Source: |
Binary string: c:\938\follow-Record\Suffix\observe-element\force.pdb source: loaddll32.exe, 00000002.00000002.683594147.000000006E22A000.00000002.00020000.sdmp, rundll32.exe, 00000004.00000002.690126193.000000006E22A000.00000002.00020000.sdmp, rundll32.exe, 00000005.00000002.691931847.000000006E22A000.00000002.00020000.sdmp, rundll32.exe, 0000000F.00000002.697216102.000000006E22A000.00000002.00020000.sdmp, rundll32.exe, 00000012.00000002.686162523.000000006E22A000.00000002.00020000.sdmp, rundll32.exe, 00000018.00000002.696718223.000000006E22A000.00000002.00020000.sdmp, rundll32.exe, 0000001A.00000002.664832906.000000006E22A000.00000002.00020000.sdmp, QDfpQK7SOG.dll |
Source: Yara match |
File source: QDfpQK7SOG.dll, type: SAMPLE |
Source: Yara match |
File source: 0000001A.00000002.664721905.000000006E1A1000.00000020.00020000.sdmp, type: MEMORY |
Source: Yara match |
File source: 00000004.00000002.677279699.000000006E1A1000.00000020.00020000.sdmp, type: MEMORY |
Source: Yara match |
File source: 00000012.00000002.686115705.000000006E1A1000.00000020.00020000.sdmp, type: MEMORY |
Source: Yara match |
File source: 00000005.00000002.687931274.000000006E1A1000.00000020.00020000.sdmp, type: MEMORY |
Source: Yara match |
File source: 00000018.00000002.696642986.000000006E1A1000.00000020.00020000.sdmp, type: MEMORY |
Source: Yara match |
File source: 0000000F.00000002.690715845.000000006E1A1000.00000020.00020000.sdmp, type: MEMORY |
Source: Yara match |
File source: 00000002.00000002.675775659.000000006E1A1000.00000020.00020000.sdmp, type: MEMORY |
Source: Yara match |
File source: 26.2.rundll32.exe.6e1a0000.1.unpack, type: UNPACKEDPE |
Source: Yara match |
File source: 2.2.loaddll32.exe.6e1a0000.0.unpack, type: UNPACKEDPE |
Source: Yara match |
File source: 15.2.rundll32.exe.6e1a0000.1.unpack, type: UNPACKEDPE |
Source: Yara match |
File source: 24.2.rundll32.exe.6e1a0000.1.unpack, type: UNPACKEDPE |
Source: Yara match |
File source: 4.2.rundll32.exe.6e1a0000.1.unpack, type: UNPACKEDPE |
Source: Yara match |
File source: 5.2.rundll32.exe.6e1a0000.1.unpack, type: UNPACKEDPE |
Source: Yara match |
File source: 18.2.rundll32.exe.6e1a0000.1.unpack, type: UNPACKEDPE |
Source: Yara match |
File source: QDfpQK7SOG.dll, type: SAMPLE |
Source: Yara match |
File source: 0000001A.00000002.664721905.000000006E1A1000.00000020.00020000.sdmp, type: MEMORY |
Source: Yara match |
File source: 00000004.00000002.677279699.000000006E1A1000.00000020.00020000.sdmp, type: MEMORY |
Source: Yara match |
File source: 00000012.00000002.686115705.000000006E1A1000.00000020.00020000.sdmp, type: MEMORY |
Source: Yara match |
File source: 00000005.00000002.687931274.000000006E1A1000.00000020.00020000.sdmp, type: MEMORY |
Source: Yara match |
File source: 00000018.00000002.696642986.000000006E1A1000.00000020.00020000.sdmp, type: MEMORY |
Source: Yara match |
File source: 0000000F.00000002.690715845.000000006E1A1000.00000020.00020000.sdmp, type: MEMORY |
Source: Yara match |
File source: 00000002.00000002.675775659.000000006E1A1000.00000020.00020000.sdmp, type: MEMORY |
Source: Yara match |
File source: 26.2.rundll32.exe.6e1a0000.1.unpack, type: UNPACKEDPE |
Source: Yara match |
File source: 2.2.loaddll32.exe.6e1a0000.0.unpack, type: UNPACKEDPE |
Source: Yara match |
File source: 15.2.rundll32.exe.6e1a0000.1.unpack, type: UNPACKEDPE |
Source: Yara match |
File source: 24.2.rundll32.exe.6e1a0000.1.unpack, type: UNPACKEDPE |
Source: Yara match |
File source: 4.2.rundll32.exe.6e1a0000.1.unpack, type: UNPACKEDPE |
Source: Yara match |
File source: 5.2.rundll32.exe.6e1a0000.1.unpack, type: UNPACKEDPE |
Source: Yara match |
File source: 18.2.rundll32.exe.6e1a0000.1.unpack, type: UNPACKEDPE |
Source: C:\Windows\System32\loaddll32.exe |
Code function: 2_2_6E1E3E00 |
2_2_6E1E3E00 |
Source: C:\Windows\System32\loaddll32.exe |
Code function: 2_2_6E1E1C3C |
2_2_6E1E1C3C |
Source: C:\Windows\System32\loaddll32.exe |
Code function: 2_2_6E2167D9 |
2_2_6E2167D9 |
Source: C:\Windows\System32\loaddll32.exe |
Code function: 2_2_6E2084BB |
2_2_6E2084BB |
Source: C:\Windows\System32\loaddll32.exe |
Code function: 2_2_6E2202BC |
2_2_6E2202BC |
Source: C:\Windows\System32\loaddll32.exe |
Code function: 2_2_6E210396 |
2_2_6E210396 |
Source: C:\Windows\System32\loaddll32.exe |
Code function: 2_2_6E1FE079 |
2_2_6E1FE079 |
Source: C:\Windows\System32\loaddll32.exe |
Code function: 2_2_6E1F5150 |
2_2_6E1F5150 |
Source: C:\Windows\SysWOW64\rundll32.exe |
Code function: 4_2_6E1E3E00 |
4_2_6E1E3E00 |
Source: C:\Windows\SysWOW64\rundll32.exe |
Code function: 4_2_6E2167D9 |
4_2_6E2167D9 |
Source: C:\Windows\SysWOW64\rundll32.exe |
Code function: 4_2_6E1E1C3C |
4_2_6E1E1C3C |
Source: C:\Windows\SysWOW64\rundll32.exe |
Code function: 4_2_6E2084BB |
4_2_6E2084BB |
Source: C:\Windows\SysWOW64\rundll32.exe |
Code function: 4_2_6E2202BC |
4_2_6E2202BC |
Source: C:\Windows\SysWOW64\rundll32.exe |
Code function: 4_2_6E210396 |
4_2_6E210396 |
Source: C:\Windows\SysWOW64\rundll32.exe |
Code function: 4_2_6E1FE079 |
4_2_6E1FE079 |
Source: C:\Windows\SysWOW64\rundll32.exe |
Code function: 4_2_6E1F5150 |
4_2_6E1F5150 |
Source: C:\Windows\SysWOW64\rundll32.exe |
Code function: 15_2_6E1E3E00 |
15_2_6E1E3E00 |
Source: C:\Windows\SysWOW64\rundll32.exe |
Code function: 15_2_6E2167D9 |
15_2_6E2167D9 |
Source: C:\Windows\SysWOW64\rundll32.exe |
Code function: 15_2_6E1E1C3C |
15_2_6E1E1C3C |
Source: C:\Windows\SysWOW64\rundll32.exe |
Code function: 15_2_6E2084BB |
15_2_6E2084BB |
Source: C:\Windows\SysWOW64\rundll32.exe |
Code function: 15_2_6E2202BC |
15_2_6E2202BC |
Source: C:\Windows\SysWOW64\rundll32.exe |
Code function: 15_2_6E210396 |
15_2_6E210396 |
Source: C:\Windows\SysWOW64\rundll32.exe |
Code function: 15_2_6E1FE079 |
15_2_6E1FE079 |
Source: C:\Windows\SysWOW64\rundll32.exe |
Code function: 15_2_6E1F5150 |
15_2_6E1F5150 |
Source: C:\Windows\System32\loaddll32.exe |
Code function: String function: 6E1E0990 appears 34 times |
|
Source: C:\Windows\System32\loaddll32.exe |
Code function: String function: 6E1E00AC appears 100 times |
|
Source: C:\Windows\SysWOW64\rundll32.exe |
Code function: String function: 6E1E0990 appears 57 times |
|
Source: C:\Windows\SysWOW64\rundll32.exe |
Code function: String function: 6E1E00E0 appears 57 times |
|
Source: C:\Windows\SysWOW64\rundll32.exe |
Code function: String function: 6E1E00AC appears 199 times |
|
Source: C:\Windows\SysWOW64\rundll32.exe |
Code function: String function: 6E2023A9 appears 35 times |
|
Source: C:\Windows\System32\conhost.exe |
Mutant created: \Sessions\1\BaseNamedObjects\Local\SM0:6648:120:WilError_01 |
Source: C:\Windows\System32\conhost.exe |
Mutant created: \Sessions\1\BaseNamedObjects\Local\SM0:5644:120:WilError_01 |
Source: C:\Windows\System32\conhost.exe |
Mutant created: \Sessions\1\BaseNamedObjects\Local\SM0:6664:120:WilError_01 |
Source: C:\Windows\System32\conhost.exe |
Mutant created: \Sessions\1\BaseNamedObjects\Local\SM0:6976:120:WilError_01 |
Source: C:\Windows\System32\conhost.exe |
Mutant created: \Sessions\1\BaseNamedObjects\Local\SM0:7124:120:WilError_01 |
Source: C:\Windows\System32\conhost.exe |
Mutant created: \Sessions\1\BaseNamedObjects\Local\SM0:5820:120:WilError_01 |
Source: C:\Windows\System32\conhost.exe |
Mutant created: \Sessions\1\BaseNamedObjects\Local\SM0:6912:120:WilError_01 |
Source: C:\Windows\System32\conhost.exe |
Mutant created: \Sessions\1\BaseNamedObjects\Local\SM0:6788:120:WilError_01 |
Source: C:\Windows\System32\conhost.exe |
Mutant created: \Sessions\1\BaseNamedObjects\Local\SM0:6808:120:WilError_01 |
Source: C:\Windows\System32\conhost.exe |
Mutant created: \Sessions\1\BaseNamedObjects\Local\SM0:5700:120:WilError_01 |
Source: C:\Windows\System32\conhost.exe |
Mutant created: \Sessions\1\BaseNamedObjects\Local\SM0:7024:120:WilError_01 |
Source: C:\Windows\System32\conhost.exe |
Mutant created: \Sessions\1\BaseNamedObjects\Local\SM0:1604:120:WilError_01 |
Source: unknown |
Process created: C:\Windows\System32\loaddll32.exe loaddll32.exe 'C:\Users\user\Desktop\QDfpQK7SOG.dll' |
|
Source: C:\Windows\System32\loaddll32.exe |
Process created: C:\Windows\SysWOW64\cmd.exe cmd.exe /C rundll32.exe 'C:\Users\user\Desktop\QDfpQK7SOG.dll',#1 |
|
Source: C:\Windows\System32\loaddll32.exe |
Process created: C:\Windows\SysWOW64\rundll32.exe rundll32.exe C:\Users\user\Desktop\QDfpQK7SOG.dll,Connectdark |
|
Source: C:\Windows\SysWOW64\cmd.exe |
Process created: C:\Windows\SysWOW64\rundll32.exe rundll32.exe 'C:\Users\user\Desktop\QDfpQK7SOG.dll',#1 |
|
Source: C:\Windows\SysWOW64\rundll32.exe |
Process created: C:\Windows\SysWOW64\cmd.exe C:\Windows\system32\cmd.exe /c cd Island |
|
Source: C:\Windows\SysWOW64\rundll32.exe |
Process created: C:\Windows\SysWOW64\cmd.exe C:\Windows\system32\cmd.exe /c cd Island |
|
Source: C:\Windows\SysWOW64\cmd.exe |
Process created: C:\Windows\System32\conhost.exe C:\Windows\system32\conhost.exe 0xffffffff -ForceV1 |
|
Source: C:\Windows\SysWOW64\cmd.exe |
Process created: C:\Windows\System32\conhost.exe C:\Windows\system32\conhost.exe 0xffffffff -ForceV1 |
|
Source: C:\Windows\SysWOW64\rundll32.exe |
Process created: C:\Windows\SysWOW64\cmd.exe C:\Windows\system32\cmd.exe /c cd Matter m |
|
Source: C:\Windows\SysWOW64\cmd.exe |
Process created: C:\Windows\System32\conhost.exe C:\Windows\system32\conhost.exe 0xffffffff -ForceV1 |
|
Source: C:\Windows\SysWOW64\rundll32.exe |
Process created: C:\Windows\SysWOW64\cmd.exe C:\Windows\system32\cmd.exe /c cd Matter m |
|
Source: C:\Windows\SysWOW64\cmd.exe |
Process created: C:\Windows\System32\conhost.exe C:\Windows\system32\conhost.exe 0xffffffff -ForceV1 |
|
Source: C:\Windows\System32\loaddll32.exe |
Process created: C:\Windows\SysWOW64\rundll32.exe rundll32.exe C:\Users\user\Desktop\QDfpQK7SOG.dll,Mindlake |
|
Source: C:\Windows\SysWOW64\rundll32.exe |
Process created: C:\Windows\SysWOW64\cmd.exe C:\Windows\system32\cmd.exe /c cd Island |
|
Source: C:\Windows\SysWOW64\cmd.exe |
Process created: C:\Windows\System32\conhost.exe C:\Windows\system32\conhost.exe 0xffffffff -ForceV1 |
|
Source: C:\Windows\System32\loaddll32.exe |
Process created: C:\Windows\SysWOW64\rundll32.exe rundll32.exe C:\Users\user\Desktop\QDfpQK7SOG.dll,Porthigh |
|
Source: C:\Windows\SysWOW64\rundll32.exe |
Process created: C:\Windows\SysWOW64\cmd.exe C:\Windows\system32\cmd.exe /c cd Matter m |
|
Source: C:\Windows\SysWOW64\cmd.exe |
Process created: C:\Windows\System32\conhost.exe C:\Windows\system32\conhost.exe 0xffffffff -ForceV1 |
|
Source: C:\Windows\SysWOW64\rundll32.exe |
Process created: C:\Windows\SysWOW64\cmd.exe C:\Windows\system32\cmd.exe /c cd Island |
|
Source: C:\Windows\SysWOW64\cmd.exe |
Process created: C:\Windows\System32\conhost.exe C:\Windows\system32\conhost.exe 0xffffffff -ForceV1 |
|
Source: C:\Windows\SysWOW64\rundll32.exe |
Process created: C:\Windows\SysWOW64\cmd.exe C:\Windows\system32\cmd.exe /c cd Matter m |
|
Source: C:\Windows\System32\loaddll32.exe |
Process created: C:\Windows\SysWOW64\rundll32.exe rundll32.exe C:\Users\user\Desktop\QDfpQK7SOG.dll,Problemscale |
|
Source: C:\Windows\SysWOW64\cmd.exe |
Process created: C:\Windows\System32\conhost.exe C:\Windows\system32\conhost.exe 0xffffffff -ForceV1 |
|
Source: C:\Windows\System32\loaddll32.exe |
Process created: C:\Windows\SysWOW64\rundll32.exe rundll32.exe C:\Users\user\Desktop\QDfpQK7SOG.dll,WingGrass |
|
Source: C:\Windows\SysWOW64\rundll32.exe |
Process created: C:\Windows\SysWOW64\cmd.exe C:\Windows\system32\cmd.exe /c cd Island |
|
Source: C:\Windows\SysWOW64\cmd.exe |
Process created: C:\Windows\System32\conhost.exe C:\Windows\system32\conhost.exe 0xffffffff -ForceV1 |
|
Source: C:\Windows\SysWOW64\rundll32.exe |
Process created: C:\Windows\SysWOW64\cmd.exe C:\Windows\system32\cmd.exe /c cd Island |
|
Source: C:\Windows\SysWOW64\cmd.exe |
Process created: C:\Windows\System32\conhost.exe C:\Windows\system32\conhost.exe 0xffffffff -ForceV1 |
|
Source: C:\Windows\SysWOW64\rundll32.exe |
Process created: C:\Windows\SysWOW64\cmd.exe C:\Windows\system32\cmd.exe /c cd Matter m |
|
Source: C:\Windows\System32\loaddll32.exe |
Process created: C:\Windows\SysWOW64\cmd.exe C:\Windows\system32\cmd.exe /c cd Island |
|
Source: C:\Windows\SysWOW64\cmd.exe |
Process created: C:\Windows\System32\conhost.exe C:\Windows\system32\conhost.exe 0xffffffff -ForceV1 |
|
Source: C:\Windows\System32\loaddll32.exe |
Process created: C:\Windows\SysWOW64\cmd.exe C:\Windows\system32\cmd.exe /c cd Matter m |
|
Source: C:\Windows\SysWOW64\rundll32.exe |
Process created: C:\Windows\SysWOW64\cmd.exe C:\Windows\system32\cmd.exe /c cd Matter m |
|
Source: C:\Windows\SysWOW64\cmd.exe |
Process created: C:\Windows\System32\conhost.exe C:\Windows\system32\conhost.exe 0xffffffff -ForceV1 |
|
Source: C:\Windows\System32\loaddll32.exe |
Process created: C:\Windows\SysWOW64\cmd.exe cmd.exe /C rundll32.exe 'C:\Users\user\Desktop\QDfpQK7SOG.dll',#1 |
Jump to behavior |
Source: C:\Windows\System32\loaddll32.exe |
Process created: C:\Windows\SysWOW64\rundll32.exe rundll32.exe C:\Users\user\Desktop\QDfpQK7SOG.dll,Connectdark |
Jump to behavior |
Source: C:\Windows\System32\loaddll32.exe |
Process created: C:\Windows\SysWOW64\rundll32.exe rundll32.exe C:\Users\user\Desktop\QDfpQK7SOG.dll,Mindlake |
Jump to behavior |
Source: C:\Windows\System32\loaddll32.exe |
Process created: C:\Windows\SysWOW64\rundll32.exe rundll32.exe C:\Users\user\Desktop\QDfpQK7SOG.dll,Porthigh |
Jump to behavior |
Source: C:\Windows\System32\loaddll32.exe |
Process created: C:\Windows\SysWOW64\rundll32.exe rundll32.exe C:\Users\user\Desktop\QDfpQK7SOG.dll,Problemscale |
Jump to behavior |
Source: C:\Windows\System32\loaddll32.exe |
Process created: C:\Windows\SysWOW64\rundll32.exe rundll32.exe C:\Users\user\Desktop\QDfpQK7SOG.dll,WingGrass |
Jump to behavior |
Source: C:\Windows\System32\loaddll32.exe |
Process created: C:\Windows\SysWOW64\cmd.exe C:\Windows\system32\cmd.exe /c cd Island |
Jump to behavior |
Source: C:\Windows\System32\loaddll32.exe |
Process created: C:\Windows\SysWOW64\cmd.exe C:\Windows\system32\cmd.exe /c cd Matter m |
Jump to behavior |
Source: C:\Windows\SysWOW64\cmd.exe |
Process created: C:\Windows\SysWOW64\rundll32.exe rundll32.exe 'C:\Users\user\Desktop\QDfpQK7SOG.dll',#1 |
Jump to behavior |
Source: C:\Windows\SysWOW64\rundll32.exe |
Process created: C:\Windows\SysWOW64\cmd.exe C:\Windows\system32\cmd.exe /c cd Island |
Jump to behavior |
Source: C:\Windows\SysWOW64\rundll32.exe |
Process created: C:\Windows\SysWOW64\cmd.exe C:\Windows\system32\cmd.exe /c cd Matter m |
Jump to behavior |
Source: C:\Windows\SysWOW64\rundll32.exe |
Process created: C:\Windows\SysWOW64\cmd.exe C:\Windows\system32\cmd.exe /c cd Island |
Jump to behavior |
Source: C:\Windows\SysWOW64\rundll32.exe |
Process created: C:\Windows\SysWOW64\cmd.exe C:\Windows\system32\cmd.exe /c cd Matter m |
Jump to behavior |
Source: C:\Windows\SysWOW64\rundll32.exe |
Process created: C:\Windows\SysWOW64\cmd.exe C:\Windows\system32\cmd.exe /c cd Island |
Jump to behavior |
Source: C:\Windows\SysWOW64\rundll32.exe |
Process created: C:\Windows\SysWOW64\cmd.exe C:\Windows\system32\cmd.exe /c cd Matter m |
Jump to behavior |
Source: C:\Windows\SysWOW64\rundll32.exe |
Process created: C:\Windows\SysWOW64\cmd.exe C:\Windows\system32\cmd.exe /c cd Island |
Jump to behavior |
Source: C:\Windows\SysWOW64\rundll32.exe |
Process created: C:\Windows\SysWOW64\cmd.exe C:\Windows\system32\cmd.exe /c cd Matter m |
Jump to behavior |
Source: C:\Windows\SysWOW64\rundll32.exe |
Process created: C:\Windows\SysWOW64\cmd.exe C:\Windows\system32\cmd.exe /c cd Island |
Jump to behavior |
Source: C:\Windows\SysWOW64\rundll32.exe |
Process created: C:\Windows\SysWOW64\cmd.exe C:\Windows\system32\cmd.exe /c cd Matter m |
Jump to behavior |
Source: C:\Windows\SysWOW64\rundll32.exe |
Process created: C:\Windows\SysWOW64\cmd.exe C:\Windows\system32\cmd.exe /c cd Island |
Jump to behavior |
Source: C:\Windows\SysWOW64\rundll32.exe |
Process created: C:\Windows\SysWOW64\cmd.exe C:\Windows\system32\cmd.exe /c cd Matter m |
Jump to behavior |
Source: |
Binary string: c:\938\follow-Record\Suffix\observe-element\force.pdb source: loaddll32.exe, 00000002.00000002.683594147.000000006E22A000.00000002.00020000.sdmp, rundll32.exe, 00000004.00000002.690126193.000000006E22A000.00000002.00020000.sdmp, rundll32.exe, 00000005.00000002.691931847.000000006E22A000.00000002.00020000.sdmp, rundll32.exe, 0000000F.00000002.697216102.000000006E22A000.00000002.00020000.sdmp, rundll32.exe, 00000012.00000002.686162523.000000006E22A000.00000002.00020000.sdmp, rundll32.exe, 00000018.00000002.696718223.000000006E22A000.00000002.00020000.sdmp, rundll32.exe, 0000001A.00000002.664832906.000000006E22A000.00000002.00020000.sdmp, QDfpQK7SOG.dll |
Source: C:\Windows\System32\loaddll32.exe |
Code function: 2_2_6E1E09D6 push ecx; ret |
2_2_6E1E09E9 |
Source: C:\Windows\System32\loaddll32.exe |
Code function: 2_2_6E1E0075 push ecx; ret |
2_2_6E1E0088 |
Source: C:\Windows\SysWOW64\rundll32.exe |
Code function: 4_2_6E1E0075 push ecx; ret |
4_2_6E1E0088 |
Source: C:\Windows\SysWOW64\rundll32.exe |
Code function: 4_2_6E1E09D6 push ecx; ret |
4_2_6E1E09E9 |
Source: C:\Windows\SysWOW64\rundll32.exe |
Code function: 15_2_6E1E0075 push ecx; ret |
15_2_6E1E0088 |
Source: C:\Windows\SysWOW64\rundll32.exe |
Code function: 15_2_6E1E09D6 push ecx; ret |
15_2_6E1E09E9 |
Source: Yara match |
File source: QDfpQK7SOG.dll, type: SAMPLE |
Source: Yara match |
File source: 0000001A.00000002.664721905.000000006E1A1000.00000020.00020000.sdmp, type: MEMORY |
Source: Yara match |
File source: 00000004.00000002.677279699.000000006E1A1000.00000020.00020000.sdmp, type: MEMORY |
Source: Yara match |
File source: 00000012.00000002.686115705.000000006E1A1000.00000020.00020000.sdmp, type: MEMORY |
Source: Yara match |
File source: 00000005.00000002.687931274.000000006E1A1000.00000020.00020000.sdmp, type: MEMORY |
Source: Yara match |
File source: 00000018.00000002.696642986.000000006E1A1000.00000020.00020000.sdmp, type: MEMORY |
Source: Yara match |
File source: 0000000F.00000002.690715845.000000006E1A1000.00000020.00020000.sdmp, type: MEMORY |
Source: Yara match |
File source: 00000002.00000002.675775659.000000006E1A1000.00000020.00020000.sdmp, type: MEMORY |
Source: Yara match |
File source: 26.2.rundll32.exe.6e1a0000.1.unpack, type: UNPACKEDPE |
Source: Yara match |
File source: 2.2.loaddll32.exe.6e1a0000.0.unpack, type: UNPACKEDPE |
Source: Yara match |
File source: 15.2.rundll32.exe.6e1a0000.1.unpack, type: UNPACKEDPE |
Source: Yara match |
File source: 24.2.rundll32.exe.6e1a0000.1.unpack, type: UNPACKEDPE |
Source: Yara match |
File source: 4.2.rundll32.exe.6e1a0000.1.unpack, type: UNPACKEDPE |
Source: Yara match |
File source: 5.2.rundll32.exe.6e1a0000.1.unpack, type: UNPACKEDPE |
Source: Yara match |
File source: 18.2.rundll32.exe.6e1a0000.1.unpack, type: UNPACKEDPE |
Source: C:\Windows\SysWOW64\rundll32.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Windows\SysWOW64\rundll32.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Windows\System32\conhost.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Windows\System32\conhost.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Windows\System32\conhost.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Windows\System32\conhost.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Windows\SysWOW64\rundll32.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Windows\System32\conhost.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Windows\SysWOW64\rundll32.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Windows\System32\conhost.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Windows\System32\conhost.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Windows\SysWOW64\rundll32.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Windows\System32\conhost.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Windows\SysWOW64\rundll32.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Windows\System32\conhost.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Windows\System32\conhost.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Windows\System32\conhost.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Windows\System32\conhost.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Windows\SysWOW64\rundll32.exe |
Last function: Thread delayed |
Source: C:\Windows\SysWOW64\rundll32.exe |
Last function: Thread delayed |
Source: C:\Windows\SysWOW64\rundll32.exe |
Last function: Thread delayed |
Source: C:\Windows\SysWOW64\rundll32.exe |
Last function: Thread delayed |
Source: C:\Windows\System32\conhost.exe |
Last function: Thread delayed |
Source: C:\Windows\System32\conhost.exe |
Last function: Thread delayed |
Source: C:\Windows\System32\conhost.exe |
Last function: Thread delayed |
Source: C:\Windows\System32\loaddll32.exe |
Code function: 2_2_6E201F6D IsDebuggerPresent,SetUnhandledExceptionFilter,UnhandledExceptionFilter, |
2_2_6E201F6D |
Source: C:\Windows\System32\loaddll32.exe |
Code function: 2_2_6E1E07A7 IsProcessorFeaturePresent,IsDebuggerPresent,SetUnhandledExceptionFilter,UnhandledExceptionFilter, |
2_2_6E1E07A7 |
Source: C:\Windows\System32\loaddll32.exe |
Code function: 2_2_6E1E0288 SetUnhandledExceptionFilter,UnhandledExceptionFilter,GetCurrentProcess,TerminateProcess, |
2_2_6E1E0288 |
Source: C:\Windows\SysWOW64\rundll32.exe |
Code function: 4_2_6E201F6D IsDebuggerPresent,SetUnhandledExceptionFilter,UnhandledExceptionFilter, |
4_2_6E201F6D |
Source: C:\Windows\SysWOW64\rundll32.exe |
Code function: 4_2_6E1E07A7 IsProcessorFeaturePresent,IsDebuggerPresent,SetUnhandledExceptionFilter,UnhandledExceptionFilter, |
4_2_6E1E07A7 |
Source: C:\Windows\SysWOW64\rundll32.exe |
Code function: 4_2_6E1E0288 SetUnhandledExceptionFilter,UnhandledExceptionFilter,GetCurrentProcess,TerminateProcess, |
4_2_6E1E0288 |
Source: C:\Windows\SysWOW64\rundll32.exe |
Code function: 15_2_6E201F6D IsDebuggerPresent,SetUnhandledExceptionFilter,UnhandledExceptionFilter, |
15_2_6E201F6D |
Source: C:\Windows\SysWOW64\rundll32.exe |
Code function: 15_2_6E1E07A7 IsProcessorFeaturePresent,IsDebuggerPresent,SetUnhandledExceptionFilter,UnhandledExceptionFilter, |
15_2_6E1E07A7 |
Source: C:\Windows\SysWOW64\rundll32.exe |
Code function: 15_2_6E1E0288 SetUnhandledExceptionFilter,UnhandledExceptionFilter,GetCurrentProcess,TerminateProcess, |
15_2_6E1E0288 |
Source: C:\Windows\System32\loaddll32.exe |
Process created: C:\Windows\SysWOW64\cmd.exe C:\Windows\system32\cmd.exe /c cd Island |
Jump to behavior |
Source: C:\Windows\System32\loaddll32.exe |
Process created: C:\Windows\SysWOW64\cmd.exe C:\Windows\system32\cmd.exe /c cd Matter m |
Jump to behavior |
Source: C:\Windows\SysWOW64\cmd.exe |
Process created: C:\Windows\SysWOW64\rundll32.exe rundll32.exe 'C:\Users\user\Desktop\QDfpQK7SOG.dll',#1 |
Jump to behavior |
Source: C:\Windows\SysWOW64\rundll32.exe |
Process created: C:\Windows\SysWOW64\cmd.exe C:\Windows\system32\cmd.exe /c cd Island |
Jump to behavior |
Source: C:\Windows\SysWOW64\rundll32.exe |
Process created: C:\Windows\SysWOW64\cmd.exe C:\Windows\system32\cmd.exe /c cd Matter m |
Jump to behavior |
Source: C:\Windows\SysWOW64\rundll32.exe |
Process created: C:\Windows\SysWOW64\cmd.exe C:\Windows\system32\cmd.exe /c cd Island |
Jump to behavior |
Source: C:\Windows\SysWOW64\rundll32.exe |
Process created: C:\Windows\SysWOW64\cmd.exe C:\Windows\system32\cmd.exe /c cd Matter m |
Jump to behavior |
Source: C:\Windows\SysWOW64\rundll32.exe |
Process created: C:\Windows\SysWOW64\cmd.exe C:\Windows\system32\cmd.exe /c cd Island |
Jump to behavior |
Source: C:\Windows\SysWOW64\rundll32.exe |
Process created: C:\Windows\SysWOW64\cmd.exe C:\Windows\system32\cmd.exe /c cd Matter m |
Jump to behavior |
Source: C:\Windows\SysWOW64\rundll32.exe |
Process created: C:\Windows\SysWOW64\cmd.exe C:\Windows\system32\cmd.exe /c cd Island |
Jump to behavior |
Source: C:\Windows\SysWOW64\rundll32.exe |
Process created: C:\Windows\SysWOW64\cmd.exe C:\Windows\system32\cmd.exe /c cd Matter m |
Jump to behavior |
Source: C:\Windows\SysWOW64\rundll32.exe |
Process created: C:\Windows\SysWOW64\cmd.exe C:\Windows\system32\cmd.exe /c cd Island |
Jump to behavior |
Source: C:\Windows\SysWOW64\rundll32.exe |
Process created: C:\Windows\SysWOW64\cmd.exe C:\Windows\system32\cmd.exe /c cd Matter m |
Jump to behavior |
Source: C:\Windows\SysWOW64\rundll32.exe |
Process created: C:\Windows\SysWOW64\cmd.exe C:\Windows\system32\cmd.exe /c cd Island |
Jump to behavior |
Source: C:\Windows\SysWOW64\rundll32.exe |
Process created: C:\Windows\SysWOW64\cmd.exe C:\Windows\system32\cmd.exe /c cd Matter m |
Jump to behavior |
Source: loaddll32.exe, 00000002.00000002.675721619.0000000001580000.00000002.00000001.sdmp, rundll32.exe, 00000004.00000002.664452445.0000000003200000.00000002.00000001.sdmp, rundll32.exe, 00000005.00000002.687883244.0000000002F50000.00000002.00000001.sdmp, rundll32.exe, 0000000F.00000002.683862618.0000000003230000.00000002.00000001.sdmp, rundll32.exe, 00000012.00000002.684399021.00000000031E0000.00000002.00000001.sdmp, rundll32.exe, 00000018.00000002.696572906.00000000033A0000.00000002.00000001.sdmp, rundll32.exe, 0000001A.00000002.664660133.00000000030E0000.00000002.00000001.sdmp |
Binary or memory string: Shell_TrayWnd |
Source: loaddll32.exe, 00000002.00000002.675721619.0000000001580000.00000002.00000001.sdmp, rundll32.exe, 00000004.00000002.664452445.0000000003200000.00000002.00000001.sdmp, rundll32.exe, 00000005.00000002.687883244.0000000002F50000.00000002.00000001.sdmp, rundll32.exe, 0000000F.00000002.683862618.0000000003230000.00000002.00000001.sdmp, rundll32.exe, 00000012.00000002.684399021.00000000031E0000.00000002.00000001.sdmp, rundll32.exe, 00000018.00000002.696572906.00000000033A0000.00000002.00000001.sdmp, rundll32.exe, 0000001A.00000002.664660133.00000000030E0000.00000002.00000001.sdmp |
Binary or memory string: Progman |
Source: loaddll32.exe, 00000002.00000002.675721619.0000000001580000.00000002.00000001.sdmp, rundll32.exe, 00000004.00000002.664452445.0000000003200000.00000002.00000001.sdmp, rundll32.exe, 00000005.00000002.687883244.0000000002F50000.00000002.00000001.sdmp, rundll32.exe, 0000000F.00000002.683862618.0000000003230000.00000002.00000001.sdmp, rundll32.exe, 00000012.00000002.684399021.00000000031E0000.00000002.00000001.sdmp, rundll32.exe, 00000018.00000002.696572906.00000000033A0000.00000002.00000001.sdmp, rundll32.exe, 0000001A.00000002.664660133.00000000030E0000.00000002.00000001.sdmp |
Binary or memory string: &Program Manager |
Source: loaddll32.exe, 00000002.00000002.675721619.0000000001580000.00000002.00000001.sdmp, rundll32.exe, 00000004.00000002.664452445.0000000003200000.00000002.00000001.sdmp, rundll32.exe, 00000005.00000002.687883244.0000000002F50000.00000002.00000001.sdmp, rundll32.exe, 0000000F.00000002.683862618.0000000003230000.00000002.00000001.sdmp, rundll32.exe, 00000012.00000002.684399021.00000000031E0000.00000002.00000001.sdmp, rundll32.exe, 00000018.00000002.696572906.00000000033A0000.00000002.00000001.sdmp, rundll32.exe, 0000001A.00000002.664660133.00000000030E0000.00000002.00000001.sdmp |
Binary or memory string: Progmanlock |
Source: C:\Windows\System32\loaddll32.exe |
Code function: GetLocaleInfoW, |
2_2_6E21DF65 |
Source: C:\Windows\System32\loaddll32.exe |
Code function: IsValidCodePage,_wcschr,_wcschr,GetLocaleInfoW, |
2_2_6E21DD96 |
Source: C:\Windows\System32\loaddll32.exe |
Code function: EnumSystemLocalesW, |
2_2_6E213952 |
Source: C:\Windows\System32\loaddll32.exe |
Code function: GetLocaleInfoW, |
2_2_6E21E61F |
Source: C:\Windows\System32\loaddll32.exe |
Code function: GetUserDefaultLCID,IsValidCodePage,IsValidLocale,GetLocaleInfoW,GetLocaleInfoW, |
2_2_6E21E6EC |
Source: C:\Windows\System32\loaddll32.exe |
Code function: GetLocaleInfoW,GetLocaleInfoW,GetACP, |
2_2_6E21E518 |
Source: C:\Windows\System32\loaddll32.exe |
Code function: GetLocaleInfoW, |
2_2_6E214323 |
Source: C:\Windows\System32\loaddll32.exe |
Code function: ___crtGetLocaleInfoEx, |
2_2_6E1DF364 |
Source: C:\Windows\System32\loaddll32.exe |
Code function: GetLocaleInfoW, |
2_2_6E21E3EF |
Source: C:\Windows\System32\loaddll32.exe |
Code function: EnumSystemLocalesW, |
2_2_6E21E00E |
Source: C:\Windows\System32\loaddll32.exe |
Code function: EnumSystemLocalesW, |
2_2_6E21E077 |
Source: C:\Windows\System32\loaddll32.exe |
Code function: EnumSystemLocalesW, |
2_2_6E21E112 |
Source: C:\Windows\System32\loaddll32.exe |
Code function: GetLocaleInfoW, |
2_2_6E1DF1B7 |
Source: C:\Windows\System32\loaddll32.exe |
Code function: GetLocaleInfoW,GetLocaleInfoW,GetLocaleInfoW, |
2_2_6E21E19F |
Source: C:\Windows\SysWOW64\rundll32.exe |
Code function: GetLocaleInfoW, |
4_2_6E21E61F |
Source: C:\Windows\SysWOW64\rundll32.exe |
Code function: GetUserDefaultLCID,IsValidCodePage,IsValidLocale,GetLocaleInfoW,GetLocaleInfoW, |
4_2_6E21E6EC |
Source: C:\Windows\SysWOW64\rundll32.exe |
Code function: GetLocaleInfoW, |
4_2_6E21DF65 |
Source: C:\Windows\SysWOW64\rundll32.exe |
Code function: GetLocaleInfoW,GetLocaleInfoW,GetACP, |
4_2_6E21E518 |
Source: C:\Windows\SysWOW64\rundll32.exe |
Code function: IsValidCodePage,_wcschr,_wcschr,GetLocaleInfoW, |
4_2_6E21DD96 |
Source: C:\Windows\SysWOW64\rundll32.exe |
Code function: GetLocaleInfoW, |
4_2_6E214323 |
Source: C:\Windows\SysWOW64\rundll32.exe |
Code function: ___crtGetLocaleInfoEx, |
4_2_6E1DF364 |
Source: C:\Windows\SysWOW64\rundll32.exe |
Code function: GetLocaleInfoW, |
4_2_6E21E3EF |
Source: C:\Windows\SysWOW64\rundll32.exe |
Code function: EnumSystemLocalesW, |
4_2_6E21E00E |
Source: C:\Windows\SysWOW64\rundll32.exe |
Code function: EnumSystemLocalesW, |
4_2_6E21E077 |
Source: C:\Windows\SysWOW64\rundll32.exe |
Code function: EnumSystemLocalesW, |
4_2_6E21E112 |
Source: C:\Windows\SysWOW64\rundll32.exe |
Code function: EnumSystemLocalesW, |
4_2_6E213952 |
Source: C:\Windows\SysWOW64\rundll32.exe |
Code function: GetLocaleInfoW, |
4_2_6E1DF1B7 |
Source: C:\Windows\SysWOW64\rundll32.exe |
Code function: GetLocaleInfoW,GetLocaleInfoW,GetLocaleInfoW, |
4_2_6E21E19F |
Source: C:\Windows\SysWOW64\rundll32.exe |
Code function: GetLocaleInfoW, |
15_2_6E21E61F |
Source: C:\Windows\SysWOW64\rundll32.exe |
Code function: GetUserDefaultLCID,IsValidCodePage,IsValidLocale,GetLocaleInfoW,GetLocaleInfoW, |
15_2_6E21E6EC |
Source: C:\Windows\SysWOW64\rundll32.exe |
Code function: GetLocaleInfoW, |
15_2_6E21DF65 |
Source: C:\Windows\SysWOW64\rundll32.exe |
Code function: GetLocaleInfoW,GetLocaleInfoW,GetACP, |
15_2_6E21E518 |
Source: C:\Windows\SysWOW64\rundll32.exe |
Code function: IsValidCodePage,_wcschr,_wcschr,GetLocaleInfoW, |
15_2_6E21DD96 |
Source: C:\Windows\SysWOW64\rundll32.exe |
Code function: GetLocaleInfoW, |
15_2_6E214323 |
Source: C:\Windows\SysWOW64\rundll32.exe |
Code function: ___crtGetLocaleInfoEx, |
15_2_6E1DF364 |
Source: C:\Windows\SysWOW64\rundll32.exe |
Code function: GetLocaleInfoW, |
15_2_6E21E3EF |
Source: C:\Windows\SysWOW64\rundll32.exe |
Code function: EnumSystemLocalesW, |
15_2_6E21E00E |
Source: C:\Windows\SysWOW64\rundll32.exe |
Code function: EnumSystemLocalesW, |
15_2_6E21E077 |
Source: C:\Windows\SysWOW64\rundll32.exe |
Code function: EnumSystemLocalesW, |
15_2_6E21E112 |
Source: C:\Windows\SysWOW64\rundll32.exe |
Code function: EnumSystemLocalesW, |
15_2_6E213952 |
Source: C:\Windows\SysWOW64\rundll32.exe |
Code function: GetLocaleInfoW, |
15_2_6E1DF1B7 |
Source: C:\Windows\SysWOW64\rundll32.exe |
Code function: GetLocaleInfoW,GetLocaleInfoW,GetLocaleInfoW, |
15_2_6E21E19F |
Source: Yara match |
File source: QDfpQK7SOG.dll, type: SAMPLE |
Source: Yara match |
File source: 0000001A.00000002.664721905.000000006E1A1000.00000020.00020000.sdmp, type: MEMORY |
Source: Yara match |
File source: 00000004.00000002.677279699.000000006E1A1000.00000020.00020000.sdmp, type: MEMORY |
Source: Yara match |
File source: 00000012.00000002.686115705.000000006E1A1000.00000020.00020000.sdmp, type: MEMORY |
Source: Yara match |
File source: 00000005.00000002.687931274.000000006E1A1000.00000020.00020000.sdmp, type: MEMORY |
Source: Yara match |
File source: 00000018.00000002.696642986.000000006E1A1000.00000020.00020000.sdmp, type: MEMORY |
Source: Yara match |
File source: 0000000F.00000002.690715845.000000006E1A1000.00000020.00020000.sdmp, type: MEMORY |
Source: Yara match |
File source: 00000002.00000002.675775659.000000006E1A1000.00000020.00020000.sdmp, type: MEMORY |
Source: Yara match |
File source: 26.2.rundll32.exe.6e1a0000.1.unpack, type: UNPACKEDPE |
Source: Yara match |
File source: 2.2.loaddll32.exe.6e1a0000.0.unpack, type: UNPACKEDPE |
Source: Yara match |
File source: 15.2.rundll32.exe.6e1a0000.1.unpack, type: UNPACKEDPE |
Source: Yara match |
File source: 24.2.rundll32.exe.6e1a0000.1.unpack, type: UNPACKEDPE |
Source: Yara match |
File source: 4.2.rundll32.exe.6e1a0000.1.unpack, type: UNPACKEDPE |
Source: Yara match |
File source: 5.2.rundll32.exe.6e1a0000.1.unpack, type: UNPACKEDPE |
Source: Yara match |
File source: 18.2.rundll32.exe.6e1a0000.1.unpack, type: UNPACKEDPE |
Source: Yara match |
File source: QDfpQK7SOG.dll, type: SAMPLE |
Source: Yara match |
File source: 0000001A.00000002.664721905.000000006E1A1000.00000020.00020000.sdmp, type: MEMORY |
Source: Yara match |
File source: 00000004.00000002.677279699.000000006E1A1000.00000020.00020000.sdmp, type: MEMORY |
Source: Yara match |
File source: 00000012.00000002.686115705.000000006E1A1000.00000020.00020000.sdmp, type: MEMORY |
Source: Yara match |
File source: 00000005.00000002.687931274.000000006E1A1000.00000020.00020000.sdmp, type: MEMORY |
Source: Yara match |
File source: 00000018.00000002.696642986.000000006E1A1000.00000020.00020000.sdmp, type: MEMORY |
Source: Yara match |
File source: 0000000F.00000002.690715845.000000006E1A1000.00000020.00020000.sdmp, type: MEMORY |
Source: Yara match |
File source: 00000002.00000002.675775659.000000006E1A1000.00000020.00020000.sdmp, type: MEMORY |
Source: Yara match |
File source: 26.2.rundll32.exe.6e1a0000.1.unpack, type: UNPACKEDPE |
Source: Yara match |
File source: 2.2.loaddll32.exe.6e1a0000.0.unpack, type: UNPACKEDPE |
Source: Yara match |
File source: 15.2.rundll32.exe.6e1a0000.1.unpack, type: UNPACKEDPE |
Source: Yara match |
File source: 24.2.rundll32.exe.6e1a0000.1.unpack, type: UNPACKEDPE |
Source: Yara match |
File source: 4.2.rundll32.exe.6e1a0000.1.unpack, type: UNPACKEDPE |
Source: Yara match |
File source: 5.2.rundll32.exe.6e1a0000.1.unpack, type: UNPACKEDPE |
Source: Yara match |
File source: 18.2.rundll32.exe.6e1a0000.1.unpack, type: UNPACKEDPE |