Click to jump to signature section
Source: Fattura.jar | ReversingLabs: Detection: 29% |
Source: Submited Sample | Integrated Neural Analysis Model: Matched 89.2% probability |
Source: C:\Program Files (x86)\Java\jre-1.8\bin\java.exe | Code function: 4x nop then cmp eax, dword ptr [ecx+04h] | 2_2_028C8298 |
Source: global traffic | TCP traffic: 192.168.2.9:49707 -> 3.124.154.255:27788 |
Source: unknown | UDP traffic detected without corresponding DNS query: 1.1.1.1 |
Source: global traffic | DNS traffic detected: DNS query: 8.tcp.eu.ngrok.io |
Source: java.exe, 00000002.00000002.1420950532.0000000009FEA000.00000004.00000800.00020000.00000000.sdmp | String found in binary or memory: http://bugreport.sun.com/bugreport/ |
Source: java.exe, 00000002.00000002.1420950532.000000000A0E8000.00000004.00000800.00020000.00000000.sdmp, java.exe, 00000002.00000002.1420950532.000000000A0FD000.00000004.00000800.00020000.00000000.sdmp | String found in binary or memory: http://cacerts.digicert.com/DigiCertAssuredIDRootCA.crt |
Source: java.exe, 00000002.00000002.1441715537.00000000157E5000.00000004.00000020.00020000.00000000.sdmp, java.exe, 00000002.00000002.1420950532.000000000A0FD000.00000004.00000800.00020000.00000000.sdmp, java.exe, 00000002.00000002.1420950532.000000000A03C000.00000004.00000800.00020000.00000000.sdmp | String found in binary or memory: http://cacerts.digicert.com/DigiCertAssuredIDRootCA.crt0E |
Source: java.exe, 00000002.00000002.1420950532.000000000A0E8000.00000004.00000800.00020000.00000000.sdmp, java.exe, 00000002.00000002.1420950532.000000000A0FD000.00000004.00000800.00020000.00000000.sdmp, java.exe, 00000002.00000002.1420950532.000000000A03C000.00000004.00000800.00020000.00000000.sdmp | String found in binary or memory: http://cacerts.digicert.com/DigiCertTrustedG4RSA4096SHA256TimeStampingCA.crt |
Source: java.exe, 00000002.00000002.1420950532.000000000A0FD000.00000004.00000800.00020000.00000000.sdmp | String found in binary or memory: http://cacerts.digicert.com/DigiCertTrustedG4RSA4096SHA256TimeStampingCA.crt0 |
Source: java.exe, 00000002.00000002.1420950532.000000000A0E8000.00000004.00000800.00020000.00000000.sdmp, java.exe, 00000002.00000002.1420950532.000000000A0FD000.00000004.00000800.00020000.00000000.sdmp | String found in binary or memory: http://cacerts.digicert.com/DigiCertTrustedRootG4.crt |
Source: java.exe, 00000002.00000002.1420950532.000000000A0FD000.00000004.00000800.00020000.00000000.sdmp, java.exe, 00000002.00000002.1420950532.000000000A03C000.00000004.00000800.00020000.00000000.sdmp | String found in binary or memory: http://cacerts.digicert.com/DigiCertTrustedRootG4.crt0C |
Source: java.exe, 00000002.00000002.1420950532.000000000A0E8000.00000004.00000800.00020000.00000000.sdmp, java.exe, 00000002.00000002.1420950532.000000000A0FD000.00000004.00000800.00020000.00000000.sdmp | String found in binary or memory: http://crl3.digicert.com/DigiCertAssuredIDRootCA.crl |
Source: java.exe, 00000002.00000002.1441715537.00000000157E5000.00000004.00000020.00020000.00000000.sdmp, java.exe, 00000002.00000002.1420950532.000000000A0FD000.00000004.00000800.00020000.00000000.sdmp, java.exe, 00000002.00000002.1420950532.000000000A03C000.00000004.00000800.00020000.00000000.sdmp | String found in binary or memory: http://crl3.digicert.com/DigiCertAssuredIDRootCA.crl0 |
Source: java.exe, 00000002.00000002.1420950532.000000000A0E8000.00000004.00000800.00020000.00000000.sdmp, java.exe, 00000002.00000002.1420950532.000000000A0FD000.00000004.00000800.00020000.00000000.sdmp | String found in binary or memory: http://crl3.digicert.com/DigiCertTrustedG4RSA4096SHA256TimeStampingCA.crl |
Source: java.exe, 00000002.00000002.1420950532.000000000A0FD000.00000004.00000800.00020000.00000000.sdmp, java.exe, 00000002.00000002.1420950532.000000000A03C000.00000004.00000800.00020000.00000000.sdmp | String found in binary or memory: http://crl3.digicert.com/DigiCertTrustedG4RSA4096SHA256TimeStampingCA.crl0 |
Source: java.exe, 00000002.00000002.1420950532.000000000A0E8000.00000004.00000800.00020000.00000000.sdmp, java.exe, 00000002.00000002.1420950532.000000000A0FD000.00000004.00000800.00020000.00000000.sdmp | String found in binary or memory: http://crl3.digicert.com/DigiCertTrustedRootG4.crl |
Source: java.exe, 00000002.00000002.1441715537.00000000157E5000.00000004.00000020.00020000.00000000.sdmp, java.exe, 00000002.00000002.1420950532.000000000A0FD000.00000004.00000800.00020000.00000000.sdmp, java.exe, 00000002.00000002.1420950532.000000000A03C000.00000004.00000800.00020000.00000000.sdmp | String found in binary or memory: http://crl3.digicert.com/DigiCertTrustedRootG4.crl0 |
Source: java.exe, 00000002.00000002.1420950532.0000000009F50000.00000004.00000800.00020000.00000000.sdmp | String found in binary or memory: http://java.oracle.com/ |
Source: java.exe, 00000002.00000002.1420950532.000000000A0FD000.00000004.00000800.00020000.00000000.sdmp, java.exe, 00000002.00000002.1441498590.0000000015270000.00000004.00000020.00020000.00000000.sdmp, java.exe, 00000002.00000002.1441715537.000000001582A000.00000004.00000020.00020000.00000000.sdmp | String found in binary or memory: http://null.oracle.com/ |
Source: java.exe, 00000002.00000002.1420950532.000000000A0FD000.00000004.00000800.00020000.00000000.sdmp | String found in binary or memory: http://ocsp.digicert.com |
Source: java.exe, 00000002.00000002.1420950532.000000000A0E8000.00000004.00000800.00020000.00000000.sdmp, java.exe, 00000002.00000002.1420950532.000000000A0FD000.00000004.00000800.00020000.00000000.sdmp, java.exe, 00000002.00000002.1420950532.000000000A03C000.00000004.00000800.00020000.00000000.sdmp | String found in binary or memory: http://ocsp.digicert.com0A |
Source: java.exe, 00000002.00000002.1420950532.000000000A0E8000.00000004.00000800.00020000.00000000.sdmp, java.exe, 00000002.00000002.1441715537.00000000157E5000.00000004.00000020.00020000.00000000.sdmp, java.exe, 00000002.00000002.1420950532.000000000A0FD000.00000004.00000800.00020000.00000000.sdmp, java.exe, 00000002.00000002.1420950532.000000000A03C000.00000004.00000800.00020000.00000000.sdmp | String found in binary or memory: http://ocsp.digicert.com0C |
Source: java.exe, 00000002.00000002.1420950532.000000000A0E8000.00000004.00000800.00020000.00000000.sdmp, java.exe, 00000002.00000002.1420950532.000000000A0FD000.00000004.00000800.00020000.00000000.sdmp, java.exe, 00000002.00000002.1420950532.000000000A03C000.00000004.00000800.00020000.00000000.sdmp | String found in binary or memory: http://ocsp.digicert.com0X |
Source: classification engine | Classification label: mal60.winJAR@7/3@1/1 |
Source: C:\Program Files (x86)\Java\jre-1.8\bin\java.exe | Mutant created: NULL |
Source: C:\Windows\System32\conhost.exe | Mutant created: \Sessions\1\BaseNamedObjects\Local\SM0:7512:120:WilError_03 |
Source: C:\Windows\System32\conhost.exe | Mutant created: \Sessions\1\BaseNamedObjects\Local\SM0:7408:120:WilError_03 |
Source: Fattura.jar | ReversingLabs: Detection: 29% |
Source: unknown | Process created: C:\Windows\SysWOW64\cmd.exe C:\Windows\system32\cmd.exe /c ""C:\Program Files (x86)\Java\jre-1.8\bin\java.exe" -javaagent:"C:\Users\user\AppData\Local\Temp\jartracer.jar" -jar "C:\Users\user\Desktop\Fattura.jar"" >> C:\cmdlinestart.log 2>&1 | |
Source: C:\Windows\SysWOW64\cmd.exe | Process created: C:\Windows\System32\conhost.exe C:\Windows\system32\conhost.exe 0xffffffff -ForceV1 | |
Source: C:\Windows\SysWOW64\cmd.exe | Process created: C:\Program Files (x86)\Java\jre-1.8\bin\java.exe "C:\Program Files (x86)\Java\jre-1.8\bin\java.exe" -javaagent:"C:\Users\user\AppData\Local\Temp\jartracer.jar" -jar "C:\Users\user\Desktop\Fattura.jar" | |
Source: C:\Program Files (x86)\Java\jre-1.8\bin\java.exe | Process created: C:\Windows\SysWOW64\icacls.exe C:\Windows\system32\icacls.exe C:\ProgramData\Oracle\Java\.oracle_jre_usage /grant "everyone":(OI)(CI)M | |
Source: C:\Windows\SysWOW64\icacls.exe | Process created: C:\Windows\System32\conhost.exe C:\Windows\system32\conhost.exe 0xffffffff -ForceV1 | |
Source: C:\Windows\SysWOW64\cmd.exe | Process created: C:\Program Files (x86)\Java\jre-1.8\bin\java.exe "C:\Program Files (x86)\Java\jre-1.8\bin\java.exe" -javaagent:"C:\Users\user\AppData\Local\Temp\jartracer.jar" -jar "C:\Users\user\Desktop\Fattura.jar" | Jump to behavior |
Source: C:\Program Files (x86)\Java\jre-1.8\bin\java.exe | Process created: C:\Windows\SysWOW64\icacls.exe C:\Windows\system32\icacls.exe C:\ProgramData\Oracle\Java\.oracle_jre_usage /grant "everyone":(OI)(CI)M | Jump to behavior |
Source: C:\Windows\SysWOW64\cmd.exe | Section loaded: apphelp.dll | Jump to behavior |
Source: C:\Program Files (x86)\Java\jre-1.8\bin\java.exe | Section loaded: apphelp.dll | Jump to behavior |
Source: C:\Program Files (x86)\Java\jre-1.8\bin\java.exe | Section loaded: wsock32.dll | Jump to behavior |
Source: C:\Program Files (x86)\Java\jre-1.8\bin\java.exe | Section loaded: winmm.dll | Jump to behavior |
Source: C:\Program Files (x86)\Java\jre-1.8\bin\java.exe | Section loaded: version.dll | Jump to behavior |
Source: C:\Program Files (x86)\Java\jre-1.8\bin\java.exe | Section loaded: kernel.appcore.dll | Jump to behavior |
Source: C:\Program Files (x86)\Java\jre-1.8\bin\java.exe | Section loaded: windows.storage.dll | Jump to behavior |
Source: C:\Program Files (x86)\Java\jre-1.8\bin\java.exe | Section loaded: wldp.dll | Jump to behavior |
Source: C:\Program Files (x86)\Java\jre-1.8\bin\java.exe | Section loaded: profapi.dll | Jump to behavior |
Source: C:\Program Files (x86)\Java\jre-1.8\bin\java.exe | Section loaded: uxtheme.dll | Jump to behavior |
Source: C:\Program Files (x86)\Java\jre-1.8\bin\java.exe | Section loaded: dwmapi.dll | Jump to behavior |
Source: C:\Program Files (x86)\Java\jre-1.8\bin\java.exe | Section loaded: mswsock.dll | Jump to behavior |
Source: C:\Program Files (x86)\Java\jre-1.8\bin\java.exe | Section loaded: iphlpapi.dll | Jump to behavior |
Source: C:\Program Files (x86)\Java\jre-1.8\bin\java.exe | Section loaded: dhcpcsvc6.dll | Jump to behavior |
Source: C:\Program Files (x86)\Java\jre-1.8\bin\java.exe | Section loaded: dhcpcsvc.dll | Jump to behavior |
Source: C:\Program Files (x86)\Java\jre-1.8\bin\java.exe | Section loaded: dnsapi.dll | Jump to behavior |
Source: C:\Program Files (x86)\Java\jre-1.8\bin\java.exe | Section loaded: rasadhlp.dll | Jump to behavior |
Source: C:\Program Files (x86)\Java\jre-1.8\bin\java.exe | Section loaded: fwpuclnt.dll | Jump to behavior |
Source: C:\Windows\SysWOW64\icacls.exe | Section loaded: ntmarta.dll | Jump to behavior |
Source: C:\Program Files (x86)\Java\jre-1.8\bin\java.exe | Code function: 2_2_0282D8F7 push 00000000h; mov dword ptr [esp], esp | 2_2_0282D921 |
Source: C:\Program Files (x86)\Java\jre-1.8\bin\java.exe | Code function: 2_2_0282A20A push ecx; ret | 2_2_0282A21A |
Source: C:\Program Files (x86)\Java\jre-1.8\bin\java.exe | Code function: 2_2_0282A21B push ecx; ret | 2_2_0282A225 |
Source: C:\Program Files (x86)\Java\jre-1.8\bin\java.exe | Code function: 2_2_0282B3B7 push 00000000h; mov dword ptr [esp], esp | 2_2_0282B3DD |
Source: C:\Program Files (x86)\Java\jre-1.8\bin\java.exe | Code function: 2_2_0282BB67 push 00000000h; mov dword ptr [esp], esp | 2_2_0282BB8D |
Source: C:\Program Files (x86)\Java\jre-1.8\bin\java.exe | Code function: 2_2_0282D8E0 push 00000000h; mov dword ptr [esp], esp | 2_2_0282D921 |
Source: C:\Program Files (x86)\Java\jre-1.8\bin\java.exe | Code function: 2_2_0282B947 push 00000000h; mov dword ptr [esp], esp | 2_2_0282B96D |
Source: C:\Program Files (x86)\Java\jre-1.8\bin\java.exe | Code function: 2_2_0282C477 push 00000000h; mov dword ptr [esp], esp | 2_2_0282C49D |
Source: C:\Program Files (x86)\Java\jre-1.8\bin\java.exe | Code function: 2_2_028CC34B push cs; ret | 2_2_028CC351 |
Source: C:\Program Files (x86)\Java\jre-1.8\bin\java.exe | Process created: C:\Windows\SysWOW64\icacls.exe C:\Windows\system32\icacls.exe C:\ProgramData\Oracle\Java\.oracle_jre_usage /grant "everyone":(OI)(CI)M |
Source: C:\Windows\System32\conhost.exe | Last function: Thread delayed |
Source: java.exe, 00000002.00000003.1390573898.0000000014E62000.00000004.00000020.00020000.00000000.sdmp | Binary or memory string: com/sun/corba/se/impl/util/SUNVMCID.classPK |
Source: java.exe, 00000002.00000003.1390573898.0000000014E62000.00000004.00000020.00020000.00000000.sdmp | Binary or memory string: &com/sun/corba/se/impl/util/SUNVMCID.classPK |
Source: java.exe, 00000002.00000002.1420440849.0000000000F8B000.00000004.00000020.00020000.00000000.sdmp | Binary or memory string: [Ljava/lang/VirtualMachineError; |
Source: java.exe, 00000002.00000003.1390573898.0000000014E62000.00000004.00000020.00020000.00000000.sdmp | Binary or memory string: org/omg/CORBA/OMGVMCID.classPK |
Source: java.exe, 00000002.00000002.1420440849.0000000000F8B000.00000004.00000020.00020000.00000000.sdmp | Binary or memory string: cjava/lang/VirtualMachineError |
Source: java.exe, 00000002.00000003.1390573898.0000000014E62000.00000004.00000020.00020000.00000000.sdmp | Binary or memory string: java/lang/VirtualMachineError.classPK |
Source: java.exe, 00000002.00000002.1420440849.0000000000F8B000.00000004.00000020.00020000.00000000.sdmp | Binary or memory string: Hyper-V RAW%SystemRoot%\system32\mswsock.dll |
Source: C:\Program Files (x86)\Java\jre-1.8\bin\java.exe | Code function: 2_2_02820672 LdrInitializeThunk, | 2_2_02820672 |
Source: C:\Windows\SysWOW64\cmd.exe | Process created: C:\Program Files (x86)\Java\jre-1.8\bin\java.exe "C:\Program Files (x86)\Java\jre-1.8\bin\java.exe" -javaagent:"C:\Users\user\AppData\Local\Temp\jartracer.jar" -jar "C:\Users\user\Desktop\Fattura.jar" | Jump to behavior |
Source: C:\Program Files (x86)\Java\jre-1.8\bin\java.exe | Process created: C:\Windows\SysWOW64\icacls.exe C:\Windows\system32\icacls.exe C:\ProgramData\Oracle\Java\.oracle_jre_usage /grant "everyone":(OI)(CI)M | Jump to behavior |
Source: C:\Program Files (x86)\Java\jre-1.8\bin\java.exe | Queries volume information: C:\Program Files (x86)\Java\jre-1.8\bin\java.dll VolumeInformation | Jump to behavior |
Source: C:\Program Files (x86)\Java\jre-1.8\bin\java.exe | Queries volume information: C:\Program Files (x86)\Java\jre-1.8\bin\client\jvm.dll VolumeInformation | Jump to behavior |
Source: C:\Program Files (x86)\Java\jre-1.8\bin\java.exe | Queries volume information: C:\Program Files (x86)\Java\jre-1.8\bin\java.dll VolumeInformation | Jump to behavior |
Source: C:\Program Files (x86)\Java\jre-1.8\bin\java.exe | Queries volume information: C:\Program Files (x86)\Java\jre-1.8\bin\java.dll VolumeInformation | Jump to behavior |
Source: C:\Program Files (x86)\Java\jre-1.8\bin\java.exe | Queries volume information: C:\Users\user\AppData\Local\Temp\hsperfdata_user\7456 VolumeInformation | Jump to behavior |
Source: C:\Program Files (x86)\Java\jre-1.8\bin\java.exe | Queries volume information: C:\Program Files (x86)\Java\jre-1.8\lib\resources.jar VolumeInformation | Jump to behavior |
Source: C:\Program Files (x86)\Java\jre-1.8\bin\java.exe | Queries volume information: C:\Program Files (x86)\Java\jre-1.8\lib\rt.jar VolumeInformation | Jump to behavior |
Source: C:\Program Files (x86)\Java\jre-1.8\bin\java.exe | Queries volume information: C:\Program Files (x86)\Java\jre-1.8\lib\jce.jar VolumeInformation | Jump to behavior |
Source: C:\Program Files (x86)\Java\jre-1.8\bin\java.exe | Queries volume information: C:\Users\user\AppData\Local\Temp\jartracer.jar VolumeInformation | Jump to behavior |