Source: 00000001.00000002.505045374.0000000002A30000.00000040.00000001.sdmp |
Malware Configuration Extractor: GuLoader {"Payload URL": "https://drive.google.com/uc?export=download&id=1ycJKs"} |
Source: GRUPO MARI#U00d1O OBRAS Y SERVICIOS, SL Oferta 2709213390.exe |
Virustotal: Detection: 27% |
Perma Link |
Source: GRUPO MARI#U00d1O OBRAS Y SERVICIOS, SL Oferta 2709213390.exe |
ReversingLabs: Detection: 11% |
Source: GRUPO MARI#U00d1O OBRAS Y SERVICIOS, SL Oferta 2709213390.exe |
Static PE information: LOCAL_SYMS_STRIPPED, 32BIT_MACHINE, EXECUTABLE_IMAGE, LINE_NUMS_STRIPPED, RELOCS_STRIPPED |
Source: Malware configuration extractor |
URLs: https://drive.google.com/uc?export=download&id=1ycJKs |
Source: GRUPO MARI#U00d1O OBRAS Y SERVICIOS, SL Oferta 2709213390.exe |
Static PE information: LOCAL_SYMS_STRIPPED, 32BIT_MACHINE, EXECUTABLE_IMAGE, LINE_NUMS_STRIPPED, RELOCS_STRIPPED |
Source: GRUPO MARI#U00d1O OBRAS Y SERVICIOS, SL Oferta 2709213390.exe, 00000001.00000000.237743772.0000000000417000.00000002.00020000.sdmp |
Binary or memory string: OriginalFilenameKios2.exe vs GRUPO MARI#U00d1O OBRAS Y SERVICIOS, SL Oferta 2709213390.exe |
Source: GRUPO MARI#U00d1O OBRAS Y SERVICIOS, SL Oferta 2709213390.exe |
Binary or memory string: OriginalFilenameKios2.exe vs GRUPO MARI#U00d1O OBRAS Y SERVICIOS, SL Oferta 2709213390.exe |
Source: GRUPO MARI#U00d1O OBRAS Y SERVICIOS, SL Oferta 2709213390.exe |
Static PE information: Resource name: RT_ICON type: GLS_BINARY_LSB_FIRST |
Source: C:\Users\user\Desktop\GRUPO MARI#U00d1O OBRAS Y SERVICIOS, SL Oferta 2709213390.exe |
Code function: 1_2_02A37233 |
1_2_02A37233 |
Source: C:\Users\user\Desktop\GRUPO MARI#U00d1O OBRAS Y SERVICIOS, SL Oferta 2709213390.exe |
Code function: 1_2_02A37403 |
1_2_02A37403 |
Source: GRUPO MARI#U00d1O OBRAS Y SERVICIOS, SL Oferta 2709213390.exe |
Virustotal: Detection: 27% |
Source: GRUPO MARI#U00d1O OBRAS Y SERVICIOS, SL Oferta 2709213390.exe |
ReversingLabs: Detection: 11% |
Source: C:\Users\user\Desktop\GRUPO MARI#U00d1O OBRAS Y SERVICIOS, SL Oferta 2709213390.exe |
File created: C:\Users\user\AppData\Local\Temp\~DF2528AA0FB36E21C6.TMP |
Jump to behavior |
Source: GRUPO MARI#U00d1O OBRAS Y SERVICIOS, SL Oferta 2709213390.exe |
Static PE information: Section: .text IMAGE_SCN_MEM_EXECUTE, IMAGE_SCN_CNT_CODE, IMAGE_SCN_MEM_READ |
Source: C:\Users\user\Desktop\GRUPO MARI#U00d1O OBRAS Y SERVICIOS, SL Oferta 2709213390.exe |
Key opened: HKEY_CURRENT_USER\Software\Policies\Microsoft\Windows\Safer\CodeIdentifiers |
Jump to behavior |
Source: C:\Users\user\Desktop\GRUPO MARI#U00d1O OBRAS Y SERVICIOS, SL Oferta 2709213390.exe |
Section loaded: C:\Windows\SysWOW64\msvbvm60.dll |
Jump to behavior |
Source: classification engine |
Classification label: mal68.troj.winEXE@1/0@0/0 |
Source: Yara match |
File source: 00000001.00000002.505045374.0000000002A30000.00000040.00000001.sdmp, type: MEMORY |
Source: C:\Users\user\Desktop\GRUPO MARI#U00d1O OBRAS Y SERVICIOS, SL Oferta 2709213390.exe |
Code function: 1_2_004055C5 push eax; retf |
1_2_004055C6 |
Source: C:\Users\user\Desktop\GRUPO MARI#U00d1O OBRAS Y SERVICIOS, SL Oferta 2709213390.exe |
Code function: 1_2_00402ACE push ecx; ret |
1_2_00402AD4 |
Source: C:\Users\user\Desktop\GRUPO MARI#U00d1O OBRAS Y SERVICIOS, SL Oferta 2709213390.exe |
Code function: 1_2_004066FC push ebx; ret |
1_2_00406705 |
Source: C:\Users\user\Desktop\GRUPO MARI#U00d1O OBRAS Y SERVICIOS, SL Oferta 2709213390.exe |
Code function: 1_2_02A320A4 push esp; iretd |
1_2_02A320A8 |
Source: C:\Users\user\Desktop\GRUPO MARI#U00d1O OBRAS Y SERVICIOS, SL Oferta 2709213390.exe |
Code function: 1_2_02A36288 push cs; iretd |
1_2_02A36311 |
Source: C:\Users\user\Desktop\GRUPO MARI#U00d1O OBRAS Y SERVICIOS, SL Oferta 2709213390.exe |
Code function: 1_2_02A350E2 push ebp; retf |
1_2_02A350E3 |
Source: C:\Users\user\Desktop\GRUPO MARI#U00d1O OBRAS Y SERVICIOS, SL Oferta 2709213390.exe |
Code function: 1_2_02A33EF3 push ss; ret |
1_2_02A33F02 |
Source: C:\Users\user\Desktop\GRUPO MARI#U00d1O OBRAS Y SERVICIOS, SL Oferta 2709213390.exe |
Code function: 1_2_02A344FF push cs; retf |
1_2_02A345D8 |
Source: C:\Users\user\Desktop\GRUPO MARI#U00d1O OBRAS Y SERVICIOS, SL Oferta 2709213390.exe |
Code function: 1_2_02A36215 push 89000002h; iretd |
1_2_02A3621A |
Source: C:\Users\user\Desktop\GRUPO MARI#U00d1O OBRAS Y SERVICIOS, SL Oferta 2709213390.exe |
Code function: 1_2_02A32219 push ss; iretd |
1_2_02A3225B |
Source: C:\Users\user\Desktop\GRUPO MARI#U00d1O OBRAS Y SERVICIOS, SL Oferta 2709213390.exe |
Code function: 1_2_02A3626F push cs; iretd |
1_2_02A36311 |
Source: C:\Users\user\Desktop\GRUPO MARI#U00d1O OBRAS Y SERVICIOS, SL Oferta 2709213390.exe |
Code function: 1_2_02A3225C push ss; iretd |
1_2_02A3225B |
Source: C:\Users\user\Desktop\GRUPO MARI#U00d1O OBRAS Y SERVICIOS, SL Oferta 2709213390.exe |
Code function: 1_2_02A321A7 push ss; iretd |
1_2_02A3225B |
Source: C:\Users\user\Desktop\GRUPO MARI#U00d1O OBRAS Y SERVICIOS, SL Oferta 2709213390.exe |
Code function: 1_2_02A363BB push ss; ret |
1_2_02A3640F |
Source: C:\Users\user\Desktop\GRUPO MARI#U00d1O OBRAS Y SERVICIOS, SL Oferta 2709213390.exe |
Code function: 1_2_02A363E9 push ss; ret |
1_2_02A3640F |
Source: C:\Users\user\Desktop\GRUPO MARI#U00d1O OBRAS Y SERVICIOS, SL Oferta 2709213390.exe |
Code function: 1_2_02A36312 push cs; iretd |
1_2_02A36311 |
Source: C:\Users\user\Desktop\GRUPO MARI#U00d1O OBRAS Y SERVICIOS, SL Oferta 2709213390.exe |
Code function: 1_2_02A32565 push ds; ret |
1_2_02A32566 |
Source: C:\Users\user\Desktop\GRUPO MARI#U00d1O OBRAS Y SERVICIOS, SL Oferta 2709213390.exe |
Code function: 1_2_02A34576 push cs; retf |
1_2_02A345D8 |
Source: C:\Users\user\Desktop\GRUPO MARI#U00d1O OBRAS Y SERVICIOS, SL Oferta 2709213390.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: all processes |
Thread injection, dropped files, key value created, disk infection and DNS query: no activity detected |
Source: C:\Users\user\Desktop\GRUPO MARI#U00d1O OBRAS Y SERVICIOS, SL Oferta 2709213390.exe |
Code function: 1_2_02A39850 rdtsc |
1_2_02A39850 |
Source: C:\Users\user\Desktop\GRUPO MARI#U00d1O OBRAS Y SERVICIOS, SL Oferta 2709213390.exe |
Code function: 1_2_02A3CC88 mov eax, dword ptr fs:[00000030h] |
1_2_02A3CC88 |
Source: C:\Users\user\Desktop\GRUPO MARI#U00d1O OBRAS Y SERVICIOS, SL Oferta 2709213390.exe |
Code function: 1_2_02A395F7 mov eax, dword ptr fs:[00000030h] |
1_2_02A395F7 |
Source: C:\Users\user\Desktop\GRUPO MARI#U00d1O OBRAS Y SERVICIOS, SL Oferta 2709213390.exe |
Code function: 1_2_02A3D33B mov eax, dword ptr fs:[00000030h] |
1_2_02A3D33B |
Source: all processes |
Thread injection, dropped files, key value created, disk infection and DNS query: no activity detected |
Source: C:\Users\user\Desktop\GRUPO MARI#U00d1O OBRAS Y SERVICIOS, SL Oferta 2709213390.exe |
Code function: 1_2_02A39850 rdtsc |
1_2_02A39850 |
Source: GRUPO MARI#U00d1O OBRAS Y SERVICIOS, SL Oferta 2709213390.exe, 00000001.00000002.504865617.0000000000C60000.00000002.00020000.sdmp |
Binary or memory string: Shell_TrayWnd |
Source: GRUPO MARI#U00d1O OBRAS Y SERVICIOS, SL Oferta 2709213390.exe, 00000001.00000002.504865617.0000000000C60000.00000002.00020000.sdmp |
Binary or memory string: Progman |
Source: GRUPO MARI#U00d1O OBRAS Y SERVICIOS, SL Oferta 2709213390.exe, 00000001.00000002.504865617.0000000000C60000.00000002.00020000.sdmp |
Binary or memory string: SProgram Managerl |
Source: GRUPO MARI#U00d1O OBRAS Y SERVICIOS, SL Oferta 2709213390.exe, 00000001.00000002.504865617.0000000000C60000.00000002.00020000.sdmp |
Binary or memory string: Shell_TrayWnd, |
Source: GRUPO MARI#U00d1O OBRAS Y SERVICIOS, SL Oferta 2709213390.exe, 00000001.00000002.504865617.0000000000C60000.00000002.00020000.sdmp |
Binary or memory string: Progmanlock |