Loading ...

Play interactive tourEdit tour

Analysis Report SecuriteInfo.com.Trojan.GenericKDZ.73120.139.15119

Overview

General Information

Sample Name:SecuriteInfo.com.Trojan.GenericKDZ.73120.139.15119 (renamed file extension from 15119 to exe)
Analysis ID:356587
MD5:fac509b5175d3647945bdbf7ac010acc
SHA1:048a87d3a938217f555da58662da7bfe59971a9e
SHA256:44283ee3be33ad2077f6c8c18b1699f3d694cb936336523b299646f1a39ea8fc

Most interesting Screenshot:

Detection

FormBook
Score:100
Range:0 - 100
Whitelisted:false
Confidence:100%

Signatures

Found malware configuration
Malicious sample detected (through community Yara rule)
Multi AV Scanner detection for submitted file
Yara detected AntiVM_3
Yara detected FormBook
.NET source code contains potential unpacker
.NET source code contains very large strings
C2 URLs / IPs found in malware configuration
Machine Learning detection for sample
Tries to detect sandboxes and other dynamic analysis tools (process name or module or function)
Tries to detect virtualization through RDTSC time measurements
Antivirus or Machine Learning detection for unpacked file
Checks if the current process is being debugged
Contains functionality for execution timing, often used to detect debuggers
Contains functionality to access loader functionality (e.g. LdrGetProcedureAddress)
Contains functionality to call native functions
Contains functionality to read the PEB
Contains long sleeps (>= 3 min)
Creates a process in suspended mode (likely to inject code)
Detected potential crypto function
Found inlined nop instructions (likely shell or obfuscated code)
Found potential string decryption / allocating functions
May sleep (evasive loops) to hinder dynamic analysis
Queries the volume information (name, serial number etc) of a device
Sample file is different than original file name gathered from version info
Uses 32bit PE files
Uses code obfuscation techniques (call, push, ret)
Yara signature match

Classification

Startup

  • System is w10x64
  • cleanup

Malware Configuration

Threatname: FormBook

{"C2 list": ["www.rizrvd.com/bw82/"], "decoy": ["fundamentaliemef.com", "gallerybrows.com", "leadeligey.com", "octoberx2.online", "climaxnovels.com", "gdsjgf.com", "curateherstories.com", "blacksailus.com", "yjpps.com", "gmobilet.com", "fcoins.club", "foreverlive2027.com", "healthyfifties.com", "wmarquezy.com", "housebulb.com", "thebabyfriendly.com", "primajayaintiperkasa.com", "learnplaychess.com", "chrisbubser.digital", "xn--avenr-wsa.com", "exlineinsurance.com", "thrivezi.com", "tuvandadayvitos24h.online", "illfingers.com", "usmedicarenow.com", "pandabutik.com", "engageautism.info", "magnabeautystyle.com", "texasdryroof.com", "woodlandpizzahartford.com", "dameadamea.com", "sedaskincare.com", "ruaysatu99.com", "mybestaide.com", "nikolaichan.com", "mrcabinetkitchenandbath.com", "ondemandbarbering.com", "activagebenefits.net", "srcsvcs.com", "cbrealvitalize.com", "ismaelworks.com", "medkomp.online", "ninasangtani.com", "h2oturkiye.com", "kolamart.com", "acdfr.com", "twistedtailgatesweeps1.com", "ramjamdee.com", "thedancehalo.com", "joeisono.com", "glasshouseroadtrip.com", "okcpp.com", "riggsfarmfenceservices.com", "mgg360.com", "xn--oi2b190cymc.com", "ctfocbdwholesale.com", "openspiers.com", "rumblingrambles.com", "thepoetrictedstudio.com", "magiclabs.media", "wellnesssensation.com", "lakegastonautoparts.com", "dealsonwheeeles.com", "semenboostplus.com"]}

Yara Overview

Memory Dumps

SourceRuleDescriptionAuthorStrings
00000002.00000002.224039712.0000000000400000.00000040.00000001.sdmpJoeSecurity_FormBookYara detected FormBookJoe Security
    00000002.00000002.224039712.0000000000400000.00000040.00000001.sdmpFormbook_1autogenerated rule brought to you by yara-signatorFelix Bilstein - yara-signator at cocacoding dot com
    • 0x85e8:$sequence_0: 03 C8 0F 31 2B C1 89 45 FC
    • 0x8972:$sequence_0: 03 C8 0F 31 2B C1 89 45 FC
    • 0x14685:$sequence_1: 3C 24 0F 84 76 FF FF FF 3C 25 74 94
    • 0x14171:$sequence_2: 3B 4F 14 73 95 85 C9 74 91
    • 0x14787:$sequence_3: 3C 69 75 44 8B 7D 18 8B 0F
    • 0x148ff:$sequence_4: 5D C3 8D 50 7C 80 FA 07
    • 0x938a:$sequence_5: 0F BE 5C 0E 01 0F B6 54 0E 02 83 E3 0F C1 EA 06
    • 0x133ec:$sequence_6: 57 89 45 FC 89 45 F4 89 45 F8
    • 0xa102:$sequence_7: 66 89 0C 02 5B 8B E5 5D
    • 0x19777:$sequence_8: 3C 54 74 04 3C 74 75 F4
    • 0x1a81a:$sequence_9: 56 68 03 01 00 00 8D 85 95 FE FF FF 6A 00
    00000002.00000002.224039712.0000000000400000.00000040.00000001.sdmpFormbookdetect Formbook in memoryJPCERT/CC Incident Response Group
    • 0x166a9:$sqlite3step: 68 34 1C 7B E1
    • 0x167bc:$sqlite3step: 68 34 1C 7B E1
    • 0x166d8:$sqlite3text: 68 38 2A 90 C5
    • 0x167fd:$sqlite3text: 68 38 2A 90 C5
    • 0x166eb:$sqlite3blob: 68 53 D8 7F 8C
    • 0x16813:$sqlite3blob: 68 53 D8 7F 8C
    00000000.00000002.224800988.00000000036E9000.00000004.00000001.sdmpJoeSecurity_FormBookYara detected FormBookJoe Security
      00000000.00000002.224800988.00000000036E9000.00000004.00000001.sdmpFormbook_1autogenerated rule brought to you by yara-signatorFelix Bilstein - yara-signator at cocacoding dot com
      • 0x254eb8:$sequence_0: 03 C8 0F 31 2B C1 89 45 FC
      • 0x255242:$sequence_0: 03 C8 0F 31 2B C1 89 45 FC
      • 0x27c0d8:$sequence_0: 03 C8 0F 31 2B C1 89 45 FC
      • 0x27c462:$sequence_0: 03 C8 0F 31 2B C1 89 45 FC
      • 0x260f55:$sequence_1: 3C 24 0F 84 76 FF FF FF 3C 25 74 94
      • 0x288175:$sequence_1: 3C 24 0F 84 76 FF FF FF 3C 25 74 94
      • 0x260a41:$sequence_2: 3B 4F 14 73 95 85 C9 74 91
      • 0x287c61:$sequence_2: 3B 4F 14 73 95 85 C9 74 91
      • 0x261057:$sequence_3: 3C 69 75 44 8B 7D 18 8B 0F
      • 0x288277:$sequence_3: 3C 69 75 44 8B 7D 18 8B 0F
      • 0x2611cf:$sequence_4: 5D C3 8D 50 7C 80 FA 07
      • 0x2883ef:$sequence_4: 5D C3 8D 50 7C 80 FA 07
      • 0x255c5a:$sequence_5: 0F BE 5C 0E 01 0F B6 54 0E 02 83 E3 0F C1 EA 06
      • 0x27ce7a:$sequence_5: 0F BE 5C 0E 01 0F B6 54 0E 02 83 E3 0F C1 EA 06
      • 0x25fcbc:$sequence_6: 57 89 45 FC 89 45 F4 89 45 F8
      • 0x286edc:$sequence_6: 57 89 45 FC 89 45 F4 89 45 F8
      • 0x2569d2:$sequence_7: 66 89 0C 02 5B 8B E5 5D
      • 0x27dbf2:$sequence_7: 66 89 0C 02 5B 8B E5 5D
      • 0x266047:$sequence_8: 3C 54 74 04 3C 74 75 F4
      • 0x28d267:$sequence_8: 3C 54 74 04 3C 74 75 F4
      • 0x2670ea:$sequence_9: 56 68 03 01 00 00 8D 85 95 FE FF FF 6A 00
      Click to see the 3 entries

      Unpacked PEs

      SourceRuleDescriptionAuthorStrings
      2.2.SecuriteInfo.com.Trojan.GenericKDZ.73120.139.exe.400000.0.raw.unpackJoeSecurity_FormBookYara detected FormBookJoe Security
        2.2.SecuriteInfo.com.Trojan.GenericKDZ.73120.139.exe.400000.0.raw.unpackFormbook_1autogenerated rule brought to you by yara-signatorFelix Bilstein - yara-signator at cocacoding dot com
        • 0x85e8:$sequence_0: 03 C8 0F 31 2B C1 89 45 FC
        • 0x8972:$sequence_0: 03 C8 0F 31 2B C1 89 45 FC
        • 0x14685:$sequence_1: 3C 24 0F 84 76 FF FF FF 3C 25 74 94
        • 0x14171:$sequence_2: 3B 4F 14 73 95 85 C9 74 91
        • 0x14787:$sequence_3: 3C 69 75 44 8B 7D 18 8B 0F
        • 0x148ff:$sequence_4: 5D C3 8D 50 7C 80 FA 07
        • 0x938a:$sequence_5: 0F BE 5C 0E 01 0F B6 54 0E 02 83 E3 0F C1 EA 06
        • 0x133ec:$sequence_6: 57 89 45 FC 89 45 F4 89 45 F8
        • 0xa102:$sequence_7: 66 89 0C 02 5B 8B E5 5D
        • 0x19777:$sequence_8: 3C 54 74 04 3C 74 75 F4
        • 0x1a81a:$sequence_9: 56 68 03 01 00 00 8D 85 95 FE FF FF 6A 00
        2.2.SecuriteInfo.com.Trojan.GenericKDZ.73120.139.exe.400000.0.raw.unpackFormbookdetect Formbook in memoryJPCERT/CC Incident Response Group
        • 0x166a9:$sqlite3step: 68 34 1C 7B E1
        • 0x167bc:$sqlite3step: 68 34 1C 7B E1
        • 0x166d8:$sqlite3text: 68 38 2A 90 C5
        • 0x167fd:$sqlite3text: 68 38 2A 90 C5
        • 0x166eb:$sqlite3blob: 68 53 D8 7F 8C
        • 0x16813:$sqlite3blob: 68 53 D8 7F 8C
        2.2.SecuriteInfo.com.Trojan.GenericKDZ.73120.139.exe.400000.0.unpackJoeSecurity_FormBookYara detected FormBookJoe Security
          2.2.SecuriteInfo.com.Trojan.GenericKDZ.73120.139.exe.400000.0.unpackFormbook_1autogenerated rule brought to you by yara-signatorFelix Bilstein - yara-signator at cocacoding dot com
          • 0x77e8:$sequence_0: 03 C8 0F 31 2B C1 89 45 FC
          • 0x7b72:$sequence_0: 03 C8 0F 31 2B C1 89 45 FC
          • 0x13885:$sequence_1: 3C 24 0F 84 76 FF FF FF 3C 25 74 94
          • 0x13371:$sequence_2: 3B 4F 14 73 95 85 C9 74 91
          • 0x13987:$sequence_3: 3C 69 75 44 8B 7D 18 8B 0F
          • 0x13aff:$sequence_4: 5D C3 8D 50 7C 80 FA 07
          • 0x858a:$sequence_5: 0F BE 5C 0E 01 0F B6 54 0E 02 83 E3 0F C1 EA 06
          • 0x125ec:$sequence_6: 57 89 45 FC 89 45 F4 89 45 F8
          • 0x9302:$sequence_7: 66 89 0C 02 5B 8B E5 5D
          • 0x18977:$sequence_8: 3C 54 74 04 3C 74 75 F4
          • 0x19a1a:$sequence_9: 56 68 03 01 00 00 8D 85 95 FE FF FF 6A 00
          Click to see the 8 entries

          Sigma Overview

          No Sigma rule has matched

          Signature Overview

          Click to jump to signature section

          Show All Signature Results

          AV Detection:

          barindex
          Found malware configurationShow sources
          Source: 2.2.SecuriteInfo.com.Trojan.GenericKDZ.73120.139.exe.400000.0.unpackMalware Configuration Extractor: FormBook {"C2 list": ["www.rizrvd.com/bw82/"], "decoy": ["fundamentaliemef.com", "gallerybrows.com", "leadeligey.com", "octoberx2.online", "climaxnovels.com", "gdsjgf.com", "curateherstories.com", "blacksailus.com", "yjpps.com", "gmobilet.com", "fcoins.club", "foreverlive2027.com", "healthyfifties.com", "wmarquezy.com", "housebulb.com", "thebabyfriendly.com", "primajayaintiperkasa.com", "learnplaychess.com", "chrisbubser.digital", "xn--avenr-wsa.com", "exlineinsurance.com", "thrivezi.com", "tuvandadayvitos24h.online", "illfingers.com", "usmedicarenow.com", "pandabutik.com", "engageautism.info", "magnabeautystyle.com", "texasdryroof.com", "woodlandpizzahartford.com", "dameadamea.com", "sedaskincare.com", "ruaysatu99.com", "mybestaide.com", "nikolaichan.com", "mrcabinetkitchenandbath.com", "ondemandbarbering.com", "activagebenefits.net", "srcsvcs.com", "cbrealvitalize.com", "ismaelworks.com", "medkomp.online", "ninasangtani.com", "h2oturkiye.com", "kolamart.com", "acdfr.com", "twistedtailgatesweeps1.com", "ramjamdee.com", "thedancehalo.com", "joeisono.com", "glasshouseroadtrip.com", "okcpp.com", "riggsfarmfenceservices.com", "mgg360.com", "xn--oi2b190cymc.com", "ctfocbdwholesale.com", "openspiers.com", "rumblingrambles.com", "thepoetrictedstudio.com", "magiclabs.media", "wellnesssensation.com", "lakegastonautoparts.com", "dealsonwheeeles.com", "semenboostplus.com"]}
          Multi AV Scanner detection for submitted fileShow sources
          Source: SecuriteInfo.com.Trojan.GenericKDZ.73120.139.exeVirustotal: Detection: 36%Perma Link
          Source: SecuriteInfo.com.Trojan.GenericKDZ.73120.139.exeReversingLabs: Detection: 29%
          Yara detected FormBookShow sources
          Source: Yara matchFile source: 00000002.00000002.224039712.0000000000400000.00000040.00000001.sdmp, type: MEMORY
          Source: Yara matchFile source: 00000000.00000002.224800988.00000000036E9000.00000004.00000001.sdmp, type: MEMORY
          Source: Yara matchFile source: 2.2.SecuriteInfo.com.Trojan.GenericKDZ.73120.139.exe.400000.0.raw.unpack, type: UNPACKEDPE
          Source: Yara matchFile source: 2.2.SecuriteInfo.com.Trojan.GenericKDZ.73120.139.exe.400000.0.unpack, type: UNPACKEDPE
          Source: Yara matchFile source: 0.2.SecuriteInfo.com.Trojan.GenericKDZ.73120.139.exe.386d620.2.raw.unpack, type: UNPACKEDPE
          Source: Yara matchFile source: 0.2.SecuriteInfo.com.Trojan.GenericKDZ.73120.139.exe.381da00.3.raw.unpack, type: UNPACKEDPE
          Machine Learning detection for sampleShow sources
          Source: SecuriteInfo.com.Trojan.GenericKDZ.73120.139.exeJoe Sandbox ML: detected
          Source: 2.2.SecuriteInfo.com.Trojan.GenericKDZ.73120.139.exe.400000.0.unpackAvira: Label: TR/Crypt.ZPACK.Gen

          Compliance:

          barindex
          Uses 32bit PE filesShow sources
          Source: SecuriteInfo.com.Trojan.GenericKDZ.73120.139.exeStatic PE information: 32BIT_MACHINE, EXECUTABLE_IMAGE
          Contains modern PE file flags such as dynamic base (ASLR) or NXShow sources
          Source: SecuriteInfo.com.Trojan.GenericKDZ.73120.139.exeStatic PE information: NO_SEH, TERMINAL_SERVER_AWARE, DYNAMIC_BASE, NX_COMPAT
          Binary contains paths to debug symbolsShow sources
          Source: Binary string: wntdll.pdbUGP source: SecuriteInfo.com.Trojan.GenericKDZ.73120.139.exe, 00000002.00000002.224505859.0000000001370000.00000040.00000001.sdmp
          Source: Binary string: wntdll.pdb source: SecuriteInfo.com.Trojan.GenericKDZ.73120.139.exe
          Source: C:\Users\user\Desktop\SecuriteInfo.com.Trojan.GenericKDZ.73120.139.exeCode function: 4x nop then jmp 05840BBEh0_2_05840040
          Source: C:\Users\user\Desktop\SecuriteInfo.com.Trojan.GenericKDZ.73120.139.exeCode function: 4x nop then mov dword ptr [ebp-18h], 00000000h0_2_058422A0
          Source: C:\Users\user\Desktop\SecuriteInfo.com.Trojan.GenericKDZ.73120.139.exeCode function: 4x nop then jmp 05840BBEh0_2_05840CC7
          Source: C:\Users\user\Desktop\SecuriteInfo.com.Trojan.GenericKDZ.73120.139.exeCode function: 4x nop then jmp 05840BBEh0_2_05840119
          Source: C:\Users\user\Desktop\SecuriteInfo.com.Trojan.GenericKDZ.73120.139.exeCode function: 4x nop then jmp 05840BBEh0_2_05840007
          Source: C:\Users\user\Desktop\SecuriteInfo.com.Trojan.GenericKDZ.73120.139.exeCode function: 4x nop then jmp 05840BBEh0_2_05840B81
          Source: C:\Users\user\Desktop\SecuriteInfo.com.Trojan.GenericKDZ.73120.139.exeCode function: 4x nop then mov dword ptr [ebp-18h], 00000000h0_2_05842290

          Networking:

          barindex
          C2 URLs / IPs found in malware configurationShow sources
          Source: Malware configuration extractorURLs: www.rizrvd.com/bw82/
          Source: SecuriteInfo.com.Trojan.GenericKDZ.73120.139.exe, 00000000.00000002.224526375.00000000026E1000.00000004.00000001.sdmpString found in binary or memory: http://schemas.xmlsoap.org/ws/2005/05/identity/claims/name
          Source: SecuriteInfo.com.Trojan.GenericKDZ.73120.139.exe, 00000000.00000002.224526375.00000000026E1000.00000004.00000001.sdmpString found in binary or memory: https://stackpath.bootstrapcdn.com/bootstrap/4.5.0/css/bootstrap.min.css

          E-Banking Fraud:

          barindex
          Yara detected FormBookShow sources
          Source: Yara matchFile source: 00000002.00000002.224039712.0000000000400000.00000040.00000001.sdmp, type: MEMORY
          Source: Yara matchFile source: 00000000.00000002.224800988.00000000036E9000.00000004.00000001.sdmp, type: MEMORY
          Source: Yara matchFile source: 2.2.SecuriteInfo.com.Trojan.GenericKDZ.73120.139.exe.400000.0.raw.unpack, type: UNPACKEDPE
          Source: Yara matchFile source: 2.2.SecuriteInfo.com.Trojan.GenericKDZ.73120.139.exe.400000.0.unpack, type: UNPACKEDPE
          Source: Yara matchFile source: 0.2.SecuriteInfo.com.Trojan.GenericKDZ.73120.139.exe.386d620.2.raw.unpack, type: UNPACKEDPE
          Source: Yara matchFile source: 0.2.SecuriteInfo.com.Trojan.GenericKDZ.73120.139.exe.381da00.3.raw.unpack, type: UNPACKEDPE

          System Summary:

          barindex
          Malicious sample detected (through community Yara rule)Show sources
          Source: 00000002.00000002.224039712.0000000000400000.00000040.00000001.sdmp, type: MEMORYMatched rule: autogenerated rule brought to you by yara-signator Author: Felix Bilstein - yara-signator at cocacoding dot com
          Source: 00000002.00000002.224039712.0000000000400000.00000040.00000001.sdmp, type: MEMORYMatched rule: detect Formbook in memory Author: JPCERT/CC Incident Response Group
          Source: 00000000.00000002.224800988.00000000036E9000.00000004.00000001.sdmp, type: MEMORYMatched rule: autogenerated rule brought to you by yara-signator Author: Felix Bilstein - yara-signator at cocacoding dot com
          Source: 00000000.00000002.224800988.00000000036E9000.00000004.00000001.sdmp, type: MEMORYMatched rule: detect Formbook in memory Author: JPCERT/CC Incident Response Group
          Source: 2.2.SecuriteInfo.com.Trojan.GenericKDZ.73120.139.exe.400000.0.raw.unpack, type: UNPACKEDPEMatched rule: autogenerated rule brought to you by yara-signator Author: Felix Bilstein - yara-signator at cocacoding dot com
          Source: 2.2.SecuriteInfo.com.Trojan.GenericKDZ.73120.139.exe.400000.0.raw.unpack, type: UNPACKEDPEMatched rule: detect Formbook in memory Author: JPCERT/CC Incident Response Group
          Source: 2.2.SecuriteInfo.com.Trojan.GenericKDZ.73120.139.exe.400000.0.unpack, type: UNPACKEDPEMatched rule: autogenerated rule brought to you by yara-signator Author: Felix Bilstein - yara-signator at cocacoding dot com
          Source: 2.2.SecuriteInfo.com.Trojan.GenericKDZ.73120.139.exe.400000.0.unpack, type: UNPACKEDPEMatched rule: detect Formbook in memory Author: JPCERT/CC Incident Response Group
          Source: 0.2.SecuriteInfo.com.Trojan.GenericKDZ.73120.139.exe.386d620.2.raw.unpack, type: UNPACKEDPEMatched rule: autogenerated rule brought to you by yara-signator Author: Felix Bilstein - yara-signator at cocacoding dot com
          Source: 0.2.SecuriteInfo.com.Trojan.GenericKDZ.73120.139.exe.386d620.2.raw.unpack, type: UNPACKEDPEMatched rule: detect Formbook in memory Author: JPCERT/CC Incident Response Group
          Source: 0.2.SecuriteInfo.com.Trojan.GenericKDZ.73120.139.exe.381da00.3.raw.unpack, type: UNPACKEDPEMatched rule: autogenerated rule brought to you by yara-signator Author: Felix Bilstein - yara-signator at cocacoding dot com
          Source: 0.2.SecuriteInfo.com.Trojan.GenericKDZ.73120.139.exe.381da00.3.raw.unpack, type: UNPACKEDPEMatched rule: detect Formbook in memory Author: JPCERT/CC Incident Response Group
          .NET source code contains very large stringsShow sources
          Source: SecuriteInfo.com.Trojan.GenericKDZ.73120.139.exe, FrmStart.csLong String: Length: 13656
          Source: C:\Users\user\Desktop\SecuriteInfo.com.Trojan.GenericKDZ.73120.139.exeCode function: 2_2_004181B0 NtCreateFile,2_2_004181B0
          Source: C:\Users\user\Desktop\SecuriteInfo.com.Trojan.GenericKDZ.73120.139.exeCode function: 2_2_00418260 NtReadFile,2_2_00418260
          Source: C:\Users\user\Desktop\SecuriteInfo.com.Trojan.GenericKDZ.73120.139.exeCode function: 2_2_004182E0 NtClose,2_2_004182E0
          Source: C:\Users\user\Desktop\SecuriteInfo.com.Trojan.GenericKDZ.73120.139.exeCode function: 2_2_00418390 NtAllocateVirtualMemory,2_2_00418390
          Source: C:\Users\user\Desktop\SecuriteInfo.com.Trojan.GenericKDZ.73120.139.exeCode function: 2_2_004181AA NtCreateFile,2_2_004181AA
          Source: C:\Users\user\Desktop\SecuriteInfo.com.Trojan.GenericKDZ.73120.139.exeCode function: 2_2_0041825C NtReadFile,2_2_0041825C
          Source: C:\Users\user\Desktop\SecuriteInfo.com.Trojan.GenericKDZ.73120.139.exeCode function: 2_2_004182DA NtClose,2_2_004182DA
          Source: C:\Users\user\Desktop\SecuriteInfo.com.Trojan.GenericKDZ.73120.139.exeCode function: 2_2_013D9860 NtQuerySystemInformation,LdrInitializeThunk,2_2_013D9860
          Source: C:\Users\user\Desktop\SecuriteInfo.com.Trojan.GenericKDZ.73120.139.exeCode function: 2_2_013D9660 NtAllocateVirtualMemory,LdrInitializeThunk,2_2_013D9660
          Source: C:\Users\user\Desktop\SecuriteInfo.com.Trojan.GenericKDZ.73120.139.exeCode function: 2_2_013D96E0 NtFreeVirtualMemory,LdrInitializeThunk,2_2_013D96E0
          Source: C:\Users\user\Desktop\SecuriteInfo.com.Trojan.GenericKDZ.73120.139.exeCode function: 2_2_013D9910 NtAdjustPrivilegesToken,2_2_013D9910
          Source: C:\Users\user\Desktop\SecuriteInfo.com.Trojan.GenericKDZ.73120.139.exeCode function: 2_2_013D9950 NtQueueApcThread,2_2_013D9950
          Source: C:\Users\user\Desktop\SecuriteInfo.com.Trojan.GenericKDZ.73120.139.exeCode function: 2_2_013D99A0 NtCreateSection,2_2_013D99A0
          Source: C:\Users\user\Desktop\SecuriteInfo.com.Trojan.GenericKDZ.73120.139.exeCode function: 2_2_013D99D0 NtCreateProcessEx,2_2_013D99D0
          Source: C:\Users\user\Desktop\SecuriteInfo.com.Trojan.GenericKDZ.73120.139.exeCode function: 2_2_013D9820 NtEnumerateKey,2_2_013D9820
          Source: C:\Users\user\Desktop\SecuriteInfo.com.Trojan.GenericKDZ.73120.139.exeCode function: 2_2_013DB040 NtSuspendThread,2_2_013DB040
          Source: C:\Users\user\Desktop\SecuriteInfo.com.Trojan.GenericKDZ.73120.139.exeCode function: 2_2_013D9840 NtDelayExecution,2_2_013D9840
          Source: C:\Users\user\Desktop\SecuriteInfo.com.Trojan.GenericKDZ.73120.139.exeCode function: 2_2_013D98A0 NtWriteVirtualMemory,2_2_013D98A0
          Source: C:\Users\user\Desktop\SecuriteInfo.com.Trojan.GenericKDZ.73120.139.exeCode function: 2_2_013D98F0 NtReadVirtualMemory,2_2_013D98F0
          Source: C:\Users\user\Desktop\SecuriteInfo.com.Trojan.GenericKDZ.73120.139.exeCode function: 2_2_013D9B00 NtSetValueKey,2_2_013D9B00
          Source: C:\Users\user\Desktop\SecuriteInfo.com.Trojan.GenericKDZ.73120.139.exeCode function: 2_2_013DA3B0 NtGetContextThread,2_2_013DA3B0
          Source: C:\Users\user\Desktop\SecuriteInfo.com.Trojan.GenericKDZ.73120.139.exeCode function: 2_2_013D9A20 NtResumeThread,2_2_013D9A20
          Source: C:\Users\user\Desktop\SecuriteInfo.com.Trojan.GenericKDZ.73120.139.exeCode function: 2_2_013D9A10 NtQuerySection,2_2_013D9A10
          Source: C:\Users\user\Desktop\SecuriteInfo.com.Trojan.GenericKDZ.73120.139.exeCode function: 2_2_013D9A00 NtProtectVirtualMemory,2_2_013D9A00
          Source: C:\Users\user\Desktop\SecuriteInfo.com.Trojan.GenericKDZ.73120.139.exeCode function: 2_2_013D9A50 NtCreateFile,2_2_013D9A50
          Source: C:\Users\user\Desktop\SecuriteInfo.com.Trojan.GenericKDZ.73120.139.exeCode function: 2_2_013D9A80 NtOpenDirectoryObject,2_2_013D9A80
          Source: C:\Users\user\Desktop\SecuriteInfo.com.Trojan.GenericKDZ.73120.139.exeCode function: 2_2_013DAD30 NtSetContextThread,2_2_013DAD30
          Source: C:\Users\user\Desktop\SecuriteInfo.com.Trojan.GenericKDZ.73120.139.exeCode function: 2_2_013D9520 NtWaitForSingleObject,2_2_013D9520
          Source: C:\Users\user\Desktop\SecuriteInfo.com.Trojan.GenericKDZ.73120.139.exeCode function: 2_2_013D9560 NtWriteFile,2_2_013D9560
          Source: C:\Users\user\Desktop\SecuriteInfo.com.Trojan.GenericKDZ.73120.139.exeCode function: 2_2_013D9540 NtReadFile,2_2_013D9540
          Source: C:\Users\user\Desktop\SecuriteInfo.com.Trojan.GenericKDZ.73120.139.exeCode function: 2_2_013D95F0 NtQueryInformationFile,2_2_013D95F0
          Source: C:\Users\user\Desktop\SecuriteInfo.com.Trojan.GenericKDZ.73120.139.exeCode function: 2_2_013D95D0 NtClose,2_2_013D95D0
          Source: C:\Users\user\Desktop\SecuriteInfo.com.Trojan.GenericKDZ.73120.139.exeCode function: 2_2_013D9730 NtQueryVirtualMemory,2_2_013D9730
          Source: C:\Users\user\Desktop\SecuriteInfo.com.Trojan.GenericKDZ.73120.139.exeCode function: 2_2_013D9710 NtQueryInformationToken,2_2_013D9710
          Source: C:\Users\user\Desktop\SecuriteInfo.com.Trojan.GenericKDZ.73120.139.exeCode function: 2_2_013DA710 NtOpenProcessToken,2_2_013DA710
          Source: C:\Users\user\Desktop\SecuriteInfo.com.Trojan.GenericKDZ.73120.139.exeCode function: 2_2_013DA770 NtOpenThread,2_2_013DA770
          Source: C:\Users\user\Desktop\SecuriteInfo.com.Trojan.GenericKDZ.73120.139.exeCode function: 2_2_013D9770 NtSetInformationFile,2_2_013D9770
          Source: C:\Users\user\Desktop\SecuriteInfo.com.Trojan.GenericKDZ.73120.139.exeCode function: 2_2_013D9760 NtOpenProcess,2_2_013D9760
          Source: C:\Users\user\Desktop\SecuriteInfo.com.Trojan.GenericKDZ.73120.139.exeCode function: 2_2_013D97A0 NtUnmapViewOfSection,2_2_013D97A0
          Source: C:\Users\user\Desktop\SecuriteInfo.com.Trojan.GenericKDZ.73120.139.exeCode function: 2_2_013D9780 NtMapViewOfSection,2_2_013D9780
          Source: C:\Users\user\Desktop\SecuriteInfo.com.Trojan.GenericKDZ.73120.139.exeCode function: 2_2_013D9FE0 NtCreateMutant,2_2_013D9FE0
          Source: C:\Users\user\Desktop\SecuriteInfo.com.Trojan.GenericKDZ.73120.139.exeCode function: 2_2_013D9610 NtEnumerateValueKey,2_2_013D9610
          Source: C:\Users\user\Desktop\SecuriteInfo.com.Trojan.GenericKDZ.73120.139.exeCode function: 2_2_013D9670 NtQueryInformationProcess,2_2_013D9670
          Source: C:\Users\user\Desktop\SecuriteInfo.com.Trojan.GenericKDZ.73120.139.exeCode function: 2_2_013D9650 NtQueryValueKey,2_2_013D9650
          Source: C:\Users\user\Desktop\SecuriteInfo.com.Trojan.GenericKDZ.73120.139.exeCode function: 2_2_013D96D0 NtCreateKey,2_2_013D96D0
          Source: C:\Users\user\Desktop\SecuriteInfo.com.Trojan.GenericKDZ.73120.139.exeCode function: 0_2_026496080_2_02649608
          Source: C:\Users\user\Desktop\SecuriteInfo.com.Trojan.GenericKDZ.73120.139.exeCode function: 0_2_0264C52D0_2_0264C52D
          Source: C:\Users\user\Desktop\SecuriteInfo.com.Trojan.GenericKDZ.73120.139.exeCode function: 0_2_0264AB340_2_0264AB34
          Source: C:\Users\user\Desktop\SecuriteInfo.com.Trojan.GenericKDZ.73120.139.exeCode function: 0_2_05842C600_2_05842C60
          Source: C:\Users\user\Desktop\SecuriteInfo.com.Trojan.GenericKDZ.73120.139.exeCode function: 0_2_05840F700_2_05840F70
          Source: C:\Users\user\Desktop\SecuriteInfo.com.Trojan.GenericKDZ.73120.139.exeCode function: 0_2_058400400_2_05840040
          Source: C:\Users\user\Desktop\SecuriteInfo.com.Trojan.GenericKDZ.73120.139.exeCode function: 0_2_058400070_2_05840007
          Source: C:\Users\user\Desktop\SecuriteInfo.com.Trojan.GenericKDZ.73120.139.exeCode function: 2_2_0040102F2_2_0040102F
          Source: C:\Users\user\Desktop\SecuriteInfo.com.Trojan.GenericKDZ.73120.139.exeCode function: 2_2_004010302_2_00401030
          Source: C:\Users\user\Desktop\SecuriteInfo.com.Trojan.GenericKDZ.73120.139.exeCode function: 2_2_00408C4C2_2_00408C4C
          Source: C:\Users\user\Desktop\SecuriteInfo.com.Trojan.GenericKDZ.73120.139.exeCode function: 2_2_00408C502_2_00408C50
          Source: C:\Users\user\Desktop\SecuriteInfo.com.Trojan.GenericKDZ.73120.139.exeCode function: 2_2_0041B4932_2_0041B493
          Source: C:\Users\user\Desktop\SecuriteInfo.com.Trojan.GenericKDZ.73120.139.exeCode function: 2_2_0041CD282_2_0041CD28
          Source: C:\Users\user\Desktop\SecuriteInfo.com.Trojan.GenericKDZ.73120.139.exeCode function: 2_2_00402D872_2_00402D87
          Source: C:\Users\user\Desktop\SecuriteInfo.com.Trojan.GenericKDZ.73120.139.exeCode function: 2_2_00402D902_2_00402D90
          Source: C:\Users\user\Desktop\SecuriteInfo.com.Trojan.GenericKDZ.73120.139.exeCode function: 2_2_0041CE772_2_0041CE77
          Source: C:\Users\user\Desktop\SecuriteInfo.com.Trojan.GenericKDZ.73120.139.exeCode function: 2_2_00402FB02_2_00402FB0
          Source: C:\Users\user\Desktop\SecuriteInfo.com.Trojan.GenericKDZ.73120.139.exeCode function: 2_2_013B41202_2_013B4120
          Source: C:\Users\user\Desktop\SecuriteInfo.com.Trojan.GenericKDZ.73120.139.exeCode function: 2_2_0139F9002_2_0139F900
          Source: C:\Users\user\Desktop\SecuriteInfo.com.Trojan.GenericKDZ.73120.139.exeCode function: 2_2_013B99BF2_2_013B99BF
          Source: C:\Users\user\Desktop\SecuriteInfo.com.Trojan.GenericKDZ.73120.139.exeCode function: 2_2_013BA8302_2_013BA830
          Source: C:\Users\user\Desktop\SecuriteInfo.com.Trojan.GenericKDZ.73120.139.exeCode function: 2_2_013968002_2_01396800
          Source: C:\Users\user\Desktop\SecuriteInfo.com.Trojan.GenericKDZ.73120.139.exeCode function: 2_2_014510022_2_01451002
          Source: C:\Users\user\Desktop\SecuriteInfo.com.Trojan.GenericKDZ.73120.139.exeCode function: 2_2_0146E8242_2_0146E824
          Source: C:\Users\user\Desktop\SecuriteInfo.com.Trojan.GenericKDZ.73120.139.exeCode function: 2_2_013C20A02_2_013C20A0
          Source: C:\Users\user\Desktop\SecuriteInfo.com.Trojan.GenericKDZ.73120.139.exeCode function: 2_2_013AB0902_2_013AB090
          Source: C:\Users\user\Desktop\SecuriteInfo.com.Trojan.GenericKDZ.73120.139.exeCode function: 2_2_014628EC2_2_014628EC
          Source: C:\Users\user\Desktop\SecuriteInfo.com.Trojan.GenericKDZ.73120.139.exeCode function: 2_2_014620A82_2_014620A8
          Source: C:\Users\user\Desktop\SecuriteInfo.com.Trojan.GenericKDZ.73120.139.exeCode function: 2_2_0143CB4F2_2_0143CB4F
          Source: C:\Users\user\Desktop\SecuriteInfo.com.Trojan.GenericKDZ.73120.139.exeCode function: 2_2_013BA3092_2_013BA309
          Source: C:\Users\user\Desktop\SecuriteInfo.com.Trojan.GenericKDZ.73120.139.exeCode function: 2_2_013B33602_2_013B3360
          Source: C:\Users\user\Desktop\SecuriteInfo.com.Trojan.GenericKDZ.73120.139.exeCode function: 2_2_0145231B2_2_0145231B
          Source: C:\Users\user\Desktop\SecuriteInfo.com.Trojan.GenericKDZ.73120.139.exeCode function: 2_2_01462B282_2_01462B28
          Source: C:\Users\user\Desktop\SecuriteInfo.com.Trojan.GenericKDZ.73120.139.exeCode function: 2_2_013BAB402_2_013BAB40
          Source: C:\Users\user\Desktop\SecuriteInfo.com.Trojan.GenericKDZ.73120.139.exeCode function: 2_2_013CEBB02_2_013CEBB0
          Source: C:\Users\user\Desktop\SecuriteInfo.com.Trojan.GenericKDZ.73120.139.exeCode function: 2_2_0145DBD22_2_0145DBD2
          Source: C:\Users\user\Desktop\SecuriteInfo.com.Trojan.GenericKDZ.73120.139.exeCode function: 2_2_014503DA2_2_014503DA
          Source: C:\Users\user\Desktop\SecuriteInfo.com.Trojan.GenericKDZ.73120.139.exeCode function: 2_2_013BEB9A2_2_013BEB9A
          Source: C:\Users\user\Desktop\SecuriteInfo.com.Trojan.GenericKDZ.73120.139.exeCode function: 2_2_014423E32_2_014423E3
          Source: C:\Users\user\Desktop\SecuriteInfo.com.Trojan.GenericKDZ.73120.139.exeCode function: 2_2_013C138B2_2_013C138B
          Source: C:\Users\user\Desktop\SecuriteInfo.com.Trojan.GenericKDZ.73120.139.exeCode function: 2_2_0143EB8A2_2_0143EB8A
          Source: C:\Users\user\Desktop\SecuriteInfo.com.Trojan.GenericKDZ.73120.139.exeCode function: 2_2_013E8BE82_2_013E8BE8
          Source: C:\Users\user\Desktop\SecuriteInfo.com.Trojan.GenericKDZ.73120.139.exeCode function: 2_2_013CABD82_2_013CABD8
          Source: C:\Users\user\Desktop\SecuriteInfo.com.Trojan.GenericKDZ.73120.139.exeCode function: 2_2_013BB2362_2_013BB236
          Source: C:\Users\user\Desktop\SecuriteInfo.com.Trojan.GenericKDZ.73120.139.exeCode function: 2_2_0144FA2B2_2_0144FA2B
          Source: C:\Users\user\Desktop\SecuriteInfo.com.Trojan.GenericKDZ.73120.139.exeCode function: 2_2_0145E2C52_2_0145E2C5
          Source: C:\Users\user\Desktop\SecuriteInfo.com.Trojan.GenericKDZ.73120.139.exeCode function: 2_2_01454AEF2_2_01454AEF
          Source: C:\Users\user\Desktop\SecuriteInfo.com.Trojan.GenericKDZ.73120.139.exeCode function: 2_2_014622AE2_2_014622AE
          Source: C:\Users\user\Desktop\SecuriteInfo.com.Trojan.GenericKDZ.73120.139.exeCode function: 2_2_014632A92_2_014632A9
          Source: C:\Users\user\Desktop\SecuriteInfo.com.Trojan.GenericKDZ.73120.139.exeCode function: 2_2_01461D552_2_01461D55
          Source: C:\Users\user\Desktop\SecuriteInfo.com.Trojan.GenericKDZ.73120.139.exeCode function: 2_2_01390D202_2_01390D20
          Source: C:\Users\user\Desktop\SecuriteInfo.com.Trojan.GenericKDZ.73120.139.exeCode function: 2_2_01462D072_2_01462D07
          Source: C:\Users\user\Desktop\SecuriteInfo.com.Trojan.GenericKDZ.73120.139.exeCode function: 2_2_013B2D502_2_013B2D50
          Source: C:\Users\user\Desktop\SecuriteInfo.com.Trojan.GenericKDZ.73120.139.exeCode function: 2_2_014625DD2_2_014625DD
          Source: C:\Users\user\Desktop\SecuriteInfo.com.Trojan.GenericKDZ.73120.139.exeCode function: 2_2_013C65A02_2_013C65A0
          Source: C:\Users\user\Desktop\SecuriteInfo.com.Trojan.GenericKDZ.73120.139.exeCode function: 2_2_013C25812_2_013C2581
          Source: C:\Users\user\Desktop\SecuriteInfo.com.Trojan.GenericKDZ.73120.139.exeCode function: 2_2_01452D822_2_01452D82
          Source: C:\Users\user\Desktop\SecuriteInfo.com.Trojan.GenericKDZ.73120.139.exeCode function: 2_2_013AD5E02_2_013AD5E0
          Source: C:\Users\user\Desktop\SecuriteInfo.com.Trojan.GenericKDZ.73120.139.exeCode function: 2_2_0145D4662_2_0145D466
          Source: C:\Users\user\Desktop\SecuriteInfo.com.Trojan.GenericKDZ.73120.139.exeCode function: 2_2_013A841F2_2_013A841F
          Source: C:\Users\user\Desktop\SecuriteInfo.com.Trojan.GenericKDZ.73120.139.exeCode function: 2_2_013BB4772_2_013BB477
          Source: C:\Users\user\Desktop\SecuriteInfo.com.Trojan.GenericKDZ.73120.139.exeCode function: 2_2_014544962_2_01454496
          Source: C:\Users\user\Desktop\SecuriteInfo.com.Trojan.GenericKDZ.73120.139.exeCode function: 2_2_0146DFCE2_2_0146DFCE
          Source: C:\Users\user\Desktop\SecuriteInfo.com.Trojan.GenericKDZ.73120.139.exeCode function: 2_2_014567E22_2_014567E2
          Source: C:\Users\user\Desktop\SecuriteInfo.com.Trojan.GenericKDZ.73120.139.exeCode function: 2_2_01461FF12_2_01461FF1
          Source: C:\Users\user\Desktop\SecuriteInfo.com.Trojan.GenericKDZ.73120.139.exeCode function: 2_2_013B6E302_2_013B6E30
          Source: C:\Users\user\Desktop\SecuriteInfo.com.Trojan.GenericKDZ.73120.139.exeCode function: 2_2_013B56002_2_013B5600
          Source: C:\Users\user\Desktop\SecuriteInfo.com.Trojan.GenericKDZ.73120.139.exeCode function: 2_2_0145D6162_2_0145D616
          Source: C:\Users\user\Desktop\SecuriteInfo.com.Trojan.GenericKDZ.73120.139.exeCode function: 2_2_01462EF72_2_01462EF7
          Source: C:\Users\user\Desktop\SecuriteInfo.com.Trojan.GenericKDZ.73120.139.exeCode function: 2_2_01441EB62_2_01441EB6
          Source: C:\Users\user\Desktop\SecuriteInfo.com.Trojan.GenericKDZ.73120.139.exeCode function: String function: 013ED08C appears 42 times
          Source: C:\Users\user\Desktop\SecuriteInfo.com.Trojan.GenericKDZ.73120.139.exeCode function: String function: 0139B150 appears 154 times
          Source: C:\Users\user\Desktop\SecuriteInfo.com.Trojan.GenericKDZ.73120.139.exeCode function: String function: 01425720 appears 51 times
          Source: SecuriteInfo.com.Trojan.GenericKDZ.73120.139.exe, 00000000.00000002.224526375.00000000026E1000.00000004.00000001.sdmpBinary or memory string: OriginalFilenameAsyncState.dllF vs SecuriteInfo.com.Trojan.GenericKDZ.73120.139.exe
          Source: SecuriteInfo.com.Trojan.GenericKDZ.73120.139.exe, 00000000.00000002.226319020.00000000057E0000.00000004.00000001.sdmpBinary or memory string: OriginalFilenameLegacyPathHandling.dllN vs SecuriteInfo.com.Trojan.GenericKDZ.73120.139.exe
          Source: SecuriteInfo.com.Trojan.GenericKDZ.73120.139.exe, 00000000.00000000.217210974.000000000032E000.00000002.00020000.sdmpBinary or memory string: OriginalFilenameCLRSurrogateEntry.exe8 vs SecuriteInfo.com.Trojan.GenericKDZ.73120.139.exe
          Source: SecuriteInfo.com.Trojan.GenericKDZ.73120.139.exe, 00000002.00000002.224992684.000000000161F000.00000040.00000001.sdmpBinary or memory string: OriginalFilenamentdll.dllj% vs SecuriteInfo.com.Trojan.GenericKDZ.73120.139.exe
          Source: SecuriteInfo.com.Trojan.GenericKDZ.73120.139.exe, 00000002.00000002.224222430.000000000086E000.00000002.00020000.sdmpBinary or memory string: OriginalFilenameCLRSurrogateEntry.exe8 vs SecuriteInfo.com.Trojan.GenericKDZ.73120.139.exe
          Source: SecuriteInfo.com.Trojan.GenericKDZ.73120.139.exeBinary or memory string: OriginalFilenameCLRSurrogateEntry.exe8 vs SecuriteInfo.com.Trojan.GenericKDZ.73120.139.exe
          Source: SecuriteInfo.com.Trojan.GenericKDZ.73120.139.exeStatic PE information: 32BIT_MACHINE, EXECUTABLE_IMAGE
          Source: 00000002.00000002.224039712.0000000000400000.00000040.00000001.sdmp, type: MEMORYMatched rule: Formbook_1 date = 2018-11-23, author = Felix Bilstein - yara-signator at cocacoding dot com, malpedia_version = 20180607, description = autogenerated rule brought to you by yara-signator, malpedia_reference = https://malpedia.caad.fkie.fraunhofer.de/details/win.formbook, cape_type = Formbook Payload, malpedia_license = CC BY-NC-SA 4.0, version = 1, tool = yara-signator 0.1a, malpedia_sharing = TLP:WHITE
          Source: 00000002.00000002.224039712.0000000000400000.00000040.00000001.sdmp, type: MEMORYMatched rule: Formbook author = JPCERT/CC Incident Response Group, description = detect Formbook in memory, rule_usage = memory scan, reference = internal research
          Source: 00000000.00000002.224800988.00000000036E9000.00000004.00000001.sdmp, type: MEMORYMatched rule: Formbook_1 date = 2018-11-23, author = Felix Bilstein - yara-signator at cocacoding dot com, malpedia_version = 20180607, description = autogenerated rule brought to you by yara-signator, malpedia_reference = https://malpedia.caad.fkie.fraunhofer.de/details/win.formbook, cape_type = Formbook Payload, malpedia_license = CC BY-NC-SA 4.0, version = 1, tool = yara-signator 0.1a, malpedia_sharing = TLP:WHITE
          Source: 00000000.00000002.224800988.00000000036E9000.00000004.00000001.sdmp, type: MEMORYMatched rule: Formbook author = JPCERT/CC Incident Response Group, description = detect Formbook in memory, rule_usage = memory scan, reference = internal research
          Source: 2.2.SecuriteInfo.com.Trojan.GenericKDZ.73120.139.exe.400000.0.raw.unpack, type: UNPACKEDPEMatched rule: Formbook_1 date = 2018-11-23, author = Felix Bilstein - yara-signator at cocacoding dot com, malpedia_version = 20180607, description = autogenerated rule brought to you by yara-signator, malpedia_reference = https://malpedia.caad.fkie.fraunhofer.de/details/win.formbook, cape_type = Formbook Payload, malpedia_license = CC BY-NC-SA 4.0, version = 1, tool = yara-signator 0.1a, malpedia_sharing = TLP:WHITE
          Source: 2.2.SecuriteInfo.com.Trojan.GenericKDZ.73120.139.exe.400000.0.raw.unpack, type: UNPACKEDPEMatched rule: Formbook author = JPCERT/CC Incident Response Group, description = detect Formbook in memory, rule_usage = memory scan, reference = internal research
          Source: 2.2.SecuriteInfo.com.Trojan.GenericKDZ.73120.139.exe.400000.0.unpack, type: UNPACKEDPEMatched rule: Formbook_1 date = 2018-11-23, author = Felix Bilstein - yara-signator at cocacoding dot com, malpedia_version = 20180607, description = autogenerated rule brought to you by yara-signator, malpedia_reference = https://malpedia.caad.fkie.fraunhofer.de/details/win.formbook, cape_type = Formbook Payload, malpedia_license = CC BY-NC-SA 4.0, version = 1, tool = yara-signator 0.1a, malpedia_sharing = TLP:WHITE
          Source: 2.2.SecuriteInfo.com.Trojan.GenericKDZ.73120.139.exe.400000.0.unpack, type: UNPACKEDPEMatched rule: Formbook author = JPCERT/CC Incident Response Group, description = detect Formbook in memory, rule_usage = memory scan, reference = internal research
          Source: 0.2.SecuriteInfo.com.Trojan.GenericKDZ.73120.139.exe.386d620.2.raw.unpack, type: UNPACKEDPEMatched rule: Formbook_1 date = 2018-11-23, author = Felix Bilstein - yara-signator at cocacoding dot com, malpedia_version = 20180607, description = autogenerated rule brought to you by yara-signator, malpedia_reference = https://malpedia.caad.fkie.fraunhofer.de/details/win.formbook, cape_type = Formbook Payload, malpedia_license = CC BY-NC-SA 4.0, version = 1, tool = yara-signator 0.1a, malpedia_sharing = TLP:WHITE
          Source: 0.2.SecuriteInfo.com.Trojan.GenericKDZ.73120.139.exe.386d620.2.raw.unpack, type: UNPACKEDPEMatched rule: Formbook author = JPCERT/CC Incident Response Group, description = detect Formbook in memory, rule_usage = memory scan, reference = internal research
          Source: 0.2.SecuriteInfo.com.Trojan.GenericKDZ.73120.139.exe.381da00.3.raw.unpack, type: UNPACKEDPEMatched rule: Formbook_1 date = 2018-11-23, author = Felix Bilstein - yara-signator at cocacoding dot com, malpedia_version = 20180607, description = autogenerated rule brought to you by yara-signator, malpedia_reference = https://malpedia.caad.fkie.fraunhofer.de/details/win.formbook, cape_type = Formbook Payload, malpedia_license = CC BY-NC-SA 4.0, version = 1, tool = yara-signator 0.1a, malpedia_sharing = TLP:WHITE
          Source: 0.2.SecuriteInfo.com.Trojan.GenericKDZ.73120.139.exe.381da00.3.raw.unpack, type: UNPACKEDPEMatched rule: Formbook author = JPCERT/CC Incident Response Group, description = detect Formbook in memory, rule_usage = memory scan, reference = internal research
          Source: SecuriteInfo.com.Trojan.GenericKDZ.73120.139.exe, FrmStart.csBase64 encoded string: 'GIdDNNZNNNNRNNNN//8NNYtNNNNNNNNNDNNNNNNNNNNNNNNNNNNNNNNNNNNNNNNNNNNNNNNNNNNNNNNNtNNNNN4sht4NgNaAVotOGZ0uITucplOjpz9apzSgVTAuoz5iqPOvMFOlqJ4tnJ4tER9GVT1iMTHhQD0XWNNNNNNNNNODEDNNGNRQNViu868NNNNNNNNNNBNNNvRYNINNNPNNNNNTNNNNNNNNlw8NNNNtNNNNDNNNNNNNRDNtNNNNNtNNONNNNNNNNNNRNNNNNNNNNNPNNNNNNtNNNNNNNNZNDVHNNONNNONNNNNNRNNNRNNNNNNNNONNNNNNNNNNNNNNNUt/NNOCNNNNNRNNNBDQNNNNNNNNNNNNNNNNNNNNNNNNNTNNNNjNNNOpCjNNUNNNNNNNNNNNNNNNNNNNNNNNNNNNNNNNNNNNNNNNNNNNNNNNNNNNNNNNNNNNVNNNPNNNNNNNNNNNNNNNPPNNNRtNNNNNNNNNNNNNNP50MKu0NNNN0O8NNNNtNNNNVNNNNNVNNNNNNNNNNNNNNNNNNPNNNTNhpaAlLjNNNBDQNNNNDNNNNNDNNNNvNNNNNNNNNNNNNNNNNNONNNONYaWyoT9wNNNZNNNNNTNNNNNPNNNNWtNNNNNNNNNNNNNNNNNNDNNNDtNNNNNNNNNNNNNNNNNNNNPfCjNNNNNNNRtNNNNPNNHNhPHNNBjLNNNQNNNNNNNNNXD+NNP4NNNNNNNNNNNNNNNNNNNNNNNNNNNNNNNNNNNNNNNNNNNNNNNNNNNNNNNNNO4PXOLNNNbdWtNPXOpNNNbNXdMmTNNNPbNONNNRpkxNNNdNNtNNOUZnNNNXtNZNNNEmTjNNPbNRNNNRXuZjNDNDNNNNNDNNRDO+NDNNOT8pNNNXPvfNOvbGZNRNRNNNNNVNNORNstVNNNEiUDNNPtbeNNLdRmNONONNNNNQNNNENU4QNNNRok4NNNbXXjNTXuZjNDNDNNNNONNNRDO+ONNNOT8sNNNXPvfNOvbGZNVNCNNNNNHNNORNstHNNNDHXPNNNNbYOljuptRNNUQDODNNNvtuNNNXolVNNNcmVjNNPtjVtNHNNNDNNU4SNNNRPvfNOvbGZNRNPjNNNNLNNORNstLNNNDXXjNTXvVNNbNTNNNRXyMmQNNNOvtxNNNXqNLNNNXNOjNNOPbrNvtyNNNXXtNNRmNONNfNNNNUNNNENU4UNNNRPvfNOvbNRmNONNfNNNNUNNNENPtANNNTPvfNOvc+pwfNNUPNPNNNOUV7NNOjtNxNNNElBjNNpVNXNNNRXxbNNvtzNNNXNNZROFtENNNTNPbNNOZjONO0NNNNPNNNRDOmWjNNPtbTVYvPNDNtXWbONT8bNNNXXPxNNNbNNvtINNNTOPtHNNNTPjpbRjNNOtZbSDNNOvtFNNNTQNtbXtNNPt0WolfNNNbqzuZRRDEiYNNNPuhnRjHEOKV9NNOjTOvAStNNNFtgNNNXWuLbYtNNPtNdRmNSNWpNNNNWNNNENPtiNNNXN28jNNNXPjVPwzxK2cRspTRZNb5cS9LK2usJwF8NNNRANb5cS9bGOORRRjHJRjLeBtxEOtVEOcRVLDpEO5SugWjEOjAiZDNNPusn/tRGPORVRjxEPFjTSuZUNPfVNORUS9LGOjNEOusJRjLEOuRSZpNWNb5cTAbK1usnS9nAYjNNNFtlNNNXqNHNNOfXXjNTXtNGZNHNctNNNNbNNORNStfPomZNNNbGOkVUXQDNNNbZPNwLTgtAPEsnS9nAYjNNNEZRPOsnRjtJRjxeDjtK2uZXSuZYXl0PRDxEP281NNNXRjjFQPt2NNNXXQpNNNbJRDDUTvt4NNNXNNpn1tfEPksJRjfEPkRXZp0EPEsJRjxEPERVZopEOOLbBDNNPuZSRDHK2usJwF8NNNRGOuRRTuRTSuRTwzxbBNNNPtNEOtbeNNLdNNNGZNVNXNNNNNfNNORNN3WYNNOjXQbNNNbbBjNNPaZwNNNXPjpPomjNNNc0VtNNNDbeNNLdRmNRNRbNNNNZNNNENNWiZDNNPuuopm0NNNbYNz8kNNNXTAbZSt0eUjpPPEuiCtNNPu8DXQ8NNNbbDNNNPz9ONNNXWtxL1t0WPQUqO29PNNNXPvfNOvbNNOZjNDNUNNNNQDNNRDNHPvfNOvcTNNVJztVKztVLzvtENNNTNPbNNNNGZNZNVNNNNN4NNORNsttNNNE+PDNNOU4XNNNRXORNNNLNpwfNNUNXXjNTXuZjNtNFNNNNQjNNRDNPNluQNNNXXRDNNNbXXjNTXtNNRmNONNjNNNNDNNNENNVbEDNNPtbeNNLdRmNONONNNNNENNNENANWNNNPXPRNNNbXXjNTXuZjNDNZNNNNQtNNRDNPXRLNNNbXXjNTXuZjNtNqNNNNRtNNRDNPwNLNNOfH/tRYOljVXNRNNPfXXjHNNtbeNNLdWtNQ/uHTNNNoXvLNNvtzNNNXNPbNNNNGZNVNADNNNOZNNORNNagVNNNXo0xNNNbYO4jWNNNoSC4OQNtfSPtPNNNePjW7FNNNPtqiFtNNPtNNNNpXXjNTXyVNNvtzNNNXNNWmFjNNPa1VNNNXXv4bTNNNObNZNNNRXu4PXPLNNNbdNNOPH0cPNDNONNNNNNNZNNNNqwVhZP41ZQplAjNNNNNSNTjNNNPbPDNNV34NNODXNNOjPDNNV1A0pzyhM3ZNNNNNuOZNNTDNNNNwIIZN6OZNNONNNNNwE1IWENNNNCtGNNQ0ONNNV0Wfo2VNNNNNNNNNNtNNNIpIbtxWQjNNNCbOZjNJNNNONNNNBDNNNNfNNNNZNNNNVjNNNORNNNOYNNNNCjNNNOZNNNNTNNNNPtNNNNjNNNNWNNNNNDNNNNDNNNNONNNNNjNNNNZNNNNPNNNNNNNZODRNNNNNNNLNdtBJOjLNSjFJOjLNztYZOt8NQttNNNLN2jXzODLNwDBzODLN/tBzODLNltBzODLN4jBzODL
          Source: classification engineClassification label: mal100.troj.evad.winEXE@3/1@0/0
          Source: C:\Users\user\Desktop\SecuriteInfo.com.Trojan.GenericKDZ.73120.139.exeFile created: C:\Users\user\AppData\Local\Microsoft\CLR_v4.0_32\UsageLogs\SecuriteInfo.com.Trojan.GenericKDZ.73120.139.exe.logJump to behavior
          Source: SecuriteInfo.com.Trojan.GenericKDZ.73120.139.exeStatic PE information: Section: .text IMAGE_SCN_MEM_EXECUTE, IMAGE_SCN_CNT_CODE, IMAGE_SCN_MEM_READ
          Source: C:\Users\user\Desktop\SecuriteInfo.com.Trojan.GenericKDZ.73120.139.exeSection loaded: C:\Windows\assembly\NativeImages_v4.0.30319_32\mscorlib\a152fe02a317a77aeee36903305e8ba6\mscorlib.ni.dllJump to behavior
          Source: C:\Users\user\Desktop\SecuriteInfo.com.Trojan.GenericKDZ.73120.139.exeKey opened: HKEY_CURRENT_USER\Software\Policies\Microsoft\Windows\Safer\CodeIdentifiersJump to behavior
          Source: SecuriteInfo.com.Trojan.GenericKDZ.73120.139.exe, 00000000.00000002.224526375.00000000026E1000.00000004.00000001.sdmpBinary or memory string: INSERT INTO Itens_Aluguel VALUES(@aluguelID, @aviaoID, @validade);
          Source: SecuriteInfo.com.Trojan.GenericKDZ.73120.139.exe, 00000000.00000002.224526375.00000000026E1000.00000004.00000001.sdmpBinary or memory string: Insert into Clientes values (@nome, @cpf, @rg, @cidade, @endereco, @uf, @telefone);
          Source: SecuriteInfo.com.Trojan.GenericKDZ.73120.139.exeVirustotal: Detection: 36%
          Source: SecuriteInfo.com.Trojan.GenericKDZ.73120.139.exeReversingLabs: Detection: 29%
          Source: unknownProcess created: C:\Users\user\Desktop\SecuriteInfo.com.Trojan.GenericKDZ.73120.139.exe 'C:\Users\user\Desktop\SecuriteInfo.com.Trojan.GenericKDZ.73120.139.exe'
          Source: unknownProcess created: C:\Users\user\Desktop\SecuriteInfo.com.Trojan.GenericKDZ.73120.139.exe C:\Users\user\Desktop\SecuriteInfo.com.Trojan.GenericKDZ.73120.139.exe
          Source: C:\Users\user\Desktop\SecuriteInfo.com.Trojan.GenericKDZ.73120.139.exeProcess created: C:\Users\user\Desktop\SecuriteInfo.com.Trojan.GenericKDZ.73120.139.exe C:\Users\user\Desktop\SecuriteInfo.com.Trojan.GenericKDZ.73120.139.exeJump to behavior
          Source: C:\Users\user\Desktop\SecuriteInfo.com.Trojan.GenericKDZ.73120.139.exeFile opened: C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscorrc.dllJump to behavior
          Source: SecuriteInfo.com.Trojan.GenericKDZ.73120.139.exeStatic PE information: data directory type: IMAGE_DIRECTORY_ENTRY_COM_DESCRIPTOR
          Source: SecuriteInfo.com.Trojan.GenericKDZ.73120.139.exeStatic PE information: NO_SEH, TERMINAL_SERVER_AWARE, DYNAMIC_BASE, NX_COMPAT
          Source: Binary string: wntdll.pdbUGP source: SecuriteInfo.com.Trojan.GenericKDZ.73120.139.exe, 00000002.00000002.224505859.0000000001370000.00000040.00000001.sdmp
          Source: Binary string: wntdll.pdb source: SecuriteInfo.com.Trojan.GenericKDZ.73120.139.exe

          Data Obfuscation:

          barindex
          .NET source code contains potential unpackerShow sources
          Source: SecuriteInfo.com.Trojan.GenericKDZ.73120.139.exe, BoundHandle.cs.Net Code: .ctor System.Reflection.Assembly System.Reflection.Assembly::Load(System.Byte[])
          Source: C:\Users\user\Desktop\SecuriteInfo.com.Trojan.GenericKDZ.73120.139.exeCode function: 2_2_0040C8B1 push ss; iretd 2_2_0040C8B5
          Source: C:\Users\user\Desktop\SecuriteInfo.com.Trojan.GenericKDZ.73120.139.exeCode function: 2_2_0041B3F2 push eax; ret 2_2_0041B3F8
          Source: C:\Users\user\Desktop\SecuriteInfo.com.Trojan.GenericKDZ.73120.139.exeCode function: 2_2_0041B3FB push eax; ret 2_2_0041B462
          Source: C:\Users\user\Desktop\SecuriteInfo.com.Trojan.GenericKDZ.73120.139.exeCode function: 2_2_0041B3A5 push eax; ret 2_2_0041B3F8
          Source: C:\Users\user\Desktop\SecuriteInfo.com.Trojan.GenericKDZ.73120.139.exeCode function: 2_2_0041B45C push eax; ret 2_2_0041B462
          Source: C:\Users\user\Desktop\SecuriteInfo.com.Trojan.GenericKDZ.73120.139.exeCode function: 2_2_00415CB8 push esi; ret 2_2_00415CB9
          Source: C:\Users\user\Desktop\SecuriteInfo.com.Trojan.GenericKDZ.73120.139.exeCode function: 2_2_0041A5F2 push cs; retf 2_2_0041A5F3
          Source: C:\Users\user\Desktop\SecuriteInfo.com.Trojan.GenericKDZ.73120.139.exeCode function: 2_2_013ED0D1 push ecx; ret 2_2_013ED0E4
          Source: initial sampleStatic PE information: section name: .text entropy: 6.80894356258
          Source: C:\Users\user\Desktop\SecuriteInfo.com.Trojan.GenericKDZ.73120.139.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
          Source: C:\Users\user\Desktop\SecuriteInfo.com.Trojan.GenericKDZ.73120.139.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
          Source: C:\Users\user\Desktop\SecuriteInfo.com.Trojan.GenericKDZ.73120.139.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
          Source: C:\Users\user\Desktop\SecuriteInfo.com.Trojan.GenericKDZ.73120.139.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
          Source: C:\Users\user\Desktop\SecuriteInfo.com.Trojan.GenericKDZ.73120.139.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
          Source: C:\Users\user\Desktop\SecuriteInfo.com.Trojan.GenericKDZ.73120.139.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
          Source: C:\Users\user\Desktop\SecuriteInfo.com.Trojan.GenericKDZ.73120.139.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
          Source: C:\Users\user\Desktop\SecuriteInfo.com.Trojan.GenericKDZ.73120.139.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
          Source: C:\Users\user\Desktop\SecuriteInfo.com.Trojan.GenericKDZ.73120.139.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
          Source: C:\Users\user\Desktop\SecuriteInfo.com.Trojan.GenericKDZ.73120.139.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
          Source: C:\Users\user\Desktop\SecuriteInfo.com.Trojan.GenericKDZ.73120.139.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
          Source: C:\Users\user\Desktop\SecuriteInfo.com.Trojan.GenericKDZ.73120.139.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
          Source: C:\Users\user\Desktop\SecuriteInfo.com.Trojan.GenericKDZ.73120.139.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
          Source: C:\Users\user\Desktop\SecuriteInfo.com.Trojan.GenericKDZ.73120.139.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
          Source: C:\Users\user\Desktop\SecuriteInfo.com.Trojan.GenericKDZ.73120.139.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
          Source: C:\Users\user\Desktop\SecuriteInfo.com.Trojan.GenericKDZ.73120.139.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
          Source: C:\Users\user\Desktop\SecuriteInfo.com.Trojan.GenericKDZ.73120.139.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
          Source: C:\Users\user\Desktop\SecuriteInfo.com.Trojan.GenericKDZ.73120.139.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
          Source: C:\Users\user\Desktop\SecuriteInfo.com.Trojan.GenericKDZ.73120.139.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
          Source: C:\Users\user\Desktop\SecuriteInfo.com.Trojan.GenericKDZ.73120.139.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
          Source: C:\Users\user\Desktop\SecuriteInfo.com.Trojan.GenericKDZ.73120.139.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
          Source: C:\Users\user\Desktop\SecuriteInfo.com.Trojan.GenericKDZ.73120.139.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
          Source: C:\Users\user\Desktop\SecuriteInfo.com.Trojan.GenericKDZ.73120.139.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
          Source: C:\Users\user\Desktop\SecuriteInfo.com.Trojan.GenericKDZ.73120.139.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
          Source: C:\Users\user\Desktop\SecuriteInfo.com.Trojan.GenericKDZ.73120.139.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
          Source: C:\Users\user\Desktop\SecuriteInfo.com.Trojan.GenericKDZ.73120.139.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
          Source: C:\Users\user\Desktop\SecuriteInfo.com.Trojan.GenericKDZ.73120.139.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
          Source: C:\Users\user\Desktop\SecuriteInfo.com.Trojan.GenericKDZ.73120.139.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
          Source: C:\Users\user\Desktop\SecuriteInfo.com.Trojan.GenericKDZ.73120.139.exeProcess information set: NOOPENFILEERRORBOXJump to behavior

          Malware Analysis System Evasion:

          barindex
          Yara detected AntiVM_3Show sources
          Source: Yara matchFile source: 00000000.00000002.224526375.00000000026E1000.00000004.00000001.sdmp, type: MEMORY
          Source: Yara matchFile source: Process Memory Space: SecuriteInfo.com.Trojan.GenericKDZ.73120.139.exe PID: 6528, type: MEMORY
          Source: Yara matchFile source: 0.2.SecuriteInfo.com.Trojan.GenericKDZ.73120.139.exe.274294c.1.raw.unpack, type: UNPACKEDPE
          Tries to detect sandboxes and other dynamic analysis tools (process name or module or function)Show sources
          Source: SecuriteInfo.com.Trojan.GenericKDZ.73120.139.exe, 00000000.00000002.224526375.00000000026E1000.00000004.00000001.sdmpBinary or memory string: SBIEDLL.DLL
          Source: SecuriteInfo.com.Trojan.GenericKDZ.73120.139.exe, 00000000.00000002.224526375.00000000026E1000.00000004.00000001.sdmpBinary or memory string: KERNEL32.DLL.WINE_GET_UNIX_FILE_NAME
          Tries to detect virtualization through RDTSC time measurementsShow sources
          Source: C:\Users\user\Desktop\SecuriteInfo.com.Trojan.GenericKDZ.73120.139.exeRDTSC instruction interceptor: First address: 00000000004085E4 second address: 00000000004085EA instructions: 0x00000000 rdtsc 0x00000002 xor ecx, ecx 0x00000004 add ecx, eax 0x00000006 rdtsc
          Source: C:\Users\user\Desktop\SecuriteInfo.com.Trojan.GenericKDZ.73120.139.exeRDTSC instruction interceptor: First address: 000000000040896E second address: 0000000000408974 instructions: 0x00000000 rdtsc 0x00000002 xor ecx, ecx 0x00000004 add ecx, eax 0x00000006 rdtsc
          Source: C:\Users\user\Desktop\SecuriteInfo.com.Trojan.GenericKDZ.73120.139.exeCode function: 2_2_004088A0 rdtsc 2_2_004088A0
          Source: C:\Users\user\Desktop\SecuriteInfo.com.Trojan.GenericKDZ.73120.139.exeThread delayed: delay time: 922337203685477Jump to behavior
          Source: C:\Users\user\Desktop\SecuriteInfo.com.Trojan.GenericKDZ.73120.139.exe TID: 6532Thread sleep time: -101885s >= -30000sJump to behavior
          Source: C:\Users\user\Desktop\SecuriteInfo.com.Trojan.GenericKDZ.73120.139.exe TID: 6564Thread sleep time: -922337203685477s >= -30000sJump to behavior
          Source: SecuriteInfo.com.Trojan.GenericKDZ.73120.139.exe, 00000000.00000002.224526375.00000000026E1000.00000004.00000001.sdmpBinary or memory string: InstallPathJC:\PROGRAM FILES\VMWARE\VMWARE TOOLS\
          Source: SecuriteInfo.com.Trojan.GenericKDZ.73120.139.exe, 00000000.00000002.224526375.00000000026E1000.00000004.00000001.sdmpBinary or memory string: vmware
          Source: SecuriteInfo.com.Trojan.GenericKDZ.73120.139.exe, 00000000.00000002.224526375.00000000026E1000.00000004.00000001.sdmpBinary or memory string: VMware SVGA II
          Source: SecuriteInfo.com.Trojan.GenericKDZ.73120.139.exe, 00000000.00000002.224526375.00000000026E1000.00000004.00000001.sdmpBinary or memory string: VMWAREDSOFTWARE\VMware, Inc.\VMware Tools
          Source: C:\Users\user\Desktop\SecuriteInfo.com.Trojan.GenericKDZ.73120.139.exeProcess information queried: ProcessInformationJump to behavior
          Source: C:\Users\user\Desktop\SecuriteInfo.com.Trojan.GenericKDZ.73120.139.exeProcess queried: DebugPortJump to behavior
          Source: C:\Users\user\Desktop\SecuriteInfo.com.Trojan.GenericKDZ.73120.139.exeCode function: 2_2_004088A0 rdtsc 2_2_004088A0
          Source: C:\Users\user\Desktop\SecuriteInfo.com.Trojan.GenericKDZ.73120.139.exeCode function: 2_2_013D9860 NtQuerySystemInformation,LdrInitializeThunk,2_2_013D9860
          Source: C:\Users\user\Desktop\SecuriteInfo.com.Trojan.GenericKDZ.73120.139.exeCode function: 2_2_01393138 mov ecx, dword ptr fs:[00000030h]2_2_01393138
          Source: C:\Users\user\Desktop\SecuriteInfo.com.Trojan.GenericKDZ.73120.139.exeCode function: 2_2_013C513A mov eax, dword ptr fs:[00000030h]2_2_013C513A
          Source: C:\Users\user\Desktop\SecuriteInfo.com.Trojan.GenericKDZ.73120.139.exeCode function: 2_2_013C513A mov eax, dword ptr fs:[00000030h]2_2_013C513A
          Source: C:\Users\user\Desktop\SecuriteInfo.com.Trojan.GenericKDZ.73120.139.exeCode function: 2_2_01451951 mov eax, dword ptr fs:[00000030h]2_2_01451951
          Source: C:\Users\user\Desktop\SecuriteInfo.com.Trojan.GenericKDZ.73120.139.exeCode function: 2_2_013B4120 mov eax, dword ptr fs:[00000030h]2_2_013B4120
          Source: C:\Users\user\Desktop\SecuriteInfo.com.Trojan.GenericKDZ.73120.139.exeCode function: 2_2_013B4120 mov eax, dword ptr fs:[00000030h]2_2_013B4120
          Source: C:\Users\user\Desktop\SecuriteInfo.com.Trojan.GenericKDZ.73120.139.exeCode function: 2_2_013B4120 mov eax, dword ptr fs:[00000030h]2_2_013B4120
          Source: C:\Users\user\Desktop\SecuriteInfo.com.Trojan.GenericKDZ.73120.139.exeCode function: 2_2_013B4120 mov eax, dword ptr fs:[00000030h]2_2_013B4120
          Source: C:\Users\user\Desktop\SecuriteInfo.com.Trojan.GenericKDZ.73120.139.exeCode function: 2_2_013B4120 mov ecx, dword ptr fs:[00000030h]2_2_013B4120
          Source: C:\Users\user\Desktop\SecuriteInfo.com.Trojan.GenericKDZ.73120.139.exeCode function: 2_2_01468966 mov eax, dword ptr fs:[00000030h]2_2_01468966
          Source: C:\Users\user\Desktop\SecuriteInfo.com.Trojan.GenericKDZ.73120.139.exeCode function: 2_2_0145E962 mov eax, dword ptr fs:[00000030h]2_2_0145E962
          Source: C:\Users\user\Desktop\SecuriteInfo.com.Trojan.GenericKDZ.73120.139.exeCode function: 2_2_01399100 mov eax, dword ptr fs:[00000030h]2_2_01399100
          Source: C:\Users\user\Desktop\SecuriteInfo.com.Trojan.GenericKDZ.73120.139.exeCode function: 2_2_01399100 mov eax, dword ptr fs:[00000030h]2_2_01399100
          Source: C:\Users\user\Desktop\SecuriteInfo.com.Trojan.GenericKDZ.73120.139.exeCode function: 2_2_01399100 mov eax, dword ptr fs:[00000030h]2_2_01399100
          Source: C:\Users\user\Desktop\SecuriteInfo.com.Trojan.GenericKDZ.73120.139.exeCode function: 2_2_013A0100 mov eax, dword ptr fs:[00000030h]2_2_013A0100
          Source: C:\Users\user\Desktop\SecuriteInfo.com.Trojan.GenericKDZ.73120.139.exeCode function: 2_2_013A0100 mov eax, dword ptr fs:[00000030h]2_2_013A0100
          Source: C:\Users\user\Desktop\SecuriteInfo.com.Trojan.GenericKDZ.73120.139.exeCode function: 2_2_013A0100 mov eax, dword ptr fs:[00000030h]2_2_013A0100
          Source: C:\Users\user\Desktop\SecuriteInfo.com.Trojan.GenericKDZ.73120.139.exeCode function: 2_2_0139B171 mov eax, dword ptr fs:[00000030h]2_2_0139B171
          Source: C:\Users\user\Desktop\SecuriteInfo.com.Trojan.GenericKDZ.73120.139.exeCode function: 2_2_0139B171 mov eax, dword ptr fs:[00000030h]2_2_0139B171
          Source: C:\Users\user\Desktop\SecuriteInfo.com.Trojan.GenericKDZ.73120.139.exeCode function: 2_2_0139C962 mov eax, dword ptr fs:[00000030h]2_2_0139C962
          Source: C:\Users\user\Desktop\SecuriteInfo.com.Trojan.GenericKDZ.73120.139.exeCode function: 2_2_0139395E mov eax, dword ptr fs:[00000030h]2_2_0139395E
          Source: C:\Users\user\Desktop\SecuriteInfo.com.Trojan.GenericKDZ.73120.139.exeCode function: 2_2_0139395E mov eax, dword ptr fs:[00000030h]2_2_0139395E
          Source: C:\Users\user\Desktop\SecuriteInfo.com.Trojan.GenericKDZ.73120.139.exeCode function: 2_2_013BB944 mov eax, dword ptr fs:[00000030h]2_2_013BB944
          Source: C:\Users\user\Desktop\SecuriteInfo.com.Trojan.GenericKDZ.73120.139.exeCode function: 2_2_013BB944 mov eax, dword ptr fs:[00000030h]2_2_013BB944
          Source: C:\Users\user\Desktop\SecuriteInfo.com.Trojan.GenericKDZ.73120.139.exeCode function: 2_2_013B99BF mov ecx, dword ptr fs:[00000030h]2_2_013B99BF
          Source: C:\Users\user\Desktop\SecuriteInfo.com.Trojan.GenericKDZ.73120.139.exeCode function: 2_2_013B99BF mov ecx, dword ptr fs:[00000030h]2_2_013B99BF
          Source: C:\Users\user\Desktop\SecuriteInfo.com.Trojan.GenericKDZ.73120.139.exeCode function: 2_2_013B99BF mov eax, dword ptr fs:[00000030h]2_2_013B99BF
          Source: C:\Users\user\Desktop\SecuriteInfo.com.Trojan.GenericKDZ.73120.139.exeCode function: 2_2_013B99BF mov ecx, dword ptr fs:[00000030h]2_2_013B99BF
          Source: C:\Users\user\Desktop\SecuriteInfo.com.Trojan.GenericKDZ.73120.139.exeCode function: 2_2_013B99BF mov ecx, dword ptr fs:[00000030h]2_2_013B99BF
          Source: C:\Users\user\Desktop\SecuriteInfo.com.Trojan.GenericKDZ.73120.139.exeCode function: 2_2_013B99BF mov eax, dword ptr fs:[00000030h]2_2_013B99BF
          Source: C:\Users\user\Desktop\SecuriteInfo.com.Trojan.GenericKDZ.73120.139.exeCode function: 2_2_013B99BF mov ecx, dword ptr fs:[00000030h]2_2_013B99BF
          Source: C:\Users\user\Desktop\SecuriteInfo.com.Trojan.GenericKDZ.73120.139.exeCode function: 2_2_013B99BF mov ecx, dword ptr fs:[00000030h]2_2_013B99BF
          Source: C:\Users\user\Desktop\SecuriteInfo.com.Trojan.GenericKDZ.73120.139.exeCode function: 2_2_013B99BF mov eax, dword ptr fs:[00000030h]2_2_013B99BF
          Source: C:\Users\user\Desktop\SecuriteInfo.com.Trojan.GenericKDZ.73120.139.exeCode function: 2_2_013B99BF mov ecx, dword ptr fs:[00000030h]2_2_013B99BF
          Source: C:\Users\user\Desktop\SecuriteInfo.com.Trojan.GenericKDZ.73120.139.exeCode function: 2_2_013B99BF mov ecx, dword ptr fs:[00000030h]2_2_013B99BF
          Source: C:\Users\user\Desktop\SecuriteInfo.com.Trojan.GenericKDZ.73120.139.exeCode function: 2_2_013B99BF mov eax, dword ptr fs:[00000030h]2_2_013B99BF
          Source: C:\Users\user\Desktop\SecuriteInfo.com.Trojan.GenericKDZ.73120.139.exeCode function: 2_2_013C61A0 mov eax, dword ptr fs:[00000030h]2_2_013C61A0
          Source: C:\Users\user\Desktop\SecuriteInfo.com.Trojan.GenericKDZ.73120.139.exeCode function: 2_2_013C61A0 mov eax, dword ptr fs:[00000030h]2_2_013C61A0
          Source: C:\Users\user\Desktop\SecuriteInfo.com.Trojan.GenericKDZ.73120.139.exeCode function: 2_2_014519D8 mov eax, dword ptr fs:[00000030h]2_2_014519D8
          Source: C:\Users\user\Desktop\SecuriteInfo.com.Trojan.GenericKDZ.73120.139.exeCode function: 2_2_014689E7 mov eax, dword ptr fs:[00000030h]2_2_014689E7
          Source: C:\Users\user\Desktop\SecuriteInfo.com.Trojan.GenericKDZ.73120.139.exeCode function: 2_2_0139519E mov eax, dword ptr fs:[00000030h]2_2_0139519E
          Source: C:\Users\user\Desktop\SecuriteInfo.com.Trojan.GenericKDZ.73120.139.exeCode function: 2_2_0139519E mov ecx, dword ptr fs:[00000030h]2_2_0139519E
          Source: C:\Users\user\Desktop\SecuriteInfo.com.Trojan.GenericKDZ.73120.139.exeCode function: 2_2_014241E8 mov eax, dword ptr fs:[00000030h]2_2_014241E8
          Source: C:\Users\user\Desktop\SecuriteInfo.com.Trojan.GenericKDZ.73120.139.exeCode function: 2_2_013C2990 mov eax, dword ptr fs:[00000030h]2_2_013C2990
          Source: C:\Users\user\Desktop\SecuriteInfo.com.Trojan.GenericKDZ.73120.139.exeCode function: 2_2_013C4190 mov eax, dword ptr fs:[00000030h]2_2_013C4190
          Source: C:\Users\user\Desktop\SecuriteInfo.com.Trojan.GenericKDZ.73120.139.exeCode function: 2_2_013BC182 mov eax, dword ptr fs:[00000030h]2_2_013BC182
          Source: C:\Users\user\Desktop\SecuriteInfo.com.Trojan.GenericKDZ.73120.139.exeCode function: 2_2_013CA185 mov eax, dword ptr fs:[00000030h]2_2_013CA185
          Source: C:\Users\user\Desktop\SecuriteInfo.com.Trojan.GenericKDZ.73120.139.exeCode function: 2_2_0145A189 mov eax, dword ptr fs:[00000030h]2_2_0145A189
          Source: C:\Users\user\Desktop\SecuriteInfo.com.Trojan.GenericKDZ.73120.139.exeCode function: 2_2_0145A189 mov ecx, dword ptr fs:[00000030h]2_2_0145A189
          Source: C:\Users\user\Desktop\SecuriteInfo.com.Trojan.GenericKDZ.73120.139.exeCode function: 2_2_0139B1E1 mov eax, dword ptr fs:[00000030h]2_2_0139B1E1
          Source: C:\Users\user\Desktop\SecuriteInfo.com.Trojan.GenericKDZ.73120.139.exeCode function: 2_2_0139B1E1 mov eax, dword ptr fs:[00000030h]2_2_0139B1E1
          Source: C:\Users\user\Desktop\SecuriteInfo.com.Trojan.GenericKDZ.73120.139.exeCode function: 2_2_0139B1E1 mov eax, dword ptr fs:[00000030h]2_2_0139B1E1
          Source: C:\Users\user\Desktop\SecuriteInfo.com.Trojan.GenericKDZ.73120.139.exeCode function: 2_2_013931E0 mov eax, dword ptr fs:[00000030h]2_2_013931E0
          Source: C:\Users\user\Desktop\SecuriteInfo.com.Trojan.GenericKDZ.73120.139.exeCode function: 2_2_014549A4 mov eax, dword ptr fs:[00000030h]2_2_014549A4
          Source: C:\Users\user\Desktop\SecuriteInfo.com.Trojan.GenericKDZ.73120.139.exeCode function: 2_2_014549A4 mov eax, dword ptr fs:[00000030h]2_2_014549A4
          Source: C:\Users\user\Desktop\SecuriteInfo.com.Trojan.GenericKDZ.73120.139.exeCode function: 2_2_014549A4 mov eax, dword ptr fs:[00000030h]2_2_014549A4
          Source: C:\Users\user\Desktop\SecuriteInfo.com.Trojan.GenericKDZ.73120.139.exeCode function: 2_2_014549A4 mov eax, dword ptr fs:[00000030h]2_2_014549A4
          Source: C:\Users\user\Desktop\SecuriteInfo.com.Trojan.GenericKDZ.73120.139.exeCode function: 2_2_014169A6 mov eax, dword ptr fs:[00000030h]2_2_014169A6
          Source: C:\Users\user\Desktop\SecuriteInfo.com.Trojan.GenericKDZ.73120.139.exeCode function: 2_2_014151BE mov eax, dword ptr fs:[00000030h]2_2_014151BE
          Source: C:\Users\user\Desktop\SecuriteInfo.com.Trojan.GenericKDZ.73120.139.exeCode function: 2_2_014151BE mov eax, dword ptr fs:[00000030h]2_2_014151BE
          Source: C:\Users\user\Desktop\SecuriteInfo.com.Trojan.GenericKDZ.73120.139.exeCode function: 2_2_014151BE mov eax, dword ptr fs:[00000030h]2_2_014151BE
          Source: C:\Users\user\Desktop\SecuriteInfo.com.Trojan.GenericKDZ.73120.139.exeCode function: 2_2_014151BE mov eax, dword ptr fs:[00000030h]2_2_014151BE
          Source: C:\Users\user\Desktop\SecuriteInfo.com.Trojan.GenericKDZ.73120.139.exeCode function: 2_2_01451843 mov eax, dword ptr fs:[00000030h]2_2_01451843
          Source: C:\Users\user\Desktop\SecuriteInfo.com.Trojan.GenericKDZ.73120.139.exeCode function: 2_2_013BA830 mov eax, dword ptr fs:[00000030h]2_2_013BA830
          Source: C:\Users\user\Desktop\SecuriteInfo.com.Trojan.GenericKDZ.73120.139.exeCode function: 2_2_013BA830 mov eax, dword ptr fs:[00000030h]2_2_013BA830
          Source: C:\Users\user\Desktop\SecuriteInfo.com.Trojan.GenericKDZ.73120.139.exeCode function: 2_2_013BA830 mov eax, dword ptr fs:[00000030h]2_2_013BA830
          Source: C:\Users\user\Desktop\SecuriteInfo.com.Trojan.GenericKDZ.73120.139.exeCode function: 2_2_013BA830 mov eax, dword ptr fs:[00000030h]2_2_013BA830
          Source: C:\Users\user\Desktop\SecuriteInfo.com.Trojan.GenericKDZ.73120.139.exeCode function: 2_2_013AB02A mov eax, dword ptr fs:[00000030h]2_2_013AB02A
          Source: C:\Users\user\Desktop\SecuriteInfo.com.Trojan.GenericKDZ.73120.139.exeCode function: 2_2_013AB02A mov eax, dword ptr fs:[00000030h]2_2_013AB02A
          Source: C:\Users\user\Desktop\SecuriteInfo.com.Trojan.GenericKDZ.73120.139.exeCode function: 2_2_013AB02A mov eax, dword ptr fs:[00000030h]2_2_013AB02A
          Source: C:\Users\user\Desktop\SecuriteInfo.com.Trojan.GenericKDZ.73120.139.exeCode function: 2_2_013AB02A mov eax, dword ptr fs:[00000030h]2_2_013AB02A
          Source: C:\Users\user\Desktop\SecuriteInfo.com.Trojan.GenericKDZ.73120.139.exeCode function: 2_2_013C002D mov eax, dword ptr fs:[00000030h]2_2_013C002D
          Source: C:\Users\user\Desktop\SecuriteInfo.com.Trojan.GenericKDZ.73120.139.exeCode function: 2_2_013C002D mov eax, dword ptr fs:[00000030h]2_2_013C002D
          Source: C:\Users\user\Desktop\SecuriteInfo.com.Trojan.GenericKDZ.73120.139.exeCode function: 2_2_013C002D mov eax, dword ptr fs:[00000030h]2_2_013C002D
          Source: C:\Users\user\Desktop\SecuriteInfo.com.Trojan.GenericKDZ.73120.139.exeCode function: 2_2_013C002D mov eax, dword ptr fs:[00000030h]2_2_013C002D
          Source: C:\Users\user\Desktop\SecuriteInfo.com.Trojan.GenericKDZ.73120.139.exeCode function: 2_2_013C002D mov eax, dword ptr fs:[00000030h]2_2_013C002D
          Source: C:\Users\user\Desktop\SecuriteInfo.com.Trojan.GenericKDZ.73120.139.exeCode function: 2_2_013C4020 mov edi, dword ptr fs:[00000030h]2_2_013C4020
          Source: C:\Users\user\Desktop\SecuriteInfo.com.Trojan.GenericKDZ.73120.139.exeCode function: 2_2_01461074 mov eax, dword ptr fs:[00000030h]2_2_01461074
          Source: C:\Users\user\Desktop\SecuriteInfo.com.Trojan.GenericKDZ.73120.139.exeCode function: 2_2_01452073 mov eax, dword ptr fs:[00000030h]2_2_01452073
          Source: C:\Users\user\Desktop\SecuriteInfo.com.Trojan.GenericKDZ.73120.139.exeCode function: 2_2_01396800 mov eax, dword ptr fs:[00000030h]2_2_01396800
          Source: C:\Users\user\Desktop\SecuriteInfo.com.Trojan.GenericKDZ.73120.139.exeCode function: 2_2_01396800 mov eax, dword ptr fs:[00000030h]2_2_01396800
          Source: C:\Users\user\Desktop\SecuriteInfo.com.Trojan.GenericKDZ.73120.139.exeCode function: 2_2_01396800 mov eax, dword ptr fs:[00000030h]2_2_01396800
          Source: C:\Users\user\Desktop\SecuriteInfo.com.Trojan.GenericKDZ.73120.139.exeCode function: 2_2_01464015 mov eax, dword ptr fs:[00000030h]2_2_01464015
          Source: C:\Users\user\Desktop\SecuriteInfo.com.Trojan.GenericKDZ.73120.139.exeCode function: 2_2_01464015 mov eax, dword ptr fs:[00000030h]2_2_01464015
          Source: C:\Users\user\Desktop\SecuriteInfo.com.Trojan.GenericKDZ.73120.139.exeCode function: 2_2_013BF86D mov eax, dword ptr fs:[00000030h]2_2_013BF86D
          Source: C:\Users\user\Desktop\SecuriteInfo.com.Trojan.GenericKDZ.73120.139.exeCode function: 2_2_01417016 mov eax, dword ptr fs:[00000030h]2_2_01417016
          Source: C:\Users\user\Desktop\SecuriteInfo.com.Trojan.GenericKDZ.73120.139.exeCode function: 2_2_01417016 mov eax, dword ptr fs:[00000030h]2_2_01417016
          Source: C:\Users\user\Desktop\SecuriteInfo.com.Trojan.GenericKDZ.73120.139.exeCode function: 2_2_01417016 mov eax, dword ptr fs:[00000030h]2_2_01417016
          Source: C:\Users\user\Desktop\SecuriteInfo.com.Trojan.GenericKDZ.73120.139.exeCode function: 2_2_01395050 mov eax, dword ptr fs:[00000030h]2_2_01395050
          Source: C:\Users\user\Desktop\SecuriteInfo.com.Trojan.GenericKDZ.73120.139.exeCode function: 2_2_01395050 mov eax, dword ptr fs:[00000030h]2_2_01395050
          Source: C:\Users\user\Desktop\SecuriteInfo.com.Trojan.GenericKDZ.73120.139.exeCode function: 2_2_01395050 mov eax, dword ptr fs:[00000030h]2_2_01395050
          Source: C:\Users\user\Desktop\SecuriteInfo.com.Trojan.GenericKDZ.73120.139.exeCode function: 2_2_013B0050 mov eax, dword ptr fs:[00000030h]2_2_013B0050
          Source: C:\Users\user\Desktop\SecuriteInfo.com.Trojan.GenericKDZ.73120.139.exeCode function: 2_2_013B0050 mov eax, dword ptr fs:[00000030h]2_2_013B0050
          Source: C:\Users\user\Desktop\SecuriteInfo.com.Trojan.GenericKDZ.73120.139.exeCode function: 2_2_01397057 mov eax, dword ptr fs:[00000030h]2_2_01397057
          Source: C:\Users\user\Desktop\SecuriteInfo.com.Trojan.GenericKDZ.73120.139.exeCode function: 2_2_013CF0BF mov ecx, dword ptr fs:[00000030h]2_2_013CF0BF
          Source: C:\Users\user\Desktop\SecuriteInfo.com.Trojan.GenericKDZ.73120.139.exeCode function: 2_2_013CF0BF mov eax, dword ptr fs:[00000030h]2_2_013CF0BF
          Source: C:\Users\user\Desktop\SecuriteInfo.com.Trojan.GenericKDZ.73120.139.exeCode function: 2_2_013CF0BF mov eax, dword ptr fs:[00000030h]2_2_013CF0BF
          Source: C:\Users\user\Desktop\SecuriteInfo.com.Trojan.GenericKDZ.73120.139.exeCode function: 2_2_014518CA mov eax, dword ptr fs:[00000030h]2_2_014518CA
          Source: C:\Users\user\Desktop\SecuriteInfo.com.Trojan.GenericKDZ.73120.139.exeCode function: 2_2_013D90AF mov eax, dword ptr fs:[00000030h]2_2_013D90AF
          Source: C:\Users\user\Desktop\SecuriteInfo.com.Trojan.GenericKDZ.73120.139.exeCode function: 2_2_013A28AE mov eax, dword ptr fs:[00000030h]2_2_013A28AE
          Source: C:\Users\user\Desktop\SecuriteInfo.com.Trojan.GenericKDZ.73120.139.exeCode function: 2_2_013A28AE mov eax, dword ptr fs:[00000030h]2_2_013A28AE
          Source: C:\Users\user\Desktop\SecuriteInfo.com.Trojan.GenericKDZ.73120.139.exeCode function: 2_2_013A28AE mov eax, dword ptr fs:[00000030h]2_2_013A28AE
          Source: C:\Users\user\Desktop\SecuriteInfo.com.Trojan.GenericKDZ.73120.139.exeCode function: 2_2_013A28AE mov ecx, dword ptr fs:[00000030h]2_2_013A28AE
          Source: C:\Users\user\Desktop\SecuriteInfo.com.Trojan.GenericKDZ.73120.139.exeCode function: 2_2_013A28AE mov eax, dword ptr fs:[00000030h]2_2_013A28AE
          Source: C:\Users\user\Desktop\SecuriteInfo.com.Trojan.GenericKDZ.73120.139.exeCode function: 2_2_013A28AE mov eax, dword ptr fs:[00000030h]2_2_013A28AE
          Source: C:\Users\user\Desktop\SecuriteInfo.com.Trojan.GenericKDZ.73120.139.exeCode function: 2_2_013C20A0 mov eax, dword ptr fs:[00000030h]2_2_013C20A0
          Source: C:\Users\user\Desktop\SecuriteInfo.com.Trojan.GenericKDZ.73120.139.exeCode function: 2_2_013C20A0 mov eax, dword ptr fs:[00000030h]2_2_013C20A0
          Source: C:\Users\user\Desktop\SecuriteInfo.com.Trojan.GenericKDZ.73120.139.exeCode function: 2_2_013C20A0 mov eax, dword ptr fs:[00000030h]2_2_013C20A0
          Source: C:\Users\user\Desktop\SecuriteInfo.com.Trojan.GenericKDZ.73120.139.exeCode function: 2_2_013C20A0 mov eax, dword ptr fs:[00000030h]2_2_013C20A0
          Source: C:\Users\user\Desktop\SecuriteInfo.com.Trojan.GenericKDZ.73120.139.exeCode function: 2_2_013C20A0 mov eax, dword ptr fs:[00000030h]2_2_013C20A0
          Source: C:\Users\user\Desktop\SecuriteInfo.com.Trojan.GenericKDZ.73120.139.exeCode function: 2_2_013C20A0 mov eax, dword ptr fs:[00000030h]2_2_013C20A0
          Source: C:\Users\user\Desktop\SecuriteInfo.com.Trojan.GenericKDZ.73120.139.exeCode function: 2_2_01399080 mov eax, dword ptr fs:[00000030h]2_2_01399080
          Source: C:\Users\user\Desktop\SecuriteInfo.com.Trojan.GenericKDZ.73120.139.exeCode function: 2_2_01393880 mov eax, dword ptr fs:[00000030h]2_2_01393880
          Source: C:\Users\user\Desktop\SecuriteInfo.com.Trojan.GenericKDZ.73120.139.exeCode function: 2_2_01393880 mov eax, dword ptr fs:[00000030h]2_2_01393880
          Source: C:\Users\user\Desktop\SecuriteInfo.com.Trojan.GenericKDZ.73120.139.exeCode function: 2_2_01413884 mov eax, dword ptr fs:[00000030h]2_2_01413884
          Source: C:\Users\user\Desktop\SecuriteInfo.com.Trojan.GenericKDZ.73120.139.exeCode function: 2_2_01413884 mov eax, dword ptr fs:[00000030h]2_2_01413884
          Source: C:\Users\user\Desktop\SecuriteInfo.com.Trojan.GenericKDZ.73120.139.exeCode function: 2_2_013A28FD mov eax, dword ptr fs:[00000030h]2_2_013A28FD
          Source: C:\Users\user\Desktop\SecuriteInfo.com.Trojan.GenericKDZ.73120.139.exeCode function: 2_2_013A28FD mov eax, dword ptr fs:[00000030h]2_2_013A28FD
          Source: C:\Users\user\Desktop\SecuriteInfo.com.Trojan.GenericKDZ.73120.139.exeCode function: 2_2_013A28FD mov eax, dword ptr fs:[00000030h]2_2_013A28FD
          Source: C:\Users\user\Desktop\SecuriteInfo.com.Trojan.GenericKDZ.73120.139.exeCode function: 2_2_013958EC mov eax, dword ptr fs:[00000030h]2_2_013958EC
          Source: C:\Users\user\Desktop\SecuriteInfo.com.Trojan.GenericKDZ.73120.139.exeCode function: 2_2_013940E1 mov eax, dword ptr fs:[00000030h]2_2_013940E1
          Source: C:\Users\user\Desktop\SecuriteInfo.com.Trojan.GenericKDZ.73120.139.exeCode function: 2_2_013940E1 mov eax, dword ptr fs:[00000030h]2_2_013940E1
          Source: C:\Users\user\Desktop\SecuriteInfo.com.Trojan.GenericKDZ.73120.139.exeCode function: 2_2_013940E1 mov eax, dword ptr fs:[00000030h]2_2_013940E1
          Source: C:\Users\user\Desktop\SecuriteInfo.com.Trojan.GenericKDZ.73120.139.exeCode function: 2_2_013BB8E4 mov eax, dword ptr fs:[00000030h]2_2_013BB8E4
          Source: C:\Users\user\Desktop\SecuriteInfo.com.Trojan.GenericKDZ.73120.139.exeCode function: 2_2_013BB8E4 mov eax, dword ptr fs:[00000030h]2_2_013BB8E4
          Source: C:\Users\user\Desktop\SecuriteInfo.com.Trojan.GenericKDZ.73120.139.exeCode function: 2_2_013970C0 mov eax, dword ptr fs:[00000030h]2_2_013970C0
          Source: C:\Users\user\Desktop\SecuriteInfo.com.Trojan.GenericKDZ.73120.139.exeCode function: 2_2_013970C0 mov eax, dword ptr fs:[00000030h]2_2_013970C0
          Source: C:\Users\user\Desktop\SecuriteInfo.com.Trojan.GenericKDZ.73120.139.exeCode function: 2_2_01468B58 mov eax, dword ptr fs:[00000030h]2_2_01468B58
          Source: C:\Users\user\Desktop\SecuriteInfo.com.Trojan.GenericKDZ.73120.139.exeCode function: 2_2_01426365 mov eax, dword ptr fs:[00000030h]2_2_01426365
          Source: C:\Users\user\Desktop\SecuriteInfo.com.Trojan.GenericKDZ.73120.139.exeCode function: 2_2_01426365 mov eax, dword ptr fs:[00000030h]2_2_01426365
          Source: C:\Users\user\Desktop\SecuriteInfo.com.Trojan.GenericKDZ.73120.139.exeCode function: 2_2_01426365 mov eax, dword ptr fs:[00000030h]2_2_01426365
          Source: C:\Users\user\Desktop\SecuriteInfo.com.Trojan.GenericKDZ.73120.139.exeCode function: 2_2_013BA309 mov eax, dword ptr fs:[00000030h]2_2_013BA309
          Source: C:\Users\user\Desktop\SecuriteInfo.com.Trojan.GenericKDZ.73120.139.exeCode function: 2_2_013BA309 mov eax, dword ptr fs:[00000030h]2_2_013BA309
          Source: C:\Users\user\Desktop\SecuriteInfo.com.Trojan.GenericKDZ.73120.139.exeCode function: 2_2_013BA309 mov eax, dword ptr fs:[00000030h]2_2_013BA309
          Source: C:\Users\user\Desktop\SecuriteInfo.com.Trojan.GenericKDZ.73120.139.exeCode function: 2_2_013BA309 mov eax, dword ptr fs:[00000030h]2_2_013BA309
          Source: C:\Users\user\Desktop\SecuriteInfo.com.Trojan.GenericKDZ.73120.139.exeCode function: 2_2_013BA309 mov eax, dword ptr fs:[00000030h]2_2_013BA309
          Source: C:\Users\user\Desktop\SecuriteInfo.com.Trojan.GenericKDZ.73120.139.exeCode function: 2_2_013BA309 mov eax, dword ptr fs:[00000030h]2_2_013BA309
          Source: C:\Users\user\Desktop\SecuriteInfo.com.Trojan.GenericKDZ.73120.139.exeCode function: 2_2_013BA309 mov eax, dword ptr fs:[00000030h]2_2_013BA309
          Source: C:\Users\user\Desktop\SecuriteInfo.com.Trojan.GenericKDZ.73120.139.exeCode function: 2_2_013BA309 mov eax, dword ptr fs:[00000030h]2_2_013BA309
          Source: C:\Users\user\Desktop\SecuriteInfo.com.Trojan.GenericKDZ.73120.139.exeCode function: 2_2_013BA309 mov eax, dword ptr fs:[00000030h]2_2_013BA309
          Source: C:\Users\user\Desktop\SecuriteInfo.com.Trojan.GenericKDZ.73120.139.exeCode function: 2_2_013BA309 mov eax, dword ptr fs:[00000030h]2_2_013BA309
          Source: C:\Users\user\Desktop\SecuriteInfo.com.Trojan.GenericKDZ.73120.139.exeCode function: 2_2_013BA309 mov eax, dword ptr fs:[00000030h]2_2_013BA309
          Source: C:\Users\user\Desktop\SecuriteInfo.com.Trojan.GenericKDZ.73120.139.exeCode function: 2_2_013BA309 mov eax, dword ptr fs:[00000030h]2_2_013BA309
          Source: C:\Users\user\Desktop\SecuriteInfo.com.Trojan.GenericKDZ.73120.139.exeCode function: 2_2_013BA309 mov eax, dword ptr fs:[00000030h]2_2_013BA309
          Source: C:\Users\user\Desktop\SecuriteInfo.com.Trojan.GenericKDZ.73120.139.exeCode function: 2_2_013BA309 mov eax, dword ptr fs:[00000030h]2_2_013BA309
          Source: C:\Users\user\Desktop\SecuriteInfo.com.Trojan.GenericKDZ.73120.139.exeCode function: 2_2_013BA309 mov eax, dword ptr fs:[00000030h]2_2_013BA309
          Source: C:\Users\user\Desktop\SecuriteInfo.com.Trojan.GenericKDZ.73120.139.exeCode function: 2_2_013BA309 mov eax, dword ptr fs:[00000030h]2_2_013BA309
          Source: C:\Users\user\Desktop\SecuriteInfo.com.Trojan.GenericKDZ.73120.139.exeCode function: 2_2_013BA309 mov eax, dword ptr fs:[00000030h]2_2_013BA309
          Source: C:\Users\user\Desktop\SecuriteInfo.com.Trojan.GenericKDZ.73120.139.exeCode function: 2_2_013BA309 mov eax, dword ptr fs:[00000030h]2_2_013BA309
          Source: C:\Users\user\Desktop\SecuriteInfo.com.Trojan.GenericKDZ.73120.139.exeCode function: 2_2_013BA309 mov eax, dword ptr fs:[00000030h]2_2_013BA309
          Source: C:\Users\user\Desktop\SecuriteInfo.com.Trojan.GenericKDZ.73120.139.exeCode function: 2_2_013BA309 mov eax, dword ptr fs:[00000030h]2_2_013BA309
          Source: C:\Users\user\Desktop\SecuriteInfo.com.Trojan.GenericKDZ.73120.139.exeCode function: 2_2_013BA309 mov eax, dword ptr fs:[00000030h]2_2_013BA309
          Source: C:\Users\user\Desktop\SecuriteInfo.com.Trojan.GenericKDZ.73120.139.exeCode function: 2_2_013C3B7A mov eax, dword ptr fs:[00000030h]2_2_013C3B7A
          Source: C:\Users\user\Desktop\SecuriteInfo.com.Trojan.GenericKDZ.73120.139.exeCode function: 2_2_013C3B7A mov eax, dword ptr fs:[00000030h]2_2_013C3B7A
          Source: C:\Users\user\Desktop\SecuriteInfo.com.Trojan.GenericKDZ.73120.139.exeCode function: 2_2_013AF370 mov eax, dword ptr fs:[00000030h]2_2_013AF370
          Source: C:\Users\user\Desktop\SecuriteInfo.com.Trojan.GenericKDZ.73120.139.exeCode function: 2_2_013AF370 mov eax, dword ptr fs:[00000030h]2_2_013AF370
          Source: C:\Users\user\Desktop\SecuriteInfo.com.Trojan.GenericKDZ.73120.139.exeCode function: 2_2_013AF370 mov eax, dword ptr fs:[00000030h]2_2_013AF370
          Source: C:\Users\user\Desktop\SecuriteInfo.com.Trojan.GenericKDZ.73120.139.exeCode function: 2_2_0139DB60 mov ecx, dword ptr fs:[00000030h]2_2_0139DB60
          Source: C:\Users\user\Desktop\SecuriteInfo.com.Trojan.GenericKDZ.73120.139.exeCode function: 2_2_0145131B mov eax, dword ptr fs:[00000030h]2_2_0145131B
          Source: C:\Users\user\Desktop\SecuriteInfo.com.Trojan.GenericKDZ.73120.139.exeCode function: 2_2_0139F358 mov eax, dword ptr fs:[00000030h]2_2_0139F358
          Source: C:\Users\user\Desktop\SecuriteInfo.com.Trojan.GenericKDZ.73120.139.exeCode function: 2_2_013C3B5A mov eax, dword ptr fs:[00000030h]2_2_013C3B5A
          Source: C:\Users\user\Desktop\SecuriteInfo.com.Trojan.GenericKDZ.73120.139.exeCode function: 2_2_013C3B5A mov eax, dword ptr fs:[00000030h]2_2_013C3B5A
          Source: C:\Users\user\Desktop\SecuriteInfo.com.Trojan.GenericKDZ.73120.139.exeCode function: 2_2_013C3B5A mov eax, dword ptr fs:[00000030h]2_2_013C3B5A
          Source: C:\Users\user\Desktop\SecuriteInfo.com.Trojan.GenericKDZ.73120.139.exeCode function: 2_2_013C3B5A mov eax, dword ptr fs:[00000030h]2_2_013C3B5A
          Source: C:\Users\user\Desktop\SecuriteInfo.com.Trojan.GenericKDZ.73120.139.exeCode function: 2_2_0139DB40 mov eax, dword ptr fs:[00000030h]2_2_0139DB40
          Source: C:\Users\user\Desktop\SecuriteInfo.com.Trojan.GenericKDZ.73120.139.exeCode function: 2_2_014153CA mov eax, dword ptr fs:[00000030h]2_2_014153CA
          Source: C:\Users\user\Desktop\SecuriteInfo.com.Trojan.GenericKDZ.73120.139.exeCode function: 2_2_014153CA mov eax, dword ptr fs:[00000030h]2_2_014153CA
          Source: C:\Users\user\Desktop\SecuriteInfo.com.Trojan.GenericKDZ.73120.139.exeCode function: 2_2_013C4BAD mov eax, dword ptr fs:[00000030h]2_2_013C4BAD
          Source: C:\Users\user\Desktop\SecuriteInfo.com.Trojan.GenericKDZ.73120.139.exeCode function: 2_2_013C4BAD mov eax, dword ptr fs:[00000030h]2_2_013C4BAD
          Source: C:\Users\user\Desktop\SecuriteInfo.com.Trojan.GenericKDZ.73120.139.exeCode function: 2_2_013C4BAD mov eax, dword ptr fs:[00000030h]2_2_013C4BAD
          Source: C:\Users\user\Desktop\SecuriteInfo.com.Trojan.GenericKDZ.73120.139.exeCode function: 2_2_013BEB9A mov eax, dword ptr fs:[00000030h]2_2_013BEB9A
          Source: C:\Users\user\Desktop\SecuriteInfo.com.Trojan.GenericKDZ.73120.139.exeCode function: 2_2_013BEB9A mov eax, dword ptr fs:[00000030h]2_2_013BEB9A
          Source: C:\Users\user\Desktop\SecuriteInfo.com.Trojan.GenericKDZ.73120.139.exeCode function: 2_2_014423E3 mov ecx, dword ptr fs:[00000030h]2_2_014423E3
          Source: C:\Users\user\Desktop\SecuriteInfo.com.Trojan.GenericKDZ.73120.139.exeCode function: 2_2_014423E3 mov ecx, dword ptr fs:[00000030h]2_2_014423E3
          Source: C:\Users\user\Desktop\SecuriteInfo.com.Trojan.GenericKDZ.73120.139.exeCode function: 2_2_014423E3 mov eax, dword ptr fs:[00000030h]2_2_014423E3
          Source: C:\Users\user\Desktop\SecuriteInfo.com.Trojan.GenericKDZ.73120.139.exeCode function: 2_2_013C2397 mov eax, dword ptr fs:[00000030h]2_2_013C2397
          Source: C:\Users\user\Desktop\SecuriteInfo.com.Trojan.GenericKDZ.73120.139.exeCode function: 2_2_013CB390 mov eax, dword ptr fs:[00000030h]2_2_013CB390
          Source: C:\Users\user\Desktop\SecuriteInfo.com.Trojan.GenericKDZ.73120.139.exeCode function: 2_2_01394B94 mov edi, dword ptr fs:[00000030h]2_2_01394B94
          Source: C:\Users\user\Desktop\SecuriteInfo.com.Trojan.GenericKDZ.73120.139.exeCode function: 2_2_013A1B8F mov eax, dword ptr fs:[00000030h]2_2_013A1B8F
          Source: C:\Users\user\Desktop\SecuriteInfo.com.Trojan.GenericKDZ.73120.139.exeCode function: 2_2_013A1B8F mov eax, dword ptr fs:[00000030h]2_2_013A1B8F
          Source: C:\Users\user\Desktop\SecuriteInfo.com.Trojan.GenericKDZ.73120.139.exeCode function: 2_2_013C138B mov eax, dword ptr fs:[00000030h]2_2_013C138B
          Source: C:\Users\user\Desktop\SecuriteInfo.com.Trojan.GenericKDZ.73120.139.exeCode function: 2_2_013C138B mov eax, dword ptr fs:[00000030h]2_2_013C138B
          Source: C:\Users\user\Desktop\SecuriteInfo.com.Trojan.GenericKDZ.73120.139.exeCode function: 2_2_013C138B mov eax, dword ptr fs:[00000030h]2_2_013C138B
          Source: C:\Users\user\Desktop\SecuriteInfo.com.Trojan.GenericKDZ.73120.139.exeCode function: 2_2_0144D380 mov ecx, dword ptr fs:[00000030h]2_2_0144D380
          Source: C:\Users\user\Desktop\SecuriteInfo.com.Trojan.GenericKDZ.73120.139.exeCode function: 2_2_0143EB8A mov ecx, dword ptr fs:[00000030h]2_2_0143EB8A
          Source: C:\Users\user\Desktop\SecuriteInfo.com.Trojan.GenericKDZ.73120.139.exeCode function: 2_2_0143EB8A mov eax, dword ptr fs:[00000030h]2_2_0143EB8A
          Source: C:\Users\user\Desktop\SecuriteInfo.com.Trojan.GenericKDZ.73120.139.exeCode function: 2_2_0143EB8A mov eax, dword ptr fs:[00000030h]2_2_0143EB8A
          Source: C:\Users\user\Desktop\SecuriteInfo.com.Trojan.GenericKDZ.73120.139.exeCode function: 2_2_0143EB8A mov eax, dword ptr fs:[00000030h]2_2_0143EB8A
          Source: C:\Users\user\Desktop\SecuriteInfo.com.Trojan.GenericKDZ.73120.139.exeCode function: 2_2_0145138A mov eax, dword ptr fs:[00000030h]2_2_0145138A
          Source: C:\Users\user\Desktop\SecuriteInfo.com.Trojan.GenericKDZ.73120.139.exeCode function: 2_2_01391BE9 mov eax, dword ptr fs:[00000030h]2_2_01391BE9
          Source: C:\Users\user\Desktop\SecuriteInfo.com.Trojan.GenericKDZ.73120.139.exeCode function: 2_2_013BDBE9 mov eax, dword ptr fs:[00000030h]2_2_013BDBE9
          Source: C:\Users\user\Desktop\SecuriteInfo.com.Trojan.GenericKDZ.73120.139.exeCode function: 2_2_013C03E2 mov eax, dword ptr fs:[00000030h]2_2_013C03E2
          Source: C:\Users\user\Desktop\SecuriteInfo.com.Trojan.GenericKDZ.73120.139.exeCode function: 2_2_013C03E2 mov eax, dword ptr fs:[00000030h]2_2_013C03E2
          Source: C:\Users\user\Desktop\SecuriteInfo.com.Trojan.GenericKDZ.73120.139.exeCode function: 2_2_013C03E2 mov eax, dword ptr fs:[00000030h]2_2_013C03E2
          Source: C:\Users\user\Desktop\SecuriteInfo.com.Trojan.GenericKDZ.73120.139.exeCode function: 2_2_013C03E2 mov eax, dword ptr fs:[00000030h]2_2_013C03E2
          Source: C:\Users\user\Desktop\SecuriteInfo.com.Trojan.GenericKDZ.73120.139.exeCode function: 2_2_013C03E2 mov eax, dword ptr fs:[00000030h]2_2_013C03E2
          Source: C:\Users\user\Desktop\SecuriteInfo.com.Trojan.GenericKDZ.73120.139.exeCode function: 2_2_013C03E2 mov eax, dword ptr fs:[00000030h]2_2_013C03E2
          Source: C:\Users\user\Desktop\SecuriteInfo.com.Trojan.GenericKDZ.73120.139.exeCode function: 2_2_01465BA5 mov eax, dword ptr fs:[00000030h]2_2_01465BA5
          Source: C:\Users\user\Desktop\SecuriteInfo.com.Trojan.GenericKDZ.73120.139.exeCode function: 2_2_01451BA8 mov eax, dword ptr fs:[00000030h]2_2_01451BA8
          Source: C:\Users\user\Desktop\SecuriteInfo.com.Trojan.GenericKDZ.73120.139.exeCode function: 2_2_01468BB6 mov eax, dword ptr fs:[00000030h]2_2_01468BB6
          Source: C:\Users\user\Desktop\SecuriteInfo.com.Trojan.GenericKDZ.73120.139.exeCode function: 2_2_01469BBE mov eax, dword ptr fs:[00000030h]2_2_01469BBE
          Source: C:\Users\user\Desktop\SecuriteInfo.com.Trojan.GenericKDZ.73120.139.exeCode function: 2_2_013C53C5 mov eax, dword ptr fs:[00000030h]2_2_013C53C5
          Source: C:\Users\user\Desktop\SecuriteInfo.com.Trojan.GenericKDZ.73120.139.exeCode function: 2_2_01398239 mov eax, dword ptr fs:[00000030h]2_2_01398239
          Source: C:\Users\user\Desktop\SecuriteInfo.com.Trojan.GenericKDZ.73120.139.exeCode function: 2_2_01398239 mov eax, dword ptr fs:[00000030h]2_2_01398239
          Source: C:\Users\user\Desktop\SecuriteInfo.com.Trojan.GenericKDZ.73120.139.exeCode function: 2_2_01398239 mov eax, dword ptr fs:[00000030h]2_2_01398239
          Source: C:\Users\user\Desktop\SecuriteInfo.com.Trojan.GenericKDZ.73120.139.exeCode function: 2_2_013BB236 mov eax, dword ptr fs:[00000030h]2_2_013BB236
          Source: C:\Users\user\Desktop\SecuriteInfo.com.Trojan.GenericKDZ.73120.139.exeCode function: 2_2_013BB236 mov eax, dword ptr fs:[00000030h]2_2_013BB236
          Source: C:\Users\user\Desktop\SecuriteInfo.com.Trojan.GenericKDZ.73120.139.exeCode function: 2_2_013BB236 mov eax, dword ptr fs:[00000030h]2_2_013BB236
          Source: C:\Users\user\Desktop\SecuriteInfo.com.Trojan.GenericKDZ.73120.139.exeCode function: 2_2_013BB236 mov eax, dword ptr fs:[00000030h]2_2_013BB236
          Source: C:\Users\user\Desktop\SecuriteInfo.com.Trojan.GenericKDZ.73120.139.exeCode function: 2_2_013BB236 mov eax, dword ptr fs:[00000030h]2_2_013BB236
          Source: C:\Users\user\Desktop\SecuriteInfo.com.Trojan.GenericKDZ.73120.139.exeCode function: 2_2_013BB236 mov eax, dword ptr fs:[00000030h]2_2_013BB236
          Source: C:\Users\user\Desktop\SecuriteInfo.com.Trojan.GenericKDZ.73120.139.exeCode function: 2_2_0145EA55 mov eax, dword ptr fs:[00000030h]2_2_0145EA55
          Source: C:\Users\user\Desktop\SecuriteInfo.com.Trojan.GenericKDZ.73120.139.exeCode function: 2_2_013D4A2C mov eax, dword ptr fs:[00000030h]2_2_013D4A2C
          Source: C:\Users\user\Desktop\SecuriteInfo.com.Trojan.GenericKDZ.73120.139.exeCode function: 2_2_013D4A2C mov eax, dword ptr fs:[00000030h]2_2_013D4A2C
          Source: C:\Users\user\Desktop\SecuriteInfo.com.Trojan.GenericKDZ.73120.139.exeCode function: 2_2_013BA229 mov eax, dword ptr fs:[00000030h]2_2_013BA229
          Source: C:\Users\user\Desktop\SecuriteInfo.com.Trojan.GenericKDZ.73120.139.exeCode function: 2_2_013BA229 mov eax, dword ptr fs:[00000030h]2_2_013BA229
          Source: C:\Users\user\Desktop\SecuriteInfo.com.Trojan.GenericKDZ.73120.139.exeCode function: 2_2_013BA229 mov eax, dword ptr fs:[00000030h]2_2_013BA229
          Source: C:\Users\user\Desktop\SecuriteInfo.com.Trojan.GenericKDZ.73120.139.exeCode function: 2_2_013BA229 mov eax, dword ptr fs:[00000030h]2_2_013BA229
          Source: C:\Users\user\Desktop\SecuriteInfo.com.Trojan.GenericKDZ.73120.139.exeCode function: 2_2_013BA229 mov eax, dword ptr fs:[00000030h]2_2_013BA229
          Source: C:\Users\user\Desktop\SecuriteInfo.com.Trojan.GenericKDZ.73120.139.exeCode function: 2_2_013BA229 mov eax, dword ptr fs:[00000030h]2_2_013BA229
          Source: C:\Users\user\Desktop\SecuriteInfo.com.Trojan.GenericKDZ.73120.139.exeCode function: 2_2_013BA229 mov eax, dword ptr fs:[00000030h]2_2_013BA229
          Source: C:\Users\user\Desktop\SecuriteInfo.com.Trojan.GenericKDZ.73120.139.exeCode function: 2_2_013BA229 mov eax, dword ptr fs:[00000030h]2_2_013BA229
          Source: C:\Users\user\Desktop\SecuriteInfo.com.Trojan.GenericKDZ.73120.139.exeCode function: 2_2_013BA229 mov eax, dword ptr fs:[00000030h]2_2_013BA229
          Source: C:\Users\user\Desktop\SecuriteInfo.com.Trojan.GenericKDZ.73120.139.exeCode function: 2_2_01424257 mov eax, dword ptr fs:[00000030h]2_2_01424257
          Source: C:\Users\user\Desktop\SecuriteInfo.com.Trojan.GenericKDZ.73120.139.exeCode function: 2_2_01394A20 mov eax, dword ptr fs:[00000030h]2_2_01394A20
          Source: C:\Users\user\Desktop\SecuriteInfo.com.Trojan.GenericKDZ.73120.139.exeCode function: 2_2_01394A20 mov eax, dword ptr fs:[00000030h]2_2_01394A20
          Source: C:\Users\user\Desktop\SecuriteInfo.com.Trojan.GenericKDZ.73120.139.exeCode function: 2_2_01451A5F mov eax, dword ptr fs:[00000030h]2_2_01451A5F
          Source: C:\Users\user\Desktop\SecuriteInfo.com.Trojan.GenericKDZ.73120.139.exeCode function: 2_2_0144B260 mov eax, dword ptr fs:[00000030h]2_2_0144B260
          Source: C:\Users\user\Desktop\SecuriteInfo.com.Trojan.GenericKDZ.73120.139.exeCode function: 2_2_0144B260 mov eax, dword ptr fs:[00000030h]2_2_0144B260
          Source: C:\Users\user\Desktop\SecuriteInfo.com.Trojan.GenericKDZ.73120.139.exeCode function: 2_2_01468A62 mov eax, dword ptr fs:[00000030h]2_2_01468A62
          Source: C:\Users\user\Desktop\SecuriteInfo.com.Trojan.GenericKDZ.73120.139.exeCode function: 2_2_013B3A1C mov eax, dword ptr fs:[00000030h]2_2_013B3A1C
          Source: C:\Users\user\Desktop\SecuriteInfo.com.Trojan.GenericKDZ.73120.139.exeCode function: 2_2_01395210 mov eax, dword ptr fs:[00000030h]2_2_01395210
          Source: C:\Users\user\Desktop\SecuriteInfo.com.Trojan.GenericKDZ.73120.139.exeCode function: 2_2_01395210 mov ecx, dword ptr fs:[00000030h]2_2_01395210
          Source: C:\Users\user\Desktop\SecuriteInfo.com.Trojan.GenericKDZ.73120.139.exeCode function: 2_2_01395210 mov eax, dword ptr fs:[00000030h]2_2_01395210
          Source: C:\Users\user\Desktop\SecuriteInfo.com.Trojan.GenericKDZ.73120.139.exeCode function: 2_2_01395210 mov eax, dword ptr fs:[00000030h]2_2_01395210
          Source: C:\Users\user\Desktop\SecuriteInfo.com.Trojan.GenericKDZ.73120.139.exeCode function: 2_2_0139AA16 mov eax, dword ptr fs:[00000030h]2_2_0139AA16
          Source: C:\Users\user\Desktop\SecuriteInfo.com.Trojan.GenericKDZ.73120.139.exeCode function: 2_2_0139AA16 mov eax, dword ptr fs:[00000030h]2_2_0139AA16
          Source: C:\Users\user\Desktop\SecuriteInfo.com.Trojan.GenericKDZ.73120.139.exeCode function: 2_2_013A8A0A mov eax, dword ptr fs:[00000030h]2_2_013A8A0A
          Source: C:\Users\user\Desktop\SecuriteInfo.com.Trojan.GenericKDZ.73120.139.exeCode function: 2_2_013D927A mov eax, dword ptr fs:[00000030h]2_2_013D927A
          Source: C:\Users\user\Desktop\SecuriteInfo.com.Trojan.GenericKDZ.73120.139.exeCode function: 2_2_0145AA16 mov eax, dword ptr fs:[00000030h]2_2_0145AA16
          Source: C:\Users\user\Desktop\SecuriteInfo.com.Trojan.GenericKDZ.73120.139.exeCode function: 2_2_0145AA16 mov eax, dword ptr fs:[00000030h]2_2_0145AA16
          Source: C:\Users\user\Desktop\SecuriteInfo.com.Trojan.GenericKDZ.73120.139.exeCode function: 2_2_013D5A69 mov eax, dword ptr fs:[00000030h]2_2_013D5A69
          Source: C:\Users\user\Desktop\SecuriteInfo.com.Trojan.GenericKDZ.73120.139.exeCode function: 2_2_013D5A69 mov eax, dword ptr fs:[00000030h]2_2_013D5A69
          Source: C:\Users\user\Desktop\SecuriteInfo.com.Trojan.GenericKDZ.73120.139.exeCode function: 2_2_013D5A69 mov eax, dword ptr fs:[00000030h]2_2_013D5A69
          Source: C:\Users\user\Desktop\SecuriteInfo.com.Trojan.GenericKDZ.73120.139.exeCode function: 2_2_01451229 mov eax, dword ptr fs:[00000030h]2_2_01451229
          Source: C:\Users\user\Desktop\SecuriteInfo.com.Trojan.GenericKDZ.73120.139.exeCode function: 2_2_01399240 mov eax, dword ptr fs:[00000030h]2_2_01399240
          Source: C:\Users\user\Desktop\SecuriteInfo.com.Trojan.GenericKDZ.73120.139.exeCode function: 2_2_01399240 mov eax, dword ptr fs:[00000030h]2_2_01399240
          Source: C:\Users\user\Desktop\SecuriteInfo.com.Trojan.GenericKDZ.73120.139.exeCode function: 2_2_01399240 mov eax, dword ptr fs:[00000030h]2_2_01399240
          Source: C:\Users\user\Desktop\SecuriteInfo.com.Trojan.GenericKDZ.73120.139.exeCode function: 2_2_01399240 mov eax, dword ptr fs:[00000030h]2_2_01399240
          Source: C:\Users\user\Desktop\SecuriteInfo.com.Trojan.GenericKDZ.73120.139.exeCode function: 2_2_013C12BD mov esi, dword ptr fs:[00000030h]2_2_013C12BD
          Source: C:\Users\user\Desktop\SecuriteInfo.com.Trojan.GenericKDZ.73120.139.exeCode function: 2_2_013C12BD mov eax, dword ptr fs:[00000030h]2_2_013C12BD
          Source: C:\Users\user\Desktop\SecuriteInfo.com.Trojan.GenericKDZ.73120.139.exeCode function: 2_2_013C12BD mov eax, dword ptr fs:[00000030h]2_2_013C12BD
          Source: C:\Users\user\Desktop\SecuriteInfo.com.Trojan.GenericKDZ.73120.139.exeCode function: 2_2_013AAAB0 mov eax, dword ptr fs:[00000030h]2_2_013AAAB0
          Source: C:\Users\user\Desktop\SecuriteInfo.com.Trojan.GenericKDZ.73120.139.exeCode function: 2_2_013AAAB0 mov eax, dword ptr fs:[00000030h]2_2_013AAAB0
          Source: C:\Users\user\Desktop\SecuriteInfo.com.Trojan.GenericKDZ.73120.139.exeCode function: 2_2_013CFAB0 mov eax, dword ptr fs:[00000030h]2_2_013CFAB0
          Source: C:\Users\user\Desktop\SecuriteInfo.com.Trojan.GenericKDZ.73120.139.exeCode function: 2_2_01391AA0 mov eax, dword ptr fs:[00000030h]2_2_01391AA0
          Source: C:\Users\user\Desktop\SecuriteInfo.com.Trojan.GenericKDZ.73120.139.exeCode function: 2_2_01468ADD mov eax, dword ptr fs:[00000030h]2_2_01468ADD
          Source: C:\Users\user\Desktop\SecuriteInfo.com.Trojan.GenericKDZ.73120.139.exeCode function: 2_2_013952A5 mov eax, dword ptr fs:[00000030h]2_2_013952A5
          Source: C:\Users\user\Desktop\SecuriteInfo.com.Trojan.GenericKDZ.73120.139.exeCode function: 2_2_013952A5 mov eax, dword ptr fs:[00000030h]2_2_013952A5
          Source: C:\Users\user\Desktop\SecuriteInfo.com.Trojan.GenericKDZ.73120.139.exeCode function: 2_2_013952A5 mov eax, dword ptr fs:[00000030h]2_2_013952A5
          Source: C:\Users\user\Desktop\SecuriteInfo.com.Trojan.GenericKDZ.73120.139.exeCode function: 2_2_013952A5 mov eax, dword ptr fs:[00000030h]2_2_013952A5
          Source: C:\Users\user\Desktop\SecuriteInfo.com.Trojan.GenericKDZ.73120.139.exeCode function: 2_2_013952A5 mov eax, dword ptr fs:[00000030h]2_2_013952A5
          Source: C:\Users\user\Desktop\SecuriteInfo.com.Trojan.GenericKDZ.73120.139.exeCode function: 2_2_013C5AA0 mov eax, dword ptr fs:[00000030h]2_2_013C5AA0
          Source: C:\Users\user\Desktop\SecuriteInfo.com.Trojan.GenericKDZ.73120.139.exeCode function: 2_2_013C5AA0 mov eax, dword ptr fs:[00000030h]2_2_013C5AA0
          Source: C:\Users\user\Desktop\SecuriteInfo.com.Trojan.GenericKDZ.73120.139.exeCode function: 2_2_013CD294 mov eax, dword ptr fs:[00000030h]2_2_013CD294
          Source: C:\Users\user\Desktop\SecuriteInfo.com.Trojan.GenericKDZ.73120.139.exeCode function: 2_2_013CD294 mov eax, dword ptr fs:[00000030h]2_2_013CD294
          Source: C:\Users\user\Desktop\SecuriteInfo.com.Trojan.GenericKDZ.73120.139.exeCode function: 2_2_01454AEF mov eax, dword ptr fs:[00000030h]2_2_01454AEF
          Source: C:\Users\user\Desktop\SecuriteInfo.com.Trojan.GenericKDZ.73120.139.exeCode function: 2_2_01454AEF mov eax, dword ptr fs:[00000030h]2_2_01454AEF
          Source: C:\Users\user\Desktop\SecuriteInfo.com.Trojan.GenericKDZ.73120.139.exeCode function: 2_2_01454AEF mov eax, dword ptr fs:[00000030h]2_2_01454AEF
          Source: C:\Users\user\Desktop\SecuriteInfo.com.Trojan.GenericKDZ.73120.139.exeCode function: 2_2_01454AEF mov eax, dword ptr fs:[00000030h]2_2_01454AEF
          Source: C:\Users\user\Desktop\SecuriteInfo.com.Trojan.GenericKDZ.73120.139.exeCode function: 2_2_01454AEF mov eax, dword ptr fs:[00000030h]2_2_01454AEF
          Source: C:\Users\user\Desktop\SecuriteInfo.com.Trojan.GenericKDZ.73120.139.exeCode function: 2_2_01454AEF mov eax, dword ptr fs:[00000030h]2_2_01454AEF
          Source: C:\Users\user\Desktop\SecuriteInfo.com.Trojan.GenericKDZ.73120.139.exeCode function: 2_2_01454AEF mov eax, dword ptr fs:[00000030h]2_2_01454AEF
          Source: C:\Users\user\Desktop\SecuriteInfo.com.Trojan.GenericKDZ.73120.139.exeCode function: 2_2_01454AEF mov eax, dword ptr fs:[00000030h]2_2_01454AEF
          Source: C:\Users\user\Desktop\SecuriteInfo.com.Trojan.GenericKDZ.73120.139.exeCode function: 2_2_01454AEF mov eax, dword ptr fs:[00000030h]2_2_01454AEF
          Source: C:\Users\user\Desktop\SecuriteInfo.com.Trojan.GenericKDZ.73120.139.exeCode function: 2_2_01454AEF mov eax, dword ptr fs:[00000030h]2_2_01454AEF
          Source: C:\Users\user\Desktop\SecuriteInfo.com.Trojan.GenericKDZ.73120.139.exeCode function: 2_2_01454AEF mov eax, dword ptr fs:[00000030h]2_2_01454AEF
          Source: C:\Users\user\Desktop\SecuriteInfo.com.Trojan.GenericKDZ.73120.139.exeCode function: 2_2_01454AEF mov eax, dword ptr fs:[00000030h]2_2_01454AEF
          Source: C:\Users\user\Desktop\SecuriteInfo.com.Trojan.GenericKDZ.73120.139.exeCode function: 2_2_01454AEF mov eax, dword ptr fs:[00000030h]2_2_01454AEF
          Source: C:\Users\user\Desktop\SecuriteInfo.com.Trojan.GenericKDZ.73120.139.exeCode function: 2_2_01454AEF mov eax, dword ptr fs:[00000030h]2_2_01454AEF
          Source: C:\Users\user\Desktop\SecuriteInfo.com.Trojan.GenericKDZ.73120.139.exeCode function: 2_2_013CDA88 mov eax, dword ptr fs:[00000030h]2_2_013CDA88
          Source: C:\Users\user\Desktop\SecuriteInfo.com.Trojan.GenericKDZ.73120.139.exeCode function: 2_2_013CDA88 mov eax, dword ptr fs:[00000030h]2_2_013CDA88
          Source: C:\Users\user\Desktop\SecuriteInfo.com.Trojan.GenericKDZ.73120.139.exeCode function: 2_2_013C2AE4 mov eax, dword ptr fs:[00000030h]2_2_013C2AE4
          Source: C:\Users\user\Desktop\SecuriteInfo.com.Trojan.GenericKDZ.73120.139.exeCode function: 2_2_0145129A mov eax, dword ptr fs:[00000030h]2_2_0145129A
          Source: C:\Users\user\Desktop\SecuriteInfo.com.Trojan.GenericKDZ.73120.139.exeCode function: 2_2_013912D4 mov eax, dword ptr fs:[00000030h]2_2_013912D4
          Source: C:\Users\user\Desktop\SecuriteInfo.com.Trojan.GenericKDZ.73120.139.exeCode function: 2_2_01393ACA mov eax, dword ptr fs:[00000030h]2_2_01393ACA
          Source: C:\Users\user\Desktop\SecuriteInfo.com.Trojan.GenericKDZ.73120.139.exeCode function: 2_2_013C2ACB mov eax, dword ptr fs:[00000030h]2_2_013C2ACB
          Source: C:\Users\user\Desktop\SecuriteInfo.com.Trojan.GenericKDZ.73120.139.exeCode function: 2_2_01395AC0 mov eax, dword ptr fs:[00000030h]2_2_01395AC0
          Source: C:\Users\user\Desktop\SecuriteInfo.com.Trojan.GenericKDZ.73120.139.exeCode function: 2_2_01395AC0 mov eax, dword ptr fs:[00000030h]2_2_01395AC0
          Source: C:\Users\user\Desktop\SecuriteInfo.com.Trojan.GenericKDZ.73120.139.exeCode function: 2_2_01395AC0 mov eax, dword ptr fs:[00000030h]2_2_01395AC0
          Source: C:\Users\user\Desktop\SecuriteInfo.com.Trojan.GenericKDZ.73120.139.exeCode function: 2_2_01413540 mov eax, dword ptr fs:[00000030h]2_2_01413540
          Source: C:\Users\user\Desktop\SecuriteInfo.com.Trojan.GenericKDZ.73120.139.exeCode function: 2_2_01448D47 mov eax, dword ptr fs:[00000030h]2_2_01448D47
          Source: C:\Users\user\Desktop\SecuriteInfo.com.Trojan.GenericKDZ.73120.139.exeCode function: 2_2_01443D40 mov eax, dword ptr fs:[00000030h]2_2_01443D40
          Source: C:\Users\user\Desktop\SecuriteInfo.com.Trojan.GenericKDZ.73120.139.exeCode function: 2_2_013C4D3B mov eax, dword ptr fs:[00000030h]2_2_013C4D3B
          Source: C:\Users\user\Desktop\SecuriteInfo.com.Trojan.GenericKDZ.73120.139.exeCode function: 2_2_013C4D3B mov eax, dword ptr fs:[00000030h]2_2_013C4D3B
          Source: C:\Users\user\Desktop\SecuriteInfo.com.Trojan.GenericKDZ.73120.139.exeCode function: 2_2_013C4D3B mov eax, dword ptr fs:[00000030h]2_2_013C4D3B
          Source: C:\Users\user\Desktop\SecuriteInfo.com.Trojan.GenericKDZ.73120.139.exeCode function: 2_2_0139AD30 mov eax, dword ptr fs:[00000030h]2_2_0139AD30
          Source: C:\Users\user\Desktop\SecuriteInfo.com.Trojan.GenericKDZ.73120.139.exeCode function: 2_2_013A3D34 mov eax, dword ptr fs:[00000030h]2_2_013A3D34
          Source: C:\Users\user\Desktop\SecuriteInfo.com.Trojan.GenericKDZ.73120.139.exeCode function: 2_2_013A3D34 mov eax, dword ptr fs:[00000030h]2_2_013A3D34
          Source: C:\Users\user\Desktop\SecuriteInfo.com.Trojan.GenericKDZ.73120.139.exeCode function: 2_2_013A3D34 mov eax, dword ptr fs:[00000030h]2_2_013A3D34
          Source: C:\Users\user\Desktop\SecuriteInfo.com.Trojan.GenericKDZ.73120.139.exeCode function: 2_2_013A3D34 mov eax, dword ptr fs:[00000030h]2_2_013A3D34
          Source: C:\Users\user\Desktop\SecuriteInfo.com.Trojan.GenericKDZ.73120.139.exeCode function: 2_2_013A3D34 mov eax, dword ptr fs:[00000030h]2_2_013A3D34
          Source: C:\Users\user\Desktop\SecuriteInfo.com.Trojan.GenericKDZ.73120.139.exeCode function: 2_2_013A3D34 mov eax, dword ptr fs:[00000030h]2_2_013A3D34
          Source: C:\Users\user\Desktop\SecuriteInfo.com.Trojan.GenericKDZ.73120.139.exeCode function: 2_2_013A3D34 mov eax, dword ptr fs:[00000030h]2_2_013A3D34
          Source: C:\Users\user\Desktop\SecuriteInfo.com.Trojan.GenericKDZ.73120.139.exeCode function: 2_2_013A3D34 mov eax, dword ptr fs:[00000030h]2_2_013A3D34
          Source: C:\Users\user\Desktop\SecuriteInfo.com.Trojan.GenericKDZ.73120.139.exeCode function: 2_2_013A3D34 mov eax, dword ptr fs:[00000030h]2_2_013A3D34
          Source: C:\Users\user\Desktop\SecuriteInfo.com.Trojan.GenericKDZ.73120.139.exeCode function: 2_2_013A3D34 mov eax, dword ptr fs:[00000030h]2_2_013A3D34
          Source: C:\Users\user\Desktop\SecuriteInfo.com.Trojan.GenericKDZ.73120.139.exeCode function: 2_2_013A3D34 mov eax, dword ptr fs:[00000030h]2_2_013A3D34
          Source: C:\Users\user\Desktop\SecuriteInfo.com.Trojan.GenericKDZ.73120.139.exeCode function: 2_2_013A3D34 mov eax, dword ptr fs:[00000030h]2_2_013A3D34
          Source: C:\Users\user\Desktop\SecuriteInfo.com.Trojan.GenericKDZ.73120.139.exeCode function: 2_2_013A3D34 mov eax, dword ptr fs:[00000030h]2_2_013A3D34
          Source: C:\Users\user\Desktop\SecuriteInfo.com.Trojan.GenericKDZ.73120.139.exeCode function: 2_2_013CF527 mov eax, dword ptr fs:[00000030h]2_2_013CF527
          Source: C:\Users\user\Desktop\SecuriteInfo.com.Trojan.GenericKDZ.73120.139.exeCode function: 2_2_013CF527 mov eax, dword ptr fs:[00000030h]2_2_013CF527
          Source: C:\Users\user\Desktop\SecuriteInfo.com.Trojan.GenericKDZ.73120.139.exeCode function: 2_2_013CF527 mov eax, dword ptr fs:[00000030h]2_2_013CF527
          Source: C:\Users\user\Desktop\SecuriteInfo.com.Trojan.GenericKDZ.73120.139.exeCode function: 2_2_013BC577 mov eax, dword ptr fs:[00000030h]2_2_013BC577
          Source: C:\Users\user\Desktop\SecuriteInfo.com.Trojan.GenericKDZ.73120.139.exeCode function: 2_2_013BC577 mov eax, dword ptr fs:[00000030h]2_2_013BC577
          Source: C:\Users\user\Desktop\SecuriteInfo.com.Trojan.GenericKDZ.73120.139.exeCode function: 2_2_013B8D76 mov eax, dword ptr fs:[00000030h]2_2_013B8D76
          Source: C:\Users\user\Desktop\SecuriteInfo.com.Trojan.GenericKDZ.73120.139.exeCode function: 2_2_013B8D76 mov eax, dword ptr fs:[00000030h]2_2_013B8D76
          Source: C:\Users\user\Desktop\SecuriteInfo.com.Trojan.GenericKDZ.73120.139.exeCode function: 2_2_013B8D76 mov eax, dword ptr fs:[00000030h]2_2_013B8D76
          Source: C:\Users\user\Desktop\SecuriteInfo.com.Trojan.GenericKDZ.73120.139.exeCode function: 2_2_013B8D76 mov eax, dword ptr fs:[00000030h]2_2_013B8D76
          Source: C:\Users\user\Desktop\SecuriteInfo.com.Trojan.GenericKDZ.73120.139.exeCode function: 2_2_013B8D76 mov eax, dword ptr fs:[00000030h]2_2_013B8D76
          Source: C:\Users\user\Desktop\SecuriteInfo.com.Trojan.GenericKDZ.73120.139.exeCode function: 2_2_01453518 mov eax, dword ptr fs:[00000030h]2_2_01453518
          Source: C:\Users\user\Desktop\SecuriteInfo.com.Trojan.GenericKDZ.73120.139.exeCode function: 2_2_01453518 mov eax, dword ptr fs:[00000030h]2_2_01453518
          Source: C:\Users\user\Desktop\SecuriteInfo.com.Trojan.GenericKDZ.73120.139.exeCode function: 2_2_01453518 mov eax, dword ptr fs:[00000030h]2_2_01453518
          Source: C:\Users\user\Desktop\SecuriteInfo.com.Trojan.GenericKDZ.73120.139.exeCode function: 2_2_013B7D50 mov eax, dword ptr fs:[00000030h]2_2_013B7D50
          Source: C:\Users\user\Desktop\SecuriteInfo.com.Trojan.GenericKDZ.73120.139.exeCode function: 2_2_013D4D51 mov eax, dword ptr fs:[00000030h]2_2_013D4D51
          Source: C:\Users\user\Desktop\SecuriteInfo.com.Trojan.GenericKDZ.73120.139.exeCode function: 2_2_013D4D51 mov eax, dword ptr fs:[00000030h]2_2_013D4D51
          Source: C:\Users\user\Desktop\SecuriteInfo.com.Trojan.GenericKDZ.73120.139.exeCode function: 2_2_01468D34 mov eax, dword ptr fs:[00000030h]2_2_01468D34
          Source: C:\Users\user\Desktop\SecuriteInfo.com.Trojan.GenericKDZ.73120.139.exeCode function: 2_2_0139354C mov eax, dword ptr fs:[00000030h]2_2_0139354C
          Source: C:\Users\user\Desktop\SecuriteInfo.com.Trojan.GenericKDZ.73120.139.exeCode function: 2_2_0139354C mov eax, dword ptr fs:[00000030h]2_2_0139354C
          Source: C:\Users\user\Desktop\SecuriteInfo.com.Trojan.GenericKDZ.73120.139.exeCode function: 2_2_0141A537 mov eax, dword ptr fs:[00000030h]2_2_0141A537
          Source: C:\Users\user\Desktop\SecuriteInfo.com.Trojan.GenericKDZ.73120.139.exeCode function: 2_2_0145E539 mov eax, dword ptr fs:[00000030h]2_2_0145E539
          Source: C:\Users\user\Desktop\SecuriteInfo.com.Trojan.GenericKDZ.73120.139.exeCode function: 2_2_013D3D43 mov eax, dword ptr fs:[00000030h]2_2_013D3D43
          Source: C:\Users\user\Desktop\SecuriteInfo.com.Trojan.GenericKDZ.73120.139.exeCode function: 2_2_01416DC9 mov eax, dword ptr fs:[00000030h]2_2_01416DC9
          Source: C:\Users\user\Desktop\SecuriteInfo.com.Trojan.GenericKDZ.73120.139.exeCode function: 2_2_01416DC9 mov eax, dword ptr fs:[00000030h]2_2_01416DC9
          Source: C:\Users\user\Desktop\SecuriteInfo.com.Trojan.GenericKDZ.73120.139.exeCode function: 2_2_01416DC9 mov eax, dword ptr fs:[00000030h]2_2_01416DC9
          Source: C:\Users\user\Desktop\SecuriteInfo.com.Trojan.GenericKDZ.73120.139.exeCode function: 2_2_01416DC9 mov ecx, dword ptr fs:[00000030h]2_2_01416DC9
          Source: C:\Users\user\Desktop\SecuriteInfo.com.Trojan.GenericKDZ.73120.139.exeCode function: 2_2_01416DC9 mov eax, dword ptr fs:[00000030h]2_2_01416DC9
          Source: C:\Users\user\Desktop\SecuriteInfo.com.Trojan.GenericKDZ.73120.139.exeCode function: 2_2_01416DC9 mov eax, dword ptr fs:[00000030h]2_2_01416DC9
          Source: C:\Users\user\Desktop\SecuriteInfo.com.Trojan.GenericKDZ.73120.139.exeCode function: 2_2_013C1DB5 mov eax, dword ptr fs:[00000030h]2_2_013C1DB5
          Source: C:\Users\user\Desktop\SecuriteInfo.com.Trojan.GenericKDZ.73120.139.exeCode function: 2_2_013C1DB5 mov eax, dword ptr fs:[00000030h]2_2_013C1DB5
          Source: C:\Users\user\Desktop\SecuriteInfo.com.Trojan.GenericKDZ.73120.139.exeCode function: 2_2_013C1DB5 mov eax, dword ptr fs:[00000030h]2_2_013C1DB5
          Source: C:\Users\user\Desktop\SecuriteInfo.com.Trojan.GenericKDZ.73120.139.exeCode function: 2_2_0144FDD3 mov eax, dword ptr fs:[00000030h]2_2_0144FDD3
          Source: C:\Users\user\Desktop\SecuriteInfo.com.Trojan.GenericKDZ.73120.139.exeCode function: 2_2_013C65A0 mov eax, dword ptr fs:[00000030h]2_2_013C65A0
          Source: C:\Users\user\Desktop\SecuriteInfo.com.Trojan.GenericKDZ.73120.139.exeCode function: 2_2_013C65A0 mov eax, dword ptr fs:[00000030h]2_2_013C65A0
          Source: C:\Users\user\Desktop\SecuriteInfo.com.Trojan.GenericKDZ.73120.139.exeCode function: 2_2_013C65A0 mov eax, dword ptr fs:[00000030h]2_2_013C65A0
          Source: C:\Users\user\Desktop\SecuriteInfo.com.Trojan.GenericKDZ.73120.139.exeCode function: 2_2_013C35A1 mov eax, dword ptr fs:[00000030h]2_2_013C35A1
          Source: C:\Users\user\Desktop\SecuriteInfo.com.Trojan.GenericKDZ.73120.139.exeCode function: 2_2_013CFD9B mov eax, dword ptr fs:[00000030h]2_2_013CFD9B
          Source: C:\Users\user\Desktop\SecuriteInfo.com.Trojan.GenericKDZ.73120.139.exeCode function: 2_2_013CFD9B mov eax, dword ptr fs:[00000030h]2_2_013CFD9B
          Source: C:\Users\user\Desktop\SecuriteInfo.com.Trojan.GenericKDZ.73120.139.exeCode function: 2_2_0145FDE2 mov eax, dword ptr fs:[00000030h]2_2_0145FDE2
          Source: C:\Users\user\Desktop\SecuriteInfo.com.Trojan.GenericKDZ.73120.139.exeCode function: 2_2_0145FDE2 mov eax, dword ptr fs:[00000030h]2_2_0145FDE2
          Source: C:\Users\user\Desktop\SecuriteInfo.com.Trojan.GenericKDZ.73120.139.exeCode function: 2_2_0145FDE2 mov eax, dword ptr fs:[00000030h]2_2_0145FDE2
          Source: C:\Users\user\Desktop\SecuriteInfo.com.Trojan.GenericKDZ.73120.139.exeCode function: 2_2_0145FDE2 mov eax, dword ptr fs:[00000030h]2_2_0145FDE2
          Source: C:\Users\user\Desktop\SecuriteInfo.com.Trojan.GenericKDZ.73120.139.exeCode function: 2_2_01393591 mov eax, dword ptr fs:[00000030h]2_2_01393591
          Source: C:\Users\user\Desktop\SecuriteInfo.com.Trojan.GenericKDZ.73120.139.exeCode function: 2_2_01392D8A mov eax, dword ptr fs:[00000030h]2_2_01392D8A
          Source: C:\Users\user\Desktop\SecuriteInfo.com.Trojan.GenericKDZ.73120.139.exeCode function: 2_2_01392D8A mov eax, dword ptr fs:[00000030h]2_2_01392D8A
          Source: C:\Users\user\Desktop\SecuriteInfo.com.Trojan.GenericKDZ.73120.139.exeCode function: 2_2_01392D8A mov eax, dword ptr fs:[00000030h]2_2_01392D8A
          Source: C:\Users\user\Desktop\SecuriteInfo.com.Trojan.GenericKDZ.73120.139.exeCode function: 2_2_01392D8A mov eax, dword ptr fs:[00000030h]2_2_01392D8A
          Source: C:\Users\user\Desktop\SecuriteInfo.com.Trojan.GenericKDZ.73120.139.exeCode function: 2_2_01392D8A mov eax, dword ptr fs:[00000030h]2_2_01392D8A
          Source: C:\Users\user\Desktop\SecuriteInfo.com.Trojan.GenericKDZ.73120.139.exeCode function: 2_2_01448DF1 mov eax, dword ptr fs:[00000030h]2_2_01448DF1
          Source: C:\Users\user\Desktop\SecuriteInfo.com.Trojan.GenericKDZ.73120.139.exeCode function: 2_2_013C2581 mov eax, dword ptr fs:[00000030h]2_2_013C2581
          Source: C:\Users\user\Desktop\SecuriteInfo.com.Trojan.GenericKDZ.73120.139.exeCode function: 2_2_013C2581 mov eax, dword ptr fs:[00000030h]2_2_013C2581
          Source: C:\Users\user\Desktop\SecuriteInfo.com.Trojan.GenericKDZ.73120.139.exeCode function: 2_2_013C2581 mov eax, dword ptr fs:[00000030h]2_2_013C2581
          Source: C:\Users\user\Desktop\SecuriteInfo.com.Trojan.GenericKDZ.73120.139.exeCode function: 2_2_013C2581 mov eax, dword ptr fs:[00000030h]2_2_013C2581
          Source: C:\Users\user\Desktop\SecuriteInfo.com.Trojan.GenericKDZ.73120.139.exeCode function: 2_2_0145B581 mov eax, dword ptr fs:[00000030h]2_2_0145B581
          Source: C:\Users\user\Desktop\SecuriteInfo.com.Trojan.GenericKDZ.73120.139.exeCode function: 2_2_0145B581 mov eax, dword ptr fs:[00000030h]2_2_0145B581
          Source: C:\Users\user\Desktop\SecuriteInfo.com.Trojan.GenericKDZ.73120.139.exeCode function: 2_2_0145B581 mov eax, dword ptr fs:[00000030h]2_2_0145B581
          Source: C:\Users\user\Desktop\SecuriteInfo.com.Trojan.GenericKDZ.73120.139.exeCode function: 2_2_0145B581 mov eax, dword ptr fs:[00000030h]2_2_0145B581
          Source: C:\Users\user\Desktop\SecuriteInfo.com.Trojan.GenericKDZ.73120.139.exeCode function: 2_2_01452D82 mov eax, dword ptr fs:[00000030h]2_2_01452D82
          Source: C:\Users\user\Desktop\SecuriteInfo.com.Trojan.GenericKDZ.73120.139.exeCode function: 2_2_01452D82 mov eax, dword ptr fs:[00000030h]2_2_01452D82
          Source: C:\Users\user\Desktop\SecuriteInfo.com.Trojan.GenericKDZ.73120.139.exeCode function: 2_2_01452D82 mov eax, dword ptr fs:[00000030h]2_2_01452D82
          Source: C:\Users\user\Desktop\SecuriteInfo.com.Trojan.GenericKDZ.73120.139.exeCode function: 2_2_01452D82 mov eax, dword ptr fs:[00000030h]2_2_01452D82
          Source: C:\Users\user\Desktop\SecuriteInfo.com.Trojan.GenericKDZ.73120.139.exeCode function: 2_2_01452D82 mov eax, dword ptr fs:[00000030h]2_2_01452D82
          Source: C:\Users\user\Desktop\SecuriteInfo.com.Trojan.GenericKDZ.73120.139.exeCode function: 2_2_01452D82 mov eax, dword ptr fs:[00000030h]2_2_01452D82
          Source: C:\Users\user\Desktop\SecuriteInfo.com.Trojan.GenericKDZ.73120.139.exeCode function: 2_2_01452D82 mov eax, dword ptr fs:[00000030h]2_2_01452D82
          Source: C:\Users\user\Desktop\SecuriteInfo.com.Trojan.GenericKDZ.73120.139.exeCode function: 2_2_013995F0 mov eax, dword ptr fs:[00000030h]2_2_013995F0
          Source: C:\Users\user\Desktop\SecuriteInfo.com.Trojan.GenericKDZ.73120.139.exeCode function: 2_2_013995F0 mov ecx, dword ptr fs:[00000030h]2_2_013995F0
          Source: C:\Users\user\Desktop\SecuriteInfo.com.Trojan.GenericKDZ.73120.139.exeCode function: 2_2_013C95EC mov eax, dword ptr fs:[00000030h]2_2_013C95EC
          Source: C:\Users\user\Desktop\SecuriteInfo.com.Trojan.GenericKDZ.73120.139.exeCode function: 2_2_013AD5E0 mov eax, dword ptr fs:[00000030h]2_2_013AD5E0
          Source: C:\Users\user\Desktop\SecuriteInfo.com.Trojan.GenericKDZ.73120.139.exeCode function: 2_2_013AD5E0 mov eax, dword ptr fs:[00000030h]2_2_013AD5E0
          Source: C:\Users\user\Desktop\SecuriteInfo.com.Trojan.GenericKDZ.73120.139.exeCode function: 2_2_014605AC mov eax, dword ptr fs:[00000030h]2_2_014605AC
          Source: C:\Users\user\Desktop\SecuriteInfo.com.Trojan.GenericKDZ.73120.139.exeCode function: 2_2_014605AC mov eax, dword ptr fs:[00000030h]2_2_014605AC
          Source: C:\Users\user\Desktop\SecuriteInfo.com.Trojan.GenericKDZ.73120.139.exeCode function: 2_2_013915C1 mov eax, dword ptr fs:[00000030h]2_2_013915C1
          Source: C:\Users\user\Desktop\SecuriteInfo.com.Trojan.GenericKDZ.73120.139.exeCode function: 2_2_01394439 mov eax, dword ptr fs:[00000030h]2_2_01394439
          Source: C:\Users\user\Desktop\SecuriteInfo.com.Trojan.GenericKDZ.73120.139.exeCode function: 2_2_013C3C3E mov eax, dword ptr fs:[00000030h]2_2_013C3C3E
          Source: C:\Users\user\Desktop\SecuriteInfo.com.Trojan.GenericKDZ.73120.139.exeCode function: 2_2_013C3C3E mov eax, dword ptr fs:[00000030h]2_2_013C3C3E
          Source: C:\Users\user\Desktop\SecuriteInfo.com.Trojan.GenericKDZ.73120.139.exeCode function: 2_2_013C3C3E mov eax, dword ptr fs:[00000030h]2_2_013C3C3E
          Source: C:\Users\user\Desktop\SecuriteInfo.com.Trojan.GenericKDZ.73120.139.exeCode function: 2_2_013AB433 mov eax, dword ptr fs:[00000030h]2_2_013AB433
          Source: C:\Users\user\Desktop\SecuriteInfo.com.Trojan.GenericKDZ.73120.139.exeCode function: 2_2_013AB433 mov eax, dword ptr fs:[00000030h]2_2_013AB433
          Source: C:\Users\user\Desktop\SecuriteInfo.com.Trojan.GenericKDZ.73120.139.exeCode function: 2_2_013AB433 mov eax, dword ptr fs:[00000030h]2_2_013AB433
          Source: C:\Users\user\Desktop\SecuriteInfo.com.Trojan.GenericKDZ.73120.139.exeCode function: 2_2_013CBC2C mov eax, dword ptr fs:[00000030h]2_2_013CBC2C
          Source: C:\Users\user\Desktop\SecuriteInfo.com.Trojan.GenericKDZ.73120.139.exeCode function: 2_2_01468450 mov eax, dword ptr fs:[00000030h]2_2_01468450
          Source: C:\Users\user\Desktop\SecuriteInfo.com.Trojan.GenericKDZ.73120.139.exeCode function: 2_2_01468C75 mov eax, dword ptr fs:[00000030h]2_2_01468C75
          Source: C:\Users\user\Desktop\SecuriteInfo.com.Trojan.GenericKDZ.73120.139.exeCode function: 2_2_01451C06 mov eax, dword ptr fs:[00000030h]2_2_01451C06
          Source: C:\Users\user\Desktop\SecuriteInfo.com.Trojan.GenericKDZ.73120.139.exeCode function: 2_2_01451C06 mov eax, dword ptr fs:[00000030h]2_2_01451C06
          Source: C:\Users\user\Desktop\SecuriteInfo.com.Trojan.GenericKDZ.73120.139.exeCode function: 2_2_01451C06 mov eax, dword ptr fs:[00000030h]2_2_01451C06
          Source: C:\Users\user\Desktop\SecuriteInfo.com.Trojan.GenericKDZ.73120.139.exeCode function: 2_2_01451C06 mov eax, dword ptr fs:[00000030h]2_2_01451C06
          Source: C:\Users\user\Desktop\SecuriteInfo.com.Trojan.GenericKDZ.73120.139.exeCode function: 2_2_01451C06 mov eax, dword ptr fs:[00000030h]2_2_01451C06
          Source: C:\Users\user\Desktop\SecuriteInfo.com.Trojan.GenericKDZ.73120.139.exeCode function: 2_2_01451C06 mov eax, dword ptr fs:[00000030h]2_2_01451C06
          Source: C:\Users\user\Desktop\SecuriteInfo.com.Trojan.GenericKDZ.73120.139.exeCode function: 2_2_01451C06 mov eax, dword ptr fs:[00000030h]2_2_01451C06
          Source: C:\Users\user\Desktop\SecuriteInfo.com.Trojan.GenericKDZ.73120.139.exeCode function: 2_2_01451C06 mov eax, dword ptr fs:[00000030h]2_2_01451C06
          Source: C:\Users\user\Desktop\SecuriteInfo.com.Trojan.GenericKDZ.73120.139.exeCode function: 2_2_01451C06 mov eax, dword ptr fs:[00000030h]2_2_01451C06
          Source: C:\Users\user\Desktop\SecuriteInfo.com.Trojan.GenericKDZ.73120.139.exeCode function: 2_2_01451C06 mov eax, dword ptr fs:[00000030h]2_2_01451C06
          Source: C:\Users\user\Desktop\SecuriteInfo.com.Trojan.GenericKDZ.73120.139.exeCode function: 2_2_01451C06 mov eax, dword ptr fs:[00000030h]2_2_01451C06
          Source: C:\Users\user\Desktop\SecuriteInfo.com.Trojan.GenericKDZ.73120.139.exeCode function: 2_2_01451C06 mov eax, dword ptr fs:[00000030h]2_2_01451C06
          Source: C:\Users\user\Desktop\SecuriteInfo.com.Trojan.GenericKDZ.73120.139.exeCode function: 2_2_01451C06 mov eax, dword ptr fs:[00000030h]2_2_01451C06
          Source: C:\Users\user\Desktop\SecuriteInfo.com.Trojan.GenericKDZ.73120.139.exeCode function: 2_2_01451C06 mov eax, dword ptr fs:[00000030h]2_2_01451C06
          Source: C:\Users\user\Desktop\SecuriteInfo.com.Trojan.GenericKDZ.73120.139.exeCode function: 2_2_013CAC7B mov eax, dword ptr fs:[00000030h]2_2_013CAC7B
          Source: C:\Users\user\Desktop\SecuriteInfo.com.Trojan.GenericKDZ.73120.139.exeCode function: 2_2_013CAC7B mov eax, dword ptr fs:[00000030h]2_2_013CAC7B
          Source: C:\Users\user\Desktop\SecuriteInfo.com.Trojan.GenericKDZ.73120.139.exeCode function: 2_2_013CAC7B mov eax, dword ptr fs:[00000030h]2_2_013CAC7B
          Source: C:\Users\user\Desktop\SecuriteInfo.com.Trojan.GenericKDZ.73120.139.exeCode function: 2_2_013CAC7B mov eax, dword ptr fs:[00000030h]2_2_013CAC7B
          Source: C:\Users\user\Desktop\SecuriteInfo.com.Trojan.GenericKDZ.73120.139.exeCode function: 2_2_013CAC7B mov eax, dword ptr fs:[00000030h]2_2_013CAC7B
          Source: C:\Users\user\Desktop\SecuriteInfo.com.Trojan.GenericKDZ.73120.139.exeCode function: 2_2_013CAC7B mov eax, dword ptr fs:[00000030h]2_2_013CAC7B
          Source: C:\Users\user\Desktop\SecuriteInfo.com.Trojan.GenericKDZ.73120.139.exeCode function: 2_2_013CAC7B mov eax, dword ptr fs:[00000030h]2_2_013CAC7B
          Source: C:\Users\user\Desktop\SecuriteInfo.com.Trojan.GenericKDZ.73120.139.exeCode function: 2_2_013CAC7B mov eax, dword ptr fs:[00000030h]2_2_013CAC7B
          Source: C:\Users\user\Desktop\SecuriteInfo.com.Trojan.GenericKDZ.73120.139.exeCode function: 2_2_013CAC7B mov eax, dword ptr fs:[00000030h]2_2_013CAC7B
          Source: C:\Users\user\Desktop\SecuriteInfo.com.Trojan.GenericKDZ.73120.139.exeCode function: 2_2_013CAC7B mov eax, dword ptr fs:[00000030h]2_2_013CAC7B
          Source: C:\Users\user\Desktop\SecuriteInfo.com.Trojan.GenericKDZ.73120.139.exeCode function: 2_2_013CAC7B mov eax, dword ptr fs:[00000030h]2_2_013CAC7B
          Source: C:\Users\user\Desktop\SecuriteInfo.com.Trojan.GenericKDZ.73120.139.exeCode function: 2_2_0146740D mov eax, dword ptr fs:[00000030h]2_2_0146740D
          Source: C:\Users\user\Desktop\SecuriteInfo.com.Trojan.GenericKDZ.73120.139.exeCode function: 2_2_0146740D mov eax, dword ptr fs:[00000030h]2_2_0146740D
          Source: C:\Users\user\Desktop\SecuriteInfo.com.Trojan.GenericKDZ.73120.139.exeCode function: 2_2_0146740D mov eax, dword ptr fs:[00000030h]2_2_0146740D
          Source: C:\Users\user\Desktop\SecuriteInfo.com.Trojan.GenericKDZ.73120.139.exeCode function: 2_2_01416C0A mov eax, dword ptr fs:[00000030h]2_2_01416C0A
          Source: C:\Users\user\Desktop\SecuriteInfo.com.Trojan.GenericKDZ.73120.139.exeCode function: 2_2_01416C0A mov eax, dword ptr fs:[00000030h]2_2_01416C0A
          Source: C:\Users\user\Desktop\SecuriteInfo.com.Trojan.GenericKDZ.73120.139.exeCode function: 2_2_01416C0A mov eax, dword ptr fs:[00000030h]2_2_01416C0A
          Source: C:\Users\user\Desktop\SecuriteInfo.com.Trojan.GenericKDZ.73120.139.exeCode function: 2_2_01416C0A mov eax, dword ptr fs:[00000030h]2_2_01416C0A
          Source: C:\Users\user\Desktop\SecuriteInfo.com.Trojan.GenericKDZ.73120.139.exeCode function: 2_2_013BB477 mov eax, dword ptr fs:[00000030h]2_2_013BB477
          Source: C:\Users\user\Desktop\SecuriteInfo.com.Trojan.GenericKDZ.73120.139.exeCode function: 2_2_013BB477 mov eax, dword ptr fs:[00000030h]2_2_013BB477
          Source: C:\Users\user\Desktop\SecuriteInfo.com.Trojan.GenericKDZ.73120.139.exeCode function: 2_2_013BB477 mov eax, dword ptr fs:[00000030h]2_2_013BB477
          Source: C:\Users\user\Desktop\SecuriteInfo.com.Trojan.GenericKDZ.73120.139.exeCode function: 2_2_013BB477 mov eax, dword ptr fs:[00000030h]2_2_013BB477
          Source: C:\Users\user\Desktop\SecuriteInfo.com.Trojan.GenericKDZ.73120.139.exeCode function: 2_2_013BB477 mov eax, dword ptr fs:[00000030h]2_2_013BB477
          Source: C:\Users\user\Desktop\SecuriteInfo.com.Trojan.GenericKDZ.73120.139.exeCode function: 2_2_013BB477 mov eax, dword ptr fs:[00000030h]2_2_013BB477
          Source: C:\Users\user\Desktop\SecuriteInfo.com.Trojan.GenericKDZ.73120.139.exeCode function: 2_2_013BB477 mov eax, dword ptr fs:[00000030h]2_2_013BB477
          Source: C:\Users\user\Desktop\SecuriteInfo.com.Trojan.GenericKDZ.73120.139.exeCode function: 2_2_013BB477 mov eax, dword ptr fs:[00000030h]2_2_013BB477
          Source: C:\Users\user\Desktop\SecuriteInfo.com.Trojan.GenericKDZ.73120.139.exeCode function: 2_2_013BB477 mov eax, dword ptr fs:[00000030h]2_2_013BB477
          Source: C:\Users\user\Desktop\SecuriteInfo.com.Trojan.GenericKDZ.73120.139.exeCode function: 2_2_013BB477 mov eax, dword ptr fs:[00000030h]2_2_013BB477
          Source: C:\Users\user\Desktop\SecuriteInfo.com.Trojan.GenericKDZ.73120.139.exeCode function: 2_2_013BB477 mov eax, dword ptr fs:[00000030h]2_2_013BB477
          Source: C:\Users\user\Desktop\SecuriteInfo.com.Trojan.GenericKDZ.73120.139.exeCode function: 2_2_013BB477 mov eax, dword ptr fs:[00000030h]2_2_013BB477
          Source: C:\Users\user\Desktop\SecuriteInfo.com.Trojan.GenericKDZ.73120.139.exeCode function: 2_2_013D5C70 mov eax, dword ptr fs:[00000030h]2_2_013D5C70
          Source: C:\Users\user\Desktop\SecuriteInfo.com.Trojan.GenericKDZ.73120.139.exeCode function: 2_2_01468C14 mov eax, dword ptr fs:[00000030h]2_2_01468C14
          Source: C:\Users\user\Desktop\SecuriteInfo.com.Trojan.GenericKDZ.73120.139.exeCode function: 2_2_013B746D mov eax, dword ptr fs:[00000030h]2_2_013B746D
          Source: C:\Users\user\Desktop\SecuriteInfo.com.Trojan.GenericKDZ.73120.139.exeCode function: 2_2_013CA44B mov eax, dword ptr fs:[00000030h]2_2_013CA44B
          Source: C:\Users\user\Desktop\SecuriteInfo.com.Trojan.GenericKDZ.73120.139.exeCode function: 2_2_01394CB0 mov eax, dword ptr fs:[00000030h]2_2_01394CB0
          Source: C:\Users\user\Desktop\SecuriteInfo.com.Trojan.GenericKDZ.73120.139.exeCode function: 2_2_013CD4B0 mov eax, dword ptr fs:[00000030h]2_2_013CD4B0
          Source: C:\Users\user\Desktop\SecuriteInfo.com.Trojan.GenericKDZ.73120.139.exeCode function: 2_2_01468CD6 mov eax, dword ptr fs:[00000030h]2_2_01468CD6
          Source: C:\Users\user\Desktop\SecuriteInfo.com.Trojan.GenericKDZ.73120.139.exeCode function: 2_2_013A849B mov eax, dword ptr fs:[00000030h]2_2_013A849B
          Source: C:\Users\user\Desktop\SecuriteInfo.com.Trojan.GenericKDZ.73120.139.exeCode function: 2_2_0139649B mov eax, dword ptr fs:[00000030h]2_2_0139649B
          Source: C:\Users\user\Desktop\SecuriteInfo.com.Trojan.GenericKDZ.73120.139.exeCode function: 2_2_0139649B mov eax, dword ptr fs:[00000030h]2_2_0139649B
          Source: C:\Users\user\Desktop\SecuriteInfo.com.Trojan.GenericKDZ.73120.139.exeCode function: 2_2_01416CF0 mov eax, dword ptr fs:[00000030h]2_2_01416CF0
          Source: C:\Users\user\Desktop\SecuriteInfo.com.Trojan.GenericKDZ.73120.139.exeCode function: 2_2_01416CF0 mov eax, dword ptr fs:[00000030h]2_2_01416CF0
          Source: C:\Users\user\Desktop\SecuriteInfo.com.Trojan.GenericKDZ.73120.139.exeCode function: 2_2_01416CF0 mov eax, dword ptr fs:[00000030h]2_2_01416CF0
          Source: C:\Users\user\Desktop\SecuriteInfo.com.Trojan.GenericKDZ.73120.139.exeCode function: 2_2_01391480 mov eax, dword ptr fs:[00000030h]2_2_01391480
          Source: C:\Users\user\Desktop\SecuriteInfo.com.Trojan.GenericKDZ.73120.139.exeCode function: 2_2_014514FB mov eax, dword ptr fs:[00000030h]2_2_014514FB
          Source: C:\Users\user\Desktop\SecuriteInfo.com.Trojan.GenericKDZ.73120.139.exeCode function: 2_2_01454496 mov eax, dword ptr fs:[00000030h]2_2_01454496
          Source: C:\Users\user\Desktop\SecuriteInfo.com.Trojan.GenericKDZ.73120.139.exeCode function: 2_2_01454496 mov eax, dword ptr fs:[00000030h]2_2_01454496
          Source: C:\Users\user\Desktop\SecuriteInfo.com.Trojan.GenericKDZ.73120.139.exeCode function: 2_2_01454496 mov eax, dword ptr fs:[00000030h]2_2_01454496
          Source: C:\Users\user\Desktop\SecuriteInfo.com.Trojan.GenericKDZ.73120.139.exeCode function: 2_2_01454496 mov eax, dword ptr fs:[00000030h]2_2_01454496
          Source: C:\Users\user\Desktop\SecuriteInfo.com.Trojan.GenericKDZ.73120.139.exeCode function: 2_2_01454496 mov eax, dword ptr fs:[00000030h]2_2_01454496
          Source: C:\Users\user\Desktop\SecuriteInfo.com.Trojan.GenericKDZ.73120.139.exeCode function: 2_2_01454496 mov eax, dword ptr fs:[00000030h]2_2_01454496
          Source: C:\Users\user\Desktop\SecuriteInfo.com.Trojan.GenericKDZ.73120.139.exeCode function: 2_2_01454496 mov eax, dword ptr fs:[00000030h]2_2_01454496
          Source: C:\Users\user\Desktop\SecuriteInfo.com.Trojan.GenericKDZ.73120.139.exeCode function: 2_2_01454496 mov eax, dword ptr fs:[00000030h]2_2_01454496
          Source: C:\Users\user\Desktop\SecuriteInfo.com.Trojan.GenericKDZ.73120.139.exeCode function: 2_2_01454496 mov eax, dword ptr fs:[00000030h]2_2_01454496
          Source: C:\Users\user\Desktop\SecuriteInfo.com.Trojan.GenericKDZ.73120.139.exeCode function: 2_2_01454496 mov eax, dword ptr fs:[00000030h]2_2_01454496
          Source: C:\Users\user\Desktop\SecuriteInfo.com.Trojan.GenericKDZ.73120.139.exeCode function: 2_2_01454496 mov eax, dword ptr fs:[00000030h]2_2_01454496
          Source: C:\Users\user\Desktop\SecuriteInfo.com.Trojan.GenericKDZ.73120.139.exeCode function: 2_2_01454496 mov eax, dword ptr fs:[00000030h]2_2_01454496
          Source: C:\Users\user\Desktop\SecuriteInfo.com.Trojan.GenericKDZ.73120.139.exeCode function: 2_2_01454496 mov eax, dword ptr fs:[00000030h]2_2_01454496
          Source: C:\Users\user\Desktop\SecuriteInfo.com.Trojan.GenericKDZ.73120.139.exeCode function: 2_2_01392CDB mov eax, dword ptr fs:[00000030h]2_2_01392CDB
          Source: C:\Users\user\Desktop\SecuriteInfo.com.Trojan.GenericKDZ.73120.139.exeCode function: 2_2_01469CB3 mov eax, dword ptr fs:[00000030h]2_2_01469CB3
          Source: C:\Users\user\Desktop\SecuriteInfo.com.Trojan.GenericKDZ.73120.139.exeCode function: 2_2_013BB73D mov eax, dword ptr fs:[00000030h]2_2_013BB73D
          Source: C:\Users\user\Desktop\SecuriteInfo.com.Trojan.GenericKDZ.73120.139.exeCode function: 2_2_013BB73D mov eax, dword ptr fs:[00000030h]2_2_013BB73D
          Source: C:\Users\user\Desktop\SecuriteInfo.com.Trojan.GenericKDZ.73120.139.exeCode function: 2_2_01396730 mov eax, dword ptr fs:[00000030h]2_2_01396730
          Source: C:\Users\user\Desktop\SecuriteInfo.com.Trojan.GenericKDZ.73120.139.exeCode function: 2_2_01396730 mov eax, dword ptr fs:[00000030h]2_2_01396730
          Source: C:\Users\user\Desktop\SecuriteInfo.com.Trojan.GenericKDZ.73120.139.exeCode function: 2_2_01396730 mov eax, dword ptr fs:[00000030h]2_2_01396730
          Source: C:\Users\user\Desktop\SecuriteInfo.com.Trojan.GenericKDZ.73120.139.exeCode function: 2_2_013CE730 mov eax, dword ptr fs:[00000030h]2_2_013CE730
          Source: C:\Users\user\Desktop\SecuriteInfo.com.Trojan.GenericKDZ.73120.139.exeCode function: 2_2_013C3F33 mov eax, dword ptr fs:[00000030h]2_2_013C3F33
          Source: C:\Users\user\Desktop\SecuriteInfo.com.Trojan.GenericKDZ.73120.139.exeCode function: 2_2_01451751 mov eax, dword ptr fs:[00000030h]2_2_01451751
          Source: C:\Users\user\Desktop\SecuriteInfo.com.Trojan.GenericKDZ.73120.139.exeCode function: 2_2_01394F2E mov eax, dword ptr fs:[00000030h]2_2_01394F2E
          Source: C:\Users\user\Desktop\SecuriteInfo.com.Trojan.GenericKDZ.73120.139.exeCode function: 2_2_01394F2E mov eax, dword ptr fs:[00000030h]2_2_01394F2E
          Source: C:\Users\user\Desktop\SecuriteInfo.com.Trojan.GenericKDZ.73120.139.exeCode function: 2_2_01425F5F mov eax, dword ptr fs:[00000030h]2_2_01425F5F
          Source: C:\Users\user\Desktop\SecuriteInfo.com.Trojan.GenericKDZ.73120.139.exeCode function: 2_2_01425F5F mov eax, dword ptr fs:[00000030h]2_2_01425F5F
          Source: C:\Users\user\Desktop\SecuriteInfo.com.Trojan.GenericKDZ.73120.139.exeCode function: 2_2_01425F5F mov eax, dword ptr fs:[00000030h]2_2_01425F5F
          Source: C:\Users\user\Desktop\SecuriteInfo.com.Trojan.GenericKDZ.73120.139.exeCode function: 2_2_01425F5F mov eax, dword ptr fs:[00000030h]2_2_01425F5F
          Source: C:\Users\user\Desktop\SecuriteInfo.com.Trojan.GenericKDZ.73120.139.exeCode function: 2_2_01425F5F mov eax, dword ptr fs:[00000030h]2_2_01425F5F
          Source: C:\Users\user\Desktop\SecuriteInfo.com.Trojan.GenericKDZ.73120.139.exeCode function: 2_2_01468F6A mov eax, dword ptr fs:[00000030h]2_2_01468F6A
          Source: C:\Users\user\Desktop\SecuriteInfo.com.Trojan.GenericKDZ.73120.139.exeCode function: 2_2_013C4710 mov eax, dword ptr fs:[00000030h]2_2_013C4710
          Source: C:\Users\user\Desktop\SecuriteInfo.com.Trojan.GenericKDZ.73120.139.exeCode function: 2_2_013BF716 mov eax, dword ptr fs:[00000030h]2_2_013BF716
          Source: C:\Users\user\Desktop\SecuriteInfo.com.Trojan.GenericKDZ.73120.139.exeCode function: 2_2_013CA70E mov eax, dword ptr fs:[00000030h]2_2_013CA70E
          Source: C:\Users\user\Desktop\SecuriteInfo.com.Trojan.GenericKDZ.73120.139.exeCode function: 2_2_013CA70E mov eax, dword ptr fs:[00000030h]2_2_013CA70E
          Source: C:\Users\user\Desktop\SecuriteInfo.com.Trojan.GenericKDZ.73120.139.exeCode function: 2_2_0146070D mov eax, dword ptr fs:[00000030h]2_2_0146070D
          Source: C:\Users\user\Desktop\SecuriteInfo.com.Trojan.GenericKDZ.73120.139.exeCode function: 2_2_0146070D mov eax, dword ptr fs:[00000030h]2_2_0146070D
          Source: C:\Users\user\Desktop\SecuriteInfo.com.Trojan.GenericKDZ.73120.139.exeCode function: 2_2_0142FF10 mov eax, dword ptr fs:[00000030h]2_2_0142FF10
          Source: C:\Users\user\Desktop\SecuriteInfo.com.Trojan.GenericKDZ.73120.139.exeCode function: 2_2_0142FF10 mov eax, dword ptr fs:[00000030h]2_2_0142FF10
          Source: C:\Users\user\Desktop\SecuriteInfo.com.Trojan.GenericKDZ.73120.139.exeCode function: 2_2_01396F60 mov eax, dword ptr fs:[00000030h]2_2_01396F60
          Source: C:\Users\user\Desktop\SecuriteInfo.com.Trojan.GenericKDZ.73120.139.exeCode function: 2_2_01396F60 mov eax, dword ptr fs:[00000030h]2_2_01396F60
          Source: C:\Users\user\Desktop\SecuriteInfo.com.Trojan.GenericKDZ.73120.139.exeCode function: 2_2_013AFF60 mov eax, dword ptr fs:[00000030h]2_2_013AFF60
          Source: C:\Users\user\Desktop\SecuriteInfo.com.Trojan.GenericKDZ.73120.139.exeCode function: 2_2_013BE760 mov eax, dword ptr fs:[00000030h]2_2_013BE760
          Source: C:\Users\user\Desktop\SecuriteInfo.com.Trojan.GenericKDZ.73120.139.exeCode function: 2_2_013BE760 mov eax, dword ptr fs:[00000030h]2_2_013BE760
          Source: C:\Users\user\Desktop\SecuriteInfo.com.Trojan.GenericKDZ.73120.139.exeCode function: 2_2_013CDF4C mov eax, dword ptr fs:[00000030h]2_2_013CDF4C
          Source: C:\Users\user\Desktop\SecuriteInfo.com.Trojan.GenericKDZ.73120.139.exeCode function: 2_2_013AEF40 mov eax, dword ptr fs:[00000030h]2_2_013AEF40
          Source: C:\Users\user\Desktop\SecuriteInfo.com.Trojan.GenericKDZ.73120.139.exeCode function: 2_2_0139A745 mov eax, dword ptr fs:[00000030h]2_2_0139A745
          Source: C:\Users\user\Desktop\SecuriteInfo.com.Trojan.GenericKDZ.73120.139.exeCode function: 2_2_01392FB0 mov eax, dword ptr fs:[00000030h]2_2_01392FB0
          Source: C:\Users\user\Desktop\SecuriteInfo.com.Trojan.GenericKDZ.73120.139.exeCode function: 2_2_01392FB0 mov eax, dword ptr fs:[00000030h]2_2_01392FB0
          Source: C:\Users\user\Desktop\SecuriteInfo.com.Trojan.GenericKDZ.73120.139.exeMemory allocated: page read and write | page guardJump to behavior
          Source: C:\Users\user\Desktop\SecuriteInfo.com.Trojan.GenericKDZ.73120.139.exeProcess created: C:\Users\user\Desktop\SecuriteInfo.com.Trojan.GenericKDZ.73120.139.exe C:\Users\user\Desktop\SecuriteInfo.com.Trojan.GenericKDZ.73120.139.exeJump to behavior
          Source: C:\Users\user\Desktop\SecuriteInfo.com.Trojan.GenericKDZ.73120.139.exeQueries volume information: C:\Users\user\Desktop\SecuriteInfo.com.Trojan.GenericKDZ.73120.139.exe VolumeInformationJump to behavior
          Source: C:\Users\user\Desktop\SecuriteInfo.com.Trojan.GenericKDZ.73120.139.exeQueries volume information: C:\Windows\Microsoft.NET\assembly\GAC_MSIL\Microsoft.VisualBasic\v4.0_10.0.0.0__b03f5f7f11d50a3a\Microsoft.VisualBasic.dll V