Windows Analysis Report Inquiry - Specifications 002021.exe

Overview

General Information

Sample Name: Inquiry - Specifications 002021.exe
Analysis ID: 491433
MD5: 768a1127c119149f96a29c0d0c0b56ec
SHA1: afe86ab8d4a8b5b092e95f1cb2ae563f5ea5867d
SHA256: 2442c3ecd04264f108429a954275ee27986e00b79cbce6d07843dfefdf4d24af
Tags: exe
Infos:

Most interesting Screenshot:

Detection

AgentTesla
Score: 100
Range: 0 - 100
Whitelisted: false
Confidence: 100%

Signatures

Found malware configuration
Snort IDS alert for network traffic (e.g. based on Emerging Threat rules)
Multi AV Scanner detection for submitted file
Yara detected AgentTesla
Yara detected AntiVM3
Installs a global keyboard hook
Tries to harvest and steal Putty / WinSCP information (sessions, passwords, etc)
Tries to harvest and steal ftp login credentials
Tries to detect sandboxes and other dynamic analysis tools (process name or module or function)
.NET source code contains potential unpacker
.NET source code contains very large array initializations
.NET source code contains very large strings
Moves itself to temp directory
Tries to steal Mail credentials (via file access)
Queries sensitive network adapter information (via WMI, Win32_NetworkAdapter, often done to detect virtual machines)
Tries to harvest and steal browser information (history, passwords, etc)
Queries sensitive BIOS Information (via WMI, Win32_Bios & Win32_BaseBoard, often done to detect virtual machines)
Uses 32bit PE files
Queries the volume information (name, serial number etc) of a device
Antivirus or Machine Learning detection for unpacked file
May sleep (evasive loops) to hinder dynamic analysis
Contains functionality to shutdown / reboot the system
Uses code obfuscation techniques (call, push, ret)
Internet Provider seen in connection with other malware
Detected potential crypto function
Yara detected Credential Stealer
Creates processes with suspicious names
IP address seen in connection with other malware
Contains long sleeps (>= 3 min)
Enables debug privileges
Creates a DirectInput object (often for capturing keystrokes)
Found a high number of Window / User specific system calls (may be a loop to detect user behavior)
Sample file is different than original file name gathered from version info
PE file contains strange resources
Detected TCP or UDP traffic on non-standard ports
Uses SMTP (mail sending)
Creates a window with clipboard capturing capabilities
Queries sensitive processor information (via WMI, Win32_Processor, often done to detect virtual machines)
Creates a process in suspended mode (likely to inject code)
Contains functionality to access loader functionality (e.g. LdrGetProcedureAddress)

Classification

AV Detection:

barindex
Found malware configuration
Source: 0.2.Inquiry - Specifications 002021.exe.35a8b58.4.unpack Malware Configuration Extractor: Agenttesla {"Exfil Mode": "SMTP", "Username": "annett.jalowi@vern-group.com", "Password": "HUSTLE2021", "Host": "smtp.vern-group.com"}
Multi AV Scanner detection for submitted file
Source: Inquiry - Specifications 002021.exe Virustotal: Detection: 7% Perma Link
Source: Inquiry - Specifications 002021.exe ReversingLabs: Detection: 42%
Antivirus or Machine Learning detection for unpacked file
Source: 5.2.Inquiry - Specifications 002021.exe.400000.0.unpack Avira: Label: TR/Spy.Gen8

Compliance:

barindex
Uses 32bit PE files
Source: Inquiry - Specifications 002021.exe Static PE information: 32BIT_MACHINE, EXECUTABLE_IMAGE
Source: Inquiry - Specifications 002021.exe Static PE information: NO_SEH, TERMINAL_SERVER_AWARE, DYNAMIC_BASE, NX_COMPAT

Networking:

barindex
Snort IDS alert for network traffic (e.g. based on Emerging Threat rules)
Source: Traffic Snort IDS: 2030171 ET TROJAN AgentTesla Exfil Via SMTP 192.168.2.3:49849 -> 208.91.198.143:587
Source: Traffic Snort IDS: 2030171 ET TROJAN AgentTesla Exfil Via SMTP 192.168.2.3:49850 -> 208.91.199.224:587
Internet Provider seen in connection with other malware
Source: Joe Sandbox View ASN Name: PUBLIC-DOMAIN-REGISTRYUS PUBLIC-DOMAIN-REGISTRYUS
IP address seen in connection with other malware
Source: Joe Sandbox View IP Address: 208.91.198.143 208.91.198.143
Source: Joe Sandbox View IP Address: 208.91.199.224 208.91.199.224
Detected TCP or UDP traffic on non-standard ports
Source: global traffic TCP traffic: 192.168.2.3:49849 -> 208.91.198.143:587
Source: global traffic TCP traffic: 192.168.2.3:49850 -> 208.91.199.224:587
Uses SMTP (mail sending)
Source: global traffic TCP traffic: 192.168.2.3:49849 -> 208.91.198.143:587
Source: global traffic TCP traffic: 192.168.2.3:49850 -> 208.91.199.224:587
Source: Inquiry - Specifications 002021.exe, 00000005.00000002.558228658.0000000002E01000.00000004.00000001.sdmp String found in binary or memory: http://127.0.0.1:HTTP/1.1
Source: Inquiry - Specifications 002021.exe, 00000005.00000002.558228658.0000000002E01000.00000004.00000001.sdmp String found in binary or memory: http://DynDns.comDynDNS
Source: Inquiry - Specifications 002021.exe, 00000000.00000002.331984585.00000000065C2000.00000004.00000001.sdmp String found in binary or memory: http://fontfabrik.com
Source: Inquiry - Specifications 002021.exe, 00000005.00000002.559762309.0000000003180000.00000004.00000001.sdmp String found in binary or memory: http://smtp.vern-group.com
Source: Inquiry - Specifications 002021.exe, 00000005.00000002.558228658.0000000002E01000.00000004.00000001.sdmp String found in binary or memory: http://tbdUKh.com
Source: Inquiry - Specifications 002021.exe, 00000005.00000002.559762309.0000000003180000.00000004.00000001.sdmp String found in binary or memory: http://us2.smtp.mailhostbox.com
Source: Inquiry - Specifications 002021.exe, 00000000.00000003.312590262.00000000053E0000.00000004.00000001.sdmp String found in binary or memory: http://www.agfamonotype.%AF
Source: Inquiry - Specifications 002021.exe, 00000000.00000002.331984585.00000000065C2000.00000004.00000001.sdmp String found in binary or memory: http://www.apache.org/licenses/LICENSE-2.0
Source: Inquiry - Specifications 002021.exe, 00000000.00000002.331984585.00000000065C2000.00000004.00000001.sdmp String found in binary or memory: http://www.carterandcone.coml
Source: Inquiry - Specifications 002021.exe, 00000000.00000002.331984585.00000000065C2000.00000004.00000001.sdmp String found in binary or memory: http://www.fontbureau.com
Source: Inquiry - Specifications 002021.exe, 00000000.00000002.331984585.00000000065C2000.00000004.00000001.sdmp String found in binary or memory: http://www.fontbureau.com/designers
Source: Inquiry - Specifications 002021.exe, 00000000.00000003.303059470.00000000053B9000.00000004.00000001.sdmp String found in binary or memory: http://www.fontbureau.com/designers/
Source: Inquiry - Specifications 002021.exe, 00000000.00000002.331984585.00000000065C2000.00000004.00000001.sdmp String found in binary or memory: http://www.fontbureau.com/designers/?
Source: Inquiry - Specifications 002021.exe, 00000000.00000003.304621163.00000000053DC000.00000004.00000001.sdmp, Inquiry - Specifications 002021.exe, 00000000.00000003.304589020.00000000053DC000.00000004.00000001.sdmp String found in binary or memory: http://www.fontbureau.com/designers/cabarga.html
Source: Inquiry - Specifications 002021.exe, 00000000.00000002.331984585.00000000065C2000.00000004.00000001.sdmp String found in binary or memory: http://www.fontbureau.com/designers/cabarga.htmlN
Source: Inquiry - Specifications 002021.exe, 00000000.00000002.331984585.00000000065C2000.00000004.00000001.sdmp String found in binary or memory: http://www.fontbureau.com/designers/frere-jones.html
Source: Inquiry - Specifications 002021.exe, 00000000.00000002.331984585.00000000065C2000.00000004.00000001.sdmp String found in binary or memory: http://www.fontbureau.com/designers8
Source: Inquiry - Specifications 002021.exe, 00000000.00000002.331984585.00000000065C2000.00000004.00000001.sdmp String found in binary or memory: http://www.fontbureau.com/designers?
Source: Inquiry - Specifications 002021.exe, 00000000.00000002.331984585.00000000065C2000.00000004.00000001.sdmp String found in binary or memory: http://www.fontbureau.com/designersG
Source: Inquiry - Specifications 002021.exe, 00000000.00000003.303059470.00000000053B9000.00000004.00000001.sdmp String found in binary or memory: http://www.fontbureau.com/designersl
Source: Inquiry - Specifications 002021.exe, 00000000.00000003.318162533.00000000053B0000.00000004.00000001.sdmp String found in binary or memory: http://www.fontbureau.comttvc
Source: Inquiry - Specifications 002021.exe, 00000000.00000003.318162533.00000000053B0000.00000004.00000001.sdmp String found in binary or memory: http://www.fontbureau.com~
Source: Inquiry - Specifications 002021.exe, 00000000.00000003.292829166.00000000053EE000.00000004.00000001.sdmp, Inquiry - Specifications 002021.exe, 00000000.00000003.292750034.00000000053EE000.00000004.00000001.sdmp String found in binary or memory: http://www.fonts.com
Source: Inquiry - Specifications 002021.exe, 00000000.00000003.292829166.00000000053EE000.00000004.00000001.sdmp String found in binary or memory: http://www.fonts.comON
Source: Inquiry - Specifications 002021.exe, 00000000.00000003.292829166.00000000053EE000.00000004.00000001.sdmp String found in binary or memory: http://www.fonts.comwN
Source: Inquiry - Specifications 002021.exe, 00000000.00000002.331984585.00000000065C2000.00000004.00000001.sdmp String found in binary or memory: http://www.founder.com.cn/cn
Source: Inquiry - Specifications 002021.exe, 00000000.00000002.331984585.00000000065C2000.00000004.00000001.sdmp String found in binary or memory: http://www.founder.com.cn/cn/bThe
Source: Inquiry - Specifications 002021.exe, 00000000.00000002.331984585.00000000065C2000.00000004.00000001.sdmp String found in binary or memory: http://www.founder.com.cn/cn/cThe
Source: Inquiry - Specifications 002021.exe, 00000000.00000002.331984585.00000000065C2000.00000004.00000001.sdmp String found in binary or memory: http://www.galapagosdesign.com/DPlease
Source: Inquiry - Specifications 002021.exe, 00000000.00000002.331984585.00000000065C2000.00000004.00000001.sdmp String found in binary or memory: http://www.galapagosdesign.com/staff/dennis.htm
Source: Inquiry - Specifications 002021.exe, 00000000.00000002.331984585.00000000065C2000.00000004.00000001.sdmp String found in binary or memory: http://www.goodfont.co.kr
Source: Inquiry - Specifications 002021.exe, 00000000.00000002.331984585.00000000065C2000.00000004.00000001.sdmp String found in binary or memory: http://www.jiyu-kobo.co.jp/
Source: Inquiry - Specifications 002021.exe, 00000000.00000003.304395330.00000000053DC000.00000004.00000001.sdmp String found in binary or memory: http://www.monotype.ccN/
Source: Inquiry - Specifications 002021.exe, 00000000.00000003.304499547.00000000053DC000.00000004.00000001.sdmp, Inquiry - Specifications 002021.exe, 00000000.00000003.304256608.00000000053DC000.00000004.00000001.sdmp String found in binary or memory: http://www.monotype.y
Source: Inquiry - Specifications 002021.exe String found in binary or memory: http://www.rspb.org.uk/wildlife/birdguide/name/
Source: Inquiry - Specifications 002021.exe, 00000000.00000003.293144259.00000000053CB000.00000004.00000001.sdmp, Inquiry - Specifications 002021.exe, 00000000.00000002.331984585.00000000065C2000.00000004.00000001.sdmp String found in binary or memory: http://www.sajatypeworks.com
Source: Inquiry - Specifications 002021.exe, 00000000.00000003.292167827.00000000053D0000.00000004.00000001.sdmp String found in binary or memory: http://www.sajatypeworks.com#
Source: Inquiry - Specifications 002021.exe, 00000000.00000003.292790308.00000000053CB000.00000004.00000001.sdmp String found in binary or memory: http://www.sajatypeworks.com-e
Source: Inquiry - Specifications 002021.exe, 00000000.00000003.292790308.00000000053CB000.00000004.00000001.sdmp String found in binary or memory: http://www.sajatypeworks.com=
Source: Inquiry - Specifications 002021.exe, 00000000.00000003.292167827.00000000053D0000.00000004.00000001.sdmp String found in binary or memory: http://www.sajatypeworks.comiv
Source: Inquiry - Specifications 002021.exe, 00000000.00000003.292451686.00000000053D0000.00000004.00000001.sdmp String found in binary or memory: http://www.sajatypeworks.comus
Source: Inquiry - Specifications 002021.exe, 00000000.00000003.292988250.00000000053CB000.00000004.00000001.sdmp String found in binary or memory: http://www.sajatypeworks.comus0
Source: Inquiry - Specifications 002021.exe, 00000000.00000003.292790308.00000000053CB000.00000004.00000001.sdmp String found in binary or memory: http://www.sajatypeworks.comusJ
Source: Inquiry - Specifications 002021.exe, 00000000.00000003.292814955.00000000053CB000.00000004.00000001.sdmp String found in binary or memory: http://www.sajatypeworks.comusW
Source: Inquiry - Specifications 002021.exe, 00000000.00000002.331984585.00000000065C2000.00000004.00000001.sdmp String found in binary or memory: http://www.sakkal.com
Source: Inquiry - Specifications 002021.exe, 00000000.00000002.331984585.00000000065C2000.00000004.00000001.sdmp String found in binary or memory: http://www.sandoll.co.kr
Source: Inquiry - Specifications 002021.exe, 00000000.00000002.331984585.00000000065C2000.00000004.00000001.sdmp String found in binary or memory: http://www.tiro.com
Source: Inquiry - Specifications 002021.exe, 00000000.00000003.293144259.00000000053CB000.00000004.00000001.sdmp String found in binary or memory: http://www.typography.net
Source: Inquiry - Specifications 002021.exe, 00000000.00000002.331984585.00000000065C2000.00000004.00000001.sdmp String found in binary or memory: http://www.typography.netD
Source: Inquiry - Specifications 002021.exe, 00000000.00000003.293144259.00000000053CB000.00000004.00000001.sdmp String found in binary or memory: http://www.typography.netI.TTFB5
Source: Inquiry - Specifications 002021.exe, 00000000.00000003.293144259.00000000053CB000.00000004.00000001.sdmp String found in binary or memory: http://www.typography.nete
Source: Inquiry - Specifications 002021.exe, 00000000.00000003.293144259.00000000053CB000.00000004.00000001.sdmp String found in binary or memory: http://www.typography.netl
Source: Inquiry - Specifications 002021.exe, 00000000.00000002.331984585.00000000065C2000.00000004.00000001.sdmp String found in binary or memory: http://www.urwpp.deDPlease
Source: Inquiry - Specifications 002021.exe, 00000000.00000002.331984585.00000000065C2000.00000004.00000001.sdmp String found in binary or memory: http://www.zhongyicts.com.cn
Source: Inquiry - Specifications 002021.exe, 00000005.00000002.559497777.00000000030EF000.00000004.00000001.sdmp String found in binary or memory: https://SAIitQOLdjJT1PWF4ciQ.net
Source: Inquiry - Specifications 002021.exe, 00000005.00000002.559497777.00000000030EF000.00000004.00000001.sdmp String found in binary or memory: https://SAIitQOLdjJT1PWF4ciQ.net(0
Source: Inquiry - Specifications 002021.exe, 00000000.00000002.329163786.00000000034D1000.00000004.00000001.sdmp, Inquiry - Specifications 002021.exe, 00000005.00000002.553693912.0000000000402000.00000040.00000001.sdmp String found in binary or memory: https://www.theonionrouter.com/dist.torproject.org/torbrowser/9.5.3/tor-win32-0.4.3.6.zip
Source: Inquiry - Specifications 002021.exe, 00000005.00000002.558228658.0000000002E01000.00000004.00000001.sdmp String found in binary or memory: https://www.theonionrouter.com/dist.torproject.org/torbrowser/9.5.3/tor-win32-0.4.3.6.zip%tordir%%ha
Source: unknown DNS traffic detected: queries for: smtp.vern-group.com

Key, Mouse, Clipboard, Microphone and Screen Capturing:

barindex
Installs a global keyboard hook
Source: C:\Users\user\Desktop\Inquiry - Specifications 002021.exe Windows user hook set: 0 keyboard low level C:\Users\user\Desktop\Inquiry - Specifications 002021.exe Jump to behavior
Creates a DirectInput object (often for capturing keystrokes)
Source: Inquiry - Specifications 002021.exe, 00000000.00000002.320291325.000000000089B000.00000004.00000020.sdmp Binary or memory string: <HOOK MODULE="DDRAW.DLL" FUNCTION="DirectDrawCreateEx"/>
Creates a window with clipboard capturing capabilities
Source: C:\Users\user\Desktop\Inquiry - Specifications 002021.exe Window created: window name: CLIPBRDWNDCLASS Jump to behavior

System Summary:

barindex
.NET source code contains very large array initializations
Source: 5.2.Inquiry - Specifications 002021.exe.400000.0.unpack, u003cPrivateImplementationDetailsu003eu007bE2C89848u002dC789u002d47AEu002d81EBu002d0E579C324E4Cu007d/u003011CEB48u002d442Bu002d4552u002dAD04u002dDFCA3A37BAA6.cs Large array initialization: .cctor: array initializer size 12003
.NET source code contains very large strings
Source: Inquiry - Specifications 002021.exe, Darwin.WindowsForm/SearchResults.cs Long String: Length: 34816
Source: 0.0.Inquiry - Specifications 002021.exe.70000.0.unpack, Darwin.WindowsForm/SearchResults.cs Long String: Length: 34816
Source: 0.2.Inquiry - Specifications 002021.exe.70000.0.unpack, Darwin.WindowsForm/SearchResults.cs Long String: Length: 34816
Source: 5.0.Inquiry - Specifications 002021.exe.a10000.0.unpack, Darwin.WindowsForm/SearchResults.cs Long String: Length: 34816
Source: 5.2.Inquiry - Specifications 002021.exe.a10000.1.unpack, Darwin.WindowsForm/SearchResults.cs Long String: Length: 34816
Uses 32bit PE files
Source: Inquiry - Specifications 002021.exe Static PE information: 32BIT_MACHINE, EXECUTABLE_IMAGE
Contains functionality to shutdown / reboot the system
Source: C:\Users\user\Desktop\Inquiry - Specifications 002021.exe Code function: 5_2_01210A70 KiUserExceptionDispatcher,GetClassInfoExA,KiUserExceptionDispatcher,CreateIconFromResourceEx,GetWindowWord,LdrInitializeThunk,DispatchMessageA,SetDeskWallpaper,EnumPropsA,GetDpiForMonitorInternal,GetMessageA,ExitWindowsEx, 5_2_01210A70
Source: C:\Users\user\Desktop\Inquiry - Specifications 002021.exe Code function: 5_2_01210A70 KiUserExceptionDispatcher,GetClassInfoExA,KiUserExceptionDispatcher,CreateIconFromResourceEx,GetWindowWord,LdrInitializeThunk,DispatchMessageA,SetDeskWallpaper,EnumPropsA,GetDpiForMonitorInternal,GetMessageA,ExitWindowsEx, 5_2_01210A70
Detected potential crypto function
Source: C:\Users\user\Desktop\Inquiry - Specifications 002021.exe Code function: 0_2_001193CF 0_2_001193CF
Source: C:\Users\user\Desktop\Inquiry - Specifications 002021.exe Code function: 0_2_000793F1 0_2_000793F1
Source: C:\Users\user\Desktop\Inquiry - Specifications 002021.exe Code function: 0_2_0087C194 0_2_0087C194
Source: C:\Users\user\Desktop\Inquiry - Specifications 002021.exe Code function: 0_2_0087E5F0 0_2_0087E5F0
Source: C:\Users\user\Desktop\Inquiry - Specifications 002021.exe Code function: 5_2_00A193F1 5_2_00A193F1
Source: C:\Users\user\Desktop\Inquiry - Specifications 002021.exe Code function: 5_2_00AB93CF 5_2_00AB93CF
Source: C:\Users\user\Desktop\Inquiry - Specifications 002021.exe Code function: 5_2_00FD2090 5_2_00FD2090
Source: C:\Users\user\Desktop\Inquiry - Specifications 002021.exe Code function: 5_2_00FDB28F 5_2_00FDB28F
Source: C:\Users\user\Desktop\Inquiry - Specifications 002021.exe Code function: 5_2_00FD6FD0 5_2_00FD6FD0
Source: C:\Users\user\Desktop\Inquiry - Specifications 002021.exe Code function: 5_2_00FD0690 5_2_00FD0690
Source: C:\Users\user\Desktop\Inquiry - Specifications 002021.exe Code function: 5_2_00FD9380 5_2_00FD9380
Source: C:\Users\user\Desktop\Inquiry - Specifications 002021.exe Code function: 5_2_01216510 5_2_01216510
Source: C:\Users\user\Desktop\Inquiry - Specifications 002021.exe Code function: 5_2_01215DD8 5_2_01215DD8
Source: C:\Users\user\Desktop\Inquiry - Specifications 002021.exe Code function: 5_2_012157A0 5_2_012157A0
Source: C:\Users\user\Desktop\Inquiry - Specifications 002021.exe Code function: 5_2_0121EAE8 5_2_0121EAE8
Source: C:\Users\user\Desktop\Inquiry - Specifications 002021.exe Code function: 5_2_014A4860 5_2_014A4860
Source: C:\Users\user\Desktop\Inquiry - Specifications 002021.exe Code function: 5_2_014A4770 5_2_014A4770
Sample file is different than original file name gathered from version info
Source: Inquiry - Specifications 002021.exe, 00000000.00000002.322874820.000000000254D000.00000004.00000001.sdmp Binary or memory string: OriginalFilenameColladaLoader.dll4 vs Inquiry - Specifications 002021.exe
Source: Inquiry - Specifications 002021.exe, 00000000.00000002.329163786.00000000034D1000.00000004.00000001.sdmp Binary or memory string: OriginalFilenameqSvvtNEnodCAvWfjURpxZnu.exe4 vs Inquiry - Specifications 002021.exe
Source: Inquiry - Specifications 002021.exe, 00000000.00000002.329163786.00000000034D1000.00000004.00000001.sdmp Binary or memory string: OriginalFilenameCF_Secretaria.dll< vs Inquiry - Specifications 002021.exe
Source: Inquiry - Specifications 002021.exe, 00000000.00000002.319293042.0000000000140000.00000002.00020000.sdmp Binary or memory string: OriginalFilenameTaskAwait.exe4 vs Inquiry - Specifications 002021.exe
Source: Inquiry - Specifications 002021.exe, 00000000.00000002.320291325.000000000089B000.00000004.00000020.sdmp Binary or memory string: OriginalFilenameclr.dllT vs Inquiry - Specifications 002021.exe
Source: Inquiry - Specifications 002021.exe, 00000005.00000000.317737287.0000000000AE0000.00000002.00020000.sdmp Binary or memory string: OriginalFilenameTaskAwait.exe4 vs Inquiry - Specifications 002021.exe
Source: Inquiry - Specifications 002021.exe, 00000005.00000002.553693912.0000000000402000.00000040.00000001.sdmp Binary or memory string: OriginalFilenameqSvvtNEnodCAvWfjURpxZnu.exe4 vs Inquiry - Specifications 002021.exe
Source: Inquiry - Specifications 002021.exe, 00000005.00000002.554538047.0000000000EF8000.00000004.00000001.sdmp Binary or memory string: OriginalFilenameUNKNOWN_FILET vs Inquiry - Specifications 002021.exe
Source: Inquiry - Specifications 002021.exe Binary or memory string: OriginalFilenameTaskAwait.exe4 vs Inquiry - Specifications 002021.exe
PE file contains strange resources
Source: Inquiry - Specifications 002021.exe Static PE information: Resource name: RT_ICON type: GLS_BINARY_LSB_FIRST
Source: Inquiry - Specifications 002021.exe Virustotal: Detection: 7%
Source: Inquiry - Specifications 002021.exe ReversingLabs: Detection: 42%
Source: Inquiry - Specifications 002021.exe Static PE information: Section: .text IMAGE_SCN_MEM_EXECUTE, IMAGE_SCN_CNT_CODE, IMAGE_SCN_MEM_READ
Source: C:\Users\user\Desktop\Inquiry - Specifications 002021.exe Key opened: HKEY_CURRENT_USER\Software\Policies\Microsoft\Windows\Safer\CodeIdentifiers Jump to behavior
Source: unknown Process created: C:\Users\user\Desktop\Inquiry - Specifications 002021.exe 'C:\Users\user\Desktop\Inquiry - Specifications 002021.exe'
Source: C:\Users\user\Desktop\Inquiry - Specifications 002021.exe Process created: C:\Users\user\Desktop\Inquiry - Specifications 002021.exe C:\Users\user\Desktop\Inquiry - Specifications 002021.exe
Source: C:\Users\user\Desktop\Inquiry - Specifications 002021.exe Process created: C:\Users\user\Desktop\Inquiry - Specifications 002021.exe C:\Users\user\Desktop\Inquiry - Specifications 002021.exe Jump to behavior
Source: C:\Users\user\Desktop\Inquiry - Specifications 002021.exe Key value queried: HKEY_LOCAL_MACHINE\SOFTWARE\Classes\WOW6432Node\CLSID\{172BDDF8-CEEA-11D1-8B05-00600806D9B6}\InProcServer32 Jump to behavior
Source: C:\Users\user\Desktop\Inquiry - Specifications 002021.exe WMI Queries: IWbemServices::CreateInstanceEnum - root\cimv2 : Win32_Processor
Source: C:\Users\user\Desktop\Inquiry - Specifications 002021.exe WMI Queries: IWbemServices::ExecQuery - root\cimv2 : SELECT * FROM Win32_Processor
Source: C:\Users\user\Desktop\Inquiry - Specifications 002021.exe WMI Queries: IWbemServices::ExecQuery - root\cimv2 : SELECT * FROM Win32_Processor
Source: C:\Users\user\Desktop\Inquiry - Specifications 002021.exe File created: C:\Users\user\AppData\Local\Microsoft\CLR_v4.0_32\UsageLogs\Inquiry - Specifications 002021.exe.log Jump to behavior
Source: classification engine Classification label: mal100.troj.spyw.evad.winEXE@3/2@4/2
Source: C:\Users\user\Desktop\Inquiry - Specifications 002021.exe Section loaded: C:\Windows\assembly\NativeImages_v4.0.30319_32\mscorlib\a152fe02a317a77aeee36903305e8ba6\mscorlib.ni.dll Jump to behavior
Source: C:\Users\user\Desktop\Inquiry - Specifications 002021.exe Section loaded: C:\Windows\assembly\NativeImages_v4.0.30319_32\mscorlib\a152fe02a317a77aeee36903305e8ba6\mscorlib.ni.dll Jump to behavior
Source: 5.2.Inquiry - Specifications 002021.exe.400000.0.unpack, A/b2.cs Cryptographic APIs: 'TransformFinalBlock', 'CreateDecryptor'
Source: 5.2.Inquiry - Specifications 002021.exe.400000.0.unpack, A/b2.cs Cryptographic APIs: 'TransformFinalBlock', 'CreateDecryptor'
Source: C:\Users\user\Desktop\Inquiry - Specifications 002021.exe File read: C:\Windows\System32\drivers\etc\hosts Jump to behavior
Source: C:\Users\user\Desktop\Inquiry - Specifications 002021.exe File read: C:\Windows\System32\drivers\etc\hosts Jump to behavior
Source: C:\Users\user\Desktop\Inquiry - Specifications 002021.exe File read: C:\Windows\System32\drivers\etc\hosts Jump to behavior
Source: C:\Users\user\Desktop\Inquiry - Specifications 002021.exe File read: C:\Windows\System32\drivers\etc\hosts Jump to behavior
Source: C:\Users\user\Desktop\Inquiry - Specifications 002021.exe File read: C:\Windows\System32\drivers\etc\hosts Jump to behavior
Source: C:\Users\user\Desktop\Inquiry - Specifications 002021.exe File opened: C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscorrc.dll Jump to behavior
Source: C:\Users\user\Desktop\Inquiry - Specifications 002021.exe Key opened: HKEY_CURRENT_USER\Software\Microsoft\Office\15.0\Outlook\Profiles\Outlook\9375CFF0413111d3B88A00104B2A6676 Jump to behavior
Source: Inquiry - Specifications 002021.exe Static PE information: data directory type: IMAGE_DIRECTORY_ENTRY_COM_DESCRIPTOR
Source: Inquiry - Specifications 002021.exe Static PE information: NO_SEH, TERMINAL_SERVER_AWARE, DYNAMIC_BASE, NX_COMPAT

Data Obfuscation:

barindex
.NET source code contains potential unpacker
Source: Inquiry - Specifications 002021.exe, Darwin.WindowsForm/MainForm.cs .Net Code: DDDDDDDDDDDDDDDDDDDDDDDDDDDDDDDDDDDDDDDD System.Reflection.Assembly System.Reflection.Assembly::Load(System.Byte[])
Source: 0.0.Inquiry - Specifications 002021.exe.70000.0.unpack, Darwin.WindowsForm/MainForm.cs .Net Code: DDDDDDDDDDDDDDDDDDDDDDDDDDDDDDDDDDDDDDDD System.Reflection.Assembly System.Reflection.Assembly::Load(System.Byte[])
Source: 0.2.Inquiry - Specifications 002021.exe.70000.0.unpack, Darwin.WindowsForm/MainForm.cs .Net Code: DDDDDDDDDDDDDDDDDDDDDDDDDDDDDDDDDDDDDDDD System.Reflection.Assembly System.Reflection.Assembly::Load(System.Byte[])
Source: 5.0.Inquiry - Specifications 002021.exe.a10000.0.unpack, Darwin.WindowsForm/MainForm.cs .Net Code: DDDDDDDDDDDDDDDDDDDDDDDDDDDDDDDDDDDDDDDD System.Reflection.Assembly System.Reflection.Assembly::Load(System.Byte[])
Source: 5.2.Inquiry - Specifications 002021.exe.a10000.1.unpack, Darwin.WindowsForm/MainForm.cs .Net Code: DDDDDDDDDDDDDDDDDDDDDDDDDDDDDDDDDDDDDDDD System.Reflection.Assembly System.Reflection.Assembly::Load(System.Byte[])
Uses code obfuscation techniques (call, push, ret)
Source: C:\Users\user\Desktop\Inquiry - Specifications 002021.exe Code function: 5_2_0121B5FF push edi; retn 0000h 5_2_0121B601
Source: C:\Users\user\Desktop\Inquiry - Specifications 002021.exe Code function: 5_2_0121D44C pushad ; retf 5_2_0121D455
Source: C:\Users\user\Desktop\Inquiry - Specifications 002021.exe Code function: 5_2_0121D458 pushad ; retf 5_2_0121D459
Source: initial sample Static PE information: section name: .text entropy: 7.0705910139

Persistence and Installation Behavior:

barindex
Creates processes with suspicious names
Source: C:\Users\user\Desktop\Inquiry - Specifications 002021.exe File created: \inquiry - specifications 002021.exe
Source: C:\Users\user\Desktop\Inquiry - Specifications 002021.exe File created: \inquiry - specifications 002021.exe Jump to behavior

Hooking and other Techniques for Hiding and Protection:

barindex
Moves itself to temp directory
Source: c:\users\user\desktop\inquiry - specifications 002021.exe File moved: C:\Users\user\AppData\Local\Temp\tmpG14.tmp Jump to behavior
Source: C:\Users\user\Desktop\Inquiry - Specifications 002021.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Users\user\Desktop\Inquiry - Specifications 002021.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Users\user\Desktop\Inquiry - Specifications 002021.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Users\user\Desktop\Inquiry - Specifications 002021.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Users\user\Desktop\Inquiry - Specifications 002021.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Users\user\Desktop\Inquiry - Specifications 002021.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Users\user\Desktop\Inquiry - Specifications 002021.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Users\user\Desktop\Inquiry - Specifications 002021.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Users\user\Desktop\Inquiry - Specifications 002021.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Users\user\Desktop\Inquiry - Specifications 002021.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Users\user\Desktop\Inquiry - Specifications 002021.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Users\user\Desktop\Inquiry - Specifications 002021.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Users\user\Desktop\Inquiry - Specifications 002021.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Users\user\Desktop\Inquiry - Specifications 002021.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Users\user\Desktop\Inquiry - Specifications 002021.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Users\user\Desktop\Inquiry - Specifications 002021.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Users\user\Desktop\Inquiry - Specifications 002021.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Users\user\Desktop\Inquiry - Specifications 002021.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Users\user\Desktop\Inquiry - Specifications 002021.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Users\user\Desktop\Inquiry - Specifications 002021.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Users\user\Desktop\Inquiry - Specifications 002021.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Users\user\Desktop\Inquiry - Specifications 002021.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Users\user\Desktop\Inquiry - Specifications 002021.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Users\user\Desktop\Inquiry - Specifications 002021.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Users\user\Desktop\Inquiry - Specifications 002021.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Users\user\Desktop\Inquiry - Specifications 002021.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Users\user\Desktop\Inquiry - Specifications 002021.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Users\user\Desktop\Inquiry - Specifications 002021.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Users\user\Desktop\Inquiry - Specifications 002021.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Users\user\Desktop\Inquiry - Specifications 002021.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Users\user\Desktop\Inquiry - Specifications 002021.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Users\user\Desktop\Inquiry - Specifications 002021.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Users\user\Desktop\Inquiry - Specifications 002021.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Users\user\Desktop\Inquiry - Specifications 002021.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Users\user\Desktop\Inquiry - Specifications 002021.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Users\user\Desktop\Inquiry - Specifications 002021.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Users\user\Desktop\Inquiry - Specifications 002021.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Users\user\Desktop\Inquiry - Specifications 002021.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Users\user\Desktop\Inquiry - Specifications 002021.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Users\user\Desktop\Inquiry - Specifications 002021.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Users\user\Desktop\Inquiry - Specifications 002021.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Users\user\Desktop\Inquiry - Specifications 002021.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Users\user\Desktop\Inquiry - Specifications 002021.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Users\user\Desktop\Inquiry - Specifications 002021.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Users\user\Desktop\Inquiry - Specifications 002021.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Users\user\Desktop\Inquiry - Specifications 002021.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Users\user\Desktop\Inquiry - Specifications 002021.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Users\user\Desktop\Inquiry - Specifications 002021.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Users\user\Desktop\Inquiry - Specifications 002021.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Users\user\Desktop\Inquiry - Specifications 002021.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Users\user\Desktop\Inquiry - Specifications 002021.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Users\user\Desktop\Inquiry - Specifications 002021.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Users\user\Desktop\Inquiry - Specifications 002021.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Users\user\Desktop\Inquiry - Specifications 002021.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Users\user\Desktop\Inquiry - Specifications 002021.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Users\user\Desktop\Inquiry - Specifications 002021.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Users\user\Desktop\Inquiry - Specifications 002021.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Users\user\Desktop\Inquiry - Specifications 002021.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Users\user\Desktop\Inquiry - Specifications 002021.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Users\user\Desktop\Inquiry - Specifications 002021.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Users\user\Desktop\Inquiry - Specifications 002021.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Users\user\Desktop\Inquiry - Specifications 002021.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Users\user\Desktop\Inquiry - Specifications 002021.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Users\user\Desktop\Inquiry - Specifications 002021.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Users\user\Desktop\Inquiry - Specifications 002021.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Users\user\Desktop\Inquiry - Specifications 002021.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Users\user\Desktop\Inquiry - Specifications 002021.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Users\user\Desktop\Inquiry - Specifications 002021.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Users\user\Desktop\Inquiry - Specifications 002021.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Users\user\Desktop\Inquiry - Specifications 002021.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Users\user\Desktop\Inquiry - Specifications 002021.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Users\user\Desktop\Inquiry - Specifications 002021.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Users\user\Desktop\Inquiry - Specifications 002021.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Users\user\Desktop\Inquiry - Specifications 002021.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Users\user\Desktop\Inquiry - Specifications 002021.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Users\user\Desktop\Inquiry - Specifications 002021.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Users\user\Desktop\Inquiry - Specifications 002021.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Users\user\Desktop\Inquiry - Specifications 002021.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Users\user\Desktop\Inquiry - Specifications 002021.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Users\user\Desktop\Inquiry - Specifications 002021.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Users\user\Desktop\Inquiry - Specifications 002021.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Users\user\Desktop\Inquiry - Specifications 002021.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Users\user\Desktop\Inquiry - Specifications 002021.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Users\user\Desktop\Inquiry - Specifications 002021.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Users\user\Desktop\Inquiry - Specifications 002021.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Users\user\Desktop\Inquiry - Specifications 002021.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Users\user\Desktop\Inquiry - Specifications 002021.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Users\user\Desktop\Inquiry - Specifications 002021.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Users\user\Desktop\Inquiry - Specifications 002021.exe Process information set: NOOPENFILEERRORBOX Jump to behavior

Malware Analysis System Evasion:

barindex
Yara detected AntiVM3
Source: Yara match File source: 0.2.Inquiry - Specifications 002021.exe.2528614.1.raw.unpack, type: UNPACKEDPE
Source: Yara match File source: 00000000.00000002.322481518.00000000024D1000.00000004.00000001.sdmp, type: MEMORY
Source: Yara match File source: 00000000.00000002.322874820.000000000254D000.00000004.00000001.sdmp, type: MEMORY
Source: Yara match File source: Process Memory Space: Inquiry - Specifications 002021.exe PID: 1360, type: MEMORYSTR
Tries to detect sandboxes and other dynamic analysis tools (process name or module or function)
Source: Inquiry - Specifications 002021.exe, 00000000.00000002.322874820.000000000254D000.00000004.00000001.sdmp Binary or memory string: SBIEDLL.DLL
Source: Inquiry - Specifications 002021.exe, 00000000.00000002.322874820.000000000254D000.00000004.00000001.sdmp Binary or memory string: KERNEL32.DLL.WINE_GET_UNIX_FILE_NAME
Queries sensitive network adapter information (via WMI, Win32_NetworkAdapter, often done to detect virtual machines)
Source: C:\Users\user\Desktop\Inquiry - Specifications 002021.exe WMI Queries: IWbemServices::CreateInstanceEnum - root\cimv2 : Win32_NetworkAdapterConfiguration
Queries sensitive BIOS Information (via WMI, Win32_Bios & Win32_BaseBoard, often done to detect virtual machines)
Source: C:\Users\user\Desktop\Inquiry - Specifications 002021.exe WMI Queries: IWbemServices::CreateInstanceEnum - root\cimv2 : Win32_BaseBoard
May sleep (evasive loops) to hinder dynamic analysis
Source: C:\Users\user\Desktop\Inquiry - Specifications 002021.exe TID: 2504 Thread sleep time: -42868s >= -30000s Jump to behavior
Source: C:\Users\user\Desktop\Inquiry - Specifications 002021.exe TID: 6944 Thread sleep time: -922337203685477s >= -30000s Jump to behavior
Source: C:\Users\user\Desktop\Inquiry - Specifications 002021.exe TID: 7136 Thread sleep time: -7378697629483816s >= -30000s Jump to behavior
Source: C:\Users\user\Desktop\Inquiry - Specifications 002021.exe TID: 6852 Thread sleep count: 657 > 30 Jump to behavior
Source: C:\Users\user\Desktop\Inquiry - Specifications 002021.exe TID: 6852 Thread sleep count: 9187 > 30 Jump to behavior
Contains long sleeps (>= 3 min)
Source: C:\Users\user\Desktop\Inquiry - Specifications 002021.exe Thread delayed: delay time: 922337203685477 Jump to behavior
Source: C:\Users\user\Desktop\Inquiry - Specifications 002021.exe Thread delayed: delay time: 922337203685477 Jump to behavior
Found a high number of Window / User specific system calls (may be a loop to detect user behavior)
Source: C:\Users\user\Desktop\Inquiry - Specifications 002021.exe Window / User API: threadDelayed 657 Jump to behavior
Source: C:\Users\user\Desktop\Inquiry - Specifications 002021.exe Window / User API: threadDelayed 9187 Jump to behavior
Queries sensitive processor information (via WMI, Win32_Processor, often done to detect virtual machines)
Source: C:\Users\user\Desktop\Inquiry - Specifications 002021.exe WMI Queries: IWbemServices::CreateInstanceEnum - root\cimv2 : Win32_Processor
Source: C:\Users\user\Desktop\Inquiry - Specifications 002021.exe WMI Queries: IWbemServices::ExecQuery - root\cimv2 : SELECT * FROM Win32_Processor
Source: C:\Users\user\Desktop\Inquiry - Specifications 002021.exe WMI Queries: IWbemServices::ExecQuery - root\cimv2 : SELECT * FROM Win32_Processor
Source: C:\Users\user\Desktop\Inquiry - Specifications 002021.exe Process information queried: ProcessInformation Jump to behavior
Source: C:\Users\user\Desktop\Inquiry - Specifications 002021.exe Thread delayed: delay time: 42868 Jump to behavior
Source: C:\Users\user\Desktop\Inquiry - Specifications 002021.exe Thread delayed: delay time: 922337203685477 Jump to behavior
Source: C:\Users\user\Desktop\Inquiry - Specifications 002021.exe Thread delayed: delay time: 922337203685477 Jump to behavior
Source: Inquiry - Specifications 002021.exe, 00000000.00000002.322874820.000000000254D000.00000004.00000001.sdmp Binary or memory string: InstallPathJC:\PROGRAM FILES\VMWARE\VMWARE TOOLS\
Source: Inquiry - Specifications 002021.exe, 00000000.00000002.322874820.000000000254D000.00000004.00000001.sdmp Binary or memory string: vmware
Source: Inquiry - Specifications 002021.exe, 00000000.00000002.322874820.000000000254D000.00000004.00000001.sdmp Binary or memory string: VMware SVGA II
Source: Inquiry - Specifications 002021.exe, 00000005.00000002.556634712.00000000011B7000.00000004.00000020.sdmp Binary or memory string: Hyper-V RAW%SystemRoot%\system32\mswsock.dll@
Source: Inquiry - Specifications 002021.exe, 00000000.00000002.322874820.000000000254D000.00000004.00000001.sdmp Binary or memory string: VMWAREDSOFTWARE\VMware, Inc.\VMware Tools

Anti Debugging:

barindex
Enables debug privileges
Source: C:\Users\user\Desktop\Inquiry - Specifications 002021.exe Process token adjusted: Debug Jump to behavior
Contains functionality to access loader functionality (e.g. LdrGetProcedureAddress)
Source: C:\Users\user\Desktop\Inquiry - Specifications 002021.exe Code function: 5_2_00FD1A80 LdrInitializeThunk, 5_2_00FD1A80
Source: C:\Users\user\Desktop\Inquiry - Specifications 002021.exe Memory allocated: page read and write | page guard Jump to behavior

HIPS / PFW / Operating System Protection Evasion:

barindex
Creates a process in suspended mode (likely to inject code)
Source: C:\Users\user\Desktop\Inquiry - Specifications 002021.exe Process created: C:\Users\user\Desktop\Inquiry - Specifications 002021.exe C:\Users\user\Desktop\Inquiry - Specifications 002021.exe Jump to behavior
Source: Inquiry - Specifications 002021.exe, 00000005.00000002.557909116.0000000001890000.00000002.00020000.sdmp Binary or memory string: Program Manager
Source: Inquiry - Specifications 002021.exe, 00000005.00000002.557909116.0000000001890000.00000002.00020000.sdmp Binary or memory string: Shell_TrayWnd
Source: Inquiry - Specifications 002021.exe, 00000005.00000002.557909116.0000000001890000.00000002.00020000.sdmp Binary or memory string: Progman
Source: Inquiry - Specifications 002021.exe, 00000005.00000002.557909116.0000000001890000.00000002.00020000.sdmp Binary or memory string: Progmanlock

Language, Device and Operating System Detection:

barindex
Queries the volume information (name, serial number etc) of a device
Source: C:\Users\user\Desktop\Inquiry - Specifications 002021.exe Queries volume information: C:\Users\user\Desktop\Inquiry - Specifications 002021.exe VolumeInformation Jump to behavior
Source: C:\Users\user\Desktop\Inquiry - Specifications 002021.exe Queries volume information: C:\Windows\Microsoft.NET\assembly\GAC_MSIL\System.Windows.Forms\v4.0_4.0.0.0__b77a5c561934e089\System.Windows.Forms.dll VolumeInformation Jump to behavior
Source: C:\Users\user\Desktop\Inquiry - Specifications 002021.exe Queries volume information: C:\Windows\Microsoft.NET\assembly\GAC_MSIL\System.Drawing\v4.0_4.0.0.0__b03f5f7f11d50a3a\System.Drawing.dll VolumeInformation Jump to behavior
Source: C:\Users\user\Desktop\Inquiry - Specifications 002021.exe Queries volume information: C:\Windows\Microsoft.NET\assembly\GAC_MSIL\Accessibility\v4.0_4.0.0.0__b03f5f7f11d50a3a\Accessibility.dll VolumeInformation Jump to behavior
Source: C:\Users\user\Desktop\Inquiry - Specifications 002021.exe Queries volume information: C:\Windows\Fonts\arial.ttf VolumeInformation Jump to behavior
Source: C:\Users\user\Desktop\Inquiry - Specifications 002021.exe Queries volume information: C:\Windows\Fonts\ariali.ttf VolumeInformation Jump to behavior
Source: C:\Users\user\Desktop\Inquiry - Specifications 002021.exe Queries volume information: C:\Windows\Fonts\arialbd.ttf VolumeInformation Jump to behavior
Source: C:\Users\user\Desktop\Inquiry - Specifications 002021.exe Queries volume information: C:\Windows\Fonts\arialbi.ttf VolumeInformation Jump to behavior
Source: C:\Users\user\Desktop\Inquiry - Specifications 002021.exe Queries volume information: C:\Windows\Fonts\ARIALN.TTF VolumeInformation Jump to behavior
Source: C:\Users\user\Desktop\Inquiry - Specifications 002021.exe Queries volume information: C:\Windows\Fonts\ariblk.ttf VolumeInformation Jump to behavior
Source: C:\Users\user\Desktop\Inquiry - Specifications 002021.exe Queries volume information: C:\Windows\Fonts\ARIALNI.TTF VolumeInformation Jump to behavior
Source: C:\Users\user\Desktop\Inquiry - Specifications 002021.exe Queries volume information: C:\Windows\Fonts\ARIALNB.TTF VolumeInformation Jump to behavior
Source: C:\Users\user\Desktop\Inquiry - Specifications 002021.exe Queries volume information: C:\Windows\Fonts\ARIALNBI.TTF VolumeInformation Jump to behavior
Source: C:\Users\user\Desktop\Inquiry - Specifications 002021.exe Queries volume information: C:\Windows\Fonts\bahnschrift.ttf VolumeInformation Jump to behavior
Source: C:\Users\user\Desktop\Inquiry - Specifications 002021.exe Queries volume information: C:\Windows\Fonts\calibri.ttf VolumeInformation Jump to behavior
Source: C:\Users\user\Desktop\Inquiry - Specifications 002021.exe Queries volume information: C:\Windows\Fonts\calibril.ttf VolumeInformation Jump to behavior
Source: C:\Users\user\Desktop\Inquiry - Specifications 002021.exe Queries volume information: C:\Windows\Fonts\calibrii.ttf VolumeInformation Jump to behavior
Source: C:\Users\user\Desktop\Inquiry - Specifications 002021.exe Queries volume information: C:\Windows\Fonts\calibrili.ttf VolumeInformation Jump to behavior
Source: C:\Users\user\Desktop\Inquiry - Specifications 002021.exe Queries volume information: C:\Windows\Fonts\calibrib.ttf VolumeInformation Jump to behavior
Source: C:\Users\user\Desktop\Inquiry - Specifications 002021.exe Queries volume information: C:\Windows\Fonts\calibriz.ttf VolumeInformation Jump to behavior
Source: C:\Users\user\Desktop\Inquiry - Specifications 002021.exe Queries volume information: C:\Windows\Fonts\cambria.ttc VolumeInformation Jump to behavior
Source: C:\Users\user\Desktop\Inquiry - Specifications 002021.exe Queries volume information: C:\Windows\Fonts\cambriai.ttf VolumeInformation Jump to behavior
Source: C:\Users\user\Desktop\Inquiry - Specifications 002021.exe Queries volume information: C:\Windows\Fonts\cambriab.ttf VolumeInformation Jump to behavior
Source: C:\Users\user\Desktop\Inquiry - Specifications 002021.exe Queries volume information: C:\Windows\Fonts\cambriaz.ttf VolumeInformation Jump to behavior
Source: C:\Users\user\Desktop\Inquiry - Specifications 002021.exe Queries volume information: C:\Windows\Fonts\Candara.ttf VolumeInformation Jump to behavior
Source: C:\Users\user\Desktop\Inquiry - Specifications 002021.exe Queries volume information: C:\Windows\Fonts\Candarai.ttf VolumeInformation Jump to behavior
Source: C:\Users\user\Desktop\Inquiry - Specifications 002021.exe Queries volume information: C:\Windows\Fonts\Candarab.ttf VolumeInformation Jump to behavior
Source: C:\Users\user\Desktop\Inquiry - Specifications 002021.exe Queries volume information: C:\Windows\Fonts\Candaraz.ttf VolumeInformation Jump to behavior
Source: C:\Users\user\Desktop\Inquiry - Specifications 002021.exe Queries volume information: C:\Windows\Fonts\comic.ttf VolumeInformation Jump to behavior
Source: C:\Users\user\Desktop\Inquiry - Specifications 002021.exe Queries volume information: C:\Windows\Fonts\comici.ttf VolumeInformation Jump to behavior
Source: C:\Users\user\Desktop\Inquiry - Specifications 002021.exe Queries volume information: C:\Windows\Fonts\comicbd.ttf VolumeInformation Jump to behavior
Source: C:\Users\user\Desktop\Inquiry - Specifications 002021.exe Queries volume information: C:\Windows\Fonts\comicz.ttf VolumeInformation Jump to behavior
Source: C:\Users\user\Desktop\Inquiry - Specifications 002021.exe Queries volume information: C:\Windows\Fonts\consola.ttf VolumeInformation Jump to behavior
Source: C:\Users\user\Desktop\Inquiry - Specifications 002021.exe Queries volume information: C:\Windows\Fonts\consolai.ttf VolumeInformation Jump to behavior
Source: C:\Users\user\Desktop\Inquiry - Specifications 002021.exe Queries volume information: C:\Windows\Fonts\consolab.ttf VolumeInformation Jump to behavior
Source: C:\Users\user\Desktop\Inquiry - Specifications 002021.exe Queries volume information: C:\Windows\Fonts\consolaz.ttf VolumeInformation Jump to behavior
Source: C:\Users\user\Desktop\Inquiry - Specifications 002021.exe Queries volume information: C:\Windows\Fonts\constan.ttf VolumeInformation Jump to behavior
Source: C:\Users\user\Desktop\Inquiry - Specifications 002021.exe Queries volume information: C:\Windows\Fonts\constani.ttf VolumeInformation Jump to behavior
Source: C:\Users\user\Desktop\Inquiry - Specifications 002021.exe Queries volume information: C:\Windows\Fonts\constanb.ttf VolumeInformation Jump to behavior
Source: C:\Users\user\Desktop\Inquiry - Specifications 002021.exe Queries volume information: C:\Windows\Fonts\constanz.ttf VolumeInformation Jump to behavior
Source: C:\Users\user\Desktop\Inquiry - Specifications 002021.exe Queries volume information: C:\Windows\Fonts\corbel.ttf VolumeInformation Jump to behavior
Source: C:\Users\user\Desktop\Inquiry - Specifications 002021.exe Queries volume information: C:\Windows\Fonts\corbeli.ttf VolumeInformation Jump to behavior
Source: C:\Users\user\Desktop\Inquiry - Specifications 002021.exe Queries volume information: C:\Windows\Fonts\corbelb.ttf VolumeInformation Jump to behavior
Source: C:\Users\user\Desktop\Inquiry - Specifications 002021.exe Queries volume information: C:\Windows\Fonts\corbelz.ttf VolumeInformation Jump to behavior
Source: C:\Users\user\Desktop\Inquiry - Specifications 002021.exe Queries volume information: C:\Windows\Fonts\cour.ttf VolumeInformation Jump to behavior
Source: C:\Users\user\Desktop\Inquiry - Specifications 002021.exe Queries volume information: C:\Windows\Fonts\couri.ttf VolumeInformation Jump to behavior
Source: C:\Users\user\Desktop\Inquiry - Specifications 002021.exe Queries volume information: C:\Windows\Fonts\courbd.ttf VolumeInformation Jump to behavior
Source: C:\Users\user\Desktop\Inquiry - Specifications 002021.exe Queries volume information: C:\Windows\Fonts\courbi.ttf VolumeInformation Jump to behavior
Source: C:\Users\user\Desktop\Inquiry - Specifications 002021.exe Queries volume information: C:\Windows\Fonts\ebrima.ttf VolumeInformation Jump to behavior
Source: C:\Users\user\Desktop\Inquiry - Specifications 002021.exe Queries volume information: C:\Windows\Fonts\ebrimabd.ttf VolumeInformation Jump to behavior
Source: C:\Users\user\Desktop\Inquiry - Specifications 002021.exe Queries volume information: C:\Windows\Fonts\framd.ttf VolumeInformation Jump to behavior
Source: C:\Users\user\Desktop\Inquiry - Specifications 002021.exe Queries volume information: C:\Windows\Fonts\FRADM.TTF VolumeInformation Jump to behavior
Source: C:\Users\user\Desktop\Inquiry - Specifications 002021.exe Queries volume information: C:\Windows\Fonts\framdit.ttf VolumeInformation Jump to behavior
Source: C:\Users\user\Desktop\Inquiry - Specifications 002021.exe Queries volume information: C:\Windows\Fonts\FRADMIT.TTF VolumeInformation Jump to behavior
Source: C:\Users\user\Desktop\Inquiry - Specifications 002021.exe Queries volume information: C:\Windows\Fonts\FRAMDCN.TTF VolumeInformation Jump to behavior
Source: C:\Users\user\Desktop\Inquiry - Specifications 002021.exe Queries volume information: C:\Windows\Fonts\FRADMCN.TTF VolumeInformation Jump to behavior
Source: C:\Users\user\Desktop\Inquiry - Specifications 002021.exe Queries volume information: C:\Windows\Fonts\FRAHV.TTF VolumeInformation Jump to behavior
Source: C:\Users\user\Desktop\Inquiry - Specifications 002021.exe Queries volume information: C:\Windows\Fonts\FRAHVIT.TTF VolumeInformation Jump to behavior
Source: C:\Users\user\Desktop\Inquiry - Specifications 002021.exe Queries volume information: C:\Windows\Fonts\Gabriola.ttf VolumeInformation Jump to behavior
Source: C:\Users\user\Desktop\Inquiry - Specifications 002021.exe Queries volume information: C:\Windows\Fonts\gadugi.ttf VolumeInformation Jump to behavior
Source: C:\Users\user\Desktop\Inquiry - Specifications 002021.exe Queries volume information: C:\Windows\Fonts\gadugib.ttf VolumeInformation Jump to behavior
Source: C:\Users\user\Desktop\Inquiry - Specifications 002021.exe Queries volume information: C:\Windows\Fonts\georgia.ttf VolumeInformation Jump to behavior
Source: C:\Users\user\Desktop\Inquiry - Specifications 002021.exe Queries volume information: C:\Windows\Fonts\georgiai.ttf VolumeInformation Jump to behavior
Source: C:\Users\user\Desktop\Inquiry - Specifications 002021.exe Queries volume information: C:\Windows\Fonts\georgiab.ttf VolumeInformation Jump to behavior
Source: C:\Users\user\Desktop\Inquiry - Specifications 002021.exe Queries volume information: C:\Windows\Fonts\georgiaz.ttf VolumeInformation Jump to behavior
Source: C:\Users\user\Desktop\Inquiry - Specifications 002021.exe Queries volume information: C:\Windows\Fonts\impact.ttf VolumeInformation Jump to behavior
Source: C:\Users\user\Desktop\Inquiry - Specifications 002021.exe Queries volume information: C:\Windows\Fonts\Inkfree.ttf VolumeInformation Jump to behavior
Source: C:\Users\user\Desktop\Inquiry - Specifications 002021.exe Queries volume information: C:\Windows\Fonts\javatext.ttf VolumeInformation Jump to behavior
Source: C:\Users\user\Desktop\Inquiry - Specifications 002021.exe Queries volume information: C:\Windows\Fonts\LeelawUI.ttf VolumeInformation Jump to behavior
Source: C:\Users\user\Desktop\Inquiry - Specifications 002021.exe Queries volume information: C:\Windows\Fonts\LeelUIsl.ttf VolumeInformation Jump to behavior
Source: C:\Users\user\Desktop\Inquiry - Specifications 002021.exe Queries volume information: C:\Windows\Fonts\LeelaUIb.ttf VolumeInformation Jump to behavior
Source: C:\Users\user\Desktop\Inquiry - Specifications 002021.exe Queries volume information: C:\Windows\Fonts\lucon.ttf VolumeInformation Jump to behavior
Source: C:\Users\user\Desktop\Inquiry - Specifications 002021.exe Queries volume information: C:\Windows\Fonts\l_10646.ttf VolumeInformation Jump to behavior
Source: C:\Users\user\Desktop\Inquiry - Specifications 002021.exe Queries volume information: C:\Windows\Fonts\malgun.ttf VolumeInformation Jump to behavior
Source: C:\Users\user\Desktop\Inquiry - Specifications 002021.exe Queries volume information: C:\Windows\Fonts\malgunsl.ttf VolumeInformation Jump to behavior
Source: C:\Users\user\Desktop\Inquiry - Specifications 002021.exe Queries volume information: C:\Windows\Fonts\malgunbd.ttf VolumeInformation Jump to behavior
Source: C:\Users\user\Desktop\Inquiry - Specifications 002021.exe Queries volume information: C:\Windows\Fonts\himalaya.ttf VolumeInformation Jump to behavior
Source: C:\Users\user\Desktop\Inquiry - Specifications 002021.exe Queries volume information: C:\Windows\Fonts\msjh.ttc VolumeInformation Jump to behavior
Source: C:\Users\user\Desktop\Inquiry - Specifications 002021.exe Queries volume information: C:\Windows\Fonts\msjhl.ttc VolumeInformation Jump to behavior
Source: C:\Users\user\Desktop\Inquiry - Specifications 002021.exe Queries volume information: C:\Windows\Fonts\msjhbd.ttc VolumeInformation Jump to behavior
Source: C:\Users\user\Desktop\Inquiry - Specifications 002021.exe Queries volume information: C:\Windows\Fonts\ntailu.ttf VolumeInformation Jump to behavior
Source: C:\Users\user\Desktop\Inquiry - Specifications 002021.exe Queries volume information: C:\Windows\Fonts\ntailub.ttf VolumeInformation Jump to behavior
Source: C:\Users\user\Desktop\Inquiry - Specifications 002021.exe Queries volume information: C:\Windows\Fonts\phagspa.ttf VolumeInformation Jump to behavior
Source: C:\Users\user\Desktop\Inquiry - Specifications 002021.exe Queries volume information: C:\Windows\Fonts\phagspab.ttf VolumeInformation Jump to behavior
Source: C:\Users\user\Desktop\Inquiry - Specifications 002021.exe Queries volume information: C:\Windows\Fonts\micross.ttf VolumeInformation Jump to behavior
Source: C:\Users\user\Desktop\Inquiry - Specifications 002021.exe Queries volume information: C:\Windows\Fonts\taile.ttf VolumeInformation Jump to behavior
Source: C:\Users\user\Desktop\Inquiry - Specifications 002021.exe Queries volume information: C:\Windows\Fonts\taileb.ttf VolumeInformation Jump to behavior
Source: C:\Users\user\Desktop\Inquiry - Specifications 002021.exe Queries volume information: C:\Windows\Fonts\msyh.ttc VolumeInformation Jump to behavior
Source: C:\Users\user\Desktop\Inquiry - Specifications 002021.exe Queries volume information: C:\Windows\Fonts\msyhl.ttc VolumeInformation Jump to behavior
Source: C:\Users\user\Desktop\Inquiry - Specifications 002021.exe Queries volume information: C:\Windows\Fonts\msyhbd.ttc VolumeInformation Jump to behavior
Source: C:\Users\user\Desktop\Inquiry - Specifications 002021.exe Queries volume information: C:\Windows\Fonts\msyi.ttf VolumeInformation Jump to behavior
Source: C:\Users\user\Desktop\Inquiry - Specifications 002021.exe Queries volume information: C:\Windows\Fonts\mingliub.ttc VolumeInformation Jump to behavior
Source: C:\Users\user\Desktop\Inquiry - Specifications 002021.exe Queries volume information: C:\Windows\Fonts\monbaiti.ttf VolumeInformation Jump to behavior
Source: C:\Users\user\Desktop\Inquiry - Specifications 002021.exe Queries volume information: C:\Windows\Fonts\msgothic.ttc VolumeInformation Jump to behavior
Source: C:\Users\user\Desktop\Inquiry - Specifications 002021.exe Queries volume information: C:\Windows\Fonts\mvboli.ttf VolumeInformation Jump to behavior
Source: C:\Users\user\Desktop\Inquiry - Specifications 002021.exe Queries volume information: C:\Windows\Fonts\mmrtext.ttf VolumeInformation Jump to behavior
Source: C:\Users\user\Desktop\Inquiry - Specifications 002021.exe Queries volume information: C:\Windows\Fonts\mmrtextb.ttf VolumeInformation Jump to behavior
Source: C:\Users\user\Desktop\Inquiry - Specifications 002021.exe Queries volume information: C:\Windows\Fonts\Nirmala.ttf VolumeInformation Jump to behavior
Source: C:\Users\user\Desktop\Inquiry - Specifications 002021.exe Queries volume information: C:\Windows\Fonts\NirmalaS.ttf VolumeInformation Jump to behavior
Source: C:\Users\user\Desktop\Inquiry - Specifications 002021.exe Queries volume information: C:\Windows\Fonts\NirmalaB.ttf VolumeInformation Jump to behavior
Source: C:\Users\user\Desktop\Inquiry - Specifications 002021.exe Queries volume information: C:\Windows\Fonts\pala.ttf VolumeInformation Jump to behavior
Source: C:\Users\user\Desktop\Inquiry - Specifications 002021.exe Queries volume information: C:\Windows\Fonts\palai.ttf VolumeInformation Jump to behavior
Source: C:\Users\user\Desktop\Inquiry - Specifications 002021.exe Queries volume information: C:\Windows\Fonts\palab.ttf VolumeInformation Jump to behavior
Source: C:\Users\user\Desktop\Inquiry - Specifications 002021.exe Queries volume information: C:\Windows\Fonts\palabi.ttf VolumeInformation Jump to behavior
Source: C:\Users\user\Desktop\Inquiry - Specifications 002021.exe Queries volume information: C:\Windows\Fonts\segoepr.ttf VolumeInformation Jump to behavior
Source: C:\Users\user\Desktop\Inquiry - Specifications 002021.exe Queries volume information: C:\Windows\Fonts\segoeprb.ttf VolumeInformation Jump to behavior
Source: C:\Users\user\Desktop\Inquiry - Specifications 002021.exe Queries volume information: C:\Windows\Fonts\segoesc.ttf VolumeInformation Jump to behavior
Source: C:\Users\user\Desktop\Inquiry - Specifications 002021.exe Queries volume information: C:\Windows\Fonts\segoescb.ttf VolumeInformation Jump to behavior
Source: C:\Users\user\Desktop\Inquiry - Specifications 002021.exe Queries volume information: C:\Windows\Fonts\segoeuii.ttf VolumeInformation Jump to behavior
Source: C:\Users\user\Desktop\Inquiry - Specifications 002021.exe Queries volume information: C:\Windows\Fonts\seguisli.ttf VolumeInformation Jump to behavior
Source: C:\Users\user\Desktop\Inquiry - Specifications 002021.exe Queries volume information: C:\Windows\Fonts\seguili.ttf VolumeInformation Jump to behavior
Source: C:\Users\user\Desktop\Inquiry - Specifications 002021.exe Queries volume information: C:\Windows\Fonts\seguisbi.ttf VolumeInformation Jump to behavior
Source: C:\Users\user\Desktop\Inquiry - Specifications 002021.exe Queries volume information: C:\Windows\Fonts\segoeuiz.ttf VolumeInformation Jump to behavior
Source: C:\Users\user\Desktop\Inquiry - Specifications 002021.exe Queries volume information: C:\Windows\Fonts\seguibl.ttf VolumeInformation Jump to behavior
Source: C:\Users\user\Desktop\Inquiry - Specifications 002021.exe Queries volume information: C:\Windows\Fonts\seguibli.ttf VolumeInformation Jump to behavior
Source: C:\Users\user\Desktop\Inquiry - Specifications 002021.exe Queries volume information: C:\Windows\Fonts\seguiemj.ttf VolumeInformation Jump to behavior
Source: C:\Users\user\Desktop\Inquiry - Specifications 002021.exe Queries volume information: C:\Windows\Fonts\seguihis.ttf VolumeInformation Jump to behavior
Source: C:\Users\user\Desktop\Inquiry - Specifications 002021.exe Queries volume information: C:\Windows\Fonts\seguisym.ttf VolumeInformation Jump to behavior
Source: C:\Users\user\Desktop\Inquiry - Specifications 002021.exe Queries volume information: C:\Windows\Fonts\simsun.ttc VolumeInformation Jump to behavior
Source: C:\Users\user\Desktop\Inquiry - Specifications 002021.exe Queries volume information: C:\Windows\Fonts\simsunb.ttf VolumeInformation Jump to behavior
Source: C:\Users\user\Desktop\Inquiry - Specifications 002021.exe Queries volume information: C:\Windows\Fonts\Sitka.ttc VolumeInformation Jump to behavior
Source: C:\Users\user\Desktop\Inquiry - Specifications 002021.exe Queries volume information: C:\Windows\Fonts\SitkaI.ttc VolumeInformation Jump to behavior
Source: C:\Users\user\Desktop\Inquiry - Specifications 002021.exe Queries volume information: C:\Windows\Fonts\SitkaB.ttc VolumeInformation Jump to behavior
Source: C:\Users\user\Desktop\Inquiry - Specifications 002021.exe Queries volume information: C:\Windows\Fonts\SitkaZ.ttc VolumeInformation Jump to behavior
Source: C:\Users\user\Desktop\Inquiry - Specifications 002021.exe Queries volume information: C:\Windows\Fonts\sylfaen.ttf VolumeInformation Jump to behavior
Source: C:\Users\user\Desktop\Inquiry - Specifications 002021.exe Queries volume information: C:\Windows\Fonts\symbol.ttf VolumeInformation Jump to behavior
Source: C:\Users\user\Desktop\Inquiry - Specifications 002021.exe Queries volume information: C:\Windows\Fonts\tahoma.ttf VolumeInformation Jump to behavior
Source: C:\Users\user\Desktop\Inquiry - Specifications 002021.exe Queries volume information: C:\Windows\Fonts\tahomabd.ttf VolumeInformation Jump to behavior
Source: C:\Users\user\Desktop\Inquiry - Specifications 002021.exe Queries volume information: C:\Windows\Fonts\timesi.ttf VolumeInformation Jump to behavior
Source: C:\Users\user\Desktop\Inquiry - Specifications 002021.exe Queries volume information: C:\Windows\Fonts\timesbd.ttf VolumeInformation Jump to behavior
Source: C:\Users\user\Desktop\Inquiry - Specifications 002021.exe Queries volume information: C:\Windows\Fonts\timesbi.ttf VolumeInformation Jump to behavior
Source: C:\Users\user\Desktop\Inquiry - Specifications 002021.exe Queries volume information: C:\Windows\Fonts\trebuc.ttf VolumeInformation Jump to behavior
Source: C:\Users\user\Desktop\Inquiry - Specifications 002021.exe Queries volume information: C:\Windows\Fonts\trebucit.ttf VolumeInformation Jump to behavior
Source: C:\Users\user\Desktop\Inquiry - Specifications 002021.exe Queries volume information: C:\Windows\Fonts\trebucbd.ttf VolumeInformation Jump to behavior
Source: C:\Users\user\Desktop\Inquiry - Specifications 002021.exe Queries volume information: C:\Windows\Fonts\trebucbi.ttf VolumeInformation Jump to behavior
Source: C:\Users\user\Desktop\Inquiry - Specifications 002021.exe Queries volume information: C:\Windows\Fonts\verdana.ttf VolumeInformation Jump to behavior
Source: C:\Users\user\Desktop\Inquiry - Specifications 002021.exe Queries volume information: C:\Windows\Fonts\verdanai.ttf VolumeInformation Jump to behavior
Source: C:\Users\user\Desktop\Inquiry - Specifications 002021.exe Queries volume information: C:\Windows\Fonts\verdanab.ttf VolumeInformation Jump to behavior
Source: C:\Users\user\Desktop\Inquiry - Specifications 002021.exe Queries volume information: C:\Windows\Fonts\verdanaz.ttf VolumeInformation Jump to behavior
Source: C:\Users\user\Desktop\Inquiry - Specifications 002021.exe Queries volume information: C:\Windows\Fonts\webdings.ttf VolumeInformation Jump to behavior
Source: C:\Users\user\Desktop\Inquiry - Specifications 002021.exe Queries volume information: C:\Windows\Fonts\wingding.ttf VolumeInformation Jump to behavior
Source: C:\Users\user\Desktop\Inquiry - Specifications 002021.exe Queries volume information: C:\Windows\Fonts\YuGothR.ttc VolumeInformation Jump to behavior
Source: C:\Users\user\Desktop\Inquiry - Specifications 002021.exe Queries volume information: C:\Windows\Fonts\YuGothM.ttc VolumeInformation Jump to behavior
Source: C:\Users\user\Desktop\Inquiry - Specifications 002021.exe Queries volume information: C:\Windows\Fonts\YuGothL.ttc VolumeInformation Jump to behavior
Source: C:\Users\user\Desktop\Inquiry - Specifications 002021.exe Queries volume information: C:\Windows\Fonts\YuGothB.ttc VolumeInformation Jump to behavior
Source: C:\Users\user\Desktop\Inquiry - Specifications 002021.exe Queries volume information: C:\Windows\Fonts\holomdl2.ttf VolumeInformation Jump to behavior
Source: C:\Users\user\Desktop\Inquiry - Specifications 002021.exe Queries volume information: C:\Windows\Fonts\CENTURY.TTF VolumeInformation Jump to behavior
Source: C:\Users\user\Desktop\Inquiry - Specifications 002021.exe Queries volume information: C:\Windows\Fonts\LEELAWAD.TTF VolumeInformation Jump to behavior
Source: C:\Users\user\Desktop\Inquiry - Specifications 002021.exe Queries volume information: C:\Windows\Fonts\LEELAWDB.TTF VolumeInformation Jump to behavior
Source: C:\Users\user\Desktop\Inquiry - Specifications 002021.exe Queries volume information: C:\Windows\Fonts\MSUIGHUR.TTF VolumeInformation Jump to behavior
Source: C:\Users\user\Desktop\Inquiry - Specifications 002021.exe Queries volume information: C:\Windows\Fonts\MSUIGHUB.TTF VolumeInformation Jump to behavior
Source: C:\Users\user\Desktop\Inquiry - Specifications 002021.exe Queries volume information: C:\Windows\Fonts\WINGDNG2.TTF VolumeInformation Jump to behavior
Source: C:\Users\user\Desktop\Inquiry - Specifications 002021.exe Queries volume information: C:\Windows\Fonts\WINGDNG3.TTF VolumeInformation Jump to behavior
Source: C:\Users\user\Desktop\Inquiry - Specifications 002021.exe Queries volume information: C:\Windows\Fonts\TEMPSITC.TTF VolumeInformation Jump to behavior
Source: C:\Users\user\Desktop\Inquiry - Specifications 002021.exe Queries volume information: C:\Windows\Fonts\PRISTINA.TTF VolumeInformation Jump to behavior
Source: C:\Users\user\Desktop\Inquiry - Specifications 002021.exe Queries volume information: C:\Windows\Fonts\PAPYRUS.TTF VolumeInformation Jump to behavior
Source: C:\Users\user\Desktop\Inquiry - Specifications 002021.exe Queries volume information: C:\Windows\Fonts\MISTRAL.TTF VolumeInformation Jump to behavior
Source: C:\Users\user\Desktop\Inquiry - Specifications 002021.exe Queries volume information: C:\Windows\Fonts\LHANDW.TTF VolumeInformation Jump to behavior
Source: C:\Users\user\Desktop\Inquiry - Specifications 002021.exe Queries volume information: C:\Windows\Fonts\ITCKRIST.TTF VolumeInformation Jump to behavior
Source: C:\Users\user\Desktop\Inquiry - Specifications 002021.exe Queries volume information: C:\Windows\Fonts\JUICE___.TTF VolumeInformation Jump to behavior
Source: C:\Users\user\Desktop\Inquiry - Specifications 002021.exe Queries volume information: C:\Windows\Fonts\FRSCRIPT.TTF VolumeInformation Jump to behavior
Source: C:\Users\user\Desktop\Inquiry - Specifications 002021.exe Queries volume information: C:\Windows\Fonts\FREESCPT.TTF VolumeInformation Jump to behavior
Source: C:\Users\user\Desktop\Inquiry - Specifications 002021.exe Queries volume information: C:\Windows\Fonts\BRADHITC.TTF VolumeInformation Jump to behavior
Source: C:\Users\user\Desktop\Inquiry - Specifications 002021.exe Queries volume information: C:\Windows\Fonts\OUTLOOK.TTF VolumeInformation Jump to behavior
Source: C:\Users\user\Desktop\Inquiry - Specifications 002021.exe Queries volume information: C:\Windows\Fonts\BKANT.TTF VolumeInformation Jump to behavior
Source: C:\Users\user\Desktop\Inquiry - Specifications 002021.exe Queries volume information: C:\Windows\Fonts\ANTQUAI.TTF VolumeInformation Jump to behavior
Source: C:\Users\user\Desktop\Inquiry - Specifications 002021.exe Queries volume information: C:\Windows\Fonts\ANTQUAB.TTF VolumeInformation Jump to behavior
Source: C:\Users\user\Desktop\Inquiry - Specifications 002021.exe Queries volume information: C:\Windows\Fonts\ANTQUABI.TTF VolumeInformation Jump to behavior
Source: C:\Users\user\Desktop\Inquiry - Specifications 002021.exe Queries volume information: C:\Windows\Fonts\GARA.TTF VolumeInformation Jump to behavior
Source: C:\Users\user\Desktop\Inquiry - Specifications 002021.exe Queries volume information: C:\Windows\Fonts\GARAIT.TTF VolumeInformation Jump to behavior
Source: C:\Users\user\Desktop\Inquiry - Specifications 002021.exe Queries volume information: C:\Windows\Fonts\GARABD.TTF VolumeInformation Jump to behavior
Source: C:\Users\user\Desktop\Inquiry - Specifications 002021.exe Queries volume information: C:\Windows\Fonts\MTCORSVA.TTF VolumeInformation Jump to behavior
Source: C:\Users\user\Desktop\Inquiry - Specifications 002021.exe Queries volume information: C:\Windows\Fonts\GOTHIC.TTF VolumeInformation Jump to behavior
Source: C:\Users\user\Desktop\Inquiry - Specifications 002021.exe Queries volume information: C:\Windows\Fonts\GOTHICI.TTF VolumeInformation Jump to behavior
Source: C:\Users\user\Desktop\Inquiry - Specifications 002021.exe Queries volume information: C:\Windows\Fonts\GOTHICB.TTF VolumeInformation Jump to behavior
Source: C:\Users\user\Desktop\Inquiry - Specifications 002021.exe Queries volume information: C:\Windows\Fonts\GOTHICBI.TTF VolumeInformation Jump to behavior
Source: C:\Users\user\Desktop\Inquiry - Specifications 002021.exe Queries volume information: C:\Windows\Fonts\ALGER.TTF VolumeInformation Jump to behavior
Source: C:\Users\user\Desktop\Inquiry - Specifications 002021.exe Queries volume information: C:\Windows\Fonts\BASKVILL.TTF VolumeInformation Jump to behavior
Source: C:\Users\user\Desktop\Inquiry - Specifications 002021.exe Queries volume information: C:\Windows\Fonts\BAUHS93.TTF VolumeInformation Jump to behavior
Source: C:\Users\user\Desktop\Inquiry - Specifications 002021.exe Queries volume information: C:\Windows\Fonts\BELL.TTF VolumeInformation Jump to behavior
Source: C:\Users\user\Desktop\Inquiry - Specifications 002021.exe Queries volume information: C:\Windows\Fonts\BELLI.TTF VolumeInformation Jump to behavior
Source: C:\Users\user\Desktop\Inquiry - Specifications 002021.exe Queries volume information: C:\Windows\Fonts\BELLB.TTF VolumeInformation Jump to behavior
Source: C:\Users\user\Desktop\Inquiry - Specifications 002021.exe Queries volume information: C:\Windows\Fonts\BRLNSR.TTF VolumeInformation Jump to behavior
Source: C:\Users\user\Desktop\Inquiry - Specifications 002021.exe Queries volume information: C:\Windows\Fonts\BRLNSDB.TTF VolumeInformation Jump to behavior
Source: C:\Users\user\Desktop\Inquiry - Specifications 002021.exe Queries volume information: C:\Windows\Fonts\BRLNSB.TTF VolumeInformation Jump to behavior
Source: C:\Users\user\Desktop\Inquiry - Specifications 002021.exe Queries volume information: C:\Windows\Fonts\BERNHC.TTF VolumeInformation Jump to behavior
Source: C:\Users\user\Desktop\Inquiry - Specifications 002021.exe Queries volume information: C:\Windows\Fonts\BOD_PSTC.TTF VolumeInformation Jump to behavior
Source: C:\Users\user\Desktop\Inquiry - Specifications 002021.exe Queries volume information: C:\Windows\Fonts\BRITANIC.TTF VolumeInformation Jump to behavior
Source: C:\Users\user\Desktop\Inquiry - Specifications 002021.exe Queries volume information: C:\Windows\Fonts\BROADW.TTF VolumeInformation Jump to behavior
Source: C:\Users\user\Desktop\Inquiry - Specifications 002021.exe Queries volume information: C:\Windows\Fonts\BRUSHSCI.TTF VolumeInformation Jump to behavior
Source: C:\Users\user\Desktop\Inquiry - Specifications 002021.exe Queries volume information: C:\Windows\Fonts\CALIFR.TTF VolumeInformation Jump to behavior
Source: C:\Users\user\Desktop\Inquiry - Specifications 002021.exe Queries volume information: C:\Windows\Fonts\CALIFI.TTF VolumeInformation Jump to behavior
Source: C:\Users\user\Desktop\Inquiry - Specifications 002021.exe Queries volume information: C:\Windows\Fonts\CALIFB.TTF VolumeInformation Jump to behavior
Source: C:\Users\user\Desktop\Inquiry - Specifications 002021.exe Queries volume information: C:\Windows\Fonts\CENTAUR.TTF VolumeInformation Jump to behavior
Source: C:\Users\user\Desktop\Inquiry - Specifications 002021.exe Queries volume information: C:\Windows\Fonts\CHILLER.TTF VolumeInformation Jump to behavior
Source: C:\Users\user\Desktop\Inquiry - Specifications 002021.exe Queries volume information: C:\Windows\Fonts\COLONNA.TTF VolumeInformation Jump to behavior
Source: C:\Users\user\Desktop\Inquiry - Specifications 002021.exe Queries volume information: C:\Windows\Fonts\COOPBL.TTF VolumeInformation Jump to behavior
Source: C:\Users\user\Desktop\Inquiry - Specifications 002021.exe Queries volume information: C:\Windows\Fonts\FTLTLT.TTF VolumeInformation Jump to behavior
Source: C:\Users\user\Desktop\Inquiry - Specifications 002021.exe Queries volume information: C:\Windows\Fonts\HARLOWSI.TTF VolumeInformation Jump to behavior
Source: C:\Users\user\Desktop\Inquiry - Specifications 002021.exe Queries volume information: C:\Windows\Fonts\HARNGTON.TTF VolumeInformation Jump to behavior
Source: C:\Users\user\Desktop\Inquiry - Specifications 002021.exe Queries volume information: C:\Windows\Fonts\HTOWERT.TTF VolumeInformation Jump to behavior
Source: C:\Users\user\Desktop\Inquiry - Specifications 002021.exe Queries volume information: C:\Windows\Fonts\HTOWERTI.TTF VolumeInformation Jump to behavior
Source: C:\Users\user\Desktop\Inquiry - Specifications 002021.exe Queries volume information: C:\Windows\Fonts\JOKERMAN.TTF VolumeInformation Jump to behavior
Source: C:\Users\user\Desktop\Inquiry - Specifications 002021.exe Queries volume information: C:\Windows\Fonts\KUNSTLER.TTF VolumeInformation Jump to behavior
Source: C:\Users\user\Desktop\Inquiry - Specifications 002021.exe Queries volume information: C:\Windows\Fonts\LBRITE.TTF VolumeInformation Jump to behavior
Source: C:\Users\user\Desktop\Inquiry - Specifications 002021.exe Queries volume information: C:\Windows\Fonts\LBRITED.TTF VolumeInformation Jump to behavior
Source: C:\Users\user\Desktop\Inquiry - Specifications 002021.exe Queries volume information: C:\Windows\Fonts\LBRITEI.TTF VolumeInformation Jump to behavior
Source: C:\Users\user\Desktop\Inquiry - Specifications 002021.exe Queries volume information: C:\Windows\Fonts\LBRITEDI.TTF VolumeInformation Jump to behavior
Source: C:\Users\user\Desktop\Inquiry - Specifications 002021.exe Queries volume information: C:\Windows\Fonts\LCALLIG.TTF VolumeInformation Jump to behavior
Source: C:\Users\user\Desktop\Inquiry - Specifications 002021.exe Queries volume information: C:\Windows\Fonts\LFAX.TTF VolumeInformation Jump to behavior
Source: C:\Users\user\Desktop\Inquiry - Specifications 002021.exe Queries volume information: C:\Windows\Fonts\LFAXD.TTF VolumeInformation Jump to behavior
Source: C:\Users\user\Desktop\Inquiry - Specifications 002021.exe Queries volume information: C:\Windows\Fonts\LFAXI.TTF VolumeInformation Jump to behavior
Source: C:\Users\user\Desktop\Inquiry - Specifications 002021.exe Queries volume information: C:\Windows\Fonts\LFAXDI.TTF VolumeInformation Jump to behavior
Source: C:\Users\user\Desktop\Inquiry - Specifications 002021.exe Queries volume information: C:\Windows\Fonts\MAGNETOB.TTF VolumeInformation Jump to behavior
Source: C:\Users\user\Desktop\Inquiry - Specifications 002021.exe Queries volume information: C:\Windows\Fonts\MATURASC.TTF VolumeInformation Jump to behavior
Source: C:\Users\user\Desktop\Inquiry - Specifications 002021.exe Queries volume information: C:\Windows\Fonts\MOD20.TTF VolumeInformation Jump to behavior
Source: C:\Users\user\Desktop\Inquiry - Specifications 002021.exe Queries volume information: C:\Windows\Fonts\NIAGENG.TTF VolumeInformation Jump to behavior
Source: C:\Users\user\Desktop\Inquiry - Specifications 002021.exe Queries volume information: C:\Windows\Fonts\NIAGSOL.TTF VolumeInformation Jump to behavior
Source: C:\Users\user\Desktop\Inquiry - Specifications 002021.exe Queries volume information: C:\Windows\Fonts\OLDENGL.TTF VolumeInformation Jump to behavior
Source: C:\Users\user\Desktop\Inquiry - Specifications 002021.exe Queries volume information: C:\Windows\Fonts\ONYX.TTF VolumeInformation Jump to behavior
Source: C:\Users\user\Desktop\Inquiry - Specifications 002021.exe Queries volume information: C:\Windows\Fonts\PARCHM.TTF VolumeInformation Jump to behavior
Source: C:\Users\user\Desktop\Inquiry - Specifications 002021.exe Queries volume information: C:\Windows\Fonts\PLAYBILL.TTF VolumeInformation Jump to behavior
Source: C:\Users\user\Desktop\Inquiry - Specifications 002021.exe Queries volume information: C:\Windows\Fonts\POORICH.TTF VolumeInformation Jump to behavior
Source: C:\Users\user\Desktop\Inquiry - Specifications 002021.exe Queries volume information: C:\Windows\Fonts\RAVIE.TTF VolumeInformation Jump to behavior
Source: C:\Users\user\Desktop\Inquiry - Specifications 002021.exe Queries volume information: C:\Windows\Fonts\INFROMAN.TTF VolumeInformation Jump to behavior
Source: C:\Users\user\Desktop\Inquiry - Specifications 002021.exe Queries volume information: C:\Windows\Fonts\SHOWG.TTF VolumeInformation Jump to behavior
Source: C:\Users\user\Desktop\Inquiry - Specifications 002021.exe Queries volume information: C:\Windows\Fonts\SNAP____.TTF VolumeInformation Jump to behavior
Source: C:\Users\user\Desktop\Inquiry - Specifications 002021.exe Queries volume information: C:\Windows\Fonts\STENCIL.TTF VolumeInformation Jump to behavior
Source: C:\Users\user\Desktop\Inquiry - Specifications 002021.exe Queries volume information: C:\Windows\Fonts\VINERITC.TTF VolumeInformation Jump to behavior
Source: C:\Users\user\Desktop\Inquiry - Specifications 002021.exe Queries volume information: C:\Windows\Fonts\VIVALDII.TTF VolumeInformation Jump to behavior
Source: C:\Users\user\Desktop\Inquiry - Specifications 002021.exe Queries volume information: C:\Windows\Fonts\VLADIMIR.TTF VolumeInformation Jump to behavior
Source: C:\Users\user\Desktop\Inquiry - Specifications 002021.exe Queries volume information: C:\Windows\Fonts\LATINWD.TTF VolumeInformation Jump to behavior
Source: C:\Users\user\Desktop\Inquiry - Specifications 002021.exe Queries volume information: C:\Windows\Fonts\TCM_____.TTF VolumeInformation Jump to behavior
Source: C:\Users\user\Desktop\Inquiry - Specifications 002021.exe Queries volume information: C:\Windows\Fonts\TCMI____.TTF VolumeInformation Jump to behavior
Source: C:\Users\user\Desktop\Inquiry - Specifications 002021.exe Queries volume information: C:\Windows\Fonts\TCB_____.TTF VolumeInformation Jump to behavior
Source: C:\Users\user\Desktop\Inquiry - Specifications 002021.exe Queries volume information: C:\Windows\Fonts\TCBI____.TTF VolumeInformation Jump to behavior
Source: C:\Users\user\Desktop\Inquiry - Specifications 002021.exe Queries volume information: C:\Windows\Fonts\TCCM____.TTF VolumeInformation Jump to behavior
Source: C:\Users\user\Desktop\Inquiry - Specifications 002021.exe Queries volume information: C:\Windows\Fonts\TCCB____.TTF VolumeInformation Jump to behavior
Source: C:\Users\user\Desktop\Inquiry - Specifications 002021.exe Queries volume information: C:\Windows\Fonts\TCCEB.TTF VolumeInformation Jump to behavior
Source: C:\Users\user\Desktop\Inquiry - Specifications 002021.exe Queries volume information: C:\Windows\Fonts\SCRIPTBL.TTF VolumeInformation Jump to behavior
Source: C:\Users\user\Desktop\Inquiry - Specifications 002021.exe Queries volume information: C:\Windows\Fonts\ROCK.TTF VolumeInformation Jump to behavior
Source: C:\Users\user\Desktop\Inquiry - Specifications 002021.exe Queries volume information: C:\Windows\Fonts\ROCKI.TTF VolumeInformation Jump to behavior
Source: C:\Users\user\Desktop\Inquiry - Specifications 002021.exe Queries volume information: C:\Windows\Fonts\ROCKB.TTF VolumeInformation Jump to behavior
Source: C:\Users\user\Desktop\Inquiry - Specifications 002021.exe Queries volume information: C:\Windows\Fonts\ROCKEB.TTF VolumeInformation Jump to behavior
Source: C:\Users\user\Desktop\Inquiry - Specifications 002021.exe Queries volume information: C:\Windows\Fonts\ROCKBI.TTF VolumeInformation Jump to behavior
Source: C:\Users\user\Desktop\Inquiry - Specifications 002021.exe Queries volume information: C:\Windows\Fonts\ROCC____.TTF VolumeInformation Jump to behavior
Source: C:\Users\user\Desktop\Inquiry - Specifications 002021.exe Queries volume information: C:\Windows\Fonts\ROCCB___.TTF VolumeInformation Jump to behavior
Source: C:\Users\user\Desktop\Inquiry - Specifications 002021.exe Queries volume information: C:\Windows\Fonts\RAGE.TTF VolumeInformation Jump to behavior
Source: C:\Users\user\Desktop\Inquiry - Specifications 002021.exe Queries volume information: C:\Windows\Fonts\PERTILI.TTF VolumeInformation Jump to behavior
Source: C:\Users\user\Desktop\Inquiry - Specifications 002021.exe Queries volume information: C:\Windows\Fonts\PERTIBD.TTF VolumeInformation Jump to behavior
Source: C:\Users\user\Desktop\Inquiry - Specifications 002021.exe Queries volume information: C:\Windows\Fonts\PER_____.TTF VolumeInformation Jump to behavior
Source: C:\Users\user\Desktop\Inquiry - Specifications 002021.exe Queries volume information: C:\Windows\Fonts\PERI____.TTF VolumeInformation Jump to behavior
Source: C:\Users\user\Desktop\Inquiry - Specifications 002021.exe Queries volume information: C:\Windows\Fonts\PERB____.TTF VolumeInformation Jump to behavior
Source: C:\Users\user\Desktop\Inquiry - Specifications 002021.exe Queries volume information: C:\Windows\Fonts\PERBI___.TTF VolumeInformation Jump to behavior
Source: C:\Users\user\Desktop\Inquiry - Specifications 002021.exe Queries volume information: C:\Windows\Fonts\PALSCRI.TTF VolumeInformation Jump to behavior
Source: C:\Users\user\Desktop\Inquiry - Specifications 002021.exe Queries volume information: C:\Windows\Fonts\OCRAEXT.TTF VolumeInformation Jump to behavior
Source: C:\Users\user\Desktop\Inquiry - Specifications 002021.exe Queries volume information: C:\Windows\Fonts\MAIAN.TTF VolumeInformation Jump to behavior
Source: C:\Users\user\Desktop\Inquiry - Specifications 002021.exe Queries volume information: C:\Windows\Fonts\LTYPE.TTF VolumeInformation Jump to behavior
Source: C:\Users\user\Desktop\Inquiry - Specifications 002021.exe Queries volume information: C:\Windows\Fonts\LTYPEO.TTF VolumeInformation Jump to behavior
Source: C:\Users\user\Desktop\Inquiry - Specifications 002021.exe Queries volume information: C:\Windows\Fonts\LTYPEB.TTF VolumeInformation Jump to behavior
Source: C:\Users\user\Desktop\Inquiry - Specifications 002021.exe Queries volume information: C:\Windows\Fonts\LTYPEBO.TTF VolumeInformation Jump to behavior
Source: C:\Users\user\Desktop\Inquiry - Specifications 002021.exe Queries volume information: C:\Windows\Fonts\LSANS.TTF VolumeInformation Jump to behavior
Source: C:\Users\user\Desktop\Inquiry - Specifications 002021.exe Queries volume information: C:\Windows\Fonts\LSANSD.TTF VolumeInformation Jump to behavior
Source: C:\Users\user\Desktop\Inquiry - Specifications 002021.exe Queries volume information: C:\Windows\Fonts\LSANSI.TTF VolumeInformation Jump to behavior
Source: C:\Users\user\Desktop\Inquiry - Specifications 002021.exe Queries volume information: C:\Windows\Fonts\LSANSDI.TTF VolumeInformation Jump to behavior
Source: C:\Users\user\Desktop\Inquiry - Specifications 002021.exe Queries volume information: C:\Windows\Fonts\IMPRISHA.TTF VolumeInformation Jump to behavior
Source: C:\Users\user\Desktop\Inquiry - Specifications 002021.exe Queries volume information: C:\Windows\Fonts\HATTEN.TTF VolumeInformation Jump to behavior
Source: C:\Users\user\Desktop\Inquiry - Specifications 002021.exe Queries volume information: C:\Windows\Fonts\GOUDYSTO.TTF VolumeInformation Jump to behavior
Source: C:\Users\user\Desktop\Inquiry - Specifications 002021.exe Queries volume information: C:\Windows\Fonts\GOUDOS.TTF VolumeInformation Jump to behavior
Source: C:\Users\user\Desktop\Inquiry - Specifications 002021.exe Queries volume information: C:\Windows\Fonts\GOUDOSI.TTF VolumeInformation Jump to behavior
Source: C:\Users\user\Desktop\Inquiry - Specifications 002021.exe Queries volume information: C:\Windows\Fonts\GOUDOSB.TTF VolumeInformation Jump to behavior
Source: C:\Users\user\Desktop\Inquiry - Specifications 002021.exe Queries volume information: C:\Windows\Fonts\GLECB.TTF VolumeInformation Jump to behavior
Source: C:\Users\user\Desktop\Inquiry - Specifications 002021.exe Queries volume information: C:\Windows\Fonts\GIL_____.TTF VolumeInformation Jump to behavior
Source: C:\Users\user\Desktop\Inquiry - Specifications 002021.exe Queries volume information: C:\Windows\Fonts\GILI____.TTF VolumeInformation Jump to behavior
Source: C:\Users\user\Desktop\Inquiry - Specifications 002021.exe Queries volume information: C:\Windows\Fonts\GILB____.TTF VolumeInformation Jump to behavior
Source: C:\Users\user\Desktop\Inquiry - Specifications 002021.exe Queries volume information: C:\Windows\Fonts\GILBI___.TTF VolumeInformation Jump to behavior
Source: C:\Users\user\Desktop\Inquiry - Specifications 002021.exe Queries volume information: C:\Windows\Fonts\GILC____.TTF VolumeInformation Jump to behavior
Source: C:\Users\user\Desktop\Inquiry - Specifications 002021.exe Queries volume information: C:\Windows\Fonts\GLSNECB.TTF VolumeInformation Jump to behavior
Source: C:\Users\user\Desktop\Inquiry - Specifications 002021.exe Queries volume information: C:\Windows\Fonts\GIGI.TTF VolumeInformation Jump to behavior
Source: C:\Users\user\Desktop\Inquiry - Specifications 002021.exe Queries volume information: C:\Windows\Fonts\FRABK.TTF VolumeInformation Jump to behavior
Source: C:\Users\user\Desktop\Inquiry - Specifications 002021.exe Queries volume information: C:\Windows\Fonts\FRABKIT.TTF VolumeInformation Jump to behavior
Source: C:\Users\user\Desktop\Inquiry - Specifications 002021.exe Queries volume information: C:\Windows\Fonts\FORTE.TTF VolumeInformation Jump to behavior
Source: C:\Users\user\Desktop\Inquiry - Specifications 002021.exe Queries volume information: C:\Windows\Fonts\FELIXTI.TTF VolumeInformation Jump to behavior
Source: C:\Users\user\Desktop\Inquiry - Specifications 002021.exe Queries volume information: C:\Windows\Fonts\ERASMD.TTF VolumeInformation Jump to behavior
Source: C:\Users\user\Desktop\Inquiry - Specifications 002021.exe Queries volume information: C:\Windows\Fonts\ERASLGHT.TTF VolumeInformation Jump to behavior
Source: C:\Users\user\Desktop\Inquiry - Specifications 002021.exe Queries volume information: C:\Windows\Fonts\ERASDEMI.TTF VolumeInformation Jump to behavior
Source: C:\Users\user\Desktop\Inquiry - Specifications 002021.exe Queries volume information: C:\Windows\Fonts\ERASBD.TTF VolumeInformation Jump to behavior
Source: C:\Users\user\Desktop\Inquiry - Specifications 002021.exe Queries volume information: C:\Windows\Fonts\ENGR.TTF VolumeInformation Jump to behavior
Source: C:\Users\user\Desktop\Inquiry - Specifications 002021.exe Queries volume information: C:\Windows\Fonts\ELEPHNT.TTF VolumeInformation Jump to behavior
Source: C:\Users\user\Desktop\Inquiry - Specifications 002021.exe Queries volume information: C:\Windows\Fonts\ELEPHNTI.TTF VolumeInformation Jump to behavior
Source: C:\Users\user\Desktop\Inquiry - Specifications 002021.exe Queries volume information: C:\Windows\Fonts\ITCEDSCR.TTF VolumeInformation Jump to behavior
Source: C:\Users\user\Desktop\Inquiry - Specifications 002021.exe Queries volume information: C:\Windows\Fonts\CURLZ___.TTF VolumeInformation Jump to behavior
Source: C:\Users\user\Desktop\Inquiry - Specifications 002021.exe Queries volume information: C:\Windows\Fonts\COPRGTL.TTF VolumeInformation Jump to behavior
Source: C:\Users\user\Desktop\Inquiry - Specifications 002021.exe Queries volume information: C:\Windows\Fonts\COPRGTB.TTF VolumeInformation Jump to behavior
Source: C:\Users\user\Desktop\Inquiry - Specifications 002021.exe Queries volume information: C:\Windows\Fonts\CENSCBK.TTF VolumeInformation Jump to behavior
Source: C:\Users\user\Desktop\Inquiry - Specifications 002021.exe Queries volume information: C:\Windows\Fonts\SCHLBKI.TTF VolumeInformation Jump to behavior
Source: C:\Users\user\Desktop\Inquiry - Specifications 002021.exe Queries volume information: C:\Windows\Fonts\SCHLBKB.TTF VolumeInformation Jump to behavior
Source: C:\Users\user\Desktop\Inquiry - Specifications 002021.exe Queries volume information: C:\Windows\Fonts\SCHLBKBI.TTF VolumeInformation Jump to behavior
Source: C:\Users\user\Desktop\Inquiry - Specifications 002021.exe Queries volume information: C:\Windows\Fonts\CASTELAR.TTF VolumeInformation Jump to behavior
Source: C:\Users\user\Desktop\Inquiry - Specifications 002021.exe Queries volume information: C:\Windows\Fonts\CALIST.TTF VolumeInformation Jump to behavior
Source: C:\Users\user\Desktop\Inquiry - Specifications 002021.exe Queries volume information: C:\Windows\Fonts\CALISTI.TTF VolumeInformation Jump to behavior
Source: C:\Users\user\Desktop\Inquiry - Specifications 002021.exe Queries volume information: C:\Windows\Fonts\CALISTB.TTF VolumeInformation Jump to behavior
Source: C:\Users\user\Desktop\Inquiry - Specifications 002021.exe Queries volume information: C:\Windows\Fonts\CALISTBI.TTF VolumeInformation Jump to behavior
Source: C:\Users\user\Desktop\Inquiry - Specifications 002021.exe Queries volume information: C:\Windows\Fonts\BOOKOS.TTF VolumeInformation Jump to behavior
Source: C:\Users\user\Desktop\Inquiry - Specifications 002021.exe Queries volume information: C:\Windows\Fonts\BOOKOSB.TTF VolumeInformation Jump to behavior
Source: C:\Users\user\Desktop\Inquiry - Specifications 002021.exe Queries volume information: C:\Windows\Fonts\BOOKOSI.TTF VolumeInformation Jump to behavior
Source: C:\Users\user\Desktop\Inquiry - Specifications 002021.exe Queries volume information: C:\Windows\Fonts\BOOKOSBI.TTF VolumeInformation Jump to behavior
Source: C:\Users\user\Desktop\Inquiry - Specifications 002021.exe Queries volume information: C:\Windows\Fonts\BOD_R.TTF VolumeInformation Jump to behavior
Source: C:\Users\user\Desktop\Inquiry - Specifications 002021.exe Queries volume information: C:\Windows\Fonts\BOD_I.TTF VolumeInformation Jump to behavior
Source: C:\Users\user\Desktop\Inquiry - Specifications 002021.exe Queries volume information: C:\Windows\Fonts\BOD_B.TTF VolumeInformation Jump to behavior
Source: C:\Users\user\Desktop\Inquiry - Specifications 002021.exe Queries volume information: C:\Windows\Fonts\BOD_BI.TTF VolumeInformation Jump to behavior
Source: C:\Users\user\Desktop\Inquiry - Specifications 002021.exe Queries volume information: C:\Windows\Fonts\BOD_CR.TTF VolumeInformation Jump to behavior
Source: C:\Users\user\Desktop\Inquiry - Specifications 002021.exe Queries volume information: C:\Windows\Fonts\BOD_BLAR.TTF VolumeInformation Jump to behavior
Source: C:\Users\user\Desktop\Inquiry - Specifications 002021.exe Queries volume information: C:\Windows\Fonts\BOD_CI.TTF VolumeInformation Jump to behavior
Source: C:\Users\user\Desktop\Inquiry - Specifications 002021.exe Queries volume information: C:\Windows\Fonts\BOD_CB.TTF VolumeInformation Jump to behavior
Source: C:\Users\user\Desktop\Inquiry - Specifications 002021.exe Queries volume information: C:\Windows\Fonts\BOD_BLAI.TTF VolumeInformation Jump to behavior
Source: C:\Users\user\Desktop\Inquiry - Specifications 002021.exe Queries volume information: C:\Windows\Fonts\BOD_CBI.TTF VolumeInformation Jump to behavior
Source: C:\Users\user\Desktop\Inquiry - Specifications 002021.exe Queries volume information: C:\Windows\Fonts\ITCBLKAD.TTF VolumeInformation Jump to behavior
Source: C:\Users\user\Desktop\Inquiry - Specifications 002021.exe Queries volume information: C:\Windows\Fonts\ARLRDBD.TTF VolumeInformation Jump to behavior
Source: C:\Users\user\Desktop\Inquiry - Specifications 002021.exe Queries volume information: C:\Windows\Fonts\AGENCYR.TTF VolumeInformation Jump to behavior
Source: C:\Users\user\Desktop\Inquiry - Specifications 002021.exe Queries volume information: C:\Windows\Fonts\AGENCYB.TTF VolumeInformation Jump to behavior
Source: C:\Users\user\Desktop\Inquiry - Specifications 002021.exe Queries volume information: C:\Windows\Fonts\BSSYM7.TTF VolumeInformation Jump to behavior
Source: C:\Users\user\Desktop\Inquiry - Specifications 002021.exe Queries volume information: C:\Windows\Fonts\REFSAN.TTF VolumeInformation Jump to behavior
Source: C:\Users\user\Desktop\Inquiry - Specifications 002021.exe Queries volume information: C:\Windows\Fonts\REFSPCL.TTF VolumeInformation Jump to behavior
Source: C:\Users\user\Desktop\Inquiry - Specifications 002021.exe Queries volume information: C:\Windows\Fonts\MTEXTRA.TTF VolumeInformation Jump to behavior
Source: C:\Users\user\Desktop\Inquiry - Specifications 002021.exe Queries volume information: C:\Windows\Fonts\marlett.ttf VolumeInformation Jump to behavior
Source: C:\Users\user\Desktop\Inquiry - Specifications 002021.exe Queries volume information: C:\Windows\Fonts\micross.ttf VolumeInformation Jump to behavior
Source: C:\Users\user\Desktop\Inquiry - Specifications 002021.exe Queries volume information: C:\Windows\Fonts\segoeuii.ttf VolumeInformation Jump to behavior
Source: C:\Users\user\Desktop\Inquiry - Specifications 002021.exe Queries volume information: C:\Windows\Fonts\segoeuiz.ttf VolumeInformation Jump to behavior
Source: C:\Users\user\Desktop\Inquiry - Specifications 002021.exe Queries volume information: C:\Windows\Microsoft.NET\assembly\GAC_MSIL\Microsoft.VisualBasic\v4.0_10.0.0.0__b03f5f7f11d50a3a\Microsoft.VisualBasic.dll VolumeInformation Jump to behavior
Source: C:\Users\user\Desktop\Inquiry - Specifications 002021.exe Queries volume information: C:\Windows\Microsoft.NET\assembly\GAC_MSIL\System.Data.Entity\v4.0_4.0.0.0__b77a5c561934e089\System.Data.Entity.dll VolumeInformation Jump to behavior
Source: C:\Users\user\Desktop\Inquiry - Specifications 002021.exe Queries volume information: C:\Users\user\Desktop\Inquiry - Specifications 002021.exe VolumeInformation Jump to behavior
Source: C:\Users\user\Desktop\Inquiry - Specifications 002021.exe Queries volume information: C:\Windows\Microsoft.NET\assembly\GAC_MSIL\System.Windows.Forms\v4.0_4.0.0.0__b77a5c561934e089\System.Windows.Forms.dll VolumeInformation Jump to behavior
Source: C:\Users\user\Desktop\Inquiry - Specifications 002021.exe Queries volume information: C:\Windows\Microsoft.NET\assembly\GAC_MSIL\Microsoft.VisualBasic\v4.0_10.0.0.0__b03f5f7f11d50a3a\Microsoft.VisualBasic.dll VolumeInformation Jump to behavior
Source: C:\Users\user\Desktop\Inquiry - Specifications 002021.exe Queries volume information: C:\Windows\Microsoft.NET\assembly\GAC_32\CustomMarshalers\v4.0_4.0.0.0__b03f5f7f11d50a3a\CustomMarshalers.dll VolumeInformation Jump to behavior
Source: C:\Users\user\Desktop\Inquiry - Specifications 002021.exe Queries volume information: C:\Windows\Microsoft.NET\assembly\GAC_32\CustomMarshalers\v4.0_4.0.0.0__b03f5f7f11d50a3a\CustomMarshalers.dll VolumeInformation Jump to behavior
Source: C:\Users\user\Desktop\Inquiry - Specifications 002021.exe Queries volume information: C:\Windows\Microsoft.NET\assembly\GAC_32\CustomMarshalers\v4.0_4.0.0.0__b03f5f7f11d50a3a\CustomMarshalers.dll VolumeInformation Jump to behavior
Source: C:\Users\user\Desktop\Inquiry - Specifications 002021.exe Queries volume information: C:\Windows\Microsoft.NET\assembly\GAC_MSIL\System.Management\v4.0_4.0.0.0__b03f5f7f11d50a3a\System.Management.dll VolumeInformation Jump to behavior
Source: C:\Users\user\Desktop\Inquiry - Specifications 002021.exe Queries volume information: C:\Windows\Microsoft.NET\assembly\GAC_MSIL\System.Drawing\v4.0_4.0.0.0__b03f5f7f11d50a3a\System.Drawing.dll VolumeInformation Jump to behavior
Source: C:\Users\user\Desktop\Inquiry - Specifications 002021.exe Queries volume information: C:\Windows\Microsoft.NET\assembly\GAC_MSIL\Accessibility\v4.0_4.0.0.0__b03f5f7f11d50a3a\Accessibility.dll VolumeInformation Jump to behavior
Source: C:\Users\user\Desktop\Inquiry - Specifications 002021.exe Key value queried: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Cryptography MachineGuid Jump to behavior

Stealing of Sensitive Information:

barindex
Yara detected AgentTesla
Source: Yara match File source: 0.2.Inquiry - Specifications 002021.exe.35a8b58.4.unpack, type: UNPACKEDPE
Source: Yara match File source: 0.2.Inquiry - Specifications 002021.exe.36d73e0.3.raw.unpack, type: UNPACKEDPE
Source: Yara match File source: 5.2.Inquiry - Specifications 002021.exe.400000.0.unpack, type: UNPACKEDPE
Source: Yara match File source: 0.2.Inquiry - Specifications 002021.exe.35a8b58.4.raw.unpack, type: UNPACKEDPE
Source: Yara match File source: 00000005.00000002.553693912.0000000000402000.00000040.00000001.sdmp, type: MEMORY
Source: Yara match File source: 00000000.00000002.329163786.00000000034D1000.00000004.00000001.sdmp, type: MEMORY
Source: Yara match File source: 00000005.00000002.559497777.00000000030EF000.00000004.00000001.sdmp, type: MEMORY
Source: Yara match File source: 00000005.00000002.558228658.0000000002E01000.00000004.00000001.sdmp, type: MEMORY
Source: Yara match File source: Process Memory Space: Inquiry - Specifications 002021.exe PID: 1360, type: MEMORYSTR
Source: Yara match File source: Process Memory Space: Inquiry - Specifications 002021.exe PID: 6580, type: MEMORYSTR
Tries to harvest and steal Putty / WinSCP information (sessions, passwords, etc)
Source: C:\Users\user\Desktop\Inquiry - Specifications 002021.exe Key opened: HKEY_CURRENT_USER\SOFTWARE\Martin Prikryl\WinSCP 2\Sessions Jump to behavior
Tries to harvest and steal ftp login credentials
Source: C:\Users\user\Desktop\Inquiry - Specifications 002021.exe File opened: C:\Users\user\AppData\Roaming\SmartFTP\Client 2.0\Favorites\Quick Connect\ Jump to behavior
Source: C:\Users\user\Desktop\Inquiry - Specifications 002021.exe File opened: C:\Users\user\AppData\Roaming\FileZilla\recentservers.xml Jump to behavior
Tries to steal Mail credentials (via file access)
Source: C:\Users\user\Desktop\Inquiry - Specifications 002021.exe File opened: C:\Users\user\AppData\Roaming\Thunderbird\profiles.ini Jump to behavior
Source: C:\Users\user\Desktop\Inquiry - Specifications 002021.exe File opened: C:\Users\user\AppData\Roaming\Thunderbird\profiles.ini Jump to behavior
Source: C:\Users\user\Desktop\Inquiry - Specifications 002021.exe Key opened: HKEY_CURRENT_USER\Software\IncrediMail\Identities Jump to behavior
Source: C:\Users\user\Desktop\Inquiry - Specifications 002021.exe Key opened: HKEY_CURRENT_USER\Software\Microsoft\Windows NT\CurrentVersion\Windows Messaging Subsystem\Profiles\Outlook\9375CFF0413111d3B88A00104B2A6676 Jump to behavior
Tries to harvest and steal browser information (history, passwords, etc)
Source: C:\Users\user\Desktop\Inquiry - Specifications 002021.exe File opened: C:\Users\user\AppData\Roaming\Mozilla\Firefox\profiles.ini Jump to behavior
Source: C:\Users\user\Desktop\Inquiry - Specifications 002021.exe File opened: C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Cookies Jump to behavior
Source: C:\Users\user\Desktop\Inquiry - Specifications 002021.exe File opened: C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Login Data Jump to behavior
Yara detected Credential Stealer
Source: Yara match File source: 00000005.00000002.558228658.0000000002E01000.00000004.00000001.sdmp, type: MEMORY
Source: Yara match File source: Process Memory Space: Inquiry - Specifications 002021.exe PID: 6580, type: MEMORYSTR

Remote Access Functionality:

barindex
Yara detected AgentTesla
Source: Yara match File source: 0.2.Inquiry - Specifications 002021.exe.35a8b58.4.unpack, type: UNPACKEDPE
Source: Yara match File source: 0.2.Inquiry - Specifications 002021.exe.36d73e0.3.raw.unpack, type: UNPACKEDPE
Source: Yara match File source: 5.2.Inquiry - Specifications 002021.exe.400000.0.unpack, type: UNPACKEDPE
Source: Yara match File source: 0.2.Inquiry - Specifications 002021.exe.35a8b58.4.raw.unpack, type: UNPACKEDPE
Source: Yara match File source: 00000005.00000002.553693912.0000000000402000.00000040.00000001.sdmp, type: MEMORY
Source: Yara match File source: 00000000.00000002.329163786.00000000034D1000.00000004.00000001.sdmp, type: MEMORY
Source: Yara match File source: 00000005.00000002.559497777.00000000030EF000.00000004.00000001.sdmp, type: MEMORY
Source: Yara match File source: 00000005.00000002.558228658.0000000002E01000.00000004.00000001.sdmp, type: MEMORY
Source: Yara match File source: Process Memory Space: Inquiry - Specifications 002021.exe PID: 1360, type: MEMORYSTR
Source: Yara match File source: Process Memory Space: Inquiry - Specifications 002021.exe PID: 6580, type: MEMORYSTR
  • No. of IPs < 25%
  • 25% < No. of IPs < 50%
  • 50% < No. of IPs < 75%
  • 75% < No. of IPs