Source: 24v3hhTWiA.exe |
ReversingLabs: Detection: 28% |
Source: Submited Sample |
Integrated Neural Analysis Model: Matched 82.0% probability |
Source: 24v3hhTWiA.exe |
Static PE information: HIGH_ENTROPY_VA, DYNAMIC_BASE, NX_COMPAT, NO_SEH, TERMINAL_SERVER_AWARE |
Source: |
Binary string: C:\Users\Administrator\Documents\CalculadoraWPF-main\CalculadoraWPF\obj\Release\netcoreapp3.1\win-x64\Installation_x64.pdb source: 24v3hhTWiA.exe |
Source: |
Binary string: PresentationFramework.pdb source: WERA74E.tmp.dmp.4.dr |
Source: |
Binary string: WindowsBase.ni.pdb source: WERA74E.tmp.dmp.4.dr |
Source: |
Binary string: System.ni.pdbRSDS source: WERA74E.tmp.dmp.4.dr |
Source: |
Binary string: WindowsBase.ni.pdbRSDS source: WERA74E.tmp.dmp.4.dr |
Source: |
Binary string: mscorlib.ni.pdbRSDS7^3l source: WERA74E.tmp.dmp.4.dr |
Source: |
Binary string: mscorlib.pdb0 source: WERA74E.tmp.dmp.4.dr |
Source: |
Binary string: Installation_x64.pdb source: WERA74E.tmp.dmp.4.dr |
Source: |
Binary string: System.pdb source: WERA74E.tmp.dmp.4.dr |
Source: |
Binary string: System.Core.ni.pdb source: WERA74E.tmp.dmp.4.dr |
Source: |
Binary string: PresentationFramework.ni.pdbRSDS source: WERA74E.tmp.dmp.4.dr |
Source: |
Binary string: PresentationCore.ni.pdbRSDS source: WERA74E.tmp.dmp.4.dr |
Source: |
Binary string: WindowsBase.pdb source: WERA74E.tmp.dmp.4.dr |
Source: |
Binary string: System.Xaml.ni.pdb source: WERA74E.tmp.dmp.4.dr |
Source: |
Binary string: mscorlib.pdb source: 24v3hhTWiA.exe, 00000000.00000002.1828208028.0000014000001000.00000004.00000800.00020000.00000000.sdmp, WERA74E.tmp.dmp.4.dr |
Source: |
Binary string: System.Xaml.ni.pdbRSDSDg{V source: WERA74E.tmp.dmp.4.dr |
Source: |
Binary string: \??\C:\Windows\symbols\dll\PresentationCore.pdb source: 24v3hhTWiA.exe, 00000000.00000002.1828357286.00000140741D6000.00000004.00000020.00020000.00000000.sdmp |
Source: |
Binary string: PresentationCore.ni.pdb source: WERA74E.tmp.dmp.4.dr |
Source: |
Binary string: \??\C:\Windows\Microsoft.Net\assembly\GAC_64\mscorlib\v4.0_4.0.0.0__b77a5c561934e089\mscorlib.pdbla source: 24v3hhTWiA.exe, 00000000.00000002.1828357286.00000140741D6000.00000004.00000020.00020000.00000000.sdmp |
Source: |
Binary string: System.pdbH source: WERA74E.tmp.dmp.4.dr |
Source: |
Binary string: System.Xaml.pdb source: WERA74E.tmp.dmp.4.dr |
Source: |
Binary string: mscorlib.ni.pdb source: WERA74E.tmp.dmp.4.dr |
Source: |
Binary string: C:\Users\Administrator\Documents\CalculadoraWPF-main\CalculadoraWPF\obj\Release\netcoreapp3.1\win-x64\Installation_x64.pdbSHA256 source: 24v3hhTWiA.exe |
Source: |
Binary string: Installation_x64.pdbA9 source: WERA74E.tmp.dmp.4.dr |
Source: |
Binary string: System.Core.pdb source: WERA74E.tmp.dmp.4.dr |
Source: |
Binary string: PresentationFramework.pdbMZ@ source: WERA74E.tmp.dmp.4.dr |
Source: |
Binary string: \??\C:\Windows\Microsoft.Net\assembly\GAC_64\PresentationCore\v4.0_4.0.0.0__31bf3856ad364e35\PresentationCore.pdb source: 24v3hhTWiA.exe, 00000000.00000002.1828357286.00000140741D6000.00000004.00000020.00020000.00000000.sdmp |
Source: |
Binary string: System.Core.pdbh source: WERA74E.tmp.dmp.4.dr |
Source: |
Binary string: PresentationFramework.ni.pdb source: WERA74E.tmp.dmp.4.dr |
Source: |
Binary string: PresentationCore.pdb source: WERA74E.tmp.dmp.4.dr |
Source: |
Binary string: System.ni.pdb source: WERA74E.tmp.dmp.4.dr |
Source: |
Binary string: System.Core.ni.pdbRSDS source: WERA74E.tmp.dmp.4.dr |
Source: Amcache.hve.4.dr |
String found in binary or memory: http://upx.sf.net |
Source: C:\Users\user\Desktop\24v3hhTWiA.exe |
Process created: C:\Windows\System32\WerFault.exe C:\Windows\system32\WerFault.exe -u -p 7292 -s 808 |
Source: 24v3hhTWiA.exe |
Static PE information: No import functions for PE file found |
Source: 24v3hhTWiA.exe, 00000000.00000000.1445053589.0000014073FB4000.00000002.00000001.01000000.00000003.sdmp |
Binary or memory string: OriginalFilenameInstallation_x64.dll6 vs 24v3hhTWiA.exe |
Source: 24v3hhTWiA.exe |
Binary or memory string: OriginalFilenameInstallation_x64.dll6 vs 24v3hhTWiA.exe |
Source: 24v3hhTWiA.exe |
Static PE information: Section: .text IMAGE_SCN_CNT_CODE, IMAGE_SCN_MEM_EXECUTE, IMAGE_SCN_MEM_READ |
Source: classification engine |
Classification label: mal52.winEXE@2/5@0/0 |
Source: C:\Users\user\Desktop\24v3hhTWiA.exe |
Mutant created: NULL |
Source: C:\Windows\System32\WerFault.exe |
Mutant created: \Sessions\1\BaseNamedObjects\Local\WERReportingForProcess7292 |
Source: C:\Windows\System32\WerFault.exe |
File created: C:\ProgramData\Microsoft\Windows\WER\Temp\c236bbf8-16e0-444b-9565-e9729369032c |
Jump to behavior |
Source: 24v3hhTWiA.exe |
Static PE information: Section: .text IMAGE_SCN_CNT_CODE, IMAGE_SCN_MEM_EXECUTE, IMAGE_SCN_MEM_READ |
Source: 24v3hhTWiA.exe |
Static file information: TRID: Win64 Executable GUI Net Framework (217006/5) 49.88% |
Source: C:\Users\user\Desktop\24v3hhTWiA.exe |
Key opened: HKEY_LOCAL_MACHINE\Software\Policies\Microsoft\Windows\Safer\CodeIdentifiers |
Jump to behavior |
Source: 24v3hhTWiA.exe |
ReversingLabs: Detection: 28% |
Source: 24v3hhTWiA.exe |
String found in binary or memory: <.ctor>b__0_0<InitializeAsync>d__1<>u__1IEnumerable`1Task`1List`1label_download1label_done1sendclick1sendopen1ProgressBar1Int32Dictionary`2TaskLoad2label_download2label_done2sendclick2sendopen2TaskLoad3label_done3Installation_x64get_UTF8<p0><p1><Module>CalculadoraWPFSystem.IOotstykdomainpublicSystem.Collections.GenericInitializeAsyncReadAsStringAsyncGetAsyncTinyPatch.MiscconnectionIdSystem.Threading.ThreadTaskLoadAdd_contentLoadedAwaitUnsafeOnCompletedget_IsCompletedSendUriKindEnsureSuccessStatusCodeget_MessageHttpResponseMessageDefenderRechargeIDisposableDownloadFilesecond_file_is_opened_skipping_to_next_filethird_file_is_opened_skipping_to_next_filefour_file_is_opened_skipping_to_next_filefirst_file_is_opened_skipping_to_next_fileIsInRoleWindowsBuiltInRoleSystem.Consoleset_FileNameget_MachineNameGetCpuNameSystem.RuntimeWriteLineCombineIAsyncStateMachineSetStateMachinestateMachineValueTypePresentationCoreMoreRangeBaseButtonBaseCloseDisposeCreateEditorBrowsableState<>1__stateTinyPatch.AnalizateDeleteSTAThreadAttributeEmbeddedAttributeCompilerGeneratedAttributeGeneratedCodeAttributeDebuggerNonUserCodeAttributeAttributeUsageAttributeDebuggableAttributeNullableAttributeEditorBrowsableAttributeAssemblyAssociatedContentFileAttributeAssemblyTitleAttributeAsyncStateMachineAttributeTargetFrameworkAttributeDebuggerHiddenAttributeAssemblyFileVersionAttributeAssemblyInformationalVersionAttributeAssemblyConfigurationAttributeThemeInfoAttributeCompilationRelaxationsAttributeAssemblyProductAttributeAssemblyCopyrightAttributeNullableContextAttributeAssemblyCompanyAttributeRuntimeCompatibilityAttributeset_UseShellExecuteByteset_ValueTryGetValueDragMovedefender_offFlagTinyPatch.ConfigAppConfigSystem.ThreadingEncodingsecond_bug_downloaded_but_having_problem_with_openningthird_bug_downloaded_but_having_problem_with_openningfour_bug_downloaded_but_having_problem_with_openningFirst_bug_downloaded_but_having_problem_with_openningSystem.Runtime.VersioningFromBase64StringDownloadStringToStringGetStringdownload_second_bugopened_second_bugerror_on_downloading_second_bugerror_on_openning_second_bugdownload_third_bugopened_third_bugerror_on_downloading_third_bugerror_on_openning_third_bugdownload_four_bugopened_four_bugerror_on_downloading_four_bugerror_on_openning_four_bugdownload_first_bugopened_first_bugerror_on_downloading_first_bugerror_on_openning_first_bugSystem.Diagnostics.DebugotstykdomaindebugFlushGetFolderPathset_StartupUri |