Click to jump to signature section
Source: unknown | TCP traffic detected without corresponding DNS query: 204.79.197.203 |
Source: unknown | TCP traffic detected without corresponding DNS query: 204.79.197.203 |
Source: unknown | UDP traffic detected without corresponding DNS query: 1.1.1.1 |
Source: unknown | UDP traffic detected without corresponding DNS query: 1.1.1.1 |
Source: unknown | UDP traffic detected without corresponding DNS query: 1.1.1.1 |
Source: unknown | UDP traffic detected without corresponding DNS query: 1.1.1.1 |
Source: global traffic | DNS traffic detected: DNS query: fat-doc.s3.us-east-2.amazonaws.com |
Source: global traffic | DNS traffic detected: DNS query: www.google.com |
Source: unknown | Network traffic detected: HTTP traffic on port 49673 -> 443 |
Source: unknown | Network traffic detected: HTTP traffic on port 49705 -> 443 |
Source: unknown | Network traffic detected: HTTP traffic on port 49702 -> 443 |
Source: unknown | Network traffic detected: HTTP traffic on port 49703 -> 443 |
Source: unknown | Network traffic detected: HTTP traffic on port 443 -> 49705 |
Source: unknown | Network traffic detected: HTTP traffic on port 443 -> 49703 |
Source: unknown | Network traffic detected: HTTP traffic on port 443 -> 49702 |
Source: classification engine | Classification label: mal60.evad.win@18/8@4/138 |
Source: C:\Program Files\Google\Chrome\Application\chrome.exe | File created: C:\Users\user\Downloads\596cd038-db66-4afc-815f-ca69191c7893.tmp |
Source: unknown | Process created: C:\Windows\System32\wscript.exe "C:\Windows\System32\WScript.exe" "C:\Users\user\AppData\Local\Temp\Temp1_Comprovativo_Abril_KDZlyr_26-04-2024_64.zip\Comprovativo_Abril_KDZlyr_26-04-2024_64\Comprovativo_Abril_KDZlyr_26-04-2024_64.vbs" |
Source: C:\Windows\System32\rundll32.exe | Key opened: HKEY_LOCAL_MACHINE\Software\Policies\Microsoft\Windows\Safer\CodeIdentifiers |
Source: unknown | Process created: C:\Windows\System32\rundll32.exe C:\Windows\System32\rundll32.exe C:\Windows\System32\shell32.dll,SHCreateLocalServerRunDll {9aa46009-3ce0-458a-a354-715610a075e6} -Embedding |
Source: unknown | Process created: C:\Program Files\Google\Chrome\Application\chrome.exe "C:\Program Files\Google\Chrome\Application\chrome.exe" --start-maximized --single-argument https://fat-doc.s3.us-east-2.amazonaws.com/Comprovativo_Abril_KDZlyr_26-04-2024_64.zip?=PGNPUKVOPEHCMOLUMNPIBIKXCKFBEBOPMVCSFREHAACJTZHQQDMNCHWFHRMVUUJNQSRQMTOUIHHAGQCFRPLAPBNDXXJPFJOFRPTBGREXQREVKZKSPGDEIIWPFNUPIKPWUBJRXBKAJOLWXREWZSKWGIZHRDXTZPNQBFBZOIVOHCUUZKSOIVSRKQSLE |
Source: C:\Program Files\Google\Chrome\Application\chrome.exe | Process created: C:\Program Files\Google\Chrome\Application\chrome.exe "C:\Program Files\Google\Chrome\Application\chrome.exe" --type=utility --utility-sub-type=network.mojom.NetworkService --lang=en-US --service-sandbox-type=none --mojo-platform-channel-handle=2044 --field-trial-handle=1960,i,8941980370019695632,7496778106780440880,262144 --disable-features=OptimizationGuideModelDownloading,OptimizationHints,OptimizationHintsFetching,OptimizationTargetPrediction /prefetch:8 |
Source: C:\Program Files\Google\Chrome\Application\chrome.exe | Process created: unknown unknown |
Source: C:\Program Files\Google\Chrome\Application\chrome.exe | Process created: unknown unknown |
Source: C:\Program Files\Google\Chrome\Application\chrome.exe | Process created: C:\Program Files\Google\Chrome\Application\chrome.exe "C:\Program Files\Google\Chrome\Application\chrome.exe" --type=utility --utility-sub-type=network.mojom.NetworkService --lang=en-US --service-sandbox-type=none --mojo-platform-channel-handle=2044 --field-trial-handle=1960,i,8941980370019695632,7496778106780440880,262144 --disable-features=OptimizationGuideModelDownloading,OptimizationHints,OptimizationHintsFetching,OptimizationTargetPrediction /prefetch:8 |
Source: C:\Program Files\Google\Chrome\Application\chrome.exe | Process created: unknown unknown |
Source: C:\Program Files\Google\Chrome\Application\chrome.exe | Process created: unknown unknown |
Source: C:\Program Files\Google\Chrome\Application\chrome.exe | Process created: unknown unknown |
Source: C:\Program Files\Google\Chrome\Application\chrome.exe | Process created: unknown unknown |
Source: C:\Program Files\Google\Chrome\Application\chrome.exe | Process created: unknown unknown |
Source: C:\Program Files\Google\Chrome\Application\chrome.exe | Process created: unknown unknown |
Source: C:\Program Files\Google\Chrome\Application\chrome.exe | Process created: unknown unknown |
Source: C:\Program Files\Google\Chrome\Application\chrome.exe | Process created: unknown unknown |
Source: unknown | Process created: C:\Windows\System32\rundll32.exe C:\Windows\System32\rundll32.exe C:\Windows\System32\shell32.dll,SHCreateLocalServerRunDll {9aa46009-3ce0-458a-a354-715610a075e6} -Embedding |
Source: C:\Program Files\Google\Chrome\Application\chrome.exe | Process created: unknown unknown |
Source: unknown | Process created: C:\Windows\System32\wscript.exe "C:\Windows\System32\WScript.exe" "C:\Users\user\AppData\Local\Temp\Temp1_Comprovativo_Abril_KDZlyr_26-04-2024_64.zip\Comprovativo_Abril_KDZlyr_26-04-2024_64\Comprovativo_Abril_KDZlyr_26-04-2024_64.vbs" |
Source: unknown | Process created: C:\Windows\System32\wscript.exe "C:\Windows\System32\WScript.exe" "C:\Users\user\Desktop\Comprovativo_Abril_KDZlyr_26-04-2024_64.vbs" |
Source: unknown | Process created: C:\Windows\System32\wscript.exe "C:\Windows\System32\WScript.exe" "C:\Users\user\Desktop\Comprovativo_Abril_KDZlyr_26-04-2024_64.vbs" |
Source: C:\Windows\System32\wscript.exe | Section loaded: version.dll |
Source: C:\Windows\System32\wscript.exe | Section loaded: kernel.appcore.dll |
Source: C:\Windows\System32\wscript.exe | Section loaded: uxtheme.dll |
Source: C:\Windows\System32\wscript.exe | Section loaded: sxs.dll |
Source: C:\Windows\System32\wscript.exe | Section loaded: vbscript.dll |
Source: C:\Windows\System32\wscript.exe | Section loaded: amsi.dll |
Source: C:\Windows\System32\wscript.exe | Section loaded: userenv.dll |
Source: C:\Windows\System32\wscript.exe | Section loaded: profapi.dll |
Source: C:\Windows\System32\wscript.exe | Section loaded: wldp.dll |
Source: C:\Windows\System32\wscript.exe | Section loaded: msasn1.dll |
Source: C:\Windows\System32\wscript.exe | Section loaded: cryptsp.dll |
Source: C:\Windows\System32\wscript.exe | Section loaded: rsaenh.dll |
Source: C:\Windows\System32\wscript.exe | Section loaded: cryptbase.dll |
Source: C:\Windows\System32\wscript.exe | Section loaded: msisip.dll |
Source: C:\Windows\System32\wscript.exe | Section loaded: wshext.dll |
Source: C:\Windows\System32\wscript.exe | Section loaded: scrobj.dll |
Source: C:\Windows\System32\wscript.exe | Section loaded: version.dll |
Source: C:\Windows\System32\wscript.exe | Section loaded: kernel.appcore.dll |
Source: C:\Windows\System32\wscript.exe | Section loaded: uxtheme.dll |
Source: C:\Windows\System32\wscript.exe | Section loaded: sxs.dll |
Source: C:\Windows\System32\wscript.exe | Section loaded: vbscript.dll |
Source: C:\Windows\System32\wscript.exe | Section loaded: amsi.dll |
Source: C:\Windows\System32\wscript.exe | Section loaded: userenv.dll |
Source: C:\Windows\System32\wscript.exe | Section loaded: profapi.dll |
Source: C:\Windows\System32\wscript.exe | Section loaded: wldp.dll |
Source: C:\Windows\System32\wscript.exe | Section loaded: msasn1.dll |
Source: C:\Windows\System32\wscript.exe | Section loaded: cryptsp.dll |
Source: C:\Windows\System32\wscript.exe | Section loaded: rsaenh.dll |
Source: C:\Windows\System32\wscript.exe | Section loaded: cryptbase.dll |
Source: C:\Windows\System32\wscript.exe | Section loaded: msisip.dll |
Source: C:\Windows\System32\wscript.exe | Section loaded: wshext.dll |
Source: C:\Windows\System32\wscript.exe | Section loaded: scrobj.dll |
Source: C:\Windows\System32\wscript.exe | Section loaded: windows.storage.dll |
Source: C:\Windows\System32\wscript.exe | Section loaded: version.dll |
Source: C:\Windows\System32\wscript.exe | Section loaded: kernel.appcore.dll |
Source: C:\Windows\System32\wscript.exe | Section loaded: uxtheme.dll |
Source: C:\Windows\System32\wscript.exe | Section loaded: sxs.dll |
Source: C:\Windows\System32\wscript.exe | Section loaded: vbscript.dll |
Source: C:\Windows\System32\wscript.exe | Section loaded: amsi.dll |
Source: C:\Windows\System32\wscript.exe | Section loaded: userenv.dll |
Source: C:\Windows\System32\wscript.exe | Section loaded: profapi.dll |
Source: C:\Windows\System32\wscript.exe | Section loaded: wldp.dll |
Source: C:\Windows\System32\wscript.exe | Section loaded: msasn1.dll |
Source: C:\Windows\System32\wscript.exe | Section loaded: cryptsp.dll |
Source: C:\Windows\System32\wscript.exe | Section loaded: rsaenh.dll |
Source: C:\Windows\System32\wscript.exe | Section loaded: cryptbase.dll |
Source: C:\Windows\System32\wscript.exe | Section loaded: msisip.dll |
Source: C:\Windows\System32\wscript.exe | Section loaded: wshext.dll |
Source: C:\Windows\System32\wscript.exe | Section loaded: scrobj.dll |
Source: C:\Windows\System32\wscript.exe | Section loaded: windows.storage.dll |
Source: C:\Windows\System32\wscript.exe | Key value queried: HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{B54F3741-5B07-11cf-A4B0-00AA004A55E8}\InprocServer32 |
Source: C:\Program Files\Google\Chrome\Application\chrome.exe | File created: C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Chrome Apps |
Source: C:\Program Files\Google\Chrome\Application\chrome.exe | File created: C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Chrome Apps\Google Drive.lnk |
Source: C:\Program Files\Google\Chrome\Application\chrome.exe | File created: C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Chrome Apps\YouTube.lnk |
Source: C:\Program Files\Google\Chrome\Application\chrome.exe | File created: C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Chrome Apps\Sheets.lnk |
Source: C:\Program Files\Google\Chrome\Application\chrome.exe | File created: C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Chrome Apps\Gmail.lnk |
Source: C:\Program Files\Google\Chrome\Application\chrome.exe | File created: C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Chrome Apps\Slides.lnk |
Source: C:\Program Files\Google\Chrome\Application\chrome.exe | File created: C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Chrome Apps\Docs.lnk |
Source: C:\Windows\System32\rundll32.exe | Process information set: NOOPENFILEERRORBOX |
Source: C:\Windows\System32\wscript.exe | Process information set: NOOPENFILEERRORBOX |
Source: C:\Windows\System32\wscript.exe | Process information set: NOOPENFILEERRORBOX |
Source: C:\Windows\System32\wscript.exe | Process information set: NOOPENFILEERRORBOX |
Source: C:\Windows\System32\wscript.exe | Process information set: NOOPENFILEERRORBOX |
Source: C:\Windows\System32\wscript.exe | Process information set: NOOPENFILEERRORBOX |
Source: C:\Windows\System32\wscript.exe | Process information set: NOOPENFILEERRORBOX |
Source: Yara match | File source: C:\Users\user\Downloads\596cd038-db66-4afc-815f-ca69191c7893.tmp, type: DROPPED |
Source: Yara match | File source: C:\Users\user\Downloads\596cd038-db66-4afc-815f-ca69191c7893.tmp, type: DROPPED |
Source: C:\Windows\System32\wscript.exe | Window found: window name: WSH-Timer |
Source: C:\Windows\System32\wscript.exe | Window found: window name: WSH-Timer |
Source: C:\Windows\System32\wscript.exe | Window found: window name: WSH-Timer |
Source: C:\Windows\System32\wscript.exe | Key value queried: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Cryptography MachineGuid |