Report #8711 check_circle

  • Creation Date: March 5, 2020, 2:52 p.m.
  • Last Update: March 5, 2020, 9:16 p.m.
  • File: Diagnostico.exe
  • Results:
Binary
DLL
False cancel
Size
1.14MB
trid
76.6% Inno Setup installer
9.9% Win32 Executable Delphi generic
4.5% Win32 Dynamic Link Library
3.1% Win32 Executable
1.4% Win16/32 Executable Delphi generic
type
PE
wordsize
32
Subsystem
Windows GUI
Hashes
md5
ce0d80180fa0ee46d489dd39bc41a09a
sha1
bc01a6fb4ddc2e921782de86ad277e8aaa6638f0
crc32
0x29a8658
sha224
d03d6831117b2d3c9c404dcfbb4075249d7c94a5837016de186740db
sha256
c5b17e74f75c2d8f0f63a1901119bc93ee5eab65ed7a827a4138080b5718b942
sha384
d1a22e1cb724e8d838f972b642d314b4935f650d5b67a3b3401cb946baa3cac537b9cc71842f9edc37ed99fe5e965ba0
sha512
2ac01ea172ef34f91f0ccbf9464e9b8cb95bcb0070f626c89e3bff99ea91671bec15019064c070ee8de5f6302b0965aa4a6b24da9f17d176d06037e6b7c9a999
ssdeep
24576:v2UJ6HuF/WeuX5CY//oRhpZ6PFJ1sn+DPK7DRPU9I8YaXag:v2MVZuXkY/wRZksn+OPRMAaV
Community
Google
False cancel
HashLib
False cancel
YARA
Matches
domain, IP, Borland_Delphi_30_, CRC32_poly_Constant, escalate_priv, borland_delphi, Microsoft_Visual_Cpp_v50v60_MFC, win_files_operation, IsPE32, Borland_Delphi_v40_v50, win_token, contentis_base64, Borland_Delphi_40_additional, IsPacked, Borland_Delphi_40, IsWindowsGUI, Delphi_Copy, Borland_Delphi_Setup_Module, Borland_Delphi_DLL, url, win_registry, HasOverlay, Borland_Delphi_30_additional, Borland_Delphi_v30

Suspicious
True check_circle

Strings
List
<asmv3:windowsSettings xmlns="http://schemas.microsoft.com/SMI/2005/WindowsSettings">
t.Ht
ScI.us
l.IR
m.pE
A.KW
jinstall.exe
"d.Ua
P.rsrc
comctl32.dll
vYP2:SO{
]_GoT
oF,E
IS:w
r]sc
hI_Mf
'%u`4d&?ho
=hKgtMb
name="Microsoft.Windows.Common-Controls"
7%-iT
)%2oT
!%AR5
R%e^_
.A?|%gH
lzma: Compressed data is corrupted (%d)
Division by zero
PEFh
August September
O%hgN
Compressed block is corrupted
Compressed block is corrupted
Compressed block is corrupted
Too many open files
I/O error %d
Control Panel\Desktop\ResourceLocale
'%s' is not a valid time!'%s' is not a valid date and time
File I/O error %d
'%s' is not a valid date
This installation was built with Inno Setup.
.DEFAULT\Control Panel\International
SeShutdownPrivilege
<requestedPrivileges>
,DNSV
publicKeyToken="6595b64144ccf1df"
XS.IM]
ZmdNSr6
ECompressError
ECompressDataError
ECompressInternalError
TCustomDecompressor
TLZMADecompressor
No argument for format '%s'
Application Error1Format '%s' invalid or incompatible with argument
GetProcAddress
EPrivilege
Invalid class typecast0Access violation at address %p. %s of address %p
ExitProcess
!'%s' is not a valid integer value('%s' is not a valid floating point value
Operation aborted%Exception %s in module %s at %p.
GL.sb^
Write)Format result longer than 4096 characters
CreateProcessA
OpenProcessToken
This program must be run under Win32
VirtualAlloc
VirtualAlloc
eD20
NewInstance
VirtualProtect
LzmaDecode failed (%d)
WriteFile
LoadResource
WriteFile
GetModuleHandleA
CreateFileA
RegQueryValueExA
RegOpenKeyExA
SetFilePointer
RemoveDirectoryA
LoadLibraryA
SetFilePointer
GetModuleHandleA
CreateDirectoryA
GetModuleFileNameA
DeleteFileA
CreateFileA
Variant is not an array!Variant array index out of bounds
ReadFile
ReadFile
`d.bg
6aCD
ab8E
External exception %x
41aI
1*%/
;Y4o*H**b
?%/-
he }?{d
o7tG.wtk
Sleep

Foremost
Matches
0.exe, 52 KB
Suspicious
True check_circle
Heuristics
IPs
hasIPs: False cancel
Allowed
Suspicious
hasAllowed: False cancel
hasSuspicious: False cancel

URLs
Allowed: http://schemas.microsoft.com/smi/2005/windowssettings
hasURLs: True check_circle
Suspicious
hasAllowed: True check_circle
hasSuspicious: False cancel

Files
Allowed: user32.dll, comctl32.dll, advapi32.dll, oleaut32.dll, kernel32.dll, shell32.dll
hasFiles: True check_circle
Suspicious
hasAllowed: True check_circle
hasSuspicious: False cancel

Binary
Sizes
RVA
RVA: 16
Suspicious: False cancel
Code
Size: 17408
Suspicious: False cancel
Image
Address: 4194304
Suspicious: False cancel
Stack
Stack: 16384
Suspicious: False cancel
Headers
Headers: 1024
Suspicious: False cancel
Suspicious: False cancel

Symbols
Number
Number: 0
Suspicious: True check_circle
Pointer
Pointer: 0
Suspicious: True check_circle
Directories
Number: 16
Suspicious: False cancel

Checksum
Value: 0
Suspicous: True check_circle

Sections
Allowed: code, data, bss, .idata, .tls, .rdata, .reloc, .rsrc
Suspicious
hasAllowed: True check_circle
hasSections: True check_circle
hasSuspicious: False cancel

Versions
OS
Version: 1
Suspicious: False cancel
Image
Version: False cancel
Suspicious: 1
Linker
Version: 2.25
Suspicious: False cancel
Subsystem
Version: 4.0
Suspicious: False cancel
Suspicious: False cancel

EntryPoint
Address: 39512
Suspicious: False cancel

Anomalies
Anomalies: The header checksum and the calculated checksum do not match.
hasAnomalies: True check_circle

Libraries
Allowed: user32.dll, comctl32.dll, advapi32.dll, oleaut32.dll, kernel32.dll, shell32.dll
hasLibs: True check_circle
Suspicious
hasAllowed: True check_circle
hasSuspicious: False cancel

Timestamp
Past: True check_circle
Valid: True check_circle
Value: 1992-06-19 19:22:17
Future: False cancel

Compilation
Packed: False cancel
Missing: False cancel
Packers
Compiled: True check_circle
Compilers: Borland Delphi 3.0 (???), Borland Delphi 4.0

Obfuscation
XOR: False cancel
Fuzzing: False cancel

PEDetector
Matches
None
Suspicious
False cancel
Disassembly
hasTricks
True check_circle
Tricks
pushret
none: 4

pushpopmath
none: 4
.rsrc: 2

garbagebytes
none: 5

hookdetection
none: 3

fakeconditionaljumps
none: 1

programcontrolflowchange
none: 4

cpuinstructionsresultscomparison
none: 1
.rsrc: 3

AVclass
banbra
1
VirusTotal
md5
ce0d80180fa0ee46d489dd39bc41a09a
sha1
bc01a6fb4ddc2e921782de86ad277e8aaa6638f0
SCANS (DETECTION RATE = 50.00%)
AVG
result: Win32:Delf-TXR [Trj]
update: 20190606
version: 18.4.3895.0
detected: True check_circle

CMC
update: 20190321
version: 1.1.0.977
detected: False cancel

MAX
result: malware (ai score=87)
update: 20190606
version: 2018.9.12.1
detected: True check_circle

APEX
update: 20190606
version: 5.25
detected: False cancel

Bkav
update: 20190606
version: 1.3.0.10239
detected: False cancel

K7GW
update: 20190606
version: 11.48.31150
detected: False cancel

ALYac
update: 20190606
version: 1.1.1.5
detected: False cancel

Avast
result: Win32:Delf-TXR [Trj]
update: 20190606
version: 18.4.3895.0
detected: True check_circle

Avira
result: TR/Spy.Banker.xmawj
update: 20190606
version: 8.3.3.8
detected: True check_circle

Baidu
update: 20190318
version: 1.0.0.2
detected: False cancel

Cyren
update: 20190606
version: 6.2.0.1
detected: False cancel

DrWeb
result: Trojan.KillProc.33681
update: 20190606
version: 7.0.34.11020
detected: True check_circle

GData
result: Trojan.GenericKD.4771945
update: 20190606
version: A:25.22281B:25.15256
detected: True check_circle

Panda
result: Trj/CI.A
update: 20190606
version: 4.6.4.2
detected: True check_circle

VBA32
result: TrojanBanker.Banbra
update: 20190606
version: 4.0.0
detected: True check_circle

VIPRE
result: Trojan.Win32.Generic!BT
update: 20190606
version: 75512
detected: True check_circle

Zoner
update: 20190605
version: 1.0
detected: False cancel

ClamAV
update: 20190606
version: 0.101.2.0
detected: False cancel

Comodo
result: Malware@#3dpdaz4gis5tv
update: 20190606
version: 30981
detected: True check_circle

F-Prot
update: 20190606
version: 4.7.1.166
detected: False cancel

Ikarus
result: Trojan.SuspectCRC
update: 20190606
version: 0.1.5.2
detected: True check_circle

McAfee
result: Artemis!CE0D80180FA0
update: 20190606
version: 6.0.6.653
detected: True check_circle

Rising
result: Malware.Undefined!8.C (TFE:5:Kknee3dagLI)
update: 20190606
version: 25.0.0.24
detected: True check_circle

Sophos
result: Mal/Generic-S
update: 20190606
version: 4.98.0
detected: True check_circle

Yandex
result: Trojan.PWS.Banbra!pc3FCBetgRk
update: 20190606
version: 5.5.2.24
detected: True check_circle

Zillya
update: 20190606
version: 2.0.0.3827
detected: False cancel

Acronis
update: 20190605
version: 1.0.1.51
detected: False cancel

Alibaba
update: 20190527
version: 0.3.0.5
detected: False cancel

Arcabit
result: Trojan.Generic.D48D069
update: 20190606
version: 1.0.0.846
detected: True check_circle

Babable
update: 20190424
version: 9107201
detected: False cancel

Cylance
result: Unsafe
update: 20190606
version: 2.3.1.101
detected: True check_circle

Endgame
update: 20190522
version: 3.0.12
detected: False cancel

FireEye
result: Trojan.Generic.12338167
update: 20190606
version: 29.7.0.0
detected: True check_circle

TACHYON
update: 20190606
version: 2019-06-06.02
detected: False cancel

Tencent
result: Win32.Trojan-banker.Banbra.Syrt
update: 20190606
version: 1.0.0.1
detected: True check_circle

ViRobot
update: 20190606
version: 2014.3.20.0
detected: False cancel

Webroot
update: 20190606
version: 1.0.0.403
detected: False cancel

eGambit
update: 20190606
version: v4.3.6
detected: False cancel

Ad-Aware
update: 20190606
version: 3.0.5.370
detected: False cancel

AegisLab
result: Trojan.Win32.Banbra.7!c
update: 20190606
version: 4.2
detected: True check_circle

Emsisoft
result: Trojan.Generic.12338167 (B)
update: 20190606
version: 2018.4.0.1029
detected: True check_circle

F-Secure
result: Trojan.TR/Spy.Banker.xmawj
update: 20190606
version: 12.0.86.52
detected: True check_circle

Fortinet
result: W32/Banbra.ABSI!tr
update: 20190606
version: 5.4.247.0
detected: True check_circle

Invincea
update: 20190525
version: 6.3.6.26157
detected: False cancel

Jiangmin
update: 20190529
version: 16.0.100
detected: False cancel

Kingsoft
update: 20190606
version: 2013.8.14.323
detected: False cancel

Paloalto
result: generic.ml
update: 20190606
version: 1.0
detected: True check_circle

Symantec
result: Trojan.Gen
update: 20190606
version: 1.9.0.0
detected: True check_circle

AhnLab-V3
update: 20190606
version: 3.15.2.24317
detected: False cancel

Antiy-AVL
result: Trojan/Win32.TSGeneric
update: 20190606
version: 3.0.0.1
detected: True check_circle

Kaspersky
result: Trojan-Banker.Win32.Banbra.bioq
update: 20190606
version: 15.0.1.13
detected: True check_circle

Microsoft
result: TrojanSpy:Win32/Banker
update: 20190606
version: 1.1.16000.6
detected: True check_circle

Qihoo-360
result: Win32/Trojan.a08
update: 20190606
version: 1.0.0.1120
detected: True check_circle

TheHacker
update: 20190605
version: 6.8.0.5.4255
detected: False cancel

Trustlook
update: 20190606
version: 1.0
detected: False cancel

ZoneAlarm
result: Trojan-Banker.Win32.Banbra.bioq
update: 20190606
version: 1.0
detected: True check_circle

Cybereason
result: malicious.80fa0e
update: 20190417
version: 1.2.449
detected: True check_circle

ESET-NOD32
result: a variant of Win32/Spy.Banker.ABSI
update: 20190606
version: 19480
detected: True check_circle

TrendMicro
update: 20190606
version: 10.0.0.1040
detected: False cancel

BitDefender
result: Trojan.Generic.12338167
update: 20190606
version: 7.2
detected: True check_circle

CrowdStrike
update: 20190212
version: 1.0
detected: False cancel

K7AntiVirus
update: 20190606
version: 11.48.31150
detected: False cancel

SentinelOne
update: 20190604
version: 1.0.27.333
detected: False cancel

Avast-Mobile
update: 20190606
version: 190606-00
detected: False cancel

Malwarebytes
update: 20190606
version: 2.1.1.1115
detected: False cancel

TotalDefense
update: 20190606
version: 37.1.62.1
detected: False cancel

CAT-QuickHeal
update: 20190606
version: 14.00
detected: False cancel

NANO-Antivirus
result: Trojan.Win32.Banker.dlxllu
update: 20190606
version: 1.0.134.24826
detected: True check_circle

MicroWorld-eScan
result: Trojan.Generic.12338167
update: 20190606
version: 14.0.297.0
detected: True check_circle

SUPERAntiSpyware
update: 20190604
version: 5.6.0.1032
detected: False cancel

McAfee-GW-Edition
result: BehavesLike.Win32.AdwareFileTour.tc
update: 20190606
version: v2017.3010
detected: True check_circle

TrendMicro-HouseCall
update: 20190606
version: 10.0.0.1040
detected: False cancel

total
72
sha256
c5b17e74f75c2d8f0f63a1901119bc93ee5eab65ed7a827a4138080b5718b942
scan_id
c5b17e74f75c2d8f0f63a1901119bc93ee5eab65ed7a827a4138080b5718b942-1559855318
resource
ce0d80180fa0ee46d489dd39bc41a09a
positives
36
scan_date
2019-06-06 21:08:38
verbose_msg
Scan finished, information embedded
response_code
1
File
Trace
5/3/2020 - 20:45:43.684Open1480C:\malware.exeC:\dwmapi.dll
5/3/2020 - 20:45:43.684Open1480C:\malware.exeC:\Windows\SysWOW64\dwmapi.dll
5/3/2020 - 20:45:43.684Open1480C:\malware.exeC:\Windows\SysWOW64\dwmapi.dll
5/3/2020 - 20:45:43.684Open1480C:\malware.exeC:\Users\Behemot\AppData\Local\Temp\is-K29G0.tmp\malware.tmp
5/3/2020 - 20:45:43.684Unknown1480C:\malware.exeC:\Users\Behemot\AppData\Local\Temp\is-K29G0.tmp\malware.tmp
5/3/2020 - 20:45:43.684Open1480C:\malware.exeC:\Users\Behemot\AppData\Local\Temp\is-K29G0.tmp\malware.tmp
5/3/2020 - 20:45:43.684Unknown1480C:\malware.exeC:\Users\Behemot\AppData\Local\Temp\is-K29G0.tmp\malware.tmp
5/3/2020 - 20:45:43.684Open1480C:\malware.exeC:\Users\Behemot\AppData\Local\Temp\is-K29G0.tmp\malware.tmp
5/3/2020 - 20:45:43.684Write1480C:\malware.exeC:\Users\Behemot\AppData\Local\Temp\is-K29G0.tmp\malware.tmp
5/3/2020 - 20:45:43.715Unknown1480C:\malware.exeC:\Users\Behemot\AppData\Local\Temp\is-K29G0.tmp\malware.tmp
5/3/2020 - 20:45:43.715Open1480C:\malware.exeC:\Windows\SysWOW64\apphelp.dll
5/3/2020 - 20:45:43.715Open1480C:\malware.exeC:\Windows\SysWOW64\apphelp.dll
5/3/2020 - 20:45:43.715Open1480C:\malware.exeC:\Windows\AppPatch\sysmain.sdb
5/3/2020 - 20:45:43.715Open1480C:\malware.exeC:\Users\Behemot\AppData\Local\Temp\is-K29G0.tmp
5/3/2020 - 20:45:43.715Unknown1480C:\malware.exeC:\Users\Behemot\AppData\Local\Temp\is-K29G0.tmp
5/3/2020 - 20:45:43.715Open1480C:\malware.exeC:\Users\Behemot\AppData\Local\Temp\is-K29G0.tmp\malware.tmp
5/3/2020 - 20:45:43.715Unknown1480C:\malware.exeC:\Users\Behemot\AppData\Local\Temp\is-K29G0.tmp\malware.tmp
5/3/2020 - 20:45:43.715Open1480C:\malware.exeC:\
5/3/2020 - 20:45:43.715Unknown1480C:\malware.exeC:\
5/3/2020 - 20:45:43.715Open1480C:\malware.exeC:\Users
5/3/2020 - 20:45:43.715Unknown1480C:\malware.exeC:\Users
5/3/2020 - 20:45:43.715Open1480C:\malware.exeC:\Users\Behemot
5/3/2020 - 20:45:43.715Unknown1480C:\malware.exeC:\Users\Behemot
5/3/2020 - 20:45:43.715Open1480C:\malware.exeC:\Users\Behemot\AppData
5/3/2020 - 20:45:43.715Unknown1480C:\malware.exeC:\Users\Behemot\AppData
5/3/2020 - 20:45:43.715Open1480C:\malware.exeC:\Users\Behemot\AppData\Local
5/3/2020 - 20:45:43.715Unknown1480C:\malware.exeC:\Users\Behemot\AppData\Local
5/3/2020 - 20:45:43.715Open1480C:\malware.exeC:\Users\Behemot\AppData\Local\Temp
5/3/2020 - 20:45:43.715Unknown1480C:\malware.exeC:\Users\Behemot\AppData\Local\Temp
5/3/2020 - 20:45:43.715Open1480C:\malware.exeC:\Users\Behemot\AppData\Local\Temp\is-K29G0.tmp
5/3/2020 - 20:45:43.715Unknown1480C:\malware.exeC:\Users\Behemot\AppData\Local\Temp\is-K29G0.tmp
5/3/2020 - 20:45:43.715Open1480C:\malware.exeC:\Users\Behemot\AppData\Local\Temp\is-K29G0.tmp
5/3/2020 - 20:45:43.715Unknown1480C:\malware.exeC:\Users\Behemot\AppData\Local\Temp\is-K29G0.tmp
5/3/2020 - 20:45:43.715Open1480C:\malware.exeC:\Users\Behemot\AppData\Local\Temp\is-K29G0.tmp\malware.tmp
5/3/2020 - 20:45:43.715Read1480C:\malware.exeC:\Users\Behemot\AppData\Local\Temp\is-K29G0.tmp\malware.tmp
5/3/2020 - 20:45:43.731Open1480C:\malware.exeC:\Windows\AppPatch\sysmain.sdb
5/3/2020 - 20:45:43.731Open1480C:\malware.exeC:\Windows\AppPatch\sysmain.sdb
5/3/2020 - 20:45:43.809Open2076C:\Users\Behemot\AppData\Local\Temp\is-K29G0.tmp\malware.tmpC:\Windows\Prefetch\MALWARE.TMP-5148402A.pf
5/3/2020 - 20:45:43.809Open2076C:\Users\Behemot\AppData\Local\Temp\is-K29G0.tmp\malware.tmpC:\Windows
5/3/2020 - 20:45:43.809Open2076C:\Users\Behemot\AppData\Local\Temp\is-K29G0.tmp\malware.tmpC:\Windows\System32\wow64.dll
5/3/2020 - 20:45:43.809Open2076C:\Users\Behemot\AppData\Local\Temp\is-K29G0.tmp\malware.tmpC:\Windows\System32\wow64.dll
5/3/2020 - 20:45:43.809Open2076C:\Users\Behemot\AppData\Local\Temp\is-K29G0.tmp\malware.tmpC:\Windows\System32\wow64win.dll
5/3/2020 - 20:45:43.809Open2076C:\Users\Behemot\AppData\Local\Temp\is-K29G0.tmp\malware.tmpC:\Windows\System32\wow64win.dll
5/3/2020 - 20:45:43.809Open2076C:\Users\Behemot\AppData\Local\Temp\is-K29G0.tmp\malware.tmpC:\Windows\System32\wow64cpu.dll
5/3/2020 - 20:45:43.809Open2076C:\Users\Behemot\AppData\Local\Temp\is-K29G0.tmp\malware.tmpC:\Windows\System32\wow64cpu.dll
5/3/2020 - 20:45:43.809Open2076C:\Users\Behemot\AppData\Local\Temp\is-K29G0.tmp\malware.tmpC:\Windows\System32\wow64log.dll
5/3/2020 - 20:45:43.809Open2076C:\Users\Behemot\AppData\Local\Temp\is-K29G0.tmp\malware.tmpC:\Windows
5/3/2020 - 20:45:43.809Unknown2076C:\Users\Behemot\AppData\Local\Temp\is-K29G0.tmp\malware.tmpC:\Windows
5/3/2020 - 20:45:43.809Open2076C:\Users\Behemot\AppData\Local\Temp\is-K29G0.tmp\malware.tmpC:\Monitor
5/3/2020 - 20:45:43.809Open2076C:\Users\Behemot\AppData\Local\Temp\is-K29G0.tmp\malware.tmpC:\Windows\SysWOW64\sechost.dll
5/3/2020 - 20:45:43.809Open2076C:\Users\Behemot\AppData\Local\Temp\is-K29G0.tmp\malware.tmpC:\Windows\SysWOW64\sechost.dll
5/3/2020 - 20:45:43.809Open2076C:\Users\Behemot\AppData\Local\Temp\is-K29G0.tmp\malware.tmpC:\Users\Behemot\AppData\Local\Temp\is-K29G0.tmp\mpr.dll
5/3/2020 - 20:45:43.809Open2076C:\Users\Behemot\AppData\Local\Temp\is-K29G0.tmp\malware.tmpC:\Windows\SysWOW64\mpr.dll
5/3/2020 - 20:45:43.809Open2076C:\Users\Behemot\AppData\Local\Temp\is-K29G0.tmp\malware.tmpC:\Windows\SysWOW64\mpr.dll
5/3/2020 - 20:45:43.809Open2076C:\Users\Behemot\AppData\Local\Temp\is-K29G0.tmp\malware.tmpC:\Users\Behemot\AppData\Local\Temp\is-K29G0.tmp\version.dll
5/3/2020 - 20:45:43.809Open2076C:\Users\Behemot\AppData\Local\Temp\is-K29G0.tmp\malware.tmpC:\Windows\SysWOW64\version.dll
5/3/2020 - 20:45:43.809Open2076C:\Users\Behemot\AppData\Local\Temp\is-K29G0.tmp\malware.tmpC:\Windows\SysWOW64\version.dll
5/3/2020 - 20:45:43.809Open2076C:\Users\Behemot\AppData\Local\Temp\is-K29G0.tmp\malware.tmpC:\Users\Behemot\AppData\Local\Temp\is-K29G0.tmp\malware.tmp.Local
5/3/2020 - 20:45:43.809Open2076C:\Users\Behemot\AppData\Local\Temp\is-K29G0.tmp\malware.tmpC:\Windows\winsxs\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.18837_none_41e855142bd5705d
5/3/2020 - 20:45:43.809Unknown2076C:\Users\Behemot\AppData\Local\Temp\is-K29G0.tmp\malware.tmpC:\Windows\winsxs\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.18837_none_41e855142bd5705d
5/3/2020 - 20:45:43.809Open2076C:\Users\Behemot\AppData\Local\Temp\is-K29G0.tmp\malware.tmpC:\Windows\winsxs\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.18837_none_41e855142bd5705d
5/3/2020 - 20:45:43.809Open2076C:\Users\Behemot\AppData\Local\Temp\is-K29G0.tmp\malware.tmpC:\Windows\winsxs\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.18837_none_41e855142bd5705d\comctl32.dll
5/3/2020 - 20:45:43.809Open2076C:\Users\Behemot\AppData\Local\Temp\is-K29G0.tmp\malware.tmpC:\Windows\winsxs\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.18837_none_41e855142bd5705d\comctl32.dll
5/3/2020 - 20:45:43.809Open2076C:\Users\Behemot\AppData\Local\Temp\is-K29G0.tmp\malware.tmpC:\Windows\SysWOW64\imm32.dll
5/3/2020 - 20:45:43.809Open2076C:\Users\Behemot\AppData\Local\Temp\is-K29G0.tmp\malware.tmpC:\Windows\SysWOW64\imm32.dll
5/3/2020 - 20:45:43.809Open2076C:\Users\Behemot\AppData\Local\Temp\is-K29G0.tmp\malware.tmpC:\Windows\SysWOW64\imm32.dll
5/3/2020 - 20:45:43.809Open2076C:\Users\Behemot\AppData\Local\Temp\is-K29G0.tmp\malware.tmpC:\Windows\SysWOW64\imm32.dll
5/3/2020 - 20:45:43.809Open2076C:\Users\Behemot\AppData\Local\Temp\is-K29G0.tmp\malware.tmpC:\Windows\SysWOW64\imm32.dll
5/3/2020 - 20:45:43.809Open2076C:\Users\Behemot\AppData\Local\Temp\is-K29G0.tmp\malware.tmpC:\Windows\SysWOW64\imm32.dll
5/3/2020 - 20:45:43.809Open2076C:\Users\Behemot\AppData\Local\Temp\is-K29G0.tmp\malware.tmpC:\Windows\WindowsShell.Manifest
5/3/2020 - 20:45:43.809Unknown2076C:\Users\Behemot\AppData\Local\Temp\is-K29G0.tmp\malware.tmpC:\Windows\WindowsShell.ManifestWindowsShell.Manifest
5/3/2020 - 20:45:43.809Open2076C:\Users\Behemot\AppData\Local\Temp\is-K29G0.tmp\malware.tmpC:\Windows\SysWOW64\uxtheme.dll
5/3/2020 - 20:45:43.809Open2076C:\Users\Behemot\AppData\Local\Temp\is-K29G0.tmp\malware.tmpC:\Windows\SysWOW64\uxtheme.dll
5/3/2020 - 20:45:43.887Open2076C:\Users\Behemot\AppData\Local\Temp\is-K29G0.tmp\malware.tmpC:\Users\Behemot\AppData\Local\Temp\is-K29G0.tmp\dwmapi.dll
5/3/2020 - 20:45:43.887Open2076C:\Users\Behemot\AppData\Local\Temp\is-K29G0.tmp\malware.tmpC:\Windows\SysWOW64\dwmapi.dll
5/3/2020 - 20:45:43.887Open2076C:\Users\Behemot\AppData\Local\Temp\is-K29G0.tmp\malware.tmpC:\Windows\SysWOW64\dwmapi.dll
5/3/2020 - 20:45:43.887Open2076C:\Users\Behemot\AppData\Local\Temp\is-K29G0.tmp\malware.tmpC:\Windows\Fonts\StaticCache.dat
5/3/2020 - 20:45:43.887Read2076C:\Users\Behemot\AppData\Local\Temp\is-K29G0.tmp\malware.tmpC:\Windows\Fonts\StaticCache.datStaticCache.dat
5/3/2020 - 20:45:43.887Open2076C:\Users\Behemot\AppData\Local\Temp\is-K29G0.tmp\malware.tmpC:\Windows\SysWOW64\ole32.dll
5/3/2020 - 20:45:43.887Open2076C:\Users\Behemot\AppData\Local\Temp\is-K29G0.tmp\malware.tmpC:\Windows\SysWOW64\ole32.dll
5/3/2020 - 20:45:43.887Open2076C:\Users\Behemot\AppData\Local\Temp\is-K29G0.tmp\malware.tmpC:\Windows\SysWOW64\rpcss.dll
5/3/2020 - 20:45:43.887Open2076C:\Users\Behemot\AppData\Local\Temp\is-K29G0.tmp\malware.tmpC:\Windows\SysWOW64\rpcss.dll
5/3/2020 - 20:45:43.887Open2076C:\Users\Behemot\AppData\Local\Temp\is-K29G0.tmp\malware.tmpC:\Windows\Globalization\Sorting\SortDefault.nls
5/3/2020 - 20:45:43.887Unknown2076C:\Users\Behemot\AppData\Local\Temp\is-K29G0.tmp\malware.tmpC:\Windows\Globalization\Sorting\SortDefault.nlsSortDefault.nls
5/3/2020 - 20:45:43.887Open2076C:\Users\Behemot\AppData\Local\Temp\is-K29G0.tmp\malware.tmpC:\Windows\SysWOW64\pt-BR\KernelBase.dll.mui
5/3/2020 - 20:45:43.887Open2076C:\Users\Behemot\AppData\Local\Temp\is-K29G0.tmp\malware.tmpC:\Windows\syswow64\pt\KERNELBASE.dll.mui
5/3/2020 - 20:45:43.887Open2076C:\Users\Behemot\AppData\Local\Temp\is-K29G0.tmp\malware.tmpC:\Windows\SysWOW64\en-US\KERNELBASE.dll.mui
5/3/2020 - 20:45:43.887Open2076C:\Users\Behemot\AppData\Local\Temp\is-K29G0.tmp\malware.tmpC:\Windows\SysWOW64\en\KERNELBASE.dll.mui
5/3/2020 - 20:45:43.887Open2076C:\Users\Behemot\AppData\Local\Temp\is-K29G0.tmp\malware.tmpC:\Users\Behemot\AppData\Local\Temp\is-K29G0.tmp\netmsg.dll
5/3/2020 - 20:45:43.887Open2076C:\Users\Behemot\AppData\Local\Temp\is-K29G0.tmp\malware.tmpC:\Windows\SysWOW64\netmsg.dll
5/3/2020 - 20:45:43.887Open2076C:\Users\Behemot\AppData\Local\Temp\is-K29G0.tmp\malware.tmpC:\Windows\SysWOW64\netmsg.dll
5/3/2020 - 20:45:43.887Open2076C:\Users\Behemot\AppData\Local\Temp\is-K29G0.tmp\malware.tmpC:\Users\Behemot\AppData\Local\Temp\is-K29G0.tmp\malware.tmp
5/3/2020 - 20:45:43.887Read2076C:\Users\Behemot\AppData\Local\Temp\is-K29G0.tmp\malware.tmpC:\Users\Behemot\AppData\Local\Temp\is-K29G0.tmp\malware.tmp
5/3/2020 - 20:45:43.887Open2076C:\Users\Behemot\AppData\Local\Temp\is-K29G0.tmp\malware.tmpC:\malware.exe
5/3/2020 - 20:45:43.887Read2076C:\Users\Behemot\AppData\Local\Temp\is-K29G0.tmp\malware.tmpC:\malware.exe
5/3/2020 - 20:45:43.887Read2076C:\Users\Behemot\AppData\Local\Temp\is-K29G0.tmp\malware.tmpC:\malware.exe
5/3/2020 - 20:45:43.887Read2076C:\Users\Behemot\AppData\Local\Temp\is-K29G0.tmp\malware.tmpC:\malware.exe
5/3/2020 - 20:45:43.887Read2076C:\Users\Behemot\AppData\Local\Temp\is-K29G0.tmp\malware.tmpC:\malware.exe
5/3/2020 - 20:45:43.887Read2076C:\Users\Behemot\AppData\Local\Temp\is-K29G0.tmp\malware.tmpC:\malware.exe
5/3/2020 - 20:45:43.903Read2076C:\Users\Behemot\AppData\Local\Temp\is-K29G0.tmp\malware.tmpC:\malware.exe
5/3/2020 - 20:45:43.903Read2076C:\Users\Behemot\AppData\Local\Temp\is-K29G0.tmp\malware.tmpC:\malware.exe
5/3/2020 - 20:45:43.903Read2076C:\Users\Behemot\AppData\Local\Temp\is-K29G0.tmp\malware.tmpC:\malware.exe
5/3/2020 - 20:45:43.903Read2076C:\Users\Behemot\AppData\Local\Temp\is-K29G0.tmp\malware.tmpC:\malware.exe
5/3/2020 - 20:45:43.903Read2076C:\Users\Behemot\AppData\Local\Temp\is-K29G0.tmp\malware.tmpC:\malware.exe
5/3/2020 - 20:45:43.903Read2076C:\Users\Behemot\AppData\Local\Temp\is-K29G0.tmp\malware.tmpC:\malware.exe
5/3/2020 - 20:45:43.903Unknown2076C:\Users\Behemot\AppData\Local\Temp\is-K29G0.tmp\malware.tmpC:\malware.exe
5/3/2020 - 20:45:43.903Open2076C:\Users\Behemot\AppData\Local\Temp\is-K29G0.tmp\malware.tmpC:\Users\Behemot\AppData\Local\Temp
5/3/2020 - 20:45:43.903Unknown2076C:\Users\Behemot\AppData\Local\Temp\is-K29G0.tmp\malware.tmpC:\Users\Behemot\AppData\Local\Temp
5/3/2020 - 20:45:43.903Open2076C:\Users\Behemot\AppData\Local\Temp\is-K29G0.tmp\malware.tmpC:\Users\Behemot\AppData\Local\Temp\is-DBPUD.tmp
5/3/2020 - 20:45:43.903Open2076C:\Users\Behemot\AppData\Local\Temp\is-K29G0.tmp\malware.tmpC:\Users\Behemot\AppData\Local\Temp\is-DBPUD.tmp
5/3/2020 - 20:45:43.903Unknown2076C:\Users\Behemot\AppData\Local\Temp\is-K29G0.tmp\malware.tmpC:\Users\Behemot\AppData\Local\Temp\is-DBPUD.tmp
5/3/2020 - 20:45:43.903Open2076C:\Users\Behemot\AppData\Local\Temp\is-K29G0.tmp\malware.tmpC:\Users\Behemot\AppData\Local\Temp\is-DBPUD.tmp\_isetup
5/3/2020 - 20:45:43.903Unknown2076C:\Users\Behemot\AppData\Local\Temp\is-K29G0.tmp\malware.tmpC:\Users\Behemot\AppData\Local\Temp\is-DBPUD.tmp\_isetup
5/3/2020 - 20:45:43.903Open2076C:\Users\Behemot\AppData\Local\Temp\is-K29G0.tmp\malware.tmpC:\Users\Behemot\AppData\Local\Temp\is-DBPUD.tmp\_isetup\_RegDLL.tmp
5/3/2020 - 20:45:43.903Write2076C:\Users\Behemot\AppData\Local\Temp\is-K29G0.tmp\malware.tmpC:\Users\Behemot\AppData\Local\Temp\is-DBPUD.tmp\_isetup\_RegDLL.tmp
5/3/2020 - 20:45:43.903Unknown2076C:\Users\Behemot\AppData\Local\Temp\is-K29G0.tmp\malware.tmpC:\Users\Behemot\AppData\Local\Temp\is-DBPUD.tmp\_isetup\_RegDLL.tmp
5/3/2020 - 20:45:43.903Open2076C:\Users\Behemot\AppData\Local\Temp\is-K29G0.tmp\malware.tmpC:\Users\Behemot\AppData\Local\Temp\is-DBPUD.tmp\_isetup\_setup64.tmp
5/3/2020 - 20:45:43.903Write2076C:\Users\Behemot\AppData\Local\Temp\is-K29G0.tmp\malware.tmpC:\Users\Behemot\AppData\Local\Temp\is-DBPUD.tmp\_isetup\_setup64.tmp
5/3/2020 - 20:45:43.903Unknown2076C:\Users\Behemot\AppData\Local\Temp\is-K29G0.tmp\malware.tmpC:\Users\Behemot\AppData\Local\Temp\is-DBPUD.tmp\_isetup\_setup64.tmp
5/3/2020 - 20:45:43.903Open2076C:\Users\Behemot\AppData\Local\Temp\is-K29G0.tmp\malware.tmpC:\Users\Behemot\AppData\Local\Temp\is-DBPUD.tmp\_isetup\_shfoldr.dll
5/3/2020 - 20:45:43.903Write2076C:\Users\Behemot\AppData\Local\Temp\is-K29G0.tmp\malware.tmpC:\Users\Behemot\AppData\Local\Temp\is-DBPUD.tmp\_isetup\_shfoldr.dll
5/3/2020 - 20:45:43.903Unknown2076C:\Users\Behemot\AppData\Local\Temp\is-K29G0.tmp\malware.tmpC:\Users\Behemot\AppData\Local\Temp\is-DBPUD.tmp\_isetup\_shfoldr.dll
5/3/2020 - 20:45:43.903Open2076C:\Users\Behemot\AppData\Local\Temp\is-K29G0.tmp\malware.tmpC:\Users\Behemot\AppData\Local\Temp\is-DBPUD.tmp\_isetup\_shfoldr.dll
5/3/2020 - 20:45:43.903Unknown2076C:\Users\Behemot\AppData\Local\Temp\is-K29G0.tmp\malware.tmpC:\Users\Behemot\AppData\Local\Temp\is-DBPUD.tmp\_isetup\_shfoldr.dll
5/3/2020 - 20:45:43.903Open2076C:\Users\Behemot\AppData\Local\Temp\is-K29G0.tmp\malware.tmpC:\Users\Behemot\AppData\Local\Temp\is-DBPUD.tmp\_isetup\_shfoldr.dll
5/3/2020 - 20:45:43.903Write2076C:\Users\Behemot\AppData\Local\Temp\is-K29G0.tmp\malware.tmpC:\Users\Behemot\AppData\Local\Temp\is-DBPUD.tmp\_isetup\_shfoldr.dll
5/3/2020 - 20:45:43.903Unknown2076C:\Users\Behemot\AppData\Local\Temp\is-K29G0.tmp\malware.tmpC:\Users\Behemot\AppData\Local\Temp\is-DBPUD.tmp\_isetup\_shfoldr.dll
5/3/2020 - 20:45:43.903Open2076C:\Users\Behemot\AppData\Local\Temp\is-K29G0.tmp\malware.tmpC:\Users\Behemot\AppData\Local\Temp\is-DBPUD.tmp\_isetup\_shfoldr.dll
5/3/2020 - 20:45:43.903Unknown2076C:\Users\Behemot\AppData\Local\Temp\is-K29G0.tmp\malware.tmpC:\Users\Behemot\AppData\Local\Temp\is-DBPUD.tmp\_isetup\_shfoldr.dll
5/3/2020 - 20:45:43.903Open2076C:\Users\Behemot\AppData\Local\Temp\is-K29G0.tmp\malware.tmpC:\Users\Behemot\AppData\Local\Temp\is-DBPUD.tmp\_isetup\_shfoldr.dll
5/3/2020 - 20:45:43.903Unknown2076C:\Users\Behemot\AppData\Local\Temp\is-K29G0.tmp\malware.tmpC:\Users\Behemot\AppData\Local\Temp\is-DBPUD.tmp\_isetup\_shfoldr.dll
5/3/2020 - 20:45:43.903Open2076C:\Users\Behemot\AppData\Local\Temp\is-K29G0.tmp\malware.tmpC:\Users\Behemot\AppData\Local\Temp\is-K29G0.tmp\shfolder.dll
5/3/2020 - 20:45:43.903Open2076C:\Users\Behemot\AppData\Local\Temp\is-K29G0.tmp\malware.tmpC:\Windows\SysWOW64\shfolder.dll
5/3/2020 - 20:45:43.903Open2076C:\Users\Behemot\AppData\Local\Temp\is-K29G0.tmp\malware.tmpC:\Windows\SysWOW64\shfolder.dll
5/3/2020 - 20:45:43.965Open2076C:\Users\Behemot\AppData\Local\Temp\is-K29G0.tmp\malware.tmpC:\Users\Behemot\AppData\Local\Temp\is-K29G0.tmp\shfolder.dll
5/3/2020 - 20:45:43.965Open2076C:\Users\Behemot\AppData\Local\Temp\is-K29G0.tmp\malware.tmpC:\Windows\SysWOW64\shfolder.dll
5/3/2020 - 20:45:43.965Open2076C:\Users\Behemot\AppData\Local\Temp\is-K29G0.tmp\malware.tmpC:\Windows\SysWOW64\shfolder.dll
5/3/2020 - 20:45:43.965Open2076C:\Users\Behemot\AppData\Local\Temp\is-K29G0.tmp\malware.tmpC:\Users\Behemot\AppData\Local\Temp\is-K29G0.tmp\shfolder.dll
5/3/2020 - 20:45:43.965Open2076C:\Users\Behemot\AppData\Local\Temp\is-K29G0.tmp\malware.tmpC:\Windows\SysWOW64\shfolder.dll
5/3/2020 - 20:45:43.965Open2076C:\Users\Behemot\AppData\Local\Temp\is-K29G0.tmp\malware.tmpC:\Windows\SysWOW64\shfolder.dll
5/3/2020 - 20:45:44.59Open2076C:\Users\Behemot\AppData\Local\Temp\is-K29G0.tmp\malware.tmpC:\Windows\SysWOW64\uxtheme.dll.Config
5/3/2020 - 20:45:44.59Open2076C:\Users\Behemot\AppData\Local\Temp\is-K29G0.tmp\malware.tmpC:\Windows\SysWOW64\uxtheme.dll
5/3/2020 - 20:45:44.59Open2076C:\Users\Behemot\AppData\Local\Temp\is-K29G0.tmp\malware.tmpC:\Users\Behemot\AppData\Local\Temp\is-K29G0.tmp\malware.tmp.Local
5/3/2020 - 20:45:44.59Open2076C:\Users\Behemot\AppData\Local\Temp\is-K29G0.tmp\malware.tmpC:\Windows\winsxs\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.18837_none_41e855142bd5705d
5/3/2020 - 20:45:44.59Unknown2076C:\Users\Behemot\AppData\Local\Temp\is-K29G0.tmp\malware.tmpC:\Windows\winsxs\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.18837_none_41e855142bd5705d
5/3/2020 - 20:45:44.59Open2076C:\Users\Behemot\AppData\Local\Temp\is-K29G0.tmp\malware.tmpC:\Windows\winsxs\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.18837_none_41e855142bd5705d
5/3/2020 - 20:45:44.59Unknown2076C:\Users\Behemot\AppData\Local\Temp\is-K29G0.tmp\malware.tmpC:\Windows\winsxs\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.18837_none_41e855142bd5705d
5/3/2020 - 20:45:44.59Open2076C:\Users\Behemot\AppData\Local\Temp\is-K29G0.tmp\malware.tmpC:\Windows\Fonts\sserife.fon
5/3/2020 - 20:45:44.59Open2076C:\Users\Behemot\AppData\Local\Temp\is-K29G0.tmp\malware.tmpC:\Windows\SysWOW64\shell32.dll
5/3/2020 - 20:45:44.59Open2076C:\Users\Behemot\AppData\Local\Temp\is-K29G0.tmp\malware.tmpC:\Users\Behemot\AppData\Local\Temp\is-K29G0.tmp\malware.tmp.Local
5/3/2020 - 20:45:44.59Open2076C:\Users\Behemot\AppData\Local\Temp\is-K29G0.tmp\malware.tmpC:\Windows\winsxs\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.18837_none_41e855142bd5705d
5/3/2020 - 20:45:44.59Unknown2076C:\Users\Behemot\AppData\Local\Temp\is-K29G0.tmp\malware.tmpC:\Windows\winsxs\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.18837_none_41e855142bd5705d
5/3/2020 - 20:45:44.59Open2076C:\Users\Behemot\AppData\Local\Temp\is-K29G0.tmp\malware.tmpC:\Windows\winsxs\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.18837_none_41e855142bd5705d
5/3/2020 - 20:45:44.122Open2076C:\Users\Behemot\AppData\Local\Temp\is-K29G0.tmp\malware.tmpC:\Windows\SysWOW64\imageres.dll
5/3/2020 - 20:45:44.122Open2076C:\Users\Behemot\AppData\Local\Temp\is-K29G0.tmp\malware.tmpC:\Windows\SysWOW64\imageres.dll
5/3/2020 - 20:45:44.122Open2076C:\Users\Behemot\AppData\Local\Temp\is-K29G0.tmp\malware.tmpC:\Windows\SysWOW64\imageres.dll
5/3/2020 - 20:45:44.122Open2076C:\Users\Behemot\AppData\Local\Temp\is-K29G0.tmp\malware.tmpC:\Windows\SysWOW64\imageres.dll
5/3/2020 - 20:45:44.356Open2076C:\Users\Behemot\AppData\Local\Temp\is-K29G0.tmp\malware.tmpC:\Windows\SysWOW64\pt-BR\imageres.dll.mui
5/3/2020 - 20:45:44.356Open2076C:\Users\Behemot\AppData\Local\Temp\is-K29G0.tmp\malware.tmpC:\Windows\System32\pt-BR\imageres.dll.mui
5/3/2020 - 20:45:44.356Open2076C:\Users\Behemot\AppData\Local\Temp\is-K29G0.tmp\malware.tmpC:\Windows\SysWOW64\pt\imageres.dll.mui
5/3/2020 - 20:45:44.356Open2076C:\Users\Behemot\AppData\Local\Temp\is-K29G0.tmp\malware.tmpC:\Windows\SysWOW64\en-US\imageres.dll.mui
5/3/2020 - 20:45:44.356Read2076C:\Users\Behemot\AppData\Local\Temp\is-K29G0.tmp\malware.tmpC:\Windows\SysWOW64\en-US\imageres.dll.muiimageres.dll.mui
5/3/2020 - 20:45:44.403Open2076C:\Users\Behemot\AppData\Local\Temp\is-K29G0.tmp\malware.tmpC:\Users\Behemot
5/3/2020 - 20:45:44.403Open2076C:\Users\Behemot\AppData\Local\Temp\is-K29G0.tmp\malware.tmpC:\Users\Behemot
5/3/2020 - 20:45:44.403Unknown2076C:\Users\Behemot\AppData\Local\Temp\is-K29G0.tmp\malware.tmpC:\Users\Behemot
5/3/2020 - 20:45:44.403Open2076C:\Users\Behemot\AppData\Local\Temp\is-K29G0.tmp\malware.tmpC:\Users\Behemot\AppData\Roaming
5/3/2020 - 20:45:44.403Open2076C:\Users\Behemot\AppData\Local\Temp\is-K29G0.tmp\malware.tmpC:\Users\Behemot\AppData\Roaming
5/3/2020 - 20:45:44.403Unknown2076C:\Users\Behemot\AppData\Local\Temp\is-K29G0.tmp\malware.tmpC:\Users\Behemot\AppData\Roaming
5/3/2020 - 20:45:44.403Open2076C:\Users\Behemot\AppData\Local\Temp\is-K29G0.tmp\malware.tmpC:\Users\Behemot\AppData\Roaming\Microsoft\Windows\Start Menu
5/3/2020 - 20:45:44.403Open2076C:\Users\Behemot\AppData\Local\Temp\is-K29G0.tmp\malware.tmpC:\Users\Behemot\AppData\Roaming\Microsoft\Windows\Start Menu
5/3/2020 - 20:45:44.403Unknown2076C:\Users\Behemot\AppData\Local\Temp\is-K29G0.tmp\malware.tmpC:\Users\Behemot\AppData\Roaming\Microsoft\Windows\Start Menu
5/3/2020 - 20:45:44.403Open2076C:\Users\Behemot\AppData\Local\Temp\is-K29G0.tmp\malware.tmpC:\Users\Behemot\AppData\Roaming\Microsoft\Windows\Start Menu\Programs
5/3/2020 - 20:45:44.403Open2076C:\Users\Behemot\AppData\Local\Temp\is-K29G0.tmp\malware.tmpC:\Users\Behemot\AppData\Roaming\Microsoft\Windows\Start Menu\Programs
5/3/2020 - 20:45:44.403Unknown2076C:\Users\Behemot\AppData\Local\Temp\is-K29G0.tmp\malware.tmpC:\Users\Behemot\AppData\Roaming\Microsoft\Windows\Start Menu\Programs
5/3/2020 - 20:45:44.403Open2076C:\Users\Behemot\AppData\Local\Temp\is-K29G0.tmp\malware.tmpC:\
5/3/2020 - 20:45:44.403Unknown2076C:\Users\Behemot\AppData\Local\Temp\is-K29G0.tmp\malware.tmpC:\
5/3/2020 - 20:45:44.403Open2076C:\Users\Behemot\AppData\Local\Temp\is-K29G0.tmp\malware.tmpC:\Windows\SysWOW64\propsys.dll
5/3/2020 - 20:45:44.403Open2076C:\Users\Behemot\AppData\Local\Temp\is-K29G0.tmp\malware.tmpC:\Windows\SysWOW64\propsys.dll
5/3/2020 - 20:45:44.403Open2076C:\Users\Behemot\AppData\Local\Temp\is-K29G0.tmp\malware.tmpC:\Users\Behemot\AppData\Local\Microsoft\Windows\Caches
5/3/2020 - 20:45:44.403Open2076C:\Users\Behemot\AppData\Local\Temp\is-K29G0.tmp\malware.tmpC:\Users\Behemot\AppData\Local\Microsoft\Windows\Caches\cversions.1.db
5/3/2020 - 20:45:44.403Open2076C:\Users\Behemot\AppData\Local\Temp\is-K29G0.tmp\malware.tmpC:\Users\Behemot\AppData\Local\Microsoft\Windows\Caches
5/3/2020 - 20:45:44.403Open2076C:\Users\Behemot\AppData\Local\Temp\is-K29G0.tmp\malware.tmpC:\Users\Behemot\AppData\Local\Microsoft\Windows\Caches\cversions.1.db
5/3/2020 - 20:45:44.403Open2076C:\Users\Behemot\AppData\Local\Temp\is-K29G0.tmp\malware.tmpC:\Users\Behemot\AppData\Local\Microsoft\Windows\Caches\{AFBF9F1A-8EE8-4C77-AF34-C647E37CA0D9}.1.ver0x0000000000000000.db
5/3/2020 - 20:45:44.403Open2076C:\Users\Behemot\AppData\Local\Temp\is-K29G0.tmp\malware.tmpC:\Users\desktop.ini
5/3/2020 - 20:45:44.403Read2076C:\Users\Behemot\AppData\Local\Temp\is-K29G0.tmp\malware.tmpC:\Users\desktop.ini
5/3/2020 - 20:45:44.403Open2076C:\Users\Behemot\AppData\Local\Temp\is-K29G0.tmp\malware.tmpC:\Users
5/3/2020 - 20:45:44.403Unknown2076C:\Users\Behemot\AppData\Local\Temp\is-K29G0.tmp\malware.tmpC:\Users
5/3/2020 - 20:45:44.403Open2076C:\Users\Behemot\AppData\Local\Temp\is-K29G0.tmp\malware.tmpC:\Users\Behemot
5/3/2020 - 20:45:44.403Unknown2076C:\Users\Behemot\AppData\Local\Temp\is-K29G0.tmp\malware.tmpC:\Users\Behemot
5/3/2020 - 20:45:44.403Open2076C:\Users\Behemot\AppData\Local\Temp\is-K29G0.tmp\malware.tmpC:\Users\Behemot\AppData
5/3/2020 - 20:45:44.403Unknown2076C:\Users\Behemot\AppData\Local\Temp\is-K29G0.tmp\malware.tmpC:\Users\Behemot\AppData
5/3/2020 - 20:45:44.403Open2076C:\Users\Behemot\AppData\Local\Temp\is-K29G0.tmp\malware.tmpC:\Users\Behemot\AppData\Roaming
5/3/2020 - 20:45:44.403Unknown2076C:\Users\Behemot\AppData\Local\Temp\is-K29G0.tmp\malware.tmpC:\Users\Behemot\AppData\Roaming
5/3/2020 - 20:45:44.403Open2076C:\Users\Behemot\AppData\Local\Temp\is-K29G0.tmp\malware.tmpC:\Users\Behemot\AppData\Roaming\Microsoft\desktop.ini
5/3/2020 - 20:45:44.403Open2076C:\Users\Behemot\AppData\Local\Temp\is-K29G0.tmp\malware.tmpC:\Users\Behemot\AppData\Roaming\Microsoft
5/3/2020 - 20:45:44.403Unknown2076C:\Users\Behemot\AppData\Local\Temp\is-K29G0.tmp\malware.tmpC:\Users\Behemot\AppData\Roaming\Microsoft
5/3/2020 - 20:45:44.403Open2076C:\Users\Behemot\AppData\Local\Temp\is-K29G0.tmp\malware.tmpC:\Users\Behemot\AppData\Roaming\Microsoft\Windows
5/3/2020 - 20:45:44.403Unknown2076C:\Users\Behemot\AppData\Local\Temp\is-K29G0.tmp\malware.tmpC:\Users\Behemot\AppData\Roaming\Microsoft\Windows
5/3/2020 - 20:45:44.403Open2076C:\Users\Behemot\AppData\Local\Temp\is-K29G0.tmp\malware.tmpC:\Users\Behemot\AppData\Roaming\Microsoft\Windows\Start Menu\desktop.ini
5/3/2020 - 20:45:44.403Read2076C:\Users\Behemot\AppData\Local\Temp\is-K29G0.tmp\malware.tmpC:\Users\Behemot\AppData\Roaming\Microsoft\Windows\Start Menu\desktop.ini
5/3/2020 - 20:45:44.403Open2076C:\Users\Behemot\AppData\Local\Temp\is-K29G0.tmp\malware.tmpC:\Users\Behemot\AppData\Roaming\Microsoft\Windows\Start Menu
5/3/2020 - 20:45:44.403Unknown2076C:\Users\Behemot\AppData\Local\Temp\is-K29G0.tmp\malware.tmpC:\Users\Behemot\AppData\Roaming\Microsoft\Windows\Start Menu
5/3/2020 - 20:45:44.403Open2076C:\Users\Behemot\AppData\Local\Temp\is-K29G0.tmp\malware.tmpC:\Users\Behemot\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\desktop.ini
5/3/2020 - 20:45:44.403Read2076C:\Users\Behemot\AppData\Local\Temp\is-K29G0.tmp\malware.tmpC:\Users\Behemot\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\desktop.ini
5/3/2020 - 20:45:44.403Open2076C:\Users\Behemot\AppData\Local\Temp\is-K29G0.tmp\malware.tmpC:\Users\Behemot\Desktop\desktop.ini
5/3/2020 - 20:45:44.403Read2076C:\Users\Behemot\AppData\Local\Temp\is-K29G0.tmp\malware.tmpC:\Users\Behemot\Desktop\desktop.ini
5/3/2020 - 20:45:44.403Unknown2076C:\Users\Behemot\AppData\Local\Temp\is-K29G0.tmp\malware.tmpC:\Users\Behemot\Desktop\desktop.ini
5/3/2020 - 20:45:44.559Open2076C:\Users\Behemot\AppData\Local\Temp\is-K29G0.tmp\malware.tmpC:\
5/3/2020 - 20:45:44.559Unknown2076C:\Users\Behemot\AppData\Local\Temp\is-K29G0.tmp\malware.tmpC:\
5/3/2020 - 20:45:44.559Open2076C:\Users\Behemot\AppData\Local\Temp\is-K29G0.tmp\malware.tmpC:\Users
5/3/2020 - 20:45:44.559Unknown2076C:\Users\Behemot\AppData\Local\Temp\is-K29G0.tmp\malware.tmpC:\Users
5/3/2020 - 20:45:44.559Open2076C:\Users\Behemot\AppData\Local\Temp\is-K29G0.tmp\malware.tmpC:\Users\Behemot
5/3/2020 - 20:45:44.559Unknown2076C:\Users\Behemot\AppData\Local\Temp\is-K29G0.tmp\malware.tmpC:\Users\Behemot
5/3/2020 - 20:45:44.559Open2076C:\Users\Behemot\AppData\Local\Temp\is-K29G0.tmp\malware.tmpC:\Users\Behemot\Searches\desktop.ini
5/3/2020 - 20:45:44.559Read2076C:\Users\Behemot\AppData\Local\Temp\is-K29G0.tmp\malware.tmpC:\Users\Behemot\Searches\desktop.ini
5/3/2020 - 20:45:44.559Open2076C:\Users\Behemot\AppData\Local\Temp\is-K29G0.tmp\malware.tmpC:\
5/3/2020 - 20:45:44.559Unknown2076C:\Users\Behemot\AppData\Local\Temp\is-K29G0.tmp\malware.tmpC:\
5/3/2020 - 20:45:44.559Open2076C:\Users\Behemot\AppData\Local\Temp\is-K29G0.tmp\malware.tmpC:\Users
5/3/2020 - 20:45:44.559Unknown2076C:\Users\Behemot\AppData\Local\Temp\is-K29G0.tmp\malware.tmpC:\Users
5/3/2020 - 20:45:44.559Open2076C:\Users\Behemot\AppData\Local\Temp\is-K29G0.tmp\malware.tmpC:\Users\Behemot
5/3/2020 - 20:45:44.559Unknown2076C:\Users\Behemot\AppData\Local\Temp\is-K29G0.tmp\malware.tmpC:\Users\Behemot
5/3/2020 - 20:45:44.559Open2076C:\Users\Behemot\AppData\Local\Temp\is-K29G0.tmp\malware.tmpC:\Users\Behemot\Videos\desktop.ini
5/3/2020 - 20:45:44.559Read2076C:\Users\Behemot\AppData\Local\Temp\is-K29G0.tmp\malware.tmpC:\Users\Behemot\Videos\desktop.ini
5/3/2020 - 20:45:44.559Open2076C:\Users\Behemot\AppData\Local\Temp\is-K29G0.tmp\malware.tmpC:\
5/3/2020 - 20:45:44.559Unknown2076C:\Users\Behemot\AppData\Local\Temp\is-K29G0.tmp\malware.tmpC:\
5/3/2020 - 20:45:44.559Open2076C:\Users\Behemot\AppData\Local\Temp\is-K29G0.tmp\malware.tmpC:\Users
5/3/2020 - 20:45:44.559Unknown2076C:\Users\Behemot\AppData\Local\Temp\is-K29G0.tmp\malware.tmpC:\Users
5/3/2020 - 20:45:44.559Open2076C:\Users\Behemot\AppData\Local\Temp\is-K29G0.tmp\malware.tmpC:\Users\Behemot
5/3/2020 - 20:45:44.559Unknown2076C:\Users\Behemot\AppData\Local\Temp\is-K29G0.tmp\malware.tmpC:\Users\Behemot
5/3/2020 - 20:45:44.559Open2076C:\Users\Behemot\AppData\Local\Temp\is-K29G0.tmp\malware.tmpC:\Users\Behemot\Pictures\desktop.ini
5/3/2020 - 20:45:44.559Read2076C:\Users\Behemot\AppData\Local\Temp\is-K29G0.tmp\malware.tmpC:\Users\Behemot\Pictures\desktop.ini
5/3/2020 - 20:45:44.559Open2076C:\Users\Behemot\AppData\Local\Temp\is-K29G0.tmp\malware.tmpC:\
5/3/2020 - 20:45:44.559Unknown2076C:\Users\Behemot\AppData\Local\Temp\is-K29G0.tmp\malware.tmpC:\
5/3/2020 - 20:45:44.559Open2076C:\Users\Behemot\AppData\Local\Temp\is-K29G0.tmp\malware.tmpC:\Users
5/3/2020 - 20:45:44.559Unknown2076C:\Users\Behemot\AppData\Local\Temp\is-K29G0.tmp\malware.tmpC:\Users
5/3/2020 - 20:45:44.559Open2076C:\Users\Behemot\AppData\Local\Temp\is-K29G0.tmp\malware.tmpC:\Users\Behemot
5/3/2020 - 20:45:44.559Unknown2076C:\Users\Behemot\AppData\Local\Temp\is-K29G0.tmp\malware.tmpC:\Users\Behemot
5/3/2020 - 20:45:44.559Open2076C:\Users\Behemot\AppData\Local\Temp\is-K29G0.tmp\malware.tmpC:\
5/3/2020 - 20:45:44.559Unknown2076C:\Users\Behemot\AppData\Local\Temp\is-K29G0.tmp\malware.tmpC:\
5/3/2020 - 20:45:44.559Open2076C:\Users\Behemot\AppData\Local\Temp\is-K29G0.tmp\malware.tmpC:\Users
5/3/2020 - 20:45:44.559Unknown2076C:\Users\Behemot\AppData\Local\Temp\is-K29G0.tmp\malware.tmpC:\Users
5/3/2020 - 20:45:44.559Open2076C:\Users\Behemot\AppData\Local\Temp\is-K29G0.tmp\malware.tmpC:\Users\Behemot
5/3/2020 - 20:45:44.559Unknown2076C:\Users\Behemot\AppData\Local\Temp\is-K29G0.tmp\malware.tmpC:\Users\Behemot
5/3/2020 - 20:45:44.559Open2076C:\Users\Behemot\AppData\Local\Temp\is-K29G0.tmp\malware.tmpC:\Users\Behemot\Contacts\desktop.ini
5/3/2020 - 20:45:44.559Read2076C:\Users\Behemot\AppData\Local\Temp\is-K29G0.tmp\malware.tmpC:\Users\Behemot\Contacts\desktop.ini
5/3/2020 - 20:45:44.559Open2076C:\Users\Behemot\AppData\Local\Temp\is-K29G0.tmp\malware.tmpC:\
5/3/2020 - 20:45:44.559Unknown2076C:\Users\Behemot\AppData\Local\Temp\is-K29G0.tmp\malware.tmpC:\
5/3/2020 - 20:45:44.559Open2076C:\Users\Behemot\AppData\Local\Temp\is-K29G0.tmp\malware.tmpC:\Users
5/3/2020 - 20:45:44.559Unknown2076C:\Users\Behemot\AppData\Local\Temp\is-K29G0.tmp\malware.tmpC:\Users
5/3/2020 - 20:45:44.559Open2076C:\Users\Behemot\AppData\Local\Temp\is-K29G0.tmp\malware.tmpC:\Users\Behemot
5/3/2020 - 20:45:44.559Unknown2076C:\Users\Behemot\AppData\Local\Temp\is-K29G0.tmp\malware.tmpC:\Users\Behemot
5/3/2020 - 20:45:44.559Open2076C:\Users\Behemot\AppData\Local\Temp\is-K29G0.tmp\malware.tmpC:\Users\Behemot\Favorites\desktop.ini
5/3/2020 - 20:45:44.559Read2076C:\Users\Behemot\AppData\Local\Temp\is-K29G0.tmp\malware.tmpC:\Users\Behemot\Favorites\desktop.ini
5/3/2020 - 20:45:44.559Open2076C:\Users\Behemot\AppData\Local\Temp\is-K29G0.tmp\malware.tmpC:\
5/3/2020 - 20:45:44.559Unknown2076C:\Users\Behemot\AppData\Local\Temp\is-K29G0.tmp\malware.tmpC:\
5/3/2020 - 20:45:44.559Open2076C:\Users\Behemot\AppData\Local\Temp\is-K29G0.tmp\malware.tmpC:\Users
5/3/2020 - 20:45:44.559Unknown2076C:\Users\Behemot\AppData\Local\Temp\is-K29G0.tmp\malware.tmpC:\Users
5/3/2020 - 20:45:44.559Open2076C:\Users\Behemot\AppData\Local\Temp\is-K29G0.tmp\malware.tmpC:\Users\Behemot
5/3/2020 - 20:45:44.559Unknown2076C:\Users\Behemot\AppData\Local\Temp\is-K29G0.tmp\malware.tmpC:\Users\Behemot
5/3/2020 - 20:45:44.559Open2076C:\Users\Behemot\AppData\Local\Temp\is-K29G0.tmp\malware.tmpC:\Users\Behemot\Music\desktop.ini
5/3/2020 - 20:45:44.559Read2076C:\Users\Behemot\AppData\Local\Temp\is-K29G0.tmp\malware.tmpC:\Users\Behemot\Music\desktop.ini
5/3/2020 - 20:45:44.559Open2076C:\Users\Behemot\AppData\Local\Temp\is-K29G0.tmp\malware.tmpC:\
5/3/2020 - 20:45:44.559Unknown2076C:\Users\Behemot\AppData\Local\Temp\is-K29G0.tmp\malware.tmpC:\
5/3/2020 - 20:45:44.559Open2076C:\Users\Behemot\AppData\Local\Temp\is-K29G0.tmp\malware.tmpC:\Users
5/3/2020 - 20:45:44.559Unknown2076C:\Users\Behemot\AppData\Local\Temp\is-K29G0.tmp\malware.tmpC:\Users
5/3/2020 - 20:45:44.559Open2076C:\Users\Behemot\AppData\Local\Temp\is-K29G0.tmp\malware.tmpC:\Users\Behemot
5/3/2020 - 20:45:44.559Unknown2076C:\Users\Behemot\AppData\Local\Temp\is-K29G0.tmp\malware.tmpC:\Users\Behemot
5/3/2020 - 20:45:44.559Open2076C:\Users\Behemot\AppData\Local\Temp\is-K29G0.tmp\malware.tmpC:\Users\Behemot\Downloads\desktop.ini
5/3/2020 - 20:45:44.559Read2076C:\Users\Behemot\AppData\Local\Temp\is-K29G0.tmp\malware.tmpC:\Users\Behemot\Downloads\desktop.ini
5/3/2020 - 20:45:44.559Open2076C:\Users\Behemot\AppData\Local\Temp\is-K29G0.tmp\malware.tmpC:\
5/3/2020 - 20:45:44.559Unknown2076C:\Users\Behemot\AppData\Local\Temp\is-K29G0.tmp\malware.tmpC:\
5/3/2020 - 20:45:44.559Open2076C:\Users\Behemot\AppData\Local\Temp\is-K29G0.tmp\malware.tmpC:\Users
5/3/2020 - 20:45:44.559Unknown2076C:\Users\Behemot\AppData\Local\Temp\is-K29G0.tmp\malware.tmpC:\Users
5/3/2020 - 20:45:44.559Open2076C:\Users\Behemot\AppData\Local\Temp\is-K29G0.tmp\malware.tmpC:\Users\Behemot
5/3/2020 - 20:45:44.559Unknown2076C:\Users\Behemot\AppData\Local\Temp\is-K29G0.tmp\malware.tmpC:\Users\Behemot
5/3/2020 - 20:45:44.559Open2076C:\Users\Behemot\AppData\Local\Temp\is-K29G0.tmp\malware.tmpC:\Users\Behemot\Documents\desktop.ini
5/3/2020 - 20:45:44.559Read2076C:\Users\Behemot\AppData\Local\Temp\is-K29G0.tmp\malware.tmpC:\Users\Behemot\Documents\desktop.ini
5/3/2020 - 20:45:44.559Open2076C:\Users\Behemot\AppData\Local\Temp\is-K29G0.tmp\malware.tmpC:\
5/3/2020 - 20:45:44.559Unknown2076C:\Users\Behemot\AppData\Local\Temp\is-K29G0.tmp\malware.tmpC:\
5/3/2020 - 20:45:44.559Open2076C:\Users\Behemot\AppData\Local\Temp\is-K29G0.tmp\malware.tmpC:\Users
5/3/2020 - 20:45:44.559Unknown2076C:\Users\Behemot\AppData\Local\Temp\is-K29G0.tmp\malware.tmpC:\Users
5/3/2020 - 20:45:44.559Open2076C:\Users\Behemot\AppData\Local\Temp\is-K29G0.tmp\malware.tmpC:\Users\Behemot
5/3/2020 - 20:45:44.559Unknown2076C:\Users\Behemot\AppData\Local\Temp\is-K29G0.tmp\malware.tmpC:\Users\Behemot
5/3/2020 - 20:45:44.559Open2076C:\Users\Behemot\AppData\Local\Temp\is-K29G0.tmp\malware.tmpC:\Users\Behemot\Links\desktop.ini
5/3/2020 - 20:45:44.559Read2076C:\Users\Behemot\AppData\Local\Temp\is-K29G0.tmp\malware.tmpC:\Users\Behemot\Links\desktop.ini
5/3/2020 - 20:45:44.559Open2076C:\Users\Behemot\AppData\Local\Temp\is-K29G0.tmp\malware.tmpC:\
5/3/2020 - 20:45:44.559Unknown2076C:\Users\Behemot\AppData\Local\Temp\is-K29G0.tmp\malware.tmpC:\
5/3/2020 - 20:45:44.559Open2076C:\Users\Behemot\AppData\Local\Temp\is-K29G0.tmp\malware.tmpC:\Users
5/3/2020 - 20:45:44.559Unknown2076C:\Users\Behemot\AppData\Local\Temp\is-K29G0.tmp\malware.tmpC:\Users
5/3/2020 - 20:45:44.559Open2076C:\Users\Behemot\AppData\Local\Temp\is-K29G0.tmp\malware.tmpC:\Users\Behemot
5/3/2020 - 20:45:44.559Unknown2076C:\Users\Behemot\AppData\Local\Temp\is-K29G0.tmp\malware.tmpC:\Users\Behemot
5/3/2020 - 20:45:44.559Open2076C:\Users\Behemot\AppData\Local\Temp\is-K29G0.tmp\malware.tmpC:\Users\Behemot\Saved Games\desktop.ini
5/3/2020 - 20:45:44.559Read2076C:\Users\Behemot\AppData\Local\Temp\is-K29G0.tmp\malware.tmpC:\Users\Behemot\Saved Games\desktop.ini
5/3/2020 - 20:45:44.559Open2076C:\Users\Behemot\AppData\Local\Temp\is-K29G0.tmp\malware.tmpC:\Users\Behemot\AppData\Local\Temp\is-K29G0.tmp\apphelp.dll
5/3/2020 - 20:45:44.559Open2076C:\Users\Behemot\AppData\Local\Temp\is-K29G0.tmp\malware.tmpC:\Windows\SysWOW64\apphelp.dll
5/3/2020 - 20:45:44.559Open2076C:\Users\Behemot\AppData\Local\Temp\is-K29G0.tmp\malware.tmpC:\Windows\SysWOW64\apphelp.dll
5/3/2020 - 20:45:44.559Open2076C:\Users\Behemot\AppData\Local\Temp\is-K29G0.tmp\malware.tmpC:\Windows\SysWOW64\shdocvw.dll
5/3/2020 - 20:45:44.559Open2076C:\Users\Behemot\AppData\Local\Temp\is-K29G0.tmp\malware.tmpC:\Windows\AppPatch\sysmain.sdb
5/3/2020 - 20:45:44.559Open2076C:\Users\Behemot\AppData\Local\Temp\is-K29G0.tmp\malware.tmpC:\Windows\SysWOW64
5/3/2020 - 20:45:44.559Unknown2076C:\Users\Behemot\AppData\Local\Temp\is-K29G0.tmp\malware.tmpC:\Windows\SysWOW64
5/3/2020 - 20:45:44.559Open2076C:\Users\Behemot\AppData\Local\Temp\is-K29G0.tmp\malware.tmpC:\Windows\SysWOW64\shdocvw.dll
5/3/2020 - 20:45:44.559Open2076C:\Users\Behemot\AppData\Local\Temp\is-K29G0.tmp\malware.tmpC:\
5/3/2020 - 20:45:44.559Unknown2076C:\Users\Behemot\AppData\Local\Temp\is-K29G0.tmp\malware.tmpC:\
5/3/2020 - 20:45:44.559Open2076C:\Users\Behemot\AppData\Local\Temp\is-K29G0.tmp\malware.tmpC:\Windows
5/3/2020 - 20:45:44.559Unknown2076C:\Users\Behemot\AppData\Local\Temp\is-K29G0.tmp\malware.tmpC:\Windows
5/3/2020 - 20:45:44.559Open2076C:\Users\Behemot\AppData\Local\Temp\is-K29G0.tmp\malware.tmpC:\Windows\SysWOW64
5/3/2020 - 20:45:44.575Unknown2076C:\Users\Behemot\AppData\Local\Temp\is-K29G0.tmp\malware.tmpC:\Windows\SysWOW64
5/3/2020 - 20:45:44.575Open2076C:\Users\Behemot\AppData\Local\Temp\is-K29G0.tmp\malware.tmpC:\Windows\SysWOW64
5/3/2020 - 20:45:44.575Unknown2076C:\Users\Behemot\AppData\Local\Temp\is-K29G0.tmp\malware.tmpC:\Windows\SysWOW64
5/3/2020 - 20:45:44.575Open2076C:\Users\Behemot\AppData\Local\Temp\is-K29G0.tmp\malware.tmpC:\Windows\SysWOW64\shdocvw.dll
5/3/2020 - 20:45:44.575Open2076C:\Users\Behemot\AppData\Local\Temp\is-K29G0.tmp\malware.tmpC:\Windows\SysWOW64\shdocvw.dll
5/3/2020 - 20:45:44.622Open2076C:\Users\Behemot\AppData\Local\Temp\is-K29G0.tmp\malware.tmpC:\Windows\SysWOW64\shdocvw.dll
5/3/2020 - 20:45:44.622Open2076C:\Users\Behemot\AppData\Local\Temp\is-K29G0.tmp\malware.tmpC:\Windows\SysWOW64\shdocvw.dll
5/3/2020 - 20:45:44.622Open2076C:\Users\Behemot\AppData\Local\Temp\is-K29G0.tmp\malware.tmpC:\Windows\SysWOW64\shdocvw.dll
5/3/2020 - 20:45:44.622Open2076C:\Users\Behemot\AppData\Local\Temp\is-K29G0.tmp\malware.tmpC:\Windows\SysWOW64\shdocvw.dll
5/3/2020 - 20:45:44.622Read2076C:\Users\Behemot\AppData\Local\Temp\is-K29G0.tmp\malware.tmpC:\Windows\SysWOW64\shdocvw.dll
5/3/2020 - 20:45:44.622Read2076C:\Users\Behemot\AppData\Local\Temp\is-K29G0.tmp\malware.tmpC:\Windows\SysWOW64\shdocvw.dll
5/3/2020 - 20:45:44.622Open2076C:\Users\Behemot\AppData\Local\Temp\is-K29G0.tmp\malware.tmpC:\Windows\SysWOW64\shdocvw.dll
5/3/2020 - 20:45:44.622Open2076C:\Users\Behemot\AppData\Local\Temp\is-K29G0.tmp\malware.tmpC:\Windows\SysWOW64\shdocvw.dll
5/3/2020 - 20:45:44.622Open2076C:\Users\Behemot\AppData\Local\Temp\is-K29G0.tmp\malware.tmpC:\Windows\SysWOW64\shdocvw.dll
5/3/2020 - 20:45:44.668Open2076C:\Users\Behemot\AppData\Local\Temp\is-K29G0.tmp\malware.tmpC:\Windows\SysWOW64\shell32.dll
5/3/2020 - 20:45:44.668Open2076C:\Users\Behemot\AppData\Local\Temp\is-K29G0.tmp\malware.tmpC:\Windows\SysWOW64\shell32.dll
5/3/2020 - 20:45:44.668Open2076C:\Users\Behemot\AppData\Local\Temp\is-K29G0.tmp\malware.tmpC:\
5/3/2020 - 20:45:44.668Unknown2076C:\Users\Behemot\AppData\Local\Temp\is-K29G0.tmp\malware.tmpC:\
5/3/2020 - 20:45:44.668Open2076C:\Users\Behemot\AppData\Local\Temp\is-K29G0.tmp\malware.tmpC:\Users
5/3/2020 - 20:45:44.668Unknown2076C:\Users\Behemot\AppData\Local\Temp\is-K29G0.tmp\malware.tmpC:\Users
5/3/2020 - 20:45:44.668Open2076C:\Users\Behemot\AppData\Local\Temp\is-K29G0.tmp\malware.tmpC:\Windows\SysWOW64\imageres.dll
5/3/2020 - 20:45:44.668Open2076C:\Users\Behemot\AppData\Local\Temp\is-K29G0.tmp\malware.tmpC:\Windows\SysWOW64\imageres.dll
5/3/2020 - 20:45:44.668Open2076C:\Users\Behemot\AppData\Local\Temp\is-K29G0.tmp\malware.tmpC:\Windows\SysWOW64\imageres.dll
5/3/2020 - 20:45:44.668Open2076C:\Users\Behemot\AppData\Local\Temp\is-K29G0.tmp\malware.tmpC:\Windows\SysWOW64\imageres.dll
5/3/2020 - 20:45:44.731Open2076C:\Users\Behemot\AppData\Local\Temp\is-K29G0.tmp\malware.tmpC:\Windows\SysWOW64\pt-BR\imageres.dll.mui
5/3/2020 - 20:45:44.731Open2076C:\Users\Behemot\AppData\Local\Temp\is-K29G0.tmp\malware.tmpC:\Windows\System32\pt-BR\imageres.dll.mui
5/3/2020 - 20:45:44.731Open2076C:\Users\Behemot\AppData\Local\Temp\is-K29G0.tmp\malware.tmpC:\Windows\SysWOW64\pt\imageres.dll.mui
5/3/2020 - 20:45:44.731Open2076C:\Users\Behemot\AppData\Local\Temp\is-K29G0.tmp\malware.tmpC:\Windows\SysWOW64\en-US\imageres.dll.mui
5/3/2020 - 20:45:44.731Unknown2076C:\Users\Behemot\AppData\Local\Temp\is-K29G0.tmp\malware.tmpC:\Windows\SysWOW64\en-US\imageres.dll.muiimageres.dll.mui
5/3/2020 - 20:45:44.731Open2076C:\Users\Behemot\AppData\Local\Temp\is-K29G0.tmp\malware.tmpC:\Windows\Fonts\verdanab.ttf
5/3/2020 - 20:45:44.778Open2076C:\Users\Behemot\AppData\Local\Temp\is-K29G0.tmp\malware.tmpC:\Windows\Fonts\verdanab.ttf
5/3/2020 - 20:45:44.872Read2076C:\Users\Behemot\AppData\Local\Temp\is-K29G0.tmp\malware.tmpC:\Windows\Fonts\StaticCache.datStaticCache.dat
5/3/2020 - 20:45:44.918Read2076C:\Users\Behemot\AppData\Local\Temp\is-K29G0.tmp\malware.tmpC:\Windows\Fonts\StaticCache.datStaticCache.dat

Process
Trace
5/3/2020 - 20:45:43.715Create1480C:\malware.exe2076C:\Users\Behemot\AppData\Local\Temp\is-K29G0.tmp\malware.tmp

Analysis
Reason
Timeout

Status
Sucessfully Executed

Results
1

Registry
Trace

File Summary
Created
Identified: True check_circle

Deleted
Identified: False cancel

Process Summary
Created
Identified: True check_circle

Deleted
Identified: False cancel

Registry Summary
Proxy
Identified: False cancel

AutoRun
Identified: False cancel

Created
Identified: False cancel

Deleted
Identified: False cancel

Browsers
Identified: False cancel

Internet
Identified: False cancel

Loading...

DNS
Query

Response

TCP
Info

UDP
Info

HTTP
Info

Summary
DNS
False cancel

TCP
False cancel

UDP
False cancel

HTTP
False cancel

Results
BINARY
KNN (K=3, NFS-BRMalware)
confidence: 66.67%
suspicious: True check_circle

Decision Tree (NFS-BRMalware)
confidence: 100.00%
suspicious: False cancel

SVC (Kernel=Linear, NFS-BRMalware)
confidence: 99.57%
suspicious: False cancel

MalConv (Ember: Raw Bytes, Threshold=0.5)
confidence: 88.57%
suspicious: True check_circle

Random Forest (100 estimators, NFS-BRMalware)
confidence: 66.00%
suspicious: False cancel

Non-Negative MalConv (Ember: Raw Bytes, Threshold=0.35)
confidence: 61.16%
suspicious: True check_circle

LightGDM (Ember: File Characteristics, Threshold=0.8336)
confidence: 100.00%
suspicious: False cancel

Add to Collection
Download