Source: Yara match | File source: 00000011.00000002.620217311.0000000003F19000.00000004.00000001.sdmp, type: MEMORY |
Source: Yara match | File source: 0000000C.00000002.623749902.0000000004231000.00000004.00000001.sdmp, type: MEMORY |
Source: Yara match | File source: 0000000C.00000002.624626944.0000000004DB7000.00000004.00000001.sdmp, type: MEMORY |
Source: Yara match | File source: 00000011.00000002.624595498.0000000005A80000.00000004.00000001.sdmp, type: MEMORY |
Source: Yara match | File source: 0000000C.00000002.624416649.0000000004CEA000.00000004.00000001.sdmp, type: MEMORY |
Source: Yara match | File source: 00000011.00000002.615389852.0000000002ED1000.00000004.00000001.sdmp, type: MEMORY |
Source: Yara match | File source: 00000011.00000002.607848743.0000000000402000.00000040.00000001.sdmp, type: MEMORY |
Source: Yara match | File source: Process Memory Space: AddInProcess32.exe PID: 1256, type: MEMORY |
Source: Yara match | File source: Process Memory Space: demiusda.exe PID: 1240, type: MEMORY |
Source: Yara match | File source: 17.2.AddInProcess32.exe.5a80000.6.raw.unpack, type: UNPACKEDPE |
Source: Yara match | File source: 17.2.AddInProcess32.exe.5a80000.6.unpack, type: UNPACKEDPE |
Source: Yara match | File source: 17.2.AddInProcess32.exe.400000.0.unpack, type: UNPACKEDPE |
Source: C:\Users\user\Desktop\DHL_file 187652345643476245.exe | Code function: 4x nop then jmp 02DAF636h | 0_2_02DAEE70 |
Source: C:\Users\user\Desktop\DHL_file 187652345643476245.exe | Code function: 4x nop then jmp 02DAF636h | 0_2_02DAEE62 |
Source: C:\Users\user\Desktop\DHL_file 187652345643476245.exe | Code function: 4x nop then jmp 02DAF636h | 0_2_02DAEE28 |
Source: C:\Users\user\Desktop\DHL_file 187652345643476245.exe | Code function: 4x nop then lea esp, dword ptr [ebp-08h] | 0_2_057AB160 |
Source: C:\Users\user\Desktop\DHL_file 187652345643476245.exe | Code function: 4x nop then mov dword ptr [ebp-1Ch], 00000000h | 0_2_057A5D80 |
Source: C:\Users\user\Desktop\DHL_file 187652345643476245.exe | Code function: 4x nop then mov dword ptr [ebp-1Ch], 00000000h | 0_2_057A3E0C |
Source: C:\Users\user\Desktop\DHL_file 187652345643476245.exe | Code function: 4x nop then lea esp, dword ptr [ebp-08h] | 0_2_057ADEB8 |
Source: C:\Users\user\Desktop\DHL_file 187652345643476245.exe | Code function: 4x nop then push dword ptr [ebp-24h] | 0_2_057A4BC8 |
Source: C:\Users\user\Desktop\DHL_file 187652345643476245.exe | Code function: 4x nop then mov dword ptr [ebp-1Ch], 7FFFFFFFh | 0_2_057A4BC8 |
Source: C:\Users\user\Desktop\DHL_file 187652345643476245.exe | Code function: 4x nop then mov esp, ebp | 0_2_057ACAB0 |
Source: C:\Users\user\Desktop\DHL_file 187652345643476245.exe | Code function: 4x nop then lea esp, dword ptr [ebp-08h] | 0_2_057AB153 |
Source: C:\Users\user\Desktop\DHL_file 187652345643476245.exe | Code function: 4x nop then mov dword ptr [ebp-1Ch], 00000000h | 0_2_057A43C5 |
Source: C:\Users\user\Desktop\DHL_file 187652345643476245.exe | Code function: 4x nop then lea esp, dword ptr [ebp-08h] | 0_2_057ADF90 |
Source: C:\Users\user\Desktop\DHL_file 187652345643476245.exe | Code function: 4x nop then mov dword ptr [ebp-1Ch], 00000000h | 0_2_057A5E60 |
Source: C:\Users\user\Desktop\DHL_file 187652345643476245.exe | Code function: 4x nop then lea esp, dword ptr [ebp-08h] | 0_2_057ADEA8 |
Source: C:\Users\user\Desktop\DHL_file 187652345643476245.exe | Code function: 4x nop then push dword ptr [ebp-20h] | 0_2_057A48A8 |
Source: C:\Users\user\Desktop\DHL_file 187652345643476245.exe | Code function: 4x nop then mov dword ptr [ebp-1Ch], 7FFFFFFFh | 0_2_057A48A8 |
Source: C:\Users\user\Desktop\DHL_file 187652345643476245.exe | Code function: 4x nop then push dword ptr [ebp-20h] | 0_2_057A489D |
Source: C:\Users\user\Desktop\DHL_file 187652345643476245.exe | Code function: 4x nop then mov dword ptr [ebp-1Ch], 7FFFFFFFh | 0_2_057A489D |
Source: C:\Users\user\Desktop\DHL_file 187652345643476245.exe | Code function: 4x nop then xor edx, edx | 0_2_057A4B00 |
Source: C:\Users\user\Desktop\DHL_file 187652345643476245.exe | Code function: 4x nop then mov dword ptr [ebp-1Ch], 00000000h | 0_2_057A6BFC |
Source: C:\Users\user\Desktop\DHL_file 187652345643476245.exe | Code function: 4x nop then push dword ptr [ebp-24h] | 0_2_057A4BBD |
Source: C:\Users\user\Desktop\DHL_file 187652345643476245.exe | Code function: 4x nop then mov dword ptr [ebp-1Ch], 7FFFFFFFh | 0_2_057A4BBD |
Source: C:\Users\user\Desktop\DHL_file 187652345643476245.exe | Code function: 4x nop then xor edx, edx | 0_2_057A4AF4 |
Source: C:\Users\user\Desktop\DHL_file 187652345643476245.exe | Code function: 4x nop then mov esp, ebp | 0_2_057ACAA1 |
Source: C:\Users\user\AppData\Roaming\demiusda.exe | Code function: 4x nop then jmp 0318F636h | 12_2_0318ED7F |
Source: C:\Users\user\AppData\Roaming\demiusda.exe | Code function: 4x nop then jmp 0318F636h | 12_2_0318EE63 |
Source: C:\Users\user\AppData\Roaming\demiusda.exe | Code function: 4x nop then jmp 058891E7h | 12_2_058890B8 |
Source: C:\Users\user\AppData\Roaming\demiusda.exe | Code function: 4x nop then jmp 0588868Eh | 12_2_05888588 |
Source: C:\Users\user\AppData\Roaming\demiusda.exe | Code function: 4x nop then jmp 0588868Eh | 12_2_05888598 |
Source: C:\Users\user\AppData\Roaming\demiusda.exe | Code function: 4x nop then jmp 058891E7h | 12_2_058890A8 |
Source: C:\Users\user\AppData\Roaming\demiusda.exe | Code function: 4x nop then jmp 058891E7h | 12_2_0588921B |
Source: C:\Users\user\AppData\Local\Temp\watchprcss.exe | Code function: 4x nop then jmp 015E0799h | 19_2_015E0560 |
Source: C:\Users\user\AppData\Local\Temp\watchprcss.exe | Code function: 4x nop then jmp 015E0799h | 19_2_015E0553 |
Source: C:\Users\user\AppData\Local\Temp\watchprcss.exe | Code function: 4x nop then jmp 02700799h | 20_2_02700560 |
Source: C:\Users\user\AppData\Local\Temp\watchprcss.exe | Code function: 4x nop then jmp 02700799h | 20_2_02700551 |
Source: C:\Users\user\AppData\Local\Temp\watchprcss.exe | Code function: 4x nop then jmp 032E0799h | 22_2_032E0560 |
Source: C:\Users\user\AppData\Local\Temp\watchprcss.exe | Code function: 4x nop then jmp 032E0799h | 22_2_032E0552 |
Source: Yara match | File source: 00000011.00000002.620217311.0000000003F19000.00000004.00000001.sdmp, type: MEMORY |
Source: Yara match | File source: 0000000C.00000002.623749902.0000000004231000.00000004.00000001.sdmp, type: MEMORY |
Source: Yara match | File source: 0000000C.00000002.624626944.0000000004DB7000.00000004.00000001.sdmp, type: MEMORY |
Source: Yara match | File source: 00000011.00000002.624595498.0000000005A80000.00000004.00000001.sdmp, type: MEMORY |
Source: Yara match | File source: 0000000C.00000002.624416649.0000000004CEA000.00000004.00000001.sdmp, type: MEMORY |
Source: Yara match | File source: 00000011.00000002.615389852.0000000002ED1000.00000004.00000001.sdmp, type: MEMORY |
Source: Yara match | File source: 00000011.00000002.607848743.0000000000402000.00000040.00000001.sdmp, type: MEMORY |
Source: Yara match | File source: Process Memory Space: AddInProcess32.exe PID: 1256, type: MEMORY |
Source: Yara match | File source: Process Memory Space: demiusda.exe PID: 1240, type: MEMORY |
Source: Yara match | File source: 17.2.AddInProcess32.exe.5a80000.6.raw.unpack, type: UNPACKEDPE |
Source: Yara match | File source: 17.2.AddInProcess32.exe.5a80000.6.unpack, type: UNPACKEDPE |
Source: Yara match | File source: 17.2.AddInProcess32.exe.400000.0.unpack, type: UNPACKEDPE |
Source: 00000011.00000002.624186822.0000000005610000.00000004.00000001.sdmp, type: MEMORY | Matched rule: Detetcs the Nanocore RAT Author: Florian Roth |
Source: 00000011.00000002.620217311.0000000003F19000.00000004.00000001.sdmp, type: MEMORY | Matched rule: NanoCore Author: Kevin Breen <kevin@techanarchy.net> |
Source: 0000000C.00000002.623749902.0000000004231000.00000004.00000001.sdmp, type: MEMORY | Matched rule: Detetcs the Nanocore RAT Author: Florian Roth |
Source: 0000000C.00000002.623749902.0000000004231000.00000004.00000001.sdmp, type: MEMORY | Matched rule: NanoCore Author: Kevin Breen <kevin@techanarchy.net> |
Source: 0000000C.00000002.624626944.0000000004DB7000.00000004.00000001.sdmp, type: MEMORY | Matched rule: Detetcs the Nanocore RAT Author: Florian Roth |
Source: 0000000C.00000002.624626944.0000000004DB7000.00000004.00000001.sdmp, type: MEMORY | Matched rule: NanoCore Author: Kevin Breen <kevin@techanarchy.net> |
Source: 00000011.00000002.624595498.0000000005A80000.00000004.00000001.sdmp, type: MEMORY | Matched rule: Detetcs the Nanocore RAT Author: Florian Roth |
Source: 0000000C.00000002.624416649.0000000004CEA000.00000004.00000001.sdmp, type: MEMORY | Matched rule: Detetcs the Nanocore RAT Author: Florian Roth |
Source: 0000000C.00000002.624416649.0000000004CEA000.00000004.00000001.sdmp, type: MEMORY | Matched rule: NanoCore Author: Kevin Breen <kevin@techanarchy.net> |
Source: 00000011.00000002.607848743.0000000000402000.00000040.00000001.sdmp, type: MEMORY | Matched rule: Detetcs the Nanocore RAT Author: Florian Roth |
Source: 00000011.00000002.607848743.0000000000402000.00000040.00000001.sdmp, type: MEMORY | Matched rule: NanoCore Author: Kevin Breen <kevin@techanarchy.net> |
Source: Process Memory Space: AddInProcess32.exe PID: 1256, type: MEMORY | Matched rule: Detetcs the Nanocore RAT Author: Florian Roth |
Source: Process Memory Space: AddInProcess32.exe PID: 1256, type: MEMORY | Matched rule: NanoCore Author: Kevin Breen <kevin@techanarchy.net> |
Source: Process Memory Space: demiusda.exe PID: 1240, type: MEMORY | Matched rule: Detetcs the Nanocore RAT Author: Florian Roth |
Source: Process Memory Space: demiusda.exe PID: 1240, type: MEMORY | Matched rule: NanoCore Author: Kevin Breen <kevin@techanarchy.net> |
Source: 17.2.AddInProcess32.exe.5a80000.6.raw.unpack, type: UNPACKEDPE | Matched rule: Detetcs the Nanocore RAT Author: Florian Roth |
Source: 17.2.AddInProcess32.exe.5610000.3.raw.unpack, type: UNPACKEDPE | Matched rule: Detetcs the Nanocore RAT Author: Florian Roth |
Source: 17.2.AddInProcess32.exe.5a80000.6.unpack, type: UNPACKEDPE | Matched rule: Detetcs the Nanocore RAT Author: Florian Roth |
Source: 17.2.AddInProcess32.exe.400000.0.unpack, type: UNPACKEDPE | Matched rule: Detetcs the Nanocore RAT Author: Florian Roth |
Source: 17.2.AddInProcess32.exe.400000.0.unpack, type: UNPACKEDPE | Matched rule: NanoCore Author: Kevin Breen <kevin@techanarchy.net> |
Source: C:\Users\user\Desktop\DHL_file 187652345643476245.exe | Code function: 0_2_00BC471C | 0_2_00BC471C |
Source: C:\Users\user\Desktop\DHL_file 187652345643476245.exe | Code function: 0_2_02DA4098 | 0_2_02DA4098 |
Source: C:\Users\user\Desktop\DHL_file 187652345643476245.exe | Code function: 0_2_02DA4800 | 0_2_02DA4800 |
Source: C:\Users\user\Desktop\DHL_file 187652345643476245.exe | Code function: 0_2_02DAA918 | 0_2_02DAA918 |
Source: C:\Users\user\Desktop\DHL_file 187652345643476245.exe | Code function: 0_2_02DAEE70 | 0_2_02DAEE70 |
Source: C:\Users\user\Desktop\DHL_file 187652345643476245.exe | Code function: 0_2_02DA9E20 | 0_2_02DA9E20 |
Source: C:\Users\user\Desktop\DHL_file 187652345643476245.exe | Code function: 0_2_02DAF768 | 0_2_02DAF768 |
Source: C:\Users\user\Desktop\DHL_file 187652345643476245.exe | Code function: 0_2_02DAD700 | 0_2_02DAD700 |
Source: C:\Users\user\Desktop\DHL_file 187652345643476245.exe | Code function: 0_2_02DABC40 | 0_2_02DABC40 |
Source: C:\Users\user\Desktop\DHL_file 187652345643476245.exe | Code function: 0_2_02DA7C20 | 0_2_02DA7C20 |
Source: C:\Users\user\Desktop\DHL_file 187652345643476245.exe | Code function: 0_2_02DAA909 | 0_2_02DAA909 |
Source: C:\Users\user\Desktop\DHL_file 187652345643476245.exe | Code function: 0_2_02DAD6F0 | 0_2_02DAD6F0 |
Source: C:\Users\user\Desktop\DHL_file 187652345643476245.exe | Code function: 0_2_02DAEE62 | 0_2_02DAEE62 |
Source: C:\Users\user\Desktop\DHL_file 187652345643476245.exe | Code function: 0_2_02DA9E10 | 0_2_02DA9E10 |
Source: C:\Users\user\Desktop\DHL_file 187652345643476245.exe | Code function: 0_2_02DAEE28 | 0_2_02DAEE28 |
Source: C:\Users\user\Desktop\DHL_file 187652345643476245.exe | Code function: 0_2_02DAF758 | 0_2_02DAF758 |
Source: C:\Users\user\Desktop\DHL_file 187652345643476245.exe | Code function: 0_2_02DABC30 | 0_2_02DABC30 |
Source: C:\Users\user\Desktop\DHL_file 187652345643476245.exe | Code function: 0_2_057A87F8 | 0_2_057A87F8 |
Source: C:\Users\user\Desktop\DHL_file 187652345643476245.exe | Code function: 0_2_057A5930 | 0_2_057A5930 |
Source: C:\Users\user\Desktop\DHL_file 187652345643476245.exe | Code function: 0_2_057ABA00 | 0_2_057ABA00 |
Source: C:\Users\user\Desktop\DHL_file 187652345643476245.exe | Code function: 0_2_057AC520 | 0_2_057AC520 |
Source: C:\Users\user\Desktop\DHL_file 187652345643476245.exe | Code function: 0_2_057AC510 | 0_2_057AC510 |
Source: C:\Users\user\Desktop\DHL_file 187652345643476245.exe | Code function: 0_2_057A536F | 0_2_057A536F |
Source: C:\Users\user\Desktop\DHL_file 187652345643476245.exe | Code function: 0_2_057A5380 | 0_2_057A5380 |
Source: C:\Users\user\Desktop\DHL_file 187652345643476245.exe | Code function: 0_2_057A0380 | 0_2_057A0380 |
Source: C:\Users\user\Desktop\DHL_file 187652345643476245.exe | Code function: 0_2_057A5923 | 0_2_057A5923 |
Source: C:\Users\user\Desktop\DHL_file 187652345643476245.exe | Code function: 0_2_057AB9F0 | 0_2_057AB9F0 |
Source: C:\Users\user\Desktop\DHL_file 187652345643476245.exe | Code function: 0_2_057AB9B0 | 0_2_057AB9B0 |
Source: C:\Users\user\AppData\Roaming\demiusda.exe | Code function: 12_2_03187BB0 | 12_2_03187BB0 |
Source: C:\Users\user\AppData\Roaming\demiusda.exe | Code function: 12_2_0318A909 | 12_2_0318A909 |
Source: C:\Users\user\AppData\Roaming\demiusda.exe | Code function: 12_2_03184098 | 12_2_03184098 |
Source: C:\Users\user\AppData\Roaming\demiusda.exe | Code function: 12_2_0318F768 | 12_2_0318F768 |
Source: C:\Users\user\AppData\Roaming\demiusda.exe | Code function: 12_2_03189E10 | 12_2_03189E10 |
Source: C:\Users\user\AppData\Roaming\demiusda.exe | Code function: 12_2_0318D6F0 | 12_2_0318D6F0 |
Source: C:\Users\user\AppData\Roaming\demiusda.exe | Code function: 12_2_0318ED7F | 12_2_0318ED7F |
Source: C:\Users\user\AppData\Roaming\demiusda.exe | Code function: 12_2_0318BC30 | 12_2_0318BC30 |
Source: C:\Users\user\AppData\Roaming\demiusda.exe | Code function: 12_2_0318F758 | 12_2_0318F758 |
Source: C:\Users\user\AppData\Roaming\demiusda.exe | Code function: 12_2_0318EE63 | 12_2_0318EE63 |
Source: C:\Users\user\AppData\Roaming\demiusda.exe | Code function: 12_2_05880CC8 | 12_2_05880CC8 |
Source: C:\Users\user\AppData\Roaming\demiusda.exe | Code function: 12_2_058813F8 | 12_2_058813F8 |
Source: C:\Users\user\AppData\Roaming\demiusda.exe | Code function: 12_2_05885B00 | 12_2_05885B00 |
Source: C:\Users\user\AppData\Roaming\demiusda.exe | Code function: 12_2_05883210 | 12_2_05883210 |
Source: C:\Users\user\AppData\Roaming\demiusda.exe | Code function: 12_2_058849A8 | 12_2_058849A8 |
Source: C:\Users\user\AppData\Roaming\demiusda.exe | Code function: 12_2_058829C7 | 12_2_058829C7 |
Source: C:\Users\user\AppData\Roaming\demiusda.exe | Code function: 12_2_058829D8 | 12_2_058829D8 |
Source: C:\Users\user\AppData\Roaming\demiusda.exe | Code function: 12_2_05882550 | 12_2_05882550 |
Source: C:\Users\user\AppData\Roaming\demiusda.exe | Code function: 12_2_05882560 | 12_2_05882560 |
Source: C:\Users\user\AppData\Roaming\demiusda.exe | Code function: 12_2_05880CB8 | 12_2_05880CB8 |
Source: C:\Users\user\AppData\Roaming\demiusda.exe | Code function: 12_2_05883C60 | 12_2_05883C60 |
Source: C:\Users\user\AppData\Roaming\demiusda.exe | Code function: 12_2_05883C70 | 12_2_05883C70 |
Source: C:\Users\user\AppData\Roaming\demiusda.exe | Code function: 12_2_058813E8 | 12_2_058813E8 |
Source: C:\Users\user\AppData\Roaming\demiusda.exe | Code function: 12_2_05886720 | 12_2_05886720 |
Source: C:\Users\user\AppData\Roaming\demiusda.exe | Code function: 12_2_05885AF0 | 12_2_05885AF0 |
Source: C:\Users\user\AppData\Roaming\demiusda.exe | Code function: 12_2_05883200 | 12_2_05883200 |
Source: C:\Users\user\AppData\Local\Temp\AddInProcess32.exe | Code function: 17_2_00B12050 | 17_2_00B12050 |
Source: C:\Users\user\AppData\Local\Temp\AddInProcess32.exe | Code function: 17_2_013EE471 | 17_2_013EE471 |
Source: C:\Users\user\AppData\Local\Temp\AddInProcess32.exe | Code function: 17_2_013EE480 | 17_2_013EE480 |
Source: C:\Users\user\AppData\Local\Temp\AddInProcess32.exe | Code function: 17_2_013EBBD4 | 17_2_013EBBD4 |
Source: C:\Users\user\AppData\Local\Temp\AddInProcess32.exe | Code function: 17_2_0557F5F8 | 17_2_0557F5F8 |
Source: C:\Users\user\AppData\Local\Temp\AddInProcess32.exe | Code function: 17_2_05579788 | 17_2_05579788 |
Source: C:\Users\user\AppData\Local\Temp\AddInProcess32.exe | Code function: 17_2_0557A602 | 17_2_0557A602 |
Source: DHL_file 187652345643476245.exe, 00000000.00000002.310619825.0000000005690000.00000002.00000001.sdmp | Binary or memory string: OriginalFilenamemscorrc.dllT vs DHL_file 187652345643476245.exe |
Source: DHL_file 187652345643476245.exe, 00000000.00000002.309186882.0000000004F30000.00000002.00000001.sdmp | Binary or memory string: originalfilename vs DHL_file 187652345643476245.exe |
Source: DHL_file 187652345643476245.exe, 00000000.00000002.309186882.0000000004F30000.00000002.00000001.sdmp | Binary or memory string: OriginalFilenamepropsys.dll.mui@ vs DHL_file 187652345643476245.exe |
Source: DHL_file 187652345643476245.exe, 00000000.00000002.307262138.0000000000C66000.00000002.00020000.sdmp | Binary or memory string: OriginalFilenameemekaike.exeL vs DHL_file 187652345643476245.exe |
Source: DHL_file 187652345643476245.exe, 00000000.00000002.308442097.0000000003F69000.00000004.00000001.sdmp | Binary or memory string: OriginalFilenameSHCore1.dll0 vs DHL_file 187652345643476245.exe |
Source: DHL_file 187652345643476245.exe, 00000000.00000002.309116173.0000000004ED0000.00000002.00000001.sdmp | Binary or memory string: System.OriginalFileName vs DHL_file 187652345643476245.exe |
Source: DHL_file 187652345643476245.exe, 00000000.00000002.312320361.00000000085A0000.00000002.00000001.sdmp | Binary or memory string: OriginalFilenameKernelbase.dll.muij% vs DHL_file 187652345643476245.exe |
Source: DHL_file 187652345643476245.exe | Binary or memory string: OriginalFilenameemekaike.exeL vs DHL_file 187652345643476245.exe |
Source: 00000011.00000002.624186822.0000000005610000.00000004.00000001.sdmp, type: MEMORY | Matched rule: Nanocore_RAT_Gen_2 date = 2016-04-22, hash1 = 755f49a4ffef5b1b62f4b5a5de279868c0c1766b528648febf76628f1fe39050, author = Florian Roth, description = Detetcs the Nanocore RAT, license = https://creativecommons.org/licenses/by-nc/4.0/, score = https://www.sentinelone.com/blogs/teaching-an-old-rat-new-tricks/ |
Source: 00000011.00000002.624186822.0000000005610000.00000004.00000001.sdmp, type: MEMORY | Matched rule: Nanocore_RAT_Feb18_1 date = 2018-02-19, hash1 = aa486173e9d594729dbb5626748ce10a75ee966481b68c1b4f6323c827d9658c, author = Florian Roth, description = Detects Nanocore RAT, reference = Internal Research - T2T, license = https://creativecommons.org/licenses/by-nc/4.0/ |
Source: 00000011.00000002.620217311.0000000003F19000.00000004.00000001.sdmp, type: MEMORY | Matched rule: NanoCore date = 2014/04, filetype = exe, author = Kevin Breen <kevin@techanarchy.net>, maltype = Remote Access Trojan, ref = http://malwareconfig.com/stats/NanoCore |
Source: 0000000C.00000002.623749902.0000000004231000.00000004.00000001.sdmp, type: MEMORY | Matched rule: Nanocore_RAT_Gen_2 date = 2016-04-22, hash1 = 755f49a4ffef5b1b62f4b5a5de279868c0c1766b528648febf76628f1fe39050, author = Florian Roth, description = Detetcs the Nanocore RAT, license = https://creativecommons.org/licenses/by-nc/4.0/, score = https://www.sentinelone.com/blogs/teaching-an-old-rat-new-tricks/ |
Source: 0000000C.00000002.623749902.0000000004231000.00000004.00000001.sdmp, type: MEMORY | Matched rule: NanoCore date = 2014/04, filetype = exe, author = Kevin Breen <kevin@techanarchy.net>, maltype = Remote Access Trojan, ref = http://malwareconfig.com/stats/NanoCore |
Source: 0000000C.00000002.624626944.0000000004DB7000.00000004.00000001.sdmp, type: MEMORY | Matched rule: Nanocore_RAT_Gen_2 date = 2016-04-22, hash1 = 755f49a4ffef5b1b62f4b5a5de279868c0c1766b528648febf76628f1fe39050, author = Florian Roth, description = Detetcs the Nanocore RAT, license = https://creativecommons.org/licenses/by-nc/4.0/, score = https://www.sentinelone.com/blogs/teaching-an-old-rat-new-tricks/ |
Source: 0000000C.00000002.624626944.0000000004DB7000.00000004.00000001.sdmp, type: MEMORY | Matched rule: NanoCore date = 2014/04, filetype = exe, author = Kevin Breen <kevin@techanarchy.net>, maltype = Remote Access Trojan, ref = http://malwareconfig.com/stats/NanoCore |
Source: 00000011.00000002.624595498.0000000005A80000.00000004.00000001.sdmp, type: MEMORY | Matched rule: Nanocore_RAT_Gen_2 date = 2016-04-22, hash1 = 755f49a4ffef5b1b62f4b5a5de279868c0c1766b528648febf76628f1fe39050, author = Florian Roth, description = Detetcs the Nanocore RAT, license = https://creativecommons.org/licenses/by-nc/4.0/, score = https://www.sentinelone.com/blogs/teaching-an-old-rat-new-tricks/ |
Source: 00000011.00000002.624595498.0000000005A80000.00000004.00000001.sdmp, type: MEMORY | Matched rule: Nanocore_RAT_Feb18_1 date = 2018-02-19, hash1 = aa486173e9d594729dbb5626748ce10a75ee966481b68c1b4f6323c827d9658c, author = Florian Roth, description = Detects Nanocore RAT, reference = Internal Research - T2T, license = https://creativecommons.org/licenses/by-nc/4.0/ |
Source: 0000000C.00000002.624416649.0000000004CEA000.00000004.00000001.sdmp, type: MEMORY | Matched rule: Nanocore_RAT_Gen_2 date = 2016-04-22, hash1 = 755f49a4ffef5b1b62f4b5a5de279868c0c1766b528648febf76628f1fe39050, author = Florian Roth, description = Detetcs the Nanocore RAT, license = https://creativecommons.org/licenses/by-nc/4.0/, score = https://www.sentinelone.com/blogs/teaching-an-old-rat-new-tricks/ |
Source: 0000000C.00000002.624416649.0000000004CEA000.00000004.00000001.sdmp, type: MEMORY | Matched rule: NanoCore date = 2014/04, filetype = exe, author = Kevin Breen <kevin@techanarchy.net>, maltype = Remote Access Trojan, ref = http://malwareconfig.com/stats/NanoCore |
Source: 00000011.00000002.607848743.0000000000402000.00000040.00000001.sdmp, type: MEMORY | Matched rule: Nanocore_RAT_Gen_2 date = 2016-04-22, hash1 = 755f49a4ffef5b1b62f4b5a5de279868c0c1766b528648febf76628f1fe39050, author = Florian Roth, description = Detetcs the Nanocore RAT, license = https://creativecommons.org/licenses/by-nc/4.0/, score = https://www.sentinelone.com/blogs/teaching-an-old-rat-new-tricks/ |
Source: 00000011.00000002.607848743.0000000000402000.00000040.00000001.sdmp, type: MEMORY | Matched rule: NanoCore date = 2014/04, filetype = exe, author = Kevin Breen <kevin@techanarchy.net>, maltype = Remote Access Trojan, ref = http://malwareconfig.com/stats/NanoCore |
Source: Process Memory Space: AddInProcess32.exe PID: 1256, type: MEMORY | Matched rule: Nanocore_RAT_Gen_2 date = 2016-04-22, hash1 = 755f49a4ffef5b1b62f4b5a5de279868c0c1766b528648febf76628f1fe39050, author = Florian Roth, description = Detetcs the Nanocore RAT, license = https://creativecommons.org/licenses/by-nc/4.0/, score = https://www.sentinelone.com/blogs/teaching-an-old-rat-new-tricks/ |
Source: Process Memory Space: AddInProcess32.exe PID: 1256, type: MEMORY | Matched rule: NanoCore date = 2014/04, filetype = exe, author = Kevin Breen <kevin@techanarchy.net>, maltype = Remote Access Trojan, ref = http://malwareconfig.com/stats/NanoCore |
Source: Process Memory Space: demiusda.exe PID: 1240, type: MEMORY | Matched rule: Nanocore_RAT_Gen_2 date = 2016-04-22, hash1 = 755f49a4ffef5b1b62f4b5a5de279868c0c1766b528648febf76628f1fe39050, author = Florian Roth, description = Detetcs the Nanocore RAT, license = https://creativecommons.org/licenses/by-nc/4.0/, score = https://www.sentinelone.com/blogs/teaching-an-old-rat-new-tricks/ |
Source: Process Memory Space: demiusda.exe PID: 1240, type: MEMORY | Matched rule: NanoCore date = 2014/04, filetype = exe, author = Kevin Breen <kevin@techanarchy.net>, maltype = Remote Access Trojan, ref = http://malwareconfig.com/stats/NanoCore |
Source: 17.2.AddInProcess32.exe.5a80000.6.raw.unpack, type: UNPACKEDPE | Matched rule: Nanocore_RAT_Gen_2 date = 2016-04-22, hash1 = 755f49a4ffef5b1b62f4b5a5de279868c0c1766b528648febf76628f1fe39050, author = Florian Roth, description = Detetcs the Nanocore RAT, license = https://creativecommons.org/licenses/by-nc/4.0/, score = https://www.sentinelone.com/blogs/teaching-an-old-rat-new-tricks/ |
Source: 17.2.AddInProcess32.exe.5a80000.6.raw.unpack, type: UNPACKEDPE | Matched rule: Nanocore_RAT_Feb18_1 date = 2018-02-19, hash1 = aa486173e9d594729dbb5626748ce10a75ee966481b68c1b4f6323c827d9658c, author = Florian Roth, description = Detects Nanocore RAT, reference = Internal Research - T2T, license = https://creativecommons.org/licenses/by-nc/4.0/ |
Source: 17.2.AddInProcess32.exe.5610000.3.raw.unpack, type: UNPACKEDPE | Matched rule: Nanocore_RAT_Gen_2 date = 2016-04-22, hash1 = 755f49a4ffef5b1b62f4b5a5de279868c0c1766b528648febf76628f1fe39050, author = Florian Roth, description = Detetcs the Nanocore RAT, license = https://creativecommons.org/licenses/by-nc/4.0/, score = https://www.sentinelone.com/blogs/teaching-an-old-rat-new-tricks/ |
Source: 17.2.AddInProcess32.exe.5610000.3.raw.unpack, type: UNPACKEDPE | Matched rule: Nanocore_RAT_Feb18_1 date = 2018-02-19, hash1 = aa486173e9d594729dbb5626748ce10a75ee966481b68c1b4f6323c827d9658c, author = Florian Roth, description = Detects Nanocore RAT, reference = Internal Research - T2T, license = https://creativecommons.org/licenses/by-nc/4.0/ |
Source: 17.2.AddInProcess32.exe.5a80000.6.unpack, type: UNPACKEDPE | Matched rule: Nanocore_RAT_Gen_2 date = 2016-04-22, hash1 = 755f49a4ffef5b1b62f4b5a5de279868c0c1766b528648febf76628f1fe39050, author = Florian Roth, description = Detetcs the Nanocore RAT, license = https://creativecommons.org/licenses/by-nc/4.0/, score = https://www.sentinelone.com/blogs/teaching-an-old-rat-new-tricks/ |
Source: 17.2.AddInProcess32.exe.5a80000.6.unpack, type: UNPACKEDPE | Matched rule: Nanocore_RAT_Feb18_1 date = 2018-02-19, hash1 = aa486173e9d594729dbb5626748ce10a75ee966481b68c1b4f6323c827d9658c, author = Florian Roth, description = Detects Nanocore RAT, reference = Internal Research - T2T, license = https://creativecommons.org/licenses/by-nc/4.0/ |
Source: 17.2.AddInProcess32.exe.400000.0.unpack, type: UNPACKEDPE | Matched rule: Nanocore_RAT_Gen_2 date = 2016-04-22, hash1 = 755f49a4ffef5b1b62f4b5a5de279868c0c1766b528648febf76628f1fe39050, author = Florian Roth, description = Detetcs the Nanocore RAT, license = https://creativecommons.org/licenses/by-nc/4.0/, score = https://www.sentinelone.com/blogs/teaching-an-old-rat-new-tricks/ |
Source: 17.2.AddInProcess32.exe.400000.0.unpack, type: UNPACKEDPE | Matched rule: Nanocore_RAT_Feb18_1 date = 2018-02-19, hash1 = aa486173e9d594729dbb5626748ce10a75ee966481b68c1b4f6323c827d9658c, author = Florian Roth, description = Detects Nanocore RAT, reference = Internal Research - T2T, license = https://creativecommons.org/licenses/by-nc/4.0/ |
Source: 17.2.AddInProcess32.exe.400000.0.unpack, type: UNPACKEDPE | Matched rule: NanoCore date = 2014/04, filetype = exe, author = Kevin Breen <kevin@techanarchy.net>, maltype = Remote Access Trojan, ref = http://malwareconfig.com/stats/NanoCore |
Source: DHL_file 187652345643476245.exe, Sg6/Tx6.cs | Cryptographic APIs: 'TransformFinalBlock' |
Source: DHL_file 187652345643476245.exe, g0XP/Aq8w.cs | Cryptographic APIs: 'CreateDecryptor' |
Source: demiusda.exe.0.dr, Sg6/Tx6.cs | Cryptographic APIs: 'TransformFinalBlock' |
Source: demiusda.exe.0.dr, g0XP/Aq8w.cs | Cryptographic APIs: 'CreateDecryptor' |
Source: 0.0.DHL_file 187652345643476245.exe.bc0000.0.unpack, Sg6/Tx6.cs | Cryptographic APIs: 'TransformFinalBlock' |
Source: 0.0.DHL_file 187652345643476245.exe.bc0000.0.unpack, g0XP/Aq8w.cs | Cryptographic APIs: 'CreateDecryptor' |
Source: 0.2.DHL_file 187652345643476245.exe.bc0000.0.unpack, Sg6/Tx6.cs | Cryptographic APIs: 'TransformFinalBlock' |
Source: 0.2.DHL_file 187652345643476245.exe.bc0000.0.unpack, g0XP/Aq8w.cs | Cryptographic APIs: 'CreateDecryptor' |
Source: 12.0.demiusda.exe.d50000.0.unpack, Sg6/Tx6.cs | Cryptographic APIs: 'TransformFinalBlock' |
Source: 12.0.demiusda.exe.d50000.0.unpack, g0XP/Aq8w.cs | Cryptographic APIs: 'CreateDecryptor' |
Source: 12.2.demiusda.exe.d50000.0.unpack, Sg6/Tx6.cs | Cryptographic APIs: 'TransformFinalBlock' |
Source: C:\Users\user\Desktop\DHL_file 187652345643476245.exe | Section loaded: C:\Windows\assembly\NativeImages_v4.0.30319_32\mscorlib\a152fe02a317a77aeee36903305e8ba6\mscorlib.ni.dll | Jump to behavior |
Source: C:\Users\user\AppData\Roaming\demiusda.exe | Section loaded: C:\Windows\assembly\NativeImages_v4.0.30319_32\mscorlib\a152fe02a317a77aeee36903305e8ba6\mscorlib.ni.dll | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\AddInProcess32.exe | Section loaded: C:\Windows\assembly\NativeImages_v4.0.30319_32\mscorlib\a152fe02a317a77aeee36903305e8ba6\mscorlib.ni.dll | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\watchprcss.exe | Section loaded: C:\Windows\assembly\NativeImages_v4.0.30319_32\mscorlib\a152fe02a317a77aeee36903305e8ba6\mscorlib.ni.dll | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\watchprcss.exe | Section loaded: C:\Windows\assembly\NativeImages_v4.0.30319_32\mscorlib\a152fe02a317a77aeee36903305e8ba6\mscorlib.ni.dll | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\watchprcss.exe | Section loaded: C:\Windows\assembly\NativeImages_v4.0.30319_32\mscorlib\a152fe02a317a77aeee36903305e8ba6\mscorlib.ni.dll | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\watchprcss.exe | Section loaded: C:\Windows\assembly\NativeImages_v4.0.30319_32\mscorlib\a152fe02a317a77aeee36903305e8ba6\mscorlib.ni.dll | |
Source: C:\Users\user\AppData\Local\Temp\watchprcss.exe | Section loaded: C:\Windows\assembly\NativeImages_v4.0.30319_32\mscorlib\a152fe02a317a77aeee36903305e8ba6\mscorlib.ni.dll | |
Source: C:\Users\user\AppData\Local\Temp\watchprcss.exe | Section loaded: C:\Windows\assembly\NativeImages_v4.0.30319_32\mscorlib\a152fe02a317a77aeee36903305e8ba6\mscorlib.ni.dll | |
Source: C:\Users\user\AppData\Local\Temp\watchprcss.exe | Section loaded: C:\Windows\assembly\NativeImages_v4.0.30319_32\mscorlib\a152fe02a317a77aeee36903305e8ba6\mscorlib.ni.dll | |
Source: C:\Users\user\AppData\Local\Temp\watchprcss.exe | Section loaded: C:\Windows\assembly\NativeImages_v4.0.30319_32\mscorlib\a152fe02a317a77aeee36903305e8ba6\mscorlib.ni.dll | |
Source: C:\Users\user\AppData\Local\Temp\watchprcss.exe | Section loaded: C:\Windows\assembly\NativeImages_v4.0.30319_32\mscorlib\a152fe02a317a77aeee36903305e8ba6\mscorlib.ni.dll | |
Source: C:\Users\user\AppData\Local\Temp\watchprcss.exe | Section loaded: C:\Windows\assembly\NativeImages_v4.0.30319_32\mscorlib\a152fe02a317a77aeee36903305e8ba6\mscorlib.ni.dll | |
Source: C:\Users\user\AppData\Local\Temp\watchprcss.exe | Section loaded: C:\Windows\assembly\NativeImages_v4.0.30319_32\mscorlib\a152fe02a317a77aeee36903305e8ba6\mscorlib.ni.dll | |
Source: C:\Users\user\AppData\Local\Temp\watchprcss.exe | Section loaded: C:\Windows\assembly\NativeImages_v4.0.30319_32\mscorlib\a152fe02a317a77aeee36903305e8ba6\mscorlib.ni.dll | |
Source: C:\Users\user\AppData\Local\Temp\watchprcss.exe | Section loaded: C:\Windows\assembly\NativeImages_v4.0.30319_32\mscorlib\a152fe02a317a77aeee36903305e8ba6\mscorlib.ni.dll | |
Source: C:\Users\user\AppData\Local\Temp\watchprcss.exe | Section loaded: C:\Windows\assembly\NativeImages_v4.0.30319_32\mscorlib\a152fe02a317a77aeee36903305e8ba6\mscorlib.ni.dll | |
Source: C:\Users\user\AppData\Local\Temp\watchprcss.exe | Section loaded: C:\Windows\assembly\NativeImages_v4.0.30319_32\mscorlib\a152fe02a317a77aeee36903305e8ba6\mscorlib.ni.dll | |
Source: C:\Users\user\AppData\Local\Temp\watchprcss.exe | Section loaded: C:\Windows\assembly\NativeImages_v4.0.30319_32\mscorlib\a152fe02a317a77aeee36903305e8ba6\mscorlib.ni.dll | |
Source: unknown | Process created: C:\Users\user\Desktop\DHL_file 187652345643476245.exe 'C:\Users\user\Desktop\DHL_file 187652345643476245.exe' | |
Source: unknown | Process created: C:\Users\user\AppData\Roaming\demiusda.exe 'C:\Users\user\AppData\Roaming\demiusda.exe' | |
Source: unknown | Process created: C:\Users\user\AppData\Local\Temp\AddInProcess32.exe C:\Users\user\AppData\Local\Temp\AddInProcess32.exe | |
Source: unknown | Process created: C:\Users\user\AppData\Local\Temp\watchprcss.exe 'C:\Users\user\AppData\Local\Temp\watchprcss.exe' | |
Source: unknown | Process created: C:\Users\user\AppData\Local\Temp\watchprcss.exe 'C:\Users\user\AppData\Local\Temp\watchprcss.exe' | |
Source: unknown | Process created: C:\Users\user\AppData\Local\Temp\watchprcss.exe 'C:\Users\user\AppData\Local\Temp\watchprcss.exe' | |
Source: unknown | Process created: C:\Users\user\AppData\Local\Temp\watchprcss.exe 'C:\Users\user\AppData\Local\Temp\watchprcss.exe' | |
Source: unknown | Process created: C:\Users\user\AppData\Local\Temp\watchprcss.exe 'C:\Users\user\AppData\Local\Temp\watchprcss.exe' | |
Source: unknown | Process created: C:\Users\user\AppData\Local\Temp\watchprcss.exe 'C:\Users\user\AppData\Local\Temp\watchprcss.exe' | |
Source: unknown | Process created: C:\Users\user\AppData\Local\Temp\watchprcss.exe 'C:\Users\user\AppData\Local\Temp\watchprcss.exe' | |
Source: unknown | Process created: C:\Users\user\AppData\Local\Temp\watchprcss.exe 'C:\Users\user\AppData\Local\Temp\watchprcss.exe' | |
Source: unknown | Process created: C:\Users\user\AppData\Local\Temp\watchprcss.exe 'C:\Users\user\AppData\Local\Temp\watchprcss.exe' | |
Source: unknown | Process created: C:\Users\user\AppData\Local\Temp\watchprcss.exe 'C:\Users\user\AppData\Local\Temp\watchprcss.exe' | |
Source: unknown | Process created: C:\Users\user\AppData\Local\Temp\watchprcss.exe 'C:\Users\user\AppData\Local\Temp\watchprcss.exe' | |
Source: unknown | Process created: C:\Users\user\AppData\Local\Temp\watchprcss.exe 'C:\Users\user\AppData\Local\Temp\watchprcss.exe' | |
Source: unknown | Process created: C:\Users\user\AppData\Local\Temp\watchprcss.exe 'C:\Users\user\AppData\Local\Temp\watchprcss.exe' | |
Source: unknown | Process created: C:\Users\user\AppData\Local\Temp\watchprcss.exe 'C:\Users\user\AppData\Local\Temp\watchprcss.exe' | |
Source: unknown | Process created: C:\Users\user\AppData\Local\Temp\watchprcss.exe 'C:\Users\user\AppData\Local\Temp\watchprcss.exe' | |
Source: unknown | Process created: C:\Users\user\AppData\Local\Temp\watchprcss.exe 'C:\Users\user\AppData\Local\Temp\watchprcss.exe' | |
Source: C:\Users\user\Desktop\DHL_file 187652345643476245.exe | Process created: C:\Users\user\AppData\Roaming\demiusda.exe 'C:\Users\user\AppData\Roaming\demiusda.exe' | Jump to behavior |
Source: C:\Users\user\AppData\Roaming\demiusda.exe | Process created: C:\Users\user\AppData\Local\Temp\AddInProcess32.exe C:\Users\user\AppData\Local\Temp\AddInProcess32.exe | Jump to behavior |
Source: C:\Users\user\AppData\Roaming\demiusda.exe | Process created: C:\Users\user\AppData\Local\Temp\watchprcss.exe 'C:\Users\user\AppData\Local\Temp\watchprcss.exe' | Jump to behavior |
Source: C:\Users\user\AppData\Roaming\demiusda.exe | Process created: C:\Users\user\AppData\Local\Temp\watchprcss.exe 'C:\Users\user\AppData\Local\Temp\watchprcss.exe' | Jump to behavior |
Source: C:\Users\user\AppData\Roaming\demiusda.exe | Process created: C:\Users\user\AppData\Local\Temp\watchprcss.exe 'C:\Users\user\AppData\Local\Temp\watchprcss.exe' | Jump to behavior |
Source: C:\Users\user\AppData\Roaming\demiusda.exe | Process created: C:\Users\user\AppData\Local\Temp\watchprcss.exe 'C:\Users\user\AppData\Local\Temp\watchprcss.exe' | Jump to behavior |
Source: C:\Users\user\AppData\Roaming\demiusda.exe | Process created: C:\Users\user\AppData\Local\Temp\watchprcss.exe 'C:\Users\user\AppData\Local\Temp\watchprcss.exe' | Jump to behavior |
Source: C:\Users\user\AppData\Roaming\demiusda.exe | Process created: C:\Users\user\AppData\Local\Temp\watchprcss.exe 'C:\Users\user\AppData\Local\Temp\watchprcss.exe' | Jump to behavior |
Source: C:\Users\user\AppData\Roaming\demiusda.exe | Process created: C:\Users\user\AppData\Local\Temp\watchprcss.exe 'C:\Users\user\AppData\Local\Temp\watchprcss.exe' | Jump to behavior |
Source: C:\Users\user\AppData\Roaming\demiusda.exe | Process created: C:\Users\user\AppData\Local\Temp\watchprcss.exe 'C:\Users\user\AppData\Local\Temp\watchprcss.exe' | Jump to behavior |
Source: C:\Users\user\AppData\Roaming\demiusda.exe | Process created: unknown unknown | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\watchprcss.exe | Process created: C:\Users\user\AppData\Local\Temp\watchprcss.exe 'C:\Users\user\AppData\Local\Temp\watchprcss.exe' | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\watchprcss.exe | Process created: C:\Users\user\AppData\Local\Temp\watchprcss.exe 'C:\Users\user\AppData\Local\Temp\watchprcss.exe' | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\watchprcss.exe | Process created: C:\Users\user\AppData\Local\Temp\watchprcss.exe 'C:\Users\user\AppData\Local\Temp\watchprcss.exe' | |
Source: C:\Users\user\AppData\Local\Temp\watchprcss.exe | Process created: C:\Users\user\AppData\Local\Temp\watchprcss.exe 'C:\Users\user\AppData\Local\Temp\watchprcss.exe' | |
Source: C:\Users\user\AppData\Local\Temp\watchprcss.exe | Process created: C:\Users\user\AppData\Local\Temp\watchprcss.exe 'C:\Users\user\AppData\Local\Temp\watchprcss.exe' | |
Source: C:\Users\user\AppData\Local\Temp\watchprcss.exe | Process created: C:\Users\user\AppData\Local\Temp\watchprcss.exe 'C:\Users\user\AppData\Local\Temp\watchprcss.exe' | |
Source: C:\Users\user\AppData\Local\Temp\watchprcss.exe | Process created: C:\Users\user\AppData\Local\Temp\watchprcss.exe 'C:\Users\user\AppData\Local\Temp\watchprcss.exe' | |
Source: C:\Users\user\AppData\Local\Temp\watchprcss.exe | Process created: C:\Users\user\AppData\Local\Temp\watchprcss.exe 'C:\Users\user\AppData\Local\Temp\watchprcss.exe' | |
Source: C:\Users\user\Desktop\DHL_file 187652345643476245.exe | Code function: 0_2_00BC6DF4 push cs; retf | 0_2_00BC6DF5 |
Source: C:\Users\user\Desktop\DHL_file 187652345643476245.exe | Code function: 0_2_00BC23E0 push esp; retn 0000h | 0_2_00BC23E1 |
Source: C:\Users\user\Desktop\DHL_file 187652345643476245.exe | Code function: 0_2_00BC3400 push cs; retf | 0_2_00BC3401 |
Source: C:\Users\user\Desktop\DHL_file 187652345643476245.exe | Code function: 0_2_057ADE4B pushad ; ret | 0_2_057ADE51 |
Source: C:\Users\user\AppData\Roaming\demiusda.exe | Code function: 12_2_00D53400 push cs; retf | 12_2_00D53401 |
Source: C:\Users\user\AppData\Roaming\demiusda.exe | Code function: 12_2_00D56DF4 push cs; retf | 12_2_00D56DF5 |
Source: C:\Users\user\AppData\Roaming\demiusda.exe | Code function: 12_2_00D523E0 push esp; retn 0000h | 12_2_00D523E1 |
Source: C:\Users\user\AppData\Local\Temp\AddInProcess32.exe | Code function: 17_2_055769FA push esp; retf | 17_2_05576A01 |
Source: C:\Users\user\AppData\Local\Temp\AddInProcess32.exe | Code function: 17_2_055769F8 pushad ; retf | 17_2_055769F9 |
Source: watchprcss.exe.12.dr, Astronotplart/My/tT7bk4FnxbYaKqMtWjIqvyKWh4J9tkfAvLZ8e5Y4BU.cs | High entropy of concatenated method names: 'nn9DM7TZkpnl4dSPqnpPS2oW', 'LztRLhG61h4KFshxtO7P7', 'G4vjdlUHNvtWZenTXSNdtGwCIYmCoKE77', '5fQycwGNtn0lBuMB2jteITZhMQF3wG', 'ZJSZEAUpgBzwUgSXvnbC6lEhXmP5VpN2nCiGvnzMTR' |
Source: watchprcss.exe.12.dr, Astronotplart/gabKErPURPS76kDKjrme.cs | High entropy of concatenated method names: '.ctor', 'EmwYECB1wGyvIA2snT', 'zQyq6GQCkVXH2m9ORWKDS7znEfc2l', 'X3TE6RCIZMD7ECwwVoqD8j43J8u', 'SwV7wVQkM24hXoCSpr83uLH4TEFtSUXME6LQS7', 'gIglw7CqsSJGzE2AtTN3JYbIYwYS1QQ7ADpw', 'aciMX0Q3f70STq8WXW' |
Source: watchprcss.exe.12.dr, Astronotplart/My/Resources/cZsjfbJLI2Nt8If5QOa3YzSXxDXbcmzUTY.cs | High entropy of concatenated method names: '7tuLHfXnvgcErulp', 'vFPZGqKub8S44KK9njyrAe1CN2qDJ3IQa7tiGW3Oebu', 'p0Rr9tY6YlifmwQtRmfPXGEDX', 'IPf8zIYNrroPiylxpRDezmMidW58Fr8mLO' |
Source: watchprcss.exe.12.dr, Astronotplart/My/nVdeDLHvVsfVxwgFzORDky8W3f9u4lGmiaWnSDb.cs | High entropy of concatenated method names: '.cctor', 'ipfF6OV8JHE8Qin24Sz2H', 'GBAU51HdoykwtyLJ8j', 'A6Cmw4VPbNKHMkR6BnXqjGTCsaLYYK', 'ZhXAveIVREq8oAgNFODqxTnhx35', 'TL13XiWxESQiImm09SkPUl2iIyfqvqfNa1eW0WN', 'hXlgWtIDkKwHkCLRcj1P0yvWMryPDm997zSDv', 'crnIowWf8YVTDoRdGn' |
Source: watchprcss.exe.12.dr, Astronotplart/rtGPmvPIdl5IaacYtOxDvUDj4cyvAKDSBQSIKnjuJ.cs | High entropy of concatenated method names: '.ctor', 'lXIhNy5k2zuUtWijXRf3Smh', 'K04wNKQqGraj7cH31jV3', 'XjtDF35KWLF6l1is3R1Q6HxEJwEr3PbjtGbh2HVd2', 'lvOSFdRQCCluXgGa7jGQkU1jNoXRaK5EpfPYnW', 'gZQk7h6spRLFg3NwAmoe' |
Source: 17.2.AddInProcess32.exe.400000.0.unpack, u0023u003dqJT4I5hOweIku0024xYFEeDszbikglXCuquUdu0024v9AXtyq2nsu003d.cs | High entropy of concatenated method names: '#=qBeOBlH6CwHFnQdZWWBgZ_pemudZ6CfCVcfOQtgpeG$Y=', '#=q5v5cLSMFBaxiTtOEjscx86gN2ozXlfytiL6UmXnyWtg=', '#=q_XA5h2lVGHLcY9dK754wKGrOjAm6aBbwPxcUJXgJThJUz83kMbCL53G5uuOLP6Rq', '#=qIFfr$DrKqIieRc688$vylAlBsEnx9Z3$TxvrDsPURfM=', '#=qejgvNXJQvgM2GomZsygLjreyguSPQ29pQHqjR_a0dWk=', '#=qCGokdf0OOxeMJLDkXSfc3NPmwygIQ29RjKQWj$wbNGB9C1pPgma_891QiNyTRXcA', '#=qDqyUVyJLXCtYqhZ0$opqkomqhUBn2WCeEEvGAXlNQ$I=', '#=qdImPAY1o3YhbLtukwCQ91cISaeIEWRKSYrGZ3dTVnkY=', '#=qza7O1AHrroJC7yRIJz4wINR_Sgo4hDpQrj_OYfIrlJE=', '#=q6Ct3QmvVLFC7my$dL1uEiHGmXJ5qCuK4WIhDwfhPTFs=' |
Source: 17.2.AddInProcess32.exe.400000.0.unpack, u0023u003dqWrm21vQ8CBMZP_RBTwpusAu003du003d.cs | High entropy of concatenated method names: '#=qCgU$tDqtOAyz2b$RwfSF7UzBcCAr0rFJWxm16x7Lre0=', '#=qeD3MBfedCIuKIQf9V1u2N3YS4VXE_FOHqw_XAjWtZK8=', '#=q$mvEHEBkZud$AdHPWqsMQnw5Xm5sD4vBSSmqrKuXGOk=', '#=qZaN94n8dM6tBEf$qCdY2kbTZb5BOW8Z134$2tNv7EJs=', '#=qtlZnL8mho$rv1eTFz0Mw9UYFC_yCabEZ0xtVePn6wR5aSHE7ti3UfKg2l7D0_xk8', '#=qVS$QmQjvFfsXSqQAKGSl6HGbkse2SG0XCab4upVjtRJkvhTEk$oIS2I9Zja7id1Q', '#=qxJg7RxTW1v5mnt12xXeJiYJv_bcctbtL2BCD5MjDi45Hlz6t8vwDNTv1Rv7tgIct', '#=qp$ZVC1r9spi890l$D7IwEd3faoKeWHvv42mVq8wIIWM=', '#=qCoWHlVuoVRMkOzC7RZubJCslkxaEWn9yZiIydECf69$ktj0IPD5wAwC2H5Cc8C$L', '#=qqs1moO$mYaS72OXOWe0Z6GycslEb6e9Ipoy7ppW0O5abIp05ajv8doqdJZHlN3cK' |
Source: 19.2.watchprcss.exe.e20000.0.unpack, Astronotplart/My/tT7bk4FnxbYaKqMtWjIqvyKWh4J9tkfAvLZ8e5Y4BU.cs | High entropy of concatenated method names: 'nn9DM7TZkpnl4dSPqnpPS2oW', 'LztRLhG61h4KFshxtO7P7', 'G4vjdlUHNvtWZenTXSNdtGwCIYmCoKE77', '5fQycwGNtn0lBuMB2jteITZhMQF3wG', 'ZJSZEAUpgBzwUgSXvnbC6lEhXmP5VpN2nCiGvnzMTR' |
Source: 19.2.watchprcss.exe.e20000.0.unpack, Astronotplart/gabKErPURPS76kDKjrme.cs | High entropy of concatenated method names: '.ctor', 'EmwYECB1wGyvIA2snT', 'zQyq6GQCkVXH2m9ORWKDS7znEfc2l', 'X3TE6RCIZMD7ECwwVoqD8j43J8u', 'SwV7wVQkM24hXoCSpr83uLH4TEFtSUXME6LQS7', 'gIglw7CqsSJGzE2AtTN3JYbIYwYS1QQ7ADpw', 'aciMX0Q3f70STq8WXW' |
Source: 19.2.watchprcss.exe.e20000.0.unpack, Astronotplart/My/nVdeDLHvVsfVxwgFzORDky8W3f9u4lGmiaWnSDb.cs | High entropy of concatenated method names: '.cctor', 'ipfF6OV8JHE8Qin24Sz2H', 'GBAU51HdoykwtyLJ8j', 'A6Cmw4VPbNKHMkR6BnXqjGTCsaLYYK', 'ZhXAveIVREq8oAgNFODqxTnhx35', 'TL13XiWxESQiImm09SkPUl2iIyfqvqfNa1eW0WN', 'hXlgWtIDkKwHkCLRcj1P0yvWMryPDm997zSDv', 'crnIowWf8YVTDoRdGn' |
Source: 19.2.watchprcss.exe.e20000.0.unpack, Astronotplart/My/Resources/cZsjfbJLI2Nt8If5QOa3YzSXxDXbcmzUTY.cs | High entropy of concatenated method names: '7tuLHfXnvgcErulp', 'vFPZGqKub8S44KK9njyrAe1CN2qDJ3IQa7tiGW3Oebu', 'p0Rr9tY6YlifmwQtRmfPXGEDX', 'IPf8zIYNrroPiylxpRDezmMidW58Fr8mLO' |
Source: 19.2.watchprcss.exe.e20000.0.unpack, Astronotplart/rtGPmvPIdl5IaacYtOxDvUDj4cyvAKDSBQSIKnjuJ.cs | High entropy of concatenated method names: '.ctor', 'lXIhNy5k2zuUtWijXRf3Smh', 'K04wNKQqGraj7cH31jV3', 'XjtDF35KWLF6l1is3R1Q6HxEJwEr3PbjtGbh2HVd2', 'lvOSFdRQCCluXgGa7jGQkU1jNoXRaK5EpfPYnW', 'gZQk7h6spRLFg3NwAmoe' |
Source: 19.0.watchprcss.exe.e20000.0.unpack, Astronotplart/My/tT7bk4FnxbYaKqMtWjIqvyKWh4J9tkfAvLZ8e5Y4BU.cs | High entropy of concatenated method names: 'nn9DM7TZkpnl4dSPqnpPS2oW', 'LztRLhG61h4KFshxtO7P7', 'G4vjdlUHNvtWZenTXSNdtGwCIYmCoKE77', '5fQycwGNtn0lBuMB2jteITZhMQF3wG', 'ZJSZEAUpgBzwUgSXvnbC6lEhXmP5VpN2nCiGvnzMTR' |
Source: 19.0.watchprcss.exe.e20000.0.unpack, Astronotplart/gabKErPURPS76kDKjrme.cs | High entropy of concatenated method names: '.ctor', 'EmwYECB1wGyvIA2snT', 'zQyq6GQCkVXH2m9ORWKDS7znEfc2l', 'X3TE6RCIZMD7ECwwVoqD8j43J8u', 'SwV7wVQkM24hXoCSpr83uLH4TEFtSUXME6LQS7', 'gIglw7CqsSJGzE2AtTN3JYbIYwYS1QQ7ADpw', 'aciMX0Q3f70STq8WXW' |
Source: 19.0.watchprcss.exe.e20000.0.unpack, Astronotplart/My/nVdeDLHvVsfVxwgFzORDky8W3f9u4lGmiaWnSDb.cs | High entropy of concatenated method names: '.cctor', 'ipfF6OV8JHE8Qin24Sz2H', 'GBAU51HdoykwtyLJ8j', 'A6Cmw4VPbNKHMkR6BnXqjGTCsaLYYK', 'ZhXAveIVREq8oAgNFODqxTnhx35', 'TL13XiWxESQiImm09SkPUl2iIyfqvqfNa1eW0WN', 'hXlgWtIDkKwHkCLRcj1P0yvWMryPDm997zSDv', 'crnIowWf8YVTDoRdGn' |
Source: 19.0.watchprcss.exe.e20000.0.unpack, Astronotplart/My/Resources/cZsjfbJLI2Nt8If5QOa3YzSXxDXbcmzUTY.cs | High entropy of concatenated method names: '7tuLHfXnvgcErulp', 'vFPZGqKub8S44KK9njyrAe1CN2qDJ3IQa7tiGW3Oebu', 'p0Rr9tY6YlifmwQtRmfPXGEDX', 'IPf8zIYNrroPiylxpRDezmMidW58Fr8mLO' |
Source: 19.0.watchprcss.exe.e20000.0.unpack, Astronotplart/rtGPmvPIdl5IaacYtOxDvUDj4cyvAKDSBQSIKnjuJ.cs | High entropy of concatenated method names: '.ctor', 'lXIhNy5k2zuUtWijXRf3Smh', 'K04wNKQqGraj7cH31jV3', 'XjtDF35KWLF6l1is3R1Q6HxEJwEr3PbjtGbh2HVd2', 'lvOSFdRQCCluXgGa7jGQkU1jNoXRaK5EpfPYnW', 'gZQk7h6spRLFg3NwAmoe' |
Source: 20.2.watchprcss.exe.200000.0.unpack, Astronotplart/My/tT7bk4FnxbYaKqMtWjIqvyKWh4J9tkfAvLZ8e5Y4BU.cs | High entropy of concatenated method names: 'nn9DM7TZkpnl4dSPqnpPS2oW', 'LztRLhG61h4KFshxtO7P7', 'G4vjdlUHNvtWZenTXSNdtGwCIYmCoKE77', '5fQycwGNtn0lBuMB2jteITZhMQF3wG', 'ZJSZEAUpgBzwUgSXvnbC6lEhXmP5VpN2nCiGvnzMTR' |
Source: 20.2.watchprcss.exe.200000.0.unpack, Astronotplart/gabKErPURPS76kDKjrme.cs | High entropy of concatenated method names: '.ctor', 'EmwYECB1wGyvIA2snT', 'zQyq6GQCkVXH2m9ORWKDS7znEfc2l', 'X3TE6RCIZMD7ECwwVoqD8j43J8u', 'SwV7wVQkM24hXoCSpr83uLH4TEFtSUXME6LQS7', 'gIglw7CqsSJGzE2AtTN3JYbIYwYS1QQ7ADpw', 'aciMX0Q3f70STq8WXW' |
Source: 20.2.watchprcss.exe.200000.0.unpack, Astronotplart/My/nVdeDLHvVsfVxwgFzORDky8W3f9u4lGmiaWnSDb.cs | High entropy of concatenated method names: '.cctor', 'ipfF6OV8JHE8Qin24Sz2H', 'GBAU51HdoykwtyLJ8j', 'A6Cmw4VPbNKHMkR6BnXqjGTCsaLYYK', 'ZhXAveIVREq8oAgNFODqxTnhx35', 'TL13XiWxESQiImm09SkPUl2iIyfqvqfNa1eW0WN', 'hXlgWtIDkKwHkCLRcj1P0yvWMryPDm997zSDv', 'crnIowWf8YVTDoRdGn' |
Source: 20.2.watchprcss.exe.200000.0.unpack, Astronotplart/My/Resources/cZsjfbJLI2Nt8If5QOa3YzSXxDXbcmzUTY.cs | High entropy of concatenated method names: '7tuLHfXnvgcErulp', 'vFPZGqKub8S44KK9njyrAe1CN2qDJ3IQa7tiGW3Oebu', 'p0Rr9tY6YlifmwQtRmfPXGEDX', 'IPf8zIYNrroPiylxpRDezmMidW58Fr8mLO' |
Source: 20.2.watchprcss.exe.200000.0.unpack, Astronotplart/rtGPmvPIdl5IaacYtOxDvUDj4cyvAKDSBQSIKnjuJ.cs | High entropy of concatenated method names: '.ctor', 'lXIhNy5k2zuUtWijXRf3Smh', 'K04wNKQqGraj7cH31jV3', 'XjtDF35KWLF6l1is3R1Q6HxEJwEr3PbjtGbh2HVd2', 'lvOSFdRQCCluXgGa7jGQkU1jNoXRaK5EpfPYnW', 'gZQk7h6spRLFg3NwAmoe' |
Source: 20.0.watchprcss.exe.200000.0.unpack, Astronotplart/My/tT7bk4FnxbYaKqMtWjIqvyKWh4J9tkfAvLZ8e5Y4BU.cs | High entropy of concatenated method names: 'nn9DM7TZkpnl4dSPqnpPS2oW', 'LztRLhG61h4KFshxtO7P7', 'G4vjdlUHNvtWZenTXSNdtGwCIYmCoKE77', '5fQycwGNtn0lBuMB2jteITZhMQF3wG', 'ZJSZEAUpgBzwUgSXvnbC6lEhXmP5VpN2nCiGvnzMTR' |
Source: 20.0.watchprcss.exe.200000.0.unpack, Astronotplart/gabKErPURPS76kDKjrme.cs | High entropy of concatenated method names: '.ctor', 'EmwYECB1wGyvIA2snT', 'zQyq6GQCkVXH2m9ORWKDS7znEfc2l', 'X3TE6RCIZMD7ECwwVoqD8j43J8u', 'SwV7wVQkM24hXoCSpr83uLH4TEFtSUXME6LQS7', 'gIglw7CqsSJGzE2AtTN3JYbIYwYS1QQ7ADpw', 'aciMX0Q3f70STq8WXW' |
Source: 20.0.watchprcss.exe.200000.0.unpack, Astronotplart/My/nVdeDLHvVsfVxwgFzORDky8W3f9u4lGmiaWnSDb.cs | High entropy of concatenated method names: '.cctor', 'ipfF6OV8JHE8Qin24Sz2H', 'GBAU51HdoykwtyLJ8j', 'A6Cmw4VPbNKHMkR6BnXqjGTCsaLYYK', 'ZhXAveIVREq8oAgNFODqxTnhx35', 'TL13XiWxESQiImm09SkPUl2iIyfqvqfNa1eW0WN', 'hXlgWtIDkKwHkCLRcj1P0yvWMryPDm997zSDv', 'crnIowWf8YVTDoRdGn' |
Source: 20.0.watchprcss.exe.200000.0.unpack, Astronotplart/My/Resources/cZsjfbJLI2Nt8If5QOa3YzSXxDXbcmzUTY.cs | High entropy of concatenated method names: '7tuLHfXnvgcErulp', 'vFPZGqKub8S44KK9njyrAe1CN2qDJ3IQa7tiGW3Oebu', 'p0Rr9tY6YlifmwQtRmfPXGEDX', 'IPf8zIYNrroPiylxpRDezmMidW58Fr8mLO' |
Source: 20.0.watchprcss.exe.200000.0.unpack, Astronotplart/rtGPmvPIdl5IaacYtOxDvUDj4cyvAKDSBQSIKnjuJ.cs | High entropy of concatenated method names: '.ctor', 'lXIhNy5k2zuUtWijXRf3Smh', 'K04wNKQqGraj7cH31jV3', 'XjtDF35KWLF6l1is3R1Q6HxEJwEr3PbjtGbh2HVd2', 'lvOSFdRQCCluXgGa7jGQkU1jNoXRaK5EpfPYnW', 'gZQk7h6spRLFg3NwAmoe' |
Source: |