Source: CV_ Filipa Barbosa.exe |
ReversingLabs: Detection: 39% |
Source: Yara match |
File source: 00000002.00000002.1452011802.0000000000401000.00000040.80000000.00040000.00000000.sdmp, type: MEMORY |
Source: Yara match |
File source: 00000002.00000002.1452204848.00000000025B0000.00000004.00001000.00020000.00000000.sdmp, type: MEMORY |
Source: CV_ Filipa Barbosa.exe |
Static PE information: EXECUTABLE_IMAGE, LARGE_ADDRESS_AWARE, 32BIT_MACHINE |
Source: Yara match |
File source: 00000002.00000002.1452011802.0000000000401000.00000040.80000000.00040000.00000000.sdmp, type: MEMORY |
Source: Yara match |
File source: 00000002.00000002.1452204848.00000000025B0000.00000004.00001000.00020000.00000000.sdmp, type: MEMORY |
Source: CV_ Filipa Barbosa.exe |
Static PE information: EXECUTABLE_IMAGE, LARGE_ADDRESS_AWARE, 32BIT_MACHINE |
Source: classification engine |
Classification label: mal68.troj.evad.winEXE@3/1@0/0 |
Source: C:\Users\user\Desktop\CV_ Filipa Barbosa.exe |
File created: C:\Users\user\AppData\Local\Temp\aut571.tmp |
Source: CV_ Filipa Barbosa.exe |
Static PE information: Section: .text IMAGE_SCN_CNT_CODE, IMAGE_SCN_MEM_EXECUTE, IMAGE_SCN_MEM_READ |
Source: C:\Users\user\Desktop\CV_ Filipa Barbosa.exe |
Key opened: HKEY_CURRENT_USER\Software\Policies\Microsoft\Windows\Safer\CodeIdentifiers |
Source: CV_ Filipa Barbosa.exe |
ReversingLabs: Detection: 39% |
Source: unknown |
Process created: C:\Users\user\Desktop\CV_ Filipa Barbosa.exe "C:\Users\user\Desktop\CV_ Filipa Barbosa.exe" |
Source: C:\Users\user\Desktop\CV_ Filipa Barbosa.exe |
Process created: C:\Windows\SysWOW64\svchost.exe "C:\Users\user\Desktop\CV_ Filipa Barbosa.exe" |
Source: C:\Users\user\Desktop\CV_ Filipa Barbosa.exe |
Process created: C:\Windows\SysWOW64\svchost.exe "C:\Users\user\Desktop\CV_ Filipa Barbosa.exe" |
Source: C:\Users\user\Desktop\CV_ Filipa Barbosa.exe |
Section loaded: apphelp.dll |
Source: C:\Users\user\Desktop\CV_ Filipa Barbosa.exe |
Section loaded: wsock32.dll |
Source: C:\Users\user\Desktop\CV_ Filipa Barbosa.exe |
Section loaded: version.dll |
Source: C:\Users\user\Desktop\CV_ Filipa Barbosa.exe |
Section loaded: winmm.dll |
Source: C:\Users\user\Desktop\CV_ Filipa Barbosa.exe |
Section loaded: mpr.dll |
Source: C:\Users\user\Desktop\CV_ Filipa Barbosa.exe |
Section loaded: wininet.dll |
Source: C:\Users\user\Desktop\CV_ Filipa Barbosa.exe |
Section loaded: iphlpapi.dll |
Source: C:\Users\user\Desktop\CV_ Filipa Barbosa.exe |
Section loaded: userenv.dll |
Source: C:\Users\user\Desktop\CV_ Filipa Barbosa.exe |
Section loaded: uxtheme.dll |
Source: C:\Users\user\Desktop\CV_ Filipa Barbosa.exe |
Section loaded: kernel.appcore.dll |
Source: C:\Users\user\Desktop\CV_ Filipa Barbosa.exe |
Section loaded: ntmarta.dll |
Source: CV_ Filipa Barbosa.exe |
Static file information: File size 1213952 > 1048576 |
Source: CV_ Filipa Barbosa.exe |
Static PE information: data directory type: IMAGE_DIRECTORY_ENTRY_IMPORT |
Source: CV_ Filipa Barbosa.exe |
Static PE information: data directory type: IMAGE_DIRECTORY_ENTRY_RESOURCE |
Source: CV_ Filipa Barbosa.exe |
Static PE information: data directory type: IMAGE_DIRECTORY_ENTRY_BASERELOC |
Source: CV_ Filipa Barbosa.exe |
Static PE information: data directory type: IMAGE_DIRECTORY_ENTRY_DEBUG |
Source: CV_ Filipa Barbosa.exe |
Static PE information: data directory type: IMAGE_DIRECTORY_ENTRY_LOAD_CONFIG |
Source: CV_ Filipa Barbosa.exe |
Static PE information: data directory type: IMAGE_DIRECTORY_ENTRY_IAT |
Source: CV_ Filipa Barbosa.exe |
Static PE information: data directory type: IMAGE_DIRECTORY_ENTRY_DEBUG |
Source: CV_ Filipa Barbosa.exe |
Static PE information: Data directory: IMAGE_DIRECTORY_ENTRY_IMPORT is in: .rdata |
Source: CV_ Filipa Barbosa.exe |
Static PE information: Data directory: IMAGE_DIRECTORY_ENTRY_RESOURCE is in: .rsrc |
Source: CV_ Filipa Barbosa.exe |
Static PE information: Data directory: IMAGE_DIRECTORY_ENTRY_BASERELOC is in: .reloc |
Source: CV_ Filipa Barbosa.exe |
Static PE information: Data directory: IMAGE_DIRECTORY_ENTRY_LOAD_CONFIG is in: .rdata |
Source: CV_ Filipa Barbosa.exe |
Static PE information: Data directory: IMAGE_DIRECTORY_ENTRY_IAT is in: .rdata |
Source: C:\Users\user\Desktop\CV_ Filipa Barbosa.exe |
Process information set: NOOPENFILEERRORBOX |
Source: C:\Users\user\Desktop\CV_ Filipa Barbosa.exe |
API/Special instruction interceptor: Address: 12F8044 |
Source: C:\Windows\SysWOW64\svchost.exe TID: 6764 |
Thread sleep time: -30000s >= -30000s |
Source: C:\Windows\SysWOW64\svchost.exe |
Process information queried: ProcessInformation |
Source: C:\Windows\SysWOW64\svchost.exe |
Process queried: DebugPort |
Source: C:\Users\user\Desktop\CV_ Filipa Barbosa.exe |
Section loaded: NULL target: C:\Windows\SysWOW64\svchost.exe protection: execute and read and write |
Source: C:\Users\user\Desktop\CV_ Filipa Barbosa.exe |
Memory written: C:\Windows\SysWOW64\svchost.exe base: 27D8008 |
Source: C:\Users\user\Desktop\CV_ Filipa Barbosa.exe |
Process created: C:\Windows\SysWOW64\svchost.exe "C:\Users\user\Desktop\CV_ Filipa Barbosa.exe" |
Source: Yara match |
File source: 00000002.00000002.1452011802.0000000000401000.00000040.80000000.00040000.00000000.sdmp, type: MEMORY |
Source: Yara match |
File source: 00000002.00000002.1452204848.00000000025B0000.00000004.00001000.00020000.00000000.sdmp, type: MEMORY |
Source: Yara match |
File source: 00000002.00000002.1452011802.0000000000401000.00000040.80000000.00040000.00000000.sdmp, type: MEMORY |
Source: Yara match |
File source: 00000002.00000002.1452204848.00000000025B0000.00000004.00001000.00020000.00000000.sdmp, type: MEMORY |