Program did not start
MALICIOUS | SUSPICIOUS | INFO |
---|---|---|
Actions looks like stealing of personal data
|
Loads DLL from Mozilla Firefox
|
No info indicators. |
Name | Virtual Address | Virtual Size | Raw Size | Charateristics | Entropy |
---|---|---|---|---|---|
.text | 0x00002000 | 0x00059BC4 | 0x00059C00 | IMAGE_SCN_CNT_CODE,IMAGE_SCN_MEM_EXECUTE,IMAGE_SCN_MEM_READ | 7.35977 |
.rsrc | 0x0005C000 | 0x00000600 | 0x00000600 | IMAGE_SCN_CNT_INITIALIZED_DATA,IMAGE_SCN_MEM_READ | 4.49079 |
.reloc | 0x0005E000 | 0x0000000C | 0x00000200 | IMAGE_SCN_CNT_INITIALIZED_DATA,IMAGE_SCN_MEM_DISCARDABLE,IMAGE_SCN_MEM_READ | 0.10191 |
No exports.
Click at the process to see the details.
Image |
---|
c:\users\admin\appdata\local\temp\haecheng order sheet revised_pdf.exe.bin.exe |
c:\systemroot\system32\ntdll.dll |
c:\windows\system32\mscoree.dll |
c:\windows\system32\kernel32.dll |
c:\windows\system32\kernelbase.dll |
c:\windows\system32\advapi32.dll |
c:\windows\system32\msvcrt.dll |
c:\windows\system32\sechost.dll |
c:\windows\system32\rpcrt4.dll |
c:\windows\microsoft.net\framework\v4.0.30319\mscoreei.dll |
c:\windows\system32\shlwapi.dll |
c:\windows\system32\gdi32.dll |
c:\windows\system32\user32.dll |
c:\windows\system32\lpk.dll |
c:\windows\system32\usp10.dll |
c:\windows\system32\imm32.dll |
c:\windows\system32\msctf.dll |
c:\windows\system32\version.dll |
c:\windows\microsoft.net\framework\v4.0.30319\clr.dll |
c:\windows\system32\msvcr120_clr0400.dll |
c:\windows\assembly\nativeimages_v4.0.30319_32\mscorlib\97e047cf68e9a7d90e196d072cd49cac\mscorlib.ni.dll |
c:\windows\system32\ole32.dll |
c:\windows\system32\cryptbase.dll |
c:\windows\microsoft.net\framework\v4.0.30319\clrjit.dll |
c:\windows\system32\oleaut32.dll |
c:\windows\microsoft.net\framework\v4.0.30319\nlssorting.dll |
c:\windows\system32\shell32.dll |
c:\windows\assembly\nativeimages_v4.0.30319_32\system\e071297bb06faa961bef045ae5f25fdc\system.ni.dll |
c:\windows\system32\propsys.dll |
c:\windows\winsxs\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_41e6975e2bd6f2b2\comctl32.dll |
c:\windows\system32\apphelp.dll |
c:\windows\system32\clbcatq.dll |
c:\windows\system32\ieframe.dll |
c:\windows\system32\psapi.dll |
c:\windows\system32\oleacc.dll |
c:\windows\system32\iertutil.dll |
c:\windows\system32\urlmon.dll |
c:\windows\system32\wininet.dll |
c:\windows\system32\crypt32.dll |
c:\windows\system32\msasn1.dll |
c:\windows\system32\cfgmgr32.dll |
c:\windows\system32\setupapi.dll |
c:\windows\system32\devobj.dll |
c:\windows\system32\ntmarta.dll |
c:\windows\system32\wldap32.dll |
c:\windows\system32\profapi.dll |
c:\windows\system32\sspicli.dll |
c:\windows\assembly\nativeimages_v4.0.30319_32\system.core\21a1606b6c00f9abe7db55c02e0f87c9\system.core.ni.dll |
c:\windows\assembly\nativeimages_v4.0.30319_32\system.management\e588691224a17737f3a164cc2d46c156\system.management.ni.dll |
c:\windows\assembly\nativeimages_v4.0.30319_32\system.web\7c32e936a07e0c7d9cae3ac27497f613\system.web.ni.dll |
c:\windows\assembly\nativeimages_v4.0.30319_32\system.web.28b9ef5a#\a00ba16c92fd291e37a00bab4a72a3fe\system.web.extensions.ni.dll |
c:\windows\system32\cryptsp.dll |
c:\windows\system32\rsaenh.dll |
c:\windows\assembly\nativeimages_v4.0.30319_32\system.serv759bfb78#\c37de755ec3ee73d604bc11f85599177\system.serviceprocess.ni.dll |
c:\windows\assembly\nativeimages_v4.0.30319_32\system.drawing\61dfb69c9ad6ed96809170d54d80b8a6\system.drawing.ni.dll |
c:\windows\assembly\nativeimages_v4.0.30319_32\system.windows.forms\2dc6cfd856864312d563098f9486361c\system.windows.forms.ni.dll |
c:\windows\winsxs\x86_microsoft.windows.gdiplus_6595b64144ccf1df_1.1.7601.17514_none_72d18a4386696c80\gdiplus.dll |
c:\windows\system32\windowscodecs.dll |
c:\windows\system32\bcrypt.dll |
c:\windows\assembly\nativeimages_v4.0.30319_32\microsoft.v9921e851#\f971acbc25b64dfe4d70e5b25837c780\microsoft.visualbasic.ni.dll |
c:\windows\microsoft.net\framework\v4.0.30319\regasm.exe |
Image |
---|
c:\windows\system32\cmd.exe |
c:\systemroot\system32\ntdll.dll |
c:\windows\system32\kernel32.dll |
c:\windows\system32\kernelbase.dll |
c:\windows\system32\msvcrt.dll |
c:\windows\system32\winbrand.dll |
c:\windows\system32\user32.dll |
c:\windows\system32\gdi32.dll |
c:\windows\system32\lpk.dll |
c:\windows\system32\usp10.dll |
c:\windows\system32\imm32.dll |
c:\windows\system32\msctf.dll |
Image |
---|
c:\windows\system32\cmd.exe |
c:\systemroot\system32\ntdll.dll |
c:\windows\system32\kernelbase.dll |
c:\windows\system32\kernel32.dll |
c:\windows\system32\msvcrt.dll |
c:\windows\system32\winbrand.dll |
c:\windows\system32\user32.dll |
c:\windows\system32\gdi32.dll |
c:\windows\system32\lpk.dll |
c:\windows\system32\usp10.dll |
c:\windows\system32\imm32.dll |
c:\windows\system32\msctf.dll |
Image |
---|
c:\windows\microsoft.net\framework\v4.0.30319\regasm.exe |
c:\systemroot\system32\ntdll.dll |
c:\windows\system32\kernel32.dll |
c:\windows\system32\kernelbase.dll |
c:\windows\system32\ws2_32.dll |
c:\windows\system32\msvcrt.dll |
c:\windows\system32\rpcrt4.dll |
c:\windows\system32\nsi.dll |
c:\windows\system32\ole32.dll |
c:\windows\system32\gdi32.dll |
c:\windows\system32\user32.dll |
c:\windows\system32\lpk.dll |
c:\windows\system32\usp10.dll |
c:\windows\system32\oleaut32.dll |
c:\windows\system32\apphelp.dll |
c:\windows\apppatch\acgenral.dll |
c:\windows\system32\sechost.dll |
c:\windows\system32\sspicli.dll |
c:\windows\system32\shlwapi.dll |
c:\windows\system32\uxtheme.dll |
c:\windows\system32\winmm.dll |
c:\windows\system32\samcli.dll |
c:\windows\system32\msacm32.dll |
c:\windows\system32\advapi32.dll |
c:\windows\system32\version.dll |
c:\windows\system32\shell32.dll |
c:\windows\system32\sfc.dll |
c:\windows\system32\sfc_os.dll |
c:\windows\system32\userenv.dll |
c:\windows\system32\profapi.dll |
c:\windows\system32\dwmapi.dll |
c:\windows\system32\setupapi.dll |
c:\windows\system32\cfgmgr32.dll |
c:\windows\system32\devobj.dll |
c:\windows\system32\urlmon.dll |
c:\windows\system32\wininet.dll |
c:\windows\system32\iertutil.dll |
c:\windows\system32\crypt32.dll |
c:\windows\system32\msasn1.dll |
c:\windows\system32\mpr.dll |
c:\windows\system32\imm32.dll |
c:\windows\system32\msctf.dll |
c:\windows\system32\cryptsp.dll |
c:\windows\system32\rsaenh.dll |
c:\windows\system32\cryptbase.dll |
c:\program files\mozilla firefox\nss3.dll |
c:\program files\mozilla firefox\mozglue.dll |
c:\windows\system32\dbghelp.dll |
c:\windows\system32\msvcp140.dll |
c:\windows\system32\vcruntime140.dll |
c:\windows\system32\api-ms-win-crt-runtime-l1-1-0.dll |
c:\windows\system32\ucrtbase.dll |
c:\windows\system32\api-ms-win-core-timezone-l1-1-0.dll |
c:\windows\system32\api-ms-win-core-file-l2-1-0.dll |
c:\windows\system32\api-ms-win-core-localization-l1-2-0.dll |
c:\windows\system32\api-ms-win-core-synch-l1-2-0.dll |
c:\windows\system32\api-ms-win-core-processthreads-l1-1-1.dll |
c:\windows\system32\api-ms-win-core-file-l1-2-0.dll |
c:\windows\system32\api-ms-win-crt-heap-l1-1-0.dll |
c:\windows\system32\api-ms-win-crt-string-l1-1-0.dll |
c:\windows\system32\api-ms-win-crt-stdio-l1-1-0.dll |
c:\windows\system32\api-ms-win-crt-convert-l1-1-0.dll |
c:\windows\system32\api-ms-win-crt-locale-l1-1-0.dll |
c:\windows\system32\api-ms-win-crt-math-l1-1-0.dll |
c:\windows\system32\api-ms-win-crt-filesystem-l1-1-0.dll |
c:\windows\system32\api-ms-win-crt-time-l1-1-0.dll |
c:\windows\system32\api-ms-win-crt-environment-l1-1-0.dll |
c:\windows\system32\api-ms-win-crt-utility-l1-1-0.dll |
c:\windows\system32\wsock32.dll |
c:\windows\system32\api-ms-win-crt-multibyte-l1-1-0.dll |
c:\program files\mozilla firefox\softokn3.dll |
c:\program files\mozilla firefox\freebl3.dll |
c:\windows\system32\vaultcli.dll |
c:\windows\system32\netapi32.dll |
c:\windows\system32\netutils.dll |
c:\windows\system32\srvcli.dll |
c:\windows\system32\wkscli.dll |
c:\windows\system32\samlib.dll |
c:\windows\system32\mswsock.dll |
c:\windows\system32\dnsapi.dll |
c:\windows\system32\iphlpapi.dll |
c:\windows\system32\winnsi.dll |
Process | Message |
---|---|
Haecheng Order Sheet Revised_pdf.exe.bin.exe | *** HR propagated: -2147024774 *** Source File: d:\iso_whid\x86fre\base\isolation\com\identityauthority.cpp, line 278 |
Haecheng Order Sheet Revised_pdf.exe.bin.exe | *** HR propagated: -2147024774 *** Source File: d:\iso_whid\x86fre\base\isolation\com\identityauthority.cpp, line 278 |
Haecheng Order Sheet Revised_pdf.exe.bin.exe | *** HR propagated: -2147024774 *** Source File: d:\iso_whid\x86fre\base\isolation\com\identityauthority.cpp, line 278 |
Haecheng Order Sheet Revised_pdf.exe.bin.exe | *** HR propagated: -2147024774 *** Source File: d:\iso_whid\x86fre\base\isolation\com\identityauthority.cpp, line 278 |
Haecheng Order Sheet Revised_pdf.exe.bin.exe | *** HR propagated: -2147024774 *** Source File: d:\iso_whid\x86fre\base\isolation\com\identityauthority.cpp, line 278 |
Haecheng Order Sheet Revised_pdf.exe.bin.exe | *** HR propagated: -2147024774 *** Source File: d:\iso_whid\x86fre\base\isolation\com\identityauthority.cpp, line 278 |
Haecheng Order Sheet Revised_pdf.exe.bin.exe | *** HR propagated: -2147024774 *** Source File: d:\iso_whid\x86fre\base\isolation\com\identityauthority.cpp, line 278 |
Haecheng Order Sheet Revised_pdf.exe.bin.exe | *** HR propagated: -2147024774 *** Source File: d:\iso_whid\x86fre\base\isolation\com\identityauthority.cpp, line 278 |