Windows Analysis Report Ziraat Bankasi Swift Mesaji.exe

Overview

General Information

Sample Name: Ziraat Bankasi Swift Mesaji.exe
Analysis ID: 553163
MD5: 161523651320083122d05dd374c87ec4
SHA1: df8fae3ff1125841de5aa2306de3501e8204919a
SHA256: f4d91c834da24d653fef9049355102bcb68be411280268af61ac8f59bce581db
Tags: AgentTeslaexegeoTURZiraatBank
Infos:

Most interesting Screenshot:

Detection

AgentTesla
Score: 100
Range: 0 - 100
Whitelisted: false
Confidence: 100%

Signatures

Found malware configuration
Multi AV Scanner detection for submitted file
Yara detected AgentTesla
Detected unpacking (creates a PE file in dynamic memory)
Tries to steal Mail credentials (via file / registry access)
Tries to harvest and steal ftp login credentials
Machine Learning detection for sample
Found evasive API chain (trying to detect sleep duration tampering with parallel thread)
Injects a PE file into a foreign processes
.NET source code contains very large array initializations
Queries sensitive network adapter information (via WMI, Win32_NetworkAdapter, often done to detect virtual machines)
Tries to harvest and steal browser information (history, passwords, etc)
Queries sensitive BIOS Information (via WMI, Win32_Bios & Win32_BaseBoard, often done to detect virtual machines)
Uses 32bit PE files
Queries the volume information (name, serial number etc) of a device
Antivirus or Machine Learning detection for unpacked file
Contains functionality to check if a debugger is running (IsDebuggerPresent)
May sleep (evasive loops) to hinder dynamic analysis
Contains functionality to shutdown / reboot the system
Uses code obfuscation techniques (call, push, ret)
Detected potential crypto function
Contains functionality to query CPU information (cpuid)
Sample execution stops while process was sleeping (likely an evasion)
Yara detected Credential Stealer
Contains functionality to call native functions
Contains functionality to dynamically determine API calls
Contains functionality which may be used to detect a debugger (GetProcessHeap)
Contains long sleeps (>= 3 min)
Enables debug privileges
Creates a DirectInput object (often for capturing keystrokes)
Found a high number of Window / User specific system calls (may be a loop to detect user behavior)
Sample file is different than original file name gathered from version info
Drops PE files
Contains functionality to read the PEB
Detected TCP or UDP traffic on non-standard ports
Uses SMTP (mail sending)
Queries sensitive processor information (via WMI, Win32_Processor, often done to detect virtual machines)
Monitors certain registry keys / values for changes (often done to protect autostart functionality)
Creates a process in suspended mode (likely to inject code)
Contains functionality to access loader functionality (e.g. LdrGetProcedureAddress)
Contains functionality for read data from the clipboard

Classification

AV Detection:

barindex
Found malware configuration
Source: 3.1.Ziraat Bankasi Swift Mesaji.exe.415058.1.unpack Malware Configuration Extractor: Agenttesla {"Exfil Mode": "SMTP", "Username": "fizikokimya@antimikrop.com.tr", "Password": "fiziko2016Kimya", "Host": "mail.antimikrop.com.tr"}
Multi AV Scanner detection for submitted file
Source: Ziraat Bankasi Swift Mesaji.exe ReversingLabs: Detection: 23%
Machine Learning detection for sample
Source: Ziraat Bankasi Swift Mesaji.exe Joe Sandbox ML: detected
Antivirus or Machine Learning detection for unpacked file
Source: 3.0.Ziraat Bankasi Swift Mesaji.exe.400000.6.unpack Avira: Label: TR/Spy.Gen8
Source: 3.1.Ziraat Bankasi Swift Mesaji.exe.400000.0.unpack Avira: Label: TR/Spy.Gen8
Source: 3.2.Ziraat Bankasi Swift Mesaji.exe.400000.1.unpack Avira: Label: TR/Spy.Gen8
Source: 3.0.Ziraat Bankasi Swift Mesaji.exe.400000.4.unpack Avira: Label: TR/Spy.Gen8
Source: 3.0.Ziraat Bankasi Swift Mesaji.exe.400000.5.unpack Avira: Label: TR/Spy.Gen8
Source: 3.0.Ziraat Bankasi Swift Mesaji.exe.400000.1.unpack Avira: Label: TR/Spy.Gen8
Source: 3.0.Ziraat Bankasi Swift Mesaji.exe.400000.2.unpack Avira: Label: TR/Spy.Gen8
Source: 3.0.Ziraat Bankasi Swift Mesaji.exe.400000.3.unpack Avira: Label: TR/Spy.Gen8
Source: 3.0.Ziraat Bankasi Swift Mesaji.exe.400000.8.unpack Avira: Label: TR/Spy.Gen8
Source: 3.2.Ziraat Bankasi Swift Mesaji.exe.4970000.5.unpack Avira: Label: TR/Spy.Gen8

Compliance:

barindex
Detected unpacking (creates a PE file in dynamic memory)
Source: C:\Users\user\Desktop\Ziraat Bankasi Swift Mesaji.exe Unpacked PE file: 3.2.Ziraat Bankasi Swift Mesaji.exe.4970000.5.unpack
Uses 32bit PE files
Source: Ziraat Bankasi Swift Mesaji.exe Static PE information: LOCAL_SYMS_STRIPPED, 32BIT_MACHINE, EXECUTABLE_IMAGE, LINE_NUMS_STRIPPED, RELOCS_STRIPPED
Source: C:\Users\user\Desktop\Ziraat Bankasi Swift Mesaji.exe File opened: C:\Windows\WinSxS\x86_microsoft.vc80.crt_1fc8b3b9a1e18e3b_8.0.50727.9445_none_d08c58b4442ba54f\MSVCR80.dll Jump to behavior
Source: Binary string: wntdll.pdbUGP source: Ziraat Bankasi Swift Mesaji.exe, 00000000.00000003.292591572.0000000003270000.00000004.00000001.sdmp, Ziraat Bankasi Swift Mesaji.exe, 00000000.00000003.284056753.00000000030E0000.00000004.00000001.sdmp
Source: Binary string: wntdll.pdb source: Ziraat Bankasi Swift Mesaji.exe, 00000000.00000003.292591572.0000000003270000.00000004.00000001.sdmp, Ziraat Bankasi Swift Mesaji.exe, 00000000.00000003.284056753.00000000030E0000.00000004.00000001.sdmp
Source: C:\Users\user\Desktop\Ziraat Bankasi Swift Mesaji.exe Code function: 0_2_00405D7C FindFirstFileA,FindClose, 0_2_00405D7C
Source: C:\Users\user\Desktop\Ziraat Bankasi Swift Mesaji.exe Code function: 0_2_004053AA CloseHandle,DeleteFileA,lstrcatA,lstrcatA,lstrlenA,FindFirstFileA,DeleteFileA,FindNextFileA,FindClose,RemoveDirectoryA, 0_2_004053AA
Source: C:\Users\user\Desktop\Ziraat Bankasi Swift Mesaji.exe Code function: 0_2_00402630 FindFirstFileA, 0_2_00402630
Source: C:\Users\user\Desktop\Ziraat Bankasi Swift Mesaji.exe Code function: 3_2_00404A29 FindFirstFileExW, 3_2_00404A29

Networking:

barindex
Detected TCP or UDP traffic on non-standard ports
Source: global traffic TCP traffic: 192.168.2.7:49729 -> 77.88.21.37:587
Uses SMTP (mail sending)
Source: global traffic TCP traffic: 192.168.2.7:49729 -> 77.88.21.37:587
Source: Ziraat Bankasi Swift Mesaji.exe, 00000003.00000002.552826458.00000000027F1000.00000004.00000001.sdmp String found in binary or memory: http://127.0.0.1:HTTP/1.1
Source: Ziraat Bankasi Swift Mesaji.exe, 00000003.00000002.552826458.00000000027F1000.00000004.00000001.sdmp String found in binary or memory: http://DynDns.comDynDNS
Source: Ziraat Bankasi Swift Mesaji.exe, 00000003.00000002.552826458.00000000027F1000.00000004.00000001.sdmp String found in binary or memory: http://lRguGt.com
Source: Ziraat Bankasi Swift Mesaji.exe String found in binary or memory: http://nsis.sf.net/NSIS_Error
Source: Ziraat Bankasi Swift Mesaji.exe String found in binary or memory: http://nsis.sf.net/NSIS_ErrorError
Source: Ziraat Bankasi Swift Mesaji.exe, 00000003.00000002.553520842.00000000029D0000.00000004.00000001.sdmp String found in binary or memory: https://Wm2Dt2zcSt3c655v3va.com
Source: Ziraat Bankasi Swift Mesaji.exe, 00000003.00000002.552826458.00000000027F1000.00000004.00000001.sdmp String found in binary or memory: https://api.ipify.org%(
Source: Ziraat Bankasi Swift Mesaji.exe, 00000003.00000002.552826458.00000000027F1000.00000004.00000001.sdmp String found in binary or memory: https://api.ipify.org%GETMozilla/5.0
Source: Ziraat Bankasi Swift Mesaji.exe, Ziraat Bankasi Swift Mesaji.exe, 00000003.00000002.554087278.00000000037F1000.00000004.00000001.sdmp, Ziraat Bankasi Swift Mesaji.exe, 00000003.00000000.292334595.0000000000414000.00000040.00000001.sdmp, Ziraat Bankasi Swift Mesaji.exe, 00000003.00000002.554248422.0000000004930000.00000004.00020000.sdmp, Ziraat Bankasi Swift Mesaji.exe, 00000003.00000001.292756258.0000000000400000.00000040.00020000.sdmp, Ziraat Bankasi Swift Mesaji.exe, 00000003.00000002.554299855.0000000004972000.00000040.00000001.sdmp String found in binary or memory: https://www.theonionrouter.com/dist.torproject.org/torbrowser/9.5.3/tor-win32-0.4.3.6.zip
Source: Ziraat Bankasi Swift Mesaji.exe, 00000003.00000002.552826458.00000000027F1000.00000004.00000001.sdmp String found in binary or memory: https://www.theonionrouter.com/dist.torproject.org/torbrowser/9.5.3/tor-win32-0.4.3.6.zip%tordir%%ha
Source: unknown DNS traffic detected: queries for: mail.antimikrop.com.tr

Key, Mouse, Clipboard, Microphone and Screen Capturing:

barindex
Creates a DirectInput object (often for capturing keystrokes)
Source: Ziraat Bankasi Swift Mesaji.exe, 00000000.00000002.293572777.000000000074A000.00000004.00000020.sdmp Binary or memory string: <HOOK MODULE="DDRAW.DLL" FUNCTION="DirectDrawCreateEx"/>
Contains functionality for read data from the clipboard
Source: C:\Users\user\Desktop\Ziraat Bankasi Swift Mesaji.exe Code function: 0_2_00404F61 GetDlgItem,GetDlgItem,GetDlgItem,GetDlgItem,GetClientRect,GetSystemMetrics,SendMessageA,SendMessageA,SendMessageA,SendMessageA,SendMessageA,SendMessageA,ShowWindow,ShowWindow,GetDlgItem,SendMessageA,SendMessageA,SendMessageA,GetDlgItem,CreateThread,CloseHandle,ShowWindow,ShowWindow,ShowWindow,ShowWindow,SendMessageA,CreatePopupMenu,AppendMenuA,GetWindowRect,TrackPopupMenu,SendMessageA,OpenClipboard,EmptyClipboard,GlobalAlloc,GlobalLock,SendMessageA,GlobalUnlock,SetClipboardData,CloseClipboard, 0_2_00404F61

System Summary:

barindex
.NET source code contains very large array initializations
Source: 3.2.Ziraat Bankasi Swift Mesaji.exe.4970000.5.unpack, u003cPrivateImplementationDetailsu003eu007b1374F29Cu002d8C84u002d421Cu002d89E5u002d3799DC6DC7BBu007d/u00389DEAE1Fu002dF3ECu002d4475u002dA0CFu002d11ACB2FDF936.cs Large array initialization: .cctor: array initializer size 11991
Uses 32bit PE files
Source: Ziraat Bankasi Swift Mesaji.exe Static PE information: LOCAL_SYMS_STRIPPED, 32BIT_MACHINE, EXECUTABLE_IMAGE, LINE_NUMS_STRIPPED, RELOCS_STRIPPED
Contains functionality to shutdown / reboot the system
Source: C:\Users\user\Desktop\Ziraat Bankasi Swift Mesaji.exe Code function: 0_2_00403225 EntryPoint,#17,SetErrorMode,OleInitialize,SHGetFileInfoA,GetCommandLineA,GetModuleHandleA,CharNextA,GetTempPathA,GetWindowsDirectoryA,lstrcatA,DeleteFileA,OleUninitialize,ExitProcess,lstrcatA,lstrcmpiA,CreateDirectoryA,SetCurrentDirectoryA,DeleteFileA,CopyFileA,CloseHandle,GetCurrentProcess,ExitWindowsEx,ExitProcess, 0_2_00403225
Detected potential crypto function
Source: C:\Users\user\Desktop\Ziraat Bankasi Swift Mesaji.exe Code function: 0_2_0040604C 0_2_0040604C
Source: C:\Users\user\Desktop\Ziraat Bankasi Swift Mesaji.exe Code function: 0_2_00404772 0_2_00404772
Source: C:\Users\user\Desktop\Ziraat Bankasi Swift Mesaji.exe Code function: 3_2_0040A2A5 3_2_0040A2A5
Source: C:\Users\user\Desktop\Ziraat Bankasi Swift Mesaji.exe Code function: 3_2_00822490 3_2_00822490
Source: C:\Users\user\Desktop\Ziraat Bankasi Swift Mesaji.exe Code function: 3_2_00821808 3_2_00821808
Source: C:\Users\user\Desktop\Ziraat Bankasi Swift Mesaji.exe Code function: 3_2_00821C48 3_2_00821C48
Source: C:\Users\user\Desktop\Ziraat Bankasi Swift Mesaji.exe Code function: 3_2_00820070 3_2_00820070
Source: C:\Users\user\Desktop\Ziraat Bankasi Swift Mesaji.exe Code function: 3_2_00820BA8 3_2_00820BA8
Source: C:\Users\user\Desktop\Ziraat Bankasi Swift Mesaji.exe Code function: 3_2_00820014 3_2_00820014
Source: C:\Users\user\Desktop\Ziraat Bankasi Swift Mesaji.exe Code function: 3_2_008C5688 3_2_008C5688
Source: C:\Users\user\Desktop\Ziraat Bankasi Swift Mesaji.exe Code function: 3_2_008C9CE0 3_2_008C9CE0
Source: C:\Users\user\Desktop\Ziraat Bankasi Swift Mesaji.exe Code function: 3_2_008CD438 3_2_008CD438
Source: C:\Users\user\Desktop\Ziraat Bankasi Swift Mesaji.exe Code function: 3_2_008C0070 3_2_008C0070
Source: C:\Users\user\Desktop\Ziraat Bankasi Swift Mesaji.exe Code function: 3_2_008CF170 3_2_008CF170
Source: C:\Users\user\Desktop\Ziraat Bankasi Swift Mesaji.exe Code function: 3_2_008C0011 3_2_008C0011
Source: C:\Users\user\Desktop\Ziraat Bankasi Swift Mesaji.exe Code function: 3_2_049D0A90 3_2_049D0A90
Source: C:\Users\user\Desktop\Ziraat Bankasi Swift Mesaji.exe Code function: 3_2_049DC8E8 3_2_049DC8E8
Source: C:\Users\user\Desktop\Ziraat Bankasi Swift Mesaji.exe Code function: 3_2_049DD310 3_2_049DD310
Source: C:\Users\user\Desktop\Ziraat Bankasi Swift Mesaji.exe Code function: 3_2_049DBB38 3_2_049DBB38
Source: C:\Users\user\Desktop\Ziraat Bankasi Swift Mesaji.exe Code function: 3_2_049DD2F5 3_2_049DD2F5
Contains functionality to call native functions
Source: C:\Users\user\Desktop\Ziraat Bankasi Swift Mesaji.exe Code function: 3_2_00A8B136 NtQuerySystemInformation, 3_2_00A8B136
Source: C:\Users\user\Desktop\Ziraat Bankasi Swift Mesaji.exe Code function: 3_2_00A8B105 NtQuerySystemInformation, 3_2_00A8B105
Sample file is different than original file name gathered from version info
Source: Ziraat Bankasi Swift Mesaji.exe, 00000000.00000003.285119056.00000000031F6000.00000004.00000001.sdmp Binary or memory string: OriginalFilenamentdll.dllj% vs Ziraat Bankasi Swift Mesaji.exe
Source: Ziraat Bankasi Swift Mesaji.exe, 00000000.00000003.285489107.000000000338F000.00000004.00000001.sdmp Binary or memory string: OriginalFilenamentdll.dllj% vs Ziraat Bankasi Swift Mesaji.exe
Source: Ziraat Bankasi Swift Mesaji.exe, 00000000.00000002.294724890.0000000003090000.00000004.00000001.sdmp Binary or memory string: OriginalFilenamepvCVvHYPqsReUXauAjcxcqbGhkyQCsxTXEGkQdn.exe4 vs Ziraat Bankasi Swift Mesaji.exe
Source: Ziraat Bankasi Swift Mesaji.exe Binary or memory string: OriginalFilename vs Ziraat Bankasi Swift Mesaji.exe
Source: Ziraat Bankasi Swift Mesaji.exe, 00000003.00000002.554087278.00000000037F1000.00000004.00000001.sdmp Binary or memory string: OriginalFilenamepvCVvHYPqsReUXauAjcxcqbGhkyQCsxTXEGkQdn.exe4 vs Ziraat Bankasi Swift Mesaji.exe
Source: Ziraat Bankasi Swift Mesaji.exe, 00000003.00000000.292334595.0000000000414000.00000040.00000001.sdmp Binary or memory string: OriginalFilenamepvCVvHYPqsReUXauAjcxcqbGhkyQCsxTXEGkQdn.exe4 vs Ziraat Bankasi Swift Mesaji.exe
Source: Ziraat Bankasi Swift Mesaji.exe, 00000003.00000002.554248422.0000000004930000.00000004.00020000.sdmp Binary or memory string: OriginalFilenamepvCVvHYPqsReUXauAjcxcqbGhkyQCsxTXEGkQdn.exe4 vs Ziraat Bankasi Swift Mesaji.exe
Source: Ziraat Bankasi Swift Mesaji.exe, 00000003.00000001.292756258.0000000000400000.00000040.00020000.sdmp Binary or memory string: OriginalFilenamepvCVvHYPqsReUXauAjcxcqbGhkyQCsxTXEGkQdn.exe4 vs Ziraat Bankasi Swift Mesaji.exe
Source: Ziraat Bankasi Swift Mesaji.exe, 00000003.00000002.554299855.0000000004972000.00000040.00000001.sdmp Binary or memory string: OriginalFilenamepvCVvHYPqsReUXauAjcxcqbGhkyQCsxTXEGkQdn.exe4 vs Ziraat Bankasi Swift Mesaji.exe
Source: Ziraat Bankasi Swift Mesaji.exe ReversingLabs: Detection: 23%
Source: C:\Users\user\Desktop\Ziraat Bankasi Swift Mesaji.exe File read: C:\Users\user\Desktop\Ziraat Bankasi Swift Mesaji.exe Jump to behavior
Source: Ziraat Bankasi Swift Mesaji.exe Static PE information: Section: .text IMAGE_SCN_MEM_EXECUTE, IMAGE_SCN_CNT_CODE, IMAGE_SCN_MEM_READ
Source: C:\Users\user\Desktop\Ziraat Bankasi Swift Mesaji.exe Key opened: HKEY_CURRENT_USER\Software\Policies\Microsoft\Windows\Safer\CodeIdentifiers Jump to behavior
Source: unknown Process created: C:\Users\user\Desktop\Ziraat Bankasi Swift Mesaji.exe "C:\Users\user\Desktop\Ziraat Bankasi Swift Mesaji.exe"
Source: C:\Users\user\Desktop\Ziraat Bankasi Swift Mesaji.exe Process created: C:\Users\user\Desktop\Ziraat Bankasi Swift Mesaji.exe "C:\Users\user\Desktop\Ziraat Bankasi Swift Mesaji.exe"
Source: C:\Users\user\Desktop\Ziraat Bankasi Swift Mesaji.exe Process created: C:\Users\user\Desktop\Ziraat Bankasi Swift Mesaji.exe "C:\Users\user\Desktop\Ziraat Bankasi Swift Mesaji.exe" Jump to behavior
Source: C:\Users\user\Desktop\Ziraat Bankasi Swift Mesaji.exe Key value queried: HKEY_LOCAL_MACHINE\SOFTWARE\Classes\WOW6432Node\CLSID\{20D04FE0-3AEA-1069-A2D8-08002B30309D}\InProcServer32 Jump to behavior
Source: C:\Users\user\Desktop\Ziraat Bankasi Swift Mesaji.exe Code function: 3_2_00A8AFBA AdjustTokenPrivileges, 3_2_00A8AFBA
Source: C:\Users\user\Desktop\Ziraat Bankasi Swift Mesaji.exe Code function: 3_2_00A8AF83 AdjustTokenPrivileges, 3_2_00A8AF83
Source: C:\Users\user\Desktop\Ziraat Bankasi Swift Mesaji.exe WMI Queries: IWbemServices::CreateInstanceEnum - root\cimv2 : Win32_Processor
Source: C:\Users\user\Desktop\Ziraat Bankasi Swift Mesaji.exe WMI Queries: IWbemServices::ExecQuery - root\cimv2 : SELECT * FROM Win32_Processor
Source: C:\Users\user\Desktop\Ziraat Bankasi Swift Mesaji.exe WMI Queries: IWbemServices::ExecQuery - root\cimv2 : SELECT * FROM Win32_Processor
Source: C:\Users\user\Desktop\Ziraat Bankasi Swift Mesaji.exe WMI Queries: IWbemServices::ExecQuery - root\cimv2 : SELECT * FROM Win32_Processor
Source: C:\Users\user\Desktop\Ziraat Bankasi Swift Mesaji.exe WMI Queries: IWbemServices::ExecQuery - root\cimv2 : SELECT * FROM Win32_Processor
Source: C:\Users\user\Desktop\Ziraat Bankasi Swift Mesaji.exe WMI Queries: IWbemServices::ExecQuery - root\cimv2 : SELECT * FROM Win32_Processor
Source: C:\Users\user\Desktop\Ziraat Bankasi Swift Mesaji.exe WMI Queries: IWbemServices::ExecQuery - root\cimv2 : SELECT * FROM Win32_Processor
Source: C:\Users\user\Desktop\Ziraat Bankasi Swift Mesaji.exe File created: C:\Users\user~1\AppData\Local\Temp\nsdADF5.tmp Jump to behavior
Source: classification engine Classification label: mal100.troj.spyw.evad.winEXE@3/4@9/1
Source: C:\Users\user\Desktop\Ziraat Bankasi Swift Mesaji.exe Code function: 0_2_00402012 CoCreateInstance,MultiByteToWideChar, 0_2_00402012
Source: C:\Users\user\Desktop\Ziraat Bankasi Swift Mesaji.exe File read: C:\Users\desktop.ini Jump to behavior
Source: C:\Users\user\Desktop\Ziraat Bankasi Swift Mesaji.exe Code function: 0_2_00404275 GetDlgItem,SetWindowTextA,SHBrowseForFolderA,CoTaskMemFree,lstrcmpiA,lstrcatA,SetDlgItemTextA,GetDiskFreeSpaceA,MulDiv,SetDlgItemTextA, 0_2_00404275
Source: C:\Users\user\Desktop\Ziraat Bankasi Swift Mesaji.exe Section loaded: C:\Windows\assembly\NativeImages_v2.0.50727_32\mscorlib\9603718106bd57ecfbb18fefd769cab4\mscorlib.ni.dll Jump to behavior
Source: C:\Users\user\Desktop\Ziraat Bankasi Swift Mesaji.exe Section loaded: C:\Windows\assembly\GAC_32\mscorlib\2.0.0.0__b77a5c561934e089\sorttbls.nlp Jump to behavior
Source: C:\Users\user\Desktop\Ziraat Bankasi Swift Mesaji.exe Section loaded: C:\Windows\assembly\GAC_32\mscorlib\2.0.0.0__b77a5c561934e089\sortkey.nlp Jump to behavior
Source: C:\Users\user\Desktop\Ziraat Bankasi Swift Mesaji.exe Mutant created: \Sessions\1\BaseNamedObjects\Global\.net clr networking
Source: C:\Users\user\Desktop\Ziraat Bankasi Swift Mesaji.exe Code function: 3_2_00401489 GetModuleHandleW,GetModuleHandleW,FindResourceW,GetModuleHandleW,LoadResource,LockResource,GetModuleHandleW,SizeofResource,FreeResource,ExitProcess, 3_2_00401489
Source: 3.2.Ziraat Bankasi Swift Mesaji.exe.4970000.5.unpack, A/b2.cs Cryptographic APIs: 'TransformFinalBlock', 'CreateDecryptor'
Source: 3.2.Ziraat Bankasi Swift Mesaji.exe.4970000.5.unpack, A/b2.cs Cryptographic APIs: 'TransformFinalBlock', 'CreateDecryptor'
Source: C:\Users\user\Desktop\Ziraat Bankasi Swift Mesaji.exe File read: C:\Windows\System32\drivers\etc\hosts Jump to behavior
Source: C:\Users\user\Desktop\Ziraat Bankasi Swift Mesaji.exe File read: C:\Windows\System32\drivers\etc\hosts Jump to behavior
Source: C:\Users\user\Desktop\Ziraat Bankasi Swift Mesaji.exe File read: C:\Windows\System32\drivers\etc\hosts Jump to behavior
Source: C:\Users\user\Desktop\Ziraat Bankasi Swift Mesaji.exe File read: C:\Windows\System32\drivers\etc\hosts Jump to behavior
Source: C:\Users\user\Desktop\Ziraat Bankasi Swift Mesaji.exe File opened: C:\Windows\Microsoft.NET\Framework\v2.0.50727\mscorrc.dll Jump to behavior
Source: C:\Users\user\Desktop\Ziraat Bankasi Swift Mesaji.exe File opened: C:\Windows\WinSxS\x86_microsoft.vc80.crt_1fc8b3b9a1e18e3b_8.0.50727.9445_none_d08c58b4442ba54f\MSVCR80.dll Jump to behavior
Source: Binary string: wntdll.pdbUGP source: Ziraat Bankasi Swift Mesaji.exe, 00000000.00000003.292591572.0000000003270000.00000004.00000001.sdmp, Ziraat Bankasi Swift Mesaji.exe, 00000000.00000003.284056753.00000000030E0000.00000004.00000001.sdmp
Source: Binary string: wntdll.pdb source: Ziraat Bankasi Swift Mesaji.exe, 00000000.00000003.292591572.0000000003270000.00000004.00000001.sdmp, Ziraat Bankasi Swift Mesaji.exe, 00000000.00000003.284056753.00000000030E0000.00000004.00000001.sdmp

Data Obfuscation:

barindex
Detected unpacking (creates a PE file in dynamic memory)
Source: C:\Users\user\Desktop\Ziraat Bankasi Swift Mesaji.exe Unpacked PE file: 3.2.Ziraat Bankasi Swift Mesaji.exe.4970000.5.unpack
Uses code obfuscation techniques (call, push, ret)
Source: C:\Users\user\Desktop\Ziraat Bankasi Swift Mesaji.exe Code function: 0_2_72C51000 push eax; ret 0_2_72C5102E
Source: C:\Users\user\Desktop\Ziraat Bankasi Swift Mesaji.exe Code function: 3_2_00401F16 push ecx; ret 3_2_00401F29
Contains functionality to dynamically determine API calls
Source: C:\Users\user\Desktop\Ziraat Bankasi Swift Mesaji.exe Code function: 0_2_00405DA3 GetModuleHandleA,LoadLibraryA,GetProcAddress, 0_2_00405DA3

Persistence and Installation Behavior:

barindex
Drops PE files
Source: C:\Users\user\Desktop\Ziraat Bankasi Swift Mesaji.exe File created: C:\Users\user\AppData\Local\Temp\nsyAE26.tmp\tkqqg.dll Jump to dropped file

Hooking and other Techniques for Hiding and Protection:

barindex
Monitors certain registry keys / values for changes (often done to protect autostart functionality)
Source: C:\Users\user\Desktop\Ziraat Bankasi Swift Mesaji.exe Registry key monitored for changes: HKEY_CURRENT_USER_Classes Jump to behavior
Source: C:\Users\user\Desktop\Ziraat Bankasi Swift Mesaji.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Users\user\Desktop\Ziraat Bankasi Swift Mesaji.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Users\user\Desktop\Ziraat Bankasi Swift Mesaji.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Users\user\Desktop\Ziraat Bankasi Swift Mesaji.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Users\user\Desktop\Ziraat Bankasi Swift Mesaji.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Users\user\Desktop\Ziraat Bankasi Swift Mesaji.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Users\user\Desktop\Ziraat Bankasi Swift Mesaji.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Users\user\Desktop\Ziraat Bankasi Swift Mesaji.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Users\user\Desktop\Ziraat Bankasi Swift Mesaji.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Users\user\Desktop\Ziraat Bankasi Swift Mesaji.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Users\user\Desktop\Ziraat Bankasi Swift Mesaji.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Users\user\Desktop\Ziraat Bankasi Swift Mesaji.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Users\user\Desktop\Ziraat Bankasi Swift Mesaji.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Users\user\Desktop\Ziraat Bankasi Swift Mesaji.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Users\user\Desktop\Ziraat Bankasi Swift Mesaji.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Users\user\Desktop\Ziraat Bankasi Swift Mesaji.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Users\user\Desktop\Ziraat Bankasi Swift Mesaji.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Users\user\Desktop\Ziraat Bankasi Swift Mesaji.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Users\user\Desktop\Ziraat Bankasi Swift Mesaji.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Users\user\Desktop\Ziraat Bankasi Swift Mesaji.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Users\user\Desktop\Ziraat Bankasi Swift Mesaji.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Users\user\Desktop\Ziraat Bankasi Swift Mesaji.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Users\user\Desktop\Ziraat Bankasi Swift Mesaji.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Users\user\Desktop\Ziraat Bankasi Swift Mesaji.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Users\user\Desktop\Ziraat Bankasi Swift Mesaji.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Users\user\Desktop\Ziraat Bankasi Swift Mesaji.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Users\user\Desktop\Ziraat Bankasi Swift Mesaji.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Users\user\Desktop\Ziraat Bankasi Swift Mesaji.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Users\user\Desktop\Ziraat Bankasi Swift Mesaji.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Users\user\Desktop\Ziraat Bankasi Swift Mesaji.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Users\user\Desktop\Ziraat Bankasi Swift Mesaji.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Users\user\Desktop\Ziraat Bankasi Swift Mesaji.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Users\user\Desktop\Ziraat Bankasi Swift Mesaji.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Users\user\Desktop\Ziraat Bankasi Swift Mesaji.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Users\user\Desktop\Ziraat Bankasi Swift Mesaji.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Users\user\Desktop\Ziraat Bankasi Swift Mesaji.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Users\user\Desktop\Ziraat Bankasi Swift Mesaji.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Users\user\Desktop\Ziraat Bankasi Swift Mesaji.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Users\user\Desktop\Ziraat Bankasi Swift Mesaji.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Users\user\Desktop\Ziraat Bankasi Swift Mesaji.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Users\user\Desktop\Ziraat Bankasi Swift Mesaji.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Users\user\Desktop\Ziraat Bankasi Swift Mesaji.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Users\user\Desktop\Ziraat Bankasi Swift Mesaji.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Users\user\Desktop\Ziraat Bankasi Swift Mesaji.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Users\user\Desktop\Ziraat Bankasi Swift Mesaji.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Users\user\Desktop\Ziraat Bankasi Swift Mesaji.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Users\user\Desktop\Ziraat Bankasi Swift Mesaji.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Users\user\Desktop\Ziraat Bankasi Swift Mesaji.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Users\user\Desktop\Ziraat Bankasi Swift Mesaji.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Users\user\Desktop\Ziraat Bankasi Swift Mesaji.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Users\user\Desktop\Ziraat Bankasi Swift Mesaji.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Users\user\Desktop\Ziraat Bankasi Swift Mesaji.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Users\user\Desktop\Ziraat Bankasi Swift Mesaji.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Users\user\Desktop\Ziraat Bankasi Swift Mesaji.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Users\user\Desktop\Ziraat Bankasi Swift Mesaji.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Users\user\Desktop\Ziraat Bankasi Swift Mesaji.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Users\user\Desktop\Ziraat Bankasi Swift Mesaji.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Users\user\Desktop\Ziraat Bankasi Swift Mesaji.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Users\user\Desktop\Ziraat Bankasi Swift Mesaji.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Users\user\Desktop\Ziraat Bankasi Swift Mesaji.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Users\user\Desktop\Ziraat Bankasi Swift Mesaji.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Users\user\Desktop\Ziraat Bankasi Swift Mesaji.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Users\user\Desktop\Ziraat Bankasi Swift Mesaji.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Users\user\Desktop\Ziraat Bankasi Swift Mesaji.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Users\user\Desktop\Ziraat Bankasi Swift Mesaji.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Users\user\Desktop\Ziraat Bankasi Swift Mesaji.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Users\user\Desktop\Ziraat Bankasi Swift Mesaji.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Users\user\Desktop\Ziraat Bankasi Swift Mesaji.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Users\user\Desktop\Ziraat Bankasi Swift Mesaji.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Users\user\Desktop\Ziraat Bankasi Swift Mesaji.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Users\user\Desktop\Ziraat Bankasi Swift Mesaji.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Users\user\Desktop\Ziraat Bankasi Swift Mesaji.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Users\user\Desktop\Ziraat Bankasi Swift Mesaji.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Users\user\Desktop\Ziraat Bankasi Swift Mesaji.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Users\user\Desktop\Ziraat Bankasi Swift Mesaji.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Users\user\Desktop\Ziraat Bankasi Swift Mesaji.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Users\user\Desktop\Ziraat Bankasi Swift Mesaji.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Users\user\Desktop\Ziraat Bankasi Swift Mesaji.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Users\user\Desktop\Ziraat Bankasi Swift Mesaji.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Users\user\Desktop\Ziraat Bankasi Swift Mesaji.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Users\user\Desktop\Ziraat Bankasi Swift Mesaji.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Users\user\Desktop\Ziraat Bankasi Swift Mesaji.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Users\user\Desktop\Ziraat Bankasi Swift Mesaji.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Users\user\Desktop\Ziraat Bankasi Swift Mesaji.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Users\user\Desktop\Ziraat Bankasi Swift Mesaji.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Users\user\Desktop\Ziraat Bankasi Swift Mesaji.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Users\user\Desktop\Ziraat Bankasi Swift Mesaji.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Users\user\Desktop\Ziraat Bankasi Swift Mesaji.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Users\user\Desktop\Ziraat Bankasi Swift Mesaji.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Users\user\Desktop\Ziraat Bankasi Swift Mesaji.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Users\user\Desktop\Ziraat Bankasi Swift Mesaji.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Users\user\Desktop\Ziraat Bankasi Swift Mesaji.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Users\user\Desktop\Ziraat Bankasi Swift Mesaji.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Users\user\Desktop\Ziraat Bankasi Swift Mesaji.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Users\user\Desktop\Ziraat Bankasi Swift Mesaji.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Users\user\Desktop\Ziraat Bankasi Swift Mesaji.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Users\user\Desktop\Ziraat Bankasi Swift Mesaji.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Users\user\Desktop\Ziraat Bankasi Swift Mesaji.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Users\user\Desktop\Ziraat Bankasi Swift Mesaji.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Users\user\Desktop\Ziraat Bankasi Swift Mesaji.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Users\user\Desktop\Ziraat Bankasi Swift Mesaji.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Users\user\Desktop\Ziraat Bankasi Swift Mesaji.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Users\user\Desktop\Ziraat Bankasi Swift Mesaji.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Users\user\Desktop\Ziraat Bankasi Swift Mesaji.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Users\user\Desktop\Ziraat Bankasi Swift Mesaji.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Users\user\Desktop\Ziraat Bankasi Swift Mesaji.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Users\user\Desktop\Ziraat Bankasi Swift Mesaji.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Users\user\Desktop\Ziraat Bankasi Swift Mesaji.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Users\user\Desktop\Ziraat Bankasi Swift Mesaji.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Users\user\Desktop\Ziraat Bankasi Swift Mesaji.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Users\user\Desktop\Ziraat Bankasi Swift Mesaji.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Users\user\Desktop\Ziraat Bankasi Swift Mesaji.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Users\user\Desktop\Ziraat Bankasi Swift Mesaji.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Users\user\Desktop\Ziraat Bankasi Swift Mesaji.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Users\user\Desktop\Ziraat Bankasi Swift Mesaji.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Users\user\Desktop\Ziraat Bankasi Swift Mesaji.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Users\user\Desktop\Ziraat Bankasi Swift Mesaji.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Users\user\Desktop\Ziraat Bankasi Swift Mesaji.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Users\user\Desktop\Ziraat Bankasi Swift Mesaji.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Users\user\Desktop\Ziraat Bankasi Swift Mesaji.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Users\user\Desktop\Ziraat Bankasi Swift Mesaji.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Users\user\Desktop\Ziraat Bankasi Swift Mesaji.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Users\user\Desktop\Ziraat Bankasi Swift Mesaji.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Users\user\Desktop\Ziraat Bankasi Swift Mesaji.exe Process information set: NOOPENFILEERRORBOX Jump to behavior

Malware Analysis System Evasion:

barindex
Found evasive API chain (trying to detect sleep duration tampering with parallel thread)
Source: C:\Users\user\Desktop\Ziraat Bankasi Swift Mesaji.exe Function Chain: threadResumed,threadDelayed,memAlloc,memAlloc,systemQueried,systemQueried,threadCreated,threadResumed,threadDelayed,threadDelayed,threadDelayed,systemQueried,systemQueried,threadDelayed,threadDelayed,threadDelayed,threadDelayed,systemQueried,threadDelayed,systemQueried,threadAPCQueued,threadDelayed,threadDelayed,threadDelayed,systemQueried
Source: C:\Users\user\Desktop\Ziraat Bankasi Swift Mesaji.exe Function Chain: systemQueried,threadCreated,threadResumed,threadDelayed,threadDelayed,threadDelayed,systemQueried,systemQueried,threadDelayed,threadDelayed,threadDelayed,threadDelayed,systemQueried,threadDelayed,systemQueried,threadAPCQueued,threadDelayed,threadDelayed,threadDelayed,systemQueried,threadDelayed,threadDelayed,threadDelayed,threadDelayed,memAlloc
Queries sensitive network adapter information (via WMI, Win32_NetworkAdapter, often done to detect virtual machines)
Source: C:\Users\user\Desktop\Ziraat Bankasi Swift Mesaji.exe WMI Queries: IWbemServices::CreateInstanceEnum - root\cimv2 : Win32_NetworkAdapterConfiguration
Queries sensitive BIOS Information (via WMI, Win32_Bios & Win32_BaseBoard, often done to detect virtual machines)
Source: C:\Users\user\Desktop\Ziraat Bankasi Swift Mesaji.exe WMI Queries: IWbemServices::CreateInstanceEnum - root\cimv2 : Win32_BaseBoard
May sleep (evasive loops) to hinder dynamic analysis
Source: C:\Users\user\Desktop\Ziraat Bankasi Swift Mesaji.exe TID: 6116 Thread sleep time: -922337203685477s >= -30000s Jump to behavior
Source: C:\Users\user\Desktop\Ziraat Bankasi Swift Mesaji.exe TID: 6116 Thread sleep time: -4170000s >= -30000s Jump to behavior
Source: C:\Users\user\Desktop\Ziraat Bankasi Swift Mesaji.exe TID: 6116 Thread sleep time: -30000s >= -30000s Jump to behavior
Source: C:\Users\user\Desktop\Ziraat Bankasi Swift Mesaji.exe TID: 6116 Thread sleep time: -57562s >= -30000s Jump to behavior
Sample execution stops while process was sleeping (likely an evasion)
Source: C:\Users\user\Desktop\Ziraat Bankasi Swift Mesaji.exe Last function: Thread delayed
Contains long sleeps (>= 3 min)
Source: C:\Users\user\Desktop\Ziraat Bankasi Swift Mesaji.exe Thread delayed: delay time: 922337203685477 Jump to behavior
Found a high number of Window / User specific system calls (may be a loop to detect user behavior)
Source: C:\Users\user\Desktop\Ziraat Bankasi Swift Mesaji.exe Window / User API: threadDelayed 544 Jump to behavior
Queries sensitive processor information (via WMI, Win32_Processor, often done to detect virtual machines)
Source: C:\Users\user\Desktop\Ziraat Bankasi Swift Mesaji.exe WMI Queries: IWbemServices::CreateInstanceEnum - root\cimv2 : Win32_Processor
Source: C:\Users\user\Desktop\Ziraat Bankasi Swift Mesaji.exe WMI Queries: IWbemServices::ExecQuery - root\cimv2 : SELECT * FROM Win32_Processor
Source: C:\Users\user\Desktop\Ziraat Bankasi Swift Mesaji.exe WMI Queries: IWbemServices::ExecQuery - root\cimv2 : SELECT * FROM Win32_Processor
Source: C:\Users\user\Desktop\Ziraat Bankasi Swift Mesaji.exe WMI Queries: IWbemServices::ExecQuery - root\cimv2 : SELECT * FROM Win32_Processor
Source: C:\Users\user\Desktop\Ziraat Bankasi Swift Mesaji.exe WMI Queries: IWbemServices::ExecQuery - root\cimv2 : SELECT * FROM Win32_Processor
Source: C:\Users\user\Desktop\Ziraat Bankasi Swift Mesaji.exe WMI Queries: IWbemServices::ExecQuery - root\cimv2 : SELECT * FROM Win32_Processor
Source: C:\Users\user\Desktop\Ziraat Bankasi Swift Mesaji.exe WMI Queries: IWbemServices::ExecQuery - root\cimv2 : SELECT * FROM Win32_Processor
Source: C:\Users\user\Desktop\Ziraat Bankasi Swift Mesaji.exe Process information queried: ProcessInformation Jump to behavior
Source: C:\Users\user\Desktop\Ziraat Bankasi Swift Mesaji.exe Code function: 0_2_00405D7C FindFirstFileA,FindClose, 0_2_00405D7C
Source: C:\Users\user\Desktop\Ziraat Bankasi Swift Mesaji.exe Code function: 0_2_004053AA CloseHandle,DeleteFileA,lstrcatA,lstrcatA,lstrlenA,FindFirstFileA,DeleteFileA,FindNextFileA,FindClose,RemoveDirectoryA, 0_2_004053AA
Source: C:\Users\user\Desktop\Ziraat Bankasi Swift Mesaji.exe Code function: 0_2_00402630 FindFirstFileA, 0_2_00402630
Source: C:\Users\user\Desktop\Ziraat Bankasi Swift Mesaji.exe Code function: 3_2_00404A29 FindFirstFileExW, 3_2_00404A29
Source: C:\Users\user\Desktop\Ziraat Bankasi Swift Mesaji.exe Thread delayed: delay time: 922337203685477 Jump to behavior
Source: C:\Users\user\Desktop\Ziraat Bankasi Swift Mesaji.exe Thread delayed: delay time: 30000 Jump to behavior
Source: C:\Users\user\Desktop\Ziraat Bankasi Swift Mesaji.exe Thread delayed: delay time: 30000 Jump to behavior
Source: C:\Users\user\Desktop\Ziraat Bankasi Swift Mesaji.exe API call chain: ExitProcess graph end node
Source: C:\Users\user\Desktop\Ziraat Bankasi Swift Mesaji.exe API call chain: ExitProcess graph end node
Source: C:\Users\user\Desktop\Ziraat Bankasi Swift Mesaji.exe API call chain: ExitProcess graph end node
Source: Ziraat Bankasi Swift Mesaji.exe, 00000003.00000003.481381105.0000000005464000.00000004.00000001.sdmp, Ziraat Bankasi Swift Mesaji.exe, 00000003.00000003.481221494.0000000005451000.00000004.00000001.sdmp, Ziraat Bankasi Swift Mesaji.exe, 00000003.00000002.554817015.0000000005466000.00000004.00000001.sdmp Binary or memory string: Hyper-V RAW
Source: Ziraat Bankasi Swift Mesaji.exe, 00000003.00000003.481381105.0000000005464000.00000004.00000001.sdmp, Ziraat Bankasi Swift Mesaji.exe, 00000003.00000003.481221494.0000000005451000.00000004.00000001.sdmp, Ziraat Bankasi Swift Mesaji.exe, 00000003.00000002.554817015.0000000005466000.00000004.00000001.sdmp Binary or memory string: Hyper-V RAW%SystemRoot%\system32\mswsock.dll

Anti Debugging:

barindex
Contains functionality to check if a debugger is running (IsDebuggerPresent)
Source: C:\Users\user\Desktop\Ziraat Bankasi Swift Mesaji.exe Code function: 3_2_0040446F IsDebuggerPresent,SetUnhandledExceptionFilter,UnhandledExceptionFilter, 3_2_0040446F
Contains functionality to dynamically determine API calls
Source: C:\Users\user\Desktop\Ziraat Bankasi Swift Mesaji.exe Code function: 0_2_00405DA3 GetModuleHandleA,LoadLibraryA,GetProcAddress, 0_2_00405DA3
Contains functionality which may be used to detect a debugger (GetProcessHeap)
Source: C:\Users\user\Desktop\Ziraat Bankasi Swift Mesaji.exe Code function: 3_2_004067FE GetProcessHeap, 3_2_004067FE
Enables debug privileges
Source: C:\Users\user\Desktop\Ziraat Bankasi Swift Mesaji.exe Process token adjusted: Debug Jump to behavior
Contains functionality to read the PEB
Source: C:\Users\user\Desktop\Ziraat Bankasi Swift Mesaji.exe Code function: 0_2_0019E986 mov eax, dword ptr fs:[00000030h] 0_2_0019E986
Source: C:\Users\user\Desktop\Ziraat Bankasi Swift Mesaji.exe Code function: 0_2_0019E772 mov eax, dword ptr fs:[00000030h] 0_2_0019E772
Source: C:\Users\user\Desktop\Ziraat Bankasi Swift Mesaji.exe Code function: 0_2_0019EAB4 mov eax, dword ptr fs:[00000030h] 0_2_0019EAB4
Source: C:\Users\user\Desktop\Ziraat Bankasi Swift Mesaji.exe Code function: 0_2_0019EA37 mov eax, dword ptr fs:[00000030h] 0_2_0019EA37
Source: C:\Users\user\Desktop\Ziraat Bankasi Swift Mesaji.exe Code function: 0_2_0019EA76 mov eax, dword ptr fs:[00000030h] 0_2_0019EA76
Source: C:\Users\user\Desktop\Ziraat Bankasi Swift Mesaji.exe Code function: 3_2_004035F1 mov eax, dword ptr fs:[00000030h] 3_2_004035F1
Contains functionality to access loader functionality (e.g. LdrGetProcedureAddress)
Source: C:\Users\user\Desktop\Ziraat Bankasi Swift Mesaji.exe Code function: 3_2_00823CC0 LdrInitializeThunk, 3_2_00823CC0
Source: C:\Users\user\Desktop\Ziraat Bankasi Swift Mesaji.exe Memory allocated: page read and write | page guard Jump to behavior
Source: C:\Users\user\Desktop\Ziraat Bankasi Swift Mesaji.exe Code function: 3_2_00401E1D SetUnhandledExceptionFilter, 3_2_00401E1D
Source: C:\Users\user\Desktop\Ziraat Bankasi Swift Mesaji.exe Code function: 3_2_0040446F IsDebuggerPresent,SetUnhandledExceptionFilter,UnhandledExceptionFilter, 3_2_0040446F
Source: C:\Users\user\Desktop\Ziraat Bankasi Swift Mesaji.exe Code function: 3_2_00401C88 IsProcessorFeaturePresent,IsDebuggerPresent,SetUnhandledExceptionFilter,UnhandledExceptionFilter, 3_2_00401C88
Source: C:\Users\user\Desktop\Ziraat Bankasi Swift Mesaji.exe Code function: 3_2_00401F30 SetUnhandledExceptionFilter,UnhandledExceptionFilter,GetCurrentProcess,TerminateProcess, 3_2_00401F30

HIPS / PFW / Operating System Protection Evasion:

barindex
Injects a PE file into a foreign processes
Source: C:\Users\user\Desktop\Ziraat Bankasi Swift Mesaji.exe Memory written: C:\Users\user\Desktop\Ziraat Bankasi Swift Mesaji.exe base: 400000 value starts with: 4D5A Jump to behavior
Creates a process in suspended mode (likely to inject code)
Source: C:\Users\user\Desktop\Ziraat Bankasi Swift Mesaji.exe Process created: C:\Users\user\Desktop\Ziraat Bankasi Swift Mesaji.exe "C:\Users\user\Desktop\Ziraat Bankasi Swift Mesaji.exe" Jump to behavior
Source: Ziraat Bankasi Swift Mesaji.exe, 00000003.00000002.552656445.0000000000EF0000.00000002.00020000.sdmp Binary or memory string: uProgram Manager
Source: Ziraat Bankasi Swift Mesaji.exe, 00000003.00000002.552656445.0000000000EF0000.00000002.00020000.sdmp Binary or memory string: Shell_TrayWnd
Source: Ziraat Bankasi Swift Mesaji.exe, 00000003.00000002.552656445.0000000000EF0000.00000002.00020000.sdmp Binary or memory string: Progman
Source: Ziraat Bankasi Swift Mesaji.exe, 00000003.00000002.552656445.0000000000EF0000.00000002.00020000.sdmp Binary or memory string: Progmanlock

Language, Device and Operating System Detection:

barindex
Queries the volume information (name, serial number etc) of a device
Source: C:\Users\user\Desktop\Ziraat Bankasi Swift Mesaji.exe Queries volume information: C:\Windows\assembly\GAC_32\CustomMarshalers\2.0.0.0__b03f5f7f11d50a3a\CustomMarshalers.dll VolumeInformation Jump to behavior
Source: C:\Users\user\Desktop\Ziraat Bankasi Swift Mesaji.exe Queries volume information: C:\Windows\assembly\GAC_32\CustomMarshalers\2.0.0.0__b03f5f7f11d50a3a\CustomMarshalers.dll VolumeInformation Jump to behavior
Contains functionality to query CPU information (cpuid)
Source: C:\Users\user\Desktop\Ziraat Bankasi Swift Mesaji.exe Code function: 3_2_0040208D cpuid 3_2_0040208D
Source: C:\Users\user\Desktop\Ziraat Bankasi Swift Mesaji.exe Key value queried: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Cryptography MachineGuid Jump to behavior
Source: C:\Users\user\Desktop\Ziraat Bankasi Swift Mesaji.exe Code function: 3_2_00401B74 GetSystemTimeAsFileTime,GetCurrentThreadId,GetCurrentProcessId,QueryPerformanceCounter, 3_2_00401B74
Source: C:\Users\user\Desktop\Ziraat Bankasi Swift Mesaji.exe Code function: 0_2_00405AA7 GetVersion,GetSystemDirectoryA,GetWindowsDirectoryA,SHGetSpecialFolderLocation,SHGetPathFromIDListA,CoTaskMemFree,lstrcatA,StrCmpNIW,lstrlenA, 0_2_00405AA7
Source: C:\Users\user\Desktop\Ziraat Bankasi Swift Mesaji.exe Code function: 3_2_00A8BB16 GetUserNameW, 3_2_00A8BB16

Stealing of Sensitive Information:

barindex
Yara detected AgentTesla
Source: Yara match File source: 3.2.Ziraat Bankasi Swift Mesaji.exe.37f3258.3.raw.unpack, type: UNPACKEDPE
Source: Yara match File source: 3.1.Ziraat Bankasi Swift Mesaji.exe.415058.1.unpack, type: UNPACKEDPE
Source: Yara match File source: 3.2.Ziraat Bankasi Swift Mesaji.exe.415058.0.unpack, type: UNPACKEDPE
Source: Yara match File source: 0.2.Ziraat Bankasi Swift Mesaji.exe.30a1458.4.raw.unpack, type: UNPACKEDPE
Source: Yara match File source: 0.2.Ziraat Bankasi Swift Mesaji.exe.3090000.5.unpack, type: UNPACKEDPE
Source: Yara match File source: 3.2.Ziraat Bankasi Swift Mesaji.exe.400000.1.raw.unpack, type: UNPACKEDPE
Source: Yara match File source: 3.0.Ziraat Bankasi Swift Mesaji.exe.400000.6.unpack, type: UNPACKEDPE
Source: Yara match File source: 3.2.Ziraat Bankasi Swift Mesaji.exe.4930000.4.unpack, type: UNPACKEDPE
Source: Yara match File source: 3.1.Ziraat Bankasi Swift Mesaji.exe.400000.0.unpack, type: UNPACKEDPE
Source: Yara match File source: 3.0.Ziraat Bankasi Swift Mesaji.exe.415058.9.unpack, type: UNPACKEDPE
Source: Yara match File source: 3.1.Ziraat Bankasi Swift Mesaji.exe.400000.0.raw.unpack, type: UNPACKEDPE
Source: Yara match File source: 3.2.Ziraat Bankasi Swift Mesaji.exe.4930000.4.raw.unpack, type: UNPACKEDPE
Source: Yara match File source: 3.0.Ziraat Bankasi Swift Mesaji.exe.415058.7.raw.unpack, type: UNPACKEDPE
Source: Yara match File source: 3.2.Ziraat Bankasi Swift Mesaji.exe.37f3258.3.unpack, type: UNPACKEDPE
Source: Yara match File source: 3.2.Ziraat Bankasi Swift Mesaji.exe.400000.1.unpack, type: UNPACKEDPE
Source: Yara match File source: 3.0.Ziraat Bankasi Swift Mesaji.exe.400000.4.unpack, type: UNPACKEDPE
Source: Yara match File source: 0.2.Ziraat Bankasi Swift Mesaji.exe.30a1458.4.unpack, type: UNPACKEDPE
Source: Yara match File source: 3.0.Ziraat Bankasi Swift Mesaji.exe.400000.1.unpack, type: UNPACKEDPE
Source: Yara match File source: 3.0.Ziraat Bankasi Swift Mesaji.exe.400000.5.unpack, type: UNPACKEDPE
Source: Yara match File source: 3.2.Ziraat Bankasi Swift Mesaji.exe.5446f0.2.raw.unpack, type: UNPACKEDPE
Source: Yara match File source: 3.0.Ziraat Bankasi Swift Mesaji.exe.400000.3.unpack, type: UNPACKEDPE
Source: Yara match File source: 0.2.Ziraat Bankasi Swift Mesaji.exe.3090000.5.raw.unpack, type: UNPACKEDPE
Source: Yara match File source: 3.0.Ziraat Bankasi Swift Mesaji.exe.400000.2.unpack, type: UNPACKEDPE
Source: Yara match File source: 3.0.Ziraat Bankasi Swift Mesaji.exe.400000.8.unpack, type: UNPACKEDPE
Source: Yara match File source: 3.0.Ziraat Bankasi Swift Mesaji.exe.415058.7.unpack, type: UNPACKEDPE
Source: Yara match File source: 3.2.Ziraat Bankasi Swift Mesaji.exe.5446f0.2.unpack, type: UNPACKEDPE
Source: Yara match File source: 3.2.Ziraat Bankasi Swift Mesaji.exe.415058.0.raw.unpack, type: UNPACKEDPE
Source: Yara match File source: 3.0.Ziraat Bankasi Swift Mesaji.exe.415058.9.raw.unpack, type: UNPACKEDPE
Source: Yara match File source: 3.1.Ziraat Bankasi Swift Mesaji.exe.415058.1.raw.unpack, type: UNPACKEDPE
Source: Yara match File source: 3.2.Ziraat Bankasi Swift Mesaji.exe.4970000.5.unpack, type: UNPACKEDPE
Source: Yara match File source: 00000003.00000002.554087278.00000000037F1000.00000004.00000001.sdmp, type: MEMORY
Source: Yara match File source: 00000003.00000002.551571985.0000000000508000.00000004.00000020.sdmp, type: MEMORY
Source: Yara match File source: 00000003.00000000.292334595.0000000000414000.00000040.00000001.sdmp, type: MEMORY
Source: Yara match File source: 00000003.00000002.554248422.0000000004930000.00000004.00020000.sdmp, type: MEMORY
Source: Yara match File source: 00000003.00000001.292756258.0000000000400000.00000040.00020000.sdmp, type: MEMORY
Source: Yara match File source: 00000003.00000000.291447047.0000000000414000.00000040.00000001.sdmp, type: MEMORY
Source: Yara match File source: 00000003.00000002.554299855.0000000004972000.00000040.00000001.sdmp, type: MEMORY
Source: Yara match File source: 00000003.00000002.548601003.0000000000400000.00000040.00000001.sdmp, type: MEMORY
Source: Yara match File source: 00000000.00000002.294724890.0000000003090000.00000004.00000001.sdmp, type: MEMORY
Source: Yara match File source: 00000003.00000002.552826458.00000000027F1000.00000004.00000001.sdmp, type: MEMORY
Source: Yara match File source: Process Memory Space: Ziraat Bankasi Swift Mesaji.exe PID: 6988, type: MEMORYSTR
Source: Yara match File source: Process Memory Space: Ziraat Bankasi Swift Mesaji.exe PID: 7108, type: MEMORYSTR
Tries to steal Mail credentials (via file / registry access)
Source: C:\Users\user\Desktop\Ziraat Bankasi Swift Mesaji.exe File opened: C:\Users\user\AppData\Roaming\Thunderbird\profiles.ini Jump to behavior
Source: C:\Users\user\Desktop\Ziraat Bankasi Swift Mesaji.exe File opened: C:\Users\user\AppData\Roaming\Thunderbird\profiles.ini Jump to behavior
Tries to harvest and steal ftp login credentials
Source: C:\Users\user\Desktop\Ziraat Bankasi Swift Mesaji.exe File opened: C:\Users\user\AppData\Roaming\SmartFTP\Client 2.0\Favorites\Quick Connect\ Jump to behavior
Source: C:\Users\user\Desktop\Ziraat Bankasi Swift Mesaji.exe File opened: C:\Users\user\AppData\Roaming\FileZilla\recentservers.xml Jump to behavior
Tries to harvest and steal browser information (history, passwords, etc)
Source: C:\Users\user\Desktop\Ziraat Bankasi Swift Mesaji.exe File opened: C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Login Data Jump to behavior
Source: C:\Users\user\Desktop\Ziraat Bankasi Swift Mesaji.exe File opened: C:\Users\user\AppData\Roaming\Mozilla\Firefox\profiles.ini Jump to behavior
Yara detected Credential Stealer
Source: Yara match File source: 00000003.00000002.552826458.00000000027F1000.00000004.00000001.sdmp, type: MEMORY
Source: Yara match File source: Process Memory Space: Ziraat Bankasi Swift Mesaji.exe PID: 7108, type: MEMORYSTR

Remote Access Functionality:

barindex
Yara detected AgentTesla
Source: Yara match File source: 3.2.Ziraat Bankasi Swift Mesaji.exe.37f3258.3.raw.unpack, type: UNPACKEDPE
Source: Yara match File source: 3.1.Ziraat Bankasi Swift Mesaji.exe.415058.1.unpack, type: UNPACKEDPE
Source: Yara match File source: 3.2.Ziraat Bankasi Swift Mesaji.exe.415058.0.unpack, type: UNPACKEDPE
Source: Yara match File source: 0.2.Ziraat Bankasi Swift Mesaji.exe.30a1458.4.raw.unpack, type: UNPACKEDPE
Source: Yara match File source: 0.2.Ziraat Bankasi Swift Mesaji.exe.3090000.5.unpack, type: UNPACKEDPE
Source: Yara match File source: 3.2.Ziraat Bankasi Swift Mesaji.exe.400000.1.raw.unpack, type: UNPACKEDPE
Source: Yara match File source: 3.0.Ziraat Bankasi Swift Mesaji.exe.400000.6.unpack, type: UNPACKEDPE
Source: Yara match File source: 3.2.Ziraat Bankasi Swift Mesaji.exe.4930000.4.unpack, type: UNPACKEDPE
Source: Yara match File source: 3.1.Ziraat Bankasi Swift Mesaji.exe.400000.0.unpack, type: UNPACKEDPE
Source: Yara match File source: 3.0.Ziraat Bankasi Swift Mesaji.exe.415058.9.unpack, type: UNPACKEDPE
Source: Yara match File source: 3.1.Ziraat Bankasi Swift Mesaji.exe.400000.0.raw.unpack, type: UNPACKEDPE
Source: Yara match File source: 3.2.Ziraat Bankasi Swift Mesaji.exe.4930000.4.raw.unpack, type: UNPACKEDPE
Source: Yara match File source: 3.0.Ziraat Bankasi Swift Mesaji.exe.415058.7.raw.unpack, type: UNPACKEDPE
Source: Yara match File source: 3.2.Ziraat Bankasi Swift Mesaji.exe.37f3258.3.unpack, type: UNPACKEDPE
Source: Yara match File source: 3.2.Ziraat Bankasi Swift Mesaji.exe.400000.1.unpack, type: UNPACKEDPE
Source: Yara match File source: 3.0.Ziraat Bankasi Swift Mesaji.exe.400000.4.unpack, type: UNPACKEDPE
Source: Yara match File source: 0.2.Ziraat Bankasi Swift Mesaji.exe.30a1458.4.unpack, type: UNPACKEDPE
Source: Yara match File source: 3.0.Ziraat Bankasi Swift Mesaji.exe.400000.1.unpack, type: UNPACKEDPE
Source: Yara match File source: 3.0.Ziraat Bankasi Swift Mesaji.exe.400000.5.unpack, type: UNPACKEDPE
Source: Yara match File source: 3.2.Ziraat Bankasi Swift Mesaji.exe.5446f0.2.raw.unpack, type: UNPACKEDPE
Source: Yara match File source: 3.0.Ziraat Bankasi Swift Mesaji.exe.400000.3.unpack, type: UNPACKEDPE
Source: Yara match File source: 0.2.Ziraat Bankasi Swift Mesaji.exe.3090000.5.raw.unpack, type: UNPACKEDPE
Source: Yara match File source: 3.0.Ziraat Bankasi Swift Mesaji.exe.400000.2.unpack, type: UNPACKEDPE
Source: Yara match File source: 3.0.Ziraat Bankasi Swift Mesaji.exe.400000.8.unpack, type: UNPACKEDPE
Source: Yara match File source: 3.0.Ziraat Bankasi Swift Mesaji.exe.415058.7.unpack, type: UNPACKEDPE
Source: Yara match File source: 3.2.Ziraat Bankasi Swift Mesaji.exe.5446f0.2.unpack, type: UNPACKEDPE
Source: Yara match File source: 3.2.Ziraat Bankasi Swift Mesaji.exe.415058.0.raw.unpack, type: UNPACKEDPE
Source: Yara match File source: 3.0.Ziraat Bankasi Swift Mesaji.exe.415058.9.raw.unpack, type: UNPACKEDPE
Source: Yara match File source: 3.1.Ziraat Bankasi Swift Mesaji.exe.415058.1.raw.unpack, type: UNPACKEDPE
Source: Yara match File source: 3.2.Ziraat Bankasi Swift Mesaji.exe.4970000.5.unpack, type: UNPACKEDPE
Source: Yara match File source: 00000003.00000002.554087278.00000000037F1000.00000004.00000001.sdmp, type: MEMORY
Source: Yara match File source: 00000003.00000002.551571985.0000000000508000.00000004.00000020.sdmp, type: MEMORY
Source: Yara match File source: 00000003.00000000.292334595.0000000000414000.00000040.00000001.sdmp, type: MEMORY
Source: Yara match File source: 00000003.00000002.554248422.0000000004930000.00000004.00020000.sdmp, type: MEMORY
Source: Yara match File source: 00000003.00000001.292756258.0000000000400000.00000040.00020000.sdmp, type: MEMORY
Source: Yara match File source: 00000003.00000000.291447047.0000000000414000.00000040.00000001.sdmp, type: MEMORY
Source: Yara match File source: 00000003.00000002.554299855.0000000004972000.00000040.00000001.sdmp, type: MEMORY
Source: Yara match File source: 00000003.00000002.548601003.0000000000400000.00000040.00000001.sdmp, type: MEMORY
Source: Yara match File source: 00000000.00000002.294724890.0000000003090000.00000004.00000001.sdmp, type: MEMORY
Source: Yara match File source: 00000003.00000002.552826458.00000000027F1000.00000004.00000001.sdmp, type: MEMORY
Source: Yara match File source: Process Memory Space: Ziraat Bankasi Swift Mesaji.exe PID: 6988, type: MEMORYSTR
Source: Yara match File source: Process Memory Space: Ziraat Bankasi Swift Mesaji.exe PID: 7108, type: MEMORYSTR
  • No. of IPs < 25%
  • 25% < No. of IPs < 50%
  • 50% < No. of IPs < 75%
  • 75% < No. of IPs