Loading Joe Sandbox Report ...

Edit tour

Windows Analysis Report
SecuriteInfo.com.Win32.PWSX-gen.11507.25552.exe

Overview

General Information

Sample name:SecuriteInfo.com.Win32.PWSX-gen.11507.25552.exe
Analysis ID:1640953
MD5:e5481d0bd29388b2025a9db3167b66ce
SHA1:78dc24a45304b5eec3c904e4248bd56765968d96
SHA256:b90b6f766b3e75cbd0cb02ac6f732e81071d3d2409b101d7986878458de2f9c5
Tags:exeuser-SecuriteInfoCom
Infos:

Detection

Snake Keylogger
Score:100
Range:0 - 100
Confidence:100%

Signatures

Antivirus / Scanner detection for submitted sample
Found malware configuration
Malicious sample detected (through community Yara rule)
Multi AV Scanner detection for submitted file
Yara detected AntiVM3
Yara detected Snake Keylogger
.NET source code contains potential unpacker
.NET source code contains very large array initializations
Injects a PE file into a foreign processes
Joe Sandbox ML detected suspicious sample
Sample uses string decryption to hide its real strings
Tries to detect the country of the analysis system (by using the IP)
Tries to harvest and steal browser information (history, passwords, etc)
Tries to steal Mail credentials (via file / registry access)
Abnormal high CPU Usage
Allocates memory with a write watch (potentially for evading sandboxes)
Contains functionality to access loader functionality (e.g. LdrGetProcedureAddress)
Contains long sleeps (>= 3 min)
Creates a process in suspended mode (likely to inject code)
Detected non-DNS traffic on DNS port
Detected potential crypto function
Enables debug privileges
Found a high number of Window / User specific system calls (may be a loop to detect user behavior)
Found inlined nop instructions (likely shell or obfuscated code)
HTTP GET or POST without a user agent
IP address seen in connection with other malware
JA3 SSL client fingerprint seen in connection with other malware
May check the online IP address of the machine
May sleep (evasive loops) to hinder dynamic analysis
Queries the volume information (name, serial number etc) of a device
Sample file is different than original file name gathered from version info
Suricata IDS alerts with low severity for network traffic
Uses 32bit PE files
Uses a known web browser user agent for HTTP communication
Uses code obfuscation techniques (call, push, ret)
Uses insecure TLS / SSL version for HTTPS connection
Yara detected Credential Stealer
Yara signature match

Classification

  • System is w10x64
  • cleanup
NameDescriptionAttributionBlogpost URLsLink
404 Keylogger, Snake KeyloggerSnake Keylogger (aka 404 Keylogger) is a subscription-based keylogger that has many capabilities. The infostealer can steal a victims sensitive information, log keyboard strokes, take screenshots and extract information from the system clipboard. It was initially released on a Russian hacking forum in August 2019. It is notable for its relatively unusual methods of data exfiltration, including via email, FTP, SMTP, Pastebin or the messaging app Telegram.No Attributionhttps://malpedia.caad.fkie.fraunhofer.de/details/win.404keylogger
{"Exfil Mode": "Telegram", "Telegram URL": "https://api.telegram.org/bot7265039693:AAEgBQWh2zD6Y0qjiHnF71BlD3yWIMzprMM/sendMessage?chat_id=7886581547", "Token": "7265039693:AAEgBQWh2zD6Y0qjiHnF71BlD3yWIMzprMM", "Chat_id": "7886581547", "Version": "5.1"}
SourceRuleDescriptionAuthorStrings
00000002.00000002.3645837674.0000000000402000.00000040.00000400.00020000.00000000.sdmpJoeSecurity_CredentialStealerYara detected Credential StealerJoe Security
    00000002.00000002.3645837674.0000000000402000.00000040.00000400.00020000.00000000.sdmpJoeSecurity_SnakeKeyloggerYara detected Snake KeyloggerJoe Security
      00000002.00000002.3645837674.0000000000402000.00000040.00000400.00020000.00000000.sdmpWindows_Trojan_SnakeKeylogger_af3faa65unknownunknown
      • 0x148bb:$a1: get_encryptedPassword
      • 0x14ba7:$a2: get_encryptedUsername
      • 0x146c7:$a3: get_timePasswordChanged
      • 0x147c2:$a4: get_passwordField
      • 0x148d1:$a5: set_encryptedPassword
      • 0x15f72:$a7: get_logins
      • 0x15ed5:$a10: KeyLoggerEventArgs
      • 0x15b40:$a11: KeyLoggerEventArgsEventHandler
      00000002.00000002.3645837674.0000000000402000.00000040.00000400.00020000.00000000.sdmpMALWARE_Win_SnakeKeyloggerDetects Snake KeyloggerditekSHen
      • 0x198c0:$x1: $%SMTPDV$
      • 0x182a4:$x2: $#TheHashHere%&
      • 0x19868:$x3: %FTPDV$
      • 0x18244:$x4: $%TelegramDv$
      • 0x15b40:$x5: KeyLoggerEventArgs
      • 0x15ed5:$x5: KeyLoggerEventArgs
      • 0x1988c:$m2: Clipboard Logs ID
      • 0x19aca:$m2: Screenshot Logs ID
      • 0x19bda:$m2: keystroke Logs ID
      • 0x19eb4:$m3: SnakePW
      • 0x19aa2:$m4: \SnakeKeylogger\
      00000002.00000002.3647546568.00000000032EB000.00000004.00000800.00020000.00000000.sdmpJoeSecurity_SnakeKeyloggerYara detected Snake KeyloggerJoe Security
        Click to see the 14 entries
        SourceRuleDescriptionAuthorStrings
        0.2.SecuriteInfo.com.Win32.PWSX-gen.11507.25552.exe.429a390.0.unpackJoeSecurity_CredentialStealerYara detected Credential StealerJoe Security
          0.2.SecuriteInfo.com.Win32.PWSX-gen.11507.25552.exe.429a390.0.unpackJoeSecurity_SnakeKeyloggerYara detected Snake KeyloggerJoe Security
            0.2.SecuriteInfo.com.Win32.PWSX-gen.11507.25552.exe.429a390.0.unpackWindows_Trojan_SnakeKeylogger_af3faa65unknownunknown
            • 0x12cbb:$a1: get_encryptedPassword
            • 0x12fa7:$a2: get_encryptedUsername
            • 0x12ac7:$a3: get_timePasswordChanged
            • 0x12bc2:$a4: get_passwordField
            • 0x12cd1:$a5: set_encryptedPassword
            • 0x14372:$a7: get_logins
            • 0x142d5:$a10: KeyLoggerEventArgs
            • 0x13f40:$a11: KeyLoggerEventArgsEventHandler
            0.2.SecuriteInfo.com.Win32.PWSX-gen.11507.25552.exe.429a390.0.unpackMAL_Envrial_Jan18_1Detects Encrial credential stealer malwareFlorian Roth
            • 0x1a676:$a2: \Comodo\Dragon\User Data\Default\Login Data
            • 0x198a8:$a3: \Google\Chrome\User Data\Default\Login Data
            • 0x19cdb:$a4: \Orbitum\User Data\Default\Login Data
            • 0x1ad1a:$a5: \Kometa\User Data\Default\Login Data
            0.2.SecuriteInfo.com.Win32.PWSX-gen.11507.25552.exe.429a390.0.unpackINDICATOR_SUSPICIOUS_EXE_DotNetProcHookDetects executables with potential process hoockingditekSHen
            • 0x138c6:$s1: UnHook
            • 0x138cd:$s2: SetHook
            • 0x138d5:$s3: CallNextHook
            • 0x138e2:$s4: _hook
            Click to see the 23 entries
            No Sigma rule has matched
            TimestampSIDSeverityClasstypeSource IPSource PortDestination IPDestination PortProtocol
            2025-03-17T22:28:15.657659+010028033053Unknown Traffic192.168.2.449716104.21.64.1443TCP
            2025-03-17T22:28:20.895629+010028033053Unknown Traffic192.168.2.449727104.21.64.1443TCP
            2025-03-17T22:28:23.454853+010028033053Unknown Traffic192.168.2.449731104.21.64.1443TCP
            TimestampSIDSeverityClasstypeSource IPSource PortDestination IPDestination PortProtocol
            2025-03-17T22:28:14.110805+010028032742Potentially Bad Traffic192.168.2.449714132.226.247.7380TCP
            2025-03-17T22:28:15.056814+010028032742Potentially Bad Traffic192.168.2.449714132.226.247.7380TCP
            2025-03-17T22:28:16.447425+010028032742Potentially Bad Traffic192.168.2.449718132.226.247.7380TCP

            Click to jump to signature section

            Show All Signature Results

            AV Detection

            barindex
            Source: SecuriteInfo.com.Win32.PWSX-gen.11507.25552.exeAvira: detected
            Source: 00000002.00000002.3647546568.0000000003121000.00000004.00000800.00020000.00000000.sdmpMalware Configuration Extractor: Snake Keylogger {"Exfil Mode": "Telegram", "Telegram URL": "https://api.telegram.org/bot7265039693:AAEgBQWh2zD6Y0qjiHnF71BlD3yWIMzprMM/sendMessage?chat_id=7886581547", "Token": "7265039693:AAEgBQWh2zD6Y0qjiHnF71BlD3yWIMzprMM", "Chat_id": "7886581547", "Version": "5.1"}
            Source: SecuriteInfo.com.Win32.PWSX-gen.11507.25552.exeReversingLabs: Detection: 33%
            Source: SecuriteInfo.com.Win32.PWSX-gen.11507.25552.exeVirustotal: Detection: 32%Perma Link
            Source: Submited SampleIntegrated Neural Analysis Model: Matched 100.0% probability
            Source: 0.2.SecuriteInfo.com.Win32.PWSX-gen.11507.25552.exe.429a390.0.raw.unpackString decryptor:
            Source: 0.2.SecuriteInfo.com.Win32.PWSX-gen.11507.25552.exe.429a390.0.raw.unpackString decryptor: 7265039693:AAEgBQWh2zD6Y0qjiHnF71BlD3yWIMzprMM
            Source: 0.2.SecuriteInfo.com.Win32.PWSX-gen.11507.25552.exe.429a390.0.raw.unpackString decryptor: 7886581547
            Source: 0.2.SecuriteInfo.com.Win32.PWSX-gen.11507.25552.exe.429a390.0.raw.unpackString decryptor:
            Source: 0.2.SecuriteInfo.com.Win32.PWSX-gen.11507.25552.exe.429a390.0.raw.unpackString decryptor: 7265039693:AAEgBQWh2zD6Y0qjiHnF71BlD3yWIMzprMM
            Source: 0.2.SecuriteInfo.com.Win32.PWSX-gen.11507.25552.exe.429a390.0.raw.unpackString decryptor: 7886581547

            Location Tracking

            barindex
            Source: unknownDNS query: name: reallyfreegeoip.org
            Source: SecuriteInfo.com.Win32.PWSX-gen.11507.25552.exeStatic PE information: EXECUTABLE_IMAGE, 32BIT_MACHINE
            Source: unknownHTTPS traffic detected: 104.21.64.1:443 -> 192.168.2.4:49715 version: TLS 1.0
            Source: SecuriteInfo.com.Win32.PWSX-gen.11507.25552.exeStatic PE information: DYNAMIC_BASE, NX_COMPAT, NO_SEH, TERMINAL_SERVER_AWARE
            Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.PWSX-gen.11507.25552.exeCode function: 4x nop then jmp 02F4F1F6h2_2_02F4F007
            Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.PWSX-gen.11507.25552.exeCode function: 4x nop then jmp 02F4FB80h2_2_02F4F007
            Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.PWSX-gen.11507.25552.exeCode function: 4x nop then mov dword ptr [ebp-14h], 00000000h2_2_02F4E528
            Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.PWSX-gen.11507.25552.exeCode function: 4x nop then jmp 05B31471h2_2_05B311C0
            Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.PWSX-gen.11507.25552.exeCode function: 4x nop then jmp 05B3D471h2_2_05B3D1C8
            Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.PWSX-gen.11507.25552.exeCode function: 4x nop then jmp 05B3CBC1h2_2_05B3C918
            Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.PWSX-gen.11507.25552.exeCode function: 4x nop then jmp 05B30BB1h2_2_05B30900
            Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.PWSX-gen.11507.25552.exeCode function: 4x nop then jmp 05B3D019h2_2_05B3CD70
            Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.PWSX-gen.11507.25552.exeCode function: 4x nop then jmp 05B31011h2_2_05B30D60
            Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.PWSX-gen.11507.25552.exeCode function: 4x nop then jmp 05B31A38h2_2_05B31966
            Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.PWSX-gen.11507.25552.exeCode function: 4x nop then jmp 05B30751h2_2_05B304A0
            Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.PWSX-gen.11507.25552.exeCode function: 4x nop then jmp 05B3F731h2_2_05B3F488
            Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.PWSX-gen.11507.25552.exeCode function: 4x nop then jmp 05B3FB89h2_2_05B3F8E0
            Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.PWSX-gen.11507.25552.exeCode function: 4x nop then jmp 05B3C769h2_2_05B3C4C0
            Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.PWSX-gen.11507.25552.exeCode function: 4x nop then jmp 05B3F2D9h2_2_05B3F030
            Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.PWSX-gen.11507.25552.exeCode function: 4x nop then jmp 05B3BEB9h2_2_05B3BC10
            Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.PWSX-gen.11507.25552.exeCode function: 4x nop then jmp 05B3C311h2_2_05B3C068
            Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.PWSX-gen.11507.25552.exeCode function: 4x nop then jmp 05B302F1h2_2_05B30040
            Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.PWSX-gen.11507.25552.exeCode function: 4x nop then jmp 05B3BA61h2_2_05B3B7B8
            Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.PWSX-gen.11507.25552.exeCode function: 4x nop then jmp 05B3EA29h2_2_05B3E780
            Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.PWSX-gen.11507.25552.exeCode function: 4x nop then jmp 05B3EE81h2_2_05B3EBD8
            Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.PWSX-gen.11507.25552.exeCode function: 4x nop then jmp 05B3E5D1h2_2_05B3E328
            Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.PWSX-gen.11507.25552.exeCode function: 4x nop then jmp 05B3B609h2_2_05B3B360
            Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.PWSX-gen.11507.25552.exeCode function: 4x nop then jmp 05B3E179h2_2_05B3DED0
            Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.PWSX-gen.11507.25552.exeCode function: 4x nop then jmp 05B31A38h2_2_05B31620
            Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.PWSX-gen.11507.25552.exeCode function: 4x nop then jmp 05B3D8C9h2_2_05B3D620
            Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.PWSX-gen.11507.25552.exeCode function: 4x nop then jmp 05B31A38h2_2_05B31610
            Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.PWSX-gen.11507.25552.exeCode function: 4x nop then jmp 05B3DD21h2_2_05B3DA78
            Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.PWSX-gen.11507.25552.exeCode function: 4x nop then jmp 06D98D4Dh2_2_06D98A10
            Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.PWSX-gen.11507.25552.exeCode function: 4x nop then jmp 06D969D1h2_2_06D96728
            Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.PWSX-gen.11507.25552.exeCode function: 4x nop then jmp 06D96579h2_2_06D962D0
            Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.PWSX-gen.11507.25552.exeCode function: 4x nop then jmp 06D96121h2_2_06D95E78
            Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.PWSX-gen.11507.25552.exeCode function: 4x nop then jmp 06D95CC9h2_2_06D95A20
            Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.PWSX-gen.11507.25552.exeCode function: 4x nop then jmp 06D97281h2_2_06D96FD8
            Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.PWSX-gen.11507.25552.exeCode function: 4x nop then lea esp, dword ptr [ebp-04h]2_2_06D937C0
            Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.PWSX-gen.11507.25552.exeCode function: 4x nop then jmp 06D96E29h2_2_06D96B80
            Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.PWSX-gen.11507.25552.exeCode function: 4x nop then lea esp, dword ptr [ebp-04h]2_2_06D937B0
            Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.PWSX-gen.11507.25552.exeCode function: 4x nop then jmp 06D90B99h2_2_06D908F0
            Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.PWSX-gen.11507.25552.exeCode function: 4x nop then jmp 06D90741h2_2_06D90498
            Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.PWSX-gen.11507.25552.exeCode function: 4x nop then jmp 06D97B59h2_2_06D978B0
            Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.PWSX-gen.11507.25552.exeCode function: 4x nop then jmp 06D97702h2_2_06D97458
            Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.PWSX-gen.11507.25552.exeCode function: 4x nop then jmp 06D902E9h2_2_06D90040
            Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.PWSX-gen.11507.25552.exeCode function: 4x nop then jmp 06D98861h2_2_06D985B8
            Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.PWSX-gen.11507.25552.exeCode function: 4x nop then jmp 06D95849h2_2_06D955A0
            Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.PWSX-gen.11507.25552.exeCode function: 4x nop then jmp 06D90FF1h2_2_06D90D48
            Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.PWSX-gen.11507.25552.exeCode function: 4x nop then jmp 06D98409h2_2_06D98160
            Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.PWSX-gen.11507.25552.exeCode function: 4x nop then jmp 06D97FB1h2_2_06D97D08
            Source: global trafficTCP traffic: 192.168.2.4:56797 -> 162.159.36.2:53
            Source: global trafficHTTP traffic detected: GET /xml/8.46.123.189 HTTP/1.1Host: reallyfreegeoip.orgConnection: Keep-Alive
            Source: global trafficHTTP traffic detected: GET /xml/8.46.123.189 HTTP/1.1Host: reallyfreegeoip.org
            Source: global trafficHTTP traffic detected: GET /xml/8.46.123.189 HTTP/1.1Host: reallyfreegeoip.orgConnection: Keep-Alive
            Source: global trafficHTTP traffic detected: GET /xml/8.46.123.189 HTTP/1.1Host: reallyfreegeoip.orgConnection: Keep-Alive
            Source: global trafficHTTP traffic detected: GET /xml/8.46.123.189 HTTP/1.1Host: reallyfreegeoip.orgConnection: Keep-Alive
            Source: global trafficHTTP traffic detected: GET /xml/8.46.123.189 HTTP/1.1Host: reallyfreegeoip.org
            Source: global trafficHTTP traffic detected: GET /xml/8.46.123.189 HTTP/1.1Host: reallyfreegeoip.orgConnection: Keep-Alive
            Source: global trafficHTTP traffic detected: GET /xml/8.46.123.189 HTTP/1.1Host: reallyfreegeoip.org
            Source: Joe Sandbox ViewIP Address: 104.21.64.1 104.21.64.1
            Source: Joe Sandbox ViewIP Address: 104.21.64.1 104.21.64.1
            Source: Joe Sandbox ViewIP Address: 132.226.247.73 132.226.247.73
            Source: Joe Sandbox ViewJA3 fingerprint: 54328bd36c14bd82ddaa0c04b25ed9ad
            Source: unknownDNS query: name: checkip.dyndns.org
            Source: unknownDNS query: name: reallyfreegeoip.org
            Source: Network trafficSuricata IDS: 2803274 - Severity 2 - ETPRO MALWARE Common Downloader Header Pattern UH : 192.168.2.4:49718 -> 132.226.247.73:80
            Source: Network trafficSuricata IDS: 2803274 - Severity 2 - ETPRO MALWARE Common Downloader Header Pattern UH : 192.168.2.4:49714 -> 132.226.247.73:80
            Source: Network trafficSuricata IDS: 2803305 - Severity 3 - ETPRO MALWARE Common Downloader Header Pattern H : 192.168.2.4:49727 -> 104.21.64.1:443
            Source: Network trafficSuricata IDS: 2803305 - Severity 3 - ETPRO MALWARE Common Downloader Header Pattern H : 192.168.2.4:49716 -> 104.21.64.1:443
            Source: Network trafficSuricata IDS: 2803305 - Severity 3 - ETPRO MALWARE Common Downloader Header Pattern H : 192.168.2.4:49731 -> 104.21.64.1:443
            Source: global trafficHTTP traffic detected: GET / HTTP/1.1User-Agent: Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.2; .NET CLR1.0.3705;)Host: checkip.dyndns.orgConnection: Keep-Alive
            Source: global trafficHTTP traffic detected: GET / HTTP/1.1User-Agent: Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.2; .NET CLR1.0.3705;)Host: checkip.dyndns.org
            Source: global trafficHTTP traffic detected: GET / HTTP/1.1User-Agent: Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.2; .NET CLR1.0.3705;)Host: checkip.dyndns.org
            Source: global trafficHTTP traffic detected: GET / HTTP/1.1User-Agent: Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.2; .NET CLR1.0.3705;)Host: checkip.dyndns.org
            Source: global trafficHTTP traffic detected: GET / HTTP/1.1User-Agent: Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.2; .NET CLR1.0.3705;)Host: checkip.dyndns.orgConnection: Keep-Alive
            Source: global trafficHTTP traffic detected: GET / HTTP/1.1User-Agent: Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.2; .NET CLR1.0.3705;)Host: checkip.dyndns.orgConnection: Keep-Alive
            Source: global trafficHTTP traffic detected: GET / HTTP/1.1User-Agent: Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.2; .NET CLR1.0.3705;)Host: checkip.dyndns.orgConnection: Keep-Alive
            Source: global trafficHTTP traffic detected: GET / HTTP/1.1User-Agent: Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.2; .NET CLR1.0.3705;)Host: checkip.dyndns.orgConnection: Keep-Alive
            Source: global trafficHTTP traffic detected: GET / HTTP/1.1User-Agent: Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.2; .NET CLR1.0.3705;)Host: checkip.dyndns.orgConnection: Keep-Alive
            Source: unknownHTTPS traffic detected: 104.21.64.1:443 -> 192.168.2.4:49715 version: TLS 1.0
            Source: unknownTCP traffic detected without corresponding DNS query: 162.159.36.2
            Source: unknownTCP traffic detected without corresponding DNS query: 162.159.36.2
            Source: unknownTCP traffic detected without corresponding DNS query: 162.159.36.2
            Source: unknownTCP traffic detected without corresponding DNS query: 162.159.36.2
            Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
            Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
            Source: global trafficHTTP traffic detected: GET /xml/8.46.123.189 HTTP/1.1Host: reallyfreegeoip.orgConnection: Keep-Alive
            Source: global trafficHTTP traffic detected: GET /xml/8.46.123.189 HTTP/1.1Host: reallyfreegeoip.org
            Source: global trafficHTTP traffic detected: GET /xml/8.46.123.189 HTTP/1.1Host: reallyfreegeoip.orgConnection: Keep-Alive
            Source: global trafficHTTP traffic detected: GET /xml/8.46.123.189 HTTP/1.1Host: reallyfreegeoip.orgConnection: Keep-Alive
            Source: global trafficHTTP traffic detected: GET /xml/8.46.123.189 HTTP/1.1Host: reallyfreegeoip.orgConnection: Keep-Alive
            Source: global trafficHTTP traffic detected: GET /xml/8.46.123.189 HTTP/1.1Host: reallyfreegeoip.org
            Source: global trafficHTTP traffic detected: GET /xml/8.46.123.189 HTTP/1.1Host: reallyfreegeoip.orgConnection: Keep-Alive
            Source: global trafficHTTP traffic detected: GET /xml/8.46.123.189 HTTP/1.1Host: reallyfreegeoip.org
            Source: global trafficHTTP traffic detected: GET / HTTP/1.1User-Agent: Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.2; .NET CLR1.0.3705;)Host: checkip.dyndns.orgConnection: Keep-Alive
            Source: global trafficHTTP traffic detected: GET / HTTP/1.1User-Agent: Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.2; .NET CLR1.0.3705;)Host: checkip.dyndns.org
            Source: global trafficHTTP traffic detected: GET / HTTP/1.1User-Agent: Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.2; .NET CLR1.0.3705;)Host: checkip.dyndns.org
            Source: global trafficHTTP traffic detected: GET / HTTP/1.1User-Agent: Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.2; .NET CLR1.0.3705;)Host: checkip.dyndns.org
            Source: global trafficHTTP traffic detected: GET / HTTP/1.1User-Agent: Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.2; .NET CLR1.0.3705;)Host: checkip.dyndns.orgConnection: Keep-Alive
            Source: global trafficHTTP traffic detected: GET / HTTP/1.1User-Agent: Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.2; .NET CLR1.0.3705;)Host: checkip.dyndns.orgConnection: Keep-Alive
            Source: global trafficHTTP traffic detected: GET / HTTP/1.1User-Agent: Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.2; .NET CLR1.0.3705;)Host: checkip.dyndns.orgConnection: Keep-Alive
            Source: global trafficHTTP traffic detected: GET / HTTP/1.1User-Agent: Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.2; .NET CLR1.0.3705;)Host: checkip.dyndns.orgConnection: Keep-Alive
            Source: global trafficHTTP traffic detected: GET / HTTP/1.1User-Agent: Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.2; .NET CLR1.0.3705;)Host: checkip.dyndns.orgConnection: Keep-Alive
            Source: global trafficDNS traffic detected: DNS query: checkip.dyndns.org
            Source: global trafficDNS traffic detected: DNS query: reallyfreegeoip.org
            Source: SecuriteInfo.com.Win32.PWSX-gen.11507.25552.exe, 00000002.00000002.3647546568.0000000003278000.00000004.00000800.00020000.00000000.sdmp, SecuriteInfo.com.Win32.PWSX-gen.11507.25552.exe, 00000002.00000002.3647546568.00000000032A1000.00000004.00000800.00020000.00000000.sdmp, SecuriteInfo.com.Win32.PWSX-gen.11507.25552.exe, 00000002.00000002.3647546568.00000000031E5000.00000004.00000800.00020000.00000000.sdmp, SecuriteInfo.com.Win32.PWSX-gen.11507.25552.exe, 00000002.00000002.3647546568.00000000032CF000.00000004.00000800.00020000.00000000.sdmp, SecuriteInfo.com.Win32.PWSX-gen.11507.25552.exe, 00000002.00000002.3647546568.0000000003286000.00000004.00000800.00020000.00000000.sdmp, SecuriteInfo.com.Win32.PWSX-gen.11507.25552.exe, 00000002.00000002.3647546568.00000000032DD000.00000004.00000800.00020000.00000000.sdmpString found in binary or memory: http://checkip.dyndns.com
            Source: SecuriteInfo.com.Win32.PWSX-gen.11507.25552.exe, 00000002.00000002.3647546568.0000000003228000.00000004.00000800.00020000.00000000.sdmp, SecuriteInfo.com.Win32.PWSX-gen.11507.25552.exe, 00000002.00000002.3647546568.00000000032AF000.00000004.00000800.00020000.00000000.sdmp, SecuriteInfo.com.Win32.PWSX-gen.11507.25552.exe, 00000002.00000002.3647546568.0000000003278000.00000004.00000800.00020000.00000000.sdmp, SecuriteInfo.com.Win32.PWSX-gen.11507.25552.exe, 00000002.00000002.3647546568.00000000032A1000.00000004.00000800.00020000.00000000.sdmp, SecuriteInfo.com.Win32.PWSX-gen.11507.25552.exe, 00000002.00000002.3647546568.00000000031E5000.00000004.00000800.00020000.00000000.sdmp, SecuriteInfo.com.Win32.PWSX-gen.11507.25552.exe, 00000002.00000002.3647546568.0000000003121000.00000004.00000800.00020000.00000000.sdmp, SecuriteInfo.com.Win32.PWSX-gen.11507.25552.exe, 00000002.00000002.3647546568.00000000032CF000.00000004.00000800.00020000.00000000.sdmp, SecuriteInfo.com.Win32.PWSX-gen.11507.25552.exe, 00000002.00000002.3647546568.0000000003286000.00000004.00000800.00020000.00000000.sdmp, SecuriteInfo.com.Win32.PWSX-gen.11507.25552.exe, 00000002.00000002.3647546568.00000000032DD000.00000004.00000800.00020000.00000000.sdmpString found in binary or memory: http://checkip.dyndns.org
            Source: SecuriteInfo.com.Win32.PWSX-gen.11507.25552.exe, 00000002.00000002.3647546568.0000000003121000.00000004.00000800.00020000.00000000.sdmpString found in binary or memory: http://checkip.dyndns.org/
            Source: SecuriteInfo.com.Win32.PWSX-gen.11507.25552.exe, 00000000.00000002.1209255105.0000000004278000.00000004.00000800.00020000.00000000.sdmp, SecuriteInfo.com.Win32.PWSX-gen.11507.25552.exe, 00000002.00000002.3645837674.0000000000402000.00000040.00000400.00020000.00000000.sdmpString found in binary or memory: http://checkip.dyndns.org/q
            Source: SecuriteInfo.com.Win32.PWSX-gen.11507.25552.exe, 00000002.00000002.3647546568.0000000003286000.00000004.00000800.00020000.00000000.sdmpString found in binary or memory: http://checkip.dyndns.org8
            Source: SecuriteInfo.com.Win32.PWSX-gen.11507.25552.exe, 00000002.00000002.3647546568.0000000003278000.00000004.00000800.00020000.00000000.sdmp, SecuriteInfo.com.Win32.PWSX-gen.11507.25552.exe, 00000002.00000002.3647546568.00000000032A1000.00000004.00000800.00020000.00000000.sdmp, SecuriteInfo.com.Win32.PWSX-gen.11507.25552.exe, 00000002.00000002.3647546568.00000000032CF000.00000004.00000800.00020000.00000000.sdmp, SecuriteInfo.com.Win32.PWSX-gen.11507.25552.exe, 00000002.00000002.3647546568.00000000031FD000.00000004.00000800.00020000.00000000.sdmp, SecuriteInfo.com.Win32.PWSX-gen.11507.25552.exe, 00000002.00000002.3647546568.0000000003286000.00000004.00000800.00020000.00000000.sdmp, SecuriteInfo.com.Win32.PWSX-gen.11507.25552.exe, 00000002.00000002.3647546568.00000000032DD000.00000004.00000800.00020000.00000000.sdmpString found in binary or memory: http://reallyfreegeoip.org
            Source: SecuriteInfo.com.Win32.PWSX-gen.11507.25552.exe, 00000002.00000002.3647546568.0000000003121000.00000004.00000800.00020000.00000000.sdmpString found in binary or memory: http://schemas.xmlsoap.org/ws/2005/05/identity/claims/name
            Source: SecuriteInfo.com.Win32.PWSX-gen.11507.25552.exe, 00000000.00000002.1210892885.00000000077D2000.00000004.00000800.00020000.00000000.sdmpString found in binary or memory: http://www.apache.org/licenses/LICENSE-2.0
            Source: SecuriteInfo.com.Win32.PWSX-gen.11507.25552.exe, 00000000.00000002.1210892885.00000000077D2000.00000004.00000800.00020000.00000000.sdmpString found in binary or memory: http://www.carterandcone.coml
            Source: SecuriteInfo.com.Win32.PWSX-gen.11507.25552.exe, 00000000.00000002.1210892885.00000000077D2000.00000004.00000800.00020000.00000000.sdmpString found in binary or memory: http://www.fontbureau.com
            Source: SecuriteInfo.com.Win32.PWSX-gen.11507.25552.exe, 00000000.00000002.1210892885.00000000077D2000.00000004.00000800.00020000.00000000.sdmpString found in binary or memory: http://www.fontbureau.com/designers
            Source: SecuriteInfo.com.Win32.PWSX-gen.11507.25552.exe, 00000000.00000002.1210892885.00000000077D2000.00000004.00000800.00020000.00000000.sdmpString found in binary or memory: http://www.fontbureau.com/designers/?
            Source: SecuriteInfo.com.Win32.PWSX-gen.11507.25552.exe, 00000000.00000002.1210892885.00000000077D2000.00000004.00000800.00020000.00000000.sdmpString found in binary or memory: http://www.fontbureau.com/designers/cabarga.htmlN
            Source: SecuriteInfo.com.Win32.PWSX-gen.11507.25552.exe, 00000000.00000002.1210892885.00000000077D2000.00000004.00000800.00020000.00000000.sdmpString found in binary or memory: http://www.fontbureau.com/designers/frere-user.html
            Source: SecuriteInfo.com.Win32.PWSX-gen.11507.25552.exe, 00000000.00000002.1210892885.00000000077D2000.00000004.00000800.00020000.00000000.sdmpString found in binary or memory: http://www.fontbureau.com/designers8
            Source: SecuriteInfo.com.Win32.PWSX-gen.11507.25552.exe, 00000000.00000002.1210892885.00000000077D2000.00000004.00000800.00020000.00000000.sdmpString found in binary or memory: http://www.fontbureau.com/designers?
            Source: SecuriteInfo.com.Win32.PWSX-gen.11507.25552.exe, 00000000.00000002.1210892885.00000000077D2000.00000004.00000800.00020000.00000000.sdmpString found in binary or memory: http://www.fontbureau.com/designersG
            Source: SecuriteInfo.com.Win32.PWSX-gen.11507.25552.exe, 00000000.00000002.1210892885.00000000077D2000.00000004.00000800.00020000.00000000.sdmpString found in binary or memory: http://www.fonts.com
            Source: SecuriteInfo.com.Win32.PWSX-gen.11507.25552.exe, 00000000.00000002.1210892885.00000000077D2000.00000004.00000800.00020000.00000000.sdmpString found in binary or memory: http://www.founder.com.cn/cn
            Source: SecuriteInfo.com.Win32.PWSX-gen.11507.25552.exe, 00000000.00000002.1210892885.00000000077D2000.00000004.00000800.00020000.00000000.sdmpString found in binary or memory: http://www.founder.com.cn/cn/bThe
            Source: SecuriteInfo.com.Win32.PWSX-gen.11507.25552.exe, 00000000.00000002.1210892885.00000000077D2000.00000004.00000800.00020000.00000000.sdmpString found in binary or memory: http://www.founder.com.cn/cn/cThe
            Source: SecuriteInfo.com.Win32.PWSX-gen.11507.25552.exe, 00000000.00000002.1210892885.00000000077D2000.00000004.00000800.00020000.00000000.sdmpString found in binary or memory: http://www.galapagosdesign.com/DPlease
            Source: SecuriteInfo.com.Win32.PWSX-gen.11507.25552.exe, 00000000.00000002.1210892885.00000000077D2000.00000004.00000800.00020000.00000000.sdmpString found in binary or memory: http://www.galapagosdesign.com/staff/dennis.htm
            Source: SecuriteInfo.com.Win32.PWSX-gen.11507.25552.exe, 00000000.00000002.1210892885.00000000077D2000.00000004.00000800.00020000.00000000.sdmpString found in binary or memory: http://www.jiyu-kobo.co.jp/
            Source: SecuriteInfo.com.Win32.PWSX-gen.11507.25552.exe, 00000000.00000002.1210892885.00000000077D2000.00000004.00000800.00020000.00000000.sdmpString found in binary or memory: http://www.sajatypeworks.com
            Source: SecuriteInfo.com.Win32.PWSX-gen.11507.25552.exe, 00000000.00000002.1210892885.00000000077D2000.00000004.00000800.00020000.00000000.sdmpString found in binary or memory: http://www.sakkal.com
            Source: SecuriteInfo.com.Win32.PWSX-gen.11507.25552.exe, 00000000.00000002.1210892885.00000000077D2000.00000004.00000800.00020000.00000000.sdmpString found in binary or memory: http://www.tiro.com
            Source: SecuriteInfo.com.Win32.PWSX-gen.11507.25552.exe, 00000000.00000002.1210892885.00000000077D2000.00000004.00000800.00020000.00000000.sdmpString found in binary or memory: http://www.typography.netD
            Source: SecuriteInfo.com.Win32.PWSX-gen.11507.25552.exe, 00000000.00000002.1210892885.00000000077D2000.00000004.00000800.00020000.00000000.sdmpString found in binary or memory: http://www.urwpp.deDPlease
            Source: SecuriteInfo.com.Win32.PWSX-gen.11507.25552.exe, 00000000.00000002.1210892885.00000000077D2000.00000004.00000800.00020000.00000000.sdmpString found in binary or memory: http://www.zhongyicts.com.cn
            Source: SecuriteInfo.com.Win32.PWSX-gen.11507.25552.exe, 00000002.00000002.3647546568.0000000003228000.00000004.00000800.00020000.00000000.sdmp, SecuriteInfo.com.Win32.PWSX-gen.11507.25552.exe, 00000002.00000002.3647546568.0000000003278000.00000004.00000800.00020000.00000000.sdmp, SecuriteInfo.com.Win32.PWSX-gen.11507.25552.exe, 00000002.00000002.3647546568.00000000032A1000.00000004.00000800.00020000.00000000.sdmp, SecuriteInfo.com.Win32.PWSX-gen.11507.25552.exe, 00000002.00000002.3647546568.00000000031E5000.00000004.00000800.00020000.00000000.sdmp, SecuriteInfo.com.Win32.PWSX-gen.11507.25552.exe, 00000002.00000002.3647546568.00000000032CF000.00000004.00000800.00020000.00000000.sdmp, SecuriteInfo.com.Win32.PWSX-gen.11507.25552.exe, 00000002.00000002.3647546568.0000000003286000.00000004.00000800.00020000.00000000.sdmp, SecuriteInfo.com.Win32.PWSX-gen.11507.25552.exe, 00000002.00000002.3647546568.00000000032DD000.00000004.00000800.00020000.00000000.sdmpString found in binary or memory: https://reallyfreegeoip.org
            Source: SecuriteInfo.com.Win32.PWSX-gen.11507.25552.exe, 00000000.00000002.1209255105.0000000004278000.00000004.00000800.00020000.00000000.sdmp, SecuriteInfo.com.Win32.PWSX-gen.11507.25552.exe, 00000002.00000002.3647546568.00000000031E5000.00000004.00000800.00020000.00000000.sdmp, SecuriteInfo.com.Win32.PWSX-gen.11507.25552.exe, 00000002.00000002.3645837674.0000000000402000.00000040.00000400.00020000.00000000.sdmpString found in binary or memory: https://reallyfreegeoip.org/xml/
            Source: SecuriteInfo.com.Win32.PWSX-gen.11507.25552.exe, 00000002.00000002.3647546568.00000000032DD000.00000004.00000800.00020000.00000000.sdmpString found in binary or memory: https://reallyfreegeoip.org/xml/8.46.123.189
            Source: SecuriteInfo.com.Win32.PWSX-gen.11507.25552.exe, 00000002.00000002.3647546568.0000000003228000.00000004.00000800.00020000.00000000.sdmp, SecuriteInfo.com.Win32.PWSX-gen.11507.25552.exe, 00000002.00000002.3647546568.0000000003278000.00000004.00000800.00020000.00000000.sdmp, SecuriteInfo.com.Win32.PWSX-gen.11507.25552.exe, 00000002.00000002.3647546568.00000000032A1000.00000004.00000800.00020000.00000000.sdmp, SecuriteInfo.com.Win32.PWSX-gen.11507.25552.exe, 00000002.00000002.3647546568.00000000032CF000.00000004.00000800.00020000.00000000.sdmp, SecuriteInfo.com.Win32.PWSX-gen.11507.25552.exe, 00000002.00000002.3647546568.0000000003286000.00000004.00000800.00020000.00000000.sdmp, SecuriteInfo.com.Win32.PWSX-gen.11507.25552.exe, 00000002.00000002.3647546568.00000000032DD000.00000004.00000800.00020000.00000000.sdmpString found in binary or memory: https://reallyfreegeoip.org/xml/8.46.123.189$
            Source: SecuriteInfo.com.Win32.PWSX-gen.11507.25552.exe, 00000002.00000002.3647546568.0000000003278000.00000004.00000800.00020000.00000000.sdmp, SecuriteInfo.com.Win32.PWSX-gen.11507.25552.exe, 00000002.00000002.3647546568.00000000032A1000.00000004.00000800.00020000.00000000.sdmp, SecuriteInfo.com.Win32.PWSX-gen.11507.25552.exe, 00000002.00000002.3647546568.00000000032CF000.00000004.00000800.00020000.00000000.sdmpString found in binary or memory: https://reallyfreegeoip.org/xml/8.46.123.1898
            Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49722
            Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49731
            Source: unknownNetwork traffic detected: HTTP traffic on port 49731 -> 443
            Source: unknownNetwork traffic detected: HTTP traffic on port 49727 -> 443
            Source: unknownNetwork traffic detected: HTTP traffic on port 49725 -> 443
            Source: unknownNetwork traffic detected: HTTP traffic on port 49729 -> 443
            Source: unknownNetwork traffic detected: HTTP traffic on port 49719 -> 443
            Source: unknownNetwork traffic detected: HTTP traffic on port 49722 -> 443
            Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49719
            Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49729
            Source: unknownNetwork traffic detected: HTTP traffic on port 49716 -> 443
            Source: unknownNetwork traffic detected: HTTP traffic on port 49715 -> 443
            Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49716
            Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49727
            Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49715
            Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49725

            System Summary

            barindex
            Source: 0.2.SecuriteInfo.com.Win32.PWSX-gen.11507.25552.exe.429a390.0.unpack, type: UNPACKEDPEMatched rule: Windows_Trojan_SnakeKeylogger_af3faa65 Author: unknown
            Source: 0.2.SecuriteInfo.com.Win32.PWSX-gen.11507.25552.exe.429a390.0.unpack, type: UNPACKEDPEMatched rule: Detects Encrial credential stealer malware Author: Florian Roth
            Source: 0.2.SecuriteInfo.com.Win32.PWSX-gen.11507.25552.exe.429a390.0.unpack, type: UNPACKEDPEMatched rule: Detects executables with potential process hoocking Author: ditekSHen
            Source: 0.2.SecuriteInfo.com.Win32.PWSX-gen.11507.25552.exe.429a390.0.unpack, type: UNPACKEDPEMatched rule: Detects Snake Keylogger Author: ditekSHen
            Source: 0.2.SecuriteInfo.com.Win32.PWSX-gen.11507.25552.exe.4279970.1.unpack, type: UNPACKEDPEMatched rule: Windows_Trojan_SnakeKeylogger_af3faa65 Author: unknown
            Source: 0.2.SecuriteInfo.com.Win32.PWSX-gen.11507.25552.exe.4279970.1.unpack, type: UNPACKEDPEMatched rule: Detects Encrial credential stealer malware Author: Florian Roth
            Source: 0.2.SecuriteInfo.com.Win32.PWSX-gen.11507.25552.exe.4279970.1.unpack, type: UNPACKEDPEMatched rule: Detects executables with potential process hoocking Author: ditekSHen
            Source: 0.2.SecuriteInfo.com.Win32.PWSX-gen.11507.25552.exe.4279970.1.unpack, type: UNPACKEDPEMatched rule: Detects Snake Keylogger Author: ditekSHen
            Source: 2.2.SecuriteInfo.com.Win32.PWSX-gen.11507.25552.exe.400000.0.unpack, type: UNPACKEDPEMatched rule: Windows_Trojan_SnakeKeylogger_af3faa65 Author: unknown
            Source: 2.2.SecuriteInfo.com.Win32.PWSX-gen.11507.25552.exe.400000.0.unpack, type: UNPACKEDPEMatched rule: Detects Encrial credential stealer malware Author: Florian Roth
            Source: 2.2.SecuriteInfo.com.Win32.PWSX-gen.11507.25552.exe.400000.0.unpack, type: UNPACKEDPEMatched rule: Detects executables with potential process hoocking Author: ditekSHen
            Source: 2.2.SecuriteInfo.com.Win32.PWSX-gen.11507.25552.exe.400000.0.unpack, type: UNPACKEDPEMatched rule: Detects Snake Keylogger Author: ditekSHen
            Source: 0.2.SecuriteInfo.com.Win32.PWSX-gen.11507.25552.exe.429a390.0.raw.unpack, type: UNPACKEDPEMatched rule: Windows_Trojan_SnakeKeylogger_af3faa65 Author: unknown
            Source: 0.2.SecuriteInfo.com.Win32.PWSX-gen.11507.25552.exe.429a390.0.raw.unpack, type: UNPACKEDPEMatched rule: Detects executables with potential process hoocking Author: ditekSHen
            Source: 0.2.SecuriteInfo.com.Win32.PWSX-gen.11507.25552.exe.429a390.0.raw.unpack, type: UNPACKEDPEMatched rule: Detects Snake Keylogger Author: ditekSHen
            Source: 0.2.SecuriteInfo.com.Win32.PWSX-gen.11507.25552.exe.4279970.1.raw.unpack, type: UNPACKEDPEMatched rule: Windows_Trojan_SnakeKeylogger_af3faa65 Author: unknown
            Source: 0.2.SecuriteInfo.com.Win32.PWSX-gen.11507.25552.exe.4279970.1.raw.unpack, type: UNPACKEDPEMatched rule: Detects executables with potential process hoocking Author: ditekSHen
            Source: 0.2.SecuriteInfo.com.Win32.PWSX-gen.11507.25552.exe.4279970.1.raw.unpack, type: UNPACKEDPEMatched rule: Detects Snake Keylogger Author: ditekSHen
            Source: 00000002.00000002.3645837674.0000000000402000.00000040.00000400.00020000.00000000.sdmp, type: MEMORYMatched rule: Windows_Trojan_SnakeKeylogger_af3faa65 Author: unknown
            Source: 00000002.00000002.3645837674.0000000000402000.00000040.00000400.00020000.00000000.sdmp, type: MEMORYMatched rule: Detects Snake Keylogger Author: ditekSHen
            Source: 00000000.00000002.1209255105.0000000004278000.00000004.00000800.00020000.00000000.sdmp, type: MEMORYMatched rule: Windows_Trojan_SnakeKeylogger_af3faa65 Author: unknown
            Source: 00000000.00000002.1209255105.0000000004278000.00000004.00000800.00020000.00000000.sdmp, type: MEMORYMatched rule: Detects Snake Keylogger Author: ditekSHen
            Source: Process Memory Space: SecuriteInfo.com.Win32.PWSX-gen.11507.25552.exe PID: 6516, type: MEMORYSTRMatched rule: Windows_Trojan_SnakeKeylogger_af3faa65 Author: unknown
            Source: Process Memory Space: SecuriteInfo.com.Win32.PWSX-gen.11507.25552.exe PID: 6516, type: MEMORYSTRMatched rule: Detects Snake Keylogger Author: ditekSHen
            Source: Process Memory Space: SecuriteInfo.com.Win32.PWSX-gen.11507.25552.exe PID: 1692, type: MEMORYSTRMatched rule: Windows_Trojan_SnakeKeylogger_af3faa65 Author: unknown
            Source: Process Memory Space: SecuriteInfo.com.Win32.PWSX-gen.11507.25552.exe PID: 1692, type: MEMORYSTRMatched rule: Detects Snake Keylogger Author: ditekSHen
            Source: SecuriteInfo.com.Win32.PWSX-gen.11507.25552.exe, VisualizationData.csLarge array initialization: : array initializer size 497783
            Source: SecuriteInfo.com.Win32.PWSX-gen.11507.25552.exe, SelectedData.csLarge array initialization: SelectedData: array initializer size 3070
            Source: SecuriteInfo.com.Win32.PWSX-gen.11507.25552.exe, FormEvents.csLarge array initialization: FormEvents: array initializer size 3839
            Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.PWSX-gen.11507.25552.exeProcess Stats: CPU usage > 49%
            Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.PWSX-gen.11507.25552.exeCode function: 0_2_07E6F5480_2_07E6F548
            Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.PWSX-gen.11507.25552.exeCode function: 0_2_07E6F5500_2_07E6F550
            Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.PWSX-gen.11507.25552.exeCode function: 0_2_07E6F9880_2_07E6F988
            Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.PWSX-gen.11507.25552.exeCode function: 0_2_07E6F9780_2_07E6F978
            Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.PWSX-gen.11507.25552.exeCode function: 0_2_081759D00_2_081759D0
            Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.PWSX-gen.11507.25552.exeCode function: 0_2_081700060_2_08170006
            Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.PWSX-gen.11507.25552.exeCode function: 0_2_081700400_2_08170040
            Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.PWSX-gen.11507.25552.exeCode function: 0_2_081768E80_2_081768E8
            Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.PWSX-gen.11507.25552.exeCode function: 0_2_081721380_2_08172138
            Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.PWSX-gen.11507.25552.exeCode function: 0_2_081721480_2_08172148
            Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.PWSX-gen.11507.25552.exeCode function: 0_2_081717980_2_08171798
            Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.PWSX-gen.11507.25552.exeCode function: 0_2_0817178A0_2_0817178A
            Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.PWSX-gen.11507.25552.exeCode function: 2_2_02F4B3282_2_02F4B328
            Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.PWSX-gen.11507.25552.exeCode function: 2_2_02F4F0072_2_02F4F007
            Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.PWSX-gen.11507.25552.exeCode function: 2_2_02F4C1902_2_02F4C190
            Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.PWSX-gen.11507.25552.exeCode function: 2_2_02F461082_2_02F46108
            Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.PWSX-gen.11507.25552.exeCode function: 2_2_02F4C7522_2_02F4C752
            Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.PWSX-gen.11507.25552.exeCode function: 2_2_02F4C4702_2_02F4C470
            Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.PWSX-gen.11507.25552.exeCode function: 2_2_02F44AD92_2_02F44AD9
            Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.PWSX-gen.11507.25552.exeCode function: 2_2_02F4CA322_2_02F4CA32
            Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.PWSX-gen.11507.25552.exeCode function: 2_2_02F4BBD22_2_02F4BBD2
            Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.PWSX-gen.11507.25552.exeCode function: 2_2_02F468802_2_02F46880
            Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.PWSX-gen.11507.25552.exeCode function: 2_2_02F498582_2_02F49858
            Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.PWSX-gen.11507.25552.exeCode function: 2_2_02F4BEB02_2_02F4BEB0
            Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.PWSX-gen.11507.25552.exeCode function: 2_2_02F435722_2_02F43572
            Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.PWSX-gen.11507.25552.exeCode function: 2_2_02F4E5282_2_02F4E528
            Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.PWSX-gen.11507.25552.exeCode function: 2_2_02F4E5172_2_02F4E517
            Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.PWSX-gen.11507.25552.exeCode function: 2_2_05B379E82_2_05B379E8
            Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.PWSX-gen.11507.25552.exeCode function: 2_2_05B336E82_2_05B336E8
            Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.PWSX-gen.11507.25552.exeCode function: 2_2_05B382D82_2_05B382D8
            Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.PWSX-gen.11507.25552.exeCode function: 2_2_05B311B02_2_05B311B0
            Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.PWSX-gen.11507.25552.exeCode function: 2_2_05B3D1B82_2_05B3D1B8
            Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.PWSX-gen.11507.25552.exeCode function: 2_2_05B311C02_2_05B311C0
            Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.PWSX-gen.11507.25552.exeCode function: 2_2_05B3D1C82_2_05B3D1C8
            Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.PWSX-gen.11507.25552.exeCode function: 2_2_05B3C9182_2_05B3C918
            Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.PWSX-gen.11507.25552.exeCode function: 2_2_05B309002_2_05B30900
            Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.PWSX-gen.11507.25552.exeCode function: 2_2_05B3C9082_2_05B3C908
            Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.PWSX-gen.11507.25552.exeCode function: 2_2_05B3CD702_2_05B3CD70
            Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.PWSX-gen.11507.25552.exeCode function: 2_2_05B30D602_2_05B30D60
            Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.PWSX-gen.11507.25552.exeCode function: 2_2_05B30D512_2_05B30D51
            Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.PWSX-gen.11507.25552.exeCode function: 2_2_05B3C4B02_2_05B3C4B0
            Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.PWSX-gen.11507.25552.exeCode function: 2_2_05B304A02_2_05B304A0
            Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.PWSX-gen.11507.25552.exeCode function: 2_2_05B304902_2_05B30490
            Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.PWSX-gen.11507.25552.exeCode function: 2_2_05B3F4882_2_05B3F488
            Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.PWSX-gen.11507.25552.exeCode function: 2_2_05B308F02_2_05B308F0
            Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.PWSX-gen.11507.25552.exeCode function: 2_2_05B3F8E02_2_05B3F8E0
            Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.PWSX-gen.11507.25552.exeCode function: 2_2_05B3F8D12_2_05B3F8D1
            Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.PWSX-gen.11507.25552.exeCode function: 2_2_05B3C4C02_2_05B3C4C0
            Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.PWSX-gen.11507.25552.exeCode function: 2_2_05B3F0302_2_05B3F030
            Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.PWSX-gen.11507.25552.exeCode function: 2_2_05B3F0212_2_05B3F021
            Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.PWSX-gen.11507.25552.exeCode function: 2_2_05B3BC102_2_05B3BC10
            Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.PWSX-gen.11507.25552.exeCode function: 2_2_05B3BC002_2_05B3BC00
            Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.PWSX-gen.11507.25552.exeCode function: 2_2_05B300062_2_05B30006
            Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.PWSX-gen.11507.25552.exeCode function: 2_2_05B37C082_2_05B37C08
            Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.PWSX-gen.11507.25552.exeCode function: 2_2_05B3F4782_2_05B3F478
            Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.PWSX-gen.11507.25552.exeCode function: 2_2_05B3C0682_2_05B3C068
            Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.PWSX-gen.11507.25552.exeCode function: 2_2_05B3C0582_2_05B3C058
            Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.PWSX-gen.11507.25552.exeCode function: 2_2_05B300402_2_05B30040
            Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.PWSX-gen.11507.25552.exeCode function: 2_2_05B3B7B82_2_05B3B7B8
            Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.PWSX-gen.11507.25552.exeCode function: 2_2_05B3B7A82_2_05B3B7A8
            Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.PWSX-gen.11507.25552.exeCode function: 2_2_05B3E7802_2_05B3E780
            Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.PWSX-gen.11507.25552.exeCode function: 2_2_05B3EBD82_2_05B3EBD8
            Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.PWSX-gen.11507.25552.exeCode function: 2_2_05B3EBC82_2_05B3EBC8
            Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.PWSX-gen.11507.25552.exeCode function: 2_2_05B3E3282_2_05B3E328
            Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.PWSX-gen.11507.25552.exeCode function: 2_2_05B3E3182_2_05B3E318
            Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.PWSX-gen.11507.25552.exeCode function: 2_2_05B3E7702_2_05B3E770
            Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.PWSX-gen.11507.25552.exeCode function: 2_2_05B3B3602_2_05B3B360
            Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.PWSX-gen.11507.25552.exeCode function: 2_2_05B3B34F2_2_05B3B34F
            Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.PWSX-gen.11507.25552.exeCode function: 2_2_05B3DED02_2_05B3DED0
            Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.PWSX-gen.11507.25552.exeCode function: 2_2_05B336D82_2_05B336D8
            Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.PWSX-gen.11507.25552.exeCode function: 2_2_05B3DEC12_2_05B3DEC1
            Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.PWSX-gen.11507.25552.exeCode function: 2_2_05B3D6202_2_05B3D620
            Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.PWSX-gen.11507.25552.exeCode function: 2_2_05B3D6102_2_05B3D610
            Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.PWSX-gen.11507.25552.exeCode function: 2_2_05B3DA782_2_05B3DA78
            Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.PWSX-gen.11507.25552.exeCode function: 2_2_05B372602_2_05B37260
            Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.PWSX-gen.11507.25552.exeCode function: 2_2_05B3DA692_2_05B3DA69
            Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.PWSX-gen.11507.25552.exeCode function: 2_2_06D9B6F02_2_06D9B6F0
            Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.PWSX-gen.11507.25552.exeCode function: 2_2_06D9D6782_2_06D9D678
            Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.PWSX-gen.11507.25552.exeCode function: 2_2_06D9AA602_2_06D9AA60
            Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.PWSX-gen.11507.25552.exeCode function: 2_2_06D98A102_2_06D98A10
            Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.PWSX-gen.11507.25552.exeCode function: 2_2_06D9C3902_2_06D9C390
            Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.PWSX-gen.11507.25552.exeCode function: 2_2_06D967282_2_06D96728
            Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.PWSX-gen.11507.25552.exeCode function: 2_2_06D9B0A82_2_06D9B0A8
            Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.PWSX-gen.11507.25552.exeCode function: 2_2_06D990592_2_06D99059
            Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.PWSX-gen.11507.25552.exeCode function: 2_2_06D9A4102_2_06D9A410
            Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.PWSX-gen.11507.25552.exeCode function: 2_2_06D9D0302_2_06D9D030
            Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.PWSX-gen.11507.25552.exeCode function: 2_2_06D9C9E02_2_06D9C9E0
            Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.PWSX-gen.11507.25552.exeCode function: 2_2_06D911A02_2_06D911A0
            Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.PWSX-gen.11507.25552.exeCode function: 2_2_06D9BD402_2_06D9BD40
            Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.PWSX-gen.11507.25552.exeCode function: 2_2_06D962D02_2_06D962D0
            Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.PWSX-gen.11507.25552.exeCode function: 2_2_06D962C02_2_06D962C0
            Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.PWSX-gen.11507.25552.exeCode function: 2_2_06D9B6E12_2_06D9B6E1
            Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.PWSX-gen.11507.25552.exeCode function: 2_2_06D9AA502_2_06D9AA50
            Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.PWSX-gen.11507.25552.exeCode function: 2_2_06D95E782_2_06D95E78
            Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.PWSX-gen.11507.25552.exeCode function: 2_2_06D9D6692_2_06D9D669
            Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.PWSX-gen.11507.25552.exeCode function: 2_2_06D95E682_2_06D95E68
            Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.PWSX-gen.11507.25552.exeCode function: 2_2_06D95A112_2_06D95A11
            Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.PWSX-gen.11507.25552.exeCode function: 2_2_06D98A0A2_2_06D98A0A
            Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.PWSX-gen.11507.25552.exeCode function: 2_2_06D95A202_2_06D95A20
            Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.PWSX-gen.11507.25552.exeCode function: 2_2_06D96FD82_2_06D96FD8
            Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.PWSX-gen.11507.25552.exeCode function: 2_2_06D96FC92_2_06D96FC9
            Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.PWSX-gen.11507.25552.exeCode function: 2_2_06D937C02_2_06D937C0
            Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.PWSX-gen.11507.25552.exeCode function: 2_2_06D96B802_2_06D96B80
            Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.PWSX-gen.11507.25552.exeCode function: 2_2_06D9C3802_2_06D9C380
            Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.PWSX-gen.11507.25552.exeCode function: 2_2_06D937B02_2_06D937B0
            Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.PWSX-gen.11507.25552.exeCode function: 2_2_06D96B722_2_06D96B72
            Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.PWSX-gen.11507.25552.exeCode function: 2_2_06D967192_2_06D96719
            Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.PWSX-gen.11507.25552.exeCode function: 2_2_06D93B382_2_06D93B38
            Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.PWSX-gen.11507.25552.exeCode function: 2_2_06D97CF82_2_06D97CF8
            Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.PWSX-gen.11507.25552.exeCode function: 2_2_06D908F02_2_06D908F0
            Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.PWSX-gen.11507.25552.exeCode function: 2_2_06D908E02_2_06D908E0
            Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.PWSX-gen.11507.25552.exeCode function: 2_2_06D904982_2_06D90498
            Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.PWSX-gen.11507.25552.exeCode function: 2_2_06D9789F2_2_06D9789F
            Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.PWSX-gen.11507.25552.exeCode function: 2_2_06D904882_2_06D90488
            Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.PWSX-gen.11507.25552.exeCode function: 2_2_06D978B02_2_06D978B0
            Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.PWSX-gen.11507.25552.exeCode function: 2_2_06D974582_2_06D97458
            Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.PWSX-gen.11507.25552.exeCode function: 2_2_06D974512_2_06D97451
            Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.PWSX-gen.11507.25552.exeCode function: 2_2_06D900402_2_06D90040
            Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.PWSX-gen.11507.25552.exeCode function: 2_2_06D92C0F2_2_06D92C0F
            Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.PWSX-gen.11507.25552.exeCode function: 2_2_06D9A4002_2_06D9A400
            Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.PWSX-gen.11507.25552.exeCode function: 2_2_06D900072_2_06D90007
            Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.PWSX-gen.11507.25552.exeCode function: 2_2_06D948382_2_06D94838
            Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.PWSX-gen.11507.25552.exeCode function: 2_2_06D92C202_2_06D92C20
            Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.PWSX-gen.11507.25552.exeCode function: 2_2_06D9D0202_2_06D9D020
            Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.PWSX-gen.11507.25552.exeCode function: 2_2_06D9C9D02_2_06D9C9D0
            Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.PWSX-gen.11507.25552.exeCode function: 2_2_06D911912_2_06D91191
            Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.PWSX-gen.11507.25552.exeCode function: 2_2_06D985B82_2_06D985B8
            Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.PWSX-gen.11507.25552.exeCode function: 2_2_06D985A82_2_06D985A8
            Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.PWSX-gen.11507.25552.exeCode function: 2_2_06D955A02_2_06D955A0
            Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.PWSX-gen.11507.25552.exeCode function: 2_2_06D981502_2_06D98150
            Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.PWSX-gen.11507.25552.exeCode function: 2_2_06D90D482_2_06D90D48
            Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.PWSX-gen.11507.25552.exeCode function: 2_2_06D981602_2_06D98160
            Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.PWSX-gen.11507.25552.exeCode function: 2_2_06D97D082_2_06D97D08
            Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.PWSX-gen.11507.25552.exeCode function: 2_2_06D90D392_2_06D90D39
            Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.PWSX-gen.11507.25552.exeCode function: 2_2_06D9BD302_2_06D9BD30
            Source: SecuriteInfo.com.Win32.PWSX-gen.11507.25552.exe, 00000000.00000002.1207520648.000000000131E000.00000004.00000020.00020000.00000000.sdmpBinary or memory string: OriginalFilenameclr.dllT vs SecuriteInfo.com.Win32.PWSX-gen.11507.25552.exe
            Source: SecuriteInfo.com.Win32.PWSX-gen.11507.25552.exe, 00000000.00000002.1208871690.00000000032D2000.00000004.00000800.00020000.00000000.sdmpBinary or memory string: OriginalFilenamelfwhUWZlmFnGhDYPudAJ.exeX vs SecuriteInfo.com.Win32.PWSX-gen.11507.25552.exe
            Source: SecuriteInfo.com.Win32.PWSX-gen.11507.25552.exe, 00000000.00000002.1211836261.00000000080F0000.00000004.08000000.00040000.00000000.sdmpBinary or memory string: OriginalFilenameMontero.dll8 vs SecuriteInfo.com.Win32.PWSX-gen.11507.25552.exe
            Source: SecuriteInfo.com.Win32.PWSX-gen.11507.25552.exe, 00000000.00000002.1209255105.0000000004278000.00000004.00000800.00020000.00000000.sdmpBinary or memory string: OriginalFilenamelfwhUWZlmFnGhDYPudAJ.exeX vs SecuriteInfo.com.Win32.PWSX-gen.11507.25552.exe
            Source: SecuriteInfo.com.Win32.PWSX-gen.11507.25552.exe, 00000000.00000002.1209255105.0000000004278000.00000004.00000800.00020000.00000000.sdmpBinary or memory string: OriginalFilenameMontero.dll8 vs SecuriteInfo.com.Win32.PWSX-gen.11507.25552.exe
            Source: SecuriteInfo.com.Win32.PWSX-gen.11507.25552.exe, 00000000.00000000.1181383069.0000000000E18000.00000002.00000001.01000000.00000003.sdmpBinary or memory string: OriginalFilenameToBz.exe> vs SecuriteInfo.com.Win32.PWSX-gen.11507.25552.exe
            Source: SecuriteInfo.com.Win32.PWSX-gen.11507.25552.exe, 00000000.00000002.1210622422.0000000005C30000.00000004.08000000.00040000.00000000.sdmpBinary or memory string: OriginalFilenameTL.dll" vs SecuriteInfo.com.Win32.PWSX-gen.11507.25552.exe
            Source: SecuriteInfo.com.Win32.PWSX-gen.11507.25552.exe, 00000002.00000002.3646096606.0000000001177000.00000004.00000010.00020000.00000000.sdmpBinary or memory string: OriginalFilenameUNKNOWN_FILET vs SecuriteInfo.com.Win32.PWSX-gen.11507.25552.exe
            Source: SecuriteInfo.com.Win32.PWSX-gen.11507.25552.exe, 00000002.00000002.3645837674.0000000000402000.00000040.00000400.00020000.00000000.sdmpBinary or memory string: OriginalFilenamelfwhUWZlmFnGhDYPudAJ.exeX vs SecuriteInfo.com.Win32.PWSX-gen.11507.25552.exe
            Source: SecuriteInfo.com.Win32.PWSX-gen.11507.25552.exeBinary or memory string: OriginalFilenameToBz.exe> vs SecuriteInfo.com.Win32.PWSX-gen.11507.25552.exe
            Source: SecuriteInfo.com.Win32.PWSX-gen.11507.25552.exeStatic PE information: EXECUTABLE_IMAGE, 32BIT_MACHINE
            Source: 0.2.SecuriteInfo.com.Win32.PWSX-gen.11507.25552.exe.429a390.0.unpack, type: UNPACKEDPEMatched rule: Windows_Trojan_SnakeKeylogger_af3faa65 os = windows, severity = x86, creation_date = 2021-04-06, scan_context = file, memory, license = Elastic License v2, threat_name = Windows.Trojan.SnakeKeylogger, fingerprint = 15f4ef2a03c6f5c6284ea6a9013007e4ea7dc90a1ba9c81a53a1c7407d85890d, id = af3faa65-b19d-4267-ac02-1a3b50cdc700, last_modified = 2021-08-23
            Source: 0.2.SecuriteInfo.com.Win32.PWSX-gen.11507.25552.exe.429a390.0.unpack, type: UNPACKEDPEMatched rule: MAL_Envrial_Jan18_1 date = 2018-01-21, hash2 = 9edd8f0e22340ecc45c5f09e449aa85d196f3f506ff3f44275367df924b95c5d, hash1 = 9ae3aa2c61f7895ba6b1a3f85fbe36c8697287dc7477c5a03d32cf994fdbce85, author = Florian Roth, description = Detects Encrial credential stealer malware, reference = https://twitter.com/malwrhunterteam/status/953313514629853184, license = https://creativecommons.org/licenses/by-nc/4.0/
            Source: 0.2.SecuriteInfo.com.Win32.PWSX-gen.11507.25552.exe.429a390.0.unpack, type: UNPACKEDPEMatched rule: INDICATOR_SUSPICIOUS_EXE_DotNetProcHook author = ditekSHen, description = Detects executables with potential process hoocking
            Source: 0.2.SecuriteInfo.com.Win32.PWSX-gen.11507.25552.exe.429a390.0.unpack, type: UNPACKEDPEMatched rule: MALWARE_Win_SnakeKeylogger author = ditekSHen, description = Detects Snake Keylogger, clamav_sig = MALWARE.Win.Trojan.SnakeKeylogger
            Source: 0.2.SecuriteInfo.com.Win32.PWSX-gen.11507.25552.exe.4279970.1.unpack, type: UNPACKEDPEMatched rule: Windows_Trojan_SnakeKeylogger_af3faa65 os = windows, severity = x86, creation_date = 2021-04-06, scan_context = file, memory, license = Elastic License v2, threat_name = Windows.Trojan.SnakeKeylogger, fingerprint = 15f4ef2a03c6f5c6284ea6a9013007e4ea7dc90a1ba9c81a53a1c7407d85890d, id = af3faa65-b19d-4267-ac02-1a3b50cdc700, last_modified = 2021-08-23
            Source: 0.2.SecuriteInfo.com.Win32.PWSX-gen.11507.25552.exe.4279970.1.unpack, type: UNPACKEDPEMatched rule: MAL_Envrial_Jan18_1 date = 2018-01-21, hash2 = 9edd8f0e22340ecc45c5f09e449aa85d196f3f506ff3f44275367df924b95c5d, hash1 = 9ae3aa2c61f7895ba6b1a3f85fbe36c8697287dc7477c5a03d32cf994fdbce85, author = Florian Roth, description = Detects Encrial credential stealer malware, reference = https://twitter.com/malwrhunterteam/status/953313514629853184, license = https://creativecommons.org/licenses/by-nc/4.0/
            Source: 0.2.SecuriteInfo.com.Win32.PWSX-gen.11507.25552.exe.4279970.1.unpack, type: UNPACKEDPEMatched rule: INDICATOR_SUSPICIOUS_EXE_DotNetProcHook author = ditekSHen, description = Detects executables with potential process hoocking
            Source: 0.2.SecuriteInfo.com.Win32.PWSX-gen.11507.25552.exe.4279970.1.unpack, type: UNPACKEDPEMatched rule: MALWARE_Win_SnakeKeylogger author = ditekSHen, description = Detects Snake Keylogger, clamav_sig = MALWARE.Win.Trojan.SnakeKeylogger
            Source: 2.2.SecuriteInfo.com.Win32.PWSX-gen.11507.25552.exe.400000.0.unpack, type: UNPACKEDPEMatched rule: Windows_Trojan_SnakeKeylogger_af3faa65 os = windows, severity = x86, creation_date = 2021-04-06, scan_context = file, memory, license = Elastic License v2, threat_name = Windows.Trojan.SnakeKeylogger, fingerprint = 15f4ef2a03c6f5c6284ea6a9013007e4ea7dc90a1ba9c81a53a1c7407d85890d, id = af3faa65-b19d-4267-ac02-1a3b50cdc700, last_modified = 2021-08-23
            Source: 2.2.SecuriteInfo.com.Win32.PWSX-gen.11507.25552.exe.400000.0.unpack, type: UNPACKEDPEMatched rule: MAL_Envrial_Jan18_1 date = 2018-01-21, hash2 = 9edd8f0e22340ecc45c5f09e449aa85d196f3f506ff3f44275367df924b95c5d, hash1 = 9ae3aa2c61f7895ba6b1a3f85fbe36c8697287dc7477c5a03d32cf994fdbce85, author = Florian Roth, description = Detects Encrial credential stealer malware, reference = https://twitter.com/malwrhunterteam/status/953313514629853184, license = https://creativecommons.org/licenses/by-nc/4.0/
            Source: 2.2.SecuriteInfo.com.Win32.PWSX-gen.11507.25552.exe.400000.0.unpack, type: UNPACKEDPEMatched rule: INDICATOR_SUSPICIOUS_EXE_DotNetProcHook author = ditekSHen, description = Detects executables with potential process hoocking
            Source: 2.2.SecuriteInfo.com.Win32.PWSX-gen.11507.25552.exe.400000.0.unpack, type: UNPACKEDPEMatched rule: MALWARE_Win_SnakeKeylogger author = ditekSHen, description = Detects Snake Keylogger, clamav_sig = MALWARE.Win.Trojan.SnakeKeylogger
            Source: 0.2.SecuriteInfo.com.Win32.PWSX-gen.11507.25552.exe.429a390.0.raw.unpack, type: UNPACKEDPEMatched rule: Windows_Trojan_SnakeKeylogger_af3faa65 os = windows, severity = x86, creation_date = 2021-04-06, scan_context = file, memory, license = Elastic License v2, threat_name = Windows.Trojan.SnakeKeylogger, fingerprint = 15f4ef2a03c6f5c6284ea6a9013007e4ea7dc90a1ba9c81a53a1c7407d85890d, id = af3faa65-b19d-4267-ac02-1a3b50cdc700, last_modified = 2021-08-23
            Source: 0.2.SecuriteInfo.com.Win32.PWSX-gen.11507.25552.exe.429a390.0.raw.unpack, type: UNPACKEDPEMatched rule: INDICATOR_SUSPICIOUS_EXE_DotNetProcHook author = ditekSHen, description = Detects executables with potential process hoocking
            Source: 0.2.SecuriteInfo.com.Win32.PWSX-gen.11507.25552.exe.429a390.0.raw.unpack, type: UNPACKEDPEMatched rule: MALWARE_Win_SnakeKeylogger author = ditekSHen, description = Detects Snake Keylogger, clamav_sig = MALWARE.Win.Trojan.SnakeKeylogger
            Source: 0.2.SecuriteInfo.com.Win32.PWSX-gen.11507.25552.exe.4279970.1.raw.unpack, type: UNPACKEDPEMatched rule: Windows_Trojan_SnakeKeylogger_af3faa65 os = windows, severity = x86, creation_date = 2021-04-06, scan_context = file, memory, license = Elastic License v2, threat_name = Windows.Trojan.SnakeKeylogger, fingerprint = 15f4ef2a03c6f5c6284ea6a9013007e4ea7dc90a1ba9c81a53a1c7407d85890d, id = af3faa65-b19d-4267-ac02-1a3b50cdc700, last_modified = 2021-08-23
            Source: 0.2.SecuriteInfo.com.Win32.PWSX-gen.11507.25552.exe.4279970.1.raw.unpack, type: UNPACKEDPEMatched rule: INDICATOR_SUSPICIOUS_EXE_DotNetProcHook author = ditekSHen, description = Detects executables with potential process hoocking
            Source: 0.2.SecuriteInfo.com.Win32.PWSX-gen.11507.25552.exe.4279970.1.raw.unpack, type: UNPACKEDPEMatched rule: MALWARE_Win_SnakeKeylogger author = ditekSHen, description = Detects Snake Keylogger, clamav_sig = MALWARE.Win.Trojan.SnakeKeylogger
            Source: 00000002.00000002.3645837674.0000000000402000.00000040.00000400.00020000.00000000.sdmp, type: MEMORYMatched rule: Windows_Trojan_SnakeKeylogger_af3faa65 os = windows, severity = x86, creation_date = 2021-04-06, scan_context = file, memory, license = Elastic License v2, threat_name = Windows.Trojan.SnakeKeylogger, fingerprint = 15f4ef2a03c6f5c6284ea6a9013007e4ea7dc90a1ba9c81a53a1c7407d85890d, id = af3faa65-b19d-4267-ac02-1a3b50cdc700, last_modified = 2021-08-23
            Source: 00000002.00000002.3645837674.0000000000402000.00000040.00000400.00020000.00000000.sdmp, type: MEMORYMatched rule: MALWARE_Win_SnakeKeylogger author = ditekSHen, description = Detects Snake Keylogger, clamav_sig = MALWARE.Win.Trojan.SnakeKeylogger
            Source: 00000000.00000002.1209255105.0000000004278000.00000004.00000800.00020000.00000000.sdmp, type: MEMORYMatched rule: Windows_Trojan_SnakeKeylogger_af3faa65 os = windows, severity = x86, creation_date = 2021-04-06, scan_context = file, memory, license = Elastic License v2, threat_name = Windows.Trojan.SnakeKeylogger, fingerprint = 15f4ef2a03c6f5c6284ea6a9013007e4ea7dc90a1ba9c81a53a1c7407d85890d, id = af3faa65-b19d-4267-ac02-1a3b50cdc700, last_modified = 2021-08-23
            Source: 00000000.00000002.1209255105.0000000004278000.00000004.00000800.00020000.00000000.sdmp, type: MEMORYMatched rule: MALWARE_Win_SnakeKeylogger author = ditekSHen, description = Detects Snake Keylogger, clamav_sig = MALWARE.Win.Trojan.SnakeKeylogger
            Source: Process Memory Space: SecuriteInfo.com.Win32.PWSX-gen.11507.25552.exe PID: 6516, type: MEMORYSTRMatched rule: Windows_Trojan_SnakeKeylogger_af3faa65 os = windows, severity = x86, creation_date = 2021-04-06, scan_context = file, memory, license = Elastic License v2, threat_name = Windows.Trojan.SnakeKeylogger, fingerprint = 15f4ef2a03c6f5c6284ea6a9013007e4ea7dc90a1ba9c81a53a1c7407d85890d, id = af3faa65-b19d-4267-ac02-1a3b50cdc700, last_modified = 2021-08-23
            Source: Process Memory Space: SecuriteInfo.com.Win32.PWSX-gen.11507.25552.exe PID: 6516, type: MEMORYSTRMatched rule: MALWARE_Win_SnakeKeylogger author = ditekSHen, description = Detects Snake Keylogger, clamav_sig = MALWARE.Win.Trojan.SnakeKeylogger
            Source: Process Memory Space: SecuriteInfo.com.Win32.PWSX-gen.11507.25552.exe PID: 1692, type: MEMORYSTRMatched rule: Windows_Trojan_SnakeKeylogger_af3faa65 os = windows, severity = x86, creation_date = 2021-04-06, scan_context = file, memory, license = Elastic License v2, threat_name = Windows.Trojan.SnakeKeylogger, fingerprint = 15f4ef2a03c6f5c6284ea6a9013007e4ea7dc90a1ba9c81a53a1c7407d85890d, id = af3faa65-b19d-4267-ac02-1a3b50cdc700, last_modified = 2021-08-23
            Source: Process Memory Space: SecuriteInfo.com.Win32.PWSX-gen.11507.25552.exe PID: 1692, type: MEMORYSTRMatched rule: MALWARE_Win_SnakeKeylogger author = ditekSHen, description = Detects Snake Keylogger, clamav_sig = MALWARE.Win.Trojan.SnakeKeylogger
            Source: SecuriteInfo.com.Win32.PWSX-gen.11507.25552.exeStatic PE information: Section: .text IMAGE_SCN_CNT_CODE, IMAGE_SCN_MEM_EXECUTE, IMAGE_SCN_MEM_READ
            Source: 0.2.SecuriteInfo.com.Win32.PWSX-gen.11507.25552.exe.429a390.0.raw.unpack, ---.csCryptographic APIs: 'TransformFinalBlock'
            Source: 0.2.SecuriteInfo.com.Win32.PWSX-gen.11507.25552.exe.429a390.0.raw.unpack, ---.csCryptographic APIs: 'TransformFinalBlock'
            Source: 0.2.SecuriteInfo.com.Win32.PWSX-gen.11507.25552.exe.429a390.0.raw.unpack, --.csCryptographic APIs: 'TransformFinalBlock'
            Source: 0.2.SecuriteInfo.com.Win32.PWSX-gen.11507.25552.exe.429a390.0.raw.unpack, --.csCryptographic APIs: 'TransformFinalBlock'
            Source: 0.2.SecuriteInfo.com.Win32.PWSX-gen.11507.25552.exe.4279970.1.raw.unpack, ---.csCryptographic APIs: 'TransformFinalBlock'
            Source: 0.2.SecuriteInfo.com.Win32.PWSX-gen.11507.25552.exe.4279970.1.raw.unpack, ---.csCryptographic APIs: 'TransformFinalBlock'
            Source: 0.2.SecuriteInfo.com.Win32.PWSX-gen.11507.25552.exe.4279970.1.raw.unpack, --.csCryptographic APIs: 'TransformFinalBlock'
            Source: 0.2.SecuriteInfo.com.Win32.PWSX-gen.11507.25552.exe.4279970.1.raw.unpack, --.csCryptographic APIs: 'TransformFinalBlock'
            Source: 0.2.SecuriteInfo.com.Win32.PWSX-gen.11507.25552.exe.429a390.0.raw.unpack, ---.csBase64 encoded string: 'xvt7iejCkuFuSlar/oezVf2tSjyeLol0O56iQIadWLRsK4Fl2D8bRyFVpvZEZHft'
            Source: 0.2.SecuriteInfo.com.Win32.PWSX-gen.11507.25552.exe.4279970.1.raw.unpack, ---.csBase64 encoded string: 'xvt7iejCkuFuSlar/oezVf2tSjyeLol0O56iQIadWLRsK4Fl2D8bRyFVpvZEZHft'
            Source: 0.2.SecuriteInfo.com.Win32.PWSX-gen.11507.25552.exe.43b2398.2.raw.unpack, VtKlMWkUt5LJIYHW47.csSecurity API names: System.IO.DirectoryInfo.SetAccessControl(System.Security.AccessControl.DirectorySecurity)
            Source: 0.2.SecuriteInfo.com.Win32.PWSX-gen.11507.25552.exe.43b2398.2.raw.unpack, VtKlMWkUt5LJIYHW47.csSecurity API names: System.Security.Principal.WindowsIdentity.GetCurrent()
            Source: 0.2.SecuriteInfo.com.Win32.PWSX-gen.11507.25552.exe.43b2398.2.raw.unpack, VtKlMWkUt5LJIYHW47.csSecurity API names: System.Security.AccessControl.FileSystemSecurity.AddAccessRule(System.Security.AccessControl.FileSystemAccessRule)
            Source: 0.2.SecuriteInfo.com.Win32.PWSX-gen.11507.25552.exe.80f0000.6.raw.unpack, X8tf2NTPiRMiLlf80U.csSecurity API names: System.Security.Principal.WindowsPrincipal.IsInRole(System.Security.Principal.WindowsBuiltInRole)
            Source: 0.2.SecuriteInfo.com.Win32.PWSX-gen.11507.25552.exe.80f0000.6.raw.unpack, X8tf2NTPiRMiLlf80U.csSecurity API names: System.Security.Principal.WindowsIdentity.GetCurrent()
            Source: 0.2.SecuriteInfo.com.Win32.PWSX-gen.11507.25552.exe.80f0000.6.raw.unpack, VtKlMWkUt5LJIYHW47.csSecurity API names: System.IO.DirectoryInfo.SetAccessControl(System.Security.AccessControl.DirectorySecurity)
            Source: 0.2.SecuriteInfo.com.Win32.PWSX-gen.11507.25552.exe.80f0000.6.raw.unpack, VtKlMWkUt5LJIYHW47.csSecurity API names: System.Security.Principal.WindowsIdentity.GetCurrent()
            Source: 0.2.SecuriteInfo.com.Win32.PWSX-gen.11507.25552.exe.80f0000.6.raw.unpack, VtKlMWkUt5LJIYHW47.csSecurity API names: System.Security.AccessControl.FileSystemSecurity.AddAccessRule(System.Security.AccessControl.FileSystemAccessRule)
            Source: 0.2.SecuriteInfo.com.Win32.PWSX-gen.11507.25552.exe.43b2398.2.raw.unpack, X8tf2NTPiRMiLlf80U.csSecurity API names: System.Security.Principal.WindowsPrincipal.IsInRole(System.Security.Principal.WindowsBuiltInRole)
            Source: 0.2.SecuriteInfo.com.Win32.PWSX-gen.11507.25552.exe.43b2398.2.raw.unpack, X8tf2NTPiRMiLlf80U.csSecurity API names: System.Security.Principal.WindowsIdentity.GetCurrent()
            Source: classification engineClassification label: mal100.troj.spyw.evad.winEXE@3/1@2/2
            Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.PWSX-gen.11507.25552.exeFile created: C:\Users\user\AppData\Local\Microsoft\CLR_v4.0_32\UsageLogs\SecuriteInfo.com.Win32.PWSX-gen.11507.25552.exe.logJump to behavior
            Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.PWSX-gen.11507.25552.exeMutant created: NULL
            Source: SecuriteInfo.com.Win32.PWSX-gen.11507.25552.exeStatic PE information: Section: .text IMAGE_SCN_CNT_CODE, IMAGE_SCN_MEM_EXECUTE, IMAGE_SCN_MEM_READ
            Source: SecuriteInfo.com.Win32.PWSX-gen.11507.25552.exeStatic file information: TRID: Win32 Executable (generic) Net Framework (10011505/4) 49.80%
            Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.PWSX-gen.11507.25552.exeKey opened: HKEY_CURRENT_USER\Software\Policies\Microsoft\Windows\Safer\CodeIdentifiersJump to behavior
            Source: SecuriteInfo.com.Win32.PWSX-gen.11507.25552.exe, 00000002.00000002.3647546568.000000000336B000.00000004.00000800.00020000.00000000.sdmp, SecuriteInfo.com.Win32.PWSX-gen.11507.25552.exe, 00000002.00000002.3647546568.000000000335B000.00000004.00000800.00020000.00000000.sdmp, SecuriteInfo.com.Win32.PWSX-gen.11507.25552.exe, 00000002.00000002.3647546568.0000000003379000.00000004.00000800.00020000.00000000.sdmpBinary or memory string: CREATE TABLE password_notes (id INTEGER PRIMARY KEY AUTOINCREMENT, parent_id INTEGER NOT NULL REFERENCES logins ON UPDATE CASCADE ON DELETE CASCADE DEFERRABLE INITIALLY DEFERRED, key VARCHAR NOT NULL, value BLOB, date_created INTEGER NOT NULL, confidential INTEGER, UNIQUE (parent_id, key));
            Source: SecuriteInfo.com.Win32.PWSX-gen.11507.25552.exeReversingLabs: Detection: 33%
            Source: SecuriteInfo.com.Win32.PWSX-gen.11507.25552.exeVirustotal: Detection: 32%
            Source: unknownProcess created: C:\Users\user\Desktop\SecuriteInfo.com.Win32.PWSX-gen.11507.25552.exe "C:\Users\user\Desktop\SecuriteInfo.com.Win32.PWSX-gen.11507.25552.exe"
            Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.PWSX-gen.11507.25552.exeProcess created: C:\Users\user\Desktop\SecuriteInfo.com.Win32.PWSX-gen.11507.25552.exe "C:\Users\user\Desktop\SecuriteInfo.com.Win32.PWSX-gen.11507.25552.exe"
            Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.PWSX-gen.11507.25552.exeProcess created: C:\Users\user\Desktop\SecuriteInfo.com.Win32.PWSX-gen.11507.25552.exe "C:\Users\user\Desktop\SecuriteInfo.com.Win32.PWSX-gen.11507.25552.exe"Jump to behavior
            Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.PWSX-gen.11507.25552.exeSection loaded: mscoree.dllJump to behavior
            Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.PWSX-gen.11507.25552.exeSection loaded: apphelp.dllJump to behavior
            Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.PWSX-gen.11507.25552.exeSection loaded: kernel.appcore.dllJump to behavior
            Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.PWSX-gen.11507.25552.exeSection loaded: version.dllJump to behavior
            Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.PWSX-gen.11507.25552.exeSection loaded: vcruntime140_clr0400.dllJump to behavior
            Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.PWSX-gen.11507.25552.exeSection loaded: ucrtbase_clr0400.dllJump to behavior
            Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.PWSX-gen.11507.25552.exeSection loaded: ucrtbase_clr0400.dllJump to behavior
            Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.PWSX-gen.11507.25552.exeSection loaded: uxtheme.dllJump to behavior
            Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.PWSX-gen.11507.25552.exeSection loaded: cryptsp.dllJump to behavior
            Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.PWSX-gen.11507.25552.exeSection loaded: rsaenh.dllJump to behavior
            Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.PWSX-gen.11507.25552.exeSection loaded: cryptbase.dllJump to behavior
            Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.PWSX-gen.11507.25552.exeSection loaded: windows.storage.dllJump to behavior
            Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.PWSX-gen.11507.25552.exeSection loaded: wldp.dllJump to behavior
            Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.PWSX-gen.11507.25552.exeSection loaded: profapi.dllJump to behavior
            Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.PWSX-gen.11507.25552.exeSection loaded: dwrite.dllJump to behavior
            Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.PWSX-gen.11507.25552.exeSection loaded: textshaping.dllJump to behavior
            Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.PWSX-gen.11507.25552.exeSection loaded: amsi.dllJump to behavior
            Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.PWSX-gen.11507.25552.exeSection loaded: userenv.dllJump to behavior
            Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.PWSX-gen.11507.25552.exeSection loaded: msasn1.dllJump to behavior
            Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.PWSX-gen.11507.25552.exeSection loaded: gpapi.dllJump to behavior
            Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.PWSX-gen.11507.25552.exeSection loaded: windowscodecs.dllJump to behavior
            Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.PWSX-gen.11507.25552.exeSection loaded: mscoree.dllJump to behavior
            Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.PWSX-gen.11507.25552.exeSection loaded: kernel.appcore.dllJump to behavior
            Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.PWSX-gen.11507.25552.exeSection loaded: version.dllJump to behavior
            Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.PWSX-gen.11507.25552.exeSection loaded: vcruntime140_clr0400.dllJump to behavior
            Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.PWSX-gen.11507.25552.exeSection loaded: ucrtbase_clr0400.dllJump to behavior
            Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.PWSX-gen.11507.25552.exeSection loaded: ucrtbase_clr0400.dllJump to behavior
            Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.PWSX-gen.11507.25552.exeSection loaded: uxtheme.dllJump to behavior
            Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.PWSX-gen.11507.25552.exeSection loaded: windows.storage.dllJump to behavior
            Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.PWSX-gen.11507.25552.exeSection loaded: wldp.dllJump to behavior
            Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.PWSX-gen.11507.25552.exeSection loaded: profapi.dllJump to behavior
            Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.PWSX-gen.11507.25552.exeSection loaded: cryptsp.dllJump to behavior
            Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.PWSX-gen.11507.25552.exeSection loaded: rsaenh.dllJump to behavior
            Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.PWSX-gen.11507.25552.exeSection loaded: cryptbase.dllJump to behavior
            Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.PWSX-gen.11507.25552.exeSection loaded: rasapi32.dllJump to behavior
            Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.PWSX-gen.11507.25552.exeSection loaded: rasman.dllJump to behavior
            Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.PWSX-gen.11507.25552.exeSection loaded: rtutils.dllJump to behavior
            Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.PWSX-gen.11507.25552.exeSection loaded: mswsock.dllJump to behavior
            Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.PWSX-gen.11507.25552.exeSection loaded: winhttp.dllJump to behavior
            Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.PWSX-gen.11507.25552.exeSection loaded: ondemandconnroutehelper.dllJump to behavior
            Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.PWSX-gen.11507.25552.exeSection loaded: iphlpapi.dllJump to behavior
            Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.PWSX-gen.11507.25552.exeSection loaded: dhcpcsvc6.dllJump to behavior
            Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.PWSX-gen.11507.25552.exeSection loaded: dhcpcsvc.dllJump to behavior
            Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.PWSX-gen.11507.25552.exeSection loaded: dnsapi.dllJump to behavior
            Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.PWSX-gen.11507.25552.exeSection loaded: winnsi.dllJump to behavior
            Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.PWSX-gen.11507.25552.exeSection loaded: rasadhlp.dllJump to behavior
            Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.PWSX-gen.11507.25552.exeSection loaded: fwpuclnt.dllJump to behavior
            Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.PWSX-gen.11507.25552.exeSection loaded: secur32.dllJump to behavior
            Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.PWSX-gen.11507.25552.exeSection loaded: sspicli.dllJump to behavior
            Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.PWSX-gen.11507.25552.exeSection loaded: schannel.dllJump to behavior
            Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.PWSX-gen.11507.25552.exeSection loaded: mskeyprotect.dllJump to behavior
            Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.PWSX-gen.11507.25552.exeSection loaded: ntasn1.dllJump to behavior
            Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.PWSX-gen.11507.25552.exeSection loaded: ncrypt.dllJump to behavior
            Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.PWSX-gen.11507.25552.exeSection loaded: ncryptsslp.dllJump to behavior
            Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.PWSX-gen.11507.25552.exeSection loaded: msasn1.dllJump to behavior
            Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.PWSX-gen.11507.25552.exeSection loaded: gpapi.dllJump to behavior
            Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.PWSX-gen.11507.25552.exeSection loaded: dpapi.dllJump to behavior
            Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.PWSX-gen.11507.25552.exeKey value queried: HKEY_LOCAL_MACHINE\SOFTWARE\Classes\WOW6432Node\CLSID\{0EE7644B-1BAD-48B1-9889-0281C206EB85}\InprocServer32Jump to behavior
            Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.PWSX-gen.11507.25552.exeFile opened: C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscorrc.dllJump to behavior
            Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.PWSX-gen.11507.25552.exeKey opened: HKEY_CURRENT_USER\Software\Microsoft\Office\15.0\Outlook\Profiles\Outlook\9375CFF0413111d3B88A00104B2A6676Jump to behavior
            Source: SecuriteInfo.com.Win32.PWSX-gen.11507.25552.exeStatic PE information: data directory type: IMAGE_DIRECTORY_ENTRY_COM_DESCRIPTOR
            Source: SecuriteInfo.com.Win32.PWSX-gen.11507.25552.exeStatic PE information: DYNAMIC_BASE, NX_COMPAT, NO_SEH, TERMINAL_SERVER_AWARE

            Data Obfuscation

            barindex
            Source: 0.2.SecuriteInfo.com.Win32.PWSX-gen.11507.25552.exe.80f0000.6.raw.unpack, VtKlMWkUt5LJIYHW47.cs.Net Code: cc5bD6Sh5X System.Reflection.Assembly.Load(byte[])
            Source: 0.2.SecuriteInfo.com.Win32.PWSX-gen.11507.25552.exe.43b2398.2.raw.unpack, VtKlMWkUt5LJIYHW47.cs.Net Code: cc5bD6Sh5X System.Reflection.Assembly.Load(byte[])
            Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.PWSX-gen.11507.25552.exeCode function: 2_2_05B32CF0 push esp; iretd 2_2_05B32CF1
            Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.PWSX-gen.11507.25552.exeCode function: 2_2_05B326A8 push esp; retf 2_2_05B32931
            Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.PWSX-gen.11507.25552.exeCode function: 2_2_06D99005 push es; ret 2_2_06D9904C
            Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.PWSX-gen.11507.25552.exeCode function: 2_2_06D97420 push 5D906C90h; ret 2_2_06D97443
            Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.PWSX-gen.11507.25552.exeCode function: 2_2_06D9F1DC push es; iretd 2_2_06D9F22C
            Source: SecuriteInfo.com.Win32.PWSX-gen.11507.25552.exeStatic PE information: section name: .text entropy: 7.573189500244981
            Source: 0.2.SecuriteInfo.com.Win32.PWSX-gen.11507.25552.exe.80f0000.6.raw.unpack, dtZUlxbglGTJkDrYwK.csHigh entropy of concatenated method names: 'pBTqvktk12', 'q7aq3kj0F2', 'oD7qDbNjLI', 'VORqCWM2Hs', 'gsiqxR6uxd', 'R2jqOb9tiY', 'chWqYHfvKY', 'm7GqjVZbj2', 'Tfyq0CWvK2', 'lFQqROrjGr'
            Source: 0.2.SecuriteInfo.com.Win32.PWSX-gen.11507.25552.exe.80f0000.6.raw.unpack, F7Jm8DzpfMncLRy9dQ.csHigh entropy of concatenated method names: 'UooLOAQuTl', 'vWILjv8AVX', 'yUqL005Kt2', 'KRgL29L0M6', 'alQL8JeaTc', 'JAmL7OxMdZ', 'avpLTXCj2A', 'p70LEhEdnY', 'oAELvanZI9', 'unxL3LDOTL'
            Source: 0.2.SecuriteInfo.com.Win32.PWSX-gen.11507.25552.exe.80f0000.6.raw.unpack, KDuqUAUiU7aAlaOKKq.csHigh entropy of concatenated method names: 'EditValue', 'GetEditStyle', 'fk11oiUyhD', 'MsL1tkt8jK', 'mUL1zTfwvs', 'KdQsHRHJGs', 'k30sP2lc3R', 'pYAs1OZu1w', 'wd3ssq7ROq', 'YQH6LjqBle2LvwEAMat'
            Source: 0.2.SecuriteInfo.com.Win32.PWSX-gen.11507.25552.exe.80f0000.6.raw.unpack, VtKlMWkUt5LJIYHW47.csHigh entropy of concatenated method names: 'lCUs6bV1cm', 'tNHsFmpUxD', 'JoBsJXaZmw', 'E78scHeZDP', 'XfBsebLrI5', 'YLysAretyv', 'pZxsqDGXTF', 'cPxsy8nXfw', 'Px0sf0qrNu', 'G6hs4gIUFW'
            Source: 0.2.SecuriteInfo.com.Win32.PWSX-gen.11507.25552.exe.80f0000.6.raw.unpack, trCZ0OiilwKLPgXtyD6.csHigh entropy of concatenated method names: 'XcTLtoFwlU', 'lR9LzBRSvi', 'iBhKHdEa03', 'JtLKPs6tP1', 'k1cK1HaJ6F', 'e9CKsr0X3Q', 'wDBKbgPQIY', 'kZaK6ppFGd', 'aY0KF0qI48', 'ogfKJOYeq5'
            Source: 0.2.SecuriteInfo.com.Win32.PWSX-gen.11507.25552.exe.80f0000.6.raw.unpack, OFedRUp96REPNdOkD2.csHigh entropy of concatenated method names: 'zIV5XHdWPS', 't2259fZyFt', 'LDy5BR703r', 'wCT5ihWp87', 'F2658pfayT', 'raw5hQRT69', 'j3C57f49C6', 'faG5TVZoha', 'iA95VmB5E9', 'HeF5uUhbv6'
            Source: 0.2.SecuriteInfo.com.Win32.PWSX-gen.11507.25552.exe.80f0000.6.raw.unpack, vkqgZNj9l4Ra9u1s7J.csHigh entropy of concatenated method names: 'hLtA6EBL4y', 'N1pAJB5C0I', 'RqSAe7eIcK', 'HaKAqPHaWp', 'j6ZAyDUK8b', 'FiMeSw6FM7', 'NyKerEL10n', 'gg1ew60Ag1', 'lLgenT4FFW', 'nkveoWs17c'
            Source: 0.2.SecuriteInfo.com.Win32.PWSX-gen.11507.25552.exe.80f0000.6.raw.unpack, X8tf2NTPiRMiLlf80U.csHigh entropy of concatenated method names: 'gL4JBGQdeX', 'R05JiQnybj', 'epVJU2fPqA', 'vXqJluHQDV', 'NkDJSsqlOg', 'd2CJrqNT3D', 'V1KJwVoD7G', 'afPJnv26BT', 'VNIJoVsTL6', 'VUjJtLCbCk'
            Source: 0.2.SecuriteInfo.com.Win32.PWSX-gen.11507.25552.exe.80f0000.6.raw.unpack, cCLoqJ7YkfCEP9MMOQ.csHigh entropy of concatenated method names: 'xhONnwXNeo', 'jpqNt0U7dJ', 'VsskHRIMQe', 'bFVkPAoYmD', 'TIwNGxhDDO', 'smjN9wFh0o', 'hB9Np7brhq', 'PrjNBTBDTe', 'HZUNipfkiH', 'DrDNUVKe5A'
            Source: 0.2.SecuriteInfo.com.Win32.PWSX-gen.11507.25552.exe.80f0000.6.raw.unpack, tgGZHBOV9nFhhTRwIc.csHigh entropy of concatenated method names: 'Uw8qFUY67l', 'G7Wqc4Bb6s', 'QEjqAGWY13', 'u53AtFcWVF', 'DFQAzWolyr', 'OFjqHgK0rc', 'NkRqPIlfSD', 'KpBq1RGiJ8', 'cdVqsW8Sw2', 'Ri3qbrV98y'
            Source: 0.2.SecuriteInfo.com.Win32.PWSX-gen.11507.25552.exe.80f0000.6.raw.unpack, Q5Q2hfi5LFO329wM8R6.csHigh entropy of concatenated method names: 'CanConvertFrom', 'ConvertFrom', 'ConvertTo', 'yuIMme7rfR', 'nhqMLPMMdq', 'quwMKvFqjr', 'pGcMMW2q9o', 'b6rMalhdh4', 'VOeMImHDwp', 'PbbME6p80T'
            Source: 0.2.SecuriteInfo.com.Win32.PWSX-gen.11507.25552.exe.80f0000.6.raw.unpack, qUW6xDxD2VwbSxqimb.csHigh entropy of concatenated method names: 'UfYcC5V0qk', 'gQucOApUI5', 'QBNcj137iU', 'nr0c0C2mvD', 'E0dc5bPV02', 'th1cgATfGA', 'EphcNRTCjZ', 'qVXckIjGdo', 'NU3cmZU7NY', 'gAncL1uFrC'
            Source: 0.2.SecuriteInfo.com.Win32.PWSX-gen.11507.25552.exe.80f0000.6.raw.unpack, B93CZ0Earl2Zpo7DQu.csHigh entropy of concatenated method names: 'z6iZjQ7WiM', 'K8VZ0avgAN', 'ORkZ2RKjeV', 'UKrZ8Y5taC', 'sZHZ7Daa4c', 'G9PZTkiV7b', 'H7MZu0qWfr', 'PlPZW983op', 'scrZXgAetA', 'TJiZGRU4wg'
            Source: 0.2.SecuriteInfo.com.Win32.PWSX-gen.11507.25552.exe.80f0000.6.raw.unpack, lZn8bss17FVr3RD4bf.csHigh entropy of concatenated method names: 'MHCDQBehq', 'eSfC3gYTX', 'pPVOGQUAn', 'kY4YQJmtE', 'ysu01YNvs', 'MkcRdTgyn', 'FWuOdYjAS6JXGrW7M1', 'DdAm43K2ScpCawmSxt', 'e6YkiTj7h', 'PaHLRFS5w'
            Source: 0.2.SecuriteInfo.com.Win32.PWSX-gen.11507.25552.exe.80f0000.6.raw.unpack, v9DMC6ieQHx20TLUFIB.csHigh entropy of concatenated method names: 'CanConvertFrom', 'ConvertFrom', 'ConvertTo', 'Aj8LGQCSLf', 'iKPL9ThmRG', 'AXVLp0Ra5d', 'L4YLBZuXhD', 'gyoLiKCoWK', 'kuhLUxG5ID', 'atrLl5Fhln'
            Source: 0.2.SecuriteInfo.com.Win32.PWSX-gen.11507.25552.exe.80f0000.6.raw.unpack, bm5U0d5w4MyAnlKagk.csHigh entropy of concatenated method names: 'KfnPqCS5T4', 'W4QPyfl7hs', 'N36P4gFnei', 'Sc6PQwZ38D', 'yfIP51qPUG', 'hX0PgTHYBE', 'JqiEvT9RO3Ua6FOiyO', 'cCcREtdEeoGosDdutC', 'SqZPPIR1oH', 'UtTPspmuSa'
            Source: 0.2.SecuriteInfo.com.Win32.PWSX-gen.11507.25552.exe.80f0000.6.raw.unpack, ToZCwDhT8sIeVS30Em.csHigh entropy of concatenated method names: 'DTbm5FjODL', 'nFCmNjCA6e', 'wLOmmHKKuT', 'TWxmKTEYuX', 'sKYmaD4bZc', 'mIamE9xWcW', 'Dispose', 'Xd8kFfFbkV', 'oUlkJjW1xr', 'Ovrkc65UFJ'
            Source: 0.2.SecuriteInfo.com.Win32.PWSX-gen.11507.25552.exe.80f0000.6.raw.unpack, oNNe91VutBA3npVvlB.csHigh entropy of concatenated method names: 'ssaN4wBq54', 'RskNQVcqwB', 'ToString', 'mvTNF1P1x8', 'XbuNJLiLGc', 'oAuNcu9Bi6', 'o7VNeDW6ig', 'ITgNAPXlU6', 'JKyNqjoaUq', 'mJENyK0VUU'
            Source: 0.2.SecuriteInfo.com.Win32.PWSX-gen.11507.25552.exe.80f0000.6.raw.unpack, ek0KX6o6NsvPVawYRn.csHigh entropy of concatenated method names: 'bQvLc0trlo', 'ej1Le9tcj2', 'WYHLACqhZ4', 'WcQLqrcs9u', 'R1hLmoDJoJ', 'a8YLyufUgt', 'Next', 'Next', 'Next', 'NextBytes'
            Source: 0.2.SecuriteInfo.com.Win32.PWSX-gen.11507.25552.exe.80f0000.6.raw.unpack, V9RuHENpEU8MoobCZI.csHigh entropy of concatenated method names: 't12exU1peu', 'xdQeY4Cj7G', 'KglchDitnA', 'LF0c7XouwJ', 'Q4pcTnfYwZ', 'PVacV96Kk2', 'sT5cuyOM7x', 'EDTcW2Hd9h', 'SNQcd2Z1Ji', 'lkgcXi7jbB'
            Source: 0.2.SecuriteInfo.com.Win32.PWSX-gen.11507.25552.exe.80f0000.6.raw.unpack, Dm91nCfIUrYMpG6Ldo.csHigh entropy of concatenated method names: 'Dispose', 'oy7PoNOuGI', 'EkB18bO7lH', 'TtFMSvurOT', 'mjuPtKigT2', 'vsnPzVYGse', 'ProcessDialogKey', 'rHc1HupGXf', 'Th71P5gpip', 'I9i114BknS'
            Source: 0.2.SecuriteInfo.com.Win32.PWSX-gen.11507.25552.exe.80f0000.6.raw.unpack, NMpHpNLZqcWxUsIIoP.csHigh entropy of concatenated method names: 'fCwm2wA5bY', 'KZxm8BFt2X', 'QlImhWrUhw', 'uIem7IwaHL', 'aYlmTyiWps', 'HnKmVVZ6SJ', 'Xtwmujmicx', 'On1mW0UgfQ', 'FxOmdQet7D', 'ENLmX0asMV'
            Source: 0.2.SecuriteInfo.com.Win32.PWSX-gen.11507.25552.exe.43b2398.2.raw.unpack, dtZUlxbglGTJkDrYwK.csHigh entropy of concatenated method names: 'pBTqvktk12', 'q7aq3kj0F2', 'oD7qDbNjLI', 'VORqCWM2Hs', 'gsiqxR6uxd', 'R2jqOb9tiY', 'chWqYHfvKY', 'm7GqjVZbj2', 'Tfyq0CWvK2', 'lFQqROrjGr'
            Source: 0.2.SecuriteInfo.com.Win32.PWSX-gen.11507.25552.exe.43b2398.2.raw.unpack, F7Jm8DzpfMncLRy9dQ.csHigh entropy of concatenated method names: 'UooLOAQuTl', 'vWILjv8AVX', 'yUqL005Kt2', 'KRgL29L0M6', 'alQL8JeaTc', 'JAmL7OxMdZ', 'avpLTXCj2A', 'p70LEhEdnY', 'oAELvanZI9', 'unxL3LDOTL'
            Source: 0.2.SecuriteInfo.com.Win32.PWSX-gen.11507.25552.exe.43b2398.2.raw.unpack, KDuqUAUiU7aAlaOKKq.csHigh entropy of concatenated method names: 'EditValue', 'GetEditStyle', 'fk11oiUyhD', 'MsL1tkt8jK', 'mUL1zTfwvs', 'KdQsHRHJGs', 'k30sP2lc3R', 'pYAs1OZu1w', 'wd3ssq7ROq', 'YQH6LjqBle2LvwEAMat'
            Source: 0.2.SecuriteInfo.com.Win32.PWSX-gen.11507.25552.exe.43b2398.2.raw.unpack, VtKlMWkUt5LJIYHW47.csHigh entropy of concatenated method names: 'lCUs6bV1cm', 'tNHsFmpUxD', 'JoBsJXaZmw', 'E78scHeZDP', 'XfBsebLrI5', 'YLysAretyv', 'pZxsqDGXTF', 'cPxsy8nXfw', 'Px0sf0qrNu', 'G6hs4gIUFW'
            Source: 0.2.SecuriteInfo.com.Win32.PWSX-gen.11507.25552.exe.43b2398.2.raw.unpack, trCZ0OiilwKLPgXtyD6.csHigh entropy of concatenated method names: 'XcTLtoFwlU', 'lR9LzBRSvi', 'iBhKHdEa03', 'JtLKPs6tP1', 'k1cK1HaJ6F', 'e9CKsr0X3Q', 'wDBKbgPQIY', 'kZaK6ppFGd', 'aY0KF0qI48', 'ogfKJOYeq5'
            Source: 0.2.SecuriteInfo.com.Win32.PWSX-gen.11507.25552.exe.43b2398.2.raw.unpack, OFedRUp96REPNdOkD2.csHigh entropy of concatenated method names: 'zIV5XHdWPS', 't2259fZyFt', 'LDy5BR703r', 'wCT5ihWp87', 'F2658pfayT', 'raw5hQRT69', 'j3C57f49C6', 'faG5TVZoha', 'iA95VmB5E9', 'HeF5uUhbv6'
            Source: 0.2.SecuriteInfo.com.Win32.PWSX-gen.11507.25552.exe.43b2398.2.raw.unpack, vkqgZNj9l4Ra9u1s7J.csHigh entropy of concatenated method names: 'hLtA6EBL4y', 'N1pAJB5C0I', 'RqSAe7eIcK', 'HaKAqPHaWp', 'j6ZAyDUK8b', 'FiMeSw6FM7', 'NyKerEL10n', 'gg1ew60Ag1', 'lLgenT4FFW', 'nkveoWs17c'
            Source: 0.2.SecuriteInfo.com.Win32.PWSX-gen.11507.25552.exe.43b2398.2.raw.unpack, X8tf2NTPiRMiLlf80U.csHigh entropy of concatenated method names: 'gL4JBGQdeX', 'R05JiQnybj', 'epVJU2fPqA', 'vXqJluHQDV', 'NkDJSsqlOg', 'd2CJrqNT3D', 'V1KJwVoD7G', 'afPJnv26BT', 'VNIJoVsTL6', 'VUjJtLCbCk'
            Source: 0.2.SecuriteInfo.com.Win32.PWSX-gen.11507.25552.exe.43b2398.2.raw.unpack, cCLoqJ7YkfCEP9MMOQ.csHigh entropy of concatenated method names: 'xhONnwXNeo', 'jpqNt0U7dJ', 'VsskHRIMQe', 'bFVkPAoYmD', 'TIwNGxhDDO', 'smjN9wFh0o', 'hB9Np7brhq', 'PrjNBTBDTe', 'HZUNipfkiH', 'DrDNUVKe5A'
            Source: 0.2.SecuriteInfo.com.Win32.PWSX-gen.11507.25552.exe.43b2398.2.raw.unpack, tgGZHBOV9nFhhTRwIc.csHigh entropy of concatenated method names: 'Uw8qFUY67l', 'G7Wqc4Bb6s', 'QEjqAGWY13', 'u53AtFcWVF', 'DFQAzWolyr', 'OFjqHgK0rc', 'NkRqPIlfSD', 'KpBq1RGiJ8', 'cdVqsW8Sw2', 'Ri3qbrV98y'
            Source: 0.2.SecuriteInfo.com.Win32.PWSX-gen.11507.25552.exe.43b2398.2.raw.unpack, Q5Q2hfi5LFO329wM8R6.csHigh entropy of concatenated method names: 'CanConvertFrom', 'ConvertFrom', 'ConvertTo', 'yuIMme7rfR', 'nhqMLPMMdq', 'quwMKvFqjr', 'pGcMMW2q9o', 'b6rMalhdh4', 'VOeMImHDwp', 'PbbME6p80T'
            Source: 0.2.SecuriteInfo.com.Win32.PWSX-gen.11507.25552.exe.43b2398.2.raw.unpack, qUW6xDxD2VwbSxqimb.csHigh entropy of concatenated method names: 'UfYcC5V0qk', 'gQucOApUI5', 'QBNcj137iU', 'nr0c0C2mvD', 'E0dc5bPV02', 'th1cgATfGA', 'EphcNRTCjZ', 'qVXckIjGdo', 'NU3cmZU7NY', 'gAncL1uFrC'
            Source: 0.2.SecuriteInfo.com.Win32.PWSX-gen.11507.25552.exe.43b2398.2.raw.unpack, B93CZ0Earl2Zpo7DQu.csHigh entropy of concatenated method names: 'z6iZjQ7WiM', 'K8VZ0avgAN', 'ORkZ2RKjeV', 'UKrZ8Y5taC', 'sZHZ7Daa4c', 'G9PZTkiV7b', 'H7MZu0qWfr', 'PlPZW983op', 'scrZXgAetA', 'TJiZGRU4wg'
            Source: 0.2.SecuriteInfo.com.Win32.PWSX-gen.11507.25552.exe.43b2398.2.raw.unpack, lZn8bss17FVr3RD4bf.csHigh entropy of concatenated method names: 'MHCDQBehq', 'eSfC3gYTX', 'pPVOGQUAn', 'kY4YQJmtE', 'ysu01YNvs', 'MkcRdTgyn', 'FWuOdYjAS6JXGrW7M1', 'DdAm43K2ScpCawmSxt', 'e6YkiTj7h', 'PaHLRFS5w'
            Source: 0.2.SecuriteInfo.com.Win32.PWSX-gen.11507.25552.exe.43b2398.2.raw.unpack, v9DMC6ieQHx20TLUFIB.csHigh entropy of concatenated method names: 'CanConvertFrom', 'ConvertFrom', 'ConvertTo', 'Aj8LGQCSLf', 'iKPL9ThmRG', 'AXVLp0Ra5d', 'L4YLBZuXhD', 'gyoLiKCoWK', 'kuhLUxG5ID', 'atrLl5Fhln'
            Source: 0.2.SecuriteInfo.com.Win32.PWSX-gen.11507.25552.exe.43b2398.2.raw.unpack, bm5U0d5w4MyAnlKagk.csHigh entropy of concatenated method names: 'KfnPqCS5T4', 'W4QPyfl7hs', 'N36P4gFnei', 'Sc6PQwZ38D', 'yfIP51qPUG', 'hX0PgTHYBE', 'JqiEvT9RO3Ua6FOiyO', 'cCcREtdEeoGosDdutC', 'SqZPPIR1oH', 'UtTPspmuSa'
            Source: 0.2.SecuriteInfo.com.Win32.PWSX-gen.11507.25552.exe.43b2398.2.raw.unpack, ToZCwDhT8sIeVS30Em.csHigh entropy of concatenated method names: 'DTbm5FjODL', 'nFCmNjCA6e', 'wLOmmHKKuT', 'TWxmKTEYuX', 'sKYmaD4bZc', 'mIamE9xWcW', 'Dispose', 'Xd8kFfFbkV', 'oUlkJjW1xr', 'Ovrkc65UFJ'
            Source: 0.2.SecuriteInfo.com.Win32.PWSX-gen.11507.25552.exe.43b2398.2.raw.unpack, oNNe91VutBA3npVvlB.csHigh entropy of concatenated method names: 'ssaN4wBq54', 'RskNQVcqwB', 'ToString', 'mvTNF1P1x8', 'XbuNJLiLGc', 'oAuNcu9Bi6', 'o7VNeDW6ig', 'ITgNAPXlU6', 'JKyNqjoaUq', 'mJENyK0VUU'
            Source: 0.2.SecuriteInfo.com.Win32.PWSX-gen.11507.25552.exe.43b2398.2.raw.unpack, ek0KX6o6NsvPVawYRn.csHigh entropy of concatenated method names: 'bQvLc0trlo', 'ej1Le9tcj2', 'WYHLACqhZ4', 'WcQLqrcs9u', 'R1hLmoDJoJ', 'a8YLyufUgt', 'Next', 'Next', 'Next', 'NextBytes'
            Source: 0.2.SecuriteInfo.com.Win32.PWSX-gen.11507.25552.exe.43b2398.2.raw.unpack, V9RuHENpEU8MoobCZI.csHigh entropy of concatenated method names: 't12exU1peu', 'xdQeY4Cj7G', 'KglchDitnA', 'LF0c7XouwJ', 'Q4pcTnfYwZ', 'PVacV96Kk2', 'sT5cuyOM7x', 'EDTcW2Hd9h', 'SNQcd2Z1Ji', 'lkgcXi7jbB'
            Source: 0.2.SecuriteInfo.com.Win32.PWSX-gen.11507.25552.exe.43b2398.2.raw.unpack, Dm91nCfIUrYMpG6Ldo.csHigh entropy of concatenated method names: 'Dispose', 'oy7PoNOuGI', 'EkB18bO7lH', 'TtFMSvurOT', 'mjuPtKigT2', 'vsnPzVYGse', 'ProcessDialogKey', 'rHc1HupGXf', 'Th71P5gpip', 'I9i114BknS'
            Source: 0.2.SecuriteInfo.com.Win32.PWSX-gen.11507.25552.exe.43b2398.2.raw.unpack, NMpHpNLZqcWxUsIIoP.csHigh entropy of concatenated method names: 'fCwm2wA5bY', 'KZxm8BFt2X', 'QlImhWrUhw', 'uIem7IwaHL', 'aYlmTyiWps', 'HnKmVVZ6SJ', 'Xtwmujmicx', 'On1mW0UgfQ', 'FxOmdQet7D', 'ENLmX0asMV'
            Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.PWSX-gen.11507.25552.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
            Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.PWSX-gen.11507.25552.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
            Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.PWSX-gen.11507.25552.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
            Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.PWSX-gen.11507.25552.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
            Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.PWSX-gen.11507.25552.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
            Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.PWSX-gen.11507.25552.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
            Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.PWSX-gen.11507.25552.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
            Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.PWSX-gen.11507.25552.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
            Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.PWSX-gen.11507.25552.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
            Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.PWSX-gen.11507.25552.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
            Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.PWSX-gen.11507.25552.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
            Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.PWSX-gen.11507.25552.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
            Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.PWSX-gen.11507.25552.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
            Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.PWSX-gen.11507.25552.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
            Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.PWSX-gen.11507.25552.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
            Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.PWSX-gen.11507.25552.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
            Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.PWSX-gen.11507.25552.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
            Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.PWSX-gen.11507.25552.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
            Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.PWSX-gen.11507.25552.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
            Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.PWSX-gen.11507.25552.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
            Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.PWSX-gen.11507.25552.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
            Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.PWSX-gen.11507.25552.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
            Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.PWSX-gen.11507.25552.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
            Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.PWSX-gen.11507.25552.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
            Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.PWSX-gen.11507.25552.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
            Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.PWSX-gen.11507.25552.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
            Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.PWSX-gen.11507.25552.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
            Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.PWSX-gen.11507.25552.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
            Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.PWSX-gen.11507.25552.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
            Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.PWSX-gen.11507.25552.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
            Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.PWSX-gen.11507.25552.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
            Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.PWSX-gen.11507.25552.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
            Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.PWSX-gen.11507.25552.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
            Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.PWSX-gen.11507.25552.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
            Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.PWSX-gen.11507.25552.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
            Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.PWSX-gen.11507.25552.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
            Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.PWSX-gen.11507.25552.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
            Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.PWSX-gen.11507.25552.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
            Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.PWSX-gen.11507.25552.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
            Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.PWSX-gen.11507.25552.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
            Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.PWSX-gen.11507.25552.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
            Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.PWSX-gen.11507.25552.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
            Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.PWSX-gen.11507.25552.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
            Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.PWSX-gen.11507.25552.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
            Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.PWSX-gen.11507.25552.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
            Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.PWSX-gen.11507.25552.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
            Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.PWSX-gen.11507.25552.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
            Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.PWSX-gen.11507.25552.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
            Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.PWSX-gen.11507.25552.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
            Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.PWSX-gen.11507.25552.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
            Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.PWSX-gen.11507.25552.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
            Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.PWSX-gen.11507.25552.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
            Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.PWSX-gen.11507.25552.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
            Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.PWSX-gen.11507.25552.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
            Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.PWSX-gen.11507.25552.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
            Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.PWSX-gen.11507.25552.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
            Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.PWSX-gen.11507.25552.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
            Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.PWSX-gen.11507.25552.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
            Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.PWSX-gen.11507.25552.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
            Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.PWSX-gen.11507.25552.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
            Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.PWSX-gen.11507.25552.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
            Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.PWSX-gen.11507.25552.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
            Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.PWSX-gen.11507.25552.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
            Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.PWSX-gen.11507.25552.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
            Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.PWSX-gen.11507.25552.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
            Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.PWSX-gen.11507.25552.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
            Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.PWSX-gen.11507.25552.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
            Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.PWSX-gen.11507.25552.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
            Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.PWSX-gen.11507.25552.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
            Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.PWSX-gen.11507.25552.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
            Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.PWSX-gen.11507.25552.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
            Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.PWSX-gen.11507.25552.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
            Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.PWSX-gen.11507.25552.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
            Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.PWSX-gen.11507.25552.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
            Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.PWSX-gen.11507.25552.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
            Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.PWSX-gen.11507.25552.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
            Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.PWSX-gen.11507.25552.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
            Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.PWSX-gen.11507.25552.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
            Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.PWSX-gen.11507.25552.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
            Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.PWSX-gen.11507.25552.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
            Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.PWSX-gen.11507.25552.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
            Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.PWSX-gen.11507.25552.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
            Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.PWSX-gen.11507.25552.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
            Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.PWSX-gen.11507.25552.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
            Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.PWSX-gen.11507.25552.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
            Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.PWSX-gen.11507.25552.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
            Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.PWSX-gen.11507.25552.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
            Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.PWSX-gen.11507.25552.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
            Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.PWSX-gen.11507.25552.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
            Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.PWSX-gen.11507.25552.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
            Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.PWSX-gen.11507.25552.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
            Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.PWSX-gen.11507.25552.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
            Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.PWSX-gen.11507.25552.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
            Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.PWSX-gen.11507.25552.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
            Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.PWSX-gen.11507.25552.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
            Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.PWSX-gen.11507.25552.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
            Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.PWSX-gen.11507.25552.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
            Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.PWSX-gen.11507.25552.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
            Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.PWSX-gen.11507.25552.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
            Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.PWSX-gen.11507.25552.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
            Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.PWSX-gen.11507.25552.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
            Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.PWSX-gen.11507.25552.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
            Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.PWSX-gen.11507.25552.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
            Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.PWSX-gen.11507.25552.exeProcess information set: NOOPENFILEERRORBOXJump to behavior

            Malware Analysis System Evasion

            barindex
            Source: Yara matchFile source: Process Memory Space: SecuriteInfo.com.Win32.PWSX-gen.11507.25552.exe PID: 6516, type: MEMORYSTR
            Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.PWSX-gen.11507.25552.exeMemory allocated: 1670000 memory reserve | memory write watchJump to behavior
            Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.PWSX-gen.11507.25552.exeMemory allocated: 3270000 memory reserve | memory write watchJump to behavior
            Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.PWSX-gen.11507.25552.exeMemory allocated: 1790000 memory reserve | memory write watchJump to behavior
            Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.PWSX-gen.11507.25552.exeMemory allocated: 99F0000 memory reserve | memory write watchJump to behavior
            Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.PWSX-gen.11507.25552.exeMemory allocated: 8560000 memory reserve | memory write watchJump to behavior
            Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.PWSX-gen.11507.25552.exeMemory allocated: A9F0000 memory reserve | memory write watchJump to behavior
            Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.PWSX-gen.11507.25552.exeMemory allocated: B9F0000 memory reserve | memory write watchJump to behavior
            Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.PWSX-gen.11507.25552.exeMemory allocated: 2F00000 memory reserve | memory write watchJump to behavior
            Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.PWSX-gen.11507.25552.exeMemory allocated: 3120000 memory reserve | memory write watchJump to behavior
            Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.PWSX-gen.11507.25552.exeMemory allocated: 2F70000 memory reserve | memory write watchJump to behavior
            Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.PWSX-gen.11507.25552.exeThread delayed: delay time: 922337203685477Jump to behavior
            Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.PWSX-gen.11507.25552.exeThread delayed: delay time: 922337203685477Jump to behavior
            Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.PWSX-gen.11507.25552.exeThread delayed: delay time: 600000Jump to behavior
            Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.PWSX-gen.11507.25552.exeThread delayed: delay time: 599875Jump to behavior
            Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.PWSX-gen.11507.25552.exeThread delayed: delay time: 599695Jump to behavior
            Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.PWSX-gen.11507.25552.exeThread delayed: delay time: 599561Jump to behavior
            Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.PWSX-gen.11507.25552.exeThread delayed: delay time: 599453Jump to behavior
            Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.PWSX-gen.11507.25552.exeThread delayed: delay time: 599344Jump to behavior
            Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.PWSX-gen.11507.25552.exeThread delayed: delay time: 599219Jump to behavior
            Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.PWSX-gen.11507.25552.exeThread delayed: delay time: 599109Jump to behavior
            Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.PWSX-gen.11507.25552.exeThread delayed: delay time: 599000Jump to behavior
            Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.PWSX-gen.11507.25552.exeThread delayed: delay time: 598890Jump to behavior
            Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.PWSX-gen.11507.25552.exeThread delayed: delay time: 598781Jump to behavior
            Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.PWSX-gen.11507.25552.exeThread delayed: delay time: 598672Jump to behavior
            Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.PWSX-gen.11507.25552.exeThread delayed: delay time: 598562Jump to behavior
            Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.PWSX-gen.11507.25552.exeThread delayed: delay time: 598453Jump to behavior
            Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.PWSX-gen.11507.25552.exeThread delayed: delay time: 598344Jump to behavior
            Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.PWSX-gen.11507.25552.exeThread delayed: delay time: 598234Jump to behavior
            Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.PWSX-gen.11507.25552.exeThread delayed: delay time: 598125Jump to behavior
            Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.PWSX-gen.11507.25552.exeThread delayed: delay time: 598015Jump to behavior
            Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.PWSX-gen.11507.25552.exeThread delayed: delay time: 597906Jump to behavior
            Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.PWSX-gen.11507.25552.exeThread delayed: delay time: 597795Jump to behavior
            Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.PWSX-gen.11507.25552.exeThread delayed: delay time: 597686Jump to behavior
            Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.PWSX-gen.11507.25552.exeThread delayed: delay time: 597578Jump to behavior
            Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.PWSX-gen.11507.25552.exeThread delayed: delay time: 597469Jump to behavior
            Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.PWSX-gen.11507.25552.exeThread delayed: delay time: 597356Jump to behavior
            Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.PWSX-gen.11507.25552.exeThread delayed: delay time: 597250Jump to behavior
            Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.PWSX-gen.11507.25552.exeThread delayed: delay time: 597140Jump to behavior
            Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.PWSX-gen.11507.25552.exeThread delayed: delay time: 597031Jump to behavior
            Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.PWSX-gen.11507.25552.exeThread delayed: delay time: 596922Jump to behavior
            Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.PWSX-gen.11507.25552.exeThread delayed: delay time: 596812Jump to behavior
            Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.PWSX-gen.11507.25552.exeThread delayed: delay time: 596703Jump to behavior
            Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.PWSX-gen.11507.25552.exeThread delayed: delay time: 596593Jump to behavior
            Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.PWSX-gen.11507.25552.exeThread delayed: delay time: 596484Jump to behavior
            Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.PWSX-gen.11507.25552.exeThread delayed: delay time: 596375Jump to behavior
            Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.PWSX-gen.11507.25552.exeThread delayed: delay time: 596266Jump to behavior
            Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.PWSX-gen.11507.25552.exeThread delayed: delay time: 596141Jump to behavior
            Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.PWSX-gen.11507.25552.exeThread delayed: delay time: 596016Jump to behavior
            Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.PWSX-gen.11507.25552.exeThread delayed: delay time: 595906Jump to behavior
            Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.PWSX-gen.11507.25552.exeThread delayed: delay time: 595797Jump to behavior
            Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.PWSX-gen.11507.25552.exeThread delayed: delay time: 595687Jump to behavior
            Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.PWSX-gen.11507.25552.exeThread delayed: delay time: 595578Jump to behavior
            Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.PWSX-gen.11507.25552.exeThread delayed: delay time: 595469Jump to behavior
            Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.PWSX-gen.11507.25552.exeThread delayed: delay time: 595359Jump to behavior
            Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.PWSX-gen.11507.25552.exeThread delayed: delay time: 595246Jump to behavior
            Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.PWSX-gen.11507.25552.exeThread delayed: delay time: 595139Jump to behavior
            Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.PWSX-gen.11507.25552.exeThread delayed: delay time: 595027Jump to behavior
            Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.PWSX-gen.11507.25552.exeThread delayed: delay time: 594743Jump to behavior
            Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.PWSX-gen.11507.25552.exeThread delayed: delay time: 594542Jump to behavior
            Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.PWSX-gen.11507.25552.exeThread delayed: delay time: 594437Jump to behavior
            Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.PWSX-gen.11507.25552.exeThread delayed: delay time: 594328Jump to behavior
            Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.PWSX-gen.11507.25552.exeThread delayed: delay time: 594219Jump to behavior
            Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.PWSX-gen.11507.25552.exeThread delayed: delay time: 594094Jump to behavior
            Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.PWSX-gen.11507.25552.exeWindow / User API: threadDelayed 1558Jump to behavior
            Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.PWSX-gen.11507.25552.exeWindow / User API: threadDelayed 8283Jump to behavior
            Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.PWSX-gen.11507.25552.exe TID: 6584Thread sleep time: -30000s >= -30000sJump to behavior
            Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.PWSX-gen.11507.25552.exe TID: 6500Thread sleep time: -922337203685477s >= -30000sJump to behavior
            Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.PWSX-gen.11507.25552.exe TID: 6960Thread sleep count: 39 > 30Jump to behavior
            Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.PWSX-gen.11507.25552.exe TID: 6960Thread sleep time: -35971150943733603s >= -30000sJump to behavior
            Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.PWSX-gen.11507.25552.exe TID: 6960Thread sleep time: -600000s >= -30000sJump to behavior
            Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.PWSX-gen.11507.25552.exe TID: 6956Thread sleep count: 1558 > 30Jump to behavior
            Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.PWSX-gen.11507.25552.exe TID: 6960Thread sleep time: -599875s >= -30000sJump to behavior
            Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.PWSX-gen.11507.25552.exe TID: 6956Thread sleep count: 8283 > 30Jump to behavior
            Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.PWSX-gen.11507.25552.exe TID: 6960Thread sleep time: -599695s >= -30000sJump to behavior
            Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.PWSX-gen.11507.25552.exe TID: 6960Thread sleep time: -599561s >= -30000sJump to behavior
            Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.PWSX-gen.11507.25552.exe TID: 6960Thread sleep time: -599453s >= -30000sJump to behavior
            Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.PWSX-gen.11507.25552.exe TID: 6960Thread sleep time: -599344s >= -30000sJump to behavior
            Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.PWSX-gen.11507.25552.exe TID: 6960Thread sleep time: -599219s >= -30000sJump to behavior
            Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.PWSX-gen.11507.25552.exe TID: 6960Thread sleep time: -599109s >= -30000sJump to behavior
            Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.PWSX-gen.11507.25552.exe TID: 6960Thread sleep time: -599000s >= -30000sJump to behavior
            Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.PWSX-gen.11507.25552.exe TID: 6960Thread sleep time: -598890s >= -30000sJump to behavior
            Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.PWSX-gen.11507.25552.exe TID: 6960Thread sleep time: -598781s >= -30000sJump to behavior
            Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.PWSX-gen.11507.25552.exe TID: 6960Thread sleep time: -598672s >= -30000sJump to behavior
            Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.PWSX-gen.11507.25552.exe TID: 6960Thread sleep time: -598562s >= -30000sJump to behavior
            Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.PWSX-gen.11507.25552.exe TID: 6960Thread sleep time: -598453s >= -30000sJump to behavior
            Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.PWSX-gen.11507.25552.exe TID: 6960Thread sleep time: -598344s >= -30000sJump to behavior
            Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.PWSX-gen.11507.25552.exe TID: 6960Thread sleep time: -598234s >= -30000sJump to behavior
            Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.PWSX-gen.11507.25552.exe TID: 6960Thread sleep time: -598125s >= -30000sJump to behavior
            Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.PWSX-gen.11507.25552.exe TID: 6960Thread sleep time: -598015s >= -30000sJump to behavior
            Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.PWSX-gen.11507.25552.exe TID: 6960Thread sleep time: -597906s >= -30000sJump to behavior
            Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.PWSX-gen.11507.25552.exe TID: 6960Thread sleep time: -597795s >= -30000sJump to behavior
            Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.PWSX-gen.11507.25552.exe TID: 6960Thread sleep time: -597686s >= -30000sJump to behavior
            Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.PWSX-gen.11507.25552.exe TID: 6960Thread sleep time: -597578s >= -30000sJump to behavior
            Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.PWSX-gen.11507.25552.exe TID: 6960Thread sleep time: -597469s >= -30000sJump to behavior
            Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.PWSX-gen.11507.25552.exe TID: 6960Thread sleep time: -597356s >= -30000sJump to behavior
            Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.PWSX-gen.11507.25552.exe TID: 6960Thread sleep time: -597250s >= -30000sJump to behavior
            Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.PWSX-gen.11507.25552.exe TID: 6960Thread sleep time: -597140s >= -30000sJump to behavior
            Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.PWSX-gen.11507.25552.exe TID: 6960Thread sleep time: -597031s >= -30000sJump to behavior
            Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.PWSX-gen.11507.25552.exe TID: 6960Thread sleep time: -596922s >= -30000sJump to behavior
            Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.PWSX-gen.11507.25552.exe TID: 6960Thread sleep time: -596812s >= -30000sJump to behavior
            Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.PWSX-gen.11507.25552.exe TID: 6960Thread sleep time: -596703s >= -30000sJump to behavior
            Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.PWSX-gen.11507.25552.exe TID: 6960Thread sleep time: -596593s >= -30000sJump to behavior
            Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.PWSX-gen.11507.25552.exe TID: 6960Thread sleep time: -596484s >= -30000sJump to behavior
            Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.PWSX-gen.11507.25552.exe TID: 6960Thread sleep time: -596375s >= -30000sJump to behavior
            Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.PWSX-gen.11507.25552.exe TID: 6960Thread sleep time: -596266s >= -30000sJump to behavior
            Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.PWSX-gen.11507.25552.exe TID: 6960Thread sleep time: -596141s >= -30000sJump to behavior
            Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.PWSX-gen.11507.25552.exe TID: 6960Thread sleep time: -596016s >= -30000sJump to behavior
            Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.PWSX-gen.11507.25552.exe TID: 6960Thread sleep time: -595906s >= -30000sJump to behavior
            Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.PWSX-gen.11507.25552.exe TID: 6960Thread sleep time: -595797s >= -30000sJump to behavior
            Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.PWSX-gen.11507.25552.exe TID: 6960Thread sleep time: -595687s >= -30000sJump to behavior
            Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.PWSX-gen.11507.25552.exe TID: 6960Thread sleep time: -595578s >= -30000sJump to behavior
            Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.PWSX-gen.11507.25552.exe TID: 6960Thread sleep time: -595469s >= -30000sJump to behavior
            Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.PWSX-gen.11507.25552.exe TID: 6960Thread sleep time: -595359s >= -30000sJump to behavior
            Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.PWSX-gen.11507.25552.exe TID: 6960Thread sleep time: -595246s >= -30000sJump to behavior
            Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.PWSX-gen.11507.25552.exe TID: 6960Thread sleep time: -595139s >= -30000sJump to behavior
            Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.PWSX-gen.11507.25552.exe TID: 6960Thread sleep time: -595027s >= -30000sJump to behavior
            Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.PWSX-gen.11507.25552.exe TID: 6960Thread sleep time: -594743s >= -30000sJump to behavior
            Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.PWSX-gen.11507.25552.exe TID: 6960Thread sleep time: -594542s >= -30000sJump to behavior
            Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.PWSX-gen.11507.25552.exe TID: 6960Thread sleep time: -594437s >= -30000sJump to behavior
            Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.PWSX-gen.11507.25552.exe TID: 6960Thread sleep time: -594328s >= -30000sJump to behavior
            Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.PWSX-gen.11507.25552.exe TID: 6960Thread sleep time: -594219s >= -30000sJump to behavior
            Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.PWSX-gen.11507.25552.exe TID: 6960Thread sleep time: -594094s >= -30000sJump to behavior
            Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.PWSX-gen.11507.25552.exeThread delayed: delay time: 30000Jump to behavior
            Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.PWSX-gen.11507.25552.exeThread delayed: delay time: 922337203685477Jump to behavior
            Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.PWSX-gen.11507.25552.exeThread delayed: delay time: 922337203685477Jump to behavior
            Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.PWSX-gen.11507.25552.exeThread delayed: delay time: 600000Jump to behavior
            Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.PWSX-gen.11507.25552.exeThread delayed: delay time: 599875Jump to behavior
            Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.PWSX-gen.11507.25552.exeThread delayed: delay time: 599695Jump to behavior
            Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.PWSX-gen.11507.25552.exeThread delayed: delay time: 599561Jump to behavior
            Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.PWSX-gen.11507.25552.exeThread delayed: delay time: 599453Jump to behavior
            Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.PWSX-gen.11507.25552.exeThread delayed: delay time: 599344Jump to behavior
            Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.PWSX-gen.11507.25552.exeThread delayed: delay time: 599219Jump to behavior
            Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.PWSX-gen.11507.25552.exeThread delayed: delay time: 599109Jump to behavior
            Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.PWSX-gen.11507.25552.exeThread delayed: delay time: 599000Jump to behavior
            Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.PWSX-gen.11507.25552.exeThread delayed: delay time: 598890Jump to behavior
            Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.PWSX-gen.11507.25552.exeThread delayed: delay time: 598781Jump to behavior
            Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.PWSX-gen.11507.25552.exeThread delayed: delay time: 598672Jump to behavior
            Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.PWSX-gen.11507.25552.exeThread delayed: delay time: 598562Jump to behavior
            Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.PWSX-gen.11507.25552.exeThread delayed: delay time: 598453Jump to behavior
            Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.PWSX-gen.11507.25552.exeThread delayed: delay time: 598344Jump to behavior
            Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.PWSX-gen.11507.25552.exeThread delayed: delay time: 598234Jump to behavior
            Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.PWSX-gen.11507.25552.exeThread delayed: delay time: 598125Jump to behavior
            Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.PWSX-gen.11507.25552.exeThread delayed: delay time: 598015Jump to behavior
            Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.PWSX-gen.11507.25552.exeThread delayed: delay time: 597906Jump to behavior
            Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.PWSX-gen.11507.25552.exeThread delayed: delay time: 597795Jump to behavior
            Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.PWSX-gen.11507.25552.exeThread delayed: delay time: 597686Jump to behavior
            Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.PWSX-gen.11507.25552.exeThread delayed: delay time: 597578Jump to behavior
            Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.PWSX-gen.11507.25552.exeThread delayed: delay time: 597469Jump to behavior
            Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.PWSX-gen.11507.25552.exeThread delayed: delay time: 597356Jump to behavior
            Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.PWSX-gen.11507.25552.exeThread delayed: delay time: 597250Jump to behavior
            Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.PWSX-gen.11507.25552.exeThread delayed: delay time: 597140Jump to behavior
            Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.PWSX-gen.11507.25552.exeThread delayed: delay time: 597031Jump to behavior
            Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.PWSX-gen.11507.25552.exeThread delayed: delay time: 596922Jump to behavior
            Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.PWSX-gen.11507.25552.exeThread delayed: delay time: 596812Jump to behavior
            Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.PWSX-gen.11507.25552.exeThread delayed: delay time: 596703Jump to behavior
            Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.PWSX-gen.11507.25552.exeThread delayed: delay time: 596593Jump to behavior
            Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.PWSX-gen.11507.25552.exeThread delayed: delay time: 596484Jump to behavior
            Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.PWSX-gen.11507.25552.exeThread delayed: delay time: 596375Jump to behavior
            Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.PWSX-gen.11507.25552.exeThread delayed: delay time: 596266Jump to behavior
            Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.PWSX-gen.11507.25552.exeThread delayed: delay time: 596141Jump to behavior
            Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.PWSX-gen.11507.25552.exeThread delayed: delay time: 596016Jump to behavior
            Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.PWSX-gen.11507.25552.exeThread delayed: delay time: 595906Jump to behavior
            Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.PWSX-gen.11507.25552.exeThread delayed: delay time: 595797Jump to behavior
            Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.PWSX-gen.11507.25552.exeThread delayed: delay time: 595687Jump to behavior
            Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.PWSX-gen.11507.25552.exeThread delayed: delay time: 595578Jump to behavior
            Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.PWSX-gen.11507.25552.exeThread delayed: delay time: 595469Jump to behavior
            Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.PWSX-gen.11507.25552.exeThread delayed: delay time: 595359Jump to behavior
            Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.PWSX-gen.11507.25552.exeThread delayed: delay time: 595246Jump to behavior
            Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.PWSX-gen.11507.25552.exeThread delayed: delay time: 595139Jump to behavior
            Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.PWSX-gen.11507.25552.exeThread delayed: delay time: 595027Jump to behavior
            Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.PWSX-gen.11507.25552.exeThread delayed: delay time: 594743Jump to behavior
            Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.PWSX-gen.11507.25552.exeThread delayed: delay time: 594542Jump to behavior
            Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.PWSX-gen.11507.25552.exeThread delayed: delay time: 594437Jump to behavior
            Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.PWSX-gen.11507.25552.exeThread delayed: delay time: 594328Jump to behavior
            Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.PWSX-gen.11507.25552.exeThread delayed: delay time: 594219Jump to behavior
            Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.PWSX-gen.11507.25552.exeThread delayed: delay time: 594094Jump to behavior
            Source: SecuriteInfo.com.Win32.PWSX-gen.11507.25552.exe, 00000002.00000002.3646157598.000000000121C000.00000004.00000020.00020000.00000000.sdmpBinary or memory string: Hyper-V RAW%SystemRoot%\system32\mswsock.dll
            Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.PWSX-gen.11507.25552.exeProcess information queried: ProcessInformationJump to behavior
            Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.PWSX-gen.11507.25552.exeCode function: 2_2_05B379E8 LdrInitializeThunk,2_2_05B379E8
            Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.PWSX-gen.11507.25552.exeProcess token adjusted: DebugJump to behavior
            Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.PWSX-gen.11507.25552.exeMemory allocated: page read and write | page guardJump to behavior

            HIPS / PFW / Operating System Protection Evasion

            barindex
            Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.PWSX-gen.11507.25552.exeMemory written: C:\Users\user\Desktop\SecuriteInfo.com.Win32.PWSX-gen.11507.25552.exe base: 400000 value starts with: 4D5AJump to behavior
            Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.PWSX-gen.11507.25552.exeProcess created: C:\Users\user\Desktop\SecuriteInfo.com.Win32.PWSX-gen.11507.25552.exe "C:\Users\user\Desktop\SecuriteInfo.com.Win32.PWSX-gen.11507.25552.exe"Jump to behavior
            Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.PWSX-gen.11507.25552.exeQueries volume information: C:\Users\user\Desktop\SecuriteInfo.com.Win32.PWSX-gen.11507.25552.exe VolumeInformationJump to behavior
            Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.PWSX-gen.11507.25552.exeQueries volume information: C:\Windows\Microsoft.NET\assembly\GAC_MSIL\System.Windows.Forms\v4.0_4.0.0.0__b77a5c561934e089\System.Windows.Forms.dll VolumeInformationJump to behavior
            Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.PWSX-gen.11507.25552.exeQueries volume information: C:\Windows\Microsoft.NET\assembly\GAC_MSIL\System.Drawing\v4.0_4.0.0.0__b03f5f7f11d50a3a\System.Drawing.dll VolumeInformationJump to behavior
            Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.PWSX-gen.11507.25552.exeQueries volume information: C:\Windows\Microsoft.NET\assembly\GAC_MSIL\System.Windows.Forms.DataVisualization\v4.0_4.0.0.0__31bf3856ad364e35\System.Windows.Forms.DataVisualization.dll VolumeInformationJump to behavior
            Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.PWSX-gen.11507.25552.exeQueries volume information: C:\Windows\Microsoft.NET\assembly\GAC_32\System.Data\v4.0_4.0.0.0__b77a5c561934e089\System.Data.dll VolumeInformationJump to behavior
            Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.PWSX-gen.11507.25552.exeQueries volume information: C:\Windows\Microsoft.NET\assembly\GAC_MSIL\Accessibility\v4.0_4.0.0.0__b03f5f7f11d50a3a\Accessibility.dll VolumeInformationJump to behavior
            Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.PWSX-gen.11507.25552.exeQueries volume information: C:\Windows\Fonts\bahnschrift.ttf VolumeInformationJump to behavior
            Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.PWSX-gen.11507.25552.exeQueries volume information: C:\Windows\Fonts\bahnschrift.ttf VolumeInformationJump to behavior
            Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.PWSX-gen.11507.25552.exeQueries volume information: C:\Windows\Fonts\bahnschrift.ttf VolumeInformationJump to behavior
            Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.PWSX-gen.11507.25552.exeQueries volume information: C:\Windows\Fonts\bahnschrift.ttf VolumeInformationJump to behavior
            Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.PWSX-gen.11507.25552.exeQueries volume information: C:\Windows\Fonts\bahnschrift.ttf VolumeInformationJump to behavior
            Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.PWSX-gen.11507.25552.exeQueries volume information: C:\Windows\Fonts\bahnschrift.ttf VolumeInformationJump to behavior
            Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.PWSX-gen.11507.25552.exeQueries volume information: C:\Windows\Fonts\bahnschrift.ttf VolumeInformationJump to behavior
            Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.PWSX-gen.11507.25552.exeQueries volume information: C:\Windows\Fonts\bahnschrift.ttf VolumeInformationJump to behavior
            Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.PWSX-gen.11507.25552.exeQueries volume information: C:\Windows\Fonts\calibrili.ttf VolumeInformationJump to behavior
            Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.PWSX-gen.11507.25552.exeQueries volume information: C:\Windows\Fonts\calibrib.ttf VolumeInformationJump to behavior
            Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.PWSX-gen.11507.25552.exeQueries volume information: C:\Windows\Fonts\cambria.ttc VolumeInformationJump to behavior
            Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.PWSX-gen.11507.25552.exeQueries volume information: C:\Windows\Fonts\cambriab.ttf VolumeInformationJump to behavior
            Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.PWSX-gen.11507.25552.exeQueries volume information: C:\Windows\Fonts\cambriaz.ttf VolumeInformationJump to behavior
            Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.PWSX-gen.11507.25552.exeQueries volume information: C:\Windows\Fonts\cambria.ttc VolumeInformationJump to behavior
            Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.PWSX-gen.11507.25552.exeQueries volume information: C:\Windows\Fonts\Candara.ttf VolumeInformationJump to behavior
            Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.PWSX-gen.11507.25552.exeQueries volume information: C:\Windows\Fonts\Candaral.ttf VolumeInformationJump to behavior
            Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.PWSX-gen.11507.25552.exeQueries volume information: C:\Windows\Fonts\Candarai.ttf VolumeInformationJump to behavior
            Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.PWSX-gen.11507.25552.exeQueries volume information: C:\Windows\Fonts\Candarali.ttf VolumeInformationJump to behavior
            Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.PWSX-gen.11507.25552.exeQueries volume information: C:\Windows\Fonts\Candarab.ttf VolumeInformationJump to behavior
            Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.PWSX-gen.11507.25552.exeQueries volume information: C:\Windows\Fonts\Candaraz.ttf VolumeInformationJump to behavior
            Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.PWSX-gen.11507.25552.exeQueries volume information: C:\Windows\Fonts\comic.ttf VolumeInformationJump to behavior
            Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.PWSX-gen.11507.25552.exeQueries volume information: C:\Windows\Fonts\comici.ttf VolumeInformationJump to behavior
            Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.PWSX-gen.11507.25552.exeQueries volume information: C:\Windows\Fonts\comicbd.ttf VolumeInformationJump to behavior
            Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.PWSX-gen.11507.25552.exeQueries volume information: C:\Windows\Fonts\comicz.ttf VolumeInformationJump to behavior
            Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.PWSX-gen.11507.25552.exeQueries volume information: C:\Windows\Fonts\constan.ttf VolumeInformationJump to behavior
            Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.PWSX-gen.11507.25552.exeQueries volume information: C:\Windows\Fonts\constani.ttf VolumeInformationJump to behavior
            Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.PWSX-gen.11507.25552.exeQueries volume information: C:\Windows\Fonts\constanb.ttf VolumeInformationJump to behavior
            Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.PWSX-gen.11507.25552.exeQueries volume information: C:\Windows\Fonts\constanz.ttf VolumeInformationJump to behavior
            Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.PWSX-gen.11507.25552.exeQueries volume information: C:\Windows\Fonts\corbel.ttf VolumeInformationJump to behavior
            Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.PWSX-gen.11507.25552.exeQueries volume information: C:\Windows\Fonts\corbell.ttf VolumeInformationJump to behavior
            Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.PWSX-gen.11507.25552.exeQueries volume information: C:\Windows\Fonts\corbeli.ttf VolumeInformationJump to behavior
            Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.PWSX-gen.11507.25552.exeQueries volume information: C:\Windows\Fonts\corbelli.ttf VolumeInformationJump to behavior
            Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.PWSX-gen.11507.25552.exeQueries volume information: C:\Windows\Fonts\corbelb.ttf VolumeInformationJump to behavior
            Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.PWSX-gen.11507.25552.exeQueries volume information: C:\Windows\Fonts\corbelz.ttf VolumeInformationJump to behavior
            Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.PWSX-gen.11507.25552.exeQueries volume information: C:\Windows\Fonts\cour.ttf VolumeInformationJump to behavior
            Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.PWSX-gen.11507.25552.exeQueries volume information: C:\Windows\Fonts\couri.ttf VolumeInformationJump to behavior
            Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.PWSX-gen.11507.25552.exeQueries volume information: C:\Windows\Fonts\courbd.ttf VolumeInformationJump to behavior
            Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.PWSX-gen.11507.25552.exeQueries volume information: C:\Windows\Fonts\courbi.ttf VolumeInformationJump to behavior
            Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.PWSX-gen.11507.25552.exeQueries volume information: C:\Windows\Fonts\ebrima.ttf VolumeInformationJump to behavior
            Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.PWSX-gen.11507.25552.exeQueries volume information: C:\Windows\Fonts\ebrimabd.ttf VolumeInformationJump to behavior
            Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.PWSX-gen.11507.25552.exeQueries volume information: C:\Windows\Fonts\framd.ttf VolumeInformationJump to behavior
            Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.PWSX-gen.11507.25552.exeQueries volume information: C:\Windows\Fonts\FRADM.TTF VolumeInformationJump to behavior
            Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.PWSX-gen.11507.25552.exeQueries volume information: C:\Windows\Fonts\framdit.ttf VolumeInformationJump to behavior
            Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.PWSX-gen.11507.25552.exeQueries volume information: C:\Windows\Fonts\FRADMIT.TTF VolumeInformationJump to behavior
            Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.PWSX-gen.11507.25552.exeQueries volume information: C:\Windows\Fonts\FRAMDCN.TTF VolumeInformationJump to behavior
            Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.PWSX-gen.11507.25552.exeQueries volume information: C:\Windows\Fonts\FRADMCN.TTF VolumeInformationJump to behavior
            Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.PWSX-gen.11507.25552.exeQueries volume information: C:\Windows\Fonts\FRAHV.TTF VolumeInformationJump to behavior
            Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.PWSX-gen.11507.25552.exeQueries volume information: C:\Windows\Fonts\FRAHVIT.TTF VolumeInformationJump to behavior
            Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.PWSX-gen.11507.25552.exeQueries volume information: C:\Windows\Fonts\Gabriola.ttf VolumeInformationJump to behavior
            Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.PWSX-gen.11507.25552.exeQueries volume information: C:\Windows\Fonts\gadugi.ttf VolumeInformationJump to behavior
            Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.PWSX-gen.11507.25552.exeQueries volume information: C:\Windows\Fonts\gadugib.ttf VolumeInformationJump to behavior
            Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.PWSX-gen.11507.25552.exeQueries volume information: C:\Windows\Fonts\georgia.ttf VolumeInformationJump to behavior
            Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.PWSX-gen.11507.25552.exeQueries volume information: C:\Windows\Fonts\georgiai.ttf VolumeInformationJump to behavior
            Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.PWSX-gen.11507.25552.exeQueries volume information: C:\Windows\Fonts\georgiab.ttf VolumeInformationJump to behavior
            Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.PWSX-gen.11507.25552.exeQueries volume information: C:\Windows\Fonts\georgiaz.ttf VolumeInformationJump to behavior
            Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.PWSX-gen.11507.25552.exeQueries volume information: C:\Windows\Fonts\impact.ttf VolumeInformationJump to behavior
            Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.PWSX-gen.11507.25552.exeQueries volume information: C:\Windows\Fonts\Inkfree.ttf VolumeInformationJump to behavior
            Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.PWSX-gen.11507.25552.exeQueries volume information: C:\Windows\Fonts\javatext.ttf VolumeInformationJump to behavior
            Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.PWSX-gen.11507.25552.exeQueries volume information: C:\Windows\Fonts\LeelawUI.ttf VolumeInformationJump to behavior
            Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.PWSX-gen.11507.25552.exeQueries volume information: C:\Windows\Fonts\LeelUIsl.ttf VolumeInformationJump to behavior
            Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.PWSX-gen.11507.25552.exeQueries volume information: C:\Windows\Fonts\LeelaUIb.ttf VolumeInformationJump to behavior
            Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.PWSX-gen.11507.25552.exeQueries volume information: C:\Windows\Fonts\lucon.ttf VolumeInformationJump to behavior
            Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.PWSX-gen.11507.25552.exeQueries volume information: C:\Windows\Fonts\l_10646.ttf VolumeInformationJump to behavior
            Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.PWSX-gen.11507.25552.exeQueries volume information: C:\Windows\Fonts\himalaya.ttf VolumeInformationJump to behavior
            Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.PWSX-gen.11507.25552.exeQueries volume information: C:\Windows\Fonts\msjhl.ttc VolumeInformationJump to behavior
            Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.PWSX-gen.11507.25552.exeQueries volume information: C:\Windows\Fonts\msjhbd.ttc VolumeInformationJump to behavior
            Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.PWSX-gen.11507.25552.exeQueries volume information: C:\Windows\Fonts\msjh.ttc VolumeInformationJump to behavior
            Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.PWSX-gen.11507.25552.exeQueries volume information: C:\Windows\Fonts\msjhl.ttc VolumeInformationJump to behavior
            Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.PWSX-gen.11507.25552.exeQueries volume information: C:\Windows\Fonts\msjhbd.ttc VolumeInformationJump to behavior
            Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.PWSX-gen.11507.25552.exeQueries volume information: C:\Windows\Fonts\ntailu.ttf VolumeInformationJump to behavior
            Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.PWSX-gen.11507.25552.exeQueries volume information: C:\Windows\Fonts\ntailub.ttf VolumeInformationJump to behavior
            Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.PWSX-gen.11507.25552.exeQueries volume information: C:\Windows\Fonts\phagspa.ttf VolumeInformationJump to behavior
            Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.PWSX-gen.11507.25552.exeQueries volume information: C:\Windows\Fonts\phagspab.ttf VolumeInformationJump to behavior
            Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.PWSX-gen.11507.25552.exeQueries volume information: C:\Windows\Fonts\micross.ttf VolumeInformationJump to behavior
            Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.PWSX-gen.11507.25552.exeQueries volume information: C:\Windows\Fonts\taile.ttf VolumeInformationJump to behavior
            Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.PWSX-gen.11507.25552.exeQueries volume information: C:\Windows\Fonts\taileb.ttf VolumeInformationJump to behavior
            Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.PWSX-gen.11507.25552.exeQueries volume information: C:\Windows\Fonts\msyh.ttc VolumeInformationJump to behavior
            Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.PWSX-gen.11507.25552.exeQueries volume information: C:\Windows\Fonts\msyhbd.ttc VolumeInformationJump to behavior
            Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.PWSX-gen.11507.25552.exeQueries volume information: C:\Windows\Fonts\msyi.ttf VolumeInformationJump to behavior
            Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.PWSX-gen.11507.25552.exeQueries volume information: C:\Windows\Fonts\mingliub.ttc VolumeInformationJump to behavior
            Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.PWSX-gen.11507.25552.exeQueries volume information: C:\Windows\Fonts\mingliub.ttc VolumeInformationJump to behavior
            Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.PWSX-gen.11507.25552.exeQueries volume information: C:\Windows\Fonts\mingliub.ttc VolumeInformationJump to behavior
            Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.PWSX-gen.11507.25552.exeQueries volume information: C:\Windows\Fonts\monbaiti.ttf VolumeInformationJump to behavior
            Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.PWSX-gen.11507.25552.exeQueries volume information: C:\Windows\Fonts\msgothic.ttc VolumeInformationJump to behavior
            Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.PWSX-gen.11507.25552.exeQueries volume information: C:\Windows\Fonts\msgothic.ttc VolumeInformationJump to behavior
            Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.PWSX-gen.11507.25552.exeQueries volume information: C:\Windows\Fonts\mvboli.ttf VolumeInformationJump to behavior
            Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.PWSX-gen.11507.25552.exeQueries volume information: C:\Windows\Fonts\mmrtext.ttf VolumeInformationJump to behavior
            Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.PWSX-gen.11507.25552.exeQueries volume information: C:\Windows\Fonts\mmrtextb.ttf VolumeInformationJump to behavior
            Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.PWSX-gen.11507.25552.exeQueries volume information: C:\Windows\Fonts\pala.ttf VolumeInformationJump to behavior
            Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.PWSX-gen.11507.25552.exeQueries volume information: C:\Windows\Fonts\palai.ttf VolumeInformationJump to behavior
            Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.PWSX-gen.11507.25552.exeQueries volume information: C:\Windows\Fonts\palab.ttf VolumeInformationJump to behavior
            Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.PWSX-gen.11507.25552.exeQueries volume information: C:\Windows\Fonts\palabi.ttf VolumeInformationJump to behavior
            Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.PWSX-gen.11507.25552.exeQueries volume information: C:\Windows\Fonts\segoepr.ttf VolumeInformationJump to behavior
            Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.PWSX-gen.11507.25552.exeQueries volume information: C:\Windows\Fonts\segoeprb.ttf VolumeInformationJump to behavior
            Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.PWSX-gen.11507.25552.exeQueries volume information: C:\Windows\Fonts\segoesc.ttf VolumeInformationJump to behavior
            Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.PWSX-gen.11507.25552.exeQueries volume information: C:\Windows\Fonts\segoescb.ttf VolumeInformationJump to behavior
            Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.PWSX-gen.11507.25552.exeQueries volume information: C:\Windows\Fonts\seguihis.ttf VolumeInformationJump to behavior
            Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.PWSX-gen.11507.25552.exeQueries volume information: C:\Windows\Fonts\simsun.ttc VolumeInformationJump to behavior
            Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.PWSX-gen.11507.25552.exeQueries volume information: C:\Windows\Fonts\simsunb.ttf VolumeInformationJump to behavior
            Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.PWSX-gen.11507.25552.exeQueries volume information: C:\Windows\Fonts\Sitka.ttc VolumeInformationJump to behavior
            Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.PWSX-gen.11507.25552.exeQueries volume information: C:\Windows\Fonts\SitkaI.ttc VolumeInformationJump to behavior
            Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.PWSX-gen.11507.25552.exeQueries volume information: C:\Windows\Fonts\SitkaB.ttc VolumeInformationJump to behavior
            Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.PWSX-gen.11507.25552.exeQueries volume information: C:\Windows\Fonts\SitkaZ.ttc VolumeInformationJump to behavior
            Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.PWSX-gen.11507.25552.exeQueries volume information: C:\Windows\Fonts\Sitka.ttc VolumeInformationJump to behavior
            Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.PWSX-gen.11507.25552.exeQueries volume information: C:\Windows\Fonts\SitkaI.ttc VolumeInformationJump to behavior
            Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.PWSX-gen.11507.25552.exeQueries volume information: C:\Windows\Fonts\SitkaB.ttc VolumeInformationJump to behavior
            Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.PWSX-gen.11507.25552.exeQueries volume information: C:\Windows\Fonts\SitkaZ.ttc VolumeInformationJump to behavior
            Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.PWSX-gen.11507.25552.exeQueries volume information: C:\Windows\Fonts\Sitka.ttc VolumeInformationJump to behavior
            Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.PWSX-gen.11507.25552.exeQueries volume information: C:\Windows\Fonts\SitkaB.ttc VolumeInformationJump to behavior
            Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.PWSX-gen.11507.25552.exeQueries volume information: C:\Windows\Fonts\SitkaZ.ttc VolumeInformationJump to behavior
            Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.PWSX-gen.11507.25552.exeQueries volume information: C:\Windows\Fonts\SitkaB.ttc VolumeInformationJump to behavior
            Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.PWSX-gen.11507.25552.exeQueries volume information: C:\Windows\Fonts\SitkaZ.ttc VolumeInformationJump to behavior
            Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.PWSX-gen.11507.25552.exeQueries volume information: C:\Windows\Fonts\SitkaB.ttc VolumeInformationJump to behavior
            Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.PWSX-gen.11507.25552.exeQueries volume information: C:\Windows\Fonts\sylfaen.ttf VolumeInformationJump to behavior
            Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.PWSX-gen.11507.25552.exeQueries volume information: C:\Windows\Fonts\symbol.ttf VolumeInformationJump to behavior
            Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.PWSX-gen.11507.25552.exeQueries volume information: C:\Windows\Fonts\trebuc.ttf VolumeInformationJump to behavior
            Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.PWSX-gen.11507.25552.exeQueries volume information: C:\Windows\Fonts\trebucit.ttf VolumeInformationJump to behavior
            Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.PWSX-gen.11507.25552.exeQueries volume information: C:\Windows\Fonts\trebucbd.ttf VolumeInformationJump to behavior
            Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.PWSX-gen.11507.25552.exeQueries volume information: C:\Windows\Fonts\trebucbi.ttf VolumeInformationJump to behavior
            Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.PWSX-gen.11507.25552.exeQueries volume information: C:\Windows\Fonts\verdanab.ttf VolumeInformationJump to behavior
            Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.PWSX-gen.11507.25552.exeQueries volume information: C:\Windows\Fonts\verdanaz.ttf VolumeInformationJump to behavior
            Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.PWSX-gen.11507.25552.exeQueries volume information: C:\Windows\Fonts\wingding.ttf VolumeInformationJump to behavior
            Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.PWSX-gen.11507.25552.exeQueries volume information: C:\Windows\Fonts\YuGothM.ttc VolumeInformationJump to behavior
            Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.PWSX-gen.11507.25552.exeQueries volume information: C:\Windows\Fonts\YuGothL.ttc VolumeInformationJump to behavior
            Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.PWSX-gen.11507.25552.exeQueries volume information: C:\Windows\Fonts\YuGothM.ttc VolumeInformationJump to behavior
            Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.PWSX-gen.11507.25552.exeQueries volume information: C:\Windows\Fonts\YuGothL.ttc VolumeInformationJump to behavior
            Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.PWSX-gen.11507.25552.exeQueries volume information: C:\Windows\Fonts\holomdl2.ttf VolumeInformationJump to behavior
            Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.PWSX-gen.11507.25552.exeQueries volume information: C:\Windows\Fonts\AGENCYR.TTF VolumeInformationJump to behavior
            Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.PWSX-gen.11507.25552.exeQueries volume information: C:\Windows\Fonts\AGENCYB.TTF VolumeInformationJump to behavior
            Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.PWSX-gen.11507.25552.exeQueries volume information: C:\Windows\Fonts\ALGER.TTF VolumeInformationJump to behavior
            Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.PWSX-gen.11507.25552.exeQueries volume information: C:\Windows\Fonts\BKANT.TTF VolumeInformationJump to behavior
            Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.PWSX-gen.11507.25552.exeQueries volume information: C:\Windows\Fonts\ANTQUAI.TTF VolumeInformationJump to behavior
            Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.PWSX-gen.11507.25552.exeQueries volume information: C:\Windows\Fonts\ANTQUAB.TTF VolumeInformationJump to behavior
            Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.PWSX-gen.11507.25552.exeQueries volume information: C:\Windows\Fonts\ANTQUABI.TTF VolumeInformationJump to behavior
            Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.PWSX-gen.11507.25552.exeQueries volume information: C:\Windows\Fonts\ARLRDBD.TTF VolumeInformationJump to behavior
            Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.PWSX-gen.11507.25552.exeQueries volume information: C:\Windows\Fonts\BASKVILL.TTF VolumeInformationJump to behavior
            Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.PWSX-gen.11507.25552.exeQueries volume information: C:\Windows\Fonts\BAUHS93.TTF VolumeInformationJump to behavior
            Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.PWSX-gen.11507.25552.exeQueries volume information: C:\Windows\Fonts\BELL.TTF VolumeInformationJump to behavior
            Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.PWSX-gen.11507.25552.exeQueries volume information: C:\Windows\Fonts\BELLI.TTF VolumeInformationJump to behavior
            Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.PWSX-gen.11507.25552.exeQueries volume information: C:\Windows\Fonts\BELLB.TTF VolumeInformationJump to behavior
            Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.PWSX-gen.11507.25552.exeQueries volume information: C:\Windows\Fonts\BERNHC.TTF VolumeInformationJump to behavior
            Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.PWSX-gen.11507.25552.exeQueries volume information: C:\Windows\Fonts\BOD_R.TTF VolumeInformationJump to behavior
            Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.PWSX-gen.11507.25552.exeQueries volume information: C:\Windows\Fonts\BOD_I.TTF VolumeInformationJump to behavior
            Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.PWSX-gen.11507.25552.exeQueries volume information: C:\Windows\Fonts\BOD_B.TTF VolumeInformationJump to behavior
            Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.PWSX-gen.11507.25552.exeQueries volume information: C:\Windows\Fonts\BOD_BI.TTF VolumeInformationJump to behavior
            Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.PWSX-gen.11507.25552.exeQueries volume information: C:\Windows\Fonts\BOD_CR.TTF VolumeInformationJump to behavior
            Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.PWSX-gen.11507.25552.exeQueries volume information: C:\Windows\Fonts\BOD_BLAR.TTF VolumeInformationJump to behavior
            Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.PWSX-gen.11507.25552.exeQueries volume information: C:\Windows\Fonts\BOD_CI.TTF VolumeInformationJump to behavior
            Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.PWSX-gen.11507.25552.exeQueries volume information: C:\Windows\Fonts\BOD_CB.TTF VolumeInformationJump to behavior
            Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.PWSX-gen.11507.25552.exeQueries volume information: C:\Windows\Fonts\BOD_BLAI.TTF VolumeInformationJump to behavior
            Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.PWSX-gen.11507.25552.exeQueries volume information: C:\Windows\Fonts\BOD_CBI.TTF VolumeInformationJump to behavior
            Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.PWSX-gen.11507.25552.exeQueries volume information: C:\Windows\Fonts\BOD_PSTC.TTF VolumeInformationJump to behavior
            Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.PWSX-gen.11507.25552.exeQueries volume information: C:\Windows\Fonts\BOOKOS.TTF VolumeInformationJump to behavior
            Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.PWSX-gen.11507.25552.exeQueries volume information: C:\Windows\Fonts\BOOKOSB.TTF VolumeInformationJump to behavior
            Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.PWSX-gen.11507.25552.exeQueries volume information: C:\Windows\Fonts\BOOKOSI.TTF VolumeInformationJump to behavior
            Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.PWSX-gen.11507.25552.exeQueries volume information: C:\Windows\Fonts\BOOKOSBI.TTF VolumeInformationJump to behavior
            Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.PWSX-gen.11507.25552.exeQueries volume information: C:\Windows\Fonts\BRADHITC.TTF VolumeInformationJump to behavior
            Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.PWSX-gen.11507.25552.exeQueries volume information: C:\Windows\Fonts\BRITANIC.TTF VolumeInformationJump to behavior
            Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.PWSX-gen.11507.25552.exeQueries volume information: C:\Windows\Fonts\BRLNSR.TTF VolumeInformationJump to behavior
            Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.PWSX-gen.11507.25552.exeQueries volume information: C:\Windows\Fonts\BRLNSDB.TTF VolumeInformationJump to behavior
            Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.PWSX-gen.11507.25552.exeQueries volume information: C:\Windows\Fonts\BRLNSB.TTF VolumeInformationJump to behavior
            Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.PWSX-gen.11507.25552.exeQueries volume information: C:\Windows\Fonts\BROADW.TTF VolumeInformationJump to behavior
            Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.PWSX-gen.11507.25552.exeQueries volume information: C:\Windows\Fonts\BRUSHSCI.TTF VolumeInformationJump to behavior
            Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.PWSX-gen.11507.25552.exeQueries volume information: C:\Windows\Fonts\BSSYM7.TTF VolumeInformationJump to behavior
            Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.PWSX-gen.11507.25552.exeQueries volume information: C:\Windows\Fonts\CALIFR.TTF VolumeInformationJump to behavior
            Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.PWSX-gen.11507.25552.exeQueries volume information: C:\Windows\Fonts\CALIFI.TTF VolumeInformationJump to behavior
            Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.PWSX-gen.11507.25552.exeQueries volume information: C:\Windows\Fonts\CALIFB.TTF VolumeInformationJump to behavior
            Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.PWSX-gen.11507.25552.exeQueries volume information: C:\Windows\Fonts\CALIST.TTF VolumeInformationJump to behavior
            Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.PWSX-gen.11507.25552.exeQueries volume information: C:\Windows\Fonts\CALISTI.TTF VolumeInformationJump to behavior
            Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.PWSX-gen.11507.25552.exeQueries volume information: C:\Windows\Fonts\CALISTB.TTF VolumeInformationJump to behavior
            Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.PWSX-gen.11507.25552.exeQueries volume information: C:\Windows\Fonts\CALISTBI.TTF VolumeInformationJump to behavior
            Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.PWSX-gen.11507.25552.exeQueries volume information: C:\Windows\Fonts\CASTELAR.TTF VolumeInformationJump to behavior
            Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.PWSX-gen.11507.25552.exeQueries volume information: C:\Windows\Fonts\CENSCBK.TTF VolumeInformationJump to behavior
            Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.PWSX-gen.11507.25552.exeQueries volume information: C:\Windows\Fonts\SCHLBKI.TTF VolumeInformationJump to behavior
            Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.PWSX-gen.11507.25552.exeQueries volume information: C:\Windows\Fonts\SCHLBKB.TTF VolumeInformationJump to behavior
            Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.PWSX-gen.11507.25552.exeQueries volume information: C:\Windows\Fonts\SCHLBKBI.TTF VolumeInformationJump to behavior
            Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.PWSX-gen.11507.25552.exeQueries volume information: C:\Windows\Fonts\CENTAUR.TTF VolumeInformationJump to behavior
            Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.PWSX-gen.11507.25552.exeQueries volume information: C:\Windows\Fonts\CENTURY.TTF VolumeInformationJump to behavior
            Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.PWSX-gen.11507.25552.exeQueries volume information: C:\Windows\Fonts\CHILLER.TTF VolumeInformationJump to behavior
            Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.PWSX-gen.11507.25552.exeQueries volume information: C:\Windows\Fonts\COLONNA.TTF VolumeInformationJump to behavior
            Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.PWSX-gen.11507.25552.exeQueries volume information: C:\Windows\Fonts\COOPBL.TTF VolumeInformationJump to behavior
            Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.PWSX-gen.11507.25552.exeQueries volume information: C:\Windows\Fonts\COPRGTL.TTF VolumeInformationJump to behavior
            Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.PWSX-gen.11507.25552.exeQueries volume information: C:\Windows\Fonts\COPRGTB.TTF VolumeInformationJump to behavior
            Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.PWSX-gen.11507.25552.exeQueries volume information: C:\Windows\Fonts\CURLZ___.TTF VolumeInformationJump to behavior
            Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.PWSX-gen.11507.25552.exeQueries volume information: C:\Windows\Fonts\DUBAI-REGULAR.TTF VolumeInformationJump to behavior
            Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.PWSX-gen.11507.25552.exeQueries volume information: C:\Windows\Fonts\DUBAI-MEDIUM.TTF VolumeInformationJump to behavior
            Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.PWSX-gen.11507.25552.exeQueries volume information: C:\Windows\Fonts\DUBAI-LIGHT.TTF VolumeInformationJump to behavior
            Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.PWSX-gen.11507.25552.exeQueries volume information: C:\Windows\Fonts\DUBAI-BOLD.TTF VolumeInformationJump to behavior
            Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.PWSX-gen.11507.25552.exeQueries volume information: C:\Windows\Fonts\ELEPHNT.TTF VolumeInformationJump to behavior
            Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.PWSX-gen.11507.25552.exeQueries volume information: C:\Windows\Fonts\ELEPHNTI.TTF VolumeInformationJump to behavior
            Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.PWSX-gen.11507.25552.exeQueries volume information: C:\Windows\Fonts\ENGR.TTF VolumeInformationJump to behavior
            Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.PWSX-gen.11507.25552.exeQueries volume information: C:\Windows\Fonts\ERASMD.TTF VolumeInformationJump to behavior
            Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.PWSX-gen.11507.25552.exeQueries volume information: C:\Windows\Fonts\ERASLGHT.TTF VolumeInformationJump to behavior
            Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.PWSX-gen.11507.25552.exeQueries volume information: C:\Windows\Fonts\ERASDEMI.TTF VolumeInformationJump to behavior
            Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.PWSX-gen.11507.25552.exeQueries volume information: C:\Windows\Fonts\ERASBD.TTF VolumeInformationJump to behavior
            Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.PWSX-gen.11507.25552.exeQueries volume information: C:\Windows\Fonts\FELIXTI.TTF VolumeInformationJump to behavior
            Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.PWSX-gen.11507.25552.exeQueries volume information: C:\Windows\Fonts\FORTE.TTF VolumeInformationJump to behavior
            Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.PWSX-gen.11507.25552.exeQueries volume information: C:\Windows\Fonts\FRABK.TTF VolumeInformationJump to behavior
            Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.PWSX-gen.11507.25552.exeQueries volume information: C:\Windows\Fonts\FRABKIT.TTF VolumeInformationJump to behavior
            Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.PWSX-gen.11507.25552.exeQueries volume information: C:\Windows\Fonts\FREESCPT.TTF VolumeInformationJump to behavior
            Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.PWSX-gen.11507.25552.exeQueries volume information: C:\Windows\Fonts\FRSCRIPT.TTF VolumeInformationJump to behavior
            Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.PWSX-gen.11507.25552.exeQueries volume information: C:\Windows\Fonts\FTLTLT.TTF VolumeInformationJump to behavior
            Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.PWSX-gen.11507.25552.exeQueries volume information: C:\Windows\Fonts\GARA.TTF VolumeInformationJump to behavior
            Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.PWSX-gen.11507.25552.exeQueries volume information: C:\Windows\Fonts\GARAIT.TTF VolumeInformationJump to behavior
            Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.PWSX-gen.11507.25552.exeQueries volume information: C:\Windows\Fonts\GARABD.TTF VolumeInformationJump to behavior
            Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.PWSX-gen.11507.25552.exeQueries volume information: C:\Windows\Fonts\GIGI.TTF VolumeInformationJump to behavior
            Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.PWSX-gen.11507.25552.exeQueries volume information: C:\Windows\Fonts\GIL_____.TTF VolumeInformationJump to behavior
            Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.PWSX-gen.11507.25552.exeQueries volume information: C:\Windows\Fonts\GILI____.TTF VolumeInformationJump to behavior
            Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.PWSX-gen.11507.25552.exeQueries volume information: C:\Windows\Fonts\GILB____.TTF VolumeInformationJump to behavior
            Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.PWSX-gen.11507.25552.exeQueries volume information: C:\Windows\Fonts\GILBI___.TTF VolumeInformationJump to behavior
            Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.PWSX-gen.11507.25552.exeQueries volume information: C:\Windows\Fonts\GILC____.TTF VolumeInformationJump to behavior
            Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.PWSX-gen.11507.25552.exeQueries volume information: C:\Windows\Fonts\GLSNECB.TTF VolumeInformationJump to behavior
            Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.PWSX-gen.11507.25552.exeQueries volume information: C:\Windows\Fonts\GLECB.TTF VolumeInformationJump to behavior
            Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.PWSX-gen.11507.25552.exeQueries volume information: C:\Windows\Fonts\GOTHIC.TTF VolumeInformationJump to behavior
            Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.PWSX-gen.11507.25552.exeQueries volume information: C:\Windows\Fonts\GOTHICI.TTF VolumeInformationJump to behavior
            Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.PWSX-gen.11507.25552.exeQueries volume information: C:\Windows\Fonts\GOTHICB.TTF VolumeInformationJump to behavior
            Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.PWSX-gen.11507.25552.exeQueries volume information: C:\Windows\Fonts\GOTHICBI.TTF VolumeInformationJump to behavior
            Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.PWSX-gen.11507.25552.exeQueries volume information: C:\Windows\Fonts\GOUDOS.TTF VolumeInformationJump to behavior
            Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.PWSX-gen.11507.25552.exeQueries volume information: C:\Windows\Fonts\GOUDOSI.TTF VolumeInformationJump to behavior
            Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.PWSX-gen.11507.25552.exeQueries volume information: C:\Windows\Fonts\GOUDOSB.TTF VolumeInformationJump to behavior
            Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.PWSX-gen.11507.25552.exeQueries volume information: C:\Windows\Fonts\GOUDYSTO.TTF VolumeInformationJump to behavior
            Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.PWSX-gen.11507.25552.exeQueries volume information: C:\Windows\Fonts\HARLOWSI.TTF VolumeInformationJump to behavior
            Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.PWSX-gen.11507.25552.exeQueries volume information: C:\Windows\Fonts\HARNGTON.TTF VolumeInformationJump to behavior
            Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.PWSX-gen.11507.25552.exeQueries volume information: C:\Windows\Fonts\HATTEN.TTF VolumeInformationJump to behavior
            Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.PWSX-gen.11507.25552.exeQueries volume information: C:\Windows\Fonts\HTOWERT.TTF VolumeInformationJump to behavior
            Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.PWSX-gen.11507.25552.exeQueries volume information: C:\Windows\Fonts\HTOWERTI.TTF VolumeInformationJump to behavior
            Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.PWSX-gen.11507.25552.exeQueries volume information: C:\Windows\Fonts\IMPRISHA.TTF VolumeInformationJump to behavior
            Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.PWSX-gen.11507.25552.exeQueries volume information: C:\Windows\Fonts\INFROMAN.TTF VolumeInformationJump to behavior
            Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.PWSX-gen.11507.25552.exeQueries volume information: C:\Windows\Fonts\ITCBLKAD.TTF VolumeInformationJump to behavior
            Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.PWSX-gen.11507.25552.exeQueries volume information: C:\Windows\Fonts\ITCEDSCR.TTF VolumeInformationJump to behavior
            Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.PWSX-gen.11507.25552.exeQueries volume information: C:\Windows\Fonts\ITCKRIST.TTF VolumeInformationJump to behavior
            Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.PWSX-gen.11507.25552.exeQueries volume information: C:\Windows\Fonts\JOKERMAN.TTF VolumeInformationJump to behavior
            Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.PWSX-gen.11507.25552.exeQueries volume information: C:\Windows\Fonts\JUICE___.TTF VolumeInformationJump to behavior
            Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.PWSX-gen.11507.25552.exeQueries volume information: C:\Windows\Fonts\KUNSTLER.TTF VolumeInformationJump to behavior
            Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.PWSX-gen.11507.25552.exeQueries volume information: C:\Windows\Fonts\LATINWD.TTF VolumeInformationJump to behavior
            Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.PWSX-gen.11507.25552.exeQueries volume information: C:\Windows\Fonts\LBRITE.TTF VolumeInformationJump to behavior
            Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.PWSX-gen.11507.25552.exeQueries volume information: C:\Windows\Fonts\LBRITED.TTF VolumeInformationJump to behavior
            Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.PWSX-gen.11507.25552.exeQueries volume information: C:\Windows\Fonts\LBRITEI.TTF VolumeInformationJump to behavior
            Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.PWSX-gen.11507.25552.exeQueries volume information: C:\Windows\Fonts\LBRITEDI.TTF VolumeInformationJump to behavior
            Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.PWSX-gen.11507.25552.exeQueries volume information: C:\Windows\Fonts\LCALLIG.TTF VolumeInformationJump to behavior
            Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.PWSX-gen.11507.25552.exeQueries volume information: C:\Windows\Fonts\LEELAWAD.TTF VolumeInformationJump to behavior
            Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.PWSX-gen.11507.25552.exeQueries volume information: C:\Windows\Fonts\LEELAWDB.TTF VolumeInformationJump to behavior
            Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.PWSX-gen.11507.25552.exeQueries volume information: C:\Windows\Fonts\LFAX.TTF VolumeInformationJump to behavior
            Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.PWSX-gen.11507.25552.exeQueries volume information: C:\Windows\Fonts\LFAXD.TTF VolumeInformationJump to behavior
            Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.PWSX-gen.11507.25552.exeQueries volume information: C:\Windows\Fonts\LFAXI.TTF VolumeInformationJump to behavior
            Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.PWSX-gen.11507.25552.exeQueries volume information: C:\Windows\Fonts\LFAXDI.TTF VolumeInformationJump to behavior
            Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.PWSX-gen.11507.25552.exeQueries volume information: C:\Windows\Fonts\LHANDW.TTF VolumeInformationJump to behavior
            Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.PWSX-gen.11507.25552.exeQueries volume information: C:\Windows\Fonts\LSANS.TTF VolumeInformationJump to behavior
            Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.PWSX-gen.11507.25552.exeQueries volume information: C:\Windows\Fonts\LSANSD.TTF VolumeInformationJump to behavior
            Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.PWSX-gen.11507.25552.exeQueries volume information: C:\Windows\Fonts\LSANSI.TTF VolumeInformationJump to behavior
            Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.PWSX-gen.11507.25552.exeQueries volume information: C:\Windows\Fonts\LSANSDI.TTF VolumeInformationJump to behavior
            Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.PWSX-gen.11507.25552.exeQueries volume information: C:\Windows\Fonts\LTYPE.TTF VolumeInformationJump to behavior
            Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.PWSX-gen.11507.25552.exeQueries volume information: C:\Windows\Fonts\LTYPEO.TTF VolumeInformationJump to behavior
            Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.PWSX-gen.11507.25552.exeQueries volume information: C:\Windows\Fonts\LTYPEB.TTF VolumeInformationJump to behavior
            Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.PWSX-gen.11507.25552.exeQueries volume information: C:\Windows\Fonts\LTYPEBO.TTF VolumeInformationJump to behavior
            Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.PWSX-gen.11507.25552.exeQueries volume information: C:\Windows\Fonts\MAGNETOB.TTF VolumeInformationJump to behavior
            Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.PWSX-gen.11507.25552.exeQueries volume information: C:\Windows\Fonts\MAIAN.TTF VolumeInformationJump to behavior
            Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.PWSX-gen.11507.25552.exeQueries volume information: C:\Windows\Fonts\MATURASC.TTF VolumeInformationJump to behavior
            Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.PWSX-gen.11507.25552.exeQueries volume information: C:\Windows\Fonts\MISTRAL.TTF VolumeInformationJump to behavior
            Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.PWSX-gen.11507.25552.exeQueries volume information: C:\Windows\Fonts\MOD20.TTF VolumeInformationJump to behavior
            Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.PWSX-gen.11507.25552.exeQueries volume information: C:\Windows\Fonts\MSUIGHUR.TTF VolumeInformationJump to behavior
            Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.PWSX-gen.11507.25552.exeQueries volume information: C:\Windows\Fonts\MSUIGHUB.TTF VolumeInformationJump to behavior
            Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.PWSX-gen.11507.25552.exeQueries volume information: C:\Windows\Fonts\MTCORSVA.TTF VolumeInformationJump to behavior
            Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.PWSX-gen.11507.25552.exeQueries volume information: C:\Windows\Fonts\MTEXTRA.TTF VolumeInformationJump to behavior
            Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.PWSX-gen.11507.25552.exeQueries volume information: C:\Windows\Fonts\NIAGENG.TTF VolumeInformationJump to behavior
            Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.PWSX-gen.11507.25552.exeQueries volume information: C:\Windows\Fonts\NIAGSOL.TTF VolumeInformationJump to behavior
            Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.PWSX-gen.11507.25552.exeQueries volume information: C:\Windows\Fonts\OCRAEXT.TTF VolumeInformationJump to behavior
            Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.PWSX-gen.11507.25552.exeQueries volume information: C:\Windows\Fonts\OLDENGL.TTF VolumeInformationJump to behavior
            Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.PWSX-gen.11507.25552.exeQueries volume information: C:\Windows\Fonts\ONYX.TTF VolumeInformationJump to behavior
            Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.PWSX-gen.11507.25552.exeQueries volume information: C:\Windows\Fonts\OUTLOOK.TTF VolumeInformationJump to behavior
            Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.PWSX-gen.11507.25552.exeQueries volume information: C:\Windows\Fonts\PALSCRI.TTF VolumeInformationJump to behavior
            Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.PWSX-gen.11507.25552.exeQueries volume information: C:\Windows\Fonts\PAPYRUS.TTF VolumeInformationJump to behavior
            Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.PWSX-gen.11507.25552.exeQueries volume information: C:\Windows\Fonts\PARCHM.TTF VolumeInformationJump to behavior
            Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.PWSX-gen.11507.25552.exeQueries volume information: C:\Windows\Fonts\PER_____.TTF VolumeInformationJump to behavior
            Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.PWSX-gen.11507.25552.exeQueries volume information: C:\Windows\Fonts\PERI____.TTF VolumeInformationJump to behavior
            Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.PWSX-gen.11507.25552.exeQueries volume information: C:\Windows\Fonts\PERB____.TTF VolumeInformationJump to behavior
            Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.PWSX-gen.11507.25552.exeQueries volume information: C:\Windows\Fonts\PERBI___.TTF VolumeInformationJump to behavior
            Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.PWSX-gen.11507.25552.exeQueries volume information: C:\Windows\Fonts\PERTILI.TTF VolumeInformationJump to behavior
            Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.PWSX-gen.11507.25552.exeQueries volume information: C:\Windows\Fonts\PERTIBD.TTF VolumeInformationJump to behavior
            Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.PWSX-gen.11507.25552.exeQueries volume information: C:\Windows\Fonts\PLAYBILL.TTF VolumeInformationJump to behavior
            Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.PWSX-gen.11507.25552.exeQueries volume information: C:\Windows\Fonts\POORICH.TTF VolumeInformationJump to behavior
            Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.PWSX-gen.11507.25552.exeQueries volume information: C:\Windows\Fonts\PRISTINA.TTF VolumeInformationJump to behavior
            Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.PWSX-gen.11507.25552.exeQueries volume information: C:\Windows\Fonts\RAGE.TTF VolumeInformationJump to behavior
            Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.PWSX-gen.11507.25552.exeQueries volume information: C:\Windows\Fonts\RAVIE.TTF VolumeInformationJump to behavior
            Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.PWSX-gen.11507.25552.exeQueries volume information: C:\Windows\Fonts\REFSAN.TTF VolumeInformationJump to behavior
            Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.PWSX-gen.11507.25552.exeQueries volume information: C:\Windows\Fonts\REFSPCL.TTF VolumeInformationJump to behavior
            Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.PWSX-gen.11507.25552.exeQueries volume information: C:\Windows\Fonts\ROCK.TTF VolumeInformationJump to behavior
            Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.PWSX-gen.11507.25552.exeQueries volume information: C:\Windows\Fonts\ROCKI.TTF VolumeInformationJump to behavior
            Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.PWSX-gen.11507.25552.exeQueries volume information: C:\Windows\Fonts\ROCKB.TTF VolumeInformationJump to behavior
            Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.PWSX-gen.11507.25552.exeQueries volume information: C:\Windows\Fonts\ROCKEB.TTF VolumeInformationJump to behavior
            Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.PWSX-gen.11507.25552.exeQueries volume information: C:\Windows\Fonts\ROCKBI.TTF VolumeInformationJump to behavior
            Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.PWSX-gen.11507.25552.exeQueries volume information: C:\Windows\Fonts\ROCC____.TTF VolumeInformationJump to behavior
            Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.PWSX-gen.11507.25552.exeQueries volume information: C:\Windows\Fonts\ROCCB___.TTF VolumeInformationJump to behavior
            Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.PWSX-gen.11507.25552.exeQueries volume information: C:\Windows\Fonts\SCRIPTBL.TTF VolumeInformationJump to behavior
            Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.PWSX-gen.11507.25552.exeQueries volume information: C:\Windows\Fonts\SHOWG.TTF VolumeInformationJump to behavior
            Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.PWSX-gen.11507.25552.exeQueries volume information: C:\Windows\Fonts\SNAP____.TTF VolumeInformationJump to behavior
            Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.PWSX-gen.11507.25552.exeQueries volume information: C:\Windows\Fonts\STENCIL.TTF VolumeInformationJump to behavior
            Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.PWSX-gen.11507.25552.exeQueries volume information: C:\Windows\Fonts\TCM_____.TTF VolumeInformationJump to behavior
            Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.PWSX-gen.11507.25552.exeQueries volume information: C:\Windows\Fonts\TCMI____.TTF VolumeInformationJump to behavior
            Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.PWSX-gen.11507.25552.exeQueries volume information: C:\Windows\Fonts\TCB_____.TTF VolumeInformationJump to behavior
            Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.PWSX-gen.11507.25552.exeQueries volume information: C:\Windows\Fonts\TCBI____.TTF VolumeInformationJump to behavior
            Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.PWSX-gen.11507.25552.exeQueries volume information: C:\Windows\Fonts\TCCM____.TTF VolumeInformationJump to behavior
            Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.PWSX-gen.11507.25552.exeQueries volume information: C:\Windows\Fonts\TCCB____.TTF VolumeInformationJump to behavior
            Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.PWSX-gen.11507.25552.exeQueries volume information: C:\Windows\Fonts\TCCEB.TTF VolumeInformationJump to behavior
            Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.PWSX-gen.11507.25552.exeQueries volume information: C:\Windows\Fonts\TEMPSITC.TTF VolumeInformationJump to behavior
            Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.PWSX-gen.11507.25552.exeQueries volume information: C:\Windows\Fonts\VINERITC.TTF VolumeInformationJump to behavior
            Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.PWSX-gen.11507.25552.exeQueries volume information: C:\Windows\Fonts\VIVALDII.TTF VolumeInformationJump to behavior
            Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.PWSX-gen.11507.25552.exeQueries volume information: C:\Windows\Fonts\VLADIMIR.TTF VolumeInformationJump to behavior
            Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.PWSX-gen.11507.25552.exeQueries volume information: C:\Windows\Fonts\WINGDNG2.TTF VolumeInformationJump to behavior
            Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.PWSX-gen.11507.25552.exeQueries volume information: C:\Windows\Fonts\WINGDNG3.TTF VolumeInformationJump to behavior
            Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.PWSX-gen.11507.25552.exeQueries volume information: C:\Windows\Fonts\flat_officeFontsPreview.ttf VolumeInformationJump to behavior
            Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.PWSX-gen.11507.25552.exeQueries volume information: C:\Windows\Fonts\OFFSYM.TTF VolumeInformationJump to behavior
            Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.PWSX-gen.11507.25552.exeQueries volume information: C:\Windows\Fonts\OFFSYMSL.TTF VolumeInformationJump to behavior
            Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.PWSX-gen.11507.25552.exeQueries volume information: C:\Windows\Fonts\OFFSYMSB.TTF VolumeInformationJump to behavior
            Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.PWSX-gen.11507.25552.exeQueries volume information: C:\Windows\Fonts\OFFSYMXL.TTF VolumeInformationJump to behavior
            Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.PWSX-gen.11507.25552.exeQueries volume information: C:\Windows\Fonts\OFFSYML.TTF VolumeInformationJump to behavior
            Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.PWSX-gen.11507.25552.exeQueries volume information: C:\Windows\Fonts\OFFSYMB.TTF VolumeInformationJump to behavior
            Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.PWSX-gen.11507.25552.exeQueries volume information: C:\Windows\Fonts\micross.ttf VolumeInformationJump to behavior
            Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.PWSX-gen.11507.25552.exeQueries volume information: C:\Windows\Microsoft.NET\assembly\GAC_MSIL\Microsoft.VisualBasic\v4.0_10.0.0.0__b03f5f7f11d50a3a\Microsoft.VisualBasic.dll VolumeInformationJump to behavior
            Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.PWSX-gen.11507.25552.exeQueries volume information: C:\Users\user\Desktop\SecuriteInfo.com.Win32.PWSX-gen.11507.25552.exe VolumeInformationJump to behavior
            Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.PWSX-gen.11507.25552.exeQueries volume information: C:\Windows\Microsoft.NET\assembly\GAC_MSIL\System.Windows.Forms\v4.0_4.0.0.0__b77a5c561934e089\System.Windows.Forms.dll VolumeInformationJump to behavior
            Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.PWSX-gen.11507.25552.exeQueries volume information: C:\Windows\Microsoft.NET\assembly\GAC_MSIL\Microsoft.VisualBasic\v4.0_10.0.0.0__b03f5f7f11d50a3a\Microsoft.VisualBasic.dll VolumeInformationJump to behavior
            Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.PWSX-gen.11507.25552.exeQueries volume information: C:\Windows\Microsoft.NET\assembly\GAC_MSIL\System.Security\v4.0_4.0.0.0__b03f5f7f11d50a3a\System.Security.dll VolumeInformationJump to behavior
            Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.PWSX-gen.11507.25552.exeQueries volume information: C:\Windows\Microsoft.NET\assembly\GAC_MSIL\System.Web.Extensions\v4.0_4.0.0.0__31bf3856ad364e35\System.Web.Extensions.dll VolumeInformationJump to behavior
            Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.PWSX-gen.11507.25552.exeQueries volume information: C:\Windows\Microsoft.NET\assembly\GAC_MSIL\System.Drawing\v4.0_4.0.0.0__b03f5f7f11d50a3a\System.Drawing.dll VolumeInformationJump to behavior
            Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.PWSX-gen.11507.25552.exeQueries volume information: C:\Windows\Microsoft.NET\assembly\GAC_MSIL\Accessibility\v4.0_4.0.0.0__b03f5f7f11d50a3a\Accessibility.dll VolumeInformationJump to behavior
            Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.PWSX-gen.11507.25552.exeKey value queried: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Cryptography MachineGuidJump to behavior

            Stealing of Sensitive Information

            barindex
            Source: Yara matchFile source: 0.2.SecuriteInfo.com.Win32.PWSX-gen.11507.25552.exe.429a390.0.unpack, type: UNPACKEDPE
            Source: Yara matchFile source: 0.2.SecuriteInfo.com.Win32.PWSX-gen.11507.25552.exe.4279970.1.unpack, type: UNPACKEDPE
            Source: Yara matchFile source: 2.2.SecuriteInfo.com.Win32.PWSX-gen.11507.25552.exe.400000.0.unpack, type: UNPACKEDPE
            Source: Yara matchFile source: 0.2.SecuriteInfo.com.Win32.PWSX-gen.11507.25552.exe.429a390.0.raw.unpack, type: UNPACKEDPE
            Source: Yara matchFile source: 0.2.SecuriteInfo.com.Win32.PWSX-gen.11507.25552.exe.4279970.1.raw.unpack, type: UNPACKEDPE
            Source: Yara matchFile source: 00000002.00000002.3645837674.0000000000402000.00000040.00000400.00020000.00000000.sdmp, type: MEMORY
            Source: Yara matchFile source: 00000002.00000002.3647546568.00000000032EB000.00000004.00000800.00020000.00000000.sdmp, type: MEMORY
            Source: Yara matchFile source: 00000000.00000002.1209255105.0000000004278000.00000004.00000800.00020000.00000000.sdmp, type: MEMORY
            Source: Yara matchFile source: 00000002.00000002.3647546568.0000000003121000.00000004.00000800.00020000.00000000.sdmp, type: MEMORY
            Source: Yara matchFile source: Process Memory Space: SecuriteInfo.com.Win32.PWSX-gen.11507.25552.exe PID: 6516, type: MEMORYSTR
            Source: Yara matchFile source: Process Memory Space: SecuriteInfo.com.Win32.PWSX-gen.11507.25552.exe PID: 1692, type: MEMORYSTR
            Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.PWSX-gen.11507.25552.exeFile opened: C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Login DataJump to behavior
            Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.PWSX-gen.11507.25552.exeFile opened: C:\Users\user\AppData\Local\Microsoft\Edge\User Data\Default\Login DataJump to behavior
            Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.PWSX-gen.11507.25552.exeFile opened: C:\Users\user\AppData\Roaming\PostboxApp\Profiles\Jump to behavior
            Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.PWSX-gen.11507.25552.exeKey opened: HKEY_CURRENT_USER\Software\Microsoft\Windows NT\CurrentVersion\Windows Messaging Subsystem\Profiles\Outlook\9375CFF0413111d3B88A00104B2A6676Jump to behavior
            Source: Yara matchFile source: 0.2.SecuriteInfo.com.Win32.PWSX-gen.11507.25552.exe.429a390.0.unpack, type: UNPACKEDPE
            Source: Yara matchFile source: 0.2.SecuriteInfo.com.Win32.PWSX-gen.11507.25552.exe.4279970.1.unpack, type: UNPACKEDPE
            Source: Yara matchFile source: 2.2.SecuriteInfo.com.Win32.PWSX-gen.11507.25552.exe.400000.0.unpack, type: UNPACKEDPE
            Source: Yara matchFile source: 0.2.SecuriteInfo.com.Win32.PWSX-gen.11507.25552.exe.429a390.0.raw.unpack, type: UNPACKEDPE
            Source: Yara matchFile source: 0.2.SecuriteInfo.com.Win32.PWSX-gen.11507.25552.exe.4279970.1.raw.unpack, type: UNPACKEDPE
            Source: Yara matchFile source: 00000002.00000002.3645837674.0000000000402000.00000040.00000400.00020000.00000000.sdmp, type: MEMORY
            Source: Yara matchFile source: 00000000.00000002.1209255105.0000000004278000.00000004.00000800.00020000.00000000.sdmp, type: MEMORY
            Source: Yara matchFile source: Process Memory Space: SecuriteInfo.com.Win32.PWSX-gen.11507.25552.exe PID: 6516, type: MEMORYSTR
            Source: Yara matchFile source: Process Memory Space: SecuriteInfo.com.Win32.PWSX-gen.11507.25552.exe PID: 1692, type: MEMORYSTR

            Remote Access Functionality

            barindex
            Source: Yara matchFile source: 0.2.SecuriteInfo.com.Win32.PWSX-gen.11507.25552.exe.429a390.0.unpack, type: UNPACKEDPE
            Source: Yara matchFile source: 0.2.SecuriteInfo.com.Win32.PWSX-gen.11507.25552.exe.4279970.1.unpack, type: UNPACKEDPE
            Source: Yara matchFile source: 2.2.SecuriteInfo.com.Win32.PWSX-gen.11507.25552.exe.400000.0.unpack, type: UNPACKEDPE
            Source: Yara matchFile source: 0.2.SecuriteInfo.com.Win32.PWSX-gen.11507.25552.exe.429a390.0.raw.unpack, type: UNPACKEDPE
            Source: Yara matchFile source: 0.2.SecuriteInfo.com.Win32.PWSX-gen.11507.25552.exe.4279970.1.raw.unpack, type: UNPACKEDPE
            Source: Yara matchFile source: 00000002.00000002.3645837674.0000000000402000.00000040.00000400.00020000.00000000.sdmp, type: MEMORY
            Source: Yara matchFile source: 00000002.00000002.3647546568.00000000032EB000.00000004.00000800.00020000.00000000.sdmp, type: MEMORY
            Source: Yara matchFile source: 00000000.00000002.1209255105.0000000004278000.00000004.00000800.00020000.00000000.sdmp, type: MEMORY
            Source: Yara matchFile source: 00000002.00000002.3647546568.0000000003121000.00000004.00000800.00020000.00000000.sdmp, type: MEMORY
            Source: Yara matchFile source: Process Memory Space: SecuriteInfo.com.Win32.PWSX-gen.11507.25552.exe PID: 6516, type: MEMORYSTR
            Source: Yara matchFile source: Process Memory Space: SecuriteInfo.com.Win32.PWSX-gen.11507.25552.exe PID: 1692, type: MEMORYSTR
            ReconnaissanceResource DevelopmentInitial AccessExecutionPersistencePrivilege EscalationDefense EvasionCredential AccessDiscoveryLateral MovementCollectionCommand and ControlExfiltrationImpact
            Gather Victim Identity InformationAcquire InfrastructureValid AccountsWindows Management Instrumentation1
            DLL Side-Loading
            111
            Process Injection
            1
            Masquerading
            1
            OS Credential Dumping
            1
            Security Software Discovery
            Remote Services1
            Email Collection
            11
            Encrypted Channel
            Exfiltration Over Other Network MediumAbuse Accessibility Features
            CredentialsDomainsDefault AccountsScheduled Task/JobBoot or Logon Initialization Scripts1
            DLL Side-Loading
            1
            Disable or Modify Tools
            LSASS Memory1
            Process Discovery
            Remote Desktop Protocol11
            Archive Collected Data
            1
            Ingress Tool Transfer
            Exfiltration Over BluetoothNetwork Denial of Service
            Email AddressesDNS ServerDomain AccountsAtLogon Script (Windows)Logon Script (Windows)31
            Virtualization/Sandbox Evasion
            Security Account Manager31
            Virtualization/Sandbox Evasion
            SMB/Windows Admin Shares1
            Data from Local System
            2
            Non-Application Layer Protocol
            Automated ExfiltrationData Encrypted for Impact
            Employee NamesVirtual Private ServerLocal AccountsCronLogin HookLogin Hook111
            Process Injection
            NTDS1
            Application Window Discovery
            Distributed Component Object ModelInput Capture13
            Application Layer Protocol
            Traffic DuplicationData Destruction
            Gather Victim Network InformationServerCloud AccountsLaunchdNetwork Logon ScriptNetwork Logon Script1
            Deobfuscate/Decode Files or Information
            LSA Secrets1
            System Network Configuration Discovery
            SSHKeyloggingFallback ChannelsScheduled TransferData Encrypted for Impact
            Domain PropertiesBotnetReplication Through Removable MediaScheduled TaskRC ScriptsRC Scripts31
            Obfuscated Files or Information
            Cached Domain Credentials13
            System Information Discovery
            VNCGUI Input CaptureMultiband CommunicationData Transfer Size LimitsService Stop
            DNSWeb ServicesExternal Remote ServicesSystemd TimersStartup ItemsStartup Items12
            Software Packing
            DCSyncRemote System DiscoveryWindows Remote ManagementWeb Portal CaptureCommonly Used PortExfiltration Over C2 ChannelInhibit System Recovery
            Network Trust DependenciesServerlessDrive-by CompromiseContainer Orchestration JobScheduled Task/JobScheduled Task/Job1
            DLL Side-Loading
            Proc FilesystemSystem Owner/User DiscoveryCloud ServicesCredential API HookingApplication Layer ProtocolExfiltration Over Alternative ProtocolDefacement

            This section contains all screenshots as thumbnails, including those not shown in the slideshow.