Source: SPPG contract 9200355_Acma Engineers SP Power_Contract No 9200355.exe | Static PE information: LOCAL_SYMS_STRIPPED, 32BIT_MACHINE, EXECUTABLE_IMAGE, LINE_NUMS_STRIPPED, RELOCS_STRIPPED |
Source: SPPG contract 9200355_Acma Engineers SP Power_Contract No 9200355.exe, 00000000.00000002.1274016968.000000000079A000.00000004.00000020.sdmp | Binary or memory string: <HOOK MODULE="DDRAW.DLL" FUNCTION="DirectDrawCreateEx"/> |
Source: C:\Users\user\Desktop\SPPG contract 9200355_Acma Engineers SP Power_Contract No 9200355.exe | Process Stats: CPU usage > 98% |
Source: SPPG contract 9200355_Acma Engineers SP Power_Contract No 9200355.exe | Static PE information: Resource name: RT_ICON type: GLS_BINARY_LSB_FIRST |
Source: SPPG contract 9200355_Acma Engineers SP Power_Contract No 9200355.exe, 00000000.00000002.1272656837.0000000000410000.00000002.00020000.sdmp | Binary or memory string: OriginalFilenameIranske.exe vs SPPG contract 9200355_Acma Engineers SP Power_Contract No 9200355.exe |
Source: SPPG contract 9200355_Acma Engineers SP Power_Contract No 9200355.exe, 00000000.00000002.1273773993.0000000000740000.00000002.00000001.sdmp | Binary or memory string: OriginalFilenameuser32j% vs SPPG contract 9200355_Acma Engineers SP Power_Contract No 9200355.exe |
Source: SPPG contract 9200355_Acma Engineers SP Power_Contract No 9200355.exe | Binary or memory string: OriginalFilenameIranske.exe vs SPPG contract 9200355_Acma Engineers SP Power_Contract No 9200355.exe |
Source: SPPG contract 9200355_Acma Engineers SP Power_Contract No 9200355.exe | Static PE information: LOCAL_SYMS_STRIPPED, 32BIT_MACHINE, EXECUTABLE_IMAGE, LINE_NUMS_STRIPPED, RELOCS_STRIPPED |
Source: classification engine | Classification label: mal76.troj.evad.winEXE@1/0@0/0 |
Source: C:\Users\user\Desktop\SPPG contract 9200355_Acma Engineers SP Power_Contract No 9200355.exe | File created: C:\Users\user\AppData\Local\Temp\~DF0ED9CA4C86CF4DE5.TMP | Jump to behavior |
Source: SPPG contract 9200355_Acma Engineers SP Power_Contract No 9200355.exe | Static PE information: Section: .text IMAGE_SCN_MEM_EXECUTE, IMAGE_SCN_CNT_CODE, IMAGE_SCN_MEM_READ |
Source: C:\Users\user\Desktop\SPPG contract 9200355_Acma Engineers SP Power_Contract No 9200355.exe | Section loaded: C:\Windows\SysWOW64\msvbvm60.dll |
Source: C:\Users\user\Desktop\SPPG contract 9200355_Acma Engineers SP Power_Contract No 9200355.exe | Key opened: HKEY_CURRENT_USER\Software\Policies\Microsoft\Windows\Safer\CodeIdentifiers |
Source: Yara match | File source: Process Memory Space: SPPG contract 9200355_Acma Engineers SP Power_Contract No 9200355.exe PID: 6072, type: MEMORY |
Source: Yara match | File source: Process Memory Space: SPPG contract 9200355_Acma Engineers SP Power_Contract No 9200355.exe PID: 6072, type: MEMORY |
Source: C:\Users\user\Desktop\SPPG contract 9200355_Acma Engineers SP Power_Contract No 9200355.exe | Code function: 0_2_00407820 push ds; retf |
Source: C:\Users\user\Desktop\SPPG contract 9200355_Acma Engineers SP Power_Contract No 9200355.exe | Code function: 0_2_00406E33 push ebp; retf |
Source: C:\Users\user\Desktop\SPPG contract 9200355_Acma Engineers SP Power_Contract No 9200355.exe | Code function: 0_2_004048E0 push ebp; ret |
Source: C:\Users\user\Desktop\SPPG contract 9200355_Acma Engineers SP Power_Contract No 9200355.exe | Code function: 0_2_00406A8F push ebp; retf |
Source: C:\Users\user\Desktop\SPPG contract 9200355_Acma Engineers SP Power_Contract No 9200355.exe | Code function: 0_2_00406C95 push ecx; retf |
Source: C:\Users\user\Desktop\SPPG contract 9200355_Acma Engineers SP Power_Contract No 9200355.exe | Code function: 0_2_00405568 push esp; retf |
Source: C:\Users\user\Desktop\SPPG contract 9200355_Acma Engineers SP Power_Contract No 9200355.exe | Code function: 0_2_00406B0C push ds; retf |
Source: C:\Users\user\Desktop\SPPG contract 9200355_Acma Engineers SP Power_Contract No 9200355.exe | Code function: 0_2_004077D4 push es; ret |
Source: C:\Users\user\Desktop\SPPG contract 9200355_Acma Engineers SP Power_Contract No 9200355.exe | Code function: 0_2_004077D4 push ds; retf |
Source: C:\Users\user\Desktop\SPPG contract 9200355_Acma Engineers SP Power_Contract No 9200355.exe | Code function: 0_2_00404DDB push ecx; retf |
Source: C:\Users\user\Desktop\SPPG contract 9200355_Acma Engineers SP Power_Contract No 9200355.exe | Code function: 0_2_00406BF1 push cs; ret |
Source: C:\Users\user\Desktop\SPPG contract 9200355_Acma Engineers SP Power_Contract No 9200355.exe | Code function: 0_2_004047B2 push ebp; retf |
Source: C:\Users\user\Desktop\SPPG contract 9200355_Acma Engineers SP Power_Contract No 9200355.exe | Code function: 0_2_00784A33 push esp; iretd |
Source: C:\Users\user\Desktop\SPPG contract 9200355_Acma Engineers SP Power_Contract No 9200355.exe | Code function: 0_2_00780005 push esp; ret |
Source: C:\Users\user\Desktop\SPPG contract 9200355_Acma Engineers SP Power_Contract No 9200355.exe | Code function: 0_2_00780007 push esp; ret |
Source: C:\Users\user\Desktop\SPPG contract 9200355_Acma Engineers SP Power_Contract No 9200355.exe | Code function: 0_2_007800AD push esp; ret |
Source: C:\Users\user\Desktop\SPPG contract 9200355_Acma Engineers SP Power_Contract No 9200355.exe | Code function: 0_2_007800AD push esp; ret |
Source: C:\Users\user\Desktop\SPPG contract 9200355_Acma Engineers SP Power_Contract No 9200355.exe | Code function: 0_2_0078009B push esp; ret |
Source: C:\Users\user\Desktop\SPPG contract 9200355_Acma Engineers SP Power_Contract No 9200355.exe | Code function: 0_2_0078009B push edx; retf |
Source: C:\Users\user\Desktop\SPPG contract 9200355_Acma Engineers SP Power_Contract No 9200355.exe | Code function: 0_2_00784A90 push eax; retf |
Source: C:\Users\user\Desktop\SPPG contract 9200355_Acma Engineers SP Power_Contract No 9200355.exe | Code function: 0_2_00780102 push esp; ret |
Source: C:\Users\user\Desktop\SPPG contract 9200355_Acma Engineers SP Power_Contract No 9200355.exe | Code function: 0_2_00780102 push edx; retf |
Source: C:\Users\user\Desktop\SPPG contract 9200355_Acma Engineers SP Power_Contract No 9200355.exe | Process information set: NOOPENFILEERRORBOX |
Source: C:\Users\user\Desktop\SPPG contract 9200355_Acma Engineers SP Power_Contract No 9200355.exe | Code function: 0_2_00784049 |
Source: C:\Users\user\Desktop\SPPG contract 9200355_Acma Engineers SP Power_Contract No 9200355.exe | Code function: 0_2_007840FD |
Source: C:\Users\user\Desktop\SPPG contract 9200355_Acma Engineers SP Power_Contract No 9200355.exe | Code function: 0_2_00784094 |
Source: C:\Users\user\Desktop\SPPG contract 9200355_Acma Engineers SP Power_Contract No 9200355.exe | Code function: 0_2_007825F7 |
Source: C:\Users\user\Desktop\SPPG contract 9200355_Acma Engineers SP Power_Contract No 9200355.exe | Code function: 0_2_00781BD9 |
Source: C:\Users\user\Desktop\SPPG contract 9200355_Acma Engineers SP Power_Contract No 9200355.exe | RDTSC instruction interceptor: First address: 00000000007866BA second address: 00000000007866BA instructions: |
Source: C:\Users\user\Desktop\SPPG contract 9200355_Acma Engineers SP Power_Contract No 9200355.exe | System information queried: CurrentTimeZoneInformation |
Source: SPPG contract 9200355_Acma Engineers SP Power_Contract No 9200355.exe, 00000000.00000002.1273943775.0000000000780000.00000040.00000001.sdmp | Binary or memory string: C:\PROGRAM FILES\QEMU-GA\QEMU-GA.EXE8 |
Source: SPPG contract 9200355_Acma Engineers SP Power_Contract No 9200355.exe | Binary or memory string: C:\PROGRAM FILES\QEMU-GA\QEMU-GA.EXE |
Source: C:\Users\user\Desktop\SPPG contract 9200355_Acma Engineers SP Power_Contract No 9200355.exe | RDTSC instruction interceptor: First address: 00000000007866BA second address: 00000000007866BA instructions: |
Source: C:\Users\user\Desktop\SPPG contract 9200355_Acma Engineers SP Power_Contract No 9200355.exe | RDTSC instruction interceptor: First address: 000000000078628D second address: 000000000078628D instructions: 0x00000000 rdtsc 0x00000002 xor eax, eax 0x00000004 inc eax 0x00000005 cpuid 0x00000007 popad 0x00000008 call 00007FA4E4759B24h 0x0000000d lfence 0x00000010 mov edx, dword ptr [7FFE0014h] 0x00000016 lfence 0x00000019 ret 0x0000001a sub edx, esi 0x0000001c ret 0x0000001d add edi, edx 0x0000001f jmp 00007FA4E4759B1Ah 0x00000021 test bl, bl 0x00000023 dec dword ptr [ebp+000000F8h] 0x00000029 cmp dword ptr [ebp+000000F8h], 00000000h 0x00000030 jne 00007FA4E4759A6Eh 0x00000032 fnop 0x00000034 call 00007FA4E4759B53h 0x00000039 call 00007FA4E4759B34h 0x0000003e lfence 0x00000041 mov edx, dword ptr [7FFE0014h] 0x00000047 lfence 0x0000004a ret 0x0000004b mov esi, edx 0x0000004d pushad 0x0000004e rdtsc |
Source: C:\Users\user\Desktop\SPPG contract 9200355_Acma Engineers SP Power_Contract No 9200355.exe | Code function: 0_2_00782870 rdtsc |
Source: all processes | Thread injection, dropped files, key value created, disk infection and DNS query: no activity detected |
Source: SPPG contract 9200355_Acma Engineers SP Power_Contract No 9200355.exe, 00000000.00000002.1273943775.0000000000780000.00000040.00000001.sdmp | Binary or memory string: C:\Program Files\Qemu-ga\qemu-ga.exe8 |
Source: SPPG contract 9200355_Acma Engineers SP Power_Contract No 9200355.exe | Binary or memory string: C:\Program Files\Qemu-ga\qemu-ga.exe |
Source: C:\Users\user\Desktop\SPPG contract 9200355_Acma Engineers SP Power_Contract No 9200355.exe | Process Stats: CPU usage > 90% for more than 60s |
Source: C:\Users\user\Desktop\SPPG contract 9200355_Acma Engineers SP Power_Contract No 9200355.exe | Code function: 0_2_00782870 rdtsc |
Source: C:\Users\user\Desktop\SPPG contract 9200355_Acma Engineers SP Power_Contract No 9200355.exe | Code function: 0_2_0078346F mov eax, dword ptr fs:[00000030h] |
Source: C:\Users\user\Desktop\SPPG contract 9200355_Acma Engineers SP Power_Contract No 9200355.exe | Code function: 0_2_00786A35 mov eax, dword ptr fs:[00000030h] |
Source: C:\Users\user\Desktop\SPPG contract 9200355_Acma Engineers SP Power_Contract No 9200355.exe | Code function: 0_2_00786A19 mov eax, dword ptr fs:[00000030h] |
Source: C:\Users\user\Desktop\SPPG contract 9200355_Acma Engineers SP Power_Contract No 9200355.exe | Code function: 0_2_007838D0 mov eax, dword ptr fs:[00000030h] |
Source: C:\Users\user\Desktop\SPPG contract 9200355_Acma Engineers SP Power_Contract No 9200355.exe | Code function: 0_2_00782368 mov eax, dword ptr fs:[00000030h] |
Source: C:\Users\user\Desktop\SPPG contract 9200355_Acma Engineers SP Power_Contract No 9200355.exe | Code function: 0_2_0078232A mov eax, dword ptr fs:[00000030h] |
Source: C:\Users\user\Desktop\SPPG contract 9200355_Acma Engineers SP Power_Contract No 9200355.exe | Code function: 0_2_00785F14 mov eax, dword ptr fs:[00000030h] |
Source: C:\Users\user\Desktop\SPPG contract 9200355_Acma Engineers SP Power_Contract No 9200355.exe | Code function: 0_2_007825FF mov eax, dword ptr fs:[00000030h] |
Source: C:\Users\user\Desktop\SPPG contract 9200355_Acma Engineers SP Power_Contract No 9200355.exe | Code function: 0_2_007825F7 mov eax, dword ptr fs:[00000030h] |
Source: C:\Users\user\Desktop\SPPG contract 9200355_Acma Engineers SP Power_Contract No 9200355.exe | Code function: 0_2_00781BD9 mov eax, dword ptr fs:[00000030h] |
Source: C:\Users\user\Desktop\SPPG contract 9200355_Acma Engineers SP Power_Contract No 9200355.exe | Code function: 0_2_007859D7 mov eax, dword ptr fs:[00000030h] |
Source: C:\Users\user\Desktop\SPPG contract 9200355_Acma Engineers SP Power_Contract No 9200355.exe | Code function: 0_2_007867C1 mov eax, dword ptr fs:[00000030h] |
Source: C:\Users\user\Desktop\SPPG contract 9200355_Acma Engineers SP Power_Contract No 9200355.exe | Code function: 0_2_007823AE mov eax, dword ptr fs:[00000030h] |
Source: all processes | Thread injection, dropped files, key value created, disk infection and DNS query: no activity detected |
Source: SPPG contract 9200355_Acma Engineers SP Power_Contract No 9200355.exe, 00000000.00000002.1274157084.0000000000E20000.00000002.00000001.sdmp | Binary or memory string: Program Manager |
Source: SPPG contract 9200355_Acma Engineers SP Power_Contract No 9200355.exe, 00000000.00000002.1274157084.0000000000E20000.00000002.00000001.sdmp | Binary or memory string: Shell_TrayWnd |
Source: SPPG contract 9200355_Acma Engineers SP Power_Contract No 9200355.exe, 00000000.00000002.1274157084.0000000000E20000.00000002.00000001.sdmp | Binary or memory string: Progman |
Source: SPPG contract 9200355_Acma Engineers SP Power_Contract No 9200355.exe, 00000000.00000002.1274157084.0000000000E20000.00000002.00000001.sdmp | Binary or memory string: Progmanlock |
Source: C:\Users\user\Desktop\SPPG contract 9200355_Acma Engineers SP Power_Contract No 9200355.exe | Code function: 0_2_00784E29 cpuid |
Thumbnails
This section contains all screenshots as thumbnails, including those not shown in the slideshow.