Loading ...

Play interactive tourEdit tour

Analysis Report eCooEFZfZJ.exe

Overview

General Information

Sample Name:eCooEFZfZJ.exe
Analysis ID:433075
MD5:2db978e7cd2512c358518b1981fee079
SHA1:22736d8d3ffe0e79cfdc0c08187bdae652d3a23c
SHA256:9ec05fd611c2df63c12cc15df8e87e411f358b7a6747a44d4a320c01e3367ca8
Tags:exeGuLoader
Infos:

Most interesting Screenshot:

Detection

GuLoader
Score:88
Range:0 - 100
Whitelisted:false
Confidence:100%

Signatures

Found malware configuration
Multi AV Scanner detection for submitted file
Potential malicious icon found
Yara detected GuLoader
C2 URLs / IPs found in malware configuration
Contains functionality to detect hardware virtualization (CPUID execution measurement)
Found potential dummy code loops (likely to delay analysis)
Tries to detect virtualization through RDTSC time measurements
Abnormal high CPU Usage
Contains functionality for execution timing, often used to detect debuggers
Contains functionality to call native functions
Contains functionality to read the PEB
Detected potential crypto function
PE file contains strange resources
Program does not show much activity (idle)
Sample file is different than original file name gathered from version info
Uses 32bit PE files
Uses code obfuscation techniques (call, push, ret)

Classification

Process Tree

  • System is w10x64
  • eCooEFZfZJ.exe (PID: 5600 cmdline: 'C:\Users\user\Desktop\eCooEFZfZJ.exe' MD5: 2DB978E7CD2512C358518B1981FEE079)
  • cleanup

Malware Configuration

Threatname: GuLoader

{"Payload URL": "https://bara-seck.com/bin_sLFaSDyCig163.bin, http://benvenuti.rs/wp-content/bin_s"}

Yara Overview

Memory Dumps

SourceRuleDescriptionAuthorStrings
00000000.00000002.755211123.00000000021B0000.00000040.00000001.sdmpJoeSecurity_GuLoader_2Yara detected GuLoaderJoe Security

    Sigma Overview

    No Sigma rule has matched

    Signature Overview

    Click to jump to signature section

    Show All Signature Results

    AV Detection:

    barindex
    Found malware configurationShow sources
    Source: 00000000.00000002.755211123.00000000021B0000.00000040.00000001.sdmpMalware Configuration Extractor: GuLoader {"Payload URL": "https://bara-seck.com/bin_sLFaSDyCig163.bin, http://benvenuti.rs/wp-content/bin_s"}
    Multi AV Scanner detection for submitted fileShow sources
    Source: eCooEFZfZJ.exeVirustotal: Detection: 15%Perma Link
    Source: eCooEFZfZJ.exeStatic PE information: LOCAL_SYMS_STRIPPED, 32BIT_MACHINE, EXECUTABLE_IMAGE, LINE_NUMS_STRIPPED, RELOCS_STRIPPED

    Networking:

    barindex
    C2 URLs / IPs found in malware configurationShow sources
    Source: Malware configuration extractorURLs: https://bara-seck.com/bin_sLFaSDyCig163.bin, http://benvenuti.rs/wp-content/bin_s

    System Summary:

    barindex
    Potential malicious icon foundShow sources
    Source: initial sampleIcon embedded in PE file: bad icon match: 20047c7c70f0e004
    Source: C:\Users\user\Desktop\eCooEFZfZJ.exeProcess Stats: CPU usage > 98%
    Source: C:\Users\user\Desktop\eCooEFZfZJ.exeCode function: 0_2_021B6C42 NtAllocateVirtualMemory,0_2_021B6C42
    Source: C:\Users\user\Desktop\eCooEFZfZJ.exeCode function: 0_2_021B6E1D NtAllocateVirtualMemory,0_2_021B6E1D
    Source: C:\Users\user\Desktop\eCooEFZfZJ.exeCode function: 0_2_021B6E0A NtAllocateVirtualMemory,0_2_021B6E0A
    Source: C:\Users\user\Desktop\eCooEFZfZJ.exeCode function: 0_2_021B6E35 NtAllocateVirtualMemory,0_2_021B6E35
    Source: C:\Users\user\Desktop\eCooEFZfZJ.exeCode function: 0_2_021B6E29 NtAllocateVirtualMemory,0_2_021B6E29
    Source: C:\Users\user\Desktop\eCooEFZfZJ.exeCode function: 0_2_021B6E2D NtAllocateVirtualMemory,0_2_021B6E2D
    Source: C:\Users\user\Desktop\eCooEFZfZJ.exeCode function: 0_2_021B6E21 NtAllocateVirtualMemory,0_2_021B6E21
    Source: C:\Users\user\Desktop\eCooEFZfZJ.exeCode function: 0_2_021B6E41 NtAllocateVirtualMemory,0_2_021B6E41
    Source: C:\Users\user\Desktop\eCooEFZfZJ.exeCode function: 0_2_021B6E7D NtAllocateVirtualMemory,0_2_021B6E7D
    Source: C:\Users\user\Desktop\eCooEFZfZJ.exeCode function: 0_2_021B6E75 NtAllocateVirtualMemory,0_2_021B6E75
    Source: C:\Users\user\Desktop\eCooEFZfZJ.exeCode function: 0_2_021B6E99 NtAllocateVirtualMemory,0_2_021B6E99
    Source: C:\Users\user\Desktop\eCooEFZfZJ.exeCode function: 0_2_021B6E95 NtAllocateVirtualMemory,0_2_021B6E95
    Source: C:\Users\user\Desktop\eCooEFZfZJ.exeCode function: 0_2_021B6E81 NtAllocateVirtualMemory,0_2_021B6E81
    Source: C:\Users\user\Desktop\eCooEFZfZJ.exeCode function: 0_2_021B6EA1 NtAllocateVirtualMemory,0_2_021B6EA1
    Source: C:\Users\user\Desktop\eCooEFZfZJ.exeCode function: 0_2_021B6EA5 NtAllocateVirtualMemory,0_2_021B6EA5
    Source: C:\Users\user\Desktop\eCooEFZfZJ.exeCode function: 0_2_021B6F19 NtAllocateVirtualMemory,0_2_021B6F19
    Source: C:\Users\user\Desktop\eCooEFZfZJ.exeCode function: 0_2_021B6F1D NtAllocateVirtualMemory,0_2_021B6F1D
    Source: C:\Users\user\Desktop\eCooEFZfZJ.exeCode function: 0_2_021B6F11 NtAllocateVirtualMemory,0_2_021B6F11
    Source: C:\Users\user\Desktop\eCooEFZfZJ.exeCode function: 0_2_021B6F0D NtAllocateVirtualMemory,0_2_021B6F0D
    Source: C:\Users\user\Desktop\eCooEFZfZJ.exeCode function: 0_2_021B6F31 NtAllocateVirtualMemory,0_2_021B6F31
    Source: C:\Users\user\Desktop\eCooEFZfZJ.exeCode function: 0_2_021B6F29 NtAllocateVirtualMemory,0_2_021B6F29
    Source: C:\Users\user\Desktop\eCooEFZfZJ.exeCode function: 0_2_021B6F25 NtAllocateVirtualMemory,0_2_021B6F25
    Source: C:\Users\user\Desktop\eCooEFZfZJ.exeCode function: 0_2_021B6F7F NtAllocateVirtualMemory,0_2_021B6F7F
    Source: C:\Users\user\Desktop\eCooEFZfZJ.exeCode function: 0_2_021B6F99 NtAllocateVirtualMemory,0_2_021B6F99
    Source: C:\Users\user\Desktop\eCooEFZfZJ.exeCode function: 0_2_021B6F9D NtAllocateVirtualMemory,0_2_021B6F9D
    Source: C:\Users\user\Desktop\eCooEFZfZJ.exeCode function: 0_2_021B6F91 NtAllocateVirtualMemory,0_2_021B6F91
    Source: C:\Users\user\Desktop\eCooEFZfZJ.exeCode function: 0_2_021B6F8D NtAllocateVirtualMemory,0_2_021B6F8D
    Source: C:\Users\user\Desktop\eCooEFZfZJ.exeCode function: 0_2_021B6F85 NtAllocateVirtualMemory,0_2_021B6F85
    Source: C:\Users\user\Desktop\eCooEFZfZJ.exeCode function: 0_2_021B6FB1 NtAllocateVirtualMemory,0_2_021B6FB1
    Source: C:\Users\user\Desktop\eCooEFZfZJ.exeCode function: 0_2_021B6FB5 NtAllocateVirtualMemory,0_2_021B6FB5
    Source: C:\Users\user\Desktop\eCooEFZfZJ.exeCode function: 0_2_021B6FA9 NtAllocateVirtualMemory,0_2_021B6FA9
    Source: C:\Users\user\Desktop\eCooEFZfZJ.exeCode function: 0_2_021B6FA5 NtAllocateVirtualMemory,0_2_021B6FA5
    Source: C:\Users\user\Desktop\eCooEFZfZJ.exeCode function: 0_2_021B6C49 NtAllocateVirtualMemory,0_2_021B6C49
    Source: C:\Users\user\Desktop\eCooEFZfZJ.exeCode function: 0_2_021B6C77 NtAllocateVirtualMemory,0_2_021B6C77
    Source: C:\Users\user\Desktop\eCooEFZfZJ.exeCode function: 0_2_021B6CBA NtAllocateVirtualMemory,0_2_021B6CBA
    Source: C:\Users\user\Desktop\eCooEFZfZJ.exeCode function: 0_2_004063AF0_2_004063AF
    Source: C:\Users\user\Desktop\eCooEFZfZJ.exeCode function: 0_2_021B6C420_2_021B6C42
    Source: C:\Users\user\Desktop\eCooEFZfZJ.exeCode function: 0_2_021B52110_2_021B5211
    Source: C:\Users\user\Desktop\eCooEFZfZJ.exeCode function: 0_2_021B52150_2_021B5215
    Source: C:\Users\user\Desktop\eCooEFZfZJ.exeCode function: 0_2_021B12090_2_021B1209
    Source: C:\Users\user\Desktop\eCooEFZfZJ.exeCode function: 0_2_021B520D0_2_021B520D
    Source: C:\Users\user\Desktop\eCooEFZfZJ.exeCode function: 0_2_021B120D0_2_021B120D
    Source: C:\Users\user\Desktop\eCooEFZfZJ.exeCode function: 0_2_021B12010_2_021B1201
    Source: C:\Users\user\Desktop\eCooEFZfZJ.exeCode function: 0_2_021B52390_2_021B5239
    Source: C:\Users\user\Desktop\eCooEFZfZJ.exeCode function: 0_2_021B522D0_2_021B522D
    Source: C:\Users\user\Desktop\eCooEFZfZJ.exeCode function: 0_2_021B52210_2_021B5221
    Source: C:\Users\user\Desktop\eCooEFZfZJ.exeCode function: 0_2_021B12250_2_021B1225
    Source: C:\Users\user\Desktop\eCooEFZfZJ.exeCode function: 0_2_021B12790_2_021B1279
    Source: C:\Users\user\Desktop\eCooEFZfZJ.exeCode function: 0_2_021B527D0_2_021B527D
    Source: C:\Users\user\Desktop\eCooEFZfZJ.exeCode function: 0_2_021B52730_2_021B5273
    Source: C:\Users\user\Desktop\eCooEFZfZJ.exeCode function: 0_2_021B52750_2_021B5275
    Source: C:\Users\user\Desktop\eCooEFZfZJ.exeCode function: 0_2_021B52990_2_021B5299
    Source: C:\Users\user\Desktop\eCooEFZfZJ.exeCode function: 0_2_021B52950_2_021B5295
    Source: C:\Users\user\Desktop\eCooEFZfZJ.exeCode function: 0_2_021B52890_2_021B5289
    Source: C:\Users\user\Desktop\eCooEFZfZJ.exeCode function: 0_2_021B528D0_2_021B528D
    Source: C:\Users\user\Desktop\eCooEFZfZJ.exeCode function: 0_2_021B52810_2_021B5281
    Source: C:\Users\user\Desktop\eCooEFZfZJ.exeCode function: 0_2_021B12810_2_021B1281
    Source: C:\Users\user\Desktop\eCooEFZfZJ.exeCode function: 0_2_021B12850_2_021B1285
    Source: C:\Users\user\Desktop\eCooEFZfZJ.exeCode function: 0_2_021B52B10_2_021B52B1
    Source: C:\Users\user\Desktop\eCooEFZfZJ.exeCode function: 0_2_021B12A90_2_021B12A9
    Source: C:\Users\user\Desktop\eCooEFZfZJ.exeCode function: 0_2_021B52AD0_2_021B52AD
    Source: C:\Users\user\Desktop\eCooEFZfZJ.exeCode function: 0_2_021B52A10_2_021B52A1
    Source: C:\Users\user\Desktop\eCooEFZfZJ.exeCode function: 0_2_021B12A50_2_021B12A5
    Source: C:\Users\user\Desktop\eCooEFZfZJ.exeCode function: 0_2_021B52A50_2_021B52A5
    Source: C:\Users\user\Desktop\eCooEFZfZJ.exeCode function: 0_2_021B12F90_2_021B12F9
    Source: C:\Users\user\Desktop\eCooEFZfZJ.exeCode function: 0_2_021B52FD0_2_021B52FD
    Source: C:\Users\user\Desktop\eCooEFZfZJ.exeCode function: 0_2_021B12F50_2_021B12F5
    Source: C:\Users\user\Desktop\eCooEFZfZJ.exeCode function: 0_2_021B12ED0_2_021B12ED
    Source: C:\Users\user\Desktop\eCooEFZfZJ.exeCode function: 0_2_021B131D0_2_021B131D
    Source: C:\Users\user\Desktop\eCooEFZfZJ.exeCode function: 0_2_021B53150_2_021B5315
    Source: C:\Users\user\Desktop\eCooEFZfZJ.exeCode function: 0_2_021B53090_2_021B5309
    Source: C:\Users\user\Desktop\eCooEFZfZJ.exeCode function: 0_2_021B532D0_2_021B532D
    Source: C:\Users\user\Desktop\eCooEFZfZJ.exeCode function: 0_2_021B53210_2_021B5321
    Source: C:\Users\user\Desktop\eCooEFZfZJ.exeCode function: 0_2_021B13250_2_021B1325
    Source: C:\Users\user\Desktop\eCooEFZfZJ.exeCode function: 0_2_021B43790_2_021B4379
    Source: C:\Users\user\Desktop\eCooEFZfZJ.exeCode function: 0_2_021B43750_2_021B4375
    Source: C:\Users\user\Desktop\eCooEFZfZJ.exeCode function: 0_2_021B13680_2_021B1368
    Source: C:\Users\user\Desktop\eCooEFZfZJ.exeCode function: 0_2_021B136D0_2_021B136D
    Source: C:\Users\user\Desktop\eCooEFZfZJ.exeCode function: 0_2_021B13990_2_021B1399
    Source: C:\Users\user\Desktop\eCooEFZfZJ.exeCode function: 0_2_021B139D0_2_021B139D
    Source: C:\Users\user\Desktop\eCooEFZfZJ.exeCode function: 0_2_021B33880_2_021B3388
    Source: C:\Users\user\Desktop\eCooEFZfZJ.exeCode function: 0_2_021B33B90_2_021B33B9
    Source: C:\Users\user\Desktop\eCooEFZfZJ.exeCode function: 0_2_021B33BD0_2_021B33BD
    Source: C:\Users\user\Desktop\eCooEFZfZJ.exeCode function: 0_2_021B53BD0_2_021B53BD
    Source: C:\Users\user\Desktop\eCooEFZfZJ.exeCode function: 0_2_021B33B10_2_021B33B1
    Source: C:\Users\user\Desktop\eCooEFZfZJ.exeCode function: 0_2_021B53B50_2_021B53B5
    Source: C:\Users\user\Desktop\eCooEFZfZJ.exeCode function: 0_2_021B33AE0_2_021B33AE
    Source: C:\Users\user\Desktop\eCooEFZfZJ.exeCode function: 0_2_021B73D90_2_021B73D9
    Source: C:\Users\user\Desktop\eCooEFZfZJ.exeCode function: 0_2_021B53DE0_2_021B53DE
    Source: C:\Users\user\Desktop\eCooEFZfZJ.exeCode function: 0_2_021B73D20_2_021B73D2
    Source: C:\Users\user\Desktop\eCooEFZfZJ.exeCode function: 0_2_021B33D50_2_021B33D5
    Source: C:\Users\user\Desktop\eCooEFZfZJ.exeCode function: 0_2_021B33C90_2_021B33C9
    Source: C:\Users\user\Desktop\eCooEFZfZJ.exeCode function: 0_2_021B53C90_2_021B53C9
    Source: C:\Users\user\Desktop\eCooEFZfZJ.exeCode function: 0_2_021B73C80_2_021B73C8
    Source: C:\Users\user\Desktop\eCooEFZfZJ.exeCode function: 0_2_021B53CD0_2_021B53CD
    Source: C:\Users\user\Desktop\eCooEFZfZJ.exeCode function: 0_2_021B33C50_2_021B33C5
    Source: C:\Users\user\Desktop\eCooEFZfZJ.exeCode function: 0_2_021B73F10_2_021B73F1
    Source: C:\Users\user\Desktop\eCooEFZfZJ.exeCode function: 0_2_021B73ED0_2_021B73ED
    Source: C:\Users\user\Desktop\eCooEFZfZJ.exeCode function: 0_2_021B73E10_2_021B73E1
    Source: C:\Users\user\Desktop\eCooEFZfZJ.exeCode function: 0_2_021B73E50_2_021B73E5
    Source: C:\Users\user\Desktop\eCooEFZfZJ.exeCode function: 0_2_021B105D0_2_021B105D
    Source: C:\Users\user\Desktop\eCooEFZfZJ.exeCode function: 0_2_021B10690_2_021B1069
    Source: C:\Users\user\Desktop\eCooEFZfZJ.exeCode function: 0_2_021B50690_2_021B5069
    Source: C:\Users\user\Desktop\eCooEFZfZJ.exeCode function: 0_2_021B506D0_2_021B506D
    Source: C:\Users\user\Desktop\eCooEFZfZJ.exeCode function: 0_2_021B10650_2_021B1065
    Source: C:\Users\user\Desktop\eCooEFZfZJ.exeCode function: 0_2_021B50990_2_021B5099
    Source: C:\Users\user\Desktop\eCooEFZfZJ.exeCode function: 0_2_021B10990_2_021B1099
    Source: C:\Users\user\Desktop\eCooEFZfZJ.exeCode function: 0_2_021B509D0_2_021B509D
    Source: C:\Users\user\Desktop\eCooEFZfZJ.exeCode function: 0_2_021B50910_2_021B5091
    Source: C:\Users\user\Desktop\eCooEFZfZJ.exeCode function: 0_2_021B10950_2_021B1095
    Source: C:\Users\user\Desktop\eCooEFZfZJ.exeCode function: 0_2_021B10890_2_021B1089
    Source: C:\Users\user\Desktop\eCooEFZfZJ.exeCode function: 0_2_021B508D0_2_021B508D
    Source: C:\Users\user\Desktop\eCooEFZfZJ.exeCode function: 0_2_021B108D0_2_021B108D
    Source: C:\Users\user\Desktop\eCooEFZfZJ.exeCode function: 0_2_021B50B10_2_021B50B1
    Source: C:\Users\user\Desktop\eCooEFZfZJ.exeCode function: 0_2_021B50A90_2_021B50A9
    Source: C:\Users\user\Desktop\eCooEFZfZJ.exeCode function: 0_2_021B50A50_2_021B50A5
    Source: C:\Users\user\Desktop\eCooEFZfZJ.exeCode function: 0_2_021B10C50_2_021B10C5
    Source: C:\Users\user\Desktop\eCooEFZfZJ.exeCode function: 0_2_021B50F90_2_021B50F9
    Source: C:\Users\user\Desktop\eCooEFZfZJ.exeCode function: 0_2_021B50FD0_2_021B50FD
    Source: C:\Users\user\Desktop\eCooEFZfZJ.exeCode function: 0_2_021B50E00_2_021B50E0
    Source: C:\Users\user\Desktop\eCooEFZfZJ.exeCode function: 0_2_021B51190_2_021B5119
    Source: C:\Users\user\Desktop\eCooEFZfZJ.exeCode function: 0_2_021B510D0_2_021B510D
    Source: C:\Users\user\Desktop\eCooEFZfZJ.exeCode function: 0_2_021B51010_2_021B5101
    Source: C:\Users\user\Desktop\eCooEFZfZJ.exeCode function: 0_2_021B113D0_2_021B113D
    Source: C:\Users\user\Desktop\eCooEFZfZJ.exeCode function: 0_2_021B11360_2_021B1136
    Source: C:\Users\user\Desktop\eCooEFZfZJ.exeCode function: 0_2_021B115D0_2_021B115D
    Source: C:\Users\user\Desktop\eCooEFZfZJ.exeCode function: 0_2_021B11510_2_021B1151
    Source: C:\Users\user\Desktop\eCooEFZfZJ.exeCode function: 0_2_021B11550_2_021B1155
    Source: C:\Users\user\Desktop\eCooEFZfZJ.exeCode function: 0_2_021B11490_2_021B1149
    Source: C:\Users\user\Desktop\eCooEFZfZJ.exeCode function: 0_2_021B11450_2_021B1145
    Source: C:\Users\user\Desktop\eCooEFZfZJ.exeCode function: 0_2_021B11690_2_021B1169
    Source: C:\Users\user\Desktop\eCooEFZfZJ.exeCode function: 0_2_021B116D0_2_021B116D
    Source: C:\Users\user\Desktop\eCooEFZfZJ.exeCode function: 0_2_021B11990_2_021B1199
    Source: C:\Users\user\Desktop\eCooEFZfZJ.exeCode function: 0_2_021B11950_2_021B1195
    Source: C:\Users\user\Desktop\eCooEFZfZJ.exeCode function: 0_2_021B11880_2_021B1188
    Source: C:\Users\user\Desktop\eCooEFZfZJ.exeCode function: 0_2_021B118D0_2_021B118D
    Source: C:\Users\user\Desktop\eCooEFZfZJ.exeCode function: 0_2_021B51B90_2_021B51B9
    Source: C:\Users\user\Desktop\eCooEFZfZJ.exeCode function: 0_2_021B11B90_2_021B11B9
    Source: C:\Users\user\Desktop\eCooEFZfZJ.exeCode function: 0_2_021B11BD0_2_021B11BD
    Source: C:\Users\user\Desktop\eCooEFZfZJ.exeCode function: 0_2_021B51BD0_2_021B51BD
    Source: C:\Users\user\Desktop\eCooEFZfZJ.exeCode function: 0_2_021B11B10_2_021B11B1
    Source: C:\Users\user\Desktop\eCooEFZfZJ.exeCode function: 0_2_021B51B10_2_021B51B1
    Source: C:\Users\user\Desktop\eCooEFZfZJ.exeCode function: 0_2_021B51AD0_2_021B51AD
    Source: C:\Users\user\Desktop\eCooEFZfZJ.exeCode function: 0_2_021B11AD0_2_021B11AD
    Source: C:\Users\user\Desktop\eCooEFZfZJ.exeCode function: 0_2_021B51A20_2_021B51A2
    Source: C:\Users\user\Desktop\eCooEFZfZJ.exeCode function: 0_2_021B51A50_2_021B51A5
    Source: C:\Users\user\Desktop\eCooEFZfZJ.exeCode function: 0_2_021B51D10_2_021B51D1
    Source: C:\Users\user\Desktop\eCooEFZfZJ.exeCode function: 0_2_021B51C90_2_021B51C9
    Source: C:\Users\user\Desktop\eCooEFZfZJ.exeCode function: 0_2_021B51C50_2_021B51C5
    Source: C:\Users\user\Desktop\eCooEFZfZJ.exeCode function: 0_2_021B11FD0_2_021B11FD
    Source: C:\Users\user\Desktop\eCooEFZfZJ.exeCode function: 0_2_021B11F10_2_021B11F1
    Source: C:\Users\user\Desktop\eCooEFZfZJ.exeCode function: 0_2_021B11F50_2_021B11F5
    Source: C:\Users\user\Desktop\eCooEFZfZJ.exeCode function: 0_2_021B11EF0_2_021B11EF
    Source: C:\Users\user\Desktop\eCooEFZfZJ.exeCode function: 0_2_021B761D0_2_021B761D
    Source: C:\Users\user\Desktop\eCooEFZfZJ.exeCode function: 0_2_021B56110_2_021B5611
    Source: C:\Users\user\Desktop\eCooEFZfZJ.exeCode function: 0_2_021B76160_2_021B7616
    Source: C:\Users\user\Desktop\eCooEFZfZJ.exeCode function: 0_2_021B760D0_2_021B760D
    Source: C:\Users\user\Desktop\eCooEFZfZJ.exeCode function: 0_2_021B46010_2_021B4601
    Source: C:\Users\user\Desktop\eCooEFZfZJ.exeCode function: 0_2_021B76010_2_021B7601
    Source: C:\Users\user\Desktop\eCooEFZfZJ.exeCode function: 0_2_021B56050_2_021B5605
    Source: C:\Users\user\Desktop\eCooEFZfZJ.exeCode function: 0_2_021B76050_2_021B7605
    Source: C:\Users\user\Desktop\eCooEFZfZJ.exeCode function: 0_2_021B76290_2_021B7629
    Source: C:\Users\user\Desktop\eCooEFZfZJ.exeCode function: 0_2_021B56250_2_021B5625
    Source: C:\Users\user\Desktop\eCooEFZfZJ.exeCode function: 0_2_021B36590_2_021B3659
    Source: C:\Users\user\Desktop\eCooEFZfZJ.exeCode function: 0_2_021B46510_2_021B4651
    Source: C:\Users\user\Desktop\eCooEFZfZJ.exeCode function: 0_2_021B76510_2_021B7651
    Source: C:\Users\user\Desktop\eCooEFZfZJ.exeCode function: 0_2_021B364D0_2_021B364D
    Source: C:\Users\user\Desktop\eCooEFZfZJ.exeCode function: 0_2_021B46450_2_021B4645
    Source: C:\Users\user\Desktop\eCooEFZfZJ.exeCode function: 0_2_021B06790_2_021B0679
    Source: C:\Users\user\Desktop\eCooEFZfZJ.exeCode function: 0_2_021B56790_2_021B5679
    Source: C:\Users\user\Desktop\eCooEFZfZJ.exeCode function: 0_2_021B567D0_2_021B567D
    Source: C:\Users\user\Desktop\eCooEFZfZJ.exeCode function: 0_2_021B56710_2_021B5671
    Source: C:\Users\user\Desktop\eCooEFZfZJ.exeCode function: 0_2_021B06750_2_021B0675
    Source: C:\Users\user\Desktop\eCooEFZfZJ.exeCode function: 0_2_021B76750_2_021B7675
    Source: C:\Users\user\Desktop\eCooEFZfZJ.exeCode function: 0_2_021B566E0_2_021B566E
    Source: C:\Users\user\Desktop\eCooEFZfZJ.exeCode function: 0_2_021B36610_2_021B3661
    Source: C:\Users\user\Desktop\eCooEFZfZJ.exeCode function: 0_2_021B36650_2_021B3665
    Source: C:\Users\user\Desktop\eCooEFZfZJ.exeCode function: 0_2_021B569D0_2_021B569D
    Source: C:\Users\user\Desktop\eCooEFZfZJ.exeCode function: 0_2_021B56890_2_021B5689
    Source: C:\Users\user\Desktop\eCooEFZfZJ.exeCode function: 0_2_021B56850_2_021B5685
    Source: C:\Users\user\Desktop\eCooEFZfZJ.exeCode function: 0_2_021B36D90_2_021B36D9
    Source: C:\Users\user\Desktop\eCooEFZfZJ.exeCode function: 0_2_021B36DD0_2_021B36DD
    Source: C:\Users\user\Desktop\eCooEFZfZJ.exeCode function: 0_2_021B36D10_2_021B36D1
    Source: C:\Users\user\Desktop\eCooEFZfZJ.exeCode function: 0_2_021B36CD0_2_021B36CD
    Source: C:\Users\user\Desktop\eCooEFZfZJ.exeCode function: 0_2_021B46C10_2_021B46C1
    Source: C:\Users\user\Desktop\eCooEFZfZJ.exeCode function: 0_2_021B36C10_2_021B36C1
    Source: C:\Users\user\Desktop\eCooEFZfZJ.exeCode function: 0_2_021B46C50_2_021B46C5
    Source: C:\Users\user\Desktop\eCooEFZfZJ.exeCode function: 0_2_021B36C50_2_021B36C5
    Source: C:\Users\user\Desktop\eCooEFZfZJ.exeCode function: 0_2_021B56F90_2_021B56F9
    Source: C:\Users\user\Desktop\eCooEFZfZJ.exeCode function: 0_2_021B06F50_2_021B06F5
    Source: C:\Users\user\Desktop\eCooEFZfZJ.exeCode function: 0_2_021B56ED0_2_021B56ED
    Source: C:\Users\user\Desktop\eCooEFZfZJ.exeCode function: 0_2_021B26E10_2_021B26E1
    Source: C:\Users\user\Desktop\eCooEFZfZJ.exeCode function: 0_2_021B56E40_2_021B56E4
    Source: C:\Users\user\Desktop\eCooEFZfZJ.exeCode function: 0_2_021B57050_2_021B5705
    Source: C:\Users\user\Desktop\eCooEFZfZJ.exeCode function: 0_2_021B37510_2_021B3751
    Source: C:\Users\user\Desktop\eCooEFZfZJ.exeCode function: 0_2_021B57550_2_021B5755
    Source: C:\Users\user\Desktop\eCooEFZfZJ.exeCode function: 0_2_021B374D0_2_021B374D
    Source: C:\Users\user\Desktop\eCooEFZfZJ.exeCode function: 0_2_021B37410_2_021B3741
    Source: C:\Users\user\Desktop\eCooEFZfZJ.exeCode function: 0_2_021B37450_2_021B3745
    Source: C:\Users\user\Desktop\eCooEFZfZJ.exeCode function: 0_2_021B07790_2_021B0779
    Source: C:\Users\user\Desktop\eCooEFZfZJ.exeCode function: 0_2_021B07750_2_021B0775
    Source: C:\Users\user\Desktop\eCooEFZfZJ.exeCode function: 0_2_021B07690_2_021B0769
    Source: C:\Users\user\Desktop\eCooEFZfZJ.exeCode function: 0_2_021B076D0_2_021B076D
    Source: C:\Users\user\Desktop\eCooEFZfZJ.exeCode function: 0_2_021B476D0_2_021B476D
    Source: C:\Users\user\Desktop\eCooEFZfZJ.exeCode function: 0_2_021B57910_2_021B5791
    Source: C:\Users\user\Desktop\eCooEFZfZJ.exeCode function: 0_2_021B57950_2_021B5795
    Source: C:\Users\user\Desktop\eCooEFZfZJ.exeCode function: 0_2_021B57890_2_021B5789
    Source: C:\Users\user\Desktop\eCooEFZfZJ.exeCode function: 0_2_021B57B90_2_021B57B9
    Source: C:\Users\user\Desktop\eCooEFZfZJ.exeCode function: 0_2_021B37B50_2_021B37B5
    Source: C:\Users\user\Desktop\eCooEFZfZJ.exeCode function: 0_2_021B57B50_2_021B57B5
    Source: C:\Users\user\Desktop\eCooEFZfZJ.exeCode function: 0_2_021B37A90_2_021B37A9
    Source: C:\Users\user\Desktop\eCooEFZfZJ.exeCode function: 0_2_021B57AD0_2_021B57AD
    Source: C:\Users\user\Desktop\eCooEFZfZJ.exeCode function: 0_2_021B57A60_2_021B57A6
    Source: C:\Users\user\Desktop\eCooEFZfZJ.exeCode function: 0_2_021B37C10_2_021B37C1
    Source: C:\Users\user\Desktop\eCooEFZfZJ.exeCode function: 0_2_021B57F90_2_021B57F9
    Source: C:\Users\user\Desktop\eCooEFZfZJ.exeCode function: 0_2_021B07F90_2_021B07F9
    Source: C:\Users\user\Desktop\eCooEFZfZJ.exeCode function: 0_2_021B57FD0_2_021B57FD
    Source: C:\Users\user\Desktop\eCooEFZfZJ.exeCode function: 0_2_021B07FD0_2_021B07FD
    Source: C:\Users\user\Desktop\eCooEFZfZJ.exeCode function: 0_2_021B57F10_2_021B57F1
    Source: C:\Users\user\Desktop\eCooEFZfZJ.exeCode function: 0_2_021B07F10_2_021B07F1
    Source: C:\Users\user\Desktop\eCooEFZfZJ.exeCode function: 0_2_021B07ED0_2_021B07ED
    Source: C:\Users\user\Desktop\eCooEFZfZJ.exeCode function: 0_2_021B07E10_2_021B07E1
    Source: C:\Users\user\Desktop\eCooEFZfZJ.exeCode function: 0_2_021B47E50_2_021B47E5
    Source: C:\Users\user\Desktop\eCooEFZfZJ.exeCode function: 0_2_021B07E50_2_021B07E5
    Source: C:\Users\user\Desktop\eCooEFZfZJ.exeCode function: 0_2_021B14190_2_021B1419
    Source: C:\Users\user\Desktop\eCooEFZfZJ.exeCode function: 0_2_021B141D0_2_021B141D
    Source: C:\Users\user\Desktop\eCooEFZfZJ.exeCode function: 0_2_021B541D0_2_021B541D
    Source: C:\Users\user\Desktop\eCooEFZfZJ.exeCode function: 0_2_021B54130_2_021B5413
    Source: C:\Users\user\Desktop\eCooEFZfZJ.exeCode function: 0_2_021B14110_2_021B1411
    Source: C:\Users\user\Desktop\eCooEFZfZJ.exeCode function: 0_2_021B54150_2_021B5415
    Source: C:\Users\user\Desktop\eCooEFZfZJ.exeCode function: 0_2_021B140D0_2_021B140D
    Source: C:\Users\user\Desktop\eCooEFZfZJ.exeCode function: 0_2_021B54390_2_021B5439
    Source: C:\Users\user\Desktop\eCooEFZfZJ.exeCode function: 0_2_021B343F0_2_021B343F
    Source: C:\Users\user\Desktop\eCooEFZfZJ.exeCode function: 0_2_021B54350_2_021B5435
    Source: C:\Users\user\Desktop\eCooEFZfZJ.exeCode function: 0_2_021B54290_2_021B5429
    Source: C:\Users\user\Desktop\eCooEFZfZJ.exeCode function: 0_2_021B542D0_2_021B542D
    Source: C:\Users\user\Desktop\eCooEFZfZJ.exeCode function: 0_2_021B54210_2_021B5421
    Source: C:\Users\user\Desktop\eCooEFZfZJ.exeCode function: 0_2_021B74250_2_021B7425
    Source: C:\Users\user\Desktop\eCooEFZfZJ.exeCode function: 0_2_021B74590_2_021B7459
    Source: C:\Users\user\Desktop\eCooEFZfZJ.exeCode function: 0_2_021B74550_2_021B7455
    Source: C:\Users\user\Desktop\eCooEFZfZJ.exeCode function: 0_2_021B344D0_2_021B344D
    Source: C:\Users\user\Desktop\eCooEFZfZJ.exeCode function: 0_2_021B34410_2_021B3441
    Source: C:\Users\user\Desktop\eCooEFZfZJ.exeCode function: 0_2_021B54410_2_021B5441
    Source: C:\Users\user\Desktop\eCooEFZfZJ.exeCode function: 0_2_021B34790_2_021B3479
    Source: C:\Users\user\Desktop\eCooEFZfZJ.exeCode function: 0_2_021B747D0_2_021B747D
    Source: C:\Users\user\Desktop\eCooEFZfZJ.exeCode function: 0_2_021B34710_2_021B3471
    Source: C:\Users\user\Desktop\eCooEFZfZJ.exeCode function: 0_2_021B44710_2_021B4471
    Source: C:\Users\user\Desktop\eCooEFZfZJ.exeCode function: 0_2_021B74760_2_021B7476
    Source: C:\Users\user\Desktop\eCooEFZfZJ.exeCode function: 0_2_021B446E0_2_021B446E
    Source: C:\Users\user\Desktop\eCooEFZfZJ.exeCode function: 0_2_021B346D0_2_021B346D
    Source: C:\Users\user\Desktop\eCooEFZfZJ.exeCode function: 0_2_021B74610_2_021B7461
    Source: C:\Users\user\Desktop\eCooEFZfZJ.exeCode function: 0_2_021B74650_2_021B7465
    Source: C:\Users\user\Desktop\eCooEFZfZJ.exeCode function: 0_2_021B549D0_2_021B549D
    Source: C:\Users\user\Desktop\eCooEFZfZJ.exeCode function: 0_2_021B54910_2_021B5491
    Source: C:\Users\user\Desktop\eCooEFZfZJ.exeCode function: 0_2_021B748E0_2_021B748E
    Source: C:\Users\user\Desktop\eCooEFZfZJ.exeCode function: 0_2_021B148D0_2_021B148D
    Source: C:\Users\user\Desktop\eCooEFZfZJ.exeCode function: 0_2_021B54800_2_021B5480
    Source: C:\Users\user\Desktop\eCooEFZfZJ.exeCode function: 0_2_021B54850_2_021B5485
    Source: C:\Users\user\Desktop\eCooEFZfZJ.exeCode function: 0_2_021B74850_2_021B7485
    Source: C:\Users\user\Desktop\eCooEFZfZJ.exeCode function: 0_2_021B54B50_2_021B54B5
    Source: C:\Users\user\Desktop\eCooEFZfZJ.exeCode function: 0_2_021B54A90_2_021B54A9
    Source: C:\Users\user\Desktop\eCooEFZfZJ.exeCode function: 0_2_021B44D90_2_021B44D9
    Source: C:\Users\user\Desktop\eCooEFZfZJ.exeCode function: 0_2_021B44D50_2_021B44D5
    Source: C:\Users\user\Desktop\eCooEFZfZJ.exeCode function: 0_2_021B44CE0_2_021B44CE
    Source: C:\Users\user\Desktop\eCooEFZfZJ.exeCode function: 0_2_021B34FD0_2_021B34FD
    Source: C:\Users\user\Desktop\eCooEFZfZJ.exeCode function: 0_2_021B74FD0_2_021B74FD
    Source: C:\Users\user\Desktop\eCooEFZfZJ.exeCode function: 0_2_021B74F50_2_021B74F5
    Source: C:\Users\user\Desktop\eCooEFZfZJ.exeCode function: 0_2_021B74EE0_2_021B74EE
    Source: C:\Users\user\Desktop\eCooEFZfZJ.exeCode function: 0_2_021B34ED0_2_021B34ED
    Source: C:\Users\user\Desktop\eCooEFZfZJ.exeCode function: 0_2_021B34E10_2_021B34E1
    Source: C:\Users\user\Desktop\eCooEFZfZJ.exeCode function: 0_2_021B44E10_2_021B44E1
    Source: C:\Users\user\Desktop\eCooEFZfZJ.exeCode function: 0_2_021B44E50_2_021B44E5
    Source: C:\Users\user\Desktop\eCooEFZfZJ.exeCode function: 0_2_021B34E50_2_021B34E5
    Source: C:\Users\user\Desktop\eCooEFZfZJ.exeCode function: 0_2_021B551D0_2_021B551D
    Source: C:\Users\user\Desktop\eCooEFZfZJ.exeCode function: 0_2_021B55110_2_021B5511
    Source: C:\Users\user\Desktop\eCooEFZfZJ.exeCode function: 0_2_021B55150_2_021B5515
    Source: C:\Users\user\Desktop\eCooEFZfZJ.exeCode function: 0_2_021B55090_2_021B5509
    Source: C:\Users\user\Desktop\eCooEFZfZJ.exeCode function: 0_2_021B75090_2_021B7509
    Source: C:\Users\user\Desktop\eCooEFZfZJ.exeCode function: 0_2_021B750D0_2_021B750D
    Source: C:\Users\user\Desktop\eCooEFZfZJ.exeCode function: 0_2_021B15010_2_021B1501
    Source: C:\Users\user\Desktop\eCooEFZfZJ.exeCode function: 0_2_021B75010_2_021B7501
    Source: C:\Users\user\Desktop\eCooEFZfZJ.exeCode function: 0_2_021B55000_2_021B5500
    Source: C:\Users\user\Desktop\eCooEFZfZJ.exeCode function: 0_2_021B55050_2_021B5505
    Source: C:\Users\user\Desktop\eCooEFZfZJ.exeCode function: 0_2_021B453C0_2_021B453C
    Source: C:\Users\user\Desktop\eCooEFZfZJ.exeCode function: 0_2_021B55350_2_021B5535
    Source: C:\Users\user\Desktop\eCooEFZfZJ.exeCode function: 0_2_021B55290_2_021B5529
    Source: C:\Users\user\Desktop\eCooEFZfZJ.exeCode function: 0_2_021B552D0_2_021B552D
    Source: C:\Users\user\Desktop\eCooEFZfZJ.exeCode function: 0_2_021B55210_2_021B5521
    Source: C:\Users\user\Desktop\eCooEFZfZJ.exeCode function: 0_2_021B35590_2_021B3559
    Source: C:\Users\user\Desktop\eCooEFZfZJ.exeCode function: 0_2_021B45590_2_021B4559
    Source: C:\Users\user\Desktop\eCooEFZfZJ.exeCode function: 0_2_021B355D0_2_021B355D
    Source: C:\Users\user\Desktop\eCooEFZfZJ.exeCode function: 0_2_021B45550_2_021B4555
    Source: C:\Users\user\Desktop\eCooEFZfZJ.exeCode function: 0_2_021B45490_2_021B4549
    Source: C:\Users\user\Desktop\eCooEFZfZJ.exeCode function: 0_2_021B454D0_2_021B454D
    Source: C:\Users\user\Desktop\eCooEFZfZJ.exeCode function: 0_2_021B45410_2_021B4541
    Source: C:\Users\user\Desktop\eCooEFZfZJ.exeCode function: 0_2_021B557D0_2_021B557D
    Source: C:\Users\user\Desktop\eCooEFZfZJ.exeCode function: 0_2_021B757D0_2_021B757D
    Source: C:\Users\user\Desktop\eCooEFZfZJ.exeCode function: 0_2_021B15710_2_021B1571
    Source: C:\Users\user\Desktop\eCooEFZfZJ.exeCode function: 0_2_021B75710_2_021B7571
    Source: C:\Users\user\Desktop\eCooEFZfZJ.exeCode function: 0_2_021B55760_2_021B5576
    Source: C:\Users\user\Desktop\eCooEFZfZJ.exeCode function: 0_2_021B75750_2_021B7575
    Source: C:\Users\user\Desktop\eCooEFZfZJ.exeCode function: 0_2_021B75690_2_021B7569
    Source: C:\Users\user\Desktop\eCooEFZfZJ.exeCode function: 0_2_021B75620_2_021B7562
    Source: C:\Users\user\Desktop\eCooEFZfZJ.exeCode function: 0_2_021B35650_2_021B3565
    Source: C:\Users\user\Desktop\eCooEFZfZJ.exeCode function: 0_2_021B25910_2_021B2591
    Source: C:\Users\user\Desktop\eCooEFZfZJ.exeCode function: 0_2_021B55910_2_021B5591
    Source: C:\Users\user\Desktop\eCooEFZfZJ.exeCode function: 0_2_021B55950_2_021B5595
    Source: C:\Users\user\Desktop\eCooEFZfZJ.exeCode function: 0_2_021B75950_2_021B7595
    Source: C:\Users\user\Desktop\eCooEFZfZJ.exeCode function: 0_2_021B55890_2_021B5589
    Source: C:\Users\user\Desktop\eCooEFZfZJ.exeCode function: 0_2_021B75890_2_021B7589
    Source: C:\Users\user\Desktop\eCooEFZfZJ.exeCode function: 0_2_021B75810_2_021B7581
    Source: C:\Users\user\Desktop\eCooEFZfZJ.exeCode function: 0_2_021B55850_2_021B5585
    Source: C:\Users\user\Desktop\eCooEFZfZJ.exeCode function: 0_2_021B45A50_2_021B45A5
    Source: C:\Users\user\Desktop\eCooEFZfZJ.exeCode function: 0_2_021B35D90_2_021B35D9
    Source: C:\Users\user\Desktop\eCooEFZfZJ.exeCode function: 0_2_021B35DD0_2_021B35DD
    Source: C:\Users\user\Desktop\eCooEFZfZJ.exeCode function: 0_2_021B35D10_2_021B35D1
    Source: C:\Users\user\Desktop\eCooEFZfZJ.exeCode function: 0_2_021B45D50_2_021B45D5
    Source: C:\Users\user\Desktop\eCooEFZfZJ.exeCode function: 0_2_021B45C90_2_021B45C9
    Source: C:\Users\user\Desktop\eCooEFZfZJ.exeCode function: 0_2_021B35CD0_2_021B35CD
    Source: C:\Users\user\Desktop\eCooEFZfZJ.exeCode function: 0_2_021B25C70_2_021B25C7
    Source: C:\Users\user\Desktop\eCooEFZfZJ.exeCode function: 0_2_021B45C60_2_021B45C6
    Source: C:\Users\user\Desktop\eCooEFZfZJ.exeCode function: 0_2_021B55FA0_2_021B55FA
    Source: C:\Users\user\Desktop\eCooEFZfZJ.exeCode function: 0_2_021B45F90_2_021B45F9
    Source: C:\Users\user\Desktop\eCooEFZfZJ.exeCode function: 0_2_021B75F90_2_021B75F9
    Source: C:\Users\user\Desktop\eCooEFZfZJ.exeCode function: 0_2_021B45F20_2_021B45F2
    Source: C:\Users\user\Desktop\eCooEFZfZJ.exeCode function: 0_2_021B75F70_2_021B75F7
    Source: C:\Users\user\Desktop\eCooEFZfZJ.exeCode function: 0_2_021B5A110_2_021B5A11
    Source: C:\Users\user\Desktop\eCooEFZfZJ.exeCode function: 0_2_021B3A090_2_021B3A09
    Source: C:\Users\user\Desktop\eCooEFZfZJ.exeCode function: 0_2_021B5A090_2_021B5A09
    Source: C:\Users\user\Desktop\eCooEFZfZJ.exeCode function: 0_2_021B3A0D0_2_021B3A0D
    Source: C:\Users\user\Desktop\eCooEFZfZJ.exeCode function: 0_2_021B3A010_2_021B3A01
    Source: C:\Users\user\Desktop\eCooEFZfZJ.exeCode function: 0_2_021B5A050_2_021B5A05
    Source: C:\Users\user\Desktop\eCooEFZfZJ.exeCode function: 0_2_021B3A250_2_021B3A25
    Source: C:\Users\user\Desktop\eCooEFZfZJ.exeCode function: 0_2_021B0A510_2_021B0A51
    Source: C:\Users\user\Desktop\eCooEFZfZJ.exeCode function: 0_2_021B0A550_2_021B0A55
    Source: C:\Users\user\Desktop\eCooEFZfZJ.exeCode function: 0_2_021B0A490_2_021B0A49
    Source: C:\Users\user\Desktop\eCooEFZfZJ.exeCode function: 0_2_021B5A400_2_021B5A40
    Source: C:\Users\user\Desktop\eCooEFZfZJ.exeCode function: 0_2_021B7A7A0_2_021B7A7A
    Source: C:\Users\user\Desktop\eCooEFZfZJ.exeCode function: 0_2_021B5A700_2_021B5A70
    Source: C:\Users\user\Desktop\eCooEFZfZJ.exeCode function: 0_2_021B0A750_2_021B0A75
    Source: C:\Users\user\Desktop\eCooEFZfZJ.exeCode function: 0_2_021B0A690_2_021B0A69
    Source: C:\Users\user\Desktop\eCooEFZfZJ.exeCode function: 0_2_021B0A6D0_2_021B0A6D
    Source: C:\Users\user\Desktop\eCooEFZfZJ.exeCode function: 0_2_021B0A990_2_021B0A99
    Source: C:\Users\user\Desktop\eCooEFZfZJ.exeCode function: 0_2_021B0A9D0_2_021B0A9D
    Source: C:\Users\user\Desktop\eCooEFZfZJ.exeCode function: 0_2_021B0A930_2_021B0A93
    Source: C:\Users\user\Desktop\eCooEFZfZJ.exeCode function: 0_2_021B5AD90_2_021B5AD9
    Source: C:\Users\user\Desktop\eCooEFZfZJ.exeCode function: 0_2_021B5AD50_2_021B5AD5
    Source: C:\Users\user\Desktop\eCooEFZfZJ.exeCode function: 0_2_021B3ACD0_2_021B3ACD
    Source: C:\Users\user\Desktop\eCooEFZfZJ.exeCode function: 0_2_021B5ACD0_2_021B5ACD
    Source: C:\Users\user\Desktop\eCooEFZfZJ.exeCode function: 0_2_021B0AC10_2_021B0AC1
    Source: C:\Users\user\Desktop\eCooEFZfZJ.exeCode function: 0_2_021B5AED0_2_021B5AED
    Source: C:\Users\user\Desktop\eCooEFZfZJ.exeCode function: 0_2_021B5AE10_2_021B5AE1
    Source: C:\Users\user\Desktop\eCooEFZfZJ.exeCode function: 0_2_021B5AE50_2_021B5AE5
    Source: C:\Users\user\Desktop\eCooEFZfZJ.exeCode function: 0_2_021B0B110_2_021B0B11
    Source: C:\Users\user\Desktop\eCooEFZfZJ.exeCode function: 0_2_021B3B0B0_2_021B3B0B
    Source: C:\Users\user\Desktop\eCooEFZfZJ.exeCode function: 0_2_021B0B0D0_2_021B0B0D
    Source: C:\Users\user\Desktop\eCooEFZfZJ.exeCode function: 0_2_021B5B410_2_021B5B41
    Source: C:\Users\user\Desktop\eCooEFZfZJ.exeCode function: 0_2_021B5B790_2_021B5B79
    Source: C:\Users\user\Desktop\eCooEFZfZJ.exeCode function: 0_2_021B5B750_2_021B5B75
    Source: C:\Users\user\Desktop\eCooEFZfZJ.exeCode function: 0_2_021B5B990_2_021B5B99
    Source: C:\Users\user\Desktop\eCooEFZfZJ.exeCode function: 0_2_021B5B910_2_021B5B91
    Source: C:\Users\user\Desktop\eCooEFZfZJ.exeCode function: 0_2_021B5B8D0_2_021B5B8D
    Source: C:\Users\user\Desktop\eCooEFZfZJ.exeCode function: 0_2_021B5B810_2_021B5B81
    Source: C:\Users\user\Desktop\eCooEFZfZJ.exeCode function: 0_2_021B5B850_2_021B5B85
    Source: C:\Users\user\Desktop\eCooEFZfZJ.exeCode function: 0_2_021B5BF50_2_021B5BF5
    Source: C:\Users\user\Desktop\eCooEFZfZJ.exeCode function: 0_2_021B581A0_2_021B581A
    Source: C:\Users\user\Desktop\eCooEFZfZJ.exeCode function: 0_2_021B381E0_2_021B381E
    Source: C:\Users\user\Desktop\eCooEFZfZJ.exeCode function: 0_2_021B58110_2_021B5811
    Source: C:\Users\user\Desktop\eCooEFZfZJ.exeCode function: 0_2_021B58090_2_021B5809
    Source: C:\Users\user\Desktop\eCooEFZfZJ.exeCode function: 0_2_021B58050_2_021B5805
    Source: C:\Users\user\Desktop\eCooEFZfZJ.exeCode function: 0_2_021B38390_2_021B3839
    Source: C:\Users\user\Desktop\eCooEFZfZJ.exeCode function: 0_2_021B38350_2_021B3835
    Source: C:\Users\user\Desktop\eCooEFZfZJ.exeCode function: 0_2_021B38290_2_021B3829
    Source: C:\Users\user\Desktop\eCooEFZfZJ.exeCode function: 0_2_021B382D0_2_021B382D
    Source: C:\Users\user\Desktop\eCooEFZfZJ.exeCode function: 0_2_021B38210_2_021B3821
    Source: C:\Users\user\Desktop\eCooEFZfZJ.exeCode function: 0_2_021B58210_2_021B5821
    Source: C:\Users\user\Desktop\eCooEFZfZJ.exeCode function: 0_2_021B08590_2_021B0859
    Source: C:\Users\user\Desktop\eCooEFZfZJ.exeCode function: 0_2_021B085D0_2_021B085D
    Source: C:\Users\user\Desktop\eCooEFZfZJ.exeCode function: 0_2_021B38410_2_021B3841
    Source: C:\Users\user\Desktop\eCooEFZfZJ.exeCode function: 0_2_021B58440_2_021B5844
    Source: C:\Users\user\Desktop\eCooEFZfZJ.exeCode function: 0_2_021B387C0_2_021B387C
    Source: C:\Users\user\Desktop\eCooEFZfZJ.exeCode function: 0_2_021B08710_2_021B0871
    Source: C:\Users\user\Desktop\eCooEFZfZJ.exeCode function: 0_2_021B58700_2_021B5870
    Source: C:\Users\user\Desktop\eCooEFZfZJ.exeCode function: 0_2_021B08690_2_021B0869
    Source: C:\Users\user\Desktop\eCooEFZfZJ.exeCode function: 0_2_021B08650_2_021B0865
    Source: C:\Users\user\Desktop\eCooEFZfZJ.exeCode function: 0_2_021B389D0_2_021B389D
    Source: C:\Users\user\Desktop\eCooEFZfZJ.exeCode function: 0_2_021B38950_2_021B3895
    Source: C:\Users\user\Desktop\eCooEFZfZJ.exeCode function: 0_2_021B388E0_2_021B388E
    Source: C:\Users\user\Desktop\eCooEFZfZJ.exeCode function: 0_2_021B38B90_2_021B38B9
    Source: C:\Users\user\Desktop\eCooEFZfZJ.exeCode function: 0_2_021B38B50_2_021B38B5
    Source: C:\Users\user\Desktop\eCooEFZfZJ.exeCode function: 0_2_021B38A90_2_021B38A9
    Source: C:\Users\user\Desktop\eCooEFZfZJ.exeCode function: 0_2_021B38AD0_2_021B38AD
    Source: C:\Users\user\Desktop\eCooEFZfZJ.exeCode function: 0_2_021B38A10_2_021B38A1
    Source: C:\Users\user\Desktop\eCooEFZfZJ.exeCode function: 0_2_021B58D90_2_021B58D9
    Source: C:\Users\user\Desktop\eCooEFZfZJ.exeCode function: 0_2_021B08DD0_2_021B08DD
    Source: C:\Users\user\Desktop\eCooEFZfZJ.exeCode function: 0_2_021B08D10_2_021B08D1
    Source: C:\Users\user\Desktop\eCooEFZfZJ.exeCode function: 0_2_021B58D50_2_021B58D5
    Source: C:\Users\user\Desktop\eCooEFZfZJ.exeCode function: 0_2_021B08D50_2_021B08D5
    Source: C:\Users\user\Desktop\eCooEFZfZJ.exeCode function: 0_2_021B58C90_2_021B58C9
    Source: C:\Users\user\Desktop\eCooEFZfZJ.exeCode function: 0_2_021B38CD0_2_021B38CD
    Source: C:\Users\user\Desktop\eCooEFZfZJ.exeCode function: 0_2_021B58CD0_2_021B58CD
    Source: C:\Users\user\Desktop\eCooEFZfZJ.exeCode function: 0_2_021B38C10_2_021B38C1
    Source: C:\Users\user\Desktop\eCooEFZfZJ.exeCode function: 0_2_021B58C10_2_021B58C1
    Source: C:\Users\user\Desktop\eCooEFZfZJ.exeCode function: 0_2_021B38C50_2_021B38C5
    Source: C:\Users\user\Desktop\eCooEFZfZJ.exeCode function: 0_2_021B38F90_2_021B38F9
    Source: C:\Users\user\Desktop\eCooEFZfZJ.exeCode function: 0_2_021B38FD0_2_021B38FD
    Source: C:\Users\user\Desktop\eCooEFZfZJ.exeCode function: 0_2_021B08F50_2_021B08F5
    Source: C:\Users\user\Desktop\eCooEFZfZJ.exeCode function: 0_2_021B38F40_2_021B38F4
    Source: C:\Users\user\Desktop\eCooEFZfZJ.exeCode function: 0_2_021B08E90_2_021B08E9
    Source: C:\Users\user\Desktop\eCooEFZfZJ.exeCode function: 0_2_021B08ED0_2_021B08ED
    Source: C:\Users\user\Desktop\eCooEFZfZJ.exeCode function: 0_2_021B58E10_2_021B58E1
    Source: C:\Users\user\Desktop\eCooEFZfZJ.exeCode function: 0_2_021B08E10_2_021B08E1
    Source: C:\Users\user\Desktop\eCooEFZfZJ.exeCode function: 0_2_021B58E50_2_021B58E5
    Source: C:\Users\user\Desktop\eCooEFZfZJ.exeCode function: 0_2_021B39110_2_021B3911
    Source: C:\Users\user\Desktop\eCooEFZfZJ.exeCode function: 0_2_021B09160_2_021B0916
    Source: C:\Users\user\Desktop\eCooEFZfZJ.exeCode function: 0_2_021B39150_2_021B3915
    Source: C:\Users\user\Desktop\eCooEFZfZJ.exeCode function: 0_2_021B39090_2_021B3909
    Source: C:\Users\user\Desktop\eCooEFZfZJ.exeCode function: 0_2_021B39050_2_021B3905
    Source: C:\Users\user\Desktop\eCooEFZfZJ.exeCode function: 0_2_021B095D0_2_021B095D
    Source: C:\Users\user\Desktop\eCooEFZfZJ.exeCode function: 0_2_021BA9530_2_021BA953
    Source: C:\Users\user\Desktop\eCooEFZfZJ.exeCode function: 0_2_021B59790_2_021B5979
    Source: C:\Users\user\Desktop\eCooEFZfZJ.exeCode function: 0_2_021B39790_2_021B3979
    Source: C:\Users\user\Desktop\eCooEFZfZJ.exeCode function: 0_2_021B397D0_2_021B397D
    Source: C:\Users\user\Desktop\eCooEFZfZJ.exeCode function: 0_2_021B59720_2_021B5972
    Source: C:\Users\user\Desktop\eCooEFZfZJ.exeCode function: 0_2_021B39710_2_021B3971
    Source: C:\Users\user\Desktop\eCooEFZfZJ.exeCode function: 0_2_021B59690_2_021B5969
    Source: C:\Users\user\Desktop\eCooEFZfZJ.exeCode function: 0_2_021B09690_2_021B0969
    Source: C:\Users\user\Desktop\eCooEFZfZJ.exeCode function: 0_2_021B396D0_2_021B396D
    Source: C:\Users\user\Desktop\eCooEFZfZJ.exeCode function: 0_2_021B096D0_2_021B096D
    Source: C:\Users\user\Desktop\eCooEFZfZJ.exeCode function: 0_2_021B59610_2_021B5961
    Source: C:\Users\user\Desktop\eCooEFZfZJ.exeCode function: 0_2_021B09610_2_021B0961
    Source: C:\Users\user\Desktop\eCooEFZfZJ.exeCode function: 0_2_021B39910_2_021B3991
    Source: C:\Users\user\Desktop\eCooEFZfZJ.exeCode function: 0_2_021B59910_2_021B5991
    Source: C:\Users\user\Desktop\eCooEFZfZJ.exeCode function: 0_2_021B39950_2_021B3995
    Source: C:\Users\user\Desktop\eCooEFZfZJ.exeCode function: 0_2_021B39890_2_021B3989
    Source: C:\Users\user\Desktop\eCooEFZfZJ.exeCode function: 0_2_021B598D0_2_021B598D
    Source: C:\Users\user\Desktop\eCooEFZfZJ.exeCode function: 0_2_021B59810_2_021B5981
    Source: C:\Users\user\Desktop\eCooEFZfZJ.exeCode function: 0_2_021B59850_2_021B5985
    Source: C:\Users\user\Desktop\eCooEFZfZJ.exeCode function: 0_2_021B39850_2_021B3985
    Source: C:\Users\user\Desktop\eCooEFZfZJ.exeCode function: 0_2_021B69B90_2_021B69B9
    Source: C:\Users\user\Desktop\eCooEFZfZJ.exeCode function: 0_2_021B69B50_2_021B69B5
    Source: C:\Users\user\Desktop\eCooEFZfZJ.exeCode function: 0_2_021B69AD0_2_021B69AD
    Source: C:\Users\user\Desktop\eCooEFZfZJ.exeCode function: 0_2_021B69A60_2_021B69A6
    Source: C:\Users\user\Desktop\eCooEFZfZJ.exeCode function: 0_2_021B09DD0_2_021B09DD
    Source: C:\Users\user\Desktop\eCooEFZfZJ.exeCode function: 0_2_021B69DC0_2_021B69DC
    Source: C:\Users\user\Desktop\eCooEFZfZJ.exeCode function: 0_2_021B09D10_2_021B09D1
    Source: C:\Users\user\Desktop\eCooEFZfZJ.exeCode function: 0_2_021B09D50_2_021B09D5
    Source: C:\Users\user\Desktop\eCooEFZfZJ.exeCode function: 0_2_021B09C90_2_021B09C9
    Source: C:\Users\user\Desktop\eCooEFZfZJ.exeCode function: 0_2_021B69C10_2_021B69C1
    Source: C:\Users\user\Desktop\eCooEFZfZJ.exeCode function: 0_2_021B69C50_2_021B69C5
    Source: C:\Users\user\Desktop\eCooEFZfZJ.exeCode function: 0_2_021B39FB0_2_021B39FB
    Source: C:\Users\user\Desktop\eCooEFZfZJ.exeCode function: 0_2_021B59F90_2_021B59F9
    Source: C:\Users\user\Desktop\eCooEFZfZJ.exeCode function: 0_2_021B59FD0_2_021B59FD
    Source: C:\Users\user\Desktop\eCooEFZfZJ.exeCode function: 0_2_021B59F10_2_021B59F1
    Source: C:\Users\user\Desktop\eCooEFZfZJ.exeCode function: 0_2_021B09E10_2_021B09E1
    Source: C:\Users\user\Desktop\eCooEFZfZJ.exeCode function: 0_2_021B5E2D0_2_021B5E2D
    Source: C:\Users\user\Desktop\eCooEFZfZJ.exeCode function: 0_2_021B6E2D0_2_021B6E2D
    Source: C:\Users\user\Desktop\eCooEFZfZJ.exeCode function: 0_2_021B5E270_2_021B5E27
    Source: C:\Users\user\Desktop\eCooEFZfZJ.exeCode function: 0_2_021B5E510_2_021B5E51
    Source: C:\Users\user\Desktop\eCooEFZfZJ.exeCode function: 0_2_021B2E4F0_2_021B2E4F
    Source: C:\Users\user\Desktop\eCooEFZfZJ.exeCode function: 0_2_021B6E410_2_021B6E41
    Source: C:\Users\user\Desktop\eCooEFZfZJ.exeCode function: 0_2_021B5E450_2_021B5E45
    Source: C:\Users\user\Desktop\eCooEFZfZJ.exeCode function: 0_2_021B5E9E0_2_021B5E9E
    Source: C:\Users\user\Desktop\eCooEFZfZJ.exeCode function: 0_2_021B5EB90_2_021B5EB9
    Source: C:\Users\user\Desktop\eCooEFZfZJ.exeCode function: 0_2_021B5EB50_2_021B5EB5
    Source: C:\Users\user\Desktop\eCooEFZfZJ.exeCode function: 0_2_021B5EA90_2_021B5EA9
    Source: C:\Users\user\Desktop\eCooEFZfZJ.exeCode function: 0_2_021B5EA10_2_021B5EA1
    Source: C:\Users\user\Desktop\eCooEFZfZJ.exeCode function: 0_2_021B6EA50_2_021B6EA5
    Source: C:\Users\user\Desktop\eCooEFZfZJ.exeCode function: 0_2_021B5ED90_2_021B5ED9
    Source: C:\Users\user\Desktop\eCooEFZfZJ.exeCode function: 0_2_021B0EF90_2_021B0EF9
    Source: C:\Users\user\Desktop\eCooEFZfZJ.exeCode function: 0_2_021B0EF50_2_021B0EF5
    Source: C:\Users\user\Desktop\eCooEFZfZJ.exeCode function: 0_2_021B0EE90_2_021B0EE9
    Source: C:\Users\user\Desktop\eCooEFZfZJ.exeCode function: 0_2_021B0EED0_2_021B0EED
    Source: C:\Users\user\Desktop\eCooEFZfZJ.exeCode function: 0_2_021B0EE10_2_021B0EE1
    Source: C:\Users\user\Desktop\eCooEFZfZJ.exeCode function: 0_2_021B0F1B0_2_021B0F1B
    Source: C:\Users\user\Desktop\eCooEFZfZJ.exeCode function: 0_2_021B0F010_2_021B0F01
    Source: C:\Users\user\Desktop\eCooEFZfZJ.exeCode function: 0_2_021B0F390_2_021B0F39
    Source: C:\Users\user\Desktop\eCooEFZfZJ.exeCode function: 0_2_021B0F350_2_021B0F35
    Source: C:\Users\user\Desktop\eCooEFZfZJ.exeCode function: 0_2_021B0F5D0_2_021B0F5D
    Source: C:\Users\user\Desktop\eCooEFZfZJ.exeCode function: 0_2_021B0F510_2_021B0F51
    Source: C:\Users\user\Desktop\eCooEFZfZJ.exeCode function: 0_2_021B0F550_2_021B0F55
    Source: C:\Users\user\Desktop\eCooEFZfZJ.exeCode function: 0_2_021B0F610_2_021B0F61
    Source: C:\Users\user\Desktop\eCooEFZfZJ.exeCode function: 0_2_021B0FDD0_2_021B0FDD
    Source: C:\Users\user\Desktop\eCooEFZfZJ.exeCode function: 0_2_021B0FD10_2_021B0FD1
    Source: C:\Users\user\Desktop\eCooEFZfZJ.exeCode function: 0_2_021B5FFD0_2_021B5FFD
    Source: C:\Users\user\Desktop\eCooEFZfZJ.exeCode function: 0_2_021B0FF10_2_021B0FF1
    Source: C:\Users\user\Desktop\eCooEFZfZJ.exeCode function: 0_2_021B0FF50_2_021B0FF5
    Source: C:\Users\user\Desktop\eCooEFZfZJ.exeCode function: 0_2_021B0FE90_2_021B0FE9
    Source: C:\Users\user\Desktop\eCooEFZfZJ.exeCode function: 0_2_021B0FE50_2_021B0FE5
    Source: C:\Users\user\Desktop\eCooEFZfZJ.exeCode function: 0_2_021B5C190_2_021B5C19
    Source: C:\Users\user\Desktop\eCooEFZfZJ.exeCode function: 0_2_021B5C0D0_2_021B5C0D
    Source: C:\Users\user\Desktop\eCooEFZfZJ.exeCode function: 0_2_021B5C010_2_021B5C01
    Source: C:\Users\user\Desktop\eCooEFZfZJ.exeCode function: 0_2_021B5C210_2_021B5C21
    Source: C:\Users\user\Desktop\eCooEFZfZJ.exeCode function: 0_2_021B5C250_2_021B5C25
    Source: C:\Users\user\Desktop\eCooEFZfZJ.exeCode function: 0_2_021B5C460_2_021B5C46
    Source: C:\Users\user\Desktop\eCooEFZfZJ.exeCode function: 0_2_021B6C770_2_021B6C77
    Source: C:\Users\user\Desktop\eCooEFZfZJ.exeCode function: 0_2_021B5C6F0_2_021B5C6F
    Source: eCooEFZfZJ.exeStatic PE information: Resource name: RT_ICON type: GLS_BINARY_LSB_FIRST
    Source: eCooEFZfZJ.exe, 00000000.00000000.227779697.0000000000430000.00000002.00020000.sdmpBinary or memory string: OriginalFilenamePerspektivls4.exe vs eCooEFZfZJ.exe
    Source: eCooEFZfZJ.exe, 00000000.00000002.755015651.00000000020C0000.00000002.00000001.sdmpBinary or memory string: OriginalFilenameuser32j% vs eCooEFZfZJ.exe
    Source: eCooEFZfZJ.exeBinary or memory string: OriginalFilenamePerspektivls4.exe vs eCooEFZfZJ.exe
    Source: eCooEFZfZJ.exeStatic PE information: LOCAL_SYMS_STRIPPED, 32BIT_MACHINE, EXECUTABLE_IMAGE, LINE_NUMS_STRIPPED, RELOCS_STRIPPED
    Source: classification engineClassification label: mal88.rans.troj.evad.winEXE@1/0@0/0
    Source: eCooEFZfZJ.exeStatic PE information: Section: .text IMAGE_SCN_MEM_EXECUTE, IMAGE_SCN_CNT_CODE, IMAGE_SCN_MEM_READ
    Source: C:\Users\user\Desktop\eCooEFZfZJ.exeSection loaded: C:\Windows\SysWOW64\msvbvm60.dllJump to behavior
    Source: C:\Users\user\Desktop\eCooEFZfZJ.exeKey opened: HKEY_CURRENT_USER\Software\Policies\Microsoft\Windows\Safer\CodeIdentifiersJump to behavior
    Source: eCooEFZfZJ.exeVirustotal: Detection: 15%

    Data Obfuscation:

    barindex
    Yara detected GuLoaderShow sources
    Source: Yara matchFile source: 00000000.00000002.755211123.00000000021B0000.00000040.00000001.sdmp, type: MEMORY
    Source: C:\Users\user\Desktop\eCooEFZfZJ.exeCode function: 0_2_0040CC6F push es; ret 0_2_0040CC79
    Source: C:\Users\user\Desktop\eCooEFZfZJ.exeCode function: 0_2_0040CD0D push es; ret 0_2_0040CD89
    Source: C:\Users\user\Desktop\eCooEFZfZJ.exeCode function: 0_2_00409133 push es; ret 0_2_0040923D
    Source: C:\Users\user\Desktop\eCooEFZfZJ.exeCode function: 0_2_0040CD36 push es; ret 0_2_0040CD89
    Source: C:\Users\user\Desktop\eCooEFZfZJ.exeCode function: 0_2_004071C4 push es; ret 0_2_004071C5
    Source: C:\Users\user\Desktop\eCooEFZfZJ.exeCode function: 0_2_0040ADE0 push es; ret 0_2_0040AE65
    Source: C:\Users\user\Desktop\eCooEFZfZJ.exeCode function: 0_2_00402DE4 push dword ptr [ebp-1Ch]; ret 0_2_004275E4
    Source: C:\Users\user\Desktop\eCooEFZfZJ.exeCode function: 0_2_0040C1E7 push es; ret 0_2_0040C1ED
    Source: C:\Users\user\Desktop\eCooEFZfZJ.exeCode function: 0_2_0040C1F2 push es; retf 0_2_0040C202
    Source: C:\Users\user\Desktop\eCooEFZfZJ.exeCode function: 0_2_00409199 push es; ret 0_2_0040923D
    Source: C:\Users\user\Desktop\eCooEFZfZJ.exeCode function: 0_2_00408A53 push es; ret 0_2_00408A69
    Source: C:\Users\user\Desktop\eCooEFZfZJ.exeCode function: 0_2_0040AE61 push es; ret 0_2_0040AE65
    Source: C:\Users\user\Desktop\eCooEFZfZJ.exeCode function: 0_2_021B6C42 push esi; iretd 0_2_021B7EBF
    Source: C:\Users\user\Desktop\eCooEFZfZJ.exeCode function: 0_2_021B723A push esi; iretd 0_2_021B7EBF
    Source: C:\Users\user\Desktop\eCooEFZfZJ.exeCode function: 0_2_021B7259 push esi; iretd 0_2_021B7EBF
    Source: C:\Users\user\Desktop\eCooEFZfZJ.exeCode function: 0_2_021B7252 push esi; iretd 0_2_021B7EBF
    Source: C:\Users\user\Desktop\eCooEFZfZJ.exeCode function: 0_2_021B7249 push esi; iretd 0_2_021B7EBF
    Source: C:\Users\user\Desktop\eCooEFZfZJ.exeCode function: 0_2_021B7241 push esi; iretd 0_2_021B7EBF
    Source: C:\Users\user\Desktop\eCooEFZfZJ.exeCode function: 0_2_021B827F push esi; iretd 0_2_021B82C5
    Source: C:\Users\user\Desktop\eCooEFZfZJ.exeCode function: 0_2_021B7261 push esi; iretd 0_2_021B7EBF
    Source: C:\Users\user\Desktop\eCooEFZfZJ.exeCode function: 0_2_021B8299 push esi; iretd 0_2_021B8316
    Source: C:\Users\user\Desktop\eCooEFZfZJ.exeCode function: 0_2_021B8292 push esi; iretd 0_2_021B8316
    Source: C:\Users\user\Desktop\eCooEFZfZJ.exeCode function: 0_2_021B72B3 push esi; iretd 0_2_021B7EBF
    Source: C:\Users\user\Desktop\eCooEFZfZJ.exeCode function: 0_2_021B82AD push esi; iretd 0_2_021B8327
    Source: C:\Users\user\Desktop\eCooEFZfZJ.exeCode function: 0_2_021B82A5 push esi; iretd 0_2_021B8327
    Source: C:\Users\user\Desktop\eCooEFZfZJ.exeCode function: 0_2_021B72D9 push esi; iretd 0_2_021B7EBF
    Source: C:\Users\user\Desktop\eCooEFZfZJ.exeCode function: 0_2_021B72D5 push esi; iretd 0_2_021B7EBF
    Source: C:\Users\user\Desktop\eCooEFZfZJ.exeCode function: 0_2_021B82D4 push esi; iretd 0_2_021B82D5
    Source: C:\Users\user\Desktop\eCooEFZfZJ.exeCode function: 0_2_021B733A push esi; iretd 0_2_021B7EBF
    Source: C:\Users\user\Desktop\eCooEFZfZJ.exeCode function: 0_2_021B7349 push esi; iretd 0_2_021B7EBF
    Source: C:\Users\user\Desktop\eCooEFZfZJ.exeCode function: 0_2_021B734D push esi; iretd 0_2_021B7EBF
    Source: C:\Users\user\Desktop\eCooEFZfZJ.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
    Source: C:\Users\user\Desktop\eCooEFZfZJ.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
    Source: C:\Users\user\Desktop\eCooEFZfZJ.exeProcess information set: NOOPENFILEERRORBOXJump to behavior

    Malware Analysis System Evasion:

    barindex
    Contains functionality to detect hardware virtualization (CPUID execution measurement)Show sources
    Source: C:\Users\user\Desktop\eCooEFZfZJ.exeCode function: 0_2_021B73D9 0_2_021B73D9
    Source: C:\Users\user\Desktop\eCooEFZfZJ.exeCode function: 0_2_021B73D2 0_2_021B73D2
    Source: C:\Users\user\Desktop\eCooEFZfZJ.exeCode function: 0_2_021B73C8 0_2_021B73C8
    Source: C:\Users\user\Desktop\eCooEFZfZJ.exeCode function: 0_2_021B73F1 0_2_021B73F1
    Source: C:\Users\user\Desktop\eCooEFZfZJ.exeCode function: 0_2_021B73ED 0_2_021B73ED
    Source: C:\Users\user\Desktop\eCooEFZfZJ.exeCode function: 0_2_021B73E1 0_2_021B73E1
    Source: C:\Users\user\Desktop\eCooEFZfZJ.exeCode function: 0_2_021B73E5 0_2_021B73E5
    Source: C:\Users\user\Desktop\eCooEFZfZJ.exeCode function: 0_2_021B761D 0_2_021B761D
    Source: C:\Users\user\Desktop\eCooEFZfZJ.exeCode function: 0_2_021B7616 0_2_021B7616
    Source: C:\Users\user\Desktop\eCooEFZfZJ.exeCode function: 0_2_021B760D 0_2_021B760D
    Source: C:\Users\user\Desktop\eCooEFZfZJ.exeCode function: 0_2_021B7601 0_2_021B7601
    Source: C:\Users\user\Desktop\eCooEFZfZJ.exeCode function: 0_2_021B7605 0_2_021B7605
    Source: C:\Users\user\Desktop\eCooEFZfZJ.exeCode function: 0_2_021B7629 0_2_021B7629
    Source: C:\Users\user\Desktop\eCooEFZfZJ.exeCode function: 0_2_021B7675 0_2_021B7675
    Source: C:\Users\user\Desktop\eCooEFZfZJ.exeCode function: 0_2_021B7425 0_2_021B7425
    Source: C:\Users\user\Desktop\eCooEFZfZJ.exeCode function: 0_2_021B7459 0_2_021B7459
    Source: C:\Users\user\Desktop\eCooEFZfZJ.exeCode function: 0_2_021B7455 0_2_021B7455
    Source: C:\Users\user\Desktop\eCooEFZfZJ.exeCode function: 0_2_021B747D 0_2_021B747D
    Source: C:\Users\user\Desktop\eCooEFZfZJ.exeCode function: 0_2_021B7476 0_2_021B7476
    Source: C:\Users\user\Desktop\eCooEFZfZJ.exeCode function: 0_2_021B7461 0_2_021B7461
    Source: C:\Users\user\Desktop\eCooEFZfZJ.exeCode function: 0_2_021B7465 0_2_021B7465
    Source: C:\Users\user\Desktop\eCooEFZfZJ.exeCode function: 0_2_021B748E 0_2_021B748E
    Source: C:\Users\user\Desktop\eCooEFZfZJ.exeCode function: 0_2_021B7485 0_2_021B7485
    Source: C:\Users\user\Desktop\eCooEFZfZJ.exeCode function: 0_2_021B74FD 0_2_021B74FD
    Source: C:\Users\user\Desktop\eCooEFZfZJ.exeCode function: 0_2_021B74F5 0_2_021B74F5
    Source: C:\Users\user\Desktop\eCooEFZfZJ.exeCode function: 0_2_021B74EE 0_2_021B74EE
    Source: C:\Users\user\Desktop\eCooEFZfZJ.exeCode function: 0_2_021B750D 0_2_021B750D
    Source: C:\Users\user\Desktop\eCooEFZfZJ.exeCode function: 0_2_021B7501 0_2_021B7501
    Source: C:\Users\user\Desktop\eCooEFZfZJ.exeCode function: 0_2_021B7571 0_2_021B7571
    Source: C:\Users\user\Desktop\eCooEFZfZJ.exeCode function: 0_2_021B7575 0_2_021B7575
    Source: C:\Users\user\Desktop\eCooEFZfZJ.exeCode function: 0_2_021B7569 0_2_021B7569
    Source: C:\Users\user\Desktop\eCooEFZfZJ.exeCode function: 0_2_021B7562 0_2_021B7562
    Source: C:\Users\user\Desktop\eCooEFZfZJ.exeCode function: 0_2_021B7595 0_2_021B7595
    Source: C:\Users\user\Desktop\eCooEFZfZJ.exeCode function: 0_2_021B7589 0_2_021B7589
    Source: C:\Users\user\Desktop\eCooEFZfZJ.exeCode function: 0_2_021BA953 0_2_021BA953
    Tries to detect virtualization through RDTSC time measurementsShow sources
    Source: C:\Users\user\Desktop\eCooEFZfZJ.exeRDTSC instruction interceptor: First address: 00000000021B9ADF second address: 00000000021B9ADF instructions: 0x00000000 rdtsc 0x00000002 lfence 0x00000005 shl edx, 20h 0x00000008 or edx, eax 0x0000000a popad 0x0000000b add edx, ebx 0x0000000d xor edx, E6D43193h 0x00000013 add esi, 02h 0x00000016 cmp word ptr [esi], 0000h 0x0000001a jne 00007FA8A0F1C80Ah 0x0000001c mov ebx, edx 0x0000001e shl edx, 05h 0x00000021 add edx, ebx 0x00000023 movzx ebx, byte ptr [esi] 0x00000026 jmp 00007FA8A0F1C8AEh 0x00000028 pushad 0x00000029 lfence 0x0000002c rdtsc
    Source: C:\Users\user\Desktop\eCooEFZfZJ.exeCode function: 0_2_00407096 rdtsc 0_2_00407096
    Source: all processesThread injection, dropped files, key value created, disk infection and DNS query: no activity detected

    Anti Debugging:

    barindex
    Found potential dummy code loops (likely to delay analysis)Show sources
    Source: C:\Users\user\Desktop\eCooEFZfZJ.exeProcess Stats: CPU usage > 90% for more than 60s
    Source: C:\Users\user\Desktop\eCooEFZfZJ.exeCode function: 0_2_00407096 rdtsc 0_2_00407096
    Source: C:\Users\user\Desktop\eCooEFZfZJ.exeCode function: 0_2_021B9059 mov eax, dword ptr fs:[00000030h]0_2_021B9059
    Source: C:\Users\user\Desktop\eCooEFZfZJ.exeCode function: 0_2_021B44D9 mov eax, dword ptr fs:[00000030h]0_2_021B44D9
    Source: C:\Users\user\Desktop\eCooEFZfZJ.exeCode function: 0_2_021B44D5 mov eax, dword ptr fs:[00000030h]0_2_021B44D5
    Source: C:\Users\user\Desktop\eCooEFZfZJ.exeCode function: 0_2_021B44CE mov eax, dword ptr fs:[00000030h]0_2_021B44CE
    Source: C:\Users\user\Desktop\eCooEFZfZJ.exeCode function: 0_2_021B453C mov eax, dword ptr fs:[00000030h]0_2_021B453C
    Source: C:\Users\user\Desktop\eCooEFZfZJ.exeCode function: 0_2_021B4549 mov eax, dword ptr fs:[00000030h]0_2_021B4549
    Source: C:\Users\user\Desktop\eCooEFZfZJ.exeCode function: 0_2_021B454D mov eax, dword ptr fs:[00000030h]0_2_021B454D
    Source: C:\Users\user\Desktop\eCooEFZfZJ.exeCode function: 0_2_021B4541 mov eax, dword ptr fs:[00000030h]0_2_021B4541
    Source: C:\Users\user\Desktop\eCooEFZfZJ.exeCode function: 0_2_021B45A5 mov eax, dword ptr fs:[00000030h]0_2_021B45A5
    Source: C:\Users\user\Desktop\eCooEFZfZJ.exeCode function: 0_2_021B387C mov eax, dword ptr fs:[00000030h]0_2_021B387C
    Source: C:\Users\user\Desktop\eCooEFZfZJ.exeCode function: 0_2_021B6862 mov eax, dword ptr fs:[00000030h]0_2_021B6862
    Source: C:\Users\user\Desktop\eCooEFZfZJ.exeCode function: 0_2_021B9916 mov eax, dword ptr fs:[00000030h]0_2_021B9916
    Source: C:\Users\user\Desktop\eCooEFZfZJ.exeCode function: 0_2_021BA953 mov eax, dword ptr fs:[00000030h]0_2_021BA953
    Source: all processesThread injection, dropped files, key value created, disk infection and DNS query: no activity detected
    Source: eCooEFZfZJ.exe, 00000000.00000002.754732099.0000000000CA0000.00000002.00000001.sdmpBinary or memory string: uProgram Manager
    Source: eCooEFZfZJ.exe, 00000000.00000002.754732099.0000000000CA0000.00000002.00000001.sdmpBinary or memory string: Shell_TrayWnd
    Source: eCooEFZfZJ.exe, 00000000.00000002.754732099.0000000000CA0000.00000002.00000001.sdmpBinary or memory string: Progman
    Source: eCooEFZfZJ.exe, 00000000.00000002.754732099.0000000000CA0000.00000002.00000001.sdmpBinary or memory string: Progmanlock
    Source: C:\Users\user\Desktop\eCooEFZfZJ.exeCode function: 0_2_00403FEC GetSystemTime,0_2_00403FEC

    Mitre Att&ck Matrix

    Initial AccessExecutionPersistencePrivilege EscalationDefense EvasionCredential AccessDiscoveryLateral MovementCollectionExfiltrationCommand and ControlNetwork EffectsRemote Service EffectsImpact
    Valid AccountsWindows Management InstrumentationPath InterceptionProcess Injection1Virtualization/Sandbox Evasion11OS Credential DumpingSystem Time Discovery1Remote ServicesArchive Collected Data1Exfiltration Over Other Network MediumEncrypted Channel1Eavesdrop on Insecure Network CommunicationRemotely Track Device Without AuthorizationModify System Partition
    Default AccountsScheduled Task/JobBoot or Logon Initialization ScriptsBoot or Logon Initialization ScriptsProcess Injection1LSASS MemorySecurity Software Discovery31Remote Desktop ProtocolData from Removable MediaExfiltration Over BluetoothApplication Layer Protocol1Exploit SS7 to Redirect Phone Calls/SMSRemotely Wipe Data Without AuthorizationDevice Lockout
    Domain AccountsAt (Linux)Logon Script (Windows)Logon Script (Windows)Obfuscated Files or Information1Security Account ManagerVirtualization/Sandbox Evasion11SMB/Windows Admin SharesData from Network Shared DriveAutomated ExfiltrationSteganographyExploit SS7 to Track Device LocationObtain Device Cloud BackupsDelete Device Data
    Local AccountsAt (Windows)Logon Script (Mac)Logon Script (Mac)Binary PaddingNTDSProcess Discovery1Distributed Component Object ModelInput CaptureScheduled TransferProtocol ImpersonationSIM Card SwapCarrier Billing Fraud
    Cloud AccountsCronNetwork Logon ScriptNetwork Logon ScriptSoftware PackingLSA SecretsSystem Information Discovery22SSHKeyloggingData Transfer Size LimitsFallback ChannelsManipulate Device CommunicationManipulate App Store Rankings or Ratings

    Behavior Graph

    Hide Legend

    Legend:

    • Process
    • Signature
    • Created File
    • DNS/IP Info
    • Is Dropped
    • Is Windows Process
    • Number of created Registry Values
    • Number of created Files
    • Visual Basic
    • Delphi
    • Java
    • .Net C# or VB.NET
    • C, C++ or other language
    • Is malicious
    • Internet

    Screenshots

    Thumbnails

    This section contains all screenshots as thumbnails, including those not shown in the slideshow.