Windows Analysis Report
SecuriteInfo.com.Win32.MalwareX-gen.26512.27594.exe

Overview

General Information

Sample name: SecuriteInfo.com.Win32.MalwareX-gen.26512.27594.exe
Analysis ID: 1528900
MD5: cc42d6edd3fc5e953bcf59b67c31faed
SHA1: 291ab6d36c851cbb00d2c344c10abaea8c4f22c0
SHA256: 78b3e10f355de8a780c69cc622dd3bc529365ff5fa141eb291112ee7b2ef2a94
Tags: exe
Infos:

Detection

FormBook
Score: 100
Range: 0 - 100
Whitelisted: false
Confidence: 100%

Signatures

Found malware configuration
Malicious sample detected (through community Yara rule)
Multi AV Scanner detection for submitted file
Yara detected AntiVM3
Yara detected FormBook
.NET source code contains potential unpacker
AI detected suspicious sample
Adds a directory exclusion to Windows Defender
C2 URLs / IPs found in malware configuration
Loading BitLocker PowerShell Module
Machine Learning detection for sample
Sigma detected: Powershell Base64 Encoded MpPreference Cmdlet
Tries to detect virtualization through RDTSC time measurements
Allocates memory with a write watch (potentially for evading sandboxes)
Binary contains a suspicious time stamp
Checks if the current process is being debugged
Contains functionality for execution timing, often used to detect debuggers
Contains functionality to access loader functionality (e.g. LdrGetProcedureAddress)
Contains functionality to call native functions
Contains functionality to read the PEB
Contains long sleeps (>= 3 min)
Creates a process in suspended mode (likely to inject code)
Detected potential crypto function
Enables debug privileges
Found a high number of Window / User specific system calls (may be a loop to detect user behavior)
Found inlined nop instructions (likely shell or obfuscated code)
Found large amount of non-executed APIs
Found potential string decryption / allocating functions
May sleep (evasive loops) to hinder dynamic analysis
PE / OLE file has an invalid certificate
Queries the volume information (name, serial number etc) of a device
Sample file is different than original file name gathered from version info
Sigma detected: Powershell Defender Exclusion
Tries to resolve domain names, but no domain seems valid (expired dropper behavior)
Uses 32bit PE files
Uses code obfuscation techniques (call, push, ret)
Yara signature match

Classification

AV Detection

barindex
Source: 00000007.00000002.1336089947.0000000000400000.00000040.00000400.00020000.00000000.sdmp Malware Configuration Extractor: FormBook {"C2 list": ["www.uggernauty.net/t94g/"], "decoy": ["32188.top", "mergencyroofrepair656460.online", "jkahu.fun", "ur4.autos", "r0lba4cl0qkaws8.bond", "eiliaowang.top", "urjav.xyz", "kidaman15.click", "old-removal-p350.today", "levatethismedia.info", "h33323s40.top", "dormy.click", "5406.club", "earlofwisdombook.pro", "6980.app", "ellwood999.biz", "otdates.lol", "164v.shop", "thereal.app", "takeget.online", "andshakecap.info", "urevitality.fit", "hinabrasilexpressbr.shop", "agacuan6.cloud", "ehuacs.vip", "ostbr.online", "xh354.xyz", "texhio.online", "utoflightbookings.online", "uikfox.top", "razeonthego.net", "ardenartpros.xyz", "rain-pipe-cleaning-72352.bond", "argoindah.online", "ilo808.vip", "urartexplore.top", "likbet77ofc.net", "olacecarenetwork.info", "nfluencer-marketing-47216.bond", "alerico.net", "ywildchicken.net", "8nj2.shop", "alsam.bond", "emaxvalley.xyz", "uwevei8.pro", "lwp6c7v.xyz", "hongzhuankk02.yachts", "kokbihi.online", "kxt.xyz", "ctivgym.online", "he616comies.shop", "loto.app", "lpha-mn.dev", "ungle-product.shop", "duaus.fun", "roduct-tester-jobs-48097.bond", "ikkidigitalpro.net", "oppr.fit", "uxk-porn-slut.top", "aoudimall.net", "pessin.tech", "ackhoffman.art", "echonocat.fun", "t-courses-mw-2.bond"]}
Source: SecuriteInfo.com.Win32.MalwareX-gen.26512.27594.exe Virustotal: Detection: 35% Perma Link
Source: Yara match File source: 7.2.SecuriteInfo.com.Win32.MalwareX-gen.26512.27594.exe.400000.0.raw.unpack, type: UNPACKEDPE
Source: Yara match File source: 7.2.SecuriteInfo.com.Win32.MalwareX-gen.26512.27594.exe.400000.0.unpack, type: UNPACKEDPE
Source: Yara match File source: 00000007.00000002.1336089947.0000000000400000.00000040.00000400.00020000.00000000.sdmp, type: MEMORY
Source: Yara match File source: 00000000.00000002.1358724042.000000000359C000.00000004.00000800.00020000.00000000.sdmp, type: MEMORY
Source: Submited Sample Integrated Neural Analysis Model: Matched 99.9% probability
Source: SecuriteInfo.com.Win32.MalwareX-gen.26512.27594.exe Joe Sandbox ML: detected
Source: SecuriteInfo.com.Win32.MalwareX-gen.26512.27594.exe Static PE information: EXECUTABLE_IMAGE, 32BIT_MACHINE
Source: SecuriteInfo.com.Win32.MalwareX-gen.26512.27594.exe Static PE information: DYNAMIC_BASE, NX_COMPAT, NO_SEH, TERMINAL_SERVER_AWARE
Source: Binary string: iGDc.pdbSHA256 source: SecuriteInfo.com.Win32.MalwareX-gen.26512.27594.exe
Source: Binary string: wntdll.pdbUGP source: SecuriteInfo.com.Win32.MalwareX-gen.26512.27594.exe, 00000007.00000002.1336299278.00000000010D0000.00000040.00001000.00020000.00000000.sdmp
Source: Binary string: wntdll.pdb source: SecuriteInfo.com.Win32.MalwareX-gen.26512.27594.exe, SecuriteInfo.com.Win32.MalwareX-gen.26512.27594.exe, 00000007.00000002.1336299278.00000000010D0000.00000040.00001000.00020000.00000000.sdmp
Source: Binary string: iGDc.pdb source: SecuriteInfo.com.Win32.MalwareX-gen.26512.27594.exe
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.MalwareX-gen.26512.27594.exe Code function: 4x nop then pop esi 7_2_004172E8
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.MalwareX-gen.26512.27594.exe Code function: 4x nop then pop edi 7_2_00417D73

Networking

barindex
Source: Malware configuration extractor URLs: www.uggernauty.net/t94g/
Source: unknown DNS traffic detected: query: 241.42.69.40.in-addr.arpa replaycode: Name error (3)
Source: unknown UDP traffic detected without corresponding DNS query: 1.1.1.1
Source: global traffic DNS traffic detected: DNS query: 241.42.69.40.in-addr.arpa
Source: SecuriteInfo.com.Win32.MalwareX-gen.26512.27594.exe String found in binary or memory: http://crl.comodoca.com/COMODORSACertificationAuthority.crl0q
Source: SecuriteInfo.com.Win32.MalwareX-gen.26512.27594.exe String found in binary or memory: http://crl.comodoca.com/COMODORSACodeSigningCA.crl0t
Source: SecuriteInfo.com.Win32.MalwareX-gen.26512.27594.exe String found in binary or memory: http://ocsp.comodoca.com0
Source: SecuriteInfo.com.Win32.MalwareX-gen.26512.27594.exe, 00000000.00000002.1354786354.00000000024A1000.00000004.00000800.00020000.00000000.sdmp String found in binary or memory: http://schemas.xmlsoap.org/ws/2005/05/identity/claims/name
Source: SecuriteInfo.com.Win32.MalwareX-gen.26512.27594.exe String found in binary or memory: https://www.chiark.greenend.org.uk/~sgtatham/putty/0

E-Banking Fraud

barindex
Source: Yara match File source: 7.2.SecuriteInfo.com.Win32.MalwareX-gen.26512.27594.exe.400000.0.raw.unpack, type: UNPACKEDPE
Source: Yara match File source: 7.2.SecuriteInfo.com.Win32.MalwareX-gen.26512.27594.exe.400000.0.unpack, type: UNPACKEDPE
Source: Yara match File source: 00000007.00000002.1336089947.0000000000400000.00000040.00000400.00020000.00000000.sdmp, type: MEMORY
Source: Yara match File source: 00000000.00000002.1358724042.000000000359C000.00000004.00000800.00020000.00000000.sdmp, type: MEMORY

System Summary

barindex
Source: 7.2.SecuriteInfo.com.Win32.MalwareX-gen.26512.27594.exe.400000.0.raw.unpack, type: UNPACKEDPE Matched rule: Windows_Trojan_Formbook_1112e116 Author: unknown
Source: 7.2.SecuriteInfo.com.Win32.MalwareX-gen.26512.27594.exe.400000.0.raw.unpack, type: UNPACKEDPE Matched rule: autogenerated rule brought to you by yara-signator Author: Felix Bilstein - yara-signator at cocacoding dot com
Source: 7.2.SecuriteInfo.com.Win32.MalwareX-gen.26512.27594.exe.400000.0.raw.unpack, type: UNPACKEDPE Matched rule: detect Formbook in memory Author: JPCERT/CC Incident Response Group
Source: 7.2.SecuriteInfo.com.Win32.MalwareX-gen.26512.27594.exe.400000.0.unpack, type: UNPACKEDPE Matched rule: Windows_Trojan_Formbook_1112e116 Author: unknown
Source: 7.2.SecuriteInfo.com.Win32.MalwareX-gen.26512.27594.exe.400000.0.unpack, type: UNPACKEDPE Matched rule: autogenerated rule brought to you by yara-signator Author: Felix Bilstein - yara-signator at cocacoding dot com
Source: 7.2.SecuriteInfo.com.Win32.MalwareX-gen.26512.27594.exe.400000.0.unpack, type: UNPACKEDPE Matched rule: detect Formbook in memory Author: JPCERT/CC Incident Response Group
Source: 00000007.00000002.1336089947.0000000000400000.00000040.00000400.00020000.00000000.sdmp, type: MEMORY Matched rule: Windows_Trojan_Formbook_1112e116 Author: unknown
Source: 00000007.00000002.1336089947.0000000000400000.00000040.00000400.00020000.00000000.sdmp, type: MEMORY Matched rule: autogenerated rule brought to you by yara-signator Author: Felix Bilstein - yara-signator at cocacoding dot com
Source: 00000007.00000002.1336089947.0000000000400000.00000040.00000400.00020000.00000000.sdmp, type: MEMORY Matched rule: detect Formbook in memory Author: JPCERT/CC Incident Response Group
Source: 00000000.00000002.1358724042.000000000359C000.00000004.00000800.00020000.00000000.sdmp, type: MEMORY Matched rule: Windows_Trojan_Formbook_1112e116 Author: unknown
Source: 00000000.00000002.1358724042.000000000359C000.00000004.00000800.00020000.00000000.sdmp, type: MEMORY Matched rule: autogenerated rule brought to you by yara-signator Author: Felix Bilstein - yara-signator at cocacoding dot com
Source: 00000000.00000002.1358724042.000000000359C000.00000004.00000800.00020000.00000000.sdmp, type: MEMORY Matched rule: detect Formbook in memory Author: JPCERT/CC Incident Response Group
Source: Process Memory Space: SecuriteInfo.com.Win32.MalwareX-gen.26512.27594.exe PID: 7460, type: MEMORYSTR Matched rule: Windows_Trojan_Formbook_1112e116 Author: unknown
Source: Process Memory Space: SecuriteInfo.com.Win32.MalwareX-gen.26512.27594.exe PID: 7744, type: MEMORYSTR Matched rule: Windows_Trojan_Formbook_1112e116 Author: unknown
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.MalwareX-gen.26512.27594.exe Code function: 7_2_0041A320 NtCreateFile, 7_2_0041A320
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.MalwareX-gen.26512.27594.exe Code function: 7_2_0041A3D0 NtReadFile, 7_2_0041A3D0
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.MalwareX-gen.26512.27594.exe Code function: 7_2_0041A450 NtClose, 7_2_0041A450
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.MalwareX-gen.26512.27594.exe Code function: 7_2_0041A500 NtAllocateVirtualMemory, 7_2_0041A500
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.MalwareX-gen.26512.27594.exe Code function: 7_2_0041A2DA NtCreateFile, 7_2_0041A2DA
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.MalwareX-gen.26512.27594.exe Code function: 7_2_0041A31A NtCreateFile, 7_2_0041A31A
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.MalwareX-gen.26512.27594.exe Code function: 7_2_01142BF0 NtAllocateVirtualMemory,LdrInitializeThunk, 7_2_01142BF0
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.MalwareX-gen.26512.27594.exe Code function: 7_2_01142DF0 NtQuerySystemInformation,LdrInitializeThunk, 7_2_01142DF0
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.MalwareX-gen.26512.27594.exe Code function: 7_2_01144340 NtSetContextThread, 7_2_01144340
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.MalwareX-gen.26512.27594.exe Code function: 7_2_01144650 NtSuspendThread, 7_2_01144650
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.MalwareX-gen.26512.27594.exe Code function: 7_2_01142B60 NtClose, 7_2_01142B60
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.MalwareX-gen.26512.27594.exe Code function: 7_2_01142B80 NtQueryInformationFile, 7_2_01142B80
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.MalwareX-gen.26512.27594.exe Code function: 7_2_01142BA0 NtEnumerateValueKey, 7_2_01142BA0
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.MalwareX-gen.26512.27594.exe Code function: 7_2_01142BE0 NtQueryValueKey, 7_2_01142BE0
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.MalwareX-gen.26512.27594.exe Code function: 7_2_01142AB0 NtWaitForSingleObject, 7_2_01142AB0
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.MalwareX-gen.26512.27594.exe Code function: 7_2_01142AD0 NtReadFile, 7_2_01142AD0
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.MalwareX-gen.26512.27594.exe Code function: 7_2_01142AF0 NtWriteFile, 7_2_01142AF0
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.MalwareX-gen.26512.27594.exe Code function: 7_2_01142D10 NtMapViewOfSection, 7_2_01142D10
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.MalwareX-gen.26512.27594.exe Code function: 7_2_01142D00 NtSetInformationFile, 7_2_01142D00
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.MalwareX-gen.26512.27594.exe Code function: 7_2_01142D30 NtUnmapViewOfSection, 7_2_01142D30
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.MalwareX-gen.26512.27594.exe Code function: 7_2_01142DB0 NtEnumerateKey, 7_2_01142DB0
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.MalwareX-gen.26512.27594.exe Code function: 7_2_01142DD0 NtDelayExecution, 7_2_01142DD0
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.MalwareX-gen.26512.27594.exe Code function: 7_2_01142C00 NtQueryInformationProcess, 7_2_01142C00
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.MalwareX-gen.26512.27594.exe Code function: 7_2_01142C70 NtFreeVirtualMemory, 7_2_01142C70
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.MalwareX-gen.26512.27594.exe Code function: 7_2_01142C60 NtCreateKey, 7_2_01142C60
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.MalwareX-gen.26512.27594.exe Code function: 7_2_01142CA0 NtQueryInformationToken, 7_2_01142CA0
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.MalwareX-gen.26512.27594.exe Code function: 7_2_01142CC0 NtQueryVirtualMemory, 7_2_01142CC0
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.MalwareX-gen.26512.27594.exe Code function: 7_2_01142CF0 NtOpenProcess, 7_2_01142CF0
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.MalwareX-gen.26512.27594.exe Code function: 7_2_01142F30 NtCreateSection, 7_2_01142F30
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.MalwareX-gen.26512.27594.exe Code function: 7_2_01142F60 NtCreateProcessEx, 7_2_01142F60
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.MalwareX-gen.26512.27594.exe Code function: 7_2_01142F90 NtProtectVirtualMemory, 7_2_01142F90
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.MalwareX-gen.26512.27594.exe Code function: 7_2_01142FB0 NtResumeThread, 7_2_01142FB0
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.MalwareX-gen.26512.27594.exe Code function: 7_2_01142FA0 NtQuerySection, 7_2_01142FA0
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.MalwareX-gen.26512.27594.exe Code function: 7_2_01142FE0 NtCreateFile, 7_2_01142FE0
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.MalwareX-gen.26512.27594.exe Code function: 7_2_01142E30 NtWriteVirtualMemory, 7_2_01142E30
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.MalwareX-gen.26512.27594.exe Code function: 7_2_01142E80 NtReadVirtualMemory, 7_2_01142E80
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.MalwareX-gen.26512.27594.exe Code function: 7_2_01142EA0 NtAdjustPrivilegesToken, 7_2_01142EA0
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.MalwareX-gen.26512.27594.exe Code function: 7_2_01142EE0 NtQueueApcThread, 7_2_01142EE0
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.MalwareX-gen.26512.27594.exe Code function: 7_2_01143010 NtOpenDirectoryObject, 7_2_01143010
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.MalwareX-gen.26512.27594.exe Code function: 7_2_01143090 NtSetValueKey, 7_2_01143090
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.MalwareX-gen.26512.27594.exe Code function: 7_2_011435C0 NtCreateMutant, 7_2_011435C0
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.MalwareX-gen.26512.27594.exe Code function: 7_2_011439B0 NtGetContextThread, 7_2_011439B0
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.MalwareX-gen.26512.27594.exe Code function: 7_2_01143D10 NtOpenProcessToken, 7_2_01143D10
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.MalwareX-gen.26512.27594.exe Code function: 7_2_01143D70 NtOpenThread, 7_2_01143D70
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.MalwareX-gen.26512.27594.exe Code function: 0_2_00B0F044 0_2_00B0F044
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.MalwareX-gen.26512.27594.exe Code function: 0_2_06801248 0_2_06801248
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.MalwareX-gen.26512.27594.exe Code function: 0_2_06803A50 0_2_06803A50
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.MalwareX-gen.26512.27594.exe Code function: 0_2_0680D3D4 0_2_0680D3D4
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.MalwareX-gen.26512.27594.exe Code function: 0_2_0684BBB0 0_2_0684BBB0
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.MalwareX-gen.26512.27594.exe Code function: 0_2_0684BBA0 0_2_0684BBA0
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.MalwareX-gen.26512.27594.exe Code function: 7_2_0041D842 7_2_0041D842
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.MalwareX-gen.26512.27594.exe Code function: 7_2_00401030 7_2_00401030
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.MalwareX-gen.26512.27594.exe Code function: 7_2_0041DC0E 7_2_0041DC0E
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.MalwareX-gen.26512.27594.exe Code function: 7_2_00402D90 7_2_00402D90
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.MalwareX-gen.26512.27594.exe Code function: 7_2_0041ED9A 7_2_0041ED9A
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.MalwareX-gen.26512.27594.exe Code function: 7_2_00409E50 7_2_00409E50
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.MalwareX-gen.26512.27594.exe Code function: 7_2_0041DF5A 7_2_0041DF5A
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.MalwareX-gen.26512.27594.exe Code function: 7_2_00402FB0 7_2_00402FB0
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.MalwareX-gen.26512.27594.exe Code function: 7_2_011AA118 7_2_011AA118
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.MalwareX-gen.26512.27594.exe Code function: 7_2_01100100 7_2_01100100
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.MalwareX-gen.26512.27594.exe Code function: 7_2_01198158 7_2_01198158
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.MalwareX-gen.26512.27594.exe Code function: 7_2_011D01AA 7_2_011D01AA
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.MalwareX-gen.26512.27594.exe Code function: 7_2_011C41A2 7_2_011C41A2
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.MalwareX-gen.26512.27594.exe Code function: 7_2_011C81CC 7_2_011C81CC
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.MalwareX-gen.26512.27594.exe Code function: 7_2_011A2000 7_2_011A2000
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.MalwareX-gen.26512.27594.exe Code function: 7_2_011CA352 7_2_011CA352
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.MalwareX-gen.26512.27594.exe Code function: 7_2_0111E3F0 7_2_0111E3F0
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.MalwareX-gen.26512.27594.exe Code function: 7_2_011D03E6 7_2_011D03E6
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.MalwareX-gen.26512.27594.exe Code function: 7_2_011B0274 7_2_011B0274
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.MalwareX-gen.26512.27594.exe Code function: 7_2_011902C0 7_2_011902C0
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.MalwareX-gen.26512.27594.exe Code function: 7_2_01110535 7_2_01110535
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.MalwareX-gen.26512.27594.exe Code function: 7_2_011D0591 7_2_011D0591
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.MalwareX-gen.26512.27594.exe Code function: 7_2_011B4420 7_2_011B4420
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.MalwareX-gen.26512.27594.exe Code function: 7_2_011C2446 7_2_011C2446
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.MalwareX-gen.26512.27594.exe Code function: 7_2_011BE4F6 7_2_011BE4F6
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.MalwareX-gen.26512.27594.exe Code function: 7_2_01134750 7_2_01134750
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.MalwareX-gen.26512.27594.exe Code function: 7_2_01110770 7_2_01110770
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.MalwareX-gen.26512.27594.exe Code function: 7_2_0110C7C0 7_2_0110C7C0
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.MalwareX-gen.26512.27594.exe Code function: 7_2_0112C6E0 7_2_0112C6E0
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.MalwareX-gen.26512.27594.exe Code function: 7_2_01126962 7_2_01126962
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.MalwareX-gen.26512.27594.exe Code function: 7_2_011129A0 7_2_011129A0
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.MalwareX-gen.26512.27594.exe Code function: 7_2_011DA9A6 7_2_011DA9A6
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.MalwareX-gen.26512.27594.exe Code function: 7_2_0111A840 7_2_0111A840
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.MalwareX-gen.26512.27594.exe Code function: 7_2_01112840 7_2_01112840
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.MalwareX-gen.26512.27594.exe Code function: 7_2_010F68B8 7_2_010F68B8
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.MalwareX-gen.26512.27594.exe Code function: 7_2_0113E8F0 7_2_0113E8F0
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.MalwareX-gen.26512.27594.exe Code function: 7_2_011CAB40 7_2_011CAB40
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.MalwareX-gen.26512.27594.exe Code function: 7_2_011C6BD7 7_2_011C6BD7
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.MalwareX-gen.26512.27594.exe Code function: 7_2_0110EA80 7_2_0110EA80
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.MalwareX-gen.26512.27594.exe Code function: 7_2_011ACD1F 7_2_011ACD1F
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.MalwareX-gen.26512.27594.exe Code function: 7_2_0111AD00 7_2_0111AD00
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.MalwareX-gen.26512.27594.exe Code function: 7_2_01128DBF 7_2_01128DBF
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.MalwareX-gen.26512.27594.exe Code function: 7_2_0110ADE0 7_2_0110ADE0
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.MalwareX-gen.26512.27594.exe Code function: 7_2_01110C00 7_2_01110C00
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.MalwareX-gen.26512.27594.exe Code function: 7_2_011B0CB5 7_2_011B0CB5
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.MalwareX-gen.26512.27594.exe Code function: 7_2_01100CF2 7_2_01100CF2
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.MalwareX-gen.26512.27594.exe Code function: 7_2_01130F30 7_2_01130F30
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.MalwareX-gen.26512.27594.exe Code function: 7_2_011B2F30 7_2_011B2F30
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.MalwareX-gen.26512.27594.exe Code function: 7_2_01152F28 7_2_01152F28
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.MalwareX-gen.26512.27594.exe Code function: 7_2_01184F40 7_2_01184F40
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.MalwareX-gen.26512.27594.exe Code function: 7_2_0118EFA0 7_2_0118EFA0
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.MalwareX-gen.26512.27594.exe Code function: 7_2_01102FC8 7_2_01102FC8
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.MalwareX-gen.26512.27594.exe Code function: 7_2_0111CFE0 7_2_0111CFE0
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.MalwareX-gen.26512.27594.exe Code function: 7_2_011CEE26 7_2_011CEE26
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.MalwareX-gen.26512.27594.exe Code function: 7_2_01110E59 7_2_01110E59
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.MalwareX-gen.26512.27594.exe Code function: 7_2_01122E90 7_2_01122E90
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.MalwareX-gen.26512.27594.exe Code function: 7_2_011CCE93 7_2_011CCE93
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.MalwareX-gen.26512.27594.exe Code function: 7_2_011CEEDB 7_2_011CEEDB
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.MalwareX-gen.26512.27594.exe Code function: 7_2_011DB16B 7_2_011DB16B
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.MalwareX-gen.26512.27594.exe Code function: 7_2_0114516C 7_2_0114516C
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.MalwareX-gen.26512.27594.exe Code function: 7_2_010FF172 7_2_010FF172
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.MalwareX-gen.26512.27594.exe Code function: 7_2_0111B1B0 7_2_0111B1B0
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.MalwareX-gen.26512.27594.exe Code function: 7_2_011170C0 7_2_011170C0
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.MalwareX-gen.26512.27594.exe Code function: 7_2_011BF0CC 7_2_011BF0CC
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.MalwareX-gen.26512.27594.exe Code function: 7_2_011C70E9 7_2_011C70E9
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.MalwareX-gen.26512.27594.exe Code function: 7_2_011CF0E0 7_2_011CF0E0
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.MalwareX-gen.26512.27594.exe Code function: 7_2_011C132D 7_2_011C132D
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.MalwareX-gen.26512.27594.exe Code function: 7_2_010FD34C 7_2_010FD34C
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.MalwareX-gen.26512.27594.exe Code function: 7_2_0115739A 7_2_0115739A
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.MalwareX-gen.26512.27594.exe Code function: 7_2_011152A0 7_2_011152A0
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.MalwareX-gen.26512.27594.exe Code function: 7_2_0112B2C0 7_2_0112B2C0
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.MalwareX-gen.26512.27594.exe Code function: 7_2_011B12ED 7_2_011B12ED
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.MalwareX-gen.26512.27594.exe Code function: 7_2_011C7571 7_2_011C7571
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.MalwareX-gen.26512.27594.exe Code function: 7_2_011AD5B0 7_2_011AD5B0
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.MalwareX-gen.26512.27594.exe Code function: 7_2_011CF43F 7_2_011CF43F
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.MalwareX-gen.26512.27594.exe Code function: 7_2_01101460 7_2_01101460
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.MalwareX-gen.26512.27594.exe Code function: 7_2_011CF7B0 7_2_011CF7B0
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.MalwareX-gen.26512.27594.exe Code function: 7_2_011C16CC 7_2_011C16CC
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.MalwareX-gen.26512.27594.exe Code function: 7_2_011A5910 7_2_011A5910
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.MalwareX-gen.26512.27594.exe Code function: 7_2_01119950 7_2_01119950
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.MalwareX-gen.26512.27594.exe Code function: 7_2_0112B950 7_2_0112B950
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.MalwareX-gen.26512.27594.exe Code function: 7_2_0117D800 7_2_0117D800
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.MalwareX-gen.26512.27594.exe Code function: 7_2_011138E0 7_2_011138E0
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.MalwareX-gen.26512.27594.exe Code function: 7_2_011CFB76 7_2_011CFB76
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.MalwareX-gen.26512.27594.exe Code function: 7_2_0112FB80 7_2_0112FB80
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.MalwareX-gen.26512.27594.exe Code function: 7_2_01185BF0 7_2_01185BF0
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.MalwareX-gen.26512.27594.exe Code function: 7_2_0114DBF9 7_2_0114DBF9
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.MalwareX-gen.26512.27594.exe Code function: 7_2_011CFA49 7_2_011CFA49
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.MalwareX-gen.26512.27594.exe Code function: 7_2_011C7A46 7_2_011C7A46
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.MalwareX-gen.26512.27594.exe Code function: 7_2_01183A6C 7_2_01183A6C
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.MalwareX-gen.26512.27594.exe Code function: 7_2_01155AA0 7_2_01155AA0
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.MalwareX-gen.26512.27594.exe Code function: 7_2_011ADAAC 7_2_011ADAAC
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.MalwareX-gen.26512.27594.exe Code function: 7_2_011B1AA3 7_2_011B1AA3
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.MalwareX-gen.26512.27594.exe Code function: 7_2_011BDAC6 7_2_011BDAC6
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.MalwareX-gen.26512.27594.exe Code function: 7_2_011C1D5A 7_2_011C1D5A
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.MalwareX-gen.26512.27594.exe Code function: 7_2_01113D40 7_2_01113D40
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.MalwareX-gen.26512.27594.exe Code function: 7_2_011C7D73 7_2_011C7D73
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.MalwareX-gen.26512.27594.exe Code function: 7_2_0112FDC0 7_2_0112FDC0
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.MalwareX-gen.26512.27594.exe Code function: 7_2_01189C32 7_2_01189C32
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.MalwareX-gen.26512.27594.exe Code function: 7_2_011CFCF2 7_2_011CFCF2
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.MalwareX-gen.26512.27594.exe Code function: 7_2_011CFF09 7_2_011CFF09
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.MalwareX-gen.26512.27594.exe Code function: 7_2_01111F92 7_2_01111F92
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.MalwareX-gen.26512.27594.exe Code function: 7_2_011CFFB1 7_2_011CFFB1
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.MalwareX-gen.26512.27594.exe Code function: 7_2_010D3FD5 7_2_010D3FD5
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.MalwareX-gen.26512.27594.exe Code function: 7_2_010D3FD2 7_2_010D3FD2
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.MalwareX-gen.26512.27594.exe Code function: 7_2_01119EB0 7_2_01119EB0
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.MalwareX-gen.26512.27594.exe Code function: String function: 01145130 appears 58 times
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.MalwareX-gen.26512.27594.exe Code function: String function: 0117EA12 appears 86 times
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.MalwareX-gen.26512.27594.exe Code function: String function: 010FB970 appears 280 times
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.MalwareX-gen.26512.27594.exe Code function: String function: 01157E54 appears 101 times
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.MalwareX-gen.26512.27594.exe Code function: String function: 0118F290 appears 105 times
Source: SecuriteInfo.com.Win32.MalwareX-gen.26512.27594.exe Static PE information: invalid certificate
Source: SecuriteInfo.com.Win32.MalwareX-gen.26512.27594.exe, 00000000.00000000.1312956631.0000000000132000.00000002.00000001.01000000.00000003.sdmp Binary or memory string: OriginalFilenameiGDc.exe, vs SecuriteInfo.com.Win32.MalwareX-gen.26512.27594.exe
Source: SecuriteInfo.com.Win32.MalwareX-gen.26512.27594.exe, 00000000.00000002.1358724042.000000000359C000.00000004.00000800.00020000.00000000.sdmp Binary or memory string: OriginalFilenameTyrone.dll8 vs SecuriteInfo.com.Win32.MalwareX-gen.26512.27594.exe
Source: SecuriteInfo.com.Win32.MalwareX-gen.26512.27594.exe, 00000000.00000002.1362367333.000000000834F000.00000004.00000020.00020000.00000000.sdmp Binary or memory string: OriginalFilenamePowerShell.EXE.MUIj% vs SecuriteInfo.com.Win32.MalwareX-gen.26512.27594.exe
Source: SecuriteInfo.com.Win32.MalwareX-gen.26512.27594.exe, 00000000.00000002.1362172458.0000000006AF0000.00000004.08000000.00040000.00000000.sdmp Binary or memory string: OriginalFilenameTyrone.dll8 vs SecuriteInfo.com.Win32.MalwareX-gen.26512.27594.exe
Source: SecuriteInfo.com.Win32.MalwareX-gen.26512.27594.exe, 00000007.00000002.1336299278.00000000011FD000.00000040.00001000.00020000.00000000.sdmp Binary or memory string: OriginalFilenamentdll.dllj% vs SecuriteInfo.com.Win32.MalwareX-gen.26512.27594.exe
Source: SecuriteInfo.com.Win32.MalwareX-gen.26512.27594.exe Binary or memory string: OriginalFilenameiGDc.exe, vs SecuriteInfo.com.Win32.MalwareX-gen.26512.27594.exe
Source: SecuriteInfo.com.Win32.MalwareX-gen.26512.27594.exe Static PE information: EXECUTABLE_IMAGE, 32BIT_MACHINE
Source: 7.2.SecuriteInfo.com.Win32.MalwareX-gen.26512.27594.exe.400000.0.raw.unpack, type: UNPACKEDPE Matched rule: Windows_Trojan_Formbook_1112e116 reference_sample = 6246f3b89f0e4913abd88ae535ae3597865270f58201dc7f8ec0c87f15ff370a, os = windows, severity = x86, creation_date = 2021-06-14, scan_context = file, memory, license = Elastic License v2, threat_name = Windows.Trojan.Formbook, fingerprint = b8b88451ad8c66b54e21455d835a5d435e52173c86e9b813ffab09451aff7134, id = 1112e116-dee0-4818-a41f-ca5c1c41b4b8, last_modified = 2021-08-23
Source: 7.2.SecuriteInfo.com.Win32.MalwareX-gen.26512.27594.exe.400000.0.raw.unpack, type: UNPACKEDPE Matched rule: Formbook_1 date = 2018-11-23, author = Felix Bilstein - yara-signator at cocacoding dot com, malpedia_version = 20180607, description = autogenerated rule brought to you by yara-signator, malpedia_reference = https://malpedia.caad.fkie.fraunhofer.de/details/win.formbook, cape_type = Formbook Payload, malpedia_license = CC BY-NC-SA 4.0, version = 1, tool = yara-signator 0.1a, malpedia_sharing = TLP:WHITE
Source: 7.2.SecuriteInfo.com.Win32.MalwareX-gen.26512.27594.exe.400000.0.raw.unpack, type: UNPACKEDPE Matched rule: Formbook author = JPCERT/CC Incident Response Group, description = detect Formbook in memory, rule_usage = memory scan, reference = internal research
Source: 7.2.SecuriteInfo.com.Win32.MalwareX-gen.26512.27594.exe.400000.0.unpack, type: UNPACKEDPE Matched rule: Windows_Trojan_Formbook_1112e116 reference_sample = 6246f3b89f0e4913abd88ae535ae3597865270f58201dc7f8ec0c87f15ff370a, os = windows, severity = x86, creation_date = 2021-06-14, scan_context = file, memory, license = Elastic License v2, threat_name = Windows.Trojan.Formbook, fingerprint = b8b88451ad8c66b54e21455d835a5d435e52173c86e9b813ffab09451aff7134, id = 1112e116-dee0-4818-a41f-ca5c1c41b4b8, last_modified = 2021-08-23
Source: 7.2.SecuriteInfo.com.Win32.MalwareX-gen.26512.27594.exe.400000.0.unpack, type: UNPACKEDPE Matched rule: Formbook_1 date = 2018-11-23, author = Felix Bilstein - yara-signator at cocacoding dot com, malpedia_version = 20180607, description = autogenerated rule brought to you by yara-signator, malpedia_reference = https://malpedia.caad.fkie.fraunhofer.de/details/win.formbook, cape_type = Formbook Payload, malpedia_license = CC BY-NC-SA 4.0, version = 1, tool = yara-signator 0.1a, malpedia_sharing = TLP:WHITE
Source: 7.2.SecuriteInfo.com.Win32.MalwareX-gen.26512.27594.exe.400000.0.unpack, type: UNPACKEDPE Matched rule: Formbook author = JPCERT/CC Incident Response Group, description = detect Formbook in memory, rule_usage = memory scan, reference = internal research
Source: 00000007.00000002.1336089947.0000000000400000.00000040.00000400.00020000.00000000.sdmp, type: MEMORY Matched rule: Windows_Trojan_Formbook_1112e116 reference_sample = 6246f3b89f0e4913abd88ae535ae3597865270f58201dc7f8ec0c87f15ff370a, os = windows, severity = x86, creation_date = 2021-06-14, scan_context = file, memory, license = Elastic License v2, threat_name = Windows.Trojan.Formbook, fingerprint = b8b88451ad8c66b54e21455d835a5d435e52173c86e9b813ffab09451aff7134, id = 1112e116-dee0-4818-a41f-ca5c1c41b4b8, last_modified = 2021-08-23
Source: 00000007.00000002.1336089947.0000000000400000.00000040.00000400.00020000.00000000.sdmp, type: MEMORY Matched rule: Formbook_1 date = 2018-11-23, author = Felix Bilstein - yara-signator at cocacoding dot com, malpedia_version = 20180607, description = autogenerated rule brought to you by yara-signator, malpedia_reference = https://malpedia.caad.fkie.fraunhofer.de/details/win.formbook, cape_type = Formbook Payload, malpedia_license = CC BY-NC-SA 4.0, version = 1, tool = yara-signator 0.1a, malpedia_sharing = TLP:WHITE
Source: 00000007.00000002.1336089947.0000000000400000.00000040.00000400.00020000.00000000.sdmp, type: MEMORY Matched rule: Formbook author = JPCERT/CC Incident Response Group, description = detect Formbook in memory, rule_usage = memory scan, reference = internal research
Source: 00000000.00000002.1358724042.000000000359C000.00000004.00000800.00020000.00000000.sdmp, type: MEMORY Matched rule: Windows_Trojan_Formbook_1112e116 reference_sample = 6246f3b89f0e4913abd88ae535ae3597865270f58201dc7f8ec0c87f15ff370a, os = windows, severity = x86, creation_date = 2021-06-14, scan_context = file, memory, license = Elastic License v2, threat_name = Windows.Trojan.Formbook, fingerprint = b8b88451ad8c66b54e21455d835a5d435e52173c86e9b813ffab09451aff7134, id = 1112e116-dee0-4818-a41f-ca5c1c41b4b8, last_modified = 2021-08-23
Source: 00000000.00000002.1358724042.000000000359C000.00000004.00000800.00020000.00000000.sdmp, type: MEMORY Matched rule: Formbook_1 date = 2018-11-23, author = Felix Bilstein - yara-signator at cocacoding dot com, malpedia_version = 20180607, description = autogenerated rule brought to you by yara-signator, malpedia_reference = https://malpedia.caad.fkie.fraunhofer.de/details/win.formbook, cape_type = Formbook Payload, malpedia_license = CC BY-NC-SA 4.0, version = 1, tool = yara-signator 0.1a, malpedia_sharing = TLP:WHITE
Source: 00000000.00000002.1358724042.000000000359C000.00000004.00000800.00020000.00000000.sdmp, type: MEMORY Matched rule: Formbook author = JPCERT/CC Incident Response Group, description = detect Formbook in memory, rule_usage = memory scan, reference = internal research
Source: Process Memory Space: SecuriteInfo.com.Win32.MalwareX-gen.26512.27594.exe PID: 7460, type: MEMORYSTR Matched rule: Windows_Trojan_Formbook_1112e116 reference_sample = 6246f3b89f0e4913abd88ae535ae3597865270f58201dc7f8ec0c87f15ff370a, os = windows, severity = x86, creation_date = 2021-06-14, scan_context = file, memory, license = Elastic License v2, threat_name = Windows.Trojan.Formbook, fingerprint = b8b88451ad8c66b54e21455d835a5d435e52173c86e9b813ffab09451aff7134, id = 1112e116-dee0-4818-a41f-ca5c1c41b4b8, last_modified = 2021-08-23
Source: Process Memory Space: SecuriteInfo.com.Win32.MalwareX-gen.26512.27594.exe PID: 7744, type: MEMORYSTR Matched rule: Windows_Trojan_Formbook_1112e116 reference_sample = 6246f3b89f0e4913abd88ae535ae3597865270f58201dc7f8ec0c87f15ff370a, os = windows, severity = x86, creation_date = 2021-06-14, scan_context = file, memory, license = Elastic License v2, threat_name = Windows.Trojan.Formbook, fingerprint = b8b88451ad8c66b54e21455d835a5d435e52173c86e9b813ffab09451aff7134, id = 1112e116-dee0-4818-a41f-ca5c1c41b4b8, last_modified = 2021-08-23
Source: SecuriteInfo.com.Win32.MalwareX-gen.26512.27594.exe Static PE information: Section: .text IMAGE_SCN_CNT_CODE, IMAGE_SCN_MEM_EXECUTE, IMAGE_SCN_MEM_READ
Source: 0.2.SecuriteInfo.com.Win32.MalwareX-gen.26512.27594.exe.6af0000.4.raw.unpack, xlIEYBw9yIGE6JMOWQ.cs Security API names: System.Security.Principal.WindowsIdentity.GetCurrent()
Source: 0.2.SecuriteInfo.com.Win32.MalwareX-gen.26512.27594.exe.3704520.1.raw.unpack, E4uZqFOLhSMef7LqQC.cs Security API names: System.IO.DirectoryInfo.SetAccessControl(System.Security.AccessControl.DirectorySecurity)
Source: 0.2.SecuriteInfo.com.Win32.MalwareX-gen.26512.27594.exe.3704520.1.raw.unpack, E4uZqFOLhSMef7LqQC.cs Security API names: System.Security.Principal.WindowsIdentity.GetCurrent()
Source: 0.2.SecuriteInfo.com.Win32.MalwareX-gen.26512.27594.exe.3704520.1.raw.unpack, E4uZqFOLhSMef7LqQC.cs Security API names: _0020.AddAccessRule
Source: 0.2.SecuriteInfo.com.Win32.MalwareX-gen.26512.27594.exe.6af0000.4.raw.unpack, E4uZqFOLhSMef7LqQC.cs Security API names: System.IO.DirectoryInfo.SetAccessControl(System.Security.AccessControl.DirectorySecurity)
Source: 0.2.SecuriteInfo.com.Win32.MalwareX-gen.26512.27594.exe.6af0000.4.raw.unpack, E4uZqFOLhSMef7LqQC.cs Security API names: System.Security.Principal.WindowsIdentity.GetCurrent()
Source: 0.2.SecuriteInfo.com.Win32.MalwareX-gen.26512.27594.exe.6af0000.4.raw.unpack, E4uZqFOLhSMef7LqQC.cs Security API names: _0020.AddAccessRule
Source: 0.2.SecuriteInfo.com.Win32.MalwareX-gen.26512.27594.exe.3694500.2.raw.unpack, xlIEYBw9yIGE6JMOWQ.cs Security API names: System.Security.Principal.WindowsIdentity.GetCurrent()
Source: 0.2.SecuriteInfo.com.Win32.MalwareX-gen.26512.27594.exe.3704520.1.raw.unpack, xlIEYBw9yIGE6JMOWQ.cs Security API names: System.Security.Principal.WindowsIdentity.GetCurrent()
Source: 0.2.SecuriteInfo.com.Win32.MalwareX-gen.26512.27594.exe.3694500.2.raw.unpack, E4uZqFOLhSMef7LqQC.cs Security API names: System.IO.DirectoryInfo.SetAccessControl(System.Security.AccessControl.DirectorySecurity)
Source: 0.2.SecuriteInfo.com.Win32.MalwareX-gen.26512.27594.exe.3694500.2.raw.unpack, E4uZqFOLhSMef7LqQC.cs Security API names: System.Security.Principal.WindowsIdentity.GetCurrent()
Source: 0.2.SecuriteInfo.com.Win32.MalwareX-gen.26512.27594.exe.3694500.2.raw.unpack, E4uZqFOLhSMef7LqQC.cs Security API names: _0020.AddAccessRule
Source: classification engine Classification label: mal100.troj.evad.winEXE@11/6@1/0
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.MalwareX-gen.26512.27594.exe File created: C:\Users\user\AppData\Local\Microsoft\CLR_v4.0_32\UsageLogs\SecuriteInfo.com.Win32.MalwareX-gen.26512.27594.exe.log Jump to behavior
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe Mutant created: NULL
Source: C:\Windows\System32\conhost.exe Mutant created: \Sessions\1\BaseNamedObjects\Local\SM0:7700:120:WilError_03
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.MalwareX-gen.26512.27594.exe Mutant created: \Sessions\1\BaseNamedObjects\gxFNYLiZ
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe File created: C:\Users\user\AppData\Local\Temp\__PSScriptPolicyTest_xe3tlqns.qbm.ps1 Jump to behavior
Source: SecuriteInfo.com.Win32.MalwareX-gen.26512.27594.exe Static PE information: Section: .text IMAGE_SCN_CNT_CODE, IMAGE_SCN_MEM_EXECUTE, IMAGE_SCN_MEM_READ
Source: SecuriteInfo.com.Win32.MalwareX-gen.26512.27594.exe Static file information: TRID: Win32 Executable (generic) Net Framework (10011505/4) 49.98%
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.MalwareX-gen.26512.27594.exe File read: C:\Users\user\Desktop\desktop.ini Jump to behavior
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.MalwareX-gen.26512.27594.exe Key opened: HKEY_CURRENT_USER\Software\Policies\Microsoft\Windows\Safer\CodeIdentifiers Jump to behavior
Source: SecuriteInfo.com.Win32.MalwareX-gen.26512.27594.exe Virustotal: Detection: 35%
Source: unknown Process created: C:\Users\user\Desktop\SecuriteInfo.com.Win32.MalwareX-gen.26512.27594.exe "C:\Users\user\Desktop\SecuriteInfo.com.Win32.MalwareX-gen.26512.27594.exe"
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.MalwareX-gen.26512.27594.exe Process created: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe "C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe" Add-MpPreference -ExclusionPath "C:\Users\user\Desktop\SecuriteInfo.com.Win32.MalwareX-gen.26512.27594.exe"
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.MalwareX-gen.26512.27594.exe Process created: C:\Users\user\Desktop\SecuriteInfo.com.Win32.MalwareX-gen.26512.27594.exe "C:\Users\user\Desktop\SecuriteInfo.com.Win32.MalwareX-gen.26512.27594.exe"
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe Process created: C:\Windows\System32\conhost.exe C:\Windows\system32\conhost.exe 0xffffffff -ForceV1
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.MalwareX-gen.26512.27594.exe Process created: C:\Users\user\Desktop\SecuriteInfo.com.Win32.MalwareX-gen.26512.27594.exe "C:\Users\user\Desktop\SecuriteInfo.com.Win32.MalwareX-gen.26512.27594.exe"
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.MalwareX-gen.26512.27594.exe Process created: C:\Users\user\Desktop\SecuriteInfo.com.Win32.MalwareX-gen.26512.27594.exe "C:\Users\user\Desktop\SecuriteInfo.com.Win32.MalwareX-gen.26512.27594.exe"
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe Process created: C:\Windows\System32\wbem\WmiPrvSE.exe C:\Windows\system32\wbem\wmiprvse.exe -secured -Embedding
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.MalwareX-gen.26512.27594.exe Process created: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe "C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe" Add-MpPreference -ExclusionPath "C:\Users\user\Desktop\SecuriteInfo.com.Win32.MalwareX-gen.26512.27594.exe" Jump to behavior
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.MalwareX-gen.26512.27594.exe Process created: C:\Users\user\Desktop\SecuriteInfo.com.Win32.MalwareX-gen.26512.27594.exe "C:\Users\user\Desktop\SecuriteInfo.com.Win32.MalwareX-gen.26512.27594.exe" Jump to behavior
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.MalwareX-gen.26512.27594.exe Process created: C:\Users\user\Desktop\SecuriteInfo.com.Win32.MalwareX-gen.26512.27594.exe "C:\Users\user\Desktop\SecuriteInfo.com.Win32.MalwareX-gen.26512.27594.exe" Jump to behavior
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.MalwareX-gen.26512.27594.exe Process created: C:\Users\user\Desktop\SecuriteInfo.com.Win32.MalwareX-gen.26512.27594.exe "C:\Users\user\Desktop\SecuriteInfo.com.Win32.MalwareX-gen.26512.27594.exe" Jump to behavior
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.MalwareX-gen.26512.27594.exe Section loaded: mscoree.dll Jump to behavior
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.MalwareX-gen.26512.27594.exe Section loaded: apphelp.dll Jump to behavior
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.MalwareX-gen.26512.27594.exe Section loaded: kernel.appcore.dll Jump to behavior
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.MalwareX-gen.26512.27594.exe Section loaded: version.dll Jump to behavior
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.MalwareX-gen.26512.27594.exe Section loaded: vcruntime140_clr0400.dll Jump to behavior
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.MalwareX-gen.26512.27594.exe Section loaded: ucrtbase_clr0400.dll Jump to behavior
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.MalwareX-gen.26512.27594.exe Section loaded: uxtheme.dll Jump to behavior
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.MalwareX-gen.26512.27594.exe Section loaded: windows.storage.dll Jump to behavior
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.MalwareX-gen.26512.27594.exe Section loaded: wldp.dll Jump to behavior
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.MalwareX-gen.26512.27594.exe Section loaded: profapi.dll Jump to behavior
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.MalwareX-gen.26512.27594.exe Section loaded: cryptsp.dll Jump to behavior
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.MalwareX-gen.26512.27594.exe Section loaded: rsaenh.dll Jump to behavior
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.MalwareX-gen.26512.27594.exe Section loaded: cryptbase.dll Jump to behavior
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.MalwareX-gen.26512.27594.exe Section loaded: dwrite.dll Jump to behavior
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.MalwareX-gen.26512.27594.exe Section loaded: textshaping.dll Jump to behavior
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.MalwareX-gen.26512.27594.exe Section loaded: windowscodecs.dll Jump to behavior
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.MalwareX-gen.26512.27594.exe Section loaded: amsi.dll Jump to behavior
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.MalwareX-gen.26512.27594.exe Section loaded: userenv.dll Jump to behavior
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.MalwareX-gen.26512.27594.exe Section loaded: msasn1.dll Jump to behavior
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.MalwareX-gen.26512.27594.exe Section loaded: gpapi.dll Jump to behavior
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.MalwareX-gen.26512.27594.exe Section loaded: propsys.dll Jump to behavior
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.MalwareX-gen.26512.27594.exe Section loaded: edputil.dll Jump to behavior
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.MalwareX-gen.26512.27594.exe Section loaded: urlmon.dll Jump to behavior
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.MalwareX-gen.26512.27594.exe Section loaded: iertutil.dll Jump to behavior
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.MalwareX-gen.26512.27594.exe Section loaded: srvcli.dll Jump to behavior
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.MalwareX-gen.26512.27594.exe Section loaded: netutils.dll Jump to behavior
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.MalwareX-gen.26512.27594.exe Section loaded: windows.staterepositoryps.dll Jump to behavior
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.MalwareX-gen.26512.27594.exe Section loaded: sspicli.dll Jump to behavior
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.MalwareX-gen.26512.27594.exe Section loaded: wintypes.dll Jump to behavior
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.MalwareX-gen.26512.27594.exe Section loaded: appresolver.dll Jump to behavior
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.MalwareX-gen.26512.27594.exe Section loaded: bcp47langs.dll Jump to behavior
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.MalwareX-gen.26512.27594.exe Section loaded: slc.dll Jump to behavior
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.MalwareX-gen.26512.27594.exe Section loaded: sppc.dll Jump to behavior
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.MalwareX-gen.26512.27594.exe Section loaded: onecorecommonproxystub.dll Jump to behavior
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.MalwareX-gen.26512.27594.exe Section loaded: onecoreuapcommonproxystub.dll Jump to behavior
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe Section loaded: atl.dll Jump to behavior
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe Section loaded: mscoree.dll Jump to behavior
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe Section loaded: kernel.appcore.dll Jump to behavior
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe Section loaded: version.dll Jump to behavior
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe Section loaded: vcruntime140_clr0400.dll Jump to behavior
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe Section loaded: ucrtbase_clr0400.dll Jump to behavior
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe Section loaded: ucrtbase_clr0400.dll Jump to behavior
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe Section loaded: cryptsp.dll Jump to behavior
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe Section loaded: rsaenh.dll Jump to behavior
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe Section loaded: cryptbase.dll Jump to behavior
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe Section loaded: windows.storage.dll Jump to behavior
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe Section loaded: wldp.dll Jump to behavior
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe Section loaded: msasn1.dll Jump to behavior
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe Section loaded: amsi.dll Jump to behavior
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe Section loaded: userenv.dll Jump to behavior
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe Section loaded: profapi.dll Jump to behavior
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe Section loaded: gpapi.dll Jump to behavior
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe Section loaded: msisip.dll Jump to behavior
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe Section loaded: wshext.dll Jump to behavior
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe Section loaded: appxsip.dll Jump to behavior
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe Section loaded: opcservices.dll Jump to behavior
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe Section loaded: secur32.dll Jump to behavior
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe Section loaded: sspicli.dll Jump to behavior
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe Section loaded: uxtheme.dll Jump to behavior
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe Section loaded: urlmon.dll Jump to behavior
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe Section loaded: iertutil.dll Jump to behavior
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe Section loaded: srvcli.dll Jump to behavior
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe Section loaded: netutils.dll Jump to behavior
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe Section loaded: propsys.dll Jump to behavior
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe Section loaded: wininet.dll Jump to behavior
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe Section loaded: microsoft.management.infrastructure.native.unmanaged.dll Jump to behavior
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe Section loaded: mi.dll Jump to behavior
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe Section loaded: miutils.dll Jump to behavior
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe Section loaded: wmidcom.dll Jump to behavior
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe Section loaded: dpapi.dll Jump to behavior
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe Section loaded: wbemcomn.dll Jump to behavior
Source: C:\Windows\System32\wbem\WmiPrvSE.exe Section loaded: fastprox.dll Jump to behavior
Source: C:\Windows\System32\wbem\WmiPrvSE.exe Section loaded: ncobjapi.dll Jump to behavior
Source: C:\Windows\System32\wbem\WmiPrvSE.exe Section loaded: wbemcomn.dll Jump to behavior
Source: C:\Windows\System32\wbem\WmiPrvSE.exe Section loaded: kernel.appcore.dll Jump to behavior
Source: C:\Windows\System32\wbem\WmiPrvSE.exe Section loaded: mpclient.dll Jump to behavior
Source: C:\Windows\System32\wbem\WmiPrvSE.exe Section loaded: userenv.dll Jump to behavior
Source: C:\Windows\System32\wbem\WmiPrvSE.exe Section loaded: version.dll Jump to behavior
Source: C:\Windows\System32\wbem\WmiPrvSE.exe Section loaded: msasn1.dll Jump to behavior
Source: C:\Windows\System32\wbem\WmiPrvSE.exe Section loaded: wmitomi.dll Jump to behavior
Source: C:\Windows\System32\wbem\WmiPrvSE.exe Section loaded: mi.dll Jump to behavior
Source: C:\Windows\System32\wbem\WmiPrvSE.exe Section loaded: miutils.dll Jump to behavior
Source: C:\Windows\System32\wbem\WmiPrvSE.exe Section loaded: gpapi.dll Jump to behavior
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.MalwareX-gen.26512.27594.exe Key value queried: HKEY_LOCAL_MACHINE\SOFTWARE\Classes\WOW6432Node\CLSID\{0EE7644B-1BAD-48B1-9889-0281C206EB85}\InprocServer32 Jump to behavior
Source: Window Recorder Window detected: More than 3 window changes detected
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.MalwareX-gen.26512.27594.exe File opened: C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscorrc.dll Jump to behavior
Source: SecuriteInfo.com.Win32.MalwareX-gen.26512.27594.exe Static PE information: data directory type: IMAGE_DIRECTORY_ENTRY_COM_DESCRIPTOR
Source: SecuriteInfo.com.Win32.MalwareX-gen.26512.27594.exe Static PE information: DYNAMIC_BASE, NX_COMPAT, NO_SEH, TERMINAL_SERVER_AWARE
Source: SecuriteInfo.com.Win32.MalwareX-gen.26512.27594.exe Static PE information: data directory type: IMAGE_DIRECTORY_ENTRY_DEBUG
Source: Binary string: iGDc.pdbSHA256 source: SecuriteInfo.com.Win32.MalwareX-gen.26512.27594.exe
Source: Binary string: wntdll.pdbUGP source: SecuriteInfo.com.Win32.MalwareX-gen.26512.27594.exe, 00000007.00000002.1336299278.00000000010D0000.00000040.00001000.00020000.00000000.sdmp
Source: Binary string: wntdll.pdb source: SecuriteInfo.com.Win32.MalwareX-gen.26512.27594.exe, SecuriteInfo.com.Win32.MalwareX-gen.26512.27594.exe, 00000007.00000002.1336299278.00000000010D0000.00000040.00001000.00020000.00000000.sdmp
Source: Binary string: iGDc.pdb source: SecuriteInfo.com.Win32.MalwareX-gen.26512.27594.exe

Data Obfuscation

barindex
Source: 0.2.SecuriteInfo.com.Win32.MalwareX-gen.26512.27594.exe.67b0000.3.raw.unpack, RZ.cs .Net Code: System.Reflection.Assembly.Load(byte[])
Source: 0.2.SecuriteInfo.com.Win32.MalwareX-gen.26512.27594.exe.3694500.2.raw.unpack, E4uZqFOLhSMef7LqQC.cs .Net Code: GlqSWLFtcA System.Reflection.Assembly.Load(byte[])
Source: 0.2.SecuriteInfo.com.Win32.MalwareX-gen.26512.27594.exe.6af0000.4.raw.unpack, E4uZqFOLhSMef7LqQC.cs .Net Code: GlqSWLFtcA System.Reflection.Assembly.Load(byte[])
Source: 0.2.SecuriteInfo.com.Win32.MalwareX-gen.26512.27594.exe.3704520.1.raw.unpack, E4uZqFOLhSMef7LqQC.cs .Net Code: GlqSWLFtcA System.Reflection.Assembly.Load(byte[])
Source: 0.2.SecuriteInfo.com.Win32.MalwareX-gen.26512.27594.exe.25e9d94.0.raw.unpack, RZ.cs .Net Code: System.Reflection.Assembly.Load(byte[])
Source: SecuriteInfo.com.Win32.MalwareX-gen.26512.27594.exe Static PE information: 0xD4049BCC [Sat Sep 19 19:30:20 2082 UTC]
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.MalwareX-gen.26512.27594.exe Code function: 0_2_067FD801 push es; ret 0_2_067FD810
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.MalwareX-gen.26512.27594.exe Code function: 0_2_06805648 pushfd ; iretd 0_2_068056F9
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.MalwareX-gen.26512.27594.exe Code function: 0_2_068056F0 pushfd ; iretd 0_2_068056F9
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.MalwareX-gen.26512.27594.exe Code function: 0_2_06805613 pushad ; iretd 0_2_06805639
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.MalwareX-gen.26512.27594.exe Code function: 0_2_0680AE19 push eax; mov dword ptr [esp], edx 0_2_0680AE2C
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.MalwareX-gen.26512.27594.exe Code function: 0_2_0684DE8B push eax; ret 0_2_0684DE91
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.MalwareX-gen.26512.27594.exe Code function: 7_2_0041D842 push CE770B89h; ret 7_2_0041D64A
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.MalwareX-gen.26512.27594.exe Code function: 7_2_0041E1D5 push CE770B89h; ret 7_2_0041D64A
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.MalwareX-gen.26512.27594.exe Code function: 7_2_0041DAED push CE770B89h; ret 7_2_0041D64A
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.MalwareX-gen.26512.27594.exe Code function: 7_2_0041DB45 push CE770B89h; ret 7_2_0041D64A
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.MalwareX-gen.26512.27594.exe Code function: 7_2_0040E355 push ebp; iretd 7_2_0040E381
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.MalwareX-gen.26512.27594.exe Code function: 7_2_0041D475 push eax; ret 7_2_0041D4C8
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.MalwareX-gen.26512.27594.exe Code function: 7_2_0041DC0E push CE770B89h; ret 7_2_0041D64A
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.MalwareX-gen.26512.27594.exe Code function: 7_2_0041D4C2 push eax; ret 7_2_0041D4C8
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.MalwareX-gen.26512.27594.exe Code function: 7_2_0041D4CB push eax; ret 7_2_0041D532
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.MalwareX-gen.26512.27594.exe Code function: 7_2_00417CDD push ecx; retf 7_2_00417CF0
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.MalwareX-gen.26512.27594.exe Code function: 7_2_0041D566 push CE770B89h; ret 7_2_0041D64A
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.MalwareX-gen.26512.27594.exe Code function: 7_2_0041D52C push eax; ret 7_2_0041D532
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.MalwareX-gen.26512.27594.exe Code function: 7_2_00416649 push ebx; iretd 7_2_0041664B
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.MalwareX-gen.26512.27594.exe Code function: 7_2_0041DE5D push CE770B89h; ret 7_2_0041D64A
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.MalwareX-gen.26512.27594.exe Code function: 7_2_0041D65F push CE770B89h; ret 7_2_0041D64A
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.MalwareX-gen.26512.27594.exe Code function: 7_2_0041DF5A push CE770B89h; ret 7_2_0041D64A
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.MalwareX-gen.26512.27594.exe Code function: 7_2_010D225F pushad ; ret 7_2_010D27F9
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.MalwareX-gen.26512.27594.exe Code function: 7_2_010D27FA pushad ; ret 7_2_010D27F9
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.MalwareX-gen.26512.27594.exe Code function: 7_2_011009AD push ecx; mov dword ptr [esp], ecx 7_2_011009B6
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.MalwareX-gen.26512.27594.exe Code function: 7_2_010D283D push eax; iretd 7_2_010D2858
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.MalwareX-gen.26512.27594.exe Code function: 7_2_010D1368 push eax; iretd 7_2_010D1369
Source: SecuriteInfo.com.Win32.MalwareX-gen.26512.27594.exe Static PE information: section name: .text entropy: 7.736784074386954
Source: 0.2.SecuriteInfo.com.Win32.MalwareX-gen.26512.27594.exe.3694500.2.raw.unpack, wvyFp5lEMaXfIDvbM4g.cs High entropy of concatenated method names: 'CanConvertFrom', 'ConvertFrom', 'ConvertTo', 'z0rfRsnEaV', 'MKbfuxmesF', 'TbtfFKRq03', 'e7RfvuQXWh', 'rNFfVcO9SM', 'QsffNHS43N', 'RoVfC7IVAq'
Source: 0.2.SecuriteInfo.com.Win32.MalwareX-gen.26512.27594.exe.3694500.2.raw.unpack, o35qSosUGnefXxGkm9.cs High entropy of concatenated method names: 'UuGb5WCYBm', 'xoqbw0fbZU', 'BP5bKaabiZ', 'tpubj4VTdK', 'pO3b8uA9T4', 'V4SbUPCYxs', 'niGbhbRc5E', 'Ehob7Xj9WN', 'mDVbQRTNbF', 'R2GbfjEV7O'
Source: 0.2.SecuriteInfo.com.Win32.MalwareX-gen.26512.27594.exe.3694500.2.raw.unpack, CpNlZy8hqofMdFNKt0.cs High entropy of concatenated method names: 'PMNrljTqKm', 'fDarbgK2Y2', 'jR1roYPXgO', 's58oXpgiW5', 'eLdozBduPo', 'U0ErIecsxZ', 'i26rOTGfIF', 'pSDr0Lk5xu', 'qcGrsfqedj', 'KhSrS5TtBQ'
Source: 0.2.SecuriteInfo.com.Win32.MalwareX-gen.26512.27594.exe.3694500.2.raw.unpack, E4uZqFOLhSMef7LqQC.cs High entropy of concatenated method names: 'Cr8s6QHGZr', 'IdysldHUlT', 'CeysH1PWUs', 'ujnsbiRM3W', 'zgusYoJG0s', 'RXRsoIDI8v', 'tbxsr7GPVq', 'pOksJNpFFp', 'bcQskAB0vC', 'KposnOXEvH'
Source: 0.2.SecuriteInfo.com.Win32.MalwareX-gen.26512.27594.exe.3694500.2.raw.unpack, IeoGratBW3O1qvysQn.cs High entropy of concatenated method names: 'xG67laWdWb', 'byE7Hig4n0', 'A8l7bwSRK2', 'dOK7YGeQIC', 'HV87oimJfK', 'Kri7ryrxkk', 'c2b7J2thxb', 'v9S7k75glI', 'UaS7nyNObm', 'Chg7t3GPff'
Source: 0.2.SecuriteInfo.com.Win32.MalwareX-gen.26512.27594.exe.3694500.2.raw.unpack, AFVuE3FDqBXyamboG8.cs High entropy of concatenated method names: 'Q2j79Twmg9', 'MFQ7L1yaNs', 'fuH71h1YZ4', 'OLU7pCSkFv', 'Wxm7Re04ZH', 'xyG7qTAxXj', 'Next', 'Next', 'Next', 'NextBytes'
Source: 0.2.SecuriteInfo.com.Win32.MalwareX-gen.26512.27594.exe.3694500.2.raw.unpack, xlIEYBw9yIGE6JMOWQ.cs High entropy of concatenated method names: 'ob5HREyBPI', 'j9CHua8Usu', 'JdkHFVob9F', 'ecnHv2SMHo', 'kRMHVoc0bC', 'GSAHNsEk8Q', 'hWWHCeMZpu', 'vT9HyG2gf8', 'eYdHBp5M5a', 'E9EHXAtrbs'
Source: 0.2.SecuriteInfo.com.Win32.MalwareX-gen.26512.27594.exe.3694500.2.raw.unpack, FXj55bXUxxvboVoahD.cs High entropy of concatenated method names: 'UIoQOsiAni', 'fuQQsCGNUZ', 'vXgQSwBFf5', 'jQQQlnLy9w', 'Rt0QHiQFMD', 'MWYQYIy2ml', 'LPyQopGXqb', 'yTW7C61ldj', 'avo7yGTMiP', 'Utw7BEAoO9'
Source: 0.2.SecuriteInfo.com.Win32.MalwareX-gen.26512.27594.exe.3694500.2.raw.unpack, EmYPgEMBQCWZ9A4T72.cs High entropy of concatenated method names: 'hWho6rZDfl', 'LRtoHHsSIv', 'cEMoY8rOtD', 'RsroroUM0M', 'zQCoJxsFlZ', 'JFuYVNscs4', 'kmLYNPNFP3', 'XEtYCOxa3a', 'qn4Yyy6EYN', 'x05YBMY8D5'
Source: 0.2.SecuriteInfo.com.Win32.MalwareX-gen.26512.27594.exe.3694500.2.raw.unpack, XpOWKj9AUfhiB883bx.cs High entropy of concatenated method names: 'ommWTkMnF', 'BHu53l7Q0', 'V7Qw7Lrq0', 'OvTdWqRdX', 'hOnj1dnfS', 'z2g3fCkfA', 'l40ID9aNCGBNcpaiKt', 'TpcyXR3bEPnEEwBm67', 'wwZ7CyD2l', 'gVQf2cP3W'
Source: 0.2.SecuriteInfo.com.Win32.MalwareX-gen.26512.27594.exe.3694500.2.raw.unpack, RUmI4MNnoe3hw9LtV7.cs High entropy of concatenated method names: 'FfhhnIdtDV', 'kmchtkCpVJ', 'ToString', 'NEWhlgswr4', 'tDchHccke8', 'pXrhbp33Hc', 'zsOhYi4Iu5', 'SHohoPvi2N', 'vZ1hrVCEhW', 'SIThJg9nFm'
Source: 0.2.SecuriteInfo.com.Win32.MalwareX-gen.26512.27594.exe.3694500.2.raw.unpack, Wf4kesqoACHAE2XEBm.cs High entropy of concatenated method names: 'BBcrPRZylc', 'EwErm8DnUd', 'XwPrWZ3Vga', 'cqer58qBu1', 'rTlrZLWxUR', 'xvKrwfkruL', 'JrLrdb49IH', 'DrprKH5ZgF', 'F2urjqHpuh', 'pQ7r31H3v8'
Source: 0.2.SecuriteInfo.com.Win32.MalwareX-gen.26512.27594.exe.3694500.2.raw.unpack, dAsYu2USK2159UQ6ET.cs High entropy of concatenated method names: 'Kl1hym0xFh', 'IUXhXgr69a', 'kby7IBTQoG', 'PrV7OTHgP2', 'pZEhiHavLj', 'KZHh4xp3qU', 'lGGhxITytH', 'oHahR4XIPo', 'zQrhuVBajw', 'xfJhFwfJtB'
Source: 0.2.SecuriteInfo.com.Win32.MalwareX-gen.26512.27594.exe.3694500.2.raw.unpack, CFlKvelphoBZvK4hXgV.cs High entropy of concatenated method names: 'klCQPskB0t', 'jbcQm8R5aF', 'aYVQWHtQCZ', 'NwrQ5nRD1X', 'XrJQZQ70ML', 'VutQw8CRrG', 'dcrQdWFXvl', 'CqZQKFmwca', 'EVqQj65cQQ', 'CAsQ3TuV5Z'
Source: 0.2.SecuriteInfo.com.Win32.MalwareX-gen.26512.27594.exe.3694500.2.raw.unpack, KAMcFOG423RXbKqhOW.cs High entropy of concatenated method names: 'ODiDKx1fLr', 'mXqDjbi15c', 'MgZD9p337e', 'jRtDLihBvf', 'd1eDp7ohvy', 'HEODq6X20D', 'HR9DEi3VNZ', 'P7jDMgFY7F', 'Uj8DTbHO1r', 'BjqDiR4vDY'
Source: 0.2.SecuriteInfo.com.Win32.MalwareX-gen.26512.27594.exe.3694500.2.raw.unpack, TAQYtDBT26ov40cDwc.cs High entropy of concatenated method names: 'XoEOrsnfRJ', 'CBDOJvWC9D', 'Y6LOn6UhQX', 'YZ5OtDqKvW', 'UKkO8YbQnQ', 'It7OU2m23G', 'K66p21qbf7PPHbyGXE', 'thJShxC4dorDkZLDMb', 'hNBOOeFvo5', 'M8OOsjvXj5'
Source: 0.2.SecuriteInfo.com.Win32.MalwareX-gen.26512.27594.exe.3694500.2.raw.unpack, zvnvEjou1LWx6J2FCc.cs High entropy of concatenated method names: 'Dispose', 'imoOB4wB27', 'Qp30Lh8uGg', 'Ah4ee9VFe7', 'U5TOXviPBt', 'R1IOzZqcn3', 'ProcessDialogKey', 'st30IY1sf3', 'bNe0OjMX5n', 'wQg00oCUQA'
Source: 0.2.SecuriteInfo.com.Win32.MalwareX-gen.26512.27594.exe.3694500.2.raw.unpack, vmprtQzxvSgJjUwOlW.cs High entropy of concatenated method names: 'CanConvertFrom', 'ConvertFrom', 'ConvertTo', 'X5wQDnc22N', 'H9MQ85bpu8', 'fG3QUxs5SK', 'QHBQhAM1QE', 'SarQ7sacBx', 'SSFQQL8nir', 'IcLQf3O3x5'
Source: 0.2.SecuriteInfo.com.Win32.MalwareX-gen.26512.27594.exe.3694500.2.raw.unpack, LuG0j34VKrxiUTTP4k.cs High entropy of concatenated method names: 'zpm8T2qBBL', 'Dfi845Uo9S', 'Bku8RwRbw5', 'hK08uVyAMy', 'SOe8L2KLCf', 'mog81lp1D9', 'FsN8pZCs2o', 'orF8qCEccZ', 'MQu8GFbSdS', 'u3H8EvhaJA'
Source: 0.2.SecuriteInfo.com.Win32.MalwareX-gen.26512.27594.exe.6af0000.4.raw.unpack, wvyFp5lEMaXfIDvbM4g.cs High entropy of concatenated method names: 'CanConvertFrom', 'ConvertFrom', 'ConvertTo', 'z0rfRsnEaV', 'MKbfuxmesF', 'TbtfFKRq03', 'e7RfvuQXWh', 'rNFfVcO9SM', 'QsffNHS43N', 'RoVfC7IVAq'
Source: 0.2.SecuriteInfo.com.Win32.MalwareX-gen.26512.27594.exe.6af0000.4.raw.unpack, o35qSosUGnefXxGkm9.cs High entropy of concatenated method names: 'UuGb5WCYBm', 'xoqbw0fbZU', 'BP5bKaabiZ', 'tpubj4VTdK', 'pO3b8uA9T4', 'V4SbUPCYxs', 'niGbhbRc5E', 'Ehob7Xj9WN', 'mDVbQRTNbF', 'R2GbfjEV7O'
Source: 0.2.SecuriteInfo.com.Win32.MalwareX-gen.26512.27594.exe.6af0000.4.raw.unpack, CpNlZy8hqofMdFNKt0.cs High entropy of concatenated method names: 'PMNrljTqKm', 'fDarbgK2Y2', 'jR1roYPXgO', 's58oXpgiW5', 'eLdozBduPo', 'U0ErIecsxZ', 'i26rOTGfIF', 'pSDr0Lk5xu', 'qcGrsfqedj', 'KhSrS5TtBQ'
Source: 0.2.SecuriteInfo.com.Win32.MalwareX-gen.26512.27594.exe.6af0000.4.raw.unpack, E4uZqFOLhSMef7LqQC.cs High entropy of concatenated method names: 'Cr8s6QHGZr', 'IdysldHUlT', 'CeysH1PWUs', 'ujnsbiRM3W', 'zgusYoJG0s', 'RXRsoIDI8v', 'tbxsr7GPVq', 'pOksJNpFFp', 'bcQskAB0vC', 'KposnOXEvH'
Source: 0.2.SecuriteInfo.com.Win32.MalwareX-gen.26512.27594.exe.6af0000.4.raw.unpack, IeoGratBW3O1qvysQn.cs High entropy of concatenated method names: 'xG67laWdWb', 'byE7Hig4n0', 'A8l7bwSRK2', 'dOK7YGeQIC', 'HV87oimJfK', 'Kri7ryrxkk', 'c2b7J2thxb', 'v9S7k75glI', 'UaS7nyNObm', 'Chg7t3GPff'
Source: 0.2.SecuriteInfo.com.Win32.MalwareX-gen.26512.27594.exe.6af0000.4.raw.unpack, AFVuE3FDqBXyamboG8.cs High entropy of concatenated method names: 'Q2j79Twmg9', 'MFQ7L1yaNs', 'fuH71h1YZ4', 'OLU7pCSkFv', 'Wxm7Re04ZH', 'xyG7qTAxXj', 'Next', 'Next', 'Next', 'NextBytes'
Source: 0.2.SecuriteInfo.com.Win32.MalwareX-gen.26512.27594.exe.6af0000.4.raw.unpack, xlIEYBw9yIGE6JMOWQ.cs High entropy of concatenated method names: 'ob5HREyBPI', 'j9CHua8Usu', 'JdkHFVob9F', 'ecnHv2SMHo', 'kRMHVoc0bC', 'GSAHNsEk8Q', 'hWWHCeMZpu', 'vT9HyG2gf8', 'eYdHBp5M5a', 'E9EHXAtrbs'
Source: 0.2.SecuriteInfo.com.Win32.MalwareX-gen.26512.27594.exe.6af0000.4.raw.unpack, FXj55bXUxxvboVoahD.cs High entropy of concatenated method names: 'UIoQOsiAni', 'fuQQsCGNUZ', 'vXgQSwBFf5', 'jQQQlnLy9w', 'Rt0QHiQFMD', 'MWYQYIy2ml', 'LPyQopGXqb', 'yTW7C61ldj', 'avo7yGTMiP', 'Utw7BEAoO9'
Source: 0.2.SecuriteInfo.com.Win32.MalwareX-gen.26512.27594.exe.6af0000.4.raw.unpack, EmYPgEMBQCWZ9A4T72.cs High entropy of concatenated method names: 'hWho6rZDfl', 'LRtoHHsSIv', 'cEMoY8rOtD', 'RsroroUM0M', 'zQCoJxsFlZ', 'JFuYVNscs4', 'kmLYNPNFP3', 'XEtYCOxa3a', 'qn4Yyy6EYN', 'x05YBMY8D5'
Source: 0.2.SecuriteInfo.com.Win32.MalwareX-gen.26512.27594.exe.6af0000.4.raw.unpack, XpOWKj9AUfhiB883bx.cs High entropy of concatenated method names: 'ommWTkMnF', 'BHu53l7Q0', 'V7Qw7Lrq0', 'OvTdWqRdX', 'hOnj1dnfS', 'z2g3fCkfA', 'l40ID9aNCGBNcpaiKt', 'TpcyXR3bEPnEEwBm67', 'wwZ7CyD2l', 'gVQf2cP3W'
Source: 0.2.SecuriteInfo.com.Win32.MalwareX-gen.26512.27594.exe.6af0000.4.raw.unpack, RUmI4MNnoe3hw9LtV7.cs High entropy of concatenated method names: 'FfhhnIdtDV', 'kmchtkCpVJ', 'ToString', 'NEWhlgswr4', 'tDchHccke8', 'pXrhbp33Hc', 'zsOhYi4Iu5', 'SHohoPvi2N', 'vZ1hrVCEhW', 'SIThJg9nFm'
Source: 0.2.SecuriteInfo.com.Win32.MalwareX-gen.26512.27594.exe.6af0000.4.raw.unpack, Wf4kesqoACHAE2XEBm.cs High entropy of concatenated method names: 'BBcrPRZylc', 'EwErm8DnUd', 'XwPrWZ3Vga', 'cqer58qBu1', 'rTlrZLWxUR', 'xvKrwfkruL', 'JrLrdb49IH', 'DrprKH5ZgF', 'F2urjqHpuh', 'pQ7r31H3v8'
Source: 0.2.SecuriteInfo.com.Win32.MalwareX-gen.26512.27594.exe.6af0000.4.raw.unpack, dAsYu2USK2159UQ6ET.cs High entropy of concatenated method names: 'Kl1hym0xFh', 'IUXhXgr69a', 'kby7IBTQoG', 'PrV7OTHgP2', 'pZEhiHavLj', 'KZHh4xp3qU', 'lGGhxITytH', 'oHahR4XIPo', 'zQrhuVBajw', 'xfJhFwfJtB'
Source: 0.2.SecuriteInfo.com.Win32.MalwareX-gen.26512.27594.exe.6af0000.4.raw.unpack, CFlKvelphoBZvK4hXgV.cs High entropy of concatenated method names: 'klCQPskB0t', 'jbcQm8R5aF', 'aYVQWHtQCZ', 'NwrQ5nRD1X', 'XrJQZQ70ML', 'VutQw8CRrG', 'dcrQdWFXvl', 'CqZQKFmwca', 'EVqQj65cQQ', 'CAsQ3TuV5Z'
Source: 0.2.SecuriteInfo.com.Win32.MalwareX-gen.26512.27594.exe.6af0000.4.raw.unpack, KAMcFOG423RXbKqhOW.cs High entropy of concatenated method names: 'ODiDKx1fLr', 'mXqDjbi15c', 'MgZD9p337e', 'jRtDLihBvf', 'd1eDp7ohvy', 'HEODq6X20D', 'HR9DEi3VNZ', 'P7jDMgFY7F', 'Uj8DTbHO1r', 'BjqDiR4vDY'
Source: 0.2.SecuriteInfo.com.Win32.MalwareX-gen.26512.27594.exe.6af0000.4.raw.unpack, TAQYtDBT26ov40cDwc.cs High entropy of concatenated method names: 'XoEOrsnfRJ', 'CBDOJvWC9D', 'Y6LOn6UhQX', 'YZ5OtDqKvW', 'UKkO8YbQnQ', 'It7OU2m23G', 'K66p21qbf7PPHbyGXE', 'thJShxC4dorDkZLDMb', 'hNBOOeFvo5', 'M8OOsjvXj5'
Source: 0.2.SecuriteInfo.com.Win32.MalwareX-gen.26512.27594.exe.6af0000.4.raw.unpack, zvnvEjou1LWx6J2FCc.cs High entropy of concatenated method names: 'Dispose', 'imoOB4wB27', 'Qp30Lh8uGg', 'Ah4ee9VFe7', 'U5TOXviPBt', 'R1IOzZqcn3', 'ProcessDialogKey', 'st30IY1sf3', 'bNe0OjMX5n', 'wQg00oCUQA'
Source: 0.2.SecuriteInfo.com.Win32.MalwareX-gen.26512.27594.exe.6af0000.4.raw.unpack, vmprtQzxvSgJjUwOlW.cs High entropy of concatenated method names: 'CanConvertFrom', 'ConvertFrom', 'ConvertTo', 'X5wQDnc22N', 'H9MQ85bpu8', 'fG3QUxs5SK', 'QHBQhAM1QE', 'SarQ7sacBx', 'SSFQQL8nir', 'IcLQf3O3x5'
Source: 0.2.SecuriteInfo.com.Win32.MalwareX-gen.26512.27594.exe.6af0000.4.raw.unpack, LuG0j34VKrxiUTTP4k.cs High entropy of concatenated method names: 'zpm8T2qBBL', 'Dfi845Uo9S', 'Bku8RwRbw5', 'hK08uVyAMy', 'SOe8L2KLCf', 'mog81lp1D9', 'FsN8pZCs2o', 'orF8qCEccZ', 'MQu8GFbSdS', 'u3H8EvhaJA'
Source: 0.2.SecuriteInfo.com.Win32.MalwareX-gen.26512.27594.exe.3704520.1.raw.unpack, wvyFp5lEMaXfIDvbM4g.cs High entropy of concatenated method names: 'CanConvertFrom', 'ConvertFrom', 'ConvertTo', 'z0rfRsnEaV', 'MKbfuxmesF', 'TbtfFKRq03', 'e7RfvuQXWh', 'rNFfVcO9SM', 'QsffNHS43N', 'RoVfC7IVAq'
Source: 0.2.SecuriteInfo.com.Win32.MalwareX-gen.26512.27594.exe.3704520.1.raw.unpack, o35qSosUGnefXxGkm9.cs High entropy of concatenated method names: 'UuGb5WCYBm', 'xoqbw0fbZU', 'BP5bKaabiZ', 'tpubj4VTdK', 'pO3b8uA9T4', 'V4SbUPCYxs', 'niGbhbRc5E', 'Ehob7Xj9WN', 'mDVbQRTNbF', 'R2GbfjEV7O'
Source: 0.2.SecuriteInfo.com.Win32.MalwareX-gen.26512.27594.exe.3704520.1.raw.unpack, CpNlZy8hqofMdFNKt0.cs High entropy of concatenated method names: 'PMNrljTqKm', 'fDarbgK2Y2', 'jR1roYPXgO', 's58oXpgiW5', 'eLdozBduPo', 'U0ErIecsxZ', 'i26rOTGfIF', 'pSDr0Lk5xu', 'qcGrsfqedj', 'KhSrS5TtBQ'
Source: 0.2.SecuriteInfo.com.Win32.MalwareX-gen.26512.27594.exe.3704520.1.raw.unpack, E4uZqFOLhSMef7LqQC.cs High entropy of concatenated method names: 'Cr8s6QHGZr', 'IdysldHUlT', 'CeysH1PWUs', 'ujnsbiRM3W', 'zgusYoJG0s', 'RXRsoIDI8v', 'tbxsr7GPVq', 'pOksJNpFFp', 'bcQskAB0vC', 'KposnOXEvH'
Source: 0.2.SecuriteInfo.com.Win32.MalwareX-gen.26512.27594.exe.3704520.1.raw.unpack, IeoGratBW3O1qvysQn.cs High entropy of concatenated method names: 'xG67laWdWb', 'byE7Hig4n0', 'A8l7bwSRK2', 'dOK7YGeQIC', 'HV87oimJfK', 'Kri7ryrxkk', 'c2b7J2thxb', 'v9S7k75glI', 'UaS7nyNObm', 'Chg7t3GPff'
Source: 0.2.SecuriteInfo.com.Win32.MalwareX-gen.26512.27594.exe.3704520.1.raw.unpack, AFVuE3FDqBXyamboG8.cs High entropy of concatenated method names: 'Q2j79Twmg9', 'MFQ7L1yaNs', 'fuH71h1YZ4', 'OLU7pCSkFv', 'Wxm7Re04ZH', 'xyG7qTAxXj', 'Next', 'Next', 'Next', 'NextBytes'
Source: 0.2.SecuriteInfo.com.Win32.MalwareX-gen.26512.27594.exe.3704520.1.raw.unpack, xlIEYBw9yIGE6JMOWQ.cs High entropy of concatenated method names: 'ob5HREyBPI', 'j9CHua8Usu', 'JdkHFVob9F', 'ecnHv2SMHo', 'kRMHVoc0bC', 'GSAHNsEk8Q', 'hWWHCeMZpu', 'vT9HyG2gf8', 'eYdHBp5M5a', 'E9EHXAtrbs'
Source: 0.2.SecuriteInfo.com.Win32.MalwareX-gen.26512.27594.exe.3704520.1.raw.unpack, FXj55bXUxxvboVoahD.cs High entropy of concatenated method names: 'UIoQOsiAni', 'fuQQsCGNUZ', 'vXgQSwBFf5', 'jQQQlnLy9w', 'Rt0QHiQFMD', 'MWYQYIy2ml', 'LPyQopGXqb', 'yTW7C61ldj', 'avo7yGTMiP', 'Utw7BEAoO9'
Source: 0.2.SecuriteInfo.com.Win32.MalwareX-gen.26512.27594.exe.3704520.1.raw.unpack, EmYPgEMBQCWZ9A4T72.cs High entropy of concatenated method names: 'hWho6rZDfl', 'LRtoHHsSIv', 'cEMoY8rOtD', 'RsroroUM0M', 'zQCoJxsFlZ', 'JFuYVNscs4', 'kmLYNPNFP3', 'XEtYCOxa3a', 'qn4Yyy6EYN', 'x05YBMY8D5'
Source: 0.2.SecuriteInfo.com.Win32.MalwareX-gen.26512.27594.exe.3704520.1.raw.unpack, XpOWKj9AUfhiB883bx.cs High entropy of concatenated method names: 'ommWTkMnF', 'BHu53l7Q0', 'V7Qw7Lrq0', 'OvTdWqRdX', 'hOnj1dnfS', 'z2g3fCkfA', 'l40ID9aNCGBNcpaiKt', 'TpcyXR3bEPnEEwBm67', 'wwZ7CyD2l', 'gVQf2cP3W'
Source: 0.2.SecuriteInfo.com.Win32.MalwareX-gen.26512.27594.exe.3704520.1.raw.unpack, RUmI4MNnoe3hw9LtV7.cs High entropy of concatenated method names: 'FfhhnIdtDV', 'kmchtkCpVJ', 'ToString', 'NEWhlgswr4', 'tDchHccke8', 'pXrhbp33Hc', 'zsOhYi4Iu5', 'SHohoPvi2N', 'vZ1hrVCEhW', 'SIThJg9nFm'
Source: 0.2.SecuriteInfo.com.Win32.MalwareX-gen.26512.27594.exe.3704520.1.raw.unpack, Wf4kesqoACHAE2XEBm.cs High entropy of concatenated method names: 'BBcrPRZylc', 'EwErm8DnUd', 'XwPrWZ3Vga', 'cqer58qBu1', 'rTlrZLWxUR', 'xvKrwfkruL', 'JrLrdb49IH', 'DrprKH5ZgF', 'F2urjqHpuh', 'pQ7r31H3v8'
Source: 0.2.SecuriteInfo.com.Win32.MalwareX-gen.26512.27594.exe.3704520.1.raw.unpack, dAsYu2USK2159UQ6ET.cs High entropy of concatenated method names: 'Kl1hym0xFh', 'IUXhXgr69a', 'kby7IBTQoG', 'PrV7OTHgP2', 'pZEhiHavLj', 'KZHh4xp3qU', 'lGGhxITytH', 'oHahR4XIPo', 'zQrhuVBajw', 'xfJhFwfJtB'
Source: 0.2.SecuriteInfo.com.Win32.MalwareX-gen.26512.27594.exe.3704520.1.raw.unpack, CFlKvelphoBZvK4hXgV.cs High entropy of concatenated method names: 'klCQPskB0t', 'jbcQm8R5aF', 'aYVQWHtQCZ', 'NwrQ5nRD1X', 'XrJQZQ70ML', 'VutQw8CRrG', 'dcrQdWFXvl', 'CqZQKFmwca', 'EVqQj65cQQ', 'CAsQ3TuV5Z'
Source: 0.2.SecuriteInfo.com.Win32.MalwareX-gen.26512.27594.exe.3704520.1.raw.unpack, KAMcFOG423RXbKqhOW.cs High entropy of concatenated method names: 'ODiDKx1fLr', 'mXqDjbi15c', 'MgZD9p337e', 'jRtDLihBvf', 'd1eDp7ohvy', 'HEODq6X20D', 'HR9DEi3VNZ', 'P7jDMgFY7F', 'Uj8DTbHO1r', 'BjqDiR4vDY'
Source: 0.2.SecuriteInfo.com.Win32.MalwareX-gen.26512.27594.exe.3704520.1.raw.unpack, TAQYtDBT26ov40cDwc.cs High entropy of concatenated method names: 'XoEOrsnfRJ', 'CBDOJvWC9D', 'Y6LOn6UhQX', 'YZ5OtDqKvW', 'UKkO8YbQnQ', 'It7OU2m23G', 'K66p21qbf7PPHbyGXE', 'thJShxC4dorDkZLDMb', 'hNBOOeFvo5', 'M8OOsjvXj5'
Source: 0.2.SecuriteInfo.com.Win32.MalwareX-gen.26512.27594.exe.3704520.1.raw.unpack, zvnvEjou1LWx6J2FCc.cs High entropy of concatenated method names: 'Dispose', 'imoOB4wB27', 'Qp30Lh8uGg', 'Ah4ee9VFe7', 'U5TOXviPBt', 'R1IOzZqcn3', 'ProcessDialogKey', 'st30IY1sf3', 'bNe0OjMX5n', 'wQg00oCUQA'
Source: 0.2.SecuriteInfo.com.Win32.MalwareX-gen.26512.27594.exe.3704520.1.raw.unpack, vmprtQzxvSgJjUwOlW.cs High entropy of concatenated method names: 'CanConvertFrom', 'ConvertFrom', 'ConvertTo', 'X5wQDnc22N', 'H9MQ85bpu8', 'fG3QUxs5SK', 'QHBQhAM1QE', 'SarQ7sacBx', 'SSFQQL8nir', 'IcLQf3O3x5'
Source: 0.2.SecuriteInfo.com.Win32.MalwareX-gen.26512.27594.exe.3704520.1.raw.unpack, LuG0j34VKrxiUTTP4k.cs High entropy of concatenated method names: 'zpm8T2qBBL', 'Dfi845Uo9S', 'Bku8RwRbw5', 'hK08uVyAMy', 'SOe8L2KLCf', 'mog81lp1D9', 'FsN8pZCs2o', 'orF8qCEccZ', 'MQu8GFbSdS', 'u3H8EvhaJA'

Hooking and other Techniques for Hiding and Protection

barindex
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe File opened: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\Modules\BitLocker\BitLocker.psd1 Jump to behavior
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe File opened: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\Modules\BitLocker\BitLocker.psd1 Jump to behavior
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe File opened: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\Modules\BitLocker\BitLocker.psd1 Jump to behavior
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe File opened: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\Modules\BitLocker\en-US\BitLocker.psd1 Jump to behavior
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe File opened: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\Modules\BitLocker\en-US\BitLocker.psd1 Jump to behavior
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe File opened: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\Modules\BitLocker\BitLocker.psd1 Jump to behavior
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe File opened: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\Modules\BitLocker\en-US\BitLocker.psd1 Jump to behavior
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.MalwareX-gen.26512.27594.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.MalwareX-gen.26512.27594.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.MalwareX-gen.26512.27594.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.MalwareX-gen.26512.27594.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.MalwareX-gen.26512.27594.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.MalwareX-gen.26512.27594.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.MalwareX-gen.26512.27594.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.MalwareX-gen.26512.27594.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.MalwareX-gen.26512.27594.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.MalwareX-gen.26512.27594.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.MalwareX-gen.26512.27594.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.MalwareX-gen.26512.27594.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.MalwareX-gen.26512.27594.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.MalwareX-gen.26512.27594.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.MalwareX-gen.26512.27594.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.MalwareX-gen.26512.27594.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.MalwareX-gen.26512.27594.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.MalwareX-gen.26512.27594.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.MalwareX-gen.26512.27594.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.MalwareX-gen.26512.27594.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.MalwareX-gen.26512.27594.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.MalwareX-gen.26512.27594.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.MalwareX-gen.26512.27594.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.MalwareX-gen.26512.27594.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.MalwareX-gen.26512.27594.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.MalwareX-gen.26512.27594.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.MalwareX-gen.26512.27594.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.MalwareX-gen.26512.27594.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.MalwareX-gen.26512.27594.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.MalwareX-gen.26512.27594.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.MalwareX-gen.26512.27594.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.MalwareX-gen.26512.27594.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.MalwareX-gen.26512.27594.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.MalwareX-gen.26512.27594.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.MalwareX-gen.26512.27594.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.MalwareX-gen.26512.27594.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.MalwareX-gen.26512.27594.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.MalwareX-gen.26512.27594.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.MalwareX-gen.26512.27594.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.MalwareX-gen.26512.27594.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.MalwareX-gen.26512.27594.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.MalwareX-gen.26512.27594.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.MalwareX-gen.26512.27594.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.MalwareX-gen.26512.27594.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.MalwareX-gen.26512.27594.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.MalwareX-gen.26512.27594.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.MalwareX-gen.26512.27594.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.MalwareX-gen.26512.27594.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe Process information set: NOOPENFILEERRORBOX Jump to behavior

Malware Analysis System Evasion

barindex
Source: Yara match File source: Process Memory Space: SecuriteInfo.com.Win32.MalwareX-gen.26512.27594.exe PID: 7460, type: MEMORYSTR
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.MalwareX-gen.26512.27594.exe RDTSC instruction interceptor: First address: 409904 second address: 40990A instructions: 0x00000000 rdtsc 0x00000002 xor ecx, ecx 0x00000004 add ecx, eax 0x00000006 rdtsc
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.MalwareX-gen.26512.27594.exe RDTSC instruction interceptor: First address: 409B6E second address: 409B74 instructions: 0x00000000 rdtsc 0x00000002 xor ecx, ecx 0x00000004 add ecx, eax 0x00000006 rdtsc
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.MalwareX-gen.26512.27594.exe Memory allocated: B00000 memory reserve | memory write watch Jump to behavior
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.MalwareX-gen.26512.27594.exe Memory allocated: 24A0000 memory reserve | memory write watch Jump to behavior
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.MalwareX-gen.26512.27594.exe Memory allocated: 44A0000 memory reserve | memory write watch Jump to behavior
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.MalwareX-gen.26512.27594.exe Memory allocated: 8560000 memory reserve | memory write watch Jump to behavior
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.MalwareX-gen.26512.27594.exe Memory allocated: 9560000 memory reserve | memory write watch Jump to behavior
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.MalwareX-gen.26512.27594.exe Memory allocated: 9760000 memory reserve | memory write watch Jump to behavior
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.MalwareX-gen.26512.27594.exe Memory allocated: A760000 memory reserve | memory write watch Jump to behavior
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.MalwareX-gen.26512.27594.exe Code function: 7_2_00409AA0 rdtsc 7_2_00409AA0
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.MalwareX-gen.26512.27594.exe Thread delayed: delay time: 922337203685477 Jump to behavior
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe Thread delayed: delay time: 922337203685477 Jump to behavior
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe Window / User API: threadDelayed 6410 Jump to behavior
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe Window / User API: threadDelayed 3266 Jump to behavior
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.MalwareX-gen.26512.27594.exe API coverage: 0.6 %
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.MalwareX-gen.26512.27594.exe TID: 7496 Thread sleep time: -922337203685477s >= -30000s Jump to behavior
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe TID: 7844 Thread sleep time: -3689348814741908s >= -30000s Jump to behavior
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.MalwareX-gen.26512.27594.exe Thread delayed: delay time: 922337203685477 Jump to behavior
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe Thread delayed: delay time: 922337203685477 Jump to behavior
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.MalwareX-gen.26512.27594.exe Process information queried: ProcessInformation Jump to behavior
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.MalwareX-gen.26512.27594.exe Process queried: DebugPort Jump to behavior
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.MalwareX-gen.26512.27594.exe Code function: 7_2_00409AA0 rdtsc 7_2_00409AA0
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.MalwareX-gen.26512.27594.exe Code function: 7_2_01142BF0 NtAllocateVirtualMemory,LdrInitializeThunk, 7_2_01142BF0
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.MalwareX-gen.26512.27594.exe Code function: 7_2_011AA118 mov ecx, dword ptr fs:[00000030h] 7_2_011AA118
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.MalwareX-gen.26512.27594.exe Code function: 7_2_011AA118 mov eax, dword ptr fs:[00000030h] 7_2_011AA118
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.MalwareX-gen.26512.27594.exe Code function: 7_2_011AA118 mov eax, dword ptr fs:[00000030h] 7_2_011AA118
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.MalwareX-gen.26512.27594.exe Code function: 7_2_011AA118 mov eax, dword ptr fs:[00000030h] 7_2_011AA118
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.MalwareX-gen.26512.27594.exe Code function: 7_2_011C0115 mov eax, dword ptr fs:[00000030h] 7_2_011C0115
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.MalwareX-gen.26512.27594.exe Code function: 7_2_011AE10E mov eax, dword ptr fs:[00000030h] 7_2_011AE10E
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.MalwareX-gen.26512.27594.exe Code function: 7_2_011AE10E mov ecx, dword ptr fs:[00000030h] 7_2_011AE10E
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.MalwareX-gen.26512.27594.exe Code function: 7_2_011AE10E mov eax, dword ptr fs:[00000030h] 7_2_011AE10E
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.MalwareX-gen.26512.27594.exe Code function: 7_2_011AE10E mov eax, dword ptr fs:[00000030h] 7_2_011AE10E
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.MalwareX-gen.26512.27594.exe Code function: 7_2_011AE10E mov ecx, dword ptr fs:[00000030h] 7_2_011AE10E
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.MalwareX-gen.26512.27594.exe Code function: 7_2_011AE10E mov eax, dword ptr fs:[00000030h] 7_2_011AE10E
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.MalwareX-gen.26512.27594.exe Code function: 7_2_011AE10E mov eax, dword ptr fs:[00000030h] 7_2_011AE10E
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.MalwareX-gen.26512.27594.exe Code function: 7_2_011AE10E mov ecx, dword ptr fs:[00000030h] 7_2_011AE10E
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.MalwareX-gen.26512.27594.exe Code function: 7_2_011AE10E mov eax, dword ptr fs:[00000030h] 7_2_011AE10E
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.MalwareX-gen.26512.27594.exe Code function: 7_2_011AE10E mov ecx, dword ptr fs:[00000030h] 7_2_011AE10E
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.MalwareX-gen.26512.27594.exe Code function: 7_2_01130124 mov eax, dword ptr fs:[00000030h] 7_2_01130124
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.MalwareX-gen.26512.27594.exe Code function: 7_2_01198158 mov eax, dword ptr fs:[00000030h] 7_2_01198158
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.MalwareX-gen.26512.27594.exe Code function: 7_2_01106154 mov eax, dword ptr fs:[00000030h] 7_2_01106154
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.MalwareX-gen.26512.27594.exe Code function: 7_2_01106154 mov eax, dword ptr fs:[00000030h] 7_2_01106154
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.MalwareX-gen.26512.27594.exe Code function: 7_2_010FC156 mov eax, dword ptr fs:[00000030h] 7_2_010FC156
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.MalwareX-gen.26512.27594.exe Code function: 7_2_01194144 mov eax, dword ptr fs:[00000030h] 7_2_01194144
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.MalwareX-gen.26512.27594.exe Code function: 7_2_01194144 mov eax, dword ptr fs:[00000030h] 7_2_01194144
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.MalwareX-gen.26512.27594.exe Code function: 7_2_01194144 mov ecx, dword ptr fs:[00000030h] 7_2_01194144
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.MalwareX-gen.26512.27594.exe Code function: 7_2_01194144 mov eax, dword ptr fs:[00000030h] 7_2_01194144
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.MalwareX-gen.26512.27594.exe Code function: 7_2_01194144 mov eax, dword ptr fs:[00000030h] 7_2_01194144
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.MalwareX-gen.26512.27594.exe Code function: 7_2_0118019F mov eax, dword ptr fs:[00000030h] 7_2_0118019F
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.MalwareX-gen.26512.27594.exe Code function: 7_2_0118019F mov eax, dword ptr fs:[00000030h] 7_2_0118019F
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.MalwareX-gen.26512.27594.exe Code function: 7_2_0118019F mov eax, dword ptr fs:[00000030h] 7_2_0118019F
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.MalwareX-gen.26512.27594.exe Code function: 7_2_0118019F mov eax, dword ptr fs:[00000030h] 7_2_0118019F
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.MalwareX-gen.26512.27594.exe Code function: 7_2_01140185 mov eax, dword ptr fs:[00000030h] 7_2_01140185
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.MalwareX-gen.26512.27594.exe Code function: 7_2_011BC188 mov eax, dword ptr fs:[00000030h] 7_2_011BC188
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.MalwareX-gen.26512.27594.exe Code function: 7_2_011BC188 mov eax, dword ptr fs:[00000030h] 7_2_011BC188
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.MalwareX-gen.26512.27594.exe Code function: 7_2_010FA197 mov eax, dword ptr fs:[00000030h] 7_2_010FA197
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.MalwareX-gen.26512.27594.exe Code function: 7_2_010FA197 mov eax, dword ptr fs:[00000030h] 7_2_010FA197
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.MalwareX-gen.26512.27594.exe Code function: 7_2_010FA197 mov eax, dword ptr fs:[00000030h] 7_2_010FA197
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.MalwareX-gen.26512.27594.exe Code function: 7_2_011A4180 mov eax, dword ptr fs:[00000030h] 7_2_011A4180
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.MalwareX-gen.26512.27594.exe Code function: 7_2_011A4180 mov eax, dword ptr fs:[00000030h] 7_2_011A4180
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.MalwareX-gen.26512.27594.exe Code function: 7_2_0117E1D0 mov eax, dword ptr fs:[00000030h] 7_2_0117E1D0
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.MalwareX-gen.26512.27594.exe Code function: 7_2_0117E1D0 mov eax, dword ptr fs:[00000030h] 7_2_0117E1D0
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.MalwareX-gen.26512.27594.exe Code function: 7_2_0117E1D0 mov ecx, dword ptr fs:[00000030h] 7_2_0117E1D0
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.MalwareX-gen.26512.27594.exe Code function: 7_2_0117E1D0 mov eax, dword ptr fs:[00000030h] 7_2_0117E1D0
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.MalwareX-gen.26512.27594.exe Code function: 7_2_0117E1D0 mov eax, dword ptr fs:[00000030h] 7_2_0117E1D0
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.MalwareX-gen.26512.27594.exe Code function: 7_2_011C61C3 mov eax, dword ptr fs:[00000030h] 7_2_011C61C3
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.MalwareX-gen.26512.27594.exe Code function: 7_2_011C61C3 mov eax, dword ptr fs:[00000030h] 7_2_011C61C3
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.MalwareX-gen.26512.27594.exe Code function: 7_2_011301F8 mov eax, dword ptr fs:[00000030h] 7_2_011301F8
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.MalwareX-gen.26512.27594.exe Code function: 7_2_011D61E5 mov eax, dword ptr fs:[00000030h] 7_2_011D61E5
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.MalwareX-gen.26512.27594.exe Code function: 7_2_0111E016 mov eax, dword ptr fs:[00000030h] 7_2_0111E016
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.MalwareX-gen.26512.27594.exe Code function: 7_2_0111E016 mov eax, dword ptr fs:[00000030h] 7_2_0111E016
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.MalwareX-gen.26512.27594.exe Code function: 7_2_0111E016 mov eax, dword ptr fs:[00000030h] 7_2_0111E016
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.MalwareX-gen.26512.27594.exe Code function: 7_2_0111E016 mov eax, dword ptr fs:[00000030h] 7_2_0111E016
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.MalwareX-gen.26512.27594.exe Code function: 7_2_01184000 mov ecx, dword ptr fs:[00000030h] 7_2_01184000
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.MalwareX-gen.26512.27594.exe Code function: 7_2_011A2000 mov eax, dword ptr fs:[00000030h] 7_2_011A2000
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.MalwareX-gen.26512.27594.exe Code function: 7_2_011A2000 mov eax, dword ptr fs:[00000030h] 7_2_011A2000
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.MalwareX-gen.26512.27594.exe Code function: 7_2_011A2000 mov eax, dword ptr fs:[00000030h] 7_2_011A2000
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.MalwareX-gen.26512.27594.exe Code function: 7_2_011A2000 mov eax, dword ptr fs:[00000030h] 7_2_011A2000
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.MalwareX-gen.26512.27594.exe Code function: 7_2_011A2000 mov eax, dword ptr fs:[00000030h] 7_2_011A2000
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.MalwareX-gen.26512.27594.exe Code function: 7_2_011A2000 mov eax, dword ptr fs:[00000030h] 7_2_011A2000
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.MalwareX-gen.26512.27594.exe Code function: 7_2_011A2000 mov eax, dword ptr fs:[00000030h] 7_2_011A2000
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.MalwareX-gen.26512.27594.exe Code function: 7_2_011A2000 mov eax, dword ptr fs:[00000030h] 7_2_011A2000
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.MalwareX-gen.26512.27594.exe Code function: 7_2_01196030 mov eax, dword ptr fs:[00000030h] 7_2_01196030
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.MalwareX-gen.26512.27594.exe Code function: 7_2_010FA020 mov eax, dword ptr fs:[00000030h] 7_2_010FA020
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.MalwareX-gen.26512.27594.exe Code function: 7_2_010FC020 mov eax, dword ptr fs:[00000030h] 7_2_010FC020
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.MalwareX-gen.26512.27594.exe Code function: 7_2_01102050 mov eax, dword ptr fs:[00000030h] 7_2_01102050
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.MalwareX-gen.26512.27594.exe Code function: 7_2_01186050 mov eax, dword ptr fs:[00000030h] 7_2_01186050
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.MalwareX-gen.26512.27594.exe Code function: 7_2_0112C073 mov eax, dword ptr fs:[00000030h] 7_2_0112C073
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.MalwareX-gen.26512.27594.exe Code function: 7_2_0110208A mov eax, dword ptr fs:[00000030h] 7_2_0110208A
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.MalwareX-gen.26512.27594.exe Code function: 7_2_011C60B8 mov eax, dword ptr fs:[00000030h] 7_2_011C60B8
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.MalwareX-gen.26512.27594.exe Code function: 7_2_011C60B8 mov ecx, dword ptr fs:[00000030h] 7_2_011C60B8
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.MalwareX-gen.26512.27594.exe Code function: 7_2_011980A8 mov eax, dword ptr fs:[00000030h] 7_2_011980A8
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.MalwareX-gen.26512.27594.exe Code function: 7_2_011820DE mov eax, dword ptr fs:[00000030h] 7_2_011820DE
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.MalwareX-gen.26512.27594.exe Code function: 7_2_011420F0 mov ecx, dword ptr fs:[00000030h] 7_2_011420F0
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.MalwareX-gen.26512.27594.exe Code function: 7_2_010FA0E3 mov ecx, dword ptr fs:[00000030h] 7_2_010FA0E3
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.MalwareX-gen.26512.27594.exe Code function: 7_2_011860E0 mov eax, dword ptr fs:[00000030h] 7_2_011860E0
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.MalwareX-gen.26512.27594.exe Code function: 7_2_011080E9 mov eax, dword ptr fs:[00000030h] 7_2_011080E9
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.MalwareX-gen.26512.27594.exe Code function: 7_2_010FC0F0 mov eax, dword ptr fs:[00000030h] 7_2_010FC0F0
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.MalwareX-gen.26512.27594.exe Code function: 7_2_01120310 mov ecx, dword ptr fs:[00000030h] 7_2_01120310
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.MalwareX-gen.26512.27594.exe Code function: 7_2_0113A30B mov eax, dword ptr fs:[00000030h] 7_2_0113A30B
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.MalwareX-gen.26512.27594.exe Code function: 7_2_0113A30B mov eax, dword ptr fs:[00000030h] 7_2_0113A30B
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.MalwareX-gen.26512.27594.exe Code function: 7_2_0113A30B mov eax, dword ptr fs:[00000030h] 7_2_0113A30B
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.MalwareX-gen.26512.27594.exe Code function: 7_2_010FC310 mov ecx, dword ptr fs:[00000030h] 7_2_010FC310
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.MalwareX-gen.26512.27594.exe Code function: 7_2_0118035C mov eax, dword ptr fs:[00000030h] 7_2_0118035C
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.MalwareX-gen.26512.27594.exe Code function: 7_2_0118035C mov eax, dword ptr fs:[00000030h] 7_2_0118035C
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.MalwareX-gen.26512.27594.exe Code function: 7_2_0118035C mov eax, dword ptr fs:[00000030h] 7_2_0118035C
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.MalwareX-gen.26512.27594.exe Code function: 7_2_0118035C mov ecx, dword ptr fs:[00000030h] 7_2_0118035C
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.MalwareX-gen.26512.27594.exe Code function: 7_2_0118035C mov eax, dword ptr fs:[00000030h] 7_2_0118035C
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.MalwareX-gen.26512.27594.exe Code function: 7_2_0118035C mov eax, dword ptr fs:[00000030h] 7_2_0118035C
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.MalwareX-gen.26512.27594.exe Code function: 7_2_011A8350 mov ecx, dword ptr fs:[00000030h] 7_2_011A8350
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.MalwareX-gen.26512.27594.exe Code function: 7_2_011CA352 mov eax, dword ptr fs:[00000030h] 7_2_011CA352
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.MalwareX-gen.26512.27594.exe Code function: 7_2_01182349 mov eax, dword ptr fs:[00000030h] 7_2_01182349
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.MalwareX-gen.26512.27594.exe Code function: 7_2_01182349 mov eax, dword ptr fs:[00000030h] 7_2_01182349
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.MalwareX-gen.26512.27594.exe Code function: 7_2_01182349 mov eax, dword ptr fs:[00000030h] 7_2_01182349
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.MalwareX-gen.26512.27594.exe Code function: 7_2_01182349 mov eax, dword ptr fs:[00000030h] 7_2_01182349
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.MalwareX-gen.26512.27594.exe Code function: 7_2_01182349 mov eax, dword ptr fs:[00000030h] 7_2_01182349
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.MalwareX-gen.26512.27594.exe Code function: 7_2_01182349 mov eax, dword ptr fs:[00000030h] 7_2_01182349
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.MalwareX-gen.26512.27594.exe Code function: 7_2_01182349 mov eax, dword ptr fs:[00000030h] 7_2_01182349
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.MalwareX-gen.26512.27594.exe Code function: 7_2_01182349 mov eax, dword ptr fs:[00000030h] 7_2_01182349
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.MalwareX-gen.26512.27594.exe Code function: 7_2_01182349 mov eax, dword ptr fs:[00000030h] 7_2_01182349
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.MalwareX-gen.26512.27594.exe Code function: 7_2_01182349 mov eax, dword ptr fs:[00000030h] 7_2_01182349
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.MalwareX-gen.26512.27594.exe Code function: 7_2_01182349 mov eax, dword ptr fs:[00000030h] 7_2_01182349
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.MalwareX-gen.26512.27594.exe Code function: 7_2_01182349 mov eax, dword ptr fs:[00000030h] 7_2_01182349
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.MalwareX-gen.26512.27594.exe Code function: 7_2_01182349 mov eax, dword ptr fs:[00000030h] 7_2_01182349
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.MalwareX-gen.26512.27594.exe Code function: 7_2_01182349 mov eax, dword ptr fs:[00000030h] 7_2_01182349
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.MalwareX-gen.26512.27594.exe Code function: 7_2_01182349 mov eax, dword ptr fs:[00000030h] 7_2_01182349
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.MalwareX-gen.26512.27594.exe Code function: 7_2_011A437C mov eax, dword ptr fs:[00000030h] 7_2_011A437C
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.MalwareX-gen.26512.27594.exe Code function: 7_2_010FE388 mov eax, dword ptr fs:[00000030h] 7_2_010FE388
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.MalwareX-gen.26512.27594.exe Code function: 7_2_010FE388 mov eax, dword ptr fs:[00000030h] 7_2_010FE388
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.MalwareX-gen.26512.27594.exe Code function: 7_2_010FE388 mov eax, dword ptr fs:[00000030h] 7_2_010FE388
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.MalwareX-gen.26512.27594.exe Code function: 7_2_010F8397 mov eax, dword ptr fs:[00000030h] 7_2_010F8397
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.MalwareX-gen.26512.27594.exe Code function: 7_2_010F8397 mov eax, dword ptr fs:[00000030h] 7_2_010F8397
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.MalwareX-gen.26512.27594.exe Code function: 7_2_010F8397 mov eax, dword ptr fs:[00000030h] 7_2_010F8397
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.MalwareX-gen.26512.27594.exe Code function: 7_2_0112438F mov eax, dword ptr fs:[00000030h] 7_2_0112438F
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.MalwareX-gen.26512.27594.exe Code function: 7_2_0112438F mov eax, dword ptr fs:[00000030h] 7_2_0112438F
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.MalwareX-gen.26512.27594.exe Code function: 7_2_011AE3DB mov eax, dword ptr fs:[00000030h] 7_2_011AE3DB
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.MalwareX-gen.26512.27594.exe Code function: 7_2_011AE3DB mov eax, dword ptr fs:[00000030h] 7_2_011AE3DB
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.MalwareX-gen.26512.27594.exe Code function: 7_2_011AE3DB mov ecx, dword ptr fs:[00000030h] 7_2_011AE3DB
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.MalwareX-gen.26512.27594.exe Code function: 7_2_011AE3DB mov eax, dword ptr fs:[00000030h] 7_2_011AE3DB
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.MalwareX-gen.26512.27594.exe Code function: 7_2_011A43D4 mov eax, dword ptr fs:[00000030h] 7_2_011A43D4
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.MalwareX-gen.26512.27594.exe Code function: 7_2_011A43D4 mov eax, dword ptr fs:[00000030h] 7_2_011A43D4
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.MalwareX-gen.26512.27594.exe Code function: 7_2_0110A3C0 mov eax, dword ptr fs:[00000030h] 7_2_0110A3C0
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.MalwareX-gen.26512.27594.exe Code function: 7_2_0110A3C0 mov eax, dword ptr fs:[00000030h] 7_2_0110A3C0
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.MalwareX-gen.26512.27594.exe Code function: 7_2_0110A3C0 mov eax, dword ptr fs:[00000030h] 7_2_0110A3C0
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.MalwareX-gen.26512.27594.exe Code function: 7_2_0110A3C0 mov eax, dword ptr fs:[00000030h] 7_2_0110A3C0
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.MalwareX-gen.26512.27594.exe Code function: 7_2_0110A3C0 mov eax, dword ptr fs:[00000030h] 7_2_0110A3C0
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.MalwareX-gen.26512.27594.exe Code function: 7_2_0110A3C0 mov eax, dword ptr fs:[00000030h] 7_2_0110A3C0
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.MalwareX-gen.26512.27594.exe Code function: 7_2_011083C0 mov eax, dword ptr fs:[00000030h] 7_2_011083C0
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.MalwareX-gen.26512.27594.exe Code function: 7_2_011083C0 mov eax, dword ptr fs:[00000030h] 7_2_011083C0
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.MalwareX-gen.26512.27594.exe Code function: 7_2_011083C0 mov eax, dword ptr fs:[00000030h] 7_2_011083C0
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.MalwareX-gen.26512.27594.exe Code function: 7_2_011083C0 mov eax, dword ptr fs:[00000030h] 7_2_011083C0
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.MalwareX-gen.26512.27594.exe Code function: 7_2_011BC3CD mov eax, dword ptr fs:[00000030h] 7_2_011BC3CD
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.MalwareX-gen.26512.27594.exe Code function: 7_2_011863C0 mov eax, dword ptr fs:[00000030h] 7_2_011863C0
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.MalwareX-gen.26512.27594.exe Code function: 7_2_0111E3F0 mov eax, dword ptr fs:[00000030h] 7_2_0111E3F0
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.MalwareX-gen.26512.27594.exe Code function: 7_2_0111E3F0 mov eax, dword ptr fs:[00000030h] 7_2_0111E3F0
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.MalwareX-gen.26512.27594.exe Code function: 7_2_0111E3F0 mov eax, dword ptr fs:[00000030h] 7_2_0111E3F0
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.MalwareX-gen.26512.27594.exe Code function: 7_2_011363FF mov eax, dword ptr fs:[00000030h] 7_2_011363FF
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.MalwareX-gen.26512.27594.exe Code function: 7_2_011103E9 mov eax, dword ptr fs:[00000030h] 7_2_011103E9
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.MalwareX-gen.26512.27594.exe Code function: 7_2_011103E9 mov eax, dword ptr fs:[00000030h] 7_2_011103E9
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.MalwareX-gen.26512.27594.exe Code function: 7_2_011103E9 mov eax, dword ptr fs:[00000030h] 7_2_011103E9
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.MalwareX-gen.26512.27594.exe Code function: 7_2_011103E9 mov eax, dword ptr fs:[00000030h] 7_2_011103E9
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.MalwareX-gen.26512.27594.exe Code function: 7_2_011103E9 mov eax, dword ptr fs:[00000030h] 7_2_011103E9
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.MalwareX-gen.26512.27594.exe Code function: 7_2_011103E9 mov eax, dword ptr fs:[00000030h] 7_2_011103E9
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.MalwareX-gen.26512.27594.exe Code function: 7_2_011103E9 mov eax, dword ptr fs:[00000030h] 7_2_011103E9
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.MalwareX-gen.26512.27594.exe Code function: 7_2_011103E9 mov eax, dword ptr fs:[00000030h] 7_2_011103E9
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.MalwareX-gen.26512.27594.exe Code function: 7_2_010F823B mov eax, dword ptr fs:[00000030h] 7_2_010F823B
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.MalwareX-gen.26512.27594.exe Code function: 7_2_01106259 mov eax, dword ptr fs:[00000030h] 7_2_01106259
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.MalwareX-gen.26512.27594.exe Code function: 7_2_011BA250 mov eax, dword ptr fs:[00000030h] 7_2_011BA250
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.MalwareX-gen.26512.27594.exe Code function: 7_2_011BA250 mov eax, dword ptr fs:[00000030h] 7_2_011BA250
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.MalwareX-gen.26512.27594.exe Code function: 7_2_01188243 mov eax, dword ptr fs:[00000030h] 7_2_01188243
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.MalwareX-gen.26512.27594.exe Code function: 7_2_01188243 mov ecx, dword ptr fs:[00000030h] 7_2_01188243
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.MalwareX-gen.26512.27594.exe Code function: 7_2_010FA250 mov eax, dword ptr fs:[00000030h] 7_2_010FA250
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.MalwareX-gen.26512.27594.exe Code function: 7_2_010F826B mov eax, dword ptr fs:[00000030h] 7_2_010F826B
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.MalwareX-gen.26512.27594.exe Code function: 7_2_011B0274 mov eax, dword ptr fs:[00000030h] 7_2_011B0274
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.MalwareX-gen.26512.27594.exe Code function: 7_2_011B0274 mov eax, dword ptr fs:[00000030h] 7_2_011B0274
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.MalwareX-gen.26512.27594.exe Code function: 7_2_011B0274 mov eax, dword ptr fs:[00000030h] 7_2_011B0274
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.MalwareX-gen.26512.27594.exe Code function: 7_2_011B0274 mov eax, dword ptr fs:[00000030h] 7_2_011B0274
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.MalwareX-gen.26512.27594.exe Code function: 7_2_011B0274 mov eax, dword ptr fs:[00000030h] 7_2_011B0274
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.MalwareX-gen.26512.27594.exe Code function: 7_2_011B0274 mov eax, dword ptr fs:[00000030h] 7_2_011B0274
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.MalwareX-gen.26512.27594.exe Code function: 7_2_011B0274 mov eax, dword ptr fs:[00000030h] 7_2_011B0274
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.MalwareX-gen.26512.27594.exe Code function: 7_2_011B0274 mov eax, dword ptr fs:[00000030h] 7_2_011B0274
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.MalwareX-gen.26512.27594.exe Code function: 7_2_011B0274 mov eax, dword ptr fs:[00000030h] 7_2_011B0274
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.MalwareX-gen.26512.27594.exe Code function: 7_2_011B0274 mov eax, dword ptr fs:[00000030h] 7_2_011B0274
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.MalwareX-gen.26512.27594.exe Code function: 7_2_011B0274 mov eax, dword ptr fs:[00000030h] 7_2_011B0274
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.MalwareX-gen.26512.27594.exe Code function: 7_2_011B0274 mov eax, dword ptr fs:[00000030h] 7_2_011B0274
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.MalwareX-gen.26512.27594.exe Code function: 7_2_01104260 mov eax, dword ptr fs:[00000030h] 7_2_01104260
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.MalwareX-gen.26512.27594.exe Code function: 7_2_01104260 mov eax, dword ptr fs:[00000030h] 7_2_01104260
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.MalwareX-gen.26512.27594.exe Code function: 7_2_01104260 mov eax, dword ptr fs:[00000030h] 7_2_01104260
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.MalwareX-gen.26512.27594.exe Code function: 7_2_0113E284 mov eax, dword ptr fs:[00000030h] 7_2_0113E284
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.MalwareX-gen.26512.27594.exe Code function: 7_2_0113E284 mov eax, dword ptr fs:[00000030h] 7_2_0113E284
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.MalwareX-gen.26512.27594.exe Code function: 7_2_01180283 mov eax, dword ptr fs:[00000030h] 7_2_01180283
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.MalwareX-gen.26512.27594.exe Code function: 7_2_01180283 mov eax, dword ptr fs:[00000030h] 7_2_01180283
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.MalwareX-gen.26512.27594.exe Code function: 7_2_01180283 mov eax, dword ptr fs:[00000030h] 7_2_01180283
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.MalwareX-gen.26512.27594.exe Code function: 7_2_011102A0 mov eax, dword ptr fs:[00000030h] 7_2_011102A0
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.MalwareX-gen.26512.27594.exe Code function: 7_2_011102A0 mov eax, dword ptr fs:[00000030h] 7_2_011102A0
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.MalwareX-gen.26512.27594.exe Code function: 7_2_011962A0 mov eax, dword ptr fs:[00000030h] 7_2_011962A0
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.MalwareX-gen.26512.27594.exe Code function: 7_2_011962A0 mov ecx, dword ptr fs:[00000030h] 7_2_011962A0
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.MalwareX-gen.26512.27594.exe Code function: 7_2_011962A0 mov eax, dword ptr fs:[00000030h] 7_2_011962A0
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.MalwareX-gen.26512.27594.exe Code function: 7_2_011962A0 mov eax, dword ptr fs:[00000030h] 7_2_011962A0
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.MalwareX-gen.26512.27594.exe Code function: 7_2_011962A0 mov eax, dword ptr fs:[00000030h] 7_2_011962A0
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.MalwareX-gen.26512.27594.exe Code function: 7_2_011962A0 mov eax, dword ptr fs:[00000030h] 7_2_011962A0
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.MalwareX-gen.26512.27594.exe Code function: 7_2_0110A2C3 mov eax, dword ptr fs:[00000030h] 7_2_0110A2C3
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.MalwareX-gen.26512.27594.exe Code function: 7_2_0110A2C3 mov eax, dword ptr fs:[00000030h] 7_2_0110A2C3
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.MalwareX-gen.26512.27594.exe Code function: 7_2_0110A2C3 mov eax, dword ptr fs:[00000030h] 7_2_0110A2C3
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.MalwareX-gen.26512.27594.exe Code function: 7_2_0110A2C3 mov eax, dword ptr fs:[00000030h] 7_2_0110A2C3
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.MalwareX-gen.26512.27594.exe Code function: 7_2_0110A2C3 mov eax, dword ptr fs:[00000030h] 7_2_0110A2C3
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.MalwareX-gen.26512.27594.exe Code function: 7_2_011102E1 mov eax, dword ptr fs:[00000030h] 7_2_011102E1
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.MalwareX-gen.26512.27594.exe Code function: 7_2_011102E1 mov eax, dword ptr fs:[00000030h] 7_2_011102E1
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.MalwareX-gen.26512.27594.exe Code function: 7_2_011102E1 mov eax, dword ptr fs:[00000030h] 7_2_011102E1
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.MalwareX-gen.26512.27594.exe Code function: 7_2_01196500 mov eax, dword ptr fs:[00000030h] 7_2_01196500
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.MalwareX-gen.26512.27594.exe Code function: 7_2_011D4500 mov eax, dword ptr fs:[00000030h] 7_2_011D4500
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.MalwareX-gen.26512.27594.exe Code function: 7_2_011D4500 mov eax, dword ptr fs:[00000030h] 7_2_011D4500
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.MalwareX-gen.26512.27594.exe Code function: 7_2_011D4500 mov eax, dword ptr fs:[00000030h] 7_2_011D4500
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.MalwareX-gen.26512.27594.exe Code function: 7_2_011D4500 mov eax, dword ptr fs:[00000030h] 7_2_011D4500
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.MalwareX-gen.26512.27594.exe Code function: 7_2_011D4500 mov eax, dword ptr fs:[00000030h] 7_2_011D4500
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.MalwareX-gen.26512.27594.exe Code function: 7_2_011D4500 mov eax, dword ptr fs:[00000030h] 7_2_011D4500
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.MalwareX-gen.26512.27594.exe Code function: 7_2_011D4500 mov eax, dword ptr fs:[00000030h] 7_2_011D4500
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.MalwareX-gen.26512.27594.exe Code function: 7_2_01110535 mov eax, dword ptr fs:[00000030h] 7_2_01110535
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.MalwareX-gen.26512.27594.exe Code function: 7_2_01110535 mov eax, dword ptr fs:[00000030h] 7_2_01110535
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.MalwareX-gen.26512.27594.exe Code function: 7_2_01110535 mov eax, dword ptr fs:[00000030h] 7_2_01110535
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.MalwareX-gen.26512.27594.exe Code function: 7_2_01110535 mov eax, dword ptr fs:[00000030h] 7_2_01110535
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.MalwareX-gen.26512.27594.exe Code function: 7_2_01110535 mov eax, dword ptr fs:[00000030h] 7_2_01110535
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.MalwareX-gen.26512.27594.exe Code function: 7_2_01110535 mov eax, dword ptr fs:[00000030h] 7_2_01110535
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.MalwareX-gen.26512.27594.exe Code function: 7_2_0112E53E mov eax, dword ptr fs:[00000030h] 7_2_0112E53E
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.MalwareX-gen.26512.27594.exe Code function: 7_2_0112E53E mov eax, dword ptr fs:[00000030h] 7_2_0112E53E
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.MalwareX-gen.26512.27594.exe Code function: 7_2_0112E53E mov eax, dword ptr fs:[00000030h] 7_2_0112E53E
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.MalwareX-gen.26512.27594.exe Code function: 7_2_0112E53E mov eax, dword ptr fs:[00000030h] 7_2_0112E53E
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.MalwareX-gen.26512.27594.exe Code function: 7_2_0112E53E mov eax, dword ptr fs:[00000030h] 7_2_0112E53E
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.MalwareX-gen.26512.27594.exe Code function: 7_2_01108550 mov eax, dword ptr fs:[00000030h] 7_2_01108550
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.MalwareX-gen.26512.27594.exe Code function: 7_2_01108550 mov eax, dword ptr fs:[00000030h] 7_2_01108550
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.MalwareX-gen.26512.27594.exe Code function: 7_2_0113656A mov eax, dword ptr fs:[00000030h] 7_2_0113656A
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.MalwareX-gen.26512.27594.exe Code function: 7_2_0113656A mov eax, dword ptr fs:[00000030h] 7_2_0113656A
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.MalwareX-gen.26512.27594.exe Code function: 7_2_0113656A mov eax, dword ptr fs:[00000030h] 7_2_0113656A
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.MalwareX-gen.26512.27594.exe Code function: 7_2_0113E59C mov eax, dword ptr fs:[00000030h] 7_2_0113E59C
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.MalwareX-gen.26512.27594.exe Code function: 7_2_01102582 mov eax, dword ptr fs:[00000030h] 7_2_01102582
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.MalwareX-gen.26512.27594.exe Code function: 7_2_01102582 mov ecx, dword ptr fs:[00000030h] 7_2_01102582
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.MalwareX-gen.26512.27594.exe Code function: 7_2_01134588 mov eax, dword ptr fs:[00000030h] 7_2_01134588
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.MalwareX-gen.26512.27594.exe Code function: 7_2_011245B1 mov eax, dword ptr fs:[00000030h] 7_2_011245B1
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.MalwareX-gen.26512.27594.exe Code function: 7_2_011245B1 mov eax, dword ptr fs:[00000030h] 7_2_011245B1
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.MalwareX-gen.26512.27594.exe Code function: 7_2_011805A7 mov eax, dword ptr fs:[00000030h] 7_2_011805A7
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.MalwareX-gen.26512.27594.exe Code function: 7_2_011805A7 mov eax, dword ptr fs:[00000030h] 7_2_011805A7
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.MalwareX-gen.26512.27594.exe Code function: 7_2_011805A7 mov eax, dword ptr fs:[00000030h] 7_2_011805A7
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.MalwareX-gen.26512.27594.exe Code function: 7_2_011065D0 mov eax, dword ptr fs:[00000030h] 7_2_011065D0
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.MalwareX-gen.26512.27594.exe Code function: 7_2_0113A5D0 mov eax, dword ptr fs:[00000030h] 7_2_0113A5D0
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.MalwareX-gen.26512.27594.exe Code function: 7_2_0113A5D0 mov eax, dword ptr fs:[00000030h] 7_2_0113A5D0
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.MalwareX-gen.26512.27594.exe Code function: 7_2_0113E5CF mov eax, dword ptr fs:[00000030h] 7_2_0113E5CF
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.MalwareX-gen.26512.27594.exe Code function: 7_2_0113E5CF mov eax, dword ptr fs:[00000030h] 7_2_0113E5CF
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.MalwareX-gen.26512.27594.exe Code function: 7_2_011025E0 mov eax, dword ptr fs:[00000030h] 7_2_011025E0
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.MalwareX-gen.26512.27594.exe Code function: 7_2_0112E5E7 mov eax, dword ptr fs:[00000030h] 7_2_0112E5E7
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.MalwareX-gen.26512.27594.exe Code function: 7_2_0112E5E7 mov eax, dword ptr fs:[00000030h] 7_2_0112E5E7
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.MalwareX-gen.26512.27594.exe Code function: 7_2_0112E5E7 mov eax, dword ptr fs:[00000030h] 7_2_0112E5E7
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.MalwareX-gen.26512.27594.exe Code function: 7_2_0112E5E7 mov eax, dword ptr fs:[00000030h] 7_2_0112E5E7
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.MalwareX-gen.26512.27594.exe Code function: 7_2_0112E5E7 mov eax, dword ptr fs:[00000030h] 7_2_0112E5E7
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.MalwareX-gen.26512.27594.exe Code function: 7_2_0112E5E7 mov eax, dword ptr fs:[00000030h] 7_2_0112E5E7
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.MalwareX-gen.26512.27594.exe Code function: 7_2_0112E5E7 mov eax, dword ptr fs:[00000030h] 7_2_0112E5E7
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.MalwareX-gen.26512.27594.exe Code function: 7_2_0112E5E7 mov eax, dword ptr fs:[00000030h] 7_2_0112E5E7
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.MalwareX-gen.26512.27594.exe Code function: 7_2_0113C5ED mov eax, dword ptr fs:[00000030h] 7_2_0113C5ED
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.MalwareX-gen.26512.27594.exe Code function: 7_2_0113C5ED mov eax, dword ptr fs:[00000030h] 7_2_0113C5ED
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.MalwareX-gen.26512.27594.exe Code function: 7_2_01138402 mov eax, dword ptr fs:[00000030h] 7_2_01138402
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.MalwareX-gen.26512.27594.exe Code function: 7_2_01138402 mov eax, dword ptr fs:[00000030h] 7_2_01138402
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.MalwareX-gen.26512.27594.exe Code function: 7_2_01138402 mov eax, dword ptr fs:[00000030h] 7_2_01138402
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.MalwareX-gen.26512.27594.exe Code function: 7_2_0113A430 mov eax, dword ptr fs:[00000030h] 7_2_0113A430
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.MalwareX-gen.26512.27594.exe Code function: 7_2_010FC427 mov eax, dword ptr fs:[00000030h] 7_2_010FC427
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.MalwareX-gen.26512.27594.exe Code function: 7_2_010FE420 mov eax, dword ptr fs:[00000030h] 7_2_010FE420
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.MalwareX-gen.26512.27594.exe Code function: 7_2_010FE420 mov eax, dword ptr fs:[00000030h] 7_2_010FE420
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.MalwareX-gen.26512.27594.exe Code function: 7_2_010FE420 mov eax, dword ptr fs:[00000030h] 7_2_010FE420
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.MalwareX-gen.26512.27594.exe Code function: 7_2_01186420 mov eax, dword ptr fs:[00000030h] 7_2_01186420
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.MalwareX-gen.26512.27594.exe Code function: 7_2_01186420 mov eax, dword ptr fs:[00000030h] 7_2_01186420
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.MalwareX-gen.26512.27594.exe Code function: 7_2_01186420 mov eax, dword ptr fs:[00000030h] 7_2_01186420
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.MalwareX-gen.26512.27594.exe Code function: 7_2_01186420 mov eax, dword ptr fs:[00000030h] 7_2_01186420
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.MalwareX-gen.26512.27594.exe Code function: 7_2_01186420 mov eax, dword ptr fs:[00000030h] 7_2_01186420
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.MalwareX-gen.26512.27594.exe Code function: 7_2_01186420 mov eax, dword ptr fs:[00000030h] 7_2_01186420
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.MalwareX-gen.26512.27594.exe Code function: 7_2_01186420 mov eax, dword ptr fs:[00000030h] 7_2_01186420
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.MalwareX-gen.26512.27594.exe Code function: 7_2_0112245A mov eax, dword ptr fs:[00000030h] 7_2_0112245A
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.MalwareX-gen.26512.27594.exe Code function: 7_2_011BA456 mov eax, dword ptr fs:[00000030h] 7_2_011BA456
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.MalwareX-gen.26512.27594.exe Code function: 7_2_0113E443 mov eax, dword ptr fs:[00000030h] 7_2_0113E443
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.MalwareX-gen.26512.27594.exe Code function: 7_2_0113E443 mov eax, dword ptr fs:[00000030h] 7_2_0113E443
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.MalwareX-gen.26512.27594.exe Code function: 7_2_0113E443 mov eax, dword ptr fs:[00000030h] 7_2_0113E443
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.MalwareX-gen.26512.27594.exe Code function: 7_2_0113E443 mov eax, dword ptr fs:[00000030h] 7_2_0113E443
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.MalwareX-gen.26512.27594.exe Code function: 7_2_0113E443 mov eax, dword ptr fs:[00000030h] 7_2_0113E443
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.MalwareX-gen.26512.27594.exe Code function: 7_2_0113E443 mov eax, dword ptr fs:[00000030h] 7_2_0113E443
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.MalwareX-gen.26512.27594.exe Code function: 7_2_0113E443 mov eax, dword ptr fs:[00000030h] 7_2_0113E443
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.MalwareX-gen.26512.27594.exe Code function: 7_2_0113E443 mov eax, dword ptr fs:[00000030h] 7_2_0113E443
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.MalwareX-gen.26512.27594.exe Code function: 7_2_010F645D mov eax, dword ptr fs:[00000030h] 7_2_010F645D
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.MalwareX-gen.26512.27594.exe Code function: 7_2_0112A470 mov eax, dword ptr fs:[00000030h] 7_2_0112A470
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.MalwareX-gen.26512.27594.exe Code function: 7_2_0112A470 mov eax, dword ptr fs:[00000030h] 7_2_0112A470
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.MalwareX-gen.26512.27594.exe Code function: 7_2_0112A470 mov eax, dword ptr fs:[00000030h] 7_2_0112A470
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.MalwareX-gen.26512.27594.exe Code function: 7_2_0118C460 mov ecx, dword ptr fs:[00000030h] 7_2_0118C460
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.MalwareX-gen.26512.27594.exe Code function: 7_2_011BA49A mov eax, dword ptr fs:[00000030h] 7_2_011BA49A
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.MalwareX-gen.26512.27594.exe Code function: 7_2_011344B0 mov ecx, dword ptr fs:[00000030h] 7_2_011344B0
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.MalwareX-gen.26512.27594.exe Code function: 7_2_0118A4B0 mov eax, dword ptr fs:[00000030h] 7_2_0118A4B0
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.MalwareX-gen.26512.27594.exe Code function: 7_2_011064AB mov eax, dword ptr fs:[00000030h] 7_2_011064AB
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.MalwareX-gen.26512.27594.exe Code function: 7_2_011004E5 mov ecx, dword ptr fs:[00000030h] 7_2_011004E5
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.MalwareX-gen.26512.27594.exe Code function: 7_2_01100710 mov eax, dword ptr fs:[00000030h] 7_2_01100710
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.MalwareX-gen.26512.27594.exe Code function: 7_2_01130710 mov eax, dword ptr fs:[00000030h] 7_2_01130710
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.MalwareX-gen.26512.27594.exe Code function: 7_2_0113C700 mov eax, dword ptr fs:[00000030h] 7_2_0113C700
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.MalwareX-gen.26512.27594.exe Code function: 7_2_0117C730 mov eax, dword ptr fs:[00000030h] 7_2_0117C730
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.MalwareX-gen.26512.27594.exe Code function: 7_2_0113273C mov eax, dword ptr fs:[00000030h] 7_2_0113273C
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.MalwareX-gen.26512.27594.exe Code function: 7_2_0113273C mov ecx, dword ptr fs:[00000030h] 7_2_0113273C
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.MalwareX-gen.26512.27594.exe Code function: 7_2_0113273C mov eax, dword ptr fs:[00000030h] 7_2_0113273C
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.MalwareX-gen.26512.27594.exe Code function: 7_2_0113C720 mov eax, dword ptr fs:[00000030h] 7_2_0113C720
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.MalwareX-gen.26512.27594.exe Code function: 7_2_0113C720 mov eax, dword ptr fs:[00000030h] 7_2_0113C720
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.MalwareX-gen.26512.27594.exe Code function: 7_2_01100750 mov eax, dword ptr fs:[00000030h] 7_2_01100750
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.MalwareX-gen.26512.27594.exe Code function: 7_2_01142750 mov eax, dword ptr fs:[00000030h] 7_2_01142750
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.MalwareX-gen.26512.27594.exe Code function: 7_2_01142750 mov eax, dword ptr fs:[00000030h] 7_2_01142750
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.MalwareX-gen.26512.27594.exe Code function: 7_2_0118E75D mov eax, dword ptr fs:[00000030h] 7_2_0118E75D
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.MalwareX-gen.26512.27594.exe Code function: 7_2_01184755 mov eax, dword ptr fs:[00000030h] 7_2_01184755
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.MalwareX-gen.26512.27594.exe Code function: 7_2_0113674D mov esi, dword ptr fs:[00000030h] 7_2_0113674D
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.MalwareX-gen.26512.27594.exe Code function: 7_2_0113674D mov eax, dword ptr fs:[00000030h] 7_2_0113674D
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.MalwareX-gen.26512.27594.exe Code function: 7_2_0113674D mov eax, dword ptr fs:[00000030h] 7_2_0113674D
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.MalwareX-gen.26512.27594.exe Code function: 7_2_01108770 mov eax, dword ptr fs:[00000030h] 7_2_01108770
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.MalwareX-gen.26512.27594.exe Code function: 7_2_01110770 mov eax, dword ptr fs:[00000030h] 7_2_01110770
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.MalwareX-gen.26512.27594.exe Code function: 7_2_01110770 mov eax, dword ptr fs:[00000030h] 7_2_01110770
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.MalwareX-gen.26512.27594.exe Code function: 7_2_01110770 mov eax, dword ptr fs:[00000030h] 7_2_01110770
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.MalwareX-gen.26512.27594.exe Code function: 7_2_01110770 mov eax, dword ptr fs:[00000030h] 7_2_01110770
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.MalwareX-gen.26512.27594.exe Code function: 7_2_01110770 mov eax, dword ptr fs:[00000030h] 7_2_01110770
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.MalwareX-gen.26512.27594.exe Code function: 7_2_01110770 mov eax, dword ptr fs:[00000030h] 7_2_01110770
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.MalwareX-gen.26512.27594.exe Code function: 7_2_01110770 mov eax, dword ptr fs:[00000030h] 7_2_01110770
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.MalwareX-gen.26512.27594.exe Code function: 7_2_01110770 mov eax, dword ptr fs:[00000030h] 7_2_01110770
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.MalwareX-gen.26512.27594.exe Code function: 7_2_01110770 mov eax, dword ptr fs:[00000030h] 7_2_01110770
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.MalwareX-gen.26512.27594.exe Code function: 7_2_01110770 mov eax, dword ptr fs:[00000030h] 7_2_01110770
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.MalwareX-gen.26512.27594.exe Code function: 7_2_01110770 mov eax, dword ptr fs:[00000030h] 7_2_01110770
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.MalwareX-gen.26512.27594.exe Code function: 7_2_01110770 mov eax, dword ptr fs:[00000030h] 7_2_01110770
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.MalwareX-gen.26512.27594.exe Code function: 7_2_011A678E mov eax, dword ptr fs:[00000030h] 7_2_011A678E
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.MalwareX-gen.26512.27594.exe Code function: 7_2_011B47A0 mov eax, dword ptr fs:[00000030h] 7_2_011B47A0
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.MalwareX-gen.26512.27594.exe Code function: 7_2_011007AF mov eax, dword ptr fs:[00000030h] 7_2_011007AF
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.MalwareX-gen.26512.27594.exe Code function: 7_2_0110C7C0 mov eax, dword ptr fs:[00000030h] 7_2_0110C7C0
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.MalwareX-gen.26512.27594.exe Code function: 7_2_011807C3 mov eax, dword ptr fs:[00000030h] 7_2_011807C3
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.MalwareX-gen.26512.27594.exe Code function: 7_2_011047FB mov eax, dword ptr fs:[00000030h] 7_2_011047FB
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.MalwareX-gen.26512.27594.exe Code function: 7_2_011047FB mov eax, dword ptr fs:[00000030h] 7_2_011047FB
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.MalwareX-gen.26512.27594.exe Code function: 7_2_0118E7E1 mov eax, dword ptr fs:[00000030h] 7_2_0118E7E1
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.MalwareX-gen.26512.27594.exe Code function: 7_2_011227ED mov eax, dword ptr fs:[00000030h] 7_2_011227ED
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.MalwareX-gen.26512.27594.exe Code function: 7_2_011227ED mov eax, dword ptr fs:[00000030h] 7_2_011227ED
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.MalwareX-gen.26512.27594.exe Code function: 7_2_011227ED mov eax, dword ptr fs:[00000030h] 7_2_011227ED
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.MalwareX-gen.26512.27594.exe Code function: 7_2_01142619 mov eax, dword ptr fs:[00000030h] 7_2_01142619
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.MalwareX-gen.26512.27594.exe Code function: 7_2_0111260B mov eax, dword ptr fs:[00000030h] 7_2_0111260B
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.MalwareX-gen.26512.27594.exe Code function: 7_2_0111260B mov eax, dword ptr fs:[00000030h] 7_2_0111260B
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.MalwareX-gen.26512.27594.exe Code function: 7_2_0111260B mov eax, dword ptr fs:[00000030h] 7_2_0111260B
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.MalwareX-gen.26512.27594.exe Code function: 7_2_0111260B mov eax, dword ptr fs:[00000030h] 7_2_0111260B
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.MalwareX-gen.26512.27594.exe Code function: 7_2_0111260B mov eax, dword ptr fs:[00000030h] 7_2_0111260B
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.MalwareX-gen.26512.27594.exe Code function: 7_2_0111260B mov eax, dword ptr fs:[00000030h] 7_2_0111260B
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.MalwareX-gen.26512.27594.exe Code function: 7_2_0111260B mov eax, dword ptr fs:[00000030h] 7_2_0111260B
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.MalwareX-gen.26512.27594.exe Code function: 7_2_0117E609 mov eax, dword ptr fs:[00000030h] 7_2_0117E609
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.MalwareX-gen.26512.27594.exe Code function: 7_2_01136620 mov eax, dword ptr fs:[00000030h] 7_2_01136620
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.MalwareX-gen.26512.27594.exe Code function: 7_2_01138620 mov eax, dword ptr fs:[00000030h] 7_2_01138620
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.MalwareX-gen.26512.27594.exe Code function: 7_2_0111E627 mov eax, dword ptr fs:[00000030h] 7_2_0111E627
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.MalwareX-gen.26512.27594.exe Code function: 7_2_0110262C mov eax, dword ptr fs:[00000030h] 7_2_0110262C
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.MalwareX-gen.26512.27594.exe Code function: 7_2_0111C640 mov eax, dword ptr fs:[00000030h] 7_2_0111C640
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.MalwareX-gen.26512.27594.exe Code function: 7_2_01132674 mov eax, dword ptr fs:[00000030h] 7_2_01132674
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.MalwareX-gen.26512.27594.exe Code function: 7_2_011C866E mov eax, dword ptr fs:[00000030h] 7_2_011C866E
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.MalwareX-gen.26512.27594.exe Code function: 7_2_011C866E mov eax, dword ptr fs:[00000030h] 7_2_011C866E
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.MalwareX-gen.26512.27594.exe Code function: 7_2_0113A660 mov eax, dword ptr fs:[00000030h] 7_2_0113A660
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.MalwareX-gen.26512.27594.exe Code function: 7_2_0113A660 mov eax, dword ptr fs:[00000030h] 7_2_0113A660
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.MalwareX-gen.26512.27594.exe Code function: 7_2_01104690 mov eax, dword ptr fs:[00000030h] 7_2_01104690
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.MalwareX-gen.26512.27594.exe Code function: 7_2_01104690 mov eax, dword ptr fs:[00000030h] 7_2_01104690
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.MalwareX-gen.26512.27594.exe Code function: 7_2_011366B0 mov eax, dword ptr fs:[00000030h] 7_2_011366B0
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.MalwareX-gen.26512.27594.exe Code function: 7_2_0113C6A6 mov eax, dword ptr fs:[00000030h] 7_2_0113C6A6
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.MalwareX-gen.26512.27594.exe Code function: 7_2_0113A6C7 mov ebx, dword ptr fs:[00000030h] 7_2_0113A6C7
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.MalwareX-gen.26512.27594.exe Code function: 7_2_0113A6C7 mov eax, dword ptr fs:[00000030h] 7_2_0113A6C7
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.MalwareX-gen.26512.27594.exe Code function: 7_2_0117E6F2 mov eax, dword ptr fs:[00000030h] 7_2_0117E6F2
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.MalwareX-gen.26512.27594.exe Code function: 7_2_0117E6F2 mov eax, dword ptr fs:[00000030h] 7_2_0117E6F2
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.MalwareX-gen.26512.27594.exe Code function: 7_2_0117E6F2 mov eax, dword ptr fs:[00000030h] 7_2_0117E6F2
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.MalwareX-gen.26512.27594.exe Code function: 7_2_0117E6F2 mov eax, dword ptr fs:[00000030h] 7_2_0117E6F2
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.MalwareX-gen.26512.27594.exe Code function: 7_2_011806F1 mov eax, dword ptr fs:[00000030h] 7_2_011806F1
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.MalwareX-gen.26512.27594.exe Code function: 7_2_011806F1 mov eax, dword ptr fs:[00000030h] 7_2_011806F1
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.MalwareX-gen.26512.27594.exe Code function: 7_2_0118C912 mov eax, dword ptr fs:[00000030h] 7_2_0118C912
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.MalwareX-gen.26512.27594.exe Code function: 7_2_010F8918 mov eax, dword ptr fs:[00000030h] 7_2_010F8918
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.MalwareX-gen.26512.27594.exe Code function: 7_2_010F8918 mov eax, dword ptr fs:[00000030h] 7_2_010F8918
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.MalwareX-gen.26512.27594.exe Code function: 7_2_0117E908 mov eax, dword ptr fs:[00000030h] 7_2_0117E908
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.MalwareX-gen.26512.27594.exe Code function: 7_2_0117E908 mov eax, dword ptr fs:[00000030h] 7_2_0117E908
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.MalwareX-gen.26512.27594.exe Code function: 7_2_0118892A mov eax, dword ptr fs:[00000030h] 7_2_0118892A
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.MalwareX-gen.26512.27594.exe Code function: 7_2_0119892B mov eax, dword ptr fs:[00000030h] 7_2_0119892B
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.MalwareX-gen.26512.27594.exe Code function: 7_2_01180946 mov eax, dword ptr fs:[00000030h] 7_2_01180946
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.MalwareX-gen.26512.27594.exe Code function: 7_2_011A4978 mov eax, dword ptr fs:[00000030h] 7_2_011A4978
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.MalwareX-gen.26512.27594.exe Code function: 7_2_011A4978 mov eax, dword ptr fs:[00000030h] 7_2_011A4978
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.MalwareX-gen.26512.27594.exe Code function: 7_2_0118C97C mov eax, dword ptr fs:[00000030h] 7_2_0118C97C
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.MalwareX-gen.26512.27594.exe Code function: 7_2_01126962 mov eax, dword ptr fs:[00000030h] 7_2_01126962
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.MalwareX-gen.26512.27594.exe Code function: 7_2_01126962 mov eax, dword ptr fs:[00000030h] 7_2_01126962
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.MalwareX-gen.26512.27594.exe Code function: 7_2_01126962 mov eax, dword ptr fs:[00000030h] 7_2_01126962
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.MalwareX-gen.26512.27594.exe Code function: 7_2_0114096E mov eax, dword ptr fs:[00000030h] 7_2_0114096E
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.MalwareX-gen.26512.27594.exe Code function: 7_2_0114096E mov edx, dword ptr fs:[00000030h] 7_2_0114096E
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.MalwareX-gen.26512.27594.exe Code function: 7_2_0114096E mov eax, dword ptr fs:[00000030h] 7_2_0114096E
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.MalwareX-gen.26512.27594.exe Code function: 7_2_011889B3 mov esi, dword ptr fs:[00000030h] 7_2_011889B3
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.MalwareX-gen.26512.27594.exe Code function: 7_2_011889B3 mov eax, dword ptr fs:[00000030h] 7_2_011889B3
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.MalwareX-gen.26512.27594.exe Code function: 7_2_011889B3 mov eax, dword ptr fs:[00000030h] 7_2_011889B3
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.MalwareX-gen.26512.27594.exe Code function: 7_2_011129A0 mov eax, dword ptr fs:[00000030h] 7_2_011129A0
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.MalwareX-gen.26512.27594.exe Code function: 7_2_011129A0 mov eax, dword ptr fs:[00000030h] 7_2_011129A0
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.MalwareX-gen.26512.27594.exe Code function: 7_2_011129A0 mov eax, dword ptr fs:[00000030h] 7_2_011129A0
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.MalwareX-gen.26512.27594.exe Code function: 7_2_011129A0 mov eax, dword ptr fs:[00000030h] 7_2_011129A0
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.MalwareX-gen.26512.27594.exe Code function: 7_2_011129A0 mov eax, dword ptr fs:[00000030h] 7_2_011129A0
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.MalwareX-gen.26512.27594.exe Code function: 7_2_011129A0 mov eax, dword ptr fs:[00000030h] 7_2_011129A0
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.MalwareX-gen.26512.27594.exe Code function: 7_2_011129A0 mov eax, dword ptr fs:[00000030h] 7_2_011129A0
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.MalwareX-gen.26512.27594.exe Code function: 7_2_011129A0 mov eax, dword ptr fs:[00000030h] 7_2_011129A0
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.MalwareX-gen.26512.27594.exe Code function: 7_2_011129A0 mov eax, dword ptr fs:[00000030h] 7_2_011129A0
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.MalwareX-gen.26512.27594.exe Code function: 7_2_011129A0 mov eax, dword ptr fs:[00000030h] 7_2_011129A0
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.MalwareX-gen.26512.27594.exe Code function: 7_2_011129A0 mov eax, dword ptr fs:[00000030h] 7_2_011129A0
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.MalwareX-gen.26512.27594.exe Code function: 7_2_011129A0 mov eax, dword ptr fs:[00000030h] 7_2_011129A0
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.MalwareX-gen.26512.27594.exe Code function: 7_2_011129A0 mov eax, dword ptr fs:[00000030h] 7_2_011129A0
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.MalwareX-gen.26512.27594.exe Code function: 7_2_011009AD mov eax, dword ptr fs:[00000030h] 7_2_011009AD
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.MalwareX-gen.26512.27594.exe Code function: 7_2_011009AD mov eax, dword ptr fs:[00000030h] 7_2_011009AD
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.MalwareX-gen.26512.27594.exe Code function: 7_2_0110A9D0 mov eax, dword ptr fs:[00000030h] 7_2_0110A9D0
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.MalwareX-gen.26512.27594.exe Code function: 7_2_0110A9D0 mov eax, dword ptr fs:[00000030h] 7_2_0110A9D0
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.MalwareX-gen.26512.27594.exe Code function: 7_2_0110A9D0 mov eax, dword ptr fs:[00000030h] 7_2_0110A9D0
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.MalwareX-gen.26512.27594.exe Code function: 7_2_0110A9D0 mov eax, dword ptr fs:[00000030h] 7_2_0110A9D0
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.MalwareX-gen.26512.27594.exe Code function: 7_2_0110A9D0 mov eax, dword ptr fs:[00000030h] 7_2_0110A9D0
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.MalwareX-gen.26512.27594.exe Code function: 7_2_0110A9D0 mov eax, dword ptr fs:[00000030h] 7_2_0110A9D0
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.MalwareX-gen.26512.27594.exe Code function: 7_2_011349D0 mov eax, dword ptr fs:[00000030h] 7_2_011349D0
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.MalwareX-gen.26512.27594.exe Code function: 7_2_011CA9D3 mov eax, dword ptr fs:[00000030h] 7_2_011CA9D3
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.MalwareX-gen.26512.27594.exe Code function: 7_2_011969C0 mov eax, dword ptr fs:[00000030h] 7_2_011969C0
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.MalwareX-gen.26512.27594.exe Code function: 7_2_011329F9 mov eax, dword ptr fs:[00000030h] 7_2_011329F9
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.MalwareX-gen.26512.27594.exe Code function: 7_2_011329F9 mov eax, dword ptr fs:[00000030h] 7_2_011329F9
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.MalwareX-gen.26512.27594.exe Code function: 7_2_0118E9E0 mov eax, dword ptr fs:[00000030h] 7_2_0118E9E0
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.MalwareX-gen.26512.27594.exe Code function: 7_2_0118C810 mov eax, dword ptr fs:[00000030h] 7_2_0118C810
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.MalwareX-gen.26512.27594.exe Code function: 7_2_011A483A mov eax, dword ptr fs:[00000030h] 7_2_011A483A
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.MalwareX-gen.26512.27594.exe Code function: 7_2_011A483A mov eax, dword ptr fs:[00000030h] 7_2_011A483A
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.MalwareX-gen.26512.27594.exe Code function: 7_2_0113A830 mov eax, dword ptr fs:[00000030h] 7_2_0113A830
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.MalwareX-gen.26512.27594.exe Code function: 7_2_01122835 mov eax, dword ptr fs:[00000030h] 7_2_01122835
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.MalwareX-gen.26512.27594.exe Code function: 7_2_01122835 mov eax, dword ptr fs:[00000030h] 7_2_01122835
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.MalwareX-gen.26512.27594.exe Code function: 7_2_01122835 mov eax, dword ptr fs:[00000030h] 7_2_01122835
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.MalwareX-gen.26512.27594.exe Code function: 7_2_01122835 mov ecx, dword ptr fs:[00000030h] 7_2_01122835
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.MalwareX-gen.26512.27594.exe Code function: 7_2_01122835 mov eax, dword ptr fs:[00000030h] 7_2_01122835
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.MalwareX-gen.26512.27594.exe Code function: 7_2_01122835 mov eax, dword ptr fs:[00000030h] 7_2_01122835
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.MalwareX-gen.26512.27594.exe Code function: 7_2_01130854 mov eax, dword ptr fs:[00000030h] 7_2_01130854
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.MalwareX-gen.26512.27594.exe Code function: 7_2_01104859 mov eax, dword ptr fs:[00000030h] 7_2_01104859
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.MalwareX-gen.26512.27594.exe Code function: 7_2_01104859 mov eax, dword ptr fs:[00000030h] 7_2_01104859
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.MalwareX-gen.26512.27594.exe Code function: 7_2_01112840 mov ecx, dword ptr fs:[00000030h] 7_2_01112840
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.MalwareX-gen.26512.27594.exe Code function: 7_2_01196870 mov eax, dword ptr fs:[00000030h] 7_2_01196870
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.MalwareX-gen.26512.27594.exe Code function: 7_2_01196870 mov eax, dword ptr fs:[00000030h] 7_2_01196870
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.MalwareX-gen.26512.27594.exe Code function: 7_2_0118E872 mov eax, dword ptr fs:[00000030h] 7_2_0118E872
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.MalwareX-gen.26512.27594.exe Code function: 7_2_0118E872 mov eax, dword ptr fs:[00000030h] 7_2_0118E872
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.MalwareX-gen.26512.27594.exe Code function: 7_2_0118C89D mov eax, dword ptr fs:[00000030h] 7_2_0118C89D
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.MalwareX-gen.26512.27594.exe Code function: 7_2_01100887 mov eax, dword ptr fs:[00000030h] 7_2_01100887
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.MalwareX-gen.26512.27594.exe Code function: 7_2_0112E8C0 mov eax, dword ptr fs:[00000030h] 7_2_0112E8C0
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.MalwareX-gen.26512.27594.exe Code function: 7_2_0113C8F9 mov eax, dword ptr fs:[00000030h] 7_2_0113C8F9
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.MalwareX-gen.26512.27594.exe Code function: 7_2_0113C8F9 mov eax, dword ptr fs:[00000030h] 7_2_0113C8F9
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.MalwareX-gen.26512.27594.exe Code function: 7_2_011CA8E4 mov eax, dword ptr fs:[00000030h] 7_2_011CA8E4
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.MalwareX-gen.26512.27594.exe Code function: 7_2_0117EB1D mov eax, dword ptr fs:[00000030h] 7_2_0117EB1D
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.MalwareX-gen.26512.27594.exe Code function: 7_2_0117EB1D mov eax, dword ptr fs:[00000030h] 7_2_0117EB1D
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.MalwareX-gen.26512.27594.exe Code function: 7_2_0117EB1D mov eax, dword ptr fs:[00000030h] 7_2_0117EB1D
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.MalwareX-gen.26512.27594.exe Code function: 7_2_0117EB1D mov eax, dword ptr fs:[00000030h] 7_2_0117EB1D
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.MalwareX-gen.26512.27594.exe Code function: 7_2_0117EB1D mov eax, dword ptr fs:[00000030h] 7_2_0117EB1D
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.MalwareX-gen.26512.27594.exe Code function: 7_2_0117EB1D mov eax, dword ptr fs:[00000030h] 7_2_0117EB1D
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.MalwareX-gen.26512.27594.exe Code function: 7_2_0117EB1D mov eax, dword ptr fs:[00000030h] 7_2_0117EB1D
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.MalwareX-gen.26512.27594.exe Code function: 7_2_0117EB1D mov eax, dword ptr fs:[00000030h] 7_2_0117EB1D
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.MalwareX-gen.26512.27594.exe Code function: 7_2_0117EB1D mov eax, dword ptr fs:[00000030h] 7_2_0117EB1D
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.MalwareX-gen.26512.27594.exe Code function: 7_2_0112EB20 mov eax, dword ptr fs:[00000030h] 7_2_0112EB20
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.MalwareX-gen.26512.27594.exe Code function: 7_2_0112EB20 mov eax, dword ptr fs:[00000030h] 7_2_0112EB20
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.MalwareX-gen.26512.27594.exe Code function: 7_2_011C8B28 mov eax, dword ptr fs:[00000030h] 7_2_011C8B28
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.MalwareX-gen.26512.27594.exe Code function: 7_2_011C8B28 mov eax, dword ptr fs:[00000030h] 7_2_011C8B28
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.MalwareX-gen.26512.27594.exe Code function: 7_2_011AEB50 mov eax, dword ptr fs:[00000030h] 7_2_011AEB50
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.MalwareX-gen.26512.27594.exe Code function: 7_2_011B4B4B mov eax, dword ptr fs:[00000030h] 7_2_011B4B4B
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.MalwareX-gen.26512.27594.exe Code function: 7_2_011B4B4B mov eax, dword ptr fs:[00000030h] 7_2_011B4B4B
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.MalwareX-gen.26512.27594.exe Code function: 7_2_011A8B42 mov eax, dword ptr fs:[00000030h] 7_2_011A8B42
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.MalwareX-gen.26512.27594.exe Code function: 7_2_01196B40 mov eax, dword ptr fs:[00000030h] 7_2_01196B40
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.MalwareX-gen.26512.27594.exe Code function: 7_2_01196B40 mov eax, dword ptr fs:[00000030h] 7_2_01196B40
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.MalwareX-gen.26512.27594.exe Code function: 7_2_011CAB40 mov eax, dword ptr fs:[00000030h] 7_2_011CAB40
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.MalwareX-gen.26512.27594.exe Code function: 7_2_010FCB7E mov eax, dword ptr fs:[00000030h] 7_2_010FCB7E
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.MalwareX-gen.26512.27594.exe Code function: 7_2_011B4BB0 mov eax, dword ptr fs:[00000030h] 7_2_011B4BB0
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.MalwareX-gen.26512.27594.exe Code function: 7_2_011B4BB0 mov eax, dword ptr fs:[00000030h] 7_2_011B4BB0
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.MalwareX-gen.26512.27594.exe Code function: 7_2_01110BBE mov eax, dword ptr fs:[00000030h] 7_2_01110BBE
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.MalwareX-gen.26512.27594.exe Code function: 7_2_01110BBE mov eax, dword ptr fs:[00000030h] 7_2_01110BBE
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.MalwareX-gen.26512.27594.exe Code function: 7_2_011AEBD0 mov eax, dword ptr fs:[00000030h] 7_2_011AEBD0
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.MalwareX-gen.26512.27594.exe Code function: 7_2_01120BCB mov eax, dword ptr fs:[00000030h] 7_2_01120BCB
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.MalwareX-gen.26512.27594.exe Code function: 7_2_01120BCB mov eax, dword ptr fs:[00000030h] 7_2_01120BCB
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.MalwareX-gen.26512.27594.exe Code function: 7_2_01120BCB mov eax, dword ptr fs:[00000030h] 7_2_01120BCB
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.MalwareX-gen.26512.27594.exe Code function: 7_2_01100BCD mov eax, dword ptr fs:[00000030h] 7_2_01100BCD
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.MalwareX-gen.26512.27594.exe Code function: 7_2_01100BCD mov eax, dword ptr fs:[00000030h] 7_2_01100BCD
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.MalwareX-gen.26512.27594.exe Code function: 7_2_01100BCD mov eax, dword ptr fs:[00000030h] 7_2_01100BCD
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.MalwareX-gen.26512.27594.exe Code function: 7_2_01108BF0 mov eax, dword ptr fs:[00000030h] 7_2_01108BF0
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.MalwareX-gen.26512.27594.exe Code function: 7_2_01108BF0 mov eax, dword ptr fs:[00000030h] 7_2_01108BF0
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.MalwareX-gen.26512.27594.exe Code function: 7_2_01108BF0 mov eax, dword ptr fs:[00000030h] 7_2_01108BF0
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.MalwareX-gen.26512.27594.exe Code function: 7_2_0118CBF0 mov eax, dword ptr fs:[00000030h] 7_2_0118CBF0
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.MalwareX-gen.26512.27594.exe Code function: 7_2_0112EBFC mov eax, dword ptr fs:[00000030h] 7_2_0112EBFC
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.MalwareX-gen.26512.27594.exe Code function: 7_2_0118CA11 mov eax, dword ptr fs:[00000030h] 7_2_0118CA11
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.MalwareX-gen.26512.27594.exe Code function: 7_2_01124A35 mov eax, dword ptr fs:[00000030h] 7_2_01124A35
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.MalwareX-gen.26512.27594.exe Code function: 7_2_01124A35 mov eax, dword ptr fs:[00000030h] 7_2_01124A35
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.MalwareX-gen.26512.27594.exe Code function: 7_2_0113CA38 mov eax, dword ptr fs:[00000030h] 7_2_0113CA38
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.MalwareX-gen.26512.27594.exe Code function: 7_2_0113CA24 mov eax, dword ptr fs:[00000030h] 7_2_0113CA24
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.MalwareX-gen.26512.27594.exe Code function: 7_2_0112EA2E mov eax, dword ptr fs:[00000030h] 7_2_0112EA2E
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.MalwareX-gen.26512.27594.exe Code function: 7_2_01106A50 mov eax, dword ptr fs:[00000030h] 7_2_01106A50
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.MalwareX-gen.26512.27594.exe Code function: 7_2_01106A50 mov eax, dword ptr fs:[00000030h] 7_2_01106A50
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.MalwareX-gen.26512.27594.exe Code function: 7_2_01106A50 mov eax, dword ptr fs:[00000030h] 7_2_01106A50
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.MalwareX-gen.26512.27594.exe Code function: 7_2_01106A50 mov eax, dword ptr fs:[00000030h] 7_2_01106A50
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.MalwareX-gen.26512.27594.exe Code function: 7_2_01106A50 mov eax, dword ptr fs:[00000030h] 7_2_01106A50
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.MalwareX-gen.26512.27594.exe Code function: 7_2_01106A50 mov eax, dword ptr fs:[00000030h] 7_2_01106A50
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.MalwareX-gen.26512.27594.exe Code function: 7_2_01106A50 mov eax, dword ptr fs:[00000030h] 7_2_01106A50
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.MalwareX-gen.26512.27594.exe Code function: 7_2_01110A5B mov eax, dword ptr fs:[00000030h] 7_2_01110A5B
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.MalwareX-gen.26512.27594.exe Code function: 7_2_01110A5B mov eax, dword ptr fs:[00000030h] 7_2_01110A5B
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.MalwareX-gen.26512.27594.exe Code function: 7_2_0117CA72 mov eax, dword ptr fs:[00000030h] 7_2_0117CA72
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.MalwareX-gen.26512.27594.exe Code function: 7_2_0117CA72 mov eax, dword ptr fs:[00000030h] 7_2_0117CA72
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.MalwareX-gen.26512.27594.exe Code function: 7_2_011AEA60 mov eax, dword ptr fs:[00000030h] 7_2_011AEA60
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.MalwareX-gen.26512.27594.exe Code function: 7_2_0113CA6F mov eax, dword ptr fs:[00000030h] 7_2_0113CA6F
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.MalwareX-gen.26512.27594.exe Code function: 7_2_0113CA6F mov eax, dword ptr fs:[00000030h] 7_2_0113CA6F
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.MalwareX-gen.26512.27594.exe Code function: 7_2_0113CA6F mov eax, dword ptr fs:[00000030h] 7_2_0113CA6F
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.MalwareX-gen.26512.27594.exe Code function: 7_2_01138A90 mov edx, dword ptr fs:[00000030h] 7_2_01138A90
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.MalwareX-gen.26512.27594.exe Code function: 7_2_0110EA80 mov eax, dword ptr fs:[00000030h] 7_2_0110EA80
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.MalwareX-gen.26512.27594.exe Code function: 7_2_0110EA80 mov eax, dword ptr fs:[00000030h] 7_2_0110EA80
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.MalwareX-gen.26512.27594.exe Code function: 7_2_0110EA80 mov eax, dword ptr fs:[00000030h] 7_2_0110EA80
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.MalwareX-gen.26512.27594.exe Code function: 7_2_0110EA80 mov eax, dword ptr fs:[00000030h] 7_2_0110EA80
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.MalwareX-gen.26512.27594.exe Code function: 7_2_0110EA80 mov eax, dword ptr fs:[00000030h] 7_2_0110EA80
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.MalwareX-gen.26512.27594.exe Code function: 7_2_0110EA80 mov eax, dword ptr fs:[00000030h] 7_2_0110EA80
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.MalwareX-gen.26512.27594.exe Code function: 7_2_0110EA80 mov eax, dword ptr fs:[00000030h] 7_2_0110EA80
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.MalwareX-gen.26512.27594.exe Code function: 7_2_0110EA80 mov eax, dword ptr fs:[00000030h] 7_2_0110EA80
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.MalwareX-gen.26512.27594.exe Code function: 7_2_0110EA80 mov eax, dword ptr fs:[00000030h] 7_2_0110EA80
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.MalwareX-gen.26512.27594.exe Code function: 7_2_011D4A80 mov eax, dword ptr fs:[00000030h] 7_2_011D4A80
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.MalwareX-gen.26512.27594.exe Code function: 7_2_01108AA0 mov eax, dword ptr fs:[00000030h] 7_2_01108AA0
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.MalwareX-gen.26512.27594.exe Code function: 7_2_01108AA0 mov eax, dword ptr fs:[00000030h] 7_2_01108AA0
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.MalwareX-gen.26512.27594.exe Code function: 7_2_01156AA4 mov eax, dword ptr fs:[00000030h] 7_2_01156AA4
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.MalwareX-gen.26512.27594.exe Code function: 7_2_01100AD0 mov eax, dword ptr fs:[00000030h] 7_2_01100AD0
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.MalwareX-gen.26512.27594.exe Code function: 7_2_01134AD0 mov eax, dword ptr fs:[00000030h] 7_2_01134AD0
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.MalwareX-gen.26512.27594.exe Code function: 7_2_01134AD0 mov eax, dword ptr fs:[00000030h] 7_2_01134AD0
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.MalwareX-gen.26512.27594.exe Code function: 7_2_01156ACC mov eax, dword ptr fs:[00000030h] 7_2_01156ACC
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.MalwareX-gen.26512.27594.exe Code function: 7_2_01156ACC mov eax, dword ptr fs:[00000030h] 7_2_01156ACC
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.MalwareX-gen.26512.27594.exe Code function: 7_2_01156ACC mov eax, dword ptr fs:[00000030h] 7_2_01156ACC
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.MalwareX-gen.26512.27594.exe Code function: 7_2_0113AAEE mov eax, dword ptr fs:[00000030h] 7_2_0113AAEE
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.MalwareX-gen.26512.27594.exe Code function: 7_2_0113AAEE mov eax, dword ptr fs:[00000030h] 7_2_0113AAEE
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.MalwareX-gen.26512.27594.exe Code function: 7_2_011B8D10 mov eax, dword ptr fs:[00000030h] 7_2_011B8D10
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.MalwareX-gen.26512.27594.exe Code function: 7_2_011B8D10 mov eax, dword ptr fs:[00000030h] 7_2_011B8D10
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.MalwareX-gen.26512.27594.exe Code function: 7_2_01134D1D mov eax, dword ptr fs:[00000030h] 7_2_01134D1D
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.MalwareX-gen.26512.27594.exe Code function: 7_2_0111AD00 mov eax, dword ptr fs:[00000030h] 7_2_0111AD00
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.MalwareX-gen.26512.27594.exe Code function: 7_2_0111AD00 mov eax, dword ptr fs:[00000030h] 7_2_0111AD00
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.MalwareX-gen.26512.27594.exe Code function: 7_2_0111AD00 mov eax, dword ptr fs:[00000030h] 7_2_0111AD00
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.MalwareX-gen.26512.27594.exe Code function: 7_2_010F6D10 mov eax, dword ptr fs:[00000030h] 7_2_010F6D10
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.MalwareX-gen.26512.27594.exe Process token adjusted: Debug Jump to behavior
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe Process token adjusted: Debug Jump to behavior
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.MalwareX-gen.26512.27594.exe Memory allocated: page read and write | page guard Jump to behavior

HIPS / PFW / Operating System Protection Evasion

barindex
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.MalwareX-gen.26512.27594.exe Process created: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe "C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe" Add-MpPreference -ExclusionPath "C:\Users\user\Desktop\SecuriteInfo.com.Win32.MalwareX-gen.26512.27594.exe"
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.MalwareX-gen.26512.27594.exe Process created: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe "C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe" Add-MpPreference -ExclusionPath "C:\Users\user\Desktop\SecuriteInfo.com.Win32.MalwareX-gen.26512.27594.exe" Jump to behavior
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.MalwareX-gen.26512.27594.exe Process created: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe "C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe" Add-MpPreference -ExclusionPath "C:\Users\user\Desktop\SecuriteInfo.com.Win32.MalwareX-gen.26512.27594.exe" Jump to behavior
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.MalwareX-gen.26512.27594.exe Process created: C:\Users\user\Desktop\SecuriteInfo.com.Win32.MalwareX-gen.26512.27594.exe "C:\Users\user\Desktop\SecuriteInfo.com.Win32.MalwareX-gen.26512.27594.exe" Jump to behavior
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.MalwareX-gen.26512.27594.exe Process created: C:\Users\user\Desktop\SecuriteInfo.com.Win32.MalwareX-gen.26512.27594.exe "C:\Users\user\Desktop\SecuriteInfo.com.Win32.MalwareX-gen.26512.27594.exe" Jump to behavior
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.MalwareX-gen.26512.27594.exe Process created: C:\Users\user\Desktop\SecuriteInfo.com.Win32.MalwareX-gen.26512.27594.exe "C:\Users\user\Desktop\SecuriteInfo.com.Win32.MalwareX-gen.26512.27594.exe" Jump to behavior
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.MalwareX-gen.26512.27594.exe Queries volume information: C:\Users\user\Desktop\SecuriteInfo.com.Win32.MalwareX-gen.26512.27594.exe VolumeInformation Jump to behavior
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.MalwareX-gen.26512.27594.exe Queries volume information: C:\Windows\Microsoft.NET\assembly\GAC_MSIL\System.Windows.Forms\v4.0_4.0.0.0__b77a5c561934e089\System.Windows.Forms.dll VolumeInformation Jump to behavior
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.MalwareX-gen.26512.27594.exe Queries volume information: C:\Windows\Microsoft.NET\assembly\GAC_MSIL\System.Drawing\v4.0_4.0.0.0__b03f5f7f11d50a3a\System.Drawing.dll VolumeInformation Jump to behavior
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.MalwareX-gen.26512.27594.exe Queries volume information: C:\Windows\Microsoft.NET\assembly\GAC_MSIL\Accessibility\v4.0_4.0.0.0__b03f5f7f11d50a3a\Accessibility.dll VolumeInformation Jump to behavior
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.MalwareX-gen.26512.27594.exe Queries volume information: C:\Windows\Fonts\micross.ttf VolumeInformation Jump to behavior
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.MalwareX-gen.26512.27594.exe Queries volume information: C:\Windows\Microsoft.NET\assembly\GAC_MSIL\Microsoft.VisualBasic\v4.0_10.0.0.0__b03f5f7f11d50a3a\Microsoft.VisualBasic.dll VolumeInformation Jump to behavior
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe Queries volume information: C:\Windows\Microsoft.NET\assembly\GAC_32\System.Data\v4.0_4.0.0.0__b77a5c561934e089\System.Data.dll VolumeInformation Jump to behavior
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe Queries volume information: C:\Windows\System32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-Client-Features-Package0313~31bf3856ad364e35~amd64~~10.0.19041.1949.cat VolumeInformation Jump to behavior
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe Queries volume information: C:\Windows\Microsoft.NET\assembly\GAC_32\System.Transactions\v4.0_4.0.0.0__b77a5c561934e089\System.Transactions.dll VolumeInformation Jump to behavior
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe Queries volume information: C:\ VolumeInformation Jump to behavior
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe Queries volume information: C:\Windows\System32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-Client-Features-Package0313~31bf3856ad364e35~amd64~~10.0.19041.1949.cat VolumeInformation Jump to behavior
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe Queries volume information: C:\Windows\System32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-Client-Features-Package0313~31bf3856ad364e35~amd64~~10.0.19041.1949.cat VolumeInformation Jump to behavior
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe Queries volume information: C:\Windows\System32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-GroupPolicy-ClientTools-WOW64-Package~31bf3856ad364e35~amd64~~10.0.19041.1949.cat VolumeInformation Jump to behavior
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe Queries volume information: C:\Windows\System32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-AppManagement-AppV-WOW64-Package~31bf3856ad364e35~amd64~~10.0.19041.1949.cat VolumeInformation Jump to behavior
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe Queries volume information: C:\Windows\Microsoft.NET\assembly\GAC_32\Microsoft.Management.Infrastructure.Native\v4.0_1.0.0.0__31bf3856ad364e35\Microsoft.Management.Infrastructure.Native.dll VolumeInformation Jump to behavior
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe Queries volume information: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\Modules\AppvClient\Microsoft.AppV.AppVClientPowerShell.dll VolumeInformation Jump to behavior
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe Queries volume information: C:\Windows\Microsoft.NET\assembly\GAC_32\Microsoft.AppV.AppvClientComConsumer\v4.0_10.0.0.0__31bf3856ad364e35\Microsoft.AppV.AppvClientComConsumer.dll VolumeInformation Jump to behavior
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe Queries volume information: C:\Windows\System32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-SecureStartup-Subsystem-WOW64-Package~31bf3856ad364e35~amd64~~10.0.19041.1865.cat VolumeInformation Jump to behavior
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe Queries volume information: C:\Windows\System32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-SecureStartup-Subsystem-WOW64-Package~31bf3856ad364e35~amd64~en-GB~10.0.19041.1.cat VolumeInformation Jump to behavior
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe Queries volume information: C:\Windows\System32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-Client-Features-Package0313~31bf3856ad364e35~amd64~~10.0.19041.1949.cat VolumeInformation Jump to behavior
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe Queries volume information: C:\Windows\System32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-Client-Features-Package0313~31bf3856ad364e35~amd64~~10.0.19041.1949.cat VolumeInformation Jump to behavior
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe Queries volume information: C:\Windows\System32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-Client-Features-Package0313~31bf3856ad364e35~amd64~~10.0.19041.1949.cat VolumeInformation Jump to behavior
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe Queries volume information: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\Modules\BitLocker\Microsoft.BitLocker.Structures.dll VolumeInformation Jump to behavior
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe Queries volume information: C:\Windows\System32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-Client-Desktop-Required-WOW64-Package~31bf3856ad364e35~amd64~~10.0.19041.2006.cat VolumeInformation Jump to behavior
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe Queries volume information: C:\Windows\System32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-Client-Desktop-Required-WOW64-Package~31bf3856ad364e35~amd64~~10.0.19041.2006.cat VolumeInformation Jump to behavior
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe Queries volume information: C:\Windows\Microsoft.NET\assembly\GAC_MSIL\Microsoft.PowerShell.Commands.Management\v4.0_3.0.0.0__31bf3856ad364e35\Microsoft.PowerShell.Commands.Management.dll VolumeInformation Jump to behavior
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe Queries volume information: C:\Windows\System32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-Client-Desktop-Required-WOW64-Package~31bf3856ad364e35~amd64~~10.0.19041.2006.cat VolumeInformation Jump to behavior
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe Queries volume information: C:\Windows\System32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-Client-Desktop-Required-WOW64-Package~31bf3856ad364e35~amd64~~10.0.19041.2006.cat VolumeInformation Jump to behavior
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe Queries volume information: C:\Windows\System32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-Client-Desktop-Required-WOW64-Package~31bf3856ad364e35~amd64~~10.0.19041.2006.cat VolumeInformation Jump to behavior
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe Queries volume information: C:\Windows\System32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-Client-Desktop-Required-WOW64-Package~31bf3856ad364e35~amd64~~10.0.19041.2006.cat VolumeInformation Jump to behavior
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe Queries volume information: C:\Windows\System32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-Client-Desktop-Required-WOW64-Package~31bf3856ad364e35~amd64~~10.0.19041.2006.cat VolumeInformation Jump to behavior
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe Queries volume information: C:\Windows\System32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-Client-Desktop-Required-WOW64-Package~31bf3856ad364e35~amd64~~10.0.19041.2006.cat VolumeInformation Jump to behavior
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe Queries volume information: C:\Windows\System32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-Client-Desktop-Required-WOW64-Package~31bf3856ad364e35~amd64~~10.0.19041.2006.cat VolumeInformation Jump to behavior
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.MalwareX-gen.26512.27594.exe Key value queried: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Cryptography MachineGuid Jump to behavior

Stealing of Sensitive Information

barindex
Source: Yara match File source: 7.2.SecuriteInfo.com.Win32.MalwareX-gen.26512.27594.exe.400000.0.raw.unpack, type: UNPACKEDPE
Source: Yara match File source: 7.2.SecuriteInfo.com.Win32.MalwareX-gen.26512.27594.exe.400000.0.unpack, type: UNPACKEDPE
Source: Yara match File source: 00000007.00000002.1336089947.0000000000400000.00000040.00000400.00020000.00000000.sdmp, type: MEMORY
Source: Yara match File source: 00000000.00000002.1358724042.000000000359C000.00000004.00000800.00020000.00000000.sdmp, type: MEMORY

Remote Access Functionality

barindex
Source: Yara match File source: 7.2.SecuriteInfo.com.Win32.MalwareX-gen.26512.27594.exe.400000.0.raw.unpack, type: UNPACKEDPE
Source: Yara match File source: 7.2.SecuriteInfo.com.Win32.MalwareX-gen.26512.27594.exe.400000.0.unpack, type: UNPACKEDPE
Source: Yara match File source: 00000007.00000002.1336089947.0000000000400000.00000040.00000400.00020000.00000000.sdmp, type: MEMORY
Source: Yara match File source: 00000000.00000002.1358724042.000000000359C000.00000004.00000800.00020000.00000000.sdmp, type: MEMORY
No contacted IP infos