Source: C:\Users\user\Desktop\Halkbank02.exe |
Code function: 4x nop then mov ebx, ebx |
1_2_00401500 |
Source: C:\Users\user\Desktop\Halkbank02.exe |
Code function: 5x nop then xor eax, 4C849A4Bh |
1_2_00401500 |
Source: C:\Users\user\Desktop\Halkbank02.exe |
Code function: 4x nop then mov ebx, ebx |
1_2_00402872 |
Source: C:\Users\user\Desktop\Halkbank02.exe |
Code function: 5x nop then xor eax, 4C849A4Bh |
1_2_00402872 |
Source: C:\Users\user\Desktop\Halkbank02.exe |
Code function: 5x nop then xor eax, 4C849A4Bh |
1_2_00402C7A |
Source: C:\Users\user\Desktop\Halkbank02.exe |
Code function: 5x nop then xor eax, 4C849A4Bh |
1_2_00402E7C |
Source: C:\Users\user\Desktop\Halkbank02.exe |
Code function: 4x nop then mov ebx, ebx |
1_2_00402A0C |
Source: C:\Users\user\Desktop\Halkbank02.exe |
Code function: 5x nop then xor eax, 4C849A4Bh |
1_2_00402A0C |
Source: C:\Users\user\Desktop\Halkbank02.exe |
Code function: 5x nop then xor eax, 4C849A4Bh |
1_2_00402C3F |
Source: C:\Users\user\Desktop\Halkbank02.exe |
Code function: 4x nop then mov ebx, ebx |
1_2_004028F7 |
Source: C:\Users\user\Desktop\Halkbank02.exe |
Code function: 5x nop then xor eax, 4C849A4Bh |
1_2_004028F7 |
Source: C:\Users\user\Desktop\Halkbank02.exe |
Code function: 4x nop then mov ebx, ebx |
1_2_00402A81 |
Source: C:\Users\user\Desktop\Halkbank02.exe |
Code function: 5x nop then xor eax, 4C849A4Bh |
1_2_00402A81 |
Source: C:\Users\user\Desktop\Halkbank02.exe |
Code function: 4x nop then mov ebx, ebx |
1_2_004020A7 |
Source: C:\Users\user\Desktop\Halkbank02.exe |
Code function: 5x nop then xor eax, 4C849A4Bh |
1_2_004020A7 |
Source: C:\Users\user\Desktop\Halkbank02.exe |
Code function: 5x nop then xor eax, 4C849A4Bh |
1_2_00402B02 |
Source: C:\Users\user\Desktop\Halkbank02.exe |
Code function: 5x nop then xor eax, 4C849A4Bh |
1_2_00402D07 |
Source: C:\Users\user\Desktop\Halkbank02.exe |
Code function: 5x nop then xor eax, 4C849A4Bh |
1_2_00402F0C |
Source: C:\Users\user\Desktop\Halkbank02.exe |
Code function: 4x nop then mov ebx, ebx |
1_2_004027DC |
Source: C:\Users\user\Desktop\Halkbank02.exe |
Code function: 5x nop then xor eax, 4C849A4Bh |
1_2_004027DC |
Source: C:\Users\user\Desktop\Halkbank02.exe |
Code function: 5x nop then xor eax, 4C849A4Bh |
1_2_00402DF6 |
Source: C:\Users\user\Desktop\Halkbank02.exe |
Code function: 5x nop then xor eax, 4C849A4Bh |
1_2_00402B84 |
Source: C:\Users\user\Desktop\Halkbank02.exe |
Code function: 4x nop then mov ebx, ebx |
1_2_0040298D |
Source: C:\Users\user\Desktop\Halkbank02.exe |
Code function: 5x nop then xor eax, 4C849A4Bh |
1_2_0040298D |
Source: C:\Users\user\Desktop\Halkbank02.exe |
Code function: 5x nop then xor eax, 4C849A4Bh |
1_2_00402F9E |
Source: 00000001.00000002.772950247.0000000000410000.00000020.00020000.sdmp, type: MEMORY |
Matched rule: LokiBot_Dropper_Packed_R11_Feb18 date = 2018-02-14, hash1 = 3b248d40fd7acb839cc592def1ed7652734e0e5ef93368be3c36c042883a3029, author = Florian Roth, description = Auto-generated rule - file scan copy.pdf.r11, reference = https://app.any.run/tasks/401df4d9-098b-4fd0-86e0-7a52ce6ddbf5, license = Detection Rule License 1.1 https://github.com/Neo23x0/signature-base/blob/master/LICENSE |
Source: 00000001.00000000.247791172.0000000000410000.00000020.00020000.sdmp, type: MEMORY |
Matched rule: LokiBot_Dropper_Packed_R11_Feb18 date = 2018-02-14, hash1 = 3b248d40fd7acb839cc592def1ed7652734e0e5ef93368be3c36c042883a3029, author = Florian Roth, description = Auto-generated rule - file scan copy.pdf.r11, reference = https://app.any.run/tasks/401df4d9-098b-4fd0-86e0-7a52ce6ddbf5, license = Detection Rule License 1.1 https://github.com/Neo23x0/signature-base/blob/master/LICENSE |
Source: C:\Users\user\Desktop\Halkbank02.exe |
Code function: 1_2_00401500 |
1_2_00401500 |
Source: C:\Users\user\Desktop\Halkbank02.exe |
Code function: 1_2_00402872 |
1_2_00402872 |
Source: C:\Users\user\Desktop\Halkbank02.exe |
Code function: 1_2_00402C7A |
1_2_00402C7A |
Source: C:\Users\user\Desktop\Halkbank02.exe |
Code function: 1_2_00402A0C |
1_2_00402A0C |
Source: C:\Users\user\Desktop\Halkbank02.exe |
Code function: 1_2_00402C3F |
1_2_00402C3F |
Source: C:\Users\user\Desktop\Halkbank02.exe |
Code function: 1_2_004028F7 |
1_2_004028F7 |
Source: C:\Users\user\Desktop\Halkbank02.exe |
Code function: 1_2_00402A81 |
1_2_00402A81 |
Source: C:\Users\user\Desktop\Halkbank02.exe |
Code function: 1_2_004020A7 |
1_2_004020A7 |
Source: C:\Users\user\Desktop\Halkbank02.exe |
Code function: 1_2_00401550 |
1_2_00401550 |
Source: C:\Users\user\Desktop\Halkbank02.exe |
Code function: 1_2_00402B02 |
1_2_00402B02 |
Source: C:\Users\user\Desktop\Halkbank02.exe |
Code function: 1_2_004027DC |
1_2_004027DC |
Source: C:\Users\user\Desktop\Halkbank02.exe |
Code function: 1_2_00402B84 |
1_2_00402B84 |
Source: C:\Users\user\Desktop\Halkbank02.exe |
Code function: 1_2_0040298D |
1_2_0040298D |
Source: C:\Users\user\Desktop\Halkbank02.exe |
Code function: 1_2_02BD65A4 |
1_2_02BD65A4 |
Source: C:\Users\user\Desktop\Halkbank02.exe |
Code function: 1_2_02BD46B6 |
1_2_02BD46B6 |
Source: C:\Users\user\Desktop\Halkbank02.exe |
Code function: 1_2_02BD18AE |
1_2_02BD18AE |
Source: C:\Users\user\Desktop\Halkbank02.exe |
Code function: 1_2_02BD38A1 |
1_2_02BD38A1 |
Source: C:\Users\user\Desktop\Halkbank02.exe |
Code function: 1_2_02BD9AA0 |
1_2_02BD9AA0 |
Source: C:\Users\user\Desktop\Halkbank02.exe |
Code function: 1_2_02BD4AA3 |
1_2_02BD4AA3 |
Source: C:\Users\user\Desktop\Halkbank02.exe |
Code function: 1_2_02BD7294 |
1_2_02BD7294 |
Source: C:\Users\user\Desktop\Halkbank02.exe |
Code function: 1_2_02BD3093 |
1_2_02BD3093 |
Source: C:\Users\user\Desktop\Halkbank02.exe |
Code function: 1_2_02BD628F |
1_2_02BD628F |
Source: C:\Users\user\Desktop\Halkbank02.exe |
Code function: 1_2_02BD8E8E |
1_2_02BD8E8E |
Source: C:\Users\user\Desktop\Halkbank02.exe |
Code function: 1_2_02BD248A |
1_2_02BD248A |
Source: C:\Users\user\Desktop\Halkbank02.exe |
Code function: 1_2_02BD22F6 |
1_2_02BD22F6 |
Source: C:\Users\user\Desktop\Halkbank02.exe |
Code function: 1_2_02BD90F3 |
1_2_02BD90F3 |
Source: C:\Users\user\Desktop\Halkbank02.exe |
Code function: 1_2_02BD28EB |
1_2_02BD28EB |
Source: C:\Users\user\Desktop\Halkbank02.exe |
Code function: 1_2_02BD98EA |
1_2_02BD98EA |
Source: C:\Users\user\Desktop\Halkbank02.exe |
Code function: 1_2_02BD8EE0 |
1_2_02BD8EE0 |
Source: C:\Users\user\Desktop\Halkbank02.exe |
Code function: 1_2_02BD08DF |
1_2_02BD08DF |
Source: C:\Users\user\Desktop\Halkbank02.exe |
Code function: 1_2_02BDA8D9 |
1_2_02BDA8D9 |
Source: C:\Users\user\Desktop\Halkbank02.exe |
Code function: 1_2_02BDACD7 |
1_2_02BDACD7 |
Source: C:\Users\user\Desktop\Halkbank02.exe |
Code function: 1_2_02BD50D3 |
1_2_02BD50D3 |
Source: C:\Users\user\Desktop\Halkbank02.exe |
Code function: 1_2_02BD52C8 |
1_2_02BD52C8 |
Source: C:\Users\user\Desktop\Halkbank02.exe |
Code function: 1_2_02BD022B |
1_2_02BD022B |
Source: C:\Users\user\Desktop\Halkbank02.exe |
Code function: 1_2_02BD122A |
1_2_02BD122A |
Source: C:\Users\user\Desktop\Halkbank02.exe |
Code function: 1_2_02BD4E25 |
1_2_02BD4E25 |
Source: C:\Users\user\Desktop\Halkbank02.exe |
Code function: 1_2_02BD2024 |
1_2_02BD2024 |
Source: C:\Users\user\Desktop\Halkbank02.exe |
Code function: 1_2_02BDA00E |
1_2_02BDA00E |
Source: C:\Users\user\Desktop\Halkbank02.exe |
Code function: 1_2_02BD060B |
1_2_02BD060B |
Source: C:\Users\user\Desktop\Halkbank02.exe |
Code function: 1_2_02BD0E01 |
1_2_02BD0E01 |
Source: C:\Users\user\Desktop\Halkbank02.exe |
Code function: 1_2_02BD3673 |
1_2_02BD3673 |
Source: C:\Users\user\Desktop\Halkbank02.exe |
Code function: 1_2_02BD146E |
1_2_02BD146E |
Source: C:\Users\user\Desktop\Halkbank02.exe |
Code function: 1_2_02BD2850 |
1_2_02BD2850 |
Source: C:\Users\user\Desktop\Halkbank02.exe |
Code function: 1_2_02BD8452 |
1_2_02BD8452 |
Source: C:\Users\user\Desktop\Halkbank02.exe |
Code function: 1_2_02BD0A46 |
1_2_02BD0A46 |
Source: C:\Users\user\Desktop\Halkbank02.exe |
Code function: 1_2_02BD1C46 |
1_2_02BD1C46 |
Source: C:\Users\user\Desktop\Halkbank02.exe |
Code function: 1_2_02BD1592 |
1_2_02BD1592 |
Source: C:\Users\user\Desktop\Halkbank02.exe |
Code function: 1_2_02BD4983 |
1_2_02BD4983 |
Source: C:\Users\user\Desktop\Halkbank02.exe |
Code function: 1_2_02BD4DF9 |
1_2_02BD4DF9 |
Source: C:\Users\user\Desktop\Halkbank02.exe |
Code function: 1_2_02BD41F0 |
1_2_02BD41F0 |
Source: C:\Users\user\Desktop\Halkbank02.exe |
Code function: 1_2_02BD85E3 |
1_2_02BD85E3 |
Source: C:\Users\user\Desktop\Halkbank02.exe |
Code function: 1_2_02BD69DD |
1_2_02BD69DD |
Source: C:\Users\user\Desktop\Halkbank02.exe |
Code function: 1_2_02BD05DF |
1_2_02BD05DF |
Source: C:\Users\user\Desktop\Halkbank02.exe |
Code function: 1_2_02BD89D6 |
1_2_02BD89D6 |
Source: C:\Users\user\Desktop\Halkbank02.exe |
Code function: 1_2_02BD4DD3 |
1_2_02BD4DD3 |
Source: C:\Users\user\Desktop\Halkbank02.exe |
Code function: 1_2_02BD37D2 |
1_2_02BD37D2 |
Source: C:\Users\user\Desktop\Halkbank02.exe |
Code function: 1_2_02BDA7C9 |
1_2_02BDA7C9 |
Source: C:\Users\user\Desktop\Halkbank02.exe |
Code function: 1_2_02BD9DC1 |
1_2_02BD9DC1 |
Source: C:\Users\user\Desktop\Halkbank02.exe |
Code function: 1_2_02BD9DC3 |
1_2_02BD9DC3 |
Source: C:\Users\user\Desktop\Halkbank02.exe |
Code function: 1_2_02BD99C2 |
1_2_02BD99C2 |
Source: C:\Users\user\Desktop\Halkbank02.exe |
Code function: 1_2_02BD1138 |
1_2_02BD1138 |
Source: C:\Users\user\Desktop\Halkbank02.exe |
Code function: 1_2_02BD352D |
1_2_02BD352D |
Source: C:\Users\user\Desktop\Halkbank02.exe |
Code function: 1_2_02BD0D2C |
1_2_02BD0D2C |
Source: C:\Users\user\Desktop\Halkbank02.exe |
Code function: 1_2_02BD2F1D |
1_2_02BD2F1D |
Source: C:\Users\user\Desktop\Halkbank02.exe |
Code function: 1_2_02BD9B0D |
1_2_02BD9B0D |
Source: C:\Users\user\Desktop\Halkbank02.exe |
Code function: 1_2_02BD630A |
1_2_02BD630A |
Source: C:\Users\user\Desktop\Halkbank02.exe |
Code function: 1_2_02BD1B72 |
1_2_02BD1B72 |
Source: C:\Users\user\Desktop\Halkbank02.exe |
Code function: 1_2_02BD8D6F |
1_2_02BD8D6F |
Source: C:\Users\user\Desktop\Halkbank02.exe |
Code function: 1_2_02BD5963 |
1_2_02BD5963 |
Source: C:\Users\user\Desktop\Halkbank02.exe |
Code function: 1_2_02BD8F56 |
1_2_02BD8F56 |
Source: C:\Users\user\Desktop\Halkbank02.exe |
Code function: 1_2_02BD614D |
1_2_02BD614D |
Source: C:\Users\user\Desktop\Halkbank02.exe |
Code function: 1_2_02BD9149 |
1_2_02BD9149 |
Source: C:\Users\user\Desktop\Halkbank02.exe |
Code function: 1_2_02BD9745 |
1_2_02BD9745 |
Source: C:\Users\user\Desktop\Halkbank02.exe |
Code function: 1_2_02BD1340 |
1_2_02BD1340 |
Source: C:\Users\user\Desktop\Halkbank02.exe |
Code function: 1_2_02BD1143 |
1_2_02BD1143 |
Source: C:\Users\user\Desktop\Halkbank02.exe |
Code function: 1_2_00403640 push 966DCA76h; iretd |
1_2_00403645 |
Source: C:\Users\user\Desktop\Halkbank02.exe |
Code function: 1_2_00405A45 push esp; iretd |
1_2_00405A5A |
Source: C:\Users\user\Desktop\Halkbank02.exe |
Code function: 1_2_00403C65 push ds; iretd |
1_2_00403C6E |
Source: C:\Users\user\Desktop\Halkbank02.exe |
Code function: 1_2_00405E73 push ds; iretd |
1_2_00405E8A |
Source: C:\Users\user\Desktop\Halkbank02.exe |
Code function: 1_2_00404A75 push 7B3E4015h; iretd |
1_2_00404A7A |
Source: C:\Users\user\Desktop\Halkbank02.exe |
Code function: 1_2_00407231 push esp; retf |
1_2_00407234 |
Source: C:\Users\user\Desktop\Halkbank02.exe |
Code function: 1_2_004080C5 push E868A7E5h; iretd |
1_2_004080CA |
Source: C:\Users\user\Desktop\Halkbank02.exe |
Code function: 1_2_00406ED7 push esi; ret |
1_2_00406ED8 |
Source: C:\Users\user\Desktop\Halkbank02.exe |
Code function: 1_2_004082EB pushfd ; iretd |
1_2_004082F5 |
Source: C:\Users\user\Desktop\Halkbank02.exe |
Code function: 1_2_004080ED push 7767F77Ch; iretd |
1_2_004080F2 |
Source: C:\Users\user\Desktop\Halkbank02.exe |
Code function: 1_2_00408105 push 03C6A3FEh; iretd |
1_2_00408112 |
Source: C:\Users\user\Desktop\Halkbank02.exe |
Code function: 1_2_00407B29 pushfd ; retf |
1_2_00407B2A |
Source: C:\Users\user\Desktop\Halkbank02.exe |
Code function: 1_2_004061DD push 22BD4488h; iretd |
1_2_004061E6 |
Source: C:\Users\user\Desktop\Halkbank02.exe |
Code function: 1_2_02BD7409 pushfd ; iretd |
1_2_02BD7412 |
Source: C:\Users\user\Desktop\Halkbank02.exe |
Code function: 1_2_00401500 mov ebx, dword ptr fs:[00000030h] |
1_2_00401500 |
Source: C:\Users\user\Desktop\Halkbank02.exe |
Code function: 1_2_004020A7 mov ebx, dword ptr fs:[00000030h] |
1_2_004020A7 |
Source: C:\Users\user\Desktop\Halkbank02.exe |
Code function: 1_2_004027DC mov ebx, dword ptr fs:[00000030h] |
1_2_004027DC |
Source: C:\Users\user\Desktop\Halkbank02.exe |
Code function: 1_2_02BD88B2 mov eax, dword ptr fs:[00000030h] |
1_2_02BD88B2 |
Source: C:\Users\user\Desktop\Halkbank02.exe |
Code function: 1_2_02BD608C mov eax, dword ptr fs:[00000030h] |
1_2_02BD608C |
Source: C:\Users\user\Desktop\Halkbank02.exe |
Code function: 1_2_02BD41F0 mov eax, dword ptr fs:[00000030h] |
1_2_02BD41F0 |
Source: C:\Users\user\Desktop\Halkbank02.exe |
Code function: 1_2_02BD352D mov eax, dword ptr fs:[00000030h] |
1_2_02BD352D |
Source: C:\Users\user\Desktop\Halkbank02.exe |
Code function: 1_2_02BD8150 mov eax, dword ptr fs:[00000030h] |
1_2_02BD8150 |
Source: C:\Users\user\Desktop\Halkbank02.exe |
Code function: 1_2_02BD9745 mov eax, dword ptr fs:[00000030h] |
1_2_02BD9745 |
Source: Halkbank02.exe, 00000001.00000002.773637952.0000000000D60000.00000002.00020000.sdmp |
Binary or memory string: Shell_TrayWnd |
Source: Halkbank02.exe, 00000001.00000002.773637952.0000000000D60000.00000002.00020000.sdmp |
Binary or memory string: Progman |
Source: Halkbank02.exe, 00000001.00000002.773637952.0000000000D60000.00000002.00020000.sdmp |
Binary or memory string: SProgram Managerl |
Source: Halkbank02.exe, 00000001.00000002.773637952.0000000000D60000.00000002.00020000.sdmp |
Binary or memory string: Shell_TrayWnd, |
Source: Halkbank02.exe, 00000001.00000002.773637952.0000000000D60000.00000002.00020000.sdmp |
Binary or memory string: Progmanlock |