Source: 1.2.MSBuild.exe.400000.0.unpack |
Malware Configuration Extractor: Agenttesla {"Exfil Mode": "SMTP", "Username": "marketing@elnasrcastings.com", "Password": "hello2012", "Host": "mail.elnasrcastings.com"} |
Source: |
Binary string: wntdll.pdbUGP source: ROQU2AjKs1.exe, 00000000.00000003.328979839.0000000002510000.00000004.00000001.sdmp |
Source: |
Binary string: wntdll.pdb source: ROQU2AjKs1.exe, 00000000.00000003.328979839.0000000002510000.00000004.00000001.sdmp |
Source: MSBuild.exe, 00000001.00000002.595803882.0000000003251000.00000004.00000001.sdmp |
String found in binary or memory: http://127.0.0.1:HTTP/1.1 |
Source: MSBuild.exe, 00000001.00000002.595803882.0000000003251000.00000004.00000001.sdmp |
String found in binary or memory: http://DynDns.comDynDNS |
Source: MSBuild.exe, 00000001.00000002.596681775.00000000035AE000.00000004.00000001.sdmp |
String found in binary or memory: http://elnasrcastings.com |
Source: MSBuild.exe, 00000001.00000002.596681775.00000000035AE000.00000004.00000001.sdmp |
String found in binary or memory: http://mail.elnasrcastings.com |
Source: MSBuild.exe, 00000001.00000002.595803882.0000000003251000.00000004.00000001.sdmp |
String found in binary or memory: http://nGbdto.com |
Source: MSBuild.exe, 00000001.00000002.596681775.00000000035AE000.00000004.00000001.sdmp |
String found in binary or memory: http://t5JwfNkibVxi.com |
Source: ROQU2AjKs1.exe, 00000000.00000002.334786374.0000000002340000.00000040.00000001.sdmp, MSBuild.exe, 00000001.00000002.594529654.0000000000402000.00000040.00000001.sdmp |
String found in binary or memory: https://www.theonionrouter.com/dist.torproject.org/torbrowser/9.5.3/tor-win32-0.4.3.6.zip |
Source: MSBuild.exe, 00000001.00000002.595803882.0000000003251000.00000004.00000001.sdmp |
String found in binary or memory: https://www.theonionrouter.com/dist.torproject.org/torbrowser/9.5.3/tor-win32-0.4.3.6.zip%tordir%%ha |
Source: 1.2.MSBuild.exe.400000.0.unpack, u003cPrivateImplementationDetailsu003eu007bDC6D1FEAu002d76D0u002d4C66u002d9A65u002dBF1A53A67512u007d/E5F46BDEu002d9F33u002d4DD6u002d9CAFu002dA746196347A3.cs |
Large array initialization: .cctor: array initializer size 11961 |
Source: C:\Users\user\Desktop\ROQU2AjKs1.exe |
Code function: 0_2_000B83D6 |
0_2_000B83D6 |
Source: C:\Users\user\Desktop\ROQU2AjKs1.exe |
Code function: 0_2_000B8B59 |
0_2_000B8B59 |
Source: C:\Users\user\Desktop\ROQU2AjKs1.exe |
Code function: 0_2_000A6C20 |
0_2_000A6C20 |
Source: C:\Users\user\Desktop\ROQU2AjKs1.exe |
Code function: 0_2_000A9420 |
0_2_000A9420 |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exe |
Code function: 1_2_00FC70CA |
1_2_00FC70CA |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exe |
Code function: 1_2_00FCC5DF |
1_2_00FCC5DF |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exe |
Code function: 1_2_00FCCA28 |
1_2_00FCCA28 |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exe |
Code function: 1_2_00FC9770 |
1_2_00FC9770 |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exe |
Code function: 1_2_015D5B40 |
1_2_015D5B40 |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exe |
Code function: 1_2_015DF240 |
1_2_015DF240 |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exe |
Code function: 1_2_015D6288 |
1_2_015D6288 |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exe |
Code function: 1_2_015DD858 |
1_2_015DD858 |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exe |
Code function: 1_2_0172CF30 |
1_2_0172CF30 |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exe |
Code function: 1_2_01720790 |
1_2_01720790 |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exe |
Code function: 1_2_017246B0 |
1_2_017246B0 |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exe |
Code function: 1_2_01729298 |
1_2_01729298 |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exe |
Code function: 1_2_01721E80 |
1_2_01721E80 |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exe |
Code function: 1_2_017299E8 |
1_2_017299E8 |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exe |
Code function: 1_2_01722F20 |
1_2_01722F20 |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exe |
Code function: 1_2_01721630 |
1_2_01721630 |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exe |
Code function: 1_2_01729AE8 |
1_2_01729AE8 |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exe |
Code function: 1_2_030A47A0 |
1_2_030A47A0 |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exe |
Code function: 1_2_030A4772 |
1_2_030A4772 |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exe |
Code function: 1_2_030A4790 |
1_2_030A4790 |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exe |
Code function: 1_2_017247A5 |
1_2_017247A5 |
Source: ROQU2AjKs1.exe, 00000000.00000003.329842267.000000000262F000.00000004.00000001.sdmp |
Binary or memory string: OriginalFilenamentdll.dllj% vs ROQU2AjKs1.exe |
Source: ROQU2AjKs1.exe, 00000000.00000002.334786374.0000000002340000.00000040.00000001.sdmp |
Binary or memory string: OriginalFilenameEqdCaVpgsOSfZbzsqUcSQb.exe4 vs ROQU2AjKs1.exe |
Source: 1.2.MSBuild.exe.400000.0.unpack, A/b2.cs |
Cryptographic APIs: 'TransformFinalBlock', 'CreateDecryptor' |
Source: 1.2.MSBuild.exe.400000.0.unpack, A/b2.cs |
Cryptographic APIs: 'TransformFinalBlock', 'CreateDecryptor' |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exe |
WMI Queries: IWbemServices::CreateInstanceEnum - root\cimv2 : Win32_Processor |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exe |
WMI Queries: IWbemServices::ExecQuery - root\cimv2 : SELECT * FROM Win32_Processor |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exe |
File read: C:\Windows\System32\drivers\etc\hosts |
Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exe |
File read: C:\Windows\System32\drivers\etc\hosts |
Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exe |
File read: C:\Windows\System32\drivers\etc\hosts |
Jump to behavior |
Source: unknown |
Process created: C:\Users\user\Desktop\ROQU2AjKs1.exe 'C:\Users\user\Desktop\ROQU2AjKs1.exe' |
|
Source: C:\Users\user\Desktop\ROQU2AjKs1.exe |
Process created: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exe 'C:\Users\user\Desktop\ROQU2AjKs1.exe' |
|
Source: C:\Users\user\Desktop\ROQU2AjKs1.exe |
Process created: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exe 'C:\Users\user\Desktop\ROQU2AjKs1.exe' |
Jump to behavior |
Source: ROQU2AjKs1.exe |
Static PE information: data directory type: IMAGE_DIRECTORY_ENTRY_IMPORT |
Source: ROQU2AjKs1.exe |
Static PE information: data directory type: IMAGE_DIRECTORY_ENTRY_RESOURCE |
Source: ROQU2AjKs1.exe |
Static PE information: data directory type: IMAGE_DIRECTORY_ENTRY_BASERELOC |
Source: ROQU2AjKs1.exe |
Static PE information: data directory type: IMAGE_DIRECTORY_ENTRY_DEBUG |
Source: ROQU2AjKs1.exe |
Static PE information: data directory type: IMAGE_DIRECTORY_ENTRY_LOAD_CONFIG |
Source: ROQU2AjKs1.exe |
Static PE information: data directory type: IMAGE_DIRECTORY_ENTRY_IAT |
Source: |
Binary string: wntdll.pdbUGP source: ROQU2AjKs1.exe, 00000000.00000003.328979839.0000000002510000.00000004.00000001.sdmp |
Source: |
Binary string: wntdll.pdb source: ROQU2AjKs1.exe, 00000000.00000003.328979839.0000000002510000.00000004.00000001.sdmp |
Source: ROQU2AjKs1.exe |
Static PE information: Data directory: IMAGE_DIRECTORY_ENTRY_IMPORT is in: .rdata |
Source: ROQU2AjKs1.exe |
Static PE information: Data directory: IMAGE_DIRECTORY_ENTRY_RESOURCE is in: .rsrc |
Source: ROQU2AjKs1.exe |
Static PE information: Data directory: IMAGE_DIRECTORY_ENTRY_BASERELOC is in: .reloc |
Source: ROQU2AjKs1.exe |
Static PE information: Data directory: IMAGE_DIRECTORY_ENTRY_LOAD_CONFIG is in: .rdata |
Source: ROQU2AjKs1.exe |
Static PE information: Data directory: IMAGE_DIRECTORY_ENTRY_IAT is in: .rdata |
Source: C:\Users\user\Desktop\ROQU2AjKs1.exe |
Code function: 0_2_000A20E8 push ss; retn 0009h |
0_2_000A20E5 |
Source: C:\Users\user\Desktop\ROQU2AjKs1.exe |
Code function: 0_2_000A2100 push edx; retn 0009h |
0_2_000A2101 |
Source: C:\Users\user\Desktop\ROQU2AjKs1.exe |
Code function: 0_2_000A01F4 push 72000993h; retf |
0_2_000A023D |
Source: C:\Users\user\Desktop\ROQU2AjKs1.exe |
Code function: 0_2_000A2230 push es; ret |
0_2_000A2231 |
Source: C:\Users\user\Desktop\ROQU2AjKs1.exe |
Code function: 0_2_000A2250 push esi; ret |
0_2_000A2251 |
Source: C:\Users\user\Desktop\ROQU2AjKs1.exe |
Code function: 0_2_000A0251 push 72000993h; retf |
0_2_000A023D |
Source: C:\Users\user\Desktop\ROQU2AjKs1.exe |
Code function: 0_2_000A2254 pushad ; ret |
0_2_000A2255 |
Source: C:\Users\user\Desktop\ROQU2AjKs1.exe |
Code function: 0_2_000A226C pushfd ; ret |
0_2_000A226D |
Source: C:\Users\user\Desktop\ROQU2AjKs1.exe |
Code function: 0_2_0009D38C push ds; retf |
0_2_0009D38D |
Source: C:\Users\user\Desktop\ROQU2AjKs1.exe |
Code function: 0_2_000A1F77 push ss; retn 0009h |
0_2_000A20E5 |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exe |
Code function: 1_2_015DB557 push edi; retn 0000h |
1_2_015DB559 |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exe |
Code function: 1_2_015DF23C pushad ; ret |
1_2_015DF23D |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exe |
Code function: 1_2_01721268 push eax; retf 5505h |
1_2_0172162E |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exe TID: 2944 |
Thread sleep time: -17524406870024063s >= -30000s |
Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exe TID: 2924 |
Thread sleep count: 570 > 30 |
Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exe TID: 2924 |
Thread sleep count: 9278 > 30 |
Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exe |
WMI Queries: IWbemServices::CreateInstanceEnum - root\cimv2 : Win32_Processor |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exe |
WMI Queries: IWbemServices::ExecQuery - root\cimv2 : SELECT * FROM Win32_Processor |
Source: MSBuild.exe, 00000001.00000002.599931677.0000000006350000.00000002.00000001.sdmp |
Binary or memory string: A Virtual Machine could not be started because Hyper-V is not installed. |
Source: MSBuild.exe, 00000001.00000002.599931677.0000000006350000.00000002.00000001.sdmp |
Binary or memory string: A communication protocol error has occurred between the Hyper-V Host and Guest Compute Service. |
Source: MSBuild.exe, 00000001.00000002.599931677.0000000006350000.00000002.00000001.sdmp |
Binary or memory string: The communication protocol version between the Hyper-V Host and Guest Compute Services is not supported. |
Source: MSBuild.exe, 00000001.00000002.600101708.0000000006440000.00000004.00000001.sdmp |
Binary or memory string: Hyper-V RAW%SystemRoot%\system32\mswsock.dll |
Source: MSBuild.exe, 00000001.00000002.599931677.0000000006350000.00000002.00000001.sdmp |
Binary or memory string: An unknown internal message was received by the Hyper-V Compute Service. |
Source: C:\Users\user\Desktop\ROQU2AjKs1.exe |
Code function: 0_2_000BAF10 mov eax, dword ptr fs:[00000030h] |
0_2_000BAF10 |
Source: C:\Users\user\Desktop\ROQU2AjKs1.exe |
Code function: 0_2_000B5D24 mov eax, dword ptr fs:[00000030h] |
0_2_000B5D24 |
Source: C:\Users\user\Desktop\ROQU2AjKs1.exe |
Code function: 0_2_000B2115 IsProcessorFeaturePresent,IsDebuggerPresent,SetUnhandledExceptionFilter,UnhandledExceptionFilter, |
0_2_000B2115 |
Source: C:\Users\user\Desktop\ROQU2AjKs1.exe |
Code function: 0_2_000B2377 SetUnhandledExceptionFilter,UnhandledExceptionFilter,GetCurrentProcess,TerminateProcess, |
0_2_000B2377 |
Source: C:\Users\user\Desktop\ROQU2AjKs1.exe |
Code function: 0_2_000B485C IsDebuggerPresent,SetUnhandledExceptionFilter,UnhandledExceptionFilter, |
0_2_000B485C |
Source: MSBuild.exe, 00000001.00000002.595378334.0000000001AF0000.00000002.00000001.sdmp |
Binary or memory string: Shell_TrayWnd |
Source: MSBuild.exe, 00000001.00000002.595378334.0000000001AF0000.00000002.00000001.sdmp |
Binary or memory string: Progman |
Source: MSBuild.exe, 00000001.00000002.595378334.0000000001AF0000.00000002.00000001.sdmp |
Binary or memory string: &Program Manager |
Source: MSBuild.exe, 00000001.00000002.595378334.0000000001AF0000.00000002.00000001.sdmp |
Binary or memory string: Progmanlock |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exe |
Queries volume information: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exe VolumeInformation |
Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exe |
Queries volume information: C:\Windows\Microsoft.NET\assembly\GAC_MSIL\System.Windows.Forms\v4.0_4.0.0.0__b77a5c561934e089\System.Windows.Forms.dll VolumeInformation |
Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exe |
Queries volume information: C:\Windows\Microsoft.NET\assembly\GAC_MSIL\Microsoft.VisualBasic\v4.0_10.0.0.0__b03f5f7f11d50a3a\Microsoft.VisualBasic.dll VolumeInformation |
Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exe |
Queries volume information: C:\Windows\Microsoft.NET\assembly\GAC_32\CustomMarshalers\v4.0_4.0.0.0__b03f5f7f11d50a3a\CustomMarshalers.dll VolumeInformation |
Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exe |
Queries volume information: C:\Windows\Microsoft.NET\assembly\GAC_32\CustomMarshalers\v4.0_4.0.0.0__b03f5f7f11d50a3a\CustomMarshalers.dll VolumeInformation |
Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exe |
Queries volume information: C:\Windows\Microsoft.NET\assembly\GAC_32\CustomMarshalers\v4.0_4.0.0.0__b03f5f7f11d50a3a\CustomMarshalers.dll VolumeInformation |
Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exe |
Queries volume information: C:\Windows\Microsoft.NET\assembly\GAC_MSIL\System.Management\v4.0_4.0.0.0__b03f5f7f11d50a3a\System.Management.dll VolumeInformation |
Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exe |
Queries volume information: C:\Windows\Microsoft.NET\assembly\GAC_MSIL\System.Drawing\v4.0_4.0.0.0__b03f5f7f11d50a3a\System.Drawing.dll VolumeInformation |
Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exe |
Queries volume information: C:\Windows\Microsoft.NET\assembly\GAC_MSIL\Accessibility\v4.0_4.0.0.0__b03f5f7f11d50a3a\Accessibility.dll VolumeInformation |
Jump to behavior |
Source: Yara match |
File source: 0.2.ROQU2AjKs1.exe.2340000.2.raw.unpack, type: UNPACKEDPE |
Source: Yara match |
File source: 0.2.ROQU2AjKs1.exe.2340000.2.unpack, type: UNPACKEDPE |
Source: Yara match |
File source: 1.2.MSBuild.exe.400000.0.unpack, type: UNPACKEDPE |
Source: Yara match |
File source: 00000001.00000002.594529654.0000000000402000.00000040.00000001.sdmp, type: MEMORY |
Source: Yara match |
File source: 00000000.00000002.334786374.0000000002340000.00000040.00000001.sdmp, type: MEMORY |
Source: Yara match |
File source: 0.2.ROQU2AjKs1.exe.2340000.2.raw.unpack, type: UNPACKEDPE |
Source: Yara match |
File source: 0.2.ROQU2AjKs1.exe.2340000.2.unpack, type: UNPACKEDPE |
Source: Yara match |
File source: 1.2.MSBuild.exe.400000.0.unpack, type: UNPACKEDPE |
Source: Yara match |
File source: 00000001.00000002.594529654.0000000000402000.00000040.00000001.sdmp, type: MEMORY |
Source: Yara match |
File source: 00000000.00000002.334786374.0000000002340000.00000040.00000001.sdmp, type: MEMORY |
Source: Yara match |
File source: Process Memory Space: ROQU2AjKs1.exe PID: 3448, type: MEMORYSTR |
Source: Yara match |
File source: Process Memory Space: MSBuild.exe PID: 1268, type: MEMORYSTR |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exe |
File opened: C:\Users\user\AppData\Roaming\Thunderbird\profiles.ini |
Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exe |
File opened: C:\Users\user\AppData\Roaming\Thunderbird\profiles.ini |
Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exe |
Key opened: HKEY_CURRENT_USER\Software\IncrediMail\Identities |
Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exe |
Key opened: HKEY_CURRENT_USER\Software\Microsoft\Windows NT\CurrentVersion\Windows Messaging Subsystem\Profiles\Outlook\9375CFF0413111d3B88A00104B2A6676 |
Jump to behavior |
Source: Yara match |
File source: 00000001.00000002.595803882.0000000003251000.00000004.00000001.sdmp, type: MEMORY |
Source: Yara match |
File source: Process Memory Space: MSBuild.exe PID: 1268, type: MEMORYSTR |
Source: Yara match |
File source: 0.2.ROQU2AjKs1.exe.2340000.2.raw.unpack, type: UNPACKEDPE |
Source: Yara match |
File source: 0.2.ROQU2AjKs1.exe.2340000.2.unpack, type: UNPACKEDPE |
Source: Yara match |
File source: 1.2.MSBuild.exe.400000.0.unpack, type: UNPACKEDPE |
Source: Yara match |
File source: 00000001.00000002.594529654.0000000000402000.00000040.00000001.sdmp, type: MEMORY |
Source: Yara match |
File source: 00000000.00000002.334786374.0000000002340000.00000040.00000001.sdmp, type: MEMORY |
Source: Yara match |
File source: 0.2.ROQU2AjKs1.exe.2340000.2.raw.unpack, type: UNPACKEDPE |
Source: Yara match |
File source: 0.2.ROQU2AjKs1.exe.2340000.2.unpack, type: UNPACKEDPE |
Source: Yara match |
File source: 1.2.MSBuild.exe.400000.0.unpack, type: UNPACKEDPE |
Source: Yara match |
File source: 00000001.00000002.594529654.0000000000402000.00000040.00000001.sdmp, type: MEMORY |
Source: Yara match |
File source: 00000000.00000002.334786374.0000000002340000.00000040.00000001.sdmp, type: MEMORY |
Source: Yara match |
File source: Process Memory Space: ROQU2AjKs1.exe PID: 3448, type: MEMORYSTR |
Source: Yara match |
File source: Process Memory Space: MSBuild.exe PID: 1268, type: MEMORYSTR |