Source: 00000011.00000000.406123178.0000000072480000.00000040.00000001.sdmp |
Malware Configuration Extractor: FormBook {"C2 list": ["www.ehawkstech.com/s4mt/"], "decoy": ["deviousrofwft.xyz", "iphone13.photos", "cameraderie.info", "flogotwheelz.com", "lunasconstructionllc.com", "unameofficial.com", "digitalboat.cloud", "hifi-cans.com", "breskizci.com", "kyleandconner.com", "punnyaseva.com", "elitephotoedit.com", "pizzatallrikar.one", "espacio40.com", "bvgsf.xyz", "splootingcorgi.com", "metaverse360.biz", "xnegbuy.com", "buysubarus.com", "optophonia.com", "jingcai16.com", "verdantpor.xyz", "mandyfarricker.com", "affiliategang.com", "chemissimo.com", "myspecialgift4you.com", "21cfintech.com", "parsvivid.com", "ufabetkhmer.net", "litunity.com", "bcwis.com", "ekokosiarki.com", "expocanna.net", "shanichara.com", "brightstarlogisticss.com", "intaom.net", "petshop.zone", "habxgg.com", "taiqen.com", "vehiculosvivienda.com", "igsc-eg.com", "jfhy88.com", "circuspolitician.com", "etxperiodontics.com", "wsxkd.com", "abosasaio.com", "magnacursos.online", "indigenousjobs.net", "digital904.com", "pp-jm.com", "hkqlxc.com", "mygutimautpribuinrop.com", "cosplayharem.com", "jsxybq.com", "fieldstationlodges.com", "ggrow-hairsalon.com", "aureliemorgane.com", "yian-ho.com", "woruke.club", "meet-hamburg.com", "leadergaterealty.com", "choitokki.com", "cfweb.tools", "loveyopu.com"]} |
Source: Yara match |
File source: 17.0.mobsync.exe.72480000.1.unpack, type: UNPACKEDPE |
Source: Yara match |
File source: 17.0.mobsync.exe.72480000.0.raw.unpack, type: UNPACKEDPE |
Source: Yara match |
File source: 17.0.mobsync.exe.72480000.2.unpack, type: UNPACKEDPE |
Source: Yara match |
File source: 17.0.mobsync.exe.72480000.3.raw.unpack, type: UNPACKEDPE |
Source: Yara match |
File source: 17.0.mobsync.exe.72480000.3.unpack, type: UNPACKEDPE |
Source: Yara match |
File source: 17.0.mobsync.exe.72480000.0.unpack, type: UNPACKEDPE |
Source: Yara match |
File source: 17.0.mobsync.exe.72480000.1.raw.unpack, type: UNPACKEDPE |
Source: Yara match |
File source: 17.0.mobsync.exe.72480000.2.raw.unpack, type: UNPACKEDPE |
Source: Yara match |
File source: 00000012.00000000.476572869.0000000006D0E000.00000040.00020000.sdmp, type: MEMORY |
Source: Yara match |
File source: 00000011.00000000.406123178.0000000072480000.00000040.00000001.sdmp, type: MEMORY |
Source: Yara match |
File source: 00000011.00000000.407026308.0000000072480000.00000040.00000001.sdmp, type: MEMORY |
Source: Yara match |
File source: 00000011.00000000.406606133.0000000072480000.00000040.00000001.sdmp, type: MEMORY |
Source: Yara match |
File source: 00000011.00000000.405354552.0000000072480000.00000040.00000001.sdmp, type: MEMORY |
Source: Yara match |
File source: 17.0.mobsync.exe.72480000.1.unpack, type: UNPACKEDPE |
Source: Yara match |
File source: 17.0.mobsync.exe.72480000.0.raw.unpack, type: UNPACKEDPE |
Source: Yara match |
File source: 17.0.mobsync.exe.72480000.2.unpack, type: UNPACKEDPE |
Source: Yara match |
File source: 17.0.mobsync.exe.72480000.3.raw.unpack, type: UNPACKEDPE |
Source: Yara match |
File source: 17.0.mobsync.exe.72480000.3.unpack, type: UNPACKEDPE |
Source: Yara match |
File source: 17.0.mobsync.exe.72480000.0.unpack, type: UNPACKEDPE |
Source: Yara match |
File source: 17.0.mobsync.exe.72480000.1.raw.unpack, type: UNPACKEDPE |
Source: Yara match |
File source: 17.0.mobsync.exe.72480000.2.raw.unpack, type: UNPACKEDPE |
Source: Yara match |
File source: 00000012.00000000.476572869.0000000006D0E000.00000040.00020000.sdmp, type: MEMORY |
Source: Yara match |
File source: 00000011.00000000.406123178.0000000072480000.00000040.00000001.sdmp, type: MEMORY |
Source: Yara match |
File source: 00000011.00000000.407026308.0000000072480000.00000040.00000001.sdmp, type: MEMORY |
Source: Yara match |
File source: 00000011.00000000.406606133.0000000072480000.00000040.00000001.sdmp, type: MEMORY |
Source: Yara match |
File source: 00000011.00000000.405354552.0000000072480000.00000040.00000001.sdmp, type: MEMORY |
Source: 17.0.mobsync.exe.72480000.1.unpack, type: UNPACKEDPE |
Matched rule: autogenerated rule brought to you by yara-signator Author: Felix Bilstein - yara-signator at cocacoding dot com |
Source: 17.0.mobsync.exe.72480000.1.unpack, type: UNPACKEDPE |
Matched rule: detect Formbook in memory Author: JPCERT/CC Incident Response Group |
Source: 17.0.mobsync.exe.72480000.0.raw.unpack, type: UNPACKEDPE |
Matched rule: autogenerated rule brought to you by yara-signator Author: Felix Bilstein - yara-signator at cocacoding dot com |
Source: 17.0.mobsync.exe.72480000.0.raw.unpack, type: UNPACKEDPE |
Matched rule: detect Formbook in memory Author: JPCERT/CC Incident Response Group |
Source: 17.0.mobsync.exe.72480000.2.unpack, type: UNPACKEDPE |
Matched rule: autogenerated rule brought to you by yara-signator Author: Felix Bilstein - yara-signator at cocacoding dot com |
Source: 17.0.mobsync.exe.72480000.2.unpack, type: UNPACKEDPE |
Matched rule: detect Formbook in memory Author: JPCERT/CC Incident Response Group |
Source: 17.0.mobsync.exe.72480000.3.raw.unpack, type: UNPACKEDPE |
Matched rule: autogenerated rule brought to you by yara-signator Author: Felix Bilstein - yara-signator at cocacoding dot com |
Source: 17.0.mobsync.exe.72480000.3.raw.unpack, type: UNPACKEDPE |
Matched rule: detect Formbook in memory Author: JPCERT/CC Incident Response Group |
Source: 17.0.mobsync.exe.72480000.3.unpack, type: UNPACKEDPE |
Matched rule: autogenerated rule brought to you by yara-signator Author: Felix Bilstein - yara-signator at cocacoding dot com |
Source: 17.0.mobsync.exe.72480000.3.unpack, type: UNPACKEDPE |
Matched rule: detect Formbook in memory Author: JPCERT/CC Incident Response Group |
Source: 17.0.mobsync.exe.72480000.0.unpack, type: UNPACKEDPE |
Matched rule: autogenerated rule brought to you by yara-signator Author: Felix Bilstein - yara-signator at cocacoding dot com |
Source: 17.0.mobsync.exe.72480000.0.unpack, type: UNPACKEDPE |
Matched rule: detect Formbook in memory Author: JPCERT/CC Incident Response Group |
Source: 17.0.mobsync.exe.72480000.1.raw.unpack, type: UNPACKEDPE |
Matched rule: autogenerated rule brought to you by yara-signator Author: Felix Bilstein - yara-signator at cocacoding dot com |
Source: 17.0.mobsync.exe.72480000.1.raw.unpack, type: UNPACKEDPE |
Matched rule: detect Formbook in memory Author: JPCERT/CC Incident Response Group |
Source: 17.0.mobsync.exe.72480000.2.raw.unpack, type: UNPACKEDPE |
Matched rule: autogenerated rule brought to you by yara-signator Author: Felix Bilstein - yara-signator at cocacoding dot com |
Source: 17.0.mobsync.exe.72480000.2.raw.unpack, type: UNPACKEDPE |
Matched rule: detect Formbook in memory Author: JPCERT/CC Incident Response Group |
Source: 00000012.00000000.476572869.0000000006D0E000.00000040.00020000.sdmp, type: MEMORY |
Matched rule: autogenerated rule brought to you by yara-signator Author: Felix Bilstein - yara-signator at cocacoding dot com |
Source: 00000012.00000000.476572869.0000000006D0E000.00000040.00020000.sdmp, type: MEMORY |
Matched rule: detect Formbook in memory Author: JPCERT/CC Incident Response Group |
Source: 00000011.00000000.406123178.0000000072480000.00000040.00000001.sdmp, type: MEMORY |
Matched rule: autogenerated rule brought to you by yara-signator Author: Felix Bilstein - yara-signator at cocacoding dot com |
Source: 00000011.00000000.406123178.0000000072480000.00000040.00000001.sdmp, type: MEMORY |
Matched rule: detect Formbook in memory Author: JPCERT/CC Incident Response Group |
Source: 00000011.00000000.407026308.0000000072480000.00000040.00000001.sdmp, type: MEMORY |
Matched rule: autogenerated rule brought to you by yara-signator Author: Felix Bilstein - yara-signator at cocacoding dot com |
Source: 00000011.00000000.407026308.0000000072480000.00000040.00000001.sdmp, type: MEMORY |
Matched rule: detect Formbook in memory Author: JPCERT/CC Incident Response Group |
Source: 00000011.00000000.406606133.0000000072480000.00000040.00000001.sdmp, type: MEMORY |
Matched rule: autogenerated rule brought to you by yara-signator Author: Felix Bilstein - yara-signator at cocacoding dot com |
Source: 00000011.00000000.406606133.0000000072480000.00000040.00000001.sdmp, type: MEMORY |
Matched rule: detect Formbook in memory Author: JPCERT/CC Incident Response Group |
Source: 00000011.00000000.405354552.0000000072480000.00000040.00000001.sdmp, type: MEMORY |
Matched rule: autogenerated rule brought to you by yara-signator Author: Felix Bilstein - yara-signator at cocacoding dot com |
Source: 00000011.00000000.405354552.0000000072480000.00000040.00000001.sdmp, type: MEMORY |
Matched rule: detect Formbook in memory Author: JPCERT/CC Incident Response Group |
Source: 17.0.mobsync.exe.72480000.1.unpack, type: UNPACKEDPE |
Matched rule: Formbook_1 date = 2018-11-23, author = Felix Bilstein - yara-signator at cocacoding dot com, malpedia_version = 20180607, description = autogenerated rule brought to you by yara-signator, malpedia_reference = https://malpedia.caad.fkie.fraunhofer.de/details/win.formbook, cape_type = Formbook Payload, malpedia_license = CC BY-NC-SA 4.0, version = 1, tool = yara-signator 0.1a, malpedia_sharing = TLP:WHITE |
Source: 17.0.mobsync.exe.72480000.1.unpack, type: UNPACKEDPE |
Matched rule: Formbook author = JPCERT/CC Incident Response Group, description = detect Formbook in memory, rule_usage = memory scan, reference = internal research |
Source: 17.0.mobsync.exe.72480000.0.raw.unpack, type: UNPACKEDPE |
Matched rule: Formbook_1 date = 2018-11-23, author = Felix Bilstein - yara-signator at cocacoding dot com, malpedia_version = 20180607, description = autogenerated rule brought to you by yara-signator, malpedia_reference = https://malpedia.caad.fkie.fraunhofer.de/details/win.formbook, cape_type = Formbook Payload, malpedia_license = CC BY-NC-SA 4.0, version = 1, tool = yara-signator 0.1a, malpedia_sharing = TLP:WHITE |
Source: 17.0.mobsync.exe.72480000.0.raw.unpack, type: UNPACKEDPE |
Matched rule: Formbook author = JPCERT/CC Incident Response Group, description = detect Formbook in memory, rule_usage = memory scan, reference = internal research |
Source: 17.0.mobsync.exe.72480000.2.unpack, type: UNPACKEDPE |
Matched rule: Formbook_1 date = 2018-11-23, author = Felix Bilstein - yara-signator at cocacoding dot com, malpedia_version = 20180607, description = autogenerated rule brought to you by yara-signator, malpedia_reference = https://malpedia.caad.fkie.fraunhofer.de/details/win.formbook, cape_type = Formbook Payload, malpedia_license = CC BY-NC-SA 4.0, version = 1, tool = yara-signator 0.1a, malpedia_sharing = TLP:WHITE |
Source: 17.0.mobsync.exe.72480000.2.unpack, type: UNPACKEDPE |
Matched rule: Formbook author = JPCERT/CC Incident Response Group, description = detect Formbook in memory, rule_usage = memory scan, reference = internal research |
Source: 17.0.mobsync.exe.72480000.3.raw.unpack, type: UNPACKEDPE |
Matched rule: Formbook_1 date = 2018-11-23, author = Felix Bilstein - yara-signator at cocacoding dot com, malpedia_version = 20180607, description = autogenerated rule brought to you by yara-signator, malpedia_reference = https://malpedia.caad.fkie.fraunhofer.de/details/win.formbook, cape_type = Formbook Payload, malpedia_license = CC BY-NC-SA 4.0, version = 1, tool = yara-signator 0.1a, malpedia_sharing = TLP:WHITE |
Source: 17.0.mobsync.exe.72480000.3.raw.unpack, type: UNPACKEDPE |
Matched rule: Formbook author = JPCERT/CC Incident Response Group, description = detect Formbook in memory, rule_usage = memory scan, reference = internal research |
Source: 17.0.mobsync.exe.72480000.3.unpack, type: UNPACKEDPE |
Matched rule: Formbook_1 date = 2018-11-23, author = Felix Bilstein - yara-signator at cocacoding dot com, malpedia_version = 20180607, description = autogenerated rule brought to you by yara-signator, malpedia_reference = https://malpedia.caad.fkie.fraunhofer.de/details/win.formbook, cape_type = Formbook Payload, malpedia_license = CC BY-NC-SA 4.0, version = 1, tool = yara-signator 0.1a, malpedia_sharing = TLP:WHITE |
Source: 17.0.mobsync.exe.72480000.3.unpack, type: UNPACKEDPE |
Matched rule: Formbook author = JPCERT/CC Incident Response Group, description = detect Formbook in memory, rule_usage = memory scan, reference = internal research |
Source: 17.0.mobsync.exe.72480000.0.unpack, type: UNPACKEDPE |
Matched rule: Formbook_1 date = 2018-11-23, author = Felix Bilstein - yara-signator at cocacoding dot com, malpedia_version = 20180607, description = autogenerated rule brought to you by yara-signator, malpedia_reference = https://malpedia.caad.fkie.fraunhofer.de/details/win.formbook, cape_type = Formbook Payload, malpedia_license = CC BY-NC-SA 4.0, version = 1, tool = yara-signator 0.1a, malpedia_sharing = TLP:WHITE |
Source: 17.0.mobsync.exe.72480000.0.unpack, type: UNPACKEDPE |
Matched rule: Formbook author = JPCERT/CC Incident Response Group, description = detect Formbook in memory, rule_usage = memory scan, reference = internal research |
Source: 17.0.mobsync.exe.72480000.1.raw.unpack, type: UNPACKEDPE |
Matched rule: Formbook_1 date = 2018-11-23, author = Felix Bilstein - yara-signator at cocacoding dot com, malpedia_version = 20180607, description = autogenerated rule brought to you by yara-signator, malpedia_reference = https://malpedia.caad.fkie.fraunhofer.de/details/win.formbook, cape_type = Formbook Payload, malpedia_license = CC BY-NC-SA 4.0, version = 1, tool = yara-signator 0.1a, malpedia_sharing = TLP:WHITE |
Source: 17.0.mobsync.exe.72480000.1.raw.unpack, type: UNPACKEDPE |
Matched rule: Formbook author = JPCERT/CC Incident Response Group, description = detect Formbook in memory, rule_usage = memory scan, reference = internal research |
Source: 17.0.mobsync.exe.72480000.2.raw.unpack, type: UNPACKEDPE |
Matched rule: Formbook_1 date = 2018-11-23, author = Felix Bilstein - yara-signator at cocacoding dot com, malpedia_version = 20180607, description = autogenerated rule brought to you by yara-signator, malpedia_reference = https://malpedia.caad.fkie.fraunhofer.de/details/win.formbook, cape_type = Formbook Payload, malpedia_license = CC BY-NC-SA 4.0, version = 1, tool = yara-signator 0.1a, malpedia_sharing = TLP:WHITE |
Source: 17.0.mobsync.exe.72480000.2.raw.unpack, type: UNPACKEDPE |
Matched rule: Formbook author = JPCERT/CC Incident Response Group, description = detect Formbook in memory, rule_usage = memory scan, reference = internal research |
Source: 00000012.00000000.522824405.000000000DDB9000.00000004.00000001.sdmp, type: MEMORY |
Matched rule: Methodology_Contains_Shortcut_OtherURIhandlers author = @itsreallynick (Nick Carr), description = Detects possible shortcut usage for .URL persistence, reference = https://twitter.com/cglyer/status/1176184798248919044, score = 27.09.2019 |
Source: 00000012.00000000.476572869.0000000006D0E000.00000040.00020000.sdmp, type: MEMORY |
Matched rule: Formbook_1 date = 2018-11-23, author = Felix Bilstein - yara-signator at cocacoding dot com, malpedia_version = 20180607, description = autogenerated rule brought to you by yara-signator, malpedia_reference = https://malpedia.caad.fkie.fraunhofer.de/details/win.formbook, cape_type = Formbook Payload, malpedia_license = CC BY-NC-SA 4.0, version = 1, tool = yara-signator 0.1a, malpedia_sharing = TLP:WHITE |
Source: 00000012.00000000.476572869.0000000006D0E000.00000040.00020000.sdmp, type: MEMORY |
Matched rule: Formbook author = JPCERT/CC Incident Response Group, description = detect Formbook in memory, rule_usage = memory scan, reference = internal research |
Source: 00000011.00000000.406123178.0000000072480000.00000040.00000001.sdmp, type: MEMORY |
Matched rule: Formbook_1 date = 2018-11-23, author = Felix Bilstein - yara-signator at cocacoding dot com, malpedia_version = 20180607, description = autogenerated rule brought to you by yara-signator, malpedia_reference = https://malpedia.caad.fkie.fraunhofer.de/details/win.formbook, cape_type = Formbook Payload, malpedia_license = CC BY-NC-SA 4.0, version = 1, tool = yara-signator 0.1a, malpedia_sharing = TLP:WHITE |
Source: 00000011.00000000.406123178.0000000072480000.00000040.00000001.sdmp, type: MEMORY |
Matched rule: Formbook author = JPCERT/CC Incident Response Group, description = detect Formbook in memory, rule_usage = memory scan, reference = internal research |
Source: 00000011.00000000.407026308.0000000072480000.00000040.00000001.sdmp, type: MEMORY |
Matched rule: Formbook_1 date = 2018-11-23, author = Felix Bilstein - yara-signator at cocacoding dot com, malpedia_version = 20180607, description = autogenerated rule brought to you by yara-signator, malpedia_reference = https://malpedia.caad.fkie.fraunhofer.de/details/win.formbook, cape_type = Formbook Payload, malpedia_license = CC BY-NC-SA 4.0, version = 1, tool = yara-signator 0.1a, malpedia_sharing = TLP:WHITE |
Source: 00000011.00000000.407026308.0000000072480000.00000040.00000001.sdmp, type: MEMORY |
Matched rule: Formbook author = JPCERT/CC Incident Response Group, description = detect Formbook in memory, rule_usage = memory scan, reference = internal research |
Source: 00000011.00000000.406606133.0000000072480000.00000040.00000001.sdmp, type: MEMORY |
Matched rule: Formbook_1 date = 2018-11-23, author = Felix Bilstein - yara-signator at cocacoding dot com, malpedia_version = 20180607, description = autogenerated rule brought to you by yara-signator, malpedia_reference = https://malpedia.caad.fkie.fraunhofer.de/details/win.formbook, cape_type = Formbook Payload, malpedia_license = CC BY-NC-SA 4.0, version = 1, tool = yara-signator 0.1a, malpedia_sharing = TLP:WHITE |
Source: 00000011.00000000.406606133.0000000072480000.00000040.00000001.sdmp, type: MEMORY |
Matched rule: Formbook author = JPCERT/CC Incident Response Group, description = detect Formbook in memory, rule_usage = memory scan, reference = internal research |
Source: 00000011.00000000.405354552.0000000072480000.00000040.00000001.sdmp, type: MEMORY |
Matched rule: Formbook_1 date = 2018-11-23, author = Felix Bilstein - yara-signator at cocacoding dot com, malpedia_version = 20180607, description = autogenerated rule brought to you by yara-signator, malpedia_reference = https://malpedia.caad.fkie.fraunhofer.de/details/win.formbook, cape_type = Formbook Payload, malpedia_license = CC BY-NC-SA 4.0, version = 1, tool = yara-signator 0.1a, malpedia_sharing = TLP:WHITE |
Source: 00000011.00000000.405354552.0000000072480000.00000040.00000001.sdmp, type: MEMORY |
Matched rule: Formbook author = JPCERT/CC Incident Response Group, description = detect Formbook in memory, rule_usage = memory scan, reference = internal research |
Source: C:\Users\Public\Libraries\owgkuB.url, type: DROPPED |
Matched rule: Methodology_Contains_Shortcut_OtherURIhandlers author = @itsreallynick (Nick Carr), description = Detects possible shortcut usage for .URL persistence, reference = https://twitter.com/cglyer/status/1176184798248919044, score = 27.09.2019 |
Source: C:\Users\user\Desktop\T-T Swift Copy.exe |
Code function: 0_3_0234A584 push eax; ret |
0_3_0234A5C0 |
Source: C:\Users\user\Desktop\T-T Swift Copy.exe |
Code function: 0_3_0234A584 push eax; ret |
0_3_0234A5C0 |
Source: C:\Users\user\Desktop\T-T Swift Copy.exe |
Code function: 0_3_0234A584 push eax; ret |
0_3_0234A5C0 |
Source: C:\Users\user\Desktop\T-T Swift Copy.exe |
Code function: 0_3_0234A584 push eax; ret |
0_3_0234A5C0 |
Source: C:\Users\user\Desktop\T-T Swift Copy.exe |
Code function: 0_3_0234A584 push eax; ret |
0_3_0234A5C0 |
Source: C:\Users\user\Desktop\T-T Swift Copy.exe |
Code function: 0_3_0234A584 push eax; ret |
0_3_0234A5C0 |
Source: C:\Users\user\Desktop\T-T Swift Copy.exe |
Code function: 0_3_0234A584 push eax; ret |
0_3_0234A5C0 |
Source: C:\Users\user\Desktop\T-T Swift Copy.exe |
Code function: 0_3_0234A584 push eax; ret |
0_3_0234A5C0 |
Source: C:\Users\user\Desktop\T-T Swift Copy.exe |
Code function: 0_3_0234A584 push eax; ret |
0_3_0234A5C0 |
Source: C:\Users\user\Desktop\T-T Swift Copy.exe |
Code function: 0_3_0234A58E push eax; ret |
0_3_0234A5C0 |
Source: C:\Users\user\Desktop\T-T Swift Copy.exe |
Code function: 0_3_0234A58E push eax; ret |
0_3_0234A5C0 |
Source: C:\Users\user\Desktop\T-T Swift Copy.exe |
Code function: 0_3_0234A58E push eax; ret |
0_3_0234A5C0 |
Source: C:\Users\user\Desktop\T-T Swift Copy.exe |
Code function: 0_3_0234A58E push eax; ret |
0_3_0234A5C0 |
Source: C:\Users\user\Desktop\T-T Swift Copy.exe |
Code function: 0_3_0234A58E push eax; ret |
0_3_0234A5C0 |
Source: C:\Users\user\Desktop\T-T Swift Copy.exe |
Code function: 0_3_0234A58E push eax; ret |
0_3_0234A5C0 |
Source: C:\Users\user\Desktop\T-T Swift Copy.exe |
Code function: 0_3_0234A58E push eax; ret |
0_3_0234A5C0 |
Source: C:\Users\user\Desktop\T-T Swift Copy.exe |
Code function: 0_3_0234A58E push eax; ret |
0_3_0234A5C0 |
Source: C:\Users\user\Desktop\T-T Swift Copy.exe |
Code function: 0_3_0234A58E push eax; ret |
0_3_0234A5C0 |
Source: explorer.exe, 00000012.00000000.427677045.0000000008AEA000.00000004.00000001.sdmp |
Binary or memory string: AGE#Volume#{e6e9dfc6-98f2-11e9-90ce-806e6f6e6963}#0000000025700000#{53f5630d-b6bf-11d0-94f2-00a0c91efb8b}\\?\STORAGE#Volume#{e6e9dfc6-98f2-11e9-90ce-806e6f6e6963}#000000001F400000#{53f5630d-b6bf-11d0-94f2-00a0c91efb8b}\\?\STORAGE#Volume#{e6e9dfc6-98f2-11e9-90ce-806e6f6e6963}#0000000026700000#{53f5630d-b6bf-11d0-94f2-00a0c91efb8b}\\?\STORAGE#Volume#{e6e9dfc6-98f2-11e9-90ce-806e6f6e6963}#0000000000100000#{53f5630d-b6bf-11d0-94f2-00a0c91efb8b}\\?\SCSI#CdRom&Ven_NECVMWar&Prod_VMware_SATA_CD00#5&280b647&0&000000#{53f5630d-b6bf-11d0-94f2-00a0c91efb8b}\\?\SCSI#CdRom&Ven_Msft&Prod_Virtual_DVD-ROM#2&1f4adffe&0&000001#{53f5630d-b6bf-11d0-94f2-00a0c91efb8b} |
Source: explorer.exe, 00000012.00000000.430733448.000000000DD50000.00000004.00000001.sdmp |
Binary or memory string: \\?\STORAGE#Volume#{e6e9dfc6-98f2-11e9-90ce-806e6f6e6963}#0000000025700000#{53f5630d-b6bf-11d0-94f2-00a0c91efb8b}\\?\STORAGE#Volume#{e6e9dfc6-98f2-11e9-90ce-806e6f6e6963}#000000001F400000#{53f5630d-b6bf-11d0-94f2-00a0c91efb8b}\\?\STORAGE#Volume#{e6e9dfc6-98f2-11e9-90ce-806e6f6e6963}#0000000026700000#{53f5630d-b6bf-11d0-94f2-00a0c91efb8b}\\?\STORAGE#Volume#{e6e9dfc6-98f2-11e9-90ce-806e6f6e6963}#0000000000100000#{53f5630d-b6bf-11d0-94f2-00a0c91efb8b}\\?\SCSI#CdRom&Ven_NECVMWar&Prod_VMware_SATA_CD00#5&280b647&0&000000#{53f5630d-b6bf-11d0-94f2-00a0c91efb8b}\\?\SCSI#CdRom&Ven_Msft&Prod_Virtual_DVD-ROM#2&1f4adffe&0&000001#{53f5630d-b6bf-11d0-94f2-00a0c91efb8b} |
Source: explorer.exe, 00000012.00000000.414140722.0000000003710000.00000004.00000001.sdmp |
Binary or memory string: \\?\scsi#cdrom&ven_necvmwar&prod_vmware_sata_cd00#5&280b647&0&000000#{53f56308-b6bf-11d0-94f2-00a0c91efb8b} |
Source: explorer.exe, 00000012.00000000.461548736.0000000003767000.00000004.00000001.sdmp |
Binary or memory string: VMware SATA CD00 |
Source: explorer.exe, 00000012.00000002.532156882.00000000011B3000.00000004.00000020.sdmp |
Binary or memory string: SCSI\Disk&Ven_VMware&Prod_Virtual_disk\5&1ec51bf7&0&000000tft\0 |
Source: explorer.exe, 00000012.00000000.495160737.0000000008AB2000.00000004.00000001.sdmp |
Binary or memory string: Prod_VMware_SATA-6 |
Source: explorer.exe, 00000012.00000000.491525429.00000000089B5000.00000004.00000001.sdmp |
Binary or memory string: SCSI\CDROM&VEN_NECVMWAR&PROD_VMWARE_SATA_CD00\5&280B647&0&000000% |
Source: explorer.exe, 00000012.00000000.464859424.00000000053C4000.00000004.00000001.sdmp |
Binary or memory string: \\?\SCSI#CdRom&Ven_NECVMWar&Prod_VMware_SATA_CD00#5&280b647&0&000000#{53f5630d-b6bf-11d0-94f2-00a0c91efb8b}>'R\" |
Source: explorer.exe, 00000012.00000000.491525429.00000000089B5000.00000004.00000001.sdmp |
Binary or memory string: SCSI\CdRom&Ven_NECVMWar&Prod_VMware_SATA_CD00\5&280b647&0&0000002 |
Source: explorer.exe, 00000012.00000000.427087654.00000000089FF000.00000004.00000001.sdmp, Bukgwo.exe, 00000015.00000002.519902050.0000000000D50000.00000002.00020000.sdmp, Bukgwo.exe, 00000018.00000002.519458391.0000000000E60000.00000002.00020000.sdmp |
Binary or memory string: Shell_TrayWnd |
Source: explorer.exe, 00000012.00000000.450521833.0000000001640000.00000002.00020000.sdmp, Bukgwo.exe, 00000015.00000002.519902050.0000000000D50000.00000002.00020000.sdmp, Bukgwo.exe, 00000018.00000002.519458391.0000000000E60000.00000002.00020000.sdmp |
Binary or memory string: Progman |
Source: explorer.exe, 00000012.00000000.450521833.0000000001640000.00000002.00020000.sdmp, Bukgwo.exe, 00000015.00000002.519902050.0000000000D50000.00000002.00020000.sdmp, Bukgwo.exe, 00000018.00000002.519458391.0000000000E60000.00000002.00020000.sdmp |
Binary or memory string: SProgram Managerl |
Source: explorer.exe, 00000012.00000000.448726082.0000000001128000.00000004.00000020.sdmp |
Binary or memory string: ProgmanOMEa |
Source: explorer.exe, 00000012.00000000.450521833.0000000001640000.00000002.00020000.sdmp, Bukgwo.exe, 00000015.00000002.519902050.0000000000D50000.00000002.00020000.sdmp, Bukgwo.exe, 00000018.00000002.519458391.0000000000E60000.00000002.00020000.sdmp |
Binary or memory string: Shell_TrayWnd, |
Source: explorer.exe, 00000012.00000000.450521833.0000000001640000.00000002.00020000.sdmp, Bukgwo.exe, 00000015.00000002.519902050.0000000000D50000.00000002.00020000.sdmp, Bukgwo.exe, 00000018.00000002.519458391.0000000000E60000.00000002.00020000.sdmp |
Binary or memory string: Progmanlock |
Source: Yara match |
File source: 17.0.mobsync.exe.72480000.1.unpack, type: UNPACKEDPE |
Source: Yara match |
File source: 17.0.mobsync.exe.72480000.0.raw.unpack, type: UNPACKEDPE |
Source: Yara match |
File source: 17.0.mobsync.exe.72480000.2.unpack, type: UNPACKEDPE |
Source: Yara match |
File source: 17.0.mobsync.exe.72480000.3.raw.unpack, type: UNPACKEDPE |
Source: Yara match |
File source: 17.0.mobsync.exe.72480000.3.unpack, type: UNPACKEDPE |
Source: Yara match |
File source: 17.0.mobsync.exe.72480000.0.unpack, type: UNPACKEDPE |
Source: Yara match |
File source: 17.0.mobsync.exe.72480000.1.raw.unpack, type: UNPACKEDPE |
Source: Yara match |
File source: 17.0.mobsync.exe.72480000.2.raw.unpack, type: UNPACKEDPE |
Source: Yara match |
File source: 00000012.00000000.476572869.0000000006D0E000.00000040.00020000.sdmp, type: MEMORY |
Source: Yara match |
File source: 00000011.00000000.406123178.0000000072480000.00000040.00000001.sdmp, type: MEMORY |
Source: Yara match |
File source: 00000011.00000000.407026308.0000000072480000.00000040.00000001.sdmp, type: MEMORY |
Source: Yara match |
File source: 00000011.00000000.406606133.0000000072480000.00000040.00000001.sdmp, type: MEMORY |
Source: Yara match |
File source: 00000011.00000000.405354552.0000000072480000.00000040.00000001.sdmp, type: MEMORY |
Source: Yara match |
File source: 17.0.mobsync.exe.72480000.1.unpack, type: UNPACKEDPE |
Source: Yara match |
File source: 17.0.mobsync.exe.72480000.0.raw.unpack, type: UNPACKEDPE |
Source: Yara match |
File source: 17.0.mobsync.exe.72480000.2.unpack, type: UNPACKEDPE |
Source: Yara match |
File source: 17.0.mobsync.exe.72480000.3.raw.unpack, type: UNPACKEDPE |
Source: Yara match |
File source: 17.0.mobsync.exe.72480000.3.unpack, type: UNPACKEDPE |
Source: Yara match |
File source: 17.0.mobsync.exe.72480000.0.unpack, type: UNPACKEDPE |
Source: Yara match |
File source: 17.0.mobsync.exe.72480000.1.raw.unpack, type: UNPACKEDPE |
Source: Yara match |
File source: 17.0.mobsync.exe.72480000.2.raw.unpack, type: UNPACKEDPE |
Source: Yara match |
File source: 00000012.00000000.476572869.0000000006D0E000.00000040.00020000.sdmp, type: MEMORY |
Source: Yara match |
File source: 00000011.00000000.406123178.0000000072480000.00000040.00000001.sdmp, type: MEMORY |
Source: Yara match |
File source: 00000011.00000000.407026308.0000000072480000.00000040.00000001.sdmp, type: MEMORY |
Source: Yara match |
File source: 00000011.00000000.406606133.0000000072480000.00000040.00000001.sdmp, type: MEMORY |
Source: Yara match |
File source: 00000011.00000000.405354552.0000000072480000.00000040.00000001.sdmp, type: MEMORY |