Windows Analysis Report
SecuriteInfo.com.BackDoor.AgentTeslaNET.20.15021.21756.exe

Overview

General Information

Sample name: SecuriteInfo.com.BackDoor.AgentTeslaNET.20.15021.21756.exe
Analysis ID: 1546266
MD5: af65821d2f5fe034ca3d446323919fc2
SHA1: e76a08a3d02185f0f5d2c03d292e04dcfad7d523
SHA256: 2d84e1e52b7502a8704c99e4a3f0e48ed31904c885ab2577a2b8cbcaff1c3620
Tags: exeFormbook
Infos:

Detection

FormBook
Score: 100
Range: 0 - 100
Whitelisted: false
Confidence: 100%

Signatures

Malicious sample detected (through community Yara rule)
Multi AV Scanner detection for submitted file
Yara detected AntiVM3
Yara detected FormBook
.NET source code contains potential unpacker
AI detected suspicious sample
Adds a directory exclusion to Windows Defender
Injects a PE file into a foreign processes
Loading BitLocker PowerShell Module
Machine Learning detection for sample
Sigma detected: Powershell Base64 Encoded MpPreference Cmdlet
AV process strings found (often used to terminate AV products)
Allocates memory with a write watch (potentially for evading sandboxes)
Checks if the current process is being debugged
Contains functionality for execution timing, often used to detect debuggers
Contains functionality to access loader functionality (e.g. LdrGetProcedureAddress)
Contains functionality to call native functions
Contains functionality to read the PEB
Contains long sleeps (>= 3 min)
Creates a process in suspended mode (likely to inject code)
Detected potential crypto function
Enables debug privileges
Found a high number of Window / User specific system calls (may be a loop to detect user behavior)
Found inlined nop instructions (likely shell or obfuscated code)
Found large amount of non-executed APIs
Found potential string decryption / allocating functions
May sleep (evasive loops) to hinder dynamic analysis
One or more processes crash
Queries the volume information (name, serial number etc) of a device
Sample file is different than original file name gathered from version info
Sigma detected: Powershell Defender Exclusion
Suricata IDS alerts with low severity for network traffic
Uses 32bit PE files
Uses code obfuscation techniques (call, push, ret)
Yara signature match

Classification

AV Detection

barindex
Source: SecuriteInfo.com.BackDoor.AgentTeslaNET.20.15021.21756.exe ReversingLabs: Detection: 55%
Source: Yara match File source: 4.2.SecuriteInfo.com.BackDoor.AgentTeslaNET.20.15021.21756.exe.400000.0.unpack, type: UNPACKEDPE
Source: Yara match File source: 4.2.SecuriteInfo.com.BackDoor.AgentTeslaNET.20.15021.21756.exe.400000.0.raw.unpack, type: UNPACKEDPE
Source: Yara match File source: 00000004.00000002.2454612791.0000000000400000.00000040.00000400.00020000.00000000.sdmp, type: MEMORY
Source: Submited Sample Integrated Neural Analysis Model: Matched 100.0% probability
Source: SecuriteInfo.com.BackDoor.AgentTeslaNET.20.15021.21756.exe Joe Sandbox ML: detected
Source: SecuriteInfo.com.BackDoor.AgentTeslaNET.20.15021.21756.exe Static PE information: EXECUTABLE_IMAGE, 32BIT_MACHINE
Source: SecuriteInfo.com.BackDoor.AgentTeslaNET.20.15021.21756.exe Static PE information: DYNAMIC_BASE, NX_COMPAT, NO_SEH, TERMINAL_SERVER_AWARE
Source: Binary string: wntdll.pdbUGP source: SecuriteInfo.com.BackDoor.AgentTeslaNET.20.15021.21756.exe, 00000004.00000002.2454956185.00000000017D0000.00000040.00001000.00020000.00000000.sdmp
Source: Binary string: wntdll.pdb source: SecuriteInfo.com.BackDoor.AgentTeslaNET.20.15021.21756.exe, SecuriteInfo.com.BackDoor.AgentTeslaNET.20.15021.21756.exe, 00000004.00000002.2454956185.00000000017D0000.00000040.00001000.00020000.00000000.sdmp
Source: C:\Users\user\Desktop\SecuriteInfo.com.BackDoor.AgentTeslaNET.20.15021.21756.exe Code function: 4x nop then jmp 06DC6524h 0_2_06DC5BBC
Source: Network traffic Suricata IDS: 2022930 - Severity 1 - ET EXPLOIT Possible CVE-2016-2211 Symantec Cab Parsing Buffer Overflow : 20.109.210.53:443 -> 192.168.2.4:49748
Source: Network traffic Suricata IDS: 2022930 - Severity 1 - ET EXPLOIT Possible CVE-2016-2211 Symantec Cab Parsing Buffer Overflow : 20.109.210.53:443 -> 192.168.2.4:49735
Source: SecuriteInfo.com.BackDoor.AgentTeslaNET.20.15021.21756.exe, 00000000.00000002.1875968569.0000000002CF0000.00000004.00000800.00020000.00000000.sdmp String found in binary or memory: http://schemas.xmlsoap.org/ws/2005/05/identity/claims/name
Source: SecuriteInfo.com.BackDoor.AgentTeslaNET.20.15021.21756.exe String found in binary or memory: http://tempuri.org/Gamee.xsd7PoisonRoulette.GameResource
Source: Amcache.hve.11.dr String found in binary or memory: http://upx.sf.net
Source: SecuriteInfo.com.BackDoor.AgentTeslaNET.20.15021.21756.exe, 00000000.00000002.1896784883.0000000006E32000.00000004.00000800.00020000.00000000.sdmp String found in binary or memory: http://www.apache.org/licenses/LICENSE-2.0
Source: SecuriteInfo.com.BackDoor.AgentTeslaNET.20.15021.21756.exe, 00000000.00000002.1896784883.0000000006E32000.00000004.00000800.00020000.00000000.sdmp String found in binary or memory: http://www.carterandcone.coml
Source: SecuriteInfo.com.BackDoor.AgentTeslaNET.20.15021.21756.exe, 00000000.00000002.1896784883.0000000006E32000.00000004.00000800.00020000.00000000.sdmp String found in binary or memory: http://www.fontbureau.com
Source: SecuriteInfo.com.BackDoor.AgentTeslaNET.20.15021.21756.exe, 00000000.00000002.1896784883.0000000006E32000.00000004.00000800.00020000.00000000.sdmp String found in binary or memory: http://www.fontbureau.com/designers
Source: SecuriteInfo.com.BackDoor.AgentTeslaNET.20.15021.21756.exe, 00000000.00000002.1896784883.0000000006E32000.00000004.00000800.00020000.00000000.sdmp String found in binary or memory: http://www.fontbureau.com/designers/?
Source: SecuriteInfo.com.BackDoor.AgentTeslaNET.20.15021.21756.exe, 00000000.00000002.1896784883.0000000006E32000.00000004.00000800.00020000.00000000.sdmp String found in binary or memory: http://www.fontbureau.com/designers/cabarga.htmlN
Source: SecuriteInfo.com.BackDoor.AgentTeslaNET.20.15021.21756.exe, 00000000.00000002.1896784883.0000000006E32000.00000004.00000800.00020000.00000000.sdmp String found in binary or memory: http://www.fontbureau.com/designers/frere-user.html
Source: SecuriteInfo.com.BackDoor.AgentTeslaNET.20.15021.21756.exe, 00000000.00000002.1896784883.0000000006E32000.00000004.00000800.00020000.00000000.sdmp String found in binary or memory: http://www.fontbureau.com/designers8
Source: SecuriteInfo.com.BackDoor.AgentTeslaNET.20.15021.21756.exe, 00000000.00000002.1896784883.0000000006E32000.00000004.00000800.00020000.00000000.sdmp String found in binary or memory: http://www.fontbureau.com/designers?
Source: SecuriteInfo.com.BackDoor.AgentTeslaNET.20.15021.21756.exe, 00000000.00000002.1896784883.0000000006E32000.00000004.00000800.00020000.00000000.sdmp String found in binary or memory: http://www.fontbureau.com/designersG
Source: SecuriteInfo.com.BackDoor.AgentTeslaNET.20.15021.21756.exe, 00000000.00000002.1896784883.0000000006E32000.00000004.00000800.00020000.00000000.sdmp String found in binary or memory: http://www.fonts.com
Source: SecuriteInfo.com.BackDoor.AgentTeslaNET.20.15021.21756.exe, 00000000.00000002.1896784883.0000000006E32000.00000004.00000800.00020000.00000000.sdmp String found in binary or memory: http://www.founder.com.cn/cn
Source: SecuriteInfo.com.BackDoor.AgentTeslaNET.20.15021.21756.exe, 00000000.00000002.1896784883.0000000006E32000.00000004.00000800.00020000.00000000.sdmp String found in binary or memory: http://www.founder.com.cn/cn/bThe
Source: SecuriteInfo.com.BackDoor.AgentTeslaNET.20.15021.21756.exe, 00000000.00000002.1896784883.0000000006E32000.00000004.00000800.00020000.00000000.sdmp String found in binary or memory: http://www.founder.com.cn/cn/cThe
Source: SecuriteInfo.com.BackDoor.AgentTeslaNET.20.15021.21756.exe, 00000000.00000002.1896784883.0000000006E32000.00000004.00000800.00020000.00000000.sdmp String found in binary or memory: http://www.galapagosdesign.com/DPlease
Source: SecuriteInfo.com.BackDoor.AgentTeslaNET.20.15021.21756.exe, 00000000.00000002.1896784883.0000000006E32000.00000004.00000800.00020000.00000000.sdmp String found in binary or memory: http://www.galapagosdesign.com/staff/dennis.htm
Source: SecuriteInfo.com.BackDoor.AgentTeslaNET.20.15021.21756.exe, 00000000.00000002.1896784883.0000000006E32000.00000004.00000800.00020000.00000000.sdmp String found in binary or memory: http://www.goodfont.co.kr
Source: SecuriteInfo.com.BackDoor.AgentTeslaNET.20.15021.21756.exe, 00000000.00000002.1896784883.0000000006E32000.00000004.00000800.00020000.00000000.sdmp String found in binary or memory: http://www.jiyu-kobo.co.jp/
Source: SecuriteInfo.com.BackDoor.AgentTeslaNET.20.15021.21756.exe, 00000000.00000002.1896784883.0000000006E32000.00000004.00000800.00020000.00000000.sdmp String found in binary or memory: http://www.sajatypeworks.com
Source: SecuriteInfo.com.BackDoor.AgentTeslaNET.20.15021.21756.exe, 00000000.00000002.1896784883.0000000006E32000.00000004.00000800.00020000.00000000.sdmp, SecuriteInfo.com.BackDoor.AgentTeslaNET.20.15021.21756.exe, 00000000.00000002.1896055683.0000000005750000.00000004.00000020.00020000.00000000.sdmp String found in binary or memory: http://www.sakkal.com
Source: SecuriteInfo.com.BackDoor.AgentTeslaNET.20.15021.21756.exe, 00000000.00000002.1896784883.0000000006E32000.00000004.00000800.00020000.00000000.sdmp String found in binary or memory: http://www.sandoll.co.kr
Source: SecuriteInfo.com.BackDoor.AgentTeslaNET.20.15021.21756.exe, 00000000.00000002.1896784883.0000000006E32000.00000004.00000800.00020000.00000000.sdmp String found in binary or memory: http://www.tiro.com
Source: SecuriteInfo.com.BackDoor.AgentTeslaNET.20.15021.21756.exe, 00000000.00000002.1896784883.0000000006E32000.00000004.00000800.00020000.00000000.sdmp String found in binary or memory: http://www.typography.netD
Source: SecuriteInfo.com.BackDoor.AgentTeslaNET.20.15021.21756.exe, 00000000.00000002.1896784883.0000000006E32000.00000004.00000800.00020000.00000000.sdmp String found in binary or memory: http://www.urwpp.deDPlease
Source: SecuriteInfo.com.BackDoor.AgentTeslaNET.20.15021.21756.exe, 00000000.00000002.1896784883.0000000006E32000.00000004.00000800.00020000.00000000.sdmp String found in binary or memory: http://www.zhongyicts.com.cn

E-Banking Fraud

barindex
Source: Yara match File source: 4.2.SecuriteInfo.com.BackDoor.AgentTeslaNET.20.15021.21756.exe.400000.0.unpack, type: UNPACKEDPE
Source: Yara match File source: 4.2.SecuriteInfo.com.BackDoor.AgentTeslaNET.20.15021.21756.exe.400000.0.raw.unpack, type: UNPACKEDPE
Source: Yara match File source: 00000004.00000002.2454612791.0000000000400000.00000040.00000400.00020000.00000000.sdmp, type: MEMORY

System Summary

barindex
Source: 4.2.SecuriteInfo.com.BackDoor.AgentTeslaNET.20.15021.21756.exe.400000.0.unpack, type: UNPACKEDPE Matched rule: Windows_Trojan_Formbook_1112e116 Author: unknown
Source: 4.2.SecuriteInfo.com.BackDoor.AgentTeslaNET.20.15021.21756.exe.400000.0.raw.unpack, type: UNPACKEDPE Matched rule: Windows_Trojan_Formbook_1112e116 Author: unknown
Source: 00000004.00000002.2454612791.0000000000400000.00000040.00000400.00020000.00000000.sdmp, type: MEMORY Matched rule: Windows_Trojan_Formbook_1112e116 Author: unknown
Source: C:\Users\user\Desktop\SecuriteInfo.com.BackDoor.AgentTeslaNET.20.15021.21756.exe Code function: 4_2_0042C923 NtClose, 4_2_0042C923
Source: C:\Users\user\Desktop\SecuriteInfo.com.BackDoor.AgentTeslaNET.20.15021.21756.exe Code function: 4_2_01842DF0 NtQuerySystemInformation,LdrInitializeThunk, 4_2_01842DF0
Source: C:\Users\user\Desktop\SecuriteInfo.com.BackDoor.AgentTeslaNET.20.15021.21756.exe Code function: 4_2_01844340 NtSetContextThread, 4_2_01844340
Source: C:\Users\user\Desktop\SecuriteInfo.com.BackDoor.AgentTeslaNET.20.15021.21756.exe Code function: 4_2_01844650 NtSuspendThread, 4_2_01844650
Source: C:\Users\user\Desktop\SecuriteInfo.com.BackDoor.AgentTeslaNET.20.15021.21756.exe Code function: 4_2_01842B80 NtQueryInformationFile, 4_2_01842B80
Source: C:\Users\user\Desktop\SecuriteInfo.com.BackDoor.AgentTeslaNET.20.15021.21756.exe Code function: 4_2_01842BA0 NtEnumerateValueKey, 4_2_01842BA0
Source: C:\Users\user\Desktop\SecuriteInfo.com.BackDoor.AgentTeslaNET.20.15021.21756.exe Code function: 4_2_01842BE0 NtQueryValueKey, 4_2_01842BE0
Source: C:\Users\user\Desktop\SecuriteInfo.com.BackDoor.AgentTeslaNET.20.15021.21756.exe Code function: 4_2_01842BF0 NtAllocateVirtualMemory, 4_2_01842BF0
Source: C:\Users\user\Desktop\SecuriteInfo.com.BackDoor.AgentTeslaNET.20.15021.21756.exe Code function: 4_2_01842B60 NtClose, 4_2_01842B60
Source: C:\Users\user\Desktop\SecuriteInfo.com.BackDoor.AgentTeslaNET.20.15021.21756.exe Code function: 4_2_01842AB0 NtWaitForSingleObject, 4_2_01842AB0
Source: C:\Users\user\Desktop\SecuriteInfo.com.BackDoor.AgentTeslaNET.20.15021.21756.exe Code function: 4_2_01842AD0 NtReadFile, 4_2_01842AD0
Source: C:\Users\user\Desktop\SecuriteInfo.com.BackDoor.AgentTeslaNET.20.15021.21756.exe Code function: 4_2_01842AF0 NtWriteFile, 4_2_01842AF0
Source: C:\Users\user\Desktop\SecuriteInfo.com.BackDoor.AgentTeslaNET.20.15021.21756.exe Code function: 4_2_01842DB0 NtEnumerateKey, 4_2_01842DB0
Source: C:\Users\user\Desktop\SecuriteInfo.com.BackDoor.AgentTeslaNET.20.15021.21756.exe Code function: 4_2_01842DD0 NtDelayExecution, 4_2_01842DD0
Source: C:\Users\user\Desktop\SecuriteInfo.com.BackDoor.AgentTeslaNET.20.15021.21756.exe Code function: 4_2_01842D00 NtSetInformationFile, 4_2_01842D00
Source: C:\Users\user\Desktop\SecuriteInfo.com.BackDoor.AgentTeslaNET.20.15021.21756.exe Code function: 4_2_01842D10 NtMapViewOfSection, 4_2_01842D10
Source: C:\Users\user\Desktop\SecuriteInfo.com.BackDoor.AgentTeslaNET.20.15021.21756.exe Code function: 4_2_01842D30 NtUnmapViewOfSection, 4_2_01842D30
Source: C:\Users\user\Desktop\SecuriteInfo.com.BackDoor.AgentTeslaNET.20.15021.21756.exe Code function: 4_2_01842CA0 NtQueryInformationToken, 4_2_01842CA0
Source: C:\Users\user\Desktop\SecuriteInfo.com.BackDoor.AgentTeslaNET.20.15021.21756.exe Code function: 4_2_01842CC0 NtQueryVirtualMemory, 4_2_01842CC0
Source: C:\Users\user\Desktop\SecuriteInfo.com.BackDoor.AgentTeslaNET.20.15021.21756.exe Code function: 4_2_01842CF0 NtOpenProcess, 4_2_01842CF0
Source: C:\Users\user\Desktop\SecuriteInfo.com.BackDoor.AgentTeslaNET.20.15021.21756.exe Code function: 4_2_01842C00 NtQueryInformationProcess, 4_2_01842C00
Source: C:\Users\user\Desktop\SecuriteInfo.com.BackDoor.AgentTeslaNET.20.15021.21756.exe Code function: 4_2_01842C60 NtCreateKey, 4_2_01842C60
Source: C:\Users\user\Desktop\SecuriteInfo.com.BackDoor.AgentTeslaNET.20.15021.21756.exe Code function: 4_2_01842C70 NtFreeVirtualMemory, 4_2_01842C70
Source: C:\Users\user\Desktop\SecuriteInfo.com.BackDoor.AgentTeslaNET.20.15021.21756.exe Code function: 4_2_01842F90 NtProtectVirtualMemory, 4_2_01842F90
Source: C:\Users\user\Desktop\SecuriteInfo.com.BackDoor.AgentTeslaNET.20.15021.21756.exe Code function: 4_2_01842FA0 NtQuerySection, 4_2_01842FA0
Source: C:\Users\user\Desktop\SecuriteInfo.com.BackDoor.AgentTeslaNET.20.15021.21756.exe Code function: 4_2_01842FB0 NtResumeThread, 4_2_01842FB0
Source: C:\Users\user\Desktop\SecuriteInfo.com.BackDoor.AgentTeslaNET.20.15021.21756.exe Code function: 4_2_01842FE0 NtCreateFile, 4_2_01842FE0
Source: C:\Users\user\Desktop\SecuriteInfo.com.BackDoor.AgentTeslaNET.20.15021.21756.exe Code function: 4_2_01842F30 NtCreateSection, 4_2_01842F30
Source: C:\Users\user\Desktop\SecuriteInfo.com.BackDoor.AgentTeslaNET.20.15021.21756.exe Code function: 4_2_01842F60 NtCreateProcessEx, 4_2_01842F60
Source: C:\Users\user\Desktop\SecuriteInfo.com.BackDoor.AgentTeslaNET.20.15021.21756.exe Code function: 4_2_01842E80 NtReadVirtualMemory, 4_2_01842E80
Source: C:\Users\user\Desktop\SecuriteInfo.com.BackDoor.AgentTeslaNET.20.15021.21756.exe Code function: 4_2_01842EA0 NtAdjustPrivilegesToken, 4_2_01842EA0
Source: C:\Users\user\Desktop\SecuriteInfo.com.BackDoor.AgentTeslaNET.20.15021.21756.exe Code function: 4_2_01842EE0 NtQueueApcThread, 4_2_01842EE0
Source: C:\Users\user\Desktop\SecuriteInfo.com.BackDoor.AgentTeslaNET.20.15021.21756.exe Code function: 4_2_01842E30 NtWriteVirtualMemory, 4_2_01842E30
Source: C:\Users\user\Desktop\SecuriteInfo.com.BackDoor.AgentTeslaNET.20.15021.21756.exe Code function: 4_2_01843090 NtSetValueKey, 4_2_01843090
Source: C:\Users\user\Desktop\SecuriteInfo.com.BackDoor.AgentTeslaNET.20.15021.21756.exe Code function: 4_2_01843010 NtOpenDirectoryObject, 4_2_01843010
Source: C:\Users\user\Desktop\SecuriteInfo.com.BackDoor.AgentTeslaNET.20.15021.21756.exe Code function: 4_2_018435C0 NtCreateMutant, 4_2_018435C0
Source: C:\Users\user\Desktop\SecuriteInfo.com.BackDoor.AgentTeslaNET.20.15021.21756.exe Code function: 4_2_018439B0 NtGetContextThread, 4_2_018439B0
Source: C:\Users\user\Desktop\SecuriteInfo.com.BackDoor.AgentTeslaNET.20.15021.21756.exe Code function: 4_2_01843D10 NtOpenProcessToken, 4_2_01843D10
Source: C:\Users\user\Desktop\SecuriteInfo.com.BackDoor.AgentTeslaNET.20.15021.21756.exe Code function: 4_2_01843D70 NtOpenThread, 4_2_01843D70
Source: C:\Users\user\Desktop\SecuriteInfo.com.BackDoor.AgentTeslaNET.20.15021.21756.exe Code function: 0_2_051CDB8C 0_2_051CDB8C
Source: C:\Users\user\Desktop\SecuriteInfo.com.BackDoor.AgentTeslaNET.20.15021.21756.exe Code function: 0_2_06DC7AE0 0_2_06DC7AE0
Source: C:\Users\user\Desktop\SecuriteInfo.com.BackDoor.AgentTeslaNET.20.15021.21756.exe Code function: 0_2_06DC16E8 0_2_06DC16E8
Source: C:\Users\user\Desktop\SecuriteInfo.com.BackDoor.AgentTeslaNET.20.15021.21756.exe Code function: 0_2_06DC3600 0_2_06DC3600
Source: C:\Users\user\Desktop\SecuriteInfo.com.BackDoor.AgentTeslaNET.20.15021.21756.exe Code function: 0_2_06DC12B0 0_2_06DC12B0
Source: C:\Users\user\Desktop\SecuriteInfo.com.BackDoor.AgentTeslaNET.20.15021.21756.exe Code function: 0_2_06DC127C 0_2_06DC127C
Source: C:\Users\user\Desktop\SecuriteInfo.com.BackDoor.AgentTeslaNET.20.15021.21756.exe Code function: 0_2_06DC31C8 0_2_06DC31C8
Source: C:\Users\user\Desktop\SecuriteInfo.com.BackDoor.AgentTeslaNET.20.15021.21756.exe Code function: 0_2_06DC2D90 0_2_06DC2D90
Source: C:\Users\user\Desktop\SecuriteInfo.com.BackDoor.AgentTeslaNET.20.15021.21756.exe Code function: 0_2_09107859 0_2_09107859
Source: C:\Users\user\Desktop\SecuriteInfo.com.BackDoor.AgentTeslaNET.20.15021.21756.exe Code function: 0_2_09106182 0_2_09106182
Source: C:\Users\user\Desktop\SecuriteInfo.com.BackDoor.AgentTeslaNET.20.15021.21756.exe Code function: 0_2_09100378 0_2_09100378
Source: C:\Users\user\Desktop\SecuriteInfo.com.BackDoor.AgentTeslaNET.20.15021.21756.exe Code function: 0_2_0910A8B0 0_2_0910A8B0
Source: C:\Users\user\Desktop\SecuriteInfo.com.BackDoor.AgentTeslaNET.20.15021.21756.exe Code function: 0_2_0910A8A0 0_2_0910A8A0
Source: C:\Users\user\Desktop\SecuriteInfo.com.BackDoor.AgentTeslaNET.20.15021.21756.exe Code function: 0_2_0910AB39 0_2_0910AB39
Source: C:\Users\user\Desktop\SecuriteInfo.com.BackDoor.AgentTeslaNET.20.15021.21756.exe Code function: 0_2_0910AB48 0_2_0910AB48
Source: C:\Users\user\Desktop\SecuriteInfo.com.BackDoor.AgentTeslaNET.20.15021.21756.exe Code function: 0_2_09109C90 0_2_09109C90
Source: C:\Users\user\Desktop\SecuriteInfo.com.BackDoor.AgentTeslaNET.20.15021.21756.exe Code function: 0_2_09100369 0_2_09100369
Source: C:\Users\user\Desktop\SecuriteInfo.com.BackDoor.AgentTeslaNET.20.15021.21756.exe Code function: 4_2_00410103 4_2_00410103
Source: C:\Users\user\Desktop\SecuriteInfo.com.BackDoor.AgentTeslaNET.20.15021.21756.exe Code function: 4_2_00402921 4_2_00402921
Source: C:\Users\user\Desktop\SecuriteInfo.com.BackDoor.AgentTeslaNET.20.15021.21756.exe Code function: 4_2_00402930 4_2_00402930
Source: C:\Users\user\Desktop\SecuriteInfo.com.BackDoor.AgentTeslaNET.20.15021.21756.exe Code function: 4_2_004011C0 4_2_004011C0
Source: C:\Users\user\Desktop\SecuriteInfo.com.BackDoor.AgentTeslaNET.20.15021.21756.exe Code function: 4_2_004031A0 4_2_004031A0
Source: C:\Users\user\Desktop\SecuriteInfo.com.BackDoor.AgentTeslaNET.20.15021.21756.exe Code function: 4_2_00416A7E 4_2_00416A7E
Source: C:\Users\user\Desktop\SecuriteInfo.com.BackDoor.AgentTeslaNET.20.15021.21756.exe Code function: 4_2_00416A83 4_2_00416A83
Source: C:\Users\user\Desktop\SecuriteInfo.com.BackDoor.AgentTeslaNET.20.15021.21756.exe Code function: 4_2_00410323 4_2_00410323
Source: C:\Users\user\Desktop\SecuriteInfo.com.BackDoor.AgentTeslaNET.20.15021.21756.exe Code function: 4_2_0040E3A3 4_2_0040E3A3
Source: C:\Users\user\Desktop\SecuriteInfo.com.BackDoor.AgentTeslaNET.20.15021.21756.exe Code function: 4_2_0040E4E7 4_2_0040E4E7
Source: C:\Users\user\Desktop\SecuriteInfo.com.BackDoor.AgentTeslaNET.20.15021.21756.exe Code function: 4_2_00402600 4_2_00402600
Source: C:\Users\user\Desktop\SecuriteInfo.com.BackDoor.AgentTeslaNET.20.15021.21756.exe Code function: 4_2_0042EF53 4_2_0042EF53
Source: C:\Users\user\Desktop\SecuriteInfo.com.BackDoor.AgentTeslaNET.20.15021.21756.exe Code function: 4_2_018D01AA 4_2_018D01AA
Source: C:\Users\user\Desktop\SecuriteInfo.com.BackDoor.AgentTeslaNET.20.15021.21756.exe Code function: 4_2_018C41A2 4_2_018C41A2
Source: C:\Users\user\Desktop\SecuriteInfo.com.BackDoor.AgentTeslaNET.20.15021.21756.exe Code function: 4_2_018C81CC 4_2_018C81CC
Source: C:\Users\user\Desktop\SecuriteInfo.com.BackDoor.AgentTeslaNET.20.15021.21756.exe Code function: 4_2_01800100 4_2_01800100
Source: C:\Users\user\Desktop\SecuriteInfo.com.BackDoor.AgentTeslaNET.20.15021.21756.exe Code function: 4_2_018AA118 4_2_018AA118
Source: C:\Users\user\Desktop\SecuriteInfo.com.BackDoor.AgentTeslaNET.20.15021.21756.exe Code function: 4_2_01898158 4_2_01898158
Source: C:\Users\user\Desktop\SecuriteInfo.com.BackDoor.AgentTeslaNET.20.15021.21756.exe Code function: 4_2_018A2000 4_2_018A2000
Source: C:\Users\user\Desktop\SecuriteInfo.com.BackDoor.AgentTeslaNET.20.15021.21756.exe Code function: 4_2_018D03E6 4_2_018D03E6
Source: C:\Users\user\Desktop\SecuriteInfo.com.BackDoor.AgentTeslaNET.20.15021.21756.exe Code function: 4_2_0181E3F0 4_2_0181E3F0
Source: C:\Users\user\Desktop\SecuriteInfo.com.BackDoor.AgentTeslaNET.20.15021.21756.exe Code function: 4_2_018CA352 4_2_018CA352
Source: C:\Users\user\Desktop\SecuriteInfo.com.BackDoor.AgentTeslaNET.20.15021.21756.exe Code function: 4_2_018902C0 4_2_018902C0
Source: C:\Users\user\Desktop\SecuriteInfo.com.BackDoor.AgentTeslaNET.20.15021.21756.exe Code function: 4_2_018B0274 4_2_018B0274
Source: C:\Users\user\Desktop\SecuriteInfo.com.BackDoor.AgentTeslaNET.20.15021.21756.exe Code function: 4_2_018D0591 4_2_018D0591
Source: C:\Users\user\Desktop\SecuriteInfo.com.BackDoor.AgentTeslaNET.20.15021.21756.exe Code function: 4_2_01810535 4_2_01810535
Source: C:\Users\user\Desktop\SecuriteInfo.com.BackDoor.AgentTeslaNET.20.15021.21756.exe Code function: 4_2_018BE4F6 4_2_018BE4F6
Source: C:\Users\user\Desktop\SecuriteInfo.com.BackDoor.AgentTeslaNET.20.15021.21756.exe Code function: 4_2_018B4420 4_2_018B4420
Source: C:\Users\user\Desktop\SecuriteInfo.com.BackDoor.AgentTeslaNET.20.15021.21756.exe Code function: 4_2_018C2446 4_2_018C2446
Source: C:\Users\user\Desktop\SecuriteInfo.com.BackDoor.AgentTeslaNET.20.15021.21756.exe Code function: 4_2_0180C7C0 4_2_0180C7C0
Source: C:\Users\user\Desktop\SecuriteInfo.com.BackDoor.AgentTeslaNET.20.15021.21756.exe Code function: 4_2_01834750 4_2_01834750
Source: C:\Users\user\Desktop\SecuriteInfo.com.BackDoor.AgentTeslaNET.20.15021.21756.exe Code function: 4_2_01810770 4_2_01810770
Source: C:\Users\user\Desktop\SecuriteInfo.com.BackDoor.AgentTeslaNET.20.15021.21756.exe Code function: 4_2_0182C6E0 4_2_0182C6E0
Source: C:\Users\user\Desktop\SecuriteInfo.com.BackDoor.AgentTeslaNET.20.15021.21756.exe Code function: 4_2_018129A0 4_2_018129A0
Source: C:\Users\user\Desktop\SecuriteInfo.com.BackDoor.AgentTeslaNET.20.15021.21756.exe Code function: 4_2_018DA9A6 4_2_018DA9A6
Source: C:\Users\user\Desktop\SecuriteInfo.com.BackDoor.AgentTeslaNET.20.15021.21756.exe Code function: 4_2_01826962 4_2_01826962
Source: C:\Users\user\Desktop\SecuriteInfo.com.BackDoor.AgentTeslaNET.20.15021.21756.exe Code function: 4_2_0183E8F0 4_2_0183E8F0
Source: C:\Users\user\Desktop\SecuriteInfo.com.BackDoor.AgentTeslaNET.20.15021.21756.exe Code function: 4_2_0181A840 4_2_0181A840
Source: C:\Users\user\Desktop\SecuriteInfo.com.BackDoor.AgentTeslaNET.20.15021.21756.exe Code function: 4_2_01812840 4_2_01812840
Source: C:\Users\user\Desktop\SecuriteInfo.com.BackDoor.AgentTeslaNET.20.15021.21756.exe Code function: 4_2_017F68B8 4_2_017F68B8
Source: C:\Users\user\Desktop\SecuriteInfo.com.BackDoor.AgentTeslaNET.20.15021.21756.exe Code function: 4_2_018C6BD7 4_2_018C6BD7
Source: C:\Users\user\Desktop\SecuriteInfo.com.BackDoor.AgentTeslaNET.20.15021.21756.exe Code function: 4_2_018CAB40 4_2_018CAB40
Source: C:\Users\user\Desktop\SecuriteInfo.com.BackDoor.AgentTeslaNET.20.15021.21756.exe Code function: 4_2_0180EA80 4_2_0180EA80
Source: C:\Users\user\Desktop\SecuriteInfo.com.BackDoor.AgentTeslaNET.20.15021.21756.exe Code function: 4_2_01828DBF 4_2_01828DBF
Source: C:\Users\user\Desktop\SecuriteInfo.com.BackDoor.AgentTeslaNET.20.15021.21756.exe Code function: 4_2_0180ADE0 4_2_0180ADE0
Source: C:\Users\user\Desktop\SecuriteInfo.com.BackDoor.AgentTeslaNET.20.15021.21756.exe Code function: 4_2_0181AD00 4_2_0181AD00
Source: C:\Users\user\Desktop\SecuriteInfo.com.BackDoor.AgentTeslaNET.20.15021.21756.exe Code function: 4_2_018ACD1F 4_2_018ACD1F
Source: C:\Users\user\Desktop\SecuriteInfo.com.BackDoor.AgentTeslaNET.20.15021.21756.exe Code function: 4_2_018B0CB5 4_2_018B0CB5
Source: C:\Users\user\Desktop\SecuriteInfo.com.BackDoor.AgentTeslaNET.20.15021.21756.exe Code function: 4_2_01800CF2 4_2_01800CF2
Source: C:\Users\user\Desktop\SecuriteInfo.com.BackDoor.AgentTeslaNET.20.15021.21756.exe Code function: 4_2_01810C00 4_2_01810C00
Source: C:\Users\user\Desktop\SecuriteInfo.com.BackDoor.AgentTeslaNET.20.15021.21756.exe Code function: 4_2_0188EFA0 4_2_0188EFA0
Source: C:\Users\user\Desktop\SecuriteInfo.com.BackDoor.AgentTeslaNET.20.15021.21756.exe Code function: 4_2_01802FC8 4_2_01802FC8
Source: C:\Users\user\Desktop\SecuriteInfo.com.BackDoor.AgentTeslaNET.20.15021.21756.exe Code function: 4_2_01852F28 4_2_01852F28
Source: C:\Users\user\Desktop\SecuriteInfo.com.BackDoor.AgentTeslaNET.20.15021.21756.exe Code function: 4_2_01830F30 4_2_01830F30
Source: C:\Users\user\Desktop\SecuriteInfo.com.BackDoor.AgentTeslaNET.20.15021.21756.exe Code function: 4_2_018B2F30 4_2_018B2F30
Source: C:\Users\user\Desktop\SecuriteInfo.com.BackDoor.AgentTeslaNET.20.15021.21756.exe Code function: 4_2_01884F40 4_2_01884F40
Source: C:\Users\user\Desktop\SecuriteInfo.com.BackDoor.AgentTeslaNET.20.15021.21756.exe Code function: 4_2_01822E90 4_2_01822E90
Source: C:\Users\user\Desktop\SecuriteInfo.com.BackDoor.AgentTeslaNET.20.15021.21756.exe Code function: 4_2_018CCE93 4_2_018CCE93
Source: C:\Users\user\Desktop\SecuriteInfo.com.BackDoor.AgentTeslaNET.20.15021.21756.exe Code function: 4_2_018CEEDB 4_2_018CEEDB
Source: C:\Users\user\Desktop\SecuriteInfo.com.BackDoor.AgentTeslaNET.20.15021.21756.exe Code function: 4_2_018CEE26 4_2_018CEE26
Source: C:\Users\user\Desktop\SecuriteInfo.com.BackDoor.AgentTeslaNET.20.15021.21756.exe Code function: 4_2_01810E59 4_2_01810E59
Source: C:\Users\user\Desktop\SecuriteInfo.com.BackDoor.AgentTeslaNET.20.15021.21756.exe Code function: 4_2_017FF172 4_2_017FF172
Source: C:\Users\user\Desktop\SecuriteInfo.com.BackDoor.AgentTeslaNET.20.15021.21756.exe Code function: 4_2_0181B1B0 4_2_0181B1B0
Source: C:\Users\user\Desktop\SecuriteInfo.com.BackDoor.AgentTeslaNET.20.15021.21756.exe Code function: 4_2_018DB16B 4_2_018DB16B
Source: C:\Users\user\Desktop\SecuriteInfo.com.BackDoor.AgentTeslaNET.20.15021.21756.exe Code function: 4_2_0184516C 4_2_0184516C
Source: C:\Users\user\Desktop\SecuriteInfo.com.BackDoor.AgentTeslaNET.20.15021.21756.exe Code function: 4_2_018170C0 4_2_018170C0
Source: C:\Users\user\Desktop\SecuriteInfo.com.BackDoor.AgentTeslaNET.20.15021.21756.exe Code function: 4_2_018BF0CC 4_2_018BF0CC
Source: C:\Users\user\Desktop\SecuriteInfo.com.BackDoor.AgentTeslaNET.20.15021.21756.exe Code function: 4_2_018C70E9 4_2_018C70E9
Source: C:\Users\user\Desktop\SecuriteInfo.com.BackDoor.AgentTeslaNET.20.15021.21756.exe Code function: 4_2_018CF0E0 4_2_018CF0E0
Source: C:\Users\user\Desktop\SecuriteInfo.com.BackDoor.AgentTeslaNET.20.15021.21756.exe Code function: 4_2_0185739A 4_2_0185739A
Source: C:\Users\user\Desktop\SecuriteInfo.com.BackDoor.AgentTeslaNET.20.15021.21756.exe Code function: 4_2_017FD34C 4_2_017FD34C
Source: C:\Users\user\Desktop\SecuriteInfo.com.BackDoor.AgentTeslaNET.20.15021.21756.exe Code function: 4_2_018C132D 4_2_018C132D
Source: C:\Users\user\Desktop\SecuriteInfo.com.BackDoor.AgentTeslaNET.20.15021.21756.exe Code function: 4_2_018152A0 4_2_018152A0
Source: C:\Users\user\Desktop\SecuriteInfo.com.BackDoor.AgentTeslaNET.20.15021.21756.exe Code function: 4_2_0182B2C0 4_2_0182B2C0
Source: C:\Users\user\Desktop\SecuriteInfo.com.BackDoor.AgentTeslaNET.20.15021.21756.exe Code function: 4_2_018B12ED 4_2_018B12ED
Source: C:\Users\user\Desktop\SecuriteInfo.com.BackDoor.AgentTeslaNET.20.15021.21756.exe Code function: 4_2_018AD5B0 4_2_018AD5B0
Source: C:\Users\user\Desktop\SecuriteInfo.com.BackDoor.AgentTeslaNET.20.15021.21756.exe Code function: 4_2_018D95C3 4_2_018D95C3
Source: C:\Users\user\Desktop\SecuriteInfo.com.BackDoor.AgentTeslaNET.20.15021.21756.exe Code function: 4_2_018C7571 4_2_018C7571
Source: C:\Users\user\Desktop\SecuriteInfo.com.BackDoor.AgentTeslaNET.20.15021.21756.exe Code function: 4_2_018CF43F 4_2_018CF43F
Source: C:\Users\user\Desktop\SecuriteInfo.com.BackDoor.AgentTeslaNET.20.15021.21756.exe Code function: 4_2_01801460 4_2_01801460
Source: C:\Users\user\Desktop\SecuriteInfo.com.BackDoor.AgentTeslaNET.20.15021.21756.exe Code function: 4_2_018CF7B0 4_2_018CF7B0
Source: C:\Users\user\Desktop\SecuriteInfo.com.BackDoor.AgentTeslaNET.20.15021.21756.exe Code function: 4_2_018C16CC 4_2_018C16CC
Source: C:\Users\user\Desktop\SecuriteInfo.com.BackDoor.AgentTeslaNET.20.15021.21756.exe Code function: 4_2_01855630 4_2_01855630
Source: C:\Users\user\Desktop\SecuriteInfo.com.BackDoor.AgentTeslaNET.20.15021.21756.exe Code function: 4_2_018A5910 4_2_018A5910
Source: C:\Users\user\Desktop\SecuriteInfo.com.BackDoor.AgentTeslaNET.20.15021.21756.exe Code function: 4_2_01819950 4_2_01819950
Source: C:\Users\user\Desktop\SecuriteInfo.com.BackDoor.AgentTeslaNET.20.15021.21756.exe Code function: 4_2_0182B950 4_2_0182B950
Source: C:\Users\user\Desktop\SecuriteInfo.com.BackDoor.AgentTeslaNET.20.15021.21756.exe Code function: 4_2_018138E0 4_2_018138E0
Source: C:\Users\user\Desktop\SecuriteInfo.com.BackDoor.AgentTeslaNET.20.15021.21756.exe Code function: 4_2_0187D800 4_2_0187D800
Source: C:\Users\user\Desktop\SecuriteInfo.com.BackDoor.AgentTeslaNET.20.15021.21756.exe Code function: 4_2_0182FB80 4_2_0182FB80
Source: C:\Users\user\Desktop\SecuriteInfo.com.BackDoor.AgentTeslaNET.20.15021.21756.exe Code function: 4_2_01885BF0 4_2_01885BF0
Source: C:\Users\user\Desktop\SecuriteInfo.com.BackDoor.AgentTeslaNET.20.15021.21756.exe Code function: 4_2_0184DBF9 4_2_0184DBF9
Source: C:\Users\user\Desktop\SecuriteInfo.com.BackDoor.AgentTeslaNET.20.15021.21756.exe Code function: 4_2_018CFB76 4_2_018CFB76
Source: C:\Users\user\Desktop\SecuriteInfo.com.BackDoor.AgentTeslaNET.20.15021.21756.exe Code function: 4_2_01855AA0 4_2_01855AA0
Source: C:\Users\user\Desktop\SecuriteInfo.com.BackDoor.AgentTeslaNET.20.15021.21756.exe Code function: 4_2_018ADAAC 4_2_018ADAAC
Source: C:\Users\user\Desktop\SecuriteInfo.com.BackDoor.AgentTeslaNET.20.15021.21756.exe Code function: 4_2_018B1AA3 4_2_018B1AA3
Source: C:\Users\user\Desktop\SecuriteInfo.com.BackDoor.AgentTeslaNET.20.15021.21756.exe Code function: 4_2_018BDAC6 4_2_018BDAC6
Source: C:\Users\user\Desktop\SecuriteInfo.com.BackDoor.AgentTeslaNET.20.15021.21756.exe Code function: 4_2_018CFA49 4_2_018CFA49
Source: C:\Users\user\Desktop\SecuriteInfo.com.BackDoor.AgentTeslaNET.20.15021.21756.exe Code function: 4_2_018C7A46 4_2_018C7A46
Source: C:\Users\user\Desktop\SecuriteInfo.com.BackDoor.AgentTeslaNET.20.15021.21756.exe Code function: 4_2_01883A6C 4_2_01883A6C
Source: C:\Users\user\Desktop\SecuriteInfo.com.BackDoor.AgentTeslaNET.20.15021.21756.exe Code function: 4_2_0182FDC0 4_2_0182FDC0
Source: C:\Users\user\Desktop\SecuriteInfo.com.BackDoor.AgentTeslaNET.20.15021.21756.exe Code function: 4_2_01813D40 4_2_01813D40
Source: C:\Users\user\Desktop\SecuriteInfo.com.BackDoor.AgentTeslaNET.20.15021.21756.exe Code function: 4_2_018C1D5A 4_2_018C1D5A
Source: C:\Users\user\Desktop\SecuriteInfo.com.BackDoor.AgentTeslaNET.20.15021.21756.exe Code function: 4_2_018C7D73 4_2_018C7D73
Source: C:\Users\user\Desktop\SecuriteInfo.com.BackDoor.AgentTeslaNET.20.15021.21756.exe Code function: 4_2_018CFCF2 4_2_018CFCF2
Source: C:\Users\user\Desktop\SecuriteInfo.com.BackDoor.AgentTeslaNET.20.15021.21756.exe Code function: 4_2_01889C32 4_2_01889C32
Source: C:\Users\user\Desktop\SecuriteInfo.com.BackDoor.AgentTeslaNET.20.15021.21756.exe Code function: 4_2_01811F92 4_2_01811F92
Source: C:\Users\user\Desktop\SecuriteInfo.com.BackDoor.AgentTeslaNET.20.15021.21756.exe Code function: 4_2_018CFFB1 4_2_018CFFB1
Source: C:\Users\user\Desktop\SecuriteInfo.com.BackDoor.AgentTeslaNET.20.15021.21756.exe Code function: 4_2_018CFF09 4_2_018CFF09
Source: C:\Users\user\Desktop\SecuriteInfo.com.BackDoor.AgentTeslaNET.20.15021.21756.exe Code function: 4_2_017D3FD5 4_2_017D3FD5
Source: C:\Users\user\Desktop\SecuriteInfo.com.BackDoor.AgentTeslaNET.20.15021.21756.exe Code function: 4_2_017D3FD2 4_2_017D3FD2
Source: C:\Users\user\Desktop\SecuriteInfo.com.BackDoor.AgentTeslaNET.20.15021.21756.exe Code function: 4_2_01819EB0 4_2_01819EB0
Source: C:\Users\user\Desktop\SecuriteInfo.com.BackDoor.AgentTeslaNET.20.15021.21756.exe Code function: String function: 0188F290 appears 105 times
Source: C:\Users\user\Desktop\SecuriteInfo.com.BackDoor.AgentTeslaNET.20.15021.21756.exe Code function: String function: 01857E54 appears 108 times
Source: C:\Users\user\Desktop\SecuriteInfo.com.BackDoor.AgentTeslaNET.20.15021.21756.exe Code function: String function: 017FB970 appears 265 times
Source: C:\Users\user\Desktop\SecuriteInfo.com.BackDoor.AgentTeslaNET.20.15021.21756.exe Code function: String function: 0187EA12 appears 86 times
Source: C:\Users\user\Desktop\SecuriteInfo.com.BackDoor.AgentTeslaNET.20.15021.21756.exe Code function: String function: 01845130 appears 58 times
Source: C:\Users\user\Desktop\SecuriteInfo.com.BackDoor.AgentTeslaNET.20.15021.21756.exe Process created: C:\Windows\SysWOW64\WerFault.exe C:\Windows\SysWOW64\WerFault.exe -u -p 2536 -s 200
Source: SecuriteInfo.com.BackDoor.AgentTeslaNET.20.15021.21756.exe, 00000000.00000002.1870536823.000000000103E000.00000004.00000020.00020000.00000000.sdmp Binary or memory string: OriginalFilenameclr.dllT vs SecuriteInfo.com.BackDoor.AgentTeslaNET.20.15021.21756.exe
Source: SecuriteInfo.com.BackDoor.AgentTeslaNET.20.15021.21756.exe, 00000000.00000002.1878117444.00000000044FA000.00000004.00000800.00020000.00000000.sdmp Binary or memory string: OriginalFilenameTyrone.dll8 vs SecuriteInfo.com.BackDoor.AgentTeslaNET.20.15021.21756.exe
Source: SecuriteInfo.com.BackDoor.AgentTeslaNET.20.15021.21756.exe, 00000000.00000002.1898270463.0000000007C90000.00000004.08000000.00040000.00000000.sdmp Binary or memory string: OriginalFilenameTyrone.dll8 vs SecuriteInfo.com.BackDoor.AgentTeslaNET.20.15021.21756.exe
Source: SecuriteInfo.com.BackDoor.AgentTeslaNET.20.15021.21756.exe, 00000000.00000002.1897801539.00000000074A7000.00000004.00000020.00020000.00000000.sdmp Binary or memory string: OriginalFilenamePowerShell.EXE.MUIj% vs SecuriteInfo.com.BackDoor.AgentTeslaNET.20.15021.21756.exe
Source: SecuriteInfo.com.BackDoor.AgentTeslaNET.20.15021.21756.exe, 00000004.00000002.2454956185.00000000018FD000.00000040.00001000.00020000.00000000.sdmp Binary or memory string: OriginalFilenamentdll.dllj% vs SecuriteInfo.com.BackDoor.AgentTeslaNET.20.15021.21756.exe
Source: SecuriteInfo.com.BackDoor.AgentTeslaNET.20.15021.21756.exe Binary or memory string: OriginalFilenamepxNz.exe@ vs SecuriteInfo.com.BackDoor.AgentTeslaNET.20.15021.21756.exe
Source: SecuriteInfo.com.BackDoor.AgentTeslaNET.20.15021.21756.exe Static PE information: EXECUTABLE_IMAGE, 32BIT_MACHINE
Source: 4.2.SecuriteInfo.com.BackDoor.AgentTeslaNET.20.15021.21756.exe.400000.0.unpack, type: UNPACKEDPE Matched rule: Windows_Trojan_Formbook_1112e116 reference_sample = 6246f3b89f0e4913abd88ae535ae3597865270f58201dc7f8ec0c87f15ff370a, os = windows, severity = x86, creation_date = 2021-06-14, scan_context = file, memory, license = Elastic License v2, threat_name = Windows.Trojan.Formbook, fingerprint = b8b88451ad8c66b54e21455d835a5d435e52173c86e9b813ffab09451aff7134, id = 1112e116-dee0-4818-a41f-ca5c1c41b4b8, last_modified = 2021-08-23
Source: 4.2.SecuriteInfo.com.BackDoor.AgentTeslaNET.20.15021.21756.exe.400000.0.raw.unpack, type: UNPACKEDPE Matched rule: Windows_Trojan_Formbook_1112e116 reference_sample = 6246f3b89f0e4913abd88ae535ae3597865270f58201dc7f8ec0c87f15ff370a, os = windows, severity = x86, creation_date = 2021-06-14, scan_context = file, memory, license = Elastic License v2, threat_name = Windows.Trojan.Formbook, fingerprint = b8b88451ad8c66b54e21455d835a5d435e52173c86e9b813ffab09451aff7134, id = 1112e116-dee0-4818-a41f-ca5c1c41b4b8, last_modified = 2021-08-23
Source: 00000004.00000002.2454612791.0000000000400000.00000040.00000400.00020000.00000000.sdmp, type: MEMORY Matched rule: Windows_Trojan_Formbook_1112e116 reference_sample = 6246f3b89f0e4913abd88ae535ae3597865270f58201dc7f8ec0c87f15ff370a, os = windows, severity = x86, creation_date = 2021-06-14, scan_context = file, memory, license = Elastic License v2, threat_name = Windows.Trojan.Formbook, fingerprint = b8b88451ad8c66b54e21455d835a5d435e52173c86e9b813ffab09451aff7134, id = 1112e116-dee0-4818-a41f-ca5c1c41b4b8, last_modified = 2021-08-23
Source: SecuriteInfo.com.BackDoor.AgentTeslaNET.20.15021.21756.exe Static PE information: Section: .text IMAGE_SCN_CNT_CODE, IMAGE_SCN_MEM_EXECUTE, IMAGE_SCN_MEM_READ
Source: 0.2.SecuriteInfo.com.BackDoor.AgentTeslaNET.20.15021.21756.exe.4731a10.0.raw.unpack, pjLLLur9tiSkaioQPu.cs Security API names: System.Security.Principal.WindowsIdentity.GetCurrent()
Source: 0.2.SecuriteInfo.com.BackDoor.AgentTeslaNET.20.15021.21756.exe.7c90000.3.raw.unpack, pjLLLur9tiSkaioQPu.cs Security API names: System.Security.Principal.WindowsIdentity.GetCurrent()
Source: 0.2.SecuriteInfo.com.BackDoor.AgentTeslaNET.20.15021.21756.exe.4731a10.0.raw.unpack, IjP6D5cWjjGgXCicYS.cs Security API names: _0020.SetAccessControl
Source: 0.2.SecuriteInfo.com.BackDoor.AgentTeslaNET.20.15021.21756.exe.4731a10.0.raw.unpack, IjP6D5cWjjGgXCicYS.cs Security API names: System.Security.Principal.WindowsIdentity.GetCurrent()
Source: 0.2.SecuriteInfo.com.BackDoor.AgentTeslaNET.20.15021.21756.exe.4731a10.0.raw.unpack, IjP6D5cWjjGgXCicYS.cs Security API names: _0020.AddAccessRule
Source: 0.2.SecuriteInfo.com.BackDoor.AgentTeslaNET.20.15021.21756.exe.7c90000.3.raw.unpack, IjP6D5cWjjGgXCicYS.cs Security API names: _0020.SetAccessControl
Source: 0.2.SecuriteInfo.com.BackDoor.AgentTeslaNET.20.15021.21756.exe.7c90000.3.raw.unpack, IjP6D5cWjjGgXCicYS.cs Security API names: System.Security.Principal.WindowsIdentity.GetCurrent()
Source: 0.2.SecuriteInfo.com.BackDoor.AgentTeslaNET.20.15021.21756.exe.7c90000.3.raw.unpack, IjP6D5cWjjGgXCicYS.cs Security API names: _0020.AddAccessRule
Source: 0.2.SecuriteInfo.com.BackDoor.AgentTeslaNET.20.15021.21756.exe.47b9c30.1.raw.unpack, pjLLLur9tiSkaioQPu.cs Security API names: System.Security.Principal.WindowsIdentity.GetCurrent()
Source: 0.2.SecuriteInfo.com.BackDoor.AgentTeslaNET.20.15021.21756.exe.47b9c30.1.raw.unpack, IjP6D5cWjjGgXCicYS.cs Security API names: _0020.SetAccessControl
Source: 0.2.SecuriteInfo.com.BackDoor.AgentTeslaNET.20.15021.21756.exe.47b9c30.1.raw.unpack, IjP6D5cWjjGgXCicYS.cs Security API names: System.Security.Principal.WindowsIdentity.GetCurrent()
Source: 0.2.SecuriteInfo.com.BackDoor.AgentTeslaNET.20.15021.21756.exe.47b9c30.1.raw.unpack, IjP6D5cWjjGgXCicYS.cs Security API names: _0020.AddAccessRule
Source: classification engine Classification label: mal100.troj.evad.winEXE@8/11@0/0
Source: C:\Users\user\Desktop\SecuriteInfo.com.BackDoor.AgentTeslaNET.20.15021.21756.exe File created: C:\Users\user\AppData\Local\Microsoft\CLR_v4.0_32\UsageLogs\SecuriteInfo.com.BackDoor.AgentTeslaNET.20.15021.21756.exe.log Jump to behavior
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe Mutant created: NULL
Source: C:\Windows\System32\conhost.exe Mutant created: \Sessions\1\BaseNamedObjects\Local\SM0:2736:120:WilError_03
Source: C:\Windows\SysWOW64\WerFault.exe Mutant created: \Sessions\1\BaseNamedObjects\Local\WERReportingForProcess2536
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe File created: C:\Users\user\AppData\Local\Temp\__PSScriptPolicyTest_5oueypog.m1r.ps1 Jump to behavior
Source: SecuriteInfo.com.BackDoor.AgentTeslaNET.20.15021.21756.exe Static PE information: Section: .text IMAGE_SCN_CNT_CODE, IMAGE_SCN_MEM_EXECUTE, IMAGE_SCN_MEM_READ
Source: SecuriteInfo.com.BackDoor.AgentTeslaNET.20.15021.21756.exe Static file information: TRID: Win32 Executable (generic) Net Framework (10011505/4) 49.83%
Source: C:\Users\user\Desktop\SecuriteInfo.com.BackDoor.AgentTeslaNET.20.15021.21756.exe File read: C:\Users\user\Desktop\desktop.ini Jump to behavior
Source: C:\Users\user\Desktop\SecuriteInfo.com.BackDoor.AgentTeslaNET.20.15021.21756.exe Key opened: HKEY_CURRENT_USER\Software\Policies\Microsoft\Windows\Safer\CodeIdentifiers Jump to behavior
Source: SecuriteInfo.com.BackDoor.AgentTeslaNET.20.15021.21756.exe ReversingLabs: Detection: 55%
Source: unknown Process created: C:\Users\user\Desktop\SecuriteInfo.com.BackDoor.AgentTeslaNET.20.15021.21756.exe "C:\Users\user\Desktop\SecuriteInfo.com.BackDoor.AgentTeslaNET.20.15021.21756.exe"
Source: C:\Users\user\Desktop\SecuriteInfo.com.BackDoor.AgentTeslaNET.20.15021.21756.exe Process created: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe "C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe" Add-MpPreference -ExclusionPath "C:\Users\user\Desktop\SecuriteInfo.com.BackDoor.AgentTeslaNET.20.15021.21756.exe"
Source: C:\Users\user\Desktop\SecuriteInfo.com.BackDoor.AgentTeslaNET.20.15021.21756.exe Process created: C:\Users\user\Desktop\SecuriteInfo.com.BackDoor.AgentTeslaNET.20.15021.21756.exe "C:\Users\user\Desktop\SecuriteInfo.com.BackDoor.AgentTeslaNET.20.15021.21756.exe"
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe Process created: C:\Windows\System32\conhost.exe C:\Windows\system32\conhost.exe 0xffffffff -ForceV1
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe Process created: C:\Windows\System32\wbem\WmiPrvSE.exe C:\Windows\system32\wbem\wmiprvse.exe -secured -Embedding
Source: C:\Users\user\Desktop\SecuriteInfo.com.BackDoor.AgentTeslaNET.20.15021.21756.exe Process created: C:\Windows\SysWOW64\WerFault.exe C:\Windows\SysWOW64\WerFault.exe -u -p 2536 -s 200
Source: C:\Users\user\Desktop\SecuriteInfo.com.BackDoor.AgentTeslaNET.20.15021.21756.exe Process created: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe "C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe" Add-MpPreference -ExclusionPath "C:\Users\user\Desktop\SecuriteInfo.com.BackDoor.AgentTeslaNET.20.15021.21756.exe" Jump to behavior
Source: C:\Users\user\Desktop\SecuriteInfo.com.BackDoor.AgentTeslaNET.20.15021.21756.exe Process created: C:\Users\user\Desktop\SecuriteInfo.com.BackDoor.AgentTeslaNET.20.15021.21756.exe "C:\Users\user\Desktop\SecuriteInfo.com.BackDoor.AgentTeslaNET.20.15021.21756.exe" Jump to behavior
Source: C:\Users\user\Desktop\SecuriteInfo.com.BackDoor.AgentTeslaNET.20.15021.21756.exe Section loaded: mscoree.dll Jump to behavior
Source: C:\Users\user\Desktop\SecuriteInfo.com.BackDoor.AgentTeslaNET.20.15021.21756.exe Section loaded: apphelp.dll Jump to behavior
Source: C:\Users\user\Desktop\SecuriteInfo.com.BackDoor.AgentTeslaNET.20.15021.21756.exe Section loaded: kernel.appcore.dll Jump to behavior
Source: C:\Users\user\Desktop\SecuriteInfo.com.BackDoor.AgentTeslaNET.20.15021.21756.exe Section loaded: version.dll Jump to behavior
Source: C:\Users\user\Desktop\SecuriteInfo.com.BackDoor.AgentTeslaNET.20.15021.21756.exe Section loaded: vcruntime140_clr0400.dll Jump to behavior
Source: C:\Users\user\Desktop\SecuriteInfo.com.BackDoor.AgentTeslaNET.20.15021.21756.exe Section loaded: ucrtbase_clr0400.dll Jump to behavior
Source: C:\Users\user\Desktop\SecuriteInfo.com.BackDoor.AgentTeslaNET.20.15021.21756.exe Section loaded: ucrtbase_clr0400.dll Jump to behavior
Source: C:\Users\user\Desktop\SecuriteInfo.com.BackDoor.AgentTeslaNET.20.15021.21756.exe Section loaded: uxtheme.dll Jump to behavior
Source: C:\Users\user\Desktop\SecuriteInfo.com.BackDoor.AgentTeslaNET.20.15021.21756.exe Section loaded: windows.storage.dll Jump to behavior
Source: C:\Users\user\Desktop\SecuriteInfo.com.BackDoor.AgentTeslaNET.20.15021.21756.exe Section loaded: wldp.dll Jump to behavior
Source: C:\Users\user\Desktop\SecuriteInfo.com.BackDoor.AgentTeslaNET.20.15021.21756.exe Section loaded: profapi.dll Jump to behavior
Source: C:\Users\user\Desktop\SecuriteInfo.com.BackDoor.AgentTeslaNET.20.15021.21756.exe Section loaded: cryptsp.dll Jump to behavior
Source: C:\Users\user\Desktop\SecuriteInfo.com.BackDoor.AgentTeslaNET.20.15021.21756.exe Section loaded: rsaenh.dll Jump to behavior
Source: C:\Users\user\Desktop\SecuriteInfo.com.BackDoor.AgentTeslaNET.20.15021.21756.exe Section loaded: cryptbase.dll Jump to behavior
Source: C:\Users\user\Desktop\SecuriteInfo.com.BackDoor.AgentTeslaNET.20.15021.21756.exe Section loaded: dwrite.dll Jump to behavior
Source: C:\Users\user\Desktop\SecuriteInfo.com.BackDoor.AgentTeslaNET.20.15021.21756.exe Section loaded: windowscodecs.dll Jump to behavior
Source: C:\Users\user\Desktop\SecuriteInfo.com.BackDoor.AgentTeslaNET.20.15021.21756.exe Section loaded: amsi.dll Jump to behavior
Source: C:\Users\user\Desktop\SecuriteInfo.com.BackDoor.AgentTeslaNET.20.15021.21756.exe Section loaded: userenv.dll Jump to behavior
Source: C:\Users\user\Desktop\SecuriteInfo.com.BackDoor.AgentTeslaNET.20.15021.21756.exe Section loaded: msasn1.dll Jump to behavior
Source: C:\Users\user\Desktop\SecuriteInfo.com.BackDoor.AgentTeslaNET.20.15021.21756.exe Section loaded: gpapi.dll Jump to behavior
Source: C:\Users\user\Desktop\SecuriteInfo.com.BackDoor.AgentTeslaNET.20.15021.21756.exe Section loaded: textshaping.dll Jump to behavior
Source: C:\Users\user\Desktop\SecuriteInfo.com.BackDoor.AgentTeslaNET.20.15021.21756.exe Section loaded: iconcodecservice.dll Jump to behavior
Source: C:\Users\user\Desktop\SecuriteInfo.com.BackDoor.AgentTeslaNET.20.15021.21756.exe Section loaded: propsys.dll Jump to behavior
Source: C:\Users\user\Desktop\SecuriteInfo.com.BackDoor.AgentTeslaNET.20.15021.21756.exe Section loaded: edputil.dll Jump to behavior
Source: C:\Users\user\Desktop\SecuriteInfo.com.BackDoor.AgentTeslaNET.20.15021.21756.exe Section loaded: urlmon.dll Jump to behavior
Source: C:\Users\user\Desktop\SecuriteInfo.com.BackDoor.AgentTeslaNET.20.15021.21756.exe Section loaded: iertutil.dll Jump to behavior
Source: C:\Users\user\Desktop\SecuriteInfo.com.BackDoor.AgentTeslaNET.20.15021.21756.exe Section loaded: srvcli.dll Jump to behavior
Source: C:\Users\user\Desktop\SecuriteInfo.com.BackDoor.AgentTeslaNET.20.15021.21756.exe Section loaded: netutils.dll Jump to behavior
Source: C:\Users\user\Desktop\SecuriteInfo.com.BackDoor.AgentTeslaNET.20.15021.21756.exe Section loaded: windows.staterepositoryps.dll Jump to behavior
Source: C:\Users\user\Desktop\SecuriteInfo.com.BackDoor.AgentTeslaNET.20.15021.21756.exe Section loaded: sspicli.dll Jump to behavior
Source: C:\Users\user\Desktop\SecuriteInfo.com.BackDoor.AgentTeslaNET.20.15021.21756.exe Section loaded: wintypes.dll Jump to behavior
Source: C:\Users\user\Desktop\SecuriteInfo.com.BackDoor.AgentTeslaNET.20.15021.21756.exe Section loaded: appresolver.dll Jump to behavior
Source: C:\Users\user\Desktop\SecuriteInfo.com.BackDoor.AgentTeslaNET.20.15021.21756.exe Section loaded: bcp47langs.dll Jump to behavior
Source: C:\Users\user\Desktop\SecuriteInfo.com.BackDoor.AgentTeslaNET.20.15021.21756.exe Section loaded: slc.dll Jump to behavior
Source: C:\Users\user\Desktop\SecuriteInfo.com.BackDoor.AgentTeslaNET.20.15021.21756.exe Section loaded: sppc.dll Jump to behavior
Source: C:\Users\user\Desktop\SecuriteInfo.com.BackDoor.AgentTeslaNET.20.15021.21756.exe Section loaded: onecorecommonproxystub.dll Jump to behavior
Source: C:\Users\user\Desktop\SecuriteInfo.com.BackDoor.AgentTeslaNET.20.15021.21756.exe Section loaded: onecoreuapcommonproxystub.dll Jump to behavior
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe Section loaded: atl.dll Jump to behavior
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe Section loaded: mscoree.dll Jump to behavior
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe Section loaded: kernel.appcore.dll Jump to behavior
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe Section loaded: version.dll Jump to behavior
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe Section loaded: vcruntime140_clr0400.dll Jump to behavior
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe Section loaded: ucrtbase_clr0400.dll Jump to behavior
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe Section loaded: ucrtbase_clr0400.dll Jump to behavior
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe Section loaded: cryptsp.dll Jump to behavior
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe Section loaded: rsaenh.dll Jump to behavior
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe Section loaded: cryptbase.dll Jump to behavior
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe Section loaded: windows.storage.dll Jump to behavior
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe Section loaded: wldp.dll Jump to behavior
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe Section loaded: msasn1.dll Jump to behavior
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe Section loaded: amsi.dll Jump to behavior
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe Section loaded: userenv.dll Jump to behavior
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe Section loaded: profapi.dll Jump to behavior
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe Section loaded: msisip.dll Jump to behavior
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe Section loaded: wshext.dll Jump to behavior
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe Section loaded: appxsip.dll Jump to behavior
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe Section loaded: opcservices.dll Jump to behavior
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe Section loaded: gpapi.dll Jump to behavior
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe Section loaded: secur32.dll Jump to behavior
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe Section loaded: sspicli.dll Jump to behavior
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe Section loaded: uxtheme.dll Jump to behavior
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe Section loaded: urlmon.dll Jump to behavior
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe Section loaded: iertutil.dll Jump to behavior
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe Section loaded: srvcli.dll Jump to behavior
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe Section loaded: netutils.dll Jump to behavior
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe Section loaded: propsys.dll Jump to behavior
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe Section loaded: wininet.dll Jump to behavior
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe Section loaded: microsoft.management.infrastructure.native.unmanaged.dll Jump to behavior
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe Section loaded: mi.dll Jump to behavior
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe Section loaded: miutils.dll Jump to behavior
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe Section loaded: wmidcom.dll Jump to behavior
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe Section loaded: dpapi.dll Jump to behavior
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe Section loaded: wbemcomn.dll Jump to behavior
Source: C:\Windows\System32\wbem\WmiPrvSE.exe Section loaded: fastprox.dll Jump to behavior
Source: C:\Windows\System32\wbem\WmiPrvSE.exe Section loaded: ncobjapi.dll Jump to behavior
Source: C:\Windows\System32\wbem\WmiPrvSE.exe Section loaded: wbemcomn.dll Jump to behavior
Source: C:\Windows\System32\wbem\WmiPrvSE.exe Section loaded: wbemcomn.dll Jump to behavior
Source: C:\Windows\System32\wbem\WmiPrvSE.exe Section loaded: kernel.appcore.dll Jump to behavior
Source: C:\Windows\System32\wbem\WmiPrvSE.exe Section loaded: mpclient.dll Jump to behavior
Source: C:\Windows\System32\wbem\WmiPrvSE.exe Section loaded: userenv.dll Jump to behavior
Source: C:\Windows\System32\wbem\WmiPrvSE.exe Section loaded: version.dll Jump to behavior
Source: C:\Windows\System32\wbem\WmiPrvSE.exe Section loaded: msasn1.dll Jump to behavior
Source: C:\Windows\System32\wbem\WmiPrvSE.exe Section loaded: wmitomi.dll Jump to behavior
Source: C:\Windows\System32\wbem\WmiPrvSE.exe Section loaded: mi.dll Jump to behavior
Source: C:\Windows\System32\wbem\WmiPrvSE.exe Section loaded: miutils.dll Jump to behavior
Source: C:\Windows\System32\wbem\WmiPrvSE.exe Section loaded: miutils.dll Jump to behavior
Source: C:\Windows\System32\wbem\WmiPrvSE.exe Section loaded: gpapi.dll Jump to behavior
Source: C:\Users\user\Desktop\SecuriteInfo.com.BackDoor.AgentTeslaNET.20.15021.21756.exe Key value queried: HKEY_LOCAL_MACHINE\SOFTWARE\Classes\WOW6432Node\CLSID\{0EE7644B-1BAD-48B1-9889-0281C206EB85}\InprocServer32 Jump to behavior
Source: Window Recorder Window detected: More than 3 window changes detected
Source: C:\Users\user\Desktop\SecuriteInfo.com.BackDoor.AgentTeslaNET.20.15021.21756.exe File opened: C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscorrc.dll Jump to behavior
Source: SecuriteInfo.com.BackDoor.AgentTeslaNET.20.15021.21756.exe Static PE information: data directory type: IMAGE_DIRECTORY_ENTRY_COM_DESCRIPTOR
Source: SecuriteInfo.com.BackDoor.AgentTeslaNET.20.15021.21756.exe Static PE information: DYNAMIC_BASE, NX_COMPAT, NO_SEH, TERMINAL_SERVER_AWARE
Source: Binary string: wntdll.pdbUGP source: SecuriteInfo.com.BackDoor.AgentTeslaNET.20.15021.21756.exe, 00000004.00000002.2454956185.00000000017D0000.00000040.00001000.00020000.00000000.sdmp
Source: Binary string: wntdll.pdb source: SecuriteInfo.com.BackDoor.AgentTeslaNET.20.15021.21756.exe, SecuriteInfo.com.BackDoor.AgentTeslaNET.20.15021.21756.exe, 00000004.00000002.2454956185.00000000017D0000.00000040.00001000.00020000.00000000.sdmp

Data Obfuscation

barindex
Source: 0.2.SecuriteInfo.com.BackDoor.AgentTeslaNET.20.15021.21756.exe.7660000.2.raw.unpack, XlF5VlCIHRSQX8M5eh.cs .Net Code: _200C_200C_202D_206C_200B_206A_206D_200B_200D_200C_202D_206A_206D_202A_206A_206B_202B_206C_202D_200B_202E_202B_202A_206C_206A_206D_202D_206B_206D_206B_200D_202B_202D_206C_206F_206C_200B_202B_206A_206D_202E System.Reflection.Assembly.Load(byte[])
Source: 0.2.SecuriteInfo.com.BackDoor.AgentTeslaNET.20.15021.21756.exe.4731a10.0.raw.unpack, IjP6D5cWjjGgXCicYS.cs .Net Code: VfX1B1ZhqW System.Reflection.Assembly.Load(byte[])
Source: 0.2.SecuriteInfo.com.BackDoor.AgentTeslaNET.20.15021.21756.exe.47b9c30.1.raw.unpack, IjP6D5cWjjGgXCicYS.cs .Net Code: VfX1B1ZhqW System.Reflection.Assembly.Load(byte[])
Source: 0.2.SecuriteInfo.com.BackDoor.AgentTeslaNET.20.15021.21756.exe.7c90000.3.raw.unpack, IjP6D5cWjjGgXCicYS.cs .Net Code: VfX1B1ZhqW System.Reflection.Assembly.Load(byte[])
Source: C:\Users\user\Desktop\SecuriteInfo.com.BackDoor.AgentTeslaNET.20.15021.21756.exe Code function: 0_2_06DC0EF6 push ds; iretd 0_2_06DC0EFF
Source: C:\Users\user\Desktop\SecuriteInfo.com.BackDoor.AgentTeslaNET.20.15021.21756.exe Code function: 0_2_06DC1FBF push cs; retf 0004h 0_2_06DC1F7A
Source: C:\Users\user\Desktop\SecuriteInfo.com.BackDoor.AgentTeslaNET.20.15021.21756.exe Code function: 0_2_06DC1F50 push cs; retf 0004h 0_2_06DC1F7A
Source: C:\Users\user\Desktop\SecuriteInfo.com.BackDoor.AgentTeslaNET.20.15021.21756.exe Code function: 4_2_0040D8C8 push 972ADD89h; iretd 4_2_0040D8CD
Source: C:\Users\user\Desktop\SecuriteInfo.com.BackDoor.AgentTeslaNET.20.15021.21756.exe Code function: 4_2_0041A971 push 00000009h; ret 4_2_0041A973
Source: C:\Users\user\Desktop\SecuriteInfo.com.BackDoor.AgentTeslaNET.20.15021.21756.exe Code function: 4_2_0040DA23 pushfd ; retf 4_2_0040DA27
Source: C:\Users\user\Desktop\SecuriteInfo.com.BackDoor.AgentTeslaNET.20.15021.21756.exe Code function: 4_2_00414B4D push esp; retf 4_2_00414B50
Source: C:\Users\user\Desktop\SecuriteInfo.com.BackDoor.AgentTeslaNET.20.15021.21756.exe Code function: 4_2_0041EBBB push esi; ret 4_2_0041EBC4
Source: C:\Users\user\Desktop\SecuriteInfo.com.BackDoor.AgentTeslaNET.20.15021.21756.exe Code function: 4_2_00403420 push eax; ret 4_2_00403422
Source: C:\Users\user\Desktop\SecuriteInfo.com.BackDoor.AgentTeslaNET.20.15021.21756.exe Code function: 4_2_0041AD97 push ecx; iretd 4_2_0041AD9E
Source: C:\Users\user\Desktop\SecuriteInfo.com.BackDoor.AgentTeslaNET.20.15021.21756.exe Code function: 4_2_0040559E push ss; ret 4_2_004055A0
Source: C:\Users\user\Desktop\SecuriteInfo.com.BackDoor.AgentTeslaNET.20.15021.21756.exe Code function: 4_2_0040D67A push ss; retf 4_2_0040D68B
Source: C:\Users\user\Desktop\SecuriteInfo.com.BackDoor.AgentTeslaNET.20.15021.21756.exe Code function: 4_2_017D225F pushad ; ret 4_2_017D27F9
Source: C:\Users\user\Desktop\SecuriteInfo.com.BackDoor.AgentTeslaNET.20.15021.21756.exe Code function: 4_2_017D27FA pushad ; ret 4_2_017D27F9
Source: C:\Users\user\Desktop\SecuriteInfo.com.BackDoor.AgentTeslaNET.20.15021.21756.exe Code function: 4_2_018009AD push ecx; mov dword ptr [esp], ecx 4_2_018009B6
Source: C:\Users\user\Desktop\SecuriteInfo.com.BackDoor.AgentTeslaNET.20.15021.21756.exe Code function: 4_2_017D283D push eax; iretd 4_2_017D2858
Source: C:\Users\user\Desktop\SecuriteInfo.com.BackDoor.AgentTeslaNET.20.15021.21756.exe Code function: 4_2_017D1366 push eax; iretd 4_2_017D1369
Source: SecuriteInfo.com.BackDoor.AgentTeslaNET.20.15021.21756.exe Static PE information: section name: .text entropy: 7.807275575545102
Source: 0.2.SecuriteInfo.com.BackDoor.AgentTeslaNET.20.15021.21756.exe.4731a10.0.raw.unpack, RW0OBEMZBRha8lPi7Y.cs High entropy of concatenated method names: 'U4A5usFaGb', 'zYD5qHWnmv', 'z8P5HOytTi', 'XWa5Q6jVjJ', 'jPS5ERXFSD', 'ETx5n87u4E', 'ILk5ObrooB', 'cjv52DPJxE', 'Ydq5xe9GdL', 'QlA5Z0c1JD'
Source: 0.2.SecuriteInfo.com.BackDoor.AgentTeslaNET.20.15021.21756.exe.4731a10.0.raw.unpack, Elq5flWOXP5Q6q3T3r.cs High entropy of concatenated method names: 'e3NFSUTouP', 'dmVFYJWBge', 'r2naRi0hbg', 'BhfaWrQEoG', 'PYkFNKXSje', 'PAVFq6lK0O', 'AQeFfZt4HU', 'AoTFHgchdW', 'sY7FQ08Mny', 'suYFMt3SRV'
Source: 0.2.SecuriteInfo.com.BackDoor.AgentTeslaNET.20.15021.21756.exe.4731a10.0.raw.unpack, ipQMcJSeB9u6PMObKo.cs High entropy of concatenated method names: 'xFlBAkZZZ', 'LQJAQ50x7', 't7xDuKplu', 'RAumBYYNC', 'DDwUC4uKk', 'jAx0v9snF', 'ybdLi2NeBUhCnQrKDO', 't5NSvCQ28R6cJAhj3V', 'OJYa8IsHb', 'tta3UmkCK'
Source: 0.2.SecuriteInfo.com.BackDoor.AgentTeslaNET.20.15021.21756.exe.4731a10.0.raw.unpack, g9XJMjAY6v2RTawueQ.cs High entropy of concatenated method names: 'Dispose', 'enDWVMvg1v', 'PSyCEBxd69', 'xO1yyP6dwx', 'sw1WYGgLHW', 'EwiWzNBjk9', 'ProcessDialogKey', 'og1CRGeTVK', 'siTCWSmf4R', 'eakCC8tmR3'
Source: 0.2.SecuriteInfo.com.BackDoor.AgentTeslaNET.20.15021.21756.exe.4731a10.0.raw.unpack, ok7eroPtk1smVUHZAW.cs High entropy of concatenated method names: 'xInhtiOMqH', 'zjlhKyLP64', 'QeQhBty2fL', 'j2LhAeYlSN', 'RqChG2oY1X', 'GCahD89lE8', 'T3Phmq1rji', 'kmEhLIYld9', 'pu2hULeBOs', 'B8mh0BdRLM'
Source: 0.2.SecuriteInfo.com.BackDoor.AgentTeslaNET.20.15021.21756.exe.4731a10.0.raw.unpack, l8eIFKRqy7DJZhgLJ7.cs High entropy of concatenated method names: 'iCBwsvjEOn', 'kb4wPgnBIl', 'lTwwXUI7sR', 'cJZwhwk4CJ', 'SM3wgmxIye', 'WmYXTR87s7', 'aqGXbH36fR', 'e3TXeDAhJa', 'Y8FXSefcPU', 'DZVXV0SbJu'
Source: 0.2.SecuriteInfo.com.BackDoor.AgentTeslaNET.20.15021.21756.exe.4731a10.0.raw.unpack, I2V8A0QX4TkkgRwi5N.cs High entropy of concatenated method names: 'HKdhrCBiyi', 'GkKhkXUpOx', 'SYFhw67q5y', 'D2KwYOg94r', 'vHcwzQ73ci', 'M2DhRLMkGF', 'm1WhWGiV8y', 'onbhCtlsYg', 'r8Dh6hf1t4', 'ODHh1gmhlf'
Source: 0.2.SecuriteInfo.com.BackDoor.AgentTeslaNET.20.15021.21756.exe.4731a10.0.raw.unpack, zK05wjZFU51aXO1gUi.cs High entropy of concatenated method names: 'U2V7LH7AeD', 'ugL7UXI2HC', 'oP27pPM6rO', 'vmS7EuH6C7', 'bDc7OxCjfY', 'GIU72hdZfH', 'yL77ZwF9Im', 'tcc7IBsY6v', 'rjo7uOiI4K', 'RGM7NnDKka'
Source: 0.2.SecuriteInfo.com.BackDoor.AgentTeslaNET.20.15021.21756.exe.4731a10.0.raw.unpack, PmHr01qHTRVv3ooYoc.cs High entropy of concatenated method names: 'CDekAXp5XA', 'YZ4kDx8IKX', 'aHqkLyO5AD', 'TPGkUid8D4', 'dXfk5hrpJn', 'WulkcEqumj', 'asWkFHnXIZ', 'VeNkaDEdIK', 'm4GkJ7kdyG', 'GAwk3Yn6Gr'
Source: 0.2.SecuriteInfo.com.BackDoor.AgentTeslaNET.20.15021.21756.exe.4731a10.0.raw.unpack, rhl6gm1YyWv1nFsA5s.cs High entropy of concatenated method names: 'MSUapAckjb', 'IwDaEYFfNh', 'ISXanC5P69', 'eKxaOkOuyr', 'zsSaHfYF44', 'sQwa2b2qEm', 'Next', 'Next', 'Next', 'NextBytes'
Source: 0.2.SecuriteInfo.com.BackDoor.AgentTeslaNET.20.15021.21756.exe.4731a10.0.raw.unpack, gauagME0A2MimyuOoW.cs High entropy of concatenated method names: 'EditValue', 'GetEditStyle', 'NgpCVyowR0', 'wlOCY7nCEm', 'RhWCzQKSfb', 'w3G6RpEISZ', 'pTs6WMZKUp', 'TA46CVNvrb', 'vtn66XZ6B7', 'z81FFCfyjgPOymts9jB'
Source: 0.2.SecuriteInfo.com.BackDoor.AgentTeslaNET.20.15021.21756.exe.4731a10.0.raw.unpack, jw5wIHaY3wWQ2nPBcN.cs High entropy of concatenated method names: 'RRMF9110jX', 'Vv9Fj0xZ78', 'ToString', 'l4aFrcFidl', 'GjKFPQZMth', 'Mu4Fkjq5GU', 'CtDFXcaTny', 'jvJFw08OqG', 'UYWFhKxGhB', 'VqZFgQ88w3'
Source: 0.2.SecuriteInfo.com.BackDoor.AgentTeslaNET.20.15021.21756.exe.4731a10.0.raw.unpack, pjLLLur9tiSkaioQPu.cs High entropy of concatenated method names: 'H1ZPHpdNgr', 'O1BPQLH0dy', 'yhmPMC2eDW', 'FmuP4yR6eh', 'ybKPT79phS', 'YhTPbyUjxs', 'QFPPeVFxdf', 'NCRPSjlaUU', 'tqNPVgYh7X', 'w5KPYmJrL3'
Source: 0.2.SecuriteInfo.com.BackDoor.AgentTeslaNET.20.15021.21756.exe.4731a10.0.raw.unpack, Obo1J1YkSoh2CJ8pK4.cs High entropy of concatenated method names: 'GggwlXTmJm', 'RkGwtuQbJf', 'GGgwBpmOxe', 'CV1wAGk0of', 'nR7wDTvZlW', 'Yn9wmiAeEP', 'q1gwUNwU3B', 'TEtw08DInI', 'Yctqh6yJ64U02LxZFVP', 'i5GUjLyMcIFJ1IM392W'
Source: 0.2.SecuriteInfo.com.BackDoor.AgentTeslaNET.20.15021.21756.exe.4731a10.0.raw.unpack, tqra9GvmsmS2fRiQIx.cs High entropy of concatenated method names: 'XuXwMxaSd0', 'xq0w4YPsfm', 'gEAwTNaCeo', 'ToString', 'B9fwbjsgtm', 'xk8weELGNl', 'DMrV1hyKDK5rgNWSSfH', 'A5IyftyjdpxuiPICjlx', 'QT7pJMycgi4FKpLJmwo'
Source: 0.2.SecuriteInfo.com.BackDoor.AgentTeslaNET.20.15021.21756.exe.4731a10.0.raw.unpack, mBF12IFFOEARE2eysc.cs High entropy of concatenated method names: 'c0LXGFdCox', 'gP7XmUbWiX', 'ObxknIvCBm', 'SHHkOAJb7C', 'yBdk2TFFSE', 'l1YkxDj2Ko', 'nhSkZkDVLS', 'q2QkIJDtNu', 'NE1kdImDpE', 'Hh4kuVpgrD'
Source: 0.2.SecuriteInfo.com.BackDoor.AgentTeslaNET.20.15021.21756.exe.4731a10.0.raw.unpack, zt5ZQmVbkkBqLx1Emv.cs High entropy of concatenated method names: 'ToString', 'b1ZcNu7fJ8', 'cSMcEkAOMh', 'oKYcnCpAJk', 'XTPcOJ7WT9', 'Gn4c2lsGWT', 'KhScxLD6ph', 'v2TcZ6sfDJ', 'SiXcINeDDv', 'G5fcdcEXv7'
Source: 0.2.SecuriteInfo.com.BackDoor.AgentTeslaNET.20.15021.21756.exe.4731a10.0.raw.unpack, DSgEOTuxglaQqdyJt4.cs High entropy of concatenated method names: 'LsFJWK9dLL', 'gHwJ6wcpXg', 'N9oJ1qqrLd', 'qJ2JrT1NBi', 'oF0JPruGI9', 'YJiJXq0fb4', 'VuWJwdkLaG', 'WpQaeCGYrI', 'JGOaSJEWL4', 'fYYaVyOWB2'
Source: 0.2.SecuriteInfo.com.BackDoor.AgentTeslaNET.20.15021.21756.exe.4731a10.0.raw.unpack, m4NLGFLSi5nwgiFUmZ.cs High entropy of concatenated method names: 'kOtWhkokEf', 'JNJWg4iNgn', 'CorW9td0JJ', 'BxDWjVnJFi', 'KHaW5JVmVX', 'nqUWc7NSHo', 'cZsG11UTn52cA4cvCf', 'aBD57UAk82QA7TBPtf', 'iH1WWSEytp', 'wYpW6dEGh6'
Source: 0.2.SecuriteInfo.com.BackDoor.AgentTeslaNET.20.15021.21756.exe.4731a10.0.raw.unpack, IjP6D5cWjjGgXCicYS.cs High entropy of concatenated method names: 'WAa6sSqc1S', 'WUn6rWJBsl', 'dBA6PtLDN5', 'mcP6kb863q', 'O8e6XwWJ5P', 'END6wlCudo', 'GmU6hhVDVO', 'uJr6gVG3cT', 'spK6ixMmCE', 'dwV699cQPw'
Source: 0.2.SecuriteInfo.com.BackDoor.AgentTeslaNET.20.15021.21756.exe.4731a10.0.raw.unpack, T7gc9pHBV3sN5iLwRpa.cs High entropy of concatenated method names: 'hd2JtIwetV', 'XgQJK4tEma', 'CyvJBPlMXp', 'YqwJAUXxrL', 'XTPJGqrSQc', 'U58JDPqj4G', 'fCqJmSwfpp', 'HNZJLya46p', 'kXiJU0OPx2', 'RgbJ0fJAZu'
Source: 0.2.SecuriteInfo.com.BackDoor.AgentTeslaNET.20.15021.21756.exe.4731a10.0.raw.unpack, Qtc6bKnyg9Tw7yp3vW.cs High entropy of concatenated method names: 'Gk9arp3FjY', 'ix0aPyZHSB', 'tZ5akBGuFT', 'IENaXyHWcT', 'wRHawk6AG2', 'SVpahhiq50', 'cemagtVdfM', 'Fg1aiNiT8A', 'd5Sa9KKQOU', 'JH8ajVVi5G'
Source: 0.2.SecuriteInfo.com.BackDoor.AgentTeslaNET.20.15021.21756.exe.47b9c30.1.raw.unpack, RW0OBEMZBRha8lPi7Y.cs High entropy of concatenated method names: 'U4A5usFaGb', 'zYD5qHWnmv', 'z8P5HOytTi', 'XWa5Q6jVjJ', 'jPS5ERXFSD', 'ETx5n87u4E', 'ILk5ObrooB', 'cjv52DPJxE', 'Ydq5xe9GdL', 'QlA5Z0c1JD'
Source: 0.2.SecuriteInfo.com.BackDoor.AgentTeslaNET.20.15021.21756.exe.47b9c30.1.raw.unpack, Elq5flWOXP5Q6q3T3r.cs High entropy of concatenated method names: 'e3NFSUTouP', 'dmVFYJWBge', 'r2naRi0hbg', 'BhfaWrQEoG', 'PYkFNKXSje', 'PAVFq6lK0O', 'AQeFfZt4HU', 'AoTFHgchdW', 'sY7FQ08Mny', 'suYFMt3SRV'
Source: 0.2.SecuriteInfo.com.BackDoor.AgentTeslaNET.20.15021.21756.exe.47b9c30.1.raw.unpack, ipQMcJSeB9u6PMObKo.cs High entropy of concatenated method names: 'xFlBAkZZZ', 'LQJAQ50x7', 't7xDuKplu', 'RAumBYYNC', 'DDwUC4uKk', 'jAx0v9snF', 'ybdLi2NeBUhCnQrKDO', 't5NSvCQ28R6cJAhj3V', 'OJYa8IsHb', 'tta3UmkCK'
Source: 0.2.SecuriteInfo.com.BackDoor.AgentTeslaNET.20.15021.21756.exe.47b9c30.1.raw.unpack, g9XJMjAY6v2RTawueQ.cs High entropy of concatenated method names: 'Dispose', 'enDWVMvg1v', 'PSyCEBxd69', 'xO1yyP6dwx', 'sw1WYGgLHW', 'EwiWzNBjk9', 'ProcessDialogKey', 'og1CRGeTVK', 'siTCWSmf4R', 'eakCC8tmR3'
Source: 0.2.SecuriteInfo.com.BackDoor.AgentTeslaNET.20.15021.21756.exe.47b9c30.1.raw.unpack, ok7eroPtk1smVUHZAW.cs High entropy of concatenated method names: 'xInhtiOMqH', 'zjlhKyLP64', 'QeQhBty2fL', 'j2LhAeYlSN', 'RqChG2oY1X', 'GCahD89lE8', 'T3Phmq1rji', 'kmEhLIYld9', 'pu2hULeBOs', 'B8mh0BdRLM'
Source: 0.2.SecuriteInfo.com.BackDoor.AgentTeslaNET.20.15021.21756.exe.47b9c30.1.raw.unpack, l8eIFKRqy7DJZhgLJ7.cs High entropy of concatenated method names: 'iCBwsvjEOn', 'kb4wPgnBIl', 'lTwwXUI7sR', 'cJZwhwk4CJ', 'SM3wgmxIye', 'WmYXTR87s7', 'aqGXbH36fR', 'e3TXeDAhJa', 'Y8FXSefcPU', 'DZVXV0SbJu'
Source: 0.2.SecuriteInfo.com.BackDoor.AgentTeslaNET.20.15021.21756.exe.47b9c30.1.raw.unpack, I2V8A0QX4TkkgRwi5N.cs High entropy of concatenated method names: 'HKdhrCBiyi', 'GkKhkXUpOx', 'SYFhw67q5y', 'D2KwYOg94r', 'vHcwzQ73ci', 'M2DhRLMkGF', 'm1WhWGiV8y', 'onbhCtlsYg', 'r8Dh6hf1t4', 'ODHh1gmhlf'
Source: 0.2.SecuriteInfo.com.BackDoor.AgentTeslaNET.20.15021.21756.exe.47b9c30.1.raw.unpack, zK05wjZFU51aXO1gUi.cs High entropy of concatenated method names: 'U2V7LH7AeD', 'ugL7UXI2HC', 'oP27pPM6rO', 'vmS7EuH6C7', 'bDc7OxCjfY', 'GIU72hdZfH', 'yL77ZwF9Im', 'tcc7IBsY6v', 'rjo7uOiI4K', 'RGM7NnDKka'
Source: 0.2.SecuriteInfo.com.BackDoor.AgentTeslaNET.20.15021.21756.exe.47b9c30.1.raw.unpack, PmHr01qHTRVv3ooYoc.cs High entropy of concatenated method names: 'CDekAXp5XA', 'YZ4kDx8IKX', 'aHqkLyO5AD', 'TPGkUid8D4', 'dXfk5hrpJn', 'WulkcEqumj', 'asWkFHnXIZ', 'VeNkaDEdIK', 'm4GkJ7kdyG', 'GAwk3Yn6Gr'
Source: 0.2.SecuriteInfo.com.BackDoor.AgentTeslaNET.20.15021.21756.exe.47b9c30.1.raw.unpack, rhl6gm1YyWv1nFsA5s.cs High entropy of concatenated method names: 'MSUapAckjb', 'IwDaEYFfNh', 'ISXanC5P69', 'eKxaOkOuyr', 'zsSaHfYF44', 'sQwa2b2qEm', 'Next', 'Next', 'Next', 'NextBytes'
Source: 0.2.SecuriteInfo.com.BackDoor.AgentTeslaNET.20.15021.21756.exe.47b9c30.1.raw.unpack, gauagME0A2MimyuOoW.cs High entropy of concatenated method names: 'EditValue', 'GetEditStyle', 'NgpCVyowR0', 'wlOCY7nCEm', 'RhWCzQKSfb', 'w3G6RpEISZ', 'pTs6WMZKUp', 'TA46CVNvrb', 'vtn66XZ6B7', 'z81FFCfyjgPOymts9jB'
Source: 0.2.SecuriteInfo.com.BackDoor.AgentTeslaNET.20.15021.21756.exe.47b9c30.1.raw.unpack, jw5wIHaY3wWQ2nPBcN.cs High entropy of concatenated method names: 'RRMF9110jX', 'Vv9Fj0xZ78', 'ToString', 'l4aFrcFidl', 'GjKFPQZMth', 'Mu4Fkjq5GU', 'CtDFXcaTny', 'jvJFw08OqG', 'UYWFhKxGhB', 'VqZFgQ88w3'
Source: 0.2.SecuriteInfo.com.BackDoor.AgentTeslaNET.20.15021.21756.exe.47b9c30.1.raw.unpack, pjLLLur9tiSkaioQPu.cs High entropy of concatenated method names: 'H1ZPHpdNgr', 'O1BPQLH0dy', 'yhmPMC2eDW', 'FmuP4yR6eh', 'ybKPT79phS', 'YhTPbyUjxs', 'QFPPeVFxdf', 'NCRPSjlaUU', 'tqNPVgYh7X', 'w5KPYmJrL3'
Source: 0.2.SecuriteInfo.com.BackDoor.AgentTeslaNET.20.15021.21756.exe.47b9c30.1.raw.unpack, Obo1J1YkSoh2CJ8pK4.cs High entropy of concatenated method names: 'GggwlXTmJm', 'RkGwtuQbJf', 'GGgwBpmOxe', 'CV1wAGk0of', 'nR7wDTvZlW', 'Yn9wmiAeEP', 'q1gwUNwU3B', 'TEtw08DInI', 'Yctqh6yJ64U02LxZFVP', 'i5GUjLyMcIFJ1IM392W'
Source: 0.2.SecuriteInfo.com.BackDoor.AgentTeslaNET.20.15021.21756.exe.47b9c30.1.raw.unpack, tqra9GvmsmS2fRiQIx.cs High entropy of concatenated method names: 'XuXwMxaSd0', 'xq0w4YPsfm', 'gEAwTNaCeo', 'ToString', 'B9fwbjsgtm', 'xk8weELGNl', 'DMrV1hyKDK5rgNWSSfH', 'A5IyftyjdpxuiPICjlx', 'QT7pJMycgi4FKpLJmwo'
Source: 0.2.SecuriteInfo.com.BackDoor.AgentTeslaNET.20.15021.21756.exe.47b9c30.1.raw.unpack, mBF12IFFOEARE2eysc.cs High entropy of concatenated method names: 'c0LXGFdCox', 'gP7XmUbWiX', 'ObxknIvCBm', 'SHHkOAJb7C', 'yBdk2TFFSE', 'l1YkxDj2Ko', 'nhSkZkDVLS', 'q2QkIJDtNu', 'NE1kdImDpE', 'Hh4kuVpgrD'
Source: 0.2.SecuriteInfo.com.BackDoor.AgentTeslaNET.20.15021.21756.exe.47b9c30.1.raw.unpack, zt5ZQmVbkkBqLx1Emv.cs High entropy of concatenated method names: 'ToString', 'b1ZcNu7fJ8', 'cSMcEkAOMh', 'oKYcnCpAJk', 'XTPcOJ7WT9', 'Gn4c2lsGWT', 'KhScxLD6ph', 'v2TcZ6sfDJ', 'SiXcINeDDv', 'G5fcdcEXv7'
Source: 0.2.SecuriteInfo.com.BackDoor.AgentTeslaNET.20.15021.21756.exe.47b9c30.1.raw.unpack, DSgEOTuxglaQqdyJt4.cs High entropy of concatenated method names: 'LsFJWK9dLL', 'gHwJ6wcpXg', 'N9oJ1qqrLd', 'qJ2JrT1NBi', 'oF0JPruGI9', 'YJiJXq0fb4', 'VuWJwdkLaG', 'WpQaeCGYrI', 'JGOaSJEWL4', 'fYYaVyOWB2'
Source: 0.2.SecuriteInfo.com.BackDoor.AgentTeslaNET.20.15021.21756.exe.47b9c30.1.raw.unpack, m4NLGFLSi5nwgiFUmZ.cs High entropy of concatenated method names: 'kOtWhkokEf', 'JNJWg4iNgn', 'CorW9td0JJ', 'BxDWjVnJFi', 'KHaW5JVmVX', 'nqUWc7NSHo', 'cZsG11UTn52cA4cvCf', 'aBD57UAk82QA7TBPtf', 'iH1WWSEytp', 'wYpW6dEGh6'
Source: 0.2.SecuriteInfo.com.BackDoor.AgentTeslaNET.20.15021.21756.exe.47b9c30.1.raw.unpack, IjP6D5cWjjGgXCicYS.cs High entropy of concatenated method names: 'WAa6sSqc1S', 'WUn6rWJBsl', 'dBA6PtLDN5', 'mcP6kb863q', 'O8e6XwWJ5P', 'END6wlCudo', 'GmU6hhVDVO', 'uJr6gVG3cT', 'spK6ixMmCE', 'dwV699cQPw'
Source: 0.2.SecuriteInfo.com.BackDoor.AgentTeslaNET.20.15021.21756.exe.47b9c30.1.raw.unpack, T7gc9pHBV3sN5iLwRpa.cs High entropy of concatenated method names: 'hd2JtIwetV', 'XgQJK4tEma', 'CyvJBPlMXp', 'YqwJAUXxrL', 'XTPJGqrSQc', 'U58JDPqj4G', 'fCqJmSwfpp', 'HNZJLya46p', 'kXiJU0OPx2', 'RgbJ0fJAZu'
Source: 0.2.SecuriteInfo.com.BackDoor.AgentTeslaNET.20.15021.21756.exe.47b9c30.1.raw.unpack, Qtc6bKnyg9Tw7yp3vW.cs High entropy of concatenated method names: 'Gk9arp3FjY', 'ix0aPyZHSB', 'tZ5akBGuFT', 'IENaXyHWcT', 'wRHawk6AG2', 'SVpahhiq50', 'cemagtVdfM', 'Fg1aiNiT8A', 'd5Sa9KKQOU', 'JH8ajVVi5G'
Source: 0.2.SecuriteInfo.com.BackDoor.AgentTeslaNET.20.15021.21756.exe.7c90000.3.raw.unpack, RW0OBEMZBRha8lPi7Y.cs High entropy of concatenated method names: 'U4A5usFaGb', 'zYD5qHWnmv', 'z8P5HOytTi', 'XWa5Q6jVjJ', 'jPS5ERXFSD', 'ETx5n87u4E', 'ILk5ObrooB', 'cjv52DPJxE', 'Ydq5xe9GdL', 'QlA5Z0c1JD'
Source: 0.2.SecuriteInfo.com.BackDoor.AgentTeslaNET.20.15021.21756.exe.7c90000.3.raw.unpack, Elq5flWOXP5Q6q3T3r.cs High entropy of concatenated method names: 'e3NFSUTouP', 'dmVFYJWBge', 'r2naRi0hbg', 'BhfaWrQEoG', 'PYkFNKXSje', 'PAVFq6lK0O', 'AQeFfZt4HU', 'AoTFHgchdW', 'sY7FQ08Mny', 'suYFMt3SRV'
Source: 0.2.SecuriteInfo.com.BackDoor.AgentTeslaNET.20.15021.21756.exe.7c90000.3.raw.unpack, ipQMcJSeB9u6PMObKo.cs High entropy of concatenated method names: 'xFlBAkZZZ', 'LQJAQ50x7', 't7xDuKplu', 'RAumBYYNC', 'DDwUC4uKk', 'jAx0v9snF', 'ybdLi2NeBUhCnQrKDO', 't5NSvCQ28R6cJAhj3V', 'OJYa8IsHb', 'tta3UmkCK'
Source: 0.2.SecuriteInfo.com.BackDoor.AgentTeslaNET.20.15021.21756.exe.7c90000.3.raw.unpack, g9XJMjAY6v2RTawueQ.cs High entropy of concatenated method names: 'Dispose', 'enDWVMvg1v', 'PSyCEBxd69', 'xO1yyP6dwx', 'sw1WYGgLHW', 'EwiWzNBjk9', 'ProcessDialogKey', 'og1CRGeTVK', 'siTCWSmf4R', 'eakCC8tmR3'
Source: 0.2.SecuriteInfo.com.BackDoor.AgentTeslaNET.20.15021.21756.exe.7c90000.3.raw.unpack, ok7eroPtk1smVUHZAW.cs High entropy of concatenated method names: 'xInhtiOMqH', 'zjlhKyLP64', 'QeQhBty2fL', 'j2LhAeYlSN', 'RqChG2oY1X', 'GCahD89lE8', 'T3Phmq1rji', 'kmEhLIYld9', 'pu2hULeBOs', 'B8mh0BdRLM'
Source: 0.2.SecuriteInfo.com.BackDoor.AgentTeslaNET.20.15021.21756.exe.7c90000.3.raw.unpack, l8eIFKRqy7DJZhgLJ7.cs High entropy of concatenated method names: 'iCBwsvjEOn', 'kb4wPgnBIl', 'lTwwXUI7sR', 'cJZwhwk4CJ', 'SM3wgmxIye', 'WmYXTR87s7', 'aqGXbH36fR', 'e3TXeDAhJa', 'Y8FXSefcPU', 'DZVXV0SbJu'
Source: 0.2.SecuriteInfo.com.BackDoor.AgentTeslaNET.20.15021.21756.exe.7c90000.3.raw.unpack, I2V8A0QX4TkkgRwi5N.cs High entropy of concatenated method names: 'HKdhrCBiyi', 'GkKhkXUpOx', 'SYFhw67q5y', 'D2KwYOg94r', 'vHcwzQ73ci', 'M2DhRLMkGF', 'm1WhWGiV8y', 'onbhCtlsYg', 'r8Dh6hf1t4', 'ODHh1gmhlf'
Source: 0.2.SecuriteInfo.com.BackDoor.AgentTeslaNET.20.15021.21756.exe.7c90000.3.raw.unpack, zK05wjZFU51aXO1gUi.cs High entropy of concatenated method names: 'U2V7LH7AeD', 'ugL7UXI2HC', 'oP27pPM6rO', 'vmS7EuH6C7', 'bDc7OxCjfY', 'GIU72hdZfH', 'yL77ZwF9Im', 'tcc7IBsY6v', 'rjo7uOiI4K', 'RGM7NnDKka'
Source: 0.2.SecuriteInfo.com.BackDoor.AgentTeslaNET.20.15021.21756.exe.7c90000.3.raw.unpack, PmHr01qHTRVv3ooYoc.cs High entropy of concatenated method names: 'CDekAXp5XA', 'YZ4kDx8IKX', 'aHqkLyO5AD', 'TPGkUid8D4', 'dXfk5hrpJn', 'WulkcEqumj', 'asWkFHnXIZ', 'VeNkaDEdIK', 'm4GkJ7kdyG', 'GAwk3Yn6Gr'
Source: 0.2.SecuriteInfo.com.BackDoor.AgentTeslaNET.20.15021.21756.exe.7c90000.3.raw.unpack, rhl6gm1YyWv1nFsA5s.cs High entropy of concatenated method names: 'MSUapAckjb', 'IwDaEYFfNh', 'ISXanC5P69', 'eKxaOkOuyr', 'zsSaHfYF44', 'sQwa2b2qEm', 'Next', 'Next', 'Next', 'NextBytes'
Source: 0.2.SecuriteInfo.com.BackDoor.AgentTeslaNET.20.15021.21756.exe.7c90000.3.raw.unpack, gauagME0A2MimyuOoW.cs High entropy of concatenated method names: 'EditValue', 'GetEditStyle', 'NgpCVyowR0', 'wlOCY7nCEm', 'RhWCzQKSfb', 'w3G6RpEISZ', 'pTs6WMZKUp', 'TA46CVNvrb', 'vtn66XZ6B7', 'z81FFCfyjgPOymts9jB'
Source: 0.2.SecuriteInfo.com.BackDoor.AgentTeslaNET.20.15021.21756.exe.7c90000.3.raw.unpack, jw5wIHaY3wWQ2nPBcN.cs High entropy of concatenated method names: 'RRMF9110jX', 'Vv9Fj0xZ78', 'ToString', 'l4aFrcFidl', 'GjKFPQZMth', 'Mu4Fkjq5GU', 'CtDFXcaTny', 'jvJFw08OqG', 'UYWFhKxGhB', 'VqZFgQ88w3'
Source: 0.2.SecuriteInfo.com.BackDoor.AgentTeslaNET.20.15021.21756.exe.7c90000.3.raw.unpack, pjLLLur9tiSkaioQPu.cs High entropy of concatenated method names: 'H1ZPHpdNgr', 'O1BPQLH0dy', 'yhmPMC2eDW', 'FmuP4yR6eh', 'ybKPT79phS', 'YhTPbyUjxs', 'QFPPeVFxdf', 'NCRPSjlaUU', 'tqNPVgYh7X', 'w5KPYmJrL3'
Source: 0.2.SecuriteInfo.com.BackDoor.AgentTeslaNET.20.15021.21756.exe.7c90000.3.raw.unpack, Obo1J1YkSoh2CJ8pK4.cs High entropy of concatenated method names: 'GggwlXTmJm', 'RkGwtuQbJf', 'GGgwBpmOxe', 'CV1wAGk0of', 'nR7wDTvZlW', 'Yn9wmiAeEP', 'q1gwUNwU3B', 'TEtw08DInI', 'Yctqh6yJ64U02LxZFVP', 'i5GUjLyMcIFJ1IM392W'
Source: 0.2.SecuriteInfo.com.BackDoor.AgentTeslaNET.20.15021.21756.exe.7c90000.3.raw.unpack, tqra9GvmsmS2fRiQIx.cs High entropy of concatenated method names: 'XuXwMxaSd0', 'xq0w4YPsfm', 'gEAwTNaCeo', 'ToString', 'B9fwbjsgtm', 'xk8weELGNl', 'DMrV1hyKDK5rgNWSSfH', 'A5IyftyjdpxuiPICjlx', 'QT7pJMycgi4FKpLJmwo'
Source: 0.2.SecuriteInfo.com.BackDoor.AgentTeslaNET.20.15021.21756.exe.7c90000.3.raw.unpack, mBF12IFFOEARE2eysc.cs High entropy of concatenated method names: 'c0LXGFdCox', 'gP7XmUbWiX', 'ObxknIvCBm', 'SHHkOAJb7C', 'yBdk2TFFSE', 'l1YkxDj2Ko', 'nhSkZkDVLS', 'q2QkIJDtNu', 'NE1kdImDpE', 'Hh4kuVpgrD'
Source: 0.2.SecuriteInfo.com.BackDoor.AgentTeslaNET.20.15021.21756.exe.7c90000.3.raw.unpack, zt5ZQmVbkkBqLx1Emv.cs High entropy of concatenated method names: 'ToString', 'b1ZcNu7fJ8', 'cSMcEkAOMh', 'oKYcnCpAJk', 'XTPcOJ7WT9', 'Gn4c2lsGWT', 'KhScxLD6ph', 'v2TcZ6sfDJ', 'SiXcINeDDv', 'G5fcdcEXv7'
Source: 0.2.SecuriteInfo.com.BackDoor.AgentTeslaNET.20.15021.21756.exe.7c90000.3.raw.unpack, DSgEOTuxglaQqdyJt4.cs High entropy of concatenated method names: 'LsFJWK9dLL', 'gHwJ6wcpXg', 'N9oJ1qqrLd', 'qJ2JrT1NBi', 'oF0JPruGI9', 'YJiJXq0fb4', 'VuWJwdkLaG', 'WpQaeCGYrI', 'JGOaSJEWL4', 'fYYaVyOWB2'
Source: 0.2.SecuriteInfo.com.BackDoor.AgentTeslaNET.20.15021.21756.exe.7c90000.3.raw.unpack, m4NLGFLSi5nwgiFUmZ.cs High entropy of concatenated method names: 'kOtWhkokEf', 'JNJWg4iNgn', 'CorW9td0JJ', 'BxDWjVnJFi', 'KHaW5JVmVX', 'nqUWc7NSHo', 'cZsG11UTn52cA4cvCf', 'aBD57UAk82QA7TBPtf', 'iH1WWSEytp', 'wYpW6dEGh6'
Source: 0.2.SecuriteInfo.com.BackDoor.AgentTeslaNET.20.15021.21756.exe.7c90000.3.raw.unpack, IjP6D5cWjjGgXCicYS.cs High entropy of concatenated method names: 'WAa6sSqc1S', 'WUn6rWJBsl', 'dBA6PtLDN5', 'mcP6kb863q', 'O8e6XwWJ5P', 'END6wlCudo', 'GmU6hhVDVO', 'uJr6gVG3cT', 'spK6ixMmCE', 'dwV699cQPw'
Source: 0.2.SecuriteInfo.com.BackDoor.AgentTeslaNET.20.15021.21756.exe.7c90000.3.raw.unpack, T7gc9pHBV3sN5iLwRpa.cs High entropy of concatenated method names: 'hd2JtIwetV', 'XgQJK4tEma', 'CyvJBPlMXp', 'YqwJAUXxrL', 'XTPJGqrSQc', 'U58JDPqj4G', 'fCqJmSwfpp', 'HNZJLya46p', 'kXiJU0OPx2', 'RgbJ0fJAZu'
Source: 0.2.SecuriteInfo.com.BackDoor.AgentTeslaNET.20.15021.21756.exe.7c90000.3.raw.unpack, Qtc6bKnyg9Tw7yp3vW.cs High entropy of concatenated method names: 'Gk9arp3FjY', 'ix0aPyZHSB', 'tZ5akBGuFT', 'IENaXyHWcT', 'wRHawk6AG2', 'SVpahhiq50', 'cemagtVdfM', 'Fg1aiNiT8A', 'd5Sa9KKQOU', 'JH8ajVVi5G'

Hooking and other Techniques for Hiding and Protection

barindex
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe File opened: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\Modules\BitLocker\BitLocker.psd1 Jump to behavior
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe File opened: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\Modules\BitLocker\BitLocker.psd1 Jump to behavior
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe File opened: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\Modules\BitLocker\BitLocker.psd1 Jump to behavior
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe File opened: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\Modules\BitLocker\en-US\BitLocker.psd1 Jump to behavior
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe File opened: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\Modules\BitLocker\en-US\BitLocker.psd1 Jump to behavior
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe File opened: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\Modules\BitLocker\BitLocker.psd1 Jump to behavior
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe File opened: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\Modules\BitLocker\en-US\BitLocker.psd1 Jump to behavior
Source: C:\Users\user\Desktop\SecuriteInfo.com.BackDoor.AgentTeslaNET.20.15021.21756.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Users\user\Desktop\SecuriteInfo.com.BackDoor.AgentTeslaNET.20.15021.21756.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Users\user\Desktop\SecuriteInfo.com.BackDoor.AgentTeslaNET.20.15021.21756.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Users\user\Desktop\SecuriteInfo.com.BackDoor.AgentTeslaNET.20.15021.21756.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Users\user\Desktop\SecuriteInfo.com.BackDoor.AgentTeslaNET.20.15021.21756.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Users\user\Desktop\SecuriteInfo.com.BackDoor.AgentTeslaNET.20.15021.21756.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Users\user\Desktop\SecuriteInfo.com.BackDoor.AgentTeslaNET.20.15021.21756.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Users\user\Desktop\SecuriteInfo.com.BackDoor.AgentTeslaNET.20.15021.21756.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Users\user\Desktop\SecuriteInfo.com.BackDoor.AgentTeslaNET.20.15021.21756.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Users\user\Desktop\SecuriteInfo.com.BackDoor.AgentTeslaNET.20.15021.21756.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Users\user\Desktop\SecuriteInfo.com.BackDoor.AgentTeslaNET.20.15021.21756.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Users\user\Desktop\SecuriteInfo.com.BackDoor.AgentTeslaNET.20.15021.21756.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Users\user\Desktop\SecuriteInfo.com.BackDoor.AgentTeslaNET.20.15021.21756.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Users\user\Desktop\SecuriteInfo.com.BackDoor.AgentTeslaNET.20.15021.21756.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Users\user\Desktop\SecuriteInfo.com.BackDoor.AgentTeslaNET.20.15021.21756.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Users\user\Desktop\SecuriteInfo.com.BackDoor.AgentTeslaNET.20.15021.21756.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Users\user\Desktop\SecuriteInfo.com.BackDoor.AgentTeslaNET.20.15021.21756.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Users\user\Desktop\SecuriteInfo.com.BackDoor.AgentTeslaNET.20.15021.21756.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Users\user\Desktop\SecuriteInfo.com.BackDoor.AgentTeslaNET.20.15021.21756.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Users\user\Desktop\SecuriteInfo.com.BackDoor.AgentTeslaNET.20.15021.21756.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Users\user\Desktop\SecuriteInfo.com.BackDoor.AgentTeslaNET.20.15021.21756.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Users\user\Desktop\SecuriteInfo.com.BackDoor.AgentTeslaNET.20.15021.21756.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Users\user\Desktop\SecuriteInfo.com.BackDoor.AgentTeslaNET.20.15021.21756.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Users\user\Desktop\SecuriteInfo.com.BackDoor.AgentTeslaNET.20.15021.21756.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Users\user\Desktop\SecuriteInfo.com.BackDoor.AgentTeslaNET.20.15021.21756.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Users\user\Desktop\SecuriteInfo.com.BackDoor.AgentTeslaNET.20.15021.21756.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Users\user\Desktop\SecuriteInfo.com.BackDoor.AgentTeslaNET.20.15021.21756.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Users\user\Desktop\SecuriteInfo.com.BackDoor.AgentTeslaNET.20.15021.21756.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Users\user\Desktop\SecuriteInfo.com.BackDoor.AgentTeslaNET.20.15021.21756.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Users\user\Desktop\SecuriteInfo.com.BackDoor.AgentTeslaNET.20.15021.21756.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Users\user\Desktop\SecuriteInfo.com.BackDoor.AgentTeslaNET.20.15021.21756.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Users\user\Desktop\SecuriteInfo.com.BackDoor.AgentTeslaNET.20.15021.21756.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Users\user\Desktop\SecuriteInfo.com.BackDoor.AgentTeslaNET.20.15021.21756.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Users\user\Desktop\SecuriteInfo.com.BackDoor.AgentTeslaNET.20.15021.21756.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Users\user\Desktop\SecuriteInfo.com.BackDoor.AgentTeslaNET.20.15021.21756.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Users\user\Desktop\SecuriteInfo.com.BackDoor.AgentTeslaNET.20.15021.21756.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Users\user\Desktop\SecuriteInfo.com.BackDoor.AgentTeslaNET.20.15021.21756.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Users\user\Desktop\SecuriteInfo.com.BackDoor.AgentTeslaNET.20.15021.21756.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Users\user\Desktop\SecuriteInfo.com.BackDoor.AgentTeslaNET.20.15021.21756.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Users\user\Desktop\SecuriteInfo.com.BackDoor.AgentTeslaNET.20.15021.21756.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Users\user\Desktop\SecuriteInfo.com.BackDoor.AgentTeslaNET.20.15021.21756.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Users\user\Desktop\SecuriteInfo.com.BackDoor.AgentTeslaNET.20.15021.21756.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Users\user\Desktop\SecuriteInfo.com.BackDoor.AgentTeslaNET.20.15021.21756.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Windows\SysWOW64\WerFault.exe Process information set: FAILCRITICALERRORS | NOGPFAULTERRORBOX Jump to behavior
Source: C:\Windows\SysWOW64\WerFault.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Windows\SysWOW64\WerFault.exe Process information set: FAILCRITICALERRORS | NOGPFAULTERRORBOX Jump to behavior
Source: C:\Windows\SysWOW64\WerFault.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Windows\SysWOW64\WerFault.exe Process information set: FAILCRITICALERRORS | NOGPFAULTERRORBOX Jump to behavior
Source: C:\Windows\SysWOW64\WerFault.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Windows\SysWOW64\WerFault.exe Process information set: FAILCRITICALERRORS | NOGPFAULTERRORBOX Jump to behavior
Source: C:\Windows\SysWOW64\WerFault.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Windows\SysWOW64\WerFault.exe Process information set: FAILCRITICALERRORS | NOGPFAULTERRORBOX Jump to behavior
Source: C:\Windows\SysWOW64\WerFault.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Windows\SysWOW64\WerFault.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Windows\SysWOW64\WerFault.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Windows\SysWOW64\WerFault.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Windows\SysWOW64\WerFault.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Windows\SysWOW64\WerFault.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Windows\SysWOW64\WerFault.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Windows\SysWOW64\WerFault.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Windows\SysWOW64\WerFault.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Windows\SysWOW64\WerFault.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Windows\SysWOW64\WerFault.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Windows\SysWOW64\WerFault.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Windows\SysWOW64\WerFault.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Windows\SysWOW64\WerFault.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Windows\SysWOW64\WerFault.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Windows\SysWOW64\WerFault.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Windows\SysWOW64\WerFault.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Windows\SysWOW64\WerFault.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Windows\SysWOW64\WerFault.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Windows\SysWOW64\WerFault.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Windows\SysWOW64\WerFault.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Windows\SysWOW64\WerFault.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Windows\SysWOW64\WerFault.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Windows\SysWOW64\WerFault.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Windows\SysWOW64\WerFault.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Windows\SysWOW64\WerFault.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Windows\SysWOW64\WerFault.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Windows\SysWOW64\WerFault.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Windows\SysWOW64\WerFault.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Windows\SysWOW64\WerFault.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Windows\SysWOW64\WerFault.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Windows\SysWOW64\WerFault.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Windows\SysWOW64\WerFault.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Windows\SysWOW64\WerFault.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Windows\SysWOW64\WerFault.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Windows\SysWOW64\WerFault.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Windows\SysWOW64\WerFault.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Windows\SysWOW64\WerFault.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Windows\SysWOW64\WerFault.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Windows\SysWOW64\WerFault.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Windows\SysWOW64\WerFault.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Windows\SysWOW64\WerFault.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Windows\SysWOW64\WerFault.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Windows\SysWOW64\WerFault.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Windows\SysWOW64\WerFault.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Windows\SysWOW64\WerFault.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Windows\SysWOW64\WerFault.exe Process information set: NOOPENFILEERRORBOX Jump to behavior

Malware Analysis System Evasion

barindex
Source: Yara match File source: Process Memory Space: SecuriteInfo.com.BackDoor.AgentTeslaNET.20.15021.21756.exe PID: 6192, type: MEMORYSTR
Source: C:\Users\user\Desktop\SecuriteInfo.com.BackDoor.AgentTeslaNET.20.15021.21756.exe Memory allocated: 2C70000 memory reserve | memory write watch Jump to behavior
Source: C:\Users\user\Desktop\SecuriteInfo.com.BackDoor.AgentTeslaNET.20.15021.21756.exe Memory allocated: 2CA0000 memory reserve | memory write watch Jump to behavior
Source: C:\Users\user\Desktop\SecuriteInfo.com.BackDoor.AgentTeslaNET.20.15021.21756.exe Memory allocated: 4CA0000 memory reserve | memory write watch Jump to behavior
Source: C:\Users\user\Desktop\SecuriteInfo.com.BackDoor.AgentTeslaNET.20.15021.21756.exe Memory allocated: 9300000 memory reserve | memory write watch Jump to behavior
Source: C:\Users\user\Desktop\SecuriteInfo.com.BackDoor.AgentTeslaNET.20.15021.21756.exe Memory allocated: A300000 memory reserve | memory write watch Jump to behavior
Source: C:\Users\user\Desktop\SecuriteInfo.com.BackDoor.AgentTeslaNET.20.15021.21756.exe Memory allocated: A520000 memory reserve | memory write watch Jump to behavior
Source: C:\Users\user\Desktop\SecuriteInfo.com.BackDoor.AgentTeslaNET.20.15021.21756.exe Memory allocated: B520000 memory reserve | memory write watch Jump to behavior
Source: C:\Users\user\Desktop\SecuriteInfo.com.BackDoor.AgentTeslaNET.20.15021.21756.exe Memory allocated: B950000 memory reserve | memory write watch Jump to behavior
Source: C:\Users\user\Desktop\SecuriteInfo.com.BackDoor.AgentTeslaNET.20.15021.21756.exe Memory allocated: C950000 memory reserve | memory write watch Jump to behavior
Source: C:\Users\user\Desktop\SecuriteInfo.com.BackDoor.AgentTeslaNET.20.15021.21756.exe Code function: 4_2_0184096E rdtsc 4_2_0184096E
Source: C:\Users\user\Desktop\SecuriteInfo.com.BackDoor.AgentTeslaNET.20.15021.21756.exe Thread delayed: delay time: 922337203685477 Jump to behavior
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe Thread delayed: delay time: 922337203685477 Jump to behavior
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe Thread delayed: delay time: 922337203685477 Jump to behavior
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe Window / User API: threadDelayed 4818 Jump to behavior
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe Window / User API: threadDelayed 616 Jump to behavior
Source: C:\Users\user\Desktop\SecuriteInfo.com.BackDoor.AgentTeslaNET.20.15021.21756.exe API coverage: 0.3 %
Source: C:\Users\user\Desktop\SecuriteInfo.com.BackDoor.AgentTeslaNET.20.15021.21756.exe TID: 6168 Thread sleep time: -922337203685477s >= -30000s Jump to behavior
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe TID: 1704 Thread sleep time: -922337203685477s >= -30000s Jump to behavior
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe TID: 1028 Thread sleep time: -922337203685477s >= -30000s Jump to behavior
Source: C:\Users\user\Desktop\SecuriteInfo.com.BackDoor.AgentTeslaNET.20.15021.21756.exe Thread delayed: delay time: 922337203685477 Jump to behavior
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe Thread delayed: delay time: 922337203685477 Jump to behavior
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe Thread delayed: delay time: 922337203685477 Jump to behavior
Source: Amcache.hve.11.dr Binary or memory string: VMware
Source: Amcache.hve.11.dr Binary or memory string: VMware Virtual USB Mouse
Source: Amcache.hve.11.dr Binary or memory string: vmci.syshbin
Source: Amcache.hve.11.dr Binary or memory string: VMware, Inc.
Source: Amcache.hve.11.dr Binary or memory string: VMware20,1hbin@
Source: Amcache.hve.11.dr Binary or memory string: c:\windows\system32\driverstore\filerepository\vmci.inf_amd64_68ed49469341f563
Source: Amcache.hve.11.dr Binary or memory string: Ascsi/cdrom&ven_necvmwar&prod_vmware_sata_cd00/4&224f42ef&0&000000
Source: Amcache.hve.11.dr Binary or memory string: .Z$c:/windows/system32/drivers/vmci.sys
Source: Amcache.hve.11.dr Binary or memory string: :scsi/disk&ven_vmware&prod_virtual_disk/4&1656f219&0&000000
Source: Amcache.hve.11.dr Binary or memory string: pci\ven_15ad&dev_0740&subsys_074015ad,pci\ven_15ad&dev_0740,root\vmwvmcihostdev
Source: Amcache.hve.11.dr Binary or memory string: c:/windows/system32/drivers/vmci.sys
Source: Amcache.hve.11.dr Binary or memory string: scsi/cdrom&ven_necvmwar&prod_vmware_sata_cd00/4&224f42ef&0&000000
Source: Amcache.hve.11.dr Binary or memory string: vmci.sys
Source: Amcache.hve.11.dr Binary or memory string: VMware-56 4d 43 71 48 15 3d ed-ae e6 c7 5a ec d9 3b f0
Source: Amcache.hve.11.dr Binary or memory string: vmci.syshbin`
Source: Amcache.hve.11.dr Binary or memory string: \driver\vmci,\driver\pci
Source: Amcache.hve.11.dr Binary or memory string: scsi/disk&ven_vmware&prod_virtual_disk/4&1656f219&0&000000
Source: Amcache.hve.11.dr Binary or memory string: VMware20,1
Source: Amcache.hve.11.dr Binary or memory string: Microsoft Hyper-V Generation Counter
Source: Amcache.hve.11.dr Binary or memory string: NECVMWar VMware SATA CD00
Source: Amcache.hve.11.dr Binary or memory string: VMware Virtual disk SCSI Disk Device
Source: Amcache.hve.11.dr Binary or memory string: scsi\cdromnecvmwarvmware_sata_cd001.00,scsi\cdromnecvmwarvmware_sata_cd00,scsi\cdromnecvmwar,scsi\necvmwarvmware_sata_cd001,necvmwarvmware_sata_cd001,gencdrom
Source: Amcache.hve.11.dr Binary or memory string: scsi\diskvmware__virtual_disk____2.0_,scsi\diskvmware__virtual_disk____,scsi\diskvmware__,scsi\vmware__virtual_disk____2,vmware__virtual_disk____2,gendisk
Source: Amcache.hve.11.dr Binary or memory string: Microsoft Hyper-V Virtualization Infrastructure Driver
Source: Amcache.hve.11.dr Binary or memory string: VMware PCI VMCI Bus Device
Source: Amcache.hve.11.dr Binary or memory string: VMware VMCI Bus Device
Source: Amcache.hve.11.dr Binary or memory string: VMware Virtual RAM
Source: Amcache.hve.11.dr Binary or memory string: BiosVendor:VMware, Inc.,BiosVersion:VMW201.00V.20829224.B64.2211211842,BiosReleaseDate:11/21/2022,BiosMajorRelease:0xff,BiosMinorRelease:0xff,SystemManufacturer:VMware, Inc.,SystemProduct:VMware20,1,SystemFamily:,SystemSKUNumber:,BaseboardManufacturer:,BaseboardProduct:,BaseboardVersion:,EnclosureType:0x1
Source: Amcache.hve.11.dr Binary or memory string: vmci.inf_amd64_68ed49469341f563
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe Process information queried: ProcessInformation Jump to behavior
Source: C:\Users\user\Desktop\SecuriteInfo.com.BackDoor.AgentTeslaNET.20.15021.21756.exe Process queried: DebugPort Jump to behavior
Source: C:\Users\user\Desktop\SecuriteInfo.com.BackDoor.AgentTeslaNET.20.15021.21756.exe Process queried: DebugPort Jump to behavior
Source: C:\Users\user\Desktop\SecuriteInfo.com.BackDoor.AgentTeslaNET.20.15021.21756.exe Code function: 4_2_0184096E rdtsc 4_2_0184096E
Source: C:\Users\user\Desktop\SecuriteInfo.com.BackDoor.AgentTeslaNET.20.15021.21756.exe Code function: 4_2_01842DF0 NtQuerySystemInformation,LdrInitializeThunk, 4_2_01842DF0
Source: C:\Users\user\Desktop\SecuriteInfo.com.BackDoor.AgentTeslaNET.20.15021.21756.exe Code function: 4_2_01840185 mov eax, dword ptr fs:[00000030h] 4_2_01840185
Source: C:\Users\user\Desktop\SecuriteInfo.com.BackDoor.AgentTeslaNET.20.15021.21756.exe Code function: 4_2_018BC188 mov eax, dword ptr fs:[00000030h] 4_2_018BC188
Source: C:\Users\user\Desktop\SecuriteInfo.com.BackDoor.AgentTeslaNET.20.15021.21756.exe Code function: 4_2_018BC188 mov eax, dword ptr fs:[00000030h] 4_2_018BC188
Source: C:\Users\user\Desktop\SecuriteInfo.com.BackDoor.AgentTeslaNET.20.15021.21756.exe Code function: 4_2_018A4180 mov eax, dword ptr fs:[00000030h] 4_2_018A4180
Source: C:\Users\user\Desktop\SecuriteInfo.com.BackDoor.AgentTeslaNET.20.15021.21756.exe Code function: 4_2_018A4180 mov eax, dword ptr fs:[00000030h] 4_2_018A4180
Source: C:\Users\user\Desktop\SecuriteInfo.com.BackDoor.AgentTeslaNET.20.15021.21756.exe Code function: 4_2_0188019F mov eax, dword ptr fs:[00000030h] 4_2_0188019F
Source: C:\Users\user\Desktop\SecuriteInfo.com.BackDoor.AgentTeslaNET.20.15021.21756.exe Code function: 4_2_0188019F mov eax, dword ptr fs:[00000030h] 4_2_0188019F
Source: C:\Users\user\Desktop\SecuriteInfo.com.BackDoor.AgentTeslaNET.20.15021.21756.exe Code function: 4_2_0188019F mov eax, dword ptr fs:[00000030h] 4_2_0188019F
Source: C:\Users\user\Desktop\SecuriteInfo.com.BackDoor.AgentTeslaNET.20.15021.21756.exe Code function: 4_2_0188019F mov eax, dword ptr fs:[00000030h] 4_2_0188019F
Source: C:\Users\user\Desktop\SecuriteInfo.com.BackDoor.AgentTeslaNET.20.15021.21756.exe Code function: 4_2_017FC156 mov eax, dword ptr fs:[00000030h] 4_2_017FC156
Source: C:\Users\user\Desktop\SecuriteInfo.com.BackDoor.AgentTeslaNET.20.15021.21756.exe Code function: 4_2_018C61C3 mov eax, dword ptr fs:[00000030h] 4_2_018C61C3
Source: C:\Users\user\Desktop\SecuriteInfo.com.BackDoor.AgentTeslaNET.20.15021.21756.exe Code function: 4_2_018C61C3 mov eax, dword ptr fs:[00000030h] 4_2_018C61C3
Source: C:\Users\user\Desktop\SecuriteInfo.com.BackDoor.AgentTeslaNET.20.15021.21756.exe Code function: 4_2_0187E1D0 mov eax, dword ptr fs:[00000030h] 4_2_0187E1D0
Source: C:\Users\user\Desktop\SecuriteInfo.com.BackDoor.AgentTeslaNET.20.15021.21756.exe Code function: 4_2_0187E1D0 mov eax, dword ptr fs:[00000030h] 4_2_0187E1D0
Source: C:\Users\user\Desktop\SecuriteInfo.com.BackDoor.AgentTeslaNET.20.15021.21756.exe Code function: 4_2_0187E1D0 mov ecx, dword ptr fs:[00000030h] 4_2_0187E1D0
Source: C:\Users\user\Desktop\SecuriteInfo.com.BackDoor.AgentTeslaNET.20.15021.21756.exe Code function: 4_2_0187E1D0 mov eax, dword ptr fs:[00000030h] 4_2_0187E1D0
Source: C:\Users\user\Desktop\SecuriteInfo.com.BackDoor.AgentTeslaNET.20.15021.21756.exe Code function: 4_2_0187E1D0 mov eax, dword ptr fs:[00000030h] 4_2_0187E1D0
Source: C:\Users\user\Desktop\SecuriteInfo.com.BackDoor.AgentTeslaNET.20.15021.21756.exe Code function: 4_2_018D61E5 mov eax, dword ptr fs:[00000030h] 4_2_018D61E5
Source: C:\Users\user\Desktop\SecuriteInfo.com.BackDoor.AgentTeslaNET.20.15021.21756.exe Code function: 4_2_018301F8 mov eax, dword ptr fs:[00000030h] 4_2_018301F8
Source: C:\Users\user\Desktop\SecuriteInfo.com.BackDoor.AgentTeslaNET.20.15021.21756.exe Code function: 4_2_018AE10E mov eax, dword ptr fs:[00000030h] 4_2_018AE10E
Source: C:\Users\user\Desktop\SecuriteInfo.com.BackDoor.AgentTeslaNET.20.15021.21756.exe Code function: 4_2_018AE10E mov ecx, dword ptr fs:[00000030h] 4_2_018AE10E
Source: C:\Users\user\Desktop\SecuriteInfo.com.BackDoor.AgentTeslaNET.20.15021.21756.exe Code function: 4_2_018AE10E mov eax, dword ptr fs:[00000030h] 4_2_018AE10E
Source: C:\Users\user\Desktop\SecuriteInfo.com.BackDoor.AgentTeslaNET.20.15021.21756.exe Code function: 4_2_018AE10E mov eax, dword ptr fs:[00000030h] 4_2_018AE10E
Source: C:\Users\user\Desktop\SecuriteInfo.com.BackDoor.AgentTeslaNET.20.15021.21756.exe Code function: 4_2_018AE10E mov ecx, dword ptr fs:[00000030h] 4_2_018AE10E
Source: C:\Users\user\Desktop\SecuriteInfo.com.BackDoor.AgentTeslaNET.20.15021.21756.exe Code function: 4_2_018AE10E mov eax, dword ptr fs:[00000030h] 4_2_018AE10E
Source: C:\Users\user\Desktop\SecuriteInfo.com.BackDoor.AgentTeslaNET.20.15021.21756.exe Code function: 4_2_018AE10E mov eax, dword ptr fs:[00000030h] 4_2_018AE10E
Source: C:\Users\user\Desktop\SecuriteInfo.com.BackDoor.AgentTeslaNET.20.15021.21756.exe Code function: 4_2_018AE10E mov ecx, dword ptr fs:[00000030h] 4_2_018AE10E
Source: C:\Users\user\Desktop\SecuriteInfo.com.BackDoor.AgentTeslaNET.20.15021.21756.exe Code function: 4_2_018AE10E mov eax, dword ptr fs:[00000030h] 4_2_018AE10E
Source: C:\Users\user\Desktop\SecuriteInfo.com.BackDoor.AgentTeslaNET.20.15021.21756.exe Code function: 4_2_018AE10E mov ecx, dword ptr fs:[00000030h] 4_2_018AE10E
Source: C:\Users\user\Desktop\SecuriteInfo.com.BackDoor.AgentTeslaNET.20.15021.21756.exe Code function: 4_2_018AA118 mov ecx, dword ptr fs:[00000030h] 4_2_018AA118
Source: C:\Users\user\Desktop\SecuriteInfo.com.BackDoor.AgentTeslaNET.20.15021.21756.exe Code function: 4_2_018AA118 mov eax, dword ptr fs:[00000030h] 4_2_018AA118
Source: C:\Users\user\Desktop\SecuriteInfo.com.BackDoor.AgentTeslaNET.20.15021.21756.exe Code function: 4_2_018AA118 mov eax, dword ptr fs:[00000030h] 4_2_018AA118
Source: C:\Users\user\Desktop\SecuriteInfo.com.BackDoor.AgentTeslaNET.20.15021.21756.exe Code function: 4_2_018AA118 mov eax, dword ptr fs:[00000030h] 4_2_018AA118
Source: C:\Users\user\Desktop\SecuriteInfo.com.BackDoor.AgentTeslaNET.20.15021.21756.exe Code function: 4_2_018C0115 mov eax, dword ptr fs:[00000030h] 4_2_018C0115
Source: C:\Users\user\Desktop\SecuriteInfo.com.BackDoor.AgentTeslaNET.20.15021.21756.exe Code function: 4_2_01830124 mov eax, dword ptr fs:[00000030h] 4_2_01830124
Source: C:\Users\user\Desktop\SecuriteInfo.com.BackDoor.AgentTeslaNET.20.15021.21756.exe Code function: 4_2_01894144 mov eax, dword ptr fs:[00000030h] 4_2_01894144
Source: C:\Users\user\Desktop\SecuriteInfo.com.BackDoor.AgentTeslaNET.20.15021.21756.exe Code function: 4_2_01894144 mov eax, dword ptr fs:[00000030h] 4_2_01894144
Source: C:\Users\user\Desktop\SecuriteInfo.com.BackDoor.AgentTeslaNET.20.15021.21756.exe Code function: 4_2_01894144 mov ecx, dword ptr fs:[00000030h] 4_2_01894144
Source: C:\Users\user\Desktop\SecuriteInfo.com.BackDoor.AgentTeslaNET.20.15021.21756.exe Code function: 4_2_01894144 mov eax, dword ptr fs:[00000030h] 4_2_01894144
Source: C:\Users\user\Desktop\SecuriteInfo.com.BackDoor.AgentTeslaNET.20.15021.21756.exe Code function: 4_2_01894144 mov eax, dword ptr fs:[00000030h] 4_2_01894144
Source: C:\Users\user\Desktop\SecuriteInfo.com.BackDoor.AgentTeslaNET.20.15021.21756.exe Code function: 4_2_01898158 mov eax, dword ptr fs:[00000030h] 4_2_01898158
Source: C:\Users\user\Desktop\SecuriteInfo.com.BackDoor.AgentTeslaNET.20.15021.21756.exe Code function: 4_2_01806154 mov eax, dword ptr fs:[00000030h] 4_2_01806154
Source: C:\Users\user\Desktop\SecuriteInfo.com.BackDoor.AgentTeslaNET.20.15021.21756.exe Code function: 4_2_01806154 mov eax, dword ptr fs:[00000030h] 4_2_01806154
Source: C:\Users\user\Desktop\SecuriteInfo.com.BackDoor.AgentTeslaNET.20.15021.21756.exe Code function: 4_2_017FA197 mov eax, dword ptr fs:[00000030h] 4_2_017FA197
Source: C:\Users\user\Desktop\SecuriteInfo.com.BackDoor.AgentTeslaNET.20.15021.21756.exe Code function: 4_2_017FA197 mov eax, dword ptr fs:[00000030h] 4_2_017FA197
Source: C:\Users\user\Desktop\SecuriteInfo.com.BackDoor.AgentTeslaNET.20.15021.21756.exe Code function: 4_2_017FA197 mov eax, dword ptr fs:[00000030h] 4_2_017FA197
Source: C:\Users\user\Desktop\SecuriteInfo.com.BackDoor.AgentTeslaNET.20.15021.21756.exe Code function: 4_2_018D4164 mov eax, dword ptr fs:[00000030h] 4_2_018D4164
Source: C:\Users\user\Desktop\SecuriteInfo.com.BackDoor.AgentTeslaNET.20.15021.21756.exe Code function: 4_2_018D4164 mov eax, dword ptr fs:[00000030h] 4_2_018D4164
Source: C:\Users\user\Desktop\SecuriteInfo.com.BackDoor.AgentTeslaNET.20.15021.21756.exe Code function: 4_2_0180208A mov eax, dword ptr fs:[00000030h] 4_2_0180208A
Source: C:\Users\user\Desktop\SecuriteInfo.com.BackDoor.AgentTeslaNET.20.15021.21756.exe Code function: 4_2_018980A8 mov eax, dword ptr fs:[00000030h] 4_2_018980A8
Source: C:\Users\user\Desktop\SecuriteInfo.com.BackDoor.AgentTeslaNET.20.15021.21756.exe Code function: 4_2_018C60B8 mov eax, dword ptr fs:[00000030h] 4_2_018C60B8
Source: C:\Users\user\Desktop\SecuriteInfo.com.BackDoor.AgentTeslaNET.20.15021.21756.exe Code function: 4_2_018C60B8 mov ecx, dword ptr fs:[00000030h] 4_2_018C60B8
Source: C:\Users\user\Desktop\SecuriteInfo.com.BackDoor.AgentTeslaNET.20.15021.21756.exe Code function: 4_2_018820DE mov eax, dword ptr fs:[00000030h] 4_2_018820DE
Source: C:\Users\user\Desktop\SecuriteInfo.com.BackDoor.AgentTeslaNET.20.15021.21756.exe Code function: 4_2_017FA020 mov eax, dword ptr fs:[00000030h] 4_2_017FA020
Source: C:\Users\user\Desktop\SecuriteInfo.com.BackDoor.AgentTeslaNET.20.15021.21756.exe Code function: 4_2_017FC020 mov eax, dword ptr fs:[00000030h] 4_2_017FC020
Source: C:\Users\user\Desktop\SecuriteInfo.com.BackDoor.AgentTeslaNET.20.15021.21756.exe Code function: 4_2_018860E0 mov eax, dword ptr fs:[00000030h] 4_2_018860E0
Source: C:\Users\user\Desktop\SecuriteInfo.com.BackDoor.AgentTeslaNET.20.15021.21756.exe Code function: 4_2_018080E9 mov eax, dword ptr fs:[00000030h] 4_2_018080E9
Source: C:\Users\user\Desktop\SecuriteInfo.com.BackDoor.AgentTeslaNET.20.15021.21756.exe Code function: 4_2_018420F0 mov ecx, dword ptr fs:[00000030h] 4_2_018420F0
Source: C:\Users\user\Desktop\SecuriteInfo.com.BackDoor.AgentTeslaNET.20.15021.21756.exe Code function: 4_2_01884000 mov ecx, dword ptr fs:[00000030h] 4_2_01884000
Source: C:\Users\user\Desktop\SecuriteInfo.com.BackDoor.AgentTeslaNET.20.15021.21756.exe Code function: 4_2_018A2000 mov eax, dword ptr fs:[00000030h] 4_2_018A2000
Source: C:\Users\user\Desktop\SecuriteInfo.com.BackDoor.AgentTeslaNET.20.15021.21756.exe Code function: 4_2_018A2000 mov eax, dword ptr fs:[00000030h] 4_2_018A2000
Source: C:\Users\user\Desktop\SecuriteInfo.com.BackDoor.AgentTeslaNET.20.15021.21756.exe Code function: 4_2_018A2000 mov eax, dword ptr fs:[00000030h] 4_2_018A2000
Source: C:\Users\user\Desktop\SecuriteInfo.com.BackDoor.AgentTeslaNET.20.15021.21756.exe Code function: 4_2_018A2000 mov eax, dword ptr fs:[00000030h] 4_2_018A2000
Source: C:\Users\user\Desktop\SecuriteInfo.com.BackDoor.AgentTeslaNET.20.15021.21756.exe Code function: 4_2_018A2000 mov eax, dword ptr fs:[00000030h] 4_2_018A2000
Source: C:\Users\user\Desktop\SecuriteInfo.com.BackDoor.AgentTeslaNET.20.15021.21756.exe Code function: 4_2_018A2000 mov eax, dword ptr fs:[00000030h] 4_2_018A2000
Source: C:\Users\user\Desktop\SecuriteInfo.com.BackDoor.AgentTeslaNET.20.15021.21756.exe Code function: 4_2_018A2000 mov eax, dword ptr fs:[00000030h] 4_2_018A2000
Source: C:\Users\user\Desktop\SecuriteInfo.com.BackDoor.AgentTeslaNET.20.15021.21756.exe Code function: 4_2_018A2000 mov eax, dword ptr fs:[00000030h] 4_2_018A2000
Source: C:\Users\user\Desktop\SecuriteInfo.com.BackDoor.AgentTeslaNET.20.15021.21756.exe Code function: 4_2_017FC0F0 mov eax, dword ptr fs:[00000030h] 4_2_017FC0F0
Source: C:\Users\user\Desktop\SecuriteInfo.com.BackDoor.AgentTeslaNET.20.15021.21756.exe Code function: 4_2_0181E016 mov eax, dword ptr fs:[00000030h] 4_2_0181E016
Source: C:\Users\user\Desktop\SecuriteInfo.com.BackDoor.AgentTeslaNET.20.15021.21756.exe Code function: 4_2_0181E016 mov eax, dword ptr fs:[00000030h] 4_2_0181E016
Source: C:\Users\user\Desktop\SecuriteInfo.com.BackDoor.AgentTeslaNET.20.15021.21756.exe Code function: 4_2_0181E016 mov eax, dword ptr fs:[00000030h] 4_2_0181E016
Source: C:\Users\user\Desktop\SecuriteInfo.com.BackDoor.AgentTeslaNET.20.15021.21756.exe Code function: 4_2_0181E016 mov eax, dword ptr fs:[00000030h] 4_2_0181E016
Source: C:\Users\user\Desktop\SecuriteInfo.com.BackDoor.AgentTeslaNET.20.15021.21756.exe Code function: 4_2_017FA0E3 mov ecx, dword ptr fs:[00000030h] 4_2_017FA0E3
Source: C:\Users\user\Desktop\SecuriteInfo.com.BackDoor.AgentTeslaNET.20.15021.21756.exe Code function: 4_2_01896030 mov eax, dword ptr fs:[00000030h] 4_2_01896030
Source: C:\Users\user\Desktop\SecuriteInfo.com.BackDoor.AgentTeslaNET.20.15021.21756.exe Code function: 4_2_01802050 mov eax, dword ptr fs:[00000030h] 4_2_01802050
Source: C:\Users\user\Desktop\SecuriteInfo.com.BackDoor.AgentTeslaNET.20.15021.21756.exe Code function: 4_2_01886050 mov eax, dword ptr fs:[00000030h] 4_2_01886050
Source: C:\Users\user\Desktop\SecuriteInfo.com.BackDoor.AgentTeslaNET.20.15021.21756.exe Code function: 4_2_017F80A0 mov eax, dword ptr fs:[00000030h] 4_2_017F80A0
Source: C:\Users\user\Desktop\SecuriteInfo.com.BackDoor.AgentTeslaNET.20.15021.21756.exe Code function: 4_2_0182C073 mov eax, dword ptr fs:[00000030h] 4_2_0182C073
Source: C:\Users\user\Desktop\SecuriteInfo.com.BackDoor.AgentTeslaNET.20.15021.21756.exe Code function: 4_2_0182438F mov eax, dword ptr fs:[00000030h] 4_2_0182438F
Source: C:\Users\user\Desktop\SecuriteInfo.com.BackDoor.AgentTeslaNET.20.15021.21756.exe Code function: 4_2_0182438F mov eax, dword ptr fs:[00000030h] 4_2_0182438F
Source: C:\Users\user\Desktop\SecuriteInfo.com.BackDoor.AgentTeslaNET.20.15021.21756.exe Code function: 4_2_0180A3C0 mov eax, dword ptr fs:[00000030h] 4_2_0180A3C0
Source: C:\Users\user\Desktop\SecuriteInfo.com.BackDoor.AgentTeslaNET.20.15021.21756.exe Code function: 4_2_0180A3C0 mov eax, dword ptr fs:[00000030h] 4_2_0180A3C0
Source: C:\Users\user\Desktop\SecuriteInfo.com.BackDoor.AgentTeslaNET.20.15021.21756.exe Code function: 4_2_0180A3C0 mov eax, dword ptr fs:[00000030h] 4_2_0180A3C0
Source: C:\Users\user\Desktop\SecuriteInfo.com.BackDoor.AgentTeslaNET.20.15021.21756.exe Code function: 4_2_0180A3C0 mov eax, dword ptr fs:[00000030h] 4_2_0180A3C0
Source: C:\Users\user\Desktop\SecuriteInfo.com.BackDoor.AgentTeslaNET.20.15021.21756.exe Code function: 4_2_0180A3C0 mov eax, dword ptr fs:[00000030h] 4_2_0180A3C0
Source: C:\Users\user\Desktop\SecuriteInfo.com.BackDoor.AgentTeslaNET.20.15021.21756.exe Code function: 4_2_0180A3C0 mov eax, dword ptr fs:[00000030h] 4_2_0180A3C0
Source: C:\Users\user\Desktop\SecuriteInfo.com.BackDoor.AgentTeslaNET.20.15021.21756.exe Code function: 4_2_018083C0 mov eax, dword ptr fs:[00000030h] 4_2_018083C0
Source: C:\Users\user\Desktop\SecuriteInfo.com.BackDoor.AgentTeslaNET.20.15021.21756.exe Code function: 4_2_018083C0 mov eax, dword ptr fs:[00000030h] 4_2_018083C0
Source: C:\Users\user\Desktop\SecuriteInfo.com.BackDoor.AgentTeslaNET.20.15021.21756.exe Code function: 4_2_018083C0 mov eax, dword ptr fs:[00000030h] 4_2_018083C0
Source: C:\Users\user\Desktop\SecuriteInfo.com.BackDoor.AgentTeslaNET.20.15021.21756.exe Code function: 4_2_018083C0 mov eax, dword ptr fs:[00000030h] 4_2_018083C0
Source: C:\Users\user\Desktop\SecuriteInfo.com.BackDoor.AgentTeslaNET.20.15021.21756.exe Code function: 4_2_018BC3CD mov eax, dword ptr fs:[00000030h] 4_2_018BC3CD
Source: C:\Users\user\Desktop\SecuriteInfo.com.BackDoor.AgentTeslaNET.20.15021.21756.exe Code function: 4_2_018863C0 mov eax, dword ptr fs:[00000030h] 4_2_018863C0
Source: C:\Users\user\Desktop\SecuriteInfo.com.BackDoor.AgentTeslaNET.20.15021.21756.exe Code function: 4_2_018AE3DB mov eax, dword ptr fs:[00000030h] 4_2_018AE3DB
Source: C:\Users\user\Desktop\SecuriteInfo.com.BackDoor.AgentTeslaNET.20.15021.21756.exe Code function: 4_2_018AE3DB mov eax, dword ptr fs:[00000030h] 4_2_018AE3DB
Source: C:\Users\user\Desktop\SecuriteInfo.com.BackDoor.AgentTeslaNET.20.15021.21756.exe Code function: 4_2_018AE3DB mov ecx, dword ptr fs:[00000030h] 4_2_018AE3DB
Source: C:\Users\user\Desktop\SecuriteInfo.com.BackDoor.AgentTeslaNET.20.15021.21756.exe Code function: 4_2_018AE3DB mov eax, dword ptr fs:[00000030h] 4_2_018AE3DB
Source: C:\Users\user\Desktop\SecuriteInfo.com.BackDoor.AgentTeslaNET.20.15021.21756.exe Code function: 4_2_018A43D4 mov eax, dword ptr fs:[00000030h] 4_2_018A43D4
Source: C:\Users\user\Desktop\SecuriteInfo.com.BackDoor.AgentTeslaNET.20.15021.21756.exe Code function: 4_2_018A43D4 mov eax, dword ptr fs:[00000030h] 4_2_018A43D4
Source: C:\Users\user\Desktop\SecuriteInfo.com.BackDoor.AgentTeslaNET.20.15021.21756.exe Code function: 4_2_018103E9 mov eax, dword ptr fs:[00000030h] 4_2_018103E9
Source: C:\Users\user\Desktop\SecuriteInfo.com.BackDoor.AgentTeslaNET.20.15021.21756.exe Code function: 4_2_018103E9 mov eax, dword ptr fs:[00000030h] 4_2_018103E9
Source: C:\Users\user\Desktop\SecuriteInfo.com.BackDoor.AgentTeslaNET.20.15021.21756.exe Code function: 4_2_018103E9 mov eax, dword ptr fs:[00000030h] 4_2_018103E9
Source: C:\Users\user\Desktop\SecuriteInfo.com.BackDoor.AgentTeslaNET.20.15021.21756.exe Code function: 4_2_018103E9 mov eax, dword ptr fs:[00000030h] 4_2_018103E9
Source: C:\Users\user\Desktop\SecuriteInfo.com.BackDoor.AgentTeslaNET.20.15021.21756.exe Code function: 4_2_018103E9 mov eax, dword ptr fs:[00000030h] 4_2_018103E9
Source: C:\Users\user\Desktop\SecuriteInfo.com.BackDoor.AgentTeslaNET.20.15021.21756.exe Code function: 4_2_018103E9 mov eax, dword ptr fs:[00000030h] 4_2_018103E9
Source: C:\Users\user\Desktop\SecuriteInfo.com.BackDoor.AgentTeslaNET.20.15021.21756.exe Code function: 4_2_018103E9 mov eax, dword ptr fs:[00000030h] 4_2_018103E9
Source: C:\Users\user\Desktop\SecuriteInfo.com.BackDoor.AgentTeslaNET.20.15021.21756.exe Code function: 4_2_018103E9 mov eax, dword ptr fs:[00000030h] 4_2_018103E9
Source: C:\Users\user\Desktop\SecuriteInfo.com.BackDoor.AgentTeslaNET.20.15021.21756.exe Code function: 4_2_017FC310 mov ecx, dword ptr fs:[00000030h] 4_2_017FC310
Source: C:\Users\user\Desktop\SecuriteInfo.com.BackDoor.AgentTeslaNET.20.15021.21756.exe Code function: 4_2_0181E3F0 mov eax, dword ptr fs:[00000030h] 4_2_0181E3F0
Source: C:\Users\user\Desktop\SecuriteInfo.com.BackDoor.AgentTeslaNET.20.15021.21756.exe Code function: 4_2_0181E3F0 mov eax, dword ptr fs:[00000030h] 4_2_0181E3F0
Source: C:\Users\user\Desktop\SecuriteInfo.com.BackDoor.AgentTeslaNET.20.15021.21756.exe Code function: 4_2_0181E3F0 mov eax, dword ptr fs:[00000030h] 4_2_0181E3F0
Source: C:\Users\user\Desktop\SecuriteInfo.com.BackDoor.AgentTeslaNET.20.15021.21756.exe Code function: 4_2_018363FF mov eax, dword ptr fs:[00000030h] 4_2_018363FF
Source: C:\Users\user\Desktop\SecuriteInfo.com.BackDoor.AgentTeslaNET.20.15021.21756.exe Code function: 4_2_0183A30B mov eax, dword ptr fs:[00000030h] 4_2_0183A30B
Source: C:\Users\user\Desktop\SecuriteInfo.com.BackDoor.AgentTeslaNET.20.15021.21756.exe Code function: 4_2_0183A30B mov eax, dword ptr fs:[00000030h] 4_2_0183A30B
Source: C:\Users\user\Desktop\SecuriteInfo.com.BackDoor.AgentTeslaNET.20.15021.21756.exe Code function: 4_2_0183A30B mov eax, dword ptr fs:[00000030h] 4_2_0183A30B
Source: C:\Users\user\Desktop\SecuriteInfo.com.BackDoor.AgentTeslaNET.20.15021.21756.exe Code function: 4_2_01820310 mov ecx, dword ptr fs:[00000030h] 4_2_01820310
Source: C:\Users\user\Desktop\SecuriteInfo.com.BackDoor.AgentTeslaNET.20.15021.21756.exe Code function: 4_2_018D8324 mov eax, dword ptr fs:[00000030h] 4_2_018D8324
Source: C:\Users\user\Desktop\SecuriteInfo.com.BackDoor.AgentTeslaNET.20.15021.21756.exe Code function: 4_2_018D8324 mov ecx, dword ptr fs:[00000030h] 4_2_018D8324
Source: C:\Users\user\Desktop\SecuriteInfo.com.BackDoor.AgentTeslaNET.20.15021.21756.exe Code function: 4_2_018D8324 mov eax, dword ptr fs:[00000030h] 4_2_018D8324
Source: C:\Users\user\Desktop\SecuriteInfo.com.BackDoor.AgentTeslaNET.20.15021.21756.exe Code function: 4_2_018D8324 mov eax, dword ptr fs:[00000030h] 4_2_018D8324
Source: C:\Users\user\Desktop\SecuriteInfo.com.BackDoor.AgentTeslaNET.20.15021.21756.exe Code function: 4_2_01882349 mov eax, dword ptr fs:[00000030h] 4_2_01882349
Source: C:\Users\user\Desktop\SecuriteInfo.com.BackDoor.AgentTeslaNET.20.15021.21756.exe Code function: 4_2_01882349 mov eax, dword ptr fs:[00000030h] 4_2_01882349
Source: C:\Users\user\Desktop\SecuriteInfo.com.BackDoor.AgentTeslaNET.20.15021.21756.exe Code function: 4_2_01882349 mov eax, dword ptr fs:[00000030h] 4_2_01882349
Source: C:\Users\user\Desktop\SecuriteInfo.com.BackDoor.AgentTeslaNET.20.15021.21756.exe Code function: 4_2_01882349 mov eax, dword ptr fs:[00000030h] 4_2_01882349
Source: C:\Users\user\Desktop\SecuriteInfo.com.BackDoor.AgentTeslaNET.20.15021.21756.exe Code function: 4_2_01882349 mov eax, dword ptr fs:[00000030h] 4_2_01882349
Source: C:\Users\user\Desktop\SecuriteInfo.com.BackDoor.AgentTeslaNET.20.15021.21756.exe Code function: 4_2_01882349 mov eax, dword ptr fs:[00000030h] 4_2_01882349
Source: C:\Users\user\Desktop\SecuriteInfo.com.BackDoor.AgentTeslaNET.20.15021.21756.exe Code function: 4_2_01882349 mov eax, dword ptr fs:[00000030h] 4_2_01882349
Source: C:\Users\user\Desktop\SecuriteInfo.com.BackDoor.AgentTeslaNET.20.15021.21756.exe Code function: 4_2_01882349 mov eax, dword ptr fs:[00000030h] 4_2_01882349
Source: C:\Users\user\Desktop\SecuriteInfo.com.BackDoor.AgentTeslaNET.20.15021.21756.exe Code function: 4_2_01882349 mov eax, dword ptr fs:[00000030h] 4_2_01882349
Source: C:\Users\user\Desktop\SecuriteInfo.com.BackDoor.AgentTeslaNET.20.15021.21756.exe Code function: 4_2_01882349 mov eax, dword ptr fs:[00000030h] 4_2_01882349
Source: C:\Users\user\Desktop\SecuriteInfo.com.BackDoor.AgentTeslaNET.20.15021.21756.exe Code function: 4_2_01882349 mov eax, dword ptr fs:[00000030h] 4_2_01882349
Source: C:\Users\user\Desktop\SecuriteInfo.com.BackDoor.AgentTeslaNET.20.15021.21756.exe Code function: 4_2_01882349 mov eax, dword ptr fs:[00000030h] 4_2_01882349
Source: C:\Users\user\Desktop\SecuriteInfo.com.BackDoor.AgentTeslaNET.20.15021.21756.exe Code function: 4_2_01882349 mov eax, dword ptr fs:[00000030h] 4_2_01882349
Source: C:\Users\user\Desktop\SecuriteInfo.com.BackDoor.AgentTeslaNET.20.15021.21756.exe Code function: 4_2_01882349 mov eax, dword ptr fs:[00000030h] 4_2_01882349
Source: C:\Users\user\Desktop\SecuriteInfo.com.BackDoor.AgentTeslaNET.20.15021.21756.exe Code function: 4_2_01882349 mov eax, dword ptr fs:[00000030h] 4_2_01882349
Source: C:\Users\user\Desktop\SecuriteInfo.com.BackDoor.AgentTeslaNET.20.15021.21756.exe Code function: 4_2_018D634F mov eax, dword ptr fs:[00000030h] 4_2_018D634F
Source: C:\Users\user\Desktop\SecuriteInfo.com.BackDoor.AgentTeslaNET.20.15021.21756.exe Code function: 4_2_0188035C mov eax, dword ptr fs:[00000030h] 4_2_0188035C
Source: C:\Users\user\Desktop\SecuriteInfo.com.BackDoor.AgentTeslaNET.20.15021.21756.exe Code function: 4_2_0188035C mov eax, dword ptr fs:[00000030h] 4_2_0188035C
Source: C:\Users\user\Desktop\SecuriteInfo.com.BackDoor.AgentTeslaNET.20.15021.21756.exe Code function: 4_2_0188035C mov eax, dword ptr fs:[00000030h] 4_2_0188035C
Source: C:\Users\user\Desktop\SecuriteInfo.com.BackDoor.AgentTeslaNET.20.15021.21756.exe Code function: 4_2_0188035C mov ecx, dword ptr fs:[00000030h] 4_2_0188035C
Source: C:\Users\user\Desktop\SecuriteInfo.com.BackDoor.AgentTeslaNET.20.15021.21756.exe Code function: 4_2_0188035C mov eax, dword ptr fs:[00000030h] 4_2_0188035C
Source: C:\Users\user\Desktop\SecuriteInfo.com.BackDoor.AgentTeslaNET.20.15021.21756.exe Code function: 4_2_0188035C mov eax, dword ptr fs:[00000030h] 4_2_0188035C
Source: C:\Users\user\Desktop\SecuriteInfo.com.BackDoor.AgentTeslaNET.20.15021.21756.exe Code function: 4_2_018A8350 mov ecx, dword ptr fs:[00000030h] 4_2_018A8350
Source: C:\Users\user\Desktop\SecuriteInfo.com.BackDoor.AgentTeslaNET.20.15021.21756.exe Code function: 4_2_018CA352 mov eax, dword ptr fs:[00000030h] 4_2_018CA352
Source: C:\Users\user\Desktop\SecuriteInfo.com.BackDoor.AgentTeslaNET.20.15021.21756.exe Code function: 4_2_017F8397 mov eax, dword ptr fs:[00000030h] 4_2_017F8397
Source: C:\Users\user\Desktop\SecuriteInfo.com.BackDoor.AgentTeslaNET.20.15021.21756.exe Code function: 4_2_017F8397 mov eax, dword ptr fs:[00000030h] 4_2_017F8397
Source: C:\Users\user\Desktop\SecuriteInfo.com.BackDoor.AgentTeslaNET.20.15021.21756.exe Code function: 4_2_017F8397 mov eax, dword ptr fs:[00000030h] 4_2_017F8397
Source: C:\Users\user\Desktop\SecuriteInfo.com.BackDoor.AgentTeslaNET.20.15021.21756.exe Code function: 4_2_018A437C mov eax, dword ptr fs:[00000030h] 4_2_018A437C
Source: C:\Users\user\Desktop\SecuriteInfo.com.BackDoor.AgentTeslaNET.20.15021.21756.exe Code function: 4_2_017FE388 mov eax, dword ptr fs:[00000030h] 4_2_017FE388
Source: C:\Users\user\Desktop\SecuriteInfo.com.BackDoor.AgentTeslaNET.20.15021.21756.exe Code function: 4_2_017FE388 mov eax, dword ptr fs:[00000030h] 4_2_017FE388
Source: C:\Users\user\Desktop\SecuriteInfo.com.BackDoor.AgentTeslaNET.20.15021.21756.exe Code function: 4_2_017FE388 mov eax, dword ptr fs:[00000030h] 4_2_017FE388
Source: C:\Users\user\Desktop\SecuriteInfo.com.BackDoor.AgentTeslaNET.20.15021.21756.exe Code function: 4_2_0183E284 mov eax, dword ptr fs:[00000030h] 4_2_0183E284
Source: C:\Users\user\Desktop\SecuriteInfo.com.BackDoor.AgentTeslaNET.20.15021.21756.exe Code function: 4_2_0183E284 mov eax, dword ptr fs:[00000030h] 4_2_0183E284
Source: C:\Users\user\Desktop\SecuriteInfo.com.BackDoor.AgentTeslaNET.20.15021.21756.exe Code function: 4_2_01880283 mov eax, dword ptr fs:[00000030h] 4_2_01880283
Source: C:\Users\user\Desktop\SecuriteInfo.com.BackDoor.AgentTeslaNET.20.15021.21756.exe Code function: 4_2_01880283 mov eax, dword ptr fs:[00000030h] 4_2_01880283
Source: C:\Users\user\Desktop\SecuriteInfo.com.BackDoor.AgentTeslaNET.20.15021.21756.exe Code function: 4_2_01880283 mov eax, dword ptr fs:[00000030h] 4_2_01880283
Source: C:\Users\user\Desktop\SecuriteInfo.com.BackDoor.AgentTeslaNET.20.15021.21756.exe Code function: 4_2_017F826B mov eax, dword ptr fs:[00000030h] 4_2_017F826B
Source: C:\Users\user\Desktop\SecuriteInfo.com.BackDoor.AgentTeslaNET.20.15021.21756.exe Code function: 4_2_018102A0 mov eax, dword ptr fs:[00000030h] 4_2_018102A0
Source: C:\Users\user\Desktop\SecuriteInfo.com.BackDoor.AgentTeslaNET.20.15021.21756.exe Code function: 4_2_018102A0 mov eax, dword ptr fs:[00000030h] 4_2_018102A0
Source: C:\Users\user\Desktop\SecuriteInfo.com.BackDoor.AgentTeslaNET.20.15021.21756.exe Code function: 4_2_018962A0 mov eax, dword ptr fs:[00000030h] 4_2_018962A0
Source: C:\Users\user\Desktop\SecuriteInfo.com.BackDoor.AgentTeslaNET.20.15021.21756.exe Code function: 4_2_018962A0 mov ecx, dword ptr fs:[00000030h] 4_2_018962A0
Source: C:\Users\user\Desktop\SecuriteInfo.com.BackDoor.AgentTeslaNET.20.15021.21756.exe Code function: 4_2_018962A0 mov eax, dword ptr fs:[00000030h] 4_2_018962A0
Source: C:\Users\user\Desktop\SecuriteInfo.com.BackDoor.AgentTeslaNET.20.15021.21756.exe Code function: 4_2_018962A0 mov eax, dword ptr fs:[00000030h] 4_2_018962A0
Source: C:\Users\user\Desktop\SecuriteInfo.com.BackDoor.AgentTeslaNET.20.15021.21756.exe Code function: 4_2_018962A0 mov eax, dword ptr fs:[00000030h] 4_2_018962A0
Source: C:\Users\user\Desktop\SecuriteInfo.com.BackDoor.AgentTeslaNET.20.15021.21756.exe Code function: 4_2_018962A0 mov eax, dword ptr fs:[00000030h] 4_2_018962A0
Source: C:\Users\user\Desktop\SecuriteInfo.com.BackDoor.AgentTeslaNET.20.15021.21756.exe Code function: 4_2_017FA250 mov eax, dword ptr fs:[00000030h] 4_2_017FA250
Source: C:\Users\user\Desktop\SecuriteInfo.com.BackDoor.AgentTeslaNET.20.15021.21756.exe Code function: 4_2_0180A2C3 mov eax, dword ptr fs:[00000030h] 4_2_0180A2C3
Source: C:\Users\user\Desktop\SecuriteInfo.com.BackDoor.AgentTeslaNET.20.15021.21756.exe Code function: 4_2_0180A2C3 mov eax, dword ptr fs:[00000030h] 4_2_0180A2C3
Source: C:\Users\user\Desktop\SecuriteInfo.com.BackDoor.AgentTeslaNET.20.15021.21756.exe Code function: 4_2_0180A2C3 mov eax, dword ptr fs:[00000030h] 4_2_0180A2C3
Source: C:\Users\user\Desktop\SecuriteInfo.com.BackDoor.AgentTeslaNET.20.15021.21756.exe Code function: 4_2_0180A2C3 mov eax, dword ptr fs:[00000030h] 4_2_0180A2C3
Source: C:\Users\user\Desktop\SecuriteInfo.com.BackDoor.AgentTeslaNET.20.15021.21756.exe Code function: 4_2_0180A2C3 mov eax, dword ptr fs:[00000030h] 4_2_0180A2C3
Source: C:\Users\user\Desktop\SecuriteInfo.com.BackDoor.AgentTeslaNET.20.15021.21756.exe Code function: 4_2_017F823B mov eax, dword ptr fs:[00000030h] 4_2_017F823B
Source: C:\Users\user\Desktop\SecuriteInfo.com.BackDoor.AgentTeslaNET.20.15021.21756.exe Code function: 4_2_018D62D6 mov eax, dword ptr fs:[00000030h] 4_2_018D62D6
Source: C:\Users\user\Desktop\SecuriteInfo.com.BackDoor.AgentTeslaNET.20.15021.21756.exe Code function: 4_2_018102E1 mov eax, dword ptr fs:[00000030h] 4_2_018102E1
Source: C:\Users\user\Desktop\SecuriteInfo.com.BackDoor.AgentTeslaNET.20.15021.21756.exe Code function: 4_2_018102E1 mov eax, dword ptr fs:[00000030h] 4_2_018102E1
Source: C:\Users\user\Desktop\SecuriteInfo.com.BackDoor.AgentTeslaNET.20.15021.21756.exe Code function: 4_2_018102E1 mov eax, dword ptr fs:[00000030h] 4_2_018102E1
Source: C:\Users\user\Desktop\SecuriteInfo.com.BackDoor.AgentTeslaNET.20.15021.21756.exe Code function: 4_2_01888243 mov eax, dword ptr fs:[00000030h] 4_2_01888243
Source: C:\Users\user\Desktop\SecuriteInfo.com.BackDoor.AgentTeslaNET.20.15021.21756.exe Code function: 4_2_01888243 mov ecx, dword ptr fs:[00000030h] 4_2_01888243
Source: C:\Users\user\Desktop\SecuriteInfo.com.BackDoor.AgentTeslaNET.20.15021.21756.exe Code function: 4_2_018D625D mov eax, dword ptr fs:[00000030h] 4_2_018D625D
Source: C:\Users\user\Desktop\SecuriteInfo.com.BackDoor.AgentTeslaNET.20.15021.21756.exe Code function: 4_2_01806259 mov eax, dword ptr fs:[00000030h] 4_2_01806259
Source: C:\Users\user\Desktop\SecuriteInfo.com.BackDoor.AgentTeslaNET.20.15021.21756.exe Code function: 4_2_018BA250 mov eax, dword ptr fs:[00000030h] 4_2_018BA250
Source: C:\Users\user\Desktop\SecuriteInfo.com.BackDoor.AgentTeslaNET.20.15021.21756.exe Code function: 4_2_018BA250 mov eax, dword ptr fs:[00000030h] 4_2_018BA250
Source: C:\Users\user\Desktop\SecuriteInfo.com.BackDoor.AgentTeslaNET.20.15021.21756.exe Code function: 4_2_01804260 mov eax, dword ptr fs:[00000030h] 4_2_01804260
Source: C:\Users\user\Desktop\SecuriteInfo.com.BackDoor.AgentTeslaNET.20.15021.21756.exe Code function: 4_2_01804260 mov eax, dword ptr fs:[00000030h] 4_2_01804260
Source: C:\Users\user\Desktop\SecuriteInfo.com.BackDoor.AgentTeslaNET.20.15021.21756.exe Code function: 4_2_01804260 mov eax, dword ptr fs:[00000030h] 4_2_01804260
Source: C:\Users\user\Desktop\SecuriteInfo.com.BackDoor.AgentTeslaNET.20.15021.21756.exe Code function: 4_2_018B0274 mov eax, dword ptr fs:[00000030h] 4_2_018B0274
Source: C:\Users\user\Desktop\SecuriteInfo.com.BackDoor.AgentTeslaNET.20.15021.21756.exe Code function: 4_2_018B0274 mov eax, dword ptr fs:[00000030h] 4_2_018B0274
Source: C:\Users\user\Desktop\SecuriteInfo.com.BackDoor.AgentTeslaNET.20.15021.21756.exe Code function: 4_2_018B0274 mov eax, dword ptr fs:[00000030h] 4_2_018B0274
Source: C:\Users\user\Desktop\SecuriteInfo.com.BackDoor.AgentTeslaNET.20.15021.21756.exe Code function: 4_2_018B0274 mov eax, dword ptr fs:[00000030h] 4_2_018B0274
Source: C:\Users\user\Desktop\SecuriteInfo.com.BackDoor.AgentTeslaNET.20.15021.21756.exe Code function: 4_2_018B0274 mov eax, dword ptr fs:[00000030h] 4_2_018B0274
Source: C:\Users\user\Desktop\SecuriteInfo.com.BackDoor.AgentTeslaNET.20.15021.21756.exe Code function: 4_2_018B0274 mov eax, dword ptr fs:[00000030h] 4_2_018B0274
Source: C:\Users\user\Desktop\SecuriteInfo.com.BackDoor.AgentTeslaNET.20.15021.21756.exe Code function: 4_2_018B0274 mov eax, dword ptr fs:[00000030h] 4_2_018B0274
Source: C:\Users\user\Desktop\SecuriteInfo.com.BackDoor.AgentTeslaNET.20.15021.21756.exe Code function: 4_2_018B0274 mov eax, dword ptr fs:[00000030h] 4_2_018B0274
Source: C:\Users\user\Desktop\SecuriteInfo.com.BackDoor.AgentTeslaNET.20.15021.21756.exe Code function: 4_2_018B0274 mov eax, dword ptr fs:[00000030h] 4_2_018B0274
Source: C:\Users\user\Desktop\SecuriteInfo.com.BackDoor.AgentTeslaNET.20.15021.21756.exe Code function: 4_2_018B0274 mov eax, dword ptr fs:[00000030h] 4_2_018B0274
Source: C:\Users\user\Desktop\SecuriteInfo.com.BackDoor.AgentTeslaNET.20.15021.21756.exe Code function: 4_2_018B0274 mov eax, dword ptr fs:[00000030h] 4_2_018B0274
Source: C:\Users\user\Desktop\SecuriteInfo.com.BackDoor.AgentTeslaNET.20.15021.21756.exe Code function: 4_2_018B0274 mov eax, dword ptr fs:[00000030h] 4_2_018B0274
Source: C:\Users\user\Desktop\SecuriteInfo.com.BackDoor.AgentTeslaNET.20.15021.21756.exe Code function: 4_2_01802582 mov eax, dword ptr fs:[00000030h] 4_2_01802582
Source: C:\Users\user\Desktop\SecuriteInfo.com.BackDoor.AgentTeslaNET.20.15021.21756.exe Code function: 4_2_01802582 mov ecx, dword ptr fs:[00000030h] 4_2_01802582
Source: C:\Users\user\Desktop\SecuriteInfo.com.BackDoor.AgentTeslaNET.20.15021.21756.exe Code function: 4_2_01834588 mov eax, dword ptr fs:[00000030h] 4_2_01834588
Source: C:\Users\user\Desktop\SecuriteInfo.com.BackDoor.AgentTeslaNET.20.15021.21756.exe Code function: 4_2_0183E59C mov eax, dword ptr fs:[00000030h] 4_2_0183E59C
Source: C:\Users\user\Desktop\SecuriteInfo.com.BackDoor.AgentTeslaNET.20.15021.21756.exe Code function: 4_2_018805A7 mov eax, dword ptr fs:[00000030h] 4_2_018805A7
Source: C:\Users\user\Desktop\SecuriteInfo.com.BackDoor.AgentTeslaNET.20.15021.21756.exe Code function: 4_2_018805A7 mov eax, dword ptr fs:[00000030h] 4_2_018805A7
Source: C:\Users\user\Desktop\SecuriteInfo.com.BackDoor.AgentTeslaNET.20.15021.21756.exe Code function: 4_2_018805A7 mov eax, dword ptr fs:[00000030h] 4_2_018805A7
Source: C:\Users\user\Desktop\SecuriteInfo.com.BackDoor.AgentTeslaNET.20.15021.21756.exe Code function: 4_2_018245B1 mov eax, dword ptr fs:[00000030h] 4_2_018245B1
Source: C:\Users\user\Desktop\SecuriteInfo.com.BackDoor.AgentTeslaNET.20.15021.21756.exe Code function: 4_2_018245B1 mov eax, dword ptr fs:[00000030h] 4_2_018245B1
Source: C:\Users\user\Desktop\SecuriteInfo.com.BackDoor.AgentTeslaNET.20.15021.21756.exe Code function: 4_2_0183E5CF mov eax, dword ptr fs:[00000030h] 4_2_0183E5CF
Source: C:\Users\user\Desktop\SecuriteInfo.com.BackDoor.AgentTeslaNET.20.15021.21756.exe Code function: 4_2_0183E5CF mov eax, dword ptr fs:[00000030h] 4_2_0183E5CF
Source: C:\Users\user\Desktop\SecuriteInfo.com.BackDoor.AgentTeslaNET.20.15021.21756.exe Code function: 4_2_018065D0 mov eax, dword ptr fs:[00000030h] 4_2_018065D0
Source: C:\Users\user\Desktop\SecuriteInfo.com.BackDoor.AgentTeslaNET.20.15021.21756.exe Code function: 4_2_0183A5D0 mov eax, dword ptr fs:[00000030h] 4_2_0183A5D0
Source: C:\Users\user\Desktop\SecuriteInfo.com.BackDoor.AgentTeslaNET.20.15021.21756.exe Code function: 4_2_0183A5D0 mov eax, dword ptr fs:[00000030h] 4_2_0183A5D0
Source: C:\Users\user\Desktop\SecuriteInfo.com.BackDoor.AgentTeslaNET.20.15021.21756.exe Code function: 4_2_018025E0 mov eax, dword ptr fs:[00000030h] 4_2_018025E0
Source: C:\Users\user\Desktop\SecuriteInfo.com.BackDoor.AgentTeslaNET.20.15021.21756.exe Code function: 4_2_0182E5E7 mov eax, dword ptr fs:[00000030h] 4_2_0182E5E7
Source: C:\Users\user\Desktop\SecuriteInfo.com.BackDoor.AgentTeslaNET.20.15021.21756.exe Code function: 4_2_0182E5E7 mov eax, dword ptr fs:[00000030h] 4_2_0182E5E7
Source: C:\Users\user\Desktop\SecuriteInfo.com.BackDoor.AgentTeslaNET.20.15021.21756.exe Code function: 4_2_0182E5E7 mov eax, dword ptr fs:[00000030h] 4_2_0182E5E7
Source: C:\Users\user\Desktop\SecuriteInfo.com.BackDoor.AgentTeslaNET.20.15021.21756.exe Code function: 4_2_0182E5E7 mov eax, dword ptr fs:[00000030h] 4_2_0182E5E7
Source: C:\Users\user\Desktop\SecuriteInfo.com.BackDoor.AgentTeslaNET.20.15021.21756.exe Code function: 4_2_0182E5E7 mov eax, dword ptr fs:[00000030h] 4_2_0182E5E7
Source: C:\Users\user\Desktop\SecuriteInfo.com.BackDoor.AgentTeslaNET.20.15021.21756.exe Code function: 4_2_0182E5E7 mov eax, dword ptr fs:[00000030h] 4_2_0182E5E7
Source: C:\Users\user\Desktop\SecuriteInfo.com.BackDoor.AgentTeslaNET.20.15021.21756.exe Code function: 4_2_0182E5E7 mov eax, dword ptr fs:[00000030h] 4_2_0182E5E7
Source: C:\Users\user\Desktop\SecuriteInfo.com.BackDoor.AgentTeslaNET.20.15021.21756.exe Code function: 4_2_0182E5E7 mov eax, dword ptr fs:[00000030h] 4_2_0182E5E7
Source: C:\Users\user\Desktop\SecuriteInfo.com.BackDoor.AgentTeslaNET.20.15021.21756.exe Code function: 4_2_0183C5ED mov eax, dword ptr fs:[00000030h] 4_2_0183C5ED
Source: C:\Users\user\Desktop\SecuriteInfo.com.BackDoor.AgentTeslaNET.20.15021.21756.exe Code function: 4_2_0183C5ED mov eax, dword ptr fs:[00000030h] 4_2_0183C5ED
Source: C:\Users\user\Desktop\SecuriteInfo.com.BackDoor.AgentTeslaNET.20.15021.21756.exe Code function: 4_2_01896500 mov eax, dword ptr fs:[00000030h] 4_2_01896500
Source: C:\Users\user\Desktop\SecuriteInfo.com.BackDoor.AgentTeslaNET.20.15021.21756.exe Code function: 4_2_018D4500 mov eax, dword ptr fs:[00000030h] 4_2_018D4500
Source: C:\Users\user\Desktop\SecuriteInfo.com.BackDoor.AgentTeslaNET.20.15021.21756.exe Code function: 4_2_018D4500 mov eax, dword ptr fs:[00000030h] 4_2_018D4500
Source: C:\Users\user\Desktop\SecuriteInfo.com.BackDoor.AgentTeslaNET.20.15021.21756.exe Code function: 4_2_018D4500 mov eax, dword ptr fs:[00000030h] 4_2_018D4500
Source: C:\Users\user\Desktop\SecuriteInfo.com.BackDoor.AgentTeslaNET.20.15021.21756.exe Code function: 4_2_018D4500 mov eax, dword ptr fs:[00000030h] 4_2_018D4500
Source: C:\Users\user\Desktop\SecuriteInfo.com.BackDoor.AgentTeslaNET.20.15021.21756.exe Code function: 4_2_018D4500 mov eax, dword ptr fs:[00000030h] 4_2_018D4500
Source: C:\Users\user\Desktop\SecuriteInfo.com.BackDoor.AgentTeslaNET.20.15021.21756.exe Code function: 4_2_018D4500 mov eax, dword ptr fs:[00000030h] 4_2_018D4500
Source: C:\Users\user\Desktop\SecuriteInfo.com.BackDoor.AgentTeslaNET.20.15021.21756.exe Code function: 4_2_018D4500 mov eax, dword ptr fs:[00000030h] 4_2_018D4500
Source: C:\Users\user\Desktop\SecuriteInfo.com.BackDoor.AgentTeslaNET.20.15021.21756.exe Code function: 4_2_01810535 mov eax, dword ptr fs:[00000030h] 4_2_01810535
Source: C:\Users\user\Desktop\SecuriteInfo.com.BackDoor.AgentTeslaNET.20.15021.21756.exe Code function: 4_2_01810535 mov eax, dword ptr fs:[00000030h] 4_2_01810535
Source: C:\Users\user\Desktop\SecuriteInfo.com.BackDoor.AgentTeslaNET.20.15021.21756.exe Code function: 4_2_01810535 mov eax, dword ptr fs:[00000030h] 4_2_01810535
Source: C:\Users\user\Desktop\SecuriteInfo.com.BackDoor.AgentTeslaNET.20.15021.21756.exe Code function: 4_2_01810535 mov eax, dword ptr fs:[00000030h] 4_2_01810535
Source: C:\Users\user\Desktop\SecuriteInfo.com.BackDoor.AgentTeslaNET.20.15021.21756.exe Code function: 4_2_01810535 mov eax, dword ptr fs:[00000030h] 4_2_01810535
Source: C:\Users\user\Desktop\SecuriteInfo.com.BackDoor.AgentTeslaNET.20.15021.21756.exe Code function: 4_2_01810535 mov eax, dword ptr fs:[00000030h] 4_2_01810535
Source: C:\Users\user\Desktop\SecuriteInfo.com.BackDoor.AgentTeslaNET.20.15021.21756.exe Code function: 4_2_0182E53E mov eax, dword ptr fs:[00000030h] 4_2_0182E53E
Source: C:\Users\user\Desktop\SecuriteInfo.com.BackDoor.AgentTeslaNET.20.15021.21756.exe Code function: 4_2_0182E53E mov eax, dword ptr fs:[00000030h] 4_2_0182E53E
Source: C:\Users\user\Desktop\SecuriteInfo.com.BackDoor.AgentTeslaNET.20.15021.21756.exe Code function: 4_2_0182E53E mov eax, dword ptr fs:[00000030h] 4_2_0182E53E
Source: C:\Users\user\Desktop\SecuriteInfo.com.BackDoor.AgentTeslaNET.20.15021.21756.exe Code function: 4_2_0182E53E mov eax, dword ptr fs:[00000030h] 4_2_0182E53E
Source: C:\Users\user\Desktop\SecuriteInfo.com.BackDoor.AgentTeslaNET.20.15021.21756.exe Code function: 4_2_0182E53E mov eax, dword ptr fs:[00000030h] 4_2_0182E53E
Source: C:\Users\user\Desktop\SecuriteInfo.com.BackDoor.AgentTeslaNET.20.15021.21756.exe Code function: 4_2_01808550 mov eax, dword ptr fs:[00000030h] 4_2_01808550
Source: C:\Users\user\Desktop\SecuriteInfo.com.BackDoor.AgentTeslaNET.20.15021.21756.exe Code function: 4_2_01808550 mov eax, dword ptr fs:[00000030h] 4_2_01808550
Source: C:\Users\user\Desktop\SecuriteInfo.com.BackDoor.AgentTeslaNET.20.15021.21756.exe Code function: 4_2_0183656A mov eax, dword ptr fs:[00000030h] 4_2_0183656A
Source: C:\Users\user\Desktop\SecuriteInfo.com.BackDoor.AgentTeslaNET.20.15021.21756.exe Code function: 4_2_0183656A mov eax, dword ptr fs:[00000030h] 4_2_0183656A
Source: C:\Users\user\Desktop\SecuriteInfo.com.BackDoor.AgentTeslaNET.20.15021.21756.exe Code function: 4_2_0183656A mov eax, dword ptr fs:[00000030h] 4_2_0183656A
Source: C:\Users\user\Desktop\SecuriteInfo.com.BackDoor.AgentTeslaNET.20.15021.21756.exe Code function: 4_2_018BA49A mov eax, dword ptr fs:[00000030h] 4_2_018BA49A
Source: C:\Users\user\Desktop\SecuriteInfo.com.BackDoor.AgentTeslaNET.20.15021.21756.exe Code function: 4_2_017F645D mov eax, dword ptr fs:[00000030h] 4_2_017F645D
Source: C:\Users\user\Desktop\SecuriteInfo.com.BackDoor.AgentTeslaNET.20.15021.21756.exe Code function: 4_2_018064AB mov eax, dword ptr fs:[00000030h] 4_2_018064AB
Source: C:\Users\user\Desktop\SecuriteInfo.com.BackDoor.AgentTeslaNET.20.15021.21756.exe Code function: 4_2_018344B0 mov ecx, dword ptr fs:[00000030h] 4_2_018344B0
Source: C:\Users\user\Desktop\SecuriteInfo.com.BackDoor.AgentTeslaNET.20.15021.21756.exe Code function: 4_2_0188A4B0 mov eax, dword ptr fs:[00000030h] 4_2_0188A4B0
Source: C:\Users\user\Desktop\SecuriteInfo.com.BackDoor.AgentTeslaNET.20.15021.21756.exe Code function: 4_2_017FC427 mov eax, dword ptr fs:[00000030h] 4_2_017FC427
Source: C:\Users\user\Desktop\SecuriteInfo.com.BackDoor.AgentTeslaNET.20.15021.21756.exe Code function: 4_2_017FE420 mov eax, dword ptr fs:[00000030h] 4_2_017FE420
Source: C:\Users\user\Desktop\SecuriteInfo.com.BackDoor.AgentTeslaNET.20.15021.21756.exe Code function: 4_2_017FE420 mov eax, dword ptr fs:[00000030h] 4_2_017FE420
Source: C:\Users\user\Desktop\SecuriteInfo.com.BackDoor.AgentTeslaNET.20.15021.21756.exe Code function: 4_2_017FE420 mov eax, dword ptr fs:[00000030h] 4_2_017FE420
Source: C:\Users\user\Desktop\SecuriteInfo.com.BackDoor.AgentTeslaNET.20.15021.21756.exe Code function: 4_2_018004E5 mov ecx, dword ptr fs:[00000030h] 4_2_018004E5
Source: C:\Users\user\Desktop\SecuriteInfo.com.BackDoor.AgentTeslaNET.20.15021.21756.exe Code function: 4_2_01838402 mov eax, dword ptr fs:[00000030h] 4_2_01838402
Source: C:\Users\user\Desktop\SecuriteInfo.com.BackDoor.AgentTeslaNET.20.15021.21756.exe Code function: 4_2_01838402 mov eax, dword ptr fs:[00000030h] 4_2_01838402
Source: C:\Users\user\Desktop\SecuriteInfo.com.BackDoor.AgentTeslaNET.20.15021.21756.exe Code function: 4_2_01838402 mov eax, dword ptr fs:[00000030h] 4_2_01838402
Source: C:\Users\user\Desktop\SecuriteInfo.com.BackDoor.AgentTeslaNET.20.15021.21756.exe Code function: 4_2_01886420 mov eax, dword ptr fs:[00000030h] 4_2_01886420
Source: C:\Users\user\Desktop\SecuriteInfo.com.BackDoor.AgentTeslaNET.20.15021.21756.exe Code function: 4_2_01886420 mov eax, dword ptr fs:[00000030h] 4_2_01886420
Source: C:\Users\user\Desktop\SecuriteInfo.com.BackDoor.AgentTeslaNET.20.15021.21756.exe Code function: 4_2_01886420 mov eax, dword ptr fs:[00000030h] 4_2_01886420
Source: C:\Users\user\Desktop\SecuriteInfo.com.BackDoor.AgentTeslaNET.20.15021.21756.exe Code function: 4_2_01886420 mov eax, dword ptr fs:[00000030h] 4_2_01886420
Source: C:\Users\user\Desktop\SecuriteInfo.com.BackDoor.AgentTeslaNET.20.15021.21756.exe Code function: 4_2_01886420 mov eax, dword ptr fs:[00000030h] 4_2_01886420
Source: C:\Users\user\Desktop\SecuriteInfo.com.BackDoor.AgentTeslaNET.20.15021.21756.exe Code function: 4_2_01886420 mov eax, dword ptr fs:[00000030h] 4_2_01886420
Source: C:\Users\user\Desktop\SecuriteInfo.com.BackDoor.AgentTeslaNET.20.15021.21756.exe Code function: 4_2_01886420 mov eax, dword ptr fs:[00000030h] 4_2_01886420
Source: C:\Users\user\Desktop\SecuriteInfo.com.BackDoor.AgentTeslaNET.20.15021.21756.exe Code function: 4_2_0183A430 mov eax, dword ptr fs:[00000030h] 4_2_0183A430
Source: C:\Users\user\Desktop\SecuriteInfo.com.BackDoor.AgentTeslaNET.20.15021.21756.exe Code function: 4_2_0183E443 mov eax, dword ptr fs:[00000030h] 4_2_0183E443
Source: C:\Users\user\Desktop\SecuriteInfo.com.BackDoor.AgentTeslaNET.20.15021.21756.exe Code function: 4_2_0183E443 mov eax, dword ptr fs:[00000030h] 4_2_0183E443
Source: C:\Users\user\Desktop\SecuriteInfo.com.BackDoor.AgentTeslaNET.20.15021.21756.exe Code function: 4_2_0183E443 mov eax, dword ptr fs:[00000030h] 4_2_0183E443
Source: C:\Users\user\Desktop\SecuriteInfo.com.BackDoor.AgentTeslaNET.20.15021.21756.exe Code function: 4_2_0183E443 mov eax, dword ptr fs:[00000030h] 4_2_0183E443
Source: C:\Users\user\Desktop\SecuriteInfo.com.BackDoor.AgentTeslaNET.20.15021.21756.exe Code function: 4_2_0183E443 mov eax, dword ptr fs:[00000030h] 4_2_0183E443
Source: C:\Users\user\Desktop\SecuriteInfo.com.BackDoor.AgentTeslaNET.20.15021.21756.exe Code function: 4_2_0183E443 mov eax, dword ptr fs:[00000030h] 4_2_0183E443
Source: C:\Users\user\Desktop\SecuriteInfo.com.BackDoor.AgentTeslaNET.20.15021.21756.exe Code function: 4_2_0183E443 mov eax, dword ptr fs:[00000030h] 4_2_0183E443
Source: C:\Users\user\Desktop\SecuriteInfo.com.BackDoor.AgentTeslaNET.20.15021.21756.exe Code function: 4_2_0183E443 mov eax, dword ptr fs:[00000030h] 4_2_0183E443
Source: C:\Users\user\Desktop\SecuriteInfo.com.BackDoor.AgentTeslaNET.20.15021.21756.exe Code function: 4_2_0182245A mov eax, dword ptr fs:[00000030h] 4_2_0182245A
Source: C:\Users\user\Desktop\SecuriteInfo.com.BackDoor.AgentTeslaNET.20.15021.21756.exe Code function: 4_2_018BA456 mov eax, dword ptr fs:[00000030h] 4_2_018BA456
Source: C:\Users\user\Desktop\SecuriteInfo.com.BackDoor.AgentTeslaNET.20.15021.21756.exe Code function: 4_2_0188C460 mov ecx, dword ptr fs:[00000030h] 4_2_0188C460
Source: C:\Users\user\Desktop\SecuriteInfo.com.BackDoor.AgentTeslaNET.20.15021.21756.exe Code function: 4_2_0182A470 mov eax, dword ptr fs:[00000030h] 4_2_0182A470
Source: C:\Users\user\Desktop\SecuriteInfo.com.BackDoor.AgentTeslaNET.20.15021.21756.exe Code function: 4_2_0182A470 mov eax, dword ptr fs:[00000030h] 4_2_0182A470
Source: C:\Users\user\Desktop\SecuriteInfo.com.BackDoor.AgentTeslaNET.20.15021.21756.exe Code function: 4_2_0182A470 mov eax, dword ptr fs:[00000030h] 4_2_0182A470
Source: C:\Users\user\Desktop\SecuriteInfo.com.BackDoor.AgentTeslaNET.20.15021.21756.exe Code function: 4_2_018A678E mov eax, dword ptr fs:[00000030h] 4_2_018A678E
Source: C:\Users\user\Desktop\SecuriteInfo.com.BackDoor.AgentTeslaNET.20.15021.21756.exe Code function: 4_2_018B47A0 mov eax, dword ptr fs:[00000030h] 4_2_018B47A0
Source: C:\Users\user\Desktop\SecuriteInfo.com.BackDoor.AgentTeslaNET.20.15021.21756.exe Code function: 4_2_018007AF mov eax, dword ptr fs:[00000030h] 4_2_018007AF
Source: C:\Users\user\Desktop\SecuriteInfo.com.BackDoor.AgentTeslaNET.20.15021.21756.exe Code function: 4_2_0180C7C0 mov eax, dword ptr fs:[00000030h] 4_2_0180C7C0
Source: C:\Users\user\Desktop\SecuriteInfo.com.BackDoor.AgentTeslaNET.20.15021.21756.exe Code function: 4_2_018807C3 mov eax, dword ptr fs:[00000030h] 4_2_018807C3
Source: C:\Users\user\Desktop\SecuriteInfo.com.BackDoor.AgentTeslaNET.20.15021.21756.exe Code function: 4_2_0188E7E1 mov eax, dword ptr fs:[00000030h] 4_2_0188E7E1
Source: C:\Users\user\Desktop\SecuriteInfo.com.BackDoor.AgentTeslaNET.20.15021.21756.exe Code function: 4_2_018227ED mov eax, dword ptr fs:[00000030h] 4_2_018227ED
Source: C:\Users\user\Desktop\SecuriteInfo.com.BackDoor.AgentTeslaNET.20.15021.21756.exe Code function: 4_2_018227ED mov eax, dword ptr fs:[00000030h] 4_2_018227ED
Source: C:\Users\user\Desktop\SecuriteInfo.com.BackDoor.AgentTeslaNET.20.15021.21756.exe Code function: 4_2_018227ED mov eax, dword ptr fs:[00000030h] 4_2_018227ED
Source: C:\Users\user\Desktop\SecuriteInfo.com.BackDoor.AgentTeslaNET.20.15021.21756.exe Code function: 4_2_018047FB mov eax, dword ptr fs:[00000030h] 4_2_018047FB
Source: C:\Users\user\Desktop\SecuriteInfo.com.BackDoor.AgentTeslaNET.20.15021.21756.exe Code function: 4_2_018047FB mov eax, dword ptr fs:[00000030h] 4_2_018047FB
Source: C:\Users\user\Desktop\SecuriteInfo.com.BackDoor.AgentTeslaNET.20.15021.21756.exe Code function: 4_2_0183C700 mov eax, dword ptr fs:[00000030h] 4_2_0183C700
Source: C:\Users\user\Desktop\SecuriteInfo.com.BackDoor.AgentTeslaNET.20.15021.21756.exe Code function: 4_2_01800710 mov eax, dword ptr fs:[00000030h] 4_2_01800710
Source: C:\Users\user\Desktop\SecuriteInfo.com.BackDoor.AgentTeslaNET.20.15021.21756.exe Code function: 4_2_01830710 mov eax, dword ptr fs:[00000030h] 4_2_01830710
Source: C:\Users\user\Desktop\SecuriteInfo.com.BackDoor.AgentTeslaNET.20.15021.21756.exe Code function: 4_2_0183C720 mov eax, dword ptr fs:[00000030h] 4_2_0183C720
Source: C:\Users\user\Desktop\SecuriteInfo.com.BackDoor.AgentTeslaNET.20.15021.21756.exe Code function: 4_2_0183C720 mov eax, dword ptr fs:[00000030h] 4_2_0183C720
Source: C:\Users\user\Desktop\SecuriteInfo.com.BackDoor.AgentTeslaNET.20.15021.21756.exe Code function: 4_2_0187C730 mov eax, dword ptr fs:[00000030h] 4_2_0187C730
Source: C:\Users\user\Desktop\SecuriteInfo.com.BackDoor.AgentTeslaNET.20.15021.21756.exe Code function: 4_2_0183273C mov eax, dword ptr fs:[00000030h] 4_2_0183273C
Source: C:\Users\user\Desktop\SecuriteInfo.com.BackDoor.AgentTeslaNET.20.15021.21756.exe Code function: 4_2_0183273C mov ecx, dword ptr fs:[00000030h] 4_2_0183273C
Source: C:\Users\user\Desktop\SecuriteInfo.com.BackDoor.AgentTeslaNET.20.15021.21756.exe Code function: 4_2_0183273C mov eax, dword ptr fs:[00000030h] 4_2_0183273C
Source: C:\Users\user\Desktop\SecuriteInfo.com.BackDoor.AgentTeslaNET.20.15021.21756.exe Code function: 4_2_0183674D mov esi, dword ptr fs:[00000030h] 4_2_0183674D
Source: C:\Users\user\Desktop\SecuriteInfo.com.BackDoor.AgentTeslaNET.20.15021.21756.exe Code function: 4_2_0183674D mov eax, dword ptr fs:[00000030h] 4_2_0183674D
Source: C:\Users\user\Desktop\SecuriteInfo.com.BackDoor.AgentTeslaNET.20.15021.21756.exe Code function: 4_2_0183674D mov eax, dword ptr fs:[00000030h] 4_2_0183674D
Source: C:\Users\user\Desktop\SecuriteInfo.com.BackDoor.AgentTeslaNET.20.15021.21756.exe Code function: 4_2_01800750 mov eax, dword ptr fs:[00000030h] 4_2_01800750
Source: C:\Users\user\Desktop\SecuriteInfo.com.BackDoor.AgentTeslaNET.20.15021.21756.exe Code function: 4_2_01842750 mov eax, dword ptr fs:[00000030h] 4_2_01842750
Source: C:\Users\user\Desktop\SecuriteInfo.com.BackDoor.AgentTeslaNET.20.15021.21756.exe Code function: 4_2_01842750 mov eax, dword ptr fs:[00000030h] 4_2_01842750
Source: C:\Users\user\Desktop\SecuriteInfo.com.BackDoor.AgentTeslaNET.20.15021.21756.exe Code function: 4_2_0188E75D mov eax, dword ptr fs:[00000030h] 4_2_0188E75D
Source: C:\Users\user\Desktop\SecuriteInfo.com.BackDoor.AgentTeslaNET.20.15021.21756.exe Code function: 4_2_01884755 mov eax, dword ptr fs:[00000030h] 4_2_01884755
Source: C:\Users\user\Desktop\SecuriteInfo.com.BackDoor.AgentTeslaNET.20.15021.21756.exe Code function: 4_2_01808770 mov eax, dword ptr fs:[00000030h] 4_2_01808770
Source: C:\Users\user\Desktop\SecuriteInfo.com.BackDoor.AgentTeslaNET.20.15021.21756.exe Code function: 4_2_01810770 mov eax, dword ptr fs:[00000030h] 4_2_01810770
Source: C:\Users\user\Desktop\SecuriteInfo.com.BackDoor.AgentTeslaNET.20.15021.21756.exe Code function: 4_2_01810770 mov eax, dword ptr fs:[00000030h] 4_2_01810770
Source: C:\Users\user\Desktop\SecuriteInfo.com.BackDoor.AgentTeslaNET.20.15021.21756.exe Code function: 4_2_01810770 mov eax, dword ptr fs:[00000030h] 4_2_01810770
Source: C:\Users\user\Desktop\SecuriteInfo.com.BackDoor.AgentTeslaNET.20.15021.21756.exe Code function: 4_2_01810770 mov eax, dword ptr fs:[00000030h] 4_2_01810770
Source: C:\Users\user\Desktop\SecuriteInfo.com.BackDoor.AgentTeslaNET.20.15021.21756.exe Code function: 4_2_01810770 mov eax, dword ptr fs:[00000030h] 4_2_01810770
Source: C:\Users\user\Desktop\SecuriteInfo.com.BackDoor.AgentTeslaNET.20.15021.21756.exe Code function: 4_2_01810770 mov eax, dword ptr fs:[00000030h] 4_2_01810770
Source: C:\Users\user\Desktop\SecuriteInfo.com.BackDoor.AgentTeslaNET.20.15021.21756.exe Code function: 4_2_01810770 mov eax, dword ptr fs:[00000030h] 4_2_01810770
Source: C:\Users\user\Desktop\SecuriteInfo.com.BackDoor.AgentTeslaNET.20.15021.21756.exe Code function: 4_2_01810770 mov eax, dword ptr fs:[00000030h] 4_2_01810770
Source: C:\Users\user\Desktop\SecuriteInfo.com.BackDoor.AgentTeslaNET.20.15021.21756.exe Code function: 4_2_01810770 mov eax, dword ptr fs:[00000030h] 4_2_01810770
Source: C:\Users\user\Desktop\SecuriteInfo.com.BackDoor.AgentTeslaNET.20.15021.21756.exe Code function: 4_2_01810770 mov eax, dword ptr fs:[00000030h] 4_2_01810770
Source: C:\Users\user\Desktop\SecuriteInfo.com.BackDoor.AgentTeslaNET.20.15021.21756.exe Code function: 4_2_01810770 mov eax, dword ptr fs:[00000030h] 4_2_01810770
Source: C:\Users\user\Desktop\SecuriteInfo.com.BackDoor.AgentTeslaNET.20.15021.21756.exe Code function: 4_2_01810770 mov eax, dword ptr fs:[00000030h] 4_2_01810770
Source: C:\Users\user\Desktop\SecuriteInfo.com.BackDoor.AgentTeslaNET.20.15021.21756.exe Code function: 4_2_01804690 mov eax, dword ptr fs:[00000030h] 4_2_01804690
Source: C:\Users\user\Desktop\SecuriteInfo.com.BackDoor.AgentTeslaNET.20.15021.21756.exe Code function: 4_2_01804690 mov eax, dword ptr fs:[00000030h] 4_2_01804690
Source: C:\Users\user\Desktop\SecuriteInfo.com.BackDoor.AgentTeslaNET.20.15021.21756.exe Code function: 4_2_0183C6A6 mov eax, dword ptr fs:[00000030h] 4_2_0183C6A6
Source: C:\Users\user\Desktop\SecuriteInfo.com.BackDoor.AgentTeslaNET.20.15021.21756.exe Code function: 4_2_018366B0 mov eax, dword ptr fs:[00000030h] 4_2_018366B0
Source: C:\Users\user\Desktop\SecuriteInfo.com.BackDoor.AgentTeslaNET.20.15021.21756.exe Code function: 4_2_0183A6C7 mov ebx, dword ptr fs:[00000030h] 4_2_0183A6C7
Source: C:\Users\user\Desktop\SecuriteInfo.com.BackDoor.AgentTeslaNET.20.15021.21756.exe Code function: 4_2_0183A6C7 mov eax, dword ptr fs:[00000030h] 4_2_0183A6C7
Source: C:\Users\user\Desktop\SecuriteInfo.com.BackDoor.AgentTeslaNET.20.15021.21756.exe Code function: 4_2_0187E6F2 mov eax, dword ptr fs:[00000030h] 4_2_0187E6F2
Source: C:\Users\user\Desktop\SecuriteInfo.com.BackDoor.AgentTeslaNET.20.15021.21756.exe Code function: 4_2_0187E6F2 mov eax, dword ptr fs:[00000030h] 4_2_0187E6F2
Source: C:\Users\user\Desktop\SecuriteInfo.com.BackDoor.AgentTeslaNET.20.15021.21756.exe Code function: 4_2_0187E6F2 mov eax, dword ptr fs:[00000030h] 4_2_0187E6F2
Source: C:\Users\user\Desktop\SecuriteInfo.com.BackDoor.AgentTeslaNET.20.15021.21756.exe Code function: 4_2_0187E6F2 mov eax, dword ptr fs:[00000030h] 4_2_0187E6F2
Source: C:\Users\user\Desktop\SecuriteInfo.com.BackDoor.AgentTeslaNET.20.15021.21756.exe Code function: 4_2_018806F1 mov eax, dword ptr fs:[00000030h] 4_2_018806F1
Source: C:\Users\user\Desktop\SecuriteInfo.com.BackDoor.AgentTeslaNET.20.15021.21756.exe Code function: 4_2_018806F1 mov eax, dword ptr fs:[00000030h] 4_2_018806F1
Source: C:\Users\user\Desktop\SecuriteInfo.com.BackDoor.AgentTeslaNET.20.15021.21756.exe Code function: 4_2_0181260B mov eax, dword ptr fs:[00000030h] 4_2_0181260B
Source: C:\Users\user\Desktop\SecuriteInfo.com.BackDoor.AgentTeslaNET.20.15021.21756.exe Code function: 4_2_0181260B mov eax, dword ptr fs:[00000030h] 4_2_0181260B
Source: C:\Users\user\Desktop\SecuriteInfo.com.BackDoor.AgentTeslaNET.20.15021.21756.exe Code function: 4_2_0181260B mov eax, dword ptr fs:[00000030h] 4_2_0181260B
Source: C:\Users\user\Desktop\SecuriteInfo.com.BackDoor.AgentTeslaNET.20.15021.21756.exe Code function: 4_2_0181260B mov eax, dword ptr fs:[00000030h] 4_2_0181260B
Source: C:\Users\user\Desktop\SecuriteInfo.com.BackDoor.AgentTeslaNET.20.15021.21756.exe Code function: 4_2_0181260B mov eax, dword ptr fs:[00000030h] 4_2_0181260B
Source: C:\Users\user\Desktop\SecuriteInfo.com.BackDoor.AgentTeslaNET.20.15021.21756.exe Code function: 4_2_0181260B mov eax, dword ptr fs:[00000030h] 4_2_0181260B
Source: C:\Users\user\Desktop\SecuriteInfo.com.BackDoor.AgentTeslaNET.20.15021.21756.exe Code function: 4_2_0181260B mov eax, dword ptr fs:[00000030h] 4_2_0181260B
Source: C:\Users\user\Desktop\SecuriteInfo.com.BackDoor.AgentTeslaNET.20.15021.21756.exe Code function: 4_2_0187E609 mov eax, dword ptr fs:[00000030h] 4_2_0187E609
Source: C:\Users\user\Desktop\SecuriteInfo.com.BackDoor.AgentTeslaNET.20.15021.21756.exe Code function: 4_2_01842619 mov eax, dword ptr fs:[00000030h] 4_2_01842619
Source: C:\Users\user\Desktop\SecuriteInfo.com.BackDoor.AgentTeslaNET.20.15021.21756.exe Code function: 4_2_01836620 mov eax, dword ptr fs:[00000030h] 4_2_01836620
Source: C:\Users\user\Desktop\SecuriteInfo.com.BackDoor.AgentTeslaNET.20.15021.21756.exe Code function: 4_2_01838620 mov eax, dword ptr fs:[00000030h] 4_2_01838620
Source: C:\Users\user\Desktop\SecuriteInfo.com.BackDoor.AgentTeslaNET.20.15021.21756.exe Code function: 4_2_0181E627 mov eax, dword ptr fs:[00000030h] 4_2_0181E627
Source: C:\Users\user\Desktop\SecuriteInfo.com.BackDoor.AgentTeslaNET.20.15021.21756.exe Code function: 4_2_0180262C mov eax, dword ptr fs:[00000030h] 4_2_0180262C
Source: C:\Users\user\Desktop\SecuriteInfo.com.BackDoor.AgentTeslaNET.20.15021.21756.exe Code function: 4_2_0181C640 mov eax, dword ptr fs:[00000030h] 4_2_0181C640
Source: C:\Users\user\Desktop\SecuriteInfo.com.BackDoor.AgentTeslaNET.20.15021.21756.exe Code function: 4_2_018C866E mov eax, dword ptr fs:[00000030h] 4_2_018C866E
Source: C:\Users\user\Desktop\SecuriteInfo.com.BackDoor.AgentTeslaNET.20.15021.21756.exe Code function: 4_2_018C866E mov eax, dword ptr fs:[00000030h] 4_2_018C866E
Source: C:\Users\user\Desktop\SecuriteInfo.com.BackDoor.AgentTeslaNET.20.15021.21756.exe Code function: 4_2_0183A660 mov eax, dword ptr fs:[00000030h] 4_2_0183A660
Source: C:\Users\user\Desktop\SecuriteInfo.com.BackDoor.AgentTeslaNET.20.15021.21756.exe Code function: 4_2_0183A660 mov eax, dword ptr fs:[00000030h] 4_2_0183A660
Source: C:\Users\user\Desktop\SecuriteInfo.com.BackDoor.AgentTeslaNET.20.15021.21756.exe Code function: 4_2_01832674 mov eax, dword ptr fs:[00000030h] 4_2_01832674
Source: C:\Users\user\Desktop\SecuriteInfo.com.BackDoor.AgentTeslaNET.20.15021.21756.exe Code function: 4_2_018129A0 mov eax, dword ptr fs:[00000030h] 4_2_018129A0
Source: C:\Users\user\Desktop\SecuriteInfo.com.BackDoor.AgentTeslaNET.20.15021.21756.exe Code function: 4_2_018129A0 mov eax, dword ptr fs:[00000030h] 4_2_018129A0
Source: C:\Users\user\Desktop\SecuriteInfo.com.BackDoor.AgentTeslaNET.20.15021.21756.exe Code function: 4_2_018129A0 mov eax, dword ptr fs:[00000030h] 4_2_018129A0
Source: C:\Users\user\Desktop\SecuriteInfo.com.BackDoor.AgentTeslaNET.20.15021.21756.exe Code function: 4_2_018129A0 mov eax, dword ptr fs:[00000030h] 4_2_018129A0
Source: C:\Users\user\Desktop\SecuriteInfo.com.BackDoor.AgentTeslaNET.20.15021.21756.exe Code function: 4_2_018129A0 mov eax, dword ptr fs:[00000030h] 4_2_018129A0
Source: C:\Users\user\Desktop\SecuriteInfo.com.BackDoor.AgentTeslaNET.20.15021.21756.exe Code function: 4_2_018129A0 mov eax, dword ptr fs:[00000030h] 4_2_018129A0
Source: C:\Users\user\Desktop\SecuriteInfo.com.BackDoor.AgentTeslaNET.20.15021.21756.exe Code function: 4_2_018129A0 mov eax, dword ptr fs:[00000030h] 4_2_018129A0
Source: C:\Users\user\Desktop\SecuriteInfo.com.BackDoor.AgentTeslaNET.20.15021.21756.exe Code function: 4_2_018129A0 mov eax, dword ptr fs:[00000030h] 4_2_018129A0
Source: C:\Users\user\Desktop\SecuriteInfo.com.BackDoor.AgentTeslaNET.20.15021.21756.exe Code function: 4_2_018129A0 mov eax, dword ptr fs:[00000030h] 4_2_018129A0
Source: C:\Users\user\Desktop\SecuriteInfo.com.BackDoor.AgentTeslaNET.20.15021.21756.exe Code function: 4_2_018129A0 mov eax, dword ptr fs:[00000030h] 4_2_018129A0
Source: C:\Users\user\Desktop\SecuriteInfo.com.BackDoor.AgentTeslaNET.20.15021.21756.exe Code function: 4_2_018129A0 mov eax, dword ptr fs:[00000030h] 4_2_018129A0
Source: C:\Users\user\Desktop\SecuriteInfo.com.BackDoor.AgentTeslaNET.20.15021.21756.exe Code function: 4_2_018129A0 mov eax, dword ptr fs:[00000030h] 4_2_018129A0
Source: C:\Users\user\Desktop\SecuriteInfo.com.BackDoor.AgentTeslaNET.20.15021.21756.exe Code function: 4_2_018129A0 mov eax, dword ptr fs:[00000030h] 4_2_018129A0
Source: C:\Users\user\Desktop\SecuriteInfo.com.BackDoor.AgentTeslaNET.20.15021.21756.exe Code function: 4_2_018009AD mov eax, dword ptr fs:[00000030h] 4_2_018009AD
Source: C:\Users\user\Desktop\SecuriteInfo.com.BackDoor.AgentTeslaNET.20.15021.21756.exe Code function: 4_2_018009AD mov eax, dword ptr fs:[00000030h] 4_2_018009AD
Source: C:\Users\user\Desktop\SecuriteInfo.com.BackDoor.AgentTeslaNET.20.15021.21756.exe Code function: 4_2_018889B3 mov esi, dword ptr fs:[00000030h] 4_2_018889B3
Source: C:\Users\user\Desktop\SecuriteInfo.com.BackDoor.AgentTeslaNET.20.15021.21756.exe Code function: 4_2_018889B3 mov eax, dword ptr fs:[00000030h] 4_2_018889B3
Source: C:\Users\user\Desktop\SecuriteInfo.com.BackDoor.AgentTeslaNET.20.15021.21756.exe Code function: 4_2_018889B3 mov eax, dword ptr fs:[00000030h] 4_2_018889B3
Source: C:\Users\user\Desktop\SecuriteInfo.com.BackDoor.AgentTeslaNET.20.15021.21756.exe Code function: 4_2_018969C0 mov eax, dword ptr fs:[00000030h] 4_2_018969C0
Source: C:\Users\user\Desktop\SecuriteInfo.com.BackDoor.AgentTeslaNET.20.15021.21756.exe Code function: 4_2_0180A9D0 mov eax, dword ptr fs:[00000030h] 4_2_0180A9D0
Source: C:\Users\user\Desktop\SecuriteInfo.com.BackDoor.AgentTeslaNET.20.15021.21756.exe Code function: 4_2_0180A9D0 mov eax, dword ptr fs:[00000030h] 4_2_0180A9D0
Source: C:\Users\user\Desktop\SecuriteInfo.com.BackDoor.AgentTeslaNET.20.15021.21756.exe Code function: 4_2_0180A9D0 mov eax, dword ptr fs:[00000030h] 4_2_0180A9D0
Source: C:\Users\user\Desktop\SecuriteInfo.com.BackDoor.AgentTeslaNET.20.15021.21756.exe Code function: 4_2_0180A9D0 mov eax, dword ptr fs:[00000030h] 4_2_0180A9D0
Source: C:\Users\user\Desktop\SecuriteInfo.com.BackDoor.AgentTeslaNET.20.15021.21756.exe Code function: 4_2_0180A9D0 mov eax, dword ptr fs:[00000030h] 4_2_0180A9D0
Source: C:\Users\user\Desktop\SecuriteInfo.com.BackDoor.AgentTeslaNET.20.15021.21756.exe Code function: 4_2_0180A9D0 mov eax, dword ptr fs:[00000030h] 4_2_0180A9D0
Source: C:\Users\user\Desktop\SecuriteInfo.com.BackDoor.AgentTeslaNET.20.15021.21756.exe Code function: 4_2_018349D0 mov eax, dword ptr fs:[00000030h] 4_2_018349D0
Source: C:\Users\user\Desktop\SecuriteInfo.com.BackDoor.AgentTeslaNET.20.15021.21756.exe Code function: 4_2_018CA9D3 mov eax, dword ptr fs:[00000030h] 4_2_018CA9D3
Source: C:\Users\user\Desktop\SecuriteInfo.com.BackDoor.AgentTeslaNET.20.15021.21756.exe Code function: 4_2_017F8918 mov eax, dword ptr fs:[00000030h] 4_2_017F8918
Source: C:\Users\user\Desktop\SecuriteInfo.com.BackDoor.AgentTeslaNET.20.15021.21756.exe Code function: 4_2_017F8918 mov eax, dword ptr fs:[00000030h] 4_2_017F8918
Source: C:\Users\user\Desktop\SecuriteInfo.com.BackDoor.AgentTeslaNET.20.15021.21756.exe Code function: 4_2_0188E9E0 mov eax, dword ptr fs:[00000030h] 4_2_0188E9E0
Source: C:\Users\user\Desktop\SecuriteInfo.com.BackDoor.AgentTeslaNET.20.15021.21756.exe Code function: 4_2_018329F9 mov eax, dword ptr fs:[00000030h] 4_2_018329F9
Source: C:\Users\user\Desktop\SecuriteInfo.com.BackDoor.AgentTeslaNET.20.15021.21756.exe Code function: 4_2_018329F9 mov eax, dword ptr fs:[00000030h] 4_2_018329F9
Source: C:\Users\user\Desktop\SecuriteInfo.com.BackDoor.AgentTeslaNET.20.15021.21756.exe Code function: 4_2_0187E908 mov eax, dword ptr fs:[00000030h] 4_2_0187E908
Source: C:\Users\user\Desktop\SecuriteInfo.com.BackDoor.AgentTeslaNET.20.15021.21756.exe Code function: 4_2_0187E908 mov eax, dword ptr fs:[00000030h] 4_2_0187E908
Source: C:\Users\user\Desktop\SecuriteInfo.com.BackDoor.AgentTeslaNET.20.15021.21756.exe Code function: 4_2_0188C912 mov eax, dword ptr fs:[00000030h] 4_2_0188C912
Source: C:\Users\user\Desktop\SecuriteInfo.com.BackDoor.AgentTeslaNET.20.15021.21756.exe Code function: 4_2_0188892A mov eax, dword ptr fs:[00000030h] 4_2_0188892A
Source: C:\Users\user\Desktop\SecuriteInfo.com.BackDoor.AgentTeslaNET.20.15021.21756.exe Code function: 4_2_0189892B mov eax, dword ptr fs:[00000030h] 4_2_0189892B
Source: C:\Users\user\Desktop\SecuriteInfo.com.BackDoor.AgentTeslaNET.20.15021.21756.exe Code function: 4_2_018D4940 mov eax, dword ptr fs:[00000030h] 4_2_018D4940
Source: C:\Users\user\Desktop\SecuriteInfo.com.BackDoor.AgentTeslaNET.20.15021.21756.exe Code function: 4_2_01880946 mov eax, dword ptr fs:[00000030h] 4_2_01880946
Source: C:\Users\user\Desktop\SecuriteInfo.com.BackDoor.AgentTeslaNET.20.15021.21756.exe Code function: 4_2_01826962 mov eax, dword ptr fs:[00000030h] 4_2_01826962
Source: C:\Users\user\Desktop\SecuriteInfo.com.BackDoor.AgentTeslaNET.20.15021.21756.exe Code function: 4_2_01826962 mov eax, dword ptr fs:[00000030h] 4_2_01826962
Source: C:\Users\user\Desktop\SecuriteInfo.com.BackDoor.AgentTeslaNET.20.15021.21756.exe Code function: 4_2_01826962 mov eax, dword ptr fs:[00000030h] 4_2_01826962
Source: C:\Users\user\Desktop\SecuriteInfo.com.BackDoor.AgentTeslaNET.20.15021.21756.exe Code function: 4_2_0184096E mov eax, dword ptr fs:[00000030h] 4_2_0184096E
Source: C:\Users\user\Desktop\SecuriteInfo.com.BackDoor.AgentTeslaNET.20.15021.21756.exe Code function: 4_2_0184096E mov edx, dword ptr fs:[00000030h] 4_2_0184096E
Source: C:\Users\user\Desktop\SecuriteInfo.com.BackDoor.AgentTeslaNET.20.15021.21756.exe Code function: 4_2_0184096E mov eax, dword ptr fs:[00000030h] 4_2_0184096E
Source: C:\Users\user\Desktop\SecuriteInfo.com.BackDoor.AgentTeslaNET.20.15021.21756.exe Code function: 4_2_018A4978 mov eax, dword ptr fs:[00000030h] 4_2_018A4978
Source: C:\Users\user\Desktop\SecuriteInfo.com.BackDoor.AgentTeslaNET.20.15021.21756.exe Code function: 4_2_018A4978 mov eax, dword ptr fs:[00000030h] 4_2_018A4978
Source: C:\Users\user\Desktop\SecuriteInfo.com.BackDoor.AgentTeslaNET.20.15021.21756.exe Code function: 4_2_0188C97C mov eax, dword ptr fs:[00000030h] 4_2_0188C97C
Source: C:\Users\user\Desktop\SecuriteInfo.com.BackDoor.AgentTeslaNET.20.15021.21756.exe Code function: 4_2_01800887 mov eax, dword ptr fs:[00000030h] 4_2_01800887
Source: C:\Users\user\Desktop\SecuriteInfo.com.BackDoor.AgentTeslaNET.20.15021.21756.exe Code function: 4_2_0188C89D mov eax, dword ptr fs:[00000030h] 4_2_0188C89D
Source: C:\Users\user\Desktop\SecuriteInfo.com.BackDoor.AgentTeslaNET.20.15021.21756.exe Code function: 4_2_0182E8C0 mov eax, dword ptr fs:[00000030h] 4_2_0182E8C0
Source: C:\Users\user\Desktop\SecuriteInfo.com.BackDoor.AgentTeslaNET.20.15021.21756.exe Code function: 4_2_018D08C0 mov eax, dword ptr fs:[00000030h] 4_2_018D08C0
Source: C:\Users\user\Desktop\SecuriteInfo.com.BackDoor.AgentTeslaNET.20.15021.21756.exe Code function: 4_2_018CA8E4 mov eax, dword ptr fs:[00000030h] 4_2_018CA8E4
Source: C:\Users\user\Desktop\SecuriteInfo.com.BackDoor.AgentTeslaNET.20.15021.21756.exe Code function: 4_2_0183C8F9 mov eax, dword ptr fs:[00000030h] 4_2_0183C8F9
Source: C:\Users\user\Desktop\SecuriteInfo.com.BackDoor.AgentTeslaNET.20.15021.21756.exe Code function: 4_2_0183C8F9 mov eax, dword ptr fs:[00000030h] 4_2_0183C8F9
Source: C:\Users\user\Desktop\SecuriteInfo.com.BackDoor.AgentTeslaNET.20.15021.21756.exe Code function: 4_2_0188C810 mov eax, dword ptr fs:[00000030h] 4_2_0188C810
Source: C:\Users\user\Desktop\SecuriteInfo.com.BackDoor.AgentTeslaNET.20.15021.21756.exe Code function: 4_2_018A483A mov eax, dword ptr fs:[00000030h] 4_2_018A483A
Source: C:\Users\user\Desktop\SecuriteInfo.com.BackDoor.AgentTeslaNET.20.15021.21756.exe Code function: 4_2_018A483A mov eax, dword ptr fs:[00000030h] 4_2_018A483A
Source: C:\Users\user\Desktop\SecuriteInfo.com.BackDoor.AgentTeslaNET.20.15021.21756.exe Code function: 4_2_0183A830 mov eax, dword ptr fs:[00000030h] 4_2_0183A830
Source: C:\Users\user\Desktop\SecuriteInfo.com.BackDoor.AgentTeslaNET.20.15021.21756.exe Code function: 4_2_01822835 mov eax, dword ptr fs:[00000030h] 4_2_01822835
Source: C:\Users\user\Desktop\SecuriteInfo.com.BackDoor.AgentTeslaNET.20.15021.21756.exe Code function: 4_2_01822835 mov eax, dword ptr fs:[00000030h] 4_2_01822835
Source: C:\Users\user\Desktop\SecuriteInfo.com.BackDoor.AgentTeslaNET.20.15021.21756.exe Code function: 4_2_01822835 mov eax, dword ptr fs:[00000030h] 4_2_01822835
Source: C:\Users\user\Desktop\SecuriteInfo.com.BackDoor.AgentTeslaNET.20.15021.21756.exe Code function: 4_2_01822835 mov ecx, dword ptr fs:[00000030h] 4_2_01822835
Source: C:\Users\user\Desktop\SecuriteInfo.com.BackDoor.AgentTeslaNET.20.15021.21756.exe Code function: 4_2_01822835 mov eax, dword ptr fs:[00000030h] 4_2_01822835
Source: C:\Users\user\Desktop\SecuriteInfo.com.BackDoor.AgentTeslaNET.20.15021.21756.exe Code function: 4_2_01822835 mov eax, dword ptr fs:[00000030h] 4_2_01822835
Source: C:\Users\user\Desktop\SecuriteInfo.com.BackDoor.AgentTeslaNET.20.15021.21756.exe Code function: 4_2_01812840 mov ecx, dword ptr fs:[00000030h] 4_2_01812840
Source: C:\Users\user\Desktop\SecuriteInfo.com.BackDoor.AgentTeslaNET.20.15021.21756.exe Code function: 4_2_01830854 mov eax, dword ptr fs:[00000030h] 4_2_01830854
Source: C:\Users\user\Desktop\SecuriteInfo.com.BackDoor.AgentTeslaNET.20.15021.21756.exe Code function: 4_2_01804859 mov eax, dword ptr fs:[00000030h] 4_2_01804859
Source: C:\Users\user\Desktop\SecuriteInfo.com.BackDoor.AgentTeslaNET.20.15021.21756.exe Code function: 4_2_01804859 mov eax, dword ptr fs:[00000030h] 4_2_01804859
Source: C:\Users\user\Desktop\SecuriteInfo.com.BackDoor.AgentTeslaNET.20.15021.21756.exe Code function: 4_2_01896870 mov eax, dword ptr fs:[00000030h] 4_2_01896870
Source: C:\Users\user\Desktop\SecuriteInfo.com.BackDoor.AgentTeslaNET.20.15021.21756.exe Code function: 4_2_01896870 mov eax, dword ptr fs:[00000030h] 4_2_01896870
Source: C:\Users\user\Desktop\SecuriteInfo.com.BackDoor.AgentTeslaNET.20.15021.21756.exe Code function: 4_2_0188E872 mov eax, dword ptr fs:[00000030h] 4_2_0188E872
Source: C:\Users\user\Desktop\SecuriteInfo.com.BackDoor.AgentTeslaNET.20.15021.21756.exe Code function: 4_2_0188E872 mov eax, dword ptr fs:[00000030h] 4_2_0188E872
Source: C:\Users\user\Desktop\SecuriteInfo.com.BackDoor.AgentTeslaNET.20.15021.21756.exe Code function: 4_2_017FCB7E mov eax, dword ptr fs:[00000030h] 4_2_017FCB7E
Source: C:\Users\user\Desktop\SecuriteInfo.com.BackDoor.AgentTeslaNET.20.15021.21756.exe Code function: 4_2_017F8B50 mov eax, dword ptr fs:[00000030h] 4_2_017F8B50
Source: C:\Users\user\Desktop\SecuriteInfo.com.BackDoor.AgentTeslaNET.20.15021.21756.exe Code function: 4_2_018B4BB0 mov eax, dword ptr fs:[00000030h] 4_2_018B4BB0
Source: C:\Users\user\Desktop\SecuriteInfo.com.BackDoor.AgentTeslaNET.20.15021.21756.exe Code function: 4_2_018B4BB0 mov eax, dword ptr fs:[00000030h] 4_2_018B4BB0
Source: C:\Users\user\Desktop\SecuriteInfo.com.BackDoor.AgentTeslaNET.20.15021.21756.exe Code function: 4_2_01810BBE mov eax, dword ptr fs:[00000030h] 4_2_01810BBE
Source: C:\Users\user\Desktop\SecuriteInfo.com.BackDoor.AgentTeslaNET.20.15021.21756.exe Code function: 4_2_01810BBE mov eax, dword ptr fs:[00000030h] 4_2_01810BBE
Source: C:\Users\user\Desktop\SecuriteInfo.com.BackDoor.AgentTeslaNET.20.15021.21756.exe Code function: 4_2_01820BCB mov eax, dword ptr fs:[00000030h] 4_2_01820BCB
Source: C:\Users\user\Desktop\SecuriteInfo.com.BackDoor.AgentTeslaNET.20.15021.21756.exe Code function: 4_2_01820BCB mov eax, dword ptr fs:[00000030h] 4_2_01820BCB
Source: C:\Users\user\Desktop\SecuriteInfo.com.BackDoor.AgentTeslaNET.20.15021.21756.exe Code function: 4_2_01820BCB mov eax, dword ptr fs:[00000030h] 4_2_01820BCB
Source: C:\Users\user\Desktop\SecuriteInfo.com.BackDoor.AgentTeslaNET.20.15021.21756.exe Code function: 4_2_01800BCD mov eax, dword ptr fs:[00000030h] 4_2_01800BCD
Source: C:\Users\user\Desktop\SecuriteInfo.com.BackDoor.AgentTeslaNET.20.15021.21756.exe Code function: 4_2_01800BCD mov eax, dword ptr fs:[00000030h] 4_2_01800BCD
Source: C:\Users\user\Desktop\SecuriteInfo.com.BackDoor.AgentTeslaNET.20.15021.21756.exe Code function: 4_2_01800BCD mov eax, dword ptr fs:[00000030h] 4_2_01800BCD
Source: C:\Users\user\Desktop\SecuriteInfo.com.BackDoor.AgentTeslaNET.20.15021.21756.exe Code function: 4_2_018AEBD0 mov eax, dword ptr fs:[00000030h] 4_2_018AEBD0
Source: C:\Users\user\Desktop\SecuriteInfo.com.BackDoor.AgentTeslaNET.20.15021.21756.exe Code function: 4_2_01808BF0 mov eax, dword ptr fs:[00000030h] 4_2_01808BF0
Source: C:\Users\user\Desktop\SecuriteInfo.com.BackDoor.AgentTeslaNET.20.15021.21756.exe Code function: 4_2_01808BF0 mov eax, dword ptr fs:[00000030h] 4_2_01808BF0
Source: C:\Users\user\Desktop\SecuriteInfo.com.BackDoor.AgentTeslaNET.20.15021.21756.exe Code function: 4_2_01808BF0 mov eax, dword ptr fs:[00000030h] 4_2_01808BF0
Source: C:\Users\user\Desktop\SecuriteInfo.com.BackDoor.AgentTeslaNET.20.15021.21756.exe Code function: 4_2_0188CBF0 mov eax, dword ptr fs:[00000030h] 4_2_0188CBF0
Source: C:\Users\user\Desktop\SecuriteInfo.com.BackDoor.AgentTeslaNET.20.15021.21756.exe Code function: 4_2_0182EBFC mov eax, dword ptr fs:[00000030h] 4_2_0182EBFC
Source: C:\Users\user\Desktop\SecuriteInfo.com.BackDoor.AgentTeslaNET.20.15021.21756.exe Code function: 4_2_018D4B00 mov eax, dword ptr fs:[00000030h] 4_2_018D4B00
Source: C:\Users\user\Desktop\SecuriteInfo.com.BackDoor.AgentTeslaNET.20.15021.21756.exe Code function: 4_2_0187EB1D mov eax, dword ptr fs:[00000030h] 4_2_0187EB1D
Source: C:\Users\user\Desktop\SecuriteInfo.com.BackDoor.AgentTeslaNET.20.15021.21756.exe Code function: 4_2_0187EB1D mov eax, dword ptr fs:[00000030h] 4_2_0187EB1D
Source: C:\Users\user\Desktop\SecuriteInfo.com.BackDoor.AgentTeslaNET.20.15021.21756.exe Code function: 4_2_0187EB1D mov eax, dword ptr fs:[00000030h] 4_2_0187EB1D
Source: C:\Users\user\Desktop\SecuriteInfo.com.BackDoor.AgentTeslaNET.20.15021.21756.exe Code function: 4_2_0187EB1D mov eax, dword ptr fs:[00000030h] 4_2_0187EB1D
Source: C:\Users\user\Desktop\SecuriteInfo.com.BackDoor.AgentTeslaNET.20.15021.21756.exe Code function: 4_2_0187EB1D mov eax, dword ptr fs:[00000030h] 4_2_0187EB1D
Source: C:\Users\user\Desktop\SecuriteInfo.com.BackDoor.AgentTeslaNET.20.15021.21756.exe Code function: 4_2_0187EB1D mov eax, dword ptr fs:[00000030h] 4_2_0187EB1D
Source: C:\Users\user\Desktop\SecuriteInfo.com.BackDoor.AgentTeslaNET.20.15021.21756.exe Code function: 4_2_0187EB1D mov eax, dword ptr fs:[00000030h] 4_2_0187EB1D
Source: C:\Users\user\Desktop\SecuriteInfo.com.BackDoor.AgentTeslaNET.20.15021.21756.exe Code function: 4_2_0187EB1D mov eax, dword ptr fs:[00000030h] 4_2_0187EB1D
Source: C:\Users\user\Desktop\SecuriteInfo.com.BackDoor.AgentTeslaNET.20.15021.21756.exe Code function: 4_2_0187EB1D mov eax, dword ptr fs:[00000030h] 4_2_0187EB1D
Source: C:\Users\user\Desktop\SecuriteInfo.com.BackDoor.AgentTeslaNET.20.15021.21756.exe Code function: 4_2_0182EB20 mov eax, dword ptr fs:[00000030h] 4_2_0182EB20
Source: C:\Users\user\Desktop\SecuriteInfo.com.BackDoor.AgentTeslaNET.20.15021.21756.exe Code function: 4_2_0182EB20 mov eax, dword ptr fs:[00000030h] 4_2_0182EB20
Source: C:\Users\user\Desktop\SecuriteInfo.com.BackDoor.AgentTeslaNET.20.15021.21756.exe Code function: 4_2_018C8B28 mov eax, dword ptr fs:[00000030h] 4_2_018C8B28
Source: C:\Users\user\Desktop\SecuriteInfo.com.BackDoor.AgentTeslaNET.20.15021.21756.exe Code function: 4_2_018C8B28 mov eax, dword ptr fs:[00000030h] 4_2_018C8B28
Source: C:\Users\user\Desktop\SecuriteInfo.com.BackDoor.AgentTeslaNET.20.15021.21756.exe Code function: 4_2_018B4B4B mov eax, dword ptr fs:[00000030h] 4_2_018B4B4B
Source: C:\Users\user\Desktop\SecuriteInfo.com.BackDoor.AgentTeslaNET.20.15021.21756.exe Code function: 4_2_018B4B4B mov eax, dword ptr fs:[00000030h] 4_2_018B4B4B
Source: C:\Users\user\Desktop\SecuriteInfo.com.BackDoor.AgentTeslaNET.20.15021.21756.exe Code function: 4_2_018A8B42 mov eax, dword ptr fs:[00000030h] 4_2_018A8B42
Source: C:\Users\user\Desktop\SecuriteInfo.com.BackDoor.AgentTeslaNET.20.15021.21756.exe Code function: 4_2_01896B40 mov eax, dword ptr fs:[00000030h] 4_2_01896B40
Source: C:\Users\user\Desktop\SecuriteInfo.com.BackDoor.AgentTeslaNET.20.15021.21756.exe Code function: 4_2_01896B40 mov eax, dword ptr fs:[00000030h] 4_2_01896B40
Source: C:\Users\user\Desktop\SecuriteInfo.com.BackDoor.AgentTeslaNET.20.15021.21756.exe Code function: 4_2_018CAB40 mov eax, dword ptr fs:[00000030h] 4_2_018CAB40
Source: C:\Users\user\Desktop\SecuriteInfo.com.BackDoor.AgentTeslaNET.20.15021.21756.exe Code function: 4_2_018AEB50 mov eax, dword ptr fs:[00000030h] 4_2_018AEB50
Source: C:\Users\user\Desktop\SecuriteInfo.com.BackDoor.AgentTeslaNET.20.15021.21756.exe Code function: 4_2_018D2B57 mov eax, dword ptr fs:[00000030h] 4_2_018D2B57
Source: C:\Users\user\Desktop\SecuriteInfo.com.BackDoor.AgentTeslaNET.20.15021.21756.exe Code function: 4_2_018D2B57 mov eax, dword ptr fs:[00000030h] 4_2_018D2B57
Source: C:\Users\user\Desktop\SecuriteInfo.com.BackDoor.AgentTeslaNET.20.15021.21756.exe Code function: 4_2_018D2B57 mov eax, dword ptr fs:[00000030h] 4_2_018D2B57
Source: C:\Users\user\Desktop\SecuriteInfo.com.BackDoor.AgentTeslaNET.20.15021.21756.exe Code function: 4_2_018D2B57 mov eax, dword ptr fs:[00000030h] 4_2_018D2B57
Source: C:\Users\user\Desktop\SecuriteInfo.com.BackDoor.AgentTeslaNET.20.15021.21756.exe Code function: 4_2_0180EA80 mov eax, dword ptr fs:[00000030h] 4_2_0180EA80
Source: C:\Users\user\Desktop\SecuriteInfo.com.BackDoor.AgentTeslaNET.20.15021.21756.exe Code function: 4_2_0180EA80 mov eax, dword ptr fs:[00000030h] 4_2_0180EA80
Source: C:\Users\user\Desktop\SecuriteInfo.com.BackDoor.AgentTeslaNET.20.15021.21756.exe Code function: 4_2_0180EA80 mov eax, dword ptr fs:[00000030h] 4_2_0180EA80
Source: C:\Users\user\Desktop\SecuriteInfo.com.BackDoor.AgentTeslaNET.20.15021.21756.exe Code function: 4_2_0180EA80 mov eax, dword ptr fs:[00000030h] 4_2_0180EA80
Source: C:\Users\user\Desktop\SecuriteInfo.com.BackDoor.AgentTeslaNET.20.15021.21756.exe Code function: 4_2_0180EA80 mov eax, dword ptr fs:[00000030h] 4_2_0180EA80
Source: C:\Users\user\Desktop\SecuriteInfo.com.BackDoor.AgentTeslaNET.20.15021.21756.exe Code function: 4_2_0180EA80 mov eax, dword ptr fs:[00000030h] 4_2_0180EA80
Source: C:\Users\user\Desktop\SecuriteInfo.com.BackDoor.AgentTeslaNET.20.15021.21756.exe Code function: 4_2_0180EA80 mov eax, dword ptr fs:[00000030h] 4_2_0180EA80
Source: C:\Users\user\Desktop\SecuriteInfo.com.BackDoor.AgentTeslaNET.20.15021.21756.exe Code function: 4_2_0180EA80 mov eax, dword ptr fs:[00000030h] 4_2_0180EA80
Source: C:\Users\user\Desktop\SecuriteInfo.com.BackDoor.AgentTeslaNET.20.15021.21756.exe Code function: 4_2_0180EA80 mov eax, dword ptr fs:[00000030h] 4_2_0180EA80
Source: C:\Users\user\Desktop\SecuriteInfo.com.BackDoor.AgentTeslaNET.20.15021.21756.exe Code function: 4_2_018D4A80 mov eax, dword ptr fs:[00000030h] 4_2_018D4A80
Source: C:\Users\user\Desktop\SecuriteInfo.com.BackDoor.AgentTeslaNET.20.15021.21756.exe Code function: 4_2_01838A90 mov edx, dword ptr fs:[00000030h] 4_2_01838A90
Source: C:\Users\user\Desktop\SecuriteInfo.com.BackDoor.AgentTeslaNET.20.15021.21756.exe Code function: 4_2_01808AA0 mov eax, dword ptr fs:[00000030h] 4_2_01808AA0
Source: C:\Users\user\Desktop\SecuriteInfo.com.BackDoor.AgentTeslaNET.20.15021.21756.exe Code function: 4_2_01808AA0 mov eax, dword ptr fs:[00000030h] 4_2_01808AA0
Source: C:\Users\user\Desktop\SecuriteInfo.com.BackDoor.AgentTeslaNET.20.15021.21756.exe Code function: 4_2_01856AA4 mov eax, dword ptr fs:[00000030h] 4_2_01856AA4
Source: C:\Users\user\Desktop\SecuriteInfo.com.BackDoor.AgentTeslaNET.20.15021.21756.exe Code function: 4_2_01856ACC mov eax, dword ptr fs:[00000030h] 4_2_01856ACC
Source: C:\Users\user\Desktop\SecuriteInfo.com.BackDoor.AgentTeslaNET.20.15021.21756.exe Code function: 4_2_01856ACC mov eax, dword ptr fs:[00000030h] 4_2_01856ACC
Source: C:\Users\user\Desktop\SecuriteInfo.com.BackDoor.AgentTeslaNET.20.15021.21756.exe Code function: 4_2_01856ACC mov eax, dword ptr fs:[00000030h] 4_2_01856ACC
Source: C:\Users\user\Desktop\SecuriteInfo.com.BackDoor.AgentTeslaNET.20.15021.21756.exe Code function: 4_2_01800AD0 mov eax, dword ptr fs:[00000030h] 4_2_01800AD0
Source: C:\Users\user\Desktop\SecuriteInfo.com.BackDoor.AgentTeslaNET.20.15021.21756.exe Code function: 4_2_01834AD0 mov eax, dword ptr fs:[00000030h] 4_2_01834AD0
Source: C:\Users\user\Desktop\SecuriteInfo.com.BackDoor.AgentTeslaNET.20.15021.21756.exe Code function: 4_2_01834AD0 mov eax, dword ptr fs:[00000030h] 4_2_01834AD0
Source: C:\Users\user\Desktop\SecuriteInfo.com.BackDoor.AgentTeslaNET.20.15021.21756.exe Code function: 4_2_0183AAEE mov eax, dword ptr fs:[00000030h] 4_2_0183AAEE
Source: C:\Users\user\Desktop\SecuriteInfo.com.BackDoor.AgentTeslaNET.20.15021.21756.exe Code function: 4_2_0183AAEE mov eax, dword ptr fs:[00000030h] 4_2_0183AAEE
Source: C:\Users\user\Desktop\SecuriteInfo.com.BackDoor.AgentTeslaNET.20.15021.21756.exe Code function: 4_2_0188CA11 mov eax, dword ptr fs:[00000030h] 4_2_0188CA11
Source: C:\Users\user\Desktop\SecuriteInfo.com.BackDoor.AgentTeslaNET.20.15021.21756.exe Code function: 4_2_0183CA24 mov eax, dword ptr fs:[00000030h] 4_2_0183CA24
Source: C:\Users\user\Desktop\SecuriteInfo.com.BackDoor.AgentTeslaNET.20.15021.21756.exe Code function: 4_2_0182EA2E mov eax, dword ptr fs:[00000030h] 4_2_0182EA2E
Source: C:\Users\user\Desktop\SecuriteInfo.com.BackDoor.AgentTeslaNET.20.15021.21756.exe Code function: 4_2_01824A35 mov eax, dword ptr fs:[00000030h] 4_2_01824A35
Source: C:\Users\user\Desktop\SecuriteInfo.com.BackDoor.AgentTeslaNET.20.15021.21756.exe Code function: 4_2_01824A35 mov eax, dword ptr fs:[00000030h] 4_2_01824A35
Source: C:\Users\user\Desktop\SecuriteInfo.com.BackDoor.AgentTeslaNET.20.15021.21756.exe Code function: 4_2_0183CA38 mov eax, dword ptr fs:[00000030h] 4_2_0183CA38
Source: C:\Users\user\Desktop\SecuriteInfo.com.BackDoor.AgentTeslaNET.20.15021.21756.exe Code function: 4_2_01806A50 mov eax, dword ptr fs:[00000030h] 4_2_01806A50
Source: C:\Users\user\Desktop\SecuriteInfo.com.BackDoor.AgentTeslaNET.20.15021.21756.exe Code function: 4_2_01806A50 mov eax, dword ptr fs:[00000030h] 4_2_01806A50
Source: C:\Users\user\Desktop\SecuriteInfo.com.BackDoor.AgentTeslaNET.20.15021.21756.exe Code function: 4_2_01806A50 mov eax, dword ptr fs:[00000030h] 4_2_01806A50
Source: C:\Users\user\Desktop\SecuriteInfo.com.BackDoor.AgentTeslaNET.20.15021.21756.exe Code function: 4_2_01806A50 mov eax, dword ptr fs:[00000030h] 4_2_01806A50
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe Process token adjusted: Debug Jump to behavior
Source: C:\Users\user\Desktop\SecuriteInfo.com.BackDoor.AgentTeslaNET.20.15021.21756.exe Memory allocated: page read and write | page guard Jump to behavior

HIPS / PFW / Operating System Protection Evasion

barindex
Source: C:\Users\user\Desktop\SecuriteInfo.com.BackDoor.AgentTeslaNET.20.15021.21756.exe Process created: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe "C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe" Add-MpPreference -ExclusionPath "C:\Users\user\Desktop\SecuriteInfo.com.BackDoor.AgentTeslaNET.20.15021.21756.exe"
Source: C:\Users\user\Desktop\SecuriteInfo.com.BackDoor.AgentTeslaNET.20.15021.21756.exe Process created: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe "C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe" Add-MpPreference -ExclusionPath "C:\Users\user\Desktop\SecuriteInfo.com.BackDoor.AgentTeslaNET.20.15021.21756.exe" Jump to behavior
Source: C:\Users\user\Desktop\SecuriteInfo.com.BackDoor.AgentTeslaNET.20.15021.21756.exe Memory written: C:\Users\user\Desktop\SecuriteInfo.com.BackDoor.AgentTeslaNET.20.15021.21756.exe base: 400000 value starts with: 4D5A Jump to behavior
Source: C:\Users\user\Desktop\SecuriteInfo.com.BackDoor.AgentTeslaNET.20.15021.21756.exe Process created: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe "C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe" Add-MpPreference -ExclusionPath "C:\Users\user\Desktop\SecuriteInfo.com.BackDoor.AgentTeslaNET.20.15021.21756.exe" Jump to behavior
Source: C:\Users\user\Desktop\SecuriteInfo.com.BackDoor.AgentTeslaNET.20.15021.21756.exe Process created: C:\Users\user\Desktop\SecuriteInfo.com.BackDoor.AgentTeslaNET.20.15021.21756.exe "C:\Users\user\Desktop\SecuriteInfo.com.BackDoor.AgentTeslaNET.20.15021.21756.exe" Jump to behavior
Source: C:\Users\user\Desktop\SecuriteInfo.com.BackDoor.AgentTeslaNET.20.15021.21756.exe Queries volume information: C:\Users\user\Desktop\SecuriteInfo.com.BackDoor.AgentTeslaNET.20.15021.21756.exe VolumeInformation Jump to behavior
Source: C:\Users\user\Desktop\SecuriteInfo.com.BackDoor.AgentTeslaNET.20.15021.21756.exe Queries volume information: C:\Windows\Microsoft.NET\assembly\GAC_MSIL\System.Windows.Forms\v4.0_4.0.0.0__b77a5c561934e089\System.Windows.Forms.dll VolumeInformation Jump to behavior
Source: C:\Users\user\Desktop\SecuriteInfo.com.BackDoor.AgentTeslaNET.20.15021.21756.exe Queries volume information: C:\Windows\Microsoft.NET\assembly\GAC_MSIL\System.Drawing\v4.0_4.0.0.0__b03f5f7f11d50a3a\System.Drawing.dll VolumeInformation Jump to behavior
Source: C:\Users\user\Desktop\SecuriteInfo.com.BackDoor.AgentTeslaNET.20.15021.21756.exe Queries volume information: C:\Windows\Microsoft.NET\assembly\GAC_MSIL\Accessibility\v4.0_4.0.0.0__b03f5f7f11d50a3a\Accessibility.dll VolumeInformation Jump to behavior
Source: C:\Users\user\Desktop\SecuriteInfo.com.BackDoor.AgentTeslaNET.20.15021.21756.exe Queries volume information: C:\Windows\Fonts\bahnschrift.ttf VolumeInformation Jump to behavior
Source: C:\Users\user\Desktop\SecuriteInfo.com.BackDoor.AgentTeslaNET.20.15021.21756.exe Queries volume information: C:\Windows\Fonts\bahnschrift.ttf VolumeInformation Jump to behavior
Source: C:\Users\user\Desktop\SecuriteInfo.com.BackDoor.AgentTeslaNET.20.15021.21756.exe Queries volume information: C:\Windows\Fonts\bahnschrift.ttf VolumeInformation Jump to behavior
Source: C:\Users\user\Desktop\SecuriteInfo.com.BackDoor.AgentTeslaNET.20.15021.21756.exe Queries volume information: C:\Windows\Fonts\bahnschrift.ttf VolumeInformation Jump to behavior
Source: C:\Users\user\Desktop\SecuriteInfo.com.BackDoor.AgentTeslaNET.20.15021.21756.exe Queries volume information: C:\Windows\Fonts\bahnschrift.ttf VolumeInformation Jump to behavior
Source: C:\Users\user\Desktop\SecuriteInfo.com.BackDoor.AgentTeslaNET.20.15021.21756.exe Queries volume information: C:\Windows\Fonts\bahnschrift.ttf VolumeInformation Jump to behavior
Source: C:\Users\user\Desktop\SecuriteInfo.com.BackDoor.AgentTeslaNET.20.15021.21756.exe Queries volume information: C:\Windows\Fonts\bahnschrift.ttf VolumeInformation Jump to behavior
Source: C:\Users\user\Desktop\SecuriteInfo.com.BackDoor.AgentTeslaNET.20.15021.21756.exe Queries volume information: C:\Windows\Fonts\bahnschrift.ttf VolumeInformation Jump to behavior
Source: C:\Users\user\Desktop\SecuriteInfo.com.BackDoor.AgentTeslaNET.20.15021.21756.exe Queries volume information: C:\Windows\Fonts\bahnschrift.ttf VolumeInformation Jump to behavior
Source: C:\Users\user\Desktop\SecuriteInfo.com.BackDoor.AgentTeslaNET.20.15021.21756.exe Queries volume information: C:\Windows\Fonts\calibrii.ttf VolumeInformation Jump to behavior
Source: C:\Users\user\Desktop\SecuriteInfo.com.BackDoor.AgentTeslaNET.20.15021.21756.exe Queries volume information: C:\Windows\Fonts\calibrili.ttf VolumeInformation Jump to behavior
Source: C:\Users\user\Desktop\SecuriteInfo.com.BackDoor.AgentTeslaNET.20.15021.21756.exe Queries volume information: C:\Windows\Fonts\calibrib.ttf VolumeInformation Jump to behavior
Source: C:\Users\user\Desktop\SecuriteInfo.com.BackDoor.AgentTeslaNET.20.15021.21756.exe Queries volume information: C:\Windows\Fonts\cambria.ttc VolumeInformation Jump to behavior
Source: C:\Users\user\Desktop\SecuriteInfo.com.BackDoor.AgentTeslaNET.20.15021.21756.exe Queries volume information: C:\Windows\Fonts\cambriai.ttf VolumeInformation Jump to behavior
Source: C:\Users\user\Desktop\SecuriteInfo.com.BackDoor.AgentTeslaNET.20.15021.21756.exe Queries volume information: C:\Windows\Fonts\cambria.ttc VolumeInformation Jump to behavior
Source: C:\Users\user\Desktop\SecuriteInfo.com.BackDoor.AgentTeslaNET.20.15021.21756.exe Queries volume information: C:\Windows\Fonts\Candara.ttf VolumeInformation Jump to behavior
Source: C:\Users\user\Desktop\SecuriteInfo.com.BackDoor.AgentTeslaNET.20.15021.21756.exe Queries volume information: C:\Windows\Fonts\Candaral.ttf VolumeInformation Jump to behavior
Source: C:\Users\user\Desktop\SecuriteInfo.com.BackDoor.AgentTeslaNET.20.15021.21756.exe Queries volume information: C:\Windows\Fonts\Candarai.ttf VolumeInformation Jump to behavior
Source: C:\Users\user\Desktop\SecuriteInfo.com.BackDoor.AgentTeslaNET.20.15021.21756.exe Queries volume information: C:\Windows\Fonts\Candarali.ttf VolumeInformation Jump to behavior
Source: C:\Users\user\Desktop\SecuriteInfo.com.BackDoor.AgentTeslaNET.20.15021.21756.exe Queries volume information: C:\Windows\Fonts\Candarab.ttf VolumeInformation Jump to behavior
Source: C:\Users\user\Desktop\SecuriteInfo.com.BackDoor.AgentTeslaNET.20.15021.21756.exe Queries volume information: C:\Windows\Fonts\Candaraz.ttf VolumeInformation Jump to behavior
Source: C:\Users\user\Desktop\SecuriteInfo.com.BackDoor.AgentTeslaNET.20.15021.21756.exe Queries volume information: C:\Windows\Fonts\comic.ttf VolumeInformation Jump to behavior
Source: C:\Users\user\Desktop\SecuriteInfo.com.BackDoor.AgentTeslaNET.20.15021.21756.exe Queries volume information: C:\Windows\Fonts\comici.ttf VolumeInformation Jump to behavior
Source: C:\Users\user\Desktop\SecuriteInfo.com.BackDoor.AgentTeslaNET.20.15021.21756.exe Queries volume information: C:\Windows\Fonts\comicbd.ttf VolumeInformation Jump to behavior
Source: C:\Users\user\Desktop\SecuriteInfo.com.BackDoor.AgentTeslaNET.20.15021.21756.exe Queries volume information: C:\Windows\Fonts\comicz.ttf VolumeInformation Jump to behavior
Source: C:\Users\user\Desktop\SecuriteInfo.com.BackDoor.AgentTeslaNET.20.15021.21756.exe Queries volume information: C:\Windows\Fonts\constan.ttf VolumeInformation Jump to behavior
Source: C:\Users\user\Desktop\SecuriteInfo.com.BackDoor.AgentTeslaNET.20.15021.21756.exe Queries volume information: C:\Windows\Fonts\constani.ttf VolumeInformation Jump to behavior
Source: C:\Users\user\Desktop\SecuriteInfo.com.BackDoor.AgentTeslaNET.20.15021.21756.exe Queries volume information: C:\Windows\Fonts\constanb.ttf VolumeInformation Jump to behavior
Source: C:\Users\user\Desktop\SecuriteInfo.com.BackDoor.AgentTeslaNET.20.15021.21756.exe Queries volume information: C:\Windows\Fonts\constanz.ttf VolumeInformation Jump to behavior
Source: C:\Users\user\Desktop\SecuriteInfo.com.BackDoor.AgentTeslaNET.20.15021.21756.exe Queries volume information: C:\Windows\Fonts\corbel.ttf VolumeInformation Jump to behavior
Source: C:\Users\user\Desktop\SecuriteInfo.com.BackDoor.AgentTeslaNET.20.15021.21756.exe Queries volume information: C:\Windows\Fonts\corbell.ttf VolumeInformation Jump to behavior
Source: C:\Users\user\Desktop\SecuriteInfo.com.BackDoor.AgentTeslaNET.20.15021.21756.exe Queries volume information: C:\Windows\Fonts\corbeli.ttf VolumeInformation Jump to behavior
Source: C:\Users\user\Desktop\SecuriteInfo.com.BackDoor.AgentTeslaNET.20.15021.21756.exe Queries volume information: C:\Windows\Fonts\corbelli.ttf VolumeInformation Jump to behavior
Source: C:\Users\user\Desktop\SecuriteInfo.com.BackDoor.AgentTeslaNET.20.15021.21756.exe Queries volume information: C:\Windows\Fonts\corbelb.ttf VolumeInformation Jump to behavior
Source: C:\Users\user\Desktop\SecuriteInfo.com.BackDoor.AgentTeslaNET.20.15021.21756.exe Queries volume information: C:\Windows\Fonts\corbelz.ttf VolumeInformation Jump to behavior
Source: C:\Users\user\Desktop\SecuriteInfo.com.BackDoor.AgentTeslaNET.20.15021.21756.exe Queries volume information: C:\Windows\Fonts\cour.ttf VolumeInformation Jump to behavior
Source: C:\Users\user\Desktop\SecuriteInfo.com.BackDoor.AgentTeslaNET.20.15021.21756.exe Queries volume information: C:\Windows\Fonts\couri.ttf VolumeInformation Jump to behavior
Source: C:\Users\user\Desktop\SecuriteInfo.com.BackDoor.AgentTeslaNET.20.15021.21756.exe Queries volume information: C:\Windows\Fonts\courbd.ttf VolumeInformation Jump to behavior
Source: C:\Users\user\Desktop\SecuriteInfo.com.BackDoor.AgentTeslaNET.20.15021.21756.exe Queries volume information: C:\Windows\Fonts\courbi.ttf VolumeInformation Jump to behavior
Source: C:\Users\user\Desktop\SecuriteInfo.com.BackDoor.AgentTeslaNET.20.15021.21756.exe Queries volume information: C:\Windows\Fonts\ebrima.ttf VolumeInformation Jump to behavior
Source: C:\Users\user\Desktop\SecuriteInfo.com.BackDoor.AgentTeslaNET.20.15021.21756.exe Queries volume information: C:\Windows\Fonts\ebrimabd.ttf VolumeInformation Jump to behavior
Source: C:\Users\user\Desktop\SecuriteInfo.com.BackDoor.AgentTeslaNET.20.15021.21756.exe Queries volume information: C:\Windows\Fonts\framd.ttf VolumeInformation Jump to behavior
Source: C:\Users\user\Desktop\SecuriteInfo.com.BackDoor.AgentTeslaNET.20.15021.21756.exe Queries volume information: C:\Windows\Fonts\FRADM.TTF VolumeInformation Jump to behavior
Source: C:\Users\user\Desktop\SecuriteInfo.com.BackDoor.AgentTeslaNET.20.15021.21756.exe Queries volume information: C:\Windows\Fonts\FRADMIT.TTF VolumeInformation Jump to behavior
Source: C:\Users\user\Desktop\SecuriteInfo.com.BackDoor.AgentTeslaNET.20.15021.21756.exe Queries volume information: C:\Windows\Fonts\FRAMDCN.TTF VolumeInformation Jump to behavior
Source: C:\Users\user\Desktop\SecuriteInfo.com.BackDoor.AgentTeslaNET.20.15021.21756.exe Queries volume information: C:\Windows\Fonts\FRADMCN.TTF VolumeInformation Jump to behavior
Source: C:\Users\user\Desktop\SecuriteInfo.com.BackDoor.AgentTeslaNET.20.15021.21756.exe Queries volume information: C:\Windows\Fonts\gadugib.ttf VolumeInformation Jump to behavior
Source: C:\Users\user\Desktop\SecuriteInfo.com.BackDoor.AgentTeslaNET.20.15021.21756.exe Queries volume information: C:\Windows\Fonts\georgia.ttf VolumeInformation Jump to behavior
Source: C:\Users\user\Desktop\SecuriteInfo.com.BackDoor.AgentTeslaNET.20.15021.21756.exe Queries volume information: C:\Windows\Fonts\georgiai.ttf VolumeInformation Jump to behavior
Source: C:\Users\user\Desktop\SecuriteInfo.com.BackDoor.AgentTeslaNET.20.15021.21756.exe Queries volume information: C:\Windows\Fonts\georgiab.ttf VolumeInformation Jump to behavior
Source: C:\Users\user\Desktop\SecuriteInfo.com.BackDoor.AgentTeslaNET.20.15021.21756.exe Queries volume information: C:\Windows\Fonts\georgiaz.ttf VolumeInformation Jump to behavior
Source: C:\Users\user\Desktop\SecuriteInfo.com.BackDoor.AgentTeslaNET.20.15021.21756.exe Queries volume information: C:\Windows\Fonts\impact.ttf VolumeInformation Jump to behavior
Source: C:\Users\user\Desktop\SecuriteInfo.com.BackDoor.AgentTeslaNET.20.15021.21756.exe Queries volume information: C:\Windows\Fonts\Inkfree.ttf VolumeInformation Jump to behavior
Source: C:\Users\user\Desktop\SecuriteInfo.com.BackDoor.AgentTeslaNET.20.15021.21756.exe Queries volume information: C:\Windows\Fonts\javatext.ttf VolumeInformation Jump to behavior
Source: C:\Users\user\Desktop\SecuriteInfo.com.BackDoor.AgentTeslaNET.20.15021.21756.exe Queries volume information: C:\Windows\Fonts\LeelawUI.ttf VolumeInformation Jump to behavior
Source: C:\Users\user\Desktop\SecuriteInfo.com.BackDoor.AgentTeslaNET.20.15021.21756.exe Queries volume information: C:\Windows\Fonts\LeelUIsl.ttf VolumeInformation Jump to behavior
Source: C:\Users\user\Desktop\SecuriteInfo.com.BackDoor.AgentTeslaNET.20.15021.21756.exe Queries volume information: C:\Windows\Fonts\LeelaUIb.ttf VolumeInformation Jump to behavior
Source: C:\Users\user\Desktop\SecuriteInfo.com.BackDoor.AgentTeslaNET.20.15021.21756.exe Queries volume information: C:\Windows\Fonts\lucon.ttf VolumeInformation Jump to behavior
Source: C:\Users\user\Desktop\SecuriteInfo.com.BackDoor.AgentTeslaNET.20.15021.21756.exe Queries volume information: C:\Windows\Fonts\l_10646.ttf VolumeInformation Jump to behavior
Source: C:\Users\user\Desktop\SecuriteInfo.com.BackDoor.AgentTeslaNET.20.15021.21756.exe Queries volume information: C:\Windows\Fonts\malgun.ttf VolumeInformation Jump to behavior
Source: C:\Users\user\Desktop\SecuriteInfo.com.BackDoor.AgentTeslaNET.20.15021.21756.exe Queries volume information: C:\Windows\Fonts\malgunsl.ttf VolumeInformation Jump to behavior
Source: C:\Users\user\Desktop\SecuriteInfo.com.BackDoor.AgentTeslaNET.20.15021.21756.exe Queries volume information: C:\Windows\Fonts\malgunbd.ttf VolumeInformation Jump to behavior
Source: C:\Users\user\Desktop\SecuriteInfo.com.BackDoor.AgentTeslaNET.20.15021.21756.exe Queries volume information: C:\Windows\Fonts\himalaya.ttf VolumeInformation Jump to behavior
Source: C:\Users\user\Desktop\SecuriteInfo.com.BackDoor.AgentTeslaNET.20.15021.21756.exe Queries volume information: C:\Windows\Fonts\msjh.ttc VolumeInformation Jump to behavior
Source: C:\Users\user\Desktop\SecuriteInfo.com.BackDoor.AgentTeslaNET.20.15021.21756.exe Queries volume information: C:\Windows\Fonts\msjhl.ttc VolumeInformation Jump to behavior
Source: C:\Users\user\Desktop\SecuriteInfo.com.BackDoor.AgentTeslaNET.20.15021.21756.exe Queries volume information: C:\Windows\Fonts\msjhbd.ttc VolumeInformation Jump to behavior
Source: C:\Users\user\Desktop\SecuriteInfo.com.BackDoor.AgentTeslaNET.20.15021.21756.exe Queries volume information: C:\Windows\Fonts\msjh.ttc VolumeInformation Jump to behavior
Source: C:\Users\user\Desktop\SecuriteInfo.com.BackDoor.AgentTeslaNET.20.15021.21756.exe Queries volume information: C:\Windows\Fonts\msjhl.ttc VolumeInformation Jump to behavior
Source: C:\Users\user\Desktop\SecuriteInfo.com.BackDoor.AgentTeslaNET.20.15021.21756.exe Queries volume information: C:\Windows\Fonts\ntailu.ttf VolumeInformation Jump to behavior
Source: C:\Users\user\Desktop\SecuriteInfo.com.BackDoor.AgentTeslaNET.20.15021.21756.exe Queries volume information: C:\Windows\Fonts\ntailub.ttf VolumeInformation Jump to behavior
Source: C:\Users\user\Desktop\SecuriteInfo.com.BackDoor.AgentTeslaNET.20.15021.21756.exe Queries volume information: C:\Windows\Fonts\phagspa.ttf VolumeInformation Jump to behavior
Source: C:\Users\user\Desktop\SecuriteInfo.com.BackDoor.AgentTeslaNET.20.15021.21756.exe Queries volume information: C:\Windows\Fonts\phagspab.ttf VolumeInformation Jump to behavior
Source: C:\Users\user\Desktop\SecuriteInfo.com.BackDoor.AgentTeslaNET.20.15021.21756.exe Queries volume information: C:\Windows\Fonts\micross.ttf VolumeInformation Jump to behavior
Source: C:\Users\user\Desktop\SecuriteInfo.com.BackDoor.AgentTeslaNET.20.15021.21756.exe Queries volume information: C:\Windows\Fonts\taile.ttf VolumeInformation Jump to behavior
Source: C:\Users\user\Desktop\SecuriteInfo.com.BackDoor.AgentTeslaNET.20.15021.21756.exe Queries volume information: C:\Windows\Fonts\taileb.ttf VolumeInformation Jump to behavior
Source: C:\Users\user\Desktop\SecuriteInfo.com.BackDoor.AgentTeslaNET.20.15021.21756.exe Queries volume information: C:\Windows\Fonts\msyh.ttc VolumeInformation Jump to behavior
Source: C:\Users\user\Desktop\SecuriteInfo.com.BackDoor.AgentTeslaNET.20.15021.21756.exe Queries volume information: C:\Windows\Fonts\msyhl.ttc VolumeInformation Jump to behavior
Source: C:\Users\user\Desktop\SecuriteInfo.com.BackDoor.AgentTeslaNET.20.15021.21756.exe Queries volume information: C:\Windows\Fonts\msyhbd.ttc VolumeInformation Jump to behavior
Source: C:\Users\user\Desktop\SecuriteInfo.com.BackDoor.AgentTeslaNET.20.15021.21756.exe Queries volume information: C:\Windows\Fonts\msyh.ttc VolumeInformation Jump to behavior
Source: C:\Users\user\Desktop\SecuriteInfo.com.BackDoor.AgentTeslaNET.20.15021.21756.exe Queries volume information: C:\Windows\Fonts\msyhl.ttc VolumeInformation Jump to behavior
Source: C:\Users\user\Desktop\SecuriteInfo.com.BackDoor.AgentTeslaNET.20.15021.21756.exe Queries volume information: C:\Windows\Fonts\msyi.ttf VolumeInformation Jump to behavior
Source: C:\Users\user\Desktop\SecuriteInfo.com.BackDoor.AgentTeslaNET.20.15021.21756.exe Queries volume information: C:\Windows\Fonts\mingliub.ttc VolumeInformation Jump to behavior
Source: C:\Users\user\Desktop\SecuriteInfo.com.BackDoor.AgentTeslaNET.20.15021.21756.exe Queries volume information: C:\Windows\Fonts\mingliub.ttc VolumeInformation Jump to behavior
Source: C:\Users\user\Desktop\SecuriteInfo.com.BackDoor.AgentTeslaNET.20.15021.21756.exe Queries volume information: C:\Windows\Fonts\mingliub.ttc VolumeInformation Jump to behavior
Source: C:\Users\user\Desktop\SecuriteInfo.com.BackDoor.AgentTeslaNET.20.15021.21756.exe Queries volume information: C:\Windows\Fonts\msgothic.ttc VolumeInformation Jump to behavior
Source: C:\Users\user\Desktop\SecuriteInfo.com.BackDoor.AgentTeslaNET.20.15021.21756.exe Queries volume information: C:\Windows\Fonts\msgothic.ttc VolumeInformation Jump to behavior
Source: C:\Users\user\Desktop\SecuriteInfo.com.BackDoor.AgentTeslaNET.20.15021.21756.exe Queries volume information: C:\Windows\Fonts\msgothic.ttc VolumeInformation Jump to behavior
Source: C:\Users\user\Desktop\SecuriteInfo.com.BackDoor.AgentTeslaNET.20.15021.21756.exe Queries volume information: C:\Windows\Fonts\mvboli.ttf VolumeInformation Jump to behavior
Source: C:\Users\user\Desktop\SecuriteInfo.com.BackDoor.AgentTeslaNET.20.15021.21756.exe Queries volume information: C:\Windows\Fonts\mmrtext.ttf VolumeInformation Jump to behavior
Source: C:\Users\user\Desktop\SecuriteInfo.com.BackDoor.AgentTeslaNET.20.15021.21756.exe Queries volume information: C:\Windows\Fonts\mmrtextb.ttf VolumeInformation Jump to behavior
Source: C:\Users\user\Desktop\SecuriteInfo.com.BackDoor.AgentTeslaNET.20.15021.21756.exe Queries volume information: C:\Windows\Fonts\Nirmala.ttf VolumeInformation Jump to behavior
Source: C:\Users\user\Desktop\SecuriteInfo.com.BackDoor.AgentTeslaNET.20.15021.21756.exe Queries volume information: C:\Windows\Fonts\NirmalaS.ttf VolumeInformation Jump to behavior
Source: C:\Users\user\Desktop\SecuriteInfo.com.BackDoor.AgentTeslaNET.20.15021.21756.exe Queries volume information: C:\Windows\Fonts\NirmalaB.ttf VolumeInformation Jump to behavior
Source: C:\Users\user\Desktop\SecuriteInfo.com.BackDoor.AgentTeslaNET.20.15021.21756.exe Queries volume information: C:\Windows\Fonts\pala.ttf VolumeInformation Jump to behavior
Source: C:\Users\user\Desktop\SecuriteInfo.com.BackDoor.AgentTeslaNET.20.15021.21756.exe Queries volume information: C:\Windows\Fonts\palai.ttf VolumeInformation Jump to behavior
Source: C:\Users\user\Desktop\SecuriteInfo.com.BackDoor.AgentTeslaNET.20.15021.21756.exe Queries volume information: C:\Windows\Fonts\palab.ttf VolumeInformation Jump to behavior
Source: C:\Users\user\Desktop\SecuriteInfo.com.BackDoor.AgentTeslaNET.20.15021.21756.exe Queries volume information: C:\Windows\Fonts\palabi.ttf VolumeInformation Jump to behavior
Source: C:\Users\user\Desktop\SecuriteInfo.com.BackDoor.AgentTeslaNET.20.15021.21756.exe Queries volume information: C:\Windows\Fonts\segoepr.ttf VolumeInformation Jump to behavior
Source: C:\Users\user\Desktop\SecuriteInfo.com.BackDoor.AgentTeslaNET.20.15021.21756.exe Queries volume information: C:\Windows\Fonts\segoeprb.ttf VolumeInformation Jump to behavior
Source: C:\Users\user\Desktop\SecuriteInfo.com.BackDoor.AgentTeslaNET.20.15021.21756.exe Queries volume information: C:\Windows\Fonts\segoesc.ttf VolumeInformation Jump to behavior
Source: C:\Users\user\Desktop\SecuriteInfo.com.BackDoor.AgentTeslaNET.20.15021.21756.exe Queries volume information: C:\Windows\Fonts\segoescb.ttf VolumeInformation Jump to behavior
Source: C:\Users\user\Desktop\SecuriteInfo.com.BackDoor.AgentTeslaNET.20.15021.21756.exe Queries volume information: C:\Windows\Fonts\seguihis.ttf VolumeInformation Jump to behavior
Source: C:\Users\user\Desktop\SecuriteInfo.com.BackDoor.AgentTeslaNET.20.15021.21756.exe Queries volume information: C:\Windows\Fonts\simsun.ttc VolumeInformation Jump to behavior
Source: C:\Users\user\Desktop\SecuriteInfo.com.BackDoor.AgentTeslaNET.20.15021.21756.exe Queries volume information: C:\Windows\Fonts\simsunb.ttf VolumeInformation Jump to behavior
Source: C:\Users\user\Desktop\SecuriteInfo.com.BackDoor.AgentTeslaNET.20.15021.21756.exe Queries volume information: C:\Windows\Fonts\Sitka.ttc VolumeInformation Jump to behavior
Source: C:\Users\user\Desktop\SecuriteInfo.com.BackDoor.AgentTeslaNET.20.15021.21756.exe Queries volume information: C:\Windows\Fonts\SitkaI.ttc VolumeInformation Jump to behavior
Source: C:\Users\user\Desktop\SecuriteInfo.com.BackDoor.AgentTeslaNET.20.15021.21756.exe Queries volume information: C:\Windows\Fonts\SitkaB.ttc VolumeInformation Jump to behavior
Source: C:\Users\user\Desktop\SecuriteInfo.com.BackDoor.AgentTeslaNET.20.15021.21756.exe Queries volume information: C:\Windows\Fonts\SitkaZ.ttc VolumeInformation Jump to behavior
Source: C:\Users\user\Desktop\SecuriteInfo.com.BackDoor.AgentTeslaNET.20.15021.21756.exe Queries volume information: C:\Windows\Fonts\Sitka.ttc VolumeInformation Jump to behavior
Source: C:\Users\user\Desktop\SecuriteInfo.com.BackDoor.AgentTeslaNET.20.15021.21756.exe Queries volume information: C:\Windows\Fonts\SitkaI.ttc VolumeInformation Jump to behavior
Source: C:\Users\user\Desktop\SecuriteInfo.com.BackDoor.AgentTeslaNET.20.15021.21756.exe Queries volume information: C:\Windows\Fonts\sylfaen.ttf VolumeInformation Jump to behavior
Source: C:\Users\user\Desktop\SecuriteInfo.com.BackDoor.AgentTeslaNET.20.15021.21756.exe Queries volume information: C:\Windows\Fonts\symbol.ttf VolumeInformation Jump to behavior
Source: C:\Users\user\Desktop\SecuriteInfo.com.BackDoor.AgentTeslaNET.20.15021.21756.exe Queries volume information: C:\Windows\Fonts\tahoma.ttf VolumeInformation Jump to behavior
Source: C:\Users\user\Desktop\SecuriteInfo.com.BackDoor.AgentTeslaNET.20.15021.21756.exe Queries volume information: C:\Windows\Fonts\tahomabd.ttf VolumeInformation Jump to behavior
Source: C:\Users\user\Desktop\SecuriteInfo.com.BackDoor.AgentTeslaNET.20.15021.21756.exe Queries volume information: C:\Windows\Fonts\timesi.ttf VolumeInformation Jump to behavior
Source: C:\Users\user\Desktop\SecuriteInfo.com.BackDoor.AgentTeslaNET.20.15021.21756.exe Queries volume information: C:\Windows\Fonts\timesbi.ttf VolumeInformation Jump to behavior
Source: C:\Users\user\Desktop\SecuriteInfo.com.BackDoor.AgentTeslaNET.20.15021.21756.exe Queries volume information: C:\Windows\Fonts\trebuc.ttf VolumeInformation Jump to behavior
Source: C:\Users\user\Desktop\SecuriteInfo.com.BackDoor.AgentTeslaNET.20.15021.21756.exe Queries volume information: C:\Windows\Fonts\trebucit.ttf VolumeInformation Jump to behavior
Source: C:\Users\user\Desktop\SecuriteInfo.com.BackDoor.AgentTeslaNET.20.15021.21756.exe Queries volume information: C:\Windows\Fonts\trebucbd.ttf VolumeInformation Jump to behavior
Source: C:\Users\user\Desktop\SecuriteInfo.com.BackDoor.AgentTeslaNET.20.15021.21756.exe Queries volume information: C:\Windows\Fonts\trebucbi.ttf VolumeInformation Jump to behavior
Source: C:\Users\user\Desktop\SecuriteInfo.com.BackDoor.AgentTeslaNET.20.15021.21756.exe Queries volume information: C:\Windows\Fonts\verdana.ttf VolumeInformation Jump to behavior
Source: C:\Users\user\Desktop\SecuriteInfo.com.BackDoor.AgentTeslaNET.20.15021.21756.exe Queries volume information: C:\Windows\Fonts\verdanai.ttf VolumeInformation Jump to behavior
Source: C:\Users\user\Desktop\SecuriteInfo.com.BackDoor.AgentTeslaNET.20.15021.21756.exe Queries volume information: C:\Windows\Fonts\verdanab.ttf VolumeInformation Jump to behavior
Source: C:\Users\user\Desktop\SecuriteInfo.com.BackDoor.AgentTeslaNET.20.15021.21756.exe Queries volume information: C:\Windows\Fonts\verdanaz.ttf VolumeInformation Jump to behavior
Source: C:\Users\user\Desktop\SecuriteInfo.com.BackDoor.AgentTeslaNET.20.15021.21756.exe Queries volume information: C:\Windows\Fonts\webdings.ttf VolumeInformation Jump to behavior
Source: C:\Users\user\Desktop\SecuriteInfo.com.BackDoor.AgentTeslaNET.20.15021.21756.exe Queries volume information: C:\Windows\Fonts\wingding.ttf VolumeInformation Jump to behavior
Source: C:\Users\user\Desktop\SecuriteInfo.com.BackDoor.AgentTeslaNET.20.15021.21756.exe Queries volume information: C:\Windows\Fonts\YuGothR.ttc VolumeInformation Jump to behavior
Source: C:\Users\user\Desktop\SecuriteInfo.com.BackDoor.AgentTeslaNET.20.15021.21756.exe Queries volume information: C:\Windows\Fonts\YuGothM.ttc VolumeInformation Jump to behavior
Source: C:\Users\user\Desktop\SecuriteInfo.com.BackDoor.AgentTeslaNET.20.15021.21756.exe Queries volume information: C:\Windows\Fonts\YuGothL.ttc VolumeInformation Jump to behavior
Source: C:\Users\user\Desktop\SecuriteInfo.com.BackDoor.AgentTeslaNET.20.15021.21756.exe Queries volume information: C:\Windows\Fonts\YuGothB.ttc VolumeInformation Jump to behavior
Source: C:\Users\user\Desktop\SecuriteInfo.com.BackDoor.AgentTeslaNET.20.15021.21756.exe Queries volume information: C:\Windows\Fonts\YuGothM.ttc VolumeInformation Jump to behavior
Source: C:\Users\user\Desktop\SecuriteInfo.com.BackDoor.AgentTeslaNET.20.15021.21756.exe Queries volume information: C:\Windows\Fonts\YuGothR.ttc VolumeInformation Jump to behavior
Source: C:\Users\user\Desktop\SecuriteInfo.com.BackDoor.AgentTeslaNET.20.15021.21756.exe Queries volume information: C:\Windows\Fonts\YuGothB.ttc VolumeInformation Jump to behavior
Source: C:\Users\user\Desktop\SecuriteInfo.com.BackDoor.AgentTeslaNET.20.15021.21756.exe Queries volume information: C:\Windows\Fonts\YuGothB.ttc VolumeInformation Jump to behavior
Source: C:\Users\user\Desktop\SecuriteInfo.com.BackDoor.AgentTeslaNET.20.15021.21756.exe Queries volume information: C:\Windows\Fonts\holomdl2.ttf VolumeInformation Jump to behavior
Source: C:\Users\user\Desktop\SecuriteInfo.com.BackDoor.AgentTeslaNET.20.15021.21756.exe Queries volume information: C:\Windows\Fonts\AGENCYR.TTF VolumeInformation Jump to behavior
Source: C:\Users\user\Desktop\SecuriteInfo.com.BackDoor.AgentTeslaNET.20.15021.21756.exe Queries volume information: C:\Windows\Fonts\ANTQUAB.TTF VolumeInformation Jump to behavior
Source: C:\Users\user\Desktop\SecuriteInfo.com.BackDoor.AgentTeslaNET.20.15021.21756.exe Queries volume information: C:\Windows\Fonts\ARLRDBD.TTF VolumeInformation Jump to behavior
Source: C:\Users\user\Desktop\SecuriteInfo.com.BackDoor.AgentTeslaNET.20.15021.21756.exe Queries volume information: C:\Windows\Fonts\BAUHS93.TTF VolumeInformation Jump to behavior
Source: C:\Users\user\Desktop\SecuriteInfo.com.BackDoor.AgentTeslaNET.20.15021.21756.exe Queries volume information: C:\Windows\Fonts\BELL.TTF VolumeInformation Jump to behavior
Source: C:\Users\user\Desktop\SecuriteInfo.com.BackDoor.AgentTeslaNET.20.15021.21756.exe Queries volume information: C:\Windows\Fonts\BOD_I.TTF VolumeInformation Jump to behavior
Source: C:\Users\user\Desktop\SecuriteInfo.com.BackDoor.AgentTeslaNET.20.15021.21756.exe Queries volume information: C:\Windows\Fonts\BOOKOSB.TTF VolumeInformation Jump to behavior
Source: C:\Users\user\Desktop\SecuriteInfo.com.BackDoor.AgentTeslaNET.20.15021.21756.exe Queries volume information: C:\Windows\Fonts\BRADHITC.TTF VolumeInformation Jump to behavior
Source: C:\Users\user\Desktop\SecuriteInfo.com.BackDoor.AgentTeslaNET.20.15021.21756.exe Queries volume information: C:\Windows\Fonts\SCHLBKB.TTF VolumeInformation Jump to behavior
Source: C:\Users\user\Desktop\SecuriteInfo.com.BackDoor.AgentTeslaNET.20.15021.21756.exe Queries volume information: C:\Windows\Fonts\SCHLBKBI.TTF VolumeInformation Jump to behavior
Source: C:\Users\user\Desktop\SecuriteInfo.com.BackDoor.AgentTeslaNET.20.15021.21756.exe Queries volume information: C:\Windows\Fonts\CENTAUR.TTF VolumeInformation Jump to behavior
Source: C:\Users\user\Desktop\SecuriteInfo.com.BackDoor.AgentTeslaNET.20.15021.21756.exe Queries volume information: C:\Windows\Fonts\CHILLER.TTF VolumeInformation Jump to behavior
Source: C:\Users\user\Desktop\SecuriteInfo.com.BackDoor.AgentTeslaNET.20.15021.21756.exe Queries volume information: C:\Windows\Fonts\COLONNA.TTF VolumeInformation Jump to behavior
Source: C:\Users\user\Desktop\SecuriteInfo.com.BackDoor.AgentTeslaNET.20.15021.21756.exe Queries volume information: C:\Windows\Fonts\COOPBL.TTF VolumeInformation Jump to behavior
Source: C:\Users\user\Desktop\SecuriteInfo.com.BackDoor.AgentTeslaNET.20.15021.21756.exe Queries volume information: C:\Windows\Fonts\COPRGTB.TTF VolumeInformation Jump to behavior
Source: C:\Users\user\Desktop\SecuriteInfo.com.BackDoor.AgentTeslaNET.20.15021.21756.exe Queries volume information: C:\Windows\Fonts\DUBAI-LIGHT.TTF VolumeInformation Jump to behavior
Source: C:\Users\user\Desktop\SecuriteInfo.com.BackDoor.AgentTeslaNET.20.15021.21756.exe Queries volume information: C:\Windows\Fonts\ERASLGHT.TTF VolumeInformation Jump to behavior
Source: C:\Users\user\Desktop\SecuriteInfo.com.BackDoor.AgentTeslaNET.20.15021.21756.exe Queries volume information: C:\Windows\Fonts\FRABK.TTF VolumeInformation Jump to behavior
Source: C:\Users\user\Desktop\SecuriteInfo.com.BackDoor.AgentTeslaNET.20.15021.21756.exe Queries volume information: C:\Windows\Fonts\GIGI.TTF VolumeInformation Jump to behavior
Source: C:\Users\user\Desktop\SecuriteInfo.com.BackDoor.AgentTeslaNET.20.15021.21756.exe Queries volume information: C:\Windows\Fonts\GILC____.TTF VolumeInformation Jump to behavior
Source: C:\Users\user\Desktop\SecuriteInfo.com.BackDoor.AgentTeslaNET.20.15021.21756.exe Queries volume information: C:\Windows\Fonts\GOTHIC.TTF VolumeInformation Jump to behavior
Source: C:\Users\user\Desktop\SecuriteInfo.com.BackDoor.AgentTeslaNET.20.15021.21756.exe Queries volume information: C:\Windows\Fonts\GOTHICB.TTF VolumeInformation Jump to behavior
Source: C:\Users\user\Desktop\SecuriteInfo.com.BackDoor.AgentTeslaNET.20.15021.21756.exe Queries volume information: C:\Windows\Fonts\GOUDOSI.TTF VolumeInformation Jump to behavior
Source: C:\Users\user\Desktop\SecuriteInfo.com.BackDoor.AgentTeslaNET.20.15021.21756.exe Queries volume information: C:\Windows\Fonts\HATTEN.TTF VolumeInformation Jump to behavior
Source: C:\Users\user\Desktop\SecuriteInfo.com.BackDoor.AgentTeslaNET.20.15021.21756.exe Queries volume information: C:\Windows\Fonts\ITCBLKAD.TTF VolumeInformation Jump to behavior
Source: C:\Users\user\Desktop\SecuriteInfo.com.BackDoor.AgentTeslaNET.20.15021.21756.exe Queries volume information: C:\Windows\Fonts\ITCEDSCR.TTF VolumeInformation Jump to behavior
Source: C:\Users\user\Desktop\SecuriteInfo.com.BackDoor.AgentTeslaNET.20.15021.21756.exe Queries volume information: C:\Windows\Fonts\ITCKRIST.TTF VolumeInformation Jump to behavior
Source: C:\Users\user\Desktop\SecuriteInfo.com.BackDoor.AgentTeslaNET.20.15021.21756.exe Queries volume information: C:\Windows\Fonts\JOKERMAN.TTF VolumeInformation Jump to behavior
Source: C:\Users\user\Desktop\SecuriteInfo.com.BackDoor.AgentTeslaNET.20.15021.21756.exe Queries volume information: C:\Windows\Fonts\KUNSTLER.TTF VolumeInformation Jump to behavior
Source: C:\Users\user\Desktop\SecuriteInfo.com.BackDoor.AgentTeslaNET.20.15021.21756.exe Queries volume information: C:\Windows\Fonts\LFAXDI.TTF VolumeInformation Jump to behavior
Source: C:\Users\user\Desktop\SecuriteInfo.com.BackDoor.AgentTeslaNET.20.15021.21756.exe Queries volume information: C:\Windows\Fonts\LSANSD.TTF VolumeInformation Jump to behavior
Source: C:\Users\user\Desktop\SecuriteInfo.com.BackDoor.AgentTeslaNET.20.15021.21756.exe Queries volume information: C:\Windows\Fonts\LSANSDI.TTF VolumeInformation Jump to behavior
Source: C:\Users\user\Desktop\SecuriteInfo.com.BackDoor.AgentTeslaNET.20.15021.21756.exe Queries volume information: C:\Windows\Fonts\MAIAN.TTF VolumeInformation Jump to behavior
Source: C:\Users\user\Desktop\SecuriteInfo.com.BackDoor.AgentTeslaNET.20.15021.21756.exe Queries volume information: C:\Windows\Fonts\MISTRAL.TTF VolumeInformation Jump to behavior
Source: C:\Users\user\Desktop\SecuriteInfo.com.BackDoor.AgentTeslaNET.20.15021.21756.exe Queries volume information: C:\Windows\Fonts\MOD20.TTF VolumeInformation Jump to behavior
Source: C:\Users\user\Desktop\SecuriteInfo.com.BackDoor.AgentTeslaNET.20.15021.21756.exe Queries volume information: C:\Windows\Fonts\MSUIGHUB.TTF VolumeInformation Jump to behavior
Source: C:\Users\user\Desktop\SecuriteInfo.com.BackDoor.AgentTeslaNET.20.15021.21756.exe Queries volume information: C:\Windows\Fonts\MTCORSVA.TTF VolumeInformation Jump to behavior
Source: C:\Users\user\Desktop\SecuriteInfo.com.BackDoor.AgentTeslaNET.20.15021.21756.exe Queries volume information: C:\Windows\Fonts\NIAGENG.TTF VolumeInformation Jump to behavior
Source: C:\Users\user\Desktop\SecuriteInfo.com.BackDoor.AgentTeslaNET.20.15021.21756.exe Queries volume information: C:\Windows\Fonts\PAPYRUS.TTF VolumeInformation Jump to behavior
Source: C:\Users\user\Desktop\SecuriteInfo.com.BackDoor.AgentTeslaNET.20.15021.21756.exe Queries volume information: C:\Windows\Fonts\PERB____.TTF VolumeInformation Jump to behavior
Source: C:\Users\user\Desktop\SecuriteInfo.com.BackDoor.AgentTeslaNET.20.15021.21756.exe Queries volume information: C:\Windows\Fonts\PLAYBILL.TTF VolumeInformation Jump to behavior
Source: C:\Users\user\Desktop\SecuriteInfo.com.BackDoor.AgentTeslaNET.20.15021.21756.exe Queries volume information: C:\Windows\Fonts\PRISTINA.TTF VolumeInformation Jump to behavior
Source: C:\Users\user\Desktop\SecuriteInfo.com.BackDoor.AgentTeslaNET.20.15021.21756.exe Queries volume information: C:\Windows\Fonts\OFFSYM.TTF VolumeInformation Jump to behavior
Source: C:\Users\user\Desktop\SecuriteInfo.com.BackDoor.AgentTeslaNET.20.15021.21756.exe Queries volume information: C:\Windows\Fonts\OFFSYML.TTF VolumeInformation Jump to behavior
Source: C:\Users\user\Desktop\SecuriteInfo.com.BackDoor.AgentTeslaNET.20.15021.21756.exe Queries volume information: C:\Windows\Fonts\micross.ttf VolumeInformation Jump to behavior
Source: C:\Users\user\Desktop\SecuriteInfo.com.BackDoor.AgentTeslaNET.20.15021.21756.exe Queries volume information: C:\Windows\Microsoft.NET\assembly\GAC_MSIL\Microsoft.VisualBasic\v4.0_10.0.0.0__b03f5f7f11d50a3a\Microsoft.VisualBasic.dll VolumeInformation Jump to behavior
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe Queries volume information: C:\Windows\System32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-Client-Features-Package0313~31bf3856ad364e35~amd64~~10.0.19041.1949.cat VolumeInformation Jump to behavior
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe Queries volume information: C:\Windows\Microsoft.NET\assembly\GAC_32\System.Data\v4.0_4.0.0.0__b77a5c561934e089\System.Data.dll VolumeInformation Jump to behavior
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe Queries volume information: C:\Windows\Microsoft.NET\assembly\GAC_32\System.Transactions\v4.0_4.0.0.0__b77a5c561934e089\System.Transactions.dll VolumeInformation Jump to behavior
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe Queries volume information: C:\ VolumeInformation Jump to behavior
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe Queries volume information: C:\Windows\System32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-Client-Features-Package0313~31bf3856ad364e35~amd64~~10.0.19041.1949.cat VolumeInformation Jump to behavior
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe Queries volume information: C:\Windows\System32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-Client-Features-Package0313~31bf3856ad364e35~amd64~~10.0.19041.1949.cat VolumeInformation Jump to behavior
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe Queries volume information: C:\Windows\System32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-GroupPolicy-ClientTools-WOW64-Package~31bf3856ad364e35~amd64~~10.0.19041.1949.cat VolumeInformation Jump to behavior
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe Queries volume information: C:\Windows\System32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-AppManagement-AppV-WOW64-Package~31bf3856ad364e35~amd64~~10.0.19041.1949.cat VolumeInformation Jump to behavior
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe Queries volume information: C:\Windows\Microsoft.NET\assembly\GAC_32\Microsoft.Management.Infrastructure.Native\v4.0_1.0.0.0__31bf3856ad364e35\Microsoft.Management.Infrastructure.Native.dll VolumeInformation Jump to behavior
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe Queries volume information: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\Modules\AppvClient\Microsoft.AppV.AppVClientPowerShell.dll VolumeInformation Jump to behavior
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe Queries volume information: C:\Windows\Microsoft.NET\assembly\GAC_32\Microsoft.AppV.AppvClientComConsumer\v4.0_10.0.0.0__31bf3856ad364e35\Microsoft.AppV.AppvClientComConsumer.dll VolumeInformation Jump to behavior
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe Queries volume information: C:\Windows\System32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-SecureStartup-Subsystem-WOW64-Package~31bf3856ad364e35~amd64~~10.0.19041.1865.cat VolumeInformation Jump to behavior
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe Queries volume information: C:\Windows\System32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-SecureStartup-Subsystem-WOW64-Package~31bf3856ad364e35~amd64~en-GB~10.0.19041.1.cat VolumeInformation Jump to behavior
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe Queries volume information: C:\Windows\System32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-Client-Features-Package0313~31bf3856ad364e35~amd64~~10.0.19041.1949.cat VolumeInformation Jump to behavior
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe Queries volume information: C:\Windows\System32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-Client-Features-Package0313~31bf3856ad364e35~amd64~~10.0.19041.1949.cat VolumeInformation Jump to behavior
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe Queries volume information: C:\Windows\System32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-Client-Features-Package0313~31bf3856ad364e35~amd64~~10.0.19041.1949.cat VolumeInformation Jump to behavior
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe Queries volume information: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\Modules\BitLocker\Microsoft.BitLocker.Structures.dll VolumeInformation Jump to behavior
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe Queries volume information: C:\Windows\System32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-Client-Desktop-Required-WOW64-Package~31bf3856ad364e35~amd64~~10.0.19041.2006.cat VolumeInformation Jump to behavior
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe Queries volume information: C:\Windows\System32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-Client-Desktop-Required-WOW64-Package~31bf3856ad364e35~amd64~~10.0.19041.2006.cat VolumeInformation Jump to behavior
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe Queries volume information: C:\Windows\Microsoft.NET\assembly\GAC_MSIL\Microsoft.PowerShell.Commands.Management\v4.0_3.0.0.0__31bf3856ad364e35\Microsoft.PowerShell.Commands.Management.dll VolumeInformation Jump to behavior
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe Queries volume information: C:\Windows\System32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-Client-Desktop-Required-WOW64-Package~31bf3856ad364e35~amd64~~10.0.19041.2006.cat VolumeInformation Jump to behavior
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe Queries volume information: C:\Windows\System32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-Client-Desktop-Required-WOW64-Package~31bf3856ad364e35~amd64~~10.0.19041.2006.cat VolumeInformation Jump to behavior
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe Queries volume information: C:\Windows\System32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-Client-Desktop-Required-WOW64-Package~31bf3856ad364e35~amd64~~10.0.19041.2006.cat VolumeInformation Jump to behavior
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe Queries volume information: C:\Windows\System32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-Client-Desktop-Required-WOW64-Package~31bf3856ad364e35~amd64~~10.0.19041.2006.cat VolumeInformation Jump to behavior
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe Queries volume information: C:\Windows\System32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-Client-Desktop-Required-WOW64-Package~31bf3856ad364e35~amd64~~10.0.19041.2006.cat VolumeInformation Jump to behavior
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe Queries volume information: C:\Windows\System32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-Client-Desktop-Required-WOW64-Package~31bf3856ad364e35~amd64~~10.0.19041.2006.cat VolumeInformation Jump to behavior
Source: C:\Users\user\Desktop\SecuriteInfo.com.BackDoor.AgentTeslaNET.20.15021.21756.exe Key value queried: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Cryptography MachineGuid Jump to behavior
Source: Amcache.hve.11.dr Binary or memory string: c:\programdata\microsoft\windows defender\platform\4.18.23080.2006-0\msmpeng.exe
Source: Amcache.hve.11.dr Binary or memory string: msmpeng.exe
Source: Amcache.hve.11.dr Binary or memory string: c:\program files\windows defender\msmpeng.exe
Source: Amcache.hve.11.dr Binary or memory string: MsMpEng.exe

Stealing of Sensitive Information

barindex
Source: Yara match File source: 4.2.SecuriteInfo.com.BackDoor.AgentTeslaNET.20.15021.21756.exe.400000.0.unpack, type: UNPACKEDPE
Source: Yara match File source: 4.2.SecuriteInfo.com.BackDoor.AgentTeslaNET.20.15021.21756.exe.400000.0.raw.unpack, type: UNPACKEDPE
Source: Yara match File source: 00000004.00000002.2454612791.0000000000400000.00000040.00000400.00020000.00000000.sdmp, type: MEMORY

Remote Access Functionality

barindex
Source: Yara match File source: 4.2.SecuriteInfo.com.BackDoor.AgentTeslaNET.20.15021.21756.exe.400000.0.unpack, type: UNPACKEDPE
Source: Yara match File source: 4.2.SecuriteInfo.com.BackDoor.AgentTeslaNET.20.15021.21756.exe.400000.0.raw.unpack, type: UNPACKEDPE
Source: Yara match File source: 00000004.00000002.2454612791.0000000000400000.00000040.00000400.00020000.00000000.sdmp, type: MEMORY
No contacted IP infos