Source: C:\Users\user\Desktop\QUOTATION OF EQUIPMENT.exe |
Code function: 0_2_00405E93 FindFirstFileA,FindClose, |
0_2_00405E93 |
Source: C:\Users\user\Desktop\QUOTATION OF EQUIPMENT.exe |
Code function: 0_2_004054BD DeleteFileA,lstrcatA,lstrcatA,lstrlenA,FindFirstFileA,DeleteFileA,FindNextFileA,FindClose,RemoveDirectoryA, |
0_2_004054BD |
Source: C:\Users\user\Desktop\QUOTATION OF EQUIPMENT.exe |
Code function: 0_2_00402671 FindFirstFileA, |
0_2_00402671 |
Source: C:\Users\user\Desktop\QUOTATION OF EQUIPMENT.exe |
Code function: 1_2_00404A29 FindFirstFileExW, |
1_2_00404A29 |
Source: QUOTATION OF EQUIPMENT.exe, 00000001.00000002.566863487.0000000002331000.00000004.00000001.sdmp |
String found in binary or memory: ftp://ftp.omindexgroup.com/info |
Source: QUOTATION OF EQUIPMENT.exe, 00000001.00000002.566863487.0000000002331000.00000004.00000001.sdmp |
String found in binary or memory: http://127.0.0.1:HTTP/1.1 |
Source: QUOTATION OF EQUIPMENT.exe, 00000001.00000002.566863487.0000000002331000.00000004.00000001.sdmp |
String found in binary or memory: http://DynDns.comDynDNS |
Source: QUOTATION OF EQUIPMENT.exe, 00000001.00000002.566863487.0000000002331000.00000004.00000001.sdmp |
String found in binary or memory: http://ftp.omindexgroup.com |
Source: QUOTATION OF EQUIPMENT.exe, 00000001.00000002.566863487.0000000002331000.00000004.00000001.sdmp, QUOTATION OF EQUIPMENT.exe, 00000001.00000003.514210140.00000000005C4000.00000004.00000001.sdmp |
String found in binary or memory: http://kMfms0NpHAa2q.org |
Source: QUOTATION OF EQUIPMENT.exe |
String found in binary or memory: http://nsis.sf.net/NSIS_Error |
Source: QUOTATION OF EQUIPMENT.exe |
String found in binary or memory: http://nsis.sf.net/NSIS_ErrorError |
Source: QUOTATION OF EQUIPMENT.exe, 00000001.00000002.566863487.0000000002331000.00000004.00000001.sdmp |
String found in binary or memory: http://schemas.xmlsoap.org/ws/2005/05/identity/claims/name |
Source: QUOTATION OF EQUIPMENT.exe, 00000001.00000002.566863487.0000000002331000.00000004.00000001.sdmp |
String found in binary or memory: http://yJUdUS.com |
Source: QUOTATION OF EQUIPMENT.exe, 00000001.00000002.566863487.0000000002331000.00000004.00000001.sdmp |
String found in binary or memory: https://api.ipify.org%$ |
Source: QUOTATION OF EQUIPMENT.exe, 00000001.00000002.566863487.0000000002331000.00000004.00000001.sdmp |
String found in binary or memory: https://api.ipify.org%GETMozilla/5.0 |
Source: QUOTATION OF EQUIPMENT.exe |
String found in binary or memory: https://www.theonionrouter.com/dist.torproject.org/torbrowser/9.5.3/tor-win32-0.4.3.6.zip |
Source: QUOTATION OF EQUIPMENT.exe, 00000001.00000002.566863487.0000000002331000.00000004.00000001.sdmp |
String found in binary or memory: https://www.theonionrouter.com/dist.torproject.org/torbrowser/9.5.3/tor-win32-0.4.3.6.zip%tordir%%ha |
Source: C:\Users\user\Desktop\QUOTATION OF EQUIPMENT.exe |
Code function: 0_2_00404FC2 GetDlgItem,GetDlgItem,GetDlgItem,GetDlgItem,GetClientRect,GetSystemMetrics,SendMessageA,SendMessageA,SendMessageA,SendMessageA,SendMessageA,SendMessageA,ShowWindow,ShowWindow,GetDlgItem,SendMessageA,SendMessageA,SendMessageA,GetDlgItem,CreateThread,CloseHandle,ShowWindow,ShowWindow,ShowWindow,ShowWindow,SendMessageA,CreatePopupMenu,AppendMenuA,GetWindowRect,TrackPopupMenu,SendMessageA,OpenClipboard,EmptyClipboard,GlobalAlloc,GlobalLock,SendMessageA,GlobalUnlock,SetClipboardData,CloseClipboard, |
0_2_00404FC2 |
Source: C:\Users\user\Desktop\QUOTATION OF EQUIPMENT.exe |
Code function: 0_2_004030FB EntryPoint,SetErrorMode,GetVersion,lstrlenA,#17,OleInitialize,SHGetFileInfoA,GetCommandLineA,GetModuleHandleA,CharNextA,GetTempPathA,GetWindowsDirectoryA,lstrcatA,DeleteFileA,OleUninitialize,ExitProcess,lstrcatA,lstrcatA,lstrcatA,lstrcmpiA,SetCurrentDirectoryA,DeleteFileA,CopyFileA,CloseHandle,GetCurrentProcess,ExitWindowsEx,ExitProcess, |
0_2_004030FB |
Source: C:\Users\user\Desktop\QUOTATION OF EQUIPMENT.exe |
Code function: 0_2_004047D3 |
0_2_004047D3 |
Source: C:\Users\user\Desktop\QUOTATION OF EQUIPMENT.exe |
Code function: 0_2_004061D4 |
0_2_004061D4 |
Source: C:\Users\user\Desktop\QUOTATION OF EQUIPMENT.exe |
Code function: 0_2_72E46A24 |
0_2_72E46A24 |
Source: C:\Users\user\Desktop\QUOTATION OF EQUIPMENT.exe |
Code function: 0_2_72E46A33 |
0_2_72E46A33 |
Source: C:\Users\user\Desktop\QUOTATION OF EQUIPMENT.exe |
Code function: 1_2_0040A2A5 |
1_2_0040A2A5 |
Source: C:\Users\user\Desktop\QUOTATION OF EQUIPMENT.exe |
Code function: 1_2_021846A0 |
1_2_021846A0 |
Source: C:\Users\user\Desktop\QUOTATION OF EQUIPMENT.exe |
Code function: 1_2_021845B0 |
1_2_021845B0 |
Source: C:\Users\user\Desktop\QUOTATION OF EQUIPMENT.exe |
Code function: 1_2_0218D310 |
1_2_0218D310 |
Source: C:\Users\user\Desktop\QUOTATION OF EQUIPMENT.exe |
Code function: 1_2_05929790 |
1_2_05929790 |
Source: C:\Users\user\Desktop\QUOTATION OF EQUIPMENT.exe |
Code function: 1_2_059246F8 |
1_2_059246F8 |
Source: C:\Users\user\Desktop\QUOTATION OF EQUIPMENT.exe |
Code function: 1_2_05925310 |
1_2_05925310 |
Source: C:\Users\user\Desktop\QUOTATION OF EQUIPMENT.exe |
Code function: 1_2_0592E260 |
1_2_0592E260 |
Source: C:\Users\user\Desktop\QUOTATION OF EQUIPMENT.exe |
Code function: 1_2_05924A40 |
1_2_05924A40 |
Source: C:\Users\user\Desktop\QUOTATION OF EQUIPMENT.exe |
Code function: 1_2_05EB0EA0 |
1_2_05EB0EA0 |
Source: C:\Users\user\Desktop\QUOTATION OF EQUIPMENT.exe |
Code function: 1_1_0040A2A5 |
1_1_0040A2A5 |
Source: QUOTATION OF EQUIPMENT.exe, 00000000.00000003.297338018.000000000F1E6000.00000004.00000001.sdmp |
Binary or memory string: OriginalFilenamentdll.dllj% vs QUOTATION OF EQUIPMENT.exe |
Source: QUOTATION OF EQUIPMENT.exe, 00000000.00000002.307528948.0000000002440000.00000004.00000001.sdmp |
Binary or memory string: OriginalFilenameeoQopvcgKxToaqzqUBTWKQEmbNlozHuMTqggKL.exe4 vs QUOTATION OF EQUIPMENT.exe |
Source: QUOTATION OF EQUIPMENT.exe |
Binary or memory string: OriginalFilename vs QUOTATION OF EQUIPMENT.exe |
Source: QUOTATION OF EQUIPMENT.exe, 00000001.00000002.567930918.0000000003331000.00000004.00000001.sdmp |
Binary or memory string: OriginalFilenameeoQopvcgKxToaqzqUBTWKQEmbNlozHuMTqggKL.exe4 vs QUOTATION OF EQUIPMENT.exe |
Source: QUOTATION OF EQUIPMENT.exe, 00000001.00000002.565195545.0000000000199000.00000004.00000001.sdmp |
Binary or memory string: OriginalFilenameUNKNOWN_FILET vs QUOTATION OF EQUIPMENT.exe |
Source: C:\Users\user\Desktop\QUOTATION OF EQUIPMENT.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\Desktop\QUOTATION OF EQUIPMENT.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\Desktop\QUOTATION OF EQUIPMENT.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\Desktop\QUOTATION OF EQUIPMENT.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\Desktop\QUOTATION OF EQUIPMENT.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\Desktop\QUOTATION OF EQUIPMENT.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\Desktop\QUOTATION OF EQUIPMENT.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\Desktop\QUOTATION OF EQUIPMENT.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\Desktop\QUOTATION OF EQUIPMENT.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\Desktop\QUOTATION OF EQUIPMENT.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\Desktop\QUOTATION OF EQUIPMENT.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\Desktop\QUOTATION OF EQUIPMENT.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\Desktop\QUOTATION OF EQUIPMENT.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\Desktop\QUOTATION OF EQUIPMENT.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\Desktop\QUOTATION OF EQUIPMENT.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\Desktop\QUOTATION OF EQUIPMENT.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\Desktop\QUOTATION OF EQUIPMENT.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\Desktop\QUOTATION OF EQUIPMENT.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\Desktop\QUOTATION OF EQUIPMENT.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\Desktop\QUOTATION OF EQUIPMENT.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\Desktop\QUOTATION OF EQUIPMENT.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\Desktop\QUOTATION OF EQUIPMENT.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\Desktop\QUOTATION OF EQUIPMENT.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\Desktop\QUOTATION OF EQUIPMENT.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\Desktop\QUOTATION OF EQUIPMENT.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\Desktop\QUOTATION OF EQUIPMENT.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\Desktop\QUOTATION OF EQUIPMENT.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\Desktop\QUOTATION OF EQUIPMENT.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\Desktop\QUOTATION OF EQUIPMENT.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\Desktop\QUOTATION OF EQUIPMENT.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\Desktop\QUOTATION OF EQUIPMENT.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\Desktop\QUOTATION OF EQUIPMENT.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\Desktop\QUOTATION OF EQUIPMENT.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\Desktop\QUOTATION OF EQUIPMENT.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\Desktop\QUOTATION OF EQUIPMENT.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\Desktop\QUOTATION OF EQUIPMENT.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\Desktop\QUOTATION OF EQUIPMENT.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\Desktop\QUOTATION OF EQUIPMENT.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\Desktop\QUOTATION OF EQUIPMENT.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\Desktop\QUOTATION OF EQUIPMENT.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\Desktop\QUOTATION OF EQUIPMENT.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\Desktop\QUOTATION OF EQUIPMENT.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\Desktop\QUOTATION OF EQUIPMENT.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\Desktop\QUOTATION OF EQUIPMENT.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\Desktop\QUOTATION OF EQUIPMENT.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\Desktop\QUOTATION OF EQUIPMENT.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\Desktop\QUOTATION OF EQUIPMENT.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\Desktop\QUOTATION OF EQUIPMENT.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\Desktop\QUOTATION OF EQUIPMENT.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\Desktop\QUOTATION OF EQUIPMENT.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\Desktop\QUOTATION OF EQUIPMENT.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\Desktop\QUOTATION OF EQUIPMENT.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\Desktop\QUOTATION OF EQUIPMENT.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\Desktop\QUOTATION OF EQUIPMENT.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\Desktop\QUOTATION OF EQUIPMENT.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\Desktop\QUOTATION OF EQUIPMENT.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\Desktop\QUOTATION OF EQUIPMENT.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\Desktop\QUOTATION OF EQUIPMENT.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\Desktop\QUOTATION OF EQUIPMENT.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\Desktop\QUOTATION OF EQUIPMENT.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\Desktop\QUOTATION OF EQUIPMENT.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\Desktop\QUOTATION OF EQUIPMENT.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\Desktop\QUOTATION OF EQUIPMENT.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\Desktop\QUOTATION OF EQUIPMENT.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\Desktop\QUOTATION OF EQUIPMENT.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\Desktop\QUOTATION OF EQUIPMENT.exe |
Code function: 0_2_00405E93 FindFirstFileA,FindClose, |
0_2_00405E93 |
Source: C:\Users\user\Desktop\QUOTATION OF EQUIPMENT.exe |
Code function: 0_2_004054BD DeleteFileA,lstrcatA,lstrcatA,lstrlenA,FindFirstFileA,DeleteFileA,FindNextFileA,FindClose,RemoveDirectoryA, |
0_2_004054BD |
Source: C:\Users\user\Desktop\QUOTATION OF EQUIPMENT.exe |
Code function: 0_2_00402671 FindFirstFileA, |
0_2_00402671 |
Source: C:\Users\user\Desktop\QUOTATION OF EQUIPMENT.exe |
Code function: 1_2_00404A29 FindFirstFileExW, |
1_2_00404A29 |
Source: C:\Users\user\Desktop\QUOTATION OF EQUIPMENT.exe |
Code function: 0_2_72E46402 mov eax, dword ptr fs:[00000030h] |
0_2_72E46402 |
Source: C:\Users\user\Desktop\QUOTATION OF EQUIPMENT.exe |
Code function: 0_2_72E466C7 mov eax, dword ptr fs:[00000030h] |
0_2_72E466C7 |
Source: C:\Users\user\Desktop\QUOTATION OF EQUIPMENT.exe |
Code function: 0_2_72E46744 mov eax, dword ptr fs:[00000030h] |
0_2_72E46744 |
Source: C:\Users\user\Desktop\QUOTATION OF EQUIPMENT.exe |
Code function: 0_2_72E46706 mov eax, dword ptr fs:[00000030h] |
0_2_72E46706 |
Source: C:\Users\user\Desktop\QUOTATION OF EQUIPMENT.exe |
Code function: 0_2_72E46616 mov eax, dword ptr fs:[00000030h] |
0_2_72E46616 |
Source: C:\Users\user\Desktop\QUOTATION OF EQUIPMENT.exe |
Code function: 1_2_004035F1 mov eax, dword ptr fs:[00000030h] |
1_2_004035F1 |
Source: C:\Users\user\Desktop\QUOTATION OF EQUIPMENT.exe |
Code function: 1_1_004035F1 mov eax, dword ptr fs:[00000030h] |
1_1_004035F1 |
Source: C:\Users\user\Desktop\QUOTATION OF EQUIPMENT.exe |
Code function: 1_2_00401E1D SetUnhandledExceptionFilter, |
1_2_00401E1D |
Source: C:\Users\user\Desktop\QUOTATION OF EQUIPMENT.exe |
Code function: 1_2_0040446F IsDebuggerPresent,SetUnhandledExceptionFilter,UnhandledExceptionFilter, |
1_2_0040446F |
Source: C:\Users\user\Desktop\QUOTATION OF EQUIPMENT.exe |
Code function: 1_2_00401C88 IsProcessorFeaturePresent,IsDebuggerPresent,SetUnhandledExceptionFilter,UnhandledExceptionFilter, |
1_2_00401C88 |
Source: C:\Users\user\Desktop\QUOTATION OF EQUIPMENT.exe |
Code function: 1_2_00401F30 SetUnhandledExceptionFilter,UnhandledExceptionFilter,GetCurrentProcess,TerminateProcess, |
1_2_00401F30 |
Source: C:\Users\user\Desktop\QUOTATION OF EQUIPMENT.exe |
Code function: 1_1_00401E1D SetUnhandledExceptionFilter, |
1_1_00401E1D |
Source: QUOTATION OF EQUIPMENT.exe, 00000001.00000002.566499923.0000000000D30000.00000002.00020000.sdmp |
Binary or memory string: Program Manager |
Source: QUOTATION OF EQUIPMENT.exe, 00000001.00000002.566499923.0000000000D30000.00000002.00020000.sdmp |
Binary or memory string: Shell_TrayWnd |
Source: QUOTATION OF EQUIPMENT.exe, 00000001.00000002.566499923.0000000000D30000.00000002.00020000.sdmp |
Binary or memory string: Progman |
Source: QUOTATION OF EQUIPMENT.exe, 00000001.00000002.566499923.0000000000D30000.00000002.00020000.sdmp |
Binary or memory string: Progmanlock |
Source: C:\Users\user\Desktop\QUOTATION OF EQUIPMENT.exe |
Queries volume information: C:\Windows\Microsoft.NET\assembly\GAC_MSIL\System.Windows.Forms\v4.0_4.0.0.0__b77a5c561934e089\System.Windows.Forms.dll VolumeInformation |
Jump to behavior |
Source: C:\Users\user\Desktop\QUOTATION OF EQUIPMENT.exe |
Queries volume information: C:\Windows\Microsoft.NET\assembly\GAC_MSIL\Microsoft.VisualBasic\v4.0_10.0.0.0__b03f5f7f11d50a3a\Microsoft.VisualBasic.dll VolumeInformation |
Jump to behavior |
Source: C:\Users\user\Desktop\QUOTATION OF EQUIPMENT.exe |
Queries volume information: C:\Windows\Microsoft.NET\assembly\GAC_32\CustomMarshalers\v4.0_4.0.0.0__b03f5f7f11d50a3a\CustomMarshalers.dll VolumeInformation |
Jump to behavior |
Source: C:\Users\user\Desktop\QUOTATION OF EQUIPMENT.exe |
Queries volume information: C:\Windows\Microsoft.NET\assembly\GAC_32\CustomMarshalers\v4.0_4.0.0.0__b03f5f7f11d50a3a\CustomMarshalers.dll VolumeInformation |
Jump to behavior |
Source: C:\Users\user\Desktop\QUOTATION OF EQUIPMENT.exe |
Queries volume information: C:\Windows\Microsoft.NET\assembly\GAC_32\CustomMarshalers\v4.0_4.0.0.0__b03f5f7f11d50a3a\CustomMarshalers.dll VolumeInformation |
Jump to behavior |
Source: C:\Users\user\Desktop\QUOTATION OF EQUIPMENT.exe |
Queries volume information: C:\Windows\Microsoft.NET\assembly\GAC_MSIL\System.Management\v4.0_4.0.0.0__b03f5f7f11d50a3a\System.Management.dll VolumeInformation |
Jump to behavior |
Source: C:\Users\user\Desktop\QUOTATION OF EQUIPMENT.exe |
Queries volume information: C:\Windows\Microsoft.NET\assembly\GAC_MSIL\System.Drawing\v4.0_4.0.0.0__b03f5f7f11d50a3a\System.Drawing.dll VolumeInformation |
Jump to behavior |
Source: C:\Users\user\Desktop\QUOTATION OF EQUIPMENT.exe |
Queries volume information: C:\Windows\Microsoft.NET\assembly\GAC_MSIL\Accessibility\v4.0_4.0.0.0__b03f5f7f11d50a3a\Accessibility.dll VolumeInformation |
Jump to behavior |
Source: C:\Users\user\Desktop\QUOTATION OF EQUIPMENT.exe |
Code function: 0_2_004030FB EntryPoint,SetErrorMode,GetVersion,lstrlenA,#17,OleInitialize,SHGetFileInfoA,GetCommandLineA,GetModuleHandleA,CharNextA,GetTempPathA,GetWindowsDirectoryA,lstrcatA,DeleteFileA,OleUninitialize,ExitProcess,lstrcatA,lstrcatA,lstrcatA,lstrcmpiA,SetCurrentDirectoryA,DeleteFileA,CopyFileA,CloseHandle,GetCurrentProcess,ExitWindowsEx,ExitProcess, |
0_2_004030FB |
Source: Yara match |
File source: 1.2.QUOTATION OF EQUIPMENT.exe.3335530.4.raw.unpack, type: UNPACKEDPE |
Source: Yara match |
File source: 1.2.QUOTATION OF EQUIPMENT.exe.415058.0.unpack, type: UNPACKEDPE |
Source: Yara match |
File source: 0.2.QUOTATION OF EQUIPMENT.exe.2451458.3.raw.unpack, type: UNPACKEDPE |
Source: Yara match |
File source: 0.2.QUOTATION OF EQUIPMENT.exe.2440000.2.raw.unpack, type: UNPACKEDPE |
Source: Yara match |
File source: 1.2.QUOTATION OF EQUIPMENT.exe.3335530.4.unpack, type: UNPACKEDPE |
Source: Yara match |
File source: 0.2.QUOTATION OF EQUIPMENT.exe.2440000.2.unpack, type: UNPACKEDPE |
Source: Yara match |
File source: 1.2.QUOTATION OF EQUIPMENT.exe.4810000.5.unpack, type: UNPACKEDPE |
Source: Yara match |
File source: 1.2.QUOTATION OF EQUIPMENT.exe.22e0000.3.raw.unpack, type: UNPACKEDPE |
Source: Yara match |
File source: 0.2.QUOTATION OF EQUIPMENT.exe.2451458.3.unpack, type: UNPACKEDPE |
Source: Yara match |
File source: 1.2.QUOTATION OF EQUIPMENT.exe.400000.1.unpack, type: UNPACKEDPE |
Source: Yara match |
File source: 1.2.QUOTATION OF EQUIPMENT.exe.22e0000.3.unpack, type: UNPACKEDPE |
Source: Yara match |
File source: 1.2.QUOTATION OF EQUIPMENT.exe.7a9f68.2.unpack, type: UNPACKEDPE |
Source: Yara match |
File source: 1.2.QUOTATION OF EQUIPMENT.exe.415058.0.raw.unpack, type: UNPACKEDPE |
Source: Yara match |
File source: 1.2.QUOTATION OF EQUIPMENT.exe.7a9f68.2.raw.unpack, type: UNPACKEDPE |
Source: Yara match |
File source: 1.2.QUOTATION OF EQUIPMENT.exe.400000.1.raw.unpack, type: UNPACKEDPE |
Source: Yara match |
File source: 00000001.00000002.567930918.0000000003331000.00000004.00000001.sdmp, type: MEMORY |
Source: Yara match |
File source: 00000000.00000002.307528948.0000000002440000.00000004.00000001.sdmp, type: MEMORY |
Source: Yara match |
File source: 00000001.00000002.566777680.00000000022E0000.00000004.00020000.sdmp, type: MEMORY |
Source: Yara match |
File source: 00000001.00000002.568210008.0000000004812000.00000040.00000001.sdmp, type: MEMORY |
Source: Yara match |
File source: 00000001.00000002.566108651.000000000078B000.00000004.00000020.sdmp, type: MEMORY |
Source: Yara match |
File source: 00000001.00000002.565262027.0000000000400000.00000040.00000001.sdmp, type: MEMORY |
Source: Yara match |
File source: 00000001.00000002.566863487.0000000002331000.00000004.00000001.sdmp, type: MEMORY |
Source: Yara match |
File source: Process Memory Space: QUOTATION OF EQUIPMENT.exe PID: 6748, type: MEMORYSTR |
Source: Yara match |
File source: Process Memory Space: QUOTATION OF EQUIPMENT.exe PID: 6716, type: MEMORYSTR |
Source: Yara match |
File source: 1.2.QUOTATION OF EQUIPMENT.exe.3335530.4.raw.unpack, type: UNPACKEDPE |
Source: Yara match |
File source: 1.2.QUOTATION OF EQUIPMENT.exe.415058.0.unpack, type: UNPACKEDPE |
Source: Yara match |
File source: 0.2.QUOTATION OF EQUIPMENT.exe.2451458.3.raw.unpack, type: UNPACKEDPE |
Source: Yara match |
File source: 0.2.QUOTATION OF EQUIPMENT.exe.2440000.2.raw.unpack, type: UNPACKEDPE |
Source: Yara match |
File source: 1.2.QUOTATION OF EQUIPMENT.exe.3335530.4.unpack, type: UNPACKEDPE |
Source: Yara match |
File source: 0.2.QUOTATION OF EQUIPMENT.exe.2440000.2.unpack, type: UNPACKEDPE |
Source: Yara match |
File source: 1.2.QUOTATION OF EQUIPMENT.exe.4810000.5.unpack, type: UNPACKEDPE |
Source: Yara match |
File source: 1.2.QUOTATION OF EQUIPMENT.exe.22e0000.3.raw.unpack, type: UNPACKEDPE |
Source: Yara match |
File source: 0.2.QUOTATION OF EQUIPMENT.exe.2451458.3.unpack, type: UNPACKEDPE |
Source: Yara match |
File source: 1.2.QUOTATION OF EQUIPMENT.exe.400000.1.unpack, type: UNPACKEDPE |
Source: Yara match |
File source: 1.2.QUOTATION OF EQUIPMENT.exe.22e0000.3.unpack, type: UNPACKEDPE |
Source: Yara match |
File source: 1.2.QUOTATION OF EQUIPMENT.exe.7a9f68.2.unpack, type: UNPACKEDPE |
Source: Yara match |
File source: 1.2.QUOTATION OF EQUIPMENT.exe.415058.0.raw.unpack, type: UNPACKEDPE |
Source: Yara match |
File source: 1.2.QUOTATION OF EQUIPMENT.exe.7a9f68.2.raw.unpack, type: UNPACKEDPE |
Source: Yara match |
File source: 1.2.QUOTATION OF EQUIPMENT.exe.400000.1.raw.unpack, type: UNPACKEDPE |
Source: Yara match |
File source: 00000001.00000002.567930918.0000000003331000.00000004.00000001.sdmp, type: MEMORY |
Source: Yara match |
File source: 00000000.00000002.307528948.0000000002440000.00000004.00000001.sdmp, type: MEMORY |
Source: Yara match |
File source: 00000001.00000002.566777680.00000000022E0000.00000004.00020000.sdmp, type: MEMORY |
Source: Yara match |
File source: 00000001.00000002.568210008.0000000004812000.00000040.00000001.sdmp, type: MEMORY |
Source: Yara match |
File source: 00000001.00000002.566108651.000000000078B000.00000004.00000020.sdmp, type: MEMORY |
Source: Yara match |
File source: 00000001.00000002.565262027.0000000000400000.00000040.00000001.sdmp, type: MEMORY |
Source: Yara match |
File source: 00000001.00000002.566863487.0000000002331000.00000004.00000001.sdmp, type: MEMORY |
Source: Yara match |
File source: Process Memory Space: QUOTATION OF EQUIPMENT.exe PID: 6748, type: MEMORYSTR |
Source: Yara match |
File source: Process Memory Space: QUOTATION OF EQUIPMENT.exe PID: 6716, type: MEMORYSTR |