Loading ...

Play interactive tourEdit tour

Analysis Report dY5HmgsBm6

Overview

General Information

Sample Name:dY5HmgsBm6 (renamed file extension from none to exe)
Analysis ID:397764
MD5:ae8f9d9b8344d52f0872dfdc852e1dd4
SHA1:7e9f4259cc193465317ee48b8428b36e74028390
SHA256:95b5d0e36464afc8391a9d056926e5859506ead18937669554bde42f7a6d135b
Infos:

Most interesting Screenshot:

Detection

Diamondfox
Score:96
Range:0 - 100
Whitelisted:false
Confidence:100%

Signatures

Found malware configuration
Multi AV Scanner detection for domain / URL
Multi AV Scanner detection for dropped file
Multi AV Scanner detection for submitted file
Yara detected Diamondfox
C2 URLs / IPs found in malware configuration
Contains functionality to inject code into remote processes
Found evasive API chain (may stop execution after checking mutex)
PE file has a writeable .text section
Contains capabilities to detect virtual machines
Contains functionality for read data from the clipboard
Contains functionality to call native functions
Contains functionality to check the parent process ID (often done to detect debuggers and analysis systems)
Contains functionality to dynamically determine API calls
Contains functionality to query CPU information (cpuid)
Contains functionality to shutdown / reboot the system
Contains long sleeps (>= 3 min)
Detected potential crypto function
Dropped file seen in connection with other malware
Drops PE files
Found dropped PE file which has not been started or loaded
Found large amount of non-executed APIs
Found potential string decryption / allocating functions
Internet Provider seen in connection with other malware
May sleep (evasive loops) to hinder dynamic analysis
PE file contains executable resources (Code or Archives)
PE file contains sections with non-standard names
PE file contains strange resources
Sample file is different than original file name gathered from version info
Tries to connect to HTTP servers, but all servers are down (expired dropper behavior)
Uses 32bit PE files
Uses code obfuscation techniques (call, push, ret)

Classification

Startup

  • System is w10x64
  • dY5HmgsBm6.exe (PID: 6924 cmdline: 'C:\Users\user\Desktop\dY5HmgsBm6.exe' MD5: AE8F9D9B8344D52F0872DFDC852E1DD4)
    • CachemanControlPanel.exe (PID: 6988 cmdline: C:\Users\user\AppData\Roaming\CachemanControlPanel\CachemanControlPanel.exe MD5: 5D3BF7A18887582B8A2CEA327F2E7BA6)
  • cleanup

Malware Configuration

Threatname: Diamondfox

{"gate": {"url[0]": "http://vladisfoxlink.ru/support/enfr/gate.php"}, "user_agent": {"agent[0]": "Mozilla/5.0 (Macintosh; Intel Mac OS X 11_1) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/87.0.4280.141 Safari/537.36"}, "connection_key": {"key[0]": "1df2b4de68ad60874427e4d6057ea13f"}, "timers": {"connect": "60", "reconnect": "30", "process": "80", "reports": "70", "plugins": "300"}, "installation": {"name": "MicrosoftEdgeCPS", "subfolder": "EdgeCP", "path": "APPDATA", "mutex": "rV8Uqv6WyyQabAbuwVPeRHm6JxPMDa6t", "melt": "0", "antis": "0", "rip": "0", "setup": "0", "startup": "0"}}

Yara Overview

Memory Dumps

SourceRuleDescriptionAuthorStrings
Process Memory Space: CachemanControlPanel.exe PID: 6988JoeSecurity_DiamondfoxYara detected DiamondfoxJoe Security

    Sigma Overview

    No Sigma rule has matched

    Signature Overview

    Click to jump to signature section

    Show All Signature Results

    AV Detection:

    barindex
    Found malware configurationShow sources
    Source: 00000002.00000003.463135358.0000000002730000.00000004.00000040.sdmpMalware Configuration Extractor: Diamondfox {"gate": {"url[0]": "http://vladisfoxlink.ru/support/enfr/gate.php"}, "user_agent": {"agent[0]": "Mozilla/5.0 (Macintosh; Intel Mac OS X 11_1) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/87.0.4280.141 Safari/537.36"}, "connection_key": {"key[0]": "1df2b4de68ad60874427e4d6057ea13f"}, "timers": {"connect": "60", "reconnect": "30", "process": "80", "reports": "70", "plugins": "300"}, "installation": {"name": "MicrosoftEdgeCPS", "subfolder": "EdgeCP", "path": "APPDATA", "mutex": "rV8Uqv6WyyQabAbuwVPeRHm6JxPMDa6t", "melt": "0", "antis": "0", "rip": "0", "setup": "0", "startup": "0"}}
    Multi AV Scanner detection for domain / URLShow sources
    Source: vladisfoxlink.ruVirustotal: Detection: 9%Perma Link
    Multi AV Scanner detection for dropped fileShow sources
    Source: C:\Users\user\AppData\Roaming\CachemanControlPanel\libgraph31.dllReversingLabs: Detection: 34%
    Source: C:\Users\user\AppData\Roaming\CachemanControlPanel\libxml3.dllReversingLabs: Detection: 20%
    Multi AV Scanner detection for submitted fileShow sources
    Source: dY5HmgsBm6.exeVirustotal: Detection: 49%Perma Link
    Source: dY5HmgsBm6.exeReversingLabs: Detection: 34%
    Source: dY5HmgsBm6.exeStatic PE information: LOCAL_SYMS_STRIPPED, 32BIT_MACHINE, EXECUTABLE_IMAGE, LINE_NUMS_STRIPPED, RELOCS_STRIPPED
    Source: dY5HmgsBm6.exeStatic PE information: NO_SEH, TERMINAL_SERVER_AWARE, DYNAMIC_BASE, NX_COMPAT
    Source: Binary string: C:\storage\SIV32X\pdb\VCL\codecs\Obj\storage\build\Release\p.pdbr source: CachemanControlPanel.exe, 00000002.00000002.465184420.0000000000674000.00000002.00020000.sdmp, CachemanControlPanel.exe.1.dr
    Source: Binary string: C:\libcrypto-1_1-x64\StartupManager\Bin\RelWithDebI.pdb source: CachemanControlPanel.exe, 00000002.00000002.467262960.000000006E4E9000.00000002.00020000.sdmp, libxml3.dll.1.dr
    Source: Binary string: d:\agent\_work\3\s\\binaries\x86ret\bin\i386\\vcruntime140.i386.pdb source: vcruntime140.dll.1.dr
    Source: Binary string: C:\storage\SIV32X\pdb\VCL\codecs\Obj\storage\build\Release\p.pdb source: CachemanControlPanel.exe, 00000002.00000002.465184420.0000000000674000.00000002.00020000.sdmp, CachemanControlPanel.exe.1.dr
    Source: Binary string: C:\Users\qt\work\qt\qtbase\lib\Qt5Concurrentd.pdb source: Qt5Concurrentd.dll.1.dr
    Source: Binary string: C:\Users\qt\work\qt\qtbase\lib\Qt5Concurrentd.pdb"" source: Qt5Concurrentd.dll.1.dr
    Source: C:\Users\user\Desktop\dY5HmgsBm6.exeCode function: 1_2_0040646B FindFirstFileA,FindClose,1_2_0040646B
    Source: C:\Users\user\Desktop\dY5HmgsBm6.exeCode function: 1_2_004027A1 FindFirstFileA,1_2_004027A1
    Source: C:\Users\user\Desktop\dY5HmgsBm6.exeCode function: 1_2_004058BF GetTempPathA,DeleteFileA,lstrcatA,lstrcatA,lstrlenA,FindFirstFileA,FindNextFileA,FindClose,1_2_004058BF
    Source: C:\Users\user\AppData\Roaming\CachemanControlPanel\CachemanControlPanel.exeCode function: 2_2_0040C837 wcsncpy,wcslen,wcscat,GetDriveTypeW,FindFirstFileW,FindClose,GetFileAttributesW,GetDriveTypeW,2_2_0040C837

    Networking:

    barindex
    C2 URLs / IPs found in malware configurationShow sources
    Source: Malware configuration extractorURLs: http://vladisfoxlink.ru/support/enfr/gate.php
    Source: Joe Sandbox ViewASN Name: ASN-GIGENETUS ASN-GIGENETUS
    Source: global trafficTCP traffic: 192.168.2.6:49740 -> 45.85.90.225:80
    Source: C:\Users\user\AppData\Roaming\CachemanControlPanel\CachemanControlPanel.exeCode function: 2_2_00408683 InternetOpenW,InternetSetOptionW,InternetConnectW,HttpOpenRequestW,HttpAddRequestHeadersW,HttpSendRequestW,InternetReadFile,InternetCloseHandle,InternetCloseHandle,InternetCloseHandle,InternetCloseHandle,2_2_00408683
    Source: unknownDNS traffic detected: queries for: vladisfoxlink.ru
    Source: Qt5Concurrentd.dll.1.drString found in binary or memory: http://cacerts.digicert.com/DigiCertAssuredIDRootCA.crt0
    Source: Qt5Concurrentd.dll.1.drString found in binary or memory: http://cacerts.digicert.com/DigiCertSHA2AssuredIDCodeSigningCA.crt0
    Source: Qt5Concurrentd.dll.1.drString found in binary or memory: http://cacerts.digicert.com/DigiCertSHA2AssuredIDTimestampingCA.crt0
    Source: Qt5Concurrentd.dll.1.drString found in binary or memory: http://crl3.digicert.com/DigiCertAssuredIDRootCA.crl0O
    Source: Qt5Concurrentd.dll.1.drString found in binary or memory: http://crl3.digicert.com/DigiCertAssuredIDRootCA.crl0P
    Source: Qt5Concurrentd.dll.1.drString found in binary or memory: http://crl3.digicert.com/sha2-assured-cs-g1.crl05
    Source: Qt5Concurrentd.dll.1.drString found in binary or memory: http://crl3.digicert.com/sha2-assured-ts.crl02
    Source: Qt5Concurrentd.dll.1.drString found in binary or memory: http://crl4.digicert.com/DigiCertAssuredIDRootCA.crl0:
    Source: Qt5Concurrentd.dll.1.drString found in binary or memory: http://crl4.digicert.com/sha2-assured-cs-g1.crl0L
    Source: Qt5Concurrentd.dll.1.drString found in binary or memory: http://crl4.digicert.com/sha2-assured-ts.crl0
    Source: dY5HmgsBm6.exeString found in binary or memory: http://nsis.sf.net/NSIS_Error
    Source: dY5HmgsBm6.exeString found in binary or memory: http://nsis.sf.net/NSIS_ErrorError
    Source: Qt5Concurrentd.dll.1.drString found in binary or memory: http://ocsp.digicert.com0C
    Source: Qt5Concurrentd.dll.1.drString found in binary or memory: http://ocsp.digicert.com0N
    Source: Qt5Concurrentd.dll.1.drString found in binary or memory: http://ocsp.digicert.com0O
    Source: CachemanControlPanel.exe, 00000002.00000003.463261074.0000000002A84000.00000004.00000040.sdmpString found in binary or memory: http://vladisfoxlink.ru/support/enfr/gate.php
    Source: CachemanControlPanel.exe, 00000002.00000003.463261074.0000000002A84000.00000004.00000040.sdmpString found in binary or memory: http://vladisfoxlink.ru/support/enfr/gate.phpte.phpK
    Source: dY5HmgsBm6.exe, 00000001.00000002.326848331.000000000040A000.00000004.00020000.sdmp, zlib.dll.1.drString found in binary or memory: http://www.zlib.net/D
    Source: CachemanControlPanel.exe, CachemanControlPanel.exe, 00000002.00000000.326512498.00000000006FD000.00000002.00020000.sdmp, CachemanControlPanel.exe.1.drString found in binary or memory: https://bitsum.com
    Source: CachemanControlPanel.exe, 00000002.00000000.326512498.00000000006FD000.00000002.00020000.sdmp, CachemanControlPanel.exe.1.drString found in binary or memory: https://bitsum.com/
    Source: CachemanControlPanel.exe, 00000002.00000000.326512498.00000000006FD000.00000002.00020000.sdmp, CachemanControlPanel.exe.1.drString found in binary or memory: https://bitsum.com/3Current
    Source: CachemanControlPanel.exeString found in binary or memory: https://ip.seeip.org/
    Source: CachemanControlPanel.exe, 00000002.00000002.463581366.0000000000401000.00000040.00020000.sdmpString found in binary or memory: https://ip.seeip.org/Content-Type:
    Source: Qt5Concurrentd.dll.1.drString found in binary or memory: https://www.digicert.com/CPS0
    Source: C:\Users\user\Desktop\dY5HmgsBm6.exeCode function: 1_2_0040535C GetDlgItem,GetDlgItem,GetDlgItem,GetDlgItem,GetClientRect,GetSystemMetrics,SendMessageA,SendMessageA,SendMessageA,SendMessageA,SendMessageA,SendMessageA,ShowWindow,ShowWindow,GetDlgItem,SendMessageA,SendMessageA,SendMessageA,GetDlgItem,CreateThread,FindCloseChangeNotification,ShowWindow,ShowWindow,ShowWindow,SendMessageA,CreatePopupMenu,AppendMenuA,GetWindowRect,TrackPopupMenu,SendMessageA,OpenClipboard,EmptyClipboard,GlobalAlloc,GlobalLock,SendMessageA,GlobalUnlock,SetClipboardData,CloseClipboard,1_2_0040535C

    E-Banking Fraud:

    barindex
    Yara detected DiamondfoxShow sources
    Source: Yara matchFile source: Process Memory Space: CachemanControlPanel.exe PID: 6988, type: MEMORY

    System Summary:

    barindex
    PE file has a writeable .text sectionShow sources
    Source: CachemanControlPanel.exe.1.drStatic PE information: Section: .text IMAGE_SCN_MEM_EXECUTE, IMAGE_SCN_MEM_WRITE, IMAGE_SCN_CNT_CODE, IMAGE_SCN_MEM_READ
    Source: C:\Users\user\AppData\Roaming\CachemanControlPanel\CachemanControlPanel.exeCode function: 2_2_00407EA1 CreateProcessW,NtUnmapViewOfSection,VirtualAllocEx,WriteProcessMemory,WriteProcessMemory,GetThreadContext,WriteProcessMemory,SetThreadContext,ResumeThread,2_2_00407EA1
    Source: C:\Users\user\Desktop\dY5HmgsBm6.exeCode function: 1_2_00403348 EntryPoint,SetErrorMode,GetVersion,lstrlenA,#17,OleInitialize,SHGetFileInfoA,GetCommandLineA,CharNextA,GetTempPathA,GetTempPathA,GetWindowsDirectoryA,lstrcatA,GetTempPathA,lstrcatA,SetEnvironmentVariableA,SetEnvironmentVariableA,SetEnvironmentVariableA,DeleteFileA,ExitProcess,OleUninitialize,ExitProcess,lstrcatA,lstrcatA,lstrcatA,lstrcmpiA,SetCurrentDirectoryA,DeleteFileA,CopyFileA,CloseHandle,GetCurrentProcess,OpenProcessToken,LookupPrivilegeValueA,AdjustTokenPrivileges,ExitWindowsEx,ExitProcess,1_2_00403348
    Source: C:\Users\user\Desktop\dY5HmgsBm6.exeCode function: 1_2_004069451_2_00406945
    Source: C:\Users\user\Desktop\dY5HmgsBm6.exeCode function: 1_2_0040711C1_2_0040711C
    Source: C:\Users\user\AppData\Roaming\CachemanControlPanel\CachemanControlPanel.exeCode function: 2_2_0040E02E2_2_0040E02E
    Source: C:\Users\user\AppData\Roaming\CachemanControlPanel\CachemanControlPanel.exeCode function: 2_2_004198A02_2_004198A0
    Source: C:\Users\user\AppData\Roaming\CachemanControlPanel\CachemanControlPanel.exeCode function: 2_2_004150A42_2_004150A4
    Source: C:\Users\user\AppData\Roaming\CachemanControlPanel\CachemanControlPanel.exeCode function: 2_2_0041C0A82_2_0041C0A8
    Source: C:\Users\user\AppData\Roaming\CachemanControlPanel\CachemanControlPanel.exeCode function: 2_2_004109502_2_00410950
    Source: C:\Users\user\AppData\Roaming\CachemanControlPanel\CachemanControlPanel.exeCode function: 2_2_004131B02_2_004131B0
    Source: C:\Users\user\AppData\Roaming\CachemanControlPanel\CachemanControlPanel.exeCode function: 2_2_0041F2002_2_0041F200
    Source: C:\Users\user\AppData\Roaming\CachemanControlPanel\CachemanControlPanel.exeCode function: 2_2_0041F2C92_2_0041F2C9
    Source: C:\Users\user\AppData\Roaming\CachemanControlPanel\CachemanControlPanel.exeCode function: 2_2_0041F2832_2_0041F283
    Source: C:\Users\user\AppData\Roaming\CachemanControlPanel\CachemanControlPanel.exeCode function: 2_2_0041FB402_2_0041FB40
    Source: C:\Users\user\AppData\Roaming\CachemanControlPanel\CachemanControlPanel.exeCode function: 2_2_0040F3602_2_0040F360
    Source: C:\Users\user\AppData\Roaming\CachemanControlPanel\CachemanControlPanel.exeCode function: 2_2_004103602_2_00410360
    Source: C:\Users\user\AppData\Roaming\CachemanControlPanel\CachemanControlPanel.exeCode function: 2_2_00410B302_2_00410B30
    Source: C:\Users\user\AppData\Roaming\CachemanControlPanel\CachemanControlPanel.exeCode function: 2_2_0040E3A72_2_0040E3A7
    Source: C:\Users\user\AppData\Roaming\CachemanControlPanel\CachemanControlPanel.exeCode function: 2_2_0040F5702_2_0040F570
    Source: C:\Users\user\AppData\Roaming\CachemanControlPanel\CachemanControlPanel.exeCode function: 2_2_0040DDF32_2_0040DDF3
    Source: C:\Users\user\AppData\Roaming\CachemanControlPanel\CachemanControlPanel.exeCode function: 2_2_0040FD802_2_0040FD80
    Source: C:\Users\user\AppData\Roaming\CachemanControlPanel\CachemanControlPanel.exeCode function: 2_2_0041B6302_2_0041B630
    Source: C:\Users\user\AppData\Roaming\CachemanControlPanel\CachemanControlPanel.exeCode function: 2_2_0041EED02_2_0041EED0
    Source: C:\Users\user\AppData\Roaming\CachemanControlPanel\CachemanControlPanel.exeCode function: 2_2_0041EEF02_2_0041EEF0
    Source: C:\Users\user\AppData\Roaming\CachemanControlPanel\CachemanControlPanel.exeCode function: 2_2_0040E7392_2_0040E739
    Source: C:\Users\user\AppData\Roaming\CachemanControlPanel\CachemanControlPanel.exeCode function: 2_2_0040F7802_2_0040F780
    Source: C:\Users\user\AppData\Roaming\CachemanControlPanel\CachemanControlPanel.exeCode function: 2_2_0040EFB32_2_0040EFB3
    Source: Joe Sandbox ViewDropped File: C:\Users\user\AppData\Roaming\CachemanControlPanel\CachemanControlPanel.exe 014D644ECCC232CD6906C5ABF8AFD3E53F94004057D4A1BB2771DFEA00F0AE4B
    Source: Joe Sandbox ViewDropped File: C:\Users\user\AppData\Roaming\CachemanControlPanel\libgraph31.dll A276F57503BAD9A4BCA17E8E057993607E715C1FA6C7D2E136A2290A19EFD560
    Source: C:\Users\user\AppData\Roaming\CachemanControlPanel\CachemanControlPanel.exeCode function: String function: 004187A0 appears 32 times
    Source: C:\Users\user\AppData\Roaming\CachemanControlPanel\CachemanControlPanel.exeCode function: String function: 00418710 appears 38 times
    Source: C:\Users\user\AppData\Roaming\CachemanControlPanel\CachemanControlPanel.exeCode function: String function: 00418770 appears 33 times
    Source: CachemanControlPanel.exe.1.drStatic PE information: Resource name: RT_RCDATA type: COM executable for DOS
    Source: dY5HmgsBm6.exeStatic PE information: Resource name: RT_ICON type: GLS_BINARY_LSB_FIRST
    Source: CachemanControlPanel.exe.1.drStatic PE information: Resource name: RT_ICON type: GLS_BINARY_LSB_FIRST
    Source: dY5HmgsBm6.exe, 00000001.00000002.326848331.000000000040A000.00000004.00020000.sdmpBinary or memory string: OriginalFilenamezlib1.dll* vs dY5HmgsBm6.exe
    Source: dY5HmgsBm6.exe, 00000001.00000002.327150069.0000000002330000.00000002.00000001.sdmpBinary or memory string: OriginalFilenameuser32j% vs dY5HmgsBm6.exe
    Source: dY5HmgsBm6.exeStatic PE information: LOCAL_SYMS_STRIPPED, 32BIT_MACHINE, EXECUTABLE_IMAGE, LINE_NUMS_STRIPPED, RELOCS_STRIPPED
    Source: classification engineClassification label: mal96.troj.evad.winEXE@3/12@1/1
    Source: C:\Users\user\Desktop\dY5HmgsBm6.exeCode function: 1_2_00403348 EntryPoint,SetErrorMode,GetVersion,lstrlenA,#17,OleInitialize,SHGetFileInfoA,GetCommandLineA,CharNextA,GetTempPathA,GetTempPathA,GetWindowsDirectoryA,lstrcatA,GetTempPathA,lstrcatA,SetEnvironmentVariableA,SetEnvironmentVariableA,SetEnvironmentVariableA,DeleteFileA,ExitProcess,OleUninitialize,ExitProcess,lstrcatA,lstrcatA,lstrcatA,lstrcmpiA,SetCurrentDirectoryA,DeleteFileA,CopyFileA,CloseHandle,GetCurrentProcess,OpenProcessToken,LookupPrivilegeValueA,AdjustTokenPrivileges,ExitWindowsEx,ExitProcess,1_2_00403348
    Source: C:\Users\user\Desktop\dY5HmgsBm6.exeCode function: 1_2_0040460D GetDlgItem,SetWindowTextA,SHBrowseForFolderA,CoTaskMemFree,lstrcmpiA,lstrcatA,SetDlgItemTextA,GetDiskFreeSpaceA,MulDiv,SetDlgItemTextA,1_2_0040460D
    Source: C:\Users\user\AppData\Roaming\CachemanControlPanel\CachemanControlPanel.exeCode function: 2_2_004039B7 CreateToolhelp32Snapshot,Process32FirstW,Process32NextW,GetCurrentProcessId,CloseHandle,2_2_004039B7
    Source: C:\Users\user\Desktop\dY5HmgsBm6.exeCode function: 1_2_0040216B CoCreateInstance,MultiByteToWideChar,1_2_0040216B
    Source: C:\Users\user\Desktop\dY5HmgsBm6.exeFile created: C:\Users\user\AppData\Roaming\CachemanControlPanelJump to behavior
    Source: C:\Users\user\AppData\Roaming\CachemanControlPanel\CachemanControlPanel.exeMutant created: \Sessions\1\BaseNamedObjects\rV8Uqv6WyyQabAbuwVPeRHm6JxPMDa6t
    Source: C:\Users\user\Desktop\dY5HmgsBm6.exeFile created: C:\Users\user\AppData\Local\Temp\nsuAFD0.tmpJump to behavior
    Source: dY5HmgsBm6.exeStatic PE information: Section: .text IMAGE_SCN_MEM_EXECUTE, IMAGE_SCN_CNT_CODE, IMAGE_SCN_MEM_READ
    Source: C:\Users\user\Desktop\dY5HmgsBm6.exeFile read: C:\Users\desktop.iniJump to behavior
    Source: C:\Users\user\Desktop\dY5HmgsBm6.exeKey opened: HKEY_CURRENT_USER\Software\Policies\Microsoft\Windows\Safer\CodeIdentifiersJump to behavior
    Source: C:\Users\user\AppData\Roaming\CachemanControlPanel\CachemanControlPanel.exeFile read: C:\Windows\System32\drivers\etc\hostsJump to behavior
    Source: C:\Users\user\AppData\Roaming\CachemanControlPanel\CachemanControlPanel.exeFile read: C:\Windows\System32\drivers\etc\hostsJump to behavior
    Source: CachemanControlPanel.exe, 00000002.00000002.465184420.0000000000674000.00000002.00020000.sdmp, CachemanControlPanel.exe.1.drBinary or memory string: UPDATE %Q.sqlite_master SET tbl_name = %Q, name = CASE WHEN type='table' THEN %Q WHEN name LIKE 'sqliteX_autoindex%%' ESCAPE 'X' AND type='index' THEN 'sqlite_autoindex_' || %Q || substr(name,%d+18) ELSE name END WHERE tbl_name=%Q COLLATE nocase AND (type='table' OR type='index' OR type='trigger');
    Source: CachemanControlPanel.exe, 00000002.00000002.465184420.0000000000674000.00000002.00020000.sdmp, CachemanControlPanel.exe.1.drBinary or memory string: INSERT INTO %Q.sqlite_master VALUES('index',%Q,%Q,#%d,%Q);
    Source: CachemanControlPanel.exe, 00000002.00000002.465184420.0000000000674000.00000002.00020000.sdmp, CachemanControlPanel.exe.1.drBinary or memory string: CREATE TABLE "%w"."%w_parent"(nodeno INTEGER PRIMARY KEY,parentnode);
    Source: dY5HmgsBm6.exeVirustotal: Detection: 49%
    Source: dY5HmgsBm6.exeReversingLabs: Detection: 34%
    Source: C:\Users\user\Desktop\dY5HmgsBm6.exeFile read: C:\Users\user\Desktop\dY5HmgsBm6.exeJump to behavior
    Source: unknownProcess created: C:\Users\user\Desktop\dY5HmgsBm6.exe 'C:\Users\user\Desktop\dY5HmgsBm6.exe'
    Source: C:\Users\user\Desktop\dY5HmgsBm6.exeProcess created: C:\Users\user\AppData\Roaming\CachemanControlPanel\CachemanControlPanel.exe C:\Users\user\AppData\Roaming\CachemanControlPanel\CachemanControlPanel.exe
    Source: C:\Users\user\Desktop\dY5HmgsBm6.exeProcess created: C:\Users\user\AppData\Roaming\CachemanControlPanel\CachemanControlPanel.exe C:\Users\user\AppData\Roaming\CachemanControlPanel\CachemanControlPanel.exeJump to behavior
    Source: C:\Users\user\Desktop\dY5HmgsBm6.exeKey value queried: HKEY_LOCAL_MACHINE\SOFTWARE\Classes\WOW6432Node\CLSID\{1f486a52-3cb1-48fd-8f50-b8dc300d9f9d}\InProcServer32Jump to behavior
    Source: dY5HmgsBm6.exeStatic file information: File size 2573987 > 1048576
    Source: dY5HmgsBm6.exeStatic PE information: NO_SEH, TERMINAL_SERVER_AWARE, DYNAMIC_BASE, NX_COMPAT
    Source: Binary string: C:\storage\SIV32X\pdb\VCL\codecs\Obj\storage\build\Release\p.pdbr source: CachemanControlPanel.exe, 00000002.00000002.465184420.0000000000674000.00000002.00020000.sdmp, CachemanControlPanel.exe.1.dr
    Source: Binary string: C:\libcrypto-1_1-x64\StartupManager\Bin\RelWithDebI.pdb source: CachemanControlPanel.exe, 00000002.00000002.467262960.000000006E4E9000.00000002.00020000.sdmp, libxml3.dll.1.dr
    Source: Binary string: d:\agent\_work\3\s\\binaries\x86ret\bin\i386\\vcruntime140.i386.pdb source: vcruntime140.dll.1.dr
    Source: Binary string: C:\storage\SIV32X\pdb\VCL\codecs\Obj\storage\build\Release\p.pdb source: CachemanControlPanel.exe, 00000002.00000002.465184420.0000000000674000.00000002.00020000.sdmp, CachemanControlPanel.exe.1.dr
    Source: Binary string: C:\Users\qt\work\qt\qtbase\lib\Qt5Concurrentd.pdb source: Qt5Concurrentd.dll.1.dr
    Source: Binary string: C:\Users\qt\work\qt\qtbase\lib\Qt5Concurrentd.pdb"" source: Qt5Concurrentd.dll.1.dr
    Source: C:\Users\user\AppData\Roaming\CachemanControlPanel\CachemanControlPanel.exeCode function: 2_2_00412C47 LoadLibraryW,GetProcAddress,memset,FreeLibrary,LoadLibraryW,GetProcAddress,FreeLibrary,2_2_00412C47
    Source: CachemanControlPanel.exe.1.drStatic PE information: section name: _RDATA
    Source: Qt5Concurrentd.dll.1.drStatic PE information: section name: .00cfg
    Source: C:\Users\user\AppData\Roaming\CachemanControlPanel\CachemanControlPanel.exeCode function: 2_2_0042E81E push cs; iretd 2_2_0042E7F2
    Source: C:\Users\user\AppData\Roaming\CachemanControlPanel\CachemanControlPanel.exeCode function: 2_2_0042E9CE push ebx; ret 2_2_0042E9CF
    Source: C:\Users\user\AppData\Roaming\CachemanControlPanel\CachemanControlPanel.exeCode function: 2_2_0042A5AB push 0000006Ah; retf 2_2_0042A684
    Source: C:\Users\user\AppData\Roaming\CachemanControlPanel\CachemanControlPanel.exeCode function: 2_2_0042A613 push 0000006Ah; retf 2_2_0042A684
    Source: C:\Users\user\AppData\Roaming\CachemanControlPanel\CachemanControlPanel.exeCode function: 2_2_0042A615 push 0000006Ah; retf 2_2_0042A684
    Source: C:\Users\user\AppData\Roaming\CachemanControlPanel\CachemanControlPanel.exeCode function: 2_2_0042E71C push cs; iretd 2_2_0042E7F2

    Persistence and Installation Behavior:

    barindex
    Yara detected DiamondfoxShow sources
    Source: Yara matchFile source: Process Memory Space: CachemanControlPanel.exe PID: 6988, type: MEMORY
    Source: C:\Users\user\Desktop\dY5HmgsBm6.exeFile created: C:\Users\user\AppData\Roaming\CachemanControlPanel\libgraph31.dllJump to dropped file
    Source: C:\Users\user\Desktop\dY5HmgsBm6.exeFile created: C:\Users\user\AppData\Roaming\CachemanControlPanel\libxml3.dllJump to dropped file
    Source: C:\Users\user\Desktop\dY5HmgsBm6.exeFile created: C:\Users\user\AppData\Roaming\CachemanControlPanel\libgcc_s_seh-1.dllJump to dropped file
    Source: C:\Users\user\Desktop\dY5HmgsBm6.exeFile created: C:\Users\user\AppData\Roaming\CachemanControlPanel\libgstcontroller-1.0-0.dllJump to dropped file
    Source: C:\Users\user\Desktop\dY5HmgsBm6.exeFile created: C:\Users\user\AppData\Roaming\CachemanControlPanel\vcruntime140.dllJump to dropped file
    Source: C:\Users\user\Desktop\dY5HmgsBm6.exeFile created: C:\Users\user\AppData\Roaming\CachemanControlPanel\libogg-0.dllJump to dropped file
    Source: C:\Users\user\Desktop\dY5HmgsBm6.exeFile created: C:\Users\user\AppData\Roaming\CachemanControlPanel\CachemanControlPanel.exeJump to dropped file
    Source: C:\Users\user\Desktop\dY5HmgsBm6.exeFile created: C:\Users\user\AppData\Roaming\CachemanControlPanel\libblkmaker-0.1-6.dllJump to dropped file
    Source: C:\Users\user\Desktop\dY5HmgsBm6.exeFile created: C:\Users\user\AppData\Roaming\CachemanControlPanel\zlib.dllJump to dropped file
    Source: C:\Users\user\Desktop\dY5HmgsBm6.exeFile created: C:\Users\user\AppData\Roaming\CachemanControlPanel\Qt5Concurrentd.dllJump to dropped file
    Source: C:\Users\user\Desktop\dY5HmgsBm6.exeProcess information set: NOOPENFILEERRORBOXJump to behavior

    Malware Analysis System Evasion:

    barindex
    Found evasive API chain (may stop execution after checking mutex)Show sources
    Source: C:\Users\user\AppData\Roaming\CachemanControlPanel\CachemanControlPanel.exeEvasive API call chain: CreateMutex,DecisionNodes,ExitProcessgraph_2-16047
    Source: C:\Users\user\Desktop\dY5HmgsBm6.exeFile opened / queried: SCSI#CdRom&Ven_NECVMWar&Prod_VMware_SATA_CD00#5&280b647&0&000000#{53f5630d-b6bf-11d0-94f2-00a0c91efb8b}Jump to behavior
    Source: C:\Users\user\AppData\Roaming\CachemanControlPanel\CachemanControlPanel.exeCode function: 2_2_004039B7 CreateToolhelp32Snapshot,Process32FirstW,Process32NextW,GetCurrentProcessId,CloseHandle,2_2_004039B7
    Source: C:\Users\user\AppData\Roaming\CachemanControlPanel\CachemanControlPanel.exeThread delayed: delay time: 260000Jump to behavior
    Source: C:\Users\user\AppData\Roaming\CachemanControlPanel\CachemanControlPanel.exeThread delayed: delay time: 259884Jump to behavior
    Source: C:\Users\user\AppData\Roaming\CachemanControlPanel\CachemanControlPanel.exeThread delayed: delay time: 259778Jump to behavior
    Source: C:\Users\user\AppData\Roaming\CachemanControlPanel\CachemanControlPanel.exeThread delayed: delay time: 259669Jump to behavior
    Source: C:\Users\user\AppData\Roaming\CachemanControlPanel\CachemanControlPanel.exeThread delayed: delay time: 259560Jump to behavior
    Source: C:\Users\user\AppData\Roaming\CachemanControlPanel\CachemanControlPanel.exeThread delayed: delay time: 259450Jump to behavior
    Source: C:\Users\user\AppData\Roaming\CachemanControlPanel\CachemanControlPanel.exeThread delayed: delay time: 259341Jump to behavior
    Source: C:\Users\user\AppData\Roaming\CachemanControlPanel\CachemanControlPanel.exeThread delayed: delay time: 259232Jump to behavior
    Source: C:\Users\user\AppData\Roaming\CachemanControlPanel\CachemanControlPanel.exeThread delayed: delay time: 259122Jump to behavior
    Source: C:\Users\user\AppData\Roaming\CachemanControlPanel\CachemanControlPanel.exeThread delayed: delay time: 259013Jump to behavior
    Source: C:\Users\user\AppData\Roaming\CachemanControlPanel\CachemanControlPanel.exeThread delayed: delay time: 258899Jump to behavior
    Source: C:\Users\user\AppData\Roaming\CachemanControlPanel\CachemanControlPanel.exeThread delayed: delay time: 258794Jump to behavior
    Source: C:\Users\user\AppData\Roaming\CachemanControlPanel\CachemanControlPanel.exeThread delayed: delay time: 258685Jump to behavior
    Source: C:\Users\user\AppData\Roaming\CachemanControlPanel\CachemanControlPanel.exeThread delayed: delay time: 258576Jump to behavior
    Source: C:\Users\user\AppData\Roaming\CachemanControlPanel\CachemanControlPanel.exeThread delayed: delay time: 258466Jump to behavior
    Source: C:\Users\user\AppData\Roaming\CachemanControlPanel\CachemanControlPanel.exeThread delayed: delay time: 258356Jump to behavior
    Source: C:\Users\user\AppData\Roaming\CachemanControlPanel\CachemanControlPanel.exeThread delayed: delay time: 258246Jump to behavior
    Source: C:\Users\user\AppData\Roaming\CachemanControlPanel\CachemanControlPanel.exeThread delayed: delay time: 258138Jump to behavior
    Source: C:\Users\user\AppData\Roaming\CachemanControlPanel\CachemanControlPanel.exeThread delayed: delay time: 258029Jump to behavior
    Source: C:\Users\user\AppData\Roaming\CachemanControlPanel\CachemanControlPanel.exeThread delayed: delay time: 257919Jump to behavior
    Source: C:\Users\user\AppData\Roaming\CachemanControlPanel\CachemanControlPanel.exeThread delayed: delay time: 257810Jump to behavior
    Source: C:\Users\user\AppData\Roaming\CachemanControlPanel\CachemanControlPanel.exeThread delayed: delay time: 257701Jump to behavior
    Source: C:\Users\user\AppData\Roaming\CachemanControlPanel\CachemanControlPanel.exeThread delayed: delay time: 257591Jump to behavior
    Source: C:\Users\user\AppData\Roaming\CachemanControlPanel\CachemanControlPanel.exeThread delayed: delay time: 257482Jump to behavior
    Source: C:\Users\user\AppData\Roaming\CachemanControlPanel\CachemanControlPanel.exeThread delayed: delay time: 257372Jump to behavior
    Source: C:\Users\user\AppData\Roaming\CachemanControlPanel\CachemanControlPanel.exeThread delayed: delay time: 257263Jump to behavior
    Source: C:\Users\user\AppData\Roaming\CachemanControlPanel\CachemanControlPanel.exeThread delayed: delay time: 257153Jump to behavior
    Source: C:\Users\user\AppData\Roaming\CachemanControlPanel\CachemanControlPanel.exeThread delayed: delay time: 257044Jump to behavior
    Source: C:\Users\user\AppData\Roaming\CachemanControlPanel\CachemanControlPanel.exeThread delayed: delay time: 256935Jump to behavior
    Source: C:\Users\user\AppData\Roaming\CachemanControlPanel\CachemanControlPanel.exeThread delayed: delay time: 256825Jump to behavior
    Source: C:\Users\user\AppData\Roaming\CachemanControlPanel\CachemanControlPanel.exeThread delayed: delay time: 256716Jump to behavior
    Source: C:\Users\user\AppData\Roaming\CachemanControlPanel\CachemanControlPanel.exeThread delayed: delay time: 256606Jump to behavior
    Source: C:\Users\user\AppData\Roaming\CachemanControlPanel\CachemanControlPanel.exeThread delayed: delay time: 256497Jump to behavior
    Source: C:\Users\user\AppData\Roaming\CachemanControlPanel\CachemanControlPanel.exeThread delayed: delay time: 256388Jump to behavior
    Source: C:\Users\user\AppData\Roaming\CachemanControlPanel\CachemanControlPanel.exeThread delayed: delay time: 256277Jump to behavior
    Source: C:\Users\user\AppData\Roaming\CachemanControlPanel\CachemanControlPanel.exeThread delayed: delay time: 256169Jump to behavior
    Source: C:\Users\user\AppData\Roaming\CachemanControlPanel\CachemanControlPanel.exeThread delayed: delay time: 256060Jump to behavior
    Source: C:\Users\user\AppData\Roaming\CachemanControlPanel\CachemanControlPanel.exeThread delayed: delay time: 255951Jump to behavior
    Source: C:\Users\user\AppData\Roaming\CachemanControlPanel\CachemanControlPanel.exeThread delayed: delay time: 255841Jump to behavior
    Source: C:\Users\user\AppData\Roaming\CachemanControlPanel\CachemanControlPanel.exeThread delayed: delay time: 255732Jump to behavior
    Source: C:\Users\user\AppData\Roaming\CachemanControlPanel\CachemanControlPanel.exeThread delayed: delay time: 255622Jump to behavior
    Source: C:\Users\user\AppData\Roaming\CachemanControlPanel\CachemanControlPanel.exeThread delayed: delay time: 255513Jump to behavior
    Source: C:\Users\user\AppData\Roaming\CachemanControlPanel\CachemanControlPanel.exeThread delayed: delay time: 255412Jump to behavior
    Source: C:\Users\user\AppData\Roaming\CachemanControlPanel\CachemanControlPanel.exeThread delayed: delay time: 255297Jump to behavior
    Source: C:\Users\user\Desktop\dY5HmgsBm6.exeDropped PE file which has not been started: C:\Users\user\AppData\Roaming\CachemanControlPanel\libgraph31.dllJump to dropped file
    Source: C:\Users\user\Desktop\dY5HmgsBm6.exeDropped PE file which has not been started: C:\Users\user\AppData\Roaming\CachemanControlPanel\libgstcontroller-1.0-0.dllJump to dropped file
    Source: C:\Users\user\Desktop\dY5HmgsBm6.exeDropped PE file which has not been started: C:\Users\user\AppData\Roaming\CachemanControlPanel\libgcc_s_seh-1.dllJump to dropped file
    Source: C:\Users\user\Desktop\dY5HmgsBm6.exeDropped PE file which has not been started: C:\Users\user\AppData\Roaming\CachemanControlPanel\vcruntime140.dllJump to dropped file
    Source: C:\Users\user\Desktop\dY5HmgsBm6.exeDropped PE file which has not been started: C:\Users\user\AppData\Roaming\CachemanControlPanel\libogg-0.dllJump to dropped file
    Source: C:\Users\user\Desktop\dY5HmgsBm6.exeDropped PE file which has not been started: C:\Users\user\AppData\Roaming\CachemanControlPanel\libblkmaker-0.1-6.dllJump to dropped file
    Source: C:\Users\user\Desktop\dY5HmgsBm6.exeDropped PE file which has not been started: C:\Users\user\AppData\Roaming\CachemanControlPanel\zlib.dllJump to dropped file
    Source: C:\Users\user\Desktop\dY5HmgsBm6.exeDropped PE file which has not been started: C:\Users\user\AppData\Roaming\CachemanControlPanel\Qt5Concurrentd.dllJump to dropped file
    Source: C:\Users\user\AppData\Roaming\CachemanControlPanel\CachemanControlPanel.exeAPI coverage: 9.6 %
    Source: C:\Users\user\AppData\Roaming\CachemanControlPanel\CachemanControlPanel.exe TID: 6992Thread sleep time: -59000s >= -30000sJump to behavior
    Source: C:\Users\user\AppData\Roaming\CachemanControlPanel\CachemanControlPanel.exe TID: 6992Thread sleep time: -58894s >= -30000sJump to behavior
    Source: C:\Users\user\AppData\Roaming\CachemanControlPanel\CachemanControlPanel.exe TID: 6992Thread sleep time: -58786s >= -30000sJump to behavior
    Source: C:\Users\user\AppData\Roaming\CachemanControlPanel\CachemanControlPanel.exe TID: 6992Thread sleep time: -58678s >= -30000sJump to behavior
    Source: C:\Users\user\AppData\Roaming\CachemanControlPanel\CachemanControlPanel.exe TID: 6992Thread sleep time: -58569s >= -30000sJump to behavior
    Source: C:\Users\user\AppData\Roaming\CachemanControlPanel\CachemanControlPanel.exe TID: 6992Thread sleep time: -58454s >= -30000sJump to behavior
    Source: C:\Users\user\AppData\Roaming\CachemanControlPanel\CachemanControlPanel.exe TID: 6992Thread sleep time: -58351s >= -30000sJump to behavior
    Source: C:\Users\user\AppData\Roaming\CachemanControlPanel\CachemanControlPanel.exe TID: 6992Thread sleep time: -58241s >= -30000sJump to behavior
    Source: C:\Users\user\AppData\Roaming\CachemanControlPanel\CachemanControlPanel.exe TID: 6992Thread sleep time: -58132s >= -30000sJump to behavior
    Source: C:\Users\user\AppData\Roaming\CachemanControlPanel\CachemanControlPanel.exe TID: 6992Thread sleep time: -58023s >= -30000sJump to behavior
    Source: C:\Users\user\AppData\Roaming\CachemanControlPanel\CachemanControlPanel.exe TID: 6992Thread sleep time: -57913s >= -30000sJump to behavior
    Source: C:\Users\user\AppData\Roaming\CachemanControlPanel\CachemanControlPanel.exe TID: 6992Thread sleep time: -57804s >= -30000sJump to behavior
    Source: C:\Users\user\AppData\Roaming\CachemanControlPanel\CachemanControlPanel.exe TID: 6992Thread sleep time: -57695s >= -30000sJump to behavior
    Source: C:\Users\user\AppData\Roaming\CachemanControlPanel\CachemanControlPanel.exe TID: 6992Thread sleep time: -57585s >= -30000sJump to behavior
    Source: C:\Users\user\AppData\Roaming\CachemanControlPanel\CachemanControlPanel.exe TID: 6992Thread sleep time: -57476s >= -30000sJump to behavior
    Source: C:\Users\user\AppData\Roaming\CachemanControlPanel\CachemanControlPanel.exe TID: 6992Thread sleep time: -57365s >= -30000sJump to behavior
    Source: C:\Users\user\AppData\Roaming\CachemanControlPanel\CachemanControlPanel.exe TID: 6992Thread sleep time: -57257s >= -30000sJump to behavior
    Source: C:\Users\user\AppData\Roaming\CachemanControlPanel\CachemanControlPanel.exe TID: 6992Thread sleep time: -57148s >= -30000sJump to behavior
    Source: C:\Users\user\AppData\Roaming\CachemanControlPanel\CachemanControlPanel.exe TID: 6992Thread sleep time: -57039s >= -30000sJump to behavior
    Source: C:\Users\user\AppData\Roaming\CachemanControlPanel\CachemanControlPanel.exe TID: 6992Thread sleep time: -56929s >= -30000sJump to behavior
    Source: C:\Users\user\AppData\Roaming\CachemanControlPanel\CachemanControlPanel.exe TID: 6992Thread sleep time: -56819s >= -30000sJump to behavior
    Source: C:\Users\user\AppData\Roaming\CachemanControlPanel\CachemanControlPanel.exe TID: 6992Thread sleep time: -56711s >= -30000sJump to behavior
    Source: C:\Users\user\AppData\Roaming\CachemanControlPanel\CachemanControlPanel.exe TID: 6992Thread sleep time: -56601s >= -30000sJump to behavior
    Source: C:\Users\user\AppData\Roaming\CachemanControlPanel\CachemanControlPanel.exe TID: 6992Thread sleep time: -56491s >= -30000sJump to behavior
    Source: C:\Users\user\AppData\Roaming\CachemanControlPanel\CachemanControlPanel.exe TID: 6992Thread sleep time: -56382s >= -30000sJump to behavior
    Source: C:\Users\user\AppData\Roaming\CachemanControlPanel\CachemanControlPanel.exe TID: 6992Thread sleep time: -56272s >= -30000sJump to behavior
    Source: C:\Users\user\AppData\Roaming\CachemanControlPanel\CachemanControlPanel.exe TID: 6992Thread sleep time: -56163s >= -30000sJump to behavior
    Source: C:\Users\user\AppData\Roaming\CachemanControlPanel\CachemanControlPanel.exe TID: 6992Thread sleep time: -56053s >= -30000sJump to behavior
    Source: C:\Users\user\AppData\Roaming\CachemanControlPanel\CachemanControlPanel.exe TID: 6992Thread sleep time: -55945s >= -30000sJump to behavior
    Source: C:\Users\user\AppData\Roaming\CachemanControlPanel\CachemanControlPanel.exe TID: 6992Thread sleep time: -55835s >= -30000sJump to behavior
    Source: C:\Users\user\AppData\Roaming\CachemanControlPanel\CachemanControlPanel.exe TID: 6992Thread sleep time: -55726s >= -30000sJump to behavior
    Source: C:\Users\user\AppData\Roaming\CachemanControlPanel\CachemanControlPanel.exe TID: 6992Thread sleep time: -55616s >= -30000sJump to behavior
    Source: C:\Users\user\AppData\Roaming\CachemanControlPanel\CachemanControlPanel.exe TID: 6992Thread sleep time: -55507s >= -30000sJump to behavior
    Source: C:\Users\user\AppData\Roaming\CachemanControlPanel\CachemanControlPanel.exe TID: 6992Thread sleep time: -55398s >= -30000sJump to behavior
    Source: C:\Users\user\AppData\Roaming\CachemanControlPanel\CachemanControlPanel.exe TID: 6992Thread sleep time: -55288s >= -30000sJump to behavior
    Source: C:\Users\user\AppData\Roaming\CachemanControlPanel\CachemanControlPanel.exe TID: 6992Thread sleep time: -55179s >= -30000sJump to behavior
    Source: C:\Users\user\AppData\Roaming\CachemanControlPanel\CachemanControlPanel.exe TID: 6992Thread sleep time: -55070s >= -30000sJump to behavior
    Source: C:\Users\user\AppData\Roaming\CachemanControlPanel\CachemanControlPanel.exe TID: 6992Thread sleep time: -54960s >= -30000sJump to behavior
    Source: C:\Users\user\AppData\Roaming\CachemanControlPanel\CachemanControlPanel.exe TID: 6992Thread sleep time: -54851s >= -30000sJump to behavior
    Source: C:\Users\user\AppData\Roaming\CachemanControlPanel\CachemanControlPanel.exe TID: 6992Thread sleep time: -54741s >= -30000sJump to behavior
    Source: C:\Users\user\AppData\Roaming\CachemanControlPanel\CachemanControlPanel.exe TID: 6992Thread sleep time: -54632s >= -30000sJump to behavior
    Source: C:\Users\user\AppData\Roaming\CachemanControlPanel\CachemanControlPanel.exe TID: 6992Thread sleep time: -54523s >= -30000sJump to behavior
    Source: C:\Users\user\AppData\Roaming\CachemanControlPanel\CachemanControlPanel.exe TID: 6992Thread sleep time: -54414s >= -30000sJump to behavior
    Source: C:\Users\user\AppData\Roaming\CachemanControlPanel\CachemanControlPanel.exe TID: 6992Thread sleep time: -54304s >= -30000sJump to behavior
    Source: C:\Users\user\AppData\Roaming\CachemanControlPanel\CachemanControlPanel.exe TID: 6992Thread sleep time: -54195s >= -30000sJump to behavior
    Source: C:\Users\user\AppData\Roaming\CachemanControlPanel\CachemanControlPanel.exe TID: 6992Thread sleep time: -54085s >= -30000sJump to behavior
    Source: C:\Users\user\AppData\Roaming\CachemanControlPanel\CachemanControlPanel.exe TID: 6992Thread sleep time: -53976s >= -30000sJump to behavior
    Source: C:\Users\user\AppData\Roaming\CachemanControlPanel\CachemanControlPanel.exe TID: 6992Thread sleep time: -53861s >= -30000sJump to behavior
    Source: C:\Users\user\AppData\Roaming\CachemanControlPanel\CachemanControlPanel.exe TID: 6992Thread sleep time: -53757s >= -30000sJump to behavior
    Source: C:\Users\user\AppData\Roaming\CachemanControlPanel\CachemanControlPanel.exe TID: 6992Thread sleep time: -53648s >= -30000sJump to behavior
    Source: C:\Users\user\AppData\Roaming\CachemanControlPanel\CachemanControlPanel.exe TID: 6992Thread sleep time: -53537s >= -30000sJump to behavior
    Source: C:\Users\user\AppData\Roaming\CachemanControlPanel\CachemanControlPanel.exe TID: 6992Thread sleep time: -53429s >= -30000sJump to behavior
    Source: C:\Users\user\AppData\Roaming\CachemanControlPanel\CachemanControlPanel.exe TID: 6992Thread sleep time: -53320s >= -30000sJump to behavior
    Source: C:\Users\user\AppData\Roaming\CachemanControlPanel\CachemanControlPanel.exe TID: 6992Thread sleep time: -53210s >= -30000sJump to behavior
    Source: C:\Users\user\AppData\Roaming\CachemanControlPanel\CachemanControlPanel.exe TID: 6992Thread sleep time: -53101s >= -30000sJump to behavior
    Source: C:\Users\user\AppData\Roaming\CachemanControlPanel\CachemanControlPanel.exe TID: 6992Thread sleep time: -52991s >= -30000sJump to behavior
    Source: C:\Users\user\AppData\Roaming\CachemanControlPanel\CachemanControlPanel.exe TID: 6992Thread sleep time: -52882s >= -30000sJump to behavior
    Source: C:\Users\user\AppData\Roaming\CachemanControlPanel\CachemanControlPanel.exe TID: 6992Thread sleep time: -52773s >= -30000sJump to behavior
    Source: C:\Users\user\AppData\Roaming\CachemanControlPanel\CachemanControlPanel.exe TID: 6992Thread sleep time: -52663s >= -30000sJump to behavior
    Source: C:\Users\user\AppData\Roaming\CachemanControlPanel\CachemanControlPanel.exe TID: 6992Thread sleep time: -52554s >= -30000sJump to behavior
    Source: C:\Users\user\AppData\Roaming\CachemanControlPanel\CachemanControlPanel.exe TID: 6992Thread sleep time: -52445s >= -30000sJump to behavior
    Source: C:\Users\user\AppData\Roaming\CachemanControlPanel\CachemanControlPanel.exe TID: 6992Thread sleep time: -52335s >= -30000sJump to behavior
    Source: C:\Users\user\AppData\Roaming\CachemanControlPanel\CachemanControlPanel.exe TID: 6992Thread sleep time: -52226s >= -30000sJump to behavior
    Source: C:\Users\user\AppData\Roaming\CachemanControlPanel\CachemanControlPanel.exe TID: 6992Thread sleep time: -52117s >= -30000sJump to behavior
    Source: C:\Users\user\AppData\Roaming\CachemanControlPanel\CachemanControlPanel.exe TID: 6992Thread sleep time: -52007s >= -30000sJump to behavior
    Source: C:\Users\user\AppData\Roaming\CachemanControlPanel\CachemanControlPanel.exe TID: 6992Thread sleep time: -51898s >= -30000sJump to behavior
    Source: C:\Users\user\AppData\Roaming\CachemanControlPanel\CachemanControlPanel.exe TID: 6992Thread sleep time: -51789s >= -30000sJump to behavior
    Source: C:\Users\user\AppData\Roaming\CachemanControlPanel\CachemanControlPanel.exe TID: 6992Thread sleep time: -51679s >= -30000sJump to behavior
    Source: C:\Users\user\AppData\Roaming\CachemanControlPanel\CachemanControlPanel.exe TID: 6992Thread sleep time: -51570s >= -30000sJump to behavior
    Source: C:\Users\user\AppData\Roaming\CachemanControlPanel\CachemanControlPanel.exe TID: 6992Thread sleep time: -51461s >= -30000sJump to behavior
    Source: C:\Users\user\AppData\Roaming\CachemanControlPanel\CachemanControlPanel.exe TID: 6992Thread sleep time: -51351s >= -30000sJump to behavior
    Source: C:\Users\user\AppData\Roaming\CachemanControlPanel\CachemanControlPanel.exe TID: 6992Thread sleep time: -51241s >= -30000sJump to behavior
    Source: C:\Users\user\AppData\Roaming\CachemanControlPanel\CachemanControlPanel.exe TID: 6992Thread sleep time: -51132s >= -30000sJump to behavior
    Source: C:\Users\user\AppData\Roaming\CachemanControlPanel\CachemanControlPanel.exe TID: 6992Thread sleep time: -51023s >= -30000sJump to behavior
    Source: C:\Users\user\AppData\Roaming\CachemanControlPanel\CachemanControlPanel.exe TID: 6992Thread sleep time: -50913s >= -30000sJump to behavior
    Source: C:\Users\user\AppData\Roaming\CachemanControlPanel\CachemanControlPanel.exe TID: 6992Thread sleep time: -50804s >= -30000sJump to behavior
    Source: C:\Users\user\AppData\Roaming\CachemanControlPanel\CachemanControlPanel.exe TID: 6992Thread sleep time: -50695s >= -30000sJump to behavior
    Source: C:\Users\user\AppData\Roaming\CachemanControlPanel\CachemanControlPanel.exe TID: 6992Thread sleep time: -50585s >= -30000sJump to behavior
    Source: C:\Users\user\AppData\Roaming\CachemanControlPanel\CachemanControlPanel.exe TID: 6992Thread sleep time: -50476s >= -30000sJump to behavior
    Source: C:\Users\user\AppData\Roaming\CachemanControlPanel\CachemanControlPanel.exe TID: 6992Thread sleep time: -50367s >= -30000sJump to behavior
    Source: C:\Users\user\AppData\Roaming\CachemanControlPanel\CachemanControlPanel.exe TID: 6992Thread sleep time: -50257s >= -30000sJump to behavior
    Source: C:\Users\user\AppData\Roaming\CachemanControlPanel\CachemanControlPanel.exe TID: 6992Thread sleep time: -50148s >= -30000sJump to behavior
    Source: C:\Users\user\AppData\Roaming\CachemanControlPanel\CachemanControlPanel.exe TID: 6992Thread sleep time: -50038s >= -30000sJump to behavior
    Source: C:\Users\user\AppData\Roaming\CachemanControlPanel\CachemanControlPanel.exe TID: 6992Thread sleep time: -49929s >= -30000sJump to behavior
    Source: C:\Users\user\AppData\Roaming\CachemanControlPanel\CachemanControlPanel.exe TID: 6992Thread sleep time: -49820s >= -30000sJump to behavior
    Source: C:\Users\user\AppData\Roaming\CachemanControlPanel\CachemanControlPanel.exe TID: 6992Thread sleep time: -49710s >= -30000sJump to behavior
    Source: C:\Users\user\AppData\Roaming\CachemanControlPanel\CachemanControlPanel.exe TID: 6992Thread sleep time: -49601s >= -30000sJump to behavior
    Source: C:\Users\user\AppData\Roaming\CachemanControlPanel\CachemanControlPanel.exe TID: 6992Thread sleep time: -49492s >= -30000sJump to behavior
    Source: C:\Users\user\AppData\Roaming\CachemanControlPanel\CachemanControlPanel.exe TID: 6992Thread sleep time: -49381s >= -30000sJump to behavior
    Source: C:\Users\user\AppData\Roaming\CachemanControlPanel\CachemanControlPanel.exe TID: 6992Thread sleep time: -49273s >= -30000sJump to behavior
    Source: C:\Users\user\AppData\Roaming\CachemanControlPanel\CachemanControlPanel.exe TID: 6992Thread sleep time: -49163s >= -30000sJump to behavior
    Source: C:\Users\user\AppData\Roaming\CachemanControlPanel\CachemanControlPanel.exe TID: 6992Thread sleep time: -49054s >= -30000sJump to behavior
    Source: C:\Users\user\AppData\Roaming\CachemanControlPanel\CachemanControlPanel.exe TID: 6992Thread sleep time: -48945s >= -30000sJump to behavior
    Source: C:\Users\user\AppData\Roaming\CachemanControlPanel\CachemanControlPanel.exe TID: 6992Thread sleep time: -48836s >= -30000sJump to behavior
    Source: C:\Users\user\AppData\Roaming\CachemanControlPanel\CachemanControlPanel.exe TID: 6992Thread sleep time: -48725s >= -30000sJump to behavior
    Source: C:\Users\user\AppData\Roaming\CachemanControlPanel\CachemanControlPanel.exe TID: 6992Thread sleep time: -48616s >= -30000sJump to behavior
    Source: C:\Users\user\AppData\Roaming\CachemanControlPanel\CachemanControlPanel.exe TID: 6992Thread sleep time: -48507s >= -30000sJump to behavior
    Source: C:\Users\user\AppData\Roaming\CachemanControlPanel\CachemanControlPanel.exe TID: 6992Thread sleep time: -48398s >= -30000sJump to behavior
    Source: C:\Users\user\AppData\Roaming\CachemanControlPanel\CachemanControlPanel.exe TID: 6992Thread sleep time: -48289s >= -30000sJump to behavior
    Source: C:\Users\user\AppData\Roaming\CachemanControlPanel\CachemanControlPanel.exe TID: 6992Thread sleep time: -48179s >= -30000sJump to behavior
    Source: C:\Users\user\AppData\Roaming\CachemanControlPanel\CachemanControlPanel.exe TID: 6992Thread sleep time: -48070s >= -30000sJump to behavior
    Source: C:\Users\user\AppData\Roaming\CachemanControlPanel\CachemanControlPanel.exe TID: 6992Thread sleep time: -47960s >= -30000sJump to behavior
    Source: C:\Users\user\AppData\Roaming\CachemanControlPanel\CachemanControlPanel.exe TID: 6992Thread sleep time: -47851s >= -30000sJump to behavior
    Source: C:\Users\user\AppData\Roaming\CachemanControlPanel\CachemanControlPanel.exe TID: 6992Thread sleep time: -47741s >= -30000sJump to behavior
    Source: C:\Users\user\AppData\Roaming\CachemanControlPanel\CachemanControlPanel.exe TID: 6992Thread sleep time: -47632s >= -30000sJump to behavior
    Source: C:\Users\user\AppData\Roaming\CachemanControlPanel\CachemanControlPanel.exe TID: 6992Thread sleep time: -47523s >= -30000sJump to behavior
    Source: C:\Users\user\AppData\Roaming\CachemanControlPanel\CachemanControlPanel.exe TID: 6992Thread sleep time: -47412s >= -30000sJump to behavior
    Source: C:\Users\user\AppData\Roaming\CachemanControlPanel\CachemanControlPanel.exe TID: 6992Thread sleep time: -47168s >= -30000sJump to behavior
    Source: C:\Users\user\AppData\Roaming\CachemanControlPanel\CachemanControlPanel.exe TID: 6992Thread sleep time: -47052s >= -30000sJump to behavior
    Source: C:\Users\user\AppData\Roaming\CachemanControlPanel\CachemanControlPanel.exe TID: 6992Thread sleep time: -46942s >= -30000sJump to behavior
    Source: C:\Users\user\AppData\Roaming\CachemanControlPanel\CachemanControlPanel.exe TID: 6992Thread sleep time: -46832s >= -30000sJump to behavior
    Source: C:\Users\user\AppData\Roaming\CachemanControlPanel\CachemanControlPanel.exe TID: 6992Thread sleep time: -46723s >= -30000sJump to behavior
    Source: C:\Users\user\AppData\Roaming\CachemanControlPanel\CachemanControlPanel.exe TID: 6992Thread sleep time: -46617s >= -30000sJump to behavior
    Source: C:\Users\user\AppData\Roaming\CachemanControlPanel\CachemanControlPanel.exe TID: 6992Thread sleep time: -46505s >= -30000sJump to behavior
    Source: C:\Users\user\AppData\Roaming\CachemanControlPanel\CachemanControlPanel.exe TID: 6992Thread sleep time: -46080s >= -30000sJump to behavior
    Source: C:\Users\user\AppData\Roaming\CachemanControlPanel\CachemanControlPanel.exe TID: 6992Thread sleep time: -45974s >= -30000sJump to behavior
    Source: C:\Users\user\AppData\Roaming\CachemanControlPanel\CachemanControlPanel.exe TID: 6992Thread sleep time: -45861s >= -30000sJump to behavior
    Source: C:\Users\user\AppData\Roaming\CachemanControlPanel\CachemanControlPanel.exe TID: 6992Thread sleep time: -45758s >= -30000sJump to behavior
    Source: C:\Users\user\AppData\Roaming\CachemanControlPanel\CachemanControlPanel.exe TID: 6992Thread sleep time: -45648s >= -30000sJump to behavior
    Source: C:\Users\user\AppData\Roaming\CachemanControlPanel\CachemanControlPanel.exe TID: 6992Thread sleep time: -45538s >= -30000sJump to behavior
    Source: C:\Users\user\AppData\Roaming\CachemanControlPanel\CachemanControlPanel.exe TID: 6992Thread sleep time: -45421s >= -30000sJump to behavior
    Source: C:\Users\user\AppData\Roaming\CachemanControlPanel\CachemanControlPanel.exe TID: 6992Thread sleep time: -44825s >= -30000sJump to behavior