Source: C:\Users\user\Desktop\comprobante de transferencia.exe |
Code function: 0_2_0040635D FindFirstFileW,FindClose, |
0_2_0040635D |
Source: C:\Users\user\Desktop\comprobante de transferencia.exe |
Code function: 0_2_0040580B GetTempPathW,DeleteFileW,lstrcatW,lstrcatW,lstrlenW,FindFirstFileW,FindNextFileW,FindClose, |
0_2_0040580B |
Source: C:\Users\user\Desktop\comprobante de transferencia.exe |
Code function: 0_2_004027FB FindFirstFileW, |
0_2_004027FB |
Source: C:\Users\user\Desktop\comprobante de transferencia.exe |
Code function: 2_2_0040635D FindFirstFileW,FindClose, |
2_2_0040635D |
Source: C:\Users\user\Desktop\comprobante de transferencia.exe |
Code function: 2_2_0040580B GetTempPathW,DeleteFileW,lstrcatW,lstrcatW,lstrlenW,FindFirstFileW,FindNextFileW,FindClose, |
2_2_0040580B |
Source: C:\Users\user\Desktop\comprobante de transferencia.exe |
Code function: 2_2_004027FB FindFirstFileW, |
2_2_004027FB |
Source: comprobante de transferencia.exe |
String found in binary or memory: http://crl.apple.com/root.crl0 |
Source: comprobante de transferencia.exe |
String found in binary or memory: http://crl.apple.com/timestamp.crl0 |
Source: comprobante de transferencia.exe, 00000002.00000003.2916893113.0000000003AA1000.00000004.00000020.00020000.00000000.sdmp, comprobante de transferencia.exe, 00000002.00000002.7687280921.0000000003A9B000.00000004.00000020.00020000.00000000.sdmp, comprobante de transferencia.exe, 00000002.00000003.2903958987.0000000003AA2000.00000004.00000020.00020000.00000000.sdmp |
String found in binary or memory: http://crl.comodoca.com/AAACertificateServices.crl06 |
Source: comprobante de transferencia.exe, 00000002.00000003.2916893113.0000000003AA1000.00000004.00000020.00020000.00000000.sdmp, comprobante de transferencia.exe, 00000002.00000002.7687280921.0000000003A9B000.00000004.00000020.00020000.00000000.sdmp, comprobante de transferencia.exe, 00000002.00000003.2903958987.0000000003AA2000.00000004.00000020.00020000.00000000.sdmp |
String found in binary or memory: http://crl.globalsign.net/root-r2.crl0 |
Source: comprobante de transferencia.exe |
String found in binary or memory: http://nsis.sf.net/NSIS_ErrorError |
Source: comprobante de transferencia.exe |
String found in binary or memory: http://www.apple.com/appleca0 |
Source: comprobante de transferencia.exe, 00000002.00000003.2916893113.0000000003AA1000.00000004.00000020.00020000.00000000.sdmp, comprobante de transferencia.exe, 00000002.00000002.7687280921.0000000003A9B000.00000004.00000020.00020000.00000000.sdmp, comprobante de transferencia.exe, 00000002.00000003.2903958987.0000000003AA2000.00000004.00000020.00020000.00000000.sdmp |
String found in binary or memory: http://www.quovadis.bm0 |
Source: comprobante de transferencia.exe, 00000002.00000003.2903907971.0000000003AFC000.00000004.00000020.00020000.00000000.sdmp |
String found in binary or memory: https://apis.google.com |
Source: comprobante de transferencia.exe, 00000002.00000002.7687280921.0000000003A28000.00000004.00000020.00020000.00000000.sdmp |
String found in binary or memory: https://drive.google.com/ |
Source: comprobante de transferencia.exe, 00000002.00000002.7687280921.0000000003A28000.00000004.00000020.00020000.00000000.sdmp |
String found in binary or memory: https://drive.google.com/Ar= |
Source: comprobante de transferencia.exe, 00000002.00000002.7687982111.0000000005740000.00000004.00001000.00020000.00000000.sdmp, comprobante de transferencia.exe, 00000002.00000002.7687280921.0000000003A65000.00000004.00000020.00020000.00000000.sdmp |
String found in binary or memory: https://drive.google.com/uc?export=download&id=1ZlWTWjrz48C7pJUuwTOgfOjeHFK1G_7k |
Source: comprobante de transferencia.exe, 00000002.00000002.7687280921.0000000003A65000.00000004.00000020.00020000.00000000.sdmp |
String found in binary or memory: https://drive.google.com/uc?export=download&id=1ZlWTWjrz48C7pJUuwTOgfOjeHFK1G_7kfyQ |
Source: comprobante de transferencia.exe, 00000002.00000003.2916893113.0000000003AA1000.00000004.00000020.00020000.00000000.sdmp, comprobante de transferencia.exe, 00000002.00000002.7687280921.0000000003A9B000.00000004.00000020.00020000.00000000.sdmp |
String found in binary or memory: https://drive.usercontent.google.com/ |
Source: comprobante de transferencia.exe, 00000002.00000003.2916893113.0000000003AA1000.00000004.00000020.00020000.00000000.sdmp, comprobante de transferencia.exe, 00000002.00000002.7687280921.0000000003A9B000.00000004.00000020.00020000.00000000.sdmp, comprobante de transferencia.exe, 00000002.00000003.2903907971.0000000003AFC000.00000004.00000020.00020000.00000000.sdmp |
String found in binary or memory: https://drive.usercontent.google.com/download?id=1ZlWTWjrz48C7pJUuwTOgfOjeHFK1G_7k&export=download |
Source: comprobante de transferencia.exe, 00000002.00000003.2916893113.0000000003AA1000.00000004.00000020.00020000.00000000.sdmp |
String found in binary or memory: https://drive.usercontent.google.com/download?id=1ZlWTWjrz48C7pJUuwTOgfOjeHFK1G_7k&export=download/r |
Source: comprobante de transferencia.exe, 00000002.00000003.2916893113.0000000003AA1000.00000004.00000020.00020000.00000000.sdmp, comprobante de transferencia.exe, 00000002.00000002.7687280921.0000000003A9B000.00000004.00000020.00020000.00000000.sdmp, comprobante de transferencia.exe, 00000002.00000003.2903958987.0000000003AA2000.00000004.00000020.00020000.00000000.sdmp |
String found in binary or memory: https://ocsp.quovadisoffshore.com0 |
Source: comprobante de transferencia.exe, 00000002.00000003.2903907971.0000000003AFC000.00000004.00000020.00020000.00000000.sdmp |
String found in binary or memory: https://ssl.gstatic.com |
Source: comprobante de transferencia.exe |
String found in binary or memory: https://www.apple.com/appleca/0 |
Source: comprobante de transferencia.exe, 00000002.00000003.2903907971.0000000003AFC000.00000004.00000020.00020000.00000000.sdmp |
String found in binary or memory: https://www.google-analytics.com;report-uri |
Source: comprobante de transferencia.exe, 00000002.00000003.2903907971.0000000003AFC000.00000004.00000020.00020000.00000000.sdmp |
String found in binary or memory: https://www.google.com |
Source: comprobante de transferencia.exe, 00000002.00000003.2903907971.0000000003AFC000.00000004.00000020.00020000.00000000.sdmp |
String found in binary or memory: https://www.googletagmanager.com |
Source: comprobante de transferencia.exe, 00000002.00000003.2903907971.0000000003AFC000.00000004.00000020.00020000.00000000.sdmp |
String found in binary or memory: https://www.gstatic.com |
Source: C:\Users\user\Desktop\comprobante de transferencia.exe |
Code function: 0_2_004052B8 GetDlgItem,GetDlgItem,GetDlgItem,GetDlgItem,GetClientRect,GetSystemMetrics,SendMessageW,SendMessageW,SendMessageW,SendMessageW,SendMessageW,SendMessageW,ShowWindow,ShowWindow,GetDlgItem,SendMessageW,SendMessageW,SendMessageW,GetDlgItem,CreateThread,FindCloseChangeNotification,ShowWindow,ShowWindow,ShowWindow,ShowWindow,LdrInitializeThunk,SendMessageW,CreatePopupMenu,LdrInitializeThunk,AppendMenuW,GetWindowRect,TrackPopupMenu,SendMessageW,OpenClipboard,EmptyClipboard,GlobalAlloc,GlobalLock,SendMessageW,GlobalUnlock,SetClipboardData,CloseClipboard, |
0_2_004052B8 |
Source: C:\Users\user\Desktop\comprobante de transferencia.exe |
Code function: 0_2_0040326A EntryPoint,SetErrorMode,GetVersion,lstrlenA,#17,OleInitialize,SHGetFileInfoW,GetCommandLineW,GetModuleHandleW,CharNextW,GetTempPathW,GetTempPathW,GetWindowsDirectoryW,lstrcatW,GetTempPathW,lstrcatW,SetEnvironmentVariableW,SetEnvironmentVariableW,SetEnvironmentVariableW,DeleteFileW,OleUninitialize,ExitProcess,lstrcatW,lstrcatW,lstrcatW,lstrcmpiW,SetCurrentDirectoryW,DeleteFileW,LdrInitializeThunk,CopyFileW,CloseHandle,GetCurrentProcess,OpenProcessToken,LookupPrivilegeValueW,AdjustTokenPrivileges,ExitWindowsEx,ExitProcess, |
0_2_0040326A |
Source: C:\Users\user\Desktop\comprobante de transferencia.exe |
Code function: 2_2_0040326A EntryPoint,SetErrorMode,GetVersion,lstrlenA,#17,OleInitialize,SHGetFileInfoW,GetCommandLineW,GetModuleHandleW,CharNextW,GetTempPathW,GetTempPathW,GetWindowsDirectoryW,lstrcatW,GetTempPathW,lstrcatW,SetEnvironmentVariableW,SetEnvironmentVariableW,SetEnvironmentVariableW,DeleteFileW,OleUninitialize,ExitProcess,lstrcatW,lstrcatW,lstrcatW,lstrcmpiW,SetCurrentDirectoryW,DeleteFileW,LdrInitializeThunk,CopyFileW,CloseHandle,GetCurrentProcess,OpenProcessToken,LookupPrivilegeValueW,AdjustTokenPrivileges,ExitWindowsEx,ExitProcess, |
2_2_0040326A |
Source: C:\Users\user\Desktop\comprobante de transferencia.exe |
Code function: 0_2_004066E2 |
0_2_004066E2 |
Source: C:\Users\user\Desktop\comprobante de transferencia.exe |
Code function: 0_2_00404AF5 |
0_2_00404AF5 |
Source: C:\Users\user\Desktop\comprobante de transferencia.exe |
Code function: 2_2_004066E2 |
2_2_004066E2 |
Source: C:\Users\user\Desktop\comprobante de transferencia.exe |
Code function: 2_2_00404AF5 |
2_2_00404AF5 |
Source: C:\Users\user\Desktop\comprobante de transferencia.exe |
Code function: 2_2_0015B010 |
2_2_0015B010 |
Source: C:\Users\user\Desktop\comprobante de transferencia.exe |
Code function: 2_2_0015D0F8 |
2_2_0015D0F8 |
Source: C:\Users\user\Desktop\comprobante de transferencia.exe |
Code function: 2_2_0015A3F8 |
2_2_0015A3F8 |
Source: C:\Users\user\Desktop\comprobante de transferencia.exe |
Code function: 2_2_00156530 |
2_2_00156530 |
Source: C:\Users\user\Desktop\comprobante de transferencia.exe |
Code function: 2_2_001541A7 |
2_2_001541A7 |
Source: C:\Users\user\Desktop\comprobante de transferencia.exe |
Code function: 2_2_00156522 |
2_2_00156522 |
Source: C:\Users\user\Desktop\comprobante de transferencia.exe |
Code function: 2_2_0015A740 |
2_2_0015A740 |
Source: C:\Users\user\Desktop\comprobante de transferencia.exe |
Code function: 2_2_36443280 |
2_2_36443280 |
Source: C:\Users\user\Desktop\comprobante de transferencia.exe |
Code function: 2_2_3644E298 |
2_2_3644E298 |
Source: C:\Users\user\Desktop\comprobante de transferencia.exe |
Code function: 2_2_3644F078 |
2_2_3644F078 |
Source: C:\Users\user\Desktop\comprobante de transferencia.exe |
Code function: 2_2_3644C158 |
2_2_3644C158 |
Source: C:\Users\user\Desktop\comprobante de transferencia.exe |
Code function: 2_2_364465F8 |
2_2_364465F8 |
Source: C:\Users\user\Desktop\comprobante de transferencia.exe |
Code function: 2_2_36442E7A |
2_2_36442E7A |
Source: C:\Users\user\Desktop\comprobante de transferencia.exe |
Code function: 2_2_3644B321 |
2_2_3644B321 |
Source: C:\Users\user\Desktop\comprobante de transferencia.exe |
Code function: 2_2_3644A580 |
2_2_3644A580 |
Source: C:\Users\user\Desktop\comprobante de transferencia.exe |
Code function: 2_2_37055150 |
2_2_37055150 |
Source: C:\Users\user\Desktop\comprobante de transferencia.exe |
Code function: 2_2_370541EA |
2_2_370541EA |
Source: C:\Users\user\Desktop\comprobante de transferencia.exe |
Code function: 2_2_37050D30 |
2_2_37050D30 |
Source: C:\Users\user\Desktop\comprobante de transferencia.exe |
Code function: 2_2_37057360 |
2_2_37057360 |
Source: C:\Users\user\Desktop\comprobante de transferencia.exe |
Code function: 2_2_37050648 |
2_2_37050648 |
Source: C:\Users\user\Desktop\comprobante de transferencia.exe |
Code function: 2_2_3714B4E0 |
2_2_3714B4E0 |
Source: comprobante de transferencia.exe, 00000002.00000002.7687280921.0000000003A65000.00000004.00000020.00020000.00000000.sdmp |
Binary or memory string: OriginalFilenameclr.dllT vs comprobante de transferencia.exe |
Source: comprobante de transferencia.exe, 00000002.00000002.7699759602.0000000034019000.00000004.00000010.00020000.00000000.sdmp |
Binary or memory string: OriginalFilenameUNKNOWN_FILET vs comprobante de transferencia.exe |
Source: C:\Users\user\Desktop\comprobante de transferencia.exe |
Section loaded: edgegdi.dll |
Jump to behavior |
Source: C:\Users\user\Desktop\comprobante de transferencia.exe |
Section loaded: uxtheme.dll |
Jump to behavior |
Source: C:\Users\user\Desktop\comprobante de transferencia.exe |
Section loaded: userenv.dll |
Jump to behavior |
Source: C:\Users\user\Desktop\comprobante de transferencia.exe |
Section loaded: apphelp.dll |
Jump to behavior |
Source: C:\Users\user\Desktop\comprobante de transferencia.exe |
Section loaded: propsys.dll |
Jump to behavior |
Source: C:\Users\user\Desktop\comprobante de transferencia.exe |
Section loaded: dwmapi.dll |
Jump to behavior |
Source: C:\Users\user\Desktop\comprobante de transferencia.exe |
Section loaded: cryptbase.dll |
Jump to behavior |
Source: C:\Users\user\Desktop\comprobante de transferencia.exe |
Section loaded: oleacc.dll |
Jump to behavior |
Source: C:\Users\user\Desktop\comprobante de transferencia.exe |
Section loaded: version.dll |
Jump to behavior |
Source: C:\Users\user\Desktop\comprobante de transferencia.exe |
Section loaded: shfolder.dll |
Jump to behavior |
Source: C:\Users\user\Desktop\comprobante de transferencia.exe |
Section loaded: kernel.appcore.dll |
Jump to behavior |
Source: C:\Users\user\Desktop\comprobante de transferencia.exe |
Section loaded: windows.storage.dll |
Jump to behavior |
Source: C:\Users\user\Desktop\comprobante de transferencia.exe |
Section loaded: wldp.dll |
Jump to behavior |
Source: C:\Users\user\Desktop\comprobante de transferencia.exe |
Section loaded: riched20.dll |
Jump to behavior |
Source: C:\Users\user\Desktop\comprobante de transferencia.exe |
Section loaded: usp10.dll |
Jump to behavior |
Source: C:\Users\user\Desktop\comprobante de transferencia.exe |
Section loaded: msls31.dll |
Jump to behavior |
Source: C:\Users\user\Desktop\comprobante de transferencia.exe |
Section loaded: textinputframework.dll |
Jump to behavior |
Source: C:\Users\user\Desktop\comprobante de transferencia.exe |
Section loaded: coreuicomponents.dll |
Jump to behavior |
Source: C:\Users\user\Desktop\comprobante de transferencia.exe |
Section loaded: coremessaging.dll |
Jump to behavior |
Source: C:\Users\user\Desktop\comprobante de transferencia.exe |
Section loaded: ntmarta.dll |
Jump to behavior |
Source: C:\Users\user\Desktop\comprobante de transferencia.exe |
Section loaded: wintypes.dll |
Jump to behavior |
Source: C:\Users\user\Desktop\comprobante de transferencia.exe |
Section loaded: wintypes.dll |
Jump to behavior |
Source: C:\Users\user\Desktop\comprobante de transferencia.exe |
Section loaded: wintypes.dll |
Jump to behavior |
Source: C:\Users\user\Desktop\comprobante de transferencia.exe |
Section loaded: textshaping.dll |
Jump to behavior |
Source: C:\Users\user\Desktop\comprobante de transferencia.exe |
Section loaded: profapi.dll |
Jump to behavior |
Source: C:\Users\user\Desktop\comprobante de transferencia.exe |
Section loaded: edgegdi.dll |
Jump to behavior |
Source: C:\Users\user\Desktop\comprobante de transferencia.exe |
Section loaded: wininet.dll |
Jump to behavior |
Source: C:\Users\user\Desktop\comprobante de transferencia.exe |
Section loaded: iertutil.dll |
Jump to behavior |
Source: C:\Users\user\Desktop\comprobante de transferencia.exe |
Section loaded: sspicli.dll |
Jump to behavior |
Source: C:\Users\user\Desktop\comprobante de transferencia.exe |
Section loaded: windows.storage.dll |
Jump to behavior |
Source: C:\Users\user\Desktop\comprobante de transferencia.exe |
Section loaded: wldp.dll |
Jump to behavior |
Source: C:\Users\user\Desktop\comprobante de transferencia.exe |
Section loaded: profapi.dll |
Jump to behavior |
Source: C:\Users\user\Desktop\comprobante de transferencia.exe |
Section loaded: kernel.appcore.dll |
Jump to behavior |
Source: C:\Users\user\Desktop\comprobante de transferencia.exe |
Section loaded: ondemandconnroutehelper.dll |
Jump to behavior |
Source: C:\Users\user\Desktop\comprobante de transferencia.exe |
Section loaded: winhttp.dll |
Jump to behavior |
Source: C:\Users\user\Desktop\comprobante de transferencia.exe |
Section loaded: mswsock.dll |
Jump to behavior |
Source: C:\Users\user\Desktop\comprobante de transferencia.exe |
Section loaded: iphlpapi.dll |
Jump to behavior |
Source: C:\Users\user\Desktop\comprobante de transferencia.exe |
Section loaded: winnsi.dll |
Jump to behavior |
Source: C:\Users\user\Desktop\comprobante de transferencia.exe |
Section loaded: urlmon.dll |
Jump to behavior |
Source: C:\Users\user\Desktop\comprobante de transferencia.exe |
Section loaded: srvcli.dll |
Jump to behavior |
Source: C:\Users\user\Desktop\comprobante de transferencia.exe |
Section loaded: netutils.dll |
Jump to behavior |
Source: C:\Users\user\Desktop\comprobante de transferencia.exe |
Section loaded: dnsapi.dll |
Jump to behavior |
Source: C:\Users\user\Desktop\comprobante de transferencia.exe |
Section loaded: rasadhlp.dll |
Jump to behavior |
Source: C:\Users\user\Desktop\comprobante de transferencia.exe |
Section loaded: fwpuclnt.dll |
Jump to behavior |
Source: C:\Users\user\Desktop\comprobante de transferencia.exe |
Section loaded: schannel.dll |
Jump to behavior |
Source: C:\Users\user\Desktop\comprobante de transferencia.exe |
Section loaded: mskeyprotect.dll |
Jump to behavior |
Source: C:\Users\user\Desktop\comprobante de transferencia.exe |
Section loaded: ntasn1.dll |
Jump to behavior |
Source: C:\Users\user\Desktop\comprobante de transferencia.exe |
Section loaded: msasn1.dll |
Jump to behavior |
Source: C:\Users\user\Desktop\comprobante de transferencia.exe |
Section loaded: dpapi.dll |
Jump to behavior |
Source: C:\Users\user\Desktop\comprobante de transferencia.exe |
Section loaded: cryptsp.dll |
Jump to behavior |
Source: C:\Users\user\Desktop\comprobante de transferencia.exe |
Section loaded: rsaenh.dll |
Jump to behavior |
Source: C:\Users\user\Desktop\comprobante de transferencia.exe |
Section loaded: cryptbase.dll |
Jump to behavior |
Source: C:\Users\user\Desktop\comprobante de transferencia.exe |
Section loaded: gpapi.dll |
Jump to behavior |
Source: C:\Users\user\Desktop\comprobante de transferencia.exe |
Section loaded: ncrypt.dll |
Jump to behavior |
Source: C:\Users\user\Desktop\comprobante de transferencia.exe |
Section loaded: ncryptsslp.dll |
Jump to behavior |
Source: C:\Users\user\Desktop\comprobante de transferencia.exe |
Section loaded: mscoree.dll |
Jump to behavior |
Source: C:\Users\user\Desktop\comprobante de transferencia.exe |
Section loaded: version.dll |
Jump to behavior |
Source: C:\Users\user\Desktop\comprobante de transferencia.exe |
Section loaded: vcruntime140_clr0400.dll |
Jump to behavior |
Source: C:\Users\user\Desktop\comprobante de transferencia.exe |
Section loaded: ucrtbase_clr0400.dll |
Jump to behavior |
Source: C:\Users\user\Desktop\comprobante de transferencia.exe |
Section loaded: uxtheme.dll |
Jump to behavior |
Source: C:\Users\user\Desktop\comprobante de transferencia.exe |
Section loaded: wbemcomn.dll |
Jump to behavior |
Source: C:\Users\user\Desktop\comprobante de transferencia.exe |
Section loaded: amsi.dll |
Jump to behavior |
Source: C:\Users\user\Desktop\comprobante de transferencia.exe |
Section loaded: userenv.dll |
Jump to behavior |
Source: C:\Users\user\Desktop\comprobante de transferencia.exe |
Section loaded: vaultcli.dll |
Jump to behavior |
Source: C:\Users\user\Desktop\comprobante de transferencia.exe |
Section loaded: wintypes.dll |
Jump to behavior |
Source: C:\Users\user\Desktop\comprobante de transferencia.exe |
Code function: 0_2_0040326A EntryPoint,SetErrorMode,GetVersion,lstrlenA,#17,OleInitialize,SHGetFileInfoW,GetCommandLineW,GetModuleHandleW,CharNextW,GetTempPathW,GetTempPathW,GetWindowsDirectoryW,lstrcatW,GetTempPathW,lstrcatW,SetEnvironmentVariableW,SetEnvironmentVariableW,SetEnvironmentVariableW,DeleteFileW,OleUninitialize,ExitProcess,lstrcatW,lstrcatW,lstrcatW,lstrcmpiW,SetCurrentDirectoryW,DeleteFileW,LdrInitializeThunk,CopyFileW,CloseHandle,GetCurrentProcess,OpenProcessToken,LookupPrivilegeValueW,AdjustTokenPrivileges,ExitWindowsEx,ExitProcess, |
0_2_0040326A |
Source: C:\Users\user\Desktop\comprobante de transferencia.exe |
Code function: 2_2_0040326A EntryPoint,SetErrorMode,GetVersion,lstrlenA,#17,OleInitialize,SHGetFileInfoW,GetCommandLineW,GetModuleHandleW,CharNextW,GetTempPathW,GetTempPathW,GetWindowsDirectoryW,lstrcatW,GetTempPathW,lstrcatW,SetEnvironmentVariableW,SetEnvironmentVariableW,SetEnvironmentVariableW,DeleteFileW,OleUninitialize,ExitProcess,lstrcatW,lstrcatW,lstrcatW,lstrcmpiW,SetCurrentDirectoryW,DeleteFileW,LdrInitializeThunk,CopyFileW,CloseHandle,GetCurrentProcess,OpenProcessToken,LookupPrivilegeValueW,AdjustTokenPrivileges,ExitWindowsEx,ExitProcess, |
2_2_0040326A |
Source: C:\Users\user\Desktop\comprobante de transferencia.exe |
Code function: 0_2_00404579 GetDlgItem,SetWindowTextW,LdrInitializeThunk,LdrInitializeThunk,SHBrowseForFolderW,CoTaskMemFree,lstrcmpiW,lstrcatW,SetDlgItemTextW,LdrInitializeThunk,GetDiskFreeSpaceW,MulDiv,SetDlgItemTextW, |
0_2_00404579 |
Source: unknown |
Process created: C:\Users\user\Desktop\comprobante de transferencia.exe C:\Users\user\Desktop\comprobante de transferencia.exe |
|
Source: C:\Users\user\Desktop\comprobante de transferencia.exe |
Process created: C:\Users\user\Desktop\comprobante de transferencia.exe C:\Users\user\Desktop\comprobante de transferencia.exe |
|
Source: C:\Users\user\Desktop\comprobante de transferencia.exe |
Process created: C:\Users\user\Desktop\comprobante de transferencia.exe C:\Users\user\Desktop\comprobante de transferencia.exe |
Jump to behavior |
Source: C:\Users\user\Desktop\comprobante de transferencia.exe |
Code function: 0_2_10001B18 GlobalAlloc,lstrcpyW,lstrcpyW,GlobalFree,GlobalFree,GlobalFree,GlobalFree,GlobalFree,GlobalFree,lstrcpyW,GetModuleHandleW,LoadLibraryW,GetProcAddress,lstrlenW, |
0_2_10001B18 |
Source: C:\Users\user\Desktop\comprobante de transferencia.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\Desktop\comprobante de transferencia.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\Desktop\comprobante de transferencia.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\Desktop\comprobante de transferencia.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\Desktop\comprobante de transferencia.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\Desktop\comprobante de transferencia.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\Desktop\comprobante de transferencia.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\Desktop\comprobante de transferencia.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\Desktop\comprobante de transferencia.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\Desktop\comprobante de transferencia.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\Desktop\comprobante de transferencia.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\Desktop\comprobante de transferencia.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\Desktop\comprobante de transferencia.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\Desktop\comprobante de transferencia.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\Desktop\comprobante de transferencia.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\Desktop\comprobante de transferencia.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\Desktop\comprobante de transferencia.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\Desktop\comprobante de transferencia.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\Desktop\comprobante de transferencia.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\Desktop\comprobante de transferencia.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\Desktop\comprobante de transferencia.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\Desktop\comprobante de transferencia.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\Desktop\comprobante de transferencia.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\Desktop\comprobante de transferencia.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\Desktop\comprobante de transferencia.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\Desktop\comprobante de transferencia.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\Desktop\comprobante de transferencia.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\Desktop\comprobante de transferencia.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\Desktop\comprobante de transferencia.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\Desktop\comprobante de transferencia.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\Desktop\comprobante de transferencia.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\Desktop\comprobante de transferencia.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\Desktop\comprobante de transferencia.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\Desktop\comprobante de transferencia.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\Desktop\comprobante de transferencia.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\Desktop\comprobante de transferencia.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\Desktop\comprobante de transferencia.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\Desktop\comprobante de transferencia.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\Desktop\comprobante de transferencia.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\Desktop\comprobante de transferencia.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\Desktop\comprobante de transferencia.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\Desktop\comprobante de transferencia.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\Desktop\comprobante de transferencia.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\Desktop\comprobante de transferencia.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\Desktop\comprobante de transferencia.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\Desktop\comprobante de transferencia.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\Desktop\comprobante de transferencia.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\Desktop\comprobante de transferencia.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\Desktop\comprobante de transferencia.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\Desktop\comprobante de transferencia.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\Desktop\comprobante de transferencia.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\Desktop\comprobante de transferencia.exe |
Code function: 0_2_0040635D FindFirstFileW,FindClose, |
0_2_0040635D |
Source: C:\Users\user\Desktop\comprobante de transferencia.exe |
Code function: 0_2_0040580B GetTempPathW,DeleteFileW,lstrcatW,lstrcatW,lstrlenW,FindFirstFileW,FindNextFileW,FindClose, |
0_2_0040580B |
Source: C:\Users\user\Desktop\comprobante de transferencia.exe |
Code function: 0_2_004027FB FindFirstFileW, |
0_2_004027FB |
Source: C:\Users\user\Desktop\comprobante de transferencia.exe |
Code function: 2_2_0040635D FindFirstFileW,FindClose, |
2_2_0040635D |
Source: C:\Users\user\Desktop\comprobante de transferencia.exe |
Code function: 2_2_0040580B GetTempPathW,DeleteFileW,lstrcatW,lstrcatW,lstrlenW,FindFirstFileW,FindNextFileW,FindClose, |
2_2_0040580B |
Source: C:\Users\user\Desktop\comprobante de transferencia.exe |
Code function: 2_2_004027FB FindFirstFileW, |
2_2_004027FB |
Source: comprobante de transferencia.exe, 00000002.00000002.7687280921.0000000003A28000.00000004.00000020.00020000.00000000.sdmp |
Binary or memory string: Hyper-V RAWX |
Source: comprobante de transferencia.exe, 00000002.00000002.7687280921.0000000003A85000.00000004.00000020.00020000.00000000.sdmp |
Binary or memory string: Hyper-V RAW |
Source: C:\Users\user\Desktop\comprobante de transferencia.exe |
Code function: 0_2_10001B18 GlobalAlloc,lstrcpyW,lstrcpyW,GlobalFree,GlobalFree,GlobalFree,GlobalFree,GlobalFree,GlobalFree,lstrcpyW,GetModuleHandleW,LoadLibraryW,GetProcAddress,lstrlenW, |
0_2_10001B18 |
Source: C:\Users\user\Desktop\comprobante de transferencia.exe |
Queries volume information: C:\Users\user\Desktop\comprobante de transferencia.exe VolumeInformation |
Jump to behavior |
Source: C:\Users\user\Desktop\comprobante de transferencia.exe |
Queries volume information: C:\Windows\Microsoft.NET\assembly\GAC_MSIL\System.Windows.Forms\v4.0_4.0.0.0__b77a5c561934e089\System.Windows.Forms.dll VolumeInformation |
Jump to behavior |
Source: C:\Users\user\Desktop\comprobante de transferencia.exe |
Queries volume information: C:\Windows\Microsoft.NET\assembly\GAC_MSIL\System.Management\v4.0_4.0.0.0__b03f5f7f11d50a3a\System.Management.dll VolumeInformation |
Jump to behavior |
Source: C:\Users\user\Desktop\comprobante de transferencia.exe |
Queries volume information: C:\Windows\Microsoft.NET\assembly\GAC_MSIL\System.Management\v4.0_4.0.0.0__b03f5f7f11d50a3a\System.Management.dll VolumeInformation |
Jump to behavior |
Source: C:\Users\user\Desktop\comprobante de transferencia.exe |
Queries volume information: C:\Windows\Microsoft.NET\assembly\GAC_MSIL\System.Security\v4.0_4.0.0.0__b03f5f7f11d50a3a\System.Security.dll VolumeInformation |
Jump to behavior |
Source: C:\Users\user\Desktop\comprobante de transferencia.exe |
Queries volume information: C:\Windows\Microsoft.NET\assembly\GAC_MSIL\System.Drawing\v4.0_4.0.0.0__b03f5f7f11d50a3a\System.Drawing.dll VolumeInformation |
Jump to behavior |
Source: C:\Users\user\Desktop\comprobante de transferencia.exe |
Queries volume information: C:\Windows\Microsoft.NET\assembly\GAC_MSIL\Accessibility\v4.0_4.0.0.0__b03f5f7f11d50a3a\Accessibility.dll VolumeInformation |
Jump to behavior |
Source: C:\Users\user\Desktop\comprobante de transferencia.exe |
Code function: 0_2_0040326A EntryPoint,SetErrorMode,GetVersion,lstrlenA,#17,OleInitialize,SHGetFileInfoW,GetCommandLineW,GetModuleHandleW,CharNextW,GetTempPathW,GetTempPathW,GetWindowsDirectoryW,lstrcatW,GetTempPathW,lstrcatW,SetEnvironmentVariableW,SetEnvironmentVariableW,SetEnvironmentVariableW,DeleteFileW,OleUninitialize,ExitProcess,lstrcatW,lstrcatW,lstrcatW,lstrcmpiW,SetCurrentDirectoryW,DeleteFileW,LdrInitializeThunk,CopyFileW,CloseHandle,GetCurrentProcess,OpenProcessToken,LookupPrivilegeValueW,AdjustTokenPrivileges,ExitWindowsEx,ExitProcess, |
0_2_0040326A |
Source: C:\Users\user\Desktop\comprobante de transferencia.exe |
File opened: C:\Users\user\AppData\Roaming\Thunderbird\profiles.ini |
Jump to behavior |
Source: C:\Users\user\Desktop\comprobante de transferencia.exe |
File opened: C:\Users\user\AppData\Roaming\Thunderbird\profiles.ini |
Jump to behavior |
Source: C:\Users\user\Desktop\comprobante de transferencia.exe |
Key opened: HKEY_CURRENT_USER\Software\Microsoft\Windows NT\CurrentVersion\Windows Messaging Subsystem\Profiles |
Jump to behavior |
Source: C:\Users\user\Desktop\comprobante de transferencia.exe |
Key opened: HKEY_CURRENT_USER\Software\IncrediMail\Identities |
Jump to behavior |