Source: 0.0.Evolution des moyens de trasport.exe.400000.0.unpack | Avira: Label: TR/Dropper.VB.Gen |
Source: 0.2.Evolution des moyens de trasport.exe.400000.0.unpack | Avira: Label: TR/Dropper.VB.Gen |
Source: Evolution des moyens de trasport.exe | Static PE information: LOCAL_SYMS_STRIPPED, 32BIT_MACHINE, EXECUTABLE_IMAGE, LINE_NUMS_STRIPPED, RELOCS_STRIPPED |
Source: Evolution des moyens de trasport.exe | String found in binary or memory: http://127.0.0.1: |
Source: Evolution des moyens de trasport.exe | Static PE information: Resource name: RT_ICON type: GLS_BINARY_LSB_FIRST |
Source: Evolution des moyens de trasport.exe | Static PE information: Resource name: RT_ICON type: GLS_BINARY_LSB_FIRST |
Source: Evolution des moyens de trasport.exe | Static PE information: Resource name: RT_ICON type: GLS_BINARY_LSB_FIRST |
Source: Evolution des moyens de trasport.exe | Binary or memory string: OriginalFileName vs Evolution des moyens de trasport.exe |
Source: Evolution des moyens de trasport.exe | Binary or memory string: OriginalFilename vs Evolution des moyens de trasport.exe |
Source: Evolution des moyens de trasport.exe, 00000000.00000002.329695649.0000000000401000.00000020.00020000.sdmp | Binary or memory string: interval0\VarFileInfo\Translation \StringFileInfo\ OriginalFileName watch list kill white list kill f vs Evolution des moyens de trasport.exe |
Source: Evolution des moyens de trasport.exe, 00000000.00000002.329695649.0000000000401000.00000020.00020000.sdmp | Binary or memory string: OriginalFilename%q vs Evolution des moyens de trasport.exe |
Source: Evolution des moyens de trasport.exe | Binary or memory string: interval0\VarFileInfo\Translation \StringFileInfo\ OriginalFileName watch list kill white list kill f vs Evolution des moyens de trasport.exe |
Source: Evolution des moyens de trasport.exe | Binary or memory string: OriginalFilename%q vs Evolution des moyens de trasport.exe |
Source: C:\Users\user\Desktop\Evolution des moyens de trasport.exe | Section loaded: utility.dll |
Source: Evolution des moyens de trasport.exe | Static PE information: LOCAL_SYMS_STRIPPED, 32BIT_MACHINE, EXECUTABLE_IMAGE, LINE_NUMS_STRIPPED, RELOCS_STRIPPED |
Source: classification engine | Classification label: clean4.winEXE@1/0@0/0 |
Source: Evolution des moyens de trasport.exe | Static PE information: Section: .text IMAGE_SCN_MEM_EXECUTE, IMAGE_SCN_CNT_CODE, IMAGE_SCN_MEM_READ |
Source: C:\Users\user\Desktop\Evolution des moyens de trasport.exe | Section loaded: C:\Windows\SysWOW64\msvbvm60.dll |
Source: C:\Users\user\Desktop\Evolution des moyens de trasport.exe | Key opened: HKEY_CURRENT_USER\Software\Policies\Microsoft\Windows\Safer\CodeIdentifiers |
Source: Evolution des moyens de trasport.exe | Static PE information: Virtual size of .text is bigger than: 0x100000 |
Source: Evolution des moyens de trasport.exe | Static file information: File size 4903529 > 1048576 |
Source: Evolution des moyens de trasport.exe | Static PE information: Raw size of .text is bigger than: 0x100000 < 0x1b4000 |
Source: Evolution des moyens de trasport.exe | Static PE information: real checksum: 0x2219e3 should be: 0x4b9400 |
Source: C:\Users\user\Desktop\Evolution des moyens de trasport.exe | Code function: 0_2_00409010 push B0005252h; iretd |
Source: C:\Users\user\Desktop\Evolution des moyens de trasport.exe | Code function: 0_2_00403013 push 0040139Eh; ret |
Source: C:\Users\user\Desktop\Evolution des moyens de trasport.exe | Code function: 0_2_0040C148 push ebx; retn 0040h |
Source: C:\Users\user\Desktop\Evolution des moyens de trasport.exe | Code function: 0_2_00408172 push 0FC02F3Bh; ret |
Source: C:\Users\user\Desktop\Evolution des moyens de trasport.exe | Code function: 0_2_0040C1C0 push 0040139Eh; ret |
Source: C:\Users\user\Desktop\Evolution des moyens de trasport.exe | Code function: 0_2_0040C1D4 push 0040139Eh; ret |
Source: C:\Users\user\Desktop\Evolution des moyens de trasport.exe | Code function: 0_2_0040C1E8 push 0040139Eh; ret |
Source: C:\Users\user\Desktop\Evolution des moyens de trasport.exe | Code function: 0_2_0040C1FC push 0040139Eh; ret |
Source: C:\Users\user\Desktop\Evolution des moyens de trasport.exe | Code function: 0_2_0040C182 push 0040139Eh; ret |
Source: C:\Users\user\Desktop\Evolution des moyens de trasport.exe | Code function: 0_2_0040C24C push 0040139Eh; ret |
Source: C:\Users\user\Desktop\Evolution des moyens de trasport.exe | Code function: 0_2_0040C260 push 0040139Eh; ret |
Source: C:\Users\user\Desktop\Evolution des moyens de trasport.exe | Code function: 0_2_0040626C push 0040139Eh; ret |
Source: C:\Users\user\Desktop\Evolution des moyens de trasport.exe | Code function: 0_2_0040C274 push 0040139Eh; ret |
Source: C:\Users\user\Desktop\Evolution des moyens de trasport.exe | Code function: 0_2_0040C210 push 0040139Eh; ret |
Source: C:\Users\user\Desktop\Evolution des moyens de trasport.exe | Code function: 0_2_00406215 push 0040139Eh; ret |
Source: C:\Users\user\Desktop\Evolution des moyens de trasport.exe | Code function: 0_2_0040621E push 0040139Eh; ret |
Source: C:\Users\user\Desktop\Evolution des moyens de trasport.exe | Code function: 0_2_0040C224 push 0040139Eh; ret |
Source: C:\Users\user\Desktop\Evolution des moyens de trasport.exe | Code function: 0_2_0040C238 push 0040139Eh; ret |
Source: C:\Users\user\Desktop\Evolution des moyens de trasport.exe | Code function: 0_2_0040C2C4 push 0040139Eh; ret |
Source: C:\Users\user\Desktop\Evolution des moyens de trasport.exe | Code function: 0_2_004062D0 push 0040139Eh; ret |
Source: C:\Users\user\Desktop\Evolution des moyens de trasport.exe | Code function: 0_2_0040C2D8 push 0040139Eh; ret |
Source: C:\Users\user\Desktop\Evolution des moyens de trasport.exe | Code function: 0_2_004062E4 push 0040139Eh; ret |
Source: C:\Users\user\Desktop\Evolution des moyens de trasport.exe | Code function: 0_2_0040C2EC push 0040139Eh; ret |
Source: C:\Users\user\Desktop\Evolution des moyens de trasport.exe | Code function: 0_2_004062F8 push 0040139Eh; ret |
Source: C:\Users\user\Desktop\Evolution des moyens de trasport.exe | Code function: 0_2_0040B286 push 0040139Eh; ret |
Source: C:\Users\user\Desktop\Evolution des moyens de trasport.exe | Code function: 0_2_0040C288 push 0040139Eh; ret |
Source: C:\Users\user\Desktop\Evolution des moyens de trasport.exe | Code function: 0_2_00406294 push 0040139Eh; ret |
Source: C:\Users\user\Desktop\Evolution des moyens de trasport.exe | Code function: 0_2_0040B29A push 0040139Eh; ret |
Source: C:\Users\user\Desktop\Evolution des moyens de trasport.exe | Code function: 0_2_0040C29C push 0040139Eh; ret |
Source: C:\Users\user\Desktop\Evolution des moyens de trasport.exe | Code function: 0_2_004062A8 push 0040139Eh; ret |
Source: C:\Users\user\Desktop\Evolution des moyens de trasport.exe | Code function: 0_2_0040B2AE push 0040139Eh; ret |
Source: C:\Users\user\Desktop\Evolution des moyens de trasport.exe | Process information set: NOOPENFILEERRORBOX |
Source: C:\Users\user\Desktop\Evolution des moyens de trasport.exe | Process information set: NOOPENFILEERRORBOX |
Source: C:\Users\user\Desktop\Evolution des moyens de trasport.exe | Process information set: NOOPENFILEERRORBOX |
Source: C:\Users\user\Desktop\Evolution des moyens de trasport.exe | Process information set: NOOPENFILEERRORBOX |
Source: C:\Users\user\Desktop\Evolution des moyens de trasport.exe | Process information set: NOOPENFILEERRORBOX |
Source: C:\Users\user\Desktop\Evolution des moyens de trasport.exe | Process information set: NOOPENFILEERRORBOX |
Source: all processes | Thread injection, dropped files, key value created, disk infection and DNS query: no activity detected |
Source: all processes | Thread injection, dropped files, key value created, disk infection and DNS query: no activity detected |
Source: Evolution des moyens de trasport.exe, 00000000.00000002.330189742.0000000000953000.00000004.00000001.sdmp | Binary or memory string: Progman UIq |
Source: Evolution des moyens de trasport.exe | Binary or memory string: Shell_TrayWnd |
Source: Evolution des moyens de trasport.exe | Binary or memory string: Progman |
Source: Evolution des moyens de trasport.exe, 00000000.00000002.330198231.000000000095E000.00000004.00000001.sdmp | Binary or memory string: Program Manager CC |
Source: Evolution des moyens de trasport.exe, 00000000.00000002.330198231.000000000095E000.00000004.00000001.sdmp | Binary or memory string: Program Manager |
Source: Evolution des moyens de trasport.exe, 00000000.00000002.330189742.0000000000953000.00000004.00000001.sdmp | Binary or memory string: Progmantd |
Source: Evolution des moyens de trasport.exe | Binary or memory string: shell_traywnd |
Thumbnails
This section contains all screenshots as thumbnails, including those not shown in the slideshow.