Source: Yara match |
File source: ts.exe, type: SAMPLE |
Source: Yara match |
File source: 0.3.ts.exe.228231c0000.3.unpack, type: UNPACKEDPE |
Source: Yara match |
File source: 0.3.ts.exe.228233eea14.0.unpack, type: UNPACKEDPE |
Source: Yara match |
File source: 0.3.ts.exe.228231c0000.3.raw.unpack, type: UNPACKEDPE |
Source: Yara match |
File source: 0.2.ts.exe.7ffa0aed0000.2.unpack, type: UNPACKEDPE |
Source: Yara match |
File source: 0.3.ts.exe.228233ca850.1.raw.unpack, type: UNPACKEDPE |
Source: Yara match |
File source: 0.3.ts.exe.228233eea14.0.raw.unpack, type: UNPACKEDPE |
Source: Yara match |
File source: 0.3.ts.exe.22823350000.2.raw.unpack, type: UNPACKEDPE |
Source: Yara match |
File source: 00000000.00000002.562441647.00007FFA0AED1000.00000020.00000001.01000000.00000004.sdmp, type: MEMORY |
Source: Yara match |
File source: 00000000.00000003.299862162.00000228231C0000.00000004.00001000.00020000.00000000.sdmp, type: MEMORY |
Source: Yara match |
File source: 00000000.00000003.299383409.0000022823350000.00000004.00001000.00020000.00000000.sdmp, type: MEMORY |
Source: Yara match |
File source: C:\Users\user\Desktop\62366813.dll, type: DROPPED |
Source: ts.exe, type: SAMPLE |
Matched rule: Windows_Trojan_Emotet_db7d33fa Author: unknown |
Source: 0.3.ts.exe.228231c0000.3.unpack, type: UNPACKEDPE |
Matched rule: Windows_Trojan_Emotet_db7d33fa Author: unknown |
Source: 0.3.ts.exe.228233eea14.0.unpack, type: UNPACKEDPE |
Matched rule: Windows_Trojan_Emotet_db7d33fa Author: unknown |
Source: 0.3.ts.exe.228231c0000.3.raw.unpack, type: UNPACKEDPE |
Matched rule: Windows_Trojan_Emotet_db7d33fa Author: unknown |
Source: 0.2.ts.exe.7ffa0aed0000.2.unpack, type: UNPACKEDPE |
Matched rule: Windows_Trojan_Emotet_db7d33fa Author: unknown |
Source: 0.3.ts.exe.228233ca850.1.raw.unpack, type: UNPACKEDPE |
Matched rule: Windows_Trojan_Emotet_db7d33fa Author: unknown |
Source: 0.3.ts.exe.228233eea14.0.raw.unpack, type: UNPACKEDPE |
Matched rule: Windows_Trojan_Emotet_db7d33fa Author: unknown |
Source: 0.3.ts.exe.22823350000.2.raw.unpack, type: UNPACKEDPE |
Matched rule: Windows_Trojan_Emotet_db7d33fa Author: unknown |
Source: 00000000.00000002.562441647.00007FFA0AED1000.00000020.00000001.01000000.00000004.sdmp, type: MEMORY |
Matched rule: Windows_Trojan_Emotet_db7d33fa Author: unknown |
Source: 00000000.00000003.299862162.00000228231C0000.00000004.00001000.00020000.00000000.sdmp, type: MEMORY |
Matched rule: Windows_Trojan_Emotet_db7d33fa Author: unknown |
Source: 00000000.00000003.299383409.0000022823350000.00000004.00001000.00020000.00000000.sdmp, type: MEMORY |
Matched rule: Windows_Trojan_Emotet_db7d33fa Author: unknown |
Source: C:\Users\user\Desktop\62366813.dll, type: DROPPED |
Matched rule: Windows_Trojan_Emotet_db7d33fa Author: unknown |
Source: ts.exe, type: SAMPLE |
Matched rule: Windows_Trojan_Emotet_db7d33fa reference_sample = 08c23400ff546db41f9ddbbb19fa75519826744dde3b3afb38f3985266577afc, os = windows, severity = x86, creation_date = 2022-05-09, scan_context = file, memory, license = Elastic License v2, threat_name = Windows.Trojan.Emotet, fingerprint = eac196154ab1ad636654c966e860dcd5763c50d7b8221dbbc7769c879daf02fd, id = db7d33fa-e50c-4c59-ab92-edb74aac87c9, last_modified = 2022-06-09 |
Source: 0.3.ts.exe.228231c0000.3.unpack, type: UNPACKEDPE |
Matched rule: Windows_Trojan_Emotet_db7d33fa reference_sample = 08c23400ff546db41f9ddbbb19fa75519826744dde3b3afb38f3985266577afc, os = windows, severity = x86, creation_date = 2022-05-09, scan_context = file, memory, license = Elastic License v2, threat_name = Windows.Trojan.Emotet, fingerprint = eac196154ab1ad636654c966e860dcd5763c50d7b8221dbbc7769c879daf02fd, id = db7d33fa-e50c-4c59-ab92-edb74aac87c9, last_modified = 2022-06-09 |
Source: 0.3.ts.exe.228233eea14.0.unpack, type: UNPACKEDPE |
Matched rule: Windows_Trojan_Emotet_db7d33fa reference_sample = 08c23400ff546db41f9ddbbb19fa75519826744dde3b3afb38f3985266577afc, os = windows, severity = x86, creation_date = 2022-05-09, scan_context = file, memory, license = Elastic License v2, threat_name = Windows.Trojan.Emotet, fingerprint = eac196154ab1ad636654c966e860dcd5763c50d7b8221dbbc7769c879daf02fd, id = db7d33fa-e50c-4c59-ab92-edb74aac87c9, last_modified = 2022-06-09 |
Source: 0.3.ts.exe.228231c0000.3.raw.unpack, type: UNPACKEDPE |
Matched rule: Windows_Trojan_Emotet_db7d33fa reference_sample = 08c23400ff546db41f9ddbbb19fa75519826744dde3b3afb38f3985266577afc, os = windows, severity = x86, creation_date = 2022-05-09, scan_context = file, memory, license = Elastic License v2, threat_name = Windows.Trojan.Emotet, fingerprint = eac196154ab1ad636654c966e860dcd5763c50d7b8221dbbc7769c879daf02fd, id = db7d33fa-e50c-4c59-ab92-edb74aac87c9, last_modified = 2022-06-09 |
Source: 0.2.ts.exe.7ffa0aed0000.2.unpack, type: UNPACKEDPE |
Matched rule: Windows_Trojan_Emotet_db7d33fa reference_sample = 08c23400ff546db41f9ddbbb19fa75519826744dde3b3afb38f3985266577afc, os = windows, severity = x86, creation_date = 2022-05-09, scan_context = file, memory, license = Elastic License v2, threat_name = Windows.Trojan.Emotet, fingerprint = eac196154ab1ad636654c966e860dcd5763c50d7b8221dbbc7769c879daf02fd, id = db7d33fa-e50c-4c59-ab92-edb74aac87c9, last_modified = 2022-06-09 |
Source: 0.3.ts.exe.228233ca850.1.raw.unpack, type: UNPACKEDPE |
Matched rule: Windows_Trojan_Emotet_db7d33fa reference_sample = 08c23400ff546db41f9ddbbb19fa75519826744dde3b3afb38f3985266577afc, os = windows, severity = x86, creation_date = 2022-05-09, scan_context = file, memory, license = Elastic License v2, threat_name = Windows.Trojan.Emotet, fingerprint = eac196154ab1ad636654c966e860dcd5763c50d7b8221dbbc7769c879daf02fd, id = db7d33fa-e50c-4c59-ab92-edb74aac87c9, last_modified = 2022-06-09 |
Source: 0.3.ts.exe.228233eea14.0.raw.unpack, type: UNPACKEDPE |
Matched rule: Windows_Trojan_Emotet_db7d33fa reference_sample = 08c23400ff546db41f9ddbbb19fa75519826744dde3b3afb38f3985266577afc, os = windows, severity = x86, creation_date = 2022-05-09, scan_context = file, memory, license = Elastic License v2, threat_name = Windows.Trojan.Emotet, fingerprint = eac196154ab1ad636654c966e860dcd5763c50d7b8221dbbc7769c879daf02fd, id = db7d33fa-e50c-4c59-ab92-edb74aac87c9, last_modified = 2022-06-09 |
Source: 0.3.ts.exe.22823350000.2.raw.unpack, type: UNPACKEDPE |
Matched rule: Windows_Trojan_Emotet_db7d33fa reference_sample = 08c23400ff546db41f9ddbbb19fa75519826744dde3b3afb38f3985266577afc, os = windows, severity = x86, creation_date = 2022-05-09, scan_context = file, memory, license = Elastic License v2, threat_name = Windows.Trojan.Emotet, fingerprint = eac196154ab1ad636654c966e860dcd5763c50d7b8221dbbc7769c879daf02fd, id = db7d33fa-e50c-4c59-ab92-edb74aac87c9, last_modified = 2022-06-09 |
Source: 00000000.00000002.562441647.00007FFA0AED1000.00000020.00000001.01000000.00000004.sdmp, type: MEMORY |
Matched rule: Windows_Trojan_Emotet_db7d33fa reference_sample = 08c23400ff546db41f9ddbbb19fa75519826744dde3b3afb38f3985266577afc, os = windows, severity = x86, creation_date = 2022-05-09, scan_context = file, memory, license = Elastic License v2, threat_name = Windows.Trojan.Emotet, fingerprint = eac196154ab1ad636654c966e860dcd5763c50d7b8221dbbc7769c879daf02fd, id = db7d33fa-e50c-4c59-ab92-edb74aac87c9, last_modified = 2022-06-09 |
Source: 00000000.00000003.299862162.00000228231C0000.00000004.00001000.00020000.00000000.sdmp, type: MEMORY |
Matched rule: Windows_Trojan_Emotet_db7d33fa reference_sample = 08c23400ff546db41f9ddbbb19fa75519826744dde3b3afb38f3985266577afc, os = windows, severity = x86, creation_date = 2022-05-09, scan_context = file, memory, license = Elastic License v2, threat_name = Windows.Trojan.Emotet, fingerprint = eac196154ab1ad636654c966e860dcd5763c50d7b8221dbbc7769c879daf02fd, id = db7d33fa-e50c-4c59-ab92-edb74aac87c9, last_modified = 2022-06-09 |
Source: 00000000.00000003.299383409.0000022823350000.00000004.00001000.00020000.00000000.sdmp, type: MEMORY |
Matched rule: Windows_Trojan_Emotet_db7d33fa reference_sample = 08c23400ff546db41f9ddbbb19fa75519826744dde3b3afb38f3985266577afc, os = windows, severity = x86, creation_date = 2022-05-09, scan_context = file, memory, license = Elastic License v2, threat_name = Windows.Trojan.Emotet, fingerprint = eac196154ab1ad636654c966e860dcd5763c50d7b8221dbbc7769c879daf02fd, id = db7d33fa-e50c-4c59-ab92-edb74aac87c9, last_modified = 2022-06-09 |
Source: C:\Users\user\Desktop\62366813.dll, type: DROPPED |
Matched rule: Windows_Trojan_Emotet_db7d33fa reference_sample = 08c23400ff546db41f9ddbbb19fa75519826744dde3b3afb38f3985266577afc, os = windows, severity = x86, creation_date = 2022-05-09, scan_context = file, memory, license = Elastic License v2, threat_name = Windows.Trojan.Emotet, fingerprint = eac196154ab1ad636654c966e860dcd5763c50d7b8221dbbc7769c879daf02fd, id = db7d33fa-e50c-4c59-ab92-edb74aac87c9, last_modified = 2022-06-09 |
Source: C:\Users\user\Desktop\ts.exe |
Code function: 0_2_00007FF7A58A46E8 |
0_2_00007FF7A58A46E8 |
Source: C:\Users\user\Desktop\ts.exe |
Code function: 0_2_00007FF7A5883DF0 |
0_2_00007FF7A5883DF0 |
Source: C:\Users\user\Desktop\ts.exe |
Code function: 0_2_00007FF7A58C6D94 |
0_2_00007FF7A58C6D94 |
Source: C:\Users\user\Desktop\ts.exe |
Code function: 0_2_00007FF7A5890B06 |
0_2_00007FF7A5890B06 |
Source: C:\Users\user\Desktop\ts.exe |
Code function: 0_2_00007FF7A58A3A40 |
0_2_00007FF7A58A3A40 |
Source: C:\Users\user\Desktop\ts.exe |
Code function: 0_2_00007FF7A58DAEB0 |
0_2_00007FF7A58DAEB0 |
Source: C:\Users\user\Desktop\ts.exe |
Code function: 0_2_00007FF7A588EEF4 |
0_2_00007FF7A588EEF4 |
Source: C:\Users\user\Desktop\ts.exe |
Code function: 0_2_00007FF7A58BD668 |
0_2_00007FF7A58BD668 |
Source: C:\Users\user\Desktop\ts.exe |
Code function: 0_2_00007FF7A58BC5A0 |
0_2_00007FF7A58BC5A0 |
Source: C:\Users\user\Desktop\ts.exe |
Code function: 0_2_00007FF7A58BCDD0 |
0_2_00007FF7A58BCDD0 |
Source: C:\Users\user\Desktop\ts.exe |
Code function: 0_2_00007FF7A588DDE8 |
0_2_00007FF7A588DDE8 |
Source: C:\Users\user\Desktop\ts.exe |
Code function: 0_2_00007FF7A58CE614 |
0_2_00007FF7A58CE614 |
Source: C:\Users\user\Desktop\ts.exe |
Code function: 0_2_00007FF7A5897D18 |
0_2_00007FF7A5897D18 |
Source: C:\Users\user\Desktop\ts.exe |
Code function: 0_2_00007FF7A58C053C |
0_2_00007FF7A58C053C |
Source: C:\Users\user\Desktop\ts.exe |
Code function: 0_2_00007FF7A58CFD5C |
0_2_00007FF7A58CFD5C |
Source: C:\Users\user\Desktop\ts.exe |
Code function: 0_2_00007FF7A58C6830 |
0_2_00007FF7A58C6830 |
Source: C:\Users\user\Desktop\ts.exe |
Code function: 0_2_00007FF7A5890024 |
0_2_00007FF7A5890024 |
Source: C:\Users\user\Desktop\ts.exe |
Code function: 0_2_00007FF7A58CC854 |
0_2_00007FF7A58CC854 |
Source: C:\Users\user\Desktop\ts.exe |
Code function: 0_2_00007FF7A58D8848 |
0_2_00007FF7A58D8848 |
Source: C:\Users\user\Desktop\ts.exe |
Code function: 0_2_00007FF7A588D7CC |
0_2_00007FF7A588D7CC |
Source: C:\Users\user\Desktop\ts.exe |
Code function: 0_2_00007FF7A5885FC0 |
0_2_00007FF7A5885FC0 |
Source: C:\Users\user\Desktop\ts.exe |
Code function: 0_2_00007FF7A58BF7F4 |
0_2_00007FF7A58BF7F4 |
Source: C:\Users\user\Desktop\ts.exe |
Code function: 0_2_00007FF7A58BC788 |
0_2_00007FF7A58BC788 |
Source: C:\Users\user\Desktop\ts.exe |
Code function: 0_2_00007FF7A5882F80 |
0_2_00007FF7A5882F80 |
Source: C:\Users\user\Desktop\ts.exe |
Code function: 0_2_00007FF7A58CE164 |
0_2_00007FF7A58CE164 |
Source: C:\Users\user\Desktop\ts.exe |
Code function: 0_2_00007FF7A58BD160 |
0_2_00007FF7A58BD160 |
Source: C:\Users\user\Desktop\ts.exe |
Code function: 0_2_00007FF7A58CEC94 |
0_2_00007FF7A58CEC94 |
Source: C:\Users\user\Desktop\ts.exe |
Code function: 0_2_00007FF7A58BC3B8 |
0_2_00007FF7A58BC3B8 |
Source: C:\Users\user\Desktop\ts.exe |
Code function: 0_2_00007FF7A5894400 |
0_2_00007FF7A5894400 |
Source: C:\Users\user\Desktop\ts.exe |
Code function: 0_2_00007FFA0AED61F4 |
0_2_00007FFA0AED61F4 |
Source: C:\Users\user\Desktop\ts.exe |
Code function: 0_2_00007FFA0AEE5F68 |
0_2_00007FFA0AEE5F68 |
Source: C:\Users\user\Desktop\ts.exe |
Code function: 0_2_00007FFA0AED3750 |
0_2_00007FFA0AED3750 |
Source: C:\Users\user\Desktop\ts.exe |
Code function: 0_2_00007FFA0AEDF51C |
0_2_00007FFA0AEDF51C |
Source: C:\Users\user\Desktop\ts.exe |
Code function: 0_2_00007FFA0AED3518 |
0_2_00007FFA0AED3518 |
Source: C:\Users\user\Desktop\ts.exe |
Code function: 0_2_00007FFA0AED66AC |
0_2_00007FFA0AED66AC |
Source: C:\Users\user\Desktop\ts.exe |
Code function: 0_2_00007FFA0AED765C |
0_2_00007FFA0AED765C |
Source: C:\Users\user\Desktop\ts.exe |
Code function: 0_2_00007FFA0AEE5B54 |
0_2_00007FFA0AEE5B54 |
Source: C:\Users\user\Desktop\ts.exe |
Code function: 0_2_00007FFA0AED7AF0 |
0_2_00007FFA0AED7AF0 |
Source: C:\Users\user\Desktop\ts.exe |
Code function: 0_2_00007FFA0AEE4AE4 |
0_2_00007FFA0AEE4AE4 |
Source: C:\Users\user\Desktop\ts.exe |
Code function: 0_2_00007FFA0AEDC480 |
0_2_00007FFA0AEDC480 |
Source: C:\Users\user\Desktop\ts.exe |
Code function: 0_2_00007FFA0AEE443C |
0_2_00007FFA0AEE443C |
Source: C:\Users\user\Desktop\ts.exe |
Code function: 0_2_00007FFA0AED6428 |
0_2_00007FFA0AED6428 |
Source: C:\Users\user\Desktop\ts.exe |
Code function: 0_2_00007FFA0AED8BDC |
0_2_00007FFA0AED8BDC |
Source: C:\Users\user\Desktop\ts.exe |
Code function: 0_2_00007FFA0AEE03D8 |
0_2_00007FFA0AEE03D8 |
Source: C:\Users\user\Desktop\ts.exe |
Code function: 0_2_00007FFA0AEE1960 |
0_2_00007FFA0AEE1960 |
Source: C:\Users\user\Desktop\ts.exe |
Code function: 0_2_00007FFA0AEE415C |
0_2_00007FFA0AEE415C |
Source: C:\Users\user\Desktop\ts.exe |
Code function: 0_2_00007FFA0AEDB134 |
0_2_00007FFA0AEDB134 |
Source: C:\Users\user\Desktop\ts.exe |
Code function: 0_2_00007FFA0AED1924 |
0_2_00007FFA0AED1924 |
Source: C:\Users\user\Desktop\ts.exe |
Code function: 0_2_00007FFA0AED7908 |
0_2_00007FFA0AED7908 |
Source: C:\Users\user\Desktop\ts.exe |
Code function: 0_2_00007FFA0AEDF28C |
0_2_00007FFA0AEDF28C |
Source: C:\Users\user\Desktop\ts.exe |
Code function: 0_2_00007FFA0AED525C |
0_2_00007FFA0AED525C |
Source: C:\Users\user\Desktop\ts.exe |
Code function: 0_2_00007FFA0AEDCA5C |
0_2_00007FFA0AEDCA5C |
Source: C:\Users\user\Desktop\ts.exe |
Code function: 0_2_00007FFA0AEE5A40 |
0_2_00007FFA0AEE5A40 |
Source: C:\Users\user\Desktop\ts.exe |
Code function: 0_2_00007FFA0AEDE234 |
0_2_00007FFA0AEDE234 |
Source: C:\Users\user\Desktop\ts.exe |
Code function: 0_2_00007FFA0AEDD1E8 |
0_2_00007FFA0AEDD1E8 |
Source: C:\Users\user\Desktop\ts.exe |
Code function: 0_2_00007FFA0AED49E4 |
0_2_00007FFA0AED49E4 |
Source: C:\Users\user\Desktop\ts.exe |
Code function: 0_2_00007FFA0AED89D0 |
0_2_00007FFA0AED89D0 |
Source: C:\Users\user\Desktop\ts.exe |
Code function: 0_2_00007FFA0AED17A0 |
0_2_00007FFA0AED17A0 |
Source: C:\Users\user\Desktop\ts.exe |
Code function: 0_2_00007FFA0AEDBF78 |
0_2_00007FFA0AEDBF78 |
Source: C:\Users\user\Desktop\ts.exe |
Code function: 0_2_00007FFA0AEDD710 |
0_2_00007FFA0AEDD710 |
Source: C:\Users\user\Desktop\ts.exe |
Code function: 0_2_00007FFA0AEDE090 |
0_2_00007FFA0AEDE090 |
Source: C:\Users\user\Desktop\ts.exe |
Code function: 0_2_00007FFA0AEE3858 |
0_2_00007FFA0AEE3858 |
Source: C:\Users\user\Desktop\ts.exe |
Code function: 0_2_00007FFA0AEE3050 |
0_2_00007FFA0AEE3050 |
Source: C:\Users\user\Desktop\ts.exe |
Code function: 0_2_00007FFA0AEDF028 |
0_2_00007FFA0AEDF028 |
Source: C:\Users\user\Desktop\ts.exe |
Code function: 0_2_00007FFA0AED9FD0 |
0_2_00007FFA0AED9FD0 |
Source: C:\Users\user\Desktop\ts.exe |
Code function: 0_2_00007FFA0AEDDDA0 |
0_2_00007FFA0AEDDDA0 |
Source: C:\Users\user\Desktop\ts.exe |
Code function: 0_2_00007FFA0AEDCD9C |
0_2_00007FFA0AEDCD9C |
Source: C:\Users\user\Desktop\ts.exe |
Code function: 0_2_00007FFA0AED9D68 |
0_2_00007FFA0AED9D68 |
Source: C:\Users\user\Desktop\ts.exe |
Code function: 0_2_00007FFA0AED6548 |
0_2_00007FFA0AED6548 |
Source: C:\Users\user\Desktop\ts.exe |
Code function: 0_2_00007FFA0AEE0D2C |
0_2_00007FFA0AEE0D2C |
Source: C:\Users\user\Desktop\ts.exe |
Code function: 0_2_00007FFA0AED250C |
0_2_00007FFA0AED250C |
Source: C:\Users\user\Desktop\ts.exe |
Code function: 0_2_00007FFA0AED5D08 |
0_2_00007FFA0AED5D08 |
Source: C:\Users\user\Desktop\ts.exe |
Code function: 0_2_00007FFA0AEDB4F0 |
0_2_00007FFA0AEDB4F0 |
Source: C:\Users\user\Desktop\ts.exe |
Code function: 0_2_00007FFA0AEE1E88 |
0_2_00007FFA0AEE1E88 |
Source: C:\Users\user\Desktop\ts.exe |
Code function: 0_2_00007FFA0AED5668 |
0_2_00007FFA0AED5668 |
Source: C:\Users\user\Desktop\ts.exe |
Code function: 0_2_00007FFA0AED8648 |
0_2_00007FFA0AED8648 |
Source: C:\Users\user\Desktop\ts.exe |
Code function: 0_2_00007FFA0AED4604 |
0_2_00007FFA0AED4604 |
Source: C:\Users\user\Desktop\ts.exe |
Code function: 0_2_00007FFA0AEE45F0 |
0_2_00007FFA0AEE45F0 |
Source: C:\Users\user\Desktop\ts.exe |
Code function: 0_2_00007FFA0AEE05C4 |
0_2_00007FFA0AEE05C4 |
Source: C:\Users\user\Desktop\ts.exe |
Code function: 0_2_00007FF7A588B110 SetUnhandledExceptionFilter,_invalid_parameter_noinfo, |
0_2_00007FF7A588B110 |
Source: C:\Users\user\Desktop\ts.exe |
Code function: 0_2_00007FF7A588B710 SetUnhandledExceptionFilter, |
0_2_00007FF7A588B710 |
Source: C:\Users\user\Desktop\ts.exe |
Code function: 0_2_00007FF7A588B568 IsProcessorFeaturePresent,RtlCaptureContext,RtlLookupFunctionEntry,RtlVirtualUnwind,IsDebuggerPresent,SetUnhandledExceptionFilter,UnhandledExceptionFilter, |
0_2_00007FF7A588B568 |
Source: C:\Users\user\Desktop\ts.exe |
Code function: 0_2_00007FF7A588B2BC SetUnhandledExceptionFilter,UnhandledExceptionFilter,GetCurrentProcess,TerminateProcess, |
0_2_00007FF7A588B2BC |
Source: C:\Users\user\Desktop\ts.exe |
Code function: 0_2_00007FF7A58BE50C RtlCaptureContext,RtlLookupFunctionEntry,RtlVirtualUnwind,IsDebuggerPresent,SetUnhandledExceptionFilter,UnhandledExceptionFilter, |
0_2_00007FF7A58BE50C |
Source: C:\Users\user\Desktop\ts.exe |
Code function: GetLocaleInfoEx, |
0_2_00007FF7A58B4F3C |
Source: C:\Users\user\Desktop\ts.exe |
Code function: EnumSystemLocalesW, |
0_2_00007FF7A58D26B4 |
Source: C:\Users\user\Desktop\ts.exe |
Code function: TranslateName,TranslateName,GetACP,IsValidCodePage,GetLocaleInfoW, |
0_2_00007FF7A58D5898 |
Source: C:\Users\user\Desktop\ts.exe |
Code function: GetLocaleInfoW,GetLocaleInfoW,GetACP, |
0_2_00007FF7A58D60F0 |
Source: C:\Users\user\Desktop\ts.exe |
Code function: EnumSystemLocalesW,GetUserDefaultLCID,ProcessCodePage,IsValidCodePage,IsValidLocale,GetLocaleInfoW,GetLocaleInfoW, |
0_2_00007FF7A58D62CC |
Source: C:\Users\user\Desktop\ts.exe |
Code function: EnumSystemLocalesW, |
0_2_00007FF7A58D5CB4 |
Source: C:\Users\user\Desktop\ts.exe |
Code function: EnumSystemLocalesW, |
0_2_00007FF7A58D5BE4 |
Source: C:\Users\user\Desktop\ts.exe |
Code function: GetLocaleInfoW, |
0_2_00007FF7A58D2BF8 |
Source: Yara match |
File source: ts.exe, type: SAMPLE |
Source: Yara match |
File source: 0.3.ts.exe.228231c0000.3.unpack, type: UNPACKEDPE |
Source: Yara match |
File source: 0.3.ts.exe.228233eea14.0.unpack, type: UNPACKEDPE |
Source: Yara match |
File source: 0.3.ts.exe.228231c0000.3.raw.unpack, type: UNPACKEDPE |
Source: Yara match |
File source: 0.2.ts.exe.7ffa0aed0000.2.unpack, type: UNPACKEDPE |
Source: Yara match |
File source: 0.3.ts.exe.228233ca850.1.raw.unpack, type: UNPACKEDPE |
Source: Yara match |
File source: 0.3.ts.exe.228233eea14.0.raw.unpack, type: UNPACKEDPE |
Source: Yara match |
File source: 0.3.ts.exe.22823350000.2.raw.unpack, type: UNPACKEDPE |
Source: Yara match |
File source: 00000000.00000002.562441647.00007FFA0AED1000.00000020.00000001.01000000.00000004.sdmp, type: MEMORY |
Source: Yara match |
File source: 00000000.00000003.299862162.00000228231C0000.00000004.00001000.00020000.00000000.sdmp, type: MEMORY |
Source: Yara match |
File source: 00000000.00000003.299383409.0000022823350000.00000004.00001000.00020000.00000000.sdmp, type: MEMORY |
Source: Yara match |
File source: C:\Users\user\Desktop\62366813.dll, type: DROPPED |