.00000000004B7000.00000004.00000001.01000000.00000003.sdmp, type: MEMORY |
Source: Yara match | File source: 00000005.00000002.267821297.0000000000401000.00000020.00000400.00020000.00000000.sdmp, type: MEMORY |
Source: Yara match | File source: 00000000.00000000.264842182.00000000004B7000.00000004.00000001.01000000.00000003.sdmp, type: MEMORY |
Source: Yara match | File source: 00000000.00000002.279205067.00000000004B7000.00000004.00000001.01000000.00000003.sdmp, type: MEMORY |