Source: 1.2.MSBuild.exe.5a0000.0.unpack |
Malware Configuration Extractor: Agenttesla {"Exfil Mode": "SMTP", "Username": "vehicle@ccsp-india.com", "Password": "Lkp$CcsP1008", "Host": "smtp.ccsp-india.com"} |
Source: 0.2.S5ol5p3Ywd.exe.21a0000.1.unpack |
Avira: Label: TR/Patched.Ren.Gen |
Source: 0.2.S5ol5p3Ywd.exe.400000.0.unpack |
Avira: Label: TR/Crypt.ZPACK.Gen |
Source: 0.0.S5ol5p3Ywd.exe.400000.0.unpack |
Avira: Label: TR/Crypt.ZPACK.Gen |
Source: S5ol5p3Ywd.exe |
Static PE information: 32BIT_MACHINE, EXECUTABLE_IMAGE, RELOCS_STRIPPED |
Source: |
Binary string: wntdll.pdbUGP source: S5ol5p3Ywd.exe, 00000000.00000003.216900650.0000000002380000.00000004.00000001.sdmp |
Source: |
Binary string: wntdll.pdb source: S5ol5p3Ywd.exe, 00000000.00000003.216900650.0000000002380000.00000004.00000001.sdmp |
Source: Traffic |
Snort IDS: 2030171 ET TROJAN AgentTesla Exfil Via SMTP 192.168.2.3:49749 -> 206.188.198.65:587 |
Source: Traffic |
Snort IDS: 2030171 ET TROJAN AgentTesla Exfil Via SMTP 192.168.2.3:49751 -> 206.188.198.65:587 |
Source: MSBuild.exe, 00000001.00000002.488248576.0000000002641000.00000004.00000001.sdmp |
String found in binary or memory: http://127.0.0.1:HTTP/1.1 |
Source: MSBuild.exe, 00000001.00000002.488248576.0000000002641000.00000004.00000001.sdmp |
String found in binary or memory: http://DynDns.comDynDNS |
Source: MSBuild.exe, 00000001.00000002.488248576.0000000002641000.00000004.00000001.sdmp, MSBuild.exe, 00000001.00000003.434135998.0000000000624000.00000004.00000001.sdmp, MSBuild.exe, 00000001.00000002.490731824.00000000029B4000.00000004.00000001.sdmp, MSBuild.exe, 00000001.00000002.490440599.0000000002951000.00000004.00000001.sdmp, MSBuild.exe, 00000001.00000002.490758061.00000000029BA000.00000004.00000001.sdmp |
String found in binary or memory: http://apVw5slr5VGGz7Jpi.com |
Source: MSBuild.exe, 00000001.00000002.488248576.0000000002641000.00000004.00000001.sdmp |
String found in binary or memory: http://oUvOEM.com |
Source: MSBuild.exe, 00000001.00000002.490857904.00000000029CA000.00000004.00000001.sdmp |
String found in binary or memory: http://smtp.ccsp-india.com |
Source: MSBuild.exe, 00000001.00000002.490857904.00000000029CA000.00000004.00000001.sdmp |
String found in binary or memory: http://smtp.ccsp-india.com.netsolmail.net |
Source: MSBuild.exe, 00000001.00000002.488248576.0000000002641000.00000004.00000001.sdmp |
String found in binary or memory: https://api.ipify.org%$ |
Source: MSBuild.exe, 00000001.00000002.488248576.0000000002641000.00000004.00000001.sdmp |
String found in binary or memory: https://api.ipify.org%GETMozilla/5.0 |
Source: S5ol5p3Ywd.exe, 00000000.00000002.226441045.0000000002220000.00000040.00000001.sdmp, MSBuild.exe, 00000001.00000002.484489566.00000000005A2000.00000040.00000001.sdmp |
String found in binary or memory: https://www.theonionrouter.com/dist.torproject.org/torbrowser/9.5.3/tor-win32-0.4.3.6.zip |
Source: MSBuild.exe, 00000001.00000002.488248576.0000000002641000.00000004.00000001.sdmp |
String found in binary or memory: https://www.theonionrouter.com/dist.torproject.org/torbrowser/9.5.3/tor-win32-0.4.3.6.zip%tordir%%ha |
Source: S5ol5p3Ywd.exe, 00000000.00000002.226326104.00000000006CA000.00000004.00000020.sdmp |
Binary or memory string: <HOOK MODULE="DDRAW.DLL" FUNCTION="DirectDrawCreateEx"/> |
|
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exe |
Code function: 1_2_00876095 |
1_2_00876095 |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exe |
Code function: 1_2_00879990 |
1_2_00879990 |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exe |
Code function: 1_2_0087DA28 |
1_2_0087DA28 |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exe |
Code function: 1_2_00879320 |
1_2_00879320 |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exe |
Code function: 1_2_00870B7F |
1_2_00870B7F |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exe |
Code function: 1_2_00872E88 |
1_2_00872E88 |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exe |
Code function: 1_2_00873614 |
1_2_00873614 |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exe |
Code function: 1_2_0087E848 |
1_2_0087E848 |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exe |
Code function: 1_2_00882D50 |
1_2_00882D50 |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exe |
Code function: 1_2_0088E298 |
1_2_0088E298 |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exe |
Code function: 1_2_00882618 |
1_2_00882618 |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exe |
Code function: 1_2_00881FE0 |
1_2_00881FE0 |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exe |
Code function: 1_2_0088AB78 |
1_2_0088AB78 |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exe |
Code function: 1_2_0088BDE1 |
1_2_0088BDE1 |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exe |
Code function: 1_2_00888FF8 |
1_2_00888FF8 |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exe |
Code function: 1_2_00A6D690 |
1_2_00A6D690 |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exe |
Code function: 1_2_00A68C60 |
1_2_00A68C60 |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exe |
Code function: 1_2_00A69078 |
1_2_00A69078 |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exe |
Code function: 1_2_00A6B458 |
1_2_00A6B458 |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exe |
Code function: 1_2_00A64B80 |
1_2_00A64B80 |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exe |
Code function: 1_2_00A69DE0 |
1_2_00A69DE0 |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exe |
Code function: 1_2_00A60145 |
1_2_00A60145 |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exe |
Code function: 1_2_00A652D0 |
1_2_00A652D0 |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exe |
Code function: 1_2_00A653C8 |
1_2_00A653C8 |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exe |
Code function: 1_2_00B43834 |
1_2_00B43834 |
Source: S5ol5p3Ywd.exe, 00000000.00000003.217038339.0000000002496000.00000004.00000001.sdmp |
Binary or memory string: OriginalFilenamentdll.dllj% vs S5ol5p3Ywd.exe |
Source: S5ol5p3Ywd.exe, 00000000.00000002.226441045.0000000002220000.00000040.00000001.sdmp |
Binary or memory string: OriginalFilenameeuBTclcChqenwdaokXVwrIozGFGzLmkrbZatUQ.exe4 vs S5ol5p3Ywd.exe |
Source: S5ol5p3Ywd.exe |
Static PE information: 32BIT_MACHINE, EXECUTABLE_IMAGE, RELOCS_STRIPPED |
Source: classification engine |
Classification label: mal100.spre.troj.spyw.evad.winEXE@3/1@4/1 |
Source: S5ol5p3Ywd.exe |
Static PE information: Section: .text IMAGE_SCN_MEM_EXECUTE, IMAGE_SCN_CNT_CODE, IMAGE_SCN_MEM_READ |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exe |
WMI Queries: IWbemServices::CreateInstanceEnum - root\cimv2 : Win32_Processor |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exe |
WMI Queries: IWbemServices::ExecQuery - root\cimv2 : SELECT * FROM Win32_Processor |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exe |
WMI Queries: IWbemServices::ExecQuery - root\cimv2 : SELECT * FROM Win32_Processor |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exe |
File read: C:\Windows\System32\drivers\etc\hosts |
Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exe |
File read: C:\Windows\System32\drivers\etc\hosts |
Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exe |
File read: C:\Windows\System32\drivers\etc\hosts |
Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exe |
File read: C:\Windows\System32\drivers\etc\hosts |
Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exe |
File read: C:\Windows\System32\drivers\etc\hosts |
Jump to behavior |
Source: unknown |
Process created: C:\Users\user\Desktop\S5ol5p3Ywd.exe 'C:\Users\user\Desktop\S5ol5p3Ywd.exe' |
|
Source: C:\Users\user\Desktop\S5ol5p3Ywd.exe |
Process created: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exe 'C:\Users\user\Desktop\S5ol5p3Ywd.exe' |
|
Source: C:\Users\user\Desktop\S5ol5p3Ywd.exe |
Process created: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exe 'C:\Users\user\Desktop\S5ol5p3Ywd.exe' |
Jump to behavior |
Source: |
Binary string: wntdll.pdbUGP source: S5ol5p3Ywd.exe, 00000000.00000003.216900650.0000000002380000.00000004.00000001.sdmp |
Source: |
Binary string: wntdll.pdb source: S5ol5p3Ywd.exe, 00000000.00000003.216900650.0000000002380000.00000004.00000001.sdmp |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exe |
WMI Queries: IWbemServices::CreateInstanceEnum - root\cimv2 : Win32_BaseBoard |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exe |
WMI Queries: IWbemServices::CreateInstanceEnum - root\cimv2 : Win32_NetworkAdapterConfiguration |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exe TID: 4552 |
Thread sleep time: -19369081277395017s >= -30000s |
Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exe TID: 4160 |
Thread sleep count: 462 > 30 |
Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exe TID: 4160 |
Thread sleep count: 9398 > 30 |
Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exe |
WMI Queries: IWbemServices::CreateInstanceEnum - root\cimv2 : Win32_Processor |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exe |
WMI Queries: IWbemServices::ExecQuery - root\cimv2 : SELECT * FROM Win32_Processor |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exe |
WMI Queries: IWbemServices::ExecQuery - root\cimv2 : SELECT * FROM Win32_Processor |
Source: MSBuild.exe, 00000001.00000002.493143036.0000000005670000.00000002.00000001.sdmp |
Binary or memory string: A Virtual Machine could not be started because Hyper-V is not installed. |
Source: MSBuild.exe, 00000001.00000002.493143036.0000000005670000.00000002.00000001.sdmp |
Binary or memory string: A communication protocol error has occurred between the Hyper-V Host and Guest Compute Service. |
Source: MSBuild.exe, 00000001.00000002.493143036.0000000005670000.00000002.00000001.sdmp |
Binary or memory string: The communication protocol version between the Hyper-V Host and Guest Compute Services is not supported. |
Source: MSBuild.exe, 00000001.00000002.493341884.0000000005783000.00000004.00000001.sdmp |
Binary or memory string: Hyper-V RAW%SystemRoot%\system32\mswsock.dll |
Source: MSBuild.exe, 00000001.00000002.493143036.0000000005670000.00000002.00000001.sdmp |
Binary or memory string: An unknown internal message was received by the Hyper-V Compute Service. |
Source: C:\Users\user\Desktop\S5ol5p3Ywd.exe |
Code function: 0_2_022106DA mov eax, dword ptr fs:[00000030h] |
0_2_022106DA |
Source: C:\Users\user\Desktop\S5ol5p3Ywd.exe |
Code function: 0_2_022108EE mov eax, dword ptr fs:[00000030h] |
0_2_022108EE |
Source: C:\Users\user\Desktop\S5ol5p3Ywd.exe |
Code function: 0_2_02210A1C mov eax, dword ptr fs:[00000030h] |
0_2_02210A1C |
Source: C:\Users\user\Desktop\S5ol5p3Ywd.exe |
Code function: 0_2_0221099F mov eax, dword ptr fs:[00000030h] |
0_2_0221099F |
Source: C:\Users\user\Desktop\S5ol5p3Ywd.exe |
Code function: 0_2_022109DE mov eax, dword ptr fs:[00000030h] |
0_2_022109DE |
Source: MSBuild.exe, 00000001.00000002.487993738.0000000001030000.00000002.00000001.sdmp |
Binary or memory string: Program Manager |
Source: MSBuild.exe, 00000001.00000002.487993738.0000000001030000.00000002.00000001.sdmp |
Binary or memory string: Shell_TrayWnd |
Source: MSBuild.exe, 00000001.00000002.487993738.0000000001030000.00000002.00000001.sdmp |
Binary or memory string: Progman |
Source: MSBuild.exe, 00000001.00000002.487993738.0000000001030000.00000002.00000001.sdmp |
Binary or memory string: Progmanlock |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exe |
Queries volume information: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exe VolumeInformation |
Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exe |
Queries volume information: C:\Windows\Microsoft.NET\assembly\GAC_MSIL\System.Windows.Forms\v4.0_4.0.0.0__b77a5c561934e089\System.Windows.Forms.dll VolumeInformation |
Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exe |
Queries volume information: C:\Windows\Microsoft.NET\assembly\GAC_MSIL\Microsoft.VisualBasic\v4.0_10.0.0.0__b03f5f7f11d50a3a\Microsoft.VisualBasic.dll VolumeInformation |
Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exe |
Queries volume information: C:\Windows\Microsoft.NET\assembly\GAC_32\CustomMarshalers\v4.0_4.0.0.0__b03f5f7f11d50a3a\CustomMarshalers.dll VolumeInformation |
Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exe |
Queries volume information: C:\Windows\Microsoft.NET\assembly\GAC_32\CustomMarshalers\v4.0_4.0.0.0__b03f5f7f11d50a3a\CustomMarshalers.dll VolumeInformation |
Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exe |
Queries volume information: C:\Windows\Microsoft.NET\assembly\GAC_32\CustomMarshalers\v4.0_4.0.0.0__b03f5f7f11d50a3a\CustomMarshalers.dll VolumeInformation |
Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exe |
Queries volume information: C:\Windows\Microsoft.NET\assembly\GAC_MSIL\System.Management\v4.0_4.0.0.0__b03f5f7f11d50a3a\System.Management.dll VolumeInformation |
Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exe |
Queries volume information: C:\Windows\Microsoft.NET\assembly\GAC_MSIL\System.Drawing\v4.0_4.0.0.0__b03f5f7f11d50a3a\System.Drawing.dll VolumeInformation |
Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exe |
Queries volume information: C:\Windows\Microsoft.NET\assembly\GAC_MSIL\Accessibility\v4.0_4.0.0.0__b03f5f7f11d50a3a\Accessibility.dll VolumeInformation |
Jump to behavior |
Source: Yara match |
File source: 0.2.S5ol5p3Ywd.exe.2220000.2.raw.unpack, type: UNPACKEDPE |
Source: Yara match |
File source: 0.2.S5ol5p3Ywd.exe.2220000.2.unpack, type: UNPACKEDPE |
Source: Yara match |
File source: 1.2.MSBuild.exe.5a0000.0.unpack, type: UNPACKEDPE |
Source: Yara match |
File source: 00000001.00000002.484489566.00000000005A2000.00000040.00000001.sdmp, type: MEMORY |
Source: Yara match |
File source: 00000000.00000002.226441045.0000000002220000.00000040.00000001.sdmp, type: MEMORY |
Source: Yara match |
File source: 0.2.S5ol5p3Ywd.exe.2220000.2.raw.unpack, type: UNPACKEDPE |
Source: Yara match |
File source: 0.2.S5ol5p3Ywd.exe.2220000.2.unpack, type: UNPACKEDPE |
Source: Yara match |
File source: 1.2.MSBuild.exe.5a0000.0.unpack, type: UNPACKEDPE |
Source: Yara match |
File source: 00000001.00000002.484489566.00000000005A2000.00000040.00000001.sdmp, type: MEMORY |
Source: Yara match |
File source: 00000000.00000002.226441045.0000000002220000.00000040.00000001.sdmp, type: MEMORY |
Source: Yara match |
File source: Process Memory Space: MSBuild.exe PID: 6116, type: MEMORY |
Source: Yara match |
File source: Process Memory Space: S5ol5p3Ywd.exe PID: 5460, type: MEMORY |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exe |
File opened: C:\Users\user\AppData\Roaming\Mozilla\Firefox\profiles.ini |
Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exe |
File opened: C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Cookies |
Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exe |
File opened: C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Login Data |
Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exe |
File opened: C:\Users\user\AppData\Roaming\SmartFTP\Client 2.0\Favorites\Quick Connect\ |
Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exe |
File opened: C:\Users\user\AppData\Roaming\FileZilla\recentservers.xml |
Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exe |
File opened: C:\Users\user\AppData\Roaming\Thunderbird\profiles.ini |
Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exe |
File opened: C:\Users\user\AppData\Roaming\Thunderbird\profiles.ini |
Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exe |
Key opened: HKEY_CURRENT_USER\Software\IncrediMail\Identities |
Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exe |
Key opened: HKEY_CURRENT_USER\Software\Microsoft\Windows NT\CurrentVersion\Windows Messaging Subsystem\Profiles\Outlook\9375CFF0413111d3B88A00104B2A6676 |
Jump to behavior |
Source: Yara match |
File source: 00000001.00000002.488248576.0000000002641000.00000004.00000001.sdmp, type: MEMORY |
Source: Yara match |
File source: Process Memory Space: MSBuild.exe PID: 6116, type: MEMORY |
Source: Yara match |
File source: 0.2.S5ol5p3Ywd.exe.2220000.2.raw.unpack, type: UNPACKEDPE |
Source: Yara match |
File source: 0.2.S5ol5p3Ywd.exe.2220000.2.unpack, type: UNPACKEDPE |
Source: Yara match |
File source: 1.2.MSBuild.exe.5a0000.0.unpack, type: UNPACKEDPE |
Source: Yara match |
File source: 00000001.00000002.484489566.00000000005A2000.00000040.00000001.sdmp, type: MEMORY |
Source: Yara match |
File source: 00000000.00000002.226441045.0000000002220000.00000040.00000001.sdmp, type: MEMORY |
Source: Yara match |
File source: 0.2.S5ol5p3Ywd.exe.2220000.2.raw.unpack, type: UNPACKEDPE |
Source: Yara match |
File source: 0.2.S5ol5p3Ywd.exe.2220000.2.unpack, type: UNPACKEDPE |
Source: Yara match |
File source: 1.2.MSBuild.exe.5a0000.0.unpack, type: UNPACKEDPE |
Source: Yara match |
File source: 00000001.00000002.484489566.00000000005A2000.00000040.00000001.sdmp, type: MEMORY |
Source: Yara match |
File source: 00000000.00000002.226441045.0000000002220000.00000040.00000001.sdmp, type: MEMORY |
Source: Yara match |
File source: Process Memory Space: MSBuild.exe PID: 6116, type: MEMORY |
Source: Yara match |
File source: Process Memory Space: S5ol5p3Ywd.exe PID: 5460, type: MEMORY |