Loading ...

Play interactive tourEdit tour

Analysis Report Szallitasi adatok.tar

Overview

General Information

Sample Name:Szallitasi adatok.tar
Analysis ID:383998
MD5:fa2c7acf057d7ecf693cbb13fab9b1b3
SHA1:b67cd39674b6d039e235fbb9cf0272a103afa475
SHA256:1b90e29a9f49905ead7832ff25d7ba91fddeb4827d7c8ca506c6c0b6f96acda7
Infos:

Most interesting Screenshot:

Detection

AgentTesla
Score:100
Range:0 - 100
Whitelisted:false
Confidence:100%

Signatures

Found malware configuration
Multi AV Scanner detection for dropped file
Yara detected AgentTesla
Yara detected AntiVM3
.NET source code contains very large array initializations
Injects a PE file into a foreign processes
Machine Learning detection for dropped file
Queries sensitive BIOS Information (via WMI, Win32_Bios & Win32_BaseBoard, often done to detect virtual machines)
Queries sensitive network adapter information (via WMI, Win32_NetworkAdapter, often done to detect virtual machines)
Tries to detect sandboxes and other dynamic analysis tools (process name or module or function)
Tries to harvest and steal Putty / WinSCP information (sessions, passwords, etc)
Tries to harvest and steal browser information (history, passwords, etc)
Tries to harvest and steal ftp login credentials
Tries to steal Mail credentials (via file access)
Antivirus or Machine Learning detection for unpacked file
Contains functionality to access loader functionality (e.g. LdrGetProcedureAddress)
Contains long sleeps (>= 3 min)
Creates a process in suspended mode (likely to inject code)
Detected TCP or UDP traffic on non-standard ports
Detected potential crypto function
Drops PE files
Enables debug privileges
Found a high number of Window / User specific system calls (may be a loop to detect user behavior)
Found inlined nop instructions (likely shell or obfuscated code)
IP address seen in connection with other malware
May sleep (evasive loops) to hinder dynamic analysis
Monitors certain registry keys / values for changes (often done to protect autostart functionality)
PE file contains strange resources
Queries sensitive processor information (via WMI, Win32_Processor, often done to detect virtual machines)
Queries the volume information (name, serial number etc) of a device
Sample file is different than original file name gathered from version info
Uses SMTP (mail sending)
Uses code obfuscation techniques (call, push, ret)
Yara detected Credential Stealer

Classification

Startup

  • System is w10x64
  • unarchiver.exe (PID: 6880 cmdline: 'C:\Windows\SysWOW64\unarchiver.exe' 'C:\Users\user\Desktop\Szallitasi adatok.tar' MD5: DB55139D9DD29F24AE8EA8F0E5606901)
    • 7za.exe (PID: 6916 cmdline: 'C:\Windows\System32\7za.exe' x -pinfected -y -o'C:\Users\user\AppData\Local\Temp\nqvbpsxm.54s' 'C:\Users\user\Desktop\Szallitasi adatok.tar' MD5: 77E556CDFDC5C592F5C46DB4127C6F4C)
      • conhost.exe (PID: 6964 cmdline: C:\Windows\system32\conhost.exe 0xffffffff -ForceV1 MD5: EA777DEEA782E8B4D7C7C33BBF8A4496)
    • cmd.exe (PID: 7008 cmdline: 'cmd.exe' /C 'C:\Users\user\AppData\Local\Temp\nqvbpsxm.54s\Szallitasi adatok.exe' MD5: F3BDBE3BB6F734E357235F4D5898582D)
      • conhost.exe (PID: 7028 cmdline: C:\Windows\system32\conhost.exe 0xffffffff -ForceV1 MD5: EA777DEEA782E8B4D7C7C33BBF8A4496)
      • Szallitasi adatok.exe (PID: 7056 cmdline: C:\Users\user\AppData\Local\Temp\nqvbpsxm.54s\Szallitasi adatok.exe MD5: C615C5F811E05D5743CE4DD4AFAD4055)
        • Szallitasi adatok.exe (PID: 7104 cmdline: C:\Users\user\AppData\Local\Temp\nqvbpsxm.54s\Szallitasi adatok.exe MD5: C615C5F811E05D5743CE4DD4AFAD4055)
  • cleanup

Malware Configuration

Threatname: Agenttesla

{"Exfil Mode": "SMTP", "SMTP Info": "torremolinos3@copiplus.esvB&6mnT00r3mol2o17smtp.1and1.es"}

Yara Overview

Memory Dumps

SourceRuleDescriptionAuthorStrings
00000007.00000002.590323403.0000000003481000.00000004.00000001.sdmpJoeSecurity_AgentTesla_1Yara detected AgentTeslaJoe Security
    00000007.00000002.590323403.0000000003481000.00000004.00000001.sdmpJoeSecurity_CredentialStealerYara detected Credential StealerJoe Security
      00000007.00000002.586946181.0000000000402000.00000040.00000001.sdmpJoeSecurity_AgentTesla_1Yara detected AgentTeslaJoe Security
        00000006.00000002.344267324.0000000003FF6000.00000004.00000001.sdmpJoeSecurity_AgentTesla_1Yara detected AgentTeslaJoe Security
          00000006.00000002.343156984.0000000002E03000.00000004.00000001.sdmpJoeSecurity_AntiVM_3Yara detected AntiVM_3Joe Security
            Click to see the 4 entries

            Unpacked PEs

            SourceRuleDescriptionAuthorStrings
            6.2.Szallitasi adatok.exe.4086228.3.unpackJoeSecurity_AgentTesla_1Yara detected AgentTeslaJoe Security
              7.2.Szallitasi adatok.exe.400000.0.unpackJoeSecurity_AgentTesla_1Yara detected AgentTeslaJoe Security
                6.2.Szallitasi adatok.exe.4086228.3.raw.unpackJoeSecurity_AgentTesla_1Yara detected AgentTeslaJoe Security
                  6.2.Szallitasi adatok.exe.4015208.2.raw.unpackJoeSecurity_AgentTesla_1Yara detected AgentTeslaJoe Security

                    Sigma Overview

                    No Sigma rule has matched

                    Signature Overview

                    Click to jump to signature section

                    Show All Signature Results

                    AV Detection:

                    barindex
                    Found malware configurationShow sources
                    Source: 6.2.Szallitasi adatok.exe.4086228.3.unpackMalware Configuration Extractor: Agenttesla {"Exfil Mode": "SMTP", "SMTP Info": "torremolinos3@copiplus.esvB&6mnT00r3mol2o17smtp.1and1.es"}
                    Multi AV Scanner detection for dropped fileShow sources
                    Source: C:\Users\user\AppData\Local\Temp\nqvbpsxm.54s\Szallitasi adatok.exeReversingLabs: Detection: 18%
                    Machine Learning detection for dropped fileShow sources
                    Source: C:\Users\user\AppData\Local\Temp\nqvbpsxm.54s\Szallitasi adatok.exeJoe Sandbox ML: detected
                    Source: 7.2.Szallitasi adatok.exe.400000.0.unpackAvira: Label: TR/Spy.Gen8
                    Source: C:\Windows\SysWOW64\unarchiver.exeFile opened: C:\Windows\WinSxS\x86_microsoft.vc80.crt_1fc8b3b9a1e18e3b_8.0.50727.9445_none_d08c58b4442ba54f\MSVCR80.dllJump to behavior
                    Source: C:\Windows\SysWOW64\unarchiver.exeCode function: 4x nop then jmp 02EB099Bh0_2_02EB02A8
                    Source: C:\Windows\SysWOW64\unarchiver.exeCode function: 4x nop then jmp 02EB099Ah0_2_02EB02A8
                    Source: C:\Users\user\AppData\Local\Temp\nqvbpsxm.54s\Szallitasi adatok.exeCode function: 4x nop then mov dword ptr [ebp-18h], 00000000h6_2_04E697A8
                    Source: C:\Users\user\AppData\Local\Temp\nqvbpsxm.54s\Szallitasi adatok.exeCode function: 4x nop then mov dword ptr [ebp-18h], 00000000h6_2_04E69798
                    Source: C:\Users\user\AppData\Local\Temp\nqvbpsxm.54s\Szallitasi adatok.exeCode function: 4x nop then mov dword ptr [ebp-18h], 00000000h6_2_04E68288
                    Source: C:\Users\user\AppData\Local\Temp\nqvbpsxm.54s\Szallitasi adatok.exeCode function: 4x nop then mov dword ptr [ebp-18h], 00000000h6_2_04E68279
                    Source: global trafficTCP traffic: 192.168.2.6:49748 -> 212.227.15.158:587
                    Source: Joe Sandbox ViewIP Address: 212.227.15.158 212.227.15.158
                    Source: global trafficTCP traffic: 192.168.2.6:49748 -> 212.227.15.158:587
                    Source: unknownDNS traffic detected: queries for: smtp.1and1.es
                    Source: Szallitasi adatok.exe, 00000007.00000002.590323403.0000000003481000.00000004.00000001.sdmpString found in binary or memory: http://127.0.0.1:HTTP/1.1
                    Source: Szallitasi adatok.exe, 00000007.00000002.590323403.0000000003481000.00000004.00000001.sdmpString found in binary or memory: http://CpKupV.com
                    Source: Szallitasi adatok.exe, 00000007.00000002.590323403.0000000003481000.00000004.00000001.sdmpString found in binary or memory: http://DynDns.comDynDNS
                    Source: Szallitasi adatok.exe, 00000007.00000002.595705814.0000000006FA0000.00000004.00000001.sdmpString found in binary or memory: http://cacerts.geotrust.com/GeoTrustRSACA2018.crt0
                    Source: Szallitasi adatok.exe, 00000007.00000002.595705814.0000000006FA0000.00000004.00000001.sdmpString found in binary or memory: http://cdp.geotrust.com/GeoTrustRSACA2018.crl0L
                    Source: Szallitasi adatok.exe, 00000007.00000002.595705814.0000000006FA0000.00000004.00000001.sdmpString found in binary or memory: http://crl3.digicert.com/DigiCertGlobalRootCA.crl0=
                    Source: Szallitasi adatok.exe, 00000006.00000002.347842702.0000000007042000.00000004.00000001.sdmpString found in binary or memory: http://fontfabrik.com
                    Source: Szallitasi adatok.exe, 00000007.00000002.595705814.0000000006FA0000.00000004.00000001.sdmpString found in binary or memory: http://ocsp.digicert.com0B
                    Source: Szallitasi adatok.exe, 00000006.00000002.343156984.0000000002E03000.00000004.00000001.sdmp, Szallitasi adatok.exe, 00000006.00000002.343135328.0000000002DF1000.00000004.00000001.sdmpString found in binary or memory: http://schemas.xmlsoap.org/ws/2005/05/identity/claims/name
                    Source: Szallitasi adatok.exe, 00000006.00000002.343156984.0000000002E03000.00000004.00000001.sdmpString found in binary or memory: http://schemas.xmlsoap.org/ws/2005/05/identity/claims/name4
                    Source: Szallitasi adatok.exe, 00000007.00000002.592552943.00000000037DC000.00000004.00000001.sdmpString found in binary or memory: http://smtp.1and1.es
                    Source: Szallitasi adatok.exe, 00000007.00000002.595705814.0000000006FA0000.00000004.00000001.sdmpString found in binary or memory: http://status.geotrust.com0=
                    Source: Szallitasi adatok.exe, 00000007.00000002.590323403.0000000003481000.00000004.00000001.sdmp, Szallitasi adatok.exe, 00000007.00000003.544547709.00000000015E4000.00000004.00000001.sdmpString found in binary or memory: http://wjANZKRbswl5oYyv5U.com
                    Source: Szallitasi adatok.exe, 00000006.00000002.347842702.0000000007042000.00000004.00000001.sdmpString found in binary or memory: http://www.apache.org/licenses/LICENSE-2.0
                    Source: Szallitasi adatok.exe, 00000006.00000003.329128388.0000000005E61000.00000004.00000001.sdmp, Szallitasi adatok.exe, 00000006.00000003.328833893.0000000005E61000.00000004.00000001.sdmpString found in binary or memory: http://www.carterandcone.com
                    Source: Szallitasi adatok.exe, 00000006.00000003.328759345.0000000005E61000.00000004.00000001.sdmpString found in binary or memory: http://www.carterandcone.com.N
                    Source: Szallitasi adatok.exe, 00000006.00000002.347842702.0000000007042000.00000004.00000001.sdmpString found in binary or memory: http://www.carterandcone.coml
                    Source: Szallitasi adatok.exe, 00000006.00000003.328833893.0000000005E61000.00000004.00000001.sdmpString found in binary or memory: http://www.carterandcone.comn-u
                    Source: Szallitasi adatok.exe, 00000006.00000003.329128388.0000000005E61000.00000004.00000001.sdmpString found in binary or memory: http://www.carterandcone.comn-u0
                    Source: Szallitasi adatok.exe, 00000006.00000003.329128388.0000000005E61000.00000004.00000001.sdmpString found in binary or memory: http://www.carterandcone.comr
                    Source: Szallitasi adatok.exe, 00000006.00000002.347842702.0000000007042000.00000004.00000001.sdmpString found in binary or memory: http://www.fontbureau.com
                    Source: Szallitasi adatok.exe, 00000006.00000002.347842702.0000000007042000.00000004.00000001.sdmp, Szallitasi adatok.exe, 00000006.00000003.334203954.0000000005E62000.00000004.00000001.sdmpString found in binary or memory: http://www.fontbureau.com/designers
                    Source: Szallitasi adatok.exe, 00000006.00000003.330798629.0000000005E62000.00000004.00000001.sdmpString found in binary or memory: http://www.fontbureau.com/designers/
                    Source: Szallitasi adatok.exe, 00000006.00000002.347842702.0000000007042000.00000004.00000001.sdmpString found in binary or memory: http://www.fontbureau.com/designers/?
                    Source: Szallitasi adatok.exe, 00000006.00000002.347842702.0000000007042000.00000004.00000001.sdmpString found in binary or memory: http://www.fontbureau.com/designers/cabarga.htmlN
                    Source: Szallitasi adatok.exe, 00000006.00000003.330983935.0000000005E62000.00000004.00000001.sdmp, Szallitasi adatok.exe, 00000006.00000002.347842702.0000000007042000.00000004.00000001.sdmpString found in binary or memory: http://www.fontbureau.com/designers/frere-jones.html
                    Source: Szallitasi adatok.exe, 00000006.00000003.330590528.0000000005E62000.00000004.00000001.sdmpString found in binary or memory: http://www.fontbureau.com/designers/i
                    Source: Szallitasi adatok.exe, 00000006.00000002.347842702.0000000007042000.00000004.00000001.sdmpString found in binary or memory: http://www.fontbureau.com/designers8
                    Source: Szallitasi adatok.exe, 00000006.00000002.347842702.0000000007042000.00000004.00000001.sdmpString found in binary or memory: http://www.fontbureau.com/designers?
                    Source: Szallitasi adatok.exe, 00000006.00000003.330822847.0000000005E62000.00000004.00000001.sdmpString found in binary or memory: http://www.fontbureau.com/designersC
                    Source: Szallitasi adatok.exe, 00000006.00000002.347842702.0000000007042000.00000004.00000001.sdmpString found in binary or memory: http://www.fontbureau.com/designersG
                    Source: Szallitasi adatok.exe, 00000006.00000003.330822847.0000000005E62000.00000004.00000001.sdmpString found in binary or memory: http://www.fontbureau.com/designersP
                    Source: Szallitasi adatok.exe, 00000006.00000003.331212623.0000000005E62000.00000004.00000001.sdmpString found in binary or memory: http://www.fontbureau.com/designers~
                    Source: Szallitasi adatok.exe, 00000006.00000003.341878900.0000000005E3A000.00000004.00000001.sdmpString found in binary or memory: http://www.fontbureau.comaJ
                    Source: Szallitasi adatok.exe, 00000006.00000003.341878900.0000000005E3A000.00000004.00000001.sdmpString found in binary or memory: http://www.fontbureau.comasc
                    Source: Szallitasi adatok.exe, 00000006.00000002.347842702.0000000007042000.00000004.00000001.sdmpString found in binary or memory: http://www.fonts.com
                    Source: Szallitasi adatok.exe, 00000006.00000002.347842702.0000000007042000.00000004.00000001.sdmpString found in binary or memory: http://www.founder.com.cn/cn
                    Source: Szallitasi adatok.exe, 00000006.00000002.347842702.0000000007042000.00000004.00000001.sdmpString found in binary or memory: http://www.founder.com.cn/cn/bThe
                    Source: Szallitasi adatok.exe, 00000006.00000002.347842702.0000000007042000.00000004.00000001.sdmpString found in binary or memory: http://www.founder.com.cn/cn/cThe
                    Source: Szallitasi adatok.exe, 00000006.00000003.328398898.0000000005E5D000.00000004.00000001.sdmpString found in binary or memory: http://www.founder.com.cn/cna-e
                    Source: Szallitasi adatok.exe, 00000006.00000002.347842702.0000000007042000.00000004.00000001.sdmpString found in binary or memory: http://www.galapagosdesign.com/DPlease
                    Source: Szallitasi adatok.exe, 00000006.00000002.347842702.0000000007042000.00000004.00000001.sdmpString found in binary or memory: http://www.galapagosdesign.com/staff/dennis.htm
                    Source: Szallitasi adatok.exe, 00000006.00000003.328148680.0000000005E5D000.00000004.00000001.sdmpString found in binary or memory: http://www.goodfont.co.kr
                    Source: Szallitasi adatok.exe, 00000006.00000003.328148680.0000000005E5D000.00000004.00000001.sdmpString found in binary or memory: http://www.goodfont.co.kr-e
                    Source: Szallitasi adatok.exe, 00000006.00000003.329656338.0000000005E37000.00000004.00000001.sdmp, Szallitasi adatok.exe, 00000006.00000003.329458297.0000000005E34000.00000004.00000001.sdmpString found in binary or memory: http://www.jiyu-kobo.co.jp/
                    Source: Szallitasi adatok.exe, 00000006.00000003.329656338.0000000005E37000.00000004.00000001.sdmp, Szallitasi adatok.exe, 00000006.00000003.329810137.0000000005E3A000.00000004.00000001.sdmpString found in binary or memory: http://www.jiyu-kobo.co.jp//
                    Source: Szallitasi adatok.exe, 00000006.00000003.329810137.0000000005E3A000.00000004.00000001.sdmpString found in binary or memory: http://www.jiyu-kobo.co.jp/C
                    Source: Szallitasi adatok.exe, 00000006.00000003.329656338.0000000005E37000.00000004.00000001.sdmpString found in binary or memory: http://www.jiyu-kobo.co.jp/U
                    Source: Szallitasi adatok.exe, 00000006.00000003.329656338.0000000005E37000.00000004.00000001.sdmp, Szallitasi adatok.exe, 00000006.00000003.329810137.0000000005E3A000.00000004.00000001.sdmpString found in binary or memory: http://www.jiyu-kobo.co.jp/jp/
                    Source: Szallitasi adatok.exe, 00000006.00000003.329656338.0000000005E37000.00000004.00000001.sdmpString found in binary or memory: http://www.jiyu-kobo.co.jp/jp/J
                    Source: Szallitasi adatok.exe, 00000006.00000003.329810137.0000000005E3A000.00000004.00000001.sdmpString found in binary or memory: http://www.jiyu-kobo.co.jp/n
                    Source: Szallitasi adatok.exe, 00000006.00000003.329656338.0000000005E37000.00000004.00000001.sdmpString found in binary or memory: http://www.jiyu-kobo.co.jp/nb-n
                    Source: Szallitasi adatok.exe, 00000006.00000003.333277327.0000000005E61000.00000004.00000001.sdmpString found in binary or memory: http://www.monotype.
                    Source: Szallitasi adatok.exe, 00000006.00000002.347842702.0000000007042000.00000004.00000001.sdmpString found in binary or memory: http://www.sajatypeworks.com
                    Source: Szallitasi adatok.exe, 00000006.00000003.329984191.0000000005E62000.00000004.00000001.sdmpString found in binary or memory: http://www.sakkal.com
                    Source: Szallitasi adatok.exe, 00000006.00000003.328148680.0000000005E5D000.00000004.00000001.sdmpString found in binary or memory: http://www.sandoll.co.kr
                    Source: Szallitasi adatok.exe, 00000006.00000003.328148680.0000000005E5D000.00000004.00000001.sdmpString found in binary or memory: http://www.sandoll.co.kr.krt-b
                    Source: Szallitasi adatok.exe, 00000006.00000002.347842702.0000000007042000.00000004.00000001.sdmpString found in binary or memory: http://www.tiro.com
                    Source: Szallitasi adatok.exe, 00000006.00000003.329144440.0000000005E61000.00000004.00000001.sdmpString found in binary or memory: http://www.tiro.comslnt
                    Source: Szallitasi adatok.exe, 00000006.00000002.347842702.0000000007042000.00000004.00000001.sdmpString found in binary or memory: http://www.typography.netD
                    Source: Szallitasi adatok.exe, 00000006.00000003.331404258.0000000005E62000.00000004.00000001.sdmpString found in binary or memory: http://www.urwpp.de
                    Source: Szallitasi adatok.exe, 00000006.00000002.347842702.0000000007042000.00000004.00000001.sdmpString found in binary or memory: http://www.urwpp.deDPlease
                    Source: Szallitasi adatok.exe, 00000006.00000003.331404258.0000000005E62000.00000004.00000001.sdmpString found in binary or memory: http://www.urwpp.derT
                    Source: Szallitasi adatok.exe, 00000006.00000002.347842702.0000000007042000.00000004.00000001.sdmpString found in binary or memory: http://www.zhongyicts.com.cn
                    Source: Szallitasi adatok.exe, 00000006.00000003.328730706.0000000005E61000.00000004.00000001.sdmpString found in binary or memory: http://www.zhongyicts.com.cna
                    Source: Szallitasi adatok.exe, Szallitasi adatok.exe, 00000007.00000000.340920875.0000000000F82000.00000002.00020000.sdmp, Szallitasi adatok.tarString found in binary or memory: https://dist.nuget.org/win-x86-commandline/latest/nuget.exe
                    Source: Szallitasi adatok.exe, Szallitasi adatok.tarString found in binary or memory: https://github.com/Spegeli/Pokemon-Go-Rocket-API/archive/master.zip
                    Source: Szallitasi adatok.exe, Szallitasi adatok.exe, 00000007.00000000.340920875.0000000000F82000.00000002.00020000.sdmp, Szallitasi adatok.tarString found in binary or memory: https://github.com/d-haxton/HaxtonBot/archive/master.zip
                    Source: Szallitasi adatok.exe, 00000006.00000002.343156984.0000000002E03000.00000004.00000001.sdmpString found in binary or memory: https://stackpath.bootstrapcdn.com/bootstrap/4.5.0/css/bootstrap.min.css
                    Source: Szallitasi adatok.exe, 00000007.00000002.595705814.0000000006FA0000.00000004.00000001.sdmpString found in binary or memory: https://www.digicert.com/CPS0
                    Source: Szallitasi adatok.exe, 00000006.00000002.344267324.0000000003FF6000.00000004.00000001.sdmp, Szallitasi adatok.exe, 00000007.00000002.586946181.0000000000402000.00000040.00000001.sdmpString found in binary or memory: https://www.theonionrouter.com/dist.torproject.org/torbrowser/9.5.3/tor-win32-0.4.3.6.zip
                    Source: Szallitasi adatok.exe, 00000007.00000002.590323403.0000000003481000.00000004.00000001.sdmpString found in binary or memory: https://www.theonionrouter.com/dist.torproject.org/torbrowser/9.5.3/tor-win32-0.4.3.6.zip%tordir%%ha

                    System Summary:

                    barindex
                    .NET source code contains very large array initializationsShow sources
                    Source: 7.2.Szallitasi adatok.exe.400000.0.unpack, u003cPrivateImplementationDetailsu003eu007bEC539FFCu002dC2DEu002d4D49u002d9C7Du002d51A304EDDE69u007d/DB0019FBu002dD56Eu002d4258u002d8DEFu002dF1840779C330.csLarge array initialization: .cctor: array initializer size 11940
                    Source: C:\Windows\SysWOW64\unarchiver.exeCode function: 0_2_02EB02A80_2_02EB02A8
                    Source: C:\Windows\SysWOW64\unarchiver.exeCode function: 0_2_02EB02990_2_02EB0299
                    Source: C:\Users\user\AppData\Local\Temp\nqvbpsxm.54s\Szallitasi adatok.exeCode function: 6_2_00A320506_2_00A32050
                    Source: C:\Users\user\AppData\Local\Temp\nqvbpsxm.54s\Szallitasi adatok.exeCode function: 6_2_014C94A86_2_014C94A8
                    Source: C:\Users\user\AppData\Local\Temp\nqvbpsxm.54s\Szallitasi adatok.exeCode function: 6_2_014CDCF46_2_014CDCF4
                    Source: C:\Users\user\AppData\Local\Temp\nqvbpsxm.54s\Szallitasi adatok.exeCode function: 6_2_014CC1486_2_014CC148
                    Source: C:\Users\user\AppData\Local\Temp\nqvbpsxm.54s\Szallitasi adatok.exeCode function: 6_2_014CE2186_2_014CE218
                    Source: C:\Users\user\AppData\Local\Temp\nqvbpsxm.54s\Szallitasi adatok.exeCode function: 6_2_014CA7486_2_014CA748
                    Source: C:\Users\user\AppData\Local\Temp\nqvbpsxm.54s\Szallitasi adatok.exeCode function: 6_2_04E600406_2_04E60040
                    Source: C:\Users\user\AppData\Local\Temp\nqvbpsxm.54s\Szallitasi adatok.exeCode function: 6_2_04E621306_2_04E62130
                    Source: C:\Users\user\AppData\Local\Temp\nqvbpsxm.54s\Szallitasi adatok.exeCode function: 6_2_04E61C306_2_04E61C30
                    Source: C:\Users\user\AppData\Local\Temp\nqvbpsxm.54s\Szallitasi adatok.exeCode function: 6_2_04E65AF56_2_04E65AF5
                    Source: C:\Users\user\AppData\Local\Temp\nqvbpsxm.54s\Szallitasi adatok.exeCode function: 6_2_04E654A86_2_04E654A8
                    Source: C:\Users\user\AppData\Local\Temp\nqvbpsxm.54s\Szallitasi adatok.exeCode function: 6_2_04E654B86_2_04E654B8
                    Source: C:\Users\user\AppData\Local\Temp\nqvbpsxm.54s\Szallitasi adatok.exeCode function: 6_2_04E600066_2_04E60006
                    Source: C:\Users\user\AppData\Local\Temp\nqvbpsxm.54s\Szallitasi adatok.exeCode function: 6_2_04E630076_2_04E63007
                    Source: C:\Users\user\AppData\Local\Temp\nqvbpsxm.54s\Szallitasi adatok.exeCode function: 6_2_04E610176_2_04E61017
                    Source: C:\Users\user\AppData\Local\Temp\nqvbpsxm.54s\Szallitasi adatok.exeCode function: 6_2_04E630186_2_04E63018
                    Source: C:\Users\user\AppData\Local\Temp\nqvbpsxm.54s\Szallitasi adatok.exeCode function: 6_2_04E621206_2_04E62120
                    Source: C:\Users\user\AppData\Local\Temp\nqvbpsxm.54s\Szallitasi adatok.exeCode function: 6_2_04E61C216_2_04E61C21
                    Source: C:\Users\user\AppData\Local\Temp\nqvbpsxm.54s\Szallitasi adatok.exeCode function: 6_2_04E60EE06_2_04E60EE0
                    Source: C:\Users\user\AppData\Local\Temp\nqvbpsxm.54s\Szallitasi adatok.exeCode function: 6_2_04E60ED86_2_04E60ED8
                    Source: C:\Users\user\AppData\Local\Temp\nqvbpsxm.54s\Szallitasi adatok.exeCode function: 7_2_00F820507_2_00F82050
                    Source: C:\Users\user\AppData\Local\Temp\nqvbpsxm.54s\Szallitasi adatok.exeCode function: 7_2_017F20207_2_017F2020
                    Source: C:\Users\user\AppData\Local\Temp\nqvbpsxm.54s\Szallitasi adatok.exeCode function: 7_2_017FAB707_2_017FAB70
                    Source: C:\Users\user\AppData\Local\Temp\nqvbpsxm.54s\Szallitasi adatok.exeCode function: 7_2_017F26187_2_017F2618
                    Source: C:\Users\user\AppData\Local\Temp\nqvbpsxm.54s\Szallitasi adatok.exeCode function: 7_2_017FC3787_2_017FC378
                    Source: C:\Users\user\AppData\Local\Temp\nqvbpsxm.54s\Szallitasi adatok.exeCode function: 7_2_018390007_2_01839000
                    Source: C:\Users\user\AppData\Local\Temp\nqvbpsxm.54s\Szallitasi adatok.exeCode function: 7_2_018338007_2_01833800
                    Source: C:\Users\user\AppData\Local\Temp\nqvbpsxm.54s\Szallitasi adatok.exeCode function: 7_2_018377A07_2_018377A0
                    Source: C:\Users\user\AppData\Local\Temp\nqvbpsxm.54s\Szallitasi adatok.exeCode function: 7_2_01831AE07_2_01831AE0
                    Source: C:\Users\user\AppData\Local\Temp\nqvbpsxm.54s\Szallitasi adatok.exeCode function: 7_2_018311087_2_01831108
                    Source: C:\Users\user\AppData\Local\Temp\nqvbpsxm.54s\Szallitasi adatok.exeCode function: 7_2_018388207_2_01838820
                    Source: C:\Users\user\AppData\Local\Temp\nqvbpsxm.54s\Szallitasi adatok.exeCode function: 7_2_0183C7C87_2_0183C7C8
                    Source: C:\Users\user\AppData\Local\Temp\nqvbpsxm.54s\Szallitasi adatok.exeCode function: 7_2_0183A3707_2_0183A370
                    Source: C:\Users\user\AppData\Local\Temp\nqvbpsxm.54s\Szallitasi adatok.exeCode function: 7_2_0183F2047_2_0183F204
                    Source: C:\Users\user\AppData\Local\Temp\nqvbpsxm.54s\Szallitasi adatok.exeCode function: 7_2_0183BA507_2_0183BA50
                    Source: C:\Users\user\AppData\Local\Temp\nqvbpsxm.54s\Szallitasi adatok.exeCode function: 7_2_0188F3C07_2_0188F3C0
                    Source: C:\Users\user\AppData\Local\Temp\nqvbpsxm.54s\Szallitasi adatok.exeCode function: 7_2_0188B7D47_2_0188B7D4
                    Source: C:\Users\user\AppData\Local\Temp\nqvbpsxm.54s\Szallitasi adatok.exeCode function: 7_2_01885D407_2_01885D40
                    Source: C:\Users\user\AppData\Local\Temp\nqvbpsxm.54s\Szallitasi adatok.exeCode function: 7_2_018800407_2_01880040
                    Source: C:\Users\user\AppData\Local\Temp\nqvbpsxm.54s\Szallitasi adatok.exeCode function: 7_2_018871F07_2_018871F0
                    Source: C:\Users\user\AppData\Local\Temp\nqvbpsxm.54s\Szallitasi adatok.exeCode function: 7_2_0188A7407_2_0188A740
                    Source: C:\Users\user\AppData\Local\Temp\nqvbpsxm.54s\Szallitasi adatok.exeCode function: 7_2_018891807_2_01889180
                    Source: C:\Users\user\AppData\Local\Temp\nqvbpsxm.54s\Szallitasi adatok.exeCode function: 7_2_018800147_2_01880014
                    Source: Szallitasi adatok.exe.2.drStatic PE information: Resource name: RT_ICON type: GLS_BINARY_LSB_FIRST
                    Source: Szallitasi adatok.tarBinary or memory string: OriginalFilenameIsByValue.exeD vs Szallitasi adatok.tar
                    Source: Szallitasi adatok.exe.2.drStatic PE information: Section: .text IMAGE_SCN_MEM_EXECUTE, IMAGE_SCN_CNT_CODE, IMAGE_SCN_MEM_READ
                    Source: 7.2.Szallitasi adatok.exe.400000.0.unpack, A/b2.csCryptographic APIs: 'TransformFinalBlock', 'CreateDecryptor'
                    Source: 7.2.Szallitasi adatok.exe.400000.0.unpack, A/b2.csCryptographic APIs: 'TransformFinalBlock', 'CreateDecryptor'
                    Source: classification engineClassification label: mal100.troj.spyw.evad.winTAR@11/4@1/1
                    Source: C:\Users\user\AppData\Local\Temp\nqvbpsxm.54s\Szallitasi adatok.exeFile created: C:\Users\user\AppData\Local\Microsoft\CLR_v4.0_32\UsageLogs\Szallitasi adatok.exe.logJump to behavior
                    Source: C:\Windows\System32\conhost.exeMutant created: \Sessions\1\BaseNamedObjects\Local\SM0:6964:120:WilError_01
                    Source: C:\Windows\System32\conhost.exeMutant created: \Sessions\1\BaseNamedObjects\Local\SM0:7028:120:WilError_01
                    Source: C:\Windows\SysWOW64\unarchiver.exeFile created: C:\Users\user\AppData\Local\Temp\mcgybaxf.vdbJump to behavior
                    Source: C:\Windows\SysWOW64\unarchiver.exeSection loaded: C:\Windows\assembly\NativeImages_v2.0.50727_32\mscorlib\9603718106bd57ecfbb18fefd769cab4\mscorlib.ni.dllJump to behavior
                    Source: C:\Windows\SysWOW64\unarchiver.exeSection loaded: C:\Windows\assembly\GAC_32\mscorlib\2.0.0.0__b77a5c561934e089\sorttbls.nlpJump to behavior
                    Source: C:\Windows\SysWOW64\unarchiver.exeSection loaded: C:\Windows\assembly\GAC_32\mscorlib\2.0.0.0__b77a5c561934e089\sortkey.nlpJump to behavior
                    Source: C:\Users\user\AppData\Local\Temp\nqvbpsxm.54s\Szallitasi adatok.exeSection loaded: C:\Windows\assembly\NativeImages_v4.0.30319_32\mscorlib\a152fe02a317a77aeee36903305e8ba6\mscorlib.ni.dllJump to behavior
                    Source: C:\Users\user\AppData\Local\Temp\nqvbpsxm.54s\Szallitasi adatok.exeSection loaded: C:\Windows\assembly\NativeImages_v4.0.30319_32\mscorlib\a152fe02a317a77aeee36903305e8ba6\mscorlib.ni.dllJump to behavior
                    Source: C:\Users\user\AppData\Local\Temp\nqvbpsxm.54s\Szallitasi adatok.exeWMI Queries: IWbemServices::CreateInstanceEnum - root\cimv2 : Win32_Processor
                    Source: C:\Users\user\AppData\Local\Temp\nqvbpsxm.54s\Szallitasi adatok.exeWMI Queries: IWbemServices::ExecQuery - root\cimv2 : SELECT * FROM Win32_Processor
                    Source: C:\Windows\SysWOW64\unarchiver.exeKey opened: HKEY_CURRENT_USER\Software\Policies\Microsoft\Windows\Safer\CodeIdentifiersJump to behavior
                    Source: C:\Users\user\AppData\Local\Temp\nqvbpsxm.54s\Szallitasi adatok.exeFile read: C:\Windows\System32\drivers\etc\hostsJump to behavior
                    Source: C:\Users\user\AppData\Local\Temp\nqvbpsxm.54s\Szallitasi adatok.exeFile read: C:\Windows\System32\drivers\etc\hostsJump to behavior
                    Source: Szallitasi adatok.exe, 00000006.00000002.343156984.0000000002E03000.00000004.00000001.sdmpBinary or memory string: Select * from UnmanagedMemoryStreamWrapper WHERE modelo=@modelo;?
                    Source: Szallitasi adatok.exe, 00000006.00000002.343156984.0000000002E03000.00000004.00000001.sdmpBinary or memory string: Select * from Clientes WHERE id=@id;;
                    Source: Szallitasi adatok.exe, 00000006.00000002.343156984.0000000002E03000.00000004.00000001.sdmpBinary or memory string: Select * from Aluguel5Erro ao listar Banco sql-UnmanagedMemoryStreamWrapper.INSERT INTO Aluguel VALUES(@clienteID, @data);
                    Source: Szallitasi adatok.exe, 00000006.00000002.343156984.0000000002E03000.00000004.00000001.sdmpBinary or memory string: INSERT INTO UnmanagedMemoryStreamWrapper VALUES(@modelo, @fabricante, @ano, @cor);
                    Source: Szallitasi adatok.exe, 00000006.00000002.343156984.0000000002E03000.00000004.00000001.sdmpBinary or memory string: INSERT INTO Itens_Aluguel VALUES(@aluguelID, @aviaoID, @validade);
                    Source: Szallitasi adatok.exe, 00000006.00000002.343156984.0000000002E03000.00000004.00000001.sdmpBinary or memory string: Insert into Clientes values (@nome, @cpf, @rg, @cidade, @endereco, @uf, @telefone);
                    Source: Szallitasi adatok.exe, 00000006.00000002.343156984.0000000002E03000.00000004.00000001.sdmpBinary or memory string: INSERT INTO Aluguel VALUES(@clienteID, @data);
                    Source: unknownProcess created: C:\Windows\SysWOW64\unarchiver.exe 'C:\Windows\SysWOW64\unarchiver.exe' 'C:\Users\user\Desktop\Szallitasi adatok.tar'
                    Source: C:\Windows\SysWOW64\unarchiver.exeProcess created: C:\Windows\SysWOW64\7za.exe 'C:\Windows\System32\7za.exe' x -pinfected -y -o'C:\Users\user\AppData\Local\Temp\nqvbpsxm.54s' 'C:\Users\user\Desktop\Szallitasi adatok.tar'
                    Source: C:\Windows\SysWOW64\7za.exeProcess created: C:\Windows\System32\conhost.exe C:\Windows\system32\conhost.exe 0xffffffff -ForceV1
                    Source: C:\Windows\SysWOW64\unarchiver.exeProcess created: C:\Windows\SysWOW64\cmd.exe 'cmd.exe' /C 'C:\Users\user\AppData\Local\Temp\nqvbpsxm.54s\Szallitasi adatok.exe'
                    Source: C:\Windows\SysWOW64\cmd.exeProcess created: C:\Windows\System32\conhost.exe C:\Windows\system32\conhost.exe 0xffffffff -ForceV1
                    Source: C:\Windows\SysWOW64\cmd.exeProcess created: C:\Users\user\AppData\Local\Temp\nqvbpsxm.54s\Szallitasi adatok.exe C:\Users\user\AppData\Local\Temp\nqvbpsxm.54s\Szallitasi adatok.exe
                    Source: C:\Users\user\AppData\Local\Temp\nqvbpsxm.54s\Szallitasi adatok.exeProcess created: C:\Users\user\AppData\Local\Temp\nqvbpsxm.54s\Szallitasi adatok.exe C:\Users\user\AppData\Local\Temp\nqvbpsxm.54s\Szallitasi adatok.exe
                    Source: C:\Windows\SysWOW64\unarchiver.exeProcess created: C:\Windows\SysWOW64\7za.exe 'C:\Windows\System32\7za.exe' x -pinfected -y -o'C:\Users\user\AppData\Local\Temp\nqvbpsxm.54s' 'C:\Users\user\Desktop\Szallitasi adatok.tar'Jump to behavior
                    Source: C:\Windows\SysWOW64\unarchiver.exeProcess created: C:\Windows\SysWOW64\cmd.exe 'cmd.exe' /C 'C:\Users\user\AppData\Local\Temp\nqvbpsxm.54s\Szallitasi adatok.exe'Jump to behavior
                    Source: C:\Windows\SysWOW64\cmd.exeProcess created: C:\Users\user\AppData\Local\Temp\nqvbpsxm.54s\Szallitasi adatok.exe C:\Users\user\AppData\Local\Temp\nqvbpsxm.54s\Szallitasi adatok.exeJump to behavior
                    Source: C:\Users\user\AppData\Local\Temp\nqvbpsxm.54s\Szallitasi adatok.exeProcess created: C:\Users\user\AppData\Local\Temp\nqvbpsxm.54s\Szallitasi adatok.exe C:\Users\user\AppData\Local\Temp\nqvbpsxm.54s\Szallitasi adatok.exeJump to behavior
                    Source: C:\Users\user\AppData\Local\Temp\nqvbpsxm.54s\Szallitasi adatok.exeKey value queried: HKEY_LOCAL_MACHINE\SOFTWARE\Classes\WOW6432Node\CLSID\{172BDDF8-CEEA-11D1-8B05-00600806D9B6}\InProcServer32Jump to behavior
                    Source: C:\Users\user\AppData\Local\Temp\nqvbpsxm.54s\Szallitasi adatok.exeFile opened: C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscorrc.dllJump to behavior
                    Source: C:\Users\user\AppData\Local\Temp\nqvbpsxm.54s\Szallitasi adatok.exeKey opened: HKEY_CURRENT_USER\Software\Microsoft\Office\15.0\Outlook\Profiles\Outlook\9375CFF0413111d3B88A00104B2A6676Jump to behavior
                    Source: C:\Windows\SysWOW64\unarchiver.exeFile opened: C:\Windows\WinSxS\x86_microsoft.vc80.crt_1fc8b3b9a1e18e3b_8.0.50727.9445_none_d08c58b4442ba54f\MSVCR80.dllJump to behavior
                    Source: C:\Users\user\AppData\Local\Temp\nqvbpsxm.54s\Szallitasi adatok.exeCode function: 6_2_00A48507 push dword ptr [esi+3Fh]; iretd 6_2_00A48519
                    Source: C:\Users\user\AppData\Local\Temp\nqvbpsxm.54s\Szallitasi adatok.exeCode function: 6_2_00A35683 push es; retf 6_2_00A35684
                    Source: C:\Users\user\AppData\Local\Temp\nqvbpsxm.54s\Szallitasi adatok.exeCode function: 6_2_00A49273 push FFFFFFD9h; iretd 6_2_00A49290
                    Source: C:\Users\user\AppData\Local\Temp\nqvbpsxm.54s\Szallitasi adatok.exeCode function: 7_2_00F98507 push dword ptr [esi+3Fh]; iretd 7_2_00F98519
                    Source: C:\Users\user\AppData\Local\Temp\nqvbpsxm.54s\Szallitasi adatok.exeCode function: 7_2_00F85683 push es; retf 7_2_00F85684
                    Source: C:\Users\user\AppData\Local\Temp\nqvbpsxm.54s\Szallitasi adatok.exeCode function: 7_2_017F7A37 push edi; retn 0000h7_2_017F7A39
                    Source: C:\Users\user\AppData\Local\Temp\nqvbpsxm.54s\Szallitasi adatok.exeCode function: 7_2_018368AB push FFFFFF8Bh; iretd 7_2_018368AF
                    Source: C:\Users\user\AppData\Local\Temp\nqvbpsxm.54s\Szallitasi adatok.exeCode function: 7_2_01836433 pushad ; retf 7_2_0183643D
                    Source: C:\Users\user\AppData\Local\Temp\nqvbpsxm.54s\Szallitasi adatok.exeCode function: 7_2_0183683D push FFFFFF8Bh; iretd 7_2_01836841
                    Source: C:\Users\user\AppData\Local\Temp\nqvbpsxm.54s\Szallitasi adatok.exeCode function: 7_2_018367C7 push FFFFFF8Bh; iretd 7_2_018367D9
                    Source: initial sampleStatic PE information: section name: .text entropy: 7.53444175386
                    Source: C:\Windows\SysWOW64\7za.exeFile created: C:\Users\user\AppData\Local\Temp\nqvbpsxm.54s\Szallitasi adatok.exeJump to dropped file
                    Source: C:\Users\user\AppData\Local\Temp\nqvbpsxm.54s\Szallitasi adatok.exeRegistry key monitored for changes: HKEY_CURRENT_USER_ClassesJump to behavior
                    Source: C:\Windows\SysWOW64\unarchiver.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
                    Source: C:\Windows\SysWOW64\unarchiver.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
                    Source: C:\Windows\SysWOW64\unarchiver.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
                    Source: C:\Windows\SysWOW64\unarchiver.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
                    Source: C:\Windows\SysWOW64\unarchiver.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
                    Source: C:\Windows\SysWOW64\unarchiver.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
                    Source: C:\Windows\SysWOW64\unarchiver.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
                    Source: C:\Windows\SysWOW64\unarchiver.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
                    Source: C:\Windows\SysWOW64\unarchiver.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
                    Source: C:\Windows\SysWOW64\unarchiver.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
                    Source: C:\Windows\SysWOW64\unarchiver.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
                    Source: C:\Windows\SysWOW64\unarchiver.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
                    Source: C:\Windows\SysWOW64\unarchiver.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
                    Source: C:\Windows\SysWOW64\unarchiver.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
                    Source: C:\Windows\SysWOW64\unarchiver.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
                    Source: C:\Windows\SysWOW64\unarchiver.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
                    Source: C:\Windows\SysWOW64\unarchiver.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
                    Source: C:\Users\user\AppData\Local\Temp\nqvbpsxm.54s\Szallitasi adatok.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
                    Source: C:\Users\user\AppData\Local\Temp\nqvbpsxm.54s\Szallitasi adatok.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
                    Source: C:\Users\user\AppData\Local\Temp\nqvbpsxm.54s\Szallitasi adatok.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
                    Source: C:\Users\user\AppData\Local\Temp\nqvbpsxm.54s\Szallitasi adatok.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
                    Source: C:\Users\user\AppData\Local\Temp\nqvbpsxm.54s\Szallitasi adatok.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
                    Source: C:\Users\user\AppData\Local\Temp\nqvbpsxm.54s\Szallitasi adatok.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
                    Source: C:\Users\user\AppData\Local\Temp\nqvbpsxm.54s\Szallitasi adatok.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
                    Source: C:\Users\user\AppData\Local\Temp\nqvbpsxm.54s\Szallitasi adatok.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
                    Source: C:\Users\user\AppData\Local\Temp\nqvbpsxm.54s\Szallitasi adatok.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
                    Source: C:\Users\user\AppData\Local\Temp\nqvbpsxm.54s\Szallitasi adatok.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
                    Source: C:\Users\user\AppData\Local\Temp\nqvbpsxm.54s\Szallitasi adatok.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
                    Source: C:\Users\user\AppData\Local\Temp\nqvbpsxm.54s\Szallitasi adatok.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
                    Source: C:\Users\user\AppData\Local\Temp\nqvbpsxm.54s\Szallitasi adatok.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
                    Source: C:\Users\user\AppData\Local\Temp\nqvbpsxm.54s\Szallitasi adatok.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
                    Source: C:\Users\user\AppData\Local\Temp\nqvbpsxm.54s\Szallitasi adatok.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
                    Source: C:\Users\user\AppData\Local\Temp\nqvbpsxm.54s\Szallitasi adatok.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
                    Source: C:\Users\user\AppData\Local\Temp\nqvbpsxm.54s\Szallitasi adatok.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
                    Source: C:\Users\user\AppData\Local\Temp\nqvbpsxm.54s\Szallitasi adatok.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
                    Source: C:\Users\user\AppData\Local\Temp\nqvbpsxm.54s\Szallitasi adatok.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
                    Source: C:\Users\user\AppData\Local\Temp\nqvbpsxm.54s\Szallitasi adatok.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
                    Source: C:\Users\user\AppData\Local\Temp\nqvbpsxm.54s\Szallitasi adatok.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
                    Source: C:\Users\user\AppData\Local\Temp\nqvbpsxm.54s\Szallitasi adatok.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
                    Source: C:\Users\user\AppData\Local\Temp\nqvbpsxm.54s\Szallitasi adatok.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
                    Source: C:\Users\user\AppData\Local\Temp\nqvbpsxm.54s\Szallitasi adatok.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
                    Source: C:\Users\user\AppData\Local\Temp\nqvbpsxm.54s\Szallitasi adatok.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
                    Source: C:\Users\user\AppData\Local\Temp\nqvbpsxm.54s\Szallitasi adatok.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
                    Source: C:\Users\user\AppData\Local\Temp\nqvbpsxm.54s\Szallitasi adatok.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
                    Source: C:\Users\user\AppData\Local\Temp\nqvbpsxm.54s\Szallitasi adatok.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
                    Source: C:\Users\user\AppData\Local\Temp\nqvbpsxm.54s\Szallitasi adatok.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
                    Source: C:\Users\user\AppData\Local\Temp\nqvbpsxm.54s\Szallitasi adatok.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
                    Source: C:\Users\user\AppData\Local\Temp\nqvbpsxm.54s\Szallitasi adatok.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
                    Source: C:\Users\user\AppData\Local\Temp\nqvbpsxm.54s\Szallitasi adatok.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
                    Source: C:\Users\user\AppData\Local\Temp\nqvbpsxm.54s\Szallitasi adatok.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
                    Source: C:\Users\user\AppData\Local\Temp\nqvbpsxm.54s\Szallitasi adatok.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
                    Source: C:\Users\user\AppData\Local\Temp\nqvbpsxm.54s\Szallitasi adatok.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
                    Source: C:\Users\user\AppData\Local\Temp\nqvbpsxm.54s\Szallitasi adatok.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
                    Source: C:\Users\user\AppData\Local\Temp\nqvbpsxm.54s\Szallitasi adatok.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
                    Source: C:\Users\user\AppData\Local\Temp\nqvbpsxm.54s\Szallitasi adatok.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
                    Source: C:\Users\user\AppData\Local\Temp\nqvbpsxm.54s\Szallitasi adatok.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
                    Source: C:\Users\user\AppData\Local\Temp\nqvbpsxm.54s\Szallitasi adatok.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
                    Source: C:\Users\user\AppData\Local\Temp\nqvbpsxm.54s\Szallitasi adatok.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
                    Source: C:\Users\user\AppData\Local\Temp\nqvbpsxm.54s\Szallitasi adatok.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
                    Source: C:\Users\user\AppData\Local\Temp\nqvbpsxm.54s\Szallitasi adatok.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
                    Source: C:\Users\user\AppData\Local\Temp\nqvbpsxm.54s\Szallitasi adatok.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
                    Source: C:\Users\user\AppData\Local\Temp\nqvbpsxm.54s\Szallitasi adatok.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
                    Source: C:\Users\user\AppData\Local\Temp\nqvbpsxm.54s\Szallitasi adatok.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
                    Source: C:\Users\user\AppData\Local\Temp\nqvbpsxm.54s\Szallitasi adatok.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
                    Source: C:\Users\user\AppData\Local\Temp\nqvbpsxm.54s\Szallitasi adatok.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
                    Source: C:\Users\user\AppData\Local\Temp\nqvbpsxm.54s\Szallitasi adatok.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
                    Source: C:\Users\user\AppData\Local\Temp\nqvbpsxm.54s\Szallitasi adatok.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
                    Source: C:\Users\user\AppData\Local\Temp\nqvbpsxm.54s\Szallitasi adatok.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
                    Source: C:\Users\user\AppData\Local\Temp\nqvbpsxm.54s\Szallitasi adatok.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
                    Source: C:\Users\user\AppData\Local\Temp\nqvbpsxm.54s\Szallitasi adatok.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
                    Source: C:\Users\user\AppData\Local\Temp\nqvbpsxm.54s\Szallitasi adatok.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
                    Source: C:\Users\user\AppData\Local\Temp\nqvbpsxm.54s\Szallitasi adatok.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
                    Source: C:\Users\user\AppData\Local\Temp\nqvbpsxm.54s\Szallitasi adatok.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
                    Source: C:\Users\user\AppData\Local\Temp\nqvbpsxm.54s\Szallitasi adatok.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
                    Source: C:\Users\user\AppData\Local\Temp\nqvbpsxm.54s\Szallitasi adatok.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
                    Source: C:\Users\user\AppData\Local\Temp\nqvbpsxm.54s\Szallitasi adatok.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
                    Source: C:\Users\user\AppData\Local\Temp\nqvbpsxm.54s\Szallitasi adatok.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
                    Source: C:\Users\user\AppData\Local\Temp\nqvbpsxm.54s\Szallitasi adatok.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
                    Source: C:\Users\user\AppData\Local\Temp\nqvbpsxm.54s\Szallitasi adatok.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
                    Source: C:\Users\user\AppData\Local\Temp\nqvbpsxm.54s\Szallitasi adatok.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
                    Source: C:\Users\user\AppData\Local\Temp\nqvbpsxm.54s\Szallitasi adatok.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
                    Source: C:\Users\user\AppData\Local\Temp\nqvbpsxm.54s\Szallitasi adatok.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
                    Source: C:\Users\user\AppData\Local\Temp\nqvbpsxm.54s\Szallitasi adatok.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
                    Source: C:\Users\user\AppData\Local\Temp\nqvbpsxm.54s\Szallitasi adatok.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
                    Source: C:\Users\user\AppData\Local\Temp\nqvbpsxm.54s\Szallitasi adatok.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
                    Source: C:\Users\user\AppData\Local\Temp\nqvbpsxm.54s\Szallitasi adatok.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
                    Source: C:\Users\user\AppData\Local\Temp\nqvbpsxm.54s\Szallitasi adatok.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
                    Source: C:\Users\user\AppData\Local\Temp\nqvbpsxm.54s\Szallitasi adatok.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
                    Source: C:\Users\user\AppData\Local\Temp\nqvbpsxm.54s\Szallitasi adatok.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
                    Source: C:\Users\user\AppData\Local\Temp\nqvbpsxm.54s\Szallitasi adatok.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
                    Source: C:\Users\user\AppData\Local\Temp\nqvbpsxm.54s\Szallitasi adatok.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
                    Source: C:\Users\user\AppData\Local\Temp\nqvbpsxm.54s\Szallitasi adatok.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
                    Source: C:\Users\user\AppData\Local\Temp\nqvbpsxm.54s\Szallitasi adatok.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
                    Source: C:\Users\user\AppData\Local\Temp\nqvbpsxm.54s\Szallitasi adatok.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
                    Source: C:\Users\user\AppData\Local\Temp\nqvbpsxm.54s\Szallitasi adatok.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
                    Source: C:\Users\user\AppData\Local\Temp\nqvbpsxm.54s\Szallitasi adatok.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
                    Source: C:\Users\user\AppData\Local\Temp\nqvbpsxm.54s\Szallitasi adatok.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
                    Source: C:\Users\user\AppData\Local\Temp\nqvbpsxm.54s\Szallitasi adatok.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
                    Source: C:\Users\user\AppData\Local\Temp\nqvbpsxm.54s\Szallitasi adatok.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
                    Source: C:\Users\user\AppData\Local\Temp\nqvbpsxm.54s\Szallitasi adatok.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
                    Source: C:\Users\user\AppData\Local\Temp\nqvbpsxm.54s\Szallitasi adatok.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
                    Source: C:\Users\user\AppData\Local\Temp\nqvbpsxm.54s\Szallitasi adatok.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
                    Source: C:\Users\user\AppData\Local\Temp\nqvbpsxm.54s\Szallitasi adatok.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
                    Source: C:\Users\user\AppData\Local\Temp\nqvbpsxm.54s\Szallitasi adatok.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
                    Source: C:\Users\user\AppData\Local\Temp\nqvbpsxm.54s\Szallitasi adatok.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
                    Source: C:\Users\user\AppData\Local\Temp\nqvbpsxm.54s\Szallitasi adatok.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
                    Source: C:\Users\user\AppData\Local\Temp\nqvbpsxm.54s\Szallitasi adatok.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
                    Source: C:\Users\user\AppData\Local\Temp\nqvbpsxm.54s\Szallitasi adatok.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
                    Source: C:\Users\user\AppData\Local\Temp\nqvbpsxm.54s\Szallitasi adatok.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
                    Source: C:\Users\user\AppData\Local\Temp\nqvbpsxm.54s\Szallitasi adatok.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
                    Source: C:\Users\user\AppData\Local\Temp\nqvbpsxm.54s\Szallitasi adatok.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
                    Source: C:\Users\user\AppData\Local\Temp\nqvbpsxm.54s\Szallitasi adatok.exeProcess information set: NOOPENFILEERRORBOXJump to behavior

                    Malware Analysis System Evasion:

                    barindex
                    Yara detected AntiVM3Show sources
                    Source: Yara matchFile source: 00000006.00000002.343156984.0000000002E03000.00000004.00000001.sdmp, type: MEMORY
                    Source: Yara matchFile source: Process Memory Space: Szallitasi adatok.exe PID: 7056, type: MEMORY
                    Queries sensitive BIOS Information (via WMI, Win32_Bios & Win32_BaseBoard, often done to detect virtual machines)Show sources
                    Source: C:\Users\user\AppData\Local\Temp\nqvbpsxm.54s\Szallitasi adatok.exeWMI Queries: IWbemServices::CreateInstanceEnum - root\cimv2 : Win32_BaseBoard
                    Queries sensitive network adapter information (via WMI, Win32_NetworkAdapter, often done to detect virtual machines)Show sources
                    Source: C:\Users\user\AppData\Local\Temp\nqvbpsxm.54s\Szallitasi adatok.exeWMI Queries: IWbemServices::CreateInstanceEnum - root\cimv2 : Win32_NetworkAdapterConfiguration
                    Tries to detect sandboxes and other dynamic analysis tools (process name or module or function)Show sources
                    Source: Szallitasi adatok.exe, 00000006.00000002.343156984.0000000002E03000.00000004.00000001.sdmpBinary or memory string: WINE_GET_UNIX_FILE_NAME
                    Source: Szallitasi adatok.exe, 00000006.00000002.343156984.0000000002E03000.00000004.00000001.sdmpBinary or memory string: SBIEDLL.DLL
                    Source: C:\Windows\SysWOW64\unarchiver.exeThread delayed: delay time: 922337203685477Jump to behavior
                    Source: C:\Users\user\AppData\Local\Temp\nqvbpsxm.54s\Szallitasi adatok.exeThread delayed: delay time: 922337203685477Jump to behavior
                    Source: C:\Users\user\AppData\Local\Temp\nqvbpsxm.54s\Szallitasi adatok.exeThread delayed: delay time: 922337203685477Jump to behavior
                    Source: C:\Users\user\AppData\Local\Temp\nqvbpsxm.54s\Szallitasi adatok.exeThread delayed: delay time: 922337203685477Jump to behavior
                    Source: C:\Users\user\AppData\Local\Temp\nqvbpsxm.54s\Szallitasi adatok.exeWindow / User API: threadDelayed 8291Jump to behavior
                    Source: C:\Users\user\AppData\Local\Temp\nqvbpsxm.54s\Szallitasi adatok.exeWindow / User API: threadDelayed 1568Jump to behavior
                    Source: C:\Windows\SysWOW64\unarchiver.exe TID: 6904Thread sleep time: -922337203685477s >= -30000sJump to behavior
                    Source: C:\Users\user\AppData\Local\Temp\nqvbpsxm.54s\Szallitasi adatok.exe TID: 7060Thread sleep time: -99493s >= -30000sJump to behavior
                    Source: C:\Users\user\AppData\Local\Temp\nqvbpsxm.54s\Szallitasi adatok.exe TID: 7080Thread sleep time: -922337203685477s >= -30000sJump to behavior
                    Source: C:\Users\user\AppData\Local\Temp\nqvbpsxm.54s\Szallitasi adatok.exe TID: 7100Thread sleep time: -922337203685477s >= -30000sJump to behavior
                    Source: C:\Users\user\AppData\Local\Temp\nqvbpsxm.54s\Szallitasi adatok.exe TID: 5608Thread sleep time: -18446744073709540s >= -30000sJump to behavior
                    Source: C:\Users\user\AppData\Local\Temp\nqvbpsxm.54s\Szallitasi adatok.exe TID: 6108Thread sleep count: 8291 > 30Jump to behavior
                    Source: C:\Users\user\AppData\Local\Temp\nqvbpsxm.54s\Szallitasi adatok.exe TID: 6108Thread sleep count: 1568 > 30Jump to behavior
                    Source: C:\Users\user\AppData\Local\Temp\nqvbpsxm.54s\Szallitasi adatok.exeWMI Queries: IWbemServices::CreateInstanceEnum - root\cimv2 : Win32_Processor
                    Source: C:\Users\user\AppData\Local\Temp\nqvbpsxm.54s\Szallitasi adatok.exeWMI Queries: IWbemServices::ExecQuery - root\cimv2 : SELECT * FROM Win32_Processor
                    Source: C:\Windows\SysWOW64\unarchiver.exeCode function: 0_2_0146B042 GetSystemInfo,0_2_0146B042
                    Source: C:\Windows\SysWOW64\unarchiver.exeThread delayed: delay time: 922337203685477Jump to behavior
                    Source: C:\Users\user\AppData\Local\Temp\nqvbpsxm.54s\Szallitasi adatok.exeThread delayed: delay time: 99493Jump to behavior
                    Source: C:\Users\user\AppData\Local\Temp\nqvbpsxm.54s\Szallitasi adatok.exeThread delayed: delay time: 922337203685477Jump to behavior
                    Source: C:\Users\user\AppData\Local\Temp\nqvbpsxm.54s\Szallitasi adatok.exeThread delayed: delay time: 922337203685477Jump to behavior
                    Source: C:\Users\user\AppData\Local\Temp\nqvbpsxm.54s\Szallitasi adatok.exeThread delayed: delay time: 922337203685477Jump to behavior
                    Source: Szallitasi adatok.exe, 00000006.00000002.343156984.0000000002E03000.00000004.00000001.sdmpBinary or memory string: vmware
                    Source: Szallitasi adatok.exe, 00000007.00000002.595705814.0000000006FA0000.00000004.00000001.sdmpBinary or memory string: Hyper-V RAW%SystemRoot%\system32\mswsock.dllM
                    Source: Szallitasi adatok.exe, 00000006.00000002.343156984.0000000002E03000.00000004.00000001.sdmpBinary or memory string: C:\PROGRAM FILES\VMWARE\VMWARE TOOLS\
                    Source: Szallitasi adatok.exe, 00000006.00000002.343156984.0000000002E03000.00000004.00000001.sdmpBinary or memory string: SOFTWARE\VMware, Inc.\VMware Tools
                    Source: Szallitasi adatok.exe, 00000006.00000002.343156984.0000000002E03000.00000004.00000001.sdmpBinary or memory string: VMware SVGA II!Add-MpPreference -ExclusionPath "
                    Source: Szallitasi adatok.exe, 00000006.00000002.343156984.0000000002E03000.00000004.00000001.sdmpBinary or memory string: VMWARE
                    Source: Szallitasi adatok.exe, 00000006.00000002.343156984.0000000002E03000.00000004.00000001.sdmpBinary or memory string: InstallPath%C:\PROGRAM FILES\VMWARE\VMWARE TOOLS\
                    Source: Szallitasi adatok.exe, 00000006.00000002.343156984.0000000002E03000.00000004.00000001.sdmpBinary or memory string: VMWARE"SOFTWARE\VMware, Inc.\VMware ToolsLHARDWARE\DEVICEMAP\Scsi\Scsi Port 1\Scsi Bus 0\Target Id 0\Logical Unit Id 0LHARDWARE\DEVICEMAP\Scsi\Scsi Port 2\Scsi Bus 0\Target Id 0\Logical Unit Id 0'SYSTEM\ControlSet001\Services\Disk\Enum
                    Source: Szallitasi adatok.exe, 00000006.00000002.343156984.0000000002E03000.00000004.00000001.sdmpBinary or memory string: VMware SVGA II
                    Source: Szallitasi adatok.exe, 00000006.00000002.343156984.0000000002E03000.00000004.00000001.sdmpBinary or memory string: vmwareNSYSTEM\ControlSet001\Control\Class\{4D36E968-E325-11CE-BFC1-08002BE10318}\0000
                    Source: C:\Users\user\AppData\Local\Temp\nqvbpsxm.54s\Szallitasi adatok.exeProcess information queried: ProcessInformationJump to behavior