Loading ...

Analysis Report

Overview

General Information

Joe Sandbox Version:20.0.0
Analysis ID:46216
Start time:21:37:49
Joe Sandbox Product:CloudBasic
Start date:12.02.2018
Overall analysis duration:0h 8m 27s
Hypervisor based Inspection enabled:false
Report type:full
Sample file name:winlogon.exe
Cookbook file name:default.jbs
Analysis system description:Windows 7 SP1 (with Office 2010 SP2, IE 11, FF 54, Chrome 60, Acrobat Reader DC 17, Flash 26, Java 8.0.1440.1)
Number of analysed new started processes analysed:26
Number of new started drivers analysed:0
Number of existing processes analysed:0
Number of existing drivers analysed:0
Number of injected processes analysed:0
Technologies
  • HCA enabled
  • EGA enabled
  • HDC enabled
Detection:MAL
Classification:mal100.evad.spre.rans.spyw.troj.winEXE@34/9@31/10
HCA Information:
  • Successful, ratio: 97%
  • Number of executed functions: 181
  • Number of non-executed functions: 171
EGA Information:
  • Successful, ratio: 100%
HDC Information:
  • Successful, ratio: 54.9% (good quality ratio 51.4%)
  • Quality average: 79%
  • Quality standard deviation: 29.3%
Cookbook Comments:
  • Adjust boot time
  • Found application associated with file extension: .exe
Warnings:
Show All
  • Connection to analysis system has been lost
  • Exclude process from analysis (whitelisted): conhost.exe, dllhost.exe
  • Report size getting too big, too many NtDeviceIoControlFile calls found.
  • Report size getting too big, too many NtQueryValueKey calls found.


Detection

StrategyScoreRangeReportingDetection
Threshold1000 - 100Report FP / FNmalicious


Confidence

StrategyScoreRangeFurther Analysis Required?Confidence
Threshold50 - 5false
ConfidenceConfidence


Classification

Analysis Advice

All domains contacted by the sample do not resolve. Likely the sample is an old dropper which does no longer work
Sample drops PE files which have not been started, submit dropped PE samples for a secondary analysis to Joe Sandbox
Sample may offer command line options, please run it with the 'Execute binary with arguments' cookbook (it's possible that the command line switches require additional characters like: "-", "/", "--"
Sample tries to load a library which is not present or installed on the analysis machine, adding the library might reveal more behavior



Signature Overview

Click to jump to signature section


AV Detection:

barindex
Antivirus detection for dropped fileShow sources
Source: C:\Users\HERBBL~1\AppData\Local\Temp\_usm.exevirustotal: Detection: 59%Perma Link
Antivirus detection for submitted fileShow sources
Source: winlogon.exevirustotal: Detection: 62%Perma Link

Cryptography:

barindex
Uses Microsoft's Enhanced Cryptographic ProviderShow sources
Source: C:\Users\user\Desktop\winlogon.exeCode function: 1_2_00D64140 CryptAcquireContextW,CryptGenRandom,CryptReleaseContext,1_2_00D64140
Source: C:\Users\user\AppData\Local\Temp\yegus.exeCode function: 2_2_10001D60 GetFileAttributesA,GetTempPathA,GetTempFileNameA,CopyFileA,CryptUnprotectData,HeapAlloc,LocalFree,HeapFree,DeleteFileA,2_2_10001D60
Source: C:\Users\user\AppData\Local\Temp\yegus.exeCode function: 2_2_100010C0 StrStrIW,lstrlenW,CryptAcquireContextA,CryptCreateHash,CryptHashData,CryptDestroyHash,CryptReleaseContext,CryptGetHashParam,wsprintfA,wsprintfA,CryptDestroyHash,CryptReleaseContext,2_2_100010C0
Source: C:\Users\user\AppData\Local\Temp\yegus.exeCode function: 2_2_10001200 StrStrIW,lstrlenW,lstrlenW,lstrlenW,CryptUnprotectData,HeapFree,HeapFree,HeapFree,HeapFree,HeapFree,HeapFree,HeapFree,LocalFree,2_2_10001200

Spam, unwanted Advertisements and Ransom Demands:

barindex
Deletes shadow drive data (may be related to ransomware)Show sources
Source: unknownProcess created: C:\Windows\System32\vssadmin.exe c:\Windows\system32\vssadmin.exe delete shadows /all /quiet
Source: winlogon.exeBinary or memory string: C:\Windows\system32\cmd.exe /c%s %s %sServicesActive%s\*...SeShutdownPrivilegec:\Windows\system32\vssadmin.exedelete shadows /all /quietwbadmin.exedelete catalog -quietbcdedit.exe/set {default} bootstatuspolicy ignoreallfailures & bcdedit /set {default} recoveryenabled nowevtutil.execl Systemcl SecurityH
Source: _usm.exeBinary or memory string: C:\Windows\system32\cmd.exe /c%s %s %sServicesActive%s\*...SeShutdownPrivilegec:\Windows\system32\vssadmin.exedelete shadows /all /quietwbadmin.exedelete catalog -quietbcdedit.exe/set {default} bootstatuspolicy ignoreallfailures & bcdedit /set {default} recoveryenabled nowevtutil.execl Systemcl SecurityH
Source: C:\Windows\System32\cmd.exeProcess created: C:\Windows\System32\vssadmin.exe c:\Windows\system32\vssadmin.exe delete shadows /all /quiet
Source: cmd.exeBinary or memory string: C:\Windows\system32\cmd.exe /c c:\Windows\system32\vssadmin.exe delete shadows /all /quiet
Source: cmd.exeBinary or memory string: C:\Users\user\Desktop\C:\Windows\system32;;C:\Windows\system32;C:\Windows\system;C:\Windows;.;C:\ProgramData\Oracle\Java\javapath;C:\Windows\system32;C:\Windows;C:\Windows\System32\Wbem;C:\Windows\System32\WindowsPowerShell\v1.0\C:\Windows\system32\cmd.exeC:\Windows\system32\cmd.exe /c c:\Windows\system32\vssadmin.exe delete shadows /all /quietC:\Windows\system32\cmd.exeWinSta0\Defaulto
Source: cmd.exeBinary or memory string: C:\Windows\system32\cmd.exe /c c:\Windows\system32\vssadmin.exe delete shadows /all /quieth
Source: cmd.exeBinary or memory string: ? c:\Windows\system32\vssadmin.exe delete shadows /all /quiet
Source: cmd.exeBinary or memory string: ?c:\Windows\system32\vssadmin.exe delete shadows /all /quiettemn
Source: cmd.exeBinary or memory string: 9C:\Windows\system32\cmd.exe/cc:\Windows\system32\vssadmin.exedeleteshadows/all/quietESSOR_LEVEL=6PROCESSOR_REVISION=3f02ProgramData=C:\ProgramDataProgramFiles=C:\Program FilesPSModulePath=C:\Windows\system32\WindowsPowerShell\v1.0\Modules\;C:\Program Files\AutoIt3\AutoItXPUBLIC=C:\Users\PublicSystemDrive=C:SystemRoot=C:\WindowsTEMP=C:\Users\HERBBL~1\A(0
Source: vssadmin.exeBinary or memory string: Lc:\Windows\system32\vssadmin.exedeleteshadows/all/quiet,
Source: vssadmin.exeBinary or memory string: c:\Windows\system32\vssadmin.exe delete shadows /all /quiet
Source: vssadmin.exeBinary or memory string: C:\Users\user\Desktop\c:\Windows\system32;;C:\Windows\system32;C:\Windows\system;C:\Windows;.;C:\ProgramData\Oracle\Java\javapath;C:\Windows\system32;C:\Windows;C:\Windows\System32\Wbem;C:\Windows\System32\WindowsPowerShell\v1.0\c:\Windows\system32\vssadmin.exec:\Windows\system32\vssadmin.exe delete shadows /all /quietc:\Windows\system32\vssadmin.exe delete shadows /all /quietWinSta0\Default
Source: vssadmin.exeBinary or memory string: Example Usage: vssadmin Delete ShadowStorage
Source: vssadmin.exeBinary or memory string: Example Usage: vssadmin Delete Shadows /Type=ClientAccessible /For=C:
Source: vssadmin.exeBinary or memory string: vssadmin Delete Shadows
Source: vssadmin.exeBinary or memory string: Example Usage: vssadmin Delete Shadows /For=C: /Oldest
Source: vssadmin.exeBinary or memory string: Example Usage: vssadmin Delete ShadowStorage /For=C: /On=D:
Source: _usm.exe.1.drBinary or memory string: C:\Windows\system32\cmd.exe /c%s %s %sServicesActive%s\*...SeShutdownPrivilegec:\Windows\system32\vssadmin.exedelete shadows /all /quietwbadmin.exedelete catalog -quietbcdedit.exe/set {default} bootstatuspolicy ignoreallfailures & bcdedit /set {default} recoveryenabled nowevtutil.execl Systemcl SecurityH
May disable shadow drive data (uses vssadmin)Show sources
Source: unknownProcess created: C:\Windows\System32\vssadmin.exe c:\Windows\system32\vssadmin.exe delete shadows /all /quiet
Source: C:\Windows\System32\cmd.exeProcess created: C:\Windows\System32\vssadmin.exe c:\Windows\system32\vssadmin.exe delete shadows /all /quiet

Networking:

barindex
Performs DNS lookupsShow sources
Source: unknownDNS traffic detected: queries for: 252.0.0.224.in-addr.arpa
Urls found in memory or binary dataShow sources
Source: yegus.exeString found in binary or memory: file:///C:/jbxinitvm.au3
Source: yegus.exeString found in binary or memory: file:///C:/jbxinitvm.au3s
Source: yegus.exeString found in binary or memory: http://certs.starfieldtech.com/repository/1402
Source: yegus.exeString found in binary or memory: http://crl.comodoca.com/COMODORSACertificationAuthority.crl0q
Source: yegus.exeString found in binary or memory: http://crl.rootca1.amazontrust.com/rootca1.crl0
Source: yegus.exeString found in binary or memory: http://crl.thawte.com/ThawtePCA-G3.crl0
Source: yegus.exeString found in binary or memory: http://crl4.digicert.com/DigiCertHighAssuranceEVRootCA.crl0=
Source: yegus.exeString found in binary or memory: http://crt.comodoca.com/COMODORSAAddTrustCA.crt0$
Source: yegus.exeString found in binary or memory: http://crt.rootca1.amazontrust.com/rootca1.cer0?
Source: yegus.exeString found in binary or memory: http://ocsp.comodoca.com0
Source: yegus.exeString found in binary or memory: http://ocsp.digicert.com0K
Source: yegus.exeString found in binary or memory: http://ocsp.rootca1.amazontrust.com0:
Source: yegus.exeString found in binary or memory: http://ocsp.thawte.com0
Source: yegus.exeString found in binary or memory: http://s.symcb.com/pca3-g5.crl0
Source: yegus.exeString found in binary or memory: http://s.symcd.com0_
Source: yegus.exeString found in binary or memory: http://t1.symcb.com/ThawtePCA.crl0/
Source: yegus.exeString found in binary or memory: http://t2.symcb.com0A
Source: winlogon.exe, _wjg.exe.1.drString found in binary or memory: http://www.sysinternals.com
Source: yegus.exeString found in binary or memory: https://d.symcb.com/cps0%
Source: yegus.exeString found in binary or memory: https://d.symcb.com/rpa0
Source: yegus.exeString found in binary or memory: https://www.digicert.com/CPS0
Source: yegus.exeString found in binary or memory: https://www.thawte.com/cps0)
Source: yegus.exeString found in binary or memory: https://www.thawte.com/cps07
Tries to resolve domain names, but no domain seems valid (expired dropper behavior)Show sources
Source: unknownDNS traffic detected: query: 252.0.0.224.in-addr.arpa replaycode: Name error (3)
Source: unknownDNS traffic detected: query: 252.0.0.224.in-addr.arpa replaycode: Name error (3)
Source: unknownDNS traffic detected: query: 252.0.0.224.in-addr.arpa replaycode: Name error (3)
Source: unknownDNS traffic detected: query: 252.0.0.224.in-addr.arpa replaycode: Name error (3)
Source: unknownDNS traffic detected: query: 252.0.0.224.in-addr.arpa replaycode: Name error (3)
Source: unknownDNS traffic detected: query: 252.0.0.224.in-addr.arpa replaycode: Name error (3)
Source: unknownDNS traffic detected: query: 252.0.0.224.in-addr.arpa replaycode: Name error (3)
Source: unknownDNS traffic detected: query: 252.0.0.224.in-addr.arpa replaycode: Name error (3)
Source: unknownDNS traffic detected: query: 252.0.0.224.in-addr.arpa replaycode: Name error (3)
Source: unknownDNS traffic detected: query: 252.0.0.224.in-addr.arpa replaycode: Name error (3)
Source: unknownDNS traffic detected: query: 252.0.0.224.in-addr.arpa replaycode: Name error (3)
Source: unknownDNS traffic detected: query: 252.0.0.224.in-addr.arpa replaycode: Name error (3)
Source: unknownDNS traffic detected: query: 252.0.0.224.in-addr.arpa replaycode: Name error (3)
Source: unknownDNS traffic detected: query: 252.0.0.224.in-addr.arpa replaycode: Name error (3)
Source: unknownDNS traffic detected: query: 252.0.0.224.in-addr.arpa replaycode: Name error (3)
Source: unknownDNS traffic detected: query: 252.0.0.224.in-addr.arpa replaycode: Name error (3)
Source: unknownDNS traffic detected: query: 252.0.0.224.in-addr.arpa replaycode: Name error (3)
Source: unknownDNS traffic detected: query: 252.0.0.224.in-addr.arpa replaycode: Name error (3)
Source: unknownDNS traffic detected: query: 252.0.0.224.in-addr.arpa replaycode: Name error (3)
Source: unknownDNS traffic detected: query: 252.0.0.224.in-addr.arpa replaycode: Name error (3)
Source: unknownDNS traffic detected: query: 252.0.0.224.in-addr.arpa replaycode: Name error (3)
Source: unknownDNS traffic detected: query: 252.0.0.224.in-addr.arpa replaycode: Name error (3)
Source: unknownDNS traffic detected: query: 252.0.0.224.in-addr.arpa replaycode: Name error (3)
Source: unknownDNS traffic detected: query: 252.0.0.224.in-addr.arpa replaycode: Name error (3)
Source: unknownDNS traffic detected: query: 252.0.0.224.in-addr.arpa replaycode: Name error (3)
Source: unknownDNS traffic detected: query: 252.0.0.224.in-addr.arpa replaycode: Name error (3)
Source: unknownDNS traffic detected: query: 252.0.0.224.in-addr.arpa replaycode: Name error (3)
Source: unknownDNS traffic detected: query: 252.0.0.224.in-addr.arpa replaycode: Name error (3)
Source: unknownDNS traffic detected: query: 252.0.0.224.in-addr.arpa replaycode: Name error (3)
Source: unknownDNS traffic detected: query: 252.0.0.224.in-addr.arpa replaycode: Name error (3)
Source: unknownDNS traffic detected: query: 252.0.0.224.in-addr.arpa replaycode: Name error (3)
Tries to resolve many domain names, but no domain seems validShow sources
Source: unknownDNS traffic detected: query: 252.0.0.224.in-addr.arpa replaycode: Name error (3)
Source: unknownDNS traffic detected: query: 252.0.0.224.in-addr.arpa replaycode: Name error (3)
Source: unknownDNS traffic detected: query: 252.0.0.224.in-addr.arpa replaycode: Name error (3)
Source: unknownDNS traffic detected: query: 252.0.0.224.in-addr.arpa replaycode: Name error (3)
Source: unknownDNS traffic detected: query: 252.0.0.224.in-addr.arpa replaycode: Name error (3)
Source: unknownDNS traffic detected: query: 252.0.0.224.in-addr.arpa replaycode: Name error (3)
Source: unknownDNS traffic detected: query: 252.0.0.224.in-addr.arpa replaycode: Name error (3)
Source: unknownDNS traffic detected: query: 252.0.0.224.in-addr.arpa replaycode: Name error (3)
Source: unknownDNS traffic detected: query: 252.0.0.224.in-addr.arpa replaycode: Name error (3)
Source: unknownDNS traffic detected: query: 252.0.0.224.in-addr.arpa replaycode: Name error (3)
Source: unknownDNS traffic detected: query: 252.0.0.224.in-addr.arpa replaycode: Name error (3)
Source: unknownDNS traffic detected: query: 252.0.0.224.in-addr.arpa replaycode: Name error (3)
Source: unknownDNS traffic detected: query: 252.0.0.224.in-addr.arpa replaycode: Name error (3)
Source: unknownDNS traffic detected: query: 252.0.0.224.in-addr.arpa replaycode: Name error (3)
Source: unknownDNS traffic detected: query: 252.0.0.224.in-addr.arpa replaycode: Name error (3)
Source: unknownDNS traffic detected: query: 252.0.0.224.in-addr.arpa replaycode: Name error (3)
Source: unknownDNS traffic detected: query: 252.0.0.224.in-addr.arpa replaycode: Name error (3)
Source: unknownDNS traffic detected: query: 252.0.0.224.in-addr.arpa replaycode: Name error (3)
Source: unknownDNS traffic detected: query: 252.0.0.224.in-addr.arpa replaycode: Name error (3)
Source: unknownDNS traffic detected: query: 252.0.0.224.in-addr.arpa replaycode: Name error (3)
Source: unknownDNS traffic detected: query: 252.0.0.224.in-addr.arpa replaycode: Name error (3)
Source: unknownDNS traffic detected: query: 252.0.0.224.in-addr.arpa replaycode: Name error (3)
Source: unknownDNS traffic detected: query: 252.0.0.224.in-addr.arpa replaycode: Name error (3)
Source: unknownDNS traffic detected: query: 252.0.0.224.in-addr.arpa replaycode: Name error (3)
Source: unknownDNS traffic detected: query: 252.0.0.224.in-addr.arpa replaycode: Name error (3)
Source: unknownDNS traffic detected: query: 252.0.0.224.in-addr.arpa replaycode: Name error (3)
Source: unknownDNS traffic detected: query: 252.0.0.224.in-addr.arpa replaycode: Name error (3)
Source: unknownDNS traffic detected: query: 252.0.0.224.in-addr.arpa replaycode: Name error (3)
Source: unknownDNS traffic detected: query: 252.0.0.224.in-addr.arpa replaycode: Name error (3)
Source: unknownDNS traffic detected: query: 252.0.0.224.in-addr.arpa replaycode: Name error (3)
Source: unknownDNS traffic detected: query: 252.0.0.224.in-addr.arpa replaycode: Name error (3)

Stealing of Sensitive Information:

barindex
Contains functionality to dump credential hashes (LSA Dump)Show sources
Source: C:\Users\user\AppData\Local\Temp\ucngw.exeCode function: 3_2_100114D0 LoadLibraryW,RtlInitUnicodeString,GetProcAddress,GetProcAddress,GetProcAddress,LocalAlloc,LocalAlloc,3_2_100114D0
Contains functionality to steal Chrome passwordsShow sources
Source: C:\Users\user\AppData\Local\Temp\yegus.exeCode function: \Google\Chrome\User Data\Default\Login Data2_2_10001FB0
Source: C:\Users\user\AppData\Local\Temp\yegus.exeCode function: \Google\Chrome\User Data\Default\Login Data2_2_10001FB0
Contains functionality to steal Internet Explorer form passwordsShow sources
Source: C:\Users\user\AppData\Local\Temp\yegus.exeCode function: Software\Microsoft\Internet Explorer\IntelliForms\Storage22_2_10082020
Tries to harvest and steal browser information (history, passwords, etc)Show sources
Source: C:\Users\user\AppData\Local\Temp\yegus.exeFile opened: C:\Users\user\AppData\Roaming\Mozilla\Firefox\profiles.ini
Source: C:\Users\user\AppData\Local\Temp\yegus.exeFile opened: C:\Users\user\AppData\Roaming\Mozilla\Firefox\Profiles\4ah7hlda.default\cert8.db
Source: C:\Users\user\AppData\Local\Temp\yegus.exeFile opened: C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Login Data
Source: C:\Users\user\AppData\Local\Temp\yegus.exeFile opened: C:\Users\user\AppData\Roaming\Mozilla\Firefox\Profiles\4ah7hlda.default\secmod.db
Source: C:\Users\user\AppData\Local\Temp\yegus.exeFile opened: C:\Users\user\AppData\Roaming\Mozilla\Firefox\Profiles\4ah7hlda.default\logins.json
Source: C:\Users\user\AppData\Local\Temp\yegus.exeFile opened: C:\Users\user\AppData\Roaming\Mozilla\Firefox\Profiles\4ah7hlda.default\key3.db

Persistence and Installation Behavior:

barindex
Drops PE filesShow sources
Source: C:\Users\user\Desktop\winlogon.exeFile created: C:\Users\HERBBL~1\AppData\Local\Temp\_yig.exe
Source: C:\Users\user\Desktop\winlogon.exeFile created: C:\Users\HERBBL~1\AppData\Local\Temp\_wjg.exe
Source: C:\Users\user\Desktop\winlogon.exeFile created: C:\Users\HERBBL~1\AppData\Local\Temp\ucngw.exe
Source: C:\Users\user\Desktop\winlogon.exeFile created: C:\Users\HERBBL~1\AppData\Local\Temp\_usm.exe
Source: C:\Users\user\Desktop\winlogon.exeFile created: C:\Users\HERBBL~1\AppData\Local\Temp\yegus.exe
May use bcdedit to modify the Windows boot settingsShow sources
Source: winlogon.exeBinary or memory string: C:\Windows\system32\cmd.exe /c%s %s %sServicesActive%s\*...SeShutdownPrivilegec:\Windows\system32\vssadmin.exedelete shadows /all /quietwbadmin.exedelete catalog -quietbcdedit.exe/set {default} bootstatuspolicy ignoreallfailures & bcdedit /set {default} recoveryenabled nowevtutil.execl Systemcl SecurityH
Source: _usm.exeBinary or memory string: bcdedit.exe
Source: _usm.exeBinary or memory string: C:\Windows\system32\cmd.exe /c%s %s %sServicesActive%s\*...SeShutdownPrivilegec:\Windows\system32\vssadmin.exedelete shadows /all /quietwbadmin.exedelete catalog -quietbcdedit.exe/set {default} bootstatuspolicy ignoreallfailures & bcdedit /set {default} recoveryenabled nowevtutil.execl Systemcl SecurityH
Source: cmd.exeBinary or memory string: 'Abcdedit.exeV
Source: cmd.exeBinary or memory string: 'Cbcdedit.exe
Source: cmd.exeBinary or memory string: bcdedit.exe
Source: cmd.exeBinary or memory string: indows\system32\bcdedit.exe
Source: cmd.exeBinary or memory string: bcdedit.exe /set {default} bootstatuspolicy ignoreallfailures & bcdedit /set {default} recoveryenabled no
Source: cmd.exeBinary or memory string: C:\Windows\system32\bcdedit.exeath\bcdedit.exe*}
Source: cmd.exeBinary or memory string: bcdedit.exe /set {default} bootstatuspolicy ignoreallfailures B
Source: cmd.exeBinary or memory string: 1C:\Windows\system32\bcdedit.exe\??\C:\Windows\system32\bcdedit.exe
Source: cmd.exeBinary or memory string: >C:\Windows\system32\cmd.exe/cbcdedit.exe/set{default}bootstatuspolicyignoreallfailures&bcdedit/set{default}recoveryenablednoamFiles=C:\Program FilesPSModulePath=C:\Windows\system32\WindowsPowerShell\v1.0\Modules\;C:\Program Files\AutoIt3\AutoItXPUBLIC=C:\Users\PublicSystemDrive=C:SystemRoot=C:\WindowsTEMP=C:\Users\HERBBL~1\AppData\Local\TempTMP=C:\Users\HERBBL~1\AppData\Local\TempUSERDOMAIN=computerUSERNAME=userUSERPROFILE=C:\Users\userwindir=C:\Windowswindows_tracing_flags=3windows_tracing_logfile=C:\BV
Source: cmd.exeBinary or memory string: C:\Windows\system32\bcdedit.exe
Source: cmd.exeBinary or memory string: InternalNamebcdedit.exe
Source: cmd.exeBinary or memory string: OriginalFilenamebcdedit.exej%
Source: cmd.exeBinary or memory string: C:\Windows\system32\cmd.exe /c bcdedit.exe /set {default} bootstatuspolicy ignoreallfailures & bcdedit /set {default} recoveryenabled no
Source: cmd.exeBinary or memory string: C:\Users\user\Desktopbcdedit.exeB
Source: cmd.exeBinary or memory string: indows\system32\bcdedit.exe.0\7
Source: cmd.exeBinary or memory string: C:\Windows\system32\bcdedit.exeath\bcdedit*B
Source: cmd.exeBinary or memory string: C:\Users\user\Desktop\C:\Windows\system32;;C:\Windows\system32;C:\Windows\system;C:\Windows;.;C:\ProgramData\Oracle\Java\javapath;C:\Windows\system32;C:\Windows;C:\Windows\System32\Wbem;C:\Windows\System32\WindowsPowerShell\v1.0\C:\Windows\system32\cmd.exeC:\Windows\system32\cmd.exe /c bcdedit.exe /set {default} bootstatuspolicy ignoreallfailures & bcdedit /set {default} recoveryenabled noC:\Windows\system32\cmd.exeWinSta0\Defaultf
Source: cmd.exeBinary or memory string: C:\Windows\system32\cmd.exe /c bcdedit.exe /set {default} bootstatuspolicy ignoreallfailures & bcdedit /set {default} recoveryenabled noa
Source: cmd.exeBinary or memory string: C:\Users\user\Desktop\C:\Windows\system32;C:\Windows\system32;C:\Windows\system;C:\Windows;.;C:\ProgramData\Oracle\Java\javapath;C:\Windows\system32;C:\Windows;C:\Windows\System32\Wbem;C:\Windows\System32\WindowsPowerShell\v1.0\bC:\Windows\system32\bcdedit.exebcdedit /set {default} recoveryenabled nobcdedit /set {default} recoveryenabled nodWinSta0\Default=C:=C:\Users\user\Desktop=ExitCode=00000000=Z:=Z:\ALLUSERSPROFILE=C:\ProgramDataAPPDATA=C:\Users\user\AppData\RoamingCommonProgramFiles=C:\Program Files\Common FilesCOMPUTERNAME=computerComSpec=C:\Windows\system32\cmd.exeFP_NO_HOST_CHECK=NOHOMEDRIVE=C:HOMEPATH=\Users\userLOCALAPPDATA=C:\Users\user\AppData\LocalLOGONSERVER=\\computerNUMBER_OF_PROCESSORS=1OS=Windows_NTPath=C:\ProgramData\Oracle\Java\javapath;C:\Windows\system32;C:\Windows;C:\Windows\System32\Wbem;C:\Windows\System32\WindowsPowerShell\v1.0\PATHEXT=.COM;.EXE;.BAT;.CMD;.VBS;.VBE;.JS;.JSE;.WSF;.WSH;.MSCPROCESSOR_ARCHITECTURE=x86PROCESSOR_IDENTIFIER=x
Source: bcdedit.exeBinary or memory string: Microsoft.Windows.OSLoader.BCDEdit,processorArchitecture="x86",type="win32",version="5.1.0.0"C:\Windows\system32\bcdedit.exeGsHd(
Source: bcdedit.exeBinary or memory string: @bcdedit.exe/set{default}bootstatuspolicyignoreallfailuresackburnLOCALAPPDATA=C:\Users\user\AppData\LocalLOGONSERVER=\\computerNUMBER_OF_PROCESSORS=1OS=Windows_NTPath=C:
Source: bcdedit.exeBinary or memory string: bcdedit.exe /set {default} bootstatuspolicy ignoreallfailures
Source: bcdedit.exeBinary or memory string: C:\Users\user\Desktop\C:\Windows\system32;C:\Windows\system32;C:\Windows\system;C:\Windows;.;C:\ProgramData\Oracle\Java\javapath;C:\Windows\system32;C:\Windows;C:\Windows\System32\Wbem;C:\Windows\System32\WindowsPowerShell\v1.0\C:\Windows\system32\bcdedit.exebcdedit.exe /set {default} bootstatuspolicy ignoreallfailures bcdedit.exe /set {default} bootstatuspolicy ignoreallfailures WinSta0\Default
Source: bcdedit.exeBinary or memory string: \Device\HarddiskVolume2\Windows\System32\bcdedit.exe;##
Source: bcdedit.exeBinary or memory string: bcdedit.exeBC:\Users\user\Desktop\
Source: bcdedit.exeBinary or memory string: Microsoft.Windows.OSLoader.BCDEdit,processorArchitecture="x86",type="win32",version="5.1.0.0"C:\Windows\system32\bcdedit.exeGsHd(
Source: bcdedit.exeBinary or memory string: bcdedit.exeBC:\Users\user\Desktop\
Source: bcdedit.exeBinary or memory string: C:\Users\user\Desktop\C:\Windows\system32;C:\Windows\system32;C:\Windows\system;C:\Windows;.;C:\ProgramData\Oracle\Java\javapath;C:\Windows\system32;C:\Windows;C:\Windows\System32\Wbem;C:\Windows\System32\WindowsPowerShell\v1.0\C:\Windows\system32\bcdedit.exebcdedit /set {default} recoveryenabled nobcdedit /set {default} recoveryenabled noWinSta0\Defaulti
Source: bcdedit.exeBinary or memory string: hj4`=\Device\HarddiskVolume2\Windows\System32\bcdedit.exe;##
Source: _usm.exe.1.drBinary or memory string: C:\Windows\system32\cmd.exe /c%s %s %sServicesActive%s\*...SeShutdownPrivilegec:\Windows\system32\vssadmin.exedelete shadows /all /quietwbadmin.exedelete catalog -quietbcdedit.exe/set {default} bootstatuspolicy ignoreallfailures & bcdedit /set {default} recoveryenabled nowevtutil.execl Systemcl SecurityH
Uses bcdedit to modify the Windows boot settingsShow sources
Source: unknownProcess created: C:\Windows\System32\bcdedit.exe bcdedit.exe /set {default} bootstatuspolicy ignoreallfailures
Source: unknownProcess created: C:\Windows\System32\bcdedit.exe bcdedit /set {default} recoveryenabled no
Source: C:\Windows\System32\cmd.exeProcess created: C:\Windows\System32\bcdedit.exe bcdedit.exe /set {default} bootstatuspolicy ignoreallfailures
Source: C:\Windows\System32\cmd.exeProcess created: C:\Windows\System32\bcdedit.exe bcdedit /set {default} recoveryenabled no

Data Obfuscation:

barindex
Contains functionality to dynamically determine API callsShow sources
Source: C:\Users\user\Desktop\winlogon.exeCode function: 1_2_00D643A0 GetVersionExW,LoadLibraryW,GetProcAddress,SHGetKnownFolderPath,1_2_00D643A0
Uses code obfuscation techniques (call, push, ret)Show sources
Source: C:\Users\user\Desktop\winlogon.exeCode function: 1_2_00D6B696 push ecx; ret 1_2_00D6B6A9
Source: C:\Users\user\AppData\Local\Temp\yegus.exeCode function: 2_2_013348F6 push ecx; ret 2_2_01334909
Source: C:\Users\user\AppData\Local\Temp\yegus.exeCode function: 2_2_10083436 push ecx; ret 2_2_10083449
Source: C:\Users\user\AppData\Local\Temp\ucngw.exeCode function: 3_2_00C51CE6 push ecx; ret 3_2_00C51CF9
Source: C:\Users\user\AppData\Local\Temp\ucngw.exeCode function: 3_2_10001966 push ecx; ret 3_2_10001979
Source: C:\Users\user\AppData\Local\Temp\_usm.exeCode function: 4_2_00142CC5 push ecx; ret 4_2_00142CD8

Spreading:

barindex
Contains functionality to enumerate / list files inside a directoryShow sources
Source: C:\Users\user\Desktop\winlogon.exeCode function: 1_2_00D75F8F FindFirstFileExW,1_2_00D75F8F
Source: C:\Users\user\AppData\Local\Temp\yegus.exeCode function: 2_2_01339A82 FindFirstFileExW,2_2_01339A82
Source: C:\Users\user\AppData\Local\Temp\yegus.exeCode function: 2_2_10088620 FindFirstFileExA,2_2_10088620
Source: C:\Users\user\AppData\Local\Temp\ucngw.exeCode function: 3_2_00C5850A FindFirstFileExW,3_2_00C5850A
Source: C:\Users\user\AppData\Local\Temp\ucngw.exeCode function: 3_2_10008EEC FindFirstFileExA,3_2_10008EEC
Source: C:\Users\user\AppData\Local\Temp\_usm.exeCode function: 4_2_00141441 wsprintfW,FindFirstFileW,GetProcessHeap,PathAppendW,GetProcessHeap,HeapAlloc,PathAppendW,PathAppendW,StrCmpCW,StrCmpCW,StrCmpCW,CreateFileW,GetFileSizeEx,CloseHandle,GetProcessHeap,HeapFree,FindNextFileW,FindClose,4_2_00141441
Creates COM task schedule object (often to register a task for autostart)Show sources
Source: C:\Windows\System32\wbengine.exeKey opened: HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{0F87369F-A4E5-4CFC-BD3E-73E6154572DD}
Source: C:\Windows\System32\wbengine.exeKey opened: HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{0f87369f-a4e5-4cfc-bd3e-73e6154572dd}\TreatAs
Source: C:\Windows\System32\wbengine.exeKey opened: HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{0f87369f-a4e5-4cfc-bd3e-73e6154572dd}\Progid
Source: C:\Windows\System32\wbengine.exeKey opened: HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{0f87369f-a4e5-4cfc-bd3e-73e6154572dd}\Progid
Source: C:\Windows\System32\wbengine.exeKey opened: HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{0f87369f-a4e5-4cfc-bd3e-73e6154572dd}\InprocServer32
Source: C:\Windows\System32\wbengine.exeKey opened: HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{0f87369f-a4e5-4cfc-bd3e-73e6154572dd}\InprocHandler32
Source: C:\Windows\System32\wbengine.exeKey opened: HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{0f87369f-a4e5-4cfc-bd3e-73e6154572dd}\InprocHandler
Source: C:\Windows\System32\wbengine.exeKey opened: HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{0F87369F-A4E5-4CFC-BD3E-73E6154572DD}
Source: C:\Windows\System32\wbengine.exeKey opened: HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{0f87369f-a4e5-4cfc-bd3e-73e6154572dd}\TreatAs
Found PSEXEC tool (often used for remote process execution)Show sources
Source: winlogon.exeString found in binary or memory: PsExec executes a program on a remote system, where remotely executed console
Source: _wjg.exe.1.drString found in binary or memory: PsExec executes a program on a remote system, where remotely executed console

System Summary:

barindex
Submission file is bigger than most known malware samplesShow sources
Source: winlogon.exeStatic file information: File size 1861632 > 1048576
PE file has a big raw sectionShow sources
Source: winlogon.exeStatic PE information: Raw size of .rsrc is bigger than: 0x100000 < 0x195c00
PE file contains a mix of data directories often seen in goodwareShow sources
Source: winlogon.exeStatic PE information: data directory type: IMAGE_DIRECTORY_ENTRY_IMPORT
Source: winlogon.exeStatic PE information: data directory type: IMAGE_DIRECTORY_ENTRY_RESOURCE
Source: winlogon.exeStatic PE information: data directory type: IMAGE_DIRECTORY_ENTRY_BASERELOC
Source: winlogon.exeStatic PE information: data directory type: IMAGE_DIRECTORY_ENTRY_DEBUG
Source: winlogon.exeStatic PE information: data directory type: IMAGE_DIRECTORY_ENTRY_LOAD_CONFIG
Source: winlogon.exeStatic PE information: data directory type: IMAGE_DIRECTORY_ENTRY_IAT
Contains modern PE file flags such as dynamic base (ASLR) or NXShow sources
Source: winlogon.exeStatic PE information: TERMINAL_SERVER_AWARE, DYNAMIC_BASE, NX_COMPAT
PE file contains a debug data directoryShow sources
Source: winlogon.exeStatic PE information: data directory type: IMAGE_DIRECTORY_ENTRY_DEBUG
Binary contains paths to debug symbolsShow sources
Source: Binary string: KERBEROS.pdb source: ucngw.exe
Source: Binary string: msv1_0.pdb source: ucngw.exe
Source: Binary string: lsasrv.pdb source: ucngw.exe
PE file contains a valid data directory to section mappingShow sources
Source: winlogon.exeStatic PE information: Data directory: IMAGE_DIRECTORY_ENTRY_IMPORT is in: .rdata
Source: winlogon.exeStatic PE information: Data directory: IMAGE_DIRECTORY_ENTRY_RESOURCE is in: .rsrc
Source: winlogon.exeStatic PE information: Data directory: IMAGE_DIRECTORY_ENTRY_BASERELOC is in: .reloc
Source: winlogon.exeStatic PE information: Data directory: IMAGE_DIRECTORY_ENTRY_LOAD_CONFIG is in: .rdata
Source: winlogon.exeStatic PE information: Data directory: IMAGE_DIRECTORY_ENTRY_IAT is in: .rdata
Binary contains device paths (device paths are often used for kernel mode <-> user mode communication)Show sources
Source: _wjg.exe.1.drBinary string: Sysinternals RocksRtlNtStatusToDosErrorntdll.dllRtlInitUnicodeStringNtOpenFileNtFsControlFile\Device\Srv2\Device\LanmanServerSeTcbPrivilege"%s" %sNetIsServiceAccountnetapi32.dll_SA_{262E99C9-6160-4871-ACEC-4E61736B6F21}NT AUTHORITYNT SERVICECreateRestrictedTokenwinsta0Winlogondefaultwinsta0\winlogonwinsta0\defaultWow64DisableWow64FsRedirectionKernel32.dll%s.exefailed to readsecure: %d
Source: _wjg.exe.1.drBinary string: Sysinternals RocksRtlNtStatusToDosErrorntdll.dllRtlInitUnicodeStringNtOpenFileNtFsControlFile\Device\LanmanRedirector\%s\ipc$Use PsKill to terminate the remotely running program.
Classification labelShow sources
Source: classification engineClassification label: mal100.evad.spre.rans.spyw.troj.winEXE@34/9@31/10
Contains functionality to adjust token privileges (e.g. debug / backup)Show sources
Source: C:\Users\user\Desktop\winlogon.exeCode function: 1_2_00D62B90 GetCurrentProcess,OpenProcessToken,GetTokenInformation,GetTokenInformation,GetTokenInformation,LookupPrivilegeNameW,AdjustTokenPrivileges,CloseHandle,1_2_00D62B90
Source: C:\Users\user\AppData\Local\Temp\yegus.exeCode function: 2_2_013335E0 GetCurrentProcess,OpenProcessToken,GetTokenInformation,GetTokenInformation,GetTokenInformation,LookupPrivilegeNameW,AdjustTokenPrivileges,CloseHandle,2_2_013335E0
Source: C:\Users\user\AppData\Local\Temp\ucngw.exeCode function: 3_2_00C61A30 GetCurrentProcess,OpenProcessToken,GetTokenInformation,GetTokenInformation,GetTokenInformation,LookupPrivilegeNameW,AdjustTokenPrivileges,CloseHandle,3_2_00C61A30
Source: C:\Users\user\AppData\Local\Temp\_usm.exeCode function: 4_2_001416E9 Wow64DisableWow64FsRedirection,LookupPrivilegeValueW,GetCurrentProcess,OpenProcessToken,AdjustTokenPrivileges,Wow64RevertWow64FsRedirection,CreateThread,Sleep,InitiateSystemShutdownExW,ExitProcess,4_2_001416E9
Contains functionality to instantiate COM classesShow sources
Source: C:\Users\user\Desktop\winlogon.exeCode function: 1_2_00D64C30 CoInitializeEx,CoInitializeSecurity,CredUIParseUserNameW,LocalAlloc,SysAllocString,SysAllocString,SysAllocString,SysAllocString,SysStringLen,SysStringLen,SysStringLen,SysStringLen,CoCreateInstance,SysFreeString,wsprintfW,SysAllocString,SysAllocString,SysAllocString,SysAllocString,CoSetProxyBlanket,CoSetProxyBlanket,SysAllocString,SysAllocString,SysFreeString,VariantClear,SysAllocString,SysAllocString,GetModuleFileNameW,CreateFileW,GetFileSize,SafeArrayCreate,SafeArrayAccessData,ReadFile,SafeArrayUnaccessData,CloseHandle,CloseHandle,SysFreeString,SysFreeString,SysFreeString,SysFreeString,SysFreeString,SysFreeString,SysFreeString,SysFreeString,LocalFree,CoUninitialize,1_2_00D64C30
Contains functionality to load and extract PE file embedded resourcesShow sources
Source: C:\Users\user\Desktop\winlogon.exeCode function: 1_2_00D6AAD0 GetModuleHandleW,FindResourceW,LoadResource,LockResource,SizeofResource,1_2_00D6AAD0
Contains functionality to modify services (start/stop/modify)Show sources
Source: C:\Users\user\AppData\Local\Temp\_usm.exeCode function: 4_2_001412E8 OpenSCManagerW,EnumServicesStatusW,EnumServicesStatusW,GetProcessHeap,GetProcessHeap,RtlAllocateHeap,EnumServicesStatusW,QueryServiceConfigW,OpenServiceW,QueryServiceConfigW,GetProcessHeap,HeapAlloc,ChangeServiceConfigW,QueryServiceConfigW,PathRemoveArgsW,GetProcessHeap,HeapFree,GetLastError,CloseServiceHandle,GetProcessHeap,HeapFree,CloseServiceHandle,4_2_001412E8
Creates files inside the user directoryShow sources
Source: C:\Users\user\Desktop\winlogon.exeFile created: C:\Users\Public\A9E5CC701A2E98F9114060D6645A7A5B
Creates temporary filesShow sources
Source: C:\Users\user\Desktop\winlogon.exeFile created: C:\Users\HERBBL~1\AppData\Local\Temp\yegus.exe
Might use command line argumentsShow sources
Source: C:\Users\user\AppData\Local\Temp\yegus.exeCommand line argument: <NULL>2_2_013338C0
Source: C:\Users\user\AppData\Local\Temp\yegus.exeCommand line argument: <NULL>2_2_013338C0
Source: C:\Users\user\AppData\Local\Temp\ucngw.exeCommand line argument: <NULL>3_2_00C61EC0
Source: C:\Users\user\AppData\Local\Temp\ucngw.exeCommand line argument: <NULL>3_2_00C61EC0
Source: C:\Users\user\AppData\Local\Temp\_usm.exeCommand line argument: wbadmin.exe4_2_001416E9
Source: C:\Users\user\AppData\Local\Temp\_usm.exeCommand line argument: bcdedit.exe4_2_001416E9
Source: C:\Users\user\AppData\Local\Temp\_usm.exeCommand line argument: wevtutil.exe4_2_001416E9
PE file has an executable .text section and no other executable sectionShow sources
Source: winlogon.exeStatic PE information: Section: .text IMAGE_SCN_MEM_EXECUTE, IMAGE_SCN_CNT_CODE, IMAGE_SCN_MEM_READ
Reads ini filesShow sources
Source: C:\Users\user\AppData\Local\Temp\yegus.exeFile read: C:\Users\user\AppData\Roaming\Mozilla\Firefox\profiles.ini
Reads software policiesShow sources
Source: C:\Users\user\Desktop\winlogon.exeKey opened: HKEY_LOCAL_MACHINE\Software\Policies\Microsoft\Windows\Safer\CodeIdentifiers
SQL strings found in memory and binary dataShow sources
Source: yegus.exeBinary or memory string: SELECT origin_url, username_value, password_value FROM logins;`R
Source: yegus.exeBinary or memory string: UPDATE "%w".%s SET sql = sqlite_rename_parent(sql, %Q, %Q) WHERE %s;
Source: yegus.exeBinary or memory string: SELECT origin_url, username_value, password_value FROM logins;
Source: yegus.exeBinary or memory string: SELECT formSubmitURL, encryptedUsername, encryptedPassword FROM moz_logins;
Source: yegus.exeBinary or memory string: INSERT INTO %Q.%s VALUES('index',%Q,%Q,#%d,%Q);
Source: yegus.exeBinary or memory string: UPDATE %Q.%s SET sql = CASE WHEN type = 'trigger' THEN sqlite_rename_trigger(sql, %Q)ELSE sqlite_rename_table(sql, %Q) END, tbl_name = %Q, name = CASE WHEN type='table' THEN %Q WHEN name LIKE 'sqlite_autoindex%%' AND type='index' THEN 'sqlite_autoindex_' || %Q || substr(name,%d+18) ELSE name END WHERE tbl_name=%Q COLLATE nocase AND (type='table' OR type='index' OR type='trigger');
Source: yegus.exeBinary or memory string: UPDATE sqlite_temp_master SET sql = sqlite_rename_trigger(sql, %Q), tbl_name = %Q WHERE %s;
Sample is known by Antivirus (Virustotal or Metascan)Show sources
Source: winlogon.exeVirustotal: hash found
Spawns processesShow sources
Source: unknownProcess created: C:\Users\user\Desktop\winlogon.exe 'C:\Users\user\Desktop\winlogon.exe'
Source: unknownProcess created: C:\Users\user\AppData\Local\Temp\yegus.exe 123 \\.\pipe\122B85FE-84BD-45AB-AEE5-28D37FB4C464
Source: unknownProcess created: C:\Users\user\AppData\Local\Temp\ucngw.exe 123 \\.\pipe\33F83B68-FC3D-4C1F-B4AE-1329770D367B
Source: unknownProcess created: C:\Users\user\AppData\Local\Temp\_usm.exe C:\Users\HERBBL~1\AppData\Local\Temp\_usm.exe
Source: unknownProcess created: C:\Windows\System32\cmd.exe C:\Windows\system32\cmd.exe /c c:\Windows\system32\vssadmin.exe delete shadows /all /quiet
Source: unknownProcess created: C:\Windows\System32\vssadmin.exe c:\Windows\system32\vssadmin.exe delete shadows /all /quiet
Source: unknownProcess created: C:\Windows\System32\cmd.exe C:\Windows\system32\cmd.exe /c wbadmin.exe delete catalog -quiet
Source: unknownProcess created: C:\Windows\System32\wbadmin.exe wbadmin.exe delete catalog -quiet
Source: unknownProcess created: C:\Windows\System32\wbengine.exe C:\Windows\system32\wbengine.exe
Source: unknownProcess created: C:\Windows\System32\vdsldr.exe C:\Windows\System32\vdsldr.exe -Embedding
Source: unknownProcess created: C:\Windows\System32\vds.exe C:\Windows\System32\vds.exe
Source: unknownProcess created: C:\Windows\System32\cmd.exe C:\Windows\system32\cmd.exe /c bcdedit.exe /set {default} bootstatuspolicy ignoreallfailures & bcdedit /set {default} recoveryenabled no
Source: unknownProcess created: C:\Windows\System32\bcdedit.exe bcdedit.exe /set {default} bootstatuspolicy ignoreallfailures
Source: unknownProcess created: C:\Windows\System32\bcdedit.exe bcdedit /set {default} recoveryenabled no
Source: unknownProcess created: C:\Windows\System32\cmd.exe C:\Windows\system32\cmd.exe /c wevtutil.exe cl System
Source: unknownProcess created: C:\Windows\System32\wevtutil.exe wevtutil.exe cl System
Source: unknownProcess created: C:\Windows\System32\cmd.exe C:\Windows\system32\cmd.exe /c wevtutil.exe cl Security
Source: unknownProcess created: C:\Windows\System32\wevtutil.exe wevtutil.exe cl Security
Source: unknownProcess created: C:\Windows\System32\LogonUI.exe 'LogonUI.exe' /flags:0x0
Source: unknownProcess created: C:\Windows\System32\LogonUI.exe unknown
Source: C:\Users\user\Desktop\winlogon.exeProcess created: C:\Users\user\AppData\Local\Temp\yegus.exe 123 \\.\pipe\122B85FE-84BD-45AB-AEE5-28D37FB4C464
Source: C:\Users\user\Desktop\winlogon.exeProcess created: C:\Users\user\AppData\Local\Temp\ucngw.exe 123 \\.\pipe\33F83B68-FC3D-4C1F-B4AE-1329770D367B
Source: C:\Users\user\Desktop\winlogon.exeProcess created: C:\Users\user\AppData\Local\Temp\_usm.exe C:\Users\HERBBL~1\AppData\Local\Temp\_usm.exe
Source: C:\Users\user\AppData\Local\Temp\_usm.exeProcess created: C:\Windows\System32\cmd.exe C:\Windows\system32\cmd.exe /c c:\Windows\system32\vssadmin.exe delete shadows /all /quiet
Source: C:\Users\user\AppData\Local\Temp\_usm.exeProcess created: C:\Windows\System32\cmd.exe C:\Windows\system32\cmd.exe /c wbadmin.exe delete catalog -quiet
Source: C:\Users\user\AppData\Local\Temp\_usm.exeProcess created: C:\Windows\System32\cmd.exe C:\Windows\system32\cmd.exe /c bcdedit.exe /set {default} bootstatuspolicy ignoreallfailures & bcdedit /set {default} recoveryenabled no
Source: C:\Users\user\AppData\Local\Temp\_usm.exeProcess created: C:\Windows\System32\cmd.exe C:\Windows\system32\cmd.exe /c wevtutil.exe cl System
Source: C:\Users\user\AppData\Local\Temp\_usm.exeProcess created: C:\Windows\System32\cmd.exe C:\Windows\system32\cmd.exe /c wevtutil.exe cl Security
Source: C:\Windows\System32\cmd.exeProcess created: C:\Windows\System32\vssadmin.exe c:\Windows\system32\vssadmin.exe delete shadows /all /quiet
Source: C:\Windows\System32\cmd.exeProcess created: C:\Windows\System32\wbadmin.exe wbadmin.exe delete catalog -quiet
Source: C:\Windows\System32\cmd.exeProcess created: C:\Windows\System32\bcdedit.exe bcdedit.exe /set {default} bootstatuspolicy ignoreallfailures
Source: C:\Windows\System32\cmd.exeProcess created: C:\Windows\System32\bcdedit.exe bcdedit /set {default} recoveryenabled no
Source: C:\Windows\System32\cmd.exeProcess created: C:\Windows\System32\wevtutil.exe wevtutil.exe cl System
Source: C:\Windows\System32\cmd.exeProcess created: C:\Windows\System32\wevtutil.exe wevtutil.exe cl Security
Uses an in-process (OLE) Automation serverShow sources
Source: C:\Users\user\Desktop\winlogon.exeKey value queried: HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{4590F811-1D3A-11D0-891F-00AA004B2E24}\InprocServer32
PE file has section (not .text) which is very likely to contain packed code (zlib compression ratio < 0.011)Show sources
Source: winlogon.exeStatic PE information: Section: .rsrc ZLIB complexity 1.00009145872
Source: yegus.exe.1.drStatic PE information: Section: .rsrc ZLIB complexity 0.999364306084
Source: ucngw.exe.1.drStatic PE information: Section: .rsrc ZLIB complexity 0.995655293367
Source: _yig.exe.1.drStatic PE information: Section: .rsrc ZLIB complexity 1.00009145872
Contains functionality to call native functionsShow sources
Source: C:\Users\user\AppData\Local\Temp\ucngw.exeCode function: 3_2_100147C0 NtQuerySystemInformation,LocalAlloc,NtQuerySystemInformation,LocalFree,3_2_100147C0
Source: C:\Users\user\AppData\Local\Temp\ucngw.exeCode function: 3_2_10013CB0 LoadLibraryW,GetModuleHandleW,NtQueryInformationProcess,3_2_10013CB0
Source: C:\Users\user\AppData\Local\Temp\ucngw.exeCode function: 3_2_100145E0 GetCurrentProcess,NtQueryInformationProcess,RtlGetCurrentPeb,3_2_100145E0
Creates files inside the system directoryShow sources
Source: C:\Windows\System32\wbadmin.exeFile created: C:\Windows\Logs\WindowsBackup
Detected potential crypto functionShow sources
Source: C:\Users\user\Desktop\winlogon.exeCode function: 1_2_00D7989E1_2_00D7989E
Source: C:\Users\user\Desktop\winlogon.exeCode function: 1_2_00D793F01_2_00D793F0
Source: C:\Users\user\Desktop\winlogon.exeCode function: 1_2_00D6F6CE1_2_00D6F6CE
Source: C:\Users\user\Desktop\winlogon.exeCode function: 1_2_00D7CF3F1_2_00D7CF3F
Source: C:\Users\user\Desktop\winlogon.exeCode function: 1_2_00D611101_2_00D61110
Source: C:\Users\user\Desktop\winlogon.exeCode function: 1_2_00D693301_2_00D69330
Source: C:\Users\user\Desktop\winlogon.exeCode function: 1_2_00D618701_2_00D61870
Source: C:\Users\user\Desktop\winlogon.exeCode function: 1_2_00D68EE01_2_00D68EE0
Source: C:\Users\user\AppData\Local\Temp\yegus.exeCode function: 2_2_013313702_2_01331370
Source: C:\Users\user\AppData\Local\Temp\yegus.exeCode function: 2_2_0133E8FF2_2_0133E8FF
Source: C:\Users\user\AppData\Local\Temp\yegus.exeCode function: 2_2_013315E02_2_013315E0
Source: C:\Users\user\AppData\Local\Temp\yegus.exeCode function: 2_2_013310A02_2_013310A0
Source: C:\Users\user\AppData\Local\Temp\yegus.exeCode function: 2_2_01332B702_2_01332B70
Source: C:\Users\user\AppData\Local\Temp\yegus.exeCode function: 2_2_013332D02_2_013332D0
Source: C:\Users\user\AppData\Local\Temp\yegus.exeCode function: 2_2_100641402_2_10064140
Source: C:\Users\user\AppData\Local\Temp\yegus.exeCode function: 2_2_100196A02_2_100196A0
Source: C:\Users\user\AppData\Local\Temp\yegus.exeCode function: 2_2_100291302_2_10029130
Source: C:\Users\user\AppData\Local\Temp\yegus.exeCode function: 2_2_1003C8802_2_1003C880
Source: C:\Users\user\AppData\Local\Temp\yegus.exeCode function: 2_2_10053C802_2_10053C80
Source: C:\Users\user\AppData\Local\Temp\yegus.exeCode function: 2_2_100658702_2_10065870
Source: C:\Users\user\AppData\Local\Temp\yegus.exeCode function: 2_2_100804F02_2_100804F0
Source: C:\Users\user\AppData\Local\Temp\yegus.exeCode function: 2_2_100270502_2_10027050
Source: C:\Users\user\AppData\Local\Temp\yegus.exeCode function: 2_2_100060222_2_10006022
Source: C:\Users\user\AppData\Local\Temp\yegus.exeCode function: 2_2_100078702_2_10007870
Source: C:\Users\user\AppData\Local\Temp\yegus.exeCode function: 2_2_10005C302_2_10005C30
Source: C:\Users\user\AppData\Local\Temp\yegus.exeCode function: 2_2_1006F8102_2_1006F810
Source: C:\Users\user\AppData\Local\Temp\yegus.exeCode function: 2_2_10036CD02_2_10036CD0
Source: C:\Users\user\AppData\Local\Temp\yegus.exeCode function: 2_2_1003B6A02_2_1003B6A0
Source: C:\Users\user\AppData\Local\Temp\yegus.exeCode function: 2_2_10008D502_2_10008D50
Source: C:\Users\user\AppData\Local\Temp\yegus.exeCode function: 2_2_100794592_2_10079459
Source: C:\Users\user\AppData\Local\Temp\yegus.exeCode function: 2_2_10022AD02_2_10022AD0
Source: C:\Users\user\AppData\Local\Temp\yegus.exeCode function: 2_2_100780602_2_10078060
Source: C:\Users\user\AppData\Local\Temp\yegus.exeCode function: 2_2_100170502_2_10017050
Source: C:\Users\user\AppData\Local\Temp\yegus.exeCode function: 2_2_100022002_2_10002200
Source: C:\Users\user\AppData\Local\Temp\yegus.exeCode function: 2_2_1002DD282_2_1002DD28
Source: C:\Users\user\AppData\Local\Temp\yegus.exeCode function: 2_2_100747802_2_10074780
Source: C:\Users\user\AppData\Local\Temp\yegus.exeCode function: 2_2_10021F802_2_10021F80
Source: C:\Users\user\AppData\Local\Temp\yegus.exeCode function: 2_2_1001EBB02_2_1001EBB0
Source: C:\Users\user\AppData\Local\Temp\yegus.exeCode function: 2_2_1001CFF02_2_1001CFF0
Source: C:\Users\user\AppData\Local\Temp\yegus.exeCode function: 2_2_1008DE012_2_1008DE01
Source: C:\Users\user\AppData\Local\Temp\yegus.exeCode function: 2_2_100722E02_2_100722E0
Source: C:\Users\user\AppData\Local\Temp\ucngw.exeCode function: 3_2_00C5FC903_2_00C5FC90
Source: C:\Users\user\AppData\Local\Temp\ucngw.exeCode function: 3_2_00C60F403_2_00C60F40
Source: C:\Users\user\AppData\Local\Temp\ucngw.exeCode function: 3_2_00C5D39F3_2_00C5D39F
Source: C:\Users\user\AppData\Local\Temp\ucngw.exeCode function: 3_2_00C5FD203_2_00C5FD20
Source: C:\Users\user\AppData\Local\Temp\ucngw.exeCode function: 3_2_00C611503_2_00C61150
Source: C:\Users\user\AppData\Local\Temp\ucngw.exeCode function: 3_2_00C5F3F03_2_00C5F3F0
Source: C:\Users\user\AppData\Local\Temp\ucngw.exeCode function: 3_2_00C5F6A03_2_00C5F6A0
Source: C:\Users\user\AppData\Local\Temp\ucngw.exeCode function: 3_2_100049503_2_10004950
Source: C:\Users\user\AppData\Local\Temp\ucngw.exeCode function: 3_2_100039B33_2_100039B3
Source: C:\Users\user\AppData\Local\Temp\ucngw.exeCode function: 3_2_1000F8983_2_1000F898
Source: C:\Users\user\AppData\Local\Temp\ucngw.exeCode function: 3_2_10003C103_2_10003C10
Source: C:\Users\user\AppData\Local\Temp\ucngw.exeCode function: 3_2_1000B61E3_2_1000B61E
Enables security privilegesShow sources
Source: C:\Users\user\Desktop\winlogon.exeProcess token adjusted: Security
Found potential string decryption / allocating functionsShow sources
Source: C:\Users\user\Desktop\winlogon.exeCode function: String function: 00D6B650 appears 34 times
Source: C:\Users\user\AppData\Local\Temp\yegus.exeCode function: String function: 100071E0 appears 59 times
Source: C:\Users\user\AppData\Local\Temp\yegus.exeCode function: String function: 10024C30 appears 105 times
Source: C:\Users\user\AppData\Local\Temp\yegus.exeCode function: String function: 10007480 appears 193 times
Source: C:\Users\user\AppData\Local\Temp\yegus.exeCode function: String function: 10008070 appears 167 times
Source: C:\Users\user\AppData\Local\Temp\ucngw.exeCode function: String function: 00C51CA0 appears 32 times
PE file contains executable resources (Code or Archives)Show sources
Source: _wjg.exe.1.drStatic PE information: Resource name: BINRES type: PE32 executable (console) Intel 80386, for MS Windows
Reads the hosts fileShow sources
Source: C:\Users\user\Desktop\winlogon.exeFile read: C:\Windows\System32\drivers\etc\hosts
Source: C:\Users\user\Desktop\winlogon.exeFile read: C:\Windows\System32\drivers\etc\hosts
Source: C:\Users\user\Desktop\winlogon.exeFile read: C:\Windows\System32\drivers\etc\hosts
Source: C:\Users\user\Desktop\winlogon.exeFile read: C:\Windows\System32\drivers\etc\hosts
Source: C:\Users\user\Desktop\winlogon.exeFile read: C:\Windows\System32\drivers\etc\hosts
Source: C:\Users\user\Desktop\winlogon.exeFile read: C:\Windows\System32\drivers\etc\hosts
Sample file is different than original file name gathered from version infoShow sources
Source: winlogon.exeBinary or memory string: OriginalFilenamepsexec.cH vs winlogon.exe
Source: winlogon.exeBinary or memory string: OriginalFilenamepsexesvc.exeH vs winlogon.exe
Sample reads its own file contentShow sources
Source: C:\Users\user\Desktop\winlogon.exeFile read: C:\Users\user\Desktop\winlogon.exe
Tries to load missing DLLsShow sources
Source: C:\Users\user\AppData\Local\Temp\yegus.exeSection loaded: ext-ms-win-kernel32-package-current-l1-1-0.dll
Source: C:\Users\user\AppData\Local\Temp\ucngw.exeSection loaded: ext-ms-win-kernel32-package-current-l1-1-0.dll

HIPS / PFW / Operating System Protection Evasion:

barindex
Contains functionality to execute programs as a different userShow sources
Source: C:\Users\user\Desktop\winlogon.exeCode function: 1_2_00D63920 LogonUserA,GetLastError,DeleteCriticalSection,1_2_00D63920
Contains functionality to inject code into remote processesShow sources
Source: C:\Users\user\Desktop\winlogon.exeCode function: 1_2_00D65DD0 ExitProcess,Sleep,DeleteFileW,GetFileSize,WriteFile,GetFileAttributesW,CreateFileW,CloseHandle,GetModuleHandleW,GetModuleFileNameW,GetWindowsDirectoryW,CreateProcessW,VirtualAllocEx,VirtualAllocEx,WriteProcessMemory,WriteProcessMemory,VirtualAllocEx,WriteProcessMemory,VirtualProtectEx,CreateRemoteThread,TerminateProcess,CloseHandle,1_2_00D65DD0
Contains functionality to inject threads in other processesShow sources
Source: C:\Users\user\Desktop\winlogon.exeCode function: 1_2_00D65DD0 ExitProcess,Sleep,DeleteFileW,GetFileSize,WriteFile,GetFileAttributesW,CreateFileW,CloseHandle,GetModuleHandleW,GetModuleFileNameW,GetWindowsDirectoryW,CreateProcessW,VirtualAllocEx,VirtualAllocEx,WriteProcessMemory,WriteProcessMemory,VirtualAllocEx,WriteProcessMemory,VirtualProtectEx,CreateRemoteThread,TerminateProcess,CloseHandle,1_2_00D65DD0

Anti Debugging:

barindex
Contains functionality to register its own exception handlerShow sources
Source: C:\Users\user\Desktop\winlogon.exeCode function: 1_2_00D6B598 SetUnhandledExceptionFilter,1_2_00D6B598
Source: C:\Users\user\Desktop\winlogon.exeCode function: 1_2_00D6AE70 SetUnhandledExceptionFilter,UnhandledExceptionFilter,GetCurrentProcess,TerminateProcess,1_2_00D6AE70
Source: C:\Users\user\Desktop\winlogon.exeCode function: 1_2_00D6B406 IsProcessorFeaturePresent,IsDebuggerPresent,SetUnhandledExceptionFilter,UnhandledExceptionFilter,1_2_00D6B406
Source: C:\Users\user\Desktop\winlogon.exeCode function: 1_2_00D7009F IsDebuggerPresent,SetUnhandledExceptionFilter,UnhandledExceptionFilter,1_2_00D7009F
Source: C:\Users\user\AppData\Local\Temp\yegus.exeCode function: 2_2_013347F1 SetUnhandledExceptionFilter,2_2_013347F1
Source: C:\Users\user\AppData\Local\Temp\yegus.exeCode function: 2_2_013346A3 IsProcessorFeaturePresent,IsDebuggerPresent,SetUnhandledExceptionFilter,UnhandledExceptionFilter,2_2_013346A3
Source: C:\Users\user\AppData\Local\Temp\yegus.exeCode function: 2_2_013340FB SetUnhandledExceptionFilter,UnhandledExceptionFilter,GetCurrentProcess,TerminateProcess,2_2_013340FB
Source: C:\Users\user\AppData\Local\Temp\yegus.exeCode function: 2_2_013372DB IsDebuggerPresent,SetUnhandledExceptionFilter,UnhandledExceptionFilter,2_2_013372DB
Source: C:\Users\user\AppData\Local\Temp\yegus.exeCode function: 2_2_100827CB SetUnhandledExceptionFilter,UnhandledExceptionFilter,GetCurrentProcess,TerminateProcess,2_2_100827CB
Source: C:\Users\user\AppData\Local\Temp\yegus.exeCode function: 2_2_1008657C IsDebuggerPresent,SetUnhandledExceptionFilter,UnhandledExceptionFilter,2_2_1008657C
Source: C:\Users\user\AppData\Local\Temp\yegus.exeCode function: 2_2_10083265 IsProcessorFeaturePresent,IsDebuggerPresent,SetUnhandledExceptionFilter,UnhandledExceptionFilter,2_2_10083265
Source: C:\Users\user\AppData\Local\Temp\ucngw.exeCode function: 3_2_00C51BE9 SetUnhandledExceptionFilter,3_2_00C51BE9
Source: C:\Users\user\AppData\Local\Temp\ucngw.exeCode function: 3_2_00C54CBD IsDebuggerPresent,SetUnhandledExceptionFilter,UnhandledExceptionFilter,3_2_00C54CBD
Source: C:\Users\user\AppData\Local\Temp\ucngw.exeCode function: 3_2_00C514CB SetUnhandledExceptionFilter,UnhandledExceptionFilter,GetCurrentProcess,TerminateProcess,3_2_00C514CB
Source: C:\Users\user\AppData\Local\Temp\ucngw.exeCode function: 3_2_00C51A54 IsProcessorFeaturePresent,IsDebuggerPresent,SetUnhandledExceptionFilter,UnhandledExceptionFilter,3_2_00C51A54
Source: C:\Users\user\AppData\Local\Temp\ucngw.exeCode function: 3_2_10001795 IsProcessorFeaturePresent,IsDebuggerPresent,SetUnhandledExceptionFilter,UnhandledExceptionFilter,3_2_10001795
Source: C:\Users\user\AppData\Local\Temp\ucngw.exeCode function: 3_2_1000662D IsDebuggerPresent,SetUnhandledExceptionFilter,UnhandledExceptionFilter,3_2_1000662D
Source: C:\Users\user\AppData\Local\Temp\ucngw.exeCode function: 3_2_10001B37 SetUnhandledExceptionFilter,UnhandledExceptionFilter,GetCurrentProcess,TerminateProcess,3_2_10001B37
Source: C:\Users\user\AppData\Local\Temp\_usm.exeCode function: 4_2_001417EA IsDebuggerPresent,SetUnhandledExceptionFilter,UnhandledExceptionFilter,GetCurrentProcess,TerminateProcess,4_2_001417EA
Source: C:\Users\user\AppData\Local\Temp\_usm.exeCode function: 4_2_0014333B IsDebuggerPresent,SetUnhandledExceptionFilter,UnhandledExceptionFilter,4_2_0014333B
Checks for kernel debuggers (NtQuerySystemInformation(SystemKernelDebuggerInformation))Show sources
Source: C:\Users\user\Desktop\winlogon.exeSystem information queried: KernelDebuggerInformation
Contains functionality to check if a debugger is running (IsDebuggerPresent)Show sources
Source: C:\Users\user\Desktop\winlogon.exeCode function: 1_2_00D6B406 IsProcessorFeaturePresent,IsDebuggerPresent,SetUnhandledExceptionFilter,UnhandledExceptionFilter,1_2_00D6B406
Contains functionality to dynamically determine API callsShow sources
Source: C:\Users\user\Desktop\winlogon.exeCode function: 1_2_00D643A0 GetVersionExW,LoadLibraryW,GetProcAddress,SHGetKnownFolderPath,1_2_00D643A0
Contains functionality to read the PEBShow sources
Source: C:\Users\user\Desktop\winlogon.exeCode function: 1_2_00D70D28 mov eax, dword ptr fs:[00000030h]1_2_00D70D28
Source: C:\Users\user\AppData\Local\Temp\yegus.exeCode function: 2_2_01337F59 mov eax, dword ptr fs:[00000030h]2_2_01337F59
Source: C:\Users\user\AppData\Local\Temp\yegus.exeCode function: 2_2_10085756 mov eax, dword ptr fs:[00000030h]2_2_10085756
Source: C:\Users\user\AppData\Local\Temp\ucngw.exeCode function: 3_2_00C558EB mov eax, dword ptr fs:[00000030h]3_2_00C558EB
Source: C:\Users\user\AppData\Local\Temp\ucngw.exeCode function: 3_2_100051BB mov eax, dword ptr fs:[00000030h]3_2_100051BB
Contains functionality which may be used to detect a debugger (GetProcessHeap)Show sources
Source: C:\Users\user\Desktop\winlogon.exeCode function: 1_2_00D6A6F0 GetProcessHeap,RtlAllocateHeap,1_2_00D6A6F0
Enables debug privilegesShow sources
Source: C:\Users\user\AppData\Local\Temp\ucngw.exeProcess token adjusted: Debug

Malware Analysis System Evasion:

barindex
Contains functionality to enumerate / list files inside a directoryShow sources
Source: C:\Users\user\Desktop\winlogon.exeCode function: 1_2_00D75F8F FindFirstFileExW,1_2_00D75F8F
Source: C:\Users\user\AppData\Local\Temp\yegus.exeCode function: 2_2_01339A82 FindFirstFileExW,2_2_01339A82
Source: C:\Users\user\AppData\Local\Temp\yegus.exeCode function: 2_2_10088620 FindFirstFileExA,2_2_10088620
Source: C:\Users\user\AppData\Local\Temp\ucngw.exeCode function: 3_2_00C5850A FindFirstFileExW,3_2_00C5850A
Source: C:\Users\user\AppData\Local\Temp\ucngw.exeCode function: 3_2_10008EEC FindFirstFileExA,3_2_10008EEC
Source: C:\Users\user\AppData\Local\Temp\_usm.exeCode function: 4_2_00141441 wsprintfW,FindFirstFileW,GetProcessHeap,PathAppendW,GetProcessHeap,HeapAlloc,PathAppendW,PathAppendW,StrCmpCW,StrCmpCW,StrCmpCW,CreateFileW,GetFileSizeEx,CloseHandle,GetProcessHeap,HeapFree,FindNextFileW,FindClose,4_2_00141441
Contains functionality to query system informationShow sources
Source: C:\Users\user\AppData\Local\Temp\yegus.exeCode function: 2_2_1000D3F0 GetSystemInfo,2_2_1000D3F0
May try to detect the virtual machine to hinder analysis (VM artifact strings found in memory)Show sources
Source: wbadmin.exeBinary or memory string: Cluster service, and Hyper-V for more information.
Source: wbadmin.exeBinary or memory string: An error occurred while preparing to back up Hyper-V data.
Program exit pointsShow sources
Source: C:\Users\user\AppData\Local\Temp\_usm.exeAPI call chain: ExitProcess graph end node
Queries a list of all running processesShow sources
Source: C:\Users\user\AppData\Local\Temp\ucngw.exeProcess information queried: ProcessInformation
Contains functionality to enumerate running servicesShow sources
Source: C:\Users\user\AppData\Local\Temp\_usm.exeCode function: OpenSCManagerW,EnumServicesStatusW,EnumServicesStatusW,GetProcessHeap,GetProcessHeap,RtlAllocateHeap,EnumServicesStatusW,QueryServiceConfigW,OpenServiceW,QueryServiceConfigW,GetProcessHeap,HeapAlloc,ChangeServiceConfigW,QueryServiceConfigW,PathRemoveArgsW,GetProcessHeap,HeapFree,GetLastError,CloseServiceHandle,GetProcessHeap,HeapFree,CloseServiceHandle,4_2_001412E8
Contains long sleeps (>= 3 min)Show sources
Source: C:\Users\user\AppData\Local\Temp\_usm.exeThread delayed: delay time: 3600000
Found dropped PE file which has not been started or loadedShow sources
Source: C:\Users\user\Desktop\winlogon.exeDropped PE file which has not been started: C:\Users\HERBBL~1\AppData\Local\Temp\_yig.exe
Source: C:\Users\user\Desktop\winlogon.exeDropped PE file which has not been started: C:\Users\HERBBL~1\AppData\Local\Temp\_wjg.exe
Found evasive API chain (may stop execution after checking a module file name)Show sources
Source: C:\Users\user\AppData\Local\Temp\_usm.exeEvasive API call chain: GetModuleFileName,DecisionNodes,Sleep
Source: C:\Users\user\AppData\Local\Temp\_usm.exeEvasive API call chain: GetModuleFileName,DecisionNodes,ExitProcess
Found evasive API chain checking for process token informationShow sources
Source: C:\Users\user\AppData\Local\Temp\yegus.exeCheck user administrative privileges: GetTokenInformation,DecisionNodes
Source: C:\Users\user\Desktop\winlogon.exeCheck user administrative privileges: GetTokenInformation,DecisionNodesgraph_1-13588
Source: C:\Users\user\AppData\Local\Temp\ucngw.exeCheck user administrative privileges: GetTokenInformation,DecisionNodes
May sleep (evasive loops) to hinder dynamic analysisShow sources
Source: C:\Users\user\Desktop\winlogon.exe TID: 3392Thread sleep time: -60000s >= -60000s
Source: C:\Users\user\AppData\Local\Temp\yegus.exe TID: 3268Thread sleep time: -120000s >= -60000s
Source: C:\Users\user\AppData\Local\Temp\_usm.exe TID: 3300Thread sleep time: -3600000s >= -60000s
Source: C:\Windows\System32\wbadmin.exe TID: 3460Thread sleep time: -120000s >= -60000s
Source: C:\Windows\System32\wbadmin.exe TID: 3460Thread sleep time: -60000s >= -60000s
Source: C:\Windows\System32\wbengine.exe TID: 3492Thread sleep count: 89 > 30
Source: C:\Windows\System32\wbengine.exe TID: 3492Thread sleep time: -5340000s >= -60000s
Source: C:\Windows\System32\vdsldr.exe TID: 3520Thread sleep count: 57 > 30
Source: C:\Windows\System32\vdsldr.exe TID: 3520Thread sleep time: -3420000s >= -60000s
Source: C:\Windows\System32\vdsldr.exe TID: 3520Thread sleep time: -60000s >= -60000s
Source: C:\Windows\System32\vds.exe TID: 3548Thread sleep count: 81 > 30
Source: C:\Windows\System32\vds.exe TID: 3548Thread sleep time: -4860000s >= -60000s
Sample execution stops while process was sleeping (likely an evasion)Show sources
Source: C:\Windows\System32\vdsldr.exeLast function: Thread delayed

Hooking and other Techniques for Hiding and Protection:

barindex
Disables application error messsages (SetErrorMode)Show sources
Source: C:\Users\user\Desktop\winlogon.exeProcess information set: NOOPENFILEERRORBOX
Source: C:\Users\user\Desktop\winlogon.exeProcess information set: NOOPENFILEERRORBOX
Source: C:\Users\user\Desktop\winlogon.exeProcess information set: NOOPENFILEERRORBOX
Source: C:\Users\user\Desktop\winlogon.exeProcess information set: NOOPENFILEERRORBOX
Source: C:\Users\user\Desktop\winlogon.exeProcess information set: NOOPENFILEERRORBOX
Source: C:\Users\user\Desktop\winlogon.exeProcess information set: NOOPENFILEERRORBOX
Source: C:\Users\user\Desktop\winlogon.exeProcess information set: NOOPENFILEERRORBOX
Source: C:\Users\user\Desktop\winlogon.exeProcess information set: NOOPENFILEERRORBOX
Source: C:\Users\user\Desktop\winlogon.exeProcess information set: NOOPENFILEERRORBOX
Source: C:\Windows\System32\cmd.exeProcess information set: NOOPENFILEERRORBOX
Source: C:\Windows\System32\cmd.exeProcess information set: NOOPENFILEERRORBOX
Source: C:\Windows\System32\cmd.exeProcess information set: NOOPENFILEERRORBOX
Source: C:\Windows\System32\cmd.exeProcess information set: NOOPENFILEERRORBOX
Source: C:\Windows\System32\cmd.exeProcess information set: NOOPENFILEERRORBOX
Source: C:\Windows\System32\cmd.exeProcess information set: NOOPENFILEERRORBOX
Source: C:\Windows\System32\cmd.exeProcess information set: NOOPENFILEERRORBOX
Source: C:\Windows\System32\cmd.exeProcess information set: NOOPENFILEERRORBOX
Source: C:\Windows\System32\cmd.exeProcess information set: NOOPENFILEERRORBOX
Creates files inside the volume driver (system volume information)Show sources
Source: C:\Windows\System32\wbengine.exeFile created: C:\System Volume Information\WindowsImageBackup

Language, Device and Operating System Detection:

barindex
Contains functionality to create pipes for IPCShow sources
Source: C:\Users\user\Desktop\winlogon.exeCode function: 1_2_00D634B0 wsprintfW,CreateNamedPipeW,CreateEventW,CloseHandle,ConnectNamedPipe,GetLastError,CloseHandle,CloseHandle,CloseHandle,WaitForSingleObject,GetOverlappedResult,CancelIo,CloseHandle,ReadFile,CloseHandle,1_2_00D634B0
Contains functionality to query local / system timeShow sources
Source: C:\Users\user\Desktop\winlogon.exeCode function: 1_2_00D74EF7 GetSystemTimeAsFileTime,1_2_00D74EF7
Contains functionality to query time zone informationShow sources
Source: C:\Users\user\AppData\Local\Temp\yegus.exeCode function: 2_2_100879B6 GetTimeZoneInformation,WideCharToMultiByte,WideCharToMultiByte,2_2_100879B6
Contains functionality to query windows versionShow sources
Source: C:\Users\user\Desktop\winlogon.exeCode function: 1_2_00D65970 GetVersionExW,__Stoull,__Stoull,1_2_00D65970
Queries the cryptographic machine GUIDShow sources
Source: C:\Users\user\Desktop\winlogon.exeKey value queried: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Cryptography MachineGuid
Contains functionality to query CPU information (cpuid)Show sources
Source: C:\Users\user\Desktop\winlogon.exeCode function: 1_2_00D6B6CE cpuid 1_2_00D6B6CE
Queries the volume information (name, serial number etc) of a deviceShow sources
Source: C:\Users\user\AppData\Local\Temp\yegus.exeQueries volume information: C:\Users\user\AppData\Roaming\Mozilla\Firefox\Profiles\4ah7hlda.default\secmod.db VolumeInformation
Source: C:\Users\user\AppData\Local\Temp\yegus.exeQueries volume information: C:\ VolumeInformation
Source: C:\Users\user\AppData\Local\Temp\yegus.exeQueries volume information: C:\Users\user\AppData\Roaming\Mozilla\Firefox\Profiles\4ah7hlda.default\cert8.db VolumeInformation
Source: C:\Users\user\AppData\Local\Temp\yegus.exeQueries volume information: C:\Users\user\AppData\Roaming\Mozilla\Firefox\Profiles\4ah7hlda.default\key3.db VolumeInformation
Source: C:\Windows\System32\cmd.exeQueries volume information: C:\ VolumeInformation

Behavior Graph

Hide Legend

Legend:

  • Process
  • Signature
  • Created File
  • DNS/IP Info
  • Is Dropped
  • Is Windows Process
  • Number of created Registry Values
  • Number of created Files
  • Visual Basic
  • Delphi
  • Java
  • .Net C# or VB.NET
  • C, C++ or other language
  • Is malicious
behaviorgraph top1 dnsIp2 2 Behavior Graph ID: 46216 Sample: winlogon.exe Startdate: 12/02/2018 Architecture: WINDOWS Score: 100 56 252.0.0.224.in-addr.arpa 2->56 64 Antivirus detection for dropped file 2->64 66 Antivirus detection for submitted file 2->66 68 May disable shadow drive data (uses vssadmin) 2->68 72 3 other signatures 2->72 9 winlogon.exe 8 2->9         started        14 wbengine.exe 2 2->14         started        16 vdsldr.exe 2->16         started        18 3 other processes 2->18 signatures3 70 Tries to resolve many domain names, but no domain seems valid 56->70 process4 dnsIp5 58 8.8.8.8, 49408, 50225, 51075 GOOGLE-GoogleIncUS United States 9->58 60 192.168.2.238, 135 unknown unknown 9->60 62 8 other IPs or domains 9->62 48 C:\Users\HERBBL~1\AppData\Local\...\_usm.exe, PE32 9->48 dropped 50 C:\Users\HERBBL~1\AppData\Local\...\yegus.exe, PE32 9->50 dropped 52 C:\Users\HERBBL~1\AppData\Local\...\ucngw.exe, PE32 9->52 dropped 54 2 other files (none is malicious) 9->54 dropped 88 Contains functionality to inject threads in other processes 9->88 90 Contains functionality to inject code into remote processes 9->90 20 _usm.exe 9->20         started        22 yegus.exe 11 9->22         started        25 ucngw.exe 9->25         started        92 Creates files inside the volume driver (system volume information) 14->92 file6 94 Tries to resolve many domain names, but no domain seems valid 58->94 signatures7 process8 signatures9 27 cmd.exe 20->27         started        30 cmd.exe 20->30         started        32 cmd.exe 20->32         started        34 2 other processes 20->34 74 Contains functionality to steal Internet Explorer form passwords 22->74 76 Contains functionality to steal Chrome passwords 22->76 78 Tries to harvest and steal browser information (history, passwords, etc) 22->78 80 Contains functionality to dump credential hashes (LSA Dump) 25->80 process10 signatures11 82 May disable shadow drive data (uses vssadmin) 27->82 84 Deletes shadow drive data (may be related to ransomware) 27->84 36 vssadmin.exe 27->36         started        86 Uses bcdedit to modify the Windows boot settings 30->86 38 bcdedit.exe 1 30->38         started        40 bcdedit.exe 30->40         started        42 wbadmin.exe 2 32->42         started        44 wevtutil.exe 34->44         started        46 wevtutil.exe 34->46         started        process12

Simulations

Behavior and APIs

No simulations

Antivirus Detection

Initial Sample

SourceDetectionCloudLink
winlogon.exe62%virustotalBrowse

Dropped Files

SourceDetectionCloudLink
C:\Users\HERBBL~1\AppData\Local\Temp\_usm.exe60%virustotalBrowse
C:\Users\HERBBL~1\AppData\Local\Temp\_wjg.exe0%virustotalBrowse
C:\Users\HERBBL~1\AppData\Local\Temp\_wjg.exe3%metadefenderBrowse

Domains

SourceDetectionCloudLink
252.0.0.224.in-addr.arpa0%virustotalBrowse

Yara Overview

Initial Sample

No yara matches

PCAP (Network Traffic)

No yara matches

Dropped Files

No yara matches

Memory Dumps

No yara matches

Unpacked PEs

No yara matches

Joe Sandbox View / Context

IPs

No context

Domains

No context

ASN

No context

Dropped Files

No context

Screenshot

windows-stand

Startup

  • System is w7
  • winlogon.exe (PID: 3216 cmdline: 'C:\Users\user\Desktop\winlogon.exe' MD5: CFDD16225E67471F5EF54CAB9B3A5558)
    • yegus.exe (PID: 3232 cmdline: 123 \\.\pipe\122B85FE-84BD-45AB-AEE5-28D37FB4C464 MD5: 4F43F03783F9789F804DCF9B9474FA6D)
    • ucngw.exe (PID: 3280 cmdline: 123 \\.\pipe\33F83B68-FC3D-4C1F-B4AE-1329770D367B MD5: 6E0EBEEEA1CB00192B074B288A4F9CFE)
    • _usm.exe (PID: 3296 cmdline: C:\Users\HERBBL~1\AppData\Local\Temp\_usm.exe MD5: 3C0D740347B0362331C882C2DEE96DBF)
      • cmd.exe (PID: 3336 cmdline: C:\Windows\system32\cmd.exe /c c:\Windows\system32\vssadmin.exe delete shadows /all /quiet MD5: AD7B9C14083B52BC532FBA5948342B98)
        • vssadmin.exe (PID: 3372 cmdline: c:\Windows\system32\vssadmin.exe delete shadows /all /quiet MD5: 6E248A3D528EDE43994457CF417BD665)
      • cmd.exe (PID: 3404 cmdline: C:\Windows\system32\cmd.exe /c wbadmin.exe delete catalog -quiet MD5: AD7B9C14083B52BC532FBA5948342B98)
        • wbadmin.exe (PID: 3428 cmdline: wbadmin.exe delete catalog -quiet MD5: EAB630E7E6A7FC248870A2FCDC098B98)
      • cmd.exe (PID: 3668 cmdline: C:\Windows\system32\cmd.exe /c bcdedit.exe /set {default} bootstatuspolicy ignoreallfailures & bcdedit /set {default} recoveryenabled no MD5: AD7B9C14083B52BC532FBA5948342B98)
        • bcdedit.exe (PID: 3692 cmdline: bcdedit.exe /set {default} bootstatuspolicy ignoreallfailures MD5: ABD373E82F6240031C1E631AA20711C7)
        • bcdedit.exe (PID: 3700 cmdline: bcdedit /set {default} recoveryenabled no MD5: ABD373E82F6240031C1E631AA20711C7)
      • cmd.exe (PID: 3708 cmdline: C:\Windows\system32\cmd.exe /c wevtutil.exe cl System MD5: AD7B9C14083B52BC532FBA5948342B98)
        • wevtutil.exe (PID: 3732 cmdline: wevtutil.exe cl System MD5: 81538B795F922B8DA6FD897EFB04B5EE)
      • cmd.exe (PID: 3748 cmdline: C:\Windows\system32\cmd.exe /c wevtutil.exe cl Security MD5: AD7B9C14083B52BC532FBA5948342B98)
        • wevtutil.exe (PID: 3772 cmdline: wevtutil.exe cl Security MD5: 81538B795F922B8DA6FD897EFB04B5EE)
  • wbengine.exe (PID: 3464 cmdline: C:\Windows\system32\wbengine.exe MD5: 691E3285E53DCA558E1A84667F13E15A)
  • vdsldr.exe (PID: 3496 cmdline: C:\Windows\System32\vdsldr.exe -Embedding MD5: A2551668C78CEA4089D71A0A3B36FC0C)
  • vds.exe (PID: 3524 cmdline: C:\Windows\System32\vds.exe MD5: C3CD30495687C2A2F66A65CA6FD89BE9)
  • LogonUI.exe (PID: 3840 cmdline: 'LogonUI.exe' /flags:0x0 MD5: 3EF0D8AB08385AAB5802E773511A2E6A)
  • LogonUI.exe (PID: 3928 cmdline: unknown MD5: 3EF0D8AB08385AAB5802E773511A2E6A)
  • cleanup

Created / dropped Files

C:\Users\HERBBL~1\AppData\Local\Temp\_usm.exe
File Type:PE32 executable (GUI) Intel 80386, for MS Windows
Size (bytes):36864
Entropy (8bit):5.891300526858096
Encrypted:false
MD5:3C0D740347B0362331C882C2DEE96DBF
SHA1:8350E06F52E5C660BB416B03EDB6A5DDC50C3A59
SHA-256:AE9A4E244A9B3C77D489DEE8AEAF35A7C3BA31B210E76D81EF2E91790F052C85
SHA-512:A701F94B9CDEBCE6EFF2F82552EC7554BF10D99019F8BCD6871EBCA804D7519BDCFA3806AC7C7D8E604C3259C61C58B905293FA641C092A8FCA8245F91EB0F8F
Malicious:true
Antivirus:
  • Antivirus: virustotal, Detection: 60%, Browse
Reputation:low
C:\Users\HERBBL~1\AppData\Local\Temp\_wjg.exe
File Type:PE32 executable (console) Intel 80386, for MS Windows
Size (bytes):339096
Entropy (8bit):6.384232735880303
Encrypted:false
MD5:27304B246C7D5B4E149124D5F93C5B01
SHA1:E50D9E3BD91908E13A26B3E23EDEAF577FB3A095
SHA-256:3337E3875B05E0BFBA69AB926532E3F179E8CFBF162EBB60CE58A0281437A7EF
SHA-512:BEC172A2F92A95796199CFC83F544A78685B52A94061CE0FFB46B265070EE0BCC018C4F548F56018BF3FF1E74952811B2AFB6DF79AB8D09F1EC73C9477AF636B
Malicious:false
Antivirus:
  • Antivirus: virustotal, Detection: 0%, Browse
  • Antivirus: metadefender, Detection: 3%, Browse
Reputation:low
C:\Users\HERBBL~1\AppData\Local\Temp\_yig.exe
File Type:PE32 executable (GUI) Intel 80386, for MS Windows
Size (bytes):3723264
Entropy (8bit):7.9213131085726545
Encrypted:false
MD5:56E50AD3D0746E4A4B1458506DACF2E7
SHA1:0B818B27FD4C1656F43B288C29C510F0BABF939A
SHA-256:131BA113ED14E999275B0CC7C932277EF7CA944888F928EE8DB50333420CA3BC
SHA-512:69FE8FC3039C5503D15C8AE77E9B4D4DFA457D2DBF52289B6A5FBB83278713EA3AF63246F64E74B021BE6A7C67E2089702FC97F3EFD4C349CFEB5C44CA57BC04
Malicious:false
Reputation:low
C:\Users\HERBBL~1\AppData\Local\Temp\_yig.exe:Zone.Identifier
File Type:ASCII text, with CRLF line terminators
Size (bytes):26
Entropy (8bit):3.9500637564362093
Encrypted:false
MD5:187F488E27DB4AF347237FE461A079AD
SHA1:6693BA299EC1881249D59262276A0D2CB21F8E64
SHA-256:255A65D30841AB4082BD9D0EEA79D49C5EE88F56136157D8D6156AEF11C12309
SHA-512:89879F237C0C051EBE784D0690657A6827A312A82735DA42DAD5F744D734FC545BEC9642C19D14C05B2F01FF53BC731530C92F7327BB7DC9CDE1B60FB21CD64E
Malicious:false
Reputation:high, very likely benign file
C:\Users\HERBBL~1\AppData\Local\Temp\chr9AAC.tmp
File Type:SQLite 3.x database
Size (bytes):18432
Entropy (8bit):0.8481809040173017
Encrypted:false
MD5:727EB3BA54F16CB4C7C19AB1101B8802
SHA1:8702933960447F3FB8423E9F9F8FEF2C23D6B7AB
SHA-256:255F5314D835CBDC33B46216B083C3FA4DD7F61B27F48B539B41341EF0911423
SHA-512:FB079623312587E70AE2263FFCC9C12C492332CE6D048A85DD1B32C15535A6CF8E9D67AE146D01862B1C50B297EED0A07042AC19A4FC8838E534BCFEBFC77BE2
Malicious:false
Reputation:moderate, very likely benign file
C:\Users\HERBBL~1\AppData\Local\Temp\ucngw.exe
File Type:PE32 executable (GUI) Intel 80386, for MS Windows
Size (bytes):231424
Entropy (8bit):7.52549984722154
Encrypted:false
MD5:6E0EBEEEA1CB00192B074B288A4F9CFE
SHA1:21CA710ED3BC536BD5394F0BFF6D6140809156CF
SHA-256:A52AF66A4438C5517870C503AC1E0515AF44D3994AA62C7D818B6EEF46CFBB2D
SHA-512:BBB24AAC7EF5B5E8CF8934666D02C1E51980DB3C4703FEC1F240BAE35E1C8517E19736D8F2E27A9ED77D8A6881C2C3A5A3653E66425E7058B2985063FC38949C
Malicious:false
Reputation:low
C:\Users\HERBBL~1\AppData\Local\Temp\yegus.exe
File Type:PE32 executable (GUI) Intel 80386, for MS Windows
Size (bytes):769536
Entropy (8bit):7.930796192224973
Encrypted:false
MD5:4F43F03783F9789F804DCF9B9474FA6D
SHA1:492D4A4A74099074E26B5DFFD0D15434009CCFD9
SHA-256:19AB44A1343DB19741B0E0B06BACCE55990B6C8F789815DAAF3476E0CC30EBEA
SHA-512:645C2F0A1342732B86A45403FB8B1343BCC18C015C9918D2EDF118BBB210FEAD98AA21F1B66AC5FAABD0542583D74E158FBAC6D5F0D49827F4EEB58C8EBAFD6D
Malicious:false
Reputation:low
\122B85FE-84BD-45AB-AEE5-28D37FB4C464
File Type:data
Size (bytes):12
Entropy (8bit):2.125814583693911
Encrypted:false
MD5:177C7293D42D1C9C48678AB79D034F1E
SHA1:C828BAEF11CC61FC91D29D00AB980FBBA9A3BD42
SHA-256:7E1246792C8DFE9E1F254115344159F0A800EBD273F678E7036F10FCAC0CD377
SHA-512:DF3A4FCBDB220FDD26301A5B4DF68A15CB6DE5D748C86E1E340268D3F7C0384323E7A792DFBE8BADB1523339994CFFFEE1E94D7C64557DD47546C466B559D557
Malicious:false
\33F83B68-FC3D-4C1F-B4AE-1329770D367B
File Type:empty
Size (bytes):0
Entropy (8bit):0.0
Encrypted:false
MD5:D41D8CD98F00B204E9800998ECF8427E
SHA1:DA39A3EE5E6B4B0D3255BFEF95601890AFD80709
SHA-256:E3B0C44298FC1C149AFBF4C8996FB92427AE41E4649B934CA495991B7852B855
SHA-512:CF83E1357EEFB8BDF1542850D66D8007D620E4050B5715DC83F4A921D36CE9CE47D0D13C5D85F2B0FF8318D2877EEC2F63B931BD47417A81A538327AF927DA3E
Malicious:false

Contacted Domains/Contacted IPs

Contacted Domains

NameIPActiveMaliciousAntivirus Detection
252.0.0.224.in-addr.arpaunknownunknowntrue0%, virustotal, Browse

Contacted IPs

  • No. of IPs < 25%
  • 25% < No. of IPs < 50%
  • 50% < No. of IPs < 75%
  • 75% < No. of IPs
IPCountryFlagASNASN NameMalicious
192.168.2.238unknown
unknownunknownfalse
192.168.2.240unknown
unknownunknownfalse
192.168.2.250unknown
unknownunknownfalse
192.168.2.252unknown
unknownunknownfalse
192.168.2.244unknown
unknownunknownfalse
8.8.8.8United States
15169GOOGLE-GoogleIncUSfalse
192.168.2.254unknown
unknownunknownfalse
192.168.2.242unknown
unknownunknownfalse
192.168.2.248unknown
unknownunknownfalse
192.168.2.246unknown
unknownunknownfalse

Static File Info

General

File type:PE32 executable (GUI) Intel 80386, for MS Windows
Entropy (8bit):7.9213131085726545
TrID:
  • Win32 Executable (generic) a (10002005/4) 99.96%
  • Generic Win/DOS Executable (2004/3) 0.02%
  • DOS Executable Generic (2002/1) 0.02%
  • Autodesk FLIC Image File (extensions: flc, fli, cel) (7/3) 0.00%
File name:winlogon.exe
File size:1861632
MD5:cfdd16225e67471f5ef54cab9b3a5558
SHA1:26de43cc558a4e0e60eddd4dc9321bcb5a0a181c
SHA256:edb1ff2521fb4bf748111f92786d260d40407a2e8463dcd24bb09f908ee13eb9
SHA512:e1855a872f4db7c17eb22130d9cb205eddde641f1b39ea5de97dfb762fc97dc2347bc6e6e88b9c5a303e1540b4b4bdb19c839c7d3e237348adbfa4b942f24adb
File Content Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$..........;E..hE..hE..h.._hO..h..]h...h..\h]..h.6ihD..h~..iQ..h~..ii..h~..iV..hL.-hF..hL.=hP..hE..h...h...iV..h..QhD..hE.9hD..h...iD..

File Icon

Static PE Info

General

Entrypoint:0x40ae66
Entrypoint Section:.text
Digitally signed:false
Imagebase:0x400000
Subsystem:windows gui
Image File Characteristics:32BIT_MACHINE, EXECUTABLE_IMAGE
DLL Characteristics:TERMINAL_SERVER_AWARE, DYNAMIC_BASE, NX_COMPAT
Time Stamp:0x5A4387AF [Wed Dec 27 11:44:47 2017 UTC]
TLS Callbacks:
CLR (.Net) Version:
OS Version Major:5
OS Version Minor:1
File Version Major:5
File Version Minor:1
Subsystem Version Major:5
Subsystem Version Minor:1
Import Hash:975087e9286238a80895b195efb3968d

Entrypoint Preview

Instruction
call 00007FC5206B76CFh
jmp 00007FC5206B70D3h
push ebp
mov ebp, esp
push 00000000h
call dword ptr [0041F188h]
push dword ptr [ebp+08h]
call dword ptr [0041F184h]
push C0000409h
call dword ptr [0041F124h]
push eax
call dword ptr [0041F114h]
pop ebp
ret
push ebp
mov ebp, esp
sub esp, 00000324h
push 00000017h
call 00007FC5206C98A3h
test eax, eax
je 00007FC5206B7247h
push 00000002h
pop ecx
int 29h
mov dword ptr [00430CC8h], eax
mov dword ptr [00430CC4h], ecx
mov dword ptr [00430CC0h], edx
mov dword ptr [00430CBCh], ebx
mov dword ptr [00430CB8h], esi
mov dword ptr [00430CB4h], edi
mov word ptr [00430CE0h], ss
mov word ptr [00430CD4h], cs
mov word ptr [00430CB0h], ds
mov word ptr [00430CACh], es
mov word ptr [00430CA8h], fs
mov word ptr [00430CA4h], gs
pushfd
pop dword ptr [00430CD8h]
mov eax, dword ptr [ebp+00h]
mov dword ptr [00430CCCh], eax
mov eax, dword ptr [ebp+04h]
mov dword ptr [00430CD0h], eax
lea eax, dword ptr [ebp+08h]
mov dword ptr [00430CDCh], eax
mov eax, dword ptr [ebp-00000324h]
mov dword ptr [00430C18h], 00010001h

Data Directories

NameVirtual AddressVirtual Size Is in Section
IMAGE_DIRECTORY_ENTRY_EXPORT0x00x0
IMAGE_DIRECTORY_ENTRY_IMPORT0x26df40xdc.rdata
IMAGE_DIRECTORY_ENTRY_RESOURCE0x330000x195b88.rsrc
IMAGE_DIRECTORY_ENTRY_EXCEPTION0x00x0
IMAGE_DIRECTORY_ENTRY_SECURITY0x00x0
IMAGE_DIRECTORY_ENTRY_BASERELOC0x1c90000x1644.reloc
IMAGE_DIRECTORY_ENTRY_DEBUG0x25df00x38.rdata
IMAGE_DIRECTORY_ENTRY_COPYRIGHT0x00x0
IMAGE_DIRECTORY_ENTRY_GLOBALPTR0x00x0
IMAGE_DIRECTORY_ENTRY_TLS0x00x0
IMAGE_DIRECTORY_ENTRY_LOAD_CONFIG0x25e280x40.rdata
IMAGE_DIRECTORY_ENTRY_BOUND_IMPORT0x00x0
IMAGE_DIRECTORY_ENTRY_IAT0x1f0000x278.rdata
IMAGE_DIRECTORY_ENTRY_DELAY_IMPORT0x00x0
IMAGE_DIRECTORY_ENTRY_COM_DESCRIPTOR0x00x0
IMAGE_DIRECTORY_ENTRY_RESERVED0x00x0

Sections

NameVirtual AddressVirtual SizeRaw SizeXored PEZLIB ComplexityFile TypeEntropyCharacteristics
.text0x10000x1d4ac0x1d600False0.573720079787data6.65423641734IMAGE_SCN_MEM_EXECUTE, IMAGE_SCN_CNT_CODE, IMAGE_SCN_MEM_READ
.rdata0x1f0000x8bac0x8c00False0.497879464286data5.462837397IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_READ
.data0x280000x96fc0x8c00False0.0412109375data0.885300140538IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_WRITE, IMAGE_SCN_MEM_READ
.gfids0x320000x1340x200False0.3984375data2.38182890346IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_READ
.rsrc0x330000x195b880x195c00False1.00009145872data7.99984549743IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_READ
.reloc0x1c90000x16440x1800False0.766927083333data6.4041746291IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_DISCARDABLE, IMAGE_SCN_MEM_READ

Resources

NameRVASizeTypeLanguageCountry
BIN0x331700xbbe00dataEnglishUnited States
BIN0xeef700x38800dataEnglishUnited States
BIN0x1277700x45600dataEnglishUnited States
BIN0x16cd700x52c98dataEnglishUnited States
BIN0x1bfa080x9000dataEnglishUnited States
RT_MANIFEST0x1c8a080x17dXML 1.0 document textEnglishUnited States

Imports

DLLImport
KERNEL32.dllGetVersionExW, GetModuleHandleA, CreateEventW, MultiByteToWideChar, Sleep, GetTempPathA, CopyFileA, GetLastError, GetFileAttributesA, CreateFileA, SetEvent, TerminateThread, DeleteFileW, CloseHandle, LoadLibraryW, CreateThread, GetOverlappedResult, VirtualProtectEx, GetWindowsDirectoryW, GetProcAddress, VirtualAllocEx, LocalFree, GetFileSize, DeleteCriticalSection, ExitProcess, GetCurrentProcessId, CreateProcessW, GetModuleHandleW, CreateRemoteThread, CreateProcessA, CreateEventA, ConnectNamedPipe, GetComputerNameA, GetFileAttributesW, HeapFree, HeapAlloc, GetProcessHeap, GetTempPathW, GetTickCount, SizeofResource, LockResource, LoadResource, FindResourceW, FindFirstFileExW, CreateFileW, LocalAlloc, WaitForSingleObject, InitializeCriticalSection, LeaveCriticalSection, WaitForMultipleObjects, CreateNamedPipeW, GetModuleFileNameW, TerminateProcess, InterlockedDecrement, WriteFile, ReadFile, GetCurrentProcess, GetCommandLineW, EnterCriticalSection, WriteProcessMemory, CancelIo, FindClose, DecodePointer, SetEndOfFile, HeapSize, WriteConsoleW, FlushFileBuffers, GetStringTypeW, SetStdHandle, ReadConsoleW, SetFilePointerEx, GetModuleFileNameA, FreeLibrary, FreeEnvironmentStringsW, GetEnvironmentStringsW, GetCommandLineA, GetCPInfo, GetOEMCP, IsValidCodePage, LCMapStringW, UnhandledExceptionFilter, SetUnhandledExceptionFilter, IsProcessorFeaturePresent, QueryPerformanceCounter, GetCurrentThreadId, GetSystemTimeAsFileTime, InitializeSListHead, IsDebuggerPresent, GetStartupInfoW, WideCharToMultiByte, EncodePointer, RaiseException, RtlUnwind, SetLastError, InitializeCriticalSectionAndSpinCount, TlsAlloc, TlsGetValue, TlsSetValue, TlsFree, LoadLibraryExW, GetStdHandle, GetModuleHandleExW, GetACP, HeapReAlloc, GetConsoleCP, GetConsoleMode, GetFileType, FindNextFileW
USER32.dllwsprintfW
ADVAPI32.dllCryptAcquireContextW, CryptReleaseContext, LookupPrivilegeValueW, AdjustTokenPrivileges, CryptGenRandom, LookupPrivilegeNameW, CopySid, IsValidSid, LogonUserA, OpenProcessToken, ConvertSidToStringSidW, GetLengthSid, LookupAccountSidW, GetTokenInformation
SHELL32.dllSHGetSpecialFolderPathW, CommandLineToArgvW
ole32.dllCoCreateGuid, CoTaskMemFree, CoSetProxyBlanket, CoInitializeEx, CoInitializeSecurity, CoCreateInstance, CoUninitialize
OLEAUT32.dllSysFreeString, SysAllocString, SysStringLen, SafeArrayUnaccessData, SafeArrayAccessData, VariantClear, SafeArrayCreate
IPHLPAPI.DLLGetIpNetTable
WS2_32.dllFreeAddrInfoW, GetAddrInfoW, WSACleanup, WSAStartup, ntohl
credui.dllCredUIParseUserNameW
NETAPI32.dllNetApiBufferFree, NetGetDCName

Possible Origin

Language of compilation systemCountry where language is spokenMap
EnglishUnited States

Network Behavior

Network Port Distribution

TCP Packets

TimestampSource PortDest PortSource IPDest IP
Feb 12, 2018 21:38:30.860141993 CET5684253192.168.2.28.8.8.8
Feb 12, 2018 21:38:30.880199909 CET5344053192.168.2.28.8.8.8
Feb 12, 2018 21:38:30.880276918 CET53534408.8.8.8192.168.2.2
Feb 12, 2018 21:38:30.905082941 CET5107553192.168.2.28.8.8.8
Feb 12, 2018 21:38:30.905164003 CET53510758.8.8.8192.168.2.2
Feb 12, 2018 21:38:30.927845955 CET6305353192.168.2.28.8.8.8
Feb 12, 2018 21:38:30.927926064 CET53630538.8.8.8192.168.2.2
Feb 12, 2018 21:38:30.995573997 CET6549053192.168.2.28.8.8.8
Feb 12, 2018 21:38:30.995654106 CET53654908.8.8.8192.168.2.2
Feb 12, 2018 21:38:31.002337933 CET6531153192.168.2.28.8.8.8
Feb 12, 2018 21:38:31.002427101 CET53653118.8.8.8192.168.2.2
Feb 12, 2018 21:38:31.012367010 CET5919553192.168.2.28.8.8.8
Feb 12, 2018 21:38:31.012440920 CET53591958.8.8.8192.168.2.2
Feb 12, 2018 21:38:31.036601067 CET6503453192.168.2.28.8.8.8
Feb 12, 2018 21:38:31.036674976 CET53650348.8.8.8192.168.2.2
Feb 12, 2018 21:38:31.050959110 CET5635253192.168.2.28.8.8.8
Feb 12, 2018 21:38:31.051029921 CET53563528.8.8.8192.168.2.2
Feb 12, 2018 21:38:31.059361935 CET5149253192.168.2.28.8.8.8
Feb 12, 2018 21:38:31.059423923 CET53514928.8.8.8192.168.2.2
Feb 12, 2018 21:38:31.765642881 CET53568428.8.8.8192.168.2.2
Feb 12, 2018 21:38:32.179327011 CET6523653192.168.2.28.8.8.8
Feb 12, 2018 21:38:32.311522007 CET53652368.8.8.8192.168.2.2
Feb 12, 2018 21:38:32.616265059 CET5717853192.168.2.28.8.8.8
Feb 12, 2018 21:38:32.753743887 CET53571788.8.8.8192.168.2.2
Feb 12, 2018 21:38:33.061160088 CET4940853192.168.2.28.8.8.8
Feb 12, 2018 21:38:33.179438114 CET53494088.8.8.8192.168.2.2
Feb 12, 2018 21:38:33.513441086 CET5729153192.168.2.28.8.8.8
Feb 12, 2018 21:38:33.718898058 CET53572918.8.8.8192.168.2.2
Feb 12, 2018 21:38:34.032504082 CET6422553192.168.2.28.8.8.8
Feb 12, 2018 21:38:34.168128967 CET53642258.8.8.8192.168.2.2
Feb 12, 2018 21:38:34.497317076 CET6401753192.168.2.28.8.8.8
Feb 12, 2018 21:38:34.668488026 CET53640178.8.8.8192.168.2.2
Feb 12, 2018 21:38:34.980822086 CET6157853192.168.2.28.8.8.8
Feb 12, 2018 21:38:35.109461069 CET53615788.8.8.8192.168.2.2
Feb 12, 2018 21:38:35.419275999 CET6480853192.168.2.28.8.8.8
Feb 12, 2018 21:38:35.682538033 CET53648088.8.8.8192.168.2.2
Feb 12, 2018 21:38:35.696975946 CET49169135192.168.2.2192.168.2.254
Feb 12, 2018 21:38:35.823093891 CET49170135192.168.2.2192.168.2.246
Feb 12, 2018 21:38:35.824702978 CET49171135192.168.2.2192.168.2.252
Feb 12, 2018 21:38:35.826517105 CET49172135192.168.2.2192.168.2.248
Feb 12, 2018 21:38:35.827938080 CET49173135192.168.2.2192.168.2.250
Feb 12, 2018 21:38:35.835345030 CET49174135192.168.2.2192.168.2.244
Feb 12, 2018 21:38:35.895308971 CET49175135192.168.2.2192.168.2.240
Feb 12, 2018 21:38:35.896699905 CET49176135192.168.2.2192.168.2.238
Feb 12, 2018 21:38:35.903877974 CET49177135192.168.2.2192.168.2.242
Feb 12, 2018 21:38:36.022747993 CET6353553192.168.2.28.8.8.8
Feb 12, 2018 21:38:36.172410011 CET53635358.8.8.8192.168.2.2
Feb 12, 2018 21:38:36.489626884 CET6411753192.168.2.28.8.8.8
Feb 12, 2018 21:38:36.696399927 CET53641178.8.8.8192.168.2.2
Feb 12, 2018 21:38:37.006269932 CET5512053192.168.2.28.8.8.8
Feb 12, 2018 21:38:37.137315989 CET53551208.8.8.8192.168.2.2
Feb 12, 2018 21:38:37.452662945 CET5896253192.168.2.28.8.8.8
Feb 12, 2018 21:38:37.739259005 CET53589628.8.8.8192.168.2.2
Feb 12, 2018 21:38:38.052788973 CET5022553192.168.2.28.8.8.8
Feb 12, 2018 21:38:38.164005041 CET53502258.8.8.8192.168.2.2
Feb 12, 2018 21:38:38.479089022 CET6027853192.168.2.28.8.8.8
Feb 12, 2018 21:38:38.696377039 CET49169135192.168.2.2192.168.2.254
Feb 12, 2018 21:38:38.718569040 CET53602788.8.8.8192.168.2.2
Feb 12, 2018 21:38:38.880198002 CET49170135192.168.2.2192.168.2.246
Feb 12, 2018 21:38:38.880208969 CET49171135192.168.2.2192.168.2.252
Feb 12, 2018 21:38:38.880218029 CET49172135192.168.2.2192.168.2.248
Feb 12, 2018 21:38:38.880224943 CET49173135192.168.2.2192.168.2.250
Feb 12, 2018 21:38:38.880234003 CET49174135192.168.2.2192.168.2.244
Feb 12, 2018 21:38:38.916991949 CET49175135192.168.2.2192.168.2.240
Feb 12, 2018 21:38:38.917016983 CET49176135192.168.2.2192.168.2.238
Feb 12, 2018 21:38:38.917036057 CET49177135192.168.2.2192.168.2.242
Feb 12, 2018 21:38:39.026475906 CET5521653192.168.2.28.8.8.8
Feb 12, 2018 21:38:39.156883001 CET53552168.8.8.8192.168.2.2
Feb 12, 2018 21:38:39.511333942 CET5695153192.168.2.28.8.8.8
Feb 12, 2018 21:38:39.673909903 CET53569518.8.8.8192.168.2.2
Feb 12, 2018 21:38:39.979579926 CET6205153192.168.2.28.8.8.8
Feb 12, 2018 21:38:40.080379009 CET53620518.8.8.8192.168.2.2
Feb 12, 2018 21:38:40.392570972 CET6104353192.168.2.28.8.8.8
Feb 12, 2018 21:38:40.572628021 CET53610438.8.8.8192.168.2.2
Feb 12, 2018 21:38:40.883240938 CET6439553192.168.2.28.8.8.8
Feb 12, 2018 21:38:41.035156965 CET53643958.8.8.8192.168.2.2
Feb 12, 2018 21:38:41.355576038 CET5741653192.168.2.28.8.8.8
Feb 12, 2018 21:38:41.578322887 CET53574168.8.8.8192.168.2.2
Feb 12, 2018 21:38:41.888006926 CET5526853192.168.2.28.8.8.8
Feb 12, 2018 21:38:42.034862995 CET53552688.8.8.8192.168.2.2
Feb 12, 2018 21:38:42.338536024 CET6506553192.168.2.28.8.8.8
Feb 12, 2018 21:38:42.437918901 CET53650658.8.8.8192.168.2.2
Feb 12, 2018 21:38:42.756555080 CET5340953192.168.2.28.8.8.8
Feb 12, 2018 21:38:42.868976116 CET53534098.8.8.8192.168.2.2
Feb 12, 2018 21:38:43.488595009 CET6188153192.168.2.28.8.8.8
Feb 12, 2018 21:38:43.676775932 CET53618818.8.8.8192.168.2.2
Feb 12, 2018 21:38:44.000485897 CET5398853192.168.2.28.8.8.8
Feb 12, 2018 21:38:44.106827974 CET53539888.8.8.8192.168.2.2
Feb 12, 2018 21:38:44.427696943 CET5565453192.168.2.28.8.8.8
Feb 12, 2018 21:38:44.625426054 CET53556548.8.8.8192.168.2.2
Feb 12, 2018 21:38:44.714911938 CET49169135192.168.2.2192.168.2.254
Feb 12, 2018 21:38:44.915150881 CET49170135192.168.2.2192.168.2.246
Feb 12, 2018 21:38:44.915175915 CET49171135192.168.2.2192.168.2.252
Feb 12, 2018 21:38:44.915184975 CET49172135192.168.2.2192.168.2.248
Feb 12, 2018 21:38:44.915193081 CET49173135192.168.2.2192.168.2.250
Feb 12, 2018 21:38:44.915199995 CET49174135192.168.2.2192.168.2.244
Feb 12, 2018 21:38:44.915205956 CET49175135192.168.2.2192.168.2.240
Feb 12, 2018 21:38:44.915213108 CET49176135192.168.2.2192.168.2.238
Feb 12, 2018 21:38:44.915226936 CET49177135192.168.2.2192.168.2.242
Feb 12, 2018 21:38:44.953222990 CET5453453192.168.2.28.8.8.8
Feb 12, 2018 21:38:45.142456055 CET53545348.8.8.8192.168.2.2
Feb 12, 2018 21:38:45.473556995 CET5120653192.168.2.28.8.8.8
Feb 12, 2018 21:38:45.779345989 CET53512068.8.8.8192.168.2.2
Feb 12, 2018 21:38:46.084404945 CET5489453192.168.2.28.8.8.8
Feb 12, 2018 21:38:46.238379002 CET53548948.8.8.8192.168.2.2
Feb 12, 2018 21:38:46.544713020 CET6011153192.168.2.28.8.8.8
Feb 12, 2018 21:38:46.779881954 CET53601118.8.8.8192.168.2.2

UDP Packets

TimestampSource PortDest PortSource IPDest IP
Feb 12, 2018 21:38:30.860141993 CET5684253192.168.2.28.8.8.8
Feb 12, 2018 21:38:30.880199909 CET5344053192.168.2.28.8.8.8
Feb 12, 2018 21:38:30.880276918 CET53534408.8.8.8192.168.2.2
Feb 12, 2018 21:38:30.905082941 CET5107553192.168.2.28.8.8.8
Feb 12, 2018 21:38:30.905164003 CET53510758.8.8.8192.168.2.2
Feb 12, 2018 21:38:30.927845955 CET6305353192.168.2.28.8.8.8
Feb 12, 2018 21:38:30.927926064 CET53630538.8.8.8192.168.2.2
Feb 12, 2018 21:38:30.995573997 CET6549053192.168.2.28.8.8.8
Feb 12, 2018 21:38:30.995654106 CET53654908.8.8.8192.168.2.2
Feb 12, 2018 21:38:31.002337933 CET6531153192.168.2.28.8.8.8
Feb 12, 2018 21:38:31.002427101 CET53653118.8.8.8192.168.2.2
Feb 12, 2018 21:38:31.012367010 CET5919553192.168.2.28.8.8.8
Feb 12, 2018 21:38:31.012440920 CET53591958.8.8.8192.168.2.2
Feb 12, 2018 21:38:31.036601067 CET6503453192.168.2.28.8.8.8
Feb 12, 2018 21:38:31.036674976 CET53650348.8.8.8192.168.2.2
Feb 12, 2018 21:38:31.050959110 CET5635253192.168.2.28.8.8.8
Feb 12, 2018 21:38:31.051029921 CET53563528.8.8.8192.168.2.2
Feb 12, 2018 21:38:31.059361935 CET5149253192.168.2.28.8.8.8
Feb 12, 2018 21:38:31.059423923 CET53514928.8.8.8192.168.2.2
Feb 12, 2018 21:38:31.765642881 CET53568428.8.8.8192.168.2.2
Feb 12, 2018 21:38:32.179327011 CET6523653192.168.2.28.8.8.8
Feb 12, 2018 21:38:32.311522007 CET53652368.8.8.8192.168.2.2
Feb 12, 2018 21:38:32.616265059 CET5717853192.168.2.28.8.8.8
Feb 12, 2018 21:38:32.753743887 CET53571788.8.8.8192.168.2.2
Feb 12, 2018 21:38:33.061160088 CET4940853192.168.2.28.8.8.8
Feb 12, 2018 21:38:33.179438114 CET53494088.8.8.8192.168.2.2
Feb 12, 2018 21:38:33.513441086 CET5729153192.168.2.28.8.8.8
Feb 12, 2018 21:38:33.718898058 CET53572918.8.8.8192.168.2.2
Feb 12, 2018 21:38:34.032504082 CET6422553192.168.2.28.8.8.8
Feb 12, 2018 21:38:34.168128967 CET53642258.8.8.8192.168.2.2
Feb 12, 2018 21:38:34.497317076 CET6401753192.168.2.28.8.8.8
Feb 12, 2018 21:38:34.668488026 CET53640178.8.8.8192.168.2.2
Feb 12, 2018 21:38:34.980822086 CET6157853192.168.2.28.8.8.8
Feb 12, 2018 21:38:35.109461069 CET53615788.8.8.8192.168.2.2
Feb 12, 2018 21:38:35.419275999 CET6480853192.168.2.28.8.8.8
Feb 12, 2018 21:38:35.682538033 CET53648088.8.8.8192.168.2.2
Feb 12, 2018 21:38:36.022747993 CET6353553192.168.2.28.8.8.8
Feb 12, 2018 21:38:36.172410011 CET53635358.8.8.8192.168.2.2
Feb 12, 2018 21:38:36.489626884 CET6411753192.168.2.28.8.8.8
Feb 12, 2018 21:38:36.696399927 CET53641178.8.8.8192.168.2.2
Feb 12, 2018 21:38:37.006269932 CET5512053192.168.2.28.8.8.8
Feb 12, 2018 21:38:37.137315989 CET53551208.8.8.8192.168.2.2
Feb 12, 2018 21:38:37.452662945 CET5896253192.168.2.28.8.8.8
Feb 12, 2018 21:38:37.739259005 CET53589628.8.8.8192.168.2.2
Feb 12, 2018 21:38:38.052788973 CET5022553192.168.2.28.8.8.8
Feb 12, 2018 21:38:38.164005041 CET53502258.8.8.8192.168.2.2
Feb 12, 2018 21:38:38.479089022 CET6027853192.168.2.28.8.8.8
Feb 12, 2018 21:38:38.718569040 CET53602788.8.8.8192.168.2.2
Feb 12, 2018 21:38:39.026475906 CET5521653192.168.2.28.8.8.8
Feb 12, 2018 21:38:39.156883001 CET53552168.8.8.8192.168.2.2
Feb 12, 2018 21:38:39.511333942 CET5695153192.168.2.28.8.8.8
Feb 12, 2018 21:38:39.673909903 CET53569518.8.8.8192.168.2.2
Feb 12, 2018 21:38:39.979579926 CET6205153192.168.2.28.8.8.8
Feb 12, 2018 21:38:40.080379009 CET53620518.8.8.8192.168.2.2
Feb 12, 2018 21:38:40.392570972 CET6104353192.168.2.28.8.8.8
Feb 12, 2018 21:38:40.572628021 CET53610438.8.8.8192.168.2.2
Feb 12, 2018 21:38:40.883240938 CET6439553192.168.2.28.8.8.8
Feb 12, 2018 21:38:41.035156965 CET53643958.8.8.8192.168.2.2
Feb 12, 2018 21:38:41.355576038 CET5741653192.168.2.28.8.8.8
Feb 12, 2018 21:38:41.578322887 CET53574168.8.8.8192.168.2.2
Feb 12, 2018 21:38:41.888006926 CET5526853192.168.2.28.8.8.8
Feb 12, 2018 21:38:42.034862995 CET53552688.8.8.8192.168.2.2
Feb 12, 2018 21:38:42.338536024 CET6506553192.168.2.28.8.8.8
Feb 12, 2018 21:38:42.437918901 CET53650658.8.8.8192.168.2.2
Feb 12, 2018 21:38:42.756555080 CET5340953192.168.2.28.8.8.8
Feb 12, 2018 21:38:42.868976116 CET53534098.8.8.8192.168.2.2
Feb 12, 2018 21:38:43.488595009 CET6188153192.168.2.28.8.8.8
Feb 12, 2018 21:38:43.676775932 CET53618818.8.8.8192.168.2.2
Feb 12, 2018 21:38:44.000485897 CET5398853192.168.2.28.8.8.8
Feb 12, 2018 21:38:44.106827974 CET53539888.8.8.8192.168.2.2
Feb 12, 2018 21:38:44.427696943 CET5565453192.168.2.28.8.8.8
Feb 12, 2018 21:38:44.625426054 CET53556548.8.8.8192.168.2.2
Feb 12, 2018 21:38:44.953222990 CET5453453192.168.2.28.8.8.8
Feb 12, 2018 21:38:45.142456055 CET53545348.8.8.8192.168.2.2
Feb 12, 2018 21:38:45.473556995 CET5120653192.168.2.28.8.8.8
Feb 12, 2018 21:38:45.779345989 CET53512068.8.8.8192.168.2.2
Feb 12, 2018 21:38:46.084404945 CET5489453192.168.2.28.8.8.8
Feb 12, 2018 21:38:46.238379002 CET53548948.8.8.8192.168.2.2
Feb 12, 2018 21:38:46.544713020 CET6011153192.168.2.28.8.8.8
Feb 12, 2018 21:38:46.779881954 CET53601118.8.8.8192.168.2.2

DNS Queries

TimestampSource IPDest IPTrans IDOP CodeNameTypeClass
Feb 12, 2018 21:38:30.860141993 CET192.168.2.28.8.8.80xb7a7Standard query (0)252.0.0.224.in-addr.arpaPTR (Pointer record)IN (0x0001)
Feb 12, 2018 21:38:32.179327011 CET192.168.2.28.8.8.80xc3ddStandard query (0)252.0.0.224.in-addr.arpaPTR (Pointer record)IN (0x0001)
Feb 12, 2018 21:38:32.616265059 CET192.168.2.28.8.8.80x152Standard query (0)252.0.0.224.in-addr.arpaPTR (Pointer record)IN (0x0001)
Feb 12, 2018 21:38:33.061160088 CET192.168.2.28.8.8.80x26e4Standard query (0)252.0.0.224.in-addr.arpaPTR (Pointer record)IN (0x0001)
Feb 12, 2018 21:38:33.513441086 CET192.168.2.28.8.8.80xcd43Standard query (0)252.0.0.224.in-addr.arpaPTR (Pointer record)IN (0x0001)
Feb 12, 2018 21:38:34.032504082 CET192.168.2.28.8.8.80xc366Standard query (0)252.0.0.224.in-addr.arpaPTR (Pointer record)IN (0x0001)
Feb 12, 2018 21:38:34.497317076 CET192.168.2.28.8.8.80xd809Standard query (0)252.0.0.224.in-addr.arpaPTR (Pointer record)IN (0x0001)
Feb 12, 2018 21:38:34.980822086 CET192.168.2.28.8.8.80xfb5Standard query (0)252.0.0.224.in-addr.arpaPTR (Pointer record)IN (0x0001)
Feb 12, 2018 21:38:35.419275999 CET192.168.2.28.8.8.80xcd9fStandard query (0)252.0.0.224.in-addr.arpaPTR (Pointer record)IN (0x0001)
Feb 12, 2018 21:38:36.022747993 CET192.168.2.28.8.8.80x8b9dStandard query (0)252.0.0.224.in-addr.arpaPTR (Pointer record)IN (0x0001)
Feb 12, 2018 21:38:36.489626884 CET192.168.2.28.8.8.80xaa99Standard query (0)252.0.0.224.in-addr.arpaPTR (Pointer record)IN (0x0001)
Feb 12, 2018 21:38:37.006269932 CET192.168.2.28.8.8.80x2ad9Standard query (0)252.0.0.224.in-addr.arpaPTR (Pointer record)IN (0x0001)
Feb 12, 2018 21:38:37.452662945 CET192.168.2.28.8.8.80x9754Standard query (0)252.0.0.224.in-addr.arpaPTR (Pointer record)IN (0x0001)
Feb 12, 2018 21:38:38.052788973 CET192.168.2.28.8.8.80x9aa7Standard query (0)252.0.0.224.in-addr.arpaPTR (Pointer record)IN (0x0001)
Feb 12, 2018 21:38:38.479089022 CET192.168.2.28.8.8.80x4024Standard query (0)252.0.0.224.in-addr.arpaPTR (Pointer record)IN (0x0001)
Feb 12, 2018 21:38:39.026475906 CET192.168.2.28.8.8.80x7ffStandard query (0)252.0.0.224.in-addr.arpaPTR (Pointer record)IN (0x0001)
Feb 12, 2018 21:38:39.511333942 CET192.168.2.28.8.8.80x3298Standard query (0)252.0.0.224.in-addr.arpaPTR (Pointer record)IN (0x0001)
Feb 12, 2018 21:38:39.979579926 CET192.168.2.28.8.8.80x2c13Standard query (0)252.0.0.224.in-addr.arpaPTR (Pointer record)IN (0x0001)
Feb 12, 2018 21:38:40.392570972 CET192.168.2.28.8.8.80xf3f5Standard query (0)252.0.0.224.in-addr.arpaPTR (Pointer record)IN (0x0001)
Feb 12, 2018 21:38:40.883240938 CET192.168.2.28.8.8.80x1fa9Standard query (0)252.0.0.224.in-addr.arpaPTR (Pointer record)IN (0x0001)
Feb 12, 2018 21:38:41.355576038 CET192.168.2.28.8.8.80x715fStandard query (0)252.0.0.224.in-addr.arpaPTR (Pointer record)IN (0x0001)
Feb 12, 2018 21:38:41.888006926 CET192.168.2.28.8.8.80x948eStandard query (0)252.0.0.224.in-addr.arpaPTR (Pointer record)IN (0x0001)
Feb 12, 2018 21:38:42.338536024 CET192.168.2.28.8.8.80x4034Standard query (0)252.0.0.224.in-addr.arpaPTR (Pointer record)IN (0x0001)
Feb 12, 2018 21:38:42.756555080 CET192.168.2.28.8.8.80xde3eStandard query (0)252.0.0.224.in-addr.arpaPTR (Pointer record)IN (0x0001)
Feb 12, 2018 21:38:43.488595009 CET192.168.2.28.8.8.80xc681Standard query (0)252.0.0.224.in-addr.arpaPTR (Pointer record)IN (0x0001)
Feb 12, 2018 21:38:44.000485897 CET192.168.2.28.8.8.80xee4cStandard query (0)252.0.0.224.in-addr.arpaPTR (Pointer record)IN (0x0001)
Feb 12, 2018 21:38:44.427696943 CET192.168.2.28.8.8.80xb3faStandard query (0)252.0.0.224.in-addr.arpaPTR (Pointer record)IN (0x0001)
Feb 12, 2018 21:38:44.953222990 CET192.168.2.28.8.8.80x10f7Standard query (0)252.0.0.224.in-addr.arpaPTR (Pointer record)IN (0x0001)
Feb 12, 2018 21:38:45.473556995 CET192.168.2.28.8.8.80xfd81Standard query (0)252.0.0.224.in-addr.arpaPTR (Pointer record)IN (0x0001)
Feb 12, 2018 21:38:46.084404945 CET192.168.2.28.8.8.80xc169Standard query (0)252.0.0.224.in-addr.arpaPTR (Pointer record)IN (0x0001)
Feb 12, 2018 21:38:46.544713020 CET192.168.2.28.8.8.80xad00Standard query (0)252.0.0.224.in-addr.arpaPTR (Pointer record)IN (0x0001)

DNS Answers

TimestampSource IPDest IPTrans IDReplay CodeNameCNameAddressTypeClass
Feb 12, 2018 21:38:31.765642881 CET8.8.8.8192.168.2.20xb7a7Name error (3)252.0.0.224.in-addr.arpanonenonePTR (Pointer record)IN (0x0001)
Feb 12, 2018 21:38:32.311522007 CET8.8.8.8192.168.2.20xc3ddName error (3)252.0.0.224.in-addr.arpanonenonePTR (Pointer record)IN (0x0001)
Feb 12, 2018 21:38:32.753743887 CET8.8.8.8192.168.2.20x152Name error (3)252.0.0.224.in-addr.arpanonenonePTR (Pointer record)IN (0x0001)
Feb 12, 2018 21:38:33.179438114 CET8.8.8.8192.168.2.20x26e4Name error (3)252.0.0.224.in-addr.arpanonenonePTR (Pointer record)IN (0x0001)
Feb 12, 2018 21:38:33.718898058 CET8.8.8.8192.168.2.20xcd43Name error (3)252.0.0.224.in-addr.arpanonenonePTR (Pointer record)IN (0x0001)
Feb 12, 2018 21:38:34.168128967 CET8.8.8.8192.168.2.20xc366Name error (3)252.0.0.224.in-addr.arpanonenonePTR (Pointer record)IN (0x0001)
Feb 12, 2018 21:38:34.668488026 CET8.8.8.8192.168.2.20xd809Name error (3)252.0.0.224.in-addr.arpanonenonePTR (Pointer record)IN (0x0001)
Feb 12, 2018 21:38:35.109461069 CET8.8.8.8192.168.2.20xfb5Name error (3)252.0.0.224.in-addr.arpanonenonePTR (Pointer record)IN (0x0001)
Feb 12, 2018 21:38:35.682538033 CET8.8.8.8192.168.2.20xcd9fName error (3)252.0.0.224.in-addr.arpanonenonePTR (Pointer record)IN (0x0001)
Feb 12, 2018 21:38:36.172410011 CET8.8.8.8192.168.2.20x8b9dName error (3)252.0.0.224.in-addr.arpanonenonePTR (Pointer record)IN (0x0001)
Feb 12, 2018 21:38:36.696399927 CET8.8.8.8192.168.2.20xaa99Name error (3)252.0.0.224.in-addr.arpanonenonePTR (Pointer record)IN (0x0001)
Feb 12, 2018 21:38:37.137315989 CET8.8.8.8192.168.2.20x2ad9Name error (3)252.0.0.224.in-addr.arpanonenonePTR (Pointer record)IN (0x0001)
Feb 12, 2018 21:38:37.739259005 CET8.8.8.8192.168.2.20x9754Name error (3)252.0.0.224.in-addr.arpanonenonePTR (Pointer record)IN (0x0001)
Feb 12, 2018 21:38:38.164005041 CET8.8.8.8192.168.2.20x9aa7Name error (3)252.0.0.224.in-addr.arpanonenonePTR (Pointer record)IN (0x0001)
Feb 12, 2018 21:38:38.718569040 CET8.8.8.8192.168.2.20x4024Name error (3)252.0.0.224.in-addr.arpanonenonePTR (Pointer record)IN (0x0001)
Feb 12, 2018 21:38:39.156883001 CET8.8.8.8192.168.2.20x7ffName error (3)252.0.0.224.in-addr.arpanonenonePTR (Pointer record)IN (0x0001)
Feb 12, 2018 21:38:39.673909903 CET8.8.8.8192.168.2.20x3298Name error (3)252.0.0.224.in-addr.arpanonenonePTR (Pointer record)IN (0x0001)
Feb 12, 2018 21:38:40.080379009 CET8.8.8.8192.168.2.20x2c13Name error (3)252.0.0.224.in-addr.arpanonenonePTR (Pointer record)IN (0x0001)
Feb 12, 2018 21:38:40.572628021 CET8.8.8.8192.168.2.20xf3f5Name error (3)252.0.0.224.in-addr.arpanonenonePTR (Pointer record)IN (0x0001)
Feb 12, 2018 21:38:41.035156965 CET8.8.8.8192.168.2.20x1fa9Name error (3)252.0.0.224.in-addr.arpanonenonePTR (Pointer record)IN (0x0001)
Feb 12, 2018 21:38:41.578322887 CET8.8.8.8192.168.2.20x715fName error (3)252.0.0.224.in-addr.arpanonenonePTR (Pointer record)IN (0x0001)
Feb 12, 2018 21:38:42.034862995 CET8.8.8.8192.168.2.20x948eName error (3)252.0.0.224.in-addr.arpanonenonePTR (Pointer record)IN (0x0001)
Feb 12, 2018 21:38:42.437918901 CET8.8.8.8192.168.2.20x4034Name error (3)252.0.0.224.in-addr.arpanonenonePTR (Pointer record)IN (0x0001)
Feb 12, 2018 21:38:42.868976116 CET8.8.8.8192.168.2.20xde3eName error (3)252.0.0.224.in-addr.arpanonenonePTR (Pointer record)IN (0x0001)
Feb 12, 2018 21:38:43.676775932 CET8.8.8.8192.168.2.20xc681Name error (3)252.0.0.224.in-addr.arpanonenonePTR (Pointer record)IN (0x0001)
Feb 12, 2018 21:38:44.106827974 CET8.8.8.8192.168.2.20xee4cName error (3)252.0.0.224.in-addr.arpanonenonePTR (Pointer record)IN (0x0001)
Feb 12, 2018 21:38:44.625426054 CET8.8.8.8192.168.2.20xb3faName error (3)252.0.0.224.in-addr.arpanonenonePTR (Pointer record)IN (0x0001)
Feb 12, 2018 21:38:45.142456055 CET8.8.8.8192.168.2.20x10f7Name error (3)252.0.0.224.in-addr.arpanonenonePTR (Pointer record)IN (0x0001)
Feb 12, 2018 21:38:45.779345989 CET8.8.8.8192.168.2.20xfd81Name error (3)252.0.0.224.in-addr.arpanonenonePTR (Pointer record)IN (0x0001)
Feb 12, 2018 21:38:46.238379002 CET8.8.8.8192.168.2.20xc169Name error (3)252.0.0.224.in-addr.arpanonenonePTR (Pointer record)IN (0x0001)
Feb 12, 2018 21:38:46.779881954 CET8.8.8.8192.168.2.20xad00Name error (3)252.0.0.224.in-addr.arpanonenonePTR (Pointer record)IN (0x0001)

Code Manipulations

Statistics

CPU Usage

Click to jump to process

Memory Usage

Click to jump to process

High Level Behavior Distribution

Click to dive into process behavior distribution

Behavior

Click to jump to process

System Behavior

General

Start time:21:38:46
Start date:12/02/2018
Path:C:\Users\user\Desktop\winlogon.exe
Wow64 process (32bit):false
Commandline:'C:\Users\user\Desktop\winlogon.exe'
Imagebase:0xd60000
File size:1861632 bytes
MD5 hash:CFDD16225E67471F5EF54CAB9B3A5558
Programmed in:C, C++ or other language
Reputation:low

General

Start time:21:38:46
Start date:12/02/2018
Path:C:\Users\user\AppData\Local\Temp\yegus.exe
Wow64 process (32bit):false
Commandline: 123 \\.\pipe\122B85FE-84BD-45AB-AEE5-28D37FB4C464
Imagebase:0x1330000
File size:769536 bytes
MD5 hash:4F43F03783F9789F804DCF9B9474FA6D
Programmed in:C, C++ or other language
Reputation:low

General

Start time:21:38:47
Start date:12/02/2018
Path:C:\Users\user\AppData\Local\Temp\ucngw.exe
Wow64 process (32bit):false
Commandline: 123 \\.\pipe\33F83B68-FC3D-4C1F-B4AE-1329770D367B
Imagebase:0xc50000
File size:231424 bytes
MD5 hash:6E0EBEEEA1CB00192B074B288A4F9CFE
Programmed in:C, C++ or other language
Reputation:low

General

Start time:21:38:49
Start date:12/02/2018
Path:C:\Users\user\AppData\Local\Temp\_usm.exe
Wow64 process (32bit):false
Commandline:C:\Users\HERBBL~1\AppData\Local\Temp\_usm.exe
Imagebase:0x140000
File size:36864 bytes
MD5 hash:3C0D740347B0362331C882C2DEE96DBF
Programmed in:C, C++ or other language
Reputation:low

General

Start time:21:38:49
Start date:12/02/2018
Path:C:\Windows\System32\cmd.exe
Wow64 process (32bit):false
Commandline:C:\Windows\system32\cmd.exe /c c:\Windows\system32\vssadmin.exe delete shadows /all /quiet
Imagebase:0x4a9e0000
File size:302592 bytes
MD5 hash:AD7B9C14083B52BC532FBA5948342B98
Programmed in:C, C++ or other language
Reputation:high

General

Start time:21:38:50
Start date:12/02/2018
Path:C:\Windows\System32\vssadmin.exe
Wow64 process (32bit):false
Commandline:c:\Windows\system32\vssadmin.exe delete shadows /all /quiet
Imagebase:0x6e0000
File size:115200 bytes
MD5 hash:6E248A3D528EDE43994457CF417BD665
Programmed in:C, C++ or other language
Reputation:moderate

General

Start time:21:38:51
Start date:12/02/2018
Path:C:\Windows\System32\cmd.exe
Wow64 process (32bit):false
Commandline:C:\Windows\system32\cmd.exe /c wbadmin.exe delete catalog -quiet
Imagebase:0x4a0d0000
File size:302592 bytes
MD5 hash:AD7B9C14083B52BC532FBA5948342B98
Programmed in:C, C++ or other language
Reputation:high

General

Start time:21:38:52
Start date:12/02/2018
Path:C:\Windows\System32\wbadmin.exe
Wow64 process (32bit):false
Commandline:wbadmin.exe delete catalog -quiet
Imagebase:0x670000
File size:224768 bytes
MD5 hash:EAB630E7E6A7FC248870A2FCDC098B98
Programmed in:C, C++ or other language
Reputation:moderate

General

Start time:21:38:52
Start date:12/02/2018
Path:C:\Windows\System32\wbengine.exe
Wow64 process (32bit):false
Commandline:C:\Windows\system32\wbengine.exe
Imagebase:0xbf0000
File size:1203200 bytes
MD5 hash:691E3285E53DCA558E1A84667F13E15A
Programmed in:C, C++ or other language
Reputation:low

General

Start time:21:38:52
Start date:12/02/2018
Path:C:\Windows\System32\vdsldr.exe
Wow64 process (32bit):false
Commandline:C:\Windows\System32\vdsldr.exe -Embedding
Imagebase:0x3b0000
File size:19968 bytes
MD5 hash:A2551668C78CEA4089D71A0A3B36FC0C
Programmed in:C, C++ or other language
Reputation:low

General

Start time:21:38:53
Start date:12/02/2018
Path:C:\Windows\System32\vds.exe
Wow64 process (32bit):false
Commandline:C:\Windows\System32\vds.exe
Imagebase:0xac0000
File size:453632 bytes
MD5 hash:C3CD30495687C2A2F66A65CA6FD89BE9
Programmed in:C, C++ or other language
Reputation:moderate

General

Start time:21:38:55
Start date:12/02/2018
Path:C:\Windows\System32\cmd.exe
Wow64 process (32bit):false
Commandline:C:\Windows\system32\cmd.exe /c bcdedit.exe /set {default} bootstatuspolicy ignoreallfailures & bcdedit /set {default} recoveryenabled no
Imagebase:0x4a460000
File size:302592 bytes
MD5 hash:AD7B9C14083B52BC532FBA5948342B98
Programmed in:C, C++ or other language
Reputation:high

General

Start time:21:38:55
Start date:12/02/2018
Path:C:\Windows\System32\bcdedit.exe
Wow64 process (32bit):false
Commandline:bcdedit.exe /set {default} bootstatuspolicy ignoreallfailures
Imagebase:0x5b0000
File size:295936 bytes
MD5 hash:ABD373E82F6240031C1E631AA20711C7
Programmed in:C, C++ or other language
Reputation:moderate

General

Start time:21:38:56
Start date:12/02/2018
Path:C:\Windows\System32\bcdedit.exe
Wow64 process (32bit):false
Commandline:bcdedit /set {default} recoveryenabled no
Imagebase:0xcf0000
File size:295936 bytes
MD5 hash:ABD373E82F6240031C1E631AA20711C7
Programmed in:C, C++ or other language
Reputation:moderate

General

Start time:21:38:57
Start date:12/02/2018
Path:C:\Windows\System32\cmd.exe
Wow64 process (32bit):false
Commandline:C:\Windows\system32\cmd.exe /c wevtutil.exe cl System
Imagebase:0x4a640000
File size:302592 bytes
MD5 hash:AD7B9C14083B52BC532FBA5948342B98
Programmed in:C, C++ or other language
Reputation:high

General

Start time:21:38:58
Start date:12/02/2018
Path:C:\Windows\System32\wevtutil.exe
Wow64 process (32bit):false
Commandline:wevtutil.exe cl System
Imagebase:0x100000
File size:175616 bytes
MD5 hash:81538B795F922B8DA6FD897EFB04B5EE
Programmed in:C, C++ or other language
Reputation:low

General

Start time:21:38:59
Start date:12/02/2018
Path:C:\Windows\System32\cmd.exe
Wow64 process (32bit):false
Commandline:C:\Windows\system32\cmd.exe /c wevtutil.exe cl Security
Imagebase:0x4a0d0000
File size:302592 bytes
MD5 hash:AD7B9C14083B52BC532FBA5948342B98
Programmed in:C, C++ or other language
Reputation:high

General

Start time:21:39:00
Start date:12/02/2018
Path:C:\Windows\System32\wevtutil.exe
Wow64 process (32bit):false
Commandline:wevtutil.exe cl Security
Imagebase:0x4a0000
File size:175616 bytes
MD5 hash:81538B795F922B8DA6FD897EFB04B5EE
Programmed in:C, C++ or other language
Reputation:low

General

Start time:21:39:04
Start date:12/02/2018
Path:C:\Windows\System32\LogonUI.exe
Wow64 process (32bit):false
Commandline:'LogonUI.exe' /flags:0x0
Imagebase:0xcc0000
File size:10752 bytes
MD5 hash:3EF0D8AB08385AAB5802E773511A2E6A
Programmed in:C, C++ or other language
Reputation:moderate

General

Start time:21:39:06
Start date:12/02/2018
Path:C:\Windows\System32\LogonUI.exe
Wow64 process (32bit):false
Commandline:unknown
Imagebase:0xcc0000
File size:10752 bytes
MD5 hash:3EF0D8AB08385AAB5802E773511A2E6A
Programmed in:C, C++ or other language
Reputation:moderate

Disassembly

Code Analysis

Reset < >