Source: unknown | TCP traffic detected without corresponding DNS query: 2.23.227.208 |
Source: unknown | TCP traffic detected without corresponding DNS query: 2.23.227.208 |
Source: unknown | TCP traffic detected without corresponding DNS query: 2.23.227.208 |
Source: unknown | TCP traffic detected without corresponding DNS query: 23.199.215.203 |
Source: unknown | TCP traffic detected without corresponding DNS query: 2.18.98.62 |
Source: unknown | TCP traffic detected without corresponding DNS query: 2.23.227.208 |
Source: unknown | TCP traffic detected without corresponding DNS query: 2.23.227.208 |
Source: unknown | TCP traffic detected without corresponding DNS query: 2.23.227.208 |
Source: unknown | TCP traffic detected without corresponding DNS query: 147.185.221.25 |
Source: unknown | TCP traffic detected without corresponding DNS query: 147.185.221.25 |
Source: unknown | TCP traffic detected without corresponding DNS query: 147.185.221.25 |
Source: unknown | TCP traffic detected without corresponding DNS query: 2.23.227.208 |
Source: unknown | TCP traffic detected without corresponding DNS query: 147.185.221.25 |
Source: unknown | TCP traffic detected without corresponding DNS query: 147.185.221.25 |
Source: unknown | TCP traffic detected without corresponding DNS query: 204.79.197.203 |
Source: unknown | TCP traffic detected without corresponding DNS query: 204.79.197.203 |
Source: unknown | TCP traffic detected without corresponding DNS query: 204.79.197.203 |
Source: unknown | TCP traffic detected without corresponding DNS query: 147.185.221.25 |
Source: unknown | TCP traffic detected without corresponding DNS query: 147.185.221.25 |
Source: unknown | TCP traffic detected without corresponding DNS query: 147.185.221.25 |
Source: unknown | TCP traffic detected without corresponding DNS query: 147.185.221.25 |
Source: unknown | TCP traffic detected without corresponding DNS query: 204.79.197.203 |
Source: unknown | TCP traffic detected without corresponding DNS query: 204.79.197.203 |
Source: unknown | TCP traffic detected without corresponding DNS query: 20.189.173.15 |
Source: unknown | TCP traffic detected without corresponding DNS query: 20.189.173.15 |
Source: unknown | TCP traffic detected without corresponding DNS query: 204.79.197.203 |
Source: unknown | TCP traffic detected without corresponding DNS query: 20.189.173.15 |
Source: unknown | TCP traffic detected without corresponding DNS query: 20.189.173.15 |
Source: unknown | TCP traffic detected without corresponding DNS query: 147.185.221.25 |
Source: unknown | TCP traffic detected without corresponding DNS query: 20.189.173.15 |
Source: unknown | TCP traffic detected without corresponding DNS query: 20.189.173.15 |
Source: unknown | TCP traffic detected without corresponding DNS query: 204.79.197.203 |
Source: unknown | TCP traffic detected without corresponding DNS query: 147.185.221.25 |
Source: unknown | TCP traffic detected without corresponding DNS query: 147.185.221.25 |
Source: unknown | TCP traffic detected without corresponding DNS query: 147.185.221.25 |
Source: unknown | TCP traffic detected without corresponding DNS query: 147.185.221.25 |
Source: unknown | TCP traffic detected without corresponding DNS query: 147.185.221.25 |
Source: unknown | TCP traffic detected without corresponding DNS query: 20.189.173.15 |
Source: unknown | TCP traffic detected without corresponding DNS query: 147.185.221.25 |
Source: unknown | TCP traffic detected without corresponding DNS query: 147.185.221.25 |
Source: unknown | TCP traffic detected without corresponding DNS query: 147.185.221.25 |
Source: unknown | TCP traffic detected without corresponding DNS query: 147.185.221.25 |
Source: unknown | TCP traffic detected without corresponding DNS query: 147.185.221.25 |
Source: unknown | TCP traffic detected without corresponding DNS query: 147.185.221.25 |
Source: unknown | TCP traffic detected without corresponding DNS query: 147.185.221.25 |
Source: unknown | TCP traffic detected without corresponding DNS query: 147.185.221.25 |
Source: unknown | TCP traffic detected without corresponding DNS query: 147.185.221.25 |
Source: unknown | TCP traffic detected without corresponding DNS query: 147.185.221.25 |
Source: unknown | TCP traffic detected without corresponding DNS query: 147.185.221.25 |
Source: unknown | TCP traffic detected without corresponding DNS query: 147.185.221.25 |
Source: RegSvcs.exe, 00000002.00000002.3351469960.0000000002AB1000.00000004.00000800.00020000.00000000.sdmp | String found in binary or memory: http://schemas.xmlsoap.org/ws/2005/05/identity/claims/name |
Source: SecuriteInfo.com.Win32.RATX-gen.28955.11907.exe, 00000003.00000002.1040941521.0000000002CE8000.00000004.00000020.00020000.00000000.sdmp, SecuriteInfo.com.Win32.RATX-gen.28955.11907.exe, 00000003.00000003.1039037230.0000000002CE8000.00000004.00000020.00020000.00000000.sdmp | String found in binary or memory: https://aui-cdn.atlassian.com/ |
Source: SecuriteInfo.com.Win32.RATX-gen.28955.11907.exe, 00000003.00000002.1040941521.0000000002CE8000.00000004.00000020.00020000.00000000.sdmp, SecuriteInfo.com.Win32.RATX-gen.28955.11907.exe, 00000003.00000003.1039037230.0000000002CE8000.00000004.00000020.00020000.00000000.sdmp | String found in binary or memory: https://bbc-frontbucket-canary.prod-east.frontend.public.atl-paas.net |
Source: SecuriteInfo.com.Win32.RATX-gen.28955.11907.exe, 00000003.00000002.1040941521.0000000002CE8000.00000004.00000020.00020000.00000000.sdmp, SecuriteInfo.com.Win32.RATX-gen.28955.11907.exe, 00000003.00000003.1039037230.0000000002CE8000.00000004.00000020.00020000.00000000.sdmp | String found in binary or memory: https://bbc-frontbucket-exp.prod-east.fronte |
Source: SecuriteInfo.com.Win32.RATX-gen.28955.11907.exe, 00000003.00000002.1040941521.0000000002CE8000.00000004.00000020.00020000.00000000.sdmp, SecuriteInfo.com.Win32.RATX-gen.28955.11907.exe, 00000003.00000003.1039037230.0000000002CE8000.00000004.00000020.00020000.00000000.sdmp | String found in binary or memory: https://bbc-frontbucket-static.prod-east.frontend.public.atl-paas.net |
Source: SecuriteInfo.com.Win32.RATX-gen.28955.11907.exe, 00000003.00000002.1040941521.0000000002CE8000.00000004.00000020.00020000.00000000.sdmp, SecuriteInfo.com.Win32.RATX-gen.28955.11907.exe, 00000003.00000003.1039037230.0000000002CE8000.00000004.00000020.00020000.00000000.sdmp | String found in binary or memory: https://bbc-frontbucket-static.stg-east.frontend.public.atl-paas.net |
Source: SecuriteInfo.com.Win32.RATX-gen.28955.11907.exe, 00000006.00000002.1118387844.00000000010E1000.00000004.00000020.00020000.00000000.sdmp, SecuriteInfo.com.Win32.RATX-gen.28955.11907.exe, 00000006.00000002.1118779907.0000000003640000.00000004.00000020.00020000.00000000.sdmp | String found in binary or memory: https://bitbucket.org/ |
Source: SecuriteInfo.com.Win32.RATX-gen.28955.11907.exe, 00000001.00000002.3350712838.0000000002818000.00000004.00000020.00020000.00000000.sdmp | String found in binary or memory: https://bitbucket.org/L |
Source: SecuriteInfo.com.Win32.RATX-gen.28955.11907.exe, 00000006.00000003.1117634851.00000000010E1000.00000004.00000020.00020000.00000000.sdmp, SecuriteInfo.com.Win32.RATX-gen.28955.11907.exe, 00000006.00000002.1118387844.00000000010E1000.00000004.00000020.00020000.00000000.sdmp | String found in binary or memory: https://bitbucket.org/emCertificates |
Source: SecuriteInfo.com.Win32.RATX-gen.28955.11907.exe, 00000003.00000002.1040900244.0000000002CC0000.00000004.00000020.00020000.00000000.sdmp, SecuriteInfo.com.Win32.RATX-gen.28955.11907.exe, 00000003.00000002.1040941521.0000000002CE8000.00000004.00000020.00020000.00000000.sdmp, SecuriteInfo.com.Win32.RATX-gen.28955.11907.exe, 00000003.00000002.1040603183.000000000130B000.00000004.00000020.00020000.00000000.sdmp, SecuriteInfo.com.Win32.RATX-gen.28955.11907.exe, 00000003.00000003.1039037230.0000000002CE8000.00000004.00000020.00020000.00000000.sdmp, SecuriteInfo.com.Win32.RATX-gen.28955.11907.exe, 00000006.00000002.1118195057.0000000001020000.00000004.00000020.00020000.00000000.sdmp, SecuriteInfo.com.Win32.RATX-gen.28955.11907.exe, 00000006.00000003.1117634851.00000000010E1000.00000004.00000020.00020000.00000000.sdmp, SecuriteInfo.com.Win32.RATX-gen.28955.11907.exe, 00000006.00000002.1118444909.00000000010F5000.00000004.00000020.00020000.00000000.sdmp, SecuriteInfo.com.Win32.RATX-gen.28955.11907.exe, 00000006.00000002.1118387844.00000000010E1000.00000004.00000020.00020000.00000000.sdmp, SecuriteInfo.com.Win32.RATX-gen.28955.11907.exe, 00000006.00000002.1118195057.000000000102C000.00000004.00000020.00020000.00000000.sdmp, SecuriteInfo.com.Win32.RATX-gen.28955.11907.exe, 00000006.00000003.1116334589.00000000010F4000.00000004.00000020.00020000.00000000.sdmp | String found in binary or memory: https://bitbucket.org/riskwca/cscacxxxc/raw/16e98537939dbd6e2c9c4b3c241587b92e1bf2cf/sdfsdfc |
Source: SecuriteInfo.com.Win32.RATX-gen.28955.11907.exe, 00000006.00000003.1117634851.00000000010E1000.00000004.00000020.00020000.00000000.sdmp, SecuriteInfo.com.Win32.RATX-gen.28955.11907.exe, 00000006.00000002.1118387844.00000000010E1000.00000004.00000020.00020000.00000000.sdmp | String found in binary or memory: https://bitbucket.org/riskwca/cscacxxxc/raw/16e98537939dbd6e2c9c4b3c241587b92e1bf2cf/sdfsdfc7 |
Source: SecuriteInfo.com.Win32.RATX-gen.28955.11907.exe, 00000006.00000002.1118779907.0000000003640000.00000004.00000020.00020000.00000000.sdmp | String found in binary or memory: https://bitbucket.org/riskwca/cscacxxxc/raw/16e98537939dbd6e2c9c4b3c241587b92e1bf2cf/sdfsdfc? |
Source: SecuriteInfo.com.Win32.RATX-gen.28955.11907.exe, 00000003.00000002.1040900244.0000000002CC0000.00000004.00000020.00020000.00000000.sdmp | String found in binary or memory: https://bitbucket.org/riskwca/cscacxxxc/raw/16e98537939dbd6e2c9c4b3c241587b92e1bf2cf/sdfsdfcEB |
Source: SecuriteInfo.com.Win32.RATX-gen.28955.11907.exe, 00000001.00000002.3349516025.0000000000B7E000.00000004.00000020.00020000.00000000.sdmp | String found in binary or memory: https://bitbucket.org/riskwca/cscacxxxc/raw/16e98537939dbd6e2c9c4b3c241587b92e1bf2cf/sdfsdfcw |
Source: SecuriteInfo.com.Win32.RATX-gen.28955.11907.exe, 00000003.00000002.1040941521.0000000002CE8000.00000004.00000020.00020000.00000000.sdmp, SecuriteInfo.com.Win32.RATX-gen.28955.11907.exe, 00000003.00000003.1039037230.0000000002CE8000.00000004.00000020.00020000.00000000.sdmp | String found in binary or memory: https://cdn.cookielaw.org/ |
Source: 6.3.SecuriteInfo.com.Win32.RATX-gen.28955.11907.exe.368e3a0.0.unpack, type: UNPACKEDPE | Matched rule: Finds XWorm (version XClient, v3) samples based on characteristic strings Author: Sekoia.io |
Source: 6.3.SecuriteInfo.com.Win32.RATX-gen.28955.11907.exe.368e3a0.0.unpack, type: UNPACKEDPE | Matched rule: Detects AsyncRAT Author: ditekSHen |
Source: 6.3.SecuriteInfo.com.Win32.RATX-gen.28955.11907.exe.3683120.1.unpack, type: UNPACKEDPE | Matched rule: Finds XWorm (version XClient, v3) samples based on characteristic strings Author: Sekoia.io |
Source: 6.3.SecuriteInfo.com.Win32.RATX-gen.28955.11907.exe.3683120.1.unpack, type: UNPACKEDPE | Matched rule: Detects AsyncRAT Author: ditekSHen |
Source: 3.3.SecuriteInfo.com.Win32.RATX-gen.28955.11907.exe.2d63e80.1.unpack, type: UNPACKEDPE | Matched rule: Finds XWorm (version XClient, v3) samples based on characteristic strings Author: Sekoia.io |
Source: 3.3.SecuriteInfo.com.Win32.RATX-gen.28955.11907.exe.2d63e80.1.unpack, type: UNPACKEDPE | Matched rule: Detects AsyncRAT Author: ditekSHen |
Source: 6.3.SecuriteInfo.com.Win32.RATX-gen.28955.11907.exe.368e3a0.0.raw.unpack, type: UNPACKEDPE | Matched rule: Finds XWorm (version XClient, v3) samples based on characteristic strings Author: Sekoia.io |
Source: 6.3.SecuriteInfo.com.Win32.RATX-gen.28955.11907.exe.368e3a0.0.raw.unpack, type: UNPACKEDPE | Matched rule: Detects AsyncRAT Author: ditekSHen |
Source: 2.2.RegSvcs.exe.400000.0.unpack, type: UNPACKEDPE | Matched rule: Finds XWorm (version XClient, v3) samples based on characteristic strings Author: Sekoia.io |
Source: 2.2.RegSvcs.exe.400000.0.unpack, type: UNPACKEDPE | Matched rule: Detects AsyncRAT Author: ditekSHen |
Source: 6.3.SecuriteInfo.com.Win32.RATX-gen.28955.11907.exe.3683120.1.raw.unpack, type: UNPACKEDPE | Matched rule: Finds XWorm (version XClient, v3) samples based on characteristic strings Author: Sekoia.io |
Source: 6.3.SecuriteInfo.com.Win32.RATX-gen.28955.11907.exe.3683120.1.raw.unpack, type: UNPACKEDPE | Matched rule: Detects AsyncRAT Author: ditekSHen |
Source: 3.3.SecuriteInfo.com.Win32.RATX-gen.28955.11907.exe.2d63e80.1.raw.unpack, type: UNPACKEDPE | Matched rule: Finds XWorm (version XClient, v3) samples based on characteristic strings Author: Sekoia.io |
Source: 3.3.SecuriteInfo.com.Win32.RATX-gen.28955.11907.exe.2d63e80.1.raw.unpack, type: UNPACKEDPE | Matched rule: Detects AsyncRAT Author: ditekSHen |
Source: 3.3.SecuriteInfo.com.Win32.RATX-gen.28955.11907.exe.2d58c00.0.unpack, type: UNPACKEDPE | Matched rule: Finds XWorm (version XClient, v3) samples based on characteristic strings Author: Sekoia.io |
Source: 3.3.SecuriteInfo.com.Win32.RATX-gen.28955.11907.exe.2d58c00.0.unpack, type: UNPACKEDPE | Matched rule: Detects AsyncRAT Author: ditekSHen |
Source: 3.3.SecuriteInfo.com.Win32.RATX-gen.28955.11907.exe.2d58c00.0.raw.unpack, type: UNPACKEDPE | Matched rule: Finds XWorm (version XClient, v3) samples based on characteristic strings Author: Sekoia.io |
Source: 3.3.SecuriteInfo.com.Win32.RATX-gen.28955.11907.exe.2d58c00.0.raw.unpack, type: UNPACKEDPE | Matched rule: Detects AsyncRAT Author: ditekSHen |
Source: 1.2.SecuriteInfo.com.Win32.RATX-gen.28955.11907.exe.28518a0.3.raw.unpack, type: UNPACKEDPE | Matched rule: Finds XWorm (version XClient, v3) samples based on characteristic strings Author: Sekoia.io |
Source: 1.2.SecuriteInfo.com.Win32.RATX-gen.28955.11907.exe.28518a0.3.raw.unpack, type: UNPACKEDPE | Matched rule: Detects AsyncRAT Author: ditekSHen |
Source: 00000006.00000003.1114583957.000000000367C000.00000004.00000020.00020000.00000000.sdmp, type: MEMORY | Matched rule: Detects AsyncRAT Author: ditekSHen |
Source: 00000006.00000003.1114583957.000000000368E000.00000004.00000020.00020000.00000000.sdmp, type: MEMORY | Matched rule: Detects AsyncRAT Author: ditekSHen |
Source: 00000001.00000002.3350712838.000000000284E000.00000004.00000020.00020000.00000000.sdmp, type: MEMORY | Matched rule: Detects AsyncRAT Author: ditekSHen |
Source: 00000002.00000002.3348856700.0000000000402000.00000040.00000400.00020000.00000000.sdmp, type: MEMORY | Matched rule: Detects AsyncRAT Author: ditekSHen |
Source: 00000003.00000003.1038950135.0000000002D46000.00000004.00000020.00020000.00000000.sdmp, type: MEMORY | Matched rule: Detects AsyncRAT Author: ditekSHen |
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.RATX-gen.28955.11907.exe | Code function: 0_2_00561010 | 0_2_00561010 |
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.RATX-gen.28955.11907.exe | Code function: 0_2_005550A7 | 0_2_005550A7 |
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.RATX-gen.28955.11907.exe | Code function: 0_2_0054B1A0 | 0_2_0054B1A0 |
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.RATX-gen.28955.11907.exe | Code function: 0_2_00567282 | 0_2_00567282 |
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.RATX-gen.28955.11907.exe | Code function: 0_2_00561370 | 0_2_00561370 |
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.RATX-gen.28955.11907.exe | Code function: 0_2_0054D997 | 0_2_0054D997 |
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.RATX-gen.28955.11907.exe | Code function: 0_2_0055FB69 | 0_2_0055FB69 |
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.RATX-gen.28955.11907.exe | Code function: 0_2_00556E70 | 0_2_00556E70 |
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.RATX-gen.28955.11907.exe | Code function: 0_2_0054EF60 | 0_2_0054EF60 |
Source: C:\Users\user\AppData\Roaming\SecuriteInfo.com.Win32.RATX-gen.28955.11907.exe | Code function: 1_2_00DB50A7 | 1_2_00DB50A7 |
Source: C:\Users\user\AppData\Roaming\SecuriteInfo.com.Win32.RATX-gen.28955.11907.exe | Code function: 1_2_00DC1010 | 1_2_00DC1010 |
Source: C:\Users\user\AppData\Roaming\SecuriteInfo.com.Win32.RATX-gen.28955.11907.exe | Code function: 1_2_00DAB1A0 | 1_2_00DAB1A0 |
Source: C:\Users\user\AppData\Roaming\SecuriteInfo.com.Win32.RATX-gen.28955.11907.exe | Code function: 1_2_00DC7282 | 1_2_00DC7282 |
Source: C:\Users\user\AppData\Roaming\SecuriteInfo.com.Win32.RATX-gen.28955.11907.exe | Code function: 1_2_00DC1370 | 1_2_00DC1370 |
Source: C:\Users\user\AppData\Roaming\SecuriteInfo.com.Win32.RATX-gen.28955.11907.exe | Code function: 1_2_00DAD997 | 1_2_00DAD997 |
Source: C:\Users\user\AppData\Roaming\SecuriteInfo.com.Win32.RATX-gen.28955.11907.exe | Code function: 1_2_00DBFB69 | 1_2_00DBFB69 |
Source: C:\Users\user\AppData\Roaming\SecuriteInfo.com.Win32.RATX-gen.28955.11907.exe | Code function: 1_2_00DB6E70 | 1_2_00DB6E70 |
Source: C:\Users\user\AppData\Roaming\SecuriteInfo.com.Win32.RATX-gen.28955.11907.exe | Code function: 1_2_00DAEF60 | 1_2_00DAEF60 |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe | Code function: 2_2_0102EAF8 | 2_2_0102EAF8 |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe | Code function: 2_2_01021399 | 2_2_01021399 |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe | Code function: 2_2_05060440 | 2_2_05060440 |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe | Code function: 2_2_0506B7F8 | 2_2_0506B7F8 |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe | Code function: 2_2_0506BC9A | 2_2_0506BC9A |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe | Code function: 2_2_05066F30 | 2_2_05066F30 |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe | Code function: 2_2_0506AFC0 | 2_2_0506AFC0 |
Source: 6.3.SecuriteInfo.com.Win32.RATX-gen.28955.11907.exe.368e3a0.0.unpack, type: UNPACKEDPE | Matched rule: rat_win_xworm_v3 author = Sekoia.io, description = Finds XWorm (version XClient, v3) samples based on characteristic strings, creation_date = 2023-03-03, classification = TLP:CLEAR, version = 1.0, id = 5fb1cbd3-1e37-43b9-9606-86d896f2150b, hash = de0127ba872c0677c3594c66b2298edea58d097b5fa697302a16b1689147b147 |
Source: 6.3.SecuriteInfo.com.Win32.RATX-gen.28955.11907.exe.368e3a0.0.unpack, type: UNPACKEDPE | Matched rule: MALWARE_Win_AsyncRAT author = ditekSHen, description = Detects AsyncRAT |
Source: 6.3.SecuriteInfo.com.Win32.RATX-gen.28955.11907.exe.3683120.1.unpack, type: UNPACKEDPE | Matched rule: rat_win_xworm_v3 author = Sekoia.io, description = Finds XWorm (version XClient, v3) samples based on characteristic strings, creation_date = 2023-03-03, classification = TLP:CLEAR, version = 1.0, id = 5fb1cbd3-1e37-43b9-9606-86d896f2150b, hash = de0127ba872c0677c3594c66b2298edea58d097b5fa697302a16b1689147b147 |
Source: 6.3.SecuriteInfo.com.Win32.RATX-gen.28955.11907.exe.3683120.1.unpack, type: UNPACKEDPE | Matched rule: MALWARE_Win_AsyncRAT author = ditekSHen, description = Detects AsyncRAT |
Source: 3.3.SecuriteInfo.com.Win32.RATX-gen.28955.11907.exe.2d63e80.1.unpack, type: UNPACKEDPE | Matched rule: rat_win_xworm_v3 author = Sekoia.io, description = Finds XWorm (version XClient, v3) samples based on characteristic strings, creation_date = 2023-03-03, classification = TLP:CLEAR, version = 1.0, id = 5fb1cbd3-1e37-43b9-9606-86d896f2150b, hash = de0127ba872c0677c3594c66b2298edea58d097b5fa697302a16b1689147b147 |
Source: 3.3.SecuriteInfo.com.Win32.RATX-gen.28955.11907.exe.2d63e80.1.unpack, type: UNPACKEDPE | Matched rule: MALWARE_Win_AsyncRAT author = ditekSHen, description = Detects AsyncRAT |
Source: 6.3.SecuriteInfo.com.Win32.RATX-gen.28955.11907.exe.368e3a0.0.raw.unpack, type: UNPACKEDPE | Matched rule: rat_win_xworm_v3 author = Sekoia.io, description = Finds XWorm (version XClient, v3) samples based on characteristic strings, creation_date = 2023-03-03, classification = TLP:CLEAR, version = 1.0, id = 5fb1cbd3-1e37-43b9-9606-86d896f2150b, hash = de0127ba872c0677c3594c66b2298edea58d097b5fa697302a16b1689147b147 |
Source: 6.3.SecuriteInfo.com.Win32.RATX-gen.28955.11907.exe.368e3a0.0.raw.unpack, type: UNPACKEDPE | Matched rule: MALWARE_Win_AsyncRAT author = ditekSHen, description = Detects AsyncRAT |
Source: 2.2.RegSvcs.exe.400000.0.unpack, type: UNPACKEDPE | Matched rule: rat_win_xworm_v3 author = Sekoia.io, description = Finds XWorm (version XClient, v3) samples based on characteristic strings, creation_date = 2023-03-03, classification = TLP:CLEAR, version = 1.0, id = 5fb1cbd3-1e37-43b9-9606-86d896f2150b, hash = de0127ba872c0677c3594c66b2298edea58d097b5fa697302a16b1689147b147 |
Source: 2.2.RegSvcs.exe.400000.0.unpack, type: UNPACKEDPE | Matched rule: MALWARE_Win_AsyncRAT author = ditekSHen, description = Detects AsyncRAT |
Source: 6.3.SecuriteInfo.com.Win32.RATX-gen.28955.11907.exe.3683120.1.raw.unpack, type: UNPACKEDPE | Matched rule: rat_win_xworm_v3 author = Sekoia.io, description = Finds XWorm (version XClient, v3) samples based on characteristic strings, creation_date = 2023-03-03, classification = TLP:CLEAR, version = 1.0, id = 5fb1cbd3-1e37-43b9-9606-86d896f2150b, hash = de0127ba872c0677c3594c66b2298edea58d097b5fa697302a16b1689147b147 |
Source: 6.3.SecuriteInfo.com.Win32.RATX-gen.28955.11907.exe.3683120.1.raw.unpack, type: UNPACKEDPE | Matched rule: MALWARE_Win_AsyncRAT author = ditekSHen, description = Detects AsyncRAT |
Source: 3.3.SecuriteInfo.com.Win32.RATX-gen.28955.11907.exe.2d63e80.1.raw.unpack, type: UNPACKEDPE | Matched rule: rat_win_xworm_v3 author = Sekoia.io, description = Finds XWorm (version XClient, v3) samples based on characteristic strings, creation_date = 2023-03-03, classification = TLP:CLEAR, version = 1.0, id = 5fb1cbd3-1e37-43b9-9606-86d896f2150b, hash = de0127ba872c0677c3594c66b2298edea58d097b5fa697302a16b1689147b147 |
Source: 3.3.SecuriteInfo.com.Win32.RATX-gen.28955.11907.exe.2d63e80.1.raw.unpack, type: UNPACKEDPE | Matched rule: MALWARE_Win_AsyncRAT author = ditekSHen, description = Detects AsyncRAT |
Source: 3.3.SecuriteInfo.com.Win32.RATX-gen.28955.11907.exe.2d58c00.0.unpack, type: UNPACKEDPE | Matched rule: rat_win_xworm_v3 author = Sekoia.io, description = Finds XWorm (version XClient, v3) samples based on characteristic strings, creation_date = 2023-03-03, classification = TLP:CLEAR, version = 1.0, id = 5fb1cbd3-1e37-43b9-9606-86d896f2150b, hash = de0127ba872c0677c3594c66b2298edea58d097b5fa697302a16b1689147b147 |
Source: 3.3.SecuriteInfo.com.Win32.RATX-gen.28955.11907.exe.2d58c00.0.unpack, type: UNPACKEDPE | Matched rule: MALWARE_Win_AsyncRAT author = ditekSHen, description = Detects AsyncRAT |
Source: 3.3.SecuriteInfo.com.Win32.RATX-gen.28955.11907.exe.2d58c00.0.raw.unpack, type: UNPACKEDPE | Matched rule: rat_win_xworm_v3 author = Sekoia.io, description = Finds XWorm (version XClient, v3) samples based on characteristic strings, creation_date = 2023-03-03, classification = TLP:CLEAR, version = 1.0, id = 5fb1cbd3-1e37-43b9-9606-86d896f2150b, hash = de0127ba872c0677c3594c66b2298edea58d097b5fa697302a16b1689147b147 |
Source: 3.3.SecuriteInfo.com.Win32.RATX-gen.28955.11907.exe.2d58c00.0.raw.unpack, type: UNPACKEDPE | Matched rule: MALWARE_Win_AsyncRAT author = ditekSHen, description = Detects AsyncRAT |
Source: 1.2.SecuriteInfo.com.Win32.RATX-gen.28955.11907.exe.28518a0.3.raw.unpack, type: UNPACKEDPE | Matched rule: rat_win_xworm_v3 author = Sekoia.io, description = Finds XWorm (version XClient, v3) samples based on characteristic strings, creation_date = 2023-03-03, classification = TLP:CLEAR, version = 1.0, id = 5fb1cbd3-1e37-43b9-9606-86d896f2150b, hash = de0127ba872c0677c3594c66b2298edea58d097b5fa697302a16b1689147b147 |
Source: 1.2.SecuriteInfo.com.Win32.RATX-gen.28955.11907.exe.28518a0.3.raw.unpack, type: UNPACKEDPE | Matched rule: MALWARE_Win_AsyncRAT author = ditekSHen, description = Detects AsyncRAT |
Source: 00000006.00000003.1114583957.000000000367C000.00000004.00000020.00020000.00000000.sdmp, type: MEMORY | Matched rule: MALWARE_Win_AsyncRAT author = ditekSHen, description = Detects AsyncRAT |
Source: 00000006.00000003.1114583957.000000000368E000.00000004.00000020.00020000.00000000.sdmp, type: MEMORY | Matched rule: MALWARE_Win_AsyncRAT author = ditekSHen, description = Detects AsyncRAT |
Source: 00000001.00000002.3350712838.000000000284E000.00000004.00000020.00020000.00000000.sdmp, type: MEMORY | Matched rule: MALWARE_Win_AsyncRAT author = ditekSHen, description = Detects AsyncRAT |
Source: 00000002.00000002.3348856700.0000000000402000.00000040.00000400.00020000.00000000.sdmp, type: MEMORY | Matched rule: MALWARE_Win_AsyncRAT author = ditekSHen, description = Detects AsyncRAT |
Source: 00000003.00000003.1038950135.0000000002D46000.00000004.00000020.00020000.00000000.sdmp, type: MEMORY | Matched rule: MALWARE_Win_AsyncRAT author = ditekSHen, description = Detects AsyncRAT |
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.RATX-gen.28955.11907.exe | Section loaded: apphelp.dll | Jump to behavior |
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.RATX-gen.28955.11907.exe | Section loaded: cryptbase.dll | Jump to behavior |
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.RATX-gen.28955.11907.exe | Section loaded: uxtheme.dll | Jump to behavior |
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.RATX-gen.28955.11907.exe | Section loaded: windows.storage.dll | Jump to behavior |
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.RATX-gen.28955.11907.exe | Section loaded: wldp.dll | Jump to behavior |
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.RATX-gen.28955.11907.exe | Section loaded: windows.storage.dll | Jump to behavior |
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.RATX-gen.28955.11907.exe | Section loaded: wldp.dll | Jump to behavior |
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.RATX-gen.28955.11907.exe | Section loaded: ntmarta.dll | Jump to behavior |
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.RATX-gen.28955.11907.exe | Section loaded: windows.storage.dll | Jump to behavior |
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.RATX-gen.28955.11907.exe | Section loaded: wldp.dll | Jump to behavior |
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.RATX-gen.28955.11907.exe | Section loaded: kernel.appcore.dll | Jump to behavior |
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.RATX-gen.28955.11907.exe | Section loaded: propsys.dll | Jump to behavior |
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.RATX-gen.28955.11907.exe | Section loaded: profapi.dll | Jump to behavior |
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.RATX-gen.28955.11907.exe | Section loaded: edputil.dll | Jump to behavior |
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.RATX-gen.28955.11907.exe | Section loaded: urlmon.dll | Jump to behavior |
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.RATX-gen.28955.11907.exe | Section loaded: iertutil.dll | Jump to behavior |
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.RATX-gen.28955.11907.exe | Section loaded: srvcli.dll | Jump to behavior |
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.RATX-gen.28955.11907.exe | Section loaded: netutils.dll | Jump to behavior |
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.RATX-gen.28955.11907.exe | Section loaded: windows.staterepositoryps.dll | Jump to behavior |
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.RATX-gen.28955.11907.exe | Section loaded: sspicli.dll | Jump to behavior |
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.RATX-gen.28955.11907.exe | Section loaded: wintypes.dll | Jump to behavior |
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.RATX-gen.28955.11907.exe | Section loaded: appresolver.dll | Jump to behavior |
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.RATX-gen.28955.11907.exe | Section loaded: bcp47langs.dll | Jump to behavior |
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.RATX-gen.28955.11907.exe | Section loaded: slc.dll | Jump to behavior |
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.RATX-gen.28955.11907.exe | Section loaded: userenv.dll | Jump to behavior |
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.RATX-gen.28955.11907.exe | Section loaded: sppc.dll | Jump to behavior |
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.RATX-gen.28955.11907.exe | Section loaded: onecorecommonproxystub.dll | Jump to behavior |
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.RATX-gen.28955.11907.exe | Section loaded: onecoreuapcommonproxystub.dll | Jump to behavior |
Source: C:\Users\user\AppData\Roaming\SecuriteInfo.com.Win32.RATX-gen.28955.11907.exe | Section loaded: apphelp.dll | Jump to behavior |
Source: C:\Users\user\AppData\Roaming\SecuriteInfo.com.Win32.RATX-gen.28955.11907.exe | Section loaded: cryptbase.dll | Jump to behavior |
Source: C:\Users\user\AppData\Roaming\SecuriteInfo.com.Win32.RATX-gen.28955.11907.exe | Section loaded: uxtheme.dll | Jump to behavior |
Source: C:\Users\user\AppData\Roaming\SecuriteInfo.com.Win32.RATX-gen.28955.11907.exe | Section loaded: windows.storage.dll | Jump to behavior |
Source: C:\Users\user\AppData\Roaming\SecuriteInfo.com.Win32.RATX-gen.28955.11907.exe | Section loaded: wldp.dll | Jump to behavior |
Source: C:\Users\user\AppData\Roaming\SecuriteInfo.com.Win32.RATX-gen.28955.11907.exe | Section loaded: windows.storage.dll | Jump to behavior |
Source: C:\Users\user\AppData\Roaming\SecuriteInfo.com.Win32.RATX-gen.28955.11907.exe | Section loaded: wldp.dll | Jump to behavior |
Source: C:\Users\user\AppData\Roaming\SecuriteInfo.com.Win32.RATX-gen.28955.11907.exe | Section loaded: wininet.dll | Jump to behavior |
Source: C:\Users\user\AppData\Roaming\SecuriteInfo.com.Win32.RATX-gen.28955.11907.exe | Section loaded: iertutil.dll | Jump to behavior |
Source: C:\Users\user\AppData\Roaming\SecuriteInfo.com.Win32.RATX-gen.28955.11907.exe | Section loaded: sspicli.dll | Jump to behavior |
Source: C:\Users\user\AppData\Roaming\SecuriteInfo.com.Win32.RATX-gen.28955.11907.exe | Section loaded: windows.storage.dll | Jump to behavior |
Source: C:\Users\user\AppData\Roaming\SecuriteInfo.com.Win32.RATX-gen.28955.11907.exe | Section loaded: wldp.dll | Jump to behavior |
Source: C:\Users\user\AppData\Roaming\SecuriteInfo.com.Win32.RATX-gen.28955.11907.exe | Section loaded: profapi.dll | Jump to behavior |
Source: C:\Users\user\AppData\Roaming\SecuriteInfo.com.Win32.RATX-gen.28955.11907.exe | Section loaded: kernel.appcore.dll | Jump to behavior |
Source: C:\Users\user\AppData\Roaming\SecuriteInfo.com.Win32.RATX-gen.28955.11907.exe | Section loaded: ondemandconnroutehelper.dll | Jump to behavior |
Source: C:\Users\user\AppData\Roaming\SecuriteInfo.com.Win32.RATX-gen.28955.11907.exe | Section loaded: winhttp.dll | Jump to behavior |
Source: C:\Users\user\AppData\Roaming\SecuriteInfo.com.Win32.RATX-gen.28955.11907.exe | Section loaded: mswsock.dll | Jump to behavior |
Source: C:\Users\user\AppData\Roaming\SecuriteInfo.com.Win32.RATX-gen.28955.11907.exe | Section loaded: iphlpapi.dll | Jump to behavior |
Source: C:\Users\user\AppData\Roaming\SecuriteInfo.com.Win32.RATX-gen.28955.11907.exe | Section loaded: winnsi.dll | Jump to behavior |
Source: C:\Users\user\AppData\Roaming\SecuriteInfo.com.Win32.RATX-gen.28955.11907.exe | Section loaded: urlmon.dll | Jump to behavior |
Source: C:\Users\user\AppData\Roaming\SecuriteInfo.com.Win32.RATX-gen.28955.11907.exe | Section loaded: srvcli.dll | Jump to behavior |
Source: C:\Users\user\AppData\Roaming\SecuriteInfo.com.Win32.RATX-gen.28955.11907.exe | Section loaded: netutils.dll | Jump to behavior |
Source: C:\Users\user\AppData\Roaming\SecuriteInfo.com.Win32.RATX-gen.28955.11907.exe | Section loaded: dnsapi.dll | Jump to behavior |
Source: C:\Users\user\AppData\Roaming\SecuriteInfo.com.Win32.RATX-gen.28955.11907.exe | Section loaded: rasadhlp.dll | Jump to behavior |
Source: C:\Users\user\AppData\Roaming\SecuriteInfo.com.Win32.RATX-gen.28955.11907.exe | Section loaded: fwpuclnt.dll | Jump to behavior |
Source: C:\Users\user\AppData\Roaming\SecuriteInfo.com.Win32.RATX-gen.28955.11907.exe | Section loaded: schannel.dll | Jump to behavior |
Source: C:\Users\user\AppData\Roaming\SecuriteInfo.com.Win32.RATX-gen.28955.11907.exe | Section loaded: mskeyprotect.dll | Jump to behavior |
Source: C:\Users\user\AppData\Roaming\SecuriteInfo.com.Win32.RATX-gen.28955.11907.exe | Section loaded: ntasn1.dll | Jump to behavior |
Source: C:\Users\user\AppData\Roaming\SecuriteInfo.com.Win32.RATX-gen.28955.11907.exe | Section loaded: msasn1.dll | Jump to behavior |
Source: C:\Users\user\AppData\Roaming\SecuriteInfo.com.Win32.RATX-gen.28955.11907.exe | Section loaded: dpapi.dll | Jump to behavior |
Source: C:\Users\user\AppData\Roaming\SecuriteInfo.com.Win32.RATX-gen.28955.11907.exe | Section loaded: cryptsp.dll | Jump to behavior |
Source: C:\Users\user\AppData\Roaming\SecuriteInfo.com.Win32.RATX-gen.28955.11907.exe | Section loaded: rsaenh.dll | Jump to behavior |
Source: C:\Users\user\AppData\Roaming\SecuriteInfo.com.Win32.RATX-gen.28955.11907.exe | Section loaded: gpapi.dll | Jump to behavior |
Source: C:\Users\user\AppData\Roaming\SecuriteInfo.com.Win32.RATX-gen.28955.11907.exe | Section loaded: ncrypt.dll | Jump to behavior |
Source: C:\Users\user\AppData\Roaming\SecuriteInfo.com.Win32.RATX-gen.28955.11907.exe | Section loaded: ncryptsslp.dll | Jump to behavior |
Source: C:\Users\user\AppData\Roaming\SecuriteInfo.com.Win32.RATX-gen.28955.11907.exe | Section loaded: cryptbase.dll | Jump to behavior |
Source: C:\Users\user\AppData\Roaming\SecuriteInfo.com.Win32.RATX-gen.28955.11907.exe | Section loaded: uxtheme.dll | Jump to behavior |
Source: C:\Users\user\AppData\Roaming\SecuriteInfo.com.Win32.RATX-gen.28955.11907.exe | Section loaded: windows.storage.dll | Jump to behavior |
Source: C:\Users\user\AppData\Roaming\SecuriteInfo.com.Win32.RATX-gen.28955.11907.exe | Section loaded: wldp.dll | Jump to behavior |
Source: C:\Users\user\AppData\Roaming\SecuriteInfo.com.Win32.RATX-gen.28955.11907.exe | Section loaded: windows.storage.dll | Jump to behavior |
Source: C:\Users\user\AppData\Roaming\SecuriteInfo.com.Win32.RATX-gen.28955.11907.exe | Section loaded: wldp.dll | Jump to behavior |
Source: C:\Users\user\AppData\Roaming\SecuriteInfo.com.Win32.RATX-gen.28955.11907.exe | Section loaded: wininet.dll | Jump to behavior |
Source: C:\Users\user\AppData\Roaming\SecuriteInfo.com.Win32.RATX-gen.28955.11907.exe | Section loaded: iertutil.dll | Jump to behavior |
Source: C:\Users\user\AppData\Roaming\SecuriteInfo.com.Win32.RATX-gen.28955.11907.exe | Section loaded: sspicli.dll | Jump to behavior |
Source: C:\Users\user\AppData\Roaming\SecuriteInfo.com.Win32.RATX-gen.28955.11907.exe | Section loaded: windows.storage.dll | Jump to behavior |
Source: C:\Users\user\AppData\Roaming\SecuriteInfo.com.Win32.RATX-gen.28955.11907.exe | Section loaded: wldp.dll | Jump to behavior |
Source: C:\Users\user\AppData\Roaming\SecuriteInfo.com.Win32.RATX-gen.28955.11907.exe | Section loaded: profapi.dll | Jump to behavior |
Source: C:\Users\user\AppData\Roaming\SecuriteInfo.com.Win32.RATX-gen.28955.11907.exe | Section loaded: kernel.appcore.dll | Jump to behavior |
Source: C:\Users\user\AppData\Roaming\SecuriteInfo.com.Win32.RATX-gen.28955.11907.exe | Section loaded: ondemandconnroutehelper.dll | Jump to behavior |
Source: C:\Users\user\AppData\Roaming\SecuriteInfo.com.Win32.RATX-gen.28955.11907.exe | Section loaded: winhttp.dll | Jump to behavior |
Source: C:\Users\user\AppData\Roaming\SecuriteInfo.com.Win32.RATX-gen.28955.11907.exe | Section loaded: iphlpapi.dll | Jump to behavior |
Source: C:\Users\user\AppData\Roaming\SecuriteInfo.com.Win32.RATX-gen.28955.11907.exe | Section loaded: mswsock.dll | Jump to behavior |
Source: C:\Users\user\AppData\Roaming\SecuriteInfo.com.Win32.RATX-gen.28955.11907.exe | Section loaded: winnsi.dll | Jump to behavior |
Source: C:\Users\user\AppData\Roaming\SecuriteInfo.com.Win32.RATX-gen.28955.11907.exe | Section loaded: dpapi.dll | Jump to behavior |
Source: C:\Users\user\AppData\Roaming\SecuriteInfo.com.Win32.RATX-gen.28955.11907.exe | Section loaded: msasn1.dll | Jump to behavior |
Source: C:\Users\user\AppData\Roaming\SecuriteInfo.com.Win32.RATX-gen.28955.11907.exe | Section loaded: cryptsp.dll | Jump to behavior |
Source: C:\Users\user\AppData\Roaming\SecuriteInfo.com.Win32.RATX-gen.28955.11907.exe | Section loaded: rsaenh.dll | Jump to behavior |
Source: C:\Users\user\AppData\Roaming\SecuriteInfo.com.Win32.RATX-gen.28955.11907.exe | Section loaded: gpapi.dll | Jump to behavior |
Source: C:\Users\user\AppData\Roaming\SecuriteInfo.com.Win32.RATX-gen.28955.11907.exe | Section loaded: urlmon.dll | Jump to behavior |
Source: C:\Users\user\AppData\Roaming\SecuriteInfo.com.Win32.RATX-gen.28955.11907.exe | Section loaded: srvcli.dll | Jump to behavior |
Source: C:\Users\user\AppData\Roaming\SecuriteInfo.com.Win32.RATX-gen.28955.11907.exe | Section loaded: netutils.dll | Jump to behavior |
Source: C:\Users\user\AppData\Roaming\SecuriteInfo.com.Win32.RATX-gen.28955.11907.exe | Section loaded: dnsapi.dll | Jump to behavior |
Source: C:\Users\user\AppData\Roaming\SecuriteInfo.com.Win32.RATX-gen.28955.11907.exe | Section loaded: rasadhlp.dll | Jump to behavior |
Source: C:\Users\user\AppData\Roaming\SecuriteInfo.com.Win32.RATX-gen.28955.11907.exe | Section loaded: fwpuclnt.dll | Jump to behavior |
Source: C:\Users\user\AppData\Roaming\SecuriteInfo.com.Win32.RATX-gen.28955.11907.exe | Section loaded: schannel.dll | Jump to behavior |
Source: C:\Users\user\AppData\Roaming\SecuriteInfo.com.Win32.RATX-gen.28955.11907.exe | Section loaded: mskeyprotect.dll | Jump to behavior |
Source: C:\Users\user\AppData\Roaming\SecuriteInfo.com.Win32.RATX-gen.28955.11907.exe | Section loaded: ntasn1.dll | Jump to behavior |
Source: C:\Users\user\AppData\Roaming\SecuriteInfo.com.Win32.RATX-gen.28955.11907.exe | Section loaded: ncrypt.dll | Jump to behavior |
Source: C:\Users\user\AppData\Roaming\SecuriteInfo.com.Win32.RATX-gen.28955.11907.exe | Section loaded: ncryptsslp.dll | Jump to behavior |
Source: C:\Users\user\AppData\Roaming\SecuriteInfo.com.Win32.RATX-gen.28955.11907.exe | Section loaded: cryptbase.dll | Jump to behavior |
Source: C:\Users\user\AppData\Roaming\SecuriteInfo.com.Win32.RATX-gen.28955.11907.exe | Section loaded: uxtheme.dll | Jump to behavior |
Source: C:\Users\user\AppData\Roaming\SecuriteInfo.com.Win32.RATX-gen.28955.11907.exe | Section loaded: windows.storage.dll | Jump to behavior |
Source: C:\Users\user\AppData\Roaming\SecuriteInfo.com.Win32.RATX-gen.28955.11907.exe | Section loaded: wldp.dll | Jump to behavior |
Source: C:\Users\user\AppData\Roaming\SecuriteInfo.com.Win32.RATX-gen.28955.11907.exe | Section loaded: windows.storage.dll | Jump to behavior |
Source: C:\Users\user\AppData\Roaming\SecuriteInfo.com.Win32.RATX-gen.28955.11907.exe | Section loaded: wldp.dll | Jump to behavior |
Source: C:\Users\user\AppData\Roaming\SecuriteInfo.com.Win32.RATX-gen.28955.11907.exe | Section loaded: wininet.dll | Jump to behavior |
Source: C:\Users\user\AppData\Roaming\SecuriteInfo.com.Win32.RATX-gen.28955.11907.exe | Section loaded: iertutil.dll | Jump to behavior |
Source: C:\Users\user\AppData\Roaming\SecuriteInfo.com.Win32.RATX-gen.28955.11907.exe | Section loaded: sspicli.dll | Jump to behavior |
Source: C:\Users\user\AppData\Roaming\SecuriteInfo.com.Win32.RATX-gen.28955.11907.exe | Section loaded: windows.storage.dll | Jump to behavior |
Source: C:\Users\user\AppData\Roaming\SecuriteInfo.com.Win32.RATX-gen.28955.11907.exe | Section loaded: wldp.dll | Jump to behavior |
Source: C:\Users\user\AppData\Roaming\SecuriteInfo.com.Win32.RATX-gen.28955.11907.exe | Section loaded: profapi.dll | Jump to behavior |
Source: C:\Users\user\AppData\Roaming\SecuriteInfo.com.Win32.RATX-gen.28955.11907.exe | Section loaded: kernel.appcore.dll | Jump to behavior |
Source: C:\Users\user\AppData\Roaming\SecuriteInfo.com.Win32.RATX-gen.28955.11907.exe | Section loaded: ondemandconnroutehelper.dll | Jump to behavior |
Source: C:\Users\user\AppData\Roaming\SecuriteInfo.com.Win32.RATX-gen.28955.11907.exe | Section loaded: winhttp.dll | Jump to behavior |
Source: C:\Users\user\AppData\Roaming\SecuriteInfo.com.Win32.RATX-gen.28955.11907.exe | Section loaded: mswsock.dll | Jump to behavior |
Source: C:\Users\user\AppData\Roaming\SecuriteInfo.com.Win32.RATX-gen.28955.11907.exe | Section loaded: iphlpapi.dll | Jump to behavior |
Source: C:\Users\user\AppData\Roaming\SecuriteInfo.com.Win32.RATX-gen.28955.11907.exe | Section loaded: winnsi.dll | Jump to behavior |
Source: C:\Users\user\AppData\Roaming\SecuriteInfo.com.Win32.RATX-gen.28955.11907.exe | Section loaded: dpapi.dll | Jump to behavior |
Source: C:\Users\user\AppData\Roaming\SecuriteInfo.com.Win32.RATX-gen.28955.11907.exe | Section loaded: msasn1.dll | Jump to behavior |
Source: C:\Users\user\AppData\Roaming\SecuriteInfo.com.Win32.RATX-gen.28955.11907.exe | Section loaded: cryptsp.dll | Jump to behavior |
Source: C:\Users\user\AppData\Roaming\SecuriteInfo.com.Win32.RATX-gen.28955.11907.exe | Section loaded: rsaenh.dll | Jump to behavior |
Source: C:\Users\user\AppData\Roaming\SecuriteInfo.com.Win32.RATX-gen.28955.11907.exe | Section loaded: gpapi.dll | Jump to behavior |
Source: C:\Users\user\AppData\Roaming\SecuriteInfo.com.Win32.RATX-gen.28955.11907.exe | Section loaded: urlmon.dll | Jump to behavior |
Source: C:\Users\user\AppData\Roaming\SecuriteInfo.com.Win32.RATX-gen.28955.11907.exe | Section loaded: srvcli.dll | Jump to behavior |
Source: C:\Users\user\AppData\Roaming\SecuriteInfo.com.Win32.RATX-gen.28955.11907.exe | Section loaded: netutils.dll | Jump to behavior |
Source: C:\Users\user\AppData\Roaming\SecuriteInfo.com.Win32.RATX-gen.28955.11907.exe | Section loaded: dnsapi.dll | Jump to behavior |
Source: C:\Users\user\AppData\Roaming\SecuriteInfo.com.Win32.RATX-gen.28955.11907.exe | Section loaded: fwpuclnt.dll | Jump to behavior |
Source: C:\Users\user\AppData\Roaming\SecuriteInfo.com.Win32.RATX-gen.28955.11907.exe | Section loaded: rasadhlp.dll | Jump to behavior |
Source: C:\Users\user\AppData\Roaming\SecuriteInfo.com.Win32.RATX-gen.28955.11907.exe | Section loaded: schannel.dll | Jump to behavior |
Source: C:\Users\user\AppData\Roaming\SecuriteInfo.com.Win32.RATX-gen.28955.11907.exe | Section loaded: mskeyprotect.dll | Jump to behavior |
Source: C:\Users\user\AppData\Roaming\SecuriteInfo.com.Win32.RATX-gen.28955.11907.exe | Section loaded: ntasn1.dll | Jump to behavior |
Source: C:\Users\user\AppData\Roaming\SecuriteInfo.com.Win32.RATX-gen.28955.11907.exe | Section loaded: ncrypt.dll | Jump to behavior |
Source: C:\Users\user\AppData\Roaming\SecuriteInfo.com.Win32.RATX-gen.28955.11907.exe | Section loaded: ncryptsslp.dll | Jump to behavior |
Source: C:\Users\user\AppData\Roaming\SecuriteInfo.com.Win32.RATX-gen.28955.11907.exe | Section loaded: apphelp.dll | Jump to behavior |
Source: 3.3.SecuriteInfo.com.Win32.RATX-gen.28955.11907.exe.2d58c00.0.raw.unpack, Messages.cs | .Net Code: NewLateBinding.LateCall(obj, (Type)null, "Invoke", new object[2]{null,new object[5]{Settings.Host,Settings.Port,Settings.SPL,Settings.KEY,Helper.ID()}}, (string[])null, (Type[])null, (bool[])null, true) |
Source: 3.3.SecuriteInfo.com.Win32.RATX-gen.28955.11907.exe.2d58c00.0.raw.unpack, Messages.cs | .Net Code: NewLateBinding.LateCall(obj, (Type)null, "Invoke", new object[2]{null,new object[2]{Pack[2],Helper.Decompress(Convert.FromBase64String(Pack[3]))}}, (string[])null, (Type[])null, (bool[])null, true) |
Source: 3.3.SecuriteInfo.com.Win32.RATX-gen.28955.11907.exe.2d63e80.1.raw.unpack, Messages.cs | .Net Code: NewLateBinding.LateCall(obj, (Type)null, "Invoke", new object[2]{null,new object[5]{Settings.Host,Settings.Port,Settings.SPL,Settings.KEY,Helper.ID()}}, (string[])null, (Type[])null, (bool[])null, true) |
Source: 3.3.SecuriteInfo.com.Win32.RATX-gen.28955.11907.exe.2d63e80.1.raw.unpack, Messages.cs | .Net Code: NewLateBinding.LateCall(obj, (Type)null, "Invoke", new object[2]{null,new object[2]{Pack[2],Helper.Decompress(Convert.FromBase64String(Pack[3]))}}, (string[])null, (Type[])null, (bool[])null, true) |
Source: 6.3.SecuriteInfo.com.Win32.RATX-gen.28955.11907.exe.368e3a0.0.raw.unpack, Messages.cs | .Net Code: NewLateBinding.LateCall(obj, (Type)null, "Invoke", new object[2]{null,new object[5]{Settings.Host,Settings.Port,Settings.SPL,Settings.KEY,Helper.ID()}}, (string[])null, (Type[])null, (bool[])null, true) |
Source: 6.3.SecuriteInfo.com.Win32.RATX-gen.28955.11907.exe.368e3a0.0.raw.unpack, Messages.cs | .Net Code: NewLateBinding.LateCall(obj, (Type)null, "Invoke", new object[2]{null,new object[2]{Pack[2],Helper.Decompress(Convert.FromBase64String(Pack[3]))}}, (string[])null, (Type[])null, (bool[])null, true) |
Source: 6.3.SecuriteInfo.com.Win32.RATX-gen.28955.11907.exe.3683120.1.raw.unpack, Messages.cs | .Net Code: NewLateBinding.LateCall(obj, (Type)null, "Invoke", new object[2]{null,new object[5]{Settings.Host,Settings.Port,Settings.SPL,Settings.KEY,Helper.ID()}}, (string[])null, (Type[])null, (bool[])null, true) |
Source: 6.3.SecuriteInfo.com.Win32.RATX-gen.28955.11907.exe.3683120.1.raw.unpack, Messages.cs | .Net Code: NewLateBinding.LateCall(obj, (Type)null, "Invoke", new object[2]{null,new object[2]{Pack[2],Helper.Decompress(Convert.FromBase64String(Pack[3]))}}, (string[])null, (Type[])null, (bool[])null, true) |
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.RATX-gen.28955.11907.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.RATX-gen.28955.11907.exe | Code function: EnumSystemLocalesW, | 0_2_0056604B |
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.RATX-gen.28955.11907.exe | Code function: EnumSystemLocalesW, | 0_2_00566096 |
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.RATX-gen.28955.11907.exe | Code function: EnumSystemLocalesW, | 0_2_00566131 |
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.RATX-gen.28955.11907.exe | Code function: GetLocaleInfoW,GetLocaleInfoW,GetLocaleInfoW, | 0_2_005661BC |
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.RATX-gen.28955.11907.exe | Code function: GetLocaleInfoW, | 0_2_00566410 |
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.RATX-gen.28955.11907.exe | Code function: GetLocaleInfoW,GetLocaleInfoW,GetACP, | 0_2_00566535 |
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.RATX-gen.28955.11907.exe | Code function: GetLocaleInfoW, | 0_2_0056663B |
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.RATX-gen.28955.11907.exe | Code function: GetUserDefaultLCID,IsValidCodePage,IsValidLocale,GetLocaleInfoW,GetLocaleInfoW, | 0_2_00566717 |
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.RATX-gen.28955.11907.exe | Code function: EnumSystemLocalesW, | 0_2_0055A874 |
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.RATX-gen.28955.11907.exe | Code function: GetLocaleInfoW, | 0_2_0055ACCF |
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.RATX-gen.28955.11907.exe | Code function: GetACP,IsValidCodePage,GetLocaleInfoW, | 0_2_00565D99 |
Source: C:\Users\user\AppData\Roaming\SecuriteInfo.com.Win32.RATX-gen.28955.11907.exe | Code function: EnumSystemLocalesW, | 1_2_00DC6096 |
Source: C:\Users\user\AppData\Roaming\SecuriteInfo.com.Win32.RATX-gen.28955.11907.exe | Code function: EnumSystemLocalesW, | 1_2_00DC604B |
Source: C:\Users\user\AppData\Roaming\SecuriteInfo.com.Win32.RATX-gen.28955.11907.exe | Code function: GetLocaleInfoW,GetLocaleInfoW,GetLocaleInfoW, | 1_2_00DC61BC |
Source: C:\Users\user\AppData\Roaming\SecuriteInfo.com.Win32.RATX-gen.28955.11907.exe | Code function: EnumSystemLocalesW, | 1_2_00DC6131 |
Source: C:\Users\user\AppData\Roaming\SecuriteInfo.com.Win32.RATX-gen.28955.11907.exe | Code function: GetLocaleInfoW, | 1_2_00DC6410 |
Source: C:\Users\user\AppData\Roaming\SecuriteInfo.com.Win32.RATX-gen.28955.11907.exe | Code function: GetLocaleInfoW,GetLocaleInfoW,GetACP, | 1_2_00DC6535 |
Source: C:\Users\user\AppData\Roaming\SecuriteInfo.com.Win32.RATX-gen.28955.11907.exe | Code function: GetLocaleInfoW, | 1_2_00DC663B |
Source: C:\Users\user\AppData\Roaming\SecuriteInfo.com.Win32.RATX-gen.28955.11907.exe | Code function: GetUserDefaultLCID,IsValidCodePage,IsValidLocale,GetLocaleInfoW,GetLocaleInfoW, | 1_2_00DC6717 |
Source: C:\Users\user\AppData\Roaming\SecuriteInfo.com.Win32.RATX-gen.28955.11907.exe | Code function: EnumSystemLocalesW, | 1_2_00DBA874 |
Source: C:\Users\user\AppData\Roaming\SecuriteInfo.com.Win32.RATX-gen.28955.11907.exe | Code function: GetLocaleInfoW, | 1_2_00DBACCF |
Source: C:\Users\user\AppData\Roaming\SecuriteInfo.com.Win32.RATX-gen.28955.11907.exe | Code function: GetACP,IsValidCodePage,GetLocaleInfoW, | 1_2_00DC5D99 |
Source: Yara match | File source: 6.3.SecuriteInfo.com.Win32.RATX-gen.28955.11907.exe.368e3a0.0.unpack, type: UNPACKEDPE |
Source: Yara match | File source: 6.3.SecuriteInfo.com.Win32.RATX-gen.28955.11907.exe.3683120.1.unpack, type: UNPACKEDPE |
Source: Yara match | File source: 3.3.SecuriteInfo.com.Win32.RATX-gen.28955.11907.exe.2d63e80.1.unpack, type: UNPACKEDPE |
Source: Yara match | File source: 6.3.SecuriteInfo.com.Win32.RATX-gen.28955.11907.exe.368e3a0.0.raw.unpack, type: UNPACKEDPE |
Source: Yara match | File source: 2.2.RegSvcs.exe.400000.0.unpack, type: UNPACKEDPE |
Source: Yara match | File source: 6.3.SecuriteInfo.com.Win32.RATX-gen.28955.11907.exe.3683120.1.raw.unpack, type: UNPACKEDPE |
Source: Yara match | File source: 3.3.SecuriteInfo.com.Win32.RATX-gen.28955.11907.exe.2d63e80.1.raw.unpack, type: UNPACKEDPE |
Source: Yara match | File source: 3.3.SecuriteInfo.com.Win32.RATX-gen.28955.11907.exe.2d58c00.0.unpack, type: UNPACKEDPE |
Source: Yara match | File source: 3.3.SecuriteInfo.com.Win32.RATX-gen.28955.11907.exe.2d58c00.0.raw.unpack, type: UNPACKEDPE |
Source: Yara match | File source: 1.2.SecuriteInfo.com.Win32.RATX-gen.28955.11907.exe.28518a0.3.raw.unpack, type: UNPACKEDPE |
Source: Yara match | File source: 00000006.00000003.1114583957.000000000367C000.00000004.00000020.00020000.00000000.sdmp, type: MEMORY |
Source: Yara match | File source: 00000006.00000003.1114583957.000000000368E000.00000004.00000020.00020000.00000000.sdmp, type: MEMORY |
Source: Yara match | File source: 00000001.00000002.3350712838.000000000284E000.00000004.00000020.00020000.00000000.sdmp, type: MEMORY |
Source: Yara match | File source: 00000002.00000002.3348856700.0000000000402000.00000040.00000400.00020000.00000000.sdmp, type: MEMORY |
Source: Yara match | File source: 00000003.00000003.1038950135.0000000002D46000.00000004.00000020.00020000.00000000.sdmp, type: MEMORY |
Source: Yara match | File source: Process Memory Space: SecuriteInfo.com.Win32.RATX-gen.28955.11907.exe PID: 6324, type: MEMORYSTR |
Source: Yara match | File source: Process Memory Space: RegSvcs.exe PID: 6568, type: MEMORYSTR |
Source: Yara match | File source: Process Memory Space: SecuriteInfo.com.Win32.RATX-gen.28955.11907.exe PID: 6920, type: MEMORYSTR |
Source: Yara match | File source: Process Memory Space: SecuriteInfo.com.Win32.RATX-gen.28955.11907.exe PID: 4404, type: MEMORYSTR |
Source: Yara match | File source: 6.3.SecuriteInfo.com.Win32.RATX-gen.28955.11907.exe.368e3a0.0.unpack, type: UNPACKEDPE |
Source: Yara match | File source: 6.3.SecuriteInfo.com.Win32.RATX-gen.28955.11907.exe.3683120.1.unpack, type: UNPACKEDPE |
Source: Yara match | File source: 3.3.SecuriteInfo.com.Win32.RATX-gen.28955.11907.exe.2d63e80.1.unpack, type: UNPACKEDPE |
Source: Yara match | File source: 6.3.SecuriteInfo.com.Win32.RATX-gen.28955.11907.exe.368e3a0.0.raw.unpack, type: UNPACKEDPE |
Source: Yara match | File source: 2.2.RegSvcs.exe.400000.0.unpack, type: UNPACKEDPE |
Source: Yara match | File source: 6.3.SecuriteInfo.com.Win32.RATX-gen.28955.11907.exe.3683120.1.raw.unpack, type: UNPACKEDPE |
Source: Yara match | File source: 3.3.SecuriteInfo.com.Win32.RATX-gen.28955.11907.exe.2d63e80.1.raw.unpack, type: UNPACKEDPE |
Source: Yara match | File source: 3.3.SecuriteInfo.com.Win32.RATX-gen.28955.11907.exe.2d58c00.0.unpack, type: UNPACKEDPE |
Source: Yara match | File source: 3.3.SecuriteInfo.com.Win32.RATX-gen.28955.11907.exe.2d58c00.0.raw.unpack, type: UNPACKEDPE |
Source: Yara match | File source: 1.2.SecuriteInfo.com.Win32.RATX-gen.28955.11907.exe.28518a0.3.raw.unpack, type: UNPACKEDPE |
Source: Yara match | File source: 00000006.00000003.1114583957.000000000367C000.00000004.00000020.00020000.00000000.sdmp, type: MEMORY |
Source: Yara match | File source: 00000006.00000003.1114583957.000000000368E000.00000004.00000020.00020000.00000000.sdmp, type: MEMORY |
Source: Yara match | File source: 00000001.00000002.3350712838.000000000284E000.00000004.00000020.00020000.00000000.sdmp, type: MEMORY |
Source: Yara match | File source: 00000002.00000002.3348856700.0000000000402000.00000040.00000400.00020000.00000000.sdmp, type: MEMORY |
Source: Yara match | File source: 00000003.00000003.1038950135.0000000002D46000.00000004.00000020.00020000.00000000.sdmp, type: MEMORY |
Source: Yara match | File source: Process Memory Space: SecuriteInfo.com.Win32.RATX-gen.28955.11907.exe PID: 6324, type: MEMORYSTR |
Source: Yara match | File source: Process Memory Space: RegSvcs.exe PID: 6568, type: MEMORYSTR |
Source: Yara match | File source: Process Memory Space: SecuriteInfo.com.Win32.RATX-gen.28955.11907.exe PID: 6920, type: MEMORYSTR |
Source: Yara match | File source: Process Memory Space: SecuriteInfo.com.Win32.RATX-gen.28955.11907.exe PID: 4404, type: MEMORYSTR |