Loading Joe Sandbox Report ...

Edit tour

Windows Analysis Report
SecuriteInfo.com.Win32.CrypterX-gen.16304.13478.exe

Overview

General Information

Sample Name:SecuriteInfo.com.Win32.CrypterX-gen.16304.13478.exe
Analysis ID:755894
MD5:2c37cb553314943214dc79d2d5cd95d2
SHA1:8d729ace154aae255cc7d20e0038889c1a16b30b
SHA256:5cfdb9f856907336025bbd526f7383ae8edbce669348b8e330251dfe21072c8f
Tags:exe
Infos:

Detection

FormBook
Score:100
Range:0 - 100
Whitelisted:false
Confidence:100%

Signatures

Multi AV Scanner detection for submitted file
Yara detected FormBook
Malicious sample detected (through community Yara rule)
Yara detected AntiVM3
Antivirus detection for URL or domain
Tries to detect sandboxes and other dynamic analysis tools (process name or module or function)
Machine Learning detection for sample
Injects a PE file into a foreign processes
Tries to detect virtualization through RDTSC time measurements
C2 URLs / IPs found in malware configuration
Uses 32bit PE files
Queries the volume information (name, serial number etc) of a device
Yara signature match
Antivirus or Machine Learning detection for unpacked file
May sleep (evasive loops) to hinder dynamic analysis
Uses code obfuscation techniques (call, push, ret)
Detected potential crypto function
Found potential string decryption / allocating functions
Contains functionality to call native functions
Contains functionality for execution timing, often used to detect debuggers
Contains long sleeps (>= 3 min)
Creates a DirectInput object (often for capturing keystrokes)
Sample file is different than original file name gathered from version info
Contains functionality to read the PEB
Checks if the current process is being debugged
Found large amount of non-executed APIs
Creates a process in suspended mode (likely to inject code)
Contains functionality to access loader functionality (e.g. LdrGetProcedureAddress)

Classification

  • System is w10x64
  • cleanup
{"C2 list": ["www.2635westkaylaneprescott.com/ndgi/"], "decoy": ["vuicotvxrejp3il.xyz", "w3fa6.net", "sappuno02.com", "konstruksirumah.xyz", "usalifehealth.com", "and1f.xyz", "atenmentfstinfdow.beauty", "primepipe.net", "roundhouseny.com", "alexandermcqueen.icu", "transporteavalos.com", "spankmetaverse.xyz", "jhccowholesale.com", "bielefeldgebaeudereinigung.com", "saintraphaelschool.com", "larifaa.online", "dejabrew.info", "izabelaeraphael.com", "granniestoneet.com", "greensourceseed.com", "jawaahirulhikmah.com", "2lipcolours.com", "ginzou.com", "vestradgivning.online", "atlasdublinresidence.com", "bfine.xyz", "decision-art.com", "nicebayloans.com", "pendingissue.biz", "troiancircular.com", "raftingtennesssee.com", "autistal.xyz", "purposeinplans.com", "socofm.com", "dafuweng0471.com", "transformcoach.info", "vugz.info", "isabellesroom.com", "kasdawerf.xyz", "angelicindia.com", "jmakerpumploc.com", "departmen.store", "kalpataruplotsariaplots.net", "mosqueenarbonne.com", "tititinews.com", "santeoglobal.com", "cornharvestdirect.com", "chickensoesco.com", "softelbow30.com", "fuxeonfire.com", "soospeter.com", "lastikfiyatlari.online", "northlandproshop.com", "youbelongstojoy.com", "asfalt-podrezkovo.store", "servequin.com", "heti.ink", "gulfingroupinvest.com", "gastries.info", "spunklane.com", "acompanhanteslux.com", "bbti.world", "juiceofjoy.com", "tlaaccounting.net"]}
SourceRuleDescriptionAuthorStrings
00000000.00000002.268979891.0000000003549000.00000004.00000800.00020000.00000000.sdmpJoeSecurity_AntiVM_3Yara detected AntiVM_3Joe Security
    00000001.00000000.262712520.0000000000401000.00000040.00000400.00020000.00000000.sdmpJoeSecurity_FormBookYara detected FormBookJoe Security
      00000001.00000000.262712520.0000000000401000.00000040.00000400.00020000.00000000.sdmpWindows_Trojan_Formbook_1112e116unknownunknown
      • 0x5251:$a1: 3C 30 50 4F 53 54 74 09 40
      • 0x1bb80:$a2: 74 0A 4E 0F B6 08 8D 44 08 01 75 F6 8D 70 01 0F B6 00 8D 55
      • 0x99bf:$a3: 1A D2 80 E2 AF 80 C2 7E EB 2A 80 FA 2F 75 11 8A D0 80 E2 01
      • 0x148a7:$a4: 04 83 C4 0C 83 06 07 5B 5F 5E 8B E5 5D C3 8B 17 03 55 0C 6A 01 83
      00000001.00000000.262712520.0000000000401000.00000040.00000400.00020000.00000000.sdmpFormbook_1autogenerated rule brought to you by yara-signatorFelix Bilstein - yara-signator at cocacoding dot com
      • 0x8908:$sequence_0: 03 C8 0F 31 2B C1 89 45 FC
      • 0x8b72:$sequence_0: 03 C8 0F 31 2B C1 89 45 FC
      • 0x146a5:$sequence_1: 3C 24 0F 84 76 FF FF FF 3C 25 74 94
      • 0x14191:$sequence_2: 3B 4F 14 73 95 85 C9 74 91
      • 0x147a7:$sequence_3: 3C 69 75 44 8B 7D 18 8B 0F
      • 0x1491f:$sequence_4: 5D C3 8D 50 7C 80 FA 07
      • 0x958a:$sequence_5: 0F BE 5C 0E 01 0F B6 54 0E 02 83 E3 0F C1 EA 06
      • 0x1340c:$sequence_6: 57 89 45 FC 89 45 F4 89 45 F8
      • 0xa283:$sequence_7: 66 89 0C 02 5B 8B E5 5D
      • 0x1a8e7:$sequence_8: 3C 54 74 04 3C 74 75 F4
      • 0x1b8ea:$sequence_9: 56 68 03 01 00 00 8D 85 95 FE FF FF 6A 00
      00000001.00000000.262712520.0000000000401000.00000040.00000400.00020000.00000000.sdmpFormbookdetect Formbook in memoryJPCERT/CC Incident Response Group
      • 0x17809:$sqlite3step: 68 34 1C 7B E1
      • 0x1791c:$sqlite3step: 68 34 1C 7B E1
      • 0x17838:$sqlite3text: 68 38 2A 90 C5
      • 0x1795d:$sqlite3text: 68 38 2A 90 C5
      • 0x1784b:$sqlite3blob: 68 53 D8 7F 8C
      • 0x17973:$sqlite3blob: 68 53 D8 7F 8C
      Click to see the 8 entries
      SourceRuleDescriptionAuthorStrings
      1.0.SecuriteInfo.com.Win32.CrypterX-gen.16304.13478.exe.400000.0.unpackJoeSecurity_FormBookYara detected FormBookJoe Security
        1.0.SecuriteInfo.com.Win32.CrypterX-gen.16304.13478.exe.400000.0.unpackWindows_Trojan_Formbook_1112e116unknownunknown
        • 0x5451:$a1: 3C 30 50 4F 53 54 74 09 40
        • 0x1bd80:$a2: 74 0A 4E 0F B6 08 8D 44 08 01 75 F6 8D 70 01 0F B6 00 8D 55
        • 0x9bbf:$a3: 1A D2 80 E2 AF 80 C2 7E EB 2A 80 FA 2F 75 11 8A D0 80 E2 01
        • 0x14aa7:$a4: 04 83 C4 0C 83 06 07 5B 5F 5E 8B E5 5D C3 8B 17 03 55 0C 6A 01 83
        1.0.SecuriteInfo.com.Win32.CrypterX-gen.16304.13478.exe.400000.0.unpackFormbook_1autogenerated rule brought to you by yara-signatorFelix Bilstein - yara-signator at cocacoding dot com
        • 0x8b08:$sequence_0: 03 C8 0F 31 2B C1 89 45 FC
        • 0x8d72:$sequence_0: 03 C8 0F 31 2B C1 89 45 FC
        • 0x148a5:$sequence_1: 3C 24 0F 84 76 FF FF FF 3C 25 74 94
        • 0x14391:$sequence_2: 3B 4F 14 73 95 85 C9 74 91
        • 0x149a7:$sequence_3: 3C 69 75 44 8B 7D 18 8B 0F
        • 0x14b1f:$sequence_4: 5D C3 8D 50 7C 80 FA 07
        • 0x978a:$sequence_5: 0F BE 5C 0E 01 0F B6 54 0E 02 83 E3 0F C1 EA 06
        • 0x1360c:$sequence_6: 57 89 45 FC 89 45 F4 89 45 F8
        • 0xa483:$sequence_7: 66 89 0C 02 5B 8B E5 5D
        • 0x1aae7:$sequence_8: 3C 54 74 04 3C 74 75 F4
        • 0x1baea:$sequence_9: 56 68 03 01 00 00 8D 85 95 FE FF FF 6A 00
        1.0.SecuriteInfo.com.Win32.CrypterX-gen.16304.13478.exe.400000.0.unpackFormbookdetect Formbook in memoryJPCERT/CC Incident Response Group
        • 0x17a09:$sqlite3step: 68 34 1C 7B E1
        • 0x17b1c:$sqlite3step: 68 34 1C 7B E1
        • 0x17a38:$sqlite3text: 68 38 2A 90 C5
        • 0x17b5d:$sqlite3text: 68 38 2A 90 C5
        • 0x17a4b:$sqlite3blob: 68 53 D8 7F 8C
        • 0x17b73:$sqlite3blob: 68 53 D8 7F 8C
        0.2.SecuriteInfo.com.Win32.CrypterX-gen.16304.13478.exe.3282f54.1.raw.unpackJoeSecurity_AntiVM_3Yara detected AntiVM_3Joe Security
          Click to see the 11 entries
          No Sigma rule has matched
          No Snort rule has matched

          Click to jump to signature section

          Show All Signature Results

          AV Detection

          barindex
          Source: SecuriteInfo.com.Win32.CrypterX-gen.16304.13478.exeReversingLabs: Detection: 29%
          Source: Yara matchFile source: 1.0.SecuriteInfo.com.Win32.CrypterX-gen.16304.13478.exe.400000.0.unpack, type: UNPACKEDPE
          Source: Yara matchFile source: 0.2.SecuriteInfo.com.Win32.CrypterX-gen.16304.13478.exe.44aef60.6.raw.unpack, type: UNPACKEDPE
          Source: Yara matchFile source: 0.2.SecuriteInfo.com.Win32.CrypterX-gen.16304.13478.exe.45233b0.5.raw.unpack, type: UNPACKEDPE
          Source: Yara matchFile source: 00000001.00000000.262712520.0000000000401000.00000040.00000400.00020000.00000000.sdmp, type: MEMORY
          Source: Yara matchFile source: 00000000.00000002.270529665.00000000044AE000.00000004.00000800.00020000.00000000.sdmp, type: MEMORY
          Source: www.2635westkaylaneprescott.com/ndgi/Avira URL Cloud: Label: malware
          Source: SecuriteInfo.com.Win32.CrypterX-gen.16304.13478.exeJoe Sandbox ML: detected
          Source: 1.0.SecuriteInfo.com.Win32.CrypterX-gen.16304.13478.exe.400000.0.unpackAvira: Label: TR/Crypt.ZPACK.Gen
          Source: 00000000.00000002.270529665.00000000044AE000.00000004.00000800.00020000.00000000.sdmpMalware Configuration Extractor: FormBook {"C2 list": ["www.2635westkaylaneprescott.com/ndgi/"], "decoy": ["vuicotvxrejp3il.xyz", "w3fa6.net", "sappuno02.com", "konstruksirumah.xyz", "usalifehealth.com", "and1f.xyz", "atenmentfstinfdow.beauty", "primepipe.net", "roundhouseny.com", "alexandermcqueen.icu", "transporteavalos.com", "spankmetaverse.xyz", "jhccowholesale.com", "bielefeldgebaeudereinigung.com", "saintraphaelschool.com", "larifaa.online", "dejabrew.info", "izabelaeraphael.com", "granniestoneet.com", "greensourceseed.com", "jawaahirulhikmah.com", "2lipcolours.com", "ginzou.com", "vestradgivning.online", "atlasdublinresidence.com", "bfine.xyz", "decision-art.com", "nicebayloans.com", "pendingissue.biz", "troiancircular.com", "raftingtennesssee.com", "autistal.xyz", "purposeinplans.com", "socofm.com", "dafuweng0471.com", "transformcoach.info", "vugz.info", "isabellesroom.com", "kasdawerf.xyz", "angelicindia.com", "jmakerpumploc.com", "departmen.store", "kalpataruplotsariaplots.net", "mosqueenarbonne.com", "tititinews.com", "santeoglobal.com", "cornharvestdirect.com", "chickensoesco.com", "softelbow30.com", "fuxeonfire.com", "soospeter.com", "lastikfiyatlari.online", "northlandproshop.com", "youbelongstojoy.com", "asfalt-podrezkovo.store", "servequin.com", "heti.ink", "gulfingroupinvest.com", "gastries.info", "spunklane.com", "acompanhanteslux.com", "bbti.world", "juiceofjoy.com", "tlaaccounting.net"]}
          Source: SecuriteInfo.com.Win32.CrypterX-gen.16304.13478.exeStatic PE information: EXECUTABLE_IMAGE, 32BIT_MACHINE
          Source: SecuriteInfo.com.Win32.CrypterX-gen.16304.13478.exeStatic PE information: DYNAMIC_BASE, NX_COMPAT, NO_SEH, TERMINAL_SERVER_AWARE
          Source: Binary string: wntdll.pdbUGP source: SecuriteInfo.com.Win32.CrypterX-gen.16304.13478.exe, 00000001.00000002.267578947.0000000001510000.00000040.00000800.00020000.00000000.sdmp, SecuriteInfo.com.Win32.CrypterX-gen.16304.13478.exe, 00000001.00000003.265561008.0000000001371000.00000004.00000800.00020000.00000000.sdmp, SecuriteInfo.com.Win32.CrypterX-gen.16304.13478.exe, 00000001.00000003.263133405.00000000011D4000.00000004.00000800.00020000.00000000.sdmp
          Source: Binary string: wntdll.pdb source: SecuriteInfo.com.Win32.CrypterX-gen.16304.13478.exe, SecuriteInfo.com.Win32.CrypterX-gen.16304.13478.exe, 00000001.00000002.267578947.0000000001510000.00000040.00000800.00020000.00000000.sdmp, SecuriteInfo.com.Win32.CrypterX-gen.16304.13478.exe, 00000001.00000003.265561008.0000000001371000.00000004.00000800.00020000.00000000.sdmp, SecuriteInfo.com.Win32.CrypterX-gen.16304.13478.exe, 00000001.00000003.263133405.00000000011D4000.00000004.00000800.00020000.00000000.sdmp

          Networking

          barindex
          Source: Malware configuration extractorURLs: www.2635westkaylaneprescott.com/ndgi/
          Source: SecuriteInfo.com.Win32.CrypterX-gen.16304.13478.exe, 00000000.00000002.272505714.0000000007232000.00000004.00000800.00020000.00000000.sdmpString found in binary or memory: http://fontfabrik.com
          Source: SecuriteInfo.com.Win32.CrypterX-gen.16304.13478.exe, 00000000.00000002.272505714.0000000007232000.00000004.00000800.00020000.00000000.sdmpString found in binary or memory: http://www.apache.org/licenses/LICENSE-2.0
          Source: SecuriteInfo.com.Win32.CrypterX-gen.16304.13478.exe, 00000000.00000002.272505714.0000000007232000.00000004.00000800.00020000.00000000.sdmpString found in binary or memory: http://www.carterandcone.coml
          Source: SecuriteInfo.com.Win32.CrypterX-gen.16304.13478.exe, 00000000.00000002.272505714.0000000007232000.00000004.00000800.00020000.00000000.sdmpString found in binary or memory: http://www.fontbureau.com
          Source: SecuriteInfo.com.Win32.CrypterX-gen.16304.13478.exe, 00000000.00000002.272505714.0000000007232000.00000004.00000800.00020000.00000000.sdmpString found in binary or memory: http://www.fontbureau.com/designers
          Source: SecuriteInfo.com.Win32.CrypterX-gen.16304.13478.exe, 00000000.00000002.272505714.0000000007232000.00000004.00000800.00020000.00000000.sdmpString found in binary or memory: http://www.fontbureau.com/designers/?
          Source: SecuriteInfo.com.Win32.CrypterX-gen.16304.13478.exe, 00000000.00000002.272505714.0000000007232000.00000004.00000800.00020000.00000000.sdmpString found in binary or memory: http://www.fontbureau.com/designers/cabarga.htmlN
          Source: SecuriteInfo.com.Win32.CrypterX-gen.16304.13478.exe, 00000000.00000002.272505714.0000000007232000.00000004.00000800.00020000.00000000.sdmpString found in binary or memory: http://www.fontbureau.com/designers/frere-jones.html
          Source: SecuriteInfo.com.Win32.CrypterX-gen.16304.13478.exe, 00000000.00000002.272505714.0000000007232000.00000004.00000800.00020000.00000000.sdmpString found in binary or memory: http://www.fontbureau.com/designers8
          Source: SecuriteInfo.com.Win32.CrypterX-gen.16304.13478.exe, 00000000.00000002.272505714.0000000007232000.00000004.00000800.00020000.00000000.sdmpString found in binary or memory: http://www.fontbureau.com/designers?
          Source: SecuriteInfo.com.Win32.CrypterX-gen.16304.13478.exe, 00000000.00000002.272505714.0000000007232000.00000004.00000800.00020000.00000000.sdmpString found in binary or memory: http://www.fontbureau.com/designersG
          Source: SecuriteInfo.com.Win32.CrypterX-gen.16304.13478.exe, 00000000.00000002.272505714.0000000007232000.00000004.00000800.00020000.00000000.sdmpString found in binary or memory: http://www.fonts.com
          Source: SecuriteInfo.com.Win32.CrypterX-gen.16304.13478.exe, 00000000.00000002.272505714.0000000007232000.00000004.00000800.00020000.00000000.sdmpString found in binary or memory: http://www.founder.com.cn/cn
          Source: SecuriteInfo.com.Win32.CrypterX-gen.16304.13478.exe, 00000000.00000002.272505714.0000000007232000.00000004.00000800.00020000.00000000.sdmpString found in binary or memory: http://www.founder.com.cn/cn/bThe
          Source: SecuriteInfo.com.Win32.CrypterX-gen.16304.13478.exe, 00000000.00000002.272505714.0000000007232000.00000004.00000800.00020000.00000000.sdmpString found in binary or memory: http://www.founder.com.cn/cn/cThe
          Source: SecuriteInfo.com.Win32.CrypterX-gen.16304.13478.exe, 00000000.00000002.272505714.0000000007232000.00000004.00000800.00020000.00000000.sdmpString found in binary or memory: http://www.galapagosdesign.com/DPlease
          Source: SecuriteInfo.com.Win32.CrypterX-gen.16304.13478.exe, 00000000.00000002.272505714.0000000007232000.00000004.00000800.00020000.00000000.sdmpString found in binary or memory: http://www.galapagosdesign.com/staff/dennis.htm
          Source: SecuriteInfo.com.Win32.CrypterX-gen.16304.13478.exe, 00000000.00000002.272505714.0000000007232000.00000004.00000800.00020000.00000000.sdmpString found in binary or memory: http://www.goodfont.co.kr
          Source: SecuriteInfo.com.Win32.CrypterX-gen.16304.13478.exe, 00000000.00000002.272505714.0000000007232000.00000004.00000800.00020000.00000000.sdmpString found in binary or memory: http://www.jiyu-kobo.co.jp/
          Source: SecuriteInfo.com.Win32.CrypterX-gen.16304.13478.exe, 00000000.00000002.272505714.0000000007232000.00000004.00000800.00020000.00000000.sdmpString found in binary or memory: http://www.sajatypeworks.com
          Source: SecuriteInfo.com.Win32.CrypterX-gen.16304.13478.exe, 00000000.00000002.272505714.0000000007232000.00000004.00000800.00020000.00000000.sdmpString found in binary or memory: http://www.sakkal.com
          Source: SecuriteInfo.com.Win32.CrypterX-gen.16304.13478.exe, 00000000.00000002.272505714.0000000007232000.00000004.00000800.00020000.00000000.sdmpString found in binary or memory: http://www.sandoll.co.kr
          Source: SecuriteInfo.com.Win32.CrypterX-gen.16304.13478.exe, 00000000.00000002.272505714.0000000007232000.00000004.00000800.00020000.00000000.sdmpString found in binary or memory: http://www.tiro.com
          Source: SecuriteInfo.com.Win32.CrypterX-gen.16304.13478.exe, 00000000.00000002.272505714.0000000007232000.00000004.00000800.00020000.00000000.sdmpString found in binary or memory: http://www.typography.netD
          Source: SecuriteInfo.com.Win32.CrypterX-gen.16304.13478.exe, 00000000.00000002.272505714.0000000007232000.00000004.00000800.00020000.00000000.sdmpString found in binary or memory: http://www.urwpp.deDPlease
          Source: SecuriteInfo.com.Win32.CrypterX-gen.16304.13478.exe, 00000000.00000002.272505714.0000000007232000.00000004.00000800.00020000.00000000.sdmpString found in binary or memory: http://www.zhongyicts.com.cn
          Source: SecuriteInfo.com.Win32.CrypterX-gen.16304.13478.exe, 00000000.00000002.264008229.000000000147B000.00000004.00000020.00020000.00000000.sdmpBinary or memory string: <HOOK MODULE="DDRAW.DLL" FUNCTION="DirectDrawCreateEx"/>

          E-Banking Fraud

          barindex
          Source: Yara matchFile source: 1.0.SecuriteInfo.com.Win32.CrypterX-gen.16304.13478.exe.400000.0.unpack, type: UNPACKEDPE
          Source: Yara matchFile source: 0.2.SecuriteInfo.com.Win32.CrypterX-gen.16304.13478.exe.44aef60.6.raw.unpack, type: UNPACKEDPE
          Source: Yara matchFile source: 0.2.SecuriteInfo.com.Win32.CrypterX-gen.16304.13478.exe.45233b0.5.raw.unpack, type: UNPACKEDPE
          Source: Yara matchFile source: 00000001.00000000.262712520.0000000000401000.00000040.00000400.00020000.00000000.sdmp, type: MEMORY
          Source: Yara matchFile source: 00000000.00000002.270529665.00000000044AE000.00000004.00000800.00020000.00000000.sdmp, type: MEMORY

          System Summary

          barindex
          Source: 1.0.SecuriteInfo.com.Win32.CrypterX-gen.16304.13478.exe.400000.0.unpack, type: UNPACKEDPEMatched rule: Windows_Trojan_Formbook_1112e116 Author: unknown
          Source: 1.0.SecuriteInfo.com.Win32.CrypterX-gen.16304.13478.exe.400000.0.unpack, type: UNPACKEDPEMatched rule: autogenerated rule brought to you by yara-signator Author: Felix Bilstein - yara-signator at cocacoding dot com
          Source: 1.0.SecuriteInfo.com.Win32.CrypterX-gen.16304.13478.exe.400000.0.unpack, type: UNPACKEDPEMatched rule: detect Formbook in memory Author: JPCERT/CC Incident Response Group
          Source: 0.2.SecuriteInfo.com.Win32.CrypterX-gen.16304.13478.exe.3282f54.1.raw.unpack, type: UNPACKEDPEMatched rule: Detects executables potentially checking for WinJail sandbox window Author: ditekSHen
          Source: 0.2.SecuriteInfo.com.Win32.CrypterX-gen.16304.13478.exe.32a0724.0.raw.unpack, type: UNPACKEDPEMatched rule: Detects executables potentially checking for WinJail sandbox window Author: ditekSHen
          Source: 0.2.SecuriteInfo.com.Win32.CrypterX-gen.16304.13478.exe.44aef60.6.raw.unpack, type: UNPACKEDPEMatched rule: Windows_Trojan_Formbook_1112e116 Author: unknown
          Source: 0.2.SecuriteInfo.com.Win32.CrypterX-gen.16304.13478.exe.44aef60.6.raw.unpack, type: UNPACKEDPEMatched rule: autogenerated rule brought to you by yara-signator Author: Felix Bilstein - yara-signator at cocacoding dot com
          Source: 0.2.SecuriteInfo.com.Win32.CrypterX-gen.16304.13478.exe.44aef60.6.raw.unpack, type: UNPACKEDPEMatched rule: detect Formbook in memory Author: JPCERT/CC Incident Response Group
          Source: 0.2.SecuriteInfo.com.Win32.CrypterX-gen.16304.13478.exe.45233b0.5.raw.unpack, type: UNPACKEDPEMatched rule: Windows_Trojan_Formbook_1112e116 Author: unknown
          Source: 0.2.SecuriteInfo.com.Win32.CrypterX-gen.16304.13478.exe.45233b0.5.raw.unpack, type: UNPACKEDPEMatched rule: autogenerated rule brought to you by yara-signator Author: Felix Bilstein - yara-signator at cocacoding dot com
          Source: 0.2.SecuriteInfo.com.Win32.CrypterX-gen.16304.13478.exe.45233b0.5.raw.unpack, type: UNPACKEDPEMatched rule: detect Formbook in memory Author: JPCERT/CC Incident Response Group
          Source: 00000001.00000000.262712520.0000000000401000.00000040.00000400.00020000.00000000.sdmp, type: MEMORYMatched rule: Windows_Trojan_Formbook_1112e116 Author: unknown
          Source: 00000001.00000000.262712520.0000000000401000.00000040.00000400.00020000.00000000.sdmp, type: MEMORYMatched rule: autogenerated rule brought to you by yara-signator Author: Felix Bilstein - yara-signator at cocacoding dot com
          Source: 00000001.00000000.262712520.0000000000401000.00000040.00000400.00020000.00000000.sdmp, type: MEMORYMatched rule: detect Formbook in memory Author: JPCERT/CC Incident Response Group
          Source: 00000000.00000002.270529665.00000000044AE000.00000004.00000800.00020000.00000000.sdmp, type: MEMORYMatched rule: Windows_Trojan_Formbook_1112e116 Author: unknown
          Source: 00000000.00000002.270529665.00000000044AE000.00000004.00000800.00020000.00000000.sdmp, type: MEMORYMatched rule: autogenerated rule brought to you by yara-signator Author: Felix Bilstein - yara-signator at cocacoding dot com
          Source: 00000000.00000002.270529665.00000000044AE000.00000004.00000800.00020000.00000000.sdmp, type: MEMORYMatched rule: detect Formbook in memory Author: JPCERT/CC Incident Response Group
          Source: Process Memory Space: SecuriteInfo.com.Win32.CrypterX-gen.16304.13478.exe PID: 5272, type: MEMORYSTRMatched rule: Windows_Trojan_Formbook_1112e116 Author: unknown
          Source: Process Memory Space: SecuriteInfo.com.Win32.CrypterX-gen.16304.13478.exe PID: 5208, type: MEMORYSTRMatched rule: Windows_Trojan_Formbook_1112e116 Author: unknown
          Source: SecuriteInfo.com.Win32.CrypterX-gen.16304.13478.exeStatic PE information: EXECUTABLE_IMAGE, 32BIT_MACHINE
          Source: 1.0.SecuriteInfo.com.Win32.CrypterX-gen.16304.13478.exe.400000.0.unpack, type: UNPACKEDPEMatched rule: Windows_Trojan_Formbook_1112e116 reference_sample = 6246f3b89f0e4913abd88ae535ae3597865270f58201dc7f8ec0c87f15ff370a, os = windows, severity = x86, creation_date = 2021-06-14, scan_context = file, memory, license = Elastic License v2, threat_name = Windows.Trojan.Formbook, fingerprint = b8b88451ad8c66b54e21455d835a5d435e52173c86e9b813ffab09451aff7134, id = 1112e116-dee0-4818-a41f-ca5c1c41b4b8, last_modified = 2021-08-23
          Source: 1.0.SecuriteInfo.com.Win32.CrypterX-gen.16304.13478.exe.400000.0.unpack, type: UNPACKEDPEMatched rule: Formbook_1 date = 2018-11-23, author = Felix Bilstein - yara-signator at cocacoding dot com, malpedia_version = 20180607, description = autogenerated rule brought to you by yara-signator, malpedia_reference = https://malpedia.caad.fkie.fraunhofer.de/details/win.formbook, cape_type = Formbook Payload, malpedia_license = CC BY-NC-SA 4.0, version = 1, tool = yara-signator 0.1a, malpedia_sharing = TLP:WHITE
          Source: 1.0.SecuriteInfo.com.Win32.CrypterX-gen.16304.13478.exe.400000.0.unpack, type: UNPACKEDPEMatched rule: Formbook author = JPCERT/CC Incident Response Group, description = detect Formbook in memory, rule_usage = memory scan, reference = internal research
          Source: 0.2.SecuriteInfo.com.Win32.CrypterX-gen.16304.13478.exe.3282f54.1.raw.unpack, type: UNPACKEDPEMatched rule: INDICATOR_SUSPICIOUS_EXE_Anti_OldCopyPaste author = ditekSHen, description = Detects executables potentially checking for WinJail sandbox window
          Source: 0.2.SecuriteInfo.com.Win32.CrypterX-gen.16304.13478.exe.32a0724.0.raw.unpack, type: UNPACKEDPEMatched rule: INDICATOR_SUSPICIOUS_EXE_Anti_OldCopyPaste author = ditekSHen, description = Detects executables potentially checking for WinJail sandbox window
          Source: 0.2.SecuriteInfo.com.Win32.CrypterX-gen.16304.13478.exe.44aef60.6.raw.unpack, type: UNPACKEDPEMatched rule: Windows_Trojan_Formbook_1112e116 reference_sample = 6246f3b89f0e4913abd88ae535ae3597865270f58201dc7f8ec0c87f15ff370a, os = windows, severity = x86, creation_date = 2021-06-14, scan_context = file, memory, license = Elastic License v2, threat_name = Windows.Trojan.Formbook, fingerprint = b8b88451ad8c66b54e21455d835a5d435e52173c86e9b813ffab09451aff7134, id = 1112e116-dee0-4818-a41f-ca5c1c41b4b8, last_modified = 2021-08-23
          Source: 0.2.SecuriteInfo.com.Win32.CrypterX-gen.16304.13478.exe.44aef60.6.raw.unpack, type: UNPACKEDPEMatched rule: Formbook_1 date = 2018-11-23, author = Felix Bilstein - yara-signator at cocacoding dot com, malpedia_version = 20180607, description = autogenerated rule brought to you by yara-signator, malpedia_reference = https://malpedia.caad.fkie.fraunhofer.de/details/win.formbook, cape_type = Formbook Payload, malpedia_license = CC BY-NC-SA 4.0, version = 1, tool = yara-signator 0.1a, malpedia_sharing = TLP:WHITE
          Source: 0.2.SecuriteInfo.com.Win32.CrypterX-gen.16304.13478.exe.44aef60.6.raw.unpack, type: UNPACKEDPEMatched rule: Formbook author = JPCERT/CC Incident Response Group, description = detect Formbook in memory, rule_usage = memory scan, reference = internal research
          Source: 0.2.SecuriteInfo.com.Win32.CrypterX-gen.16304.13478.exe.45233b0.5.raw.unpack, type: UNPACKEDPEMatched rule: Windows_Trojan_Formbook_1112e116 reference_sample = 6246f3b89f0e4913abd88ae535ae3597865270f58201dc7f8ec0c87f15ff370a, os = windows, severity = x86, creation_date = 2021-06-14, scan_context = file, memory, license = Elastic License v2, threat_name = Windows.Trojan.Formbook, fingerprint = b8b88451ad8c66b54e21455d835a5d435e52173c86e9b813ffab09451aff7134, id = 1112e116-dee0-4818-a41f-ca5c1c41b4b8, last_modified = 2021-08-23
          Source: 0.2.SecuriteInfo.com.Win32.CrypterX-gen.16304.13478.exe.45233b0.5.raw.unpack, type: UNPACKEDPEMatched rule: Formbook_1 date = 2018-11-23, author = Felix Bilstein - yara-signator at cocacoding dot com, malpedia_version = 20180607, description = autogenerated rule brought to you by yara-signator, malpedia_reference = https://malpedia.caad.fkie.fraunhofer.de/details/win.formbook, cape_type = Formbook Payload, malpedia_license = CC BY-NC-SA 4.0, version = 1, tool = yara-signator 0.1a, malpedia_sharing = TLP:WHITE
          Source: 0.2.SecuriteInfo.com.Win32.CrypterX-gen.16304.13478.exe.45233b0.5.raw.unpack, type: UNPACKEDPEMatched rule: Formbook author = JPCERT/CC Incident Response Group, description = detect Formbook in memory, rule_usage = memory scan, reference = internal research
          Source: 00000001.00000000.262712520.0000000000401000.00000040.00000400.00020000.00000000.sdmp, type: MEMORYMatched rule: Windows_Trojan_Formbook_1112e116 reference_sample = 6246f3b89f0e4913abd88ae535ae3597865270f58201dc7f8ec0c87f15ff370a, os = windows, severity = x86, creation_date = 2021-06-14, scan_context = file, memory, license = Elastic License v2, threat_name = Windows.Trojan.Formbook, fingerprint = b8b88451ad8c66b54e21455d835a5d435e52173c86e9b813ffab09451aff7134, id = 1112e116-dee0-4818-a41f-ca5c1c41b4b8, last_modified = 2021-08-23
          Source: 00000001.00000000.262712520.0000000000401000.00000040.00000400.00020000.00000000.sdmp, type: MEMORYMatched rule: Formbook_1 date = 2018-11-23, author = Felix Bilstein - yara-signator at cocacoding dot com, malpedia_version = 20180607, description = autogenerated rule brought to you by yara-signator, malpedia_reference = https://malpedia.caad.fkie.fraunhofer.de/details/win.formbook, cape_type = Formbook Payload, malpedia_license = CC BY-NC-SA 4.0, version = 1, tool = yara-signator 0.1a, malpedia_sharing = TLP:WHITE
          Source: 00000001.00000000.262712520.0000000000401000.00000040.00000400.00020000.00000000.sdmp, type: MEMORYMatched rule: Formbook author = JPCERT/CC Incident Response Group, description = detect Formbook in memory, rule_usage = memory scan, reference = internal research
          Source: 00000000.00000002.270529665.00000000044AE000.00000004.00000800.00020000.00000000.sdmp, type: MEMORYMatched rule: Windows_Trojan_Formbook_1112e116 reference_sample = 6246f3b89f0e4913abd88ae535ae3597865270f58201dc7f8ec0c87f15ff370a, os = windows, severity = x86, creation_date = 2021-06-14, scan_context = file, memory, license = Elastic License v2, threat_name = Windows.Trojan.Formbook, fingerprint = b8b88451ad8c66b54e21455d835a5d435e52173c86e9b813ffab09451aff7134, id = 1112e116-dee0-4818-a41f-ca5c1c41b4b8, last_modified = 2021-08-23
          Source: 00000000.00000002.270529665.00000000044AE000.00000004.00000800.00020000.00000000.sdmp, type: MEMORYMatched rule: Formbook_1 date = 2018-11-23, author = Felix Bilstein - yara-signator at cocacoding dot com, malpedia_version = 20180607, description = autogenerated rule brought to you by yara-signator, malpedia_reference = https://malpedia.caad.fkie.fraunhofer.de/details/win.formbook, cape_type = Formbook Payload, malpedia_license = CC BY-NC-SA 4.0, version = 1, tool = yara-signator 0.1a, malpedia_sharing = TLP:WHITE
          Source: 00000000.00000002.270529665.00000000044AE000.00000004.00000800.00020000.00000000.sdmp, type: MEMORYMatched rule: Formbook author = JPCERT/CC Incident Response Group, description = detect Formbook in memory, rule_usage = memory scan, reference = internal research
          Source: Process Memory Space: SecuriteInfo.com.Win32.CrypterX-gen.16304.13478.exe PID: 5272, type: MEMORYSTRMatched rule: Windows_Trojan_Formbook_1112e116 reference_sample = 6246f3b89f0e4913abd88ae535ae3597865270f58201dc7f8ec0c87f15ff370a, os = windows, severity = x86, creation_date = 2021-06-14, scan_context = file, memory, license = Elastic License v2, threat_name = Windows.Trojan.Formbook, fingerprint = b8b88451ad8c66b54e21455d835a5d435e52173c86e9b813ffab09451aff7134, id = 1112e116-dee0-4818-a41f-ca5c1c41b4b8, last_modified = 2021-08-23
          Source: Process Memory Space: SecuriteInfo.com.Win32.CrypterX-gen.16304.13478.exe PID: 5208, type: MEMORYSTRMatched rule: Windows_Trojan_Formbook_1112e116 reference_sample = 6246f3b89f0e4913abd88ae535ae3597865270f58201dc7f8ec0c87f15ff370a, os = windows, severity = x86, creation_date = 2021-06-14, scan_context = file, memory, license = Elastic License v2, threat_name = Windows.Trojan.Formbook, fingerprint = b8b88451ad8c66b54e21455d835a5d435e52173c86e9b813ffab09451aff7134, id = 1112e116-dee0-4818-a41f-ca5c1c41b4b8, last_modified = 2021-08-23
          Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.CrypterX-gen.16304.13478.exeCode function: 0_2_0171C164
          Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.CrypterX-gen.16304.13478.exeCode function: 0_2_0171E5B0
          Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.CrypterX-gen.16304.13478.exeCode function: 0_2_0171E5A1
          Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.CrypterX-gen.16304.13478.exeCode function: 0_2_056F06E8
          Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.CrypterX-gen.16304.13478.exeCode function: 0_2_056F2868
          Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.CrypterX-gen.16304.13478.exeCode function: 0_2_056F6660
          Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.CrypterX-gen.16304.13478.exeCode function: 0_2_056F6650
          Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.CrypterX-gen.16304.13478.exeCode function: 0_2_056F06D9
          Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.CrypterX-gen.16304.13478.exeCode function: 0_2_056F2320
          Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.CrypterX-gen.16304.13478.exeCode function: 0_2_056F2330
          Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.CrypterX-gen.16304.13478.exeCode function: 0_2_056F22FA
          Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.CrypterX-gen.16304.13478.exeCode function: 1_2_0153F900
          Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.CrypterX-gen.16304.13478.exeCode function: 1_2_01554120
          Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.CrypterX-gen.16304.13478.exeCode function: 1_2_0154C1C0
          Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.CrypterX-gen.16304.13478.exeCode function: 1_2_01552990
          Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.CrypterX-gen.16304.13478.exeCode function: 1_2_015599BF
          Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.CrypterX-gen.16304.13478.exeCode function: 1_2_0160E824
          Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.CrypterX-gen.16304.13478.exeCode function: 1_2_0156701D
          Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.CrypterX-gen.16304.13478.exeCode function: 1_2_01536800
          Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.CrypterX-gen.16304.13478.exeCode function: 1_2_015F1002
          Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.CrypterX-gen.16304.13478.exeCode function: 1_2_0155A830
          Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.CrypterX-gen.16304.13478.exeCode function: 1_2_016028EC
          Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.CrypterX-gen.16304.13478.exeCode function: 1_2_015F60F5
          Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.CrypterX-gen.16304.13478.exeCode function: 1_2_0154B090
          Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.CrypterX-gen.16304.13478.exeCode function: 1_2_016020A8
          Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.CrypterX-gen.16304.13478.exeCode function: 1_2_015620A0
          Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.CrypterX-gen.16304.13478.exeCode function: 1_2_015DCB4F
          Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.CrypterX-gen.16304.13478.exeCode function: 1_2_0155AB40
          Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.CrypterX-gen.16304.13478.exeCode function: 1_2_0151337D
          Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.CrypterX-gen.16304.13478.exeCode function: 1_2_01553360
          Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.CrypterX-gen.16304.13478.exeCode function: 1_2_015F231B
          Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.CrypterX-gen.16304.13478.exeCode function: 1_2_01602B28
          Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.CrypterX-gen.16304.13478.exeCode function: 1_2_0155A309
          Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.CrypterX-gen.16304.13478.exeCode function: 1_2_015F03DA
          Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.CrypterX-gen.16304.13478.exeCode function: 1_2_015FDBD2
          Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.CrypterX-gen.16304.13478.exeCode function: 1_2_0156ABD8
          Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.CrypterX-gen.16304.13478.exeCode function: 1_2_01588BE8
          Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.CrypterX-gen.16304.13478.exeCode function: 1_2_015E23E3
          Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.CrypterX-gen.16304.13478.exeCode function: 1_2_0155EB9A
          Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.CrypterX-gen.16304.13478.exeCode function: 1_2_01513382
          Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.CrypterX-gen.16304.13478.exeCode function: 1_2_015DEB8A
          Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.CrypterX-gen.16304.13478.exeCode function: 1_2_0156138B
          Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.CrypterX-gen.16304.13478.exeCode function: 1_2_0156EBB0
          Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.CrypterX-gen.16304.13478.exeCode function: 1_2_0151225E
          Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.CrypterX-gen.16304.13478.exeCode function: 1_2_015F5A4F
          Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.CrypterX-gen.16304.13478.exeCode function: 1_2_0155B236
          Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.CrypterX-gen.16304.13478.exeCode function: 1_2_015EFA2B
          Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.CrypterX-gen.16304.13478.exeCode function: 1_2_015FE2C5
          Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.CrypterX-gen.16304.13478.exeCode function: 1_2_015F4AEF
          Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.CrypterX-gen.16304.13478.exeCode function: 1_2_016032A9
          Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.CrypterX-gen.16304.13478.exeCode function: 1_2_016022AE
          Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.CrypterX-gen.16304.13478.exeCode function: 1_2_01552D50
          Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.CrypterX-gen.16304.13478.exeCode function: 1_2_01601D55
          Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.CrypterX-gen.16304.13478.exeCode function: 1_2_01602D07
          Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.CrypterX-gen.16304.13478.exeCode function: 1_2_01530D20
          Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.CrypterX-gen.16304.13478.exeCode function: 1_2_0154D5E0
          Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.CrypterX-gen.16304.13478.exeCode function: 1_2_016025DD
          Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.CrypterX-gen.16304.13478.exeCode function: 1_2_01562581
          Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.CrypterX-gen.16304.13478.exeCode function: 1_2_015F2D82
          Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.CrypterX-gen.16304.13478.exeCode function: 1_2_015665A0
          Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.CrypterX-gen.16304.13478.exeCode function: 1_2_0155B477
          Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.CrypterX-gen.16304.13478.exeCode function: 1_2_015FD466
          Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.CrypterX-gen.16304.13478.exeCode function: 1_2_0154841F
          Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.CrypterX-gen.16304.13478.exeCode function: 1_2_01552430
          Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.CrypterX-gen.16304.13478.exeCode function: 1_2_01564CD4
          Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.CrypterX-gen.16304.13478.exeCode function: 1_2_015F4496
          Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.CrypterX-gen.16304.13478.exeCode function: 1_2_015194B8
          Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.CrypterX-gen.16304.13478.exeCode function: 1_2_01601FF1
          Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.CrypterX-gen.16304.13478.exeCode function: 1_2_0160DFCE
          Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.CrypterX-gen.16304.13478.exeCode function: 1_2_015F67E2
          Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.CrypterX-gen.16304.13478.exeCode function: 1_2_015BAE60
          Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.CrypterX-gen.16304.13478.exeCode function: 1_2_015FD616
          Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.CrypterX-gen.16304.13478.exeCode function: 1_2_01555600
          Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.CrypterX-gen.16304.13478.exeCode function: 1_2_01556E30
          Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.CrypterX-gen.16304.13478.exeCode function: 1_2_01602EF7
          Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.CrypterX-gen.16304.13478.exeCode function: 1_2_015E1EB6
          Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.CrypterX-gen.16304.13478.exeCode function: String function: 0158D08C appears 47 times
          Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.CrypterX-gen.16304.13478.exeCode function: String function: 0153B150 appears 159 times
          Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.CrypterX-gen.16304.13478.exeCode function: String function: 015C5720 appears 81 times
          Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.CrypterX-gen.16304.13478.exeCode function: 1_2_01579860 NtQuerySystemInformation,LdrInitializeThunk,
          Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.CrypterX-gen.16304.13478.exeCode function: 1_2_01579660 NtAllocateVirtualMemory,LdrInitializeThunk,
          Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.CrypterX-gen.16304.13478.exeCode function: 1_2_015796E0 NtFreeVirtualMemory,LdrInitializeThunk,
          Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.CrypterX-gen.16304.13478.exeCode function: 1_2_01579950 NtQueueApcThread,
          Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.CrypterX-gen.16304.13478.exeCode function: 1_2_01579910 NtAdjustPrivilegesToken,
          Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.CrypterX-gen.16304.13478.exeCode function: 1_2_015799D0 NtCreateProcessEx,
          Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.CrypterX-gen.16304.13478.exeCode function: 1_2_015799A0 NtCreateSection,
          Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.CrypterX-gen.16304.13478.exeCode function: 1_2_01579840 NtDelayExecution,
          Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.CrypterX-gen.16304.13478.exeCode function: 1_2_0157B040 NtSuspendThread,
          Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.CrypterX-gen.16304.13478.exeCode function: 1_2_01579820 NtEnumerateKey,
          Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.CrypterX-gen.16304.13478.exeCode function: 1_2_015798F0 NtReadVirtualMemory,
          Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.CrypterX-gen.16304.13478.exeCode function: 1_2_015798A0 NtWriteVirtualMemory,
          Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.CrypterX-gen.16304.13478.exeCode function: 1_2_01579B00 NtSetValueKey,
          Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.CrypterX-gen.16304.13478.exeCode function: 1_2_0157A3B0 NtGetContextThread,
          Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.CrypterX-gen.16304.13478.exeCode function: 1_2_01579A50 NtCreateFile,
          Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.CrypterX-gen.16304.13478.exeCode function: 1_2_01579A10 NtQuerySection,
          Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.CrypterX-gen.16304.13478.exeCode function: 1_2_01579A00 NtProtectVirtualMemory,
          Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.CrypterX-gen.16304.13478.exeCode function: 1_2_01579A20 NtResumeThread,
          Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.CrypterX-gen.16304.13478.exeCode function: 1_2_01579A80 NtOpenDirectoryObject,
          Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.CrypterX-gen.16304.13478.exeCode function: 1_2_01579540 NtReadFile,
          Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.CrypterX-gen.16304.13478.exeCode function: 1_2_01579560 NtWriteFile,
          Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.CrypterX-gen.16304.13478.exeCode function: 1_2_0157AD30 NtSetContextThread,
          Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.CrypterX-gen.16304.13478.exeCode function: 1_2_01579520 NtWaitForSingleObject,
          Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.CrypterX-gen.16304.13478.exeCode function: 1_2_015795D0 NtClose,
          Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.CrypterX-gen.16304.13478.exeCode function: 1_2_015795F0 NtQueryInformationFile,
          Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.CrypterX-gen.16304.13478.exeCode function: 1_2_0157A770 NtOpenThread,
          Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.CrypterX-gen.16304.13478.exeCode function: 1_2_01579770 NtSetInformationFile,
          Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.CrypterX-gen.16304.13478.exeCode function: 1_2_01579760 NtOpenProcess,
          Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.CrypterX-gen.16304.13478.exeCode function: 1_2_0157A710 NtOpenProcessToken,
          Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.CrypterX-gen.16304.13478.exeCode function: 1_2_01579710 NtQueryInformationToken,
          Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.CrypterX-gen.16304.13478.exeCode function: 1_2_01579730 NtQueryVirtualMemory,
          Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.CrypterX-gen.16304.13478.exeCode function: 1_2_01579FE0 NtCreateMutant,
          Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.CrypterX-gen.16304.13478.exeCode function: 1_2_01579780 NtMapViewOfSection,
          Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.CrypterX-gen.16304.13478.exeCode function: 1_2_015797A0 NtUnmapViewOfSection,
          Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.CrypterX-gen.16304.13478.exeCode function: 1_2_01579650 NtQueryValueKey,
          Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.CrypterX-gen.16304.13478.exeCode function: 1_2_01579670 NtQueryInformationProcess,
          Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.CrypterX-gen.16304.13478.exeCode function: 1_2_01579610 NtEnumerateValueKey,
          Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.CrypterX-gen.16304.13478.exeCode function: 1_2_015796D0 NtCreateKey,
          Source: SecuriteInfo.com.Win32.CrypterX-gen.16304.13478.exe, 00000000.00000000.243748362.0000000000D84000.00000002.00000001.01000000.00000003.sdmpBinary or memory string: OriginalFilenameyFcW.exeB vs SecuriteInfo.com.Win32.CrypterX-gen.16304.13478.exe
          Source: SecuriteInfo.com.Win32.CrypterX-gen.16304.13478.exe, 00000000.00000002.264008229.000000000147B000.00000004.00000020.00020000.00000000.sdmpBinary or memory string: OriginalFilenameclr.dllT vs SecuriteInfo.com.Win32.CrypterX-gen.16304.13478.exe
          Source: SecuriteInfo.com.Win32.CrypterX-gen.16304.13478.exe, 00000000.00000002.275549628.0000000007990000.00000004.08000000.00040000.00000000.sdmpBinary or memory string: OriginalFilenameCollins.dll8 vs SecuriteInfo.com.Win32.CrypterX-gen.16304.13478.exe
          Source: SecuriteInfo.com.Win32.CrypterX-gen.16304.13478.exe, 00000000.00000002.270529665.00000000044AE000.00000004.00000800.00020000.00000000.sdmpBinary or memory string: OriginalFilenameCollins.dll8 vs SecuriteInfo.com.Win32.CrypterX-gen.16304.13478.exe
          Source: SecuriteInfo.com.Win32.CrypterX-gen.16304.13478.exe, 00000000.00000002.266387939.0000000003261000.00000004.00000800.00020000.00000000.sdmpBinary or memory string: OriginalFilenamePrecision.dll6 vs SecuriteInfo.com.Win32.CrypterX-gen.16304.13478.exe
          Source: SecuriteInfo.com.Win32.CrypterX-gen.16304.13478.exe, 00000000.00000002.266387939.0000000003261000.00000004.00000800.00020000.00000000.sdmpBinary or memory string: OriginalFilenameInspector.dllN vs SecuriteInfo.com.Win32.CrypterX-gen.16304.13478.exe
          Source: SecuriteInfo.com.Win32.CrypterX-gen.16304.13478.exe, 00000001.00000003.266489821.0000000001490000.00000004.00000800.00020000.00000000.sdmpBinary or memory string: OriginalFilenamentdll.dllj% vs SecuriteInfo.com.Win32.CrypterX-gen.16304.13478.exe
          Source: SecuriteInfo.com.Win32.CrypterX-gen.16304.13478.exe, 00000001.00000003.263873744.00000000012EA000.00000004.00000800.00020000.00000000.sdmpBinary or memory string: OriginalFilenamentdll.dllj% vs SecuriteInfo.com.Win32.CrypterX-gen.16304.13478.exe
          Source: SecuriteInfo.com.Win32.CrypterX-gen.16304.13478.exe, 00000001.00000002.268632378.000000000162F000.00000040.00000800.00020000.00000000.sdmpBinary or memory string: OriginalFilenamentdll.dllj% vs SecuriteInfo.com.Win32.CrypterX-gen.16304.13478.exe
          Source: SecuriteInfo.com.Win32.CrypterX-gen.16304.13478.exeBinary or memory string: OriginalFilenameyFcW.exeB vs SecuriteInfo.com.Win32.CrypterX-gen.16304.13478.exe
          Source: SecuriteInfo.com.Win32.CrypterX-gen.16304.13478.exeStatic PE information: Section: .text IMAGE_SCN_CNT_CODE, IMAGE_SCN_MEM_EXECUTE, IMAGE_SCN_MEM_READ
          Source: SecuriteInfo.com.Win32.CrypterX-gen.16304.13478.exeReversingLabs: Detection: 29%
          Source: SecuriteInfo.com.Win32.CrypterX-gen.16304.13478.exeStatic PE information: Section: .text IMAGE_SCN_CNT_CODE, IMAGE_SCN_MEM_EXECUTE, IMAGE_SCN_MEM_READ
          Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.CrypterX-gen.16304.13478.exeKey opened: HKEY_CURRENT_USER\Software\Policies\Microsoft\Windows\Safer\CodeIdentifiers
          Source: unknownProcess created: C:\Users\user\Desktop\SecuriteInfo.com.Win32.CrypterX-gen.16304.13478.exe C:\Users\user\Desktop\SecuriteInfo.com.Win32.CrypterX-gen.16304.13478.exe
          Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.CrypterX-gen.16304.13478.exeProcess created: C:\Users\user\Desktop\SecuriteInfo.com.Win32.CrypterX-gen.16304.13478.exe C:\Users\user\Desktop\SecuriteInfo.com.Win32.CrypterX-gen.16304.13478.exe
          Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.CrypterX-gen.16304.13478.exeProcess created: C:\Users\user\Desktop\SecuriteInfo.com.Win32.CrypterX-gen.16304.13478.exe C:\Users\user\Desktop\SecuriteInfo.com.Win32.CrypterX-gen.16304.13478.exe
          Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.CrypterX-gen.16304.13478.exeFile created: C:\Users\user\AppData\Local\Microsoft\CLR_v4.0_32\UsageLogs\SecuriteInfo.com.Win32.CrypterX-gen.16304.13478.exe.logJump to behavior
          Source: classification engineClassification label: mal100.troj.evad.winEXE@3/1@0/0
          Source: SecuriteInfo.com.Win32.CrypterX-gen.16304.13478.exe, 00000000.00000000.243588948.0000000000CA2000.00000002.00000001.01000000.00000003.sdmpBinary or memory string: insert into User_Transportation(UserID,TransportationID) values (@UserID,@TransID);
          Source: SecuriteInfo.com.Win32.CrypterX-gen.16304.13478.exe, 00000000.00000000.243588948.0000000000CA2000.00000002.00000001.01000000.00000003.sdmpBinary or memory string: insert into TourPlace(Name,Location,TicketPrice) values (@name,@location,@ticket);
          Source: SecuriteInfo.com.Win32.CrypterX-gen.16304.13478.exe, 00000000.00000000.243588948.0000000000CA2000.00000002.00000001.01000000.00000003.sdmpBinary or memory string: insert into User_TourPlace(UserID,TourPlaceID) values (@UserID,@TourplaceID);
          Source: SecuriteInfo.com.Win32.CrypterX-gen.16304.13478.exeStatic file information: TRID: Win32 Executable (generic) Net Framework (10011505/4) 49.80%
          Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.CrypterX-gen.16304.13478.exeSection loaded: C:\Windows\assembly\NativeImages_v4.0.30319_32\mscorlib\a152fe02a317a77aeee36903305e8ba6\mscorlib.ni.dll
          Source: SecuriteInfo.com.Win32.CrypterX-gen.16304.13478.exeString found in binary or memory: AddUserButton'AddUserPhoneTextbox'AdduserEmailtextbox-Adduserpasswordtextbox
          Source: SecuriteInfo.com.Win32.CrypterX-gen.16304.13478.exeString found in binary or memory: Username:-AddusertextBoxUsernameCash
          Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.CrypterX-gen.16304.13478.exeFile opened: C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscorrc.dll
          Source: SecuriteInfo.com.Win32.CrypterX-gen.16304.13478.exeStatic PE information: data directory type: IMAGE_DIRECTORY_ENTRY_COM_DESCRIPTOR
          Source: SecuriteInfo.com.Win32.CrypterX-gen.16304.13478.exeStatic PE information: DYNAMIC_BASE, NX_COMPAT, NO_SEH, TERMINAL_SERVER_AWARE
          Source: Binary string: wntdll.pdbUGP source: SecuriteInfo.com.Win32.CrypterX-gen.16304.13478.exe, 00000001.00000002.267578947.0000000001510000.00000040.00000800.00020000.00000000.sdmp, SecuriteInfo.com.Win32.CrypterX-gen.16304.13478.exe, 00000001.00000003.265561008.0000000001371000.00000004.00000800.00020000.00000000.sdmp, SecuriteInfo.com.Win32.CrypterX-gen.16304.13478.exe, 00000001.00000003.263133405.00000000011D4000.00000004.00000800.00020000.00000000.sdmp
          Source: Binary string: wntdll.pdb source: SecuriteInfo.com.Win32.CrypterX-gen.16304.13478.exe, SecuriteInfo.com.Win32.CrypterX-gen.16304.13478.exe, 00000001.00000002.267578947.0000000001510000.00000040.00000800.00020000.00000000.sdmp, SecuriteInfo.com.Win32.CrypterX-gen.16304.13478.exe, 00000001.00000003.265561008.0000000001371000.00000004.00000800.00020000.00000000.sdmp, SecuriteInfo.com.Win32.CrypterX-gen.16304.13478.exe, 00000001.00000003.263133405.00000000011D4000.00000004.00000800.00020000.00000000.sdmp
          Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.CrypterX-gen.16304.13478.exeCode function: 0_2_0171F978 pushad ; iretd
          Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.CrypterX-gen.16304.13478.exeCode function: 0_2_01717AFF push eax; retf
          Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.CrypterX-gen.16304.13478.exeCode function: 1_2_0151191C pushfd ; iretd
          Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.CrypterX-gen.16304.13478.exeCode function: 1_2_0158D0D1 push ecx; ret
          Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.CrypterX-gen.16304.13478.exeCode function: 1_2_0151225E push eax; retf
          Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.CrypterX-gen.16304.13478.exeCode function: 1_2_01519271 push es; iretd
          Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.CrypterX-gen.16304.13478.exeCode function: 1_2_0151427E pushad ; retf 000Dh
          Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.CrypterX-gen.16304.13478.exeCode function: 1_2_0151322C push eax; retf
          Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.CrypterX-gen.16304.13478.exeCode function: 1_2_01514288 pushad ; retf
          Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.CrypterX-gen.16304.13478.exeCode function: 1_2_0151A7C0 push es; iretd
          Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.CrypterX-gen.16304.13478.exeCode function: 1_2_01513F9F pushad ; ret
          Source: initial sampleStatic PE information: section name: .text entropy: 7.649413315465482
          Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.CrypterX-gen.16304.13478.exeProcess information set: NOOPENFILEERRORBOX
          Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.CrypterX-gen.16304.13478.exeProcess information set: NOOPENFILEERRORBOX
          Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.CrypterX-gen.16304.13478.exeProcess information set: NOOPENFILEERRORBOX
          Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.CrypterX-gen.16304.13478.exeProcess information set: NOOPENFILEERRORBOX
          Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.CrypterX-gen.16304.13478.exeProcess information set: NOOPENFILEERRORBOX
          Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.CrypterX-gen.16304.13478.exeProcess information set: NOOPENFILEERRORBOX
          Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.CrypterX-gen.16304.13478.exeProcess information set: NOOPENFILEERRORBOX
          Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.CrypterX-gen.16304.13478.exeProcess information set: NOOPENFILEERRORBOX
          Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.CrypterX-gen.16304.13478.exeProcess information set: NOOPENFILEERRORBOX
          Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.CrypterX-gen.16304.13478.exeProcess information set: NOOPENFILEERRORBOX
          Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.CrypterX-gen.16304.13478.exeProcess information set: NOOPENFILEERRORBOX
          Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.CrypterX-gen.16304.13478.exeProcess information set: NOOPENFILEERRORBOX
          Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.CrypterX-gen.16304.13478.exeProcess information set: NOOPENFILEERRORBOX
          Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.CrypterX-gen.16304.13478.exeProcess information set: NOOPENFILEERRORBOX
          Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.CrypterX-gen.16304.13478.exeProcess information set: NOOPENFILEERRORBOX
          Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.CrypterX-gen.16304.13478.exeProcess information set: NOOPENFILEERRORBOX
          Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.CrypterX-gen.16304.13478.exeProcess information set: NOOPENFILEERRORBOX
          Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.CrypterX-gen.16304.13478.exeProcess information set: NOOPENFILEERRORBOX
          Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.CrypterX-gen.16304.13478.exeProcess information set: NOOPENFILEERRORBOX
          Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.CrypterX-gen.16304.13478.exeProcess information set: NOOPENFILEERRORBOX
          Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.CrypterX-gen.16304.13478.exeProcess information set: NOOPENFILEERRORBOX
          Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.CrypterX-gen.16304.13478.exeProcess information set: NOOPENFILEERRORBOX
          Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.CrypterX-gen.16304.13478.exeProcess information set: NOOPENFILEERRORBOX
          Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.CrypterX-gen.16304.13478.exeProcess information set: NOOPENFILEERRORBOX
          Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.CrypterX-gen.16304.13478.exeProcess information set: NOOPENFILEERRORBOX
          Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.CrypterX-gen.16304.13478.exeProcess information set: NOOPENFILEERRORBOX
          Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.CrypterX-gen.16304.13478.exeProcess information set: NOOPENFILEERRORBOX
          Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.CrypterX-gen.16304.13478.exeProcess information set: NOOPENFILEERRORBOX
          Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.CrypterX-gen.16304.13478.exeProcess information set: NOOPENFILEERRORBOX
          Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.CrypterX-gen.16304.13478.exeProcess information set: NOOPENFILEERRORBOX
          Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.CrypterX-gen.16304.13478.exeProcess information set: NOOPENFILEERRORBOX
          Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.CrypterX-gen.16304.13478.exeProcess information set: NOOPENFILEERRORBOX
          Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.CrypterX-gen.16304.13478.exeProcess information set: NOOPENFILEERRORBOX
          Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.CrypterX-gen.16304.13478.exeProcess information set: NOOPENFILEERRORBOX

          Malware Analysis System Evasion

          barindex
          Source: Yara matchFile source: 0.2.SecuriteInfo.com.Win32.CrypterX-gen.16304.13478.exe.3282f54.1.raw.unpack, type: UNPACKEDPE
          Source: Yara matchFile source: 0.2.SecuriteInfo.com.Win32.CrypterX-gen.16304.13478.exe.32a0724.0.raw.unpack, type: UNPACKEDPE
          Source: Yara matchFile source: 00000000.00000002.268979891.0000000003549000.00000004.00000800.00020000.00000000.sdmp, type: MEMORY
          Source: Yara matchFile source: 00000000.00000002.266387939.0000000003261000.00000004.00000800.00020000.00000000.sdmp, type: MEMORY
          Source: Yara matchFile source: Process Memory Space: SecuriteInfo.com.Win32.CrypterX-gen.16304.13478.exe PID: 5272, type: MEMORYSTR
          Source: SecuriteInfo.com.Win32.CrypterX-gen.16304.13478.exe, 00000000.00000002.268979891.0000000003549000.00000004.00000800.00020000.00000000.sdmp, SecuriteInfo.com.Win32.CrypterX-gen.16304.13478.exe, 00000000.00000002.266387939.0000000003261000.00000004.00000800.00020000.00000000.sdmpBinary or memory string: SBIEDLL.DLL
          Source: SecuriteInfo.com.Win32.CrypterX-gen.16304.13478.exe, 00000000.00000002.268979891.0000000003549000.00000004.00000800.00020000.00000000.sdmp, SecuriteInfo.com.Win32.CrypterX-gen.16304.13478.exe, 00000000.00000002.266387939.0000000003261000.00000004.00000800.00020000.00000000.sdmpBinary or memory string: KERNEL32.DLL.WINE_GET_UNIX_FILE_NAME
          Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.CrypterX-gen.16304.13478.exeRDTSC instruction interceptor: First address: 0000000000409904 second address: 000000000040990A instructions: 0x00000000 rdtsc 0x00000002 xor ecx, ecx 0x00000004 add ecx, eax 0x00000006 rdtsc
          Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.CrypterX-gen.16304.13478.exeRDTSC instruction interceptor: First address: 0000000000409B6E second address: 0000000000409B74 instructions: 0x00000000 rdtsc 0x00000002 xor ecx, ecx 0x00000004 add ecx, eax 0x00000006 rdtsc
          Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.CrypterX-gen.16304.13478.exe TID: 5180Thread sleep time: -38122s >= -30000s
          Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.CrypterX-gen.16304.13478.exe TID: 1404Thread sleep time: -922337203685477s >= -30000s
          Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.CrypterX-gen.16304.13478.exeCode function: 1_2_01605BA5 rdtsc
          Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.CrypterX-gen.16304.13478.exeThread delayed: delay time: 922337203685477
          Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.CrypterX-gen.16304.13478.exeAPI coverage: 0.5 %
          Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.CrypterX-gen.16304.13478.exeProcess information queried: ProcessInformation
          Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.CrypterX-gen.16304.13478.exeThread delayed: delay time: 38122
          Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.CrypterX-gen.16304.13478.exeThread delayed: delay time: 922337203685477
          Source: SecuriteInfo.com.Win32.CrypterX-gen.16304.13478.exe, 00000000.00000002.266387939.0000000003261000.00000004.00000800.00020000.00000000.sdmpBinary or memory string: InstallPathJC:\PROGRAM FILES\VMWARE\VMWARE TOOLS\
          Source: SecuriteInfo.com.Win32.CrypterX-gen.16304.13478.exe, 00000000.00000002.266387939.0000000003261000.00000004.00000800.00020000.00000000.sdmpBinary or memory string: vmware
          Source: SecuriteInfo.com.Win32.CrypterX-gen.16304.13478.exe, 00000000.00000002.266387939.0000000003261000.00000004.00000800.00020000.00000000.sdmpBinary or memory string: VMware SVGA II
          Source: SecuriteInfo.com.Win32.CrypterX-gen.16304.13478.exe, 00000000.00000002.266387939.0000000003261000.00000004.00000800.00020000.00000000.sdmpBinary or memory string: VMWAREDSOFTWARE\VMware, Inc.\VMware Tools
          Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.CrypterX-gen.16304.13478.exeCode function: 1_2_01605BA5 rdtsc
          Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.CrypterX-gen.16304.13478.exeCode function: 1_2_01608966 mov eax, dword ptr fs:[00000030h]
          Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.CrypterX-gen.16304.13478.exeCode function: 1_2_0153395E mov eax, dword ptr fs:[00000030h]
          Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.CrypterX-gen.16304.13478.exeCode function: 1_2_0153395E mov eax, dword ptr fs:[00000030h]
          Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.CrypterX-gen.16304.13478.exeCode function: 1_2_015F1951 mov eax, dword ptr fs:[00000030h]
          Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.CrypterX-gen.16304.13478.exeCode function: 1_2_0155B944 mov eax, dword ptr fs:[00000030h]
          Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.CrypterX-gen.16304.13478.exeCode function: 1_2_0155B944 mov eax, dword ptr fs:[00000030h]
          Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.CrypterX-gen.16304.13478.exeCode function: 1_2_0153B171 mov eax, dword ptr fs:[00000030h]
          Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.CrypterX-gen.16304.13478.exeCode function: 1_2_0153B171 mov eax, dword ptr fs:[00000030h]
          Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.CrypterX-gen.16304.13478.exeCode function: 1_2_0153C962 mov eax, dword ptr fs:[00000030h]
          Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.CrypterX-gen.16304.13478.exeCode function: 1_2_015FE962 mov eax, dword ptr fs:[00000030h]
          Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.CrypterX-gen.16304.13478.exeCode function: 1_2_01539100 mov eax, dword ptr fs:[00000030h]
          Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.CrypterX-gen.16304.13478.exeCode function: 1_2_01539100 mov eax, dword ptr fs:[00000030h]
          Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.CrypterX-gen.16304.13478.exeCode function: 1_2_01539100 mov eax, dword ptr fs:[00000030h]
          Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.CrypterX-gen.16304.13478.exeCode function: 1_2_01540100 mov eax, dword ptr fs:[00000030h]
          Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.CrypterX-gen.16304.13478.exeCode function: 1_2_01540100 mov eax, dword ptr fs:[00000030h]
          Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.CrypterX-gen.16304.13478.exeCode function: 1_2_01540100 mov eax, dword ptr fs:[00000030h]
          Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.CrypterX-gen.16304.13478.exeCode function: 1_2_01533138 mov ecx, dword ptr fs:[00000030h]
          Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.CrypterX-gen.16304.13478.exeCode function: 1_2_0156513A mov eax, dword ptr fs:[00000030h]
          Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.CrypterX-gen.16304.13478.exeCode function: 1_2_0156513A mov eax, dword ptr fs:[00000030h]
          Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.CrypterX-gen.16304.13478.exeCode function: 1_2_01554120 mov eax, dword ptr fs:[00000030h]
          Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.CrypterX-gen.16304.13478.exeCode function: 1_2_01554120 mov eax, dword ptr fs:[00000030h]
          Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.CrypterX-gen.16304.13478.exeCode function: 1_2_01554120 mov eax, dword ptr fs:[00000030h]
          Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.CrypterX-gen.16304.13478.exeCode function: 1_2_01554120 mov eax, dword ptr fs:[00000030h]
          Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.CrypterX-gen.16304.13478.exeCode function: 1_2_01554120 mov ecx, dword ptr fs:[00000030h]
          Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.CrypterX-gen.16304.13478.exeCode function: 1_2_015F19D8 mov eax, dword ptr fs:[00000030h]
          Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.CrypterX-gen.16304.13478.exeCode function: 1_2_016089E7 mov eax, dword ptr fs:[00000030h]
          Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.CrypterX-gen.16304.13478.exeCode function: 1_2_015499C7 mov eax, dword ptr fs:[00000030h]
          Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.CrypterX-gen.16304.13478.exeCode function: 1_2_015499C7 mov eax, dword ptr fs:[00000030h]
          Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.CrypterX-gen.16304.13478.exeCode function: 1_2_015499C7 mov eax, dword ptr fs:[00000030h]
          Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.CrypterX-gen.16304.13478.exeCode function: 1_2_015499C7 mov eax, dword ptr fs:[00000030h]
          Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.CrypterX-gen.16304.13478.exeCode function: 1_2_0154C1C0 mov eax, dword ptr fs:[00000030h]
          Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.CrypterX-gen.16304.13478.exeCode function: 1_2_0153B1E1 mov eax, dword ptr fs:[00000030h]
          Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.CrypterX-gen.16304.13478.exeCode function: 1_2_0153B1E1 mov eax, dword ptr fs:[00000030h]
          Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.CrypterX-gen.16304.13478.exeCode function: 1_2_0153B1E1 mov eax, dword ptr fs:[00000030h]
          Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.CrypterX-gen.16304.13478.exeCode function: 1_2_015331E0 mov eax, dword ptr fs:[00000030h]
          Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.CrypterX-gen.16304.13478.exeCode function: 1_2_015C41E8 mov eax, dword ptr fs:[00000030h]
          Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.CrypterX-gen.16304.13478.exeCode function: 1_2_01562990 mov eax, dword ptr fs:[00000030h]
          Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.CrypterX-gen.16304.13478.exeCode function: 1_2_01564190 mov eax, dword ptr fs:[00000030h]
          Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.CrypterX-gen.16304.13478.exeCode function: 1_2_0153519E mov eax, dword ptr fs:[00000030h]
          Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.CrypterX-gen.16304.13478.exeCode function: 1_2_0153519E mov ecx, dword ptr fs:[00000030h]
          Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.CrypterX-gen.16304.13478.exeCode function: 1_2_0156A185 mov eax, dword ptr fs:[00000030h]
          Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.CrypterX-gen.16304.13478.exeCode function: 1_2_0160F1B5 mov eax, dword ptr fs:[00000030h]
          Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.CrypterX-gen.16304.13478.exeCode function: 1_2_0160F1B5 mov eax, dword ptr fs:[00000030h]
          Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.CrypterX-gen.16304.13478.exeCode function: 1_2_015FA189 mov eax, dword ptr fs:[00000030h]
          Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.CrypterX-gen.16304.13478.exeCode function: 1_2_015FA189 mov ecx, dword ptr fs:[00000030h]
          Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.CrypterX-gen.16304.13478.exeCode function: 1_2_0155C182 mov eax, dword ptr fs:[00000030h]
          Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.CrypterX-gen.16304.13478.exeCode function: 1_2_015B51BE mov eax, dword ptr fs:[00000030h]
          Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.CrypterX-gen.16304.13478.exeCode function: 1_2_015B51BE mov eax, dword ptr fs:[00000030h]
          Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.CrypterX-gen.16304.13478.exeCode function: 1_2_015B51BE mov eax, dword ptr fs:[00000030h]
          Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.CrypterX-gen.16304.13478.exeCode function: 1_2_015B51BE mov eax, dword ptr fs:[00000030h]
          Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.CrypterX-gen.16304.13478.exeCode function: 1_2_0156C9BF mov eax, dword ptr fs:[00000030h]
          Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.CrypterX-gen.16304.13478.exeCode function: 1_2_0156C9BF mov eax, dword ptr fs:[00000030h]
          Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.CrypterX-gen.16304.13478.exeCode function: 1_2_015599BF mov ecx, dword ptr fs:[00000030h]
          Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.CrypterX-gen.16304.13478.exeCode function: 1_2_015599BF mov ecx, dword ptr fs:[00000030h]
          Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.CrypterX-gen.16304.13478.exeCode function: 1_2_015599BF mov eax, dword ptr fs:[00000030h]
          Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.CrypterX-gen.16304.13478.exeCode function: 1_2_015599BF mov ecx, dword ptr fs:[00000030h]
          Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.CrypterX-gen.16304.13478.exeCode function: 1_2_015599BF mov ecx, dword ptr fs:[00000030h]
          Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.CrypterX-gen.16304.13478.exeCode function: 1_2_015599BF mov eax, dword ptr fs:[00000030h]
          Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.CrypterX-gen.16304.13478.exeCode function: 1_2_015599BF mov ecx, dword ptr fs:[00000030h]
          Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.CrypterX-gen.16304.13478.exeCode function: 1_2_015599BF mov ecx, dword ptr fs:[00000030h]
          Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.CrypterX-gen.16304.13478.exeCode function: 1_2_015599BF mov eax, dword ptr fs:[00000030h]
          Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.CrypterX-gen.16304.13478.exeCode function: 1_2_015599BF mov ecx, dword ptr fs:[00000030h]
          Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.CrypterX-gen.16304.13478.exeCode function: 1_2_015599BF mov ecx, dword ptr fs:[00000030h]
          Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.CrypterX-gen.16304.13478.exeCode function: 1_2_015599BF mov eax, dword ptr fs:[00000030h]
          Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.CrypterX-gen.16304.13478.exeCode function: 1_2_015461A7 mov eax, dword ptr fs:[00000030h]
          Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.CrypterX-gen.16304.13478.exeCode function: 1_2_015461A7 mov eax, dword ptr fs:[00000030h]
          Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.CrypterX-gen.16304.13478.exeCode function: 1_2_015461A7 mov eax, dword ptr fs:[00000030h]
          Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.CrypterX-gen.16304.13478.exeCode function: 1_2_015461A7 mov eax, dword ptr fs:[00000030h]
          Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.CrypterX-gen.16304.13478.exeCode function: 1_2_015661A0 mov eax, dword ptr fs:[00000030h]
          Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.CrypterX-gen.16304.13478.exeCode function: 1_2_015661A0 mov eax, dword ptr fs:[00000030h]
          Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.CrypterX-gen.16304.13478.exeCode function: 1_2_015F49A4 mov eax, dword ptr fs:[00000030h]
          Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.CrypterX-gen.16304.13478.exeCode function: 1_2_015F49A4 mov eax, dword ptr fs:[00000030h]
          Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.CrypterX-gen.16304.13478.exeCode function: 1_2_015F49A4 mov eax, dword ptr fs:[00000030h]
          Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.CrypterX-gen.16304.13478.exeCode function: 1_2_015F49A4 mov eax, dword ptr fs:[00000030h]
          Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.CrypterX-gen.16304.13478.exeCode function: 1_2_015B69A6 mov eax, dword ptr fs:[00000030h]
          Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.CrypterX-gen.16304.13478.exeCode function: 1_2_01535050 mov eax, dword ptr fs:[00000030h]
          Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.CrypterX-gen.16304.13478.exeCode function: 1_2_01535050 mov eax, dword ptr fs:[00000030h]
          Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.CrypterX-gen.16304.13478.exeCode function: 1_2_01535050 mov eax, dword ptr fs:[00000030h]
          Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.CrypterX-gen.16304.13478.exeCode function: 1_2_01537057 mov eax, dword ptr fs:[00000030h]
          Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.CrypterX-gen.16304.13478.exeCode function: 1_2_01550050 mov eax, dword ptr fs:[00000030h]
          Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.CrypterX-gen.16304.13478.exeCode function: 1_2_01550050 mov eax, dword ptr fs:[00000030h]
          Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.CrypterX-gen.16304.13478.exeCode function: 1_2_01601074 mov eax, dword ptr fs:[00000030h]
          Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.CrypterX-gen.16304.13478.exeCode function: 1_2_015F1843 mov eax, dword ptr fs:[00000030h]
          Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.CrypterX-gen.16304.13478.exeCode function: 1_2_015F2073 mov eax, dword ptr fs:[00000030h]
          Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.CrypterX-gen.16304.13478.exeCode function: 1_2_0155F86D mov eax, dword ptr fs:[00000030h]
          Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.CrypterX-gen.16304.13478.exeCode function: 1_2_0156701D mov eax, dword ptr fs:[00000030h]
          Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.CrypterX-gen.16304.13478.exeCode function: 1_2_0156701D mov eax, dword ptr fs:[00000030h]
          Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.CrypterX-gen.16304.13478.exeCode function: 1_2_0156701D mov eax, dword ptr fs:[00000030h]
          Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.CrypterX-gen.16304.13478.exeCode function: 1_2_0156701D mov eax, dword ptr fs:[00000030h]
          Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.CrypterX-gen.16304.13478.exeCode function: 1_2_0156701D mov eax, dword ptr fs:[00000030h]
          Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.CrypterX-gen.16304.13478.exeCode function: 1_2_0156701D mov eax, dword ptr fs:[00000030h]
          Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.CrypterX-gen.16304.13478.exeCode function: 1_2_015B7016 mov eax, dword ptr fs:[00000030h]
          Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.CrypterX-gen.16304.13478.exeCode function: 1_2_015B7016 mov eax, dword ptr fs:[00000030h]
          Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.CrypterX-gen.16304.13478.exeCode function: 1_2_015B7016 mov eax, dword ptr fs:[00000030h]
          Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.CrypterX-gen.16304.13478.exeCode function: 1_2_01536800 mov eax, dword ptr fs:[00000030h]
          Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.CrypterX-gen.16304.13478.exeCode function: 1_2_01536800 mov eax, dword ptr fs:[00000030h]
          Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.CrypterX-gen.16304.13478.exeCode function: 1_2_01536800 mov eax, dword ptr fs:[00000030h]
          Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.CrypterX-gen.16304.13478.exeCode function: 1_2_0155A830 mov eax, dword ptr fs:[00000030h]
          Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.CrypterX-gen.16304.13478.exeCode function: 1_2_0155A830 mov eax, dword ptr fs:[00000030h]
          Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.CrypterX-gen.16304.13478.exeCode function: 1_2_0155A830 mov eax, dword ptr fs:[00000030h]
          Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.CrypterX-gen.16304.13478.exeCode function: 1_2_0155A830 mov eax, dword ptr fs:[00000030h]
          Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.CrypterX-gen.16304.13478.exeCode function: 1_2_01604015 mov eax, dword ptr fs:[00000030h]
          Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.CrypterX-gen.16304.13478.exeCode function: 1_2_01604015 mov eax, dword ptr fs:[00000030h]
          Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.CrypterX-gen.16304.13478.exeCode function: 1_2_01564020 mov edi, dword ptr fs:[00000030h]
          Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.CrypterX-gen.16304.13478.exeCode function: 1_2_0156002D mov eax, dword ptr fs:[00000030h]
          Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.CrypterX-gen.16304.13478.exeCode function: 1_2_0156002D mov eax, dword ptr fs:[00000030h]
          Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.CrypterX-gen.16304.13478.exeCode function: 1_2_0156002D mov eax, dword ptr fs:[00000030h]
          Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.CrypterX-gen.16304.13478.exeCode function: 1_2_0156002D mov eax, dword ptr fs:[00000030h]
          Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.CrypterX-gen.16304.13478.exeCode function: 1_2_0156002D mov eax, dword ptr fs:[00000030h]
          Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.CrypterX-gen.16304.13478.exeCode function: 1_2_0154B02A mov eax, dword ptr fs:[00000030h]
          Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.CrypterX-gen.16304.13478.exeCode function: 1_2_0154B02A mov eax, dword ptr fs:[00000030h]
          Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.CrypterX-gen.16304.13478.exeCode function: 1_2_0154B02A mov eax, dword ptr fs:[00000030h]
          Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.CrypterX-gen.16304.13478.exeCode function: 1_2_0154B02A mov eax, dword ptr fs:[00000030h]
          Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.CrypterX-gen.16304.13478.exeCode function: 1_2_015378D6 mov eax, dword ptr fs:[00000030h]
          Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.CrypterX-gen.16304.13478.exeCode function: 1_2_015378D6 mov eax, dword ptr fs:[00000030h]
          Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.CrypterX-gen.16304.13478.exeCode function: 1_2_015378D6 mov ecx, dword ptr fs:[00000030h]
          Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.CrypterX-gen.16304.13478.exeCode function: 1_2_015CB8D0 mov eax, dword ptr fs:[00000030h]
          Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.CrypterX-gen.16304.13478.exeCode function: 1_2_015CB8D0 mov ecx, dword ptr fs:[00000030h]
          Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.CrypterX-gen.16304.13478.exeCode function: 1_2_015CB8D0 mov eax, dword ptr fs:[00000030h]
          Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.CrypterX-gen.16304.13478.exeCode function: 1_2_015CB8D0 mov eax, dword ptr fs:[00000030h]
          Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.CrypterX-gen.16304.13478.exeCode function: 1_2_015CB8D0 mov eax, dword ptr fs:[00000030h]
          Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.CrypterX-gen.16304.13478.exeCode function: 1_2_015CB8D0 mov eax, dword ptr fs:[00000030h]
          Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.CrypterX-gen.16304.13478.exeCode function: 1_2_015370C0 mov eax, dword ptr fs:[00000030h]
          Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.CrypterX-gen.16304.13478.exeCode function: 1_2_015370C0 mov eax, dword ptr fs:[00000030h]
          Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.CrypterX-gen.16304.13478.exeCode function: 1_2_015F18CA mov eax, dword ptr fs:[00000030h]
          Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.CrypterX-gen.16304.13478.exeCode function: 1_2_015428FD mov eax, dword ptr fs:[00000030h]
          Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.CrypterX-gen.16304.13478.exeCode function: 1_2_015428FD mov eax, dword ptr fs:[00000030h]
          Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.CrypterX-gen.16304.13478.exeCode function: 1_2_015428FD mov eax, dword ptr fs:[00000030h]
          Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.CrypterX-gen.16304.13478.exeCode function: 1_2_015F60F5 mov eax, dword ptr fs:[00000030h]
          Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.CrypterX-gen.16304.13478.exeCode function: 1_2_015F60F5 mov eax, dword ptr fs:[00000030h]
          Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.CrypterX-gen.16304.13478.exeCode function: 1_2_015F60F5 mov eax, dword ptr fs:[00000030h]
          Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.CrypterX-gen.16304.13478.exeCode function: 1_2_015F60F5 mov eax, dword ptr fs:[00000030h]
          Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.CrypterX-gen.16304.13478.exeCode function: 1_2_0155B8E4 mov eax, dword ptr fs:[00000030h]
          Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.CrypterX-gen.16304.13478.exeCode function: 1_2_0155B8E4 mov eax, dword ptr fs:[00000030h]
          Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.CrypterX-gen.16304.13478.exeCode function: 1_2_015340E1 mov eax, dword ptr fs:[00000030h]
          Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.CrypterX-gen.16304.13478.exeCode function: 1_2_015340E1 mov eax, dword ptr fs:[00000030h]
          Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.CrypterX-gen.16304.13478.exeCode function: 1_2_015340E1 mov eax, dword ptr fs:[00000030h]
          Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.CrypterX-gen.16304.13478.exeCode function: 1_2_015358EC mov eax, dword ptr fs:[00000030h]
          Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.CrypterX-gen.16304.13478.exeCode function: 1_2_01539080 mov eax, dword ptr fs:[00000030h]
          Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.CrypterX-gen.16304.13478.exeCode function: 1_2_01533880 mov eax, dword ptr fs:[00000030h]
          Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.CrypterX-gen.16304.13478.exeCode function: 1_2_01533880 mov eax, dword ptr fs:[00000030h]
          Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.CrypterX-gen.16304.13478.exeCode function: 1_2_015B3884 mov eax, dword ptr fs:[00000030h]
          Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.CrypterX-gen.16304.13478.exeCode function: 1_2_015B3884 mov eax, dword ptr fs:[00000030h]
          Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.CrypterX-gen.16304.13478.exeCode function: 1_2_0156F0BF mov ecx, dword ptr fs:[00000030h]
          Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.CrypterX-gen.16304.13478.exeCode function: 1_2_0156F0BF mov eax, dword ptr fs:[00000030h]
          Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.CrypterX-gen.16304.13478.exeCode function: 1_2_0156F0BF mov eax, dword ptr fs:[00000030h]
          Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.CrypterX-gen.16304.13478.exeCode function: 1_2_015620A0 mov eax, dword ptr fs:[00000030h]
          Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.CrypterX-gen.16304.13478.exeCode function: 1_2_015620A0 mov eax, dword ptr fs:[00000030h]
          Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.CrypterX-gen.16304.13478.exeCode function: 1_2_015620A0 mov eax, dword ptr fs:[00000030h]
          Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.CrypterX-gen.16304.13478.exeCode function: 1_2_015620A0 mov eax, dword ptr fs:[00000030h]
          Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.CrypterX-gen.16304.13478.exeCode function: 1_2_015620A0 mov eax, dword ptr fs:[00000030h]
          Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.CrypterX-gen.16304.13478.exeCode function: 1_2_015620A0 mov eax, dword ptr fs:[00000030h]
          Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.CrypterX-gen.16304.13478.exeCode function: 1_2_015678A0 mov eax, dword ptr fs:[00000030h]
          Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.CrypterX-gen.16304.13478.exeCode function: 1_2_015678A0 mov eax, dword ptr fs:[00000030h]
          Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.CrypterX-gen.16304.13478.exeCode function: 1_2_015678A0 mov eax, dword ptr fs:[00000030h]
          Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.CrypterX-gen.16304.13478.exeCode function: 1_2_015678A0 mov eax, dword ptr fs:[00000030h]
          Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.CrypterX-gen.16304.13478.exeCode function: 1_2_015678A0 mov eax, dword ptr fs:[00000030h]
          Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.CrypterX-gen.16304.13478.exeCode function: 1_2_015678A0 mov eax, dword ptr fs:[00000030h]
          Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.CrypterX-gen.16304.13478.exeCode function: 1_2_015678A0 mov eax, dword ptr fs:[00000030h]
          Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.CrypterX-gen.16304.13478.exeCode function: 1_2_015678A0 mov eax, dword ptr fs:[00000030h]
          Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.CrypterX-gen.16304.13478.exeCode function: 1_2_015678A0 mov eax, dword ptr fs:[00000030h]
          Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.CrypterX-gen.16304.13478.exeCode function: 1_2_015790AF mov eax, dword ptr fs:[00000030h]
          Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.CrypterX-gen.16304.13478.exeCode function: 1_2_015428AE mov eax, dword ptr fs:[00000030h]
          Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.CrypterX-gen.16304.13478.exeCode function: 1_2_015428AE mov eax, dword ptr fs:[00000030h]
          Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.CrypterX-gen.16304.13478.exeCode function: 1_2_015428AE mov eax, dword ptr fs:[00000030h]
          Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.CrypterX-gen.16304.13478.exeCode function: 1_2_015428AE mov ecx, dword ptr fs:[00000030h]
          Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.CrypterX-gen.16304.13478.exeCode function: 1_2_015428AE mov eax, dword ptr fs:[00000030h]
          Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.CrypterX-gen.16304.13478.exeCode function: 1_2_015428AE mov eax, dword ptr fs:[00000030h]
          Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.CrypterX-gen.16304.13478.exeCode function: 1_2_0153F358 mov eax, dword ptr fs:[00000030h]
          Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.CrypterX-gen.16304.13478.exeCode function: 1_2_01563B5A mov eax, dword ptr fs:[00000030h]
          Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.CrypterX-gen.16304.13478.exeCode function: 1_2_01563B5A mov eax, dword ptr fs:[00000030h]
          Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.CrypterX-gen.16304.13478.exeCode function: 1_2_01563B5A mov eax, dword ptr fs:[00000030h]
          Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.CrypterX-gen.16304.13478.exeCode function: 1_2_01563B5A mov eax, dword ptr fs:[00000030h]
          Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.CrypterX-gen.16304.13478.exeCode function: 1_2_0153DB40 mov eax, dword ptr fs:[00000030h]
          Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.CrypterX-gen.16304.13478.exeCode function: 1_2_01537B70 mov eax, dword ptr fs:[00000030h]
          Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.CrypterX-gen.16304.13478.exeCode function: 1_2_0154F370 mov eax, dword ptr fs:[00000030h]
          Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.CrypterX-gen.16304.13478.exeCode function: 1_2_0154F370 mov eax, dword ptr fs:[00000030h]
          Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.CrypterX-gen.16304.13478.exeCode function: 1_2_0154F370 mov eax, dword ptr fs:[00000030h]
          Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.CrypterX-gen.16304.13478.exeCode function: 1_2_01563B7A mov eax, dword ptr fs:[00000030h]
          Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.CrypterX-gen.16304.13478.exeCode function: 1_2_01563B7A mov eax, dword ptr fs:[00000030h]
          Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.CrypterX-gen.16304.13478.exeCode function: 1_2_0153DB60 mov ecx, dword ptr fs:[00000030h]
          Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.CrypterX-gen.16304.13478.exeCode function: 1_2_01608B58 mov eax, dword ptr fs:[00000030h]
          Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.CrypterX-gen.16304.13478.exeCode function: 1_2_015C6365 mov eax, dword ptr fs:[00000030h]
          Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.CrypterX-gen.16304.13478.exeCode function: 1_2_015C6365 mov eax, dword ptr fs:[00000030h]
          Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.CrypterX-gen.16304.13478.exeCode function: 1_2_015C6365 mov eax, dword ptr fs:[00000030h]
          Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.CrypterX-gen.16304.13478.exeCode function: 1_2_015F131B mov eax, dword ptr fs:[00000030h]
          Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.CrypterX-gen.16304.13478.exeCode function: 1_2_0155A309 mov eax, dword ptr fs:[00000030h]
          Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.CrypterX-gen.16304.13478.exeCode function: 1_2_0155A309 mov eax, dword ptr fs:[00000030h]
          Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.CrypterX-gen.16304.13478.exeCode function: 1_2_0155A309 mov eax, dword ptr fs:[00000030h]
          Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.CrypterX-gen.16304.13478.exeCode function: 1_2_0155A309 mov eax, dword ptr fs:[00000030h]
          Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.CrypterX-gen.16304.13478.exeCode function: 1_2_0155A309 mov eax, dword ptr fs:[00000030h]
          Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.CrypterX-gen.16304.13478.exeCode function: 1_2_0155A309 mov eax, dword ptr fs:[00000030h]
          Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.CrypterX-gen.16304.13478.exeCode function: 1_2_0155A309 mov eax, dword ptr fs:[00000030h]
          Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.CrypterX-gen.16304.13478.exeCode function: 1_2_0155A309 mov eax, dword ptr fs:[00000030h]
          Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.CrypterX-gen.16304.13478.exeCode function: 1_2_0155A309 mov eax, dword ptr fs:[00000030h]
          Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.CrypterX-gen.16304.13478.exeCode function: 1_2_0155A309 mov eax, dword ptr fs:[00000030h]
          Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.CrypterX-gen.16304.13478.exeCode function: 1_2_0155A309 mov eax, dword ptr fs:[00000030h]
          Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.CrypterX-gen.16304.13478.exeCode function: 1_2_0155A309 mov eax, dword ptr fs:[00000030h]
          Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.CrypterX-gen.16304.13478.exeCode function: 1_2_0155A309 mov eax, dword ptr fs:[00000030h]
          Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.CrypterX-gen.16304.13478.exeCode function: 1_2_0155A309 mov eax, dword ptr fs:[00000030h]
          Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.CrypterX-gen.16304.13478.exeCode function: 1_2_0155A309 mov eax, dword ptr fs:[00000030h]
          Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.CrypterX-gen.16304.13478.exeCode function: 1_2_0155A309 mov eax, dword ptr fs:[00000030h]
          Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.CrypterX-gen.16304.13478.exeCode function: 1_2_0155A309 mov eax, dword ptr fs:[00000030h]
          Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.CrypterX-gen.16304.13478.exeCode function: 1_2_0155A309 mov eax, dword ptr fs:[00000030h]
          Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.CrypterX-gen.16304.13478.exeCode function: 1_2_0155A309 mov eax, dword ptr fs:[00000030h]
          Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.CrypterX-gen.16304.13478.exeCode function: 1_2_0155A309 mov eax, dword ptr fs:[00000030h]
          Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.CrypterX-gen.16304.13478.exeCode function: 1_2_0155A309 mov eax, dword ptr fs:[00000030h]
          Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.CrypterX-gen.16304.13478.exeCode function: 1_2_015B53CA mov eax, dword ptr fs:[00000030h]
          Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.CrypterX-gen.16304.13478.exeCode function: 1_2_015B53CA mov eax, dword ptr fs:[00000030h]
          Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.CrypterX-gen.16304.13478.exeCode function: 1_2_015653C5 mov eax, dword ptr fs:[00000030h]
          Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.CrypterX-gen.16304.13478.exeCode function: 1_2_015603E2 mov eax, dword ptr fs:[00000030h]
          Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.CrypterX-gen.16304.13478.exeCode function: 1_2_015603E2 mov eax, dword ptr fs:[00000030h]
          Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.CrypterX-gen.16304.13478.exeCode function: 1_2_015603E2 mov eax, dword ptr fs:[00000030h]
          Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.CrypterX-gen.16304.13478.exeCode function: 1_2_015603E2 mov eax, dword ptr fs:[00000030h]
          Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.CrypterX-gen.16304.13478.exeCode function: 1_2_015603E2 mov eax, dword ptr fs:[00000030h]
          Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.CrypterX-gen.16304.13478.exeCode function: 1_2_015603E2 mov eax, dword ptr fs:[00000030h]
          Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.CrypterX-gen.16304.13478.exeCode function: 1_2_01531BE9 mov eax, dword ptr fs:[00000030h]
          Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.CrypterX-gen.16304.13478.exeCode function: 1_2_0155DBE9 mov eax, dword ptr fs:[00000030h]
          Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.CrypterX-gen.16304.13478.exeCode function: 1_2_015E23E3 mov ecx, dword ptr fs:[00000030h]
          Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.CrypterX-gen.16304.13478.exeCode function: 1_2_015E23E3 mov ecx, dword ptr fs:[00000030h]
          Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.CrypterX-gen.16304.13478.exeCode function: 1_2_015E23E3 mov eax, dword ptr fs:[00000030h]
          Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.CrypterX-gen.16304.13478.exeCode function: 1_2_01562397 mov eax, dword ptr fs:[00000030h]
          Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.CrypterX-gen.16304.13478.exeCode function: 1_2_01605BA5 mov eax, dword ptr fs:[00000030h]
          Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.CrypterX-gen.16304.13478.exeCode function: 1_2_0156B390 mov eax, dword ptr fs:[00000030h]
          Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.CrypterX-gen.16304.13478.exeCode function: 1_2_01534B94 mov edi, dword ptr fs:[00000030h]
          Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.CrypterX-gen.16304.13478.exeCode function: 1_2_0155EB9A mov eax, dword ptr fs:[00000030h]
          Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.CrypterX-gen.16304.13478.exeCode function: 1_2_0155EB9A mov eax, dword ptr fs:[00000030h]
          Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.CrypterX-gen.16304.13478.exeCode function: 1_2_015F138A mov eax, dword ptr fs:[00000030h]
          Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.CrypterX-gen.16304.13478.exeCode function: 1_2_01608BB6 mov eax, dword ptr fs:[00000030h]
          Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.CrypterX-gen.16304.13478.exeCode function: 1_2_015DEB8A mov ecx, dword ptr fs:[00000030h]
          Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.CrypterX-gen.16304.13478.exeCode function: 1_2_015DEB8A mov eax, dword ptr fs:[00000030h]
          Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.CrypterX-gen.16304.13478.exeCode function: 1_2_015DEB8A mov eax, dword ptr fs:[00000030h]
          Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.CrypterX-gen.16304.13478.exeCode function: 1_2_015DEB8A mov eax, dword ptr fs:[00000030h]
          Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.CrypterX-gen.16304.13478.exeCode function: 1_2_01541B8F mov eax, dword ptr fs:[00000030h]
          Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.CrypterX-gen.16304.13478.exeCode function: 1_2_01541B8F mov eax, dword ptr fs:[00000030h]
          Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.CrypterX-gen.16304.13478.exeCode function: 1_2_0156138B mov eax, dword ptr fs:[00000030h]
          Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.CrypterX-gen.16304.13478.exeCode function: 1_2_0156138B mov eax, dword ptr fs:[00000030h]
          Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.CrypterX-gen.16304.13478.exeCode function: 1_2_0156138B mov eax, dword ptr fs:[00000030h]
          Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.CrypterX-gen.16304.13478.exeCode function: 1_2_015ED380 mov ecx, dword ptr fs:[00000030h]
          Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.CrypterX-gen.16304.13478.exeCode function: 1_2_01609BBE mov eax, dword ptr fs:[00000030h]
          Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.CrypterX-gen.16304.13478.exeCode function: 1_2_015F1BA8 mov eax, dword ptr fs:[00000030h]
          Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.CrypterX-gen.16304.13478.exeCode function: 1_2_01564BAD mov eax, dword ptr fs:[00000030h]
          Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.CrypterX-gen.16304.13478.exeCode function: 1_2_01564BAD mov eax, dword ptr fs:[00000030h]
          Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.CrypterX-gen.16304.13478.exeCode function: 1_2_01564BAD mov eax, dword ptr fs:[00000030h]
          Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.CrypterX-gen.16304.13478.exeCode function: 1_2_015F1A5F mov eax, dword ptr fs:[00000030h]
          Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.CrypterX-gen.16304.13478.exeCode function: 1_2_01608A62 mov eax, dword ptr fs:[00000030h]
          Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.CrypterX-gen.16304.13478.exeCode function: 1_2_015FEA55 mov eax, dword ptr fs:[00000030h]
          Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.CrypterX-gen.16304.13478.exeCode function: 1_2_015C4257 mov eax, dword ptr fs:[00000030h]
          Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.CrypterX-gen.16304.13478.exeCode function: 1_2_015F5A4F mov eax, dword ptr fs:[00000030h]
          Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.CrypterX-gen.16304.13478.exeCode function: 1_2_015F5A4F mov eax, dword ptr fs:[00000030h]
          Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.CrypterX-gen.16304.13478.exeCode function: 1_2_015F5A4F mov eax, dword ptr fs:[00000030h]
          Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.CrypterX-gen.16304.13478.exeCode function: 1_2_015F5A4F mov eax, dword ptr fs:[00000030h]
          Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.CrypterX-gen.16304.13478.exeCode function: 1_2_01539240 mov eax, dword ptr fs:[00000030h]
          Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.CrypterX-gen.16304.13478.exeCode function: 1_2_01539240 mov eax, dword ptr fs:[00000030h]
          Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.CrypterX-gen.16304.13478.exeCode function: 1_2_01539240 mov eax, dword ptr fs:[00000030h]
          Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.CrypterX-gen.16304.13478.exeCode function: 1_2_01539240 mov eax, dword ptr fs:[00000030h]
          Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.CrypterX-gen.16304.13478.exeCode function: 1_2_0157927A mov eax, dword ptr fs:[00000030h]
          Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.CrypterX-gen.16304.13478.exeCode function: 1_2_015EB260 mov eax, dword ptr fs:[00000030h]
          Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.CrypterX-gen.16304.13478.exeCode function: 1_2_015EB260 mov eax, dword ptr fs:[00000030h]
          Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.CrypterX-gen.16304.13478.exeCode function: 1_2_01575A69 mov eax, dword ptr fs:[00000030h]
          Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.CrypterX-gen.16304.13478.exeCode function: 1_2_01575A69 mov eax, dword ptr fs:[00000030h]
          Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.CrypterX-gen.16304.13478.exeCode function: 1_2_01575A69 mov eax, dword ptr fs:[00000030h]
          Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.CrypterX-gen.16304.13478.exeCode function: 1_2_01535210 mov eax, dword ptr fs:[00000030h]
          Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.CrypterX-gen.16304.13478.exeCode function: 1_2_01535210 mov ecx, dword ptr fs:[00000030h]
          Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.CrypterX-gen.16304.13478.exeCode function: 1_2_01535210 mov eax, dword ptr fs:[00000030h]
          Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.CrypterX-gen.16304.13478.exeCode function: 1_2_01535210 mov eax, dword ptr fs:[00000030h]
          Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.CrypterX-gen.16304.13478.exeCode function: 1_2_0153AA16 mov eax, dword ptr fs:[00000030h]
          Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.CrypterX-gen.16304.13478.exeCode function: 1_2_0153AA16 mov eax, dword ptr fs:[00000030h]
          Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.CrypterX-gen.16304.13478.exeCode function: 1_2_01553A1C mov eax, dword ptr fs:[00000030h]
          Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.CrypterX-gen.16304.13478.exeCode function: 1_2_015FAA16 mov eax, dword ptr fs:[00000030h]
          Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.CrypterX-gen.16304.13478.exeCode function: 1_2_015FAA16 mov eax, dword ptr fs:[00000030h]
          Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.CrypterX-gen.16304.13478.exeCode function: 1_2_0154BA00 mov eax, dword ptr fs:[00000030h]
          Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.CrypterX-gen.16304.13478.exeCode function: 1_2_0154BA00 mov eax, dword ptr fs:[00000030h]
          Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.CrypterX-gen.16304.13478.exeCode function: 1_2_0154BA00 mov eax, dword ptr fs:[00000030h]
          Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.CrypterX-gen.16304.13478.exeCode function: 1_2_0154BA00 mov ecx, dword ptr fs:[00000030h]
          Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.CrypterX-gen.16304.13478.exeCode function: 1_2_0154BA00 mov eax, dword ptr fs:[00000030h]
          Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.CrypterX-gen.16304.13478.exeCode function: 1_2_0154BA00 mov eax, dword ptr fs:[00000030h]
          Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.CrypterX-gen.16304.13478.exeCode function: 1_2_0154BA00 mov eax, dword ptr fs:[00000030h]
          Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.CrypterX-gen.16304.13478.exeCode function: 1_2_0154BA00 mov eax, dword ptr fs:[00000030h]
          Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.CrypterX-gen.16304.13478.exeCode function: 1_2_0154BA00 mov eax, dword ptr fs:[00000030h]
          Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.CrypterX-gen.16304.13478.exeCode function: 1_2_0154BA00 mov eax, dword ptr fs:[00000030h]
          Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.CrypterX-gen.16304.13478.exeCode function: 1_2_0154BA00 mov eax, dword ptr fs:[00000030h]
          Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.CrypterX-gen.16304.13478.exeCode function: 1_2_0154BA00 mov eax, dword ptr fs:[00000030h]
          Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.CrypterX-gen.16304.13478.exeCode function: 1_2_0154BA00 mov eax, dword ptr fs:[00000030h]
          Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.CrypterX-gen.16304.13478.exeCode function: 1_2_0154BA00 mov eax, dword ptr fs:[00000030h]
          Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.CrypterX-gen.16304.13478.exeCode function: 1_2_01548A0A mov eax, dword ptr fs:[00000030h]
          Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.CrypterX-gen.16304.13478.exeCode function: 1_2_0155B236 mov eax, dword ptr fs:[00000030h]
          Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.CrypterX-gen.16304.13478.exeCode function: 1_2_0155B236 mov eax, dword ptr fs:[00000030h]
          Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.CrypterX-gen.16304.13478.exeCode function: 1_2_0155B236 mov eax, dword ptr fs:[00000030h]
          Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.CrypterX-gen.16304.13478.exeCode function: 1_2_0155B236 mov eax, dword ptr fs:[00000030h]
          Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.CrypterX-gen.16304.13478.exeCode function: 1_2_0155B236 mov eax, dword ptr fs:[00000030h]
          Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.CrypterX-gen.16304.13478.exeCode function: 1_2_0155B236 mov eax, dword ptr fs:[00000030h]
          Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.CrypterX-gen.16304.13478.exeCode function: 1_2_01538239 mov eax, dword ptr fs:[00000030h]
          Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.CrypterX-gen.16304.13478.exeCode function: 1_2_01538239 mov eax, dword ptr fs:[00000030h]
          Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.CrypterX-gen.16304.13478.exeCode function: 1_2_01538239 mov eax, dword ptr fs:[00000030h]
          Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.CrypterX-gen.16304.13478.exeCode function: 1_2_01534A20 mov eax, dword ptr fs:[00000030h]
          Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.CrypterX-gen.16304.13478.exeCode function: 1_2_01534A20 mov eax, dword ptr fs:[00000030h]
          Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.CrypterX-gen.16304.13478.exeCode function: 1_2_015F1229 mov eax, dword ptr fs:[00000030h]
          Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.CrypterX-gen.16304.13478.exeCode function: 1_2_01574A2C mov eax, dword ptr fs:[00000030h]
          Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.CrypterX-gen.16304.13478.exeCode function: 1_2_01574A2C mov eax, dword ptr fs:[00000030h]
          Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.CrypterX-gen.16304.13478.exeCode function: 1_2_0155A229 mov eax, dword ptr fs:[00000030h]
          Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.CrypterX-gen.16304.13478.exeCode function: 1_2_0155A229 mov eax, dword ptr fs:[00000030h]
          Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.CrypterX-gen.16304.13478.exeCode function: 1_2_0155A229 mov eax, dword ptr fs:[00000030h]
          Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.CrypterX-gen.16304.13478.exeCode function: 1_2_0155A229 mov eax, dword ptr fs:[00000030h]
          Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.CrypterX-gen.16304.13478.exeCode function: 1_2_0155A229 mov eax, dword ptr fs:[00000030h]
          Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.CrypterX-gen.16304.13478.exeCode function: 1_2_0155A229 mov eax, dword ptr fs:[00000030h]
          Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.CrypterX-gen.16304.13478.exeCode function: 1_2_0155A229 mov eax, dword ptr fs:[00000030h]
          Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.CrypterX-gen.16304.13478.exeCode function: 1_2_0155A229 mov eax, dword ptr fs:[00000030h]
          Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.CrypterX-gen.16304.13478.exeCode function: 1_2_0155A229 mov eax, dword ptr fs:[00000030h]
          Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.CrypterX-gen.16304.13478.exeCode function: 1_2_015312D4 mov eax, dword ptr fs:[00000030h]
          Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.CrypterX-gen.16304.13478.exeCode function: 1_2_01535AC0 mov eax, dword ptr fs:[00000030h]
          Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.CrypterX-gen.16304.13478.exeCode function: 1_2_01535AC0 mov eax, dword ptr fs:[00000030h]
          Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.CrypterX-gen.16304.13478.exeCode function: 1_2_01535AC0 mov eax, dword ptr fs:[00000030h]
          Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.CrypterX-gen.16304.13478.exeCode function: 1_2_01533ACA mov eax, dword ptr fs:[00000030h]
          Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.CrypterX-gen.16304.13478.exeCode function: 1_2_01562ACB mov eax, dword ptr fs:[00000030h]
          Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.CrypterX-gen.16304.13478.exeCode function: 1_2_015F4AEF mov eax, dword ptr fs:[00000030h]
          Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.CrypterX-gen.16304.13478.exeCode function: 1_2_015F4AEF mov eax, dword ptr fs:[00000030h]
          Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.CrypterX-gen.16304.13478.exeCode function: 1_2_015F4AEF mov eax, dword ptr fs:[00000030h]
          Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.CrypterX-gen.16304.13478.exeCode function: 1_2_015F4AEF mov eax, dword ptr fs:[00000030h]
          Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.CrypterX-gen.16304.13478.exeCode function: 1_2_015F4AEF mov eax, dword ptr fs:[00000030h]
          Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.CrypterX-gen.16304.13478.exeCode function: 1_2_015F4AEF mov eax, dword ptr fs:[00000030h]
          Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.CrypterX-gen.16304.13478.exeCode function: 1_2_015F4AEF mov eax, dword ptr fs:[00000030h]
          Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.CrypterX-gen.16304.13478.exeCode function: 1_2_015F4AEF mov eax, dword ptr fs:[00000030h]
          Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.CrypterX-gen.16304.13478.exeCode function: 1_2_015F4AEF mov eax, dword ptr fs:[00000030h]
          Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.CrypterX-gen.16304.13478.exeCode function: 1_2_015F4AEF mov eax, dword ptr fs:[00000030h]
          Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.CrypterX-gen.16304.13478.exeCode function: 1_2_015F4AEF mov eax, dword ptr fs:[00000030h]
          Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.CrypterX-gen.16304.13478.exeCode function: 1_2_015F4AEF mov eax, dword ptr fs:[00000030h]
          Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.CrypterX-gen.16304.13478.exeCode function: 1_2_015F4AEF mov eax, dword ptr fs:[00000030h]
          Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.CrypterX-gen.16304.13478.exeCode function: 1_2_015F4AEF mov eax, dword ptr fs:[00000030h]
          Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.CrypterX-gen.16304.13478.exeCode function: 1_2_01562AE4 mov eax, dword ptr fs:[00000030h]
          Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.CrypterX-gen.16304.13478.exeCode function: 1_2_01608ADD mov eax, dword ptr fs:[00000030h]
          Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.CrypterX-gen.16304.13478.exeCode function: 1_2_0156D294 mov eax, dword ptr fs:[00000030h]
          Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.CrypterX-gen.16304.13478.exeCode function: 1_2_0156D294 mov eax, dword ptr fs:[00000030h]
          Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.CrypterX-gen.16304.13478.exeCode function: 1_2_015F129A mov eax, dword ptr fs:[00000030h]
          Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.CrypterX-gen.16304.13478.exeCode function: 1_2_0156DA88 mov eax, dword ptr fs:[00000030h]
          Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.CrypterX-gen.16304.13478.exeCode function: 1_2_0156DA88 mov eax, dword ptr fs:[00000030h]
          Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.CrypterX-gen.16304.13478.exeCode function: 1_2_0154AAB0 mov eax, dword ptr fs:[00000030h]
          Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.CrypterX-gen.16304.13478.exeCode function: 1_2_0154AAB0 mov eax, dword ptr fs:[00000030h]
          Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.CrypterX-gen.16304.13478.exeCode function: 1_2_0156FAB0 mov eax, dword ptr fs:[00000030h]
          Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.CrypterX-gen.16304.13478.exeCode function: 1_2_015612BD mov esi, dword ptr fs:[00000030h]
          Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.CrypterX-gen.16304.13478.exeCode function: 1_2_015612BD mov eax, dword ptr fs:[00000030h]
          Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.CrypterX-gen.16304.13478.exeCode function: 1_2_015612BD mov eax, dword ptr fs:[00000030h]
          Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.CrypterX-gen.16304.13478.exeCode function: 1_2_01531AA0 mov eax, dword ptr fs:[00000030h]
          Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.CrypterX-gen.16304.13478.exeCode function: 1_2_015462A0 mov eax, dword ptr fs:[00000030h]
          Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.CrypterX-gen.16304.13478.exeCode function: 1_2_015462A0 mov eax, dword ptr fs:[00000030h]
          Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.CrypterX-gen.16304.13478.exeCode function: 1_2_015462A0 mov eax, dword ptr fs:[00000030h]
          Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.CrypterX-gen.16304.13478.exeCode function: 1_2_015462A0 mov eax, dword ptr fs:[00000030h]
          Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.CrypterX-gen.16304.13478.exeCode function: 1_2_015352A5 mov eax, dword ptr fs:[00000030h]
          Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.CrypterX-gen.16304.13478.exeCode function: 1_2_015352A5 mov eax, dword ptr fs:[00000030h]
          Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.CrypterX-gen.16304.13478.exeCode function: 1_2_015352A5 mov eax, dword ptr fs:[00000030h]
          Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.CrypterX-gen.16304.13478.exeCode function: 1_2_015352A5 mov eax, dword ptr fs:[00000030h]
          Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.CrypterX-gen.16304.13478.exeCode function: 1_2_015352A5 mov eax, dword ptr fs:[00000030h]
          Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.CrypterX-gen.16304.13478.exeCode function: 1_2_01565AA0 mov eax, dword ptr fs:[00000030h]
          Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.CrypterX-gen.16304.13478.exeCode function: 1_2_01565AA0 mov eax, dword ptr fs:[00000030h]
          Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.CrypterX-gen.16304.13478.exeCode function: 1_2_01557D50 mov eax, dword ptr fs:[00000030h]
          Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.CrypterX-gen.16304.13478.exeCode function: 1_2_01574D51 mov eax, dword ptr fs:[00000030h]
          Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.CrypterX-gen.16304.13478.exeCode function: 1_2_01574D51 mov eax, dword ptr fs:[00000030h]
          Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.CrypterX-gen.16304.13478.exeCode function: 1_2_01573D43 mov eax, dword ptr fs:[00000030h]
          Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.CrypterX-gen.16304.13478.exeCode function: 1_2_015E8D47 mov eax, dword ptr fs:[00000030h]
          Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.CrypterX-gen.16304.13478.exeCode function: 1_2_015B3540 mov eax, dword ptr fs:[00000030h]
          Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.CrypterX-gen.16304.13478.exeCode function: 1_2_015E3D40 mov eax, dword ptr fs:[00000030h]
          Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.CrypterX-gen.16304.13478.exeCode function: 1_2_0153354C mov eax, dword ptr fs:[00000030h]
          Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.CrypterX-gen.16304.13478.exeCode function: 1_2_0153354C mov eax, dword ptr fs:[00000030h]
          Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.CrypterX-gen.16304.13478.exeCode function: 1_2_0155C577 mov eax, dword ptr fs:[00000030h]
          Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.CrypterX-gen.16304.13478.exeCode function: 1_2_0155C577 mov eax, dword ptr fs:[00000030h]
          Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.CrypterX-gen.16304.13478.exeCode function: 1_2_01558D76 mov eax, dword ptr fs:[00000030h]
          Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.CrypterX-gen.16304.13478.exeCode function: 1_2_01558D76 mov eax, dword ptr fs:[00000030h]
          Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.CrypterX-gen.16304.13478.exeCode function: 1_2_01558D76 mov eax, dword ptr fs:[00000030h]
          Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.CrypterX-gen.16304.13478.exeCode function: 1_2_01558D76 mov eax, dword ptr fs:[00000030h]
          Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.CrypterX-gen.16304.13478.exeCode function: 1_2_01558D76 mov eax, dword ptr fs:[00000030h]
          Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.CrypterX-gen.16304.13478.exeCode function: 1_2_015F3518 mov eax, dword ptr fs:[00000030h]
          Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.CrypterX-gen.16304.13478.exeCode function: 1_2_015F3518 mov eax, dword ptr fs:[00000030h]
          Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.CrypterX-gen.16304.13478.exeCode function: 1_2_015F3518 mov eax, dword ptr fs:[00000030h]
          Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.CrypterX-gen.16304.13478.exeCode function: 1_2_0153751A mov eax, dword ptr fs:[00000030h]
          Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.CrypterX-gen.16304.13478.exeCode function: 1_2_0153751A mov eax, dword ptr fs:[00000030h]
          Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.CrypterX-gen.16304.13478.exeCode function: 1_2_0153751A mov eax, dword ptr fs:[00000030h]
          Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.CrypterX-gen.16304.13478.exeCode function: 1_2_0153751A mov eax, dword ptr fs:[00000030h]
          Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.CrypterX-gen.16304.13478.exeCode function: 1_2_01608D34 mov eax, dword ptr fs:[00000030h]
          Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.CrypterX-gen.16304.13478.exeCode function: 1_2_015DCD04 mov eax, dword ptr fs:[00000030h]
          Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.CrypterX-gen.16304.13478.exeCode function: 1_2_01543D34 mov eax, dword ptr fs:[00000030h]
          Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.CrypterX-gen.16304.13478.exeCode function: 1_2_01543D34 mov eax, dword ptr fs:[00000030h]
          Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.CrypterX-gen.16304.13478.exeCode function: 1_2_01543D34 mov eax, dword ptr fs:[00000030h]
          Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.CrypterX-gen.16304.13478.exeCode function: 1_2_01543D34 mov eax, dword ptr fs:[00000030h]
          Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.CrypterX-gen.16304.13478.exeCode function: 1_2_01543D34 mov eax, dword ptr fs:[00000030h]
          Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.CrypterX-gen.16304.13478.exeCode function: 1_2_01543D34 mov eax, dword ptr fs:[00000030h]
          Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.CrypterX-gen.16304.13478.exeCode function: 1_2_01543D34 mov eax, dword ptr fs:[00000030h]
          Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.CrypterX-gen.16304.13478.exeCode function: 1_2_01543D34 mov eax, dword ptr fs:[00000030h]
          Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.CrypterX-gen.16304.13478.exeCode function: 1_2_01543D34 mov eax, dword ptr fs:[00000030h]
          Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.CrypterX-gen.16304.13478.exeCode function: 1_2_01543D34 mov eax, dword ptr fs:[00000030h]
          Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.CrypterX-gen.16304.13478.exeCode function: 1_2_01543D34 mov eax, dword ptr fs:[00000030h]
          Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.CrypterX-gen.16304.13478.exeCode function: 1_2_01543D34 mov eax, dword ptr fs:[00000030h]
          Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.CrypterX-gen.16304.13478.exeCode function: 1_2_01543D34 mov eax, dword ptr fs:[00000030h]
          Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.CrypterX-gen.16304.13478.exeCode function: 1_2_0153AD30 mov eax, dword ptr fs:[00000030h]
          Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.CrypterX-gen.16304.13478.exeCode function: 1_2_015FE539 mov eax, dword ptr fs:[00000030h]
          Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.CrypterX-gen.16304.13478.exeCode function: 1_2_015BA537 mov eax, dword ptr fs:[00000030h]
          Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.CrypterX-gen.16304.13478.exeCode function: 1_2_01564D3B mov eax, dword ptr fs:[00000030h]
          Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.CrypterX-gen.16304.13478.exeCode function: 1_2_01564D3B mov eax, dword ptr fs:[00000030h]
          Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.CrypterX-gen.16304.13478.exeCode function: 1_2_01564D3B mov eax, dword ptr fs:[00000030h]
          Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.CrypterX-gen.16304.13478.exeCode function: 1_2_0156F527 mov eax, dword ptr fs:[00000030h]
          Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.CrypterX-gen.16304.13478.exeCode function: 1_2_0156F527 mov eax, dword ptr fs:[00000030h]
          Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.CrypterX-gen.16304.13478.exeCode function: 1_2_0156F527 mov eax, dword ptr fs:[00000030h]
          Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.CrypterX-gen.16304.13478.exeCode function: 1_2_015EFDD3 mov eax, dword ptr fs:[00000030h]
          Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.CrypterX-gen.16304.13478.exeCode function: 1_2_015B6DC9 mov eax, dword ptr fs:[00000030h]
          Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.CrypterX-gen.16304.13478.exeCode function: 1_2_015B6DC9 mov eax, dword ptr fs:[00000030h]
          Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.CrypterX-gen.16304.13478.exeCode function: 1_2_015B6DC9 mov eax, dword ptr fs:[00000030h]
          Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.CrypterX-gen.16304.13478.exeCode function: 1_2_015B6DC9 mov ecx, dword ptr fs:[00000030h]
          Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.CrypterX-gen.16304.13478.exeCode function: 1_2_015B6DC9 mov eax, dword ptr fs:[00000030h]
          Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.CrypterX-gen.16304.13478.exeCode function: 1_2_015B6DC9 mov eax, dword ptr fs:[00000030h]
          Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.CrypterX-gen.16304.13478.exeCode function: 1_2_015315C1 mov eax, dword ptr fs:[00000030h]
          Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.CrypterX-gen.16304.13478.exeCode function: 1_2_015395F0 mov eax, dword ptr fs:[00000030h]
          Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.CrypterX-gen.16304.13478.exeCode function: 1_2_015395F0 mov ecx, dword ptr fs:[00000030h]
          Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.CrypterX-gen.16304.13478.exeCode function: 1_2_015E8DF1 mov eax, dword ptr fs:[00000030h]
          Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.CrypterX-gen.16304.13478.exeCode function: 1_2_0154D5E0 mov eax, dword ptr fs:[00000030h]
          Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.CrypterX-gen.16304.13478.exeCode function: 1_2_0154D5E0 mov eax, dword ptr fs:[00000030h]
          Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.CrypterX-gen.16304.13478.exeCode function: 1_2_015695EC mov eax, dword ptr fs:[00000030h]
          Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.CrypterX-gen.16304.13478.exeCode function: 1_2_015FFDE2 mov eax, dword ptr fs:[00000030h]
          Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.CrypterX-gen.16304.13478.exeCode function: 1_2_015FFDE2 mov eax, dword ptr fs:[00000030h]
          Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.CrypterX-gen.16304.13478.exeCode function: 1_2_015FFDE2 mov eax, dword ptr fs:[00000030h]
          Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.CrypterX-gen.16304.13478.exeCode function: 1_2_015FFDE2 mov eax, dword ptr fs:[00000030h]
          Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.CrypterX-gen.16304.13478.exeCode function: 1_2_01533591 mov eax, dword ptr fs:[00000030h]
          Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.CrypterX-gen.16304.13478.exeCode function: 1_2_016005AC mov eax, dword ptr fs:[00000030h]
          Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.CrypterX-gen.16304.13478.exeCode function: 1_2_016005AC mov eax, dword ptr fs:[00000030h]
          Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.CrypterX-gen.16304.13478.exeCode function: 1_2_0156FD9B mov eax, dword ptr fs:[00000030h]
          Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.CrypterX-gen.16304.13478.exeCode function: 1_2_0156FD9B mov eax, dword ptr fs:[00000030h]
          Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.CrypterX-gen.16304.13478.exeCode function: 1_2_01562581 mov eax, dword ptr fs:[00000030h]
          Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.CrypterX-gen.16304.13478.exeCode function: 1_2_01562581 mov eax, dword ptr fs:[00000030h]
          Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.CrypterX-gen.16304.13478.exeCode function: 1_2_01562581 mov eax, dword ptr fs:[00000030h]
          Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.CrypterX-gen.16304.13478.exeCode function: 1_2_01562581 mov eax, dword ptr fs:[00000030h]
          Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.CrypterX-gen.16304.13478.exeCode function: 1_2_01532D8A mov eax, dword ptr fs:[00000030h]
          Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.CrypterX-gen.16304.13478.exeCode function: 1_2_01532D8A mov eax, dword ptr fs:[00000030h]
          Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.CrypterX-gen.16304.13478.exeCode function: 1_2_01532D8A mov eax, dword ptr fs:[00000030h]
          Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.CrypterX-gen.16304.13478.exeCode function: 1_2_01532D8A mov eax, dword ptr fs:[00000030h]
          Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.CrypterX-gen.16304.13478.exeCode function: 1_2_01532D8A mov eax, dword ptr fs:[00000030h]
          Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.CrypterX-gen.16304.13478.exeCode function: 1_2_015F2D82 mov eax, dword ptr fs:[00000030h]
          Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.CrypterX-gen.16304.13478.exeCode function: 1_2_015F2D82 mov eax, dword ptr fs:[00000030h]
          Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.CrypterX-gen.16304.13478.exeCode function: 1_2_015F2D82 mov eax, dword ptr fs:[00000030h]
          Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.CrypterX-gen.16304.13478.exeCode function: 1_2_015F2D82 mov eax, dword ptr fs:[00000030h]
          Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.CrypterX-gen.16304.13478.exeCode function: 1_2_015F2D82 mov eax, dword ptr fs:[00000030h]
          Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.CrypterX-gen.16304.13478.exeCode function: 1_2_015F2D82 mov eax, dword ptr fs:[00000030h]
          Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.CrypterX-gen.16304.13478.exeCode function: 1_2_015F2D82 mov eax, dword ptr fs:[00000030h]
          Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.CrypterX-gen.16304.13478.exeCode function: 1_2_015FB581 mov eax, dword ptr fs:[00000030h]
          Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.CrypterX-gen.16304.13478.exeCode function: 1_2_015FB581 mov eax, dword ptr fs:[00000030h]
          Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.CrypterX-gen.16304.13478.exeCode function: 1_2_015FB581 mov eax, dword ptr fs:[00000030h]
          Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.CrypterX-gen.16304.13478.exeCode function: 1_2_015FB581 mov eax, dword ptr fs:[00000030h]
          Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.CrypterX-gen.16304.13478.exeCode function: 1_2_01561DB5 mov eax, dword ptr fs:[00000030h]
          Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.CrypterX-gen.16304.13478.exeCode function: 1_2_01561DB5 mov eax, dword ptr fs:[00000030h]
          Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.CrypterX-gen.16304.13478.exeCode function: 1_2_01561DB5 mov eax, dword ptr fs:[00000030h]
          Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.CrypterX-gen.16304.13478.exeCode function: 1_2_015665A0 mov eax, dword ptr fs:[00000030h]
          Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.CrypterX-gen.16304.13478.exeCode function: 1_2_015665A0 mov eax, dword ptr fs:[00000030h]
          Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.CrypterX-gen.16304.13478.exeCode function: 1_2_015665A0 mov eax, dword ptr fs:[00000030h]
          Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.CrypterX-gen.16304.13478.exeCode function: 1_2_015635A1 mov eax, dword ptr fs:[00000030h]
          Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.CrypterX-gen.16304.13478.exeCode function: 1_2_015CC450 mov eax, dword ptr fs:[00000030h]
          Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.CrypterX-gen.16304.13478.exeCode function: 1_2_015CC450 mov eax, dword ptr fs:[00000030h]
          Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.CrypterX-gen.16304.13478.exeCode function: 1_2_01608C75 mov eax, dword ptr fs:[00000030h]
          Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.CrypterX-gen.16304.13478.exeCode function: 1_2_0156A44B mov eax, dword ptr fs:[00000030h]
          Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.CrypterX-gen.16304.13478.exeCode function: 1_2_0155B477 mov eax, dword ptr fs:[00000030h]
          Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.CrypterX-gen.16304.13478.exeCode function: 1_2_0155B477 mov eax, dword ptr fs:[00000030h]
          Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.CrypterX-gen.16304.13478.exeCode function: 1_2_0155B477 mov eax, dword ptr fs:[00000030h]
          Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.CrypterX-gen.16304.13478.exeCode function: 1_2_0155B477 mov eax, dword ptr fs:[00000030h]
          Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.CrypterX-gen.16304.13478.exeCode function: 1_2_0155B477 mov eax, dword ptr fs:[00000030h]
          Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.CrypterX-gen.16304.13478.exeCode function: 1_2_0155B477 mov eax, dword ptr fs:[00000030h]
          Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.CrypterX-gen.16304.13478.exeCode function: 1_2_0155B477 mov eax, dword ptr fs:[00000030h]
          Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.CrypterX-gen.16304.13478.exeCode function: 1_2_0155B477 mov eax, dword ptr fs:[00000030h]
          Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.CrypterX-gen.16304.13478.exeCode function: 1_2_0155B477 mov eax, dword ptr fs:[00000030h]
          Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.CrypterX-gen.16304.13478.exeCode function: 1_2_0155B477 mov eax, dword ptr fs:[00000030h]
          Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.CrypterX-gen.16304.13478.exeCode function: 1_2_0155B477 mov eax, dword ptr fs:[00000030h]
          Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.CrypterX-gen.16304.13478.exeCode function: 1_2_0155B477 mov eax, dword ptr fs:[00000030h]
          Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.CrypterX-gen.16304.13478.exeCode function: 1_2_01575C70 mov eax, dword ptr fs:[00000030h]
          Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.CrypterX-gen.16304.13478.exeCode function: 1_2_0156AC7B mov eax, dword ptr fs:[00000030h]
          Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.CrypterX-gen.16304.13478.exeCode function: 1_2_0156AC7B mov eax, dword ptr fs:[00000030h]
          Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.CrypterX-gen.16304.13478.exeCode function: 1_2_0156AC7B mov eax, dword ptr fs:[00000030h]
          Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.CrypterX-gen.16304.13478.exeCode function: 1_2_0156AC7B mov eax, dword ptr fs:[00000030h]
          Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.CrypterX-gen.16304.13478.exeCode function: 1_2_0156AC7B mov eax, dword ptr fs:[00000030h]
          Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.CrypterX-gen.16304.13478.exeCode function: 1_2_0156AC7B mov eax, dword ptr fs:[00000030h]
          Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.CrypterX-gen.16304.13478.exeCode function: 1_2_0156AC7B mov eax, dword ptr fs:[00000030h]
          Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.CrypterX-gen.16304.13478.exeCode function: 1_2_0156AC7B mov eax, dword ptr fs:[00000030h]
          Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.CrypterX-gen.16304.13478.exeCode function: 1_2_0156AC7B mov eax, dword ptr fs:[00000030h]
          Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.CrypterX-gen.16304.13478.exeCode function: 1_2_0156AC7B mov eax, dword ptr fs:[00000030h]
          Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.CrypterX-gen.16304.13478.exeCode function: 1_2_0156AC7B mov eax, dword ptr fs:[00000030h]
          Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.CrypterX-gen.16304.13478.exeCode function: 1_2_01608450 mov eax, dword ptr fs:[00000030h]
          Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.CrypterX-gen.16304.13478.exeCode function: 1_2_0155746D mov eax, dword ptr fs:[00000030h]
          Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.CrypterX-gen.16304.13478.exeCode function: 1_2_015B6C0A mov eax, dword ptr fs:[00000030h]
          Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.CrypterX-gen.16304.13478.exeCode function: 1_2_015B6C0A mov eax, dword ptr fs:[00000030h]
          Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.CrypterX-gen.16304.13478.exeCode function: 1_2_015B6C0A mov eax, dword ptr fs:[00000030h]
          Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.CrypterX-gen.16304.13478.exeCode function: 1_2_015B6C0A mov eax, dword ptr fs:[00000030h]
          Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.CrypterX-gen.16304.13478.exeCode function: 1_2_015F1C06 mov eax, dword ptr fs:[00000030h]
          Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.CrypterX-gen.16304.13478.exeCode function: 1_2_015F1C06 mov eax, dword ptr fs:[00000030h]
          Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.CrypterX-gen.16304.13478.exeCode function: 1_2_015F1C06 mov eax, dword ptr fs:[00000030h]
          Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.CrypterX-gen.16304.13478.exeCode function: 1_2_015F1C06 mov eax, dword ptr fs:[00000030h]
          Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.CrypterX-gen.16304.13478.exeCode function: 1_2_015F1C06 mov eax, dword ptr fs:[00000030h]
          Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.CrypterX-gen.16304.13478.exeCode function: 1_2_015F1C06 mov eax, dword ptr fs:[00000030h]
          Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.CrypterX-gen.16304.13478.exeCode function: 1_2_015F1C06 mov eax, dword ptr fs:[00000030h]
          Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.CrypterX-gen.16304.13478.exeCode function: 1_2_015F1C06 mov eax, dword ptr fs:[00000030h]
          Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.CrypterX-gen.16304.13478.exeCode function: 1_2_015F1C06 mov eax, dword ptr fs:[00000030h]
          Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.CrypterX-gen.16304.13478.exeCode function: 1_2_015F1C06 mov eax, dword ptr fs:[00000030h]
          Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.CrypterX-gen.16304.13478.exeCode function: 1_2_015F1C06 mov eax, dword ptr fs:[00000030h]
          Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.CrypterX-gen.16304.13478.exeCode function: 1_2_015F1C06 mov eax, dword ptr fs:[00000030h]
          Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.CrypterX-gen.16304.13478.exeCode function: 1_2_015F1C06 mov eax, dword ptr fs:[00000030h]
          Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.CrypterX-gen.16304.13478.exeCode function: 1_2_015F1C06 mov eax, dword ptr fs:[00000030h]
          Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.CrypterX-gen.16304.13478.exeCode function: 1_2_01552430 mov eax, dword ptr fs:[00000030h]
          Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.CrypterX-gen.16304.13478.exeProcess queried: DebugPort
          Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.CrypterX-gen.16304.13478.exeCode function: 1_2_01579860 NtQuerySystemInformation,LdrInitializeThunk,
          Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.CrypterX-gen.16304.13478.exeMemory allocated: page read and write | page guard

          HIPS / PFW / Operating System Protection Evasion

          barindex
          Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.CrypterX-gen.16304.13478.exeMemory written: C:\Users\user\Desktop\SecuriteInfo.com.Win32.CrypterX-gen.16304.13478.exe base: 400000 value starts with: 4D5A
          Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.CrypterX-gen.16304.13478.exeProcess created: C:\Users\user\Desktop\SecuriteInfo.com.Win32.CrypterX-gen.16304.13478.exe C:\Users\user\Desktop\SecuriteInfo.com.Win32.CrypterX-gen.16304.13478.exe
          Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.CrypterX-gen.16304.13478.exeQueries volume information: C:\Users\user\Desktop\SecuriteInfo.com.Win32.CrypterX-gen.16304.13478.exe VolumeInformation
          Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.CrypterX-gen.16304.13478.exeQueries volume information: C:\Windows\Microsoft.NET\assembly\GAC_MSIL\System.Windows.Forms\v4.0_4.0.0.0__b77a5c561934e089\System.Windows.Forms.dll VolumeInformation
          Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.CrypterX-gen.16304.13478.exeQueries volume information: C:\Windows\Microsoft.NET\assembly\GAC_MSIL\System.Drawing\v4.0_4.0.0.0__b03f5f7f11d50a3a\System.Drawing.dll VolumeInformation
          Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.CrypterX-gen.16304.13478.exeQueries volume information: C:\Windows\Microsoft.NET\assembly\GAC_MSIL\Accessibility\v4.0_4.0.0.0__b03f5f7f11d50a3a\Accessibility.dll VolumeInformation
          Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.CrypterX-gen.16304.13478.exeQueries volume information: C:\Windows\Fonts\arial.ttf VolumeInformation
          Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.CrypterX-gen.16304.13478.exeQueries volume information: C:\Windows\Fonts\ariali.ttf VolumeInformation
          Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.CrypterX-gen.16304.13478.exeQueries volume information: C:\Windows\Fonts\arialbd.ttf VolumeInformation
          Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.CrypterX-gen.16304.13478.exeQueries volume information: C:\Windows\Fonts\arialbi.ttf VolumeInformation
          Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.CrypterX-gen.16304.13478.exeQueries volume information: C:\Windows\Fonts\ARIALN.TTF VolumeInformation
          Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.CrypterX-gen.16304.13478.exeQueries volume information: C:\Windows\Fonts\ariblk.ttf VolumeInformation
          Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.CrypterX-gen.16304.13478.exeQueries volume information: C:\Windows\Fonts\ARIALNI.TTF VolumeInformation
          Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.CrypterX-gen.16304.13478.exeQueries volume information: C:\Windows\Fonts\ARIALNB.TTF VolumeInformation
          Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.CrypterX-gen.16304.13478.exeQueries volume information: C:\Windows\Fonts\ARIALNBI.TTF VolumeInformation
          Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.CrypterX-gen.16304.13478.exeQueries volume information: C:\Windows\Fonts\bahnschrift.ttf VolumeInformation
          Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.CrypterX-gen.16304.13478.exeQueries volume information: C:\Windows\Fonts\calibri.ttf VolumeInformation
          Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.CrypterX-gen.16304.13478.exeQueries volume information: C:\Windows\Fonts\calibril.ttf VolumeInformation
          Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.CrypterX-gen.16304.13478.exeQueries volume information: C:\Windows\Fonts\calibrii.ttf VolumeInformation
          Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.CrypterX-gen.16304.13478.exeQueries volume information: C:\Windows\Fonts\calibrili.ttf VolumeInformation
          Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.CrypterX-gen.16304.13478.exeQueries volume information: C:\Windows\Fonts\calibrib.ttf VolumeInformation
          Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.CrypterX-gen.16304.13478.exeQueries volume information: C:\Windows\Fonts\calibriz.ttf VolumeInformation
          Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.CrypterX-gen.16304.13478.exeQueries volume information: C:\Windows\Fonts\cambria.ttc VolumeInformation
          Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.CrypterX-gen.16304.13478.exeQueries volume information: C:\Windows\Fonts\cambriai.ttf VolumeInformation
          Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.CrypterX-gen.16304.13478.exeQueries volume information: C:\Windows\Fonts\cambriab.ttf VolumeInformation
          Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.CrypterX-gen.16304.13478.exeQueries volume information: C:\Windows\Fonts\cambriaz.ttf VolumeInformation
          Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.CrypterX-gen.16304.13478.exeQueries volume information: C:\Windows\Fonts\Candara.ttf VolumeInformation
          Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.CrypterX-gen.16304.13478.exeQueries volume information: C:\Windows\Fonts\Candarai.ttf VolumeInformation
          Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.CrypterX-gen.16304.13478.exeQueries volume information: C:\Windows\Fonts\Candarab.ttf VolumeInformation
          Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.CrypterX-gen.16304.13478.exeQueries volume information: C:\Windows\Fonts\Candaraz.ttf VolumeInformation
          Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.CrypterX-gen.16304.13478.exeQueries volume information: C:\Windows\Fonts\comic.ttf VolumeInformation
          Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.CrypterX-gen.16304.13478.exeQueries volume information: C:\Windows\Fonts\comici.ttf VolumeInformation
          Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.CrypterX-gen.16304.13478.exeQueries volume information: C:\Windows\Fonts\comicbd.ttf VolumeInformation
          Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.CrypterX-gen.16304.13478.exeQueries volume information: C:\Windows\Fonts\comicz.ttf VolumeInformation
          Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.CrypterX-gen.16304.13478.exeQueries volume information: C:\Windows\Fonts\consola.ttf VolumeInformation
          Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.CrypterX-gen.16304.13478.exeQueries volume information: C:\Windows\Fonts\consolai.ttf VolumeInformation
          Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.CrypterX-gen.16304.13478.exeQueries volume information: C:\Windows\Fonts\consolab.ttf VolumeInformation
          Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.CrypterX-gen.16304.13478.exeQueries volume information: C:\Windows\Fonts\consolaz.ttf VolumeInformation
          Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.CrypterX-gen.16304.13478.exeQueries volume information: C:\Windows\Fonts\constan.ttf VolumeInformation
          Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.CrypterX-gen.16304.13478.exeQueries volume information: C:\Windows\Fonts\constani.ttf VolumeInformation
          Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.CrypterX-gen.16304.13478.exeQueries volume information: C:\Windows\Fonts\constanb.ttf VolumeInformation
          Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.CrypterX-gen.16304.13478.exeQueries volume information: C:\Windows\Fonts\constanz.ttf VolumeInformation
          Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.CrypterX-gen.16304.13478.exeQueries volume information: C:\Windows\Fonts\corbel.ttf VolumeInformation
          Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.CrypterX-gen.16304.13478.exeQueries volume information: C:\Windows\Fonts\corbeli.ttf VolumeInformation
          Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.CrypterX-gen.16304.13478.exeQueries volume information: C:\Windows\Fonts\corbelb.ttf VolumeInformation
          Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.CrypterX-gen.16304.13478.exeQueries volume information: C:\Windows\Fonts\corbelz.ttf VolumeInformation
          Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.CrypterX-gen.16304.13478.exeQueries volume information: C:\Windows\Fonts\cour.ttf VolumeInformation
          Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.CrypterX-gen.16304.13478.exeQueries volume information: C:\Windows\Fonts\couri.ttf VolumeInformation
          Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.CrypterX-gen.16304.13478.exeQueries volume information: C:\Windows\Fonts\courbd.ttf VolumeInformation
          Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.CrypterX-gen.16304.13478.exeQueries volume information: C:\Windows\Fonts\courbi.ttf VolumeInformation
          Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.CrypterX-gen.16304.13478.exeQueries volume information: C:\Windows\Fonts\ebrima.ttf VolumeInformation
          Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.CrypterX-gen.16304.13478.exeQueries volume information: C:\Windows\Fonts\ebrimabd.ttf VolumeInformation
          Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.CrypterX-gen.16304.13478.exeQueries volume information: C:\Windows\Fonts\framd.ttf VolumeInformation
          Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.CrypterX-gen.16304.13478.exeQueries volume information: C:\Windows\Fonts\FRADM.TTF VolumeInformation
          Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.CrypterX-gen.16304.13478.exeQueries volume information: C:\Windows\Fonts\framdit.ttf VolumeInformation
          Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.CrypterX-gen.16304.13478.exeQueries volume information: C:\Windows\Fonts\FRADMIT.TTF VolumeInformation
          Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.CrypterX-gen.16304.13478.exeQueries volume information: C:\Windows\Fonts\FRAMDCN.TTF VolumeInformation
          Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.CrypterX-gen.16304.13478.exeQueries volume information: C:\Windows\Fonts\FRADMCN.TTF VolumeInformation
          Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.CrypterX-gen.16304.13478.exeQueries volume information: C:\Windows\Fonts\FRAHV.TTF VolumeInformation
          Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.CrypterX-gen.16304.13478.exeQueries volume information: C:\Windows\Fonts\FRAHVIT.TTF VolumeInformation
          Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.CrypterX-gen.16304.13478.exeQueries volume information: C:\Windows\Fonts\Gabriola.ttf VolumeInformation
          Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.CrypterX-gen.16304.13478.exeQueries volume information: C:\Windows\Fonts\gadugi.ttf VolumeInformation
          Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.CrypterX-gen.16304.13478.exeQueries volume information: C:\Windows\Fonts\gadugib.ttf VolumeInformation
          Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.CrypterX-gen.16304.13478.exeQueries volume information: C:\Windows\Fonts\georgia.ttf VolumeInformation
          Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.CrypterX-gen.16304.13478.exeQueries volume information: C:\Windows\Fonts\georgiai.ttf VolumeInformation
          Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.CrypterX-gen.16304.13478.exeQueries volume information: C:\Windows\Fonts\georgiab.ttf VolumeInformation
          Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.CrypterX-gen.16304.13478.exeQueries volume information: C:\Windows\Fonts\georgiaz.ttf VolumeInformation
          Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.CrypterX-gen.16304.13478.exeQueries volume information: C:\Windows\Fonts\impact.ttf VolumeInformation
          Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.CrypterX-gen.16304.13478.exeQueries volume information: C:\Windows\Fonts\Inkfree.ttf VolumeInformation
          Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.CrypterX-gen.16304.13478.exeQueries volume information: C:\Windows\Fonts\javatext.ttf VolumeInformation
          Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.CrypterX-gen.16304.13478.exeQueries volume information: C:\Windows\Fonts\LeelawUI.ttf VolumeInformation
          Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.CrypterX-gen.16304.13478.exeQueries volume information: C:\Windows\Fonts\LeelUIsl.ttf VolumeInformation
          Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.CrypterX-gen.16304.13478.exeQueries volume information: C:\Windows\Fonts\LeelaUIb.ttf VolumeInformation
          Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.CrypterX-gen.16304.13478.exeQueries volume information: C:\Windows\Fonts\lucon.ttf VolumeInformation
          Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.CrypterX-gen.16304.13478.exeQueries volume information: C:\Windows\Fonts\l_10646.ttf VolumeInformation
          Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.CrypterX-gen.16304.13478.exeQueries volume information: C:\Windows\Fonts\malgun.ttf VolumeInformation
          Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.CrypterX-gen.16304.13478.exeQueries volume information: C:\Windows\Fonts\malgunsl.ttf VolumeInformation
          Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.CrypterX-gen.16304.13478.exeQueries volume information: C:\Windows\Fonts\malgunbd.ttf VolumeInformation
          Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.CrypterX-gen.16304.13478.exeQueries volume information: C:\Windows\Fonts\himalaya.ttf VolumeInformation
          Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.CrypterX-gen.16304.13478.exeQueries volume information: C:\Windows\Fonts\msjh.ttc VolumeInformation
          Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.CrypterX-gen.16304.13478.exeQueries volume information: C:\Windows\Fonts\msjhl.ttc VolumeInformation
          Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.CrypterX-gen.16304.13478.exeQueries volume information: C:\Windows\Fonts\msjhbd.ttc VolumeInformation
          Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.CrypterX-gen.16304.13478.exeQueries volume information: C:\Windows\Fonts\ntailu.ttf VolumeInformation
          Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.CrypterX-gen.16304.13478.exeQueries volume information: C:\Windows\Fonts\ntailub.ttf VolumeInformation
          Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.CrypterX-gen.16304.13478.exeQueries volume information: C:\Windows\Fonts\phagspa.ttf VolumeInformation
          Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.CrypterX-gen.16304.13478.exeQueries volume information: C:\Windows\Fonts\phagspab.ttf VolumeInformation
          Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.CrypterX-gen.16304.13478.exeQueries volume information: C:\Windows\Fonts\micross.ttf VolumeInformation
          Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.CrypterX-gen.16304.13478.exeQueries volume information: C:\Windows\Fonts\taile.ttf VolumeInformation
          Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.CrypterX-gen.16304.13478.exeQueries volume information: C:\Windows\Fonts\taileb.ttf VolumeInformation
          Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.CrypterX-gen.16304.13478.exeQueries volume information: C:\Windows\Fonts\msyh.ttc VolumeInformation
          Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.CrypterX-gen.16304.13478.exeQueries volume information: C:\Windows\Fonts\msyhl.ttc VolumeInformation
          Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.CrypterX-gen.16304.13478.exeQueries volume information: C:\Windows\Fonts\msyhbd.ttc VolumeInformation
          Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.CrypterX-gen.16304.13478.exeQueries volume information: C:\Windows\Fonts\msyi.ttf VolumeInformation
          Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.CrypterX-gen.16304.13478.exeQueries volume information: C:\Windows\Fonts\mingliub.ttc VolumeInformation
          Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.CrypterX-gen.16304.13478.exeQueries volume information: C:\Windows\Fonts\monbaiti.ttf VolumeInformation
          Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.CrypterX-gen.16304.13478.exeQueries volume information: C:\Windows\Fonts\msgothic.ttc VolumeInformation
          Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.CrypterX-gen.16304.13478.exeQueries volume information: C:\Windows\Fonts\mvboli.ttf VolumeInformation
          Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.CrypterX-gen.16304.13478.exeQueries volume information: C:\Windows\Fonts\mmrtext.ttf VolumeInformation
          Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.CrypterX-gen.16304.13478.exeQueries volume information: C:\Windows\Fonts\mmrtextb.ttf VolumeInformation
          Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.CrypterX-gen.16304.13478.exeQueries volume information: C:\Windows\Fonts\Nirmala.ttf VolumeInformation
          Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.CrypterX-gen.16304.13478.exeQueries volume information: C:\Windows\Fonts\NirmalaS.ttf VolumeInformation
          Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.CrypterX-gen.16304.13478.exeQueries volume information: C:\Windows\Fonts\NirmalaB.ttf VolumeInformation
          Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.CrypterX-gen.16304.13478.exeQueries volume information: C:\Windows\Fonts\pala.ttf VolumeInformation
          Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.CrypterX-gen.16304.13478.exeQueries volume information: C:\Windows\Fonts\palai.ttf VolumeInformation
          Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.CrypterX-gen.16304.13478.exeQueries volume information: C:\Windows\Fonts\palab.ttf VolumeInformation
          Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.CrypterX-gen.16304.13478.exeQueries volume information: C:\Windows\Fonts\palabi.ttf VolumeInformation
          Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.CrypterX-gen.16304.13478.exeQueries volume information: C:\Windows\Fonts\segoepr.ttf VolumeInformation
          Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.CrypterX-gen.16304.13478.exeQueries volume information: C:\Windows\Fonts\segoeprb.ttf VolumeInformation
          Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.CrypterX-gen.16304.13478.exeQueries volume information: C:\Windows\Fonts\segoesc.ttf VolumeInformation
          Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.CrypterX-gen.16304.13478.exeQueries volume information: C:\Windows\Fonts\segoescb.ttf VolumeInformation
          Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.CrypterX-gen.16304.13478.exeQueries volume information: C:\Windows\Fonts\segoeuii.ttf VolumeInformation
          Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.CrypterX-gen.16304.13478.exeQueries volume information: C:\Windows\Fonts\seguisli.ttf VolumeInformation
          Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.CrypterX-gen.16304.13478.exeQueries volume information: C:\Windows\Fonts\seguili.ttf VolumeInformation
          Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.CrypterX-gen.16304.13478.exeQueries volume information: C:\Windows\Fonts\seguisbi.ttf VolumeInformation
          Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.CrypterX-gen.16304.13478.exeQueries volume information: C:\Windows\Fonts\segoeuiz.ttf VolumeInformation
          Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.CrypterX-gen.16304.13478.exeQueries volume information: C:\Windows\Fonts\seguibl.ttf VolumeInformation
          Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.CrypterX-gen.16304.13478.exeQueries volume information: C:\Windows\Fonts\seguibli.ttf VolumeInformation
          Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.CrypterX-gen.16304.13478.exeQueries volume information: C:\Windows\Fonts\seguiemj.ttf VolumeInformation
          Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.CrypterX-gen.16304.13478.exeQueries volume information: C:\Windows\Fonts\seguihis.ttf VolumeInformation
          Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.CrypterX-gen.16304.13478.exeQueries volume information: C:\Windows\Fonts\seguisym.ttf VolumeInformation
          Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.CrypterX-gen.16304.13478.exeQueries volume information: C:\Windows\Fonts\simsun.ttc VolumeInformation
          Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.CrypterX-gen.16304.13478.exeQueries volume information: C:\Windows\Fonts\simsunb.ttf VolumeInformation
          Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.CrypterX-gen.16304.13478.exeQueries volume information: C:\Windows\Fonts\Sitka.ttc VolumeInformation
          Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.CrypterX-gen.16304.13478.exeQueries volume information: C:\Windows\Fonts\SitkaI.ttc VolumeInformation
          Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.CrypterX-gen.16304.13478.exeQueries volume information: C:\Windows\Fonts\SitkaB.ttc VolumeInformation
          Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.CrypterX-gen.16304.13478.exeQueries volume information: C:\Windows\Fonts\SitkaZ.ttc VolumeInformation
          Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.CrypterX-gen.16304.13478.exeQueries volume information: C:\Windows\Fonts\sylfaen.ttf VolumeInformation
          Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.CrypterX-gen.16304.13478.exeQueries volume information: C:\Windows\Fonts\symbol.ttf VolumeInformation
          Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.CrypterX-gen.16304.13478.exeQueries volume information: C:\Windows\Fonts\tahoma.ttf VolumeInformation
          Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.CrypterX-gen.16304.13478.exeQueries volume information: C:\Windows\Fonts\tahomabd.ttf VolumeInformation
          Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.CrypterX-gen.16304.13478.exeQueries volume information: C:\Windows\Fonts\timesi.ttf VolumeInformation
          Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.CrypterX-gen.16304.13478.exeQueries volume information: C:\Windows\Fonts\timesbd.ttf VolumeInformation
          Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.CrypterX-gen.16304.13478.exeQueries volume information: C:\Windows\Fonts\timesbi.ttf VolumeInformation
          Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.CrypterX-gen.16304.13478.exeQueries volume information: C:\Windows\Fonts\trebuc.ttf VolumeInformation
          Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.CrypterX-gen.16304.13478.exeQueries volume information: C:\Windows\Fonts\trebucit.ttf VolumeInformation
          Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.CrypterX-gen.16304.13478.exeQueries volume information: C:\Windows\Fonts\trebucbd.ttf VolumeInformation
          Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.CrypterX-gen.16304.13478.exeQueries volume information: C:\Windows\Fonts\trebucbi.ttf VolumeInformation
          Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.CrypterX-gen.16304.13478.exeQueries volume information: C:\Windows\Fonts\verdana.ttf VolumeInformation
          Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.CrypterX-gen.16304.13478.exeQueries volume information: C:\Windows\Fonts\verdanai.ttf VolumeInformation
          Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.CrypterX-gen.16304.13478.exeQueries volume information: C:\Windows\Fonts\verdanab.ttf VolumeInformation
          Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.CrypterX-gen.16304.13478.exeQueries volume information: C:\Windows\Fonts\verdanaz.ttf VolumeInformation
          Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.CrypterX-gen.16304.13478.exeQueries volume information: C:\Windows\Fonts\webdings.ttf VolumeInformation
          Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.CrypterX-gen.16304.13478.exeQueries volume information: C:\Windows\Fonts\wingding.ttf VolumeInformation
          Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.CrypterX-gen.16304.13478.exeQueries volume information: C:\Windows\Fonts\YuGothR.ttc VolumeInformation
          Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.CrypterX-gen.16304.13478.exeQueries volume information: C:\Windows\Fonts\YuGothM.ttc VolumeInformation
          Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.CrypterX-gen.16304.13478.exeQueries volume information: C:\Windows\Fonts\YuGothL.ttc VolumeInformation
          Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.CrypterX-gen.16304.13478.exeQueries volume information: C:\Windows\Fonts\YuGothB.ttc VolumeInformation
          Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.CrypterX-gen.16304.13478.exeQueries volume information: C:\Windows\Fonts\holomdl2.ttf VolumeInformation
          Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.CrypterX-gen.16304.13478.exeQueries volume information: C:\Windows\Fonts\CENTURY.TTF VolumeInformation
          Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.CrypterX-gen.16304.13478.exeQueries volume information: C:\Windows\Fonts\LEELAWAD.TTF VolumeInformation
          Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.CrypterX-gen.16304.13478.exeQueries volume information: C:\Windows\Fonts\LEELAWDB.TTF VolumeInformation
          Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.CrypterX-gen.16304.13478.exeQueries volume information: C:\Windows\Fonts\MSUIGHUR.TTF VolumeInformation
          Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.CrypterX-gen.16304.13478.exeQueries volume information: C:\Windows\Fonts\MSUIGHUB.TTF VolumeInformation
          Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.CrypterX-gen.16304.13478.exeQueries volume information: C:\Windows\Fonts\WINGDNG2.TTF VolumeInformation
          Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.CrypterX-gen.16304.13478.exeQueries volume information: C:\Windows\Fonts\WINGDNG3.TTF VolumeInformation
          Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.CrypterX-gen.16304.13478.exeQueries volume information: C:\Windows\Fonts\TEMPSITC.TTF VolumeInformation
          Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.CrypterX-gen.16304.13478.exeQueries volume information: C:\Windows\Fonts\PRISTINA.TTF VolumeInformation
          Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.CrypterX-gen.16304.13478.exeQueries volume information: C:\Windows\Fonts\PAPYRUS.TTF VolumeInformation
          Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.CrypterX-gen.16304.13478.exeQueries volume information: C:\Windows\Fonts\MISTRAL.TTF VolumeInformation
          Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.CrypterX-gen.16304.13478.exeQueries volume information: C:\Windows\Fonts\LHANDW.TTF VolumeInformation
          Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.CrypterX-gen.16304.13478.exeQueries volume information: C:\Windows\Fonts\ITCKRIST.TTF VolumeInformation
          Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.CrypterX-gen.16304.13478.exeQueries volume information: C:\Windows\Fonts\JUICE___.TTF VolumeInformation
          Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.CrypterX-gen.16304.13478.exeQueries volume information: C:\Windows\Fonts\FRSCRIPT.TTF VolumeInformation
          Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.CrypterX-gen.16304.13478.exeQueries volume information: C:\Windows\Fonts\FREESCPT.TTF VolumeInformation
          Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.CrypterX-gen.16304.13478.exeQueries volume information: C:\Windows\Fonts\BRADHITC.TTF VolumeInformation
          Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.CrypterX-gen.16304.13478.exeQueries volume information: C:\Windows\Fonts\OUTLOOK.TTF VolumeInformation
          Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.CrypterX-gen.16304.13478.exeQueries volume information: C:\Windows\Fonts\BKANT.TTF VolumeInformation
          Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.CrypterX-gen.16304.13478.exeQueries volume information: C:\Windows\Fonts\ANTQUAI.TTF VolumeInformation
          Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.CrypterX-gen.16304.13478.exeQueries volume information: C:\Windows\Fonts\ANTQUAB.TTF VolumeInformation
          Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.CrypterX-gen.16304.13478.exeQueries volume information: C:\Windows\Fonts\ANTQUABI.TTF VolumeInformation
          Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.CrypterX-gen.16304.13478.exeQueries volume information: C:\Windows\Fonts\GARA.TTF VolumeInformation
          Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.CrypterX-gen.16304.13478.exeQueries volume information: C:\Windows\Fonts\GARAIT.TTF VolumeInformation
          Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.CrypterX-gen.16304.13478.exeQueries volume information: C:\Windows\Fonts\GARABD.TTF VolumeInformation
          Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.CrypterX-gen.16304.13478.exeQueries volume information: C:\Windows\Fonts\MTCORSVA.TTF VolumeInformation
          Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.CrypterX-gen.16304.13478.exeQueries volume information: C:\Windows\Fonts\GOTHIC.TTF VolumeInformation
          Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.CrypterX-gen.16304.13478.exeQueries volume information: C:\Windows\Fonts\GOTHICI.TTF VolumeInformation
          Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.CrypterX-gen.16304.13478.exeQueries volume information: C:\Windows\Fonts\GOTHICB.TTF VolumeInformation
          Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.CrypterX-gen.16304.13478.exeQueries volume information: C:\Windows\Fonts\GOTHICBI.TTF VolumeInformation
          Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.CrypterX-gen.16304.13478.exeQueries volume information: C:\Windows\Fonts\ALGER.TTF VolumeInformation
          Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.CrypterX-gen.16304.13478.exeQueries volume information: C:\Windows\Fonts\BASKVILL.TTF VolumeInformation
          Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.CrypterX-gen.16304.13478.exeQueries volume information: C:\Windows\Fonts\BAUHS93.TTF VolumeInformation
          Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.CrypterX-gen.16304.13478.exeQueries volume information: C:\Windows\Fonts\BELL.TTF VolumeInformation
          Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.CrypterX-gen.16304.13478.exeQueries volume information: C:\Windows\Fonts\BELLI.TTF VolumeInformation
          Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.CrypterX-gen.16304.13478.exeQueries volume information: C:\Windows\Fonts\BELLB.TTF VolumeInformation
          Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.CrypterX-gen.16304.13478.exeQueries volume information: C:\Windows\Fonts\BRLNSR.TTF VolumeInformation
          Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.CrypterX-gen.16304.13478.exeQueries volume information: C:\Windows\Fonts\BRLNSDB.TTF VolumeInformation
          Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.CrypterX-gen.16304.13478.exeQueries volume information: C:\Windows\Fonts\BRLNSB.TTF VolumeInformation
          Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.CrypterX-gen.16304.13478.exeQueries volume information: C:\Windows\Fonts\BERNHC.TTF VolumeInformation
          Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.CrypterX-gen.16304.13478.exeQueries volume information: C:\Windows\Fonts\BOD_PSTC.TTF VolumeInformation
          Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.CrypterX-gen.16304.13478.exeQueries volume information: C:\Windows\Fonts\BRITANIC.TTF VolumeInformation
          Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.CrypterX-gen.16304.13478.exeQueries volume information: C:\Windows\Fonts\BROADW.TTF VolumeInformation
          Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.CrypterX-gen.16304.13478.exeQueries volume information: C:\Windows\Fonts\BRUSHSCI.TTF VolumeInformation
          Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.CrypterX-gen.16304.13478.exeQueries volume information: C:\Windows\Fonts\CALIFR.TTF VolumeInformation
          Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.CrypterX-gen.16304.13478.exeQueries volume information: C:\Windows\Fonts\CALIFI.TTF VolumeInformation
          Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.CrypterX-gen.16304.13478.exeQueries volume information: C:\Windows\Fonts\CALIFB.TTF VolumeInformation
          Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.CrypterX-gen.16304.13478.exeQueries volume information: C:\Windows\Fonts\CENTAUR.TTF VolumeInformation
          Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.CrypterX-gen.16304.13478.exeQueries volume information: C:\Windows\Fonts\CHILLER.TTF VolumeInformation
          Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.CrypterX-gen.16304.13478.exeQueries volume information: C:\Windows\Fonts\COLONNA.TTF VolumeInformation
          Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.CrypterX-gen.16304.13478.exeQueries volume information: C:\Windows\Fonts\COOPBL.TTF VolumeInformation
          Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.CrypterX-gen.16304.13478.exeQueries volume information: C:\Windows\Fonts\FTLTLT.TTF VolumeInformation
          Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.CrypterX-gen.16304.13478.exeQueries volume information: C:\Windows\Fonts\HARLOWSI.TTF VolumeInformation
          Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.CrypterX-gen.16304.13478.exeQueries volume information: C:\Windows\Fonts\HARNGTON.TTF VolumeInformation
          Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.CrypterX-gen.16304.13478.exeQueries volume information: C:\Windows\Fonts\HTOWERT.TTF VolumeInformation
          Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.CrypterX-gen.16304.13478.exeQueries volume information: C:\Windows\Fonts\HTOWERTI.TTF VolumeInformation
          Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.CrypterX-gen.16304.13478.exeQueries volume information: C:\Windows\Fonts\JOKERMAN.TTF VolumeInformation
          Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.CrypterX-gen.16304.13478.exeQueries volume information: C:\Windows\Fonts\KUNSTLER.TTF VolumeInformation
          Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.CrypterX-gen.16304.13478.exeQueries volume information: C:\Windows\Fonts\LBRITE.TTF VolumeInformation
          Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.CrypterX-gen.16304.13478.exeQueries volume information: C:\Windows\Fonts\LBRITED.TTF VolumeInformation
          Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.CrypterX-gen.16304.13478.exeQueries volume information: C:\Windows\Fonts\LBRITEI.TTF VolumeInformation
          Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.CrypterX-gen.16304.13478.exeQueries volume information: C:\Windows\Fonts\LBRITEDI.TTF VolumeInformation
          Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.CrypterX-gen.16304.13478.exeQueries volume information: C:\Windows\Fonts\LCALLIG.TTF VolumeInformation
          Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.CrypterX-gen.16304.13478.exeQueries volume information: C:\Windows\Fonts\LFAX.TTF VolumeInformation
          Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.CrypterX-gen.16304.13478.exeQueries volume information: C:\Windows\Fonts\LFAXD.TTF VolumeInformation
          Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.CrypterX-gen.16304.13478.exeQueries volume information: C:\Windows\Fonts\LFAXI.TTF VolumeInformation
          Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.CrypterX-gen.16304.13478.exeQueries volume information: C:\Windows\Fonts\LFAXDI.TTF VolumeInformation
          Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.CrypterX-gen.16304.13478.exeQueries volume information: C:\Windows\Fonts\MAGNETOB.TTF VolumeInformation
          Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.CrypterX-gen.16304.13478.exeQueries volume information: C:\Windows\Fonts\MATURASC.TTF VolumeInformation
          Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.CrypterX-gen.16304.13478.exeQueries volume information: C:\Windows\Fonts\MOD20.TTF VolumeInformation
          Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.CrypterX-gen.16304.13478.exeQueries volume information: C:\Windows\Fonts\NIAGENG.TTF VolumeInformation
          Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.CrypterX-gen.16304.13478.exeQueries volume information: C:\Windows\Fonts\NIAGSOL.TTF VolumeInformation
          Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.CrypterX-gen.16304.13478.exeQueries volume information: C:\Windows\Fonts\OLDENGL.TTF VolumeInformation
          Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.CrypterX-gen.16304.13478.exeQueries volume information: C:\Windows\Fonts\ONYX.TTF VolumeInformation
          Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.CrypterX-gen.16304.13478.exeQueries volume information: C:\Windows\Fonts\PARCHM.TTF VolumeInformation
          Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.CrypterX-gen.16304.13478.exeQueries volume information: C:\Windows\Fonts\PLAYBILL.TTF VolumeInformation
          Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.CrypterX-gen.16304.13478.exeQueries volume information: C:\Windows\Fonts\POORICH.TTF VolumeInformation
          Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.CrypterX-gen.16304.13478.exeQueries volume information: C:\Windows\Fonts\RAVIE.TTF VolumeInformation
          Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.CrypterX-gen.16304.13478.exeQueries volume information: C:\Windows\Fonts\INFROMAN.TTF VolumeInformation
          Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.CrypterX-gen.16304.13478.exeQueries volume information: C:\Windows\Fonts\SHOWG.TTF VolumeInformation
          Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.CrypterX-gen.16304.13478.exeQueries volume information: C:\Windows\Fonts\SNAP____.TTF VolumeInformation
          Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.CrypterX-gen.16304.13478.exeQueries volume information: C:\Windows\Fonts\STENCIL.TTF VolumeInformation
          Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.CrypterX-gen.16304.13478.exeQueries volume information: C:\Windows\Fonts\VINERITC.TTF VolumeInformation
          Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.CrypterX-gen.16304.13478.exeQueries volume information: C:\Windows\Fonts\VIVALDII.TTF VolumeInformation
          Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.CrypterX-gen.16304.13478.exeQueries volume information: C:\Windows\Fonts\VLADIMIR.TTF VolumeInformation
          Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.CrypterX-gen.16304.13478.exeQueries volume information: C:\Windows\Fonts\LATINWD.TTF VolumeInformation
          Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.CrypterX-gen.16304.13478.exeQueries volume information: C:\Windows\Fonts\TCM_____.TTF VolumeInformation
          Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.CrypterX-gen.16304.13478.exeQueries volume information: C:\Windows\Fonts\TCMI____.TTF VolumeInformation
          Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.CrypterX-gen.16304.13478.exeQueries volume information: C:\Windows\Fonts\TCB_____.TTF VolumeInformation
          Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.CrypterX-gen.16304.13478.exeQueries volume information: C:\Windows\Fonts\TCBI____.TTF VolumeInformation
          Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.CrypterX-gen.16304.13478.exeQueries volume information: C:\Windows\Fonts\TCCM____.TTF VolumeInformation
          Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.CrypterX-gen.16304.13478.exeQueries volume information: C:\Windows\Fonts\TCCB____.TTF VolumeInformation
          Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.CrypterX-gen.16304.13478.exeQueries volume information: C:\Windows\Fonts\TCCEB.TTF VolumeInformation
          Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.CrypterX-gen.16304.13478.exeQueries volume information: C:\Windows\Fonts\SCRIPTBL.TTF VolumeInformation
          Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.CrypterX-gen.16304.13478.exeQueries volume information: C:\Windows\Fonts\ROCK.TTF VolumeInformation
          Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.CrypterX-gen.16304.13478.exeQueries volume information: C:\Windows\Fonts\ROCKI.TTF VolumeInformation
          Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.CrypterX-gen.16304.13478.exeQueries volume information: C:\Windows\Fonts\ROCKB.TTF VolumeInformation
          Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.CrypterX-gen.16304.13478.exeQueries volume information: C:\Windows\Fonts\ROCKEB.TTF VolumeInformation
          Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.CrypterX-gen.16304.13478.exeQueries volume information: C:\Windows\Fonts\ROCKBI.TTF VolumeInformation
          Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.CrypterX-gen.16304.13478.exeQueries volume information: C:\Windows\Fonts\ROCC____.TTF VolumeInformation
          Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.CrypterX-gen.16304.13478.exeQueries volume information: C:\Windows\Fonts\ROCCB___.TTF VolumeInformation
          Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.CrypterX-gen.16304.13478.exeQueries volume information: C:\Windows\Fonts\RAGE.TTF VolumeInformation
          Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.CrypterX-gen.16304.13478.exeQueries volume information: C:\Windows\Fonts\PERTILI.TTF VolumeInformation
          Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.CrypterX-gen.16304.13478.exeQueries volume information: C:\Windows\Fonts\PERTIBD.TTF VolumeInformation
          Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.CrypterX-gen.16304.13478.exeQueries volume information: C:\Windows\Fonts\PER_____.TTF VolumeInformation
          Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.CrypterX-gen.16304.13478.exeQueries volume information: C:\Windows\Fonts\PERI____.TTF VolumeInformation
          Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.CrypterX-gen.16304.13478.exeQueries volume information: C:\Windows\Fonts\PERB____.TTF VolumeInformation
          Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.CrypterX-gen.16304.13478.exeQueries volume information: C:\Windows\Fonts\PERBI___.TTF VolumeInformation
          Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.CrypterX-gen.16304.13478.exeQueries volume information: C:\Windows\Fonts\PALSCRI.TTF VolumeInformation
          Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.CrypterX-gen.16304.13478.exeQueries volume information: C:\Windows\Fonts\OCRAEXT.TTF VolumeInformation
          Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.CrypterX-gen.16304.13478.exeQueries volume information: C:\Windows\Fonts\MAIAN.TTF VolumeInformation
          Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.CrypterX-gen.16304.13478.exeQueries volume information: C:\Windows\Fonts\LTYPE.TTF VolumeInformation
          Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.CrypterX-gen.16304.13478.exeQueries volume information: C:\Windows\Fonts\LTYPEO.TTF VolumeInformation
          Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.CrypterX-gen.16304.13478.exeQueries volume information: C:\Windows\Fonts\LTYPEB.TTF VolumeInformation
          Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.CrypterX-gen.16304.13478.exeQueries volume information: C:\Windows\Fonts\LTYPEBO.TTF VolumeInformation
          Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.CrypterX-gen.16304.13478.exeQueries volume information: C:\Windows\Fonts\LSANS.TTF VolumeInformation
          Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.CrypterX-gen.16304.13478.exeQueries volume information: C:\Windows\Fonts\LSANSD.TTF VolumeInformation
          Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.CrypterX-gen.16304.13478.exeQueries volume information: C:\Windows\Fonts\LSANSI.TTF VolumeInformation
          Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.CrypterX-gen.16304.13478.exeQueries volume information: C:\Windows\Fonts\LSANSDI.TTF VolumeInformation
          Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.CrypterX-gen.16304.13478.exeQueries volume information: C:\Windows\Fonts\IMPRISHA.TTF VolumeInformation
          Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.CrypterX-gen.16304.13478.exeQueries volume information: C:\Windows\Fonts\HATTEN.TTF VolumeInformation
          Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.CrypterX-gen.16304.13478.exeQueries volume information: C:\Windows\Fonts\GOUDYSTO.TTF VolumeInformation
          Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.CrypterX-gen.16304.13478.exeQueries volume information: C:\Windows\Fonts\GOUDOS.TTF VolumeInformation
          Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.CrypterX-gen.16304.13478.exeQueries volume information: C:\Windows\Fonts\GOUDOSI.TTF VolumeInformation
          Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.CrypterX-gen.16304.13478.exeQueries volume information: C:\Windows\Fonts\GOUDOSB.TTF VolumeInformation
          Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.CrypterX-gen.16304.13478.exeQueries volume information: C:\Windows\Fonts\GLECB.TTF VolumeInformation
          Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.CrypterX-gen.16304.13478.exeQueries volume information: C:\Windows\Fonts\GIL_____.TTF VolumeInformation
          Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.CrypterX-gen.16304.13478.exeQueries volume information: C:\Windows\Fonts\GILI____.TTF VolumeInformation
          Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.CrypterX-gen.16304.13478.exeQueries volume information: C:\Windows\Fonts\GILB____.TTF VolumeInformation
          Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.CrypterX-gen.16304.13478.exeQueries volume information: C:\Windows\Fonts\GILBI___.TTF VolumeInformation
          Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.CrypterX-gen.16304.13478.exeQueries volume information: C:\Windows\Fonts\GILC____.TTF VolumeInformation
          Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.CrypterX-gen.16304.13478.exeQueries volume information: C:\Windows\Fonts\GLSNECB.TTF VolumeInformation
          Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.CrypterX-gen.16304.13478.exeQueries volume information: C:\Windows\Fonts\GIGI.TTF VolumeInformation
          Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.CrypterX-gen.16304.13478.exeQueries volume information: C:\Windows\Fonts\FRABK.TTF VolumeInformation
          Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.CrypterX-gen.16304.13478.exeQueries volume information: C:\Windows\Fonts\FRABKIT.TTF VolumeInformation
          Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.CrypterX-gen.16304.13478.exeQueries volume information: C:\Windows\Fonts\FORTE.TTF VolumeInformation
          Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.CrypterX-gen.16304.13478.exeQueries volume information: C:\Windows\Fonts\FELIXTI.TTF VolumeInformation
          Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.CrypterX-gen.16304.13478.exeQueries volume information: C:\Windows\Fonts\ERASMD.TTF VolumeInformation
          Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.CrypterX-gen.16304.13478.exeQueries volume information: C:\Windows\Fonts\ERASLGHT.TTF VolumeInformation
          Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.CrypterX-gen.16304.13478.exeQueries volume information: C:\Windows\Fonts\ERASDEMI.TTF VolumeInformation
          Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.CrypterX-gen.16304.13478.exeQueries volume information: C:\Windows\Fonts\ERASBD.TTF VolumeInformation
          Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.CrypterX-gen.16304.13478.exeQueries volume information: C:\Windows\Fonts\ENGR.TTF VolumeInformation
          Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.CrypterX-gen.16304.13478.exeQueries volume information: C:\Windows\Fonts\ELEPHNT.TTF VolumeInformation
          Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.CrypterX-gen.16304.13478.exeQueries volume information: C:\Windows\Fonts\ELEPHNTI.TTF VolumeInformation
          Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.CrypterX-gen.16304.13478.exeQueries volume information: C:\Windows\Fonts\ITCEDSCR.TTF VolumeInformation
          Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.CrypterX-gen.16304.13478.exeQueries volume information: C:\Windows\Fonts\CURLZ___.TTF VolumeInformation
          Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.CrypterX-gen.16304.13478.exeQueries volume information: C:\Windows\Fonts\COPRGTL.TTF VolumeInformation
          Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.CrypterX-gen.16304.13478.exeQueries volume information: C:\Windows\Fonts\COPRGTB.TTF VolumeInformation
          Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.CrypterX-gen.16304.13478.exeQueries volume information: C:\Windows\Fonts\CENSCBK.TTF VolumeInformation
          Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.CrypterX-gen.16304.13478.exeQueries volume information: C:\Windows\Fonts\SCHLBKI.TTF VolumeInformation
          Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.CrypterX-gen.16304.13478.exeQueries volume information: C:\Windows\Fonts\SCHLBKB.TTF VolumeInformation
          Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.CrypterX-gen.16304.13478.exeQueries volume information: C:\Windows\Fonts\SCHLBKBI.TTF VolumeInformation
          Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.CrypterX-gen.16304.13478.exeQueries volume information: C:\Windows\Fonts\CASTELAR.TTF VolumeInformation
          Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.CrypterX-gen.16304.13478.exeQueries volume information: C:\Windows\Fonts\CALIST.TTF VolumeInformation
          Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.CrypterX-gen.16304.13478.exeQueries volume information: C:\Windows\Fonts\CALISTI.TTF VolumeInformation
          Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.CrypterX-gen.16304.13478.exeQueries volume information: C:\Windows\Fonts\CALISTB.TTF VolumeInformation
          Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.CrypterX-gen.16304.13478.exeQueries volume information: C:\Windows\Fonts\CALISTBI.TTF VolumeInformation
          Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.CrypterX-gen.16304.13478.exeQueries volume information: C:\Windows\Fonts\BOOKOS.TTF VolumeInformation
          Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.CrypterX-gen.16304.13478.exeQueries volume information: C:\Windows\Fonts\BOOKOSB.TTF VolumeInformation
          Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.CrypterX-gen.16304.13478.exeQueries volume information: C:\Windows\Fonts\BOOKOSI.TTF VolumeInformation
          Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.CrypterX-gen.16304.13478.exeQueries volume information: C:\Windows\Fonts\BOOKOSBI.TTF VolumeInformation
          Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.CrypterX-gen.16304.13478.exeQueries volume information: C:\Windows\Fonts\BOD_R.TTF VolumeInformation
          Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.CrypterX-gen.16304.13478.exeQueries volume information: C:\Windows\Fonts\BOD_I.TTF VolumeInformation
          Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.CrypterX-gen.16304.13478.exeQueries volume information: C:\Windows\Fonts\BOD_B.TTF VolumeInformation
          Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.CrypterX-gen.16304.13478.exeQueries volume information: C:\Windows\Fonts\BOD_BI.TTF VolumeInformation
          Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.CrypterX-gen.16304.13478.exeQueries volume information: C:\Windows\Fonts\BOD_CR.TTF VolumeInformation
          Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.CrypterX-gen.16304.13478.exeQueries volume information: C:\Windows\Fonts\BOD_BLAR.TTF VolumeInformation
          Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.CrypterX-gen.16304.13478.exeQueries volume information: C:\Windows\Fonts\BOD_CI.TTF VolumeInformation
          Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.CrypterX-gen.16304.13478.exeQueries volume information: C:\Windows\Fonts\BOD_CB.TTF VolumeInformation
          Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.CrypterX-gen.16304.13478.exeQueries volume information: C:\Windows\Fonts\BOD_BLAI.TTF VolumeInformation
          Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.CrypterX-gen.16304.13478.exeQueries volume information: C:\Windows\Fonts\BOD_CBI.TTF VolumeInformation
          Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.CrypterX-gen.16304.13478.exeQueries volume information: C:\Windows\Fonts\ITCBLKAD.TTF VolumeInformation
          Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.CrypterX-gen.16304.13478.exeQueries volume information: C:\Windows\Fonts\ARLRDBD.TTF VolumeInformation
          Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.CrypterX-gen.16304.13478.exeQueries volume information: C:\Windows\Fonts\AGENCYR.TTF VolumeInformation
          Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.CrypterX-gen.16304.13478.exeQueries volume information: C:\Windows\Fonts\AGENCYB.TTF VolumeInformation
          Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.CrypterX-gen.16304.13478.exeQueries volume information: C:\Windows\Fonts\BSSYM7.TTF VolumeInformation
          Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.CrypterX-gen.16304.13478.exeQueries volume information: C:\Windows\Fonts\REFSAN.TTF VolumeInformation
          Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.CrypterX-gen.16304.13478.exeQueries volume information: C:\Windows\Fonts\REFSPCL.TTF VolumeInformation
          Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.CrypterX-gen.16304.13478.exeQueries volume information: C:\Windows\Fonts\MTEXTRA.TTF VolumeInformation
          Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.CrypterX-gen.16304.13478.exeQueries volume information: C:\Windows\Fonts\marlett.ttf VolumeInformation
          Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.CrypterX-gen.16304.13478.exeQueries volume information: C:\Windows\Fonts\tahoma.ttf VolumeInformation
          Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.CrypterX-gen.16304.13478.exeQueries volume information: C:\Windows\Fonts\tahomabd.ttf VolumeInformation
          Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.CrypterX-gen.16304.13478.exeQueries volume information: C:\Windows\Fonts\micross.ttf VolumeInformation
          Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.CrypterX-gen.16304.13478.exeQueries volume information: C:\Windows\Microsoft.NET\assembly\GAC_MSIL\Microsoft.VisualBasic\v4.0_10.0.0.0__b03f5f7f11d50a3a\Microsoft.VisualBasic.dll VolumeInformation
          Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.CrypterX-gen.16304.13478.exeKey value queried: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Cryptography MachineGuid

          Stealing of Sensitive Information

          barindex
          Source: Yara matchFile source: 1.0.SecuriteInfo.com.Win32.CrypterX-gen.16304.13478.exe.400000.0.unpack, type: UNPACKEDPE
          Source: Yara matchFile source: 0.2.SecuriteInfo.com.Win32.CrypterX-gen.16304.13478.exe.44aef60.6.raw.unpack, type: UNPACKEDPE
          Source: Yara matchFile source: 0.2.SecuriteInfo.com.Win32.CrypterX-gen.16304.13478.exe.45233b0.5.raw.unpack, type: UNPACKEDPE
          Source: Yara matchFile source: 00000001.00000000.262712520.0000000000401000.00000040.00000400.00020000.00000000.sdmp, type: MEMORY
          Source: Yara matchFile source: 00000000.00000002.270529665.00000000044AE000.00000004.00000800.00020000.00000000.sdmp, type: MEMORY

          Remote Access Functionality

          barindex
          Source: Yara matchFile source: 1.0.SecuriteInfo.com.Win32.CrypterX-gen.16304.13478.exe.400000.0.unpack, type: UNPACKEDPE
          Source: Yara matchFile source: 0.2.SecuriteInfo.com.Win32.CrypterX-gen.16304.13478.exe.44aef60.6.raw.unpack, type: UNPACKEDPE
          Source: Yara matchFile source: 0.2.SecuriteInfo.com.Win32.CrypterX-gen.16304.13478.exe.45233b0.5.raw.unpack, type: UNPACKEDPE
          Source: Yara matchFile source: 00000001.00000000.262712520.0000000000401000.00000040.00000400.00020000.00000000.sdmp, type: MEMORY
          Source: Yara matchFile source: 00000000.00000002.270529665.00000000044AE000.00000004.00000800.00020000.00000000.sdmp, type: MEMORY
          Initial AccessExecutionPersistencePrivilege EscalationDefense EvasionCredential AccessDiscoveryLateral MovementCollectionExfiltrationCommand and ControlNetwork EffectsRemote Service EffectsImpact
          Valid Accounts2
          Command and Scripting Interpreter
          Path Interception111
          Process Injection
          1
          Masquerading
          1
          Input Capture
          221
          Security Software Discovery
          Remote Services1
          Input Capture
          Exfiltration Over Other Network Medium1
          Encrypted Channel
          Eavesdrop on Insecure Network CommunicationRemotely Track Device Without AuthorizationModify System Partition
          Default AccountsScheduled Task/JobBoot or Logon Initialization ScriptsBoot or Logon Initialization Scripts1
          Disable or Modify Tools
          LSASS Memory1
          Process Discovery
          Remote Desktop Protocol1
          Archive Collected Data
          Exfiltration Over Bluetooth1
          Application Layer Protocol
          Exploit SS7 to Redirect Phone Calls/SMSRemotely Wipe Data Without AuthorizationDevice Lockout
          Domain AccountsAt (Linux)Logon Script (Windows)Logon Script (Windows)31
          Virtualization/Sandbox Evasion
          Security Account Manager31
          Virtualization/Sandbox Evasion
          SMB/Windows Admin SharesData from Network Shared DriveAutomated ExfiltrationSteganographyExploit SS7 to Track Device LocationObtain Device Cloud BackupsDelete Device Data
          Local AccountsAt (Windows)Logon Script (Mac)Logon Script (Mac)111
          Process Injection
          NTDS112
          System Information Discovery
          Distributed Component Object ModelInput CaptureScheduled TransferProtocol ImpersonationSIM Card SwapCarrier Billing Fraud
          Cloud AccountsCronNetwork Logon ScriptNetwork Logon Script1
          Deobfuscate/Decode Files or Information
          LSA SecretsRemote System DiscoverySSHKeyloggingData Transfer Size LimitsFallback ChannelsManipulate Device CommunicationManipulate App Store Rankings or Ratings
          Replication Through Removable MediaLaunchdRc.commonRc.common3
          Obfuscated Files or Information
          Cached Domain CredentialsSystem Owner/User DiscoveryVNCGUI Input CaptureExfiltration Over C2 ChannelMultiband CommunicationJamming or Denial of ServiceAbuse Accessibility Features
          External Remote ServicesScheduled TaskStartup ItemsStartup Items3
          Software Packing
          DCSyncNetwork SniffingWindows Remote ManagementWeb Portal CaptureExfiltration Over Alternative ProtocolCommonly Used PortRogue Wi-Fi Access PointsData Encrypted for Impact
          Hide Legend

          Legend:

          • Process
          • Signature
          • Created File
          • DNS/IP Info
          • Is Dropped
          • Is Windows Process
          • Number of created Registry Values
          • Number of created Files
          • Visual Basic
          • Delphi
          • Java
          • .Net C# or VB.NET
          • C, C++ or other language
          • Is malicious
          • Internet

          This section contains all screenshots as thumbnails, including those not shown in the slideshow.


          windows-stand
          SourceDetectionScannerLabelLink
          SecuriteInfo.com.Win32.CrypterX-gen.16304.13478.exe29%ReversingLabsWin32.Trojan.Woreflint
          SecuriteInfo.com.Win32.CrypterX-gen.16304.13478.exe100%Joe Sandbox ML
          No Antivirus matches
          SourceDetectionScannerLabelLinkDownload
          1.0.SecuriteInfo.com.Win32.CrypterX-gen.16304.13478.exe.400000.0.unpack100%AviraTR/Crypt.ZPACK.GenDownload File
          No Antivirus matches
          SourceDetectionScannerLabelLink
          http://www.founder.com.cn/cn/bThe0%URL Reputationsafe
          http://www.tiro.com0%URL Reputationsafe
          http://www.goodfont.co.kr0%URL Reputationsafe
          http://www.carterandcone.coml0%URL Reputationsafe
          http://www.sajatypeworks.com0%URL Reputationsafe
          http://www.sajatypeworks.com0%URL Reputationsafe
          http://www.typography.netD0%URL Reputationsafe
          http://www.founder.com.cn/cn/cThe0%URL Reputationsafe
          http://www.founder.com.cn/cn/cThe0%URL Reputationsafe
          http://www.galapagosdesign.com/staff/dennis.htm0%URL Reputationsafe
          http://fontfabrik.com0%URL Reputationsafe
          http://www.founder.com.cn/cn0%URL Reputationsafe
          http://www.jiyu-kobo.co.jp/0%URL Reputationsafe
          http://www.galapagosdesign.com/DPlease0%URL Reputationsafe
          http://www.sandoll.co.kr0%URL Reputationsafe
          http://www.urwpp.deDPlease0%URL Reputationsafe
          http://www.zhongyicts.com.cn0%URL Reputationsafe
          http://www.sakkal.com0%URL Reputationsafe
          www.2635westkaylaneprescott.com/ndgi/1%VirustotalBrowse
          www.2635westkaylaneprescott.com/ndgi/100%Avira URL Cloudmalware
          No contacted domains info
          NameMaliciousAntivirus DetectionReputation
          www.2635westkaylaneprescott.com/ndgi/true
          • 1%, Virustotal, Browse
          • Avira URL Cloud: malware
          low
          NameSourceMaliciousAntivirus DetectionReputation
          http://www.apache.org/licenses/LICENSE-2.0SecuriteInfo.com.Win32.CrypterX-gen.16304.13478.exe, 00000000.00000002.272505714.0000000007232000.00000004.00000800.00020000.00000000.sdmpfalse
            high
            http://www.fontbureau.comSecuriteInfo.com.Win32.CrypterX-gen.16304.13478.exe, 00000000.00000002.272505714.0000000007232000.00000004.00000800.00020000.00000000.sdmpfalse
              high
              http://www.fontbureau.com/designersGSecuriteInfo.com.Win32.CrypterX-gen.16304.13478.exe, 00000000.00000002.272505714.0000000007232000.00000004.00000800.00020000.00000000.sdmpfalse
                high
                http://www.fontbureau.com/designers/?SecuriteInfo.com.Win32.CrypterX-gen.16304.13478.exe, 00000000.00000002.272505714.0000000007232000.00000004.00000800.00020000.00000000.sdmpfalse
                  high
                  http://www.founder.com.cn/cn/bTheSecuriteInfo.com.Win32.CrypterX-gen.16304.13478.exe, 00000000.00000002.272505714.0000000007232000.00000004.00000800.00020000.00000000.sdmpfalse
                  • URL Reputation: safe
                  unknown
                  http://www.fontbureau.com/designers?SecuriteInfo.com.Win32.CrypterX-gen.16304.13478.exe, 00000000.00000002.272505714.0000000007232000.00000004.00000800.00020000.00000000.sdmpfalse
                    high
                    http://www.tiro.comSecuriteInfo.com.Win32.CrypterX-gen.16304.13478.exe, 00000000.00000002.272505714.0000000007232000.00000004.00000800.00020000.00000000.sdmpfalse
                    • URL Reputation: safe
                    unknown
                    http://www.fontbureau.com/designersSecuriteInfo.com.Win32.CrypterX-gen.16304.13478.exe, 00000000.00000002.272505714.0000000007232000.00000004.00000800.00020000.00000000.sdmpfalse
                      high
                      http://www.goodfont.co.krSecuriteInfo.com.Win32.CrypterX-gen.16304.13478.exe, 00000000.00000002.272505714.0000000007232000.00000004.00000800.00020000.00000000.sdmpfalse
                      • URL Reputation: safe
                      unknown
                      http://www.carterandcone.comlSecuriteInfo.com.Win32.CrypterX-gen.16304.13478.exe, 00000000.00000002.272505714.0000000007232000.00000004.00000800.00020000.00000000.sdmpfalse
                      • URL Reputation: safe
                      unknown
                      http://www.sajatypeworks.comSecuriteInfo.com.Win32.CrypterX-gen.16304.13478.exe, 00000000.00000002.272505714.0000000007232000.00000004.00000800.00020000.00000000.sdmpfalse
                      • URL Reputation: safe
                      • URL Reputation: safe
                      unknown
                      http://www.typography.netDSecuriteInfo.com.Win32.CrypterX-gen.16304.13478.exe, 00000000.00000002.272505714.0000000007232000.00000004.00000800.00020000.00000000.sdmpfalse
                      • URL Reputation: safe
                      unknown
                      http://www.fontbureau.com/designers/cabarga.htmlNSecuriteInfo.com.Win32.CrypterX-gen.16304.13478.exe, 00000000.00000002.272505714.0000000007232000.00000004.00000800.00020000.00000000.sdmpfalse
                        high
                        http://www.founder.com.cn/cn/cTheSecuriteInfo.com.Win32.CrypterX-gen.16304.13478.exe, 00000000.00000002.272505714.0000000007232000.00000004.00000800.00020000.00000000.sdmpfalse
                        • URL Reputation: safe
                        • URL Reputation: safe
                        unknown
                        http://www.galapagosdesign.com/staff/dennis.htmSecuriteInfo.com.Win32.CrypterX-gen.16304.13478.exe, 00000000.00000002.272505714.0000000007232000.00000004.00000800.00020000.00000000.sdmpfalse
                        • URL Reputation: safe
                        unknown
                        http://fontfabrik.comSecuriteInfo.com.Win32.CrypterX-gen.16304.13478.exe, 00000000.00000002.272505714.0000000007232000.00000004.00000800.00020000.00000000.sdmpfalse
                        • URL Reputation: safe
                        unknown
                        http://www.founder.com.cn/cnSecuriteInfo.com.Win32.CrypterX-gen.16304.13478.exe, 00000000.00000002.272505714.0000000007232000.00000004.00000800.00020000.00000000.sdmpfalse
                        • URL Reputation: safe
                        unknown
                        http://www.fontbureau.com/designers/frere-jones.htmlSecuriteInfo.com.Win32.CrypterX-gen.16304.13478.exe, 00000000.00000002.272505714.0000000007232000.00000004.00000800.00020000.00000000.sdmpfalse
                          high
                          http://www.jiyu-kobo.co.jp/SecuriteInfo.com.Win32.CrypterX-gen.16304.13478.exe, 00000000.00000002.272505714.0000000007232000.00000004.00000800.00020000.00000000.sdmpfalse
                          • URL Reputation: safe
                          unknown
                          http://www.galapagosdesign.com/DPleaseSecuriteInfo.com.Win32.CrypterX-gen.16304.13478.exe, 00000000.00000002.272505714.0000000007232000.00000004.00000800.00020000.00000000.sdmpfalse
                          • URL Reputation: safe
                          unknown
                          http://www.fontbureau.com/designers8SecuriteInfo.com.Win32.CrypterX-gen.16304.13478.exe, 00000000.00000002.272505714.0000000007232000.00000004.00000800.00020000.00000000.sdmpfalse
                            high
                            http://www.fonts.comSecuriteInfo.com.Win32.CrypterX-gen.16304.13478.exe, 00000000.00000002.272505714.0000000007232000.00000004.00000800.00020000.00000000.sdmpfalse
                              high
                              http://www.sandoll.co.krSecuriteInfo.com.Win32.CrypterX-gen.16304.13478.exe, 00000000.00000002.272505714.0000000007232000.00000004.00000800.00020000.00000000.sdmpfalse
                              • URL Reputation: safe
                              unknown
                              http://www.urwpp.deDPleaseSecuriteInfo.com.Win32.CrypterX-gen.16304.13478.exe, 00000000.00000002.272505714.0000000007232000.00000004.00000800.00020000.00000000.sdmpfalse
                              • URL Reputation: safe
                              unknown
                              http://www.zhongyicts.com.cnSecuriteInfo.com.Win32.CrypterX-gen.16304.13478.exe, 00000000.00000002.272505714.0000000007232000.00000004.00000800.00020000.00000000.sdmpfalse
                              • URL Reputation: safe
                              unknown
                              http://www.sakkal.comSecuriteInfo.com.Win32.CrypterX-gen.16304.13478.exe, 00000000.00000002.272505714.0000000007232000.00000004.00000800.00020000.00000000.sdmpfalse
                              • URL Reputation: safe
                              unknown
                              No contacted IP infos
                              Joe Sandbox Version:36.0.0 Rainbow Opal
                              Analysis ID:755894
                              Start date and time:2022-11-29 09:34:09 +01:00
                              Joe Sandbox Product:CloudBasic
                              Overall analysis duration:0h 8m 0s
                              Hypervisor based Inspection enabled:false
                              Report type:light
                              Sample file name:SecuriteInfo.com.Win32.CrypterX-gen.16304.13478.exe
                              Cookbook file name:default.jbs
                              Analysis system description:Windows 10 64 bit v1803 with Office Professional Plus 2016, Chrome 104, IE 11, Adobe Reader DC 19, Java 8 Update 211
                              Number of analysed new started processes analysed:13
                              Number of new started drivers analysed:0
                              Number of existing processes analysed:0
                              Number of existing drivers analysed:0
                              Number of injected processes analysed:0
                              Technologies:
                              • HCA enabled
                              • EGA enabled
                              • HDC enabled
                              • AMSI enabled
                              Analysis Mode:default
                              Analysis stop reason:Timeout
                              Detection:MAL
                              Classification:mal100.troj.evad.winEXE@3/1@0/0
                              EGA Information:
                              • Successful, ratio: 100%
                              HDC Information:Failed
                              HCA Information:
                              • Successful, ratio: 96%
                              • Number of executed functions: 0
                              • Number of non-executed functions: 0
                              Cookbook Comments:
                              • Found application associated with file extension: .exe
                              • Exclude process from analysis (whitelisted): MpCmdRun.exe, SgrmBroker.exe, conhost.exe, svchost.exe
                              • Excluded domains from analysis (whitelisted): fs.microsoft.com
                              • Not all processes where analyzed, report is missing behavior information
                              • Report creation exceeded maximum time and may have missing disassembly code information.
                              • Report size getting too big, too many NtAllocateVirtualMemory calls found.
                              TimeTypeDescription
                              09:35:09API Interceptor1x Sleep call for process: SecuriteInfo.com.Win32.CrypterX-gen.16304.13478.exe modified
                              No context
                              No context
                              No context
                              No context
                              No context
                              Process:C:\Users\user\Desktop\SecuriteInfo.com.Win32.CrypterX-gen.16304.13478.exe
                              File Type:ASCII text, with CRLF line terminators
                              Category:dropped
                              Size (bytes):1216
                              Entropy (8bit):5.355304211458859
                              Encrypted:false
                              SSDEEP:24:MLUE4K5E4Ks2E1qE4qXKDE4KhK3VZ9pKhPKIE4oKFKHKoZAE4Kzr7FE4x84j:MIHK5HKXE1qHiYHKhQnoPtHoxHhAHKzr
                              MD5:FED34146BF2F2FA59DCF8702FCC8232E
                              SHA1:B03BFEA175989D989850CF06FE5E7BBF56EAA00A
                              SHA-256:123BE4E3590609A008E85501243AF5BC53FA0C26C82A92881B8879524F8C0D5C
                              SHA-512:1CC89F2ED1DBD70628FA1DC41A32BA0BFA3E81EAE1A1CF3C5F6A48F2DA0BF1F21A5001B8A18B04043C5B8FE4FBE663068D86AA8C4BD8E17933F75687C3178FF6
                              Malicious:true
                              Reputation:high, very likely benign file
                              Preview:1,"fusion","GAC",0..1,"WinRT","NotApp",1..2,"System.Windows.Forms, Version=4.0.0.0, Culture=neutral, PublicKeyToken=b77a5c561934e089",0..3,"System, Version=4.0.0.0, Culture=neutral, PublicKeyToken=b77a5c561934e089","C:\Windows\assembly\NativeImages_v4.0.30319_32\System\4f0a7eefa3cd3e0ba98b5ebddbbc72e6\System.ni.dll",0..2,"System.Drawing, Version=4.0.0.0, Culture=neutral, PublicKeyToken=b03f5f7f11d50a3a",0..3,"System.Core, Version=4.0.0.0, Culture=neutral, PublicKeyToken=b77a5c561934e089","C:\Windows\assembly\NativeImages_v4.0.30319_32\System.Core\f1d8480152e0da9a60ad49c6d16a3b6d\System.Core.ni.dll",0..3,"System.Configuration, Version=4.0.0.0, Culture=neutral, PublicKeyToken=b03f5f7f11d50a3a","C:\Windows\assembly\NativeImages_v4.0.30319_32\System.Configuration\8d67d92724ba494b6c7fd089d6f25b48\System.Configuration.ni.dll",0..3,"System.Xml, Version=4.0.0.0, Culture=neutral, PublicKeyToken=b77a5c561934e089","C:\Windows\assembly\NativeImages_v4.0.30319_32\System.Xml\b219d4630d26b88041b59c21
                              File type:PE32 executable (GUI) Intel 80386 Mono/.Net assembly, for MS Windows
                              Entropy (8bit):7.642628084460062
                              TrID:
                              • Win32 Executable (generic) Net Framework (10011505/4) 49.80%
                              • Win32 Executable (generic) a (10002005/4) 49.75%
                              • Generic CIL Executable (.NET, Mono, etc.) (73296/58) 0.36%
                              • Windows Screen Saver (13104/52) 0.07%
                              • Generic Win/DOS Executable (2004/3) 0.01%
                              File name:SecuriteInfo.com.Win32.CrypterX-gen.16304.13478.exe
                              File size:923648
                              MD5:2c37cb553314943214dc79d2d5cd95d2
                              SHA1:8d729ace154aae255cc7d20e0038889c1a16b30b
                              SHA256:5cfdb9f856907336025bbd526f7383ae8edbce669348b8e330251dfe21072c8f
                              SHA512:fea37cc09a83b578a2911924becca74df9fa1cec27fe182a455cc88b31c91033ceaee5f32bb4ce4e51cb354156da295c3d5281f383264261be0aa467b2bc6686
                              SSDEEP:24576:0YLeTgdo0x708aTH0wikFauuPZA2FDdEPf:0YLKgDx70j0wikFauuPZAzP
                              TLSH:5915D09033A6AF75F12867F37511810827723C6EA5E1D6296EDDF0DE2A72B4109F0B27
                              File Content Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.......PE..L......c..............0............../... ...@....@.. ....................................@................................
                              Icon Hash:00828e8e8686b000
                              Entrypoint:0x4e2fba
                              Entrypoint Section:.text
                              Digitally signed:false
                              Imagebase:0x400000
                              Subsystem:windows gui
                              Image File Characteristics:EXECUTABLE_IMAGE, 32BIT_MACHINE
                              DLL Characteristics:DYNAMIC_BASE, NX_COMPAT, NO_SEH, TERMINAL_SERVER_AWARE
                              Time Stamp:0x6385A4F1 [Tue Nov 29 06:21:37 2022 UTC]
                              TLS Callbacks:
                              CLR (.Net) Version:
                              OS Version Major:4
                              OS Version Minor:0
                              File Version Major:4
                              File Version Minor:0
                              Subsystem Version Major:4
                              Subsystem Version Minor:0
                              Import Hash:f34d5f2d4577ed6d9ceec516c1f5a744
                              Instruction
                              jmp dword ptr [00402000h]
                              add byte ptr [eax], al
                              add byte ptr [eax], al
                              add byte ptr [eax], al
                              add byte ptr [eax], al
                              add byte ptr [eax], al
                              add byte ptr [eax], al
                              add byte ptr [eax], al
                              add byte ptr [eax], al
                              add byte ptr [eax], al
                              add byte ptr [eax], al
                              add byte ptr [eax], al
                              add byte ptr [eax], al
                              add byte ptr [eax], al
                              add byte ptr [eax], al
                              add byte ptr [eax], al
                              add byte ptr [eax], al
                              add byte ptr [eax], al
                              add byte ptr [eax], al
                              add byte ptr [eax], al
                              add byte ptr [eax], al
                              add byte ptr [eax], al
                              add byte ptr [eax], al
                              add byte ptr [eax], al
                              add byte ptr [eax], al
                              add byte ptr [eax], al
                              add byte ptr [eax], al
                              add byte ptr [eax], al
                              add byte ptr [eax], al
                              add byte ptr [eax], al
                              add byte ptr [eax], al
                              add byte ptr [eax], al
                              add byte ptr [eax], al
                              add byte ptr [eax], al
                              add byte ptr [eax], al
                              add byte ptr [eax], al
                              add byte ptr [eax], al
                              add byte ptr [eax], al
                              add byte ptr [eax], al
                              add byte ptr [eax], al
                              add byte ptr [eax], al
                              add byte ptr [eax], al
                              add byte ptr [eax], al
                              add byte ptr [eax], al
                              add byte ptr [eax], al
                              add byte ptr [eax], al
                              add byte ptr [eax], al
                              add byte ptr [eax], al
                              add byte ptr [eax], al
                              add byte ptr [eax], al
                              add byte ptr [eax], al
                              add byte ptr [eax], al
                              add byte ptr [eax], al
                              add byte ptr [eax], al
                              add byte ptr [eax], al
                              add byte ptr [eax], al
                              add byte ptr [eax], al
                              add byte ptr [eax], al
                              add byte ptr [eax], al
                              add byte ptr [eax], al
                              add byte ptr [eax], al
                              add byte ptr [eax], al
                              add byte ptr [eax], al
                              add byte ptr [eax], al
                              add byte ptr [eax], al
                              add byte ptr [eax], al
                              add byte ptr [eax], al
                              add byte ptr [eax], al
                              add byte ptr [eax], al
                              add byte ptr [eax], al
                              add byte ptr [eax], al
                              add byte ptr [eax], al
                              add byte ptr [eax], al
                              add byte ptr [eax], al
                              add byte ptr [eax], al
                              add byte ptr [eax], al
                              add byte ptr [eax], al
                              add byte ptr [eax], al
                              add byte ptr [eax], al
                              add byte ptr [eax], al
                              add byte ptr [eax], al
                              add byte ptr [eax], al
                              add byte ptr [eax], al
                              add byte ptr [eax], al
                              add byte ptr [eax], al
                              add byte ptr [eax], al
                              add byte ptr [eax], al
                              add byte ptr [eax], al
                              add byte ptr [eax], al
                              add byte ptr [eax], al
                              add byte ptr [eax], al
                              add byte ptr [eax], al
                              add byte ptr [eax], al
                              add byte ptr [eax], al
                              add byte ptr [eax], al
                              add byte ptr [eax], al
                              add byte ptr [eax], al
                              add byte ptr [eax], al
                              NameVirtual AddressVirtual Size Is in Section
                              IMAGE_DIRECTORY_ENTRY_EXPORT0x00x0
                              IMAGE_DIRECTORY_ENTRY_IMPORT0xe2f680x4f.text
                              IMAGE_DIRECTORY_ENTRY_RESOURCE0xe40000x388.rsrc
                              IMAGE_DIRECTORY_ENTRY_EXCEPTION0x00x0
                              IMAGE_DIRECTORY_ENTRY_SECURITY0x00x0
                              IMAGE_DIRECTORY_ENTRY_BASERELOC0xe60000xc.reloc
                              IMAGE_DIRECTORY_ENTRY_DEBUG0x00x0
                              IMAGE_DIRECTORY_ENTRY_COPYRIGHT0x00x0
                              IMAGE_DIRECTORY_ENTRY_GLOBALPTR0x00x0
                              IMAGE_DIRECTORY_ENTRY_TLS0x00x0
                              IMAGE_DIRECTORY_ENTRY_LOAD_CONFIG0x00x0
                              IMAGE_DIRECTORY_ENTRY_BOUND_IMPORT0x00x0
                              IMAGE_DIRECTORY_ENTRY_IAT0x20000x8.text
                              IMAGE_DIRECTORY_ENTRY_DELAY_IMPORT0x00x0
                              IMAGE_DIRECTORY_ENTRY_COM_DESCRIPTOR0x20080x48.text
                              IMAGE_DIRECTORY_ENTRY_RESERVED0x00x0
                              NameVirtual AddressVirtual SizeRaw SizeXored PEZLIB ComplexityFile TypeEntropyCharacteristics
                              .text0x20000xe0fc00xe1000False0.8231304253472222data7.649413315465482IMAGE_SCN_CNT_CODE, IMAGE_SCN_MEM_EXECUTE, IMAGE_SCN_MEM_READ
                              .rsrc0xe40000x3880x400False0.3701171875data2.8571244568349785IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_READ
                              .reloc0xe60000xc0x200False0.044921875data0.10191042566270775IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_DISCARDABLE, IMAGE_SCN_MEM_READ
                              NameRVASizeTypeLanguageCountry
                              RT_VERSION0xe40580x32cdata
                              DLLImport
                              mscoree.dll_CorExeMain
                              No network behavior found

                              Click to jump to process

                              Target ID:0
                              Start time:09:35:01
                              Start date:29/11/2022
                              Path:C:\Users\user\Desktop\SecuriteInfo.com.Win32.CrypterX-gen.16304.13478.exe
                              Wow64 process (32bit):true
                              Commandline:C:\Users\user\Desktop\SecuriteInfo.com.Win32.CrypterX-gen.16304.13478.exe
                              Imagebase:0xca0000
                              File size:923648 bytes
                              MD5 hash:2C37CB553314943214DC79D2D5CD95D2
                              Has elevated privileges:true
                              Has administrator privileges:true
                              Programmed in:.Net C# or VB.NET
                              Yara matches:
                              • Rule: JoeSecurity_AntiVM_3, Description: Yara detected AntiVM_3, Source: 00000000.00000002.268979891.0000000003549000.00000004.00000800.00020000.00000000.sdmp, Author: Joe Security
                              • Rule: JoeSecurity_FormBook, Description: Yara detected FormBook, Source: 00000000.00000002.270529665.00000000044AE000.00000004.00000800.00020000.00000000.sdmp, Author: Joe Security
                              • Rule: Windows_Trojan_Formbook_1112e116, Description: unknown, Source: 00000000.00000002.270529665.00000000044AE000.00000004.00000800.00020000.00000000.sdmp, Author: unknown
                              • Rule: Formbook_1, Description: autogenerated rule brought to you by yara-signator, Source: 00000000.00000002.270529665.00000000044AE000.00000004.00000800.00020000.00000000.sdmp, Author: Felix Bilstein - yara-signator at cocacoding dot com
                              • Rule: Formbook, Description: detect Formbook in memory, Source: 00000000.00000002.270529665.00000000044AE000.00000004.00000800.00020000.00000000.sdmp, Author: JPCERT/CC Incident Response Group
                              • Rule: JoeSecurity_AntiVM_3, Description: Yara detected AntiVM_3, Source: 00000000.00000002.266387939.0000000003261000.00000004.00000800.00020000.00000000.sdmp, Author: Joe Security
                              Reputation:low

                              Target ID:1
                              Start time:09:35:10
                              Start date:29/11/2022
                              Path:C:\Users\user\Desktop\SecuriteInfo.com.Win32.CrypterX-gen.16304.13478.exe
                              Wow64 process (32bit):true
                              Commandline:C:\Users\user\Desktop\SecuriteInfo.com.Win32.CrypterX-gen.16304.13478.exe
                              Imagebase:0x940000
                              File size:923648 bytes
                              MD5 hash:2C37CB553314943214DC79D2D5CD95D2
                              Has elevated privileges:true
                              Has administrator privileges:true
                              Programmed in:C, C++ or other language
                              Yara matches:
                              • Rule: JoeSecurity_FormBook, Description: Yara detected FormBook, Source: 00000001.00000000.262712520.0000000000401000.00000040.00000400.00020000.00000000.sdmp, Author: Joe Security
                              • Rule: Windows_Trojan_Formbook_1112e116, Description: unknown, Source: 00000001.00000000.262712520.0000000000401000.00000040.00000400.00020000.00000000.sdmp, Author: unknown
                              • Rule: Formbook_1, Description: autogenerated rule brought to you by yara-signator, Source: 00000001.00000000.262712520.0000000000401000.00000040.00000400.00020000.00000000.sdmp, Author: Felix Bilstein - yara-signator at cocacoding dot com
                              • Rule: Formbook, Description: detect Formbook in memory, Source: 00000001.00000000.262712520.0000000000401000.00000040.00000400.00020000.00000000.sdmp, Author: JPCERT/CC Incident Response Group
                              Reputation:low

                              No disassembly