Loading ...

Play interactive tourEdit tour

Analysis Report TPZi2Evolution des moyens de trasport.exe

Overview

General Information

Sample Name:TPZi2Evolution des moyens de trasport.exe
Analysis ID:385486
MD5:3ffead9503aef3dd3c60fc58b0c41d01
SHA1:94596dc41a99f7e6c3f5209e3d65d797082ec93b
SHA256:fc3adb1a06fb6e66dc53ad01726b85af4c296a3438a49df73b98b7d481f6d154
Infos:

Most interesting Screenshot:

Detection

Score:48
Range:0 - 100
Whitelisted:false
Confidence:100%

Signatures

Icon mismatch, binary includes an icon from a different legit application in order to fool users
Creates a DirectInput object (often for capturing keystrokes)
Installs a global mouse hook
Monitors certain registry keys / values for changes (often done to protect autostart functionality)
PE file contains an invalid checksum
PE file contains sections with non-standard names
PE file contains strange resources
Sample file is different than original file name gathered from version info
Tries to load missing DLLs
Uses 32bit PE files

Classification

Startup

  • System is w10x64
  • cleanup

Malware Configuration

No configs have been found

Yara Overview

No yara matches

Sigma Overview

No Sigma rule has matched

Signature Overview

Click to jump to signature section

Show All Signature Results
Source: TPZi2Evolution des moyens de trasport.exeStatic PE information: 32BIT_MACHINE, EXECUTABLE_IMAGE
Source: TPZi2Evolution des moyens de trasport.exeStatic PE information: TERMINAL_SERVER_AWARE, DYNAMIC_BASE, NX_COMPAT
Source: Binary string: FlashPlayer.pdb source: TPZi2Evolution des moyens de trasport.exe
Source: TPZi2Evolution des moyens de trasport.exeString found in binary or memory: http://%shttp://a.SharedObject.BadPersistenceSharedObject.UriMismatchpending.heu.swz
Source: TPZi2Evolution des moyens de trasport.exeString found in binary or memory: http://ad./adserver/e?type=playererrorhttp://ad.auditude.com/adserver/e?type=playererror//_.dashmpd&
Source: TPZi2Evolution des moyens de trasport.exeString found in binary or memory: http://ad./adserver?tm=15&u=&u=&l=&z=&of=1.4&g=Auditude
Source: TPZi2Evolution des moyens de trasport.exeString found in binary or memory: http://ad.auditude.com/adserver/e?type=playererror
Source: TPZi2Evolution des moyens de trasport.exeString found in binary or memory: http://cdn2.auditude.com/assets/3p/v
Source: TPZi2Evolution des moyens de trasport.exeString found in binary or memory: http://cdn2.auditude.com/assets/3p/vService
Source: TPZi2Evolution des moyens de trasport.exeString found in binary or memory: http://crl.thawte.com/ThawteTimestampingCA.crl0
Source: TPZi2Evolution des moyens de trasport.exeString found in binary or memory: http://dashif.org/guidelines/trickmode
Source: TPZi2Evolution des moyens de trasport.exeString found in binary or memory: http://dashif.org/guidelines/trickmode1
Source: TPZi2Evolution des moyens de trasport.exeString found in binary or memory: http://fpdownload2.macromedia.com/get/
Source: TPZi2Evolution des moyens de trasport.exeString found in binary or memory: http://fpdownload2.macromedia.com/get/flashplayer/update/current/xml/express/version_win_
Source: TPZi2Evolution des moyens de trasport.exe, 00000001.00000002.607497816.0000000001C26000.00000002.00020000.sdmpString found in binary or memory: http://fpdownload2.macromedia.com/get/flashplayer/update/current/xml/express/version_win_WUV
Source: TPZi2Evolution des moyens de trasport.exeString found in binary or memory: http://fpdownload2.macromedia.com/get/flashplayer/update/current/xml/express/version_win_WUiF
Source: TPZi2Evolution des moyens de trasport.exeString found in binary or memory: http://fpdownload2.macromedia.com/get/https://fpdownload.macromedia.com/get/https://www.macromedia.c
Source: TPZi2Evolution des moyens de trasport.exeString found in binary or memory: http://ocsp.thawte.com0
Source: TPZi2Evolution des moyens de trasport.exeString found in binary or memory: http://s.symcb.com/pca3-g5.crl0
Source: TPZi2Evolution des moyens de trasport.exeString found in binary or memory: http://s.symcd.com0_
Source: TPZi2Evolution des moyens de trasport.exeString found in binary or memory: http://s3.amazonaws.com/venkat-test/ads/camry/file-640k.m3u8
Source: TPZi2Evolution des moyens de trasport.exeString found in binary or memory: http://s3.amazonaws.com/venkat-test/ads/camry/file-640k.m3u82L
Source: TPZi2Evolution des moyens de trasport.exeString found in binary or memory: http://sw.symcb.com/sw.crl0
Source: TPZi2Evolution des moyens de trasport.exeString found in binary or memory: http://sw.symcd.com0
Source: TPZi2Evolution des moyens de trasport.exeString found in binary or memory: http://sw1.symcb.com/sw.crt0
Source: TPZi2Evolution des moyens de trasport.exeString found in binary or memory: http://ts-aia.ws.symantec.com/tss-ca-g2.cer0
Source: TPZi2Evolution des moyens de trasport.exeString found in binary or memory: http://ts-crl.ws.symantec.com/tss-ca-g2.crl0(
Source: TPZi2Evolution des moyens de trasport.exeString found in binary or memory: http://ts-ocsp.ws.symantec.com07
Source: TPZi2Evolution des moyens de trasport.exeString found in binary or memory: http://www.macromedia.com
Source: TPZi2Evolution des moyens de trasport.exeString found in binary or memory: http://www.macromedia.com/go/player_settings_
Source: TPZi2Evolution des moyens de trasport.exeString found in binary or memory: http://www.macromedia.com/go/player_settings_.Unmuted.MutedCamera.UnmutedCamera.MutedMicrophone.Unmu
Source: TPZi2Evolution des moyens de trasport.exeString found in binary or memory: http://www.macromedia.comhttps://www.macromedia.com/support/flashplayer/sys/&amp
Source: TPZi2Evolution des moyens de trasport.exeString found in binary or memory: https://ats.macromedia.com/Players/ATS/ATS10AS3/Shipping/html/Security/ProtectedMode/PenTestDriverDL
Source: TPZi2Evolution des moyens de trasport.exeString found in binary or memory: https://auth.adobefpl.com/1/
Source: TPZi2Evolution des moyens de trasport.exeString found in binary or memory: https://d.symcb.com/cps0%
Source: TPZi2Evolution des moyens de trasport.exeString found in binary or memory: https://d.symcb.com/rpa0
Source: TPZi2Evolution des moyens de trasport.exeString found in binary or memory: https://d.symcb.com/rpa0)
Source: TPZi2Evolution des moyens de trasport.exeString found in binary or memory: https://fpdownload.macromedia.com/get/
Source: TPZi2Evolution des moyens de trasport.exeString found in binary or memory: https://primetimeenablement.sc.omtrdc.net/b/ss//6
Source: TPZi2Evolution des moyens de trasport.exeString found in binary or memory: https://primetimeenablement.sc.omtrdc.net/b/ss//6primesample2
Source: TPZi2Evolution des moyens de trasport.exeString found in binary or memory: https://www.macromedia.com/bin/flashdownload.cgi
Source: TPZi2Evolution des moyens de trasport.exeString found in binary or memory: https://www.macromedia.com/support/flashplayer/sys/
Source: TPZi2Evolution des moyens de trasport.exe, 00000001.00000002.612301693.0000000005815000.00000004.00000040.sdmpString found in binary or memory: https://www.macromedia.com/support/flashplayer/sys/.
Source: TPZi2Evolution des moyens de trasport.exe, 00000001.00000002.612301693.0000000005815000.00000004.00000040.sdmpString found in binary or memory: https://www.macromedia.com/support/flashplayer/sys/rs
Source: TPZi2Evolution des moyens de trasport.exe, 00000001.00000002.612301693.0000000005815000.00000004.00000040.sdmpString found in binary or memory: https://www.macromedia.com/support/flashplayer/sys/x
Source: TPZi2Evolution des moyens de trasport.exe, 00000001.00000002.607497816.0000000001C26000.00000002.00020000.sdmpBinary or memory string: DirectInput8Create
Source: C:\Users\user\Desktop\TPZi2Evolution des moyens de trasport.exeWindows user hook set: 0 mouse low level C:\Windows\system32\dinput8.dllJump to behavior
Source: TPZi2Evolution des moyens de trasport.exeStatic PE information: Resource name: RT_ICON type: GLS_BINARY_LSB_FIRST
Source: TPZi2Evolution des moyens de trasport.exeStatic PE information: Resource name: RT_ICON type: GLS_BINARY_LSB_FIRST
Source: TPZi2Evolution des moyens de trasport.exeStatic PE information: Resource name: RT_ICON type: GLS_BINARY_LSB_FIRST
Source: TPZi2Evolution des moyens de trasport.exeStatic PE information: Resource name: RT_ICON type: GLS_BINARY_LSB_FIRST
Source: TPZi2Evolution des moyens de trasport.exeStatic PE information: Resource name: RT_ICON type: GLS_BINARY_LSB_FIRST
Source: TPZi2Evolution des moyens de trasport.exeStatic PE information: Resource name: RT_ICON type: GLS_BINARY_LSB_FIRST
Source: TPZi2Evolution des moyens de trasport.exeStatic PE information: Resource name: RT_ICON type: GLS_BINARY_LSB_FIRST
Source: TPZi2Evolution des moyens de trasport.exeStatic PE information: Resource name: RT_ICON type: GLS_BINARY_LSB_FIRST
Source: TPZi2Evolution des moyens de trasport.exeStatic PE information: Resource name: RT_ICON type: GLS_BINARY_LSB_FIRST
Source: TPZi2Evolution des moyens de trasport.exeStatic PE information: Resource name: RT_ICON type: GLS_BINARY_LSB_FIRST
Source: TPZi2Evolution des moyens de trasport.exeStatic PE information: Resource name: RT_ICON type: GLS_BINARY_LSB_FIRST
Source: TPZi2Evolution des moyens de trasport.exe, 00000001.00000002.622283403.000000000AB80000.00000002.00000001.sdmpBinary or memory string: OriginalFilenamewdmaud.drv.muij% vs TPZi2Evolution des moyens de trasport.exe
Source: TPZi2Evolution des moyens de trasport.exe, 00000001.00000000.333150151.0000000002165000.00000002.00020000.sdmpBinary or memory string: OriginalFilenameSAFlashPlayer.exe@ vs TPZi2Evolution des moyens de trasport.exe
Source: TPZi2Evolution des moyens de trasport.exe, 00000001.00000002.622292153.000000000AB90000.00000002.00000001.sdmpBinary or memory string: OriginalFilenamemsacm32.acm.muij% vs TPZi2Evolution des moyens de trasport.exe
Source: TPZi2Evolution des moyens de trasport.exeBinary or memory string: OriginalFilenameSAFlashPlayer.exe@ vs TPZi2Evolution des moyens de trasport.exe
Source: C:\Users\user\Desktop\TPZi2Evolution des moyens de trasport.exeSection loaded: comres.dllJump to behavior
Source: C:\Users\user\Desktop\TPZi2Evolution des moyens de trasport.exeSection loaded: ws2help.dllJump to behavior
Source: C:\Users\user\Desktop\TPZi2Evolution des moyens de trasport.exeSection loaded: xpsp2res.dllJump to behavior
Source: TPZi2Evolution des moyens de trasport.exeStatic PE information: 32BIT_MACHINE, EXECUTABLE_IMAGE
Source: classification engineClassification label: mal48.winEXE@1/1@0/0
Source: C:\Users\user\Desktop\TPZi2Evolution des moyens de trasport.exeFile created: C:\Users\user\AppData\Roaming\Adobe\Flash Player\AssetCacheJump to behavior
Source: C:\Users\user\Desktop\TPZi2Evolution des moyens de trasport.exeKey opened: HKEY_CURRENT_USER\Software\Policies\Microsoft\Windows\Safer\CodeIdentifiersJump to behavior
Source: TPZi2Evolution des moyens de trasport.exeString found in binary or memory: ms-help:
Source: TPZi2Evolution des moyens de trasport.exeString found in binary or memory: G@msencdata:hcp:ms-help:etc:vnd.ms.wmhtml:wmhtml:mhtml:Ms-its:mk:@MSITStore:local://rtmfp:rtmpte:rtmpe:rtmps:rtmpt:rtmp:https%3ahttp%3ablob:jar:feed:pcast:file:////\\#? ^ [A-Za-z0-9]+ :// [^/?#]+ https://http://:443:80https:http:"noneinternalallsameDomainneveralwaysrtmp://http://www.adobe.com/go/about_flash_playerlevelevent:FWS
Source: TPZi2Evolution des moyens de trasport.exeString found in binary or memory: unaru. <a href='http://adobe.com/go/addlocalstorage_rs' target='_blank'><u><font color='#0000FF'>Saznajte vi
Source: TPZi2Evolution des moyens de trasport.exeString found in binary or memory: imaldab kiiremini laadida ja teavet arvutisse salvestada. <a href='http://adobe.com/go/addlocalstorage_ee' target='_blank'><u><font color='#0000FF'>Lisateave</font></u></a>
Source: TPZi2Evolution des moyens de trasport.exeString found in binary or memory: imaldab kiiremini laadida ja teavet arvutisse salvestada. <a href='http://adobe.com/go/addlocalstorage_ee' target='_blank'><u><font color='#0000FF'>Lisateave</font></u></a>Rakenduse otsetee loomineSalvesta heliKopeeri pilt nimega ...Kopeeri pildi asukohtKopeeri piltSalvesta link nimega ...Lisa link j
Source: TPZi2Evolution des moyens de trasport.exeString found in binary or memory: <br/><a href='http://adobe.com/go/addlocalstorage' target='_blank'><u><font color='#0000FF'>
Source: TPZi2Evolution des moyens de trasport.exeString found in binary or memory: iame kompiuteryje. <a href='http://adobe.com/go/addlocalstorage_lt' target='_blank'><u><font color='#0000FF'>Su
Source: TPZi2Evolution des moyens de trasport.exeString found in binary or memory: . <a href='http://adobe.com/go/addlocalstorage_lv' target='_blank'><u><font color='#0000FF'>Uzziniet vair
Source: TPZi2Evolution des moyens de trasport.exeString found in binary or memory: . <a href='http://adobe.com/go/addlocalstorage_ua' target='_blank'><u><font color='#0000FF'>
Source: TPZi2Evolution des moyens de trasport.exeString found in binary or memory: unalu. <a href='http://adobe.com/go/addlocalstorage_hr' target='_blank'><u><font color='#0000FF'>Saznajte vi
Source: TPZi2Evolution des moyens de trasport.exeString found in binary or memory: iile pe acest computer. <a href='http://adobe.com/go/addlocalstorage_ro' target='_blank'><u><font color='#0000FF'>Mai multe informa
Source: TPZi2Evolution des moyens de trasport.exeString found in binary or memory: unalniku. <a href='http://adobe.com/go/addlocalstorage_si' target='_blank'><u><font color='#0000FF'>Ve
Source: TPZi2Evolution des moyens de trasport.exeString found in binary or memory: . <a href='http://adobe.com/go/addlocalstorage_bg' target='_blank'><u><font color='#0000FF'>
Source: TPZi2Evolution des moyens de trasport.exeString found in binary or memory: i. <a href='http://adobe.com/go/addlocalstorage_sk' target='_blank'><u><font color='#0000FF'>
Source: TPZi2Evolution des moyens de trasport.exeString found in binary or memory: . <a href='http://adobe.com/go/addlocalstorage' target='_blank'><u><font color='#0000FF'>
Source: TPZi2Evolution des moyens de trasport.exeString found in binary or memory: Allow this game to use local storage? This will allow it to load faster and save information on this computer. <a href='http://adobe.com/go/addlocalstorage' target='_blank'><u><font colour='#0000FF'>Learn More</font></u></a>
Source: TPZi2Evolution des moyens de trasport.exeString found in binary or memory: WARNING: For content targeting Flash Player version 14 or higher, ExternalInterface escapes strings using JSON conventions. To maintain compatibility, content published to earlier Flash Player versions continues to use the legacy escaping behaviour.by <a href='%1' target='_blank'><u><font colour='#0000FF'>%2</font></u></a>Allow this game to use local storage? This will allow it to load faster and save information on this computer. <a href='http://adobe.com/go/addlocalstorage' target='_blank'><u><font colour='#0000FF'>Learn More</font></u></a>Reload FilmFilm not loaded...Hae p
Source: TPZi2Evolution des moyens de trasport.exeString found in binary or memory: paikallista tallennustilaa? Tietojen tallentaminen paikallisesti nopeuttaa pelin latautumista. <a href='http://adobe.com/go/addlocalstorage_fi' target='_blank'><u><font color='#0000FF'>Lis
Source: TPZi2Evolution des moyens de trasport.exeString found in binary or memory: pen. <a href='http://adobe.com/go/addlocalstorage_hu' target='_blank'><u><font color='#0000FF'>Tov
Source: TPZi2Evolution des moyens de trasport.exeString found in binary or memory: datamaskinen. <a href='http://adobe.com/go/addlocalstorage_no' target='_blank'><u><font color='#0000FF'>Finn ut mer</font></u></a>
Source: TPZi2Evolution des moyens de trasport.exeString found in binary or memory: datamaskinen. <a href='http://adobe.com/go/addlocalstorage_no' target='_blank'><u><font color='#0000FF'>Finn ut mer</font></u></a>Opprett programsnarveiLydopptakLagre bilde som...Kopier bildeplasseringKopier bildeLagre kobling som...Bokmerkekobling...Kopier koblingsplassering
Source: TPZi2Evolution des moyens de trasport.exeString found in binary or memory: o no computador. <a href='http://adobe.com/go/addlocalstorage_pt' target='_blank'><u><font color='#0000FF'>Saber mais</font></u></a>
Source: TPZi2Evolution des moyens de trasport.exeString found in binary or memory: o no computador. <a href='http://adobe.com/go/addlocalstorage_pt' target='_blank'><u><font color='#0000FF'>Saber mais</font></u></a>Criar atalho de aplica
Source: TPZi2Evolution des moyens de trasport.exeString found in binary or memory: denne computer. <a href='http://adobe.com/go/addlocalstorage_da' target='_blank'><u><font color='#0000FF'>F
Source: TPZi2Evolution des moyens de trasport.exeString found in binary or memory: <a href='http://adobe.com/go/addlocalstorage' target='_blank'><u><font color='#0000FF'>
Source: TPZi2Evolution des moyens de trasport.exeString found in binary or memory: klenmesine ve bu bilgisayarda bilgi kaydetmesine izin verir. <a href='http://adobe.com/go/addlocalstorage' target='_blank'><u><font color='#0000FF'>Daha Fazla Bilgi</font></u></a>
Source: TPZi2Evolution des moyens de trasport.exeString found in binary or memory: klenmesine ve bu bilgisayarda bilgi kaydetmesine izin verir. <a href='http://adobe.com/go/addlocalstorage' target='_blank'><u><font color='#0000FF'>Daha Fazla Bilgi</font></u></a>Uygulama K
Source: TPZi2Evolution des moyens de trasport.exeString found in binary or memory: r datorn. <a href='http://adobe.com/go/addlocalstorage' target='_blank'><u><font color='#0000FF'>L
Source: TPZi2Evolution des moyens de trasport.exeString found in binary or memory: es neste computador. <a href='http://adobe.com/go/addlocalstorage' target='_blank'><u><font color='#0000FF'>Saiba mais</font></u></a>
Source: TPZi2Evolution des moyens de trasport.exeString found in binary or memory: es neste computador. <a href='http://adobe.com/go/addlocalstorage' target='_blank'><u><font color='#0000FF'>Saiba mais</font></u></a>Criar atalho de aplicativoGravar
Source: TPZi2Evolution des moyens de trasport.exeString found in binary or memory: informacji na tym komputerze. <a href='http://adobe.com/go/addlocalstorage' target='_blank'><u><font color='#0000FF'>Wi
Source: TPZi2Evolution des moyens de trasport.exeString found in binary or memory: Lokale opslag toegankelijk maken voor dit spel? Hierdoor wordt het spel sneller geladen en worden de spelgegevens opgeslagen op deze computer. <a href='http://adobe.com/go/addlocalstorage' target='_blank'><u><font color='#0000FF'>Meer informatie</font></u></a>
Source: TPZi2Evolution des moyens de trasport.exeString found in binary or memory: -inhoud uit dit domein niet naar behoren.<br><br><font color='#0000FF'><u><a href='http://www.adobe.com/go/learn_fp_safari_safe_mode_nl'>Meer informatie</a></u></font></textformat>Toevoegen aan Adobe PlaypanelVastmaken aan Startprobeert te communiceren met deze voor internet geschikte locatie:De volgende lokale toepassing op uw computer of netwerk:Adobe Flash Player heeft een potentieel onveilige bewerking gestopt.NeeEen script in deze film zorgt ervoor dat Adobe Flash Player langzaam wordt uitgevoerd. Als dit script actief blijft, reageert de computer mogelijk niet meer. Wilt u het script afbreken?Sneltoets voor deze toepassing maken op het bureaublad?Sneltoets toevoegen aan bureaubladToevoegen aan lokale opslag in Flash Playerdoor <a href='%1' target='_blank'><u><font color='#0000FF'>%2</font></u></a>Sneltoets makenAnnulerenVastzetten op taakbalkToevoegen aan menu StartToevoegen aan bureaubladSneltoetsen voor de toepassing maken in de volgende locaties:Ook sneltoetsen voor de toepassing maken in de volgende locaties:Lokale opslag toegankelijk maken voor dit spel? Hierdoor wordt het spel sneller geladen en worden de spelgegevens opgeslagen op deze computer. <a href='http://adobe.com/go/addlocalstorage' target='_blank'><u><font color='#0000FF'>Meer informatie</font></u></a>Sneltoets voor de toepassing makenAudio opnemenAfbeelding opslaan als...Afbeeldingslocatie kopi
Source: TPZi2Evolution des moyens de trasport.exeString found in binary or memory: informazioni su questo computer. <a href='http://adobe.com/go/addlocalstorage' target='_blank'><u><font color='#0000FF'>Altre informazioni</font></u></a>
Source: TPZi2Evolution des moyens de trasport.exeString found in binary or memory: informazioni su questo computer. <a href='http://adobe.com/go/addlocalstorage' target='_blank'><u><font color='#0000FF'>Altre informazioni</font></u></a>Crea collegamento applicazioneRegistra audioSalva immagine con nome...Copia posizione immagineCopia immagineSalva collegamento con nome...Imposta collegamento come segnalibro...Copia posizione collegamentoApri in una nuova schedaApri in una nuova finestraApriSeleziona tuttoEliminaIncollaCopiaTagliaAnnullaInformazioni su Adobe Flash Player %s...Impostazioni globali...Impostazioni...Ricarica filmatoMostra aree ridisegnoStampa...Filmato non caricato...IndietroAvantiRiavvolgiCicloRiproduciBassaQualit
Source: TPZi2Evolution des moyens de trasport.exeString found in binary or memory: ? Le jeu pourra se charger plus rapidement et enregistrer des informations sur cet ordinateur. <a href='http://adobe.com/go/addlocalstorage' target='_blank'><u><font color='#0000FF'>En savoir plus</font></u></a>
Source: TPZi2Evolution des moyens de trasport.exeString found in binary or memory: ? Le jeu pourra se charger plus rapidement et enregistrer des informations sur cet ordinateur. <a href='http://adobe.com/go/addlocalstorage' target='_blank'><u><font color='#0000FF'>En savoir plus</font></u></a>Cr
Source: TPZi2Evolution des moyens de trasport.exeString found in binary or memory: n en este ordenador. <a href='http://adobe.com/go/addlocalstorage' target='_blank'><u><font color='#0000FF'>M
Source: TPZi2Evolution des moyens de trasport.exeString found in binary or memory: Darf dieses Spiel den lokalen Speicher verwenden? Dadurch wird es schneller geladen und kann Informationen auf diesem Computer speichern. <a href='http://adobe.com/go/addlocalstorage' target='_blank'><u><font color='#0000FF'>Weitere Informationen</font></u></a>
Source: TPZi2Evolution des moyens de trasport.exeString found in binary or memory: pfungen auch hier erstellen:Darf dieses Spiel den lokalen Speicher verwenden? Dadurch wird es schneller geladen und kann Informationen auf diesem Computer speichern. <a href='http://adobe.com/go/addlocalstorage' target='_blank'><u><font color='#0000FF'>Weitere Informationen</font></u></a>Verkn
Source: TPZi2Evolution des moyens de trasport.exeString found in binary or memory: e. <a href='http://adobe.com/go/addlocalstorage' target='_blank'><u><font color='#0000FF'>Dal
Source: TPZi2Evolution des moyens de trasport.exeString found in binary or memory: Allow this game to use local storage? This will allow it to load faster and save information on this computer. <a href='http://adobe.com/go/addlocalstorage' target='_blank'><u><font color='#0000FF'>Learn More</font></u></a>
Source: TPZi2Evolution des moyens de trasport.exeString found in binary or memory: Check for Updates...Create Shortcut on Desktop<textformat leftmargin='2' rightmargin='2'>Do you trust this content to connect to the Internet?</textformat>WARNING: For content targeting Flash Player version 14 or higher, ExternalInterface escapes strings using JSON conventions. To maintain compatibility, content published to earlier Flash Player versions continues to use the legacy escaping behavior.<textformat leftmargin='2' rightmargin='2'>"Add to Adobe Playpanel" has failed. You must first launch and login to Adobe Playpanel to use this feature.</textformat>Find games with Adobe Playpanel<textformat leftmargin='2' rightmargin='2'>You must adjust Safari's security preferences to allow Flash content from this domain to work properly.<br><br><font color='#0000FF'><u><a href='http://www.adobe.com/go/learn_fp_safari_safe_mode'>Learn More</a></u></font></textformat>Add to Adobe PlaypanelPin to Startis trying to communicate with this Internet-enabled location:The following local application on your computer or network:Adobe Flash Player has stopped a potentially unsafe operation.NoYesA script in this movie is causing Adobe Flash Player to run slowly. If it continues to run, your computer may become unresponsive. Do you want to abort the script?Create a desktop shortcut for this application?Add shortcut to desktopAdd to Local Storage in Flash Playerby <a href='%1' target='_blank'><u><font color='#0000FF'>%2</font></u></a>Create ShortcutsOKCancelPin to TaskbarAdd to Start menuAdd to DesktopCreate application shortcuts in these places:Also create application shortcuts in these places:Allow this game to use local storage? This will allow it to load faster and save information on this computer. <a href='http://adobe.com/go/addlocalstorage' target='_blank'><u><font color='#0000FF'>Learn More</font></u></a>Create Application ShortcutRecord AudioSave Image As...Copy Image LocationCopy ImageSave link as...Bookmark link...Open in new tabAbout Adobe Flash Player %s...Global Settings...Settings...Reload MoviePrint...Movie not loaded...HighMediumLowFull ScreenSetWaitableTimerExpJ
Source: TPZi2Evolution des moyens de trasport.exeString found in binary or memory: <!--StartFragment-->
Source: TPZi2Evolution des moyens de trasport.exeString found in binary or memory: flashplayer/update/current/install/inline/
Source: TPZi2Evolution des moyens de trasport.exeString found in binary or memory: mflashplayer/update/current/install/inline/.datAFCache?nocache=https://auth.adobefpl.com/1/
Source: TPZi2Evolution des moyens de trasport.exeString found in binary or memory: [mem] sweep-start
Source: C:\Users\user\Desktop\TPZi2Evolution des moyens de trasport.exeFile read: C:\Users\user\Desktop\TPZi2Evolution des moyens de trasport.exeJump to behavior
Source: C:\Users\user\Desktop\TPZi2Evolution des moyens de trasport.exeKey value queried: HKEY_LOCAL_MACHINE\SOFTWARE\Classes\WOW6432Node\CLSID\{275C23E2-3747-11D0-9FEA-00AA003F8646}\InProcServer32Jump to behavior
Source: TPZi2Evolution des moyens de trasport.exeStatic PE information: Virtual size of .text is bigger than: 0x100000
Source: TPZi2Evolution des moyens de trasport.exeStatic file information: File size 17140460 > 1048576
Source: TPZi2Evolution des moyens de trasport.exeStatic PE information: Raw size of .text is bigger than: 0x100000 < 0x952c00
Source: TPZi2Evolution des moyens de trasport.exeStatic PE information: Raw size of .rdata is bigger than: 0x100000 < 0x1d8400
Source: TPZi2Evolution des moyens de trasport.exeStatic PE information: Raw size of .rsrc is bigger than: 0x100000 < 0x1c1200
Source: TPZi2Evolution des moyens de trasport.exeStatic PE information: More than 200 imports for KERNEL32.dll
Source: TPZi2Evolution des moyens de trasport.exeStatic PE information: data directory type: IMAGE_DIRECTORY_ENTRY_IMPORT
Source: TPZi2Evolution des moyens de trasport.exeStatic PE information: data directory type: IMAGE_DIRECTORY_ENTRY_RESOURCE
Source: TPZi2Evolution des moyens de trasport.exeStatic PE information: data directory type: IMAGE_DIRECTORY_ENTRY_BASERELOC
Source: TPZi2Evolution des moyens de trasport.exeStatic PE information: data directory type: IMAGE_DIRECTORY_ENTRY_DEBUG
Source: TPZi2Evolution des moyens de trasport.exeStatic PE information: data directory type: IMAGE_DIRECTORY_ENTRY_LOAD_CONFIG
Source: TPZi2Evolution des moyens de trasport.exeStatic PE information: data directory type: IMAGE_DIRECTORY_ENTRY_IAT
Source: TPZi2Evolution des moyens de trasport.exeStatic PE information: TERMINAL_SERVER_AWARE, DYNAMIC_BASE, NX_COMPAT
Source: TPZi2Evolution des moyens de trasport.exeStatic PE information: data directory type: IMAGE_DIRECTORY_ENTRY_DEBUG
Source: Binary string: FlashPlayer.pdb source: TPZi2Evolution des moyens de trasport.exe
Source: TPZi2Evolution des moyens de trasport.exeStatic PE information: Data directory: IMAGE_DIRECTORY_ENTRY_IMPORT is in: .rdata
Source: TPZi2Evolution des moyens de trasport.exeStatic PE information: Data directory: IMAGE_DIRECTORY_ENTRY_RESOURCE is in: .rsrc
Source: TPZi2Evolution des moyens de trasport.exeStatic PE information: Data directory: IMAGE_DIRECTORY_ENTRY_BASERELOC is in: .reloc
Source: TPZi2Evolution des moyens de trasport.exeStatic PE information: Data directory: IMAGE_DIRECTORY_ENTRY_LOAD_CONFIG is in: .rdata
Source: TPZi2Evolution des moyens de trasport.exeStatic PE information: Data directory: IMAGE_DIRECTORY_ENTRY_IAT is in: .rdata
Source: TPZi2Evolution des moyens de trasport.exeStatic PE information: real checksum: 0xe2f1fa should be:
Source: TPZi2Evolution des moyens de trasport.exeStatic PE information: section name: .rodata

Hooking and other Techniques for Hiding and Protection:

barindex
Icon mismatch, binary includes an icon from a different legit application in order to fool usersShow sources
Source: initial sampleIcon embedded in binary file: icon matches a legit application icon: icon5339.png
Source: C:\Users\user\Desktop\TPZi2Evolution des moyens de trasport.exeRegistry key monitored for changes: HKEY_CURRENT_USER_ClassesJump to behavior
Source: C:\Users\user\Desktop\TPZi2Evolution des moyens de trasport.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Users\user\Desktop\TPZi2Evolution des moyens de trasport.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Users\user\Desktop\TPZi2Evolution des moyens de trasport.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Users\user\Desktop\TPZi2Evolution des moyens de trasport.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: TPZi2Evolution des moyens de trasport.exe, 00000001.00000002.608569932.00000000021F0000.00000002.00000001.sdmpBinary or memory string: Shell_TrayWnd
Source: TPZi2Evolution des moyens de trasport.exe, 00000001.00000002.608569932.00000000021F0000.00000002.00000001.sdmpBinary or memory string: Progman
Source: TPZi2Evolution des moyens de trasport.exe, 00000001.00000002.608569932.00000000021F0000.00000002.00000001.sdmpBinary or memory string: &Program Manager
Source: TPZi2Evolution des moyens de trasport.exe, 00000001.00000002.608569932.00000000021F0000.00000002.00000001.sdmpBinary or memory string: Progmanlock
Source: C:\Users\user\Desktop\TPZi2Evolution des moyens de trasport.exeKey value queried: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Cryptography MachineGuidJump to behavior

Mitre Att&ck Matrix

Initial AccessExecutionPersistencePrivilege EscalationDefense EvasionCredential AccessDiscoveryLateral MovementCollectionExfiltrationCommand and ControlNetwork EffectsRemote Service EffectsImpact
Valid AccountsCommand and Scripting Interpreter2DLL Side-Loading1Process Injection1Masquerading11Input Capture2Query Registry1Remote ServicesInput Capture2Exfiltration Over Other Network MediumData ObfuscationEavesdrop on Insecure Network CommunicationRemotely Track Device Without AuthorizationModify System Partition
Default AccountsScheduled Task/JobBoot or Logon Initialization ScriptsDLL Side-Loading1Process Injection1LSASS MemoryProcess Discovery1Remote Desktop ProtocolData from Removable MediaExfiltration Over BluetoothJunk DataExploit SS7 to Redirect Phone Calls/SMSRemotely Wipe Data Without AuthorizationDevice Lockout
Domain AccountsAt (Linux)Logon Script (Windows)Logon Script (Windows)DLL Side-Loading1Security Account ManagerSystem Information Discovery2SMB/Windows Admin SharesData from Network Shared DriveAutomated ExfiltrationSteganographyExploit SS7 to Track Device LocationObtain Device Cloud BackupsDelete Device Data

Behavior Graph

Hide Legend

Legend:

  • Process
  • Signature
  • Created File
  • DNS/IP Info
  • Is Dropped
  • Is Windows Process
  • Number of created Registry Values
  • Number of created Files
  • Visual Basic
  • Delphi
  • Java
  • .Net C# or VB.NET
  • C, C++ or other language
  • Is malicious
  • Internet

Screenshots

Thumbnails

This section contains all screenshots as thumbnails, including those not shown in the slideshow.

windows-stand

Antivirus, Machine Learning and Genetic Malware Detection

Initial Sample

SourceDetectionScannerLabelLink
TPZi2Evolution des moyens de trasport.exe0%VirustotalBrowse
TPZi2Evolution des moyens de trasport.exe2%ReversingLabs

Dropped Files

No Antivirus matches

Unpacked PE Files

No Antivirus matches

Domains

No Antivirus matches

URLs

SourceDetectionScannerLabelLink
https://auth.adobefpl.com/1/0%VirustotalBrowse
https://auth.adobefpl.com/1/0%Avira URL Cloudsafe
http://ocsp.thawte.com00%URL Reputationsafe
http://ocsp.thawte.com00%URL Reputationsafe
http://ocsp.thawte.com00%URL Reputationsafe
http://ocsp.thawte.com00%URL Reputationsafe
https://primetimeenablement.sc.omtrdc.net/b/ss//6primesample20%Avira URL Cloudsafe
http://%shttp://a.SharedObject.BadPersistenceSharedObject.UriMismatchpending.heu.swz0%Avira URL Cloudsafe
http://cdn2.auditude.com/assets/3p/vService0%Avira URL Cloudsafe
http://ad./adserver/e?type=playererrorhttp://ad.auditude.com/adserver/e?type=playererror//_.dashmpd&0%Avira URL Cloudsafe
http://dashif.org/guidelines/trickmode10%Avira URL Cloudsafe
http://www.macromedia.comhttps://www.macromedia.com/support/flashplayer/sys/&amp0%Avira URL Cloudsafe
https://primetimeenablement.sc.omtrdc.net/b/ss//60%Avira URL Cloudsafe
http://ad.auditude.com/adserver/e?type=playererror0%Avira URL Cloudsafe
http://dashif.org/guidelines/trickmode0%Avira URL Cloudsafe
http://ad./adserver?tm=15&u=&u=&l=&z=&of=1.4&g=Auditude0%Avira URL Cloudsafe
http://cdn2.auditude.com/assets/3p/v0%Avira URL Cloudsafe

Domains and IPs

Contacted Domains

No contacted domains info

URLs from Memory and Binaries

NameSourceMaliciousAntivirus DetectionReputation
http://www.macromedia.comTPZi2Evolution des moyens de trasport.exefalse
    high
    https://www.macromedia.com/support/flashplayer/sys/xTPZi2Evolution des moyens de trasport.exe, 00000001.00000002.612301693.0000000005815000.00000004.00000040.sdmpfalse
      high
      https://auth.adobefpl.com/1/TPZi2Evolution des moyens de trasport.exefalse
      • 0%, Virustotal, Browse
      • Avira URL Cloud: safe
      unknown
      https://www.macromedia.com/support/flashplayer/sys/rsTPZi2Evolution des moyens de trasport.exe, 00000001.00000002.612301693.0000000005815000.00000004.00000040.sdmpfalse
        high
        http://ocsp.thawte.com0TPZi2Evolution des moyens de trasport.exefalse
        • URL Reputation: safe
        • URL Reputation: safe
        • URL Reputation: safe
        • URL Reputation: safe
        unknown
        https://www.macromedia.com/support/flashplayer/sys/.TPZi2Evolution des moyens de trasport.exe, 00000001.00000002.612301693.0000000005815000.00000004.00000040.sdmpfalse
          high
          https://primetimeenablement.sc.omtrdc.net/b/ss//6primesample2TPZi2Evolution des moyens de trasport.exefalse
          • Avira URL Cloud: safe
          unknown
          http://%shttp://a.SharedObject.BadPersistenceSharedObject.UriMismatchpending.heu.swzTPZi2Evolution des moyens de trasport.exefalse
          • Avira URL Cloud: safe
          low
          http://s3.amazonaws.com/venkat-test/ads/camry/file-640k.m3u82LTPZi2Evolution des moyens de trasport.exefalse
            high
            http://cdn2.auditude.com/assets/3p/vServiceTPZi2Evolution des moyens de trasport.exefalse
            • Avira URL Cloud: safe
            unknown
            http://s3.amazonaws.com/venkat-test/ads/camry/file-640k.m3u8TPZi2Evolution des moyens de trasport.exefalse
              high
              http://crl.thawte.com/ThawteTimestampingCA.crl0TPZi2Evolution des moyens de trasport.exefalse
                high
                http://www.macromedia.com/go/player_settings_TPZi2Evolution des moyens de trasport.exefalse
                  high
                  http://ad./adserver/e?type=playererrorhttp://ad.auditude.com/adserver/e?type=playererror//_.dashmpd&TPZi2Evolution des moyens de trasport.exefalse
                  • Avira URL Cloud: safe
                  unknown
                  http://dashif.org/guidelines/trickmode1TPZi2Evolution des moyens de trasport.exefalse
                  • Avira URL Cloud: safe
                  unknown
                  http://fpdownload2.macromedia.com/get/TPZi2Evolution des moyens de trasport.exefalse
                    high
                    http://www.macromedia.comhttps://www.macromedia.com/support/flashplayer/sys/&ampTPZi2Evolution des moyens de trasport.exefalse
                    • Avira URL Cloud: safe
                    unknown
                    https://primetimeenablement.sc.omtrdc.net/b/ss//6TPZi2Evolution des moyens de trasport.exefalse
                    • Avira URL Cloud: safe
                    unknown
                    http://ad.auditude.com/adserver/e?type=playererrorTPZi2Evolution des moyens de trasport.exefalse
                    • Avira URL Cloud: safe
                    unknown
                    http://dashif.org/guidelines/trickmodeTPZi2Evolution des moyens de trasport.exefalse
                    • Avira URL Cloud: safe
                    unknown
                    https://ats.macromedia.com/Players/ATS/ATS10AS3/Shipping/html/Security/ProtectedMode/PenTestDriverDLTPZi2Evolution des moyens de trasport.exefalse
                      high
                      http://www.macromedia.com/go/player_settings_.Unmuted.MutedCamera.UnmutedCamera.MutedMicrophone.UnmuTPZi2Evolution des moyens de trasport.exefalse
                        high
                        http://ad./adserver?tm=15&u=&u=&l=&z=&of=1.4&g=AuditudeTPZi2Evolution des moyens de trasport.exefalse
                        • Avira URL Cloud: safe
                        unknown
                        https://www.macromedia.com/bin/flashdownload.cgiTPZi2Evolution des moyens de trasport.exefalse
                          high
                          https://www.macromedia.com/support/flashplayer/sys/TPZi2Evolution des moyens de trasport.exefalse
                            high
                            https://fpdownload.macromedia.com/get/TPZi2Evolution des moyens de trasport.exefalse
                              high
                              http://cdn2.auditude.com/assets/3p/vTPZi2Evolution des moyens de trasport.exefalse
                              • Avira URL Cloud: safe
                              unknown
                              http://fpdownload2.macromedia.com/get/https://fpdownload.macromedia.com/get/https://www.macromedia.cTPZi2Evolution des moyens de trasport.exefalse
                                high

                                Contacted IPs

                                No contacted IP infos

                                General Information

                                Joe Sandbox Version:31.0.0 Emerald
                                Analysis ID:385486
                                Start date:12.04.2021
                                Start time:15:26:52
                                Joe Sandbox Product:CloudBasic
                                Overall analysis duration:0h 5m 25s
                                Hypervisor based Inspection enabled:false
                                Report type:full
                                Sample file name:TPZi2Evolution des moyens de trasport.exe
                                Cookbook file name:default.jbs
                                Analysis system description:Windows 10 64 bit v1803 with Office Professional Plus 2016, Chrome 85, IE 11, Adobe Reader DC 19, Java 8 Update 211
                                Number of analysed new started processes analysed:22
                                Number of new started drivers analysed:0
                                Number of existing processes analysed:0
                                Number of existing drivers analysed:0
                                Number of injected processes analysed:0
                                Technologies:
                                • HCA enabled
                                • EGA enabled
                                • HDC enabled
                                • AMSI enabled
                                Analysis Mode:default
                                Analysis stop reason:Timeout
                                Detection:MAL
                                Classification:mal48.winEXE@1/1@0/0
                                EGA Information:Failed
                                HDC Information:Failed
                                HCA Information:Failed
                                Cookbook Comments:
                                • Adjust boot time
                                • Enable AMSI
                                • Found application associated with file extension: .exe
                                Warnings:
                                Show All
                                • Exclude process from analysis (whitelisted): MpCmdRun.exe, audiodg.exe, BackgroundTransferHost.exe, WMIADAP.exe, backgroundTaskHost.exe, conhost.exe, svchost.exe, wuapihost.exe
                                • Report size getting too big, too many NtAllocateVirtualMemory calls found.
                                • Report size getting too big, too many NtQueryValueKey calls found.

                                Simulations

                                Behavior and APIs

                                No simulations

                                Joe Sandbox View / Context

                                IPs

                                No context

                                Domains

                                No context

                                ASN

                                No context

                                JA3 Fingerprints

                                No context

                                Dropped Files

                                No context

                                Created / dropped Files

                                C:\Users\user\AppData\Roaming\Macromedia\Flash Player\macromedia.com\support\flashplayer\sys\settings.sxx
                                Process:C:\Users\user\Desktop\TPZi2Evolution des moyens de trasport.exe
                                File Type:data
                                Category:dropped
                                Size (bytes):3058
                                Entropy (8bit):4.522136039388766
                                Encrypted:false
                                SSDEEP:48:rFyq96326q6pA6pR6p9s6p9CiHF6p9Cid6p9Ciy6p9CiG6p9Ci+:KFhher3rCJrCHrC0rCErC
                                MD5:2B7040E47AF0BF2F2571CB0D62915E24
                                SHA1:992CF691BC68865A9A0C38FF3FD204ACD2AEB28E
                                SHA-256:B54E96CCD7489B3ACDD276B7853F91167E3BBF1584F66653945BE17909442FD0
                                SHA-512:B35D7279523DE13D9C995AE374DE51C4EF291737ED3835BBEC6E39668E7E696323921AFCAF39FFDD5AC1F62F836B286E6C8FEF6623C04E82853753B184A6471B
                                Malicious:false
                                Reputation:low
                                Preview: .....(TCSO........settings......gain.@I............<TCSO........settings......gain.@I.........echosuppression........STCSO........settings......gain.@I.........echosuppression.....defaultmicrophone.........fTCSO........settings......gain.@I.........echosuppression.....defaultmicrophone......defaultcamera..........TCSO........settings......gain.@I.........echosuppression.....defaultmicrophone......defaultcamera......defaultklimit.@Y.............TCSO........settings......gain.@I.........echosuppression.....defaultmicrophone......defaultcamera......defaultklimit.@Y.........defaultalways.........TCSO........settings......gain.@I.........echosuppression.....defaultmicrophone......defaultcamera......defaultklimit.@Y.........defaultalways.....windowlessDisable.........TCSO........settings......gain.@I.........echosuppression.....defaultmicrophone......defaultcamera......defaultklimit.@Y.........defaultalways.....windowlessDisable.....crossdomainAllow.........TCSO........settings......gain.@I.

                                Static File Info

                                General

                                File type:PE32 executable (GUI) Intel 80386, for MS Windows
                                Entropy (8bit):6.987146009315598
                                TrID:
                                • Win32 Executable (generic) a (10002005/4) 99.96%
                                • Generic Win/DOS Executable (2004/3) 0.02%
                                • DOS Executable Generic (2002/1) 0.02%
                                • Autodesk FLIC Image File (extensions: flc, fli, cel) (7/3) 0.00%
                                File name:TPZi2Evolution des moyens de trasport.exe
                                File size:17140460
                                MD5:3ffead9503aef3dd3c60fc58b0c41d01
                                SHA1:94596dc41a99f7e6c3f5209e3d65d797082ec93b
                                SHA256:fc3adb1a06fb6e66dc53ad01726b85af4c296a3438a49df73b98b7d481f6d154
                                SHA512:029d2d3e473aa3242b3ed1e744c243366b8126c11dfa349a5fb71c7696a48348ac85f30d2961b0f5752e036c8f5af3543d782ffa0332f2d4cc1495fee5a7010a
                                SSDEEP:393216:zmZhRuI5NoDil/XS8SOzzX/Zi3+Af1oRSqnmaBJ7:zmZhRTl9Dyf12SB4d
                                File Content Preview:MZ......................@...................................(...........!..L.!This program cannot be run in DOS mode....$........[.E.:...:...:...uz..:...By..:...:...:...Be..:.......:.......:..k5...:...:..(8.......:...Bo.6;...hh..:...Bh.O>...B~..:...hx..:.

                                File Icon

                                Icon Hash:92eae4b2d8889608

                                Static PE Info

                                General

                                Entrypoint:0xc969e2
                                Entrypoint Section:.text
                                Digitally signed:true
                                Imagebase:0x400000
                                Subsystem:windows gui
                                Image File Characteristics:32BIT_MACHINE, EXECUTABLE_IMAGE
                                DLL Characteristics:TERMINAL_SERVER_AWARE, DYNAMIC_BASE, NX_COMPAT
                                Time Stamp:0x57C4C9DD [Mon Aug 29 23:48:45 2016 UTC]
                                TLS Callbacks:
                                CLR (.Net) Version:
                                OS Version Major:5
                                OS Version Minor:0
                                File Version Major:5
                                File Version Minor:0
                                Subsystem Version Major:5
                                Subsystem Version Minor:0
                                Import Hash:ac44d030aac7077131ee014b7adc735c

                                Authenticode Signature

                                Signature Valid:
                                Signature Issuer:
                                Signature Validation Error:
                                Error Number:
                                Not Before, Not After
                                  Subject Chain
                                    Version:
                                    Thumbprint MD5:
                                    Thumbprint SHA-1:
                                    Thumbprint SHA-256:
                                    Serial:

                                    Entrypoint Preview

                                    Instruction
                                    call 00007F1584EB828Dh
                                    jmp 00007F1584EAD95Dh
                                    mov edi, edi
                                    push ebp
                                    mov ebp, esp
                                    mov eax, dword ptr [ebp+08h]
                                    push esi
                                    mov esi, ecx
                                    mov byte ptr [esi+0Ch], 00000000h
                                    test eax, eax
                                    jne 00007F1584EADB45h
                                    call 00007F1584EB713Eh
                                    mov dword ptr [esi+08h], eax
                                    mov ecx, dword ptr [eax+6Ch]
                                    mov dword ptr [esi], ecx
                                    mov ecx, dword ptr [eax+68h]
                                    mov dword ptr [esi+04h], ecx
                                    mov ecx, dword ptr [esi]
                                    cmp ecx, dword ptr [00FFB9D0h]
                                    je 00007F1584EADAF4h
                                    mov ecx, dword ptr [00FFB8ECh]
                                    test dword ptr [eax+70h], ecx
                                    jne 00007F1584EADAE9h
                                    call 00007F1584EB8C70h
                                    mov dword ptr [esi], eax
                                    mov eax, dword ptr [esi+04h]
                                    cmp eax, dword ptr [00FFB7F0h]
                                    je 00007F1584EADAF8h
                                    mov eax, dword ptr [esi+08h]
                                    mov ecx, dword ptr [00FFB8ECh]
                                    test dword ptr [eax+70h], ecx
                                    jne 00007F1584EADAEAh
                                    call 00007F1584EB84E4h
                                    mov dword ptr [esi+04h], eax
                                    mov eax, dword ptr [esi+08h]
                                    test byte ptr [eax+70h], 00000002h
                                    jne 00007F1584EADAF6h
                                    or dword ptr [eax+70h], 02h
                                    mov byte ptr [esi+0Ch], 00000001h
                                    jmp 00007F1584EADAECh
                                    mov ecx, dword ptr [eax]
                                    mov dword ptr [esi], ecx
                                    mov eax, dword ptr [eax+04h]
                                    mov dword ptr [esi+04h], eax
                                    mov eax, esi
                                    pop esi
                                    pop ebp
                                    retn 0004h
                                    mov edi, edi
                                    push ebp
                                    mov ebp, esp
                                    sub esp, 10h
                                    push dword ptr [ebp+0Ch]
                                    lea ecx, dword ptr [ebp-10h]
                                    call 00007F1584EADA4Bh
                                    mov eax, dword ptr [ebp-10h]
                                    cmp dword ptr [eax+000000ACh], 01h
                                    jle 00007F1584EADAF8h
                                    lea eax, dword ptr [ebp-10h]
                                    push eax
                                    push 00000103h
                                    push dword ptr [ebp+08h]
                                    call 00007F1584EB8C6Fh
                                    add esp, 0Ch
                                    jmp 00007F1584EADAF4h
                                    mov eax, dword ptr [eax+00000000h]

                                    Rich Headers

                                    Programming Language:
                                    • [ASM] VS2008 SP1 build 30729
                                    • [ C ] VS2008 SP1 build 30729
                                    • [ C ] VS2005 build 50727
                                    • [C++] VS2005 build 50727
                                    • [IMP] VS2005 build 50727
                                    • [RES] VS2008 build 21022
                                    • [C++] VS2008 build 21022
                                    • [EXP] VS2008 SP1 build 30729
                                    • [C++] VS2008 SP1 build 30729

                                    Data Directories

                                    NameVirtual AddressVirtual Size Is in Section
                                    IMAGE_DIRECTORY_ENTRY_EXPORT0xb2e2e00xd2.rdata
                                    IMAGE_DIRECTORY_ENTRY_IMPORT0xb2ce6c0x3c.rdata
                                    IMAGE_DIRECTORY_ENTRY_RESOURCE0xcec0000x1c1044.rsrc
                                    IMAGE_DIRECTORY_ENTRY_EXCEPTION0x00x0
                                    IMAGE_DIRECTORY_ENTRY_SECURITY0xe2b8000x18f8.rsrc
                                    IMAGE_DIRECTORY_ENTRY_BASERELOC0xeae0000x542a0.reloc
                                    IMAGE_DIRECTORY_ENTRY_DEBUG0x956a000x1c.rdata
                                    IMAGE_DIRECTORY_ENTRY_COPYRIGHT0x00x0
                                    IMAGE_DIRECTORY_ENTRY_GLOBALPTR0x00x0
                                    IMAGE_DIRECTORY_ENTRY_TLS0x00x0
                                    IMAGE_DIRECTORY_ENTRY_LOAD_CONFIG0xaf7d400x40.rdata
                                    IMAGE_DIRECTORY_ENTRY_BOUND_IMPORT0x00x0
                                    IMAGE_DIRECTORY_ENTRY_IAT0x9560000x38c.rdata
                                    IMAGE_DIRECTORY_ENTRY_DELAY_IMPORT0xb2a5b80x220.rdata
                                    IMAGE_DIRECTORY_ENTRY_COM_DESCRIPTOR0x00x0
                                    IMAGE_DIRECTORY_ENTRY_RESERVED0x00x0

                                    Sections

                                    NameVirtual AddressVirtual SizeRaw SizeXored PEZLIB ComplexityFile TypeEntropyCharacteristics
                                    .text0x10000x952ada0x952c00unknownunknownunknownunknownIMAGE_SCN_MEM_EXECUTE, IMAGE_SCN_CNT_CODE, IMAGE_SCN_MEM_READ
                                    .rodata0x9540000x10e00x1200False0.215277777778data4.16783024928IMAGE_SCN_MEM_EXECUTE, IMAGE_SCN_CNT_CODE, IMAGE_SCN_MEM_READ
                                    .rdata0x9560000x1d83b20x1d8400False0.435927367324data6.53070366078IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_READ
                                    .data0xb2f0000x1bc1880xcec00False0.745528123111data7.53274240162IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_WRITE, IMAGE_SCN_MEM_READ
                                    .rsrc0xcec0000x1c10440x1c1200False0.057476669044data4.32823409135IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_READ
                                    .reloc0xeae0000x6f3b00x6f400False0.323817152388data5.57559035468IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_DISCARDABLE, IMAGE_SCN_MEM_READ

                                    Resources

                                    NameRVASizeTypeLanguageCountry
                                    RT_CURSOR0xcedd080x134dataEnglishUnited States
                                    RT_CURSOR0xcede3c0xb4dataEnglishUnited States
                                    RT_CURSOR0xcedef00x134dataEnglishUnited States
                                    RT_ICON0xcee0240x42028dBase III DBT, version number 0, next free block index 40EnglishUnited States
                                    RT_ICON0xd3004c0x25a8dataEnglishUnited States
                                    RT_ICON0xd325f40x10a8dataEnglishUnited States
                                    RT_ICON0xd3369c0x988dataEnglishUnited States
                                    RT_ICON0xd340240x468GLS_BINARY_LSB_FIRSTEnglishUnited States
                                    RT_ICON0xd3448c0xea8dBase III DBT, version number 0, next free block index 40EnglishUnited States
                                    RT_ICON0xd353340x8a8dBase III DBT, version number 0, next free block index 40EnglishUnited States
                                    RT_ICON0xd35bdc0x568GLS_BINARY_LSB_FIRSTEnglishUnited States
                                    RT_ICON0xd361440x42028dBase III DBT, version number 0, next free block index 40EnglishUnited States
                                    RT_ICON0xd7816c0x25a8dataEnglishUnited States
                                    RT_ICON0xd7a7140x10a8dataEnglishUnited States
                                    RT_ICON0xd7b7bc0x468GLS_BINARY_LSB_FIRSTEnglishUnited States
                                    RT_ICON0xd7bc240xea8dBase III DBT, version number 0, next free block index 40EnglishUnited States
                                    RT_ICON0xd7cacc0x8a8dBase III DBT, version number 0, next free block index 40EnglishUnited States
                                    RT_ICON0xd7d3740x568GLS_BINARY_LSB_FIRSTEnglishUnited States
                                    RT_ICON0xd7d8dc0x42028dBase III DBT, version number 0, next free block index 40EnglishUnited States
                                    RT_ICON0xdbf9040x25a8dataEnglishUnited States
                                    RT_ICON0xdc1eac0x10a8dataEnglishUnited States
                                    RT_ICON0xdc2f540x468GLS_BINARY_LSB_FIRSTEnglishUnited States
                                    RT_ICON0xdc33bc0xea8dBase III DBT, version number 0, next free block index 40EnglishUnited States
                                    RT_ICON0xdc42640x8a8dBase III DBT, version number 0, next free block index 40EnglishUnited States
                                    RT_ICON0xdc4b0c0x568GLS_BINARY_LSB_FIRSTEnglishUnited States
                                    RT_ICON0xdc50740x42028dBase III DBT, version number 0, next free block index 40EnglishUnited States
                                    RT_ICON0xe0709c0x25a8dataEnglishUnited States
                                    RT_ICON0xe096440x10a8dataEnglishUnited States
                                    RT_ICON0xe0a6ec0x468GLS_BINARY_LSB_FIRSTEnglishUnited States
                                    RT_ICON0xe0ab540xea8dBase III DBT, version number 0, next free block index 40EnglishUnited States
                                    RT_ICON0xe0b9fc0x8a8dBase III DBT, version number 0, next free block index 40EnglishUnited States
                                    RT_ICON0xe0c2a40x568GLS_BINARY_LSB_FIRSTEnglishUnited States
                                    RT_ICON0xe0c80c0x42028dBase III DBT, version number 0, next free block index 40EnglishUnited States
                                    RT_ICON0xe4e8340x25a8dataEnglishUnited States
                                    RT_ICON0xe50ddc0x10a8dataEnglishUnited States
                                    RT_ICON0xe51e840x468GLS_BINARY_LSB_FIRSTEnglishUnited States
                                    RT_ICON0xe522ec0xea8dBase III DBT, version number 0, next free block index 40EnglishUnited States
                                    RT_ICON0xe531940x8a8dBase III DBT, version number 0, next free block index 40EnglishUnited States
                                    RT_ICON0xe53a3c0x568GLS_BINARY_LSB_FIRSTEnglishUnited States
                                    RT_ICON0xe53fa40x42028dBase III DBT, version number 0, next free block index 40EnglishUnited States
                                    RT_ICON0xe95fcc0x25a8dataEnglishUnited States
                                    RT_ICON0xe985740x10a8dataEnglishUnited States
                                    RT_ICON0xe9961c0x468GLS_BINARY_LSB_FIRSTEnglishUnited States
                                    RT_MENU0xe99a840x300data
                                    RT_MENU0xe99d840x284dataChineseTaiwan
                                    RT_MENU0xe9a0080x358dataCzechCzech Republic
                                    RT_MENU0xe9a3600x34edataGermanGermany
                                    RT_MENU0xe9a6b00x2d4dataEnglishUnited States
                                    RT_MENU0xe9a9840x344dataFrenchFrance
                                    RT_MENU0xe9acc80x314dataItalianItaly
                                    RT_MENU0xe9afdc0x2b2dataJapaneseJapan
                                    RT_MENU0xe9b2900x2a0dataKoreanNorth Korea
                                    RT_MENU0xe9b2900x2a0dataKoreanSouth Korea
                                    RT_MENU0xe9b5300x35adataDutchNetherlands
                                    RT_MENU0xe9b88c0x330dataPolishPoland
                                    RT_MENU0xe9bbbc0x33edataPortugueseBrazil
                                    RT_MENU0xe9befc0x366dataRussianRussia
                                    RT_MENU0xe9c2640x300dataTurkishTurkey
                                    RT_MENU0xe9c5640x27adataChineseChina
                                    RT_MENU0xe9c7e00x30cdata
                                    RT_MENU0xe9caec0x23adata
                                    RT_MENU0xe9cd280x136dataChineseTaiwan
                                    RT_MENU0xe9ce600x250dataCzechCzech Republic
                                    RT_MENU0xe9d0b00x236dataGermanGermany
                                    RT_MENU0xe9d2e80x1f0dataEnglishUnited States
                                    RT_MENU0xe9d4d80x244dataFrenchFrance
                                    RT_MENU0xe9d71c0x228dataItalianItaly
                                    RT_MENU0xe9d9440x158dataJapaneseJapan
                                    RT_MENU0xe9da9c0x15cdataKoreanNorth Korea
                                    RT_MENU0xe9da9c0x15cdataKoreanSouth Korea
                                    RT_MENU0xe9dbf80x258dataDutchNetherlands
                                    RT_MENU0xe9de500x246dataPolishPoland
                                    RT_MENU0xe9e0980x24adataPortugueseBrazil
                                    RT_MENU0xe9e2e40x26cdataRussianRussia
                                    RT_MENU0xe9e5500x216dataTurkishTurkey
                                    RT_MENU0xe9e7680x142dataChineseChina
                                    RT_MENU0xe9e8ac0x220data
                                    RT_MENU0xe9eacc0x92data
                                    RT_MENU0xe9eb600x6adataChineseTaiwan
                                    RT_MENU0xe9ebcc0x8adataCzechCzech Republic
                                    RT_MENU0xe9ec580x9cdataGermanGermany
                                    RT_MENU0xe9ecf40x70dataEnglishUnited States
                                    RT_MENU0xe9ed640x90dataFrenchFrance
                                    RT_MENU0xe9edf40x88dataItalianItaly
                                    RT_MENU0xe9ee7c0x7adataJapaneseJapan
                                    RT_MENU0xe9eef80x78dataKoreanNorth Korea
                                    RT_MENU0xe9eef80x78dataKoreanSouth Korea
                                    RT_MENU0xe9ef700x9cdataDutchNetherlands
                                    RT_MENU0xe9f00c0x82dataPolishPoland
                                    RT_MENU0xe9f0900x8adataPortugueseBrazil
                                    RT_MENU0xe9f11c0x92dataRussianRussia
                                    RT_MENU0xe9f1b00x76dataTurkishTurkey
                                    RT_MENU0xe9f2280x6adataChineseChina
                                    RT_MENU0xe9f2940x8cdata
                                    RT_MENU0xe9f3200x50data
                                    RT_MENU0xe9f3700x34dataChineseTaiwan
                                    RT_MENU0xe9f3a40x5edataCzechCzech Republic
                                    RT_MENU0xe9f4040x6adataGermanGermany
                                    RT_MENU0xe9f4700x4cdataEnglishUnited States
                                    RT_MENU0xe9f4bc0x62dataFrenchFrance
                                    RT_MENU0xe9f5200x5edataItalianItaly
                                    RT_MENU0xe9f5800x3edataJapaneseJapan
                                    RT_MENU0xe9f5c00x38dataKoreanNorth Korea
                                    RT_MENU0xe9f5c00x38dataKoreanSouth Korea
                                    RT_MENU0xe9f5f80x60dataDutchNetherlands
                                    RT_MENU0xe9f6580x58dataPolishPoland
                                    RT_MENU0xe9f6b00x52dataPortugueseBrazil
                                    RT_MENU0xe9f7040x6edataRussianRussia
                                    RT_MENU0xe9f7740x5cdataTurkishTurkey
                                    RT_MENU0xe9f7d00x34dataChineseChina
                                    RT_MENU0xe9f8040x60data
                                    RT_DIALOG0xe9f8640x1eadata
                                    RT_DIALOG0xe9fa500x1e2dataChineseTaiwan
                                    RT_DIALOG0xe9fc340x1e2dataCzechCzech Republic
                                    RT_DIALOG0xe9fe180x1e2dataGermanGermany
                                    RT_DIALOG0xe9fffc0x1e2dataEnglishUnited States
                                    RT_DIALOG0xea01e00x1e2dataFrenchFrance
                                    RT_DIALOG0xea03c40x1e2dataItalianItaly
                                    RT_DIALOG0xea05a80x1e6dataJapaneseJapan
                                    RT_DIALOG0xea07900x1e2dataKoreanNorth Korea
                                    RT_DIALOG0xea07900x1e2dataKoreanSouth Korea
                                    RT_DIALOG0xea09740x1e6dataDutchNetherlands
                                    RT_DIALOG0xea0b5c0x1e2dataPolishPoland
                                    RT_DIALOG0xea0d400x1e6dataPortugueseBrazil
                                    RT_DIALOG0xea0f280x1e6dataRussianRussia
                                    RT_DIALOG0xea11100x1e6dataTurkishTurkey
                                    RT_DIALOG0xea12f80x1e6dataChineseChina
                                    RT_DIALOG0xea14e00x1eedata
                                    RT_DIALOG0xea16d00x1a4data
                                    RT_DIALOG0xea18740x138dataChineseTaiwan
                                    RT_DIALOG0xea19ac0x1dcdataCzechCzech Republic
                                    RT_DIALOG0xea1b880x1d0dataGermanGermany
                                    RT_DIALOG0xea1d580x1cadataEnglishUnited States
                                    RT_DIALOG0xea1f240x1b8dataFrenchFrance
                                    RT_DIALOG0xea20dc0x1c0dataItalianItaly
                                    RT_DIALOG0xea229c0x170dataJapaneseJapan
                                    RT_DIALOG0xea240c0x148dataKoreanNorth Korea
                                    RT_DIALOG0xea240c0x148dataKoreanSouth Korea
                                    RT_DIALOG0xea25540x1dedataDutchNetherlands
                                    RT_DIALOG0xea27340x1cedataPolishPoland
                                    RT_DIALOG0xea29040x1cadataPortugueseBrazil
                                    RT_DIALOG0xea2ad00x1d0dataRussianRussia
                                    RT_DIALOG0xea2ca00x1b0dataTurkishTurkey
                                    RT_DIALOG0xea2e500x138dataChineseChina
                                    RT_DIALOG0xea2f880x1cedata
                                    RT_DIALOG0xea31580x60dataEnglishUnited States
                                    RT_DIALOG0xea31b80x456data
                                    RT_DIALOG0xea36100x2b2dataChineseTaiwan
                                    RT_DIALOG0xea38c40x466dataCzechCzech Republic
                                    RT_DIALOG0xea3d2c0x4b2dataGermanGermany
                                    RT_DIALOG0xea41e00x434dataEnglishUnited States
                                    RT_DIALOG0xea46140x4dcdataFrenchFrance
                                    RT_DIALOG0xea4af00x48cdataItalianItaly
                                    RT_DIALOG0xea4f7c0x32adataJapaneseJapan
                                    RT_DIALOG0xea52a80x32adataKoreanNorth Korea
                                    RT_DIALOG0xea52a80x32adataKoreanSouth Korea
                                    RT_DIALOG0xea55d40x47cdataDutchNetherlands
                                    RT_DIALOG0xea5a500x4b0dataPolishPoland
                                    RT_DIALOG0xea5f000x46edataPortugueseBrazil
                                    RT_DIALOG0xea63700x46adataRussianRussia
                                    RT_DIALOG0xea67dc0x442dataTurkishTurkey
                                    RT_DIALOG0xea6c200x2badataChineseChina
                                    RT_DIALOG0xea6edc0x2b2dataChineseChina
                                    RT_DIALOG0xea71900x47adata
                                    RT_STRING0xea760c0x26edata
                                    RT_STRING0xea787c0x24adataChineseTaiwan
                                    RT_STRING0xea7ac80x274dataCzechCzech Republic
                                    RT_STRING0xea7d3c0x274dataGermanGermany
                                    RT_STRING0xea7fb00x26edataEnglishUnited States
                                    RT_STRING0xea82200x280dataFrenchFrance
                                    RT_STRING0xea84a00x278dataItalianItaly
                                    RT_STRING0xea87180x264dataJapaneseJapan
                                    RT_STRING0xea897c0x250dataKoreanNorth Korea
                                    RT_STRING0xea897c0x250dataKoreanSouth Korea
                                    RT_STRING0xea8bcc0x294dataDutchNetherlands
                                    RT_STRING0xea8e600x274dataPolishPoland
                                    RT_STRING0xea90d40x280dataPortugueseBrazil
                                    RT_STRING0xea93540x26cdataRussianRussia
                                    RT_STRING0xea95c00x276dataTurkishTurkey
                                    RT_STRING0xea98380x24adataChineseChina
                                    RT_STRING0xea9a840x286data
                                    RT_STRING0xea9d0c0x11cdata
                                    RT_STRING0xea9e280x6cdataChineseTaiwan
                                    RT_STRING0xea9e940x138dataCzechCzech Republic
                                    RT_STRING0xea9fcc0x14edataGermanGermany
                                    RT_STRING0xeaa11c0x106dataEnglishUnited States
                                    RT_STRING0xeaa2240x152dataFrenchFrance
                                    RT_STRING0xeaa3780x138dataItalianItaly
                                    RT_STRING0xeaa4b00xb0dataJapaneseJapan
                                    RT_STRING0xeaa5600xa0dataKoreanNorth Korea
                                    RT_STRING0xeaa5600xa0dataKoreanSouth Korea
                                    RT_STRING0xeaa6000x162dataDutchNetherlands
                                    RT_STRING0xeaa7640x15adataPolishPoland
                                    RT_STRING0xeaa8c00x110dataPortugueseBrazil
                                    RT_STRING0xeaa9d00x140dataRussianRussia
                                    RT_STRING0xeaab100x122dataTurkishTurkey
                                    RT_STRING0xeaac340x74dataChineseChina
                                    RT_STRING0xeaaca80x138data
                                    RT_STRING0xeaade00xecdata
                                    RT_STRING0xeaaecc0x7adataChineseTaiwan
                                    RT_STRING0xeaaf480x154dataCzechCzech Republic
                                    RT_STRING0xeab09c0x10cdataGermanGermany
                                    RT_STRING0xeab1a80xcadataEnglishUnited States
                                    RT_STRING0xeab2740x106dataFrenchFrance
                                    RT_STRING0xeab37c0xfadataItalianItaly
                                    RT_STRING0xeab4780x8edataJapaneseJapan
                                    RT_STRING0xeab5080x7cdataKoreanNorth Korea
                                    RT_STRING0xeab5080x7cdataKoreanSouth Korea
                                    RT_STRING0xeab5840x134dataDutchNetherlands
                                    RT_STRING0xeab6b80xe4dataPolishPoland
                                    RT_STRING0xeab79c0xf2dataPortugueseBrazil
                                    RT_STRING0xeab8900x114dataRussianRussia
                                    RT_STRING0xeab9a40xb8dataTurkishTurkey
                                    RT_STRING0xeaba5c0x6edataChineseChina
                                    RT_STRING0xeabacc0x138data
                                    RT_STRING0xeabc040x80data
                                    RT_STRING0xeabc840x52dataChineseTaiwan
                                    RT_STRING0xeabcd80x9adataCzechCzech Republic
                                    RT_STRING0xeabd740xaadataGermanGermany
                                    RT_STRING0xeabe200x98dataEnglishUnited States
                                    RT_STRING0xeabeb80xd6dataFrenchFrance
                                    RT_STRING0xeabf900xaadataItalianItaly
                                    RT_STRING0xeac03c0x72dataJapaneseJapan
                                    RT_STRING0xeac0b00x5adataKoreanNorth Korea
                                    RT_STRING0xeac0b00x5adataKoreanSouth Korea
                                    RT_STRING0xeac10c0xa4dataDutchNetherlands
                                    RT_STRING0xeac1b00x9cdataPolishPoland
                                    RT_STRING0xeac24c0xb2dataPortugueseBrazil
                                    RT_STRING0xeac3000x92dataRussianRussia
                                    RT_STRING0xeac3940x98dataTurkishTurkey
                                    RT_STRING0xeac42c0x52dataChineseChina
                                    RT_STRING0xeac4800x52dataChineseChina
                                    RT_STRING0xeac4d40xc8data
                                    RT_ACCELERATOR0xeac59c0x70dataEnglishUnited States
                                    RT_GROUP_CURSOR0xeac60c0x22Lotus unknown worksheet or configuration, revision 0x2EnglishUnited States
                                    RT_GROUP_CURSOR0xeac6300x14Lotus unknown worksheet or configuration, revision 0x1EnglishUnited States
                                    RT_GROUP_ICON0xeac6440x4cdataEnglishUnited States
                                    RT_GROUP_ICON0xeac6900x68dataEnglishUnited States
                                    RT_GROUP_ICON0xeac6f80x68dataEnglishUnited States
                                    RT_GROUP_ICON0xeac7600x68dataEnglishUnited States
                                    RT_GROUP_ICON0xeac7c80x68dataEnglishUnited States
                                    RT_GROUP_ICON0xeac8300x68dataEnglishUnited States
                                    RT_VERSION0xeac8980x4f8dataEnglishUnited States
                                    RT_MANIFEST0xeacd900x2b2ASCII text, with CRLF line terminatorsEnglishUnited States

                                    Imports

                                    DLLImport
                                    KERNEL32.dllWaitForSingleObject, GetProcAddress, GetModuleHandleW, ReadFile, SetFilePointer, GetFileSize, CreateFileW, GetModuleFileNameA, GetCommandLineW, SetEndOfFile, WriteFile, CreateFileA, GetFileAttributesA, GetStartupInfoW, GetCommandLineA, ExitProcess, RemoveDirectoryW, CopyFileW, GetModuleFileNameW, GetCPInfo, GetACP, IsDBCSLeadByte, HeapSize, DeviceIoControl, CreateProcessA, GetTempPathA, FindNextFileW, GetSystemWow64DirectoryW, ExpandEnvironmentStringsA, WideCharToMultiByte, MultiByteToWideChar, lstrlenW, GetLongPathNameW, CreateProcessW, GetTempFileNameA, CreateDirectoryA, DeleteFileA, GetFileAttributesW, CreateMutexA, SetFilePointerEx, GetFileSizeEx, GetFileAttributesExW, GetFileInformationByHandle, GetVolumeInformationW, MoveFileExW, GetCurrentDirectoryW, SetCurrentDirectoryW, GetFullPathNameW, ExpandEnvironmentStringsW, OutputDebugStringA, LoadLibraryA, GetSystemDirectoryA, FreeLibrary, GetVersionExW, GetCurrentProcess, VirtualQuery, ExitThread, GetUserDefaultLangID, GetUserDefaultUILanguage, VerifyVersionInfoW, VerSetConditionMask, GlobalFree, CreateThread, LockResource, LoadResource, FindResourceExA, FindResourceExW, GlobalAlloc, DebugBreak, GlobalUnlock, GlobalLock, QueryPerformanceCounter, QueryPerformanceFrequency, GlobalSize, QueueUserAPC, OpenThread, SleepEx, SetUnhandledExceptionFilter, GetCurrentProcessId, GetProcessTimes, RaiseException, FlushInstructionCache, SetLastError, TerminateThread, CreateEventW, SetEvent, ResetEvent, WaitForMultipleObjects, GetExitCodeProcess, GetTickCount, SetThreadPriority, GetTimeZoneInformation, GetSystemTime, SystemTimeToFileTime, GetLocaleInfoW, LCMapStringW, GetExitCodeThread, DuplicateHandle, GetCurrentThread, MapViewOfFile, UnmapViewOfFile, CompareFileTime, LocalFree, ReleaseMutex, CreateFileMappingA, ReleaseSemaphore, CreateSemaphoreW, SetThreadAffinityMask, CreateEventA, CreateWaitableTimerA, SetWaitableTimer, CancelWaitableTimer, InterlockedExchangeAdd, GetVersionExA, GetVersion, VirtualAlloc, VirtualFree, FlushFileBuffers, GlobalMemoryStatusEx, IsDebuggerPresent, SetSystemTime, FileTimeToSystemTime, TlsAlloc, TlsFree, ResumeThread, CreateTimerQueueTimer, DeleteTimerQueueTimer, CreateSemaphoreA, HeapAlloc, HeapFree, HeapUnlock, HeapWalk, HeapLock, HeapCreate, HeapDestroy, VirtualProtect, GetNumberFormatW, GetCurrencyFormatW, CompareStringW, GetDateFormatW, GetTimeFormatW, GetUserDefaultLCID, EnumSystemLocalesW, GetProcessHeap, GetProcessAffinityMask, IsProcessorFeaturePresent, GetStartupInfoA, RtlUnwind, UnhandledExceptionFilter, HeapReAlloc, GetSystemTimeAsFileTime, GetStdHandle, TerminateProcess, FreeEnvironmentStringsA, GetEnvironmentStrings, FreeEnvironmentStringsW, GetEnvironmentStringsW, SetHandleCount, GetFileType, GetOEMCP, IsValidCodePage, LCMapStringA, GetConsoleCP, GetConsoleMode, InitializeCriticalSectionAndSpinCount, SetStdHandle, GetLocaleInfoA, GetStringTypeA, GetStringTypeW, WriteConsoleA, GetConsoleOutputCP, WriteConsoleW, CompareStringA, SetEnvironmentVariableA, LocalAlloc, CloseHandle, FindFirstFileW, FindClose, GetSystemDirectoryW, LoadLibraryW, GetModuleHandleA, GetTempPathW, GetTempFileNameW, GetLastError, DeleteFileW, CreateDirectoryW, GetSystemInfo, SwitchToThread, TlsGetValue, TlsSetValue, GetCurrentThreadId, LeaveCriticalSection, EnterCriticalSection, TryEnterCriticalSection, DeleteCriticalSection, InitializeCriticalSection, InterlockedDecrement, InterlockedIncrement, InterlockedExchange, InterlockedCompareExchange, CreateWaitableTimerW, Sleep
                                    ADVAPI32.dllCryptEncrypt, CryptDestroyKey, CryptImportKey, CryptSetKeyParam, CryptGetHashParam, CryptHashData, CryptDestroyHash, CryptAcquireContextA, CryptCreateHash, RegOpenKeyA, CryptAcquireContextW, CryptGenRandom, CryptReleaseContext, RegOpenKeyExA, RegQueryValueExW, RegSetValueExW, RegCreateKeyExW, RegSetValueExA, RegQueryValueExA, RegCloseKey, RegCreateKeyExA, RegOpenKeyExW, CryptDecrypt

                                    Exports

                                    NameOrdinalAddress
                                    IAEModule_AEModule_PutKernel10x923ed0
                                    IAEModule_IAEKernel_LoadModule20x920150
                                    IAEModule_IAEKernel_UnloadModule30x9201d0
                                    _WinMainSandboxed@2040x41efc7

                                    Version Infos

                                    DescriptionData
                                    LegalCopyrightAdobe Flash Player. Copyright 1996-2016 Adobe Systems Incorporated. All Rights Reserved. Adobe and Flash are either trademarks or registered trademarks in the United States and/or other countries.
                                    InternalNameAdobe Flash Player 23.0
                                    FileVersion23,0,0,162
                                    CompanyNameAdobe Systems, Inc.
                                    LegalTrademarksAdobe Flash Player
                                    ProductNameShockwave Flash
                                    ProductVersion23,0,0,162
                                    FileDescriptionAdobe Flash Player 23.0 r0
                                    OriginalFilenameSAFlashPlayer.exe
                                    Debugger0
                                    Translation0x0409 0x04b0

                                    Possible Origin

                                    Language of compilation systemCountry where language is spokenMap
                                    EnglishUnited States
                                    ChineseTaiwan
                                    CzechCzech Republic
                                    GermanGermany
                                    FrenchFrance
                                    ItalianItaly
                                    JapaneseJapan
                                    KoreanNorth Korea
                                    KoreanSouth Korea
                                    DutchNetherlands
                                    PolishPoland
                                    PortugueseBrazil
                                    RussianRussia
                                    TurkishTurkey
                                    ChineseChina

                                    Network Behavior

                                    No network behavior found

                                    Code Manipulations

                                    Statistics

                                    CPU Usage

                                    Click to jump to process

                                    Memory Usage

                                    Click to jump to process

                                    High Level Behavior Distribution

                                    Click to dive into process behavior distribution

                                    System Behavior

                                    General

                                    Start time:15:27:44
                                    Start date:12/04/2021
                                    Path:C:\Users\user\Desktop\TPZi2Evolution des moyens de trasport.exe
                                    Wow64 process (32bit):true
                                    Commandline:'C:\Users\user\Desktop\TPZi2Evolution des moyens de trasport.exe'
                                    Imagebase:0x12d0000
                                    File size:17140460 bytes
                                    MD5 hash:3FFEAD9503AEF3DD3C60FC58B0C41D01
                                    Has elevated privileges:true
                                    Has administrator privileges:true
                                    Programmed in:C, C++ or other language
                                    Reputation:low

                                    Disassembly

                                    Code Analysis

                                    Reset < >