Analysis
-
max time kernel
150s -
max time network
146s -
platform
windows7_x64 -
resource
win7-20240419-en -
resource tags
arch:x64arch:x86image:win7-20240419-enlocale:en-usos:windows7-x64system -
submitted
27-06-2024 01:42
Static task
static1
Behavioral task
behavioral1
Sample
SMKT_COPY20240604.exe
Resource
win7-20240419-en
Behavioral task
behavioral2
Sample
SMKT_COPY20240604.exe
Resource
win10v2004-20240226-en
Behavioral task
behavioral3
Sample
$PLUGINSDIR/System.dll
Resource
win7-20240221-en
Behavioral task
behavioral4
Sample
$PLUGINSDIR/System.dll
Resource
win10v2004-20240508-en
Behavioral task
behavioral5
Sample
$PLUGINSDIR/nsExec.dll
Resource
win7-20240220-en
Behavioral task
behavioral6
Sample
$PLUGINSDIR/nsExec.dll
Resource
win10v2004-20240226-en
General
-
Target
SMKT_COPY20240604.exe
-
Size
314KB
-
MD5
c7ceecb921d43912ec928af816a43ede
-
SHA1
2c4266ebdae98fc609ffb191cf26e85dc0671faa
-
SHA256
144540da6bfc395bdd8726b156099a7f7b27240321424411ba8af877cbdcbe86
-
SHA512
8b4ecfc89221af3d4dde2ab7effc288f9c9ddaba764b67acbde33fbc5c19d69e16d69c40f35de74e36f4eb12bdd2ffba44b702bea9d5249476dafc7f4f389e31
-
SSDEEP
6144:BXFKo5F4CtVeI8Y9BA6MA4ph2LN7LNNhEdMUjzz4elzC:BX54CVeI8Y9BA6uph2LN7LNNhTelO
Malware Config
Signatures
-
Guloader,Cloudeye
A shellcode based downloader first seen in 2020.
-
NirSoft MailPassView 2 IoCs
Password recovery tool for various email clients
Processes:
resource yara_rule behavioral1/memory/2520-1812-0x0000000000400000-0x0000000000462000-memory.dmp MailPassView behavioral1/memory/2520-1824-0x0000000000400000-0x0000000000462000-memory.dmp MailPassView -
NirSoft WebBrowserPassView 3 IoCs
Password recovery tool for various web browsers
Processes:
resource yara_rule behavioral1/memory/2356-1808-0x0000000000400000-0x0000000000478000-memory.dmp WebBrowserPassView behavioral1/memory/2356-1806-0x0000000000400000-0x0000000000478000-memory.dmp WebBrowserPassView behavioral1/memory/2356-1821-0x0000000000400000-0x0000000000478000-memory.dmp WebBrowserPassView -
Nirsoft 8 IoCs
Processes:
resource yara_rule behavioral1/memory/1464-1813-0x0000000000400000-0x0000000000424000-memory.dmp Nirsoft behavioral1/memory/1464-1814-0x0000000000400000-0x0000000000424000-memory.dmp Nirsoft behavioral1/memory/2520-1812-0x0000000000400000-0x0000000000462000-memory.dmp Nirsoft behavioral1/memory/1464-1815-0x0000000000400000-0x0000000000424000-memory.dmp Nirsoft behavioral1/memory/2356-1808-0x0000000000400000-0x0000000000478000-memory.dmp Nirsoft behavioral1/memory/2356-1806-0x0000000000400000-0x0000000000478000-memory.dmp Nirsoft behavioral1/memory/2356-1821-0x0000000000400000-0x0000000000478000-memory.dmp Nirsoft behavioral1/memory/2520-1824-0x0000000000400000-0x0000000000462000-memory.dmp Nirsoft -
Executes dropped EXE 4 IoCs
Processes:
QQ.exeQQ.exeQQ.exeQQ.exepid process 540 QQ.exe 2356 QQ.exe 2520 QQ.exe 1464 QQ.exe -
Loads dropped DLL 64 IoCs
Processes:
SMKT_COPY20240604.exepid process 1760 SMKT_COPY20240604.exe 1760 SMKT_COPY20240604.exe 1760 SMKT_COPY20240604.exe 1760 SMKT_COPY20240604.exe 1760 SMKT_COPY20240604.exe 1760 SMKT_COPY20240604.exe 1760 SMKT_COPY20240604.exe 1760 SMKT_COPY20240604.exe 1760 SMKT_COPY20240604.exe 1760 SMKT_COPY20240604.exe 1760 SMKT_COPY20240604.exe 1760 SMKT_COPY20240604.exe 1760 SMKT_COPY20240604.exe 1760 SMKT_COPY20240604.exe 1760 SMKT_COPY20240604.exe 1760 SMKT_COPY20240604.exe 1760 SMKT_COPY20240604.exe 1760 SMKT_COPY20240604.exe 1760 SMKT_COPY20240604.exe 1760 SMKT_COPY20240604.exe 1760 SMKT_COPY20240604.exe 1760 SMKT_COPY20240604.exe 1760 SMKT_COPY20240604.exe 1760 SMKT_COPY20240604.exe 1760 SMKT_COPY20240604.exe 1760 SMKT_COPY20240604.exe 1760 SMKT_COPY20240604.exe 1760 SMKT_COPY20240604.exe 1760 SMKT_COPY20240604.exe 1760 SMKT_COPY20240604.exe 1760 SMKT_COPY20240604.exe 1760 SMKT_COPY20240604.exe 1760 SMKT_COPY20240604.exe 1760 SMKT_COPY20240604.exe 1760 SMKT_COPY20240604.exe 1760 SMKT_COPY20240604.exe 1760 SMKT_COPY20240604.exe 1760 SMKT_COPY20240604.exe 1760 SMKT_COPY20240604.exe 1760 SMKT_COPY20240604.exe 1760 SMKT_COPY20240604.exe 1760 SMKT_COPY20240604.exe 1760 SMKT_COPY20240604.exe 1760 SMKT_COPY20240604.exe 1760 SMKT_COPY20240604.exe 1760 SMKT_COPY20240604.exe 1760 SMKT_COPY20240604.exe 1760 SMKT_COPY20240604.exe 1760 SMKT_COPY20240604.exe 1760 SMKT_COPY20240604.exe 1760 SMKT_COPY20240604.exe 1760 SMKT_COPY20240604.exe 1760 SMKT_COPY20240604.exe 1760 SMKT_COPY20240604.exe 1760 SMKT_COPY20240604.exe 1760 SMKT_COPY20240604.exe 1760 SMKT_COPY20240604.exe 1760 SMKT_COPY20240604.exe 1760 SMKT_COPY20240604.exe 1760 SMKT_COPY20240604.exe 1760 SMKT_COPY20240604.exe 1760 SMKT_COPY20240604.exe 1760 SMKT_COPY20240604.exe 1760 SMKT_COPY20240604.exe -
Reads user/profile data of web browsers 2 TTPs
Infostealers often target stored browser data, which can include saved credentials etc.
-
Accesses Microsoft Outlook accounts 1 TTPs 1 IoCs
Processes:
QQ.exedescription ioc process Key opened \REGISTRY\USER\S-1-5-21-481678230-3773327859-3495911762-1000\Software\Microsoft\Office\Outlook\OMI Account Manager\Accounts QQ.exe -
Adds Run key to start application 2 TTPs 4 IoCs
Processes:
SMKT_COPY20240604.exeQQ.exedescription ioc process Set value (str) \REGISTRY\USER\S-1-5-21-481678230-3773327859-3495911762-1000\Software\Microsoft\Windows\CurrentVersion\Run\Rmc-R6CJUW = "\"C:\\Users\\Admin\\AppData\\Roaming\\QQ\\QQ.exe\"" SMKT_COPY20240604.exe Set value (str) \REGISTRY\MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Run\Rmc-R6CJUW = "\"C:\\Users\\Admin\\AppData\\Roaming\\QQ\\QQ.exe\"" SMKT_COPY20240604.exe Set value (str) \REGISTRY\USER\S-1-5-21-481678230-3773327859-3495911762-1000\Software\Microsoft\Windows\CurrentVersion\Run\Rmc-R6CJUW = "\"C:\\Users\\Admin\\AppData\\Roaming\\QQ\\QQ.exe\"" QQ.exe Set value (str) \REGISTRY\MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Run\Rmc-R6CJUW = "\"C:\\Users\\Admin\\AppData\\Roaming\\QQ\\QQ.exe\"" QQ.exe -
Suspicious use of NtCreateThreadExHideFromDebugger 4 IoCs
Processes:
SMKT_COPY20240604.exeQQ.exepid process 2180 SMKT_COPY20240604.exe 2180 SMKT_COPY20240604.exe 2632 QQ.exe 2632 QQ.exe -
Suspicious use of NtSetInformationThreadHideFromDebugger 4 IoCs
Processes:
SMKT_COPY20240604.exeSMKT_COPY20240604.exeQQ.exeQQ.exepid process 1760 SMKT_COPY20240604.exe 2180 SMKT_COPY20240604.exe 540 QQ.exe 2632 QQ.exe -
Suspicious use of SetThreadContext 5 IoCs
Processes:
SMKT_COPY20240604.exeQQ.exeQQ.exedescription pid process target process PID 1760 set thread context of 2180 1760 SMKT_COPY20240604.exe SMKT_COPY20240604.exe PID 540 set thread context of 2632 540 QQ.exe QQ.exe PID 2632 set thread context of 2356 2632 QQ.exe QQ.exe PID 2632 set thread context of 2520 2632 QQ.exe QQ.exe PID 2632 set thread context of 1464 2632 QQ.exe QQ.exe -
Enumerates physical storage devices 1 TTPs
Attempts to interact with connected storage/optical drive(s).
-
Processes:
SMKT_COPY20240604.exeQQ.exedescription ioc process Key created \REGISTRY\MACHINE\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\Certificates\D1EB23A46D17D68FD92564C2F1F1601764D8E349 SMKT_COPY20240604.exe Set value (data) \REGISTRY\MACHINE\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\Certificates\D1EB23A46D17D68FD92564C2F1F1601764D8E349\Blob = 0f00000001000000140000003e8e6487f8fd27d322a269a71edaac5d57811286090000000100000034000000303206082b0601050507030106082b0601050507030206082b0601050507030406082b0601050507030306082b0601050507030853000000010000002600000030243022060c2b06010401b231010201050130123010060a2b0601040182373c0101030200c00b00000001000000180000004300b7004f00b7004d00b7004f00b7004400b7004f000000140000000100000014000000a0110a233e96f107ece2af29ef82a57fd030a4b41d00000001000000100000002e0d6875874a44c820912e85e964cfdb030000000100000014000000d1eb23a46d17d68fd92564c2f1f1601764d8e349200000000100000036040000308204323082031aa003020102020101300d06092a864886f70d0101050500307b310b3009060355040613024742311b301906035504080c1247726561746572204d616e636865737465723110300e06035504070c0753616c666f7264311a3018060355040a0c11436f6d6f646f204341204c696d697465643121301f06035504030c18414141204365727469666963617465205365727669636573301e170d3034303130313030303030305a170d3238313233313233353935395a307b310b3009060355040613024742311b301906035504080c1247726561746572204d616e636865737465723110300e06035504070c0753616c666f7264311a3018060355040a0c11436f6d6f646f204341204c696d697465643121301f06035504030c1841414120436572746966696361746520536572766963657330820122300d06092a864886f70d01010105000382010f003082010a0282010100be409df46ee1ea76871c4d45448ebe46c883069dc12afe181f8ee402faf3ab5d508a16310b9a06d0c57022cd492d5463ccb66e68460b53eacb4c24c0bc724eeaf115aef4549a120ac37ab23360e2da8955f32258f3dedccfef8386a28c944f9f68f29890468427c776bfe3cc352c8b5e07646582c048b0a891f9619f762050a891c766b5eb78620356f08a1a13ea31a31ea099fd38f6f62732586f07f56bb8fb142bafb7aaccd6635f738cda0599a838a8cb17783651ace99ef4783a8dcf0fd942e2980cab2f9f0e01deef9f9949f12ddfac744d1b98b547c5e529d1f99018c7629cbe83c7267b3e8a25c7c0dd9de6356810209d8fd8ded2c3849c0d5ee82fc90203010001a381c03081bd301d0603551d0e04160414a0110a233e96f107ece2af29ef82a57fd030a4b4300e0603551d0f0101ff040403020106300f0603551d130101ff040530030101ff307b0603551d1f047430723038a036a0348632687474703a2f2f63726c2e636f6d6f646f63612e636f6d2f414141436572746966696361746553657276696365732e63726c3036a034a0328630687474703a2f2f63726c2e636f6d6f646f2e6e65742f414141436572746966696361746553657276696365732e63726c300d06092a864886f70d010105050003820101000856fc02f09be8ffa4fad67bc64480ce4fc4c5f60058cca6b6bc1449680476e8e6ee5dec020f60d68d50184f264e01e3e6b0a5eebfbc745441bffdfc12b8c74f5af48960057f60b7054af3f6f1c2bfc4b97486b62d7d6bccd2f346dd2fc6e06ac3c334032c7d96dd5ac20ea70a99c1058bab0c2ff35c3acf6c37550987de53406c58effcb6ab656e04f61bdc3ce05a15c69ed9f15948302165036cece92173ec9b03a1e037ada015188ffaba02cea72ca910132cd4e50826ab229760f8905e74d4a29a53bdf2a968e0a26ec2d76cb1a30f9ebfeb68e756f2aef2e32b383a0981b56b85d7be2ded3f1ab7b263e2f5622c82d46a004150f139839f95e93696986e SMKT_COPY20240604.exe Set value (data) \REGISTRY\MACHINE\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\Certificates\D1EB23A46D17D68FD92564C2F1F1601764D8E349\Blob = 1900000001000000100000002aa1c05e2ae606f198c2c5e937c97aa2030000000100000014000000d1eb23a46d17d68fd92564c2f1f1601764d8e3491d00000001000000100000002e0d6875874a44c820912e85e964cfdb140000000100000014000000a0110a233e96f107ece2af29ef82a57fd030a4b40b00000001000000180000004300b7004f00b7004d00b7004f00b7004400b7004f00000053000000010000002600000030243022060c2b06010401b231010201050130123010060a2b0601040182373c0101030200c0090000000100000034000000303206082b0601050507030106082b0601050507030206082b0601050507030406082b0601050507030306082b060105050703080f00000001000000140000003e8e6487f8fd27d322a269a71edaac5d57811286200000000100000036040000308204323082031aa003020102020101300d06092a864886f70d0101050500307b310b3009060355040613024742311b301906035504080c1247726561746572204d616e636865737465723110300e06035504070c0753616c666f7264311a3018060355040a0c11436f6d6f646f204341204c696d697465643121301f06035504030c18414141204365727469666963617465205365727669636573301e170d3034303130313030303030305a170d3238313233313233353935395a307b310b3009060355040613024742311b301906035504080c1247726561746572204d616e636865737465723110300e06035504070c0753616c666f7264311a3018060355040a0c11436f6d6f646f204341204c696d697465643121301f06035504030c1841414120436572746966696361746520536572766963657330820122300d06092a864886f70d01010105000382010f003082010a0282010100be409df46ee1ea76871c4d45448ebe46c883069dc12afe181f8ee402faf3ab5d508a16310b9a06d0c57022cd492d5463ccb66e68460b53eacb4c24c0bc724eeaf115aef4549a120ac37ab23360e2da8955f32258f3dedccfef8386a28c944f9f68f29890468427c776bfe3cc352c8b5e07646582c048b0a891f9619f762050a891c766b5eb78620356f08a1a13ea31a31ea099fd38f6f62732586f07f56bb8fb142bafb7aaccd6635f738cda0599a838a8cb17783651ace99ef4783a8dcf0fd942e2980cab2f9f0e01deef9f9949f12ddfac744d1b98b547c5e529d1f99018c7629cbe83c7267b3e8a25c7c0dd9de6356810209d8fd8ded2c3849c0d5ee82fc90203010001a381c03081bd301d0603551d0e04160414a0110a233e96f107ece2af29ef82a57fd030a4b4300e0603551d0f0101ff040403020106300f0603551d130101ff040530030101ff307b0603551d1f047430723038a036a0348632687474703a2f2f63726c2e636f6d6f646f63612e636f6d2f414141436572746966696361746553657276696365732e63726c3036a034a0328630687474703a2f2f63726c2e636f6d6f646f2e6e65742f414141436572746966696361746553657276696365732e63726c300d06092a864886f70d010105050003820101000856fc02f09be8ffa4fad67bc64480ce4fc4c5f60058cca6b6bc1449680476e8e6ee5dec020f60d68d50184f264e01e3e6b0a5eebfbc745441bffdfc12b8c74f5af48960057f60b7054af3f6f1c2bfc4b97486b62d7d6bccd2f346dd2fc6e06ac3c334032c7d96dd5ac20ea70a99c1058bab0c2ff35c3acf6c37550987de53406c58effcb6ab656e04f61bdc3ce05a15c69ed9f15948302165036cece92173ec9b03a1e037ada015188ffaba02cea72ca910132cd4e50826ab229760f8905e74d4a29a53bdf2a968e0a26ec2d76cb1a30f9ebfeb68e756f2aef2e32b383a0981b56b85d7be2ded3f1ab7b263e2f5622c82d46a004150f139839f95e93696986e SMKT_COPY20240604.exe Set value (data) \REGISTRY\MACHINE\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\Certificates\D1EB23A46D17D68FD92564C2F1F1601764D8E349\Blob = 040000000100000010000000497904b0eb8719ac47b0bc11519b74d00f00000001000000140000003e8e6487f8fd27d322a269a71edaac5d57811286090000000100000034000000303206082b0601050507030106082b0601050507030206082b0601050507030406082b0601050507030306082b0601050507030853000000010000002600000030243022060c2b06010401b231010201050130123010060a2b0601040182373c0101030200c00b00000001000000180000004300b7004f00b7004d00b7004f00b7004400b7004f000000140000000100000014000000a0110a233e96f107ece2af29ef82a57fd030a4b41d00000001000000100000002e0d6875874a44c820912e85e964cfdb030000000100000014000000d1eb23a46d17d68fd92564c2f1f1601764d8e3491900000001000000100000002aa1c05e2ae606f198c2c5e937c97aa2200000000100000036040000308204323082031aa003020102020101300d06092a864886f70d0101050500307b310b3009060355040613024742311b301906035504080c1247726561746572204d616e636865737465723110300e06035504070c0753616c666f7264311a3018060355040a0c11436f6d6f646f204341204c696d697465643121301f06035504030c18414141204365727469666963617465205365727669636573301e170d3034303130313030303030305a170d3238313233313233353935395a307b310b3009060355040613024742311b301906035504080c1247726561746572204d616e636865737465723110300e06035504070c0753616c666f7264311a3018060355040a0c11436f6d6f646f204341204c696d697465643121301f06035504030c1841414120436572746966696361746520536572766963657330820122300d06092a864886f70d01010105000382010f003082010a0282010100be409df46ee1ea76871c4d45448ebe46c883069dc12afe181f8ee402faf3ab5d508a16310b9a06d0c57022cd492d5463ccb66e68460b53eacb4c24c0bc724eeaf115aef4549a120ac37ab23360e2da8955f32258f3dedccfef8386a28c944f9f68f29890468427c776bfe3cc352c8b5e07646582c048b0a891f9619f762050a891c766b5eb78620356f08a1a13ea31a31ea099fd38f6f62732586f07f56bb8fb142bafb7aaccd6635f738cda0599a838a8cb17783651ace99ef4783a8dcf0fd942e2980cab2f9f0e01deef9f9949f12ddfac744d1b98b547c5e529d1f99018c7629cbe83c7267b3e8a25c7c0dd9de6356810209d8fd8ded2c3849c0d5ee82fc90203010001a381c03081bd301d0603551d0e04160414a0110a233e96f107ece2af29ef82a57fd030a4b4300e0603551d0f0101ff040403020106300f0603551d130101ff040530030101ff307b0603551d1f047430723038a036a0348632687474703a2f2f63726c2e636f6d6f646f63612e636f6d2f414141436572746966696361746553657276696365732e63726c3036a034a0328630687474703a2f2f63726c2e636f6d6f646f2e6e65742f414141436572746966696361746553657276696365732e63726c300d06092a864886f70d010105050003820101000856fc02f09be8ffa4fad67bc64480ce4fc4c5f60058cca6b6bc1449680476e8e6ee5dec020f60d68d50184f264e01e3e6b0a5eebfbc745441bffdfc12b8c74f5af48960057f60b7054af3f6f1c2bfc4b97486b62d7d6bccd2f346dd2fc6e06ac3c334032c7d96dd5ac20ea70a99c1058bab0c2ff35c3acf6c37550987de53406c58effcb6ab656e04f61bdc3ce05a15c69ed9f15948302165036cece92173ec9b03a1e037ada015188ffaba02cea72ca910132cd4e50826ab229760f8905e74d4a29a53bdf2a968e0a26ec2d76cb1a30f9ebfeb68e756f2aef2e32b383a0981b56b85d7be2ded3f1ab7b263e2f5622c82d46a004150f139839f95e93696986e SMKT_COPY20240604.exe Key created \REGISTRY\USER\S-1-5-21-481678230-3773327859-3495911762-1000\Software\Microsoft\SystemCertificates\CA\Certificates\D89E3BD43D5D909B47A18977AA9D5CE36CEE184C SMKT_COPY20240604.exe Set value (data) \REGISTRY\USER\S-1-5-21-481678230-3773327859-3495911762-1000\Software\Microsoft\SystemCertificates\CA\Certificates\D89E3BD43D5D909B47A18977AA9D5CE36CEE184C\Blob = 030000000100000014000000d89e3bd43d5d909b47a18977aa9d5ce36cee184c1400000001000000140000005379bf5aaa2b4acf5480e1d89bc09df2b20366cb040000000100000010000000285ec909c4ab0d2d57f5086b225799aa0f000000010000003000000013baa039635f1c5292a8c2f36aae7e1d25c025202e9092f5b0f53f5f752dfa9c71b3d1b8d9a6358fcee6ec75622fabf9190000000100000010000000ea6089055218053dd01e37e1d806eedf1800000001000000100000002aa1c05e2ae606f198c2c5e937c97aa22000000001000000850500003082058130820469a00302010202103972443af922b751d7d36c10dd313595300d06092a864886f70d01010c0500307b310b3009060355040613024742311b301906035504080c1247726561746572204d616e636865737465723110300e06035504070c0753616c666f7264311a3018060355040a0c11436f6d6f646f204341204c696d697465643121301f06035504030c18414141204365727469666963617465205365727669636573301e170d3139303331323030303030305a170d3238313233313233353935395a308188310b3009060355040613025553311330110603550408130a4e6577204a6572736579311430120603550407130b4a65727365792043697479311e301c060355040a131554686520555345525452555354204e6574776f726b312e302c06035504031325555345525472757374205253412043657274696669636174696f6e20417574686f7269747930820222300d06092a864886f70d01010105000382020f003082020a028202010080126517360ec3db08b3d0ac570d76edcd27d34cad508361e2aa204d092d6409dcce899fcc3da9ecf6cfc1dcf1d3b1d67b3728112b47da39c6bc3a19b45fa6bd7d9da36342b676f2a93b2b91f8e26fd0ec162090093ee2e874c918b491d46264db7fa306f188186a90223cbcfe13f087147bf6e41f8ed4e451c61167460851cb8614543fbc33fe7e6c9cff169d18bd518e35a6a766c87267db2166b1d49b7803c0503ae8ccf0dcbc9e4cfeaf0596351f575ab7ffcef93db72cb6f654ddc8e7123a4dae4c8ab75c9ab4b7203dca7f2234ae7e3b68660144e7014e46539b3360f794be5337907343f332c353efdbaafe744e69c76b8c6093dec4c70cdfe132aecc933b517895678bee3d56fe0cd0690f1b0ff325266b336df76e47fa7343e57e0ea566b1297c3284635589c40dc19354301913acd37d37a7eb5d3a6c355cdb41d712daa9490bdfd8808a0993628eb566cf2588cd84b8b13fa4390fd9029eeb124c957cf36b05a95e1683ccb867e2e8139dcc5b82d34cb3ed5bffdee573ac233b2d00bf3555740949d849581a7f9236e651920ef3267d1c4d17bcc9ec4326d0bf415f40a94444f499e757879e501f5754a83efd74632fb1506509e658422e431a4cb4f0254759fa041e93d426464a5081b2debe78b7fc6715e1c957841e0f63d6e962bad65f552eea5cc62808042539b80e2ba9f24c971c073f0d52f5edef2f820f0203010001a381f23081ef301f0603551d23041830168014a0110a233e96f107ece2af29ef82a57fd030a4b4301d0603551d0e041604145379bf5aaa2b4acf5480e1d89bc09df2b20366cb300e0603551d0f0101ff040403020186300f0603551d130101ff040530030101ff30110603551d20040a300830060604551d200030430603551d1f043c303a3038a036a0348632687474703a2f2f63726c2e636f6d6f646f63612e636f6d2f414141436572746966696361746553657276696365732e63726c303406082b0601050507010104283026302406082b060105050730018618687474703a2f2f6f6373702e636f6d6f646f63612e636f6d300d06092a864886f70d01010c05000382010100188751dc74213d9c8ae027b733d02eccecf0e6cb5e11de226f9b758e9e72fee4d6feaa1f9c962def034a7eaef48d6f723c433bc03febb8df5caaa9c6aef2fcd8eea37b43f686367c14e0cdf4f73ffedeb8b48af09196fefd43647efdccd201a17d7df81919c9422b13bf588bbaa4a266047688914e0c8914cea24dc932b3bae8141abc71f15bf0410b98000a220310e50cb1f9cd923719ed3bf1e43ab6f945132675afbbaaef3f7b773bd2c402913d1900d3175c39db3f7b180d45cd9385962f5ddf59164f3f51bdd545183fed4a8ee80661742316b50d50732744477f105d892a6b853114c4e8a96a4c80bc6a78cfb87f8e7672990c9dfed7910816a1a35f95 SMKT_COPY20240604.exe Key created \REGISTRY\USER\S-1-5-21-481678230-3773327859-3495911762-1000\Software\Microsoft\SystemCertificates\CA\Certificates\D89E3BD43D5D909B47A18977AA9D5CE36CEE184C QQ.exe Set value (data) \REGISTRY\USER\S-1-5-21-481678230-3773327859-3495911762-1000\Software\Microsoft\SystemCertificates\CA\Certificates\D89E3BD43D5D909B47A18977AA9D5CE36CEE184C\Blob = 4b0000000100000044000000420032004600410046003700360039003200460044003900460046004200440036003400450044004500330031003700450034003200330033003400420041005f0000001800000001000000100000002aa1c05e2ae606f198c2c5e937c97aa2190000000100000010000000ea6089055218053dd01e37e1d806eedf0f000000010000003000000013baa039635f1c5292a8c2f36aae7e1d25c025202e9092f5b0f53f5f752dfa9c71b3d1b8d9a6358fcee6ec75622fabf9040000000100000010000000285ec909c4ab0d2d57f5086b225799aa1400000001000000140000005379bf5aaa2b4acf5480e1d89bc09df2b20366cb030000000100000014000000d89e3bd43d5d909b47a18977aa9d5ce36cee184c2000000001000000850500003082058130820469a00302010202103972443af922b751d7d36c10dd313595300d06092a864886f70d01010c0500307b310b3009060355040613024742311b301906035504080c1247726561746572204d616e636865737465723110300e06035504070c0753616c666f7264311a3018060355040a0c11436f6d6f646f204341204c696d697465643121301f06035504030c18414141204365727469666963617465205365727669636573301e170d3139303331323030303030305a170d3238313233313233353935395a308188310b3009060355040613025553311330110603550408130a4e6577204a6572736579311430120603550407130b4a65727365792043697479311e301c060355040a131554686520555345525452555354204e6574776f726b312e302c06035504031325555345525472757374205253412043657274696669636174696f6e20417574686f7269747930820222300d06092a864886f70d01010105000382020f003082020a028202010080126517360ec3db08b3d0ac570d76edcd27d34cad508361e2aa204d092d6409dcce899fcc3da9ecf6cfc1dcf1d3b1d67b3728112b47da39c6bc3a19b45fa6bd7d9da36342b676f2a93b2b91f8e26fd0ec162090093ee2e874c918b491d46264db7fa306f188186a90223cbcfe13f087147bf6e41f8ed4e451c61167460851cb8614543fbc33fe7e6c9cff169d18bd518e35a6a766c87267db2166b1d49b7803c0503ae8ccf0dcbc9e4cfeaf0596351f575ab7ffcef93db72cb6f654ddc8e7123a4dae4c8ab75c9ab4b7203dca7f2234ae7e3b68660144e7014e46539b3360f794be5337907343f332c353efdbaafe744e69c76b8c6093dec4c70cdfe132aecc933b517895678bee3d56fe0cd0690f1b0ff325266b336df76e47fa7343e57e0ea566b1297c3284635589c40dc19354301913acd37d37a7eb5d3a6c355cdb41d712daa9490bdfd8808a0993628eb566cf2588cd84b8b13fa4390fd9029eeb124c957cf36b05a95e1683ccb867e2e8139dcc5b82d34cb3ed5bffdee573ac233b2d00bf3555740949d849581a7f9236e651920ef3267d1c4d17bcc9ec4326d0bf415f40a94444f499e757879e501f5754a83efd74632fb1506509e658422e431a4cb4f0254759fa041e93d426464a5081b2debe78b7fc6715e1c957841e0f63d6e962bad65f552eea5cc62808042539b80e2ba9f24c971c073f0d52f5edef2f820f0203010001a381f23081ef301f0603551d23041830168014a0110a233e96f107ece2af29ef82a57fd030a4b4301d0603551d0e041604145379bf5aaa2b4acf5480e1d89bc09df2b20366cb300e0603551d0f0101ff040403020186300f0603551d130101ff040530030101ff30110603551d20040a300830060604551d200030430603551d1f043c303a3038a036a0348632687474703a2f2f63726c2e636f6d6f646f63612e636f6d2f414141436572746966696361746553657276696365732e63726c303406082b0601050507010104283026302406082b060105050730018618687474703a2f2f6f6373702e636f6d6f646f63612e636f6d300d06092a864886f70d01010c05000382010100188751dc74213d9c8ae027b733d02eccecf0e6cb5e11de226f9b758e9e72fee4d6feaa1f9c962def034a7eaef48d6f723c433bc03febb8df5caaa9c6aef2fcd8eea37b43f686367c14e0cdf4f73ffedeb8b48af09196fefd43647efdccd201a17d7df81919c9422b13bf588bbaa4a266047688914e0c8914cea24dc932b3bae8141abc71f15bf0410b98000a220310e50cb1f9cd923719ed3bf1e43ab6f945132675afbbaaef3f7b773bd2c402913d1900d3175c39db3f7b180d45cd9385962f5ddf59164f3f51bdd545183fed4a8ee80661742316b50d50732744477f105d892a6b853114c4e8a96a4c80bc6a78cfb87f8e7672990c9dfed7910816a1a35f95 QQ.exe -
Suspicious behavior: EnumeratesProcesses 2 IoCs
Processes:
QQ.exepid process 2356 QQ.exe 2356 QQ.exe -
Suspicious behavior: MapViewOfSection 5 IoCs
Processes:
SMKT_COPY20240604.exeQQ.exeQQ.exepid process 1760 SMKT_COPY20240604.exe 540 QQ.exe 2632 QQ.exe 2632 QQ.exe 2632 QQ.exe -
Suspicious use of AdjustPrivilegeToken 1 IoCs
Processes:
QQ.exedescription pid process Token: SeDebugPrivilege 1464 QQ.exe -
Suspicious use of SetWindowsHookEx 1 IoCs
Processes:
QQ.exepid process 2632 QQ.exe -
Suspicious use of WriteProcessMemory 64 IoCs
Processes:
SMKT_COPY20240604.exedescription pid process target process PID 1760 wrote to memory of 2688 1760 SMKT_COPY20240604.exe cmd.exe PID 1760 wrote to memory of 2688 1760 SMKT_COPY20240604.exe cmd.exe PID 1760 wrote to memory of 2688 1760 SMKT_COPY20240604.exe cmd.exe PID 1760 wrote to memory of 2688 1760 SMKT_COPY20240604.exe cmd.exe PID 1760 wrote to memory of 2832 1760 SMKT_COPY20240604.exe cmd.exe PID 1760 wrote to memory of 2832 1760 SMKT_COPY20240604.exe cmd.exe PID 1760 wrote to memory of 2832 1760 SMKT_COPY20240604.exe cmd.exe PID 1760 wrote to memory of 2832 1760 SMKT_COPY20240604.exe cmd.exe PID 1760 wrote to memory of 2248 1760 SMKT_COPY20240604.exe cmd.exe PID 1760 wrote to memory of 2248 1760 SMKT_COPY20240604.exe cmd.exe PID 1760 wrote to memory of 2248 1760 SMKT_COPY20240604.exe cmd.exe PID 1760 wrote to memory of 2248 1760 SMKT_COPY20240604.exe cmd.exe PID 1760 wrote to memory of 2124 1760 SMKT_COPY20240604.exe cmd.exe PID 1760 wrote to memory of 2124 1760 SMKT_COPY20240604.exe cmd.exe PID 1760 wrote to memory of 2124 1760 SMKT_COPY20240604.exe cmd.exe PID 1760 wrote to memory of 2124 1760 SMKT_COPY20240604.exe cmd.exe PID 1760 wrote to memory of 2720 1760 SMKT_COPY20240604.exe cmd.exe PID 1760 wrote to memory of 2720 1760 SMKT_COPY20240604.exe cmd.exe PID 1760 wrote to memory of 2720 1760 SMKT_COPY20240604.exe cmd.exe PID 1760 wrote to memory of 2720 1760 SMKT_COPY20240604.exe cmd.exe PID 1760 wrote to memory of 2500 1760 SMKT_COPY20240604.exe cmd.exe PID 1760 wrote to memory of 2500 1760 SMKT_COPY20240604.exe cmd.exe PID 1760 wrote to memory of 2500 1760 SMKT_COPY20240604.exe cmd.exe PID 1760 wrote to memory of 2500 1760 SMKT_COPY20240604.exe cmd.exe PID 1760 wrote to memory of 2960 1760 SMKT_COPY20240604.exe cmd.exe PID 1760 wrote to memory of 2960 1760 SMKT_COPY20240604.exe cmd.exe PID 1760 wrote to memory of 2960 1760 SMKT_COPY20240604.exe cmd.exe PID 1760 wrote to memory of 2960 1760 SMKT_COPY20240604.exe cmd.exe PID 1760 wrote to memory of 1564 1760 SMKT_COPY20240604.exe cmd.exe PID 1760 wrote to memory of 1564 1760 SMKT_COPY20240604.exe cmd.exe PID 1760 wrote to memory of 1564 1760 SMKT_COPY20240604.exe cmd.exe PID 1760 wrote to memory of 1564 1760 SMKT_COPY20240604.exe cmd.exe PID 1760 wrote to memory of 1496 1760 SMKT_COPY20240604.exe cmd.exe PID 1760 wrote to memory of 1496 1760 SMKT_COPY20240604.exe cmd.exe PID 1760 wrote to memory of 1496 1760 SMKT_COPY20240604.exe cmd.exe PID 1760 wrote to memory of 1496 1760 SMKT_COPY20240604.exe cmd.exe PID 1760 wrote to memory of 2532 1760 SMKT_COPY20240604.exe cmd.exe PID 1760 wrote to memory of 2532 1760 SMKT_COPY20240604.exe cmd.exe PID 1760 wrote to memory of 2532 1760 SMKT_COPY20240604.exe cmd.exe PID 1760 wrote to memory of 2532 1760 SMKT_COPY20240604.exe cmd.exe PID 1760 wrote to memory of 1764 1760 SMKT_COPY20240604.exe cmd.exe PID 1760 wrote to memory of 1764 1760 SMKT_COPY20240604.exe cmd.exe PID 1760 wrote to memory of 1764 1760 SMKT_COPY20240604.exe cmd.exe PID 1760 wrote to memory of 1764 1760 SMKT_COPY20240604.exe cmd.exe PID 1760 wrote to memory of 2376 1760 SMKT_COPY20240604.exe cmd.exe PID 1760 wrote to memory of 2376 1760 SMKT_COPY20240604.exe cmd.exe PID 1760 wrote to memory of 2376 1760 SMKT_COPY20240604.exe cmd.exe PID 1760 wrote to memory of 2376 1760 SMKT_COPY20240604.exe cmd.exe PID 1760 wrote to memory of 1856 1760 SMKT_COPY20240604.exe cmd.exe PID 1760 wrote to memory of 1856 1760 SMKT_COPY20240604.exe cmd.exe PID 1760 wrote to memory of 1856 1760 SMKT_COPY20240604.exe cmd.exe PID 1760 wrote to memory of 1856 1760 SMKT_COPY20240604.exe cmd.exe PID 1760 wrote to memory of 552 1760 SMKT_COPY20240604.exe cmd.exe PID 1760 wrote to memory of 552 1760 SMKT_COPY20240604.exe cmd.exe PID 1760 wrote to memory of 552 1760 SMKT_COPY20240604.exe cmd.exe PID 1760 wrote to memory of 552 1760 SMKT_COPY20240604.exe cmd.exe PID 1760 wrote to memory of 276 1760 SMKT_COPY20240604.exe cmd.exe PID 1760 wrote to memory of 276 1760 SMKT_COPY20240604.exe cmd.exe PID 1760 wrote to memory of 276 1760 SMKT_COPY20240604.exe cmd.exe PID 1760 wrote to memory of 276 1760 SMKT_COPY20240604.exe cmd.exe PID 1760 wrote to memory of 236 1760 SMKT_COPY20240604.exe cmd.exe PID 1760 wrote to memory of 236 1760 SMKT_COPY20240604.exe cmd.exe PID 1760 wrote to memory of 236 1760 SMKT_COPY20240604.exe cmd.exe PID 1760 wrote to memory of 236 1760 SMKT_COPY20240604.exe cmd.exe
Processes
-
C:\Users\Admin\AppData\Local\Temp\SMKT_COPY20240604.exe"C:\Users\Admin\AppData\Local\Temp\SMKT_COPY20240604.exe"1⤵
- Loads dropped DLL
- Suspicious use of NtSetInformationThreadHideFromDebugger
- Suspicious use of SetThreadContext
- Suspicious behavior: MapViewOfSection
- Suspicious use of WriteProcessMemory
-
C:\Windows\SysWOW64\cmd.execmd /c set /a "0x53^38"2⤵
-
C:\Windows\SysWOW64\cmd.execmd /c set /a "0x55^38"2⤵
-
C:\Windows\SysWOW64\cmd.execmd /c set /a "0x43^38"2⤵
-
C:\Windows\SysWOW64\cmd.execmd /c set /a "0x54^38"2⤵
-
C:\Windows\SysWOW64\cmd.execmd /c set /a "0x15^38"2⤵
-
C:\Windows\SysWOW64\cmd.execmd /c set /a "0x14^38"2⤵
-
C:\Windows\SysWOW64\cmd.execmd /c set /a "0x1C^38"2⤵
-
C:\Windows\SysWOW64\cmd.execmd /c set /a "0x1C^38"2⤵
-
C:\Windows\SysWOW64\cmd.execmd /c set /a "0x75^38"2⤵
-
C:\Windows\SysWOW64\cmd.execmd /c set /a "0x4E^38"2⤵
-
C:\Windows\SysWOW64\cmd.execmd /c set /a "0x49^38"2⤵
-
C:\Windows\SysWOW64\cmd.execmd /c set /a "0x51^38"2⤵
-
C:\Windows\SysWOW64\cmd.execmd /c set /a "0x71^38"2⤵
-
C:\Windows\SysWOW64\cmd.execmd /c set /a "0x4F^38"2⤵
-
C:\Windows\SysWOW64\cmd.execmd /c set /a "0x48^38"2⤵
-
C:\Windows\SysWOW64\cmd.execmd /c set /a "0x42^38"2⤵
-
C:\Windows\SysWOW64\cmd.execmd /c set /a "0x49^38"2⤵
-
C:\Windows\SysWOW64\cmd.execmd /c set /a "0x51^38"2⤵
-
C:\Windows\SysWOW64\cmd.execmd /c set /a "0x0E^38"2⤵
-
C:\Windows\SysWOW64\cmd.execmd /c set /a "0x4F^38"2⤵
-
C:\Windows\SysWOW64\cmd.execmd /c set /a "0x54^38"2⤵
-
C:\Windows\SysWOW64\cmd.execmd /c set /a "0x11^38"2⤵
-
C:\Windows\SysWOW64\cmd.execmd /c set /a "0x0A^38"2⤵
-
C:\Windows\SysWOW64\cmd.execmd /c set /a "0x4F^38"2⤵
-
C:\Windows\SysWOW64\cmd.execmd /c set /a "0x16^38"2⤵
-
C:\Windows\SysWOW64\cmd.execmd /c set /a "0x0F^38"2⤵
-
C:\Windows\SysWOW64\cmd.execmd /c set /a "0x5F^38"2⤵
-
C:\Windows\SysWOW64\cmd.execmd /c set /a "0x4B^38"2⤵
-
C:\Windows\SysWOW64\cmd.execmd /c set /a "0x55^38"2⤵
-
C:\Windows\SysWOW64\cmd.execmd /c set /a "0x50^38"2⤵
-
C:\Windows\SysWOW64\cmd.execmd /c set /a "0x45^38"2⤵
-
C:\Windows\SysWOW64\cmd.execmd /c set /a "0x54^38"2⤵
-
C:\Windows\SysWOW64\cmd.execmd /c set /a "0x52^38"2⤵
-
C:\Windows\SysWOW64\cmd.execmd /c set /a "0x08^38"2⤵
-
C:\Windows\SysWOW64\cmd.execmd /c set /a "0x42^38"2⤵
-
C:\Windows\SysWOW64\cmd.execmd /c set /a "0x4A^38"2⤵
-
C:\Windows\SysWOW64\cmd.execmd /c set /a "0x4A^38"2⤵
-
C:\Windows\SysWOW64\cmd.execmd /c set /a "0x1C^38"2⤵
-
C:\Windows\SysWOW64\cmd.execmd /c set /a "0x1C^38"2⤵
-
C:\Windows\SysWOW64\cmd.execmd /c set /a "0x79^38"2⤵
-
C:\Windows\SysWOW64\cmd.execmd /c set /a "0x49^38"2⤵
-
C:\Windows\SysWOW64\cmd.execmd /c set /a "0x56^38"2⤵
-
C:\Windows\SysWOW64\cmd.execmd /c set /a "0x43^38"2⤵
-
C:\Windows\SysWOW64\cmd.execmd /c set /a "0x48^38"2⤵
-
C:\Windows\SysWOW64\cmd.execmd /c set /a "0x0E^38"2⤵
-
C:\Windows\SysWOW64\cmd.execmd /c set /a "0x4B^38"2⤵
-
C:\Windows\SysWOW64\cmd.execmd /c set /a "0x06^38"2⤵
-
C:\Windows\SysWOW64\cmd.execmd /c set /a "0x54^38"2⤵
-
C:\Windows\SysWOW64\cmd.execmd /c set /a "0x12^38"2⤵
-
C:\Windows\SysWOW64\cmd.execmd /c set /a "0x0A^38"2⤵
-
C:\Windows\SysWOW64\cmd.execmd /c set /a "0x06^38"2⤵
-
C:\Windows\SysWOW64\cmd.execmd /c set /a "0x06^38"2⤵
-
C:\Windows\SysWOW64\cmd.execmd /c set /a "0x4F^38"2⤵
-
C:\Windows\SysWOW64\cmd.execmd /c set /a "0x06^38"2⤵
-
C:\Windows\SysWOW64\cmd.execmd /c set /a "0x16^38"2⤵
-
C:\Windows\SysWOW64\cmd.execmd /c set /a "0x5E^38"2⤵
-
C:\Windows\SysWOW64\cmd.execmd /c set /a "0x1E^38"2⤵
-
C:\Windows\SysWOW64\cmd.execmd /c set /a "0x16^38"2⤵
-
C:\Windows\SysWOW64\cmd.execmd /c set /a "0x16^38"2⤵
-
C:\Windows\SysWOW64\cmd.execmd /c set /a "0x16^38"2⤵
-
C:\Windows\SysWOW64\cmd.execmd /c set /a "0x0A^38"2⤵
-
C:\Windows\SysWOW64\cmd.execmd /c set /a "0x06^38"2⤵
-
C:\Windows\SysWOW64\cmd.execmd /c set /a "0x4F^38"2⤵
-
C:\Windows\SysWOW64\cmd.execmd /c set /a "0x06^38"2⤵
-
C:\Windows\SysWOW64\cmd.execmd /c set /a "0x16^38"2⤵
-
C:\Windows\SysWOW64\cmd.execmd /c set /a "0x5E^38"2⤵
-
C:\Windows\SysWOW64\cmd.execmd /c set /a "0x17^38"2⤵
-
C:\Windows\SysWOW64\cmd.execmd /c set /a "0x16^38"2⤵
-
C:\Windows\SysWOW64\cmd.execmd /c set /a "0x16^38"2⤵
-
C:\Windows\SysWOW64\cmd.execmd /c set /a "0x0F^38"2⤵
-
C:\Windows\SysWOW64\cmd.execmd /c set /a "0x4F^38"2⤵
-
C:\Windows\SysWOW64\cmd.execmd /c set /a "0x08^38"2⤵
-
C:\Windows\SysWOW64\cmd.execmd /c set /a "0x54^38"2⤵
-
C:\Windows\SysWOW64\cmd.execmd /c set /a "0x13^38"2⤵
-
C:\Windows\SysWOW64\cmd.execmd /c set /a "0x5F^38"2⤵
-
C:\Windows\SysWOW64\cmd.execmd /c set /a "0x6D^38"2⤵
-
C:\Windows\SysWOW64\cmd.execmd /c set /a "0x63^38"2⤵
-
C:\Windows\SysWOW64\cmd.execmd /c set /a "0x74^38"2⤵
-
C:\Windows\SysWOW64\cmd.execmd /c set /a "0x68^38"2⤵
-
C:\Windows\SysWOW64\cmd.execmd /c set /a "0x63^38"2⤵
-
C:\Windows\SysWOW64\cmd.execmd /c set /a "0x6A^38"2⤵
-
C:\Windows\SysWOW64\cmd.execmd /c set /a "0x15^38"2⤵
-
C:\Windows\SysWOW64\cmd.execmd /c set /a "0x14^38"2⤵
-
C:\Windows\SysWOW64\cmd.execmd /c set /a "0x1C^38"2⤵
-
C:\Windows\SysWOW64\cmd.execmd /c set /a "0x1C^38"2⤵
-
C:\Windows\SysWOW64\cmd.execmd /c set /a "0x70^38"2⤵
-
C:\Windows\SysWOW64\cmd.execmd /c set /a "0x4F^38"2⤵
-
C:\Windows\SysWOW64\cmd.execmd /c set /a "0x54^38"2⤵
-
C:\Windows\SysWOW64\cmd.execmd /c set /a "0x52^38"2⤵
-
C:\Windows\SysWOW64\cmd.execmd /c set /a "0x53^38"2⤵
-
C:\Windows\SysWOW64\cmd.execmd /c set /a "0x47^38"2⤵
-
C:\Windows\SysWOW64\cmd.execmd /c set /a "0x4A^38"2⤵
-
C:\Windows\SysWOW64\cmd.execmd /c set /a "0x67^38"2⤵
-
C:\Windows\SysWOW64\cmd.execmd /c set /a "0x4A^38"2⤵
-
C:\Windows\SysWOW64\cmd.execmd /c set /a "0x4A^38"2⤵
-
C:\Windows\SysWOW64\cmd.execmd /c set /a "0x49^38"2⤵
-
C:\Windows\SysWOW64\cmd.execmd /c set /a "0x45^38"2⤵
-
C:\Windows\SysWOW64\cmd.execmd /c set /a "0x63^38"2⤵
-
C:\Windows\SysWOW64\cmd.execmd /c set /a "0x5E^38"2⤵
-
C:\Windows\SysWOW64\cmd.execmd /c set /a "0x0E^38"2⤵
-
C:\Windows\SysWOW64\cmd.execmd /c set /a "0x4F^38"2⤵
-
C:\Windows\SysWOW64\cmd.execmd /c set /a "0x06^38"2⤵
-
C:\Windows\SysWOW64\cmd.execmd /c set /a "0x0B^38"2⤵
-
C:\Windows\SysWOW64\cmd.execmd /c set /a "0x17^38"2⤵
-
C:\Windows\SysWOW64\cmd.execmd /c set /a "0x0A^38"2⤵
-
C:\Windows\SysWOW64\cmd.execmd /c set /a "0x06^38"2⤵
-
C:\Windows\SysWOW64\cmd.execmd /c set /a "0x4F^38"2⤵
-
C:\Windows\SysWOW64\cmd.execmd /c set /a "0x06^38"2⤵
-
C:\Windows\SysWOW64\cmd.execmd /c set /a "0x16^38"2⤵
-
C:\Windows\SysWOW64\cmd.execmd /c set /a "0x0A^38"2⤵
-
C:\Windows\SysWOW64\cmd.execmd /c set /a "0x4F^38"2⤵
-
C:\Windows\SysWOW64\cmd.execmd /c set /a "0x06^38"2⤵
-
C:\Windows\SysWOW64\cmd.execmd /c set /a "0x15^38"2⤵
-
C:\Windows\SysWOW64\cmd.execmd /c set /a "0x12^38"2⤵
-
C:\Windows\SysWOW64\cmd.execmd /c set /a "0x13^38"2⤵
-
C:\Windows\SysWOW64\cmd.execmd /c set /a "0x12^38"2⤵
-
C:\Windows\SysWOW64\cmd.execmd /c set /a "0x13^38"2⤵
-
C:\Windows\SysWOW64\cmd.execmd /c set /a "0x10^38"2⤵
-
C:\Windows\SysWOW64\cmd.execmd /c set /a "0x10^38"2⤵
-
C:\Windows\SysWOW64\cmd.execmd /c set /a "0x12^38"2⤵
-
C:\Windows\SysWOW64\cmd.execmd /c set /a "0x0A^38"2⤵
-
C:\Windows\SysWOW64\cmd.execmd /c set /a "0x06^38"2⤵
-
C:\Windows\SysWOW64\cmd.execmd /c set /a "0x4F^38"2⤵
-
C:\Windows\SysWOW64\cmd.execmd /c set /a "0x06^38"2⤵
-
C:\Windows\SysWOW64\cmd.execmd /c set /a "0x16^38"2⤵
-
C:\Windows\SysWOW64\cmd.execmd /c set /a "0x5E^38"2⤵
-
C:\Windows\SysWOW64\cmd.execmd /c set /a "0x15^38"2⤵
-
C:\Windows\SysWOW64\cmd.execmd /c set /a "0x16^38"2⤵
-
C:\Windows\SysWOW64\cmd.execmd /c set /a "0x16^38"2⤵
-
C:\Windows\SysWOW64\cmd.execmd /c set /a "0x16^38"2⤵
-
C:\Windows\SysWOW64\cmd.execmd /c set /a "0x0A^38"2⤵
-
C:\Windows\SysWOW64\cmd.execmd /c set /a "0x06^38"2⤵
-
C:\Windows\SysWOW64\cmd.execmd /c set /a "0x4F^38"2⤵
-
C:\Windows\SysWOW64\cmd.execmd /c set /a "0x06^38"2⤵
-
C:\Windows\SysWOW64\cmd.execmd /c set /a "0x10^38"2⤵
-
C:\Windows\SysWOW64\cmd.execmd /c set /a "0x12^38"2⤵
-
C:\Windows\SysWOW64\cmd.execmd /c set /a "0x0F^38"2⤵
-
C:\Windows\SysWOW64\cmd.execmd /c set /a "0x56^38"2⤵
-
C:\Windows\SysWOW64\cmd.execmd /c set /a "0x08^38"2⤵
-
C:\Windows\SysWOW64\cmd.execmd /c set /a "0x54^38"2⤵
-
C:\Windows\SysWOW64\cmd.execmd /c set /a "0x12^38"2⤵
-
C:\Windows\SysWOW64\cmd.execmd /c set /a "0x5F^38"2⤵
-
C:\Windows\SysWOW64\cmd.execmd /c set /a "0x4B^38"2⤵
-
C:\Windows\SysWOW64\cmd.execmd /c set /a "0x55^38"2⤵
-
C:\Windows\SysWOW64\cmd.execmd /c set /a "0x50^38"2⤵
-
C:\Windows\SysWOW64\cmd.execmd /c set /a "0x45^38"2⤵
-
C:\Windows\SysWOW64\cmd.execmd /c set /a "0x54^38"2⤵
-
C:\Windows\SysWOW64\cmd.execmd /c set /a "0x52^38"2⤵
-
C:\Windows\SysWOW64\cmd.execmd /c set /a "0x1C^38"2⤵
-
C:\Windows\SysWOW64\cmd.execmd /c set /a "0x1C^38"2⤵
-
C:\Windows\SysWOW64\cmd.execmd /c set /a "0x79^38"2⤵
-
C:\Windows\SysWOW64\cmd.execmd /c set /a "0x4A^38"2⤵
-
C:\Windows\SysWOW64\cmd.execmd /c set /a "0x55^38"2⤵
-
C:\Windows\SysWOW64\cmd.execmd /c set /a "0x43^38"2⤵
-
C:\Windows\SysWOW64\cmd.execmd /c set /a "0x43^38"2⤵
-
C:\Windows\SysWOW64\cmd.execmd /c set /a "0x4D^38"2⤵
-
C:\Windows\SysWOW64\cmd.execmd /c set /a "0x0E^38"2⤵
-
C:\Windows\SysWOW64\cmd.execmd /c set /a "0x4F^38"2⤵
-
C:\Windows\SysWOW64\cmd.execmd /c set /a "0x06^38"2⤵
-
C:\Windows\SysWOW64\cmd.execmd /c set /a "0x54^38"2⤵
-
C:\Windows\SysWOW64\cmd.execmd /c set /a "0x13^38"2⤵
-
C:\Windows\SysWOW64\cmd.execmd /c set /a "0x0A^38"2⤵
-
C:\Windows\SysWOW64\cmd.execmd /c set /a "0x06^38"2⤵
-
C:\Windows\SysWOW64\cmd.execmd /c set /a "0x4F^38"2⤵
-
C:\Windows\SysWOW64\cmd.execmd /c set /a "0x06^38"2⤵
-
C:\Windows\SysWOW64\cmd.execmd /c set /a "0x11^38"2⤵
-
C:\Windows\SysWOW64\cmd.execmd /c set /a "0x17^38"2⤵
-
C:\Windows\SysWOW64\cmd.execmd /c set /a "0x1F^38"2⤵
-
C:\Windows\SysWOW64\cmd.execmd /c set /a "0x16^38"2⤵
-
C:\Windows\SysWOW64\cmd.execmd /c set /a "0x06^38"2⤵
-
C:\Windows\SysWOW64\cmd.execmd /c set /a "0x0A^38"2⤵
-
C:\Windows\SysWOW64\cmd.execmd /c set /a "0x06^38"2⤵
-
C:\Windows\SysWOW64\cmd.execmd /c set /a "0x4F^38"2⤵
-
C:\Windows\SysWOW64\cmd.execmd /c set /a "0x06^38"2⤵
-
C:\Windows\SysWOW64\cmd.execmd /c set /a "0x16^38"2⤵
-
C:\Windows\SysWOW64\cmd.execmd /c set /a "0x0F^38"2⤵
-
C:\Windows\SysWOW64\cmd.execmd /c set /a "0x4F^38"2⤵
-
C:\Windows\SysWOW64\cmd.execmd /c set /a "0x08^38"2⤵
-
C:\Windows\SysWOW64\cmd.execmd /c set /a "0x54^38"2⤵
-
C:\Windows\SysWOW64\cmd.execmd /c set /a "0x11^38"2⤵
-
C:\Windows\SysWOW64\cmd.execmd /c set /a "0x5F^38"2⤵
-
C:\Windows\SysWOW64\cmd.execmd /c set /a "0x4B^38"2⤵
-
C:\Windows\SysWOW64\cmd.execmd /c set /a "0x55^38"2⤵
-
C:\Windows\SysWOW64\cmd.execmd /c set /a "0x50^38"2⤵
-
C:\Windows\SysWOW64\cmd.execmd /c set /a "0x45^38"2⤵
-
C:\Windows\SysWOW64\cmd.execmd /c set /a "0x54^38"2⤵
-
C:\Windows\SysWOW64\cmd.execmd /c set /a "0x52^38"2⤵
-
C:\Windows\SysWOW64\cmd.execmd /c set /a "0x08^38"2⤵
-
C:\Windows\SysWOW64\cmd.execmd /c set /a "0x42^38"2⤵
-
C:\Windows\SysWOW64\cmd.execmd /c set /a "0x4A^38"2⤵
-
C:\Windows\SysWOW64\cmd.execmd /c set /a "0x4A^38"2⤵
-
C:\Windows\SysWOW64\cmd.execmd /c set /a "0x1C^38"2⤵
-
C:\Windows\SysWOW64\cmd.execmd /c set /a "0x1C^38"2⤵
-
C:\Windows\SysWOW64\cmd.execmd /c set /a "0x79^38"2⤵
-
C:\Windows\SysWOW64\cmd.execmd /c set /a "0x54^38"2⤵
-
C:\Windows\SysWOW64\cmd.execmd /c set /a "0x43^38"2⤵
-
C:\Windows\SysWOW64\cmd.execmd /c set /a "0x47^38"2⤵
-
C:\Windows\SysWOW64\cmd.execmd /c set /a "0x42^38"2⤵
-
C:\Windows\SysWOW64\cmd.execmd /c set /a "0x0E^38"2⤵
-
C:\Windows\SysWOW64\cmd.execmd /c set /a "0x4F^38"2⤵
-
C:\Windows\SysWOW64\cmd.execmd /c set /a "0x06^38"2⤵
-
C:\Windows\SysWOW64\cmd.execmd /c set /a "0x54^38"2⤵
-
C:\Windows\SysWOW64\cmd.execmd /c set /a "0x13^38"2⤵
-
C:\Windows\SysWOW64\cmd.execmd /c set /a "0x0A^38"2⤵
-
C:\Windows\SysWOW64\cmd.execmd /c set /a "0x06^38"2⤵
-
C:\Windows\SysWOW64\cmd.execmd /c set /a "0x4F^38"2⤵
-
C:\Windows\SysWOW64\cmd.execmd /c set /a "0x06^38"2⤵
-
C:\Windows\SysWOW64\cmd.execmd /c set /a "0x54^38"2⤵
-
C:\Windows\SysWOW64\cmd.execmd /c set /a "0x12^38"2⤵
-
C:\Windows\SysWOW64\cmd.execmd /c set /a "0x0A^38"2⤵
-
C:\Windows\SysWOW64\cmd.execmd /c set /a "0x06^38"2⤵
-
C:\Windows\SysWOW64\cmd.execmd /c set /a "0x4F^38"2⤵
-
C:\Windows\SysWOW64\cmd.execmd /c set /a "0x06^38"2⤵
-
C:\Windows\SysWOW64\cmd.execmd /c set /a "0x15^38"2⤵
-
C:\Windows\SysWOW64\cmd.execmd /c set /a "0x12^38"2⤵
-
C:\Windows\SysWOW64\cmd.execmd /c set /a "0x13^38"2⤵
-
C:\Windows\SysWOW64\cmd.execmd /c set /a "0x12^38"2⤵
-
C:\Windows\SysWOW64\cmd.execmd /c set /a "0x13^38"2⤵
-
C:\Windows\SysWOW64\cmd.execmd /c set /a "0x10^38"2⤵
-
C:\Windows\SysWOW64\cmd.execmd /c set /a "0x10^38"2⤵
-
C:\Windows\SysWOW64\cmd.execmd /c set /a "0x12^38"2⤵
-
C:\Windows\SysWOW64\cmd.execmd /c set /a "0x0F^38"2⤵
-
C:\Windows\SysWOW64\cmd.execmd /c set /a "0x5F^38"2⤵
-
C:\Windows\SysWOW64\cmd.execmd /c set /a "0x53^38"2⤵
-
C:\Windows\SysWOW64\cmd.execmd /c set /a "0x55^38"2⤵
-
C:\Windows\SysWOW64\cmd.execmd /c set /a "0x43^38"2⤵
-
C:\Windows\SysWOW64\cmd.execmd /c set /a "0x54^38"2⤵
-
C:\Windows\SysWOW64\cmd.execmd /c set /a "0x15^38"2⤵
-
C:\Windows\SysWOW64\cmd.execmd /c set /a "0x14^38"2⤵
-
C:\Windows\SysWOW64\cmd.execmd /c set /a "0x1C^38"2⤵
-
C:\Windows\SysWOW64\cmd.execmd /c set /a "0x1C^38"2⤵
-
C:\Windows\SysWOW64\cmd.execmd /c set /a "0x65^38"2⤵
-
C:\Windows\SysWOW64\cmd.execmd /c set /a "0x47^38"2⤵
-
C:\Windows\SysWOW64\cmd.execmd /c set /a "0x4A^38"2⤵
-
C:\Windows\SysWOW64\cmd.execmd /c set /a "0x4A^38"2⤵
-
C:\Windows\SysWOW64\cmd.execmd /c set /a "0x71^38"2⤵
-
C:\Windows\SysWOW64\cmd.execmd /c set /a "0x4F^38"2⤵
-
C:\Windows\SysWOW64\cmd.execmd /c set /a "0x48^38"2⤵
-
C:\Windows\SysWOW64\cmd.execmd /c set /a "0x42^38"2⤵
-
C:\Windows\SysWOW64\cmd.execmd /c set /a "0x49^38"2⤵
-
C:\Windows\SysWOW64\cmd.execmd /c set /a "0x51^38"2⤵
-
C:\Windows\SysWOW64\cmd.execmd /c set /a "0x76^38"2⤵
-
C:\Windows\SysWOW64\cmd.execmd /c set /a "0x54^38"2⤵
-
C:\Windows\SysWOW64\cmd.execmd /c set /a "0x49^38"2⤵
-
C:\Windows\SysWOW64\cmd.execmd /c set /a "0x45^38"2⤵
-
C:\Windows\SysWOW64\cmd.execmd /c set /a "0x67^38"2⤵
-
C:\Windows\SysWOW64\cmd.execmd /c set /a "0x0E^38"2⤵
-
C:\Windows\SysWOW64\cmd.execmd /c set /a "0x4F^38"2⤵
-
C:\Windows\SysWOW64\cmd.execmd /c set /a "0x06^38"2⤵
-
C:\Windows\SysWOW64\cmd.execmd /c set /a "0x54^38"2⤵
-
C:\Windows\SysWOW64\cmd.execmd /c set /a "0x12^38"2⤵
-
C:\Windows\SysWOW64\cmd.execmd /c set /a "0x06^38"2⤵
-
C:\Windows\SysWOW64\cmd.execmd /c set /a "0x0A^38"2⤵
-
C:\Windows\SysWOW64\cmd.execmd /c set /a "0x4F^38"2⤵
-
C:\Windows\SysWOW64\cmd.execmd /c set /a "0x06^38"2⤵
-
C:\Windows\SysWOW64\cmd.execmd /c set /a "0x16^38"2⤵
-
C:\Windows\SysWOW64\cmd.execmd /c set /a "0x0A^38"2⤵
-
C:\Windows\SysWOW64\cmd.execmd /c set /a "0x4F^38"2⤵
-
C:\Windows\SysWOW64\cmd.execmd /c set /a "0x06^38"2⤵
-
C:\Windows\SysWOW64\cmd.execmd /c set /a "0x16^38"2⤵
-
C:\Windows\SysWOW64\cmd.execmd /c set /a "0x0A^38"2⤵
-
C:\Windows\SysWOW64\cmd.execmd /c set /a "0x06^38"2⤵
-
C:\Windows\SysWOW64\cmd.execmd /c set /a "0x4F^38"2⤵
-
C:\Windows\SysWOW64\cmd.execmd /c set /a "0x06^38"2⤵
-
C:\Windows\SysWOW64\cmd.execmd /c set /a "0x16^38"2⤵
-
C:\Windows\SysWOW64\cmd.execmd /c set /a "0x0A^38"2⤵
-
C:\Windows\SysWOW64\cmd.execmd /c set /a "0x06^38"2⤵
-
C:\Windows\SysWOW64\cmd.execmd /c set /a "0x4F^38"2⤵
-
C:\Windows\SysWOW64\cmd.execmd /c set /a "0x06^38"2⤵
-
C:\Windows\SysWOW64\cmd.execmd /c set /a "0x16^38"2⤵
-
C:\Windows\SysWOW64\cmd.execmd /c set /a "0x0F^38"2⤵
-
C:\Windows\SysWOW64\cmd.execmd /c set /a "0x5F^38"2⤵
-
C:\Users\Admin\AppData\Local\Temp\SMKT_COPY20240604.exe"C:\Users\Admin\AppData\Local\Temp\SMKT_COPY20240604.exe"2⤵
- Adds Run key to start application
- Suspicious use of NtCreateThreadExHideFromDebugger
- Suspicious use of NtSetInformationThreadHideFromDebugger
- Modifies system certificate store
-
C:\Users\Admin\AppData\Roaming\QQ\QQ.exe"C:\Users\Admin\AppData\Roaming\QQ\QQ.exe"3⤵
- Executes dropped EXE
- Suspicious use of NtSetInformationThreadHideFromDebugger
- Suspicious use of SetThreadContext
- Suspicious behavior: MapViewOfSection
-
C:\Windows\SysWOW64\cmd.execmd /c set /a "0x53^38"4⤵
-
C:\Windows\SysWOW64\cmd.execmd /c set /a "0x55^38"4⤵
-
C:\Windows\SysWOW64\cmd.execmd /c set /a "0x43^38"4⤵
-
C:\Windows\SysWOW64\cmd.execmd /c set /a "0x54^38"4⤵
-
C:\Windows\SysWOW64\cmd.execmd /c set /a "0x15^38"4⤵
-
C:\Windows\SysWOW64\cmd.execmd /c set /a "0x14^38"4⤵
-
C:\Windows\SysWOW64\cmd.execmd /c set /a "0x1C^38"4⤵
-
C:\Windows\SysWOW64\cmd.execmd /c set /a "0x1C^38"4⤵
-
C:\Windows\SysWOW64\cmd.execmd /c set /a "0x75^38"4⤵
-
C:\Windows\SysWOW64\cmd.execmd /c set /a "0x4E^38"4⤵
-
C:\Windows\SysWOW64\cmd.execmd /c set /a "0x49^38"4⤵
-
C:\Windows\SysWOW64\cmd.execmd /c set /a "0x51^38"4⤵
-
C:\Windows\SysWOW64\cmd.execmd /c set /a "0x71^38"4⤵
-
C:\Windows\SysWOW64\cmd.execmd /c set /a "0x4F^38"4⤵
-
C:\Windows\SysWOW64\cmd.execmd /c set /a "0x48^38"4⤵
-
C:\Windows\SysWOW64\cmd.execmd /c set /a "0x42^38"4⤵
-
C:\Windows\SysWOW64\cmd.execmd /c set /a "0x49^38"4⤵
-
C:\Windows\SysWOW64\cmd.execmd /c set /a "0x51^38"4⤵
-
C:\Windows\SysWOW64\cmd.execmd /c set /a "0x0E^38"4⤵
-
C:\Windows\SysWOW64\cmd.execmd /c set /a "0x4F^38"4⤵
-
C:\Windows\SysWOW64\cmd.execmd /c set /a "0x54^38"4⤵
-
C:\Windows\SysWOW64\cmd.execmd /c set /a "0x11^38"4⤵
-
C:\Windows\SysWOW64\cmd.execmd /c set /a "0x0A^38"4⤵
-
C:\Windows\SysWOW64\cmd.execmd /c set /a "0x4F^38"4⤵
-
C:\Windows\SysWOW64\cmd.execmd /c set /a "0x16^38"4⤵
-
C:\Windows\SysWOW64\cmd.execmd /c set /a "0x0F^38"4⤵
-
C:\Windows\SysWOW64\cmd.execmd /c set /a "0x5F^38"4⤵
-
C:\Windows\SysWOW64\cmd.execmd /c set /a "0x4B^38"4⤵
-
C:\Windows\SysWOW64\cmd.execmd /c set /a "0x55^38"4⤵
-
C:\Windows\SysWOW64\cmd.execmd /c set /a "0x50^38"4⤵
-
C:\Windows\SysWOW64\cmd.execmd /c set /a "0x45^38"4⤵
-
C:\Windows\SysWOW64\cmd.execmd /c set /a "0x54^38"4⤵
-
C:\Windows\SysWOW64\cmd.execmd /c set /a "0x52^38"4⤵
-
C:\Windows\SysWOW64\cmd.execmd /c set /a "0x08^38"4⤵
-
C:\Windows\SysWOW64\cmd.execmd /c set /a "0x42^38"4⤵
-
C:\Windows\SysWOW64\cmd.execmd /c set /a "0x4A^38"4⤵
-
C:\Windows\SysWOW64\cmd.execmd /c set /a "0x4A^38"4⤵
-
C:\Windows\SysWOW64\cmd.execmd /c set /a "0x1C^38"4⤵
-
C:\Windows\SysWOW64\cmd.execmd /c set /a "0x1C^38"4⤵
-
C:\Windows\SysWOW64\cmd.execmd /c set /a "0x79^38"4⤵
-
C:\Windows\SysWOW64\cmd.execmd /c set /a "0x49^38"4⤵
-
C:\Windows\SysWOW64\cmd.execmd /c set /a "0x56^38"4⤵
-
C:\Windows\SysWOW64\cmd.execmd /c set /a "0x43^38"4⤵
-
C:\Windows\SysWOW64\cmd.execmd /c set /a "0x48^38"4⤵
-
C:\Windows\SysWOW64\cmd.execmd /c set /a "0x0E^38"4⤵
-
C:\Windows\SysWOW64\cmd.execmd /c set /a "0x4B^38"4⤵
-
C:\Windows\SysWOW64\cmd.execmd /c set /a "0x06^38"4⤵
-
C:\Windows\SysWOW64\cmd.execmd /c set /a "0x54^38"4⤵
-
C:\Windows\SysWOW64\cmd.execmd /c set /a "0x12^38"4⤵
-
C:\Windows\SysWOW64\cmd.execmd /c set /a "0x0A^38"4⤵
-
C:\Windows\SysWOW64\cmd.execmd /c set /a "0x06^38"4⤵
-
C:\Windows\SysWOW64\cmd.execmd /c set /a "0x06^38"4⤵
-
C:\Windows\SysWOW64\cmd.execmd /c set /a "0x4F^38"4⤵
-
C:\Windows\SysWOW64\cmd.execmd /c set /a "0x06^38"4⤵
-
C:\Windows\SysWOW64\cmd.execmd /c set /a "0x16^38"4⤵
-
C:\Windows\SysWOW64\cmd.execmd /c set /a "0x5E^38"4⤵
-
C:\Windows\SysWOW64\cmd.execmd /c set /a "0x1E^38"4⤵
-
C:\Windows\SysWOW64\cmd.execmd /c set /a "0x16^38"4⤵
-
C:\Windows\SysWOW64\cmd.execmd /c set /a "0x16^38"4⤵
-
C:\Windows\SysWOW64\cmd.execmd /c set /a "0x16^38"4⤵
-
C:\Windows\SysWOW64\cmd.execmd /c set /a "0x0A^38"4⤵
-
C:\Windows\SysWOW64\cmd.execmd /c set /a "0x06^38"4⤵
-
C:\Windows\SysWOW64\cmd.execmd /c set /a "0x4F^38"4⤵
-
C:\Windows\SysWOW64\cmd.execmd /c set /a "0x06^38"4⤵
-
C:\Windows\SysWOW64\cmd.execmd /c set /a "0x16^38"4⤵
-
C:\Windows\SysWOW64\cmd.execmd /c set /a "0x5E^38"4⤵
-
C:\Windows\SysWOW64\cmd.execmd /c set /a "0x17^38"4⤵
-
C:\Windows\SysWOW64\cmd.execmd /c set /a "0x16^38"4⤵
-
C:\Windows\SysWOW64\cmd.execmd /c set /a "0x16^38"4⤵
-
C:\Windows\SysWOW64\cmd.execmd /c set /a "0x0F^38"4⤵
-
C:\Windows\SysWOW64\cmd.execmd /c set /a "0x4F^38"4⤵
-
C:\Windows\SysWOW64\cmd.execmd /c set /a "0x08^38"4⤵
-
C:\Windows\SysWOW64\cmd.execmd /c set /a "0x54^38"4⤵
-
C:\Windows\SysWOW64\cmd.execmd /c set /a "0x13^38"4⤵
-
C:\Windows\SysWOW64\cmd.execmd /c set /a "0x5F^38"4⤵
-
C:\Windows\SysWOW64\cmd.execmd /c set /a "0x6D^38"4⤵
-
C:\Windows\SysWOW64\cmd.execmd /c set /a "0x63^38"4⤵
-
C:\Windows\SysWOW64\cmd.execmd /c set /a "0x74^38"4⤵
-
C:\Windows\SysWOW64\cmd.execmd /c set /a "0x68^38"4⤵
-
C:\Windows\SysWOW64\cmd.execmd /c set /a "0x63^38"4⤵
-
C:\Windows\SysWOW64\cmd.execmd /c set /a "0x6A^38"4⤵
-
C:\Windows\SysWOW64\cmd.execmd /c set /a "0x15^38"4⤵
-
C:\Windows\SysWOW64\cmd.execmd /c set /a "0x14^38"4⤵
-
C:\Windows\SysWOW64\cmd.execmd /c set /a "0x1C^38"4⤵
-
C:\Windows\SysWOW64\cmd.execmd /c set /a "0x1C^38"4⤵
-
C:\Windows\SysWOW64\cmd.execmd /c set /a "0x70^38"4⤵
-
C:\Windows\SysWOW64\cmd.execmd /c set /a "0x4F^38"4⤵
-
C:\Windows\SysWOW64\cmd.execmd /c set /a "0x54^38"4⤵
-
C:\Windows\SysWOW64\cmd.execmd /c set /a "0x52^38"4⤵
-
C:\Windows\SysWOW64\cmd.execmd /c set /a "0x53^38"4⤵
-
C:\Windows\SysWOW64\cmd.execmd /c set /a "0x47^38"4⤵
-
C:\Windows\SysWOW64\cmd.execmd /c set /a "0x4A^38"4⤵
-
C:\Windows\SysWOW64\cmd.execmd /c set /a "0x67^38"4⤵
-
C:\Windows\SysWOW64\cmd.execmd /c set /a "0x4A^38"4⤵
-
C:\Windows\SysWOW64\cmd.execmd /c set /a "0x4A^38"4⤵
-
C:\Windows\SysWOW64\cmd.execmd /c set /a "0x49^38"4⤵
-
C:\Windows\SysWOW64\cmd.execmd /c set /a "0x45^38"4⤵
-
C:\Windows\SysWOW64\cmd.execmd /c set /a "0x63^38"4⤵
-
C:\Windows\SysWOW64\cmd.execmd /c set /a "0x5E^38"4⤵
-
C:\Windows\SysWOW64\cmd.execmd /c set /a "0x0E^38"4⤵
-
C:\Windows\SysWOW64\cmd.execmd /c set /a "0x4F^38"4⤵
-
C:\Windows\SysWOW64\cmd.execmd /c set /a "0x06^38"4⤵
-
C:\Windows\SysWOW64\cmd.execmd /c set /a "0x0B^38"4⤵
-
C:\Windows\SysWOW64\cmd.execmd /c set /a "0x17^38"4⤵
-
C:\Windows\SysWOW64\cmd.execmd /c set /a "0x0A^38"4⤵
-
C:\Windows\SysWOW64\cmd.execmd /c set /a "0x06^38"4⤵
-
C:\Windows\SysWOW64\cmd.execmd /c set /a "0x4F^38"4⤵
-
C:\Windows\SysWOW64\cmd.execmd /c set /a "0x06^38"4⤵
-
C:\Windows\SysWOW64\cmd.execmd /c set /a "0x16^38"4⤵
-
C:\Windows\SysWOW64\cmd.execmd /c set /a "0x0A^38"4⤵
-
C:\Windows\SysWOW64\cmd.execmd /c set /a "0x4F^38"4⤵
-
C:\Windows\SysWOW64\cmd.execmd /c set /a "0x06^38"4⤵
-
C:\Windows\SysWOW64\cmd.execmd /c set /a "0x15^38"4⤵
-
C:\Windows\SysWOW64\cmd.execmd /c set /a "0x12^38"4⤵
-
C:\Windows\SysWOW64\cmd.execmd /c set /a "0x13^38"4⤵
-
C:\Windows\SysWOW64\cmd.execmd /c set /a "0x12^38"4⤵
-
C:\Windows\SysWOW64\cmd.execmd /c set /a "0x13^38"4⤵
-
C:\Windows\SysWOW64\cmd.execmd /c set /a "0x10^38"4⤵
-
C:\Windows\SysWOW64\cmd.execmd /c set /a "0x10^38"4⤵
-
C:\Windows\SysWOW64\cmd.execmd /c set /a "0x12^38"4⤵
-
C:\Windows\SysWOW64\cmd.execmd /c set /a "0x0A^38"4⤵
-
C:\Windows\SysWOW64\cmd.execmd /c set /a "0x06^38"4⤵
-
C:\Windows\SysWOW64\cmd.execmd /c set /a "0x4F^38"4⤵
-
C:\Windows\SysWOW64\cmd.execmd /c set /a "0x06^38"4⤵
-
C:\Windows\SysWOW64\cmd.execmd /c set /a "0x16^38"4⤵
-
C:\Windows\SysWOW64\cmd.execmd /c set /a "0x5E^38"4⤵
-
C:\Windows\SysWOW64\cmd.execmd /c set /a "0x15^38"4⤵
-
C:\Windows\SysWOW64\cmd.execmd /c set /a "0x16^38"4⤵
-
C:\Windows\SysWOW64\cmd.execmd /c set /a "0x16^38"4⤵
-
C:\Windows\SysWOW64\cmd.execmd /c set /a "0x16^38"4⤵
-
C:\Windows\SysWOW64\cmd.execmd /c set /a "0x0A^38"4⤵
-
C:\Windows\SysWOW64\cmd.execmd /c set /a "0x06^38"4⤵
-
C:\Windows\SysWOW64\cmd.execmd /c set /a "0x4F^38"4⤵
-
C:\Windows\SysWOW64\cmd.execmd /c set /a "0x06^38"4⤵
-
C:\Windows\SysWOW64\cmd.execmd /c set /a "0x10^38"4⤵
-
C:\Windows\SysWOW64\cmd.execmd /c set /a "0x12^38"4⤵
-
C:\Windows\SysWOW64\cmd.execmd /c set /a "0x0F^38"4⤵
-
C:\Windows\SysWOW64\cmd.execmd /c set /a "0x56^38"4⤵
-
C:\Windows\SysWOW64\cmd.execmd /c set /a "0x08^38"4⤵
-
C:\Windows\SysWOW64\cmd.execmd /c set /a "0x54^38"4⤵
-
C:\Windows\SysWOW64\cmd.execmd /c set /a "0x12^38"4⤵
-
C:\Windows\SysWOW64\cmd.execmd /c set /a "0x5F^38"4⤵
-
C:\Windows\SysWOW64\cmd.execmd /c set /a "0x4B^38"4⤵
-
C:\Windows\SysWOW64\cmd.execmd /c set /a "0x55^38"4⤵
-
C:\Windows\SysWOW64\cmd.execmd /c set /a "0x50^38"4⤵
-
C:\Windows\SysWOW64\cmd.execmd /c set /a "0x45^38"4⤵
-
C:\Windows\SysWOW64\cmd.execmd /c set /a "0x54^38"4⤵
-
C:\Windows\SysWOW64\cmd.execmd /c set /a "0x52^38"4⤵
-
C:\Windows\SysWOW64\cmd.execmd /c set /a "0x1C^38"4⤵
-
C:\Windows\SysWOW64\cmd.execmd /c set /a "0x1C^38"4⤵
-
C:\Windows\SysWOW64\cmd.execmd /c set /a "0x79^38"4⤵
-
C:\Windows\SysWOW64\cmd.execmd /c set /a "0x4A^38"4⤵
-
C:\Windows\SysWOW64\cmd.execmd /c set /a "0x55^38"4⤵
-
C:\Windows\SysWOW64\cmd.execmd /c set /a "0x43^38"4⤵
-
C:\Windows\SysWOW64\cmd.execmd /c set /a "0x43^38"4⤵
-
C:\Windows\SysWOW64\cmd.execmd /c set /a "0x4D^38"4⤵
-
C:\Windows\SysWOW64\cmd.execmd /c set /a "0x0E^38"4⤵
-
C:\Windows\SysWOW64\cmd.execmd /c set /a "0x4F^38"4⤵
-
C:\Windows\SysWOW64\cmd.execmd /c set /a "0x06^38"4⤵
-
C:\Windows\SysWOW64\cmd.execmd /c set /a "0x54^38"4⤵
-
C:\Windows\SysWOW64\cmd.execmd /c set /a "0x13^38"4⤵
-
C:\Windows\SysWOW64\cmd.execmd /c set /a "0x0A^38"4⤵
-
C:\Windows\SysWOW64\cmd.execmd /c set /a "0x06^38"4⤵
-
C:\Windows\SysWOW64\cmd.execmd /c set /a "0x4F^38"4⤵
-
C:\Windows\SysWOW64\cmd.execmd /c set /a "0x06^38"4⤵
-
C:\Windows\SysWOW64\cmd.execmd /c set /a "0x11^38"4⤵
-
C:\Windows\SysWOW64\cmd.execmd /c set /a "0x17^38"4⤵
-
C:\Windows\SysWOW64\cmd.execmd /c set /a "0x1F^38"4⤵
-
C:\Windows\SysWOW64\cmd.execmd /c set /a "0x16^38"4⤵
-
C:\Windows\SysWOW64\cmd.execmd /c set /a "0x06^38"4⤵
-
C:\Windows\SysWOW64\cmd.execmd /c set /a "0x0A^38"4⤵
-
C:\Windows\SysWOW64\cmd.execmd /c set /a "0x06^38"4⤵
-
C:\Windows\SysWOW64\cmd.execmd /c set /a "0x4F^38"4⤵
-
C:\Windows\SysWOW64\cmd.execmd /c set /a "0x06^38"4⤵
-
C:\Windows\SysWOW64\cmd.execmd /c set /a "0x16^38"4⤵
-
C:\Windows\SysWOW64\cmd.execmd /c set /a "0x0F^38"4⤵
-
C:\Windows\SysWOW64\cmd.execmd /c set /a "0x4F^38"4⤵
-
C:\Windows\SysWOW64\cmd.execmd /c set /a "0x08^38"4⤵
-
C:\Windows\SysWOW64\cmd.execmd /c set /a "0x54^38"4⤵
-
C:\Windows\SysWOW64\cmd.execmd /c set /a "0x11^38"4⤵
-
C:\Windows\SysWOW64\cmd.execmd /c set /a "0x5F^38"4⤵
-
C:\Windows\SysWOW64\cmd.execmd /c set /a "0x4B^38"4⤵
-
C:\Windows\SysWOW64\cmd.execmd /c set /a "0x55^38"4⤵
-
C:\Windows\SysWOW64\cmd.execmd /c set /a "0x50^38"4⤵
-
C:\Windows\SysWOW64\cmd.execmd /c set /a "0x45^38"4⤵
-
C:\Windows\SysWOW64\cmd.execmd /c set /a "0x54^38"4⤵
-
C:\Windows\SysWOW64\cmd.execmd /c set /a "0x52^38"4⤵
-
C:\Windows\SysWOW64\cmd.execmd /c set /a "0x08^38"4⤵
-
C:\Windows\SysWOW64\cmd.execmd /c set /a "0x42^38"4⤵
-
C:\Windows\SysWOW64\cmd.execmd /c set /a "0x4A^38"4⤵
-
C:\Windows\SysWOW64\cmd.execmd /c set /a "0x4A^38"4⤵
-
C:\Windows\SysWOW64\cmd.execmd /c set /a "0x1C^38"4⤵
-
C:\Windows\SysWOW64\cmd.execmd /c set /a "0x1C^38"4⤵
-
C:\Windows\SysWOW64\cmd.execmd /c set /a "0x79^38"4⤵
-
C:\Windows\SysWOW64\cmd.execmd /c set /a "0x54^38"4⤵
-
C:\Windows\SysWOW64\cmd.execmd /c set /a "0x43^38"4⤵
-
C:\Windows\SysWOW64\cmd.execmd /c set /a "0x47^38"4⤵
-
C:\Windows\SysWOW64\cmd.execmd /c set /a "0x42^38"4⤵
-
C:\Windows\SysWOW64\cmd.execmd /c set /a "0x0E^38"4⤵
-
C:\Windows\SysWOW64\cmd.execmd /c set /a "0x4F^38"4⤵
-
C:\Windows\SysWOW64\cmd.execmd /c set /a "0x06^38"4⤵
-
C:\Windows\SysWOW64\cmd.execmd /c set /a "0x54^38"4⤵
-
C:\Windows\SysWOW64\cmd.execmd /c set /a "0x13^38"4⤵
-
C:\Windows\SysWOW64\cmd.execmd /c set /a "0x0A^38"4⤵
-
C:\Windows\SysWOW64\cmd.execmd /c set /a "0x06^38"4⤵
-
C:\Windows\SysWOW64\cmd.execmd /c set /a "0x4F^38"4⤵
-
C:\Windows\SysWOW64\cmd.execmd /c set /a "0x06^38"4⤵
-
C:\Windows\SysWOW64\cmd.execmd /c set /a "0x54^38"4⤵
-
C:\Windows\SysWOW64\cmd.execmd /c set /a "0x12^38"4⤵
-
C:\Windows\SysWOW64\cmd.execmd /c set /a "0x0A^38"4⤵
-
C:\Windows\SysWOW64\cmd.execmd /c set /a "0x06^38"4⤵
-
C:\Windows\SysWOW64\cmd.execmd /c set /a "0x4F^38"4⤵
-
C:\Windows\SysWOW64\cmd.execmd /c set /a "0x06^38"4⤵
-
C:\Windows\SysWOW64\cmd.execmd /c set /a "0x15^38"4⤵
-
C:\Windows\SysWOW64\cmd.execmd /c set /a "0x12^38"4⤵
-
C:\Windows\SysWOW64\cmd.execmd /c set /a "0x13^38"4⤵
-
C:\Windows\SysWOW64\cmd.execmd /c set /a "0x12^38"4⤵
-
C:\Windows\SysWOW64\cmd.execmd /c set /a "0x13^38"4⤵
-
C:\Windows\SysWOW64\cmd.execmd /c set /a "0x10^38"4⤵
-
C:\Windows\SysWOW64\cmd.execmd /c set /a "0x10^38"4⤵
-
C:\Windows\SysWOW64\cmd.execmd /c set /a "0x12^38"4⤵
-
C:\Windows\SysWOW64\cmd.execmd /c set /a "0x0F^38"4⤵
-
C:\Windows\SysWOW64\cmd.execmd /c set /a "0x5F^38"4⤵
-
C:\Windows\SysWOW64\cmd.execmd /c set /a "0x53^38"4⤵
-
C:\Windows\SysWOW64\cmd.execmd /c set /a "0x55^38"4⤵
-
C:\Windows\SysWOW64\cmd.execmd /c set /a "0x43^38"4⤵
-
C:\Windows\SysWOW64\cmd.execmd /c set /a "0x54^38"4⤵
-
C:\Windows\SysWOW64\cmd.execmd /c set /a "0x15^38"4⤵
-
C:\Windows\SysWOW64\cmd.execmd /c set /a "0x14^38"4⤵
-
C:\Windows\SysWOW64\cmd.execmd /c set /a "0x1C^38"4⤵
-
C:\Windows\SysWOW64\cmd.execmd /c set /a "0x1C^38"4⤵
-
C:\Windows\SysWOW64\cmd.execmd /c set /a "0x65^38"4⤵
-
C:\Windows\SysWOW64\cmd.execmd /c set /a "0x47^38"4⤵
-
C:\Windows\SysWOW64\cmd.execmd /c set /a "0x4A^38"4⤵
-
C:\Windows\SysWOW64\cmd.execmd /c set /a "0x4A^38"4⤵
-
C:\Windows\SysWOW64\cmd.execmd /c set /a "0x71^38"4⤵
-
C:\Windows\SysWOW64\cmd.execmd /c set /a "0x4F^38"4⤵
-
C:\Windows\SysWOW64\cmd.execmd /c set /a "0x48^38"4⤵
-
C:\Windows\SysWOW64\cmd.execmd /c set /a "0x42^38"4⤵
-
C:\Windows\SysWOW64\cmd.execmd /c set /a "0x49^38"4⤵
-
C:\Windows\SysWOW64\cmd.execmd /c set /a "0x51^38"4⤵
-
C:\Windows\SysWOW64\cmd.execmd /c set /a "0x76^38"4⤵
-
C:\Windows\SysWOW64\cmd.execmd /c set /a "0x54^38"4⤵
-
C:\Windows\SysWOW64\cmd.execmd /c set /a "0x49^38"4⤵
-
C:\Windows\SysWOW64\cmd.execmd /c set /a "0x45^38"4⤵
-
C:\Windows\SysWOW64\cmd.execmd /c set /a "0x67^38"4⤵
-
C:\Windows\SysWOW64\cmd.execmd /c set /a "0x0E^38"4⤵
-
C:\Windows\SysWOW64\cmd.execmd /c set /a "0x4F^38"4⤵
-
C:\Windows\SysWOW64\cmd.execmd /c set /a "0x06^38"4⤵
-
C:\Windows\SysWOW64\cmd.execmd /c set /a "0x54^38"4⤵
-
C:\Windows\SysWOW64\cmd.execmd /c set /a "0x12^38"4⤵
-
C:\Windows\SysWOW64\cmd.execmd /c set /a "0x06^38"4⤵
-
C:\Windows\SysWOW64\cmd.execmd /c set /a "0x0A^38"4⤵
-
C:\Windows\SysWOW64\cmd.execmd /c set /a "0x4F^38"4⤵
-
C:\Windows\SysWOW64\cmd.execmd /c set /a "0x06^38"4⤵
-
C:\Windows\SysWOW64\cmd.execmd /c set /a "0x16^38"4⤵
-
C:\Windows\SysWOW64\cmd.execmd /c set /a "0x0A^38"4⤵
-
C:\Windows\SysWOW64\cmd.execmd /c set /a "0x4F^38"4⤵
-
C:\Windows\SysWOW64\cmd.execmd /c set /a "0x06^38"4⤵
-
C:\Windows\SysWOW64\cmd.execmd /c set /a "0x16^38"4⤵
-
C:\Windows\SysWOW64\cmd.execmd /c set /a "0x0A^38"4⤵
-
C:\Windows\SysWOW64\cmd.execmd /c set /a "0x06^38"4⤵
-
C:\Windows\SysWOW64\cmd.execmd /c set /a "0x4F^38"4⤵
-
C:\Windows\SysWOW64\cmd.execmd /c set /a "0x06^38"4⤵
-
C:\Windows\SysWOW64\cmd.execmd /c set /a "0x16^38"4⤵
-
C:\Windows\SysWOW64\cmd.execmd /c set /a "0x0A^38"4⤵
-
C:\Windows\SysWOW64\cmd.execmd /c set /a "0x06^38"4⤵
-
C:\Windows\SysWOW64\cmd.execmd /c set /a "0x4F^38"4⤵
-
C:\Windows\SysWOW64\cmd.execmd /c set /a "0x06^38"4⤵
-
C:\Windows\SysWOW64\cmd.execmd /c set /a "0x16^38"4⤵
-
C:\Windows\SysWOW64\cmd.execmd /c set /a "0x0F^38"4⤵
-
C:\Windows\SysWOW64\cmd.execmd /c set /a "0x5F^38"4⤵
-
C:\Users\Admin\AppData\Roaming\QQ\QQ.exe"C:\Users\Admin\AppData\Roaming\QQ\QQ.exe"4⤵
- Adds Run key to start application
- Suspicious use of NtCreateThreadExHideFromDebugger
- Suspicious use of NtSetInformationThreadHideFromDebugger
- Suspicious use of SetThreadContext
- Modifies system certificate store
- Suspicious behavior: MapViewOfSection
- Suspicious use of SetWindowsHookEx
-
C:\Users\Admin\AppData\Roaming\QQ\QQ.exeC:\Users\Admin\AppData\Roaming\QQ\QQ.exe /stext "C:\Users\Admin\AppData\Local\Temp\rvxwhusvevars"5⤵
- Executes dropped EXE
- Suspicious behavior: EnumeratesProcesses
-
C:\Users\Admin\AppData\Roaming\QQ\QQ.exeC:\Users\Admin\AppData\Roaming\QQ\QQ.exe /stext "C:\Users\Admin\AppData\Local\Temp\bxdhimdosdsecnfhl"5⤵
- Executes dropped EXE
- Accesses Microsoft Outlook accounts
-
C:\Users\Admin\AppData\Roaming\QQ\QQ.exeC:\Users\Admin\AppData\Roaming\QQ\QQ.exe /stext "C:\Users\Admin\AppData\Local\Temp\mrizjeoqolkjfttluxfx"5⤵
- Executes dropped EXE
- Suspicious use of AdjustPrivilegeToken
Network
MITRE ATT&CK Matrix ATT&CK v13
Replay Monitor
Loading Replay Monitor...
Downloads
-
C:\ProgramData\remcos\logs.datFilesize
144B
MD58943f5e4ccca1e44d93809d9e608b2d3
SHA101e83b9ec3148a4daa4f8f529f5c88637d18da00
SHA256abc58c226778428eb5497ba17c3422d97501906c1c3187412ef4a5d0383baf1a
SHA5126fd7d3c3ec482b9f119159affa7ef6a736c28da3edab6eddc121ce6c07cfab8c5dca6f69c35f776f47a912ee6034ce3e3b8f3b146aa0d71ad21838c71f70f76b
-
C:\Users\Admin\AppData\LocalLow\Microsoft\CryptnetUrlCache\Content\94308059B57B3142E455B38A6EB92015Filesize
70KB
MD549aebf8cbd62d92ac215b2923fb1b9f5
SHA11723be06719828dda65ad804298d0431f6aff976
SHA256b33efcb95235b98b48508e019afa4b7655e80cf071defabd8b2123fc8b29307f
SHA512bf86116b015fb56709516d686e168e7c9c68365136231cc51d0b6542ae95323a71d2c7acec84aad7dcecc2e410843f6d82a0a6d51b9acfc721a9c84fdd877b5b
-
C:\Users\Admin\AppData\Local\Temp\TarFD4A.tmpFilesize
181KB
MD54ea6026cf93ec6338144661bf1202cd1
SHA1a1dec9044f750ad887935a01430bf49322fbdcb7
SHA2568efbc21559ef8b1bcf526800d8070baad42474ce7198e26fa771dbb41a76b1d8
SHA5126c7e0980e39aacf4c3689802353f464a08cd17753bd210ee997e5f2a455deb4f287a9ef74d84579dbde49bc96213cd2b8b247723919c412ea980aa6e6bfe218b
-
\Users\Admin\AppData\Local\Temp\nst3026.tmp\System.dllFilesize
12KB
MD54add245d4ba34b04f213409bfe504c07
SHA1ef756d6581d70e87d58cc4982e3f4d18e0ea5b09
SHA2569111099efe9d5c9b391dc132b2faf0a3851a760d4106d5368e30ac744eb42706
SHA5121bd260cabe5ea3cefbbc675162f30092ab157893510f45a1b571489e03ebb2903c55f64f89812754d3fe03c8f10012b8078d1261a7e73ac1f87c82f714bce03d
-
\Users\Admin\AppData\Local\Temp\nst3026.tmp\nsExec.dllFilesize
7KB
MD5b4579bc396ace8cafd9e825ff63fe244
SHA132a87ed28a510e3b3c06a451d1f3d0ba9faf8d9c
SHA25601e72332362345c415a7edcb366d6a1b52be9ac6e946fb9da49785c140ba1a4b
SHA5123a76e0e259a0ca12275fed922ce6e01bdfd9e33ba85973e80101b8025ef9243f5e32461a113bbcc6aa75e40894bb5d3a42d6b21045517b6b3cf12d76b4cfa36a
-
memory/1464-1815-0x0000000000400000-0x0000000000424000-memory.dmpFilesize
144KB
-
memory/1464-1810-0x0000000000400000-0x0000000000424000-memory.dmpFilesize
144KB
-
memory/1464-1813-0x0000000000400000-0x0000000000424000-memory.dmpFilesize
144KB
-
memory/1464-1814-0x0000000000400000-0x0000000000424000-memory.dmpFilesize
144KB
-
memory/1464-1811-0x0000000000400000-0x0000000000424000-memory.dmpFilesize
144KB
-
memory/2180-961-0x0000000000470000-0x00000000014D2000-memory.dmpFilesize
16.4MB
-
memory/2180-960-0x0000000000470000-0x00000000014D2000-memory.dmpFilesize
16.4MB
-
memory/2180-959-0x00000000014E0000-0x00000000035D2000-memory.dmpFilesize
32.9MB
-
memory/2180-954-0x00000000014E0000-0x00000000035D2000-memory.dmpFilesize
32.9MB
-
memory/2356-1803-0x0000000000400000-0x0000000000478000-memory.dmpFilesize
480KB
-
memory/2356-1808-0x0000000000400000-0x0000000000478000-memory.dmpFilesize
480KB
-
memory/2356-1821-0x0000000000400000-0x0000000000478000-memory.dmpFilesize
480KB
-
memory/2356-1804-0x0000000000400000-0x0000000000478000-memory.dmpFilesize
480KB
-
memory/2356-1806-0x0000000000400000-0x0000000000478000-memory.dmpFilesize
480KB
-
memory/2520-1809-0x0000000000400000-0x0000000000462000-memory.dmpFilesize
392KB
-
memory/2520-1805-0x0000000000400000-0x0000000000462000-memory.dmpFilesize
392KB
-
memory/2520-1807-0x0000000000400000-0x0000000000462000-memory.dmpFilesize
392KB
-
memory/2520-1812-0x0000000000400000-0x0000000000462000-memory.dmpFilesize
392KB
-
memory/2520-1824-0x0000000000400000-0x0000000000462000-memory.dmpFilesize
392KB
-
memory/2632-1826-0x0000000034930000-0x0000000034949000-memory.dmpFilesize
100KB
-
memory/2632-1830-0x0000000034930000-0x0000000034949000-memory.dmpFilesize
100KB
-
memory/2632-1829-0x0000000034930000-0x0000000034949000-memory.dmpFilesize
100KB
-
memory/2632-1800-0x00000000014E0000-0x00000000035D2000-memory.dmpFilesize
32.9MB