Score: | 69 |
Range: | 0 - 100 |
Whitelisted: | false |
Confidence: | 100% |
Score: | 18 |
Range: | 0 - 100 |
AV Detection: |
---|
Found malware configuration |
Source: |
Malware Configuration Extractor: |
Multi AV Scanner detection for submitted file |
Source: |
ReversingLabs: |
Antivirus or Machine Learning detection for unpacked file |
Source: |
Avira: |
Privilege Escalation: |
---|
EXE planting / hijacking vulnerabilities found |
Source: |
EXE: |
Jump to behavior | ||
Source: |
EXE: |
Jump to behavior |
DLL planting / hijacking vulnerabilities found |
Source: |
DLL: |
Jump to behavior | ||
Source: |
DLL: |
Jump to behavior | ||
Source: |
DLL: |
Jump to behavior | ||
Source: |
DLL: |
Jump to behavior | ||
Source: |
DLL: |
Jump to behavior | ||
Source: |
DLL: |
Jump to behavior | ||
Source: |
DLL: |
Jump to behavior | ||
Source: |
DLL: |
Jump to behavior | ||
Source: |
DLL: |
Jump to behavior | ||
Source: |
DLL: |
Jump to behavior | ||
Source: |
DLL: |
Jump to behavior | ||
Source: |
DLL: |
Jump to behavior | ||
Source: |
DLL: |
Jump to behavior | ||
Source: |
DLL: |
Jump to behavior | ||
Source: |
DLL: |
Jump to behavior | ||
Source: |
DLL: |
Jump to behavior | ||
Source: |
DLL: |
Jump to behavior | ||
Source: |
DLL: |
Jump to behavior | ||
Source: |
DLL: |
Jump to behavior | ||
Source: |
DLL: |
Jump to behavior | ||
Source: |
DLL: |
Jump to behavior | ||
Source: |
DLL: |
Jump to behavior | ||
Source: |
DLL: |
Jump to behavior | ||
Source: |
DLL: |
Jump to behavior | ||
Source: |
DLL: |
Jump to behavior | ||
Source: |
DLL: |
Jump to behavior | ||
Source: |
DLL: |
Jump to behavior | ||
Source: |
DLL: |
Jump to behavior | ||
Source: |
DLL: |
Jump to behavior |
Compliance: |
---|
Uses 32bit PE files |
Source: |
Static PE information: |
EXE planting / hijacking vulnerabilities found |
Source: |
EXE: |
Jump to behavior | ||
Source: |
EXE: |
Jump to behavior |
DLL planting / hijacking vulnerabilities found |
Source: |
DLL: |
Jump to behavior | ||
Source: |
DLL: |
Jump to behavior | ||
Source: |
DLL: |
Jump to behavior | ||
Source: |
DLL: |
Jump to behavior | ||
Source: |
DLL: |
Jump to behavior | ||
Source: |
DLL: |
Jump to behavior | ||
Source: |
DLL: |
Jump to behavior | ||
Source: |
DLL: |
Jump to behavior | ||
Source: |
DLL: |
Jump to behavior | ||
Source: |
DLL: |
Jump to behavior | ||
Source: |
DLL: |
Jump to behavior | ||
Source: |
DLL: |
Jump to behavior | ||
Source: |
DLL: |
Jump to behavior | ||
Source: |
DLL: |
Jump to behavior | ||
Source: |
DLL: |
Jump to behavior | ||
Source: |
DLL: |
Jump to behavior | ||
Source: |
DLL: |
Jump to behavior | ||
Source: |
DLL: |
Jump to behavior | ||
Source: |
DLL: |
Jump to behavior | ||
Source: |
DLL: |
Jump to behavior | ||
Source: |
DLL: |
Jump to behavior | ||
Source: |
DLL: |
Jump to behavior | ||
Source: |
DLL: |
Jump to behavior | ||
Source: |
DLL: |
Jump to behavior | ||
Source: |
DLL: |
Jump to behavior | ||
Source: |
DLL: |
Jump to behavior | ||
Source: |
DLL: |
Jump to behavior | ||
Source: |
DLL: |
Jump to behavior | ||
Source: |
DLL: |
Jump to behavior |
Creates license or readme file |
Source: |
File created: |
Jump to behavior | ||
Source: |
File created: |
Jump to behavior | ||
Source: |
File created: |
Jump to behavior | ||
Source: |
File created: |
Jump to behavior |
PE / OLE file has a valid certificate |
Source: |
Static PE information: |
Contains modern PE file flags such as dynamic base (ASLR) or NX |
Source: |
Static PE information: |
Binary contains paths to debug symbols |
Source: |
Binary string: |
||
Source: |
Binary string: |
||
Source: |
Binary string: |
||
Source: |
Binary string: |
||
Source: |
Binary string: |
||
Source: |
Binary string: |
||
Source: |
Binary string: |
||
Source: |
Binary string: |
||
Source: |
Binary string: |
||
Source: |
Binary string: |
||
Source: |
Binary string: |
||
Source: |
Binary string: |
||
Source: |
Binary string: |
||
Source: |
Binary string: |
||
Source: |
Binary string: |
||
Source: |
Binary string: |
||
Source: |
Binary string: |
||
Source: |
Binary string: |
||
Source: |
Binary string: |
||
Source: |
Binary string: |
||
Source: |
Binary string: |
||
Source: |
Binary string: |
||
Source: |
Binary string: |
||
Source: |
Binary string: |
||
Source: |
Binary string: |
||
Source: |
Binary string: |
Spreading: |
---|
Checks for available system drives (often done to infect USB drives) |
Source: |
File opened: |
Jump to behavior | ||
Source: |
File opened: |
Jump to behavior | ||
Source: |
File opened: |
Jump to behavior | ||
Source: |
File opened: |
Jump to behavior | ||
Source: |
File opened: |
Jump to behavior | ||
Source: |
File opened: |
Jump to behavior | ||
Source: |
File opened: |
Jump to behavior | ||
Source: |
File opened: |
Jump to behavior | ||
Source: |
File opened: |
Jump to behavior | ||
Source: |
File opened: |
Jump to behavior | ||
Source: |
File opened: |
Jump to behavior | ||
Source: |
File opened: |
Jump to behavior | ||
Source: |
File opened: |
Jump to behavior | ||
Source: |
File opened: |
Jump to behavior | ||
Source: |
File opened: |
Jump to behavior | ||
Source: |
File opened: |
Jump to behavior | ||
Source: |
File opened: |
Jump to behavior | ||
Source: |
File opened: |
Jump to behavior | ||
Source: |
File opened: |
Jump to behavior | ||
Source: |
File opened: |
Jump to behavior | ||
Source: |
File opened: |
Jump to behavior | ||
Source: |
File opened: |
Jump to behavior | ||
Source: |
File opened: |
Jump to behavior | ||
Source: |
File opened: |
Jump to behavior | ||
Source: |
File opened: |
Jump to behavior |
Source: |
Code function: |
1_2_01342910 | |
Source: |
Code function: |
1_2_01345B80 | |
Source: |
Code function: |
1_2_01346A30 | |
Source: |
Code function: |
1_2_013294D0 | |
Source: |
Code function: |
1_2_012A8740 | |
Source: |
Code function: |
1_2_013529C0 | |
Source: |
Code function: |
1_2_013640F0 | |
Source: |
Code function: |
1_2_01328B70 |
Networking: |
---|
Tries to resolve domain names, but no domain seems valid (expired dropper behavior) |
Source: |
DNS traffic detected: |
Source: |
String found in binary or memory: |
||
Source: |
String found in binary or memory: |
Source: |
String found in binary or memory: |
||
Source: |
String found in binary or memory: |
||
Source: |
String found in binary or memory: |
||
Source: |
String found in binary or memory: |
||
Source: |
String found in binary or memory: |
||
Source: |
String found in binary or memory: |
||
Source: |
String found in binary or memory: |
||
Source: |
String found in binary or memory: |
||
Source: |
String found in binary or memory: |
||
Source: |
String found in binary or memory: |
||
Source: |
String found in binary or memory: |
||
Source: |
String found in binary or memory: |
||
Source: |
String found in binary or memory: |
||
Source: |
String found in binary or memory: |
||
Source: |
String found in binary or memory: |
||
Source: |
String found in binary or memory: |
||
Source: |
String found in binary or memory: |
||
Source: |
String found in binary or memory: |
||
Source: |
String found in binary or memory: |
||
Source: |
String found in binary or memory: |
||
Source: |
String found in binary or memory: |
||
Source: |
String found in binary or memory: |
||
Source: |
String found in binary or memory: |
||
Source: |
String found in binary or memory: |
||
Source: |
String found in binary or memory: |
||
Source: |
String found in binary or memory: |
||
Source: |
String found in binary or memory: |
||
Source: |
String found in binary or memory: |
||
Source: |
String found in binary or memory: |
||
Source: |
String found in binary or memory: |
||
Source: |
String found in binary or memory: |
||
Source: |
String found in binary or memory: |
||
Source: |
String found in binary or memory: |
||
Source: |
String found in binary or memory: |
||
Source: |
String found in binary or memory: |
||
Source: |
String found in binary or memory: |
||
Source: |
String found in binary or memory: |
||
Source: |
String found in binary or memory: |
||
Source: |
String found in binary or memory: |
||
Source: |
String found in binary or memory: |
||
Source: |
String found in binary or memory: |
||
Source: |
String found in binary or memory: |
||
Source: |
String found in binary or memory: |
||
Source: |
String found in binary or memory: |
||
Source: |
String found in binary or memory: |
||
Source: |
String found in binary or memory: |
||
Source: |
String found in binary or memory: |
||
Source: |
String found in binary or memory: |
||
Source: |
String found in binary or memory: |
||
Source: |
String found in binary or memory: |
||
Source: |
String found in binary or memory: |
||
Source: |
String found in binary or memory: |
||
Source: |
String found in binary or memory: |
||
Source: |
String found in binary or memory: |
||
Source: |
String found in binary or memory: |
||
Source: |
String found in binary or memory: |
||
Source: |
String found in binary or memory: |
||
Source: |
String found in binary or memory: |
||
Source: |
String found in binary or memory: |
||
Source: |
String found in binary or memory: |
||
Source: |
String found in binary or memory: |
||
Source: |
String found in binary or memory: |
||
Source: |
String found in binary or memory: |
||
Source: |
String found in binary or memory: |
||
Source: |
String found in binary or memory: |
||
Source: |
String found in binary or memory: |
||
Source: |
String found in binary or memory: |
||
Source: |
String found in binary or memory: |
||
Source: |
String found in binary or memory: |
||
Source: |
String found in binary or memory: |
||
Source: |
String found in binary or memory: |
||
Source: |
String found in binary or memory: |
||
Source: |
String found in binary or memory: |
||
Source: |
String found in binary or memory: |
Source: |
DNS traffic detected: |
Source: |
Code function: |
9_2_00A903A0 |
Key, Mouse, Clipboard, Microphone and Screen Capturing: |
---|
Yara detected Ursnif |
Source: |
File source: |
||
Source: |
File source: |
||
Source: |
File source: |
||
Source: |
File source: |
||
Source: |
File source: |
||
Source: |
File source: |
||
Source: |
File source: |
||
Source: |
File source: |
||
Source: |
File source: |
||
Source: |
File source: |
||
Source: |
File source: |
||
Source: |
File source: |
||
Source: |
File source: |
||
Source: |
File source: |
E-Banking Fraud: |
---|
Yara detected Ursnif |
Source: |
File source: |
||
Source: |
File source: |
||
Source: |
File source: |
||
Source: |
File source: |
||
Source: |
File source: |
||
Source: |
File source: |
||
Source: |
File source: |
||
Source: |
File source: |
||
Source: |
File source: |
||
Source: |
File source: |
||
Source: |
File source: |
||
Source: |
File source: |
||
Source: |
File source: |
||
Source: |
File source: |
System Summary: |
---|
PE file has a writeable .text section |
Source: |
Static PE information: |
||
Source: |
Static PE information: |
Writes or reads registry keys via WMI |
Source: |
WMI Queries: |
||
Source: |
WMI Queries: |
||
Source: |
WMI Queries: |
||
Source: |
WMI Queries: |
||
Source: |
WMI Queries: |
Writes registry values via WMI |
Source: |
WMI Registry write: |
||
Source: |
WMI Registry write: |
||
Source: |
WMI Registry write: |
Uses 32bit PE files |
Source: |
Static PE information: |
Deletes files inside the Windows folder |
Source: |
File deleted: |
Jump to behavior |
Creates files inside the system directory |
Source: |
File created: |
Jump to behavior |
Detected potential crypto function |
Source: |
Code function: |
1_2_01342910 | |
Source: |
Code function: |
1_2_012A8740 | |
Source: |
Code function: |
1_2_013446B0 | |
Source: |
Code function: |
1_2_01292080 | |
Source: |
Code function: |
1_2_012AC080 | |
Source: |
Code function: |
1_2_013038F0 | |
Source: |
Code function: |
1_2_013D7354 | |
Source: |
Code function: |
1_2_013C2241 | |
Source: |
Code function: |
1_2_012A6AC0 | |
Source: |
Code function: |
1_2_012BF560 | |
Source: |
Code function: |
1_2_013D8F4E | |
Source: |
Code function: |
1_2_013D8E2E | |
Source: |
Code function: |
9_2_00AB0130 | |
Source: |
Code function: |
9_2_00ACB960 | |
Source: |
Code function: |
9_2_00AA6AF0 | |
Source: |
Code function: |
9_2_00C43483 | |
Source: |
Code function: |
9_2_00C344AF | |
Source: |
Code function: |
9_2_00C274B9 | |
Source: |
Code function: |
9_2_00C3FC19 | |
Source: |
Code function: |
9_2_00C435A3 | |
Source: |
Code function: |
9_2_00AA75D0 | |
Source: |
Code function: |
9_2_00AD5D70 | |
Source: |
Code function: |
9_2_00AAAF30 |
Found potential string decryption / allocating functions |
Source: |
Code function: |
Contains functionality to call native functions |
Source: |
Code function: |
1_2_0129D890 | |
Source: |
Code function: |
1_2_012A0320 | |
Source: |
Code function: |
1_2_0129D260 | |
Source: |
Code function: |
1_2_012AA2E0 | |
Source: |
Code function: |
1_2_0129FD60 | |
Source: |
Code function: |
1_2_0129CCB0 | |
Source: |
Code function: |
1_2_012C7CF0 | |
Source: |
Code function: |
1_2_012A6760 | |
Source: |
Code function: |
1_2_0129F740 | |
Source: |
Code function: |
9_2_00A719A0 | |
Source: |
Code function: |
9_2_00A71703 | |
Source: |
Code function: |
9_2_00A71C90 |
Sample file is different than original file name gathered from version info |
Source: |
Binary or memory string: |
||
Source: |
Binary or memory string: |
||
Source: |
Binary or memory string: |
||
Source: |
Binary or memory string: |
||
Source: |
Binary or memory string: |
||
Source: |
Binary or memory string: |
||
Source: |
Binary or memory string: |
||
Source: |
Binary or memory string: |
||
Source: |
Binary or memory string: |
||
Source: |
Binary or memory string: |
||
Source: |
Binary or memory string: |
||
Source: |
Binary or memory string: |
||
Source: |
Binary or memory string: |
||
Source: |
Binary or memory string: |
||
Source: |
Binary or memory string: |
||
Source: |
Binary or memory string: |
||
Source: |
Binary or memory string: |
||
Source: |
Binary or memory string: |
||
Source: |
Binary or memory string: |
PE file contains strange resources |
Source: |
Static PE information: |
||
Source: |
Static PE information: |
||
Source: |
Static PE information: |
Tries to load missing DLLs |
Source: |
Section loaded: |
Jump to behavior | ||
Source: |
Section loaded: |
Jump to behavior | ||
Source: |
Section loaded: |
Jump to behavior | ||
Source: |
Section loaded: |
Jump to behavior | ||
Source: |
Section loaded: |
Jump to behavior | ||
Source: |
Section loaded: |
Jump to behavior | ||
Source: |
Section loaded: |
Jump to behavior | ||
Source: |
Section loaded: |
Jump to behavior | ||
Source: |
Section loaded: |
Jump to behavior |
Source: |
Static PE information: |
||
Source: |
Static PE information: |
Source: |
ReversingLabs: |
Source: |
File read: |
Jump to behavior |
Source: |
Static PE information: |
Source: |
Key opened: |
Jump to behavior |
Source: |
Process created: |
|||
Source: |
Process created: |
|||
Source: |
Process created: |
|||
Source: |
Process created: |
|||
Source: |
Process created: |
|||
Source: |
Process created: |
|||
Source: |
Process created: |
Jump to behavior | ||
Source: |
Process created: |
Jump to behavior | ||
Source: |
Process created: |
Jump to behavior | ||
Source: |
Process created: |
Jump to behavior |
Source: |
Key value queried: |
Jump to behavior |
Source: |
File created: |
Jump to behavior |
Source: |
File created: |
Jump to behavior |
Source: |
Classification label: |
Source: |
File read: |
Jump to behavior |
Source: |
Code function: |
1_2_01350E70 |
Source: |
Task registration methods: |
||
Source: |
Task registration methods: |
||
Source: |
Task registration methods: |
Source: |
Joe Sandbox Cloud Basic: |
Perma Link |
Source: |
Code function: |
1_2_01297B80 |
Source: |
Binary or memory string: |
Source: |
Cryptographic APIs: |
||
Source: |
Cryptographic APIs: |
||
Source: |
Cryptographic APIs: |
||
Source: |
Cryptographic APIs: |
Source: |
File read: |
Jump to behavior | ||
Source: |
File read: |
Jump to behavior | ||
Source: |
File read: |
Jump to behavior |
Source: |
Static PE information: |
Source: |
Static file information: |
Source: |
Static PE information: |
Source: |
Static PE information: |
Source: |
Static PE information: |
||
Source: |
Static PE information: |
||
Source: |
Static PE information: |
||
Source: |
Static PE information: |
||
Source: |
Static PE information: |
||
Source: |
Static PE information: |
Source: |
Static PE information: |
Source: |
Static PE information: |
Source: |
Binary string: |
||
Source: |
Binary string: |
||
Source: |
Binary string: |
||
Source: |
Binary string: |
||
Source: |
Binary string: |
||
Source: |
Binary string: |
||
Source: |
Binary string: |
||
Source: |
Binary string: |
||
Source: |
Binary string: |
||
Source: |
Binary string: |
||
Source: |
Binary string: |
||
Source: |
Binary string: |
||
Source: |
Binary string: |
||
Source: |
Binary string: |
||
Source: |
Binary string: |
||
Source: |
Binary string: |
||
Source: |
Binary string: |
||
Source: |
Binary string: |
||
Source: |
Binary string: |
||
Source: |
Binary string: |
||
Source: |
Binary string: |
||
Source: |
Binary string: |
||
Source: |
Binary string: |
||
Source: |
Binary string: |
||
Source: |
Binary string: |
||
Source: |
Binary string: |
Source: |
Static PE information: |
||
Source: |
Static PE information: |
||
Source: |
Static PE information: |
||
Source: |
Static PE information: |
||
Source: |
Static PE information: |
Data Obfuscation: |
---|
Detected unpacking (changes PE section rights) |
Source: |
Unpacked PE file: |
Uses code obfuscation techniques (call, push, ret) |
Source: |
Code function: |
1_2_013BC4BF | |
Source: |
Code function: |
1_2_012A3CB1 | |
Source: |
Code function: |
9_2_00C55744 |
PE file contains sections with non-standard names |
Source: |
Static PE information: |
||
Source: |
Static PE information: |
Contains functionality to dynamically determine API calls |
Source: |
Code function: |
1_2_01363D80 |
PE file contains an invalid checksum |
Source: |
Static PE information: |
||
Source: |
Static PE information: |
||
Source: |
Static PE information: |
Binary contains a suspicious time stamp |
Source: |
Static PE information: |
Source: |
Static PE information: |
||
Source: |
Static PE information: |
Persistence and Installation Behavior: |
---|
Drops files with a non-matching file extension (content does not match file extension) |
Source: |
File created: |
Jump to dropped file | ||
Source: |
File created: |
Jump to dropped file |
Drops PE files |
Source: |
File created: |
Jump to dropped file | ||
Source: |
File created: |
Jump to dropped file | ||
Source: |
File created: |
Jump to dropped file | ||
Source: |
File created: |
Jump to dropped file | ||
Source: |
File created: |
Jump to dropped file | ||
Source: |
File created: |
Jump to dropped file | ||
Source: |
File created: |
Jump to dropped file | ||
Source: |
File created: |
Jump to dropped file | ||
Source: |
File created: |
Jump to dropped file | ||
Source: |
File created: |
Jump to dropped file | ||
Source: |
File created: |
Jump to dropped file | ||
Source: |
File created: |
Jump to dropped file | ||
Source: |
File created: |
Jump to dropped file | ||
Source: |
File created: |
Jump to dropped file | ||
Source: |
File created: |
Jump to dropped file | ||
Source: |
File created: |
Jump to dropped file | ||
Source: |
File created: |
Jump to dropped file | ||
Source: |
File created: |
Jump to dropped file | ||
Source: |
File created: |
Jump to dropped file | ||
Source: |
File created: |
Jump to dropped file | ||
Source: |
File created: |
Jump to dropped file | ||
Source: |
File created: |
Jump to dropped file | ||
Source: |
File created: |
Jump to dropped file | ||
Source: |
File created: |
Jump to dropped file | ||
Source: |
File created: |
Jump to dropped file | ||
Source: |
File created: |
Jump to dropped file | ||
Source: |
File created: |
Jump to dropped file | ||
Source: |
File created: |
Jump to dropped file | ||
Source: |
File created: |
Jump to dropped file | ||
Source: |
File created: |
Jump to dropped file | ||
Source: |
File created: |
Jump to dropped file | ||
Source: |
File created: |
Jump to dropped file |
Drops PE files to the windows directory (C:\Windows) |
Source: |
File created: |
Jump to dropped file | ||
Source: |
File created: |
Jump to dropped file | ||
Source: |
File created: |
Jump to dropped file | ||
Source: |
File created: |
Jump to dropped file | ||
Source: |
File created: |
Jump to dropped file | ||
Source: |
File created: |
Jump to dropped file |
Source: |
File created: |
Jump to behavior | ||
Source: |
File created: |
Jump to behavior | ||
Source: |
File created: |
Jump to behavior | ||
Source: |
File created: |
Jump to behavior |
Hooking and other Techniques for Hiding and Protection: |
---|
Yara detected Ursnif |
Source: |
File source: |
||
Source: |
File source: |
||
Source: |
File source: |
||
Source: |
File source: |
||
Source: |
File source: |
||
Source: |
File source: |
||
Source: |
File source: |
||
Source: |
File source: |
||
Source: |
File source: |
||
Source: |
File source: |
||
Source: |
File source: |
||
Source: |
File source: |
||
Source: |
File source: |
||
Source: |
File source: |
Monitors certain registry keys / values for changes (often done to protect autostart functionality) |
Source: |
Registry key monitored for changes: |
Jump to behavior |
Source: |
Process information set: |
Jump to behavior | ||
Source: |
Process information set: |
Jump to behavior | ||
Source: |
Process information set: |
Jump to behavior | ||
Source: |
Process information set: |
Jump to behavior | ||
Source: |
Process information set: |
Jump to behavior | ||
Source: |
Process information set: |
Jump to behavior | ||
Source: |
Process information set: |
Jump to behavior | ||
Source: |
Process information set: |
Jump to behavior | ||
Source: |
Process information set: |
Jump to behavior | ||
Source: |
Process information set: |
Jump to behavior | ||
Source: |
Process information set: |
Jump to behavior | ||
Source: |
Process information set: |
Jump to behavior | ||
Source: |
Process information set: |
Jump to behavior | ||
Source: |
Process information set: |
Jump to behavior | ||
Source: |
Process information set: |
Jump to behavior | ||
Source: |
Process information set: |
Jump to behavior | ||
Source: |
Process information set: |
Jump to behavior | ||
Source: |
Process information set: |
Jump to behavior | ||
Source: |
Process information set: |
Jump to behavior | ||
Source: |
Process information set: |
Jump to behavior | ||
Source: |
Process information set: |
Jump to behavior | ||
Source: |
Process information set: |
Jump to behavior | ||
Source: |
Process information set: |
Jump to behavior | ||
Source: |
Process information set: |
Jump to behavior | ||
Source: |
Process information set: |
Jump to behavior | ||
Source: |
Process information set: |
Jump to behavior | ||
Source: |
Process information set: |
Jump to behavior | ||
Source: |
Process information set: |
Jump to behavior | ||
Source: |
Process information set: |
Jump to behavior | ||
Source: |
Process information set: |
Jump to behavior | ||
Source: |
Process information set: |
Jump to behavior | ||
Source: |
Process information set: |
Jump to behavior | ||
Source: |
Process information set: |
Jump to behavior | ||
Source: |
Process information set: |
Jump to behavior | ||
Source: |
Process information set: |
Jump to behavior | ||
Source: |
Process information set: |
Jump to behavior | ||
Source: |
Process information set: |
Jump to behavior |
Malware Analysis System Evasion: |
---|
May sleep (evasive loops) to hinder dynamic analysis |
Source: |
Thread sleep time: |
Jump to behavior | ||
Source: |
Thread sleep time: |
Jump to behavior | ||
Source: |
Thread sleep time: |
Jump to behavior | ||
Source: |
Thread sleep count: |
Jump to behavior | ||
Source: |
Thread sleep count: |
Jump to behavior | ||
Source: |
Thread sleep count: |
Jump to behavior |
Found dropped PE file which has not been started or loaded |
Source: |
Dropped PE file which has not been started: |
Jump to dropped file | ||
Source: |
Dropped PE file which has not been started: |
Jump to dropped file | ||
Source: |
Dropped PE file which has not been started: |
Jump to dropped file | ||
Source: |
Dropped PE file which has not been started: |
Jump to dropped file | ||
Source: |
Dropped PE file which has not been started: |
Jump to dropped file | ||
Source: |
Dropped PE file which has not been started: |
Jump to dropped file | ||
Source: |
Dropped PE file which has not been started: |
Jump to dropped file | ||
Source: |
Dropped PE file which has not been started: |
Jump to dropped file | ||
Source: |
Dropped PE file which has not been started: |
Jump to dropped file | ||
Source: |
Dropped PE file which has not been started: |
Jump to dropped file | ||
Source: |
Dropped PE file which has not been started: |
Jump to dropped file | ||
Source: |
Dropped PE file which has not been started: |
Jump to dropped file | ||
Source: |
Dropped PE file which has not been started: |
Jump to dropped file | ||
Source: |
Dropped PE file which has not been started: |
Jump to dropped file | ||
Source: |
Dropped PE file which has not been started: |
Jump to dropped file | ||
Source: |
Dropped PE file which has not been started: |
Jump to dropped file | ||
Source: |
Dropped PE file which has not been started: |
Jump to dropped file | ||
Source: |
Dropped PE file which has not been started: |
Jump to dropped file | ||
Source: |
Dropped PE file which has not been started: |
Jump to dropped file | ||
Source: |
Dropped PE file which has not been started: |
Jump to dropped file | ||
Source: |
Dropped PE file which has not been started: |
Jump to dropped file | ||
Source: |
Dropped PE file which has not been started: |
Jump to dropped file |
Contains long sleeps (>= 3 min) |
Source: |
Thread delayed: |
Jump to behavior |
Source: |
Process information queried: |
Jump to behavior |
Source: |
Code function: |
1_2_01342910 | |
Source: |
Code function: |
1_2_01345B80 | |
Source: |
Code function: |
1_2_01346A30 | |
Source: |
Code function: |
1_2_013294D0 | |
Source: |
Code function: |
1_2_012A8740 | |
Source: |
Code function: |
1_2_013529C0 | |
Source: |
Code function: |
1_2_013640F0 | |
Source: |
Code function: |
1_2_01328B70 |
Source: |
Thread delayed: |
Jump to behavior | ||
Source: |
Thread delayed: |
Jump to behavior |
Source: |
File Volume queried: |
Jump to behavior | ||
Source: |
File Volume queried: |
Jump to behavior | ||
Source: |
File Volume queried: |
Jump to behavior | ||
Source: |
File Volume queried: |
Jump to behavior | ||
Source: |
File Volume queried: |
Jump to behavior | ||
Source: |
File Volume queried: |
Jump to behavior | ||
Source: |
File Volume queried: |
Jump to behavior | ||
Source: |
File Volume queried: |
Jump to behavior | ||
Source: |
File Volume queried: |
Jump to behavior | ||
Source: |
File Volume queried: |
Jump to behavior | ||
Source: |
File Volume queried: |
Jump to behavior | ||
Source: |
File Volume queried: |
Jump to behavior | ||
Source: |
File Volume queried: |
Jump to behavior | ||
Source: |
File Volume queried: |
Jump to behavior | ||
Source: |
File Volume queried: |
Jump to behavior | ||
Source: |
File Volume queried: |
Jump to behavior | ||
Source: |
File Volume queried: |
Jump to behavior | ||
Source: |
File Volume queried: |
Jump to behavior | ||
Source: |
File Volume queried: |
Jump to behavior | ||
Source: |
File Volume queried: |
Jump to behavior | ||
Source: |
File Volume queried: |
Jump to behavior | ||
Source: |
File Volume queried: |
Jump to behavior | ||
Source: |
File Volume queried: |
Jump to behavior | ||
Source: |
File Volume queried: |
Jump to behavior | ||
Source: |
File Volume queried: |
Jump to behavior | ||
Source: |
File Volume queried: |
Jump to behavior | ||
Source: |
File Volume queried: |
Jump to behavior | ||
Source: |
File Volume queried: |
Jump to behavior | ||
Source: |
File Volume queried: |
Jump to behavior |
Source: |
Binary or memory string: |
||
Source: |
Binary or memory string: |
Anti Debugging: |
---|
Contains functionality to check if a debugger is running (IsDebuggerPresent) |
Source: |
Code function: |
1_2_013C03A3 |
Contains functionality to check if a debugger is running (OutputDebugString,GetLastError) |
Source: |
Code function: |
1_2_0135BAD0 |
Contains functionality to dynamically determine API calls |
Source: |
Code function: |
1_2_01363D80 |
Contains functionality which may be used to detect a debugger (GetProcessHeap) |
Source: |
Code function: |
1_2_013B959D |
Contains functionality to read the PEB |
Source: |
Code function: |
1_2_013CB05F | |
Source: |
Code function: |
1_2_013B95CD | |
Source: |
Code function: |
1_2_013D5DCA | |
Source: |
Code function: |
9_2_6D855BE9 | |
Source: |
Code function: |
9_2_00C25B18 | |
Source: |
Code function: |
9_2_00C36DDC | |
Source: |
Code function: |
9_2_00C6AC46 |
Launches processes in debugging mode, may be used to hinder debugging |
Source: |
Process created: |
Jump to behavior |
Source: |
Code function: |
1_2_013C03A3 | |
Source: |
Code function: |
1_2_013BBE30 | |
Source: |
Code function: |
9_2_6D837D41 | |
Source: |
Code function: |
9_2_6D846FED | |
Source: |
Code function: |
9_2_00C29C76 | |
Source: |
Code function: |
9_2_00C17C2C |
HIPS / PFW / Operating System Protection Evasion: |
---|
Very long cmdline option found, this is very uncommon (may be encrypted or packed) |
Source: |
Process created: |
|||
Source: |
Process created: |
Jump to behavior |
Source: |
Code function: |
1_2_01352DA0 |
Source: |
Binary or memory string: |
||
Source: |
Binary or memory string: |
||
Source: |
Binary or memory string: |
||
Source: |
Binary or memory string: |
Language, Device and Operating System Detection: |
---|
Queries the volume information (name, serial number etc) of a device |
Source: |
Queries volume information: |
Jump to behavior | ||
Source: |
Queries volume information: |
Jump to behavior | ||
Source: |
Queries volume information: |
Jump to behavior |
Contains functionality to query locales information (e.g. system language) |
Source: |
Code function: |
1_2_013CE806 | |
Source: |
Code function: |
1_2_013D2878 | |
Source: |
Code function: |
1_2_013D20EC | |
Source: |
Code function: |
1_2_013D238E | |
Source: |
Code function: |
1_2_013D23D9 | |
Source: |
Code function: |
1_2_013D2A4D | |
Source: |
Code function: |
1_2_013CE28D | |
Source: |
Code function: |
1_2_013D2474 | |
Source: |
Code function: |
1_2_013487A0 | |
Source: |
Code function: |
9_2_00C3E1C8 | |
Source: |
Code function: |
9_2_00C3E954 | |
Source: |
Code function: |
9_2_00C36AC1 | |
Source: |
Code function: |
9_2_00C3EB29 | |
Source: |
Code function: |
9_2_00C3E4B5 | |
Source: |
Code function: |
9_2_00C3E46A | |
Source: |
Code function: |
9_2_00C3E550 | |
Source: |
Code function: |
9_2_00C3655F |
Contains functionality to query CPU information (cpuid) |
Source: |
Code function: |
1_2_013BB9A6 |
Source: |
Key value queried: |
Jump to behavior |
Source: |
Code function: |
1_2_0135FEF0 |
Source: |
Code function: |
1_2_0135B9F0 |
Source: |
Code function: |
9_2_00A71752 |
Stealing of Sensitive Information: |
---|
Yara detected Ursnif |
Source: |
File source: |
||
Source: |
File source: |
||
Source: |
File source: |
||
Source: |
File source: |
||
Source: |
File source: |
||
Source: |
File source: |
||
Source: |
File source: |
||
Source: |
File source: |
||
Source: |
File source: |
||
Source: |
File source: |
||
Source: |
File source: |
||
Source: |
File source: |
||
Source: |
File source: |
||
Source: |
File source: |
Remote Access Functionality: |
---|
Yara detected Ursnif |
Source: |
File source: |
||
Source: |
File source: |
||
Source: |
File source: |
||
Source: |
File source: |
||
Source: |
File source: |
||
Source: |
File source: |
||
Source: |
File source: |
||
Source: |
File source: |
||
Source: |
File source: |
||
Source: |
File source: |
||
Source: |
File source: |
||
Source: |
File source: |
||
Source: |
File source: |
||
Source: |
File source: |
Contains functionality to open a port and listen for incoming connection (possibly a backdoor) |
Source: |
Code function: |
9_2_00A910D0 | |
Source: |
Code function: |
9_2_00A8F6D0 |
No contacted IP infos |
---|
Name | IP | Active |
---|---|---|
get.updates.avast.cn | unknown | unknown |