Source: 00000012.00000002.318294839.0000000002E70000.00000004.00000040.sdmp |
Malware Configuration Extractor: Remcos {"Host:Port:Password": "Xhpvfingusti.club:6609:s%qDr", "Assigned name": "gogo", "Connect interval": "1", "Install flag": "Disable", "Setup HKCU\\Run": "Enable", "Setup HKLM\\Run": "Disable", "Install path": "AppData", "Copy file": "remcos.exe", "Startup value": "Remcos", "Hide file": "Disable", "Mutex": "Remcos-WHOQYH", "Keylog flag": "1", "Keylog path": "AppData", "Keylog file": "logs.dat", "Keylog crypt": "Disable", "Hide keylog file": "Disable", "Screenshot flag": "Disable", "Screenshot time": "10", "Take Screenshot option": "Disable", "Take screenshot title": "wikipedia;solitaire;", "Take screenshot time": "5", "Screenshot path": "AppData", "Screenshot file": "Screenshots", "Screenshot crypt": "Disable", "Mouse option": "Disable", "Delete file": "Disable", "Audio record time": "5", "Audio path": "AppData", "Audio folder": "MicRecords", "Connect delay": "0", "Copy folder": "Remcos", "Keylog folder": "remcos", "Keylog file max size": "10000"} |
Source: Yara match |
File source: 17.3.glpmruvjds.pif.47bf208.14.unpack, type: UNPACKEDPE |
Source: Yara match |
File source: 17.3.glpmruvjds.pif.47ff218.6.raw.unpack, type: UNPACKEDPE |
Source: Yara match |
File source: 17.3.glpmruvjds.pif.47df210.9.unpack, type: UNPACKEDPE |
Source: Yara match |
File source: 5.3.glpmruvjds.pif.3c90a88.7.unpack, type: UNPACKEDPE |
Source: Yara match |
File source: 5.3.glpmruvjds.pif.3c90a88.5.raw.unpack, type: UNPACKEDPE |
Source: Yara match |
File source: 7.2.RegSvcs.exe.800000.0.unpack, type: UNPACKEDPE |
Source: Yara match |
File source: 17.3.glpmruvjds.pif.47bf208.8.unpack, type: UNPACKEDPE |
Source: Yara match |
File source: 5.3.glpmruvjds.pif.3c90a88.5.unpack, type: UNPACKEDPE |
Source: Yara match |
File source: 17.3.glpmruvjds.pif.47df210.9.raw.unpack, type: UNPACKEDPE |
Source: Yara match |
File source: 17.3.glpmruvjds.pif.47bf208.12.raw.unpack, type: UNPACKEDPE |
Source: Yara match |
File source: 5.3.glpmruvjds.pif.3c90a88.2.raw.unpack, type: UNPACKEDPE |
Source: Yara match |
File source: 17.3.glpmruvjds.pif.47df210.11.raw.unpack, type: UNPACKEDPE |
Source: Yara match |
File source: 17.3.glpmruvjds.pif.47bf208.12.unpack, type: UNPACKEDPE |
Source: Yara match |
File source: 17.3.glpmruvjds.pif.3ab5f28.0.raw.unpack, type: UNPACKEDPE |
Source: Yara match |
File source: 17.3.glpmruvjds.pif.47bf208.4.unpack, type: UNPACKEDPE |
Source: Yara match |
File source: 17.3.glpmruvjds.pif.47bf208.2.unpack, type: UNPACKEDPE |
Source: Yara match |
File source: 5.3.glpmruvjds.pif.3c90a88.6.unpack, type: UNPACKEDPE |
Source: Yara match |
File source: 5.3.glpmruvjds.pif.3cd0a98.3.raw.unpack, type: UNPACKEDPE |
Source: Yara match |
File source: 18.2.RegSvcs.exe.930000.0.raw.unpack, type: UNPACKEDPE |
Source: Yara match |
File source: 5.3.glpmruvjds.pif.3c90a88.6.raw.unpack, type: UNPACKEDPE |
Source: Yara match |
File source: 17.3.glpmruvjds.pif.47df210.7.raw.unpack, type: UNPACKEDPE |
Source: Yara match |
File source: 17.3.glpmruvjds.pif.47bf208.1.unpack, type: UNPACKEDPE |
Source: Yara match |
File source: 17.3.glpmruvjds.pif.47ff218.6.unpack, type: UNPACKEDPE |
Source: Yara match |
File source: 17.3.glpmruvjds.pif.47df210.3.unpack, type: UNPACKEDPE |
Source: Yara match |
File source: 17.3.glpmruvjds.pif.47bf208.2.raw.unpack, type: UNPACKEDPE |
Source: Yara match |
File source: 17.3.glpmruvjds.pif.47bf208.10.raw.unpack, type: UNPACKEDPE |
Source: Yara match |
File source: 17.3.glpmruvjds.pif.47bf208.10.unpack, type: UNPACKEDPE |
Source: Yara match |
File source: 7.2.RegSvcs.exe.800000.0.raw.unpack, type: UNPACKEDPE |
Source: Yara match |
File source: 17.3.glpmruvjds.pif.47df210.5.unpack, type: UNPACKEDPE |
Source: Yara match |
File source: 17.3.glpmruvjds.pif.47df210.7.unpack, type: UNPACKEDPE |
Source: Yara match |
File source: 17.3.glpmruvjds.pif.47df210.13.unpack, type: UNPACKEDPE |
Source: Yara match |
File source: 17.3.glpmruvjds.pif.3ab5f28.0.unpack, type: UNPACKEDPE |
Source: Yara match |
File source: 5.3.glpmruvjds.pif.3c90a88.2.unpack, type: UNPACKEDPE |
Source: Yara match |
File source: 5.3.glpmruvjds.pif.3c90a88.7.raw.unpack, type: UNPACKEDPE |
Source: Yara match |
File source: 18.2.RegSvcs.exe.930000.0.unpack, type: UNPACKEDPE |
Source: Yara match |
File source: 17.3.glpmruvjds.pif.47df210.11.unpack, type: UNPACKEDPE |
Source: Yara match |
File source: 17.3.glpmruvjds.pif.47df210.3.raw.unpack, type: UNPACKEDPE |
Source: Yara match |
File source: 17.3.glpmruvjds.pif.3ab5f28.15.unpack, type: UNPACKEDPE |
Source: Yara match |
File source: 5.3.glpmruvjds.pif.3c50a78.0.raw.unpack, type: UNPACKEDPE |
Source: Yara match |
File source: 17.3.glpmruvjds.pif.47df210.5.raw.unpack, type: UNPACKEDPE |
Source: Yara match |
File source: 5.3.glpmruvjds.pif.3cd0a98.4.raw.unpack, type: UNPACKEDPE |
Source: Yara match |
File source: 17.3.glpmruvjds.pif.47bf208.14.raw.unpack, type: UNPACKEDPE |
Source: Yara match |
File source: 5.3.glpmruvjds.pif.3c70a80.1.raw.unpack, type: UNPACKEDPE |
Source: Yara match |
File source: 17.3.glpmruvjds.pif.47df210.13.raw.unpack, type: UNPACKEDPE |
Source: Yara match |
File source: 17.3.glpmruvjds.pif.3ab5f28.15.raw.unpack, type: UNPACKEDPE |
Source: Yara match |
File source: 17.3.glpmruvjds.pif.47bf208.4.raw.unpack, type: UNPACKEDPE |
Source: Yara match |
File source: 17.3.glpmruvjds.pif.47bf208.8.raw.unpack, type: UNPACKEDPE |
Source: Yara match |
File source: 17.3.glpmruvjds.pif.47bf208.1.raw.unpack, type: UNPACKEDPE |
Source: Yara match |
File source: 00000011.00000003.317794056.0000000004800000.00000004.00000001.sdmp, type: MEMORY |
Source: Yara match |
File source: 00000005.00000003.270724186.0000000003C71000.00000004.00000001.sdmp, type: MEMORY |
Source: Yara match |
File source: 00000011.00000003.314903867.0000000003AB6000.00000004.00000001.sdmp, type: MEMORY |
Source: Yara match |
File source: 00000005.00000003.271079064.0000000004010000.00000004.00000001.sdmp, type: MEMORY |
Source: Yara match |
File source: 00000005.00000003.269314350.0000000003C91000.00000004.00000001.sdmp, type: MEMORY |
Source: Yara match |
File source: 00000011.00000003.316020069.00000000047BE000.00000004.00000001.sdmp, type: MEMORY |
Source: Yara match |
File source: 00000011.00000003.316748134.00000000047BE000.00000004.00000001.sdmp, type: MEMORY |
Source: Yara match |
File source: 00000011.00000003.318319543.0000000003AB6000.00000004.00000001.sdmp, type: MEMORY |
Source: Yara match |
File source: 00000011.00000003.315218162.00000000047BE000.00000004.00000001.sdmp, type: MEMORY |
Source: Yara match |
File source: 00000011.00000003.315274051.0000000004791000.00000004.00000001.sdmp, type: MEMORY |
Source: Yara match |
File source: 00000005.00000003.270887890.0000000002FDE000.00000004.00000001.sdmp, type: MEMORY |
Source: Yara match |
File source: 00000011.00000003.316141009.00000000047BE000.00000004.00000001.sdmp, type: MEMORY |
Source: Yara match |
File source: 00000011.00000003.315298076.00000000047BE000.00000004.00000001.sdmp, type: MEMORY |
Source: Yara match |
File source: 00000011.00000003.315083483.00000000047E0000.00000004.00000001.sdmp, type: MEMORY |
Source: Yara match |
File source: 00000011.00000003.315046193.00000000047BE000.00000004.00000001.sdmp, type: MEMORY |
Source: Yara match |
File source: 00000011.00000003.317892072.00000000047C0000.00000004.00000001.sdmp, type: MEMORY |
Source: Yara match |
File source: 00000011.00000003.315114343.00000000047BE000.00000004.00000001.sdmp, type: MEMORY |
Source: Yara match |
File source: 00000005.00000003.269290149.0000000003C91000.00000004.00000001.sdmp, type: MEMORY |
Source: Yara match |
File source: 00000005.00000003.269142650.0000000003C51000.00000004.00000001.sdmp, type: MEMORY |
Source: Yara match |
File source: 00000011.00000003.318055782.0000000003A93000.00000004.00000001.sdmp, type: MEMORY |
Source: Yara match |
File source: 00000007.00000002.492377010.0000000000800000.00000040.00000001.sdmp, type: MEMORY |
Source: Yara match |
File source: 00000012.00000002.318294839.0000000002E70000.00000004.00000040.sdmp, type: MEMORY |
Source: Yara match |
File source: 00000011.00000003.315100780.0000000004771000.00000004.00000001.sdmp, type: MEMORY |
Source: Yara match |
File source: 00000011.00000003.314813363.0000000003A93000.00000004.00000001.sdmp, type: MEMORY |
Source: Yara match |
File source: 00000005.00000003.271397021.0000000002FB7000.00000004.00000001.sdmp, type: MEMORY |
Source: Yara match |
File source: 00000011.00000003.314881153.00000000047E0000.00000004.00000001.sdmp, type: MEMORY |
Source: Yara match |
File source: 00000005.00000003.269094828.0000000003C71000.00000004.00000001.sdmp, type: MEMORY |
Source: Yara match |
File source: 00000005.00000003.269387450.0000000003CD0000.00000004.00000001.sdmp, type: MEMORY |
Source: Yara match |
File source: 00000005.00000003.271157446.0000000003C90000.00000004.00000001.sdmp, type: MEMORY |
Source: Yara match |
File source: 00000007.00000002.492855959.0000000002AA0000.00000004.00000040.sdmp, type: MEMORY |
Source: Yara match |
File source: 00000011.00000003.315347274.0000000004800000.00000004.00000001.sdmp, type: MEMORY |
Source: Yara match |
File source: 00000011.00000003.317556415.00000000047E0000.00000004.00000001.sdmp, type: MEMORY |
Source: Yara match |
File source: 00000011.00000003.315175094.0000000004771000.00000004.00000001.sdmp, type: MEMORY |
Source: Yara match |
File source: 00000011.00000003.314941565.00000000047C0000.00000004.00000001.sdmp, type: MEMORY |
Source: Yara match |
File source: 00000005.00000003.269350761.0000000003CB1000.00000004.00000001.sdmp, type: MEMORY |
Source: Yara match |
File source: 00000005.00000003.269227982.0000000003C71000.00000004.00000001.sdmp, type: MEMORY |
Source: Yara match |
File source: 00000005.00000003.270937496.0000000003C51000.00000004.00000001.sdmp, type: MEMORY |
Source: Yara match |
File source: 00000011.00000003.317942588.0000000004B60000.00000004.00000001.sdmp, type: MEMORY |
Source: Yara match |
File source: 00000005.00000003.271019743.0000000003C90000.00000004.00000001.sdmp, type: MEMORY |
Source: Yara match |
File source: 00000005.00000003.271290186.0000000003C31000.00000004.00000001.sdmp, type: MEMORY |
Source: Yara match |
File source: 00000012.00000002.318094476.0000000000930000.00000040.00000001.sdmp, type: MEMORY |
Source: Yara match |
File source: 00000005.00000003.269119072.0000000002FB7000.00000004.00000001.sdmp, type: MEMORY |
Source: Yara match |
File source: 00000011.00000003.318006153.0000000004771000.00000004.00000001.sdmp, type: MEMORY |
Source: Yara match |
File source: 00000005.00000003.269002467.0000000003C31000.00000004.00000001.sdmp, type: MEMORY |
Source: Yara match |
File source: Process Memory Space: glpmruvjds.pif PID: 2436, type: MEMORYSTR |
Source: Yara match |
File source: Process Memory Space: RegSvcs.exe PID: 3508, type: MEMORYSTR |
Source: Yara match |
File source: Process Memory Space: glpmruvjds.pif PID: 6556, type: MEMORYSTR |
Source: Yara match |
File source: Process Memory Space: RegSvcs.exe PID: 6688, type: MEMORYSTR |
Source: 5.3.glpmruvjds.pif.3cd0a98.3.unpack |
Avira: Label: TR/Patched.Ren.Gen |
Source: 17.3.glpmruvjds.pif.47bf208.12.unpack |
Avira: Label: BDS/Backdoor.Gen |
Source: 17.3.glpmruvjds.pif.47bf208.14.unpack |
Avira: Label: BDS/Backdoor.Gen |
Source: 17.3.glpmruvjds.pif.47bf208.1.unpack |
Avira: Label: BDS/Backdoor.Gen |
Source: 17.3.glpmruvjds.pif.47df210.11.unpack |
Avira: Label: BDS/Backdoor.Gen |
Source: 17.3.glpmruvjds.pif.47ff218.6.unpack |
Avira: Label: BDS/Backdoor.Gen |
Source: 17.3.glpmruvjds.pif.47df210.3.unpack |
Avira: Label: BDS/Backdoor.Gen |
Source: 17.3.glpmruvjds.pif.47df210.13.unpack |
Avira: Label: BDS/Backdoor.Gen |
Source: 17.3.glpmruvjds.pif.47bf208.2.unpack |
Avira: Label: BDS/Backdoor.Gen |
Source: 17.3.glpmruvjds.pif.47bf208.4.unpack |
Avira: Label: BDS/Backdoor.Gen |
Source: 18.2.RegSvcs.exe.930000.0.unpack |
Avira: Label: BDS/Backdoor.Gen |
Source: 17.3.glpmruvjds.pif.47df210.7.unpack |
Avira: Label: BDS/Backdoor.Gen |
Source: 17.3.glpmruvjds.pif.47bf208.10.unpack |
Avira: Label: BDS/Backdoor.Gen |
Source: 5.3.glpmruvjds.pif.3c90a88.5.unpack |
Avira: Label: BDS/Backdoor.Gen |
Source: 17.3.glpmruvjds.pif.47df210.9.unpack |
Avira: Label: BDS/Backdoor.Gen |
Source: 5.3.glpmruvjds.pif.3c90a88.7.unpack |
Avira: Label: BDS/Backdoor.Gen |
Source: 5.3.glpmruvjds.pif.3c90a88.6.unpack |
Avira: Label: BDS/Backdoor.Gen |
Source: 17.3.glpmruvjds.pif.47bf208.8.unpack |
Avira: Label: BDS/Backdoor.Gen |
Source: 7.2.RegSvcs.exe.800000.0.unpack |
Avira: Label: BDS/Backdoor.Gen |
Source: 5.3.glpmruvjds.pif.3c70a80.1.unpack |
Avira: Label: TR/Patched.Ren.Gen |
Source: 5.3.glpmruvjds.pif.3cd0a98.4.unpack |
Avira: Label: TR/Patched.Ren.Gen |
Source: 5.3.glpmruvjds.pif.3c50a78.0.unpack |
Avira: Label: TR/Patched.Ren.Gen |
Source: 17.3.glpmruvjds.pif.47df210.5.unpack |
Avira: Label: BDS/Backdoor.Gen |
Source: 17.3.glpmruvjds.pif.3ab5f28.0.unpack |
Avira: Label: BDS/Backdoor.Gen |
Source: 5.3.glpmruvjds.pif.3c90a88.2.unpack |
Avira: Label: BDS/Backdoor.Gen |
Source: 17.3.glpmruvjds.pif.3ab5f28.15.unpack |
Avira: Label: BDS/Backdoor.Gen |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe |
Code function: 7_2_00803C4A ??0?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAE@ABV01@@Z,SetEvent,?c_str@?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QBEPBDXZ,?npos@?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@2IB,?npos@?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@2IB,?substr@?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QBE?AV12@II@Z,??0?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAE@ABV01@@Z,??0?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAE@ABV01@@Z,??0?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAE@ABV01@@Z,??0?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAE@ABV01@@Z,??0?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAE@ABV01@@Z,?c_str@?$basic_string@GU?$char_traits@G@std@@V?$allocator@G@2@@std@@QBEPBGXZ,??1?$basic_string@GU?$char_traits@G@std@@V?$allocator@G@2@@std@@QAE@XZ,??Hstd@@YA?AV?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@0@PBDABV10@@Z,??0?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAE@PBDABV?$allocator@D@1@@Z,??1?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAE@XZ,??Hstd@@YA?AV?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@0@PBDABV10@@Z,??0?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAE@PBDABV?$allocator@D@1@@Z,??1?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAE@XZ,??1?$basic_string@GU?$char_traits@G@std@@V?$allocator@G@2@@std@@QAE@XZ,?c_str@?$basic_string@GU?$char_traits@G@std@@V?$allocator@G@2@@std@@QBEPBGXZ,ShellExecuteW,??Hstd@@YA?AV?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@0@PBDABV10@@Z,??0?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAE@PBDABV?$allocator@D@1@@Z,??1?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAE@XZ,??0?$basic_string@GU?$char_traits@G@std@@V?$allocator@G@2@@std@@QAE@ABV01@@Z,?length@?$basic_string@GU?$char_traits@G@std@@V?$allocator@G@2@@std@@QBEIXZ,?substr@?$basic_string@GU?$char_traits@G@std@@V?$allocator@G@2@@std@@QBE?AV12@II@Z,??Hstd@@YA?AV?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@0@PBDABV10@@Z,??0?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAE@PBDABV?$allocator@D@1@@Z,??1?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAE@XZ,??1?$basic_string@GU?$char_traits@G@std@@V?$allocator@G@2@@std@@QAE@XZ,GetLogicalDriveStringsA,??0?$basic_string@DU?$char_traits@D@std@@V?$a |