Source: cert9.db.0.dr | String found in binary or memory: http://cacerts.digicert.com/DigiCertGlobalRootCA.crt0 |
Source: cert9.db.0.dr | String found in binary or memory: http://cacerts.digicert.com/DigiCertGlobalRootCA.crt0B |
Source: cert9.db.0.dr | String found in binary or memory: http://crl.rootca1.amazontrust.com/rootca1.crl0 |
Source: 123.scr.exe, 00000000.00000002.1686332899.000001DE8E6C5000.00000004.00000020.00020000.00000000.sdmp | String found in binary or memory: http://crl.v |
Source: cert9.db.0.dr | String found in binary or memory: http://crl3.digicert.com/DigiCertGlobalRootCA.crl07 |
Source: cert9.db.0.dr | String found in binary or memory: http://crl3.digicert.com/DigiCertGlobalRootCA.crl0= |
Source: cert9.db.0.dr | String found in binary or memory: http://crl4.digicert.com/DigiCertGlobalRootCA.crl00 |
Source: cert9.db.0.dr | String found in binary or memory: http://crt.rootca1.amazontrust.com/rootca1.cer0? |
Source: 123.scr.exe, 00000000.00000002.1686858017.000001DE90286000.00000004.00000800.00020000.00000000.sdmp | String found in binary or memory: http://freegeoip.app |
Source: 123.scr.exe, 00000000.00000002.1686332899.000001DE8E6C5000.00000004.00000020.00020000.00000000.sdmp | String found in binary or memory: http://go.micQ |
Source: 123.scr.exe, 00000000.00000002.1686858017.000001DE902BF000.00000004.00000800.00020000.00000000.sdmp | String found in binary or memory: http://ipbase.com |
Source: cert9.db.0.dr | String found in binary or memory: http://ocsp.digicert.com0 |
Source: cert9.db.0.dr | String found in binary or memory: http://ocsp.rootca1.amazontrust.com0: |
Source: 123.scr.exe, 00000000.00000002.1686858017.000001DE901F7000.00000004.00000800.00020000.00000000.sdmp | String found in binary or memory: http://schemas.xmlsoap.org/ws/2005/05/identity/claims/name |
Source: cert9.db.0.dr | String found in binary or memory: http://x1.c.lencr.org/0 |
Source: cert9.db.0.dr | String found in binary or memory: http://x1.i.lencr.org/0 |
Source: 123.scr.exe, 00000000.00000002.1690460808.000001DEA0079000.00000004.00000800.00020000.00000000.sdmp, 123.scr.exe, 00000000.00000002.1690460808.000001DEA0593000.00000004.00000800.00020000.00000000.sdmp, tmp47E3.tmp.dat.0.dr, tmp4754.tmp.dat.0.dr | String found in binary or memory: https://ac.ecosia.org/autocomplete?q= |
Source: 123.scr.exe, 00000000.00000002.1686858017.000001DE902A2000.00000004.00000800.00020000.00000000.sdmp, 123.scr.exe, 00000000.00000002.1686858017.000001DE9031A000.00000004.00000800.00020000.00000000.sdmp | String found in binary or memory: https://answers.netlify.com/t/support-guide-i-ve-deployed-my-site-but-i-still-see-page-not-found/125 |
Source: 123.scr.exe, 00000000.00000002.1686858017.000001DE9000E000.00000004.00000800.00020000.00000000.sdmp | String found in binary or memory: https://api.vimeworld.ru/user/name/ |
Source: 123.scr.exe, 00000000.00000002.1690460808.000001DEA0079000.00000004.00000800.00020000.00000000.sdmp, 123.scr.exe, 00000000.00000002.1690460808.000001DEA0593000.00000004.00000800.00020000.00000000.sdmp, tmp47E3.tmp.dat.0.dr, tmp4754.tmp.dat.0.dr | String found in binary or memory: https://cdn.ecosia.org/assets/images/ico/favicon.icohttps://www.ecosia.org/search?q= |
Source: 123.scr.exe, 00000000.00000002.1690460808.000001DEA0079000.00000004.00000800.00020000.00000000.sdmp, 123.scr.exe, 00000000.00000002.1690460808.000001DEA0593000.00000004.00000800.00020000.00000000.sdmp, tmp47E3.tmp.dat.0.dr, tmp4754.tmp.dat.0.dr | String found in binary or memory: https://ch.search.yahoo.com/favicon.icohttps://ch.search.yahoo.com/search |
Source: 123.scr.exe, 00000000.00000002.1690460808.000001DEA0079000.00000004.00000800.00020000.00000000.sdmp, 123.scr.exe, 00000000.00000002.1690460808.000001DEA0593000.00000004.00000800.00020000.00000000.sdmp, tmp47E3.tmp.dat.0.dr, tmp4754.tmp.dat.0.dr | String found in binary or memory: https://ch.search.yahoo.com/sugg/chrome?output=fxjson&appid=crmas&command= |
Source: 123.scr.exe, 00000000.00000002.1686858017.000001DE9000E000.00000004.00000800.00020000.00000000.sdmp | String found in binary or memory: https://discordapp.com/api/webhooks/1184504729359896607/fPAMX9PDaXX6cd_-7EdUwUPRgvGLKrETMXz361gwk0y1 |
Source: 123.scr.exe, 00000000.00000002.1690460808.000001DEA0079000.00000004.00000800.00020000.00000000.sdmp, 123.scr.exe, 00000000.00000002.1690460808.000001DEA0593000.00000004.00000800.00020000.00000000.sdmp, tmp47E3.tmp.dat.0.dr, tmp4754.tmp.dat.0.dr | String found in binary or memory: https://duckduckgo.com/ac/?q= |
Source: 123.scr.exe, 00000000.00000002.1690460808.000001DEA0079000.00000004.00000800.00020000.00000000.sdmp, 123.scr.exe, 00000000.00000002.1690460808.000001DEA0593000.00000004.00000800.00020000.00000000.sdmp, tmp47E3.tmp.dat.0.dr, tmp4754.tmp.dat.0.dr | String found in binary or memory: https://duckduckgo.com/chrome_newtab |
Source: 123.scr.exe, 00000000.00000002.1690460808.000001DEA0079000.00000004.00000800.00020000.00000000.sdmp, 123.scr.exe, 00000000.00000002.1690460808.000001DEA0593000.00000004.00000800.00020000.00000000.sdmp, tmp47E3.tmp.dat.0.dr, tmp4754.tmp.dat.0.dr | String found in binary or memory: https://duckduckgo.com/favicon.icohttps://duckduckgo.com/?q= |
Source: 123.scr.exe, 00000000.00000002.1686858017.000001DE9031A000.00000004.00000800.00020000.00000000.sdmp | String found in binary or memory: https://fonts.googleapis.com/css?family=Roboto:400 |
Source: 123.scr.exe, 00000000.00000002.1686858017.000001DE90262000.00000004.00000800.00020000.00000000.sdmp | String found in binary or memory: https://freegeoip.app |
Source: 123.scr.exe, 00000000.00000002.1686858017.000001DE9000E000.00000004.00000800.00020000.00000000.sdmp, 123.scr.exe, 00000000.00000002.1686858017.000001DE900D8000.00000004.00000800.00020000.00000000.sdmp | String found in binary or memory: https://freegeoip.app/xml/ |
Source: 123.scr.exe, 00000000.00000002.1686858017.000001DE902AA000.00000004.00000800.00020000.00000000.sdmp | String found in binary or memory: https://ipbase.com |
Source: 123.scr.exe, 00000000.00000002.1686858017.000001DE902A6000.00000004.00000800.00020000.00000000.sdmp, 123.scr.exe, 00000000.00000002.1686858017.000001DE90286000.00000004.00000800.00020000.00000000.sdmp, 123.scr.exe, 00000000.00000002.1686858017.000001DE902AA000.00000004.00000800.00020000.00000000.sdmp | String found in binary or memory: https://ipbase.com/xml/ |
Source: 123.scr.exe, 00000000.00000002.1686858017.000001DE9000E000.00000004.00000800.00020000.00000000.sdmp | String found in binary or memory: https://steamcommunity.com/profiles/ |
Source: tmp4714.tmp.tmpdb.0.dr | String found in binary or memory: https://support.mozilla.org |
Source: tmp4714.tmp.tmpdb.0.dr | String found in binary or memory: https://support.mozilla.org/kb/customize-firefox-controls-buttons-and-toolbars?utm_source=firefox-br |
Source: tmp4714.tmp.tmpdb.0.dr | String found in binary or memory: https://support.mozilla.org/products/firefoxgro.allizom.troppus.zvXrErQ5GYDF |
Source: 123.scr.exe, 00000000.00000002.1690460808.000001DEA0079000.00000004.00000800.00020000.00000000.sdmp, 123.scr.exe, 00000000.00000002.1690460808.000001DEA0593000.00000004.00000800.00020000.00000000.sdmp, tmp47E3.tmp.dat.0.dr, tmp4754.tmp.dat.0.dr | String found in binary or memory: https://www.ecosia.org/newtab/ |
Source: 123.scr.exe, 00000000.00000002.1690460808.000001DEA0079000.00000004.00000800.00020000.00000000.sdmp, 123.scr.exe, 00000000.00000002.1690460808.000001DEA0593000.00000004.00000800.00020000.00000000.sdmp, tmp47E3.tmp.dat.0.dr, tmp4754.tmp.dat.0.dr | String found in binary or memory: https://www.google.com/images/branding/product/ico/googleg_lodp.ico |
Source: tmp4714.tmp.tmpdb.0.dr | String found in binary or memory: https://www.mozilla.org |
Source: tmp4714.tmp.tmpdb.0.dr | String found in binary or memory: https://www.mozilla.org/about/gro.allizom.www.VsJpOAWrHqB2 |
Source: tmp4714.tmp.tmpdb.0.dr | String found in binary or memory: https://www.mozilla.org/contribute/gro.allizom.www.n0g9CLHwD9nR |
Source: 123.scr.exe, 00000000.00000002.1690460808.000001DEA009A000.00000004.00000800.00020000.00000000.sdmp, tmp4714.tmp.tmpdb.0.dr | String found in binary or memory: https://www.mozilla.org/en-US/privacy/firefox/Firefox |
Source: tmp4714.tmp.tmpdb.0.dr | String found in binary or memory: https://www.mozilla.org/firefox/?utm_medium=firefox-desktop&utm_source=bookmarks-toolbar&utm_campaig |
Source: 123.scr.exe, 00000000.00000002.1690460808.000001DEA009A000.00000004.00000800.00020000.00000000.sdmp, tmp4714.tmp.tmpdb.0.dr | String found in binary or memory: https://www.mozilla.org/privacy/firefox/gro.allizom.www. |
Source: 00000000.00000002.1686858017.000001DE900D8000.00000004.00000800.00020000.00000000.sdmp, type: MEMORY | Matched rule: Detects executables referencing Discord tokens regular expressions Author: ditekSHen |
Source: 00000000.00000002.1686858017.000001DE9000E000.00000004.00000800.00020000.00000000.sdmp, type: MEMORY | Matched rule: Detects executables referencing Discord tokens regular expressions Author: ditekSHen |
Source: Process Memory Space: 123.scr.exe PID: 6840, type: MEMORYSTR | Matched rule: Detects executables referencing Discord tokens regular expressions Author: ditekSHen |
Source: C:\Users\user\Desktop\123.scr.exe | Code function: 0_2_00007FFD9BAB4F7F | 0_2_00007FFD9BAB4F7F |
Source: C:\Users\user\Desktop\123.scr.exe | Code function: 0_2_00007FFD9BAB07B8 | 0_2_00007FFD9BAB07B8 |
Source: C:\Users\user\Desktop\123.scr.exe | Code function: 0_2_00007FFD9BAB0568 | 0_2_00007FFD9BAB0568 |
Source: C:\Users\user\Desktop\123.scr.exe | Code function: 0_2_00007FFD9BAB089D | 0_2_00007FFD9BAB089D |
Source: C:\Users\user\Desktop\123.scr.exe | Code function: 0_2_00007FFD9BAB9C34 | 0_2_00007FFD9BAB9C34 |
Source: C:\Users\user\Desktop\123.scr.exe | Code function: 0_2_00007FFD9BABDB36 | 0_2_00007FFD9BABDB36 |
Source: C:\Users\user\Desktop\123.scr.exe | Code function: 0_2_00007FFD9BAB0730 | 0_2_00007FFD9BAB0730 |
Source: C:\Users\user\Desktop\123.scr.exe | Code function: 0_2_00007FFD9BAB8A10 | 0_2_00007FFD9BAB8A10 |
Source: C:\Users\user\Desktop\123.scr.exe | Code function: 0_2_00007FFD9BABB1FB | 0_2_00007FFD9BABB1FB |
Source: C:\Users\user\Desktop\123.scr.exe | Code function: 0_2_00007FFD9BAB0500 | 0_2_00007FFD9BAB0500 |
Source: C:\Users\user\Desktop\123.scr.exe | Code function: 0_2_00007FFD9BABDC7F | 0_2_00007FFD9BABDC7F |
Source: 00000000.00000002.1686858017.000001DE900D8000.00000004.00000800.00020000.00000000.sdmp, type: MEMORY | Matched rule: INDICATOR_SUSPICIOUS_EXE_Discord_Regex author = ditekSHen, description = Detects executables referencing Discord tokens regular expressions |
Source: 00000000.00000002.1686858017.000001DE9000E000.00000004.00000800.00020000.00000000.sdmp, type: MEMORY | Matched rule: INDICATOR_SUSPICIOUS_EXE_Discord_Regex author = ditekSHen, description = Detects executables referencing Discord tokens regular expressions |
Source: Process Memory Space: 123.scr.exe PID: 6840, type: MEMORYSTR | Matched rule: INDICATOR_SUSPICIOUS_EXE_Discord_Regex author = ditekSHen, description = Detects executables referencing Discord tokens regular expressions |
Source: C:\Users\user\Desktop\123.scr.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\123.scr.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\123.scr.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\123.scr.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\123.scr.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\123.scr.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\123.scr.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\123.scr.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\123.scr.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\123.scr.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\123.scr.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\123.scr.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\123.scr.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\123.scr.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\123.scr.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\123.scr.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\123.scr.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\123.scr.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\123.scr.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\123.scr.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\123.scr.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\123.scr.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\123.scr.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\123.scr.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\123.scr.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\123.scr.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\123.scr.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\123.scr.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\123.scr.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\123.scr.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\123.scr.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\123.scr.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\123.scr.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\123.scr.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\123.scr.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\123.scr.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\123.scr.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\123.scr.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\123.scr.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\123.scr.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\123.scr.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\123.scr.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\123.scr.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\123.scr.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\123.scr.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\123.scr.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\123.scr.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\123.scr.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\123.scr.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\123.scr.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\123.scr.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\123.scr.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\123.scr.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\123.scr.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\123.scr.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\123.scr.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\123.scr.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\123.scr.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\123.scr.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\123.scr.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\123.scr.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\123.scr.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\123.scr.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\123.scr.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\123.scr.exe | Thread delayed: delay time: 922337203685477 | Jump to behavior |
Source: C:\Users\user\Desktop\123.scr.exe | Thread delayed: delay time: 600000 | Jump to behavior |
Source: C:\Users\user\Desktop\123.scr.exe | Thread delayed: delay time: 599875 | Jump to behavior |
Source: C:\Users\user\Desktop\123.scr.exe | Thread delayed: delay time: 599766 | Jump to behavior |
Source: C:\Users\user\Desktop\123.scr.exe | Thread delayed: delay time: 599657 | Jump to behavior |
Source: C:\Users\user\Desktop\123.scr.exe | Thread delayed: delay time: 599532 | Jump to behavior |
Source: C:\Users\user\Desktop\123.scr.exe | Thread delayed: delay time: 599422 | Jump to behavior |
Source: C:\Users\user\Desktop\123.scr.exe | Thread delayed: delay time: 599308 | Jump to behavior |
Source: C:\Users\user\Desktop\123.scr.exe | Thread delayed: delay time: 599188 | Jump to behavior |
Source: C:\Users\user\Desktop\123.scr.exe | Thread delayed: delay time: 599063 | Jump to behavior |
Source: C:\Users\user\Desktop\123.scr.exe | Thread delayed: delay time: 598938 | Jump to behavior |
Source: C:\Users\user\Desktop\123.scr.exe | Thread delayed: delay time: 598813 | Jump to behavior |
Source: C:\Users\user\Desktop\123.scr.exe | Thread delayed: delay time: 598704 | Jump to behavior |
Source: C:\Users\user\Desktop\123.scr.exe | Thread delayed: delay time: 598579 | Jump to behavior |
Source: C:\Users\user\Desktop\123.scr.exe | Thread delayed: delay time: 598454 | Jump to behavior |
Source: C:\Users\user\Desktop\123.scr.exe | Thread delayed: delay time: 922337203685477 | Jump to behavior |
Source: C:\Users\user\Desktop\123.scr.exe TID: 6332 | Thread sleep time: -8301034833169293s >= -30000s | Jump to behavior |
Source: C:\Users\user\Desktop\123.scr.exe TID: 6332 | Thread sleep time: -600000s >= -30000s | Jump to behavior |
Source: C:\Users\user\Desktop\123.scr.exe TID: 6332 | Thread sleep time: -599875s >= -30000s | Jump to behavior |
Source: C:\Users\user\Desktop\123.scr.exe TID: 6332 | Thread sleep time: -599766s >= -30000s | Jump to behavior |
Source: C:\Users\user\Desktop\123.scr.exe TID: 6332 | Thread sleep time: -599657s >= -30000s | Jump to behavior |
Source: C:\Users\user\Desktop\123.scr.exe TID: 6332 | Thread sleep time: -599532s >= -30000s | Jump to behavior |
Source: C:\Users\user\Desktop\123.scr.exe TID: 6332 | Thread sleep time: -599422s >= -30000s | Jump to behavior |
Source: C:\Users\user\Desktop\123.scr.exe TID: 6332 | Thread sleep time: -599308s >= -30000s | Jump to behavior |
Source: C:\Users\user\Desktop\123.scr.exe TID: 6332 | Thread sleep time: -599188s >= -30000s | Jump to behavior |
Source: C:\Users\user\Desktop\123.scr.exe TID: 6332 | Thread sleep time: -599063s >= -30000s | Jump to behavior |
Source: C:\Users\user\Desktop\123.scr.exe TID: 6332 | Thread sleep time: -598938s >= -30000s | Jump to behavior |
Source: C:\Users\user\Desktop\123.scr.exe TID: 6332 | Thread sleep time: -598813s >= -30000s | Jump to behavior |
Source: C:\Users\user\Desktop\123.scr.exe TID: 6332 | Thread sleep time: -598704s >= -30000s | Jump to behavior |
Source: C:\Users\user\Desktop\123.scr.exe TID: 6332 | Thread sleep time: -598579s >= -30000s | Jump to behavior |
Source: C:\Users\user\Desktop\123.scr.exe TID: 6332 | Thread sleep time: -598454s >= -30000s | Jump to behavior |
Source: C:\Users\user\Desktop\123.scr.exe TID: 7120 | Thread sleep time: -30000s >= -30000s | Jump to behavior |
Source: C:\Users\user\Desktop\123.scr.exe TID: 6912 | Thread sleep time: -922337203685477s >= -30000s | Jump to behavior |
Source: C:\Users\user\Desktop\123.scr.exe | Thread delayed: delay time: 922337203685477 | Jump to behavior |
Source: C:\Users\user\Desktop\123.scr.exe | Thread delayed: delay time: 600000 | Jump to behavior |
Source: C:\Users\user\Desktop\123.scr.exe | Thread delayed: delay time: 599875 | Jump to behavior |
Source: C:\Users\user\Desktop\123.scr.exe | Thread delayed: delay time: 599766 | Jump to behavior |
Source: C:\Users\user\Desktop\123.scr.exe | Thread delayed: delay time: 599657 | Jump to behavior |
Source: C:\Users\user\Desktop\123.scr.exe | Thread delayed: delay time: 599532 | Jump to behavior |
Source: C:\Users\user\Desktop\123.scr.exe | Thread delayed: delay time: 599422 | Jump to behavior |
Source: C:\Users\user\Desktop\123.scr.exe | Thread delayed: delay time: 599308 | Jump to behavior |
Source: C:\Users\user\Desktop\123.scr.exe | Thread delayed: delay time: 599188 | Jump to behavior |
Source: C:\Users\user\Desktop\123.scr.exe | Thread delayed: delay time: 599063 | Jump to behavior |
Source: C:\Users\user\Desktop\123.scr.exe | Thread delayed: delay time: 598938 | Jump to behavior |
Source: C:\Users\user\Desktop\123.scr.exe | Thread delayed: delay time: 598813 | Jump to behavior |
Source: C:\Users\user\Desktop\123.scr.exe | Thread delayed: delay time: 598704 | Jump to behavior |
Source: C:\Users\user\Desktop\123.scr.exe | Thread delayed: delay time: 598579 | Jump to behavior |
Source: C:\Users\user\Desktop\123.scr.exe | Thread delayed: delay time: 598454 | Jump to behavior |
Source: C:\Users\user\Desktop\123.scr.exe | Thread delayed: delay time: 922337203685477 | Jump to behavior |
Source: 123.scr.exe, 00000000.00000002.1692233734.000001DEA89D6000.00000004.00000020.00020000.00000000.sdmp | Binary or memory string: Hyper-V RAW%SystemRoot%\system32\mswsock.dllXz" |
Source: 123.scr.exe, 00000000.00000002.1692233734.000001DEA89D6000.00000004.00000020.00020000.00000000.sdmp | Binary or memory string: VMware |
Source: 123.scr.exe, 00000000.00000002.1692233734.000001DEA89D6000.00000004.00000020.00020000.00000000.sdmp | Binary or memory string: Win32_VideoController(Standard display types)VMwarePS7ON1OFWin32_VideoControllerPN_KWUCDVideoController120060621000000.000000-00044967925display.infMSBDA6EU8CVZ1PCI\VEN_15AD&DEV_0405&SUBSYS_040515AD&REV_00\3&61AAA01&0&78OKWin32_ComputerSystemuser-PC1280 x 1024 x 4294967296 colorsS9ODUAU9 |
Source: 123.scr.exe, 00000000.00000002.1686858017.000001DE9000E000.00000004.00000800.00020000.00000000.sdmp | String found in binary or memory: \Electrum\wallets |
Source: 123.scr.exe, 00000000.00000002.1686858017.000001DE900D8000.00000004.00000800.00020000.00000000.sdmp | String found in binary or memory: 1C:\Users\user\AppData\Roaming\Electrum\wallets\* |
Source: 123.scr.exe, 00000000.00000002.1686858017.000001DE9000E000.00000004.00000800.00020000.00000000.sdmp | String found in binary or memory: \com.liberty.jaxx\IndexedDB\file__0.indexeddb.leveldb\ |
Source: 123.scr.exe, 00000000.00000002.1686858017.000001DE9000E000.00000004.00000800.00020000.00000000.sdmp | String found in binary or memory: \Exodus\exodus.wallet\ |
Source: 123.scr.exe, 00000000.00000002.1686858017.000001DE9000E000.00000004.00000800.00020000.00000000.sdmp | String found in binary or memory: \Ethereum\keystore |
Source: 123.scr.exe, 00000000.00000002.1686858017.000001DE9000E000.00000004.00000800.00020000.00000000.sdmp | String found in binary or memory: \Exodus\exodus.wallet\ |
Source: 123.scr.exe, 00000000.00000002.1686858017.000001DE9000E000.00000004.00000800.00020000.00000000.sdmp | String found in binary or memory: \Ethereum\keystore |
Source: 123.scr.exe, 00000000.00000002.1686858017.000001DE9000E000.00000004.00000800.00020000.00000000.sdmp | String found in binary or memory: \Exodus\exodus.wallet\ |
Source: 123.scr.exe, 00000000.00000002.1686858017.000001DE9000E000.00000004.00000800.00020000.00000000.sdmp | String found in binary or memory: \Ethereum\keystore |
Source: C:\Users\user\Desktop\123.scr.exe | File opened: C:\Users\user\AppData\Roaming\Mozilla\Firefox\Profiles\fqs92o4p.default-release\key4.db | Jump to behavior |
Source: C:\Users\user\Desktop\123.scr.exe | File opened: C:\Users\user\AppData\Roaming\Mozilla\Firefox\Profiles\fqs92o4p.default-release\cert9.db | Jump to behavior |
Source: C:\Users\user\Desktop\123.scr.exe | File opened: C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Login Data | Jump to behavior |
Source: C:\Users\user\Desktop\123.scr.exe | File opened: C:\Users\user\AppData\Local\Microsoft\Edge\User Data\Default\Login Data | Jump to behavior |
Source: C:\Users\user\Desktop\123.scr.exe | File opened: C:\Users\user\AppData\Roaming\Mozilla\Firefox\Profiles\fqs92o4p.default-release\cookies.sqlite | Jump to behavior |
Source: C:\Users\user\Desktop\123.scr.exe | File opened: C:\Users\user\AppData\Roaming\Mozilla\Firefox\Profiles\fqs92o4p.default-release\places.sqlite | Jump to behavior |
Source: C:\Users\user\Desktop\123.scr.exe | File opened: C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Web Data | Jump to behavior |