Loading Joe Sandbox Report ...

Edit tour

Windows Analysis Report
SimpleLoader v2.1.exe1.exe

Overview

General Information

Sample name:SimpleLoader v2.1.exe1.exe
Analysis ID:1637271
MD5:eff5d3bc8920a72ad1bb26e34e3f5132
SHA1:672aafe1ddd2a21ce76d04d287ac1ec0ae60087b
SHA256:cfcf4fec48112057c235868a2561693719656dd179862b895de3908bd8f4956c
Tags:exeuser-TornadoAV_dev
Infos:

Detection

LummaC Stealer
Score:100
Range:0 - 100
Confidence:100%

Signatures

Antivirus detection for URL or domain
Found malware configuration
Multi AV Scanner detection for submitted file
Yara detected LummaC Stealer
C2 URLs / IPs found in malware configuration
Contains functionality to inject code into remote processes
Found many strings related to Crypto-Wallets (likely being stolen)
Injects a PE file into a foreign processes
Queries sensitive video device information (via WMI, Win32_VideoController, often done to detect virtual machines)
Query firmware table information (likely to detect VMs)
Sample uses string decryption to hide its real strings
Tries to harvest and steal browser information (history, passwords, etc)
Tries to harvest and steal ftp login credentials
Tries to steal Crypto Currency Wallets
AV process strings found (often used to terminate AV products)
Checks if Antivirus/Antispyware/Firewall program is installed (via WMI)
Contains functionality for read data from the clipboard
Contains functionality to access loader functionality (e.g. LdrGetProcedureAddress)
Contains functionality to check if a debugger is running (IsDebuggerPresent)
Contains functionality to modify clipboard data
Contains functionality to query locales information (e.g. system language)
Contains functionality to read the PEB
Contains functionality to read the clipboard data
Contains functionality to record screenshots
Contains functionality which may be used to detect a debugger (GetProcessHeap)
Creates a process in suspended mode (likely to inject code)
Detected potential crypto function
Found a high number of Window / User specific system calls (may be a loop to detect user behavior)
Found inlined nop instructions (likely shell or obfuscated code)
Found potential string decryption / allocating functions
HTTP GET or POST without a user agent
IP address seen in connection with other malware
Internet Provider seen in connection with other malware
JA3 SSL client fingerprint seen in connection with other malware
May sleep (evasive loops) to hinder dynamic analysis
PE / OLE file has an invalid certificate
Queries sensitive BIOS Information (via WMI, Win32_Bios & Win32_BaseBoard, often done to detect virtual machines)
Queries the volume information (name, serial number etc) of a device
Sample execution stops while process was sleeping (likely an evasion)
Searches for user specific document files
Suricata IDS alerts with low severity for network traffic
Uses 32bit PE files
Uses Microsoft's Enhanced Cryptographic Provider
Uses a known web browser user agent for HTTP communication
Uses code obfuscation techniques (call, push, ret)
Yara detected Credential Stealer

Classification

  • System is w10x64
  • SimpleLoader v2.1.exe1.exe (PID: 6396 cmdline: "C:\Users\user\Desktop\SimpleLoader v2.1.exe1.exe" MD5: EFF5D3BC8920A72AD1BB26E34E3F5132)
    • SimpleLoader v2.1.exe1.exe (PID: 6636 cmdline: "C:\Users\user\Desktop\SimpleLoader v2.1.exe1.exe" MD5: EFF5D3BC8920A72AD1BB26E34E3F5132)
    • SimpleLoader v2.1.exe1.exe (PID: 6632 cmdline: "C:\Users\user\Desktop\SimpleLoader v2.1.exe1.exe" MD5: EFF5D3BC8920A72AD1BB26E34E3F5132)
    • SimpleLoader v2.1.exe1.exe (PID: 6680 cmdline: "C:\Users\user\Desktop\SimpleLoader v2.1.exe1.exe" MD5: EFF5D3BC8920A72AD1BB26E34E3F5132)
  • cleanup
{"C2 url": ["decorathnome.icu/ABbss", "crosshairc.life/dAnjhw", "mrodularmall.top/aNzS", "jowinjoinery.icu/bdWUa", "legenassedk.top/bdpWO", "htardwarehu.icu/Sbdsa", "cjlaspcorne.icu/DbIps", "bugildbett.top/bAuz"], "Build id": "b4287a743f335371bbe1c5776c8678552b93aece476cd0a7b2d34d7b"}
SourceRuleDescriptionAuthorStrings
00000004.00000002.2609424437.0000000000400000.00000040.00000400.00020000.00000000.sdmpJoeSecurity_LummaCStealer_4Yara detected LummaC StealerJoe Security
    00000000.00000002.1370342630.0000000001147000.00000004.00000020.00020000.00000000.sdmpJoeSecurity_LummaCStealer_4Yara detected LummaC StealerJoe Security
      00000004.00000003.1520289258.0000000001049000.00000004.00000020.00020000.00000000.sdmpJoeSecurity_CredentialStealerYara detected Credential StealerJoe Security
        00000004.00000003.1477891390.0000000001093000.00000004.00000020.00020000.00000000.sdmpJoeSecurity_CredentialStealerYara detected Credential StealerJoe Security
          00000004.00000003.1520161620.000000000109D000.00000004.00000020.00020000.00000000.sdmpJoeSecurity_CredentialStealerYara detected Credential StealerJoe Security
            Click to see the 3 entries
            SourceRuleDescriptionAuthorStrings
            4.2.SimpleLoader v2.1.exe1.exe.400000.0.raw.unpackJoeSecurity_LummaCStealer_4Yara detected LummaC StealerJoe Security
              4.2.SimpleLoader v2.1.exe1.exe.400000.0.unpackJoeSecurity_LummaCStealer_4Yara detected LummaC StealerJoe Security
                No Sigma rule has matched
                TimestampSIDSeverityClasstypeSource IPSource PortDestination IPDestination PortProtocol
                2025-03-13T13:33:32.771778+010020283713Unknown Traffic192.168.2.649687149.154.167.99443TCP
                2025-03-13T13:33:35.321046+010020283713Unknown Traffic192.168.2.649688172.67.144.37443TCP
                2025-03-13T13:33:36.660991+010020283713Unknown Traffic192.168.2.649689172.67.144.37443TCP
                2025-03-13T13:33:39.070480+010020283713Unknown Traffic192.168.2.649690172.67.144.37443TCP
                2025-03-13T13:33:41.189411+010020283713Unknown Traffic192.168.2.649691172.67.144.37443TCP
                2025-03-13T13:33:44.206390+010020283713Unknown Traffic192.168.2.649692172.67.144.37443TCP
                2025-03-13T13:33:47.875469+010020283713Unknown Traffic192.168.2.649694172.67.144.37443TCP
                2025-03-13T13:33:51.297930+010020283713Unknown Traffic192.168.2.649697172.67.144.37443TCP
                2025-03-13T13:33:55.169599+010020283713Unknown Traffic192.168.2.649700172.67.144.37443TCP

                Click to jump to signature section

                Show All Signature Results

                AV Detection

                barindex
                Source: crosshairc.life/dAnjhwAvira URL Cloud: Label: malware
                Source: 00000000.00000002.1370342630.0000000001147000.00000004.00000020.00020000.00000000.sdmpMalware Configuration Extractor: LummaC {"C2 url": ["decorathnome.icu/ABbss", "crosshairc.life/dAnjhw", "mrodularmall.top/aNzS", "jowinjoinery.icu/bdWUa", "legenassedk.top/bdpWO", "htardwarehu.icu/Sbdsa", "cjlaspcorne.icu/DbIps", "bugildbett.top/bAuz"], "Build id": "b4287a743f335371bbe1c5776c8678552b93aece476cd0a7b2d34d7b"}
                Source: SimpleLoader v2.1.exe1.exeVirustotal: Detection: 42%Perma Link
                Source: SimpleLoader v2.1.exe1.exeReversingLabs: Detection: 39%
                Source: 00000000.00000002.1370342630.0000000001147000.00000004.00000020.00020000.00000000.sdmpString decryptor: decorathnome.icu/ABbss
                Source: 00000000.00000002.1370342630.0000000001147000.00000004.00000020.00020000.00000000.sdmpString decryptor: crosshairc.life/dAnjhw
                Source: 00000000.00000002.1370342630.0000000001147000.00000004.00000020.00020000.00000000.sdmpString decryptor: mrodularmall.top/aNzS
                Source: 00000000.00000002.1370342630.0000000001147000.00000004.00000020.00020000.00000000.sdmpString decryptor: jowinjoinery.icu/bdWUa
                Source: 00000000.00000002.1370342630.0000000001147000.00000004.00000020.00020000.00000000.sdmpString decryptor: legenassedk.top/bdpWO
                Source: 00000000.00000002.1370342630.0000000001147000.00000004.00000020.00020000.00000000.sdmpString decryptor: htardwarehu.icu/Sbdsa
                Source: 00000000.00000002.1370342630.0000000001147000.00000004.00000020.00020000.00000000.sdmpString decryptor: cjlaspcorne.icu/DbIps
                Source: 00000000.00000002.1370342630.0000000001147000.00000004.00000020.00020000.00000000.sdmpString decryptor: bugildbett.top/bAuz
                Source: C:\Users\user\Desktop\SimpleLoader v2.1.exe1.exeCode function: 4_2_0041CAA0 CryptUnprotectData,CryptUnprotectData,4_2_0041CAA0
                Source: C:\Users\user\Desktop\SimpleLoader v2.1.exe1.exeCode function: 4_2_0041BED0 CryptUnprotectData,4_2_0041BED0
                Source: SimpleLoader v2.1.exe1.exeStatic PE information: EXECUTABLE_IMAGE, 32BIT_MACHINE
                Source: unknownHTTPS traffic detected: 149.154.167.99:443 -> 192.168.2.6:49687 version: TLS 1.2
                Source: unknownHTTPS traffic detected: 172.67.144.37:443 -> 192.168.2.6:49689 version: TLS 1.2
                Source: unknownHTTPS traffic detected: 172.67.144.37:443 -> 192.168.2.6:49690 version: TLS 1.2
                Source: unknownHTTPS traffic detected: 172.67.144.37:443 -> 192.168.2.6:49691 version: TLS 1.2
                Source: unknownHTTPS traffic detected: 172.67.144.37:443 -> 192.168.2.6:49692 version: TLS 1.2
                Source: unknownHTTPS traffic detected: 172.67.144.37:443 -> 192.168.2.6:49694 version: TLS 1.2
                Source: unknownHTTPS traffic detected: 172.67.144.37:443 -> 192.168.2.6:49697 version: TLS 1.2
                Source: unknownHTTPS traffic detected: 172.67.144.37:443 -> 192.168.2.6:49700 version: TLS 1.2
                Source: SimpleLoader v2.1.exe1.exeStatic PE information: DYNAMIC_BASE, NX_COMPAT, TERMINAL_SERVER_AWARE
                Source: C:\Users\user\Desktop\SimpleLoader v2.1.exe1.exeCode function: 0_2_00628ECE FindFirstFileExW,0_2_00628ECE
                Source: C:\Users\user\Desktop\SimpleLoader v2.1.exe1.exeCode function: 0_2_00628F7F FindFirstFileExW,FindNextFileW,FindClose,FindClose,0_2_00628F7F
                Source: C:\Users\user\Desktop\SimpleLoader v2.1.exe1.exeCode function: 2_2_00628ECE FindFirstFileExW,2_2_00628ECE
                Source: C:\Users\user\Desktop\SimpleLoader v2.1.exe1.exeCode function: 2_2_00628F7F FindFirstFileExW,FindNextFileW,FindClose,FindClose,2_2_00628F7F
                Source: C:\Users\user\Desktop\SimpleLoader v2.1.exe1.exeCode function: 4x nop then movzx esi, byte ptr [esp+ecx+3EEB158Ah]4_2_0040D880
                Source: C:\Users\user\Desktop\SimpleLoader v2.1.exe1.exeCode function: 4x nop then cmp word ptr [edi+ebx], 0000h4_2_0044E140
                Source: C:\Users\user\Desktop\SimpleLoader v2.1.exe1.exeCode function: 4x nop then cmp dword ptr [esi+edx*8], C0F3A0E1h4_2_0044C13E
                Source: C:\Users\user\Desktop\SimpleLoader v2.1.exe1.exeCode function: 4x nop then movzx ecx, byte ptr [esp+eax+000000E0h]4_2_00411A86
                Source: C:\Users\user\Desktop\SimpleLoader v2.1.exe1.exeCode function: 4x nop then cmp dword ptr [esi+edx*8], 18A944CDh4_2_0041CAA0
                Source: C:\Users\user\Desktop\SimpleLoader v2.1.exe1.exeCode function: 4x nop then mov eax, ecx4_2_0041CAA0
                Source: C:\Users\user\Desktop\SimpleLoader v2.1.exe1.exeCode function: 4x nop then mov byte ptr [esi], cl4_2_00439E3D
                Source: C:\Users\user\Desktop\SimpleLoader v2.1.exe1.exeCode function: 4x nop then movzx esi, byte ptr [esp+ecx+00000160h]4_2_0041BED0
                Source: C:\Users\user\Desktop\SimpleLoader v2.1.exe1.exeCode function: 4x nop then movzx edx, byte ptr [esp+eax+000002E8h]4_2_0041BED0
                Source: C:\Users\user\Desktop\SimpleLoader v2.1.exe1.exeCode function: 4x nop then movzx ecx, byte ptr [esp+eax+7002D656h]4_2_00430EF0
                Source: C:\Users\user\Desktop\SimpleLoader v2.1.exe1.exeCode function: 4x nop then movzx edx, byte ptr [esp+ecx+04h]4_2_0044B695
                Source: C:\Users\user\Desktop\SimpleLoader v2.1.exe1.exeCode function: 4x nop then cmp dword ptr [edx+ecx*8], 743EDB10h4_2_0044E850
                Source: C:\Users\user\Desktop\SimpleLoader v2.1.exe1.exeCode function: 4x nop then movzx ecx, byte ptr [esp+eax-000000DAh]4_2_0044E850
                Source: C:\Users\user\Desktop\SimpleLoader v2.1.exe1.exeCode function: 4x nop then movzx eax, word ptr [ecx]4_2_0044E850
                Source: C:\Users\user\Desktop\SimpleLoader v2.1.exe1.exeCode function: 4x nop then cmp dword ptr [edi+esi*8], 1ED597A4h4_2_0044A0E0
                Source: C:\Users\user\Desktop\SimpleLoader v2.1.exe1.exeCode function: 4x nop then mov ebx, dword ptr [edi+04h]4_2_00435090
                Source: C:\Users\user\Desktop\SimpleLoader v2.1.exe1.exeCode function: 4x nop then movsx eax, byte ptr [esi+ecx]4_2_0041B150
                Source: C:\Users\user\Desktop\SimpleLoader v2.1.exe1.exeCode function: 4x nop then movzx edx, byte ptr [esp+eax-3A6108A1h]4_2_00423938
                Source: C:\Users\user\Desktop\SimpleLoader v2.1.exe1.exeCode function: 4x nop then movzx ecx, word ptr [ebx+eax]4_2_0042A1D0
                Source: C:\Users\user\Desktop\SimpleLoader v2.1.exe1.exeCode function: 4x nop then cmp dword ptr [esi+edx*8], 93A82FD1h4_2_0042A1D0
                Source: C:\Users\user\Desktop\SimpleLoader v2.1.exe1.exeCode function: 4x nop then mov word ptr [eax], cx4_2_004219EE
                Source: C:\Users\user\Desktop\SimpleLoader v2.1.exe1.exeCode function: 4x nop then movzx edx, byte ptr [esp+ecx-30929966h]4_2_0043998F
                Source: C:\Users\user\Desktop\SimpleLoader v2.1.exe1.exeCode function: 4x nop then movzx edx, byte ptr [esp+eax-48C7705Ah]4_2_0041B210
                Source: C:\Users\user\Desktop\SimpleLoader v2.1.exe1.exeCode function: 4x nop then movzx esi, byte ptr [esp+eax-48C7705Eh]4_2_0044A220
                Source: C:\Users\user\Desktop\SimpleLoader v2.1.exe1.exeCode function: 4x nop then add eax, dword ptr [esp+ecx*4+24h]4_2_0040A230
                Source: C:\Users\user\Desktop\SimpleLoader v2.1.exe1.exeCode function: 4x nop then movzx ecx, word ptr [edi+esi*4]4_2_0040A230
                Source: C:\Users\user\Desktop\SimpleLoader v2.1.exe1.exeCode function: 4x nop then jmp dword ptr [004555DCh]4_2_00420AE4
                Source: C:\Users\user\Desktop\SimpleLoader v2.1.exe1.exeCode function: 4x nop then movzx ecx, byte ptr [edx+eax-639E4F5Ch]4_2_0042134F
                Source: C:\Users\user\Desktop\SimpleLoader v2.1.exe1.exeCode function: 4x nop then movzx ecx, byte ptr [esp+eax-3CB6001Eh]4_2_00428350
                Source: C:\Users\user\Desktop\SimpleLoader v2.1.exe1.exeCode function: 4x nop then movzx ecx, byte ptr [esp+eax+50DC5C06h]4_2_0040DB5B
                Source: C:\Users\user\Desktop\SimpleLoader v2.1.exe1.exeCode function: 4x nop then mov byte ptr [edi], al4_2_00437376
                Source: C:\Users\user\Desktop\SimpleLoader v2.1.exe1.exeCode function: 4x nop then jmp ecx4_2_0042FB3B
                Source: C:\Users\user\Desktop\SimpleLoader v2.1.exe1.exeCode function: 4x nop then lea edx, dword ptr [eax+00000270h]4_2_0040BBD0
                Source: C:\Users\user\Desktop\SimpleLoader v2.1.exe1.exeCode function: 4x nop then mov byte ptr [edi], al4_2_004373E4
                Source: C:\Users\user\Desktop\SimpleLoader v2.1.exe1.exeCode function: 4x nop then mov byte ptr [edi], 00000020h4_2_00437395
                Source: C:\Users\user\Desktop\SimpleLoader v2.1.exe1.exeCode function: 4x nop then mov byte ptr [ebx], al4_2_00439B99
                Source: C:\Users\user\Desktop\SimpleLoader v2.1.exe1.exeCode function: 4x nop then movzx esi, byte ptr [esp+eax+06h]4_2_004333B0
                Source: C:\Users\user\Desktop\SimpleLoader v2.1.exe1.exeCode function: 4x nop then mov byte ptr [edi], al4_2_00437443
                Source: C:\Users\user\Desktop\SimpleLoader v2.1.exe1.exeCode function: 4x nop then movzx edx, byte ptr [esp+eax+000002E8h]4_2_0041C444
                Source: C:\Users\user\Desktop\SimpleLoader v2.1.exe1.exeCode function: 4x nop then mov dword ptr [esp+38h], 00000800h4_2_00430451
                Source: C:\Users\user\Desktop\SimpleLoader v2.1.exe1.exeCode function: 4x nop then movzx edx, byte ptr [esp+ecx+1D2427C0h]4_2_0043946D
                Source: C:\Users\user\Desktop\SimpleLoader v2.1.exe1.exeCode function: 4x nop then jmp ecx4_2_0042FC38
                Source: C:\Users\user\Desktop\SimpleLoader v2.1.exe1.exeCode function: 4x nop then movzx ebx, byte ptr [esp+edx+3E68D7A0h]4_2_0040C4F0
                Source: C:\Users\user\Desktop\SimpleLoader v2.1.exe1.exeCode function: 4x nop then movzx esi, byte ptr [esp+ecx+08h]4_2_0040C4F0
                Source: C:\Users\user\Desktop\SimpleLoader v2.1.exe1.exeCode function: 4x nop then movzx esi, byte ptr [esp+ecx+1BA59E12h]4_2_0040C4F0
                Source: C:\Users\user\Desktop\SimpleLoader v2.1.exe1.exeCode function: 4x nop then mov dword ptr [esp+04h], edi4_2_0041D4F8
                Source: C:\Users\user\Desktop\SimpleLoader v2.1.exe1.exeCode function: 4x nop then mov byte ptr [edi], cl4_2_00437CB9
                Source: C:\Users\user\Desktop\SimpleLoader v2.1.exe1.exeCode function: 4x nop then mov dword ptr [esp], edx4_2_00432557
                Source: C:\Users\user\Desktop\SimpleLoader v2.1.exe1.exeCode function: 4x nop then mov word ptr [eax], cx4_2_00433DD6
                Source: C:\Users\user\Desktop\SimpleLoader v2.1.exe1.exeCode function: 4x nop then mov edx, edi4_2_004255A0
                Source: C:\Users\user\Desktop\SimpleLoader v2.1.exe1.exeCode function: 4x nop then movzx ecx, byte ptr [esp+eax+76318D9Ah]4_2_0044A640
                Source: C:\Users\user\Desktop\SimpleLoader v2.1.exe1.exeCode function: 4x nop then movzx edx, byte ptr [esp+eax-48C7705Eh]4_2_0044A640
                Source: C:\Users\user\Desktop\SimpleLoader v2.1.exe1.exeCode function: 4x nop then mov dword ptr [esi], 6B6A7573h4_2_0044BE48
                Source: C:\Users\user\Desktop\SimpleLoader v2.1.exe1.exeCode function: 4x nop then movzx ebx, byte ptr [edx]4_2_00443660
                Source: C:\Users\user\Desktop\SimpleLoader v2.1.exe1.exeCode function: 4x nop then movzx ecx, byte ptr [esp+eax-505762B2h]4_2_0041EE70
                Source: C:\Users\user\Desktop\SimpleLoader v2.1.exe1.exeCode function: 4x nop then movzx ebx, byte ptr [esp+edi-0AAF5356h]4_2_00437E7B
                Source: C:\Users\user\Desktop\SimpleLoader v2.1.exe1.exeCode function: 4x nop then mov byte ptr [edi], cl4_2_00438E0F
                Source: C:\Users\user\Desktop\SimpleLoader v2.1.exe1.exeCode function: 4x nop then movzx ecx, byte ptr [esp+eax-3AEEC40Ch]4_2_004316FF
                Source: C:\Users\user\Desktop\SimpleLoader v2.1.exe1.exeCode function: 4x nop then jmp eax4_2_004316FF
                Source: C:\Users\user\Desktop\SimpleLoader v2.1.exe1.exeCode function: 4x nop then movzx edx, byte ptr [esp+eax-1ADEC1F4h]4_2_004236B0
                Source: C:\Users\user\Desktop\SimpleLoader v2.1.exe1.exeCode function: 4x nop then movzx ecx, byte ptr [esp+eax+6Ch]4_2_0041DF48
                Source: C:\Users\user\Desktop\SimpleLoader v2.1.exe1.exeCode function: 4x nop then mov word ptr [eax], cx4_2_0041DF48
                Source: C:\Users\user\Desktop\SimpleLoader v2.1.exe1.exeCode function: 4x nop then mov dword ptr [esp+04h], edx4_2_0041DF48
                Source: C:\Users\user\Desktop\SimpleLoader v2.1.exe1.exeCode function: 4x nop then mov dword ptr [esp+0Ch], eax4_2_0042A750
                Source: C:\Users\user\Desktop\SimpleLoader v2.1.exe1.exeCode function: 4x nop then movzx edx, byte ptr [esp+eax+10h]4_2_0040DF5F
                Source: C:\Users\user\Desktop\SimpleLoader v2.1.exe1.exeCode function: 4x nop then mov word ptr [esi], cx4_2_00412F23
                Source: C:\Users\user\Desktop\SimpleLoader v2.1.exe1.exeCode function: 4x nop then movzx edx, byte ptr [esp+ecx-21FA49F8h]4_2_0044DFF0
                Source: C:\Users\user\Desktop\SimpleLoader v2.1.exe1.exeCode function: 4x nop then movzx edi, byte ptr [ecx+esi]4_2_00402780
                Source: C:\Users\user\Desktop\SimpleLoader v2.1.exe1.exeCode function: 4x nop then movzx ecx, byte ptr [esp+edx+10h]4_2_004337A2
                Source: C:\Users\user\Desktop\SimpleLoader v2.1.exe1.exeCode function: 4x nop then mov dword ptr [esp], eax4_2_00410FB0

                Networking

                barindex
                Source: Malware configuration extractorURLs: decorathnome.icu/ABbss
                Source: Malware configuration extractorURLs: crosshairc.life/dAnjhw
                Source: Malware configuration extractorURLs: mrodularmall.top/aNzS
                Source: Malware configuration extractorURLs: jowinjoinery.icu/bdWUa
                Source: Malware configuration extractorURLs: legenassedk.top/bdpWO
                Source: Malware configuration extractorURLs: htardwarehu.icu/Sbdsa
                Source: Malware configuration extractorURLs: cjlaspcorne.icu/DbIps
                Source: Malware configuration extractorURLs: bugildbett.top/bAuz
                Source: global trafficHTTP traffic detected: GET /kz_prokla1 HTTP/1.1Connection: Keep-AliveHost: t.me
                Source: Joe Sandbox ViewIP Address: 149.154.167.99 149.154.167.99
                Source: Joe Sandbox ViewIP Address: 149.154.167.99 149.154.167.99
                Source: Joe Sandbox ViewASN Name: CLOUDFLARENETUS CLOUDFLARENETUS
                Source: Joe Sandbox ViewJA3 fingerprint: a0e9f5d64349fb13191bc781f81f42e1
                Source: Network trafficSuricata IDS: 2028371 - Severity 3 - ET JA3 Hash - Possible Malware - Fake Firefox Font Update : 192.168.2.6:49689 -> 172.67.144.37:443
                Source: Network trafficSuricata IDS: 2028371 - Severity 3 - ET JA3 Hash - Possible Malware - Fake Firefox Font Update : 192.168.2.6:49688 -> 172.67.144.37:443
                Source: Network trafficSuricata IDS: 2028371 - Severity 3 - ET JA3 Hash - Possible Malware - Fake Firefox Font Update : 192.168.2.6:49690 -> 172.67.144.37:443
                Source: Network trafficSuricata IDS: 2028371 - Severity 3 - ET JA3 Hash - Possible Malware - Fake Firefox Font Update : 192.168.2.6:49692 -> 172.67.144.37:443
                Source: Network trafficSuricata IDS: 2028371 - Severity 3 - ET JA3 Hash - Possible Malware - Fake Firefox Font Update : 192.168.2.6:49697 -> 172.67.144.37:443
                Source: Network trafficSuricata IDS: 2028371 - Severity 3 - ET JA3 Hash - Possible Malware - Fake Firefox Font Update : 192.168.2.6:49700 -> 172.67.144.37:443
                Source: Network trafficSuricata IDS: 2028371 - Severity 3 - ET JA3 Hash - Possible Malware - Fake Firefox Font Update : 192.168.2.6:49687 -> 149.154.167.99:443
                Source: Network trafficSuricata IDS: 2028371 - Severity 3 - ET JA3 Hash - Possible Malware - Fake Firefox Font Update : 192.168.2.6:49694 -> 172.67.144.37:443
                Source: Network trafficSuricata IDS: 2028371 - Severity 3 - ET JA3 Hash - Possible Malware - Fake Firefox Font Update : 192.168.2.6:49691 -> 172.67.144.37:443
                Source: global trafficHTTP traffic detected: POST /ABbss HTTP/1.1Connection: Keep-AliveContent-Type: application/x-www-form-urlencodedUser-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/119.0.0.0 Safari/537.36Content-Length: 65Host: decorathnome.icu
                Source: global trafficHTTP traffic detected: POST /ABbss HTTP/1.1Connection: Keep-AliveContent-Type: multipart/form-data; boundary=87FJSNfYEi5IPIUser-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/119.0.0.0 Safari/537.36Content-Length: 14913Host: decorathnome.icu
                Source: global trafficHTTP traffic detected: POST /ABbss HTTP/1.1Connection: Keep-AliveContent-Type: multipart/form-data; boundary=kv8WaGUgIUser-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/119.0.0.0 Safari/537.36Content-Length: 15069Host: decorathnome.icu
                Source: global trafficHTTP traffic detected: POST /ABbss HTTP/1.1Connection: Keep-AliveContent-Type: multipart/form-data; boundary=3T4Imk2rn0Pq7NUser-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/119.0.0.0 Safari/537.36Content-Length: 19951Host: decorathnome.icu
                Source: global trafficHTTP traffic detected: POST /ABbss HTTP/1.1Connection: Keep-AliveContent-Type: multipart/form-data; boundary=qrGMjjA121User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/119.0.0.0 Safari/537.36Content-Length: 2393Host: decorathnome.icu
                Source: global trafficHTTP traffic detected: POST /ABbss HTTP/1.1Connection: Keep-AliveContent-Type: multipart/form-data; boundary=wLQyQqHZ9S2User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/119.0.0.0 Safari/537.36Content-Length: 589071Host: decorathnome.icu
                Source: global trafficHTTP traffic detected: POST /ABbss HTTP/1.1Connection: Keep-AliveContent-Type: application/x-www-form-urlencodedUser-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/119.0.0.0 Safari/537.36Content-Length: 103Host: decorathnome.icu
                Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
                Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
                Source: global trafficHTTP traffic detected: GET /kz_prokla1 HTTP/1.1Connection: Keep-AliveHost: t.me
                Source: global trafficDNS traffic detected: DNS query: t.me
                Source: global trafficDNS traffic detected: DNS query: decorathnome.icu
                Source: unknownHTTP traffic detected: POST /ABbss HTTP/1.1Connection: Keep-AliveContent-Type: application/x-www-form-urlencodedUser-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/119.0.0.0 Safari/537.36Content-Length: 65Host: decorathnome.icu
                Source: SimpleLoader v2.1.exe1.exe, 00000004.00000003.1478974812.00000000038D8000.00000004.00000800.00020000.00000000.sdmpString found in binary or memory: http://cacerts.digicert.com/DigiCertGlobalRootCA.crt0
                Source: SimpleLoader v2.1.exe1.exe, 00000004.00000003.1478974812.00000000038D8000.00000004.00000800.00020000.00000000.sdmpString found in binary or memory: http://cacerts.digicert.com/DigiCertGlobalRootCA.crt0B
                Source: SimpleLoader v2.1.exe1.exe, 00000004.00000003.1478974812.00000000038D8000.00000004.00000800.00020000.00000000.sdmpString found in binary or memory: http://crl.rootca1.amazontrust.com/rootca1.crl0
                Source: SimpleLoader v2.1.exe1.exe, 00000004.00000003.1478974812.00000000038D8000.00000004.00000800.00020000.00000000.sdmpString found in binary or memory: http://crl3.digicert.com/DigiCertGlobalRootCA.crl07
                Source: SimpleLoader v2.1.exe1.exe, 00000004.00000003.1478974812.00000000038D8000.00000004.00000800.00020000.00000000.sdmpString found in binary or memory: http://crl3.digicert.com/DigiCertGlobalRootCA.crl0=
                Source: SimpleLoader v2.1.exe1.exe, 00000004.00000003.1478974812.00000000038D8000.00000004.00000800.00020000.00000000.sdmpString found in binary or memory: http://crl4.digicert.com/DigiCertGlobalRootCA.crl00
                Source: SimpleLoader v2.1.exe1.exe, 00000004.00000003.1478974812.00000000038D8000.00000004.00000800.00020000.00000000.sdmpString found in binary or memory: http://crt.rootca1.amazontrust.com/rootca1.cer0?
                Source: SimpleLoader v2.1.exe1.exe, 00000004.00000003.1478974812.00000000038D8000.00000004.00000800.00020000.00000000.sdmpString found in binary or memory: http://ocsp.digicert.com0
                Source: SimpleLoader v2.1.exe1.exe, 00000004.00000003.1478974812.00000000038D8000.00000004.00000800.00020000.00000000.sdmpString found in binary or memory: http://ocsp.rootca1.amazontrust.com0:
                Source: SimpleLoader v2.1.exe1.exe, 00000004.00000003.1478974812.00000000038D8000.00000004.00000800.00020000.00000000.sdmpString found in binary or memory: http://x1.c.lencr.org/0
                Source: SimpleLoader v2.1.exe1.exe, 00000004.00000003.1478974812.00000000038D8000.00000004.00000800.00020000.00000000.sdmpString found in binary or memory: http://x1.i.lencr.org/0
                Source: SimpleLoader v2.1.exe1.exe, 00000004.00000003.1435581061.00000000038D6000.00000004.00000800.00020000.00000000.sdmpString found in binary or memory: https://ac.ecosia.org?q=
                Source: SimpleLoader v2.1.exe1.exe, 00000004.00000003.1485841501.00000000010C7000.00000004.00000020.00020000.00000000.sdmpString found in binary or memory: https://bridge.sfo1.admarketplace.net/ctp?version=16.0.0&key=1696484494400800000.2&ci=1696484494189.
                Source: SimpleLoader v2.1.exe1.exe, 00000004.00000003.1485841501.00000000010C7000.00000004.00000020.00020000.00000000.sdmpString found in binary or memory: https://bridge.sfo1.ap01.net/ctp?version=16.0.0&key=1696484494400800000.1&ci=1696484494189.12791&cta
                Source: SimpleLoader v2.1.exe1.exe, 00000004.00000003.1435581061.00000000038D6000.00000004.00000800.00020000.00000000.sdmpString found in binary or memory: https://cdn.ecosia.org/assets/images/ico/favicon.icohttps://www.ecosia.org/search?q=
                Source: SimpleLoader v2.1.exe1.exe, 00000004.00000003.1435581061.00000000038D6000.00000004.00000800.00020000.00000000.sdmpString found in binary or memory: https://ch.search.yahoo.com/favicon.icohttps://ch.search.yahoo.com/search
                Source: SimpleLoader v2.1.exe1.exe, 00000004.00000003.1435581061.00000000038D6000.00000004.00000800.00020000.00000000.sdmpString found in binary or memory: https://ch.search.yahoo.com/sugg/chrome?output=fxjson&appid=crmas&command=
                Source: SimpleLoader v2.1.exe1.exe, 00000004.00000003.1485841501.00000000010C7000.00000004.00000020.00020000.00000000.sdmpString found in binary or memory: https://contile-images.services.mozilla.com/T23eBL4EHswiSaF6kya2gYsRHvdfADK-NYjs1mVRNGE.3351.jpg
                Source: SimpleLoader v2.1.exe1.exe, 00000004.00000003.1485841501.00000000010C7000.00000004.00000020.00020000.00000000.sdmpString found in binary or memory: https://contile-images.services.mozilla.com/obgoOYObjIFea_bXuT6L4LbBJ8j425AD87S1HMD3BWg.9991.jpg
                Source: SimpleLoader v2.1.exe1.exe, 00000004.00000003.1433741427.000000000105D000.00000004.00000020.00020000.00000000.sdmpString found in binary or memory: https://decorathnome.icu/
                Source: SimpleLoader v2.1.exe1.exe, 00000004.00000003.1433741427.000000000105D000.00000004.00000020.00020000.00000000.sdmpString found in binary or memory: https://decorathnome.icu//
                Source: SimpleLoader v2.1.exe1.exe, 00000004.00000003.1595827243.00000000010BE000.00000004.00000020.00020000.00000000.sdmp, SimpleLoader v2.1.exe1.exe, 00000004.00000003.1477812993.00000000010DA000.00000004.00000020.00020000.00000000.sdmp, SimpleLoader v2.1.exe1.exe, 00000004.00000003.2218298564.00000000010BE000.00000004.00000020.00020000.00000000.sdmp, SimpleLoader v2.1.exe1.exe, 00000004.00000003.1551469610.00000000010BE000.00000004.00000020.00020000.00000000.sdmp, SimpleLoader v2.1.exe1.exe, 00000004.00000003.1485841501.00000000010DB000.00000004.00000020.00020000.00000000.sdmp, SimpleLoader v2.1.exe1.exe, 00000004.00000003.1477310973.00000000010DA000.00000004.00000020.00020000.00000000.sdmp, SimpleLoader v2.1.exe1.exe, 00000004.00000003.1478953161.00000000010DB000.00000004.00000020.00020000.00000000.sdmp, SimpleLoader v2.1.exe1.exe, 00000004.00000002.2610086431.00000000010D9000.00000004.00000020.00020000.00000000.sdmp, SimpleLoader v2.1.exe1.exe, 00000004.00000003.1571288821.00000000010BE000.00000004.00000020.00020000.00000000.sdmp, SimpleLoader v2.1.exe1.exe, 00000004.00000003.1509553771.00000000010DA000.00000004.00000020.00020000.00000000.sdmp, SimpleLoader v2.1.exe1.exe, 00000004.00000002.2610051245.00000000010BE000.00000004.00000020.00020000.00000000.sdmp, SimpleLoader v2.1.exe1.exe, 00000004.00000003.1456171629.00000000010D9000.00000004.00000020.00020000.00000000.sdmp, SimpleLoader v2.1.exe1.exe, 00000004.00000003.1433741427.000000000101C000.00000004.00000020.00020000.00000000.sdmp, SimpleLoader v2.1.exe1.exe, 00000004.00000003.1457415838.00000000010DA000.00000004.00000020.00020000.00000000.sdmp, SimpleLoader v2.1.exe1.exe, 00000004.00000003.1433741427.000000000105D000.00000004.00000020.00020000.00000000.sdmp, SimpleLoader v2.1.exe1.exe, 00000004.00000003.1551358100.00000000010DB000.00000004.00000020.00020000.00000000.sdmpString found in binary or memory: https://decorathnome.icu/ABbss
                Source: SimpleLoader v2.1.exe1.exe, 00000004.00000003.1433741427.000000000105D000.00000004.00000020.00020000.00000000.sdmpString found in binary or memory: https://decorathnome.icu/ABbssA
                Source: SimpleLoader v2.1.exe1.exe, 00000004.00000003.1570683653.00000000010DA000.00000004.00000020.00020000.00000000.sdmp, SimpleLoader v2.1.exe1.exe, 00000004.00000003.1571141047.00000000010DA000.00000004.00000020.00020000.00000000.sdmp, SimpleLoader v2.1.exe1.exe, 00000004.00000002.2610086431.00000000010D9000.00000004.00000020.00020000.00000000.sdmp, SimpleLoader v2.1.exe1.exe, 00000004.00000003.1556473568.00000000010DB000.00000004.00000020.00020000.00000000.sdmp, SimpleLoader v2.1.exe1.exe, 00000004.00000003.1551358100.00000000010DB000.00000004.00000020.00020000.00000000.sdmpString found in binary or memory: https://decorathnome.icu/ABbssC
                Source: SimpleLoader v2.1.exe1.exe, 00000004.00000003.1433741427.000000000105D000.00000004.00000020.00020000.00000000.sdmpString found in binary or memory: https://decorathnome.icu/ABbssF
                Source: SimpleLoader v2.1.exe1.exe, 00000004.00000003.1595827243.00000000010BE000.00000004.00000020.00020000.00000000.sdmp, SimpleLoader v2.1.exe1.exe, 00000004.00000003.1571288821.00000000010BE000.00000004.00000020.00020000.00000000.sdmpString found in binary or memory: https://decorathnome.icu/ABbssPM=
                Source: SimpleLoader v2.1.exe1.exe, 00000004.00000003.1477812993.00000000010DA000.00000004.00000020.00020000.00000000.sdmp, SimpleLoader v2.1.exe1.exe, 00000004.00000003.1485841501.00000000010DB000.00000004.00000020.00020000.00000000.sdmp, SimpleLoader v2.1.exe1.exe, 00000004.00000003.1477310973.00000000010DA000.00000004.00000020.00020000.00000000.sdmp, SimpleLoader v2.1.exe1.exe, 00000004.00000003.1478953161.00000000010DB000.00000004.00000020.00020000.00000000.sdmp, SimpleLoader v2.1.exe1.exe, 00000004.00000003.1457415838.00000000010DA000.00000004.00000020.00020000.00000000.sdmpString found in binary or memory: https://decorathnome.icu/ABbssQvQ
                Source: SimpleLoader v2.1.exe1.exe, 00000004.00000003.1456171629.00000000010D9000.00000004.00000020.00020000.00000000.sdmpString found in binary or memory: https://decorathnome.icu/ABbssTs
                Source: SimpleLoader v2.1.exe1.exe, 00000004.00000003.1433741427.000000000103D000.00000004.00000020.00020000.00000000.sdmpString found in binary or memory: https://decorathnome.icu/ABbssW
                Source: SimpleLoader v2.1.exe1.exe, 00000004.00000003.1433741427.000000000105D000.00000004.00000020.00020000.00000000.sdmpString found in binary or memory: https://decorathnome.icu/ABbssm
                Source: SimpleLoader v2.1.exe1.exe, 00000004.00000003.1433741427.000000000105D000.00000004.00000020.00020000.00000000.sdmpString found in binary or memory: https://decorathnome.icu/W
                Source: SimpleLoader v2.1.exe1.exe, 00000004.00000003.1477891390.00000000010BE000.00000004.00000020.00020000.00000000.sdmpString found in binary or memory: https://decorathnome.icu/Windows
                Source: SimpleLoader v2.1.exe1.exe, 00000004.00000003.1551469610.00000000010BE000.00000004.00000020.00020000.00000000.sdmpString found in binary or memory: https://decorathnome.icu/s
                Source: SimpleLoader v2.1.exe1.exe, 00000004.00000003.1551469610.00000000010BE000.00000004.00000020.00020000.00000000.sdmpString found in binary or memory: https://decorathnome.icu/sows
                Source: SimpleLoader v2.1.exe1.exe, 00000004.00000003.2218298564.00000000010BE000.00000004.00000020.00020000.00000000.sdmp, SimpleLoader v2.1.exe1.exe, 00000004.00000002.2610051245.00000000010BE000.00000004.00000020.00020000.00000000.sdmpString found in binary or memory: https://decorathnome.icu/x8
                Source: SimpleLoader v2.1.exe1.exe, 00000004.00000003.1571288821.00000000010A4000.00000004.00000020.00020000.00000000.sdmpString found in binary or memory: https://decorathnome.icu:443/ABbss
                Source: SimpleLoader v2.1.exe1.exe, 00000004.00000003.1435581061.00000000038D6000.00000004.00000800.00020000.00000000.sdmpString found in binary or memory: https://duckduckgo.com/ac/?q=
                Source: SimpleLoader v2.1.exe1.exe, 00000004.00000003.1435581061.00000000038D6000.00000004.00000800.00020000.00000000.sdmpString found in binary or memory: https://duckduckgo.com/chrome_newtabv20-
                Source: SimpleLoader v2.1.exe1.exe, 00000004.00000003.1435581061.00000000038D6000.00000004.00000800.00020000.00000000.sdmpString found in binary or memory: https://duckduckgo.com/favicon.icohttps://duckduckgo.com/?q=
                Source: SimpleLoader v2.1.exe1.exe, 00000004.00000003.1435581061.00000000038D6000.00000004.00000800.00020000.00000000.sdmpString found in binary or memory: https://gemini.google.com/app?q=
                Source: SimpleLoader v2.1.exe1.exe, 00000004.00000003.1485841501.00000000010C7000.00000004.00000020.00020000.00000000.sdmpString found in binary or memory: https://imp.mt48.net/static?id=7RHzfOIXjFEYsBdvIpkX4Qqm4pLk4pqk4pbW1pbWfpbW7ReNxR3UIG8zInwYIFIVs9eYi
                Source: SimpleLoader v2.1.exe1.exe, 00000004.00000003.1484721856.0000000003AC2000.00000004.00000800.00020000.00000000.sdmpString found in binary or memory: https://support.mozilla.org/kb/customize-firefox-controls-buttons-and-toolbars?utm_source=firefox-br
                Source: SimpleLoader v2.1.exe1.exe, 00000004.00000003.1484721856.0000000003AC2000.00000004.00000800.00020000.00000000.sdmpString found in binary or memory: https://support.mozilla.org/products/firefoxgro.all
                Source: SimpleLoader v2.1.exe1.exe, 00000004.00000003.1433741427.0000000001027000.00000004.00000020.00020000.00000000.sdmp, SimpleLoader v2.1.exe1.exe, 00000004.00000003.1394821560.0000000001085000.00000004.00000020.00020000.00000000.sdmp, SimpleLoader v2.1.exe1.exe, 00000004.00000003.1394763471.0000000001027000.00000004.00000020.00020000.00000000.sdmpString found in binary or memory: https://t.me/
                Source: SimpleLoader v2.1.exe1.exe, 00000004.00000003.1394641354.0000000001099000.00000004.00000020.00020000.00000000.sdmp, SimpleLoader v2.1.exe1.exe, 00000004.00000003.1394660916.0000000001093000.00000004.00000020.00020000.00000000.sdmp, SimpleLoader v2.1.exe1.exe, 00000004.00000003.1394678962.000000000103F000.00000004.00000020.00020000.00000000.sdmp, SimpleLoader v2.1.exe1.exe, 00000004.00000003.1433741427.000000000103D000.00000004.00000020.00020000.00000000.sdmpString found in binary or memory: https://t.me/kz_prokla1
                Source: SimpleLoader v2.1.exe1.exe, 00000004.00000003.1394678962.0000000001049000.00000004.00000020.00020000.00000000.sdmpString found in binary or memory: https://web.telegram.org
                Source: SimpleLoader v2.1.exe1.exe, 00000004.00000003.1394678962.0000000001049000.00000004.00000020.00020000.00000000.sdmpString found in binary or memory: https://web.telegram.orgPersistent-AuthWWW-AuthenticateVarystel_ssid=a88ac38d923dcffb84_785111170565
                Source: SimpleLoader v2.1.exe1.exe, 00000004.00000003.1394678962.0000000001049000.00000004.00000020.00020000.00000000.sdmpString found in binary or memory: https://web.telegram.orgX-Frame-OptionsALLOW-FROM
                Source: SimpleLoader v2.1.exe1.exe, 00000004.00000003.1485841501.00000000010C7000.00000004.00000020.00020000.00000000.sdmpString found in binary or memory: https://www.amazon.com/?tag=admarketus-20&ref=pd_sl_86277c656a4bd7d619968160e91c45fd066919bb3bd119b3
                Source: SimpleLoader v2.1.exe1.exe, 00000004.00000003.1435581061.00000000038D6000.00000004.00000800.00020000.00000000.sdmpString found in binary or memory: https://www.ecosia.org/newtab/v20
                Source: SimpleLoader v2.1.exe1.exe, 00000004.00000003.1435581061.00000000038D6000.00000004.00000800.00020000.00000000.sdmpString found in binary or memory: https://www.google.com/images/branding/product/ico/googleg_alldp.ico
                Source: SimpleLoader v2.1.exe1.exe, 00000004.00000003.1484629474.00000000038D4000.00000004.00000800.00020000.00000000.sdmpString found in binary or memory: https://www.mozilla.or
                Source: SimpleLoader v2.1.exe1.exe, 00000004.00000003.1484629474.00000000038D4000.00000004.00000800.00020000.00000000.sdmpString found in binary or memory: https://www.mozilla.org
                Source: SimpleLoader v2.1.exe1.exe, 00000004.00000003.1484721856.0000000003AC2000.00000004.00000800.00020000.00000000.sdmpString found in binary or memory: https://www.mozilla.org/about/gro.allizom.www.bwSC1pmG_zle
                Source: SimpleLoader v2.1.exe1.exe, 00000004.00000003.1484721856.0000000003AC2000.00000004.00000800.00020000.00000000.sdmpString found in binary or memory: https://www.mozilla.org/contribute/gro.allizom.www.hjKdHaZH-dbQ
                Source: SimpleLoader v2.1.exe1.exe, 00000004.00000003.1484721856.0000000003AC2000.00000004.00000800.00020000.00000000.sdmpString found in binary or memory: https://www.mozilla.org/firefox/?utm_medium=firefox-desktop&utm_source=bookmarks-toolbar&utm_campaig
                Source: SimpleLoader v2.1.exe1.exe, 00000004.00000003.1485841501.00000000010C7000.00000004.00000020.00020000.00000000.sdmpString found in binary or memory: https://www.t-mobile.com/cell-phones/brand/apple?cmpid=MGPO_PAM_P_EVGRNIPHN_
                Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49689
                Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49700
                Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49688
                Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49687
                Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49697
                Source: unknownNetwork traffic detected: HTTP traffic on port 49694 -> 443
                Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49694
                Source: unknownNetwork traffic detected: HTTP traffic on port 49697 -> 443
                Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49692
                Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49691
                Source: unknownNetwork traffic detected: HTTP traffic on port 49692 -> 443
                Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49690
                Source: unknownNetwork traffic detected: HTTP traffic on port 49691 -> 443
                Source: unknownNetwork traffic detected: HTTP traffic on port 49689 -> 443
                Source: unknownNetwork traffic detected: HTTP traffic on port 49690 -> 443
                Source: unknownNetwork traffic detected: HTTP traffic on port 49700 -> 443
                Source: unknownNetwork traffic detected: HTTP traffic on port 49687 -> 443
                Source: unknownNetwork traffic detected: HTTP traffic on port 49688 -> 443
                Source: unknownHTTPS traffic detected: 149.154.167.99:443 -> 192.168.2.6:49687 version: TLS 1.2
                Source: unknownHTTPS traffic detected: 172.67.144.37:443 -> 192.168.2.6:49689 version: TLS 1.2
                Source: unknownHTTPS traffic detected: 172.67.144.37:443 -> 192.168.2.6:49690 version: TLS 1.2
                Source: unknownHTTPS traffic detected: 172.67.144.37:443 -> 192.168.2.6:49691 version: TLS 1.2
                Source: unknownHTTPS traffic detected: 172.67.144.37:443 -> 192.168.2.6:49692 version: TLS 1.2
                Source: unknownHTTPS traffic detected: 172.67.144.37:443 -> 192.168.2.6:49694 version: TLS 1.2
                Source: unknownHTTPS traffic detected: 172.67.144.37:443 -> 192.168.2.6:49697 version: TLS 1.2
                Source: unknownHTTPS traffic detected: 172.67.144.37:443 -> 192.168.2.6:49700 version: TLS 1.2
                Source: C:\Users\user\Desktop\SimpleLoader v2.1.exe1.exeCode function: 4_2_004416E0 OpenClipboard,GetClipboardData,GlobalLock,GetWindowRect,GlobalUnlock,CloseClipboard,4_2_004416E0
                Source: C:\Users\user\Desktop\SimpleLoader v2.1.exe1.exeCode function: 4_2_03641000 EntryPoint,GetClipboardSequenceNumber,Sleep,Sleep,OpenClipboard,GetClipboardData,GlobalLock,GlobalAlloc,GlobalLock,GlobalUnlock,EmptyClipboard,SetClipboardData,GlobalFree,GlobalUnlock,CloseClipboard,GetClipboardSequenceNumber,4_2_03641000
                Source: C:\Users\user\Desktop\SimpleLoader v2.1.exe1.exeCode function: 4_2_004416E0 OpenClipboard,GetClipboardData,GlobalLock,GetWindowRect,GlobalUnlock,CloseClipboard,4_2_004416E0
                Source: C:\Users\user\Desktop\SimpleLoader v2.1.exe1.exeCode function: 4_2_004418D0 GetDC,GetSystemMetrics,GetSystemMetrics,GetSystemMetrics,GetCurrentObject,GetObjectW,DeleteObject,CreateCompatibleDC,CreateCompatibleBitmap,SelectObject,BitBlt,SelectObject,DeleteDC,ReleaseDC,DeleteObject,4_2_004418D0
                Source: C:\Users\user\Desktop\SimpleLoader v2.1.exe1.exeCode function: 0_2_005E31F00_2_005E31F0
                Source: C:\Users\user\Desktop\SimpleLoader v2.1.exe1.exeCode function: 0_2_005E36400_2_005E3640
                Source: C:\Users\user\Desktop\SimpleLoader v2.1.exe1.exeCode function: 0_2_0060F0600_2_0060F060
                Source: C:\Users\user\Desktop\SimpleLoader v2.1.exe1.exeCode function: 0_2_005F40400_2_005F4040
                Source: C:\Users\user\Desktop\SimpleLoader v2.1.exe1.exeCode function: 0_2_005E60700_2_005E6070
                Source: C:\Users\user\Desktop\SimpleLoader v2.1.exe1.exeCode function: 0_2_0060A0200_2_0060A020
                Source: C:\Users\user\Desktop\SimpleLoader v2.1.exe1.exeCode function: 0_2_005FC0100_2_005FC010
                Source: C:\Users\user\Desktop\SimpleLoader v2.1.exe1.exeCode function: 0_2_005E10000_2_005E1000
                Source: C:\Users\user\Desktop\SimpleLoader v2.1.exe1.exeCode function: 0_2_006138130_2_00613813
                Source: C:\Users\user\Desktop\SimpleLoader v2.1.exe1.exeCode function: 0_2_005FA8200_2_005FA820
                Source: C:\Users\user\Desktop\SimpleLoader v2.1.exe1.exeCode function: 0_2_005F90200_2_005F9020
                Source: C:\Users\user\Desktop\SimpleLoader v2.1.exe1.exeCode function: 0_2_006100D00_2_006100D0
                Source: C:\Users\user\Desktop\SimpleLoader v2.1.exe1.exeCode function: 0_2_005E80900_2_005E8090
                Source: C:\Users\user\Desktop\SimpleLoader v2.1.exe1.exeCode function: 0_2_005F08900_2_005F0890
                Source: C:\Users\user\Desktop\SimpleLoader v2.1.exe1.exeCode function: 0_2_005E40800_2_005E4080
                Source: C:\Users\user\Desktop\SimpleLoader v2.1.exe1.exeCode function: 0_2_0060D0800_2_0060D080
                Source: C:\Users\user\Desktop\SimpleLoader v2.1.exe1.exeCode function: 0_2_006038900_2_00603890
                Source: C:\Users\user\Desktop\SimpleLoader v2.1.exe1.exeCode function: 0_2_006118900_2_00611890
                Source: C:\Users\user\Desktop\SimpleLoader v2.1.exe1.exeCode function: 0_2_005E58A00_2_005E58A0
                Source: C:\Users\user\Desktop\SimpleLoader v2.1.exe1.exeCode function: 0_2_005FE0A00_2_005FE0A0
                Source: C:\Users\user\Desktop\SimpleLoader v2.1.exe1.exeCode function: 0_2_006131600_2_00613160
                Source: C:\Users\user\Desktop\SimpleLoader v2.1.exe1.exeCode function: 0_2_005E49400_2_005E4940
                Source: C:\Users\user\Desktop\SimpleLoader v2.1.exe1.exeCode function: 0_2_005FC9400_2_005FC940
                Source: C:\Users\user\Desktop\SimpleLoader v2.1.exe1.exeCode function: 0_2_005EE1700_2_005EE170
                Source: C:\Users\user\Desktop\SimpleLoader v2.1.exe1.exeCode function: 0_2_006129200_2_00612920
                Source: C:\Users\user\Desktop\SimpleLoader v2.1.exe1.exeCode function: 0_2_006091000_2_00609100
                Source: C:\Users\user\Desktop\SimpleLoader v2.1.exe1.exeCode function: 0_2_0062C9080_2_0062C908
                Source: C:\Users\user\Desktop\SimpleLoader v2.1.exe1.exeCode function: 0_2_006001100_2_00600110
                Source: C:\Users\user\Desktop\SimpleLoader v2.1.exe1.exeCode function: 0_2_005FB1E00_2_005FB1E0
                Source: C:\Users\user\Desktop\SimpleLoader v2.1.exe1.exeCode function: 0_2_0060F9B00_2_0060F9B0
                Source: C:\Users\user\Desktop\SimpleLoader v2.1.exe1.exeCode function: 0_2_005F61800_2_005F6180
                Source: C:\Users\user\Desktop\SimpleLoader v2.1.exe1.exeCode function: 0_2_00608A500_2_00608A50
                Source: C:\Users\user\Desktop\SimpleLoader v2.1.exe1.exeCode function: 0_2_00616A540_2_00616A54
                Source: C:\Users\user\Desktop\SimpleLoader v2.1.exe1.exeCode function: 0_2_006052200_2_00605220
                Source: C:\Users\user\Desktop\SimpleLoader v2.1.exe1.exeCode function: 0_2_00606A000_2_00606A00
                Source: C:\Users\user\Desktop\SimpleLoader v2.1.exe1.exeCode function: 0_2_006082000_2_00608200
                Source: C:\Users\user\Desktop\SimpleLoader v2.1.exe1.exeCode function: 0_2_00600A100_2_00600A10
                Source: C:\Users\user\Desktop\SimpleLoader v2.1.exe1.exeCode function: 0_2_005E52200_2_005E5220
                Source: C:\Users\user\Desktop\SimpleLoader v2.1.exe1.exeCode function: 0_2_005E92200_2_005E9220
                Source: C:\Users\user\Desktop\SimpleLoader v2.1.exe1.exeCode function: 0_2_0060F2E00_2_0060F2E0
                Source: C:\Users\user\Desktop\SimpleLoader v2.1.exe1.exeCode function: 0_2_005EF2D00_2_005EF2D0
                Source: C:\Users\user\Desktop\SimpleLoader v2.1.exe1.exeCode function: 0_2_005F52C00_2_005F52C0
                Source: C:\Users\user\Desktop\SimpleLoader v2.1.exe1.exeCode function: 0_2_005F42900_2_005F4290
                Source: C:\Users\user\Desktop\SimpleLoader v2.1.exe1.exeCode function: 0_2_00609AB00_2_00609AB0
                Source: C:\Users\user\Desktop\SimpleLoader v2.1.exe1.exeCode function: 0_2_005E22800_2_005E2280
                Source: C:\Users\user\Desktop\SimpleLoader v2.1.exe1.exeCode function: 0_2_005EEAA00_2_005EEAA0
                Source: C:\Users\user\Desktop\SimpleLoader v2.1.exe1.exeCode function: 0_2_006013700_2_00601370
                Source: C:\Users\user\Desktop\SimpleLoader v2.1.exe1.exeCode function: 0_2_005E83400_2_005E8340
                Source: C:\Users\user\Desktop\SimpleLoader v2.1.exe1.exeCode function: 0_2_0060EB400_2_0060EB40
                Source: C:\Users\user\Desktop\SimpleLoader v2.1.exe1.exeCode function: 0_2_005FFB700_2_005FFB70
                Source: C:\Users\user\Desktop\SimpleLoader v2.1.exe1.exeCode function: 0_2_006003500_2_00600350
                Source: C:\Users\user\Desktop\SimpleLoader v2.1.exe1.exeCode function: 0_2_005EC3100_2_005EC310
                Source: C:\Users\user\Desktop\SimpleLoader v2.1.exe1.exeCode function: 0_2_005EB3000_2_005EB300
                Source: C:\Users\user\Desktop\SimpleLoader v2.1.exe1.exeCode function: 0_2_005FF3D00_2_005FF3D0
                Source: C:\Users\user\Desktop\SimpleLoader v2.1.exe1.exeCode function: 0_2_005F73F00_2_005F73F0
                Source: C:\Users\user\Desktop\SimpleLoader v2.1.exe1.exeCode function: 0_2_005E63900_2_005E6390
                Source: C:\Users\user\Desktop\SimpleLoader v2.1.exe1.exeCode function: 0_2_005F33900_2_005F3390
                Source: C:\Users\user\Desktop\SimpleLoader v2.1.exe1.exeCode function: 0_2_005FABA00_2_005FABA0
                Source: C:\Users\user\Desktop\SimpleLoader v2.1.exe1.exeCode function: 0_2_00605C600_2_00605C60
                Source: C:\Users\user\Desktop\SimpleLoader v2.1.exe1.exeCode function: 0_2_006134770_2_00613477
                Source: C:\Users\user\Desktop\SimpleLoader v2.1.exe1.exeCode function: 0_2_005E2C400_2_005E2C40
                Source: C:\Users\user\Desktop\SimpleLoader v2.1.exe1.exeCode function: 0_2_005FEC400_2_005FEC40
                Source: C:\Users\user\Desktop\SimpleLoader v2.1.exe1.exeCode function: 0_2_00608C400_2_00608C40
                Source: C:\Users\user\Desktop\SimpleLoader v2.1.exe1.exeCode function: 0_2_006084500_2_00608450
                Source: C:\Users\user\Desktop\SimpleLoader v2.1.exe1.exeCode function: 0_2_006214200_2_00621420
                Source: C:\Users\user\Desktop\SimpleLoader v2.1.exe1.exeCode function: 0_2_0061B41A0_2_0061B41A
                Source: C:\Users\user\Desktop\SimpleLoader v2.1.exe1.exeCode function: 0_2_005E5C200_2_005E5C20
                Source: C:\Users\user\Desktop\SimpleLoader v2.1.exe1.exeCode function: 0_2_005EE4C00_2_005EE4C0
                Source: C:\Users\user\Desktop\SimpleLoader v2.1.exe1.exeCode function: 0_2_005F3CC00_2_005F3CC0
                Source: C:\Users\user\Desktop\SimpleLoader v2.1.exe1.exeCode function: 0_2_005FCCE00_2_005FCCE0
                Source: C:\Users\user\Desktop\SimpleLoader v2.1.exe1.exeCode function: 0_2_005F04900_2_005F0490
                Source: C:\Users\user\Desktop\SimpleLoader v2.1.exe1.exeCode function: 0_2_005E6C800_2_005E6C80
                Source: C:\Users\user\Desktop\SimpleLoader v2.1.exe1.exeCode function: 0_2_005F64800_2_005F6480
                Source: C:\Users\user\Desktop\SimpleLoader v2.1.exe1.exeCode function: 0_2_006054800_2_00605480
                Source: C:\Users\user\Desktop\SimpleLoader v2.1.exe1.exeCode function: 0_2_006124800_2_00612480
                Source: C:\Users\user\Desktop\SimpleLoader v2.1.exe1.exeCode function: 0_2_00613C900_2_00613C90
                Source: C:\Users\user\Desktop\SimpleLoader v2.1.exe1.exeCode function: 0_2_005E54A00_2_005E54A0
                Source: C:\Users\user\Desktop\SimpleLoader v2.1.exe1.exeCode function: 0_2_005FDD500_2_005FDD50
                Source: C:\Users\user\Desktop\SimpleLoader v2.1.exe1.exeCode function: 0_2_005F85400_2_005F8540
                Source: C:\Users\user\Desktop\SimpleLoader v2.1.exe1.exeCode function: 0_2_0060FD500_2_0060FD50
                Source: C:\Users\user\Desktop\SimpleLoader v2.1.exe1.exeCode function: 0_2_005FD5600_2_005FD560
                Source: C:\Users\user\Desktop\SimpleLoader v2.1.exe1.exeCode function: 0_2_005F95000_2_005F9500
                Source: C:\Users\user\Desktop\SimpleLoader v2.1.exe1.exeCode function: 0_2_005E7D300_2_005E7D30
                Source: C:\Users\user\Desktop\SimpleLoader v2.1.exe1.exeCode function: 0_2_005EF5300_2_005EF530
                Source: C:\Users\user\Desktop\SimpleLoader v2.1.exe1.exeCode function: 0_2_005EAD300_2_005EAD30
                Source: C:\Users\user\Desktop\SimpleLoader v2.1.exe1.exeCode function: 0_2_006135C00_2_006135C0
                Source: C:\Users\user\Desktop\SimpleLoader v2.1.exe1.exeCode function: 0_2_0060F5D00_2_0060F5D0
                Source: C:\Users\user\Desktop\SimpleLoader v2.1.exe1.exeCode function: 0_2_0060EDB00_2_0060EDB0
                Source: C:\Users\user\Desktop\SimpleLoader v2.1.exe1.exeCode function: 0_2_005E95800_2_005E9580
                Source: C:\Users\user\Desktop\SimpleLoader v2.1.exe1.exeCode function: 0_2_0060DD800_2_0060DD80
                Source: C:\Users\user\Desktop\SimpleLoader v2.1.exe1.exeCode function: 0_2_005F55B00_2_005F55B0
                Source: C:\Users\user\Desktop\SimpleLoader v2.1.exe1.exeCode function: 0_2_005F7E500_2_005F7E50
                Source: C:\Users\user\Desktop\SimpleLoader v2.1.exe1.exeCode function: 0_2_005E86400_2_005E8640
                Source: C:\Users\user\Desktop\SimpleLoader v2.1.exe1.exeCode function: 0_2_005F6E400_2_005F6E40
                Source: C:\Users\user\Desktop\SimpleLoader v2.1.exe1.exeCode function: 0_2_005E46600_2_005E4660
                Source: C:\Users\user\Desktop\SimpleLoader v2.1.exe1.exeCode function: 0_2_006106200_2_00610620
                Source: C:\Users\user\Desktop\SimpleLoader v2.1.exe1.exeCode function: 0_2_006096300_2_00609630
                Source: C:\Users\user\Desktop\SimpleLoader v2.1.exe1.exeCode function: 0_2_005FB6300_2_005FB630
                Source: C:\Users\user\Desktop\SimpleLoader v2.1.exe1.exeCode function: 0_2_005F76200_2_005F7620
                Source: C:\Users\user\Desktop\SimpleLoader v2.1.exe1.exeCode function: 0_2_005F0E200_2_005F0E20
                Source: C:\Users\user\Desktop\SimpleLoader v2.1.exe1.exeCode function: 0_2_00611EF00_2_00611EF0
                Source: C:\Users\user\Desktop\SimpleLoader v2.1.exe1.exeCode function: 0_2_005F26F00_2_005F26F0
                Source: C:\Users\user\Desktop\SimpleLoader v2.1.exe1.exeCode function: 0_2_005F2E900_2_005F2E90
                Source: C:\Users\user\Desktop\SimpleLoader v2.1.exe1.exeCode function: 0_2_0060B6800_2_0060B680
                Source: C:\Users\user\Desktop\SimpleLoader v2.1.exe1.exeCode function: 0_2_006086900_2_00608690
                Source: C:\Users\user\Desktop\SimpleLoader v2.1.exe1.exeCode function: 0_2_00612E900_2_00612E90
                Source: C:\Users\user\Desktop\SimpleLoader v2.1.exe1.exeCode function: 0_2_005FC6A00_2_005FC6A0
                Source: C:\Users\user\Desktop\SimpleLoader v2.1.exe1.exeCode function: 0_2_005FFF700_2_005FFF70
                Source: C:\Users\user\Desktop\SimpleLoader v2.1.exe1.exeCode function: 0_2_00609F000_2_00609F00
                Source: C:\Users\user\Desktop\SimpleLoader v2.1.exe1.exeCode function: 0_2_005EE7300_2_005EE730
                Source: C:\Users\user\Desktop\SimpleLoader v2.1.exe1.exeCode function: 0_2_005F97200_2_005F9720
                Source: C:\Users\user\Desktop\SimpleLoader v2.1.exe1.exeCode function: 0_2_005E67D00_2_005E67D0
                Source: C:\Users\user\Desktop\SimpleLoader v2.1.exe1.exeCode function: 0_2_005E9FF00_2_005E9FF0
                Source: C:\Users\user\Desktop\SimpleLoader v2.1.exe1.exeCode function: 0_2_005E17900_2_005E1790
                Source: C:\Users\user\Desktop\SimpleLoader v2.1.exe1.exeCode function: 0_2_005F67900_2_005F6790
                Source: C:\Users\user\Desktop\SimpleLoader v2.1.exe1.exeCode function: 0_2_005EB7800_2_005EB780
                Source: C:\Users\user\Desktop\SimpleLoader v2.1.exe1.exeCode function: 0_2_0062E7820_2_0062E782
                Source: C:\Users\user\Desktop\SimpleLoader v2.1.exe1.exeCode function: 0_2_00600F800_2_00600F80
                Source: C:\Users\user\Desktop\SimpleLoader v2.1.exe1.exeCode function: 2_2_0060F0602_2_0060F060
                Source: C:\Users\user\Desktop\SimpleLoader v2.1.exe1.exeCode function: 2_2_005F40402_2_005F4040
                Source: C:\Users\user\Desktop\SimpleLoader v2.1.exe1.exeCode function: 2_2_005E60702_2_005E6070
                Source: C:\Users\user\Desktop\SimpleLoader v2.1.exe1.exeCode function: 2_2_0060A0202_2_0060A020
                Source: C:\Users\user\Desktop\SimpleLoader v2.1.exe1.exeCode function: 2_2_005FC0102_2_005FC010
                Source: C:\Users\user\Desktop\SimpleLoader v2.1.exe1.exeCode function: 2_2_005E10002_2_005E1000
                Source: C:\Users\user\Desktop\SimpleLoader v2.1.exe1.exeCode function: 2_2_006138132_2_00613813
                Source: C:\Users\user\Desktop\SimpleLoader v2.1.exe1.exeCode function: 2_2_005FA8202_2_005FA820
                Source: C:\Users\user\Desktop\SimpleLoader v2.1.exe1.exeCode function: 2_2_005F90202_2_005F9020
                Source: C:\Users\user\Desktop\SimpleLoader v2.1.exe1.exeCode function: 2_2_006100D02_2_006100D0
                Source: C:\Users\user\Desktop\SimpleLoader v2.1.exe1.exeCode function: 2_2_005E80902_2_005E8090
                Source: C:\Users\user\Desktop\SimpleLoader v2.1.exe1.exeCode function: 2_2_005F08902_2_005F0890
                Source: C:\Users\user\Desktop\SimpleLoader v2.1.exe1.exeCode function: 2_2_005E40802_2_005E4080
                Source: C:\Users\user\Desktop\SimpleLoader v2.1.exe1.exeCode function: 2_2_0060D0802_2_0060D080
                Source: C:\Users\user\Desktop\SimpleLoader v2.1.exe1.exeCode function: 2_2_006038902_2_00603890
                Source: C:\Users\user\Desktop\SimpleLoader v2.1.exe1.exeCode function: 2_2_006118902_2_00611890
                Source: C:\Users\user\Desktop\SimpleLoader v2.1.exe1.exeCode function: 2_2_005E58A02_2_005E58A0
                Source: C:\Users\user\Desktop\SimpleLoader v2.1.exe1.exeCode function: 2_2_005FE0A02_2_005FE0A0
                Source: C:\Users\user\Desktop\SimpleLoader v2.1.exe1.exeCode function: 2_2_006131602_2_00613160
                Source: C:\Users\user\Desktop\SimpleLoader v2.1.exe1.exeCode function: 2_2_005E49402_2_005E4940
                Source: C:\Users\user\Desktop\SimpleLoader v2.1.exe1.exeCode function: 2_2_005FC9402_2_005FC940
                Source: C:\Users\user\Desktop\SimpleLoader v2.1.exe1.exeCode function: 2_2_005EE1702_2_005EE170
                Source: C:\Users\user\Desktop\SimpleLoader v2.1.exe1.exeCode function: 2_2_006129202_2_00612920
                Source: C:\Users\user\Desktop\SimpleLoader v2.1.exe1.exeCode function: 2_2_006091002_2_00609100
                Source: C:\Users\user\Desktop\SimpleLoader v2.1.exe1.exeCode function: 2_2_0062C9082_2_0062C908
                Source: C:\Users\user\Desktop\SimpleLoader v2.1.exe1.exeCode function: 2_2_006001102_2_00600110
                Source: C:\Users\user\Desktop\SimpleLoader v2.1.exe1.exeCode function: 2_2_005E31F02_2_005E31F0
                Source: C:\Users\user\Desktop\SimpleLoader v2.1.exe1.exeCode function: 2_2_005FB1E02_2_005FB1E0
                Source: C:\Users\user\Desktop\SimpleLoader v2.1.exe1.exeCode function: 2_2_0060F9B02_2_0060F9B0
                Source: C:\Users\user\Desktop\SimpleLoader v2.1.exe1.exeCode function: 2_2_005F61802_2_005F6180
                Source: C:\Users\user\Desktop\SimpleLoader v2.1.exe1.exeCode function: 2_2_00608A502_2_00608A50
                Source: C:\Users\user\Desktop\SimpleLoader v2.1.exe1.exeCode function: 2_2_00616A542_2_00616A54
                Source: C:\Users\user\Desktop\SimpleLoader v2.1.exe1.exeCode function: 2_2_006052202_2_00605220
                Source: C:\Users\user\Desktop\SimpleLoader v2.1.exe1.exeCode function: 2_2_00606A002_2_00606A00
                Source: C:\Users\user\Desktop\SimpleLoader v2.1.exe1.exeCode function: 2_2_006082002_2_00608200
                Source: C:\Users\user\Desktop\SimpleLoader v2.1.exe1.exeCode function: 2_2_00600A102_2_00600A10
                Source: C:\Users\user\Desktop\SimpleLoader v2.1.exe1.exeCode function: 2_2_005E52202_2_005E5220
                Source: C:\Users\user\Desktop\SimpleLoader v2.1.exe1.exeCode function: 2_2_005E92202_2_005E9220
                Source: C:\Users\user\Desktop\SimpleLoader v2.1.exe1.exeCode function: 2_2_0060F2E02_2_0060F2E0
                Source: C:\Users\user\Desktop\SimpleLoader v2.1.exe1.exeCode function: 2_2_005EF2D02_2_005EF2D0
                Source: C:\Users\user\Desktop\SimpleLoader v2.1.exe1.exeCode function: 2_2_005F52C02_2_005F52C0
                Source: C:\Users\user\Desktop\SimpleLoader v2.1.exe1.exeCode function: 2_2_005F42902_2_005F4290
                Source: C:\Users\user\Desktop\SimpleLoader v2.1.exe1.exeCode function: 2_2_00609AB02_2_00609AB0
                Source: C:\Users\user\Desktop\SimpleLoader v2.1.exe1.exeCode function: 2_2_005E22802_2_005E2280
                Source: C:\Users\user\Desktop\SimpleLoader v2.1.exe1.exeCode function: 2_2_005EEAA02_2_005EEAA0
                Source: C:\Users\user\Desktop\SimpleLoader v2.1.exe1.exeCode function: 2_2_006013702_2_00601370
                Source: C:\Users\user\Desktop\SimpleLoader v2.1.exe1.exeCode function: 2_2_005E83402_2_005E8340
                Source: C:\Users\user\Desktop\SimpleLoader v2.1.exe1.exeCode function: 2_2_0060EB402_2_0060EB40
                Source: C:\Users\user\Desktop\SimpleLoader v2.1.exe1.exeCode function: 2_2_005FFB702_2_005FFB70
                Source: C:\Users\user\Desktop\SimpleLoader v2.1.exe1.exeCode function: 2_2_006003502_2_00600350
                Source: C:\Users\user\Desktop\SimpleLoader v2.1.exe1.exeCode function: 2_2_005EC3102_2_005EC310
                Source: C:\Users\user\Desktop\SimpleLoader v2.1.exe1.exeCode function: 2_2_005EB3002_2_005EB300
                Source: C:\Users\user\Desktop\SimpleLoader v2.1.exe1.exeCode function: 2_2_005FF3D02_2_005FF3D0
                Source: C:\Users\user\Desktop\SimpleLoader v2.1.exe1.exeCode function: 2_2_005F73F02_2_005F73F0
                Source: C:\Users\user\Desktop\SimpleLoader v2.1.exe1.exeCode function: 2_2_005E63902_2_005E6390
                Source: C:\Users\user\Desktop\SimpleLoader v2.1.exe1.exeCode function: 2_2_005F33902_2_005F3390
                Source: C:\Users\user\Desktop\SimpleLoader v2.1.exe1.exeCode function: 2_2_005FABA02_2_005FABA0
                Source: C:\Users\user\Desktop\SimpleLoader v2.1.exe1.exeCode function: 2_2_00605C602_2_00605C60
                Source: C:\Users\user\Desktop\SimpleLoader v2.1.exe1.exeCode function: 2_2_006134772_2_00613477
                Source: C:\Users\user\Desktop\SimpleLoader v2.1.exe1.exeCode function: 2_2_005E2C402_2_005E2C40
                Source: C:\Users\user\Desktop\SimpleLoader v2.1.exe1.exeCode function: 2_2_005FEC402_2_005FEC40
                Source: C:\Users\user\Desktop\SimpleLoader v2.1.exe1.exeCode function: 2_2_00608C402_2_00608C40
                Source: C:\Users\user\Desktop\SimpleLoader v2.1.exe1.exeCode function: 2_2_006084502_2_00608450
                Source: C:\Users\user\Desktop\SimpleLoader v2.1.exe1.exeCode function: 2_2_006214202_2_00621420
                Source: C:\Users\user\Desktop\SimpleLoader v2.1.exe1.exeCode function: 2_2_0061B41A2_2_0061B41A
                Source: C:\Users\user\Desktop\SimpleLoader v2.1.exe1.exeCode function: 2_2_005E5C202_2_005E5C20
                Source: C:\Users\user\Desktop\SimpleLoader v2.1.exe1.exeCode function: 2_2_005EE4C02_2_005EE4C0
                Source: C:\Users\user\Desktop\SimpleLoader v2.1.exe1.exeCode function: 2_2_005F3CC02_2_005F3CC0
                Source: C:\Users\user\Desktop\SimpleLoader v2.1.exe1.exeCode function: 2_2_005FCCE02_2_005FCCE0
                Source: C:\Users\user\Desktop\SimpleLoader v2.1.exe1.exeCode function: 2_2_005F04902_2_005F0490
                Source: C:\Users\user\Desktop\SimpleLoader v2.1.exe1.exeCode function: 2_2_005E6C802_2_005E6C80
                Source: C:\Users\user\Desktop\SimpleLoader v2.1.exe1.exeCode function: 2_2_005F64802_2_005F6480
                Source: C:\Users\user\Desktop\SimpleLoader v2.1.exe1.exeCode function: 2_2_006054802_2_00605480
                Source: C:\Users\user\Desktop\SimpleLoader v2.1.exe1.exeCode function: 2_2_006124802_2_00612480
                Source: C:\Users\user\Desktop\SimpleLoader v2.1.exe1.exeCode function: 2_2_00613C902_2_00613C90
                Source: C:\Users\user\Desktop\SimpleLoader v2.1.exe1.exeCode function: 2_2_005E54A02_2_005E54A0
                Source: C:\Users\user\Desktop\SimpleLoader v2.1.exe1.exeCode function: 2_2_005FDD502_2_005FDD50
                Source: C:\Users\user\Desktop\SimpleLoader v2.1.exe1.exeCode function: 2_2_005F85402_2_005F8540
                Source: C:\Users\user\Desktop\SimpleLoader v2.1.exe1.exeCode function: 2_2_0060FD502_2_0060FD50
                Source: C:\Users\user\Desktop\SimpleLoader v2.1.exe1.exeCode function: 2_2_005FD5602_2_005FD560
                Source: C:\Users\user\Desktop\SimpleLoader v2.1.exe1.exeCode function: 2_2_005F95002_2_005F9500
                Source: C:\Users\user\Desktop\SimpleLoader v2.1.exe1.exeCode function: 2_2_005E7D302_2_005E7D30
                Source: C:\Users\user\Desktop\SimpleLoader v2.1.exe1.exeCode function: 2_2_005EF5302_2_005EF530
                Source: C:\Users\user\Desktop\SimpleLoader v2.1.exe1.exeCode function: 2_2_005EAD302_2_005EAD30
                Source: C:\Users\user\Desktop\SimpleLoader v2.1.exe1.exeCode function: 2_2_006135C02_2_006135C0
                Source: C:\Users\user\Desktop\SimpleLoader v2.1.exe1.exeCode function: 2_2_0060F5D02_2_0060F5D0
                Source: C:\Users\user\Desktop\SimpleLoader v2.1.exe1.exeCode function: 2_2_0060EDB02_2_0060EDB0
                Source: C:\Users\user\Desktop\SimpleLoader v2.1.exe1.exeCode function: 2_2_005E95802_2_005E9580
                Source: C:\Users\user\Desktop\SimpleLoader v2.1.exe1.exeCode function: 2_2_0060DD802_2_0060DD80
                Source: C:\Users\user\Desktop\SimpleLoader v2.1.exe1.exeCode function: 2_2_005F55B02_2_005F55B0
                Source: C:\Users\user\Desktop\SimpleLoader v2.1.exe1.exeCode function: 2_2_005F7E502_2_005F7E50
                Source: C:\Users\user\Desktop\SimpleLoader v2.1.exe1.exeCode function: 2_2_005E86402_2_005E8640
                Source: C:\Users\user\Desktop\SimpleLoader v2.1.exe1.exeCode function: 2_2_005E36402_2_005E3640
                Source: C:\Users\user\Desktop\SimpleLoader v2.1.exe1.exeCode function: 2_2_005F6E402_2_005F6E40
                Source: C:\Users\user\Desktop\SimpleLoader v2.1.exe1.exeCode function: 2_2_005E46602_2_005E4660
                Source: C:\Users\user\Desktop\SimpleLoader v2.1.exe1.exeCode function: 2_2_006106202_2_00610620
                Source: C:\Users\user\Desktop\SimpleLoader v2.1.exe1.exeCode function: 2_2_006096302_2_00609630
                Source: C:\Users\user\Desktop\SimpleLoader v2.1.exe1.exeCode function: 2_2_005FB6302_2_005FB630
                Source: C:\Users\user\Desktop\SimpleLoader v2.1.exe1.exeCode function: 2_2_005F76202_2_005F7620
                Source: C:\Users\user\Desktop\SimpleLoader v2.1.exe1.exeCode function: 2_2_005F0E202_2_005F0E20
                Source: C:\Users\user\Desktop\SimpleLoader v2.1.exe1.exeCode function: 2_2_00611EF02_2_00611EF0
                Source: C:\Users\user\Desktop\SimpleLoader v2.1.exe1.exeCode function: 2_2_005F26F02_2_005F26F0
                Source: C:\Users\user\Desktop\SimpleLoader v2.1.exe1.exeCode function: 2_2_005F2E902_2_005F2E90
                Source: C:\Users\user\Desktop\SimpleLoader v2.1.exe1.exeCode function: 2_2_0060B6802_2_0060B680
                Source: C:\Users\user\Desktop\SimpleLoader v2.1.exe1.exeCode function: 2_2_006086902_2_00608690
                Source: C:\Users\user\Desktop\SimpleLoader v2.1.exe1.exeCode function: 2_2_00612E902_2_00612E90
                Source: C:\Users\user\Desktop\SimpleLoader v2.1.exe1.exeCode function: 2_2_005FC6A02_2_005FC6A0
                Source: C:\Users\user\Desktop\SimpleLoader v2.1.exe1.exeCode function: 2_2_005FFF702_2_005FFF70
                Source: C:\Users\user\Desktop\SimpleLoader v2.1.exe1.exeCode function: 2_2_00609F002_2_00609F00
                Source: C:\Users\user\Desktop\SimpleLoader v2.1.exe1.exeCode function: 2_2_005EE7302_2_005EE730
                Source: C:\Users\user\Desktop\SimpleLoader v2.1.exe1.exeCode function: 2_2_005F97202_2_005F9720
                Source: C:\Users\user\Desktop\SimpleLoader v2.1.exe1.exeCode function: 2_2_005E67D02_2_005E67D0
                Source: C:\Users\user\Desktop\SimpleLoader v2.1.exe1.exeCode function: 2_2_005E9FF02_2_005E9FF0
                Source: C:\Users\user\Desktop\SimpleLoader v2.1.exe1.exeCode function: 2_2_005E17902_2_005E1790
                Source: C:\Users\user\Desktop\SimpleLoader v2.1.exe1.exeCode function: 2_2_005F67902_2_005F6790
                Source: C:\Users\user\Desktop\SimpleLoader v2.1.exe1.exeCode function: 2_2_005EB7802_2_005EB780
                Source: C:\Users\user\Desktop\SimpleLoader v2.1.exe1.exeCode function: 2_2_0062E7822_2_0062E782
                Source: C:\Users\user\Desktop\SimpleLoader v2.1.exe1.exeCode function: 2_2_00600F802_2_00600F80
                Source: C:\Users\user\Desktop\SimpleLoader v2.1.exe1.exeCode function: 4_2_0043805F4_2_0043805F
                Source: C:\Users\user\Desktop\SimpleLoader v2.1.exe1.exeCode function: 4_2_0040B8604_2_0040B860
                Source: C:\Users\user\Desktop\SimpleLoader v2.1.exe1.exeCode function: 4_2_0044F0604_2_0044F060
                Source: C:\Users\user\Desktop\SimpleLoader v2.1.exe1.exeCode function: 4_2_004461D04_2_004461D0
                Source: C:\Users\user\Desktop\SimpleLoader v2.1.exe1.exeCode function: 4_2_00417AC04_2_00417AC0
                Source: C:\Users\user\Desktop\SimpleLoader v2.1.exe1.exeCode function: 4_2_0041CAA04_2_0041CAA0
                Source: C:\Users\user\Desktop\SimpleLoader v2.1.exe1.exeCode function: 4_2_0044E2B04_2_0044E2B0
                Source: C:\Users\user\Desktop\SimpleLoader v2.1.exe1.exeCode function: 4_2_004293204_2_00429320
                Source: C:\Users\user\Desktop\SimpleLoader v2.1.exe1.exeCode function: 4_2_0040D4404_2_0040D440
                Source: C:\Users\user\Desktop\SimpleLoader v2.1.exe1.exeCode function: 4_2_0044FD204_2_0044FD20
                Source: C:\Users\user\Desktop\SimpleLoader v2.1.exe1.exeCode function: 4_2_00445E004_2_00445E00
                Source: C:\Users\user\Desktop\SimpleLoader v2.1.exe1.exeCode function: 4_2_00421EC04_2_00421EC0
                Source: C:\Users\user\Desktop\SimpleLoader v2.1.exe1.exeCode function: 4_2_0041BED04_2_0041BED0
                Source: C:\Users\user\Desktop\SimpleLoader v2.1.exe1.exeCode function: 4_2_00430EF04_2_00430EF0
                Source: C:\Users\user\Desktop\SimpleLoader v2.1.exe1.exeCode function: 4_2_0040E6A04_2_0040E6A0
                Source: C:\Users\user\Desktop\SimpleLoader v2.1.exe1.exeCode function: 4_2_00415EA54_2_00415EA5
                Source: C:\Users\user\Desktop\SimpleLoader v2.1.exe1.exeCode function: 4_2_0042D7824_2_0042D782
                Source: C:\Users\user\Desktop\SimpleLoader v2.1.exe1.exeCode function: 4_2_004010404_2_00401040
                Source: C:\Users\user\Desktop\SimpleLoader v2.1.exe1.exeCode function: 4_2_0043B0494_2_0043B049
                Source: C:\Users\user\Desktop\SimpleLoader v2.1.exe1.exeCode function: 4_2_004208514_2_00420851
                Source: C:\Users\user\Desktop\SimpleLoader v2.1.exe1.exeCode function: 4_2_0044E8504_2_0044E850
                Source: C:\Users\user\Desktop\SimpleLoader v2.1.exe1.exeCode function: 4_2_0040F8704_2_0040F870
                Source: C:\Users\user\Desktop\SimpleLoader v2.1.exe1.exeCode function: 4_2_004300704_2_00430070
                Source: C:\Users\user\Desktop\SimpleLoader v2.1.exe1.exeCode function: 4_2_0043E0304_2_0043E030
                Source: C:\Users\user\Desktop\SimpleLoader v2.1.exe1.exeCode function: 4_2_0042E0D04_2_0042E0D0
                Source: C:\Users\user\Desktop\SimpleLoader v2.1.exe1.exeCode function: 4_2_0041209E4_2_0041209E
                Source: C:\Users\user\Desktop\SimpleLoader v2.1.exe1.exeCode function: 4_2_0043D8A04_2_0043D8A0
                Source: C:\Users\user\Desktop\SimpleLoader v2.1.exe1.exeCode function: 4_2_004259604_2_00425960
                Source: C:\Users\user\Desktop\SimpleLoader v2.1.exe1.exeCode function: 4_2_004479604_2_00447960
                Source: C:\Users\user\Desktop\SimpleLoader v2.1.exe1.exeCode function: 4_2_004411004_2_00441100
                Source: C:\Users\user\Desktop\SimpleLoader v2.1.exe1.exeCode function: 4_2_0043C91A4_2_0043C91A
                Source: C:\Users\user\Desktop\SimpleLoader v2.1.exe1.exeCode function: 4_2_004471204_2_00447120
                Source: C:\Users\user\Desktop\SimpleLoader v2.1.exe1.exeCode function: 4_2_0042C93A4_2_0042C93A
                Source: C:\Users\user\Desktop\SimpleLoader v2.1.exe1.exeCode function: 4_2_0042A1D04_2_0042A1D0
                Source: C:\Users\user\Desktop\SimpleLoader v2.1.exe1.exeCode function: 4_2_004219EE4_2_004219EE
                Source: C:\Users\user\Desktop\SimpleLoader v2.1.exe1.exeCode function: 4_2_0043C1A84_2_0043C1A8
                Source: C:\Users\user\Desktop\SimpleLoader v2.1.exe1.exeCode function: 4_2_00408A604_2_00408A60
                Source: C:\Users\user\Desktop\SimpleLoader v2.1.exe1.exeCode function: 4_2_004322734_2_00432273
                Source: C:\Users\user\Desktop\SimpleLoader v2.1.exe1.exeCode function: 4_2_0041B2104_2_0041B210
                Source: C:\Users\user\Desktop\SimpleLoader v2.1.exe1.exeCode function: 4_2_0040A2304_2_0040A230
                Source: C:\Users\user\Desktop\SimpleLoader v2.1.exe1.exeCode function: 4_2_00402AD04_2_00402AD0
                Source: C:\Users\user\Desktop\SimpleLoader v2.1.exe1.exeCode function: 4_2_004572E44_2_004572E4
                Source: C:\Users\user\Desktop\SimpleLoader v2.1.exe1.exeCode function: 4_2_0040BAF04_2_0040BAF0
                Source: C:\Users\user\Desktop\SimpleLoader v2.1.exe1.exeCode function: 4_2_0042134F4_2_0042134F
                Source: C:\Users\user\Desktop\SimpleLoader v2.1.exe1.exeCode function: 4_2_004283504_2_00428350
                Source: C:\Users\user\Desktop\SimpleLoader v2.1.exe1.exeCode function: 4_2_004343304_2_00434330
                Source: C:\Users\user\Desktop\SimpleLoader v2.1.exe1.exeCode function: 4_2_00427B374_2_00427B37
                Source: C:\Users\user\Desktop\SimpleLoader v2.1.exe1.exeCode function: 4_2_004413D04_2_004413D0
                Source: C:\Users\user\Desktop\SimpleLoader v2.1.exe1.exeCode function: 4_2_0043E3E04_2_0043E3E0
                Source: C:\Users\user\Desktop\SimpleLoader v2.1.exe1.exeCode function: 4_2_004373E44_2_004373E4
                Source: C:\Users\user\Desktop\SimpleLoader v2.1.exe1.exeCode function: 4_2_0042D3BF4_2_0042D3BF
                Source: C:\Users\user\Desktop\SimpleLoader v2.1.exe1.exeCode function: 4_2_0044EC404_2_0044EC40
                Source: C:\Users\user\Desktop\SimpleLoader v2.1.exe1.exeCode function: 4_2_0041C4444_2_0041C444
                Source: C:\Users\user\Desktop\SimpleLoader v2.1.exe1.exeCode function: 4_2_004094504_2_00409450
                Source: C:\Users\user\Desktop\SimpleLoader v2.1.exe1.exeCode function: 4_2_004304514_2_00430451
                Source: C:\Users\user\Desktop\SimpleLoader v2.1.exe1.exeCode function: 4_2_0044D4604_2_0044D460
                Source: C:\Users\user\Desktop\SimpleLoader v2.1.exe1.exeCode function: 4_2_00443C6D4_2_00443C6D
                Source: C:\Users\user\Desktop\SimpleLoader v2.1.exe1.exeCode function: 4_2_00433C004_2_00433C00
                Source: C:\Users\user\Desktop\SimpleLoader v2.1.exe1.exeCode function: 4_2_0042E4224_2_0042E422
                Source: C:\Users\user\Desktop\SimpleLoader v2.1.exe1.exeCode function: 4_2_00429C204_2_00429C20
                Source: C:\Users\user\Desktop\SimpleLoader v2.1.exe1.exeCode function: 4_2_004034D04_2_004034D0
                Source: C:\Users\user\Desktop\SimpleLoader v2.1.exe1.exeCode function: 4_2_004454E04_2_004454E0
                Source: C:\Users\user\Desktop\SimpleLoader v2.1.exe1.exeCode function: 4_2_0040C4F04_2_0040C4F0
                Source: C:\Users\user\Desktop\SimpleLoader v2.1.exe1.exeCode function: 4_2_0043848D4_2_0043848D
                Source: C:\Users\user\Desktop\SimpleLoader v2.1.exe1.exeCode function: 4_2_00423C9E4_2_00423C9E
                Source: C:\Users\user\Desktop\SimpleLoader v2.1.exe1.exeCode function: 4_2_00437CB94_2_00437CB9
                Source: C:\Users\user\Desktop\SimpleLoader v2.1.exe1.exeCode function: 4_2_0040CD404_2_0040CD40
                Source: C:\Users\user\Desktop\SimpleLoader v2.1.exe1.exeCode function: 4_2_00425D604_2_00425D60
                Source: C:\Users\user\Desktop\SimpleLoader v2.1.exe1.exeCode function: 4_2_00407D704_2_00407D70
                Source: C:\Users\user\Desktop\SimpleLoader v2.1.exe1.exeCode function: 4_2_00440D704_2_00440D70
                Source: C:\Users\user\Desktop\SimpleLoader v2.1.exe1.exeCode function: 4_2_0044D5704_2_0044D570
                Source: C:\Users\user\Desktop\SimpleLoader v2.1.exe1.exeCode function: 4_2_0043805F4_2_0043805F
                Source: C:\Users\user\Desktop\SimpleLoader v2.1.exe1.exeCode function: 4_2_0041FD104_2_0041FD10
                Source: C:\Users\user\Desktop\SimpleLoader v2.1.exe1.exeCode function: 4_2_00416D204_2_00416D20
                Source: C:\Users\user\Desktop\SimpleLoader v2.1.exe1.exeCode function: 4_2_00447DE24_2_00447DE2
                Source: C:\Users\user\Desktop\SimpleLoader v2.1.exe1.exeCode function: 4_2_0042DDF04_2_0042DDF0
                Source: C:\Users\user\Desktop\SimpleLoader v2.1.exe1.exeCode function: 4_2_00446D804_2_00446D80
                Source: C:\Users\user\Desktop\SimpleLoader v2.1.exe1.exeCode function: 4_2_0044D5894_2_0044D589
                Source: C:\Users\user\Desktop\SimpleLoader v2.1.exe1.exeCode function: 4_2_0044D58B4_2_0044D58B
                Source: C:\Users\user\Desktop\SimpleLoader v2.1.exe1.exeCode function: 4_2_004025904_2_00402590
                Source: C:\Users\user\Desktop\SimpleLoader v2.1.exe1.exeCode function: 4_2_004255A04_2_004255A0
                Source: C:\Users\user\Desktop\SimpleLoader v2.1.exe1.exeCode function: 4_2_0044A6404_2_0044A640
                Source: C:\Users\user\Desktop\SimpleLoader v2.1.exe1.exeCode function: 4_2_00432E5D4_2_00432E5D
                Source: C:\Users\user\Desktop\SimpleLoader v2.1.exe1.exeCode function: 4_2_0043266C4_2_0043266C
                Source: C:\Users\user\Desktop\SimpleLoader v2.1.exe1.exeCode function: 4_2_00403E704_2_00403E70
                Source: C:\Users\user\Desktop\SimpleLoader v2.1.exe1.exeCode function: 4_2_0041EE704_2_0041EE70
                Source: C:\Users\user\Desktop\SimpleLoader v2.1.exe1.exeCode function: 4_2_0044D6084_2_0044D608
                Source: C:\Users\user\Desktop\SimpleLoader v2.1.exe1.exeCode function: 4_2_00438E0F4_2_00438E0F
                Source: C:\Users\user\Desktop\SimpleLoader v2.1.exe1.exeCode function: 4_2_0044461C4_2_0044461C
                Source: C:\Users\user\Desktop\SimpleLoader v2.1.exe1.exeCode function: 4_2_00408ED04_2_00408ED0
                Source: C:\Users\user\Desktop\SimpleLoader v2.1.exe1.exeCode function: 4_2_004316FF4_2_004316FF
                Source: C:\Users\user\Desktop\SimpleLoader v2.1.exe1.exeCode function: 4_2_004457404_2_00445740
                Source: C:\Users\user\Desktop\SimpleLoader v2.1.exe1.exeCode function: 4_2_004047524_2_00404752
                Source: C:\Users\user\Desktop\SimpleLoader v2.1.exe1.exeCode function: 4_2_0041E75B4_2_0041E75B
                Source: C:\Users\user\Desktop\SimpleLoader v2.1.exe1.exeCode function: 4_2_0044FF604_2_0044FF60
                Source: C:\Users\user\Desktop\SimpleLoader v2.1.exe1.exeCode function: 4_2_0041F7794_2_0041F779
                Source: C:\Users\user\Desktop\SimpleLoader v2.1.exe1.exeCode function: 4_2_0044D7304_2_0044D730
                Source: C:\Users\user\Desktop\SimpleLoader v2.1.exe1.exeCode function: 4_2_0044D7E04_2_0044D7E0
                Source: C:\Users\user\Desktop\SimpleLoader v2.1.exe1.exeCode function: 4_2_00425FA04_2_00425FA0
                Source: C:\Users\user\Desktop\SimpleLoader v2.1.exe1.exeCode function: 4_2_00410FB04_2_00410FB0
                Source: C:\Users\user\Desktop\SimpleLoader v2.1.exe1.exeCode function: String function: 00624014 appears 34 times
                Source: C:\Users\user\Desktop\SimpleLoader v2.1.exe1.exeCode function: String function: 00616F60 appears 102 times
                Source: C:\Users\user\Desktop\SimpleLoader v2.1.exe1.exeCode function: String function: 0061F1CC appears 46 times
                Source: C:\Users\user\Desktop\SimpleLoader v2.1.exe1.exeCode function: String function: 0041B200 appears 98 times
                Source: C:\Users\user\Desktop\SimpleLoader v2.1.exe1.exeCode function: String function: 0040B230 appears 39 times
                Source: SimpleLoader v2.1.exe1.exeStatic PE information: invalid certificate
                Source: SimpleLoader v2.1.exe1.exeStatic PE information: EXECUTABLE_IMAGE, 32BIT_MACHINE
                Source: SimpleLoader v2.1.exe1.exeStatic PE information: Section: .bss ZLIB complexity 1.0003282335069446
                Source: classification engineClassification label: mal100.troj.spyw.evad.winEXE@7/0@2/2
                Source: C:\Users\user\Desktop\SimpleLoader v2.1.exe1.exeCode function: 4_2_004461D0 CoCreateInstance,SysAllocString,CoSetProxyBlanket,SysAllocString,SysAllocString,VariantInit,VariantClear,SysFreeString,SysFreeString,SysFreeString,SysFreeString,GetVolumeInformationW,4_2_004461D0
                Source: SimpleLoader v2.1.exe1.exeStatic PE information: Section: .text IMAGE_SCN_CNT_CODE, IMAGE_SCN_MEM_EXECUTE, IMAGE_SCN_MEM_READ
                Source: C:\Users\user\Desktop\SimpleLoader v2.1.exe1.exeKey opened: HKEY_CURRENT_USER\Software\Policies\Microsoft\Windows\Safer\CodeIdentifiersJump to behavior
                Source: SimpleLoader v2.1.exe1.exe, 00000004.00000003.1435011180.00000000038C4000.00000004.00000800.00020000.00000000.sdmp, SimpleLoader v2.1.exe1.exe, 00000004.00000003.1456629075.00000000038B2000.00000004.00000800.00020000.00000000.sdmp, SimpleLoader v2.1.exe1.exe, 00000004.00000003.1435424942.00000000038A4000.00000004.00000800.00020000.00000000.sdmpBinary or memory string: CREATE TABLE password_notes (id INTEGER PRIMARY KEY AUTOINCREMENT, parent_id INTEGER NOT NULL REFERENCES logins ON UPDATE CASCADE ON DELETE CASCADE DEFERRABLE INITIALLY DEFERRED, key VARCHAR NOT NULL, value BLOB, date_created INTEGER NOT NULL, confidential INTEGER, UNIQUE (parent_id, key));
                Source: SimpleLoader v2.1.exe1.exeVirustotal: Detection: 42%
                Source: SimpleLoader v2.1.exe1.exeReversingLabs: Detection: 39%
                Source: C:\Users\user\Desktop\SimpleLoader v2.1.exe1.exeFile read: C:\Users\user\Desktop\SimpleLoader v2.1.exe1.exeJump to behavior
                Source: unknownProcess created: C:\Users\user\Desktop\SimpleLoader v2.1.exe1.exe "C:\Users\user\Desktop\SimpleLoader v2.1.exe1.exe"
                Source: C:\Users\user\Desktop\SimpleLoader v2.1.exe1.exeProcess created: C:\Users\user\Desktop\SimpleLoader v2.1.exe1.exe "C:\Users\user\Desktop\SimpleLoader v2.1.exe1.exe"
                Source: C:\Users\user\Desktop\SimpleLoader v2.1.exe1.exeProcess created: C:\Users\user\Desktop\SimpleLoader v2.1.exe1.exe "C:\Users\user\Desktop\SimpleLoader v2.1.exe1.exe"
                Source: C:\Users\user\Desktop\SimpleLoader v2.1.exe1.exeProcess created: C:\Users\user\Desktop\SimpleLoader v2.1.exe1.exe "C:\Users\user\Desktop\SimpleLoader v2.1.exe1.exe"
                Source: C:\Users\user\Desktop\SimpleLoader v2.1.exe1.exeProcess created: C:\Users\user\Desktop\SimpleLoader v2.1.exe1.exe "C:\Users\user\Desktop\SimpleLoader v2.1.exe1.exe"Jump to behavior
                Source: C:\Users\user\Desktop\SimpleLoader v2.1.exe1.exeProcess created: C:\Users\user\Desktop\SimpleLoader v2.1.exe1.exe "C:\Users\user\Desktop\SimpleLoader v2.1.exe1.exe"Jump to behavior
                Source: C:\Users\user\Desktop\SimpleLoader v2.1.exe1.exeProcess created: C:\Users\user\Desktop\SimpleLoader v2.1.exe1.exe "C:\Users\user\Desktop\SimpleLoader v2.1.exe1.exe"Jump to behavior
                Source: C:\Users\user\Desktop\SimpleLoader v2.1.exe1.exeSection loaded: apphelp.dllJump to behavior
                Source: C:\Users\user\Desktop\SimpleLoader v2.1.exe1.exeSection loaded: kernel.appcore.dllJump to behavior
                Source: C:\Users\user\Desktop\SimpleLoader v2.1.exe1.exeSection loaded: windows.storage.dllJump to behavior
                Source: C:\Users\user\Desktop\SimpleLoader v2.1.exe1.exeSection loaded: wldp.dllJump to behavior
                Source: C:\Users\user\Desktop\SimpleLoader v2.1.exe1.exeSection loaded: winhttp.dllJump to behavior
                Source: C:\Users\user\Desktop\SimpleLoader v2.1.exe1.exeSection loaded: ondemandconnroutehelper.dllJump to behavior
                Source: C:\Users\user\Desktop\SimpleLoader v2.1.exe1.exeSection loaded: webio.dllJump to behavior
                Source: C:\Users\user\Desktop\SimpleLoader v2.1.exe1.exeSection loaded: mswsock.dllJump to behavior
                Source: C:\Users\user\Desktop\SimpleLoader v2.1.exe1.exeSection loaded: iphlpapi.dllJump to behavior
                Source: C:\Users\user\Desktop\SimpleLoader v2.1.exe1.exeSection loaded: winnsi.dllJump to behavior
                Source: C:\Users\user\Desktop\SimpleLoader v2.1.exe1.exeSection loaded: sspicli.dllJump to behavior
                Source: C:\Users\user\Desktop\SimpleLoader v2.1.exe1.exeSection loaded: dnsapi.dllJump to behavior
                Source: C:\Users\user\Desktop\SimpleLoader v2.1.exe1.exeSection loaded: rasadhlp.dllJump to behavior
                Source: C:\Users\user\Desktop\SimpleLoader v2.1.exe1.exeSection loaded: fwpuclnt.dllJump to behavior
                Source: C:\Users\user\Desktop\SimpleLoader v2.1.exe1.exeSection loaded: schannel.dllJump to behavior
                Source: C:\Users\user\Desktop\SimpleLoader v2.1.exe1.exeSection loaded: mskeyprotect.dllJump to behavior
                Source: C:\Users\user\Desktop\SimpleLoader v2.1.exe1.exeSection loaded: ntasn1.dllJump to behavior
                Source: C:\Users\user\Desktop\SimpleLoader v2.1.exe1.exeSection loaded: ncrypt.dllJump to behavior
                Source: C:\Users\user\Desktop\SimpleLoader v2.1.exe1.exeSection loaded: ncryptsslp.dllJump to behavior
                Source: C:\Users\user\Desktop\SimpleLoader v2.1.exe1.exeSection loaded: msasn1.dllJump to behavior
                Source: C:\Users\user\Desktop\SimpleLoader v2.1.exe1.exeSection loaded: cryptsp.dllJump to behavior
                Source: C:\Users\user\Desktop\SimpleLoader v2.1.exe1.exeSection loaded: rsaenh.dllJump to behavior
                Source: C:\Users\user\Desktop\SimpleLoader v2.1.exe1.exeSection loaded: cryptbase.dllJump to behavior
                Source: C:\Users\user\Desktop\SimpleLoader v2.1.exe1.exeSection loaded: gpapi.dllJump to behavior
                Source: C:\Users\user\Desktop\SimpleLoader v2.1.exe1.exeSection loaded: dpapi.dllJump to behavior
                Source: C:\Users\user\Desktop\SimpleLoader v2.1.exe1.exeSection loaded: ondemandconnroutehelper.dllJump to behavior
                Source: C:\Users\user\Desktop\SimpleLoader v2.1.exe1.exeSection loaded: kernel.appcore.dllJump to behavior
                Source: C:\Users\user\Desktop\SimpleLoader v2.1.exe1.exeSection loaded: uxtheme.dllJump to behavior
                Source: C:\Users\user\Desktop\SimpleLoader v2.1.exe1.exeSection loaded: wbemcomn.dllJump to behavior
                Source: C:\Users\user\Desktop\SimpleLoader v2.1.exe1.exeSection loaded: amsi.dllJump to behavior
                Source: C:\Users\user\Desktop\SimpleLoader v2.1.exe1.exeSection loaded: userenv.dllJump to behavior
                Source: C:\Users\user\Desktop\SimpleLoader v2.1.exe1.exeSection loaded: profapi.dllJump to behavior
                Source: C:\Users\user\Desktop\SimpleLoader v2.1.exe1.exeSection loaded: version.dllJump to behavior
                Source: C:\Users\user\Desktop\SimpleLoader v2.1.exe1.exeSection loaded: ondemandconnroutehelper.dllJump to behavior
                Source: C:\Users\user\Desktop\SimpleLoader v2.1.exe1.exeSection loaded: ondemandconnroutehelper.dllJump to behavior
                Source: C:\Users\user\Desktop\SimpleLoader v2.1.exe1.exeSection loaded: ondemandconnroutehelper.dllJump to behavior
                Source: C:\Users\user\Desktop\SimpleLoader v2.1.exe1.exeSection loaded: ondemandconnroutehelper.dllJump to behavior
                Source: C:\Users\user\Desktop\SimpleLoader v2.1.exe1.exeSection loaded: ondemandconnroutehelper.dllJump to behavior
                Source: C:\Users\user\Desktop\SimpleLoader v2.1.exe1.exeSection loaded: ondemandconnroutehelper.dllJump to behavior
                Source: SimpleLoader v2.1.exe1.exeStatic PE information: DYNAMIC_BASE, NX_COMPAT, TERMINAL_SERVER_AWARE
                Source: C:\Users\user\Desktop\SimpleLoader v2.1.exe1.exeCode function: 0_2_006418C1 push ebp; iretd 0_2_006418C9
                Source: C:\Users\user\Desktop\SimpleLoader v2.1.exe1.exeCode function: 0_2_0061711A push ecx; ret 0_2_0061712D
                Source: C:\Users\user\Desktop\SimpleLoader v2.1.exe1.exeCode function: 2_2_0061711A push ecx; ret 2_2_0061712D
                Source: C:\Users\user\Desktop\SimpleLoader v2.1.exe1.exeCode function: 4_2_00452859 push ebx; retf 4_2_0045285A
                Source: C:\Users\user\Desktop\SimpleLoader v2.1.exe1.exeCode function: 4_2_00454422 push edi; retf 4_2_00454423
                Source: C:\Users\user\Desktop\SimpleLoader v2.1.exe1.exeCode function: 4_2_0042B48C push eax; retf 4_2_0042B48D
                Source: C:\Users\user\Desktop\SimpleLoader v2.1.exe1.exeCode function: 4_2_00455CB0 push cs; ret 4_2_00455C69
                Source: C:\Users\user\Desktop\SimpleLoader v2.1.exe1.exeCode function: 4_2_00427569 push ebp; mov dword ptr [esp], ebx4_2_0042756D
                Source: C:\Users\user\Desktop\SimpleLoader v2.1.exe1.exeCode function: 4_2_00457FC2 push ebx; ret 4_2_00457FC3
                Source: C:\Users\user\Desktop\SimpleLoader v2.1.exe1.exeProcess information set: NOOPENFILEERRORBOXJump to behavior

                Malware Analysis System Evasion

                barindex
                Source: C:\Users\user\Desktop\SimpleLoader v2.1.exe1.exeWMI Queries: IWbemServices::ExecQuery - ROOT\CIMV2 : SELECT * FROM Win32_VideoController
                Source: C:\Users\user\Desktop\SimpleLoader v2.1.exe1.exeSystem information queried: FirmwareTableInformationJump to behavior
                Source: C:\Users\user\Desktop\SimpleLoader v2.1.exe1.exeWindow / User API: threadDelayed 5888Jump to behavior
                Source: C:\Users\user\Desktop\SimpleLoader v2.1.exe1.exe TID: 5768Thread sleep time: -180000s >= -30000sJump to behavior
                Source: C:\Users\user\Desktop\SimpleLoader v2.1.exe1.exe TID: 6596Thread sleep count: 5888 > 30Jump to behavior
                Source: C:\Users\user\Desktop\SimpleLoader v2.1.exe1.exeWMI Queries: IWbemServices::ExecQuery - ROOT\CIMV2 : SELECT * FROM Win32_BIOS
                Source: C:\Users\user\Desktop\SimpleLoader v2.1.exe1.exeLast function: Thread delayed
                Source: C:\Users\user\Desktop\SimpleLoader v2.1.exe1.exeLast function: Thread delayed
                Source: C:\Users\user\Desktop\SimpleLoader v2.1.exe1.exeCode function: 0_2_00628ECE FindFirstFileExW,0_2_00628ECE
                Source: C:\Users\user\Desktop\SimpleLoader v2.1.exe1.exeCode function: 0_2_00628F7F FindFirstFileExW,FindNextFileW,FindClose,FindClose,0_2_00628F7F
                Source: C:\Users\user\Desktop\SimpleLoader v2.1.exe1.exeCode function: 2_2_00628ECE FindFirstFileExW,2_2_00628ECE
                Source: C:\Users\user\Desktop\SimpleLoader v2.1.exe1.exeCode function: 2_2_00628F7F FindFirstFileExW,FindNextFileW,FindClose,FindClose,2_2_00628F7F
                Source: SimpleLoader v2.1.exe1.exe, 00000004.00000003.1456965442.00000000038CB000.00000004.00000800.00020000.00000000.sdmpBinary or memory string: Interactive Brokers - EU East & CentralVMware20,11696487552
                Source: SimpleLoader v2.1.exe1.exe, 00000004.00000003.1456965442.00000000038CB000.00000004.00000800.00020000.00000000.sdmpBinary or memory string: secure.bankofamerica.comVMware20,11696487552|UE
                Source: SimpleLoader v2.1.exe1.exe, 00000004.00000003.1456965442.00000000038CB000.00000004.00000800.00020000.00000000.sdmpBinary or memory string: account.microsoft.com/profileVMware20,11696487552u
                Source: SimpleLoader v2.1.exe1.exe, 00000004.00000003.1456965442.00000000038CB000.00000004.00000800.00020000.00000000.sdmpBinary or memory string: discord.comVMware20,11696487552f
                Source: SimpleLoader v2.1.exe1.exe, 00000004.00000003.1456965442.00000000038CB000.00000004.00000800.00020000.00000000.sdmpBinary or memory string: bankofamerica.comVMware20,11696487552x
                Source: SimpleLoader v2.1.exe1.exe, 00000004.00000003.1456965442.00000000038CB000.00000004.00000800.00020000.00000000.sdmpBinary or memory string: www.interactivebrokers.comVMware20,11696487552}
                Source: SimpleLoader v2.1.exe1.exe, 00000004.00000003.1520289258.0000000001049000.00000004.00000020.00020000.00000000.sdmp, SimpleLoader v2.1.exe1.exe, 00000004.00000003.1433741427.0000000001049000.00000004.00000020.00020000.00000000.sdmp, SimpleLoader v2.1.exe1.exe, 00000004.00000003.1571380014.0000000001049000.00000004.00000020.00020000.00000000.sdmp, SimpleLoader v2.1.exe1.exe, 00000004.00000003.2218386420.0000000001049000.00000004.00000020.00020000.00000000.sdmp, SimpleLoader v2.1.exe1.exe, 00000004.00000003.1570795532.0000000001049000.00000004.00000020.00020000.00000000.sdmp, SimpleLoader v2.1.exe1.exe, 00000004.00000003.1556652338.0000000001049000.00000004.00000020.00020000.00000000.sdmp, SimpleLoader v2.1.exe1.exe, 00000004.00000002.2609810835.000000000104C000.00000004.00000020.00020000.00000000.sdmp, SimpleLoader v2.1.exe1.exe, 00000004.00000003.1551661764.0000000001049000.00000004.00000020.00020000.00000000.sdmp, SimpleLoader v2.1.exe1.exe, 00000004.00000003.2218575506.000000000104B000.00000004.00000020.00020000.00000000.sdmpBinary or memory string: Hyper-V RAW
                Source: SimpleLoader v2.1.exe1.exe, 00000004.00000003.1456965442.00000000038CB000.00000004.00000800.00020000.00000000.sdmpBinary or memory string: ms.portal.azure.comVMware20,11696487552
                Source: SimpleLoader v2.1.exe1.exe, 00000004.00000003.1456965442.00000000038CB000.00000004.00000800.00020000.00000000.sdmpBinary or memory string: Canara Change Transaction PasswordVMware20,11696487552
                Source: SimpleLoader v2.1.exe1.exe, 00000004.00000003.1456857433.00000000038D8000.00000004.00000800.00020000.00000000.sdmpBinary or memory string: - GDCDYNVMware20,11696487552p
                Source: SimpleLoader v2.1.exe1.exe, 00000004.00000003.1456965442.00000000038CB000.00000004.00000800.00020000.00000000.sdmpBinary or memory string: Interactive Brokers - COM.HKVMware20,11696487552
                Source: SimpleLoader v2.1.exe1.exe, 00000004.00000003.1456965442.00000000038CB000.00000004.00000800.00020000.00000000.sdmpBinary or memory string: global block list test formVMware20,11696487552
                Source: SimpleLoader v2.1.exe1.exe, 00000004.00000003.1456965442.00000000038CB000.00000004.00000800.00020000.00000000.sdmpBinary or memory string: tasks.office.comVMware20,11696487552o
                Source: SimpleLoader v2.1.exe1.exe, 00000004.00000003.1456965442.00000000038CB000.00000004.00000800.00020000.00000000.sdmpBinary or memory string: AMC password management pageVMware20,11696487552
                Source: SimpleLoader v2.1.exe1.exe, 00000004.00000003.1456965442.00000000038CB000.00000004.00000800.00020000.00000000.sdmpBinary or memory string: interactivebrokers.co.inVMware20,11696487552d
                Source: SimpleLoader v2.1.exe1.exe, 00000004.00000003.1456965442.00000000038CB000.00000004.00000800.00020000.00000000.sdmpBinary or memory string: interactivebrokers.comVMware20,11696487552
                Source: SimpleLoader v2.1.exe1.exe, 00000004.00000003.1456965442.00000000038CB000.00000004.00000800.00020000.00000000.sdmpBinary or memory string: dev.azure.comVMware20,11696487552j
                Source: SimpleLoader v2.1.exe1.exe, 00000004.00000003.1456965442.00000000038CB000.00000004.00000800.00020000.00000000.sdmpBinary or memory string: Interactive Brokers - HKVMware20,11696487552]
                Source: SimpleLoader v2.1.exe1.exe, 00000004.00000003.1456965442.00000000038CB000.00000004.00000800.00020000.00000000.sdmpBinary or memory string: microsoft.visualstudio.comVMware20,11696487552x
                Source: SimpleLoader v2.1.exe1.exe, 00000004.00000003.1456965442.00000000038CB000.00000004.00000800.00020000.00000000.sdmpBinary or memory string: netportal.hdfcbank.comVMware20,11696487552
                Source: SimpleLoader v2.1.exe1.exe, 00000004.00000003.1456965442.00000000038CB000.00000004.00000800.00020000.00000000.sdmpBinary or memory string: trackpan.utiitsl.comVMware20,11696487552h
                Source: SimpleLoader v2.1.exe1.exe, 00000004.00000003.1456965442.00000000038CB000.00000004.00000800.00020000.00000000.sdmpBinary or memory string: Interactive Brokers - NDCDYNVMware20,11696487552z
                Source: SimpleLoader v2.1.exe1.exe, 00000004.00000003.1456965442.00000000038CB000.00000004.00000800.00020000.00000000.sdmpBinary or memory string: www.interactivebrokers.co.inVMware20,11696487552~
                Source: SimpleLoader v2.1.exe1.exe, 00000004.00000003.1456965442.00000000038CB000.00000004.00000800.00020000.00000000.sdmpBinary or memory string: outlook.office365.comVMware20,11696487552t
                Source: SimpleLoader v2.1.exe1.exe, 00000004.00000003.1456965442.00000000038CB000.00000004.00000800.00020000.00000000.sdmpBinary or memory string: Canara Change Transaction PasswordVMware20,11696487552^
                Source: SimpleLoader v2.1.exe1.exe, 00000004.00000003.1456965442.00000000038CB000.00000004.00000800.00020000.00000000.sdmpBinary or memory string: Interactive Brokers - GDCDYNVMware20,11696487552p
                Source: SimpleLoader v2.1.exe1.exe, 00000004.00000003.1456965442.00000000038CB000.00000004.00000800.00020000.00000000.sdmpBinary or memory string: Interactive Brokers - EU WestVMware20,11696487552n
                Source: SimpleLoader v2.1.exe1.exe, 00000004.00000003.1456965442.00000000038CB000.00000004.00000800.00020000.00000000.sdmpBinary or memory string: outlook.office.comVMware20,11696487552s
                Source: SimpleLoader v2.1.exe1.exe, 00000004.00000003.1456965442.00000000038CB000.00000004.00000800.00020000.00000000.sdmpBinary or memory string: Test URL for global passwords blocklistVMware20,11696487552
                Source: SimpleLoader v2.1.exe1.exe, 00000004.00000003.1456965442.00000000038CB000.00000004.00000800.00020000.00000000.sdmpBinary or memory string: turbotax.intuit.comVMware20,11696487552t
                Source: SimpleLoader v2.1.exe1.exe, 00000004.00000003.1456965442.00000000038CB000.00000004.00000800.00020000.00000000.sdmpBinary or memory string: Canara Transaction PasswordVMware20,11696487552x
                Source: SimpleLoader v2.1.exe1.exe, 00000004.00000003.1456965442.00000000038CB000.00000004.00000800.00020000.00000000.sdmpBinary or memory string: Canara Transaction PasswordVMware20,11696487552}
                Source: SimpleLoader v2.1.exe1.exe, 00000004.00000003.1456965442.00000000038CB000.00000004.00000800.00020000.00000000.sdmpBinary or memory string: Interactive Brokers - non-EU EuropeVMware20,11696487552
                Source: SimpleLoader v2.1.exe1.exe, 00000004.00000003.1520289258.0000000001049000.00000004.00000020.00020000.00000000.sdmp, SimpleLoader v2.1.exe1.exe, 00000004.00000003.1433741427.0000000001049000.00000004.00000020.00020000.00000000.sdmp, SimpleLoader v2.1.exe1.exe, 00000004.00000003.1571380014.0000000001049000.00000004.00000020.00020000.00000000.sdmp, SimpleLoader v2.1.exe1.exe, 00000004.00000003.2218386420.0000000001049000.00000004.00000020.00020000.00000000.sdmp, SimpleLoader v2.1.exe1.exe, 00000004.00000003.1570795532.0000000001049000.00000004.00000020.00020000.00000000.sdmp, SimpleLoader v2.1.exe1.exe, 00000004.00000003.1556652338.0000000001049000.00000004.00000020.00020000.00000000.sdmp, SimpleLoader v2.1.exe1.exe, 00000004.00000002.2609810835.000000000104C000.00000004.00000020.00020000.00000000.sdmp, SimpleLoader v2.1.exe1.exe, 00000004.00000003.1551661764.0000000001049000.00000004.00000020.00020000.00000000.sdmp, SimpleLoader v2.1.exe1.exe, 00000004.00000003.2218575506.000000000104B000.00000004.00000020.00020000.00000000.sdmpBinary or memory string: Hyper-V RAWC
                Source: C:\Users\user\Desktop\SimpleLoader v2.1.exe1.exeAPI call chain: ExitProcess graph end node
                Source: C:\Users\user\Desktop\SimpleLoader v2.1.exe1.exeProcess information queried: ProcessInformationJump to behavior
                Source: C:\Users\user\Desktop\SimpleLoader v2.1.exe1.exeCode function: 4_2_0044BB80 LdrInitializeThunk,4_2_0044BB80
                Source: C:\Users\user\Desktop\SimpleLoader v2.1.exe1.exeCode function: 0_2_00616DE8 IsProcessorFeaturePresent,IsDebuggerPresent,SetUnhandledExceptionFilter,UnhandledExceptionFilter,0_2_00616DE8
                Source: C:\Users\user\Desktop\SimpleLoader v2.1.exe1.exeCode function: 0_2_0063F1B4 mov edi, dword ptr fs:[00000030h]0_2_0063F1B4
                Source: C:\Users\user\Desktop\SimpleLoader v2.1.exe1.exeCode function: 0_2_0062490C GetProcessHeap,0_2_0062490C
                Source: C:\Users\user\Desktop\SimpleLoader v2.1.exe1.exeCode function: 0_2_00616A2C SetUnhandledExceptionFilter,UnhandledExceptionFilter,GetCurrentProcess,TerminateProcess,0_2_00616A2C
                Source: C:\Users\user\Desktop\SimpleLoader v2.1.exe1.exeCode function: 0_2_00616DE8 IsProcessorFeaturePresent,IsDebuggerPresent,SetUnhandledExceptionFilter,UnhandledExceptionFilter,0_2_00616DE8
                Source: C:\Users\user\Desktop\SimpleLoader v2.1.exe1.exeCode function: 0_2_00616DDC SetUnhandledExceptionFilter,0_2_00616DDC
                Source: C:\Users\user\Desktop\SimpleLoader v2.1.exe1.exeCode function: 0_2_0061EF1E IsDebuggerPresent,SetUnhandledExceptionFilter,UnhandledExceptionFilter,0_2_0061EF1E
                Source: C:\Users\user\Desktop\SimpleLoader v2.1.exe1.exeCode function: 2_2_00616A2C SetUnhandledExceptionFilter,UnhandledExceptionFilter,GetCurrentProcess,TerminateProcess,2_2_00616A2C
                Source: C:\Users\user\Desktop\SimpleLoader v2.1.exe1.exeCode function: 2_2_00616DE8 IsProcessorFeaturePresent,IsDebuggerPresent,SetUnhandledExceptionFilter,UnhandledExceptionFilter,2_2_00616DE8
                Source: C:\Users\user\Desktop\SimpleLoader v2.1.exe1.exeCode function: 2_2_00616DDC SetUnhandledExceptionFilter,2_2_00616DDC
                Source: C:\Users\user\Desktop\SimpleLoader v2.1.exe1.exeCode function: 2_2_0061EF1E IsDebuggerPresent,SetUnhandledExceptionFilter,UnhandledExceptionFilter,2_2_0061EF1E

                HIPS / PFW / Operating System Protection Evasion

                barindex
                Source: C:\Users\user\Desktop\SimpleLoader v2.1.exe1.exeCode function: 0_2_0063F1B4 GetProcAddress,GetProcAddress,GetProcAddress,GetProcAddress,GetProcAddress,GetProcAddress,GetProcAddress,GetProcAddress,CreateProcessW,CreateProcessW,VirtualAlloc,VirtualAlloc,GetThreadContext,Wow64GetThreadContext,ReadProcessMemory,ReadProcessMemory,VirtualAllocEx,VirtualAllocEx,GetProcAddress,TerminateProcess,WriteProcessMemory,WriteProcessMemory,WriteProcessMemory,WriteProcessMemory,WriteProcessMemory,WriteProcessMemory,SetThreadContext,Wow64SetThreadContext,ResumeThread,ResumeThread,0_2_0063F1B4
                Source: C:\Users\user\Desktop\SimpleLoader v2.1.exe1.exeMemory written: C:\Users\user\Desktop\SimpleLoader v2.1.exe1.exe base: 400000 value starts with: 4D5AJump to behavior
                Source: C:\Users\user\Desktop\SimpleLoader v2.1.exe1.exeProcess created: C:\Users\user\Desktop\SimpleLoader v2.1.exe1.exe "C:\Users\user\Desktop\SimpleLoader v2.1.exe1.exe"Jump to behavior
                Source: C:\Users\user\Desktop\SimpleLoader v2.1.exe1.exeProcess created: C:\Users\user\Desktop\SimpleLoader v2.1.exe1.exe "C:\Users\user\Desktop\SimpleLoader v2.1.exe1.exe"Jump to behavior
                Source: C:\Users\user\Desktop\SimpleLoader v2.1.exe1.exeProcess created: C:\Users\user\Desktop\SimpleLoader v2.1.exe1.exe "C:\Users\user\Desktop\SimpleLoader v2.1.exe1.exe"Jump to behavior
                Source: C:\Users\user\Desktop\SimpleLoader v2.1.exe1.exeCode function: GetLocaleInfoW,0_2_006288F6
                Source: C:\Users\user\Desktop\SimpleLoader v2.1.exe1.exeCode function: EnumSystemLocalesW,0_2_006288AB
                Source: C:\Users\user\Desktop\SimpleLoader v2.1.exe1.exeCode function: EnumSystemLocalesW,0_2_006241F7
                Source: C:\Users\user\Desktop\SimpleLoader v2.1.exe1.exeCode function: GetLocaleInfoW,GetLocaleInfoW,GetACP,0_2_0062899D
                Source: C:\Users\user\Desktop\SimpleLoader v2.1.exe1.exeCode function: GetUserDefaultLCID,IsValidCodePage,IsValidLocale,GetLocaleInfoW,GetLocaleInfoW,0_2_00628238
                Source: C:\Users\user\Desktop\SimpleLoader v2.1.exe1.exeCode function: GetLocaleInfoW,0_2_00628AA3
                Source: C:\Users\user\Desktop\SimpleLoader v2.1.exe1.exeCode function: GetLocaleInfoW,0_2_00623CFC
                Source: C:\Users\user\Desktop\SimpleLoader v2.1.exe1.exeCode function: EnumSystemLocalesW,0_2_00628489
                Source: C:\Users\user\Desktop\SimpleLoader v2.1.exe1.exeCode function: GetLocaleInfoW,GetLocaleInfoW,GetLocaleInfoW,0_2_00628524
                Source: C:\Users\user\Desktop\SimpleLoader v2.1.exe1.exeCode function: EnumSystemLocalesW,0_2_00628777
                Source: C:\Users\user\Desktop\SimpleLoader v2.1.exe1.exeCode function: GetLocaleInfoW,0_2_006287D6
                Source: C:\Users\user\Desktop\SimpleLoader v2.1.exe1.exeCode function: GetLocaleInfoW,2_2_006288F6
                Source: C:\Users\user\Desktop\SimpleLoader v2.1.exe1.exeCode function: EnumSystemLocalesW,2_2_006288AB
                Source: C:\Users\user\Desktop\SimpleLoader v2.1.exe1.exeCode function: EnumSystemLocalesW,2_2_006241F7
                Source: C:\Users\user\Desktop\SimpleLoader v2.1.exe1.exeCode function: GetLocaleInfoW,GetLocaleInfoW,GetACP,2_2_0062899D
                Source: C:\Users\user\Desktop\SimpleLoader v2.1.exe1.exeCode function: GetUserDefaultLCID,IsValidCodePage,IsValidLocale,GetLocaleInfoW,GetLocaleInfoW,2_2_00628238
                Source: C:\Users\user\Desktop\SimpleLoader v2.1.exe1.exeCode function: GetLocaleInfoW,2_2_00628AA3
                Source: C:\Users\user\Desktop\SimpleLoader v2.1.exe1.exeCode function: GetLocaleInfoW,2_2_00623CFC
                Source: C:\Users\user\Desktop\SimpleLoader v2.1.exe1.exeCode function: EnumSystemLocalesW,2_2_00628489
                Source: C:\Users\user\Desktop\SimpleLoader v2.1.exe1.exeCode function: GetLocaleInfoW,GetLocaleInfoW,GetLocaleInfoW,2_2_00628524
                Source: C:\Users\user\Desktop\SimpleLoader v2.1.exe1.exeCode function: EnumSystemLocalesW,2_2_00628777
                Source: C:\Users\user\Desktop\SimpleLoader v2.1.exe1.exeCode function: GetLocaleInfoW,2_2_006287D6
                Source: C:\Users\user\Desktop\SimpleLoader v2.1.exe1.exeQueries volume information: C:\ VolumeInformationJump to behavior
                Source: C:\Users\user\Desktop\SimpleLoader v2.1.exe1.exeCode function: 0_2_00617827 GetSystemTimeAsFileTime,GetCurrentThreadId,GetCurrentProcessId,QueryPerformanceCounter,0_2_00617827
                Source: C:\Users\user\Desktop\SimpleLoader v2.1.exe1.exeKey value queried: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Cryptography MachineGuidJump to behavior
                Source: SimpleLoader v2.1.exe1.exe, 00000004.00000002.2609991669.00000000010A0000.00000004.00000020.00020000.00000000.sdmp, SimpleLoader v2.1.exe1.exe, 00000004.00000003.1571380014.0000000001049000.00000004.00000020.00020000.00000000.sdmp, SimpleLoader v2.1.exe1.exe, 00000004.00000003.1570795532.0000000001049000.00000004.00000020.00020000.00000000.sdmp, SimpleLoader v2.1.exe1.exe, 00000004.00000003.1571288821.00000000010A4000.00000004.00000020.00020000.00000000.sdmp, SimpleLoader v2.1.exe1.exe, 00000004.00000003.1556652338.0000000001049000.00000004.00000020.00020000.00000000.sdmp, SimpleLoader v2.1.exe1.exe, 00000004.00000003.2218298564.00000000010A0000.00000004.00000020.00020000.00000000.sdmp, SimpleLoader v2.1.exe1.exe, 00000004.00000003.1595827243.00000000010A4000.00000004.00000020.00020000.00000000.sdmp, SimpleLoader v2.1.exe1.exe, 00000004.00000003.1556652338.000000000103F000.00000004.00000020.00020000.00000000.sdmpBinary or memory string: %ProgramFiles%\Windows Defender\MsMpeng.exe
                Source: C:\Users\user\Desktop\SimpleLoader v2.1.exe1.exeWMI Queries: IWbemServices::ExecQuery - ROOT\SecurityCenter2 : SELECT * FROM AntiVirusProduct

                Stealing of Sensitive Information

                barindex
                Source: Yara matchFile source: Process Memory Space: SimpleLoader v2.1.exe1.exe PID: 6680, type: MEMORYSTR
                Source: Yara matchFile source: 4.2.SimpleLoader v2.1.exe1.exe.400000.0.raw.unpack, type: UNPACKEDPE
                Source: Yara matchFile source: 4.2.SimpleLoader v2.1.exe1.exe.400000.0.unpack, type: UNPACKEDPE
                Source: Yara matchFile source: 00000004.00000002.2609424437.0000000000400000.00000040.00000400.00020000.00000000.sdmp, type: MEMORY
                Source: Yara matchFile source: 00000000.00000002.1370342630.0000000001147000.00000004.00000020.00020000.00000000.sdmp, type: MEMORY
                Source: SimpleLoader v2.1.exe1.exe, 00000004.00000003.1520289258.0000000001049000.00000004.00000020.00020000.00000000.sdmpString found in binary or memory: Wallets/Electrum-LTC
                Source: SimpleLoader v2.1.exe1.exe, 00000004.00000003.1523351846.00000000010A8000.00000004.00000020.00020000.00000000.sdmpString found in binary or memory: \??\C:\Users\user\AppData\Roaming\ElectronCash\walletsC
                Source: SimpleLoader v2.1.exe1.exe, 00000004.00000003.1551795829.00000000010A4000.00000004.00000020.00020000.00000000.sdmpString found in binary or memory: "ez":"Jaxx Liberty"},{"en":"fihkakfobkmkjojpchpfgcmhfjnmnfpi","ez":"BitApp"}
                Source: SimpleLoader v2.1.exe1.exe, 00000004.00000003.1520289258.0000000001049000.00000004.00000020.00020000.00000000.sdmpString found in binary or memory: window-state.json
                Source: SimpleLoader v2.1.exe1.exe, 00000004.00000003.1520289258.0000000001049000.00000004.00000020.00020000.00000000.sdmpString found in binary or memory: %appdata%\Exodus\exodus.wallet
                Source: SimpleLoader v2.1.exe1.exe, 00000004.00000003.1551795829.00000000010A4000.00000004.00000020.00020000.00000000.sdmpString found in binary or memory: pfdialjgjfhomihkjbmgjidlcdno","ez":"ExodusWeb3"},{"en":"onhogfjeacnfoofkfgpp V
                Source: SimpleLoader v2.1.exe1.exe, 00000004.00000003.1520289258.0000000001049000.00000004.00000020.00020000.00000000.sdmpString found in binary or memory: %appdata%\Ethereum
                Source: SimpleLoader v2.1.exe1.exe, 00000004.00000003.1551817451.000000000101B000.00000004.00000020.00020000.00000000.sdmpString found in binary or memory: %localappdata%\Coinomi\Coinomi\wallets
                Source: SimpleLoader v2.1.exe1.exe, 00000004.00000003.1520215654.0000000001094000.00000004.00000020.00020000.00000000.sdmpString found in binary or memory: keystore
                Source: SimpleLoader v2.1.exe1.exe, 00000004.00000002.2609991669.00000000010A0000.00000004.00000020.00020000.00000000.sdmpString found in binary or memory: C:\Users\user\AppData\Roaming\Ledger Live
                Source: C:\Users\user\Desktop\SimpleLoader v2.1.exe1.exeFile opened: C:\Users\user\AppData\Roaming\Mozilla\Firefox\Profiles\2o7hffxt.default-release\logins.jsonJump to behavior
                Source: C:\Users\user\Desktop\SimpleLoader v2.1.exe1.exeFile opened: C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Local Extension Settings\flpiciilemghbmfalicajoolhkkenfeJump to behavior
                Source: C:\Users\user\Desktop\SimpleLoader v2.1.exe1.exeFile opened: C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Local Extension Settings\ilgcnhelpchnceeipipijaljkblbcobJump to behavior
                Source: C:\Users\user\Desktop\SimpleLoader v2.1.exe1.exeFile opened: C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Local Extension Settings\kppfdiipphfccemcignhifpjkapfbihdJump to behavior
                Source: C:\Users\user\Desktop\SimpleLoader v2.1.exe1.exeFile opened: C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Local Extension Settings\dlcobpjiigpikoobohmabehhmhfoodbbJump to behavior
                Source: C:\Users\user\Desktop\SimpleLoader v2.1.exe1.exeFile opened: C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Local Extension Settings\nngceckbapebfimnlniiiahkandclblbJump to behavior
                Source: C:\Users\user\Desktop\SimpleLoader v2.1.exe1.exeFile opened: C:\Users\user\AppData\Roaming\Mozilla\Firefox\Profiles\2o7hffxt.default-release\cert9.dbJump to behavior
                Source: C:\Users\user\Desktop\SimpleLoader v2.1.exe1.exeFile opened: C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Web DataJump to behavior
                Source: C:\Users\user\Desktop\SimpleLoader v2.1.exe1.exeFile opened: C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Local Extension Settings\ocjdpmoallmgmjbbogfiiaofphbjgchhJump to behavior
                Source: C:\Users\user\Desktop\SimpleLoader v2.1.exe1.exeFile opened: C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Local Extension Settings\kkpllkodjeloidieedojogacfhpaihohJump to behavior
                Source: C:\Users\user\Desktop\SimpleLoader v2.1.exe1.exeFile opened: C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Local Extension Settings\bhhhlbepdkbapadjdnnojkbgioiodbicJump to behavior
                Source: C:\Users\user\Desktop\SimpleLoader v2.1.exe1.exeFile opened: C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Local Extension Settings\pioclpoplcdbaefihamjohnefbikjilcJump to behavior
                Source: C:\Users\user\Desktop\SimpleLoader v2.1.exe1.exeFile opened: C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Local Extension Settings\ibnejdfjmmkpcnlpebklmnkoeoihofecJump to behavior
                Source: C:\Users\user\Desktop\SimpleLoader v2.1.exe1.exeFile opened: C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Local Extension Settings\ppbibelpcjmhbdihakflkdcoccbgbkpoJump to behavior
                Source: C:\Users\user\Desktop\SimpleLoader v2.1.exe1.exeFile opened: C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Local Extension Settings\oeljdldpnmdbchonielidgobddffflaJump to behavior
                Source: C:\Users\user\Desktop\SimpleLoader v2.1.exe1.exeFile opened: C:\Users\user\AppData\Local\Microsoft\Edge\User Data\Default\HistoryJump to behavior
                Source: C:\Users\user\Desktop\SimpleLoader v2.1.exe1.exeFile opened: C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Local Extension Settings\kpfopkelmapcoipemfendmdcghnegimnJump to behavior
                Source: C:\Users\user\Desktop\SimpleLoader v2.1.exe1.exeFile opened: C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Local Extension Settings\aiifbnbfobpmeekipheeijimdpnlpgppJump to behavior
                Source: C:\Users\user\Desktop\SimpleLoader v2.1.exe1.exeFile opened: C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Local Extension Settings\bfnaelmomeimhlpmgjnjophhpkkoljpaJump to behavior
                Source: C:\Users\user\Desktop\SimpleLoader v2.1.exe1.exeFile opened: C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Local Extension Settings\ojggmchlghnjlapmfbnjholfjkiidbchJump to behavior
                Source: C:\Users\user\Desktop\SimpleLoader v2.1.exe1.exeFile opened: C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Local Extension Settings\fihkakfobkmkjojpchpfgcmhfjnmnfpiJump to behavior
                Source: C:\Users\user\Desktop\SimpleLoader v2.1.exe1.exeFile opened: C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Local Extension Settings\nanjmdknhkinifnkgdcggcfnhdaammmjJump to behavior
                Source: C:\Users\user\Desktop\SimpleLoader v2.1.exe1.exeFile opened: C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Local Extension Settings\fhbohimaelbohpjbbldcngcnapndodjpJump to behavior
                Source: C:\Users\user\Desktop\SimpleLoader v2.1.exe1.exeFile opened: C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Local Extension Settings\nkbihfbeogaeaoehlefnkodbefgpgknnJump to behavior
                Source: C:\Users\user\Desktop\SimpleLoader v2.1.exe1.exeFile opened: C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Local Extension Settings\nlgbhdfgdhgbiamfdfmbikcdghidoaddJump to behavior
                Source: C:\Users\user\Desktop\SimpleLoader v2.1.exe1.exeFile opened: C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Local Extension Settings\hnfanknocfeofbddgcijnmhnfnkdnaadJump to behavior
                Source: C:\Users\user\Desktop\SimpleLoader v2.1.exe1.exeFile opened: C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Local Extension Settings\mkpegjkblkkefacfnmkajcjmabijhclgJump to behavior
                Source: C:\Users\user\Desktop\SimpleLoader v2.1.exe1.exeFile opened: C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Local Extension Settings\dkdedlpgdmmkkfjabffeganieamfklkmJump to behavior
                Source: C:\Users\user\Desktop\SimpleLoader v2.1.exe1.exeFile opened: C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Local Extension Settings\infeboajgfhgbjpjbeppbkgnabfdkdafJump to behavior
                Source: C:\Users\user\Desktop\SimpleLoader v2.1.exe1.exeFile opened: C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Local Extension Settings\blnieiiffboillknjnepogjhkgnoapacJump to behavior
                Source: C:\Users\user\Desktop\SimpleLoader v2.1.exe1.exeFile opened: C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\HistoryJump to behavior
                Source: C:\Users\user\Desktop\SimpleLoader v2.1.exe1.exeFile opened: C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Local Extension Settings\jiidiaalihmmhddjgbnbgdfflelocpakJump to behavior
                Source: C:\Users\user\Desktop\SimpleLoader v2.1.exe1.exeFile opened: C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Local Extension Settings\acmacodkjbdgmoleebolmdjonilkdbchJump to behavior
                Source: C:\Users\user\Desktop\SimpleLoader v2.1.exe1.exeFile opened: C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Local Extension Settings\mmmjbcfofconkannjonfmjjajpllddbgJump to behavior
                Source: C:\Users\user\Desktop\SimpleLoader v2.1.exe1.exeFile opened: C:\Users\user\AppData\Roaming\Mozilla\Firefox\ProfilesJump to behavior
                Source: C:\Users\user\Desktop\SimpleLoader v2.1.exe1.exeFile opened: C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Local Extension Settings\anokgmphncpekkhclmingpimjmcooifbJump to behavior
                Source: C:\Users\user\Desktop\SimpleLoader v2.1.exe1.exeFile opened: C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Local Extension Settings\efbglgofoippbgcjepnhiblaibcnclgkJump to behavior
                Source: C:\Users\user\Desktop\SimpleLoader v2.1.exe1.exeFile opened: C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Local Extension Settings\hcflpincpppdclinealmandijcmnkbgnJump to behavior
                Source: C:\Users\user\Desktop\SimpleLoader v2.1.exe1.exeFile opened: C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Local Extension Settings\ejbalbakoplchlghecdalmeeeajnimhmJump to behavior
                Source: C:\Users\user\Desktop\SimpleLoader v2.1.exe1.exeFile opened: C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Local Extension Settings\cpojfbodiccabbabgimdeohkkpjfpbnfJump to behavior
                Source: C:\Users\user\Desktop\SimpleLoader v2.1.exe1.exeFile opened: C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Local Extension Settings\hdokiejnpimakedhajhdlcegeplioahdJump to behavior
                Source: C:\Users\user\Desktop\SimpleLoader v2.1.exe1.exeFile opened: C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Local Extension Settings\kjmoohlgokccodicjjfebfomlbljgfhkJump to behavior
                Source: C:\Users\user\Desktop\SimpleLoader v2.1.exe1.exeFile opened: C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Local Extension Settings\cphhlgmgameodnhkjdmkpanlelnlohaoJump to behavior
                Source: C:\Users\user\Desktop\SimpleLoader v2.1.exe1.exeFile opened: C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Network\CookiesJump to behavior
                Source: C:\Users\user\Desktop\SimpleLoader v2.1.exe1.exeFile opened: C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Local Extension Settings\mopnmbcafieddcagagdcbnhejhlodfddJump to behavior
                Source: C:\Users\user\Desktop\SimpleLoader v2.1.exe1.exeFile opened: C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Local Extension Settings\klnaejjgbibmhlephnhpmaofohgkpgkdJump to behavior
                Source: C:\Users\user\Desktop\SimpleLoader v2.1.exe1.exeFile opened: C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Local Extension Settings\aeblfdkhhhdcdjpifhhbdiojplfjncoaJump to behavior
                Source: C:\Users\user\Desktop\SimpleLoader v2.1.exe1.exeFile opened: C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Local Extension Settings\aholpfdialjgjfhomihkjbmgjidlcdnoJump to behavior
                Source: C:\Users\user\Desktop\SimpleLoader v2.1.exe1.exeFile opened: C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Sync Extension Settings\ilgcnhelpchnceeipipijaljkblbcobJump to behavior
                Source: C:\Users\user\Desktop\SimpleLoader v2.1.exe1.exeFile opened: C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Local Extension Settings\dmkamcknogkgcdfhhbddcghachkejeapJump to behavior
                Source: C:\Users\user\Desktop\SimpleLoader v2.1.exe1.exeFile opened: C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Local Extension Settings\onofpnbbkehpmmoabgpcpmigafmmnjhJump to behavior
                Source: C:\Users\user\Desktop\SimpleLoader v2.1.exe1.exeFile opened: C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Local Extension Settings\bhghoamapcdpbohphigoooaddinpkbaiJump to behavior
                Source: C:\Users\user\Desktop\SimpleLoader v2.1.exe1.exeFile opened: C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Local Extension Settings\ookjlbkiijinhpmnjffcofjonbfbgaocJump to behavior
                Source: C:\Users\user\Desktop\SimpleLoader v2.1.exe1.exeFile opened: C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Sync Extension Settings\oeljdldpnmdbchonielidgobddffflaJump to behavior
                Source: C:\Users\user\Desktop\SimpleLoader v2.1.exe1.exeFile opened: C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Local Extension Settings\cihmoadaighcejopammfbmddcmdekcjeJump to behavior
                Source: C:\Users\user\Desktop\SimpleLoader v2.1.exe1.exeFile opened: C:\Users\user\AppData\Local\Microsoft\Edge\User Data\Default\Login DataJump to behavior
                Source: C:\Users\user\Desktop\SimpleLoader v2.1.exe1.exeFile opened: C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Local Extension Settings\jojhfeoedkpkglbfimdfabpdfjaoolafJump to behavior
                Source: C:\Users\user\Desktop\SimpleLoader v2.1.exe1.exeFile opened: C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Local Extension Settings\kncchdigobghenbbaddojjnnaogfppfjJump to behavior
                Source: C:\Users\user\Desktop\SimpleLoader v2.1.exe1.exeFile opened: C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Local Extension Settings\aeachknmefphepccionboohckonoeemgJump to behavior
                Source: C:\Users\user\Desktop\SimpleLoader v2.1.exe1.exeFile opened: C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Local Extension Settings\ejjladinnckdgjemekebdpeokbikhfciJump to behavior
                Source: C:\Users\user\Desktop\SimpleLoader v2.1.exe1.exeFile opened: C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Local Extension Settings\dngmlblcodfobpdpecaadgfbcggfjfnmJump to behavior
                Source: C:\Users\user\Desktop\SimpleLoader v2.1.exe1.exeFile opened: C:\Users\user\AppData\Roaming\Mozilla\Firefox\Profiles\2o7hffxt.default-release\prefs.jsJump to behavior
                Source: C:\Users\user\Desktop\SimpleLoader v2.1.exe1.exeFile opened: C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Sync Extension Settings\bhghoamapcdpbohphigoooaddinpkbaiJump to behavior
                Source: C:\Users\user\Desktop\SimpleLoader v2.1.exe1.exeFile opened: C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Local Extension Settings\hpglfhgfnhbgpjdenjgmdgoeiappaflnJump to behavior
                Source: C:\Users\user\Desktop\SimpleLoader v2.1.exe1.exeFile opened: C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Local Extension Settings\cnmamaachppnkjgnildpdmkaakejnhaeJump to behavior
                Source: C:\Users\user\Desktop\SimpleLoader v2.1.exe1.exeFile opened: C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Local Extension Settings\mnfifefkajgofkcjkemidiaecocnkjehJump to behavior
                Source: C:\Users\user\Desktop\SimpleLoader v2.1.exe1.exeFile opened: C:\Users\user\AppData\Roaming\Mozilla\Firefox\Profiles\2o7hffxt.default-release\cookies.sqliteJump to behavior
                Source: C:\Users\user\Desktop\SimpleLoader v2.1.exe1.exeFile opened: C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Local Extension Settings\lpfcbjknijpeeillifnkikgncikgfhdoJump to behavior
                Source: C:\Users\user\Desktop\SimpleLoader v2.1.exe1.exeFile opened: C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Local Extension Settings\ffnbelfdoeiohenkjibnmadjiehjhajbJump to behavior
                Source: C:\Users\user\Desktop\SimpleLoader v2.1.exe1.exeFile opened: C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Local Extension Settings\fijngjgcjhjmmpcmkeiomlglpeiijkldJump to behavior
                Source: C:\Users\user\Desktop\SimpleLoader v2.1.exe1.exeFile opened: C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Local Extension Settings\lkcjlnjfpbikmcmbachjpdbijejflpcmJump to behavior
                Source: C:\Users\user\Desktop\SimpleLoader v2.1.exe1.exeFile opened: C:\Users\user\AppData\Roaming\Mozilla\Firefox\Profiles\2o7hffxt.default-release\formhistory.sqliteJump to behavior
                Source: C:\Users\user\Desktop\SimpleLoader v2.1.exe1.exeFile opened: C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Local Extension Settings\nhnkbkgjikgcigadomkphalanndcapjkJump to behavior
                Source: C:\Users\user\Desktop\SimpleLoader v2.1.exe1.exeFile opened: C:\Users\user\AppData\Local\Microsoft\Edge\User Data\Default\Network\CookiesJump to behavior
                Source: C:\Users\user\Desktop\SimpleLoader v2.1.exe1.exeFile opened: C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Local Extension Settings\abogmiocnneedmmepnohnhlijcjpcifdJump to behavior
                Source: C:\Users\user\Desktop\SimpleLoader v2.1.exe1.exeFile opened: C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Local Extension Settings\egjidjbpglichdcondbcbdnbeeppgdphJump to behavior
                Source: C:\Users\user\Desktop\SimpleLoader v2.1.exe1.exeFile opened: C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Local Extension Settings\fhmfendgdocmcbmfikdcogofphimnknoJump to behavior
                Source: C:\Users\user\Desktop\SimpleLoader v2.1.exe1.exeFile opened: C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Local Extension Settings\fnjhmkhhmkbjkkabndcnnogagogbneecJump to behavior
                Source: C:\Users\user\Desktop\SimpleLoader v2.1.exe1.exeFile opened: C:\Users\user\AppData\Local\Microsoft\Edge\User Data\Default\Login Data For AccountJump to behavior
                Source: C:\Users\user\Desktop\SimpleLoader v2.1.exe1.exeFile opened: C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Local Extension Settings\cjelfplplebdjjenllpjcblmjkfcffneJump to behavior
                Source: C:\Users\user\Desktop\SimpleLoader v2.1.exe1.exeFile opened: C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Local Extension Settings\imloifkgjagghnncjkhggdhalmcnfklkJump to behavior
                Source: C:\Users\user\Desktop\SimpleLoader v2.1.exe1.exeFile opened: C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Login Data For AccountJump to behavior
                Source: C:\Users\user\Desktop\SimpleLoader v2.1.exe1.exeFile opened: C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Local Extension Settings\jnlgamecbpmbajjfhmmmlhejkemejdmaJump to behavior
                Source: C:\Users\user\Desktop\SimpleLoader v2.1.exe1.exeFile opened: C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Local Extension Settings\afbcbjpbpfadlkmhmclhkeeodmamcflcJump to behavior
                Source: C:\Users\user\Desktop\SimpleLoader v2.1.exe1.exeFile opened: C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Local Extension Settings\fcfcfllfndlomdhbehjjcoimbgofdncgJump to behavior
                Source: C:\Users\user\Desktop\SimpleLoader v2.1.exe1.exeFile opened: C:\Users\user\AppData\Roaming\Mozilla\Firefox\Profiles\2o7hffxt.default-release\places.sqliteJump to behavior
                Source: C:\Users\user\Desktop\SimpleLoader v2.1.exe1.exeFile opened: C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Local Extension Settings\jgaaimajipbpdogpdglhaphldakikgefJump to behavior
                Source: C:\Users\user\Desktop\SimpleLoader v2.1.exe1.exeFile opened: C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Local Extension Settings\nknhiehlklippafakaeklbeglecifhadJump to behavior
                Source: C:\Users\user\Desktop\SimpleLoader v2.1.exe1.exeFile opened: C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Local Extension Settings\opcgpfmipidbgpenhmajoajpbobppdilJump to behavior
                Source: C:\Users\user\Desktop\SimpleLoader v2.1.exe1.exeFile opened: C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Local Extension Settings\mcohilncbfahbmgdjkbpemcciiolgcgeJump to behavior
                Source: C:\Users\user\Desktop\SimpleLoader v2.1.exe1.exeFile opened: C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Local Extension Settings\nkddgncdjgjfcddamfgcmfnlhccnimigJump to behavior
                Source: C:\Users\user\Desktop\SimpleLoader v2.1.exe1.exeFile opened: C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Local Extension Settings\cnncmdhjacpkmjmkcafchppbnpnhdmonJump to behavior
                Source: C:\Users\user\Desktop\SimpleLoader v2.1.exe1.exeFile opened: C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Local Extension Settings\jbdaocneiiinmjbjlgalhcelgbejmnidJump to behavior
                Source: C:\Users\user\Desktop\SimpleLoader v2.1.exe1.exeFile opened: C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Local Extension Settings\amkmjjmmflddogmhpjloimipbofnfjihJump to behavior
                Source: C:\Users\user\Desktop\SimpleLoader v2.1.exe1.exeFile opened: C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Local Extension Settings\aflkmfhebedbjioipglgcbcmnbpgliofJump to behavior
                Source: C:\Users\user\Desktop\SimpleLoader v2.1.exe1.exeFile opened: C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Login DataJump to behavior
                Source: C:\Users\user\Desktop\SimpleLoader v2.1.exe1.exeFile opened: C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Local Extension Settings\heefohaffomkkkphnlpohglngmbcclhiJump to behavior
                Source: C:\Users\user\Desktop\SimpleLoader v2.1.exe1.exeFile opened: C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Local Extension Settings\bcopgchhojmggmffilplmbdicgaihlkpJump to behavior
                Source: C:\Users\user\Desktop\SimpleLoader v2.1.exe1.exeFile opened: C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Local Extension Settings\phkbamefinggmakgklpkljjmgibohnbaJump to behavior
                Source: C:\Users\user\Desktop\SimpleLoader v2.1.exe1.exeFile opened: C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Local Extension Settings\hifafgmccdpekplomjjkcfgodnhcelljJump to behavior
                Source: C:\Users\user\Desktop\SimpleLoader v2.1.exe1.exeFile opened: C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Local Extension Settings\loinekcabhlmhjjbocijdoimmejangoaJump to behavior
                Source: C:\Users\user\Desktop\SimpleLoader v2.1.exe1.exeFile opened: C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Local Extension Settings\nlbmnnijcnlegkjjpcfjclmcfggfefdmJump to behavior
                Source: C:\Users\user\Desktop\SimpleLoader v2.1.exe1.exeFile opened: C:\Users\user\AppData\Roaming\Mozilla\Firefox\Profiles\2o7hffxt.default-release\key4.dbJump to behavior
                Source: C:\Users\user\Desktop\SimpleLoader v2.1.exe1.exeFile opened: C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Local Extension Settings\idnnbdplmphpflfnlkomgpfbpcgelopgJump to behavior
                Source: C:\Users\user\Desktop\SimpleLoader v2.1.exe1.exeFile opened: C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Local Extension Settings\onhogfjeacnfoofkfgppdlbmlmnplgbnJump to behavior
                Source: C:\Users\user\Desktop\SimpleLoader v2.1.exe1.exeFile opened: C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Local Extension Settings\ijmpgkjfkbfhoebgogflfebnmejmfbmJump to behavior
                Source: C:\Users\user\Desktop\SimpleLoader v2.1.exe1.exeFile opened: C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Local Extension Settings\gaedmjdfmmahhbjefcbgaolhhanlaolbJump to behavior
                Source: C:\Users\user\Desktop\SimpleLoader v2.1.exe1.exeFile opened: C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Local Extension Settings\lgmpcpglpngdoalbgeoldeajfclnhafaJump to behavior
                Source: C:\Users\user\Desktop\SimpleLoader v2.1.exe1.exeFile opened: C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Local Extension Settings\lodccjjbdhfakaekdiahmedfbieldgikJump to behavior
                Source: C:\Users\user\Desktop\SimpleLoader v2.1.exe1.exeFile opened: C:\Users\user\AppData\Roaming\FTPInfoJump to behavior
                Source: C:\Users\user\Desktop\SimpleLoader v2.1.exe1.exeFile opened: C:\Users\user\AppData\Roaming\Conceptworld\NotezillaJump to behavior
                Source: C:\Users\user\Desktop\SimpleLoader v2.1.exe1.exeFile opened: C:\Users\user\AppData\Roaming\FTPboxJump to behavior
                Source: C:\Users\user\Desktop\SimpleLoader v2.1.exe1.exeFile opened: C:\Users\user\AppData\Roaming\SmartFTP\Client 2.0\FavoritesJump to behavior
                Source: C:\Users\user\Desktop\SimpleLoader v2.1.exe1.exeFile opened: C:\Users\user\AppData\Roaming\FTPRushJump to behavior
                Source: C:\Users\user\Desktop\SimpleLoader v2.1.exe1.exeFile opened: C:\Users\user\AppData\Roaming\FTPGetterJump to behavior
                Source: C:\Users\user\Desktop\SimpleLoader v2.1.exe1.exeFile opened: C:\ProgramData\SiteDesigner\3D-FTPJump to behavior
                Source: C:\Users\user\Desktop\SimpleLoader v2.1.exe1.exeFile opened: C:\Users\user\AppData\Roaming\Exodus\exodus.walletJump to behavior
                Source: C:\Users\user\Desktop\SimpleLoader v2.1.exe1.exeFile opened: C:\Users\user\AppData\Roaming\Exodus\exodus.walletJump to behavior
                Source: C:\Users\user\Desktop\SimpleLoader v2.1.exe1.exeFile opened: C:\Users\user\AppData\Roaming\Ledger LiveJump to behavior
                Source: C:\Users\user\Desktop\SimpleLoader v2.1.exe1.exeFile opened: C:\Users\user\AppData\Roaming\atomic\Local Storage\leveldbJump to behavior
                Source: C:\Users\user\Desktop\SimpleLoader v2.1.exe1.exeFile opened: C:\Users\user\AppData\Local\Coinomi\Coinomi\walletsJump to behavior
                Source: C:\Users\user\Desktop\SimpleLoader v2.1.exe1.exeFile opened: C:\Users\user\AppData\Local\Coinomi\Coinomi\walletsJump to behavior
                Source: C:\Users\user\Desktop\SimpleLoader v2.1.exe1.exeFile opened: C:\Users\user\AppData\Roaming\Bitcoin\walletsJump to behavior
                Source: C:\Users\user\Desktop\SimpleLoader v2.1.exe1.exeFile opened: C:\Users\user\AppData\Roaming\BinanceJump to behavior
                Source: C:\Users\user\Desktop\SimpleLoader v2.1.exe1.exeFile opened: C:\Users\user\AppData\Roaming\com.liberty.jaxx\IndexedDBJump to behavior
                Source: C:\Users\user\Desktop\SimpleLoader v2.1.exe1.exeFile opened: C:\Users\user\AppData\Roaming\Electrum\walletsJump to behavior
                Source: C:\Users\user\Desktop\SimpleLoader v2.1.exe1.exeFile opened: C:\Users\user\AppData\Roaming\Electrum-LTC\walletsJump to behavior
                Source: C:\Users\user\Desktop\SimpleLoader v2.1.exe1.exeFile opened: C:\Users\user\AppData\Roaming\Guarda\IndexedDBJump to behavior
                Source: C:\Users\user\Desktop\SimpleLoader v2.1.exe1.exeDirectory queried: C:\Users\user\DocumentsJump to behavior
                Source: C:\Users\user\Desktop\SimpleLoader v2.1.exe1.exeDirectory queried: C:\Users\user\DocumentsJump to behavior
                Source: C:\Users\user\Desktop\SimpleLoader v2.1.exe1.exeDirectory queried: C:\Users\user\Documents\KLIZUSIQENJump to behavior
                Source: C:\Users\user\Desktop\SimpleLoader v2.1.exe1.exeDirectory queried: C:\Users\user\Documents\KLIZUSIQENJump to behavior
                Source: C:\Users\user\Desktop\SimpleLoader v2.1.exe1.exeDirectory queried: C:\Users\user\Documents\MXPXCVPDVNJump to behavior
                Source: C:\Users\user\Desktop\SimpleLoader v2.1.exe1.exeDirectory queried: C:\Users\user\Documents\MXPXCVPDVNJump to behavior
                Source: Yara matchFile source: 00000004.00000003.1520289258.0000000001049000.00000004.00000020.00020000.00000000.sdmp, type: MEMORY
                Source: Yara matchFile source: 00000004.00000003.1477891390.0000000001093000.00000004.00000020.00020000.00000000.sdmp, type: MEMORY
                Source: Yara matchFile source: 00000004.00000003.1520161620.000000000109D000.00000004.00000020.00020000.00000000.sdmp, type: MEMORY
                Source: Yara matchFile source: 00000004.00000003.1551661764.0000000001049000.00000004.00000020.00020000.00000000.sdmp, type: MEMORY
                Source: Yara matchFile source: Process Memory Space: SimpleLoader v2.1.exe1.exe PID: 6680, type: MEMORYSTR

                Remote Access Functionality

                barindex
                Source: Yara matchFile source: Process Memory Space: SimpleLoader v2.1.exe1.exe PID: 6680, type: MEMORYSTR
                Source: Yara matchFile source: 4.2.SimpleLoader v2.1.exe1.exe.400000.0.raw.unpack, type: UNPACKEDPE
                Source: Yara matchFile source: 4.2.SimpleLoader v2.1.exe1.exe.400000.0.unpack, type: UNPACKEDPE
                Source: Yara matchFile source: 00000004.00000002.2609424437.0000000000400000.00000040.00000400.00020000.00000000.sdmp, type: MEMORY
                Source: Yara matchFile source: 00000000.00000002.1370342630.0000000001147000.00000004.00000020.00020000.00000000.sdmp, type: MEMORY
                ReconnaissanceResource DevelopmentInitial AccessExecutionPersistencePrivilege EscalationDefense EvasionCredential AccessDiscoveryLateral MovementCollectionCommand and ControlExfiltrationImpact
                Gather Victim Identity InformationAcquire InfrastructureValid Accounts12
                Windows Management Instrumentation
                1
                DLL Side-Loading
                211
                Process Injection
                21
                Virtualization/Sandbox Evasion
                2
                OS Credential Dumping
                1
                System Time Discovery
                Remote Services1
                Screen Capture
                21
                Encrypted Channel
                Exfiltration Over Other Network MediumAbuse Accessibility Features
                CredentialsDomainsDefault AccountsScheduled Task/JobBoot or Logon Initialization Scripts1
                DLL Side-Loading
                211
                Process Injection
                LSASS Memory241
                Security Software Discovery
                Remote Desktop Protocol1
                Archive Collected Data
                1
                Ingress Tool Transfer
                Exfiltration Over BluetoothNetwork Denial of Service
                Email AddressesDNS ServerDomain AccountsAtLogon Script (Windows)Logon Script (Windows)1
                Deobfuscate/Decode Files or Information
                Security Account Manager21
                Virtualization/Sandbox Evasion
                SMB/Windows Admin Shares41
                Data from Local System
                3
                Non-Application Layer Protocol
                Automated ExfiltrationData Encrypted for Impact
                Employee NamesVirtual Private ServerLocal AccountsCronLogin HookLogin Hook3
                Obfuscated Files or Information
                NTDS1
                Process Discovery
                Distributed Component Object Model3
                Clipboard Data
                114
                Application Layer Protocol
                Traffic DuplicationData Destruction
                Gather Victim Network InformationServerCloud AccountsLaunchdNetwork Logon ScriptNetwork Logon Script1
                Software Packing
                LSA Secrets1
                Application Window Discovery
                SSHKeyloggingFallback ChannelsScheduled TransferData Encrypted for Impact
                Domain PropertiesBotnetReplication Through Removable MediaScheduled TaskRC ScriptsRC Scripts1
                DLL Side-Loading
                Cached Domain Credentials11
                File and Directory Discovery
                VNCGUI Input CaptureMultiband CommunicationData Transfer Size LimitsService Stop
                DNSWeb ServicesExternal Remote ServicesSystemd TimersStartup ItemsStartup ItemsCompile After DeliveryDCSync33
                System Information Discovery
                Windows Remote ManagementWeb Portal CaptureCommonly Used PortExfiltration Over C2 ChannelInhibit System Recovery
                Hide Legend

                Legend:

                • Process
                • Signature
                • Created File
                • DNS/IP Info
                • Is Dropped
                • Is Windows Process
                • Number of created Registry Values
                • Number of created Files
                • Visual Basic
                • Delphi
                • Java
                • .Net C# or VB.NET
                • C, C++ or other language
                • Is malicious
                • Internet

                This section contains all screenshots as thumbnails, including those not shown in the slideshow.