Source: HALKBANK_EKSTRE_20210611_080203_744623,PDF.exe, 00000003.00000002.482152633.0000000003071000.00000004.00000001.sdmp |
String found in binary or memory: http://127.0.0.1:HTTP/1.1 |
Source: HALKBANK_EKSTRE_20210611_080203_744623,PDF.exe, 00000003.00000002.482152633.0000000003071000.00000004.00000001.sdmp |
String found in binary or memory: http://DynDns.comDynDNS |
Source: HALKBANK_EKSTRE_20210611_080203_744623,PDF.exe, 00000003.00000002.484187088.0000000003334000.00000004.00000001.sdmp |
String found in binary or memory: http://apps.identrust.com/roots/dstrootcax3.p7c0 |
Source: HALKBANK_EKSTRE_20210611_080203_744623,PDF.exe, 00000003.00000002.484187088.0000000003334000.00000004.00000001.sdmp |
String found in binary or memory: http://bmrtecpack.com |
Source: HALKBANK_EKSTRE_20210611_080203_744623,PDF.exe, 00000003.00000002.484187088.0000000003334000.00000004.00000001.sdmp |
String found in binary or memory: http://cps.letsencrypt.org0 |
Source: HALKBANK_EKSTRE_20210611_080203_744623,PDF.exe, 00000003.00000002.484187088.0000000003334000.00000004.00000001.sdmp |
String found in binary or memory: http://cps.root-x1.letsencrypt.org0 |
Source: HALKBANK_EKSTRE_20210611_080203_744623,PDF.exe, 00000003.00000002.484187088.0000000003334000.00000004.00000001.sdmp |
String found in binary or memory: http://crl.identrust.com/DSTROOTCAX3CRL.crl0 |
Source: HALKBANK_EKSTRE_20210611_080203_744623,PDF.exe, 00000003.00000002.482152633.0000000003071000.00000004.00000001.sdmp |
String found in binary or memory: http://ePfJSq.com |
Source: HALKBANK_EKSTRE_20210611_080203_744623,PDF.exe, 00000003.00000002.484187088.0000000003334000.00000004.00000001.sdmp |
String found in binary or memory: http://mail.bmrtecpack.com |
Source: HALKBANK_EKSTRE_20210611_080203_744623,PDF.exe, 00000003.00000002.484187088.0000000003334000.00000004.00000001.sdmp |
String found in binary or memory: http://r3.i.lencr.org/0B |
Source: HALKBANK_EKSTRE_20210611_080203_744623,PDF.exe, 00000003.00000002.484187088.0000000003334000.00000004.00000001.sdmp |
String found in binary or memory: http://r3.o.lencr.org0 |
Source: HALKBANK_EKSTRE_20210611_080203_744623,PDF.exe, 00000000.00000002.219661677.0000000002531000.00000004.00000001.sdmp |
String found in binary or memory: http://schemas.xmlsoap.org/ws/2005/05/identity/claims/name |
Source: HALKBANK_EKSTRE_20210611_080203_744623,PDF.exe, 00000003.00000002.484187088.0000000003334000.00000004.00000001.sdmp |
String found in binary or memory: http://x1.c.lencr.org/0 |
Source: HALKBANK_EKSTRE_20210611_080203_744623,PDF.exe, 00000003.00000002.484187088.0000000003334000.00000004.00000001.sdmp |
String found in binary or memory: http://x1.i.lencr.org/0 |
Source: HALKBANK_EKSTRE_20210611_080203_744623,PDF.exe, 00000003.00000002.482152633.0000000003071000.00000004.00000001.sdmp, HALKBANK_EKSTRE_20210611_080203_744623,PDF.exe, 00000003.00000003.423100074.0000000000BC4000.00000004.00000001.sdmp |
String found in binary or memory: https://9YHNdCcoTaUn.org |
Source: HALKBANK_EKSTRE_20210611_080203_744623,PDF.exe, 00000003.00000002.482152633.0000000003071000.00000004.00000001.sdmp |
String found in binary or memory: https://api.ipify.org% |
Source: HALKBANK_EKSTRE_20210611_080203_744623,PDF.exe, 00000003.00000002.482152633.0000000003071000.00000004.00000001.sdmp |
String found in binary or memory: https://api.ipify.org%GETMozilla/5.0 |
Source: HALKBANK_EKSTRE_20210611_080203_744623,PDF.exe, 00000000.00000002.219661677.0000000002531000.00000004.00000001.sdmp |
String found in binary or memory: https://stackpath.bootstrapcdn.com/bootstrap/4.5.0/css/bootstrap.min.css |
Source: HALKBANK_EKSTRE_20210611_080203_744623,PDF.exe, 00000000.00000002.220437474.0000000003539000.00000004.00000001.sdmp, HALKBANK_EKSTRE_20210611_080203_744623,PDF.exe, 00000003.00000000.217706120.0000000000402000.00000040.00000001.sdmp |
String found in binary or memory: https://www.theonionrouter.com/dist.torproject.org/torbrowser/9.5.3/tor-win32-0.4.3.6.zip |
Source: HALKBANK_EKSTRE_20210611_080203_744623,PDF.exe, 00000003.00000002.482152633.0000000003071000.00000004.00000001.sdmp |
String found in binary or memory: https://www.theonionrouter.com/dist.torproject.org/torbrowser/9.5.3/tor-win32-0.4.3.6.zip%tordir%%ha |
Source: C:\Users\user\Desktop\HALKBANK_EKSTRE_20210611_080203_744623,PDF.exe |
Code function: 0_2_00B6B5AC |
0_2_00B6B5AC |
Source: C:\Users\user\Desktop\HALKBANK_EKSTRE_20210611_080203_744623,PDF.exe |
Code function: 0_2_00B6E470 |
0_2_00B6E470 |
Source: C:\Users\user\Desktop\HALKBANK_EKSTRE_20210611_080203_744623,PDF.exe |
Code function: 0_2_00B6CA2B |
0_2_00B6CA2B |
Source: C:\Users\user\Desktop\HALKBANK_EKSTRE_20210611_080203_744623,PDF.exe |
Code function: 0_2_00B6B1E0 |
0_2_00B6B1E0 |
Source: C:\Users\user\Desktop\HALKBANK_EKSTRE_20210611_080203_744623,PDF.exe |
Code function: 0_2_00B6B5A0 |
0_2_00B6B5A0 |
Source: C:\Users\user\Desktop\HALKBANK_EKSTRE_20210611_080203_744623,PDF.exe |
Code function: 0_2_0453067A |
0_2_0453067A |
Source: C:\Users\user\Desktop\HALKBANK_EKSTRE_20210611_080203_744623,PDF.exe |
Code function: 0_2_045300D0 |
0_2_045300D0 |
Source: C:\Users\user\Desktop\HALKBANK_EKSTRE_20210611_080203_744623,PDF.exe |
Code function: 0_2_045307D7 |
0_2_045307D7 |
Source: C:\Users\user\Desktop\HALKBANK_EKSTRE_20210611_080203_744623,PDF.exe |
Code function: 3_2_01175114 |
3_2_01175114 |
Source: C:\Users\user\Desktop\HALKBANK_EKSTRE_20210611_080203_744623,PDF.exe |
Code function: 3_2_01170898 |
3_2_01170898 |
Source: C:\Users\user\Desktop\HALKBANK_EKSTRE_20210611_080203_744623,PDF.exe |
Code function: 3_2_01178548 |
3_2_01178548 |
Source: C:\Users\user\Desktop\HALKBANK_EKSTRE_20210611_080203_744623,PDF.exe |
Code function: 3_2_01170040 |
3_2_01170040 |
Source: C:\Users\user\Desktop\HALKBANK_EKSTRE_20210611_080203_744623,PDF.exe |
Code function: 3_2_0117E890 |
3_2_0117E890 |
Source: C:\Users\user\Desktop\HALKBANK_EKSTRE_20210611_080203_744623,PDF.exe |
Code function: 3_2_01172A58 |
3_2_01172A58 |
Source: C:\Users\user\Desktop\HALKBANK_EKSTRE_20210611_080203_744623,PDF.exe |
Code function: 3_2_01172AB8 |
3_2_01172AB8 |
Source: C:\Users\user\Desktop\HALKBANK_EKSTRE_20210611_080203_744623,PDF.exe |
Code function: 3_2_0123B908 |
3_2_0123B908 |
Source: C:\Users\user\Desktop\HALKBANK_EKSTRE_20210611_080203_744623,PDF.exe |
Code function: 3_2_01236C4C |
3_2_01236C4C |
Source: C:\Users\user\Desktop\HALKBANK_EKSTRE_20210611_080203_744623,PDF.exe |
Code function: 3_2_01240062 |
3_2_01240062 |
Source: C:\Users\user\Desktop\HALKBANK_EKSTRE_20210611_080203_744623,PDF.exe |
Code function: 3_2_0124B0F0 |
3_2_0124B0F0 |
Source: C:\Users\user\Desktop\HALKBANK_EKSTRE_20210611_080203_744623,PDF.exe |
Code function: 3_2_012497B8 |
3_2_012497B8 |
Source: C:\Users\user\Desktop\HALKBANK_EKSTRE_20210611_080203_744623,PDF.exe |
Code function: 3_2_01245E48 |
3_2_01245E48 |
Source: C:\Users\user\Desktop\HALKBANK_EKSTRE_20210611_080203_744623,PDF.exe |
Code function: 3_2_0124CF10 |
3_2_0124CF10 |
Source: C:\Users\user\Desktop\HALKBANK_EKSTRE_20210611_080203_744623,PDF.exe |
Code function: 3_2_01247240 |
3_2_01247240 |
Source: HALKBANK_EKSTRE_20210611_080203_744623,PDF.exe, 00000000.00000002.219661677.0000000002531000.00000004.00000001.sdmp |
Binary or memory string: OriginalFilenamenXOvOrEbczSOMbuQKuxXmuqDbcrtLzJGuFczuTT.exe4 vs HALKBANK_EKSTRE_20210611_080203_744623,PDF.exe |
Source: HALKBANK_EKSTRE_20210611_080203_744623,PDF.exe, 00000000.00000002.220856658.00000000036AF000.00000004.00000001.sdmp |
Binary or memory string: OriginalFilenameDSASignature.dll@ vs HALKBANK_EKSTRE_20210611_080203_744623,PDF.exe |
Source: HALKBANK_EKSTRE_20210611_080203_744623,PDF.exe, 00000000.00000000.208995346.000000000022E000.00000002.00020000.sdmp |
Binary or memory string: OriginalFilenameConsistency.exe< vs HALKBANK_EKSTRE_20210611_080203_744623,PDF.exe |
Source: HALKBANK_EKSTRE_20210611_080203_744623,PDF.exe, 00000000.00000002.219282495.000000000093B000.00000004.00000020.sdmp |
Binary or memory string: OriginalFilenameclr.dllT vs HALKBANK_EKSTRE_20210611_080203_744623,PDF.exe |
Source: HALKBANK_EKSTRE_20210611_080203_744623,PDF.exe, 00000000.00000002.220437474.0000000003539000.00000004.00000001.sdmp |
Binary or memory string: OriginalFilenameKygo.dll* vs HALKBANK_EKSTRE_20210611_080203_744623,PDF.exe |
Source: HALKBANK_EKSTRE_20210611_080203_744623,PDF.exe, 00000002.00000000.215986662.000000000031E000.00000002.00020000.sdmp |
Binary or memory string: OriginalFilenameConsistency.exe< vs HALKBANK_EKSTRE_20210611_080203_744623,PDF.exe |
Source: HALKBANK_EKSTRE_20210611_080203_744623,PDF.exe, 00000003.00000002.477347413.0000000000AAE000.00000002.00020000.sdmp |
Binary or memory string: OriginalFilenameConsistency.exe< vs HALKBANK_EKSTRE_20210611_080203_744623,PDF.exe |
Source: HALKBANK_EKSTRE_20210611_080203_744623,PDF.exe, 00000003.00000002.479540519.00000000011A0000.00000002.00000001.sdmp |
Binary or memory string: OriginalFilenamewshom.ocx.mui vs HALKBANK_EKSTRE_20210611_080203_744623,PDF.exe |
Source: HALKBANK_EKSTRE_20210611_080203_744623,PDF.exe, 00000003.00000002.479505881.0000000001190000.00000002.00000001.sdmp |
Binary or memory string: OriginalFilenamewshom.ocx vs HALKBANK_EKSTRE_20210611_080203_744623,PDF.exe |
Source: HALKBANK_EKSTRE_20210611_080203_744623,PDF.exe, 00000003.00000002.477581620.0000000000EF8000.00000004.00000001.sdmp |
Binary or memory string: OriginalFilenameUNKNOWN_FILET vs HALKBANK_EKSTRE_20210611_080203_744623,PDF.exe |
Source: HALKBANK_EKSTRE_20210611_080203_744623,PDF.exe, 00000003.00000002.476523997.0000000000402000.00000040.00000001.sdmp |
Binary or memory string: OriginalFilenamenXOvOrEbczSOMbuQKuxXmuqDbcrtLzJGuFczuTT.exe4 vs HALKBANK_EKSTRE_20210611_080203_744623,PDF.exe |
Source: HALKBANK_EKSTRE_20210611_080203_744623,PDF.exe, 00000003.00000002.479981873.0000000001250000.00000002.00000001.sdmp |
Binary or memory string: OriginalFilenamemscorrc.dllT vs HALKBANK_EKSTRE_20210611_080203_744623,PDF.exe |
Source: HALKBANK_EKSTRE_20210611_080203_744623,PDF.exe |
Binary or memory string: OriginalFilenameConsistency.exe< vs HALKBANK_EKSTRE_20210611_080203_744623,PDF.exe |
Source: HALKBANK_EKSTRE_20210611_080203_744623,PDF.exe, vJiGl01UUJfXfNWas3/DyyVDbaRvM1YfIq9il.cs |
Cryptographic APIs: 'CreateDecryptor' |
Source: HALKBANK_EKSTRE_20210611_080203_744623,PDF.exe, vJiGl01UUJfXfNWas3/DyyVDbaRvM1YfIq9il.cs |
Cryptographic APIs: 'CreateDecryptor' |
Source: 0.2.HALKBANK_EKSTRE_20210611_080203_744623,PDF.exe.150000.0.unpack, vJiGl01UUJfXfNWas3/DyyVDbaRvM1YfIq9il.cs |
Cryptographic APIs: 'CreateDecryptor' |
Source: 0.2.HALKBANK_EKSTRE_20210611_080203_744623,PDF.exe.150000.0.unpack, vJiGl01UUJfXfNWas3/DyyVDbaRvM1YfIq9il.cs |
Cryptographic APIs: 'CreateDecryptor' |
Source: 2.2.HALKBANK_EKSTRE_20210611_080203_744623,PDF.exe.240000.0.unpack, vJiGl01UUJfXfNWas3/DyyVDbaRvM1YfIq9il.cs |
Cryptographic APIs: 'CreateDecryptor' |
Source: 2.2.HALKBANK_EKSTRE_20210611_080203_744623,PDF.exe.240000.0.unpack, vJiGl01UUJfXfNWas3/DyyVDbaRvM1YfIq9il.cs |
Cryptographic APIs: 'CreateDecryptor' |
Source: 2.0.HALKBANK_EKSTRE_20210611_080203_744623,PDF.exe.240000.0.unpack, vJiGl01UUJfXfNWas3/DyyVDbaRvM1YfIq9il.cs |
Cryptographic APIs: 'CreateDecryptor' |
Source: 2.0.HALKBANK_EKSTRE_20210611_080203_744623,PDF.exe.240000.0.unpack, vJiGl01UUJfXfNWas3/DyyVDbaRvM1YfIq9il.cs |
Cryptographic APIs: 'CreateDecryptor' |
Source: 3.2.HALKBANK_EKSTRE_20210611_080203_744623,PDF.exe.9d0000.1.unpack, vJiGl01UUJfXfNWas3/DyyVDbaRvM1YfIq9il.cs |
Cryptographic APIs: 'CreateDecryptor' |
Source: 3.2.HALKBANK_EKSTRE_20210611_080203_744623,PDF.exe.9d0000.1.unpack, vJiGl01UUJfXfNWas3/DyyVDbaRvM1YfIq9il.cs |
Cryptographic APIs: 'CreateDecryptor' |
Source: 3.2.HALKBANK_EKSTRE_20210611_080203_744623,PDF.exe.400000.0.unpack, A/b2.cs |
Cryptographic APIs: 'TransformFinalBlock', 'CreateDecryptor' |
Source: 3.2.HALKBANK_EKSTRE_20210611_080203_744623,PDF.exe.400000.0.unpack, A/b2.cs |
Cryptographic APIs: 'TransformFinalBlock', 'CreateDecryptor' |
Source: HALKBANK_EKSTRE_20210611_080203_744623,PDF.exe, 00000000.00000002.219661677.0000000002531000.00000004.00000001.sdmp |
Binary or memory string: Select * from Clientes WHERE id=@id;; |
Source: HALKBANK_EKSTRE_20210611_080203_744623,PDF.exe, 00000000.00000002.219661677.0000000002531000.00000004.00000001.sdmp |
Binary or memory string: Select * from Aluguel Erro ao listar Banco sql-Aluguel.INSERT INTO Aluguel VALUES(@clienteID, @data); |
Source: HALKBANK_EKSTRE_20210611_080203_744623,PDF.exe, 00000000.00000002.219661677.0000000002531000.00000004.00000001.sdmp |
Binary or memory string: Select * from SecurityLogonType WHERE id=@id; |
Source: HALKBANK_EKSTRE_20210611_080203_744623,PDF.exe, 00000000.00000002.219661677.0000000002531000.00000004.00000001.sdmp |
Binary or memory string: Select * from SecurityLogonType WHERE modelo=@modelo; |
Source: HALKBANK_EKSTRE_20210611_080203_744623,PDF.exe, 00000000.00000002.219661677.0000000002531000.00000004.00000001.sdmp |
Binary or memory string: INSERT INTO Itens_Aluguel VALUES(@aluguelID, @aviaoID, @validade); |
Source: HALKBANK_EKSTRE_20210611_080203_744623,PDF.exe, 00000000.00000002.219661677.0000000002531000.00000004.00000001.sdmp |
Binary or memory string: Insert into Clientes values (@nome, @cpf, @rg, @cidade, @endereco, @uf, @telefone); |
Source: HALKBANK_EKSTRE_20210611_080203_744623,PDF.exe, 00000000.00000002.219661677.0000000002531000.00000004.00000001.sdmp |
Binary or memory string: INSERT INTO Aluguel VALUES(@clienteID, @data); |
Source: HALKBANK_EKSTRE_20210611_080203_744623,PDF.exe, 00000000.00000002.219661677.0000000002531000.00000004.00000001.sdmp |
Binary or memory string: INSERT INTO SecurityLogonType VALUES(@modelo, @fabricante, @ano, @cor); |
Source: HALKBANK_EKSTRE_20210611_080203_744623,PDF.exe, 00000000.00000002.219661677.0000000002531000.00000004.00000001.sdmp |
Binary or memory string: Select * from SecurityLogonType*Erro ao listar Banco sql-SecurityLogonType,Select * from SecurityLogonType WHERE id=@id;Select * from SecurityLogonType WHERE (modelo LIKE @modelo) |
Source: HALKBANK_EKSTRE_20210611_080203_744623,PDF.exe, vJiGl01UUJfXfNWas3/DyyVDbaRvM1YfIq9il.cs |
High entropy of concatenated method names: '.cctor', 'OvQg6h', 'creoiNvd7', 'jZiU8kt7k', 'yIEeUuogE', 'HNMMnrD0K', 'U6ZIpjiMV', 'TYIaeXNeW', 'rI3lmZ9FL', 'SuhhReBcy' |
Source: 0.2.HALKBANK_EKSTRE_20210611_080203_744623,PDF.exe.150000.0.unpack, vJiGl01UUJfXfNWas3/DyyVDbaRvM1YfIq9il.cs |
High entropy of concatenated method names: '.cctor', 'OvQg6h', 'creoiNvd7', 'jZiU8kt7k', 'yIEeUuogE', 'HNMMnrD0K', 'U6ZIpjiMV', 'TYIaeXNeW', 'rI3lmZ9FL', 'SuhhReBcy' |
Source: 2.2.HALKBANK_EKSTRE_20210611_080203_744623,PDF.exe.240000.0.unpack, vJiGl01UUJfXfNWas3/DyyVDbaRvM1YfIq9il.cs |
High entropy of concatenated method names: '.cctor', 'OvQg6h', 'creoiNvd7', 'jZiU8kt7k', 'yIEeUuogE', 'HNMMnrD0K', 'U6ZIpjiMV', 'TYIaeXNeW', 'rI3lmZ9FL', 'SuhhReBcy' |
Source: 2.0.HALKBANK_EKSTRE_20210611_080203_744623,PDF.exe.240000.0.unpack, vJiGl01UUJfXfNWas3/DyyVDbaRvM1YfIq9il.cs |
High entropy of concatenated method names: '.cctor', 'OvQg6h', 'creoiNvd7', 'jZiU8kt7k', 'yIEeUuogE', 'HNMMnrD0K', 'U6ZIpjiMV', 'TYIaeXNeW', 'rI3lmZ9FL', 'SuhhReBcy' |
Source: 3.2.HALKBANK_EKSTRE_20210611_080203_744623,PDF.exe.9d0000.1.unpack, vJiGl01UUJfXfNWas3/DyyVDbaRvM1YfIq9il.cs |
High entropy of concatenated method names: '.cctor', 'OvQg6h', 'creoiNvd7', 'jZiU8kt7k', 'yIEeUuogE', 'HNMMnrD0K', 'U6ZIpjiMV', 'TYIaeXNeW', 'rI3lmZ9FL', 'SuhhReBcy' |
Source: C:\Users\user\Desktop\HALKBANK_EKSTRE_20210611_080203_744623,PDF.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\Desktop\HALKBANK_EKSTRE_20210611_080203_744623,PDF.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\Desktop\HALKBANK_EKSTRE_20210611_080203_744623,PDF.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\Desktop\HALKBANK_EKSTRE_20210611_080203_744623,PDF.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\Desktop\HALKBANK_EKSTRE_20210611_080203_744623,PDF.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\Desktop\HALKBANK_EKSTRE_20210611_080203_744623,PDF.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\Desktop\HALKBANK_EKSTRE_20210611_080203_744623,PDF.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\Desktop\HALKBANK_EKSTRE_20210611_080203_744623,PDF.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\Desktop\HALKBANK_EKSTRE_20210611_080203_744623,PDF.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\Desktop\HALKBANK_EKSTRE_20210611_080203_744623,PDF.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\Desktop\HALKBANK_EKSTRE_20210611_080203_744623,PDF.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\Desktop\HALKBANK_EKSTRE_20210611_080203_744623,PDF.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\Desktop\HALKBANK_EKSTRE_20210611_080203_744623,PDF.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\Desktop\HALKBANK_EKSTRE_20210611_080203_744623,PDF.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\Desktop\HALKBANK_EKSTRE_20210611_080203_744623,PDF.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\Desktop\HALKBANK_EKSTRE_20210611_080203_744623,PDF.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\Desktop\HALKBANK_EKSTRE_20210611_080203_744623,PDF.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\Desktop\HALKBANK_EKSTRE_20210611_080203_744623,PDF.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\Desktop\HALKBANK_EKSTRE_20210611_080203_744623,PDF.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\Desktop\HALKBANK_EKSTRE_20210611_080203_744623,PDF.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\Desktop\HALKBANK_EKSTRE_20210611_080203_744623,PDF.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\Desktop\HALKBANK_EKSTRE_20210611_080203_744623,PDF.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\Desktop\HALKBANK_EKSTRE_20210611_080203_744623,PDF.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\Desktop\HALKBANK_EKSTRE_20210611_080203_744623,PDF.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\Desktop\HALKBANK_EKSTRE_20210611_080203_744623,PDF.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\Desktop\HALKBANK_EKSTRE_20210611_080203_744623,PDF.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\Desktop\HALKBANK_EKSTRE_20210611_080203_744623,PDF.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\Desktop\HALKBANK_EKSTRE_20210611_080203_744623,PDF.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\Desktop\HALKBANK_EKSTRE_20210611_080203_744623,PDF.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\Desktop\HALKBANK_EKSTRE_20210611_080203_744623,PDF.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\Desktop\HALKBANK_EKSTRE_20210611_080203_744623,PDF.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\Desktop\HALKBANK_EKSTRE_20210611_080203_744623,PDF.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\Desktop\HALKBANK_EKSTRE_20210611_080203_744623,PDF.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\Desktop\HALKBANK_EKSTRE_20210611_080203_744623,PDF.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\Desktop\HALKBANK_EKSTRE_20210611_080203_744623,PDF.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\Desktop\HALKBANK_EKSTRE_20210611_080203_744623,PDF.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\Desktop\HALKBANK_EKSTRE_20210611_080203_744623,PDF.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\Desktop\HALKBANK_EKSTRE_20210611_080203_744623,PDF.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\Desktop\HALKBANK_EKSTRE_20210611_080203_744623,PDF.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\Desktop\HALKBANK_EKSTRE_20210611_080203_744623,PDF.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\Desktop\HALKBANK_EKSTRE_20210611_080203_744623,PDF.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\Desktop\HALKBANK_EKSTRE_20210611_080203_744623,PDF.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\Desktop\HALKBANK_EKSTRE_20210611_080203_744623,PDF.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\Desktop\HALKBANK_EKSTRE_20210611_080203_744623,PDF.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\Desktop\HALKBANK_EKSTRE_20210611_080203_744623,PDF.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\Desktop\HALKBANK_EKSTRE_20210611_080203_744623,PDF.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\Desktop\HALKBANK_EKSTRE_20210611_080203_744623,PDF.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\Desktop\HALKBANK_EKSTRE_20210611_080203_744623,PDF.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\Desktop\HALKBANK_EKSTRE_20210611_080203_744623,PDF.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\Desktop\HALKBANK_EKSTRE_20210611_080203_744623,PDF.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\Desktop\HALKBANK_EKSTRE_20210611_080203_744623,PDF.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\Desktop\HALKBANK_EKSTRE_20210611_080203_744623,PDF.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\Desktop\HALKBANK_EKSTRE_20210611_080203_744623,PDF.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\Desktop\HALKBANK_EKSTRE_20210611_080203_744623,PDF.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\Desktop\HALKBANK_EKSTRE_20210611_080203_744623,PDF.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\Desktop\HALKBANK_EKSTRE_20210611_080203_744623,PDF.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\Desktop\HALKBANK_EKSTRE_20210611_080203_744623,PDF.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\Desktop\HALKBANK_EKSTRE_20210611_080203_744623,PDF.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\Desktop\HALKBANK_EKSTRE_20210611_080203_744623,PDF.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\Desktop\HALKBANK_EKSTRE_20210611_080203_744623,PDF.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\Desktop\HALKBANK_EKSTRE_20210611_080203_744623,PDF.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\Desktop\HALKBANK_EKSTRE_20210611_080203_744623,PDF.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\Desktop\HALKBANK_EKSTRE_20210611_080203_744623,PDF.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\Desktop\HALKBANK_EKSTRE_20210611_080203_744623,PDF.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\Desktop\HALKBANK_EKSTRE_20210611_080203_744623,PDF.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\Desktop\HALKBANK_EKSTRE_20210611_080203_744623,PDF.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\Desktop\HALKBANK_EKSTRE_20210611_080203_744623,PDF.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\Desktop\HALKBANK_EKSTRE_20210611_080203_744623,PDF.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\Desktop\HALKBANK_EKSTRE_20210611_080203_744623,PDF.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\Desktop\HALKBANK_EKSTRE_20210611_080203_744623,PDF.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\Desktop\HALKBANK_EKSTRE_20210611_080203_744623,PDF.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\Desktop\HALKBANK_EKSTRE_20210611_080203_744623,PDF.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\Desktop\HALKBANK_EKSTRE_20210611_080203_744623,PDF.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\Desktop\HALKBANK_EKSTRE_20210611_080203_744623,PDF.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\Desktop\HALKBANK_EKSTRE_20210611_080203_744623,PDF.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\Desktop\HALKBANK_EKSTRE_20210611_080203_744623,PDF.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\Desktop\HALKBANK_EKSTRE_20210611_080203_744623,PDF.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\Desktop\HALKBANK_EKSTRE_20210611_080203_744623,PDF.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\Desktop\HALKBANK_EKSTRE_20210611_080203_744623,PDF.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\Desktop\HALKBANK_EKSTRE_20210611_080203_744623,PDF.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\Desktop\HALKBANK_EKSTRE_20210611_080203_744623,PDF.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\Desktop\HALKBANK_EKSTRE_20210611_080203_744623,PDF.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\Desktop\HALKBANK_EKSTRE_20210611_080203_744623,PDF.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\Desktop\HALKBANK_EKSTRE_20210611_080203_744623,PDF.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\Desktop\HALKBANK_EKSTRE_20210611_080203_744623,PDF.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\Desktop\HALKBANK_EKSTRE_20210611_080203_744623,PDF.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\Desktop\HALKBANK_EKSTRE_20210611_080203_744623,PDF.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: HALKBANK_EKSTRE_20210611_080203_744623,PDF.exe |
Binary or memory string: QEMUP |
Source: HALKBANK_EKSTRE_20210611_080203_744623,PDF.exe, 00000000.00000002.219661677.0000000002531000.00000004.00000001.sdmp |
Binary or memory string: vmware |
Source: HALKBANK_EKSTRE_20210611_080203_744623,PDF.exe, 00000000.00000002.219661677.0000000002531000.00000004.00000001.sdmp |
Binary or memory string: C:\PROGRAM FILES\VMWARE\VMWARE TOOLS\ |
Source: HALKBANK_EKSTRE_20210611_080203_744623,PDF.exe, 00000000.00000002.219661677.0000000002531000.00000004.00000001.sdmp |
Binary or memory string: SOFTWARE\VMware, Inc.\VMware Tools |
Source: HALKBANK_EKSTRE_20210611_080203_744623,PDF.exe, 00000000.00000002.219661677.0000000002531000.00000004.00000001.sdmp |
Binary or memory string: VMware SVGA II!Add-MpPreference -ExclusionPath " |
Source: HALKBANK_EKSTRE_20210611_080203_744623,PDF.exe, 00000000.00000002.219661677.0000000002531000.00000004.00000001.sdmp |
Binary or memory string: VMWARE |
Source: HALKBANK_EKSTRE_20210611_080203_744623,PDF.exe, 00000000.00000002.219661677.0000000002531000.00000004.00000001.sdmp |
Binary or memory string: InstallPath%C:\PROGRAM FILES\VMWARE\VMWARE TOOLS\ |
Source: HALKBANK_EKSTRE_20210611_080203_744623,PDF.exe, 00000000.00000002.219661677.0000000002531000.00000004.00000001.sdmp |
Binary or memory string: VMWARE"SOFTWARE\VMware, Inc.\VMware ToolsLHARDWARE\DEVICEMAP\Scsi\Scsi Port 1\Scsi Bus 0\Target Id 0\Logical Unit Id 0LHARDWARE\DEVICEMAP\Scsi\Scsi Port 2\Scsi Bus 0\Target Id 0\Logical Unit Id 0'SYSTEM\ControlSet001\Services\Disk\Enum |
Source: HALKBANK_EKSTRE_20210611_080203_744623,PDF.exe, 00000000.00000002.219661677.0000000002531000.00000004.00000001.sdmp |
Binary or memory string: VMware SVGA II |
Source: HALKBANK_EKSTRE_20210611_080203_744623,PDF.exe, 00000000.00000002.219661677.0000000002531000.00000004.00000001.sdmp |
Binary or memory string: vmwareNSYSTEM\ControlSet001\Control\Class\{4D36E968-E325-11CE-BFC1-08002BE10318}\0000 |
Source: HALKBANK_EKSTRE_20210611_080203_744623,PDF.exe, 00000003.00000002.479214809.0000000001110000.00000004.00000020.sdmp |
Binary or memory string: Hyper-V RAW%SystemRoot%\system32\mswsock.dll |
Source: C:\Users\user\Desktop\HALKBANK_EKSTRE_20210611_080203_744623,PDF.exe |
Queries volume information: C:\Users\user\Desktop\HALKBANK_EKSTRE_20210611_080203_744623,PDF.exe VolumeInformation |
Jump to behavior |
Source: C:\Users\user\Desktop\HALKBANK_EKSTRE_20210611_080203_744623,PDF.exe |
Queries volume information: C:\Windows\Microsoft.NET\assembly\GAC_MSIL\Microsoft.VisualBasic\v4.0_10.0.0.0__b03f5f7f11d50a3a\Microsoft.VisualBasic.dll VolumeInformation |
Jump to behavior |
Source: C:\Users\user\Desktop\HALKBANK_EKSTRE_20210611_080203_744623,PDF.exe |
Queries volume information: C:\Windows\Microsoft.NET\assembly\GAC_MSIL\System.Windows.Forms\v4.0_4.0.0.0__b77a5c561934e089\System.Windows.Forms.dll VolumeInformation |
Jump to behavior |
Source: C:\Users\user\Desktop\HALKBANK_EKSTRE_20210611_080203_744623,PDF.exe |
Queries volume information: C:\Windows\Microsoft.NET\assembly\GAC_MSIL\System.Drawing\v4.0_4.0.0.0__b03f5f7f11d50a3a\System.Drawing.dll VolumeInformation |
Jump to behavior |
Source: C:\Users\user\Desktop\HALKBANK_EKSTRE_20210611_080203_744623,PDF.exe |
Queries volume information: C:\Windows\Microsoft.NET\assembly\GAC_MSIL\Accessibility\v4.0_4.0.0.0__b03f5f7f11d50a3a\Accessibility.dll VolumeInformation |
Jump to behavior |
Source: C:\Users\user\Desktop\HALKBANK_EKSTRE_20210611_080203_744623,PDF.exe |
Queries volume information: C:\Windows\Microsoft.NET\assembly\GAC_MSIL\System.Runtime.Remoting\v4.0_4.0.0.0__b77a5c561934e089\System.Runtime.Remoting.dll VolumeInformation |
Jump to behavior |
Source: C:\Users\user\Desktop\HALKBANK_EKSTRE_20210611_080203_744623,PDF.exe |
Queries volume information: C:\Users\user\Desktop\HALKBANK_EKSTRE_20210611_080203_744623,PDF.exe VolumeInformation |
Jump to behavior |
Source: C:\Users\user\Desktop\HALKBANK_EKSTRE_20210611_080203_744623,PDF.exe |
Queries volume information: C:\Windows\Microsoft.NET\assembly\GAC_MSIL\System.Windows.Forms\v4.0_4.0.0.0__b77a5c561934e089\System.Windows.Forms.dll VolumeInformation |
Jump to behavior |
Source: C:\Users\user\Desktop\HALKBANK_EKSTRE_20210611_080203_744623,PDF.exe |
Queries volume information: C:\Windows\Microsoft.NET\assembly\GAC_MSIL\Microsoft.VisualBasic\v4.0_10.0.0.0__b03f5f7f11d50a3a\Microsoft.VisualBasic.dll VolumeInformation |
Jump to behavior |
Source: C:\Users\user\Desktop\HALKBANK_EKSTRE_20210611_080203_744623,PDF.exe |
Queries volume information: C:\Windows\Microsoft.NET\assembly\GAC_32\CustomMarshalers\v4.0_4.0.0.0__b03f5f7f11d50a3a\CustomMarshalers.dll VolumeInformation |
Jump to behavior |
Source: C:\Users\user\Desktop\HALKBANK_EKSTRE_20210611_080203_744623,PDF.exe |
Queries volume information: C:\Windows\Microsoft.NET\assembly\GAC_32\CustomMarshalers\v4.0_4.0.0.0__b03f5f7f11d50a3a\CustomMarshalers.dll VolumeInformation |
Jump to behavior |
Source: C:\Users\user\Desktop\HALKBANK_EKSTRE_20210611_080203_744623,PDF.exe |
Queries volume information: C:\Windows\Microsoft.NET\assembly\GAC_32\CustomMarshalers\v4.0_4.0.0.0__b03f5f7f11d50a3a\CustomMarshalers.dll VolumeInformation |
Jump to behavior |
Source: C:\Users\user\Desktop\HALKBANK_EKSTRE_20210611_080203_744623,PDF.exe |
Queries volume information: C:\Windows\Microsoft.NET\assembly\GAC_MSIL\System.Management\v4.0_4.0.0.0__b03f5f7f11d50a3a\System.Management.dll VolumeInformation |
Jump to behavior |
Source: C:\Users\user\Desktop\HALKBANK_EKSTRE_20210611_080203_744623,PDF.exe |
Queries volume information: C:\Windows\Microsoft.NET\assembly\GAC_MSIL\System.Drawing\v4.0_4.0.0.0__b03f5f7f11d50a3a\System.Drawing.dll VolumeInformation |
Jump to behavior |
Source: C:\Users\user\Desktop\HALKBANK_EKSTRE_20210611_080203_744623,PDF.exe |
Queries volume information: C:\Windows\Microsoft.NET\assembly\GAC_MSIL\Accessibility\v4.0_4.0.0.0__b03f5f7f11d50a3a\Accessibility.dll VolumeInformation |
Jump to behavior |