Source: 0.2.KkPVouLuOx.exe.2af0000.2.unpack |
Malware Configuration Extractor: Agenttesla {"Exfil Mode": "SMTP", "Username": "info@karsanmax.com", "Password": "erk#bmc2007", "Host": "mail.karsanmax.com"} |
Source: |
Binary string: wntdll.pdbUGP source: KkPVouLuOx.exe, 00000000.00000003.236887920.0000000002B90000.00000004.00000001.sdmp |
Source: |
Binary string: wntdll.pdb source: KkPVouLuOx.exe, 00000000.00000003.236887920.0000000002B90000.00000004.00000001.sdmp |
Source: MSBuild.exe, 00000002.00000002.502987084.00000000034C1000.00000004.00000001.sdmp |
String found in binary or memory: http://127.0.0.1:HTTP/1.1 |
Source: MSBuild.exe, 00000002.00000002.502987084.00000000034C1000.00000004.00000001.sdmp |
String found in binary or memory: http://DynDns.comDynDNS |
Source: MSBuild.exe, 00000002.00000002.505310278.0000000003825000.00000004.00000001.sdmp |
String found in binary or memory: http://mail.karsanmax.com |
Source: MSBuild.exe, 00000002.00000002.502987084.00000000034C1000.00000004.00000001.sdmp |
String found in binary or memory: http://myRZFP.com |
Source: KkPVouLuOx.exe, 00000000.00000002.240535528.0000000002AF0000.00000040.00000001.sdmp, MSBuild.exe, 00000002.00000002.499202518.0000000000402000.00000040.00000001.sdmp |
String found in binary or memory: https://www.theonionrouter.com/dist.torproject.org/torbrowser/9.5.3/tor-win32-0.4.3.6.zip |
Source: MSBuild.exe, 00000002.00000002.502987084.00000000034C1000.00000004.00000001.sdmp |
String found in binary or memory: https://www.theonionrouter.com/dist.torproject.org/torbrowser/9.5.3/tor-win32-0.4.3.6.zip%tordir%%ha |
Source: MSBuild.exe, 00000002.00000002.502987084.00000000034C1000.00000004.00000001.sdmp |
String found in binary or memory: https://yE6yjauUrbNMVyVX.com |
Source: C:\Users\user\Desktop\KkPVouLuOx.exe |
Code function: 0_2_003A8456 |
0_2_003A8456 |
Source: C:\Users\user\Desktop\KkPVouLuOx.exe |
Code function: 0_2_003A8BC9 |
0_2_003A8BC9 |
Source: C:\Users\user\Desktop\KkPVouLuOx.exe |
Code function: 0_2_00396C20 |
0_2_00396C20 |
Source: C:\Users\user\Desktop\KkPVouLuOx.exe |
Code function: 0_2_00399420 |
0_2_00399420 |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exe |
Code function: 2_2_01457EC0 |
2_2_01457EC0 |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exe |
Code function: 2_2_0145E0D8 |
2_2_0145E0D8 |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exe |
Code function: 2_2_01459148 |
2_2_01459148 |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exe |
Code function: 2_2_016BAB30 |
2_2_016BAB30 |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exe |
Code function: 2_2_016B1BE0 |
2_2_016B1BE0 |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exe |
Code function: 2_2_016BAD50 |
2_2_016BAD50 |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exe |
Code function: 2_2_016B4D38 |
2_2_016B4D38 |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exe |
Code function: 2_2_016B7DC0 |
2_2_016B7DC0 |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exe |
Code function: 2_2_016B2E88 |
2_2_016B2E88 |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exe |
Code function: 2_2_016B42C8 |
2_2_016B42C8 |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exe |
Code function: 2_2_016BBB70 |
2_2_016BBB70 |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exe |
Code function: 2_2_016BBC20 |
2_2_016BBC20 |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exe |
Code function: 2_2_016E5B18 |
2_2_016E5B18 |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exe |
Code function: 2_2_016EC0B8 |
2_2_016EC0B8 |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exe |
Code function: 2_2_016EB3D5 |
2_2_016EB3D5 |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exe |
Code function: 2_2_016EB531 |
2_2_016EB531 |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exe |
Code function: 2_2_016EB4CF |
2_2_016EB4CF |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exe |
Code function: 2_2_016EB487 |
2_2_016EB487 |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exe |
Code function: 2_2_016EB7DE |
2_2_016EB7DE |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exe |
Code function: 2_2_032847A0 |
2_2_032847A0 |
Source: KkPVouLuOx.exe, 00000000.00000003.232733016.0000000002DFF000.00000004.00000001.sdmp |
Binary or memory string: OriginalFilenamentdll.dllj% vs KkPVouLuOx.exe |
Source: KkPVouLuOx.exe, 00000000.00000002.240535528.0000000002AF0000.00000040.00000001.sdmp |
Binary or memory string: OriginalFilenameFLQsqxQVGqhcqKgsCJFGvvBdNseuTyWeUb.exe4 vs KkPVouLuOx.exe |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exe |
WMI Queries: IWbemServices::CreateInstanceEnum - root\cimv2 : Win32_Processor |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exe |
WMI Queries: IWbemServices::ExecQuery - root\cimv2 : SELECT * FROM Win32_Processor |
Source: unknown |
Process created: C:\Users\user\Desktop\KkPVouLuOx.exe 'C:\Users\user\Desktop\KkPVouLuOx.exe' |
|
Source: C:\Users\user\Desktop\KkPVouLuOx.exe |
Process created: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exe 'C:\Users\user\Desktop\KkPVouLuOx.exe' |
|
Source: C:\Users\user\Desktop\KkPVouLuOx.exe |
Process created: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exe 'C:\Users\user\Desktop\KkPVouLuOx.exe' |
Jump to behavior |
Source: KkPVouLuOx.exe |
Static PE information: data directory type: IMAGE_DIRECTORY_ENTRY_IMPORT |
Source: KkPVouLuOx.exe |
Static PE information: data directory type: IMAGE_DIRECTORY_ENTRY_RESOURCE |
Source: KkPVouLuOx.exe |
Static PE information: data directory type: IMAGE_DIRECTORY_ENTRY_BASERELOC |
Source: KkPVouLuOx.exe |
Static PE information: data directory type: IMAGE_DIRECTORY_ENTRY_DEBUG |
Source: KkPVouLuOx.exe |
Static PE information: data directory type: IMAGE_DIRECTORY_ENTRY_LOAD_CONFIG |
Source: KkPVouLuOx.exe |
Static PE information: data directory type: IMAGE_DIRECTORY_ENTRY_IAT |
Source: |
Binary string: wntdll.pdbUGP source: KkPVouLuOx.exe, 00000000.00000003.236887920.0000000002B90000.00000004.00000001.sdmp |
Source: |
Binary string: wntdll.pdb source: KkPVouLuOx.exe, 00000000.00000003.236887920.0000000002B90000.00000004.00000001.sdmp |
Source: KkPVouLuOx.exe |
Static PE information: Data directory: IMAGE_DIRECTORY_ENTRY_IMPORT is in: .rdata |
Source: KkPVouLuOx.exe |
Static PE information: Data directory: IMAGE_DIRECTORY_ENTRY_RESOURCE is in: .rsrc |
Source: KkPVouLuOx.exe |
Static PE information: Data directory: IMAGE_DIRECTORY_ENTRY_BASERELOC is in: .reloc |
Source: KkPVouLuOx.exe |
Static PE information: Data directory: IMAGE_DIRECTORY_ENTRY_LOAD_CONFIG is in: .rdata |
Source: KkPVouLuOx.exe |
Static PE information: Data directory: IMAGE_DIRECTORY_ENTRY_IAT is in: .rdata |
Source: C:\Users\user\Desktop\KkPVouLuOx.exe |
Code function: 0_2_003920E8 push ss; retn 0038h |
0_2_003920E5 |
Source: C:\Users\user\Desktop\KkPVouLuOx.exe |
Code function: 0_2_00392100 push edx; retn 0038h |
0_2_00392101 |
Source: C:\Users\user\Desktop\KkPVouLuOx.exe |
Code function: 0_2_003901F4 push 72003893h; retf |
0_2_0039023D |
Source: C:\Users\user\Desktop\KkPVouLuOx.exe |
Code function: 0_2_00392230 push es; ret |
0_2_00392231 |
Source: C:\Users\user\Desktop\KkPVouLuOx.exe |
Code function: 0_2_0039226C pushfd ; ret |
0_2_0039226D |
Source: C:\Users\user\Desktop\KkPVouLuOx.exe |
Code function: 0_2_00390251 push 72003893h; retf |
0_2_0039023D |
Source: C:\Users\user\Desktop\KkPVouLuOx.exe |
Code function: 0_2_00392250 push esi; ret |
0_2_00392251 |
Source: C:\Users\user\Desktop\KkPVouLuOx.exe |
Code function: 0_2_00392254 pushad ; ret |
0_2_00392255 |
Source: C:\Users\user\Desktop\KkPVouLuOx.exe |
Code function: 0_2_0038D38C push ds; retf |
0_2_0038D38D |
Source: C:\Users\user\Desktop\KkPVouLuOx.exe |
Code function: 0_2_00391F77 push ss; retn 0038h |
0_2_003920E5 |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exe |
Code function: 2_2_01453D78 pushad ; retf |
2_2_01453D79 |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exe |
Code function: 2_2_01453D7B push esp; retf |
2_2_01453D81 |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exe |
Code function: 2_2_016B9493 push 8BFFFFFFh; retf |
2_2_016B94A0 |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exe TID: 2964 |
Thread sleep time: -19369081277395017s >= -30000s |
Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exe TID: 5472 |
Thread sleep count: 1350 > 30 |
Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exe TID: 5472 |
Thread sleep count: 8496 > 30 |
Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exe |
WMI Queries: IWbemServices::CreateInstanceEnum - root\cimv2 : Win32_Processor |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exe |
WMI Queries: IWbemServices::ExecQuery - root\cimv2 : SELECT * FROM Win32_Processor |
Source: MSBuild.exe, 00000002.00000002.508724569.00000000063E0000.00000002.00000001.sdmp |
Binary or memory string: A Virtual Machine could not be started because Hyper-V is not installed. |
Source: MSBuild.exe, 00000002.00000002.508724569.00000000063E0000.00000002.00000001.sdmp |
Binary or memory string: A communication protocol error has occurred between the Hyper-V Host and Guest Compute Service. |
Source: MSBuild.exe, 00000002.00000002.508724569.00000000063E0000.00000002.00000001.sdmp |
Binary or memory string: The communication protocol version between the Hyper-V Host and Guest Compute Services is not supported. |
Source: MSBuild.exe, 00000002.00000002.508915956.0000000006509000.00000004.00000001.sdmp |
Binary or memory string: Hyper-V RAW%SystemRoot%\system32\mswsock.dlllter-0000 |
Source: MSBuild.exe, 00000002.00000002.508724569.00000000063E0000.00000002.00000001.sdmp |
Binary or memory string: An unknown internal message was received by the Hyper-V Compute Service. |
Source: C:\Users\user\Desktop\KkPVouLuOx.exe |
Code function: 0_2_003AAF80 mov eax, dword ptr fs:[00000030h] |
0_2_003AAF80 |
Source: C:\Users\user\Desktop\KkPVouLuOx.exe |
Code function: 0_2_003A5DA4 mov eax, dword ptr fs:[00000030h] |
0_2_003A5DA4 |
Source: C:\Users\user\Desktop\KkPVouLuOx.exe |
Code function: 0_2_003A2195 IsProcessorFeaturePresent,IsDebuggerPresent,SetUnhandledExceptionFilter,UnhandledExceptionFilter, |
0_2_003A2195 |
Source: C:\Users\user\Desktop\KkPVouLuOx.exe |
Code function: 0_2_003A23F7 SetUnhandledExceptionFilter,UnhandledExceptionFilter,GetCurrentProcess,TerminateProcess, |
0_2_003A23F7 |
Source: C:\Users\user\Desktop\KkPVouLuOx.exe |
Code function: 0_2_003A48DC IsDebuggerPresent,SetUnhandledExceptionFilter,UnhandledExceptionFilter, |
0_2_003A48DC |
Source: MSBuild.exe, 00000002.00000002.502443522.0000000001CF0000.00000002.00000001.sdmp |
Binary or memory string: Shell_TrayWnd |
Source: MSBuild.exe, 00000002.00000002.502443522.0000000001CF0000.00000002.00000001.sdmp |
Binary or memory string: Progman |
Source: MSBuild.exe, 00000002.00000002.502443522.0000000001CF0000.00000002.00000001.sdmp |
Binary or memory string: SProgram Managerl |
Source: MSBuild.exe, 00000002.00000002.502443522.0000000001CF0000.00000002.00000001.sdmp |
Binary or memory string: Shell_TrayWnd, |
Source: MSBuild.exe, 00000002.00000002.502443522.0000000001CF0000.00000002.00000001.sdmp |
Binary or memory string: Progmanlock |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exe |
Queries volume information: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exe VolumeInformation |
Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exe |
Queries volume information: C:\Windows\Microsoft.NET\assembly\GAC_MSIL\System.Windows.Forms\v4.0_4.0.0.0__b77a5c561934e089\System.Windows.Forms.dll VolumeInformation |
Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exe |
Queries volume information: C:\Windows\Microsoft.NET\assembly\GAC_MSIL\Microsoft.VisualBasic\v4.0_10.0.0.0__b03f5f7f11d50a3a\Microsoft.VisualBasic.dll VolumeInformation |
Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exe |
Queries volume information: C:\Windows\Microsoft.NET\assembly\GAC_32\CustomMarshalers\v4.0_4.0.0.0__b03f5f7f11d50a3a\CustomMarshalers.dll VolumeInformation |
Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exe |
Queries volume information: C:\Windows\Microsoft.NET\assembly\GAC_32\CustomMarshalers\v4.0_4.0.0.0__b03f5f7f11d50a3a\CustomMarshalers.dll VolumeInformation |
Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exe |
Queries volume information: C:\Windows\Microsoft.NET\assembly\GAC_32\CustomMarshalers\v4.0_4.0.0.0__b03f5f7f11d50a3a\CustomMarshalers.dll VolumeInformation |
Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exe |
Queries volume information: C:\Windows\Microsoft.NET\assembly\GAC_MSIL\System.Management\v4.0_4.0.0.0__b03f5f7f11d50a3a\System.Management.dll VolumeInformation |
Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exe |
Queries volume information: C:\Windows\Microsoft.NET\assembly\GAC_MSIL\System.Drawing\v4.0_4.0.0.0__b03f5f7f11d50a3a\System.Drawing.dll VolumeInformation |
Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exe |
Queries volume information: C:\Windows\Microsoft.NET\assembly\GAC_MSIL\Accessibility\v4.0_4.0.0.0__b03f5f7f11d50a3a\Accessibility.dll VolumeInformation |
Jump to behavior |
Source: Yara match |
File source: 0.2.KkPVouLuOx.exe.2af0000.2.raw.unpack, type: UNPACKEDPE |
Source: Yara match |
File source: 0.2.KkPVouLuOx.exe.2af0000.2.unpack, type: UNPACKEDPE |
Source: Yara match |
File source: 2.2.MSBuild.exe.400000.0.unpack, type: UNPACKEDPE |
Source: Yara match |
File source: 00000002.00000002.499202518.0000000000402000.00000040.00000001.sdmp, type: MEMORY |
Source: Yara match |
File source: 00000000.00000002.240535528.0000000002AF0000.00000040.00000001.sdmp, type: MEMORY |
Source: Yara match |
File source: 0.2.KkPVouLuOx.exe.2af0000.2.raw.unpack, type: UNPACKEDPE |
Source: Yara match |
File source: 0.2.KkPVouLuOx.exe.2af0000.2.unpack, type: UNPACKEDPE |
Source: Yara match |
File source: 2.2.MSBuild.exe.400000.0.unpack, type: UNPACKEDPE |
Source: Yara match |
File source: 00000002.00000002.499202518.0000000000402000.00000040.00000001.sdmp, type: MEMORY |
Source: Yara match |
File source: 00000000.00000002.240535528.0000000002AF0000.00000040.00000001.sdmp, type: MEMORY |
Source: Yara match |
File source: 00000002.00000002.502987084.00000000034C1000.00000004.00000001.sdmp, type: MEMORY |
Source: Yara match |
File source: Process Memory Space: KkPVouLuOx.exe PID: 1336, type: MEMORYSTR |
Source: Yara match |
File source: Process Memory Space: MSBuild.exe PID: 1068, type: MEMORYSTR |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exe |
File opened: C:\Users\user\AppData\Roaming\Thunderbird\profiles.ini |
Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exe |
File opened: C:\Users\user\AppData\Roaming\Thunderbird\profiles.ini |
Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exe |
Key opened: HKEY_CURRENT_USER\Software\IncrediMail\Identities |
Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exe |
Key opened: HKEY_CURRENT_USER\Software\Microsoft\Windows NT\CurrentVersion\Windows Messaging Subsystem\Profiles\Outlook\9375CFF0413111d3B88A00104B2A6676 |
Jump to behavior |
Source: Yara match |
File source: 00000002.00000002.502987084.00000000034C1000.00000004.00000001.sdmp, type: MEMORY |
Source: Yara match |
File source: Process Memory Space: MSBuild.exe PID: 1068, type: MEMORYSTR |
Source: Yara match |
File source: 0.2.KkPVouLuOx.exe.2af0000.2.raw.unpack, type: UNPACKEDPE |
Source: Yara match |
File source: 0.2.KkPVouLuOx.exe.2af0000.2.unpack, type: UNPACKEDPE |
Source: Yara match |
File source: 2.2.MSBuild.exe.400000.0.unpack, type: UNPACKEDPE |
Source: Yara match |
File source: 00000002.00000002.499202518.0000000000402000.00000040.00000001.sdmp, type: MEMORY |
Source: Yara match |
File source: 00000000.00000002.240535528.0000000002AF0000.00000040.00000001.sdmp, type: MEMORY |
Source: Yara match |
File source: 0.2.KkPVouLuOx.exe.2af0000.2.raw.unpack, type: UNPACKEDPE |
Source: Yara match |
File source: 0.2.KkPVouLuOx.exe.2af0000.2.unpack, type: UNPACKEDPE |
Source: Yara match |
File source: 2.2.MSBuild.exe.400000.0.unpack, type: UNPACKEDPE |
Source: Yara match |
File source: 00000002.00000002.499202518.0000000000402000.00000040.00000001.sdmp, type: MEMORY |
Source: Yara match |
File source: 00000000.00000002.240535528.0000000002AF0000.00000040.00000001.sdmp, type: MEMORY |
Source: Yara match |
File source: 00000002.00000002.502987084.00000000034C1000.00000004.00000001.sdmp, type: MEMORY |
Source: Yara match |
File source: Process Memory Space: KkPVouLuOx.exe PID: 1336, type: MEMORYSTR |
Source: Yara match |
File source: Process Memory Space: MSBuild.exe PID: 1068, type: MEMORYSTR |