Source: uxtheme.dll |
Static PE information: Number of sections : 17 > 10 |
Source: classification engine |
Classification label: clean2.winDLL@1/0@0/0 |
Source: uxtheme.dll |
Static PE information: Section: .text IMAGE_SCN_ALIGN_MASK, IMAGE_SCN_ALIGN_256BYTES, IMAGE_SCN_ALIGN_16BYTES, IMAGE_SCN_ALIGN_64BYTES, IMAGE_SCN_ALIGN_1BYTES, IMAGE_SCN_MEM_EXECUTE, IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_ALIGN_2048BYTES, IMAGE_SCN_ALIGN_1024BYTES, IMAGE_SCN_ALIGN_32BYTES, IMAGE_SCN_ALIGN_4BYTES, IMAGE_SCN_ALIGN_8BYTES, IMAGE_SCN_CNT_CODE, IMAGE_SCN_ALIGN_8192BYTES, IMAGE_SCN_ALIGN_4096BYTES, IMAGE_SCN_MEM_READ |
Source: C:\Windows\System32\loaddll64.exe |
Key opened: HKEY_LOCAL_MACHINE\Software\Policies\Microsoft\Windows\Safer\CodeIdentifiers |
Jump to behavior |
Source: uxtheme.dll |
Static PE information: Image base 0x64880000 > 0x60000000 |
Source: uxtheme.dll |
Static PE information: real checksum: 0x18e9e should be: 0xc2cd |
Source: uxtheme.dll |
Static PE information: section name: .xdata |
Source: uxtheme.dll |
Static PE information: section name: /4 |
Source: uxtheme.dll |
Static PE information: section name: /19 |
Source: uxtheme.dll |
Static PE information: section name: /31 |
Source: uxtheme.dll |
Static PE information: section name: /45 |
Source: uxtheme.dll |
Static PE information: section name: /57 |
Source: uxtheme.dll |
Static PE information: section name: /70 |
Source: all processes |
Thread injection, dropped files, key value created, disk infection and DNS query: no activity detected |
Source: all processes |
Thread injection, dropped files, key value created, disk infection and DNS query: no activity detected |
Source: C:\Windows\System32\loaddll64.exe |
Code function: 0_2_648815C0 RtlCaptureContext,RtlLookupFunctionEntry,RtlVirtualUnwind,SetUnhandledExceptionFilter,UnhandledExceptionFilter,GetCurrentProcess,TerminateProcess,abort, |
0_2_648815C0 |
Source: C:\Windows\System32\loaddll64.exe |
Code function: 0_2_648814E0 GetSystemTimeAsFileTime,GetCurrentProcessId,GetCurrentThreadId,GetTickCount,QueryPerformanceCounter, |
0_2_648814E0 |