Click to jump to signature section
Source: Submited Sample | Integrated Neural Analysis Model: Matched 99.3% probability |
Source: Catch Me If You Can (2002) 1080p.BluRay.x264.Full 744MB.exe | Static PE information: EXECUTABLE_IMAGE, LINE_NUMS_STRIPPED, LOCAL_SYMS_STRIPPED, BYTES_REVERSED_LO, 32BIT_MACHINE, BYTES_REVERSED_HI |
Source: | Binary string: wntdll.pdbUGP source: Catch Me If You Can (2002) 1080p.BluRay.x264.Full 744MB.exe, 00000001.00000002.1424620774.000000002D7F0000.00000040.00001000.00020000.00000000.sdmp |
Source: | Binary string: wntdll.pdb source: Catch Me If You Can (2002) 1080p.BluRay.x264.Full 744MB.exe, 00000001.00000002.1424620774.000000002D7F0000.00000040.00001000.00020000.00000000.sdmp |
Source: Joe Sandbox View | IP Address: 104.26.13.205 104.26.13.205 |
Source: Joe Sandbox View | IP Address: 104.26.13.205 104.26.13.205 |
Source: unknown | DNS query: name: api.ipify.org |
Source: unknown | DNS query: name: api.ipify.org |
Source: global traffic | HTTP traffic detected: GET /?format=xml HTTP/1.1Accept: */*Accept-Encoding: gzip, deflateUser-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.2; WOW64; Trident/7.0; .NET4.0C; .NET4.0E; .NET CLR 2.0.50727; .NET CLR 3.0.30729; .NET CLR 3.5.30729)Host: api.ipify.orgConnection: Keep-Alive |
Source: unknown | TCP traffic detected without corresponding DNS query: 45.93.201.181 |
Source: unknown | TCP traffic detected without corresponding DNS query: 45.93.201.181 |
Source: unknown | TCP traffic detected without corresponding DNS query: 45.93.201.181 |
Source: unknown | UDP traffic detected without corresponding DNS query: 1.1.1.1 |
Source: global traffic | HTTP traffic detected: GET /?format=xml HTTP/1.1Accept: */*Accept-Encoding: gzip, deflateUser-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.2; WOW64; Trident/7.0; .NET4.0C; .NET4.0E; .NET CLR 2.0.50727; .NET CLR 3.0.30729; .NET CLR 3.5.30729)Host: api.ipify.orgConnection: Keep-Alive |
Source: global traffic | DNS traffic detected: DNS query: api.ipify.org |
Source: Catch Me If You Can (2002) 1080p.BluRay.x264.Full 744MB.exe, 00000008.00000002.3757679565.0000000000578000.00000004.00000020.00020000.00000000.sdmp, Catch Me If You Can (2002) 1080p.BluRay.x264.Full 744MB.exe, 00000008.00000002.3757679565.000000000058E000.00000004.00000020.00020000.00000000.sdmp | String found in binary or memory: http://api.ipify.org/?format=xml |
Source: Catch Me If You Can (2002) 1080p.BluRay.x264.Full 744MB.exe, 00000008.00000002.3757679565.000000000058E000.00000004.00000020.00020000.00000000.sdmp | String found in binary or memory: http://api.ipify.org/?format=xml6 |
Source: Catch Me If You Can (2002) 1080p.BluRay.x264.Full 744MB.exe, 00000008.00000002.3757679565.0000000000598000.00000004.00000020.00020000.00000000.sdmp | String found in binary or memory: http://api.ipify.org/?format=xmlM |
Source: Catch Me If You Can (2002) 1080p.BluRay.x264.Full 744MB.exe, 00000008.00000002.3757679565.0000000000598000.00000004.00000020.00020000.00000000.sdmp | String found in binary or memory: http://api.ipify.org/?format=xmlRRC: |
Source: Catch Me If You Can (2002) 1080p.BluRay.x264.Full 744MB.exe, 00000008.00000002.3757679565.0000000000598000.00000004.00000020.00020000.00000000.sdmp | String found in binary or memory: http://api.ipify.org/?format=xmlS |
Source: Catch Me If You Can (2002) 1080p.BluRay.x264.Full 744MB.exe | String found in binary or memory: http://www.blacksunsoftware.com |
Source: Catch Me If You Can (2002) 1080p.BluRay.x264.Full 744MB.exe | String found in binary or memory: http://www.blacksunsoftware.com/upgrading.htmlopenU |
Source: Catch Me If You Can (2002) 1080p.BluRay.x264.Full 744MB.exe | String found in binary or memory: http://www.blacksunsoftware.com/version/colormania.txt |
Source: Catch Me If You Can (2002) 1080p.BluRay.x264.Full 744MB.exe | String found in binary or memory: http://www.blacksunsoftware.comD |
Source: Catch Me If You Can (2002) 1080p.BluRay.x264.Full 744MB.exe | String found in binary or memory: http://www.blacksunsoftware.comS |
Source: Catch Me If You Can (2002) 1080p.BluRay.x264.Full 744MB.exe | String found in binary or memory: http://www.blacksunsoftware.comopen |
Source: Catch Me If You Can (2002) 1080p.BluRay.x264.Full 744MB.exe | String found in binary or memory: http://www.blacksunsoftware.comopenU |
Source: Catch Me If You Can (2002) 1080p.BluRay.x264.Full 744MB.exe, 00000008.00000002.3757679565.00000000005E0000.00000004.00000020.00020000.00000000.sdmp | String found in binary or memory: https://login.live.comP |
Source: 00000001.00000002.1425700818.000000002DAE0000.00000004.00001000.00020000.00000000.sdmp, type: MEMORY | Matched rule: Windows_Trojan_Fickerstealer_f2159bec Author: unknown |
Source: 00000008.00000002.3757232649.0000000000400000.00000040.00000400.00020000.00000000.sdmp, type: MEMORY | Matched rule: Windows_Trojan_Fickerstealer_f2159bec Author: unknown |
Source: Catch Me If You Can (2002) 1080p.BluRay.x264.Full 744MB.exe | Static PE information: section name: |
Source: C:\Users\user\Desktop\Catch Me If You Can (2002) 1080p.BluRay.x264.Full 744MB.exe | Process Stats: CPU usage > 49% |
Source: Catch Me If You Can (2002) 1080p.BluRay.x264.Full 744MB.exe | Static PE information: Number of sections : 13 > 10 |
Source: Catch Me If You Can (2002) 1080p.BluRay.x264.Full 744MB.exe, 00000001.00000002.1424620774.000000002D91D000.00000040.00001000.00020000.00000000.sdmp | Binary or memory string: OriginalFilenamentdll.dllj% vs Catch Me If You Can (2002) 1080p.BluRay.x264.Full 744MB.exe |
Source: Catch Me If You Can (2002) 1080p.BluRay.x264.Full 744MB.exe, 00000001.00000000.1240945423.000000000041D000.00000020.00000001.01000000.00000006.sdmp | Binary or memory string: OriginalFilename vs Catch Me If You Can (2002) 1080p.BluRay.x264.Full 744MB.exe |
Source: Catch Me If You Can (2002) 1080p.BluRay.x264.Full 744MB.exe, 00000001.00000002.1423809796.000000002D427000.00000004.00001000.00020000.00000000.sdmp | Binary or memory string: OriginalFilenameCOMCTL32.DLL.MUIj% vs Catch Me If You Can (2002) 1080p.BluRay.x264.Full 744MB.exe |
Source: Catch Me If You Can (2002) 1080p.BluRay.x264.Full 744MB.exe | Binary or memory string: OriginalFilename vs Catch Me If You Can (2002) 1080p.BluRay.x264.Full 744MB.exe |
Source: Catch Me If You Can (2002) 1080p.BluRay.x264.Full 744MB.exe | Static PE information: EXECUTABLE_IMAGE, LINE_NUMS_STRIPPED, LOCAL_SYMS_STRIPPED, BYTES_REVERSED_LO, 32BIT_MACHINE, BYTES_REVERSED_HI |
Source: 00000001.00000002.1425700818.000000002DAE0000.00000004.00001000.00020000.00000000.sdmp, type: MEMORY | Matched rule: Windows_Trojan_Fickerstealer_f2159bec reference_sample = a4113ccb55e06e783b6cb213647614f039aa7dbb454baa338459ccf37897ebd6, os = windows, severity = x86, creation_date = 2021-07-22, scan_context = file, memory, license = Elastic License v2, threat_name = Windows.Trojan.Fickerstealer, fingerprint = 0671691c6d5c7177fe155e4076ab39bf5f909ed300f32c1530e80d471dff0296, id = f2159bec-a3ce-47a9-91ad-43b8a19ac172, last_modified = 2021-08-23 |
Source: 00000008.00000002.3757232649.0000000000400000.00000040.00000400.00020000.00000000.sdmp, type: MEMORY | Matched rule: Windows_Trojan_Fickerstealer_f2159bec reference_sample = a4113ccb55e06e783b6cb213647614f039aa7dbb454baa338459ccf37897ebd6, os = windows, severity = x86, creation_date = 2021-07-22, scan_context = file, memory, license = Elastic License v2, threat_name = Windows.Trojan.Fickerstealer, fingerprint = 0671691c6d5c7177fe155e4076ab39bf5f909ed300f32c1530e80d471dff0296, id = f2159bec-a3ce-47a9-91ad-43b8a19ac172, last_modified = 2021-08-23 |
Source: Catch Me If You Can (2002) 1080p.BluRay.x264.Full 744MB.exe | Static PE information: Section: uYFHVLAW ZLIB complexity 0.9960201027526395 |
Source: classification engine | Classification label: mal72.evad.winEXE@3/2@1/2 |
Source: C:\Users\user\Desktop\Catch Me If You Can (2002) 1080p.BluRay.x264.Full 744MB.exe | File created: C:\Users\user\AppData\Local\Microsoft\Windows\INetCache\IE\ZVZFKMB9\ETO08RL7.txt | Jump to behavior |
Source: C:\Users\user\Desktop\Catch Me If You Can (2002) 1080p.BluRay.x264.Full 744MB.exe | Mutant created: \Sessions\1\BaseNamedObjects\ah;waeh;isfdgaf |
Source: C:\Users\user\Desktop\Catch Me If You Can (2002) 1080p.BluRay.x264.Full 744MB.exe | Mutant created: \Sessions\1\BaseNamedObjects\o;awefijo;ijo; |
Source: C:\Users\user\Desktop\Catch Me If You Can (2002) 1080p.BluRay.x264.Full 744MB.exe | Mutant created: \Sessions\1\BaseNamedObjects\wh;ijo;h |
Source: C:\Users\user\Desktop\Catch Me If You Can (2002) 1080p.BluRay.x264.Full 744MB.exe | Mutant created: \Sessions\1\BaseNamedObjects\hrth |
Source: C:\Users\user\Desktop\Catch Me If You Can (2002) 1080p.BluRay.x264.Full 744MB.exe | Mutant created: \Sessions\1\BaseNamedObjects\ho;ah |
Source: C:\Users\user\Desktop\Catch Me If You Can (2002) 1080p.BluRay.x264.Full 744MB.exe | Mutant created: \Sessions\1\BaseNamedObjects\whoareyoutellmeandilltellwhoyou |
Source: C:\Users\user\Desktop\Catch Me If You Can (2002) 1080p.BluRay.x264.Full 744MB.exe | Mutant created: \Sessions\1\BaseNamedObjects\ijlhlkwah;joi;i |
Source: Yara match | File source: 00000001.00000000.1240945423.0000000000401000.00000020.00000001.01000000.00000006.sdmp, type: MEMORY |
Source: C:\Users\user\Desktop\Catch Me If You Can (2002) 1080p.BluRay.x264.Full 744MB.exe | Key opened: HKEY_CURRENT_USER\Software\Borland\Delphi\Locales | Jump to behavior |
Source: C:\Users\user\Desktop\Catch Me If You Can (2002) 1080p.BluRay.x264.Full 744MB.exe | Key opened: HKEY_CURRENT_USER\Software\Borland\Delphi\Locales | Jump to behavior |
Source: C:\Users\user\Desktop\Catch Me If You Can (2002) 1080p.BluRay.x264.Full 744MB.exe | Key opened: HKEY_CURRENT_USER\Software\Policies\Microsoft\Windows\Safer\CodeIdentifiers | Jump to behavior |
Source: unknown | Process created: C:\Users\user\Desktop\Catch Me If You Can (2002) 1080p.BluRay.x264.Full 744MB.exe "C:\Users\user\Desktop\Catch Me If You Can (2002) 1080p.BluRay.x264.Full 744MB.exe" | |
Source: C:\Users\user\Desktop\Catch Me If You Can (2002) 1080p.BluRay.x264.Full 744MB.exe | Process created: C:\Users\user\Desktop\Catch Me If You Can (2002) 1080p.BluRay.x264.Full 744MB.exe "C:\Users\user\Desktop\Catch Me If You Can (2002) 1080p.BluRay.x264.Full 744MB.exe" | |
Source: C:\Users\user\Desktop\Catch Me If You Can (2002) 1080p.BluRay.x264.Full 744MB.exe | Process created: C:\Users\user\Desktop\Catch Me If You Can (2002) 1080p.BluRay.x264.Full 744MB.exe "C:\Users\user\Desktop\Catch Me If You Can (2002) 1080p.BluRay.x264.Full 744MB.exe" | Jump to behavior |
Source: C:\Users\user\Desktop\Catch Me If You Can (2002) 1080p.BluRay.x264.Full 744MB.exe | Section loaded: apphelp.dll | Jump to behavior |
Source: C:\Users\user\Desktop\Catch Me If You Can (2002) 1080p.BluRay.x264.Full 744MB.exe | Section loaded: wininet.dll | Jump to behavior |
Source: C:\Users\user\Desktop\Catch Me If You Can (2002) 1080p.BluRay.x264.Full 744MB.exe | Section loaded: version.dll | Jump to behavior |
Source: C:\Users\user\Desktop\Catch Me If You Can (2002) 1080p.BluRay.x264.Full 744MB.exe | Section loaded: netapi32.dll | Jump to behavior |
Source: C:\Users\user\Desktop\Catch Me If You Can (2002) 1080p.BluRay.x264.Full 744MB.exe | Section loaded: netutils.dll | Jump to behavior |
Source: C:\Users\user\Desktop\Catch Me If You Can (2002) 1080p.BluRay.x264.Full 744MB.exe | Section loaded: uxtheme.dll | Jump to behavior |
Source: C:\Users\user\Desktop\Catch Me If You Can (2002) 1080p.BluRay.x264.Full 744MB.exe | Section loaded: kernel.appcore.dll | Jump to behavior |
Source: C:\Users\user\Desktop\Catch Me If You Can (2002) 1080p.BluRay.x264.Full 744MB.exe | Section loaded: wtsapi32.dll | Jump to behavior |
Source: C:\Users\user\Desktop\Catch Me If You Can (2002) 1080p.BluRay.x264.Full 744MB.exe | Section loaded: winsta.dll | Jump to behavior |
Source: C:\Users\user\Desktop\Catch Me If You Can (2002) 1080p.BluRay.x264.Full 744MB.exe | Section loaded: userenv.dll | Jump to behavior |
Source: C:\Users\user\Desktop\Catch Me If You Can (2002) 1080p.BluRay.x264.Full 744MB.exe | Section loaded: cryptbase.dll | Jump to behavior |
Source: C:\Users\user\Desktop\Catch Me If You Can (2002) 1080p.BluRay.x264.Full 744MB.exe | Section loaded: urlmon.dll | Jump to behavior |
Source: C:\Users\user\Desktop\Catch Me If You Can (2002) 1080p.BluRay.x264.Full 744MB.exe | Section loaded: iertutil.dll | Jump to behavior |
Source: C:\Users\user\Desktop\Catch Me If You Can (2002) 1080p.BluRay.x264.Full 744MB.exe | Section loaded: srvcli.dll | Jump to behavior |
Source: C:\Users\user\Desktop\Catch Me If You Can (2002) 1080p.BluRay.x264.Full 744MB.exe | Section loaded: netutils.dll | Jump to behavior |
Source: C:\Users\user\Desktop\Catch Me If You Can (2002) 1080p.BluRay.x264.Full 744MB.exe | Section loaded: kernel.appcore.dll | Jump to behavior |
Source: C:\Users\user\Desktop\Catch Me If You Can (2002) 1080p.BluRay.x264.Full 744MB.exe | Section loaded: uxtheme.dll | Jump to behavior |
Source: C:\Users\user\Desktop\Catch Me If You Can (2002) 1080p.BluRay.x264.Full 744MB.exe | Section loaded: textshaping.dll | Jump to behavior |
Source: C:\Users\user\Desktop\Catch Me If You Can (2002) 1080p.BluRay.x264.Full 744MB.exe | Section loaded: wininet.dll | Jump to behavior |
Source: C:\Users\user\Desktop\Catch Me If You Can (2002) 1080p.BluRay.x264.Full 744MB.exe | Section loaded: sspicli.dll | Jump to behavior |
Source: C:\Users\user\Desktop\Catch Me If You Can (2002) 1080p.BluRay.x264.Full 744MB.exe | Section loaded: windows.storage.dll | Jump to behavior |
Source: C:\Users\user\Desktop\Catch Me If You Can (2002) 1080p.BluRay.x264.Full 744MB.exe | Section loaded: wldp.dll | Jump to behavior |
Source: C:\Users\user\Desktop\Catch Me If You Can (2002) 1080p.BluRay.x264.Full 744MB.exe | Section loaded: profapi.dll | Jump to behavior |
Source: C:\Users\user\Desktop\Catch Me If You Can (2002) 1080p.BluRay.x264.Full 744MB.exe | Section loaded: textinputframework.dll | Jump to behavior |
Source: C:\Users\user\Desktop\Catch Me If You Can (2002) 1080p.BluRay.x264.Full 744MB.exe | Section loaded: coreuicomponents.dll | Jump to behavior |
Source: C:\Users\user\Desktop\Catch Me If You Can (2002) 1080p.BluRay.x264.Full 744MB.exe | Section loaded: coremessaging.dll | Jump to behavior |
Source: C:\Users\user\Desktop\Catch Me If You Can (2002) 1080p.BluRay.x264.Full 744MB.exe | Section loaded: ntmarta.dll | Jump to behavior |
Source: C:\Users\user\Desktop\Catch Me If You Can (2002) 1080p.BluRay.x264.Full 744MB.exe | Section loaded: coremessaging.dll | Jump to behavior |
Source: C:\Users\user\Desktop\Catch Me If You Can (2002) 1080p.BluRay.x264.Full 744MB.exe | Section loaded: wintypes.dll | Jump to behavior |
Source: C:\Users\user\Desktop\Catch Me If You Can (2002) 1080p.BluRay.x264.Full 744MB.exe | Section loaded: wintypes.dll | Jump to behavior |
Source: C:\Users\user\Desktop\Catch Me If You Can (2002) 1080p.BluRay.x264.Full 744MB.exe | Section loaded: wintypes.dll | Jump to behavior |
Source: C:\Users\user\Desktop\Catch Me If You Can (2002) 1080p.BluRay.x264.Full 744MB.exe | Section loaded: ondemandconnroutehelper.dll | Jump to behavior |
Source: C:\Users\user\Desktop\Catch Me If You Can (2002) 1080p.BluRay.x264.Full 744MB.exe | Section loaded: winhttp.dll | Jump to behavior |
Source: C:\Users\user\Desktop\Catch Me If You Can (2002) 1080p.BluRay.x264.Full 744MB.exe | Section loaded: mswsock.dll | Jump to behavior |
Source: C:\Users\user\Desktop\Catch Me If You Can (2002) 1080p.BluRay.x264.Full 744MB.exe | Section loaded: iphlpapi.dll | Jump to behavior |
Source: C:\Users\user\Desktop\Catch Me If You Can (2002) 1080p.BluRay.x264.Full 744MB.exe | Section loaded: winnsi.dll | Jump to behavior |
Source: C:\Users\user\Desktop\Catch Me If You Can (2002) 1080p.BluRay.x264.Full 744MB.exe | Section loaded: dnsapi.dll | Jump to behavior |
Source: C:\Users\user\Desktop\Catch Me If You Can (2002) 1080p.BluRay.x264.Full 744MB.exe | Section loaded: rasadhlp.dll | Jump to behavior |
Source: C:\Users\user\Desktop\Catch Me If You Can (2002) 1080p.BluRay.x264.Full 744MB.exe | Section loaded: fwpuclnt.dll | Jump to behavior |
Source: C:\Users\user\Desktop\Catch Me If You Can (2002) 1080p.BluRay.x264.Full 744MB.exe | Key value queried: HKEY_LOCAL_MACHINE\SOFTWARE\Classes\WOW6432Node\CLSID\{057EEE47-2572-4AA1-88D7-60CE2149E33C}\InProcServer32 | Jump to behavior |
Source: Catch Me If You Can (2002) 1080p.BluRay.x264.Full 744MB.exe | Static PE information: Virtual size of .text is bigger than: 0x100000 |
Source: Catch Me If You Can (2002) 1080p.BluRay.x264.Full 744MB.exe | Static file information: File size 724063744 > 1048576 |
Source: Catch Me If You Can (2002) 1080p.BluRay.x264.Full 744MB.exe | Static PE information: Raw size of .text is bigger than: 0x100000 < 0x368200 |
Source: Catch Me If You Can (2002) 1080p.BluRay.x264.Full 744MB.exe | Static PE information: Raw size of Performv is bigger than: 0x100000 < 0x2addfa00 |
Source: Catch Me If You Can (2002) 1080p.BluRay.x264.Full 744MB.exe | Static PE information: More than 200 imports for user32.dll |
Source: | Binary string: wntdll.pdbUGP source: Catch Me If You Can (2002) 1080p.BluRay.x264.Full 744MB.exe, 00000001.00000002.1424620774.000000002D7F0000.00000040.00001000.00020000.00000000.sdmp |
Source: | Binary string: wntdll.pdb source: Catch Me If You Can (2002) 1080p.BluRay.x264.Full 744MB.exe, 00000001.00000002.1424620774.000000002D7F0000.00000040.00001000.00020000.00000000.sdmp |
Source: Catch Me If You Can (2002) 1080p.BluRay.x264.Full 744MB.exe | Static PE information: section name: .didata |
Source: Catch Me If You Can (2002) 1080p.BluRay.x264.Full 744MB.exe | Static PE information: section name: |
Source: Catch Me If You Can (2002) 1080p.BluRay.x264.Full 744MB.exe | Static PE information: section name: uYFHVLAW |
Source: Catch Me If You Can (2002) 1080p.BluRay.x264.Full 744MB.exe | Static PE information: section name: Performv |
Source: Catch Me If You Can (2002) 1080p.BluRay.x264.Full 744MB.exe | Static PE information: section name: uYFHVLAW entropy: 7.996713302303785 |
Source: C:\Users\user\Desktop\Catch Me If You Can (2002) 1080p.BluRay.x264.Full 744MB.exe | File created: \catch me if you can (2002) 1080p.bluray.x264.full 744mb.exe | |
Source: C:\Users\user\Desktop\Catch Me If You Can (2002) 1080p.BluRay.x264.Full 744MB.exe | File created: \catch me if you can (2002) 1080p.bluray.x264.full 744mb.exe | Jump to behavior |
Source: C:\Users\user\Desktop\Catch Me If You Can (2002) 1080p.BluRay.x264.Full 744MB.exe | Memory written: PID: 2020 base: 77752EC0 value: E9 3B D1 A6 88 | Jump to behavior |
Source: C:\Users\user\Desktop\Catch Me If You Can (2002) 1080p.BluRay.x264.Full 744MB.exe | Process information set: FAILCRITICALERRORS | NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\Catch Me If You Can (2002) 1080p.BluRay.x264.Full 744MB.exe | Process information set: FAILCRITICALERRORS | NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\Catch Me If You Can (2002) 1080p.BluRay.x264.Full 744MB.exe | RDTSC instruction interceptor: First address: 944798 second address: 94479C instructions: 0x00000000 rdtsc 0x00000002 dec ch 0x00000004 rdtsc |
Source: C:\Users\user\Desktop\Catch Me If You Can (2002) 1080p.BluRay.x264.Full 744MB.exe | RDTSC instruction interceptor: First address: 94479C second address: 9447AA instructions: 0x00000000 rdtsc 0x00000002 jmp 00007F31E0F3E5BCh 0x00000004 rdtsc |
Source: Catch Me If You Can (2002) 1080p.BluRay.x264.Full 744MB.exe, 00000008.00000002.3757679565.0000000000608000.00000004.00000020.00020000.00000000.sdmp, Catch Me If You Can (2002) 1080p.BluRay.x264.Full 744MB.exe, 00000008.00000002.3757679565.0000000000598000.00000004.00000020.00020000.00000000.sdmp | Binary or memory string: Hyper-V RAW |
Source: C:\Users\user\Desktop\Catch Me If You Can (2002) 1080p.BluRay.x264.Full 744MB.exe | Memory allocated: page read and write | page guard | Jump to behavior |
Source: C:\Users\user\Desktop\Catch Me If You Can (2002) 1080p.BluRay.x264.Full 744MB.exe | Memory written: PID: 2020 base: 77752EC0 value: E9 | Jump to behavior |
Source: C:\Users\user\Desktop\Catch Me If You Can (2002) 1080p.BluRay.x264.Full 744MB.exe | Memory written: C:\Users\user\Desktop\Catch Me If You Can (2002) 1080p.BluRay.x264.Full 744MB.exe base: 400000 value starts with: 4D5A | Jump to behavior |
Source: C:\Users\user\Desktop\Catch Me If You Can (2002) 1080p.BluRay.x264.Full 744MB.exe | Process created: C:\Users\user\Desktop\Catch Me If You Can (2002) 1080p.BluRay.x264.Full 744MB.exe "C:\Users\user\Desktop\Catch Me If You Can (2002) 1080p.BluRay.x264.Full 744MB.exe" | Jump to behavior |
Source: Catch Me If You Can (2002) 1080p.BluRay.x264.Full 744MB.exe | Binary or memory string: Shell_TrayWndTrayNotifyWndSV |