Click to jump to signature section
Source: wnGDKyXdAo.exe | Static PE information: HIGH_ENTROPY_VA, DYNAMIC_BASE, NX_COMPAT, TERMINAL_SERVER_AWARE |
Source: wnGDKyXdAo.exe | String found in binary or memory: https://http://Mozilla/5.0 |
Source: C:\Users\user\Desktop\wnGDKyXdAo.exe | Code function: 0_2_00007FF6B9CCDA9C | 0_2_00007FF6B9CCDA9C |
Source: C:\Users\user\Desktop\wnGDKyXdAo.exe | Code function: 0_2_00007FF6B9C9E053 | 0_2_00007FF6B9C9E053 |
Source: C:\Users\user\Desktop\wnGDKyXdAo.exe | Code function: 0_2_00007FF6B9CC2020 | 0_2_00007FF6B9CC2020 |
Source: C:\Users\user\Desktop\wnGDKyXdAo.exe | Code function: 0_2_00007FF6B9CD6F64 | 0_2_00007FF6B9CD6F64 |
Source: C:\Users\user\Desktop\wnGDKyXdAo.exe | Code function: 0_2_00007FF6B9CC2644 | 0_2_00007FF6B9CC2644 |
Source: C:\Users\user\Desktop\wnGDKyXdAo.exe | Code function: 0_2_00007FF6B9C91A00 | 0_2_00007FF6B9C91A00 |
Source: C:\Users\user\Desktop\wnGDKyXdAo.exe | Code function: 0_2_00007FF6B9C839F0 | 0_2_00007FF6B9C839F0 |
Source: C:\Users\user\Desktop\wnGDKyXdAo.exe | Code function: 0_2_00007FF6B9CE5CC8 | 0_2_00007FF6B9CE5CC8 |
Source: C:\Users\user\Desktop\wnGDKyXdAo.exe | Code function: 0_2_00007FF6B9CBDBB4 | 0_2_00007FF6B9CBDBB4 |
Source: C:\Users\user\Desktop\wnGDKyXdAo.exe | Code function: 0_2_00007FF6B9C9FB3E | 0_2_00007FF6B9C9FB3E |
Source: C:\Users\user\Desktop\wnGDKyXdAo.exe | Code function: 0_2_00007FF6B9C9CB40 | 0_2_00007FF6B9C9CB40 |
Source: C:\Users\user\Desktop\wnGDKyXdAo.exe | Code function: 0_2_00007FF6B9CB1B38 | 0_2_00007FF6B9CB1B38 |
Source: C:\Users\user\Desktop\wnGDKyXdAo.exe | Code function: 0_2_00007FF6B9C8CB60 | 0_2_00007FF6B9C8CB60 |
Source: C:\Users\user\Desktop\wnGDKyXdAo.exe | Code function: 0_2_00007FF6B9C96F32 | 0_2_00007FF6B9C96F32 |
Source: C:\Users\user\Desktop\wnGDKyXdAo.exe | Code function: 0_2_00007FF6B9CCCE74 | 0_2_00007FF6B9CCCE74 |
Source: C:\Users\user\Desktop\wnGDKyXdAo.exe | Code function: 0_2_00007FF6B9C9BE20 | 0_2_00007FF6B9C9BE20 |
Source: C:\Users\user\Desktop\wnGDKyXdAo.exe | Code function: 0_2_00007FF6B9C88DD0 | 0_2_00007FF6B9C88DD0 |
Source: C:\Users\user\Desktop\wnGDKyXdAo.exe | Code function: 0_2_00007FF6B9CB1DC4 | 0_2_00007FF6B9CB1DC4 |
Source: C:\Users\user\Desktop\wnGDKyXdAo.exe | Code function: 0_2_00007FF6B9CB5124 | 0_2_00007FF6B9CB5124 |
Source: C:\Users\user\Desktop\wnGDKyXdAo.exe | Code function: 0_2_00007FF6B9C95050 | 0_2_00007FF6B9C95050 |
Source: C:\Users\user\Desktop\wnGDKyXdAo.exe | Code function: 0_2_00007FF6B9CC0010 | 0_2_00007FF6B9CC0010 |
Source: C:\Users\user\Desktop\wnGDKyXdAo.exe | Code function: 0_2_00007FF6B9CE1FE4 | 0_2_00007FF6B9CE1FE4 |
Source: C:\Users\user\Desktop\wnGDKyXdAo.exe | Code function: 0_2_00007FF6B9CC0FB0 | 0_2_00007FF6B9CC0FB0 |
Source: C:\Users\user\Desktop\wnGDKyXdAo.exe | Code function: 0_2_00007FF6B9CB8F9C | 0_2_00007FF6B9CB8F9C |
Source: C:\Users\user\Desktop\wnGDKyXdAo.exe | Code function: 0_2_00007FF6B9C85F70 | 0_2_00007FF6B9C85F70 |
Source: C:\Users\user\Desktop\wnGDKyXdAo.exe | Code function: 0_2_00007FF6B9CC52FC | 0_2_00007FF6B9CC52FC |
Source: C:\Users\user\Desktop\wnGDKyXdAo.exe | Code function: 0_2_00007FF6B9CD42D8 | 0_2_00007FF6B9CD42D8 |
Source: C:\Users\user\Desktop\wnGDKyXdAo.exe | Code function: 0_2_00007FF6B9C9F298 | 0_2_00007FF6B9C9F298 |
Source: C:\Users\user\Desktop\wnGDKyXdAo.exe | Code function: 0_2_00007FF6B9CC1248 | 0_2_00007FF6B9CC1248 |
Source: C:\Users\user\Desktop\wnGDKyXdAo.exe | Code function: 0_2_00007FF6B9C85190 | 0_2_00007FF6B9C85190 |
Source: C:\Users\user\Desktop\wnGDKyXdAo.exe | Code function: 0_2_00007FF6B9C94160 | 0_2_00007FF6B9C94160 |
Source: C:\Users\user\Desktop\wnGDKyXdAo.exe | Code function: 0_2_00007FF6B9C92500 | 0_2_00007FF6B9C92500 |
Source: C:\Users\user\Desktop\wnGDKyXdAo.exe | Code function: 0_2_00007FF6B9C8E480 | 0_2_00007FF6B9C8E480 |
Source: C:\Users\user\Desktop\wnGDKyXdAo.exe | Code function: 0_2_00007FF6B9C854A0 | 0_2_00007FF6B9C854A0 |
Source: C:\Users\user\Desktop\wnGDKyXdAo.exe | Code function: 0_2_00007FF6B9CD1450 | 0_2_00007FF6B9CD1450 |
Source: C:\Users\user\Desktop\wnGDKyXdAo.exe | Code function: 0_2_00007FF6B9C93470 | 0_2_00007FF6B9C93470 |
Source: C:\Users\user\Desktop\wnGDKyXdAo.exe | Code function: 0_2_00007FF6B9CE5474 | 0_2_00007FF6B9CE5474 |
Source: C:\Users\user\Desktop\wnGDKyXdAo.exe | Code function: 0_2_00007FF6B9C87360 | 0_2_00007FF6B9C87360 |
Source: C:\Users\user\Desktop\wnGDKyXdAo.exe | Code function: 0_2_00007FF6B9CC56AC | 0_2_00007FF6B9CC56AC |
Source: C:\Users\user\Desktop\wnGDKyXdAo.exe | Code function: 0_2_00007FF6B9CEB698 | 0_2_00007FF6B9CEB698 |
Source: C:\Users\user\Desktop\wnGDKyXdAo.exe | Code function: 0_2_00007FF6B9C965D0 | 0_2_00007FF6B9C965D0 |
Source: C:\Users\user\Desktop\wnGDKyXdAo.exe | Code function: 0_2_00007FF6B9C9A594 | 0_2_00007FF6B9C9A594 |
Source: C:\Users\user\Desktop\wnGDKyXdAo.exe | Code function: 0_2_00007FF6B9C86590 | 0_2_00007FF6B9C86590 |
Source: C:\Users\user\Desktop\wnGDKyXdAo.exe | Code function: 0_2_00007FF6B9CCB59C | 0_2_00007FF6B9CCB59C |
Source: C:\Users\user\Desktop\wnGDKyXdAo.exe | Code function: 0_2_00007FF6B9CD48FC | 0_2_00007FF6B9CD48FC |
Source: C:\Users\user\Desktop\wnGDKyXdAo.exe | Code function: 0_2_00007FF6B9CDF8F8 | 0_2_00007FF6B9CDF8F8 |
Source: C:\Users\user\Desktop\wnGDKyXdAo.exe | Code function: 0_2_00007FF6B9C947B0 | 0_2_00007FF6B9C947B0 |
Source: C:\Users\user\Desktop\wnGDKyXdAo.exe | Code function: 0_2_00007FF6B9C8A740 | 0_2_00007FF6B9C8A740 |
Source: C:\Users\user\Desktop\wnGDKyXdAo.exe | Code function: 0_2_00007FF6B9CBE764 | 0_2_00007FF6B9CBE764 |
Source: C:\Users\user\Desktop\wnGDKyXdAo.exe | Code function: String function: 00007FF6B9CA4AE0 appears 36 times | |
Source: C:\Users\user\Desktop\wnGDKyXdAo.exe | Code function: String function: 00007FF6B9CAC040 appears 144 times | |
Source: C:\Users\user\Desktop\wnGDKyXdAo.exe | Code function: String function: 00007FF6B9CB0700 appears 63 times | |
Source: classification engine | Classification label: mal48.winEXE@2/1@0/0 |
Source: C:\Windows\System32\conhost.exe | Mutant created: \Sessions\1\BaseNamedObjects\Local\SM0:2872:120:WilError_03 |
Source: wnGDKyXdAo.exe | Static PE information: Section: .text IMAGE_SCN_CNT_CODE, IMAGE_SCN_MEM_EXECUTE, IMAGE_SCN_MEM_READ |
Source: C:\Users\user\Desktop\wnGDKyXdAo.exe | Key opened: HKEY_LOCAL_MACHINE\Software\Policies\Microsoft\Windows\Safer\CodeIdentifiers | Jump to behavior |
Source: C:\Users\user\Desktop\wnGDKyXdAo.exe | File read: C:\Users\user\Desktop\wnGDKyXdAo.exe | Jump to behavior |
Source: unknown | Process created: C:\Users\user\Desktop\wnGDKyXdAo.exe "C:\Users\user\Desktop\wnGDKyXdAo.exe" |
Source: C:\Users\user\Desktop\wnGDKyXdAo.exe | Process created: C:\Windows\System32\conhost.exe C:\Windows\system32\conhost.exe 0xffffffff -ForceV1 |
Source: C:\Users\user\Desktop\wnGDKyXdAo.exe | Section loaded: apphelp.dll | Jump to behavior |
Source: C:\Users\user\Desktop\wnGDKyXdAo.exe | Section loaded: iphlpapi.dll | Jump to behavior |
Source: C:\Users\user\Desktop\wnGDKyXdAo.exe | Section loaded: wininet.dll | Jump to behavior |
Source: wnGDKyXdAo.exe | Static PE information: Image base 0x140000000 > 0x60000000 |
Source: wnGDKyXdAo.exe | Static PE information: HIGH_ENTROPY_VA, DYNAMIC_BASE, NX_COMPAT, TERMINAL_SERVER_AWARE |
Source: wnGDKyXdAo.exe | Static PE information: Data directory: IMAGE_DIRECTORY_ENTRY_IMPORT is in: .rdata |
Source: wnGDKyXdAo.exe | Static PE information: Data directory: IMAGE_DIRECTORY_ENTRY_RESOURCE is in: .rsrc |
Source: wnGDKyXdAo.exe | Static PE information: Data directory: IMAGE_DIRECTORY_ENTRY_BASERELOC is in: .reloc |
Source: wnGDKyXdAo.exe | Static PE information: Data directory: IMAGE_DIRECTORY_ENTRY_LOAD_CONFIG is in: .rdata |
Source: wnGDKyXdAo.exe | Static PE information: Data directory: IMAGE_DIRECTORY_ENTRY_IAT is in: .rdata |
Source: C:\Users\user\Desktop\wnGDKyXdAo.exe | Code function: 0_2_00007FF6B9CD227C EncodePointer,__crtIsPackagedApp,LoadLibraryExW,GetLastError,LoadLibraryW,GetProcAddress,EncodePointer,GetProcAddress,EncodePointer,GetProcAddress,EncodePointer,GetProcAddress,EncodePointer,GetProcAddress,EncodePointer,IsDebuggerPresent,OutputDebugStringW,DecodePointer,DecodePointer,DecodePointer,DecodePointer,DecodePointer,DecodePointer, | 0_2_00007FF6B9CD227C |
Source: C:\Users\user\Desktop\wnGDKyXdAo.exe | Code function: 0_2_00007FF6B9CDCB44 GetModuleHandleW,GetProcAddress,GetModuleHandleW,GetProcAddress,GetModuleHandleW,GetProcAddress,GetModuleHandleW,GetProcAddress,GetModuleHandleW,GetProcAddress,GetModuleHandleW,GetProcAddress,GetModuleHandleW,GetProcAddress,GetModuleHandleW,GetProcAddress,GetModuleHandleW,GetProcAddress,GetModuleHandleW,GetProcAddress,GetModuleHandleW,GetProcAddress,GetModuleHandleW,GetProcAddress,GetModuleHandleW,GetProcAddress,GetModuleHandleW,GetProcAddress,GetModuleHandleW,GetProcAddress,GetModuleHandleW,GetProcAddress,GetModuleHandleW,GetProcAddress,GetLastError,Concurrency::scheduler_resource_allocation_error::scheduler_resource_allocation_error,_CxxThrowException,GetLastError,Concurrency::scheduler_resource_allocation_error::scheduler_resource_allocation_error,_CxxThrowException,GetLastError,Concurrency::scheduler_resource_allocation_error::scheduler_resource_allocation_error,_CxxThrowException,GetLastError,Concurrency::scheduler_resource_allocation_error::scheduler_resource_allocation_error,_CxxThrowException,GetLastError,Concurrency::scheduler_resource_allocation_error::scheduler_resource_allocation_error,_CxxThrowException,GetLastError,Concurrency::scheduler_resource_allocation_error::scheduler_resource_allocation_error,_CxxThrowException,GetLastError,Concurrency::scheduler_resource_allocation_error::scheduler_resource_allocation_error,_CxxThrowException,GetLastError,Concurrency::scheduler_resource_allocation_error::scheduler_resource_allocation_error,_CxxThrowException,GetLastError,Concurrency::scheduler_resource_allocation_error::scheduler_resource_allocation_error,_CxxThrowException,GetLastError,Concurrency::scheduler_resource_allocation_error::scheduler_resource_allocation_error,_CxxThrowException,GetLastError,Concurrency::scheduler_resource_allocation_error::scheduler_resource_allocation_error,_CxxThrowException,GetLastError,Concurrency::scheduler_resource_allocation_error::scheduler_resource_allocation_error,_CxxThrowException,GetLastError,Concurrency::scheduler_resource_allocation_error::scheduler_resource_allocation_error,_CxxThrowException,GetLastError,Concurrency::scheduler_resource_allocation_error::scheduler_resource_allocation_error,_CxxThrowException,GetLastError,Concurrency::scheduler_resource_allocation_error::scheduler_resource_allocation_error,_CxxThrowException,GetLastError,Concurrency::scheduler_resource_allocation_error::scheduler_resource_allocation_error,_CxxThrowException,GetLastError,Conc |