Loading Joe Sandbox Report ...

Edit tour

Windows Analysis Report
SecuriteInfo.com.Win32.PWSX-gen.27251.20675.exe

Overview

General Information

Sample Name:SecuriteInfo.com.Win32.PWSX-gen.27251.20675.exe
Analysis ID:755946
MD5:7b6dcd6fcd1c26b9abdba167929f4c82
SHA1:04f11f07ef4a51b16383b5dde94f1af405893b45
SHA256:e38f6fab27253171688423b0792d38be81e4c01cceb35c7bca05d2ebfc011ae9
Tags:exe
Infos:

Detection

FormBook
Score:92
Range:0 - 100
Whitelisted:false
Confidence:100%

Signatures

Multi AV Scanner detection for submitted file
Yara detected FormBook
Malicious sample detected (through community Yara rule)
Yara detected AntiVM3
Tries to detect sandboxes and other dynamic analysis tools (process name or module or function)
Machine Learning detection for sample
Injects a PE file into a foreign processes
Tries to detect virtualization through RDTSC time measurements
C2 URLs / IPs found in malware configuration
Uses 32bit PE files
Queries the volume information (name, serial number etc) of a device
Yara signature match
Antivirus or Machine Learning detection for unpacked file
May sleep (evasive loops) to hinder dynamic analysis
Uses code obfuscation techniques (call, push, ret)
Detected potential crypto function
Found potential string decryption / allocating functions
Contains functionality to call native functions
Contains functionality for execution timing, often used to detect debuggers
Contains long sleeps (>= 3 min)
Enables debug privileges
Sample file is different than original file name gathered from version info
Contains functionality to read the PEB
Checks if the current process is being debugged
Binary contains a suspicious time stamp
Found large amount of non-executed APIs
Creates a process in suspended mode (likely to inject code)
Contains functionality to access loader functionality (e.g. LdrGetProcedureAddress)

Classification

  • System is w10x64
  • cleanup
{"C2 list": ["www.imperiumtowns.xyz/b3es/"], "decoy": ["sweets.wtf", "apextama.com", "tygbs.com", "kumaoedu.com", "bestbathroomremodeling.club", "lnshykj.com", "nelsonanddima.com", "falunap.info", "codyhinrichs.com", "2797vip.com", "danutka.com", "3o2t307a.com", "kellymariewest.com", "profilelonn.online", "procan.website", "sopjimmy.com", "xn--skdarkae-55ac80i.net", "entitymanaged.com", "melitadahl.art", "joineguru.net", "good-meme.com", "creditconepts.com", "narafconstruction.com", "paspsichologa.com", "rancho365.com", "rimplefeel.com", "kingsub.online", "cnsrdns.com", "billythepainter.com", "clientevirtualpdf.net", "marycruzruiz.com", "renaultcikmaparca.xyz", "1600156.com", "paymallmart.info", "garafe.com", "fredrikk.net", "gogo-tunisia.space", "center-me.com", "xiaohuayhq.com", "xn--h49a60xt7azzcm91a.com", "unidiliobobo.info", "libertypolestore.com", "20111210.net", "atraofix.online", "furniron.com", "mingyun58.com", "shfesmua.com", "rdougdigital.life", "safsip.com", "melon.town", "sagihigaibengo.net", "ethnicsbyak.com", "designoffaitheventsllc.com", "dpmforensics.com", "ripple-us.net", "fuyouhin-happiness.com", "conceptweb.online", "l453.net", "zenars.com", "mepcoonlinebill.com", "oonn99.xyz", "dackus.energy", "articvas.com", "yayuanlin.com"]}
SourceRuleDescriptionAuthorStrings
00000000.00000002.260745770.0000000003051000.00000004.00000800.00020000.00000000.sdmpJoeSecurity_AntiVM_3Yara detected AntiVM_3Joe Security
    00000000.00000002.265052163.0000000004196000.00000004.00000800.00020000.00000000.sdmpJoeSecurity_FormBookYara detected FormBookJoe Security
      00000000.00000002.265052163.0000000004196000.00000004.00000800.00020000.00000000.sdmpWindows_Trojan_Formbook_1112e116unknownunknown
      • 0x65d1:$a1: 3C 30 50 4F 53 54 74 09 40
      • 0x349f1:$a1: 3C 30 50 4F 53 54 74 09 40
      • 0x61e11:$a1: 3C 30 50 4F 53 54 74 09 40
      • 0x1cf10:$a2: 74 0A 4E 0F B6 08 8D 44 08 01 75 F6 8D 70 01 0F B6 00 8D 55
      • 0x4b330:$a2: 74 0A 4E 0F B6 08 8D 44 08 01 75 F6 8D 70 01 0F B6 00 8D 55
      • 0x78750:$a2: 74 0A 4E 0F B6 08 8D 44 08 01 75 F6 8D 70 01 0F B6 00 8D 55
      • 0xad4f:$a3: 1A D2 80 E2 AF 80 C2 7E EB 2A 80 FA 2F 75 11 8A D0 80 E2 01
      • 0x3916f:$a3: 1A D2 80 E2 AF 80 C2 7E EB 2A 80 FA 2F 75 11 8A D0 80 E2 01
      • 0x6658f:$a3: 1A D2 80 E2 AF 80 C2 7E EB 2A 80 FA 2F 75 11 8A D0 80 E2 01
      • 0x15c37:$a4: 04 83 C4 0C 83 06 07 5B 5F 5E 8B E5 5D C3 8B 17 03 55 0C 6A 01 83
      • 0x44057:$a4: 04 83 C4 0C 83 06 07 5B 5F 5E 8B E5 5D C3 8B 17 03 55 0C 6A 01 83
      • 0x71477:$a4: 04 83 C4 0C 83 06 07 5B 5F 5E 8B E5 5D C3 8B 17 03 55 0C 6A 01 83
      00000000.00000002.265052163.0000000004196000.00000004.00000800.00020000.00000000.sdmpFormbook_1autogenerated rule brought to you by yara-signatorFelix Bilstein - yara-signator at cocacoding dot com
      • 0x9c88:$sequence_0: 03 C8 0F 31 2B C1 89 45 FC
      • 0x9f02:$sequence_0: 03 C8 0F 31 2B C1 89 45 FC
      • 0x380a8:$sequence_0: 03 C8 0F 31 2B C1 89 45 FC
      • 0x38322:$sequence_0: 03 C8 0F 31 2B C1 89 45 FC
      • 0x654c8:$sequence_0: 03 C8 0F 31 2B C1 89 45 FC
      • 0x65742:$sequence_0: 03 C8 0F 31 2B C1 89 45 FC
      • 0x15a35:$sequence_1: 3C 24 0F 84 76 FF FF FF 3C 25 74 94
      • 0x43e55:$sequence_1: 3C 24 0F 84 76 FF FF FF 3C 25 74 94
      • 0x71275:$sequence_1: 3C 24 0F 84 76 FF FF FF 3C 25 74 94
      • 0x15521:$sequence_2: 3B 4F 14 73 95 85 C9 74 91
      • 0x43941:$sequence_2: 3B 4F 14 73 95 85 C9 74 91
      • 0x70d61:$sequence_2: 3B 4F 14 73 95 85 C9 74 91
      • 0x15b37:$sequence_3: 3C 69 75 44 8B 7D 18 8B 0F
      • 0x43f57:$sequence_3: 3C 69 75 44 8B 7D 18 8B 0F
      • 0x71377:$sequence_3: 3C 69 75 44 8B 7D 18 8B 0F
      • 0x15caf:$sequence_4: 5D C3 8D 50 7C 80 FA 07
      • 0x440cf:$sequence_4: 5D C3 8D 50 7C 80 FA 07
      • 0x714ef:$sequence_4: 5D C3 8D 50 7C 80 FA 07
      • 0xa91a:$sequence_5: 0F BE 5C 0E 01 0F B6 54 0E 02 83 E3 0F C1 EA 06
      • 0x38d3a:$sequence_5: 0F BE 5C 0E 01 0F B6 54 0E 02 83 E3 0F C1 EA 06
      • 0x6615a:$sequence_5: 0F BE 5C 0E 01 0F B6 54 0E 02 83 E3 0F C1 EA 06
      00000000.00000002.265052163.0000000004196000.00000004.00000800.00020000.00000000.sdmpFormbookdetect Formbook in memoryJPCERT/CC Incident Response Group
      • 0x18b99:$sqlite3step: 68 34 1C 7B E1
      • 0x18cac:$sqlite3step: 68 34 1C 7B E1
      • 0x46fb9:$sqlite3step: 68 34 1C 7B E1
      • 0x470cc:$sqlite3step: 68 34 1C 7B E1
      • 0x743d9:$sqlite3step: 68 34 1C 7B E1
      • 0x744ec:$sqlite3step: 68 34 1C 7B E1
      • 0x18bc8:$sqlite3text: 68 38 2A 90 C5
      • 0x18ced:$sqlite3text: 68 38 2A 90 C5
      • 0x46fe8:$sqlite3text: 68 38 2A 90 C5
      • 0x4710d:$sqlite3text: 68 38 2A 90 C5
      • 0x74408:$sqlite3text: 68 38 2A 90 C5
      • 0x7452d:$sqlite3text: 68 38 2A 90 C5
      • 0x18bdb:$sqlite3blob: 68 53 D8 7F 8C
      • 0x18d03:$sqlite3blob: 68 53 D8 7F 8C
      • 0x46ffb:$sqlite3blob: 68 53 D8 7F 8C
      • 0x47123:$sqlite3blob: 68 53 D8 7F 8C
      • 0x7441b:$sqlite3blob: 68 53 D8 7F 8C
      • 0x74543:$sqlite3blob: 68 53 D8 7F 8C
      Click to see the 7 entries
      SourceRuleDescriptionAuthorStrings
      1.0.SecuriteInfo.com.Win32.PWSX-gen.27251.20675.exe.400000.0.unpackJoeSecurity_FormBookYara detected FormBookJoe Security
        1.0.SecuriteInfo.com.Win32.PWSX-gen.27251.20675.exe.400000.0.unpackWindows_Trojan_Formbook_1112e116unknownunknown
        • 0x5451:$a1: 3C 30 50 4F 53 54 74 09 40
        • 0x1bd90:$a2: 74 0A 4E 0F B6 08 8D 44 08 01 75 F6 8D 70 01 0F B6 00 8D 55
        • 0x9bcf:$a3: 1A D2 80 E2 AF 80 C2 7E EB 2A 80 FA 2F 75 11 8A D0 80 E2 01
        • 0x14ab7:$a4: 04 83 C4 0C 83 06 07 5B 5F 5E 8B E5 5D C3 8B 17 03 55 0C 6A 01 83
        1.0.SecuriteInfo.com.Win32.PWSX-gen.27251.20675.exe.400000.0.unpackFormbook_1autogenerated rule brought to you by yara-signatorFelix Bilstein - yara-signator at cocacoding dot com
        • 0x8b08:$sequence_0: 03 C8 0F 31 2B C1 89 45 FC
        • 0x8d82:$sequence_0: 03 C8 0F 31 2B C1 89 45 FC
        • 0x148b5:$sequence_1: 3C 24 0F 84 76 FF FF FF 3C 25 74 94
        • 0x143a1:$sequence_2: 3B 4F 14 73 95 85 C9 74 91
        • 0x149b7:$sequence_3: 3C 69 75 44 8B 7D 18 8B 0F
        • 0x14b2f:$sequence_4: 5D C3 8D 50 7C 80 FA 07
        • 0x979a:$sequence_5: 0F BE 5C 0E 01 0F B6 54 0E 02 83 E3 0F C1 EA 06
        • 0x1361c:$sequence_6: 57 89 45 FC 89 45 F4 89 45 F8
        • 0xa493:$sequence_7: 66 89 0C 02 5B 8B E5 5D
        • 0x1aaf7:$sequence_8: 3C 54 74 04 3C 74 75 F4
        • 0x1bafa:$sequence_9: 56 68 03 01 00 00 8D 85 95 FE FF FF 6A 00
        1.0.SecuriteInfo.com.Win32.PWSX-gen.27251.20675.exe.400000.0.unpackFormbookdetect Formbook in memoryJPCERT/CC Incident Response Group
        • 0x17a19:$sqlite3step: 68 34 1C 7B E1
        • 0x17b2c:$sqlite3step: 68 34 1C 7B E1
        • 0x17a48:$sqlite3text: 68 38 2A 90 C5
        • 0x17b6d:$sqlite3text: 68 38 2A 90 C5
        • 0x17a5b:$sqlite3blob: 68 53 D8 7F 8C
        • 0x17b83:$sqlite3blob: 68 53 D8 7F 8C
        No Sigma rule has matched
        No Snort rule has matched

        Click to jump to signature section

        Show All Signature Results

        AV Detection

        barindex
        Source: SecuriteInfo.com.Win32.PWSX-gen.27251.20675.exeReversingLabs: Detection: 41%
        Source: SecuriteInfo.com.Win32.PWSX-gen.27251.20675.exeVirustotal: Detection: 45%Perma Link
        Source: Yara matchFile source: 1.0.SecuriteInfo.com.Win32.PWSX-gen.27251.20675.exe.400000.0.unpack, type: UNPACKEDPE
        Source: Yara matchFile source: 00000000.00000002.265052163.0000000004196000.00000004.00000800.00020000.00000000.sdmp, type: MEMORY
        Source: Yara matchFile source: 00000001.00000000.257340997.0000000000401000.00000040.00000400.00020000.00000000.sdmp, type: MEMORY
        Source: SecuriteInfo.com.Win32.PWSX-gen.27251.20675.exeJoe Sandbox ML: detected
        Source: 1.0.SecuriteInfo.com.Win32.PWSX-gen.27251.20675.exe.400000.0.unpackAvira: Label: TR/Crypt.ZPACK.Gen
        Source: 00000000.00000002.265052163.0000000004196000.00000004.00000800.00020000.00000000.sdmpMalware Configuration Extractor: FormBook {"C2 list": ["www.imperiumtowns.xyz/b3es/"], "decoy": ["sweets.wtf", "apextama.com", "tygbs.com", "kumaoedu.com", "bestbathroomremodeling.club", "lnshykj.com", "nelsonanddima.com", "falunap.info", "codyhinrichs.com", "2797vip.com", "danutka.com", "3o2t307a.com", "kellymariewest.com", "profilelonn.online", "procan.website", "sopjimmy.com", "xn--skdarkae-55ac80i.net", "entitymanaged.com", "melitadahl.art", "joineguru.net", "good-meme.com", "creditconepts.com", "narafconstruction.com", "paspsichologa.com", "rancho365.com", "rimplefeel.com", "kingsub.online", "cnsrdns.com", "billythepainter.com", "clientevirtualpdf.net", "marycruzruiz.com", "renaultcikmaparca.xyz", "1600156.com", "paymallmart.info", "garafe.com", "fredrikk.net", "gogo-tunisia.space", "center-me.com", "xiaohuayhq.com", "xn--h49a60xt7azzcm91a.com", "unidiliobobo.info", "libertypolestore.com", "20111210.net", "atraofix.online", "furniron.com", "mingyun58.com", "shfesmua.com", "rdougdigital.life", "safsip.com", "melon.town", "sagihigaibengo.net", "ethnicsbyak.com", "designoffaitheventsllc.com", "dpmforensics.com", "ripple-us.net", "fuyouhin-happiness.com", "conceptweb.online", "l453.net", "zenars.com", "mepcoonlinebill.com", "oonn99.xyz", "dackus.energy", "articvas.com", "yayuanlin.com"]}
        Source: SecuriteInfo.com.Win32.PWSX-gen.27251.20675.exeStatic PE information: EXECUTABLE_IMAGE, 32BIT_MACHINE
        Source: SecuriteInfo.com.Win32.PWSX-gen.27251.20675.exeStatic PE information: DYNAMIC_BASE, NX_COMPAT, NO_SEH, TERMINAL_SERVER_AWARE
        Source: Binary string: wntdll.pdbUGP source: SecuriteInfo.com.Win32.PWSX-gen.27251.20675.exe, 00000001.00000003.257989308.0000000000CBF000.00000004.00000800.00020000.00000000.sdmp, SecuriteInfo.com.Win32.PWSX-gen.27251.20675.exe, 00000001.00000003.260648591.0000000000E5F000.00000004.00000800.00020000.00000000.sdmp, SecuriteInfo.com.Win32.PWSX-gen.27251.20675.exe, 00000001.00000002.262649793.0000000001000000.00000040.00000800.00020000.00000000.sdmp
        Source: Binary string: wntdll.pdb source: SecuriteInfo.com.Win32.PWSX-gen.27251.20675.exe, SecuriteInfo.com.Win32.PWSX-gen.27251.20675.exe, 00000001.00000003.257989308.0000000000CBF000.00000004.00000800.00020000.00000000.sdmp, SecuriteInfo.com.Win32.PWSX-gen.27251.20675.exe, 00000001.00000003.260648591.0000000000E5F000.00000004.00000800.00020000.00000000.sdmp, SecuriteInfo.com.Win32.PWSX-gen.27251.20675.exe, 00000001.00000002.262649793.0000000001000000.00000040.00000800.00020000.00000000.sdmp

        Networking

        barindex
        Source: Malware configuration extractorURLs: www.imperiumtowns.xyz/b3es/
        Source: SecuriteInfo.com.Win32.PWSX-gen.27251.20675.exe, 00000000.00000002.266762478.0000000007222000.00000004.00000800.00020000.00000000.sdmpString found in binary or memory: http://fontfabrik.com
        Source: SecuriteInfo.com.Win32.PWSX-gen.27251.20675.exe, 00000000.00000002.266762478.0000000007222000.00000004.00000800.00020000.00000000.sdmpString found in binary or memory: http://www.apache.org/licenses/LICENSE-2.0
        Source: SecuriteInfo.com.Win32.PWSX-gen.27251.20675.exe, 00000000.00000003.248951472.0000000006016000.00000004.00000800.00020000.00000000.sdmp, SecuriteInfo.com.Win32.PWSX-gen.27251.20675.exe, 00000000.00000003.249535557.0000000006017000.00000004.00000800.00020000.00000000.sdmp, SecuriteInfo.com.Win32.PWSX-gen.27251.20675.exe, 00000000.00000003.248773244.0000000006015000.00000004.00000800.00020000.00000000.sdmp, SecuriteInfo.com.Win32.PWSX-gen.27251.20675.exe, 00000000.00000003.249659691.000000000601C000.00000004.00000800.00020000.00000000.sdmp, SecuriteInfo.com.Win32.PWSX-gen.27251.20675.exe, 00000000.00000003.249765760.000000000601C000.00000004.00000800.00020000.00000000.sdmpString found in binary or memory: http://www.carterandcone.com
        Source: SecuriteInfo.com.Win32.PWSX-gen.27251.20675.exe, 00000000.00000002.266762478.0000000007222000.00000004.00000800.00020000.00000000.sdmpString found in binary or memory: http://www.carterandcone.coml
        Source: SecuriteInfo.com.Win32.PWSX-gen.27251.20675.exe, 00000000.00000002.266762478.0000000007222000.00000004.00000800.00020000.00000000.sdmpString found in binary or memory: http://www.fontbureau.com
        Source: SecuriteInfo.com.Win32.PWSX-gen.27251.20675.exe, 00000000.00000002.266762478.0000000007222000.00000004.00000800.00020000.00000000.sdmpString found in binary or memory: http://www.fontbureau.com/designers
        Source: SecuriteInfo.com.Win32.PWSX-gen.27251.20675.exe, 00000000.00000002.266762478.0000000007222000.00000004.00000800.00020000.00000000.sdmpString found in binary or memory: http://www.fontbureau.com/designers/?
        Source: SecuriteInfo.com.Win32.PWSX-gen.27251.20675.exe, 00000000.00000002.266762478.0000000007222000.00000004.00000800.00020000.00000000.sdmpString found in binary or memory: http://www.fontbureau.com/designers/cabarga.htmlN
        Source: SecuriteInfo.com.Win32.PWSX-gen.27251.20675.exe, 00000000.00000002.266762478.0000000007222000.00000004.00000800.00020000.00000000.sdmpString found in binary or memory: http://www.fontbureau.com/designers/frere-jones.html
        Source: SecuriteInfo.com.Win32.PWSX-gen.27251.20675.exe, 00000000.00000002.266762478.0000000007222000.00000004.00000800.00020000.00000000.sdmpString found in binary or memory: http://www.fontbureau.com/designers8
        Source: SecuriteInfo.com.Win32.PWSX-gen.27251.20675.exe, 00000000.00000002.266762478.0000000007222000.00000004.00000800.00020000.00000000.sdmpString found in binary or memory: http://www.fontbureau.com/designers?
        Source: SecuriteInfo.com.Win32.PWSX-gen.27251.20675.exe, 00000000.00000002.266762478.0000000007222000.00000004.00000800.00020000.00000000.sdmpString found in binary or memory: http://www.fontbureau.com/designersG
        Source: SecuriteInfo.com.Win32.PWSX-gen.27251.20675.exe, 00000000.00000003.250428092.0000000006028000.00000004.00000800.00020000.00000000.sdmp, SecuriteInfo.com.Win32.PWSX-gen.27251.20675.exe, 00000000.00000003.250339759.0000000006027000.00000004.00000800.00020000.00000000.sdmpString found in binary or memory: http://www.fontbureau.comB.TTF1
        Source: SecuriteInfo.com.Win32.PWSX-gen.27251.20675.exe, 00000000.00000003.250551871.0000000006027000.00000004.00000800.00020000.00000000.sdmp, SecuriteInfo.com.Win32.PWSX-gen.27251.20675.exe, 00000000.00000003.250428092.0000000006028000.00000004.00000800.00020000.00000000.sdmp, SecuriteInfo.com.Win32.PWSX-gen.27251.20675.exe, 00000000.00000003.250339759.0000000006027000.00000004.00000800.00020000.00000000.sdmpString found in binary or memory: http://www.fontbureau.comF
        Source: SecuriteInfo.com.Win32.PWSX-gen.27251.20675.exe, 00000000.00000003.250551871.0000000006027000.00000004.00000800.00020000.00000000.sdmpString found in binary or memory: http://www.fontbureau.comF1
        Source: SecuriteInfo.com.Win32.PWSX-gen.27251.20675.exe, 00000000.00000003.250551871.0000000006027000.00000004.00000800.00020000.00000000.sdmp, SecuriteInfo.com.Win32.PWSX-gen.27251.20675.exe, 00000000.00000003.258838031.0000000006022000.00000004.00000800.00020000.00000000.sdmp, SecuriteInfo.com.Win32.PWSX-gen.27251.20675.exe, 00000000.00000003.250428092.0000000006028000.00000004.00000800.00020000.00000000.sdmp, SecuriteInfo.com.Win32.PWSX-gen.27251.20675.exe, 00000000.00000002.266638604.0000000006027000.00000004.00000800.00020000.00000000.sdmp, SecuriteInfo.com.Win32.PWSX-gen.27251.20675.exe, 00000000.00000003.250339759.0000000006027000.00000004.00000800.00020000.00000000.sdmpString found in binary or memory: http://www.fontbureau.coma
        Source: SecuriteInfo.com.Win32.PWSX-gen.27251.20675.exe, 00000000.00000003.250551871.0000000006027000.00000004.00000800.00020000.00000000.sdmpString found in binary or memory: http://www.fontbureau.comals
        Source: SecuriteInfo.com.Win32.PWSX-gen.27251.20675.exe, 00000000.00000003.258838031.0000000006022000.00000004.00000800.00020000.00000000.sdmp, SecuriteInfo.com.Win32.PWSX-gen.27251.20675.exe, 00000000.00000002.266638604.0000000006027000.00000004.00000800.00020000.00000000.sdmpString found in binary or memory: http://www.fontbureau.comce
        Source: SecuriteInfo.com.Win32.PWSX-gen.27251.20675.exe, 00000000.00000003.250428092.0000000006028000.00000004.00000800.00020000.00000000.sdmp, SecuriteInfo.com.Win32.PWSX-gen.27251.20675.exe, 00000000.00000003.250339759.0000000006027000.00000004.00000800.00020000.00000000.sdmpString found in binary or memory: http://www.fontbureau.comessed
        Source: SecuriteInfo.com.Win32.PWSX-gen.27251.20675.exe, 00000000.00000003.250339759.0000000006027000.00000004.00000800.00020000.00000000.sdmpString found in binary or memory: http://www.fontbureau.comi
        Source: SecuriteInfo.com.Win32.PWSX-gen.27251.20675.exe, 00000000.00000003.258838031.0000000006022000.00000004.00000800.00020000.00000000.sdmp, SecuriteInfo.com.Win32.PWSX-gen.27251.20675.exe, 00000000.00000002.266638604.0000000006027000.00000004.00000800.00020000.00000000.sdmpString found in binary or memory: http://www.fontbureau.comicom
        Source: SecuriteInfo.com.Win32.PWSX-gen.27251.20675.exe, 00000000.00000003.250428092.0000000006028000.00000004.00000800.00020000.00000000.sdmpString found in binary or memory: http://www.fontbureau.comitue
        Source: SecuriteInfo.com.Win32.PWSX-gen.27251.20675.exe, 00000000.00000003.250339759.0000000006027000.00000004.00000800.00020000.00000000.sdmpString found in binary or memory: http://www.fontbureau.comoitu
        Source: SecuriteInfo.com.Win32.PWSX-gen.27251.20675.exe, 00000000.00000003.250428092.0000000006028000.00000004.00000800.00020000.00000000.sdmpString found in binary or memory: http://www.fontbureau.comt
        Source: SecuriteInfo.com.Win32.PWSX-gen.27251.20675.exe, 00000000.00000002.266762478.0000000007222000.00000004.00000800.00020000.00000000.sdmpString found in binary or memory: http://www.fonts.com
        Source: SecuriteInfo.com.Win32.PWSX-gen.27251.20675.exe, 00000000.00000003.247878242.0000000006028000.00000004.00000800.00020000.00000000.sdmpString found in binary or memory: http://www.founder.cm
        Source: SecuriteInfo.com.Win32.PWSX-gen.27251.20675.exe, 00000000.00000002.266762478.0000000007222000.00000004.00000800.00020000.00000000.sdmp, SecuriteInfo.com.Win32.PWSX-gen.27251.20675.exe, 00000000.00000003.247855685.000000000601A000.00000004.00000800.00020000.00000000.sdmp, SecuriteInfo.com.Win32.PWSX-gen.27251.20675.exe, 00000000.00000003.247400149.000000000602B000.00000004.00000800.00020000.00000000.sdmpString found in binary or memory: http://www.founder.com.cn/cn
        Source: SecuriteInfo.com.Win32.PWSX-gen.27251.20675.exe, 00000000.00000003.247855685.000000000601A000.00000004.00000800.00020000.00000000.sdmpString found in binary or memory: http://www.founder.com.cn/cn/-e
        Source: SecuriteInfo.com.Win32.PWSX-gen.27251.20675.exe, 00000000.00000002.266762478.0000000007222000.00000004.00000800.00020000.00000000.sdmpString found in binary or memory: http://www.founder.com.cn/cn/bThe
        Source: SecuriteInfo.com.Win32.PWSX-gen.27251.20675.exe, 00000000.00000002.266762478.0000000007222000.00000004.00000800.00020000.00000000.sdmpString found in binary or memory: http://www.founder.com.cn/cn/cThe
        Source: SecuriteInfo.com.Win32.PWSX-gen.27251.20675.exe, 00000000.00000002.266762478.0000000007222000.00000004.00000800.00020000.00000000.sdmpString found in binary or memory: http://www.galapagosdesign.com/DPlease
        Source: SecuriteInfo.com.Win32.PWSX-gen.27251.20675.exe, 00000000.00000002.266762478.0000000007222000.00000004.00000800.00020000.00000000.sdmpString found in binary or memory: http://www.galapagosdesign.com/staff/dennis.htm
        Source: SecuriteInfo.com.Win32.PWSX-gen.27251.20675.exe, 00000000.00000003.250848136.0000000006027000.00000004.00000800.00020000.00000000.sdmpString found in binary or memory: http://www.galapagosdesign.com/staff/dennis.htmX
        Source: SecuriteInfo.com.Win32.PWSX-gen.27251.20675.exe, 00000000.00000002.266762478.0000000007222000.00000004.00000800.00020000.00000000.sdmpString found in binary or memory: http://www.goodfont.co.kr
        Source: SecuriteInfo.com.Win32.PWSX-gen.27251.20675.exe, 00000000.00000003.249668471.0000000006022000.00000004.00000800.00020000.00000000.sdmp, SecuriteInfo.com.Win32.PWSX-gen.27251.20675.exe, 00000000.00000002.266762478.0000000007222000.00000004.00000800.00020000.00000000.sdmp, SecuriteInfo.com.Win32.PWSX-gen.27251.20675.exe, 00000000.00000003.249560073.0000000006028000.00000004.00000800.00020000.00000000.sdmp, SecuriteInfo.com.Win32.PWSX-gen.27251.20675.exe, 00000000.00000003.248773244.0000000006015000.00000004.00000800.00020000.00000000.sdmp, SecuriteInfo.com.Win32.PWSX-gen.27251.20675.exe, 00000000.00000003.249774268.0000000006022000.00000004.00000800.00020000.00000000.sdmp, SecuriteInfo.com.Win32.PWSX-gen.27251.20675.exe, 00000000.00000003.249059141.0000000006028000.00000004.00000800.00020000.00000000.sdmpString found in binary or memory: http://www.jiyu-kobo.co.jp/
        Source: SecuriteInfo.com.Win32.PWSX-gen.27251.20675.exe, 00000000.00000003.249668471.0000000006022000.00000004.00000800.00020000.00000000.sdmp, SecuriteInfo.com.Win32.PWSX-gen.27251.20675.exe, 00000000.00000003.249560073.0000000006028000.00000004.00000800.00020000.00000000.sdmp, SecuriteInfo.com.Win32.PWSX-gen.27251.20675.exe, 00000000.00000003.248773244.0000000006015000.00000004.00000800.00020000.00000000.sdmp, SecuriteInfo.com.Win32.PWSX-gen.27251.20675.exe, 00000000.00000003.249774268.0000000006022000.00000004.00000800.00020000.00000000.sdmp, SecuriteInfo.com.Win32.PWSX-gen.27251.20675.exe, 00000000.00000003.249059141.0000000006028000.00000004.00000800.00020000.00000000.sdmpString found in binary or memory: http://www.jiyu-kobo.co.jp/#
        Source: SecuriteInfo.com.Win32.PWSX-gen.27251.20675.exe, 00000000.00000003.249059141.0000000006028000.00000004.00000800.00020000.00000000.sdmpString found in binary or memory: http://www.jiyu-kobo.co.jp/F
        Source: SecuriteInfo.com.Win32.PWSX-gen.27251.20675.exe, 00000000.00000003.249668471.0000000006022000.00000004.00000800.00020000.00000000.sdmp, SecuriteInfo.com.Win32.PWSX-gen.27251.20675.exe, 00000000.00000003.249560073.0000000006028000.00000004.00000800.00020000.00000000.sdmp, SecuriteInfo.com.Win32.PWSX-gen.27251.20675.exe, 00000000.00000003.249774268.0000000006022000.00000004.00000800.00020000.00000000.sdmp, SecuriteInfo.com.Win32.PWSX-gen.27251.20675.exe, 00000000.00000003.249059141.0000000006028000.00000004.00000800.00020000.00000000.sdmpString found in binary or memory: http://www.jiyu-kobo.co.jp/Kal1
        Source: SecuriteInfo.com.Win32.PWSX-gen.27251.20675.exe, 00000000.00000003.249668471.0000000006022000.00000004.00000800.00020000.00000000.sdmp, SecuriteInfo.com.Win32.PWSX-gen.27251.20675.exe, 00000000.00000003.249560073.0000000006028000.00000004.00000800.00020000.00000000.sdmpString found in binary or memory: http://www.jiyu-kobo.co.jp/M
        Source: SecuriteInfo.com.Win32.PWSX-gen.27251.20675.exe, 00000000.00000003.249668471.0000000006022000.00000004.00000800.00020000.00000000.sdmp, SecuriteInfo.com.Win32.PWSX-gen.27251.20675.exe, 00000000.00000003.249560073.0000000006028000.00000004.00000800.00020000.00000000.sdmp, SecuriteInfo.com.Win32.PWSX-gen.27251.20675.exe, 00000000.00000003.249774268.0000000006022000.00000004.00000800.00020000.00000000.sdmpString found in binary or memory: http://www.jiyu-kobo.co.jp/Y0/i
        Source: SecuriteInfo.com.Win32.PWSX-gen.27251.20675.exe, 00000000.00000003.249668471.0000000006022000.00000004.00000800.00020000.00000000.sdmp, SecuriteInfo.com.Win32.PWSX-gen.27251.20675.exe, 00000000.00000003.249560073.0000000006028000.00000004.00000800.00020000.00000000.sdmp, SecuriteInfo.com.Win32.PWSX-gen.27251.20675.exe, 00000000.00000003.249774268.0000000006022000.00000004.00000800.00020000.00000000.sdmp, SecuriteInfo.com.Win32.PWSX-gen.27251.20675.exe, 00000000.00000003.249059141.0000000006028000.00000004.00000800.00020000.00000000.sdmpString found in binary or memory: http://www.jiyu-kobo.co.jp/b
        Source: SecuriteInfo.com.Win32.PWSX-gen.27251.20675.exe, 00000000.00000003.249774268.0000000006022000.00000004.00000800.00020000.00000000.sdmp, SecuriteInfo.com.Win32.PWSX-gen.27251.20675.exe, 00000000.00000003.249059141.0000000006028000.00000004.00000800.00020000.00000000.sdmpString found in binary or memory: http://www.jiyu-kobo.co.jp/jp/
        Source: SecuriteInfo.com.Win32.PWSX-gen.27251.20675.exe, 00000000.00000003.249668471.0000000006022000.00000004.00000800.00020000.00000000.sdmp, SecuriteInfo.com.Win32.PWSX-gen.27251.20675.exe, 00000000.00000003.249774268.0000000006022000.00000004.00000800.00020000.00000000.sdmpString found in binary or memory: http://www.jiyu-kobo.co.jp/or1
        Source: SecuriteInfo.com.Win32.PWSX-gen.27251.20675.exe, 00000000.00000003.248773244.0000000006015000.00000004.00000800.00020000.00000000.sdmpString found in binary or memory: http://www.jiyu-kobo.co.jp/siv
        Source: SecuriteInfo.com.Win32.PWSX-gen.27251.20675.exe, 00000000.00000003.249668471.0000000006022000.00000004.00000800.00020000.00000000.sdmp, SecuriteInfo.com.Win32.PWSX-gen.27251.20675.exe, 00000000.00000003.249560073.0000000006028000.00000004.00000800.00020000.00000000.sdmp, SecuriteInfo.com.Win32.PWSX-gen.27251.20675.exe, 00000000.00000003.248773244.0000000006015000.00000004.00000800.00020000.00000000.sdmp, SecuriteInfo.com.Win32.PWSX-gen.27251.20675.exe, 00000000.00000003.249774268.0000000006022000.00000004.00000800.00020000.00000000.sdmp, SecuriteInfo.com.Win32.PWSX-gen.27251.20675.exe, 00000000.00000003.249059141.0000000006028000.00000004.00000800.00020000.00000000.sdmpString found in binary or memory: http://www.jiyu-kobo.co.jp/vno
        Source: SecuriteInfo.com.Win32.PWSX-gen.27251.20675.exe, 00000000.00000002.266638604.0000000006027000.00000004.00000800.00020000.00000000.sdmpString found in binary or memory: http://www.monotype.
        Source: SecuriteInfo.com.Win32.PWSX-gen.27251.20675.exe, 00000000.00000002.266762478.0000000007222000.00000004.00000800.00020000.00000000.sdmpString found in binary or memory: http://www.sajatypeworks.com
        Source: SecuriteInfo.com.Win32.PWSX-gen.27251.20675.exe, 00000000.00000002.266762478.0000000007222000.00000004.00000800.00020000.00000000.sdmpString found in binary or memory: http://www.sakkal.com
        Source: SecuriteInfo.com.Win32.PWSX-gen.27251.20675.exe, 00000000.00000002.266762478.0000000007222000.00000004.00000800.00020000.00000000.sdmpString found in binary or memory: http://www.sandoll.co.kr
        Source: SecuriteInfo.com.Win32.PWSX-gen.27251.20675.exe, 00000000.00000002.266762478.0000000007222000.00000004.00000800.00020000.00000000.sdmpString found in binary or memory: http://www.tiro.com
        Source: SecuriteInfo.com.Win32.PWSX-gen.27251.20675.exe, 00000000.00000002.266762478.0000000007222000.00000004.00000800.00020000.00000000.sdmpString found in binary or memory: http://www.typography.netD
        Source: SecuriteInfo.com.Win32.PWSX-gen.27251.20675.exe, 00000000.00000002.266762478.0000000007222000.00000004.00000800.00020000.00000000.sdmpString found in binary or memory: http://www.urwpp.deDPlease
        Source: SecuriteInfo.com.Win32.PWSX-gen.27251.20675.exe, 00000000.00000002.266762478.0000000007222000.00000004.00000800.00020000.00000000.sdmpString found in binary or memory: http://www.zhongyicts.com.cn

        E-Banking Fraud

        barindex
        Source: Yara matchFile source: 1.0.SecuriteInfo.com.Win32.PWSX-gen.27251.20675.exe.400000.0.unpack, type: UNPACKEDPE
        Source: Yara matchFile source: 00000000.00000002.265052163.0000000004196000.00000004.00000800.00020000.00000000.sdmp, type: MEMORY
        Source: Yara matchFile source: 00000001.00000000.257340997.0000000000401000.00000040.00000400.00020000.00000000.sdmp, type: MEMORY

        System Summary

        barindex
        Source: 1.0.SecuriteInfo.com.Win32.PWSX-gen.27251.20675.exe.400000.0.unpack, type: UNPACKEDPEMatched rule: Windows_Trojan_Formbook_1112e116 Author: unknown
        Source: 1.0.SecuriteInfo.com.Win32.PWSX-gen.27251.20675.exe.400000.0.unpack, type: UNPACKEDPEMatched rule: autogenerated rule brought to you by yara-signator Author: Felix Bilstein - yara-signator at cocacoding dot com
        Source: 1.0.SecuriteInfo.com.Win32.PWSX-gen.27251.20675.exe.400000.0.unpack, type: UNPACKEDPEMatched rule: detect Formbook in memory Author: JPCERT/CC Incident Response Group
        Source: 00000000.00000002.265052163.0000000004196000.00000004.00000800.00020000.00000000.sdmp, type: MEMORYMatched rule: Windows_Trojan_Formbook_1112e116 Author: unknown
        Source: 00000000.00000002.265052163.0000000004196000.00000004.00000800.00020000.00000000.sdmp, type: MEMORYMatched rule: autogenerated rule brought to you by yara-signator Author: Felix Bilstein - yara-signator at cocacoding dot com
        Source: 00000000.00000002.265052163.0000000004196000.00000004.00000800.00020000.00000000.sdmp, type: MEMORYMatched rule: detect Formbook in memory Author: JPCERT/CC Incident Response Group
        Source: 00000001.00000000.257340997.0000000000401000.00000040.00000400.00020000.00000000.sdmp, type: MEMORYMatched rule: Windows_Trojan_Formbook_1112e116 Author: unknown
        Source: 00000001.00000000.257340997.0000000000401000.00000040.00000400.00020000.00000000.sdmp, type: MEMORYMatched rule: autogenerated rule brought to you by yara-signator Author: Felix Bilstein - yara-signator at cocacoding dot com
        Source: 00000001.00000000.257340997.0000000000401000.00000040.00000400.00020000.00000000.sdmp, type: MEMORYMatched rule: detect Formbook in memory Author: JPCERT/CC Incident Response Group
        Source: Process Memory Space: SecuriteInfo.com.Win32.PWSX-gen.27251.20675.exe PID: 5448, type: MEMORYSTRMatched rule: Windows_Trojan_Formbook_1112e116 Author: unknown
        Source: Process Memory Space: SecuriteInfo.com.Win32.PWSX-gen.27251.20675.exe PID: 5572, type: MEMORYSTRMatched rule: Windows_Trojan_Formbook_1112e116 Author: unknown
        Source: SecuriteInfo.com.Win32.PWSX-gen.27251.20675.exeStatic PE information: EXECUTABLE_IMAGE, 32BIT_MACHINE
        Source: 1.0.SecuriteInfo.com.Win32.PWSX-gen.27251.20675.exe.400000.0.unpack, type: UNPACKEDPEMatched rule: Windows_Trojan_Formbook_1112e116 reference_sample = 6246f3b89f0e4913abd88ae535ae3597865270f58201dc7f8ec0c87f15ff370a, os = windows, severity = x86, creation_date = 2021-06-14, scan_context = file, memory, license = Elastic License v2, threat_name = Windows.Trojan.Formbook, fingerprint = b8b88451ad8c66b54e21455d835a5d435e52173c86e9b813ffab09451aff7134, id = 1112e116-dee0-4818-a41f-ca5c1c41b4b8, last_modified = 2021-08-23
        Source: 1.0.SecuriteInfo.com.Win32.PWSX-gen.27251.20675.exe.400000.0.unpack, type: UNPACKEDPEMatched rule: Formbook_1 date = 2018-11-23, author = Felix Bilstein - yara-signator at cocacoding dot com, malpedia_version = 20180607, description = autogenerated rule brought to you by yara-signator, malpedia_reference = https://malpedia.caad.fkie.fraunhofer.de/details/win.formbook, cape_type = Formbook Payload, malpedia_license = CC BY-NC-SA 4.0, version = 1, tool = yara-signator 0.1a, malpedia_sharing = TLP:WHITE
        Source: 1.0.SecuriteInfo.com.Win32.PWSX-gen.27251.20675.exe.400000.0.unpack, type: UNPACKEDPEMatched rule: Formbook author = JPCERT/CC Incident Response Group, description = detect Formbook in memory, rule_usage = memory scan, reference = internal research
        Source: 00000000.00000002.265052163.0000000004196000.00000004.00000800.00020000.00000000.sdmp, type: MEMORYMatched rule: Windows_Trojan_Formbook_1112e116 reference_sample = 6246f3b89f0e4913abd88ae535ae3597865270f58201dc7f8ec0c87f15ff370a, os = windows, severity = x86, creation_date = 2021-06-14, scan_context = file, memory, license = Elastic License v2, threat_name = Windows.Trojan.Formbook, fingerprint = b8b88451ad8c66b54e21455d835a5d435e52173c86e9b813ffab09451aff7134, id = 1112e116-dee0-4818-a41f-ca5c1c41b4b8, last_modified = 2021-08-23
        Source: 00000000.00000002.265052163.0000000004196000.00000004.00000800.00020000.00000000.sdmp, type: MEMORYMatched rule: Formbook_1 date = 2018-11-23, author = Felix Bilstein - yara-signator at cocacoding dot com, malpedia_version = 20180607, description = autogenerated rule brought to you by yara-signator, malpedia_reference = https://malpedia.caad.fkie.fraunhofer.de/details/win.formbook, cape_type = Formbook Payload, malpedia_license = CC BY-NC-SA 4.0, version = 1, tool = yara-signator 0.1a, malpedia_sharing = TLP:WHITE
        Source: 00000000.00000002.265052163.0000000004196000.00000004.00000800.00020000.00000000.sdmp, type: MEMORYMatched rule: Formbook author = JPCERT/CC Incident Response Group, description = detect Formbook in memory, rule_usage = memory scan, reference = internal research
        Source: 00000001.00000000.257340997.0000000000401000.00000040.00000400.00020000.00000000.sdmp, type: MEMORYMatched rule: Windows_Trojan_Formbook_1112e116 reference_sample = 6246f3b89f0e4913abd88ae535ae3597865270f58201dc7f8ec0c87f15ff370a, os = windows, severity = x86, creation_date = 2021-06-14, scan_context = file, memory, license = Elastic License v2, threat_name = Windows.Trojan.Formbook, fingerprint = b8b88451ad8c66b54e21455d835a5d435e52173c86e9b813ffab09451aff7134, id = 1112e116-dee0-4818-a41f-ca5c1c41b4b8, last_modified = 2021-08-23
        Source: 00000001.00000000.257340997.0000000000401000.00000040.00000400.00020000.00000000.sdmp, type: MEMORYMatched rule: Formbook_1 date = 2018-11-23, author = Felix Bilstein - yara-signator at cocacoding dot com, malpedia_version = 20180607, description = autogenerated rule brought to you by yara-signator, malpedia_reference = https://malpedia.caad.fkie.fraunhofer.de/details/win.formbook, cape_type = Formbook Payload, malpedia_license = CC BY-NC-SA 4.0, version = 1, tool = yara-signator 0.1a, malpedia_sharing = TLP:WHITE
        Source: 00000001.00000000.257340997.0000000000401000.00000040.00000400.00020000.00000000.sdmp, type: MEMORYMatched rule: Formbook author = JPCERT/CC Incident Response Group, description = detect Formbook in memory, rule_usage = memory scan, reference = internal research
        Source: Process Memory Space: SecuriteInfo.com.Win32.PWSX-gen.27251.20675.exe PID: 5448, type: MEMORYSTRMatched rule: Windows_Trojan_Formbook_1112e116 reference_sample = 6246f3b89f0e4913abd88ae535ae3597865270f58201dc7f8ec0c87f15ff370a, os = windows, severity = x86, creation_date = 2021-06-14, scan_context = file, memory, license = Elastic License v2, threat_name = Windows.Trojan.Formbook, fingerprint = b8b88451ad8c66b54e21455d835a5d435e52173c86e9b813ffab09451aff7134, id = 1112e116-dee0-4818-a41f-ca5c1c41b4b8, last_modified = 2021-08-23
        Source: Process Memory Space: SecuriteInfo.com.Win32.PWSX-gen.27251.20675.exe PID: 5572, type: MEMORYSTRMatched rule: Windows_Trojan_Formbook_1112e116 reference_sample = 6246f3b89f0e4913abd88ae535ae3597865270f58201dc7f8ec0c87f15ff370a, os = windows, severity = x86, creation_date = 2021-06-14, scan_context = file, memory, license = Elastic License v2, threat_name = Windows.Trojan.Formbook, fingerprint = b8b88451ad8c66b54e21455d835a5d435e52173c86e9b813ffab09451aff7134, id = 1112e116-dee0-4818-a41f-ca5c1c41b4b8, last_modified = 2021-08-23
        Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.PWSX-gen.27251.20675.exeCode function: 0_2_015FC334
        Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.PWSX-gen.27251.20675.exeCode function: 0_2_015FE790
        Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.PWSX-gen.27251.20675.exeCode function: 0_2_015FE78A
        Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.PWSX-gen.27251.20675.exeCode function: 1_2_0102F900
        Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.PWSX-gen.27251.20675.exeCode function: 1_2_01044120
        Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.PWSX-gen.27251.20675.exeCode function: 1_2_01042990
        Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.PWSX-gen.27251.20675.exeCode function: 1_2_010499BF
        Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.PWSX-gen.27251.20675.exeCode function: 1_2_0103C1C0
        Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.PWSX-gen.27251.20675.exeCode function: 1_2_01026800
        Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.PWSX-gen.27251.20675.exeCode function: 1_2_010E1002
        Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.PWSX-gen.27251.20675.exeCode function: 1_2_0105701D
        Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.PWSX-gen.27251.20675.exeCode function: 1_2_010FE824
        Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.PWSX-gen.27251.20675.exeCode function: 1_2_0104A830
        Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.PWSX-gen.27251.20675.exeCode function: 1_2_0103B090
        Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.PWSX-gen.27251.20675.exeCode function: 1_2_010520A0
        Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.PWSX-gen.27251.20675.exeCode function: 1_2_010F20A8
        Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.PWSX-gen.27251.20675.exeCode function: 1_2_010F28EC
        Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.PWSX-gen.27251.20675.exeCode function: 1_2_010E60F5
        Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.PWSX-gen.27251.20675.exeCode function: 1_2_0104A309
        Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.PWSX-gen.27251.20675.exeCode function: 1_2_010E231B
        Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.PWSX-gen.27251.20675.exeCode function: 1_2_010F2B28
        Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.PWSX-gen.27251.20675.exeCode function: 1_2_010CCB4F
        Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.PWSX-gen.27251.20675.exeCode function: 1_2_0104AB40
        Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.PWSX-gen.27251.20675.exeCode function: 1_2_01043360
        Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.PWSX-gen.27251.20675.exeCode function: 1_2_010CEB8A
        Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.PWSX-gen.27251.20675.exeCode function: 1_2_0105138B
        Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.PWSX-gen.27251.20675.exeCode function: 1_2_0104EB9A
        Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.PWSX-gen.27251.20675.exeCode function: 1_2_0105EBB0
        Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.PWSX-gen.27251.20675.exeCode function: 1_2_010E03DA
        Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.PWSX-gen.27251.20675.exeCode function: 1_2_010EDBD2
        Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.PWSX-gen.27251.20675.exeCode function: 1_2_0105ABD8
        Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.PWSX-gen.27251.20675.exeCode function: 1_2_010D23E3
        Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.PWSX-gen.27251.20675.exeCode function: 1_2_01078BE8
        Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.PWSX-gen.27251.20675.exeCode function: 1_2_010DFA2B
        Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.PWSX-gen.27251.20675.exeCode function: 1_2_0104B236
        Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.PWSX-gen.27251.20675.exeCode function: 1_2_010E5A4F
        Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.PWSX-gen.27251.20675.exeCode function: 1_2_010F22AE
        Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.PWSX-gen.27251.20675.exeCode function: 1_2_010F32A9
        Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.PWSX-gen.27251.20675.exeCode function: 1_2_010EE2C5
        Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.PWSX-gen.27251.20675.exeCode function: 1_2_010E4AEF
        Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.PWSX-gen.27251.20675.exeCode function: 1_2_010F2D07
        Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.PWSX-gen.27251.20675.exeCode function: 1_2_01020D20
        Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.PWSX-gen.27251.20675.exeCode function: 1_2_01042D50
        Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.PWSX-gen.27251.20675.exeCode function: 1_2_010F1D55
        Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.PWSX-gen.27251.20675.exeCode function: 1_2_01052581
        Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.PWSX-gen.27251.20675.exeCode function: 1_2_010E2D82
        Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.PWSX-gen.27251.20675.exeCode function: 1_2_010565A0
        Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.PWSX-gen.27251.20675.exeCode function: 1_2_010F25DD
        Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.PWSX-gen.27251.20675.exeCode function: 1_2_0103D5E0
        Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.PWSX-gen.27251.20675.exeCode function: 1_2_0103841F
        Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.PWSX-gen.27251.20675.exeCode function: 1_2_01042430
        Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.PWSX-gen.27251.20675.exeCode function: 1_2_010ED466
        Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.PWSX-gen.27251.20675.exeCode function: 1_2_0104B477
        Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.PWSX-gen.27251.20675.exeCode function: 1_2_010ECC77
        Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.PWSX-gen.27251.20675.exeCode function: 1_2_010E4496
        Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.PWSX-gen.27251.20675.exeCode function: 1_2_01054CD4
        Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.PWSX-gen.27251.20675.exeCode function: 1_2_010FDFCE
        Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.PWSX-gen.27251.20675.exeCode function: 1_2_010E67E2
        Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.PWSX-gen.27251.20675.exeCode function: 1_2_010F1FF1
        Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.PWSX-gen.27251.20675.exeCode function: 1_2_01045600
        Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.PWSX-gen.27251.20675.exeCode function: 1_2_010ED616
        Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.PWSX-gen.27251.20675.exeCode function: 1_2_01046E30
        Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.PWSX-gen.27251.20675.exeCode function: 1_2_010AAE60
        Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.PWSX-gen.27251.20675.exeCode function: 1_2_010D1EB6
        Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.PWSX-gen.27251.20675.exeCode function: 1_2_010506C0
        Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.PWSX-gen.27251.20675.exeCode function: 1_2_010F2EF7
        Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.PWSX-gen.27251.20675.exeCode function: String function: 0102B150 appears 177 times
        Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.PWSX-gen.27251.20675.exeCode function: String function: 010B5720 appears 85 times
        Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.PWSX-gen.27251.20675.exeCode function: String function: 0107D08C appears 48 times
        Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.PWSX-gen.27251.20675.exeCode function: 1_2_01069860 NtQuerySystemInformation,LdrInitializeThunk,
        Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.PWSX-gen.27251.20675.exeCode function: 1_2_01069660 NtAllocateVirtualMemory,LdrInitializeThunk,
        Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.PWSX-gen.27251.20675.exeCode function: 1_2_010696E0 NtFreeVirtualMemory,LdrInitializeThunk,
        Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.PWSX-gen.27251.20675.exeCode function: 1_2_01069910 NtAdjustPrivilegesToken,
        Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.PWSX-gen.27251.20675.exeCode function: 1_2_01069950 NtQueueApcThread,
        Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.PWSX-gen.27251.20675.exeCode function: 1_2_010699A0 NtCreateSection,
        Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.PWSX-gen.27251.20675.exeCode function: 1_2_010699D0 NtCreateProcessEx,
        Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.PWSX-gen.27251.20675.exeCode function: 1_2_01069820 NtEnumerateKey,
        Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.PWSX-gen.27251.20675.exeCode function: 1_2_01069840 NtDelayExecution,
        Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.PWSX-gen.27251.20675.exeCode function: 1_2_0106B040 NtSuspendThread,
        Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.PWSX-gen.27251.20675.exeCode function: 1_2_010698A0 NtWriteVirtualMemory,
        Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.PWSX-gen.27251.20675.exeCode function: 1_2_010698F0 NtReadVirtualMemory,
        Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.PWSX-gen.27251.20675.exeCode function: 1_2_01069B00 NtSetValueKey,
        Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.PWSX-gen.27251.20675.exeCode function: 1_2_0106A3B0 NtGetContextThread,
        Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.PWSX-gen.27251.20675.exeCode function: 1_2_01069A00 NtProtectVirtualMemory,
        Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.PWSX-gen.27251.20675.exeCode function: 1_2_01069A10 NtQuerySection,
        Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.PWSX-gen.27251.20675.exeCode function: 1_2_01069A20 NtResumeThread,
        Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.PWSX-gen.27251.20675.exeCode function: 1_2_01069A50 NtCreateFile,
        Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.PWSX-gen.27251.20675.exeCode function: 1_2_01069A80 NtOpenDirectoryObject,
        Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.PWSX-gen.27251.20675.exeCode function: 1_2_01069520 NtWaitForSingleObject,
        Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.PWSX-gen.27251.20675.exeCode function: 1_2_0106AD30 NtSetContextThread,
        Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.PWSX-gen.27251.20675.exeCode function: 1_2_01069540 NtReadFile,
        Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.PWSX-gen.27251.20675.exeCode function: 1_2_01069560 NtWriteFile,
        Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.PWSX-gen.27251.20675.exeCode function: 1_2_010695D0 NtClose,
        Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.PWSX-gen.27251.20675.exeCode function: 1_2_010695F0 NtQueryInformationFile,
        Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.PWSX-gen.27251.20675.exeCode function: 1_2_0106A710 NtOpenProcessToken,
        Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.PWSX-gen.27251.20675.exeCode function: 1_2_01069710 NtQueryInformationToken,
        Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.PWSX-gen.27251.20675.exeCode function: 1_2_01069730 NtQueryVirtualMemory,
        Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.PWSX-gen.27251.20675.exeCode function: 1_2_01069760 NtOpenProcess,
        Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.PWSX-gen.27251.20675.exeCode function: 1_2_0106A770 NtOpenThread,
        Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.PWSX-gen.27251.20675.exeCode function: 1_2_01069770 NtSetInformationFile,
        Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.PWSX-gen.27251.20675.exeCode function: 1_2_01069780 NtMapViewOfSection,
        Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.PWSX-gen.27251.20675.exeCode function: 1_2_010697A0 NtUnmapViewOfSection,
        Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.PWSX-gen.27251.20675.exeCode function: 1_2_01069FE0 NtCreateMutant,
        Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.PWSX-gen.27251.20675.exeCode function: 1_2_01069610 NtEnumerateValueKey,
        Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.PWSX-gen.27251.20675.exeCode function: 1_2_01069650 NtQueryValueKey,
        Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.PWSX-gen.27251.20675.exeCode function: 1_2_01069670 NtQueryInformationProcess,
        Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.PWSX-gen.27251.20675.exeCode function: 1_2_010696D0 NtCreateKey,
        Source: SecuriteInfo.com.Win32.PWSX-gen.27251.20675.exe, 00000000.00000002.267730037.00000000078D0000.00000004.08000000.00040000.00000000.sdmpBinary or memory string: OriginalFilenameCollins.dll8 vs SecuriteInfo.com.Win32.PWSX-gen.27251.20675.exe
        Source: SecuriteInfo.com.Win32.PWSX-gen.27251.20675.exe, 00000000.00000002.260335497.0000000003001000.00000004.00000800.00020000.00000000.sdmpBinary or memory string: OriginalFilenamePrecision.dll6 vs SecuriteInfo.com.Win32.PWSX-gen.27251.20675.exe
        Source: SecuriteInfo.com.Win32.PWSX-gen.27251.20675.exe, 00000000.00000002.260335497.0000000003001000.00000004.00000800.00020000.00000000.sdmpBinary or memory string: OriginalFilenameInspector.dllN vs SecuriteInfo.com.Win32.PWSX-gen.27251.20675.exe
        Source: SecuriteInfo.com.Win32.PWSX-gen.27251.20675.exe, 00000001.00000002.264250960.000000000111F000.00000040.00000800.00020000.00000000.sdmpBinary or memory string: OriginalFilenamentdll.dllj% vs SecuriteInfo.com.Win32.PWSX-gen.27251.20675.exe
        Source: SecuriteInfo.com.Win32.PWSX-gen.27251.20675.exe, 00000001.00000003.261495799.0000000000F7E000.00000004.00000800.00020000.00000000.sdmpBinary or memory string: OriginalFilenamentdll.dllj% vs SecuriteInfo.com.Win32.PWSX-gen.27251.20675.exe
        Source: SecuriteInfo.com.Win32.PWSX-gen.27251.20675.exe, 00000001.00000003.259043934.0000000000DD5000.00000004.00000800.00020000.00000000.sdmpBinary or memory string: OriginalFilenamentdll.dllj% vs SecuriteInfo.com.Win32.PWSX-gen.27251.20675.exe
        Source: SecuriteInfo.com.Win32.PWSX-gen.27251.20675.exeBinary or memory string: OriginalFilenamefzynaa.exe< vs SecuriteInfo.com.Win32.PWSX-gen.27251.20675.exe
        Source: SecuriteInfo.com.Win32.PWSX-gen.27251.20675.exeStatic PE information: Section: .text IMAGE_SCN_CNT_CODE, IMAGE_SCN_MEM_EXECUTE, IMAGE_SCN_MEM_READ
        Source: SecuriteInfo.com.Win32.PWSX-gen.27251.20675.exeReversingLabs: Detection: 41%
        Source: SecuriteInfo.com.Win32.PWSX-gen.27251.20675.exeVirustotal: Detection: 45%
        Source: SecuriteInfo.com.Win32.PWSX-gen.27251.20675.exeStatic PE information: Section: .text IMAGE_SCN_CNT_CODE, IMAGE_SCN_MEM_EXECUTE, IMAGE_SCN_MEM_READ
        Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.PWSX-gen.27251.20675.exeKey opened: HKEY_CURRENT_USER\Software\Policies\Microsoft\Windows\Safer\CodeIdentifiers
        Source: unknownProcess created: C:\Users\user\Desktop\SecuriteInfo.com.Win32.PWSX-gen.27251.20675.exe C:\Users\user\Desktop\SecuriteInfo.com.Win32.PWSX-gen.27251.20675.exe
        Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.PWSX-gen.27251.20675.exeProcess created: C:\Users\user\Desktop\SecuriteInfo.com.Win32.PWSX-gen.27251.20675.exe C:\Users\user\Desktop\SecuriteInfo.com.Win32.PWSX-gen.27251.20675.exe
        Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.PWSX-gen.27251.20675.exeProcess created: C:\Users\user\Desktop\SecuriteInfo.com.Win32.PWSX-gen.27251.20675.exe C:\Users\user\Desktop\SecuriteInfo.com.Win32.PWSX-gen.27251.20675.exe
        Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.PWSX-gen.27251.20675.exeFile created: C:\Users\user\AppData\Local\Microsoft\CLR_v4.0_32\UsageLogs\SecuriteInfo.com.Win32.PWSX-gen.27251.20675.exe.logJump to behavior
        Source: classification engineClassification label: mal92.troj.evad.winEXE@3/1@0/0
        Source: SecuriteInfo.com.Win32.PWSX-gen.27251.20675.exeStatic file information: TRID: Win32 Executable (generic) Net Framework (10011505/4) 49.80%
        Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.PWSX-gen.27251.20675.exeSection loaded: C:\Windows\assembly\NativeImages_v4.0.30319_32\mscorlib\a152fe02a317a77aeee36903305e8ba6\mscorlib.ni.dll
        Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.PWSX-gen.27251.20675.exeMutant created: \Sessions\1\BaseNamedObjects\wGtrYQj
        Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.PWSX-gen.27251.20675.exeFile opened: C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscorrc.dll
        Source: SecuriteInfo.com.Win32.PWSX-gen.27251.20675.exeStatic PE information: data directory type: IMAGE_DIRECTORY_ENTRY_COM_DESCRIPTOR
        Source: SecuriteInfo.com.Win32.PWSX-gen.27251.20675.exeStatic PE information: DYNAMIC_BASE, NX_COMPAT, NO_SEH, TERMINAL_SERVER_AWARE
        Source: SecuriteInfo.com.Win32.PWSX-gen.27251.20675.exeStatic PE information: data directory type: IMAGE_DIRECTORY_ENTRY_DEBUG
        Source: Binary string: wntdll.pdbUGP source: SecuriteInfo.com.Win32.PWSX-gen.27251.20675.exe, 00000001.00000003.257989308.0000000000CBF000.00000004.00000800.00020000.00000000.sdmp, SecuriteInfo.com.Win32.PWSX-gen.27251.20675.exe, 00000001.00000003.260648591.0000000000E5F000.00000004.00000800.00020000.00000000.sdmp, SecuriteInfo.com.Win32.PWSX-gen.27251.20675.exe, 00000001.00000002.262649793.0000000001000000.00000040.00000800.00020000.00000000.sdmp
        Source: Binary string: wntdll.pdb source: SecuriteInfo.com.Win32.PWSX-gen.27251.20675.exe, SecuriteInfo.com.Win32.PWSX-gen.27251.20675.exe, 00000001.00000003.257989308.0000000000CBF000.00000004.00000800.00020000.00000000.sdmp, SecuriteInfo.com.Win32.PWSX-gen.27251.20675.exe, 00000001.00000003.260648591.0000000000E5F000.00000004.00000800.00020000.00000000.sdmp, SecuriteInfo.com.Win32.PWSX-gen.27251.20675.exe, 00000001.00000002.262649793.0000000001000000.00000040.00000800.00020000.00000000.sdmp
        Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.PWSX-gen.27251.20675.exeCode function: 1_2_0107D0D1 push ecx; ret
        Source: SecuriteInfo.com.Win32.PWSX-gen.27251.20675.exeStatic PE information: 0xBF0A3116 [Sun Jul 26 06:03:02 2071 UTC]
        Source: initial sampleStatic PE information: section name: .text entropy: 7.830178117653337
        Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.PWSX-gen.27251.20675.exeProcess information set: NOOPENFILEERRORBOX
        Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.PWSX-gen.27251.20675.exeProcess information set: NOOPENFILEERRORBOX
        Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.PWSX-gen.27251.20675.exeProcess information set: NOOPENFILEERRORBOX
        Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.PWSX-gen.27251.20675.exeProcess information set: NOOPENFILEERRORBOX
        Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.PWSX-gen.27251.20675.exeProcess information set: NOOPENFILEERRORBOX
        Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.PWSX-gen.27251.20675.exeProcess information set: NOOPENFILEERRORBOX
        Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.PWSX-gen.27251.20675.exeProcess information set: NOOPENFILEERRORBOX
        Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.PWSX-gen.27251.20675.exeProcess information set: NOOPENFILEERRORBOX
        Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.PWSX-gen.27251.20675.exeProcess information set: NOOPENFILEERRORBOX
        Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.PWSX-gen.27251.20675.exeProcess information set: NOOPENFILEERRORBOX
        Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.PWSX-gen.27251.20675.exeProcess information set: NOOPENFILEERRORBOX
        Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.PWSX-gen.27251.20675.exeProcess information set: NOOPENFILEERRORBOX
        Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.PWSX-gen.27251.20675.exeProcess information set: NOOPENFILEERRORBOX
        Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.PWSX-gen.27251.20675.exeProcess information set: NOOPENFILEERRORBOX
        Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.PWSX-gen.27251.20675.exeProcess information set: NOOPENFILEERRORBOX
        Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.PWSX-gen.27251.20675.exeProcess information set: NOOPENFILEERRORBOX
        Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.PWSX-gen.27251.20675.exeProcess information set: NOOPENFILEERRORBOX
        Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.PWSX-gen.27251.20675.exeProcess information set: NOOPENFILEERRORBOX
        Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.PWSX-gen.27251.20675.exeProcess information set: NOOPENFILEERRORBOX
        Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.PWSX-gen.27251.20675.exeProcess information set: NOOPENFILEERRORBOX
        Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.PWSX-gen.27251.20675.exeProcess information set: NOOPENFILEERRORBOX
        Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.PWSX-gen.27251.20675.exeProcess information set: NOOPENFILEERRORBOX
        Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.PWSX-gen.27251.20675.exeProcess information set: NOOPENFILEERRORBOX
        Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.PWSX-gen.27251.20675.exeProcess information set: NOOPENFILEERRORBOX
        Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.PWSX-gen.27251.20675.exeProcess information set: NOOPENFILEERRORBOX
        Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.PWSX-gen.27251.20675.exeProcess information set: NOOPENFILEERRORBOX
        Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.PWSX-gen.27251.20675.exeProcess information set: NOOPENFILEERRORBOX
        Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.PWSX-gen.27251.20675.exeProcess information set: NOOPENFILEERRORBOX
        Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.PWSX-gen.27251.20675.exeProcess information set: NOOPENFILEERRORBOX
        Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.PWSX-gen.27251.20675.exeProcess information set: NOOPENFILEERRORBOX
        Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.PWSX-gen.27251.20675.exeProcess information set: NOOPENFILEERRORBOX
        Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.PWSX-gen.27251.20675.exeProcess information set: NOOPENFILEERRORBOX
        Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.PWSX-gen.27251.20675.exeProcess information set: NOOPENFILEERRORBOX
        Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.PWSX-gen.27251.20675.exeProcess information set: NOOPENFILEERRORBOX
        Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.PWSX-gen.27251.20675.exeProcess information set: NOOPENFILEERRORBOX
        Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.PWSX-gen.27251.20675.exeProcess information set: NOOPENFILEERRORBOX
        Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.PWSX-gen.27251.20675.exeProcess information set: NOOPENFILEERRORBOX
        Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.PWSX-gen.27251.20675.exeProcess information set: NOOPENFILEERRORBOX

        Malware Analysis System Evasion

        barindex
        Source: Yara matchFile source: 00000000.00000002.260745770.0000000003051000.00000004.00000800.00020000.00000000.sdmp, type: MEMORY
        Source: Yara matchFile source: Process Memory Space: SecuriteInfo.com.Win32.PWSX-gen.27251.20675.exe PID: 5448, type: MEMORYSTR
        Source: SecuriteInfo.com.Win32.PWSX-gen.27251.20675.exe, 00000000.00000002.260745770.0000000003051000.00000004.00000800.00020000.00000000.sdmpBinary or memory string: SBIEDLL.DLL
        Source: SecuriteInfo.com.Win32.PWSX-gen.27251.20675.exe, 00000000.00000002.260745770.0000000003051000.00000004.00000800.00020000.00000000.sdmpBinary or memory string: KERNEL32.DLL.WINE_GET_UNIX_FILE_NAME
        Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.PWSX-gen.27251.20675.exeRDTSC instruction interceptor: First address: 0000000000409904 second address: 000000000040990A instructions: 0x00000000 rdtsc 0x00000002 xor ecx, ecx 0x00000004 add ecx, eax 0x00000006 rdtsc
        Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.PWSX-gen.27251.20675.exeRDTSC instruction interceptor: First address: 0000000000409B7E second address: 0000000000409B84 instructions: 0x00000000 rdtsc 0x00000002 xor ecx, ecx 0x00000004 add ecx, eax 0x00000006 rdtsc
        Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.PWSX-gen.27251.20675.exe TID: 5464Thread sleep time: -38122s >= -30000s
        Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.PWSX-gen.27251.20675.exe TID: 5468Thread sleep time: -922337203685477s >= -30000s
        Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.PWSX-gen.27251.20675.exe TID: 5576Thread sleep time: -922337203685477s >= -30000s
        Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.PWSX-gen.27251.20675.exeCode function: 1_2_01056B90 rdtsc
        Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.PWSX-gen.27251.20675.exeThread delayed: delay time: 922337203685477
        Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.PWSX-gen.27251.20675.exeThread delayed: delay time: 922337203685477
        Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.PWSX-gen.27251.20675.exeAPI coverage: 0.5 %
        Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.PWSX-gen.27251.20675.exeProcess information queried: ProcessInformation
        Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.PWSX-gen.27251.20675.exeThread delayed: delay time: 38122
        Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.PWSX-gen.27251.20675.exeThread delayed: delay time: 922337203685477
        Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.PWSX-gen.27251.20675.exeThread delayed: delay time: 922337203685477
        Source: SecuriteInfo.com.Win32.PWSX-gen.27251.20675.exe, 00000000.00000002.260745770.0000000003051000.00000004.00000800.00020000.00000000.sdmpBinary or memory string: InstallPathJC:\PROGRAM FILES\VMWARE\VMWARE TOOLS\
        Source: SecuriteInfo.com.Win32.PWSX-gen.27251.20675.exe, 00000000.00000002.260745770.0000000003051000.00000004.00000800.00020000.00000000.sdmpBinary or memory string: vmware
        Source: SecuriteInfo.com.Win32.PWSX-gen.27251.20675.exe, 00000000.00000002.260745770.0000000003051000.00000004.00000800.00020000.00000000.sdmpBinary or memory string: VMware SVGA II
        Source: SecuriteInfo.com.Win32.PWSX-gen.27251.20675.exe, 00000000.00000002.260745770.0000000003051000.00000004.00000800.00020000.00000000.sdmpBinary or memory string: VMWAREDSOFTWARE\VMware, Inc.\VMware Tools
        Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.PWSX-gen.27251.20675.exeCode function: 1_2_01056B90 rdtsc
        Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.PWSX-gen.27251.20675.exeProcess token adjusted: Debug
        Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.PWSX-gen.27251.20675.exeCode function: 1_2_01029100 mov eax, dword ptr fs:[00000030h]
        Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.PWSX-gen.27251.20675.exeCode function: 1_2_01029100 mov eax, dword ptr fs:[00000030h]
        Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.PWSX-gen.27251.20675.exeCode function: 1_2_01029100 mov eax, dword ptr fs:[00000030h]
        Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.PWSX-gen.27251.20675.exeCode function: 1_2_01030100 mov eax, dword ptr fs:[00000030h]
        Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.PWSX-gen.27251.20675.exeCode function: 1_2_01030100 mov eax, dword ptr fs:[00000030h]
        Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.PWSX-gen.27251.20675.exeCode function: 1_2_01030100 mov eax, dword ptr fs:[00000030h]
        Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.PWSX-gen.27251.20675.exeCode function: 1_2_01044120 mov eax, dword ptr fs:[00000030h]
        Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.PWSX-gen.27251.20675.exeCode function: 1_2_01044120 mov eax, dword ptr fs:[00000030h]
        Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.PWSX-gen.27251.20675.exeCode function: 1_2_01044120 mov eax, dword ptr fs:[00000030h]
        Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.PWSX-gen.27251.20675.exeCode function: 1_2_01044120 mov eax, dword ptr fs:[00000030h]
        Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.PWSX-gen.27251.20675.exeCode function: 1_2_01044120 mov ecx, dword ptr fs:[00000030h]
        Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.PWSX-gen.27251.20675.exeCode function: 1_2_01023138 mov ecx, dword ptr fs:[00000030h]
        Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.PWSX-gen.27251.20675.exeCode function: 1_2_0105513A mov eax, dword ptr fs:[00000030h]
        Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.PWSX-gen.27251.20675.exeCode function: 1_2_0105513A mov eax, dword ptr fs:[00000030h]
        Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.PWSX-gen.27251.20675.exeCode function: 1_2_0104B944 mov eax, dword ptr fs:[00000030h]
        Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.PWSX-gen.27251.20675.exeCode function: 1_2_0104B944 mov eax, dword ptr fs:[00000030h]
        Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.PWSX-gen.27251.20675.exeCode function: 1_2_0102395E mov eax, dword ptr fs:[00000030h]
        Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.PWSX-gen.27251.20675.exeCode function: 1_2_0102395E mov eax, dword ptr fs:[00000030h]
        Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.PWSX-gen.27251.20675.exeCode function: 1_2_010E1951 mov eax, dword ptr fs:[00000030h]
        Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.PWSX-gen.27251.20675.exeCode function: 1_2_0102C962 mov eax, dword ptr fs:[00000030h]
        Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.PWSX-gen.27251.20675.exeCode function: 1_2_010F8966 mov eax, dword ptr fs:[00000030h]
        Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.PWSX-gen.27251.20675.exeCode function: 1_2_010EE962 mov eax, dword ptr fs:[00000030h]
        Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.PWSX-gen.27251.20675.exeCode function: 1_2_0102B171 mov eax, dword ptr fs:[00000030h]
        Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.PWSX-gen.27251.20675.exeCode function: 1_2_0102B171 mov eax, dword ptr fs:[00000030h]
        Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.PWSX-gen.27251.20675.exeCode function: 1_2_0105A185 mov eax, dword ptr fs:[00000030h]
        Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.PWSX-gen.27251.20675.exeCode function: 1_2_0104C182 mov eax, dword ptr fs:[00000030h]
        Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.PWSX-gen.27251.20675.exeCode function: 1_2_010EA189 mov eax, dword ptr fs:[00000030h]
        Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.PWSX-gen.27251.20675.exeCode function: 1_2_010EA189 mov ecx, dword ptr fs:[00000030h]
        Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.PWSX-gen.27251.20675.exeCode function: 1_2_01028190 mov ecx, dword ptr fs:[00000030h]
        Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.PWSX-gen.27251.20675.exeCode function: 1_2_01052990 mov eax, dword ptr fs:[00000030h]
        Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.PWSX-gen.27251.20675.exeCode function: 1_2_01054190 mov eax, dword ptr fs:[00000030h]
        Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.PWSX-gen.27251.20675.exeCode function: 1_2_0102519E mov eax, dword ptr fs:[00000030h]
        Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.PWSX-gen.27251.20675.exeCode function: 1_2_0102519E mov ecx, dword ptr fs:[00000030h]
        Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.PWSX-gen.27251.20675.exeCode function: 1_2_010361A7 mov eax, dword ptr fs:[00000030h]
        Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.PWSX-gen.27251.20675.exeCode function: 1_2_010361A7 mov eax, dword ptr fs:[00000030h]
        Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.PWSX-gen.27251.20675.exeCode function: 1_2_010361A7 mov eax, dword ptr fs:[00000030h]
        Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.PWSX-gen.27251.20675.exeCode function: 1_2_010361A7 mov eax, dword ptr fs:[00000030h]
        Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.PWSX-gen.27251.20675.exeCode function: 1_2_010561A0 mov eax, dword ptr fs:[00000030h]
        Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.PWSX-gen.27251.20675.exeCode function: 1_2_010561A0 mov eax, dword ptr fs:[00000030h]
        Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.PWSX-gen.27251.20675.exeCode function: 1_2_010E49A4 mov eax, dword ptr fs:[00000030h]
        Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.PWSX-gen.27251.20675.exeCode function: 1_2_010E49A4 mov eax, dword ptr fs:[00000030h]
        Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.PWSX-gen.27251.20675.exeCode function: 1_2_010E49A4 mov eax, dword ptr fs:[00000030h]
        Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.PWSX-gen.27251.20675.exeCode function: 1_2_010E49A4 mov eax, dword ptr fs:[00000030h]
        Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.PWSX-gen.27251.20675.exeCode function: 1_2_010A69A6 mov eax, dword ptr fs:[00000030h]
        Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.PWSX-gen.27251.20675.exeCode function: 1_2_010A51BE mov eax, dword ptr fs:[00000030h]
        Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.PWSX-gen.27251.20675.exeCode function: 1_2_010A51BE mov eax, dword ptr fs:[00000030h]
        Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.PWSX-gen.27251.20675.exeCode function: 1_2_010A51BE mov eax, dword ptr fs:[00000030h]
        Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.PWSX-gen.27251.20675.exeCode function: 1_2_010A51BE mov eax, dword ptr fs:[00000030h]
        Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.PWSX-gen.27251.20675.exeCode function: 1_2_010599BC mov eax, dword ptr fs:[00000030h]
        Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.PWSX-gen.27251.20675.exeCode function: 1_2_0105C9BF mov eax, dword ptr fs:[00000030h]
        Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.PWSX-gen.27251.20675.exeCode function: 1_2_0105C9BF mov eax, dword ptr fs:[00000030h]
        Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.PWSX-gen.27251.20675.exeCode function: 1_2_010FF1B5 mov eax, dword ptr fs:[00000030h]
        Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.PWSX-gen.27251.20675.exeCode function: 1_2_010FF1B5 mov eax, dword ptr fs:[00000030h]
        Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.PWSX-gen.27251.20675.exeCode function: 1_2_010499BF mov ecx, dword ptr fs:[00000030h]
        Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.PWSX-gen.27251.20675.exeCode function: 1_2_010499BF mov ecx, dword ptr fs:[00000030h]
        Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.PWSX-gen.27251.20675.exeCode function: 1_2_010499BF mov eax, dword ptr fs:[00000030h]
        Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.PWSX-gen.27251.20675.exeCode function: 1_2_010499BF mov ecx, dword ptr fs:[00000030h]
        Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.PWSX-gen.27251.20675.exeCode function: 1_2_010499BF mov ecx, dword ptr fs:[00000030h]
        Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.PWSX-gen.27251.20675.exeCode function: 1_2_010499BF mov eax, dword ptr fs:[00000030h]
        Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.PWSX-gen.27251.20675.exeCode function: 1_2_010499BF mov ecx, dword ptr fs:[00000030h]
        Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.PWSX-gen.27251.20675.exeCode function: 1_2_010499BF mov ecx, dword ptr fs:[00000030h]
        Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.PWSX-gen.27251.20675.exeCode function: 1_2_010499BF mov eax, dword ptr fs:[00000030h]
        Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.PWSX-gen.27251.20675.exeCode function: 1_2_010499BF mov ecx, dword ptr fs:[00000030h]
        Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.PWSX-gen.27251.20675.exeCode function: 1_2_010499BF mov ecx, dword ptr fs:[00000030h]
        Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.PWSX-gen.27251.20675.exeCode function: 1_2_010499BF mov eax, dword ptr fs:[00000030h]
        Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.PWSX-gen.27251.20675.exeCode function: 1_2_0103C1C0 mov eax, dword ptr fs:[00000030h]
        Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.PWSX-gen.27251.20675.exeCode function: 1_2_010399C7 mov eax, dword ptr fs:[00000030h]
        Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.PWSX-gen.27251.20675.exeCode function: 1_2_010399C7 mov eax, dword ptr fs:[00000030h]
        Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.PWSX-gen.27251.20675.exeCode function: 1_2_010399C7 mov eax, dword ptr fs:[00000030h]
        Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.PWSX-gen.27251.20675.exeCode function: 1_2_010399C7 mov eax, dword ptr fs:[00000030h]
        Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.PWSX-gen.27251.20675.exeCode function: 1_2_010E31DC mov eax, dword ptr fs:[00000030h]
        Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.PWSX-gen.27251.20675.exeCode function: 1_2_010E31DC mov eax, dword ptr fs:[00000030h]
        Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.PWSX-gen.27251.20675.exeCode function: 1_2_010E31DC mov eax, dword ptr fs:[00000030h]
        Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.PWSX-gen.27251.20675.exeCode function: 1_2_010E31DC mov eax, dword ptr fs:[00000030h]
        Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.PWSX-gen.27251.20675.exeCode function: 1_2_010E31DC mov eax, dword ptr fs:[00000030h]
        Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.PWSX-gen.27251.20675.exeCode function: 1_2_010E31DC mov eax, dword ptr fs:[00000030h]
        Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.PWSX-gen.27251.20675.exeCode function: 1_2_010E31DC mov eax, dword ptr fs:[00000030h]
        Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.PWSX-gen.27251.20675.exeCode function: 1_2_010E31DC mov ecx, dword ptr fs:[00000030h]
        Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.PWSX-gen.27251.20675.exeCode function: 1_2_010E31DC mov ecx, dword ptr fs:[00000030h]
        Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.PWSX-gen.27251.20675.exeCode function: 1_2_010E31DC mov eax, dword ptr fs:[00000030h]
        Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.PWSX-gen.27251.20675.exeCode function: 1_2_010E31DC mov eax, dword ptr fs:[00000030h]
        Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.PWSX-gen.27251.20675.exeCode function: 1_2_010E31DC mov eax, dword ptr fs:[00000030h]
        Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.PWSX-gen.27251.20675.exeCode function: 1_2_010E31DC mov eax, dword ptr fs:[00000030h]
        Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.PWSX-gen.27251.20675.exeCode function: 1_2_010E19D8 mov eax, dword ptr fs:[00000030h]
        Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.PWSX-gen.27251.20675.exeCode function: 1_2_010231E0 mov eax, dword ptr fs:[00000030h]
        Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.PWSX-gen.27251.20675.exeCode function: 1_2_010B41E8 mov eax, dword ptr fs:[00000030h]
        Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.PWSX-gen.27251.20675.exeCode function: 1_2_0102B1E1 mov eax, dword ptr fs:[00000030h]
        Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.PWSX-gen.27251.20675.exeCode function: 1_2_0102B1E1 mov eax, dword ptr fs:[00000030h]
        Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.PWSX-gen.27251.20675.exeCode function: 1_2_0102B1E1 mov eax, dword ptr fs:[00000030h]
        Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.PWSX-gen.27251.20675.exeCode function: 1_2_010F89E7 mov eax, dword ptr fs:[00000030h]
        Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.PWSX-gen.27251.20675.exeCode function: 1_2_0104D1EF mov eax, dword ptr fs:[00000030h]
        Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.PWSX-gen.27251.20675.exeCode function: 1_2_01026800 mov eax, dword ptr fs:[00000030h]
        Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.PWSX-gen.27251.20675.exeCode function: 1_2_01026800 mov eax, dword ptr fs:[00000030h]
        Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.PWSX-gen.27251.20675.exeCode function: 1_2_01026800 mov eax, dword ptr fs:[00000030h]
        Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.PWSX-gen.27251.20675.exeCode function: 1_2_0105701D mov eax, dword ptr fs:[00000030h]
        Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.PWSX-gen.27251.20675.exeCode function: 1_2_0105701D mov eax, dword ptr fs:[00000030h]
        Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.PWSX-gen.27251.20675.exeCode function: 1_2_0105701D mov eax, dword ptr fs:[00000030h]
        Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.PWSX-gen.27251.20675.exeCode function: 1_2_0105701D mov eax, dword ptr fs:[00000030h]
        Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.PWSX-gen.27251.20675.exeCode function: 1_2_0105701D mov eax, dword ptr fs:[00000030h]
        Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.PWSX-gen.27251.20675.exeCode function: 1_2_0105701D mov eax, dword ptr fs:[00000030h]
        Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.PWSX-gen.27251.20675.exeCode function: 1_2_010F4015 mov eax, dword ptr fs:[00000030h]
        Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.PWSX-gen.27251.20675.exeCode function: 1_2_010F4015 mov eax, dword ptr fs:[00000030h]
        Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.PWSX-gen.27251.20675.exeCode function: 1_2_010A7016 mov eax, dword ptr fs:[00000030h]
        Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.PWSX-gen.27251.20675.exeCode function: 1_2_010A7016 mov eax, dword ptr fs:[00000030h]
        Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.PWSX-gen.27251.20675.exeCode function: 1_2_010A7016 mov eax, dword ptr fs:[00000030h]
        Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.PWSX-gen.27251.20675.exeCode function: 1_2_01054020 mov edi, dword ptr fs:[00000030h]
        Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.PWSX-gen.27251.20675.exeCode function: 1_2_0105002D mov eax, dword ptr fs:[00000030h]
        Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.PWSX-gen.27251.20675.exeCode function: 1_2_0105002D mov eax, dword ptr fs:[00000030h]
        Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.PWSX-gen.27251.20675.exeCode function: 1_2_0105002D mov eax, dword ptr fs:[00000030h]
        Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.PWSX-gen.27251.20675.exeCode function: 1_2_0105002D mov eax, dword ptr fs:[00000030h]
        Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.PWSX-gen.27251.20675.exeCode function: 1_2_0105002D mov eax, dword ptr fs:[00000030h]
        Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.PWSX-gen.27251.20675.exeCode function: 1_2_0103B02A mov eax, dword ptr fs:[00000030h]
        Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.PWSX-gen.27251.20675.exeCode function: 1_2_0103B02A mov eax, dword ptr fs:[00000030h]
        Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.PWSX-gen.27251.20675.exeCode function: 1_2_0103B02A mov eax, dword ptr fs:[00000030h]
        Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.PWSX-gen.27251.20675.exeCode function: 1_2_0103B02A mov eax, dword ptr fs:[00000030h]
        Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.PWSX-gen.27251.20675.exeCode function: 1_2_0104A830 mov eax, dword ptr fs:[00000030h]
        Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.PWSX-gen.27251.20675.exeCode function: 1_2_0104A830 mov eax, dword ptr fs:[00000030h]
        Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.PWSX-gen.27251.20675.exeCode function: 1_2_0104A830 mov eax, dword ptr fs:[00000030h]
        Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.PWSX-gen.27251.20675.exeCode function: 1_2_0104A830 mov eax, dword ptr fs:[00000030h]
        Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.PWSX-gen.27251.20675.exeCode function: 1_2_010E1843 mov eax, dword ptr fs:[00000030h]
        Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.PWSX-gen.27251.20675.exeCode function: 1_2_01025050 mov eax, dword ptr fs:[00000030h]
        Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.PWSX-gen.27251.20675.exeCode function: 1_2_01025050 mov eax, dword ptr fs:[00000030h]
        Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.PWSX-gen.27251.20675.exeCode function: 1_2_01025050 mov eax, dword ptr fs:[00000030h]
        Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.PWSX-gen.27251.20675.exeCode function: 1_2_01040050 mov eax, dword ptr fs:[00000030h]
        Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.PWSX-gen.27251.20675.exeCode function: 1_2_01040050 mov eax, dword ptr fs:[00000030h]
        Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.PWSX-gen.27251.20675.exeCode function: 1_2_01027057 mov eax, dword ptr fs:[00000030h]
        Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.PWSX-gen.27251.20675.exeCode function: 1_2_0104F86D mov eax, dword ptr fs:[00000030h]
        Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.PWSX-gen.27251.20675.exeCode function: 1_2_010F1074 mov eax, dword ptr fs:[00000030h]
        Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.PWSX-gen.27251.20675.exeCode function: 1_2_010E2073 mov eax, dword ptr fs:[00000030h]
        Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.PWSX-gen.27251.20675.exeCode function: 1_2_01029080 mov eax, dword ptr fs:[00000030h]
        Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.PWSX-gen.27251.20675.exeCode function: 1_2_01023880 mov eax, dword ptr fs:[00000030h]
        Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.PWSX-gen.27251.20675.exeCode function: 1_2_01023880 mov eax, dword ptr fs:[00000030h]
        Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.PWSX-gen.27251.20675.exeCode function: 1_2_010A3884 mov eax, dword ptr fs:[00000030h]
        Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.PWSX-gen.27251.20675.exeCode function: 1_2_010A3884 mov eax, dword ptr fs:[00000030h]
        Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.PWSX-gen.27251.20675.exeCode function: 1_2_010520A0 mov eax, dword ptr fs:[00000030h]
        Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.PWSX-gen.27251.20675.exeCode function: 1_2_010520A0 mov eax, dword ptr fs:[00000030h]
        Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.PWSX-gen.27251.20675.exeCode function: 1_2_010520A0 mov eax, dword ptr fs:[00000030h]
        Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.PWSX-gen.27251.20675.exeCode function: 1_2_010520A0 mov eax, dword ptr fs:[00000030h]
        Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.PWSX-gen.27251.20675.exeCode function: 1_2_010520A0 mov eax, dword ptr fs:[00000030h]
        Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.PWSX-gen.27251.20675.exeCode function: 1_2_010520A0 mov eax, dword ptr fs:[00000030h]
        Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.PWSX-gen.27251.20675.exeCode function: 1_2_010578A0 mov eax, dword ptr fs:[00000030h]
        Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.PWSX-gen.27251.20675.exeCode function: 1_2_010578A0 mov eax, dword ptr fs:[00000030h]
        Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.PWSX-gen.27251.20675.exeCode function: 1_2_010578A0 mov eax, dword ptr fs:[00000030h]
        Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.PWSX-gen.27251.20675.exeCode function: 1_2_010578A0 mov eax, dword ptr fs:[00000030h]
        Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.PWSX-gen.27251.20675.exeCode function: 1_2_010578A0 mov eax, dword ptr fs:[00000030h]
        Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.PWSX-gen.27251.20675.exeCode function: 1_2_010578A0 mov eax, dword ptr fs:[00000030h]
        Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.PWSX-gen.27251.20675.exeCode function: 1_2_010578A0 mov eax, dword ptr fs:[00000030h]
        Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.PWSX-gen.27251.20675.exeCode function: 1_2_010578A0 mov eax, dword ptr fs:[00000030h]
        Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.PWSX-gen.27251.20675.exeCode function: 1_2_010578A0 mov eax, dword ptr fs:[00000030h]
        Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.PWSX-gen.27251.20675.exeCode function: 1_2_010690AF mov eax, dword ptr fs:[00000030h]
        Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.PWSX-gen.27251.20675.exeCode function: 1_2_010328AE mov eax, dword ptr fs:[00000030h]
        Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.PWSX-gen.27251.20675.exeCode function: 1_2_010328AE mov eax, dword ptr fs:[00000030h]
        Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.PWSX-gen.27251.20675.exeCode function: 1_2_010328AE mov eax, dword ptr fs:[00000030h]
        Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.PWSX-gen.27251.20675.exeCode function: 1_2_010328AE mov ecx, dword ptr fs:[00000030h]
        Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.PWSX-gen.27251.20675.exeCode function: 1_2_010328AE mov eax, dword ptr fs:[00000030h]
        Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.PWSX-gen.27251.20675.exeCode function: 1_2_010328AE mov eax, dword ptr fs:[00000030h]
        Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.PWSX-gen.27251.20675.exeCode function: 1_2_0105F0BF mov ecx, dword ptr fs:[00000030h]
        Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.PWSX-gen.27251.20675.exeCode function: 1_2_0105F0BF mov eax, dword ptr fs:[00000030h]
        Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.PWSX-gen.27251.20675.exeCode function: 1_2_0105F0BF mov eax, dword ptr fs:[00000030h]
        Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.PWSX-gen.27251.20675.exeCode function: 1_2_010270C0 mov eax, dword ptr fs:[00000030h]
        Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.PWSX-gen.27251.20675.exeCode function: 1_2_010270C0 mov eax, dword ptr fs:[00000030h]
        Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.PWSX-gen.27251.20675.exeCode function: 1_2_010E18CA mov eax, dword ptr fs:[00000030h]
        Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.PWSX-gen.27251.20675.exeCode function: 1_2_010EB0C7 mov eax, dword ptr fs:[00000030h]
        Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.PWSX-gen.27251.20675.exeCode function: 1_2_010EB0C7 mov eax, dword ptr fs:[00000030h]
        Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.PWSX-gen.27251.20675.exeCode function: 1_2_010278D6 mov eax, dword ptr fs:[00000030h]
        Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.PWSX-gen.27251.20675.exeCode function: 1_2_010278D6 mov eax, dword ptr fs:[00000030h]
        Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.PWSX-gen.27251.20675.exeCode function: 1_2_010278D6 mov ecx, dword ptr fs:[00000030h]
        Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.PWSX-gen.27251.20675.exeCode function: 1_2_010BB8D0 mov eax, dword ptr fs:[00000030h]
        Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.PWSX-gen.27251.20675.exeCode function: 1_2_010BB8D0 mov ecx, dword ptr fs:[00000030h]
        Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.PWSX-gen.27251.20675.exeCode function: 1_2_010BB8D0 mov eax, dword ptr fs:[00000030h]
        Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.PWSX-gen.27251.20675.exeCode function: 1_2_010BB8D0 mov eax, dword ptr fs:[00000030h]
        Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.PWSX-gen.27251.20675.exeCode function: 1_2_010BB8D0 mov eax, dword ptr fs:[00000030h]
        Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.PWSX-gen.27251.20675.exeCode function: 1_2_010BB8D0 mov eax, dword ptr fs:[00000030h]
        Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.PWSX-gen.27251.20675.exeCode function: 1_2_0104B8E4 mov eax, dword ptr fs:[00000030h]
        Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.PWSX-gen.27251.20675.exeCode function: 1_2_0104B8E4 mov eax, dword ptr fs:[00000030h]
        Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.PWSX-gen.27251.20675.exeCode function: 1_2_010240E1 mov eax, dword ptr fs:[00000030h]
        Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.PWSX-gen.27251.20675.exeCode function: 1_2_010240E1 mov eax, dword ptr fs:[00000030h]
        Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.PWSX-gen.27251.20675.exeCode function: 1_2_010240E1 mov eax, dword ptr fs:[00000030h]
        Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.PWSX-gen.27251.20675.exeCode function: 1_2_010258EC mov eax, dword ptr fs:[00000030h]
        Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.PWSX-gen.27251.20675.exeCode function: 1_2_010E60F5 mov eax, dword ptr fs:[00000030h]
        Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.PWSX-gen.27251.20675.exeCode function: 1_2_010E60F5 mov eax, dword ptr fs:[00000030h]
        Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.PWSX-gen.27251.20675.exeCode function: 1_2_010E60F5 mov eax, dword ptr fs:[00000030h]
        Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.PWSX-gen.27251.20675.exeCode function: 1_2_010E60F5 mov eax, dword ptr fs:[00000030h]
        Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.PWSX-gen.27251.20675.exeCode function: 1_2_010328FD mov eax, dword ptr fs:[00000030h]
        Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.PWSX-gen.27251.20675.exeCode function: 1_2_010328FD mov eax, dword ptr fs:[00000030h]
        Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.PWSX-gen.27251.20675.exeCode function: 1_2_010328FD mov eax, dword ptr fs:[00000030h]
        Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.PWSX-gen.27251.20675.exeCode function: 1_2_0104A309 mov eax, dword ptr fs:[00000030h]
        Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.PWSX-gen.27251.20675.exeCode function: 1_2_0104A309 mov eax, dword ptr fs:[00000030h]
        Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.PWSX-gen.27251.20675.exeCode function: 1_2_0104A309 mov eax, dword ptr fs:[00000030h]
        Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.PWSX-gen.27251.20675.exeCode function: 1_2_0104A309 mov eax, dword ptr fs:[00000030h]
        Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.PWSX-gen.27251.20675.exeCode function: 1_2_0104A309 mov eax, dword ptr fs:[00000030h]
        Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.PWSX-gen.27251.20675.exeCode function: 1_2_0104A309 mov eax, dword ptr fs:[00000030h]
        Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.PWSX-gen.27251.20675.exeCode function: 1_2_0104A309 mov eax, dword ptr fs:[00000030h]
        Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.PWSX-gen.27251.20675.exeCode function: 1_2_0104A309 mov eax, dword ptr fs:[00000030h]
        Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.PWSX-gen.27251.20675.exeCode function: 1_2_0104A309 mov eax, dword ptr fs:[00000030h]
        Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.PWSX-gen.27251.20675.exeCode function: 1_2_0104A309 mov eax, dword ptr fs:[00000030h]
        Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.PWSX-gen.27251.20675.exeCode function: 1_2_0104A309 mov eax, dword ptr fs:[00000030h]
        Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.PWSX-gen.27251.20675.exeCode function: 1_2_0104A309 mov eax, dword ptr fs:[00000030h]
        Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.PWSX-gen.27251.20675.exeCode function: 1_2_0104A309 mov eax, dword ptr fs:[00000030h]
        Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.PWSX-gen.27251.20675.exeCode function: 1_2_0104A309 mov eax, dword ptr fs:[00000030h]
        Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.PWSX-gen.27251.20675.exeCode function: 1_2_0104A309 mov eax, dword ptr fs:[00000030h]
        Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.PWSX-gen.27251.20675.exeCode function: 1_2_0104A309 mov eax, dword ptr fs:[00000030h]
        Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.PWSX-gen.27251.20675.exeCode function: 1_2_0104A309 mov eax, dword ptr fs:[00000030h]
        Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.PWSX-gen.27251.20675.exeCode function: 1_2_0104A309 mov eax, dword ptr fs:[00000030h]
        Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.PWSX-gen.27251.20675.exeCode function: 1_2_0104A309 mov eax, dword ptr fs:[00000030h]
        Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.PWSX-gen.27251.20675.exeCode function: 1_2_0104A309 mov eax, dword ptr fs:[00000030h]
        Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.PWSX-gen.27251.20675.exeCode function: 1_2_0104A309 mov eax, dword ptr fs:[00000030h]
        Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.PWSX-gen.27251.20675.exeCode function: 1_2_010E131B mov eax, dword ptr fs:[00000030h]
        Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.PWSX-gen.27251.20675.exeCode function: 1_2_0102DB40 mov eax, dword ptr fs:[00000030h]
        Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.PWSX-gen.27251.20675.exeCode function: 1_2_010F8B58 mov eax, dword ptr fs:[00000030h]
        Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.PWSX-gen.27251.20675.exeCode function: 1_2_0102F358 mov eax, dword ptr fs:[00000030h]
        Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.PWSX-gen.27251.20675.exeCode function: 1_2_01053B5A mov eax, dword ptr fs:[00000030h]
        Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.PWSX-gen.27251.20675.exeCode function: 1_2_01053B5A mov eax, dword ptr fs:[00000030h]
        Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.PWSX-gen.27251.20675.exeCode function: 1_2_01053B5A mov eax, dword ptr fs:[00000030h]
        Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.PWSX-gen.27251.20675.exeCode function: 1_2_01053B5A mov eax, dword ptr fs:[00000030h]
        Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.PWSX-gen.27251.20675.exeCode function: 1_2_0102DB60 mov ecx, dword ptr fs:[00000030h]
        Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.PWSX-gen.27251.20675.exeCode function: 1_2_010B6365 mov eax, dword ptr fs:[00000030h]
        Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.PWSX-gen.27251.20675.exeCode function: 1_2_010B6365 mov eax, dword ptr fs:[00000030h]
        Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.PWSX-gen.27251.20675.exeCode function: 1_2_010B6365 mov eax, dword ptr fs:[00000030h]
        Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.PWSX-gen.27251.20675.exeCode function: 1_2_01027B70 mov eax, dword ptr fs:[00000030h]
        Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.PWSX-gen.27251.20675.exeCode function: 1_2_0103F370 mov eax, dword ptr fs:[00000030h]
        Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.PWSX-gen.27251.20675.exeCode function: 1_2_0103F370 mov eax, dword ptr fs:[00000030h]
        Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.PWSX-gen.27251.20675.exeCode function: 1_2_0103F370 mov eax, dword ptr fs:[00000030h]
        Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.PWSX-gen.27251.20675.exeCode function: 1_2_01053B7A mov eax, dword ptr fs:[00000030h]
        Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.PWSX-gen.27251.20675.exeCode function: 1_2_01053B7A mov eax, dword ptr fs:[00000030h]
        Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.PWSX-gen.27251.20675.exeCode function: 1_2_010E138A mov eax, dword ptr fs:[00000030h]
        Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.PWSX-gen.27251.20675.exeCode function: 1_2_010CEB8A mov ecx, dword ptr fs:[00000030h]
        Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.PWSX-gen.27251.20675.exeCode function: 1_2_010CEB8A mov eax, dword ptr fs:[00000030h]
        Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.PWSX-gen.27251.20675.exeCode function: 1_2_010CEB8A mov eax, dword ptr fs:[00000030h]
        Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.PWSX-gen.27251.20675.exeCode function: 1_2_010CEB8A mov eax, dword ptr fs:[00000030h]
        Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.PWSX-gen.27251.20675.exeCode function: 1_2_01031B8F mov eax, dword ptr fs:[00000030h]
        Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.PWSX-gen.27251.20675.exeCode function: 1_2_01031B8F mov eax, dword ptr fs:[00000030h]
        Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.PWSX-gen.27251.20675.exeCode function: 1_2_010DD380 mov ecx, dword ptr fs:[00000030h]
        Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.PWSX-gen.27251.20675.exeCode function: 1_2_0105138B mov eax, dword ptr fs:[00000030h]
        Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.PWSX-gen.27251.20675.exeCode function: 1_2_0105138B mov eax, dword ptr fs:[00000030h]
        Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.PWSX-gen.27251.20675.exeCode function: 1_2_0105138B mov eax, dword ptr fs:[00000030h]
        Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.PWSX-gen.27251.20675.exeCode function: 1_2_01052397 mov eax, dword ptr fs:[00000030h]
        Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.PWSX-gen.27251.20675.exeCode function: 1_2_0105B390 mov eax, dword ptr fs:[00000030h]
        Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.PWSX-gen.27251.20675.exeCode function: 1_2_01024B94 mov edi, dword ptr fs:[00000030h]
        Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.PWSX-gen.27251.20675.exeCode function: 1_2_0104EB9A mov eax, dword ptr fs:[00000030h]
        Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.PWSX-gen.27251.20675.exeCode function: 1_2_0104EB9A mov eax, dword ptr fs:[00000030h]
        Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.PWSX-gen.27251.20675.exeCode function: 1_2_010E1BA8 mov eax, dword ptr fs:[00000030h]
        Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.PWSX-gen.27251.20675.exeCode function: 1_2_01054BAD mov eax, dword ptr fs:[00000030h]
        Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.PWSX-gen.27251.20675.exeCode function: 1_2_01054BAD mov eax, dword ptr fs:[00000030h]
        Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.PWSX-gen.27251.20675.exeCode function: 1_2_01054BAD mov eax, dword ptr fs:[00000030h]
        Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.PWSX-gen.27251.20675.exeCode function: 1_2_010F5BA5 mov eax, dword ptr fs:[00000030h]
        Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.PWSX-gen.27251.20675.exeCode function: 1_2_010F9BBE mov eax, dword ptr fs:[00000030h]
        Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.PWSX-gen.27251.20675.exeCode function: 1_2_010F8BB6 mov eax, dword ptr fs:[00000030h]
        Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.PWSX-gen.27251.20675.exeCode function: 1_2_010A53CA mov eax, dword ptr fs:[00000030h]
        Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.PWSX-gen.27251.20675.exeCode function: 1_2_010A53CA mov eax, dword ptr fs:[00000030h]
        Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.PWSX-gen.27251.20675.exeCode function: 1_2_010553C5 mov eax, dword ptr fs:[00000030h]
        Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.PWSX-gen.27251.20675.exeCode function: 1_2_010503E2 mov eax, dword ptr fs:[00000030h]
        Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.PWSX-gen.27251.20675.exeCode function: 1_2_010503E2 mov eax, dword ptr fs:[00000030h]
        Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.PWSX-gen.27251.20675.exeCode function: 1_2_010503E2 mov eax, dword ptr fs:[00000030h]
        Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.PWSX-gen.27251.20675.exeCode function: 1_2_010503E2 mov eax, dword ptr fs:[00000030h]
        Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.PWSX-gen.27251.20675.exeCode function: 1_2_010503E2 mov eax, dword ptr fs:[00000030h]
        Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.PWSX-gen.27251.20675.exeCode function: 1_2_010503E2 mov eax, dword ptr fs:[00000030h]
        Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.PWSX-gen.27251.20675.exeCode function: 1_2_01021BE9 mov eax, dword ptr fs:[00000030h]
        Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.PWSX-gen.27251.20675.exeCode function: 1_2_0104DBE9 mov eax, dword ptr fs:[00000030h]
        Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.PWSX-gen.27251.20675.exeCode function: 1_2_010D23E3 mov ecx, dword ptr fs:[00000030h]
        Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.PWSX-gen.27251.20675.exeCode function: 1_2_010D23E3 mov ecx, dword ptr fs:[00000030h]
        Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.PWSX-gen.27251.20675.exeCode function: 1_2_010D23E3 mov eax, dword ptr fs:[00000030h]
        Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.PWSX-gen.27251.20675.exeCode function: 1_2_0103BA00 mov eax, dword ptr fs:[00000030h]
        Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.PWSX-gen.27251.20675.exeCode function: 1_2_0103BA00 mov eax, dword ptr fs:[00000030h]
        Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.PWSX-gen.27251.20675.exeCode function: 1_2_0103BA00 mov eax, dword ptr fs:[00000030h]
        Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.PWSX-gen.27251.20675.exeCode function: 1_2_0103BA00 mov ecx, dword ptr fs:[00000030h]
        Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.PWSX-gen.27251.20675.exeCode function: 1_2_0103BA00 mov eax, dword ptr fs:[00000030h]
        Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.PWSX-gen.27251.20675.exeCode function: 1_2_0103BA00 mov eax, dword ptr fs:[00000030h]
        Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.PWSX-gen.27251.20675.exeCode function: 1_2_0103BA00 mov eax, dword ptr fs:[00000030h]
        Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.PWSX-gen.27251.20675.exeCode function: 1_2_0103BA00 mov eax, dword ptr fs:[00000030h]
        Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.PWSX-gen.27251.20675.exeCode function: 1_2_0103BA00 mov eax, dword ptr fs:[00000030h]
        Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.PWSX-gen.27251.20675.exeCode function: 1_2_0103BA00 mov eax, dword ptr fs:[00000030h]
        Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.PWSX-gen.27251.20675.exeCode function: 1_2_0103BA00 mov eax, dword ptr fs:[00000030h]
        Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.PWSX-gen.27251.20675.exeCode function: 1_2_0103BA00 mov eax, dword ptr fs:[00000030h]
        Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.PWSX-gen.27251.20675.exeCode function: 1_2_0103BA00 mov eax, dword ptr fs:[00000030h]
        Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.PWSX-gen.27251.20675.exeCode function: 1_2_0103BA00 mov eax, dword ptr fs:[00000030h]
        Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.PWSX-gen.27251.20675.exeCode function: 1_2_01038A0A mov eax, dword ptr fs:[00000030h]
        Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.PWSX-gen.27251.20675.exeCode function: 1_2_01025210 mov eax, dword ptr fs:[00000030h]
        Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.PWSX-gen.27251.20675.exeCode function: 1_2_01025210 mov ecx, dword ptr fs:[00000030h]
        Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.PWSX-gen.27251.20675.exeCode function: 1_2_01025210 mov eax, dword ptr fs:[00000030h]
        Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.PWSX-gen.27251.20675.exeCode function: 1_2_01025210 mov eax, dword ptr fs:[00000030h]
        Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.PWSX-gen.27251.20675.exeCode function: 1_2_0102AA16 mov eax, dword ptr fs:[00000030h]
        Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.PWSX-gen.27251.20675.exeCode function: 1_2_0102AA16 mov eax, dword ptr fs:[00000030h]
        Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.PWSX-gen.27251.20675.exeCode function: 1_2_01043A1C mov eax, dword ptr fs:[00000030h]
        Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.PWSX-gen.27251.20675.exeCode function: 1_2_010EAA16 mov eax, dword ptr fs:[00000030h]
        Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.PWSX-gen.27251.20675.exeCode function: 1_2_010EAA16 mov eax, dword ptr fs:[00000030h]
        Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.PWSX-gen.27251.20675.exeCode function: 1_2_01024A20 mov eax, dword ptr fs:[00000030h]
        Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.PWSX-gen.27251.20675.exeCode function: 1_2_01024A20 mov eax, dword ptr fs:[00000030h]
        Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.PWSX-gen.27251.20675.exeCode function: 1_2_010E1229 mov eax, dword ptr fs:[00000030h]
        Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.PWSX-gen.27251.20675.exeCode function: 1_2_01064A2C mov eax, dword ptr fs:[00000030h]
        Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.PWSX-gen.27251.20675.exeCode function: 1_2_01064A2C mov eax, dword ptr fs:[00000030h]
        Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.PWSX-gen.27251.20675.exeCode function: 1_2_0104A229 mov eax, dword ptr fs:[00000030h]
        Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.PWSX-gen.27251.20675.exeCode function: 1_2_0104A229 mov eax, dword ptr fs:[00000030h]
        Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.PWSX-gen.27251.20675.exeCode function: 1_2_0104A229 mov eax, dword ptr fs:[00000030h]
        Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.PWSX-gen.27251.20675.exeCode function: 1_2_0104A229 mov eax, dword ptr fs:[00000030h]
        Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.PWSX-gen.27251.20675.exeCode function: 1_2_0104A229 mov eax, dword ptr fs:[00000030h]
        Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.PWSX-gen.27251.20675.exeCode function: 1_2_0104A229 mov eax, dword ptr fs:[00000030h]
        Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.PWSX-gen.27251.20675.exeCode function: 1_2_0104A229 mov eax, dword ptr fs:[00000030h]
        Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.PWSX-gen.27251.20675.exeCode function: 1_2_0104A229 mov eax, dword ptr fs:[00000030h]
        Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.PWSX-gen.27251.20675.exeCode function: 1_2_0104A229 mov eax, dword ptr fs:[00000030h]
        Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.PWSX-gen.27251.20675.exeCode function: 1_2_0104B236 mov eax, dword ptr fs:[00000030h]
        Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.PWSX-gen.27251.20675.exeCode function: 1_2_0104B236 mov eax, dword ptr fs:[00000030h]
        Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.PWSX-gen.27251.20675.exeCode function: 1_2_0104B236 mov eax, dword ptr fs:[00000030h]
        Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.PWSX-gen.27251.20675.exeCode function: 1_2_0104B236 mov eax, dword ptr fs:[00000030h]
        Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.PWSX-gen.27251.20675.exeCode function: 1_2_0104B236 mov eax, dword ptr fs:[00000030h]
        Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.PWSX-gen.27251.20675.exeCode function: 1_2_0104B236 mov eax, dword ptr fs:[00000030h]
        Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.PWSX-gen.27251.20675.exeCode function: 1_2_01028239 mov eax, dword ptr fs:[00000030h]
        Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.PWSX-gen.27251.20675.exeCode function: 1_2_01028239 mov eax, dword ptr fs:[00000030h]
        Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.PWSX-gen.27251.20675.exeCode function: 1_2_01028239 mov eax, dword ptr fs:[00000030h]
        Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.PWSX-gen.27251.20675.exeCode function: 1_2_010E5A4F mov eax, dword ptr fs:[00000030h]
        Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.PWSX-gen.27251.20675.exeCode function: 1_2_010E5A4F mov eax, dword ptr fs:[00000030h]
        Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.PWSX-gen.27251.20675.exeCode function: 1_2_010E5A4F mov eax, dword ptr fs:[00000030h]
        Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.PWSX-gen.27251.20675.exeCode function: 1_2_010E5A4F mov eax, dword ptr fs:[00000030h]
        Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.PWSX-gen.27251.20675.exeCode function: 1_2_01029240 mov eax, dword ptr fs:[00000030h]
        Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.PWSX-gen.27251.20675.exeCode function: 1_2_01029240 mov eax, dword ptr fs:[00000030h]
        Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.PWSX-gen.27251.20675.exeCode function: 1_2_01029240 mov eax, dword ptr fs:[00000030h]
        Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.PWSX-gen.27251.20675.exeCode function: 1_2_01029240 mov eax, dword ptr fs:[00000030h]
        Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.PWSX-gen.27251.20675.exeCode function: 1_2_010E1A5F mov eax, dword ptr fs:[00000030h]
        Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.PWSX-gen.27251.20675.exeCode function: 1_2_010EEA55 mov eax, dword ptr fs:[00000030h]
        Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.PWSX-gen.27251.20675.exeCode function: 1_2_010B4257 mov eax, dword ptr fs:[00000030h]
        Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.PWSX-gen.27251.20675.exeCode function: 1_2_010DB260 mov eax, dword ptr fs:[00000030h]
        Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.PWSX-gen.27251.20675.exeCode function: 1_2_010DB260 mov eax, dword ptr fs:[00000030h]
        Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.PWSX-gen.27251.20675.exeCode function: 1_2_010F8A62 mov eax, dword ptr fs:[00000030h]
        Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.PWSX-gen.27251.20675.exeCode function: 1_2_01065A69 mov eax, dword ptr fs:[00000030h]
        Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.PWSX-gen.27251.20675.exeCode function: 1_2_01065A69 mov eax, dword ptr fs:[00000030h]
        Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.PWSX-gen.27251.20675.exeCode function: 1_2_01065A69 mov eax, dword ptr fs:[00000030h]
        Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.PWSX-gen.27251.20675.exeCode function: 1_2_0106927A mov eax, dword ptr fs:[00000030h]
        Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.PWSX-gen.27251.20675.exeCode function: 1_2_0105DA88 mov eax, dword ptr fs:[00000030h]
        Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.PWSX-gen.27251.20675.exeCode function: 1_2_0105DA88 mov eax, dword ptr fs:[00000030h]
        Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.PWSX-gen.27251.20675.exeCode function: 1_2_0105D294 mov eax, dword ptr fs:[00000030h]
        Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.PWSX-gen.27251.20675.exeCode function: 1_2_0105D294 mov eax, dword ptr fs:[00000030h]
        Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.PWSX-gen.27251.20675.exeCode function: 1_2_010E129A mov eax, dword ptr fs:[00000030h]
        Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.PWSX-gen.27251.20675.exeCode function: 1_2_01021AA0 mov eax, dword ptr fs:[00000030h]
        Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.PWSX-gen.27251.20675.exeCode function: 1_2_010362A0 mov eax, dword ptr fs:[00000030h]
        Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.PWSX-gen.27251.20675.exeCode function: 1_2_010362A0 mov eax, dword ptr fs:[00000030h]
        Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.PWSX-gen.27251.20675.exeCode function: 1_2_010362A0 mov eax, dword ptr fs:[00000030h]
        Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.PWSX-gen.27251.20675.exeCode function: 1_2_010362A0 mov eax, dword ptr fs:[00000030h]
        Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.PWSX-gen.27251.20675.exeCode function: 1_2_01055AA0 mov eax, dword ptr fs:[00000030h]
        Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.PWSX-gen.27251.20675.exeCode function: 1_2_01055AA0 mov eax, dword ptr fs:[00000030h]
        Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.PWSX-gen.27251.20675.exeCode function: 1_2_010252A5 mov eax, dword ptr fs:[00000030h]
        Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.PWSX-gen.27251.20675.exeCode function: 1_2_010252A5 mov eax, dword ptr fs:[00000030h]
        Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.PWSX-gen.27251.20675.exeCode function: 1_2_010252A5 mov eax, dword ptr fs:[00000030h]
        Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.PWSX-gen.27251.20675.exeCode function: 1_2_010252A5 mov eax, dword ptr fs:[00000030h]
        Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.PWSX-gen.27251.20675.exeCode function: 1_2_010252A5 mov eax, dword ptr fs:[00000030h]
        Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.PWSX-gen.27251.20675.exeCode function: 1_2_0103AAB0 mov eax, dword ptr fs:[00000030h]
        Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.PWSX-gen.27251.20675.exeCode function: 1_2_0103AAB0 mov eax, dword ptr fs:[00000030h]
        Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.PWSX-gen.27251.20675.exeCode function: 1_2_0105FAB0 mov eax, dword ptr fs:[00000030h]
        Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.PWSX-gen.27251.20675.exeCode function: 1_2_010512BD mov esi, dword ptr fs:[00000030h]
        Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.PWSX-gen.27251.20675.exeCode function: 1_2_010512BD mov eax, dword ptr fs:[00000030h]
        Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.PWSX-gen.27251.20675.exeCode function: 1_2_010512BD mov eax, dword ptr fs:[00000030h]
        Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.PWSX-gen.27251.20675.exeCode function: 1_2_01025AC0 mov eax, dword ptr fs:[00000030h]
        Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.PWSX-gen.27251.20675.exeCode function: 1_2_01025AC0 mov eax, dword ptr fs:[00000030h]
        Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.PWSX-gen.27251.20675.exeCode function: 1_2_01025AC0 mov eax, dword ptr fs:[00000030h]
        Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.PWSX-gen.27251.20675.exeCode function: 1_2_01023ACA mov eax, dword ptr fs:[00000030h]
        Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.PWSX-gen.27251.20675.exeCode function: 1_2_01052ACB mov eax, dword ptr fs:[00000030h]
        Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.PWSX-gen.27251.20675.exeCode function: 1_2_010F8ADD mov eax, dword ptr fs:[00000030h]
        Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.PWSX-gen.27251.20675.exeCode function: 1_2_010212D4 mov eax, dword ptr fs:[00000030h]
        Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.PWSX-gen.27251.20675.exeCode function: 1_2_01052AE4 mov eax, dword ptr fs:[00000030h]
        Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.PWSX-gen.27251.20675.exeCode function: 1_2_010E4AEF mov eax, dword ptr fs:[00000030h]
        Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.PWSX-gen.27251.20675.exeCode function: 1_2_010E4AEF mov eax, dword ptr fs:[00000030h]
        Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.PWSX-gen.27251.20675.exeCode function: 1_2_010E4AEF mov eax, dword ptr fs:[00000030h]
        Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.PWSX-gen.27251.20675.exeCode function: 1_2_010E4AEF mov eax, dword ptr fs:[00000030h]
        Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.PWSX-gen.27251.20675.exeCode function: 1_2_010E4AEF mov eax, dword ptr fs:[00000030h]
        Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.PWSX-gen.27251.20675.exeCode function: 1_2_010E4AEF mov eax, dword ptr fs:[00000030h]
        Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.PWSX-gen.27251.20675.exeCode function: 1_2_010E4AEF mov eax, dword ptr fs:[00000030h]
        Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.PWSX-gen.27251.20675.exeCode function: 1_2_010E4AEF mov eax, dword ptr fs:[00000030h]
        Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.PWSX-gen.27251.20675.exeCode function: 1_2_010E4AEF mov eax, dword ptr fs:[00000030h]
        Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.PWSX-gen.27251.20675.exeCode function: 1_2_010E4AEF mov eax, dword ptr fs:[00000030h]
        Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.PWSX-gen.27251.20675.exeCode function: 1_2_010E4AEF mov eax, dword ptr fs:[00000030h]
        Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.PWSX-gen.27251.20675.exeCode function: 1_2_010E4AEF mov eax, dword ptr fs:[00000030h]
        Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.PWSX-gen.27251.20675.exeCode function: 1_2_010E4AEF mov eax, dword ptr fs:[00000030h]
        Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.PWSX-gen.27251.20675.exeCode function: 1_2_010E4AEF mov eax, dword ptr fs:[00000030h]
        Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.PWSX-gen.27251.20675.exeCode function: 1_2_010EB2E8 mov eax, dword ptr fs:[00000030h]
        Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.PWSX-gen.27251.20675.exeCode function: 1_2_010EB2E8 mov eax, dword ptr fs:[00000030h]
        Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.PWSX-gen.27251.20675.exeCode function: 1_2_010EB2E8 mov eax, dword ptr fs:[00000030h]
        Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.PWSX-gen.27251.20675.exeCode function: 1_2_010EB2E8 mov eax, dword ptr fs:[00000030h]
        Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.PWSX-gen.27251.20675.exeCode function: 1_2_010CCD04 mov eax, dword ptr fs:[00000030h]
        Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.PWSX-gen.27251.20675.exeCode function: 1_2_010E3518 mov eax, dword ptr fs:[00000030h]
        Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.PWSX-gen.27251.20675.exeCode function: 1_2_010E3518 mov eax, dword ptr fs:[00000030h]
        Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.PWSX-gen.27251.20675.exeCode function: 1_2_010E3518 mov eax, dword ptr fs:[00000030h]
        Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.PWSX-gen.27251.20675.exeCode function: 1_2_0102751A mov eax, dword ptr fs:[00000030h]
        Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.PWSX-gen.27251.20675.exeCode function: 1_2_0102751A mov eax, dword ptr fs:[00000030h]
        Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.PWSX-gen.27251.20675.exeCode function: 1_2_0102751A mov eax, dword ptr fs:[00000030h]
        Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.PWSX-gen.27251.20675.exeCode function: 1_2_0102751A mov eax, dword ptr fs:[00000030h]
        Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.PWSX-gen.27251.20675.exeCode function: 1_2_0105F527 mov eax, dword ptr fs:[00000030h]
        Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.PWSX-gen.27251.20675.exeCode function: 1_2_0105F527 mov eax, dword ptr fs:[00000030h]
        Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.PWSX-gen.27251.20675.exeCode function: 1_2_0105F527 mov eax, dword ptr fs:[00000030h]
        Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.PWSX-gen.27251.20675.exeCode function: 1_2_0102AD30 mov eax, dword ptr fs:[00000030h]
        Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.PWSX-gen.27251.20675.exeCode function: 1_2_01033D34 mov eax, dword ptr fs:[00000030h]
        Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.PWSX-gen.27251.20675.exeCode function: 1_2_01033D34 mov eax, dword ptr fs:[00000030h]
        Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.PWSX-gen.27251.20675.exeCode function: 1_2_01033D34 mov eax, dword ptr fs:[00000030h]
        Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.PWSX-gen.27251.20675.exeCode function: 1_2_01033D34 mov eax, dword ptr fs:[00000030h]
        Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.PWSX-gen.27251.20675.exeCode function: 1_2_01033D34 mov eax, dword ptr fs:[00000030h]
        Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.PWSX-gen.27251.20675.exeCode function: 1_2_01033D34 mov eax, dword ptr fs:[00000030h]
        Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.PWSX-gen.27251.20675.exeCode function: 1_2_01033D34 mov eax, dword ptr fs:[00000030h]
        Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.PWSX-gen.27251.20675.exeCode function: 1_2_01033D34 mov eax, dword ptr fs:[00000030h]
        Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.PWSX-gen.27251.20675.exeCode function: 1_2_01033D34 mov eax, dword ptr fs:[00000030h]
        Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.PWSX-gen.27251.20675.exeCode function: 1_2_01033D34 mov eax, dword ptr fs:[00000030h]
        Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.PWSX-gen.27251.20675.exeCode function: 1_2_01033D34 mov eax, dword ptr fs:[00000030h]
        Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.PWSX-gen.27251.20675.exeCode function: 1_2_01033D34 mov eax, dword ptr fs:[00000030h]
        Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.PWSX-gen.27251.20675.exeCode function: 1_2_01033D34 mov eax, dword ptr fs:[00000030h]
        Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.PWSX-gen.27251.20675.exeCode function: 1_2_010EE539 mov eax, dword ptr fs:[00000030h]
        Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.PWSX-gen.27251.20675.exeCode function: 1_2_010F8D34 mov eax, dword ptr fs:[00000030h]
        Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.PWSX-gen.27251.20675.exeCode function: 1_2_010AA537 mov eax, dword ptr fs:[00000030h]
        Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.PWSX-gen.27251.20675.exeCode function: 1_2_01054D3B mov eax, dword ptr fs:[00000030h]
        Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.PWSX-gen.27251.20675.exeCode function: 1_2_01054D3B mov eax, dword ptr fs:[00000030h]
        Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.PWSX-gen.27251.20675.exeCode function: 1_2_01054D3B mov eax, dword ptr fs:[00000030h]
        Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.PWSX-gen.27251.20675.exeCode function: 1_2_01063D43 mov eax, dword ptr fs:[00000030h]
        Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.PWSX-gen.27251.20675.exeCode function: 1_2_010A3540 mov eax, dword ptr fs:[00000030h]
        Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.PWSX-gen.27251.20675.exeCode function: 1_2_010D8D47 mov eax, dword ptr fs:[00000030h]
        Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.PWSX-gen.27251.20675.exeCode function: 1_2_010D3D40 mov eax, dword ptr fs:[00000030h]
        Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.PWSX-gen.27251.20675.exeCode function: 1_2_0102354C mov eax, dword ptr fs:[00000030h]
        Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.PWSX-gen.27251.20675.exeCode function: 1_2_0102354C mov eax, dword ptr fs:[00000030h]
        Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.PWSX-gen.27251.20675.exeCode function: 1_2_01047D50 mov eax, dword ptr fs:[00000030h]
        Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.PWSX-gen.27251.20675.exeCode function: 1_2_01064D51 mov eax, dword ptr fs:[00000030h]
        Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.PWSX-gen.27251.20675.exeCode function: 1_2_01064D51 mov eax, dword ptr fs:[00000030h]
        Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.PWSX-gen.27251.20675.exeCode function: 1_2_010DFD52 mov eax, dword ptr fs:[00000030h]
        Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.PWSX-gen.27251.20675.exeCode function: 1_2_01048D76 mov eax, dword ptr fs:[00000030h]
        Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.PWSX-gen.27251.20675.exeCode function: 1_2_01048D76 mov eax, dword ptr fs:[00000030h]
        Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.PWSX-gen.27251.20675.exeCode function: 1_2_01048D76 mov eax, dword ptr fs:[00000030h]
        Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.PWSX-gen.27251.20675.exeCode function: 1_2_01048D76 mov eax, dword ptr fs:[00000030h]
        Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.PWSX-gen.27251.20675.exeCode function: 1_2_01048D76 mov eax, dword ptr fs:[00000030h]
        Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.PWSX-gen.27251.20675.exeCode function: 1_2_0104C577 mov eax, dword ptr fs:[00000030h]
        Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.PWSX-gen.27251.20675.exeCode function: 1_2_0104C577 mov eax, dword ptr fs:[00000030h]
        Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.PWSX-gen.27251.20675.exeCode function: 1_2_01052581 mov eax, dword ptr fs:[00000030h]
        Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.PWSX-gen.27251.20675.exeCode function: 1_2_01052581 mov eax, dword ptr fs:[00000030h]
        Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.PWSX-gen.27251.20675.exeCode function: 1_2_01052581 mov eax, dword ptr fs:[00000030h]
        Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.PWSX-gen.27251.20675.exeCode function: 1_2_01052581 mov eax, dword ptr fs:[00000030h]
        Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.PWSX-gen.27251.20675.exeCode function: 1_2_01022D8A mov eax, dword ptr fs:[00000030h]
        Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.PWSX-gen.27251.20675.exeCode function: 1_2_01022D8A mov eax, dword ptr fs:[00000030h]
        Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.PWSX-gen.27251.20675.exeCode function: 1_2_01022D8A mov eax, dword ptr fs:[00000030h]
        Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.PWSX-gen.27251.20675.exeCode function: 1_2_01022D8A mov eax, dword ptr fs:[00000030h]
        Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.PWSX-gen.27251.20675.exeCode function: 1_2_01022D8A mov eax, dword ptr fs:[00000030h]
        Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.PWSX-gen.27251.20675.exeCode function: 1_2_010E2D82 mov eax, dword ptr fs:[00000030h]
        Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.PWSX-gen.27251.20675.exeCode function: 1_2_010E2D82 mov eax, dword ptr fs:[00000030h]
        Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.PWSX-gen.27251.20675.exeCode function: 1_2_010E2D82 mov eax, dword ptr fs:[00000030h]
        Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.PWSX-gen.27251.20675.exeCode function: 1_2_010E2D82 mov eax, dword ptr fs:[00000030h]
        Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.PWSX-gen.27251.20675.exeCode function: 1_2_010E2D82 mov eax, dword ptr fs:[00000030h]
        Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.PWSX-gen.27251.20675.exeCode function: 1_2_010E2D82 mov eax, dword ptr fs:[00000030h]
        Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.PWSX-gen.27251.20675.exeCode function: 1_2_010E2D82 mov eax, dword ptr fs:[00000030h]
        Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.PWSX-gen.27251.20675.exeCode function: 1_2_010EB581 mov eax, dword ptr fs:[00000030h]
        Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.PWSX-gen.27251.20675.exeCode function: 1_2_010EB581 mov eax, dword ptr fs:[00000030h]
        Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.PWSX-gen.27251.20675.exeCode function: 1_2_010EB581 mov eax, dword ptr fs:[00000030h]
        Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.PWSX-gen.27251.20675.exeCode function: 1_2_010EB581 mov eax, dword ptr fs:[00000030h]
        Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.PWSX-gen.27251.20675.exeCode function: 1_2_01023591 mov eax, dword ptr fs:[00000030h]
        Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.PWSX-gen.27251.20675.exeCode function: 1_2_0105FD9B mov eax, dword ptr fs:[00000030h]
        Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.PWSX-gen.27251.20675.exeCode function: 1_2_0105FD9B mov eax, dword ptr fs:[00000030h]
        Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.PWSX-gen.27251.20675.exeCode function: 1_2_010F05AC mov eax, dword ptr fs:[00000030h]
        Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.PWSX-gen.27251.20675.exeCode function: 1_2_010F05AC mov eax, dword ptr fs:[00000030h]
        Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.PWSX-gen.27251.20675.exeCode function: 1_2_010535A1 mov eax, dword ptr fs:[00000030h]
        Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.PWSX-gen.27251.20675.exeCode function: 1_2_010565A0 mov eax, dword ptr fs:[00000030h]
        Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.PWSX-gen.27251.20675.exeCode function: 1_2_010565A0 mov eax, dword ptr fs:[00000030h]
        Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.PWSX-gen.27251.20675.exeCode function: 1_2_010565A0 mov eax, dword ptr fs:[00000030h]
        Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.PWSX-gen.27251.20675.exeCode function: 1_2_01051DB5 mov eax, dword ptr fs:[00000030h]
        Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.PWSX-gen.27251.20675.exeCode function: 1_2_01051DB5 mov eax, dword ptr fs:[00000030h]
        Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.PWSX-gen.27251.20675.exeCode function: 1_2_01051DB5 mov eax, dword ptr fs:[00000030h]
        Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.PWSX-gen.27251.20675.exeCode function: 1_2_010A6DC9 mov eax, dword ptr fs:[00000030h]
        Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.PWSX-gen.27251.20675.exeCode function: 1_2_010A6DC9 mov eax, dword ptr fs:[00000030h]
        Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.PWSX-gen.27251.20675.exeCode function: 1_2_010A6DC9 mov eax, dword ptr fs:[00000030h]
        Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.PWSX-gen.27251.20675.exeCode function: 1_2_010A6DC9 mov ecx, dword ptr fs:[00000030h]
        Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.PWSX-gen.27251.20675.exeCode function: 1_2_010A6DC9 mov eax, dword ptr fs:[00000030h]
        Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.PWSX-gen.27251.20675.exeCode function: 1_2_010A6DC9 mov eax, dword ptr fs:[00000030h]
        Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.PWSX-gen.27251.20675.exeCode function: 1_2_010215C1 mov eax, dword ptr fs:[00000030h]
        Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.PWSX-gen.27251.20675.exeCode function: 1_2_010DFDD3 mov eax, dword ptr fs:[00000030h]
        Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.PWSX-gen.27251.20675.exeCode function: 1_2_0103D5E0 mov eax, dword ptr fs:[00000030h]
        Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.PWSX-gen.27251.20675.exeCode function: 1_2_0103D5E0 mov eax, dword ptr fs:[00000030h]
        Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.PWSX-gen.27251.20675.exeCode function: 1_2_010B3DE3 mov ecx, dword ptr fs:[00000030h]
        Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.PWSX-gen.27251.20675.exeCode function: 1_2_010B3DE3 mov eax, dword ptr fs:[00000030h]
        Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.PWSX-gen.27251.20675.exeCode function: 1_2_010B3DE3 mov eax, dword ptr fs:[00000030h]
        Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.PWSX-gen.27251.20675.exeCode function: 1_2_010595EC mov eax, dword ptr fs:[00000030h]
        Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.PWSX-gen.27251.20675.exeCode function: 1_2_010EFDE2 mov eax, dword ptr fs:[00000030h]
        Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.PWSX-gen.27251.20675.exeCode function: 1_2_010EFDE2 mov eax, dword ptr fs:[00000030h]
        Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.PWSX-gen.27251.20675.exeCode function: 1_2_010EFDE2 mov eax, dword ptr fs:[00000030h]
        Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.PWSX-gen.27251.20675.exeCode function: 1_2_010EFDE2 mov eax, dword ptr fs:[00000030h]
        Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.PWSX-gen.27251.20675.exeCode function: 1_2_010295F0 mov eax, dword ptr fs:[00000030h]
        Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.PWSX-gen.27251.20675.exeCode function: 1_2_010295F0 mov ecx, dword ptr fs:[00000030h]
        Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.PWSX-gen.27251.20675.exeCode function: 1_2_010D8DF1 mov eax, dword ptr fs:[00000030h]
        Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.PWSX-gen.27251.20675.exeCode function: 1_2_010A6C0A mov eax, dword ptr fs:[00000030h]
        Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.PWSX-gen.27251.20675.exeCode function: 1_2_010A6C0A mov eax, dword ptr fs:[00000030h]
        Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.PWSX-gen.27251.20675.exeCode function: 1_2_010A6C0A mov eax, dword ptr fs:[00000030h]
        Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.PWSX-gen.27251.20675.exeCode function: 1_2_010A6C0A mov eax, dword ptr fs:[00000030h]
        Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.PWSX-gen.27251.20675.exeCode function: 1_2_010F740D mov eax, dword ptr fs:[00000030h]
        Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.PWSX-gen.27251.20675.exeCode function: 1_2_010F740D mov eax, dword ptr fs:[00000030h]
        Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.PWSX-gen.27251.20675.exeCode function: 1_2_010F740D mov eax, dword ptr fs:[00000030h]
        Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.PWSX-gen.27251.20675.exeCode function: 1_2_010E1C06 mov eax, dword ptr fs:[00000030h]
        Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.PWSX-gen.27251.20675.exeCode function: 1_2_010E1C06 mov eax, dword ptr fs:[00000030h]
        Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.PWSX-gen.27251.20675.exeCode function: 1_2_010E1C06 mov eax, dword ptr fs:[00000030h]
        Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.PWSX-gen.27251.20675.exeCode function: 1_2_010E1C06 mov eax, dword ptr fs:[00000030h]
        Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.PWSX-gen.27251.20675.exeCode function: 1_2_010E1C06 mov eax, dword ptr fs:[00000030h]
        Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.PWSX-gen.27251.20675.exeCode function: 1_2_010E1C06 mov eax, dword ptr fs:[00000030h]
        Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.PWSX-gen.27251.20675.exeCode function: 1_2_010E1C06 mov eax, dword ptr fs:[00000030h]
        Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.PWSX-gen.27251.20675.exeCode function: 1_2_010E1C06 mov eax, dword ptr fs:[00000030h]
        Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.PWSX-gen.27251.20675.exeCode function: 1_2_010E1C06 mov eax, dword ptr fs:[00000030h]
        Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.PWSX-gen.27251.20675.exeCode function: 1_2_010E1C06 mov eax, dword ptr fs:[00000030h]
        Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.PWSX-gen.27251.20675.exeCode function: 1_2_010E1C06 mov eax, dword ptr fs:[00000030h]
        Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.PWSX-gen.27251.20675.exeCode function: 1_2_010E1C06 mov eax, dword ptr fs:[00000030h]
        Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.PWSX-gen.27251.20675.exeCode function: 1_2_010E1C06 mov eax, dword ptr fs:[00000030h]
        Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.PWSX-gen.27251.20675.exeCode function: 1_2_010E1C06 mov eax, dword ptr fs:[00000030h]
        Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.PWSX-gen.27251.20675.exeCode function: 1_2_01028410 mov eax, dword ptr fs:[00000030h]
        Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.PWSX-gen.27251.20675.exeCode function: 1_2_010F8C14 mov eax, dword ptr fs:[00000030h]
        Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.PWSX-gen.27251.20675.exeProcess queried: DebugPort
        Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.PWSX-gen.27251.20675.exeCode function: 1_2_01069860 NtQuerySystemInformation,LdrInitializeThunk,
        Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.PWSX-gen.27251.20675.exeMemory allocated: page read and write | page guard

        HIPS / PFW / Operating System Protection Evasion

        barindex
        Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.PWSX-gen.27251.20675.exeMemory written: C:\Users\user\Desktop\SecuriteInfo.com.Win32.PWSX-gen.27251.20675.exe base: 400000 value starts with: 4D5A
        Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.PWSX-gen.27251.20675.exeProcess created: C:\Users\user\Desktop\SecuriteInfo.com.Win32.PWSX-gen.27251.20675.exe C:\Users\user\Desktop\SecuriteInfo.com.Win32.PWSX-gen.27251.20675.exe
        Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.PWSX-gen.27251.20675.exeQueries volume information: C:\Users\user\Desktop\SecuriteInfo.com.Win32.PWSX-gen.27251.20675.exe VolumeInformation
        Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.PWSX-gen.27251.20675.exeQueries volume information: C:\Windows\Microsoft.NET\assembly\GAC_MSIL\System.Windows.Forms\v4.0_4.0.0.0__b77a5c561934e089\System.Windows.Forms.dll VolumeInformation
        Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.PWSX-gen.27251.20675.exeQueries volume information: C:\Windows\Microsoft.NET\assembly\GAC_MSIL\System.Drawing\v4.0_4.0.0.0__b03f5f7f11d50a3a\System.Drawing.dll VolumeInformation
        Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.PWSX-gen.27251.20675.exeQueries volume information: C:\Windows\Microsoft.NET\assembly\GAC_MSIL\Accessibility\v4.0_4.0.0.0__b03f5f7f11d50a3a\Accessibility.dll VolumeInformation
        Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.PWSX-gen.27251.20675.exeQueries volume information: C:\Windows\Fonts\arial.ttf VolumeInformation
        Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.PWSX-gen.27251.20675.exeQueries volume information: C:\Windows\Fonts\ariali.ttf VolumeInformation
        Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.PWSX-gen.27251.20675.exeQueries volume information: C:\Windows\Fonts\arialbd.ttf VolumeInformation
        Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.PWSX-gen.27251.20675.exeQueries volume information: C:\Windows\Fonts\arialbi.ttf VolumeInformation
        Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.PWSX-gen.27251.20675.exeQueries volume information: C:\Windows\Fonts\ARIALN.TTF VolumeInformation
        Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.PWSX-gen.27251.20675.exeQueries volume information: C:\Windows\Fonts\ariblk.ttf VolumeInformation
        Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.PWSX-gen.27251.20675.exeQueries volume information: C:\Windows\Fonts\ARIALNI.TTF VolumeInformation
        Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.PWSX-gen.27251.20675.exeQueries volume information: C:\Windows\Fonts\ARIALNB.TTF VolumeInformation
        Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.PWSX-gen.27251.20675.exeQueries volume information: C:\Windows\Fonts\ARIALNBI.TTF VolumeInformation
        Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.PWSX-gen.27251.20675.exeQueries volume information: C:\Windows\Fonts\bahnschrift.ttf VolumeInformation
        Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.PWSX-gen.27251.20675.exeQueries volume information: C:\Windows\Fonts\calibri.ttf VolumeInformation
        Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.PWSX-gen.27251.20675.exeQueries volume information: C:\Windows\Fonts\calibril.ttf VolumeInformation
        Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.PWSX-gen.27251.20675.exeQueries volume information: C:\Windows\Fonts\calibrii.ttf VolumeInformation
        Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.PWSX-gen.27251.20675.exeQueries volume information: C:\Windows\Fonts\calibrili.ttf VolumeInformation
        Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.PWSX-gen.27251.20675.exeQueries volume information: C:\Windows\Fonts\calibrib.ttf VolumeInformation
        Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.PWSX-gen.27251.20675.exeQueries volume information: C:\Windows\Fonts\calibriz.ttf VolumeInformation
        Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.PWSX-gen.27251.20675.exeQueries volume information: C:\Windows\Fonts\cambria.ttc VolumeInformation
        Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.PWSX-gen.27251.20675.exeQueries volume information: C:\Windows\Fonts\cambriai.ttf VolumeInformation
        Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.PWSX-gen.27251.20675.exeQueries volume information: C:\Windows\Fonts\cambriab.ttf VolumeInformation
        Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.PWSX-gen.27251.20675.exeQueries volume information: C:\Windows\Fonts\cambriaz.ttf VolumeInformation
        Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.PWSX-gen.27251.20675.exeQueries volume information: C:\Windows\Fonts\Candara.ttf VolumeInformation
        Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.PWSX-gen.27251.20675.exeQueries volume information: C:\Windows\Fonts\Candarai.ttf VolumeInformation
        Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.PWSX-gen.27251.20675.exeQueries volume information: C:\Windows\Fonts\Candarab.ttf VolumeInformation
        Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.PWSX-gen.27251.20675.exeQueries volume information: C:\Windows\Fonts\Candaraz.ttf VolumeInformation
        Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.PWSX-gen.27251.20675.exeQueries volume information: C:\Windows\Fonts\comic.ttf VolumeInformation
        Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.PWSX-gen.27251.20675.exeQueries volume information: C:\Windows\Fonts\comici.ttf VolumeInformation
        Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.PWSX-gen.27251.20675.exeQueries volume information: C:\Windows\Fonts\comicbd.ttf VolumeInformation
        Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.PWSX-gen.27251.20675.exeQueries volume information: C:\Windows\Fonts\comicz.ttf VolumeInformation
        Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.PWSX-gen.27251.20675.exeQueries volume information: C:\Windows\Fonts\consola.ttf VolumeInformation
        Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.PWSX-gen.27251.20675.exeQueries volume information: C:\Windows\Fonts\consolai.ttf VolumeInformation
        Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.PWSX-gen.27251.20675.exeQueries volume information: C:\Windows\Fonts\consolab.ttf VolumeInformation
        Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.PWSX-gen.27251.20675.exeQueries volume information: C:\Windows\Fonts\consolaz.ttf VolumeInformation
        Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.PWSX-gen.27251.20675.exeQueries volume information: C:\Windows\Fonts\constan.ttf VolumeInformation
        Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.PWSX-gen.27251.20675.exeQueries volume information: C:\Windows\Fonts\constani.ttf VolumeInformation
        Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.PWSX-gen.27251.20675.exeQueries volume information: C:\Windows\Fonts\constanb.ttf VolumeInformation
        Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.PWSX-gen.27251.20675.exeQueries volume information: C:\Windows\Fonts\constanz.ttf VolumeInformation
        Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.PWSX-gen.27251.20675.exeQueries volume information: C:\Windows\Fonts\corbel.ttf VolumeInformation
        Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.PWSX-gen.27251.20675.exeQueries volume information: C:\Windows\Fonts\corbeli.ttf VolumeInformation
        Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.PWSX-gen.27251.20675.exeQueries volume information: C:\Windows\Fonts\corbelb.ttf VolumeInformation
        Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.PWSX-gen.27251.20675.exeQueries volume information: C:\Windows\Fonts\corbelz.ttf VolumeInformation
        Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.PWSX-gen.27251.20675.exeQueries volume information: C:\Windows\Fonts\cour.ttf VolumeInformation
        Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.PWSX-gen.27251.20675.exeQueries volume information: C:\Windows\Fonts\couri.ttf VolumeInformation
        Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.PWSX-gen.27251.20675.exeQueries volume information: C:\Windows\Fonts\courbd.ttf VolumeInformation
        Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.PWSX-gen.27251.20675.exeQueries volume information: C:\Windows\Fonts\courbi.ttf VolumeInformation
        Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.PWSX-gen.27251.20675.exeQueries volume information: C:\Windows\Fonts\ebrima.ttf VolumeInformation
        Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.PWSX-gen.27251.20675.exeQueries volume information: C:\Windows\Fonts\ebrimabd.ttf VolumeInformation
        Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.PWSX-gen.27251.20675.exeQueries volume information: C:\Windows\Fonts\framd.ttf VolumeInformation
        Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.PWSX-gen.27251.20675.exeQueries volume information: C:\Windows\Fonts\FRADM.TTF VolumeInformation
        Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.PWSX-gen.27251.20675.exeQueries volume information: C:\Windows\Fonts\framdit.ttf VolumeInformation
        Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.PWSX-gen.27251.20675.exeQueries volume information: C:\Windows\Fonts\FRADMIT.TTF VolumeInformation
        Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.PWSX-gen.27251.20675.exeQueries volume information: C:\Windows\Fonts\FRAMDCN.TTF VolumeInformation
        Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.PWSX-gen.27251.20675.exeQueries volume information: C:\Windows\Fonts\FRADMCN.TTF VolumeInformation
        Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.PWSX-gen.27251.20675.exeQueries volume information: C:\Windows\Fonts\FRAHV.TTF VolumeInformation
        Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.PWSX-gen.27251.20675.exeQueries volume information: C:\Windows\Fonts\FRAHVIT.TTF VolumeInformation
        Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.PWSX-gen.27251.20675.exeQueries volume information: C:\Windows\Fonts\Gabriola.ttf VolumeInformation
        Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.PWSX-gen.27251.20675.exeQueries volume information: C:\Windows\Fonts\gadugi.ttf VolumeInformation
        Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.PWSX-gen.27251.20675.exeQueries volume information: C:\Windows\Fonts\gadugib.ttf VolumeInformation
        Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.PWSX-gen.27251.20675.exeQueries volume information: C:\Windows\Fonts\georgia.ttf VolumeInformation
        Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.PWSX-gen.27251.20675.exeQueries volume information: C:\Windows\Fonts\georgiai.ttf VolumeInformation
        Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.PWSX-gen.27251.20675.exeQueries volume information: C:\Windows\Fonts\georgiab.ttf VolumeInformation
        Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.PWSX-gen.27251.20675.exeQueries volume information: C:\Windows\Fonts\georgiaz.ttf VolumeInformation
        Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.PWSX-gen.27251.20675.exeQueries volume information: C:\Windows\Fonts\impact.ttf VolumeInformation
        Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.PWSX-gen.27251.20675.exeQueries volume information: C:\Windows\Fonts\Inkfree.ttf VolumeInformation
        Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.PWSX-gen.27251.20675.exeQueries volume information: C:\Windows\Fonts\javatext.ttf VolumeInformation
        Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.PWSX-gen.27251.20675.exeQueries volume information: C:\Windows\Fonts\LeelawUI.ttf VolumeInformation
        Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.PWSX-gen.27251.20675.exeQueries volume information: C:\Windows\Fonts\LeelUIsl.ttf VolumeInformation
        Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.PWSX-gen.27251.20675.exeQueries volume information: C:\Windows\Fonts\LeelaUIb.ttf VolumeInformation
        Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.PWSX-gen.27251.20675.exeQueries volume information: C:\Windows\Fonts\lucon.ttf VolumeInformation
        Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.PWSX-gen.27251.20675.exeQueries volume information: C:\Windows\Fonts\l_10646.ttf VolumeInformation
        Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.PWSX-gen.27251.20675.exeQueries volume information: C:\Windows\Fonts\malgun.ttf VolumeInformation
        Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.PWSX-gen.27251.20675.exeQueries volume information: C:\Windows\Fonts\malgunsl.ttf VolumeInformation
        Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.PWSX-gen.27251.20675.exeQueries volume information: C:\Windows\Fonts\malgunbd.ttf VolumeInformation
        Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.PWSX-gen.27251.20675.exeQueries volume information: C:\Windows\Fonts\himalaya.ttf VolumeInformation
        Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.PWSX-gen.27251.20675.exeQueries volume information: C:\Windows\Fonts\msjh.ttc VolumeInformation
        Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.PWSX-gen.27251.20675.exeQueries volume information: C:\Windows\Fonts\msjhl.ttc VolumeInformation
        Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.PWSX-gen.27251.20675.exeQueries volume information: C:\Windows\Fonts\msjhbd.ttc VolumeInformation
        Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.PWSX-gen.27251.20675.exeQueries volume information: C:\Windows\Fonts\ntailu.ttf VolumeInformation
        Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.PWSX-gen.27251.20675.exeQueries volume information: C:\Windows\Fonts\ntailub.ttf VolumeInformation
        Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.PWSX-gen.27251.20675.exeQueries volume information: C:\Windows\Fonts\phagspa.ttf VolumeInformation
        Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.PWSX-gen.27251.20675.exeQueries volume information: C:\Windows\Fonts\phagspab.ttf VolumeInformation
        Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.PWSX-gen.27251.20675.exeQueries volume information: C:\Windows\Fonts\micross.ttf VolumeInformation
        Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.PWSX-gen.27251.20675.exeQueries volume information: C:\Windows\Fonts\taile.ttf VolumeInformation
        Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.PWSX-gen.27251.20675.exeQueries volume information: C:\Windows\Fonts\taileb.ttf VolumeInformation
        Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.PWSX-gen.27251.20675.exeQueries volume information: C:\Windows\Fonts\msyh.ttc VolumeInformation
        Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.PWSX-gen.27251.20675.exeQueries volume information: C:\Windows\Fonts\msyhl.ttc VolumeInformation
        Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.PWSX-gen.27251.20675.exeQueries volume information: C:\Windows\Fonts\msyhbd.ttc VolumeInformation
        Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.PWSX-gen.27251.20675.exeQueries volume information: C:\Windows\Fonts\msyi.ttf VolumeInformation
        Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.PWSX-gen.27251.20675.exeQueries volume information: C:\Windows\Fonts\mingliub.ttc VolumeInformation
        Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.PWSX-gen.27251.20675.exeQueries volume information: C:\Windows\Fonts\monbaiti.ttf VolumeInformation
        Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.PWSX-gen.27251.20675.exeQueries volume information: C:\Windows\Fonts\msgothic.ttc VolumeInformation
        Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.PWSX-gen.27251.20675.exeQueries volume information: C:\Windows\Fonts\mvboli.ttf VolumeInformation
        Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.PWSX-gen.27251.20675.exeQueries volume information: C:\Windows\Fonts\mmrtext.ttf VolumeInformation
        Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.PWSX-gen.27251.20675.exeQueries volume information: C:\Windows\Fonts\mmrtextb.ttf VolumeInformation
        Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.PWSX-gen.27251.20675.exeQueries volume information: C:\Windows\Fonts\Nirmala.ttf VolumeInformation
        Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.PWSX-gen.27251.20675.exeQueries volume information: C:\Windows\Fonts\NirmalaS.ttf VolumeInformation
        Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.PWSX-gen.27251.20675.exeQueries volume information: C:\Windows\Fonts\NirmalaB.ttf VolumeInformation
        Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.PWSX-gen.27251.20675.exeQueries volume information: C:\Windows\Fonts\pala.ttf VolumeInformation
        Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.PWSX-gen.27251.20675.exeQueries volume information: C:\Windows\Fonts\palai.ttf VolumeInformation
        Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.PWSX-gen.27251.20675.exeQueries volume information: C:\Windows\Fonts\palab.ttf VolumeInformation
        Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.PWSX-gen.27251.20675.exeQueries volume information: C:\Windows\Fonts\palabi.ttf VolumeInformation
        Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.PWSX-gen.27251.20675.exeQueries volume information: C:\Windows\Fonts\segoepr.ttf VolumeInformation
        Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.PWSX-gen.27251.20675.exeQueries volume information: C:\Windows\Fonts\segoeprb.ttf VolumeInformation
        Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.PWSX-gen.27251.20675.exeQueries volume information: C:\Windows\Fonts\segoesc.ttf VolumeInformation
        Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.PWSX-gen.27251.20675.exeQueries volume information: C:\Windows\Fonts\segoescb.ttf VolumeInformation
        Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.PWSX-gen.27251.20675.exeQueries volume information: C:\Windows\Fonts\segoeuii.ttf VolumeInformation
        Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.PWSX-gen.27251.20675.exeQueries volume information: C:\Windows\Fonts\seguisli.ttf VolumeInformation
        Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.PWSX-gen.27251.20675.exeQueries volume information: C:\Windows\Fonts\seguili.ttf VolumeInformation
        Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.PWSX-gen.27251.20675.exeQueries volume information: C:\Windows\Fonts\seguisbi.ttf VolumeInformation
        Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.PWSX-gen.27251.20675.exeQueries volume information: C:\Windows\Fonts\segoeuiz.ttf VolumeInformation
        Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.PWSX-gen.27251.20675.exeQueries volume information: C:\Windows\Fonts\seguibl.ttf VolumeInformation
        Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.PWSX-gen.27251.20675.exeQueries volume information: C:\Windows\Fonts\seguibli.ttf VolumeInformation
        Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.PWSX-gen.27251.20675.exeQueries volume information: C:\Windows\Fonts\seguiemj.ttf VolumeInformation
        Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.PWSX-gen.27251.20675.exeQueries volume information: C:\Windows\Fonts\seguihis.ttf VolumeInformation
        Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.PWSX-gen.27251.20675.exeQueries volume information: C:\Windows\Fonts\seguisym.ttf VolumeInformation
        Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.PWSX-gen.27251.20675.exeQueries volume information: C:\Windows\Fonts\simsun.ttc VolumeInformation
        Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.PWSX-gen.27251.20675.exeQueries volume information: C:\Windows\Fonts\simsunb.ttf VolumeInformation
        Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.PWSX-gen.27251.20675.exeQueries volume information: C:\Windows\Fonts\Sitka.ttc VolumeInformation
        Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.PWSX-gen.27251.20675.exeQueries volume information: C:\Windows\Fonts\SitkaI.ttc VolumeInformation
        Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.PWSX-gen.27251.20675.exeQueries volume information: C:\Windows\Fonts\SitkaB.ttc VolumeInformation
        Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.PWSX-gen.27251.20675.exeQueries volume information: C:\Windows\Fonts\SitkaZ.ttc VolumeInformation
        Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.PWSX-gen.27251.20675.exeQueries volume information: C:\Windows\Fonts\sylfaen.ttf VolumeInformation
        Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.PWSX-gen.27251.20675.exeQueries volume information: C:\Windows\Fonts\symbol.ttf VolumeInformation
        Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.PWSX-gen.27251.20675.exeQueries volume information: C:\Windows\Fonts\tahoma.ttf VolumeInformation
        Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.PWSX-gen.27251.20675.exeQueries volume information: C:\Windows\Fonts\tahomabd.ttf VolumeInformation
        Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.PWSX-gen.27251.20675.exeQueries volume information: C:\Windows\Fonts\timesi.ttf VolumeInformation
        Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.PWSX-gen.27251.20675.exeQueries volume information: C:\Windows\Fonts\timesbd.ttf VolumeInformation
        Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.PWSX-gen.27251.20675.exeQueries volume information: C:\Windows\Fonts\timesbi.ttf VolumeInformation
        Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.PWSX-gen.27251.20675.exeQueries volume information: C:\Windows\Fonts\trebuc.ttf VolumeInformation
        Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.PWSX-gen.27251.20675.exeQueries volume information: C:\Windows\Fonts\trebucit.ttf VolumeInformation
        Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.PWSX-gen.27251.20675.exeQueries volume information: C:\Windows\Fonts\trebucbd.ttf VolumeInformation
        Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.PWSX-gen.27251.20675.exeQueries volume information: C:\Windows\Fonts\trebucbi.ttf VolumeInformation
        Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.PWSX-gen.27251.20675.exeQueries volume information: C:\Windows\Fonts\verdana.ttf VolumeInformation
        Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.PWSX-gen.27251.20675.exeQueries volume information: C:\Windows\Fonts\verdanai.ttf VolumeInformation
        Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.PWSX-gen.27251.20675.exeQueries volume information: C:\Windows\Fonts\verdanab.ttf VolumeInformation
        Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.PWSX-gen.27251.20675.exeQueries volume information: C:\Windows\Fonts\verdanaz.ttf VolumeInformation
        Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.PWSX-gen.27251.20675.exeQueries volume information: C:\Windows\Fonts\webdings.ttf VolumeInformation
        Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.PWSX-gen.27251.20675.exeQueries volume information: C:\Windows\Fonts\wingding.ttf VolumeInformation
        Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.PWSX-gen.27251.20675.exeQueries volume information: C:\Windows\Fonts\YuGothR.ttc VolumeInformation
        Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.PWSX-gen.27251.20675.exeQueries volume information: C:\Windows\Fonts\YuGothM.ttc VolumeInformation
        Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.PWSX-gen.27251.20675.exeQueries volume information: C:\Windows\Fonts\YuGothL.ttc VolumeInformation
        Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.PWSX-gen.27251.20675.exeQueries volume information: C:\Windows\Fonts\YuGothB.ttc VolumeInformation
        Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.PWSX-gen.27251.20675.exeQueries volume information: C:\Windows\Fonts\holomdl2.ttf VolumeInformation
        Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.PWSX-gen.27251.20675.exeQueries volume information: C:\Windows\Fonts\CENTURY.TTF VolumeInformation
        Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.PWSX-gen.27251.20675.exeQueries volume information: C:\Windows\Fonts\LEELAWAD.TTF VolumeInformation
        Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.PWSX-gen.27251.20675.exeQueries volume information: C:\Windows\Fonts\LEELAWDB.TTF VolumeInformation
        Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.PWSX-gen.27251.20675.exeQueries volume information: C:\Windows\Fonts\MSUIGHUR.TTF VolumeInformation
        Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.PWSX-gen.27251.20675.exeQueries volume information: C:\Windows\Fonts\MSUIGHUB.TTF VolumeInformation
        Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.PWSX-gen.27251.20675.exeQueries volume information: C:\Windows\Fonts\WINGDNG2.TTF VolumeInformation
        Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.PWSX-gen.27251.20675.exeQueries volume information: C:\Windows\Fonts\WINGDNG3.TTF VolumeInformation
        Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.PWSX-gen.27251.20675.exeQueries volume information: C:\Windows\Fonts\TEMPSITC.TTF VolumeInformation
        Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.PWSX-gen.27251.20675.exeQueries volume information: C:\Windows\Fonts\PRISTINA.TTF VolumeInformation
        Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.PWSX-gen.27251.20675.exeQueries volume information: C:\Windows\Fonts\PAPYRUS.TTF VolumeInformation
        Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.PWSX-gen.27251.20675.exeQueries volume information: C:\Windows\Fonts\MISTRAL.TTF VolumeInformation
        Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.PWSX-gen.27251.20675.exeQueries volume information: C:\Windows\Fonts\LHANDW.TTF VolumeInformation
        Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.PWSX-gen.27251.20675.exeQueries volume information: C:\Windows\Fonts\ITCKRIST.TTF VolumeInformation
        Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.PWSX-gen.27251.20675.exeQueries volume information: C:\Windows\Fonts\JUICE___.TTF VolumeInformation
        Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.PWSX-gen.27251.20675.exeQueries volume information: C:\Windows\Fonts\FRSCRIPT.TTF VolumeInformation
        Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.PWSX-gen.27251.20675.exeQueries volume information: C:\Windows\Fonts\FREESCPT.TTF VolumeInformation
        Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.PWSX-gen.27251.20675.exeQueries volume information: C:\Windows\Fonts\BRADHITC.TTF VolumeInformation
        Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.PWSX-gen.27251.20675.exeQueries volume information: C:\Windows\Fonts\OUTLOOK.TTF VolumeInformation
        Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.PWSX-gen.27251.20675.exeQueries volume information: C:\Windows\Fonts\BKANT.TTF VolumeInformation
        Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.PWSX-gen.27251.20675.exeQueries volume information: C:\Windows\Fonts\ANTQUAI.TTF VolumeInformation
        Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.PWSX-gen.27251.20675.exeQueries volume information: C:\Windows\Fonts\ANTQUAB.TTF VolumeInformation
        Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.PWSX-gen.27251.20675.exeQueries volume information: C:\Windows\Fonts\ANTQUABI.TTF VolumeInformation
        Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.PWSX-gen.27251.20675.exeQueries volume information: C:\Windows\Fonts\GARA.TTF VolumeInformation
        Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.PWSX-gen.27251.20675.exeQueries volume information: C:\Windows\Fonts\GARAIT.TTF VolumeInformation
        Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.PWSX-gen.27251.20675.exeQueries volume information: C:\Windows\Fonts\GARABD.TTF VolumeInformation
        Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.PWSX-gen.27251.20675.exeQueries volume information: C:\Windows\Fonts\MTCORSVA.TTF VolumeInformation
        Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.PWSX-gen.27251.20675.exeQueries volume information: C:\Windows\Fonts\GOTHIC.TTF VolumeInformation
        Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.PWSX-gen.27251.20675.exeQueries volume information: C:\Windows\Fonts\GOTHICI.TTF VolumeInformation
        Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.PWSX-gen.27251.20675.exeQueries volume information: C:\Windows\Fonts\GOTHICB.TTF VolumeInformation
        Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.PWSX-gen.27251.20675.exeQueries volume information: C:\Windows\Fonts\GOTHICBI.TTF VolumeInformation
        Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.PWSX-gen.27251.20675.exeQueries volume information: C:\Windows\Fonts\ALGER.TTF VolumeInformation
        Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.PWSX-gen.27251.20675.exeQueries volume information: C:\Windows\Fonts\BASKVILL.TTF VolumeInformation
        Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.PWSX-gen.27251.20675.exeQueries volume information: C:\Windows\Fonts\BAUHS93.TTF VolumeInformation
        Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.PWSX-gen.27251.20675.exeQueries volume information: C:\Windows\Fonts\BELL.TTF VolumeInformation
        Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.PWSX-gen.27251.20675.exeQueries volume information: C:\Windows\Fonts\BELLI.TTF VolumeInformation
        Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.PWSX-gen.27251.20675.exeQueries volume information: C:\Windows\Fonts\BELLB.TTF VolumeInformation
        Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.PWSX-gen.27251.20675.exeQueries volume information: C:\Windows\Fonts\BRLNSR.TTF VolumeInformation
        Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.PWSX-gen.27251.20675.exeQueries volume information: C:\Windows\Fonts\BRLNSDB.TTF VolumeInformation
        Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.PWSX-gen.27251.20675.exeQueries volume information: C:\Windows\Fonts\BRLNSB.TTF VolumeInformation
        Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.PWSX-gen.27251.20675.exeQueries volume information: C:\Windows\Fonts\BERNHC.TTF VolumeInformation
        Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.PWSX-gen.27251.20675.exeQueries volume information: C:\Windows\Fonts\BOD_PSTC.TTF VolumeInformation
        Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.PWSX-gen.27251.20675.exeQueries volume information: C:\Windows\Fonts\BRITANIC.TTF VolumeInformation
        Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.PWSX-gen.27251.20675.exeQueries volume information: C:\Windows\Fonts\BROADW.TTF VolumeInformation
        Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.PWSX-gen.27251.20675.exeQueries volume information: C:\Windows\Fonts\BRUSHSCI.TTF VolumeInformation
        Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.PWSX-gen.27251.20675.exeQueries volume information: C:\Windows\Fonts\CALIFR.TTF VolumeInformation
        Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.PWSX-gen.27251.20675.exeQueries volume information: C:\Windows\Fonts\CALIFI.TTF VolumeInformation
        Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.PWSX-gen.27251.20675.exeQueries volume information: C:\Windows\Fonts\CALIFB.TTF VolumeInformation
        Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.PWSX-gen.27251.20675.exeQueries volume information: C:\Windows\Fonts\CENTAUR.TTF VolumeInformation
        Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.PWSX-gen.27251.20675.exeQueries volume information: C:\Windows\Fonts\CHILLER.TTF VolumeInformation
        Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.PWSX-gen.27251.20675.exeQueries volume information: C:\Windows\Fonts\COLONNA.TTF VolumeInformation
        Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.PWSX-gen.27251.20675.exeQueries volume information: C:\Windows\Fonts\COOPBL.TTF VolumeInformation
        Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.PWSX-gen.27251.20675.exeQueries volume information: C:\Windows\Fonts\FTLTLT.TTF VolumeInformation
        Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.PWSX-gen.27251.20675.exeQueries volume information: C:\Windows\Fonts\HARLOWSI.TTF VolumeInformation
        Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.PWSX-gen.27251.20675.exeQueries volume information: C:\Windows\Fonts\HARNGTON.TTF VolumeInformation
        Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.PWSX-gen.27251.20675.exeQueries volume information: C:\Windows\Fonts\HTOWERT.TTF VolumeInformation
        Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.PWSX-gen.27251.20675.exeQueries volume information: C:\Windows\Fonts\HTOWERTI.TTF VolumeInformation
        Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.PWSX-gen.27251.20675.exeQueries volume information: C:\Windows\Fonts\JOKERMAN.TTF VolumeInformation
        Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.PWSX-gen.27251.20675.exeQueries volume information: C:\Windows\Fonts\KUNSTLER.TTF VolumeInformation
        Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.PWSX-gen.27251.20675.exeQueries volume information: C:\Windows\Fonts\LBRITE.TTF VolumeInformation
        Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.PWSX-gen.27251.20675.exeQueries volume information: C:\Windows\Fonts\LBRITED.TTF VolumeInformation
        Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.PWSX-gen.27251.20675.exeQueries volume information: C:\Windows\Fonts\LBRITEI.TTF VolumeInformation
        Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.PWSX-gen.27251.20675.exeQueries volume information: C:\Windows\Fonts\LBRITEDI.TTF VolumeInformation
        Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.PWSX-gen.27251.20675.exeQueries volume information: C:\Windows\Fonts\LCALLIG.TTF VolumeInformation
        Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.PWSX-gen.27251.20675.exeQueries volume information: C:\Windows\Fonts\LFAX.TTF VolumeInformation
        Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.PWSX-gen.27251.20675.exeQueries volume information: C:\Windows\Fonts\LFAXD.TTF VolumeInformation
        Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.PWSX-gen.27251.20675.exeQueries volume information: C:\Windows\Fonts\LFAXI.TTF VolumeInformation
        Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.PWSX-gen.27251.20675.exeQueries volume information: C:\Windows\Fonts\LFAXDI.TTF VolumeInformation
        Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.PWSX-gen.27251.20675.exeQueries volume information: C:\Windows\Fonts\MAGNETOB.TTF VolumeInformation
        Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.PWSX-gen.27251.20675.exeQueries volume information: C:\Windows\Fonts\MATURASC.TTF VolumeInformation
        Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.PWSX-gen.27251.20675.exeQueries volume information: C:\Windows\Fonts\MOD20.TTF VolumeInformation
        Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.PWSX-gen.27251.20675.exeQueries volume information: C:\Windows\Fonts\NIAGENG.TTF VolumeInformation
        Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.PWSX-gen.27251.20675.exeQueries volume information: C:\Windows\Fonts\NIAGSOL.TTF VolumeInformation
        Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.PWSX-gen.27251.20675.exeQueries volume information: C:\Windows\Fonts\OLDENGL.TTF VolumeInformation
        Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.PWSX-gen.27251.20675.exeQueries volume information: C:\Windows\Fonts\ONYX.TTF VolumeInformation
        Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.PWSX-gen.27251.20675.exeQueries volume information: C:\Windows\Fonts\PARCHM.TTF VolumeInformation
        Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.PWSX-gen.27251.20675.exeQueries volume information: C:\Windows\Fonts\PLAYBILL.TTF VolumeInformation
        Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.PWSX-gen.27251.20675.exeQueries volume information: C:\Windows\Fonts\POORICH.TTF VolumeInformation
        Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.PWSX-gen.27251.20675.exeQueries volume information: C:\Windows\Fonts\RAVIE.TTF VolumeInformation
        Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.PWSX-gen.27251.20675.exeQueries volume information: C:\Windows\Fonts\INFROMAN.TTF VolumeInformation
        Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.PWSX-gen.27251.20675.exeQueries volume information: C:\Windows\Fonts\SHOWG.TTF VolumeInformation
        Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.PWSX-gen.27251.20675.exeQueries volume information: C:\Windows\Fonts\SNAP____.TTF VolumeInformation
        Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.PWSX-gen.27251.20675.exeQueries volume information: C:\Windows\Fonts\STENCIL.TTF VolumeInformation
        Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.PWSX-gen.27251.20675.exeQueries volume information: C:\Windows\Fonts\VINERITC.TTF VolumeInformation
        Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.PWSX-gen.27251.20675.exeQueries volume information: C:\Windows\Fonts\VIVALDII.TTF VolumeInformation
        Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.PWSX-gen.27251.20675.exeQueries volume information: C:\Windows\Fonts\VLADIMIR.TTF VolumeInformation
        Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.PWSX-gen.27251.20675.exeQueries volume information: C:\Windows\Fonts\LATINWD.TTF VolumeInformation
        Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.PWSX-gen.27251.20675.exeQueries volume information: C:\Windows\Fonts\TCM_____.TTF VolumeInformation
        Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.PWSX-gen.27251.20675.exeQueries volume information: C:\Windows\Fonts\TCMI____.TTF VolumeInformation
        Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.PWSX-gen.27251.20675.exeQueries volume information: C:\Windows\Fonts\TCB_____.TTF VolumeInformation
        Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.PWSX-gen.27251.20675.exeQueries volume information: C:\Windows\Fonts\TCBI____.TTF VolumeInformation
        Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.PWSX-gen.27251.20675.exeQueries volume information: C:\Windows\Fonts\TCCM____.TTF VolumeInformation
        Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.PWSX-gen.27251.20675.exeQueries volume information: C:\Windows\Fonts\TCCB____.TTF VolumeInformation
        Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.PWSX-gen.27251.20675.exeQueries volume information: C:\Windows\Fonts\TCCEB.TTF VolumeInformation
        Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.PWSX-gen.27251.20675.exeQueries volume information: C:\Windows\Fonts\SCRIPTBL.TTF VolumeInformation
        Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.PWSX-gen.27251.20675.exeQueries volume information: C:\Windows\Fonts\ROCK.TTF VolumeInformation
        Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.PWSX-gen.27251.20675.exeQueries volume information: C:\Windows\Fonts\ROCKI.TTF VolumeInformation
        Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.PWSX-gen.27251.20675.exeQueries volume information: C:\Windows\Fonts\ROCKB.TTF VolumeInformation
        Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.PWSX-gen.27251.20675.exeQueries volume information: C:\Windows\Fonts\ROCKEB.TTF VolumeInformation
        Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.PWSX-gen.27251.20675.exeQueries volume information: C:\Windows\Fonts\ROCKBI.TTF VolumeInformation
        Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.PWSX-gen.27251.20675.exeQueries volume information: C:\Windows\Fonts\ROCC____.TTF VolumeInformation
        Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.PWSX-gen.27251.20675.exeQueries volume information: C:\Windows\Fonts\ROCCB___.TTF VolumeInformation
        Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.PWSX-gen.27251.20675.exeQueries volume information: C:\Windows\Fonts\RAGE.TTF VolumeInformation
        Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.PWSX-gen.27251.20675.exeQueries volume information: C:\Windows\Fonts\PERTILI.TTF VolumeInformation
        Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.PWSX-gen.27251.20675.exeQueries volume information: C:\Windows\Fonts\PERTIBD.TTF VolumeInformation
        Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.PWSX-gen.27251.20675.exeQueries volume information: C:\Windows\Fonts\PER_____.TTF VolumeInformation
        Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.PWSX-gen.27251.20675.exeQueries volume information: C:\Windows\Fonts\PERI____.TTF VolumeInformation
        Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.PWSX-gen.27251.20675.exeQueries volume information: C:\Windows\Fonts\PERB____.TTF VolumeInformation
        Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.PWSX-gen.27251.20675.exeQueries volume information: C:\Windows\Fonts\PERBI___.TTF VolumeInformation
        Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.PWSX-gen.27251.20675.exeQueries volume information: C:\Windows\Fonts\PALSCRI.TTF VolumeInformation
        Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.PWSX-gen.27251.20675.exeQueries volume information: C:\Windows\Fonts\OCRAEXT.TTF VolumeInformation
        Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.PWSX-gen.27251.20675.exeQueries volume information: C:\Windows\Fonts\MAIAN.TTF VolumeInformation
        Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.PWSX-gen.27251.20675.exeQueries volume information: C:\Windows\Fonts\LTYPE.TTF VolumeInformation
        Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.PWSX-gen.27251.20675.exeQueries volume information: C:\Windows\Fonts\LTYPEO.TTF VolumeInformation
        Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.PWSX-gen.27251.20675.exeQueries volume information: C:\Windows\Fonts\LTYPEB.TTF VolumeInformation
        Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.PWSX-gen.27251.20675.exeQueries volume information: C:\Windows\Fonts\LTYPEBO.TTF VolumeInformation
        Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.PWSX-gen.27251.20675.exeQueries volume information: C:\Windows\Fonts\LSANS.TTF VolumeInformation
        Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.PWSX-gen.27251.20675.exeQueries volume information: C:\Windows\Fonts\LSANSD.TTF VolumeInformation
        Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.PWSX-gen.27251.20675.exeQueries volume information: C:\Windows\Fonts\LSANSI.TTF VolumeInformation
        Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.PWSX-gen.27251.20675.exeQueries volume information: C:\Windows\Fonts\LSANSDI.TTF VolumeInformation
        Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.PWSX-gen.27251.20675.exeQueries volume information: C:\Windows\Fonts\IMPRISHA.TTF VolumeInformation
        Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.PWSX-gen.27251.20675.exeQueries volume information: C:\Windows\Fonts\HATTEN.TTF VolumeInformation
        Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.PWSX-gen.27251.20675.exeQueries volume information: C:\Windows\Fonts\GOUDYSTO.TTF VolumeInformation
        Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.PWSX-gen.27251.20675.exeQueries volume information: C:\Windows\Fonts\GOUDOS.TTF VolumeInformation
        Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.PWSX-gen.27251.20675.exeQueries volume information: C:\Windows\Fonts\GOUDOSI.TTF VolumeInformation
        Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.PWSX-gen.27251.20675.exeQueries volume information: C:\Windows\Fonts\GOUDOSB.TTF VolumeInformation
        Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.PWSX-gen.27251.20675.exeQueries volume information: C:\Windows\Fonts\GLECB.TTF VolumeInformation
        Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.PWSX-gen.27251.20675.exeQueries volume information: C:\Windows\Fonts\GIL_____.TTF VolumeInformation
        Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.PWSX-gen.27251.20675.exeQueries volume information: C:\Windows\Fonts\GILI____.TTF VolumeInformation
        Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.PWSX-gen.27251.20675.exeQueries volume information: C:\Windows\Fonts\GILB____.TTF VolumeInformation
        Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.PWSX-gen.27251.20675.exeQueries volume information: C:\Windows\Fonts\GILBI___.TTF VolumeInformation
        Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.PWSX-gen.27251.20675.exeQueries volume information: C:\Windows\Fonts\GILC____.TTF VolumeInformation
        Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.PWSX-gen.27251.20675.exeQueries volume information: C:\Windows\Fonts\GLSNECB.TTF VolumeInformation
        Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.PWSX-gen.27251.20675.exeQueries volume information: C:\Windows\Fonts\GIGI.TTF VolumeInformation
        Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.PWSX-gen.27251.20675.exeQueries volume information: C:\Windows\Fonts\FRABK.TTF VolumeInformation
        Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.PWSX-gen.27251.20675.exeQueries volume information: C:\Windows\Fonts\FRABKIT.TTF VolumeInformation
        Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.PWSX-gen.27251.20675.exeQueries volume information: C:\Windows\Fonts\FORTE.TTF VolumeInformation
        Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.PWSX-gen.27251.20675.exeQueries volume information: C:\Windows\Fonts\FELIXTI.TTF VolumeInformation
        Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.PWSX-gen.27251.20675.exeQueries volume information: C:\Windows\Fonts\ERASMD.TTF VolumeInformation
        Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.PWSX-gen.27251.20675.exeQueries volume information: C:\Windows\Fonts\ERASLGHT.TTF VolumeInformation
        Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.PWSX-gen.27251.20675.exeQueries volume information: C:\Windows\Fonts\ERASDEMI.TTF VolumeInformation
        Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.PWSX-gen.27251.20675.exeQueries volume information: C:\Windows\Fonts\ERASBD.TTF VolumeInformation
        Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.PWSX-gen.27251.20675.exeQueries volume information: C:\Windows\Fonts\ENGR.TTF VolumeInformation
        Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.PWSX-gen.27251.20675.exeQueries volume information: C:\Windows\Fonts\ELEPHNT.TTF VolumeInformation
        Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.PWSX-gen.27251.20675.exeQueries volume information: C:\Windows\Fonts\ELEPHNTI.TTF VolumeInformation
        Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.PWSX-gen.27251.20675.exeQueries volume information: C:\Windows\Fonts\ITCEDSCR.TTF VolumeInformation
        Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.PWSX-gen.27251.20675.exeQueries volume information: C:\Windows\Fonts\CURLZ___.TTF VolumeInformation
        Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.PWSX-gen.27251.20675.exeQueries volume information: C:\Windows\Fonts\COPRGTL.TTF VolumeInformation
        Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.PWSX-gen.27251.20675.exeQueries volume information: C:\Windows\Fonts\COPRGTB.TTF VolumeInformation
        Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.PWSX-gen.27251.20675.exeQueries volume information: C:\Windows\Fonts\CENSCBK.TTF VolumeInformation
        Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.PWSX-gen.27251.20675.exeQueries volume information: C:\Windows\Fonts\SCHLBKI.TTF VolumeInformation
        Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.PWSX-gen.27251.20675.exeQueries volume information: C:\Windows\Fonts\SCHLBKB.TTF VolumeInformation
        Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.PWSX-gen.27251.20675.exeQueries volume information: C:\Windows\Fonts\SCHLBKBI.TTF VolumeInformation
        Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.PWSX-gen.27251.20675.exeQueries volume information: C:\Windows\Fonts\CASTELAR.TTF VolumeInformation
        Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.PWSX-gen.27251.20675.exeQueries volume information: C:\Windows\Fonts\CALIST.TTF VolumeInformation
        Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.PWSX-gen.27251.20675.exeQueries volume information: C:\Windows\Fonts\CALISTI.TTF VolumeInformation
        Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.PWSX-gen.27251.20675.exeQueries volume information: C:\Windows\Fonts\CALISTB.TTF VolumeInformation
        Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.PWSX-gen.27251.20675.exeQueries volume information: C:\Windows\Fonts\CALISTBI.TTF VolumeInformation
        Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.PWSX-gen.27251.20675.exeQueries volume information: C:\Windows\Fonts\BOOKOS.TTF VolumeInformation
        Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.PWSX-gen.27251.20675.exeQueries volume information: C:\Windows\Fonts\BOOKOSB.TTF VolumeInformation
        Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.PWSX-gen.27251.20675.exeQueries volume information: C:\Windows\Fonts\BOOKOSI.TTF VolumeInformation
        Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.PWSX-gen.27251.20675.exeQueries volume information: C:\Windows\Fonts\BOOKOSBI.TTF VolumeInformation
        Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.PWSX-gen.27251.20675.exeQueries volume information: C:\Windows\Fonts\BOD_R.TTF VolumeInformation
        Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.PWSX-gen.27251.20675.exeQueries volume information: C:\Windows\Fonts\BOD_I.TTF VolumeInformation
        Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.PWSX-gen.27251.20675.exeQueries volume information: C:\Windows\Fonts\BOD_B.TTF VolumeInformation
        Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.PWSX-gen.27251.20675.exeQueries volume information: C:\Windows\Fonts\BOD_BI.TTF VolumeInformation
        Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.PWSX-gen.27251.20675.exeQueries volume information: C:\Windows\Fonts\BOD_CR.TTF VolumeInformation
        Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.PWSX-gen.27251.20675.exeQueries volume information: C:\Windows\Fonts\BOD_BLAR.TTF VolumeInformation
        Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.PWSX-gen.27251.20675.exeQueries volume information: C:\Windows\Fonts\BOD_CI.TTF VolumeInformation
        Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.PWSX-gen.27251.20675.exeQueries volume information: C:\Windows\Fonts\BOD_CB.TTF VolumeInformation
        Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.PWSX-gen.27251.20675.exeQueries volume information: C:\Windows\Fonts\BOD_BLAI.TTF VolumeInformation
        Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.PWSX-gen.27251.20675.exeQueries volume information: C:\Windows\Fonts\BOD_CBI.TTF VolumeInformation
        Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.PWSX-gen.27251.20675.exeQueries volume information: C:\Windows\Fonts\ITCBLKAD.TTF VolumeInformation
        Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.PWSX-gen.27251.20675.exeQueries volume information: C:\Windows\Fonts\ARLRDBD.TTF VolumeInformation
        Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.PWSX-gen.27251.20675.exeQueries volume information: C:\Windows\Fonts\AGENCYR.TTF VolumeInformation
        Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.PWSX-gen.27251.20675.exeQueries volume information: C:\Windows\Fonts\AGENCYB.TTF VolumeInformation
        Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.PWSX-gen.27251.20675.exeQueries volume information: C:\Windows\Fonts\BSSYM7.TTF VolumeInformation
        Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.PWSX-gen.27251.20675.exeQueries volume information: C:\Windows\Fonts\REFSAN.TTF VolumeInformation
        Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.PWSX-gen.27251.20675.exeQueries volume information: C:\Windows\Fonts\REFSPCL.TTF VolumeInformation
        Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.PWSX-gen.27251.20675.exeQueries volume information: C:\Windows\Fonts\MTEXTRA.TTF VolumeInformation
        Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.PWSX-gen.27251.20675.exeQueries volume information: C:\Windows\Fonts\marlett.ttf VolumeInformation
        Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.PWSX-gen.27251.20675.exeQueries volume information: C:\Windows\Fonts\SNAP____.TTF VolumeInformation
        Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.PWSX-gen.27251.20675.exeQueries volume information: C:\Windows\Fonts\micross.ttf VolumeInformation
        Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.PWSX-gen.27251.20675.exeQueries volume information: C:\Windows\Fonts\MOD20.TTF VolumeInformation
        Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.PWSX-gen.27251.20675.exeQueries volume information: C:\Windows\Microsoft.NET\assembly\GAC_MSIL\Microsoft.VisualBasic\v4.0_10.0.0.0__b03f5f7f11d50a3a\Microsoft.VisualBasic.dll VolumeInformation
        Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.PWSX-gen.27251.20675.exeKey value queried: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Cryptography MachineGuid

        Stealing of Sensitive Information

        barindex
        Source: Yara matchFile source: 1.0.SecuriteInfo.com.Win32.PWSX-gen.27251.20675.exe.400000.0.unpack, type: UNPACKEDPE
        Source: Yara matchFile source: 00000000.00000002.265052163.0000000004196000.00000004.00000800.00020000.00000000.sdmp, type: MEMORY
        Source: Yara matchFile source: 00000001.00000000.257340997.0000000000401000.00000040.00000400.00020000.00000000.sdmp, type: MEMORY

        Remote Access Functionality

        barindex
        Source: Yara matchFile source: 1.0.SecuriteInfo.com.Win32.PWSX-gen.27251.20675.exe.400000.0.unpack, type: UNPACKEDPE
        Source: Yara matchFile source: 00000000.00000002.265052163.0000000004196000.00000004.00000800.00020000.00000000.sdmp, type: MEMORY
        Source: Yara matchFile source: 00000001.00000000.257340997.0000000000401000.00000040.00000400.00020000.00000000.sdmp, type: MEMORY
        Initial AccessExecutionPersistencePrivilege EscalationDefense EvasionCredential AccessDiscoveryLateral MovementCollectionExfiltrationCommand and ControlNetwork EffectsRemote Service EffectsImpact
        Valid AccountsWindows Management InstrumentationPath Interception111
        Process Injection
        1
        Masquerading
        OS Credential Dumping221
        Security Software Discovery
        Remote Services1
        Archive Collected Data
        Exfiltration Over Other Network Medium1
        Encrypted Channel
        Eavesdrop on Insecure Network CommunicationRemotely Track Device Without AuthorizationModify System Partition
        Default AccountsScheduled Task/JobBoot or Logon Initialization ScriptsBoot or Logon Initialization Scripts1
        Disable or Modify Tools
        LSASS Memory1
        Process Discovery
        Remote Desktop ProtocolData from Removable MediaExfiltration Over Bluetooth1
        Application Layer Protocol
        Exploit SS7 to Redirect Phone Calls/SMSRemotely Wipe Data Without AuthorizationDevice Lockout
        Domain AccountsAt (Linux)Logon Script (Windows)Logon Script (Windows)31
        Virtualization/Sandbox Evasion
        Security Account Manager31
        Virtualization/Sandbox Evasion
        SMB/Windows Admin SharesData from Network Shared DriveAutomated ExfiltrationSteganographyExploit SS7 to Track Device LocationObtain Device Cloud BackupsDelete Device Data
        Local AccountsAt (Windows)Logon Script (Mac)Logon Script (Mac)111
        Process Injection
        NTDS112
        System Information Discovery
        Distributed Component Object ModelInput CaptureScheduled TransferProtocol ImpersonationSIM Card SwapCarrier Billing Fraud
        Cloud AccountsCronNetwork Logon ScriptNetwork Logon Script1
        Deobfuscate/Decode Files or Information
        LSA SecretsRemote System DiscoverySSHKeyloggingData Transfer Size LimitsFallback ChannelsManipulate Device CommunicationManipulate App Store Rankings or Ratings
        Replication Through Removable MediaLaunchdRc.commonRc.common3
        Obfuscated Files or Information
        Cached Domain CredentialsSystem Owner/User DiscoveryVNCGUI Input CaptureExfiltration Over C2 ChannelMultiband CommunicationJamming or Denial of ServiceAbuse Accessibility Features
        External Remote ServicesScheduled TaskStartup ItemsStartup Items3
        Software Packing
        DCSyncNetwork SniffingWindows Remote ManagementWeb Portal CaptureExfiltration Over Alternative ProtocolCommonly Used PortRogue Wi-Fi Access PointsData Encrypted for Impact
        Drive-by CompromiseCommand and Scripting InterpreterScheduled Task/JobScheduled Task/Job1
        Timestomp
        Proc FilesystemNetwork Service ScanningShared WebrootCredential API HookingExfiltration Over Symmetric Encrypted Non-C2 ProtocolApplication Layer ProtocolDowngrade to Insecure ProtocolsGenerate Fraudulent Advertising Revenue
        Hide Legend

        Legend:

        • Process
        • Signature
        • Created File
        • DNS/IP Info
        • Is Dropped
        • Is Windows Process
        • Number of created Registry Values
        • Number of created Files
        • Visual Basic
        • Delphi
        • Java
        • .Net C# or VB.NET
        • C, C++ or other language
        • Is malicious
        • Internet

        This section contains all screenshots as thumbnails, including those not shown in the slideshow.


        windows-stand
        SourceDetectionScannerLabelLink
        SecuriteInfo.com.Win32.PWSX-gen.27251.20675.exe41%ReversingLabsWin32.Trojan.Lazy
        SecuriteInfo.com.Win32.PWSX-gen.27251.20675.exe46%VirustotalBrowse
        SecuriteInfo.com.Win32.PWSX-gen.27251.20675.exe100%Joe Sandbox ML
        No Antivirus matches
        SourceDetectionScannerLabelLinkDownload
        1.0.SecuriteInfo.com.Win32.PWSX-gen.27251.20675.exe.400000.0.unpack100%AviraTR/Crypt.ZPACK.GenDownload File
        No Antivirus matches
        SourceDetectionScannerLabelLink
        http://www.founder.com.cn/cn/bThe0%URL Reputationsafe
        http://www.founder.com.cn/cn/bThe0%URL Reputationsafe
        http://www.tiro.com0%URL Reputationsafe
        http://www.tiro.com0%URL Reputationsafe
        http://www.jiyu-kobo.co.jp/siv0%URL Reputationsafe
        http://www.fontbureau.comessed0%URL Reputationsafe
        http://www.goodfont.co.kr0%URL Reputationsafe
        http://www.carterandcone.com0%URL Reputationsafe
        http://www.sajatypeworks.com0%URL Reputationsafe
        http://www.typography.netD0%URL Reputationsafe
        http://www.typography.netD0%URL Reputationsafe
        http://www.founder.com.cn/cn/cThe0%URL Reputationsafe
        http://www.galapagosdesign.com/staff/dennis.htm0%URL Reputationsafe
        http://fontfabrik.com0%URL Reputationsafe
        http://www.galapagosdesign.com/DPlease0%URL Reputationsafe
        http://www.sandoll.co.kr0%URL Reputationsafe
        http://www.jiyu-kobo.co.jp/#0%URL Reputationsafe
        http://www.urwpp.deDPlease0%URL Reputationsafe
        http://www.zhongyicts.com.cn0%URL Reputationsafe
        http://www.sakkal.com0%URL Reputationsafe
        http://www.fontbureau.comF0%URL Reputationsafe
        http://www.jiyu-kobo.co.jp/vno0%URL Reputationsafe
        http://www.jiyu-kobo.co.jp/M0%URL Reputationsafe
        http://www.jiyu-kobo.co.jp/F0%URL Reputationsafe
        http://www.jiyu-kobo.co.jp/jp/0%URL Reputationsafe
        http://www.fontbureau.coma0%URL Reputationsafe
        http://www.carterandcone.coml0%URL Reputationsafe
        http://www.fontbureau.comi0%URL Reputationsafe
        http://www.founder.com.cn/cn0%URL Reputationsafe
        http://www.fontbureau.comoitu0%URL Reputationsafe
        http://www.monotype.0%URL Reputationsafe
        http://www.fontbureau.comt0%URL Reputationsafe
        http://www.jiyu-kobo.co.jp/0%URL Reputationsafe
        http://www.fontbureau.comce0%URL Reputationsafe
        http://www.fontbureau.comals0%URL Reputationsafe
        http://www.jiyu-kobo.co.jp/b0%URL Reputationsafe
        www.imperiumtowns.xyz/b3es/1%VirustotalBrowse
        http://www.jiyu-kobo.co.jp/Kal10%VirustotalBrowse
        http://www.jiyu-kobo.co.jp/Kal10%Avira URL Cloudsafe
        http://www.jiyu-kobo.co.jp/Y0/i0%Avira URL Cloudsafe
        http://www.fontbureau.comF10%Avira URL Cloudsafe
        http://www.founder.com.cn/cn/-e0%Avira URL Cloudsafe
        www.imperiumtowns.xyz/b3es/0%Avira URL Cloudsafe
        http://www.jiyu-kobo.co.jp/Y0/i0%VirustotalBrowse
        http://www.founder.cm0%Avira URL Cloudsafe
        http://www.fontbureau.comitue0%Avira URL Cloudsafe
        http://www.fontbureau.comB.TTF10%Avira URL Cloudsafe
        http://www.galapagosdesign.com/staff/dennis.htmX0%Avira URL Cloudsafe
        http://www.jiyu-kobo.co.jp/or10%Avira URL Cloudsafe
        http://www.fontbureau.comicom0%Avira URL Cloudsafe
        No contacted domains info
        NameMaliciousAntivirus DetectionReputation
        www.imperiumtowns.xyz/b3es/true
        • 1%, Virustotal, Browse
        • Avira URL Cloud: safe
        low
        NameSourceMaliciousAntivirus DetectionReputation
        http://www.fontbureau.com/designersGSecuriteInfo.com.Win32.PWSX-gen.27251.20675.exe, 00000000.00000002.266762478.0000000007222000.00000004.00000800.00020000.00000000.sdmpfalse
          high
          http://www.fontbureau.com/designers/?SecuriteInfo.com.Win32.PWSX-gen.27251.20675.exe, 00000000.00000002.266762478.0000000007222000.00000004.00000800.00020000.00000000.sdmpfalse
            high
            http://www.founder.com.cn/cn/bTheSecuriteInfo.com.Win32.PWSX-gen.27251.20675.exe, 00000000.00000002.266762478.0000000007222000.00000004.00000800.00020000.00000000.sdmpfalse
            • URL Reputation: safe
            • URL Reputation: safe
            unknown
            http://www.fontbureau.com/designers?SecuriteInfo.com.Win32.PWSX-gen.27251.20675.exe, 00000000.00000002.266762478.0000000007222000.00000004.00000800.00020000.00000000.sdmpfalse
              high
              http://www.tiro.comSecuriteInfo.com.Win32.PWSX-gen.27251.20675.exe, 00000000.00000002.266762478.0000000007222000.00000004.00000800.00020000.00000000.sdmpfalse
              • URL Reputation: safe
              • URL Reputation: safe
              unknown
              http://www.jiyu-kobo.co.jp/sivSecuriteInfo.com.Win32.PWSX-gen.27251.20675.exe, 00000000.00000003.248773244.0000000006015000.00000004.00000800.00020000.00000000.sdmpfalse
              • URL Reputation: safe
              unknown
              http://www.jiyu-kobo.co.jp/Kal1SecuriteInfo.com.Win32.PWSX-gen.27251.20675.exe, 00000000.00000003.249668471.0000000006022000.00000004.00000800.00020000.00000000.sdmp, SecuriteInfo.com.Win32.PWSX-gen.27251.20675.exe, 00000000.00000003.249560073.0000000006028000.00000004.00000800.00020000.00000000.sdmp, SecuriteInfo.com.Win32.PWSX-gen.27251.20675.exe, 00000000.00000003.249774268.0000000006022000.00000004.00000800.00020000.00000000.sdmp, SecuriteInfo.com.Win32.PWSX-gen.27251.20675.exe, 00000000.00000003.249059141.0000000006028000.00000004.00000800.00020000.00000000.sdmpfalse
              • 0%, Virustotal, Browse
              • Avira URL Cloud: safe
              unknown
              http://www.fontbureau.com/designersSecuriteInfo.com.Win32.PWSX-gen.27251.20675.exe, 00000000.00000002.266762478.0000000007222000.00000004.00000800.00020000.00000000.sdmpfalse
                high
                http://www.fontbureau.comessedSecuriteInfo.com.Win32.PWSX-gen.27251.20675.exe, 00000000.00000003.250428092.0000000006028000.00000004.00000800.00020000.00000000.sdmp, SecuriteInfo.com.Win32.PWSX-gen.27251.20675.exe, 00000000.00000003.250339759.0000000006027000.00000004.00000800.00020000.00000000.sdmpfalse
                • URL Reputation: safe
                unknown
                http://www.goodfont.co.krSecuriteInfo.com.Win32.PWSX-gen.27251.20675.exe, 00000000.00000002.266762478.0000000007222000.00000004.00000800.00020000.00000000.sdmpfalse
                • URL Reputation: safe
                unknown
                http://www.carterandcone.comSecuriteInfo.com.Win32.PWSX-gen.27251.20675.exe, 00000000.00000003.248951472.0000000006016000.00000004.00000800.00020000.00000000.sdmp, SecuriteInfo.com.Win32.PWSX-gen.27251.20675.exe, 00000000.00000003.249535557.0000000006017000.00000004.00000800.00020000.00000000.sdmp, SecuriteInfo.com.Win32.PWSX-gen.27251.20675.exe, 00000000.00000003.248773244.0000000006015000.00000004.00000800.00020000.00000000.sdmp, SecuriteInfo.com.Win32.PWSX-gen.27251.20675.exe, 00000000.00000003.249659691.000000000601C000.00000004.00000800.00020000.00000000.sdmp, SecuriteInfo.com.Win32.PWSX-gen.27251.20675.exe, 00000000.00000003.249765760.000000000601C000.00000004.00000800.00020000.00000000.sdmpfalse
                • URL Reputation: safe
                unknown
                http://www.sajatypeworks.comSecuriteInfo.com.Win32.PWSX-gen.27251.20675.exe, 00000000.00000002.266762478.0000000007222000.00000004.00000800.00020000.00000000.sdmpfalse
                • URL Reputation: safe
                unknown
                http://www.typography.netDSecuriteInfo.com.Win32.PWSX-gen.27251.20675.exe, 00000000.00000002.266762478.0000000007222000.00000004.00000800.00020000.00000000.sdmpfalse
                • URL Reputation: safe
                • URL Reputation: safe
                unknown
                http://www.founder.com.cn/cn/cTheSecuriteInfo.com.Win32.PWSX-gen.27251.20675.exe, 00000000.00000002.266762478.0000000007222000.00000004.00000800.00020000.00000000.sdmpfalse
                • URL Reputation: safe
                unknown
                http://www.galapagosdesign.com/staff/dennis.htmSecuriteInfo.com.Win32.PWSX-gen.27251.20675.exe, 00000000.00000002.266762478.0000000007222000.00000004.00000800.00020000.00000000.sdmpfalse
                • URL Reputation: safe
                unknown
                http://fontfabrik.comSecuriteInfo.com.Win32.PWSX-gen.27251.20675.exe, 00000000.00000002.266762478.0000000007222000.00000004.00000800.00020000.00000000.sdmpfalse
                • URL Reputation: safe
                unknown
                http://www.founder.com.cn/cn/-eSecuriteInfo.com.Win32.PWSX-gen.27251.20675.exe, 00000000.00000003.247855685.000000000601A000.00000004.00000800.00020000.00000000.sdmpfalse
                • Avira URL Cloud: safe
                unknown
                http://www.fontbureau.comF1SecuriteInfo.com.Win32.PWSX-gen.27251.20675.exe, 00000000.00000003.250551871.0000000006027000.00000004.00000800.00020000.00000000.sdmpfalse
                • Avira URL Cloud: safe
                unknown
                http://www.jiyu-kobo.co.jp/Y0/iSecuriteInfo.com.Win32.PWSX-gen.27251.20675.exe, 00000000.00000003.249668471.0000000006022000.00000004.00000800.00020000.00000000.sdmp, SecuriteInfo.com.Win32.PWSX-gen.27251.20675.exe, 00000000.00000003.249560073.0000000006028000.00000004.00000800.00020000.00000000.sdmp, SecuriteInfo.com.Win32.PWSX-gen.27251.20675.exe, 00000000.00000003.249774268.0000000006022000.00000004.00000800.00020000.00000000.sdmpfalse
                • 0%, Virustotal, Browse
                • Avira URL Cloud: safe
                unknown
                http://www.galapagosdesign.com/DPleaseSecuriteInfo.com.Win32.PWSX-gen.27251.20675.exe, 00000000.00000002.266762478.0000000007222000.00000004.00000800.00020000.00000000.sdmpfalse
                • URL Reputation: safe
                unknown
                http://www.fonts.comSecuriteInfo.com.Win32.PWSX-gen.27251.20675.exe, 00000000.00000002.266762478.0000000007222000.00000004.00000800.00020000.00000000.sdmpfalse
                  high
                  http://www.sandoll.co.krSecuriteInfo.com.Win32.PWSX-gen.27251.20675.exe, 00000000.00000002.266762478.0000000007222000.00000004.00000800.00020000.00000000.sdmpfalse
                  • URL Reputation: safe
                  unknown
                  http://www.founder.cmSecuriteInfo.com.Win32.PWSX-gen.27251.20675.exe, 00000000.00000003.247878242.0000000006028000.00000004.00000800.00020000.00000000.sdmpfalse
                  • Avira URL Cloud: safe
                  unknown
                  http://www.jiyu-kobo.co.jp/#SecuriteInfo.com.Win32.PWSX-gen.27251.20675.exe, 00000000.00000003.249668471.0000000006022000.00000004.00000800.00020000.00000000.sdmp, SecuriteInfo.com.Win32.PWSX-gen.27251.20675.exe, 00000000.00000003.249560073.0000000006028000.00000004.00000800.00020000.00000000.sdmp, SecuriteInfo.com.Win32.PWSX-gen.27251.20675.exe, 00000000.00000003.248773244.0000000006015000.00000004.00000800.00020000.00000000.sdmp, SecuriteInfo.com.Win32.PWSX-gen.27251.20675.exe, 00000000.00000003.249774268.0000000006022000.00000004.00000800.00020000.00000000.sdmp, SecuriteInfo.com.Win32.PWSX-gen.27251.20675.exe, 00000000.00000003.249059141.0000000006028000.00000004.00000800.00020000.00000000.sdmpfalse
                  • URL Reputation: safe
                  unknown
                  http://www.urwpp.deDPleaseSecuriteInfo.com.Win32.PWSX-gen.27251.20675.exe, 00000000.00000002.266762478.0000000007222000.00000004.00000800.00020000.00000000.sdmpfalse
                  • URL Reputation: safe
                  unknown
                  http://www.zhongyicts.com.cnSecuriteInfo.com.Win32.PWSX-gen.27251.20675.exe, 00000000.00000002.266762478.0000000007222000.00000004.00000800.00020000.00000000.sdmpfalse
                  • URL Reputation: safe
                  unknown
                  http://www.sakkal.comSecuriteInfo.com.Win32.PWSX-gen.27251.20675.exe, 00000000.00000002.266762478.0000000007222000.00000004.00000800.00020000.00000000.sdmpfalse
                  • URL Reputation: safe
                  unknown
                  http://www.galapagosdesign.com/staff/dennis.htmXSecuriteInfo.com.Win32.PWSX-gen.27251.20675.exe, 00000000.00000003.250848136.0000000006027000.00000004.00000800.00020000.00000000.sdmpfalse
                  • Avira URL Cloud: safe
                  unknown
                  http://www.apache.org/licenses/LICENSE-2.0SecuriteInfo.com.Win32.PWSX-gen.27251.20675.exe, 00000000.00000002.266762478.0000000007222000.00000004.00000800.00020000.00000000.sdmpfalse
                    high
                    http://www.fontbureau.comSecuriteInfo.com.Win32.PWSX-gen.27251.20675.exe, 00000000.00000002.266762478.0000000007222000.00000004.00000800.00020000.00000000.sdmpfalse
                      high
                      http://www.fontbureau.comitueSecuriteInfo.com.Win32.PWSX-gen.27251.20675.exe, 00000000.00000003.250428092.0000000006028000.00000004.00000800.00020000.00000000.sdmpfalse
                      • Avira URL Cloud: safe
                      unknown
                      http://www.fontbureau.comFSecuriteInfo.com.Win32.PWSX-gen.27251.20675.exe, 00000000.00000003.250551871.0000000006027000.00000004.00000800.00020000.00000000.sdmp, SecuriteInfo.com.Win32.PWSX-gen.27251.20675.exe, 00000000.00000003.250428092.0000000006028000.00000004.00000800.00020000.00000000.sdmp, SecuriteInfo.com.Win32.PWSX-gen.27251.20675.exe, 00000000.00000003.250339759.0000000006027000.00000004.00000800.00020000.00000000.sdmpfalse
                      • URL Reputation: safe
                      unknown
                      http://www.jiyu-kobo.co.jp/or1SecuriteInfo.com.Win32.PWSX-gen.27251.20675.exe, 00000000.00000003.249668471.0000000006022000.00000004.00000800.00020000.00000000.sdmp, SecuriteInfo.com.Win32.PWSX-gen.27251.20675.exe, 00000000.00000003.249774268.0000000006022000.00000004.00000800.00020000.00000000.sdmpfalse
                      • Avira URL Cloud: safe
                      unknown
                      http://www.jiyu-kobo.co.jp/vnoSecuriteInfo.com.Win32.PWSX-gen.27251.20675.exe, 00000000.00000003.249668471.0000000006022000.00000004.00000800.00020000.00000000.sdmp, SecuriteInfo.com.Win32.PWSX-gen.27251.20675.exe, 00000000.00000003.249560073.0000000006028000.00000004.00000800.00020000.00000000.sdmp, SecuriteInfo.com.Win32.PWSX-gen.27251.20675.exe, 00000000.00000003.248773244.0000000006015000.00000004.00000800.00020000.00000000.sdmp, SecuriteInfo.com.Win32.PWSX-gen.27251.20675.exe, 00000000.00000003.249774268.0000000006022000.00000004.00000800.00020000.00000000.sdmp, SecuriteInfo.com.Win32.PWSX-gen.27251.20675.exe, 00000000.00000003.249059141.0000000006028000.00000004.00000800.00020000.00000000.sdmpfalse
                      • URL Reputation: safe
                      unknown
                      http://www.jiyu-kobo.co.jp/MSecuriteInfo.com.Win32.PWSX-gen.27251.20675.exe, 00000000.00000003.249668471.0000000006022000.00000004.00000800.00020000.00000000.sdmp, SecuriteInfo.com.Win32.PWSX-gen.27251.20675.exe, 00000000.00000003.249560073.0000000006028000.00000004.00000800.00020000.00000000.sdmpfalse
                      • URL Reputation: safe
                      unknown
                      http://www.jiyu-kobo.co.jp/FSecuriteInfo.com.Win32.PWSX-gen.27251.20675.exe, 00000000.00000003.249059141.0000000006028000.00000004.00000800.00020000.00000000.sdmpfalse
                      • URL Reputation: safe
                      unknown
                      http://www.jiyu-kobo.co.jp/jp/SecuriteInfo.com.Win32.PWSX-gen.27251.20675.exe, 00000000.00000003.249774268.0000000006022000.00000004.00000800.00020000.00000000.sdmp, SecuriteInfo.com.Win32.PWSX-gen.27251.20675.exe, 00000000.00000003.249059141.0000000006028000.00000004.00000800.00020000.00000000.sdmpfalse
                      • URL Reputation: safe
                      unknown
                      http://www.fontbureau.comaSecuriteInfo.com.Win32.PWSX-gen.27251.20675.exe, 00000000.00000003.250551871.0000000006027000.00000004.00000800.00020000.00000000.sdmp, SecuriteInfo.com.Win32.PWSX-gen.27251.20675.exe, 00000000.00000003.258838031.0000000006022000.00000004.00000800.00020000.00000000.sdmp, SecuriteInfo.com.Win32.PWSX-gen.27251.20675.exe, 00000000.00000003.250428092.0000000006028000.00000004.00000800.00020000.00000000.sdmp, SecuriteInfo.com.Win32.PWSX-gen.27251.20675.exe, 00000000.00000002.266638604.0000000006027000.00000004.00000800.00020000.00000000.sdmp, SecuriteInfo.com.Win32.PWSX-gen.27251.20675.exe, 00000000.00000003.250339759.0000000006027000.00000004.00000800.00020000.00000000.sdmpfalse
                      • URL Reputation: safe
                      unknown
                      http://www.carterandcone.comlSecuriteInfo.com.Win32.PWSX-gen.27251.20675.exe, 00000000.00000002.266762478.0000000007222000.00000004.00000800.00020000.00000000.sdmpfalse
                      • URL Reputation: safe
                      unknown
                      http://www.fontbureau.com/designers/cabarga.htmlNSecuriteInfo.com.Win32.PWSX-gen.27251.20675.exe, 00000000.00000002.266762478.0000000007222000.00000004.00000800.00020000.00000000.sdmpfalse
                        high
                        http://www.fontbureau.comiSecuriteInfo.com.Win32.PWSX-gen.27251.20675.exe, 00000000.00000003.250339759.0000000006027000.00000004.00000800.00020000.00000000.sdmpfalse
                        • URL Reputation: safe
                        unknown
                        http://www.founder.com.cn/cnSecuriteInfo.com.Win32.PWSX-gen.27251.20675.exe, 00000000.00000002.266762478.0000000007222000.00000004.00000800.00020000.00000000.sdmp, SecuriteInfo.com.Win32.PWSX-gen.27251.20675.exe, 00000000.00000003.247855685.000000000601A000.00000004.00000800.00020000.00000000.sdmp, SecuriteInfo.com.Win32.PWSX-gen.27251.20675.exe, 00000000.00000003.247400149.000000000602B000.00000004.00000800.00020000.00000000.sdmpfalse
                        • URL Reputation: safe
                        unknown
                        http://www.fontbureau.com/designers/frere-jones.htmlSecuriteInfo.com.Win32.PWSX-gen.27251.20675.exe, 00000000.00000002.266762478.0000000007222000.00000004.00000800.00020000.00000000.sdmpfalse
                          high
                          http://www.fontbureau.comoituSecuriteInfo.com.Win32.PWSX-gen.27251.20675.exe, 00000000.00000003.250339759.0000000006027000.00000004.00000800.00020000.00000000.sdmpfalse
                          • URL Reputation: safe
                          unknown
                          http://www.fontbureau.comB.TTF1SecuriteInfo.com.Win32.PWSX-gen.27251.20675.exe, 00000000.00000003.250428092.0000000006028000.00000004.00000800.00020000.00000000.sdmp, SecuriteInfo.com.Win32.PWSX-gen.27251.20675.exe, 00000000.00000003.250339759.0000000006027000.00000004.00000800.00020000.00000000.sdmpfalse
                          • Avira URL Cloud: safe
                          unknown
                          http://www.monotype.SecuriteInfo.com.Win32.PWSX-gen.27251.20675.exe, 00000000.00000002.266638604.0000000006027000.00000004.00000800.00020000.00000000.sdmpfalse
                          • URL Reputation: safe
                          unknown
                          http://www.fontbureau.comtSecuriteInfo.com.Win32.PWSX-gen.27251.20675.exe, 00000000.00000003.250428092.0000000006028000.00000004.00000800.00020000.00000000.sdmpfalse
                          • URL Reputation: safe
                          unknown
                          http://www.jiyu-kobo.co.jp/SecuriteInfo.com.Win32.PWSX-gen.27251.20675.exe, 00000000.00000003.249668471.0000000006022000.00000004.00000800.00020000.00000000.sdmp, SecuriteInfo.com.Win32.PWSX-gen.27251.20675.exe, 00000000.00000002.266762478.0000000007222000.00000004.00000800.00020000.00000000.sdmp, SecuriteInfo.com.Win32.PWSX-gen.27251.20675.exe, 00000000.00000003.249560073.0000000006028000.00000004.00000800.00020000.00000000.sdmp, SecuriteInfo.com.Win32.PWSX-gen.27251.20675.exe, 00000000.00000003.248773244.0000000006015000.00000004.00000800.00020000.00000000.sdmp, SecuriteInfo.com.Win32.PWSX-gen.27251.20675.exe, 00000000.00000003.249774268.0000000006022000.00000004.00000800.00020000.00000000.sdmp, SecuriteInfo.com.Win32.PWSX-gen.27251.20675.exe, 00000000.00000003.249059141.0000000006028000.00000004.00000800.00020000.00000000.sdmpfalse
                          • URL Reputation: safe
                          unknown
                          http://www.fontbureau.com/designers8SecuriteInfo.com.Win32.PWSX-gen.27251.20675.exe, 00000000.00000002.266762478.0000000007222000.00000004.00000800.00020000.00000000.sdmpfalse
                            high
                            http://www.fontbureau.comceSecuriteInfo.com.Win32.PWSX-gen.27251.20675.exe, 00000000.00000003.258838031.0000000006022000.00000004.00000800.00020000.00000000.sdmp, SecuriteInfo.com.Win32.PWSX-gen.27251.20675.exe, 00000000.00000002.266638604.0000000006027000.00000004.00000800.00020000.00000000.sdmpfalse
                            • URL Reputation: safe
                            unknown
                            http://www.fontbureau.comalsSecuriteInfo.com.Win32.PWSX-gen.27251.20675.exe, 00000000.00000003.250551871.0000000006027000.00000004.00000800.00020000.00000000.sdmpfalse
                            • URL Reputation: safe
                            unknown
                            http://www.jiyu-kobo.co.jp/bSecuriteInfo.com.Win32.PWSX-gen.27251.20675.exe, 00000000.00000003.249668471.0000000006022000.00000004.00000800.00020000.00000000.sdmp, SecuriteInfo.com.Win32.PWSX-gen.27251.20675.exe, 00000000.00000003.249560073.0000000006028000.00000004.00000800.00020000.00000000.sdmp, SecuriteInfo.com.Win32.PWSX-gen.27251.20675.exe, 00000000.00000003.249774268.0000000006022000.00000004.00000800.00020000.00000000.sdmp, SecuriteInfo.com.Win32.PWSX-gen.27251.20675.exe, 00000000.00000003.249059141.0000000006028000.00000004.00000800.00020000.00000000.sdmpfalse
                            • URL Reputation: safe
                            unknown
                            http://www.fontbureau.comicomSecuriteInfo.com.Win32.PWSX-gen.27251.20675.exe, 00000000.00000003.258838031.0000000006022000.00000004.00000800.00020000.00000000.sdmp, SecuriteInfo.com.Win32.PWSX-gen.27251.20675.exe, 00000000.00000002.266638604.0000000006027000.00000004.00000800.00020000.00000000.sdmpfalse
                            • Avira URL Cloud: safe
                            unknown
                            No contacted IP infos
                            Joe Sandbox Version:36.0.0 Rainbow Opal
                            Analysis ID:755946
                            Start date and time:2022-11-29 10:44:30 +01:00
                            Joe Sandbox Product:CloudBasic
                            Overall analysis duration:0h 6m 12s
                            Hypervisor based Inspection enabled:false
                            Report type:light
                            Sample file name:SecuriteInfo.com.Win32.PWSX-gen.27251.20675.exe
                            Cookbook file name:default.jbs
                            Analysis system description:Windows 10 64 bit v1803 with Office Professional Plus 2016, Chrome 104, IE 11, Adobe Reader DC 19, Java 8 Update 211
                            Number of analysed new started processes analysed:2
                            Number of new started drivers analysed:0
                            Number of existing processes analysed:0
                            Number of existing drivers analysed:0
                            Number of injected processes analysed:0
                            Technologies:
                            • HCA enabled
                            • EGA enabled
                            • HDC enabled
                            • AMSI enabled
                            Analysis Mode:default
                            Analysis stop reason:Timeout
                            Detection:MAL
                            Classification:mal92.troj.evad.winEXE@3/1@0/0
                            EGA Information:
                            • Successful, ratio: 100%
                            HDC Information:
                            • Successful, ratio: 100% (good quality ratio 90.5%)
                            • Quality average: 75.2%
                            • Quality standard deviation: 30.7%
                            HCA Information:
                            • Successful, ratio: 100%
                            • Number of executed functions: 0
                            • Number of non-executed functions: 0
                            Cookbook Comments:
                            • Found application associated with file extension: .exe
                            • Stop behavior analysis, all processes terminated
                            • Excluded domains from analysis (whitelisted): fs.microsoft.com
                            • Report creation exceeded maximum time and may have missing disassembly code information.
                            • Report size getting too big, too many NtAllocateVirtualMemory calls found.
                            TimeTypeDescription
                            10:45:31API Interceptor1x Sleep call for process: SecuriteInfo.com.Win32.PWSX-gen.27251.20675.exe modified
                            No context
                            No context
                            No context
                            No context
                            No context
                            Process:C:\Users\user\Desktop\SecuriteInfo.com.Win32.PWSX-gen.27251.20675.exe
                            File Type:ASCII text, with CRLF line terminators
                            Category:dropped
                            Size (bytes):1216
                            Entropy (8bit):5.355304211458859
                            Encrypted:false
                            SSDEEP:24:MLUE4K5E4Ks2E1qE4qXKDE4KhK3VZ9pKhPKIE4oKFKHKoZAE4Kzr7FE4x84j:MIHK5HKXE1qHiYHKhQnoPtHoxHhAHKzr
                            MD5:FED34146BF2F2FA59DCF8702FCC8232E
                            SHA1:B03BFEA175989D989850CF06FE5E7BBF56EAA00A
                            SHA-256:123BE4E3590609A008E85501243AF5BC53FA0C26C82A92881B8879524F8C0D5C
                            SHA-512:1CC89F2ED1DBD70628FA1DC41A32BA0BFA3E81EAE1A1CF3C5F6A48F2DA0BF1F21A5001B8A18B04043C5B8FE4FBE663068D86AA8C4BD8E17933F75687C3178FF6
                            Malicious:true
                            Reputation:high, very likely benign file
                            Preview:1,"fusion","GAC",0..1,"WinRT","NotApp",1..2,"System.Windows.Forms, Version=4.0.0.0, Culture=neutral, PublicKeyToken=b77a5c561934e089",0..3,"System, Version=4.0.0.0, Culture=neutral, PublicKeyToken=b77a5c561934e089","C:\Windows\assembly\NativeImages_v4.0.30319_32\System\4f0a7eefa3cd3e0ba98b5ebddbbc72e6\System.ni.dll",0..2,"System.Drawing, Version=4.0.0.0, Culture=neutral, PublicKeyToken=b03f5f7f11d50a3a",0..3,"System.Core, Version=4.0.0.0, Culture=neutral, PublicKeyToken=b77a5c561934e089","C:\Windows\assembly\NativeImages_v4.0.30319_32\System.Core\f1d8480152e0da9a60ad49c6d16a3b6d\System.Core.ni.dll",0..3,"System.Configuration, Version=4.0.0.0, Culture=neutral, PublicKeyToken=b03f5f7f11d50a3a","C:\Windows\assembly\NativeImages_v4.0.30319_32\System.Configuration\8d67d92724ba494b6c7fd089d6f25b48\System.Configuration.ni.dll",0..3,"System.Xml, Version=4.0.0.0, Culture=neutral, PublicKeyToken=b77a5c561934e089","C:\Windows\assembly\NativeImages_v4.0.30319_32\System.Xml\b219d4630d26b88041b59c21
                            File type:PE32 executable (GUI) Intel 80386 Mono/.Net assembly, for MS Windows
                            Entropy (8bit):7.824187241753943
                            TrID:
                            • Win32 Executable (generic) Net Framework (10011505/4) 49.80%
                            • Win32 Executable (generic) a (10002005/4) 49.75%
                            • Generic CIL Executable (.NET, Mono, etc.) (73296/58) 0.36%
                            • Windows Screen Saver (13104/52) 0.07%
                            • Generic Win/DOS Executable (2004/3) 0.01%
                            File name:SecuriteInfo.com.Win32.PWSX-gen.27251.20675.exe
                            File size:935424
                            MD5:7b6dcd6fcd1c26b9abdba167929f4c82
                            SHA1:04f11f07ef4a51b16383b5dde94f1af405893b45
                            SHA256:e38f6fab27253171688423b0792d38be81e4c01cceb35c7bca05d2ebfc011ae9
                            SHA512:0a12c658607c69b203f3674a6097b86b925e29d00003b4e1c975e5bd09894eba722af22ced22c0c01ca555657eaa7251a908f36e0fabfe2f521aad9124d6b942
                            SSDEEP:12288:pe+QDdzoa1cfNv+/O/OW9HiiwdIvL94CsAH0vJHlAMMLOV8SWRdXZIQFhZMRR3im:qDdEPflOO/OW9CkL9/fDxiMR/phUz
                            TLSH:3815026D32A45381E7190FB66BA7814853397DBFF8D1D71E2989B29F097CB908201F27
                            File Content Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.......PE..L....1................0..>...........\... ...`....@.. ....................................@................................
                            Icon Hash:00828e8e8686b000
                            Entrypoint:0x4e5c9a
                            Entrypoint Section:.text
                            Digitally signed:false
                            Imagebase:0x400000
                            Subsystem:windows gui
                            Image File Characteristics:EXECUTABLE_IMAGE, 32BIT_MACHINE
                            DLL Characteristics:DYNAMIC_BASE, NX_COMPAT, NO_SEH, TERMINAL_SERVER_AWARE
                            Time Stamp:0xBF0A3116 [Sun Jul 26 06:03:02 2071 UTC]
                            TLS Callbacks:
                            CLR (.Net) Version:
                            OS Version Major:4
                            OS Version Minor:0
                            File Version Major:4
                            File Version Minor:0
                            Subsystem Version Major:4
                            Subsystem Version Minor:0
                            Import Hash:f34d5f2d4577ed6d9ceec516c1f5a744
                            Instruction
                            jmp dword ptr [00402000h]
                            add byte ptr [eax], al
                            add byte ptr [eax], al
                            add byte ptr [eax], al
                            add byte ptr [eax], al
                            add byte ptr [eax], al
                            add byte ptr [eax], al
                            add byte ptr [eax], al
                            add byte ptr [eax], al
                            add byte ptr [eax], al
                            add byte ptr [eax], al
                            add byte ptr [eax], al
                            add byte ptr [eax], al
                            add byte ptr [eax], al
                            add byte ptr [eax], al
                            add byte ptr [eax], al
                            add byte ptr [eax], al
                            add byte ptr [eax], al
                            add byte ptr [eax], al
                            add byte ptr [eax], al
                            add byte ptr [eax], al
                            add byte ptr [eax], al
                            add byte ptr [eax], al
                            add byte ptr [eax], al
                            add byte ptr [eax], al
                            add byte ptr [eax], al
                            add byte ptr [eax], al
                            add byte ptr [eax], al
                            add byte ptr [eax], al
                            add byte ptr [eax], al
                            add byte ptr [eax], al
                            add byte ptr [eax], al
                            add byte ptr [eax], al
                            add byte ptr [eax], al
                            add byte ptr [eax], al
                            add byte ptr [eax], al
                            add byte ptr [eax], al
                            add byte ptr [eax], al
                            add byte ptr [eax], al
                            add byte ptr [eax], al
                            add byte ptr [eax], al
                            add byte ptr [eax], al
                            add byte ptr [eax], al
                            add byte ptr [eax], al
                            add byte ptr [eax], al
                            add byte ptr [eax], al
                            add byte ptr [eax], al
                            add byte ptr [eax], al
                            add byte ptr [eax], al
                            add byte ptr [eax], al
                            add byte ptr [eax], al
                            add byte ptr [eax], al
                            add byte ptr [eax], al
                            add byte ptr [eax], al
                            add byte ptr [eax], al
                            add byte ptr [eax], al
                            add byte ptr [eax], al
                            add byte ptr [eax], al
                            add byte ptr [eax], al
                            add byte ptr [eax], al
                            add byte ptr [eax], al
                            add byte ptr [eax], al
                            add byte ptr [eax], al
                            add byte ptr [eax], al
                            add byte ptr [eax], al
                            add byte ptr [eax], al
                            add byte ptr [eax], al
                            add byte ptr [eax], al
                            add byte ptr [eax], al
                            add byte ptr [eax], al
                            add byte ptr [eax], al
                            add byte ptr [eax], al
                            add byte ptr [eax], al
                            add byte ptr [eax], al
                            add byte ptr [eax], al
                            add byte ptr [eax], al
                            add byte ptr [eax], al
                            add byte ptr [eax], al
                            add byte ptr [eax], al
                            add byte ptr [eax], al
                            add byte ptr [eax], al
                            add byte ptr [eax], al
                            add byte ptr [eax], al
                            add byte ptr [eax], al
                            add byte ptr [eax], al
                            add byte ptr [eax], al
                            add byte ptr [eax], al
                            add byte ptr [eax], al
                            add byte ptr [eax], al
                            add byte ptr [eax], al
                            add byte ptr [eax], al
                            add byte ptr [eax], al
                            add byte ptr [eax], al
                            add byte ptr [eax], al
                            add byte ptr [eax], al
                            add byte ptr [eax], al
                            add byte ptr [eax], al
                            add byte ptr [eax], al
                            NameVirtual AddressVirtual Size Is in Section
                            IMAGE_DIRECTORY_ENTRY_EXPORT0x00x0
                            IMAGE_DIRECTORY_ENTRY_IMPORT0xe5c480x4f.text
                            IMAGE_DIRECTORY_ENTRY_RESOURCE0xe60000x390.rsrc
                            IMAGE_DIRECTORY_ENTRY_EXCEPTION0x00x0
                            IMAGE_DIRECTORY_ENTRY_SECURITY0x00x0
                            IMAGE_DIRECTORY_ENTRY_BASERELOC0xe80000xc.reloc
                            IMAGE_DIRECTORY_ENTRY_DEBUG0xe5c2c0x1c.text
                            IMAGE_DIRECTORY_ENTRY_COPYRIGHT0x00x0
                            IMAGE_DIRECTORY_ENTRY_GLOBALPTR0x00x0
                            IMAGE_DIRECTORY_ENTRY_TLS0x00x0
                            IMAGE_DIRECTORY_ENTRY_LOAD_CONFIG0x00x0
                            IMAGE_DIRECTORY_ENTRY_BOUND_IMPORT0x00x0
                            IMAGE_DIRECTORY_ENTRY_IAT0x20000x8.text
                            IMAGE_DIRECTORY_ENTRY_DELAY_IMPORT0x00x0
                            IMAGE_DIRECTORY_ENTRY_COM_DESCRIPTOR0x20080x48.text
                            IMAGE_DIRECTORY_ENTRY_RESERVED0x00x0
                            NameVirtual AddressVirtual SizeRaw SizeXored PEZLIB ComplexityFile TypeEntropyCharacteristics
                            .text0x20000xe3ca00xe3e00False0.8989110497805815data7.830178117653337IMAGE_SCN_CNT_CODE, IMAGE_SCN_MEM_EXECUTE, IMAGE_SCN_MEM_READ
                            .rsrc0xe60000x3900x400False0.3779296875data2.88981025898553IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_READ
                            .reloc0xe80000xc0x200False0.044921875data0.10191042566270775IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_DISCARDABLE, IMAGE_SCN_MEM_READ
                            NameRVASizeTypeLanguageCountry
                            RT_VERSION0xe60580x334data
                            DLLImport
                            mscoree.dll_CorExeMain
                            No network behavior found

                            Click to jump to process

                            Target ID:0
                            Start time:10:45:26
                            Start date:29/11/2022
                            Path:C:\Users\user\Desktop\SecuriteInfo.com.Win32.PWSX-gen.27251.20675.exe
                            Wow64 process (32bit):true
                            Commandline:C:\Users\user\Desktop\SecuriteInfo.com.Win32.PWSX-gen.27251.20675.exe
                            Imagebase:0xcc0000
                            File size:935424 bytes
                            MD5 hash:7B6DCD6FCD1C26B9ABDBA167929F4C82
                            Has elevated privileges:true
                            Has administrator privileges:true
                            Programmed in:.Net C# or VB.NET
                            Yara matches:
                            • Rule: JoeSecurity_AntiVM_3, Description: Yara detected AntiVM_3, Source: 00000000.00000002.260745770.0000000003051000.00000004.00000800.00020000.00000000.sdmp, Author: Joe Security
                            • Rule: JoeSecurity_FormBook, Description: Yara detected FormBook, Source: 00000000.00000002.265052163.0000000004196000.00000004.00000800.00020000.00000000.sdmp, Author: Joe Security
                            • Rule: Windows_Trojan_Formbook_1112e116, Description: unknown, Source: 00000000.00000002.265052163.0000000004196000.00000004.00000800.00020000.00000000.sdmp, Author: unknown
                            • Rule: Formbook_1, Description: autogenerated rule brought to you by yara-signator, Source: 00000000.00000002.265052163.0000000004196000.00000004.00000800.00020000.00000000.sdmp, Author: Felix Bilstein - yara-signator at cocacoding dot com
                            • Rule: Formbook, Description: detect Formbook in memory, Source: 00000000.00000002.265052163.0000000004196000.00000004.00000800.00020000.00000000.sdmp, Author: JPCERT/CC Incident Response Group
                            Reputation:low

                            Target ID:1
                            Start time:10:45:33
                            Start date:29/11/2022
                            Path:C:\Users\user\Desktop\SecuriteInfo.com.Win32.PWSX-gen.27251.20675.exe
                            Wow64 process (32bit):true
                            Commandline:C:\Users\user\Desktop\SecuriteInfo.com.Win32.PWSX-gen.27251.20675.exe
                            Imagebase:0x520000
                            File size:935424 bytes
                            MD5 hash:7B6DCD6FCD1C26B9ABDBA167929F4C82
                            Has elevated privileges:true
                            Has administrator privileges:true
                            Programmed in:C, C++ or other language
                            Yara matches:
                            • Rule: JoeSecurity_FormBook, Description: Yara detected FormBook, Source: 00000001.00000000.257340997.0000000000401000.00000040.00000400.00020000.00000000.sdmp, Author: Joe Security
                            • Rule: Windows_Trojan_Formbook_1112e116, Description: unknown, Source: 00000001.00000000.257340997.0000000000401000.00000040.00000400.00020000.00000000.sdmp, Author: unknown
                            • Rule: Formbook_1, Description: autogenerated rule brought to you by yara-signator, Source: 00000001.00000000.257340997.0000000000401000.00000040.00000400.00020000.00000000.sdmp, Author: Felix Bilstein - yara-signator at cocacoding dot com
                            • Rule: Formbook, Description: detect Formbook in memory, Source: 00000001.00000000.257340997.0000000000401000.00000040.00000400.00020000.00000000.sdmp, Author: JPCERT/CC Incident Response Group
                            Reputation:low

                            No disassembly