Loading Joe Sandbox Report ...

Edit tour

Windows Analysis Report
Busy2.0.exe

Overview

General Information

Sample name:Busy2.0.exe
Analysis ID:1639482
MD5:6ee9b76d1bfd47a5b4c4ae58a293c05c
SHA1:11564c7122e44a3c4da2afdd73cab6f53321508c
SHA256:670d7d789fcfc13fca28cf4633543cfcfbd13183a5dedb1c3fa5709a5190cd33
Tags:exeuser-2huMarisa
Infos:

Detection

Babadeda
Score:100
Range:0 - 100
Confidence:100%

Signatures

Antivirus / Scanner detection for submitted sample
Antivirus detection for dropped file
Multi AV Scanner detection for dropped file
Multi AV Scanner detection for submitted file
Yara detected Babadeda
Changes the wallpaper picture
Contains functionality to access PhysicalDrive, possible boot sector overwrite
Contains functionality to infect the boot sector
Disable Task Manager(disabletaskmgr)
Disables the Windows task manager (taskmgr)
Joe Sandbox ML detected suspicious sample
Sigma detected: Schtasks Creation Or Modification With SYSTEM Privileges
Tries to detect process monitoring tools (Task Manager, Process Explorer etc.)
Uses cmd line tools excessively to alter registry or file data
Uses schtasks.exe or at.exe to add and modify task schedules
Writes directly to the primary disk partition (DR0)
Allocates memory with a write watch (potentially for evading sandboxes)
Binary contains a suspicious time stamp
Contains functionality to dynamically determine API calls
Contains functionality to launch a program with higher privileges
Contains functionality to query locales information (e.g. system language)
Contains functionality to shutdown / reboot the system
Creates a process in suspended mode (likely to inject code)
Detected potential crypto function
Dropped file seen in connection with other malware
Drops PE files
Extensive use of GetProcAddress (often used to hide API calls)
Found a high number of Window / User specific system calls (may be a loop to detect user behavior)
Found dropped PE file which has not been started or loaded
Found inlined nop instructions (likely shell or obfuscated code)
Found potential string decryption / allocating functions
JA3 SSL client fingerprint seen in connection with other malware
May sleep (evasive loops) to hinder dynamic analysis
PE file contains sections with non-standard names
Queries disk information (often used to detect virtual machines)
Queries keyboard layouts
Queries the volume information (name, serial number etc) of a device
Sample execution stops while process was sleeping (likely an evasion)
Sample file is different than original file name gathered from version info
Sigma detected: CurrentVersion Autorun Keys Modification
Sigma detected: Potentially Suspicious Desktop Background Change Via Registry
Sleep loop found (likely to delay execution)
Uses 32bit PE files
Uses code obfuscation techniques (call, push, ret)
Uses reg.exe to modify the Windows registry

Classification

  • System is w10x64
  • Busy2.0.exe (PID: 7132 cmdline: "C:\Users\user\Desktop\Busy2.0.exe" MD5: 6EE9B76D1BFD47A5B4C4AE58A293C05C)
    • conhost.exe (PID: 6468 cmdline: C:\Windows\system32\conhost.exe 0xffffffff -ForceV1 MD5: 0D698AF330FD17BEE3BF90011D49251D)
    • cmd.exe (PID: 5380 cmdline: "C:\Windows\sysnative\cmd" /c "C:\Users\user\AppData\Local\Temp\2A8E.tmp\2A8F.tmp\2A90.bat C:\Users\user\Desktop\Busy2.0.exe" MD5: 8A2122E8162DBEF04694B9C3E0B6CDEE)
      • timeout.exe (PID: 4960 cmdline: timeout /t 30 MD5: 100065E21CFBBDE57CBA2838921F84D6)
      • timeout.exe (PID: 7296 cmdline: timeout /t 5 MD5: 100065E21CFBBDE57CBA2838921F84D6)
      • timeout.exe (PID: 7324 cmdline: timeout /t 1 MD5: 100065E21CFBBDE57CBA2838921F84D6)
      • timeout.exe (PID: 7340 cmdline: timeout /t 1 MD5: 100065E21CFBBDE57CBA2838921F84D6)
      • timeout.exe (PID: 7364 cmdline: timeout /t 2 MD5: 100065E21CFBBDE57CBA2838921F84D6)
      • timeout.exe (PID: 7392 cmdline: timeout /t 4 MD5: 100065E21CFBBDE57CBA2838921F84D6)
      • reg.exe (PID: 7424 cmdline: reg add "HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\System" /v DisableTaskMgr /t "REG_DWORD" /d "1" /f MD5: 227F63E1D9008B36BDBCC4B397780BE4)
      • MBR.exe (PID: 7440 cmdline: MBR.exe MD5: 344C84937D34113C838494FBC6E9AC16)
        • schtasks.exe (PID: 7452 cmdline: schtasks.exe /Create /TN "Windows Update" /ru SYSTEM /SC ONSTART /TR "C:\Users\user\Desktop\MBR.exe" MD5: 48C2FE20575769DE916F48EF0676A965)
          • conhost.exe (PID: 7476 cmdline: C:\Windows\system32\conhost.exe 0xffffffff -ForceV1 MD5: 0D698AF330FD17BEE3BF90011D49251D)
      • timeout.exe (PID: 7928 cmdline: timeout /t 1 MD5: 100065E21CFBBDE57CBA2838921F84D6)
      • reg.exe (PID: 8084 cmdline: reg add "HKEY_CURRENT_USER\Control Panel\Desktop" /v "Wallpaper" /t REG_SZ /d "C:\Users\userDesktop\YuuyaCat.bmp" /f MD5: 227F63E1D9008B36BDBCC4B397780BE4)
      • rundll32.exe (PID: 8156 cmdline: RUNDLL32.EXE user32.dll,UpdatePerUserSystemParameters MD5: EF3179D498793BF4234F708D3BE28633)
      • reg.exe (PID: 6644 cmdline: reg add "HKEY_CURRENT_USER\Control Panel\Desktop" /v "Wallpaper" /t REG_SZ /d "C:\Users\userDesktop\YuuyaCat.bmp" /f MD5: 227F63E1D9008B36BDBCC4B397780BE4)
      • rundll32.exe (PID: 5204 cmdline: RUNDLL32.EXE user32.dll,UpdatePerUserSystemParameters MD5: EF3179D498793BF4234F708D3BE28633)
      • reg.exe (PID: 5664 cmdline: reg add "HKEY_CURRENT_USER\Control Panel\Desktop" /v "Wallpaper" /t REG_SZ /d "C:\Users\userDesktop\YuuyaCat.bmp" /f MD5: 227F63E1D9008B36BDBCC4B397780BE4)
      • rundll32.exe (PID: 7136 cmdline: RUNDLL32.EXE user32.dll,UpdatePerUserSystemParameters MD5: EF3179D498793BF4234F708D3BE28633)
      • reg.exe (PID: 932 cmdline: reg add "HKEY_CURRENT_USER\Control Panel\Desktop" /v "Wallpaper" /t REG_SZ /d "C:\Users\userDesktop\YuuyaCat.bmp" /f MD5: 227F63E1D9008B36BDBCC4B397780BE4)
      • rundll32.exe (PID: 7328 cmdline: RUNDLL32.EXE user32.dll,UpdatePerUserSystemParameters MD5: EF3179D498793BF4234F708D3BE28633)
      • timeout.exe (PID: 760 cmdline: timeout /t 4 MD5: 100065E21CFBBDE57CBA2838921F84D6)
      • IconDance.exe (PID: 1720 cmdline: IconDance.exe MD5: DD5D7042C222D232731C2E55182E5DFF)
      • runaway.exe (PID: 1152 cmdline: runaway.exe MD5: 979B597855746AEE2F30EE74F9D7C163)
  • Music.UI.exe (PID: 7576 cmdline: "C:\Program Files\WindowsApps\Microsoft.ZuneMusic_10.19071.19011.0_x64__8wekyb3d8bbwe\Music.UI.exe" -ServerName:Microsoft.ZuneMusic.AppX48dcrcgzqqdshm3kf61t0cm5e9pyd6h6.mca MD5: F963F75C0AD152437E10D656A00793A3)
  • MBR.exe (PID: 7616 cmdline: C:\Users\user\Desktop\MBR.exe MD5: 344C84937D34113C838494FBC6E9AC16)
    • schtasks.exe (PID: 7656 cmdline: schtasks.exe /Create /TN "Windows Update" /ru SYSTEM /SC ONSTART /TR "C:\Users\user\Desktop\MBR.exe" MD5: 48C2FE20575769DE916F48EF0676A965)
      • conhost.exe (PID: 7768 cmdline: C:\Windows\system32\conhost.exe 0xffffffff -ForceV1 MD5: 0D698AF330FD17BEE3BF90011D49251D)
  • cleanup
NameDescriptionAttributionBlogpost URLsLink
BabadedaAccording to PCrisk, Babadeda is a new sample in the crypters family, allowing threat actors to encrypt and obfuscate the malicious samples. The obfuscation allows malware to bypass the majority of antivirus protections without triggering any alerts. According to the researchers analysis, Babadeda leverages a sophisticated and complex obfuscation that shows a very low detection rate by anti-virus engines.No Attributionhttps://malpedia.caad.fkie.fraunhofer.de/details/win.babadeda
No configs have been found
SourceRuleDescriptionAuthorStrings
Busy2.0.exeJoeSecurity_BabadedaYara detected BabadedaJoe Security
    SourceRuleDescriptionAuthorStrings
    C:\Users\user\Desktop\matrix.exeJoeSecurity_BabadedaYara detected BabadedaJoe Security

      System Summary

      barindex
      Source: Process startedAuthor: Nasreddine Bencherchali (Nextron Systems): Data: Command: schtasks.exe /Create /TN "Windows Update" /ru SYSTEM /SC ONSTART /TR "C:\Users\user\Desktop\MBR.exe", CommandLine: schtasks.exe /Create /TN "Windows Update" /ru SYSTEM /SC ONSTART /TR "C:\Users\user\Desktop\MBR.exe", CommandLine|base64offset|contains: *j, Image: C:\Windows\SysWOW64\schtasks.exe, NewProcessName: C:\Windows\SysWOW64\schtasks.exe, OriginalFileName: C:\Windows\SysWOW64\schtasks.exe, ParentCommandLine: MBR.exe, ParentImage: C:\Users\user\Desktop\MBR.exe, ParentProcessId: 7440, ParentProcessName: MBR.exe, ProcessCommandLine: schtasks.exe /Create /TN "Windows Update" /ru SYSTEM /SC ONSTART /TR "C:\Users\user\Desktop\MBR.exe", ProcessId: 7452, ProcessName: schtasks.exe
      Source: Registry Key setAuthor: Victor Sergeev, Daniil Yugoslavskiy, Gleb Sukhodolskiy, Timur Zinniatullin, oscd.community, Tim Shelton, frack113 (split): Data: Details: C:\Users\user\Desktop\MBR.exe, EventID: 13, EventType: SetValue, Image: C:\Users\user\Desktop\MBR.exe, ProcessId: 7440, TargetObject: HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\Windows Update
      Source: Registry Key setAuthor: Nasreddine Bencherchali (Nextron Systems), Stephen Lincoln @slincoln-aiq (AttackIQ): Data: Details: C:\Users\userDesktop\YuuyaCat.bmp, EventID: 13, EventType: SetValue, Image: C:\Windows\System32\reg.exe, ProcessId: 8084, TargetObject: HKEY_CURRENT_USER\Control Panel\Desktop\Wallpaper
      No Suricata rule has matched

      Click to jump to signature section

      Show All Signature Results

      AV Detection

      barindex
      Source: Busy2.0.exeAvira: detected
      Source: C:\Users\user\Desktop\MBR.exeAvira: detection malicious, Label: HEUR/AGEN.1330675
      Source: C:\Users\user\Desktop\Melting.exeAvira: detection malicious, Label: TR/BadJoke.U
      Source: C:\Users\user\Desktop\Hydra.exeAvira: detection malicious, Label: TR/BadJoke.gjdfh
      Source: C:\Users\user\Desktop\IconDance.exeAvira: detection malicious, Label: JOKE/Win32.IconDance
      Source: C:\Users\user\Desktop\Hydra.exeReversingLabs: Detection: 50%
      Source: C:\Users\user\Desktop\IconDance.exeReversingLabs: Detection: 79%
      Source: C:\Users\user\Desktop\MBR.exeReversingLabs: Detection: 79%
      Source: C:\Users\user\Desktop\Melting.exeReversingLabs: Detection: 50%
      Source: C:\Users\user\Desktop\matrix.exeReversingLabs: Detection: 27%
      Source: C:\Users\user\Desktop\runaway.exeReversingLabs: Detection: 29%
      Source: Busy2.0.exeVirustotal: Detection: 66%Perma Link
      Source: Busy2.0.exeReversingLabs: Detection: 61%
      Source: Submited SampleIntegrated Neural Analysis Model: Matched 98.0% probability
      Source: Busy2.0.exeStatic PE information: RELOCS_STRIPPED, EXECUTABLE_IMAGE, LINE_NUMS_STRIPPED, LOCAL_SYMS_STRIPPED, 32BIT_MACHINE
      Source: unknownHTTPS traffic detected: 23.219.148.9:443 -> 192.168.2.8:49692 version: TLS 1.2
      Source: Binary string: C:\Users\FlyTech\Documents\Visual Studio 2015\Projects\Messager\Messager\obj\Debug\Messager.pdb source: Busy2.0.exe, 00000000.00000003.1008656527.0000000002ED2000.00000004.00000020.00020000.00000000.sdmp, runaway.exe, 0000002B.00000000.1531313090.0000000000112000.00000002.00000001.01000000.00000013.sdmp, runaway.exe.0.dr
      Source: Binary string: D:\Visual Studio Projects\Hydra\Hydra\obj\Release\Hydra.pdb source: Busy2.0.exe, 00000000.00000003.1008777841.0000000002DD3000.00000004.00000020.00020000.00000000.sdmp, Hydra.exe.0.dr
      Source: Binary string: C:\Users\Domas\Desktop\ScreenMelter\x64\Release\ScreenMelter.pdb source: Melting.exe.0.dr
      Source: C:\Users\user\Desktop\MBR.exeCode function: 19_2_004049A0 GetModuleHandleA,GetProcAddress,lstrcpyn,lstrcpyn,lstrcpyn,FindFirstFileA,FindClose,lstrlen,lstrcpyn,lstrlen,lstrcpyn,19_2_004049A0
      Source: C:\Users\user\Desktop\Busy2.0.exeFile opened: C:\Users\user\AppData\Local\Temp\2A8E.tmpJump to behavior
      Source: C:\Users\user\Desktop\Busy2.0.exeFile opened: C:\Users\user\AppData\Jump to behavior
      Source: C:\Users\user\Desktop\Busy2.0.exeFile opened: C:\Users\user\AppData\Local\Temp\2A8E.tmp\2A8F.tmp\2A90.tmpJump to behavior
      Source: C:\Users\user\Desktop\Busy2.0.exeFile opened: C:\Users\user\Jump to behavior
      Source: C:\Users\user\Desktop\Busy2.0.exeFile opened: C:\Users\user\AppData\Local\Jump to behavior
      Source: C:\Users\user\Desktop\Busy2.0.exeFile opened: C:\Users\user\AppData\Local\Temp\2A8E.tmp\2A8F.tmpJump to behavior
      Source: C:\Users\user\Desktop\runaway.exeCode function: 4x nop then mov ecx, dword ptr [ebp-38h]43_2_009E8360
      Source: C:\Users\user\Desktop\runaway.exeCode function: 4x nop then mov ecx, dword ptr [ebp-38h]43_2_009E8590
      Source: C:\Users\user\Desktop\runaway.exeCode function: 4x nop then mov ecx, dword ptr [ebp-3Ch]43_2_009E0AD8
      Source: C:\Users\user\Desktop\runaway.exeCode function: 4x nop then push dword ptr [ebp-10h]43_2_009E8CA0
      Source: C:\Users\user\Desktop\runaway.exeCode function: 4x nop then mov dword ptr [ebp-20h], 7FFFFFFFh43_2_009E94F0
      Source: C:\Users\user\Desktop\runaway.exeCode function: 4x nop then mov ecx, dword ptr [ebp-38h]43_2_009E8358
      Source: C:\Users\user\Desktop\runaway.exeCode function: 4x nop then mov dword ptr [ebp-20h], 7FFFFFFFh43_2_009E8470
      Source: C:\Users\user\Desktop\runaway.exeCode function: 4x nop then mov dword ptr [ebp-20h], 7FFFFFFFh43_2_009E8466
      Source: C:\Users\user\Desktop\runaway.exeCode function: 4x nop then mov ecx, dword ptr [ebp-3Ch]43_2_009E0AD1
      Source: C:\Users\user\Desktop\runaway.exeCode function: 4x nop then mov ecx, dword ptr [ebp-38h]43_2_009E93D0
      Source: C:\Users\user\Desktop\runaway.exeCode function: 4x nop then mov dword ptr [ebp-20h], 7FFFFFFFh43_2_009E94E4
      Source: Joe Sandbox ViewJA3 fingerprint: 6271f898ce5be7dd52b0fc260d0662b3
      Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
      Source: global trafficHTTP traffic detected: GET /XBLWinClient/v10_music/configuration.xml HTTP/1.1Accept: */*User-Agent: XBLWIN10.19071Accept-Language: en-CHAccept-Encoding: gzip, deflate, brHost: settings-ssl.xboxlive.comConnection: Keep-Alive
      Source: global trafficDNS traffic detected: DNS query: settings-ssl.xboxlive.com
      Source: Music.UI.exe, 00000017.00000002.2323531952.0000013ECD186000.00000004.00000020.00020000.00000000.sdmpString found in binary or memory: https://login.live.com
      Source: Music.UI.exe, 00000017.00000002.2323531952.0000013ECD186000.00000004.00000020.00020000.00000000.sdmpString found in binary or memory: https://login.live.com/xsts.auth.xboxlive.com
      Source: Music.UI.exe, 00000017.00000002.2322000807.0000013ECD0D9000.00000004.00000020.00020000.00000000.sdmpString found in binary or memory: https://login.windows.local
      Source: Music.UI.exe, 00000017.00000002.2322000807.0000013ECD0D9000.00000004.00000020.00020000.00000000.sdmpString found in binary or memory: https://login.windows.local/
      Source: Music.UI.exe, 00000017.00000002.2322000807.0000013ECD0D9000.00000004.00000020.00020000.00000000.sdmpString found in binary or memory: https://login.windows.net
      Source: Music.UI.exe, 00000017.00000002.2322000807.0000013ECD0D9000.00000004.00000020.00020000.00000000.sdmpString found in binary or memory: https://login.windows.net/
      Source: Music.UI.exe, 00000017.00000002.2306720921.0000013ECC4D2000.00000004.00000020.00020000.00000000.sdmpString found in binary or memory: https://musicart.xboxlive.com/9/5c6a4700-0000-0000-0000-000000000002/504/image.jpg
      Source: Music.UI.exe, 00000017.00000002.2306720921.0000013ECC4D2000.00000004.00000020.00020000.00000000.sdmpString found in binary or memory: https://musicart.xboxlive.com/9/e74d4600-0000-0000-0000-000000000002/504/image.jpg
      Source: Music.UI.exe, 00000017.00000002.2305918447.0000013ECC41B000.00000004.00000020.00020000.00000000.sdmpString found in binary or memory: https://musicimage.xboxlive.comtXBLWinClient/v10_music/configuration.xmlC:
      Source: Music.UI.exe, 00000017.00000003.1492393080.0000013ECC461000.00000004.00000020.00020000.00000000.sdmp, Music.UI.exe, 00000017.00000002.2305918447.0000013ECC41B000.00000004.00000020.00020000.00000000.sdmpString found in binary or memory: https://settings-ssl.xboxlive.com
      Source: Music.UI.exe, 00000017.00000003.1492393080.0000013ECC461000.00000004.00000020.00020000.00000000.sdmp, Music.UI.exe, 00000017.00000002.2305918447.0000013ECC41B000.00000004.00000020.00020000.00000000.sdmpString found in binary or memory: https://settings-ssl.xboxlive.com/
      Source: Music.UI.exe, 00000017.00000003.1492393080.0000013ECC461000.00000004.00000020.00020000.00000000.sdmpString found in binary or memory: https://settings-ssl.xboxlive.com/XBLWinClient/v10_music/configuration.xml
      Source: Music.UI.exe, 00000017.00000003.1492393080.0000013ECC461000.00000004.00000020.00020000.00000000.sdmpString found in binary or memory: https://settings-ssl.xboxlive.com/XBLWinClient/v10_music/configuration.xmlC:
      Source: Music.UI.exe, 00000017.00000002.2322000807.0000013ECD0D9000.00000004.00000020.00020000.00000000.sdmpString found in binary or memory: https://xsts.auth.xboxlive.com
      Source: Music.UI.exe, 00000017.00000002.2322000807.0000013ECD0D9000.00000004.00000020.00020000.00000000.sdmpString found in binary or memory: https://xsts.auth.xboxlive.com/p
      Source: Music.UI.exe, 00000017.00000002.2306720921.0000013ECC536000.00000004.00000020.00020000.00000000.sdmpString found in binary or memory: https://xsts.auth.xboxlive.com5png
      Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49692
      Source: unknownNetwork traffic detected: HTTP traffic on port 49692 -> 443
      Source: unknownHTTPS traffic detected: 23.219.148.9:443 -> 192.168.2.8:49692 version: TLS 1.2

      Spam, unwanted Advertisements and Ransom Demands

      barindex
      Source: C:\Windows\System32\reg.exeKey value created or modified: HKEY_CURRENT_USER\Control Panel\Desktop Wallpaper C:\Users\userDesktop\YuuyaCat.bmpJump to behavior

      Operating System Destruction

      barindex
      Source: C:\Users\user\Desktop\MBR.exeCode function: 19_2_00412DE0 CreateFileA on filename \\.\PhysicalDrive019_2_00412DE0
      Source: C:\Users\user\Desktop\MBR.exeCode function: 19_2_00412AF8 GetCurrentProcess,OpenProcessToken,LookupPrivilegeValueA,AdjustTokenPrivileges,ExitWindowsEx,19_2_00412AF8
      Source: C:\Users\user\Desktop\Busy2.0.exeCode function: 0_2_00410C800_2_00410C80
      Source: C:\Users\user\Desktop\Busy2.0.exeCode function: 0_2_0040EFF00_2_0040EFF0
      Source: C:\Users\user\Desktop\MBR.exeCode function: 19_2_0040C33619_2_0040C336
      Source: C:\Users\user\Desktop\runaway.exeCode function: 43_2_009E74F843_2_009E74F8
      Source: C:\Users\user\Desktop\runaway.exeCode function: 43_2_009E74E843_2_009E74E8
      Source: Joe Sandbox ViewDropped File: C:\Users\user\Desktop\Hydra.exe 0B6C0AF51CDE971B3E5F8AA204F8205418AB8C180B79A5AC1C11A6E0676F0F7C
      Source: C:\Users\user\Desktop\MBR.exeCode function: String function: 00403A44 appears 53 times
      Source: Busy2.0.exe, 00000000.00000003.1008656527.0000000002ED2000.00000004.00000020.00020000.00000000.sdmpBinary or memory string: OriginalFilenameMessager.exe4 vs Busy2.0.exe
      Source: Busy2.0.exe, 00000000.00000003.1008777841.0000000002DD3000.00000004.00000020.00020000.00000000.sdmpBinary or memory string: OriginalFilenameHydra.exe, vs Busy2.0.exe
      Source: Busy2.0.exe, 00000000.00000003.1009119771.0000000002E09000.00000004.00000020.00020000.00000000.sdmpBinary or memory string: OriginalFilenamematrix.exe6 vs Busy2.0.exe
      Source: Busy2.0.exe, 00000000.00000003.1009119771.0000000002E09000.00000004.00000020.00020000.00000000.sdmpBinary or memory string: OriginalFilename" vs Busy2.0.exe
      Source: Busy2.0.exeBinary or memory string: OriginalFilenameBusy2.00 vs Busy2.0.exe
      Source: Busy2.0.exeStatic PE information: RELOCS_STRIPPED, EXECUTABLE_IMAGE, LINE_NUMS_STRIPPED, LOCAL_SYMS_STRIPPED, 32BIT_MACHINE
      Source: C:\Windows\System32\cmd.exeProcess created: C:\Windows\System32\reg.exe reg add "HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\System" /v DisableTaskMgr /t "REG_DWORD" /d "1" /f
      Source: classification engineClassification label: mal100.rans.troj.evad.winEXE@98/31@1/1
      Source: C:\Users\user\Desktop\MBR.exeCode function: 19_2_00412888 GetCurrentProcess,OpenProcessToken,LookupPrivilegeValueA,AdjustTokenPrivileges,CloseHandle,19_2_00412888
      Source: C:\Users\user\Desktop\MBR.exeCode function: 19_2_00412AF8 GetCurrentProcess,OpenProcessToken,LookupPrivilegeValueA,AdjustTokenPrivileges,ExitWindowsEx,19_2_00412AF8
      Source: C:\Users\user\Desktop\MBR.exeCode function: 19_2_00406F56 GetDiskFreeSpaceA,19_2_00406F56
      Source: C:\Users\user\Desktop\Busy2.0.exeCode function: 0_2_00402664 LoadResource,SizeofResource,FreeResource,0_2_00402664
      Source: C:\Users\user\Desktop\Busy2.0.exeFile created: C:\Users\user\Desktop\gg.wavJump to behavior
      Source: C:\Users\user\Desktop\runaway.exeMutant created: NULL
      Source: C:\Windows\System32\conhost.exeMutant created: \BaseNamedObjects\Local\SM0:7768:120:WilError_03
      Source: C:\Windows\System32\conhost.exeMutant created: \Sessions\1\BaseNamedObjects\Local\SM0:7476:120:WilError_03
      Source: C:\Windows\System32\conhost.exeMutant created: \Sessions\1\BaseNamedObjects\Local\SM0:6468:120:WilError_03
      Source: C:\Users\user\Desktop\Busy2.0.exeFile created: C:\Users\user\AppData\Local\Temp\2A8E.tmpJump to behavior
      Source: C:\Users\user\Desktop\Busy2.0.exeProcess created: C:\Windows\System32\cmd.exe "C:\Windows\sysnative\cmd" /c "C:\Users\user\AppData\Local\Temp\2A8E.tmp\2A8F.tmp\2A90.bat C:\Users\user\Desktop\Busy2.0.exe"
      Source: C:\Users\user\Desktop\MBR.exeKey opened: HKEY_CURRENT_USER\Software\Borland\Delphi\LocalesJump to behavior
      Source: C:\Users\user\Desktop\MBR.exeKey opened: HKEY_USERS.DEFAULT\Software\Borland\Delphi\LocalesJump to behavior
      Source: C:\Users\user\Desktop\IconDance.exeKey opened: HKEY_CURRENT_USER\Software\Borland\Delphi\Locales
      Source: C:\Windows\System32\cmd.exeFile read: C:\Users\user\Desktop\desktop.iniJump to behavior
      Source: C:\Users\user\Desktop\Busy2.0.exeKey opened: HKEY_CURRENT_USER\Software\Policies\Microsoft\Windows\Safer\CodeIdentifiersJump to behavior
      Source: C:\Windows\System32\cmd.exeProcess created: C:\Windows\System32\rundll32.exe RUNDLL32.EXE user32.dll,UpdatePerUserSystemParameters
      Source: Busy2.0.exeVirustotal: Detection: 66%
      Source: Busy2.0.exeReversingLabs: Detection: 61%
      Source: unknownProcess created: C:\Users\user\Desktop\Busy2.0.exe "C:\Users\user\Desktop\Busy2.0.exe"
      Source: C:\Users\user\Desktop\Busy2.0.exeProcess created: C:\Windows\System32\conhost.exe C:\Windows\system32\conhost.exe 0xffffffff -ForceV1
      Source: C:\Users\user\Desktop\Busy2.0.exeProcess created: C:\Windows\System32\cmd.exe "C:\Windows\sysnative\cmd" /c "C:\Users\user\AppData\Local\Temp\2A8E.tmp\2A8F.tmp\2A90.bat C:\Users\user\Desktop\Busy2.0.exe"
      Source: C:\Windows\System32\cmd.exeProcess created: C:\Windows\System32\timeout.exe timeout /t 30
      Source: C:\Windows\System32\cmd.exeProcess created: C:\Windows\System32\timeout.exe timeout /t 5
      Source: C:\Windows\System32\cmd.exeProcess created: C:\Windows\System32\timeout.exe timeout /t 1
      Source: C:\Windows\System32\cmd.exeProcess created: C:\Windows\System32\timeout.exe timeout /t 1
      Source: C:\Windows\System32\cmd.exeProcess created: C:\Windows\System32\timeout.exe timeout /t 2
      Source: C:\Windows\System32\cmd.exeProcess created: C:\Windows\System32\timeout.exe timeout /t 4
      Source: C:\Windows\System32\cmd.exeProcess created: C:\Windows\System32\reg.exe reg add "HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\System" /v DisableTaskMgr /t "REG_DWORD" /d "1" /f
      Source: C:\Windows\System32\cmd.exeProcess created: C:\Users\user\Desktop\MBR.exe MBR.exe
      Source: C:\Users\user\Desktop\MBR.exeProcess created: C:\Windows\SysWOW64\schtasks.exe schtasks.exe /Create /TN "Windows Update" /ru SYSTEM /SC ONSTART /TR "C:\Users\user\Desktop\MBR.exe"
      Source: C:\Windows\SysWOW64\schtasks.exeProcess created: C:\Windows\System32\conhost.exe C:\Windows\system32\conhost.exe 0xffffffff -ForceV1
      Source: unknownProcess created: C:\Program Files\WindowsApps\Microsoft.ZuneMusic_10.19071.19011.0_x64__8wekyb3d8bbwe\Music.UI.exe "C:\Program Files\WindowsApps\Microsoft.ZuneMusic_10.19071.19011.0_x64__8wekyb3d8bbwe\Music.UI.exe" -ServerName:Microsoft.ZuneMusic.AppX48dcrcgzqqdshm3kf61t0cm5e9pyd6h6.mca
      Source: unknownProcess created: C:\Users\user\Desktop\MBR.exe C:\Users\user\Desktop\MBR.exe
      Source: C:\Users\user\Desktop\MBR.exeProcess created: C:\Windows\SysWOW64\schtasks.exe schtasks.exe /Create /TN "Windows Update" /ru SYSTEM /SC ONSTART /TR "C:\Users\user\Desktop\MBR.exe"
      Source: C:\Windows\SysWOW64\schtasks.exeProcess created: C:\Windows\System32\conhost.exe C:\Windows\system32\conhost.exe 0xffffffff -ForceV1
      Source: C:\Windows\System32\cmd.exeProcess created: C:\Windows\System32\timeout.exe timeout /t 1
      Source: C:\Windows\System32\cmd.exeProcess created: C:\Windows\System32\reg.exe reg add "HKEY_CURRENT_USER\Control Panel\Desktop" /v "Wallpaper" /t REG_SZ /d "C:\Users\userDesktop\YuuyaCat.bmp" /f
      Source: C:\Windows\System32\cmd.exeProcess created: C:\Windows\System32\rundll32.exe RUNDLL32.EXE user32.dll,UpdatePerUserSystemParameters
      Source: C:\Windows\System32\cmd.exeProcess created: C:\Windows\System32\reg.exe reg add "HKEY_CURRENT_USER\Control Panel\Desktop" /v "Wallpaper" /t REG_SZ /d "C:\Users\userDesktop\YuuyaCat.bmp" /f
      Source: C:\Windows\System32\cmd.exeProcess created: C:\Windows\System32\rundll32.exe RUNDLL32.EXE user32.dll,UpdatePerUserSystemParameters
      Source: C:\Windows\System32\cmd.exeProcess created: C:\Windows\System32\reg.exe reg add "HKEY_CURRENT_USER\Control Panel\Desktop" /v "Wallpaper" /t REG_SZ /d "C:\Users\userDesktop\YuuyaCat.bmp" /f
      Source: C:\Windows\System32\cmd.exeProcess created: C:\Windows\System32\rundll32.exe RUNDLL32.EXE user32.dll,UpdatePerUserSystemParameters
      Source: C:\Windows\System32\cmd.exeProcess created: C:\Windows\System32\reg.exe reg add "HKEY_CURRENT_USER\Control Panel\Desktop" /v "Wallpaper" /t REG_SZ /d "C:\Users\userDesktop\YuuyaCat.bmp" /f
      Source: C:\Windows\System32\cmd.exeProcess created: C:\Windows\System32\rundll32.exe RUNDLL32.EXE user32.dll,UpdatePerUserSystemParameters
      Source: C:\Windows\System32\cmd.exeProcess created: C:\Windows\System32\timeout.exe timeout /t 4
      Source: C:\Windows\System32\cmd.exeProcess created: C:\Users\user\Desktop\IconDance.exe IconDance.exe
      Source: C:\Windows\System32\cmd.exeProcess created: C:\Users\user\Desktop\runaway.exe runaway.exe
      Source: C:\Users\user\Desktop\Busy2.0.exeProcess created: C:\Windows\System32\cmd.exe "C:\Windows\sysnative\cmd" /c "C:\Users\user\AppData\Local\Temp\2A8E.tmp\2A8F.tmp\2A90.bat C:\Users\user\Desktop\Busy2.0.exe"Jump to behavior
      Source: C:\Windows\System32\cmd.exeProcess created: C:\Windows\System32\timeout.exe timeout /t 30Jump to behavior
      Source: C:\Windows\System32\cmd.exeProcess created: C:\Windows\System32\timeout.exe timeout /t 5Jump to behavior
      Source: C:\Windows\System32\cmd.exeProcess created: C:\Windows\System32\timeout.exe timeout /t 1Jump to behavior
      Source: C:\Windows\System32\cmd.exeProcess created: C:\Windows\System32\timeout.exe timeout /t 1Jump to behavior
      Source: C:\Windows\System32\cmd.exeProcess created: C:\Windows\System32\timeout.exe timeout /t 2Jump to behavior
      Source: C:\Windows\System32\cmd.exeProcess created: C:\Windows\System32\timeout.exe timeout /t 4Jump to behavior
      Source: C:\Windows\System32\cmd.exeProcess created: C:\Windows\System32\reg.exe reg add "HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\System" /v DisableTaskMgr /t "REG_DWORD" /d "1" /fJump to behavior
      Source: C:\Windows\System32\cmd.exeProcess created: C:\Users\user\Desktop\MBR.exe MBR.exeJump to behavior
      Source: C:\Windows\System32\cmd.exeProcess created: C:\Windows\System32\timeout.exe timeout /t 1Jump to behavior
      Source: C:\Windows\System32\cmd.exeProcess created: C:\Windows\System32\reg.exe reg add "HKEY_CURRENT_USER\Control Panel\Desktop" /v "Wallpaper" /t REG_SZ /d "C:\Users\userDesktop\YuuyaCat.bmp" /fJump to behavior
      Source: C:\Windows\System32\cmd.exeProcess created: C:\Windows\System32\rundll32.exe RUNDLL32.EXE user32.dll,UpdatePerUserSystemParametersJump to behavior
      Source: C:\Windows\System32\cmd.exeProcess created: C:\Windows\System32\reg.exe reg add "HKEY_CURRENT_USER\Control Panel\Desktop" /v "Wallpaper" /t REG_SZ /d "C:\Users\userDesktop\YuuyaCat.bmp" /fJump to behavior
      Source: C:\Windows\System32\cmd.exeProcess created: C:\Windows\System32\rundll32.exe RUNDLL32.EXE user32.dll,UpdatePerUserSystemParametersJump to behavior
      Source: C:\Windows\System32\cmd.exeProcess created: C:\Windows\System32\reg.exe reg add "HKEY_CURRENT_USER\Control Panel\Desktop" /v "Wallpaper" /t REG_SZ /d "C:\Users\userDesktop\YuuyaCat.bmp" /fJump to behavior
      Source: C:\Windows\System32\cmd.exeProcess created: C:\Windows\System32\rundll32.exe RUNDLL32.EXE user32.dll,UpdatePerUserSystemParametersJump to behavior
      Source: C:\Windows\System32\cmd.exeProcess created: C:\Windows\System32\reg.exe reg add "HKEY_CURRENT_USER\Control Panel\Desktop" /v "Wallpaper" /t REG_SZ /d "C:\Users\userDesktop\YuuyaCat.bmp" /fJump to behavior
      Source: C:\Windows\System32\cmd.exeProcess created: C:\Windows\System32\rundll32.exe RUNDLL32.EXE user32.dll,UpdatePerUserSystemParametersJump to behavior
      Source: C:\Windows\System32\cmd.exeProcess created: C:\Windows\System32\timeout.exe timeout /t 4Jump to behavior
      Source: C:\Windows\System32\cmd.exeProcess created: C:\Users\user\Desktop\IconDance.exe IconDance.exeJump to behavior
      Source: C:\Windows\System32\cmd.exeProcess created: C:\Users\user\Desktop\runaway.exe runaway.exeJump to behavior
      Source: C:\Windows\System32\cmd.exeProcess created: unknown unknownJump to behavior
      Source: C:\Windows\System32\cmd.exeProcess created: unknown unknownJump to behavior
      Source: C:\Windows\System32\cmd.exeProcess created: unknown unknownJump to behavior
      Source: C:\Windows\System32\cmd.exeProcess created: unknown unknownJump to behavior
      Source: C:\Windows\System32\cmd.exeProcess created: unknown unknownJump to behavior
      Source: C:\Windows\System32\cmd.exeProcess created: unknown unknownJump to behavior
      Source: C:\Windows\System32\cmd.exeProcess created: unknown unknownJump to behavior
      Source: C:\Windows\System32\cmd.exeProcess created: unknown unknownJump to behavior
      Source: C:\Windows\System32\cmd.exeProcess created: unknown unknownJump to behavior
      Source: C:\Windows\System32\cmd.exeProcess created: unknown unknownJump to behavior
      Source: C:\Windows\System32\cmd.exeProcess created: unknown unknownJump to behavior
      Source: C:\Windows\System32\cmd.exeProcess created: unknown unknownJump to behavior
      Source: C:\Windows\System32\cmd.exeProcess created: unknown unknownJump to behavior
      Source: C:\Windows\System32\cmd.exeProcess created: unknown unknownJump to behavior
      Source: C:\Windows\System32\cmd.exeProcess created: unknown unknownJump to behavior
      Source: C:\Windows\System32\cmd.exeProcess created: unknown unknownJump to behavior
      Source: C:\Windows\System32\cmd.exeProcess created: unknown unknownJump to behavior
      Source: C:\Windows\System32\cmd.exeProcess created: unknown unknownJump to behavior
      Source: C:\Windows\System32\cmd.exeProcess created: unknown unknownJump to behavior
      Source: C:\Windows\System32\cmd.exeProcess created: unknown unknownJump to behavior
      Source: C:\Windows\System32\cmd.exeProcess created: unknown unknownJump to behavior
      Source: C:\Windows\System32\cmd.exeProcess created: unknown unknownJump to behavior
      Source: C:\Windows\System32\cmd.exeProcess created: unknown unknownJump to behavior
      Source: C:\Windows\System32\cmd.exeProcess created: unknown unknownJump to behavior
      Source: C:\Windows\System32\cmd.exeProcess created: unknown unknownJump to behavior
      Source: C:\Windows\System32\cmd.exeProcess created: unknown unknownJump to behavior
      Source: C:\Windows\System32\cmd.exeProcess created: unknown unknownJump to behavior
      Source: C:\Windows\System32\cmd.exeProcess created: unknown unknownJump to behavior
      Source: C:\Windows\System32\cmd.exeProcess created: unknown unknownJump to behavior
      Source: C:\Windows\System32\cmd.exeProcess created: unknown unknownJump to behavior
      Source: C:\Windows\System32\cmd.exeProcess created: unknown unknownJump to behavior
      Source: C:\Windows\System32\cmd.exeProcess created: unknown unknownJump to behavior
      Source: C:\Windows\System32\cmd.exeProcess created: C:\Windows\System32\reg.exe reg add "HKEY_CURRENT_USER\Control Panel\Desktop" /v "Wallpaper" /t REG_SZ /d "C:\Users\userDesktop\YuuyaCat.bmp" /fJump to behavior
      Source: C:\Windows\System32\cmd.exeProcess created: C:\Windows\System32\rundll32.exe RUNDLL32.EXE user32.dll,UpdatePerUserSystemParametersJump to behavior
      Source: C:\Windows\System32\cmd.exeProcess created: unknown unknownJump to behavior
      Source: C:\Windows\System32\cmd.exeProcess created: unknown unknownJump to behavior
      Source: C:\Windows\System32\cmd.exeProcess created: unknown unknownJump to behavior
      Source: C:\Windows\System32\cmd.exeProcess created: unknown unknownJump to behavior
      Source: C:\Windows\System32\cmd.exeProcess created: unknown unknownJump to behavior
      Source: C:\Windows\System32\cmd.exeProcess created: unknown unknownJump to behavior
      Source: C:\Windows\System32\cmd.exeProcess created: unknown unknownJump to behavior
      Source: C:\Windows\System32\cmd.exeProcess created: unknown unknownJump to behavior
      Source: C:\Windows\System32\cmd.exeProcess created: unknown unknownJump to behavior
      Source: C:\Windows\System32\cmd.exeProcess created: unknown unknownJump to behavior
      Source: C:\Windows\System32\cmd.exeProcess created: unknown unknownJump to behavior
      Source: C:\Users\user\Desktop\MBR.exeProcess created: C:\Windows\SysWOW64\schtasks.exe schtasks.exe /Create /TN "Windows Update" /ru SYSTEM /SC ONSTART /TR "C:\Users\user\Desktop\MBR.exe"Jump to behavior
      Source: C:\Users\user\Desktop\MBR.exeProcess created: C:\Windows\SysWOW64\schtasks.exe schtasks.exe /Create /TN "Windows Update" /ru SYSTEM /SC ONSTART /TR "C:\Users\user\Desktop\MBR.exe"Jump to behavior
      Source: C:\Users\user\Desktop\Busy2.0.exeSection loaded: apphelp.dllJump to behavior
      Source: C:\Users\user\Desktop\Busy2.0.exeSection loaded: winmm.dllJump to behavior
      Source: C:\Users\user\Desktop\Busy2.0.exeSection loaded: kernel.appcore.dllJump to behavior
      Source: C:\Users\user\Desktop\Busy2.0.exeSection loaded: uxtheme.dllJump to behavior
      Source: C:\Windows\System32\cmd.exeSection loaded: cmdext.dllJump to behavior
      Source: C:\Windows\System32\cmd.exeSection loaded: apphelp.dllJump to behavior
      Source: C:\Windows\System32\cmd.exeSection loaded: kernel.appcore.dllJump to behavior
      Source: C:\Windows\System32\cmd.exeSection loaded: uxtheme.dllJump to behavior
      Source: C:\Windows\System32\cmd.exeSection loaded: windows.storage.dllJump to behavior
      Source: C:\Windows\System32\cmd.exeSection loaded: wldp.dllJump to behavior
      Source: C:\Windows\System32\cmd.exeSection loaded: propsys.dllJump to behavior
      Source: C:\Windows\System32\cmd.exeSection loaded: edputil.dllJump to behavior
      Source: C:\Windows\System32\cmd.exeSection loaded: urlmon.dllJump to behavior
      Source: C:\Windows\System32\cmd.exeSection loaded: iertutil.dllJump to behavior
      Source: C:\Windows\System32\cmd.exeSection loaded: srvcli.dllJump to behavior
      Source: C:\Windows\System32\cmd.exeSection loaded: netutils.dllJump to behavior
      Source: C:\Windows\System32\cmd.exeSection loaded: windows.staterepositoryps.dllJump to behavior
      Source: C:\Windows\System32\cmd.exeSection loaded: wintypes.dllJump to behavior
      Source: C:\Windows\System32\cmd.exeSection loaded: policymanager.dllJump to behavior
      Source: C:\Windows\System32\cmd.exeSection loaded: msvcp110_win.dllJump to behavior
      Source: C:\Windows\System32\cmd.exeSection loaded: sspicli.dllJump to behavior
      Source: C:\Windows\System32\cmd.exeSection loaded: twinui.appcore.dllJump to behavior
      Source: C:\Windows\System32\cmd.exeSection loaded: onecoreuapcommonproxystub.dllJump to behavior
      Source: C:\Windows\System32\cmd.exeSection loaded: execmodelproxy.dllJump to behavior
      Source: C:\Windows\System32\cmd.exeSection loaded: mrmcorer.dllJump to behavior
      Source: C:\Windows\System32\cmd.exeSection loaded: windows.staterepositorycore.dllJump to behavior
      Source: C:\Windows\System32\cmd.exeSection loaded: profapi.dllJump to behavior
      Source: C:\Windows\System32\cmd.exeSection loaded: appxdeploymentclient.dllJump to behavior
      Source: C:\Windows\System32\cmd.exeSection loaded: bcp47mrm.dllJump to behavior
      Source: C:\Windows\System32\cmd.exeSection loaded: windows.ui.dllJump to behavior
      Source: C:\Windows\System32\cmd.exeSection loaded: windowmanagementapi.dllJump to behavior
      Source: C:\Windows\System32\cmd.exeSection loaded: textinputframework.dllJump to behavior
      Source: C:\Windows\System32\cmd.exeSection loaded: inputhost.dllJump to behavior
      Source: C:\Windows\System32\cmd.exeSection loaded: twinapi.appcore.dllJump to behavior
      Source: C:\Windows\System32\cmd.exeSection loaded: coremessaging.dllJump to behavior
      Source: C:\Windows\System32\cmd.exeSection loaded: twinapi.appcore.dllJump to behavior
      Source: C:\Windows\System32\cmd.exeSection loaded: coreuicomponents.dllJump to behavior
      Source: C:\Windows\System32\cmd.exeSection loaded: coremessaging.dllJump to behavior
      Source: C:\Windows\System32\cmd.exeSection loaded: coremessaging.dllJump to behavior
      Source: C:\Windows\System32\cmd.exeSection loaded: coreuicomponents.dllJump to behavior
      Source: C:\Windows\System32\cmd.exeSection loaded: ntmarta.dllJump to behavior
      Source: C:\Windows\System32\timeout.exeSection loaded: version.dllJump to behavior
      Source: C:\Windows\System32\timeout.exeSection loaded: version.dllJump to behavior
      Source: C:\Windows\System32\timeout.exeSection loaded: version.dllJump to behavior
      Source: C:\Windows\System32\timeout.exeSection loaded: version.dllJump to behavior
      Source: C:\Windows\System32\timeout.exeSection loaded: version.dllJump to behavior
      Source: C:\Windows\System32\timeout.exeSection loaded: version.dllJump to behavior
      Source: C:\Users\user\Desktop\MBR.exeSection loaded: apphelp.dllJump to behavior
      Source: C:\Windows\SysWOW64\schtasks.exeSection loaded: kernel.appcore.dllJump to behavior
      Source: C:\Windows\SysWOW64\schtasks.exeSection loaded: taskschd.dllJump to behavior
      Source: C:\Windows\SysWOW64\schtasks.exeSection loaded: sspicli.dllJump to behavior
      Source: C:\Windows\SysWOW64\schtasks.exeSection loaded: xmllite.dllJump to behavior
      Source: C:\Program Files\WindowsApps\Microsoft.ZuneMusic_10.19071.19011.0_x64__8wekyb3d8bbwe\Music.UI.exeSection loaded: d3d11.dllJump to behavior
      Source: C:\Program Files\WindowsApps\Microsoft.ZuneMusic_10.19071.19011.0_x64__8wekyb3d8bbwe\Music.UI.exeSection loaded: sharedui.dllJump to behavior
      Source: C:\Program Files\WindowsApps\Microsoft.ZuneMusic_10.19071.19011.0_x64__8wekyb3d8bbwe\Music.UI.exeSection loaded: vccorlib140_app.dllJump to behavior
      Source: C:\Program Files\WindowsApps\Microsoft.ZuneMusic_10.19071.19011.0_x64__8wekyb3d8bbwe\Music.UI.exeSection loaded: msvcp140_app.dllJump to behavior
      Source: C:\Program Files\WindowsApps\Microsoft.ZuneMusic_10.19071.19011.0_x64__8wekyb3d8bbwe\Music.UI.exeSection loaded: concrt140_app.dllJump to behavior
      Source: C:\Program Files\WindowsApps\Microsoft.ZuneMusic_10.19071.19011.0_x64__8wekyb3d8bbwe\Music.UI.exeSection loaded: vcruntime140_app.dllJump to behavior
      Source: C:\Program Files\WindowsApps\Microsoft.ZuneMusic_10.19071.19011.0_x64__8wekyb3d8bbwe\Music.UI.exeSection loaded: dxgi.dllJump to behavior
      Source: C:\Program Files\WindowsApps\Microsoft.ZuneMusic_10.19071.19011.0_x64__8wekyb3d8bbwe\Music.UI.exeSection loaded: vcruntime140_app.dllJump to behavior
      Source: C:\Program Files\WindowsApps\Microsoft.ZuneMusic_10.19071.19011.0_x64__8wekyb3d8bbwe\Music.UI.exeSection loaded: msvcp140_app.dllJump to behavior
      Source: C:\Program Files\WindowsApps\Microsoft.ZuneMusic_10.19071.19011.0_x64__8wekyb3d8bbwe\Music.UI.exeSection loaded: vcruntime140_app.dllJump to behavior
      Source: C:\Program Files\WindowsApps\Microsoft.ZuneMusic_10.19071.19011.0_x64__8wekyb3d8bbwe\Music.UI.exeSection loaded: concrt140_app.dllJump to behavior
      Source: C:\Program Files\WindowsApps\Microsoft.ZuneMusic_10.19071.19011.0_x64__8wekyb3d8bbwe\Music.UI.exeSection loaded: kernel.appcore.dllJump to behavior
      Source: C:\Program Files\WindowsApps\Microsoft.ZuneMusic_10.19071.19011.0_x64__8wekyb3d8bbwe\Music.UI.exeSection loaded: windows.ui.xaml.dllJump to behavior
      Source: C:\Program Files\WindowsApps\Microsoft.ZuneMusic_10.19071.19011.0_x64__8wekyb3d8bbwe\Music.UI.exeSection loaded: coremessaging.dllJump to behavior
      Source: C:\Program Files\WindowsApps\Microsoft.ZuneMusic_10.19071.19011.0_x64__8wekyb3d8bbwe\Music.UI.exeSection loaded: bcp47langs.dllJump to behavior
      Source: C:\Program Files\WindowsApps\Microsoft.ZuneMusic_10.19071.19011.0_x64__8wekyb3d8bbwe\Music.UI.exeSection loaded: iertutil.dllJump to behavior
      Source: C:\Program Files\WindowsApps\Microsoft.ZuneMusic_10.19071.19011.0_x64__8wekyb3d8bbwe\Music.UI.exeSection loaded: dcomp.dllJump to behavior
      Source: C:\Program Files\WindowsApps\Microsoft.ZuneMusic_10.19071.19011.0_x64__8wekyb3d8bbwe\Music.UI.exeSection loaded: twinapi.appcore.dllJump to behavior
      Source: C:\Program Files\WindowsApps\Microsoft.ZuneMusic_10.19071.19011.0_x64__8wekyb3d8bbwe\Music.UI.exeSection loaded: wintypes.dllJump to behavior
      Source: C:\Program Files\WindowsApps\Microsoft.ZuneMusic_10.19071.19011.0_x64__8wekyb3d8bbwe\Music.UI.exeSection loaded: windows.staterepositorycore.dllJump to behavior
      Source: C:\Program Files\WindowsApps\Microsoft.ZuneMusic_10.19071.19011.0_x64__8wekyb3d8bbwe\Music.UI.exeSection loaded: windows.ui.dllJump to behavior
      Source: C:\Program Files\WindowsApps\Microsoft.ZuneMusic_10.19071.19011.0_x64__8wekyb3d8bbwe\Music.UI.exeSection loaded: windowmanagementapi.dllJump to behavior
      Source: C:\Program Files\WindowsApps\Microsoft.ZuneMusic_10.19071.19011.0_x64__8wekyb3d8bbwe\Music.UI.exeSection loaded: textinputframework.dllJump to behavior
      Source: C:\Program Files\WindowsApps\Microsoft.ZuneMusic_10.19071.19011.0_x64__8wekyb3d8bbwe\Music.UI.exeSection loaded: inputhost.dllJump to behavior
      Source: C:\Program Files\WindowsApps\Microsoft.ZuneMusic_10.19071.19011.0_x64__8wekyb3d8bbwe\Music.UI.exeSection loaded: coreuicomponents.dllJump to behavior
      Source: C:\Program Files\WindowsApps\Microsoft.ZuneMusic_10.19071.19011.0_x64__8wekyb3d8bbwe\Music.UI.exeSection loaded: propsys.dllJump to behavior
      Source: C:\Program Files\WindowsApps\Microsoft.ZuneMusic_10.19071.19011.0_x64__8wekyb3d8bbwe\Music.UI.exeSection loaded: coreuicomponents.dllJump to behavior
      Source: C:\Program Files\WindowsApps\Microsoft.ZuneMusic_10.19071.19011.0_x64__8wekyb3d8bbwe\Music.UI.exeSection loaded: ntmarta.dllJump to behavior
      Source: C:\Program Files\WindowsApps\Microsoft.ZuneMusic_10.19071.19011.0_x64__8wekyb3d8bbwe\Music.UI.exeSection loaded: onecoreuapcommonproxystub.dllJump to behavior
      Source: C:\Program Files\WindowsApps\Microsoft.ZuneMusic_10.19071.19011.0_x64__8wekyb3d8bbwe\Music.UI.exeSection loaded: uxtheme.dllJump to behavior
      Source: C:\Program Files\WindowsApps\Microsoft.ZuneMusic_10.19071.19011.0_x64__8wekyb3d8bbwe\Music.UI.exeSection loaded: urlmon.dllJump to behavior
      Source: C:\Program Files\WindowsApps\Microsoft.ZuneMusic_10.19071.19011.0_x64__8wekyb3d8bbwe\Music.UI.exeSection loaded: srvcli.dllJump to behavior
      Source: C:\Program Files\WindowsApps\Microsoft.ZuneMusic_10.19071.19011.0_x64__8wekyb3d8bbwe\Music.UI.exeSection loaded: netutils.dllJump to behavior
      Source: C:\Program Files\WindowsApps\Microsoft.ZuneMusic_10.19071.19011.0_x64__8wekyb3d8bbwe\Music.UI.exeSection loaded: resourcepolicyclient.dllJump to behavior
      Source: C:\Program Files\WindowsApps\Microsoft.ZuneMusic_10.19071.19011.0_x64__8wekyb3d8bbwe\Music.UI.exeSection loaded: d3d10warp.dllJump to behavior
      Source: C:\Program Files\WindowsApps\Microsoft.ZuneMusic_10.19071.19011.0_x64__8wekyb3d8bbwe\Music.UI.exeSection loaded: dxcore.dllJump to behavior
      Source: C:\Program Files\WindowsApps\Microsoft.ZuneMusic_10.19071.19011.0_x64__8wekyb3d8bbwe\Music.UI.exeSection loaded: rometadata.dllJump to behavior
      Source: C:\Program Files\WindowsApps\Microsoft.ZuneMusic_10.19071.19011.0_x64__8wekyb3d8bbwe\Music.UI.exeSection loaded: d2d1.dllJump to behavior
      Source: C:\Program Files\WindowsApps\Microsoft.ZuneMusic_10.19071.19011.0_x64__8wekyb3d8bbwe\Music.UI.exeSection loaded: dwrite.dllJump to behavior
      Source: C:\Program Files\WindowsApps\Microsoft.ZuneMusic_10.19071.19011.0_x64__8wekyb3d8bbwe\Music.UI.exeSection loaded: textshaping.dllJump to behavior
      Source: C:\Program Files\WindowsApps\Microsoft.ZuneMusic_10.19071.19011.0_x64__8wekyb3d8bbwe\Music.UI.exeSection loaded: windows.applicationmodel.dllJump to behavior
      Source: C:\Program Files\WindowsApps\Microsoft.ZuneMusic_10.19071.19011.0_x64__8wekyb3d8bbwe\Music.UI.exeSection loaded: esent.dllJump to behavior
      Source: C:\Program Files\WindowsApps\Microsoft.ZuneMusic_10.19071.19011.0_x64__8wekyb3d8bbwe\Music.UI.exeSection loaded: windows.storage.applicationdata.dllJump to behavior
      Source: C:\Program Files\WindowsApps\Microsoft.ZuneMusic_10.19071.19011.0_x64__8wekyb3d8bbwe\Music.UI.exeSection loaded: windows.storage.dllJump to behavior
      Source: C:\Program Files\WindowsApps\Microsoft.ZuneMusic_10.19071.19011.0_x64__8wekyb3d8bbwe\Music.UI.exeSection loaded: wldp.dllJump to behavior
      Source: C:\Program Files\WindowsApps\Microsoft.ZuneMusic_10.19071.19011.0_x64__8wekyb3d8bbwe\Music.UI.exeSection loaded: logoncli.dllJump to behavior
      Source: C:\Program Files\WindowsApps\Microsoft.ZuneMusic_10.19071.19011.0_x64__8wekyb3d8bbwe\Music.UI.exeSection loaded: mrmcorer.dllJump to behavior
      Source: C:\Program Files\WindowsApps\Microsoft.ZuneMusic_10.19071.19011.0_x64__8wekyb3d8bbwe\Music.UI.exeSection loaded: windows.staterepositoryclient.dllJump to behavior
      Source: C:\Program Files\WindowsApps\Microsoft.ZuneMusic_10.19071.19011.0_x64__8wekyb3d8bbwe\Music.UI.exeSection loaded: profapi.dllJump to behavior
      Source: C:\Program Files\WindowsApps\Microsoft.ZuneMusic_10.19071.19011.0_x64__8wekyb3d8bbwe\Music.UI.exeSection loaded: appxdeploymentclient.dllJump to behavior
      Source: C:\Program Files\WindowsApps\Microsoft.ZuneMusic_10.19071.19011.0_x64__8wekyb3d8bbwe\Music.UI.exeSection loaded: bcp47mrm.dllJump to behavior
      Source: C:\Program Files\WindowsApps\Microsoft.ZuneMusic_10.19071.19011.0_x64__8wekyb3d8bbwe\Music.UI.exeSection loaded: cryptbase.dllJump to behavior
      Source: C:\Program Files\WindowsApps\Microsoft.ZuneMusic_10.19071.19011.0_x64__8wekyb3d8bbwe\Music.UI.exeSection loaded: windows.ui.xaml.controls.dllJump to behavior
      Source: C:\Program Files\WindowsApps\Microsoft.ZuneMusic_10.19071.19011.0_x64__8wekyb3d8bbwe\Music.UI.exeSection loaded: windows.shell.servicehostbuilder.dllJump to behavior
      Source: C:\Program Files\WindowsApps\Microsoft.ZuneMusic_10.19071.19011.0_x64__8wekyb3d8bbwe\Music.UI.exeSection loaded: execmodelproxy.dllJump to behavior
      Source: C:\Program Files\WindowsApps\Microsoft.ZuneMusic_10.19071.19011.0_x64__8wekyb3d8bbwe\Music.UI.exeSection loaded: rmclient.dllJump to behavior
      Source: C:\Program Files\WindowsApps\Microsoft.ZuneMusic_10.19071.19011.0_x64__8wekyb3d8bbwe\Music.UI.exeSection loaded: uiamanager.dllJump to behavior
      Source: C:\Program Files\WindowsApps\Microsoft.ZuneMusic_10.19071.19011.0_x64__8wekyb3d8bbwe\Music.UI.exeSection loaded: windows.ui.core.textinput.dllJump to behavior
      Source: C:\Program Files\WindowsApps\Microsoft.ZuneMusic_10.19071.19011.0_x64__8wekyb3d8bbwe\Music.UI.exeSection loaded: windows.ui.immersive.dllJump to behavior
      Source: C:\Program Files\WindowsApps\Microsoft.ZuneMusic_10.19071.19011.0_x64__8wekyb3d8bbwe\Music.UI.exeSection loaded: dataexchange.dllJump to behavior
      Source: C:\Program Files\WindowsApps\Microsoft.ZuneMusic_10.19071.19011.0_x64__8wekyb3d8bbwe\Music.UI.exeSection loaded: threadpoolwinrt.dllJump to behavior
      Source: C:\Program Files\WindowsApps\Microsoft.ZuneMusic_10.19071.19011.0_x64__8wekyb3d8bbwe\Music.UI.exeSection loaded: windows.globalization.dllJump to behavior
      Source: C:\Program Files\WindowsApps\Microsoft.ZuneMusic_10.19071.19011.0_x64__8wekyb3d8bbwe\Music.UI.exeSection loaded: windows.system.profile.retailinfo.dllJump to behavior
      Source: C:\Program Files\WindowsApps\Microsoft.ZuneMusic_10.19071.19011.0_x64__8wekyb3d8bbwe\Music.UI.exeSection loaded: windows.media.dllJump to behavior
      Source: C:\Program Files\WindowsApps\Microsoft.ZuneMusic_10.19071.19011.0_x64__8wekyb3d8bbwe\Music.UI.exeSection loaded: windows.applicationmodel.lockscreen.dllJump to behavior
      Source: C:\Program Files\WindowsApps\Microsoft.ZuneMusic_10.19071.19011.0_x64__8wekyb3d8bbwe\Music.UI.exeSection loaded: wincorlib.dllJump to behavior
      Source: C:\Program Files\WindowsApps\Microsoft.ZuneMusic_10.19071.19011.0_x64__8wekyb3d8bbwe\Music.UI.exeSection loaded: lockappbroker.dllJump to behavior
      Source: C:\Program Files\WindowsApps\Microsoft.ZuneMusic_10.19071.19011.0_x64__8wekyb3d8bbwe\Music.UI.exeSection loaded: msvcp110_win.dllJump to behavior
      Source: C:\Program Files\WindowsApps\Microsoft.ZuneMusic_10.19071.19011.0_x64__8wekyb3d8bbwe\Music.UI.exeSection loaded: powrprof.dllJump to behavior
      Source: C:\Program Files\WindowsApps\Microsoft.ZuneMusic_10.19071.19011.0_x64__8wekyb3d8bbwe\Music.UI.exeSection loaded: umpdc.dllJump to behavior
      Source: C:\Program Files\WindowsApps\Microsoft.ZuneMusic_10.19071.19011.0_x64__8wekyb3d8bbwe\Music.UI.exeSection loaded: windows.graphics.dllJump to behavior
      Source: C:\Program Files\WindowsApps\Microsoft.ZuneMusic_10.19071.19011.0_x64__8wekyb3d8bbwe\Music.UI.exeSection loaded: windows.ui.xaml.phone.dllJump to behavior
      Source: C:\Program Files\WindowsApps\Microsoft.ZuneMusic_10.19071.19011.0_x64__8wekyb3d8bbwe\Music.UI.exeSection loaded: twinapi.dllJump to behavior
      Source: C:\Program Files\WindowsApps\Microsoft.ZuneMusic_10.19071.19011.0_x64__8wekyb3d8bbwe\Music.UI.exeSection loaded: windows.networking.connectivity.dllJump to behavior
      Source: C:\Program Files\WindowsApps\Microsoft.ZuneMusic_10.19071.19011.0_x64__8wekyb3d8bbwe\Music.UI.exeSection loaded: windows.media.playback.mediaplayer.dllJump to behavior
      Source: C:\Program Files\WindowsApps\Microsoft.ZuneMusic_10.19071.19011.0_x64__8wekyb3d8bbwe\Music.UI.exeSection loaded: mfplat.dllJump to behavior
      Source: C:\Program Files\WindowsApps\Microsoft.ZuneMusic_10.19071.19011.0_x64__8wekyb3d8bbwe\Music.UI.exeSection loaded: rtworkq.dllJump to behavior
      Source: C:\Program Files\WindowsApps\Microsoft.ZuneMusic_10.19071.19011.0_x64__8wekyb3d8bbwe\Music.UI.exeSection loaded: windows.media.mediacontrol.dllJump to behavior
      Source: C:\Program Files\WindowsApps\Microsoft.ZuneMusic_10.19071.19011.0_x64__8wekyb3d8bbwe\Music.UI.exeSection loaded: mmdevapi.dllJump to behavior
      Source: C:\Program Files\WindowsApps\Microsoft.ZuneMusic_10.19071.19011.0_x64__8wekyb3d8bbwe\Music.UI.exeSection loaded: devobj.dllJump to behavior
      Source: C:\Program Files\WindowsApps\Microsoft.ZuneMusic_10.19071.19011.0_x64__8wekyb3d8bbwe\Music.UI.exeSection loaded: mfmediaengine.dllJump to behavior
      Source: C:\Program Files\WindowsApps\Microsoft.ZuneMusic_10.19071.19011.0_x64__8wekyb3d8bbwe\Music.UI.exeSection loaded: xmllite.dllJump to behavior
      Source: C:\Program Files\WindowsApps\Microsoft.ZuneMusic_10.19071.19011.0_x64__8wekyb3d8bbwe\Music.UI.exeSection loaded: audioses.dllJump to behavior
      Source: C:\Program Files\WindowsApps\Microsoft.ZuneMusic_10.19071.19011.0_x64__8wekyb3d8bbwe\Music.UI.exeSection loaded: windows.media.devices.dllJump to behavior
      Source: C:\Program Files\WindowsApps\Microsoft.ZuneMusic_10.19071.19011.0_x64__8wekyb3d8bbwe\Music.UI.exeSection loaded: windows.media.playback.proxystub.dllJump to behavior
      Source: C:\Program Files\WindowsApps\Microsoft.ZuneMusic_10.19071.19011.0_x64__8wekyb3d8bbwe\Music.UI.exeSection loaded: comppkgsup.dllJump to behavior
      Source: C:\Program Files\WindowsApps\Microsoft.ZuneMusic_10.19071.19011.0_x64__8wekyb3d8bbwe\Music.UI.exeSection loaded: directmanipulation.dllJump to behavior
      Source: C:\Program Files\WindowsApps\Microsoft.ZuneMusic_10.19071.19011.0_x64__8wekyb3d8bbwe\Music.UI.exeSection loaded: msftedit.dllJump to behavior
      Source: C:\Program Files\WindowsApps\Microsoft.ZuneMusic_10.19071.19011.0_x64__8wekyb3d8bbwe\Music.UI.exeSection loaded: globinputhost.dllJump to behavior
      Source: C:\Program Files\WindowsApps\Microsoft.ZuneMusic_10.19071.19011.0_x64__8wekyb3d8bbwe\Music.UI.exeSection loaded: msxml6.dllJump to behavior
      Source: C:\Program Files\WindowsApps\Microsoft.ZuneMusic_10.19071.19011.0_x64__8wekyb3d8bbwe\Music.UI.exeSection loaded: wpnapps.dllJump to behavior
      Source: C:\Program Files\WindowsApps\Microsoft.ZuneMusic_10.19071.19011.0_x64__8wekyb3d8bbwe\Music.UI.exeSection loaded: windows.web.dllJump to behavior
      Source: C:\Program Files\WindowsApps\Microsoft.ZuneMusic_10.19071.19011.0_x64__8wekyb3d8bbwe\Music.UI.exeSection loaded: windows.devices.enumeration.dllJump to behavior
      Source: C:\Program Files\WindowsApps\Microsoft.ZuneMusic_10.19071.19011.0_x64__8wekyb3d8bbwe\Music.UI.exeSection loaded: windowscodecs.dllJump to behavior
      Source: C:\Program Files\WindowsApps\Microsoft.ZuneMusic_10.19071.19011.0_x64__8wekyb3d8bbwe\Music.UI.exeSection loaded: devdispitemprovider.dllJump to behavior
      Source: C:\Program Files\WindowsApps\Microsoft.ZuneMusic_10.19071.19011.0_x64__8wekyb3d8bbwe\Music.UI.exeSection loaded: ddores.dllJump to behavior
      Source: C:\Program Files\WindowsApps\Microsoft.ZuneMusic_10.19071.19011.0_x64__8wekyb3d8bbwe\Music.UI.exeSection loaded: defaultdevicemanager.dllJump to behavior
      Source: C:\Program Files\WindowsApps\Microsoft.ZuneMusic_10.19071.19011.0_x64__8wekyb3d8bbwe\Music.UI.exeSection loaded: photometadatahandler.dllJump to behavior
      Source: C:\Program Files\WindowsApps\Microsoft.ZuneMusic_10.19071.19011.0_x64__8wekyb3d8bbwe\Music.UI.exeSection loaded: wuceffects.dllJump to behavior
      Source: C:\Program Files\WindowsApps\Microsoft.ZuneMusic_10.19071.19011.0_x64__8wekyb3d8bbwe\Music.UI.exeSection loaded: wininet.dllJump to behavior
      Source: C:\Program Files\WindowsApps\Microsoft.ZuneMusic_10.19071.19011.0_x64__8wekyb3d8bbwe\Music.UI.exeSection loaded: windows.networking.backgroundtransfer.dllJump to behavior
      Source: C:\Program Files\WindowsApps\Microsoft.ZuneMusic_10.19071.19011.0_x64__8wekyb3d8bbwe\Music.UI.exeSection loaded: systemeventsbrokerclient.dllJump to behavior
      Source: C:\Program Files\WindowsApps\Microsoft.ZuneMusic_10.19071.19011.0_x64__8wekyb3d8bbwe\Music.UI.exeSection loaded: sspicli.dllJump to behavior
      Source: C:\Program Files\WindowsApps\Microsoft.ZuneMusic_10.19071.19011.0_x64__8wekyb3d8bbwe\Music.UI.exeSection loaded: userenv.dllJump to behavior
      Source: C:\Program Files\WindowsApps\Microsoft.ZuneMusic_10.19071.19011.0_x64__8wekyb3d8bbwe\Music.UI.exeSection loaded: profext.dllJump to behavior
      Source: C:\Program Files\WindowsApps\Microsoft.ZuneMusic_10.19071.19011.0_x64__8wekyb3d8bbwe\Music.UI.exeSection loaded: ondemandconnroutehelper.dllJump to behavior
      Source: C:\Program Files\WindowsApps\Microsoft.ZuneMusic_10.19071.19011.0_x64__8wekyb3d8bbwe\Music.UI.exeSection loaded: winhttp.dllJump to behavior
      Source: C:\Program Files\WindowsApps\Microsoft.ZuneMusic_10.19071.19011.0_x64__8wekyb3d8bbwe\Music.UI.exeSection loaded: mswsock.dllJump to behavior
      Source: C:\Program Files\WindowsApps\Microsoft.ZuneMusic_10.19071.19011.0_x64__8wekyb3d8bbwe\Music.UI.exeSection loaded: iphlpapi.dllJump to behavior
      Source: C:\Program Files\WindowsApps\Microsoft.ZuneMusic_10.19071.19011.0_x64__8wekyb3d8bbwe\Music.UI.exeSection loaded: winnsi.dllJump to behavior
      Source: C:\Program Files\WindowsApps\Microsoft.ZuneMusic_10.19071.19011.0_x64__8wekyb3d8bbwe\Music.UI.exeSection loaded: biwinrt.dllJump to behavior
      Source: C:\Program Files\WindowsApps\Microsoft.ZuneMusic_10.19071.19011.0_x64__8wekyb3d8bbwe\Music.UI.exeSection loaded: dnsapi.dllJump to behavior
      Source: C:\Program Files\WindowsApps\Microsoft.ZuneMusic_10.19071.19011.0_x64__8wekyb3d8bbwe\Music.UI.exeSection loaded: rasadhlp.dllJump to behavior
      Source: C:\Program Files\WindowsApps\Microsoft.ZuneMusic_10.19071.19011.0_x64__8wekyb3d8bbwe\Music.UI.exeSection loaded: fwpuclnt.dllJump to behavior
      Source: C:\Program Files\WindowsApps\Microsoft.ZuneMusic_10.19071.19011.0_x64__8wekyb3d8bbwe\Music.UI.exeSection loaded: schannel.dllJump to behavior
      Source: C:\Program Files\WindowsApps\Microsoft.ZuneMusic_10.19071.19011.0_x64__8wekyb3d8bbwe\Music.UI.exeSection loaded: windows.security.authentication.web.core.dllJump to behavior
      Source: C:\Program Files\WindowsApps\Microsoft.ZuneMusic_10.19071.19011.0_x64__8wekyb3d8bbwe\Music.UI.exeSection loaded: onecorecommonproxystub.dllJump to behavior
      Source: C:\Program Files\WindowsApps\Microsoft.ZuneMusic_10.19071.19011.0_x64__8wekyb3d8bbwe\Music.UI.exeSection loaded: vaultcli.dllJump to behavior
      Source: C:\Program Files\WindowsApps\Microsoft.ZuneMusic_10.19071.19011.0_x64__8wekyb3d8bbwe\Music.UI.exeSection loaded: windows.staterepositoryps.dllJump to behavior
      Source: C:\Program Files\WindowsApps\Microsoft.ZuneMusic_10.19071.19011.0_x64__8wekyb3d8bbwe\Music.UI.exeSection loaded: microsoftaccountwamextension.dllJump to behavior
      Source: C:\Program Files\WindowsApps\Microsoft.ZuneMusic_10.19071.19011.0_x64__8wekyb3d8bbwe\Music.UI.exeSection loaded: mskeyprotect.dllJump to behavior
      Source: C:\Program Files\WindowsApps\Microsoft.ZuneMusic_10.19071.19011.0_x64__8wekyb3d8bbwe\Music.UI.exeSection loaded: ntasn1.dllJump to behavior
      Source: C:\Program Files\WindowsApps\Microsoft.ZuneMusic_10.19071.19011.0_x64__8wekyb3d8bbwe\Music.UI.exeSection loaded: ncrypt.dllJump to behavior
      Source: C:\Program Files\WindowsApps\Microsoft.ZuneMusic_10.19071.19011.0_x64__8wekyb3d8bbwe\Music.UI.exeSection loaded: ncryptsslp.dllJump to behavior
      Source: C:\Program Files\WindowsApps\Microsoft.ZuneMusic_10.19071.19011.0_x64__8wekyb3d8bbwe\Music.UI.exeSection loaded: msasn1.dllJump to behavior
      Source: C:\Program Files\WindowsApps\Microsoft.ZuneMusic_10.19071.19011.0_x64__8wekyb3d8bbwe\Music.UI.exeSection loaded: dpapi.dllJump to behavior
      Source: C:\Program Files\WindowsApps\Microsoft.ZuneMusic_10.19071.19011.0_x64__8wekyb3d8bbwe\Music.UI.exeSection loaded: cryptsp.dllJump to behavior
      Source: C:\Program Files\WindowsApps\Microsoft.ZuneMusic_10.19071.19011.0_x64__8wekyb3d8bbwe\Music.UI.exeSection loaded: rsaenh.dllJump to behavior
      Source: C:\Program Files\WindowsApps\Microsoft.ZuneMusic_10.19071.19011.0_x64__8wekyb3d8bbwe\Music.UI.exeSection loaded: gpapi.dllJump to behavior
      Source: C:\Program Files\WindowsApps\Microsoft.ZuneMusic_10.19071.19011.0_x64__8wekyb3d8bbwe\Music.UI.exeSection loaded: mfsrcsnk.dllJump to behavior
      Source: C:\Program Files\WindowsApps\Microsoft.ZuneMusic_10.19071.19011.0_x64__8wekyb3d8bbwe\Music.UI.exeSection loaded: mfcore.dllJump to behavior
      Source: C:\Program Files\WindowsApps\Microsoft.ZuneMusic_10.19071.19011.0_x64__8wekyb3d8bbwe\Music.UI.exeSection loaded: ksuser.dllJump to behavior
      Source: C:\Program Files\WindowsApps\Microsoft.ZuneMusic_10.19071.19011.0_x64__8wekyb3d8bbwe\Music.UI.exeSection loaded: avrt.dllJump to behavior
      Source: C:\Program Files\WindowsApps\Microsoft.ZuneMusic_10.19071.19011.0_x64__8wekyb3d8bbwe\Music.UI.exeSection loaded: resourcepolicyclient.dllJump to behavior
      Source: C:\Program Files\WindowsApps\Microsoft.ZuneMusic_10.19071.19011.0_x64__8wekyb3d8bbwe\Music.UI.exeSection loaded: resampledmo.dllJump to behavior
      Source: C:\Program Files\WindowsApps\Microsoft.ZuneMusic_10.19071.19011.0_x64__8wekyb3d8bbwe\Music.UI.exeSection loaded: msdmo.dllJump to behavior
      Source: C:\Program Files\WindowsApps\Microsoft.ZuneMusic_10.19071.19011.0_x64__8wekyb3d8bbwe\Music.UI.exeSection loaded: gnsdk_fp.dllJump to behavior
      Source: C:\Windows\SysWOW64\schtasks.exeSection loaded: kernel.appcore.dllJump to behavior
      Source: C:\Windows\SysWOW64\schtasks.exeSection loaded: taskschd.dllJump to behavior
      Source: C:\Windows\SysWOW64\schtasks.exeSection loaded: sspicli.dllJump to behavior
      Source: C:\Windows\SysWOW64\schtasks.exeSection loaded: xmllite.dllJump to behavior
      Source: C:\Windows\System32\timeout.exeSection loaded: version.dllJump to behavior
      Source: C:\Windows\System32\timeout.exeSection loaded: version.dll
      Source: C:\Users\user\Desktop\IconDance.exeSection loaded: apphelp.dll
      Source: C:\Users\user\Desktop\IconDance.exeSection loaded: uxtheme.dll
      Source: C:\Users\user\Desktop\runaway.exeSection loaded: mscoree.dll
      Source: C:\Users\user\Desktop\runaway.exeSection loaded: apphelp.dll
      Source: C:\Users\user\Desktop\runaway.exeSection loaded: kernel.appcore.dll
      Source: C:\Users\user\Desktop\runaway.exeSection loaded: version.dll
      Source: C:\Users\user\Desktop\runaway.exeSection loaded: vcruntime140_clr0400.dll
      Source: C:\Users\user\Desktop\runaway.exeSection loaded: ucrtbase_clr0400.dll
      Source: C:\Users\user\Desktop\runaway.exeSection loaded: ucrtbase_clr0400.dll
      Source: C:\Users\user\Desktop\runaway.exeSection loaded: textshaping.dll
      Source: C:\Users\user\Desktop\runaway.exeSection loaded: uxtheme.dll
      Source: C:\Users\user\Desktop\runaway.exeSection loaded: textinputframework.dll
      Source: C:\Users\user\Desktop\runaway.exeSection loaded: coreuicomponents.dll
      Source: C:\Users\user\Desktop\runaway.exeSection loaded: coremessaging.dll
      Source: C:\Users\user\Desktop\runaway.exeSection loaded: ntmarta.dll
      Source: C:\Users\user\Desktop\runaway.exeSection loaded: wintypes.dll
      Source: C:\Users\user\Desktop\runaway.exeSection loaded: wintypes.dll
      Source: C:\Users\user\Desktop\runaway.exeSection loaded: wintypes.dll
      Source: C:\Program Files\WindowsApps\Microsoft.ZuneMusic_10.19071.19011.0_x64__8wekyb3d8bbwe\Music.UI.exeKey value queried: HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{95E15D0A-66E6-93D9-C53C-76E6219D3341}\InProcServer32Jump to behavior
      Source: C:\Program Files\WindowsApps\Microsoft.ZuneMusic_10.19071.19011.0_x64__8wekyb3d8bbwe\Music.UI.exeFile opened: C:\Windows\SYSTEM32\msftedit.dllJump to behavior
      Source: Window RecorderWindow detected: More than 3 window changes detected
      Source: Busy2.0.exeStatic file information: File size 11605504 > 1048576
      Source: Busy2.0.exeStatic PE information: Raw size of .rsrc is bigger than: 0x100000 < 0xafb800
      Source: Binary string: C:\Users\FlyTech\Documents\Visual Studio 2015\Projects\Messager\Messager\obj\Debug\Messager.pdb source: Busy2.0.exe, 00000000.00000003.1008656527.0000000002ED2000.00000004.00000020.00020000.00000000.sdmp, runaway.exe, 0000002B.00000000.1531313090.0000000000112000.00000002.00000001.01000000.00000013.sdmp, runaway.exe.0.dr
      Source: Binary string: D:\Visual Studio Projects\Hydra\Hydra\obj\Release\Hydra.pdb source: Busy2.0.exe, 00000000.00000003.1008777841.0000000002DD3000.00000004.00000020.00020000.00000000.sdmp, Hydra.exe.0.dr
      Source: Binary string: C:\Users\Domas\Desktop\ScreenMelter\x64\Release\ScreenMelter.pdb source: Melting.exe.0.dr

      Data Obfuscation

      barindex
      Source: Yara matchFile source: Busy2.0.exe, type: SAMPLE
      Source: Yara matchFile source: C:\Users\user\Desktop\matrix.exe, type: DROPPED
      Source: Hydra.exe.0.drStatic PE information: 0xBFB48831 [Wed Dec 2 11:00:01 2071 UTC]
      Source: C:\Users\user\Desktop\Busy2.0.exeCode function: 0_2_0040ADD6 GetTempPathW,LoadLibraryW,GetProcAddress,GetLongPathNameW,FreeLibrary,0_2_0040ADD6
      Source: Busy2.0.exeStatic PE information: section name: .code
      Source: matrix.exe.0.drStatic PE information: section name: .code
      Source: C:\Users\user\Desktop\MBR.exeCode function: 19_2_00405488 push 004054D9h; ret 19_2_004054D1
      Source: C:\Users\user\Desktop\MBR.exeCode function: 19_2_00412848 push 00412874h; ret 19_2_0041286C
      Source: C:\Users\user\Desktop\MBR.exeCode function: 19_2_0040B86C push 0040B9E8h; ret 19_2_0040B9E0
      Source: C:\Users\user\Desktop\MBR.exeCode function: 19_2_00412020 push 004120B0h; ret 19_2_004120A8
      Source: C:\Users\user\Desktop\MBR.exeCode function: 19_2_004120CB push 0041210Fh; ret 19_2_00412107
      Source: C:\Users\user\Desktop\MBR.exeCode function: 19_2_004120CC push 0041210Fh; ret 19_2_00412107
      Source: C:\Users\user\Desktop\MBR.exeCode function: 19_2_00405900 push 0040592Ch; ret 19_2_00405924
      Source: C:\Users\user\Desktop\MBR.exeCode function: 19_2_00405938 push 00405C34h; ret 19_2_00405C2C
      Source: C:\Users\user\Desktop\MBR.exeCode function: 19_2_0040E9CC push 0040EA42h; ret 19_2_0040EA3A
      Source: C:\Users\user\Desktop\MBR.exeCode function: 19_2_0040B9EA push 0040BA5Bh; ret 19_2_0040BA53
      Source: C:\Users\user\Desktop\MBR.exeCode function: 19_2_0040B9EC push 0040BA5Bh; ret 19_2_0040BA53
      Source: C:\Users\user\Desktop\MBR.exeCode function: 19_2_0040EA44 push 0040EAECh; ret 19_2_0040EAE4
      Source: C:\Users\user\Desktop\MBR.exeCode function: 19_2_0040BA64 push 0040BAA0h; ret 19_2_0040BA98
      Source: C:\Users\user\Desktop\MBR.exeCode function: 19_2_0040BA74 push 0040BAA0h; ret 19_2_0040BA98
      Source: C:\Users\user\Desktop\MBR.exeCode function: 19_2_0040B204 push ecx; mov dword ptr [esp], edx19_2_0040B209
      Source: C:\Users\user\Desktop\MBR.exeCode function: 19_2_0040EAEE push 0040EB84h; ret 19_2_0040EB7C
      Source: C:\Users\user\Desktop\MBR.exeCode function: 19_2_0040C2A0 push 0040C2CCh; ret 19_2_0040C2C4
      Source: C:\Users\user\Desktop\MBR.exeCode function: 19_2_0040BAAC push 0040BAD8h; ret 19_2_0040BAD0
      Source: C:\Users\user\Desktop\MBR.exeCode function: 19_2_0040EB58 push 0040EB84h; ret 19_2_0040EB7C
      Source: C:\Users\user\Desktop\MBR.exeCode function: 19_2_00402BC4 push eax; ret 19_2_00402C00
      Source: C:\Users\user\Desktop\MBR.exeCode function: 19_2_0040EBBB push 0040EC09h; ret 19_2_0040EC01
      Source: C:\Users\user\Desktop\MBR.exeCode function: 19_2_0040EBBC push 0040EC09h; ret 19_2_0040EC01
      Source: C:\Users\user\Desktop\MBR.exeCode function: 19_2_00405C08 push 00405C34h; ret 19_2_00405C2C
      Source: C:\Users\user\Desktop\MBR.exeCode function: 19_2_0040EC0D push 0040EC40h; ret 19_2_0040EC38
      Source: C:\Users\user\Desktop\MBR.exeCode function: 19_2_0040EC14 push 0040EC40h; ret 19_2_0040EC38
      Source: C:\Users\user\Desktop\MBR.exeCode function: 19_2_0041251B push 0041255Fh; ret 19_2_00412557
      Source: C:\Users\user\Desktop\MBR.exeCode function: 19_2_0041251C push 0041255Fh; ret 19_2_00412557
      Source: C:\Users\user\Desktop\MBR.exeCode function: 19_2_00412D20 push 00412D46h; ret 19_2_00412D3E
      Source: C:\Users\user\Desktop\MBR.exeCode function: 19_2_004056F0 push 0040571Ch; ret 19_2_00405714
      Source: C:\Users\user\Desktop\MBR.exeCode function: 19_2_004056B8 push 004056E4h; ret 19_2_004056DC
      Source: C:\Users\user\Desktop\MBR.exeCode function: 19_2_00410744 push ecx; mov dword ptr [esp], ecx19_2_00410749

      Persistence and Installation Behavior

      barindex
      Source: C:\Users\user\Desktop\MBR.exeCode function: EntryPoint,FindWindowA,PostMessageA,FindWindowA,PostMessageA,WinExec,CreateFileA,WriteFile,CloseHandle, \\.\PhysicalDrive019_2_00412DE0
      Source: C:\Windows\System32\cmd.exeProcess created: reg.exe
      Source: C:\Windows\System32\cmd.exeProcess created: reg.exe
      Source: C:\Windows\System32\cmd.exeProcess created: reg.exe
      Source: C:\Windows\System32\cmd.exeProcess created: reg.exe
      Source: C:\Windows\System32\cmd.exeProcess created: reg.exe
      Source: C:\Windows\System32\cmd.exeProcess created: reg.exeJump to behavior
      Source: C:\Windows\System32\cmd.exeProcess created: reg.exeJump to behavior
      Source: C:\Windows\System32\cmd.exeProcess created: reg.exeJump to behavior
      Source: C:\Windows\System32\cmd.exeProcess created: reg.exeJump to behavior
      Source: C:\Windows\System32\cmd.exeProcess created: reg.exeJump to behavior
      Source: C:\Windows\System32\cmd.exeProcess created: reg.exeJump to behavior
      Source: C:\Users\user\Desktop\MBR.exeFile written: \Device\Harddisk0\DR0 offset: 12288 length: 12288Jump to behavior
      Source: C:\Users\user\Desktop\MBR.exeFile written: \Device\Harddisk0\DR0 offset: 12288 length: 12288Jump to behavior
      Source: C:\Users\user\Desktop\Busy2.0.exeFile created: C:\Users\user\Desktop\MBR.exeJump to dropped file
      Source: C:\Users\user\Desktop\Busy2.0.exeFile created: C:\Users\user\Desktop\Hydra.exeJump to dropped file
      Source: C:\Users\user\Desktop\Busy2.0.exeFile created: C:\Users\user\Desktop\matrix.exeJump to dropped file
      Source: C:\Users\user\Desktop\Busy2.0.exeFile created: C:\Users\user\Desktop\Melting.exeJump to dropped file
      Source: C:\Users\user\Desktop\Busy2.0.exeFile created: C:\Users\user\Desktop\runaway.exeJump to dropped file
      Source: C:\Users\user\Desktop\Busy2.0.exeFile created: C:\Users\user\Desktop\IconDance.exeJump to dropped file

      Boot Survival

      barindex
      Source: C:\Users\user\Desktop\MBR.exeCode function: EntryPoint,FindWindowA,PostMessageA,FindWindowA,PostMessageA,WinExec,CreateFileA,WriteFile,CloseHandle, \\.\PhysicalDrive019_2_00412DE0
      Source: C:\Users\user\Desktop\IconDance.exeWindow found: window name: progman
      Source: C:\Users\user\Desktop\MBR.exeProcess created: C:\Windows\SysWOW64\schtasks.exe schtasks.exe /Create /TN "Windows Update" /ru SYSTEM /SC ONSTART /TR "C:\Users\user\Desktop\MBR.exe"
      Source: C:\Users\user\Desktop\MBR.exeRegistry value created or modified: HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run Windows UpdateJump to behavior
      Source: C:\Users\user\Desktop\MBR.exeRegistry value created or modified: HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run Windows UpdateJump to behavior
      Source: C:\Users\user\Desktop\MBR.exeRegistry value created or modified: HKEY_USERS.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run Windows UpdateJump to behavior
      Source: C:\Users\user\Desktop\MBR.exeRegistry value created or modified: HKEY_USERS.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run Windows UpdateJump to behavior
      Source: C:\Users\user\Desktop\MBR.exeCode function: 19_2_0041256C GetModuleHandleA,GetProcAddress,GetProcAddress,GetProcAddress,GetProcAddress,GetProcAddress,GetProcAddress,GetProcAddress,GetProcAddress,GetProcAddress,GetProcAddress,GetProcAddress,GetProcAddress,GetProcAddress,GetProcAddress,GetProcAddress,GetProcAddress,19_2_0041256C
      Source: C:\Users\user\Desktop\Busy2.0.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
      Source: C:\Users\user\Desktop\Busy2.0.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
      Source: C:\Windows\System32\cmd.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
      Source: C:\Windows\System32\cmd.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
      Source: C:\Program Files\WindowsApps\Microsoft.ZuneMusic_10.19071.19011.0_x64__8wekyb3d8bbwe\Music.UI.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
      Source: C:\Program Files\WindowsApps\Microsoft.ZuneMusic_10.19071.19011.0_x64__8wekyb3d8bbwe\Music.UI.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
      Source: C:\Program Files\WindowsApps\Microsoft.ZuneMusic_10.19071.19011.0_x64__8wekyb3d8bbwe\Music.UI.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
      Source: C:\Program Files\WindowsApps\Microsoft.ZuneMusic_10.19071.19011.0_x64__8wekyb3d8bbwe\Music.UI.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
      Source: C:\Program Files\WindowsApps\Microsoft.ZuneMusic_10.19071.19011.0_x64__8wekyb3d8bbwe\Music.UI.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
      Source: C:\Program Files\WindowsApps\Microsoft.ZuneMusic_10.19071.19011.0_x64__8wekyb3d8bbwe\Music.UI.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
      Source: C:\Program Files\WindowsApps\Microsoft.ZuneMusic_10.19071.19011.0_x64__8wekyb3d8bbwe\Music.UI.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
      Source: C:\Program Files\WindowsApps\Microsoft.ZuneMusic_10.19071.19011.0_x64__8wekyb3d8bbwe\Music.UI.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
      Source: C:\Windows\System32\rundll32.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
      Source: C:\Windows\System32\rundll32.exeProcess information set: NOOPENFILEERRORBOX
      Source: C:\Windows\System32\rundll32.exeProcess information set: NOOPENFILEERRORBOX
      Source: C:\Windows\System32\rundll32.exeProcess information set: NOOPENFILEERRORBOX
      Source: C:\Users\user\Desktop\runaway.exeProcess information set: NOOPENFILEERRORBOX
      Source: C:\Users\user\Desktop\runaway.exeProcess information set: NOOPENFILEERRORBOX
      Source: C:\Users\user\Desktop\runaway.exeProcess information set: NOOPENFILEERRORBOX
      Source: C:\Users\user\Desktop\runaway.exeProcess information set: NOOPENFILEERRORBOX
      Source: C:\Users\user\Desktop\runaway.exeProcess information set: NOOPENFILEERRORBOX
      Source: C:\Users\user\Desktop\runaway.exeProcess information set: NOOPENFILEERRORBOX
      Source: C:\Users\user\Desktop\runaway.exeProcess information set: NOOPENFILEERRORBOX
      Source: C:\Users\user\Desktop\runaway.exeProcess information set: NOOPENFILEERRORBOX
      Source: C:\Users\user\Desktop\runaway.exeProcess information set: NOOPENFILEERRORBOX
      Source: C:\Users\user\Desktop\runaway.exeProcess information set: NOOPENFILEERRORBOX
      Source: C:\Users\user\Desktop\runaway.exeProcess information set: NOOPENFILEERRORBOX
      Source: C:\Users\user\Desktop\runaway.exeProcess information set: NOOPENFILEERRORBOX
      Source: C:\Users\user\Desktop\runaway.exeProcess information set: NOOPENFILEERRORBOX
      Source: C:\Users\user\Desktop\runaway.exeProcess information set: NOOPENFILEERRORBOX
      Source: C:\Users\user\Desktop\runaway.exeProcess information set: NOOPENFILEERRORBOX
      Source: C:\Users\user\Desktop\runaway.exeProcess information set: NOOPENFILEERRORBOX
      Source: C:\Users\user\Desktop\runaway.exeProcess information set: NOOPENFILEERRORBOX
      Source: C:\Users\user\Desktop\runaway.exeMemory allocated: 960000 memory reserve | memory write watch
      Source: C:\Users\user\Desktop\runaway.exeMemory allocated: 2400000 memory reserve | memory write watch
      Source: C:\Users\user\Desktop\runaway.exeMemory allocated: 21C0000 memory reserve | memory write watch
      Source: C:\Users\user\Desktop\Busy2.0.exeWindow / User API: threadDelayed 5573Jump to behavior
      Source: C:\Users\user\Desktop\Busy2.0.exeDropped PE file which has not been started: C:\Users\user\Desktop\Hydra.exeJump to dropped file
      Source: C:\Users\user\Desktop\Busy2.0.exeDropped PE file which has not been started: C:\Users\user\Desktop\matrix.exeJump to dropped file
      Source: C:\Users\user\Desktop\Busy2.0.exeDropped PE file which has not been started: C:\Users\user\Desktop\Melting.exeJump to dropped file
      Source: C:\Users\user\Desktop\Busy2.0.exe TID: 6488Thread sleep time: -55730s >= -30000sJump to behavior
      Source: C:\Windows\System32\timeout.exe TID: 3912Thread sleep count: 251 > 30Jump to behavior
      Source: C:\Windows\System32\timeout.exe TID: 7300Thread sleep count: 42 > 30Jump to behavior
      Source: C:\Program Files\WindowsApps\Microsoft.ZuneMusic_10.19071.19011.0_x64__8wekyb3d8bbwe\Music.UI.exe TID: 7668Thread sleep time: -4233600000s >= -30000sJump to behavior
      Source: C:\Program Files\WindowsApps\Microsoft.ZuneMusic_10.19071.19011.0_x64__8wekyb3d8bbwe\Music.UI.exe TID: 7668Thread sleep time: -86400000s >= -30000sJump to behavior
      Source: C:\Users\user\Desktop\MBR.exeFile opened: PhysicalDrive0Jump to behavior
      Source: C:\Windows\System32\rundll32.exeKey opened: HKEY_LOCAL_MACHINE\System\CurrentControlSet\Control\Keyboard Layouts\00000807Jump to behavior
      Source: C:\Windows\System32\rundll32.exeKey opened: HKEY_LOCAL_MACHINE\System\CurrentControlSet\Control\Keyboard Layouts\00000407Jump to behavior
      Source: C:\Windows\System32\rundll32.exeKey opened: HKEY_LOCAL_MACHINE\System\CurrentControlSet\Control\Keyboard Layouts\00000807
      Source: C:\Windows\System32\rundll32.exeKey opened: HKEY_LOCAL_MACHINE\System\CurrentControlSet\Control\Keyboard Layouts\00000407
      Source: C:\Windows\System32\rundll32.exeKey opened: HKEY_LOCAL_MACHINE\System\CurrentControlSet\Control\Keyboard Layouts\00000807
      Source: C:\Windows\System32\rundll32.exeKey opened: HKEY_LOCAL_MACHINE\System\CurrentControlSet\Control\Keyboard Layouts\00000407
      Source: C:\Windows\System32\rundll32.exeKey opened: HKEY_LOCAL_MACHINE\System\CurrentControlSet\Control\Keyboard Layouts\00000807
      Source: C:\Windows\System32\rundll32.exeKey opened: HKEY_LOCAL_MACHINE\System\CurrentControlSet\Control\Keyboard Layouts\00000407
      Source: C:\Windows\System32\conhost.exeLast function: Thread delayed
      Source: C:\Windows\System32\conhost.exeLast function: Thread delayed
      Source: C:\Users\user\Desktop\Busy2.0.exeThread sleep count: Count: 5573 delay: -10Jump to behavior
      Source: C:\Users\user\Desktop\MBR.exeCode function: 19_2_004049A0 GetModuleHandleA,GetProcAddress,lstrcpyn,lstrcpyn,lstrcpyn,FindFirstFileA,FindClose,lstrlen,lstrcpyn,lstrlen,lstrcpyn,19_2_004049A0
      Source: C:\Users\user\Desktop\Busy2.0.exeFile opened: C:\Users\user\AppData\Local\Temp\2A8E.tmpJump to behavior
      Source: C:\Users\user\Desktop\Busy2.0.exeFile opened: C:\Users\user\AppData\Jump to behavior
      Source: C:\Users\user\Desktop\Busy2.0.exeFile opened: C:\Users\user\AppData\Local\Temp\2A8E.tmp\2A8F.tmp\2A90.tmpJump to behavior
      Source: C:\Users\user\Desktop\Busy2.0.exeFile opened: C:\Users\user\Jump to behavior
      Source: C:\Users\user\Desktop\Busy2.0.exeFile opened: C:\Users\user\AppData\Local\Jump to behavior
      Source: C:\Users\user\Desktop\Busy2.0.exeFile opened: C:\Users\user\AppData\Local\Temp\2A8E.tmp\2A8F.tmpJump to behavior
      Source: Music.UI.exe, 00000017.00000002.2308008252.0000013ECC581000.00000004.00000020.00020000.00000000.sdmpBinary or memory string: Hyper-V RAW%SystemRoot%\system32\mswsock.dll
      Source: C:\Users\user\Desktop\Busy2.0.exeCode function: 0_2_0040ADD6 GetTempPathW,LoadLibraryW,GetProcAddress,GetLongPathNameW,FreeLibrary,0_2_0040ADD6
      Source: C:\Users\user\Desktop\Busy2.0.exeCode function: 0_2_00409FD0 SetUnhandledExceptionFilter,0_2_00409FD0
      Source: C:\Users\user\Desktop\Busy2.0.exeCode function: 0_2_00409FB0 SetUnhandledExceptionFilter,SetUnhandledExceptionFilter,SetUnhandledExceptionFilter,0_2_00409FB0
      Source: C:\Users\user\Desktop\runaway.exeMemory allocated: page read and write | page guard
      Source: C:\Users\user\Desktop\MBR.exeCode function: 19_2_00412C00 ShellExecuteEx,19_2_00412C00
      Source: C:\Windows\System32\cmd.exeProcess created: C:\Windows\System32\timeout.exe timeout /t 30Jump to behavior
      Source: C:\Windows\System32\cmd.exeProcess created: C:\Windows\System32\timeout.exe timeout /t 5Jump to behavior
      Source: C:\Windows\System32\cmd.exeProcess created: C:\Windows\System32\timeout.exe timeout /t 1Jump to behavior
      Source: C:\Windows\System32\cmd.exeProcess created: C:\Windows\System32\timeout.exe timeout /t 1Jump to behavior
      Source: C:\Windows\System32\cmd.exeProcess created: C:\Windows\System32\timeout.exe timeout /t 2Jump to behavior
      Source: C:\Windows\System32\cmd.exeProcess created: C:\Windows\System32\timeout.exe timeout /t 4Jump to behavior
      Source: C:\Windows\System32\cmd.exeProcess created: C:\Windows\System32\reg.exe reg add "HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\System" /v DisableTaskMgr /t "REG_DWORD" /d "1" /fJump to behavior
      Source: C:\Windows\System32\cmd.exeProcess created: C:\Users\user\Desktop\MBR.exe MBR.exeJump to behavior
      Source: C:\Windows\System32\cmd.exeProcess created: C:\Windows\System32\timeout.exe timeout /t 1Jump to behavior
      Source: C:\Windows\System32\cmd.exeProcess created: C:\Windows\System32\reg.exe reg add "HKEY_CURRENT_USER\Control Panel\Desktop" /v "Wallpaper" /t REG_SZ /d "C:\Users\userDesktop\YuuyaCat.bmp" /fJump to behavior
      Source: C:\Windows\System32\cmd.exeProcess created: C:\Windows\System32\rundll32.exe RUNDLL32.EXE user32.dll,UpdatePerUserSystemParametersJump to behavior
      Source: C:\Windows\System32\cmd.exeProcess created: C:\Windows\System32\reg.exe reg add "HKEY_CURRENT_USER\Control Panel\Desktop" /v "Wallpaper" /t REG_SZ /d "C:\Users\userDesktop\YuuyaCat.bmp" /fJump to behavior
      Source: C:\Windows\System32\cmd.exeProcess created: C:\Windows\System32\rundll32.exe RUNDLL32.EXE user32.dll,UpdatePerUserSystemParametersJump to behavior
      Source: C:\Windows\System32\cmd.exeProcess created: C:\Windows\System32\reg.exe reg add "HKEY_CURRENT_USER\Control Panel\Desktop" /v "Wallpaper" /t REG_SZ /d "C:\Users\userDesktop\YuuyaCat.bmp" /fJump to behavior
      Source: C:\Windows\System32\cmd.exeProcess created: C:\Windows\System32\rundll32.exe RUNDLL32.EXE user32.dll,UpdatePerUserSystemParametersJump to behavior
      Source: C:\Windows\System32\cmd.exeProcess created: C:\Windows\System32\reg.exe reg add "HKEY_CURRENT_USER\Control Panel\Desktop" /v "Wallpaper" /t REG_SZ /d "C:\Users\userDesktop\YuuyaCat.bmp" /fJump to behavior
      Source: C:\Windows\System32\cmd.exeProcess created: C:\Windows\System32\rundll32.exe RUNDLL32.EXE user32.dll,UpdatePerUserSystemParametersJump to behavior
      Source: C:\Windows\System32\cmd.exeProcess created: C:\Windows\System32\timeout.exe timeout /t 4Jump to behavior
      Source: C:\Windows\System32\cmd.exeProcess created: C:\Users\user\Desktop\IconDance.exe IconDance.exeJump to behavior
      Source: C:\Windows\System32\cmd.exeProcess created: C:\Users\user\Desktop\runaway.exe runaway.exeJump to behavior
      Source: C:\Windows\System32\cmd.exeProcess created: unknown unknownJump to behavior
      Source: C:\Windows\System32\cmd.exeProcess created: unknown unknownJump to behavior
      Source: C:\Windows\System32\cmd.exeProcess created: unknown unknownJump to behavior
      Source: C:\Windows\System32\cmd.exeProcess created: unknown unknownJump to behavior
      Source: C:\Windows\System32\cmd.exeProcess created: unknown unknownJump to behavior
      Source: C:\Windows\System32\cmd.exeProcess created: unknown unknownJump to behavior
      Source: C:\Windows\System32\cmd.exeProcess created: unknown unknownJump to behavior
      Source: C:\Windows\System32\cmd.exeProcess created: unknown unknownJump to behavior
      Source: C:\Windows\System32\cmd.exeProcess created: unknown unknownJump to behavior
      Source: C:\Windows\System32\cmd.exeProcess created: unknown unknownJump to behavior
      Source: C:\Windows\System32\cmd.exeProcess created: unknown unknownJump to behavior
      Source: C:\Windows\System32\cmd.exeProcess created: unknown unknownJump to behavior
      Source: C:\Windows\System32\cmd.exeProcess created: unknown unknownJump to behavior
      Source: C:\Windows\System32\cmd.exeProcess created: unknown unknownJump to behavior
      Source: C:\Windows\System32\cmd.exeProcess created: unknown unknownJump to behavior
      Source: C:\Windows\System32\cmd.exeProcess created: unknown unknownJump to behavior
      Source: C:\Windows\System32\cmd.exeProcess created: unknown unknownJump to behavior
      Source: C:\Windows\System32\cmd.exeProcess created: unknown unknownJump to behavior
      Source: C:\Windows\System32\cmd.exeProcess created: unknown unknownJump to behavior
      Source: C:\Windows\System32\cmd.exeProcess created: unknown unknownJump to behavior
      Source: C:\Windows\System32\cmd.exeProcess created: unknown unknownJump to behavior
      Source: C:\Windows\System32\cmd.exeProcess created: unknown unknownJump to behavior
      Source: C:\Windows\System32\cmd.exeProcess created: unknown unknownJump to behavior
      Source: C:\Windows\System32\cmd.exeProcess created: unknown unknownJump to behavior
      Source: C:\Windows\System32\cmd.exeProcess created: unknown unknownJump to behavior
      Source: C:\Windows\System32\cmd.exeProcess created: unknown unknownJump to behavior
      Source: C:\Windows\System32\cmd.exeProcess created: unknown unknownJump to behavior
      Source: C:\Windows\System32\cmd.exeProcess created: unknown unknownJump to behavior
      Source: C:\Windows\System32\cmd.exeProcess created: unknown unknownJump to behavior
      Source: C:\Windows\System32\cmd.exeProcess created: unknown unknownJump to behavior
      Source: C:\Windows\System32\cmd.exeProcess created: unknown unknownJump to behavior
      Source: C:\Windows\System32\cmd.exeProcess created: unknown unknownJump to behavior
      Source: C:\Windows\System32\cmd.exeProcess created: C:\Windows\System32\reg.exe reg add "HKEY_CURRENT_USER\Control Panel\Desktop" /v "Wallpaper" /t REG_SZ /d "C:\Users\userDesktop\YuuyaCat.bmp" /fJump to behavior
      Source: C:\Windows\System32\cmd.exeProcess created: C:\Windows\System32\rundll32.exe RUNDLL32.EXE user32.dll,UpdatePerUserSystemParametersJump to behavior
      Source: C:\Windows\System32\cmd.exeProcess created: unknown unknownJump to behavior
      Source: C:\Windows\System32\cmd.exeProcess created: unknown unknownJump to behavior
      Source: C:\Windows\System32\cmd.exeProcess created: unknown unknownJump to behavior
      Source: C:\Windows\System32\cmd.exeProcess created: unknown unknownJump to behavior
      Source: C:\Windows\System32\cmd.exeProcess created: unknown unknownJump to behavior
      Source: C:\Windows\System32\cmd.exeProcess created: unknown unknownJump to behavior
      Source: C:\Windows\System32\cmd.exeProcess created: unknown unknownJump to behavior
      Source: C:\Windows\System32\cmd.exeProcess created: unknown unknownJump to behavior
      Source: C:\Windows\System32\cmd.exeProcess created: unknown unknownJump to behavior
      Source: C:\Windows\System32\cmd.exeProcess created: unknown unknownJump to behavior
      Source: C:\Windows\System32\cmd.exeProcess created: unknown unknownJump to behavior
      Source: C:\Users\user\Desktop\MBR.exeCode function: 19_2_00412BA4 AllocateAndInitializeSid,CheckTokenMembership,FreeSid,19_2_00412BA4
      Source: Busy2.0.exe, 00000000.00000003.1008532988.0000000002DCF000.00000004.00000020.00020000.00000000.sdmp, MBR.exe, MBR.exe, 00000013.00000000.1440878627.0000000000401000.00000020.00000001.01000000.00000007.sdmp, MBR.exe, 00000018.00000000.1446991933.0000000000401000.00000020.00000001.01000000.00000007.sdmpBinary or memory string: Shell_TrayWnd
      Source: IconDance.exe, 0000002A.00000002.2243380828.000000000073E000.00000004.00000020.00020000.00000000.sdmpBinary or memory string: progmanyK
      Source: Busy2.0.exe, 00000000.00000003.1008532988.0000000002DCF000.00000004.00000020.00020000.00000000.sdmp, MBR.exe, 00000013.00000000.1440878627.0000000000401000.00000020.00000001.01000000.00000007.sdmp, MBR.exe, 00000018.00000000.1446991933.0000000000401000.00000020.00000001.01000000.00000007.sdmpBinary or memory string: Windows UpdateShell_TrayWnd
      Source: Busy2.0.exe, 00000000.00000003.1009119771.0000000002E09000.00000004.00000020.00020000.00000000.sdmp, IconDance.exe, 0000002A.00000000.1530907222.0000000000401000.00000020.00000001.01000000.00000012.sdmp, IconDance.exe.0.drBinary or memory string: progman
      Source: C:\Users\user\Desktop\MBR.exeCode function: GetModuleFileNameA,RegOpenKeyExA,RegOpenKeyExA,RegOpenKeyExA,RegQueryValueExA,RegQueryValueExA,RegCloseKey,lstrcpyn,GetThreadLocale,GetLocaleInfoA,lstrlen,lstrcpyn,LoadLibraryExA,lstrcpyn,LoadLibraryExA,lstrcpyn,LoadLibraryExA,19_2_00404B58
      Source: C:\Users\user\Desktop\MBR.exeCode function: GetLocaleInfoA,GetACP,19_2_0040AA6C
      Source: C:\Users\user\Desktop\MBR.exeCode function: lstrcpyn,GetThreadLocale,GetLocaleInfoA,lstrlen,lstrcpyn,LoadLibraryExA,lstrcpyn,LoadLibraryExA,lstrcpyn,LoadLibraryExA,19_2_00404C64
      Source: C:\Users\user\Desktop\MBR.exeCode function: GetLocaleInfoA,19_2_00405412
      Source: C:\Users\user\Desktop\MBR.exeCode function: GetLocaleInfoA,19_2_00405414
      Source: C:\Users\user\Desktop\MBR.exeCode function: GetLocaleInfoA,19_2_00409664
      Source: C:\Users\user\Desktop\MBR.exeCode function: GetLocaleInfoA,19_2_00409618
      Source: C:\Windows\System32\cmd.exeQueries volume information: C:\ VolumeInformationJump to behavior
      Source: C:\Program Files\WindowsApps\Microsoft.ZuneMusic_10.19071.19011.0_x64__8wekyb3d8bbwe\Music.UI.exeQueries volume information: C:\Windows\Fonts\segoeui.ttf VolumeInformationJump to behavior
      Source: C:\Program Files\WindowsApps\Microsoft.ZuneMusic_10.19071.19011.0_x64__8wekyb3d8bbwe\Music.UI.exeQueries volume information: C:\Users\user\AppData\Local\Packages\Microsoft.ZuneMusic_8wekyb3d8bbwe\LocalState\Database\anonymous\edbtmp.log VolumeInformationJump to behavior
      Source: C:\Program Files\WindowsApps\Microsoft.ZuneMusic_10.19071.19011.0_x64__8wekyb3d8bbwe\Music.UI.exeQueries volume information: C:\Users\user\AppData\Local\Packages\Microsoft.ZuneMusic_8wekyb3d8bbwe\LocalState\Database\anonymous\edbtmp.log VolumeInformationJump to behavior
      Source: C:\Program Files\WindowsApps\Microsoft.ZuneMusic_10.19071.19011.0_x64__8wekyb3d8bbwe\Music.UI.exeQueries volume information: C:\Users\user\AppData\Local\Packages\Microsoft.ZuneMusic_8wekyb3d8bbwe\LocalState\Database\anonymous\edbres00001.jrs VolumeInformationJump to behavior
      Source: C:\Program Files\WindowsApps\Microsoft.ZuneMusic_10.19071.19011.0_x64__8wekyb3d8bbwe\Music.UI.exeQueries volume information: C:\Users\user\AppData\Local\Packages\Microsoft.ZuneMusic_8wekyb3d8bbwe\LocalState\Database\anonymous\edbres00002.jrs VolumeInformationJump to behavior
      Source: C:\Program Files\WindowsApps\Microsoft.ZuneMusic_10.19071.19011.0_x64__8wekyb3d8bbwe\Music.UI.exeQueries volume information: C:\Users\user\AppData\Local\Packages\Microsoft.ZuneMusic_8wekyb3d8bbwe\LocalState\Database\anonymous\edb.log VolumeInformationJump to behavior
      Source: C:\Program Files\WindowsApps\Microsoft.ZuneMusic_10.19071.19011.0_x64__8wekyb3d8bbwe\Music.UI.exeQueries volume information: C:\Users\user\AppData\Local\Packages\Microsoft.ZuneMusic_8wekyb3d8bbwe\LocalState\Database\anonymous\edb.log VolumeInformationJump to behavior
      Source: C:\Program Files\WindowsApps\Microsoft.ZuneMusic_10.19071.19011.0_x64__8wekyb3d8bbwe\Music.UI.exeQueries volume information: C:\Users\user\AppData\Local\Packages\Microsoft.ZuneMusic_8wekyb3d8bbwe\LocalState\Database\anonymous\edb.log VolumeInformationJump to behavior
      Source: C:\Program Files\WindowsApps\Microsoft.ZuneMusic_10.19071.19011.0_x64__8wekyb3d8bbwe\Music.UI.exeQueries volume information: C:\Users\user\AppData\Local\Packages\Microsoft.ZuneMusic_8wekyb3d8bbwe\LocalState\Database\anonymous\edb.chk VolumeInformationJump to behavior
      Source: C:\Program Files\WindowsApps\Microsoft.ZuneMusic_10.19071.19011.0_x64__8wekyb3d8bbwe\Music.UI.exeQueries volume information: C:\Users\user\AppData\Local\Packages\Microsoft.ZuneMusic_8wekyb3d8bbwe\LocalState\Database\anonymous\EntClientDb.jfm VolumeInformationJump to behavior
      Source: C:\Program Files\WindowsApps\Microsoft.ZuneMusic_10.19071.19011.0_x64__8wekyb3d8bbwe\Music.UI.exeQueries volume information: C:\Users\user\AppData\Local\Packages\Microsoft.ZuneMusic_8wekyb3d8bbwe\LocalState\Database\anonymous\EntClientDb.edb VolumeInformationJump to behavior
      Source: C:\Program Files\WindowsApps\Microsoft.ZuneMusic_10.19071.19011.0_x64__8wekyb3d8bbwe\Music.UI.exeQueries volume information: C:\Users\user\AppData\Local\Packages\Microsoft.ZuneMusic_8wekyb3d8bbwe\LocalState\Database\anonymous\EntClientDb.edb VolumeInformationJump to behavior
      Source: C:\Program Files\WindowsApps\Microsoft.ZuneMusic_10.19071.19011.0_x64__8wekyb3d8bbwe\Music.UI.exeQueries volume information: C:\Users\user\AppData\Local\Packages\Microsoft.ZuneMusic_8wekyb3d8bbwe\LocalState\Database\anonymous\tmp.edb VolumeInformationJump to behavior
      Source: C:\Program Files\WindowsApps\Microsoft.ZuneMusic_10.19071.19011.0_x64__8wekyb3d8bbwe\Music.UI.exeQueries volume information: C:\Program Files\WindowsApps\Microsoft.ZuneMusic_10.19071.19011.0_x64__8wekyb3d8bbwe\Resources\Fonts\SegMVR2.ttf VolumeInformationJump to behavior
      Source: C:\Program Files\WindowsApps\Microsoft.ZuneMusic_10.19071.19011.0_x64__8wekyb3d8bbwe\Music.UI.exeQueries volume information: C:\Program Files\WindowsApps\Microsoft.ZuneMusic_10.19071.19011.0_x64__8wekyb3d8bbwe\Resources\Fonts\SegMVR2.ttf VolumeInformationJump to behavior
      Source: C:\Program Files\WindowsApps\Microsoft.ZuneMusic_10.19071.19011.0_x64__8wekyb3d8bbwe\Music.UI.exeQueries volume information: C:\Program Files\WindowsApps\Microsoft.ZuneMusic_10.19071.19011.0_x64__8wekyb3d8bbwe\Resources\Fonts\SegMVR2.ttf VolumeInformationJump to behavior
      Source: C:\Program Files\WindowsApps\Microsoft.ZuneMusic_10.19071.19011.0_x64__8wekyb3d8bbwe\Music.UI.exeQueries volume information: C:\Program Files\WindowsApps\Microsoft.ZuneMusic_10.19071.19011.0_x64__8wekyb3d8bbwe\Resources\Fonts\SegMVR2.ttf VolumeInformationJump to behavior
      Source: C:\Program Files\WindowsApps\Microsoft.ZuneMusic_10.19071.19011.0_x64__8wekyb3d8bbwe\Music.UI.exeQueries volume information: C:\Program Files\WindowsApps\Microsoft.ZuneMusic_10.19071.19011.0_x64__8wekyb3d8bbwe\Resources\Fonts\SegMVR2.ttf VolumeInformationJump to behavior
      Source: C:\Program Files\WindowsApps\Microsoft.ZuneMusic_10.19071.19011.0_x64__8wekyb3d8bbwe\Music.UI.exeQueries volume information: C:\Windows\Fonts\segoeuisl.ttf VolumeInformationJump to behavior
      Source: C:\Program Files\WindowsApps\Microsoft.ZuneMusic_10.19071.19011.0_x64__8wekyb3d8bbwe\Music.UI.exeQueries volume information: C:\Users\user\AppData\Local\Packages\Microsoft.ZuneMusic_8wekyb3d8bbwe\LocalState\SRPData.xml VolumeInformationJump to behavior
      Source: C:\Program Files\WindowsApps\Microsoft.ZuneMusic_10.19071.19011.0_x64__8wekyb3d8bbwe\Music.UI.exeQueries volume information: C:\Users\user\AppData\Local\Packages\Microsoft.ZuneMusic_8wekyb3d8bbwe\LocalState VolumeInformationJump to behavior
      Source: C:\Program Files\WindowsApps\Microsoft.ZuneMusic_10.19071.19011.0_x64__8wekyb3d8bbwe\Music.UI.exeQueries volume information: C:\Windows\Fonts\segoeuib.ttf VolumeInformationJump to behavior
      Source: C:\Users\user\Desktop\runaway.exeQueries volume information: C:\Users\user\Desktop\runaway.exe VolumeInformation
      Source: C:\Users\user\Desktop\runaway.exeQueries volume information: C:\Windows\Microsoft.NET\assembly\GAC_MSIL\System.Windows.Forms\v4.0_4.0.0.0__b77a5c561934e089\System.Windows.Forms.dll VolumeInformation
      Source: C:\Users\user\Desktop\runaway.exeQueries volume information: C:\Windows\Microsoft.NET\assembly\GAC_MSIL\System.Drawing\v4.0_4.0.0.0__b03f5f7f11d50a3a\System.Drawing.dll VolumeInformation
      Source: C:\Users\user\Desktop\MBR.exeCode function: 19_2_00408118 GetLocalTime,19_2_00408118
      Source: C:\Users\user\Desktop\Busy2.0.exeCode function: 0_2_00405573 GetVersionExW,GetVersionExW,0_2_00405573

      Lowering of HIPS / PFW / Operating System Security Settings

      barindex
      Source: C:\Windows\System32\reg.exeRegistry value created: DisableTaskMgr 1Jump to behavior
      Source: C:\Windows\System32\reg.exeRegistry key created or modified: HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\System DisableTaskMgrJump to behavior
      ReconnaissanceResource DevelopmentInitial AccessExecutionPersistencePrivilege EscalationDefense EvasionCredential AccessDiscoveryLateral MovementCollectionCommand and ControlExfiltrationImpact
      Gather Victim Identity Information1
      Scripting
      Valid Accounts1
      Native API
      1
      Scripting
      1
      Exploitation for Privilege Escalation
      21
      Disable or Modify Tools
      OS Credential Dumping1
      System Time Discovery
      Remote Services1
      Archive Collected Data
      1
      Ingress Tool Transfer
      Exfiltration Over Other Network Medium1
      System Shutdown/Reboot
      CredentialsDomainsDefault Accounts1
      Command and Scripting Interpreter
      1
      DLL Side-Loading
      1
      DLL Side-Loading
      1
      Deobfuscate/Decode Files or Information
      LSASS Memory3
      File and Directory Discovery
      Remote Desktop ProtocolData from Removable Media11
      Encrypted Channel
      Exfiltration Over BluetoothNetwork Denial of Service
      Email AddressesDNS ServerDomain Accounts1
      Scheduled Task/Job
      1
      Scheduled Task/Job
      1
      Access Token Manipulation
      3
      Obfuscated Files or Information
      Security Account Manager44
      System Information Discovery
      SMB/Windows Admin SharesData from Network Shared Drive2
      Non-Application Layer Protocol
      Automated ExfiltrationData Encrypted for Impact
      Employee NamesVirtual Private ServerLocal AccountsCron1
      Registry Run Keys / Startup Folder
      12
      Process Injection
      1
      Timestomp
      NTDS211
      Security Software Discovery
      Distributed Component Object ModelInput Capture3
      Application Layer Protocol
      Traffic DuplicationData Destruction
      Gather Victim Network InformationServerCloud AccountsLaunchd3
      Bootkit
      1
      Scheduled Task/Job
      1
      DLL Side-Loading
      LSA Secrets4
      Virtualization/Sandbox Evasion
      SSHKeyloggingFallback ChannelsScheduled TransferData Encrypted for Impact
      Domain PropertiesBotnetReplication Through Removable MediaScheduled TaskRC Scripts1
      Registry Run Keys / Startup Folder
      1
      Masquerading
      Cached Domain Credentials1
      Process Discovery
      VNCGUI Input CaptureMultiband CommunicationData Transfer Size LimitsService Stop
      DNSWeb ServicesExternal Remote ServicesSystemd TimersStartup ItemsStartup Items1
      Modify Registry
      DCSync1
      Application Window Discovery
      Windows Remote ManagementWeb Portal CaptureCommonly Used PortExfiltration Over C2 ChannelInhibit System Recovery
      Network Trust DependenciesServerlessDrive-by CompromiseContainer Orchestration JobScheduled Task/JobScheduled Task/Job4
      Virtualization/Sandbox Evasion
      Proc FilesystemSystem Owner/User DiscoveryCloud ServicesCredential API HookingApplication Layer ProtocolExfiltration Over Alternative ProtocolDefacement
      Network TopologyMalvertisingExploit Public-Facing ApplicationCommand and Scripting InterpreterAtAt1
      Access Token Manipulation
      /etc/passwd and /etc/shadowNetwork SniffingDirect Cloud VM ConnectionsData StagedWeb ProtocolsExfiltration Over Symmetric Encrypted Non-C2 ProtocolInternal Defacement
      IP AddressesCompromise InfrastructureSupply Chain CompromisePowerShellCronCron12
      Process Injection
      Network SniffingNetwork Service DiscoveryShared WebrootLocal Data StagingFile Transfer ProtocolsExfiltration Over Asymmetric Encrypted Non-C2 ProtocolExternal Defacement
      Network Security AppliancesDomainsCompromise Software Dependencies and Development ToolsAppleScriptLaunchdLaunchd3
      Bootkit
      Input CaptureSystem Network Connections DiscoverySoftware Deployment ToolsRemote Data StagingMail ProtocolsExfiltration Over Unencrypted Non-C2 ProtocolFirmware Corruption
      Gather Victim Org InformationDNS ServerCompromise Software Supply ChainWindows Command ShellScheduled TaskScheduled Task1
      Rundll32
      KeyloggingProcess DiscoveryTaint Shared ContentScreen CaptureDNSExfiltration Over Physical MediumResource Hijacking
      Hide Legend

      Legend:

      • Process
      • Signature
      • Created File
      • DNS/IP Info
      • Is Dropped
      • Is Windows Process
      • Number of created Registry Values
      • Number of created Files
      • Visual Basic
      • Delphi
      • Java
      • .Net C# or VB.NET
      • C, C++ or other language
      • Is malicious
      • Internet
      behaviorgraph top1 dnsIp2 2 Behavior Graph ID: 1639482 Sample: Busy2.0.exe Startdate: 15/03/2025 Architecture: WINDOWS Score: 100 53 settings-ssl.xboxlive.com.edgekey.net 2->53 55 settings-ssl.xboxlive.com 2->55 57 e87.dspb.akamaiedge.net 2->57 59 Antivirus detection for dropped file 2->59 61 Antivirus / Scanner detection for submitted sample 2->61 63 Multi AV Scanner detection for dropped file 2->63 65 4 other signatures 2->65 10 Busy2.0.exe 16 2->10         started        13 MBR.exe 1 2->13         started        16 Music.UI.exe 63 38 2->16         started        signatures3 process4 dnsIp5 41 C:\Users\user\Desktop\runaway.exe, PE32 10->41 dropped 43 C:\Users\user\Desktop\matrix.exe, PE32 10->43 dropped 45 C:\Users\user\Desktop\Melting.exe, PE32+ 10->45 dropped 49 3 other malicious files 10->49 dropped 19 cmd.exe 2 10->19         started        22 conhost.exe 10->22         started        47 \Device\Harddisk0\DR0, DOS/MBR 13->47 dropped 85 Writes directly to the primary disk partition (DR0) 13->85 24 schtasks.exe 1 13->24         started        51 e87.dspb.akamaiedge.net 23.219.148.9, 443, 49692 VTRBANDAANCHASACL United States 16->51 file6 signatures7 process8 signatures9 67 Uses cmd line tools excessively to alter registry or file data 19->67 26 MBR.exe 1 19->26         started        29 IconDance.exe 19->29         started        31 reg.exe 1 1 19->31         started        35 17 other processes 19->35 33 conhost.exe 24->33         started        process10 signatures11 69 Antivirus detection for dropped file 26->69 71 Multi AV Scanner detection for dropped file 26->71 73 Writes directly to the primary disk partition (DR0) 26->73 83 3 other signatures 26->83 37 schtasks.exe 1 26->37         started        75 Tries to detect process monitoring tools (Task Manager, Process Explorer etc.) 29->75 77 Disable Task Manager(disabletaskmgr) 31->77 79 Disables the Windows task manager (taskmgr) 31->79 81 Changes the wallpaper picture 35->81 process12 process13 39 conhost.exe 37->39         started       

      This section contains all screenshots as thumbnails, including those not shown in the slideshow.