Source: wnGDKyXdAo.exe |
Static PE information: HIGH_ENTROPY_VA, DYNAMIC_BASE, NX_COMPAT, TERMINAL_SERVER_AWARE |
Source: wnGDKyXdAo.exe |
String found in binary or memory: https://http://Mozilla/5.0 |
Source: C:\Users\user\Desktop\wnGDKyXdAo.exe |
Code function: 0_2_00007FF6B9CCDA9C |
0_2_00007FF6B9CCDA9C |
Source: C:\Users\user\Desktop\wnGDKyXdAo.exe |
Code function: 0_2_00007FF6B9C9E053 |
0_2_00007FF6B9C9E053 |
Source: C:\Users\user\Desktop\wnGDKyXdAo.exe |
Code function: 0_2_00007FF6B9CC2020 |
0_2_00007FF6B9CC2020 |
Source: C:\Users\user\Desktop\wnGDKyXdAo.exe |
Code function: 0_2_00007FF6B9CD6F64 |
0_2_00007FF6B9CD6F64 |
Source: C:\Users\user\Desktop\wnGDKyXdAo.exe |
Code function: 0_2_00007FF6B9CC2644 |
0_2_00007FF6B9CC2644 |
Source: C:\Users\user\Desktop\wnGDKyXdAo.exe |
Code function: 0_2_00007FF6B9C91A00 |
0_2_00007FF6B9C91A00 |
Source: C:\Users\user\Desktop\wnGDKyXdAo.exe |
Code function: 0_2_00007FF6B9C839F0 |
0_2_00007FF6B9C839F0 |
Source: C:\Users\user\Desktop\wnGDKyXdAo.exe |
Code function: 0_2_00007FF6B9CE5CC8 |
0_2_00007FF6B9CE5CC8 |
Source: C:\Users\user\Desktop\wnGDKyXdAo.exe |
Code function: 0_2_00007FF6B9CBDBB4 |
0_2_00007FF6B9CBDBB4 |
Source: C:\Users\user\Desktop\wnGDKyXdAo.exe |
Code function: 0_2_00007FF6B9C9FB3E |
0_2_00007FF6B9C9FB3E |
Source: C:\Users\user\Desktop\wnGDKyXdAo.exe |
Code function: 0_2_00007FF6B9C9CB40 |
0_2_00007FF6B9C9CB40 |
Source: C:\Users\user\Desktop\wnGDKyXdAo.exe |
Code function: 0_2_00007FF6B9CB1B38 |
0_2_00007FF6B9CB1B38 |
Source: C:\Users\user\Desktop\wnGDKyXdAo.exe |
Code function: 0_2_00007FF6B9C8CB60 |
0_2_00007FF6B9C8CB60 |
Source: C:\Users\user\Desktop\wnGDKyXdAo.exe |
Code function: 0_2_00007FF6B9C96F32 |
0_2_00007FF6B9C96F32 |
Source: C:\Users\user\Desktop\wnGDKyXdAo.exe |
Code function: 0_2_00007FF6B9CCCE74 |
0_2_00007FF6B9CCCE74 |
Source: C:\Users\user\Desktop\wnGDKyXdAo.exe |
Code function: 0_2_00007FF6B9C9BE20 |
0_2_00007FF6B9C9BE20 |
Source: C:\Users\user\Desktop\wnGDKyXdAo.exe |
Code function: 0_2_00007FF6B9C88DD0 |
0_2_00007FF6B9C88DD0 |
Source: C:\Users\user\Desktop\wnGDKyXdAo.exe |
Code function: 0_2_00007FF6B9CB1DC4 |
0_2_00007FF6B9CB1DC4 |
Source: C:\Users\user\Desktop\wnGDKyXdAo.exe |
Code function: 0_2_00007FF6B9CB5124 |
0_2_00007FF6B9CB5124 |
Source: C:\Users\user\Desktop\wnGDKyXdAo.exe |
Code function: 0_2_00007FF6B9C95050 |
0_2_00007FF6B9C95050 |
Source: C:\Users\user\Desktop\wnGDKyXdAo.exe |
Code function: 0_2_00007FF6B9CC0010 |
0_2_00007FF6B9CC0010 |
Source: C:\Users\user\Desktop\wnGDKyXdAo.exe |
Code function: 0_2_00007FF6B9CE1FE4 |
0_2_00007FF6B9CE1FE4 |
Source: C:\Users\user\Desktop\wnGDKyXdAo.exe |
Code function: 0_2_00007FF6B9CC0FB0 |
0_2_00007FF6B9CC0FB0 |
Source: C:\Users\user\Desktop\wnGDKyXdAo.exe |
Code function: 0_2_00007FF6B9CB8F9C |
0_2_00007FF6B9CB8F9C |
Source: C:\Users\user\Desktop\wnGDKyXdAo.exe |
Code function: 0_2_00007FF6B9C85F70 |
0_2_00007FF6B9C85F70 |
Source: C:\Users\user\Desktop\wnGDKyXdAo.exe |
Code function: 0_2_00007FF6B9CC52FC |
0_2_00007FF6B9CC52FC |
Source: C:\Users\user\Desktop\wnGDKyXdAo.exe |
Code function: 0_2_00007FF6B9CD42D8 |
0_2_00007FF6B9CD42D8 |
Source: C:\Users\user\Desktop\wnGDKyXdAo.exe |
Code function: 0_2_00007FF6B9C9F298 |
0_2_00007FF6B9C9F298 |
Source: C:\Users\user\Desktop\wnGDKyXdAo.exe |
Code function: 0_2_00007FF6B9CC1248 |
0_2_00007FF6B9CC1248 |
Source: C:\Users\user\Desktop\wnGDKyXdAo.exe |
Code function: 0_2_00007FF6B9C85190 |
0_2_00007FF6B9C85190 |
Source: C:\Users\user\Desktop\wnGDKyXdAo.exe |
Code function: 0_2_00007FF6B9C94160 |
0_2_00007FF6B9C94160 |
Source: C:\Users\user\Desktop\wnGDKyXdAo.exe |
Code function: 0_2_00007FF6B9C92500 |
0_2_00007FF6B9C92500 |
Source: C:\Users\user\Desktop\wnGDKyXdAo.exe |
Code function: 0_2_00007FF6B9C8E480 |
0_2_00007FF6B9C8E480 |
Source: C:\Users\user\Desktop\wnGDKyXdAo.exe |
Code function: 0_2_00007FF6B9C854A0 |
0_2_00007FF6B9C854A0 |
Source: C:\Users\user\Desktop\wnGDKyXdAo.exe |
Code function: 0_2_00007FF6B9CD1450 |
0_2_00007FF6B9CD1450 |
Source: C:\Users\user\Desktop\wnGDKyXdAo.exe |
Code function: 0_2_00007FF6B9C93470 |
0_2_00007FF6B9C93470 |
Source: C:\Users\user\Desktop\wnGDKyXdAo.exe |
Code function: 0_2_00007FF6B9CE5474 |
0_2_00007FF6B9CE5474 |
Source: C:\Users\user\Desktop\wnGDKyXdAo.exe |
Code function: 0_2_00007FF6B9C87360 |
0_2_00007FF6B9C87360 |
Source: C:\Users\user\Desktop\wnGDKyXdAo.exe |
Code function: 0_2_00007FF6B9CC56AC |
0_2_00007FF6B9CC56AC |
Source: C:\Users\user\Desktop\wnGDKyXdAo.exe |
Code function: 0_2_00007FF6B9CEB698 |
0_2_00007FF6B9CEB698 |
Source: C:\Users\user\Desktop\wnGDKyXdAo.exe |
Code function: 0_2_00007FF6B9C965D0 |
0_2_00007FF6B9C965D0 |
Source: C:\Users\user\Desktop\wnGDKyXdAo.exe |
Code function: 0_2_00007FF6B9C9A594 |
0_2_00007FF6B9C9A594 |
Source: C:\Users\user\Desktop\wnGDKyXdAo.exe |
Code function: 0_2_00007FF6B9C86590 |
0_2_00007FF6B9C86590 |
Source: C:\Users\user\Desktop\wnGDKyXdAo.exe |
Code function: 0_2_00007FF6B9CCB59C |
0_2_00007FF6B9CCB59C |
Source: C:\Users\user\Desktop\wnGDKyXdAo.exe |
Code function: 0_2_00007FF6B9CD48FC |
0_2_00007FF6B9CD48FC |
Source: C:\Users\user\Desktop\wnGDKyXdAo.exe |
Code function: 0_2_00007FF6B9CDF8F8 |
0_2_00007FF6B9CDF8F8 |
Source: C:\Users\user\Desktop\wnGDKyXdAo.exe |
Code function: 0_2_00007FF6B9C947B0 |
0_2_00007FF6B9C947B0 |
Source: C:\Users\user\Desktop\wnGDKyXdAo.exe |
Code function: 0_2_00007FF6B9C8A740 |
0_2_00007FF6B9C8A740 |
Source: C:\Users\user\Desktop\wnGDKyXdAo.exe |
Code function: 0_2_00007FF6B9CBE764 |
0_2_00007FF6B9CBE764 |
Source: C:\Users\user\Desktop\wnGDKyXdAo.exe |
Code function: String function: 00007FF6B9CA4AE0 appears 36 times |
|
Source: C:\Users\user\Desktop\wnGDKyXdAo.exe |
Code function: String function: 00007FF6B9CAC040 appears 144 times |
|
Source: C:\Users\user\Desktop\wnGDKyXdAo.exe |
Code function: String function: 00007FF6B9CB0700 appears 63 times |
|
Source: classification engine |
Classification label: mal48.winEXE@2/1@0/0 |
Source: C:\Windows\System32\conhost.exe |
Mutant created: \Sessions\1\BaseNamedObjects\Local\SM0:2872:120:WilError_03 |
Source: wnGDKyXdAo.exe |
Static PE information: Section: .text IMAGE_SCN_CNT_CODE, IMAGE_SCN_MEM_EXECUTE, IMAGE_SCN_MEM_READ |
Source: C:\Users\user\Desktop\wnGDKyXdAo.exe |
Key opened: HKEY_LOCAL_MACHINE\Software\Policies\Microsoft\Windows\Safer\CodeIdentifiers |
Jump to behavior |
Source: C:\Users\user\Desktop\wnGDKyXdAo.exe |
File read: C:\Users\user\Desktop\wnGDKyXdAo.exe |
Jump to behavior |
Source: unknown |
Process created: C:\Users\user\Desktop\wnGDKyXdAo.exe "C:\Users\user\Desktop\wnGDKyXdAo.exe" |
Source: C:\Users\user\Desktop\wnGDKyXdAo.exe |
Process created: C:\Windows\System32\conhost.exe C:\Windows\system32\conhost.exe 0xffffffff -ForceV1 |
Source: C:\Users\user\Desktop\wnGDKyXdAo.exe |
Section loaded: apphelp.dll |
Jump to behavior |
Source: C:\Users\user\Desktop\wnGDKyXdAo.exe |
Section loaded: iphlpapi.dll |
Jump to behavior |
Source: C:\Users\user\Desktop\wnGDKyXdAo.exe |
Section loaded: wininet.dll |
Jump to behavior |
Source: wnGDKyXdAo.exe |
Static PE information: Image base 0x140000000 > 0x60000000 |
Source: wnGDKyXdAo.exe |
Static PE information: HIGH_ENTROPY_VA, DYNAMIC_BASE, NX_COMPAT, TERMINAL_SERVER_AWARE |
Source: wnGDKyXdAo.exe |
Static PE information: Data directory: IMAGE_DIRECTORY_ENTRY_IMPORT is in: .rdata |
Source: wnGDKyXdAo.exe |
Static PE information: Data directory: IMAGE_DIRECTORY_ENTRY_RESOURCE is in: .rsrc |
Source: wnGDKyXdAo.exe |
Static PE information: Data directory: IMAGE_DIRECTORY_ENTRY_BASERELOC is in: .reloc |
Source: wnGDKyXdAo.exe |
Static PE information: Data directory: IMAGE_DIRECTORY_ENTRY_LOAD_CONFIG is in: .rdata |
Source: wnGDKyXdAo.exe |
Static PE information: Data directory: IMAGE_DIRECTORY_ENTRY_IAT is in: .rdata |
Source: C:\Users\user\Desktop\wnGDKyXdAo.exe |
Code function: 0_2_00007FF6B9CD227C EncodePointer,__crtIsPackagedApp,LoadLibraryExW,GetLastError,LoadLibraryW,GetProcAddress,EncodePointer,GetProcAddress,EncodePointer,GetProcAddress,EncodePointer,GetProcAddress,EncodePointer,GetProcAddress,EncodePointer,IsDebuggerPresent,OutputDebugStringW,DecodePointer,DecodePointer,DecodePointer,DecodePointer,DecodePointer,DecodePointer, |
0_2_00007FF6B9CD227C |
Source: C:\Users\user\Desktop\wnGDKyXdAo.exe |
Code function: 0_2_00007FF6B9CDCB44 GetModuleHandleW,GetProcAddress,GetModuleHandleW,GetProcAddress,GetModuleHandleW,GetProcAddress,GetModuleHandleW,GetProcAddress,GetModuleHandleW,GetProcAddress,GetModuleHandleW,GetProcAddress,GetModuleHandleW,GetProcAddress,GetModuleHandleW,GetProcAddress,GetModuleHandleW,GetProcAddress,GetModuleHandleW,GetProcAddress,GetModuleHandleW,GetProcAddress,GetModuleHandleW,GetProcAddress,GetModuleHandleW,GetProcAddress,GetModuleHandleW,GetProcAddress,GetModuleHandleW,GetProcAddress,GetModuleHandleW,GetProcAddress,GetModuleHandleW,GetProcAddress,GetLastError,Concurrency::scheduler_resource_allocation_error::scheduler_resource_allocation_error,_CxxThrowException,GetLastError,Concurrency::scheduler_resource_allocation_error::scheduler_resource_allocation_error,_CxxThrowException,GetLastError,Concurrency::scheduler_resource_allocation_error::scheduler_resource_allocation_error,_CxxThrowException,GetLastError,Concurrency::scheduler_resource_allocation_error::scheduler_resource_allocation_error,_CxxThrowException,GetLastError,Concurrency::scheduler_resource_allocation_error::scheduler_resource_allocation_error,_CxxThrowException,GetLastError,Concurrency::scheduler_resource_allocation_error::scheduler_resource_allocation_error,_CxxThrowException,GetLastError,Concurrency::scheduler_resource_allocation_error::scheduler_resource_allocation_error,_CxxThrowException,GetLastError,Concurrency::scheduler_resource_allocation_error::scheduler_resource_allocation_error,_CxxThrowException,GetLastError,Concurrency::scheduler_resource_allocation_error::scheduler_resource_allocation_error,_CxxThrowException,GetLastError,Concurrency::scheduler_resource_allocation_error::scheduler_resource_allocation_error,_CxxThrowException,GetLastError,Concurrency::scheduler_resource_allocation_error::scheduler_resource_allocation_error,_CxxThrowException,GetLastError,Concurrency::scheduler_resource_allocation_error::scheduler_resource_allocation_error,_CxxThrowException,GetLastError,Concurrency::scheduler_resource_allocation_error::scheduler_resource_allocation_error,_CxxThrowException,GetLastError,Concurrency::scheduler_resource_allocation_error::scheduler_resource_allocation_error,_CxxThrowException,GetLastError,Concurrency::scheduler_resource_allocation_error::scheduler_resource_allocation_error,_CxxThrowException,GetLastError,Concurrency::scheduler_resource_allocation_error::scheduler_resource_allocation_error,_CxxThrowExcepti |