Extracted/injected images (may contain unpacked executables)
Download #1
Match: Network_TCP_Socket
Match: Create_Service
Match: Sniff_Audio
Match: Chrome_User_Data_Check_Zero
Match: Escalate_priviledges
Match: KeyLogger
Match: Win_Trojan_agentTesla_Zero
Match: Code_injection
Match: infoStealer_browser_Zero
Match: Network_Downloader
Match: DebuggerCheck__GlobalFlags
Match: DebuggerCheck__QueryInfo
Match: DebuggerHiding__Thread
Match: DebuggerHiding__Active
Match: ThreadControl__Context
Match: SEH__vectored
Match: anti_dbg
Match: disable_dep
Match: win_hook
http://crl4.digicert.com/sha2-assured-ts.crl0 http://crl3.digicert.com/DigiCertHighAssuranceEVRootCA.crl0= http://cacerts.digicert.com/DigiCertSHA2AssuredIDTimestampingCA.crt0 https://www.nuget.org/packages/Newtonsoft.Json.Bson http://ocsp.digicert.com0O http://ocsp.digicert.com0K http://crl4.digicert.com/NETFoundationProjectsCodeSigningCA.crl0L http://crl3.digicert.com/DigiCertAssuredIDRootCA.crl0P http://crl3.digicert.com/NETFoundationProjectsCodeSigningCA.crl0E https://www.newtonsoft.com/jsonschema http://cacerts.digicert.com/NETFoundationProjectsCodeSigningCA.crt0 http://crl4.digicert.com/DigiCertAssuredIDRootCA.crl0: https://www.newtonsoft.com/json http://cacerts.digicert.com/DigiCertAssuredIDRootCA.crt0 http://ocsp.digicert.com0N http://ocsp.digicert.com0C http://crl3.digicert.com/sha2-assured-ts.crl02 https://www.digicert.com/CPS0 http://www.digicert.com/CPS0