Performs some HTTP requests
(2 个事件)
| request |
GET http://download.mozilla.org/?os=win64&lang=fr&product=firefox-latest |
| request |
GET http://download.cdn.mozilla.net/pub/firefox/releases/88.0.1/win64/fr/Firefox%20Setup%2088.0.1.exe |
Allocates read-write-execute memory (usually to unpack itself)
(1 个事件)
| Time & API |
Arguments |
Status |
Return |
Repeated |
1620843588.842375
NtProtectVirtualMemory
|
process_identifier:
2468
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
length:
4096
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
base_address:
0x10004000
|
success
|
0 |
0
|
Queries the disk size which could be used to detect virtual machine with small fixed size or dynamic allocation
(2 个事件)
| Time & API |
Arguments |
Status |
Return |
Repeated |
1620843589.311375
GetDiskFreeSpaceExW
|
root_path:
C:\Program Files\
free_bytes_available:
19608551424
total_number_of_free_bytes:
19608551424
total_number_of_bytes:
34252779520
|
success
|
1 |
0
|
1620843589.327375
GetDiskFreeSpaceExW
|
root_path:
C:\Program Files\
free_bytes_available:
19608342528
total_number_of_free_bytes:
19608342528
total_number_of_bytes:
34252779520
|
success
|
1 |
0
|
Steals private information from local Internet browsers
(2 个事件)
| registry |
HKEY_LOCAL_MACHINE\Software\Mozilla\Mozilla Firefox |
| registry |
HKEY_CURRENT_USER\Software\Mozilla\Mozilla Firefox |
Creates executable files on the filesystem
(7 个事件)
| file |
C:\Users\Administrator.Oskar-PC\AppData\Local\Temp\nsy6A4F.tmp\nsDialogs.dll |
| file |
C:\Users\Administrator.Oskar-PC\AppData\Local\Temp\nsy6A4F.tmp\UserInfo.dll |
| file |
C:\Users\Administrator.Oskar-PC\AppData\Local\Temp\nsy6A4F.tmp\UAC.dll |
| file |
C:\Users\Administrator.Oskar-PC\AppData\Local\Temp\nsy6A4F.tmp\System.dll |
| file |
C:\Users\Administrator.Oskar-PC\AppData\Local\Temp\7zS57EE.tmp\setup-stub.exe |
| file |
C:\Users\Administrator.Oskar-PC\AppData\Local\Temp\nsy6A4F.tmp\download.exe |
| file |
C:\Users\Administrator.Oskar-PC\AppData\Local\Temp\nsy6A4F.tmp\InetBgDL.dll |
Drops an executable to the user AppData folder
(7 个事件)
| file |
C:\Users\Administrator.Oskar-PC\AppData\Local\Temp\7zS57EE.tmp\setup-stub.exe |
| file |
C:\Users\Administrator.Oskar-PC\AppData\Local\Temp\nsy6A4F.tmp\System.dll |
| file |
C:\Users\Administrator.Oskar-PC\AppData\Local\Temp\nsy6A4F.tmp\nsDialogs.dll |
| file |
C:\Users\Administrator.Oskar-PC\AppData\Local\Temp\nsy6A4F.tmp\InetBgDL.dll |
| file |
C:\Users\Administrator.Oskar-PC\AppData\Local\Temp\nsy6A4F.tmp\download.exe |
| file |
C:\Users\Administrator.Oskar-PC\AppData\Local\Temp\nsy6A4F.tmp\UserInfo.dll |
| file |
C:\Users\Administrator.Oskar-PC\AppData\Local\Temp\nsy6A4F.tmp\UAC.dll |
Checks adapter addresses which can be used to detect virtual network interfaces
(1 个事件)
| Time & API |
Arguments |
Status |
Return |
Repeated |
1620843590.577375
GetAdaptersAddresses
|
flags:
0
family:
0
|
failed
|
111 |
0
|
An executable file was downloaded by the process setup-stub.exe
(1 个事件)
| Time & API |
Arguments |
Status |
Return |
Repeated |
1620843625.811375
InternetReadFile
|
buffer:
MZ ÿÿ ¸ @ ð º ´ Í!¸LÍ!This program cannot be run in DOS mode.
$ ù
Î`YÎ`YÎ`YMnYÉ`Y&dYÌ`Y
?YÏ`Y
=YÍ`YÎaYb`Y&jYÔ`Y&kY`YvfYÏ`YRichÎ`Y PE L 9m[ à @ O P ` @ ` [4d L[ ´ ` Lû àuc ' |