Windows Analysis Report
macrox!.exe

Overview

General Information

Sample name: macrox!.exe
Analysis ID: 1541136
MD5: 764187e5f44212696bd5f8ff204c2b48
SHA1: df944305847ad3109088817d9531593593a544f5
SHA256: d1b28fdfdf1c3b23f39dd770e04783a9403e8b7916695ea526cad311e0934aa6
Infos:

Detection

Score: 36
Range: 0 - 100
Whitelisted: false
Confidence: 20%

Signatures

Machine Learning detection for dropped file
Sets file extension default program settings to executables
Creates Visual Basic Runtime Dlls
Creates files inside the system directory
Drops PE files
Drops PE files to the windows directory (C:\Windows)
Found a high number of Window / User specific system calls (may be a loop to detect user behavior)
Found dropped PE file which has not been started or loaded
Modifies existing windows services
PE file contains sections with non-standard names
Queries the volume information (name, serial number etc) of a device
Sample file is different than original file name gathered from version info
Stores files to the Windows start menu directory
Uses 32bit PE files

Classification

AV Detection

barindex
Source: C:\Program Files (x86)\MacroX\sys\mcxexe.dll Joe Sandbox ML: detected
Source: macrox!.exe Static PE information: RELOCS_STRIPPED, EXECUTABLE_IMAGE, LINE_NUMS_STRIPPED, LOCAL_SYMS_STRIPPED, 32BIT_MACHINE
Source: Binary string: E:\VC-Projekte\x86.binz\dskeybrd.pdb source: macrox!.exe, 00000000.00000002.2926507817.00000000025E4000.00000004.00000020.00020000.00000000.sdmp, nsa434D.tmp.0.dr, mcxkeyboardhook.dll.0.dr
Source: Binary string: msscript.pdb source: macrox!.exe, 00000000.00000002.2926137934.0000000000409000.00000004.00000001.01000000.00000003.sdmp, macrox!.exe, 00000000.00000002.2926507817.0000000002808000.00000004.00000020.00020000.00000000.sdmp, nsa434D.tmp.0.dr
Source: Binary string: E:\VC-Projekte\x86.binz\dskeybrd.pdb MZ source: macrox!.exe, 00000000.00000002.2926507817.00000000025E4000.00000004.00000020.00020000.00000000.sdmp, nsa434D.tmp.0.dr
Source: Binary string: E:\VC-Projekte\x86.binz\dsmouse.pdbXp source: macrox!.exe, 00000000.00000002.2926507817.00000000025E4000.00000004.00000020.00020000.00000000.sdmp, nsa434D.tmp.0.dr
Source: Binary string: E:\VC-Projekte\x86.binz\dsmouse.pdb source: macrox!.exe, 00000000.00000002.2926507817.00000000025E4000.00000004.00000020.00020000.00000000.sdmp, nsa434D.tmp.0.dr, mcxmousehook.dll.0.dr
Source: C:\Users\user\Desktop\macrox!.exe File opened: C:\Users\user\AppData\Roaming Jump to behavior
Source: C:\Users\user\Desktop\macrox!.exe File opened: C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\desktop.ini Jump to behavior
Source: C:\Users\user\Desktop\macrox!.exe File opened: C:\Users\user Jump to behavior
Source: C:\Users\user\Desktop\macrox!.exe File opened: C:\Users\user\AppData\Roaming\Microsoft Jump to behavior
Source: C:\Users\user\Desktop\macrox!.exe File opened: C:\Users\user\AppData Jump to behavior
Source: C:\Users\user\Desktop\macrox!.exe File opened: C:\Users\user\AppData\Roaming\Microsoft\Windows Jump to behavior
Source: macrox!.exe, 00000000.00000002.2926507817.000000000222F000.00000004.00000020.00020000.00000000.sdmp, nsa434D.tmp.0.dr, MACROX.EXE.0.dr String found in binary or memory: http://bug.macrox.dezu
Source: macrox!.exe, 00000000.00000002.2926507817.000000000222F000.00000004.00000020.00020000.00000000.sdmp, nsa434D.tmp.0.dr, MACROX.EXE.0.dr String found in binary or memory: http://squeakmac.tripod.comU
Source: nsa434D.tmp.0.dr, MacroX.url.0.dr String found in binary or memory: http://www.MacroX.de
Source: macrox!.exe, 00000000.00000002.2926255771.0000000000796000.00000004.00000020.00020000.00000000.sdmp String found in binary or memory: http://www.MacroX.de)
Source: macrox!.exe, 00000000.00000002.2926507817.000000000222F000.00000004.00000020.00020000.00000000.sdmp, nsa434D.tmp.0.dr, MACROX.EXE.0.dr String found in binary or memory: http://www.macrox.de
Source: macrox!.exe, 00000000.00000002.2926507817.000000000222F000.00000004.00000020.00020000.00000000.sdmp, nsa434D.tmp.0.dr, MACROX.EXE.0.dr String found in binary or memory: http://www.macrox.deEditClicked
Source: macrox!.exe, 00000000.00000002.2926507817.000000000222F000.00000004.00000020.00020000.00000000.sdmp, nsa434D.tmp.0.dr, MACROX.EXE.0.dr String found in binary or memory: http://www.millsoft.de9O
Source: MACROX.EXE.0.dr String found in binary or memory: http://www.softwareedition.de/macrox
Source: macrox!.exe, 00000000.00000002.2926507817.000000000222F000.00000004.00000020.00020000.00000000.sdmp, nsa434D.tmp.0.dr, MACROX.EXE.0.dr String found in binary or memory: http://www.softwareedition.de/macrox/Align2p
Source: macrox!.exe, 00000000.00000002.2926507817.000000000222F000.00000004.00000020.00020000.00000000.sdmp, macrox!.exe, 00000000.00000002.2926507817.00000000023B5000.00000004.00000020.00020000.00000000.sdmp, nsa434D.tmp.0.dr, CMAX20.OCX.0.dr String found in binary or memory: http://www.winmain.com
Source: macrox!.exe, 00000000.00000002.2926507817.00000000023B5000.00000004.00000020.00020000.00000000.sdmp, nsa434D.tmp.0.dr, CMAX20.OCX.0.dr String found in binary or memory: http://www.winmain.com)6
Source: macrox!.exe, 00000000.00000002.2926507817.000000000222F000.00000004.00000020.00020000.00000000.sdmp, nsa434D.tmp.0.dr, CMAX20.OCX.0.dr String found in binary or memory: http://www.winmain.comSDBValForceRemoveNoRemoveDeleteCLSIDTYPELIBSDBValForceRemoveNoRemoveDeleteCLSI
Source: C:\Users\user\Desktop\macrox!.exe File created: C:\Windows\SysWOW64\Mswinsck.ocx Jump to behavior
Source: C:\Users\user\Desktop\macrox!.exe File created: C:\Windows\SysWOW64\mcxkeyboardhook.dll Jump to behavior
Source: C:\Users\user\Desktop\macrox!.exe File created: C:\Windows\SysWOW64\mcxmousehook.dll Jump to behavior
Source: C:\Users\user\Desktop\macrox!.exe File created: C:\Windows\SysWOW64\MSCOMCTL.OCX Jump to behavior
Source: C:\Users\user\Desktop\macrox!.exe File created: C:\Windows\SysWOW64\SSUBTMR6.DLL Jump to behavior
Source: C:\Users\user\Desktop\macrox!.exe File created: C:\Windows\SysWOW64\Mswinsck.ocx Jump to behavior
Source: macrox!.exe, 00000000.00000002.2926507817.0000000002400000.00000004.00000020.00020000.00000000.sdmp Binary or memory string: OriginalFilenameHookMenu.ocx, vs macrox!.exe
Source: macrox!.exe, 00000000.00000002.2926507817.0000000002400000.00000004.00000020.00020000.00000000.sdmp Binary or memory string: OriginalFilenamemacroxrecord.dll, vs macrox!.exe
Source: macrox!.exe, 00000000.00000002.2926507817.0000000002400000.00000004.00000020.00020000.00000000.sdmp Binary or memory string: OriginalFilenamemacroxsettings.dll, vs macrox!.exe
Source: macrox!.exe, 00000000.00000002.2926507817.0000000002400000.00000004.00000020.00020000.00000000.sdmp Binary or memory string: OriginalFilenamemc vs macrox!.exe
Source: macrox!.exe, 00000000.00000002.2926507817.0000000002400000.00000004.00000020.00020000.00000000.sdmp Binary or memory string: OriginalFilenamemcx3.dll, vs macrox!.exe
Source: macrox!.exe, 00000000.00000002.2926507817.0000000002400000.00000004.00000020.00020000.00000000.sdmp Binary or memory string: OriginalFilenamemcxexe.exe vs macrox!.exe
Source: macrox!.exe, 00000000.00000002.2926507817.0000000002400000.00000004.00000020.00020000.00000000.sdmp Binary or memory string: OriginalFilenamemcxKernel.dll, vs macrox!.exe
Source: macrox!.exe, 00000000.00000002.2926507817.0000000002400000.00000004.00000020.00020000.00000000.sdmp Binary or memory string: OriginalFilenamemcxLanguage.dll, vs macrox!.exe
Source: macrox!.exe, 00000000.00000002.2926507817.0000000002400000.00000004.00000020.00020000.00000000.sdmp Binary or memory string: OriginalFilenamemcxnetbar.ocx, vs macrox!.exe
Source: macrox!.exe, 00000000.00000002.2926507817.0000000002400000.00000004.00000020.00020000.00000000.sdmp Binary or memory string: OriginalFilenamemcxRun.exe vs macrox!.exe
Source: macrox!.exe, 00000000.00000002.2926507817.0000000002400000.00000004.00000020.00020000.00000000.sdmp Binary or memory string: OriginalFilenamemcxtabx.ocx, vs macrox!.exe
Source: macrox!.exe, 00000000.00000002.2926507817.0000000002400000.00000004.00000020.00020000.00000000.sdmp Binary or memory string: OriginalFilenamevbalIml6.ocx, vs macrox!.exe
Source: macrox!.exe, 00000000.00000002.2926507817.0000000002400000.00000004.00000020.00020000.00000000.sdmp Binary or memory string: OriginalFilenamemcxinternet.dll, vs macrox!.exe
Source: macrox!.exe, 00000000.00000002.2926507817.00000000025CC000.00000004.00000020.00020000.00000000.sdmp Binary or memory string: OriginalFilenamemcxregistry.dll, vs macrox!.exe
Source: macrox!.exe, 00000000.00000002.2926507817.00000000025CC000.00000004.00000020.00020000.00000000.sdmp Binary or memory string: OriginalFilenameRedirect.DLL vs macrox!.exe
Source: macrox!.exe, 00000000.00000002.2926507817.000000000222F000.00000004.00000020.00020000.00000000.sdmp Binary or memory string: OriginalFilenameMacroX.exe vs macrox!.exe
Source: macrox!.exe, 00000000.00000002.2926507817.0000000002808000.00000004.00000020.00020000.00000000.sdmp Binary or memory string: OriginalFilenamemsscript.dllZ vs macrox!.exe
Source: macrox!.exe, 00000000.00000002.2926507817.00000000026F9000.00000004.00000020.00020000.00000000.sdmp Binary or memory string: OriginalFilenameSSubTmr6.dll, vs macrox!.exe
Source: macrox!.exe, 00000000.00000002.2926507817.000000000269B000.00000004.00000020.00020000.00000000.sdmp Binary or memory string: OriginalFilenameMSCOMCTL.OCX2 vs macrox!.exe
Source: macrox!.exe, 00000000.00000002.2926507817.00000000023B5000.00000004.00000020.00020000.00000000.sdmp Binary or memory string: OriginalFilenameCMAX20.OCX0 vs macrox!.exe
Source: macrox!.exe, 00000000.00000002.2926507817.00000000025E4000.00000004.00000020.00020000.00000000.sdmp Binary or memory string: OriginalFilenamemcxruntag.dll, vs macrox!.exe
Source: macrox!.exe, 00000000.00000002.2926507817.00000000025E4000.00000004.00000020.00020000.00000000.sdmp Binary or memory string: OriginalFilenamedskeybrd.dll vs macrox!.exe
Source: macrox!.exe, 00000000.00000002.2926507817.00000000025E4000.00000004.00000020.00020000.00000000.sdmp Binary or memory string: OriginalFilenamedsmouse.dllR vs macrox!.exe
Source: macrox!.exe Static PE information: RELOCS_STRIPPED, EXECUTABLE_IMAGE, LINE_NUMS_STRIPPED, LOCAL_SYMS_STRIPPED, 32BIT_MACHINE
Source: macrox!.exe, 00000000.00000002.2926507817.0000000002400000.00000004.00000020.00020000.00000000.sdmp, nsa434D.tmp.0.dr, vbalIml6.ocx.0.dr Binary or memory string: F*\AC:\SteveMac\VB6\Controls\ImgList6\vbalIml6.vbp
Source: macrox!.exe, 00000000.00000002.2926507817.000000000269B000.00000004.00000020.00020000.00000000.sdmp, nsa434D.tmp.0.dr, SSUBTMR6.DLL.0.dr Binary or memory string: .*\AC:\Program Files\Microsoft Visual Studio\3RD PARTY\vbAccel\SSubTmr\SubTimer6.vbp
Source: classification engine Classification label: sus36.winEXE@1/62@0/0
Source: C:\Users\user\Desktop\macrox!.exe File created: C:\Program Files (x86)\MacroX Jump to behavior
Source: C:\Users\user\Desktop\macrox!.exe File created: C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\MacroX Jump to behavior
Source: C:\Users\user\Desktop\macrox!.exe Mutant created: NULL
Source: C:\Users\user\Desktop\macrox!.exe File created: C:\Users\user\AppData\Local\Temp\nsa434C.tmp Jump to behavior
Source: macrox!.exe Static PE information: Section: .text IMAGE_SCN_CNT_CODE, IMAGE_SCN_MEM_EXECUTE, IMAGE_SCN_MEM_READ
Source: C:\Users\user\Desktop\macrox!.exe File read: C:\Users\user\AppData\Local\Temp\nsv437D.tmp\ioSpecial.ini Jump to behavior
Source: C:\Users\user\Desktop\macrox!.exe Key opened: HKEY_CURRENT_USER\Software\Policies\Microsoft\Windows\Safer\CodeIdentifiers Jump to behavior
Source: C:\Users\user\Desktop\macrox!.exe File read: C:\Users\user\Desktop\macrox!.exe Jump to behavior
Source: C:\Users\user\Desktop\macrox!.exe Section loaded: apphelp.dll Jump to behavior
Source: C:\Users\user\Desktop\macrox!.exe Section loaded: acgenral.dll Jump to behavior
Source: C:\Users\user\Desktop\macrox!.exe Section loaded: uxtheme.dll Jump to behavior
Source: C:\Users\user\Desktop\macrox!.exe Section loaded: winmm.dll Jump to behavior
Source: C:\Users\user\Desktop\macrox!.exe Section loaded: samcli.dll Jump to behavior
Source: C:\Users\user\Desktop\macrox!.exe Section loaded: msacm32.dll Jump to behavior
Source: C:\Users\user\Desktop\macrox!.exe Section loaded: version.dll Jump to behavior
Source: C:\Users\user\Desktop\macrox!.exe Section loaded: userenv.dll Jump to behavior
Source: C:\Users\user\Desktop\macrox!.exe Section loaded: dwmapi.dll Jump to behavior
Source: C:\Users\user\Desktop\macrox!.exe Section loaded: urlmon.dll Jump to behavior
Source: C:\Users\user\Desktop\macrox!.exe Section loaded: mpr.dll Jump to behavior
Source: C:\Users\user\Desktop\macrox!.exe Section loaded: sspicli.dll Jump to behavior
Source: C:\Users\user\Desktop\macrox!.exe Section loaded: winmmbase.dll Jump to behavior
Source: C:\Users\user\Desktop\macrox!.exe Section loaded: winmmbase.dll Jump to behavior
Source: C:\Users\user\Desktop\macrox!.exe Section loaded: iertutil.dll Jump to behavior
Source: C:\Users\user\Desktop\macrox!.exe Section loaded: srvcli.dll Jump to behavior
Source: C:\Users\user\Desktop\macrox!.exe Section loaded: netutils.dll Jump to behavior
Source: C:\Users\user\Desktop\macrox!.exe Section loaded: aclayers.dll Jump to behavior
Source: C:\Users\user\Desktop\macrox!.exe Section loaded: sfc.dll Jump to behavior
Source: C:\Users\user\Desktop\macrox!.exe Section loaded: sfc_os.dll Jump to behavior
Source: C:\Users\user\Desktop\macrox!.exe Section loaded: kernel.appcore.dll Jump to behavior
Source: C:\Users\user\Desktop\macrox!.exe Section loaded: riched20.dll Jump to behavior
Source: C:\Users\user\Desktop\macrox!.exe Section loaded: usp10.dll Jump to behavior
Source: C:\Users\user\Desktop\macrox!.exe Section loaded: msls31.dll Jump to behavior
Source: C:\Users\user\Desktop\macrox!.exe Section loaded: textinputframework.dll Jump to behavior
Source: C:\Users\user\Desktop\macrox!.exe Section loaded: coreuicomponents.dll Jump to behavior
Source: C:\Users\user\Desktop\macrox!.exe Section loaded: coremessaging.dll Jump to behavior
Source: C:\Users\user\Desktop\macrox!.exe Section loaded: ntmarta.dll Jump to behavior
Source: C:\Users\user\Desktop\macrox!.exe Section loaded: coremessaging.dll Jump to behavior
Source: C:\Users\user\Desktop\macrox!.exe Section loaded: wintypes.dll Jump to behavior
Source: C:\Users\user\Desktop\macrox!.exe Section loaded: wintypes.dll Jump to behavior
Source: C:\Users\user\Desktop\macrox!.exe Section loaded: wintypes.dll Jump to behavior
Source: C:\Users\user\Desktop\macrox!.exe Section loaded: textshaping.dll Jump to behavior
Source: C:\Users\user\Desktop\macrox!.exe Section loaded: windows.storage.dll Jump to behavior
Source: C:\Users\user\Desktop\macrox!.exe Section loaded: wldp.dll Jump to behavior
Source: C:\Users\user\Desktop\macrox!.exe Section loaded: profapi.dll Jump to behavior
Source: C:\Users\user\Desktop\macrox!.exe Section loaded: propsys.dll Jump to behavior
Source: C:\Users\user\Desktop\macrox!.exe Section loaded: msvbvm60.dll Jump to behavior
Source: C:\Users\user\Desktop\macrox!.exe Section loaded: sxs.dll Jump to behavior
Source: C:\Users\user\Desktop\macrox!.exe Section loaded: ssubtmr6.dll Jump to behavior
Source: C:\Users\user\Desktop\macrox!.exe Section loaded: msvbvm60.dll Jump to behavior
Source: C:\Users\user\Desktop\macrox!.exe Section loaded: wsock32.dll Jump to behavior
Source: C:\Users\user\Desktop\macrox!.exe Section loaded: msvbvm60.dll Jump to behavior
Source: C:\Users\user\Desktop\macrox!.exe Section loaded: msvbvm60.dll Jump to behavior
Source: C:\Users\user\Desktop\macrox!.exe Section loaded: msvbvm60.dll Jump to behavior
Source: C:\Users\user\Desktop\macrox!.exe Section loaded: msvbvm60.dll Jump to behavior
Source: C:\Users\user\Desktop\macrox!.exe Section loaded: msvbvm60.dll Jump to behavior
Source: C:\Users\user\Desktop\macrox!.exe Section loaded: msvbvm60.dll Jump to behavior
Source: C:\Users\user\Desktop\macrox!.exe Section loaded: msvbvm60.dll Jump to behavior
Source: C:\Users\user\Desktop\macrox!.exe Section loaded: msvbvm60.dll Jump to behavior
Source: C:\Users\user\Desktop\macrox!.exe Section loaded: msvbvm60.dll Jump to behavior
Source: C:\Users\user\Desktop\macrox!.exe Section loaded: msvbvm60.dll Jump to behavior
Source: C:\Users\user\Desktop\macrox!.exe Section loaded: msvbvm60.dll Jump to behavior
Source: C:\Users\user\Desktop\macrox!.exe Section loaded: msvbvm60.dll Jump to behavior
Source: C:\Users\user\Desktop\macrox!.exe Section loaded: linkinfo.dll Jump to behavior
Source: C:\Users\user\Desktop\macrox!.exe Section loaded: ntshrui.dll Jump to behavior
Source: C:\Users\user\Desktop\macrox!.exe Section loaded: cscapi.dll Jump to behavior
Source: C:\Users\user\Desktop\macrox!.exe Key value queried: HKEY_LOCAL_MACHINE\SOFTWARE\Classes\WOW6432Node\CLSID\{20D04FE0-3AEA-1069-A2D8-08002B30309D}\InProcServer32 Jump to behavior
Source: MacroX.lnk.0.dr LNK file: ..\..\..\..\..\..\..\..\..\Program Files (x86)\MacroX\MACROX.EXE
Source: MacroX.lnk0.0.dr LNK file: ..\..\..\Program Files (x86)\MacroX\MACROX.EXE
Source: ClickButton.lnk.0.dr LNK file: ..\..\..\..\..\..\..\..\..\..\Program Files (x86)\MacroX\sample\ClickButton.mcx
Source: RunTag.lnk.0.dr LNK file: ..\..\..\..\..\..\..\..\..\..\Program Files (x86)\MacroX\sample\runtag.mcx
Source: InstanzTest.lnk.0.dr LNK file: ..\..\..\..\..\..\..\..\..\..\Program Files (x86)\MacroX\sample\instanztest.mcx
Source: Registry.lnk.0.dr LNK file: ..\..\..\..\..\..\..\..\..\..\Program Files (x86)\MacroX\sample\Registry.mcx
Source: WatchMouse.lnk.0.dr LNK file: ..\..\..\..\..\..\..\..\..\..\Program Files (x86)\MacroX\sample\WatchMouse.mcx
Source: WatchMouse2.lnk.0.dr LNK file: ..\..\..\..\..\..\..\..\..\..\Program Files (x86)\MacroX\sample\WatchMouse2.mcx
Source: Mouse.lnk.0.dr LNK file: ..\..\..\..\..\..\..\..\..\..\Program Files (x86)\MacroX\sample\Mouse.mcx
Source: TimeOut.lnk.0.dr LNK file: ..\..\..\..\..\..\..\..\..\..\Program Files (x86)\MacroX\sample\TimeOut.mcx
Source: Loop-Text.lnk.0.dr LNK file: ..\..\..\..\..\..\..\..\..\..\Program Files (x86)\MacroX\sample\Loop-Text.mcx
Source: MacroX im Internet.lnk.0.dr LNK file: ..\..\..\..\..\..\..\..\..\Program Files (x86)\MacroX\MacroX.url
Source: Deinstallieren.lnk.0.dr LNK file: ..\..\..\..\..\..\..\..\..\Program Files (x86)\MacroX\uninst.exe
Source: C:\Users\user\Desktop\macrox!.exe File written: C:\Users\user\AppData\Local\Temp\nsv437D.tmp\ioSpecial.ini Jump to behavior
Source: C:\Users\user\Desktop\macrox!.exe Automated click: Installieren
Source: C:\Users\user\Desktop\macrox!.exe Automated click: OK
Source: Window Recorder Window detected: More than 3 window changes detected
Source: C:\Users\user\Desktop\macrox!.exe Key value created or modified: HKEY_CURRENT_USER\Control Panel\Mouse MouseHoverTime Jump to behavior
Source: macrox!.exe Static file information: File size 2322122 > 1048576
Source: Binary string: E:\VC-Projekte\x86.binz\dskeybrd.pdb source: macrox!.exe, 00000000.00000002.2926507817.00000000025E4000.00000004.00000020.00020000.00000000.sdmp, nsa434D.tmp.0.dr, mcxkeyboardhook.dll.0.dr
Source: Binary string: msscript.pdb source: macrox!.exe, 00000000.00000002.2926137934.0000000000409000.00000004.00000001.01000000.00000003.sdmp, macrox!.exe, 00000000.00000002.2926507817.0000000002808000.00000004.00000020.00020000.00000000.sdmp, nsa434D.tmp.0.dr
Source: Binary string: E:\VC-Projekte\x86.binz\dskeybrd.pdb MZ source: macrox!.exe, 00000000.00000002.2926507817.00000000025E4000.00000004.00000020.00020000.00000000.sdmp, nsa434D.tmp.0.dr
Source: Binary string: E:\VC-Projekte\x86.binz\dsmouse.pdbXp source: macrox!.exe, 00000000.00000002.2926507817.00000000025E4000.00000004.00000020.00020000.00000000.sdmp, nsa434D.tmp.0.dr
Source: Binary string: E:\VC-Projekte\x86.binz\dsmouse.pdb source: macrox!.exe, 00000000.00000002.2926507817.00000000025E4000.00000004.00000020.00020000.00000000.sdmp, nsa434D.tmp.0.dr, mcxmousehook.dll.0.dr
Source: mcxkeyboardhook.dll.0.dr Static PE information: section name: Shared
Source: mcxmousehook.dll.0.dr Static PE information: section name: Shared
Source: CMAX20.OCX.0.dr Static PE information: section name: Shared
Source: initial sample Static PE information: section name: UPX0
Source: initial sample Static PE information: section name: UPX1
Source: C:\Users\user\Desktop\macrox!.exe File created: C:\Program Files (x86)\MacroX\sys\HookMenu.ocx Jump to dropped file
Source: C:\Users\user\Desktop\macrox!.exe File created: C:\Program Files (x86)\MacroX\sys\vbalIml6.ocx Jump to dropped file
Source: C:\Users\user\Desktop\macrox!.exe File created: C:\Windows\SysWOW64\SSUBTMR6.DLL Jump to dropped file
Source: C:\Users\user\Desktop\macrox!.exe File created: C:\Program Files (x86)\MacroX\sys\macroxrecord.dll Jump to dropped file
Source: C:\Users\user\Desktop\macrox!.exe File created: C:\Windows\SysWOW64\MSCOMCTL.OCX Jump to dropped file
Source: C:\Users\user\Desktop\macrox!.exe File created: C:\Program Files (x86)\MacroX\sys\mcxRun.exe Jump to dropped file
Source: C:\Users\user\Desktop\macrox!.exe File created: C:\Windows\SysWOW64\mcxmousehook.dll Jump to dropped file
Source: C:\Users\user\Desktop\macrox!.exe File created: C:\Users\user\AppData\Local\Temp\nsv437D.tmp\InstallOptions.dll Jump to dropped file
Source: C:\Users\user\Desktop\macrox!.exe File created: C:\Program Files (x86)\MacroX\sys\mcxLanguage.dll Jump to dropped file
Source: C:\Users\user\Desktop\macrox!.exe File created: C:\Program Files (x86)\MacroX\sys\mcxKernel.dll Jump to dropped file
Source: C:\Users\user\Desktop\macrox!.exe File created: C:\Program Files (x86)\MacroX\sys\mcxtabx.ocx Jump to dropped file
Source: C:\Users\user\Desktop\macrox!.exe File created: C:\Program Files (x86)\MacroX\sys\CMAX20.OCX Jump to dropped file
Source: C:\Users\user\Desktop\macrox!.exe File created: C:\Program Files (x86)\MacroX\sys\mcxnetbar.ocx Jump to dropped file
Source: C:\Users\user\Desktop\macrox!.exe File created: C:\Windows\SysWOW64\mcxkeyboardhook.dll Jump to dropped file
Source: C:\Users\user\Desktop\macrox!.exe File created: C:\Program Files (x86)\MacroX\MACROX.EXE Jump to dropped file
Source: C:\Users\user\Desktop\macrox!.exe File created: C:\Program Files (x86)\MacroX\plugins\registry\mcxregistry.dll Jump to dropped file
Source: C:\Users\user\Desktop\macrox!.exe File created: C:\Program Files (x86)\MacroX\plugins\internet\mcxinternet.dll Jump to dropped file
Source: C:\Users\user\Desktop\macrox!.exe File created: C:\Program Files (x86)\MacroX\sys\macroxsettings.dll Jump to dropped file
Source: C:\Users\user\Desktop\macrox!.exe File created: C:\Program Files (x86)\MacroX\sys\mcxexe.dll Jump to dropped file
Source: C:\Users\user\Desktop\macrox!.exe File created: C:\Windows\SysWOW64\Mswinsck.ocx Jump to dropped file
Source: C:\Users\user\Desktop\macrox!.exe File created: C:\Program Files (x86)\MacroX\plugins\runtag\red.dll Jump to dropped file
Source: C:\Users\user\Desktop\macrox!.exe File created: C:\Program Files (x86)\MacroX\uninst.exe Jump to dropped file
Source: C:\Users\user\Desktop\macrox!.exe File created: C:\Program Files (x86)\MacroX\plugins\runtag\mcxruntag.dll Jump to dropped file
Source: C:\Users\user\Desktop\macrox!.exe File created: C:\Program Files (x86)\MacroX\sys\MCX3.DLL Jump to dropped file
Source: C:\Users\user\Desktop\macrox!.exe File created: C:\Windows\SysWOW64\SSUBTMR6.DLL Jump to dropped file
Source: C:\Users\user\Desktop\macrox!.exe File created: C:\Windows\SysWOW64\mcxkeyboardhook.dll Jump to dropped file
Source: C:\Users\user\Desktop\macrox!.exe File created: C:\Windows\SysWOW64\MSCOMCTL.OCX Jump to dropped file
Source: C:\Users\user\Desktop\macrox!.exe File created: C:\Windows\SysWOW64\Mswinsck.ocx Jump to dropped file
Source: C:\Users\user\Desktop\macrox!.exe File created: C:\Windows\SysWOW64\mcxmousehook.dll Jump to dropped file

Boot Survival

barindex
Source: C:\Users\user\Desktop\macrox!.exe Registry value created: HKEY_LOCAL_MACHINE\SOFTWARE\Classes\MacroX Script\Shell\open\command C:\Program Files (x86)\MacroX\sys\mcxrun.exe %1 Jump to behavior
Source: C:\Users\user\Desktop\macrox!.exe Registry key value modified: HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\EventLog\Application\VBRuntime Jump to behavior
Source: C:\Users\user\Desktop\macrox!.exe File created: C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\MacroX Jump to behavior
Source: C:\Users\user\Desktop\macrox!.exe File created: C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\MacroX\Beispiele Jump to behavior
Source: C:\Users\user\Desktop\macrox!.exe File created: C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\MacroX\MacroX.lnk Jump to behavior
Source: C:\Users\user\Desktop\macrox!.exe File created: C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\MacroX\Beispiele\ClickButton.lnk Jump to behavior
Source: C:\Users\user\Desktop\macrox!.exe File created: C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\MacroX\Beispiele\RunTag.lnk Jump to behavior
Source: C:\Users\user\Desktop\macrox!.exe File created: C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\MacroX\Beispiele\InstanzTest.lnk Jump to behavior
Source: C:\Users\user\Desktop\macrox!.exe File created: C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\MacroX\Beispiele\Registry.lnk Jump to behavior
Source: C:\Users\user\Desktop\macrox!.exe File created: C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\MacroX\Beispiele\WatchMouse.lnk Jump to behavior
Source: C:\Users\user\Desktop\macrox!.exe File created: C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\MacroX\Beispiele\WatchMouse2.lnk Jump to behavior
Source: C:\Users\user\Desktop\macrox!.exe File created: C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\MacroX\Beispiele\Mouse.lnk Jump to behavior
Source: C:\Users\user\Desktop\macrox!.exe File created: C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\MacroX\Beispiele\TimeOut.lnk Jump to behavior
Source: C:\Users\user\Desktop\macrox!.exe File created: C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\MacroX\Beispiele\Loop-Text.lnk Jump to behavior
Source: C:\Users\user\Desktop\macrox!.exe File created: C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\MacroX\MacroX im Internet.lnk Jump to behavior
Source: C:\Users\user\Desktop\macrox!.exe File created: C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\MacroX\Deinstallieren.lnk Jump to behavior
Source: C:\Users\user\Desktop\macrox!.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Users\user\Desktop\macrox!.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Users\user\Desktop\macrox!.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Users\user\Desktop\macrox!.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Users\user\Desktop\macrox!.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Users\user\Desktop\macrox!.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Users\user\Desktop\macrox!.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Users\user\Desktop\macrox!.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Users\user\Desktop\macrox!.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Users\user\Desktop\macrox!.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Users\user\Desktop\macrox!.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Users\user\Desktop\macrox!.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Users\user\Desktop\macrox!.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Users\user\Desktop\macrox!.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Users\user\Desktop\macrox!.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Users\user\Desktop\macrox!.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Users\user\Desktop\macrox!.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Users\user\Desktop\macrox!.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Users\user\Desktop\macrox!.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Users\user\Desktop\macrox!.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Users\user\Desktop\macrox!.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Users\user\Desktop\macrox!.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Users\user\Desktop\macrox!.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Users\user\Desktop\macrox!.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Users\user\Desktop\macrox!.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Users\user\Desktop\macrox!.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Users\user\Desktop\macrox!.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Users\user\Desktop\macrox!.exe Window / User API: foregroundWindowGot 579 Jump to behavior
Source: C:\Users\user\Desktop\macrox!.exe Dropped PE file which has not been started: C:\Program Files (x86)\MacroX\sys\CMAX20.OCX Jump to dropped file
Source: C:\Users\user\Desktop\macrox!.exe Dropped PE file which has not been started: C:\Program Files (x86)\MacroX\sys\HookMenu.ocx Jump to dropped file
Source: C:\Users\user\Desktop\macrox!.exe Dropped PE file which has not been started: C:\Program Files (x86)\MacroX\sys\mcxnetbar.ocx Jump to dropped file
Source: C:\Users\user\Desktop\macrox!.exe Dropped PE file which has not been started: C:\Windows\SysWOW64\mcxkeyboardhook.dll Jump to dropped file
Source: C:\Users\user\Desktop\macrox!.exe Dropped PE file which has not been started: C:\Program Files (x86)\MacroX\sys\vbalIml6.ocx Jump to dropped file
Source: C:\Users\user\Desktop\macrox!.exe Dropped PE file which has not been started: C:\Program Files (x86)\MacroX\MACROX.EXE Jump to dropped file
Source: C:\Users\user\Desktop\macrox!.exe Dropped PE file which has not been started: C:\Program Files (x86)\MacroX\sys\macroxrecord.dll Jump to dropped file
Source: C:\Users\user\Desktop\macrox!.exe Dropped PE file which has not been started: C:\Program Files (x86)\MacroX\plugins\registry\mcxregistry.dll Jump to dropped file
Source: C:\Users\user\Desktop\macrox!.exe Dropped PE file which has not been started: C:\Program Files (x86)\MacroX\plugins\internet\mcxinternet.dll Jump to dropped file
Source: C:\Users\user\Desktop\macrox!.exe Dropped PE file which has not been started: C:\Program Files (x86)\MacroX\sys\macroxsettings.dll Jump to dropped file
Source: C:\Users\user\Desktop\macrox!.exe Dropped PE file which has not been started: C:\Program Files (x86)\MacroX\sys\mcxexe.dll Jump to dropped file
Source: C:\Users\user\Desktop\macrox!.exe Dropped PE file which has not been started: C:\Program Files (x86)\MacroX\sys\mcxRun.exe Jump to dropped file
Source: C:\Users\user\Desktop\macrox!.exe Dropped PE file which has not been started: C:\Windows\SysWOW64\mcxmousehook.dll Jump to dropped file
Source: C:\Users\user\Desktop\macrox!.exe Dropped PE file which has not been started: C:\Program Files (x86)\MacroX\sys\mcxLanguage.dll Jump to dropped file
Source: C:\Users\user\Desktop\macrox!.exe Dropped PE file which has not been started: C:\Users\user\AppData\Local\Temp\nsv437D.tmp\InstallOptions.dll Jump to dropped file
Source: C:\Users\user\Desktop\macrox!.exe Dropped PE file which has not been started: C:\Program Files (x86)\MacroX\plugins\runtag\red.dll Jump to dropped file
Source: C:\Users\user\Desktop\macrox!.exe Dropped PE file which has not been started: C:\Program Files (x86)\MacroX\plugins\runtag\mcxruntag.dll Jump to dropped file
Source: C:\Users\user\Desktop\macrox!.exe Dropped PE file which has not been started: C:\Program Files (x86)\MacroX\uninst.exe Jump to dropped file
Source: C:\Users\user\Desktop\macrox!.exe Dropped PE file which has not been started: C:\Program Files (x86)\MacroX\sys\MCX3.DLL Jump to dropped file
Source: C:\Users\user\Desktop\macrox!.exe Dropped PE file which has not been started: C:\Program Files (x86)\MacroX\sys\mcxKernel.dll Jump to dropped file
Source: C:\Users\user\Desktop\macrox!.exe Dropped PE file which has not been started: C:\Program Files (x86)\MacroX\sys\mcxtabx.ocx Jump to dropped file
Source: C:\Users\user\Desktop\macrox!.exe File opened: C:\Users\user\AppData\Roaming Jump to behavior
Source: C:\Users\user\Desktop\macrox!.exe File opened: C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\desktop.ini Jump to behavior
Source: C:\Users\user\Desktop\macrox!.exe File opened: C:\Users\user Jump to behavior
Source: C:\Users\user\Desktop\macrox!.exe File opened: C:\Users\user\AppData\Roaming\Microsoft Jump to behavior
Source: C:\Users\user\Desktop\macrox!.exe File opened: C:\Users\user\AppData Jump to behavior
Source: C:\Users\user\Desktop\macrox!.exe File opened: C:\Users\user\AppData\Roaming\Microsoft\Windows Jump to behavior
Source: macrox!.exe, 00000000.00000002.2926255771.000000000077C000.00000004.00000020.00020000.00000000.sdmp Binary or memory string: \\?\SCSI#CdRom&Ven_NECVMWar&Prod_VMware_SATA_CD00#4&224f42ef&0&000000#{53f5630d-b6bf-11d0-94f2-00a0c91efb8b}\\\?\Volume{a33c736e-61ca-11ee-8c18-806e6f6e6963}\
Source: macrox!.exe, 00000000.00000003.1762167687.000000000079F000.00000004.00000020.00020000.00000000.sdmp Binary or memory string: Hyper-V RAW%SystemRoot%\system32\mswsock.dll
Source: C:\Users\user\Desktop\macrox!.exe Queries volume information: C:\ VolumeInformation Jump to behavior
Source: C:\Users\user\Desktop\macrox!.exe Queries volume information: C:\ VolumeInformation Jump to behavior
Source: C:\Users\user\Desktop\macrox!.exe Queries volume information: C:\ VolumeInformation Jump to behavior
Source: C:\Users\user\Desktop\macrox!.exe Queries volume information: C:\ VolumeInformation Jump to behavior
Source: C:\Users\user\Desktop\macrox!.exe Queries volume information: C:\ VolumeInformation Jump to behavior
Source: C:\Users\user\Desktop\macrox!.exe Queries volume information: C:\ VolumeInformation Jump to behavior
Source: C:\Users\user\Desktop\macrox!.exe Queries volume information: C:\ VolumeInformation Jump to behavior
Source: C:\Users\user\Desktop\macrox!.exe Queries volume information: C:\ VolumeInformation Jump to behavior
Source: C:\Users\user\Desktop\macrox!.exe Queries volume information: C:\ VolumeInformation Jump to behavior
Source: C:\Users\user\Desktop\macrox!.exe Queries volume information: C:\ VolumeInformation Jump to behavior
Source: C:\Users\user\Desktop\macrox!.exe Queries volume information: C:\ VolumeInformation Jump to behavior
Source: C:\Users\user\Desktop\macrox!.exe Queries volume information: C:\ VolumeInformation Jump to behavior
Source: C:\Users\user\Desktop\macrox!.exe Queries volume information: C:\ VolumeInformation Jump to behavior
No contacted IP infos