Malicious
Classifications
-
Threat Names
-
Dynamic Analysis Report
Created on 2023-09-19T15:13:45+00:00
libGLESv2.dll.exe
Windows Exe (x86-32)
Remarks (2/2)
(0x0200003A): A tasks were rescheduled ahead of time to reveal dormant functionality.
(0x0200000E): The overall sleep time of all monitored processes was truncated from "49 days, 17 hours, 8 minutes, 7 seconds" to "20 seconds" to reveal dormant functionality.
This is a filtered view
This list contains only the embedded files, downloaded files, and dropped files
Filters: |
There are no files for this filter
There are no files in this analysis
File Name | Category | Type | Verdict | Actions |
---|
C:\Users\RDhJ0CNFevzX\Desktop\libGLESv2.dll.exe | Sample File | Binary |
Malicious
|
...
|
»
PE Information
»
Image Base | 0x00400000 |
Entry Point | 0x005F131E |
Size Of Code | 0x001EF400 |
Size Of Initialized Data | 0x00003600 |
File Type | IMAGE_FILE_EXECUTABLE_IMAGE |
Subsystem | IMAGE_SUBSYSTEM_WINDOWS_GUI |
Machine Type | IMAGE_FILE_MACHINE_I386 |
Compile Timestamp | 2022-05-04 16:03 (UTC) |
Version Information (4)
»
FileVersion | 5.15.2.0 |
OriginalFilename | libGLESv2.dll |
ProductName | libGLESv2 |
ProductVersion | 5.15.2.0 |
Sections (4)
»
Name | Virtual Address | Virtual Size | Raw Data Size | Raw Data Offset | Flags | Entropy |
---|---|---|---|---|---|---|
.text | 0x00402000 | 0x001EF324 | 0x001EF400 | 0x00000400 | IMAGE_SCN_CNT_CODE, IMAGE_SCN_MEM_EXECUTE, IMAGE_SCN_MEM_READ | 7.52 |
.sdata | 0x005F2000 | 0x00002FDF | 0x00003000 | 0x001EF800 | IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_READ, IMAGE_SCN_MEM_WRITE | 3.24 |
.rsrc | 0x005F6000 | 0x00000218 | 0x00000400 | 0x001F2800 | IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_READ | 1.84 |
.reloc | 0x005F8000 | 0x0000000C | 0x00000200 | 0x001F2C00 | IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_DISCARDABLE, IMAGE_SCN_MEM_READ | 0.1 |
Imports (1)
»
mscoree.dll (1)
»
API Name | Ordinal | IAT Address | Thunk RVA | Thunk Offset | Hint |
---|---|---|---|---|---|
_CorExeMain | - | 0x00402000 | 0x001F12F8 | 0x001EF6F8 | 0x00000000 |
Memory Dumps (103)
»
Name | Process ID | Start VA | End VA | Dump Reason | PE Rebuild | Bitness | Entry Point | YARA | Actions |
---|---|---|---|---|---|---|---|---|---|
libglesv2.dll.exe | 1 | 0x00B00000 | 0x00CF9FFF | Relevant Image | 64-bit | - |
...
|
||
buffer | 1 | 0x00530000 | 0x00537FFF | Reflectively Loaded .NET Assembly | 64-bit | - |
...
|
||
buffer | 1 | 0x00540000 | 0x00540FFF | Reflectively Loaded .NET Assembly | 64-bit | - |
...
|
||
buffer | 1 | 0x00550000 | 0x00564FFF | Reflectively Loaded .NET Assembly | 64-bit | - |
...
|
||
buffer | 1 | 0x00570000 | 0x00570FFF | Reflectively Loaded .NET Assembly | 64-bit | - |
...
|
||
buffer | 1 | 0x00580000 | 0x00589FFF | Reflectively Loaded .NET Assembly | 64-bit | - |
...
|
||
buffer | 1 | 0x00790000 | 0x007A0FFF | Reflectively Loaded .NET Assembly | 64-bit | - |
...
|
||
buffer | 1 | 0x007B0000 | 0x007B0FFF | Reflectively Loaded .NET Assembly | 64-bit | - |
...
|
||
buffer | 1 | 0x007E0000 | 0x007E4FFF | Reflectively Loaded .NET Assembly | 64-bit | - |
...
|
||
buffer | 1 | 0x007C0000 | 0x007C5FFF | Reflectively Loaded .NET Assembly | 64-bit | - |
...
|
||
buffer | 1 | 0x007D0000 | 0x007D1FFF | Reflectively Loaded .NET Assembly | 64-bit | - |
...
|
||
buffer | 1 | 0x007C0000 | 0x007C5FFF | Reflectively Loaded .NET Assembly | 64-bit | - |
...
|
||
buffer | 1 | 0x007F0000 | 0x007FBFFF | Reflectively Loaded .NET Assembly | 64-bit | - |
...
|
||
buffer | 1 | 0x007D0000 | 0x007D1FFF | Reflectively Loaded .NET Assembly | 64-bit | - |
...
|
||
buffer | 1 | 0x007C0000 | 0x007C5FFF | Reflectively Loaded .NET Assembly | 64-bit | - |
...
|
||
buffer | 1 | 0x00820000 | 0x00825FFF | Reflectively Loaded .NET Assembly | 64-bit | - |
...
|
||
buffer | 1 | 0x00830000 | 0x00834FFF | Reflectively Loaded .NET Assembly | 64-bit | - |
...
|
||
buffer | 1 | 0x009E0000 | 0x009E6FFF | Reflectively Loaded .NET Assembly | 64-bit | - |
...
|
||
buffer | 1 | 0x009F0000 | 0x009F6FFF | Reflectively Loaded .NET Assembly | 64-bit | - |
...
|
||
buffer | 1 | 0x00A50000 | 0x00A51FFF | Reflectively Loaded .NET Assembly | 64-bit | - |
...
|
||
buffer | 1 | 0x00A00000 | 0x00A05FFF | Reflectively Loaded .NET Assembly | 64-bit | - |
...
|
||
buffer | 1 | 0x00A10000 | 0x00A14FFF | Reflectively Loaded .NET Assembly | 64-bit | - |
...
|
||
buffer | 1 | 0x00A20000 | 0x00A28FFF | Reflectively Loaded .NET Assembly | 64-bit | - |
...
|
||
buffer | 1 | 0x00A30000 | 0x00A30FFF | Reflectively Loaded .NET Assembly | 64-bit | - |
...
|
||
buffer | 1 | 0x00A60000 | 0x00A61FFF | Reflectively Loaded .NET Assembly | 64-bit | - |
...
|
||
buffer | 1 | 0x00A00000 | 0x00A05FFF | Reflectively Loaded .NET Assembly | 64-bit | - |
...
|
||
buffer | 1 | 0x00A70000 | 0x00A75FFF | Reflectively Loaded .NET Assembly | 64-bit | - |
...
|
||
buffer | 1 | 0x00A80000 | 0x00A81FFF | Reflectively Loaded .NET Assembly | 64-bit | - |
...
|
||
buffer | 1 | 0x00A90000 | 0x00A95FFF | Reflectively Loaded .NET Assembly | 64-bit | - |
...
|
||
buffer | 1 | 0x00A80000 | 0x00A81FFF | Reflectively Loaded .NET Assembly | 64-bit | - |
...
|
||
libglesv2.dll.exe | 1 | 0x00B00000 | 0x00CF9FFF | Final Dump | 64-bit | - |
...
|
||
libglesv2.dll.exe | 1 | 0x00B00000 | 0x00CF9FFF | Process Termination | 64-bit | - |
...
|
||
explorer.exe | 43 | 0x006B0000 | 0x008A9FFF | Relevant Image | 64-bit | - |
...
|
||
buffer | 43 | 0x00640000 | 0x00647FFF | Reflectively Loaded .NET Assembly | 64-bit | - |
...
|
||
buffer | 43 | 0x00650000 | 0x00650FFF | Reflectively Loaded .NET Assembly | 64-bit | - |
...
|
||
buffer | 43 | 0x00660000 | 0x00674FFF | Reflectively Loaded .NET Assembly | 64-bit | - |
...
|
||
buffer | 43 | 0x00650000 | 0x00650FFF | Reflectively Loaded .NET Assembly | 64-bit | - |
...
|
||
buffer | 43 | 0x00690000 | 0x00690FFF | Reflectively Loaded .NET Assembly | 64-bit | - |
...
|
||
buffer | 43 | 0x006A0000 | 0x006A9FFF | Reflectively Loaded .NET Assembly | 64-bit | - |
...
|
||
buffer | 43 | 0x00690000 | 0x00690FFF | Reflectively Loaded .NET Assembly | 64-bit | - |
...
|
||
buffer | 43 | 0x021D0000 | 0x021E0FFF | Reflectively Loaded .NET Assembly | 64-bit | - |
...
|
||
buffer | 43 | 0x006A0000 | 0x006A9FFF | Reflectively Loaded .NET Assembly | 64-bit | - |
...
|
||
buffer | 43 | 0x00690000 | 0x00690FFF | Reflectively Loaded .NET Assembly | 64-bit | - |
...
|
||
buffer | 43 | 0x021F0000 | 0x021F0FFF | Reflectively Loaded .NET Assembly | 64-bit | - |
...
|
||
buffer | 43 | 0x021D0000 | 0x021E0FFF | Reflectively Loaded .NET Assembly | 64-bit | - |
...
|
||
buffer | 43 | 0x006A0000 | 0x006A9FFF | Reflectively Loaded .NET Assembly | 64-bit | - |
...
|
||
buffer | 43 | 0x00690000 | 0x00690FFF | Reflectively Loaded .NET Assembly | 64-bit | - |
...
|
||
buffer | 43 | 0x02220000 | 0x02224FFF | Reflectively Loaded .NET Assembly | 64-bit | - |
...
|
||
buffer | 43 | 0x02200000 | 0x02205FFF | Reflectively Loaded .NET Assembly | 64-bit | - |
...
|
||
buffer | 43 | 0x02220000 | 0x02224FFF | Reflectively Loaded .NET Assembly | 64-bit | - |
...
|
||
buffer | 43 | 0x02210000 | 0x02211FFF | Reflectively Loaded .NET Assembly | 64-bit | - |
...
|
||
buffer | 43 | 0x02200000 | 0x02205FFF | Reflectively Loaded .NET Assembly | 64-bit | - |
...
|
||
buffer | 43 | 0x02220000 | 0x02224FFF | Reflectively Loaded .NET Assembly | 64-bit | - |
...
|
||
buffer | 43 | 0x02230000 | 0x0223BFFF | Reflectively Loaded .NET Assembly | 64-bit | - |
...
|
||
buffer | 43 | 0x02210000 | 0x02211FFF | Reflectively Loaded .NET Assembly | 64-bit | - |
...
|
||
buffer | 43 | 0x02200000 | 0x02205FFF | Reflectively Loaded .NET Assembly | 64-bit | - |
...
|
||
buffer | 43 | 0x02220000 | 0x02224FFF | Reflectively Loaded .NET Assembly | 64-bit | - |
...
|
||
buffer | 43 | 0x02260000 | 0x02265FFF | Reflectively Loaded .NET Assembly | 64-bit | - |
...
|
||
buffer | 43 | 0x02390000 | 0x02394FFF | Reflectively Loaded .NET Assembly | 64-bit | - |
...
|
||
buffer | 43 | 0x023A0000 | 0x023A6FFF | Reflectively Loaded .NET Assembly | 64-bit | - |
...
|
||
buffer | 43 | 0x02390000 | 0x02394FFF | Reflectively Loaded .NET Assembly | 64-bit | - |
...
|
||
buffer | 43 | 0x023B0000 | 0x023B6FFF | Reflectively Loaded .NET Assembly | 64-bit | - |
...
|
||
buffer | 43 | 0x023A0000 | 0x023A6FFF | Reflectively Loaded .NET Assembly | 64-bit | - |
...
|
||
buffer | 43 | 0x02390000 | 0x02394FFF | Reflectively Loaded .NET Assembly | 64-bit | - |
...
|
||
buffer | 43 | 0x02410000 | 0x02411FFF | Reflectively Loaded .NET Assembly | 64-bit | - |
...
|
||
buffer | 43 | 0x023C0000 | 0x023C5FFF | Reflectively Loaded .NET Assembly | 64-bit | - |
...
|
||
buffer | 43 | 0x023D0000 | 0x023D4FFF | Reflectively Loaded .NET Assembly | 64-bit | - |
...
|
||
buffer | 43 | 0x023E0000 | 0x023E8FFF | Reflectively Loaded .NET Assembly | 64-bit | - |
...
|
||
buffer | 43 | 0x023D0000 | 0x023D4FFF | Reflectively Loaded .NET Assembly | 64-bit | - |
...
|
||
buffer | 43 | 0x023F0000 | 0x023F0FFF | Reflectively Loaded .NET Assembly | 64-bit | - |
...
|
||
buffer | 43 | 0x023E0000 | 0x023E8FFF | Reflectively Loaded .NET Assembly | 64-bit | - |
...
|
||
buffer | 43 | 0x023D0000 | 0x023D4FFF | Reflectively Loaded .NET Assembly | 64-bit | - |
...
|
||
buffer | 43 | 0x02400000 | 0x02401FFF | Reflectively Loaded .NET Assembly | 64-bit | - |
...
|
||
buffer | 43 | 0x023F0000 | 0x023F0FFF | Reflectively Loaded .NET Assembly | 64-bit | - |
...
|
||
buffer | 43 | 0x023E0000 | 0x023E8FFF | Reflectively Loaded .NET Assembly | 64-bit | - |
...
|
||
buffer | 43 | 0x023D0000 | 0x023D4FFF | Reflectively Loaded .NET Assembly | 64-bit | - |
...
|
||
buffer | 43 | 0x1ACF0000 | 0x1ACF5FFF | Reflectively Loaded .NET Assembly | 64-bit | - |
...
|
||
buffer | 43 | 0x02400000 | 0x02401FFF | Reflectively Loaded .NET Assembly | 64-bit | - |
...
|
||
buffer | 43 | 0x023F0000 | 0x023F0FFF | Reflectively Loaded .NET Assembly | 64-bit | - |
...
|
||
buffer | 43 | 0x023E0000 | 0x023E8FFF | Reflectively Loaded .NET Assembly | 64-bit | - |
...
|
||
buffer | 43 | 0x023D0000 | 0x023D4FFF | Reflectively Loaded .NET Assembly | 64-bit | - |
...
|
||
buffer | 43 | 0x1AD00000 | 0x1AD01FFF | Reflectively Loaded .NET Assembly | 64-bit | - |
...
|
||
buffer | 43 | 0x1ACF0000 | 0x1ACF5FFF | Reflectively Loaded .NET Assembly | 64-bit | - |
...
|
||
buffer | 43 | 0x02400000 | 0x02401FFF | Reflectively Loaded .NET Assembly | 64-bit | - |
...
|
||
buffer | 43 | 0x023F0000 | 0x023F0FFF | Reflectively Loaded .NET Assembly | 64-bit | - |
...
|
||
buffer | 43 | 0x023E0000 | 0x023E8FFF | Reflectively Loaded .NET Assembly | 64-bit | - |
...
|
||
buffer | 43 | 0x023D0000 | 0x023D4FFF | Reflectively Loaded .NET Assembly | 64-bit | - |
...
|
||
buffer | 43 | 0x1AD10000 | 0x1AD15FFF | Reflectively Loaded .NET Assembly | 64-bit | - |
...
|
||
buffer | 43 | 0x1B8BA000 | 0x1B8BFFFF | First Network Behavior | 64-bit | - |
...
|
||
buffer | 43 | 0x1B7BA000 | 0x1B7BFFFF | First Network Behavior | 64-bit | - |
...
|
||
buffer | 43 | 0x1B1B7000 | 0x1B1BFFFF | First Network Behavior | 64-bit | - |
...
|
||
buffer | 43 | 0x1B0B5000 | 0x1B0BFFFF | First Network Behavior | 64-bit | - |
...
|
||
buffer | 43 | 0x1A89D000 | 0x1A89FFFF | First Network Behavior | 64-bit | - |
...
|
||
buffer | 43 | 0x00146000 | 0x0014FFFF | First Network Behavior | 64-bit | - |
...
|
||
explorer.exe | 43 | 0x006B0000 | 0x008A9FFF | First Network Behavior | 64-bit | - |
...
|
||
dwm.exe | 19 | 0x00F80000 | 0x01179FFF | Relevant Image | 64-bit | - |
...
|
||
pidgin.exe | 27 | 0x002C0000 | 0x004B9FFF | Relevant Image | 64-bit | - |
...
|
||
gmailnotifierpro.exe | 22 | 0x00FB0000 | 0x011A9FFF | Relevant Image | 64-bit | - |
...
|
||
omnipos.exe | 31 | 0x00310000 | 0x00509FFF | Relevant Image | 64-bit | - |
...
|
||
draw face.exe | 38 | 0x00320000 | 0x00519FFF | Relevant Image | 64-bit | - |
...
|
||
explorer.exe | 36 | 0x00CA0000 | 0x00E99FFF | Relevant Image | 64-bit | - |
...
|
||
accupos.exe | 41 | 0x000F0000 | 0x002E9FFF | Relevant Image | 64-bit | - |
...
|
||
searchui.exe | 42 | 0x003A0000 | 0x00599FFF | Relevant Image | 64-bit | - |
...
|
C:\MSOCache\All Users\{90160000-001A-0409-1000-0000000FF1CE}-C\910ec55cf4df7d | Dropped File | Text |
Clean
|
...
|
»
C:\Users\RDhJ0CNFevzX\AppData\Local\Temp\d4294808-742c-4d98-9537-1e79e4c62434.vbs | Dropped File | Text |
Clean
|
...
|
»
C:\Program Files (x86)\Windows NT\TableTextService\c529457537ee3f | Dropped File | Text |
Clean
|
...
|
»
C:\Users\RDhJ0CNFevzX\AppData\Local\Temp\68366bda-2e55-443c-927d-1ffb87bfb9fd.vbs | Dropped File | Text |
Clean
|
...
|
»
C:\Recovery\WindowsRE\dab4d89cac03ec | Dropped File | Text |
Clean
|
...
|
»
C:\Program Files\Microsoft SQL Server\110\Shared\6cb0b6c459d5d3 | Dropped File | Text |
Clean
|
...
|
»
C:\Users\RDhJ0CNFevzX\AppData\Local\Temp\PBAoSMgkVL.bat | Dropped File | Text |
Clean
|
...
|
»
C:\MSOCache\All Users\{90160000-0018-0409-1000-0000000FF1CE}-C\9a9ef8f6a80f81 | Dropped File | Text |
Clean
|
...
|
»
C:\Users\RDhJ0CNFevzX\AppData\Local\Temp\aIXcL1n5fg | Dropped File | Text |
Clean
|
...
|
»
ad57480fc18d55031cc7c956bc8beabb89eebdeb-b609687e132b072de1c4d480bfccd0dc8a4c7775 | Downloaded File | ZIP |
Clean
|
...
|
»
Archive Information
»
Number of Files | 7 |
Number of Folders | 2 |
Size of Packed Archive Contents | 131.70 KB |
Size of Unpacked Archive Contents | 136.67 KB |
File Format | zip |
Contents (7)
»
File Name | Packed Size | Unpacked Size | Compression | Is Encrypted | Modify Time | Verdict | Recursively Submitted | Actions |
---|---|---|---|---|---|---|---|---|
~Work.log | 375 Bytes | 837 Bytes | Deflate | False | 2023-09-19 15:17 (UTC) |
Clean
|
- |
...
|
Other/Steam#Information.txt | 20 Bytes | 20 Bytes | Store | False | 2023-09-19 15:17 (UTC) |
Clean
|
- |
...
|
Other/Telegram#Information.txt | 23 Bytes | 23 Bytes | Store | False | 2023-09-19 15:17 (UTC) |
Clean
|
- |
...
|
Information [DE, Ingolstadt].txt | 605 Bytes | 1.09 KB | Deflate | False | 2023-09-19 15:16 (UTC) |
Clean
|
- |
...
|
Clipboard [Text].txt | 32 Bytes | 32 Bytes | Store | False | 2023-09-19 15:17 (UTC) |
Clean
|
- |
...
|
Other/Discord Tokens [0].txt | 22 Bytes | 22 Bytes | Store | False | 2023-09-19 15:17 (UTC) |
Clean
|
- |
...
|
Screenshots/Screenshot#DISPLAY1.jpg | 130.65 KB | 134.67 KB | Deflate | False | 2023-09-19 15:17 (UTC) |
Clean
|
- |
...
|
778a3a03ae2eeabce1598b2b807ffd7ed72e1455f4031d970d3520212189b1b9 | Downloaded File | Text |
Clean
|
...
|
»
190ec79840e3a7e9b3d0746f0a09f6aa92fac9b4a88970473af2bbe8749849f8 | Downloaded File | Text |
Clean
|
...
|
»
e667b3c79f382ff0a07913cafa14fe54812008ea0d0f370ca50f65813feb6027 | Downloaded File | Text |
Clean
|
...
|
»
Screenshots/Screenshot#DISPLAY1.jpg | Archive File | Image |
Clean
|
...
|
»
Information [DE, Ingolstadt].txt | Archive File | Text |
Clean
|
...
|
»
Clipboard [Text].txt | Archive File | Text |
Clean
|
...
|
»
Other/Telegram#Information.txt | Archive File | Text |
Clean
|
...
|
»
Other/Discord Tokens [0].txt | Archive File | Text |
Clean
|
...
|
»
Other/Steam#Information.txt | Archive File | Text |
Clean
|
...
|
»