Source: Yara match |
File source: 4.3.gajb.pif.4efdf30.0.unpack, type: UNPACKEDPE |
Source: Yara match |
File source: 7.3.gajb.pif.3e2df30.16.raw.unpack, type: UNPACKEDPE |
Source: Yara match |
File source: 4.3.gajb.pif.4efdf30.10.unpack, type: UNPACKEDPE |
Source: Yara match |
File source: 4.3.gajb.pif.4eddf28.16.unpack, type: UNPACKEDPE |
Source: Yara match |
File source: 7.3.gajb.pif.30e7c20.11.raw.unpack, type: UNPACKEDPE |
Source: Yara match |
File source: 4.3.gajb.pif.4efdf30.12.raw.unpack, type: UNPACKEDPE |
Source: Yara match |
File source: 4.3.gajb.pif.4efdf30.15.raw.unpack, type: UNPACKEDPE |
Source: Yara match |
File source: 4.3.gajb.pif.4efdf30.5.unpack, type: UNPACKEDPE |
Source: Yara match |
File source: 7.3.gajb.pif.3e2df30.15.raw.unpack, type: UNPACKEDPE |
Source: Yara match |
File source: 6.2.RegSvcs.exe.b00000.0.unpack, type: UNPACKEDPE |
Source: Yara match |
File source: 4.3.gajb.pif.4eddf28.11.unpack, type: UNPACKEDPE |
Source: Yara match |
File source: 7.3.gajb.pif.3e2df30.3.raw.unpack, type: UNPACKEDPE |
Source: Yara match |
File source: 4.3.gajb.pif.4eddf28.13.raw.unpack, type: UNPACKEDPE |
Source: Yara match |
File source: 4.3.gajb.pif.4eddf28.14.unpack, type: UNPACKEDPE |
Source: Yara match |
File source: 4.3.gajb.pif.4f1e740.9.raw.unpack, type: UNPACKEDPE |
Source: Yara match |
File source: 4.3.gajb.pif.4eddf28.8.raw.unpack, type: UNPACKEDPE |
Source: Yara match |
File source: 10.2.RegSvcs.exe.720000.0.unpack, type: UNPACKEDPE |
Source: Yara match |
File source: 4.3.gajb.pif.4efdf30.10.raw.unpack, type: UNPACKEDPE |
Source: Yara match |
File source: 4.3.gajb.pif.4efdf30.3.unpack, type: UNPACKEDPE |
Source: Yara match |
File source: 7.3.gajb.pif.3e2df30.7.raw.unpack, type: UNPACKEDPE |
Source: Yara match |
File source: 4.3.gajb.pif.4efdf30.17.raw.unpack, type: UNPACKEDPE |
Source: Yara match |
File source: 7.3.gajb.pif.3e0df28.14.raw.unpack, type: UNPACKEDPE |
Source: Yara match |
File source: 7.3.gajb.pif.3e2df30.13.raw.unpack, type: UNPACKEDPE |
Source: Yara match |
File source: 4.3.gajb.pif.4eddf28.13.unpack, type: UNPACKEDPE |
Source: Yara match |
File source: 7.3.gajb.pif.3de0050.8.raw.unpack, type: UNPACKEDPE |
Source: Yara match |
File source: 4.3.gajb.pif.4eddf28.2.unpack, type: UNPACKEDPE |
Source: Yara match |
File source: 4.3.gajb.pif.4efdf30.7.unpack, type: UNPACKEDPE |
Source: Yara match |
File source: 7.3.gajb.pif.3e6e748.5.raw.unpack, type: UNPACKEDPE |
Source: Yara match |
File source: 4.3.gajb.pif.4efdf30.12.unpack, type: UNPACKEDPE |
Source: Yara match |
File source: 7.3.gajb.pif.3e0df28.10.raw.unpack, type: UNPACKEDPE |
Source: Yara match |
File source: 10.2.RegSvcs.exe.720000.0.raw.unpack, type: UNPACKEDPE |
Source: Yara match |
File source: 7.3.gajb.pif.3e2df30.1.raw.unpack, type: UNPACKEDPE |
Source: Yara match |
File source: 4.3.gajb.pif.4eddf28.2.raw.unpack, type: UNPACKEDPE |
Source: Yara match |
File source: 4.3.gajb.pif.4efdf30.1.raw.unpack, type: UNPACKEDPE |
Source: Yara match |
File source: 4.3.gajb.pif.4eddf28.14.raw.unpack, type: UNPACKEDPE |
Source: Yara match |
File source: 7.3.gajb.pif.3e0df28.12.raw.unpack, type: UNPACKEDPE |
Source: Yara match |
File source: 7.3.gajb.pif.3e0df28.2.raw.unpack, type: UNPACKEDPE |
Source: Yara match |
File source: 7.3.gajb.pif.3e2df30.17.raw.unpack, type: UNPACKEDPE |
Source: Yara match |
File source: 4.3.gajb.pif.4eddf28.4.unpack, type: UNPACKEDPE |
Source: Yara match |
File source: 4.3.gajb.pif.4eddf28.4.raw.unpack, type: UNPACKEDPE |
Source: Yara match |
File source: 4.3.gajb.pif.4efdf30.15.unpack, type: UNPACKEDPE |
Source: Yara match |
File source: 6.2.RegSvcs.exe.b00000.0.raw.unpack, type: UNPACKEDPE |
Source: Yara match |
File source: 4.3.gajb.pif.4eddf28.6.raw.unpack, type: UNPACKEDPE |
Source: Yara match |
File source: 7.3.gajb.pif.3e2df30.9.raw.unpack, type: UNPACKEDPE |
Source: Yara match |
File source: 7.3.gajb.pif.3e2df30.4.raw.unpack, type: UNPACKEDPE |
Source: Yara match |
File source: 4.3.gajb.pif.4efdf30.7.raw.unpack, type: UNPACKEDPE |
Source: Yara match |
File source: 4.3.gajb.pif.4eddf28.16.raw.unpack, type: UNPACKEDPE |
Source: Yara match |
File source: 7.3.gajb.pif.3e2df30.0.raw.unpack, type: UNPACKEDPE |
Source: Yara match |
File source: 4.3.gajb.pif.4eddf28.11.raw.unpack, type: UNPACKEDPE |
Source: Yara match |
File source: 4.3.gajb.pif.4efdf30.3.raw.unpack, type: UNPACKEDPE |
Source: Yara match |
File source: 4.3.gajb.pif.4efdf30.5.raw.unpack, type: UNPACKEDPE |
Source: Yara match |
File source: 4.3.gajb.pif.41a67d0.18.raw.unpack, type: UNPACKEDPE |
Source: Yara match |
File source: 4.3.gajb.pif.4efdf30.17.unpack, type: UNPACKEDPE |
Source: Yara match |
File source: 4.3.gajb.pif.4efdf30.0.raw.unpack, type: UNPACKEDPE |
Source: Yara match |
File source: 4.3.gajb.pif.4eddf28.8.unpack, type: UNPACKEDPE |
Source: Yara match |
File source: 4.3.gajb.pif.4efdf30.1.unpack, type: UNPACKEDPE |
Source: Yara match |
File source: 7.3.gajb.pif.3e0df28.6.raw.unpack, type: UNPACKEDPE |
Source: Yara match |
File source: 4.3.gajb.pif.4eddf28.6.unpack, type: UNPACKEDPE |
Source: Yara match |
File source: 00000004.00000003.363037979.0000000004E91000.00000004.00000001.sdmp, type: MEMORY |
Source: Yara match |
File source: 00000004.00000003.368157698.0000000004EDE000.00000004.00000001.sdmp, type: MEMORY |
Source: Yara match |
File source: 00000007.00000003.394956149.00000000030E8000.00000004.00000001.sdmp, type: MEMORY |
Source: Yara match |
File source: 00000004.00000003.362785019.0000000004EDE000.00000004.00000001.sdmp, type: MEMORY |
Source: Yara match |
File source: 00000007.00000003.394845153.00000000030E4000.00000004.00000001.sdmp, type: MEMORY |
Source: Yara match |
File source: 00000007.00000003.392597947.0000000003E2E000.00000004.00000001.sdmp, type: MEMORY |
Source: Yara match |
File source: 00000004.00000003.363087933.0000000004E91000.00000004.00000001.sdmp, type: MEMORY |
Source: Yara match |
File source: 00000004.00000003.368298826.0000000004183000.00000004.00000001.sdmp, type: MEMORY |
Source: Yara match |
File source: 00000007.00000003.394884254.0000000003E01000.00000004.00000001.sdmp, type: MEMORY |
Source: Yara match |
File source: 00000007.00000003.392716765.0000000003E2D000.00000004.00000001.sdmp, type: MEMORY |
Source: Yara match |
File source: 00000007.00000003.392613575.0000000003E0E000.00000004.00000001.sdmp, type: MEMORY |
Source: Yara match |
File source: 00000004.00000003.368190067.0000000004E91000.00000004.00000001.sdmp, type: MEMORY |
Source: Yara match |
File source: 00000007.00000003.395236457.0000000003E2D000.00000004.00000001.sdmp, type: MEMORY |
Source: Yara match |
File source: 00000007.00000003.394633722.0000000003DC1000.00000004.00000001.sdmp, type: MEMORY |
Source: Yara match |
File source: 00000007.00000003.392497684.0000000003E0D000.00000004.00000001.sdmp, type: MEMORY |
Source: Yara match |
File source: 00000007.00000003.395044365.0000000003E0D000.00000004.00000001.sdmp, type: MEMORY |
Source: Yara match |
File source: 00000004.00000003.363208796.0000000004F1F000.00000004.00000001.sdmp, type: MEMORY |
Source: Yara match |
File source: 00000007.00000003.395138441.0000000003E0E000.00000004.00000001.sdmp, type: MEMORY |
Source: Yara match |
File source: 00000007.00000003.394775886.0000000003E0D000.00000004.00000001.sdmp, type: MEMORY |
Source: Yara match |
File source: 00000007.00000003.392562844.00000000030E8000.00000004.00000001.sdmp, type: MEMORY |
Source: Yara match |
File source: 00000004.00000003.365775815.0000000004EDD000.00000004.00000001.sdmp, type: MEMORY |
Source: Yara match |
File source: 00000007.00000003.394897994.0000000003E0D000.00000004.00000001.sdmp, type: MEMORY |
Source: Yara match |
File source: 00000004.00000003.368263690.00000000041A6000.00000004.00000001.sdmp, type: MEMORY |
Source: Yara match |
File source: 00000004.00000003.363139227.0000000004EB1000.00000004.00000001.sdmp, type: MEMORY |
Source: Yara match |
File source: 00000004.00000003.362829270.0000000004E91000.00000004.00000001.sdmp, type: MEMORY |
Source: Yara match |
File source: 00000004.00000003.364800207.0000000004EDD000.00000004.00000001.sdmp, type: MEMORY |
Source: Yara match |
File source: 0000000A.00000002.395200943.0000000002C40000.00000004.00000040.sdmp, type: MEMORY |
Source: Yara match |
File source: 00000004.00000003.363109577.0000000004EDD000.00000004.00000001.sdmp, type: MEMORY |
Source: Yara match |
File source: 00000004.00000003.362748203.0000000004EDD000.00000004.00000001.sdmp, type: MEMORY |
Source: Yara match |
File source: 00000004.00000003.362850029.0000000004EDD000.00000004.00000001.sdmp, type: MEMORY |
Source: Yara match |
File source: 00000006.00000002.604178944.0000000000B00000.00000040.00000001.sdmp, type: MEMORY |
Source: Yara match |
File source: 00000004.00000003.368145080.0000000004F20000.00000004.00000001.sdmp, type: MEMORY |
Source: Yara match |
File source: 00000004.00000003.367804453.0000000004EFE000.00000004.00000001.sdmp, type: MEMORY |
Source: Yara match |
File source: 00000007.00000003.392774240.0000000003E4F000.00000004.00000001.sdmp, type: MEMORY |
Source: Yara match |
File source: 00000007.00000003.392430101.0000000003E0E000.00000004.00000001.sdmp, type: MEMORY |
Source: Yara match |
File source: 00000006.00000002.605185347.0000000002E90000.00000004.00000040.sdmp, type: MEMORY |
Source: Yara match |
File source: 00000004.00000003.362989854.0000000004EDD000.00000004.00000001.sdmp, type: MEMORY |
Source: Yara match |
File source: 00000004.00000003.363056424.0000000004EDD000.00000004.00000001.sdmp, type: MEMORY |
Source: Yara match |
File source: 00000007.00000003.392475891.0000000003DC1000.00000004.00000001.sdmp, type: MEMORY |
Source: Yara match |
File source: 00000004.00000003.365073207.0000000004EDD000.00000004.00000001.sdmp, type: MEMORY |
Source: Yara match |
File source: 00000004.00000003.362894368.00000000041A6000.00000004.00000001.sdmp, type: MEMORY |
Source: Yara match |
File source: 00000004.00000003.362921698.0000000004EFE000.00000004.00000001.sdmp, type: MEMORY |
Source: Yara match |
File source: 00000007.00000003.394990382.0000000003DE0000.00000004.00000001.sdmp, type: MEMORY |
Source: Yara match |
File source: 0000000A.00000002.394968459.0000000000720000.00000040.00000001.sdmp, type: MEMORY |
Source: Yara match |
File source: 00000004.00000003.363159769.0000000004EDD000.00000004.00000001.sdmp, type: MEMORY |
Source: Yara match |
File source: 00000004.00000003.363020662.0000000004EFE000.00000004.00000001.sdmp, type: MEMORY |
Source: Yara match |
File source: 00000007.00000003.392846038.0000000003E0D000.00000004.00000001.sdmp, type: MEMORY |
Source: Yara match |
File source: Process Memory Space: gajb.pif PID: 7164, type: MEMORYSTR |
Source: Yara match |
File source: Process Memory Space: RegSvcs.exe PID: 6288, type: MEMORYSTR |
Source: Yara match |
File source: Process Memory Space: gajb.pif PID: 4752, type: MEMORYSTR |
Source: Yara match |
File source: Process Memory Space: RegSvcs.exe PID: 4124, type: MEMORYSTR |
Source: 7.3.gajb.pif.30e7c20.11.unpack |
Avira: Label: TR/Patched.Ren.Gen |
Source: 10.2.RegSvcs.exe.720000.0.unpack |
Avira: Label: BDS/Backdoor.Gen |
Source: 4.3.gajb.pif.4eddf28.14.unpack |
Avira: Label: BDS/Backdoor.Gen |
Source: 6.2.RegSvcs.exe.b00000.0.unpack |
Avira: Label: BDS/Backdoor.Gen |
Source: 4.3.gajb.pif.4efdf30.3.unpack |
Avira: Label: BDS/Backdoor.Gen |
Source: 4.3.gajb.pif.4efdf30.7.unpack |
Avira: Label: BDS/Backdoor.Gen |
Source: 4.3.gajb.pif.4eddf28.13.unpack |
Avira: Label: BDS/Backdoor.Gen |
Source: 7.3.gajb.pif.3e0df28.14.unpack |
Avira: Label: TR/Patched.Ren.Gen |
Source: 7.3.gajb.pif.3e2df30.7.unpack |
Avira: Label: TR/Patched.Ren.Gen |
Source: 4.3.gajb.pif.4eddf28.11.unpack |
Avira: Label: BDS/Backdoor.Gen |
Source: 7.3.gajb.pif.3e2df30.13.unpack |
Avira: Label: TR/Patched.Ren.Gen |
Source: 4.3.gajb.pif.4eddf28.2.unpack |
Avira: Label: BDS/Backdoor.Gen |
Source: 7.3.gajb.pif.3e0df28.2.unpack |
Avira: Label: TR/Patched.Ren.Gen |
Source: 4.3.gajb.pif.4efdf30.0.unpack |
Avira: Label: BDS/Backdoor.Gen |
Source: 4.3.gajb.pif.4eddf28.16.unpack |
Avira: Label: BDS/Backdoor.Gen |
Source: 4.3.gajb.pif.4efdf30.10.unpack |
Avira: Label: BDS/Backdoor.Gen |
Source: 7.3.gajb.pif.3e0df28.12.unpack |
Avira: Label: TR/Patched.Ren.Gen |
Source: 7.3.gajb.pif.3e2df30.17.unpack |
Avira: Label: TR/Patched.Ren.Gen |
Source: 7.3.gajb.pif.3e2df30.9.unpack |
Avira: Label: TR/Patched.Ren.Gen |
Source: 4.3.gajb.pif.4efdf30.5.unpack |
Avira: Label: BDS/Backdoor.Gen |
Source: 7.3.gajb.pif.3e2df30.3.unpack |
Avira: Label: TR/Patched.Ren.Gen |
Source: 4.3.gajb.pif.41a67d0.18.unpack |
Avira: Label: TR/Patched.Ren.Gen |
Source: 4.3.gajb.pif.4f1e740.9.unpack |
Avira: Label: TR/Patched.Ren.Gen |
Source: 7.3.gajb.pif.3e2df30.4.unpack |
Avira: Label: TR/Patched.Ren.Gen |
Source: 7.3.gajb.pif.3de0050.8.unpack |
Avira: Label: TR/Patched.Ren.Gen |
Source: 4.3.gajb.pif.4efdf30.12.unpack |
Avira: Label: BDS/Backdoor.Gen |
Source: 7.3.gajb.pif.3e2df30.16.unpack |
Avira: Label: TR/Patched.Ren.Gen |
Source: 7.3.gajb.pif.3e2df30.1.unpack |
Avira: Label: TR/Patched.Ren.Gen |
Source: 7.3.gajb.pif.3e0df28.10.unpack |
Avira: Label: TR/Patched.Ren.Gen |
Source: 7.3.gajb.pif.3e6e748.5.unpack |
Avira: Label: TR/Patched.Ren.Gen |
Source: 4.3.gajb.pif.4eddf28.4.unpack |
Avira: Label: BDS/Backdoor.Gen |
Source: 4.3.gajb.pif.4efdf30.15.unpack |
Avira: Label: BDS/Backdoor.Gen |
Source: 7.3.gajb.pif.3e0df28.6.unpack |
Avira: Label: TR/Patched.Ren.Gen |
Source: 4.3.gajb.pif.4efdf30.17.unpack |
Avira: Label: BDS/Backdoor.Gen |
Source: 4.3.gajb.pif.4efdf30.1.unpack |
Avira: Label: BDS/Backdoor.Gen |
Source: 7.3.gajb.pif.3e2df30.15.unpack |
Avira: Label: TR/Patched.Ren.Gen |
Source: 4.3.gajb.pif.4eddf28.6.unpack |
Avira: Label: BDS/Backdoor.Gen |
Source: 4.3.gajb.pif.4eddf28.8.unpack |
Avira: Label: BDS/Backdoor.Gen |
Source: 7.3.gajb.pif.3e2df30.0.unpack |
Avira: Label: TR/Patched.Ren.Gen |