e2ee_CacheClear
e2ee_CacheDecr
e2ee_CacheDelete
e2ee_CacheExists
e2ee_CacheGet
e2ee_CacheGetMulti
e2ee_CacheGetMultiText
e2ee_CacheGetText
e2ee_CacheIncr
e2ee_CacheSet
e2ee_CacheSetExpire
e2ee_CacheSetText
Behavioral task
behavioral1
Sample
935b96e440d09b97aa56911a89819776d808dc7228a4b4884e5e3890d04c355e.exe
Resource
win7-20240419-en
Target
935b96e440d09b97aa56911a89819776d808dc7228a4b4884e5e3890d04c355e
Size
9.5MB
MD5
210c45579d733b180a5db0237a800ae2
SHA1
7d6b40efbefc66fac828db1c268d01760f387fac
SHA256
935b96e440d09b97aa56911a89819776d808dc7228a4b4884e5e3890d04c355e
SHA512
eca415ced3d40141a7debabbc4fd581f87f334bbb38ed11fd2ce3e97119bc7bc36863dda69c91bfa4a2c9cfbd16af0887d90c3619ec3d4570ae8301ad33e9768
SSDEEP
196608:2bCLAxe5wV0dNnKCjU+Pto5TaJQKXbKnPSkq/cXyGredCc7jZYv+F:2bCn1NXA+PyTs1Xbp/cCGrsVvZYvC
Processes:
resource | yara_rule |
---|---|
sample | vmprotect |
Checks for missing Authenticode signature.
Processes:
resource |
---|
935b96e440d09b97aa56911a89819776d808dc7228a4b4884e5e3890d04c355e |
IMAGE_FILE_RELOCS_STRIPPED
IMAGE_FILE_EXECUTABLE_IMAGE
IMAGE_FILE_LINE_NUMS_STRIPPED
IMAGE_FILE_LOCAL_SYMS_STRIPPED
IMAGE_FILE_32BIT_MACHINE
RasGetConnectStatusA
GetVersionExA
GetVersion
VirtualQuery
LocalAlloc
LocalFree
GetModuleFileNameW
GetProcessAffinityMask
SetProcessAffinityMask
SetThreadAffinityMask
Sleep
ExitProcess
FreeLibrary
LoadLibraryA
GetModuleHandleA
GetProcAddress
GetWindowTextA
GetUserObjectInformationW
GetProcessWindowStation
GetUserObjectInformationW
SetStretchBltMode
mixerClose
DocumentPropertiesA
RegQueryValueA
ShellExecuteA
CoGetClassObject
SafeArrayPutElement
ImageList_SetBkColor
ord8
WSAAsyncSelect
HttpOpenRequestA
GetFileTitleA
WTSSendMessageW
e2ee_CacheClear
e2ee_CacheDecr
e2ee_CacheDelete
e2ee_CacheExists
e2ee_CacheGet
e2ee_CacheGetMulti
e2ee_CacheGetMultiText
e2ee_CacheGetText
e2ee_CacheIncr
e2ee_CacheSet
e2ee_CacheSetExpire
e2ee_CacheSetText
IMAGE_SCN_CNT_CODE
IMAGE_SCN_MEM_EXECUTE
IMAGE_SCN_MEM_READ
IMAGE_SCN_CNT_INITIALIZED_DATA
IMAGE_SCN_MEM_READ
IMAGE_SCN_CNT_INITIALIZED_DATA
IMAGE_SCN_MEM_READ
IMAGE_SCN_MEM_WRITE
IMAGE_SCN_CNT_CODE
IMAGE_SCN_CNT_INITIALIZED_DATA
IMAGE_SCN_MEM_EXECUTE
IMAGE_SCN_MEM_READ
IMAGE_SCN_CNT_CODE
IMAGE_SCN_CNT_INITIALIZED_DATA
IMAGE_SCN_MEM_EXECUTE
IMAGE_SCN_MEM_READ
IMAGE_SCN_CNT_INITIALIZED_DATA
IMAGE_SCN_MEM_READ