Analysis Report COVID 19 BENEFIT FORM 2.exe

Overview

General Information

Sample Name: COVID 19 BENEFIT FORM 2.exe
Analysis ID: 397590
MD5: 734dcc6ee873ad6667d9cad4e5040134
SHA1: 205b63e53d5789f469bdfafdfb553e74b967f5df
SHA256: cce12e2162f90a88715e50bfa993e9d3233fecaf608fb18cda68f0154f0e1d5b
Tags: AgentTeslaCOVID-19exe
Infos:

Most interesting Screenshot:

Detection

AgentTesla
Score: 100
Range: 0 - 100
Whitelisted: false
Confidence: 100%

Signatures

Found malware configuration
Multi AV Scanner detection for dropped file
Multi AV Scanner detection for submitted file
Sigma detected: Scheduled temp file as task from temp location
Yara detected AgentTesla
Yara detected AntiVM3
.NET source code contains very large array initializations
Injects a PE file into a foreign processes
Machine Learning detection for dropped file
Machine Learning detection for sample
Queries sensitive BIOS Information (via WMI, Win32_Bios & Win32_BaseBoard, often done to detect virtual machines)
Queries sensitive network adapter information (via WMI, Win32_NetworkAdapter, often done to detect virtual machines)
Tries to detect sandboxes and other dynamic analysis tools (process name or module or function)
Tries to harvest and steal Putty / WinSCP information (sessions, passwords, etc)
Tries to harvest and steal browser information (history, passwords, etc)
Tries to harvest and steal ftp login credentials
Tries to steal Mail credentials (via file access)
Uses schtasks.exe or at.exe to add and modify task schedules
Antivirus or Machine Learning detection for unpacked file
Binary contains a suspicious time stamp
Contains capabilities to detect virtual machines
Contains functionality to access loader functionality (e.g. LdrGetProcedureAddress)
Contains long sleeps (>= 3 min)
Creates a process in suspended mode (likely to inject code)
Creates a window with clipboard capturing capabilities
Detected potential crypto function
Drops PE files
Enables debug privileges
Found a high number of Window / User specific system calls (may be a loop to detect user behavior)
May sleep (evasive loops) to hinder dynamic analysis
Monitors certain registry keys / values for changes (often done to protect autostart functionality)
Queries sensitive processor information (via WMI, Win32_Processor, often done to detect virtual machines)
Queries the volume information (name, serial number etc) of a device
Sample execution stops while process was sleeping (likely an evasion)
Sample file is different than original file name gathered from version info
Uses 32bit PE files
Uses code obfuscation techniques (call, push, ret)
Yara detected Credential Stealer

Classification

AV Detection:

barindex
Found malware configuration
Source: 0.2.COVID 19 BENEFIT FORM 2.exe.4293c80.2.unpack Malware Configuration Extractor: Agenttesla {"Exfil Mode": "SMTP", "SMTP Info": "logs@seedchangeinv.commmm777@@mail.privateemail.com"}
Multi AV Scanner detection for dropped file
Source: C:\Users\user\AppData\Roaming\lVGkcjmu.exe ReversingLabs: Detection: 36%
Multi AV Scanner detection for submitted file
Source: COVID 19 BENEFIT FORM 2.exe Virustotal: Detection: 43% Perma Link
Source: COVID 19 BENEFIT FORM 2.exe ReversingLabs: Detection: 36%
Machine Learning detection for dropped file
Source: C:\Users\user\AppData\Roaming\lVGkcjmu.exe Joe Sandbox ML: detected
Machine Learning detection for sample
Source: COVID 19 BENEFIT FORM 2.exe Joe Sandbox ML: detected
Antivirus or Machine Learning detection for unpacked file
Source: 10.2.COVID 19 BENEFIT FORM 2.exe.400000.0.unpack Avira: Label: TR/Spy.Gen8

Compliance:

barindex
Uses 32bit PE files
Source: COVID 19 BENEFIT FORM 2.exe Static PE information: 32BIT_MACHINE, EXECUTABLE_IMAGE
Source: COVID 19 BENEFIT FORM 2.exe Static PE information: NO_SEH, TERMINAL_SERVER_AWARE, DYNAMIC_BASE, NX_COMPAT
Source: COVID 19 BENEFIT FORM 2.exe, 0000000A.00000002.599311455.0000000002871000.00000004.00000001.sdmp String found in binary or memory: http://127.0.0.1:HTTP/1.1
Source: COVID 19 BENEFIT FORM 2.exe, 0000000A.00000002.599311455.0000000002871000.00000004.00000001.sdmp String found in binary or memory: http://DynDns.comDynDNS
Source: COVID 19 BENEFIT FORM 2.exe, 0000000A.00000002.599311455.0000000002871000.00000004.00000001.sdmp String found in binary or memory: http://SBRGHbI6v8zShNk.net
Source: COVID 19 BENEFIT FORM 2.exe, 0000000A.00000002.599311455.0000000002871000.00000004.00000001.sdmp String found in binary or memory: http://SBRGHbI6v8zShNk.netL2
Source: COVID 19 BENEFIT FORM 2.exe, 0000000A.00000002.601224082.0000000002BD1000.00000004.00000001.sdmp String found in binary or memory: http://crl.comodoca.com/AAACertificateServices.crl04
Source: COVID 19 BENEFIT FORM 2.exe, 0000000A.00000002.601224082.0000000002BD1000.00000004.00000001.sdmp String found in binary or memory: http://crt.sectigo.com/SectigoRSADomainValidationSecureServerCA.crt0#
Source: COVID 19 BENEFIT FORM 2.exe, 00000000.00000003.330293022.0000000005EAA000.00000004.00000001.sdmp String found in binary or memory: http://en.w
Source: COVID 19 BENEFIT FORM 2.exe, 00000000.00000003.329792577.0000000005E9B000.00000004.00000001.sdmp, COVID 19 BENEFIT FORM 2.exe, 00000000.00000002.382360322.0000000005F70000.00000002.00000001.sdmp String found in binary or memory: http://fontfabrik.com
Source: COVID 19 BENEFIT FORM 2.exe, 0000000A.00000002.601224082.0000000002BD1000.00000004.00000001.sdmp String found in binary or memory: http://mail.privateemail.com
Source: COVID 19 BENEFIT FORM 2.exe, 0000000A.00000002.599311455.0000000002871000.00000004.00000001.sdmp String found in binary or memory: http://mapoex.com
Source: COVID 19 BENEFIT FORM 2.exe, 0000000A.00000002.601224082.0000000002BD1000.00000004.00000001.sdmp String found in binary or memory: http://ocsp.comodoca.com0
Source: COVID 19 BENEFIT FORM 2.exe, 0000000A.00000002.601224082.0000000002BD1000.00000004.00000001.sdmp String found in binary or memory: http://ocsp.sectigo.com0
Source: COVID 19 BENEFIT FORM 2.exe, 00000000.00000002.375417166.0000000002F21000.00000004.00000001.sdmp String found in binary or memory: http://schemas.xmlsoap.org/ws/2005/05/identity/claims/name
Source: COVID 19 BENEFIT FORM 2.exe, 00000000.00000002.382360322.0000000005F70000.00000002.00000001.sdmp String found in binary or memory: http://www.apache.org/licenses/LICENSE-2.0
Source: COVID 19 BENEFIT FORM 2.exe, 00000000.00000003.334907624.0000000005EA3000.00000004.00000001.sdmp String found in binary or memory: http://www.ascendercorp.com/typedesigners.html
Source: COVID 19 BENEFIT FORM 2.exe, 00000000.00000003.334907624.0000000005EA3000.00000004.00000001.sdmp String found in binary or memory: http://www.ascendercorp.com/typedesigners.htmlBW
Source: COVID 19 BENEFIT FORM 2.exe, 00000000.00000003.334231166.0000000005EA3000.00000004.00000001.sdmp String found in binary or memory: http://www.ascendercorp.com/typedesigners.htmlnW/
Source: COVID 19 BENEFIT FORM 2.exe, 00000000.00000003.332725617.0000000005E9B000.00000004.00000001.sdmp, COVID 19 BENEFIT FORM 2.exe, 00000000.00000003.332816319.0000000005E9B000.00000004.00000001.sdmp String found in binary or memory: http://www.carterandcone.com
Source: COVID 19 BENEFIT FORM 2.exe, 00000000.00000003.332725617.0000000005E9B000.00000004.00000001.sdmp String found in binary or memory: http://www.carterandcone.com0
Source: COVID 19 BENEFIT FORM 2.exe, 00000000.00000003.333039942.0000000005E9B000.00000004.00000001.sdmp String found in binary or memory: http://www.carterandcone.comJhEB
Source: COVID 19 BENEFIT FORM 2.exe, 00000000.00000003.333039942.0000000005E9B000.00000004.00000001.sdmp String found in binary or memory: http://www.carterandcone.comNF8
Source: COVID 19 BENEFIT FORM 2.exe, 00000000.00000003.332816319.0000000005E9B000.00000004.00000001.sdmp String found in binary or memory: http://www.carterandcone.comTC
Source: COVID 19 BENEFIT FORM 2.exe, 00000000.00000003.332725617.0000000005E9B000.00000004.00000001.sdmp String found in binary or memory: http://www.carterandcone.comTC(Sr
Source: COVID 19 BENEFIT FORM 2.exe, 00000000.00000003.333039942.0000000005E9B000.00000004.00000001.sdmp String found in binary or memory: http://www.carterandcone.comWF3
Source: COVID 19 BENEFIT FORM 2.exe, 00000000.00000003.333146895.0000000005E9B000.00000004.00000001.sdmp String found in binary or memory: http://www.carterandcone.comac
Source: COVID 19 BENEFIT FORM 2.exe, 00000000.00000003.332725617.0000000005E9B000.00000004.00000001.sdmp, COVID 19 BENEFIT FORM 2.exe, 00000000.00000003.332479184.0000000005E9B000.00000004.00000001.sdmp String found in binary or memory: http://www.carterandcone.come
Source: COVID 19 BENEFIT FORM 2.exe, 00000000.00000003.333146895.0000000005E9B000.00000004.00000001.sdmp String found in binary or memory: http://www.carterandcone.come5BV
Source: COVID 19 BENEFIT FORM 2.exe, 00000000.00000003.333039942.0000000005E9B000.00000004.00000001.sdmp String found in binary or memory: http://www.carterandcone.comen
Source: COVID 19 BENEFIT FORM 2.exe, 00000000.00000003.333039942.0000000005E9B000.00000004.00000001.sdmp String found in binary or memory: http://www.carterandcone.comic
Source: COVID 19 BENEFIT FORM 2.exe, 00000000.00000002.382360322.0000000005F70000.00000002.00000001.sdmp String found in binary or memory: http://www.carterandcone.coml
Source: COVID 19 BENEFIT FORM 2.exe, 00000000.00000003.332725617.0000000005E9B000.00000004.00000001.sdmp String found in binary or memory: http://www.carterandcone.comlt
Source: COVID 19 BENEFIT FORM 2.exe, 00000000.00000003.332725617.0000000005E9B000.00000004.00000001.sdmp String found in binary or memory: http://www.carterandcone.como.
Source: COVID 19 BENEFIT FORM 2.exe, 00000000.00000003.333146895.0000000005E9B000.00000004.00000001.sdmp String found in binary or memory: http://www.carterandcone.compt
Source: COVID 19 BENEFIT FORM 2.exe, 00000000.00000003.332725617.0000000005E9B000.00000004.00000001.sdmp String found in binary or memory: http://www.carterandcone.comtig
Source: COVID 19 BENEFIT FORM 2.exe, 00000000.00000003.333146895.0000000005E9B000.00000004.00000001.sdmp String found in binary or memory: http://www.carterandcone.comx
Source: COVID 19 BENEFIT FORM 2.exe, 00000000.00000002.375338319.00000000015E7000.00000004.00000040.sdmp String found in binary or memory: http://www.fontbureau.com
Source: COVID 19 BENEFIT FORM 2.exe, 00000000.00000002.382360322.0000000005F70000.00000002.00000001.sdmp String found in binary or memory: http://www.fontbureau.com/designers
Source: COVID 19 BENEFIT FORM 2.exe, 00000000.00000003.338116776.0000000005E9B000.00000004.00000001.sdmp String found in binary or memory: http://www.fontbureau.com/designers#
Source: COVID 19 BENEFIT FORM 2.exe, 00000000.00000003.337167523.0000000005E9B000.00000004.00000001.sdmp String found in binary or memory: http://www.fontbureau.com/designers-Sq
Source: COVID 19 BENEFIT FORM 2.exe, 00000000.00000003.336671003.0000000005E9B000.00000004.00000001.sdmp String found in binary or memory: http://www.fontbureau.com/designers/
Source: COVID 19 BENEFIT FORM 2.exe, 00000000.00000002.382360322.0000000005F70000.00000002.00000001.sdmp String found in binary or memory: http://www.fontbureau.com/designers/?
Source: COVID 19 BENEFIT FORM 2.exe, 00000000.00000002.382360322.0000000005F70000.00000002.00000001.sdmp String found in binary or memory: http://www.fontbureau.com/designers/cabarga.htmlN
Source: COVID 19 BENEFIT FORM 2.exe, 00000000.00000003.338045037.0000000005EBE000.00000004.00000001.sdmp String found in binary or memory: http://www.fontbureau.com/designers/cabarga.htmld
Source: COVID 19 BENEFIT FORM 2.exe, 00000000.00000003.338606084.0000000005EBE000.00000004.00000001.sdmp String found in binary or memory: http://www.fontbureau.com/designers/cabarga.htmlh
Source: COVID 19 BENEFIT FORM 2.exe, 00000000.00000003.337413588.0000000005EBE000.00000004.00000001.sdmp, COVID 19 BENEFIT FORM 2.exe, 00000000.00000002.382360322.0000000005F70000.00000002.00000001.sdmp String found in binary or memory: http://www.fontbureau.com/designers/frere-jones.html
Source: COVID 19 BENEFIT FORM 2.exe, 00000000.00000003.337387930.0000000005E9B000.00000004.00000001.sdmp String found in binary or memory: http://www.fontbureau.com/designers/frere-jones.htmlf
Source: COVID 19 BENEFIT FORM 2.exe, 00000000.00000002.382360322.0000000005F70000.00000002.00000001.sdmp String found in binary or memory: http://www.fontbureau.com/designers8
Source: COVID 19 BENEFIT FORM 2.exe, 00000000.00000002.382360322.0000000005F70000.00000002.00000001.sdmp String found in binary or memory: http://www.fontbureau.com/designers?
Source: COVID 19 BENEFIT FORM 2.exe, 00000000.00000003.345153128.0000000005E9B000.00000004.00000001.sdmp String found in binary or memory: http://www.fontbureau.com/designersB
Source: COVID 19 BENEFIT FORM 2.exe, 00000000.00000003.345153128.0000000005E9B000.00000004.00000001.sdmp String found in binary or memory: http://www.fontbureau.com/designersES
Source: COVID 19 BENEFIT FORM 2.exe, 00000000.00000003.337167523.0000000005E9B000.00000004.00000001.sdmp String found in binary or memory: http://www.fontbureau.com/designersF
Source: COVID 19 BENEFIT FORM 2.exe, 00000000.00000002.382360322.0000000005F70000.00000002.00000001.sdmp String found in binary or memory: http://www.fontbureau.com/designersG
Source: COVID 19 BENEFIT FORM 2.exe, 00000000.00000003.338116776.0000000005E9B000.00000004.00000001.sdmp String found in binary or memory: http://www.fontbureau.com/designersdSF
Source: COVID 19 BENEFIT FORM 2.exe, 00000000.00000002.375338319.00000000015E7000.00000004.00000040.sdmp String found in binary or memory: http://www.fontbureau.comgreta
Source: COVID 19 BENEFIT FORM 2.exe, 00000000.00000002.375338319.00000000015E7000.00000004.00000040.sdmp String found in binary or memory: http://www.fontbureau.comiona
Source: COVID 19 BENEFIT FORM 2.exe, 00000000.00000002.382360322.0000000005F70000.00000002.00000001.sdmp String found in binary or memory: http://www.fonts.com
Source: COVID 19 BENEFIT FORM 2.exe, 00000000.00000003.331820934.0000000005EA4000.00000004.00000001.sdmp, COVID 19 BENEFIT FORM 2.exe, 00000000.00000003.331864305.0000000005EA0000.00000004.00000001.sdmp String found in binary or memory: http://www.founder.com.cn/cn
Source: COVID 19 BENEFIT FORM 2.exe, 00000000.00000003.332128006.0000000005E9B000.00000004.00000001.sdmp, COVID 19 BENEFIT FORM 2.exe, 00000000.00000003.331974163.0000000005EA2000.00000004.00000001.sdmp String found in binary or memory: http://www.founder.com.cn/cn/
Source: COVID 19 BENEFIT FORM 2.exe, 00000000.00000003.331540177.0000000005E9B000.00000004.00000001.sdmp String found in binary or memory: http://www.founder.com.cn/cn/FqR
Source: COVID 19 BENEFIT FORM 2.exe, 00000000.00000002.382360322.0000000005F70000.00000002.00000001.sdmp String found in binary or memory: http://www.founder.com.cn/cn/bThe
Source: COVID 19 BENEFIT FORM 2.exe, 00000000.00000002.382360322.0000000005F70000.00000002.00000001.sdmp String found in binary or memory: http://www.founder.com.cn/cn/cThe
Source: COVID 19 BENEFIT FORM 2.exe, 00000000.00000003.332725617.0000000005E9B000.00000004.00000001.sdmp String found in binary or memory: http://www.founder.com.cn/cn;
Source: COVID 19 BENEFIT FORM 2.exe, 00000000.00000003.332128006.0000000005E9B000.00000004.00000001.sdmp String found in binary or memory: http://www.founder.com.cn/cnK
Source: COVID 19 BENEFIT FORM 2.exe, 00000000.00000003.332128006.0000000005E9B000.00000004.00000001.sdmp String found in binary or memory: http://www.founder.com.cn/cnk
Source: COVID 19 BENEFIT FORM 2.exe, 00000000.00000003.332128006.0000000005E9B000.00000004.00000001.sdmp String found in binary or memory: http://www.founder.com.cn/cnl
Source: COVID 19 BENEFIT FORM 2.exe, 00000000.00000003.332128006.0000000005E9B000.00000004.00000001.sdmp String found in binary or memory: http://www.founder.com.cn/cnof
Source: COVID 19 BENEFIT FORM 2.exe, 00000000.00000002.382360322.0000000005F70000.00000002.00000001.sdmp String found in binary or memory: http://www.galapagosdesign.com/DPlease
Source: COVID 19 BENEFIT FORM 2.exe, 00000000.00000003.341196577.0000000005E9B000.00000004.00000001.sdmp, COVID 19 BENEFIT FORM 2.exe, 00000000.00000002.382360322.0000000005F70000.00000002.00000001.sdmp String found in binary or memory: http://www.galapagosdesign.com/staff/dennis.htm
Source: COVID 19 BENEFIT FORM 2.exe, 00000000.00000003.331540177.0000000005E9B000.00000004.00000001.sdmp String found in binary or memory: http://www.goodfont.co.k
Source: COVID 19 BENEFIT FORM 2.exe, 00000000.00000002.382360322.0000000005F70000.00000002.00000001.sdmp String found in binary or memory: http://www.goodfont.co.kr
Source: COVID 19 BENEFIT FORM 2.exe, 00000000.00000003.331486082.0000000005E9B000.00000004.00000001.sdmp String found in binary or memory: http://www.goodfont.co.kr-c
Source: COVID 19 BENEFIT FORM 2.exe, 00000000.00000003.331486082.0000000005E9B000.00000004.00000001.sdmp String found in binary or memory: http://www.goodfont.co.krx.
Source: COVID 19 BENEFIT FORM 2.exe, 00000000.00000002.382360322.0000000005F70000.00000002.00000001.sdmp String found in binary or memory: http://www.jiyu-kobo.co.jp/
Source: COVID 19 BENEFIT FORM 2.exe, 00000000.00000003.341196577.0000000005E9B000.00000004.00000001.sdmp String found in binary or memory: http://www.monotype.
Source: COVID 19 BENEFIT FORM 2.exe, 00000000.00000003.336815155.0000000005E9B000.00000004.00000001.sdmp String found in binary or memory: http://www.monotype.)Qr
Source: COVID 19 BENEFIT FORM 2.exe, 00000000.00000002.382360322.0000000005F70000.00000002.00000001.sdmp, COVID 19 BENEFIT FORM 2.exe, 00000000.00000003.328572795.0000000005E82000.00000004.00000001.sdmp String found in binary or memory: http://www.sajatypeworks.com
Source: COVID 19 BENEFIT FORM 2.exe, 00000000.00000003.328572795.0000000005E82000.00000004.00000001.sdmp String found in binary or memory: http://www.sajatypeworks.comn
Source: COVID 19 BENEFIT FORM 2.exe, 00000000.00000002.382360322.0000000005F70000.00000002.00000001.sdmp String found in binary or memory: http://www.sakkal.com
Source: COVID 19 BENEFIT FORM 2.exe, 00000000.00000003.331486082.0000000005E9B000.00000004.00000001.sdmp String found in binary or memory: http://www.sandoll.co.kr
Source: COVID 19 BENEFIT FORM 2.exe, 00000000.00000003.331486082.0000000005E9B000.00000004.00000001.sdmp String found in binary or memory: http://www.sandoll.co.kr)Rr
Source: COVID 19 BENEFIT FORM 2.exe, 00000000.00000003.331382313.0000000005E9B000.00000004.00000001.sdmp String found in binary or memory: http://www.sandoll.co.kra-es)Rr
Source: COVID 19 BENEFIT FORM 2.exe, 00000000.00000003.331486082.0000000005E9B000.00000004.00000001.sdmp String found in binary or memory: http://www.sandoll.co.krn-usur
Source: COVID 19 BENEFIT FORM 2.exe, 00000000.00000003.331540177.0000000005E9B000.00000004.00000001.sdmp String found in binary or memory: http://www.sandoll.co.krq
Source: COVID 19 BENEFIT FORM 2.exe, 00000000.00000002.382360322.0000000005F70000.00000002.00000001.sdmp String found in binary or memory: http://www.tiro.com
Source: COVID 19 BENEFIT FORM 2.exe, 00000000.00000003.333146895.0000000005E9B000.00000004.00000001.sdmp String found in binary or memory: http://www.tiro.comWE0
Source: COVID 19 BENEFIT FORM 2.exe, 00000000.00000003.332246844.00000000015EC000.00000004.00000001.sdmp String found in binary or memory: http://www.tiro.comn-u3
Source: COVID 19 BENEFIT FORM 2.exe, 00000000.00000002.382360322.0000000005F70000.00000002.00000001.sdmp String found in binary or memory: http://www.typography.netD
Source: COVID 19 BENEFIT FORM 2.exe, 00000000.00000003.336364737.0000000005E9B000.00000004.00000001.sdmp String found in binary or memory: http://www.urwpp.de
Source: COVID 19 BENEFIT FORM 2.exe, 00000000.00000002.382360322.0000000005F70000.00000002.00000001.sdmp String found in binary or memory: http://www.urwpp.deDPlease
Source: COVID 19 BENEFIT FORM 2.exe, 00000000.00000003.338840406.0000000005E9B000.00000004.00000001.sdmp String found in binary or memory: http://www.urwpp.deEEB
Source: COVID 19 BENEFIT FORM 2.exe, 00000000.00000003.336364737.0000000005E9B000.00000004.00000001.sdmp String found in binary or memory: http://www.urwpp.deLE;
Source: COVID 19 BENEFIT FORM 2.exe, 00000000.00000003.339197866.0000000005EA8000.00000004.00000001.sdmp String found in binary or memory: http://www.urwpp.deWE0
Source: COVID 19 BENEFIT FORM 2.exe, 00000000.00000003.336364737.0000000005E9B000.00000004.00000001.sdmp String found in binary or memory: http://www.urwpp.deiEEB
Source: COVID 19 BENEFIT FORM 2.exe, 00000000.00000003.332725617.0000000005E9B000.00000004.00000001.sdmp, COVID 19 BENEFIT FORM 2.exe, 00000000.00000002.382360322.0000000005F70000.00000002.00000001.sdmp String found in binary or memory: http://www.zhongyicts.com.cn
Source: COVID 19 BENEFIT FORM 2.exe, 00000000.00000003.332725617.0000000005E9B000.00000004.00000001.sdmp String found in binary or memory: http://www.zhongyicts.com.cnK
Source: COVID 19 BENEFIT FORM 2.exe, 00000000.00000003.332725617.0000000005E9B000.00000004.00000001.sdmp String found in binary or memory: http://www.zhongyicts.com.cna
Source: COVID 19 BENEFIT FORM 2.exe, 00000000.00000003.332430336.0000000005E9B000.00000004.00000001.sdmp String found in binary or memory: http://www.zhongyicts.com.cno.
Source: COVID 19 BENEFIT FORM 2.exe, 00000000.00000003.332430336.0000000005E9B000.00000004.00000001.sdmp String found in binary or memory: http://www.zhongyicts.com.cnr-f
Source: COVID 19 BENEFIT FORM 2.exe, 0000000A.00000002.599311455.0000000002871000.00000004.00000001.sdmp String found in binary or memory: https://api.ipify.org%
Source: COVID 19 BENEFIT FORM 2.exe, 0000000A.00000002.599311455.0000000002871000.00000004.00000001.sdmp String found in binary or memory: https://api.ipify.org%GETMozilla/5.0
Source: COVID 19 BENEFIT FORM 2.exe, 0000000A.00000002.601224082.0000000002BD1000.00000004.00000001.sdmp String found in binary or memory: https://sectigo.com/CPS0
Source: COVID 19 BENEFIT FORM 2.exe, 00000000.00000002.377324089.0000000003F29000.00000004.00000001.sdmp, COVID 19 BENEFIT FORM 2.exe, 0000000A.00000002.596294759.0000000000402000.00000040.00000001.sdmp String found in binary or memory: https://www.theonionrouter.com/dist.torproject.org/torbrowser/9.5.3/tor-win32-0.4.3.6.zip
Source: COVID 19 BENEFIT FORM 2.exe, 0000000A.00000002.599311455.0000000002871000.00000004.00000001.sdmp String found in binary or memory: https://www.theonionrouter.com/dist.torproject.org/torbrowser/9.5.3/tor-win32-0.4.3.6.zip%tordir%%ha

Key, Mouse, Clipboard, Microphone and Screen Capturing:

barindex
Creates a window with clipboard capturing capabilities
Source: C:\Users\user\Desktop\COVID 19 BENEFIT FORM 2.exe Window created: window name: CLIPBRDWNDCLASS Jump to behavior

System Summary:

barindex
.NET source code contains very large array initializations
Source: 10.2.COVID 19 BENEFIT FORM 2.exe.400000.0.unpack, u003cPrivateImplementationDetailsu003eu007b3C5ACC4Eu002d4173u002d4CE9u002dA88Eu002d8EFA98FCB099u007d/u003293A124Bu002dAB49u002d44B7u002d9397u002d5CD9CB98E805.cs Large array initialization: .cctor: array initializer size 12037
Detected potential crypto function
Source: C:\Users\user\Desktop\COVID 19 BENEFIT FORM 2.exe Code function: 0_2_00B62304 0_2_00B62304
Source: C:\Users\user\Desktop\COVID 19 BENEFIT FORM 2.exe Code function: 0_2_0158C124 0_2_0158C124
Source: C:\Users\user\Desktop\COVID 19 BENEFIT FORM 2.exe Code function: 0_2_0158E570 0_2_0158E570
Source: C:\Users\user\Desktop\COVID 19 BENEFIT FORM 2.exe Code function: 0_2_0158E560 0_2_0158E560
Source: C:\Users\user\Desktop\COVID 19 BENEFIT FORM 2.exe Code function: 0_2_081F1978 0_2_081F1978
Source: C:\Users\user\Desktop\COVID 19 BENEFIT FORM 2.exe Code function: 0_2_081F1C10 0_2_081F1C10
Source: C:\Users\user\Desktop\COVID 19 BENEFIT FORM 2.exe Code function: 0_2_081F3D7E 0_2_081F3D7E
Source: C:\Users\user\Desktop\COVID 19 BENEFIT FORM 2.exe Code function: 0_2_081F0040 0_2_081F0040
Source: C:\Users\user\Desktop\COVID 19 BENEFIT FORM 2.exe Code function: 0_2_081F1969 0_2_081F1969
Source: C:\Users\user\Desktop\COVID 19 BENEFIT FORM 2.exe Code function: 0_2_081F1C00 0_2_081F1C00
Source: C:\Users\user\Desktop\COVID 19 BENEFIT FORM 2.exe Code function: 0_2_081F0C78 0_2_081F0C78
Source: C:\Users\user\Desktop\COVID 19 BENEFIT FORM 2.exe Code function: 0_2_081F0C6A 0_2_081F0C6A
Source: C:\Users\user\Desktop\COVID 19 BENEFIT FORM 2.exe Code function: 0_2_081F1E4D 0_2_081F1E4D
Source: C:\Users\user\Desktop\COVID 19 BENEFIT FORM 2.exe Code function: 0_2_081F1E98 0_2_081F1E98
Source: C:\Users\user\Desktop\COVID 19 BENEFIT FORM 2.exe Code function: 0_2_081F3EB6 0_2_081F3EB6
Source: C:\Users\user\Desktop\COVID 19 BENEFIT FORM 2.exe Code function: 0_2_081F0006 0_2_081F0006
Source: C:\Users\user\Desktop\COVID 19 BENEFIT FORM 2.exe Code function: 0_2_081F0579 0_2_081F0579
Source: C:\Users\user\Desktop\COVID 19 BENEFIT FORM 2.exe Code function: 0_2_081F0588 0_2_081F0588
Source: C:\Users\user\Desktop\COVID 19 BENEFIT FORM 2.exe Code function: 0_2_081F1698 0_2_081F1698
Source: C:\Users\user\Desktop\COVID 19 BENEFIT FORM 2.exe Code function: 0_2_081F16A8 0_2_081F16A8
Source: C:\Users\user\Desktop\COVID 19 BENEFIT FORM 2.exe Code function: 7_2_002A2304 7_2_002A2304
Source: C:\Users\user\Desktop\COVID 19 BENEFIT FORM 2.exe Code function: 8_2_00062304 8_2_00062304
Source: C:\Users\user\Desktop\COVID 19 BENEFIT FORM 2.exe Code function: 9_2_00222304 9_2_00222304
Source: C:\Users\user\Desktop\COVID 19 BENEFIT FORM 2.exe Code function: 10_2_004C2304 10_2_004C2304
Source: C:\Users\user\Desktop\COVID 19 BENEFIT FORM 2.exe Code function: 10_2_00B50040 10_2_00B50040
Source: C:\Users\user\Desktop\COVID 19 BENEFIT FORM 2.exe Code function: 10_2_00B59990 10_2_00B59990
Source: C:\Users\user\Desktop\COVID 19 BENEFIT FORM 2.exe Code function: 10_2_00B541F8 10_2_00B541F8
Source: C:\Users\user\Desktop\COVID 19 BENEFIT FORM 2.exe Code function: 10_2_00B56154 10_2_00B56154
Source: C:\Users\user\Desktop\COVID 19 BENEFIT FORM 2.exe Code function: 10_2_00B55AA8 10_2_00B55AA8
Source: C:\Users\user\Desktop\COVID 19 BENEFIT FORM 2.exe Code function: 10_2_00B53210 10_2_00B53210
Source: C:\Users\user\Desktop\COVID 19 BENEFIT FORM 2.exe Code function: 10_2_00B5B5AD 10_2_00B5B5AD
Source: C:\Users\user\Desktop\COVID 19 BENEFIT FORM 2.exe Code function: 10_2_00B52590 10_2_00B52590
Source: C:\Users\user\Desktop\COVID 19 BENEFIT FORM 2.exe Code function: 10_2_00B54198 10_2_00B54198
Source: C:\Users\user\Desktop\COVID 19 BENEFIT FORM 2.exe Code function: 10_2_00B5CB70 10_2_00B5CB70
Source: C:\Users\user\Desktop\COVID 19 BENEFIT FORM 2.exe Code function: 10_2_00C868D8 10_2_00C868D8
Source: C:\Users\user\Desktop\COVID 19 BENEFIT FORM 2.exe Code function: 10_2_00C85650 10_2_00C85650
Source: C:\Users\user\Desktop\COVID 19 BENEFIT FORM 2.exe Code function: 10_2_00C85B78 10_2_00C85B78
Source: C:\Users\user\Desktop\COVID 19 BENEFIT FORM 2.exe Code function: 10_2_00CA0068 10_2_00CA0068
Source: C:\Users\user\Desktop\COVID 19 BENEFIT FORM 2.exe Code function: 10_2_00CA9610 10_2_00CA9610
Source: C:\Users\user\Desktop\COVID 19 BENEFIT FORM 2.exe Code function: 10_2_00CA5FB0 10_2_00CA5FB0
Source: C:\Users\user\Desktop\COVID 19 BENEFIT FORM 2.exe Code function: 10_2_00CA70D8 10_2_00CA70D8
Source: C:\Users\user\Desktop\COVID 19 BENEFIT FORM 2.exe Code function: 10_2_00CAB3D8 10_2_00CAB3D8
Source: C:\Users\user\Desktop\COVID 19 BENEFIT FORM 2.exe Code function: 10_2_00CACD50 10_2_00CACD50
Sample file is different than original file name gathered from version info
Source: COVID 19 BENEFIT FORM 2.exe Binary or memory string: OriginalFilename vs COVID 19 BENEFIT FORM 2.exe
Source: COVID 19 BENEFIT FORM 2.exe, 00000000.00000002.388072223.00000000100F0000.00000002.00000001.sdmp Binary or memory string: originalfilename vs COVID 19 BENEFIT FORM 2.exe
Source: COVID 19 BENEFIT FORM 2.exe, 00000000.00000002.388072223.00000000100F0000.00000002.00000001.sdmp Binary or memory string: OriginalFilenamepropsys.dll.mui@ vs COVID 19 BENEFIT FORM 2.exe
Source: COVID 19 BENEFIT FORM 2.exe, 00000000.00000002.387855603.000000000FFF0000.00000002.00000001.sdmp Binary or memory string: System.OriginalFileName vs COVID 19 BENEFIT FORM 2.exe
Source: COVID 19 BENEFIT FORM 2.exe, 00000000.00000002.373930838.0000000000B62000.00000002.00020000.sdmp Binary or memory string: OriginalFilenameyY0 vs COVID 19 BENEFIT FORM 2.exe
Source: COVID 19 BENEFIT FORM 2.exe, 00000000.00000002.375417166.0000000002F21000.00000004.00000001.sdmp Binary or memory string: OriginalFilenameSmartFormat.dll8 vs COVID 19 BENEFIT FORM 2.exe
Source: COVID 19 BENEFIT FORM 2.exe, 00000000.00000002.375417166.0000000002F21000.00000004.00000001.sdmp Binary or memory string: OriginalFilenamelEoaqcxNgfzuerfwjwfBvMgttynocmgZjwmB.exe4 vs COVID 19 BENEFIT FORM 2.exe
Source: COVID 19 BENEFIT FORM 2.exe, 00000000.00000002.386735033.0000000009940000.00000004.00000001.sdmp Binary or memory string: OriginalFilenameMajorRevision.exe< vs COVID 19 BENEFIT FORM 2.exe
Source: COVID 19 BENEFIT FORM 2.exe Binary or memory string: OriginalFilename vs COVID 19 BENEFIT FORM 2.exe
Source: COVID 19 BENEFIT FORM 2.exe, 00000007.00000002.368822725.00000000002A2000.00000002.00020000.sdmp Binary or memory string: OriginalFilenameyY0 vs COVID 19 BENEFIT FORM 2.exe
Source: COVID 19 BENEFIT FORM 2.exe Binary or memory string: OriginalFilename vs COVID 19 BENEFIT FORM 2.exe
Source: COVID 19 BENEFIT FORM 2.exe, 00000008.00000000.369729906.0000000000062000.00000002.00020000.sdmp Binary or memory string: OriginalFilenameyY0 vs COVID 19 BENEFIT FORM 2.exe
Source: COVID 19 BENEFIT FORM 2.exe Binary or memory string: OriginalFilename vs COVID 19 BENEFIT FORM 2.exe
Source: COVID 19 BENEFIT FORM 2.exe, 00000009.00000000.371224608.0000000000222000.00000002.00020000.sdmp Binary or memory string: OriginalFilenameyY0 vs COVID 19 BENEFIT FORM 2.exe
Source: COVID 19 BENEFIT FORM 2.exe Binary or memory string: OriginalFilename vs COVID 19 BENEFIT FORM 2.exe
Source: COVID 19 BENEFIT FORM 2.exe, 0000000A.00000002.605368510.0000000005DA0000.00000002.00000001.sdmp Binary or memory string: OriginalFilenamemscorrc.dllT vs COVID 19 BENEFIT FORM 2.exe
Source: COVID 19 BENEFIT FORM 2.exe, 0000000A.00000002.598377640.0000000000C90000.00000002.00000001.sdmp Binary or memory string: OriginalFilenamewshom.ocx.mui vs COVID 19 BENEFIT FORM 2.exe
Source: COVID 19 BENEFIT FORM 2.exe, 0000000A.00000002.596294759.0000000000402000.00000040.00000001.sdmp Binary or memory string: OriginalFilenamelEoaqcxNgfzuerfwjwfBvMgttynocmgZjwmB.exe4 vs COVID 19 BENEFIT FORM 2.exe
Source: COVID 19 BENEFIT FORM 2.exe, 0000000A.00000002.596448626.00000000004C2000.00000002.00020000.sdmp Binary or memory string: OriginalFilenameyY0 vs COVID 19 BENEFIT FORM 2.exe
Source: COVID 19 BENEFIT FORM 2.exe, 0000000A.00000002.598293272.0000000000C70000.00000002.00000001.sdmp Binary or memory string: OriginalFilenamewshom.ocx vs COVID 19 BENEFIT FORM 2.exe
Source: COVID 19 BENEFIT FORM 2.exe Binary or memory string: OriginalFilenameyY0 vs COVID 19 BENEFIT FORM 2.exe
Uses 32bit PE files
Source: COVID 19 BENEFIT FORM 2.exe Static PE information: 32BIT_MACHINE, EXECUTABLE_IMAGE
Source: COVID 19 BENEFIT FORM 2.exe Static PE information: Section: .text IMAGE_SCN_MEM_EXECUTE, IMAGE_SCN_CNT_CODE, IMAGE_SCN_MEM_READ
Source: lVGkcjmu.exe.0.dr Static PE information: Section: .text IMAGE_SCN_MEM_EXECUTE, IMAGE_SCN_CNT_CODE, IMAGE_SCN_MEM_READ
Source: 10.2.COVID 19 BENEFIT FORM 2.exe.400000.0.unpack, A/b2.cs Cryptographic APIs: 'TransformFinalBlock', 'CreateDecryptor'
Source: 10.2.COVID 19 BENEFIT FORM 2.exe.400000.0.unpack, A/b2.cs Cryptographic APIs: 'TransformFinalBlock', 'CreateDecryptor'
Source: classification engine Classification label: mal100.troj.spyw.evad.winEXE@12/3@0/0
Source: C:\Users\user\Desktop\COVID 19 BENEFIT FORM 2.exe File created: C:\Users\user\AppData\Roaming\lVGkcjmu.exe Jump to behavior
Source: C:\Users\user\Desktop\COVID 19 BENEFIT FORM 2.exe Mutant created: \Sessions\1\BaseNamedObjects\qzUKnVUVtEAujFcp
Source: C:\Windows\System32\conhost.exe Mutant created: \Sessions\1\BaseNamedObjects\Local\SM0:6936:120:WilError_01
Source: C:\Users\user\Desktop\COVID 19 BENEFIT FORM 2.exe File created: C:\Users\user\AppData\Local\Temp\tmp764A.tmp Jump to behavior
Source: COVID 19 BENEFIT FORM 2.exe Static PE information: Section: .text IMAGE_SCN_MEM_EXECUTE, IMAGE_SCN_CNT_CODE, IMAGE_SCN_MEM_READ
Source: C:\Users\user\Desktop\COVID 19 BENEFIT FORM 2.exe Section loaded: C:\Windows\assembly\NativeImages_v4.0.30319_32\mscorlib\a152fe02a317a77aeee36903305e8ba6\mscorlib.ni.dll Jump to behavior
Source: C:\Users\user\Desktop\COVID 19 BENEFIT FORM 2.exe Section loaded: C:\Windows\assembly\NativeImages_v4.0.30319_32\mscorlib\a152fe02a317a77aeee36903305e8ba6\mscorlib.ni.dll Jump to behavior
Source: C:\Users\user\Desktop\COVID 19 BENEFIT FORM 2.exe WMI Queries: IWbemServices::CreateInstanceEnum - root\cimv2 : Win32_Processor
Source: C:\Users\user\Desktop\COVID 19 BENEFIT FORM 2.exe File read: C:\Users\user\Desktop\desktop.ini Jump to behavior
Source: C:\Users\user\Desktop\COVID 19 BENEFIT FORM 2.exe Key opened: HKEY_CURRENT_USER\Software\Policies\Microsoft\Windows\Safer\CodeIdentifiers Jump to behavior
Source: COVID 19 BENEFIT FORM 2.exe, 00000000.00000002.373930838.0000000000B62000.00000002.00020000.sdmp, COVID 19 BENEFIT FORM 2.exe, 00000007.00000002.368822725.00000000002A2000.00000002.00020000.sdmp, COVID 19 BENEFIT FORM 2.exe, 00000008.00000000.369729906.0000000000062000.00000002.00020000.sdmp, COVID 19 BENEFIT FORM 2.exe, 00000009.00000000.371224608.0000000000222000.00000002.00020000.sdmp, COVID 19 BENEFIT FORM 2.exe, 0000000A.00000002.596448626.00000000004C2000.00000002.00020000.sdmp Binary or memory string: SELECT id,prizm_code,upc,name,description,brand_id,color,price,tax,tax_id,stock_in_hand,jedinica_mere,is_active FROM pos.items;Error while displaying items!%dataGridViewUpdate
Source: COVID 19 BENEFIT FORM 2.exe Virustotal: Detection: 43%
Source: COVID 19 BENEFIT FORM 2.exe ReversingLabs: Detection: 36%
Source: C:\Users\user\Desktop\COVID 19 BENEFIT FORM 2.exe File read: C:\Users\user\Desktop\COVID 19 BENEFIT FORM 2.exe Jump to behavior
Source: unknown Process created: C:\Users\user\Desktop\COVID 19 BENEFIT FORM 2.exe 'C:\Users\user\Desktop\COVID 19 BENEFIT FORM 2.exe'
Source: C:\Users\user\Desktop\COVID 19 BENEFIT FORM 2.exe Process created: C:\Windows\SysWOW64\schtasks.exe 'C:\Windows\System32\schtasks.exe' /Create /TN 'Updates\lVGkcjmu' /XML 'C:\Users\user\AppData\Local\Temp\tmp764A.tmp'
Source: C:\Windows\SysWOW64\schtasks.exe Process created: C:\Windows\System32\conhost.exe C:\Windows\system32\conhost.exe 0xffffffff -ForceV1
Source: C:\Users\user\Desktop\COVID 19 BENEFIT FORM 2.exe Process created: C:\Users\user\Desktop\COVID 19 BENEFIT FORM 2.exe {path}
Source: C:\Users\user\Desktop\COVID 19 BENEFIT FORM 2.exe Process created: C:\Users\user\Desktop\COVID 19 BENEFIT FORM 2.exe {path}
Source: C:\Users\user\Desktop\COVID 19 BENEFIT FORM 2.exe Process created: C:\Users\user\Desktop\COVID 19 BENEFIT FORM 2.exe {path}
Source: C:\Users\user\Desktop\COVID 19 BENEFIT FORM 2.exe Process created: C:\Users\user\Desktop\COVID 19 BENEFIT FORM 2.exe {path}
Source: C:\Users\user\Desktop\COVID 19 BENEFIT FORM 2.exe Process created: C:\Windows\SysWOW64\schtasks.exe 'C:\Windows\System32\schtasks.exe' /Create /TN 'Updates\lVGkcjmu' /XML 'C:\Users\user\AppData\Local\Temp\tmp764A.tmp' Jump to behavior
Source: C:\Users\user\Desktop\COVID 19 BENEFIT FORM 2.exe Process created: C:\Users\user\Desktop\COVID 19 BENEFIT FORM 2.exe {path} Jump to behavior
Source: C:\Users\user\Desktop\COVID 19 BENEFIT FORM 2.exe Process created: C:\Users\user\Desktop\COVID 19 BENEFIT FORM 2.exe {path} Jump to behavior
Source: C:\Users\user\Desktop\COVID 19 BENEFIT FORM 2.exe Process created: C:\Users\user\Desktop\COVID 19 BENEFIT FORM 2.exe {path} Jump to behavior
Source: C:\Users\user\Desktop\COVID 19 BENEFIT FORM 2.exe Process created: C:\Users\user\Desktop\COVID 19 BENEFIT FORM 2.exe {path} Jump to behavior
Source: C:\Users\user\Desktop\COVID 19 BENEFIT FORM 2.exe Key value queried: HKEY_LOCAL_MACHINE\SOFTWARE\Classes\WOW6432Node\CLSID\{95E15D0A-66E6-93D9-C53C-76E6219D3341}\InProcServer32 Jump to behavior
Source: C:\Users\user\Desktop\COVID 19 BENEFIT FORM 2.exe File opened: C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscorrc.dll Jump to behavior
Source: COVID 19 BENEFIT FORM 2.exe Static PE information: data directory type: IMAGE_DIRECTORY_ENTRY_COM_DESCRIPTOR
Source: COVID 19 BENEFIT FORM 2.exe Static PE information: Virtual size of .text is bigger than: 0x100000
Source: COVID 19 BENEFIT FORM 2.exe Static file information: File size 1059328 > 1048576
Source: COVID 19 BENEFIT FORM 2.exe Static PE information: Raw size of .text is bigger than: 0x100000 < 0x102000
Source: COVID 19 BENEFIT FORM 2.exe Static PE information: NO_SEH, TERMINAL_SERVER_AWARE, DYNAMIC_BASE, NX_COMPAT
Source: COVID 19 BENEFIT FORM 2.exe Static PE information: data directory type: IMAGE_DIRECTORY_ENTRY_DEBUG

Data Obfuscation:

barindex
Binary contains a suspicious time stamp
Source: COVID 19 BENEFIT FORM 2.exe Static PE information: 0xD4A32624 [Mon Jan 18 01:38:44 2083 UTC]
Uses code obfuscation techniques (call, push, ret)
Source: C:\Users\user\Desktop\COVID 19 BENEFIT FORM 2.exe Code function: 0_2_00B6B071 push es; ret 0_2_00B6B072
Source: C:\Users\user\Desktop\COVID 19 BENEFIT FORM 2.exe Code function: 0_2_00B6B06B push es; ret 0_2_00B6B06C
Source: C:\Users\user\Desktop\COVID 19 BENEFIT FORM 2.exe Code function: 0_2_0158F930 push eax; iretd 0_2_0158F931
Source: C:\Users\user\Desktop\COVID 19 BENEFIT FORM 2.exe Code function: 0_2_081F67E4 push dword ptr [edx+ebp*2-75h]; iretd 0_2_081F67EF
Source: C:\Users\user\Desktop\COVID 19 BENEFIT FORM 2.exe Code function: 7_2_002AB06B push es; ret 7_2_002AB06C
Source: C:\Users\user\Desktop\COVID 19 BENEFIT FORM 2.exe Code function: 7_2_002AB071 push es; ret 7_2_002AB072
Source: C:\Users\user\Desktop\COVID 19 BENEFIT FORM 2.exe Code function: 8_2_0006B06B push es; ret 8_2_0006B06C
Source: C:\Users\user\Desktop\COVID 19 BENEFIT FORM 2.exe Code function: 8_2_0006B071 push es; ret 8_2_0006B072
Source: C:\Users\user\Desktop\COVID 19 BENEFIT FORM 2.exe Code function: 9_2_0022B06B push es; ret 9_2_0022B06C
Source: C:\Users\user\Desktop\COVID 19 BENEFIT FORM 2.exe Code function: 9_2_0022B071 push es; ret 9_2_0022B072
Source: C:\Users\user\Desktop\COVID 19 BENEFIT FORM 2.exe Code function: 10_2_004CB06B push es; ret 10_2_004CB06C
Source: C:\Users\user\Desktop\COVID 19 BENEFIT FORM 2.exe Code function: 10_2_004CB071 push es; ret 10_2_004CB072
Source: C:\Users\user\Desktop\COVID 19 BENEFIT FORM 2.exe Code function: 10_2_00B59685 push esp; iretd 10_2_00B59686
Source: C:\Users\user\Desktop\COVID 19 BENEFIT FORM 2.exe Code function: 10_2_00C8B5BF push edi; retn 0000h 10_2_00C8B5C1
Source: C:\Users\user\Desktop\COVID 19 BENEFIT FORM 2.exe Code function: 10_2_00CA46F2 push 8BFFFFFFh; retf 10_2_00CA46F8
Source: C:\Users\user\Desktop\COVID 19 BENEFIT FORM 2.exe Code function: 10_2_00CAE613 push edi; ret 10_2_00CAE616
Source: C:\Users\user\Desktop\COVID 19 BENEFIT FORM 2.exe Code function: 10_2_00D9D95C push eax; ret 10_2_00D9D95D
Source: C:\Users\user\Desktop\COVID 19 BENEFIT FORM 2.exe Code function: 10_2_00D9E348 push eax; ret 10_2_00D9E349
Source: initial sample Static PE information: section name: .text entropy: 7.55509346108
Source: initial sample Static PE information: section name: .text entropy: 7.55509346108

Persistence and Installation Behavior:

barindex
Drops PE files
Source: C:\Users\user\Desktop\COVID 19 BENEFIT FORM 2.exe File created: C:\Users\user\AppData\Roaming\lVGkcjmu.exe Jump to dropped file

Boot Survival:

barindex
Uses schtasks.exe or at.exe to add and modify task schedules
Source: C:\Users\user\Desktop\COVID 19 BENEFIT FORM 2.exe Process created: C:\Windows\SysWOW64\schtasks.exe 'C:\Windows\System32\schtasks.exe' /Create /TN 'Updates\lVGkcjmu' /XML 'C:\Users\user\AppData\Local\Temp\tmp764A.tmp'

Hooking and other Techniques for Hiding and Protection:

barindex
Monitors certain registry keys / values for changes (often done to protect autostart functionality)
Source: C:\Users\user\Desktop\COVID 19 BENEFIT FORM 2.exe Registry key monitored for changes: HKEY_CURRENT_USER_Classes Jump to behavior
Source: C:\Users\user\Desktop\COVID 19 BENEFIT FORM 2.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Users\user\Desktop\COVID 19 BENEFIT FORM 2.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Users\user\Desktop\COVID 19 BENEFIT FORM 2.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Users\user\Desktop\COVID 19 BENEFIT FORM 2.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Users\user\Desktop\COVID 19 BENEFIT FORM 2.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Users\user\Desktop\COVID 19 BENEFIT FORM 2.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Users\user\Desktop\COVID 19 BENEFIT FORM 2.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Users\user\Desktop\COVID 19 BENEFIT FORM 2.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Users\user\Desktop\COVID 19 BENEFIT FORM 2.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Users\user\Desktop\COVID 19 BENEFIT FORM 2.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Users\user\Desktop\COVID 19 BENEFIT FORM 2.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Users\user\Desktop\COVID 19 BENEFIT FORM 2.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Users\user\Desktop\COVID 19 BENEFIT FORM 2.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Users\user\Desktop\COVID 19 BENEFIT FORM 2.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Users\user\Desktop\COVID 19 BENEFIT FORM 2.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Users\user\Desktop\COVID 19 BENEFIT FORM 2.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Users\user\Desktop\COVID 19 BENEFIT FORM 2.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Users\user\Desktop\COVID 19 BENEFIT FORM 2.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Users\user\Desktop\COVID 19 BENEFIT FORM 2.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Users\user\Desktop\COVID 19 BENEFIT FORM 2.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Users\user\Desktop\COVID 19 BENEFIT FORM 2.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Users\user\Desktop\COVID 19 BENEFIT FORM 2.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Users\user\Desktop\COVID 19 BENEFIT FORM 2.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Users\user\Desktop\COVID 19 BENEFIT FORM 2.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Users\user\Desktop\COVID 19 BENEFIT FORM 2.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Users\user\Desktop\COVID 19 BENEFIT FORM 2.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Users\user\Desktop\COVID 19 BENEFIT FORM 2.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Users\user\Desktop\COVID 19 BENEFIT FORM 2.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Users\user\Desktop\COVID 19 BENEFIT FORM 2.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Users\user\Desktop\COVID 19 BENEFIT FORM 2.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Users\user\Desktop\COVID 19 BENEFIT FORM 2.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Users\user\Desktop\COVID 19 BENEFIT FORM 2.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Users\user\Desktop\COVID 19 BENEFIT FORM 2.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Users\user\Desktop\COVID 19 BENEFIT FORM 2.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Users\user\Desktop\COVID 19 BENEFIT FORM 2.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Users\user\Desktop\COVID 19 BENEFIT FORM 2.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Users\user\Desktop\COVID 19 BENEFIT FORM 2.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Users\user\Desktop\COVID 19 BENEFIT FORM 2.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Users\user\Desktop\COVID 19 BENEFIT FORM 2.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Users\user\Desktop\COVID 19 BENEFIT FORM 2.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Users\user\Desktop\COVID 19 BENEFIT FORM 2.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Users\user\Desktop\COVID 19 BENEFIT FORM 2.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Users\user\Desktop\COVID 19 BENEFIT FORM 2.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Users\user\Desktop\COVID 19 BENEFIT FORM 2.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Users\user\Desktop\COVID 19 BENEFIT FORM 2.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Users\user\Desktop\COVID 19 BENEFIT FORM 2.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Users\user\Desktop\COVID 19 BENEFIT FORM 2.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Users\user\Desktop\COVID 19 BENEFIT FORM 2.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Users\user\Desktop\COVID 19 BENEFIT FORM 2.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Users\user\Desktop\COVID 19 BENEFIT FORM 2.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Users\user\Desktop\COVID 19 BENEFIT FORM 2.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Users\user\Desktop\COVID 19 BENEFIT FORM 2.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Users\user\Desktop\COVID 19 BENEFIT FORM 2.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Users\user\Desktop\COVID 19 BENEFIT FORM 2.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Users\user\Desktop\COVID 19 BENEFIT FORM 2.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Users\user\Desktop\COVID 19 BENEFIT FORM 2.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Users\user\Desktop\COVID 19 BENEFIT FORM 2.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Users\user\Desktop\COVID 19 BENEFIT FORM 2.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Users\user\Desktop\COVID 19 BENEFIT FORM 2.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Users\user\Desktop\COVID 19 BENEFIT FORM 2.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Users\user\Desktop\COVID 19 BENEFIT FORM 2.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Users\user\Desktop\COVID 19 BENEFIT FORM 2.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Users\user\Desktop\COVID 19 BENEFIT FORM 2.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Users\user\Desktop\COVID 19 BENEFIT FORM 2.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Users\user\Desktop\COVID 19 BENEFIT FORM 2.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Users\user\Desktop\COVID 19 BENEFIT FORM 2.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Users\user\Desktop\COVID 19 BENEFIT FORM 2.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Users\user\Desktop\COVID 19 BENEFIT FORM 2.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Users\user\Desktop\COVID 19 BENEFIT FORM 2.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Users\user\Desktop\COVID 19 BENEFIT FORM 2.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Users\user\Desktop\COVID 19 BENEFIT FORM 2.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Users\user\Desktop\COVID 19 BENEFIT FORM 2.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Users\user\Desktop\COVID 19 BENEFIT FORM 2.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Users\user\Desktop\COVID 19 BENEFIT FORM 2.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Users\user\Desktop\COVID 19 BENEFIT FORM 2.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Users\user\Desktop\COVID 19 BENEFIT FORM 2.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Users\user\Desktop\COVID 19 BENEFIT FORM 2.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Users\user\Desktop\COVID 19 BENEFIT FORM 2.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Users\user\Desktop\COVID 19 BENEFIT FORM 2.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Users\user\Desktop\COVID 19 BENEFIT FORM 2.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Users\user\Desktop\COVID 19 BENEFIT FORM 2.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Users\user\Desktop\COVID 19 BENEFIT FORM 2.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Users\user\Desktop\COVID 19 BENEFIT FORM 2.exe Process information set: NOOPENFILEERRORBOX Jump to behavior

Malware Analysis System Evasion:

barindex
Yara detected AntiVM3
Source: Yara match File source: Process Memory Space: COVID 19 BENEFIT FORM 2.exe PID: 6424, type: MEMORY
Queries sensitive BIOS Information (via WMI, Win32_Bios & Win32_BaseBoard, often done to detect virtual machines)
Source: C:\Users\user\Desktop\COVID 19 BENEFIT FORM 2.exe WMI Queries: IWbemServices::CreateInstanceEnum - root\cimv2 : Win32_BaseBoard
Queries sensitive network adapter information (via WMI, Win32_NetworkAdapter, often done to detect virtual machines)
Source: C:\Users\user\Desktop\COVID 19 BENEFIT FORM 2.exe WMI Queries: IWbemServices::CreateInstanceEnum - root\cimv2 : Win32_NetworkAdapterConfiguration
Tries to detect sandboxes and other dynamic analysis tools (process name or module or function)
Source: COVID 19 BENEFIT FORM 2.exe, 00000000.00000002.375417166.0000000002F21000.00000004.00000001.sdmp Binary or memory string: WINE_GET_UNIX_FILE_NAME
Source: COVID 19 BENEFIT FORM 2.exe, 00000000.00000002.375417166.0000000002F21000.00000004.00000001.sdmp Binary or memory string: SBIEDLL.DLL
Contains capabilities to detect virtual machines
Source: C:\Users\user\Desktop\COVID 19 BENEFIT FORM 2.exe File opened / queried: SCSI#CdRom&Ven_NECVMWar&Prod_VMware_SATA_CD00#5&280b647&0&000000#{53f5630d-b6bf-11d0-94f2-00a0c91efb8b} Jump to behavior
Contains long sleeps (>= 3 min)
Source: C:\Users\user\Desktop\COVID 19 BENEFIT FORM 2.exe Thread delayed: delay time: 922337203685477 Jump to behavior
Source: C:\Users\user\Desktop\COVID 19 BENEFIT FORM 2.exe Thread delayed: delay time: 922337203685477 Jump to behavior
Found a high number of Window / User specific system calls (may be a loop to detect user behavior)
Source: C:\Users\user\Desktop\COVID 19 BENEFIT FORM 2.exe Window / User API: threadDelayed 1059 Jump to behavior
Source: C:\Users\user\Desktop\COVID 19 BENEFIT FORM 2.exe Window / User API: threadDelayed 8793 Jump to behavior
May sleep (evasive loops) to hinder dynamic analysis
Source: C:\Users\user\Desktop\COVID 19 BENEFIT FORM 2.exe TID: 6428 Thread sleep time: -31500s >= -30000s Jump to behavior
Source: C:\Users\user\Desktop\COVID 19 BENEFIT FORM 2.exe TID: 6448 Thread sleep time: -922337203685477s >= -30000s Jump to behavior
Source: C:\Users\user\Desktop\COVID 19 BENEFIT FORM 2.exe TID: 3876 Thread sleep time: -12912720851596678s >= -30000s Jump to behavior
Source: C:\Users\user\Desktop\COVID 19 BENEFIT FORM 2.exe TID: 6504 Thread sleep count: 1059 > 30 Jump to behavior
Source: C:\Users\user\Desktop\COVID 19 BENEFIT FORM 2.exe TID: 6504 Thread sleep count: 8793 > 30 Jump to behavior
Queries sensitive processor information (via WMI, Win32_Processor, often done to detect virtual machines)
Source: C:\Users\user\Desktop\COVID 19 BENEFIT FORM 2.exe WMI Queries: IWbemServices::CreateInstanceEnum - root\cimv2 : Win32_Processor
Sample execution stops while process was sleeping (likely an evasion)
Source: C:\Windows\System32\conhost.exe Last function: Thread delayed
Source: C:\Users\user\Desktop\COVID 19 BENEFIT FORM 2.exe Thread delayed: delay time: 31500 Jump to behavior
Source: C:\Users\user\Desktop\COVID 19 BENEFIT FORM 2.exe Thread delayed: delay time: 922337203685477 Jump to behavior
Source: C:\Users\user\Desktop\COVID 19 BENEFIT FORM 2.exe Thread delayed: delay time: 922337203685477 Jump to behavior
Source: COVID 19 BENEFIT FORM 2.exe, 00000000.00000002.375417166.0000000002F21000.00000004.00000001.sdmp Binary or memory string: VMware SVGA IIOData Source=localhost\sqlexpress;Initial Catalog=dbSMS;Integrated Security=True
Source: COVID 19 BENEFIT FORM 2.exe, 00000000.00000002.375417166.0000000002F21000.00000004.00000001.sdmp Binary or memory string: vmware
Source: COVID 19 BENEFIT FORM 2.exe, 00000000.00000002.375417166.0000000002F21000.00000004.00000001.sdmp Binary or memory string: C:\PROGRAM FILES\VMWARE\VMWARE TOOLS\
Source: COVID 19 BENEFIT FORM 2.exe, 00000000.00000002.375417166.0000000002F21000.00000004.00000001.sdmp Binary or memory string: SOFTWARE\VMware, Inc.\VMware Tools
Source: COVID 19 BENEFIT FORM 2.exe, 00000000.00000002.375417166.0000000002F21000.00000004.00000001.sdmp Binary or memory string: VMWARE
Source: COVID 19 BENEFIT FORM 2.exe, 00000000.00000002.375417166.0000000002F21000.00000004.00000001.sdmp Binary or memory string: InstallPath%C:\PROGRAM FILES\VMWARE\VMWARE TOOLS\
Source: COVID 19 BENEFIT FORM 2.exe, 00000000.00000002.375417166.0000000002F21000.00000004.00000001.sdmp Binary or memory string: VMWARE"SOFTWARE\VMware, Inc.\VMware ToolsLHARDWARE\DEVICEMAP\Scsi\Scsi Port 1\Scsi Bus 0\Target Id 0\Logical Unit Id 0LHARDWARE\DEVICEMAP\Scsi\Scsi Port 2\Scsi Bus 0\Target Id 0\Logical Unit Id 0'SYSTEM\ControlSet001\Services\Disk\Enum
Source: COVID 19 BENEFIT FORM 2.exe, 00000000.00000002.375417166.0000000002F21000.00000004.00000001.sdmp Binary or memory string: VMware SVGA II
Source: COVID 19 BENEFIT FORM 2.exe, 00000000.00000002.375417166.0000000002F21000.00000004.00000001.sdmp Binary or memory string: vmwareNSYSTEM\ControlSet001\Control\Class\{4D36E968-E325-11CE-BFC1-08002BE10318}\0000
Source: COVID 19 BENEFIT FORM 2.exe, 0000000A.00000002.598943149.0000000000E47000.00000004.00000001.sdmp Binary or memory string: Hyper-V RAW%SystemRoot%\system32\mswsock.dll
Source: C:\Users\user\Desktop\COVID 19 BENEFIT FORM 2.exe Process information queried: ProcessInformation Jump to behavior

Anti Debugging:

barindex
Contains functionality to access loader functionality (e.g. LdrGetProcedureAddress)
Source: C:\Users\user\Desktop\COVID 19 BENEFIT FORM 2.exe Code function: 10_2_00B518F8 LdrInitializeThunk, 10_2_00B518F8
Enables debug privileges
Source: C:\Users\user\Desktop\COVID 19 BENEFIT FORM 2.exe Process token adjusted: Debug Jump to behavior
Source: C:\Users\user\Desktop\COVID 19 BENEFIT FORM 2.exe Process token adjusted: Debug Jump to behavior
Source: C:\Users\user\Desktop\COVID 19 BENEFIT FORM 2.exe Memory allocated: page read and write | page guard Jump to behavior

HIPS / PFW / Operating System Protection Evasion:

barindex
Injects a PE file into a foreign processes
Source: C:\Users\user\Desktop\COVID 19 BENEFIT FORM 2.exe Memory written: C:\Users\user\Desktop\COVID 19 BENEFIT FORM 2.exe base: 400000 value starts with: 4D5A Jump to behavior
Creates a process in suspended mode (likely to inject code)
Source: C:\Users\user\Desktop\COVID 19 BENEFIT FORM 2.exe Process created: C:\Windows\SysWOW64\schtasks.exe 'C:\Windows\System32\schtasks.exe' /Create /TN 'Updates\lVGkcjmu' /XML 'C:\Users\user\AppData\Local\Temp\tmp764A.tmp' Jump to behavior
Source: C:\Users\user\Desktop\COVID 19 BENEFIT FORM 2.exe Process created: C:\Users\user\Desktop\COVID 19 BENEFIT FORM 2.exe {path} Jump to behavior
Source: C:\Users\user\Desktop\COVID 19 BENEFIT FORM 2.exe Process created: C:\Users\user\Desktop\COVID 19 BENEFIT FORM 2.exe {path} Jump to behavior
Source: C:\Users\user\Desktop\COVID 19 BENEFIT FORM 2.exe Process created: C:\Users\user\Desktop\COVID 19 BENEFIT FORM 2.exe {path} Jump to behavior
Source: C:\Users\user\Desktop\COVID 19 BENEFIT FORM 2.exe Process created: C:\Users\user\Desktop\COVID 19 BENEFIT FORM 2.exe {path} Jump to behavior
Source: COVID 19 BENEFIT FORM 2.exe, 0000000A.00000002.599020135.00000000012D0000.00000002.00000001.sdmp Binary or memory string: Shell_TrayWnd
Source: COVID 19 BENEFIT FORM 2.exe, 0000000A.00000002.599020135.00000000012D0000.00000002.00000001.sdmp Binary or memory string: Progman
Source: COVID 19 BENEFIT FORM 2.exe, 0000000A.00000002.599020135.00000000012D0000.00000002.00000001.sdmp Binary or memory string: &Program Manager
Source: COVID 19 BENEFIT FORM 2.exe, 0000000A.00000002.599020135.00000000012D0000.00000002.00000001.sdmp Binary or memory string: Progmanlock

Language, Device and Operating System Detection:

barindex
Queries the volume information (name, serial number etc) of a device
Source: C:\Users\user\Desktop\COVID 19 BENEFIT FORM 2.exe Queries volume information: C:\Users\user\Desktop\COVID 19 BENEFIT FORM 2.exe VolumeInformation Jump to behavior
Source: C:\Users\user\Desktop\COVID 19 BENEFIT FORM 2.exe Queries volume information: C:\Windows\Microsoft.NET\assembly\GAC_MSIL\System.Windows.Forms\v4.0_4.0.0.0__b77a5c561934e089\System.Windows.Forms.dll VolumeInformation Jump to behavior
Source: C:\Users\user\Desktop\COVID 19 BENEFIT FORM 2.exe Queries volume information: C:\Windows\Microsoft.NET\assembly\GAC_MSIL\System.Drawing\v4.0_4.0.0.0__b03f5f7f11d50a3a\System.Drawing.dll VolumeInformation Jump to behavior
Source: C:\Users\user\Desktop\COVID 19 BENEFIT FORM 2.exe Queries volume information: C:\Windows\Microsoft.NET\assembly\GAC_MSIL\Accessibility\v4.0_4.0.0.0__b03f5f7f11d50a3a\Accessibility.dll VolumeInformation Jump to behavior
Source: C:\Users\user\Desktop\COVID 19 BENEFIT FORM 2.exe Queries volume information: C:\Windows\Fonts\arial.ttf VolumeInformation Jump to behavior
Source: C:\Users\user\Desktop\COVID 19 BENEFIT FORM 2.exe Queries volume information: C:\Windows\Fonts\ariali.ttf VolumeInformation Jump to behavior
Source: C:\Users\user\Desktop\COVID 19 BENEFIT FORM 2.exe Queries volume information: C:\Windows\Fonts\arialbd.ttf VolumeInformation Jump to behavior
Source: C:\Users\user\Desktop\COVID 19 BENEFIT FORM 2.exe Queries volume information: C:\Windows\Fonts\arialbi.ttf VolumeInformation Jump to behavior
Source: C:\Users\user\Desktop\COVID 19 BENEFIT FORM 2.exe Queries volume information: C:\Windows\Fonts\ARIALN.TTF VolumeInformation Jump to behavior
Source: C:\Users\user\Desktop\COVID 19 BENEFIT FORM 2.exe Queries volume information: C:\Windows\Fonts\ariblk.ttf VolumeInformation Jump to behavior
Source: C:\Users\user\Desktop\COVID 19 BENEFIT FORM 2.exe Queries volume information: C:\Windows\Fonts\ARIALNI.TTF VolumeInformation Jump to behavior
Source: C:\Users\user\Desktop\COVID 19 BENEFIT FORM 2.exe Queries volume information: C:\Windows\Fonts\ARIALNB.TTF VolumeInformation Jump to behavior
Source: C:\Users\user\Desktop\COVID 19 BENEFIT FORM 2.exe Queries volume information: C:\Windows\Fonts\ARIALNBI.TTF VolumeInformation Jump to behavior
Source: C:\Users\user\Desktop\COVID 19 BENEFIT FORM 2.exe Queries volume information: C:\Windows\Fonts\bahnschrift.ttf VolumeInformation Jump to behavior
Source: C:\Users\user\Desktop\COVID 19 BENEFIT FORM 2.exe Queries volume information: C:\Windows\Fonts\calibri.ttf VolumeInformation Jump to behavior
Source: C:\Users\user\Desktop\COVID 19 BENEFIT FORM 2.exe Queries volume information: C:\Windows\Fonts\calibril.ttf VolumeInformation Jump to behavior
Source: C:\Users\user\Desktop\COVID 19 BENEFIT FORM 2.exe Queries volume information: C:\Windows\Fonts\calibrii.ttf VolumeInformation Jump to behavior
Source: C:\Users\user\Desktop\COVID 19 BENEFIT FORM 2.exe Queries volume information: C:\Windows\Fonts\calibrili.ttf VolumeInformation Jump to behavior
Source: C:\Users\user\Desktop\COVID 19 BENEFIT FORM 2.exe Queries volume information: C:\Windows\Fonts\calibrib.ttf VolumeInformation Jump to behavior
Source: C:\Users\user\Desktop\COVID 19 BENEFIT FORM 2.exe Queries volume information: C:\Windows\Fonts\calibriz.ttf VolumeInformation Jump to behavior
Source: C:\Users\user\Desktop\COVID 19 BENEFIT FORM 2.exe Queries volume information: C:\Windows\Fonts\cambria.ttc VolumeInformation Jump to behavior
Source: C:\Users\user\Desktop\COVID 19 BENEFIT FORM 2.exe Queries volume information: C:\Windows\Fonts\cambriai.ttf VolumeInformation Jump to behavior
Source: C:\Users\user\Desktop\COVID 19 BENEFIT FORM 2.exe Queries volume information: C:\Windows\Fonts\cambriab.ttf VolumeInformation Jump to behavior
Source: C:\Users\user\Desktop\COVID 19 BENEFIT FORM 2.exe Queries volume information: C:\Windows\Fonts\cambriaz.ttf VolumeInformation Jump to behavior
Source: C:\Users\user\Desktop\COVID 19 BENEFIT FORM 2.exe Queries volume information: C:\Windows\Fonts\Candara.ttf VolumeInformation Jump to behavior
Source: C:\Users\user\Desktop\COVID 19 BENEFIT FORM 2.exe Queries volume information: C:\Windows\Fonts\Candarai.ttf VolumeInformation Jump to behavior
Source: C:\Users\user\Desktop\COVID 19 BENEFIT FORM 2.exe Queries volume information: C:\Windows\Fonts\Candarab.ttf VolumeInformation Jump to behavior
Source: C:\Users\user\Desktop\COVID 19 BENEFIT FORM 2.exe Queries volume information: C:\Windows\Fonts\Candaraz.ttf VolumeInformation Jump to behavior
Source: C:\Users\user\Desktop\COVID 19 BENEFIT FORM 2.exe Queries volume information: C:\Windows\Fonts\comic.ttf VolumeInformation Jump to behavior
Source: C:\Users\user\Desktop\COVID 19 BENEFIT FORM 2.exe Queries volume information: C:\Windows\Fonts\comici.ttf VolumeInformation Jump to behavior
Source: C:\Users\user\Desktop\COVID 19 BENEFIT FORM 2.exe Queries volume information: C:\Windows\Fonts\comicbd.ttf VolumeInformation Jump to behavior
Source: C:\Users\user\Desktop\COVID 19 BENEFIT FORM 2.exe Queries volume information: C:\Windows\Fonts\comicz.ttf VolumeInformation Jump to behavior
Source: C:\Users\user\Desktop\COVID 19 BENEFIT FORM 2.exe Queries volume information: C:\Windows\Fonts\consola.ttf VolumeInformation Jump to behavior
Source: C:\Users\user\Desktop\COVID 19 BENEFIT FORM 2.exe Queries volume information: C:\Windows\Fonts\consolai.ttf VolumeInformation Jump to behavior
Source: C:\Users\user\Desktop\COVID 19 BENEFIT FORM 2.exe Queries volume information: C:\Windows\Fonts\consolab.ttf VolumeInformation Jump to behavior
Source: C:\Users\user\Desktop\COVID 19 BENEFIT FORM 2.exe Queries volume information: C:\Windows\Fonts\consolaz.ttf VolumeInformation Jump to behavior
Source: C:\Users\user\Desktop\COVID 19 BENEFIT FORM 2.exe Queries volume information: C:\Windows\Fonts\constan.ttf VolumeInformation Jump to behavior
Source: C:\Users\user\Desktop\COVID 19 BENEFIT FORM 2.exe Queries volume information: C:\Windows\Fonts\constani.ttf VolumeInformation Jump to behavior
Source: C:\Users\user\Desktop\COVID 19 BENEFIT FORM 2.exe Queries volume information: C:\Windows\Fonts\constanb.ttf VolumeInformation Jump to behavior
Source: C:\Users\user\Desktop\COVID 19 BENEFIT FORM 2.exe Queries volume information: C:\Windows\Fonts\constanz.ttf VolumeInformation Jump to behavior
Source: C:\Users\user\Desktop\COVID 19 BENEFIT FORM 2.exe Queries volume information: C:\Windows\Fonts\corbel.ttf VolumeInformation Jump to behavior
Source: C:\Users\user\Desktop\COVID 19 BENEFIT FORM 2.exe Queries volume information: C:\Windows\Fonts\corbeli.ttf VolumeInformation Jump to behavior
Source: C:\Users\user\Desktop\COVID 19 BENEFIT FORM 2.exe Queries volume information: C:\Windows\Fonts\corbelb.ttf VolumeInformation Jump to behavior
Source: C:\Users\user\Desktop\COVID 19 BENEFIT FORM 2.exe Queries volume information: C:\Windows\Fonts\corbelz.ttf VolumeInformation Jump to behavior
Source: C:\Users\user\Desktop\COVID 19 BENEFIT FORM 2.exe Queries volume information: C:\Windows\Fonts\cour.ttf VolumeInformation Jump to behavior
Source: C:\Users\user\Desktop\COVID 19 BENEFIT FORM 2.exe Queries volume information: C:\Windows\Fonts\couri.ttf VolumeInformation Jump to behavior
Source: C:\Users\user\Desktop\COVID 19 BENEFIT FORM 2.exe Queries volume information: C:\Windows\Fonts\courbd.ttf VolumeInformation Jump to behavior
Source: C:\Users\user\Desktop\COVID 19 BENEFIT FORM 2.exe Queries volume information: C:\Windows\Fonts\courbi.ttf VolumeInformation Jump to behavior
Source: C:\Users\user\Desktop\COVID 19 BENEFIT FORM 2.exe Queries volume information: C:\Windows\Fonts\ebrima.ttf VolumeInformation Jump to behavior
Source: C:\Users\user\Desktop\COVID 19 BENEFIT FORM 2.exe Queries volume information: C:\Windows\Fonts\ebrimabd.ttf VolumeInformation Jump to behavior
Source: C:\Users\user\Desktop\COVID 19 BENEFIT FORM 2.exe Queries volume information: C:\Windows\Fonts\framd.ttf VolumeInformation Jump to behavior
Source: C:\Users\user\Desktop\COVID 19 BENEFIT FORM 2.exe Queries volume information: C:\Windows\Fonts\FRADM.TTF VolumeInformation Jump to behavior
Source: C:\Users\user\Desktop\COVID 19 BENEFIT FORM 2.exe Queries volume information: C:\Windows\Fonts\framdit.ttf VolumeInformation Jump to behavior
Source: C:\Users\user\Desktop\COVID 19 BENEFIT FORM 2.exe Queries volume information: C:\Windows\Fonts\FRADMIT.TTF VolumeInformation Jump to behavior
Source: C:\Users\user\Desktop\COVID 19 BENEFIT FORM 2.exe Queries volume information: C:\Windows\Fonts\FRAMDCN.TTF VolumeInformation Jump to behavior
Source: C:\Users\user\Desktop\COVID 19 BENEFIT FORM 2.exe Queries volume information: C:\Windows\Fonts\FRADMCN.TTF VolumeInformation Jump to behavior
Source: C:\Users\user\Desktop\COVID 19 BENEFIT FORM 2.exe Queries volume information: C:\Windows\Fonts\FRAHV.TTF VolumeInformation Jump to behavior
Source: C:\Users\user\Desktop\COVID 19 BENEFIT FORM 2.exe Queries volume information: C:\Windows\Fonts\FRAHVIT.TTF VolumeInformation Jump to behavior
Source: C:\Users\user\Desktop\COVID 19 BENEFIT FORM 2.exe Queries volume information: C:\Windows\Fonts\Gabriola.ttf VolumeInformation Jump to behavior
Source: C:\Users\user\Desktop\COVID 19 BENEFIT FORM 2.exe Queries volume information: C:\Windows\Fonts\gadugi.ttf VolumeInformation Jump to behavior
Source: C:\Users\user\Desktop\COVID 19 BENEFIT FORM 2.exe Queries volume information: C:\Windows\Fonts\gadugib.ttf VolumeInformation Jump to behavior
Source: C:\Users\user\Desktop\COVID 19 BENEFIT FORM 2.exe Queries volume information: C:\Windows\Fonts\georgia.ttf VolumeInformation Jump to behavior
Source: C:\Users\user\Desktop\COVID 19 BENEFIT FORM 2.exe Queries volume information: C:\Windows\Fonts\georgiai.ttf VolumeInformation Jump to behavior
Source: C:\Users\user\Desktop\COVID 19 BENEFIT FORM 2.exe Queries volume information: C:\Windows\Fonts\georgiab.ttf VolumeInformation Jump to behavior
Source: C:\Users\user\Desktop\COVID 19 BENEFIT FORM 2.exe Queries volume information: C:\Windows\Fonts\georgiaz.ttf VolumeInformation Jump to behavior
Source: C:\Users\user\Desktop\COVID 19 BENEFIT FORM 2.exe Queries volume information: C:\Windows\Fonts\impact.ttf VolumeInformation Jump to behavior
Source: C:\Users\user\Desktop\COVID 19 BENEFIT FORM 2.exe Queries volume information: C:\Windows\Fonts\Inkfree.ttf VolumeInformation Jump to behavior
Source: C:\Users\user\Desktop\COVID 19 BENEFIT FORM 2.exe Queries volume information: C:\Windows\Fonts\javatext.ttf VolumeInformation Jump to behavior
Source: C:\Users\user\Desktop\COVID 19 BENEFIT FORM 2.exe Queries volume information: C:\Windows\Fonts\LeelawUI.ttf VolumeInformation Jump to behavior
Source: C:\Users\user\Desktop\COVID 19 BENEFIT FORM 2.exe Queries volume information: C:\Windows\Fonts\LeelUIsl.ttf VolumeInformation Jump to behavior
Source: C:\Users\user\Desktop\COVID 19 BENEFIT FORM 2.exe Queries volume information: C:\Windows\Fonts\LeelaUIb.ttf VolumeInformation Jump to behavior
Source: C:\Users\user\Desktop\COVID 19 BENEFIT FORM 2.exe Queries volume information: C:\Windows\Fonts\lucon.ttf VolumeInformation Jump to behavior
Source: C:\Users\user\Desktop\COVID 19 BENEFIT FORM 2.exe Queries volume information: C:\Windows\Fonts\l_10646.ttf VolumeInformation Jump to behavior
Source: C:\Users\user\Desktop\COVID 19 BENEFIT FORM 2.exe Queries volume information: C:\Windows\Fonts\malgun.ttf VolumeInformation Jump to behavior
Source: C:\Users\user\Desktop\COVID 19 BENEFIT FORM 2.exe Queries volume information: C:\Windows\Fonts\malgunsl.ttf VolumeInformation Jump to behavior
Source: C:\Users\user\Desktop\COVID 19 BENEFIT FORM 2.exe Queries volume information: C:\Windows\Fonts\malgunbd.ttf VolumeInformation Jump to behavior
Source: C:\Users\user\Desktop\COVID 19 BENEFIT FORM 2.exe Queries volume information: C:\Windows\Fonts\himalaya.ttf VolumeInformation Jump to behavior
Source: C:\Users\user\Desktop\COVID 19 BENEFIT FORM 2.exe Queries volume information: C:\Windows\Fonts\msjh.ttc VolumeInformation Jump to behavior
Source: C:\Users\user\Desktop\COVID 19 BENEFIT FORM 2.exe Queries volume information: C:\Windows\Fonts\msjhl.ttc VolumeInformation Jump to behavior
Source: C:\Users\user\Desktop\COVID 19 BENEFIT FORM 2.exe Queries volume information: C:\Windows\Fonts\msjhbd.ttc VolumeInformation Jump to behavior
Source: C:\Users\user\Desktop\COVID 19 BENEFIT FORM 2.exe Queries volume information: C:\Windows\Fonts\ntailu.ttf VolumeInformation Jump to behavior
Source: C:\Users\user\Desktop\COVID 19 BENEFIT FORM 2.exe Queries volume information: C:\Windows\Fonts\ntailub.ttf VolumeInformation Jump to behavior
Source: C:\Users\user\Desktop\COVID 19 BENEFIT FORM 2.exe Queries volume information: C:\Windows\Fonts\phagspa.ttf VolumeInformation Jump to behavior
Source: C:\Users\user\Desktop\COVID 19 BENEFIT FORM 2.exe Queries volume information: C:\Windows\Fonts\phagspab.ttf VolumeInformation Jump to behavior
Source: C:\Users\user\Desktop\COVID 19 BENEFIT FORM 2.exe Queries volume information: C:\Windows\Fonts\micross.ttf VolumeInformation Jump to behavior
Source: C:\Users\user\Desktop\COVID 19 BENEFIT FORM 2.exe Queries volume information: C:\Windows\Fonts\taile.ttf VolumeInformation Jump to behavior
Source: C:\Users\user\Desktop\COVID 19 BENEFIT FORM 2.exe Queries volume information: C:\Windows\Fonts\taileb.ttf VolumeInformation Jump to behavior
Source: C:\Users\user\Desktop\COVID 19 BENEFIT FORM 2.exe Queries volume information: C:\Windows\Fonts\msyh.ttc VolumeInformation Jump to behavior
Source: C:\Users\user\Desktop\COVID 19 BENEFIT FORM 2.exe Queries volume information: C:\Windows\Fonts\msyhl.ttc VolumeInformation Jump to behavior
Source: C:\Users\user\Desktop\COVID 19 BENEFIT FORM 2.exe Queries volume information: C:\Windows\Fonts\msyhbd.ttc VolumeInformation Jump to behavior
Source: C:\Users\user\Desktop\COVID 19 BENEFIT FORM 2.exe Queries volume information: C:\Windows\Fonts\msyi.ttf VolumeInformation Jump to behavior
Source: C:\Users\user\Desktop\COVID 19 BENEFIT FORM 2.exe Queries volume information: C:\Windows\Fonts\mingliub.ttc VolumeInformation Jump to behavior
Source: C:\Users\user\Desktop\COVID 19 BENEFIT FORM 2.exe Queries volume information: C:\Windows\Fonts\monbaiti.ttf VolumeInformation Jump to behavior
Source: C:\Users\user\Desktop\COVID 19 BENEFIT FORM 2.exe Queries volume information: C:\Windows\Fonts\msgothic.ttc VolumeInformation Jump to behavior
Source: C:\Users\user\Desktop\COVID 19 BENEFIT FORM 2.exe Queries volume information: C:\Windows\Fonts\mvboli.ttf VolumeInformation Jump to behavior
Source: C:\Users\user\Desktop\COVID 19 BENEFIT FORM 2.exe Queries volume information: C:\Windows\Fonts\mmrtext.ttf VolumeInformation Jump to behavior
Source: C:\Users\user\Desktop\COVID 19 BENEFIT FORM 2.exe Queries volume information: C:\Windows\Fonts\mmrtextb.ttf VolumeInformation Jump to behavior
Source: C:\Users\user\Desktop\COVID 19 BENEFIT FORM 2.exe Queries volume information: C:\Windows\Fonts\Nirmala.ttf VolumeInformation Jump to behavior
Source: C:\Users\user\Desktop\COVID 19 BENEFIT FORM 2.exe Queries volume information: C:\Windows\Fonts\NirmalaS.ttf VolumeInformation Jump to behavior
Source: C:\Users\user\Desktop\COVID 19 BENEFIT FORM 2.exe Queries volume information: C:\Windows\Fonts\NirmalaB.ttf VolumeInformation Jump to behavior
Source: C:\Users\user\Desktop\COVID 19 BENEFIT FORM 2.exe Queries volume information: C:\Windows\Fonts\pala.ttf VolumeInformation Jump to behavior
Source: C:\Users\user\Desktop\COVID 19 BENEFIT FORM 2.exe Queries volume information: C:\Windows\Fonts\palai.ttf VolumeInformation Jump to behavior
Source: C:\Users\user\Desktop\COVID 19 BENEFIT FORM 2.exe Queries volume information: C:\Windows\Fonts\palab.ttf VolumeInformation Jump to behavior
Source: C:\Users\user\Desktop\COVID 19 BENEFIT FORM 2.exe Queries volume information: C:\Windows\Fonts\palabi.ttf VolumeInformation Jump to behavior
Source: C:\Users\user\Desktop\COVID 19 BENEFIT FORM 2.exe Queries volume information: C:\Windows\Fonts\segoepr.ttf VolumeInformation Jump to behavior
Source: C:\Users\user\Desktop\COVID 19 BENEFIT FORM 2.exe Queries volume information: C:\Windows\Fonts\segoeprb.ttf VolumeInformation Jump to behavior
Source: C:\Users\user\Desktop\COVID 19 BENEFIT FORM 2.exe Queries volume information: C:\Windows\Fonts\segoesc.ttf VolumeInformation Jump to behavior
Source: C:\Users\user\Desktop\COVID 19 BENEFIT FORM 2.exe Queries volume information: C:\Windows\Fonts\segoescb.ttf VolumeInformation Jump to behavior
Source: C:\Users\user\Desktop\COVID 19 BENEFIT FORM 2.exe Queries volume information: C:\Windows\Fonts\seguiemj.ttf VolumeInformation Jump to behavior
Source: C:\Users\user\Desktop\COVID 19 BENEFIT FORM 2.exe Queries volume information: C:\Windows\Fonts\seguihis.ttf VolumeInformation Jump to behavior
Source: C:\Users\user\Desktop\COVID 19 BENEFIT FORM 2.exe Queries volume information: C:\Windows\Fonts\seguisym.ttf VolumeInformation Jump to behavior
Source: C:\Users\user\Desktop\COVID 19 BENEFIT FORM 2.exe Queries volume information: C:\Windows\Fonts\simsun.ttc VolumeInformation Jump to behavior
Source: C:\Users\user\Desktop\COVID 19 BENEFIT FORM 2.exe Queries volume information: C:\Windows\Fonts\simsunb.ttf VolumeInformation Jump to behavior
Source: C:\Users\user\Desktop\COVID 19 BENEFIT FORM 2.exe Queries volume information: C:\Windows\Fonts\Sitka.ttc VolumeInformation Jump to behavior
Source: C:\Users\user\Desktop\COVID 19 BENEFIT FORM 2.exe Queries volume information: C:\Windows\Fonts\SitkaI.ttc VolumeInformation Jump to behavior
Source: C:\Users\user\Desktop\COVID 19 BENEFIT FORM 2.exe Queries volume information: C:\Windows\Fonts\SitkaB.ttc VolumeInformation Jump to behavior
Source: C:\Users\user\Desktop\COVID 19 BENEFIT FORM 2.exe Queries volume information: C:\Windows\Fonts\SitkaZ.ttc VolumeInformation Jump to behavior
Source: C:\Users\user\Desktop\COVID 19 BENEFIT FORM 2.exe Queries volume information: C:\Windows\Fonts\sylfaen.ttf VolumeInformation Jump to behavior
Source: C:\Users\user\Desktop\COVID 19 BENEFIT FORM 2.exe Queries volume information: C:\Windows\Fonts\symbol.ttf VolumeInformation Jump to behavior
Source: C:\Users\user\Desktop\COVID 19 BENEFIT FORM 2.exe Queries volume information: C:\Windows\Fonts\tahoma.ttf VolumeInformation Jump to behavior
Source: C:\Users\user\Desktop\COVID 19 BENEFIT FORM 2.exe Queries volume information: C:\Windows\Fonts\tahomabd.ttf VolumeInformation Jump to behavior
Source: C:\Users\user\Desktop\COVID 19 BENEFIT FORM 2.exe Queries volume information: C:\Windows\Fonts\trebuc.ttf VolumeInformation Jump to behavior
Source: C:\Users\user\Desktop\COVID 19 BENEFIT FORM 2.exe Queries volume information: C:\Windows\Fonts\trebucit.ttf VolumeInformation Jump to behavior
Source: C:\Users\user\Desktop\COVID 19 BENEFIT FORM 2.exe Queries volume information: C:\Windows\Fonts\trebucbd.ttf VolumeInformation Jump to behavior
Source: C:\Users\user\Desktop\COVID 19 BENEFIT FORM 2.exe Queries volume information: C:\Windows\Fonts\trebucbi.ttf VolumeInformation Jump to behavior
Source: C:\Users\user\Desktop\COVID 19 BENEFIT FORM 2.exe Queries volume information: C:\Windows\Fonts\verdana.ttf VolumeInformation Jump to behavior
Source: C:\Users\user\Desktop\COVID 19 BENEFIT FORM 2.exe Queries volume information: C:\Windows\Fonts\verdanai.ttf VolumeInformation Jump to behavior
Source: C:\Users\user\Desktop\COVID 19 BENEFIT FORM 2.exe Queries volume information: C:\Windows\Fonts\verdanab.ttf VolumeInformation Jump to behavior
Source: C:\Users\user\Desktop\COVID 19 BENEFIT FORM 2.exe Queries volume information: C:\Windows\Fonts\verdanaz.ttf VolumeInformation Jump to behavior
Source: C:\Users\user\Desktop\COVID 19 BENEFIT FORM 2.exe Queries volume information: C:\Windows\Fonts\webdings.ttf VolumeInformation Jump to behavior
Source: C:\Users\user\Desktop\COVID 19 BENEFIT FORM 2.exe Queries volume information: C:\Windows\Fonts\wingding.ttf VolumeInformation Jump to behavior
Source: C:\Users\user\Desktop\COVID 19 BENEFIT FORM 2.exe Queries volume information: C:\Windows\Fonts\YuGothR.ttc VolumeInformation Jump to behavior
Source: C:\Users\user\Desktop\COVID 19 BENEFIT FORM 2.exe Queries volume information: C:\Windows\Fonts\YuGothM.ttc VolumeInformation Jump to behavior
Source: C:\Users\user\Desktop\COVID 19 BENEFIT FORM 2.exe Queries volume information: C:\Windows\Fonts\YuGothL.ttc VolumeInformation Jump to behavior
Source: C:\Users\user\Desktop\COVID 19 BENEFIT FORM 2.exe Queries volume information: C:\Windows\Fonts\YuGothB.ttc VolumeInformation Jump to behavior
Source: C:\Users\user\Desktop\COVID 19 BENEFIT FORM 2.exe Queries volume information: C:\Windows\Fonts\holomdl2.ttf VolumeInformation Jump to behavior
Source: C:\Users\user\Desktop\COVID 19 BENEFIT FORM 2.exe Queries volume information: C:\Windows\Fonts\CENTURY.TTF VolumeInformation Jump to behavior
Source: C:\Users\user\Desktop\COVID 19 BENEFIT FORM 2.exe Queries volume information: C:\Windows\Fonts\LEELAWAD.TTF VolumeInformation Jump to behavior
Source: C:\Users\user\Desktop\COVID 19 BENEFIT FORM 2.exe Queries volume information: C:\Windows\Fonts\LEELAWDB.TTF VolumeInformation Jump to behavior
Source: C:\Users\user\Desktop\COVID 19 BENEFIT FORM 2.exe Queries volume information: C:\Windows\Fonts\MSUIGHUR.TTF VolumeInformation Jump to behavior
Source: C:\Users\user\Desktop\COVID 19 BENEFIT FORM 2.exe Queries volume information: C:\Windows\Fonts\MSUIGHUB.TTF VolumeInformation Jump to behavior
Source: C:\Users\user\Desktop\COVID 19 BENEFIT FORM 2.exe Queries volume information: C:\Windows\Fonts\WINGDNG2.TTF VolumeInformation Jump to behavior
Source: C:\Users\user\Desktop\COVID 19 BENEFIT FORM 2.exe Queries volume information: C:\Windows\Fonts\WINGDNG3.TTF VolumeInformation Jump to behavior
Source: C:\Users\user\Desktop\COVID 19 BENEFIT FORM 2.exe Queries volume information: C:\Windows\Fonts\TEMPSITC.TTF VolumeInformation Jump to behavior
Source: C:\Users\user\Desktop\COVID 19 BENEFIT FORM 2.exe Queries volume information: C:\Windows\Fonts\PRISTINA.TTF VolumeInformation Jump to behavior
Source: C:\Users\user\Desktop\COVID 19 BENEFIT FORM 2.exe Queries volume information: C:\Windows\Fonts\PAPYRUS.TTF VolumeInformation Jump to behavior
Source: C:\Users\user\Desktop\COVID 19 BENEFIT FORM 2.exe Queries volume information: C:\Windows\Fonts\MISTRAL.TTF VolumeInformation Jump to behavior
Source: C:\Users\user\Desktop\COVID 19 BENEFIT FORM 2.exe Queries volume information: C:\Windows\Fonts\LHANDW.TTF VolumeInformation Jump to behavior
Source: C:\Users\user\Desktop\COVID 19 BENEFIT FORM 2.exe Queries volume information: C:\Windows\Fonts\ITCKRIST.TTF VolumeInformation Jump to behavior
Source: C:\Users\user\Desktop\COVID 19 BENEFIT FORM 2.exe Queries volume information: C:\Windows\Fonts\JUICE___.TTF VolumeInformation Jump to behavior
Source: C:\Users\user\Desktop\COVID 19 BENEFIT FORM 2.exe Queries volume information: C:\Windows\Fonts\FRSCRIPT.TTF VolumeInformation Jump to behavior
Source: C:\Users\user\Desktop\COVID 19 BENEFIT FORM 2.exe Queries volume information: C:\Windows\Fonts\FREESCPT.TTF VolumeInformation Jump to behavior
Source: C:\Users\user\Desktop\COVID 19 BENEFIT FORM 2.exe Queries volume information: C:\Windows\Fonts\BRADHITC.TTF VolumeInformation Jump to behavior
Source: C:\Users\user\Desktop\COVID 19 BENEFIT FORM 2.exe Queries volume information: C:\Windows\Fonts\OUTLOOK.TTF VolumeInformation Jump to behavior
Source: C:\Users\user\Desktop\COVID 19 BENEFIT FORM 2.exe Queries volume information: C:\Windows\Fonts\BKANT.TTF VolumeInformation Jump to behavior
Source: C:\Users\user\Desktop\COVID 19 BENEFIT FORM 2.exe Queries volume information: C:\Windows\Fonts\ANTQUAI.TTF VolumeInformation Jump to behavior
Source: C:\Users\user\Desktop\COVID 19 BENEFIT FORM 2.exe Queries volume information: C:\Windows\Fonts\ANTQUAB.TTF VolumeInformation Jump to behavior
Source: C:\Users\user\Desktop\COVID 19 BENEFIT FORM 2.exe Queries volume information: C:\Windows\Fonts\ANTQUABI.TTF VolumeInformation Jump to behavior
Source: C:\Users\user\Desktop\COVID 19 BENEFIT FORM 2.exe Queries volume information: C:\Windows\Fonts\GARA.TTF VolumeInformation Jump to behavior
Source: C:\Users\user\Desktop\COVID 19 BENEFIT FORM 2.exe Queries volume information: C:\Windows\Fonts\GARAIT.TTF VolumeInformation Jump to behavior
Source: C:\Users\user\Desktop\COVID 19 BENEFIT FORM 2.exe Queries volume information: C:\Windows\Fonts\GARABD.TTF VolumeInformation Jump to behavior
Source: C:\Users\user\Desktop\COVID 19 BENEFIT FORM 2.exe Queries volume information: C:\Windows\Fonts\MTCORSVA.TTF VolumeInformation Jump to behavior
Source: C:\Users\user\Desktop\COVID 19 BENEFIT FORM 2.exe Queries volume information: C:\Windows\Fonts\GOTHIC.TTF VolumeInformation Jump to behavior
Source: C:\Users\user\Desktop\COVID 19 BENEFIT FORM 2.exe Queries volume information: C:\Windows\Fonts\GOTHICI.TTF VolumeInformation Jump to behavior
Source: C:\Users\user\Desktop\COVID 19 BENEFIT FORM 2.exe Queries volume information: C:\Windows\Fonts\GOTHICB.TTF VolumeInformation Jump to behavior
Source: C:\Users\user\Desktop\COVID 19 BENEFIT FORM 2.exe Queries volume information: C:\Windows\Fonts\GOTHICBI.TTF VolumeInformation Jump to behavior
Source: C:\Users\user\Desktop\COVID 19 BENEFIT FORM 2.exe Queries volume information: C:\Windows\Fonts\ALGER.TTF VolumeInformation Jump to behavior
Source: C:\Users\user\Desktop\COVID 19 BENEFIT FORM 2.exe Queries volume information: C:\Windows\Fonts\BASKVILL.TTF VolumeInformation Jump to behavior
Source: C:\Users\user\Desktop\COVID 19 BENEFIT FORM 2.exe Queries volume information: C:\Windows\Fonts\BAUHS93.TTF VolumeInformation Jump to behavior
Source: C:\Users\user\Desktop\COVID 19 BENEFIT FORM 2.exe Queries volume information: C:\Windows\Fonts\BELL.TTF VolumeInformation Jump to behavior
Source: C:\Users\user\Desktop\COVID 19 BENEFIT FORM 2.exe Queries volume information: C:\Windows\Fonts\BELLI.TTF VolumeInformation Jump to behavior
Source: C:\Users\user\Desktop\COVID 19 BENEFIT FORM 2.exe Queries volume information: C:\Windows\Fonts\BELLB.TTF VolumeInformation Jump to behavior
Source: C:\Users\user\Desktop\COVID 19 BENEFIT FORM 2.exe Queries volume information: C:\Windows\Fonts\BRLNSR.TTF VolumeInformation Jump to behavior
Source: C:\Users\user\Desktop\COVID 19 BENEFIT FORM 2.exe Queries volume information: C:\Windows\Fonts\BRLNSDB.TTF VolumeInformation Jump to behavior
Source: C:\Users\user\Desktop\COVID 19 BENEFIT FORM 2.exe Queries volume information: C:\Windows\Fonts\BRLNSB.TTF VolumeInformation Jump to behavior
Source: C:\Users\user\Desktop\COVID 19 BENEFIT FORM 2.exe Queries volume information: C:\Windows\Fonts\BERNHC.TTF VolumeInformation Jump to behavior
Source: C:\Users\user\Desktop\COVID 19 BENEFIT FORM 2.exe Queries volume information: C:\Windows\Fonts\BOD_PSTC.TTF VolumeInformation Jump to behavior
Source: C:\Users\user\Desktop\COVID 19 BENEFIT FORM 2.exe Queries volume information: C:\Windows\Fonts\BRITANIC.TTF VolumeInformation Jump to behavior
Source: C:\Users\user\Desktop\COVID 19 BENEFIT FORM 2.exe Queries volume information: C:\Windows\Fonts\BROADW.TTF VolumeInformation Jump to behavior
Source: C:\Users\user\Desktop\COVID 19 BENEFIT FORM 2.exe Queries volume information: C:\Windows\Fonts\BRUSHSCI.TTF VolumeInformation Jump to behavior
Source: C:\Users\user\Desktop\COVID 19 BENEFIT FORM 2.exe Queries volume information: C:\Windows\Fonts\CALIFR.TTF VolumeInformation Jump to behavior
Source: C:\Users\user\Desktop\COVID 19 BENEFIT FORM 2.exe Queries volume information: C:\Windows\Fonts\CALIFI.TTF VolumeInformation Jump to behavior
Source: C:\Users\user\Desktop\COVID 19 BENEFIT FORM 2.exe Queries volume information: C:\Windows\Fonts\CALIFB.TTF VolumeInformation Jump to behavior
Source: C:\Users\user\Desktop\COVID 19 BENEFIT FORM 2.exe Queries volume information: C:\Windows\Fonts\CENTAUR.TTF VolumeInformation Jump to behavior
Source: C:\Users\user\Desktop\COVID 19 BENEFIT FORM 2.exe Queries volume information: C:\Windows\Fonts\CHILLER.TTF VolumeInformation Jump to behavior
Source: C:\Users\user\Desktop\COVID 19 BENEFIT FORM 2.exe Queries volume information: C:\Windows\Fonts\COLONNA.TTF VolumeInformation Jump to behavior
Source: C:\Users\user\Desktop\COVID 19 BENEFIT FORM 2.exe Queries volume information: C:\Windows\Fonts\COOPBL.TTF VolumeInformation Jump to behavior
Source: C:\Users\user\Desktop\COVID 19 BENEFIT FORM 2.exe Queries volume information: C:\Windows\Fonts\FTLTLT.TTF VolumeInformation Jump to behavior
Source: C:\Users\user\Desktop\COVID 19 BENEFIT FORM 2.exe Queries volume information: C:\Windows\Fonts\HARLOWSI.TTF VolumeInformation Jump to behavior
Source: C:\Users\user\Desktop\COVID 19 BENEFIT FORM 2.exe Queries volume information: C:\Windows\Fonts\HARNGTON.TTF VolumeInformation Jump to behavior
Source: C:\Users\user\Desktop\COVID 19 BENEFIT FORM 2.exe Queries volume information: C:\Windows\Fonts\HTOWERT.TTF VolumeInformation Jump to behavior
Source: C:\Users\user\Desktop\COVID 19 BENEFIT FORM 2.exe Queries volume information: C:\Windows\Fonts\HTOWERTI.TTF VolumeInformation Jump to behavior
Source: C:\Users\user\Desktop\COVID 19 BENEFIT FORM 2.exe Queries volume information: C:\Windows\Fonts\JOKERMAN.TTF VolumeInformation Jump to behavior
Source: C:\Users\user\Desktop\COVID 19 BENEFIT FORM 2.exe Queries volume information: C:\Windows\Fonts\KUNSTLER.TTF VolumeInformation Jump to behavior
Source: C:\Users\user\Desktop\COVID 19 BENEFIT FORM 2.exe Queries volume information: C:\Windows\Fonts\LBRITE.TTF VolumeInformation Jump to behavior
Source: C:\Users\user\Desktop\COVID 19 BENEFIT FORM 2.exe Queries volume information: C:\Windows\Fonts\LBRITED.TTF VolumeInformation Jump to behavior
Source: C:\Users\user\Desktop\COVID 19 BENEFIT FORM 2.exe Queries volume information: C:\Windows\Fonts\LBRITEI.TTF VolumeInformation Jump to behavior
Source: C:\Users\user\Desktop\COVID 19 BENEFIT FORM 2.exe Queries volume information: C:\Windows\Fonts\LBRITEDI.TTF VolumeInformation Jump to behavior
Source: C:\Users\user\Desktop\COVID 19 BENEFIT FORM 2.exe Queries volume information: C:\Windows\Fonts\LCALLIG.TTF VolumeInformation Jump to behavior
Source: C:\Users\user\Desktop\COVID 19 BENEFIT FORM 2.exe Queries volume information: C:\Windows\Fonts\LFAX.TTF VolumeInformation Jump to behavior
Source: C:\Users\user\Desktop\COVID 19 BENEFIT FORM 2.exe Queries volume information: C:\Windows\Fonts\LFAXD.TTF VolumeInformation Jump to behavior
Source: C:\Users\user\Desktop\COVID 19 BENEFIT FORM 2.exe Queries volume information: C:\Windows\Fonts\LFAXI.TTF VolumeInformation Jump to behavior
Source: C:\Users\user\Desktop\COVID 19 BENEFIT FORM 2.exe Queries volume information: C:\Windows\Fonts\LFAXDI.TTF VolumeInformation Jump to behavior
Source: C:\Users\user\Desktop\COVID 19 BENEFIT FORM 2.exe Queries volume information: C:\Windows\Fonts\MAGNETOB.TTF VolumeInformation Jump to behavior
Source: C:\Users\user\Desktop\COVID 19 BENEFIT FORM 2.exe Queries volume information: C:\Windows\Fonts\MATURASC.TTF VolumeInformation Jump to behavior
Source: C:\Users\user\Desktop\COVID 19 BENEFIT FORM 2.exe Queries volume information: C:\Windows\Fonts\MOD20.TTF VolumeInformation Jump to behavior
Source: C:\Users\user\Desktop\COVID 19 BENEFIT FORM 2.exe Queries volume information: C:\Windows\Fonts\NIAGENG.TTF VolumeInformation Jump to behavior
Source: C:\Users\user\Desktop\COVID 19 BENEFIT FORM 2.exe Queries volume information: C:\Windows\Fonts\NIAGSOL.TTF VolumeInformation Jump to behavior
Source: C:\Users\user\Desktop\COVID 19 BENEFIT FORM 2.exe Queries volume information: C:\Windows\Fonts\OLDENGL.TTF VolumeInformation Jump to behavior
Source: C:\Users\user\Desktop\COVID 19 BENEFIT FORM 2.exe Queries volume information: C:\Windows\Fonts\ONYX.TTF VolumeInformation Jump to behavior
Source: C:\Users\user\Desktop\COVID 19 BENEFIT FORM 2.exe Queries volume information: C:\Windows\Fonts\PARCHM.TTF VolumeInformation Jump to behavior
Source: C:\Users\user\Desktop\COVID 19 BENEFIT FORM 2.exe Queries volume information: C:\Windows\Fonts\PLAYBILL.TTF VolumeInformation Jump to behavior
Source: C:\Users\user\Desktop\COVID 19 BENEFIT FORM 2.exe Queries volume information: C:\Windows\Fonts\POORICH.TTF VolumeInformation Jump to behavior
Source: C:\Users\user\Desktop\COVID 19 BENEFIT FORM 2.exe Queries volume information: C:\Windows\Fonts\RAVIE.TTF VolumeInformation Jump to behavior
Source: C:\Users\user\Desktop\COVID 19 BENEFIT FORM 2.exe Queries volume information: C:\Windows\Fonts\INFROMAN.TTF VolumeInformation Jump to behavior
Source: C:\Users\user\Desktop\COVID 19 BENEFIT FORM 2.exe Queries volume information: C:\Windows\Fonts\SHOWG.TTF VolumeInformation Jump to behavior
Source: C:\Users\user\Desktop\COVID 19 BENEFIT FORM 2.exe Queries volume information: C:\Windows\Fonts\SNAP____.TTF VolumeInformation Jump to behavior
Source: C:\Users\user\Desktop\COVID 19 BENEFIT FORM 2.exe Queries volume information: C:\Windows\Fonts\STENCIL.TTF VolumeInformation Jump to behavior
Source: C:\Users\user\Desktop\COVID 19 BENEFIT FORM 2.exe Queries volume information: C:\Windows\Fonts\VINERITC.TTF VolumeInformation Jump to behavior
Source: C:\Users\user\Desktop\COVID 19 BENEFIT FORM 2.exe Queries volume information: C:\Windows\Fonts\VIVALDII.TTF VolumeInformation Jump to behavior
Source: C:\Users\user\Desktop\COVID 19 BENEFIT FORM 2.exe Queries volume information: C:\Windows\Fonts\VLADIMIR.TTF VolumeInformation Jump to behavior
Source: C:\Users\user\Desktop\COVID 19 BENEFIT FORM 2.exe Queries volume information: C:\Windows\Fonts\LATINWD.TTF VolumeInformation Jump to behavior
Source: C:\Users\user\Desktop\COVID 19 BENEFIT FORM 2.exe Queries volume information: C:\Windows\Fonts\TCM_____.TTF VolumeInformation Jump to behavior
Source: C:\Users\user\Desktop\COVID 19 BENEFIT FORM 2.exe Queries volume information: C:\Windows\Fonts\TCMI____.TTF VolumeInformation Jump to behavior
Source: C:\Users\user\Desktop\COVID 19 BENEFIT FORM 2.exe Queries volume information: C:\Windows\Fonts\TCB_____.TTF VolumeInformation Jump to behavior
Source: C:\Users\user\Desktop\COVID 19 BENEFIT FORM 2.exe Queries volume information: C:\Windows\Fonts\TCBI____.TTF VolumeInformation Jump to behavior
Source: C:\Users\user\Desktop\COVID 19 BENEFIT FORM 2.exe Queries volume information: C:\Windows\Fonts\TCCM____.TTF VolumeInformation Jump to behavior
Source: C:\Users\user\Desktop\COVID 19 BENEFIT FORM 2.exe Queries volume information: C:\Windows\Fonts\TCCB____.TTF VolumeInformation Jump to behavior
Source: C:\Users\user\Desktop\COVID 19 BENEFIT FORM 2.exe Queries volume information: C:\Windows\Fonts\TCCEB.TTF VolumeInformation Jump to behavior
Source: C:\Users\user\Desktop\COVID 19 BENEFIT FORM 2.exe Queries volume information: C:\Windows\Fonts\SCRIPTBL.TTF VolumeInformation Jump to behavior
Source: C:\Users\user\Desktop\COVID 19 BENEFIT FORM 2.exe Queries volume information: C:\Windows\Fonts\ROCK.TTF VolumeInformation Jump to behavior
Source: C:\Users\user\Desktop\COVID 19 BENEFIT FORM 2.exe Queries volume information: C:\Windows\Fonts\ROCKI.TTF VolumeInformation Jump to behavior
Source: C:\Users\user\Desktop\COVID 19 BENEFIT FORM 2.exe Queries volume information: C:\Windows\Fonts\ROCKB.TTF VolumeInformation Jump to behavior
Source: C:\Users\user\Desktop\COVID 19 BENEFIT FORM 2.exe Queries volume information: C:\Windows\Fonts\ROCKEB.TTF VolumeInformation Jump to behavior
Source: C:\Users\user\Desktop\COVID 19 BENEFIT FORM 2.exe Queries volume information: C:\Windows\Fonts\ROCKBI.TTF VolumeInformation Jump to behavior
Source: C:\Users\user\Desktop\COVID 19 BENEFIT FORM 2.exe Queries volume information: C:\Windows\Fonts\ROCC____.TTF VolumeInformation Jump to behavior
Source: C:\Users\user\Desktop\COVID 19 BENEFIT FORM 2.exe Queries volume information: C:\Windows\Fonts\ROCCB___.TTF VolumeInformation Jump to behavior
Source: C:\Users\user\Desktop\COVID 19 BENEFIT FORM 2.exe Queries volume information: C:\Windows\Fonts\RAGE.TTF VolumeInformation Jump to behavior
Source: C:\Users\user\Desktop\COVID 19 BENEFIT FORM 2.exe Queries volume information: C:\Windows\Fonts\PERTILI.TTF VolumeInformation Jump to behavior
Source: C:\Users\user\Desktop\COVID 19 BENEFIT FORM 2.exe Queries volume information: C:\Windows\Fonts\PERTIBD.TTF VolumeInformation Jump to behavior
Source: C:\Users\user\Desktop\COVID 19 BENEFIT FORM 2.exe Queries volume information: C:\Windows\Fonts\PER_____.TTF VolumeInformation Jump to behavior
Source: C:\Users\user\Desktop\COVID 19 BENEFIT FORM 2.exe Queries volume information: C:\Windows\Fonts\PERI____.TTF VolumeInformation Jump to behavior
Source: C:\Users\user\Desktop\COVID 19 BENEFIT FORM 2.exe Queries volume information: C:\Windows\Fonts\PERB____.TTF VolumeInformation Jump to behavior
Source: C:\Users\user\Desktop\COVID 19 BENEFIT FORM 2.exe Queries volume information: C:\Windows\Fonts\PERBI___.TTF VolumeInformation Jump to behavior
Source: C:\Users\user\Desktop\COVID 19 BENEFIT FORM 2.exe Queries volume information: C:\Windows\Fonts\PALSCRI.TTF VolumeInformation Jump to behavior
Source: C:\Users\user\Desktop\COVID 19 BENEFIT FORM 2.exe Queries volume information: C:\Windows\Fonts\OCRAEXT.TTF VolumeInformation Jump to behavior
Source: C:\Users\user\Desktop\COVID 19 BENEFIT FORM 2.exe Queries volume information: C:\Windows\Fonts\MAIAN.TTF VolumeInformation Jump to behavior
Source: C:\Users\user\Desktop\COVID 19 BENEFIT FORM 2.exe Queries volume information: C:\Windows\Fonts\LTYPE.TTF VolumeInformation Jump to behavior
Source: C:\Users\user\Desktop\COVID 19 BENEFIT FORM 2.exe Queries volume information: C:\Windows\Fonts\LTYPEO.TTF VolumeInformation Jump to behavior
Source: C:\Users\user\Desktop\COVID 19 BENEFIT FORM 2.exe Queries volume information: C:\Windows\Fonts\LTYPEB.TTF VolumeInformation Jump to behavior
Source: C:\Users\user\Desktop\COVID 19 BENEFIT FORM 2.exe Queries volume information: C:\Windows\Fonts\LTYPEBO.TTF VolumeInformation Jump to behavior
Source: C:\Users\user\Desktop\COVID 19 BENEFIT FORM 2.exe Queries volume information: C:\Windows\Fonts\LSANS.TTF VolumeInformation Jump to behavior
Source: C:\Users\user\Desktop\COVID 19 BENEFIT FORM 2.exe Queries volume information: C:\Windows\Fonts\LSANSD.TTF VolumeInformation Jump to behavior
Source: C:\Users\user\Desktop\COVID 19 BENEFIT FORM 2.exe Queries volume information: C:\Windows\Fonts\LSANSI.TTF VolumeInformation Jump to behavior
Source: C:\Users\user\Desktop\COVID 19 BENEFIT FORM 2.exe Queries volume information: C:\Windows\Fonts\LSANSDI.TTF VolumeInformation Jump to behavior
Source: C:\Users\user\Desktop\COVID 19 BENEFIT FORM 2.exe Queries volume information: C:\Windows\Fonts\IMPRISHA.TTF VolumeInformation Jump to behavior
Source: C:\Users\user\Desktop\COVID 19 BENEFIT FORM 2.exe Queries volume information: C:\Windows\Fonts\HATTEN.TTF VolumeInformation Jump to behavior
Source: C:\Users\user\Desktop\COVID 19 BENEFIT FORM 2.exe Queries volume information: C:\Windows\Fonts\GOUDYSTO.TTF VolumeInformation Jump to behavior
Source: C:\Users\user\Desktop\COVID 19 BENEFIT FORM 2.exe Queries volume information: C:\Windows\Fonts\GOUDOS.TTF VolumeInformation Jump to behavior
Source: C:\Users\user\Desktop\COVID 19 BENEFIT FORM 2.exe Queries volume information: C:\Windows\Fonts\GOUDOSI.TTF VolumeInformation Jump to behavior
Source: C:\Users\user\Desktop\COVID 19 BENEFIT FORM 2.exe Queries volume information: C:\Windows\Fonts\GOUDOSB.TTF VolumeInformation Jump to behavior
Source: C:\Users\user\Desktop\COVID 19 BENEFIT FORM 2.exe Queries volume information: C:\Windows\Fonts\GLECB.TTF VolumeInformation Jump to behavior
Source: C:\Users\user\Desktop\COVID 19 BENEFIT FORM 2.exe Queries volume information: C:\Windows\Fonts\GIL_____.TTF VolumeInformation Jump to behavior
Source: C:\Users\user\Desktop\COVID 19 BENEFIT FORM 2.exe Queries volume information: C:\Windows\Fonts\GILI____.TTF VolumeInformation Jump to behavior
Source: C:\Users\user\Desktop\COVID 19 BENEFIT FORM 2.exe Queries volume information: C:\Windows\Fonts\GILB____.TTF VolumeInformation Jump to behavior
Source: C:\Users\user\Desktop\COVID 19 BENEFIT FORM 2.exe Queries volume information: C:\Windows\Fonts\GILBI___.TTF VolumeInformation Jump to behavior
Source: C:\Users\user\Desktop\COVID 19 BENEFIT FORM 2.exe Queries volume information: C:\Windows\Fonts\GILC____.TTF VolumeInformation Jump to behavior
Source: C:\Users\user\Desktop\COVID 19 BENEFIT FORM 2.exe Queries volume information: C:\Windows\Fonts\GLSNECB.TTF VolumeInformation Jump to behavior
Source: C:\Users\user\Desktop\COVID 19 BENEFIT FORM 2.exe Queries volume information: C:\Windows\Fonts\GIGI.TTF VolumeInformation Jump to behavior
Source: C:\Users\user\Desktop\COVID 19 BENEFIT FORM 2.exe Queries volume information: C:\Windows\Fonts\FRABK.TTF VolumeInformation Jump to behavior
Source: C:\Users\user\Desktop\COVID 19 BENEFIT FORM 2.exe Queries volume information: C:\Windows\Fonts\FRABKIT.TTF VolumeInformation Jump to behavior
Source: C:\Users\user\Desktop\COVID 19 BENEFIT FORM 2.exe Queries volume information: C:\Windows\Fonts\FORTE.TTF VolumeInformation Jump to behavior
Source: C:\Users\user\Desktop\COVID 19 BENEFIT FORM 2.exe Queries volume information: C:\Windows\Fonts\FELIXTI.TTF VolumeInformation Jump to behavior
Source: C:\Users\user\Desktop\COVID 19 BENEFIT FORM 2.exe Queries volume information: C:\Windows\Fonts\ERASMD.TTF VolumeInformation Jump to behavior
Source: C:\Users\user\Desktop\COVID 19 BENEFIT FORM 2.exe Queries volume information: C:\Windows\Fonts\ERASLGHT.TTF VolumeInformation Jump to behavior
Source: C:\Users\user\Desktop\COVID 19 BENEFIT FORM 2.exe Queries volume information: C:\Windows\Fonts\ERASDEMI.TTF VolumeInformation Jump to behavior
Source: C:\Users\user\Desktop\COVID 19 BENEFIT FORM 2.exe Queries volume information: C:\Windows\Fonts\ERASBD.TTF VolumeInformation Jump to behavior
Source: C:\Users\user\Desktop\COVID 19 BENEFIT FORM 2.exe Queries volume information: C:\Windows\Fonts\ENGR.TTF VolumeInformation Jump to behavior
Source: C:\Users\user\Desktop\COVID 19 BENEFIT FORM 2.exe Queries volume information: C:\Windows\Fonts\ELEPHNT.TTF VolumeInformation Jump to behavior
Source: C:\Users\user\Desktop\COVID 19 BENEFIT FORM 2.exe Queries volume information: C:\Windows\Fonts\ELEPHNTI.TTF VolumeInformation Jump to behavior
Source: C:\Users\user\Desktop\COVID 19 BENEFIT FORM 2.exe Queries volume information: C:\Windows\Fonts\ITCEDSCR.TTF VolumeInformation Jump to behavior
Source: C:\Users\user\Desktop\COVID 19 BENEFIT FORM 2.exe Queries volume information: C:\Windows\Fonts\CURLZ___.TTF VolumeInformation Jump to behavior
Source: C:\Users\user\Desktop\COVID 19 BENEFIT FORM 2.exe Queries volume information: C:\Windows\Fonts\COPRGTL.TTF VolumeInformation Jump to behavior
Source: C:\Users\user\Desktop\COVID 19 BENEFIT FORM 2.exe Queries volume information: C:\Windows\Fonts\COPRGTB.TTF VolumeInformation Jump to behavior
Source: C:\Users\user\Desktop\COVID 19 BENEFIT FORM 2.exe Queries volume information: C:\Windows\Fonts\CENSCBK.TTF VolumeInformation Jump to behavior
Source: C:\Users\user\Desktop\COVID 19 BENEFIT FORM 2.exe Queries volume information: C:\Windows\Fonts\SCHLBKI.TTF VolumeInformation Jump to behavior
Source: C:\Users\user\Desktop\COVID 19 BENEFIT FORM 2.exe Queries volume information: C:\Windows\Fonts\SCHLBKB.TTF VolumeInformation Jump to behavior
Source: C:\Users\user\Desktop\COVID 19 BENEFIT FORM 2.exe Queries volume information: C:\Windows\Fonts\SCHLBKBI.TTF VolumeInformation Jump to behavior
Source: C:\Users\user\Desktop\COVID 19 BENEFIT FORM 2.exe Queries volume information: C:\Windows\Fonts\CASTELAR.TTF VolumeInformation Jump to behavior
Source: C:\Users\user\Desktop\COVID 19 BENEFIT FORM 2.exe Queries volume information: C:\Windows\Fonts\CALIST.TTF VolumeInformation Jump to behavior
Source: C:\Users\user\Desktop\COVID 19 BENEFIT FORM 2.exe Queries volume information: C:\Windows\Fonts\CALISTI.TTF VolumeInformation Jump to behavior
Source: C:\Users\user\Desktop\COVID 19 BENEFIT FORM 2.exe Queries volume information: C:\Windows\Fonts\CALISTB.TTF VolumeInformation Jump to behavior
Source: C:\Users\user\Desktop\COVID 19 BENEFIT FORM 2.exe Queries volume information: C:\Windows\Fonts\CALISTBI.TTF VolumeInformation Jump to behavior
Source: C:\Users\user\Desktop\COVID 19 BENEFIT FORM 2.exe Queries volume information: C:\Windows\Fonts\BOOKOS.TTF VolumeInformation Jump to behavior
Source: C:\Users\user\Desktop\COVID 19 BENEFIT FORM 2.exe Queries volume information: C:\Windows\Fonts\BOOKOSB.TTF VolumeInformation Jump to behavior
Source: C:\Users\user\Desktop\COVID 19 BENEFIT FORM 2.exe Queries volume information: C:\Windows\Fonts\BOOKOSI.TTF VolumeInformation Jump to behavior
Source: C:\Users\user\Desktop\COVID 19 BENEFIT FORM 2.exe Queries volume information: C:\Windows\Fonts\BOOKOSBI.TTF VolumeInformation Jump to behavior
Source: C:\Users\user\Desktop\COVID 19 BENEFIT FORM 2.exe Queries volume information: C:\Windows\Fonts\BOD_R.TTF VolumeInformation Jump to behavior
Source: C:\Users\user\Desktop\COVID 19 BENEFIT FORM 2.exe Queries volume information: C:\Windows\Fonts\BOD_I.TTF VolumeInformation Jump to behavior
Source: C:\Users\user\Desktop\COVID 19 BENEFIT FORM 2.exe Queries volume information: C:\Windows\Fonts\BOD_B.TTF VolumeInformation Jump to behavior
Source: C:\Users\user\Desktop\COVID 19 BENEFIT FORM 2.exe Queries volume information: C:\Windows\Fonts\BOD_BI.TTF VolumeInformation Jump to behavior
Source: C:\Users\user\Desktop\COVID 19 BENEFIT FORM 2.exe Queries volume information: C:\Windows\Fonts\BOD_CR.TTF VolumeInformation Jump to behavior
Source: C:\Users\user\Desktop\COVID 19 BENEFIT FORM 2.exe Queries volume information: C:\Windows\Fonts\BOD_BLAR.TTF VolumeInformation Jump to behavior
Source: C:\Users\user\Desktop\COVID 19 BENEFIT FORM 2.exe Queries volume information: C:\Windows\Fonts\BOD_CI.TTF VolumeInformation Jump to behavior
Source: C:\Users\user\Desktop\COVID 19 BENEFIT FORM 2.exe Queries volume information: C:\Windows\Fonts\BOD_CB.TTF VolumeInformation Jump to behavior
Source: C:\Users\user\Desktop\COVID 19 BENEFIT FORM 2.exe Queries volume information: C:\Windows\Fonts\BOD_BLAI.TTF VolumeInformation Jump to behavior
Source: C:\Users\user\Desktop\COVID 19 BENEFIT FORM 2.exe Queries volume information: C:\Windows\Fonts\BOD_CBI.TTF VolumeInformation Jump to behavior
Source: C:\Users\user\Desktop\COVID 19 BENEFIT FORM 2.exe Queries volume information: C:\Windows\Fonts\ITCBLKAD.TTF VolumeInformation Jump to behavior
Source: C:\Users\user\Desktop\COVID 19 BENEFIT FORM 2.exe Queries volume information: C:\Windows\Fonts\ARLRDBD.TTF VolumeInformation Jump to behavior
Source: C:\Users\user\Desktop\COVID 19 BENEFIT FORM 2.exe Queries volume information: C:\Windows\Fonts\AGENCYR.TTF VolumeInformation Jump to behavior
Source: C:\Users\user\Desktop\COVID 19 BENEFIT FORM 2.exe Queries volume information: C:\Windows\Fonts\AGENCYB.TTF VolumeInformation Jump to behavior
Source: C:\Users\user\Desktop\COVID 19 BENEFIT FORM 2.exe Queries volume information: C:\Windows\Fonts\BSSYM7.TTF VolumeInformation Jump to behavior
Source: C:\Users\user\Desktop\COVID 19 BENEFIT FORM 2.exe Queries volume information: C:\Windows\Fonts\REFSAN.TTF VolumeInformation Jump to behavior
Source: C:\Users\user\Desktop\COVID 19 BENEFIT FORM 2.exe Queries volume information: C:\Windows\Fonts\REFSPCL.TTF VolumeInformation Jump to behavior
Source: C:\Users\user\Desktop\COVID 19 BENEFIT FORM 2.exe Queries volume information: C:\Windows\Fonts\MTEXTRA.TTF VolumeInformation Jump to behavior
Source: C:\Users\user\Desktop\COVID 19 BENEFIT FORM 2.exe Queries volume information: C:\Windows\Fonts\marlett.ttf VolumeInformation Jump to behavior
Source: C:\Users\user\Desktop\COVID 19 BENEFIT FORM 2.exe Queries volume information: C:\Windows\Fonts\msyhl.ttc VolumeInformation Jump to behavior
Source: C:\Users\user\Desktop\COVID 19 BENEFIT FORM 2.exe Queries volume information: C:\Windows\Fonts\micross.ttf VolumeInformation Jump to behavior
Source: C:\Users\user\Desktop\COVID 19 BENEFIT FORM 2.exe Queries volume information: C:\Windows\Microsoft.NET\assembly\GAC_MSIL\Microsoft.VisualBasic\v4.0_10.0.0.0__b03f5f7f11d50a3a\Microsoft.VisualBasic.dll VolumeInformation Jump to behavior
Source: C:\Users\user\Desktop\COVID 19 BENEFIT FORM 2.exe Queries volume information: C:\Users\user\Desktop\COVID 19 BENEFIT FORM 2.exe VolumeInformation Jump to behavior
Source: C:\Users\user\Desktop\COVID 19 BENEFIT FORM 2.exe Queries volume information: C:\Windows\Microsoft.NET\assembly\GAC_MSIL\System.Windows.Forms\v4.0_4.0.0.0__b77a5c561934e089\System.Windows.Forms.dll VolumeInformation Jump to behavior
Source: C:\Users\user\Desktop\COVID 19 BENEFIT FORM 2.exe Queries volume information: C:\Windows\Microsoft.NET\assembly\GAC_MSIL\Microsoft.VisualBasic\v4.0_10.0.0.0__b03f5f7f11d50a3a\Microsoft.VisualBasic.dll VolumeInformation Jump to behavior
Source: C:\Users\user\Desktop\COVID 19 BENEFIT FORM 2.exe Queries volume information: C:\Windows\Microsoft.NET\assembly\GAC_32\CustomMarshalers\v4.0_4.0.0.0__b03f5f7f11d50a3a\CustomMarshalers.dll VolumeInformation Jump to behavior
Source: C:\Users\user\Desktop\COVID 19 BENEFIT FORM 2.exe Queries volume information: C:\Windows\Microsoft.NET\assembly\GAC_32\CustomMarshalers\v4.0_4.0.0.0__b03f5f7f11d50a3a\CustomMarshalers.dll VolumeInformation Jump to behavior
Source: C:\Users\user\Desktop\COVID 19 BENEFIT FORM 2.exe Queries volume information: C:\Windows\Microsoft.NET\assembly\GAC_32\CustomMarshalers\v4.0_4.0.0.0__b03f5f7f11d50a3a\CustomMarshalers.dll VolumeInformation Jump to behavior
Source: C:\Users\user\Desktop\COVID 19 BENEFIT FORM 2.exe Queries volume information: C:\Windows\Microsoft.NET\assembly\GAC_MSIL\System.Management\v4.0_4.0.0.0__b03f5f7f11d50a3a\System.Management.dll VolumeInformation Jump to behavior
Source: C:\Users\user\Desktop\COVID 19 BENEFIT FORM 2.exe Queries volume information: C:\Windows\Microsoft.NET\assembly\GAC_MSIL\System.Drawing\v4.0_4.0.0.0__b03f5f7f11d50a3a\System.Drawing.dll VolumeInformation Jump to behavior
Source: C:\Users\user\Desktop\COVID 19 BENEFIT FORM 2.exe Key value queried: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Cryptography MachineGuid Jump to behavior

Stealing of Sensitive Information:

barindex
Yara detected AgentTesla
Source: Yara match File source: 0000000A.00000002.596294759.0000000000402000.00000040.00000001.sdmp, type: MEMORY
Source: Yara match File source: 0000000A.00000002.599311455.0000000002871000.00000004.00000001.sdmp, type: MEMORY
Source: Yara match File source: 00000000.00000002.377564391.00000000040CD000.00000004.00000001.sdmp, type: MEMORY
Source: Yara match File source: 00000000.00000002.377324089.0000000003F29000.00000004.00000001.sdmp, type: MEMORY
Source: Yara match File source: Process Memory Space: COVID 19 BENEFIT FORM 2.exe PID: 6424, type: MEMORY
Source: Yara match File source: Process Memory Space: COVID 19 BENEFIT FORM 2.exe PID: 7000, type: MEMORY
Source: Yara match File source: 0.2.COVID 19 BENEFIT FORM 2.exe.4293c80.2.unpack, type: UNPACKEDPE
Source: Yara match File source: 10.2.COVID 19 BENEFIT FORM 2.exe.400000.0.unpack, type: UNPACKEDPE
Source: Yara match File source: 0.2.COVID 19 BENEFIT FORM 2.exe.4293c80.2.raw.unpack, type: UNPACKEDPE
Tries to harvest and steal Putty / WinSCP information (sessions, passwords, etc)
Source: C:\Users\user\Desktop\COVID 19 BENEFIT FORM 2.exe Key opened: HKEY_CURRENT_USER\SOFTWARE\Martin Prikryl\WinSCP 2\Sessions Jump to behavior
Tries to harvest and steal browser information (history, passwords, etc)
Source: C:\Users\user\Desktop\COVID 19 BENEFIT FORM 2.exe File opened: C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Login Data Jump to behavior
Source: C:\Users\user\Desktop\COVID 19 BENEFIT FORM 2.exe File opened: C:\Users\user\AppData\Roaming\Mozilla\Firefox\profiles.ini Jump to behavior
Tries to harvest and steal ftp login credentials
Source: C:\Users\user\Desktop\COVID 19 BENEFIT FORM 2.exe File opened: C:\Users\user\AppData\Roaming\FileZilla\recentservers.xml Jump to behavior
Source: C:\Users\user\Desktop\COVID 19 BENEFIT FORM 2.exe File opened: C:\Users\user\AppData\Roaming\SmartFTP\Client 2.0\Favorites\Quick Connect\ Jump to behavior
Tries to steal Mail credentials (via file access)
Source: C:\Users\user\Desktop\COVID 19 BENEFIT FORM 2.exe File opened: C:\Users\user\AppData\Roaming\Thunderbird\profiles.ini Jump to behavior
Source: C:\Users\user\Desktop\COVID 19 BENEFIT FORM 2.exe File opened: C:\Users\user\AppData\Roaming\Thunderbird\profiles.ini Jump to behavior
Source: C:\Users\user\Desktop\COVID 19 BENEFIT FORM 2.exe Key opened: HKEY_CURRENT_USER\Software\IncrediMail\Identities Jump to behavior
Yara detected Credential Stealer
Source: Yara match File source: 0000000A.00000002.599311455.0000000002871000.00000004.00000001.sdmp, type: MEMORY
Source: Yara match File source: Process Memory Space: COVID 19 BENEFIT FORM 2.exe PID: 7000, type: MEMORY

Remote Access Functionality:

barindex
Yara detected AgentTesla
Source: Yara match File source: 0000000A.00000002.596294759.0000000000402000.00000040.00000001.sdmp, type: MEMORY
Source: Yara match File source: 0000000A.00000002.599311455.0000000002871000.00000004.00000001.sdmp, type: MEMORY
Source: Yara match File source: 00000000.00000002.377564391.00000000040CD000.00000004.00000001.sdmp, type: MEMORY
Source: Yara match File source: 00000000.00000002.377324089.0000000003F29000.00000004.00000001.sdmp, type: MEMORY
Source: Yara match File source: Process Memory Space: COVID 19 BENEFIT FORM 2.exe PID: 6424, type: MEMORY
Source: Yara match File source: Process Memory Space: COVID 19 BENEFIT FORM 2.exe PID: 7000, type: MEMORY
Source: Yara match File source: 0.2.COVID 19 BENEFIT FORM 2.exe.4293c80.2.unpack, type: UNPACKEDPE
Source: Yara match File source: 10.2.COVID 19 BENEFIT FORM 2.exe.400000.0.unpack, type: UNPACKEDPE
Source: Yara match File source: 0.2.COVID 19 BENEFIT FORM 2.exe.4293c80.2.raw.unpack, type: UNPACKEDPE
Hide Legend

Legend:

  • Process
  • Signature
  • Created File
  • DNS/IP Info
  • Is Dropped
  • Is Windows Process
  • Number of created Registry Values
  • Number of created Files
  • Visual Basic
  • Delphi
  • Java
  • .Net C# or VB.NET
  • C, C++ or other language
  • Is malicious
  • Internet
behaviorgraph top1 signatures2 2 Behavior Graph ID: 397590 Sample: COVID 19 BENEFIT FORM 2.exe Startdate: 26/04/2021 Architecture: WINDOWS Score: 100 28 Found malware configuration 2->28 30 Multi AV Scanner detection for dropped file 2->30 32 Sigma detected: Scheduled temp file as task from temp location 2->32 34 10 other signatures 2->34 7 COVID 19 BENEFIT FORM 2.exe 6 2->7         started        process3 file4 22 C:\Users\user\AppData\Roaming\lVGkcjmu.exe, PE32 7->22 dropped 24 C:\Users\user\AppData\Local\...\tmp764A.tmp, XML 7->24 dropped 26 C:\Users\...\COVID 19 BENEFIT FORM 2.exe.log, ASCII 7->26 dropped 36 Injects a PE file into a foreign processes 7->36 11 COVID 19 BENEFIT FORM 2.exe 2 7->11         started        14 schtasks.exe 1 7->14         started        16 COVID 19 BENEFIT FORM 2.exe 7->16         started        18 2 other processes 7->18 signatures5 process6 signatures7 38 Tries to harvest and steal Putty / WinSCP information (sessions, passwords, etc) 11->38 40 Tries to steal Mail credentials (via file access) 11->40 42 Tries to harvest and steal ftp login credentials 11->42 44 Tries to harvest and steal browser information (history, passwords, etc) 11->44 20 conhost.exe 14->20         started        process8
No contacted IP infos