Analysis Report SecuriteInfo.com.Trojan.GenericKDZ.73120.139.15119

Overview

General Information

Sample Name: SecuriteInfo.com.Trojan.GenericKDZ.73120.139.15119 (renamed file extension from 15119 to exe)
Analysis ID: 356587
MD5: fac509b5175d3647945bdbf7ac010acc
SHA1: 048a87d3a938217f555da58662da7bfe59971a9e
SHA256: 44283ee3be33ad2077f6c8c18b1699f3d694cb936336523b299646f1a39ea8fc

Most interesting Screenshot:

Detection

FormBook
Score: 100
Range: 0 - 100
Whitelisted: false
Confidence: 100%

Signatures

Found malware configuration
Malicious sample detected (through community Yara rule)
Multi AV Scanner detection for submitted file
Yara detected AntiVM_3
Yara detected FormBook
.NET source code contains potential unpacker
.NET source code contains very large strings
C2 URLs / IPs found in malware configuration
Machine Learning detection for sample
Tries to detect sandboxes and other dynamic analysis tools (process name or module or function)
Tries to detect virtualization through RDTSC time measurements
Antivirus or Machine Learning detection for unpacked file
Checks if the current process is being debugged
Contains functionality for execution timing, often used to detect debuggers
Contains functionality to access loader functionality (e.g. LdrGetProcedureAddress)
Contains functionality to call native functions
Contains functionality to read the PEB
Contains long sleeps (>= 3 min)
Creates a process in suspended mode (likely to inject code)
Detected potential crypto function
Found inlined nop instructions (likely shell or obfuscated code)
Found potential string decryption / allocating functions
May sleep (evasive loops) to hinder dynamic analysis
Queries the volume information (name, serial number etc) of a device
Sample file is different than original file name gathered from version info
Uses 32bit PE files
Uses code obfuscation techniques (call, push, ret)
Yara signature match

Classification

AV Detection:

barindex
Found malware configuration
Source: 2.2.SecuriteInfo.com.Trojan.GenericKDZ.73120.139.exe.400000.0.unpack Malware Configuration Extractor: FormBook {"C2 list": ["www.rizrvd.com/bw82/"], "decoy": ["fundamentaliemef.com", "gallerybrows.com", "leadeligey.com", "octoberx2.online", "climaxnovels.com", "gdsjgf.com", "curateherstories.com", "blacksailus.com", "yjpps.com", "gmobilet.com", "fcoins.club", "foreverlive2027.com", "healthyfifties.com", "wmarquezy.com", "housebulb.com", "thebabyfriendly.com", "primajayaintiperkasa.com", "learnplaychess.com", "chrisbubser.digital", "xn--avenr-wsa.com", "exlineinsurance.com", "thrivezi.com", "tuvandadayvitos24h.online", "illfingers.com", "usmedicarenow.com", "pandabutik.com", "engageautism.info", "magnabeautystyle.com", "texasdryroof.com", "woodlandpizzahartford.com", "dameadamea.com", "sedaskincare.com", "ruaysatu99.com", "mybestaide.com", "nikolaichan.com", "mrcabinetkitchenandbath.com", "ondemandbarbering.com", "activagebenefits.net", "srcsvcs.com", "cbrealvitalize.com", "ismaelworks.com", "medkomp.online", "ninasangtani.com", "h2oturkiye.com", "kolamart.com", "acdfr.com", "twistedtailgatesweeps1.com", "ramjamdee.com", "thedancehalo.com", "joeisono.com", "glasshouseroadtrip.com", "okcpp.com", "riggsfarmfenceservices.com", "mgg360.com", "xn--oi2b190cymc.com", "ctfocbdwholesale.com", "openspiers.com", "rumblingrambles.com", "thepoetrictedstudio.com", "magiclabs.media", "wellnesssensation.com", "lakegastonautoparts.com", "dealsonwheeeles.com", "semenboostplus.com"]}
Multi AV Scanner detection for submitted file
Source: SecuriteInfo.com.Trojan.GenericKDZ.73120.139.exe Virustotal: Detection: 36% Perma Link
Source: SecuriteInfo.com.Trojan.GenericKDZ.73120.139.exe ReversingLabs: Detection: 29%
Yara detected FormBook
Source: Yara match File source: 00000002.00000002.224039712.0000000000400000.00000040.00000001.sdmp, type: MEMORY
Source: Yara match File source: 00000000.00000002.224800988.00000000036E9000.00000004.00000001.sdmp, type: MEMORY
Source: Yara match File source: 2.2.SecuriteInfo.com.Trojan.GenericKDZ.73120.139.exe.400000.0.raw.unpack, type: UNPACKEDPE
Source: Yara match File source: 2.2.SecuriteInfo.com.Trojan.GenericKDZ.73120.139.exe.400000.0.unpack, type: UNPACKEDPE
Source: Yara match File source: 0.2.SecuriteInfo.com.Trojan.GenericKDZ.73120.139.exe.386d620.2.raw.unpack, type: UNPACKEDPE
Source: Yara match File source: 0.2.SecuriteInfo.com.Trojan.GenericKDZ.73120.139.exe.381da00.3.raw.unpack, type: UNPACKEDPE
Machine Learning detection for sample
Source: SecuriteInfo.com.Trojan.GenericKDZ.73120.139.exe Joe Sandbox ML: detected
Antivirus or Machine Learning detection for unpacked file
Source: 2.2.SecuriteInfo.com.Trojan.GenericKDZ.73120.139.exe.400000.0.unpack Avira: Label: TR/Crypt.ZPACK.Gen

Compliance:

barindex
Uses 32bit PE files
Source: SecuriteInfo.com.Trojan.GenericKDZ.73120.139.exe Static PE information: 32BIT_MACHINE, EXECUTABLE_IMAGE
Contains modern PE file flags such as dynamic base (ASLR) or NX
Source: SecuriteInfo.com.Trojan.GenericKDZ.73120.139.exe Static PE information: NO_SEH, TERMINAL_SERVER_AWARE, DYNAMIC_BASE, NX_COMPAT
Binary contains paths to debug symbols
Source: Binary string: wntdll.pdbUGP source: SecuriteInfo.com.Trojan.GenericKDZ.73120.139.exe, 00000002.00000002.224505859.0000000001370000.00000040.00000001.sdmp
Source: Binary string: wntdll.pdb source: SecuriteInfo.com.Trojan.GenericKDZ.73120.139.exe

Software Vulnerabilities:

barindex
Found inlined nop instructions (likely shell or obfuscated code)
Source: C:\Users\user\Desktop\SecuriteInfo.com.Trojan.GenericKDZ.73120.139.exe Code function: 4x nop then jmp 05840BBEh 0_2_05840040
Source: C:\Users\user\Desktop\SecuriteInfo.com.Trojan.GenericKDZ.73120.139.exe Code function: 4x nop then mov dword ptr [ebp-18h], 00000000h 0_2_058422A0
Source: C:\Users\user\Desktop\SecuriteInfo.com.Trojan.GenericKDZ.73120.139.exe Code function: 4x nop then jmp 05840BBEh 0_2_05840CC7
Source: C:\Users\user\Desktop\SecuriteInfo.com.Trojan.GenericKDZ.73120.139.exe Code function: 4x nop then jmp 05840BBEh 0_2_05840119
Source: C:\Users\user\Desktop\SecuriteInfo.com.Trojan.GenericKDZ.73120.139.exe Code function: 4x nop then jmp 05840BBEh 0_2_05840007
Source: C:\Users\user\Desktop\SecuriteInfo.com.Trojan.GenericKDZ.73120.139.exe Code function: 4x nop then jmp 05840BBEh 0_2_05840B81
Source: C:\Users\user\Desktop\SecuriteInfo.com.Trojan.GenericKDZ.73120.139.exe Code function: 4x nop then mov dword ptr [ebp-18h], 00000000h 0_2_05842290

Networking:

barindex
C2 URLs / IPs found in malware configuration
Source: Malware configuration extractor URLs: www.rizrvd.com/bw82/
Source: SecuriteInfo.com.Trojan.GenericKDZ.73120.139.exe, 00000000.00000002.224526375.00000000026E1000.00000004.00000001.sdmp String found in binary or memory: http://schemas.xmlsoap.org/ws/2005/05/identity/claims/name
Source: SecuriteInfo.com.Trojan.GenericKDZ.73120.139.exe, 00000000.00000002.224526375.00000000026E1000.00000004.00000001.sdmp String found in binary or memory: https://stackpath.bootstrapcdn.com/bootstrap/4.5.0/css/bootstrap.min.css

E-Banking Fraud:

barindex
Yara detected FormBook
Source: Yara match File source: 00000002.00000002.224039712.0000000000400000.00000040.00000001.sdmp, type: MEMORY
Source: Yara match File source: 00000000.00000002.224800988.00000000036E9000.00000004.00000001.sdmp, type: MEMORY
Source: Yara match File source: 2.2.SecuriteInfo.com.Trojan.GenericKDZ.73120.139.exe.400000.0.raw.unpack, type: UNPACKEDPE
Source: Yara match File source: 2.2.SecuriteInfo.com.Trojan.GenericKDZ.73120.139.exe.400000.0.unpack, type: UNPACKEDPE
Source: Yara match File source: 0.2.SecuriteInfo.com.Trojan.GenericKDZ.73120.139.exe.386d620.2.raw.unpack, type: UNPACKEDPE
Source: Yara match File source: 0.2.SecuriteInfo.com.Trojan.GenericKDZ.73120.139.exe.381da00.3.raw.unpack, type: UNPACKEDPE

System Summary:

barindex
Malicious sample detected (through community Yara rule)
Source: 00000002.00000002.224039712.0000000000400000.00000040.00000001.sdmp, type: MEMORY Matched rule: autogenerated rule brought to you by yara-signator Author: Felix Bilstein - yara-signator at cocacoding dot com
Source: 00000002.00000002.224039712.0000000000400000.00000040.00000001.sdmp, type: MEMORY Matched rule: detect Formbook in memory Author: JPCERT/CC Incident Response Group
Source: 00000000.00000002.224800988.00000000036E9000.00000004.00000001.sdmp, type: MEMORY Matched rule: autogenerated rule brought to you by yara-signator Author: Felix Bilstein - yara-signator at cocacoding dot com
Source: 00000000.00000002.224800988.00000000036E9000.00000004.00000001.sdmp, type: MEMORY Matched rule: detect Formbook in memory Author: JPCERT/CC Incident Response Group
Source: 2.2.SecuriteInfo.com.Trojan.GenericKDZ.73120.139.exe.400000.0.raw.unpack, type: UNPACKEDPE Matched rule: autogenerated rule brought to you by yara-signator Author: Felix Bilstein - yara-signator at cocacoding dot com
Source: 2.2.SecuriteInfo.com.Trojan.GenericKDZ.73120.139.exe.400000.0.raw.unpack, type: UNPACKEDPE Matched rule: detect Formbook in memory Author: JPCERT/CC Incident Response Group
Source: 2.2.SecuriteInfo.com.Trojan.GenericKDZ.73120.139.exe.400000.0.unpack, type: UNPACKEDPE Matched rule: autogenerated rule brought to you by yara-signator Author: Felix Bilstein - yara-signator at cocacoding dot com
Source: 2.2.SecuriteInfo.com.Trojan.GenericKDZ.73120.139.exe.400000.0.unpack, type: UNPACKEDPE Matched rule: detect Formbook in memory Author: JPCERT/CC Incident Response Group
Source: 0.2.SecuriteInfo.com.Trojan.GenericKDZ.73120.139.exe.386d620.2.raw.unpack, type: UNPACKEDPE Matched rule: autogenerated rule brought to you by yara-signator Author: Felix Bilstein - yara-signator at cocacoding dot com
Source: 0.2.SecuriteInfo.com.Trojan.GenericKDZ.73120.139.exe.386d620.2.raw.unpack, type: UNPACKEDPE Matched rule: detect Formbook in memory Author: JPCERT/CC Incident Response Group
Source: 0.2.SecuriteInfo.com.Trojan.GenericKDZ.73120.139.exe.381da00.3.raw.unpack, type: UNPACKEDPE Matched rule: autogenerated rule brought to you by yara-signator Author: Felix Bilstein - yara-signator at cocacoding dot com
Source: 0.2.SecuriteInfo.com.Trojan.GenericKDZ.73120.139.exe.381da00.3.raw.unpack, type: UNPACKEDPE Matched rule: detect Formbook in memory Author: JPCERT/CC Incident Response Group
.NET source code contains very large strings
Source: SecuriteInfo.com.Trojan.GenericKDZ.73120.139.exe, FrmStart.cs Long String: Length: 13656
Contains functionality to call native functions
Source: C:\Users\user\Desktop\SecuriteInfo.com.Trojan.GenericKDZ.73120.139.exe Code function: 2_2_004181B0 NtCreateFile, 2_2_004181B0
Source: C:\Users\user\Desktop\SecuriteInfo.com.Trojan.GenericKDZ.73120.139.exe Code function: 2_2_00418260 NtReadFile, 2_2_00418260
Source: C:\Users\user\Desktop\SecuriteInfo.com.Trojan.GenericKDZ.73120.139.exe Code function: 2_2_004182E0 NtClose, 2_2_004182E0
Source: C:\Users\user\Desktop\SecuriteInfo.com.Trojan.GenericKDZ.73120.139.exe Code function: 2_2_00418390 NtAllocateVirtualMemory, 2_2_00418390
Source: C:\Users\user\Desktop\SecuriteInfo.com.Trojan.GenericKDZ.73120.139.exe Code function: 2_2_004181AA NtCreateFile, 2_2_004181AA
Source: C:\Users\user\Desktop\SecuriteInfo.com.Trojan.GenericKDZ.73120.139.exe Code function: 2_2_0041825C NtReadFile, 2_2_0041825C
Source: C:\Users\user\Desktop\SecuriteInfo.com.Trojan.GenericKDZ.73120.139.exe Code function: 2_2_004182DA NtClose, 2_2_004182DA
Source: C:\Users\user\Desktop\SecuriteInfo.com.Trojan.GenericKDZ.73120.139.exe Code function: 2_2_013D9860 NtQuerySystemInformation,LdrInitializeThunk, 2_2_013D9860
Source: C:\Users\user\Desktop\SecuriteInfo.com.Trojan.GenericKDZ.73120.139.exe Code function: 2_2_013D9660 NtAllocateVirtualMemory,LdrInitializeThunk, 2_2_013D9660
Source: C:\Users\user\Desktop\SecuriteInfo.com.Trojan.GenericKDZ.73120.139.exe Code function: 2_2_013D96E0 NtFreeVirtualMemory,LdrInitializeThunk, 2_2_013D96E0
Source: C:\Users\user\Desktop\SecuriteInfo.com.Trojan.GenericKDZ.73120.139.exe Code function: 2_2_013D9910 NtAdjustPrivilegesToken, 2_2_013D9910
Source: C:\Users\user\Desktop\SecuriteInfo.com.Trojan.GenericKDZ.73120.139.exe Code function: 2_2_013D9950 NtQueueApcThread, 2_2_013D9950
Source: C:\Users\user\Desktop\SecuriteInfo.com.Trojan.GenericKDZ.73120.139.exe Code function: 2_2_013D99A0 NtCreateSection, 2_2_013D99A0
Source: C:\Users\user\Desktop\SecuriteInfo.com.Trojan.GenericKDZ.73120.139.exe Code function: 2_2_013D99D0 NtCreateProcessEx, 2_2_013D99D0
Source: C:\Users\user\Desktop\SecuriteInfo.com.Trojan.GenericKDZ.73120.139.exe Code function: 2_2_013D9820 NtEnumerateKey, 2_2_013D9820
Source: C:\Users\user\Desktop\SecuriteInfo.com.Trojan.GenericKDZ.73120.139.exe Code function: 2_2_013DB040 NtSuspendThread, 2_2_013DB040
Source: C:\Users\user\Desktop\SecuriteInfo.com.Trojan.GenericKDZ.73120.139.exe Code function: 2_2_013D9840 NtDelayExecution, 2_2_013D9840
Source: C:\Users\user\Desktop\SecuriteInfo.com.Trojan.GenericKDZ.73120.139.exe Code function: 2_2_013D98A0 NtWriteVirtualMemory, 2_2_013D98A0
Source: C:\Users\user\Desktop\SecuriteInfo.com.Trojan.GenericKDZ.73120.139.exe Code function: 2_2_013D98F0 NtReadVirtualMemory, 2_2_013D98F0
Source: C:\Users\user\Desktop\SecuriteInfo.com.Trojan.GenericKDZ.73120.139.exe Code function: 2_2_013D9B00 NtSetValueKey, 2_2_013D9B00
Source: C:\Users\user\Desktop\SecuriteInfo.com.Trojan.GenericKDZ.73120.139.exe Code function: 2_2_013DA3B0 NtGetContextThread, 2_2_013DA3B0
Source: C:\Users\user\Desktop\SecuriteInfo.com.Trojan.GenericKDZ.73120.139.exe Code function: 2_2_013D9A20 NtResumeThread, 2_2_013D9A20
Source: C:\Users\user\Desktop\SecuriteInfo.com.Trojan.GenericKDZ.73120.139.exe Code function: 2_2_013D9A10 NtQuerySection, 2_2_013D9A10
Source: C:\Users\user\Desktop\SecuriteInfo.com.Trojan.GenericKDZ.73120.139.exe Code function: 2_2_013D9A00 NtProtectVirtualMemory, 2_2_013D9A00
Source: C:\Users\user\Desktop\SecuriteInfo.com.Trojan.GenericKDZ.73120.139.exe Code function: 2_2_013D9A50 NtCreateFile, 2_2_013D9A50
Source: C:\Users\user\Desktop\SecuriteInfo.com.Trojan.GenericKDZ.73120.139.exe Code function: 2_2_013D9A80 NtOpenDirectoryObject, 2_2_013D9A80
Source: C:\Users\user\Desktop\SecuriteInfo.com.Trojan.GenericKDZ.73120.139.exe Code function: 2_2_013DAD30 NtSetContextThread, 2_2_013DAD30
Source: C:\Users\user\Desktop\SecuriteInfo.com.Trojan.GenericKDZ.73120.139.exe Code function: 2_2_013D9520 NtWaitForSingleObject, 2_2_013D9520
Source: C:\Users\user\Desktop\SecuriteInfo.com.Trojan.GenericKDZ.73120.139.exe Code function: 2_2_013D9560 NtWriteFile, 2_2_013D9560
Source: C:\Users\user\Desktop\SecuriteInfo.com.Trojan.GenericKDZ.73120.139.exe Code function: 2_2_013D9540 NtReadFile, 2_2_013D9540
Source: C:\Users\user\Desktop\SecuriteInfo.com.Trojan.GenericKDZ.73120.139.exe Code function: 2_2_013D95F0 NtQueryInformationFile, 2_2_013D95F0
Source: C:\Users\user\Desktop\SecuriteInfo.com.Trojan.GenericKDZ.73120.139.exe Code function: 2_2_013D95D0 NtClose, 2_2_013D95D0
Source: C:\Users\user\Desktop\SecuriteInfo.com.Trojan.GenericKDZ.73120.139.exe Code function: 2_2_013D9730 NtQueryVirtualMemory, 2_2_013D9730
Source: C:\Users\user\Desktop\SecuriteInfo.com.Trojan.GenericKDZ.73120.139.exe Code function: 2_2_013D9710 NtQueryInformationToken, 2_2_013D9710
Source: C:\Users\user\Desktop\SecuriteInfo.com.Trojan.GenericKDZ.73120.139.exe Code function: 2_2_013DA710 NtOpenProcessToken, 2_2_013DA710
Source: C:\Users\user\Desktop\SecuriteInfo.com.Trojan.GenericKDZ.73120.139.exe Code function: 2_2_013DA770 NtOpenThread, 2_2_013DA770
Source: C:\Users\user\Desktop\SecuriteInfo.com.Trojan.GenericKDZ.73120.139.exe Code function: 2_2_013D9770 NtSetInformationFile, 2_2_013D9770
Source: C:\Users\user\Desktop\SecuriteInfo.com.Trojan.GenericKDZ.73120.139.exe Code function: 2_2_013D9760 NtOpenProcess, 2_2_013D9760
Source: C:\Users\user\Desktop\SecuriteInfo.com.Trojan.GenericKDZ.73120.139.exe Code function: 2_2_013D97A0 NtUnmapViewOfSection, 2_2_013D97A0
Source: C:\Users\user\Desktop\SecuriteInfo.com.Trojan.GenericKDZ.73120.139.exe Code function: 2_2_013D9780 NtMapViewOfSection, 2_2_013D9780
Source: C:\Users\user\Desktop\SecuriteInfo.com.Trojan.GenericKDZ.73120.139.exe Code function: 2_2_013D9FE0 NtCreateMutant, 2_2_013D9FE0
Source: C:\Users\user\Desktop\SecuriteInfo.com.Trojan.GenericKDZ.73120.139.exe Code function: 2_2_013D9610 NtEnumerateValueKey, 2_2_013D9610
Source: C:\Users\user\Desktop\SecuriteInfo.com.Trojan.GenericKDZ.73120.139.exe Code function: 2_2_013D9670 NtQueryInformationProcess, 2_2_013D9670
Source: C:\Users\user\Desktop\SecuriteInfo.com.Trojan.GenericKDZ.73120.139.exe Code function: 2_2_013D9650 NtQueryValueKey, 2_2_013D9650
Source: C:\Users\user\Desktop\SecuriteInfo.com.Trojan.GenericKDZ.73120.139.exe Code function: 2_2_013D96D0 NtCreateKey, 2_2_013D96D0
Detected potential crypto function
Source: C:\Users\user\Desktop\SecuriteInfo.com.Trojan.GenericKDZ.73120.139.exe Code function: 0_2_02649608 0_2_02649608
Source: C:\Users\user\Desktop\SecuriteInfo.com.Trojan.GenericKDZ.73120.139.exe Code function: 0_2_0264C52D 0_2_0264C52D
Source: C:\Users\user\Desktop\SecuriteInfo.com.Trojan.GenericKDZ.73120.139.exe Code function: 0_2_0264AB34 0_2_0264AB34
Source: C:\Users\user\Desktop\SecuriteInfo.com.Trojan.GenericKDZ.73120.139.exe Code function: 0_2_05842C60 0_2_05842C60
Source: C:\Users\user\Desktop\SecuriteInfo.com.Trojan.GenericKDZ.73120.139.exe Code function: 0_2_05840F70 0_2_05840F70
Source: C:\Users\user\Desktop\SecuriteInfo.com.Trojan.GenericKDZ.73120.139.exe Code function: 0_2_05840040 0_2_05840040
Source: C:\Users\user\Desktop\SecuriteInfo.com.Trojan.GenericKDZ.73120.139.exe Code function: 0_2_05840007 0_2_05840007
Source: C:\Users\user\Desktop\SecuriteInfo.com.Trojan.GenericKDZ.73120.139.exe Code function: 2_2_0040102F 2_2_0040102F
Source: C:\Users\user\Desktop\SecuriteInfo.com.Trojan.GenericKDZ.73120.139.exe Code function: 2_2_00401030 2_2_00401030
Source: C:\Users\user\Desktop\SecuriteInfo.com.Trojan.GenericKDZ.73120.139.exe Code function: 2_2_00408C4C 2_2_00408C4C
Source: C:\Users\user\Desktop\SecuriteInfo.com.Trojan.GenericKDZ.73120.139.exe Code function: 2_2_00408C50 2_2_00408C50
Source: C:\Users\user\Desktop\SecuriteInfo.com.Trojan.GenericKDZ.73120.139.exe Code function: 2_2_0041B493 2_2_0041B493
Source: C:\Users\user\Desktop\SecuriteInfo.com.Trojan.GenericKDZ.73120.139.exe Code function: 2_2_0041CD28 2_2_0041CD28
Source: C:\Users\user\Desktop\SecuriteInfo.com.Trojan.GenericKDZ.73120.139.exe Code function: 2_2_00402D87 2_2_00402D87
Source: C:\Users\user\Desktop\SecuriteInfo.com.Trojan.GenericKDZ.73120.139.exe Code function: 2_2_00402D90 2_2_00402D90
Source: C:\Users\user\Desktop\SecuriteInfo.com.Trojan.GenericKDZ.73120.139.exe Code function: 2_2_0041CE77 2_2_0041CE77
Source: C:\Users\user\Desktop\SecuriteInfo.com.Trojan.GenericKDZ.73120.139.exe Code function: 2_2_00402FB0 2_2_00402FB0
Source: C:\Users\user\Desktop\SecuriteInfo.com.Trojan.GenericKDZ.73120.139.exe Code function: 2_2_013B4120 2_2_013B4120
Source: C:\Users\user\Desktop\SecuriteInfo.com.Trojan.GenericKDZ.73120.139.exe Code function: 2_2_0139F900 2_2_0139F900
Source: C:\Users\user\Desktop\SecuriteInfo.com.Trojan.GenericKDZ.73120.139.exe Code function: 2_2_013B99BF 2_2_013B99BF
Source: C:\Users\user\Desktop\SecuriteInfo.com.Trojan.GenericKDZ.73120.139.exe Code function: 2_2_013BA830 2_2_013BA830
Source: C:\Users\user\Desktop\SecuriteInfo.com.Trojan.GenericKDZ.73120.139.exe Code function: 2_2_01396800 2_2_01396800
Source: C:\Users\user\Desktop\SecuriteInfo.com.Trojan.GenericKDZ.73120.139.exe Code function: 2_2_01451002 2_2_01451002
Source: C:\Users\user\Desktop\SecuriteInfo.com.Trojan.GenericKDZ.73120.139.exe Code function: 2_2_0146E824 2_2_0146E824
Source: C:\Users\user\Desktop\SecuriteInfo.com.Trojan.GenericKDZ.73120.139.exe Code function: 2_2_013C20A0 2_2_013C20A0
Source: C:\Users\user\Desktop\SecuriteInfo.com.Trojan.GenericKDZ.73120.139.exe Code function: 2_2_013AB090 2_2_013AB090
Source: C:\Users\user\Desktop\SecuriteInfo.com.Trojan.GenericKDZ.73120.139.exe Code function: 2_2_014628EC 2_2_014628EC
Source: C:\Users\user\Desktop\SecuriteInfo.com.Trojan.GenericKDZ.73120.139.exe Code function: 2_2_014620A8 2_2_014620A8
Source: C:\Users\user\Desktop\SecuriteInfo.com.Trojan.GenericKDZ.73120.139.exe Code function: 2_2_0143CB4F 2_2_0143CB4F
Source: C:\Users\user\Desktop\SecuriteInfo.com.Trojan.GenericKDZ.73120.139.exe Code function: 2_2_013BA309 2_2_013BA309
Source: C:\Users\user\Desktop\SecuriteInfo.com.Trojan.GenericKDZ.73120.139.exe Code function: 2_2_013B3360 2_2_013B3360
Source: C:\Users\user\Desktop\SecuriteInfo.com.Trojan.GenericKDZ.73120.139.exe Code function: 2_2_0145231B 2_2_0145231B
Source: C:\Users\user\Desktop\SecuriteInfo.com.Trojan.GenericKDZ.73120.139.exe Code function: 2_2_01462B28 2_2_01462B28
Source: C:\Users\user\Desktop\SecuriteInfo.com.Trojan.GenericKDZ.73120.139.exe Code function: 2_2_013BAB40 2_2_013BAB40
Source: C:\Users\user\Desktop\SecuriteInfo.com.Trojan.GenericKDZ.73120.139.exe Code function: 2_2_013CEBB0 2_2_013CEBB0
Source: C:\Users\user\Desktop\SecuriteInfo.com.Trojan.GenericKDZ.73120.139.exe Code function: 2_2_0145DBD2 2_2_0145DBD2
Source: C:\Users\user\Desktop\SecuriteInfo.com.Trojan.GenericKDZ.73120.139.exe Code function: 2_2_014503DA 2_2_014503DA
Source: C:\Users\user\Desktop\SecuriteInfo.com.Trojan.GenericKDZ.73120.139.exe Code function: 2_2_013BEB9A 2_2_013BEB9A
Source: C:\Users\user\Desktop\SecuriteInfo.com.Trojan.GenericKDZ.73120.139.exe Code function: 2_2_014423E3 2_2_014423E3
Source: C:\Users\user\Desktop\SecuriteInfo.com.Trojan.GenericKDZ.73120.139.exe Code function: 2_2_013C138B 2_2_013C138B
Source: C:\Users\user\Desktop\SecuriteInfo.com.Trojan.GenericKDZ.73120.139.exe Code function: 2_2_0143EB8A 2_2_0143EB8A
Source: C:\Users\user\Desktop\SecuriteInfo.com.Trojan.GenericKDZ.73120.139.exe Code function: 2_2_013E8BE8 2_2_013E8BE8
Source: C:\Users\user\Desktop\SecuriteInfo.com.Trojan.GenericKDZ.73120.139.exe Code function: 2_2_013CABD8 2_2_013CABD8
Source: C:\Users\user\Desktop\SecuriteInfo.com.Trojan.GenericKDZ.73120.139.exe Code function: 2_2_013BB236 2_2_013BB236
Source: C:\Users\user\Desktop\SecuriteInfo.com.Trojan.GenericKDZ.73120.139.exe Code function: 2_2_0144FA2B 2_2_0144FA2B
Source: C:\Users\user\Desktop\SecuriteInfo.com.Trojan.GenericKDZ.73120.139.exe Code function: 2_2_0145E2C5 2_2_0145E2C5
Source: C:\Users\user\Desktop\SecuriteInfo.com.Trojan.GenericKDZ.73120.139.exe Code function: 2_2_01454AEF 2_2_01454AEF
Source: C:\Users\user\Desktop\SecuriteInfo.com.Trojan.GenericKDZ.73120.139.exe Code function: 2_2_014622AE 2_2_014622AE
Source: C:\Users\user\Desktop\SecuriteInfo.com.Trojan.GenericKDZ.73120.139.exe Code function: 2_2_014632A9 2_2_014632A9
Source: C:\Users\user\Desktop\SecuriteInfo.com.Trojan.GenericKDZ.73120.139.exe Code function: 2_2_01461D55 2_2_01461D55
Source: C:\Users\user\Desktop\SecuriteInfo.com.Trojan.GenericKDZ.73120.139.exe Code function: 2_2_01390D20 2_2_01390D20
Source: C:\Users\user\Desktop\SecuriteInfo.com.Trojan.GenericKDZ.73120.139.exe Code function: 2_2_01462D07 2_2_01462D07
Source: C:\Users\user\Desktop\SecuriteInfo.com.Trojan.GenericKDZ.73120.139.exe Code function: 2_2_013B2D50 2_2_013B2D50
Source: C:\Users\user\Desktop\SecuriteInfo.com.Trojan.GenericKDZ.73120.139.exe Code function: 2_2_014625DD 2_2_014625DD
Source: C:\Users\user\Desktop\SecuriteInfo.com.Trojan.GenericKDZ.73120.139.exe Code function: 2_2_013C65A0 2_2_013C65A0
Source: C:\Users\user\Desktop\SecuriteInfo.com.Trojan.GenericKDZ.73120.139.exe Code function: 2_2_013C2581 2_2_013C2581
Source: C:\Users\user\Desktop\SecuriteInfo.com.Trojan.GenericKDZ.73120.139.exe Code function: 2_2_01452D82 2_2_01452D82
Source: C:\Users\user\Desktop\SecuriteInfo.com.Trojan.GenericKDZ.73120.139.exe Code function: 2_2_013AD5E0 2_2_013AD5E0
Source: C:\Users\user\Desktop\SecuriteInfo.com.Trojan.GenericKDZ.73120.139.exe Code function: 2_2_0145D466 2_2_0145D466
Source: C:\Users\user\Desktop\SecuriteInfo.com.Trojan.GenericKDZ.73120.139.exe Code function: 2_2_013A841F 2_2_013A841F
Source: C:\Users\user\Desktop\SecuriteInfo.com.Trojan.GenericKDZ.73120.139.exe Code function: 2_2_013BB477 2_2_013BB477
Source: C:\Users\user\Desktop\SecuriteInfo.com.Trojan.GenericKDZ.73120.139.exe Code function: 2_2_01454496 2_2_01454496
Source: C:\Users\user\Desktop\SecuriteInfo.com.Trojan.GenericKDZ.73120.139.exe Code function: 2_2_0146DFCE 2_2_0146DFCE
Source: C:\Users\user\Desktop\SecuriteInfo.com.Trojan.GenericKDZ.73120.139.exe Code function: 2_2_014567E2 2_2_014567E2
Source: C:\Users\user\Desktop\SecuriteInfo.com.Trojan.GenericKDZ.73120.139.exe Code function: 2_2_01461FF1 2_2_01461FF1
Source: C:\Users\user\Desktop\SecuriteInfo.com.Trojan.GenericKDZ.73120.139.exe Code function: 2_2_013B6E30 2_2_013B6E30
Source: C:\Users\user\Desktop\SecuriteInfo.com.Trojan.GenericKDZ.73120.139.exe Code function: 2_2_013B5600 2_2_013B5600
Source: C:\Users\user\Desktop\SecuriteInfo.com.Trojan.GenericKDZ.73120.139.exe Code function: 2_2_0145D616 2_2_0145D616
Source: C:\Users\user\Desktop\SecuriteInfo.com.Trojan.GenericKDZ.73120.139.exe Code function: 2_2_01462EF7 2_2_01462EF7
Source: C:\Users\user\Desktop\SecuriteInfo.com.Trojan.GenericKDZ.73120.139.exe Code function: 2_2_01441EB6 2_2_01441EB6
Found potential string decryption / allocating functions
Source: C:\Users\user\Desktop\SecuriteInfo.com.Trojan.GenericKDZ.73120.139.exe Code function: String function: 013ED08C appears 42 times
Source: C:\Users\user\Desktop\SecuriteInfo.com.Trojan.GenericKDZ.73120.139.exe Code function: String function: 0139B150 appears 154 times
Source: C:\Users\user\Desktop\SecuriteInfo.com.Trojan.GenericKDZ.73120.139.exe Code function: String function: 01425720 appears 51 times
Sample file is different than original file name gathered from version info
Source: SecuriteInfo.com.Trojan.GenericKDZ.73120.139.exe, 00000000.00000002.224526375.00000000026E1000.00000004.00000001.sdmp Binary or memory string: OriginalFilenameAsyncState.dllF vs SecuriteInfo.com.Trojan.GenericKDZ.73120.139.exe
Source: SecuriteInfo.com.Trojan.GenericKDZ.73120.139.exe, 00000000.00000002.226319020.00000000057E0000.00000004.00000001.sdmp Binary or memory string: OriginalFilenameLegacyPathHandling.dllN vs SecuriteInfo.com.Trojan.GenericKDZ.73120.139.exe
Source: SecuriteInfo.com.Trojan.GenericKDZ.73120.139.exe, 00000000.00000000.217210974.000000000032E000.00000002.00020000.sdmp Binary or memory string: OriginalFilenameCLRSurrogateEntry.exe8 vs SecuriteInfo.com.Trojan.GenericKDZ.73120.139.exe
Source: SecuriteInfo.com.Trojan.GenericKDZ.73120.139.exe, 00000002.00000002.224992684.000000000161F000.00000040.00000001.sdmp Binary or memory string: OriginalFilenamentdll.dllj% vs SecuriteInfo.com.Trojan.GenericKDZ.73120.139.exe
Source: SecuriteInfo.com.Trojan.GenericKDZ.73120.139.exe, 00000002.00000002.224222430.000000000086E000.00000002.00020000.sdmp Binary or memory string: OriginalFilenameCLRSurrogateEntry.exe8 vs SecuriteInfo.com.Trojan.GenericKDZ.73120.139.exe
Source: SecuriteInfo.com.Trojan.GenericKDZ.73120.139.exe Binary or memory string: OriginalFilenameCLRSurrogateEntry.exe8 vs SecuriteInfo.com.Trojan.GenericKDZ.73120.139.exe
Uses 32bit PE files
Source: SecuriteInfo.com.Trojan.GenericKDZ.73120.139.exe Static PE information: 32BIT_MACHINE, EXECUTABLE_IMAGE
Yara signature match
Source: 00000002.00000002.224039712.0000000000400000.00000040.00000001.sdmp, type: MEMORY Matched rule: Formbook_1 date = 2018-11-23, author = Felix Bilstein - yara-signator at cocacoding dot com, malpedia_version = 20180607, description = autogenerated rule brought to you by yara-signator, malpedia_reference = https://malpedia.caad.fkie.fraunhofer.de/details/win.formbook, cape_type = Formbook Payload, malpedia_license = CC BY-NC-SA 4.0, version = 1, tool = yara-signator 0.1a, malpedia_sharing = TLP:WHITE
Source: 00000002.00000002.224039712.0000000000400000.00000040.00000001.sdmp, type: MEMORY Matched rule: Formbook author = JPCERT/CC Incident Response Group, description = detect Formbook in memory, rule_usage = memory scan, reference = internal research
Source: 00000000.00000002.224800988.00000000036E9000.00000004.00000001.sdmp, type: MEMORY Matched rule: Formbook_1 date = 2018-11-23, author = Felix Bilstein - yara-signator at cocacoding dot com, malpedia_version = 20180607, description = autogenerated rule brought to you by yara-signator, malpedia_reference = https://malpedia.caad.fkie.fraunhofer.de/details/win.formbook, cape_type = Formbook Payload, malpedia_license = CC BY-NC-SA 4.0, version = 1, tool = yara-signator 0.1a, malpedia_sharing = TLP:WHITE
Source: 00000000.00000002.224800988.00000000036E9000.00000004.00000001.sdmp, type: MEMORY Matched rule: Formbook author = JPCERT/CC Incident Response Group, description = detect Formbook in memory, rule_usage = memory scan, reference = internal research
Source: 2.2.SecuriteInfo.com.Trojan.GenericKDZ.73120.139.exe.400000.0.raw.unpack, type: UNPACKEDPE Matched rule: Formbook_1 date = 2018-11-23, author = Felix Bilstein - yara-signator at cocacoding dot com, malpedia_version = 20180607, description = autogenerated rule brought to you by yara-signator, malpedia_reference = https://malpedia.caad.fkie.fraunhofer.de/details/win.formbook, cape_type = Formbook Payload, malpedia_license = CC BY-NC-SA 4.0, version = 1, tool = yara-signator 0.1a, malpedia_sharing = TLP:WHITE
Source: 2.2.SecuriteInfo.com.Trojan.GenericKDZ.73120.139.exe.400000.0.raw.unpack, type: UNPACKEDPE Matched rule: Formbook author = JPCERT/CC Incident Response Group, description = detect Formbook in memory, rule_usage = memory scan, reference = internal research
Source: 2.2.SecuriteInfo.com.Trojan.GenericKDZ.73120.139.exe.400000.0.unpack, type: UNPACKEDPE Matched rule: Formbook_1 date = 2018-11-23, author = Felix Bilstein - yara-signator at cocacoding dot com, malpedia_version = 20180607, description = autogenerated rule brought to you by yara-signator, malpedia_reference = https://malpedia.caad.fkie.fraunhofer.de/details/win.formbook, cape_type = Formbook Payload, malpedia_license = CC BY-NC-SA 4.0, version = 1, tool = yara-signator 0.1a, malpedia_sharing = TLP:WHITE
Source: 2.2.SecuriteInfo.com.Trojan.GenericKDZ.73120.139.exe.400000.0.unpack, type: UNPACKEDPE Matched rule: Formbook author = JPCERT/CC Incident Response Group, description = detect Formbook in memory, rule_usage = memory scan, reference = internal research
Source: 0.2.SecuriteInfo.com.Trojan.GenericKDZ.73120.139.exe.386d620.2.raw.unpack, type: UNPACKEDPE Matched rule: Formbook_1 date = 2018-11-23, author = Felix Bilstein - yara-signator at cocacoding dot com, malpedia_version = 20180607, description = autogenerated rule brought to you by yara-signator, malpedia_reference = https://malpedia.caad.fkie.fraunhofer.de/details/win.formbook, cape_type = Formbook Payload, malpedia_license = CC BY-NC-SA 4.0, version = 1, tool = yara-signator 0.1a, malpedia_sharing = TLP:WHITE
Source: 0.2.SecuriteInfo.com.Trojan.GenericKDZ.73120.139.exe.386d620.2.raw.unpack, type: UNPACKEDPE Matched rule: Formbook author = JPCERT/CC Incident Response Group, description = detect Formbook in memory, rule_usage = memory scan, reference = internal research
Source: 0.2.SecuriteInfo.com.Trojan.GenericKDZ.73120.139.exe.381da00.3.raw.unpack, type: UNPACKEDPE Matched rule: Formbook_1 date = 2018-11-23, author = Felix Bilstein - yara-signator at cocacoding dot com, malpedia_version = 20180607, description = autogenerated rule brought to you by yara-signator, malpedia_reference = https://malpedia.caad.fkie.fraunhofer.de/details/win.formbook, cape_type = Formbook Payload, malpedia_license = CC BY-NC-SA 4.0, version = 1, tool = yara-signator 0.1a, malpedia_sharing = TLP:WHITE
Source: 0.2.SecuriteInfo.com.Trojan.GenericKDZ.73120.139.exe.381da00.3.raw.unpack, type: UNPACKEDPE Matched rule: Formbook author = JPCERT/CC Incident Response Group, description = detect Formbook in memory, rule_usage = memory scan, reference = internal research
Source: SecuriteInfo.com.Trojan.GenericKDZ.73120.139.exe, FrmStart.cs Base64 encoded string: 'GIdDNNZNNNNRNNNN//8NNYtNNNNNNNNNDNNNNNNNNNNNNNNNNNNNNNNNNNNNNNNNNNNNNNNNNNNNNNNNtNNNNN4sht4NgNaAVotOGZ0uITucplOjpz9apzSgVTAuoz5iqPOvMFOlqJ4tnJ4tER9GVT1iMTHhQD0XWNNNNNNNNNODEDNNGNRQNViu868NNNNNNNNNNBNNNvRYNINNNPNNNNNTNNNNNNNNlw8NNNNtNNNNDNNNNNNNRDNtNNNNNtNNONNNNNNNNNNRNNNNNNNNNNPNNNNNNtNNNNNNNNZNDVHNNONNNONNNNNNRNNNRNNNNNNNNONNNNNNNNNNNNNNNUt/NNOCNNNNNRNNNBDQNNNNNNNNNNNNNNNNNNNNNNNNNTNNNNjNNNOpCjNNUNNNNNNNNNNNNNNNNNNNNNNNNNNNNNNNNNNNNNNNNNNNNNNNNNNNNNNNNNNNVNNNPNNNNNNNNNNNNNNNPPNNNRtNNNNNNNNNNNNNNP50MKu0NNNN0O8NNNNtNNNNVNNNNNVNNNNNNNNNNNNNNNNNNPNNNTNhpaAlLjNNNBDQNNNNDNNNNNDNNNNvNNNNNNNNNNNNNNNNNNONNNONYaWyoT9wNNNZNNNNNTNNNNNPNNNNWtNNNNNNNNNNNNNNNNNNDNNNDtNNNNNNNNNNNNNNNNNNNNPfCjNNNNNNNRtNNNNPNNHNhPHNNBjLNNNQNNNNNNNNNXD+NNP4NNNNNNNNNNNNNNNNNNNNNNNNNNNNNNNNNNNNNNNNNNNNNNNNNNNNNNNNNO4PXOLNNNbdWtNPXOpNNNbNXdMmTNNNPbNONNNRpkxNNNdNNtNNOUZnNNNXtNZNNNEmTjNNPbNRNNNRXuZjNDNDNNNNNDNNRDO+NDNNOT8pNNNXPvfNOvbGZNRNRNNNNNVNNORNstVNNNEiUDNNPtbeNNLdRmNONONNNNNQNNNENU4QNNNRok4NNNbXXjNTXuZjNDNDNNNNONNNRDO+ONNNOT8sNNNXPvfNOvbGZNVNCNNNNNHNNORNstHNNNDHXPNNNNbYOljuptRNNUQDODNNNvtuNNNXolVNNNcmVjNNPtjVtNHNNNDNNU4SNNNRPvfNOvbGZNRNPjNNNNLNNORNstLNNNDXXjNTXvVNNbNTNNNRXyMmQNNNOvtxNNNXqNLNNNXNOjNNOPbrNvtyNNNXXtNNRmNONNfNNNNUNNNENU4UNNNRPvfNOvbNRmNONNfNNNNUNNNENPtANNNTPvfNOvc+pwfNNUPNPNNNOUV7NNOjtNxNNNElBjNNpVNXNNNRXxbNNvtzNNNXNNZROFtENNNTNPbNNOZjONO0NNNNPNNNRDOmWjNNPtbTVYvPNDNtXWbONT8bNNNXXPxNNNbNNvtINNNTOPtHNNNTPjpbRjNNOtZbSDNNOvtFNNNTQNtbXtNNPt0WolfNNNbqzuZRRDEiYNNNPuhnRjHEOKV9NNOjTOvAStNNNFtgNNNXWuLbYtNNPtNdRmNSNWpNNNNWNNNENPtiNNNXN28jNNNXPjVPwzxK2cRspTRZNb5cS9LK2usJwF8NNNRANb5cS9bGOORRRjHJRjLeBtxEOtVEOcRVLDpEO5SugWjEOjAiZDNNPusn/tRGPORVRjxEPFjTSuZUNPfVNORUS9LGOjNEOusJRjLEOuRSZpNWNb5cTAbK1usnS9nAYjNNNFtlNNNXqNHNNOfXXjNTXtNGZNHNctNNNNbNNORNStfPomZNNNbGOkVUXQDNNNbZPNwLTgtAPEsnS9nAYjNNNEZRPOsnRjtJRjxeDjtK2uZXSuZYXl0PRDxEP281NNNXRjjFQPt2NNNXXQpNNNbJRDDUTvt4NNNXNNpn1tfEPksJRjfEPkRXZp0EPEsJRjxEPERVZopEOOLbBDNNPuZSRDHK2usJwF8NNNRGOuRRTuRTSuRTwzxbBNNNPtNEOtbeNNLdNNNGZNVNXNNNNNfNNORNN3WYNNOjXQbNNNbbBjNNPaZwNNNXPjpPomjNNNc0VtNNNDbeNNLdRmNRNRbNNNNZNNNENNWiZDNNPuuopm0NNNbYNz8kNNNXTAbZSt0eUjpPPEuiCtNNPu8DXQ8NNNbbDNNNPz9ONNNXWtxL1t0WPQUqO29PNNNXPvfNOvbNNOZjNDNUNNNNQDNNRDNHPvfNOvcTNNVJztVKztVLzvtENNNTNPbNNNNGZNZNVNNNNN4NNORNsttNNNE+PDNNOU4XNNNRXORNNNLNpwfNNUNXXjNTXuZjNtNFNNNNQjNNRDNPNluQNNNXXRDNNNbXXjNTXtNNRmNONNjNNNNDNNNENNVbEDNNPtbeNNLdRmNONONNNNNENNNENANWNNNPXPRNNNbXXjNTXuZjNDNZNNNNQtNNRDNPXRLNNNbXXjNTXuZjNtNqNNNNRtNNRDNPwNLNNOfH/tRYOljVXNRNNPfXXjHNNtbeNNLdWtNQ/uHTNNNoXvLNNvtzNNNXNPbNNNNGZNVNADNNNOZNNORNNagVNNNXo0xNNNbYO4jWNNNoSC4OQNtfSPtPNNNePjW7FNNNPtqiFtNNPtNNNNpXXjNTXyVNNvtzNNNXNNWmFjNNPa1VNNNXXv4bTNNNObNZNNNRXu4PXPLNNNbdNNOPH0cPNDNONNNNNNNZNNNNqwVhZP41ZQplAjNNNNNSNTjNNNPbPDNNV34NNODXNNOjPDNNV1A0pzyhM3ZNNNNNuOZNNTDNNNNwIIZN6OZNNONNNNNwE1IWENNNNCtGNNQ0ONNNV0Wfo2VNNNNNNNNNNtNNNIpIbtxWQjNNNCbOZjNJNNNONNNNBDNNNNfNNNNZNNNNVjNNNORNNNOYNNNNCjNNNOZNNNNTNNNNPtNNNNjNNNNWNNNNNDNNNNDNNNNONNNNNjNNNNZNNNNPNNNNNNNZODRNNNNNNNLNdtBJOjLNSjFJOjLNztYZOt8NQttNNNLN2jXzODLNwDBzODLN/tBzODLNltBzODLN4jBzODL
Source: classification engine Classification label: mal100.troj.evad.winEXE@3/1@0/0
Source: C:\Users\user\Desktop\SecuriteInfo.com.Trojan.GenericKDZ.73120.139.exe File created: C:\Users\user\AppData\Local\Microsoft\CLR_v4.0_32\UsageLogs\SecuriteInfo.com.Trojan.GenericKDZ.73120.139.exe.log Jump to behavior
Source: SecuriteInfo.com.Trojan.GenericKDZ.73120.139.exe Static PE information: Section: .text IMAGE_SCN_MEM_EXECUTE, IMAGE_SCN_CNT_CODE, IMAGE_SCN_MEM_READ
Source: C:\Users\user\Desktop\SecuriteInfo.com.Trojan.GenericKDZ.73120.139.exe Section loaded: C:\Windows\assembly\NativeImages_v4.0.30319_32\mscorlib\a152fe02a317a77aeee36903305e8ba6\mscorlib.ni.dll Jump to behavior
Source: C:\Users\user\Desktop\SecuriteInfo.com.Trojan.GenericKDZ.73120.139.exe Key opened: HKEY_CURRENT_USER\Software\Policies\Microsoft\Windows\Safer\CodeIdentifiers Jump to behavior
Source: SecuriteInfo.com.Trojan.GenericKDZ.73120.139.exe, 00000000.00000002.224526375.00000000026E1000.00000004.00000001.sdmp Binary or memory string: INSERT INTO Itens_Aluguel VALUES(@aluguelID, @aviaoID, @validade);
Source: SecuriteInfo.com.Trojan.GenericKDZ.73120.139.exe, 00000000.00000002.224526375.00000000026E1000.00000004.00000001.sdmp Binary or memory string: Insert into Clientes values (@nome, @cpf, @rg, @cidade, @endereco, @uf, @telefone);
Source: SecuriteInfo.com.Trojan.GenericKDZ.73120.139.exe Virustotal: Detection: 36%
Source: SecuriteInfo.com.Trojan.GenericKDZ.73120.139.exe ReversingLabs: Detection: 29%
Source: unknown Process created: C:\Users\user\Desktop\SecuriteInfo.com.Trojan.GenericKDZ.73120.139.exe 'C:\Users\user\Desktop\SecuriteInfo.com.Trojan.GenericKDZ.73120.139.exe'
Source: unknown Process created: C:\Users\user\Desktop\SecuriteInfo.com.Trojan.GenericKDZ.73120.139.exe C:\Users\user\Desktop\SecuriteInfo.com.Trojan.GenericKDZ.73120.139.exe
Source: C:\Users\user\Desktop\SecuriteInfo.com.Trojan.GenericKDZ.73120.139.exe Process created: C:\Users\user\Desktop\SecuriteInfo.com.Trojan.GenericKDZ.73120.139.exe C:\Users\user\Desktop\SecuriteInfo.com.Trojan.GenericKDZ.73120.139.exe Jump to behavior
Source: C:\Users\user\Desktop\SecuriteInfo.com.Trojan.GenericKDZ.73120.139.exe File opened: C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscorrc.dll Jump to behavior
Source: SecuriteInfo.com.Trojan.GenericKDZ.73120.139.exe Static PE information: data directory type: IMAGE_DIRECTORY_ENTRY_COM_DESCRIPTOR
Source: SecuriteInfo.com.Trojan.GenericKDZ.73120.139.exe Static PE information: NO_SEH, TERMINAL_SERVER_AWARE, DYNAMIC_BASE, NX_COMPAT
Source: Binary string: wntdll.pdbUGP source: SecuriteInfo.com.Trojan.GenericKDZ.73120.139.exe, 00000002.00000002.224505859.0000000001370000.00000040.00000001.sdmp
Source: Binary string: wntdll.pdb source: SecuriteInfo.com.Trojan.GenericKDZ.73120.139.exe

Data Obfuscation:

barindex
.NET source code contains potential unpacker
Source: SecuriteInfo.com.Trojan.GenericKDZ.73120.139.exe, BoundHandle.cs .Net Code: .ctor System.Reflection.Assembly System.Reflection.Assembly::Load(System.Byte[])
Uses code obfuscation techniques (call, push, ret)
Source: C:\Users\user\Desktop\SecuriteInfo.com.Trojan.GenericKDZ.73120.139.exe Code function: 2_2_0040C8B1 push ss; iretd 2_2_0040C8B5
Source: C:\Users\user\Desktop\SecuriteInfo.com.Trojan.GenericKDZ.73120.139.exe Code function: 2_2_0041B3F2 push eax; ret 2_2_0041B3F8
Source: C:\Users\user\Desktop\SecuriteInfo.com.Trojan.GenericKDZ.73120.139.exe Code function: 2_2_0041B3FB push eax; ret 2_2_0041B462
Source: C:\Users\user\Desktop\SecuriteInfo.com.Trojan.GenericKDZ.73120.139.exe Code function: 2_2_0041B3A5 push eax; ret 2_2_0041B3F8
Source: C:\Users\user\Desktop\SecuriteInfo.com.Trojan.GenericKDZ.73120.139.exe Code function: 2_2_0041B45C push eax; ret 2_2_0041B462
Source: C:\Users\user\Desktop\SecuriteInfo.com.Trojan.GenericKDZ.73120.139.exe Code function: 2_2_00415CB8 push esi; ret 2_2_00415CB9
Source: C:\Users\user\Desktop\SecuriteInfo.com.Trojan.GenericKDZ.73120.139.exe Code function: 2_2_0041A5F2 push cs; retf 2_2_0041A5F3
Source: C:\Users\user\Desktop\SecuriteInfo.com.Trojan.GenericKDZ.73120.139.exe Code function: 2_2_013ED0D1 push ecx; ret 2_2_013ED0E4
Source: initial sample Static PE information: section name: .text entropy: 6.80894356258
Source: C:\Users\user\Desktop\SecuriteInfo.com.Trojan.GenericKDZ.73120.139.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Users\user\Desktop\SecuriteInfo.com.Trojan.GenericKDZ.73120.139.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Users\user\Desktop\SecuriteInfo.com.Trojan.GenericKDZ.73120.139.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Users\user\Desktop\SecuriteInfo.com.Trojan.GenericKDZ.73120.139.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Users\user\Desktop\SecuriteInfo.com.Trojan.GenericKDZ.73120.139.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Users\user\Desktop\SecuriteInfo.com.Trojan.GenericKDZ.73120.139.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Users\user\Desktop\SecuriteInfo.com.Trojan.GenericKDZ.73120.139.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Users\user\Desktop\SecuriteInfo.com.Trojan.GenericKDZ.73120.139.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Users\user\Desktop\SecuriteInfo.com.Trojan.GenericKDZ.73120.139.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Users\user\Desktop\SecuriteInfo.com.Trojan.GenericKDZ.73120.139.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Users\user\Desktop\SecuriteInfo.com.Trojan.GenericKDZ.73120.139.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Users\user\Desktop\SecuriteInfo.com.Trojan.GenericKDZ.73120.139.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Users\user\Desktop\SecuriteInfo.com.Trojan.GenericKDZ.73120.139.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Users\user\Desktop\SecuriteInfo.com.Trojan.GenericKDZ.73120.139.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Users\user\Desktop\SecuriteInfo.com.Trojan.GenericKDZ.73120.139.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Users\user\Desktop\SecuriteInfo.com.Trojan.GenericKDZ.73120.139.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Users\user\Desktop\SecuriteInfo.com.Trojan.GenericKDZ.73120.139.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Users\user\Desktop\SecuriteInfo.com.Trojan.GenericKDZ.73120.139.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Users\user\Desktop\SecuriteInfo.com.Trojan.GenericKDZ.73120.139.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Users\user\Desktop\SecuriteInfo.com.Trojan.GenericKDZ.73120.139.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Users\user\Desktop\SecuriteInfo.com.Trojan.GenericKDZ.73120.139.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Users\user\Desktop\SecuriteInfo.com.Trojan.GenericKDZ.73120.139.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Users\user\Desktop\SecuriteInfo.com.Trojan.GenericKDZ.73120.139.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Users\user\Desktop\SecuriteInfo.com.Trojan.GenericKDZ.73120.139.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Users\user\Desktop\SecuriteInfo.com.Trojan.GenericKDZ.73120.139.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Users\user\Desktop\SecuriteInfo.com.Trojan.GenericKDZ.73120.139.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Users\user\Desktop\SecuriteInfo.com.Trojan.GenericKDZ.73120.139.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Users\user\Desktop\SecuriteInfo.com.Trojan.GenericKDZ.73120.139.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Users\user\Desktop\SecuriteInfo.com.Trojan.GenericKDZ.73120.139.exe Process information set: NOOPENFILEERRORBOX Jump to behavior

Malware Analysis System Evasion:

barindex
Yara detected AntiVM_3
Source: Yara match File source: 00000000.00000002.224526375.00000000026E1000.00000004.00000001.sdmp, type: MEMORY
Source: Yara match File source: Process Memory Space: SecuriteInfo.com.Trojan.GenericKDZ.73120.139.exe PID: 6528, type: MEMORY
Source: Yara match File source: 0.2.SecuriteInfo.com.Trojan.GenericKDZ.73120.139.exe.274294c.1.raw.unpack, type: UNPACKEDPE
Tries to detect sandboxes and other dynamic analysis tools (process name or module or function)
Source: SecuriteInfo.com.Trojan.GenericKDZ.73120.139.exe, 00000000.00000002.224526375.00000000026E1000.00000004.00000001.sdmp Binary or memory string: SBIEDLL.DLL
Source: SecuriteInfo.com.Trojan.GenericKDZ.73120.139.exe, 00000000.00000002.224526375.00000000026E1000.00000004.00000001.sdmp Binary or memory string: KERNEL32.DLL.WINE_GET_UNIX_FILE_NAME
Tries to detect virtualization through RDTSC time measurements
Source: C:\Users\user\Desktop\SecuriteInfo.com.Trojan.GenericKDZ.73120.139.exe RDTSC instruction interceptor: First address: 00000000004085E4 second address: 00000000004085EA instructions: 0x00000000 rdtsc 0x00000002 xor ecx, ecx 0x00000004 add ecx, eax 0x00000006 rdtsc
Source: C:\Users\user\Desktop\SecuriteInfo.com.Trojan.GenericKDZ.73120.139.exe RDTSC instruction interceptor: First address: 000000000040896E second address: 0000000000408974 instructions: 0x00000000 rdtsc 0x00000002 xor ecx, ecx 0x00000004 add ecx, eax 0x00000006 rdtsc
Contains functionality for execution timing, often used to detect debuggers
Source: C:\Users\user\Desktop\SecuriteInfo.com.Trojan.GenericKDZ.73120.139.exe Code function: 2_2_004088A0 rdtsc 2_2_004088A0
Contains long sleeps (>= 3 min)
Source: C:\Users\user\Desktop\SecuriteInfo.com.Trojan.GenericKDZ.73120.139.exe Thread delayed: delay time: 922337203685477 Jump to behavior
May sleep (evasive loops) to hinder dynamic analysis
Source: C:\Users\user\Desktop\SecuriteInfo.com.Trojan.GenericKDZ.73120.139.exe TID: 6532 Thread sleep time: -101885s >= -30000s Jump to behavior
Source: C:\Users\user\Desktop\SecuriteInfo.com.Trojan.GenericKDZ.73120.139.exe TID: 6564 Thread sleep time: -922337203685477s >= -30000s Jump to behavior
Source: SecuriteInfo.com.Trojan.GenericKDZ.73120.139.exe, 00000000.00000002.224526375.00000000026E1000.00000004.00000001.sdmp Binary or memory string: InstallPathJC:\PROGRAM FILES\VMWARE\VMWARE TOOLS\
Source: SecuriteInfo.com.Trojan.GenericKDZ.73120.139.exe, 00000000.00000002.224526375.00000000026E1000.00000004.00000001.sdmp Binary or memory string: vmware
Source: SecuriteInfo.com.Trojan.GenericKDZ.73120.139.exe, 00000000.00000002.224526375.00000000026E1000.00000004.00000001.sdmp Binary or memory string: VMware SVGA II
Source: SecuriteInfo.com.Trojan.GenericKDZ.73120.139.exe, 00000000.00000002.224526375.00000000026E1000.00000004.00000001.sdmp Binary or memory string: VMWAREDSOFTWARE\VMware, Inc.\VMware Tools
Source: C:\Users\user\Desktop\SecuriteInfo.com.Trojan.GenericKDZ.73120.139.exe Process information queried: ProcessInformation Jump to behavior

Anti Debugging:

barindex
Checks if the current process is being debugged
Source: C:\Users\user\Desktop\SecuriteInfo.com.Trojan.GenericKDZ.73120.139.exe Process queried: DebugPort Jump to behavior
Contains functionality for execution timing, often used to detect debuggers
Source: C:\Users\user\Desktop\SecuriteInfo.com.Trojan.GenericKDZ.73120.139.exe Code function: 2_2_004088A0 rdtsc 2_2_004088A0
Contains functionality to access loader functionality (e.g. LdrGetProcedureAddress)
Source: C:\Users\user\Desktop\SecuriteInfo.com.Trojan.GenericKDZ.73120.139.exe Code function: 2_2_013D9860 NtQuerySystemInformation,LdrInitializeThunk, 2_2_013D9860
Contains functionality to read the PEB
Source: C:\Users\user\Desktop\SecuriteInfo.com.Trojan.GenericKDZ.73120.139.exe Code function: 2_2_01393138 mov ecx, dword ptr fs:[00000030h] 2_2_01393138
Source: C:\Users\user\Desktop\SecuriteInfo.com.Trojan.GenericKDZ.73120.139.exe Code function: 2_2_013C513A mov eax, dword ptr fs:[00000030h] 2_2_013C513A
Source: C:\Users\user\Desktop\SecuriteInfo.com.Trojan.GenericKDZ.73120.139.exe Code function: 2_2_013C513A mov eax, dword ptr fs:[00000030h] 2_2_013C513A
Source: C:\Users\user\Desktop\SecuriteInfo.com.Trojan.GenericKDZ.73120.139.exe Code function: 2_2_01451951 mov eax, dword ptr fs:[00000030h] 2_2_01451951
Source: C:\Users\user\Desktop\SecuriteInfo.com.Trojan.GenericKDZ.73120.139.exe Code function: 2_2_013B4120 mov eax, dword ptr fs:[00000030h] 2_2_013B4120
Source: C:\Users\user\Desktop\SecuriteInfo.com.Trojan.GenericKDZ.73120.139.exe Code function: 2_2_013B4120 mov eax, dword ptr fs:[00000030h] 2_2_013B4120
Source: C:\Users\user\Desktop\SecuriteInfo.com.Trojan.GenericKDZ.73120.139.exe Code function: 2_2_013B4120 mov eax, dword ptr fs:[00000030h] 2_2_013B4120
Source: C:\Users\user\Desktop\SecuriteInfo.com.Trojan.GenericKDZ.73120.139.exe Code function: 2_2_013B4120 mov eax, dword ptr fs:[00000030h] 2_2_013B4120
Source: C:\Users\user\Desktop\SecuriteInfo.com.Trojan.GenericKDZ.73120.139.exe Code function: 2_2_013B4120 mov ecx, dword ptr fs:[00000030h] 2_2_013B4120
Source: C:\Users\user\Desktop\SecuriteInfo.com.Trojan.GenericKDZ.73120.139.exe Code function: 2_2_01468966 mov eax, dword ptr fs:[00000030h] 2_2_01468966
Source: C:\Users\user\Desktop\SecuriteInfo.com.Trojan.GenericKDZ.73120.139.exe Code function: 2_2_0145E962 mov eax, dword ptr fs:[00000030h] 2_2_0145E962
Source: C:\Users\user\Desktop\SecuriteInfo.com.Trojan.GenericKDZ.73120.139.exe Code function: 2_2_01399100 mov eax, dword ptr fs:[00000030h] 2_2_01399100
Source: C:\Users\user\Desktop\SecuriteInfo.com.Trojan.GenericKDZ.73120.139.exe Code function: 2_2_01399100 mov eax, dword ptr fs:[00000030h] 2_2_01399100
Source: C:\Users\user\Desktop\SecuriteInfo.com.Trojan.GenericKDZ.73120.139.exe Code function: 2_2_01399100 mov eax, dword ptr fs:[00000030h] 2_2_01399100
Source: C:\Users\user\Desktop\SecuriteInfo.com.Trojan.GenericKDZ.73120.139.exe Code function: 2_2_013A0100 mov eax, dword ptr fs:[00000030h] 2_2_013A0100
Source: C:\Users\user\Desktop\SecuriteInfo.com.Trojan.GenericKDZ.73120.139.exe Code function: 2_2_013A0100 mov eax, dword ptr fs:[00000030h] 2_2_013A0100
Source: C:\Users\user\Desktop\SecuriteInfo.com.Trojan.GenericKDZ.73120.139.exe Code function: 2_2_013A0100 mov eax, dword ptr fs:[00000030h] 2_2_013A0100
Source: C:\Users\user\Desktop\SecuriteInfo.com.Trojan.GenericKDZ.73120.139.exe Code function: 2_2_0139B171 mov eax, dword ptr fs:[00000030h] 2_2_0139B171
Source: C:\Users\user\Desktop\SecuriteInfo.com.Trojan.GenericKDZ.73120.139.exe Code function: 2_2_0139B171 mov eax, dword ptr fs:[00000030h] 2_2_0139B171
Source: C:\Users\user\Desktop\SecuriteInfo.com.Trojan.GenericKDZ.73120.139.exe Code function: 2_2_0139C962 mov eax, dword ptr fs:[00000030h] 2_2_0139C962
Source: C:\Users\user\Desktop\SecuriteInfo.com.Trojan.GenericKDZ.73120.139.exe Code function: 2_2_0139395E mov eax, dword ptr fs:[00000030h] 2_2_0139395E
Source: C:\Users\user\Desktop\SecuriteInfo.com.Trojan.GenericKDZ.73120.139.exe Code function: 2_2_0139395E mov eax, dword ptr fs:[00000030h] 2_2_0139395E
Source: C:\Users\user\Desktop\SecuriteInfo.com.Trojan.GenericKDZ.73120.139.exe Code function: 2_2_013BB944 mov eax, dword ptr fs:[00000030h] 2_2_013BB944
Source: C:\Users\user\Desktop\SecuriteInfo.com.Trojan.GenericKDZ.73120.139.exe Code function: 2_2_013BB944 mov eax, dword ptr fs:[00000030h] 2_2_013BB944
Source: C:\Users\user\Desktop\SecuriteInfo.com.Trojan.GenericKDZ.73120.139.exe Code function: 2_2_013B99BF mov ecx, dword ptr fs:[00000030h] 2_2_013B99BF
Source: C:\Users\user\Desktop\SecuriteInfo.com.Trojan.GenericKDZ.73120.139.exe Code function: 2_2_013B99BF mov ecx, dword ptr fs:[00000030h] 2_2_013B99BF
Source: C:\Users\user\Desktop\SecuriteInfo.com.Trojan.GenericKDZ.73120.139.exe Code function: 2_2_013B99BF mov eax, dword ptr fs:[00000030h] 2_2_013B99BF
Source: C:\Users\user\Desktop\SecuriteInfo.com.Trojan.GenericKDZ.73120.139.exe Code function: 2_2_013B99BF mov ecx, dword ptr fs:[00000030h] 2_2_013B99BF
Source: C:\Users\user\Desktop\SecuriteInfo.com.Trojan.GenericKDZ.73120.139.exe Code function: 2_2_013B99BF mov ecx, dword ptr fs:[00000030h] 2_2_013B99BF
Source: C:\Users\user\Desktop\SecuriteInfo.com.Trojan.GenericKDZ.73120.139.exe Code function: 2_2_013B99BF mov eax, dword ptr fs:[00000030h] 2_2_013B99BF
Source: C:\Users\user\Desktop\SecuriteInfo.com.Trojan.GenericKDZ.73120.139.exe Code function: 2_2_013B99BF mov ecx, dword ptr fs:[00000030h] 2_2_013B99BF
Source: C:\Users\user\Desktop\SecuriteInfo.com.Trojan.GenericKDZ.73120.139.exe Code function: 2_2_013B99BF mov ecx, dword ptr fs:[00000030h] 2_2_013B99BF
Source: C:\Users\user\Desktop\SecuriteInfo.com.Trojan.GenericKDZ.73120.139.exe Code function: 2_2_013B99BF mov eax, dword ptr fs:[00000030h] 2_2_013B99BF
Source: C:\Users\user\Desktop\SecuriteInfo.com.Trojan.GenericKDZ.73120.139.exe Code function: 2_2_013B99BF mov ecx, dword ptr fs:[00000030h] 2_2_013B99BF
Source: C:\Users\user\Desktop\SecuriteInfo.com.Trojan.GenericKDZ.73120.139.exe Code function: 2_2_013B99BF mov ecx, dword ptr fs:[00000030h] 2_2_013B99BF
Source: C:\Users\user\Desktop\SecuriteInfo.com.Trojan.GenericKDZ.73120.139.exe Code function: 2_2_013B99BF mov eax, dword ptr fs:[00000030h] 2_2_013B99BF
Source: C:\Users\user\Desktop\SecuriteInfo.com.Trojan.GenericKDZ.73120.139.exe Code function: 2_2_013C61A0 mov eax, dword ptr fs:[00000030h] 2_2_013C61A0
Source: C:\Users\user\Desktop\SecuriteInfo.com.Trojan.GenericKDZ.73120.139.exe Code function: 2_2_013C61A0 mov eax, dword ptr fs:[00000030h] 2_2_013C61A0
Source: C:\Users\user\Desktop\SecuriteInfo.com.Trojan.GenericKDZ.73120.139.exe Code function: 2_2_014519D8 mov eax, dword ptr fs:[00000030h] 2_2_014519D8
Source: C:\Users\user\Desktop\SecuriteInfo.com.Trojan.GenericKDZ.73120.139.exe Code function: 2_2_014689E7 mov eax, dword ptr fs:[00000030h] 2_2_014689E7
Source: C:\Users\user\Desktop\SecuriteInfo.com.Trojan.GenericKDZ.73120.139.exe Code function: 2_2_0139519E mov eax, dword ptr fs:[00000030h] 2_2_0139519E
Source: C:\Users\user\Desktop\SecuriteInfo.com.Trojan.GenericKDZ.73120.139.exe Code function: 2_2_0139519E mov ecx, dword ptr fs:[00000030h] 2_2_0139519E
Source: C:\Users\user\Desktop\SecuriteInfo.com.Trojan.GenericKDZ.73120.139.exe Code function: 2_2_014241E8 mov eax, dword ptr fs:[00000030h] 2_2_014241E8
Source: C:\Users\user\Desktop\SecuriteInfo.com.Trojan.GenericKDZ.73120.139.exe Code function: 2_2_013C2990 mov eax, dword ptr fs:[00000030h] 2_2_013C2990
Source: C:\Users\user\Desktop\SecuriteInfo.com.Trojan.GenericKDZ.73120.139.exe Code function: 2_2_013C4190 mov eax, dword ptr fs:[00000030h] 2_2_013C4190
Source: C:\Users\user\Desktop\SecuriteInfo.com.Trojan.GenericKDZ.73120.139.exe Code function: 2_2_013BC182 mov eax, dword ptr fs:[00000030h] 2_2_013BC182
Source: C:\Users\user\Desktop\SecuriteInfo.com.Trojan.GenericKDZ.73120.139.exe Code function: 2_2_013CA185 mov eax, dword ptr fs:[00000030h] 2_2_013CA185
Source: C:\Users\user\Desktop\SecuriteInfo.com.Trojan.GenericKDZ.73120.139.exe Code function: 2_2_0145A189 mov eax, dword ptr fs:[00000030h] 2_2_0145A189
Source: C:\Users\user\Desktop\SecuriteInfo.com.Trojan.GenericKDZ.73120.139.exe Code function: 2_2_0145A189 mov ecx, dword ptr fs:[00000030h] 2_2_0145A189
Source: C:\Users\user\Desktop\SecuriteInfo.com.Trojan.GenericKDZ.73120.139.exe Code function: 2_2_0139B1E1 mov eax, dword ptr fs:[00000030h] 2_2_0139B1E1
Source: C:\Users\user\Desktop\SecuriteInfo.com.Trojan.GenericKDZ.73120.139.exe Code function: 2_2_0139B1E1 mov eax, dword ptr fs:[00000030h] 2_2_0139B1E1
Source: C:\Users\user\Desktop\SecuriteInfo.com.Trojan.GenericKDZ.73120.139.exe Code function: 2_2_0139B1E1 mov eax, dword ptr fs:[00000030h] 2_2_0139B1E1
Source: C:\Users\user\Desktop\SecuriteInfo.com.Trojan.GenericKDZ.73120.139.exe Code function: 2_2_013931E0 mov eax, dword ptr fs:[00000030h] 2_2_013931E0
Source: C:\Users\user\Desktop\SecuriteInfo.com.Trojan.GenericKDZ.73120.139.exe Code function: 2_2_014549A4 mov eax, dword ptr fs:[00000030h] 2_2_014549A4
Source: C:\Users\user\Desktop\SecuriteInfo.com.Trojan.GenericKDZ.73120.139.exe Code function: 2_2_014549A4 mov eax, dword ptr fs:[00000030h] 2_2_014549A4
Source: C:\Users\user\Desktop\SecuriteInfo.com.Trojan.GenericKDZ.73120.139.exe Code function: 2_2_014549A4 mov eax, dword ptr fs:[00000030h] 2_2_014549A4
Source: C:\Users\user\Desktop\SecuriteInfo.com.Trojan.GenericKDZ.73120.139.exe Code function: 2_2_014549A4 mov eax, dword ptr fs:[00000030h] 2_2_014549A4
Source: C:\Users\user\Desktop\SecuriteInfo.com.Trojan.GenericKDZ.73120.139.exe Code function: 2_2_014169A6 mov eax, dword ptr fs:[00000030h] 2_2_014169A6
Source: C:\Users\user\Desktop\SecuriteInfo.com.Trojan.GenericKDZ.73120.139.exe Code function: 2_2_014151BE mov eax, dword ptr fs:[00000030h] 2_2_014151BE
Source: C:\Users\user\Desktop\SecuriteInfo.com.Trojan.GenericKDZ.73120.139.exe Code function: 2_2_014151BE mov eax, dword ptr fs:[00000030h] 2_2_014151BE
Source: C:\Users\user\Desktop\SecuriteInfo.com.Trojan.GenericKDZ.73120.139.exe Code function: 2_2_014151BE mov eax, dword ptr fs:[00000030h] 2_2_014151BE
Source: C:\Users\user\Desktop\SecuriteInfo.com.Trojan.GenericKDZ.73120.139.exe Code function: 2_2_014151BE mov eax, dword ptr fs:[00000030h] 2_2_014151BE
Source: C:\Users\user\Desktop\SecuriteInfo.com.Trojan.GenericKDZ.73120.139.exe Code function: 2_2_01451843 mov eax, dword ptr fs:[00000030h] 2_2_01451843
Source: C:\Users\user\Desktop\SecuriteInfo.com.Trojan.GenericKDZ.73120.139.exe Code function: 2_2_013BA830 mov eax, dword ptr fs:[00000030h] 2_2_013BA830
Source: C:\Users\user\Desktop\SecuriteInfo.com.Trojan.GenericKDZ.73120.139.exe Code function: 2_2_013BA830 mov eax, dword ptr fs:[00000030h] 2_2_013BA830
Source: C:\Users\user\Desktop\SecuriteInfo.com.Trojan.GenericKDZ.73120.139.exe Code function: 2_2_013BA830 mov eax, dword ptr fs:[00000030h] 2_2_013BA830
Source: C:\Users\user\Desktop\SecuriteInfo.com.Trojan.GenericKDZ.73120.139.exe Code function: 2_2_013BA830 mov eax, dword ptr fs:[00000030h] 2_2_013BA830
Source: C:\Users\user\Desktop\SecuriteInfo.com.Trojan.GenericKDZ.73120.139.exe Code function: 2_2_013AB02A mov eax, dword ptr fs:[00000030h] 2_2_013AB02A
Source: C:\Users\user\Desktop\SecuriteInfo.com.Trojan.GenericKDZ.73120.139.exe Code function: 2_2_013AB02A mov eax, dword ptr fs:[00000030h] 2_2_013AB02A
Source: C:\Users\user\Desktop\SecuriteInfo.com.Trojan.GenericKDZ.73120.139.exe Code function: 2_2_013AB02A mov eax, dword ptr fs:[00000030h] 2_2_013AB02A
Source: C:\Users\user\Desktop\SecuriteInfo.com.Trojan.GenericKDZ.73120.139.exe Code function: 2_2_013AB02A mov eax, dword ptr fs:[00000030h] 2_2_013AB02A
Source: C:\Users\user\Desktop\SecuriteInfo.com.Trojan.GenericKDZ.73120.139.exe Code function: 2_2_013C002D mov eax, dword ptr fs:[00000030h] 2_2_013C002D
Source: C:\Users\user\Desktop\SecuriteInfo.com.Trojan.GenericKDZ.73120.139.exe Code function: 2_2_013C002D mov eax, dword ptr fs:[00000030h] 2_2_013C002D
Source: C:\Users\user\Desktop\SecuriteInfo.com.Trojan.GenericKDZ.73120.139.exe Code function: 2_2_013C002D mov eax, dword ptr fs:[00000030h] 2_2_013C002D
Source: C:\Users\user\Desktop\SecuriteInfo.com.Trojan.GenericKDZ.73120.139.exe Code function: 2_2_013C002D mov eax, dword ptr fs:[00000030h] 2_2_013C002D
Source: C:\Users\user\Desktop\SecuriteInfo.com.Trojan.GenericKDZ.73120.139.exe Code function: 2_2_013C002D mov eax, dword ptr fs:[00000030h] 2_2_013C002D
Source: C:\Users\user\Desktop\SecuriteInfo.com.Trojan.GenericKDZ.73120.139.exe Code function: 2_2_013C4020 mov edi, dword ptr fs:[00000030h] 2_2_013C4020
Source: C:\Users\user\Desktop\SecuriteInfo.com.Trojan.GenericKDZ.73120.139.exe Code function: 2_2_01461074 mov eax, dword ptr fs:[00000030h] 2_2_01461074
Source: C:\Users\user\Desktop\SecuriteInfo.com.Trojan.GenericKDZ.73120.139.exe Code function: 2_2_01452073 mov eax, dword ptr fs:[00000030h] 2_2_01452073
Source: C:\Users\user\Desktop\SecuriteInfo.com.Trojan.GenericKDZ.73120.139.exe Code function: 2_2_01396800 mov eax, dword ptr fs:[00000030h] 2_2_01396800
Source: C:\Users\user\Desktop\SecuriteInfo.com.Trojan.GenericKDZ.73120.139.exe Code function: 2_2_01396800 mov eax, dword ptr fs:[00000030h] 2_2_01396800
Source: C:\Users\user\Desktop\SecuriteInfo.com.Trojan.GenericKDZ.73120.139.exe Code function: 2_2_01396800 mov eax, dword ptr fs:[00000030h] 2_2_01396800
Source: C:\Users\user\Desktop\SecuriteInfo.com.Trojan.GenericKDZ.73120.139.exe Code function: 2_2_01464015 mov eax, dword ptr fs:[00000030h] 2_2_01464015
Source: C:\Users\user\Desktop\SecuriteInfo.com.Trojan.GenericKDZ.73120.139.exe Code function: 2_2_01464015 mov eax, dword ptr fs:[00000030h] 2_2_01464015
Source: C:\Users\user\Desktop\SecuriteInfo.com.Trojan.GenericKDZ.73120.139.exe Code function: 2_2_013BF86D mov eax, dword ptr fs:[00000030h] 2_2_013BF86D
Source: C:\Users\user\Desktop\SecuriteInfo.com.Trojan.GenericKDZ.73120.139.exe Code function: 2_2_01417016 mov eax, dword ptr fs:[00000030h] 2_2_01417016
Source: C:\Users\user\Desktop\SecuriteInfo.com.Trojan.GenericKDZ.73120.139.exe Code function: 2_2_01417016 mov eax, dword ptr fs:[00000030h] 2_2_01417016
Source: C:\Users\user\Desktop\SecuriteInfo.com.Trojan.GenericKDZ.73120.139.exe Code function: 2_2_01417016 mov eax, dword ptr fs:[00000030h] 2_2_01417016
Source: C:\Users\user\Desktop\SecuriteInfo.com.Trojan.GenericKDZ.73120.139.exe Code function: 2_2_01395050 mov eax, dword ptr fs:[00000030h] 2_2_01395050
Source: C:\Users\user\Desktop\SecuriteInfo.com.Trojan.GenericKDZ.73120.139.exe Code function: 2_2_01395050 mov eax, dword ptr fs:[00000030h] 2_2_01395050
Source: C:\Users\user\Desktop\SecuriteInfo.com.Trojan.GenericKDZ.73120.139.exe Code function: 2_2_01395050 mov eax, dword ptr fs:[00000030h] 2_2_01395050
Source: C:\Users\user\Desktop\SecuriteInfo.com.Trojan.GenericKDZ.73120.139.exe Code function: 2_2_013B0050 mov eax, dword ptr fs:[00000030h] 2_2_013B0050
Source: C:\Users\user\Desktop\SecuriteInfo.com.Trojan.GenericKDZ.73120.139.exe Code function: 2_2_013B0050 mov eax, dword ptr fs:[00000030h] 2_2_013B0050
Source: C:\Users\user\Desktop\SecuriteInfo.com.Trojan.GenericKDZ.73120.139.exe Code function: 2_2_01397057 mov eax, dword ptr fs:[00000030h] 2_2_01397057
Source: C:\Users\user\Desktop\SecuriteInfo.com.Trojan.GenericKDZ.73120.139.exe Code function: 2_2_013CF0BF mov ecx, dword ptr fs:[00000030h] 2_2_013CF0BF
Source: C:\Users\user\Desktop\SecuriteInfo.com.Trojan.GenericKDZ.73120.139.exe Code function: 2_2_013CF0BF mov eax, dword ptr fs:[00000030h] 2_2_013CF0BF
Source: C:\Users\user\Desktop\SecuriteInfo.com.Trojan.GenericKDZ.73120.139.exe Code function: 2_2_013CF0BF mov eax, dword ptr fs:[00000030h] 2_2_013CF0BF
Source: C:\Users\user\Desktop\SecuriteInfo.com.Trojan.GenericKDZ.73120.139.exe Code function: 2_2_014518CA mov eax, dword ptr fs:[00000030h] 2_2_014518CA
Source: C:\Users\user\Desktop\SecuriteInfo.com.Trojan.GenericKDZ.73120.139.exe Code function: 2_2_013D90AF mov eax, dword ptr fs:[00000030h] 2_2_013D90AF
Source: C:\Users\user\Desktop\SecuriteInfo.com.Trojan.GenericKDZ.73120.139.exe Code function: 2_2_013A28AE mov eax, dword ptr fs:[00000030h] 2_2_013A28AE
Source: C:\Users\user\Desktop\SecuriteInfo.com.Trojan.GenericKDZ.73120.139.exe Code function: 2_2_013A28AE mov eax, dword ptr fs:[00000030h] 2_2_013A28AE
Source: C:\Users\user\Desktop\SecuriteInfo.com.Trojan.GenericKDZ.73120.139.exe Code function: 2_2_013A28AE mov eax, dword ptr fs:[00000030h] 2_2_013A28AE
Source: C:\Users\user\Desktop\SecuriteInfo.com.Trojan.GenericKDZ.73120.139.exe Code function: 2_2_013A28AE mov ecx, dword ptr fs:[00000030h] 2_2_013A28AE
Source: C:\Users\user\Desktop\SecuriteInfo.com.Trojan.GenericKDZ.73120.139.exe Code function: 2_2_013A28AE mov eax, dword ptr fs:[00000030h] 2_2_013A28AE
Source: C:\Users\user\Desktop\SecuriteInfo.com.Trojan.GenericKDZ.73120.139.exe Code function: 2_2_013A28AE mov eax, dword ptr fs:[00000030h] 2_2_013A28AE
Source: C:\Users\user\Desktop\SecuriteInfo.com.Trojan.GenericKDZ.73120.139.exe Code function: 2_2_013C20A0 mov eax, dword ptr fs:[00000030h] 2_2_013C20A0
Source: C:\Users\user\Desktop\SecuriteInfo.com.Trojan.GenericKDZ.73120.139.exe Code function: 2_2_013C20A0 mov eax, dword ptr fs:[00000030h] 2_2_013C20A0
Source: C:\Users\user\Desktop\SecuriteInfo.com.Trojan.GenericKDZ.73120.139.exe Code function: 2_2_013C20A0 mov eax, dword ptr fs:[00000030h] 2_2_013C20A0
Source: C:\Users\user\Desktop\SecuriteInfo.com.Trojan.GenericKDZ.73120.139.exe Code function: 2_2_013C20A0 mov eax, dword ptr fs:[00000030h] 2_2_013C20A0
Source: C:\Users\user\Desktop\SecuriteInfo.com.Trojan.GenericKDZ.73120.139.exe Code function: 2_2_013C20A0 mov eax, dword ptr fs:[00000030h] 2_2_013C20A0
Source: C:\Users\user\Desktop\SecuriteInfo.com.Trojan.GenericKDZ.73120.139.exe Code function: 2_2_013C20A0 mov eax, dword ptr fs:[00000030h] 2_2_013C20A0
Source: C:\Users\user\Desktop\SecuriteInfo.com.Trojan.GenericKDZ.73120.139.exe Code function: 2_2_01399080 mov eax, dword ptr fs:[00000030h] 2_2_01399080
Source: C:\Users\user\Desktop\SecuriteInfo.com.Trojan.GenericKDZ.73120.139.exe Code function: 2_2_01393880 mov eax, dword ptr fs:[00000030h] 2_2_01393880
Source: C:\Users\user\Desktop\SecuriteInfo.com.Trojan.GenericKDZ.73120.139.exe Code function: 2_2_01393880 mov eax, dword ptr fs:[00000030h] 2_2_01393880
Source: C:\Users\user\Desktop\SecuriteInfo.com.Trojan.GenericKDZ.73120.139.exe Code function: 2_2_01413884 mov eax, dword ptr fs:[00000030h] 2_2_01413884
Source: C:\Users\user\Desktop\SecuriteInfo.com.Trojan.GenericKDZ.73120.139.exe Code function: 2_2_01413884 mov eax, dword ptr fs:[00000030h] 2_2_01413884
Source: C:\Users\user\Desktop\SecuriteInfo.com.Trojan.GenericKDZ.73120.139.exe Code function: 2_2_013A28FD mov eax, dword ptr fs:[00000030h] 2_2_013A28FD
Source: C:\Users\user\Desktop\SecuriteInfo.com.Trojan.GenericKDZ.73120.139.exe Code function: 2_2_013A28FD mov eax, dword ptr fs:[00000030h] 2_2_013A28FD
Source: C:\Users\user\Desktop\SecuriteInfo.com.Trojan.GenericKDZ.73120.139.exe Code function: 2_2_013A28FD mov eax, dword ptr fs:[00000030h] 2_2_013A28FD
Source: C:\Users\user\Desktop\SecuriteInfo.com.Trojan.GenericKDZ.73120.139.exe Code function: 2_2_013958EC mov eax, dword ptr fs:[00000030h] 2_2_013958EC
Source: C:\Users\user\Desktop\SecuriteInfo.com.Trojan.GenericKDZ.73120.139.exe Code function: 2_2_013940E1 mov eax, dword ptr fs:[00000030h] 2_2_013940E1
Source: C:\Users\user\Desktop\SecuriteInfo.com.Trojan.GenericKDZ.73120.139.exe Code function: 2_2_013940E1 mov eax, dword ptr fs:[00000030h] 2_2_013940E1
Source: C:\Users\user\Desktop\SecuriteInfo.com.Trojan.GenericKDZ.73120.139.exe Code function: 2_2_013940E1 mov eax, dword ptr fs:[00000030h] 2_2_013940E1
Source: C:\Users\user\Desktop\SecuriteInfo.com.Trojan.GenericKDZ.73120.139.exe Code function: 2_2_013BB8E4 mov eax, dword ptr fs:[00000030h] 2_2_013BB8E4
Source: C:\Users\user\Desktop\SecuriteInfo.com.Trojan.GenericKDZ.73120.139.exe Code function: 2_2_013BB8E4 mov eax, dword ptr fs:[00000030h] 2_2_013BB8E4
Source: C:\Users\user\Desktop\SecuriteInfo.com.Trojan.GenericKDZ.73120.139.exe Code function: 2_2_013970C0 mov eax, dword ptr fs:[00000030h] 2_2_013970C0
Source: C:\Users\user\Desktop\SecuriteInfo.com.Trojan.GenericKDZ.73120.139.exe Code function: 2_2_013970C0 mov eax, dword ptr fs:[00000030h] 2_2_013970C0
Source: C:\Users\user\Desktop\SecuriteInfo.com.Trojan.GenericKDZ.73120.139.exe Code function: 2_2_01468B58 mov eax, dword ptr fs:[00000030h] 2_2_01468B58
Source: C:\Users\user\Desktop\SecuriteInfo.com.Trojan.GenericKDZ.73120.139.exe Code function: 2_2_01426365 mov eax, dword ptr fs:[00000030h] 2_2_01426365
Source: C:\Users\user\Desktop\SecuriteInfo.com.Trojan.GenericKDZ.73120.139.exe Code function: 2_2_01426365 mov eax, dword ptr fs:[00000030h] 2_2_01426365
Source: C:\Users\user\Desktop\SecuriteInfo.com.Trojan.GenericKDZ.73120.139.exe Code function: 2_2_01426365 mov eax, dword ptr fs:[00000030h] 2_2_01426365
Source: C:\Users\user\Desktop\SecuriteInfo.com.Trojan.GenericKDZ.73120.139.exe Code function: 2_2_013BA309 mov eax, dword ptr fs:[00000030h] 2_2_013BA309
Source: C:\Users\user\Desktop\SecuriteInfo.com.Trojan.GenericKDZ.73120.139.exe Code function: 2_2_013BA309 mov eax, dword ptr fs:[00000030h] 2_2_013BA309
Source: C:\Users\user\Desktop\SecuriteInfo.com.Trojan.GenericKDZ.73120.139.exe Code function: 2_2_013BA309 mov eax, dword ptr fs:[00000030h] 2_2_013BA309
Source: C:\Users\user\Desktop\SecuriteInfo.com.Trojan.GenericKDZ.73120.139.exe Code function: 2_2_013BA309 mov eax, dword ptr fs:[00000030h] 2_2_013BA309
Source: C:\Users\user\Desktop\SecuriteInfo.com.Trojan.GenericKDZ.73120.139.exe Code function: 2_2_013BA309 mov eax, dword ptr fs:[00000030h] 2_2_013BA309
Source: C:\Users\user\Desktop\SecuriteInfo.com.Trojan.GenericKDZ.73120.139.exe Code function: 2_2_013BA309 mov eax, dword ptr fs:[00000030h] 2_2_013BA309
Source: C:\Users\user\Desktop\SecuriteInfo.com.Trojan.GenericKDZ.73120.139.exe Code function: 2_2_013BA309 mov eax, dword ptr fs:[00000030h] 2_2_013BA309
Source: C:\Users\user\Desktop\SecuriteInfo.com.Trojan.GenericKDZ.73120.139.exe Code function: 2_2_013BA309 mov eax, dword ptr fs:[00000030h] 2_2_013BA309
Source: C:\Users\user\Desktop\SecuriteInfo.com.Trojan.GenericKDZ.73120.139.exe Code function: 2_2_013BA309 mov eax, dword ptr fs:[00000030h] 2_2_013BA309
Source: C:\Users\user\Desktop\SecuriteInfo.com.Trojan.GenericKDZ.73120.139.exe Code function: 2_2_013BA309 mov eax, dword ptr fs:[00000030h] 2_2_013BA309
Source: C:\Users\user\Desktop\SecuriteInfo.com.Trojan.GenericKDZ.73120.139.exe Code function: 2_2_013BA309 mov eax, dword ptr fs:[00000030h] 2_2_013BA309
Source: C:\Users\user\Desktop\SecuriteInfo.com.Trojan.GenericKDZ.73120.139.exe Code function: 2_2_013BA309 mov eax, dword ptr fs:[00000030h] 2_2_013BA309
Source: C:\Users\user\Desktop\SecuriteInfo.com.Trojan.GenericKDZ.73120.139.exe Code function: 2_2_013BA309 mov eax, dword ptr fs:[00000030h] 2_2_013BA309
Source: C:\Users\user\Desktop\SecuriteInfo.com.Trojan.GenericKDZ.73120.139.exe Code function: 2_2_013BA309 mov eax, dword ptr fs:[00000030h] 2_2_013BA309
Source: C:\Users\user\Desktop\SecuriteInfo.com.Trojan.GenericKDZ.73120.139.exe Code function: 2_2_013BA309 mov eax, dword ptr fs:[00000030h] 2_2_013BA309
Source: C:\Users\user\Desktop\SecuriteInfo.com.Trojan.GenericKDZ.73120.139.exe Code function: 2_2_013BA309 mov eax, dword ptr fs:[00000030h] 2_2_013BA309
Source: C:\Users\user\Desktop\SecuriteInfo.com.Trojan.GenericKDZ.73120.139.exe Code function: 2_2_013BA309 mov eax, dword ptr fs:[00000030h] 2_2_013BA309
Source: C:\Users\user\Desktop\SecuriteInfo.com.Trojan.GenericKDZ.73120.139.exe Code function: 2_2_013BA309 mov eax, dword ptr fs:[00000030h] 2_2_013BA309
Source: C:\Users\user\Desktop\SecuriteInfo.com.Trojan.GenericKDZ.73120.139.exe Code function: 2_2_013BA309 mov eax, dword ptr fs:[00000030h] 2_2_013BA309
Source: C:\Users\user\Desktop\SecuriteInfo.com.Trojan.GenericKDZ.73120.139.exe Code function: 2_2_013BA309 mov eax, dword ptr fs:[00000030h] 2_2_013BA309
Source: C:\Users\user\Desktop\SecuriteInfo.com.Trojan.GenericKDZ.73120.139.exe Code function: 2_2_013BA309 mov eax, dword ptr fs:[00000030h] 2_2_013BA309
Source: C:\Users\user\Desktop\SecuriteInfo.com.Trojan.GenericKDZ.73120.139.exe Code function: 2_2_013C3B7A mov eax, dword ptr fs:[00000030h] 2_2_013C3B7A
Source: C:\Users\user\Desktop\SecuriteInfo.com.Trojan.GenericKDZ.73120.139.exe Code function: 2_2_013C3B7A mov eax, dword ptr fs:[00000030h] 2_2_013C3B7A
Source: C:\Users\user\Desktop\SecuriteInfo.com.Trojan.GenericKDZ.73120.139.exe Code function: 2_2_013AF370 mov eax, dword ptr fs:[00000030h] 2_2_013AF370
Source: C:\Users\user\Desktop\SecuriteInfo.com.Trojan.GenericKDZ.73120.139.exe Code function: 2_2_013AF370 mov eax, dword ptr fs:[00000030h] 2_2_013AF370
Source: C:\Users\user\Desktop\SecuriteInfo.com.Trojan.GenericKDZ.73120.139.exe Code function: 2_2_013AF370 mov eax, dword ptr fs:[00000030h] 2_2_013AF370
Source: C:\Users\user\Desktop\SecuriteInfo.com.Trojan.GenericKDZ.73120.139.exe Code function: 2_2_0139DB60 mov ecx, dword ptr fs:[00000030h] 2_2_0139DB60
Source: C:\Users\user\Desktop\SecuriteInfo.com.Trojan.GenericKDZ.73120.139.exe Code function: 2_2_0145131B mov eax, dword ptr fs:[00000030h] 2_2_0145131B
Source: C:\Users\user\Desktop\SecuriteInfo.com.Trojan.GenericKDZ.73120.139.exe Code function: 2_2_0139F358 mov eax, dword ptr fs:[00000030h] 2_2_0139F358
Source: C:\Users\user\Desktop\SecuriteInfo.com.Trojan.GenericKDZ.73120.139.exe Code function: 2_2_013C3B5A mov eax, dword ptr fs:[00000030h] 2_2_013C3B5A
Source: C:\Users\user\Desktop\SecuriteInfo.com.Trojan.GenericKDZ.73120.139.exe Code function: 2_2_013C3B5A mov eax, dword ptr fs:[00000030h] 2_2_013C3B5A
Source: C:\Users\user\Desktop\SecuriteInfo.com.Trojan.GenericKDZ.73120.139.exe Code function: 2_2_013C3B5A mov eax, dword ptr fs:[00000030h] 2_2_013C3B5A
Source: C:\Users\user\Desktop\SecuriteInfo.com.Trojan.GenericKDZ.73120.139.exe Code function: 2_2_013C3B5A mov eax, dword ptr fs:[00000030h] 2_2_013C3B5A
Source: C:\Users\user\Desktop\SecuriteInfo.com.Trojan.GenericKDZ.73120.139.exe Code function: 2_2_0139DB40 mov eax, dword ptr fs:[00000030h] 2_2_0139DB40
Source: C:\Users\user\Desktop\SecuriteInfo.com.Trojan.GenericKDZ.73120.139.exe Code function: 2_2_014153CA mov eax, dword ptr fs:[00000030h] 2_2_014153CA
Source: C:\Users\user\Desktop\SecuriteInfo.com.Trojan.GenericKDZ.73120.139.exe Code function: 2_2_014153CA mov eax, dword ptr fs:[00000030h] 2_2_014153CA
Source: C:\Users\user\Desktop\SecuriteInfo.com.Trojan.GenericKDZ.73120.139.exe Code function: 2_2_013C4BAD mov eax, dword ptr fs:[00000030h] 2_2_013C4BAD
Source: C:\Users\user\Desktop\SecuriteInfo.com.Trojan.GenericKDZ.73120.139.exe Code function: 2_2_013C4BAD mov eax, dword ptr fs:[00000030h] 2_2_013C4BAD
Source: C:\Users\user\Desktop\SecuriteInfo.com.Trojan.GenericKDZ.73120.139.exe Code function: 2_2_013C4BAD mov eax, dword ptr fs:[00000030h] 2_2_013C4BAD
Source: C:\Users\user\Desktop\SecuriteInfo.com.Trojan.GenericKDZ.73120.139.exe Code function: 2_2_013BEB9A mov eax, dword ptr fs:[00000030h] 2_2_013BEB9A
Source: C:\Users\user\Desktop\SecuriteInfo.com.Trojan.GenericKDZ.73120.139.exe Code function: 2_2_013BEB9A mov eax, dword ptr fs:[00000030h] 2_2_013BEB9A
Source: C:\Users\user\Desktop\SecuriteInfo.com.Trojan.GenericKDZ.73120.139.exe Code function: 2_2_014423E3 mov ecx, dword ptr fs:[00000030h] 2_2_014423E3
Source: C:\Users\user\Desktop\SecuriteInfo.com.Trojan.GenericKDZ.73120.139.exe Code function: 2_2_014423E3 mov ecx, dword ptr fs:[00000030h] 2_2_014423E3
Source: C:\Users\user\Desktop\SecuriteInfo.com.Trojan.GenericKDZ.73120.139.exe Code function: 2_2_014423E3 mov eax, dword ptr fs:[00000030h] 2_2_014423E3
Source: C:\Users\user\Desktop\SecuriteInfo.com.Trojan.GenericKDZ.73120.139.exe Code function: 2_2_013C2397 mov eax, dword ptr fs:[00000030h] 2_2_013C2397
Source: C:\Users\user\Desktop\SecuriteInfo.com.Trojan.GenericKDZ.73120.139.exe Code function: 2_2_013CB390 mov eax, dword ptr fs:[00000030h] 2_2_013CB390
Source: C:\Users\user\Desktop\SecuriteInfo.com.Trojan.GenericKDZ.73120.139.exe Code function: 2_2_01394B94 mov edi, dword ptr fs:[00000030h] 2_2_01394B94
Source: C:\Users\user\Desktop\SecuriteInfo.com.Trojan.GenericKDZ.73120.139.exe Code function: 2_2_013A1B8F mov eax, dword ptr fs:[00000030h] 2_2_013A1B8F
Source: C:\Users\user\Desktop\SecuriteInfo.com.Trojan.GenericKDZ.73120.139.exe Code function: 2_2_013A1B8F mov eax, dword ptr fs:[00000030h] 2_2_013A1B8F
Source: C:\Users\user\Desktop\SecuriteInfo.com.Trojan.GenericKDZ.73120.139.exe Code function: 2_2_013C138B mov eax, dword ptr fs:[00000030h] 2_2_013C138B
Source: C:\Users\user\Desktop\SecuriteInfo.com.Trojan.GenericKDZ.73120.139.exe Code function: 2_2_013C138B mov eax, dword ptr fs:[00000030h] 2_2_013C138B
Source: C:\Users\user\Desktop\SecuriteInfo.com.Trojan.GenericKDZ.73120.139.exe Code function: 2_2_013C138B mov eax, dword ptr fs:[00000030h] 2_2_013C138B
Source: C:\Users\user\Desktop\SecuriteInfo.com.Trojan.GenericKDZ.73120.139.exe Code function: 2_2_0144D380 mov ecx, dword ptr fs:[00000030h] 2_2_0144D380
Source: C:\Users\user\Desktop\SecuriteInfo.com.Trojan.GenericKDZ.73120.139.exe Code function: 2_2_0143EB8A mov ecx, dword ptr fs:[00000030h] 2_2_0143EB8A
Source: C:\Users\user\Desktop\SecuriteInfo.com.Trojan.GenericKDZ.73120.139.exe Code function: 2_2_0143EB8A mov eax, dword ptr fs:[00000030h] 2_2_0143EB8A
Source: C:\Users\user\Desktop\SecuriteInfo.com.Trojan.GenericKDZ.73120.139.exe Code function: 2_2_0143EB8A mov eax, dword ptr fs:[00000030h] 2_2_0143EB8A
Source: C:\Users\user\Desktop\SecuriteInfo.com.Trojan.GenericKDZ.73120.139.exe Code function: 2_2_0143EB8A mov eax, dword ptr fs:[00000030h] 2_2_0143EB8A
Source: C:\Users\user\Desktop\SecuriteInfo.com.Trojan.GenericKDZ.73120.139.exe Code function: 2_2_0145138A mov eax, dword ptr fs:[00000030h] 2_2_0145138A
Source: C:\Users\user\Desktop\SecuriteInfo.com.Trojan.GenericKDZ.73120.139.exe Code function: 2_2_01391BE9 mov eax, dword ptr fs:[00000030h] 2_2_01391BE9
Source: C:\Users\user\Desktop\SecuriteInfo.com.Trojan.GenericKDZ.73120.139.exe Code function: 2_2_013BDBE9 mov eax, dword ptr fs:[00000030h] 2_2_013BDBE9
Source: C:\Users\user\Desktop\SecuriteInfo.com.Trojan.GenericKDZ.73120.139.exe Code function: 2_2_013C03E2 mov eax, dword ptr fs:[00000030h] 2_2_013C03E2
Source: C:\Users\user\Desktop\SecuriteInfo.com.Trojan.GenericKDZ.73120.139.exe Code function: 2_2_013C03E2 mov eax, dword ptr fs:[00000030h] 2_2_013C03E2
Source: C:\Users\user\Desktop\SecuriteInfo.com.Trojan.GenericKDZ.73120.139.exe Code function: 2_2_013C03E2 mov eax, dword ptr fs:[00000030h] 2_2_013C03E2
Source: C:\Users\user\Desktop\SecuriteInfo.com.Trojan.GenericKDZ.73120.139.exe Code function: 2_2_013C03E2 mov eax, dword ptr fs:[00000030h] 2_2_013C03E2
Source: C:\Users\user\Desktop\SecuriteInfo.com.Trojan.GenericKDZ.73120.139.exe Code function: 2_2_013C03E2 mov eax, dword ptr fs:[00000030h] 2_2_013C03E2
Source: C:\Users\user\Desktop\SecuriteInfo.com.Trojan.GenericKDZ.73120.139.exe Code function: 2_2_013C03E2 mov eax, dword ptr fs:[00000030h] 2_2_013C03E2
Source: C:\Users\user\Desktop\SecuriteInfo.com.Trojan.GenericKDZ.73120.139.exe Code function: 2_2_01465BA5 mov eax, dword ptr fs:[00000030h] 2_2_01465BA5
Source: C:\Users\user\Desktop\SecuriteInfo.com.Trojan.GenericKDZ.73120.139.exe Code function: 2_2_01451BA8 mov eax, dword ptr fs:[00000030h] 2_2_01451BA8
Source: C:\Users\user\Desktop\SecuriteInfo.com.Trojan.GenericKDZ.73120.139.exe Code function: 2_2_01468BB6 mov eax, dword ptr fs:[00000030h] 2_2_01468BB6
Source: C:\Users\user\Desktop\SecuriteInfo.com.Trojan.GenericKDZ.73120.139.exe Code function: 2_2_01469BBE mov eax, dword ptr fs:[00000030h] 2_2_01469BBE
Source: C:\Users\user\Desktop\SecuriteInfo.com.Trojan.GenericKDZ.73120.139.exe Code function: 2_2_013C53C5 mov eax, dword ptr fs:[00000030h] 2_2_013C53C5
Source: C:\Users\user\Desktop\SecuriteInfo.com.Trojan.GenericKDZ.73120.139.exe Code function: 2_2_01398239 mov eax, dword ptr fs:[00000030h] 2_2_01398239
Source: C:\Users\user\Desktop\SecuriteInfo.com.Trojan.GenericKDZ.73120.139.exe Code function: 2_2_01398239 mov eax, dword ptr fs:[00000030h] 2_2_01398239
Source: C:\Users\user\Desktop\SecuriteInfo.com.Trojan.GenericKDZ.73120.139.exe Code function: 2_2_01398239 mov eax, dword ptr fs:[00000030h] 2_2_01398239
Source: C:\Users\user\Desktop\SecuriteInfo.com.Trojan.GenericKDZ.73120.139.exe Code function: 2_2_013BB236 mov eax, dword ptr fs:[00000030h] 2_2_013BB236
Source: C:\Users\user\Desktop\SecuriteInfo.com.Trojan.GenericKDZ.73120.139.exe Code function: 2_2_013BB236 mov eax, dword ptr fs:[00000030h] 2_2_013BB236
Source: C:\Users\user\Desktop\SecuriteInfo.com.Trojan.GenericKDZ.73120.139.exe Code function: 2_2_013BB236 mov eax, dword ptr fs:[00000030h] 2_2_013BB236
Source: C:\Users\user\Desktop\SecuriteInfo.com.Trojan.GenericKDZ.73120.139.exe Code function: 2_2_013BB236 mov eax, dword ptr fs:[00000030h] 2_2_013BB236
Source: C:\Users\user\Desktop\SecuriteInfo.com.Trojan.GenericKDZ.73120.139.exe Code function: 2_2_013BB236 mov eax, dword ptr fs:[00000030h] 2_2_013BB236
Source: C:\Users\user\Desktop\SecuriteInfo.com.Trojan.GenericKDZ.73120.139.exe Code function: 2_2_013BB236 mov eax, dword ptr fs:[00000030h] 2_2_013BB236
Source: C:\Users\user\Desktop\SecuriteInfo.com.Trojan.GenericKDZ.73120.139.exe Code function: 2_2_0145EA55 mov eax, dword ptr fs:[00000030h] 2_2_0145EA55
Source: C:\Users\user\Desktop\SecuriteInfo.com.Trojan.GenericKDZ.73120.139.exe Code function: 2_2_013D4A2C mov eax, dword ptr fs:[00000030h] 2_2_013D4A2C
Source: C:\Users\user\Desktop\SecuriteInfo.com.Trojan.GenericKDZ.73120.139.exe Code function: 2_2_013D4A2C mov eax, dword ptr fs:[00000030h] 2_2_013D4A2C
Source: C:\Users\user\Desktop\SecuriteInfo.com.Trojan.GenericKDZ.73120.139.exe Code function: 2_2_013BA229 mov eax, dword ptr fs:[00000030h] 2_2_013BA229
Source: C:\Users\user\Desktop\SecuriteInfo.com.Trojan.GenericKDZ.73120.139.exe Code function: 2_2_013BA229 mov eax, dword ptr fs:[00000030h] 2_2_013BA229
Source: C:\Users\user\Desktop\SecuriteInfo.com.Trojan.GenericKDZ.73120.139.exe Code function: 2_2_013BA229 mov eax, dword ptr fs:[00000030h] 2_2_013BA229
Source: C:\Users\user\Desktop\SecuriteInfo.com.Trojan.GenericKDZ.73120.139.exe Code function: 2_2_013BA229 mov eax, dword ptr fs:[00000030h] 2_2_013BA229
Source: C:\Users\user\Desktop\SecuriteInfo.com.Trojan.GenericKDZ.73120.139.exe Code function: 2_2_013BA229 mov eax, dword ptr fs:[00000030h] 2_2_013BA229
Source: C:\Users\user\Desktop\SecuriteInfo.com.Trojan.GenericKDZ.73120.139.exe Code function: 2_2_013BA229 mov eax, dword ptr fs:[00000030h] 2_2_013BA229
Source: C:\Users\user\Desktop\SecuriteInfo.com.Trojan.GenericKDZ.73120.139.exe Code function: 2_2_013BA229 mov eax, dword ptr fs:[00000030h] 2_2_013BA229
Source: C:\Users\user\Desktop\SecuriteInfo.com.Trojan.GenericKDZ.73120.139.exe Code function: 2_2_013BA229 mov eax, dword ptr fs:[00000030h] 2_2_013BA229
Source: C:\Users\user\Desktop\SecuriteInfo.com.Trojan.GenericKDZ.73120.139.exe Code function: 2_2_013BA229 mov eax, dword ptr fs:[00000030h] 2_2_013BA229
Source: C:\Users\user\Desktop\SecuriteInfo.com.Trojan.GenericKDZ.73120.139.exe Code function: 2_2_01424257 mov eax, dword ptr fs:[00000030h] 2_2_01424257
Source: C:\Users\user\Desktop\SecuriteInfo.com.Trojan.GenericKDZ.73120.139.exe Code function: 2_2_01394A20 mov eax, dword ptr fs:[00000030h] 2_2_01394A20
Source: C:\Users\user\Desktop\SecuriteInfo.com.Trojan.GenericKDZ.73120.139.exe Code function: 2_2_01394A20 mov eax, dword ptr fs:[00000030h] 2_2_01394A20
Source: C:\Users\user\Desktop\SecuriteInfo.com.Trojan.GenericKDZ.73120.139.exe Code function: 2_2_01451A5F mov eax, dword ptr fs:[00000030h] 2_2_01451A5F
Source: C:\Users\user\Desktop\SecuriteInfo.com.Trojan.GenericKDZ.73120.139.exe Code function: 2_2_0144B260 mov eax, dword ptr fs:[00000030h] 2_2_0144B260
Source: C:\Users\user\Desktop\SecuriteInfo.com.Trojan.GenericKDZ.73120.139.exe Code function: 2_2_0144B260 mov eax, dword ptr fs:[00000030h] 2_2_0144B260
Source: C:\Users\user\Desktop\SecuriteInfo.com.Trojan.GenericKDZ.73120.139.exe Code function: 2_2_01468A62 mov eax, dword ptr fs:[00000030h] 2_2_01468A62
Source: C:\Users\user\Desktop\SecuriteInfo.com.Trojan.GenericKDZ.73120.139.exe Code function: 2_2_013B3A1C mov eax, dword ptr fs:[00000030h] 2_2_013B3A1C
Source: C:\Users\user\Desktop\SecuriteInfo.com.Trojan.GenericKDZ.73120.139.exe Code function: 2_2_01395210 mov eax, dword ptr fs:[00000030h] 2_2_01395210
Source: C:\Users\user\Desktop\SecuriteInfo.com.Trojan.GenericKDZ.73120.139.exe Code function: 2_2_01395210 mov ecx, dword ptr fs:[00000030h] 2_2_01395210
Source: C:\Users\user\Desktop\SecuriteInfo.com.Trojan.GenericKDZ.73120.139.exe Code function: 2_2_01395210 mov eax, dword ptr fs:[00000030h] 2_2_01395210
Source: C:\Users\user\Desktop\SecuriteInfo.com.Trojan.GenericKDZ.73120.139.exe Code function: 2_2_01395210 mov eax, dword ptr fs:[00000030h] 2_2_01395210
Source: C:\Users\user\Desktop\SecuriteInfo.com.Trojan.GenericKDZ.73120.139.exe Code function: 2_2_0139AA16 mov eax, dword ptr fs:[00000030h] 2_2_0139AA16
Source: C:\Users\user\Desktop\SecuriteInfo.com.Trojan.GenericKDZ.73120.139.exe Code function: 2_2_0139AA16 mov eax, dword ptr fs:[00000030h] 2_2_0139AA16
Source: C:\Users\user\Desktop\SecuriteInfo.com.Trojan.GenericKDZ.73120.139.exe Code function: 2_2_013A8A0A mov eax, dword ptr fs:[00000030h] 2_2_013A8A0A
Source: C:\Users\user\Desktop\SecuriteInfo.com.Trojan.GenericKDZ.73120.139.exe Code function: 2_2_013D927A mov eax, dword ptr fs:[00000030h] 2_2_013D927A
Source: C:\Users\user\Desktop\SecuriteInfo.com.Trojan.GenericKDZ.73120.139.exe Code function: 2_2_0145AA16 mov eax, dword ptr fs:[00000030h] 2_2_0145AA16
Source: C:\Users\user\Desktop\SecuriteInfo.com.Trojan.GenericKDZ.73120.139.exe Code function: 2_2_0145AA16 mov eax, dword ptr fs:[00000030h] 2_2_0145AA16
Source: C:\Users\user\Desktop\SecuriteInfo.com.Trojan.GenericKDZ.73120.139.exe Code function: 2_2_013D5A69 mov eax, dword ptr fs:[00000030h] 2_2_013D5A69
Source: C:\Users\user\Desktop\SecuriteInfo.com.Trojan.GenericKDZ.73120.139.exe Code function: 2_2_013D5A69 mov eax, dword ptr fs:[00000030h] 2_2_013D5A69
Source: C:\Users\user\Desktop\SecuriteInfo.com.Trojan.GenericKDZ.73120.139.exe Code function: 2_2_013D5A69 mov eax, dword ptr fs:[00000030h] 2_2_013D5A69
Source: C:\Users\user\Desktop\SecuriteInfo.com.Trojan.GenericKDZ.73120.139.exe Code function: 2_2_01451229 mov eax, dword ptr fs:[00000030h] 2_2_01451229
Source: C:\Users\user\Desktop\SecuriteInfo.com.Trojan.GenericKDZ.73120.139.exe Code function: 2_2_01399240 mov eax, dword ptr fs:[00000030h] 2_2_01399240
Source: C:\Users\user\Desktop\SecuriteInfo.com.Trojan.GenericKDZ.73120.139.exe Code function: 2_2_01399240 mov eax, dword ptr fs:[00000030h] 2_2_01399240
Source: C:\Users\user\Desktop\SecuriteInfo.com.Trojan.GenericKDZ.73120.139.exe Code function: 2_2_01399240 mov eax, dword ptr fs:[00000030h] 2_2_01399240
Source: C:\Users\user\Desktop\SecuriteInfo.com.Trojan.GenericKDZ.73120.139.exe Code function: 2_2_01399240 mov eax, dword ptr fs:[00000030h] 2_2_01399240
Source: C:\Users\user\Desktop\SecuriteInfo.com.Trojan.GenericKDZ.73120.139.exe Code function: 2_2_013C12BD mov esi, dword ptr fs:[00000030h] 2_2_013C12BD
Source: C:\Users\user\Desktop\SecuriteInfo.com.Trojan.GenericKDZ.73120.139.exe Code function: 2_2_013C12BD mov eax, dword ptr fs:[00000030h] 2_2_013C12BD
Source: C:\Users\user\Desktop\SecuriteInfo.com.Trojan.GenericKDZ.73120.139.exe Code function: 2_2_013C12BD mov eax, dword ptr fs:[00000030h] 2_2_013C12BD
Source: C:\Users\user\Desktop\SecuriteInfo.com.Trojan.GenericKDZ.73120.139.exe Code function: 2_2_013AAAB0 mov eax, dword ptr fs:[00000030h] 2_2_013AAAB0
Source: C:\Users\user\Desktop\SecuriteInfo.com.Trojan.GenericKDZ.73120.139.exe Code function: 2_2_013AAAB0 mov eax, dword ptr fs:[00000030h] 2_2_013AAAB0
Source: C:\Users\user\Desktop\SecuriteInfo.com.Trojan.GenericKDZ.73120.139.exe Code function: 2_2_013CFAB0 mov eax, dword ptr fs:[00000030h] 2_2_013CFAB0
Source: C:\Users\user\Desktop\SecuriteInfo.com.Trojan.GenericKDZ.73120.139.exe Code function: 2_2_01391AA0 mov eax, dword ptr fs:[00000030h] 2_2_01391AA0
Source: C:\Users\user\Desktop\SecuriteInfo.com.Trojan.GenericKDZ.73120.139.exe Code function: 2_2_01468ADD mov eax, dword ptr fs:[00000030h] 2_2_01468ADD
Source: C:\Users\user\Desktop\SecuriteInfo.com.Trojan.GenericKDZ.73120.139.exe Code function: 2_2_013952A5 mov eax, dword ptr fs:[00000030h] 2_2_013952A5
Source: C:\Users\user\Desktop\SecuriteInfo.com.Trojan.GenericKDZ.73120.139.exe Code function: 2_2_013952A5 mov eax, dword ptr fs:[00000030h] 2_2_013952A5
Source: C:\Users\user\Desktop\SecuriteInfo.com.Trojan.GenericKDZ.73120.139.exe Code function: 2_2_013952A5 mov eax, dword ptr fs:[00000030h] 2_2_013952A5
Source: C:\Users\user\Desktop\SecuriteInfo.com.Trojan.GenericKDZ.73120.139.exe Code function: 2_2_013952A5 mov eax, dword ptr fs:[00000030h] 2_2_013952A5
Source: C:\Users\user\Desktop\SecuriteInfo.com.Trojan.GenericKDZ.73120.139.exe Code function: 2_2_013952A5 mov eax, dword ptr fs:[00000030h] 2_2_013952A5
Source: C:\Users\user\Desktop\SecuriteInfo.com.Trojan.GenericKDZ.73120.139.exe Code function: 2_2_013C5AA0 mov eax, dword ptr fs:[00000030h] 2_2_013C5AA0
Source: C:\Users\user\Desktop\SecuriteInfo.com.Trojan.GenericKDZ.73120.139.exe Code function: 2_2_013C5AA0 mov eax, dword ptr fs:[00000030h] 2_2_013C5AA0
Source: C:\Users\user\Desktop\SecuriteInfo.com.Trojan.GenericKDZ.73120.139.exe Code function: 2_2_013CD294 mov eax, dword ptr fs:[00000030h] 2_2_013CD294
Source: C:\Users\user\Desktop\SecuriteInfo.com.Trojan.GenericKDZ.73120.139.exe Code function: 2_2_013CD294 mov eax, dword ptr fs:[00000030h] 2_2_013CD294
Source: C:\Users\user\Desktop\SecuriteInfo.com.Trojan.GenericKDZ.73120.139.exe Code function: 2_2_01454AEF mov eax, dword ptr fs:[00000030h] 2_2_01454AEF
Source: C:\Users\user\Desktop\SecuriteInfo.com.Trojan.GenericKDZ.73120.139.exe Code function: 2_2_01454AEF mov eax, dword ptr fs:[00000030h] 2_2_01454AEF
Source: C:\Users\user\Desktop\SecuriteInfo.com.Trojan.GenericKDZ.73120.139.exe Code function: 2_2_01454AEF mov eax, dword ptr fs:[00000030h] 2_2_01454AEF
Source: C:\Users\user\Desktop\SecuriteInfo.com.Trojan.GenericKDZ.73120.139.exe Code function: 2_2_01454AEF mov eax, dword ptr fs:[00000030h] 2_2_01454AEF
Source: C:\Users\user\Desktop\SecuriteInfo.com.Trojan.GenericKDZ.73120.139.exe Code function: 2_2_01454AEF mov eax, dword ptr fs:[00000030h] 2_2_01454AEF
Source: C:\Users\user\Desktop\SecuriteInfo.com.Trojan.GenericKDZ.73120.139.exe Code function: 2_2_01454AEF mov eax, dword ptr fs:[00000030h] 2_2_01454AEF
Source: C:\Users\user\Desktop\SecuriteInfo.com.Trojan.GenericKDZ.73120.139.exe Code function: 2_2_01454AEF mov eax, dword ptr fs:[00000030h] 2_2_01454AEF
Source: C:\Users\user\Desktop\SecuriteInfo.com.Trojan.GenericKDZ.73120.139.exe Code function: 2_2_01454AEF mov eax, dword ptr fs:[00000030h] 2_2_01454AEF
Source: C:\Users\user\Desktop\SecuriteInfo.com.Trojan.GenericKDZ.73120.139.exe Code function: 2_2_01454AEF mov eax, dword ptr fs:[00000030h] 2_2_01454AEF
Source: C:\Users\user\Desktop\SecuriteInfo.com.Trojan.GenericKDZ.73120.139.exe Code function: 2_2_01454AEF mov eax, dword ptr fs:[00000030h] 2_2_01454AEF
Source: C:\Users\user\Desktop\SecuriteInfo.com.Trojan.GenericKDZ.73120.139.exe Code function: 2_2_01454AEF mov eax, dword ptr fs:[00000030h] 2_2_01454AEF
Source: C:\Users\user\Desktop\SecuriteInfo.com.Trojan.GenericKDZ.73120.139.exe Code function: 2_2_01454AEF mov eax, dword ptr fs:[00000030h] 2_2_01454AEF
Source: C:\Users\user\Desktop\SecuriteInfo.com.Trojan.GenericKDZ.73120.139.exe Code function: 2_2_01454AEF mov eax, dword ptr fs:[00000030h] 2_2_01454AEF
Source: C:\Users\user\Desktop\SecuriteInfo.com.Trojan.GenericKDZ.73120.139.exe Code function: 2_2_01454AEF mov eax, dword ptr fs:[00000030h] 2_2_01454AEF
Source: C:\Users\user\Desktop\SecuriteInfo.com.Trojan.GenericKDZ.73120.139.exe Code function: 2_2_013CDA88 mov eax, dword ptr fs:[00000030h] 2_2_013CDA88
Source: C:\Users\user\Desktop\SecuriteInfo.com.Trojan.GenericKDZ.73120.139.exe Code function: 2_2_013CDA88 mov eax, dword ptr fs:[00000030h] 2_2_013CDA88
Source: C:\Users\user\Desktop\SecuriteInfo.com.Trojan.GenericKDZ.73120.139.exe Code function: 2_2_013C2AE4 mov eax, dword ptr fs:[00000030h] 2_2_013C2AE4
Source: C:\Users\user\Desktop\SecuriteInfo.com.Trojan.GenericKDZ.73120.139.exe Code function: 2_2_0145129A mov eax, dword ptr fs:[00000030h] 2_2_0145129A
Source: C:\Users\user\Desktop\SecuriteInfo.com.Trojan.GenericKDZ.73120.139.exe Code function: 2_2_013912D4 mov eax, dword ptr fs:[00000030h] 2_2_013912D4
Source: C:\Users\user\Desktop\SecuriteInfo.com.Trojan.GenericKDZ.73120.139.exe Code function: 2_2_01393ACA mov eax, dword ptr fs:[00000030h] 2_2_01393ACA
Source: C:\Users\user\Desktop\SecuriteInfo.com.Trojan.GenericKDZ.73120.139.exe Code function: 2_2_013C2ACB mov eax, dword ptr fs:[00000030h] 2_2_013C2ACB
Source: C:\Users\user\Desktop\SecuriteInfo.com.Trojan.GenericKDZ.73120.139.exe Code function: 2_2_01395AC0 mov eax, dword ptr fs:[00000030h] 2_2_01395AC0
Source: C:\Users\user\Desktop\SecuriteInfo.com.Trojan.GenericKDZ.73120.139.exe Code function: 2_2_01395AC0 mov eax, dword ptr fs:[00000030h] 2_2_01395AC0
Source: C:\Users\user\Desktop\SecuriteInfo.com.Trojan.GenericKDZ.73120.139.exe Code function: 2_2_01395AC0 mov eax, dword ptr fs:[00000030h] 2_2_01395AC0
Source: C:\Users\user\Desktop\SecuriteInfo.com.Trojan.GenericKDZ.73120.139.exe Code function: 2_2_01413540 mov eax, dword ptr fs:[00000030h] 2_2_01413540
Source: C:\Users\user\Desktop\SecuriteInfo.com.Trojan.GenericKDZ.73120.139.exe Code function: 2_2_01448D47 mov eax, dword ptr fs:[00000030h] 2_2_01448D47
Source: C:\Users\user\Desktop\SecuriteInfo.com.Trojan.GenericKDZ.73120.139.exe Code function: 2_2_01443D40 mov eax, dword ptr fs:[00000030h] 2_2_01443D40
Source: C:\Users\user\Desktop\SecuriteInfo.com.Trojan.GenericKDZ.73120.139.exe Code function: 2_2_013C4D3B mov eax, dword ptr fs:[00000030h] 2_2_013C4D3B
Source: C:\Users\user\Desktop\SecuriteInfo.com.Trojan.GenericKDZ.73120.139.exe Code function: 2_2_013C4D3B mov eax, dword ptr fs:[00000030h] 2_2_013C4D3B
Source: C:\Users\user\Desktop\SecuriteInfo.com.Trojan.GenericKDZ.73120.139.exe Code function: 2_2_013C4D3B mov eax, dword ptr fs:[00000030h] 2_2_013C4D3B
Source: C:\Users\user\Desktop\SecuriteInfo.com.Trojan.GenericKDZ.73120.139.exe Code function: 2_2_0139AD30 mov eax, dword ptr fs:[00000030h] 2_2_0139AD30
Source: C:\Users\user\Desktop\SecuriteInfo.com.Trojan.GenericKDZ.73120.139.exe Code function: 2_2_013A3D34 mov eax, dword ptr fs:[00000030h] 2_2_013A3D34
Source: C:\Users\user\Desktop\SecuriteInfo.com.Trojan.GenericKDZ.73120.139.exe Code function: 2_2_013A3D34 mov eax, dword ptr fs:[00000030h] 2_2_013A3D34
Source: C:\Users\user\Desktop\SecuriteInfo.com.Trojan.GenericKDZ.73120.139.exe Code function: 2_2_013A3D34 mov eax, dword ptr fs:[00000030h] 2_2_013A3D34
Source: C:\Users\user\Desktop\SecuriteInfo.com.Trojan.GenericKDZ.73120.139.exe Code function: 2_2_013A3D34 mov eax, dword ptr fs:[00000030h] 2_2_013A3D34
Source: C:\Users\user\Desktop\SecuriteInfo.com.Trojan.GenericKDZ.73120.139.exe Code function: 2_2_013A3D34 mov eax, dword ptr fs:[00000030h] 2_2_013A3D34
Source: C:\Users\user\Desktop\SecuriteInfo.com.Trojan.GenericKDZ.73120.139.exe Code function: 2_2_013A3D34 mov eax, dword ptr fs:[00000030h] 2_2_013A3D34
Source: C:\Users\user\Desktop\SecuriteInfo.com.Trojan.GenericKDZ.73120.139.exe Code function: 2_2_013A3D34 mov eax, dword ptr fs:[00000030h] 2_2_013A3D34
Source: C:\Users\user\Desktop\SecuriteInfo.com.Trojan.GenericKDZ.73120.139.exe Code function: 2_2_013A3D34 mov eax, dword ptr fs:[00000030h] 2_2_013A3D34
Source: C:\Users\user\Desktop\SecuriteInfo.com.Trojan.GenericKDZ.73120.139.exe Code function: 2_2_013A3D34 mov eax, dword ptr fs:[00000030h] 2_2_013A3D34
Source: C:\Users\user\Desktop\SecuriteInfo.com.Trojan.GenericKDZ.73120.139.exe Code function: 2_2_013A3D34 mov eax, dword ptr fs:[00000030h] 2_2_013A3D34
Source: C:\Users\user\Desktop\SecuriteInfo.com.Trojan.GenericKDZ.73120.139.exe Code function: 2_2_013A3D34 mov eax, dword ptr fs:[00000030h] 2_2_013A3D34
Source: C:\Users\user\Desktop\SecuriteInfo.com.Trojan.GenericKDZ.73120.139.exe Code function: 2_2_013A3D34 mov eax, dword ptr fs:[00000030h] 2_2_013A3D34
Source: C:\Users\user\Desktop\SecuriteInfo.com.Trojan.GenericKDZ.73120.139.exe Code function: 2_2_013A3D34 mov eax, dword ptr fs:[00000030h] 2_2_013A3D34
Source: C:\Users\user\Desktop\SecuriteInfo.com.Trojan.GenericKDZ.73120.139.exe Code function: 2_2_013CF527 mov eax, dword ptr fs:[00000030h] 2_2_013CF527
Source: C:\Users\user\Desktop\SecuriteInfo.com.Trojan.GenericKDZ.73120.139.exe Code function: 2_2_013CF527 mov eax, dword ptr fs:[00000030h] 2_2_013CF527
Source: C:\Users\user\Desktop\SecuriteInfo.com.Trojan.GenericKDZ.73120.139.exe Code function: 2_2_013CF527 mov eax, dword ptr fs:[00000030h] 2_2_013CF527
Source: C:\Users\user\Desktop\SecuriteInfo.com.Trojan.GenericKDZ.73120.139.exe Code function: 2_2_013BC577 mov eax, dword ptr fs:[00000030h] 2_2_013BC577
Source: C:\Users\user\Desktop\SecuriteInfo.com.Trojan.GenericKDZ.73120.139.exe Code function: 2_2_013BC577 mov eax, dword ptr fs:[00000030h] 2_2_013BC577
Source: C:\Users\user\Desktop\SecuriteInfo.com.Trojan.GenericKDZ.73120.139.exe Code function: 2_2_013B8D76 mov eax, dword ptr fs:[00000030h] 2_2_013B8D76
Source: C:\Users\user\Desktop\SecuriteInfo.com.Trojan.GenericKDZ.73120.139.exe Code function: 2_2_013B8D76 mov eax, dword ptr fs:[00000030h] 2_2_013B8D76
Source: C:\Users\user\Desktop\SecuriteInfo.com.Trojan.GenericKDZ.73120.139.exe Code function: 2_2_013B8D76 mov eax, dword ptr fs:[00000030h] 2_2_013B8D76
Source: C:\Users\user\Desktop\SecuriteInfo.com.Trojan.GenericKDZ.73120.139.exe Code function: 2_2_013B8D76 mov eax, dword ptr fs:[00000030h] 2_2_013B8D76
Source: C:\Users\user\Desktop\SecuriteInfo.com.Trojan.GenericKDZ.73120.139.exe Code function: 2_2_013B8D76 mov eax, dword ptr fs:[00000030h] 2_2_013B8D76
Source: C:\Users\user\Desktop\SecuriteInfo.com.Trojan.GenericKDZ.73120.139.exe Code function: 2_2_01453518 mov eax, dword ptr fs:[00000030h] 2_2_01453518
Source: C:\Users\user\Desktop\SecuriteInfo.com.Trojan.GenericKDZ.73120.139.exe Code function: 2_2_01453518 mov eax, dword ptr fs:[00000030h] 2_2_01453518
Source: C:\Users\user\Desktop\SecuriteInfo.com.Trojan.GenericKDZ.73120.139.exe Code function: 2_2_01453518 mov eax, dword ptr fs:[00000030h] 2_2_01453518
Source: C:\Users\user\Desktop\SecuriteInfo.com.Trojan.GenericKDZ.73120.139.exe Code function: 2_2_013B7D50 mov eax, dword ptr fs:[00000030h] 2_2_013B7D50
Source: C:\Users\user\Desktop\SecuriteInfo.com.Trojan.GenericKDZ.73120.139.exe Code function: 2_2_013D4D51 mov eax, dword ptr fs:[00000030h] 2_2_013D4D51
Source: C:\Users\user\Desktop\SecuriteInfo.com.Trojan.GenericKDZ.73120.139.exe Code function: 2_2_013D4D51 mov eax, dword ptr fs:[00000030h] 2_2_013D4D51
Source: C:\Users\user\Desktop\SecuriteInfo.com.Trojan.GenericKDZ.73120.139.exe Code function: 2_2_01468D34 mov eax, dword ptr fs:[00000030h] 2_2_01468D34
Source: C:\Users\user\Desktop\SecuriteInfo.com.Trojan.GenericKDZ.73120.139.exe Code function: 2_2_0139354C mov eax, dword ptr fs:[00000030h] 2_2_0139354C
Source: C:\Users\user\Desktop\SecuriteInfo.com.Trojan.GenericKDZ.73120.139.exe Code function: 2_2_0139354C mov eax, dword ptr fs:[00000030h] 2_2_0139354C
Source: C:\Users\user\Desktop\SecuriteInfo.com.Trojan.GenericKDZ.73120.139.exe Code function: 2_2_0141A537 mov eax, dword ptr fs:[00000030h] 2_2_0141A537
Source: C:\Users\user\Desktop\SecuriteInfo.com.Trojan.GenericKDZ.73120.139.exe Code function: 2_2_0145E539 mov eax, dword ptr fs:[00000030h] 2_2_0145E539
Source: C:\Users\user\Desktop\SecuriteInfo.com.Trojan.GenericKDZ.73120.139.exe Code function: 2_2_013D3D43 mov eax, dword ptr fs:[00000030h] 2_2_013D3D43
Source: C:\Users\user\Desktop\SecuriteInfo.com.Trojan.GenericKDZ.73120.139.exe Code function: 2_2_01416DC9 mov eax, dword ptr fs:[00000030h] 2_2_01416DC9
Source: C:\Users\user\Desktop\SecuriteInfo.com.Trojan.GenericKDZ.73120.139.exe Code function: 2_2_01416DC9 mov eax, dword ptr fs:[00000030h] 2_2_01416DC9
Source: C:\Users\user\Desktop\SecuriteInfo.com.Trojan.GenericKDZ.73120.139.exe Code function: 2_2_01416DC9 mov eax, dword ptr fs:[00000030h] 2_2_01416DC9
Source: C:\Users\user\Desktop\SecuriteInfo.com.Trojan.GenericKDZ.73120.139.exe Code function: 2_2_01416DC9 mov ecx, dword ptr fs:[00000030h] 2_2_01416DC9
Source: C:\Users\user\Desktop\SecuriteInfo.com.Trojan.GenericKDZ.73120.139.exe Code function: 2_2_01416DC9 mov eax, dword ptr fs:[00000030h] 2_2_01416DC9
Source: C:\Users\user\Desktop\SecuriteInfo.com.Trojan.GenericKDZ.73120.139.exe Code function: 2_2_01416DC9 mov eax, dword ptr fs:[00000030h] 2_2_01416DC9
Source: C:\Users\user\Desktop\SecuriteInfo.com.Trojan.GenericKDZ.73120.139.exe Code function: 2_2_013C1DB5 mov eax, dword ptr fs:[00000030h] 2_2_013C1DB5
Source: C:\Users\user\Desktop\SecuriteInfo.com.Trojan.GenericKDZ.73120.139.exe Code function: 2_2_013C1DB5 mov eax, dword ptr fs:[00000030h] 2_2_013C1DB5
Source: C:\Users\user\Desktop\SecuriteInfo.com.Trojan.GenericKDZ.73120.139.exe Code function: 2_2_013C1DB5 mov eax, dword ptr fs:[00000030h] 2_2_013C1DB5
Source: C:\Users\user\Desktop\SecuriteInfo.com.Trojan.GenericKDZ.73120.139.exe Code function: 2_2_0144FDD3 mov eax, dword ptr fs:[00000030h] 2_2_0144FDD3
Source: C:\Users\user\Desktop\SecuriteInfo.com.Trojan.GenericKDZ.73120.139.exe Code function: 2_2_013C65A0 mov eax, dword ptr fs:[00000030h] 2_2_013C65A0
Source: C:\Users\user\Desktop\SecuriteInfo.com.Trojan.GenericKDZ.73120.139.exe Code function: 2_2_013C65A0 mov eax, dword ptr fs:[00000030h] 2_2_013C65A0
Source: C:\Users\user\Desktop\SecuriteInfo.com.Trojan.GenericKDZ.73120.139.exe Code function: 2_2_013C65A0 mov eax, dword ptr fs:[00000030h] 2_2_013C65A0
Source: C:\Users\user\Desktop\SecuriteInfo.com.Trojan.GenericKDZ.73120.139.exe Code function: 2_2_013C35A1 mov eax, dword ptr fs:[00000030h] 2_2_013C35A1
Source: C:\Users\user\Desktop\SecuriteInfo.com.Trojan.GenericKDZ.73120.139.exe Code function: 2_2_013CFD9B mov eax, dword ptr fs:[00000030h] 2_2_013CFD9B
Source: C:\Users\user\Desktop\SecuriteInfo.com.Trojan.GenericKDZ.73120.139.exe Code function: 2_2_013CFD9B mov eax, dword ptr fs:[00000030h] 2_2_013CFD9B
Source: C:\Users\user\Desktop\SecuriteInfo.com.Trojan.GenericKDZ.73120.139.exe Code function: 2_2_0145FDE2 mov eax, dword ptr fs:[00000030h] 2_2_0145FDE2
Source: C:\Users\user\Desktop\SecuriteInfo.com.Trojan.GenericKDZ.73120.139.exe Code function: 2_2_0145FDE2 mov eax, dword ptr fs:[00000030h] 2_2_0145FDE2
Source: C:\Users\user\Desktop\SecuriteInfo.com.Trojan.GenericKDZ.73120.139.exe Code function: 2_2_0145FDE2 mov eax, dword ptr fs:[00000030h] 2_2_0145FDE2
Source: C:\Users\user\Desktop\SecuriteInfo.com.Trojan.GenericKDZ.73120.139.exe Code function: 2_2_0145FDE2 mov eax, dword ptr fs:[00000030h] 2_2_0145FDE2
Source: C:\Users\user\Desktop\SecuriteInfo.com.Trojan.GenericKDZ.73120.139.exe Code function: 2_2_01393591 mov eax, dword ptr fs:[00000030h] 2_2_01393591
Source: C:\Users\user\Desktop\SecuriteInfo.com.Trojan.GenericKDZ.73120.139.exe Code function: 2_2_01392D8A mov eax, dword ptr fs:[00000030h] 2_2_01392D8A
Source: C:\Users\user\Desktop\SecuriteInfo.com.Trojan.GenericKDZ.73120.139.exe Code function: 2_2_01392D8A mov eax, dword ptr fs:[00000030h] 2_2_01392D8A
Source: C:\Users\user\Desktop\SecuriteInfo.com.Trojan.GenericKDZ.73120.139.exe Code function: 2_2_01392D8A mov eax, dword ptr fs:[00000030h] 2_2_01392D8A
Source: C:\Users\user\Desktop\SecuriteInfo.com.Trojan.GenericKDZ.73120.139.exe Code function: 2_2_01392D8A mov eax, dword ptr fs:[00000030h] 2_2_01392D8A
Source: C:\Users\user\Desktop\SecuriteInfo.com.Trojan.GenericKDZ.73120.139.exe Code function: 2_2_01392D8A mov eax, dword ptr fs:[00000030h] 2_2_01392D8A
Source: C:\Users\user\Desktop\SecuriteInfo.com.Trojan.GenericKDZ.73120.139.exe Code function: 2_2_01448DF1 mov eax, dword ptr fs:[00000030h] 2_2_01448DF1
Source: C:\Users\user\Desktop\SecuriteInfo.com.Trojan.GenericKDZ.73120.139.exe Code function: 2_2_013C2581 mov eax, dword ptr fs:[00000030h] 2_2_013C2581
Source: C:\Users\user\Desktop\SecuriteInfo.com.Trojan.GenericKDZ.73120.139.exe Code function: 2_2_013C2581 mov eax, dword ptr fs:[00000030h] 2_2_013C2581
Source: C:\Users\user\Desktop\SecuriteInfo.com.Trojan.GenericKDZ.73120.139.exe Code function: 2_2_013C2581 mov eax, dword ptr fs:[00000030h] 2_2_013C2581
Source: C:\Users\user\Desktop\SecuriteInfo.com.Trojan.GenericKDZ.73120.139.exe Code function: 2_2_013C2581 mov eax, dword ptr fs:[00000030h] 2_2_013C2581
Source: C:\Users\user\Desktop\SecuriteInfo.com.Trojan.GenericKDZ.73120.139.exe Code function: 2_2_0145B581 mov eax, dword ptr fs:[00000030h] 2_2_0145B581
Source: C:\Users\user\Desktop\SecuriteInfo.com.Trojan.GenericKDZ.73120.139.exe Code function: 2_2_0145B581 mov eax, dword ptr fs:[00000030h] 2_2_0145B581
Source: C:\Users\user\Desktop\SecuriteInfo.com.Trojan.GenericKDZ.73120.139.exe Code function: 2_2_0145B581 mov eax, dword ptr fs:[00000030h] 2_2_0145B581
Source: C:\Users\user\Desktop\SecuriteInfo.com.Trojan.GenericKDZ.73120.139.exe Code function: 2_2_0145B581 mov eax, dword ptr fs:[00000030h] 2_2_0145B581
Source: C:\Users\user\Desktop\SecuriteInfo.com.Trojan.GenericKDZ.73120.139.exe Code function: 2_2_01452D82 mov eax, dword ptr fs:[00000030h] 2_2_01452D82
Source: C:\Users\user\Desktop\SecuriteInfo.com.Trojan.GenericKDZ.73120.139.exe Code function: 2_2_01452D82 mov eax, dword ptr fs:[00000030h] 2_2_01452D82
Source: C:\Users\user\Desktop\SecuriteInfo.com.Trojan.GenericKDZ.73120.139.exe Code function: 2_2_01452D82 mov eax, dword ptr fs:[00000030h] 2_2_01452D82
Source: C:\Users\user\Desktop\SecuriteInfo.com.Trojan.GenericKDZ.73120.139.exe Code function: 2_2_01452D82 mov eax, dword ptr fs:[00000030h] 2_2_01452D82
Source: C:\Users\user\Desktop\SecuriteInfo.com.Trojan.GenericKDZ.73120.139.exe Code function: 2_2_01452D82 mov eax, dword ptr fs:[00000030h] 2_2_01452D82
Source: C:\Users\user\Desktop\SecuriteInfo.com.Trojan.GenericKDZ.73120.139.exe Code function: 2_2_01452D82 mov eax, dword ptr fs:[00000030h] 2_2_01452D82
Source: C:\Users\user\Desktop\SecuriteInfo.com.Trojan.GenericKDZ.73120.139.exe Code function: 2_2_01452D82 mov eax, dword ptr fs:[00000030h] 2_2_01452D82
Source: C:\Users\user\Desktop\SecuriteInfo.com.Trojan.GenericKDZ.73120.139.exe Code function: 2_2_013995F0 mov eax, dword ptr fs:[00000030h] 2_2_013995F0
Source: C:\Users\user\Desktop\SecuriteInfo.com.Trojan.GenericKDZ.73120.139.exe Code function: 2_2_013995F0 mov ecx, dword ptr fs:[00000030h] 2_2_013995F0
Source: C:\Users\user\Desktop\SecuriteInfo.com.Trojan.GenericKDZ.73120.139.exe Code function: 2_2_013C95EC mov eax, dword ptr fs:[00000030h] 2_2_013C95EC
Source: C:\Users\user\Desktop\SecuriteInfo.com.Trojan.GenericKDZ.73120.139.exe Code function: 2_2_013AD5E0 mov eax, dword ptr fs:[00000030h] 2_2_013AD5E0
Source: C:\Users\user\Desktop\SecuriteInfo.com.Trojan.GenericKDZ.73120.139.exe Code function: 2_2_013AD5E0 mov eax, dword ptr fs:[00000030h] 2_2_013AD5E0
Source: C:\Users\user\Desktop\SecuriteInfo.com.Trojan.GenericKDZ.73120.139.exe Code function: 2_2_014605AC mov eax, dword ptr fs:[00000030h] 2_2_014605AC
Source: C:\Users\user\Desktop\SecuriteInfo.com.Trojan.GenericKDZ.73120.139.exe Code function: 2_2_014605AC mov eax, dword ptr fs:[00000030h] 2_2_014605AC
Source: C:\Users\user\Desktop\SecuriteInfo.com.Trojan.GenericKDZ.73120.139.exe Code function: 2_2_013915C1 mov eax, dword ptr fs:[00000030h] 2_2_013915C1
Source: C:\Users\user\Desktop\SecuriteInfo.com.Trojan.GenericKDZ.73120.139.exe Code function: 2_2_01394439 mov eax, dword ptr fs:[00000030h] 2_2_01394439
Source: C:\Users\user\Desktop\SecuriteInfo.com.Trojan.GenericKDZ.73120.139.exe Code function: 2_2_013C3C3E mov eax, dword ptr fs:[00000030h] 2_2_013C3C3E
Source: C:\Users\user\Desktop\SecuriteInfo.com.Trojan.GenericKDZ.73120.139.exe Code function: 2_2_013C3C3E mov eax, dword ptr fs:[00000030h] 2_2_013C3C3E
Source: C:\Users\user\Desktop\SecuriteInfo.com.Trojan.GenericKDZ.73120.139.exe Code function: 2_2_013C3C3E mov eax, dword ptr fs:[00000030h] 2_2_013C3C3E
Source: C:\Users\user\Desktop\SecuriteInfo.com.Trojan.GenericKDZ.73120.139.exe Code function: 2_2_013AB433 mov eax, dword ptr fs:[00000030h] 2_2_013AB433
Source: C:\Users\user\Desktop\SecuriteInfo.com.Trojan.GenericKDZ.73120.139.exe Code function: 2_2_013AB433 mov eax, dword ptr fs:[00000030h] 2_2_013AB433
Source: C:\Users\user\Desktop\SecuriteInfo.com.Trojan.GenericKDZ.73120.139.exe Code function: 2_2_013AB433 mov eax, dword ptr fs:[00000030h] 2_2_013AB433
Source: C:\Users\user\Desktop\SecuriteInfo.com.Trojan.GenericKDZ.73120.139.exe Code function: 2_2_013CBC2C mov eax, dword ptr fs:[00000030h] 2_2_013CBC2C
Source: C:\Users\user\Desktop\SecuriteInfo.com.Trojan.GenericKDZ.73120.139.exe Code function: 2_2_01468450 mov eax, dword ptr fs:[00000030h] 2_2_01468450
Source: C:\Users\user\Desktop\SecuriteInfo.com.Trojan.GenericKDZ.73120.139.exe Code function: 2_2_01468C75 mov eax, dword ptr fs:[00000030h] 2_2_01468C75
Source: C:\Users\user\Desktop\SecuriteInfo.com.Trojan.GenericKDZ.73120.139.exe Code function: 2_2_01451C06 mov eax, dword ptr fs:[00000030h] 2_2_01451C06
Source: C:\Users\user\Desktop\SecuriteInfo.com.Trojan.GenericKDZ.73120.139.exe Code function: 2_2_01451C06 mov eax, dword ptr fs:[00000030h] 2_2_01451C06
Source: C:\Users\user\Desktop\SecuriteInfo.com.Trojan.GenericKDZ.73120.139.exe Code function: 2_2_01451C06 mov eax, dword ptr fs:[00000030h] 2_2_01451C06
Source: C:\Users\user\Desktop\SecuriteInfo.com.Trojan.GenericKDZ.73120.139.exe Code function: 2_2_01451C06 mov eax, dword ptr fs:[00000030h] 2_2_01451C06
Source: C:\Users\user\Desktop\SecuriteInfo.com.Trojan.GenericKDZ.73120.139.exe Code function: 2_2_01451C06 mov eax, dword ptr fs:[00000030h] 2_2_01451C06
Source: C:\Users\user\Desktop\SecuriteInfo.com.Trojan.GenericKDZ.73120.139.exe Code function: 2_2_01451C06 mov eax, dword ptr fs:[00000030h] 2_2_01451C06
Source: C:\Users\user\Desktop\SecuriteInfo.com.Trojan.GenericKDZ.73120.139.exe Code function: 2_2_01451C06 mov eax, dword ptr fs:[00000030h] 2_2_01451C06
Source: C:\Users\user\Desktop\SecuriteInfo.com.Trojan.GenericKDZ.73120.139.exe Code function: 2_2_01451C06 mov eax, dword ptr fs:[00000030h] 2_2_01451C06
Source: C:\Users\user\Desktop\SecuriteInfo.com.Trojan.GenericKDZ.73120.139.exe Code function: 2_2_01451C06 mov eax, dword ptr fs:[00000030h] 2_2_01451C06
Source: C:\Users\user\Desktop\SecuriteInfo.com.Trojan.GenericKDZ.73120.139.exe Code function: 2_2_01451C06 mov eax, dword ptr fs:[00000030h] 2_2_01451C06
Source: C:\Users\user\Desktop\SecuriteInfo.com.Trojan.GenericKDZ.73120.139.exe Code function: 2_2_01451C06 mov eax, dword ptr fs:[00000030h] 2_2_01451C06
Source: C:\Users\user\Desktop\SecuriteInfo.com.Trojan.GenericKDZ.73120.139.exe Code function: 2_2_01451C06 mov eax, dword ptr fs:[00000030h] 2_2_01451C06
Source: C:\Users\user\Desktop\SecuriteInfo.com.Trojan.GenericKDZ.73120.139.exe Code function: 2_2_01451C06 mov eax, dword ptr fs:[00000030h] 2_2_01451C06
Source: C:\Users\user\Desktop\SecuriteInfo.com.Trojan.GenericKDZ.73120.139.exe Code function: 2_2_01451C06 mov eax, dword ptr fs:[00000030h] 2_2_01451C06
Source: C:\Users\user\Desktop\SecuriteInfo.com.Trojan.GenericKDZ.73120.139.exe Code function: 2_2_013CAC7B mov eax, dword ptr fs:[00000030h] 2_2_013CAC7B
Source: C:\Users\user\Desktop\SecuriteInfo.com.Trojan.GenericKDZ.73120.139.exe Code function: 2_2_013CAC7B mov eax, dword ptr fs:[00000030h] 2_2_013CAC7B
Source: C:\Users\user\Desktop\SecuriteInfo.com.Trojan.GenericKDZ.73120.139.exe Code function: 2_2_013CAC7B mov eax, dword ptr fs:[00000030h] 2_2_013CAC7B
Source: C:\Users\user\Desktop\SecuriteInfo.com.Trojan.GenericKDZ.73120.139.exe Code function: 2_2_013CAC7B mov eax, dword ptr fs:[00000030h] 2_2_013CAC7B
Source: C:\Users\user\Desktop\SecuriteInfo.com.Trojan.GenericKDZ.73120.139.exe Code function: 2_2_013CAC7B mov eax, dword ptr fs:[00000030h] 2_2_013CAC7B
Source: C:\Users\user\Desktop\SecuriteInfo.com.Trojan.GenericKDZ.73120.139.exe Code function: 2_2_013CAC7B mov eax, dword ptr fs:[00000030h] 2_2_013CAC7B
Source: C:\Users\user\Desktop\SecuriteInfo.com.Trojan.GenericKDZ.73120.139.exe Code function: 2_2_013CAC7B mov eax, dword ptr fs:[00000030h] 2_2_013CAC7B
Source: C:\Users\user\Desktop\SecuriteInfo.com.Trojan.GenericKDZ.73120.139.exe Code function: 2_2_013CAC7B mov eax, dword ptr fs:[00000030h] 2_2_013CAC7B
Source: C:\Users\user\Desktop\SecuriteInfo.com.Trojan.GenericKDZ.73120.139.exe Code function: 2_2_013CAC7B mov eax, dword ptr fs:[00000030h] 2_2_013CAC7B
Source: C:\Users\user\Desktop\SecuriteInfo.com.Trojan.GenericKDZ.73120.139.exe Code function: 2_2_013CAC7B mov eax, dword ptr fs:[00000030h] 2_2_013CAC7B
Source: C:\Users\user\Desktop\SecuriteInfo.com.Trojan.GenericKDZ.73120.139.exe Code function: 2_2_013CAC7B mov eax, dword ptr fs:[00000030h] 2_2_013CAC7B
Source: C:\Users\user\Desktop\SecuriteInfo.com.Trojan.GenericKDZ.73120.139.exe Code function: 2_2_0146740D mov eax, dword ptr fs:[00000030h] 2_2_0146740D
Source: C:\Users\user\Desktop\SecuriteInfo.com.Trojan.GenericKDZ.73120.139.exe Code function: 2_2_0146740D mov eax, dword ptr fs:[00000030h] 2_2_0146740D
Source: C:\Users\user\Desktop\SecuriteInfo.com.Trojan.GenericKDZ.73120.139.exe Code function: 2_2_0146740D mov eax, dword ptr fs:[00000030h] 2_2_0146740D
Source: C:\Users\user\Desktop\SecuriteInfo.com.Trojan.GenericKDZ.73120.139.exe Code function: 2_2_01416C0A mov eax, dword ptr fs:[00000030h] 2_2_01416C0A
Source: C:\Users\user\Desktop\SecuriteInfo.com.Trojan.GenericKDZ.73120.139.exe Code function: 2_2_01416C0A mov eax, dword ptr fs:[00000030h] 2_2_01416C0A
Source: C:\Users\user\Desktop\SecuriteInfo.com.Trojan.GenericKDZ.73120.139.exe Code function: 2_2_01416C0A mov eax, dword ptr fs:[00000030h] 2_2_01416C0A
Source: C:\Users\user\Desktop\SecuriteInfo.com.Trojan.GenericKDZ.73120.139.exe Code function: 2_2_01416C0A mov eax, dword ptr fs:[00000030h] 2_2_01416C0A
Source: C:\Users\user\Desktop\SecuriteInfo.com.Trojan.GenericKDZ.73120.139.exe Code function: 2_2_013BB477 mov eax, dword ptr fs:[00000030h] 2_2_013BB477
Source: C:\Users\user\Desktop\SecuriteInfo.com.Trojan.GenericKDZ.73120.139.exe Code function: 2_2_013BB477 mov eax, dword ptr fs:[00000030h] 2_2_013BB477
Source: C:\Users\user\Desktop\SecuriteInfo.com.Trojan.GenericKDZ.73120.139.exe Code function: 2_2_013BB477 mov eax, dword ptr fs:[00000030h] 2_2_013BB477
Source: C:\Users\user\Desktop\SecuriteInfo.com.Trojan.GenericKDZ.73120.139.exe Code function: 2_2_013BB477 mov eax, dword ptr fs:[00000030h] 2_2_013BB477
Source: C:\Users\user\Desktop\SecuriteInfo.com.Trojan.GenericKDZ.73120.139.exe Code function: 2_2_013BB477 mov eax, dword ptr fs:[00000030h] 2_2_013BB477
Source: C:\Users\user\Desktop\SecuriteInfo.com.Trojan.GenericKDZ.73120.139.exe Code function: 2_2_013BB477 mov eax, dword ptr fs:[00000030h] 2_2_013BB477
Source: C:\Users\user\Desktop\SecuriteInfo.com.Trojan.GenericKDZ.73120.139.exe Code function: 2_2_013BB477 mov eax, dword ptr fs:[00000030h] 2_2_013BB477
Source: C:\Users\user\Desktop\SecuriteInfo.com.Trojan.GenericKDZ.73120.139.exe Code function: 2_2_013BB477 mov eax, dword ptr fs:[00000030h] 2_2_013BB477
Source: C:\Users\user\Desktop\SecuriteInfo.com.Trojan.GenericKDZ.73120.139.exe Code function: 2_2_013BB477 mov eax, dword ptr fs:[00000030h] 2_2_013BB477
Source: C:\Users\user\Desktop\SecuriteInfo.com.Trojan.GenericKDZ.73120.139.exe Code function: 2_2_013BB477 mov eax, dword ptr fs:[00000030h] 2_2_013BB477
Source: C:\Users\user\Desktop\SecuriteInfo.com.Trojan.GenericKDZ.73120.139.exe Code function: 2_2_013BB477 mov eax, dword ptr fs:[00000030h] 2_2_013BB477
Source: C:\Users\user\Desktop\SecuriteInfo.com.Trojan.GenericKDZ.73120.139.exe Code function: 2_2_013BB477 mov eax, dword ptr fs:[00000030h] 2_2_013BB477
Source: C:\Users\user\Desktop\SecuriteInfo.com.Trojan.GenericKDZ.73120.139.exe Code function: 2_2_013D5C70 mov eax, dword ptr fs:[00000030h] 2_2_013D5C70
Source: C:\Users\user\Desktop\SecuriteInfo.com.Trojan.GenericKDZ.73120.139.exe Code function: 2_2_01468C14 mov eax, dword ptr fs:[00000030h] 2_2_01468C14
Source: C:\Users\user\Desktop\SecuriteInfo.com.Trojan.GenericKDZ.73120.139.exe Code function: 2_2_013B746D mov eax, dword ptr fs:[00000030h] 2_2_013B746D
Source: C:\Users\user\Desktop\SecuriteInfo.com.Trojan.GenericKDZ.73120.139.exe Code function: 2_2_013CA44B mov eax, dword ptr fs:[00000030h] 2_2_013CA44B
Source: C:\Users\user\Desktop\SecuriteInfo.com.Trojan.GenericKDZ.73120.139.exe Code function: 2_2_01394CB0 mov eax, dword ptr fs:[00000030h] 2_2_01394CB0
Source: C:\Users\user\Desktop\SecuriteInfo.com.Trojan.GenericKDZ.73120.139.exe Code function: 2_2_013CD4B0 mov eax, dword ptr fs:[00000030h] 2_2_013CD4B0
Source: C:\Users\user\Desktop\SecuriteInfo.com.Trojan.GenericKDZ.73120.139.exe Code function: 2_2_01468CD6 mov eax, dword ptr fs:[00000030h] 2_2_01468CD6
Source: C:\Users\user\Desktop\SecuriteInfo.com.Trojan.GenericKDZ.73120.139.exe Code function: 2_2_013A849B mov eax, dword ptr fs:[00000030h] 2_2_013A849B
Source: C:\Users\user\Desktop\SecuriteInfo.com.Trojan.GenericKDZ.73120.139.exe Code function: 2_2_0139649B mov eax, dword ptr fs:[00000030h] 2_2_0139649B
Source: C:\Users\user\Desktop\SecuriteInfo.com.Trojan.GenericKDZ.73120.139.exe Code function: 2_2_0139649B mov eax, dword ptr fs:[00000030h] 2_2_0139649B
Source: C:\Users\user\Desktop\SecuriteInfo.com.Trojan.GenericKDZ.73120.139.exe Code function: 2_2_01416CF0 mov eax, dword ptr fs:[00000030h] 2_2_01416CF0
Source: C:\Users\user\Desktop\SecuriteInfo.com.Trojan.GenericKDZ.73120.139.exe Code function: 2_2_01416CF0 mov eax, dword ptr fs:[00000030h] 2_2_01416CF0
Source: C:\Users\user\Desktop\SecuriteInfo.com.Trojan.GenericKDZ.73120.139.exe Code function: 2_2_01416CF0 mov eax, dword ptr fs:[00000030h] 2_2_01416CF0
Source: C:\Users\user\Desktop\SecuriteInfo.com.Trojan.GenericKDZ.73120.139.exe Code function: 2_2_01391480 mov eax, dword ptr fs:[00000030h] 2_2_01391480
Source: C:\Users\user\Desktop\SecuriteInfo.com.Trojan.GenericKDZ.73120.139.exe Code function: 2_2_014514FB mov eax, dword ptr fs:[00000030h] 2_2_014514FB
Source: C:\Users\user\Desktop\SecuriteInfo.com.Trojan.GenericKDZ.73120.139.exe Code function: 2_2_01454496 mov eax, dword ptr fs:[00000030h] 2_2_01454496
Source: C:\Users\user\Desktop\SecuriteInfo.com.Trojan.GenericKDZ.73120.139.exe Code function: 2_2_01454496 mov eax, dword ptr fs:[00000030h] 2_2_01454496
Source: C:\Users\user\Desktop\SecuriteInfo.com.Trojan.GenericKDZ.73120.139.exe Code function: 2_2_01454496 mov eax, dword ptr fs:[00000030h] 2_2_01454496
Source: C:\Users\user\Desktop\SecuriteInfo.com.Trojan.GenericKDZ.73120.139.exe Code function: 2_2_01454496 mov eax, dword ptr fs:[00000030h] 2_2_01454496
Source: C:\Users\user\Desktop\SecuriteInfo.com.Trojan.GenericKDZ.73120.139.exe Code function: 2_2_01454496 mov eax, dword ptr fs:[00000030h] 2_2_01454496
Source: C:\Users\user\Desktop\SecuriteInfo.com.Trojan.GenericKDZ.73120.139.exe Code function: 2_2_01454496 mov eax, dword ptr fs:[00000030h] 2_2_01454496
Source: C:\Users\user\Desktop\SecuriteInfo.com.Trojan.GenericKDZ.73120.139.exe Code function: 2_2_01454496 mov eax, dword ptr fs:[00000030h] 2_2_01454496
Source: C:\Users\user\Desktop\SecuriteInfo.com.Trojan.GenericKDZ.73120.139.exe Code function: 2_2_01454496 mov eax, dword ptr fs:[00000030h] 2_2_01454496
Source: C:\Users\user\Desktop\SecuriteInfo.com.Trojan.GenericKDZ.73120.139.exe Code function: 2_2_01454496 mov eax, dword ptr fs:[00000030h] 2_2_01454496
Source: C:\Users\user\Desktop\SecuriteInfo.com.Trojan.GenericKDZ.73120.139.exe Code function: 2_2_01454496 mov eax, dword ptr fs:[00000030h] 2_2_01454496
Source: C:\Users\user\Desktop\SecuriteInfo.com.Trojan.GenericKDZ.73120.139.exe Code function: 2_2_01454496 mov eax, dword ptr fs:[00000030h] 2_2_01454496
Source: C:\Users\user\Desktop\SecuriteInfo.com.Trojan.GenericKDZ.73120.139.exe Code function: 2_2_01454496 mov eax, dword ptr fs:[00000030h] 2_2_01454496
Source: C:\Users\user\Desktop\SecuriteInfo.com.Trojan.GenericKDZ.73120.139.exe Code function: 2_2_01454496 mov eax, dword ptr fs:[00000030h] 2_2_01454496
Source: C:\Users\user\Desktop\SecuriteInfo.com.Trojan.GenericKDZ.73120.139.exe Code function: 2_2_01392CDB mov eax, dword ptr fs:[00000030h] 2_2_01392CDB
Source: C:\Users\user\Desktop\SecuriteInfo.com.Trojan.GenericKDZ.73120.139.exe Code function: 2_2_01469CB3 mov eax, dword ptr fs:[00000030h] 2_2_01469CB3
Source: C:\Users\user\Desktop\SecuriteInfo.com.Trojan.GenericKDZ.73120.139.exe Code function: 2_2_013BB73D mov eax, dword ptr fs:[00000030h] 2_2_013BB73D
Source: C:\Users\user\Desktop\SecuriteInfo.com.Trojan.GenericKDZ.73120.139.exe Code function: 2_2_013BB73D mov eax, dword ptr fs:[00000030h] 2_2_013BB73D
Source: C:\Users\user\Desktop\SecuriteInfo.com.Trojan.GenericKDZ.73120.139.exe Code function: 2_2_01396730 mov eax, dword ptr fs:[00000030h] 2_2_01396730
Source: C:\Users\user\Desktop\SecuriteInfo.com.Trojan.GenericKDZ.73120.139.exe Code function: 2_2_01396730 mov eax, dword ptr fs:[00000030h] 2_2_01396730
Source: C:\Users\user\Desktop\SecuriteInfo.com.Trojan.GenericKDZ.73120.139.exe Code function: 2_2_01396730 mov eax, dword ptr fs:[00000030h] 2_2_01396730
Source: C:\Users\user\Desktop\SecuriteInfo.com.Trojan.GenericKDZ.73120.139.exe Code function: 2_2_013CE730 mov eax, dword ptr fs:[00000030h] 2_2_013CE730
Source: C:\Users\user\Desktop\SecuriteInfo.com.Trojan.GenericKDZ.73120.139.exe Code function: 2_2_013C3F33 mov eax, dword ptr fs:[00000030h] 2_2_013C3F33
Source: C:\Users\user\Desktop\SecuriteInfo.com.Trojan.GenericKDZ.73120.139.exe Code function: 2_2_01451751 mov eax, dword ptr fs:[00000030h] 2_2_01451751
Source: C:\Users\user\Desktop\SecuriteInfo.com.Trojan.GenericKDZ.73120.139.exe Code function: 2_2_01394F2E mov eax, dword ptr fs:[00000030h] 2_2_01394F2E
Source: C:\Users\user\Desktop\SecuriteInfo.com.Trojan.GenericKDZ.73120.139.exe Code function: 2_2_01394F2E mov eax, dword ptr fs:[00000030h] 2_2_01394F2E
Source: C:\Users\user\Desktop\SecuriteInfo.com.Trojan.GenericKDZ.73120.139.exe Code function: 2_2_01425F5F mov eax, dword ptr fs:[00000030h] 2_2_01425F5F
Source: C:\Users\user\Desktop\SecuriteInfo.com.Trojan.GenericKDZ.73120.139.exe Code function: 2_2_01425F5F mov eax, dword ptr fs:[00000030h] 2_2_01425F5F
Source: C:\Users\user\Desktop\SecuriteInfo.com.Trojan.GenericKDZ.73120.139.exe Code function: 2_2_01425F5F mov eax, dword ptr fs:[00000030h] 2_2_01425F5F
Source: C:\Users\user\Desktop\SecuriteInfo.com.Trojan.GenericKDZ.73120.139.exe Code function: 2_2_01425F5F mov eax, dword ptr fs:[00000030h] 2_2_01425F5F
Source: C:\Users\user\Desktop\SecuriteInfo.com.Trojan.GenericKDZ.73120.139.exe Code function: 2_2_01425F5F mov eax, dword ptr fs:[00000030h] 2_2_01425F5F
Source: C:\Users\user\Desktop\SecuriteInfo.com.Trojan.GenericKDZ.73120.139.exe Code function: 2_2_01468F6A mov eax, dword ptr fs:[00000030h] 2_2_01468F6A
Source: C:\Users\user\Desktop\SecuriteInfo.com.Trojan.GenericKDZ.73120.139.exe Code function: 2_2_013C4710 mov eax, dword ptr fs:[00000030h] 2_2_013C4710
Source: C:\Users\user\Desktop\SecuriteInfo.com.Trojan.GenericKDZ.73120.139.exe Code function: 2_2_013BF716 mov eax, dword ptr fs:[00000030h] 2_2_013BF716
Source: C:\Users\user\Desktop\SecuriteInfo.com.Trojan.GenericKDZ.73120.139.exe Code function: 2_2_013CA70E mov eax, dword ptr fs:[00000030h] 2_2_013CA70E
Source: C:\Users\user\Desktop\SecuriteInfo.com.Trojan.GenericKDZ.73120.139.exe Code function: 2_2_013CA70E mov eax, dword ptr fs:[00000030h] 2_2_013CA70E
Source: C:\Users\user\Desktop\SecuriteInfo.com.Trojan.GenericKDZ.73120.139.exe Code function: 2_2_0146070D mov eax, dword ptr fs:[00000030h] 2_2_0146070D
Source: C:\Users\user\Desktop\SecuriteInfo.com.Trojan.GenericKDZ.73120.139.exe Code function: 2_2_0146070D mov eax, dword ptr fs:[00000030h] 2_2_0146070D
Source: C:\Users\user\Desktop\SecuriteInfo.com.Trojan.GenericKDZ.73120.139.exe Code function: 2_2_0142FF10 mov eax, dword ptr fs:[00000030h] 2_2_0142FF10
Source: C:\Users\user\Desktop\SecuriteInfo.com.Trojan.GenericKDZ.73120.139.exe Code function: 2_2_0142FF10 mov eax, dword ptr fs:[00000030h] 2_2_0142FF10
Source: C:\Users\user\Desktop\SecuriteInfo.com.Trojan.GenericKDZ.73120.139.exe Code function: 2_2_01396F60 mov eax, dword ptr fs:[00000030h] 2_2_01396F60
Source: C:\Users\user\Desktop\SecuriteInfo.com.Trojan.GenericKDZ.73120.139.exe Code function: 2_2_01396F60 mov eax, dword ptr fs:[00000030h] 2_2_01396F60
Source: C:\Users\user\Desktop\SecuriteInfo.com.Trojan.GenericKDZ.73120.139.exe Code function: 2_2_013AFF60 mov eax, dword ptr fs:[00000030h] 2_2_013AFF60
Source: C:\Users\user\Desktop\SecuriteInfo.com.Trojan.GenericKDZ.73120.139.exe Code function: 2_2_013BE760 mov eax, dword ptr fs:[00000030h] 2_2_013BE760
Source: C:\Users\user\Desktop\SecuriteInfo.com.Trojan.GenericKDZ.73120.139.exe Code function: 2_2_013BE760 mov eax, dword ptr fs:[00000030h] 2_2_013BE760
Source: C:\Users\user\Desktop\SecuriteInfo.com.Trojan.GenericKDZ.73120.139.exe Code function: 2_2_013CDF4C mov eax, dword ptr fs:[00000030h] 2_2_013CDF4C
Source: C:\Users\user\Desktop\SecuriteInfo.com.Trojan.GenericKDZ.73120.139.exe Code function: 2_2_013AEF40 mov eax, dword ptr fs:[00000030h] 2_2_013AEF40
Source: C:\Users\user\Desktop\SecuriteInfo.com.Trojan.GenericKDZ.73120.139.exe Code function: 2_2_0139A745 mov eax, dword ptr fs:[00000030h] 2_2_0139A745
Source: C:\Users\user\Desktop\SecuriteInfo.com.Trojan.GenericKDZ.73120.139.exe Code function: 2_2_01392FB0 mov eax, dword ptr fs:[00000030h] 2_2_01392FB0
Source: C:\Users\user\Desktop\SecuriteInfo.com.Trojan.GenericKDZ.73120.139.exe Code function: 2_2_01392FB0 mov eax, dword ptr fs:[00000030h] 2_2_01392FB0
Source: C:\Users\user\Desktop\SecuriteInfo.com.Trojan.GenericKDZ.73120.139.exe Memory allocated: page read and write | page guard Jump to behavior

HIPS / PFW / Operating System Protection Evasion:

barindex
Creates a process in suspended mode (likely to inject code)
Source: C:\Users\user\Desktop\SecuriteInfo.com.Trojan.GenericKDZ.73120.139.exe Process created: C:\Users\user\Desktop\SecuriteInfo.com.Trojan.GenericKDZ.73120.139.exe C:\Users\user\Desktop\SecuriteInfo.com.Trojan.GenericKDZ.73120.139.exe Jump to behavior

Language, Device and Operating System Detection:

barindex
Queries the volume information (name, serial number etc) of a device
Source: C:\Users\user\Desktop\SecuriteInfo.com.Trojan.GenericKDZ.73120.139.exe Queries volume information: C:\Users\user\Desktop\SecuriteInfo.com.Trojan.GenericKDZ.73120.139.exe VolumeInformation Jump to behavior
Source: C:\Users\user\Desktop\SecuriteInfo.com.Trojan.GenericKDZ.73120.139.exe Queries volume information: C:\Windows\Microsoft.NET\assembly\GAC_MSIL\Microsoft.VisualBasic\v4.0_10.0.0.0__b03f5f7f11d50a3a\Microsoft.VisualBasic.dll VolumeInformation Jump to behavior
Source: C:\Users\user\Desktop\SecuriteInfo.com.Trojan.GenericKDZ.73120.139.exe Queries volume information: C:\Windows\Microsoft.NET\assembly\GAC_MSIL\System.Windows.Forms\v4.0_4.0.0.0__b77a5c561934e089\System.Windows.Forms.dll VolumeInformation Jump to behavior
Source: C:\Users\user\Desktop\SecuriteInfo.com.Trojan.GenericKDZ.73120.139.exe Queries volume information: C:\Windows\Microsoft.NET\assembly\GAC_MSIL\System.Drawing\v4.0_4.0.0.0__b03f5f7f11d50a3a\System.Drawing.dll VolumeInformation Jump to behavior
Source: C:\Users\user\Desktop\SecuriteInfo.com.Trojan.GenericKDZ.73120.139.exe Queries volume information: C:\Windows\Microsoft.NET\assembly\GAC_MSIL\Accessibility\v4.0_4.0.0.0__b03f5f7f11d50a3a\Accessibility.dll VolumeInformation Jump to behavior
Source: C:\Users\user\Desktop\SecuriteInfo.com.Trojan.GenericKDZ.73120.139.exe Queries volume information: C:\Windows\Microsoft.NET\assembly\GAC_MSIL\System.Runtime.Remoting\v4.0_4.0.0.0__b77a5c561934e089\System.Runtime.Remoting.dll VolumeInformation Jump to behavior
Source: C:\Users\user\Desktop\SecuriteInfo.com.Trojan.GenericKDZ.73120.139.exe Key value queried: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Cryptography MachineGuid Jump to behavior

Stealing of Sensitive Information:

barindex
Yara detected FormBook
Source: Yara match File source: 00000002.00000002.224039712.0000000000400000.00000040.00000001.sdmp, type: MEMORY
Source: Yara match File source: 00000000.00000002.224800988.00000000036E9000.00000004.00000001.sdmp, type: MEMORY
Source: Yara match File source: 2.2.SecuriteInfo.com.Trojan.GenericKDZ.73120.139.exe.400000.0.raw.unpack, type: UNPACKEDPE
Source: Yara match File source: 2.2.SecuriteInfo.com.Trojan.GenericKDZ.73120.139.exe.400000.0.unpack, type: UNPACKEDPE
Source: Yara match File source: 0.2.SecuriteInfo.com.Trojan.GenericKDZ.73120.139.exe.386d620.2.raw.unpack, type: UNPACKEDPE
Source: Yara match File source: 0.2.SecuriteInfo.com.Trojan.GenericKDZ.73120.139.exe.381da00.3.raw.unpack, type: UNPACKEDPE

Remote Access Functionality:

barindex
Yara detected FormBook
Source: Yara match File source: 00000002.00000002.224039712.0000000000400000.00000040.00000001.sdmp, type: MEMORY
Source: Yara match File source: 00000000.00000002.224800988.00000000036E9000.00000004.00000001.sdmp, type: MEMORY
Source: Yara match File source: 2.2.SecuriteInfo.com.Trojan.GenericKDZ.73120.139.exe.400000.0.raw.unpack, type: UNPACKEDPE
Source: Yara match File source: 2.2.SecuriteInfo.com.Trojan.GenericKDZ.73120.139.exe.400000.0.unpack, type: UNPACKEDPE
Source: Yara match File source: 0.2.SecuriteInfo.com.Trojan.GenericKDZ.73120.139.exe.386d620.2.raw.unpack, type: UNPACKEDPE
Source: Yara match File source: 0.2.SecuriteInfo.com.Trojan.GenericKDZ.73120.139.exe.381da00.3.raw.unpack, type: UNPACKEDPE
Hide Legend

Legend:

  • Process
  • Signature
  • Created File
  • DNS/IP Info
  • Is Dropped
  • Is Windows Process
  • Number of created Registry Values
  • Number of created Files
  • Visual Basic
  • Delphi
  • Java
  • .Net C# or VB.NET
  • C, C++ or other language
  • Is malicious
  • Internet
behaviorgraph top1 signatures2 2 Behavior Graph ID: 356587 Sample: SecuriteInfo.com.Trojan.Gen... Startdate: 23/02/2021 Architecture: WINDOWS Score: 100 14 Found malware configuration 2->14 16 Malicious sample detected (through community Yara rule) 2->16 18 Multi AV Scanner detection for submitted file 2->18 20 7 other signatures 2->20 6 SecuriteInfo.com.Trojan.GenericKDZ.73120.139.exe 3 2->6         started        process3 file4 12 SecuriteInfo.com.T...Z.73120.139.exe.log, ASCII 6->12 dropped 22 Tries to detect virtualization through RDTSC time measurements 6->22 10 SecuriteInfo.com.Trojan.GenericKDZ.73120.139.exe 6->10         started        signatures5 process6
No contacted IP infos

Contacted URLs

Name Malicious Antivirus Detection Reputation
www.rizrvd.com/bw82/ true
  • Avira URL Cloud: safe
low