Click to jump to signature section
Source: C:\Users\user\AppData\Roaming\SystemWindows\WindowsService.exe | Avira: detection malicious, Label: TR/Dropper.Gen |
Source: a.exe | Static PE information: RELOCS_STRIPPED, EXECUTABLE_IMAGE, LINE_NUMS_STRIPPED, LOCAL_SYMS_STRIPPED, 32BIT_MACHINE |
Source: C:\Users\user\Desktop\a.exe | Code function: 0_2_004085D0 | 0_2_004085D0 |
Source: C:\Users\user\AppData\Roaming\SystemWindows\WindowsService.exe | Code function: 4_2_004085D0 | 4_2_004085D0 |
Source: C:\Users\user\AppData\Roaming\SystemWindows\WindowsService.exe | Code function: 5_2_004085D0 | 5_2_004085D0 |
Source: C:\Users\user\AppData\Roaming\SystemWindows\WindowsService.exe | Code function: 7_2_004085D0 | 7_2_004085D0 |
Source: a.exe | Static PE information: Resource name: RT_VERSION type: ARM COFF executable, no relocation info, not stripped, 52 sections, symbol offset=0x5f0053, 4522070 symbols, optional header size 82, created Sat Mar 7 05:34:56 1970 |
Source: WindowsService.exe.0.dr | Static PE information: Resource name: RT_VERSION type: ARM COFF executable, no relocation info, not stripped, 52 sections, symbol offset=0x5f0053, 4522070 symbols, optional header size 82, created Sat Mar 7 05:34:56 1970 |
Source: a.exe | Static PE information: RELOCS_STRIPPED, EXECUTABLE_IMAGE, LINE_NUMS_STRIPPED, LOCAL_SYMS_STRIPPED, 32BIT_MACHINE |
Source: C:\Windows\SysWOW64\cmd.exe | Process created: C:\Windows\SysWOW64\reg.exe REG ADD "HKCU\Software\Microsoft\Windows\CurrentVersion\Run" /v "sidebar" /t REG_SZ /d "C:\Users\user\AppData\Roaming\SystemWindows\WindowsService.exe" /f |
Source: classification engine | Classification label: mal80.winEXE@11/3@0/0 |
Source: C:\Users\user\AppData\Roaming\SystemWindows\WindowsService.exe | Mutant created: NULL |
Source: C:\Windows\System32\conhost.exe | Mutant created: \Sessions\1\BaseNamedObjects\Local\SM0:7352:120:WilError_03 |
Source: C:\Users\user\Desktop\a.exe | Process created: C:\Windows\SysWOW64\cmd.exe C:\Windows\system32\cmd.exe /c ""C:\Users\user\AppData\Local\Temp\HMIIU.bat" " |
Source: a.exe | ReversingLabs: Detection: 84% |
Source: a.exe | Virustotal: Detection: 76% |
Source: unknown | Process created: C:\Users\user\Desktop\a.exe "C:\Users\user\Desktop\a.exe" | |
Source: C:\Users\user\Desktop\a.exe | Process created: C:\Windows\SysWOW64\cmd.exe C:\Windows\system32\cmd.exe /c ""C:\Users\user\AppData\Local\Temp\HMIIU.bat" " | |
Source: C:\Windows\SysWOW64\cmd.exe | Process created: C:\Windows\System32\conhost.exe C:\Windows\system32\conhost.exe 0xffffffff -ForceV1 | |
Source: C:\Windows\SysWOW64\cmd.exe | Process created: C:\Windows\SysWOW64\reg.exe REG ADD "HKCU\Software\Microsoft\Windows\CurrentVersion\Run" /v "sidebar" /t REG_SZ /d "C:\Users\user\AppData\Roaming\SystemWindows\WindowsService.exe" /f | |
Source: C:\Users\user\Desktop\a.exe | Process created: C:\Users\user\AppData\Roaming\SystemWindows\WindowsService.exe "C:\Users\user\AppData\Roaming\SystemWindows\WindowsService.exe" | |
Source: unknown | Process created: C:\Users\user\AppData\Roaming\SystemWindows\WindowsService.exe "C:\Users\user\AppData\Roaming\SystemWindows\WindowsService.exe" | |
Source: unknown | Process created: C:\Users\user\AppData\Roaming\SystemWindows\WindowsService.exe "C:\Users\user\AppData\Roaming\SystemWindows\WindowsService.exe" | |
Source: C:\Users\user\Desktop\a.exe | Process created: C:\Windows\SysWOW64\cmd.exe C:\Windows\system32\cmd.exe /c ""C:\Users\user\AppData\Local\Temp\HMIIU.bat" " | Jump to behavior |
Source: C:\Users\user\Desktop\a.exe | Process created: C:\Users\user\AppData\Roaming\SystemWindows\WindowsService.exe "C:\Users\user\AppData\Roaming\SystemWindows\WindowsService.exe" | Jump to behavior |
Source: C:\Windows\SysWOW64\cmd.exe | Process created: C:\Windows\SysWOW64\reg.exe REG ADD "HKCU\Software\Microsoft\Windows\CurrentVersion\Run" /v "sidebar" /t REG_SZ /d "C:\Users\user\AppData\Roaming\SystemWindows\WindowsService.exe" /f | Jump to behavior |
Source: C:\Users\user\Desktop\a.exe | Section loaded: apphelp.dll | Jump to behavior |
Source: C:\Users\user\Desktop\a.exe | Section loaded: msvbvm60.dll | Jump to behavior |
Source: C:\Users\user\Desktop\a.exe | Section loaded: vb6zz.dll | Jump to behavior |
Source: C:\Users\user\Desktop\a.exe | Section loaded: kernel.appcore.dll | Jump to behavior |
Source: C:\Users\user\Desktop\a.exe | Section loaded: uxtheme.dll | Jump to behavior |
Source: C:\Users\user\Desktop\a.exe | Section loaded: sxs.dll | Jump to behavior |
Source: C:\Users\user\Desktop\a.exe | Section loaded: mpr.dll | Jump to behavior |
Source: C:\Users\user\Desktop\a.exe | Section loaded: scrrun.dll | Jump to behavior |
Source: C:\Users\user\Desktop\a.exe | Section loaded: version.dll | Jump to behavior |
Source: C:\Users\user\Desktop\a.exe | Section loaded: ntmarta.dll | Jump to behavior |
Source: C:\Users\user\Desktop\a.exe | Section loaded: windows.storage.dll | Jump to behavior |
Source: C:\Users\user\Desktop\a.exe | Section loaded: wldp.dll | Jump to behavior |
Source: C:\Users\user\Desktop\a.exe | Section loaded: propsys.dll | Jump to behavior |
Source: C:\Users\user\Desktop\a.exe | Section loaded: profapi.dll | Jump to behavior |
Source: C:\Users\user\Desktop\a.exe | Section loaded: edputil.dll | Jump to behavior |
Source: C:\Users\user\Desktop\a.exe | Section loaded: urlmon.dll | Jump to behavior |
Source: C:\Users\user\Desktop\a.exe | Section loaded: iertutil.dll | Jump to behavior |
Source: C:\Users\user\Desktop\a.exe | Section loaded: srvcli.dll | Jump to behavior |
Source: C:\Users\user\Desktop\a.exe | Section loaded: netutils.dll | Jump to behavior |
Source: C:\Users\user\Desktop\a.exe | Section loaded: windows.staterepositoryps.dll | Jump to behavior |
Source: C:\Users\user\Desktop\a.exe | Section loaded: sspicli.dll | Jump to behavior |
Source: C:\Users\user\Desktop\a.exe | Section loaded: wintypes.dll | Jump to behavior |
Source: C:\Users\user\Desktop\a.exe | Section loaded: appresolver.dll | Jump to behavior |
Source: C:\Users\user\Desktop\a.exe | Section loaded: bcp47langs.dll | Jump to behavior |
Source: C:\Users\user\Desktop\a.exe | Section loaded: slc.dll | Jump to behavior |
Source: C:\Users\user\Desktop\a.exe | Section loaded: userenv.dll | Jump to behavior |
Source: C:\Users\user\Desktop\a.exe | Section loaded: sppc.dll | Jump to behavior |
Source: C:\Users\user\Desktop\a.exe | Section loaded: onecorecommonproxystub.dll | Jump to behavior |
Source: C:\Users\user\Desktop\a.exe | Section loaded: onecoreuapcommonproxystub.dll | Jump to behavior |
Source: C:\Users\user\Desktop\a.exe | Section loaded: pcacli.dll | Jump to behavior |
Source: C:\Users\user\Desktop\a.exe | Section loaded: sfc_os.dll | Jump to behavior |
Source: C:\Users\user\Desktop\a.exe | Section loaded: lz32.dll | Jump to behavior |
Source: C:\Windows\SysWOW64\cmd.exe | Section loaded: cmdext.dll | Jump to behavior |
Source: C:\Users\user\AppData\Roaming\SystemWindows\WindowsService.exe | Section loaded: apphelp.dll | Jump to behavior |
Source: C:\Users\user\AppData\Roaming\SystemWindows\WindowsService.exe | Section loaded: msvbvm60.dll | Jump to behavior |
Source: C:\Users\user\AppData\Roaming\SystemWindows\WindowsService.exe | Section loaded: vb6zz.dll | Jump to behavior |
Source: C:\Users\user\AppData\Roaming\SystemWindows\WindowsService.exe | Section loaded: kernel.appcore.dll | Jump to behavior |
Source: C:\Users\user\AppData\Roaming\SystemWindows\WindowsService.exe | Section loaded: uxtheme.dll | Jump to behavior |
Source: C:\Users\user\AppData\Roaming\SystemWindows\WindowsService.exe | Section loaded: sxs.dll | Jump to behavior |
Source: C:\Users\user\AppData\Roaming\SystemWindows\WindowsService.exe | Section loaded: mpr.dll | Jump to behavior |
Source: C:\Users\user\AppData\Roaming\SystemWindows\WindowsService.exe | Section loaded: scrrun.dll | Jump to behavior |
Source: C:\Users\user\AppData\Roaming\SystemWindows\WindowsService.exe | Section loaded: version.dll | Jump to behavior |
Source: C:\Users\user\AppData\Roaming\SystemWindows\WindowsService.exe | Section loaded: windows.storage.dll | Jump to behavior |
Source: C:\Users\user\AppData\Roaming\SystemWindows\WindowsService.exe | Section loaded: wldp.dll | Jump to behavior |
Source: C:\Users\user\AppData\Roaming\SystemWindows\WindowsService.exe | Section loaded: mpr.dll | Jump to behavior |
Source: C:\Users\user\AppData\Roaming\SystemWindows\WindowsService.exe | Section loaded: scrrun.dll | Jump to behavior |
Source: C:\Users\user\AppData\Roaming\SystemWindows\WindowsService.exe | Section loaded: version.dll | Jump to behavior |
Source: C:\Users\user\AppData\Roaming\SystemWindows\WindowsService.exe | Section loaded: msvbvm60.dll | Jump to behavior |
Source: C:\Users\user\AppData\Roaming\SystemWindows\WindowsService.exe | Section loaded: vb6zz.dll | Jump to behavior |
Source: C:\Users\user\AppData\Roaming\SystemWindows\WindowsService.exe | Section loaded: kernel.appcore.dll | Jump to behavior |
Source: C:\Users\user\AppData\Roaming\SystemWindows\WindowsService.exe | Section loaded: uxtheme.dll | Jump to behavior |
Source: C:\Users\user\AppData\Roaming\SystemWindows\WindowsService.exe | Section loaded: sxs.dll | Jump to behavior |
Source: C:\Users\user\AppData\Roaming\SystemWindows\WindowsService.exe | Section loaded: mpr.dll | Jump to behavior |
Source: C:\Users\user\AppData\Roaming\SystemWindows\WindowsService.exe | Section loaded: scrrun.dll | Jump to behavior |
Source: C:\Users\user\AppData\Roaming\SystemWindows\WindowsService.exe | Section loaded: version.dll | Jump to behavior |
Source: C:\Users\user\AppData\Roaming\SystemWindows\WindowsService.exe | Section loaded: msvbvm60.dll | Jump to behavior |
Source: C:\Users\user\AppData\Roaming\SystemWindows\WindowsService.exe | Section loaded: vb6zz.dll | Jump to behavior |
Source: C:\Users\user\AppData\Roaming\SystemWindows\WindowsService.exe | Section loaded: kernel.appcore.dll | Jump to behavior |
Source: C:\Users\user\AppData\Roaming\SystemWindows\WindowsService.exe | Section loaded: uxtheme.dll | Jump to behavior |
Source: C:\Users\user\AppData\Roaming\SystemWindows\WindowsService.exe | Section loaded: sxs.dll | Jump to behavior |
Source: C:\Users\user\AppData\Roaming\SystemWindows\WindowsService.exe | Section loaded: mpr.dll | Jump to behavior |
Source: C:\Users\user\AppData\Roaming\SystemWindows\WindowsService.exe | Section loaded: scrrun.dll | Jump to behavior |
Source: C:\Users\user\AppData\Roaming\SystemWindows\WindowsService.exe | Section loaded: version.dll | Jump to behavior |
Source: C:\Users\user\Desktop\a.exe | Code function: 0_2_00401BC4 push 00401100h; ret | 0_2_00401BD7 |
Source: C:\Users\user\Desktop\a.exe | Code function: 0_2_00401A88 push 00401100h; ret | 0_2_00401B87 |
Source: C:\Users\user\Desktop\a.exe | Code function: 0_2_00401B88 push 00401100h; ret | 0_2_00401B9B |
Source: C:\Users\user\Desktop\a.exe | Code function: 0_2_00401B9C push 00401100h; ret | 0_2_00401BAF |
Source: C:\Users\user\Desktop\a.exe | Code function: 0_2_00401BB0 push 00401100h; ret | 0_2_00401BC3 |
Source: C:\Users\user\AppData\Roaming\SystemWindows\WindowsService.exe | Code function: 4_2_00401BC4 push 00401100h; ret | 4_2_00401BD7 |
Source: C:\Users\user\AppData\Roaming\SystemWindows\WindowsService.exe | Code function: 4_2_00401A88 push 00401100h; ret | 4_2_00401B87 |
Source: C:\Users\user\AppData\Roaming\SystemWindows\WindowsService.exe | Code function: 4_2_00401B88 push 00401100h; ret | 4_2_00401B9B |
Source: C:\Users\user\AppData\Roaming\SystemWindows\WindowsService.exe | Code function: 4_2_00401B9C push 00401100h; ret | 4_2_00401BAF |
Source: C:\Users\user\AppData\Roaming\SystemWindows\WindowsService.exe | Code function: 4_2_00401BB0 push 00401100h; ret | 4_2_00401BC3 |
Source: C:\Users\user\AppData\Roaming\SystemWindows\WindowsService.exe | Code function: 5_2_00401BC4 push 00401100h; ret | 5_2_00401BD7 |
Source: C:\Users\user\AppData\Roaming\SystemWindows\WindowsService.exe | Code function: 5_2_00401A88 push 00401100h; ret | 5_2_00401B87 |
Source: C:\Users\user\AppData\Roaming\SystemWindows\WindowsService.exe | Code function: 5_2_00401B88 push 00401100h; ret | 5_2_00401B9B |
Source: C:\Users\user\AppData\Roaming\SystemWindows\WindowsService.exe | Code function: 5_2_00401B9C push 00401100h; ret | 5_2_00401BAF |
Source: C:\Users\user\AppData\Roaming\SystemWindows\WindowsService.exe | Code function: 5_2_00401BB0 push 00401100h; ret | 5_2_00401BC3 |
Source: C:\Users\user\AppData\Roaming\SystemWindows\WindowsService.exe | Code function: 7_2_00401BC4 push 00401100h; ret | 7_2_00401BD7 |
Source: C:\Users\user\AppData\Roaming\SystemWindows\WindowsService.exe | Code function: 7_2_00401A88 push 00401100h; ret | 7_2_00401B87 |
Source: C:\Users\user\AppData\Roaming\SystemWindows\WindowsService.exe | Code function: 7_2_00401B88 push 00401100h; ret | 7_2_00401B9B |
Source: C:\Users\user\AppData\Roaming\SystemWindows\WindowsService.exe | Code function: 7_2_00401B9C push 00401100h; ret | 7_2_00401BAF |
Source: C:\Users\user\AppData\Roaming\SystemWindows\WindowsService.exe | Code function: 7_2_00401BB0 push 00401100h; ret | 7_2_00401BC3 |
Source: initial sample | Static PE information: section name: UPX0 |
Source: initial sample | Static PE information: section name: UPX1 |
Source: initial sample | Static PE information: section name: UPX0 |
Source: initial sample | Static PE information: section name: UPX1 |
Source: C:\Windows\SysWOW64\reg.exe | Registry value created or modified: HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run sidebar | Jump to behavior |
Source: C:\Windows\SysWOW64\reg.exe | Registry value created or modified: HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run sidebar | Jump to behavior |
Source: C:\Users\user\Desktop\a.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\a.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\a.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\a.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\a.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\a.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\a.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\a.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\a.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\a.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\a.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\a.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\a.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\a.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\a.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\a.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\a.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\a.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\a.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\a.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\a.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\a.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\a.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\cmd.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\AppData\Roaming\SystemWindows\WindowsService.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\AppData\Roaming\SystemWindows\WindowsService.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\AppData\Roaming\SystemWindows\WindowsService.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\AppData\Roaming\SystemWindows\WindowsService.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\AppData\Roaming\SystemWindows\WindowsService.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\AppData\Roaming\SystemWindows\WindowsService.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\AppData\Roaming\SystemWindows\WindowsService.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\AppData\Roaming\SystemWindows\WindowsService.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\AppData\Roaming\SystemWindows\WindowsService.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\AppData\Roaming\SystemWindows\WindowsService.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\AppData\Roaming\SystemWindows\WindowsService.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\AppData\Roaming\SystemWindows\WindowsService.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\AppData\Roaming\SystemWindows\WindowsService.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\AppData\Roaming\SystemWindows\WindowsService.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\AppData\Roaming\SystemWindows\WindowsService.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\System32\conhost.exe | Last function: Thread delayed |
Source: C:\Users\user\Desktop\a.exe | Process created: C:\Windows\SysWOW64\cmd.exe C:\Windows\system32\cmd.exe /c ""C:\Users\user\AppData\Local\Temp\HMIIU.bat" " | Jump to behavior |
Source: C:\Users\user\Desktop\a.exe | Process created: C:\Users\user\AppData\Roaming\SystemWindows\WindowsService.exe "C:\Users\user\AppData\Roaming\SystemWindows\WindowsService.exe" | Jump to behavior |
Source: C:\Windows\SysWOW64\cmd.exe | Process created: C:\Windows\SysWOW64\reg.exe REG ADD "HKCU\Software\Microsoft\Windows\CurrentVersion\Run" /v "sidebar" /t REG_SZ /d "C:\Users\user\AppData\Roaming\SystemWindows\WindowsService.exe" /f | Jump to behavior |