Windows Analysis Report
Copy10330520PDF.exe

Overview

General Information

Sample name: Copy10330520PDF.exe
Analysis ID: 1526379
MD5: 54ce77b9385fd7750d737f5af323ab34
SHA1: 01d494636d190d2b42e5edd1660b92519fcfeee4
SHA256: b441b07b39a642c7298e1127c9daf37ef9c1492148997a7f7e83fda9fcb908b1
Tags: exeuser-abuse_ch
Infos:

Detection

Score: 76
Range: 0 - 100
Whitelisted: false
Confidence: 100%

Signatures

Antivirus / Scanner detection for submitted sample
Multi AV Scanner detection for domain / URL
Multi AV Scanner detection for submitted file
.NET source code contains potential unpacker
AI detected suspicious sample
Machine Learning detection for sample
Abnormal high CPU Usage
Allocates memory with a write watch (potentially for evading sandboxes)
Contains long sleeps (>= 3 min)
Enables debug privileges
Found a high number of Window / User specific system calls (may be a loop to detect user behavior)
HTTP GET or POST without a user agent
IP address seen in connection with other malware
May sleep (evasive loops) to hinder dynamic analysis
PE / OLE file has an invalid certificate
Queries the volume information (name, serial number etc) of a device
Sample file is different than original file name gathered from version info
Uses 32bit PE files

Classification

AV Detection

barindex
Source: Copy10330520PDF.exe Avira: detected
Source: http://98.142.254.109 Virustotal: Detection: 5% Perma Link
Source: Copy10330520PDF.exe Virustotal: Detection: 60% Perma Link
Source: Copy10330520PDF.exe ReversingLabs: Detection: 63%
Source: Submited Sample Integrated Neural Analysis Model: Matched 99.9% probability
Source: Copy10330520PDF.exe Joe Sandbox ML: detected
Source: Copy10330520PDF.exe Static PE information: EXECUTABLE_IMAGE, 32BIT_MACHINE
Source: Copy10330520PDF.exe Static PE information: HIGH_ENTROPY_VA, DYNAMIC_BASE, NX_COMPAT, NO_SEH, TERMINAL_SERVER_AWARE
Source: global traffic HTTP traffic detected: GET /ii/Kpcwtduh.mp4 HTTP/1.1Host: 98.142.254.109Connection: Keep-Alive
Source: global traffic HTTP traffic detected: GET /ii/Kpcwtduh.mp4 HTTP/1.1Host: 98.142.254.109Connection: Keep-Alive
Source: global traffic HTTP traffic detected: GET /ii/Kpcwtduh.mp4 HTTP/1.1Host: 98.142.254.109Connection: Keep-Alive
Source: global traffic HTTP traffic detected: GET /ii/Kpcwtduh.mp4 HTTP/1.1Host: 98.142.254.109Connection: Keep-Alive
Source: global traffic HTTP traffic detected: GET /ii/Kpcwtduh.mp4 HTTP/1.1Host: 98.142.254.109Connection: Keep-Alive
Source: global traffic HTTP traffic detected: GET /ii/Kpcwtduh.mp4 HTTP/1.1Host: 98.142.254.109Connection: Keep-Alive
Source: global traffic HTTP traffic detected: GET /ii/Kpcwtduh.mp4 HTTP/1.1Host: 98.142.254.109Connection: Keep-Alive
Source: global traffic HTTP traffic detected: GET /ii/Kpcwtduh.mp4 HTTP/1.1Host: 98.142.254.109Connection: Keep-Alive
Source: global traffic HTTP traffic detected: GET /ii/Kpcwtduh.mp4 HTTP/1.1Host: 98.142.254.109Connection: Keep-Alive
Source: global traffic HTTP traffic detected: GET /ii/Kpcwtduh.mp4 HTTP/1.1Host: 98.142.254.109Connection: Keep-Alive
Source: global traffic HTTP traffic detected: GET /ii/Kpcwtduh.mp4 HTTP/1.1Host: 98.142.254.109Connection: Keep-Alive
Source: global traffic HTTP traffic detected: GET /ii/Kpcwtduh.mp4 HTTP/1.1Host: 98.142.254.109Connection: Keep-Alive
Source: global traffic HTTP traffic detected: GET /ii/Kpcwtduh.mp4 HTTP/1.1Host: 98.142.254.109Connection: Keep-Alive
Source: global traffic HTTP traffic detected: GET /ii/Kpcwtduh.mp4 HTTP/1.1Host: 98.142.254.109Connection: Keep-Alive
Source: global traffic HTTP traffic detected: GET /ii/Kpcwtduh.mp4 HTTP/1.1Host: 98.142.254.109Connection: Keep-Alive
Source: global traffic HTTP traffic detected: GET /ii/Kpcwtduh.mp4 HTTP/1.1Host: 98.142.254.109Connection: Keep-Alive
Source: global traffic HTTP traffic detected: GET /ii/Kpcwtduh.mp4 HTTP/1.1Host: 98.142.254.109Connection: Keep-Alive
Source: global traffic HTTP traffic detected: GET /ii/Kpcwtduh.mp4 HTTP/1.1Host: 98.142.254.109Connection: Keep-Alive
Source: global traffic HTTP traffic detected: GET /ii/Kpcwtduh.mp4 HTTP/1.1Host: 98.142.254.109Connection: Keep-Alive
Source: global traffic HTTP traffic detected: GET /ii/Kpcwtduh.mp4 HTTP/1.1Host: 98.142.254.109Connection: Keep-Alive
Source: global traffic HTTP traffic detected: GET /ii/Kpcwtduh.mp4 HTTP/1.1Host: 98.142.254.109Connection: Keep-Alive
Source: global traffic HTTP traffic detected: GET /ii/Kpcwtduh.mp4 HTTP/1.1Host: 98.142.254.109Connection: Keep-Alive
Source: global traffic HTTP traffic detected: GET /ii/Kpcwtduh.mp4 HTTP/1.1Host: 98.142.254.109Connection: Keep-Alive
Source: global traffic HTTP traffic detected: GET /ii/Kpcwtduh.mp4 HTTP/1.1Host: 98.142.254.109Connection: Keep-Alive
Source: Joe Sandbox View IP Address: 98.142.254.109 98.142.254.109
Source: unknown TCP traffic detected without corresponding DNS query: 98.142.254.109
Source: unknown TCP traffic detected without corresponding DNS query: 98.142.254.109
Source: unknown TCP traffic detected without corresponding DNS query: 98.142.254.109
Source: unknown TCP traffic detected without corresponding DNS query: 98.142.254.109
Source: unknown TCP traffic detected without corresponding DNS query: 98.142.254.109
Source: unknown TCP traffic detected without corresponding DNS query: 98.142.254.109
Source: unknown TCP traffic detected without corresponding DNS query: 98.142.254.109
Source: unknown TCP traffic detected without corresponding DNS query: 98.142.254.109
Source: unknown TCP traffic detected without corresponding DNS query: 98.142.254.109
Source: unknown TCP traffic detected without corresponding DNS query: 98.142.254.109
Source: unknown TCP traffic detected without corresponding DNS query: 98.142.254.109
Source: unknown TCP traffic detected without corresponding DNS query: 98.142.254.109
Source: unknown TCP traffic detected without corresponding DNS query: 98.142.254.109
Source: unknown TCP traffic detected without corresponding DNS query: 98.142.254.109
Source: unknown TCP traffic detected without corresponding DNS query: 98.142.254.109
Source: unknown TCP traffic detected without corresponding DNS query: 98.142.254.109
Source: unknown TCP traffic detected without corresponding DNS query: 98.142.254.109
Source: unknown TCP traffic detected without corresponding DNS query: 98.142.254.109
Source: unknown TCP traffic detected without corresponding DNS query: 98.142.254.109
Source: unknown TCP traffic detected without corresponding DNS query: 98.142.254.109
Source: unknown TCP traffic detected without corresponding DNS query: 98.142.254.109
Source: unknown TCP traffic detected without corresponding DNS query: 98.142.254.109
Source: unknown TCP traffic detected without corresponding DNS query: 98.142.254.109
Source: unknown TCP traffic detected without corresponding DNS query: 98.142.254.109
Source: unknown TCP traffic detected without corresponding DNS query: 98.142.254.109
Source: unknown TCP traffic detected without corresponding DNS query: 98.142.254.109
Source: unknown TCP traffic detected without corresponding DNS query: 98.142.254.109
Source: unknown TCP traffic detected without corresponding DNS query: 98.142.254.109
Source: unknown TCP traffic detected without corresponding DNS query: 98.142.254.109
Source: unknown TCP traffic detected without corresponding DNS query: 98.142.254.109
Source: unknown TCP traffic detected without corresponding DNS query: 98.142.254.109
Source: unknown TCP traffic detected without corresponding DNS query: 98.142.254.109
Source: unknown TCP traffic detected without corresponding DNS query: 98.142.254.109
Source: unknown TCP traffic detected without corresponding DNS query: 98.142.254.109
Source: unknown TCP traffic detected without corresponding DNS query: 98.142.254.109
Source: unknown TCP traffic detected without corresponding DNS query: 98.142.254.109
Source: unknown TCP traffic detected without corresponding DNS query: 98.142.254.109
Source: unknown TCP traffic detected without corresponding DNS query: 98.142.254.109
Source: unknown TCP traffic detected without corresponding DNS query: 98.142.254.109
Source: unknown TCP traffic detected without corresponding DNS query: 98.142.254.109
Source: unknown TCP traffic detected without corresponding DNS query: 98.142.254.109
Source: unknown TCP traffic detected without corresponding DNS query: 98.142.254.109
Source: unknown TCP traffic detected without corresponding DNS query: 98.142.254.109
Source: unknown TCP traffic detected without corresponding DNS query: 98.142.254.109
Source: unknown TCP traffic detected without corresponding DNS query: 98.142.254.109
Source: unknown TCP traffic detected without corresponding DNS query: 98.142.254.109
Source: unknown TCP traffic detected without corresponding DNS query: 98.142.254.109
Source: unknown TCP traffic detected without corresponding DNS query: 98.142.254.109
Source: unknown TCP traffic detected without corresponding DNS query: 98.142.254.109
Source: unknown TCP traffic detected without corresponding DNS query: 98.142.254.109
Source: global traffic HTTP traffic detected: GET /ii/Kpcwtduh.mp4 HTTP/1.1Host: 98.142.254.109Connection: Keep-Alive
Source: global traffic HTTP traffic detected: GET /ii/Kpcwtduh.mp4 HTTP/1.1Host: 98.142.254.109Connection: Keep-Alive
Source: global traffic HTTP traffic detected: GET /ii/Kpcwtduh.mp4 HTTP/1.1Host: 98.142.254.109Connection: Keep-Alive
Source: global traffic HTTP traffic detected: GET /ii/Kpcwtduh.mp4 HTTP/1.1Host: 98.142.254.109Connection: Keep-Alive
Source: global traffic HTTP traffic detected: GET /ii/Kpcwtduh.mp4 HTTP/1.1Host: 98.142.254.109Connection: Keep-Alive
Source: global traffic HTTP traffic detected: GET /ii/Kpcwtduh.mp4 HTTP/1.1Host: 98.142.254.109Connection: Keep-Alive
Source: global traffic HTTP traffic detected: GET /ii/Kpcwtduh.mp4 HTTP/1.1Host: 98.142.254.109Connection: Keep-Alive
Source: global traffic HTTP traffic detected: GET /ii/Kpcwtduh.mp4 HTTP/1.1Host: 98.142.254.109Connection: Keep-Alive
Source: global traffic HTTP traffic detected: GET /ii/Kpcwtduh.mp4 HTTP/1.1Host: 98.142.254.109Connection: Keep-Alive
Source: global traffic HTTP traffic detected: GET /ii/Kpcwtduh.mp4 HTTP/1.1Host: 98.142.254.109Connection: Keep-Alive
Source: global traffic HTTP traffic detected: GET /ii/Kpcwtduh.mp4 HTTP/1.1Host: 98.142.254.109Connection: Keep-Alive
Source: global traffic HTTP traffic detected: GET /ii/Kpcwtduh.mp4 HTTP/1.1Host: 98.142.254.109Connection: Keep-Alive
Source: global traffic HTTP traffic detected: GET /ii/Kpcwtduh.mp4 HTTP/1.1Host: 98.142.254.109Connection: Keep-Alive
Source: global traffic HTTP traffic detected: GET /ii/Kpcwtduh.mp4 HTTP/1.1Host: 98.142.254.109Connection: Keep-Alive
Source: global traffic HTTP traffic detected: GET /ii/Kpcwtduh.mp4 HTTP/1.1Host: 98.142.254.109Connection: Keep-Alive
Source: global traffic HTTP traffic detected: GET /ii/Kpcwtduh.mp4 HTTP/1.1Host: 98.142.254.109Connection: Keep-Alive
Source: global traffic HTTP traffic detected: GET /ii/Kpcwtduh.mp4 HTTP/1.1Host: 98.142.254.109Connection: Keep-Alive
Source: global traffic HTTP traffic detected: GET /ii/Kpcwtduh.mp4 HTTP/1.1Host: 98.142.254.109Connection: Keep-Alive
Source: global traffic HTTP traffic detected: GET /ii/Kpcwtduh.mp4 HTTP/1.1Host: 98.142.254.109Connection: Keep-Alive
Source: global traffic HTTP traffic detected: GET /ii/Kpcwtduh.mp4 HTTP/1.1Host: 98.142.254.109Connection: Keep-Alive
Source: global traffic HTTP traffic detected: GET /ii/Kpcwtduh.mp4 HTTP/1.1Host: 98.142.254.109Connection: Keep-Alive
Source: global traffic HTTP traffic detected: GET /ii/Kpcwtduh.mp4 HTTP/1.1Host: 98.142.254.109Connection: Keep-Alive
Source: global traffic HTTP traffic detected: GET /ii/Kpcwtduh.mp4 HTTP/1.1Host: 98.142.254.109Connection: Keep-Alive
Source: global traffic HTTP traffic detected: GET /ii/Kpcwtduh.mp4 HTTP/1.1Host: 98.142.254.109Connection: Keep-Alive
Source: Copy10330520PDF.exe, 00000000.00000002.3844939876.0000000002DDA000.00000004.00000800.00020000.00000000.sdmp, Copy10330520PDF.exe, 00000000.00000002.3844939876.0000000002E26000.00000004.00000800.00020000.00000000.sdmp String found in binary or memory: http://98.142.254.109
Source: Copy10330520PDF.exe String found in binary or memory: http://98.142.254.109/ii/Kpcwtduh.mp4
Source: Copy10330520PDF.exe, 00000000.00000002.3844212648.0000000000F5E000.00000004.00000020.00020000.00000000.sdmp String found in binary or memory: http://98.142.254.109/ii/Kpcwtduh.mp40
Source: Copy10330520PDF.exe, 00000000.00000002.3844939876.0000000002E5C000.00000004.00000800.00020000.00000000.sdmp, Copy10330520PDF.exe, 00000000.00000002.3844939876.0000000002E64000.00000004.00000800.00020000.00000000.sdmp, Copy10330520PDF.exe, 00000000.00000002.3844939876.0000000002E6C000.00000004.00000800.00020000.00000000.sdmp, Copy10330520PDF.exe, 00000000.00000002.3844939876.0000000002D71000.00000004.00000800.00020000.00000000.sdmp, Copy10330520PDF.exe, 00000000.00000002.3844939876.0000000002E38000.00000004.00000800.00020000.00000000.sdmp, Copy10330520PDF.exe, 00000000.00000002.3844939876.0000000002E1E000.00000004.00000800.00020000.00000000.sdmp, Copy10330520PDF.exe, 00000000.00000002.3844939876.0000000002DDA000.00000004.00000800.00020000.00000000.sdmp, Copy10330520PDF.exe, 00000000.00000002.3844939876.0000000002E74000.00000004.00000800.00020000.00000000.sdmp, Copy10330520PDF.exe, 00000000.00000002.3844939876.0000000002E26000.00000004.00000800.00020000.00000000.sdmp String found in binary or memory: http://98.142.254.109/ii/Kpcwtduh.mp4P
Source: Copy10330520PDF.exe, 00000000.00000002.3844939876.0000000002D71000.00000004.00000800.00020000.00000000.sdmp String found in binary or memory: http://98.142.254.109/ii/Kpcwtduh.mp4t
Source: Copy10330520PDF.exe, 00000000.00000002.3844939876.0000000002E5C000.00000004.00000800.00020000.00000000.sdmp, Copy10330520PDF.exe, 00000000.00000002.3844939876.0000000002E64000.00000004.00000800.00020000.00000000.sdmp, Copy10330520PDF.exe, 00000000.00000002.3844939876.0000000002E6C000.00000004.00000800.00020000.00000000.sdmp, Copy10330520PDF.exe, 00000000.00000002.3844939876.0000000002DFC000.00000004.00000800.00020000.00000000.sdmp, Copy10330520PDF.exe, 00000000.00000002.3844939876.0000000002E1E000.00000004.00000800.00020000.00000000.sdmp, Copy10330520PDF.exe, 00000000.00000002.3844939876.0000000002DF5000.00000004.00000800.00020000.00000000.sdmp, Copy10330520PDF.exe, 00000000.00000002.3844939876.0000000002DDA000.00000004.00000800.00020000.00000000.sdmp, Copy10330520PDF.exe, 00000000.00000002.3844939876.0000000002E1A000.00000004.00000800.00020000.00000000.sdmp, Copy10330520PDF.exe, 00000000.00000002.3844939876.0000000002E26000.00000004.00000800.00020000.00000000.sdmp String found in binary or memory: http://98.142.254.109D
Source: Copy10330520PDF.exe String found in binary or memory: http://cacerts.digicert.com/DigiCertAssuredIDRootCA.crt0
Source: Copy10330520PDF.exe String found in binary or memory: http://cacerts.digicert.com/DigiCertSHA2AssuredIDCodeSigningCA.crt0
Source: Copy10330520PDF.exe String found in binary or memory: http://crl.thawte.com/ThawteTimestampingCA.crl0
Source: Copy10330520PDF.exe String found in binary or memory: http://crl3.digicert.com/DigiCertAssuredIDRootCA.crl0O
Source: Copy10330520PDF.exe String found in binary or memory: http://crl3.digicert.com/sha2-assured-cs-g1.crl05
Source: Copy10330520PDF.exe String found in binary or memory: http://crl4.digicert.com/DigiCertAssuredIDRootCA.crl0:
Source: Copy10330520PDF.exe String found in binary or memory: http://crl4.digicert.com/sha2-assured-cs-g1.crl0L
Source: Copy10330520PDF.exe String found in binary or memory: http://ocsp.digicert.com0C
Source: Copy10330520PDF.exe String found in binary or memory: http://ocsp.digicert.com0N
Source: Copy10330520PDF.exe String found in binary or memory: http://ocsp.thawte.com0
Source: Copy10330520PDF.exe String found in binary or memory: http://s.symcb.com/universal-root.crl0
Source: Copy10330520PDF.exe String found in binary or memory: http://s.symcd.com06
Source: Copy10330520PDF.exe, 00000000.00000002.3844939876.0000000002DDA000.00000004.00000800.00020000.00000000.sdmp String found in binary or memory: http://schemas.xmlsoap.org/ws/2005/05/identity/claims/name
Source: Copy10330520PDF.exe String found in binary or memory: http://ts-aia.ws.symantec.com/sha256-tss-ca.cer0(
Source: Copy10330520PDF.exe String found in binary or memory: http://ts-aia.ws.symantec.com/tss-ca-g2.cer0
Source: Copy10330520PDF.exe String found in binary or memory: http://ts-crl.ws.symantec.com/sha256-tss-ca.crl0
Source: Copy10330520PDF.exe String found in binary or memory: http://ts-crl.ws.symantec.com/tss-ca-g2.crl0(
Source: Copy10330520PDF.exe String found in binary or memory: http://ts-ocsp.ws.symantec.com07
Source: Copy10330520PDF.exe String found in binary or memory: http://ts-ocsp.ws.symantec.com0;
Source: Copy10330520PDF.exe String found in binary or memory: https://d.symcb.com/cps0%
Source: Copy10330520PDF.exe String found in binary or memory: https://d.symcb.com/rpa0
Source: Copy10330520PDF.exe String found in binary or memory: https://d.symcb.com/rpa0.
Source: Copy10330520PDF.exe String found in binary or memory: https://www.digicert.com/CPS0
Source: C:\Users\user\Desktop\Copy10330520PDF.exe Process Stats: CPU usage > 49%
Source: Copy10330520PDF.exe Static PE information: invalid certificate
Source: Copy10330520PDF.exe, 00000000.00000000.1380245091.0000000000964000.00000002.00000001.01000000.00000003.sdmp Binary or memory string: OriginalFilenameBjsox.exeD vs Copy10330520PDF.exe
Source: Copy10330520PDF.exe, 00000000.00000002.3844212648.0000000000F5E000.00000004.00000020.00020000.00000000.sdmp Binary or memory string: OriginalFilenameclr.dllT vs Copy10330520PDF.exe
Source: Copy10330520PDF.exe Binary or memory string: OriginalFilenameBjsox.exeD vs Copy10330520PDF.exe
Source: Copy10330520PDF.exe Static PE information: EXECUTABLE_IMAGE, 32BIT_MACHINE
Source: classification engine Classification label: mal76.evad.winEXE@1/0@0/1
Source: C:\Users\user\Desktop\Copy10330520PDF.exe Mutant created: NULL
Source: Copy10330520PDF.exe Static PE information: Section: .text IMAGE_SCN_CNT_CODE, IMAGE_SCN_MEM_EXECUTE, IMAGE_SCN_MEM_READ
Source: Copy10330520PDF.exe Static file information: TRID: Win32 Executable (generic) Net Framework (10011505/4) 50.01%
Source: C:\Users\user\Desktop\Copy10330520PDF.exe Key opened: HKEY_CURRENT_USER\Software\Policies\Microsoft\Windows\Safer\CodeIdentifiers Jump to behavior
Source: Copy10330520PDF.exe Virustotal: Detection: 60%
Source: Copy10330520PDF.exe ReversingLabs: Detection: 63%
Source: C:\Users\user\Desktop\Copy10330520PDF.exe Section loaded: mscoree.dll Jump to behavior
Source: C:\Users\user\Desktop\Copy10330520PDF.exe Section loaded: apphelp.dll Jump to behavior
Source: C:\Users\user\Desktop\Copy10330520PDF.exe Section loaded: kernel.appcore.dll Jump to behavior
Source: C:\Users\user\Desktop\Copy10330520PDF.exe Section loaded: version.dll Jump to behavior
Source: C:\Users\user\Desktop\Copy10330520PDF.exe Section loaded: vcruntime140_clr0400.dll Jump to behavior
Source: C:\Users\user\Desktop\Copy10330520PDF.exe Section loaded: ucrtbase_clr0400.dll Jump to behavior
Source: C:\Users\user\Desktop\Copy10330520PDF.exe Section loaded: ucrtbase_clr0400.dll Jump to behavior
Source: C:\Users\user\Desktop\Copy10330520PDF.exe Section loaded: windows.storage.dll Jump to behavior
Source: C:\Users\user\Desktop\Copy10330520PDF.exe Section loaded: wldp.dll Jump to behavior
Source: C:\Users\user\Desktop\Copy10330520PDF.exe Section loaded: profapi.dll Jump to behavior
Source: C:\Users\user\Desktop\Copy10330520PDF.exe Section loaded: cryptsp.dll Jump to behavior
Source: C:\Users\user\Desktop\Copy10330520PDF.exe Section loaded: rsaenh.dll Jump to behavior
Source: C:\Users\user\Desktop\Copy10330520PDF.exe Section loaded: cryptbase.dll Jump to behavior
Source: C:\Users\user\Desktop\Copy10330520PDF.exe Section loaded: iphlpapi.dll Jump to behavior
Source: C:\Users\user\Desktop\Copy10330520PDF.exe Section loaded: dnsapi.dll Jump to behavior
Source: C:\Users\user\Desktop\Copy10330520PDF.exe Section loaded: dhcpcsvc6.dll Jump to behavior
Source: C:\Users\user\Desktop\Copy10330520PDF.exe Section loaded: dhcpcsvc.dll Jump to behavior
Source: C:\Users\user\Desktop\Copy10330520PDF.exe Section loaded: winnsi.dll Jump to behavior
Source: C:\Users\user\Desktop\Copy10330520PDF.exe Section loaded: rasapi32.dll Jump to behavior
Source: C:\Users\user\Desktop\Copy10330520PDF.exe Section loaded: rasman.dll Jump to behavior
Source: C:\Users\user\Desktop\Copy10330520PDF.exe Section loaded: rtutils.dll Jump to behavior
Source: C:\Users\user\Desktop\Copy10330520PDF.exe Section loaded: mswsock.dll Jump to behavior
Source: C:\Users\user\Desktop\Copy10330520PDF.exe Section loaded: winhttp.dll Jump to behavior
Source: C:\Users\user\Desktop\Copy10330520PDF.exe Section loaded: ondemandconnroutehelper.dll Jump to behavior
Source: Copy10330520PDF.exe Static PE information: data directory type: IMAGE_DIRECTORY_ENTRY_COM_DESCRIPTOR
Source: Copy10330520PDF.exe Static PE information: HIGH_ENTROPY_VA, DYNAMIC_BASE, NX_COMPAT, NO_SEH, TERMINAL_SERVER_AWARE

Data Obfuscation

barindex
Source: Copy10330520PDF.exe, Program.cs .Net Code: A System.Reflection.Assembly.Load(byte[])
Source: C:\Users\user\Desktop\Copy10330520PDF.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Users\user\Desktop\Copy10330520PDF.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Users\user\Desktop\Copy10330520PDF.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Users\user\Desktop\Copy10330520PDF.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Users\user\Desktop\Copy10330520PDF.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Users\user\Desktop\Copy10330520PDF.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Users\user\Desktop\Copy10330520PDF.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Users\user\Desktop\Copy10330520PDF.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Users\user\Desktop\Copy10330520PDF.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Users\user\Desktop\Copy10330520PDF.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Users\user\Desktop\Copy10330520PDF.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Users\user\Desktop\Copy10330520PDF.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Users\user\Desktop\Copy10330520PDF.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Users\user\Desktop\Copy10330520PDF.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Users\user\Desktop\Copy10330520PDF.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Users\user\Desktop\Copy10330520PDF.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Users\user\Desktop\Copy10330520PDF.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Users\user\Desktop\Copy10330520PDF.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Users\user\Desktop\Copy10330520PDF.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Users\user\Desktop\Copy10330520PDF.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Users\user\Desktop\Copy10330520PDF.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Users\user\Desktop\Copy10330520PDF.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Users\user\Desktop\Copy10330520PDF.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Users\user\Desktop\Copy10330520PDF.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Users\user\Desktop\Copy10330520PDF.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Users\user\Desktop\Copy10330520PDF.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Users\user\Desktop\Copy10330520PDF.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Users\user\Desktop\Copy10330520PDF.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Users\user\Desktop\Copy10330520PDF.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Users\user\Desktop\Copy10330520PDF.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Users\user\Desktop\Copy10330520PDF.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Users\user\Desktop\Copy10330520PDF.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Users\user\Desktop\Copy10330520PDF.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Users\user\Desktop\Copy10330520PDF.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Users\user\Desktop\Copy10330520PDF.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Users\user\Desktop\Copy10330520PDF.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Users\user\Desktop\Copy10330520PDF.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Users\user\Desktop\Copy10330520PDF.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Users\user\Desktop\Copy10330520PDF.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Users\user\Desktop\Copy10330520PDF.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Users\user\Desktop\Copy10330520PDF.exe Memory allocated: 12E0000 memory reserve | memory write watch Jump to behavior
Source: C:\Users\user\Desktop\Copy10330520PDF.exe Memory allocated: 2D70000 memory reserve | memory write watch Jump to behavior
Source: C:\Users\user\Desktop\Copy10330520PDF.exe Memory allocated: 2C70000 memory reserve | memory write watch Jump to behavior
Source: C:\Users\user\Desktop\Copy10330520PDF.exe Thread delayed: delay time: 922337203685477 Jump to behavior
Source: C:\Users\user\Desktop\Copy10330520PDF.exe Window / User API: threadDelayed 2147 Jump to behavior
Source: C:\Users\user\Desktop\Copy10330520PDF.exe Window / User API: threadDelayed 7709 Jump to behavior
Source: C:\Users\user\Desktop\Copy10330520PDF.exe TID: 7520 Thread sleep count: 33 > 30 Jump to behavior
Source: C:\Users\user\Desktop\Copy10330520PDF.exe TID: 7520 Thread sleep time: -30437127721620741s >= -30000s Jump to behavior
Source: C:\Users\user\Desktop\Copy10330520PDF.exe TID: 7520 Thread sleep time: -100000s >= -30000s Jump to behavior
Source: C:\Users\user\Desktop\Copy10330520PDF.exe TID: 7552 Thread sleep count: 2147 > 30 Jump to behavior
Source: C:\Users\user\Desktop\Copy10330520PDF.exe TID: 7552 Thread sleep count: 7709 > 30 Jump to behavior
Source: C:\Users\user\Desktop\Copy10330520PDF.exe TID: 7520 Thread sleep time: -99871s >= -30000s Jump to behavior
Source: C:\Users\user\Desktop\Copy10330520PDF.exe TID: 7520 Thread sleep time: -99765s >= -30000s Jump to behavior
Source: C:\Users\user\Desktop\Copy10330520PDF.exe TID: 7520 Thread sleep time: -99656s >= -30000s Jump to behavior
Source: C:\Users\user\Desktop\Copy10330520PDF.exe TID: 7520 Thread sleep time: -99546s >= -30000s Jump to behavior
Source: C:\Users\user\Desktop\Copy10330520PDF.exe TID: 7520 Thread sleep time: -99437s >= -30000s Jump to behavior
Source: C:\Users\user\Desktop\Copy10330520PDF.exe TID: 7520 Thread sleep time: -99328s >= -30000s Jump to behavior
Source: C:\Users\user\Desktop\Copy10330520PDF.exe TID: 7520 Thread sleep time: -99218s >= -30000s Jump to behavior
Source: C:\Users\user\Desktop\Copy10330520PDF.exe TID: 7520 Thread sleep time: -99109s >= -30000s Jump to behavior
Source: C:\Users\user\Desktop\Copy10330520PDF.exe TID: 7520 Thread sleep time: -99000s >= -30000s Jump to behavior
Source: C:\Users\user\Desktop\Copy10330520PDF.exe TID: 7520 Thread sleep time: -98883s >= -30000s Jump to behavior
Source: C:\Users\user\Desktop\Copy10330520PDF.exe TID: 7520 Thread sleep time: -98780s >= -30000s Jump to behavior
Source: C:\Users\user\Desktop\Copy10330520PDF.exe TID: 7520 Thread sleep time: -98671s >= -30000s Jump to behavior
Source: C:\Users\user\Desktop\Copy10330520PDF.exe TID: 7520 Thread sleep time: -98562s >= -30000s Jump to behavior
Source: C:\Users\user\Desktop\Copy10330520PDF.exe TID: 7520 Thread sleep time: -98301s >= -30000s Jump to behavior
Source: C:\Users\user\Desktop\Copy10330520PDF.exe TID: 7520 Thread sleep time: -98186s >= -30000s Jump to behavior
Source: C:\Users\user\Desktop\Copy10330520PDF.exe TID: 7520 Thread sleep time: -97989s >= -30000s Jump to behavior
Source: C:\Users\user\Desktop\Copy10330520PDF.exe TID: 7520 Thread sleep time: -97754s >= -30000s Jump to behavior
Source: C:\Users\user\Desktop\Copy10330520PDF.exe TID: 7520 Thread sleep time: -97615s >= -30000s Jump to behavior
Source: C:\Users\user\Desktop\Copy10330520PDF.exe TID: 7520 Thread sleep time: -97489s >= -30000s Jump to behavior
Source: C:\Users\user\Desktop\Copy10330520PDF.exe TID: 7520 Thread sleep time: -97374s >= -30000s Jump to behavior
Source: C:\Users\user\Desktop\Copy10330520PDF.exe TID: 7520 Thread sleep time: -97265s >= -30000s Jump to behavior
Source: C:\Users\user\Desktop\Copy10330520PDF.exe TID: 7520 Thread sleep time: -97156s >= -30000s Jump to behavior
Source: C:\Users\user\Desktop\Copy10330520PDF.exe TID: 7520 Thread sleep time: -97046s >= -30000s Jump to behavior
Source: C:\Users\user\Desktop\Copy10330520PDF.exe TID: 7520 Thread sleep time: -96937s >= -30000s Jump to behavior
Source: C:\Users\user\Desktop\Copy10330520PDF.exe TID: 7520 Thread sleep time: -96828s >= -30000s Jump to behavior
Source: C:\Users\user\Desktop\Copy10330520PDF.exe TID: 7520 Thread sleep time: -96718s >= -30000s Jump to behavior
Source: C:\Users\user\Desktop\Copy10330520PDF.exe TID: 7520 Thread sleep time: -96609s >= -30000s Jump to behavior
Source: C:\Users\user\Desktop\Copy10330520PDF.exe TID: 7520 Thread sleep time: -96499s >= -30000s Jump to behavior
Source: C:\Users\user\Desktop\Copy10330520PDF.exe TID: 7520 Thread sleep time: -96390s >= -30000s Jump to behavior
Source: C:\Users\user\Desktop\Copy10330520PDF.exe TID: 7520 Thread sleep time: -96281s >= -30000s Jump to behavior
Source: C:\Users\user\Desktop\Copy10330520PDF.exe TID: 7520 Thread sleep time: -96171s >= -30000s Jump to behavior
Source: C:\Users\user\Desktop\Copy10330520PDF.exe TID: 7520 Thread sleep time: -96062s >= -30000s Jump to behavior
Source: C:\Users\user\Desktop\Copy10330520PDF.exe TID: 7520 Thread sleep time: -95953s >= -30000s Jump to behavior
Source: C:\Users\user\Desktop\Copy10330520PDF.exe TID: 7520 Thread sleep time: -95843s >= -30000s Jump to behavior
Source: C:\Users\user\Desktop\Copy10330520PDF.exe TID: 7520 Thread sleep time: -95734s >= -30000s Jump to behavior
Source: C:\Users\user\Desktop\Copy10330520PDF.exe TID: 7520 Thread sleep time: -95624s >= -30000s Jump to behavior
Source: C:\Users\user\Desktop\Copy10330520PDF.exe TID: 7520 Thread sleep time: -95515s >= -30000s Jump to behavior
Source: C:\Users\user\Desktop\Copy10330520PDF.exe TID: 7520 Thread sleep time: -95406s >= -30000s Jump to behavior
Source: C:\Users\user\Desktop\Copy10330520PDF.exe TID: 7520 Thread sleep time: -95296s >= -30000s Jump to behavior
Source: C:\Users\user\Desktop\Copy10330520PDF.exe TID: 7520 Thread sleep time: -95187s >= -30000s Jump to behavior
Source: C:\Users\user\Desktop\Copy10330520PDF.exe TID: 7520 Thread sleep time: -95078s >= -30000s Jump to behavior
Source: C:\Users\user\Desktop\Copy10330520PDF.exe TID: 7520 Thread sleep time: -94968s >= -30000s Jump to behavior
Source: C:\Users\user\Desktop\Copy10330520PDF.exe TID: 7520 Thread sleep time: -94859s >= -30000s Jump to behavior
Source: C:\Users\user\Desktop\Copy10330520PDF.exe TID: 7520 Thread sleep time: -94749s >= -30000s Jump to behavior
Source: C:\Users\user\Desktop\Copy10330520PDF.exe TID: 7520 Thread sleep time: -94639s >= -30000s Jump to behavior
Source: C:\Users\user\Desktop\Copy10330520PDF.exe TID: 7520 Thread sleep time: -94492s >= -30000s Jump to behavior
Source: C:\Users\user\Desktop\Copy10330520PDF.exe TID: 7520 Thread sleep time: -94361s >= -30000s Jump to behavior
Source: C:\Users\user\Desktop\Copy10330520PDF.exe Thread delayed: delay time: 922337203685477 Jump to behavior
Source: C:\Users\user\Desktop\Copy10330520PDF.exe Thread delayed: delay time: 100000 Jump to behavior
Source: C:\Users\user\Desktop\Copy10330520PDF.exe Thread delayed: delay time: 99871 Jump to behavior
Source: C:\Users\user\Desktop\Copy10330520PDF.exe Thread delayed: delay time: 99765 Jump to behavior
Source: C:\Users\user\Desktop\Copy10330520PDF.exe Thread delayed: delay time: 99656 Jump to behavior
Source: C:\Users\user\Desktop\Copy10330520PDF.exe Thread delayed: delay time: 99546 Jump to behavior
Source: C:\Users\user\Desktop\Copy10330520PDF.exe Thread delayed: delay time: 99437 Jump to behavior
Source: C:\Users\user\Desktop\Copy10330520PDF.exe Thread delayed: delay time: 99328 Jump to behavior
Source: C:\Users\user\Desktop\Copy10330520PDF.exe Thread delayed: delay time: 99218 Jump to behavior
Source: C:\Users\user\Desktop\Copy10330520PDF.exe Thread delayed: delay time: 99109 Jump to behavior
Source: C:\Users\user\Desktop\Copy10330520PDF.exe Thread delayed: delay time: 99000 Jump to behavior
Source: C:\Users\user\Desktop\Copy10330520PDF.exe Thread delayed: delay time: 98883 Jump to behavior
Source: C:\Users\user\Desktop\Copy10330520PDF.exe Thread delayed: delay time: 98780 Jump to behavior
Source: C:\Users\user\Desktop\Copy10330520PDF.exe Thread delayed: delay time: 98671 Jump to behavior
Source: C:\Users\user\Desktop\Copy10330520PDF.exe Thread delayed: delay time: 98562 Jump to behavior
Source: C:\Users\user\Desktop\Copy10330520PDF.exe Thread delayed: delay time: 98301 Jump to behavior
Source: C:\Users\user\Desktop\Copy10330520PDF.exe Thread delayed: delay time: 98186 Jump to behavior
Source: C:\Users\user\Desktop\Copy10330520PDF.exe Thread delayed: delay time: 97989 Jump to behavior
Source: C:\Users\user\Desktop\Copy10330520PDF.exe Thread delayed: delay time: 97754 Jump to behavior
Source: C:\Users\user\Desktop\Copy10330520PDF.exe Thread delayed: delay time: 97615 Jump to behavior
Source: C:\Users\user\Desktop\Copy10330520PDF.exe Thread delayed: delay time: 97489 Jump to behavior
Source: C:\Users\user\Desktop\Copy10330520PDF.exe Thread delayed: delay time: 97374 Jump to behavior
Source: C:\Users\user\Desktop\Copy10330520PDF.exe Thread delayed: delay time: 97265 Jump to behavior
Source: C:\Users\user\Desktop\Copy10330520PDF.exe Thread delayed: delay time: 97156 Jump to behavior
Source: C:\Users\user\Desktop\Copy10330520PDF.exe Thread delayed: delay time: 97046 Jump to behavior
Source: C:\Users\user\Desktop\Copy10330520PDF.exe Thread delayed: delay time: 96937 Jump to behavior
Source: C:\Users\user\Desktop\Copy10330520PDF.exe Thread delayed: delay time: 96828 Jump to behavior
Source: C:\Users\user\Desktop\Copy10330520PDF.exe Thread delayed: delay time: 96718 Jump to behavior
Source: C:\Users\user\Desktop\Copy10330520PDF.exe Thread delayed: delay time: 96609 Jump to behavior
Source: C:\Users\user\Desktop\Copy10330520PDF.exe Thread delayed: delay time: 96499 Jump to behavior
Source: C:\Users\user\Desktop\Copy10330520PDF.exe Thread delayed: delay time: 96390 Jump to behavior
Source: C:\Users\user\Desktop\Copy10330520PDF.exe Thread delayed: delay time: 96281 Jump to behavior
Source: C:\Users\user\Desktop\Copy10330520PDF.exe Thread delayed: delay time: 96171 Jump to behavior
Source: C:\Users\user\Desktop\Copy10330520PDF.exe Thread delayed: delay time: 96062 Jump to behavior
Source: C:\Users\user\Desktop\Copy10330520PDF.exe Thread delayed: delay time: 95953 Jump to behavior
Source: C:\Users\user\Desktop\Copy10330520PDF.exe Thread delayed: delay time: 95843 Jump to behavior
Source: C:\Users\user\Desktop\Copy10330520PDF.exe Thread delayed: delay time: 95734 Jump to behavior
Source: C:\Users\user\Desktop\Copy10330520PDF.exe Thread delayed: delay time: 95624 Jump to behavior
Source: C:\Users\user\Desktop\Copy10330520PDF.exe Thread delayed: delay time: 95515 Jump to behavior
Source: C:\Users\user\Desktop\Copy10330520PDF.exe Thread delayed: delay time: 95406 Jump to behavior
Source: C:\Users\user\Desktop\Copy10330520PDF.exe Thread delayed: delay time: 95296 Jump to behavior
Source: C:\Users\user\Desktop\Copy10330520PDF.exe Thread delayed: delay time: 95187 Jump to behavior
Source: C:\Users\user\Desktop\Copy10330520PDF.exe Thread delayed: delay time: 95078 Jump to behavior
Source: C:\Users\user\Desktop\Copy10330520PDF.exe Thread delayed: delay time: 94968 Jump to behavior
Source: C:\Users\user\Desktop\Copy10330520PDF.exe Thread delayed: delay time: 94859 Jump to behavior
Source: C:\Users\user\Desktop\Copy10330520PDF.exe Thread delayed: delay time: 94749 Jump to behavior
Source: C:\Users\user\Desktop\Copy10330520PDF.exe Thread delayed: delay time: 94639 Jump to behavior
Source: C:\Users\user\Desktop\Copy10330520PDF.exe Thread delayed: delay time: 94492 Jump to behavior
Source: C:\Users\user\Desktop\Copy10330520PDF.exe Thread delayed: delay time: 94361 Jump to behavior
Source: Copy10330520PDF.exe, 00000000.00000002.3844212648.0000000000FCE000.00000004.00000020.00020000.00000000.sdmp Binary or memory string: Hyper-V RAW%SystemRoot%\system32\mswsock.dll#
Source: C:\Users\user\Desktop\Copy10330520PDF.exe Process token adjusted: Debug Jump to behavior
Source: C:\Users\user\Desktop\Copy10330520PDF.exe Memory allocated: page read and write | page guard Jump to behavior
Source: C:\Users\user\Desktop\Copy10330520PDF.exe Queries volume information: C:\Users\user\Desktop\Copy10330520PDF.exe VolumeInformation Jump to behavior
Source: C:\Users\user\Desktop\Copy10330520PDF.exe Key value queried: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Cryptography MachineGuid Jump to behavior
  • No. of IPs < 25%
  • 25% < No. of IPs < 50%
  • 50% < No. of IPs < 75%
  • 75% < No. of IPs