Score: | 24 |
Range: | 0 - 100 |
Whitelisted: | false |
Confidence: | 40% |
Score: | 48 |
Range: | 0 - 100 |
Source: |
EXE: |
Jump to behavior | ||
Source: |
EXE: |
Jump to behavior | ||
Source: |
EXE: |
Jump to behavior | ||
Source: |
EXE: |
Jump to behavior | ||
Source: |
EXE: |
Jump to behavior |
Compliance |
---|
Source: |
EXE: |
Jump to behavior | ||
Source: |
EXE: |
Jump to behavior | ||
Source: |
EXE: |
Jump to behavior | ||
Source: |
EXE: |
Jump to behavior | ||
Source: |
EXE: |
Jump to behavior |
Source: |
File created: |
Jump to behavior | ||
Source: |
File created: |
Jump to behavior |
Source: |
Static PE information: |
Source: |
Static PE information: |
Source: |
Binary string: |
||
Source: |
Binary string: |
||
Source: |
Binary string: |
||
Source: |
Binary string: |
||
Source: |
Binary string: |
||
Source: |
Binary string: |
||
Source: |
Binary string: |
||
Source: |
Binary string: |
||
Source: |
Binary string: |
||
Source: |
Binary string: |
||
Source: |
Binary string: |
||
Source: |
Binary string: |
||
Source: |
Binary string: |
||
Source: |
Binary string: |
||
Source: |
Binary string: |
||
Source: |
Binary string: |
||
Source: |
Binary string: |
||
Source: |
Binary string: |
||
Source: |
Binary string: |
||
Source: |
Binary string: |
Source: |
Code function: |
0_2_000000013F791F08 | |
Source: |
Code function: |
0_2_000000013F7B9B40 | |
Source: |
Code function: |
0_2_000000013F7A34D0 | |
Source: |
Code function: |
4_2_000000013FA49B10 | |
Source: |
Code function: |
4_2_000000013FA66DC0 |
Source: |
String found in binary or memory: |
||
Source: |
String found in binary or memory: |
||
Source: |
String found in binary or memory: |
||
Source: |
String found in binary or memory: |
||
Source: |
String found in binary or memory: |
||
Source: |
String found in binary or memory: |
||
Source: |
String found in binary or memory: |
||
Source: |
String found in binary or memory: |
||
Source: |
String found in binary or memory: |
||
Source: |
String found in binary or memory: |
||
Source: |
String found in binary or memory: |
||
Source: |
String found in binary or memory: |
||
Source: |
String found in binary or memory: |
||
Source: |
String found in binary or memory: |
||
Source: |
String found in binary or memory: |
||
Source: |
String found in binary or memory: |
||
Source: |
String found in binary or memory: |
||
Source: |
String found in binary or memory: |
||
Source: |
String found in binary or memory: |
Source: |
Window created: |
Jump to behavior |
Spam, unwanted Advertisements and Ransom Demands |
---|
Source: |
File dropped: |
Jump to dropped file |
Source: |
Code function: |
0_2_000000013F7A0A20 |
Source: |
Code function: |
0_2_000000013F78C4E0 |
Source: |
Code function: |
0_2_000000013F78DE98 | |
Source: |
Code function: |
0_2_000000013F795B4C | |
Source: |
Code function: |
0_2_000000013F7A5ABC | |
Source: |
Code function: |
0_2_000000013F796960 | |
Source: |
Code function: |
0_2_000000013F7A4930 | |
Source: |
Code function: |
0_2_000000013F785330 | |
Source: |
Code function: |
0_2_000000013F79D3C0 | |
Source: |
Code function: |
0_2_000000013F7A41D0 | |
Source: |
Code function: |
0_2_000000013F79EEF0 | |
Source: |
Code function: |
0_2_000000013F797FC8 | |
Source: |
Code function: |
0_2_000000013F7BCFAC | |
Source: |
Code function: |
0_2_000000013F7B7D40 | |
Source: |
Code function: |
0_2_000000013F7A1CE8 | |
Source: |
Code function: |
0_2_000000013F7B1D94 | |
Source: |
Code function: |
0_2_000000013F7B9B40 | |
Source: |
Code function: |
0_2_000000013F7BCB10 | |
Source: |
Code function: |
0_2_000000013F788BE0 | |
Source: |
Code function: |
0_2_000000013F7B1B90 | |
Source: |
Code function: |
0_2_000000013F79F9B0 | |
Source: |
Code function: |
0_2_000000013F7B1984 | |
Source: |
Code function: |
0_2_000000013F798978 | |
Source: |
Code function: |
0_2_000000013F7B2840 | |
Source: |
Code function: |
0_2_000000013F7B78AC | |
Source: |
Code function: |
0_2_000000013F787754 | |
Source: |
Code function: |
0_2_000000013F7B1780 | |
Source: |
Code function: |
0_2_000000013F784778 | |
Source: |
Code function: |
0_2_000000013F7C1518 | |
Source: |
Code function: |
0_2_000000013F7B35D4 | |
Source: |
Code function: |
0_2_000000013F7B65C0 | |
Source: |
Code function: |
0_2_000000013F7B1574 | |
Source: |
Code function: |
0_2_000000013F7994DC | |
Source: |
Code function: |
0_2_000000013F7B83C0 | |
Source: |
Code function: |
0_2_000000013F7B1370 | |
Source: |
Code function: |
0_2_000000013F78A1EC | |
Source: |
Code function: |
0_2_000000013F7B31D0 | |
Source: |
Code function: |
0_2_000000013F79F04C | |
Source: |
Code function: |
4_2_000000013FA6CC50 | |
Source: |
Code function: |
4_2_000000013FA4BA0C | |
Source: |
Code function: |
4_2_000000013FA48F98 | |
Source: |
Code function: |
4_2_000000013FA5C780 | |
Source: |
Code function: |
4_2_000000013FA52FD8 | |
Source: |
Code function: |
4_2_000000013FA4C7E0 | |
Source: |
Code function: |
4_2_000000013FA5DFC0 | |
Source: |
Code function: |
4_2_000000013FA6C704 | |
Source: |
Code function: |
4_2_000000013FA5BF60 | |
Source: |
Code function: |
4_2_000000013FA62D9C | |
Source: |
Code function: |
4_2_000000013FA5C57C | |
Source: |
Code function: |
4_2_000000013FA6F5C8 | |
Source: |
Code function: |
4_2_000000013FA66DC0 | |
Source: |
Code function: |
4_2_000000013FA5BD5C | |
Source: |
Code function: |
4_2_000000013FA69D30 | |
Source: |
Code function: |
4_2_000000013FA5C370 | |
Source: |
Code function: |
4_2_000000013FA5DBBC | |
Source: |
Code function: |
4_2_000000013FA63230 | |
Source: |
Code function: |
4_2_000000013FA5D22C | |
Source: |
Code function: |
4_2_000000013FA5C16C | |
Source: |
Code function: |
4_2_000000013FA6A1CC | |
Source: |
Code function: |
4_2_000000013FA61928 | |
Source: |
Code function: |
4_2_000000013FA638B0 |
Source: |
Dropped File: |
||
Source: |
Dropped File: |
Source: |
Binary or memory string: |
||
Source: |
Binary or memory string: |
||
Source: |
Binary or memory string: |
||
Source: |
Binary or memory string: |
||
Source: |
Binary or memory string: |
||
Source: |
Binary or memory string: |
||
Source: |
Binary or memory string: |
||
Source: |
Binary or memory string: |
Source: |
Key opened: |
Jump to behavior |
Source: |
Classification label: |
Source: |
Code function: |
0_2_000000013F78BA38 |
Source: |
Code function: |
4_2_000000013FA4853C |
Source: |
Code function: |
0_2_000000013F7A02DC |
Source: |
Code function: |
0_2_000000013F7A1FEC |
Source: |
File created: |
Jump to behavior |
Source: |
Static PE information: |
Source: |
File read: |
Jump to behavior |
Source: |
Key opened: |
Jump to behavior |
Source: |
String found in binary or memory: |
||
Source: |
String found in binary or memory: |
Source: |
File read: |
Jump to behavior |
Source: |
Process created: |
|||
Source: |
Process created: |
|||
Source: |
Process created: |
Jump to behavior |
Source: |
Section loaded: |
Jump to behavior | ||
Source: |
Section loaded: |
Jump to behavior | ||
Source: |
Section loaded: |
Jump to behavior | ||
Source: |
Section loaded: |
Jump to behavior | ||
Source: |
Section loaded: |
Jump to behavior | ||
Source: |
Section loaded: |
Jump to behavior | ||
Source: |
Section loaded: |
Jump to behavior | ||
Source: |
Section loaded: |
Jump to behavior | ||
Source: |
Section loaded: |
Jump to behavior | ||
Source: |
Section loaded: |
Jump to behavior | ||
Source: |
Section loaded: |
Jump to behavior | ||
Source: |
Section loaded: |
Jump to behavior | ||
Source: |
Section loaded: |
Jump to behavior | ||
Source: |
Section loaded: |
Jump to behavior | ||
Source: |
Section loaded: |
Jump to behavior | ||
Source: |
Section loaded: |
Jump to behavior | ||
Source: |
Section loaded: |
Jump to behavior | ||
Source: |
Section loaded: |
Jump to behavior | ||
Source: |
Section loaded: |
Jump to behavior | ||
Source: |
Section loaded: |
Jump to behavior | ||
Source: |
Section loaded: |
Jump to behavior | ||
Source: |
Section loaded: |
Jump to behavior | ||
Source: |
Section loaded: |
Jump to behavior | ||
Source: |
Section loaded: |
Jump to behavior | ||
Source: |
Section loaded: |
Jump to behavior | ||
Source: |
Section loaded: |
Jump to behavior | ||
Source: |
Section loaded: |
Jump to behavior | ||
Source: |
Section loaded: |
Jump to behavior | ||
Source: |
Section loaded: |
Jump to behavior | ||
Source: |
Section loaded: |
Jump to behavior | ||
Source: |
Section loaded: |
Jump to behavior | ||
Source: |
Section loaded: |
Jump to behavior | ||
Source: |
Section loaded: |
Jump to behavior | ||
Source: |
Section loaded: |
Jump to behavior | ||
Source: |
Section loaded: |
Jump to behavior | ||
Source: |
Section loaded: |
Jump to behavior | ||
Source: |
Section loaded: |
Jump to behavior | ||
Source: |
Section loaded: |
Jump to behavior | ||
Source: |
Section loaded: |
Jump to behavior | ||
Source: |
Section loaded: |
Jump to behavior | ||
Source: |
Section loaded: |
Jump to behavior | ||
Source: |
Section loaded: |
Jump to behavior | ||
Source: |
Section loaded: |
Jump to behavior |
Source: |
Key value queried: |
Jump to behavior |
Source: |
LNK file: |
||
Source: |
LNK file: |
||
Source: |
LNK file: |
||
Source: |
LNK file: |
||
Source: |
LNK file: |
||
Source: |
LNK file: |
||
Source: |
LNK file: |
||
Source: |
LNK file: |
Source: |
Automated click: |
||
Source: |
Automated click: |
||
Source: |
Automated click: |
Source: |
Window detected: |
Source: |
Window detected: |
Source: |
Static PE information: |
Source: |
Static PE information: |
Source: |
Static file information: |
Source: |
Static PE information: |
||
Source: |
Static PE information: |
||
Source: |
Static PE information: |
||
Source: |
Static PE information: |
||
Source: |
Static PE information: |
||
Source: |
Static PE information: |
Source: |
Static PE information: |
Source: |
Static PE information: |
Source: |
Binary string: |
||
Source: |
Binary string: |
||
Source: |
Binary string: |
||
Source: |
Binary string: |
||
Source: |
Binary string: |
||
Source: |
Binary string: |
||
Source: |
Binary string: |
||
Source: |
Binary string: |
||
Source: |
Binary string: |
||
Source: |
Binary string: |
||
Source: |
Binary string: |
||
Source: |
Binary string: |
||
Source: |
Binary string: |
||
Source: |
Binary string: |
||
Source: |
Binary string: |
||
Source: |
Binary string: |
||
Source: |
Binary string: |
||
Source: |
Binary string: |
||
Source: |
Binary string: |
||
Source: |
Binary string: |
Source: |
Static PE information: |
||
Source: |
Static PE information: |
||
Source: |
Static PE information: |
||
Source: |
Static PE information: |
||
Source: |
Static PE information: |
Source: |
File created: |
Jump to behavior |
Source: |
Static PE information: |
||
Source: |
Static PE information: |
||
Source: |
Static PE information: |
||
Source: |
Static PE information: |
||
Source: |
Static PE information: |
||
Source: |
Static PE information: |
||
Source: |
Static PE information: |
||
Source: |
Static PE information: |
||
Source: |
Static PE information: |
||
Source: |
Static PE information: |
||
Source: |
Static PE information: |
||
Source: |
Static PE information: |
||
Source: |
Static PE information: |
||
Source: |
Static PE information: |
||
Source: |
Static PE information: |
||
Source: |
Static PE information: |
||
Source: |
Static PE information: |
||
Source: |
Static PE information: |
Source: |
File created: |
Jump to dropped file | ||
Source: |
File created: |
Jump to dropped file | ||
Source: |
File created: |
Jump to dropped file | ||
Source: |
File created: |
Jump to dropped file | ||
Source: |
File created: |
Jump to dropped file | ||
Source: |
File created: |
Jump to dropped file | ||
Source: |
File created: |
Jump to dropped file | ||
Source: |
File created: |
Jump to dropped file | ||
Source: |
File created: |
Jump to dropped file | ||
Source: |
File created: |
Jump to dropped file | ||
Source: |
File created: |
Jump to dropped file | ||
Source: |
File created: |
Jump to dropped file | ||
Source: |
File created: |
Jump to dropped file | ||
Source: |
File created: |
Jump to dropped file |
Source: |
File created: |
Jump to dropped file | ||
Source: |
File created: |
Jump to dropped file | ||
Source: |
File created: |
Jump to dropped file | ||
Source: |
File created: |
Jump to dropped file | ||
Source: |
File created: |
Jump to dropped file | ||
Source: |
File created: |
Jump to dropped file | ||
Source: |
File created: |
Jump to dropped file | ||
Source: |
File created: |
Jump to dropped file | ||
Source: |
File created: |
Jump to dropped file | ||
Source: |
File created: |
Jump to dropped file | ||
Source: |
File created: |
Jump to dropped file | ||
Source: |
File created: |
Jump to dropped file | ||
Source: |
File created: |
Jump to dropped file | ||
Source: |
File created: |
Jump to dropped file |
Source: |
File created: |
Jump to dropped file | ||
Source: |
File created: |
Jump to dropped file | ||
Source: |
File created: |
Jump to dropped file | ||
Source: |
File created: |
Jump to dropped file | ||
Source: |
File created: |
Jump to dropped file | ||
Source: |
File created: |
Jump to dropped file |
Source: |
File created: |
Jump to behavior | ||
Source: |
File created: |
Jump to behavior |
Boot Survival |
---|
Source: |
File created: |
Jump to dropped file | ||
Source: |
File created: |
Jump to dropped file | ||
Source: |
File created: |
Jump to dropped file | ||
Source: |
File created: |
Jump to dropped file | ||
Source: |
File created: |
Jump to dropped file | ||
Source: |
File created: |
Jump to dropped file | ||
Source: |
File created: |
Jump to dropped file | ||
Source: |
File created: |
Jump to dropped file | ||
Source: |
File created: |
Jump to dropped file | ||
Source: |
File created: |
Jump to dropped file | ||
Source: |
File created: |
Jump to dropped file | ||
Source: |
File created: |
Jump to dropped file | ||
Source: |
File created: |
Jump to dropped file | ||
Source: |
File created: |
Jump to dropped file |
Source: |
File created: |
Jump to behavior | ||
Source: |
File created: |
Jump to behavior | ||
Source: |
File created: |
Jump to behavior | ||
Source: |
File created: |
Jump to behavior | ||
Source: |
File created: |
Jump to behavior | ||
Source: |
File created: |
Jump to behavior | ||
Source: |
File created: |
Jump to behavior | ||
Source: |
File created: |
Jump to behavior | ||
Source: |
File created: |
Jump to behavior | ||
Source: |
File created: |
Jump to behavior |
Source: |
Process information set: |
Jump to behavior | ||
Source: |
Process information set: |
Jump to behavior | ||
Source: |
Process information set: |
Jump to behavior | ||
Source: |
Process information set: |
Jump to behavior | ||
Source: |
Process information set: |
Jump to behavior | ||
Source: |
Process information set: |
Jump to behavior | ||
Source: |
Process information set: |
Jump to behavior | ||
Source: |
Process information set: |
Jump to behavior | ||
Source: |
Process information set: |
Jump to behavior | ||
Source: |
Process information set: |
Jump to behavior |
Source: |
Memory allocated: |
Jump to behavior | ||
Source: |
Memory allocated: |
Jump to behavior |
Source: |
Dropped PE file which has not been started: |
Jump to dropped file | ||
Source: |
Dropped PE file which has not been started: |
Jump to dropped file | ||
Source: |
Dropped PE file which has not been started: |
Jump to dropped file | ||
Source: |
Dropped PE file which has not been started: |
Jump to dropped file | ||
Source: |
Dropped PE file which has not been started: |
Jump to dropped file | ||
Source: |
Dropped PE file which has not been started: |
Jump to dropped file | ||
Source: |
Dropped PE file which has not been started: |
Jump to dropped file | ||
Source: |
Dropped PE file which has not been started: |
Jump to dropped file | ||
Source: |
Dropped PE file which has not been started: |
Jump to dropped file | ||
Source: |
Dropped PE file which has not been started: |
Jump to dropped file | ||
Source: |
Dropped PE file which has not been started: |
Jump to dropped file | ||
Source: |
Dropped PE file which has not been started: |
Jump to dropped file | ||
Source: |
Dropped PE file which has not been started: |
Jump to dropped file |
Source: |
Thread sleep time: |
Jump to behavior |
Source: |
Code function: |
0_2_000000013F791F08 | |
Source: |
Code function: |
0_2_000000013F7B9B40 | |
Source: |
Code function: |
0_2_000000013F7A34D0 | |
Source: |
Code function: |
4_2_000000013FA49B10 | |
Source: |
Code function: |
4_2_000000013FA66DC0 |
Source: |
Code function: |
0_2_000000013F7A88A0 |
Source: |
Binary or memory string: |
Source: |
Code function: |
0_2_000000013F7AFEC8 |
Source: |
Code function: |
0_2_000000013F7BB630 |
Source: |
Code function: |
0_2_000000013F7A9D00 | |
Source: |
Code function: |
0_2_000000013F7AFEC8 | |
Source: |
Code function: |
0_2_000000013F7A9458 | |
Source: |
Code function: |
0_2_000000013F7AA354 | |
Source: |
Code function: |
0_2_000000013F7AA170 | |
Source: |
Code function: |
4_2_000000013FA54E10 | |
Source: |
Code function: |
4_2_000000013FA5AE38 | |
Source: |
Code function: |
4_2_000000013FA55488 | |
Source: |
Code function: |
4_2_000000013FA55298 | |
Source: |
Code function: |
4_2_000000013FA547F8 |
Source: |
Code function: |
0_2_000000013F7A4930 |
Source: |
Process created: |
Jump to behavior |
Source: |
Binary or memory string: |
Source: |
Code function: |
0_2_000000013F79AEE4 |
Source: |
Code function: |
0_2_000000013F7A2954 |
Source: |
Queries volume information: |
Jump to behavior | ||
Source: |
Queries volume information: |
Jump to behavior | ||
Source: |
Queries volume information: |
Jump to behavior | ||
Source: |
Queries volume information: |
Jump to behavior | ||
Source: |
Queries volume information: |
Jump to behavior | ||
Source: |
Queries volume information: |
Jump to behavior | ||
Source: |
Queries volume information: |
Jump to behavior | ||
Source: |
Queries volume information: |
Jump to behavior | ||
Source: |
Queries volume information: |
Jump to behavior | ||
Source: |
Queries volume information: |
Jump to behavior | ||
Source: |
Queries volume information: |
Jump to behavior | ||
Source: |
Queries volume information: |
Jump to behavior | ||
Source: |
Queries volume information: |
Jump to behavior | ||
Source: |
Queries volume information: |
Jump to behavior | ||
Source: |
Queries volume information: |
Jump to behavior | ||
Source: |
Queries volume information: |
Jump to behavior | ||
Source: |
Queries volume information: |
Jump to behavior | ||
Source: |
Queries volume information: |
Jump to behavior | ||
Source: |
Queries volume information: |
Jump to behavior |
Source: |
Code function: |
0_2_000000013F7A41D0 |
Source: |
Code function: |
0_2_000000013F792D64 |
Source: |
Key value queried: |
Jump to behavior |