Spyware Injector
FormBook XLoader Mal/HTMLGen-A
Created on 2024-09-05T16:00:31+00:00
0nazQxrt5MZ5BRK.exe
Remarks (1/1)
(0x0200000E): The overall sleep time of all monitored processes was truncated from "3 hours, 20 minutes, 54 seconds" to "5 seconds" to reveal dormant functionality.
Remarks
(0x0200005D): 84 additional dumps with the reason "Content Changed" and a total of 128 MB were skipped because the respective maximum limit was reached.
This list contains only the embedded files, downloaded files, and dropped files
Filters: |
There are no files for this filter
There are no files in this analysis
File Name | Category | Type | Verdict | Actions |
---|
C:\Users\RDhJ0CNFevzX\Desktop\0nazQxrt5MZ5BRK.exe | Sample File | Binary |
Malicious
|
...
|
Image Base | 0x00400000 |
Entry Point | 0x004AA67E |
Size Of Code | 0x000A9400 |
Size Of Initialized Data | 0x00017400 |
File Type | IMAGE_FILE_EXECUTABLE_IMAGE |
Subsystem | IMAGE_SUBSYSTEM_WINDOWS_GUI |
Machine Type | IMAGE_FILE_MACHINE_I386 |
Compile Timestamp | 2043-10-18 06:54 (UTC+2) |
Comments | - |
CompanyName | - |
FileDescription | Sachy_Obrazky |
FileVersion | 1.0.0.0 |
InternalName | OSJv.exe |
LegalCopyright | Copyright © 2020 |
LegalTrademarks | - |
OriginalFilename | OSJv.exe |
ProductName | Sachy_Obrazky |
ProductVersion | 1.0.0.0 |
Assembly Version | 1.0.0.0 |
Name | Virtual Address | Virtual Size | Raw Data Size | Raw Data Offset | Flags | Entropy |
---|---|---|---|---|---|---|
.text | 0x00402000 | 0x000A927C | 0x000A9400 | 0x00000200 | IMAGE_SCN_CNT_CODE, IMAGE_SCN_MEM_EXECUTE, IMAGE_SCN_MEM_READ | 7.9 |
.rsrc | 0x004AC000 | 0x000171BC | 0x00017200 | 0x000A9600 | IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_READ | 4.96 |
.reloc | 0x004C4000 | 0x0000000C | 0x00000200 | 0x000C0800 | IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_DISCARDABLE, IMAGE_SCN_MEM_READ | 0.1 |
API Name | Ordinal | IAT Address | Thunk RVA | Thunk Offset | Hint |
---|---|---|---|---|---|
_CorExeMain | - | 0x00402000 | 0x000AA651 | 0x000A8851 | 0x00000000 |
Name | Process ID | Start VA | End VA | Dump Reason | PE Rebuild | Bitness | Entry Point | YARA | Actions |
---|---|---|---|---|---|---|---|---|---|
0nazqxrt5mz5brk.exe | 1 | 0x00550000 | 0x00615FFF | Relevant Image | 32-bit | - |
...
|
||
buffer | 1 | 0x04850000 | 0x04861FFF | Reflectively Loaded .NET Assembly | 32-bit | - |
...
|
||
buffer | 1 | 0x06890000 | 0x068FFFFF | Reflectively Loaded .NET Assembly | 32-bit | - |
...
|
||
buffer | 3 | 0x00400000 | 0x0042EFFF | First Execution | 32-bit | 0x0041F150 |
...
|
||
0nazqxrt5mz5brk.exe | 3 | 0x00750000 | 0x00815FFF | Relevant Image | 32-bit | - |
...
|
||
0nazqxrt5mz5brk.exe | 1 | 0x00550000 | 0x00615FFF | Process Termination | 32-bit | - |
...
|
||
buffer | 3 | 0x00C80000 | 0x00F79FFF | First Execution | 32-bit | 0x00CF7000 |
...
|
||
buffer | 3 | 0x00B10000 | 0x00B23FFF | First Execution | 32-bit | 0x00B10000 |
...
|
||
buffer | 3 | 0x009B0000 | 0x00AE2FFF | Marked Executable | 32-bit | - |
...
|
||
buffer | 3 | 0x00400000 | 0x0042EFFF | Content Changed | 32-bit | 0x00419E8B |
...
|
||
buffer | 3 | 0x00400000 | 0x0042EFFF | Dump Rule: FormBookConfig | 32-bit | - |
...
|
||
buffer | 3 | 0x00400000 | 0x0042EFFF | Process Termination | 32-bit | - |
...
|
||
buffer | 3 | 0x00530000 | 0x0062FFFF | Process Termination | 32-bit | - |
...
|
||
buffer | 3 | 0x00AF0000 | 0x00B03FFF | Process Termination | 32-bit | - |
...
|
||
buffer | 3 | 0x00B10000 | 0x00B23FFF | Process Termination | 32-bit | - |
...
|
||
buffer | 3 | 0x00C80000 | 0x00F79FFF | Process Termination | 32-bit | - |
...
|
||
0nazqxrt5mz5brk.exe | 3 | 0x00750000 | 0x00815FFF | Process Termination | 32-bit | - |
...
|
||
buffer | 3 | 0x00830000 | 0x00836FFF | Image In Buffer | 32-bit | - |
...
|
||
buffer | 3 | 0x00960000 | 0x0098EFFF | Marked Executable | 32-bit | - |
...
|
||
buffer | 3 | 0x00B30000 | 0x00B5EFFF | Marked Executable | 32-bit | - |
...
|
\??\C:\Users\RDhJ0CNFevzX\AppData\Roaming\O61RB957\O61logim.jpeg | Dropped File | Image |
Clean
|
...
|
c:\users\rdhj0cnfevzx\appdata\roaming\o61rb957\o61logrc.ini | Dropped File | Stream |
Clean
|
...
|
c:\users\rdhj0cnfevzx\appdata\roaming\o61rb957\o61logrv.ini | Dropped File | Stream |
Clean
|
...
|
c:\users\rdhj0cnfevzx\appdata\roaming\o61rb957\o61logri.ini | Dropped File | Stream |
Clean
|
...
|
c:\users\rdhj0cnfevzx\appdata\roaming\o61rb957\o61log.ini | Dropped File | Empty |
Clean
|
...
|
7e45d17bff06e61d77132d4842b1202f6222a43cac3a4b1317b9829b1d2848e2 | Downloaded File | Text |
Clean
|
...
|
09b4fc1f3ef4d0ccdd3d1ab3ac8a0abecf986301b7973323e9a320a626305217 | Downloaded File | Text |
Clean
|
...
|
a365c4017aee2b1ee481935de5e3989b1abe1646bcf0070a0fefd9831d50b012 | Downloaded File | Text |
Clean
|
...
|
0ab05f76ee5623f821eb9cdac39ed95e5de5aeab699ea1f381eab07191e23e35 | Downloaded File | Text |
Clean
|
...
|
58ef91387ee40cc8f536592bdec40740e228d0e8d667d0359700f3ac9f69b55e | Downloaded File | Text |
Clean
|
...
|
eda6bbd0acc2ca6df8c7ced895195ea322d9583487662702c66b354b47b337f6 | Downloaded File | Text |
Clean
|
...
|
bc57a1307436a5bcfbdc8537175772d1dca2d2d0736039d4301e4b10125648d5 | Downloaded File | HTML |
Clean
|
...
|
URL | WHOIS Data | Reputation Status | Recursively Submitted | Actions |
---|---|---|---|---|
https://www.cloudflare.com/5xx-error-landing |
Show WHOIS
|
Not Available
|
- |
...
|
a25627d3ffc69b181df60978029de9f3a7d1dd98868901f6fb65494772b5be2b | Downloaded File | HTML |
Clean
|
...
|
URL | WHOIS Data | Reputation Status | Recursively Submitted | Actions |
---|---|---|---|---|
https://www.cloudflare.com/5xx-error-landing |
Show WHOIS
|
Not Available
|
- |
...
|
94c6499fc183bb13d8d3b7b96e88b0b9a8592753a63b50136537e94f9d7ecd2a | Downloaded File | HTML |
Clean
|
...
|
URL | WHOIS Data | Reputation Status | Recursively Submitted | Actions |
---|---|---|---|---|
https://www.cloudflare.com/5xx-error-landing |
Show WHOIS
|
Not Available
|
- |
...
|
fe1c81e54ad7016ba238e24aee5dd92356785892f5b5816e018540d5b6d43452 | Downloaded File | HTML |
Clean
|
...
|
URL | WHOIS Data | Reputation Status | Recursively Submitted | Actions |
---|---|---|---|---|
https://www.cloudflare.com/5xx-error-landing |
Show WHOIS
|
Not Available
|
- |
...
|
21aeac46efd57071a6dd767cca7fa01d094ba18f1b4d0e8212b9bb62126b3fc9 | Downloaded File | HTML |
Clean
|
...
|
URL | WHOIS Data | Reputation Status | Recursively Submitted | Actions |
---|---|---|---|---|
https://www.cloudflare.com/5xx-error-landing |
Show WHOIS
|
Not Available
|
- |
...
|
ff137fab366714260725f4ca8641caa97420170265d2c93a7643a9319a8e6c05 | Downloaded File | HTML |
Clean
|
...
|
URL | WHOIS Data | Reputation Status | Recursively Submitted | Actions |
---|---|---|---|---|
https://www.cloudflare.com/5xx-error-landing |
Show WHOIS
|
Not Available
|
- |
...
|
5c0244dfbd167480cc18128795f4f37c2f02aace6c3e60d34e324e4f8b587af7 | Downloaded File | Text |
Clean
|
...
|
51abc193f6aa4ca0dda5b2ce80998719d00cb4367cfdf9f3c13e7741d4bb25c4 | Downloaded File | Text |
Clean
|
...
|
22e235f422af3fa20dfdd19e1c8da0fd88130dffda0adcb2ab2f0a420e1fdfce | Downloaded File | Text |
Clean
|
...
|
920cbaba9c3521bf47ed3a8941ffb800824d8f430eacc58747931c7d2fce2c4b | Downloaded File | Text |
Clean
|
...
|
e398cb20566a1b01ea0cf68a16d462f153e0c16eb661ffc0f981b5b4949f1e40 | Downloaded File | Text |
Clean
|
...
|
39293302e7334b4dbc291f201149d0cc7f92ed0fbf1172b2955b6d6a50089ba6 | Downloaded File | Text |
Clean
|
...
|
4c13d452dd5d49671bd93ca32f2b4f85c78e39b6ab0ad1f38d98ed267f8fd896 | Downloaded File | HTML |
Clean
|
...
|
c4b07931b3fc37bc80d56a367783e7fa7c04ced4befec7f57ed079c38c960400 | Downloaded File | HTML |
Clean
|
...
|
e8b101a7c7f64aad528cc734513cbeb02243c0af37930dc0f3239749cff184b6 | Downloaded File | HTML |
Clean
|
...
|
ae02e579f6b0afbd3c2cad8d8779a11b1edf7180ca8627d7c32686b8d5340337 | Downloaded File | Text |
Clean
|
...
|
4c82442f45556689083afd8feb0126f87e17d90c450dbaca27b9283546fa4c57 | Downloaded File | Text |
Clean
|
...
|
1d1bb81c930a4f5419e709d9f1a33b2f5d2119483385df1da9daa1529e22dbb8 | Downloaded File | Text |
Clean
|
...
|
86fe314dfc1fe2c50a7111d15fdb9e3d8418acaa5bfa3956a493f0693c30b45e | Downloaded File | Text |
Clean
|
...
|
9c37f0d1be486dc8950cfb045e49fae7e70b7be433e130f6d0d6f72d99b5e16e | Downloaded File | Text |
Clean
|
...
|
70e95e929b5335e07e3c667a1945f3502259856b44af57178388368ad09ff68e | Downloaded File | Text |
Clean
|
...
|
9d375783bb9c5f8a5030d495fd7fcd378a068a0e23f788583449a095576bddfb | Downloaded File | HTML |
Clean
|
...
|
6049a9d514fdc7e18967c4d17f2806b887f7dbf68891d6c22cdce221a75c29a8 | Downloaded File | HTML |
Clean
|
...
|
0a2529bce56bfc3545b96bd0d742e6f9a977c04d72c19f8bb02521fc05615e21 | Downloaded File | HTML |
Clean
|
...
|
446a6087825fa73eadb045e5a2e9e2adf7df241b571228187728191d961dda1f | Downloaded File | HTML |
Clean
|
...
|
32f2fa940d4b4fe19aca1e53a24e5aac29c57b7c5ee78588325b87f1b649c864 | Downloaded File | HTML |
Clean
|
...
|
55f7d9e99b8e2d4e0e193b2f0275501e6d9c1ebd29cadbea6a0da48a8587e3e0 | Downloaded File | HTML |
Clean
Known to be clean.
|
...
|
Verdict |
Clean
Known to be clean.
|
9d97328f76430c226c738d18c3f30fdfc89fbc40443c0a4065bfaf7987856cc4 | Downloaded File | HTML |
Clean
|
...
|
URL | WHOIS Data | Reputation Status | Recursively Submitted | Actions |
---|---|---|---|---|
http://www.searchgpt.world |
Show WHOIS
|
Not Available
|
- |
...
|
72524851f2ce69237411c1e74738abec8564c44622dd14900216bef04be72f98 | Downloaded File | Text |
Clean
|
...
|
c:\users\rdhj0cnfevzx\appdata\local\microsoft\windows\inetcache\counters.dat | Modified File | Stream |
Clean
|
...
|