Source: URGENT MEDICAL REQUIREMENT.exe | Virustotal: Detection: 24% | Perma Link |
Source: URGENT MEDICAL REQUIREMENT.exe | Static PE information: LOCAL_SYMS_STRIPPED, 32BIT_MACHINE, EXECUTABLE_IMAGE, LINE_NUMS_STRIPPED, RELOCS_STRIPPED |
Source: C:\Users\user\Desktop\URGENT MEDICAL REQUIREMENT.exe | Process Stats: CPU usage > 98% |
Source: C:\Users\user\Desktop\URGENT MEDICAL REQUIREMENT.exe | Code function: 0_2_00422C4B |
Source: C:\Users\user\Desktop\URGENT MEDICAL REQUIREMENT.exe | Code function: 0_2_0042206B |
Source: C:\Users\user\Desktop\URGENT MEDICAL REQUIREMENT.exe | Code function: 0_2_0042526F |
Source: C:\Users\user\Desktop\URGENT MEDICAL REQUIREMENT.exe | Code function: 0_2_00421677 |
Source: C:\Users\user\Desktop\URGENT MEDICAL REQUIREMENT.exe | Code function: 0_2_0042287B |
Source: C:\Users\user\Desktop\URGENT MEDICAL REQUIREMENT.exe | Code function: 0_2_00422600 |
Source: C:\Users\user\Desktop\URGENT MEDICAL REQUIREMENT.exe | Code function: 0_2_00426613 |
Source: C:\Users\user\Desktop\URGENT MEDICAL REQUIREMENT.exe | Code function: 0_2_00425217 |
Source: C:\Users\user\Desktop\URGENT MEDICAL REQUIREMENT.exe | Code function: 0_2_00427A2B |
Source: C:\Users\user\Desktop\URGENT MEDICAL REQUIREMENT.exe | Code function: 0_2_00422437 |
Source: C:\Users\user\Desktop\URGENT MEDICAL REQUIREMENT.exe | Code function: 0_2_00427634 |
Source: C:\Users\user\Desktop\URGENT MEDICAL REQUIREMENT.exe | Code function: 0_2_004252C0 |
Source: C:\Users\user\Desktop\URGENT MEDICAL REQUIREMENT.exe | Code function: 0_2_004276D7 |
Source: C:\Users\user\Desktop\URGENT MEDICAL REQUIREMENT.exe | Code function: 0_2_004222F7 |
Source: C:\Users\user\Desktop\URGENT MEDICAL REQUIREMENT.exe | Code function: 0_2_00425AFF |
Source: C:\Users\user\Desktop\URGENT MEDICAL REQUIREMENT.exe | Code function: 0_2_00422E83 |
Source: C:\Users\user\Desktop\URGENT MEDICAL REQUIREMENT.exe | Code function: 0_2_00427688 |
Source: C:\Users\user\Desktop\URGENT MEDICAL REQUIREMENT.exe | Code function: 0_2_004254A3 |
Source: C:\Users\user\Desktop\URGENT MEDICAL REQUIREMENT.exe | Code function: 0_2_0042274B |
Source: C:\Users\user\Desktop\URGENT MEDICAL REQUIREMENT.exe | Code function: 0_2_00422F5F |
Source: C:\Users\user\Desktop\URGENT MEDICAL REQUIREMENT.exe | Code function: 0_2_0042335D |
Source: C:\Users\user\Desktop\URGENT MEDICAL REQUIREMENT.exe | Code function: 0_2_00422967 |
Source: C:\Users\user\Desktop\URGENT MEDICAL REQUIREMENT.exe | Code function: 0_2_0042797F |
Source: C:\Users\user\Desktop\URGENT MEDICAL REQUIREMENT.exe | Code function: 0_2_00423303 |
Source: C:\Users\user\Desktop\URGENT MEDICAL REQUIREMENT.exe | Code function: 0_2_00425D08 |
Source: C:\Users\user\Desktop\URGENT MEDICAL REQUIREMENT.exe | Code function: 0_2_00427512 |
Source: C:\Users\user\Desktop\URGENT MEDICAL REQUIREMENT.exe | Code function: 0_2_0042191B |
Source: C:\Users\user\Desktop\URGENT MEDICAL REQUIREMENT.exe | Code function: 0_2_0042611F |
Source: C:\Users\user\Desktop\URGENT MEDICAL REQUIREMENT.exe | Code function: 0_2_00425937 |
Source: C:\Users\user\Desktop\URGENT MEDICAL REQUIREMENT.exe | Code function: 0_2_004259D3 |
Source: C:\Users\user\Desktop\URGENT MEDICAL REQUIREMENT.exe | Code function: 0_2_004221D7 |
Source: C:\Users\user\Desktop\URGENT MEDICAL REQUIREMENT.exe | Code function: 0_2_004275EB |
Source: C:\Users\user\Desktop\URGENT MEDICAL REQUIREMENT.exe | Code function: 0_2_00422B83 |
Source: C:\Users\user\Desktop\URGENT MEDICAL REQUIREMENT.exe | Code function: 0_2_004213AB |
Source: C:\Users\user\Desktop\URGENT MEDICAL REQUIREMENT.exe | Code function: 0_2_004227AF |
Source: C:\Users\user\Desktop\URGENT MEDICAL REQUIREMENT.exe | Code function: 0_2_004253AF |
Source: C:\Users\user\Desktop\URGENT MEDICAL REQUIREMENT.exe | Code function: 0_2_00422DB3 |
Source: C:\Users\user\Desktop\URGENT MEDICAL REQUIREMENT.exe | Code function: 0_2_00421FBB |
Source: URGENT MEDICAL REQUIREMENT.exe | Static PE information: Resource name: RT_ICON type: GLS_BINARY_LSB_FIRST |
Source: URGENT MEDICAL REQUIREMENT.exe, 00000000.00000002.1258460847.0000000002090000.00000002.00000001.sdmp | Binary or memory string: OriginalFilenameuser32j% vs URGENT MEDICAL REQUIREMENT.exe |
Source: URGENT MEDICAL REQUIREMENT.exe, 00000000.00000002.1257535826.0000000000410000.00000002.00020000.sdmp | Binary or memory string: OriginalFilenameHybridizers5.exe vs URGENT MEDICAL REQUIREMENT.exe |
Source: URGENT MEDICAL REQUIREMENT.exe | Binary or memory string: OriginalFilenameHybridizers5.exe vs URGENT MEDICAL REQUIREMENT.exe |
Source: URGENT MEDICAL REQUIREMENT.exe | Static PE information: LOCAL_SYMS_STRIPPED, 32BIT_MACHINE, EXECUTABLE_IMAGE, LINE_NUMS_STRIPPED, RELOCS_STRIPPED |
Source: classification engine | Classification label: mal84.troj.evad.winEXE@1/0@0/0 |
Source: C:\Users\user\Desktop\URGENT MEDICAL REQUIREMENT.exe | File created: C:\Users\user\AppData\Local\Temp\~DFE70F2CB0D79118EF.TMP | Jump to behavior |
Source: URGENT MEDICAL REQUIREMENT.exe | Static PE information: Section: .text IMAGE_SCN_MEM_EXECUTE, IMAGE_SCN_CNT_CODE, IMAGE_SCN_MEM_READ |
Source: C:\Users\user\Desktop\URGENT MEDICAL REQUIREMENT.exe | Section loaded: C:\Windows\SysWOW64\msvbvm60.dll |
Source: C:\Users\user\Desktop\URGENT MEDICAL REQUIREMENT.exe | Key opened: HKEY_CURRENT_USER\Software\Policies\Microsoft\Windows\Safer\CodeIdentifiers |
Source: URGENT MEDICAL REQUIREMENT.exe | Virustotal: Detection: 24% |
Source: Yara match | File source: Process Memory Space: URGENT MEDICAL REQUIREMENT.exe PID: 6388, type: MEMORY |
Source: Yara match | File source: Process Memory Space: URGENT MEDICAL REQUIREMENT.exe PID: 6388, type: MEMORY |
Source: C:\Users\user\Desktop\URGENT MEDICAL REQUIREMENT.exe | Code function: 0_2_00405063 pushfd ; iretd |
Source: C:\Users\user\Desktop\URGENT MEDICAL REQUIREMENT.exe | Code function: 0_2_00406863 pushfd ; iretd |
Source: C:\Users\user\Desktop\URGENT MEDICAL REQUIREMENT.exe | Code function: 0_2_00405E7C push esp; iretd |
Source: C:\Users\user\Desktop\URGENT MEDICAL REQUIREMENT.exe | Code function: 0_2_004048F3 pushfd ; iretd |
Source: C:\Users\user\Desktop\URGENT MEDICAL REQUIREMENT.exe | Code function: 0_2_004070B3 pushfd ; iretd |
Source: C:\Users\user\Desktop\URGENT MEDICAL REQUIREMENT.exe | Code function: 0_2_00426CBE push eax; ret |
Source: C:\Users\user\Desktop\URGENT MEDICAL REQUIREMENT.exe | Code function: 0_2_00423BD6 push esp; retf |
Source: C:\Users\user\Desktop\URGENT MEDICAL REQUIREMENT.exe | Code function: 0_2_00423BF8 push esp; retf |
Source: C:\Users\user\Desktop\URGENT MEDICAL REQUIREMENT.exe | Process information set: NOOPENFILEERRORBOX |
Source: C:\Users\user\Desktop\URGENT MEDICAL REQUIREMENT.exe | Code function: 0_2_0042181B |
Source: C:\Users\user\Desktop\URGENT MEDICAL REQUIREMENT.exe | RDTSC instruction interceptor: First address: 00000000004265EB second address: 00000000004265EB instructions: |
Source: C:\Users\user\Desktop\URGENT MEDICAL REQUIREMENT.exe | System information queried: CurrentTimeZoneInformation |
Source: URGENT MEDICAL REQUIREMENT.exe | Binary or memory string: C:\PROGRAM FILES\QEMU-GA\QEMU-GA.EXE |
Source: C:\Users\user\Desktop\URGENT MEDICAL REQUIREMENT.exe | RDTSC instruction interceptor: First address: 00000000004265EB second address: 00000000004265EB instructions: |
Source: C:\Users\user\Desktop\URGENT MEDICAL REQUIREMENT.exe | RDTSC instruction interceptor: First address: 0000000000426348 second address: 0000000000426348 instructions: 0x00000000 rdtsc 0x00000002 xor eax, eax 0x00000004 inc eax 0x00000005 cpuid 0x00000007 popad 0x00000008 call 00007F9854B64FA8h 0x0000000d lfence 0x00000010 mov edx, dword ptr [7FFE0014h] 0x00000016 lfence 0x00000019 ret 0x0000001a sub edx, esi 0x0000001c ret 0x0000001d cmp ch, dh 0x0000001f add edi, edx 0x00000021 cmp ah, 00000069h 0x00000024 dec dword ptr [ebp+000000F8h] 0x0000002a cmp bl, bl 0x0000002c cmp dword ptr [ebp+000000F8h], 00000000h 0x00000033 jne 00007F9854B64F85h 0x00000035 call 00007F9854B64FD8h 0x0000003a call 00007F9854B64FB8h 0x0000003f lfence 0x00000042 mov edx, dword ptr [7FFE0014h] 0x00000048 lfence 0x0000004b ret 0x0000004c mov esi, edx 0x0000004e pushad 0x0000004f rdtsc |
Source: C:\Users\user\Desktop\URGENT MEDICAL REQUIREMENT.exe | Code function: 0_2_00421847 rdtsc |
Source: all processes | Thread injection, dropped files, key value created, disk infection and DNS query: no activity detected |
Source: URGENT MEDICAL REQUIREMENT.exe | Binary or memory string: C:\Program Files\Qemu-ga\qemu-ga.exe |
Source: C:\Users\user\Desktop\URGENT MEDICAL REQUIREMENT.exe | Process Stats: CPU usage > 90% for more than 60s |
Source: C:\Users\user\Desktop\URGENT MEDICAL REQUIREMENT.exe | Code function: 0_2_00421847 rdtsc |
Source: C:\Users\user\Desktop\URGENT MEDICAL REQUIREMENT.exe | Code function: 0_2_00426031 mov eax, dword ptr fs:[00000030h] |
Source: C:\Users\user\Desktop\URGENT MEDICAL REQUIREMENT.exe | Code function: 0_2_00422437 mov eax, dword ptr fs:[00000030h] |
Source: C:\Users\user\Desktop\URGENT MEDICAL REQUIREMENT.exe | Code function: 0_2_00425A39 mov eax, dword ptr fs:[00000030h] |
Source: C:\Users\user\Desktop\URGENT MEDICAL REQUIREMENT.exe | Code function: 0_2_0042223C mov eax, dword ptr fs:[00000030h] |
Source: C:\Users\user\Desktop\URGENT MEDICAL REQUIREMENT.exe | Code function: 0_2_004232E6 mov eax, dword ptr fs:[00000030h] |
Source: C:\Users\user\Desktop\URGENT MEDICAL REQUIREMENT.exe | Code function: 0_2_0042249A mov eax, dword ptr fs:[00000030h] |
Source: C:\Users\user\Desktop\URGENT MEDICAL REQUIREMENT.exe | Code function: 0_2_00421F4F mov eax, dword ptr fs:[00000030h] |
Source: C:\Users\user\Desktop\URGENT MEDICAL REQUIREMENT.exe | Code function: 0_2_00423303 mov eax, dword ptr fs:[00000030h] |
Source: all processes | Thread injection, dropped files, key value created, disk infection and DNS query: no activity detected |
Source: URGENT MEDICAL REQUIREMENT.exe, 00000000.00000002.1258241168.0000000000C70000.00000002.00000001.sdmp | Binary or memory string: Shell_TrayWnd |
Source: URGENT MEDICAL REQUIREMENT.exe, 00000000.00000002.1258241168.0000000000C70000.00000002.00000001.sdmp | Binary or memory string: Progman |
Source: URGENT MEDICAL REQUIREMENT.exe, 00000000.00000002.1258241168.0000000000C70000.00000002.00000001.sdmp | Binary or memory string: SProgram Managerl |
Source: URGENT MEDICAL REQUIREMENT.exe, 00000000.00000002.1258241168.0000000000C70000.00000002.00000001.sdmp | Binary or memory string: Shell_TrayWnd, |
Source: URGENT MEDICAL REQUIREMENT.exe, 00000000.00000002.1258241168.0000000000C70000.00000002.00000001.sdmp | Binary or memory string: Progmanlock |
Source: C:\Users\user\Desktop\URGENT MEDICAL REQUIREMENT.exe | Code function: 0_2_00422E83 cpuid |
Thumbnails
This section contains all screenshots as thumbnails, including those not shown in the slideshow.