Loading ...

Play interactive tourEdit tour

Analysis Report INV 3326GHF- from Outriger General Importers Korea for acknowledgment.jar

Overview

General Information

Joe Sandbox Version:24.0.0
Analysis ID:749556
Start date:30.12.2018
Start time:12:42:02
Joe Sandbox Product:Cloud
Overall analysis duration:0h 5m 50s
Hypervisor based Inspection enabled:false
Report type:full
Sample file name:INV 3326GHF- from Outriger General Importers Korea for acknowledgment.jar
Cookbook file name:defaultwindowsfilecookbook.jbs
Analysis system description:Windows 7 (Office 2010 SP2, Java 1.8.0_40 1.8.0_191, Flash 16.0.0.305, Acrobat Reader 11.0.08, Internet Explorer 11, Chrome 55, Firefox 43)
Number of analysed new started processes analysed:41
Number of new started drivers analysed:0
Number of existing processes analysed:0
Number of existing drivers analysed:0
Number of injected processes analysed:0
Technologies
  • EGA enabled
  • GSI enabled (VBA)
  • GSI enabled (Javascript)
  • GSI enabled (Java)
Analysis stop reason:Timeout
Detection:MAL
Classification:mal88.troj.expl.evad.winJAR@129/267@5/2
Cookbook Comments:
  • Adjust boot time
  • Found application associated with file extension: .jar
Warnings:
Show All
  • Exclude process from analysis (whitelisted): conhost.exe
  • Report size exceeded maximum capacity and may have missing behavior information.
  • Report size getting too big, too many NtAllocateVirtualMemory calls found.
  • Report size getting too big, too many NtOpenFile calls found.
  • Report size getting too big, too many NtQueryDirectoryFile calls found.
  • Report size getting too big, too many NtQueryValueKey calls found.
  • Report size getting too big, too many NtQueryVolumeInformationFile calls found.
  • Report size getting too big, too many NtReadFile calls found.
  • Report size getting too big, too many NtSetInformationFile calls found.

Detection

StrategyScoreRangeReportingWhitelistedDetection
Threshold880 - 100Report FP / FNfalsemalicious

Confidence

StrategyScoreRangeFurther Analysis Required?Confidence
Threshold50 - 5false
ConfidenceConfidence


Classification

Analysis Advice

Sample drops PE files which have not been started, submit dropped PE samples for a secondary analysis to Joe Sandbox



Mitre Att&ck Matrix

Initial AccessExecutionPersistencePrivilege EscalationDefense EvasionCredential AccessDiscoveryLateral MovementCollectionExfiltrationCommand and Control
Valid AccountsCommand-Line Interface1Hidden Files and Directories1Process Injection11Masquerading1Credential DumpingSecurity Software Discovery121Application Deployment SoftwareData from Local SystemData CompressedUncommonly Used Port1
Replication Through Removable MediaScripting1Registry Run Keys / Start Folder21Accessibility FeaturesHidden Files and Directories1Network SniffingRemote System Discovery1Remote ServicesData from Removable MediaExfiltration Over Other Network MediumRemote Access Tools3
Drive-by CompromiseExploitation for Client Execution1Accessibility FeaturesPath InterceptionDisabling Security Tools1Input CaptureFile and Directory Discovery1Windows Remote ManagementData from Network Shared DriveAutomated ExfiltrationStandard Non-Application Layer Protocol1
Exploit Public-Facing ApplicationScheduled TaskSystem FirmwareDLL Search Order HijackingProcess Injection11Credentials in FilesSystem Information Discovery1Logon ScriptsInput CaptureData EncryptedStandard Application Layer Protocol1
Spearphishing LinkCommand-Line InterfaceShortcut ModificationFile System Permissions WeaknessScripting1Account ManipulationRemote System DiscoveryShared WebrootData StagedScheduled TransferStandard Cryptographic Protocol

Signature Overview

Click to jump to signature section


AV Detection:

barindex
Yara signature matchShow sources
Source: C:\Users\user~1\AppData\Local\Temp\_0.63493269659919425532230313552172834.class, type: DROPPEDMatched rule: MAL_JRAT_Oct18_1 date = 2018-10-11, hash1 = ce190c37a6fdb2632f4bc5ea0bb613b3fbe697d04e68e126b41910a6831d3411, author = Florian Roth, description = Detects JRAT malware, reference = Internal Research
Source: C:\Users\user~1\AppData\Local\Temp\_0.259951839382067235585996733401964613.class, type: DROPPEDMatched rule: MAL_JRAT_Oct18_1 date = 2018-10-11, hash1 = ce190c37a6fdb2632f4bc5ea0bb613b3fbe697d04e68e126b41910a6831d3411, author = Florian Roth, description = Detects JRAT malware, reference = Internal Research
Source: C:\Users\user~1\AppData\Local\Temp\_0.27057588722335616152848481378506703.class, type: DROPPEDMatched rule: MAL_JRAT_Oct18_1 date = 2018-10-11, hash1 = ce190c37a6fdb2632f4bc5ea0bb613b3fbe697d04e68e126b41910a6831d3411, author = Florian Roth, description = Detects JRAT malware, reference = Internal Research

Spreading:

barindex
Enumerates the file systemShow sources
Source: C:\Users\user\AppData\Roaming\Oracle\bin\javaw.exeFile opened: C:\Users\user\AppData\Roaming\
Source: C:\Users\user\AppData\Roaming\Oracle\bin\javaw.exeFile opened: C:\Users\user\AppData\Roaming\Oracle\
Source: C:\Users\user\AppData\Roaming\Oracle\bin\javaw.exeFile opened: C:\Users\user\AppData\
Source: C:\Users\user\AppData\Roaming\Oracle\bin\javaw.exeFile opened: C:\Users\user\
Source: C:\Users\user\AppData\Roaming\Oracle\bin\javaw.exeFile opened: C:\Users\user\AppData\Roaming\Oracle\lib\
Source: C:\Users\user\AppData\Roaming\Oracle\bin\javaw.exeFile opened: C:\Users\user\AppData\Roaming\Oracle\lib\ext\

Software Vulnerabilities:

barindex
Exploit detected, runtime environment starts unknown processesShow sources
Source: C:\Program Files\Java\jre1.8.0_191\bin\java.exeProcess created: C:\Windows\System32\cmd.exeJump to behavior

Networking:

barindex
Detected TCP or UDP traffic on non-standard portsShow sources
Source: global trafficTCP traffic: 192.168.1.16:49230 -> 185.244.30.124:6654
Uses dynamic DNS servicesShow sources
Source: unknownDNS query: name: onyeka1.duckdns.org
Performs DNS lookupsShow sources
Source: unknownDNS traffic detected: queries for: onyeka1.duckdns.org
Urls found in memory or binary dataShow sources
Source: java.dll.19.drString found in binary or memory: http://bugreport.sun.com/bugreport/
Source: java.dll.19.drString found in binary or memory: http://bugreport.sun.com/bugreport/java.vendor.url.bughttp://java.oracle.com/java.vendor.urljava.ven
Source: gstreamer-lite.dll.19.drString found in binary or memory: http://bugzilla.gnome.org/enter_bug.cgi?product=GStreamer.
Source: gstreamer-lite.dll.19.drString found in binary or memory: http://bugzilla.gnome.org/enter_bug.cgi?product=GStreamer.GStreamer
Source: gstreamer-lite.dll.19.drString found in binary or memory: http://bugzilla.gnome.org/enter_bug.cgi?product=GStreamer.Internal
Source: gstreamer-lite.dll.19.drString found in binary or memory: http://bugzilla.gnome.org/enter_bug.cgi?product=GStreamer.Your
Source: THIRDPARTYLICENSEREADME-JAVAFX.txt.19.drString found in binary or memory: http://casper.beckman.uiuc.edu/~c-tsai4
Source: THIRDPARTYLICENSEREADME-JAVAFX.txt.19.drString found in binary or memory: http://chasen.aist-nara.ac.jp/chasen/distribution.html
Source: gstreamer-lite.dll.19.drString found in binary or memory: http://creativecommons.org/licenses/
Source: gstreamer-lite.dll.19.drString found in binary or memory: http://creativecommons.org/licenses/WOAFID3PrivateFramehttp://musicbrainz.org%d/%d%drxRemixcr
Source: Welcome.html.19.drString found in binary or memory: http://download.oracle.com/javase/7/docs/technotes/guides/plugin/
Source: jfxwebkit.dll.19.drString found in binary or memory: http://exslt.org/common
Source: jfxwebkit.dll.19.drString found in binary or memory: http://exslt.org/commonnode-set
Source: THIRDPARTYLICENSEREADME.txt.19.drString found in binary or memory: http://hg.openjdk.java.net/jdk8u/jdk8u/jdk/file/tip/src/share/native/sun/security/ec/impl
Source: THIRDPARTYLICENSEREADME-JAVAFX.txt.19.drString found in binary or memory: http://hg.openjdk.java.net/openjfx/8u/rt
Source: java.dll.19.drString found in binary or memory: http://java.oracle.com/
Source: jdwp.dll.19.drString found in binary or memory: http://java.sun.com/products/jpda
Source: fxplugins.dll.19.drString found in binary or memory: http://javafx.com/
Source: fxplugins.dll.19.drString found in binary or memory: http://javafx.com/vp6decoderflvdemuxvideo/unsupportedvideo/x-vp6-flashvideo/x-vp6-alphaOn2
Source: THIRDPARTYLICENSEREADME.txt.19.drString found in binary or memory: http://mozilla.org/MPL/2.0/.
Source: gstreamer-lite.dll.19.drString found in binary or memory: http://musicbrainz.org
Source: THIRDPARTYLICENSEREADME-JAVAFX.txt.19.drString found in binary or memory: http://opensource.org/licenses/bsd-license.php
Source: THIRDPARTYLICENSEREADME.txt.19.drString found in binary or memory: http://relaxngcc.sf.net/).
Source: awt.dll.19.drString found in binary or memory: http://s.symcb.com/universal-root.crl0
Source: awt.dll.19.drString found in binary or memory: http://s.symcd.com06
Source: awt.dll.19.drString found in binary or memory: http://s1.symcb.com/pca3-g5.crl0
Source: awt.dll.19.drString found in binary or memory: http://s2.symcb.com0
Source: awt.dll.19.drString found in binary or memory: http://sv.symcb.com/sv.crl0W
Source: awt.dll.19.drString found in binary or memory: http://sv.symcb.com/sv.crt0
Source: awt.dll.19.drString found in binary or memory: http://sv.symcd.com0&
Source: THIRDPARTYLICENSEREADME.txt.19.drString found in binary or memory: http://tartarus.org/~martin/PorterStemmer
Source: jfxwebkit.dll.19.drString found in binary or memory: http://tools.ietf.org/html/rfc3986#section-2.1.
Source: jfxwebkit.dll.19.drString found in binary or memory: http://tools.ietf.org/html/rfc3986#section-2.1.The
Source: awt.dll.19.drString found in binary or memory: http://ts-aia.ws.symantec.com/sha256-tss-ca.cer0(
Source: awt.dll.19.drString found in binary or memory: http://ts-crl.ws.symantec.com/sha256-tss-ca.crl0
Source: awt.dll.19.drString found in binary or memory: http://ts-ocsp.ws.symantec.com0;
Source: THIRDPARTYLICENSEREADME.txt.19.drString found in binary or memory: http://upx.sourceforge.net/upx-license.html.
Source: THIRDPARTYLICENSEREADME.txt.19.drString found in binary or memory: http://upx.tsx.org
Source: THIRDPARTYLICENSEREADME.txt.19.drString found in binary or memory: http://wildsau.idv.uni-linz.ac.at/mfx/upx.html
Source: THIRDPARTYLICENSEREADME.txt.19.drString found in binary or memory: http://www.apache.org/).
Source: THIRDPARTYLICENSEREADME.txt.19.drString found in binary or memory: http://www.apache.org/licenses/
Source: THIRDPARTYLICENSEREADME.txt.19.drString found in binary or memory: http://www.apache.org/licenses/LICENSE-2.0
Source: THIRDPARTYLICENSEREADME.txt.19.drString found in binary or memory: http://www.ecma-international.org
Source: THIRDPARTYLICENSEREADME.txt.19.drString found in binary or memory: http://www.ecma-international.org/memento/codeofconduct.htm
Source: THIRDPARTYLICENSEREADME.txt.19.drString found in binary or memory: http://www.freebxml.org/
Source: THIRDPARTYLICENSEREADME.txt.19.drString found in binary or memory: http://www.freebxml.org/).
Source: jfxwebkit.dll.19.drString found in binary or memory: http://www.ibm.com/data/dtd/v11/ibmxhtml1-transitional.dtd
Source: jfxwebkit.dll.19.drString found in binary or memory: http://www.ibm.com/data/dtd/v11/ibmxhtml1-transitional.dtd-//w3c//dtd
Source: gstreamer-lite.dll.19.drString found in binary or memory: http://www.ifpi.org/isrc/
Source: THIRDPARTYLICENSEREADME.txt.19.drString found in binary or memory: http://www.linuxnet.com
Source: THIRDPARTYLICENSEREADME.txt.19.drString found in binary or memory: http://www.nexus.hu/upx
Source: THIRDPARTYLICENSEREADME.txt.19.drString found in binary or memory: http://www.oracle.com/goto/opensourcecode/request
Source: Welcome.html.19.drString found in binary or memory: http://www.oracle.com/technetwork/java/javase/overview/
Source: awt.dll.19.drString found in binary or memory: http://www.symauth.com/cps0(
Source: awt.dll.19.drString found in binary or memory: http://www.symauth.com/rpa00
Source: THIRDPARTYLICENSEREADME-JAVAFX.txt.19.dr, THIRDPARTYLICENSEREADME.txt.19.drString found in binary or memory: http://www.unicode.org/Public/
Source: THIRDPARTYLICENSEREADME-JAVAFX.txt.19.dr, THIRDPARTYLICENSEREADME.txt.19.drString found in binary or memory: http://www.unicode.org/Public/.
Source: THIRDPARTYLICENSEREADME.txt.19.drString found in binary or memory: http://www.unicode.org/cldr/data/.
Source: THIRDPARTYLICENSEREADME-JAVAFX.txt.19.drString found in binary or memory: http://www.unicode.org/copyright.html.
Source: THIRDPARTYLICENSEREADME-JAVAFX.txt.19.dr, THIRDPARTYLICENSEREADME.txt.19.drString found in binary or memory: http://www.unicode.org/reports/
Source: THIRDPARTYLICENSEREADME.txt.19.drString found in binary or memory: http://www.xfree86.org/)
Source: awt.dll.19.drString found in binary or memory: https://d.symcb.com/cps0%
Source: awt.dll.19.drString found in binary or memory: https://d.symcb.com/rpa0
Source: awt.dll.19.drString found in binary or memory: https://d.symcb.com/rpa0.
Source: THIRDPARTYLICENSEREADME-JAVAFX.txt.19.drString found in binary or memory: https://sourceforge.net/project/?group_id=1519

DDoS:

barindex
Too many similar processes foundShow sources
Source: unknownProcess created: 80

System Summary:

barindex
Creates files inside the system directoryShow sources
Source: C:\Program Files\Java\jre1.8.0_191\bin\java.exeFile created: C:\Windows\System32\test.txtJump to behavior
Reads the hosts fileShow sources
Source: C:\Users\user\AppData\Roaming\Oracle\bin\javaw.exeFile read: C:\Windows\System32\drivers\etc\hosts
Source: C:\Users\user\AppData\Roaming\Oracle\bin\javaw.exeFile read: C:\Windows\System32\drivers\etc\hosts
Uses reg.exe to modify the Windows registryShow sources
Source: unknownProcess created: C:\Windows\System32\reg.exe reg add HKCU\Software\Microsoft\Windows\CurrentVersion\Run /v bJnYSNphoio /t REG_EXPAND_SZ /d '\'C:\Users\user\AppData\Roaming\Oracle\bin\javaw.exe\' -jar \'C:\Users\user\KtXRptueuIB\XSZHGSWUUvB.nxPNyG\'' /f
Classification labelShow sources
Source: classification engineClassification label: mal88.troj.expl.evad.winJAR@129/267@5/2
Creates files inside the user directoryShow sources
Source: C:\Program Files\Java\jre1.8.0_191\bin\java.exeFile created: C:\Users\user\KtXRptueuIBJump to behavior
Creates temporary filesShow sources
Source: C:\Program Files\Java\jre1.8.0_191\bin\java.exeFile created: C:\Users\user~1\AppData\Local\Temp\hsperfdata_user\3864Jump to behavior
Executable is probably coded in javaShow sources
Source: C:\Windows\System32\cmd.exeSection loaded: C:\Program Files\Java\jre1.8.0_191\bin\java.dllJump to behavior
Executes visual basic scriptsShow sources
Source: unknownProcess created: C:\Windows\System32\cmd.exe cmd.exe /C cscript.exe C:\Users\user~1\AppData\Local\Temp\Retrive5438807271024442592.vbs
Queries process information (via WMI, Win32_Process)Show sources
Source: C:\Windows\System32\cmd.exeWMI Queries: IWbemServices::ExecQuery - SELECT __PATH, ProcessId, CSName, Caption, SessionId, ThreadCount, WorkingSetSize, KernelModeTime, UserModeTime, ParentProcessId FROM Win32_Process
Source: C:\Windows\System32\cscript.exeWMI Queries: IWbemServices::ExecQuery - SELECT __PATH, ProcessId, CSName, Caption, SessionId, ThreadCount, WorkingSetSize, KernelModeTime, UserModeTime, ParentProcessId FROM Win32_Process
Reads software policiesShow sources
Source: C:\Program Files\Java\jre1.8.0_191\bin\java.exeKey opened: HKEY_LOCAL_MACHINE\Software\Policies\Microsoft\Windows\Safer\CodeIdentifiersJump to behavior
SQL strings found in memory and binary dataShow sources
Source: jfxwebkit.dll.19.drBinary or memory string: CREATE TABLE Origins (origin TEXT UNIQUE ON CONFLICT REPLACE, quota INTEGER NOT NULL ON CONFLICT FAIL);
Source: jfxwebkit.dll.19.drBinary or memory string: SELECT name FROM sqlite_master WHERE type='table';
Source: jfxwebkit.dll.19.drBinary or memory string: SELECT origin FROM Origins where origin=?;
Source: jfxwebkit.dll.19.drBinary or memory string: CREATE TABLE Databases (guid INTEGER PRIMARY KEY AUTOINCREMENT, origin TEXT, name TEXT, displayName TEXT, estimatedSize INTEGER, path TEXT);
Source: jfxwebkit.dll.19.drBinary or memory string: SELECT guid FROM Databases WHERE origin=? AND name=?;
Source: jfxwebkit.dll.19.drBinary or memory string: SELECT name FROM Databases where origin=?;
Source: jfxwebkit.dll.19.drBinary or memory string: INSERT INTO Databases (origin, name, path) VALUES (?, ?, ?);
Source: jfxwebkit.dll.19.drBinary or memory string: CREATE TABLE IF NOT EXISTS CacheGroups (id INTEGER PRIMARY KEY AUTOINCREMENT, manifestHostHash INTEGER NOT NULL ON CONFLICT FAIL, manifestURL TEXT UNIQUE ON CONFLICT FAIL, newestCache INTEGER, origin TEXT)CREATE TABLE IF NOT EXISTS Caches (id INTEGER PRIMARY KEY AUTOINCREMENT, cacheGroup INTEGER, size INTEGER) was redirected.CREATE TABLE IF NOT EXISTS CacheWhitelistURLs (url TEXT NOT NULL ON CONFLICT FAIL, cache INTEGER NOT NULL ON CONFLICT FAIL)Application Cache update failed, because CREATE TABLE IF NOT EXISTS CacheAllowsAllNetworkRequests (wildcard INTEGER NOT NULL ON CONFLICT FAIL, cache INTEGER NOT NULL ON CONFLICT FAIL)CREATE TABLE IF NOT EXISTS FallbackURLs (namespace TEXT NOT NULL ON CONFLICT FAIL, fallbackURL TEXT NOT NULL ON CONFLICT FAIL, cache INTEGER NOT NULL ON CONFLICT FAIL)CREATE TABLE IF NOT EXISTS CacheEntries (cache INTEGER NOT NULL ON CONFLICT FAIL, type INTEGER, resource INTEGER NOT NULL)Application Cache update failed, because CREATE TABLE IF NOT EXISTS CacheResources (id INTEGER PRIMARY
Source: jfxwebkit.dll.19.drBinary or memory string: SELECT quota FROM Origins where origin=?;
Source: jfxwebkit.dll.19.drBinary or memory string: SELECT path FROM Databases WHERE origin=? AND name=?;
Source: jfxwebkit.dll.19.drBinary or memory string: CREATE TABLE Origins (origin TEXT UNIQUE ON CONFLICT REPLACE, path TEXT);
Spawns processesShow sources
Source: unknownProcess created: C:\Windows\System32\cmd.exe C:\Windows\system32\cmd.exe /c ''C:\Program Files\Java\jre1.8.0_191\bin\java.exe' -javaagent:'C:\Users\user~1\AppData\Local\Temp\jartracer.jar' -jar 'C:\Users\user\Desktop\INV 3326GHF- from Outriger General Importers Korea for acknowledgment.jar'' >> C:\cmdlinestart.log 2>&1
Source: unknownProcess created: C:\Program Files\Java\jre1.8.0_191\bin\java.exe 'C:\Program Files\Java\jre1.8.0_191\bin\java.exe' -javaagent:'C:\Users\user~1\AppData\Local\Temp\jartracer.jar' -jar 'C:\Users\user\Desktop\INV 3326GHF- from Outriger General Importers Korea for acknowledgment.jar'
Source: unknownProcess created: C:\Windows\System32\icacls.exe C:\Windows\system32\icacls.exe C:\ProgramData\Oracle\Java\.oracle_jre_usage /grant 'everyone':(OI)(CI)M
Source: unknownProcess created: C:\Program Files\Java\jre1.8.0_191\bin\java.exe 'C:\Program Files\Java\jre1.8.0_191\bin\java.exe' -javaagent:'C:\Users\user~1\AppData\Local\Temp\jartracer.jar' -jar C:\Users\user~1\AppData\Local\Temp\_0.63493269659919425532230313552172834.class
Source: unknownProcess created: C:\Windows\System32\cmd.exe cmd.exe /C cscript.exe C:\Users\user~1\AppData\Local\Temp\Retrive5438807271024442592.vbs
Source: unknownProcess created: C:\Windows\System32\cscript.exe cscript.exe C:\Users\user~1\AppData\Local\Temp\Retrive5438807271024442592.vbs
Source: unknownProcess created: C:\Windows\System32\cmd.exe cmd.exe /C cscript.exe C:\Users\user~1\AppData\Local\Temp\Retrive7307749898854467482.vbs
Source: unknownProcess created: C:\Windows\System32\cscript.exe cscript.exe C:\Users\user~1\AppData\Local\Temp\Retrive7307749898854467482.vbs
Source: unknownProcess created: C:\Windows\System32\cmd.exe cmd.exe /C cscript.exe C:\Users\user~1\AppData\Local\Temp\Retrive2024933177882465042.vbs
Source: unknownProcess created: C:\Windows\System32\cscript.exe cscript.exe C:\Users\user~1\AppData\Local\Temp\Retrive2024933177882465042.vbs
Source: unknownProcess created: C:\Windows\System32\cmd.exe cmd.exe /C cscript.exe C:\Users\user~1\AppData\Local\Temp\Retrive7530535289870207342.vbs
Source: unknownProcess created: C:\Windows\System32\cscript.exe cscript.exe C:\Users\user~1\AppData\Local\Temp\Retrive7530535289870207342.vbs
Source: unknownProcess created: C:\Windows\System32\xcopy.exe xcopy 'C:\Program Files\Java\jre1.8.0_191' 'C:\Users\user\AppData\Roaming\Oracle\' /e
Source: unknownProcess created: C:\Windows\System32\xcopy.exe xcopy 'C:\Program Files\Java\jre1.8.0_191' 'C:\Users\user\AppData\Roaming\Oracle\' /e
Source: unknownProcess created: C:\Windows\System32\cmd.exe cmd.exe
Source: unknownProcess created: C:\Windows\System32\reg.exe reg add HKCU\Software\Microsoft\Windows\CurrentVersion\Run /v bJnYSNphoio /t REG_EXPAND_SZ /d '\'C:\Users\user\AppData\Roaming\Oracle\bin\javaw.exe\' -jar \'C:\Users\user\KtXRptueuIB\XSZHGSWUUvB.nxPNyG\'' /f
Source: unknownProcess created: C:\Windows\System32\attrib.exe attrib +h 'C:\Users\user\KtXRptueuIB\*.*'
Source: unknownProcess created: C:\Windows\System32\attrib.exe attrib +h 'C:\Users\user\KtXRptueuIB'
Source: unknownProcess created: C:\Users\user\AppData\Roaming\Oracle\bin\javaw.exe C:\Users\user\AppData\Roaming\Oracle\bin\javaw.exe -javaagent:'C:\Users\user~1\AppData\Local\Temp\jartracer.jar' -jar C:\Users\user\KtXRptueuIB\XSZHGSWUUvB.nxPNyG
Source: unknownProcess created: C:\Users\user\AppData\Roaming\Oracle\bin\javaw.exe 'C:\Users\user\AppData\Roaming\Oracle\bin\javaw.exe' -jar 'C:\Users\user\KtXRptueuIB\XSZHGSWUUvB.nxPNyG'
Source: unknownProcess created: C:\Users\user\AppData\Roaming\Oracle\bin\java.exe C:\Users\user\AppData\Roaming\Oracle\bin\java.exe -jar C:\Users\user~1\AppData\Local\Temp\_0.27057588722335616152848481378506703.class
Source: unknownProcess created: C:\Windows\System32\cmd.exe cmd.exe /C cscript.exe C:\Users\user~1\AppData\Local\Temp\Retrive7103461586894408784.vbs
Source: unknownProcess created: C:\Windows\System32\cscript.exe cscript.exe C:\Users\user~1\AppData\Local\Temp\Retrive7103461586894408784.vbs
Source: unknownProcess created: C:\Windows\System32\cmd.exe cmd.exe /C cscript.exe C:\Users\user~1\AppData\Local\Temp\Retrive3097055394604195664.vbs
Source: unknownProcess created: C:\Windows\System32\cscript.exe cscript.exe C:\Users\user~1\AppData\Local\Temp\Retrive3097055394604195664.vbs
Source: C:\Windows\System32\cmd.exeProcess created: C:\Program Files\Java\jre1.8.0_191\bin\java.exe 'C:\Program Files\Java\jre1.8.0_191\bin\java.exe' -javaagent:'C:\Users\user~1\AppData\Local\Temp\jartracer.jar' -jar 'C:\Users\user\Desktop\INV 3326GHF- from Outriger General Importers Korea for acknowledgment.jar' Jump to behavior
Source: C:\Program Files\Java\jre1.8.0_191\bin\java.exeProcess created: C:\Windows\System32\icacls.exe C:\Windows\system32\icacls.exe C:\ProgramData\Oracle\Java\.oracle_jre_usage /grant 'everyone':(OI)(CI)MJump to behavior
Source: C:\Program Files\Java\jre1.8.0_191\bin\java.exeProcess created: C:\Program Files\Java\jre1.8.0_191\bin\java.exe 'C:\Program Files\Java\jre1.8.0_191\bin\java.exe' -javaagent:'C:\Users\user~1\AppData\Local\Temp\jartracer.jar' -jar C:\Users\user~1\AppData\Local\Temp\_0.63493269659919425532230313552172834.classJump to behavior
Source: C:\Program Files\Java\jre1.8.0_191\bin\java.exeProcess created: C:\Windows\System32\cmd.exe cmd.exe /C cscript.exe C:\Users\user~1\AppData\Local\Temp\Retrive5438807271024442592.vbsJump to behavior
Source: C:\Program Files\Java\jre1.8.0_191\bin\java.exeProcess created: C:\Windows\System32\cmd.exe cmd.exe /C cscript.exe C:\Users\user~1\AppData\Local\Temp\Retrive2024933177882465042.vbsJump to behavior
Source: C:\Program Files\Java\jre1.8.0_191\bin\java.exeProcess created: C:\Windows\System32\xcopy.exe xcopy 'C:\Program Files\Java\jre1.8.0_191' 'C:\Users\user\AppData\Roaming\Oracle\' /eJump to behavior
Source: C:\Program Files\Java\jre1.8.0_191\bin\java.exeProcess created: C:\Windows\System32\cmd.exe cmd.exeJump to behavior
Source: C:\Program Files\Java\jre1.8.0_191\bin\java.exeProcess created: C:\Windows\System32\reg.exe reg add HKCU\Software\Microsoft\Windows\CurrentVersion\Run /v bJnYSNphoio /t REG_EXPAND_SZ /d '\'C:\Users\user\AppData\Roaming\Oracle\bin\javaw.exe\' -jar \'C:\Users\user\KtXRptueuIB\XSZHGSWUUvB.nxPNyG\'' /fJump to behavior
Source: C:\Program Files\Java\jre1.8.0_191\bin\java.exeProcess created: C:\Windows\System32\attrib.exe attrib +h 'C:\Users\user\KtXRptueuIB\*.*'Jump to behavior
Source: C:\Program Files\Java\jre1.8.0_191\bin\java.exeProcess created: C:\Windows\System32\attrib.exe attrib +h 'C:\Users\user\KtXRptueuIB'Jump to behavior
Source: C:\Program Files\Java\jre1.8.0_191\bin\java.exeProcess created: C:\Users\user\AppData\Roaming\Oracle\bin\javaw.exe C:\Users\user\AppData\Roaming\Oracle\bin\javaw.exe -javaagent:'C:\Users\user~1\AppData\Local\Temp\jartracer.jar' -jar C:\Users\user\KtXRptueuIB\XSZHGSWUUvB.nxPNyGJump to behavior
Source: C:\Program Files\Java\jre1.8.0_191\bin\java.exeProcess created: C:\Windows\System32\cmd.exe cmd.exe /C cscript.exe C:\Users\user~1\AppData\Local\Temp\Retrive7307749898854467482.vbsJump to behavior
Source: C:\Program Files\Java\jre1.8.0_191\bin\java.exeProcess created: C:\Windows\System32\cmd.exe cmd.exe /C cscript.exe C:\Users\user~1\AppData\Local\Temp\Retrive7530535289870207342.vbsJump to behavior
Source: C:\Program Files\Java\jre1.8.0_191\bin\java.exeProcess created: C:\Windows\System32\xcopy.exe xcopy 'C:\Program Files\Java\jre1.8.0_191' 'C:\Users\user\AppData\Roaming\Oracle\' /eJump to behavior
Source: C:\Windows\System32\cmd.exeProcess created: C:\Windows\System32\cscript.exe cscript.exe C:\Users\user~1\AppData\Local\Temp\Retrive5438807271024442592.vbsJump to behavior
Source: C:\Windows\System32\cmd.exeProcess created: C:\Windows\System32\cscript.exe cscript.exe C:\Users\user~1\AppData\Local\Temp\Retrive7307749898854467482.vbsJump to behavior
Source: C:\Windows\System32\cmd.exeProcess created: C:\Windows\System32\cscript.exe cscript.exe C:\Users\user~1\AppData\Local\Temp\Retrive2024933177882465042.vbsJump to behavior
Source: C:\Windows\System32\cmd.exeProcess created: C:\Windows\System32\cscript.exe cscript.exe C:\Users\user~1\AppData\Local\Temp\Retrive7530535289870207342.vbsJump to behavior
Source: C:\Users\user\AppData\Roaming\Oracle\bin\javaw.exeProcess created: unknown unknown
Source: C:\Users\user\AppData\Roaming\Oracle\bin\javaw.exeProcess created: unknown unknown
Source: C:\Users\user\AppData\Roaming\Oracle\bin\javaw.exeProcess created: unknown unknown
Source: C:\Users\user\AppData\Roaming\Oracle\bin\javaw.exeProcess created: unknown unknown
Source: C:\Users\user\AppData\Roaming\Oracle\bin\javaw.exeProcess created: unknown unknown
Source: C:\Users\user\AppData\Roaming\Oracle\bin\javaw.exeProcess created: unknown unknown
Source: C:\Users\user\AppData\Roaming\Oracle\bin\javaw.exeProcess created: unknown unknown
Source: C:\Users\user\AppData\Roaming\Oracle\bin\javaw.exeProcess created: unknown unknown
Source: C:\Users\user\AppData\Roaming\Oracle\bin\javaw.exeProcess created: unknown unknown
Source: C:\Users\user\AppData\Roaming\Oracle\bin\javaw.exeProcess created: unknown unknown
Source: C:\Users\user\AppData\Roaming\Oracle\bin\javaw.exeProcess created: unknown unknown
Source: C:\Users\user\AppData\Roaming\Oracle\bin\javaw.exeProcess created: unknown unknown
Source: C:\Users\user\AppData\Roaming\Oracle\bin\javaw.exeProcess created: unknown unknown
Source: C:\Users\user\AppData\Roaming\Oracle\bin\javaw.exeProcess created: unknown unknown
Source: C:\Users\user\AppData\Roaming\Oracle\bin\javaw.exeProcess created: unknown unknown
Source: C:\Users\user\AppData\Roaming\Oracle\bin\javaw.exeProcess created: unknown unknown
Source: C:\Users\user\AppData\Roaming\Oracle\bin\javaw.exeProcess created: C:\Windows\System32\cscript.exe cscript.exe C:\Users\user~1\AppData\Local\Temp\Retrive3097055394604195664.vbs
Source: C:\Users\user\AppData\Roaming\Oracle\bin\javaw.exeProcess created: unknown unknown
Source: C:\Users\user\AppData\Roaming\Oracle\bin\javaw.exeProcess created: unknown unknown
Source: C:\Users\user\AppData\Roaming\Oracle\bin\javaw.exeProcess created: unknown unknown
Source: C:\Users\user\AppData\Roaming\Oracle\bin\javaw.exeProcess created: unknown unknown
Source: C:\Users\user\AppData\Roaming\Oracle\bin\javaw.exeProcess created: unknown unknown
Source: C:\Users\user\AppData\Roaming\Oracle\bin\javaw.exeProcess created: unknown unknown
Source: C:\Users\user\AppData\Roaming\Oracle\bin\javaw.exeProcess created: unknown unknown
Source: C:\Users\user\AppData\Roaming\Oracle\bin\javaw.exeProcess created: unknown unknown
Source: C:\Users\user\AppData\Roaming\Oracle\bin\javaw.exeProcess created: unknown unknown
Source: C:\Users\user\AppData\Roaming\Oracle\bin\javaw.exeProcess created: unknown unknown
Source: C:\Users\user\AppData\Roaming\Oracle\bin\javaw.exeProcess created: unknown unknown
Source: C:\Users\user\AppData\Roaming\Oracle\bin\javaw.exeProcess created: unknown unknown
Source: C:\Users\user\AppData\Roaming\Oracle\bin\javaw.exeProcess created: unknown unknown
Source: C:\Users\user\AppData\Roaming\Oracle\bin\javaw.exeProcess created: unknown unknown
Source: C:\Users\user\AppData\Roaming\Oracle\bin\javaw.exeProcess created: unknown unknown
Source: C:\Users\user\AppData\Roaming\Oracle\bin\javaw.exeProcess created: unknown unknown
Source: C:\Users\user\AppData\Roaming\Oracle\bin\javaw.exeProcess created: unknown unknown
Source: C:\Users\user\AppData\Roaming\Oracle\bin\javaw.exeProcess created: unknown unknown
Source: C:\Users\user\AppData\Roaming\Oracle\bin\javaw.exeProcess created: unknown unknown
Source: C:\Users\user\AppData\Roaming\Oracle\bin\javaw.exeProcess created: unknown unknown
Source: C:\Users\user\AppData\Roaming\Oracle\bin\javaw.exeProcess created: C:\Users\user\AppData\Roaming\Oracle\bin\java.exe C:\Users\user\AppData\Roaming\Oracle\bin\java.exe -jar C:\Users\user~1\AppData\Local\Temp\_0.27057588722335616152848481378506703.class
Source: C:\Users\user\AppData\Roaming\Oracle\bin\javaw.exeProcess created: C:\Windows\System32\cmd.exe cmd.exe /C cscript.exe C:\Users\user~1\AppData\Local\Temp\Retrive7103461586894408784.vbs
Source: C:\Users\user\AppData\Roaming\Oracle\bin\javaw.exeProcess created: unknown unknown
Source: C:\Users\user\AppData\Roaming\Oracle\bin\javaw.exeProcess created: unknown unknown
Source: C:\Users\user\AppData\Roaming\Oracle\bin\javaw.exeProcess created: unknown unknown
Source: C:\Users\user\AppData\Roaming\Oracle\bin\javaw.exeProcess created: unknown unknown
Source: C:\Users\user\AppData\Roaming\Oracle\bin\javaw.exeProcess created: unknown unknown
Source: C:\Users\user\AppData\Roaming\Oracle\bin\javaw.exeProcess created: unknown unknown
Source: C:\Users\user\AppData\Roaming\Oracle\bin\javaw.exeProcess created: unknown unknown
Source: C:\Users\user\AppData\Roaming\Oracle\bin\javaw.exeProcess created: unknown unknown
Source: C:\Users\user\AppData\Roaming\Oracle\bin\javaw.exeProcess created: unknown unknown
Source: C:\Users\user\AppData\Roaming\Oracle\bin\javaw.exeProcess created: unknown unknown
Source: C:\Users\user\AppData\Roaming\Oracle\bin\javaw.exeProcess created: unknown unknown
Source: C:\Users\user\AppData\Roaming\Oracle\bin\javaw.exeProcess created: unknown unknown
Source: C:\Users\user\AppData\Roaming\Oracle\bin\javaw.exeProcess created: unknown unknown
Source: C:\Users\user\AppData\Roaming\Oracle\bin\javaw.exeProcess created: unknown unknown
Source: C:\Users\user\AppData\Roaming\Oracle\bin\javaw.exeProcess created: unknown unknown
Source: C:\Users\user\AppData\Roaming\Oracle\bin\javaw.exeProcess created: unknown unknown
Source: C:\Users\user\AppData\Roaming\Oracle\bin\javaw.exeProcess created: unknown unknown
Source: C:\Users\user\AppData\Roaming\Oracle\bin\javaw.exeProcess created: unknown unknown
Source: C:\Users\user\AppData\Roaming\Oracle\bin\javaw.exeProcess created: unknown unknown
Source: C:\Users\user\AppData\Roaming\Oracle\bin\javaw.exeProcess created: unknown unknown
Source: C:\Users\user\AppData\Roaming\Oracle\bin\javaw.exeProcess created: unknown unknown
Source: C:\Users\user\AppData\Roaming\Oracle\bin\javaw.exeProcess created: unknown unknown
Source: C:\Users\user\AppData\Roaming\Oracle\bin\javaw.exeProcess created: unknown unknown
Source: C:\Users\user\AppData\Roaming\Oracle\bin\javaw.exeProcess created: unknown unknown
Source: C:\Users\user\AppData\Roaming\Oracle\bin\javaw.exeProcess created: unknown unknown
Source: C:\Users\user\AppData\Roaming\Oracle\bin\javaw.exeProcess created: unknown unknown
Source: C:\Users\user\AppData\Roaming\Oracle\bin\javaw.exeProcess created: unknown unknown
Source: C:\Users\user\AppData\Roaming\Oracle\bin\javaw.exeProcess created: unknown unknown
Source: C:\Users\user\AppData\Roaming\Oracle\bin\javaw.exeProcess created: unknown unknown
Source: C:\Users\user\AppData\Roaming\Oracle\bin\javaw.exeProcess created: unknown unknown
Source: C:\Users\user\AppData\Roaming\Oracle\bin\javaw.exeProcess created: unknown unknown
Source: C:\Users\user\AppData\Roaming\Oracle\bin\javaw.exeProcess created: unknown unknown
Source: C:\Users\user\AppData\Roaming\Oracle\bin\javaw.exeProcess created: unknown unknown
Source: C:\Users\user\AppData\Roaming\Oracle\bin\javaw.exeProcess created: unknown unknown
Source: C:\Users\user\AppData\Roaming\Oracle\bin\javaw.exeProcess created: unknown unknown
Source: C:\Users\user\AppData\Roaming\Oracle\bin\javaw.exeProcess created: unknown unknown
Source: C:\Users\user\AppData\Roaming\Oracle\bin\javaw.exeProcess created: unknown unknown
Source: C:\Users\user\AppData\Roaming\Oracle\bin\javaw.exeProcess created: unknown unknown
Source: C:\Users\user\AppData\Roaming\Oracle\bin\javaw.exeProcess created: unknown unknown
Source: C:\Users\user\AppData\Roaming\Oracle\bin\javaw.exeProcess created: unknown unknown
Source: C:\Users\user\AppData\Roaming\Oracle\bin\javaw.exeProcess created: unknown unknown
Source: C:\Users\user\AppData\Roaming\Oracle\bin\javaw.exeProcess created: unknown unknown
Source: C:\Users\user\AppData\Roaming\Oracle\bin\java.exeProcess created: C:\Windows\System32\cmd.exe cmd.exe /C cscript.exe C:\Users\user~1\AppData\Local\Temp\Retrive3097055394604195664.vbs
Source: C:\Users\user\AppData\Roaming\Oracle\bin\java.exeProcess created: unknown unknown
Source: C:\Users\user\AppData\Roaming\Oracle\bin\java.exeProcess created: unknown unknown
Source: C:\Windows\System32\cmd.exeProcess created: C:\Windows\System32\cscript.exe cscript.exe C:\Users\user~1\AppData\Local\Temp\Retrive7103461586894408784.vbs
Source: C:\Windows\System32\cmd.exeProcess created: C:\Windows\System32\cscript.exe cscript.exe C:\Users\user~1\AppData\Local\Temp\Retrive3097055394604195664.vbs
Uses an in-process (OLE) Automation serverShow sources
Source: C:\Windows\System32\cscript.exeKey value queried: HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{B54F3741-5B07-11cf-A4B0-00AA004A55E8}\InprocServer32Jump to behavior
Uses new MSVCR DllsShow sources
Source: C:\Program Files\Java\jre1.8.0_191\bin\java.exeFile opened: C:\Program Files\Java\jre1.8.0_191\bin\msvcr100.dllJump to behavior
Binary contains paths to debug symbolsShow sources
Source: Binary string: api-ms-win-crt-locale-l1-1-0.pdb source: api-ms-win-crt-locale-l1-1-0.dll.19.dr
Source: Binary string: api-ms-win-crt-runtime-l1-1-0.pdb source: api-ms-win-crt-runtime-l1-1-0.dll.19.dr
Source: Binary string: c:\workspace\8-2-build-windows-i586-cygwin\jdk8u191\11896\build\windows-i586\jdk\objs\libjava\java.pdb source: java.dll.19.dr
Source: Binary string: c:\workspace\8-2-build-windows-i586-cygwin\jdk8u191\11896\build\windows-i586\deploy\jre-image\bin\deploy.pdb ^m source: deploy.dll.19.dr
Source: Binary string: api-ms-win-core-file-l1-2-0.pdb source: api-ms-win-core-file-l1-2-0.dll.19.dr
Source: Binary string: api-ms-win-core-memory-l1-1-0.pdb source: api-ms-win-core-memory-l1-1-0.dll.19.dr
Source: Binary string: api-ms-win-core-debug-l1-1-0.pdb source: api-ms-win-core-debug-l1-1-0.dll.19.dr
Source: Binary string: concrt140.i386.pdbGCTL source: concrt140.dll.19.dr
Source: Binary string: api-ms-win-core-sysinfo-l1-1-0.pdb source: api-ms-win-core-sysinfo-l1-1-0.dll.19.dr
Source: Binary string: c:\workspace\8-2-build-windows-i586-cygwin\jdk8u191\11896\build\windows-i586\deploy\tmp\eula\obj\eula.pdb source: eula.dll.19.dr
Source: Binary string: api-ms-win-crt-filesystem-l1-1-0.pdb source: api-ms-win-crt-filesystem-l1-1-0.dll.19.dr
Source: Binary string: c:\workspace\8-2-build-windows-i586-cygwin\jdk8u191\11896\build\windows-i586\jdk\objs\libhprof_jvmti\hprof.pdb source: hprof.dll.19.dr
Source: Binary string: api-ms-win-crt-stdio-l1-1-0.pdb source: api-ms-win-crt-stdio-l1-1-0.dll.19.dr
Source: Binary string: c:\workspace\8-2-build-windows-i586-cygwin\jdk8u191\11896\build\windows-i586\deploy\tmp\javacpl\obj\javacpl.pdb source: javacpl.cpl.19.dr
Source: Binary string: c:\workspace\8-2-build-windows-i586-cygwin\jdk8u191\11896\build\windows-i586\jdk\objs\libjava\java.pdbG* source: java.dll.19.dr
Source: Binary string: c:\workspace\8-2-build-windows-i586-cygwin\jdk8u191\11896\build\windows-i586\jdk\objs\libjfr\jfr.pdb source: jfr.dll.19.dr
Source: Binary string: api-ms-win-core-heap-l1-1-0.pdb source: api-ms-win-core-heap-l1-1-0.dll.19.dr
Source: Binary string: c:\workspace\8-2-build-windows-i586-cygwin\jdk8u191\11896\build\windows-i586\jdk\objs\libjaas\jaas_nt.pdb source: jaas_nt.dll.19.dr
Source: Binary string: api-ms-win-core-util-l1-1-0.pdb source: api-ms-win-core-util-l1-1-0.dll.19.dr
Source: Binary string: api-ms-win-core-synch-l1-1-0.pdb source: api-ms-win-core-synch-l1-1-0.dll.19.dr
Source: Binary string: api-ms-win-crt-environment-l1-1-0.pdb source: api-ms-win-crt-environment-l1-1-0.dll.19.dr
Source: Binary string: c:\workspace\8-2-build-windows-i586-cygwin\jdk8u191\11896\build\windows-i586\deploy\tmp\javacplexec\obj\javacpl.pdb source: javacpl.exe.19.dr
Source: Binary string: api-ms-win-core-errorhandling-l1-1-0.pdb source: api-ms-win-core-errorhandling-l1-1-0.dll.19.dr
Source: Binary string: api-ms-win-core-processthreads-l1-1-0.pdb source: api-ms-win-core-processthreads-l1-1-0.dll.19.dr
Source: Binary string: api-ms-win-core-console-l1-1-0.pdb source: api-ms-win-core-console-l1-1-0.dll.19.dr
Source: Binary string: api-ms-win-core-file-l1-1-0.pdb source: api-ms-win-core-file-l1-1-0.dll.19.dr
Source: Binary string: api-ms-win-crt-private-l1-1-0.pdb source: api-ms-win-crt-private-l1-1-0.dll.19.dr
Source: Binary string: api-ms-win-crt-convert-l1-1-0.pdb source: api-ms-win-crt-convert-l1-1-0.dll.19.dr
Source: Binary string: c:\workspace\8-2-build-windows-i586-cygwin\jdk8u191\11896\build\windows-i586\jdk\objs\libdcpr\dcpr.pdb source: dcpr.dll.19.dr
Source: Binary string: api-ms-win-core-profile-l1-1-0.pdb source: api-ms-win-core-profile-l1-1-0.dll.19.dr
Source: Binary string: api-ms-win-crt-time-l1-1-0.pdb source: api-ms-win-crt-time-l1-1-0.dll.19.dr
Source: Binary string: c:\workspace\8-2-build-windows-i586-cygwin\jdk8u191\11896\build\windows-i586\jdk\objs\java-rmi_objs\java-rmi.pdb source: java-rmi.exe.19.dr
Source: Binary string: c:\workspace\8-2-build-windows-i586-cygwin\jdk8u191\11896\build\windows-i586\jdk\objs\libj2pkcs11\j2pkcs11.pdb source: j2pkcs11.dll.19.dr
Source: Binary string: c:\workspace\8-2-build-windows-i586-cygwin\jdk8u191\11896\build\windows-i586\jdk\objs\javaw_objs\javaw.pdb0 source: javaw.exe.19.dr
Source: Binary string: c:\workspace\8-2-build-windows-i586-cygwin\jdk8u191\11896\build\windows-i586\jdk\objs\libawt\awt.pdb source: awt.dll.19.dr
Source: Binary string: c:\workspace\8-2-build-windows-i586-cygwin\jdk8u191\11896\build\windows-i586\jdk\objs\libjfr\jfr.pdby+ source: jfr.dll.19.dr
Source: Binary string: api-ms-win-core-handle-l1-1-0.pdb source: api-ms-win-core-handle-l1-1-0.dll.19.dr
Source: Binary string: c:\workspace\8-2-build-windows-i586-cygwin\jdk8u191\11896\build\windows-i586\jdk\objs\java_objs\java.pdb source: java.exe.19.dr
Source: Binary string: c:\workspace\8-2-build-windows-i586-cygwin\jdk8u191\11896\build\windows-i586\jdk\objs\libjava_crw_demo\java_crw_demo.pdb98 source: java_crw_demo.dll.19.dr
Source: Binary string: c:\workspace\8-2-build-windows-i586-cygwin\jdk8u191\11896\build\windows-i586\jdk\objs\libfontmanager\fontmanager.pdb source: fontmanager.dll.19.dr
Source: Binary string: api-ms-win-core-synch-l1-2-0.pdb source: api-ms-win-core-synch-l1-2-0.dll.19.dr
Source: Binary string: c:\workspace\8-2-build-windows-i586-cygwin\jdk8u191\11896\build\windows-i586\deploy\tmp\javacpl\obj\javacpl.pdb< source: javacpl.cpl.19.dr
Source: Binary string: c:\workspace\8-2-build-windows-i586-cygwin\jdk8u191\11896\build\windows-i586\jdk\objs\libjava_crw_demo\java_crw_demo.pdb source: java_crw_demo.dll.19.dr
Source: Binary string: c:\workspace\8-2-build-windows-i586-cygwin\jdk8u191\11896\build\windows-i586\deploy\tmp\eula\obj\eula.pdb0 source: eula.dll.19.dr
Source: Binary string: c:\workspace\8-2-build-windows-i586-cygwin\jdk8u191\11896\build\windows-i586\jdk\objs\libinstrument\instrument.pdbp source: instrument.dll.19.dr
Source: Binary string: c:\workspace\8-2-build-windows-i586-cygwin\jdk8u191\11896\build\windows-i586\jdk\objs\libdt_socket\dt_socket.pdb source: dt_socket.dll.19.dr
Source: Binary string: api-ms-win-core-processenvironment-l1-1-0.pdb source: api-ms-win-core-processenvironment-l1-1-0.dll.19.dr
Source: Binary string: c:\workspace\8-2-build-windows-i586-cygwin\jdk8u191\11896\build\windows-i586\jdk\objs\libjawtaccessbridge\JAWTAccessBridge.pdb source: JAWTAccessBridge.dll.19.dr
Source: Binary string: api-ms-win-core-datetime-l1-1-0.pdb source: api-ms-win-core-datetime-l1-1-0.dll.19.dr
Source: Binary string: c:\workspace\8-2-build-windows-i586-cygwin\jdk8u191\11896\build\windows-i586\jdk\objs\javaw_objs\javaw.pdb source: javaw.exe.19.dr
Source: Binary string: c:\workspace\8-2-build-windows-i586-cygwin\jdk8u191\11896\build\windows-i586\jdk\objs\libhprof_jvmti\hprof.pdbi source: hprof.dll.19.dr
Source: Binary string: c:\workspace\8-2-build-windows-i586-cygwin\jdk8u191\11896\build\windows-i586\jdk\objs\libj2pcsc\j2pcsc.pdb source: j2pcsc.dll.19.dr
Source: Binary string: api-ms-win-crt-conio-l1-1-0.pdb source: api-ms-win-crt-conio-l1-1-0.dll.19.dr
Source: Binary string: c:\workspace\8-2-build-windows-i586-cygwin\jdk8u191\11896\build\windows-i586\jdk\objs\jabswitch\jabswitch.pdb source: jabswitch.exe.19.dr
Source: Binary string: c:\workspace\8-2-build-windows-i586-cygwin\jdk8u191\11896\build\windows-i586\deploy\tmp\javacplexec\obj\javacpl.pdb0 source: javacpl.exe.19.dr
Source: Binary string: api-ms-win-core-localization-l1-2-0.pdb source: api-ms-win-core-localization-l1-2-0.dll.19.dr
Source: Binary string: api-ms-win-crt-math-l1-1-0.pdb source: api-ms-win-crt-math-l1-1-0.dll.19.dr
Source: Binary string: c:\workspace\8-2-build-windows-i586-cygwin\jdk8u191\11896\build\windows-i586\jdk\objs\libjawt\jawt.pdb source: jawt.dll.19.dr
Source: Binary string: api-ms-win-core-processthreads-l1-1-1.pdb source: api-ms-win-core-processthreads-l1-1-1.dll.19.dr
Source: Binary string: c:\workspace\8-2-build-windows-i586-cygwin\jdk8u191\11896\build\windows-i586\jdk\objs\libinstrument\instrument.pdb source: instrument.dll.19.dr
Source: Binary string: c:\workspace\8-2-build-windows-i586-cygwin\jdk8u191\11896\build\windows-i586\jdk\objs\libjavaaccessbridge\JavaAccessBridge.pdb source: JavaAccessBridge.dll.19.dr
Source: Binary string: api-ms-win-core-namedpipe-l1-1-0.pdb source: api-ms-win-core-namedpipe-l1-1-0.dll.19.dr
Source: Binary string: api-ms-win-crt-multibyte-l1-1-0.pdb source: api-ms-win-crt-multibyte-l1-1-0.dll.19.dr
Source: Binary string: api-ms-win-crt-utility-l1-1-0.pdb source: api-ms-win-crt-utility-l1-1-0.dll.19.dr
Source: Binary string: api-ms-win-core-rtlsupport-l1-1-0.pdb source: api-ms-win-core-rtlsupport-l1-1-0.dll.19.dr
Source: Binary string: api-ms-win-core-timezone-l1-1-0.pdb source: api-ms-win-core-timezone-l1-1-0.dll.19.dr
Source: Binary string: api-ms-win-core-string-l1-1-0.pdb source: api-ms-win-core-string-l1-1-0.dll.19.dr
Source: Binary string: api-ms-win-core-file-l2-1-0.pdb source: api-ms-win-core-file-l2-1-0.dll.19.dr
Source: Binary string: api-ms-win-crt-process-l1-1-0.pdb source: api-ms-win-crt-process-l1-1-0.dll.19.dr
Source: Binary string: api-ms-win-core-libraryloader-l1-1-0.pdb source: api-ms-win-core-libraryloader-l1-1-0.dll.19.dr
Source: Binary string: c:\workspace\8-2-build-windows-i586-cygwin\jdk8u191\11896\build\windows-i586\deploy\jre-image\bin\deploy.pdb source: deploy.dll.19.dr
Source: Binary string: c:\workspace\8-2-build-windows-i586-cygwin\jdk8u191\11896\build\windows-i586\jdk\objs\libjdwp\jdwp.pdb source: jdwp.dll.19.dr
Source: Binary string: c:\workspace\8-2-build-windows-i586-cygwin\jdk8u191\11896\build\windows-i586\jdk\objs\libawt\awt.pdb8~ source: awt.dll.19.dr
Source: Binary string: c:\workspace\8-2-build-windows-i586-cygwin\jdk8u191\11896\build\windows-i586\jdk\objs\libdt_shmem\dt_shmem.pdb source: dt_shmem.dll.19.dr
Source: Binary string: api-ms-win-core-interlocked-l1-1-0.pdb source: api-ms-win-core-interlocked-l1-1-0.dll.19.dr
Source: Binary string: c:\workspace\8-2-build-windows-i586-cygwin\jdk8u191\11896\build\windows-i586\jdk\objs\libbci\bci.pdb source: bci.dll.19.dr
Source: Binary string: concrt140.i386.pdb source: concrt140.dll.19.dr
Source: Binary string: c:\workspace\8-2-build-windows-i586-cygwin\jdk8u191\11896\build\windows-i586\deploy\jre-image\bin\javaws.pdb source: javaws.exe.19.dr
Source: Binary string: c:\workspace\8-2-build-windows-i586-cygwin\jdk8u191\11896\build\windows-i586\jdk\objs\libfontmanager\fontmanager.pdb@ source: fontmanager.dll.19.dr
Source: Binary string: api-ms-win-crt-heap-l1-1-0.pdb source: api-ms-win-crt-heap-l1-1-0.dll.19.dr
Source: Binary string: api-ms-win-crt-string-l1-1-0.pdb source: api-ms-win-crt-string-l1-1-0.dll.19.dr
Source: Binary string: c:\workspace\8-2-build-windows-i586-cygwin\jdk8u191\11896\build\windows-i586\deploy\jre-image\bin\javaws.pdb| source: javaws.exe.19.dr

Data Obfuscation:

barindex
Launches a Java Jar file from a suspicious file locationShow sources
Source: Java tracingExecutes: java.lang.ProcessBuilder(java.lang.String[]) on c:\program files\java\jre1.8.0_191\bin\java.exe -javaagent:"c:\users\user~1\appdata\local\temp\jartracer.jar" -jar c:\users\user~1\appdata\local\temp\_0.63493269659919425532230313552172834.class
Source: Java tracingExecutes: java.lang.ProcessBuilder(java.lang.String[]) on reg add hkcu\software\microsoft\windows\currentversion\run /v bjnysnphoio /t reg_expand_sz /d \"c:\users\user\appdata\roaming\oracle\bin\javaw.exe\" -jar \"c:\users\user\ktxrptueuib\xszhgswuuvb.nxpnyg\" /f
Source: Java tracingExecutes: java.lang.ProcessBuilder(java.lang.String[]) on c:\users\user\appdata\roaming\oracle\bin\java.exe -javaagent:"c:\users\user~1\appdata\local\temp\jartracer.jar" -jar c:\users\user~1\appdata\local\temp\_0.259951839382067235585996733401964613.class

Persistence and Installation Behavior:

barindex
Drops PE filesShow sources
Source: C:\Windows\System32\xcopy.exeFile created: C:\Users\user\AppData\Roaming\Oracle\bin\api-ms-win-crt-heap-l1-1-0.dllJump to dropped file
Source: C:\Windows\System32\xcopy.exeFile created: C:\Users\user\AppData\Roaming\Oracle\bin\glass.dllJump to dropped file
Source: C:\Windows\System32\xcopy.exeFile created: C:\Users\user\AppData\Roaming\Oracle\bin\kinit.exeJump to dropped file
Source: C:\Windows\System32\xcopy.exeFile created: C:\Users\user\AppData\Roaming\Oracle\bin\nio.dllJump to dropped file
Source: C:\Windows\System32\xcopy.exeFile created: C:\Users\user\AppData\Roaming\Oracle\bin\api-ms-win-core-synch-l1-1-0.dllJump to dropped file
Source: C:\Windows\System32\xcopy.exeFile created: C:\Users\user\AppData\Roaming\Oracle\bin\client\jvm.dllJump to dropped file
Source: C:\Windows\System32\xcopy.exeFile created: C:\Users\user\AppData\Roaming\Oracle\bin\ssvagent.exeJump to dropped file
Source: C:\Windows\System32\xcopy.exeFile created: C:\Users\user\AppData\Roaming\Oracle\bin\instrument.dllJump to dropped file
Source: C:\Windows\System32\xcopy.exeFile created: C:\Users\user\AppData\Roaming\Oracle\bin\java_crw_demo.dllJump to dropped file
Source: C:\Windows\System32\xcopy.exeFile created: C:\Users\user\AppData\Roaming\Oracle\bin\fontmanager.dllJump to dropped file
Source: C:\Windows\System32\xcopy.exeFile created: C:\Users\user\AppData\Roaming\Oracle\bin\dt_shmem.dllJump to dropped file
Source: C:\Windows\System32\xcopy.exeFile created: C:\Users\user\AppData\Roaming\Oracle\bin\java.exeJump to dropped file
Source: C:\Windows\System32\xcopy.exeFile created: C:\Users\user\AppData\Roaming\Oracle\bin\javafx_font.dllJump to dropped file
Source: C:\Windows\System32\xcopy.exeFile created: C:\Users\user\AppData\Roaming\Oracle\bin\orbd.exeJump to dropped file
Source: C:\Windows\System32\xcopy.exeFile created: C:\Users\user\AppData\Roaming\Oracle\bin\pack200.exeJump to dropped file
Source: C:\Windows\System32\xcopy.exeFile created: C:\Users\user\AppData\Roaming\Oracle\bin\concrt140.dllJump to dropped file
Source: C:\Windows\System32\xcopy.exeFile created: C:\Users\user\AppData\Roaming\Oracle\bin\javafx_font_t2k.dllJump to dropped file
Source: C:\Windows\System32\xcopy.exeFile created: C:\Users\user\AppData\Roaming\Oracle\bin\rmiregistry.exeJump to dropped file
Source: C:\Windows\System32\xcopy.exeFile created: C:\Users\user\AppData\Roaming\Oracle\bin\api-ms-win-crt-locale-l1-1-0.dllJump to dropped file
Source: C:\Windows\System32\xcopy.exeFile created: C:\Users\user\AppData\Roaming\Oracle\bin\hprof.dllJump to dropped file
Source: C:\Windows\System32\xcopy.exeFile created: C:\Users\user\AppData\Roaming\Oracle\bin\t2k.dllJump to dropped file
Source: C:\Windows\System32\xcopy.exeFile created: C:\Users\user\AppData\Roaming\Oracle\bin\unpack200.exeJump to dropped file
Source: C:\Windows\System32\xcopy.exeFile created: C:\Users\user\AppData\Roaming\Oracle\bin\api-ms-win-core-memory-l1-1-0.dllJump to dropped file
Source: C:\Windows\System32\xcopy.exeFile created: C:\Users\user\AppData\Roaming\Oracle\bin\api-ms-win-core-errorhandling-l1-1-0.dllJump to dropped file
Source: C:\Windows\System32\xcopy.exeFile created: C:\Users\user\AppData\Roaming\Oracle\bin\WindowsAccessBridge.dllJump to dropped file
Source: C:\Windows\System32\xcopy.exeFile created: C:\Users\user\AppData\Roaming\Oracle\bin\api-ms-win-core-datetime-l1-1-0.dllJump to dropped file
Source: C:\Windows\System32\xcopy.exeFile created: C:\Users\user\AppData\Roaming\Oracle\bin\api-ms-win-crt-process-l1-1-0.dllJump to dropped file
Source: C:\Windows\System32\xcopy.exeFile created: C:\Users\user\AppData\Roaming\Oracle\bin\api-ms-win-core-namedpipe-l1-1-0.dllJump to dropped file
Source: C:\Windows\System32\xcopy.exeFile created: C:\Users\user\AppData\Roaming\Oracle\bin\api-ms-win-core-heap-l1-1-0.dllJump to dropped file
Source: C:\Windows\System32\xcopy.exeFile created: C:\Users\user\AppData\Roaming\Oracle\bin\jp2launcher.exeJump to dropped file
Source: C:\Windows\System32\xcopy.exeFile created: C:\Users\user\AppData\Roaming\Oracle\bin\api-ms-win-core-synch-l1-2-0.dllJump to dropped file
Source: C:\Windows\System32\xcopy.exeFile created: C:\Users\user\AppData\Roaming\Oracle\bin\zip.dllJump to dropped file
Source: C:\Windows\System32\xcopy.exeFile created: C:\Users\user\AppData\Roaming\Oracle\bin\javacpl.cplJump to dropped file
Source: C:\Windows\System32\xcopy.exeFile created: C:\Users\user\AppData\Roaming\Oracle\bin\jp2ssv.dllJump to dropped file
Source: C:\Windows\System32\xcopy.exeFile created: C:\Users\user\AppData\Roaming\Oracle\bin\javaws.exeJump to dropped file
Source: C:\Windows\System32\xcopy.exeFile created: C:\Users\user\AppData\Roaming\Oracle\bin\api-ms-win-crt-string-l1-1-0.dllJump to dropped file
Source: C:\Windows\System32\xcopy.exeFile created: C:\Users\user\AppData\Roaming\Oracle\bin\sunec.dllJump to dropped file
Source: C:\Windows\System32\xcopy.exeFile created: C:\Users\user\AppData\Roaming\Oracle\bin\api-ms-win-core-interlocked-l1-1-0.dllJump to dropped file
Source: C:\Windows\System32\xcopy.exeFile created: C:\Users\user\AppData\Roaming\Oracle\bin\mlib_image.dllJump to dropped file
Source: C:\Windows\System32\xcopy.exeFile created: C:\Users\user\AppData\Roaming\Oracle\bin\jsdt.dllJump to dropped file
Source: C:\Windows\System32\xcopy.exeFile created: C:\Users\user\AppData\Roaming\Oracle\bin\net.dllJump to dropped file
Source: C:\Windows\System32\xcopy.exeFile created: C:\Users\user\AppData\Roaming\Oracle\bin\prism_sw.dllJump to dropped file
Source: C:\Windows\System32\xcopy.exeFile created: C:\Users\user\AppData\Roaming\Oracle\bin\ktab.exeJump to dropped file
Source: C:\Windows\System32\xcopy.exeFile created: C:\Users\user\AppData\Roaming\Oracle\bin\verify.dllJump to dropped file
Source: C:\Windows\System32\xcopy.exeFile created: C:\Users\user\AppData\Roaming\Oracle\bin\plugin2\npjp2.dllJump to dropped file
Source: C:\Windows\System32\xcopy.exeFile created: C:\Users\user\AppData\Roaming\Oracle\bin\api-ms-win-core-processthreads-l1-1-0.dllJump to dropped file
Source: C:\Windows\System32\xcopy.exeFile created: C:\Users\user\AppData\Roaming\Oracle\bin\api-ms-win-crt-time-l1-1-0.dllJump to dropped file
Source: C:\Windows\System32\xcopy.exeFile created: C:\Users\user\AppData\Roaming\Oracle\bin\fxplugins.dllJump to dropped file
Source: C:\Windows\System32\xcopy.exeFile created: C:\Users\user\AppData\Roaming\Oracle\bin\glib-lite.dllJump to dropped file
Source: C:\Windows\System32\xcopy.exeFile created: C:\Users\user\AppData\Roaming\Oracle\bin\JAWTAccessBridge.dllJump to dropped file
Source: C:\Windows\System32\xcopy.exeFile created: C:\Users\user\AppData\Roaming\Oracle\bin\rmid.exeJump to dropped file
Source: C:\Windows\System32\xcopy.exeFile created: C:\Users\user\AppData\Roaming\Oracle\bin\api-ms-win-core-sysinfo-l1-1-0.dllJump to dropped file
Source: C:\Windows\System32\xcopy.exeFile created: C:\Users\user\AppData\Roaming\Oracle\bin\api-ms-win-crt-environment-l1-1-0.dllJump to dropped file
Source: C:\Windows\System32\xcopy.exeFile created: C:\Users\user\AppData\Roaming\Oracle\bin\prism_common.dllJump to dropped file
Source: C:\Windows\System32\xcopy.exeFile created: C:\Users\user\AppData\Roaming\Oracle\bin\jjs.exeJump to dropped file
Source: C:\Windows\System32\xcopy.exeFile created: C:\Users\user\AppData\Roaming\Oracle\bin\api-ms-win-core-profile-l1-1-0.dllJump to dropped file
Source: C:\Windows\System32\xcopy.exeFile created: C:\Users\user\AppData\Roaming\Oracle\bin\api-ms-win-core-processthreads-l1-1-1.dllJump to dropped file
Source: C:\Windows\System32\xcopy.exeFile created: C:\Users\user\AppData\Roaming\Oracle\bin\awt.dllJump to dropped file
Source: C:\Windows\System32\xcopy.exeFile created: C:\Users\user\AppData\Roaming\Oracle\bin\msvcr100.dllJump to dropped file
Source: C:\Windows\System32\xcopy.exeFile created: C:\Users\user\AppData\Roaming\Oracle\bin\management.dllJump to dropped file
Source: C:\Windows\System32\xcopy.exeFile created: C:\Users\user\AppData\Roaming\Oracle\bin\api-ms-win-crt-filesystem-l1-1-0.dllJump to dropped file
Source: C:\Windows\System32\xcopy.exeFile created: C:\Users\user\AppData\Roaming\Oracle\bin\api-ms-win-core-util-l1-1-0.dllJump to dropped file
Source: C:\Windows\System32\xcopy.exeFile created: C:\Users\user\AppData\Roaming\Oracle\bin\api-ms-win-core-file-l1-1-0.dllJump to dropped file
Source: C:\Windows\System32\xcopy.exeFile created: C:\Users\user\AppData\Roaming\Oracle\bin\javafx_iio.dllJump to dropped file
Source: C:\Windows\System32\xcopy.exeFile created: C:\Users\user\AppData\Roaming\Oracle\bin\jp2native.dllJump to dropped file
Source: C:\Windows\System32\xcopy.exeFile created: C:\Users\user\AppData\Roaming\Oracle\bin\sunmscapi.dllJump to dropped file
Source: C:\Windows\System32\xcopy.exeFile created: C:\Users\user\AppData\Roaming\Oracle\bin\dt_socket.dllJump to dropped file
Source: C:\Windows\System32\xcopy.exeFile created: C:\Users\user\AppData\Roaming\Oracle\bin\bci.dllJump to dropped file
Source: C:\Windows\System32\xcopy.exeFile created: C:\Users\user\AppData\Roaming\Oracle\bin\ucrtbase.dllJump to dropped file
Source: C:\Windows\System32\xcopy.exeFile created: C:\Users\user\AppData\Roaming\Oracle\bin\dcpr.dllJump to dropped file
Source: C:\Windows\System32\xcopy.exeFile created: C:\Users\user\AppData\Roaming\Oracle\bin\api-ms-win-core-processenvironment-l1-1-0.dllJump to dropped file
Source: C:\Windows\System32\xcopy.exeFile created: C:\Users\user\AppData\Roaming\Oracle\bin\dtplugin\deployJava1.dllJump to dropped file
Source: C:\Windows\System32\xcopy.exeFile created: C:\Users\user\AppData\Roaming\Oracle\bin\jdwp.dllJump to dropped file
Source: C:\Windows\System32\xcopy.exeFile created: C:\Users\user\AppData\Roaming\Oracle\bin\api-ms-win-core-debug-l1-1-0.dllJump to dropped file
Source: C:\Windows\System32\xcopy.exeFile created: C:\Users\user\AppData\Roaming\Oracle\bin\policytool.exeJump to dropped file
Source: C:\Windows\System32\xcopy.exeFile created: C:\Users\user\AppData\Roaming\Oracle\bin\dtplugin\npdeployJava1.dllJump to dropped file
Source: C:\Windows\System32\xcopy.exeFile created: C:\Users\user\AppData\Roaming\Oracle\bin\api-ms-win-crt-multibyte-l1-1-0.dllJump to dropped file
Source: C:\Windows\System32\xcopy.exeFile created: C:\Users\user\AppData\Roaming\Oracle\bin\jsound.dllJump to dropped file
Source: C:\Windows\System32\xcopy.exeFile created: C:\Users\user\AppData\Roaming\Oracle\bin\decora_sse.dllJump to dropped file
Source: C:\Windows\System32\xcopy.exeFile created: C:\Users\user\AppData\Roaming\Oracle\bin\splashscreen.dllJump to dropped file
Source: C:\Windows\System32\xcopy.exeFile created: C:\Users\user\AppData\Roaming\Oracle\bin\j2pkcs11.dllJump to dropped file
Source: C:\Windows\System32\xcopy.exeFile created: C:\Users\user\AppData\Roaming\Oracle\bin\jp2iexp.dllJump to dropped file
Source: C:\Windows\System32\xcopy.exeFile created: C:\Users\user\AppData\Roaming\Oracle\bin\api-ms-win-crt-stdio-l1-1-0.dllJump to dropped file
Source: C:\Windows\System32\xcopy.exeFile created: C:\Users\user\AppData\Roaming\Oracle\bin\api-ms-win-core-string-l1-1-0.dllJump to dropped file
Source: C:\Windows\System32\xcopy.exeFile created: C:\Users\user\AppData\Roaming\Oracle\bin\api-ms-win-core-rtlsupport-l1-1-0.dllJump to dropped file
Source: C:\Windows\System32\xcopy.exeFile created: C:\Users\user\AppData\Roaming\Oracle\bin\j2pcsc.dllJump to dropped file
Source: C:\Windows\System32\xcopy.exeFile created: C:\Users\user\AppData\Roaming\Oracle\bin\api-ms-win-crt-utility-l1-1-0.dllJump to dropped file
Source: C:\Windows\System32\xcopy.exeFile created: C:\Users\user\AppData\Roaming\Oracle\bin\api-ms-win-crt-runtime-l1-1-0.dllJump to dropped file
Source: C:\Windows\System32\xcopy.exeFile created: C:\Users\user\AppData\Roaming\Oracle\bin\gstreamer-lite.dllJump to dropped file
Source: C:\Windows\System32\xcopy.exeFile created: C:\Users\user\AppData\Roaming\Oracle\bin\java-rmi.exeJump to dropped file
Source: C:\Windows\System32\xcopy.exeFile created: C:\Users\user\AppData\Roaming\Oracle\bin\jabswitch.exeJump to dropped file
Source: C:\Windows\System32\xcopy.exeFile created: C:\Users\user\AppData\Roaming\Oracle\bin\keytool.exeJump to dropped file
Source: C:\Windows\System32\xcopy.exeFile created: C:\Users\user\AppData\Roaming\Oracle\bin\api-ms-win-core-file-l1-2-0.dllJump to dropped file
Source: C:\Windows\System32\xcopy.exeFile created: C:\Users\user\AppData\Roaming\Oracle\bin\javaw.exeJump to dropped file
Source: C:\Windows\System32\xcopy.exeFile created: C:\Users\user\AppData\Roaming\Oracle\bin\kcms.dllJump to dropped file
Source: C:\Windows\System32\xcopy.exeFile created: C:\Users\user\AppData\Roaming\Oracle\bin\lcms.dllJump to dropped file
Source: C:\Windows\System32\xcopy.exeFile created: C:\Users\user\AppData\Roaming\Oracle\bin\jfxwebkit.dllJump to dropped file
Source: C:\Windows\System32\xcopy.exeFile created: C:\Users\user\AppData\Roaming\Oracle\bin\jaas_nt.dllJump to dropped file
Source: C:\Windows\System32\xcopy.exeFile created: C:\Users\user\AppData\Roaming\Oracle\bin\api-ms-win-crt-private-l1-1-0.dllJump to dropped file
Source: C:\Windows\System32\xcopy.exeFile created: C:\Users\user\AppData\Roaming\Oracle\bin\servertool.exeJump to dropped file
Source: C:\Windows\System32\xcopy.exeFile created: C:\Users\user\AppData\Roaming\Oracle\bin\jsoundds.dllJump to dropped file
Source: C:\Windows\System32\xcopy.exeFile created: C:\Users\user\AppData\Roaming\Oracle\bin\jfxmedia.dllJump to dropped file
Source: C:\Windows\System32\xcopy.exeFile created: C:\Users\user\AppData\Roaming\Oracle\bin\api-ms-win-core-console-l1-1-0.dllJump to dropped file
Source: C:\Windows\System32\xcopy.exeFile created: C:\Users\user\AppData\Roaming\Oracle\bin\api-ms-win-core-file-l2-1-0.dllJump to dropped file
Source: C:\Windows\System32\xcopy.exeFile created: C:\Users\user\AppData\Roaming\Oracle\bin\msvcp140.dllJump to dropped file
Source: C:\Windows\System32\xcopy.exeFile created: C:\Users\user\AppData\Roaming\Oracle\bin\w2k_lsa_auth.dllJump to dropped file
Source: C:\Windows\System32\xcopy.exeFile created: C:\Users\user\AppData\Roaming\Oracle\bin\npt.dllJump to dropped file
Source: C:\Windows\System32\xcopy.exeFile created: C:\Users\user\AppData\Roaming\Oracle\bin\resource.dllJump to dropped file
Source: C:\Windows\System32\xcopy.exeFile created: C:\Users\user\AppData\Roaming\Oracle\bin\jpeg.dllJump to dropped file
Source: C:\Windows\System32\xcopy.exeFile created: C:\Users\user\AppData\Roaming\Oracle\bin\jfr.dllJump to dropped file
Source: C:\Windows\System32\xcopy.exeFile created: C:\Users\user\AppData\Roaming\Oracle\bin\api-ms-win-core-localization-l1-2-0.dllJump to dropped file
Source: C:\Windows\System32\xcopy.exeFile created: C:\Users\user\AppData\Roaming\Oracle\bin\api-ms-win-crt-math-l1-1-0.dllJump to dropped file
Source: C:\Windows\System32\xcopy.exeFile created: C:\Users\user\AppData\Roaming\Oracle\bin\jawt.dllJump to dropped file
Source: C:\Windows\System32\xcopy.exeFile created: C:\Users\user\AppData\Roaming\Oracle\bin\klist.exeJump to dropped file
Source: C:\Windows\System32\xcopy.exeFile created: C:\Users\user\AppData\Roaming\Oracle\bin\javacpl.exeJump to dropped file
Source: C:\Windows\System32\xcopy.exeFile created: C:\Users\user\AppData\Roaming\Oracle\bin\jli.dllJump to dropped file
Source: C:\Windows\System32\xcopy.exeFile created: C:\Users\user\AppData\Roaming\Oracle\bin\vcruntime140.dllJump to dropped file
Source: C:\Windows\System32\xcopy.exeFile created: C:\Users\user\AppData\Roaming\Oracle\bin\eula.dllJump to dropped file
Source: C:\Windows\System32\xcopy.exeFile created: C:\Users\user\AppData\Roaming\Oracle\bin\api-ms-win-core-timezone-l1-1-0.dllJump to dropped file
Source: C:\Windows\System32\xcopy.exeFile created: C:\Users\user\AppData\Roaming\Oracle\bin\unpack.dllJump to dropped file
Source: C:\Windows\System32\xcopy.exeFile created: C:\Users\user\AppData\Roaming\Oracle\bin\wsdetect.dllJump to dropped file
Source: C:\Windows\System32\xcopy.exeFile created: C:\Users\user\AppData\Roaming\Oracle\bin\plugin2\msvcr100.dllJump to dropped file
Source: C:\Windows\System32\xcopy.exeFile created: C:\Users\user\AppData\Roaming\Oracle\bin\prism_d3d.dllJump to dropped file
Source: C:\Windows\System32\xcopy.exeFile created: C:\Users\user\AppData\Roaming\Oracle\bin\api-ms-win-core-libraryloader-l1-1-0.dllJump to dropped file
Source: C:\Windows\System32\xcopy.exeFile created: C:\Users\user\AppData\Roaming\Oracle\bin\tnameserv.exeJump to dropped file
Source: C:\Windows\System32\xcopy.exeFile created: C:\Users\user\AppData\Roaming\Oracle\bin\api-ms-win-crt-convert-l1-1-0.dllJump to dropped file
Source: C:\Windows\System32\xcopy.exeFile created: C:\Users\user\AppData\Roaming\Oracle\bin\java.dllJump to dropped file
Source: C:\Windows\System32\xcopy.exeFile created: C:\Users\user\AppData\Roaming\Oracle\bin\JavaAccessBridge.dllJump to dropped file
Source: C:\Windows\System32\xcopy.exeFile created: C:\Users\user\AppData\Roaming\Oracle\bin\deploy.dllJump to dropped file
Source: C:\Windows\System32\xcopy.exeFile created: C:\Users\user\AppData\Roaming\Oracle\bin\ssv.dllJump to dropped file
Source: C:\Windows\System32\xcopy.exeFile created: C:\Users\user\AppData\Roaming\Oracle\bin\api-ms-win-crt-conio-l1-1-0.dllJump to dropped file
Source: C:\Windows\System32\xcopy.exeFile created: C:\Users\user\AppData\Roaming\Oracle\bin\api-ms-win-core-handle-l1-1-0.dllJump to dropped file
Drops files with a non-matching file extension (content does not match file extension)Show sources
Source: C:\Windows\System32\xcopy.exeFile created: C:\Users\user\AppData\Roaming\Oracle\bin\javacpl.cplJump to dropped file
Creates license or readme fileShow sources
Source: C:\Windows\System32\xcopy.exeFile created: C:\Users\user\AppData\Roaming\Oracle\README.txt
Source: C:\Windows\System32\xcopy.exeFile created: C:\Users\user\AppData\Roaming\Oracle\THIRDPARTYLICENSEREADME-JAVAFX.txt
Source: C:\Windows\System32\xcopy.exeFile created: C:\Users\user\AppData\Roaming\Oracle\THIRDPARTYLICENSEREADME-JAVAFX.txt
Source: C:\Windows\System32\xcopy.exeFile created: C:\Users\user\AppData\Roaming\Oracle\THIRDPARTYLICENSEREADME.txt
Source: C:\Windows\System32\xcopy.exeFile created: C:\Users\user\AppData\Roaming\Oracle\THIRDPARTYLICENSEREADME.txt

Boot Survival:

barindex
Creates autostart registry keys to launch javaShow sources
Source: C:\Windows\System32\reg.exeRegistry value created or modified: HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run bJnYSNphoio "C:\Users\user\AppData\Roaming\Oracle\bin\javaw.exe" -jar "C:\Users\user\KtXRptueuIB\XSZHGSWUUvB.nxPNyG"
Java Jar creates autostart registry key (Windows persistence behavior)Show sources
Source: Java tracingJava Jar creates autostart registry key: java.lang.ProcessBuilder(java.lang.String[]) on reg add HKCU\Software\Microsoft\Windows\CurrentVersion\Run /v bJnYSNphoio /t REG_EXPAND_SZ /d \"C:\Users\user\AppData\Roaming\Oracle\bin\javaw.exe\" -jar \"C:\Users\user\KtXRptueuIB\XSZHGSWUUvB.nxPNyG\" /f
Creates an autostart registry keyShow sources
Source: C:\Windows\System32\reg.exeRegistry value created or modified: HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run bJnYSNphoio
Source: C:\Windows\System32\reg.exeRegistry value created or modified: HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run bJnYSNphoio

Hooking and other Techniques for Hiding and Protection:

barindex
Java Jar changes file attribute to hide it from userShow sources
Source: Java tracingJava Jar changes file attribute to hide it: java.lang.ProcessBuilder(java.lang.String[]) on attrib +h "C:\Users\user\KtXRptueuIB\*.*"
Uses cacls to modify the permissions of filesShow sources
Source: unknownProcess created: C:\Windows\System32\icacls.exe C:\Windows\system32\icacls.exe C:\ProgramData\Oracle\Java\.oracle_jre_usage /grant 'everyone':(OI)(CI)M
Disables application error messsages (SetErrorMode)Show sources
Source: C:\Windows\System32\cmd.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Windows\System32\cmd.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Windows\System32\cmd.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Windows\System32\cmd.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Windows\System32\cmd.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Windows\System32\cmd.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Windows\System32\cmd.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Program Files\Java\jre1.8.0_191\bin\java.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Program Files\Java\jre1.8.0_191\bin\java.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Program Files\Java\jre1.8.0_191\bin\java.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Program Files\Java\jre1.8.0_191\bin\java.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Program Files\Java\jre1.8.0_191\bin\java.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Program Files\Java\jre1.8.0_191\bin\java.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Program Files\Java\jre1.8.0_191\bin\java.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Program Files\Java\jre1.8.0_191\bin\java.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Program Files\Java\jre1.8.0_191\bin\java.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Program Files\Java\jre1.8.0_191\bin\java.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Program Files\Java\jre1.8.0_191\bin\java.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Program Files\Java\jre1.8.0_191\bin\java.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Windows\System32\cmd.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Windows\System32\cmd.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Windows\System32\cmd.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Windows\System32\cmd.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Windows\System32\cmd.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Windows\System32\cscript.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Windows\System32\cscript.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Windows\System32\cscript.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Windows\System32\cscript.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Windows\System32\cmd.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Windows\System32\cscript.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Windows\System32\cscript.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Windows\System32\cscript.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Windows\System32\cscript.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Windows\System32\cmd.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Windows\System32\cscript.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Windows\System32\cscript.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Windows\System32\cscript.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Windows\System32\cscript.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Windows\System32\cmd.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Windows\System32\cscript.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Windows\System32\cscript.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Windows\System32\cscript.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Windows\System32\cscript.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Windows\System32\cmd.exeProcess information set: NOOPENFILEERRORBOX
Source: C:\Users\user\AppData\Roaming\Oracle\bin\javaw.exeProcess information set: NOOPENFILEERRORBOX
Source: C:\Users\user\AppData\Roaming\Oracle\bin\javaw.exeProcess information set: NOOPENFILEERRORBOX
Source: C:\Users\user\AppData\Roaming\Oracle\bin\javaw.exeProcess information set: NOOPENFILEERRORBOX
Source: C:\Users\user\AppData\Roaming\Oracle\bin\javaw.exeProcess information set: NOOPENFILEERRORBOX
Source: C:\Users\user\AppData\Roaming\Oracle\bin\javaw.exeProcess information set: NOOPENFILEERRORBOX
Source: C:\Users\user\AppData\Roaming\Oracle\bin\javaw.exeProcess information set: NOOPENFILEERRORBOX
Source: C:\Users\user\AppData\Roaming\Oracle\bin\javaw.exeProcess information set: NOOPENFILEERRORBOX
Source: C:\Users\user\AppData\Roaming\Oracle\bin\javaw.exeProcess information set: NOOPENFILEERRORBOX
Source: C:\Users\user\AppData\Roaming\Oracle\bin\javaw.exeProcess information set: NOOPENFILEERRORBOX
Source: C:\Users\user\AppData\Roaming\Oracle\bin\javaw.exeProcess information set: NOOPENFILEERRORBOX
Source: C:\Users\user\AppData\Roaming\Oracle\bin\javaw.exeProcess information set: NOOPENFILEERRORBOX
Source: C:\Users\user\AppData\Roaming\Oracle\bin\javaw.exeProcess information set: NOOPENFILEERRORBOX
Source: C:\Users\user\AppData\Roaming\Oracle\bin\javaw.exeProcess information set: NOOPENFILEERRORBOX
Source: C:\Users\user\AppData\Roaming\Oracle\bin\javaw.exeProcess information set: NOOPENFILEERRORBOX
Source: C:\Windows\System32\cscript.exeProcess information set: NOOPENFILEERRORBOX
Source: C:\Windows\System32\cscript.exeProcess information set: NOOPENFILEERRORBOX

Malware Analysis System Evasion:

barindex
Enumerates the file systemShow sources
Source: C:\Users\user\AppData\Roaming\Oracle\bin\javaw.exeFile opened: C:\Users\user\AppData\Roaming\
Source: C:\Users\user\AppData\Roaming\Oracle\bin\javaw.exeFile opened: C:\Users\user\AppData\Roaming\Oracle\
Source: C:\Users\user\AppData\Roaming\Oracle\bin\javaw.exeFile opened: C:\Users\user\AppData\
Source: C:\Users\user\AppData\Roaming\Oracle\bin\javaw.exeFile opened: C:\Users\user\
Source: C:\Users\user\AppData\Roaming\Oracle\bin\javaw.exeFile opened: C:\Users\user\AppData\Roaming\Oracle\lib\
Source: C:\Users\user\AppData\Roaming\Oracle\bin\javaw.exeFile opened: C:\Users\user\AppData\Roaming\Oracle\lib\ext\
Found dropped PE file which has not been started or loadedShow sources
Source: C:\Windows\System32\xcopy.exeDropped PE file which has not been started: C:\Users\user\AppData\Roaming\Oracle\bin\glass.dllJump to dropped file
Source: C:\Windows\System32\xcopy.exeDropped PE file which has not been started: C:\Users\user\AppData\Roaming\Oracle\bin\api-ms-win-crt-heap-l1-1-0.dllJump to dropped file
Source: C:\Windows\System32\xcopy.exeDropped PE file which has not been started: C:\Users\user\AppData\Roaming\Oracle\bin\kinit.exeJump to dropped file
Source: C:\Windows\System32\xcopy.exeDropped PE file which has not been started: C:\Users\user\AppData\Roaming\Oracle\bin\api-ms-win-core-synch-l1-1-0.dllJump to dropped file
Source: C:\Windows\System32\xcopy.exeDropped PE file which has not been started: C:\Users\user\AppData\Roaming\Oracle\bin\ssvagent.exeJump to dropped file
Source: C:\Windows\System32\xcopy.exeDropped PE file which has not been started: C:\Users\user\AppData\Roaming\Oracle\bin\java_crw_demo.dllJump to dropped file
Source: C:\Windows\System32\xcopy.exeDropped PE file which has not been started: C:\Users\user\AppData\Roaming\Oracle\bin\fontmanager.dllJump to dropped file
Source: C:\Windows\System32\xcopy.exeDropped PE file which has not been started: C:\Users\user\AppData\Roaming\Oracle\bin\dt_shmem.dllJump to dropped file
Source: C:\Windows\System32\xcopy.exeDropped PE file which has not been started: C:\Users\user\AppData\Roaming\Oracle\bin\javafx_font.dllJump to dropped file
Source: C:\Windows\System32\xcopy.exeDropped PE file which has not been started: C:\Users\user\AppData\Roaming\Oracle\bin\orbd.exeJump to dropped file
Source: C:\Windows\System32\xcopy.exeDropped PE file which has not been started: C:\Users\user\AppData\Roaming\Oracle\bin\pack200.exeJump to dropped file
Source: C:\Windows\System32\xcopy.exeDropped PE file which has not been started: C:\Users\user\AppData\Roaming\Oracle\bin\concrt140.dllJump to dropped file
Source: C:\Windows\System32\xcopy.exeDropped PE file which has not been started: C:\Users\user\AppData\Roaming\Oracle\bin\javafx_font_t2k.dllJump to dropped file
Source: C:\Windows\System32\xcopy.exeDropped PE file which has not been started: C:\Users\user\AppData\Roaming\Oracle\bin\rmiregistry.exeJump to dropped file
Source: C:\Windows\System32\xcopy.exeDropped PE file which has not been started: C:\Users\user\AppData\Roaming\Oracle\bin\api-ms-win-crt-locale-l1-1-0.dllJump to dropped file
Source: C:\Windows\System32\xcopy.exeDropped PE file which has not been started: C:\Users\user\AppData\Roaming\Oracle\bin\t2k.dllJump to dropped file
Source: C:\Windows\System32\xcopy.exeDropped PE file which has not been started: C:\Users\user\AppData\Roaming\Oracle\bin\hprof.dllJump to dropped file
Source: C:\Windows\System32\xcopy.exeDropped PE file which has not been started: C:\Users\user\AppData\Roaming\Oracle\bin\unpack200.exeJump to dropped file
Source: C:\Windows\System32\xcopy.exeDropped PE file which has not been started: C:\Users\user\AppData\Roaming\Oracle\bin\api-ms-win-core-memory-l1-1-0.dllJump to dropped file
Source: C:\Windows\System32\xcopy.exeDropped PE file which has not been started: C:\Users\user\AppData\Roaming\Oracle\bin\api-ms-win-core-errorhandling-l1-1-0.dllJump to dropped file
Source: C:\Windows\System32\xcopy.exeDropped PE file which has not been started: C:\Users\user\AppData\Roaming\Oracle\bin\WindowsAccessBridge.dllJump to dropped file
Source: C:\Windows\System32\xcopy.exeDropped PE file which has not been started: C:\Users\user\AppData\Roaming\Oracle\bin\api-ms-win-crt-process-l1-1-0.dllJump to dropped file
Source: C:\Windows\System32\xcopy.exeDropped PE file which has not been started: C:\Users\user\AppData\Roaming\Oracle\bin\api-ms-win-core-datetime-l1-1-0.dllJump to dropped file
Source: C:\Windows\System32\xcopy.exeDropped PE file which has not been started: C:\Users\user\AppData\Roaming\Oracle\bin\api-ms-win-core-namedpipe-l1-1-0.dllJump to dropped file
Source: C:\Windows\System32\xcopy.exeDropped PE file which has not been started: C:\Users\user\AppData\Roaming\Oracle\bin\api-ms-win-core-heap-l1-1-0.dllJump to dropped file
Source: C:\Windows\System32\xcopy.exeDropped PE file which has not been started: C:\Users\user\AppData\Roaming\Oracle\bin\jp2launcher.exeJump to dropped file
Source: C:\Windows\System32\xcopy.exeDropped PE file which has not been started: C:\Users\user\AppData\Roaming\Oracle\bin\api-ms-win-core-synch-l1-2-0.dllJump to dropped file
Source: C:\Windows\System32\xcopy.exeDropped PE file which has not been started: C:\Users\user\AppData\Roaming\Oracle\bin\javacpl.cplJump to dropped file
Source: C:\Windows\System32\xcopy.exeDropped PE file which has not been started: C:\Users\user\AppData\Roaming\Oracle\bin\jp2ssv.dllJump to dropped file
Source: C:\Windows\System32\xcopy.exeDropped PE file which has not been started: C:\Users\user\AppData\Roaming\Oracle\bin\javaws.exeJump to dropped file
Source: C:\Windows\System32\xcopy.exeDropped PE file which has not been started: C:\Users\user\AppData\Roaming\Oracle\bin\api-ms-win-crt-string-l1-1-0.dllJump to dropped file
Source: C:\Windows\System32\xcopy.exeDropped PE file which has not been started: C:\Users\user\AppData\Roaming\Oracle\bin\mlib_image.dllJump to dropped file
Source: C:\Windows\System32\xcopy.exeDropped PE file which has not been started: C:\Users\user\AppData\Roaming\Oracle\bin\api-ms-win-core-interlocked-l1-1-0.dllJump to dropped file
Source: C:\Windows\System32\xcopy.exeDropped PE file which has not been started: C:\Users\user\AppData\Roaming\Oracle\bin\jsdt.dllJump to dropped file
Source: C:\Windows\System32\xcopy.exeDropped PE file which has not been started: C:\Users\user\AppData\Roaming\Oracle\bin\prism_sw.dllJump to dropped file
Source: C:\Windows\System32\xcopy.exeDropped PE file which has not been started: C:\Users\user\AppData\Roaming\Oracle\bin\ktab.exeJump to dropped file
Source: C:\Windows\System32\xcopy.exeDropped PE file which has not been started: C:\Users\user\AppData\Roaming\Oracle\bin\plugin2\npjp2.dllJump to dropped file
Source: C:\Windows\System32\xcopy.exeDropped PE file which has not been started: C:\Users\user\AppData\Roaming\Oracle\bin\api-ms-win-core-processthreads-l1-1-0.dllJump to dropped file
Source: C:\Windows\System32\xcopy.exeDropped PE file which has not been started: C:\Users\user\AppData\Roaming\Oracle\bin\api-ms-win-crt-time-l1-1-0.dllJump to dropped file
Source: C:\Windows\System32\xcopy.exeDropped PE file which has not been started: C:\Users\user\AppData\Roaming\Oracle\bin\fxplugins.dllJump to dropped file
Source: C:\Windows\System32\xcopy.exeDropped PE file which has not been started: C:\Users\user\AppData\Roaming\Oracle\bin\JAWTAccessBridge.dllJump to dropped file
Source: C:\Windows\System32\xcopy.exeDropped PE file which has not been started: C:\Users\user\AppData\Roaming\Oracle\bin\glib-lite.dllJump to dropped file
Source: C:\Windows\System32\xcopy.exeDropped PE file which has not been started: C:\Users\user\AppData\Roaming\Oracle\bin\rmid.exeJump to dropped file
Source: C:\Windows\System32\xcopy.exeDropped PE file which has not been started: C:\Users\user\AppData\Roaming\Oracle\bin\api-ms-win-crt-environment-l1-1-0.dllJump to dropped file
Source: C:\Windows\System32\xcopy.exeDropped PE file which has not been started: C:\Users\user\AppData\Roaming\Oracle\bin\api-ms-win-core-sysinfo-l1-1-0.dllJump to dropped file
Source: C:\Windows\System32\xcopy.exeDropped PE file which has not been started: C:\Users\user\AppData\Roaming\Oracle\bin\prism_common.dllJump to dropped file
Source: C:\Windows\System32\xcopy.exeDropped PE file which has not been started: C:\Users\user\AppData\Roaming\Oracle\bin\jjs.exeJump to dropped file
Source: C:\Windows\System32\xcopy.exeDropped PE file which has not been started: C:\Users\user\AppData\Roaming\Oracle\bin\api-ms-win-core-profile-l1-1-0.dllJump to dropped file
Source: C:\Windows\System32\xcopy.exeDropped PE file which has not been started: C:\Users\user\AppData\Roaming\Oracle\bin\api-ms-win-core-processthreads-l1-1-1.dllJump to dropped file
Source: C:\Windows\System32\xcopy.exeDropped PE file which has not been started: C:\Users\user\AppData\Roaming\Oracle\bin\api-ms-win-crt-filesystem-l1-1-0.dllJump to dropped file
Source: C:\Windows\System32\xcopy.exeDropped PE file which has not been started: C:\Users\user\AppData\Roaming\Oracle\bin\api-ms-win-core-util-l1-1-0.dllJump to dropped file
Source: C:\Windows\System32\xcopy.exeDropped PE file which has not been started: C:\Users\user\AppData\Roaming\Oracle\bin\javafx_iio.dllJump to dropped file
Source: C:\Windows\System32\xcopy.exeDropped PE file which has not been started: C:\Users\user\AppData\Roaming\Oracle\bin\api-ms-win-core-file-l1-1-0.dllJump to dropped file
Source: C:\Windows\System32\xcopy.exeDropped PE file which has not been started: C:\Users\user\AppData\Roaming\Oracle\bin\jp2native.dllJump to dropped file
Source: C:\Windows\System32\xcopy.exeDropped PE file which has not been started: C:\Users\user\AppData\Roaming\Oracle\bin\dt_socket.dllJump to dropped file
Source: C:\Windows\System32\xcopy.exeDropped PE file which has not been started: C:\Users\user\AppData\Roaming\Oracle\bin\bci.dllJump to dropped file
Source: C:\Windows\System32\xcopy.exeDropped PE file which has not been started: C:\Users\user\AppData\Roaming\Oracle\bin\ucrtbase.dllJump to dropped file
Source: C:\Windows\System32\xcopy.exeDropped PE file which has not been started: C:\Users\user\AppData\Roaming\Oracle\bin\api-ms-win-core-processenvironment-l1-1-0.dllJump to dropped file
Source: C:\Windows\System32\xcopy.exeDropped PE file which has not been started: C:\Users\user\AppData\Roaming\Oracle\bin\dcpr.dllJump to dropped file
Source: C:\Windows\System32\xcopy.exeDropped PE file which has not been started: C:\Users\user\AppData\Roaming\Oracle\bin\dtplugin\deployJava1.dllJump to dropped file
Source: C:\Windows\System32\xcopy.exeDropped PE file which has not been started: C:\Users\user\AppData\Roaming\Oracle\bin\jdwp.dllJump to dropped file
Source: C:\Windows\System32\xcopy.exeDropped PE file which has not been started: C:\Users\user\AppData\Roaming\Oracle\bin\api-ms-win-core-debug-l1-1-0.dllJump to dropped file
Source: C:\Windows\System32\xcopy.exeDropped PE file which has not been started: C:\Users\user\AppData\Roaming\Oracle\bin\policytool.exeJump to dropped file
Source: C:\Windows\System32\xcopy.exeDropped PE file which has not been started: C:\Users\user\AppData\Roaming\Oracle\bin\dtplugin\npdeployJava1.dllJump to dropped file
Source: C:\Windows\System32\xcopy.exeDropped PE file which has not been started: C:\Users\user\AppData\Roaming\Oracle\bin\api-ms-win-crt-multibyte-l1-1-0.dllJump to dropped file
Source: C:\Windows\System32\xcopy.exeDropped PE file which has not been started: C:\Users\user\AppData\Roaming\Oracle\bin\jsound.dllJump to dropped file
Source: C:\Windows\System32\xcopy.exeDropped PE file which has not been started: C:\Users\user\AppData\Roaming\Oracle\bin\decora_sse.dllJump to dropped file
Source: C:\Windows\System32\xcopy.exeDropped PE file which has not been started: C:\Users\user\AppData\Roaming\Oracle\bin\splashscreen.dllJump to dropped file
Source: C:\Windows\System32\xcopy.exeDropped PE file which has not been started: C:\Users\user\AppData\Roaming\Oracle\bin\j2pkcs11.dllJump to dropped file
Source: C:\Windows\System32\xcopy.exeDropped PE file which has not been started: C:\Users\user\AppData\Roaming\Oracle\bin\jp2iexp.dllJump to dropped file
Source: C:\Windows\System32\xcopy.exeDropped PE file which has not been started: C:\Users\user\AppData\Roaming\Oracle\bin\api-ms-win-crt-stdio-l1-1-0.dllJump to dropped file
Source: C:\Windows\System32\xcopy.exeDropped PE file which has not been started: C:\Users\user\AppData\Roaming\Oracle\bin\api-ms-win-core-string-l1-1-0.dllJump to dropped file
Source: C:\Windows\System32\xcopy.exeDropped PE file which has not been started: C:\Users\user\AppData\Roaming\Oracle\bin\j2pcsc.dllJump to dropped file
Source: C:\Windows\System32\xcopy.exeDropped PE file which has not been started: C:\Users\user\AppData\Roaming\Oracle\bin\api-ms-win-core-rtlsupport-l1-1-0.dllJump to dropped file
Source: C:\Windows\System32\xcopy.exeDropped PE file which has not been started: C:\Users\user\AppData\Roaming\Oracle\bin\api-ms-win-crt-utility-l1-1-0.dllJump to dropped file
Source: C:\Windows\System32\xcopy.exeDropped PE file which has not been started: C:\Users\user\AppData\Roaming\Oracle\bin\api-ms-win-crt-runtime-l1-1-0.dllJump to dropped file
Source: C:\Windows\System32\xcopy.exeDropped PE file which has not been started: C:\Users\user\AppData\Roaming\Oracle\bin\gstreamer-lite.dllJump to dropped file
Source: C:\Windows\System32\xcopy.exeDropped PE file which has not been started: C:\Users\user\AppData\Roaming\Oracle\bin\java-rmi.exeJump to dropped file
Source: C:\Windows\System32\xcopy.exeDropped PE file which has not been started: C:\Users\user\AppData\Roaming\Oracle\bin\keytool.exeJump to dropped file
Source: C:\Windows\System32\xcopy.exeDropped PE file which has not been started: C:\Users\user\AppData\Roaming\Oracle\bin\jabswitch.exeJump to dropped file
Source: C:\Windows\System32\xcopy.exeDropped PE file which has not been started: C:\Users\user\AppData\Roaming\Oracle\bin\api-ms-win-core-file-l1-2-0.dllJump to dropped file
Source: C:\Windows\System32\xcopy.exeDropped PE file which has not been started: C:\Users\user\AppData\Roaming\Oracle\bin\kcms.dllJump to dropped file
Source: C:\Windows\System32\xcopy.exeDropped PE file which has not been started: C:\Users\user\AppData\Roaming\Oracle\bin\lcms.dllJump to dropped file
Source: C:\Windows\System32\xcopy.exeDropped PE file which has not been started: C:\Users\user\AppData\Roaming\Oracle\bin\jfxwebkit.dllJump to dropped file
Source: C:\Windows\System32\xcopy.exeDropped PE file which has not been started: C:\Users\user\AppData\Roaming\Oracle\bin\jaas_nt.dllJump to dropped file
Source: C:\Windows\System32\xcopy.exeDropped PE file which has not been started: C:\Users\user\AppData\Roaming\Oracle\bin\api-ms-win-crt-private-l1-1-0.dllJump to dropped file
Source: C:\Windows\System32\xcopy.exeDropped PE file which has not been started: C:\Users\user\AppData\Roaming\Oracle\bin\servertool.exeJump to dropped file
Source: C:\Windows\System32\xcopy.exeDropped PE file which has not been started: C:\Users\user\AppData\Roaming\Oracle\bin\jsoundds.dllJump to dropped file
Source: C:\Windows\System32\xcopy.exeDropped PE file which has not been started: C:\Users\user\AppData\Roaming\Oracle\bin\jfxmedia.dllJump to dropped file
Source: C:\Windows\System32\xcopy.exeDropped PE file which has not been started: C:\Users\user\AppData\Roaming\Oracle\bin\api-ms-win-core-file-l2-1-0.dllJump to dropped file
Source: C:\Windows\System32\xcopy.exeDropped PE file which has not been started: C:\Users\user\AppData\Roaming\Oracle\bin\api-ms-win-core-console-l1-1-0.dllJump to dropped file
Source: C:\Windows\System32\xcopy.exeDropped PE file which has not been started: C:\Users\user\AppData\Roaming\Oracle\bin\msvcp140.dllJump to dropped file
Source: C:\Windows\System32\xcopy.exeDropped PE file which has not been started: C:\Users\user\AppData\Roaming\Oracle\bin\w2k_lsa_auth.dllJump to dropped file
Source: C:\Windows\System32\xcopy.exeDropped PE file which has not been started: C:\Users\user\AppData\Roaming\Oracle\bin\npt.dllJump to dropped file
Source: C:\Windows\System32\xcopy.exeDropped PE file which has not been started: C:\Users\user\AppData\Roaming\Oracle\bin\resource.dllJump to dropped file
Source: C:\Windows\System32\xcopy.exeDropped PE file which has not been started: C:\Users\user\AppData\Roaming\Oracle\bin\jpeg.dllJump to dropped file
Source: C:\Windows\System32\xcopy.exeDropped PE file which has not been started: C:\Users\user\AppData\Roaming\Oracle\bin\jfr.dllJump to dropped file
Source: C:\Windows\System32\xcopy.exeDropped PE file which has not been started: C:\Users\user\AppData\Roaming\Oracle\bin\api-ms-win-crt-math-l1-1-0.dllJump to dropped file
Source: C:\Windows\System32\xcopy.exeDropped PE file which has not been started: C:\Users\user\AppData\Roaming\Oracle\bin\api-ms-win-core-localization-l1-2-0.dllJump to dropped file
Source: C:\Windows\System32\xcopy.exeDropped PE file which has not been started: C:\Users\user\AppData\Roaming\Oracle\bin\klist.exeJump to dropped file
Source: C:\Windows\System32\xcopy.exeDropped PE file which has not been started: C:\Users\user\AppData\Roaming\Oracle\bin\javacpl.exeJump to dropped file
Source: C:\Windows\System32\xcopy.exeDropped PE file which has not been started: C:\Users\user\AppData\Roaming\Oracle\bin\vcruntime140.dllJump to dropped file
Source: C:\Windows\System32\xcopy.exeDropped PE file which has not been started: C:\Users\user\AppData\Roaming\Oracle\bin\jli.dllJump to dropped file
Source: C:\Windows\System32\xcopy.exeDropped PE file which has not been started: C:\Users\user\AppData\Roaming\Oracle\bin\eula.dllJump to dropped file
Source: C:\Windows\System32\xcopy.exeDropped PE file which has not been started: C:\Users\user\AppData\Roaming\Oracle\bin\api-ms-win-core-timezone-l1-1-0.dllJump to dropped file
Source: C:\Windows\System32\xcopy.exeDropped PE file which has not been started: C:\Users\user\AppData\Roaming\Oracle\bin\unpack.dllJump to dropped file
Source: C:\Windows\System32\xcopy.exeDropped PE file which has not been started: C:\Users\user\AppData\Roaming\Oracle\bin\wsdetect.dllJump to dropped file
Source: C:\Windows\System32\xcopy.exeDropped PE file which has not been started: C:\Users\user\AppData\Roaming\Oracle\bin\prism_d3d.dllJump to dropped file
Source: C:\Windows\System32\xcopy.exeDropped PE file which has not been started: C:\Users\user\AppData\Roaming\Oracle\bin\tnameserv.exeJump to dropped file
Source: C:\Windows\System32\xcopy.exeDropped PE file which has not been started: C:\Users\user\AppData\Roaming\Oracle\bin\api-ms-win-core-libraryloader-l1-1-0.dllJump to dropped file
Source: C:\Windows\System32\xcopy.exeDropped PE file which has not been started: C:\Users\user\AppData\Roaming\Oracle\bin\api-ms-win-crt-convert-l1-1-0.dllJump to dropped file
Source: C:\Windows\System32\xcopy.exeDropped PE file which has not been started: C:\Users\user\AppData\Roaming\Oracle\bin\JavaAccessBridge.dllJump to dropped file
Source: C:\Windows\System32\xcopy.exeDropped PE file which has not been started: C:\Users\user\AppData\Roaming\Oracle\bin\deploy.dllJump to dropped file
Source: C:\Windows\System32\xcopy.exeDropped PE file which has not been started: C:\Users\user\AppData\Roaming\Oracle\bin\ssv.dllJump to dropped file
Source: C:\Windows\System32\xcopy.exeDropped PE file which has not been started: C:\Users\user\AppData\Roaming\Oracle\bin\api-ms-win-crt-conio-l1-1-0.dllJump to dropped file
Source: C:\Windows\System32\xcopy.exeDropped PE file which has not been started: C:\Users\user\AppData\Roaming\Oracle\bin\api-ms-win-core-handle-l1-1-0.dllJump to dropped file
May sleep (evasive loops) to hinder dynamic analysisShow sources
Source: C:\Windows\System32\cscript.exe TID: 2216Thread sleep time: -60000s >= -30000sJump to behavior
Source: C:\Windows\System32\cscript.exe TID: 808Thread sleep time: -60000s >= -30000sJump to behavior
Source: C:\Windows\System32\cscript.exe TID: 1144Thread sleep time: -60000s >= -30000sJump to behavior
Source: C:\Windows\System32\cscript.exe TID: 1868Thread sleep time: -60000s >= -30000sJump to behavior
Source: C:\Windows\System32\cscript.exe TID: 1568Thread sleep time: -60000s >= -30000s
Source: C:\Windows\System32\cscript.exe TID: 2960Thread sleep time: -60000s >= -30000s
May try to detect the virtual machine to hinder analysis (VM artifact strings found in memory)Show sources
Source: jdwp.dll.19.drBinary or memory string: JVM version %s (%s, %s)<unknown>VirtualMachineImpl.cRedefineClassesGetTopThreadGroupsJNI_FALSENewStringUTF;DeleteWeakGlobalRefsignature bagsignaturesclassTrack.cloaded classesclassTrack tableNewWeakGlobalRefsignatureKlassNodeAttempting to insert duplicate classloaded classes arraySetTagcommonRef.cDeleteGlobalRefFreeing %d (%x)
Source: jdwp.dll.19.drBinary or memory string: VirtualMachineImpl.c

Anti Debugging:

barindex
Checks for kernel debuggers (NtQuerySystemInformation(SystemKernelDebuggerInformation))Show sources
Source: C:\Program Files\Java\jre1.8.0_191\bin\java.exeSystem information queried: KernelDebuggerInformationJump to behavior
Creates guard pages, often used to prevent reverse engineering and debuggingShow sources
Source: C:\Program Files\Java\jre1.8.0_191\bin\java.exeMemory protected: page read and write | page guardJump to behavior

HIPS / PFW / Operating System Protection Evasion:

barindex
Creates a process in suspended mode (likely to inject code)Show sources
Source: C:\Windows\System32\cmd.exeProcess created: C:\Program Files\Java\jre1.8.0_191\bin\java.exe 'C:\Program Files\Java\jre1.8.0_191\bin\java.exe' -javaagent:'C:\Users\user~1\AppData\Local\Temp\jartracer.jar' -jar 'C:\Users\user\Desktop\INV 3326GHF- from Outriger General Importers Korea for acknowledgment.jar' Jump to behavior
Source: C:\Program Files\Java\jre1.8.0_191\bin\java.exeProcess created: C:\Windows\System32\icacls.exe C:\Windows\system32\icacls.exe C:\ProgramData\Oracle\Java\.oracle_jre_usage /grant 'everyone':(OI)(CI)MJump to behavior
Source: C:\Program Files\Java\jre1.8.0_191\bin\java.exeProcess created: C:\Program Files\Java\jre1.8.0_191\bin\java.exe 'C:\Program Files\Java\jre1.8.0_191\bin\java.exe' -javaagent:'C:\Users\user~1\AppData\Local\Temp\jartracer.jar' -jar C:\Users\user~1\AppData\Local\Temp\_0.63493269659919425532230313552172834.classJump to behavior
Source: C:\Program Files\Java\jre1.8.0_191\bin\java.exeProcess created: C:\Windows\System32\cmd.exe cmd.exe /C cscript.exe C:\Users\user~1\AppData\Local\Temp\Retrive5438807271024442592.vbsJump to behavior
Source: C:\Program Files\Java\jre1.8.0_191\bin\java.exeProcess created: C:\Windows\System32\cmd.exe cmd.exe /C cscript.exe C:\Users\user~1\AppData\Local\Temp\Retrive2024933177882465042.vbsJump to behavior
Source: C:\Program Files\Java\jre1.8.0_191\bin\java.exeProcess created: C:\Windows\System32\xcopy.exe xcopy 'C:\Program Files\Java\jre1.8.0_191' 'C:\Users\user\AppData\Roaming\Oracle\' /eJump to behavior
Source: C:\Program Files\Java\jre1.8.0_191\bin\java.exeProcess created: C:\Windows\System32\cmd.exe cmd.exeJump to behavior
Source: C:\Program Files\Java\jre1.8.0_191\bin\java.exeProcess created: C:\Windows\System32\reg.exe reg add HKCU\Software\Microsoft\Windows\CurrentVersion\Run /v bJnYSNphoio /t REG_EXPAND_SZ /d '\'C:\Users\user\AppData\Roaming\Oracle\bin\javaw.exe\' -jar \'C:\Users\user\KtXRptueuIB\XSZHGSWUUvB.nxPNyG\'' /fJump to behavior
Source: C:\Program Files\Java\jre1.8.0_191\bin\java.exeProcess created: C:\Windows\System32\attrib.exe attrib +h 'C:\Users\user\KtXRptueuIB\*.*'Jump to behavior
Source: C:\Program Files\Java\jre1.8.0_191\bin\java.exeProcess created: C:\Windows\System32\attrib.exe attrib +h 'C:\Users\user\KtXRptueuIB'Jump to behavior
Source: C:\Program Files\Java\jre1.8.0_191\bin\java.exeProcess created: C:\Users\user\AppData\Roaming\Oracle\bin\javaw.exe C:\Users\user\AppData\Roaming\Oracle\bin\javaw.exe -javaagent:'C:\Users\user~1\AppData\Local\Temp\jartracer.jar' -jar C:\Users\user\KtXRptueuIB\XSZHGSWUUvB.nxPNyGJump to behavior
Source: C:\Program Files\Java\jre1.8.0_191\bin\java.exeProcess created: C:\Windows\System32\cmd.exe cmd.exe /C cscript.exe C:\Users\user~1\AppData\Local\Temp\Retrive7307749898854467482.vbsJump to behavior
Source: C:\Program Files\Java\jre1.8.0_191\bin\java.exeProcess created: C:\Windows\System32\cmd.exe cmd.exe /C cscript.exe C:\Users\user~1\AppData\Local\Temp\Retrive7530535289870207342.vbsJump to behavior
Source: C:\Program Files\Java\jre1.8.0_191\bin\java.exeProcess created: C:\Windows\System32\xcopy.exe xcopy 'C:\Program Files\Java\jre1.8.0_191' 'C:\Users\user\AppData\Roaming\Oracle\' /eJump to behavior
Source: C:\Windows\System32\cmd.exeProcess created: C:\Windows\System32\cscript.exe cscript.exe C:\Users\user~1\AppData\Local\Temp\Retrive5438807271024442592.vbsJump to behavior
Source: C:\Windows\System32\cmd.exeProcess created: C:\Windows\System32\cscript.exe cscript.exe C:\Users\user~1\AppData\Local\Temp\Retrive7307749898854467482.vbsJump to behavior
Source: C:\Windows\System32\cmd.exeProcess created: C:\Windows\System32\cscript.exe cscript.exe C:\Users\user~1\AppData\Local\Temp\Retrive2024933177882465042.vbsJump to behavior
Source: C:\Windows\System32\cmd.exeProcess created: C:\Windows\System32\cscript.exe cscript.exe C:\Users\user~1\AppData\Local\Temp\Retrive7530535289870207342.vbsJump to behavior
Source: C:\Users\user\AppData\Roaming\Oracle\bin\javaw.exeProcess created: unknown unknown
Source: C:\Users\user\AppData\Roaming\Oracle\bin\javaw.exeProcess created: unknown unknown
Source: C:\Users\user\AppData\Roaming\Oracle\bin\javaw.exeProcess created: unknown unknown
Source: C:\Users\user\AppData\Roaming\Oracle\bin\javaw.exeProcess created: unknown unknown
Source: C:\Users\user\AppData\Roaming\Oracle\bin\javaw.exeProcess created: unknown unknown
Source: C:\Users\user\AppData\Roaming\Oracle\bin\javaw.exeProcess created: unknown unknown
Source: C:\Users\user\AppData\Roaming\Oracle\bin\javaw.exeProcess created: unknown unknown
Source: C:\Users\user\AppData\Roaming\Oracle\bin\javaw.exeProcess created: unknown unknown
Source: C:\Users\user\AppData\Roaming\Oracle\bin\javaw.exeProcess created: unknown unknown
Source: C:\Users\user\AppData\Roaming\Oracle\bin\javaw.exeProcess created: unknown unknown
Source: C:\Users\user\AppData\Roaming\Oracle\bin\javaw.exeProcess created: unknown unknown
Source: C:\Users\user\AppData\Roaming\Oracle\bin\javaw.exeProcess created: unknown unknown
Source: C:\Users\user\AppData\Roaming\Oracle\bin\javaw.exeProcess created: unknown unknown
Source: C:\Users\user\AppData\Roaming\Oracle\bin\javaw.exeProcess created: unknown unknown
Source: C:\Users\user\AppData\Roaming\Oracle\bin\javaw.exeProcess created: unknown unknown
Source: C:\Users\user\AppData\Roaming\Oracle\bin\javaw.exeProcess created: unknown unknown
Source: C:\Users\user\AppData\Roaming\Oracle\bin\javaw.exeProcess created: C:\Windows\System32\cscript.exe cscript.exe C:\Users\user~1\AppData\Local\Temp\Retrive3097055394604195664.vbs
Source: C:\Users\user\AppData\Roaming\Oracle\bin\javaw.exeProcess created: unknown unknown
Source: C:\Users\user\AppData\Roaming\Oracle\bin\javaw.exeProcess created: unknown unknown
Source: C:\Users\user\AppData\Roaming\Oracle\bin\javaw.exeProcess created: unknown unknown
Source: C:\Users\user\AppData\Roaming\Oracle\bin\javaw.exeProcess created: unknown unknown
Source: C:\Users\user\AppData\Roaming\Oracle\bin\javaw.exeProcess created: unknown unknown
Source: C:\Users\user\AppData\Roaming\Oracle\bin\javaw.exeProcess created: unknown unknown
Source: C:\Users\user\AppData\Roaming\Oracle\bin\javaw.exeProcess created: unknown unknown
Source: C:\Users\user\AppData\Roaming\Oracle\bin\javaw.exeProcess created: unknown unknown
Source: C:\Users\user\AppData\Roaming\Oracle\bin\javaw.exeProcess created: unknown unknown
Source: C:\Users\user\AppData\Roaming\Oracle\bin\javaw.exeProcess created: unknown unknown
Source: C:\Users\user\AppData\Roaming\Oracle\bin\javaw.exeProcess created: unknown unknown
Source: C:\Users\user\AppData\Roaming\Oracle\bin\javaw.exeProcess created: unknown unknown
Source: C:\Users\user\AppData\Roaming\Oracle\bin\javaw.exeProcess created: unknown unknown
Source: C:\Users\user\AppData\Roaming\Oracle\bin\javaw.exeProcess created: unknown unknown
Source: C:\Users\user\AppData\Roaming\Oracle\bin\javaw.exeProcess created: unknown unknown
Source: C:\Users\user\AppData\Roaming\Oracle\bin\javaw.exeProcess created: unknown unknown
Source: C:\Users\user\AppData\Roaming\Oracle\bin\javaw.exeProcess created: unknown unknown
Source: C:\Users\user\AppData\Roaming\Oracle\bin\javaw.exeProcess created: unknown unknown
Source: C:\Users\user\AppData\Roaming\Oracle\bin\javaw.exeProcess created: unknown unknown
Source: C:\Users\user\AppData\Roaming\Oracle\bin\javaw.exeProcess created: unknown unknown
Source: C:\Users\user\AppData\Roaming\Oracle\bin\javaw.exeProcess created: C:\Users\user\AppData\Roaming\Oracle\bin\java.exe C:\Users\user\AppData\Roaming\Oracle\bin\java.exe -jar C:\Users\user~1\AppData\Local\Temp\_0.27057588722335616152848481378506703.class
Source: C:\Users\user\AppData\Roaming\Oracle\bin\javaw.exeProcess created: C:\Windows\System32\cmd.exe cmd.exe /C cscript.exe C:\Users\user~1\AppData\Local\Temp\Retrive7103461586894408784.vbs
Source: C:\Users\user\AppData\Roaming\Oracle\bin\javaw.exeProcess created: unknown unknown
Source: C:\Users\user\AppData\Roaming\Oracle\bin\javaw.exeProcess created: unknown unknown
Source: C:\Users\user\AppData\Roaming\Oracle\bin\javaw.exeProcess created: unknown unknown
Source: C:\Users\user\AppData\Roaming\Oracle\bin\javaw.exeProcess created: unknown unknown
Source: C:\Users\user\AppData\Roaming\Oracle\bin\javaw.exeProcess created: unknown unknown
Source: C:\Users\user\AppData\Roaming\Oracle\bin\javaw.exeProcess created: unknown unknown
Source: C:\Users\user\AppData\Roaming\Oracle\bin\javaw.exeProcess created: unknown unknown
Source: C:\Users\user\AppData\Roaming\Oracle\bin\javaw.exeProcess created: unknown unknown
Source: C:\Users\user\AppData\Roaming\Oracle\bin\javaw.exeProcess created: unknown unknown
Source: C:\Users\user\AppData\Roaming\Oracle\bin\javaw.exeProcess created: unknown unknown
Source: C:\Users\user\AppData\Roaming\Oracle\bin\javaw.exeProcess created: unknown unknown
Source: C:\Users\user\AppData\Roaming\Oracle\bin\javaw.exeProcess created: unknown unknown
Source: C:\Users\user\AppData\Roaming\Oracle\bin\javaw.exeProcess created: unknown unknown
Source: C:\Users\user\AppData\Roaming\Oracle\bin\javaw.exeProcess created: unknown unknown
Source: C:\Users\user\AppData\Roaming\Oracle\bin\javaw.exeProcess created: unknown unknown
Source: C:\Users\user\AppData\Roaming\Oracle\bin\javaw.exeProcess created: unknown unknown
Source: C:\Users\user\AppData\Roaming\Oracle\bin\javaw.exeProcess created: unknown unknown
Source: C:\Users\user\AppData\Roaming\Oracle\bin\javaw.exeProcess created: unknown unknown
Source: C:\Users\user\AppData\Roaming\Oracle\bin\javaw.exeProcess created: unknown unknown
Source: C:\Users\user\AppData\Roaming\Oracle\bin\javaw.exeProcess created: unknown unknown
Source: C:\Users\user\AppData\Roaming\Oracle\bin\javaw.exeProcess created: unknown unknown
Source: C:\Users\user\AppData\Roaming\Oracle\bin\javaw.exeProcess created: unknown unknown
Source: C:\Users\user\AppData\Roaming\Oracle\bin\javaw.exeProcess created: unknown unknown
Source: C:\Users\user\AppData\Roaming\Oracle\bin\javaw.exeProcess created: unknown unknown
Source: C:\Users\user\AppData\Roaming\Oracle\bin\javaw.exeProcess created: unknown unknown
Source: C:\Users\user\AppData\Roaming\Oracle\bin\javaw.exeProcess created: unknown unknown
Source: C:\Users\user\AppData\Roaming\Oracle\bin\javaw.exeProcess created: unknown unknown
Source: C:\Users\user\AppData\Roaming\Oracle\bin\javaw.exeProcess created: unknown unknown
Source: C:\Users\user\AppData\Roaming\Oracle\bin\javaw.exeProcess created: unknown unknown
Source: C:\Users\user\AppData\Roaming\Oracle\bin\javaw.exeProcess created: unknown unknown
Source: C:\Users\user\AppData\Roaming\Oracle\bin\javaw.exeProcess created: unknown unknown
Source: C:\Users\user\AppData\Roaming\Oracle\bin\javaw.exeProcess created: unknown unknown
Source: C:\Users\user\AppData\Roaming\Oracle\bin\javaw.exeProcess created: unknown unknown
Source: C:\Users\user\AppData\Roaming\Oracle\bin\javaw.exeProcess created: unknown unknown
Source: C:\Users\user\AppData\Roaming\Oracle\bin\javaw.exeProcess created: unknown unknown
Source: C:\Users\user\AppData\Roaming\Oracle\bin\javaw.exeProcess created: unknown unknown
Source: C:\Users\user\AppData\Roaming\Oracle\bin\javaw.exeProcess created: unknown unknown
Source: C:\Users\user\AppData\Roaming\Oracle\bin\javaw.exeProcess created: unknown unknown
Source: C:\Users\user\AppData\Roaming\Oracle\bin\javaw.exeProcess created: unknown unknown
Source: C:\Users\user\AppData\Roaming\Oracle\bin\javaw.exeProcess created: unknown unknown
Source: C:\Users\user\AppData\Roaming\Oracle\bin\javaw.exeProcess created: unknown unknown
Source: C:\Users\user\AppData\Roaming\Oracle\bin\javaw.exeProcess created: unknown unknown
Source: C:\Users\user\AppData\Roaming\Oracle\bin\java.exeProcess created: C:\Windows\System32\cmd.exe cmd.exe /C cscript.exe C:\Users\user~1\AppData\Local\Temp\Retrive3097055394604195664.vbs
Source: C:\Users\user\AppData\Roaming\Oracle\bin\java.exeProcess created: unknown unknown
Source: C:\Users\user\AppData\Roaming\Oracle\bin\java.exeProcess created: unknown unknown
Source: C:\Windows\System32\cmd.exeProcess created: C:\Windows\System32\cscript.exe cscript.exe C:\Users\user~1\AppData\Local\Temp\Retrive7103461586894408784.vbs
Source: C:\Windows\System32\cmd.exeProcess created: C:\Windows\System32\cscript.exe cscript.exe C:\Users\user~1\AppData\Local\Temp\Retrive3097055394604195664.vbs
Very long cmdline option found, this is very uncommon (may be encrypted or packed)Show sources
Source: unknownProcess created: C:\Windows\System32\cmd.exe C:\Windows\system32\cmd.exe /c ''C:\Program Files\Java\jre1.8.0_191\bin\java.exe' -javaagent:'C:\Users\user~1\AppData\Local\Temp\jartracer.jar' -jar 'C:\Users\user\Desktop\INV 3326GHF- from Outriger General Importers Korea for acknowledgment.jar'' >> C:\cmdlinestart.log 2>&1
May try to detect the Windows Explorer process (often used for injection)Show sources
Source: deploy.dll.19.drBinary or memory string: \mwndProcID was NULL in mainLoop()wndProc(JIJJ)JNULL != hIcon../../src/common/windows/native/WindowsJavaTrayIcon.cppTrayNotifyWndShell_TrayWndUnable to Start Java Plug-in Control Panel%s\javacpl.exeJava Sys Tray

Language, Device and Operating System Detection:

barindex
Queries the cryptographic machine GUIDShow sources
Source: C:\Program Files\Java\jre1.8.0_191\bin\java.exeKey value queried: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Cryptography MachineGuidJump to behavior

Lowering of HIPS / PFW / Operating System Security Settings:

barindex
Checks if Antivirus/Antispyware/Firewall program is installed (via WMI)Show sources
Source: C:\Windows\System32\icacls.exeWMI Queries: IWbemServices::ExecQuery - Select * from FirewallProduct
Source: C:\Windows\System32\cscript.exeWMI Queries: IWbemServices::ExecQuery - Select * from AntiVirusProduct
Source: C:\Windows\System32\cscript.exeWMI Queries: IWbemServices::ExecQuery - Select * from AntiVirusProduct
Source: C:\Windows\System32\cscript.exeWMI Queries: IWbemServices::ExecQuery - Select * from FirewallProduct
Source: C:\Windows\System32\cscript.exeWMI Queries: IWbemServices::ExecQuery - Select * from FirewallProduct
Source: C:\Windows\System32\cscript.exeWMI Queries: IWbemServices::ExecQuery - Select * from AntiVirusProduct
Source: C:\Windows\System32\cscript.exeWMI Queries: IWbemServices::ExecQuery - Select * from AntiVirusProduct

Remote Access Functionality:

barindex
ADWIND Rat detectedShow sources
Source: C:\Program Files\Java\jre1.8.0_191\bin\java.exeDropped file: Set oWMI = GetObject("winmgmts:{impersonationLevel=impersonate}!\\.\root\SecurityCenter2")Set colItems = oWMI.ExecQuery("Select * from AntiVirusProduct")For Each objItem in colItems With objItem WScript.Echo "{""AV"":""" & .displayName & """}" End WithNextJump to dropped file
Source: C:\Program Files\Java\jre1.8.0_191\bin\java.exeDropped file: Set oWMI = GetObject("winmgmts:{impersonationLevel=impersonate}!\\.\root\SecurityCenter2")Set colItems = oWMI.ExecQuery("Select * from FirewallProduct")For Each objItem in colItems With objItem WScript.Echo "{""FIREWALL"":""" & .displayName & """}" End WithNextJump to dropped file
Source: C:\Program Files\Java\jre1.8.0_191\bin\java.exeDropped file: Set oWMI = GetObject("winmgmts:{impersonationLevel=impersonate}!\\.\root\SecurityCenter2")Set colItems = oWMI.ExecQuery("Select * from AntiVirusProduct")For Each objItem in colItems With objItem WScript.Echo "{""AV"":""" & .displayName & """}" End WithNextJump to dropped file
Source: C:\Program Files\Java\jre1.8.0_191\bin\java.exeDropped file: Set oWMI = GetObject("winmgmts:{impersonationLevel=impersonate}!\\.\root\SecurityCenter2")Set colItems = oWMI.ExecQuery("Select * from FirewallProduct")For Each objItem in colItems With objItem WScript.Echo "{""FIREWALL"":""" & .displayName & """}" End WithNextJump to dropped file
Source: C:\Users\user\AppData\Roaming\Oracle\bin\javaw.exeDropped file: Set oWMI = GetObject("winmgmts:{impersonationLevel=impersonate}!\\.\root\SecurityCenter2")Set colItems = oWMI.ExecQuery("Select * from AntiVirusProduct")For Each objItem in colItems With objItem WScript.Echo "{""AV"":""" & .displayName & """}" End WithNextJump to dropped file
Source: C:\Users\user\AppData\Roaming\Oracle\bin\javaw.exeDropped file: Set oWMI = GetObject("winmgmts:{impersonationLevel=impersonate}!\\.\root\SecurityCenter2")Set colItems = oWMI.ExecQuery("Select * from FirewallProduct")For Each objItem in colItems With objItem WScript.Echo "{""FIREWALL"":""" & .displayName & """}" End WithNextJump to dropped file
Source: C:\Users\user\AppData\Roaming\Oracle\bin\javaw.exeDropped file: Set oWMI = GetObject("winmgmts:{impersonationLevel=impersonate}!\\.\root\SecurityCenter2")Set colItems = oWMI.ExecQuery("Select * from AntiVirusProduct")For Each objItem in colItems With objItem WScript.Echo "{""AV"":""" & .displayName & """}" End WithNextJump to dropped file
Source: C:\Users\user\AppData\Roaming\Oracle\bin\javaw.exeDropped file: Set oWMI = GetObject("winmgmts:{impersonationLevel=impersonate}!\\.\root\SecurityCenter2")Set colItems = oWMI.ExecQuery("Select * from FirewallProduct")For Each objItem in colItems With objItem WScript.Echo "{""FIREWALL"":""" & .displayName & """}" End WithNextJump to dropped file
Source: C:\Users\user\AppData\Roaming\Oracle\bin\java.exeDropped file: Set oWMI = GetObject("winmgmts:{impersonationLevel=impersonate}!\\.\root\SecurityCenter2")Set colItems = oWMI.ExecQuery("Select * from AntiVirusProduct")For Each objItem in colItems With objItem WScript.Echo "{""AV"":""" & .displayName & """}" End WithNextJump to dropped file
Source: C:\Users\user\AppData\Roaming\Oracle\bin\java.exeDropped file: Set oWMI = GetObject("winmgmts:{impersonationLevel=impersonate}!\\.\root\SecurityCenter2")Set colItems = oWMI.ExecQuery("Select * from FirewallProduct")For Each objItem in colItems With objItem WScript.Echo "{""FIREWALL"":""" & .displayName & """}" End WithNextJump to dropped file
Collects Antivirus and Firewall information (ADWIND Rat suspicion)Show sources
Source: Java tracingExecutes: java.io.Writer.write(java.lang.String) on Set oWMI = GetObject("winmgmts:{impersonationLevel=impersonate}!\\.\root\SecurityCenter2")Set colItems = oWMI.ExecQuery("Select * from AntiVirusProduct")For Each objItem in colItems With objItem WScript.Echo "{""AV"":""" & .displayName & """}" End WithNext
Source: Java tracingExecutes: java.io.Writer.write(java.lang.String) on Set oWMI = GetObject("winmgmts:{impersonationLevel=impersonate}!\\.\root\SecurityCenter2")Set colItems = oWMI.ExecQuery("Select * from FirewallProduct")For Each objItem in colItems With objItem WScript.Echo "{""FIREWALL"":""" & .displayName & """}" End WithNext
Source: Java tracingExecutes: java.io.Writer.write(java.lang.String) on Set oWMI = GetObject("winmgmts:{impersonationLevel=impersonate}!\\.\root\SecurityCenter2")Set colItems = oWMI.ExecQuery("Select * from AntiVirusProduct")For Each objItem in colItems With objItem WScript.Echo "{""AV"":""" & .displayName & """}" End WithNext
Source: Java tracingExecutes: java.io.Writer.write(java.lang.String) on Set oWMI = GetObject("winmgmts:{impersonationLevel=impersonate}!\\.\root\SecurityCenter2")Set colItems = oWMI.ExecQuery("Select * from FirewallProduct")For Each objItem in colItems With objItem WScript.Echo "{""FIREWALL"":""" & .displayName & """}" End WithNext
Source: Java tracingExecutes: java.io.Writer.write(java.lang.String) on Set oWMI = GetObject("winmgmts:{impersonationLevel=impersonate}!\\.\root\SecurityCenter2")Set colItems = oWMI.ExecQuery("Select * from AntiVirusProduct")For Each objItem in colItems With objItem WScript.Echo "{""AV"":""" & .displayName & """}" End WithNext
Source: Java tracingExecutes: java.io.Writer.write(java.lang.String) on Set oWMI = GetObject("winmgmts:{impersonationLevel=impersonate}!\\.\root\SecurityCenter2")Set colItems = oWMI.ExecQuery("Select * from FirewallProduct")For Each objItem in colItems With objItem WScript.Echo "{""FIREWALL"":""" & .displayName & """}" End WithNext
Found Adwind RAT configuration as decrypted stringShow sources
Source: Java tracingAdWind RAT configuration: {"NETWORK":[{"PORT":7777,"DNS":"127.0.0.1"}],"INSTALL":false,"MODULE_PATH":"zS/lq/BTk.GI","PLUGIN_FOLDER":"DdWDtpinxpf","JRE_FOLDER":"HSIROD","JAR_FOLDER":"fUTkALeaTxM","JAR_EXTENSION":"Vybgol","ENCRYPT_KEY":"cPFjgddXIBcXBCIseEuXTZjwi","DELAY_INSTALL":2,"NICKNAME":"User","VMWARE":false,"PLUGIN_EXTENSION":"DhjWU","WEBSITE_PROJECT":"https://jrat.io","JAR_NAME":"uiylKSALYJr","JAR_REGISTRY":"WLyQyhWoosi","DELAY_CONNECT":2,"VBOX":false}

Behavior Graph

Hide Legend

Legend:

  • Process
  • Signature
  • Created File
  • DNS/IP Info
  • Is Dropped
  • Is Windows Process
  • Number of created Registry Values
  • Number of created Files
  • Visual Basic
  • Delphi
  • Java
  • .Net C# or VB.NET
  • C, C++ or other language
  • Is malicious
behaviorgraph top1 dnsIp2 2 Behavior Graph ID: 749556 Sample: INV 3326GHF- from Outriger General Importers Korea for ac... Startdate: 30/12/2018 Architecture: WINDOWS Score: 88 62 onyeka1.duckdns.org 2->62 77 Too many similar processes found 2->77 79 ADWIND Rat detected 2->79 81 Found Adwind RAT configuration as decrypted string 2->81 83 5 other signatures 2->83 10 cmd.exe 1 2->10         started        12 javaw.exe 2->12         started        signatures3 process4 dnsIp5 15 java.exe 19 10->15         started        66 onyeka1.duckdns.org 185.244.30.124, 49230, 49233, 49239 LEASEWEB-NLNetherlandsNL unknown 12->66 69 127.0.0.1 unknown unknown 12->69 19 java.exe 12->19         started        21 cmd.exe 12->21         started        signatures6 75 Detected TCP or UDP traffic on non-standard ports 66->75 process7 file8 60 C:\Users\user\...\XSZHGSWUUvB.nxPNyG, Zip 15->60 dropped 71 Exploit detected, runtime environment starts unknown processes 15->71 23 xcopy.exe 15->23         started        26 javaw.exe 15->26         started        30 reg.exe