Loading Joe Sandbox Report ...

Edit tour

Windows Analysis Report
SecuriteInfo.com.Win32.SpywareX-gen.21876.23851.exe

Overview

General Information

Sample name:SecuriteInfo.com.Win32.SpywareX-gen.21876.23851.exe
Analysis ID:1638174
MD5:d1ca8274f37ee2e0717ea26e71ffcd56
SHA1:dd2848231fb7d61ed5afb34c13a4a3bd0fc82996
SHA256:9b8178881c7c7d18b45fe179d604a23748349cf7e19250edad32072039d683b1
Tags:exeuser-SecuriteInfoCom
Infos:

Detection

Snake Keylogger
Score:100
Range:0 - 100
Confidence:100%

Signatures

Found malware configuration
Malicious sample detected (through community Yara rule)
Multi AV Scanner detection for submitted file
Yara detected AntiVM3
Yara detected Snake Keylogger
.NET source code contains potential unpacker
.NET source code contains very large array initializations
Joe Sandbox ML detected suspicious sample
Sample uses string decryption to hide its real strings
Tries to detect the country of the analysis system (by using the IP)
Tries to harvest and steal browser information (history, passwords, etc)
Tries to steal Mail credentials (via file / registry access)
Abnormal high CPU Usage
Allocates memory with a write watch (potentially for evading sandboxes)
Contains long sleeps (>= 3 min)
Creates a process in suspended mode (likely to inject code)
Detected potential crypto function
Enables debug privileges
Found a high number of Window / User specific system calls (may be a loop to detect user behavior)
Found inlined nop instructions (likely shell or obfuscated code)
HTTP GET or POST without a user agent
IP address seen in connection with other malware
JA3 SSL client fingerprint seen in connection with other malware
May check the online IP address of the machine
May sleep (evasive loops) to hinder dynamic analysis
Queries the volume information (name, serial number etc) of a device
Sample file is different than original file name gathered from version info
Suricata IDS alerts with low severity for network traffic
Uses 32bit PE files
Uses a known web browser user agent for HTTP communication
Uses insecure TLS / SSL version for HTTPS connection
Yara detected Credential Stealer
Yara signature match

Classification

  • System is w10x64
  • cleanup
NameDescriptionAttributionBlogpost URLsLink
404 Keylogger, Snake KeyloggerSnake Keylogger (aka 404 Keylogger) is a subscription-based keylogger that has many capabilities. The infostealer can steal a victims sensitive information, log keyboard strokes, take screenshots and extract information from the system clipboard. It was initially released on a Russian hacking forum in August 2019. It is notable for its relatively unusual methods of data exfiltration, including via email, FTP, SMTP, Pastebin or the messaging app Telegram.No Attributionhttps://malpedia.caad.fkie.fraunhofer.de/details/win.404keylogger
{"Exfil Mode": "Telegram", "Telegram URL": "https://api.telegram.org/bot7922655426:AAFVRqVw9pB4VZ3uipJRDfn5kD08nswJtAk/sendMessage?chat_id=7854955274", "Token": "7922655426:AAFVRqVw9pB4VZ3uipJRDfn5kD08nswJtAk", "Chat_id": "7854955274", "Version": "5.1"}
SourceRuleDescriptionAuthorStrings
00000001.00000002.3600280033.0000000000402000.00000040.00000400.00020000.00000000.sdmpJoeSecurity_CredentialStealerYara detected Credential StealerJoe Security
    00000001.00000002.3600280033.0000000000402000.00000040.00000400.00020000.00000000.sdmpJoeSecurity_SnakeKeyloggerYara detected Snake KeyloggerJoe Security
      00000001.00000002.3600280033.0000000000402000.00000040.00000400.00020000.00000000.sdmpWindows_Trojan_SnakeKeylogger_af3faa65unknownunknown
      • 0x148ce:$a1: get_encryptedPassword
      • 0x14bba:$a2: get_encryptedUsername
      • 0x146da:$a3: get_timePasswordChanged
      • 0x147d5:$a4: get_passwordField
      • 0x148e4:$a5: set_encryptedPassword
      • 0x15f8b:$a7: get_logins
      • 0x15eee:$a10: KeyLoggerEventArgs
      • 0x15b59:$a11: KeyLoggerEventArgsEventHandler
      00000001.00000002.3600280033.0000000000402000.00000040.00000400.00020000.00000000.sdmpMALWARE_Win_SnakeKeyloggerDetects Snake KeyloggerditekSHen
      • 0x198a4:$x1: $%SMTPDV$
      • 0x18288:$x2: $#TheHashHere%&
      • 0x1984c:$x3: %FTPDV$
      • 0x18228:$x4: $%TelegramDv$
      • 0x15b59:$x5: KeyLoggerEventArgs
      • 0x15eee:$x5: KeyLoggerEventArgs
      • 0x19870:$m2: Clipboard Logs ID
      • 0x19aae:$m2: Screenshot Logs ID
      • 0x19bbe:$m2: keystroke Logs ID
      • 0x19e98:$m3: SnakePW
      • 0x19a86:$m4: \SnakeKeylogger\
      00000001.00000002.3604112864.0000000003020000.00000004.00000800.00020000.00000000.sdmpJoeSecurity_SnakeKeyloggerYara detected Snake KeyloggerJoe Security
        Click to see the 14 entries
        SourceRuleDescriptionAuthorStrings
        0.2.SecuriteInfo.com.Win32.SpywareX-gen.21876.23851.exe.3682330.3.unpackJoeSecurity_CredentialStealerYara detected Credential StealerJoe Security
          0.2.SecuriteInfo.com.Win32.SpywareX-gen.21876.23851.exe.3682330.3.unpackJoeSecurity_SnakeKeyloggerYara detected Snake KeyloggerJoe Security
            0.2.SecuriteInfo.com.Win32.SpywareX-gen.21876.23851.exe.3682330.3.unpackWindows_Trojan_SnakeKeylogger_af3faa65unknownunknown
            • 0x12cce:$a1: get_encryptedPassword
            • 0x12fba:$a2: get_encryptedUsername
            • 0x12ada:$a3: get_timePasswordChanged
            • 0x12bd5:$a4: get_passwordField
            • 0x12ce4:$a5: set_encryptedPassword
            • 0x1438b:$a7: get_logins
            • 0x142ee:$a10: KeyLoggerEventArgs
            • 0x13f59:$a11: KeyLoggerEventArgsEventHandler
            0.2.SecuriteInfo.com.Win32.SpywareX-gen.21876.23851.exe.3682330.3.unpackMAL_Envrial_Jan18_1Detects Encrial credential stealer malwareFlorian Roth
            • 0x1a65a:$a2: \Comodo\Dragon\User Data\Default\Login Data
            • 0x1988c:$a3: \Google\Chrome\User Data\Default\Login Data
            • 0x19cbf:$a4: \Orbitum\User Data\Default\Login Data
            • 0x1acfe:$a5: \Kometa\User Data\Default\Login Data
            0.2.SecuriteInfo.com.Win32.SpywareX-gen.21876.23851.exe.3682330.3.unpackINDICATOR_SUSPICIOUS_EXE_DotNetProcHookDetects executables with potential process hoockingditekSHen
            • 0x138c7:$s1: UnHook
            • 0x138ce:$s2: SetHook
            • 0x138d6:$s3: CallNextHook
            • 0x138e3:$s4: _hook
            Click to see the 23 entries
            No Sigma rule has matched
            TimestampSIDSeverityClasstypeSource IPSource PortDestination IPDestination PortProtocol
            2025-03-14T09:33:12.152653+010028033053Unknown Traffic192.168.2.449712104.21.112.1443TCP
            2025-03-14T09:33:19.088215+010028033053Unknown Traffic192.168.2.449726104.21.112.1443TCP
            2025-03-14T09:33:20.338296+010028033053Unknown Traffic192.168.2.449729104.21.112.1443TCP
            TimestampSIDSeverityClasstypeSource IPSource PortDestination IPDestination PortProtocol
            2025-03-14T09:33:10.676370+010028032742Potentially Bad Traffic192.168.2.449710193.122.6.16880TCP
            2025-03-14T09:33:11.598280+010028032742Potentially Bad Traffic192.168.2.449710193.122.6.16880TCP
            2025-03-14T09:33:12.848280+010028032742Potentially Bad Traffic192.168.2.449713193.122.6.16880TCP

            Click to jump to signature section

            Show All Signature Results

            AV Detection

            barindex
            Source: 00000000.00000002.1162231043.0000000003661000.00000004.00000800.00020000.00000000.sdmpMalware Configuration Extractor: Snake Keylogger {"Exfil Mode": "Telegram", "Telegram URL": "https://api.telegram.org/bot7922655426:AAFVRqVw9pB4VZ3uipJRDfn5kD08nswJtAk/sendMessage?chat_id=7854955274", "Token": "7922655426:AAFVRqVw9pB4VZ3uipJRDfn5kD08nswJtAk", "Chat_id": "7854955274", "Version": "5.1"}
            Source: SecuriteInfo.com.Win32.SpywareX-gen.21876.23851.exeVirustotal: Detection: 35%Perma Link
            Source: SecuriteInfo.com.Win32.SpywareX-gen.21876.23851.exeReversingLabs: Detection: 44%
            Source: Submited SampleIntegrated Neural Analysis Model: Matched 100.0% probability
            Source: 0.2.SecuriteInfo.com.Win32.SpywareX-gen.21876.23851.exe.3661910.2.unpackString decryptor:
            Source: 0.2.SecuriteInfo.com.Win32.SpywareX-gen.21876.23851.exe.3661910.2.unpackString decryptor: 7922655426:AAFVRqVw9pB4VZ3uipJRDfn5kD08nswJtAk
            Source: 0.2.SecuriteInfo.com.Win32.SpywareX-gen.21876.23851.exe.3661910.2.unpackString decryptor: 7854955274

            Location Tracking

            barindex
            Source: unknownDNS query: name: reallyfreegeoip.org
            Source: SecuriteInfo.com.Win32.SpywareX-gen.21876.23851.exeStatic PE information: EXECUTABLE_IMAGE, 32BIT_MACHINE
            Source: unknownHTTPS traffic detected: 104.21.112.1:443 -> 192.168.2.4:49711 version: TLS 1.0
            Source: SecuriteInfo.com.Win32.SpywareX-gen.21876.23851.exeStatic PE information: HIGH_ENTROPY_VA, DYNAMIC_BASE, NX_COMPAT, NO_SEH, TERMINAL_SERVER_AWARE
            Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.SpywareX-gen.21876.23851.exeCode function: 4x nop then jmp 012DF1F6h1_2_012DF007
            Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.SpywareX-gen.21876.23851.exeCode function: 4x nop then jmp 012DFB80h1_2_012DF007
            Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.SpywareX-gen.21876.23851.exeCode function: 4x nop then mov dword ptr [ebp-14h], 00000000h1_2_012DE528
            Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.SpywareX-gen.21876.23851.exeCode function: 4x nop then mov dword ptr [ebp-14h], 00000000h1_2_012DEB5B
            Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.SpywareX-gen.21876.23851.exeCode function: 4x nop then mov dword ptr [ebp-14h], 00000000h1_2_012DED3C
            Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.SpywareX-gen.21876.23851.exeCode function: 4x nop then jmp 058B8945h1_2_058B8608
            Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.SpywareX-gen.21876.23851.exeCode function: 4x nop then jmp 058B5441h1_2_058B5198
            Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.SpywareX-gen.21876.23851.exeCode function: 4x nop then jmp 058B8459h1_2_058B81B0
            Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.SpywareX-gen.21876.23851.exeCode function: 4x nop then jmp 058B7BA9h1_2_058B7900
            Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.SpywareX-gen.21876.23851.exeCode function: 4x nop then jmp 058B0FF1h1_2_058B0D48
            Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.SpywareX-gen.21876.23851.exeCode function: 4x nop then jmp 058B8001h1_2_058B7D58
            Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.SpywareX-gen.21876.23851.exeCode function: 4x nop then jmp 058B0741h1_2_058B0498
            Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.SpywareX-gen.21876.23851.exeCode function: 4x nop then jmp 058B7751h1_2_058B74A8
            Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.SpywareX-gen.21876.23851.exeCode function: 4x nop then jmp 058B0B99h1_2_058B08F0
            Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.SpywareX-gen.21876.23851.exeCode function: 4x nop then jmp 058B02E9h1_2_058B0040
            Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.SpywareX-gen.21876.23851.exeCode function: 4x nop then jmp 058B72FAh1_2_058B7050
            Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.SpywareX-gen.21876.23851.exeCode function: 4x nop then lea esp, dword ptr [ebp-04h]1_2_058B33A8
            Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.SpywareX-gen.21876.23851.exeCode function: 4x nop then lea esp, dword ptr [ebp-04h]1_2_058B33B8
            Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.SpywareX-gen.21876.23851.exeCode function: 4x nop then jmp 058B6E79h1_2_058B6BD0
            Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.SpywareX-gen.21876.23851.exeCode function: 4x nop then jmp 058B65C9h1_2_058B6320
            Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.SpywareX-gen.21876.23851.exeCode function: 4x nop then jmp 058B6A21h1_2_058B6778
            Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.SpywareX-gen.21876.23851.exeCode function: 4x nop then jmp 058B6171h1_2_058B5EC8
            Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.SpywareX-gen.21876.23851.exeCode function: 4x nop then lea esp, dword ptr [ebp-04h]1_2_058B36CE
            Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.SpywareX-gen.21876.23851.exeCode function: 4x nop then jmp 058B58C1h1_2_058B5618
            Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.SpywareX-gen.21876.23851.exeCode function: 4x nop then jmp 058B5D19h1_2_058B5A70
            Source: global trafficHTTP traffic detected: GET /xml/8.46.123.189 HTTP/1.1Host: reallyfreegeoip.orgConnection: Keep-Alive
            Source: global trafficHTTP traffic detected: GET /xml/8.46.123.189 HTTP/1.1Host: reallyfreegeoip.org
            Source: global trafficHTTP traffic detected: GET /xml/8.46.123.189 HTTP/1.1Host: reallyfreegeoip.orgConnection: Keep-Alive
            Source: global trafficHTTP traffic detected: GET /xml/8.46.123.189 HTTP/1.1Host: reallyfreegeoip.orgConnection: Keep-Alive
            Source: global trafficHTTP traffic detected: GET /xml/8.46.123.189 HTTP/1.1Host: reallyfreegeoip.orgConnection: Keep-Alive
            Source: global trafficHTTP traffic detected: GET /xml/8.46.123.189 HTTP/1.1Host: reallyfreegeoip.orgConnection: Keep-Alive
            Source: global trafficHTTP traffic detected: GET /xml/8.46.123.189 HTTP/1.1Host: reallyfreegeoip.org
            Source: global trafficHTTP traffic detected: GET /xml/8.46.123.189 HTTP/1.1Host: reallyfreegeoip.org
            Source: Joe Sandbox ViewIP Address: 104.21.112.1 104.21.112.1
            Source: Joe Sandbox ViewIP Address: 104.21.112.1 104.21.112.1
            Source: Joe Sandbox ViewIP Address: 193.122.6.168 193.122.6.168
            Source: Joe Sandbox ViewJA3 fingerprint: 54328bd36c14bd82ddaa0c04b25ed9ad
            Source: unknownDNS query: name: checkip.dyndns.org
            Source: unknownDNS query: name: reallyfreegeoip.org
            Source: Network trafficSuricata IDS: 2803274 - Severity 2 - ETPRO MALWARE Common Downloader Header Pattern UH : 192.168.2.4:49713 -> 193.122.6.168:80
            Source: Network trafficSuricata IDS: 2803274 - Severity 2 - ETPRO MALWARE Common Downloader Header Pattern UH : 192.168.2.4:49710 -> 193.122.6.168:80
            Source: Network trafficSuricata IDS: 2803305 - Severity 3 - ETPRO MALWARE Common Downloader Header Pattern H : 192.168.2.4:49726 -> 104.21.112.1:443
            Source: Network trafficSuricata IDS: 2803305 - Severity 3 - ETPRO MALWARE Common Downloader Header Pattern H : 192.168.2.4:49712 -> 104.21.112.1:443
            Source: Network trafficSuricata IDS: 2803305 - Severity 3 - ETPRO MALWARE Common Downloader Header Pattern H : 192.168.2.4:49729 -> 104.21.112.1:443
            Source: global trafficHTTP traffic detected: GET / HTTP/1.1User-Agent: Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.2; .NET CLR1.0.3705;)Host: checkip.dyndns.orgConnection: Keep-Alive
            Source: global trafficHTTP traffic detected: GET / HTTP/1.1User-Agent: Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.2; .NET CLR1.0.3705;)Host: checkip.dyndns.org
            Source: global trafficHTTP traffic detected: GET / HTTP/1.1User-Agent: Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.2; .NET CLR1.0.3705;)Host: checkip.dyndns.org
            Source: global trafficHTTP traffic detected: GET / HTTP/1.1User-Agent: Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.2; .NET CLR1.0.3705;)Host: checkip.dyndns.org
            Source: global trafficHTTP traffic detected: GET / HTTP/1.1User-Agent: Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.2; .NET CLR1.0.3705;)Host: checkip.dyndns.orgConnection: Keep-Alive
            Source: global trafficHTTP traffic detected: GET / HTTP/1.1User-Agent: Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.2; .NET CLR1.0.3705;)Host: checkip.dyndns.orgConnection: Keep-Alive
            Source: global trafficHTTP traffic detected: GET / HTTP/1.1User-Agent: Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.2; .NET CLR1.0.3705;)Host: checkip.dyndns.orgConnection: Keep-Alive
            Source: global trafficHTTP traffic detected: GET / HTTP/1.1User-Agent: Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.2; .NET CLR1.0.3705;)Host: checkip.dyndns.orgConnection: Keep-Alive
            Source: global trafficHTTP traffic detected: GET / HTTP/1.1User-Agent: Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.2; .NET CLR1.0.3705;)Host: checkip.dyndns.orgConnection: Keep-Alive
            Source: unknownHTTPS traffic detected: 104.21.112.1:443 -> 192.168.2.4:49711 version: TLS 1.0
            Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
            Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
            Source: global trafficHTTP traffic detected: GET /xml/8.46.123.189 HTTP/1.1Host: reallyfreegeoip.orgConnection: Keep-Alive
            Source: global trafficHTTP traffic detected: GET /xml/8.46.123.189 HTTP/1.1Host: reallyfreegeoip.org
            Source: global trafficHTTP traffic detected: GET /xml/8.46.123.189 HTTP/1.1Host: reallyfreegeoip.orgConnection: Keep-Alive
            Source: global trafficHTTP traffic detected: GET /xml/8.46.123.189 HTTP/1.1Host: reallyfreegeoip.orgConnection: Keep-Alive
            Source: global trafficHTTP traffic detected: GET /xml/8.46.123.189 HTTP/1.1Host: reallyfreegeoip.orgConnection: Keep-Alive
            Source: global trafficHTTP traffic detected: GET /xml/8.46.123.189 HTTP/1.1Host: reallyfreegeoip.orgConnection: Keep-Alive
            Source: global trafficHTTP traffic detected: GET /xml/8.46.123.189 HTTP/1.1Host: reallyfreegeoip.org
            Source: global trafficHTTP traffic detected: GET /xml/8.46.123.189 HTTP/1.1Host: reallyfreegeoip.org
            Source: global trafficHTTP traffic detected: GET / HTTP/1.1User-Agent: Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.2; .NET CLR1.0.3705;)Host: checkip.dyndns.orgConnection: Keep-Alive
            Source: global trafficHTTP traffic detected: GET / HTTP/1.1User-Agent: Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.2; .NET CLR1.0.3705;)Host: checkip.dyndns.org
            Source: global trafficHTTP traffic detected: GET / HTTP/1.1User-Agent: Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.2; .NET CLR1.0.3705;)Host: checkip.dyndns.org
            Source: global trafficHTTP traffic detected: GET / HTTP/1.1User-Agent: Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.2; .NET CLR1.0.3705;)Host: checkip.dyndns.org
            Source: global trafficHTTP traffic detected: GET / HTTP/1.1User-Agent: Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.2; .NET CLR1.0.3705;)Host: checkip.dyndns.orgConnection: Keep-Alive
            Source: global trafficHTTP traffic detected: GET / HTTP/1.1User-Agent: Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.2; .NET CLR1.0.3705;)Host: checkip.dyndns.orgConnection: Keep-Alive
            Source: global trafficHTTP traffic detected: GET / HTTP/1.1User-Agent: Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.2; .NET CLR1.0.3705;)Host: checkip.dyndns.orgConnection: Keep-Alive
            Source: global trafficHTTP traffic detected: GET / HTTP/1.1User-Agent: Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.2; .NET CLR1.0.3705;)Host: checkip.dyndns.orgConnection: Keep-Alive
            Source: global trafficHTTP traffic detected: GET / HTTP/1.1User-Agent: Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.2; .NET CLR1.0.3705;)Host: checkip.dyndns.orgConnection: Keep-Alive
            Source: global trafficDNS traffic detected: DNS query: checkip.dyndns.org
            Source: global trafficDNS traffic detected: DNS query: reallyfreegeoip.org
            Source: SecuriteInfo.com.Win32.SpywareX-gen.21876.23851.exe, 00000001.00000002.3604112864.0000000003004000.00000004.00000800.00020000.00000000.sdmp, SecuriteInfo.com.Win32.SpywareX-gen.21876.23851.exe, 00000001.00000002.3604112864.0000000002F1A000.00000004.00000800.00020000.00000000.sdmp, SecuriteInfo.com.Win32.SpywareX-gen.21876.23851.exe, 00000001.00000002.3604112864.0000000002FBB000.00000004.00000800.00020000.00000000.sdmp, SecuriteInfo.com.Win32.SpywareX-gen.21876.23851.exe, 00000001.00000002.3604112864.0000000002FAD000.00000004.00000800.00020000.00000000.sdmp, SecuriteInfo.com.Win32.SpywareX-gen.21876.23851.exe, 00000001.00000002.3604112864.0000000002FC9000.00000004.00000800.00020000.00000000.sdmpString found in binary or memory: http://checkip.dyndns.com
            Source: SecuriteInfo.com.Win32.SpywareX-gen.21876.23851.exe, 00000001.00000002.3604112864.0000000003004000.00000004.00000800.00020000.00000000.sdmp, SecuriteInfo.com.Win32.SpywareX-gen.21876.23851.exe, 00000001.00000002.3604112864.0000000002F1A000.00000004.00000800.00020000.00000000.sdmp, SecuriteInfo.com.Win32.SpywareX-gen.21876.23851.exe, 00000001.00000002.3604112864.0000000002FBB000.00000004.00000800.00020000.00000000.sdmp, SecuriteInfo.com.Win32.SpywareX-gen.21876.23851.exe, 00000001.00000002.3604112864.0000000002F5D000.00000004.00000800.00020000.00000000.sdmp, SecuriteInfo.com.Win32.SpywareX-gen.21876.23851.exe, 00000001.00000002.3604112864.0000000002FAD000.00000004.00000800.00020000.00000000.sdmp, SecuriteInfo.com.Win32.SpywareX-gen.21876.23851.exe, 00000001.00000002.3604112864.0000000002FC9000.00000004.00000800.00020000.00000000.sdmp, SecuriteInfo.com.Win32.SpywareX-gen.21876.23851.exe, 00000001.00000002.3604112864.0000000002E51000.00000004.00000800.00020000.00000000.sdmpString found in binary or memory: http://checkip.dyndns.org
            Source: SecuriteInfo.com.Win32.SpywareX-gen.21876.23851.exe, 00000001.00000002.3604112864.0000000002E51000.00000004.00000800.00020000.00000000.sdmpString found in binary or memory: http://checkip.dyndns.org/
            Source: SecuriteInfo.com.Win32.SpywareX-gen.21876.23851.exe, 00000000.00000002.1162231043.0000000003661000.00000004.00000800.00020000.00000000.sdmp, SecuriteInfo.com.Win32.SpywareX-gen.21876.23851.exe, 00000001.00000002.3600280033.0000000000402000.00000040.00000400.00020000.00000000.sdmpString found in binary or memory: http://checkip.dyndns.org/q
            Source: SecuriteInfo.com.Win32.SpywareX-gen.21876.23851.exe, 00000001.00000002.3604112864.0000000003004000.00000004.00000800.00020000.00000000.sdmp, SecuriteInfo.com.Win32.SpywareX-gen.21876.23851.exe, 00000001.00000002.3604112864.0000000002FBB000.00000004.00000800.00020000.00000000.sdmp, SecuriteInfo.com.Win32.SpywareX-gen.21876.23851.exe, 00000001.00000002.3604112864.0000000002F32000.00000004.00000800.00020000.00000000.sdmp, SecuriteInfo.com.Win32.SpywareX-gen.21876.23851.exe, 00000001.00000002.3604112864.0000000002FAD000.00000004.00000800.00020000.00000000.sdmp, SecuriteInfo.com.Win32.SpywareX-gen.21876.23851.exe, 00000001.00000002.3604112864.0000000002FC9000.00000004.00000800.00020000.00000000.sdmpString found in binary or memory: http://reallyfreegeoip.org
            Source: SecuriteInfo.com.Win32.SpywareX-gen.21876.23851.exe, 00000001.00000002.3604112864.0000000002E51000.00000004.00000800.00020000.00000000.sdmpString found in binary or memory: http://schemas.xmlsoap.org/ws/2005/05/identity/claims/name
            Source: SecuriteInfo.com.Win32.SpywareX-gen.21876.23851.exe, 00000000.00000002.1164468326.0000000005562000.00000004.00000800.00020000.00000000.sdmpString found in binary or memory: http://www.apache.org/licenses/LICENSE-2.0
            Source: SecuriteInfo.com.Win32.SpywareX-gen.21876.23851.exe, 00000000.00000002.1164468326.0000000005562000.00000004.00000800.00020000.00000000.sdmpString found in binary or memory: http://www.carterandcone.coml
            Source: SecuriteInfo.com.Win32.SpywareX-gen.21876.23851.exe, 00000000.00000002.1164468326.0000000005562000.00000004.00000800.00020000.00000000.sdmpString found in binary or memory: http://www.fontbureau.com
            Source: SecuriteInfo.com.Win32.SpywareX-gen.21876.23851.exe, 00000000.00000002.1164468326.0000000005562000.00000004.00000800.00020000.00000000.sdmpString found in binary or memory: http://www.fontbureau.com/designers
            Source: SecuriteInfo.com.Win32.SpywareX-gen.21876.23851.exe, 00000000.00000002.1164468326.0000000005562000.00000004.00000800.00020000.00000000.sdmpString found in binary or memory: http://www.fontbureau.com/designers/?
            Source: SecuriteInfo.com.Win32.SpywareX-gen.21876.23851.exe, 00000000.00000002.1164468326.0000000005562000.00000004.00000800.00020000.00000000.sdmpString found in binary or memory: http://www.fontbureau.com/designers/cabarga.htmlN
            Source: SecuriteInfo.com.Win32.SpywareX-gen.21876.23851.exe, 00000000.00000002.1164468326.0000000005562000.00000004.00000800.00020000.00000000.sdmpString found in binary or memory: http://www.fontbureau.com/designers/frere-user.html
            Source: SecuriteInfo.com.Win32.SpywareX-gen.21876.23851.exe, 00000000.00000002.1164468326.0000000005562000.00000004.00000800.00020000.00000000.sdmpString found in binary or memory: http://www.fontbureau.com/designers8
            Source: SecuriteInfo.com.Win32.SpywareX-gen.21876.23851.exe, 00000000.00000002.1164468326.0000000005562000.00000004.00000800.00020000.00000000.sdmpString found in binary or memory: http://www.fontbureau.com/designers?
            Source: SecuriteInfo.com.Win32.SpywareX-gen.21876.23851.exe, 00000000.00000002.1164468326.0000000005562000.00000004.00000800.00020000.00000000.sdmpString found in binary or memory: http://www.fontbureau.com/designersG
            Source: SecuriteInfo.com.Win32.SpywareX-gen.21876.23851.exe, 00000000.00000002.1164468326.0000000005562000.00000004.00000800.00020000.00000000.sdmpString found in binary or memory: http://www.fonts.com
            Source: SecuriteInfo.com.Win32.SpywareX-gen.21876.23851.exe, 00000000.00000002.1164468326.0000000005562000.00000004.00000800.00020000.00000000.sdmpString found in binary or memory: http://www.founder.com.cn/cn
            Source: SecuriteInfo.com.Win32.SpywareX-gen.21876.23851.exe, 00000000.00000002.1164468326.0000000005562000.00000004.00000800.00020000.00000000.sdmpString found in binary or memory: http://www.founder.com.cn/cn/bThe
            Source: SecuriteInfo.com.Win32.SpywareX-gen.21876.23851.exe, 00000000.00000002.1164468326.0000000005562000.00000004.00000800.00020000.00000000.sdmpString found in binary or memory: http://www.founder.com.cn/cn/cThe
            Source: SecuriteInfo.com.Win32.SpywareX-gen.21876.23851.exe, 00000000.00000002.1164468326.0000000005562000.00000004.00000800.00020000.00000000.sdmpString found in binary or memory: http://www.galapagosdesign.com/DPlease
            Source: SecuriteInfo.com.Win32.SpywareX-gen.21876.23851.exe, 00000000.00000002.1164468326.0000000005562000.00000004.00000800.00020000.00000000.sdmpString found in binary or memory: http://www.galapagosdesign.com/staff/dennis.htm
            Source: SecuriteInfo.com.Win32.SpywareX-gen.21876.23851.exe, 00000000.00000002.1164468326.0000000005562000.00000004.00000800.00020000.00000000.sdmpString found in binary or memory: http://www.jiyu-kobo.co.jp/
            Source: SecuriteInfo.com.Win32.SpywareX-gen.21876.23851.exe, 00000000.00000002.1164468326.0000000005562000.00000004.00000800.00020000.00000000.sdmpString found in binary or memory: http://www.sajatypeworks.com
            Source: SecuriteInfo.com.Win32.SpywareX-gen.21876.23851.exe, 00000000.00000002.1164468326.0000000005562000.00000004.00000800.00020000.00000000.sdmpString found in binary or memory: http://www.sakkal.com
            Source: SecuriteInfo.com.Win32.SpywareX-gen.21876.23851.exe, 00000000.00000002.1164468326.0000000005562000.00000004.00000800.00020000.00000000.sdmpString found in binary or memory: http://www.tiro.com
            Source: SecuriteInfo.com.Win32.SpywareX-gen.21876.23851.exe, 00000000.00000002.1164468326.0000000005562000.00000004.00000800.00020000.00000000.sdmpString found in binary or memory: http://www.typography.netD
            Source: SecuriteInfo.com.Win32.SpywareX-gen.21876.23851.exe, 00000000.00000002.1164468326.0000000005562000.00000004.00000800.00020000.00000000.sdmpString found in binary or memory: http://www.urwpp.deDPlease
            Source: SecuriteInfo.com.Win32.SpywareX-gen.21876.23851.exe, 00000000.00000002.1164468326.0000000005562000.00000004.00000800.00020000.00000000.sdmpString found in binary or memory: http://www.zhongyicts.com.cn
            Source: SecuriteInfo.com.Win32.SpywareX-gen.21876.23851.exe, 00000001.00000002.3604112864.0000000003004000.00000004.00000800.00020000.00000000.sdmp, SecuriteInfo.com.Win32.SpywareX-gen.21876.23851.exe, 00000001.00000002.3604112864.0000000002F1A000.00000004.00000800.00020000.00000000.sdmp, SecuriteInfo.com.Win32.SpywareX-gen.21876.23851.exe, 00000001.00000002.3604112864.0000000002FBB000.00000004.00000800.00020000.00000000.sdmp, SecuriteInfo.com.Win32.SpywareX-gen.21876.23851.exe, 00000001.00000002.3604112864.0000000002F5D000.00000004.00000800.00020000.00000000.sdmp, SecuriteInfo.com.Win32.SpywareX-gen.21876.23851.exe, 00000001.00000002.3604112864.0000000002FAD000.00000004.00000800.00020000.00000000.sdmp, SecuriteInfo.com.Win32.SpywareX-gen.21876.23851.exe, 00000001.00000002.3604112864.0000000002FC9000.00000004.00000800.00020000.00000000.sdmpString found in binary or memory: https://reallyfreegeoip.org
            Source: SecuriteInfo.com.Win32.SpywareX-gen.21876.23851.exe, 00000000.00000002.1162231043.0000000003661000.00000004.00000800.00020000.00000000.sdmp, SecuriteInfo.com.Win32.SpywareX-gen.21876.23851.exe, 00000001.00000002.3600280033.0000000000402000.00000040.00000400.00020000.00000000.sdmp, SecuriteInfo.com.Win32.SpywareX-gen.21876.23851.exe, 00000001.00000002.3604112864.0000000002F1A000.00000004.00000800.00020000.00000000.sdmpString found in binary or memory: https://reallyfreegeoip.org/xml/
            Source: SecuriteInfo.com.Win32.SpywareX-gen.21876.23851.exe, 00000001.00000002.3604112864.0000000002FC9000.00000004.00000800.00020000.00000000.sdmpString found in binary or memory: https://reallyfreegeoip.org/xml/8.46.123.189
            Source: SecuriteInfo.com.Win32.SpywareX-gen.21876.23851.exe, 00000001.00000002.3604112864.0000000003004000.00000004.00000800.00020000.00000000.sdmp, SecuriteInfo.com.Win32.SpywareX-gen.21876.23851.exe, 00000001.00000002.3604112864.0000000002FBB000.00000004.00000800.00020000.00000000.sdmp, SecuriteInfo.com.Win32.SpywareX-gen.21876.23851.exe, 00000001.00000002.3604112864.0000000002F5D000.00000004.00000800.00020000.00000000.sdmp, SecuriteInfo.com.Win32.SpywareX-gen.21876.23851.exe, 00000001.00000002.3604112864.0000000002FAD000.00000004.00000800.00020000.00000000.sdmp, SecuriteInfo.com.Win32.SpywareX-gen.21876.23851.exe, 00000001.00000002.3604112864.0000000002FC9000.00000004.00000800.00020000.00000000.sdmpString found in binary or memory: https://reallyfreegeoip.org/xml/8.46.123.189$
            Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49711
            Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49720
            Source: unknownNetwork traffic detected: HTTP traffic on port 49712 -> 443
            Source: unknownNetwork traffic detected: HTTP traffic on port 49711 -> 443
            Source: unknownNetwork traffic detected: HTTP traffic on port 49726 -> 443
            Source: unknownNetwork traffic detected: HTTP traffic on port 49729 -> 443
            Source: unknownNetwork traffic detected: HTTP traffic on port 49720 -> 443
            Source: unknownNetwork traffic detected: HTTP traffic on port 49723 -> 443
            Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49718
            Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49729
            Source: unknownNetwork traffic detected: HTTP traffic on port 49714 -> 443
            Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49726
            Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49714
            Source: unknownNetwork traffic detected: HTTP traffic on port 49718 -> 443
            Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49712
            Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49723

            System Summary

            barindex
            Source: 0.2.SecuriteInfo.com.Win32.SpywareX-gen.21876.23851.exe.3682330.3.unpack, type: UNPACKEDPEMatched rule: Windows_Trojan_SnakeKeylogger_af3faa65 Author: unknown
            Source: 0.2.SecuriteInfo.com.Win32.SpywareX-gen.21876.23851.exe.3682330.3.unpack, type: UNPACKEDPEMatched rule: Detects Encrial credential stealer malware Author: Florian Roth
            Source: 0.2.SecuriteInfo.com.Win32.SpywareX-gen.21876.23851.exe.3682330.3.unpack, type: UNPACKEDPEMatched rule: Detects executables with potential process hoocking Author: ditekSHen
            Source: 0.2.SecuriteInfo.com.Win32.SpywareX-gen.21876.23851.exe.3682330.3.unpack, type: UNPACKEDPEMatched rule: Detects Snake Keylogger Author: ditekSHen
            Source: 1.2.SecuriteInfo.com.Win32.SpywareX-gen.21876.23851.exe.400000.0.unpack, type: UNPACKEDPEMatched rule: Windows_Trojan_SnakeKeylogger_af3faa65 Author: unknown
            Source: 1.2.SecuriteInfo.com.Win32.SpywareX-gen.21876.23851.exe.400000.0.unpack, type: UNPACKEDPEMatched rule: Detects Encrial credential stealer malware Author: Florian Roth
            Source: 1.2.SecuriteInfo.com.Win32.SpywareX-gen.21876.23851.exe.400000.0.unpack, type: UNPACKEDPEMatched rule: Detects executables with potential process hoocking Author: ditekSHen
            Source: 1.2.SecuriteInfo.com.Win32.SpywareX-gen.21876.23851.exe.400000.0.unpack, type: UNPACKEDPEMatched rule: Detects Snake Keylogger Author: ditekSHen
            Source: 0.2.SecuriteInfo.com.Win32.SpywareX-gen.21876.23851.exe.3661910.2.unpack, type: UNPACKEDPEMatched rule: Windows_Trojan_SnakeKeylogger_af3faa65 Author: unknown
            Source: 0.2.SecuriteInfo.com.Win32.SpywareX-gen.21876.23851.exe.3661910.2.unpack, type: UNPACKEDPEMatched rule: Detects Encrial credential stealer malware Author: Florian Roth
            Source: 0.2.SecuriteInfo.com.Win32.SpywareX-gen.21876.23851.exe.3661910.2.unpack, type: UNPACKEDPEMatched rule: Detects executables with potential process hoocking Author: ditekSHen
            Source: 0.2.SecuriteInfo.com.Win32.SpywareX-gen.21876.23851.exe.3661910.2.unpack, type: UNPACKEDPEMatched rule: Detects Snake Keylogger Author: ditekSHen
            Source: 0.2.SecuriteInfo.com.Win32.SpywareX-gen.21876.23851.exe.3682330.3.raw.unpack, type: UNPACKEDPEMatched rule: Windows_Trojan_SnakeKeylogger_af3faa65 Author: unknown
            Source: 0.2.SecuriteInfo.com.Win32.SpywareX-gen.21876.23851.exe.3682330.3.raw.unpack, type: UNPACKEDPEMatched rule: Detects executables with potential process hoocking Author: ditekSHen
            Source: 0.2.SecuriteInfo.com.Win32.SpywareX-gen.21876.23851.exe.3682330.3.raw.unpack, type: UNPACKEDPEMatched rule: Detects Snake Keylogger Author: ditekSHen
            Source: 0.2.SecuriteInfo.com.Win32.SpywareX-gen.21876.23851.exe.3661910.2.raw.unpack, type: UNPACKEDPEMatched rule: Windows_Trojan_SnakeKeylogger_af3faa65 Author: unknown
            Source: 0.2.SecuriteInfo.com.Win32.SpywareX-gen.21876.23851.exe.3661910.2.raw.unpack, type: UNPACKEDPEMatched rule: Detects executables with potential process hoocking Author: ditekSHen
            Source: 0.2.SecuriteInfo.com.Win32.SpywareX-gen.21876.23851.exe.3661910.2.raw.unpack, type: UNPACKEDPEMatched rule: Detects Snake Keylogger Author: ditekSHen
            Source: 00000001.00000002.3600280033.0000000000402000.00000040.00000400.00020000.00000000.sdmp, type: MEMORYMatched rule: Windows_Trojan_SnakeKeylogger_af3faa65 Author: unknown
            Source: 00000001.00000002.3600280033.0000000000402000.00000040.00000400.00020000.00000000.sdmp, type: MEMORYMatched rule: Detects Snake Keylogger Author: ditekSHen
            Source: 00000000.00000002.1162231043.0000000003661000.00000004.00000800.00020000.00000000.sdmp, type: MEMORYMatched rule: Windows_Trojan_SnakeKeylogger_af3faa65 Author: unknown
            Source: 00000000.00000002.1162231043.0000000003661000.00000004.00000800.00020000.00000000.sdmp, type: MEMORYMatched rule: Detects Snake Keylogger Author: ditekSHen
            Source: Process Memory Space: SecuriteInfo.com.Win32.SpywareX-gen.21876.23851.exe PID: 7784, type: MEMORYSTRMatched rule: Windows_Trojan_SnakeKeylogger_af3faa65 Author: unknown
            Source: Process Memory Space: SecuriteInfo.com.Win32.SpywareX-gen.21876.23851.exe PID: 7784, type: MEMORYSTRMatched rule: Detects Snake Keylogger Author: ditekSHen
            Source: Process Memory Space: SecuriteInfo.com.Win32.SpywareX-gen.21876.23851.exe PID: 7876, type: MEMORYSTRMatched rule: Windows_Trojan_SnakeKeylogger_af3faa65 Author: unknown
            Source: Process Memory Space: SecuriteInfo.com.Win32.SpywareX-gen.21876.23851.exe PID: 7876, type: MEMORYSTRMatched rule: Detects Snake Keylogger Author: ditekSHen
            Source: SecuriteInfo.com.Win32.SpywareX-gen.21876.23851.exe, Form1.csLarge array initialization: : array initializer size 499836
            Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.SpywareX-gen.21876.23851.exeProcess Stats: CPU usage > 49%
            Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.SpywareX-gen.21876.23851.exeCode function: 0_2_074E00400_2_074E0040
            Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.SpywareX-gen.21876.23851.exeCode function: 0_2_074EE67A0_2_074EE67A
            Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.SpywareX-gen.21876.23851.exeCode function: 0_2_074E00060_2_074E0006
            Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.SpywareX-gen.21876.23851.exeCode function: 0_2_074EEEE00_2_074EEEE0
            Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.SpywareX-gen.21876.23851.exeCode function: 0_2_074EEEF00_2_074EEEF0
            Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.SpywareX-gen.21876.23851.exeCode function: 0_2_074EEAA80_2_074EEAA8
            Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.SpywareX-gen.21876.23851.exeCode function: 0_2_074EEAB80_2_074EEAB8
            Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.SpywareX-gen.21876.23851.exeCode function: 1_2_012D61081_2_012D6108
            Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.SpywareX-gen.21876.23851.exeCode function: 1_2_012DC1901_2_012DC190
            Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.SpywareX-gen.21876.23851.exeCode function: 1_2_012DF0071_2_012DF007
            Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.SpywareX-gen.21876.23851.exeCode function: 1_2_012DC4701_2_012DC470
            Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.SpywareX-gen.21876.23851.exeCode function: 1_2_012DB4A01_2_012DB4A0
            Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.SpywareX-gen.21876.23851.exeCode function: 1_2_012D67301_2_012D6730
            Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.SpywareX-gen.21876.23851.exeCode function: 1_2_012DC7511_2_012DC751
            Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.SpywareX-gen.21876.23851.exeCode function: 1_2_012D98581_2_012D9858
            Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.SpywareX-gen.21876.23851.exeCode function: 1_2_012DBBD31_2_012DBBD3
            Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.SpywareX-gen.21876.23851.exeCode function: 1_2_012DCA311_2_012DCA31
            Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.SpywareX-gen.21876.23851.exeCode function: 1_2_012D4AD91_2_012D4AD9
            Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.SpywareX-gen.21876.23851.exeCode function: 1_2_012DBEB01_2_012DBEB0
            Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.SpywareX-gen.21876.23851.exeCode function: 1_2_012DE5281_2_012DE528
            Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.SpywareX-gen.21876.23851.exeCode function: 1_2_012DE5171_2_012DE517
            Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.SpywareX-gen.21876.23851.exeCode function: 1_2_012D35701_2_012D3570
            Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.SpywareX-gen.21876.23851.exeCode function: 1_2_012DB4F31_2_012DB4F3
            Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.SpywareX-gen.21876.23851.exeCode function: 1_2_058BC9D81_2_058BC9D8
            Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.SpywareX-gen.21876.23851.exeCode function: 1_2_058BBD381_2_058BBD38
            Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.SpywareX-gen.21876.23851.exeCode function: 1_2_058BB0A01_2_058BB0A0
            Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.SpywareX-gen.21876.23851.exeCode function: 1_2_058BA4081_2_058BA408
            Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.SpywareX-gen.21876.23851.exeCode function: 1_2_058BD0281_2_058BD028
            Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.SpywareX-gen.21876.23851.exeCode function: 1_2_058BC3881_2_058BC388
            Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.SpywareX-gen.21876.23851.exeCode function: 1_2_058B8B581_2_058B8B58
            Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.SpywareX-gen.21876.23851.exeCode function: 1_2_058BB6E81_2_058BB6E8
            Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.SpywareX-gen.21876.23851.exeCode function: 1_2_058B86081_2_058B8608
            Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.SpywareX-gen.21876.23851.exeCode function: 1_2_058BAA581_2_058BAA58
            Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.SpywareX-gen.21876.23851.exeCode function: 1_2_058BD6701_2_058BD670
            Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.SpywareX-gen.21876.23851.exeCode function: 1_2_058B518A1_2_058B518A
            Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.SpywareX-gen.21876.23851.exeCode function: 1_2_058B51981_2_058B5198
            Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.SpywareX-gen.21876.23851.exeCode function: 1_2_058B11911_2_058B1191
            Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.SpywareX-gen.21876.23851.exeCode function: 1_2_058B11A01_2_058B11A0
            Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.SpywareX-gen.21876.23851.exeCode function: 1_2_058B81A01_2_058B81A0
            Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.SpywareX-gen.21876.23851.exeCode function: 1_2_058B81B01_2_058B81B0
            Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.SpywareX-gen.21876.23851.exeCode function: 1_2_058BC9C81_2_058BC9C8
            Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.SpywareX-gen.21876.23851.exeCode function: 1_2_058B85FC1_2_058B85FC
            Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.SpywareX-gen.21876.23851.exeCode function: 1_2_058B79001_2_058B7900
            Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.SpywareX-gen.21876.23851.exeCode function: 1_2_058BBD281_2_058BBD28
            Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.SpywareX-gen.21876.23851.exeCode function: 1_2_058B0D391_2_058B0D39
            Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.SpywareX-gen.21876.23851.exeCode function: 1_2_058B0D481_2_058B0D48
            Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.SpywareX-gen.21876.23851.exeCode function: 1_2_058B7D481_2_058B7D48
            Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.SpywareX-gen.21876.23851.exeCode function: 1_2_058B7D581_2_058B7D58
            Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.SpywareX-gen.21876.23851.exeCode function: 1_2_058B04881_2_058B0488
            Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.SpywareX-gen.21876.23851.exeCode function: 1_2_058BB08F1_2_058BB08F
            Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.SpywareX-gen.21876.23851.exeCode function: 1_2_058B04981_2_058B0498
            Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.SpywareX-gen.21876.23851.exeCode function: 1_2_058B74971_2_058B7497
            Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.SpywareX-gen.21876.23851.exeCode function: 1_2_058B74A81_2_058B74A8
            Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.SpywareX-gen.21876.23851.exeCode function: 1_2_058B28B01_2_058B28B0
            Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.SpywareX-gen.21876.23851.exeCode function: 1_2_058B08E01_2_058B08E0
            Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.SpywareX-gen.21876.23851.exeCode function: 1_2_058B08F01_2_058B08F0
            Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.SpywareX-gen.21876.23851.exeCode function: 1_2_058B78F01_2_058B78F0
            Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.SpywareX-gen.21876.23851.exeCode function: 1_2_058B28091_2_058B2809
            Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.SpywareX-gen.21876.23851.exeCode function: 1_2_058B28071_2_058B2807
            Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.SpywareX-gen.21876.23851.exeCode function: 1_2_058B00061_2_058B0006
            Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.SpywareX-gen.21876.23851.exeCode function: 1_2_058BD0181_2_058BD018
            Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.SpywareX-gen.21876.23851.exeCode function: 1_2_058B44301_2_058B4430
            Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.SpywareX-gen.21876.23851.exeCode function: 1_2_058B00401_2_058B0040
            Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.SpywareX-gen.21876.23851.exeCode function: 1_2_058B70401_2_058B7040
            Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.SpywareX-gen.21876.23851.exeCode function: 1_2_058B70501_2_058B7050
            Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.SpywareX-gen.21876.23851.exeCode function: 1_2_058B33A81_2_058B33A8
            Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.SpywareX-gen.21876.23851.exeCode function: 1_2_058B33B81_2_058B33B8
            Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.SpywareX-gen.21876.23851.exeCode function: 1_2_058B6BC11_2_058B6BC1
            Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.SpywareX-gen.21876.23851.exeCode function: 1_2_058B6BD01_2_058B6BD0
            Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.SpywareX-gen.21876.23851.exeCode function: 1_2_058BA3F81_2_058BA3F8
            Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.SpywareX-gen.21876.23851.exeCode function: 1_2_058B63121_2_058B6312
            Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.SpywareX-gen.21876.23851.exeCode function: 1_2_058B63201_2_058B6320
            Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.SpywareX-gen.21876.23851.exeCode function: 1_2_058B37301_2_058B3730
            Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.SpywareX-gen.21876.23851.exeCode function: 1_2_058B676A1_2_058B676A
            Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.SpywareX-gen.21876.23851.exeCode function: 1_2_058B67781_2_058B6778
            Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.SpywareX-gen.21876.23851.exeCode function: 1_2_058BC3781_2_058BC378
            Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.SpywareX-gen.21876.23851.exeCode function: 1_2_058B8B761_2_058B8B76
            Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.SpywareX-gen.21876.23851.exeCode function: 1_2_058B5EB81_2_058B5EB8
            Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.SpywareX-gen.21876.23851.exeCode function: 1_2_058B5EC81_2_058B5EC8
            Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.SpywareX-gen.21876.23851.exeCode function: 1_2_058BB6D91_2_058BB6D9
            Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.SpywareX-gen.21876.23851.exeCode function: 1_2_058B560A1_2_058B560A
            Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.SpywareX-gen.21876.23851.exeCode function: 1_2_058B56181_2_058B5618
            Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.SpywareX-gen.21876.23851.exeCode function: 1_2_058BAA481_2_058BAA48
            Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.SpywareX-gen.21876.23851.exeCode function: 1_2_058BD6631_2_058BD663
            Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.SpywareX-gen.21876.23851.exeCode function: 1_2_058B5A601_2_058B5A60
            Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.SpywareX-gen.21876.23851.exeCode function: 1_2_058B5A701_2_058B5A70
            Source: SecuriteInfo.com.Win32.SpywareX-gen.21876.23851.exe, 00000000.00000002.1162231043.0000000003661000.00000004.00000800.00020000.00000000.sdmpBinary or memory string: OriginalFilenamelfwhUWZlmFnGhDYPudAJ.exeX vs SecuriteInfo.com.Win32.SpywareX-gen.21876.23851.exe
            Source: SecuriteInfo.com.Win32.SpywareX-gen.21876.23851.exe, 00000000.00000002.1162231043.0000000003661000.00000004.00000800.00020000.00000000.sdmpBinary or memory string: OriginalFilenameMontero.dll8 vs SecuriteInfo.com.Win32.SpywareX-gen.21876.23851.exe
            Source: SecuriteInfo.com.Win32.SpywareX-gen.21876.23851.exe, 00000000.00000002.1161640598.0000000002651000.00000004.00000800.00020000.00000000.sdmpBinary or memory string: OriginalFilenamelfwhUWZlmFnGhDYPudAJ.exeX vs SecuriteInfo.com.Win32.SpywareX-gen.21876.23851.exe
            Source: SecuriteInfo.com.Win32.SpywareX-gen.21876.23851.exe, 00000000.00000002.1164436670.0000000005530000.00000004.08000000.00040000.00000000.sdmpBinary or memory string: OriginalFilenameTL.dll" vs SecuriteInfo.com.Win32.SpywareX-gen.21876.23851.exe
            Source: SecuriteInfo.com.Win32.SpywareX-gen.21876.23851.exe, 00000000.00000002.1161640598.0000000002853000.00000004.00000800.00020000.00000000.sdmpBinary or memory string: OriginalFilenameTL.dll" vs SecuriteInfo.com.Win32.SpywareX-gen.21876.23851.exe
            Source: SecuriteInfo.com.Win32.SpywareX-gen.21876.23851.exe, 00000000.00000002.1165753645.0000000007A90000.00000004.08000000.00040000.00000000.sdmpBinary or memory string: OriginalFilenameMontero.dll8 vs SecuriteInfo.com.Win32.SpywareX-gen.21876.23851.exe
            Source: SecuriteInfo.com.Win32.SpywareX-gen.21876.23851.exe, 00000000.00000002.1161640598.0000000002895000.00000004.00000800.00020000.00000000.sdmpBinary or memory string: OriginalFilenameTL.dll" vs SecuriteInfo.com.Win32.SpywareX-gen.21876.23851.exe
            Source: SecuriteInfo.com.Win32.SpywareX-gen.21876.23851.exe, 00000000.00000000.1135109616.00000000001AA000.00000002.00000001.01000000.00000003.sdmpBinary or memory string: OriginalFilenameRPLs.exe4 vs SecuriteInfo.com.Win32.SpywareX-gen.21876.23851.exe
            Source: SecuriteInfo.com.Win32.SpywareX-gen.21876.23851.exe, 00000001.00000002.3600280033.0000000000402000.00000040.00000400.00020000.00000000.sdmpBinary or memory string: OriginalFilenamelfwhUWZlmFnGhDYPudAJ.exeX vs SecuriteInfo.com.Win32.SpywareX-gen.21876.23851.exe
            Source: SecuriteInfo.com.Win32.SpywareX-gen.21876.23851.exe, 00000001.00000002.3600684769.0000000000EF7000.00000004.00000010.00020000.00000000.sdmpBinary or memory string: OriginalFilenameUNKNOWN_FILET vs SecuriteInfo.com.Win32.SpywareX-gen.21876.23851.exe
            Source: SecuriteInfo.com.Win32.SpywareX-gen.21876.23851.exeBinary or memory string: OriginalFilenameRPLs.exe4 vs SecuriteInfo.com.Win32.SpywareX-gen.21876.23851.exe
            Source: SecuriteInfo.com.Win32.SpywareX-gen.21876.23851.exeStatic PE information: EXECUTABLE_IMAGE, 32BIT_MACHINE
            Source: 0.2.SecuriteInfo.com.Win32.SpywareX-gen.21876.23851.exe.3682330.3.unpack, type: UNPACKEDPEMatched rule: Windows_Trojan_SnakeKeylogger_af3faa65 os = windows, severity = x86, creation_date = 2021-04-06, scan_context = file, memory, license = Elastic License v2, threat_name = Windows.Trojan.SnakeKeylogger, fingerprint = 15f4ef2a03c6f5c6284ea6a9013007e4ea7dc90a1ba9c81a53a1c7407d85890d, id = af3faa65-b19d-4267-ac02-1a3b50cdc700, last_modified = 2021-08-23
            Source: 0.2.SecuriteInfo.com.Win32.SpywareX-gen.21876.23851.exe.3682330.3.unpack, type: UNPACKEDPEMatched rule: MAL_Envrial_Jan18_1 date = 2018-01-21, hash2 = 9edd8f0e22340ecc45c5f09e449aa85d196f3f506ff3f44275367df924b95c5d, hash1 = 9ae3aa2c61f7895ba6b1a3f85fbe36c8697287dc7477c5a03d32cf994fdbce85, author = Florian Roth, description = Detects Encrial credential stealer malware, reference = https://twitter.com/malwrhunterteam/status/953313514629853184, license = https://creativecommons.org/licenses/by-nc/4.0/
            Source: 0.2.SecuriteInfo.com.Win32.SpywareX-gen.21876.23851.exe.3682330.3.unpack, type: UNPACKEDPEMatched rule: INDICATOR_SUSPICIOUS_EXE_DotNetProcHook author = ditekSHen, description = Detects executables with potential process hoocking
            Source: 0.2.SecuriteInfo.com.Win32.SpywareX-gen.21876.23851.exe.3682330.3.unpack, type: UNPACKEDPEMatched rule: MALWARE_Win_SnakeKeylogger author = ditekSHen, description = Detects Snake Keylogger, clamav_sig = MALWARE.Win.Trojan.SnakeKeylogger
            Source: 1.2.SecuriteInfo.com.Win32.SpywareX-gen.21876.23851.exe.400000.0.unpack, type: UNPACKEDPEMatched rule: Windows_Trojan_SnakeKeylogger_af3faa65 os = windows, severity = x86, creation_date = 2021-04-06, scan_context = file, memory, license = Elastic License v2, threat_name = Windows.Trojan.SnakeKeylogger, fingerprint = 15f4ef2a03c6f5c6284ea6a9013007e4ea7dc90a1ba9c81a53a1c7407d85890d, id = af3faa65-b19d-4267-ac02-1a3b50cdc700, last_modified = 2021-08-23
            Source: 1.2.SecuriteInfo.com.Win32.SpywareX-gen.21876.23851.exe.400000.0.unpack, type: UNPACKEDPEMatched rule: MAL_Envrial_Jan18_1 date = 2018-01-21, hash2 = 9edd8f0e22340ecc45c5f09e449aa85d196f3f506ff3f44275367df924b95c5d, hash1 = 9ae3aa2c61f7895ba6b1a3f85fbe36c8697287dc7477c5a03d32cf994fdbce85, author = Florian Roth, description = Detects Encrial credential stealer malware, reference = https://twitter.com/malwrhunterteam/status/953313514629853184, license = https://creativecommons.org/licenses/by-nc/4.0/
            Source: 1.2.SecuriteInfo.com.Win32.SpywareX-gen.21876.23851.exe.400000.0.unpack, type: UNPACKEDPEMatched rule: INDICATOR_SUSPICIOUS_EXE_DotNetProcHook author = ditekSHen, description = Detects executables with potential process hoocking
            Source: 1.2.SecuriteInfo.com.Win32.SpywareX-gen.21876.23851.exe.400000.0.unpack, type: UNPACKEDPEMatched rule: MALWARE_Win_SnakeKeylogger author = ditekSHen, description = Detects Snake Keylogger, clamav_sig = MALWARE.Win.Trojan.SnakeKeylogger
            Source: 0.2.SecuriteInfo.com.Win32.SpywareX-gen.21876.23851.exe.3661910.2.unpack, type: UNPACKEDPEMatched rule: Windows_Trojan_SnakeKeylogger_af3faa65 os = windows, severity = x86, creation_date = 2021-04-06, scan_context = file, memory, license = Elastic License v2, threat_name = Windows.Trojan.SnakeKeylogger, fingerprint = 15f4ef2a03c6f5c6284ea6a9013007e4ea7dc90a1ba9c81a53a1c7407d85890d, id = af3faa65-b19d-4267-ac02-1a3b50cdc700, last_modified = 2021-08-23
            Source: 0.2.SecuriteInfo.com.Win32.SpywareX-gen.21876.23851.exe.3661910.2.unpack, type: UNPACKEDPEMatched rule: MAL_Envrial_Jan18_1 date = 2018-01-21, hash2 = 9edd8f0e22340ecc45c5f09e449aa85d196f3f506ff3f44275367df924b95c5d, hash1 = 9ae3aa2c61f7895ba6b1a3f85fbe36c8697287dc7477c5a03d32cf994fdbce85, author = Florian Roth, description = Detects Encrial credential stealer malware, reference = https://twitter.com/malwrhunterteam/status/953313514629853184, license = https://creativecommons.org/licenses/by-nc/4.0/
            Source: 0.2.SecuriteInfo.com.Win32.SpywareX-gen.21876.23851.exe.3661910.2.unpack, type: UNPACKEDPEMatched rule: INDICATOR_SUSPICIOUS_EXE_DotNetProcHook author = ditekSHen, description = Detects executables with potential process hoocking
            Source: 0.2.SecuriteInfo.com.Win32.SpywareX-gen.21876.23851.exe.3661910.2.unpack, type: UNPACKEDPEMatched rule: MALWARE_Win_SnakeKeylogger author = ditekSHen, description = Detects Snake Keylogger, clamav_sig = MALWARE.Win.Trojan.SnakeKeylogger
            Source: 0.2.SecuriteInfo.com.Win32.SpywareX-gen.21876.23851.exe.3682330.3.raw.unpack, type: UNPACKEDPEMatched rule: Windows_Trojan_SnakeKeylogger_af3faa65 os = windows, severity = x86, creation_date = 2021-04-06, scan_context = file, memory, license = Elastic License v2, threat_name = Windows.Trojan.SnakeKeylogger, fingerprint = 15f4ef2a03c6f5c6284ea6a9013007e4ea7dc90a1ba9c81a53a1c7407d85890d, id = af3faa65-b19d-4267-ac02-1a3b50cdc700, last_modified = 2021-08-23
            Source: 0.2.SecuriteInfo.com.Win32.SpywareX-gen.21876.23851.exe.3682330.3.raw.unpack, type: UNPACKEDPEMatched rule: INDICATOR_SUSPICIOUS_EXE_DotNetProcHook author = ditekSHen, description = Detects executables with potential process hoocking
            Source: 0.2.SecuriteInfo.com.Win32.SpywareX-gen.21876.23851.exe.3682330.3.raw.unpack, type: UNPACKEDPEMatched rule: MALWARE_Win_SnakeKeylogger author = ditekSHen, description = Detects Snake Keylogger, clamav_sig = MALWARE.Win.Trojan.SnakeKeylogger
            Source: 0.2.SecuriteInfo.com.Win32.SpywareX-gen.21876.23851.exe.3661910.2.raw.unpack, type: UNPACKEDPEMatched rule: Windows_Trojan_SnakeKeylogger_af3faa65 os = windows, severity = x86, creation_date = 2021-04-06, scan_context = file, memory, license = Elastic License v2, threat_name = Windows.Trojan.SnakeKeylogger, fingerprint = 15f4ef2a03c6f5c6284ea6a9013007e4ea7dc90a1ba9c81a53a1c7407d85890d, id = af3faa65-b19d-4267-ac02-1a3b50cdc700, last_modified = 2021-08-23
            Source: 0.2.SecuriteInfo.com.Win32.SpywareX-gen.21876.23851.exe.3661910.2.raw.unpack, type: UNPACKEDPEMatched rule: INDICATOR_SUSPICIOUS_EXE_DotNetProcHook author = ditekSHen, description = Detects executables with potential process hoocking
            Source: 0.2.SecuriteInfo.com.Win32.SpywareX-gen.21876.23851.exe.3661910.2.raw.unpack, type: UNPACKEDPEMatched rule: MALWARE_Win_SnakeKeylogger author = ditekSHen, description = Detects Snake Keylogger, clamav_sig = MALWARE.Win.Trojan.SnakeKeylogger
            Source: 00000001.00000002.3600280033.0000000000402000.00000040.00000400.00020000.00000000.sdmp, type: MEMORYMatched rule: Windows_Trojan_SnakeKeylogger_af3faa65 os = windows, severity = x86, creation_date = 2021-04-06, scan_context = file, memory, license = Elastic License v2, threat_name = Windows.Trojan.SnakeKeylogger, fingerprint = 15f4ef2a03c6f5c6284ea6a9013007e4ea7dc90a1ba9c81a53a1c7407d85890d, id = af3faa65-b19d-4267-ac02-1a3b50cdc700, last_modified = 2021-08-23
            Source: 00000001.00000002.3600280033.0000000000402000.00000040.00000400.00020000.00000000.sdmp, type: MEMORYMatched rule: MALWARE_Win_SnakeKeylogger author = ditekSHen, description = Detects Snake Keylogger, clamav_sig = MALWARE.Win.Trojan.SnakeKeylogger
            Source: 00000000.00000002.1162231043.0000000003661000.00000004.00000800.00020000.00000000.sdmp, type: MEMORYMatched rule: Windows_Trojan_SnakeKeylogger_af3faa65 os = windows, severity = x86, creation_date = 2021-04-06, scan_context = file, memory, license = Elastic License v2, threat_name = Windows.Trojan.SnakeKeylogger, fingerprint = 15f4ef2a03c6f5c6284ea6a9013007e4ea7dc90a1ba9c81a53a1c7407d85890d, id = af3faa65-b19d-4267-ac02-1a3b50cdc700, last_modified = 2021-08-23
            Source: 00000000.00000002.1162231043.0000000003661000.00000004.00000800.00020000.00000000.sdmp, type: MEMORYMatched rule: MALWARE_Win_SnakeKeylogger author = ditekSHen, description = Detects Snake Keylogger, clamav_sig = MALWARE.Win.Trojan.SnakeKeylogger
            Source: Process Memory Space: SecuriteInfo.com.Win32.SpywareX-gen.21876.23851.exe PID: 7784, type: MEMORYSTRMatched rule: Windows_Trojan_SnakeKeylogger_af3faa65 os = windows, severity = x86, creation_date = 2021-04-06, scan_context = file, memory, license = Elastic License v2, threat_name = Windows.Trojan.SnakeKeylogger, fingerprint = 15f4ef2a03c6f5c6284ea6a9013007e4ea7dc90a1ba9c81a53a1c7407d85890d, id = af3faa65-b19d-4267-ac02-1a3b50cdc700, last_modified = 2021-08-23
            Source: Process Memory Space: SecuriteInfo.com.Win32.SpywareX-gen.21876.23851.exe PID: 7784, type: MEMORYSTRMatched rule: MALWARE_Win_SnakeKeylogger author = ditekSHen, description = Detects Snake Keylogger, clamav_sig = MALWARE.Win.Trojan.SnakeKeylogger
            Source: Process Memory Space: SecuriteInfo.com.Win32.SpywareX-gen.21876.23851.exe PID: 7876, type: MEMORYSTRMatched rule: Windows_Trojan_SnakeKeylogger_af3faa65 os = windows, severity = x86, creation_date = 2021-04-06, scan_context = file, memory, license = Elastic License v2, threat_name = Windows.Trojan.SnakeKeylogger, fingerprint = 15f4ef2a03c6f5c6284ea6a9013007e4ea7dc90a1ba9c81a53a1c7407d85890d, id = af3faa65-b19d-4267-ac02-1a3b50cdc700, last_modified = 2021-08-23
            Source: Process Memory Space: SecuriteInfo.com.Win32.SpywareX-gen.21876.23851.exe PID: 7876, type: MEMORYSTRMatched rule: MALWARE_Win_SnakeKeylogger author = ditekSHen, description = Detects Snake Keylogger, clamav_sig = MALWARE.Win.Trojan.SnakeKeylogger
            Source: SecuriteInfo.com.Win32.SpywareX-gen.21876.23851.exeStatic PE information: Section: .text IMAGE_SCN_CNT_CODE, IMAGE_SCN_MEM_EXECUTE, IMAGE_SCN_MEM_READ
            Source: 0.2.SecuriteInfo.com.Win32.SpywareX-gen.21876.23851.exe.3661910.2.raw.unpack, ---.csCryptographic APIs: 'TransformFinalBlock'
            Source: 0.2.SecuriteInfo.com.Win32.SpywareX-gen.21876.23851.exe.3661910.2.raw.unpack, ---.csCryptographic APIs: 'TransformFinalBlock'
            Source: 0.2.SecuriteInfo.com.Win32.SpywareX-gen.21876.23851.exe.3661910.2.raw.unpack, z2.csCryptographic APIs: 'TransformFinalBlock'
            Source: 0.2.SecuriteInfo.com.Win32.SpywareX-gen.21876.23851.exe.3661910.2.raw.unpack, z2.csCryptographic APIs: 'TransformFinalBlock'
            Source: 0.2.SecuriteInfo.com.Win32.SpywareX-gen.21876.23851.exe.3682330.3.raw.unpack, ---.csCryptographic APIs: 'TransformFinalBlock'
            Source: 0.2.SecuriteInfo.com.Win32.SpywareX-gen.21876.23851.exe.3682330.3.raw.unpack, ---.csCryptographic APIs: 'TransformFinalBlock'
            Source: 0.2.SecuriteInfo.com.Win32.SpywareX-gen.21876.23851.exe.3682330.3.raw.unpack, z2.csCryptographic APIs: 'TransformFinalBlock'
            Source: 0.2.SecuriteInfo.com.Win32.SpywareX-gen.21876.23851.exe.3682330.3.raw.unpack, z2.csCryptographic APIs: 'TransformFinalBlock'
            Source: 0.2.SecuriteInfo.com.Win32.SpywareX-gen.21876.23851.exe.3661910.2.raw.unpack, ---.csBase64 encoded string: 'JzeJw/b9xm+6S2XbSxm04VLxDXW0s8jprFo3QVj1S6zHgpFf8L4EKsa9LKLu5QP6'
            Source: 0.2.SecuriteInfo.com.Win32.SpywareX-gen.21876.23851.exe.3682330.3.raw.unpack, ---.csBase64 encoded string: 'JzeJw/b9xm+6S2XbSxm04VLxDXW0s8jprFo3QVj1S6zHgpFf8L4EKsa9LKLu5QP6'
            Source: 0.2.SecuriteInfo.com.Win32.SpywareX-gen.21876.23851.exe.379a448.5.raw.unpack, xjuciJKCOIPdtRI75L.csSecurity API names: System.Security.Principal.WindowsPrincipal.IsInRole(System.Security.Principal.WindowsBuiltInRole)
            Source: 0.2.SecuriteInfo.com.Win32.SpywareX-gen.21876.23851.exe.379a448.5.raw.unpack, xjuciJKCOIPdtRI75L.csSecurity API names: System.Security.Principal.WindowsIdentity.GetCurrent()
            Source: 0.2.SecuriteInfo.com.Win32.SpywareX-gen.21876.23851.exe.7a90000.8.raw.unpack, xjuciJKCOIPdtRI75L.csSecurity API names: System.Security.Principal.WindowsPrincipal.IsInRole(System.Security.Principal.WindowsBuiltInRole)
            Source: 0.2.SecuriteInfo.com.Win32.SpywareX-gen.21876.23851.exe.7a90000.8.raw.unpack, xjuciJKCOIPdtRI75L.csSecurity API names: System.Security.Principal.WindowsIdentity.GetCurrent()
            Source: 0.2.SecuriteInfo.com.Win32.SpywareX-gen.21876.23851.exe.7a90000.8.raw.unpack, EyJk559tnEhMxIsMfN.csSecurity API names: System.IO.DirectoryInfo.SetAccessControl(System.Security.AccessControl.DirectorySecurity)
            Source: 0.2.SecuriteInfo.com.Win32.SpywareX-gen.21876.23851.exe.7a90000.8.raw.unpack, EyJk559tnEhMxIsMfN.csSecurity API names: System.Security.Principal.WindowsIdentity.GetCurrent()
            Source: 0.2.SecuriteInfo.com.Win32.SpywareX-gen.21876.23851.exe.7a90000.8.raw.unpack, EyJk559tnEhMxIsMfN.csSecurity API names: System.Security.AccessControl.FileSystemSecurity.AddAccessRule(System.Security.AccessControl.FileSystemAccessRule)
            Source: 0.2.SecuriteInfo.com.Win32.SpywareX-gen.21876.23851.exe.379a448.5.raw.unpack, EyJk559tnEhMxIsMfN.csSecurity API names: System.IO.DirectoryInfo.SetAccessControl(System.Security.AccessControl.DirectorySecurity)
            Source: 0.2.SecuriteInfo.com.Win32.SpywareX-gen.21876.23851.exe.379a448.5.raw.unpack, EyJk559tnEhMxIsMfN.csSecurity API names: System.Security.Principal.WindowsIdentity.GetCurrent()
            Source: 0.2.SecuriteInfo.com.Win32.SpywareX-gen.21876.23851.exe.379a448.5.raw.unpack, EyJk559tnEhMxIsMfN.csSecurity API names: System.Security.AccessControl.FileSystemSecurity.AddAccessRule(System.Security.AccessControl.FileSystemAccessRule)
            Source: classification engineClassification label: mal100.troj.spyw.evad.winEXE@3/1@2/2
            Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.SpywareX-gen.21876.23851.exeFile created: C:\Users\user\AppData\Local\Microsoft\CLR_v4.0_32\UsageLogs\SecuriteInfo.com.Win32.SpywareX-gen.21876.23851.exe.logJump to behavior
            Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.SpywareX-gen.21876.23851.exeMutant created: NULL
            Source: SecuriteInfo.com.Win32.SpywareX-gen.21876.23851.exeStatic PE information: Section: .text IMAGE_SCN_CNT_CODE, IMAGE_SCN_MEM_EXECUTE, IMAGE_SCN_MEM_READ
            Source: SecuriteInfo.com.Win32.SpywareX-gen.21876.23851.exeStatic file information: TRID: Win32 Executable (generic) Net Framework (10011505/4) 49.80%
            Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.SpywareX-gen.21876.23851.exeKey opened: HKEY_CURRENT_USER\Software\Policies\Microsoft\Windows\Safer\CodeIdentifiersJump to behavior
            Source: SecuriteInfo.com.Win32.SpywareX-gen.21876.23851.exe, 00000001.00000002.3604112864.00000000030A5000.00000004.00000800.00020000.00000000.sdmp, SecuriteInfo.com.Win32.SpywareX-gen.21876.23851.exe, 00000001.00000002.3604112864.0000000003095000.00000004.00000800.00020000.00000000.sdmp, SecuriteInfo.com.Win32.SpywareX-gen.21876.23851.exe, 00000001.00000002.3604112864.00000000030B3000.00000004.00000800.00020000.00000000.sdmpBinary or memory string: CREATE TABLE password_notes (id INTEGER PRIMARY KEY AUTOINCREMENT, parent_id INTEGER NOT NULL REFERENCES logins ON UPDATE CASCADE ON DELETE CASCADE DEFERRABLE INITIALLY DEFERRED, key VARCHAR NOT NULL, value BLOB, date_created INTEGER NOT NULL, confidential INTEGER, UNIQUE (parent_id, key));
            Source: SecuriteInfo.com.Win32.SpywareX-gen.21876.23851.exeVirustotal: Detection: 35%
            Source: SecuriteInfo.com.Win32.SpywareX-gen.21876.23851.exeReversingLabs: Detection: 44%
            Source: unknownProcess created: C:\Users\user\Desktop\SecuriteInfo.com.Win32.SpywareX-gen.21876.23851.exe "C:\Users\user\Desktop\SecuriteInfo.com.Win32.SpywareX-gen.21876.23851.exe"
            Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.SpywareX-gen.21876.23851.exeProcess created: C:\Users\user\Desktop\SecuriteInfo.com.Win32.SpywareX-gen.21876.23851.exe "C:\Users\user\Desktop\SecuriteInfo.com.Win32.SpywareX-gen.21876.23851.exe"
            Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.SpywareX-gen.21876.23851.exeProcess created: C:\Users\user\Desktop\SecuriteInfo.com.Win32.SpywareX-gen.21876.23851.exe "C:\Users\user\Desktop\SecuriteInfo.com.Win32.SpywareX-gen.21876.23851.exe"Jump to behavior
            Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.SpywareX-gen.21876.23851.exeSection loaded: mscoree.dllJump to behavior
            Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.SpywareX-gen.21876.23851.exeSection loaded: apphelp.dllJump to behavior
            Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.SpywareX-gen.21876.23851.exeSection loaded: kernel.appcore.dllJump to behavior
            Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.SpywareX-gen.21876.23851.exeSection loaded: version.dllJump to behavior
            Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.SpywareX-gen.21876.23851.exeSection loaded: vcruntime140_clr0400.dllJump to behavior
            Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.SpywareX-gen.21876.23851.exeSection loaded: ucrtbase_clr0400.dllJump to behavior
            Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.SpywareX-gen.21876.23851.exeSection loaded: uxtheme.dllJump to behavior
            Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.SpywareX-gen.21876.23851.exeSection loaded: windows.storage.dllJump to behavior
            Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.SpywareX-gen.21876.23851.exeSection loaded: wldp.dllJump to behavior
            Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.SpywareX-gen.21876.23851.exeSection loaded: profapi.dllJump to behavior
            Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.SpywareX-gen.21876.23851.exeSection loaded: cryptsp.dllJump to behavior
            Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.SpywareX-gen.21876.23851.exeSection loaded: rsaenh.dllJump to behavior
            Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.SpywareX-gen.21876.23851.exeSection loaded: cryptbase.dllJump to behavior
            Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.SpywareX-gen.21876.23851.exeSection loaded: dwrite.dllJump to behavior
            Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.SpywareX-gen.21876.23851.exeSection loaded: amsi.dllJump to behavior
            Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.SpywareX-gen.21876.23851.exeSection loaded: userenv.dllJump to behavior
            Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.SpywareX-gen.21876.23851.exeSection loaded: msasn1.dllJump to behavior
            Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.SpywareX-gen.21876.23851.exeSection loaded: gpapi.dllJump to behavior
            Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.SpywareX-gen.21876.23851.exeSection loaded: windowscodecs.dllJump to behavior
            Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.SpywareX-gen.21876.23851.exeSection loaded: iconcodecservice.dllJump to behavior
            Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.SpywareX-gen.21876.23851.exeSection loaded: mscoree.dllJump to behavior
            Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.SpywareX-gen.21876.23851.exeSection loaded: kernel.appcore.dllJump to behavior
            Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.SpywareX-gen.21876.23851.exeSection loaded: version.dllJump to behavior
            Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.SpywareX-gen.21876.23851.exeSection loaded: vcruntime140_clr0400.dllJump to behavior
            Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.SpywareX-gen.21876.23851.exeSection loaded: ucrtbase_clr0400.dllJump to behavior
            Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.SpywareX-gen.21876.23851.exeSection loaded: ucrtbase_clr0400.dllJump to behavior
            Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.SpywareX-gen.21876.23851.exeSection loaded: uxtheme.dllJump to behavior
            Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.SpywareX-gen.21876.23851.exeSection loaded: windows.storage.dllJump to behavior
            Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.SpywareX-gen.21876.23851.exeSection loaded: wldp.dllJump to behavior
            Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.SpywareX-gen.21876.23851.exeSection loaded: profapi.dllJump to behavior
            Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.SpywareX-gen.21876.23851.exeSection loaded: cryptsp.dllJump to behavior
            Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.SpywareX-gen.21876.23851.exeSection loaded: rsaenh.dllJump to behavior
            Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.SpywareX-gen.21876.23851.exeSection loaded: cryptbase.dllJump to behavior
            Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.SpywareX-gen.21876.23851.exeSection loaded: rasapi32.dllJump to behavior
            Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.SpywareX-gen.21876.23851.exeSection loaded: rasman.dllJump to behavior
            Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.SpywareX-gen.21876.23851.exeSection loaded: rtutils.dllJump to behavior
            Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.SpywareX-gen.21876.23851.exeSection loaded: mswsock.dllJump to behavior
            Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.SpywareX-gen.21876.23851.exeSection loaded: winhttp.dllJump to behavior
            Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.SpywareX-gen.21876.23851.exeSection loaded: ondemandconnroutehelper.dllJump to behavior
            Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.SpywareX-gen.21876.23851.exeSection loaded: iphlpapi.dllJump to behavior
            Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.SpywareX-gen.21876.23851.exeSection loaded: dhcpcsvc6.dllJump to behavior
            Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.SpywareX-gen.21876.23851.exeSection loaded: dhcpcsvc.dllJump to behavior
            Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.SpywareX-gen.21876.23851.exeSection loaded: dnsapi.dllJump to behavior
            Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.SpywareX-gen.21876.23851.exeSection loaded: winnsi.dllJump to behavior
            Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.SpywareX-gen.21876.23851.exeSection loaded: rasadhlp.dllJump to behavior
            Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.SpywareX-gen.21876.23851.exeSection loaded: fwpuclnt.dllJump to behavior
            Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.SpywareX-gen.21876.23851.exeSection loaded: secur32.dllJump to behavior
            Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.SpywareX-gen.21876.23851.exeSection loaded: sspicli.dllJump to behavior
            Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.SpywareX-gen.21876.23851.exeSection loaded: schannel.dllJump to behavior
            Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.SpywareX-gen.21876.23851.exeSection loaded: mskeyprotect.dllJump to behavior
            Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.SpywareX-gen.21876.23851.exeSection loaded: ntasn1.dllJump to behavior
            Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.SpywareX-gen.21876.23851.exeSection loaded: ncrypt.dllJump to behavior
            Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.SpywareX-gen.21876.23851.exeSection loaded: ncryptsslp.dllJump to behavior
            Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.SpywareX-gen.21876.23851.exeSection loaded: msasn1.dllJump to behavior
            Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.SpywareX-gen.21876.23851.exeSection loaded: gpapi.dllJump to behavior
            Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.SpywareX-gen.21876.23851.exeSection loaded: dpapi.dllJump to behavior
            Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.SpywareX-gen.21876.23851.exeKey value queried: HKEY_LOCAL_MACHINE\SOFTWARE\Classes\WOW6432Node\CLSID\{0EE7644B-1BAD-48B1-9889-0281C206EB85}\InprocServer32Jump to behavior
            Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.SpywareX-gen.21876.23851.exeFile opened: C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscorrc.dllJump to behavior
            Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.SpywareX-gen.21876.23851.exeKey opened: HKEY_CURRENT_USER\Software\Microsoft\Office\15.0\Outlook\Profiles\Outlook\9375CFF0413111d3B88A00104B2A6676Jump to behavior
            Source: SecuriteInfo.com.Win32.SpywareX-gen.21876.23851.exeStatic PE information: data directory type: IMAGE_DIRECTORY_ENTRY_COM_DESCRIPTOR
            Source: SecuriteInfo.com.Win32.SpywareX-gen.21876.23851.exeStatic PE information: HIGH_ENTROPY_VA, DYNAMIC_BASE, NX_COMPAT, NO_SEH, TERMINAL_SERVER_AWARE

            Data Obfuscation

            barindex
            Source: 0.2.SecuriteInfo.com.Win32.SpywareX-gen.21876.23851.exe.379a448.5.raw.unpack, EyJk559tnEhMxIsMfN.cs.Net Code: AbsxYiQiJB System.Reflection.Assembly.Load(byte[])
            Source: 0.2.SecuriteInfo.com.Win32.SpywareX-gen.21876.23851.exe.7a90000.8.raw.unpack, EyJk559tnEhMxIsMfN.cs.Net Code: AbsxYiQiJB System.Reflection.Assembly.Load(byte[])
            Source: SecuriteInfo.com.Win32.SpywareX-gen.21876.23851.exeStatic PE information: section name: .text entropy: 7.698772372207659
            Source: 0.2.SecuriteInfo.com.Win32.SpywareX-gen.21876.23851.exe.379a448.5.raw.unpack, e1U4VQQ7acWEeuQfEj.csHigh entropy of concatenated method names: 'P01NmeoquZ', 'i1nNMD6Ovn', 'kORNYlrGYK', 'JZ3NDPkxSp', 'CkENygnak1', 'wZkNwcWP9b', 'S8jNIpuT5I', 'aKVNKrAusD', 'lRENTcOcr5', 'SjcNAWUPPD'
            Source: 0.2.SecuriteInfo.com.Win32.SpywareX-gen.21876.23851.exe.379a448.5.raw.unpack, XRQd6OjQcOl3TObGqN.csHigh entropy of concatenated method names: 'Dispose', 'HtVricdUSD', 'tCS6eqrvMM', 'hrlxuMKsXS', 'HhMrfMeWCM', 'Tncrz4itbP', 'ProcessDialogKey', 'pJJ6krZHNF', 'p5J6rXA7KJ', 'UEd66gr4s1'
            Source: 0.2.SecuriteInfo.com.Win32.SpywareX-gen.21876.23851.exe.379a448.5.raw.unpack, S4qbZtrrTqTlb9PaCuT.csHigh entropy of concatenated method names: 'njcqfbZ7Em', 'CNsqzMYxjg', 'BxaokwbM4y', 'BiZorm1TP9', 'zIVo6bOeAl', 'K27oBmCbwU', 'xK1oxSBop8', 'AFDoWK7kAj', 'faBo1suI5P', 'e83ojs1MnN'
            Source: 0.2.SecuriteInfo.com.Win32.SpywareX-gen.21876.23851.exe.379a448.5.raw.unpack, EyJk559tnEhMxIsMfN.csHigh entropy of concatenated method names: 'TxgBWe327M', 'KZoB1lQ4YC', 'o0LBjKdVrD', 'lg6BG22Sn1', 'QqpB5lIErM', 'd03BVPhGtJ', 'tp8BNVS6gC', 'Y1eB9BnVIG', 'HsCBphMh6G', 'ffNB8pQ2IB'
            Source: 0.2.SecuriteInfo.com.Win32.SpywareX-gen.21876.23851.exe.379a448.5.raw.unpack, bCWvHbG4CeRvKZSRlV.csHigh entropy of concatenated method names: 'EditValue', 'GetEditStyle', 'bMt6ieSYgm', 'y8M6fhjTd0', 'BWM6zT6Vk5', 'sMaBklI35k', 'WbxBrOJ0d0', 'QvZB6A4DE8', 'MZgBBM4QkB', 'pbKxfvXjmcVfu6XPtJV'
            Source: 0.2.SecuriteInfo.com.Win32.SpywareX-gen.21876.23851.exe.379a448.5.raw.unpack, RocnB2u6C8dIpdLghk.csHigh entropy of concatenated method names: 'jdCVWOkECE', 'BtUVjX1oJy', 'xmJV5SnXlt', 'jkCVNCVXcU', 'QnxV93VOQ9', 'JrF5RlJOET', 'uDM5nRBPwI', 'FUc5C67aHe', 'IHo5ZsIwDf', 'nmn5iuQYWQ'
            Source: 0.2.SecuriteInfo.com.Win32.SpywareX-gen.21876.23851.exe.379a448.5.raw.unpack, z7HkQISSUc8fxlNT0x.csHigh entropy of concatenated method names: 'FnDs8axPlF', 'U4ZslSRcgX', 'ToString', 'FE4s1dlYeU', 'gbUsj6RmVQ', 'ssWsGe8a5X', 'hOls5MFQhb', 'yZFsVPykcr', 'zaUsNYkTT3', 'i43s9D8jir'
            Source: 0.2.SecuriteInfo.com.Win32.SpywareX-gen.21876.23851.exe.379a448.5.raw.unpack, w3ZuvYCFmLtVcdUSDL.csHigh entropy of concatenated method names: 'ACO2F3wZB8', 'uXT2sFDswQ', 'WIf22Pdvw7', 'C0b2omCkqv', 'nrl2dJdGMG', 'QPK2HA3JA9', 'Dispose', 'SooJ1t1jT0', 'jwvJjxHgsg', 'pIlJGIXytF'
            Source: 0.2.SecuriteInfo.com.Win32.SpywareX-gen.21876.23851.exe.379a448.5.raw.unpack, pr4s13fQXspK0cwc1I.csHigh entropy of concatenated method names: 't39qGFMsFp', 'kjjq5Y7Pvp', 'yPBqVWqLyg', 'kkKqNDZdqV', 'rfmq2p7QQ7', 'Yuoq9SIi5d', 'Next', 'Next', 'Next', 'NextBytes'
            Source: 0.2.SecuriteInfo.com.Win32.SpywareX-gen.21876.23851.exe.379a448.5.raw.unpack, qrZHNFig5JXA7KJREd.csHigh entropy of concatenated method names: 'WKn2ulCoZK', 'SSI2eHgmRL', 'Usx2L0OiOk', 'U5h20bYHGf', 'WBR23Ln1M3', 'QN22Ocxq2i', 'eOT2EU9xAm', 'KkU2UrjOsA', 'I8X2QVA5f9', 'RA52XVhgyO'
            Source: 0.2.SecuriteInfo.com.Win32.SpywareX-gen.21876.23851.exe.379a448.5.raw.unpack, fcADGoPOgv7XtLc1lr.csHigh entropy of concatenated method names: 'ToString', 'U8Hgctc4oH', 'NfygeaN4Nh', 'OTtgLhBlAg', 'TZJg0aJ6qm', 'Lo1g3RRTrS', 'a4DgOwbd3y', 'zC5gEjSMvK', 's30gUsIQx0', 'cpTgQUaKWY'
            Source: 0.2.SecuriteInfo.com.Win32.SpywareX-gen.21876.23851.exe.379a448.5.raw.unpack, fUtiR375gvAFZ0s7oX.csHigh entropy of concatenated method names: 'lLm4KWvhAf', 'RpQ4TBIqA8', 'BcB4ucjpC1', 'ac54eoWPGQ', 'URZ403OIR4', 'lUP43wQvFn', 'J224E3341q', 'epI4UexKy9', 'TD14Xi7FpI', 'ad64coTohs'
            Source: 0.2.SecuriteInfo.com.Win32.SpywareX-gen.21876.23851.exe.379a448.5.raw.unpack, OyoJ5qrk9TMoyInOpOI.csHigh entropy of concatenated method names: 'CanConvertFrom', 'ConvertFrom', 'ConvertTo', 'eOuqcWIdd2', 'M6OqaUpIyw', 'gW2q7KaoRt', 'Ygkqh7OiCY', 'A3Iqt69qqI', 'FHEqPoCqF7', 'fBVqSGWpKj'
            Source: 0.2.SecuriteInfo.com.Win32.SpywareX-gen.21876.23851.exe.379a448.5.raw.unpack, gHNKGQTwPXojjZtPg1.csHigh entropy of concatenated method names: 'iVPGDq6Ho4', 'WsyGwrFVO6', 'seMGK8o6y7', 'x0XGTrhy82', 'qChGF1HbYd', 'R3sGg9gE16', 'iyjGsaGrky', 'dZJGJ8TDX6', 'EFOG2PFJwx', 'ociGq5dQV5'
            Source: 0.2.SecuriteInfo.com.Win32.SpywareX-gen.21876.23851.exe.379a448.5.raw.unpack, PeRObGEbsmxBxW0AqV.csHigh entropy of concatenated method names: 'OyNN1hCBL7', 'oCtNGF2Rsj', 'E2nNVJ1C5R', 'xuNVfQaP1J', 'UAqVzy0JNT', 'AImNkodmDF', 'Id6NrHa1El', 'vMjN6VjuI5', 'rsMNBAe4fK', 'dD3NxisHBu'
            Source: 0.2.SecuriteInfo.com.Win32.SpywareX-gen.21876.23851.exe.379a448.5.raw.unpack, boxq7on20nxSOc1pYB.csHigh entropy of concatenated method names: 'H3CsZrRSMF', 'VCxsfQpu9q', 'qs2JkArA25', 'vA0Jrv1Zfy', 'y4FscRI5jE', 'aiKsah08gf', 'b5ss7wCspt', 'Djrshn4TLU', 'lcystgJCaq', 'rOisPISEp9'
            Source: 0.2.SecuriteInfo.com.Win32.SpywareX-gen.21876.23851.exe.379a448.5.raw.unpack, KRNngrUKXnqM1Klq8d.csHigh entropy of concatenated method names: 'ISKNsxDoCT', 'ac7N2mgoRl', 'CBDNgK5fav', 'rRWykrMJPYhfE8satsL', 'FMLjQoMy0JdH9im2peK', 'dEXOhoMFvwr1TcUqkry'
            Source: 0.2.SecuriteInfo.com.Win32.SpywareX-gen.21876.23851.exe.379a448.5.raw.unpack, xjuciJKCOIPdtRI75L.csHigh entropy of concatenated method names: 'MIJjhEMlKS', 'q7JjtkhU2H', 'z1sjPVLVwm', 'wMbjScV40B', 'CydjRdZaEv', 'psJjnVSTAS', 'KLwjCorqUj', 'HAyjZ44REx', 'PONjiVZ4AM', 'NMPjfAQhiJ'
            Source: 0.2.SecuriteInfo.com.Win32.SpywareX-gen.21876.23851.exe.379a448.5.raw.unpack, AK3Fh9AHBPMI9DMtJn.csHigh entropy of concatenated method names: 'Cgw5yG8Cx1', 'fAb5Ix9UGQ', 'g0sGLiOB4k', 'HksG0S5e8C', 'cjsG3Sjs6m', 'wZUGO1br3M', 'VxGGEr3edb', 'tfLGUuBq2c', 'V1oGQfidFf', 'z2tGXCF21p'
            Source: 0.2.SecuriteInfo.com.Win32.SpywareX-gen.21876.23851.exe.379a448.5.raw.unpack, RJaaji63qW95FhffxD.csHigh entropy of concatenated method names: 'UtfYCr8Jg', 'NmXDCDgSl', 'xQ8wsEZZG', 'XXCIdZh8l', 'uBMTBtUjl', 'uScA09hCe', 'JjVgk2P0gqd9OpBDvg', 'XmhkRtKjHEa5suBvZ8', 'h7gJnQ2at', 'XaNqPEXWp'
            Source: 0.2.SecuriteInfo.com.Win32.SpywareX-gen.21876.23851.exe.379a448.5.raw.unpack, RWedmCzgLalRtVO9k4.csHigh entropy of concatenated method names: 'JC1qwAnUkA', 'ILcqKMcmyJ', 'mxYqTuHZUT', 'JFlqu3cr0Q', 'Nt8qe2Xckw', 'OgBq0VwgLm', 'fhGq3j9lOw', 'beCqHdMT0h', 'ajyqmmcjgC', 'DjGqM4K5wj'
            Source: 0.2.SecuriteInfo.com.Win32.SpywareX-gen.21876.23851.exe.379a448.5.raw.unpack, OtiHIKxaCIp5HFqLh8.csHigh entropy of concatenated method names: 'hwHrNjuciJ', 'VOIr9PdtRI', 'MwPr8XojjZ', 'RPgrl1yK3F', 'AMtrFJntoc', 'VB2rg6C8dI', 'EuPjhV7P38V1pB5C9S', 'BvgqOuvOAmwReNjbu0', 'xxarrJmvnM', 'dH8rBYVCZl'
            Source: 0.2.SecuriteInfo.com.Win32.SpywareX-gen.21876.23851.exe.7a90000.8.raw.unpack, e1U4VQQ7acWEeuQfEj.csHigh entropy of concatenated method names: 'P01NmeoquZ', 'i1nNMD6Ovn', 'kORNYlrGYK', 'JZ3NDPkxSp', 'CkENygnak1', 'wZkNwcWP9b', 'S8jNIpuT5I', 'aKVNKrAusD', 'lRENTcOcr5', 'SjcNAWUPPD'
            Source: 0.2.SecuriteInfo.com.Win32.SpywareX-gen.21876.23851.exe.7a90000.8.raw.unpack, XRQd6OjQcOl3TObGqN.csHigh entropy of concatenated method names: 'Dispose', 'HtVricdUSD', 'tCS6eqrvMM', 'hrlxuMKsXS', 'HhMrfMeWCM', 'Tncrz4itbP', 'ProcessDialogKey', 'pJJ6krZHNF', 'p5J6rXA7KJ', 'UEd66gr4s1'
            Source: 0.2.SecuriteInfo.com.Win32.SpywareX-gen.21876.23851.exe.7a90000.8.raw.unpack, S4qbZtrrTqTlb9PaCuT.csHigh entropy of concatenated method names: 'njcqfbZ7Em', 'CNsqzMYxjg', 'BxaokwbM4y', 'BiZorm1TP9', 'zIVo6bOeAl', 'K27oBmCbwU', 'xK1oxSBop8', 'AFDoWK7kAj', 'faBo1suI5P', 'e83ojs1MnN'
            Source: 0.2.SecuriteInfo.com.Win32.SpywareX-gen.21876.23851.exe.7a90000.8.raw.unpack, EyJk559tnEhMxIsMfN.csHigh entropy of concatenated method names: 'TxgBWe327M', 'KZoB1lQ4YC', 'o0LBjKdVrD', 'lg6BG22Sn1', 'QqpB5lIErM', 'd03BVPhGtJ', 'tp8BNVS6gC', 'Y1eB9BnVIG', 'HsCBphMh6G', 'ffNB8pQ2IB'
            Source: 0.2.SecuriteInfo.com.Win32.SpywareX-gen.21876.23851.exe.7a90000.8.raw.unpack, bCWvHbG4CeRvKZSRlV.csHigh entropy of concatenated method names: 'EditValue', 'GetEditStyle', 'bMt6ieSYgm', 'y8M6fhjTd0', 'BWM6zT6Vk5', 'sMaBklI35k', 'WbxBrOJ0d0', 'QvZB6A4DE8', 'MZgBBM4QkB', 'pbKxfvXjmcVfu6XPtJV'
            Source: 0.2.SecuriteInfo.com.Win32.SpywareX-gen.21876.23851.exe.7a90000.8.raw.unpack, RocnB2u6C8dIpdLghk.csHigh entropy of concatenated method names: 'jdCVWOkECE', 'BtUVjX1oJy', 'xmJV5SnXlt', 'jkCVNCVXcU', 'QnxV93VOQ9', 'JrF5RlJOET', 'uDM5nRBPwI', 'FUc5C67aHe', 'IHo5ZsIwDf', 'nmn5iuQYWQ'
            Source: 0.2.SecuriteInfo.com.Win32.SpywareX-gen.21876.23851.exe.7a90000.8.raw.unpack, z7HkQISSUc8fxlNT0x.csHigh entropy of concatenated method names: 'FnDs8axPlF', 'U4ZslSRcgX', 'ToString', 'FE4s1dlYeU', 'gbUsj6RmVQ', 'ssWsGe8a5X', 'hOls5MFQhb', 'yZFsVPykcr', 'zaUsNYkTT3', 'i43s9D8jir'
            Source: 0.2.SecuriteInfo.com.Win32.SpywareX-gen.21876.23851.exe.7a90000.8.raw.unpack, w3ZuvYCFmLtVcdUSDL.csHigh entropy of concatenated method names: 'ACO2F3wZB8', 'uXT2sFDswQ', 'WIf22Pdvw7', 'C0b2omCkqv', 'nrl2dJdGMG', 'QPK2HA3JA9', 'Dispose', 'SooJ1t1jT0', 'jwvJjxHgsg', 'pIlJGIXytF'
            Source: 0.2.SecuriteInfo.com.Win32.SpywareX-gen.21876.23851.exe.7a90000.8.raw.unpack, pr4s13fQXspK0cwc1I.csHigh entropy of concatenated method names: 't39qGFMsFp', 'kjjq5Y7Pvp', 'yPBqVWqLyg', 'kkKqNDZdqV', 'rfmq2p7QQ7', 'Yuoq9SIi5d', 'Next', 'Next', 'Next', 'NextBytes'
            Source: 0.2.SecuriteInfo.com.Win32.SpywareX-gen.21876.23851.exe.7a90000.8.raw.unpack, qrZHNFig5JXA7KJREd.csHigh entropy of concatenated method names: 'WKn2ulCoZK', 'SSI2eHgmRL', 'Usx2L0OiOk', 'U5h20bYHGf', 'WBR23Ln1M3', 'QN22Ocxq2i', 'eOT2EU9xAm', 'KkU2UrjOsA', 'I8X2QVA5f9', 'RA52XVhgyO'
            Source: 0.2.SecuriteInfo.com.Win32.SpywareX-gen.21876.23851.exe.7a90000.8.raw.unpack, fcADGoPOgv7XtLc1lr.csHigh entropy of concatenated method names: 'ToString', 'U8Hgctc4oH', 'NfygeaN4Nh', 'OTtgLhBlAg', 'TZJg0aJ6qm', 'Lo1g3RRTrS', 'a4DgOwbd3y', 'zC5gEjSMvK', 's30gUsIQx0', 'cpTgQUaKWY'
            Source: 0.2.SecuriteInfo.com.Win32.SpywareX-gen.21876.23851.exe.7a90000.8.raw.unpack, fUtiR375gvAFZ0s7oX.csHigh entropy of concatenated method names: 'lLm4KWvhAf', 'RpQ4TBIqA8', 'BcB4ucjpC1', 'ac54eoWPGQ', 'URZ403OIR4', 'lUP43wQvFn', 'J224E3341q', 'epI4UexKy9', 'TD14Xi7FpI', 'ad64coTohs'
            Source: 0.2.SecuriteInfo.com.Win32.SpywareX-gen.21876.23851.exe.7a90000.8.raw.unpack, OyoJ5qrk9TMoyInOpOI.csHigh entropy of concatenated method names: 'CanConvertFrom', 'ConvertFrom', 'ConvertTo', 'eOuqcWIdd2', 'M6OqaUpIyw', 'gW2q7KaoRt', 'Ygkqh7OiCY', 'A3Iqt69qqI', 'FHEqPoCqF7', 'fBVqSGWpKj'
            Source: 0.2.SecuriteInfo.com.Win32.SpywareX-gen.21876.23851.exe.7a90000.8.raw.unpack, gHNKGQTwPXojjZtPg1.csHigh entropy of concatenated method names: 'iVPGDq6Ho4', 'WsyGwrFVO6', 'seMGK8o6y7', 'x0XGTrhy82', 'qChGF1HbYd', 'R3sGg9gE16', 'iyjGsaGrky', 'dZJGJ8TDX6', 'EFOG2PFJwx', 'ociGq5dQV5'
            Source: 0.2.SecuriteInfo.com.Win32.SpywareX-gen.21876.23851.exe.7a90000.8.raw.unpack, PeRObGEbsmxBxW0AqV.csHigh entropy of concatenated method names: 'OyNN1hCBL7', 'oCtNGF2Rsj', 'E2nNVJ1C5R', 'xuNVfQaP1J', 'UAqVzy0JNT', 'AImNkodmDF', 'Id6NrHa1El', 'vMjN6VjuI5', 'rsMNBAe4fK', 'dD3NxisHBu'
            Source: 0.2.SecuriteInfo.com.Win32.SpywareX-gen.21876.23851.exe.7a90000.8.raw.unpack, boxq7on20nxSOc1pYB.csHigh entropy of concatenated method names: 'H3CsZrRSMF', 'VCxsfQpu9q', 'qs2JkArA25', 'vA0Jrv1Zfy', 'y4FscRI5jE', 'aiKsah08gf', 'b5ss7wCspt', 'Djrshn4TLU', 'lcystgJCaq', 'rOisPISEp9'
            Source: 0.2.SecuriteInfo.com.Win32.SpywareX-gen.21876.23851.exe.7a90000.8.raw.unpack, KRNngrUKXnqM1Klq8d.csHigh entropy of concatenated method names: 'ISKNsxDoCT', 'ac7N2mgoRl', 'CBDNgK5fav', 'rRWykrMJPYhfE8satsL', 'FMLjQoMy0JdH9im2peK', 'dEXOhoMFvwr1TcUqkry'
            Source: 0.2.SecuriteInfo.com.Win32.SpywareX-gen.21876.23851.exe.7a90000.8.raw.unpack, xjuciJKCOIPdtRI75L.csHigh entropy of concatenated method names: 'MIJjhEMlKS', 'q7JjtkhU2H', 'z1sjPVLVwm', 'wMbjScV40B', 'CydjRdZaEv', 'psJjnVSTAS', 'KLwjCorqUj', 'HAyjZ44REx', 'PONjiVZ4AM', 'NMPjfAQhiJ'
            Source: 0.2.SecuriteInfo.com.Win32.SpywareX-gen.21876.23851.exe.7a90000.8.raw.unpack, AK3Fh9AHBPMI9DMtJn.csHigh entropy of concatenated method names: 'Cgw5yG8Cx1', 'fAb5Ix9UGQ', 'g0sGLiOB4k', 'HksG0S5e8C', 'cjsG3Sjs6m', 'wZUGO1br3M', 'VxGGEr3edb', 'tfLGUuBq2c', 'V1oGQfidFf', 'z2tGXCF21p'
            Source: 0.2.SecuriteInfo.com.Win32.SpywareX-gen.21876.23851.exe.7a90000.8.raw.unpack, RJaaji63qW95FhffxD.csHigh entropy of concatenated method names: 'UtfYCr8Jg', 'NmXDCDgSl', 'xQ8wsEZZG', 'XXCIdZh8l', 'uBMTBtUjl', 'uScA09hCe', 'JjVgk2P0gqd9OpBDvg', 'XmhkRtKjHEa5suBvZ8', 'h7gJnQ2at', 'XaNqPEXWp'
            Source: 0.2.SecuriteInfo.com.Win32.SpywareX-gen.21876.23851.exe.7a90000.8.raw.unpack, RWedmCzgLalRtVO9k4.csHigh entropy of concatenated method names: 'JC1qwAnUkA', 'ILcqKMcmyJ', 'mxYqTuHZUT', 'JFlqu3cr0Q', 'Nt8qe2Xckw', 'OgBq0VwgLm', 'fhGq3j9lOw', 'beCqHdMT0h', 'ajyqmmcjgC', 'DjGqM4K5wj'
            Source: 0.2.SecuriteInfo.com.Win32.SpywareX-gen.21876.23851.exe.7a90000.8.raw.unpack, OtiHIKxaCIp5HFqLh8.csHigh entropy of concatenated method names: 'hwHrNjuciJ', 'VOIr9PdtRI', 'MwPr8XojjZ', 'RPgrl1yK3F', 'AMtrFJntoc', 'VB2rg6C8dI', 'EuPjhV7P38V1pB5C9S', 'BvgqOuvOAmwReNjbu0', 'xxarrJmvnM', 'dH8rBYVCZl'
            Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.SpywareX-gen.21876.23851.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
            Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.SpywareX-gen.21876.23851.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
            Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.SpywareX-gen.21876.23851.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
            Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.SpywareX-gen.21876.23851.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
            Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.SpywareX-gen.21876.23851.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
            Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.SpywareX-gen.21876.23851.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
            Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.SpywareX-gen.21876.23851.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
            Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.SpywareX-gen.21876.23851.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
            Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.SpywareX-gen.21876.23851.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
            Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.SpywareX-gen.21876.23851.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
            Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.SpywareX-gen.21876.23851.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
            Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.SpywareX-gen.21876.23851.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
            Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.SpywareX-gen.21876.23851.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
            Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.SpywareX-gen.21876.23851.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
            Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.SpywareX-gen.21876.23851.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
            Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.SpywareX-gen.21876.23851.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
            Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.SpywareX-gen.21876.23851.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
            Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.SpywareX-gen.21876.23851.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
            Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.SpywareX-gen.21876.23851.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
            Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.SpywareX-gen.21876.23851.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
            Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.SpywareX-gen.21876.23851.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
            Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.SpywareX-gen.21876.23851.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
            Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.SpywareX-gen.21876.23851.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
            Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.SpywareX-gen.21876.23851.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
            Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.SpywareX-gen.21876.23851.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
            Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.SpywareX-gen.21876.23851.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
            Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.SpywareX-gen.21876.23851.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
            Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.SpywareX-gen.21876.23851.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
            Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.SpywareX-gen.21876.23851.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
            Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.SpywareX-gen.21876.23851.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
            Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.SpywareX-gen.21876.23851.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
            Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.SpywareX-gen.21876.23851.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
            Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.SpywareX-gen.21876.23851.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
            Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.SpywareX-gen.21876.23851.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
            Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.SpywareX-gen.21876.23851.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
            Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.SpywareX-gen.21876.23851.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
            Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.SpywareX-gen.21876.23851.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
            Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.SpywareX-gen.21876.23851.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
            Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.SpywareX-gen.21876.23851.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
            Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.SpywareX-gen.21876.23851.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
            Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.SpywareX-gen.21876.23851.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
            Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.SpywareX-gen.21876.23851.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
            Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.SpywareX-gen.21876.23851.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
            Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.SpywareX-gen.21876.23851.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
            Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.SpywareX-gen.21876.23851.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
            Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.SpywareX-gen.21876.23851.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
            Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.SpywareX-gen.21876.23851.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
            Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.SpywareX-gen.21876.23851.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
            Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.SpywareX-gen.21876.23851.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
            Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.SpywareX-gen.21876.23851.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
            Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.SpywareX-gen.21876.23851.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
            Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.SpywareX-gen.21876.23851.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
            Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.SpywareX-gen.21876.23851.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
            Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.SpywareX-gen.21876.23851.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
            Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.SpywareX-gen.21876.23851.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
            Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.SpywareX-gen.21876.23851.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
            Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.SpywareX-gen.21876.23851.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
            Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.SpywareX-gen.21876.23851.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
            Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.SpywareX-gen.21876.23851.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
            Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.SpywareX-gen.21876.23851.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
            Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.SpywareX-gen.21876.23851.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
            Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.SpywareX-gen.21876.23851.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
            Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.SpywareX-gen.21876.23851.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
            Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.SpywareX-gen.21876.23851.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
            Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.SpywareX-gen.21876.23851.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
            Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.SpywareX-gen.21876.23851.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
            Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.SpywareX-gen.21876.23851.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
            Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.SpywareX-gen.21876.23851.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
            Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.SpywareX-gen.21876.23851.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
            Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.SpywareX-gen.21876.23851.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
            Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.SpywareX-gen.21876.23851.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
            Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.SpywareX-gen.21876.23851.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
            Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.SpywareX-gen.21876.23851.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
            Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.SpywareX-gen.21876.23851.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
            Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.SpywareX-gen.21876.23851.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
            Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.SpywareX-gen.21876.23851.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
            Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.SpywareX-gen.21876.23851.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
            Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.SpywareX-gen.21876.23851.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
            Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.SpywareX-gen.21876.23851.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
            Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.SpywareX-gen.21876.23851.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
            Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.SpywareX-gen.21876.23851.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
            Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.SpywareX-gen.21876.23851.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
            Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.SpywareX-gen.21876.23851.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
            Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.SpywareX-gen.21876.23851.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
            Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.SpywareX-gen.21876.23851.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
            Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.SpywareX-gen.21876.23851.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
            Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.SpywareX-gen.21876.23851.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
            Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.SpywareX-gen.21876.23851.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
            Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.SpywareX-gen.21876.23851.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
            Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.SpywareX-gen.21876.23851.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
            Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.SpywareX-gen.21876.23851.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
            Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.SpywareX-gen.21876.23851.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
            Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.SpywareX-gen.21876.23851.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
            Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.SpywareX-gen.21876.23851.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
            Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.SpywareX-gen.21876.23851.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
            Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.SpywareX-gen.21876.23851.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
            Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.SpywareX-gen.21876.23851.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
            Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.SpywareX-gen.21876.23851.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
            Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.SpywareX-gen.21876.23851.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
            Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.SpywareX-gen.21876.23851.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
            Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.SpywareX-gen.21876.23851.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
            Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.SpywareX-gen.21876.23851.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
            Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.SpywareX-gen.21876.23851.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
            Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.SpywareX-gen.21876.23851.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
            Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.SpywareX-gen.21876.23851.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
            Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.SpywareX-gen.21876.23851.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
            Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.SpywareX-gen.21876.23851.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
            Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.SpywareX-gen.21876.23851.exeProcess information set: NOOPENFILEERRORBOXJump to behavior

            Malware Analysis System Evasion

            barindex
            Source: Yara matchFile source: Process Memory Space: SecuriteInfo.com.Win32.SpywareX-gen.21876.23851.exe PID: 7784, type: MEMORYSTR
            Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.SpywareX-gen.21876.23851.exeMemory allocated: 810000 memory reserve | memory write watchJump to behavior
            Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.SpywareX-gen.21876.23851.exeMemory allocated: 2650000 memory reserve | memory write watchJump to behavior
            Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.SpywareX-gen.21876.23851.exeMemory allocated: 2450000 memory reserve | memory write watchJump to behavior
            Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.SpywareX-gen.21876.23851.exeMemory allocated: 7C40000 memory reserve | memory write watchJump to behavior
            Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.SpywareX-gen.21876.23851.exeMemory allocated: 8C40000 memory reserve | memory write watchJump to behavior
            Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.SpywareX-gen.21876.23851.exeMemory allocated: 8E10000 memory reserve | memory write watchJump to behavior
            Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.SpywareX-gen.21876.23851.exeMemory allocated: 9E10000 memory reserve | memory write watchJump to behavior
            Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.SpywareX-gen.21876.23851.exeMemory allocated: 1290000 memory reserve | memory write watchJump to behavior
            Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.SpywareX-gen.21876.23851.exeMemory allocated: 2E50000 memory reserve | memory write watchJump to behavior
            Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.SpywareX-gen.21876.23851.exeMemory allocated: 2C50000 memory reserve | memory write watchJump to behavior
            Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.SpywareX-gen.21876.23851.exeThread delayed: delay time: 922337203685477Jump to behavior
            Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.SpywareX-gen.21876.23851.exeThread delayed: delay time: 922337203685477Jump to behavior
            Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.SpywareX-gen.21876.23851.exeThread delayed: delay time: 600000Jump to behavior
            Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.SpywareX-gen.21876.23851.exeThread delayed: delay time: 599891Jump to behavior
            Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.SpywareX-gen.21876.23851.exeThread delayed: delay time: 599781Jump to behavior
            Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.SpywareX-gen.21876.23851.exeThread delayed: delay time: 599672Jump to behavior
            Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.SpywareX-gen.21876.23851.exeThread delayed: delay time: 599563Jump to behavior
            Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.SpywareX-gen.21876.23851.exeThread delayed: delay time: 599438Jump to behavior
            Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.SpywareX-gen.21876.23851.exeThread delayed: delay time: 599313Jump to behavior
            Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.SpywareX-gen.21876.23851.exeThread delayed: delay time: 599203Jump to behavior
            Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.SpywareX-gen.21876.23851.exeThread delayed: delay time: 599094Jump to behavior
            Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.SpywareX-gen.21876.23851.exeThread delayed: delay time: 598969Jump to behavior
            Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.SpywareX-gen.21876.23851.exeThread delayed: delay time: 598859Jump to behavior
            Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.SpywareX-gen.21876.23851.exeThread delayed: delay time: 598750Jump to behavior
            Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.SpywareX-gen.21876.23851.exeThread delayed: delay time: 598641Jump to behavior
            Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.SpywareX-gen.21876.23851.exeThread delayed: delay time: 598531Jump to behavior
            Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.SpywareX-gen.21876.23851.exeThread delayed: delay time: 598422Jump to behavior
            Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.SpywareX-gen.21876.23851.exeThread delayed: delay time: 598313Jump to behavior
            Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.SpywareX-gen.21876.23851.exeThread delayed: delay time: 598188Jump to behavior
            Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.SpywareX-gen.21876.23851.exeThread delayed: delay time: 598078Jump to behavior
            Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.SpywareX-gen.21876.23851.exeThread delayed: delay time: 597969Jump to behavior
            Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.SpywareX-gen.21876.23851.exeThread delayed: delay time: 597844Jump to behavior
            Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.SpywareX-gen.21876.23851.exeThread delayed: delay time: 597735Jump to behavior
            Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.SpywareX-gen.21876.23851.exeThread delayed: delay time: 597610Jump to behavior
            Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.SpywareX-gen.21876.23851.exeThread delayed: delay time: 597485Jump to behavior
            Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.SpywareX-gen.21876.23851.exeThread delayed: delay time: 597360Jump to behavior
            Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.SpywareX-gen.21876.23851.exeThread delayed: delay time: 597235Jump to behavior
            Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.SpywareX-gen.21876.23851.exeThread delayed: delay time: 597110Jump to behavior
            Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.SpywareX-gen.21876.23851.exeThread delayed: delay time: 596985Jump to behavior
            Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.SpywareX-gen.21876.23851.exeThread delayed: delay time: 596860Jump to behavior
            Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.SpywareX-gen.21876.23851.exeThread delayed: delay time: 596735Jump to behavior
            Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.SpywareX-gen.21876.23851.exeThread delayed: delay time: 596610Jump to behavior
            Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.SpywareX-gen.21876.23851.exeThread delayed: delay time: 596485Jump to behavior
            Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.SpywareX-gen.21876.23851.exeThread delayed: delay time: 596360Jump to behavior
            Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.SpywareX-gen.21876.23851.exeThread delayed: delay time: 596235Jump to behavior
            Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.SpywareX-gen.21876.23851.exeThread delayed: delay time: 596110Jump to behavior
            Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.SpywareX-gen.21876.23851.exeThread delayed: delay time: 595985Jump to behavior
            Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.SpywareX-gen.21876.23851.exeThread delayed: delay time: 595860Jump to behavior
            Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.SpywareX-gen.21876.23851.exeThread delayed: delay time: 595735Jump to behavior
            Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.SpywareX-gen.21876.23851.exeThread delayed: delay time: 595610Jump to behavior
            Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.SpywareX-gen.21876.23851.exeThread delayed: delay time: 595485Jump to behavior
            Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.SpywareX-gen.21876.23851.exeThread delayed: delay time: 595360Jump to behavior
            Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.SpywareX-gen.21876.23851.exeThread delayed: delay time: 595235Jump to behavior
            Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.SpywareX-gen.21876.23851.exeThread delayed: delay time: 595110Jump to behavior
            Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.SpywareX-gen.21876.23851.exeThread delayed: delay time: 594985Jump to behavior
            Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.SpywareX-gen.21876.23851.exeThread delayed: delay time: 594860Jump to behavior
            Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.SpywareX-gen.21876.23851.exeThread delayed: delay time: 594735Jump to behavior
            Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.SpywareX-gen.21876.23851.exeThread delayed: delay time: 594610Jump to behavior
            Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.SpywareX-gen.21876.23851.exeThread delayed: delay time: 594485Jump to behavior
            Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.SpywareX-gen.21876.23851.exeThread delayed: delay time: 594360Jump to behavior
            Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.SpywareX-gen.21876.23851.exeThread delayed: delay time: 594235Jump to behavior
            Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.SpywareX-gen.21876.23851.exeThread delayed: delay time: 594110Jump to behavior
            Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.SpywareX-gen.21876.23851.exeWindow / User API: threadDelayed 7987Jump to behavior
            Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.SpywareX-gen.21876.23851.exeWindow / User API: threadDelayed 1841Jump to behavior
            Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.SpywareX-gen.21876.23851.exe TID: 7788Thread sleep time: -30000s >= -30000sJump to behavior
            Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.SpywareX-gen.21876.23851.exe TID: 7804Thread sleep time: -922337203685477s >= -30000sJump to behavior
            Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.SpywareX-gen.21876.23851.exe TID: 7936Thread sleep time: -24903104499507879s >= -30000sJump to behavior
            Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.SpywareX-gen.21876.23851.exe TID: 7936Thread sleep time: -600000s >= -30000sJump to behavior
            Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.SpywareX-gen.21876.23851.exe TID: 7936Thread sleep time: -599891s >= -30000sJump to behavior
            Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.SpywareX-gen.21876.23851.exe TID: 7940Thread sleep count: 7987 > 30Jump to behavior
            Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.SpywareX-gen.21876.23851.exe TID: 7936Thread sleep time: -599781s >= -30000sJump to behavior
            Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.SpywareX-gen.21876.23851.exe TID: 7936Thread sleep time: -599672s >= -30000sJump to behavior
            Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.SpywareX-gen.21876.23851.exe TID: 7940Thread sleep count: 1841 > 30Jump to behavior
            Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.SpywareX-gen.21876.23851.exe TID: 7936Thread sleep time: -599563s >= -30000sJump to behavior
            Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.SpywareX-gen.21876.23851.exe TID: 7936Thread sleep count: 32 > 30Jump to behavior
            Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.SpywareX-gen.21876.23851.exe TID: 7936Thread sleep time: -599438s >= -30000sJump to behavior
            Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.SpywareX-gen.21876.23851.exe TID: 7936Thread sleep time: -599313s >= -30000sJump to behavior
            Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.SpywareX-gen.21876.23851.exe TID: 7936Thread sleep time: -599203s >= -30000sJump to behavior
            Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.SpywareX-gen.21876.23851.exe TID: 7936Thread sleep time: -599094s >= -30000sJump to behavior
            Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.SpywareX-gen.21876.23851.exe TID: 7936Thread sleep time: -598969s >= -30000sJump to behavior
            Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.SpywareX-gen.21876.23851.exe TID: 7936Thread sleep time: -598859s >= -30000sJump to behavior
            Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.SpywareX-gen.21876.23851.exe TID: 7936Thread sleep time: -598750s >= -30000sJump to behavior
            Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.SpywareX-gen.21876.23851.exe TID: 7936Thread sleep time: -598641s >= -30000sJump to behavior
            Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.SpywareX-gen.21876.23851.exe TID: 7936Thread sleep time: -598531s >= -30000sJump to behavior
            Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.SpywareX-gen.21876.23851.exe TID: 7936Thread sleep time: -598422s >= -30000sJump to behavior
            Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.SpywareX-gen.21876.23851.exe TID: 7936Thread sleep time: -598313s >= -30000sJump to behavior
            Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.SpywareX-gen.21876.23851.exe TID: 7936Thread sleep time: -598188s >= -30000sJump to behavior
            Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.SpywareX-gen.21876.23851.exe TID: 7936Thread sleep time: -598078s >= -30000sJump to behavior
            Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.SpywareX-gen.21876.23851.exe TID: 7936Thread sleep time: -597969s >= -30000sJump to behavior
            Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.SpywareX-gen.21876.23851.exe TID: 7936Thread sleep time: -597844s >= -30000sJump to behavior
            Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.SpywareX-gen.21876.23851.exe TID: 7936Thread sleep time: -597735s >= -30000sJump to behavior
            Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.SpywareX-gen.21876.23851.exe TID: 7936Thread sleep time: -597610s >= -30000sJump to behavior
            Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.SpywareX-gen.21876.23851.exe TID: 7936Thread sleep time: -597485s >= -30000sJump to behavior
            Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.SpywareX-gen.21876.23851.exe TID: 7936Thread sleep time: -597360s >= -30000sJump to behavior
            Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.SpywareX-gen.21876.23851.exe TID: 7936Thread sleep time: -597235s >= -30000sJump to behavior
            Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.SpywareX-gen.21876.23851.exe TID: 7936Thread sleep time: -597110s >= -30000sJump to behavior
            Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.SpywareX-gen.21876.23851.exe TID: 7936Thread sleep time: -596985s >= -30000sJump to behavior
            Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.SpywareX-gen.21876.23851.exe TID: 7936Thread sleep time: -596860s >= -30000sJump to behavior
            Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.SpywareX-gen.21876.23851.exe TID: 7936Thread sleep time: -596735s >= -30000sJump to behavior
            Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.SpywareX-gen.21876.23851.exe TID: 7936Thread sleep time: -596610s >= -30000sJump to behavior
            Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.SpywareX-gen.21876.23851.exe TID: 7936Thread sleep time: -596485s >= -30000sJump to behavior
            Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.SpywareX-gen.21876.23851.exe TID: 7936Thread sleep time: -596360s >= -30000sJump to behavior
            Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.SpywareX-gen.21876.23851.exe TID: 7936Thread sleep time: -596235s >= -30000sJump to behavior
            Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.SpywareX-gen.21876.23851.exe TID: 7936Thread sleep time: -596110s >= -30000sJump to behavior
            Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.SpywareX-gen.21876.23851.exe TID: 7936Thread sleep time: -595985s >= -30000sJump to behavior
            Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.SpywareX-gen.21876.23851.exe TID: 7936Thread sleep time: -595860s >= -30000sJump to behavior
            Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.SpywareX-gen.21876.23851.exe TID: 7936Thread sleep time: -595735s >= -30000sJump to behavior
            Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.SpywareX-gen.21876.23851.exe TID: 7936Thread sleep time: -595610s >= -30000sJump to behavior
            Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.SpywareX-gen.21876.23851.exe TID: 7936Thread sleep time: -595485s >= -30000sJump to behavior
            Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.SpywareX-gen.21876.23851.exe TID: 7936Thread sleep time: -595360s >= -30000sJump to behavior
            Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.SpywareX-gen.21876.23851.exe TID: 7936Thread sleep time: -595235s >= -30000sJump to behavior
            Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.SpywareX-gen.21876.23851.exe TID: 7936Thread sleep time: -595110s >= -30000sJump to behavior
            Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.SpywareX-gen.21876.23851.exe TID: 7936Thread sleep time: -594985s >= -30000sJump to behavior
            Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.SpywareX-gen.21876.23851.exe TID: 7936Thread sleep time: -594860s >= -30000sJump to behavior
            Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.SpywareX-gen.21876.23851.exe TID: 7936Thread sleep time: -594735s >= -30000sJump to behavior
            Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.SpywareX-gen.21876.23851.exe TID: 7936Thread sleep time: -594610s >= -30000sJump to behavior
            Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.SpywareX-gen.21876.23851.exe TID: 7936Thread sleep time: -594485s >= -30000sJump to behavior
            Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.SpywareX-gen.21876.23851.exe TID: 7936Thread sleep time: -594360s >= -30000sJump to behavior
            Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.SpywareX-gen.21876.23851.exe TID: 7936Thread sleep time: -594235s >= -30000sJump to behavior
            Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.SpywareX-gen.21876.23851.exe TID: 7936Thread sleep time: -594110s >= -30000sJump to behavior
            Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.SpywareX-gen.21876.23851.exeThread delayed: delay time: 30000Jump to behavior
            Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.SpywareX-gen.21876.23851.exeThread delayed: delay time: 922337203685477Jump to behavior
            Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.SpywareX-gen.21876.23851.exeThread delayed: delay time: 922337203685477Jump to behavior
            Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.SpywareX-gen.21876.23851.exeThread delayed: delay time: 600000Jump to behavior
            Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.SpywareX-gen.21876.23851.exeThread delayed: delay time: 599891Jump to behavior
            Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.SpywareX-gen.21876.23851.exeThread delayed: delay time: 599781Jump to behavior
            Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.SpywareX-gen.21876.23851.exeThread delayed: delay time: 599672Jump to behavior
            Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.SpywareX-gen.21876.23851.exeThread delayed: delay time: 599563Jump to behavior
            Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.SpywareX-gen.21876.23851.exeThread delayed: delay time: 599438Jump to behavior
            Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.SpywareX-gen.21876.23851.exeThread delayed: delay time: 599313Jump to behavior
            Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.SpywareX-gen.21876.23851.exeThread delayed: delay time: 599203Jump to behavior
            Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.SpywareX-gen.21876.23851.exeThread delayed: delay time: 599094Jump to behavior
            Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.SpywareX-gen.21876.23851.exeThread delayed: delay time: 598969Jump to behavior
            Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.SpywareX-gen.21876.23851.exeThread delayed: delay time: 598859Jump to behavior
            Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.SpywareX-gen.21876.23851.exeThread delayed: delay time: 598750Jump to behavior
            Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.SpywareX-gen.21876.23851.exeThread delayed: delay time: 598641Jump to behavior
            Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.SpywareX-gen.21876.23851.exeThread delayed: delay time: 598531Jump to behavior
            Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.SpywareX-gen.21876.23851.exeThread delayed: delay time: 598422Jump to behavior
            Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.SpywareX-gen.21876.23851.exeThread delayed: delay time: 598313Jump to behavior
            Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.SpywareX-gen.21876.23851.exeThread delayed: delay time: 598188Jump to behavior
            Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.SpywareX-gen.21876.23851.exeThread delayed: delay time: 598078Jump to behavior
            Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.SpywareX-gen.21876.23851.exeThread delayed: delay time: 597969Jump to behavior
            Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.SpywareX-gen.21876.23851.exeThread delayed: delay time: 597844Jump to behavior
            Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.SpywareX-gen.21876.23851.exeThread delayed: delay time: 597735Jump to behavior
            Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.SpywareX-gen.21876.23851.exeThread delayed: delay time: 597610Jump to behavior
            Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.SpywareX-gen.21876.23851.exeThread delayed: delay time: 597485Jump to behavior
            Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.SpywareX-gen.21876.23851.exeThread delayed: delay time: 597360Jump to behavior
            Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.SpywareX-gen.21876.23851.exeThread delayed: delay time: 597235Jump to behavior
            Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.SpywareX-gen.21876.23851.exeThread delayed: delay time: 597110Jump to behavior
            Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.SpywareX-gen.21876.23851.exeThread delayed: delay time: 596985Jump to behavior
            Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.SpywareX-gen.21876.23851.exeThread delayed: delay time: 596860Jump to behavior
            Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.SpywareX-gen.21876.23851.exeThread delayed: delay time: 596735Jump to behavior
            Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.SpywareX-gen.21876.23851.exeThread delayed: delay time: 596610Jump to behavior
            Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.SpywareX-gen.21876.23851.exeThread delayed: delay time: 596485Jump to behavior
            Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.SpywareX-gen.21876.23851.exeThread delayed: delay time: 596360Jump to behavior
            Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.SpywareX-gen.21876.23851.exeThread delayed: delay time: 596235Jump to behavior
            Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.SpywareX-gen.21876.23851.exeThread delayed: delay time: 596110Jump to behavior
            Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.SpywareX-gen.21876.23851.exeThread delayed: delay time: 595985Jump to behavior
            Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.SpywareX-gen.21876.23851.exeThread delayed: delay time: 595860Jump to behavior
            Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.SpywareX-gen.21876.23851.exeThread delayed: delay time: 595735Jump to behavior
            Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.SpywareX-gen.21876.23851.exeThread delayed: delay time: 595610Jump to behavior
            Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.SpywareX-gen.21876.23851.exeThread delayed: delay time: 595485Jump to behavior
            Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.SpywareX-gen.21876.23851.exeThread delayed: delay time: 595360Jump to behavior
            Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.SpywareX-gen.21876.23851.exeThread delayed: delay time: 595235Jump to behavior
            Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.SpywareX-gen.21876.23851.exeThread delayed: delay time: 595110Jump to behavior
            Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.SpywareX-gen.21876.23851.exeThread delayed: delay time: 594985Jump to behavior
            Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.SpywareX-gen.21876.23851.exeThread delayed: delay time: 594860Jump to behavior
            Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.SpywareX-gen.21876.23851.exeThread delayed: delay time: 594735Jump to behavior
            Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.SpywareX-gen.21876.23851.exeThread delayed: delay time: 594610Jump to behavior
            Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.SpywareX-gen.21876.23851.exeThread delayed: delay time: 594485Jump to behavior
            Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.SpywareX-gen.21876.23851.exeThread delayed: delay time: 594360Jump to behavior
            Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.SpywareX-gen.21876.23851.exeThread delayed: delay time: 594235Jump to behavior
            Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.SpywareX-gen.21876.23851.exeThread delayed: delay time: 594110Jump to behavior
            Source: SecuriteInfo.com.Win32.SpywareX-gen.21876.23851.exe, 00000001.00000002.3600754548.0000000001116000.00000004.00000020.00020000.00000000.sdmpBinary or memory string: Hyper-V RAW%SystemRoot%\system32\mswsock.dll.
            Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.SpywareX-gen.21876.23851.exeProcess information queried: ProcessInformationJump to behavior
            Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.SpywareX-gen.21876.23851.exeProcess token adjusted: DebugJump to behavior
            Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.SpywareX-gen.21876.23851.exeMemory allocated: page read and write | page guardJump to behavior
            Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.SpywareX-gen.21876.23851.exeProcess created: C:\Users\user\Desktop\SecuriteInfo.com.Win32.SpywareX-gen.21876.23851.exe "C:\Users\user\Desktop\SecuriteInfo.com.Win32.SpywareX-gen.21876.23851.exe"Jump to behavior
            Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.SpywareX-gen.21876.23851.exeQueries volume information: C:\Users\user\Desktop\SecuriteInfo.com.Win32.SpywareX-gen.21876.23851.exe VolumeInformationJump to behavior
            Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.SpywareX-gen.21876.23851.exeQueries volume information: C:\Windows\Microsoft.NET\assembly\GAC_MSIL\System.Design\v4.0_4.0.0.0__b03f5f7f11d50a3a\System.Design.dll VolumeInformationJump to behavior
            Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.SpywareX-gen.21876.23851.exeQueries volume information: C:\Windows\Microsoft.NET\assembly\GAC_MSIL\System.Windows.Forms\v4.0_4.0.0.0__b77a5c561934e089\System.Windows.Forms.dll VolumeInformationJump to behavior
            Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.SpywareX-gen.21876.23851.exeQueries volume information: C:\Windows\Microsoft.NET\assembly\GAC_MSIL\System.Drawing\v4.0_4.0.0.0__b03f5f7f11d50a3a\System.Drawing.dll VolumeInformationJump to behavior
            Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.SpywareX-gen.21876.23851.exeQueries volume information: C:\Windows\Microsoft.NET\assembly\GAC_32\System.Data\v4.0_4.0.0.0__b77a5c561934e089\System.Data.dll VolumeInformationJump to behavior
            Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.SpywareX-gen.21876.23851.exeQueries volume information: C:\Windows\Microsoft.NET\assembly\GAC_MSIL\Accessibility\v4.0_4.0.0.0__b03f5f7f11d50a3a\Accessibility.dll VolumeInformationJump to behavior
            Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.SpywareX-gen.21876.23851.exeQueries volume information: C:\Windows\Fonts\bahnschrift.ttf VolumeInformationJump to behavior
            Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.SpywareX-gen.21876.23851.exeQueries volume information: C:\Windows\Fonts\bahnschrift.ttf VolumeInformationJump to behavior
            Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.SpywareX-gen.21876.23851.exeQueries volume information: C:\Windows\Fonts\bahnschrift.ttf VolumeInformationJump to behavior
            Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.SpywareX-gen.21876.23851.exeQueries volume information: C:\Windows\Fonts\bahnschrift.ttf VolumeInformationJump to behavior
            Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.SpywareX-gen.21876.23851.exeQueries volume information: C:\Windows\Fonts\bahnschrift.ttf VolumeInformationJump to behavior
            Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.SpywareX-gen.21876.23851.exeQueries volume information: C:\Windows\Fonts\bahnschrift.ttf VolumeInformationJump to behavior
            Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.SpywareX-gen.21876.23851.exeQueries volume information: C:\Windows\Fonts\bahnschrift.ttf VolumeInformationJump to behavior
            Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.SpywareX-gen.21876.23851.exeQueries volume information: C:\Windows\Fonts\bahnschrift.ttf VolumeInformationJump to behavior
            Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.SpywareX-gen.21876.23851.exeQueries volume information: C:\Windows\Fonts\bahnschrift.ttf VolumeInformationJump to behavior
            Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.SpywareX-gen.21876.23851.exeQueries volume information: C:\Windows\Fonts\calibriz.ttf VolumeInformationJump to behavior
            Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.SpywareX-gen.21876.23851.exeQueries volume information: C:\Windows\Fonts\cambria.ttc VolumeInformationJump to behavior
            Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.SpywareX-gen.21876.23851.exeQueries volume information: C:\Windows\Fonts\cambriai.ttf VolumeInformationJump to behavior
            Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.SpywareX-gen.21876.23851.exeQueries volume information: C:\Windows\Fonts\cambriab.ttf VolumeInformationJump to behavior
            Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.SpywareX-gen.21876.23851.exeQueries volume information: C:\Windows\Fonts\cambriaz.ttf VolumeInformationJump to behavior
            Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.SpywareX-gen.21876.23851.exeQueries volume information: C:\Windows\Fonts\cambria.ttc VolumeInformationJump to behavior
            Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.SpywareX-gen.21876.23851.exeQueries volume information: C:\Windows\Fonts\Candara.ttf VolumeInformationJump to behavior
            Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.SpywareX-gen.21876.23851.exeQueries volume information: C:\Windows\Fonts\Candaral.ttf VolumeInformationJump to behavior
            Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.SpywareX-gen.21876.23851.exeQueries volume information: C:\Windows\Fonts\Candarai.ttf VolumeInformationJump to behavior
            Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.SpywareX-gen.21876.23851.exeQueries volume information: C:\Windows\Fonts\Candarali.ttf VolumeInformationJump to behavior
            Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.SpywareX-gen.21876.23851.exeQueries volume information: C:\Windows\Fonts\Candarab.ttf VolumeInformationJump to behavior
            Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.SpywareX-gen.21876.23851.exeQueries volume information: C:\Windows\Fonts\Candaraz.ttf VolumeInformationJump to behavior
            Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.SpywareX-gen.21876.23851.exeQueries volume information: C:\Windows\Fonts\comic.ttf VolumeInformationJump to behavior
            Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.SpywareX-gen.21876.23851.exeQueries volume information: C:\Windows\Fonts\comici.ttf VolumeInformationJump to behavior
            Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.SpywareX-gen.21876.23851.exeQueries volume information: C:\Windows\Fonts\comicbd.ttf VolumeInformationJump to behavior
            Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.SpywareX-gen.21876.23851.exeQueries volume information: C:\Windows\Fonts\comicz.ttf VolumeInformationJump to behavior
            Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.SpywareX-gen.21876.23851.exeQueries volume information: C:\Windows\Fonts\constan.ttf VolumeInformationJump to behavior
            Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.SpywareX-gen.21876.23851.exeQueries volume information: C:\Windows\Fonts\constani.ttf VolumeInformationJump to behavior
            Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.SpywareX-gen.21876.23851.exeQueries volume information: C:\Windows\Fonts\constanb.ttf VolumeInformationJump to behavior
            Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.SpywareX-gen.21876.23851.exeQueries volume information: C:\Windows\Fonts\constanz.ttf VolumeInformationJump to behavior
            Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.SpywareX-gen.21876.23851.exeQueries volume information: C:\Windows\Fonts\corbel.ttf VolumeInformationJump to behavior
            Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.SpywareX-gen.21876.23851.exeQueries volume information: C:\Windows\Fonts\corbell.ttf VolumeInformationJump to behavior
            Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.SpywareX-gen.21876.23851.exeQueries volume information: C:\Windows\Fonts\corbeli.ttf VolumeInformationJump to behavior
            Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.SpywareX-gen.21876.23851.exeQueries volume information: C:\Windows\Fonts\corbelli.ttf VolumeInformationJump to behavior
            Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.SpywareX-gen.21876.23851.exeQueries volume information: C:\Windows\Fonts\corbelb.ttf VolumeInformationJump to behavior
            Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.SpywareX-gen.21876.23851.exeQueries volume information: C:\Windows\Fonts\corbelz.ttf VolumeInformationJump to behavior
            Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.SpywareX-gen.21876.23851.exeQueries volume information: C:\Windows\Fonts\cour.ttf VolumeInformationJump to behavior
            Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.SpywareX-gen.21876.23851.exeQueries volume information: C:\Windows\Fonts\couri.ttf VolumeInformationJump to behavior
            Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.SpywareX-gen.21876.23851.exeQueries volume information: C:\Windows\Fonts\courbd.ttf VolumeInformationJump to behavior
            Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.SpywareX-gen.21876.23851.exeQueries volume information: C:\Windows\Fonts\courbi.ttf VolumeInformationJump to behavior
            Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.SpywareX-gen.21876.23851.exeQueries volume information: C:\Windows\Fonts\ebrima.ttf VolumeInformationJump to behavior
            Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.SpywareX-gen.21876.23851.exeQueries volume information: C:\Windows\Fonts\ebrimabd.ttf VolumeInformationJump to behavior
            Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.SpywareX-gen.21876.23851.exeQueries volume information: C:\Windows\Fonts\framd.ttf VolumeInformationJump to behavior
            Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.SpywareX-gen.21876.23851.exeQueries volume information: C:\Windows\Fonts\FRADM.TTF VolumeInformationJump to behavior
            Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.SpywareX-gen.21876.23851.exeQueries volume information: C:\Windows\Fonts\framdit.ttf VolumeInformationJump to behavior
            Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.SpywareX-gen.21876.23851.exeQueries volume information: C:\Windows\Fonts\FRADMIT.TTF VolumeInformationJump to behavior
            Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.SpywareX-gen.21876.23851.exeQueries volume information: C:\Windows\Fonts\FRAMDCN.TTF VolumeInformationJump to behavior
            Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.SpywareX-gen.21876.23851.exeQueries volume information: C:\Windows\Fonts\FRADMCN.TTF VolumeInformationJump to behavior
            Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.SpywareX-gen.21876.23851.exeQueries volume information: C:\Windows\Fonts\FRAHV.TTF VolumeInformationJump to behavior
            Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.SpywareX-gen.21876.23851.exeQueries volume information: C:\Windows\Fonts\FRAHVIT.TTF VolumeInformationJump to behavior
            Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.SpywareX-gen.21876.23851.exeQueries volume information: C:\Windows\Fonts\Gabriola.ttf VolumeInformationJump to behavior
            Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.SpywareX-gen.21876.23851.exeQueries volume information: C:\Windows\Fonts\gadugi.ttf VolumeInformationJump to behavior
            Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.SpywareX-gen.21876.23851.exeQueries volume information: C:\Windows\Fonts\gadugib.ttf VolumeInformationJump to behavior
            Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.SpywareX-gen.21876.23851.exeQueries volume information: C:\Windows\Fonts\georgia.ttf VolumeInformationJump to behavior
            Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.SpywareX-gen.21876.23851.exeQueries volume information: C:\Windows\Fonts\georgiai.ttf VolumeInformationJump to behavior
            Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.SpywareX-gen.21876.23851.exeQueries volume information: C:\Windows\Fonts\georgiab.ttf VolumeInformationJump to behavior
            Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.SpywareX-gen.21876.23851.exeQueries volume information: C:\Windows\Fonts\georgiaz.ttf VolumeInformationJump to behavior
            Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.SpywareX-gen.21876.23851.exeQueries volume information: C:\Windows\Fonts\impact.ttf VolumeInformationJump to behavior
            Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.SpywareX-gen.21876.23851.exeQueries volume information: C:\Windows\Fonts\Inkfree.ttf VolumeInformationJump to behavior
            Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.SpywareX-gen.21876.23851.exeQueries volume information: C:\Windows\Fonts\javatext.ttf VolumeInformationJump to behavior
            Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.SpywareX-gen.21876.23851.exeQueries volume information: C:\Windows\Fonts\LeelawUI.ttf VolumeInformationJump to behavior
            Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.SpywareX-gen.21876.23851.exeQueries volume information: C:\Windows\Fonts\LeelUIsl.ttf VolumeInformationJump to behavior
            Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.SpywareX-gen.21876.23851.exeQueries volume information: C:\Windows\Fonts\LeelaUIb.ttf VolumeInformationJump to behavior
            Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.SpywareX-gen.21876.23851.exeQueries volume information: C:\Windows\Fonts\lucon.ttf VolumeInformationJump to behavior
            Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.SpywareX-gen.21876.23851.exeQueries volume information: C:\Windows\Fonts\l_10646.ttf VolumeInformationJump to behavior
            Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.SpywareX-gen.21876.23851.exeQueries volume information: C:\Windows\Fonts\himalaya.ttf VolumeInformationJump to behavior
            Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.SpywareX-gen.21876.23851.exeQueries volume information: C:\Windows\Fonts\msjhl.ttc VolumeInformationJump to behavior
            Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.SpywareX-gen.21876.23851.exeQueries volume information: C:\Windows\Fonts\msjhbd.ttc VolumeInformationJump to behavior
            Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.SpywareX-gen.21876.23851.exeQueries volume information: C:\Windows\Fonts\msjh.ttc VolumeInformationJump to behavior
            Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.SpywareX-gen.21876.23851.exeQueries volume information: C:\Windows\Fonts\msjhbd.ttc VolumeInformationJump to behavior
            Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.SpywareX-gen.21876.23851.exeQueries volume information: C:\Windows\Fonts\ntailu.ttf VolumeInformationJump to behavior
            Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.SpywareX-gen.21876.23851.exeQueries volume information: C:\Windows\Fonts\ntailub.ttf VolumeInformationJump to behavior
            Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.SpywareX-gen.21876.23851.exeQueries volume information: C:\Windows\Fonts\phagspa.ttf VolumeInformationJump to behavior
            Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.SpywareX-gen.21876.23851.exeQueries volume information: C:\Windows\Fonts\phagspab.ttf VolumeInformationJump to behavior
            Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.SpywareX-gen.21876.23851.exeQueries volume information: C:\Windows\Fonts\micross.ttf VolumeInformationJump to behavior
            Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.SpywareX-gen.21876.23851.exeQueries volume information: C:\Windows\Fonts\taile.ttf VolumeInformationJump to behavior
            Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.SpywareX-gen.21876.23851.exeQueries volume information: C:\Windows\Fonts\msyh.ttc VolumeInformationJump to behavior
            Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.SpywareX-gen.21876.23851.exeQueries volume information: C:\Windows\Fonts\msyhbd.ttc VolumeInformationJump to behavior
            Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.SpywareX-gen.21876.23851.exeQueries volume information: C:\Windows\Fonts\msyi.ttf VolumeInformationJump to behavior
            Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.SpywareX-gen.21876.23851.exeQueries volume information: C:\Windows\Fonts\mingliub.ttc VolumeInformationJump to behavior
            Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.SpywareX-gen.21876.23851.exeQueries volume information: C:\Windows\Fonts\mingliub.ttc VolumeInformationJump to behavior
            Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.SpywareX-gen.21876.23851.exeQueries volume information: C:\Windows\Fonts\mingliub.ttc VolumeInformationJump to behavior
            Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.SpywareX-gen.21876.23851.exeQueries volume information: C:\Windows\Fonts\msgothic.ttc VolumeInformationJump to behavior
            Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.SpywareX-gen.21876.23851.exeQueries volume information: C:\Windows\Fonts\msgothic.ttc VolumeInformationJump to behavior
            Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.SpywareX-gen.21876.23851.exeQueries volume information: C:\Windows\Fonts\mvboli.ttf VolumeInformationJump to behavior
            Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.SpywareX-gen.21876.23851.exeQueries volume information: C:\Windows\Fonts\mmrtext.ttf VolumeInformationJump to behavior
            Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.SpywareX-gen.21876.23851.exeQueries volume information: C:\Windows\Fonts\mmrtextb.ttf VolumeInformationJump to behavior
            Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.SpywareX-gen.21876.23851.exeQueries volume information: C:\Windows\Fonts\pala.ttf VolumeInformationJump to behavior
            Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.SpywareX-gen.21876.23851.exeQueries volume information: C:\Windows\Fonts\palai.ttf VolumeInformationJump to behavior
            Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.SpywareX-gen.21876.23851.exeQueries volume information: C:\Windows\Fonts\palab.ttf VolumeInformationJump to behavior
            Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.SpywareX-gen.21876.23851.exeQueries volume information: C:\Windows\Fonts\palabi.ttf VolumeInformationJump to behavior
            Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.SpywareX-gen.21876.23851.exeQueries volume information: C:\Windows\Fonts\segoepr.ttf VolumeInformationJump to behavior
            Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.SpywareX-gen.21876.23851.exeQueries volume information: C:\Windows\Fonts\segoeprb.ttf VolumeInformationJump to behavior
            Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.SpywareX-gen.21876.23851.exeQueries volume information: C:\Windows\Fonts\segoesc.ttf VolumeInformationJump to behavior
            Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.SpywareX-gen.21876.23851.exeQueries volume information: C:\Windows\Fonts\segoescb.ttf VolumeInformationJump to behavior
            Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.SpywareX-gen.21876.23851.exeQueries volume information: C:\Windows\Fonts\seguihis.ttf VolumeInformationJump to behavior
            Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.SpywareX-gen.21876.23851.exeQueries volume information: C:\Windows\Fonts\simsun.ttc VolumeInformationJump to behavior
            Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.SpywareX-gen.21876.23851.exeQueries volume information: C:\Windows\Fonts\simsunb.ttf VolumeInformationJump to behavior
            Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.SpywareX-gen.21876.23851.exeQueries volume information: C:\Windows\Fonts\Sitka.ttc VolumeInformationJump to behavior
            Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.SpywareX-gen.21876.23851.exeQueries volume information: C:\Windows\Fonts\SitkaI.ttc VolumeInformationJump to behavior
            Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.SpywareX-gen.21876.23851.exeQueries volume information: C:\Windows\Fonts\SitkaB.ttc VolumeInformationJump to behavior
            Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.SpywareX-gen.21876.23851.exeQueries volume information: C:\Windows\Fonts\SitkaZ.ttc VolumeInformationJump to behavior
            Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.SpywareX-gen.21876.23851.exeQueries volume information: C:\Windows\Fonts\Sitka.ttc VolumeInformationJump to behavior
            Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.SpywareX-gen.21876.23851.exeQueries volume information: C:\Windows\Fonts\SitkaI.ttc VolumeInformationJump to behavior
            Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.SpywareX-gen.21876.23851.exeQueries volume information: C:\Windows\Fonts\SitkaB.ttc VolumeInformationJump to behavior
            Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.SpywareX-gen.21876.23851.exeQueries volume information: C:\Windows\Fonts\SitkaZ.ttc VolumeInformationJump to behavior
            Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.SpywareX-gen.21876.23851.exeQueries volume information: C:\Windows\Fonts\Sitka.ttc VolumeInformationJump to behavior
            Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.SpywareX-gen.21876.23851.exeQueries volume information: C:\Windows\Fonts\SitkaI.ttc VolumeInformationJump to behavior
            Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.SpywareX-gen.21876.23851.exeQueries volume information: C:\Windows\Fonts\SitkaB.ttc VolumeInformationJump to behavior
            Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.SpywareX-gen.21876.23851.exeQueries volume information: C:\Windows\Fonts\SitkaZ.ttc VolumeInformationJump to behavior
            Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.SpywareX-gen.21876.23851.exeQueries volume information: C:\Windows\Fonts\Sitka.ttc VolumeInformationJump to behavior
            Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.SpywareX-gen.21876.23851.exeQueries volume information: C:\Windows\Fonts\SitkaI.ttc VolumeInformationJump to behavior
            Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.SpywareX-gen.21876.23851.exeQueries volume information: C:\Windows\Fonts\SitkaZ.ttc VolumeInformationJump to behavior
            Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.SpywareX-gen.21876.23851.exeQueries volume information: C:\Windows\Fonts\Sitka.ttc VolumeInformationJump to behavior
            Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.SpywareX-gen.21876.23851.exeQueries volume information: C:\Windows\Fonts\sylfaen.ttf VolumeInformationJump to behavior
            Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.SpywareX-gen.21876.23851.exeQueries volume information: C:\Windows\Fonts\symbol.ttf VolumeInformationJump to behavior
            Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.SpywareX-gen.21876.23851.exeQueries volume information: C:\Windows\Fonts\trebuc.ttf VolumeInformationJump to behavior
            Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.SpywareX-gen.21876.23851.exeQueries volume information: C:\Windows\Fonts\trebucit.ttf VolumeInformationJump to behavior
            Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.SpywareX-gen.21876.23851.exeQueries volume information: C:\Windows\Fonts\trebucbd.ttf VolumeInformationJump to behavior
            Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.SpywareX-gen.21876.23851.exeQueries volume information: C:\Windows\Fonts\trebucbi.ttf VolumeInformationJump to behavior
            Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.SpywareX-gen.21876.23851.exeQueries volume information: C:\Windows\Fonts\verdana.ttf VolumeInformationJump to behavior
            Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.SpywareX-gen.21876.23851.exeQueries volume information: C:\Windows\Fonts\verdanai.ttf VolumeInformationJump to behavior
            Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.SpywareX-gen.21876.23851.exeQueries volume information: C:\Windows\Fonts\verdanaz.ttf VolumeInformationJump to behavior
            Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.SpywareX-gen.21876.23851.exeQueries volume information: C:\Windows\Fonts\webdings.ttf VolumeInformationJump to behavior
            Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.SpywareX-gen.21876.23851.exeQueries volume information: C:\Windows\Fonts\wingding.ttf VolumeInformationJump to behavior
            Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.SpywareX-gen.21876.23851.exeQueries volume information: C:\Windows\Fonts\YuGothM.ttc VolumeInformationJump to behavior
            Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.SpywareX-gen.21876.23851.exeQueries volume information: C:\Windows\Fonts\YuGothL.ttc VolumeInformationJump to behavior
            Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.SpywareX-gen.21876.23851.exeQueries volume information: C:\Windows\Fonts\YuGothB.ttc VolumeInformationJump to behavior
            Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.SpywareX-gen.21876.23851.exeQueries volume information: C:\Windows\Fonts\YuGothM.ttc VolumeInformationJump to behavior
            Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.SpywareX-gen.21876.23851.exeQueries volume information: C:\Windows\Fonts\YuGothR.ttc VolumeInformationJump to behavior
            Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.SpywareX-gen.21876.23851.exeQueries volume information: C:\Windows\Fonts\YuGothL.ttc VolumeInformationJump to behavior
            Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.SpywareX-gen.21876.23851.exeQueries volume information: C:\Windows\Fonts\YuGothB.ttc VolumeInformationJump to behavior
            Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.SpywareX-gen.21876.23851.exeQueries volume information: C:\Windows\Fonts\holomdl2.ttf VolumeInformationJump to behavior
            Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.SpywareX-gen.21876.23851.exeQueries volume information: C:\Windows\Fonts\AGENCYR.TTF VolumeInformationJump to behavior
            Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.SpywareX-gen.21876.23851.exeQueries volume information: C:\Windows\Fonts\AGENCYB.TTF VolumeInformationJump to behavior
            Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.SpywareX-gen.21876.23851.exeQueries volume information: C:\Windows\Fonts\ALGER.TTF VolumeInformationJump to behavior
            Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.SpywareX-gen.21876.23851.exeQueries volume information: C:\Windows\Fonts\BKANT.TTF VolumeInformationJump to behavior
            Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.SpywareX-gen.21876.23851.exeQueries volume information: C:\Windows\Fonts\ANTQUAI.TTF VolumeInformationJump to behavior
            Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.SpywareX-gen.21876.23851.exeQueries volume information: C:\Windows\Fonts\ANTQUAB.TTF VolumeInformationJump to behavior
            Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.SpywareX-gen.21876.23851.exeQueries volume information: C:\Windows\Fonts\ANTQUABI.TTF VolumeInformationJump to behavior
            Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.SpywareX-gen.21876.23851.exeQueries volume information: C:\Windows\Fonts\ARLRDBD.TTF VolumeInformationJump to behavior
            Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.SpywareX-gen.21876.23851.exeQueries volume information: C:\Windows\Fonts\BASKVILL.TTF VolumeInformationJump to behavior
            Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.SpywareX-gen.21876.23851.exeQueries volume information: C:\Windows\Fonts\BAUHS93.TTF VolumeInformationJump to behavior
            Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.SpywareX-gen.21876.23851.exeQueries volume information: C:\Windows\Fonts\BELL.TTF VolumeInformationJump to behavior
            Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.SpywareX-gen.21876.23851.exeQueries volume information: C:\Windows\Fonts\BELLI.TTF VolumeInformationJump to behavior
            Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.SpywareX-gen.21876.23851.exeQueries volume information: C:\Windows\Fonts\BELLB.TTF VolumeInformationJump to behavior
            Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.SpywareX-gen.21876.23851.exeQueries volume information: C:\Windows\Fonts\BERNHC.TTF VolumeInformationJump to behavior
            Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.SpywareX-gen.21876.23851.exeQueries volume information: C:\Windows\Fonts\BOD_R.TTF VolumeInformationJump to behavior
            Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.SpywareX-gen.21876.23851.exeQueries volume information: C:\Windows\Fonts\BOD_I.TTF VolumeInformationJump to behavior
            Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.SpywareX-gen.21876.23851.exeQueries volume information: C:\Windows\Fonts\BOD_B.TTF VolumeInformationJump to behavior
            Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.SpywareX-gen.21876.23851.exeQueries volume information: C:\Windows\Fonts\BOD_BI.TTF VolumeInformationJump to behavior
            Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.SpywareX-gen.21876.23851.exeQueries volume information: C:\Windows\Fonts\BOD_CR.TTF VolumeInformationJump to behavior
            Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.SpywareX-gen.21876.23851.exeQueries volume information: C:\Windows\Fonts\BOD_BLAR.TTF VolumeInformationJump to behavior
            Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.SpywareX-gen.21876.23851.exeQueries volume information: C:\Windows\Fonts\BOD_CI.TTF VolumeInformationJump to behavior
            Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.SpywareX-gen.21876.23851.exeQueries volume information: C:\Windows\Fonts\BOD_CB.TTF VolumeInformationJump to behavior
            Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.SpywareX-gen.21876.23851.exeQueries volume information: C:\Windows\Fonts\BOD_BLAI.TTF VolumeInformationJump to behavior
            Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.SpywareX-gen.21876.23851.exeQueries volume information: C:\Windows\Fonts\BOD_CBI.TTF VolumeInformationJump to behavior
            Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.SpywareX-gen.21876.23851.exeQueries volume information: C:\Windows\Fonts\BOD_PSTC.TTF VolumeInformationJump to behavior
            Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.SpywareX-gen.21876.23851.exeQueries volume information: C:\Windows\Fonts\BOOKOS.TTF VolumeInformationJump to behavior
            Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.SpywareX-gen.21876.23851.exeQueries volume information: C:\Windows\Fonts\BOOKOSB.TTF VolumeInformationJump to behavior
            Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.SpywareX-gen.21876.23851.exeQueries volume information: C:\Windows\Fonts\BOOKOSI.TTF VolumeInformationJump to behavior
            Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.SpywareX-gen.21876.23851.exeQueries volume information: C:\Windows\Fonts\BOOKOSBI.TTF VolumeInformationJump to behavior
            Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.SpywareX-gen.21876.23851.exeQueries volume information: C:\Windows\Fonts\BRADHITC.TTF VolumeInformationJump to behavior
            Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.SpywareX-gen.21876.23851.exeQueries volume information: C:\Windows\Fonts\BRITANIC.TTF VolumeInformationJump to behavior
            Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.SpywareX-gen.21876.23851.exeQueries volume information: C:\Windows\Fonts\BRLNSR.TTF VolumeInformationJump to behavior
            Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.SpywareX-gen.21876.23851.exeQueries volume information: C:\Windows\Fonts\BRLNSDB.TTF VolumeInformationJump to behavior
            Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.SpywareX-gen.21876.23851.exeQueries volume information: C:\Windows\Fonts\BRLNSB.TTF VolumeInformationJump to behavior
            Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.SpywareX-gen.21876.23851.exeQueries volume information: C:\Windows\Fonts\BROADW.TTF VolumeInformationJump to behavior
            Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.SpywareX-gen.21876.23851.exeQueries volume information: C:\Windows\Fonts\BRUSHSCI.TTF VolumeInformationJump to behavior
            Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.SpywareX-gen.21876.23851.exeQueries volume information: C:\Windows\Fonts\BSSYM7.TTF VolumeInformationJump to behavior
            Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.SpywareX-gen.21876.23851.exeQueries volume information: C:\Windows\Fonts\CALIFR.TTF VolumeInformationJump to behavior
            Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.SpywareX-gen.21876.23851.exeQueries volume information: C:\Windows\Fonts\CALIFI.TTF VolumeInformationJump to behavior
            Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.SpywareX-gen.21876.23851.exeQueries volume information: C:\Windows\Fonts\CALIFB.TTF VolumeInformationJump to behavior
            Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.SpywareX-gen.21876.23851.exeQueries volume information: C:\Windows\Fonts\CALIST.TTF VolumeInformationJump to behavior
            Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.SpywareX-gen.21876.23851.exeQueries volume information: C:\Windows\Fonts\CALISTI.TTF VolumeInformationJump to behavior
            Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.SpywareX-gen.21876.23851.exeQueries volume information: C:\Windows\Fonts\CALISTB.TTF VolumeInformationJump to behavior
            Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.SpywareX-gen.21876.23851.exeQueries volume information: C:\Windows\Fonts\CALISTBI.TTF VolumeInformationJump to behavior
            Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.SpywareX-gen.21876.23851.exeQueries volume information: C:\Windows\Fonts\CASTELAR.TTF VolumeInformationJump to behavior
            Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.SpywareX-gen.21876.23851.exeQueries volume information: C:\Windows\Fonts\CENSCBK.TTF VolumeInformationJump to behavior
            Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.SpywareX-gen.21876.23851.exeQueries volume information: C:\Windows\Fonts\SCHLBKI.TTF VolumeInformationJump to behavior
            Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.SpywareX-gen.21876.23851.exeQueries volume information: C:\Windows\Fonts\SCHLBKB.TTF VolumeInformationJump to behavior
            Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.SpywareX-gen.21876.23851.exeQueries volume information: C:\Windows\Fonts\SCHLBKBI.TTF VolumeInformationJump to behavior
            Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.SpywareX-gen.21876.23851.exeQueries volume information: C:\Windows\Fonts\CENTAUR.TTF VolumeInformationJump to behavior
            Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.SpywareX-gen.21876.23851.exeQueries volume information: C:\Windows\Fonts\CENTURY.TTF VolumeInformationJump to behavior
            Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.SpywareX-gen.21876.23851.exeQueries volume information: C:\Windows\Fonts\CHILLER.TTF VolumeInformationJump to behavior
            Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.SpywareX-gen.21876.23851.exeQueries volume information: C:\Windows\Fonts\COLONNA.TTF VolumeInformationJump to behavior
            Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.SpywareX-gen.21876.23851.exeQueries volume information: C:\Windows\Fonts\COOPBL.TTF VolumeInformationJump to behavior
            Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.SpywareX-gen.21876.23851.exeQueries volume information: C:\Windows\Fonts\COPRGTL.TTF VolumeInformationJump to behavior
            Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.SpywareX-gen.21876.23851.exeQueries volume information: C:\Windows\Fonts\COPRGTB.TTF VolumeInformationJump to behavior
            Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.SpywareX-gen.21876.23851.exeQueries volume information: C:\Windows\Fonts\CURLZ___.TTF VolumeInformationJump to behavior
            Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.SpywareX-gen.21876.23851.exeQueries volume information: C:\Windows\Fonts\DUBAI-REGULAR.TTF VolumeInformationJump to behavior
            Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.SpywareX-gen.21876.23851.exeQueries volume information: C:\Windows\Fonts\DUBAI-MEDIUM.TTF VolumeInformationJump to behavior
            Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.SpywareX-gen.21876.23851.exeQueries volume information: C:\Windows\Fonts\DUBAI-BOLD.TTF VolumeInformationJump to behavior
            Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.SpywareX-gen.21876.23851.exeQueries volume information: C:\Windows\Fonts\ELEPHNT.TTF VolumeInformationJump to behavior
            Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.SpywareX-gen.21876.23851.exeQueries volume information: C:\Windows\Fonts\ELEPHNTI.TTF VolumeInformationJump to behavior
            Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.SpywareX-gen.21876.23851.exeQueries volume information: C:\Windows\Fonts\ENGR.TTF VolumeInformationJump to behavior
            Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.SpywareX-gen.21876.23851.exeQueries volume information: C:\Windows\Fonts\ERASMD.TTF VolumeInformationJump to behavior
            Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.SpywareX-gen.21876.23851.exeQueries volume information: C:\Windows\Fonts\ERASLGHT.TTF VolumeInformationJump to behavior
            Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.SpywareX-gen.21876.23851.exeQueries volume information: C:\Windows\Fonts\ERASDEMI.TTF VolumeInformationJump to behavior
            Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.SpywareX-gen.21876.23851.exeQueries volume information: C:\Windows\Fonts\ERASBD.TTF VolumeInformationJump to behavior
            Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.SpywareX-gen.21876.23851.exeQueries volume information: C:\Windows\Fonts\FELIXTI.TTF VolumeInformationJump to behavior
            Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.SpywareX-gen.21876.23851.exeQueries volume information: C:\Windows\Fonts\FORTE.TTF VolumeInformationJump to behavior
            Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.SpywareX-gen.21876.23851.exeQueries volume information: C:\Windows\Fonts\FRABK.TTF VolumeInformationJump to behavior
            Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.SpywareX-gen.21876.23851.exeQueries volume information: C:\Windows\Fonts\FRABKIT.TTF VolumeInformationJump to behavior
            Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.SpywareX-gen.21876.23851.exeQueries volume information: C:\Windows\Fonts\FREESCPT.TTF VolumeInformationJump to behavior
            Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.SpywareX-gen.21876.23851.exeQueries volume information: C:\Windows\Fonts\FRSCRIPT.TTF VolumeInformationJump to behavior
            Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.SpywareX-gen.21876.23851.exeQueries volume information: C:\Windows\Fonts\FTLTLT.TTF VolumeInformationJump to behavior
            Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.SpywareX-gen.21876.23851.exeQueries volume information: C:\Windows\Fonts\GARA.TTF VolumeInformationJump to behavior
            Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.SpywareX-gen.21876.23851.exeQueries volume information: C:\Windows\Fonts\GARAIT.TTF VolumeInformationJump to behavior
            Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.SpywareX-gen.21876.23851.exeQueries volume information: C:\Windows\Fonts\GARABD.TTF VolumeInformationJump to behavior
            Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.SpywareX-gen.21876.23851.exeQueries volume information: C:\Windows\Fonts\GIGI.TTF VolumeInformationJump to behavior
            Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.SpywareX-gen.21876.23851.exeQueries volume information: C:\Windows\Fonts\GIL_____.TTF VolumeInformationJump to behavior
            Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.SpywareX-gen.21876.23851.exeQueries volume information: C:\Windows\Fonts\GILI____.TTF VolumeInformationJump to behavior
            Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.SpywareX-gen.21876.23851.exeQueries volume information: C:\Windows\Fonts\GILB____.TTF VolumeInformationJump to behavior
            Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.SpywareX-gen.21876.23851.exeQueries volume information: C:\Windows\Fonts\GILBI___.TTF VolumeInformationJump to behavior
            Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.SpywareX-gen.21876.23851.exeQueries volume information: C:\Windows\Fonts\GILC____.TTF VolumeInformationJump to behavior
            Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.SpywareX-gen.21876.23851.exeQueries volume information: C:\Windows\Fonts\GLSNECB.TTF VolumeInformationJump to behavior
            Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.SpywareX-gen.21876.23851.exeQueries volume information: C:\Windows\Fonts\GLECB.TTF VolumeInformationJump to behavior
            Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.SpywareX-gen.21876.23851.exeQueries volume information: C:\Windows\Fonts\GOTHIC.TTF VolumeInformationJump to behavior
            Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.SpywareX-gen.21876.23851.exeQueries volume information: C:\Windows\Fonts\GOTHICI.TTF VolumeInformationJump to behavior
            Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.SpywareX-gen.21876.23851.exeQueries volume information: C:\Windows\Fonts\GOTHICB.TTF VolumeInformationJump to behavior
            Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.SpywareX-gen.21876.23851.exeQueries volume information: C:\Windows\Fonts\GOTHICBI.TTF VolumeInformationJump to behavior
            Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.SpywareX-gen.21876.23851.exeQueries volume information: C:\Windows\Fonts\GOUDOS.TTF VolumeInformationJump to behavior
            Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.SpywareX-gen.21876.23851.exeQueries volume information: C:\Windows\Fonts\GOUDOSI.TTF VolumeInformationJump to behavior
            Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.SpywareX-gen.21876.23851.exeQueries volume information: C:\Windows\Fonts\GOUDOSB.TTF VolumeInformationJump to behavior
            Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.SpywareX-gen.21876.23851.exeQueries volume information: C:\Windows\Fonts\GOUDYSTO.TTF VolumeInformationJump to behavior
            Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.SpywareX-gen.21876.23851.exeQueries volume information: C:\Windows\Fonts\HARLOWSI.TTF VolumeInformationJump to behavior
            Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.SpywareX-gen.21876.23851.exeQueries volume information: C:\Windows\Fonts\HARNGTON.TTF VolumeInformationJump to behavior
            Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.SpywareX-gen.21876.23851.exeQueries volume information: C:\Windows\Fonts\HATTEN.TTF VolumeInformationJump to behavior
            Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.SpywareX-gen.21876.23851.exeQueries volume information: C:\Windows\Fonts\HTOWERT.TTF VolumeInformationJump to behavior
            Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.SpywareX-gen.21876.23851.exeQueries volume information: C:\Windows\Fonts\HTOWERTI.TTF VolumeInformationJump to behavior
            Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.SpywareX-gen.21876.23851.exeQueries volume information: C:\Windows\Fonts\IMPRISHA.TTF VolumeInformationJump to behavior
            Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.SpywareX-gen.21876.23851.exeQueries volume information: C:\Windows\Fonts\INFROMAN.TTF VolumeInformationJump to behavior
            Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.SpywareX-gen.21876.23851.exeQueries volume information: C:\Windows\Fonts\ITCBLKAD.TTF VolumeInformationJump to behavior
            Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.SpywareX-gen.21876.23851.exeQueries volume information: C:\Windows\Fonts\ITCEDSCR.TTF VolumeInformationJump to behavior
            Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.SpywareX-gen.21876.23851.exeQueries volume information: C:\Windows\Fonts\ITCKRIST.TTF VolumeInformationJump to behavior
            Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.SpywareX-gen.21876.23851.exeQueries volume information: C:\Windows\Fonts\JOKERMAN.TTF VolumeInformationJump to behavior
            Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.SpywareX-gen.21876.23851.exeQueries volume information: C:\Windows\Fonts\JUICE___.TTF VolumeInformationJump to behavior
            Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.SpywareX-gen.21876.23851.exeQueries volume information: C:\Windows\Fonts\KUNSTLER.TTF VolumeInformationJump to behavior
            Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.SpywareX-gen.21876.23851.exeQueries volume information: C:\Windows\Fonts\LATINWD.TTF VolumeInformationJump to behavior
            Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.SpywareX-gen.21876.23851.exeQueries volume information: C:\Windows\Fonts\LBRITE.TTF VolumeInformationJump to behavior
            Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.SpywareX-gen.21876.23851.exeQueries volume information: C:\Windows\Fonts\LBRITED.TTF VolumeInformationJump to behavior
            Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.SpywareX-gen.21876.23851.exeQueries volume information: C:\Windows\Fonts\LBRITEI.TTF VolumeInformationJump to behavior
            Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.SpywareX-gen.21876.23851.exeQueries volume information: C:\Windows\Fonts\LBRITEDI.TTF VolumeInformationJump to behavior
            Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.SpywareX-gen.21876.23851.exeQueries volume information: C:\Windows\Fonts\LCALLIG.TTF VolumeInformationJump to behavior
            Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.SpywareX-gen.21876.23851.exeQueries volume information: C:\Windows\Fonts\LEELAWAD.TTF VolumeInformationJump to behavior
            Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.SpywareX-gen.21876.23851.exeQueries volume information: C:\Windows\Fonts\LEELAWDB.TTF VolumeInformationJump to behavior
            Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.SpywareX-gen.21876.23851.exeQueries volume information: C:\Windows\Fonts\LFAX.TTF VolumeInformationJump to behavior
            Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.SpywareX-gen.21876.23851.exeQueries volume information: C:\Windows\Fonts\LFAXD.TTF VolumeInformationJump to behavior
            Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.SpywareX-gen.21876.23851.exeQueries volume information: C:\Windows\Fonts\LFAXI.TTF VolumeInformationJump to behavior
            Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.SpywareX-gen.21876.23851.exeQueries volume information: C:\Windows\Fonts\LFAXDI.TTF VolumeInformationJump to behavior
            Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.SpywareX-gen.21876.23851.exeQueries volume information: C:\Windows\Fonts\LHANDW.TTF VolumeInformationJump to behavior
            Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.SpywareX-gen.21876.23851.exeQueries volume information: C:\Windows\Fonts\LSANS.TTF VolumeInformationJump to behavior
            Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.SpywareX-gen.21876.23851.exeQueries volume information: C:\Windows\Fonts\LSANSD.TTF VolumeInformationJump to behavior
            Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.SpywareX-gen.21876.23851.exeQueries volume information: C:\Windows\Fonts\LSANSI.TTF VolumeInformationJump to behavior
            Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.SpywareX-gen.21876.23851.exeQueries volume information: C:\Windows\Fonts\LSANSDI.TTF VolumeInformationJump to behavior
            Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.SpywareX-gen.21876.23851.exeQueries volume information: C:\Windows\Fonts\LTYPE.TTF VolumeInformationJump to behavior
            Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.SpywareX-gen.21876.23851.exeQueries volume information: C:\Windows\Fonts\LTYPEO.TTF VolumeInformationJump to behavior
            Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.SpywareX-gen.21876.23851.exeQueries volume information: C:\Windows\Fonts\LTYPEB.TTF VolumeInformationJump to behavior
            Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.SpywareX-gen.21876.23851.exeQueries volume information: C:\Windows\Fonts\LTYPEBO.TTF VolumeInformationJump to behavior
            Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.SpywareX-gen.21876.23851.exeQueries volume information: C:\Windows\Fonts\MAGNETOB.TTF VolumeInformationJump to behavior
            Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.SpywareX-gen.21876.23851.exeQueries volume information: C:\Windows\Fonts\MAIAN.TTF VolumeInformationJump to behavior
            Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.SpywareX-gen.21876.23851.exeQueries volume information: C:\Windows\Fonts\MATURASC.TTF VolumeInformationJump to behavior
            Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.SpywareX-gen.21876.23851.exeQueries volume information: C:\Windows\Fonts\MISTRAL.TTF VolumeInformationJump to behavior
            Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.SpywareX-gen.21876.23851.exeQueries volume information: C:\Windows\Fonts\MOD20.TTF VolumeInformationJump to behavior
            Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.SpywareX-gen.21876.23851.exeQueries volume information: C:\Windows\Fonts\MSUIGHUR.TTF VolumeInformationJump to behavior
            Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.SpywareX-gen.21876.23851.exeQueries volume information: C:\Windows\Fonts\MSUIGHUB.TTF VolumeInformationJump to behavior
            Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.SpywareX-gen.21876.23851.exeQueries volume information: C:\Windows\Fonts\MTCORSVA.TTF VolumeInformationJump to behavior
            Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.SpywareX-gen.21876.23851.exeQueries volume information: C:\Windows\Fonts\MTEXTRA.TTF VolumeInformationJump to behavior
            Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.SpywareX-gen.21876.23851.exeQueries volume information: C:\Windows\Fonts\NIAGENG.TTF VolumeInformationJump to behavior
            Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.SpywareX-gen.21876.23851.exeQueries volume information: C:\Windows\Fonts\NIAGSOL.TTF VolumeInformationJump to behavior
            Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.SpywareX-gen.21876.23851.exeQueries volume information: C:\Windows\Fonts\OCRAEXT.TTF VolumeInformationJump to behavior
            Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.SpywareX-gen.21876.23851.exeQueries volume information: C:\Windows\Fonts\OLDENGL.TTF VolumeInformationJump to behavior
            Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.SpywareX-gen.21876.23851.exeQueries volume information: C:\Windows\Fonts\ONYX.TTF VolumeInformationJump to behavior
            Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.SpywareX-gen.21876.23851.exeQueries volume information: C:\Windows\Fonts\OUTLOOK.TTF VolumeInformationJump to behavior
            Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.SpywareX-gen.21876.23851.exeQueries volume information: C:\Windows\Fonts\PALSCRI.TTF VolumeInformationJump to behavior
            Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.SpywareX-gen.21876.23851.exeQueries volume information: C:\Windows\Fonts\PAPYRUS.TTF VolumeInformationJump to behavior
            Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.SpywareX-gen.21876.23851.exeQueries volume information: C:\Windows\Fonts\PARCHM.TTF VolumeInformationJump to behavior
            Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.SpywareX-gen.21876.23851.exeQueries volume information: C:\Windows\Fonts\PER_____.TTF VolumeInformationJump to behavior
            Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.SpywareX-gen.21876.23851.exeQueries volume information: C:\Windows\Fonts\PERI____.TTF VolumeInformationJump to behavior
            Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.SpywareX-gen.21876.23851.exeQueries volume information: C:\Windows\Fonts\PERB____.TTF VolumeInformationJump to behavior
            Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.SpywareX-gen.21876.23851.exeQueries volume information: C:\Windows\Fonts\PERBI___.TTF VolumeInformationJump to behavior
            Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.SpywareX-gen.21876.23851.exeQueries volume information: C:\Windows\Fonts\PERTILI.TTF VolumeInformationJump to behavior
            Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.SpywareX-gen.21876.23851.exeQueries volume information: C:\Windows\Fonts\PERTIBD.TTF VolumeInformationJump to behavior
            Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.SpywareX-gen.21876.23851.exeQueries volume information: C:\Windows\Fonts\PLAYBILL.TTF VolumeInformationJump to behavior
            Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.SpywareX-gen.21876.23851.exeQueries volume information: C:\Windows\Fonts\POORICH.TTF VolumeInformationJump to behavior
            Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.SpywareX-gen.21876.23851.exeQueries volume information: C:\Windows\Fonts\PRISTINA.TTF VolumeInformationJump to behavior
            Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.SpywareX-gen.21876.23851.exeQueries volume information: C:\Windows\Fonts\RAGE.TTF VolumeInformationJump to behavior
            Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.SpywareX-gen.21876.23851.exeQueries volume information: C:\Windows\Fonts\RAVIE.TTF VolumeInformationJump to behavior
            Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.SpywareX-gen.21876.23851.exeQueries volume information: C:\Windows\Fonts\REFSAN.TTF VolumeInformationJump to behavior
            Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.SpywareX-gen.21876.23851.exeQueries volume information: C:\Windows\Fonts\REFSPCL.TTF VolumeInformationJump to behavior
            Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.SpywareX-gen.21876.23851.exeQueries volume information: C:\Windows\Fonts\ROCK.TTF VolumeInformationJump to behavior
            Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.SpywareX-gen.21876.23851.exeQueries volume information: C:\Windows\Fonts\ROCKI.TTF VolumeInformationJump to behavior
            Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.SpywareX-gen.21876.23851.exeQueries volume information: C:\Windows\Fonts\ROCKB.TTF VolumeInformationJump to behavior
            Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.SpywareX-gen.21876.23851.exeQueries volume information: C:\Windows\Fonts\ROCKEB.TTF VolumeInformationJump to behavior
            Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.SpywareX-gen.21876.23851.exeQueries volume information: C:\Windows\Fonts\ROCKBI.TTF VolumeInformationJump to behavior
            Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.SpywareX-gen.21876.23851.exeQueries volume information: C:\Windows\Fonts\ROCC____.TTF VolumeInformationJump to behavior
            Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.SpywareX-gen.21876.23851.exeQueries volume information: C:\Windows\Fonts\ROCCB___.TTF VolumeInformationJump to behavior
            Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.SpywareX-gen.21876.23851.exeQueries volume information: C:\Windows\Fonts\SCRIPTBL.TTF VolumeInformationJump to behavior
            Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.SpywareX-gen.21876.23851.exeQueries volume information: C:\Windows\Fonts\SHOWG.TTF VolumeInformationJump to behavior
            Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.SpywareX-gen.21876.23851.exeQueries volume information: C:\Windows\Fonts\SNAP____.TTF VolumeInformationJump to behavior
            Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.SpywareX-gen.21876.23851.exeQueries volume information: C:\Windows\Fonts\STENCIL.TTF VolumeInformationJump to behavior
            Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.SpywareX-gen.21876.23851.exeQueries volume information: C:\Windows\Fonts\TCM_____.TTF VolumeInformationJump to behavior
            Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.SpywareX-gen.21876.23851.exeQueries volume information: C:\Windows\Fonts\TCMI____.TTF VolumeInformationJump to behavior
            Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.SpywareX-gen.21876.23851.exeQueries volume information: C:\Windows\Fonts\TCB_____.TTF VolumeInformationJump to behavior
            Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.SpywareX-gen.21876.23851.exeQueries volume information: C:\Windows\Fonts\TCBI____.TTF VolumeInformationJump to behavior
            Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.SpywareX-gen.21876.23851.exeQueries volume information: C:\Windows\Fonts\TCCM____.TTF VolumeInformationJump to behavior
            Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.SpywareX-gen.21876.23851.exeQueries volume information: C:\Windows\Fonts\TCCB____.TTF VolumeInformationJump to behavior
            Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.SpywareX-gen.21876.23851.exeQueries volume information: C:\Windows\Fonts\TCCEB.TTF VolumeInformationJump to behavior
            Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.SpywareX-gen.21876.23851.exeQueries volume information: C:\Windows\Fonts\TEMPSITC.TTF VolumeInformationJump to behavior
            Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.SpywareX-gen.21876.23851.exeQueries volume information: C:\Windows\Fonts\VINERITC.TTF VolumeInformationJump to behavior
            Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.SpywareX-gen.21876.23851.exeQueries volume information: C:\Windows\Fonts\VIVALDII.TTF VolumeInformationJump to behavior
            Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.SpywareX-gen.21876.23851.exeQueries volume information: C:\Windows\Fonts\VLADIMIR.TTF VolumeInformationJump to behavior
            Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.SpywareX-gen.21876.23851.exeQueries volume information: C:\Windows\Fonts\WINGDNG2.TTF VolumeInformationJump to behavior
            Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.SpywareX-gen.21876.23851.exeQueries volume information: C:\Windows\Fonts\WINGDNG3.TTF VolumeInformationJump to behavior
            Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.SpywareX-gen.21876.23851.exeQueries volume information: C:\Windows\Fonts\flat_officeFontsPreview.ttf VolumeInformationJump to behavior
            Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.SpywareX-gen.21876.23851.exeQueries volume information: C:\Windows\Fonts\OFFSYM.TTF VolumeInformationJump to behavior
            Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.SpywareX-gen.21876.23851.exeQueries volume information: C:\Windows\Fonts\OFFSYMSL.TTF VolumeInformationJump to behavior
            Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.SpywareX-gen.21876.23851.exeQueries volume information: C:\Windows\Fonts\OFFSYMSB.TTF VolumeInformationJump to behavior
            Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.SpywareX-gen.21876.23851.exeQueries volume information: C:\Windows\Fonts\OFFSYMXL.TTF VolumeInformationJump to behavior
            Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.SpywareX-gen.21876.23851.exeQueries volume information: C:\Windows\Fonts\OFFSYML.TTF VolumeInformationJump to behavior
            Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.SpywareX-gen.21876.23851.exeQueries volume information: C:\Windows\Fonts\OFFSYMB.TTF VolumeInformationJump to behavior
            Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.SpywareX-gen.21876.23851.exeQueries volume information: C:\Windows\Fonts\micross.ttf VolumeInformationJump to behavior
            Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.SpywareX-gen.21876.23851.exeQueries volume information: C:\Windows\Microsoft.NET\assembly\GAC_MSIL\Microsoft.VisualBasic\v4.0_10.0.0.0__b03f5f7f11d50a3a\Microsoft.VisualBasic.dll VolumeInformationJump to behavior
            Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.SpywareX-gen.21876.23851.exeQueries volume information: C:\Users\user\Desktop\SecuriteInfo.com.Win32.SpywareX-gen.21876.23851.exe VolumeInformationJump to behavior
            Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.SpywareX-gen.21876.23851.exeQueries volume information: C:\Windows\Microsoft.NET\assembly\GAC_MSIL\System.Windows.Forms\v4.0_4.0.0.0__b77a5c561934e089\System.Windows.Forms.dll VolumeInformationJump to behavior
            Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.SpywareX-gen.21876.23851.exeQueries volume information: C:\Windows\Microsoft.NET\assembly\GAC_MSIL\Microsoft.VisualBasic\v4.0_10.0.0.0__b03f5f7f11d50a3a\Microsoft.VisualBasic.dll VolumeInformationJump to behavior
            Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.SpywareX-gen.21876.23851.exeQueries volume information: C:\Windows\Microsoft.NET\assembly\GAC_MSIL\System.Security\v4.0_4.0.0.0__b03f5f7f11d50a3a\System.Security.dll VolumeInformationJump to behavior
            Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.SpywareX-gen.21876.23851.exeQueries volume information: C:\Windows\Microsoft.NET\assembly\GAC_MSIL\System.Web.Extensions\v4.0_4.0.0.0__31bf3856ad364e35\System.Web.Extensions.dll VolumeInformationJump to behavior
            Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.SpywareX-gen.21876.23851.exeQueries volume information: C:\Windows\Microsoft.NET\assembly\GAC_MSIL\System.Drawing\v4.0_4.0.0.0__b03f5f7f11d50a3a\System.Drawing.dll VolumeInformationJump to behavior
            Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.SpywareX-gen.21876.23851.exeQueries volume information: C:\Windows\Microsoft.NET\assembly\GAC_MSIL\Accessibility\v4.0_4.0.0.0__b03f5f7f11d50a3a\Accessibility.dll VolumeInformationJump to behavior
            Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.SpywareX-gen.21876.23851.exeKey value queried: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Cryptography MachineGuidJump to behavior

            Stealing of Sensitive Information

            barindex
            Source: Yara matchFile source: 0.2.SecuriteInfo.com.Win32.SpywareX-gen.21876.23851.exe.3682330.3.unpack, type: UNPACKEDPE
            Source: Yara matchFile source: 1.2.SecuriteInfo.com.Win32.SpywareX-gen.21876.23851.exe.400000.0.unpack, type: UNPACKEDPE
            Source: Yara matchFile source: 0.2.SecuriteInfo.com.Win32.SpywareX-gen.21876.23851.exe.3661910.2.unpack, type: UNPACKEDPE
            Source: Yara matchFile source: 0.2.SecuriteInfo.com.Win32.SpywareX-gen.21876.23851.exe.3682330.3.raw.unpack, type: UNPACKEDPE
            Source: Yara matchFile source: 0.2.SecuriteInfo.com.Win32.SpywareX-gen.21876.23851.exe.3661910.2.raw.unpack, type: UNPACKEDPE
            Source: Yara matchFile source: 00000001.00000002.3600280033.0000000000402000.00000040.00000400.00020000.00000000.sdmp, type: MEMORY
            Source: Yara matchFile source: 00000001.00000002.3604112864.0000000003020000.00000004.00000800.00020000.00000000.sdmp, type: MEMORY
            Source: Yara matchFile source: 00000000.00000002.1162231043.0000000003661000.00000004.00000800.00020000.00000000.sdmp, type: MEMORY
            Source: Yara matchFile source: 00000001.00000002.3604112864.0000000002E51000.00000004.00000800.00020000.00000000.sdmp, type: MEMORY
            Source: Yara matchFile source: Process Memory Space: SecuriteInfo.com.Win32.SpywareX-gen.21876.23851.exe PID: 7784, type: MEMORYSTR
            Source: Yara matchFile source: Process Memory Space: SecuriteInfo.com.Win32.SpywareX-gen.21876.23851.exe PID: 7876, type: MEMORYSTR
            Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.SpywareX-gen.21876.23851.exeFile opened: C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Login DataJump to behavior
            Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.SpywareX-gen.21876.23851.exeFile opened: C:\Users\user\AppData\Local\Microsoft\Edge\User Data\Default\Login DataJump to behavior
            Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.SpywareX-gen.21876.23851.exeFile opened: C:\Users\user\AppData\Roaming\PostboxApp\Profiles\Jump to behavior
            Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.SpywareX-gen.21876.23851.exeKey opened: HKEY_CURRENT_USER\Software\Microsoft\Windows NT\CurrentVersion\Windows Messaging Subsystem\Profiles\Outlook\9375CFF0413111d3B88A00104B2A6676Jump to behavior
            Source: Yara matchFile source: 0.2.SecuriteInfo.com.Win32.SpywareX-gen.21876.23851.exe.3682330.3.unpack, type: UNPACKEDPE
            Source: Yara matchFile source: 1.2.SecuriteInfo.com.Win32.SpywareX-gen.21876.23851.exe.400000.0.unpack, type: UNPACKEDPE
            Source: Yara matchFile source: 0.2.SecuriteInfo.com.Win32.SpywareX-gen.21876.23851.exe.3661910.2.unpack, type: UNPACKEDPE
            Source: Yara matchFile source: 0.2.SecuriteInfo.com.Win32.SpywareX-gen.21876.23851.exe.3682330.3.raw.unpack, type: UNPACKEDPE
            Source: Yara matchFile source: 0.2.SecuriteInfo.com.Win32.SpywareX-gen.21876.23851.exe.3661910.2.raw.unpack, type: UNPACKEDPE
            Source: Yara matchFile source: 00000001.00000002.3600280033.0000000000402000.00000040.00000400.00020000.00000000.sdmp, type: MEMORY
            Source: Yara matchFile source: 00000000.00000002.1162231043.0000000003661000.00000004.00000800.00020000.00000000.sdmp, type: MEMORY
            Source: Yara matchFile source: Process Memory Space: SecuriteInfo.com.Win32.SpywareX-gen.21876.23851.exe PID: 7784, type: MEMORYSTR
            Source: Yara matchFile source: Process Memory Space: SecuriteInfo.com.Win32.SpywareX-gen.21876.23851.exe PID: 7876, type: MEMORYSTR

            Remote Access Functionality

            barindex
            Source: Yara matchFile source: 0.2.SecuriteInfo.com.Win32.SpywareX-gen.21876.23851.exe.3682330.3.unpack, type: UNPACKEDPE
            Source: Yara matchFile source: 1.2.SecuriteInfo.com.Win32.SpywareX-gen.21876.23851.exe.400000.0.unpack, type: UNPACKEDPE
            Source: Yara matchFile source: 0.2.SecuriteInfo.com.Win32.SpywareX-gen.21876.23851.exe.3661910.2.unpack, type: UNPACKEDPE
            Source: Yara matchFile source: 0.2.SecuriteInfo.com.Win32.SpywareX-gen.21876.23851.exe.3682330.3.raw.unpack, type: UNPACKEDPE
            Source: Yara matchFile source: 0.2.SecuriteInfo.com.Win32.SpywareX-gen.21876.23851.exe.3661910.2.raw.unpack, type: UNPACKEDPE
            Source: Yara matchFile source: 00000001.00000002.3600280033.0000000000402000.00000040.00000400.00020000.00000000.sdmp, type: MEMORY
            Source: Yara matchFile source: 00000001.00000002.3604112864.0000000003020000.00000004.00000800.00020000.00000000.sdmp, type: MEMORY
            Source: Yara matchFile source: 00000000.00000002.1162231043.0000000003661000.00000004.00000800.00020000.00000000.sdmp, type: MEMORY
            Source: Yara matchFile source: 00000001.00000002.3604112864.0000000002E51000.00000004.00000800.00020000.00000000.sdmp, type: MEMORY
            Source: Yara matchFile source: Process Memory Space: SecuriteInfo.com.Win32.SpywareX-gen.21876.23851.exe PID: 7784, type: MEMORYSTR
            Source: Yara matchFile source: Process Memory Space: SecuriteInfo.com.Win32.SpywareX-gen.21876.23851.exe PID: 7876, type: MEMORYSTR
            ReconnaissanceResource DevelopmentInitial AccessExecutionPersistencePrivilege EscalationDefense EvasionCredential AccessDiscoveryLateral MovementCollectionCommand and ControlExfiltrationImpact
            Gather Victim Identity InformationAcquire InfrastructureValid AccountsWindows Management Instrumentation1
            DLL Side-Loading
            11
            Process Injection
            1
            Masquerading
            1
            OS Credential Dumping
            1
            Security Software Discovery
            Remote Services1
            Email Collection
            11
            Encrypted Channel
            Exfiltration Over Other Network MediumAbuse Accessibility Features
            CredentialsDomainsDefault AccountsScheduled Task/JobBoot or Logon Initialization Scripts1
            DLL Side-Loading
            1
            Disable or Modify Tools
            LSASS Memory1
            Process Discovery
            Remote Desktop Protocol11
            Archive Collected Data
            1
            Ingress Tool Transfer
            Exfiltration Over BluetoothNetwork Denial of Service
            Email AddressesDNS ServerDomain AccountsAtLogon Script (Windows)Logon Script (Windows)31
            Virtualization/Sandbox Evasion
            Security Account Manager31
            Virtualization/Sandbox Evasion
            SMB/Windows Admin Shares1
            Data from Local System
            2
            Non-Application Layer Protocol
            Automated ExfiltrationData Encrypted for Impact
            Employee NamesVirtual Private ServerLocal AccountsCronLogin HookLogin Hook11
            Process Injection
            NTDS1
            Application Window Discovery
            Distributed Component Object ModelInput Capture13
            Application Layer Protocol
            Traffic DuplicationData Destruction
            Gather Victim Network InformationServerCloud AccountsLaunchdNetwork Logon ScriptNetwork Logon Script1
            Deobfuscate/Decode Files or Information
            LSA Secrets1
            System Network Configuration Discovery
            SSHKeyloggingFallback ChannelsScheduled TransferData Encrypted for Impact
            Domain PropertiesBotnetReplication Through Removable MediaScheduled TaskRC ScriptsRC Scripts21
            Obfuscated Files or Information
            Cached Domain Credentials13
            System Information Discovery
            VNCGUI Input CaptureMultiband CommunicationData Transfer Size LimitsService Stop
            DNSWeb ServicesExternal Remote ServicesSystemd TimersStartup ItemsStartup Items12
            Software Packing
            DCSyncRemote System DiscoveryWindows Remote ManagementWeb Portal CaptureCommonly Used PortExfiltration Over C2 ChannelInhibit System Recovery
            Network Trust DependenciesServerlessDrive-by CompromiseContainer Orchestration JobScheduled Task/JobScheduled Task/Job1
            DLL Side-Loading
            Proc FilesystemSystem Owner/User DiscoveryCloud ServicesCredential API HookingApplication Layer ProtocolExfiltration Over Alternative ProtocolDefacement

            This section contains all screenshots as thumbnails, including those not shown in the slideshow.