Source: PHOTOCHLORINATION.exe |
Virustotal: Detection: 27% |
Perma Link |
Source: PHOTOCHLORINATION.exe |
ReversingLabs: Detection: 10% |
Source: PHOTOCHLORINATION.exe |
Joe Sandbox ML: detected |
Source: PHOTOCHLORINATION.exe |
Static PE information: LOCAL_SYMS_STRIPPED, 32BIT_MACHINE, EXECUTABLE_IMAGE, LINE_NUMS_STRIPPED, RELOCS_STRIPPED |
Source: C:\Users\user\Desktop\PHOTOCHLORINATION.exe |
Process Stats: CPU usage > 98% |
Source: C:\Users\user\Desktop\PHOTOCHLORINATION.exe |
Code function: 0_2_00409131 |
0_2_00409131 |
Source: C:\Users\user\Desktop\PHOTOCHLORINATION.exe |
Code function: 0_2_0040942D |
0_2_0040942D |
Source: C:\Users\user\Desktop\PHOTOCHLORINATION.exe |
Code function: 0_2_004094BA |
0_2_004094BA |
Source: C:\Users\user\Desktop\PHOTOCHLORINATION.exe |
Code function: 0_2_00409350 |
0_2_00409350 |
Source: C:\Users\user\Desktop\PHOTOCHLORINATION.exe |
Code function: 0_2_00427AAC |
0_2_00427AAC |
Source: PHOTOCHLORINATION.exe, 00000000.00000002.1173852011.0000000002130000.00000002.00000001.sdmp |
Binary or memory string: OriginalFilenameuser32j% vs PHOTOCHLORINATION.exe |
Source: PHOTOCHLORINATION.exe |
Static PE information: LOCAL_SYMS_STRIPPED, 32BIT_MACHINE, EXECUTABLE_IMAGE, LINE_NUMS_STRIPPED, RELOCS_STRIPPED |
Source: classification engine |
Classification label: mal84.troj.evad.winEXE@1/0@0/0 |
Source: C:\Users\user\Desktop\PHOTOCHLORINATION.exe |
File created: C:\Users\user\AppData\Local\Temp\~DF14F9078FF1501F8C.TMP |
Jump to behavior |
Source: PHOTOCHLORINATION.exe |
Static PE information: Section: .text IMAGE_SCN_MEM_EXECUTE, IMAGE_SCN_CNT_CODE, IMAGE_SCN_MEM_READ |
Source: C:\Users\user\Desktop\PHOTOCHLORINATION.exe |
Section loaded: C:\Windows\SysWOW64\msvbvm60.dll |
Jump to behavior |
Source: C:\Users\user\Desktop\PHOTOCHLORINATION.exe |
Key opened: HKEY_CURRENT_USER\Software\Policies\Microsoft\Windows\Safer\CodeIdentifiers |
Jump to behavior |
Source: PHOTOCHLORINATION.exe |
Virustotal: Detection: 27% |
Source: PHOTOCHLORINATION.exe |
ReversingLabs: Detection: 10% |
Source: Yara match |
File source: Process Memory Space: PHOTOCHLORINATION.exe PID: 3000, type: MEMORY |
Source: Yara match |
File source: Process Memory Space: PHOTOCHLORINATION.exe PID: 3000, type: MEMORY |
Source: PHOTOCHLORINATION.exe |
Static PE information: real checksum: 0x24302 should be: 0x1df4d |
Source: C:\Users\user\Desktop\PHOTOCHLORINATION.exe |
Code function: 0_2_00409131 push ecx; ret |
0_2_00409160 |
Source: C:\Users\user\Desktop\PHOTOCHLORINATION.exe |
Code function: 0_2_00407C50 pushfd ; iretd |
0_2_00407C52 |
Source: C:\Users\user\Desktop\PHOTOCHLORINATION.exe |
Code function: 0_2_00406497 push ebx; retf |
0_2_004064C5 |
Source: C:\Users\user\Desktop\PHOTOCHLORINATION.exe |
Code function: 0_2_004078A5 pushfd ; ret |
0_2_004079BA |
Source: C:\Users\user\Desktop\PHOTOCHLORINATION.exe |
Code function: 0_2_0040A0B1 push CF58EBC2h; retn 58EBh |
0_2_0040A0AD |
Source: C:\Users\user\Desktop\PHOTOCHLORINATION.exe |
Code function: 0_2_0040912A push ecx; ret |
0_2_00409130 |
Source: C:\Users\user\Desktop\PHOTOCHLORINATION.exe |
Code function: 0_2_00408DC9 push ss; retf |
0_2_00408DCA |
Source: C:\Users\user\Desktop\PHOTOCHLORINATION.exe |
Code function: 0_2_00408E4A pushfd ; iretd |
0_2_00408E4E |
Source: C:\Users\user\Desktop\PHOTOCHLORINATION.exe |
Code function: 0_2_0040660D push ebx; retf |
0_2_0040660E |
Source: C:\Users\user\Desktop\PHOTOCHLORINATION.exe |
Code function: 0_2_00407694 pushfd ; ret |
0_2_004079BA |
Source: C:\Users\user\Desktop\PHOTOCHLORINATION.exe |
Code function: 0_2_00421C71 push 39B0D224h; retf |
0_2_00421C89 |
Source: C:\Users\user\Desktop\PHOTOCHLORINATION.exe |
Code function: 0_2_004208C9 push E8D18566h; retf 0055h |
0_2_004208E5 |
Source: C:\Users\user\Desktop\PHOTOCHLORINATION.exe |
Code function: 0_2_00424CD1 push 38B0D224h; ret |
0_2_00424D09 |
Source: C:\Users\user\Desktop\PHOTOCHLORINATION.exe |
Code function: 0_2_00423515 push 38B0D224h; ret |
0_2_0042352D |
Source: C:\Users\user\Desktop\PHOTOCHLORINATION.exe |
Code function: 0_2_00423A39 push C9D38566h; retn 0004h |
0_2_00423A55 |
Source: C:\Users\user\Desktop\PHOTOCHLORINATION.exe |
Code function: 0_2_004252F9 push 39B0D224h; retf |
0_2_00425331 |
Source: C:\Users\user\Desktop\PHOTOCHLORINATION.exe |
Code function: 0_2_00421A89 push 39B0D224h; retf |
0_2_00421AA1 |
Source: C:\Users\user\Desktop\PHOTOCHLORINATION.exe |
Code function: 0_2_004227C5 push ebx; ret |
0_2_004227EA |
Source: C:\Users\user\Desktop\PHOTOCHLORINATION.exe |
Code function: 0_2_00421BF9 push 39B0D224h; retf |
0_2_00421C11 |
Source: C:\Users\user\Desktop\PHOTOCHLORINATION.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\Desktop\PHOTOCHLORINATION.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\Desktop\PHOTOCHLORINATION.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\Desktop\PHOTOCHLORINATION.exe |
Code function: 0_2_00422833 |
0_2_00422833 |
Source: C:\Users\user\Desktop\PHOTOCHLORINATION.exe |
Code function: 0_2_004228C5 |
0_2_004228C5 |
Source: C:\Users\user\Desktop\PHOTOCHLORINATION.exe |
Code function: 0_2_00422887 |
0_2_00422887 |
Source: C:\Users\user\Desktop\PHOTOCHLORINATION.exe |
Code function: 0_2_0042294B |
0_2_0042294B |
Source: C:\Users\user\Desktop\PHOTOCHLORINATION.exe |
Code function: 0_2_00422917 |
0_2_00422917 |
Source: C:\Users\user\Desktop\PHOTOCHLORINATION.exe |
Code function: 0_2_00421937 |
0_2_00421937 |
Source: C:\Users\user\Desktop\PHOTOCHLORINATION.exe |
Code function: 0_2_004229E5 |
0_2_004229E5 |
Source: C:\Users\user\Desktop\PHOTOCHLORINATION.exe |
Code function: 0_2_00422991 |
0_2_00422991 |
Source: C:\Users\user\Desktop\PHOTOCHLORINATION.exe |
Code function: 0_2_00422A61 |
0_2_00422A61 |
Source: C:\Users\user\Desktop\PHOTOCHLORINATION.exe |
Code function: 0_2_00422A1B |
0_2_00422A1B |
Source: C:\Users\user\Desktop\PHOTOCHLORINATION.exe |
Code function: 0_2_00421283 |
0_2_00421283 |
Source: C:\Users\user\Desktop\PHOTOCHLORINATION.exe |
Code function: 0_2_00421280 |
0_2_00421280 |
Source: C:\Users\user\Desktop\PHOTOCHLORINATION.exe |
Code function: 0_2_00422AB5 |
0_2_00422AB5 |
Source: C:\Users\user\Desktop\PHOTOCHLORINATION.exe |
Code function: 0_2_00421F4F |
0_2_00421F4F |
Source: C:\Users\user\Desktop\PHOTOCHLORINATION.exe |
Code function: 0_2_00422B6B |
0_2_00422B6B |
Source: C:\Users\user\Desktop\PHOTOCHLORINATION.exe |
Code function: 0_2_00421F76 |
0_2_00421F76 |
Source: C:\Users\user\Desktop\PHOTOCHLORINATION.exe |
Code function: 0_2_00422B15 |
0_2_00422B15 |
Source: C:\Users\user\Desktop\PHOTOCHLORINATION.exe |
Code function: 0_2_00421F19 |
0_2_00421F19 |
Source: C:\Users\user\Desktop\PHOTOCHLORINATION.exe |
Code function: 0_2_004227EE |
0_2_004227EE |
Source: C:\Users\user\Desktop\PHOTOCHLORINATION.exe |
Code function: 0_2_004227F1 |
0_2_004227F1 |
Source: C:\Users\user\Desktop\PHOTOCHLORINATION.exe |
Code function: 0_2_00421FA3 |
0_2_00421FA3 |
Source: C:\Users\user\Desktop\PHOTOCHLORINATION.exe |
Code function: 0_2_00422BA7 |
0_2_00422BA7 |
Source: C:\Users\user\Desktop\PHOTOCHLORINATION.exe |
RDTSC instruction interceptor: First address: 0000000000426276 second address: 0000000000426276 instructions: |
Source: PHOTOCHLORINATION.exe |
Binary or memory string: C:\PROGRAM FILES\QEMU-GA\QEMU-GA.EXE |
Source: PHOTOCHLORINATION.exe, 00000000.00000002.1172940359.0000000000420000.00000040.00000001.sdmp |
Binary or memory string: C:\PROGRAM FILES\QEMU-GA\QEMU-GA.EXEW |
Source: C:\Users\user\Desktop\PHOTOCHLORINATION.exe |
RDTSC instruction interceptor: First address: 0000000000426276 second address: 0000000000426276 instructions: |
Source: C:\Users\user\Desktop\PHOTOCHLORINATION.exe |
Code function: 0_2_00409131 rdtsc |
0_2_00409131 |
Source: all processes |
Thread injection, dropped files, key value created, disk infection and DNS query: no activity detected |
Source: PHOTOCHLORINATION.exe |
Binary or memory string: C:\Program Files\Qemu-ga\qemu-ga.exe |
Source: PHOTOCHLORINATION.exe, 00000000.00000002.1172940359.0000000000420000.00000040.00000001.sdmp |
Binary or memory string: C:\Program Files\Qemu-ga\qemu-ga.exeW |
Source: C:\Users\user\Desktop\PHOTOCHLORINATION.exe |
Process Stats: CPU usage > 90% for more than 60s |
Source: C:\Users\user\Desktop\PHOTOCHLORINATION.exe |
Code function: 0_2_00409131 rdtsc |
0_2_00409131 |
Source: C:\Users\user\Desktop\PHOTOCHLORINATION.exe |
Code function: 0_2_0042688D mov eax, dword ptr fs:[00000030h] |
0_2_0042688D |
Source: C:\Users\user\Desktop\PHOTOCHLORINATION.exe |
Code function: 0_2_00426897 mov eax, dword ptr fs:[00000030h] |
0_2_00426897 |
Source: C:\Users\user\Desktop\PHOTOCHLORINATION.exe |
Code function: 0_2_00421937 mov eax, dword ptr fs:[00000030h] |
0_2_00421937 |
Source: C:\Users\user\Desktop\PHOTOCHLORINATION.exe |
Code function: 0_2_004221C0 mov eax, dword ptr fs:[00000030h] |
0_2_004221C0 |
Source: C:\Users\user\Desktop\PHOTOCHLORINATION.exe |
Code function: 0_2_004221FB mov eax, dword ptr fs:[00000030h] |
0_2_004221FB |
Source: C:\Users\user\Desktop\PHOTOCHLORINATION.exe |
Code function: 0_2_0042327C mov eax, dword ptr fs:[00000030h] |
0_2_0042327C |
Source: C:\Users\user\Desktop\PHOTOCHLORINATION.exe |
Code function: 0_2_0042575C mov eax, dword ptr fs:[00000030h] |
0_2_0042575C |
Source: C:\Users\user\Desktop\PHOTOCHLORINATION.exe |
Code function: 0_2_00425FC9 mov eax, dword ptr fs:[00000030h] |
0_2_00425FC9 |
Source: all processes |
Thread injection, dropped files, key value created, disk infection and DNS query: no activity detected |
Source: PHOTOCHLORINATION.exe, 00000000.00000002.1173641561.0000000000CA0000.00000002.00000001.sdmp |
Binary or memory string: Program Manager |
Source: PHOTOCHLORINATION.exe, 00000000.00000002.1173641561.0000000000CA0000.00000002.00000001.sdmp |
Binary or memory string: Shell_TrayWnd |
Source: PHOTOCHLORINATION.exe, 00000000.00000002.1173641561.0000000000CA0000.00000002.00000001.sdmp |
Binary or memory string: Progman |
Source: PHOTOCHLORINATION.exe, 00000000.00000002.1173641561.0000000000CA0000.00000002.00000001.sdmp |
Binary or memory string: Progmanlock |
Source: C:\Users\user\Desktop\PHOTOCHLORINATION.exe |
Code function: 0_2_004263D9 cpuid |
0_2_004263D9 |