Loading ...

Play interactive tourEdit tour

Windows Analysis Report new order TRICOLOR-6.45 TRICOLOR-6.3 TRICOLOR-8.1 TRICOLOR-7.66.......exe

Overview

General Information

Sample Name:new order TRICOLOR-6.45 TRICOLOR-6.3 TRICOLOR-8.1 TRICOLOR-7.66.......exe
Analysis ID:532730
MD5:66cbe976594f666d5440264a4084b21f
SHA1:944c8819e41ad59333527141a7fd5180253969e1
SHA256:460eb4667362671be2be1e94afe56e73331c3a3cd58b028e49ec135fec8888a9
Tags:agentteslaexe
Infos:

Most interesting Screenshot:

Detection

AgentTesla
Score:100
Range:0 - 100
Whitelisted:false
Confidence:100%

Signatures

Found malware configuration
Snort IDS alert for network traffic (e.g. based on Emerging Threat rules)
Multi AV Scanner detection for submitted file
Yara detected AgentTesla
Yara detected AntiVM3
Multi AV Scanner detection for dropped file
Tries to steal Mail credentials (via file / registry access)
Initial sample is a PE file and has a suspicious name
Tries to harvest and steal Putty / WinSCP information (sessions, passwords, etc)
Tries to harvest and steal ftp login credentials
Tries to detect sandboxes and other dynamic analysis tools (process name or module or function)
Sigma detected: Suspicius Add Task From User AppData Temp
Machine Learning detection for sample
Injects a PE file into a foreign processes
.NET source code contains very large array initializations
Machine Learning detection for dropped file
Queries sensitive network adapter information (via WMI, Win32_NetworkAdapter, often done to detect virtual machines)
Uses schtasks.exe or at.exe to add and modify task schedules
Tries to harvest and steal browser information (history, passwords, etc)
Queries sensitive BIOS Information (via WMI, Win32_Bios & Win32_BaseBoard, often done to detect virtual machines)
Uses 32bit PE files
Queries the volume information (name, serial number etc) of a device
Antivirus or Machine Learning detection for unpacked file
May sleep (evasive loops) to hinder dynamic analysis
Uses code obfuscation techniques (call, push, ret)
Internet Provider seen in connection with other malware
Detected potential crypto function
Sample execution stops while process was sleeping (likely an evasion)
Yara detected Credential Stealer
Creates processes with suspicious names
Contains long sleeps (>= 3 min)
Enables debug privileges
Found a high number of Window / User specific system calls (may be a loop to detect user behavior)
Sample file is different than original file name gathered from version info
Drops PE files
Detected TCP or UDP traffic on non-standard ports
Binary contains a suspicious time stamp
Uses SMTP (mail sending)
Queries sensitive processor information (via WMI, Win32_Processor, often done to detect virtual machines)
Monitors certain registry keys / values for changes (often done to protect autostart functionality)
Creates a process in suspended mode (likely to inject code)
Contains functionality to access loader functionality (e.g. LdrGetProcedureAddress)

Classification

Process Tree

  • System is w10x64
  • cleanup

Malware Configuration

Threatname: Agenttesla

{"Exfil Mode": "SMTP", "Username": "marketing@kyowasecurity.com.sg", "Password": "avKw1$991", "Host": "mail.kyowasecurity.com.sg"}

Yara Overview

Memory Dumps

SourceRuleDescriptionAuthorStrings
00000005.00000000.282084634.0000000000402000.00000040.00000001.sdmpJoeSecurity_AgentTesla_1Yara detected AgentTeslaJoe Security
    00000005.00000000.282084634.0000000000402000.00000040.00000001.sdmpJoeSecurity_AgentTesla_2Yara detected AgentTeslaJoe Security
      00000005.00000000.283151659.0000000000402000.00000040.00000001.sdmpJoeSecurity_AgentTesla_1Yara detected AgentTeslaJoe Security
        00000005.00000000.283151659.0000000000402000.00000040.00000001.sdmpJoeSecurity_AgentTesla_2Yara detected AgentTeslaJoe Security
          00000000.00000002.287974260.0000000002761000.00000004.00000001.sdmpJoeSecurity_AntiVM_3Yara detected AntiVM_3Joe Security
            Click to see the 14 entries

            Unpacked PEs

            SourceRuleDescriptionAuthorStrings
            5.0.new order TRICOLOR-6.45 TRICOLOR-6.3 TRICOLOR-8.1 TRICOLOR-7.66.......exe.400000.6.unpackJoeSecurity_AgentTesla_1Yara detected AgentTeslaJoe Security
              5.0.new order TRICOLOR-6.45 TRICOLOR-6.3 TRICOLOR-8.1 TRICOLOR-7.66.......exe.400000.6.unpackJoeSecurity_AgentTesla_2Yara detected AgentTeslaJoe Security
                5.0.new order TRICOLOR-6.45 TRICOLOR-6.3 TRICOLOR-8.1 TRICOLOR-7.66.......exe.400000.10.unpackJoeSecurity_AgentTesla_1Yara detected AgentTeslaJoe Security
                  5.0.new order TRICOLOR-6.45 TRICOLOR-6.3 TRICOLOR-8.1 TRICOLOR-7.66.......exe.400000.10.unpackJoeSecurity_AgentTesla_2Yara detected AgentTeslaJoe Security
                    0.2.new order TRICOLOR-6.45 TRICOLOR-6.3 TRICOLOR-8.1 TRICOLOR-7.66.......exe.3922928.4.raw.unpackJoeSecurity_AgentTesla_1Yara detected AgentTeslaJoe Security
                      Click to see the 16 entries

                      Sigma Overview

                      System Summary:

                      barindex
                      Sigma detected: Suspicius Add Task From User AppData TempShow sources
                      Source: Process startedAuthor: frack113: Data: Command: C:\Windows\System32\schtasks.exe" /Create /TN "Updates\aUkURZiJ" /XML "C:\Users\user\AppData\Local\Temp\tmp8923.tmp, CommandLine: C:\Windows\System32\schtasks.exe" /Create /TN "Updates\aUkURZiJ" /XML "C:\Users\user\AppData\Local\Temp\tmp8923.tmp, CommandLine|base64offset|contains: *j, Image: C:\Windows\SysWOW64\schtasks.exe, NewProcessName: C:\Windows\SysWOW64\schtasks.exe, OriginalFileName: C:\Windows\SysWOW64\schtasks.exe, ParentCommandLine: "C:\Users\user\Desktop\new order TRICOLOR-6.45 TRICOLOR-6.3 TRICOLOR-8.1 TRICOLOR-7.66.......exe" , ParentImage: C:\Users\user\Desktop\new order TRICOLOR-6.45 TRICOLOR-6.3 TRICOLOR-8.1 TRICOLOR-7.66.......exe, ParentProcessId: 4252, ProcessCommandLine: C:\Windows\System32\schtasks.exe" /Create /TN "Updates\aUkURZiJ" /XML "C:\Users\user\AppData\Local\Temp\tmp8923.tmp, ProcessId: 2964

                      Jbx Signature Overview

                      Click to jump to signature section

                      Show All Signature Results

                      AV Detection:

                      barindex
                      Found malware configurationShow sources
                      Source: 5.0.new order TRICOLOR-6.45 TRICOLOR-6.3 TRICOLOR-8.1 TRICOLOR-7.66.......exe.400000.4.unpackMalware Configuration Extractor: Agenttesla {"Exfil Mode": "SMTP", "Username": "marketing@kyowasecurity.com.sg", "Password": "avKw1$991", "Host": "mail.kyowasecurity.com.sg"}
                      Multi AV Scanner detection for submitted fileShow sources
                      Source: new order TRICOLOR-6.45 TRICOLOR-6.3 TRICOLOR-8.1 TRICOLOR-7.66.......exeReversingLabs: Detection: 41%
                      Multi AV Scanner detection for dropped fileShow sources
                      Source: C:\Users\user\AppData\Roaming\aUkURZiJ.exeReversingLabs: Detection: 41%
                      Machine Learning detection for sampleShow sources
                      Source: new order TRICOLOR-6.45 TRICOLOR-6.3 TRICOLOR-8.1 TRICOLOR-7.66.......exeJoe Sandbox ML: detected
                      Machine Learning detection for dropped fileShow sources
                      Source: C:\Users\user\AppData\Roaming\aUkURZiJ.exeJoe Sandbox ML: detected
                      Source: 5.0.new order TRICOLOR-6.45 TRICOLOR-6.3 TRICOLOR-8.1 TRICOLOR-7.66.......exe.400000.4.unpackAvira: Label: TR/Spy.Gen8
                      Source: 5.0.new order TRICOLOR-6.45 TRICOLOR-6.3 TRICOLOR-8.1 TRICOLOR-7.66.......exe.400000.12.unpackAvira: Label: TR/Spy.Gen8
                      Source: 5.2.new order TRICOLOR-6.45 TRICOLOR-6.3 TRICOLOR-8.1 TRICOLOR-7.66.......exe.400000.0.unpackAvira: Label: TR/Spy.Gen8
                      Source: 5.0.new order TRICOLOR-6.45 TRICOLOR-6.3 TRICOLOR-8.1 TRICOLOR-7.66.......exe.400000.6.unpackAvira: Label: TR/Spy.Gen8
                      Source: 5.0.new order TRICOLOR-6.45 TRICOLOR-6.3 TRICOLOR-8.1 TRICOLOR-7.66.......exe.400000.10.unpackAvira: Label: TR/Spy.Gen8
                      Source: 5.0.new order TRICOLOR-6.45 TRICOLOR-6.3 TRICOLOR-8.1 TRICOLOR-7.66.......exe.400000.8.unpackAvira: Label: TR/Spy.Gen8
                      Source: new order TRICOLOR-6.45 TRICOLOR-6.3 TRICOLOR-8.1 TRICOLOR-7.66.......exeStatic PE information: 32BIT_MACHINE, EXECUTABLE_IMAGE
                      Source: new order TRICOLOR-6.45 TRICOLOR-6.3 TRICOLOR-8.1 TRICOLOR-7.66.......exeStatic PE information: NO_SEH, TERMINAL_SERVER_AWARE, DYNAMIC_BASE, NX_COMPAT

                      Networking:

                      barindex
                      Snort IDS alert for network traffic (e.g. based on Emerging Threat rules)Show sources
                      Source: TrafficSnort IDS: 2030171 ET TROJAN AgentTesla Exfil Via SMTP 192.168.2.5:49831 -> 113.197.35.43:587
                      Source: Joe Sandbox ViewASN Name: USONYX-AS-APUSONYXPTELTDSG USONYX-AS-APUSONYXPTELTDSG
                      Source: global trafficTCP traffic: 192.168.2.5:49831 -> 113.197.35.43:587
                      Source: global trafficTCP traffic: 192.168.2.5:49831 -> 113.197.35.43:587
                      Source: new order TRICOLOR-6.45 TRICOLOR-6.3 TRICOLOR-8.1 TRICOLOR-7.66.......exe, 00000005.00000002.523008375.0000000002DB1000.00000004.00000001.sdmpString found in binary or memory: http://127.0.0.1:HTTP/1.1
                      Source: new order TRICOLOR-6.45 TRICOLOR-6.3 TRICOLOR-8.1 TRICOLOR-7.66.......exe, 00000005.00000002.523008375.0000000002DB1000.00000004.00000001.sdmpString found in binary or memory: http://DynDns.comDynDNS
                      Source: new order TRICOLOR-6.45 TRICOLOR-6.3 TRICOLOR-8.1 TRICOLOR-7.66.......exe, 00000005.00000002.523008375.0000000002DB1000.00000004.00000001.sdmpString found in binary or memory: http://KpGsSw.com
                      Source: new order TRICOLOR-6.45 TRICOLOR-6.3 TRICOLOR-8.1 TRICOLOR-7.66.......exe, 00000000.00000002.292992821.0000000006872000.00000004.00000001.sdmpString found in binary or memory: http://fontfabrik.com
                      Source: new order TRICOLOR-6.45 TRICOLOR-6.3 TRICOLOR-8.1 TRICOLOR-7.66.......exe, 00000005.00000002.524762835.0000000003112000.00000004.00000001.sdmpString found in binary or memory: http://mail.kyowasecurity.com.sg
                      Source: new order TRICOLOR-6.45 TRICOLOR-6.3 TRICOLOR-8.1 TRICOLOR-7.66.......exe, 00000000.00000002.287974260.0000000002761000.00000004.00000001.sdmpString found in binary or memory: http://schemas.xmlsoap.org/ws/2005/05/identity/claims/name
                      Source: new order TRICOLOR-6.45 TRICOLOR-6.3 TRICOLOR-8.1 TRICOLOR-7.66.......exe, 00000000.00000003.248903417.000000000569E000.00000004.00000001.sdmp, new order TRICOLOR-6.45 TRICOLOR-6.3 TRICOLOR-8.1 TRICOLOR-7.66.......exe, 00000000.00000002.292992821.0000000006872000.00000004.00000001.sdmp, new order TRICOLOR-6.45 TRICOLOR-6.3 TRICOLOR-8.1 TRICOLOR-7.66.......exe, 00000000.00000003.248877687.00000000056A1000.00000004.00000001.sdmp, new order TRICOLOR-6.45 TRICOLOR-6.3 TRICOLOR-8.1 TRICOLOR-7.66.......exe, 00000000.00000003.248865129.000000000569E000.00000004.00000001.sdmpString found in binary or memory: http://www.apache.org/licenses/LICENSE-2.0
                      Source: new order TRICOLOR-6.45 TRICOLOR-6.3 TRICOLOR-8.1 TRICOLOR-7.66.......exe, 00000000.00000002.292992821.0000000006872000.00000004.00000001.sdmpString found in binary or memory: http://www.carterandcone.coml
                      Source: new order TRICOLOR-6.45 TRICOLOR-6.3 TRICOLOR-8.1 TRICOLOR-7.66.......exe, 00000000.00000002.292765423.0000000005660000.00000004.00000001.sdmp, new order TRICOLOR-6.45 TRICOLOR-6.3 TRICOLOR-8.1 TRICOLOR-7.66.......exe, 00000000.00000003.285795268.0000000005660000.00000004.00000001.sdmp, new order TRICOLOR-6.45 TRICOLOR-6.3 TRICOLOR-8.1 TRICOLOR-7.66.......exe, 00000000.00000002.292992821.0000000006872000.00000004.00000001.sdmp, new order TRICOLOR-6.45 TRICOLOR-6.3 TRICOLOR-8.1 TRICOLOR-7.66.......exe, 00000000.00000003.255093562.000000000566E000.00000004.00000001.sdmp, new order TRICOLOR-6.45 TRICOLOR-6.3 TRICOLOR-8.1 TRICOLOR-7.66.......exe, 00000000.00000003.254533956.000000000566C000.00000004.00000001.sdmp, new order TRICOLOR-6.45 TRICOLOR-6.3 TRICOLOR-8.1 TRICOLOR-7.66.......exe, 00000000.00000003.254906163.000000000566F000.00000004.00000001.sdmp, new order TRICOLOR-6.45 TRICOLOR-6.3 TRICOLOR-8.1 TRICOLOR-7.66.......exe, 00000000.00000003.253839535.000000000566F000.00000004.00000001.sdmp, new order TRICOLOR-6.45 TRICOLOR-6.3 TRICOLOR-8.1 TRICOLOR-7.66.......exe, 00000000.00000003.254979634.000000000566F000.00000004.00000001.sdmpString found in binary or memory: http://www.fontbureau.com
                      Source: new order TRICOLOR-6.45 TRICOLOR-6.3 TRICOLOR-8.1 TRICOLOR-7.66.......exe, 00000000.00000003.255044284.0000000005699000.00000004.00000001.sdmp, new order TRICOLOR-6.45 TRICOLOR-6.3 TRICOLOR-8.1 TRICOLOR-7.66.......exe, 00000000.00000003.261125302.0000000005699000.00000004.00000001.sdmp, new order TRICOLOR-6.45 TRICOLOR-6.3 TRICOLOR-8.1 TRICOLOR-7.66.......exe, 00000000.00000003.253788835.0000000005699000.00000004.00000001.sdmp, new order TRICOLOR-6.45 TRICOLOR-6.3 TRICOLOR-8.1 TRICOLOR-7.66.......exe, 00000000.00000003.253886398.0000000005699000.00000004.00000001.sdmp, new order TRICOLOR-6.45 TRICOLOR-6.3 TRICOLOR-8.1 TRICOLOR-7.66.......exe, 00000000.00000003.252653993.0000000005699000.00000004.00000001.sdmpString found in binary or memory: http://www.fontbureau.com/designers
                      Source: new order TRICOLOR-6.45 TRICOLOR-6.3 TRICOLOR-8.1 TRICOLOR-7.66.......exe, 00000000.00000003.252695500.0000000005699000.00000004.00000001.sdmp, new order TRICOLOR-6.45 TRICOLOR-6.3 TRICOLOR-8.1 TRICOLOR-7.66.......exe, 00000000.00000003.252577474.000000000569C000.00000004.00000001.sdmp, new order TRICOLOR-6.45 TRICOLOR-6.3 TRICOLOR-8.1 TRICOLOR-7.66.......exe, 00000000.00000003.252494210.0000000005699000.00000004.00000001.sdmp, new order TRICOLOR-6.45 TRICOLOR-6.3 TRICOLOR-8.1 TRICOLOR-7.66.......exe, 00000000.00000003.252547005.0000000005699000.00000004.00000001.sdmp, new order TRICOLOR-6.45 TRICOLOR-6.3 TRICOLOR-8.1 TRICOLOR-7.66.......exe, 00000000.00000003.252614032.0000000005699000.00000004.00000001.sdmp, new order TRICOLOR-6.45 TRICOLOR-6.3 TRICOLOR-8.1 TRICOLOR-7.66.......exe, 00000000.00000003.252799955.0000000005699000.00000004.00000001.sdmp, new order TRICOLOR-6.45 TRICOLOR-6.3 TRICOLOR-8.1 TRICOLOR-7.66.......exe, 00000000.00000003.252653993.0000000005699000.00000004.00000001.sdmp, new order TRICOLOR-6.45 TRICOLOR-6.3 TRICOLOR-8.1 TRICOLOR-7.66.......exe, 00000000.00000003.252756029.0000000005699000.00000004.00000001.sdmpString found in binary or memory: http://www.fontbureau.com/designers/
                      Source: new order TRICOLOR-6.45 TRICOLOR-6.3 TRICOLOR-8.1 TRICOLOR-7.66.......exe, 00000000.00000002.292992821.0000000006872000.00000004.00000001.sdmpString found in binary or memory: http://www.fontbureau.com/designers/?
                      Source: new order TRICOLOR-6.45 TRICOLOR-6.3 TRICOLOR-8.1 TRICOLOR-7.66.......exe, 00000000.00000003.254533956.000000000566C000.00000004.00000001.sdmpString found in binary or memory: http://www.fontbureau.com/designers/cabarga.html
                      Source: new order TRICOLOR-6.45 TRICOLOR-6.3 TRICOLOR-8.1 TRICOLOR-7.66.......exe, 00000000.00000002.292992821.0000000006872000.00000004.00000001.sdmpString found in binary or memory: http://www.fontbureau.com/designers/cabarga.htmlN
                      Source: new order TRICOLOR-6.45 TRICOLOR-6.3 TRICOLOR-8.1 TRICOLOR-7.66.......exe, 00000000.00000003.254533956.000000000566C000.00000004.00000001.sdmpString found in binary or memory: http://www.fontbureau.com/designers/cabarga.htmlrpQj
                      Source: new order TRICOLOR-6.45 TRICOLOR-6.3 TRICOLOR-8.1 TRICOLOR-7.66.......exe, 00000000.00000002.292992821.0000000006872000.00000004.00000001.sdmp, new order TRICOLOR-6.45 TRICOLOR-6.3 TRICOLOR-8.1 TRICOLOR-7.66.......exe, 00000000.00000003.253657790.0000000005699000.00000004.00000001.sdmpString found in binary or memory: http://www.fontbureau.com/designers/frere-jones.html
                      Source: new order TRICOLOR-6.45 TRICOLOR-6.3 TRICOLOR-8.1 TRICOLOR-7.66.......exe, 00000000.00000003.253839535.000000000566F000.00000004.00000001.sdmpString found in binary or memory: http://www.fontbureau.com/designers/frere-jones.html8
                      Source: new order TRICOLOR-6.45 TRICOLOR-6.3 TRICOLOR-8.1 TRICOLOR-7.66.......exe, 00000000.00000003.252494210.0000000005699000.00000004.00000001.sdmp, new order TRICOLOR-6.45 TRICOLOR-6.3 TRICOLOR-8.1 TRICOLOR-7.66.......exe, 00000000.00000003.252547005.0000000005699000.00000004.00000001.sdmpString found in binary or memory: http://www.fontbureau.com/designers/j
                      Source: new order TRICOLOR-6.45 TRICOLOR-6.3 TRICOLOR-8.1 TRICOLOR-7.66.......exe, 00000000.00000003.254671506.0000000005699000.00000004.00000001.sdmpString found in binary or memory: http://www.fontbureau.com/designers6
                      Source: new order TRICOLOR-6.45 TRICOLOR-6.3 TRICOLOR-8.1 TRICOLOR-7.66.......exe, 00000000.00000002.292992821.0000000006872000.00000004.00000001.sdmpString found in binary or memory: http://www.fontbureau.com/designers8
                      Source: new order TRICOLOR-6.45 TRICOLOR-6.3 TRICOLOR-8.1 TRICOLOR-7.66.......exe, 00000000.00000002.292992821.0000000006872000.00000004.00000001.sdmpString found in binary or memory: http://www.fontbureau.com/designers?
                      Source: new order TRICOLOR-6.45 TRICOLOR-6.3 TRICOLOR-8.1 TRICOLOR-7.66.......exe, 00000000.00000002.292992821.0000000006872000.00000004.00000001.sdmpString found in binary or memory: http://www.fontbureau.com/designersG
                      Source: new order TRICOLOR-6.45 TRICOLOR-6.3 TRICOLOR-8.1 TRICOLOR-7.66.......exe, 00000000.00000003.261091046.0000000005699000.00000004.00000001.sdmp, new order TRICOLOR-6.45 TRICOLOR-6.3 TRICOLOR-8.1 TRICOLOR-7.66.......exe, 00000000.00000003.261061221.0000000005699000.00000004.00000001.sdmpString found in binary or memory: http://www.fontbureau.com/designersW
                      Source: new order TRICOLOR-6.45 TRICOLOR-6.3 TRICOLOR-8.1 TRICOLOR-7.66.......exe, 00000000.00000003.254877068.0000000005699000.00000004.00000001.sdmpString found in binary or memory: http://www.fontbureau.com/designerss
                      Source: new order TRICOLOR-6.45 TRICOLOR-6.3 TRICOLOR-8.1 TRICOLOR-7.66.......exe, 00000000.00000003.254533956.000000000566C000.00000004.00000001.sdmp, new order TRICOLOR-6.45 TRICOLOR-6.3 TRICOLOR-8.1 TRICOLOR-7.66.......exe, 00000000.00000003.253839535.000000000566F000.00000004.00000001.sdmpString found in binary or memory: http://www.fontbureau.com=
                      Source: new order TRICOLOR-6.45 TRICOLOR-6.3 TRICOLOR-8.1 TRICOLOR-7.66.......exe, 00000000.00000003.254533956.000000000566C000.00000004.00000001.sdmp, new order TRICOLOR-6.45 TRICOLOR-6.3 TRICOLOR-8.1 TRICOLOR-7.66.......exe, 00000000.00000003.254906163.000000000566F000.00000004.00000001.sdmp, new order TRICOLOR-6.45 TRICOLOR-6.3 TRICOLOR-8.1 TRICOLOR-7.66.......exe, 00000000.00000003.253839535.000000000566F000.00000004.00000001.sdmp, new order TRICOLOR-6.45 TRICOLOR-6.3 TRICOLOR-8.1 TRICOLOR-7.66.......exe, 00000000.00000003.254979634.000000000566F000.00000004.00000001.sdmpString found in binary or memory: http://www.fontbureau.comF
                      Source: new order TRICOLOR-6.45 TRICOLOR-6.3 TRICOLOR-8.1 TRICOLOR-7.66.......exe, 00000000.00000003.255093562.000000000566E000.00000004.00000001.sdmp, new order TRICOLOR-6.45 TRICOLOR-6.3 TRICOLOR-8.1 TRICOLOR-7.66.......exe, 00000000.00000003.254533956.000000000566C000.00000004.00000001.sdmp, new order TRICOLOR-6.45 TRICOLOR-6.3 TRICOLOR-8.1 TRICOLOR-7.66.......exe, 00000000.00000003.254906163.000000000566F000.00000004.00000001.sdmp, new order TRICOLOR-6.45 TRICOLOR-6.3 TRICOLOR-8.1 TRICOLOR-7.66.......exe, 00000000.00000003.256055028.000000000566E000.00000004.00000001.sdmp, new order TRICOLOR-6.45 TRICOLOR-6.3 TRICOLOR-8.1 TRICOLOR-7.66.......exe, 00000000.00000003.254979634.000000000566F000.00000004.00000001.sdmpString found in binary or memory: http://www.fontbureau.comI.TTFks
                      Source: new order TRICOLOR-6.45 TRICOLOR-6.3 TRICOLOR-8.1 TRICOLOR-7.66.......exe, 00000000.00000003.255093562.000000000566E000.00000004.00000001.sdmpString found in binary or memory: http://www.fontbureau.comVsF
                      Source: new order TRICOLOR-6.45 TRICOLOR-6.3 TRICOLOR-8.1 TRICOLOR-7.66.......exe, 00000000.00000003.253839535.000000000566F000.00000004.00000001.sdmpString found in binary or memory: http://www.fontbureau.coma
                      Source: new order TRICOLOR-6.45 TRICOLOR-6.3 TRICOLOR-8.1 TRICOLOR-7.66.......exe, 00000000.00000003.255093562.000000000566E000.00000004.00000001.sdmpString found in binary or memory: http://www.fontbureau.comcomF
                      Source: new order TRICOLOR-6.45 TRICOLOR-6.3 TRICOLOR-8.1 TRICOLOR-7.66.......exe, 00000000.00000003.255093562.000000000566E000.00000004.00000001.sdmp, new order TRICOLOR-6.45 TRICOLOR-6.3 TRICOLOR-8.1 TRICOLOR-7.66.......exe, 00000000.00000003.256209853.000000000566C000.00000004.00000001.sdmp, new order TRICOLOR-6.45 TRICOLOR-6.3 TRICOLOR-8.1 TRICOLOR-7.66.......exe, 00000000.00000003.254906163.000000000566F000.00000004.00000001.sdmp, new order TRICOLOR-6.45 TRICOLOR-6.3 TRICOLOR-8.1 TRICOLOR-7.66.......exe, 00000000.00000003.256055028.000000000566E000.00000004.00000001.sdmp, new order TRICOLOR-6.45 TRICOLOR-6.3 TRICOLOR-8.1 TRICOLOR-7.66.......exe, 00000000.00000003.254979634.000000000566F000.00000004.00000001.sdmpString found in binary or memory: http://www.fontbureau.comd
                      Source: new order TRICOLOR-6.45 TRICOLOR-6.3 TRICOLOR-8.1 TRICOLOR-7.66.......exe, 00000000.00000003.253839535.000000000566F000.00000004.00000001.sdmpString found in binary or memory: http://www.fontbureau.comdrs
                      Source: new order TRICOLOR-6.45 TRICOLOR-6.3 TRICOLOR-8.1 TRICOLOR-7.66.......exe, 00000000.00000003.255093562.000000000566E000.00000004.00000001.sdmp, new order TRICOLOR-6.45 TRICOLOR-6.3 TRICOLOR-8.1 TRICOLOR-7.66.......exe, 00000000.00000003.254533956.000000000566C000.00000004.00000001.sdmp, new order TRICOLOR-6.45 TRICOLOR-6.3 TRICOLOR-8.1 TRICOLOR-7.66.......exe, 00000000.00000003.254906163.000000000566F000.00000004.00000001.sdmp, new order TRICOLOR-6.45 TRICOLOR-6.3 TRICOLOR-8.1 TRICOLOR-7.66.......exe, 00000000.00000003.253839535.000000000566F000.00000004.00000001.sdmp, new order TRICOLOR-6.45 TRICOLOR-6.3 TRICOLOR-8.1 TRICOLOR-7.66.......exe, 00000000.00000003.254979634.000000000566F000.00000004.00000001.sdmpString found in binary or memory: http://www.fontbureau.comessed
                      Source: new order TRICOLOR-6.45 TRICOLOR-6.3 TRICOLOR-8.1 TRICOLOR-7.66.......exe, 00000000.00000003.255093562.000000000566E000.00000004.00000001.sdmp, new order TRICOLOR-6.45 TRICOLOR-6.3 TRICOLOR-8.1 TRICOLOR-7.66.......exe, 00000000.00000003.254906163.000000000566F000.00000004.00000001.sdmp, new order TRICOLOR-6.45 TRICOLOR-6.3 TRICOLOR-8.1 TRICOLOR-7.66.......exe, 00000000.00000003.254979634.000000000566F000.00000004.00000001.sdmpString found in binary or memory: http://www.fontbureau.comessed3sm
                      Source: new order TRICOLOR-6.45 TRICOLOR-6.3 TRICOLOR-8.1 TRICOLOR-7.66.......exe, 00000000.00000003.255093562.000000000566E000.00000004.00000001.sdmp, new order TRICOLOR-6.45 TRICOLOR-6.3 TRICOLOR-8.1 TRICOLOR-7.66.......exe, 00000000.00000003.254906163.000000000566F000.00000004.00000001.sdmp, new order TRICOLOR-6.45 TRICOLOR-6.3 TRICOLOR-8.1 TRICOLOR-7.66.......exe, 00000000.00000003.254979634.000000000566F000.00000004.00000001.sdmpString found in binary or memory: http://www.fontbureau.comsiva
                      Source: new order TRICOLOR-6.45 TRICOLOR-6.3 TRICOLOR-8.1 TRICOLOR-7.66.......exe, 00000000.00000002.292765423.0000000005660000.00000004.00000001.sdmp, new order TRICOLOR-6.45 TRICOLOR-6.3 TRICOLOR-8.1 TRICOLOR-7.66.......exe, 00000000.00000003.285795268.0000000005660000.00000004.00000001.sdmpString found in binary or memory: http://www.fontbureau.comttv
                      Source: new order TRICOLOR-6.45 TRICOLOR-6.3 TRICOLOR-8.1 TRICOLOR-7.66.......exe, 00000000.00000003.253839535.000000000566F000.00000004.00000001.sdmpString found in binary or memory: http://www.fontbureau.comtuta
                      Source: new order TRICOLOR-6.45 TRICOLOR-6.3 TRICOLOR-8.1 TRICOLOR-7.66.......exe, 00000000.00000003.252725051.000000000566E000.00000004.00000001.sdmp, new order TRICOLOR-6.45 TRICOLOR-6.3 TRICOLOR-8.1 TRICOLOR-7.66.......exe, 00000000.00000003.252931728.000000000566F000.00000004.00000001.sdmpString found in binary or memory: http://www.fontbureau.comzana
                      Source: new order TRICOLOR-6.45 TRICOLOR-6.3 TRICOLOR-8.1 TRICOLOR-7.66.......exe, 00000000.00000002.292992821.0000000006872000.00000004.00000001.sdmpString found in binary or memory: http://www.fonts.com
                      Source: new order TRICOLOR-6.45 TRICOLOR-6.3 TRICOLOR-8.1 TRICOLOR-7.66.......exe, 00000000.00000002.292992821.0000000006872000.00000004.00000001.sdmp, new order TRICOLOR-6.45 TRICOLOR-6.3 TRICOLOR-8.1 TRICOLOR-7.66.......exe, 00000000.00000003.248100348.000000000569A000.00000004.00000001.sdmp, new order TRICOLOR-6.45 TRICOLOR-6.3 TRICOLOR-8.1 TRICOLOR-7.66.......exe, 00000000.00000003.248045051.0000000005699000.00000004.00000001.sdmpString found in binary or memory: http://www.founder.com.cn/cn
                      Source: new order TRICOLOR-6.45 TRICOLOR-6.3 TRICOLOR-8.1 TRICOLOR-7.66.......exe, 00000000.00000003.248332429.0000000005699000.00000004.00000001.sdmpString found in binary or memory: http://www.founder.com.cn/cn/
                      Source: new order TRICOLOR-6.45 TRICOLOR-6.3 TRICOLOR-8.1 TRICOLOR-7.66.......exe, 00000000.00000002.292992821.0000000006872000.00000004.00000001.sdmpString found in binary or memory: http://www.founder.com.cn/cn/bThe
                      Source: new order TRICOLOR-6.45 TRICOLOR-6.3 TRICOLOR-8.1 TRICOLOR-7.66.......exe, 00000000.00000002.292992821.0000000006872000.00000004.00000001.sdmpString found in binary or memory: http://www.founder.com.cn/cn/cThe
                      Source: new order TRICOLOR-6.45 TRICOLOR-6.3 TRICOLOR-8.1 TRICOLOR-7.66.......exe, 00000000.00000003.257088272.0000000005699000.00000004.00000001.sdmp, new order TRICOLOR-6.45 TRICOLOR-6.3 TRICOLOR-8.1 TRICOLOR-7.66.......exe, 00000000.00000003.257018883.0000000005699000.00000004.00000001.sdmpString found in binary or memory: http://www.galapagosdesign.com/
                      Source: new order TRICOLOR-6.45 TRICOLOR-6.3 TRICOLOR-8.1 TRICOLOR-7.66.......exe, 00000000.00000003.257184730.000000000566E000.00000004.00000001.sdmpString found in binary or memory: http://www.galapagosdesign.com/3sm
                      Source: new order TRICOLOR-6.45 TRICOLOR-6.3 TRICOLOR-8.1 TRICOLOR-7.66.......exe, 00000000.00000002.292992821.0000000006872000.00000004.00000001.sdmpString found in binary or memory: http://www.galapagosdesign.com/DPlease
                      Source: new order TRICOLOR-6.45 TRICOLOR-6.3 TRICOLOR-8.1 TRICOLOR-7.66.......exe, 00000000.00000003.258256920.000000000567A000.00000004.00000001.sdmp, new order TRICOLOR-6.45 TRICOLOR-6.3 TRICOLOR-8.1 TRICOLOR-7.66.......exe, 00000000.00000002.292992821.0000000006872000.00000004.00000001.sdmp, new order TRICOLOR-6.45 TRICOLOR-6.3 TRICOLOR-8.1 TRICOLOR-7.66.......exe, 00000000.00000003.257256254.0000000005699000.00000004.00000001.sdmp, new order TRICOLOR-6.45 TRICOLOR-6.3 TRICOLOR-8.1 TRICOLOR-7.66.......exe, 00000000.00000003.257951856.000000000567A000.00000004.00000001.sdmp, new order TRICOLOR-6.45 TRICOLOR-6.3 TRICOLOR-8.1 TRICOLOR-7.66.......exe, 00000000.00000003.257160579.0000000005699000.00000004.00000001.sdmp, new order TRICOLOR-6.45 TRICOLOR-6.3 TRICOLOR-8.1 TRICOLOR-7.66.......exe, 00000000.00000003.257050058.000000000569D000.00000004.00000001.sdmp, new order TRICOLOR-6.45 TRICOLOR-6.3 TRICOLOR-8.1 TRICOLOR-7.66.......exe, 00000000.00000003.257213807.000000000567A000.00000004.00000001.sdmp, new order TRICOLOR-6.45 TRICOLOR-6.3 TRICOLOR-8.1 TRICOLOR-7.66.......exe, 00000000.00000003.257382975.000000000567A000.00000004.00000001.sdmp, new order TRICOLOR-6.45 TRICOLOR-6.3 TRICOLOR-8.1 TRICOLOR-7.66.......exe, 00000000.00000003.257294565.0000000005699000.00000004.00000001.sdmp, new order TRICOLOR-6.45 TRICOLOR-6.3 TRICOLOR-8.1 TRICOLOR-7.66.......exe, 00000000.00000003.257018883.0000000005699000.00000004.00000001.sdmpString found in binary or memory: http://www.galapagosdesign.com/staff/dennis.htm
                      Source: new order TRICOLOR-6.45 TRICOLOR-6.3 TRICOLOR-8.1 TRICOLOR-7.66.......exe, 00000000.00000002.292992821.0000000006872000.00000004.00000001.sdmpString found in binary or memory: http://www.goodfont.co.kr
                      Source: new order TRICOLOR-6.45 TRICOLOR-6.3 TRICOLOR-8.1 TRICOLOR-7.66.......exe, 00000000.00000003.250202745.000000000566D000.00000004.00000001.sdmpString found in binary or memory: http://www.jiyu-kobo.co.jp/
                      Source: new order TRICOLOR-6.45 TRICOLOR-6.3 TRICOLOR-8.1 TRICOLOR-7.66.......exe, 00000000.00000003.250729764.0000000005663000.00000004.00000001.sdmp, new order TRICOLOR-6.45 TRICOLOR-6.3 TRICOLOR-8.1 TRICOLOR-7.66.......exe, 00000000.00000003.250373934.0000000005663000.00000004.00000001.sdmp, new order TRICOLOR-6.45 TRICOLOR-6.3 TRICOLOR-8.1 TRICOLOR-7.66.......exe, 00000000.00000003.250906706.000000000566C000.00000004.00000001.sdmpString found in binary or memory: http://www.jiyu-kobo.co.jp/)
                      Source: new order TRICOLOR-6.45 TRICOLOR-6.3 TRICOLOR-8.1 TRICOLOR-7.66.......exe, 00000000.00000003.250336903.000000000566D000.00000004.00000001.sdmp, new order TRICOLOR-6.45 TRICOLOR-6.3 TRICOLOR-8.1 TRICOLOR-7.66.......exe, 00000000.00000003.250373934.0000000005663000.00000004.00000001.sdmpString found in binary or memory: http://www.jiyu-kobo.co.jp//
                      Source: new order TRICOLOR-6.45 TRICOLOR-6.3 TRICOLOR-8.1 TRICOLOR-7.66.......exe, 00000000.00000003.250729764.0000000005663000.00000004.00000001.sdmp, new order TRICOLOR-6.45 TRICOLOR-6.3 TRICOLOR-8.1 TRICOLOR-7.66.......exe, 00000000.00000003.249804536.0000000005663000.00000004.00000001.sdmpString found in binary or memory: http://www.jiyu-kobo.co.jp/OsI
                      Source: new order TRICOLOR-6.45 TRICOLOR-6.3 TRICOLOR-8.1 TRICOLOR-7.66.......exe, 00000000.00000003.250729764.0000000005663000.00000004.00000001.sdmp, new order TRICOLOR-6.45 TRICOLOR-6.3 TRICOLOR-8.1 TRICOLOR-7.66.......exe, 00000000.00000003.250336903.000000000566D000.00000004.00000001.sdmp, new order TRICOLOR-6.45 TRICOLOR-6.3 TRICOLOR-8.1 TRICOLOR-7.66.......exe, 00000000.00000003.250373934.0000000005663000.00000004.00000001.sdmp, new order TRICOLOR-6.45 TRICOLOR-6.3 TRICOLOR-8.1 TRICOLOR-7.66.......exe, 00000000.00000003.250906706.000000000566C000.00000004.00000001.sdmpString found in binary or memory: http://www.jiyu-kobo.co.jp/VsF
                      Source: new order TRICOLOR-6.45 TRICOLOR-6.3 TRICOLOR-8.1 TRICOLOR-7.66.......exe, 00000000.00000003.250906706.000000000566C000.00000004.00000001.sdmpString found in binary or memory: http://www.jiyu-kobo.co.jp/Y0y
                      Source: new order TRICOLOR-6.45 TRICOLOR-6.3 TRICOLOR-8.1 TRICOLOR-7.66.......exe, 00000000.00000003.250202745.000000000566D000.00000004.00000001.sdmpString found in binary or memory: http://www.jiyu-kobo.co.jp/a
                      Source: new order TRICOLOR-6.45 TRICOLOR-6.3 TRICOLOR-8.1 TRICOLOR-7.66.......exe, 00000000.00000003.250729764.0000000005663000.00000004.00000001.sdmp, new order TRICOLOR-6.45 TRICOLOR-6.3 TRICOLOR-8.1 TRICOLOR-7.66.......exe, 00000000.00000003.250906706.000000000566C000.00000004.00000001.sdmpString found in binary or memory: http://www.jiyu-kobo.co.jp/ch
                      Source: new order TRICOLOR-6.45 TRICOLOR-6.3 TRICOLOR-8.1 TRICOLOR-7.66.......exe, 00000000.00000003.250729764.0000000005663000.00000004.00000001.sdmp, new order TRICOLOR-6.45 TRICOLOR-6.3 TRICOLOR-8.1 TRICOLOR-7.66.......exe, 00000000.00000003.250336903.000000000566D000.00000004.00000001.sdmp, new order TRICOLOR-6.45 TRICOLOR-6.3 TRICOLOR-8.1 TRICOLOR-7.66.......exe, 00000000.00000003.250373934.0000000005663000.00000004.00000001.sdmp, new order TRICOLOR-6.45 TRICOLOR-6.3 TRICOLOR-8.1 TRICOLOR-7.66.......exe, 00000000.00000003.250906706.000000000566C000.00000004.00000001.sdmp, new order TRICOLOR-6.45 TRICOLOR-6.3 TRICOLOR-8.1 TRICOLOR-7.66.......exe, 00000000.00000003.250202745.000000000566D000.00000004.00000001.sdmpString found in binary or memory: http://www.jiyu-kobo.co.jp/jp/
                      Source: new order TRICOLOR-6.45 TRICOLOR-6.3 TRICOLOR-8.1 TRICOLOR-7.66.......exe, 00000000.00000003.250906706.000000000566C000.00000004.00000001.sdmpString found in binary or memory: http://www.jiyu-kobo.co.jp/jp/OsI
                      Source: new order TRICOLOR-6.45 TRICOLOR-6.3 TRICOLOR-8.1 TRICOLOR-7.66.......exe, 00000000.00000003.250729764.0000000005663000.00000004.00000001.sdmp, new order TRICOLOR-6.45 TRICOLOR-6.3 TRICOLOR-8.1 TRICOLOR-7.66.......exe, 00000000.00000003.250906706.000000000566C000.00000004.00000001.sdmpString found in binary or memory: http://www.jiyu-kobo.co.jp/ks
                      Source: new order TRICOLOR-6.45 TRICOLOR-6.3 TRICOLOR-8.1 TRICOLOR-7.66.......exe, 00000000.00000003.250729764.0000000005663000.00000004.00000001.sdmp, new order TRICOLOR-6.45 TRICOLOR-6.3 TRICOLOR-8.1 TRICOLOR-7.66.......exe, 00000000.00000003.250373934.0000000005663000.00000004.00000001.sdmp, new order TRICOLOR-6.45 TRICOLOR-6.3 TRICOLOR-8.1 TRICOLOR-7.66.......exe, 00000000.00000003.250906706.000000000566C000.00000004.00000001.sdmpString found in binary or memory: http://www.jiyu-kobo.co.jp/ms
                      Source: new order TRICOLOR-6.45 TRICOLOR-6.3 TRICOLOR-8.1 TRICOLOR-7.66.......exe, 00000000.00000003.250729764.0000000005663000.00000004.00000001.sdmp, new order TRICOLOR-6.45 TRICOLOR-6.3 TRICOLOR-8.1 TRICOLOR-7.66.......exe, 00000000.00000003.250373934.0000000005663000.00000004.00000001.sdmp, new order TRICOLOR-6.45 TRICOLOR-6.3 TRICOLOR-8.1 TRICOLOR-7.66.......exe, 00000000.00000003.250906706.000000000566C000.00000004.00000001.sdmpString found in binary or memory: http://www.jiyu-kobo.co.jp/ys;
                      Source: new order TRICOLOR-6.45 TRICOLOR-6.3 TRICOLOR-8.1 TRICOLOR-7.66.......exe, 00000000.00000002.292992821.0000000006872000.00000004.00000001.sdmpString found in binary or memory: http://www.sajatypeworks.com
                      Source: new order TRICOLOR-6.45 TRICOLOR-6.3 TRICOLOR-8.1 TRICOLOR-7.66.......exe, 00000000.00000002.292992821.0000000006872000.00000004.00000001.sdmpString found in binary or memory: http://www.sakkal.com
                      Source: new order TRICOLOR-6.45 TRICOLOR-6.3 TRICOLOR-8.1 TRICOLOR-7.66.......exe, 00000000.00000002.292992821.0000000006872000.00000004.00000001.sdmpString found in binary or memory: http://www.sandoll.co.kr
                      Source: new order TRICOLOR-6.45 TRICOLOR-6.3 TRICOLOR-8.1 TRICOLOR-7.66.......exe, 00000000.00000002.292992821.0000000006872000.00000004.00000001.sdmp, new order TRICOLOR-6.45 TRICOLOR-6.3 TRICOLOR-8.1 TRICOLOR-7.66.......exe, 00000000.00000003.248682275.000000000566E000.00000004.00000001.sdmp, new order TRICOLOR-6.45 TRICOLOR-6.3 TRICOLOR-8.1 TRICOLOR-7.66.......exe, 00000000.00000003.248549588.000000000569A000.00000004.00000001.sdmpString found in binary or memory: http://www.tiro.com
                      Source: new order TRICOLOR-6.45 TRICOLOR-6.3 TRICOLOR-8.1 TRICOLOR-7.66.......exe, 00000000.00000003.248499503.0000000005699000.00000004.00000001.sdmpString found in binary or memory: http://www.tiro.comD
                      Source: new order TRICOLOR-6.45 TRICOLOR-6.3 TRICOLOR-8.1 TRICOLOR-7.66.......exe, 00000000.00000002.292992821.0000000006872000.00000004.00000001.sdmpString found in binary or memory: http://www.typography.netD
                      Source: new order TRICOLOR-6.45 TRICOLOR-6.3 TRICOLOR-8.1 TRICOLOR-7.66.......exe, 00000000.00000003.255093562.000000000566E000.00000004.00000001.sdmpString found in binary or memory: http://www.urwpp.de
                      Source: new order TRICOLOR-6.45 TRICOLOR-6.3 TRICOLOR-8.1 TRICOLOR-7.66.......exe, 00000000.00000003.255093562.000000000566E000.00000004.00000001.sdmpString found in binary or memory: http://www.urwpp.de.T
                      Source: new order TRICOLOR-6.45 TRICOLOR-6.3 TRICOLOR-8.1 TRICOLOR-7.66.......exe, 00000000.00000002.292992821.0000000006872000.00000004.00000001.sdmpString found in binary or memory: http://www.urwpp.deDPlease
                      Source: new order TRICOLOR-6.45 TRICOLOR-6.3 TRICOLOR-8.1 TRICOLOR-7.66.......exe, 00000000.00000003.255093562.000000000566E000.00000004.00000001.sdmpString found in binary or memory: http://www.urwpp.deF
                      Source: new order TRICOLOR-6.45 TRICOLOR-6.3 TRICOLOR-8.1 TRICOLOR-7.66.......exe, 00000000.00000003.255093562.000000000566E000.00000004.00000001.sdmpString found in binary or memory: http://www.urwpp.demM
                      Source: new order TRICOLOR-6.45 TRICOLOR-6.3 TRICOLOR-8.1 TRICOLOR-7.66.......exe, 00000000.00000002.292992821.0000000006872000.00000004.00000001.sdmpString found in binary or memory: http://www.zhongyicts.com.cn
                      Source: new order TRICOLOR-6.45 TRICOLOR-6.3 TRICOLOR-8.1 TRICOLOR-7.66.......exe, 00000005.00000002.523008375.0000000002DB1000.00000004.00000001.sdmpString found in binary or memory: https://gaOQV1SxHxPSyzn.com
                      Source: new order TRICOLOR-6.45 TRICOLOR-6.3 TRICOLOR-8.1 TRICOLOR-7.66.......exe, 00000000.00000002.290045970.0000000003769000.00000004.00000001.sdmp, new order TRICOLOR-6.45 TRICOLOR-6.3 TRICOLOR-8.1 TRICOLOR-7.66.......exe, 00000005.00000000.282084634.0000000000402000.00000040.00000001.sdmp, new order TRICOLOR-6.45 TRICOLOR-6.3 TRICOLOR-8.1 TRICOLOR-7.66.......exe, 00000005.00000000.283151659.0000000000402000.00000040.00000001.sdmpString found in binary or memory: https://www.theonionrouter.com/dist.torproject.org/torbrowser/9.5.3/tor-win32-0.4.3.6.zip
                      Source: new order TRICOLOR-6.45 TRICOLOR-6.3 TRICOLOR-8.1 TRICOLOR-7.66.......exe, 00000005.00000002.523008375.0000000002DB1000.00000004.00000001.sdmpString found in binary or memory: https://www.theonionrouter.com/dist.torproject.org/torbrowser/9.5.3/tor-win32-0.4.3.6.zip%tordir%%ha
                      Source: unknownDNS traffic detected: queries for: mail.kyowasecurity.com.sg

                      System Summary:

                      barindex
                      Initial sample is a PE file and has a suspicious nameShow sources
                      Source: initial sampleStatic PE information: Filename: new order TRICOLOR-6.45 TRICOLOR-6.3 TRICOLOR-8.1 TRICOLOR-7.66.......exe
                      .NET source code contains very large array initializationsShow sources
                      Source: 5.0.new order TRICOLOR-6.45 TRICOLOR-6.3 TRICOLOR-8.1 TRICOLOR-7.66.......exe.400000.4.unpack, u003cPrivateImplementationDetailsu003eu007b9182023Bu002d9602u002d4B7Eu002d88F7u002d3D12A60DF8AAu007d/u00323823707u002d2712u002d4FEEu002d9E00u002dE6693C4B0FA0.csLarge array initialization: .cctor: array initializer size 11950
                      Source: 5.0.new order TRICOLOR-6.45 TRICOLOR-6.3 TRICOLOR-8.1 TRICOLOR-7.66.......exe.400000.12.unpack, u003cPrivateImplementationDetailsu003eu007b9182023Bu002d9602u002d4B7Eu002d88F7u002d3D12A60DF8AAu007d/u00323823707u002d2712u002d4FEEu002d9E00u002dE6693C4B0FA0.csLarge array initialization: .cctor: array initializer size 11950
                      Source: 5.2.new order TRICOLOR-6.45 TRICOLOR-6.3 TRICOLOR-8.1 TRICOLOR-7.66.......exe.400000.0.unpack, u003cPrivateImplementationDetailsu003eu007b9182023Bu002d9602u002d4B7Eu002d88F7u002d3D12A60DF8AAu007d/u00323823707u002d2712u002d4FEEu002d9E00u002dE6693C4B0FA0.csLarge array initialization: .cctor: array initializer size 11950
                      Source: 5.0.new order TRICOLOR-6.45 TRICOLOR-6.3 TRICOLOR-8.1 TRICOLOR-7.66.......exe.400000.10.unpack, u003cPrivateImplementationDetailsu003eu007b9182023Bu002d9602u002d4B7Eu002d88F7u002d3D12A60DF8AAu007d/u00323823707u002d2712u002d4FEEu002d9E00u002dE6693C4B0FA0.csLarge array initialization: .cctor: array initializer size 11950
                      Source: 5.0.new order TRICOLOR-6.45 TRICOLOR-6.3 TRICOLOR-8.1 TRICOLOR-7.66.......exe.400000.8.unpack, u003cPrivateImplementationDetailsu003eu007b9182023Bu002d9602u002d4B7Eu002d88F7u002d3D12A60DF8AAu007d/u00323823707u002d2712u002d4FEEu002d9E00u002dE6693C4B0FA0.csLarge array initialization: .cctor: array initializer size 11950
                      Source: new order TRICOLOR-6.45 TRICOLOR-6.3 TRICOLOR-8.1 TRICOLOR-7.66.......exeStatic PE information: 32BIT_MACHINE, EXECUTABLE_IMAGE
                      Source: C:\Users\user\Desktop\new order TRICOLOR-6.45 TRICOLOR-6.3 TRICOLOR-8.1 TRICOLOR-7.66.......exeCode function: 0_2_025598E80_2_025598E8
                      Source: C:\Users\user\Desktop\new order TRICOLOR-6.45 TRICOLOR-6.3 TRICOLOR-8.1 TRICOLOR-7.66.......exeCode function: 0_2_025597900_2_02559790
                      Source: C:\Users\user\Desktop\new order TRICOLOR-6.45 TRICOLOR-6.3 TRICOLOR-8.1 TRICOLOR-7.66.......exeCode function: 0_2_07083F400_2_07083F40
                      Source: C:\Users\user\Desktop\new order TRICOLOR-6.45 TRICOLOR-6.3 TRICOLOR-8.1 TRICOLOR-7.66.......exeCode function: 0_2_07082D000_2_07082D00
                      Source: C:\Users\user\Desktop\new order TRICOLOR-6.45 TRICOLOR-6.3 TRICOLOR-8.1 TRICOLOR-7.66.......exeCode function: 0_2_070855700_2_07085570
                      Source: C:\Users\user\Desktop\new order TRICOLOR-6.45 TRICOLOR-6.3 TRICOLOR-8.1 TRICOLOR-7.66.......exeCode function: 0_2_07088C180_2_07088C18
                      Source: C:\Users\user\Desktop\new order TRICOLOR-6.45 TRICOLOR-6.3 TRICOLOR-8.1 TRICOLOR-7.66.......exeCode function: 0_2_0708D4580_2_0708D458
                      Source: C:\Users\user\Desktop\new order TRICOLOR-6.45 TRICOLOR-6.3 TRICOLOR-8.1 TRICOLOR-7.66.......exeCode function: 0_2_070864A00_2_070864A0
                      Source: C:\Users\user\Desktop\new order TRICOLOR-6.45 TRICOLOR-6.3 TRICOLOR-8.1 TRICOLOR-7.66.......exeCode function: 0_2_07084B800_2_07084B80
                      Source: C:\Users\user\Desktop\new order TRICOLOR-6.45 TRICOLOR-6.3 TRICOLOR-8.1 TRICOLOR-7.66.......exeCode function: 0_2_0708D9280_2_0708D928
                      Source: C:\Users\user\Desktop\new order TRICOLOR-6.45 TRICOLOR-6.3 TRICOLOR-8.1 TRICOLOR-7.66.......exeCode function: 0_2_070800400_2_07080040
                      Source: C:\Users\user\Desktop\new order TRICOLOR-6.45 TRICOLOR-6.3 TRICOLOR-8.1 TRICOLOR-7.66.......exeCode function: 0_2_07087F400_2_07087F40
                      Source: C:\Users\user\Desktop\new order TRICOLOR-6.45 TRICOLOR-6.3 TRICOLOR-8.1 TRICOLOR-7.66.......exeCode function: 0_2_07087F500_2_07087F50
                      Source: C:\Users\user\Desktop\new order TRICOLOR-6.45 TRICOLOR-6.3 TRICOLOR-8.1 TRICOLOR-7.66.......exeCode function: 0_2_070897B10_2_070897B1
                      Source: C:\Users\user\Desktop\new order TRICOLOR-6.45 TRICOLOR-6.3 TRICOLOR-8.1 TRICOLOR-7.66.......exeCode function: 0_2_070897D80_2_070897D8
                      Source: C:\Users\user\Desktop\new order TRICOLOR-6.45 TRICOLOR-6.3 TRICOLOR-8.1 TRICOLOR-7.66.......exeCode function: 0_2_0708DE500_2_0708DE50
                      Source: C:\Users\user\Desktop\new order TRICOLOR-6.45 TRICOLOR-6.3 TRICOLOR-8.1 TRICOLOR-7.66.......exeCode function: 0_2_07083E9B0_2_07083E9B
                      Source: C:\Users\user\Desktop\new order TRICOLOR-6.45 TRICOLOR-6.3 TRICOLOR-8.1 TRICOLOR-7.66.......exeCode function: 0_2_07083EF10_2_07083EF1
                      Source: C:\Users\user\Desktop\new order TRICOLOR-6.45 TRICOLOR-6.3 TRICOLOR-8.1 TRICOLOR-7.66.......exeCode function: 0_2_070855600_2_07085560
                      Source: C:\Users\user\Desktop\new order TRICOLOR-6.45 TRICOLOR-6.3 TRICOLOR-8.1 TRICOLOR-7.66.......exeCode function: 0_2_0708C5B00_2_0708C5B0
                      Source: C:\Users\user\Desktop\new order TRICOLOR-6.45 TRICOLOR-6.3 TRICOLOR-8.1 TRICOLOR-7.66.......exeCode function: 0_2_070885C80_2_070885C8
                      Source: C:\Users\user\Desktop\new order TRICOLOR-6.45 TRICOLOR-6.3 TRICOLOR-8.1 TRICOLOR-7.66.......exeCode function: 0_2_070885D80_2_070885D8
                      Source: C:\Users\user\Desktop\new order TRICOLOR-6.45 TRICOLOR-6.3 TRICOLOR-8.1 TRICOLOR-7.66.......exeCode function: 0_2_07088C080_2_07088C08
                      Source: C:\Users\user\Desktop\new order TRICOLOR-6.45 TRICOLOR-6.3 TRICOLOR-8.1 TRICOLOR-7.66.......exeCode function: 0_2_070833300_2_07083330
                      Source: C:\Users\user\Desktop\new order TRICOLOR-6.45 TRICOLOR-6.3 TRICOLOR-8.1 TRICOLOR-7.66.......exeCode function: 0_2_070833400_2_07083340
                      Source: C:\Users\user\Desktop\new order TRICOLOR-6.45 TRICOLOR-6.3 TRICOLOR-8.1 TRICOLOR-7.66.......exeCode function: 0_2_0708CB680_2_0708CB68
                      Source: C:\Users\user\Desktop\new order TRICOLOR-6.45 TRICOLOR-6.3 TRICOLOR-8.1 TRICOLOR-7.66.......exeCode function: 0_2_07084B700_2_07084B70
                      Source: C:\Users\user\Desktop\new order TRICOLOR-6.45 TRICOLOR-6.3 TRICOLOR-8.1 TRICOLOR-7.66.......exeCode function: 0_2_070863A00_2_070863A0
                      Source: C:\Users\user\Desktop\new order TRICOLOR-6.45 TRICOLOR-6.3 TRICOLOR-8.1 TRICOLOR-7.66.......exeCode function: 0_2_070873A10_2_070873A1
                      Source: C:\Users\user\Desktop\new order TRICOLOR-6.45 TRICOLOR-6.3 TRICOLOR-8.1 TRICOLOR-7.66.......exeCode function: 0_2_070873B00_2_070873B0
                      Source: C:\Users\user\Desktop\new order TRICOLOR-6.45 TRICOLOR-6.3 TRICOLOR-8.1 TRICOLOR-7.66.......exeCode function: 0_2_070863FB0_2_070863FB
                      Source: C:\Users\user\Desktop\new order TRICOLOR-6.45 TRICOLOR-6.3 TRICOLOR-8.1 TRICOLOR-7.66.......exeCode function: 0_2_07088A400_2_07088A40
                      Source: C:\Users\user\Desktop\new order TRICOLOR-6.45 TRICOLOR-6.3 TRICOLOR-8.1 TRICOLOR-7.66.......exeCode function: 0_2_070882580_2_07088258
                      Source: C:\Users\user\Desktop\new order TRICOLOR-6.45 TRICOLOR-6.3 TRICOLOR-8.1 TRICOLOR-7.66.......exeCode function: 0_2_07088A500_2_07088A50
                      Source: C:\Users\user\Desktop\new order TRICOLOR-6.45 TRICOLOR-6.3 TRICOLOR-8.1 TRICOLOR-7.66.......exeCode function: 0_2_070882680_2_07088268
                      Source: C:\Users\user\Desktop\new order TRICOLOR-6.45 TRICOLOR-6.3 TRICOLOR-8.1 TRICOLOR-7.66.......exeCode function: 0_2_0708F1180_2_0708F118
                      Source: C:\Users\user\Desktop\new order TRICOLOR-6.45 TRICOLOR-6.3 TRICOLOR-8.1 TRICOLOR-7.66.......exeCode function: 0_2_070888000_2_07088800
                      Source: C:\Users\user\Desktop\new order TRICOLOR-6.45 TRICOLOR-6.3 TRICOLOR-8.1 TRICOLOR-7.66.......exeCode function: 0_2_070888100_2_07088810
                      Source: C:\Users\user\Desktop\new order TRICOLOR-6.45 TRICOLOR-6.3 TRICOLOR-8.1 TRICOLOR-7.66.......exeCode function: 0_2_0CF100400_2_0CF10040
                      Source: C:\Users\user\Desktop\new order TRICOLOR-6.45 TRICOLOR-6.3 TRICOLOR-8.1 TRICOLOR-7.66.......exeCode function: 0_2_0CF1210A0_2_0CF1210A
                      Source: C:\Users\user\Desktop\new order TRICOLOR-6.45 TRICOLOR-6.3 TRICOLOR-8.1 TRICOLOR-7.66.......exeCode function: 0_2_0CF144800_2_0CF14480
                      Source: C:\Users\user\Desktop\new order TRICOLOR-6.45 TRICOLOR-6.3 TRICOLOR-8.1 TRICOLOR-7.66.......exeCode function: 0_2_0CF100060_2_0CF10006
                      Source: C:\Users\user\Desktop\new order TRICOLOR-6.45 TRICOLOR-6.3 TRICOLOR-8.1 TRICOLOR-7.66.......exeCode function: 0_2_0CF122AA0_2_0CF122AA
                      Source: C:\Users\user\Desktop\new order TRICOLOR-6.45 TRICOLOR-6.3 TRICOLOR-8.1 TRICOLOR-7.66.......exeCode function: 5_2_01122D505_2_01122D50
                      Source: C:\Users\user\Desktop\new order TRICOLOR-6.45 TRICOLOR-6.3 TRICOLOR-8.1 TRICOLOR-7.66.......exeCode function: 5_2_0112DFD85_2_0112DFD8
                      Source: C:\Users\user\Desktop\new order TRICOLOR-6.45 TRICOLOR-6.3 TRICOLOR-8.1 TRICOLOR-7.66.......exeCode function: 5_2_01121FF05_2_01121FF0
                      Source: C:\Users\user\Desktop\new order TRICOLOR-6.45 TRICOLOR-6.3 TRICOLOR-8.1 TRICOLOR-7.66.......exeCode function: 5_2_011226185_2_01122618
                      Source: C:\Users\user\Desktop\new order TRICOLOR-6.45 TRICOLOR-6.3 TRICOLOR-8.1 TRICOLOR-7.66.......exeCode function: 5_2_01129DB85_2_01129DB8
                      Source: C:\Users\user\Desktop\new order TRICOLOR-6.45 TRICOLOR-6.3 TRICOLOR-8.1 TRICOLOR-7.66.......exeCode function: 5_2_011EC5105_2_011EC510
                      Source: C:\Users\user\Desktop\new order TRICOLOR-6.45 TRICOLOR-6.3 TRICOLOR-8.1 TRICOLOR-7.66.......exeCode function: 5_2_011E55585_2_011E5558
                      Source: C:\Users\user\Desktop\new order TRICOLOR-6.45 TRICOLOR-6.3 TRICOLOR-8.1 TRICOLOR-7.66.......exeCode function: 5_2_011E19705_2_011E1970
                      Source: C:\Users\user\Desktop\new order TRICOLOR-6.45 TRICOLOR-6.3 TRICOLOR-8.1 TRICOLOR-7.66.......exeCode function: 5_2_011E00405_2_011E0040
                      Source: C:\Users\user\Desktop\new order TRICOLOR-6.45 TRICOLOR-6.3 TRICOLOR-8.1 TRICOLOR-7.66.......exeCode function: 5_2_011E78F85_2_011E78F8
                      Source: C:\Users\user\Desktop\new order TRICOLOR-6.45 TRICOLOR-6.3 TRICOLOR-8.1 TRICOLOR-7.66.......exeCode function: 5_2_011E40E85_2_011E40E8
                      Source: C:\Users\user\Desktop\new order TRICOLOR-6.45 TRICOLOR-6.3 TRICOLOR-8.1 TRICOLOR-7.66.......exeCode function: 5_2_011E00065_2_011E0006
                      Source: C:\Users\user\Desktop\new order TRICOLOR-6.45 TRICOLOR-6.3 TRICOLOR-8.1 TRICOLOR-7.66.......exeCode function: 5_2_011E4E505_2_011E4E50
                      Source: C:\Users\user\Desktop\new order TRICOLOR-6.45 TRICOLOR-6.3 TRICOLOR-8.1 TRICOLOR-7.66.......exeCode function: 5_2_011E82F85_2_011E82F8
                      Source: C:\Users\user\Desktop\new order TRICOLOR-6.45 TRICOLOR-6.3 TRICOLOR-8.1 TRICOLOR-7.66.......exeCode function: 5_2_013E48005_2_013E4800
                      Source: C:\Users\user\Desktop\new order TRICOLOR-6.45 TRICOLOR-6.3 TRICOLOR-8.1 TRICOLOR-7.66.......exeCode function: 5_2_013E3D2C5_2_013E3D2C
                      Source: C:\Users\user\Desktop\new order TRICOLOR-6.45 TRICOLOR-6.3 TRICOLOR-8.1 TRICOLOR-7.66.......exeCode function: 5_2_013E3EB85_2_013E3EB8
                      Source: C:\Users\user\Desktop\new order TRICOLOR-6.45 TRICOLOR-6.3 TRICOLOR-8.1 TRICOLOR-7.66.......exeCode function: 5_2_013E47705_2_013E4770
                      Source: C:\Users\user\Desktop\new order TRICOLOR-6.45 TRICOLOR-6.3 TRICOLOR-8.1 TRICOLOR-7.66.......exeCode function: 5_2_013E47505_2_013E4750
                      Source: C:\Users\user\Desktop\new order TRICOLOR-6.45 TRICOLOR-6.3 TRICOLOR-8.1 TRICOLOR-7.66.......exeCode function: 5_2_013E47F35_2_013E47F3
                      Source: C:\Users\user\Desktop\new order TRICOLOR-6.45 TRICOLOR-6.3 TRICOLOR-8.1 TRICOLOR-7.66.......exeCode function: 5_2_013E54F05_2_013E54F0
                      Source: C:\Users\user\Desktop\new order TRICOLOR-6.45 TRICOLOR-6.3 TRICOLOR-8.1 TRICOLOR-7.66.......exeCode function: 5_2_013ED8005_2_013ED800
                      Source: new order TRICOLOR-6.45 TRICOLOR-6.3 TRICOLOR-8.1 TRICOLOR-7.66.......exe, 00000000.00000002.290045970.0000000003769000.00000004.00000001.sdmpBinary or memory string: OriginalFilenameMajorRevision.exe< vs new order TRICOLOR-6.45 TRICOLOR-6.3 TRICOLOR-8.1 TRICOLOR-7.66.......exe
                      Source: new order TRICOLOR-6.45 TRICOLOR-6.3 TRICOLOR-8.1 TRICOLOR-7.66.......exe, 00000000.00000002.290045970.0000000003769000.00000004.00000001.sdmpBinary or memory string: OriginalFilenameuhljaIlIyVxZXxXUzeXkqULlxd.exe4 vs new order TRICOLOR-6.45 TRICOLOR-6.3 TRICOLOR-8.1 TRICOLOR-7.66.......exe
                      Source: new order TRICOLOR-6.45 TRICOLOR-6.3 TRICOLOR-8.1 TRICOLOR-7.66.......exe, 00000000.00000002.290045970.0000000003769000.00000004.00000001.sdmpBinary or memory string: OriginalFilenameVHbIB.exe8 vs new order TRICOLOR-6.45 TRICOLOR-6.3 TRICOLOR-8.1 TRICOLOR-7.66.......exe
                      Source: new order TRICOLOR-6.45 TRICOLOR-6.3 TRICOLOR-8.1 TRICOLOR-7.66.......exe, 00000000.00000002.287974260.0000000002761000.00000004.00000001.sdmpBinary or memory string: OriginalFilenameBunifu.UI.dll4 vs new order TRICOLOR-6.45 TRICOLOR-6.3 TRICOLOR-8.1 TRICOLOR-7.66.......exe
                      Source: new order TRICOLOR-6.45 TRICOLOR-6.3 TRICOLOR-8.1 TRICOLOR-7.66.......exe, 00000000.00000002.287974260.0000000002761000.00000004.00000001.sdmpBinary or memory string: OriginalFilenameuhljaIlIyVxZXxXUzeXkqULlxd.exe4 vs new order TRICOLOR-6.45 TRICOLOR-6.3 TRICOLOR-8.1 TRICOLOR-7.66.......exe
                      Source: new order TRICOLOR-6.45 TRICOLOR-6.3 TRICOLOR-8.1 TRICOLOR-7.66.......exe, 00000000.00000002.287974260.0000000002761000.00000004.00000001.sdmpBinary or memory string: OriginalFilenameMajorRevision.exe< vs new order TRICOLOR-6.45 TRICOLOR-6.3 TRICOLOR-8.1 TRICOLOR-7.66.......exe
                      Source: new order TRICOLOR-6.45 TRICOLOR-6.3 TRICOLOR-8.1 TRICOLOR-7.66.......exe, 00000000.00000000.243922147.000000000030C000.00000002.00020000.sdmpBinary or memory string: OriginalFilenameVHbIB.exe8 vs new order TRICOLOR-6.45 TRICOLOR-6.3 TRICOLOR-8.1 TRICOLOR-7.66.......exe
                      Source: new order TRICOLOR-6.45 TRICOLOR-6.3 TRICOLOR-8.1 TRICOLOR-7.66.......exe, 00000000.00000002.293338597.0000000006F70000.00000004.00020000.sdmpBinary or memory string: OriginalFilenameMajorRevision.exe< vs new order TRICOLOR-6.45 TRICOLOR-6.3 TRICOLOR-8.1 TRICOLOR-7.66.......exe
                      Source: new order TRICOLOR-6.45 TRICOLOR-6.3 TRICOLOR-8.1 TRICOLOR-7.66.......exe, 00000005.00000002.518319405.0000000000ABC000.00000002.00020000.sdmpBinary or memory string: OriginalFilenameVHbIB.exe8 vs new order TRICOLOR-6.45 TRICOLOR-6.3 TRICOLOR-8.1 TRICOLOR-7.66.......exe
                      Source: new order TRICOLOR-6.45 TRICOLOR-6.3 TRICOLOR-8.1 TRICOLOR-7.66.......exe, 00000005.00000000.283151659.0000000000402000.00000040.00000001.sdmpBinary or memory string: OriginalFilenameuhljaIlIyVxZXxXUzeXkqULlxd.exe4 vs new order TRICOLOR-6.45 TRICOLOR-6.3 TRICOLOR-8.1 TRICOLOR-7.66.......exe
                      Source: new order TRICOLOR-6.45 TRICOLOR-6.3 TRICOLOR-8.1 TRICOLOR-7.66.......exeBinary or memory string: OriginalFilenameVHbIB.exe8 vs new order TRICOLOR-6.45 TRICOLOR-6.3 TRICOLOR-8.1 TRICOLOR-7.66.......exe
                      Source: new order TRICOLOR-6.45 TRICOLOR-6.3 TRICOLOR-8.1 TRICOLOR-7.66.......exeStatic PE information: Section: .text IMAGE_SCN_MEM_EXECUTE, IMAGE_SCN_CNT_CODE, IMAGE_SCN_MEM_READ
                      Source: aUkURZiJ.exe.0.drStatic PE information: Section: .text IMAGE_SCN_MEM_EXECUTE, IMAGE_SCN_CNT_CODE, IMAGE_SCN_MEM_READ
                      Source: new order TRICOLOR-6.45 TRICOLOR-6.3 TRICOLOR-8.1 TRICOLOR-7.66.......exeReversingLabs: Detection: 41%
                      Source: C:\Users\user\Desktop\new order TRICOLOR-6.45 TRICOLOR-6.3 TRICOLOR-8.1 TRICOLOR-7.66.......exeFile read: C:\Users\user\Desktop\new order TRICOLOR-6.45 TRICOLOR-6.3 TRICOLOR-8.1 TRICOLOR-7.66.......exeJump to behavior
                      Source: new order TRICOLOR-6.45 TRICOLOR-6.3 TRICOLOR-8.1 TRICOLOR-7.66.......exeStatic PE information: Section: .text IMAGE_SCN_MEM_EXECUTE, IMAGE_SCN_CNT_CODE, IMAGE_SCN_MEM_READ
                      Source: C:\Users\user\Desktop\new order TRICOLOR-6.45 TRICOLOR-6.3 TRICOLOR-8.1 TRICOLOR-7.66.......exeKey opened: HKEY_CURRENT_USER\Software\Policies\Microsoft\Windows\Safer\CodeIdentifiersJump to behavior
                      Source: unknownProcess created: C:\Users\user\Desktop\new order TRICOLOR-6.45 TRICOLOR-6.3 TRICOLOR-8.1 TRICOLOR-7.66.......exe "C:\Users\user\Desktop\new order TRICOLOR-6.45 TRICOLOR-6.3 TRICOLOR-8.1 TRICOLOR-7.66.......exe"
                      Source: C:\Users\user\Desktop\new order TRICOLOR-6.45 TRICOLOR-6.3 TRICOLOR-8.1 TRICOLOR-7.66.......exeProcess created: C:\Windows\SysWOW64\schtasks.exe C:\Windows\System32\schtasks.exe" /Create /TN "Updates\aUkURZiJ" /XML "C:\Users\user\AppData\Local\Temp\tmp8923.tmp
                      Source: C:\Windows\SysWOW64\schtasks.exeProcess created: C:\Windows\System32\conhost.exe C:\Windows\system32\conhost.exe 0xffffffff -ForceV1
                      Source: C:\Users\user\Desktop\new order TRICOLOR-6.45 TRICOLOR-6.3 TRICOLOR-8.1 TRICOLOR-7.66.......exeProcess created: C:\Users\user\Desktop\new order TRICOLOR-6.45 TRICOLOR-6.3 TRICOLOR-8.1 TRICOLOR-7.66.......exe {path}
                      Source: C:\Users\user\Desktop\new order TRICOLOR-6.45 TRICOLOR-6.3 TRICOLOR-8.1 TRICOLOR-7.66.......exeProcess created: C:\Windows\SysWOW64\schtasks.exe C:\Windows\System32\schtasks.exe" /Create /TN "Updates\aUkURZiJ" /XML "C:\Users\user\AppData\Local\Temp\tmp8923.tmpJump to behavior
                      Source: C:\Users\user\Desktop\new order TRICOLOR-6.45 TRICOLOR-6.3 TRICOLOR-8.1 TRICOLOR-7.66.......exeProcess created: C:\Users\user\Desktop\new order TRICOLOR-6.45 TRICOLOR-6.3 TRICOLOR-8.1 TRICOLOR-7.66.......exe {path}Jump to behavior
                      Source: C:\Users\user\Desktop\new order TRICOLOR-6.45 TRICOLOR-6.3 TRICOLOR-8.1 TRICOLOR-7.66.......exeKey value queried: HKEY_LOCAL_MACHINE\SOFTWARE\Classes\WOW6432Node\CLSID\{95E15D0A-66E6-93D9-C53C-76E6219D3341}\InProcServer32Jump to behavior
                      Source: C:\Users\user\Desktop\new order TRICOLOR-6.45 TRICOLOR-6.3 TRICOLOR-8.1 TRICOLOR-7.66.......exeWMI Queries: IWbemServices::CreateInstanceEnum - root\cimv2 : Win32_Processor
                      Source: C:\Users\user\Desktop\new order TRICOLOR-6.45 TRICOLOR-6.3 TRICOLOR-8.1 TRICOLOR-7.66.......exeWMI Queries: IWbemServices::ExecQuery - root\cimv2 : SELECT * FROM Win32_Processor
                      Source: C:\Users\user\Desktop\new order TRICOLOR-6.45 TRICOLOR-6.3 TRICOLOR-8.1 TRICOLOR-7.66.......exeFile created: C:\Users\user\AppData\Roaming\aUkURZiJ.exeJump to behavior
                      Source: C:\Users\user\Desktop\new order TRICOLOR-6.45 TRICOLOR-6.3 TRICOLOR-8.1 TRICOLOR-7.66.......exeFile created: C:\Users\user\AppData\Local\Temp\tmp8923.tmpJump to behavior
                      Source: classification engineClassification label: mal100.troj.spyw.evad.winEXE@6/3@1/1
                      Source: C:\Users\user\Desktop\new order TRICOLOR-6.45 TRICOLOR-6.3 TRICOLOR-8.1 TRICOLOR-7.66.......exeFile read: C:\Users\user\Desktop\desktop.iniJump to behavior
                      Source: C:\Users\user\Desktop\new order TRICOLOR-6.45 TRICOLOR-6.3 TRICOLOR-8.1 TRICOLOR-7.66.......exeSection loaded: C:\Windows\assembly\NativeImages_v4.0.30319_32\mscorlib\a152fe02a317a77aeee36903305e8ba6\mscorlib.ni.dllJump to behavior
                      Source: C:\Users\user\Desktop\new order TRICOLOR-6.45 TRICOLOR-6.3 TRICOLOR-8.1 TRICOLOR-7.66.......exeSection loaded: C:\Windows\assembly\NativeImages_v4.0.30319_32\mscorlib\a152fe02a317a77aeee36903305e8ba6\mscorlib.ni.dllJump to behavior
                      Source: C:\Windows\System32\conhost.exeMutant created: \Sessions\1\BaseNamedObjects\Local\SM0:3336:120:WilError_01
                      Source: C:\Users\user\Desktop\new order TRICOLOR-6.45 TRICOLOR-6.3 TRICOLOR-8.1 TRICOLOR-7.66.......exeMutant created: \Sessions\1\BaseNamedObjects\qhBPaQtUSZKpqqGhtcCkqEcA
                      Source: 5.0.new order TRICOLOR-6.45 TRICOLOR-6.3 TRICOLOR-8.1 TRICOLOR-7.66.......exe.400000.4.unpack, A/b2.csCryptographic APIs: 'TransformFinalBlock', 'CreateDecryptor'
                      Source: 5.0.new order TRICOLOR-6.45 TRICOLOR-6.3 TRICOLOR-8.1 TRICOLOR-7.66.......exe.400000.4.unpack, A/b2.csCryptographic APIs: 'TransformFinalBlock', 'CreateDecryptor'
                      Source: 5.0.new order TRICOLOR-6.45 TRICOLOR-6.3 TRICOLOR-8.1 TRICOLOR-7.66.......exe.400000.12.unpack, A/b2.csCryptographic APIs: 'TransformFinalBlock', 'CreateDecryptor'
                      Source: 5.0.new order TRICOLOR-6.45 TRICOLOR-6.3 TRICOLOR-8.1 TRICOLOR-7.66.......exe.400000.12.unpack, A/b2.csCryptographic APIs: 'TransformFinalBlock', 'CreateDecryptor'
                      Source: 5.2.new order TRICOLOR-6.45 TRICOLOR-6.3 TRICOLOR-8.1 TRICOLOR-7.66.......exe.400000.0.unpack, A/b2.csCryptographic APIs: 'TransformFinalBlock', 'CreateDecryptor'
                      Source: 5.2.new order TRICOLOR-6.45 TRICOLOR-6.3 TRICOLOR-8.1 TRICOLOR-7.66.......exe.400000.0.unpack, A/b2.csCryptographic APIs: 'TransformFinalBlock', 'CreateDecryptor'
                      Source: C:\Users\user\Desktop\new order TRICOLOR-6.45 TRICOLOR-6.3 TRICOLOR-8.1 TRICOLOR-7.66.......exeFile read: C:\Windows\System32\drivers\etc\hostsJump to behavior
                      Source: C:\Users\user\Desktop\new order TRICOLOR-6.45 TRICOLOR-6.3 TRICOLOR-8.1 TRICOLOR-7.66.......exeFile read: C:\Windows\System32\drivers\etc\hostsJump to behavior
                      Source: C:\Users\user\Desktop\new order TRICOLOR-6.45 TRICOLOR-6.3 TRICOLOR-8.1 TRICOLOR-7.66.......exeFile opened: C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscorrc.dllJump to behavior
                      Source: C:\Users\user\Desktop\new order TRICOLOR-6.45 TRICOLOR-6.3 TRICOLOR-8.1 TRICOLOR-7.66.......exeKey opened: HKEY_CURRENT_USER\Software\Microsoft\Office\15.0\Outlook\Profiles\Outlook\9375CFF0413111d3B88A00104B2A6676Jump to behavior
                      Source: new order TRICOLOR-6.45 TRICOLOR-6.3 TRICOLOR-8.1 TRICOLOR-7.66.......exeStatic PE information: data directory type: IMAGE_DIRECTORY_ENTRY_COM_DESCRIPTOR
                      Source: new order TRICOLOR-6.45 TRICOLOR-6.3 TRICOLOR-8.1 TRICOLOR-7.66.......exeStatic PE information: NO_SEH, TERMINAL_SERVER_AWARE, DYNAMIC_BASE, NX_COMPAT
                      Source: C:\Users\user\Desktop\new order TRICOLOR-6.45 TRICOLOR-6.3 TRICOLOR-8.1 TRICOLOR-7.66.......exeCode function: 0_2_0028376A push ebp; retf 0_2_0028376B
                      Source: C:\Users\user\Desktop\new order TRICOLOR-6.45 TRICOLOR-6.3 TRICOLOR-8.1 TRICOLOR-7.66.......exeCode function: 5_2_00A3376A push ebp; retf 5_2_00A3376B
                      Source: C:\Users\user\Desktop\new order TRICOLOR-6.45 TRICOLOR-6.3 TRICOLOR-8.1 TRICOLOR-7.66.......exeCode function: 5_2_01127A37 push edi; retn 0000h5_2_01127A39
                      Source: C:\Users\user\Desktop\new order TRICOLOR-6.45 TRICOLOR-6.3 TRICOLOR-8.1 TRICOLOR-7.66.......exeCode function: 5_2_011EBA50 pushfd ; retf 5_2_011EBDB9
                      Source: C:\Users\user\Desktop\new order TRICOLOR-6.45 TRICOLOR-6.3 TRICOLOR-8.1 TRICOLOR-7.66.......exeCode function: 5_2_0138E333 push eax; ret 5_2_0138E349
                      Source: C:\Users\user\Desktop\new order TRICOLOR-6.45 TRICOLOR-6.3 TRICOLOR-8.1 TRICOLOR-7.66.......exeCode function: 5_2_0138D95C push eax; ret 5_2_0138D95D
                      Source: new order TRICOLOR-6.45 TRICOLOR-6.3 TRICOLOR-8.1 TRICOLOR-7.66.......exeStatic PE information: 0xAC6B97B1 [Wed Aug 31 16:45:37 2061 UTC]
                      Source: initial sampleStatic PE information: section name: .text entropy: 7.63105429026
                      Source: initial sampleStatic PE information: section name: .text entropy: 7.63105429026
                      Source: C:\Users\user\Desktop\new order TRICOLOR-6.45 TRICOLOR-6.3 TRICOLOR-8.1 TRICOLOR-7.66.......exeFile created: \new order tricolor-6.45 tricolor-6.3 tricolor-8.1 tricolor-7.66.......exe
                      Source: C:\Users\user\Desktop\new order TRICOLOR-6.45 TRICOLOR-6.3 TRICOLOR-8.1 TRICOLOR-7.66.......exeFile created: \new order tricolor-6.45 tricolor-6.3 tricolor-8.1 tricolor-7.66.......exe
                      Source: C:\Users\user\Desktop\new order TRICOLOR-6.45 TRICOLOR-6.3 TRICOLOR-8.1 TRICOLOR-7.66.......exeFile created: \new order tricolor-6.45 tricolor-6.3 tricolor-8.1 tricolor-7.66.......exeJump to behavior
                      Source: C:\Users\user\Desktop\new order TRICOLOR-6.45 TRICOLOR-6.3 TRICOLOR-8.1 TRICOLOR-7.66.......exeFile created: \new order tricolor-6.45 tricolor-6.3 tricolor-8.1 tricolor-7.66.......exeJump to behavior
                      Source: C:\Users\user\Desktop\new order TRICOLOR-6.45 TRICOLOR-6.3 TRICOLOR-8.1 TRICOLOR-7.66.......exeFile created: C:\Users\user\AppData\Roaming\aUkURZiJ.exeJump to dropped file

                      Boot Survival:

                      barindex
                      Uses schtasks.exe or at.exe to add and modify task schedulesShow sources
                      Source: C:\Users\user\Desktop\new order TRICOLOR-6.45 TRICOLOR-6.3 TRICOLOR-8.1 TRICOLOR-7.66.......exeProcess created: C:\Windows\SysWOW64\schtasks.exe C:\Windows\System32\schtasks.exe" /Create /TN "Updates\aUkURZiJ" /XML "C:\Users\user\AppData\Local\Temp\tmp8923.tmp