Source: C:\Users\user\Desktop\._cache_1.exe |
Code function: 0_2_004339B6 GetFileAttributesW,FindFirstFileW,FindClose, |
0_2_004339B6 |
Source: C:\Users\user\Desktop\._cache_1.exe |
Code function: 0_2_0044BD27 _wcscat,_wcscat,__wsplitpath,FindFirstFileW,CopyFileW,_wcscpy,_wcscat,_wcscat,lstrcmpiW,DeleteFileW,MoveFileW,CopyFileW,DeleteFileW,CopyFileW,FindClose,MoveFileW,FindNextFileW,FindClose, |
0_2_0044BD27 |
Source: C:\Users\user\Desktop\._cache_1.exe |
Code function: 0_2_0044BF8B _wcscat,__wsplitpath,FindFirstFileW,_wcscpy,_wcscat,_wcscat,DeleteFileW,FindNextFileW,FindClose,FindClose, |
0_2_0044BF8B |
Source: C:\Users\user\Desktop\._cache_1.exe |
Code function: 0_2_00452492 FindFirstFileW,Sleep,FindNextFileW,FindClose, |
0_2_00452492 |
Source: C:\Users\user\Desktop\._cache_1.exe |
Code function: 0_2_00442886 FindFirstFileW,FindFirstFileW,FindNextFileW,FindClose,FindClose,FindClose,FindFirstFileW,SetCurrentDirectoryW,SetCurrentDirectoryW,SetCurrentDirectoryW,FindNextFileW,FindClose,FindClose, |
0_2_00442886 |
Source: C:\Users\user\Desktop\._cache_1.exe |
Code function: 0_2_004788BD FindFirstFileW,FindClose,FileTimeToLocalFileTime,FileTimeToLocalFileTime,FileTimeToLocalFileTime,FileTimeToSystemTime,__swprintf,__swprintf,__swprintf,__swprintf,__swprintf,__swprintf,__swprintf, |
0_2_004788BD |
Source: C:\Users\user\Desktop\._cache_1.exe |
Code function: 0_2_0045CAFA FindFirstFileW,FindNextFileW,FindClose, |
0_2_0045CAFA |
Source: C:\Users\user\Desktop\._cache_1.exe |
Code function: 0_2_00431A86 FindFirstFileW,FindFirstFileW,GetFileAttributesW,SetFileAttributesW,FindNextFileW,FindClose,FindClose,FindClose,FindFirstFileW,SetCurrentDirectoryW,SetCurrentDirectoryW,SetCurrentDirectoryW,FindNextFileW,FindClose,FindClose, |
0_2_00431A86 |
Source: C:\Users\user\Desktop\._cache_1.exe |
Code function: 0_2_0045DE8F FindFirstFileW,FindClose, |
0_2_0045DE8F |
Source: C:\Users\user\AppData\Local\Temp\Tr.exe |
Code function: 1_2_00B2449B GetFileAttributesW,FindFirstFileW,FindClose, |
1_2_00B2449B |
Source: C:\Users\user\AppData\Local\Temp\Tr.exe |
Code function: 1_2_00B2C7E8 FindFirstFileW,FindClose,FileTimeToLocalFileTime,FileTimeToLocalFileTime,FileTimeToLocalFileTime,FileTimeToSystemTime,__swprintf,__swprintf,__swprintf,__swprintf,__swprintf,__swprintf,__swprintf, |
1_2_00B2C7E8 |
Source: C:\Users\user\AppData\Local\Temp\Tr.exe |
Code function: 1_2_00B2C75D FindFirstFileW,FindClose, |
1_2_00B2C75D |
Source: C:\Users\user\AppData\Local\Temp\Tr.exe |
Code function: 1_2_00B2F021 SetCurrentDirectoryW,FindFirstFileW,FindFirstFileW,_wcscmp,_wcscmp,GetFileAttributesW,SetFileAttributesW,FindNextFileW,FindClose,FindFirstFileW,SetCurrentDirectoryW,_wcscmp,_wcscmp,SetCurrentDirectoryW,SetCurrentDirectoryW,FindNextFileW,FindClose,FindClose, |
1_2_00B2F021 |
Source: C:\Users\user\AppData\Local\Temp\Tr.exe |
Code function: 1_2_00B2F17E SetCurrentDirectoryW,FindFirstFileW,FindFirstFileW,_wcscmp,_wcscmp,FindNextFileW,FindClose,FindFirstFileW,SetCurrentDirectoryW,_wcscmp,_wcscmp,SetCurrentDirectoryW,SetCurrentDirectoryW,FindNextFileW,FindClose,FindClose, |
1_2_00B2F17E |
Source: C:\Users\user\AppData\Local\Temp\Tr.exe |
Code function: 1_2_00B2F47F FindFirstFileW,Sleep,_wcscmp,_wcscmp,FindNextFileW,FindClose, |
1_2_00B2F47F |
Source: C:\Users\user\AppData\Local\Temp\Tr.exe |
Code function: 1_2_00B23833 FindFirstFileW,DeleteFileW,DeleteFileW,MoveFileW,DeleteFileW,FindNextFileW,FindClose,FindClose, |
1_2_00B23833 |
Source: C:\Users\user\AppData\Local\Temp\Tr.exe |
Code function: 1_2_00B23B56 FindFirstFileW,DeleteFileW,FindNextFileW,FindClose,FindClose, |
1_2_00B23B56 |
Source: C:\Users\user\AppData\Local\Temp\Tr.exe |
Code function: 1_2_00B2BD48 FindFirstFileW,_wcscmp,_wcscmp,FindNextFileW,FindClose, |
1_2_00B2BD48 |
Source: C:\Users\user\AppData\Local\Temp\Tr.exe |
Code function: 12_2_0040449B GetFileAttributesW,FindFirstFileW,FindClose, |
12_2_0040449B |
Source: C:\Users\user\AppData\Local\Temp\Tr.exe |
Code function: 12_2_0040C75D FindFirstFileW,FindClose, |
12_2_0040C75D |
Source: C:\Users\user\AppData\Local\Temp\Tr.exe |
Code function: 12_2_0040C7E8 FindFirstFileW,FindClose,FileTimeToLocalFileTime,FileTimeToLocalFileTime,FileTimeToLocalFileTime,FileTimeToSystemTime,__swprintf,__swprintf,__swprintf,__swprintf,__swprintf,__swprintf,__swprintf, |
12_2_0040C7E8 |
Source: C:\Users\user\AppData\Local\Temp\Tr.exe |
Code function: 12_2_0040F021 SetCurrentDirectoryW,FindFirstFileW,FindFirstFileW,_wcscmp,_wcscmp,GetFileAttributesW,SetFileAttributesW,FindNextFileW,FindClose,FindFirstFileW,SetCurrentDirectoryW,_wcscmp,_wcscmp,SetCurrentDirectoryW,SetCurrentDirectoryW,FindNextFileW,FindClose,FindClose, |
12_2_0040F021 |
Source: C:\Users\user\AppData\Local\Temp\Tr.exe |
Code function: 12_2_0040F17E SetCurrentDirectoryW,FindFirstFileW,FindFirstFileW,_wcscmp,_wcscmp,FindNextFileW,FindClose,FindFirstFileW,SetCurrentDirectoryW,_wcscmp,_wcscmp,SetCurrentDirectoryW,SetCurrentDirectoryW,FindNextFileW,FindClose,FindClose, |
12_2_0040F17E |
Source: C:\Users\user\AppData\Local\Temp\Tr.exe |
Code function: 12_2_0040F47F FindFirstFileW,Sleep,_wcscmp,_wcscmp,FindNextFileW,FindClose, |
12_2_0040F47F |
Source: C:\Users\user\AppData\Local\Temp\Tr.exe |
Code function: 12_2_00403833 FindFirstFileW,DeleteFileW,DeleteFileW,MoveFileW,DeleteFileW,FindNextFileW,FindClose,FindClose, |
12_2_00403833 |
Source: C:\Users\user\AppData\Local\Temp\Tr.exe |
Code function: 12_2_00403B56 FindFirstFileW,DeleteFileW,FindNextFileW,FindClose,FindClose, |
12_2_00403B56 |
Source: C:\Users\user\AppData\Local\Temp\Tr.exe |
Code function: 12_2_0040BD48 FindFirstFileW,_wcscmp,_wcscmp,FindNextFileW,FindClose, |
12_2_0040BD48 |
Source: C:\Users\user\Desktop\._cache_1.exe |
Code function: 0_2_0047C81C SendMessageW,DefDlgProcW,GetKeyState,GetKeyState,GetKeyState,SendMessageW,GetKeyState,GetWindowLongW,SendMessageW,SendMessageW,SendMessageW,_wcsncpy,SendMessageW,SendMessageW,SendMessageW,InvalidateRect,SendMessageW,ImageList_SetDragCursorImage,ImageList_BeginDrag,SetCapture,ClientToScreen,ImageList_DragEnter,ReleaseCapture,GetCursorPos,ScreenToClient,SendMessageW,SendMessageW,SendMessageW,SendMessageW,SendMessageW,SendMessageW,SendMessageW,SendMessageW,GetCursorPos,ScreenToClient,GetParent,SendMessageW,SendMessageW,ClientToScreen,TrackPopupMenuEx,SendMessageW,SendMessageW,ClientToScreen,TrackPopupMenuEx,GetWindowLongW, |
0_2_0047C81C |
Source: C:\Users\user\AppData\Local\Temp\Tr.exe |
Code function: 1_2_00B4CB26 DefDlgProcW,SendMessageW,GetWindowLongW,SendMessageW,SendMessageW,_wcsncpy,GetKeyState,GetKeyState,GetKeyState,SendMessageW,GetKeyState,SendMessageW,SendMessageW,SendMessageW,ImageList_SetDragCursorImage,ImageList_BeginDrag,SetCapture,ClientToScreen,ImageList_DragEnter,InvalidateRect,ReleaseCapture,GetCursorPos,ScreenToClient,SendMessageW,SendMessageW,SendMessageW,SendMessageW,SendMessageW,SendMessageW,SendMessageW,GetCursorPos,ScreenToClient,GetParent,SendMessageW,SendMessageW,ClientToScreen,TrackPopupMenuEx,SendMessageW,SendMessageW,ClientToScreen,TrackPopupMenuEx,GetWindowLongW, |
1_2_00B4CB26 |
Source: C:\Users\user\AppData\Local\Temp\Tr.exe |
Code function: 12_2_0042CB26 DefDlgProcW,SendMessageW,GetWindowLongW,SendMessageW,SendMessageW,_wcsncpy,GetKeyState,GetKeyState,GetKeyState,SendMessageW,GetKeyState,SendMessageW,SendMessageW,SendMessageW,ImageList_SetDragCursorImage,ImageList_BeginDrag,SetCapture,ClientToScreen,ImageList_DragEnter,InvalidateRect,ReleaseCapture,GetCursorPos,ScreenToClient,SendMessageW,SendMessageW,SendMessageW,SendMessageW,SendMessageW,SendMessageW,SendMessageW,GetCursorPos,ScreenToClient,GetParent,SendMessageW,SendMessageW,ClientToScreen,TrackPopupMenuEx,SendMessageW,SendMessageW,ClientToScreen,TrackPopupMenuEx,GetWindowLongW, |
12_2_0042CB26 |
Source: C:\Users\user\Desktop\._cache_1.exe |
Code function: 0_2_0042200C |
0_2_0042200C |
Source: C:\Users\user\Desktop\._cache_1.exe |
Code function: 0_2_0041A217 |
0_2_0041A217 |
Source: C:\Users\user\Desktop\._cache_1.exe |
Code function: 0_2_00412216 |
0_2_00412216 |
Source: C:\Users\user\Desktop\._cache_1.exe |
Code function: 0_2_0042435D |
0_2_0042435D |
Source: C:\Users\user\Desktop\._cache_1.exe |
Code function: 0_2_004033C0 |
0_2_004033C0 |
Source: C:\Users\user\Desktop\._cache_1.exe |
Code function: 0_2_004125E8 |
0_2_004125E8 |
Source: C:\Users\user\Desktop\._cache_1.exe |
Code function: 0_2_0044663B |
0_2_0044663B |
Source: C:\Users\user\Desktop\._cache_1.exe |
Code function: 0_2_004096A0 |
0_2_004096A0 |
Source: C:\Users\user\Desktop\._cache_1.exe |
Code function: 0_2_00413801 |
0_2_00413801 |
Source: C:\Users\user\Desktop\._cache_1.exe |
Code function: 0_2_0042096F |
0_2_0042096F |
Source: C:\Users\user\Desktop\._cache_1.exe |
Code function: 0_2_004129D0 |
0_2_004129D0 |
Source: C:\Users\user\Desktop\._cache_1.exe |
Code function: 0_2_004119E3 |
0_2_004119E3 |
Source: C:\Users\user\Desktop\._cache_1.exe |
Code function: 0_2_0041C9AE |
0_2_0041C9AE |
Source: C:\Users\user\Desktop\._cache_1.exe |
Code function: 0_2_0047EA6F |
0_2_0047EA6F |
Source: C:\Users\user\Desktop\._cache_1.exe |
Code function: 0_2_0040FA10 |
0_2_0040FA10 |
Source: C:\Users\user\Desktop\._cache_1.exe |
Code function: 0_2_00423C81 |
0_2_00423C81 |
Source: C:\Users\user\Desktop\._cache_1.exe |
Code function: 0_2_00411E78 |
0_2_00411E78 |
Source: C:\Users\user\Desktop\._cache_1.exe |
Code function: 0_2_00442E0C |
0_2_00442E0C |
Source: C:\Users\user\Desktop\._cache_1.exe |
Code function: 0_2_00420EC0 |
0_2_00420EC0 |
Source: C:\Users\user\Desktop\._cache_1.exe |
Code function: 0_2_0044CF17 |
0_2_0044CF17 |
Source: C:\Users\user\Desktop\._cache_1.exe |
Code function: 0_2_00444FD2 |
0_2_00444FD2 |
Source: C:\Users\user\AppData\Local\Temp\Tr.exe |
Code function: 1_2_00B408E2 |
1_2_00B408E2 |
Source: C:\Users\user\AppData\Local\Temp\Tr.exe |
Code function: 1_2_00ACE800 |
1_2_00ACE800 |
Source: C:\Users\user\AppData\Local\Temp\Tr.exe |
Code function: 1_2_00AE3307 |
1_2_00AE3307 |
Source: C:\Users\user\AppData\Local\Temp\Tr.exe |
Code function: 1_2_00ACE060 |
1_2_00ACE060 |
Source: C:\Users\user\AppData\Local\Temp\Tr.exe |
Code function: 1_2_00AD4140 |
1_2_00AD4140 |
Source: C:\Users\user\AppData\Local\Temp\Tr.exe |
Code function: 1_2_00AE2345 |
1_2_00AE2345 |
Source: C:\Users\user\AppData\Local\Temp\Tr.exe |
Code function: 1_2_00B40465 |
1_2_00B40465 |
Source: C:\Users\user\AppData\Local\Temp\Tr.exe |
Code function: 1_2_00AF6452 |
1_2_00AF6452 |
Source: C:\Users\user\AppData\Local\Temp\Tr.exe |
Code function: 1_2_00AF25AE |
1_2_00AF25AE |
Source: C:\Users\user\AppData\Local\Temp\Tr.exe |
Code function: 1_2_00AE277A |
1_2_00AE277A |
Source: C:\Users\user\AppData\Local\Temp\Tr.exe |
Code function: 1_2_00AD6841 |
1_2_00AD6841 |
Source: C:\Users\user\AppData\Local\Temp\Tr.exe |
Code function: 1_2_00AF69C4 |
1_2_00AF69C4 |
Source: C:\Users\user\AppData\Local\Temp\Tr.exe |
Code function: 1_2_00B28932 |
1_2_00B28932 |
Source: C:\Users\user\AppData\Local\Temp\Tr.exe |
Code function: 1_2_00B1E928 |
1_2_00B1E928 |
Source: C:\Users\user\AppData\Local\Temp\Tr.exe |
Code function: 1_2_00AF890F |
1_2_00AF890F |
Source: C:\Users\user\AppData\Local\Temp\Tr.exe |
Code function: 1_2_00AD8968 |
1_2_00AD8968 |
Source: C:\Users\user\AppData\Local\Temp\Tr.exe |
Code function: 1_2_00AECCA1 |
1_2_00AECCA1 |
Source: C:\Users\user\AppData\Local\Temp\Tr.exe |
Code function: 1_2_00AF6F36 |
1_2_00AF6F36 |
Source: C:\Users\user\AppData\Local\Temp\Tr.exe |
Code function: 1_2_00AD70FE |
1_2_00AD70FE |
Source: C:\Users\user\AppData\Local\Temp\Tr.exe |
Code function: 1_2_00AD3190 |
1_2_00AD3190 |
Source: C:\Users\user\AppData\Local\Temp\Tr.exe |
Code function: 1_2_00AC1287 |
1_2_00AC1287 |
Source: C:\Users\user\AppData\Local\Temp\Tr.exe |
Code function: 1_2_00AEF359 |
1_2_00AEF359 |
Source: C:\Users\user\AppData\Local\Temp\Tr.exe |
Code function: 1_2_00AD5680 |
1_2_00AD5680 |
Source: C:\Users\user\AppData\Local\Temp\Tr.exe |
Code function: 1_2_00AE1604 |
1_2_00AE1604 |
Source: C:\Users\user\AppData\Local\Temp\Tr.exe |
Code function: 1_2_00AD58C0 |
1_2_00AD58C0 |
Source: C:\Users\user\AppData\Local\Temp\Tr.exe |
Code function: 1_2_00AE7813 |
1_2_00AE7813 |
Source: C:\Users\user\AppData\Local\Temp\Tr.exe |
Code function: 1_2_00AE1AF8 |
1_2_00AE1AF8 |
Source: C:\Users\user\AppData\Local\Temp\Tr.exe |
Code function: 1_2_00AEDAF5 |
1_2_00AEDAF5 |
Source: C:\Users\user\AppData\Local\Temp\Tr.exe |
Code function: 1_2_00AF9C35 |
1_2_00AF9C35 |
Source: C:\Users\user\AppData\Local\Temp\Tr.exe |
Code function: 1_2_00B47E0D |
1_2_00B47E0D |
Source: C:\Users\user\AppData\Local\Temp\Tr.exe |
Code function: 1_2_00ACFE40 |
1_2_00ACFE40 |
Source: C:\Users\user\AppData\Local\Temp\Tr.exe |
Code function: 1_2_00AEBF26 |
1_2_00AEBF26 |
Source: C:\Users\user\AppData\Local\Temp\Tr.exe |
Code function: 1_2_00AE1F10 |
1_2_00AE1F10 |
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe |
Code function: 4_2_000007FE93D7F836 |
4_2_000007FE93D7F836 |
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe |
Code function: 4_2_000007FE93D797E8 |
4_2_000007FE93D797E8 |
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe |
Code function: 4_2_000007FE93D805E2 |
4_2_000007FE93D805E2 |
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe |
Code function: 4_2_000007FE93D7F339 |
4_2_000007FE93D7F339 |
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe |
Code function: 4_2_000007FE93D745C5 |
4_2_000007FE93D745C5 |
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe |
Code function: 4_2_000007FE93E41416 |
4_2_000007FE93E41416 |
Source: C:\Users\user\AppData\Local\Temp\Tr.exe |
Code function: 12_2_003AE800 |
12_2_003AE800 |
Source: C:\Users\user\AppData\Local\Temp\Tr.exe |
Code function: 12_2_004208E2 |
12_2_004208E2 |
Source: C:\Users\user\AppData\Local\Temp\Tr.exe |
Code function: 12_2_003C3307 |
12_2_003C3307 |
Source: C:\Users\user\AppData\Local\Temp\Tr.exe |
Code function: 12_2_003AE060 |
12_2_003AE060 |
Source: C:\Users\user\AppData\Local\Temp\Tr.exe |
Code function: 12_2_003B4140 |
12_2_003B4140 |
Source: C:\Users\user\AppData\Local\Temp\Tr.exe |
Code function: 12_2_003C2345 |
12_2_003C2345 |
Source: C:\Users\user\AppData\Local\Temp\Tr.exe |
Code function: 12_2_00420465 |
12_2_00420465 |
Source: C:\Users\user\AppData\Local\Temp\Tr.exe |
Code function: 12_2_003D6452 |
12_2_003D6452 |
Source: C:\Users\user\AppData\Local\Temp\Tr.exe |
Code function: 12_2_003D25AE |
12_2_003D25AE |
Source: C:\Users\user\AppData\Local\Temp\Tr.exe |
Code function: 12_2_003C277A |
12_2_003C277A |
Source: C:\Users\user\AppData\Local\Temp\Tr.exe |
Code function: 12_2_003B6841 |
12_2_003B6841 |
Source: C:\Users\user\AppData\Local\Temp\Tr.exe |
Code function: 12_2_003FE928 |
12_2_003FE928 |
Source: C:\Users\user\AppData\Local\Temp\Tr.exe |
Code function: 12_2_003D890F |
12_2_003D890F |
Source: C:\Users\user\AppData\Local\Temp\Tr.exe |
Code function: 12_2_003B8968 |
12_2_003B8968 |
Source: C:\Users\user\AppData\Local\Temp\Tr.exe |
Code function: 12_2_00408932 |
12_2_00408932 |
Source: C:\Users\user\AppData\Local\Temp\Tr.exe |
Code function: 12_2_003D69C4 |
12_2_003D69C4 |
Source: C:\Users\user\AppData\Local\Temp\Tr.exe |
Code function: 12_2_003CCCA1 |
12_2_003CCCA1 |
Source: C:\Users\user\AppData\Local\Temp\Tr.exe |
Code function: 12_2_003D6F36 |
12_2_003D6F36 |
Source: C:\Users\user\AppData\Local\Temp\Tr.exe |
Code function: 12_2_003B70FE |
12_2_003B70FE |
Source: C:\Users\user\AppData\Local\Temp\Tr.exe |
Code function: 12_2_003B3190 |
12_2_003B3190 |
Source: C:\Users\user\AppData\Local\Temp\Tr.exe |
Code function: 12_2_003A1287 |
12_2_003A1287 |
Source: C:\Users\user\AppData\Local\Temp\Tr.exe |
Code function: 12_2_003CF359 |
12_2_003CF359 |
Source: C:\Users\user\AppData\Local\Temp\Tr.exe |
Code function: 12_2_003C1604 |
12_2_003C1604 |
Source: C:\Users\user\AppData\Local\Temp\Tr.exe |
Code function: 12_2_003B5680 |
12_2_003B5680 |
Source: C:\Users\user\AppData\Local\Temp\Tr.exe |
Code function: 12_2_003C7813 |
12_2_003C7813 |
Source: C:\Users\user\AppData\Local\Temp\Tr.exe |
Code function: 12_2_003B58C0 |
12_2_003B58C0 |
Source: C:\Users\user\AppData\Local\Temp\Tr.exe |
Code function: 12_2_003C1AF8 |
12_2_003C1AF8 |
Source: C:\Users\user\AppData\Local\Temp\Tr.exe |
Code function: 12_2_003CDAF5 |
12_2_003CDAF5 |
Source: C:\Users\user\AppData\Local\Temp\Tr.exe |
Code function: 12_2_003D9C35 |
12_2_003D9C35 |
Source: C:\Users\user\AppData\Local\Temp\Tr.exe |
Code function: 12_2_00427E0D |
12_2_00427E0D |
Source: C:\Users\user\AppData\Local\Temp\Tr.exe |
Code function: 12_2_003AFE40 |
12_2_003AFE40 |
Source: C:\Users\user\AppData\Local\Temp\Tr.exe |
Code function: 12_2_003CBF26 |
12_2_003CBF26 |
Source: C:\Users\user\AppData\Local\Temp\Tr.exe |
Code function: 12_2_003C1F10 |
12_2_003C1F10 |
Source: 9.2.powershell.exe.2db8ea0.1.raw.unpack, type: UNPACKEDPE |
Matched rule: Windows_Trojan_Njrat_30f3c220 reference_sample = 741a0f3954499c11f9eddc8df7c31e7c59ca41f1a7005646735b8b1d53438c1b, os = windows, severity = x86, creation_date = 2021-06-13, scan_context = file, memory, license = Elastic License v2, threat_name = Windows.Trojan.Njrat, fingerprint = d15e131bca6beddcaecb20fffaff1784ad8a33a25e7ce90f7450d1a362908cc4, id = 30f3c220-b8dc-45a1-bcf0-027c2f76fa63, last_modified = 2021-10-04 |
Source: 9.2.powershell.exe.2db8ea0.1.raw.unpack, type: UNPACKEDPE |
Matched rule: RAT_njRat date = 01.04.2014, filetype = exe, author = Kevin Breen <kevin@techanarchy.net>, maltype = Remote Access Trojan, description = Detects njRAT, reference = http://malwareconfig.com/stats/njRat |
Source: 9.2.powershell.exe.2db8ea0.1.raw.unpack, type: UNPACKEDPE |
Matched rule: njrat1 date = 2015-05-27, author = Brian Wallace @botnet_hunter, description = Identify njRat, author_email = bwall@ballastsecurity.net |
Source: 9.2.powershell.exe.2db8ea0.1.raw.unpack, type: UNPACKEDPE |
Matched rule: MALWARE_Win_NjRAT author = ditekSHen, description = Detects NjRAT / Bladabindi |
Source: 00000009.00000002.395438531.0000000002D1A000.00000004.00000800.00020000.00000000.sdmp, type: MEMORY |
Matched rule: Windows_Trojan_Njrat_30f3c220 reference_sample = 741a0f3954499c11f9eddc8df7c31e7c59ca41f1a7005646735b8b1d53438c1b, os = windows, severity = x86, creation_date = 2021-06-13, scan_context = file, memory, license = Elastic License v2, threat_name = Windows.Trojan.Njrat, fingerprint = d15e131bca6beddcaecb20fffaff1784ad8a33a25e7ce90f7450d1a362908cc4, id = 30f3c220-b8dc-45a1-bcf0-027c2f76fa63, last_modified = 2021-10-04 |
Source: 00000009.00000002.395438531.0000000002D1A000.00000004.00000800.00020000.00000000.sdmp, type: MEMORY |
Matched rule: RAT_njRat date = 01.04.2014, filetype = exe, author = Kevin Breen <kevin@techanarchy.net>, maltype = Remote Access Trojan, description = Detects njRAT, reference = http://malwareconfig.com/stats/njRat |
Source: 00000009.00000002.395438531.0000000002D1A000.00000004.00000800.00020000.00000000.sdmp, type: MEMORY |
Matched rule: njrat1 date = 2015-05-27, author = Brian Wallace @botnet_hunter, description = Identify njRat, author_email = bwall@ballastsecurity.net |
Source: 00000004.00000002.872864488.000000000296C000.00000004.00000800.00020000.00000000.sdmp, type: MEMORY |
Matched rule: Windows_Trojan_Njrat_30f3c220 reference_sample = 741a0f3954499c11f9eddc8df7c31e7c59ca41f1a7005646735b8b1d53438c1b, os = windows, severity = x86, creation_date = 2021-06-13, scan_context = file, memory, license = Elastic License v2, threat_name = Windows.Trojan.Njrat, fingerprint = d15e131bca6beddcaecb20fffaff1784ad8a33a25e7ce90f7450d1a362908cc4, id = 30f3c220-b8dc-45a1-bcf0-027c2f76fa63, last_modified = 2021-10-04 |
Source: 00000004.00000002.872864488.000000000296C000.00000004.00000800.00020000.00000000.sdmp, type: MEMORY |
Matched rule: RAT_njRat date = 01.04.2014, filetype = exe, author = Kevin Breen <kevin@techanarchy.net>, maltype = Remote Access Trojan, description = Detects njRAT, reference = http://malwareconfig.com/stats/njRat |
Source: 00000004.00000002.872864488.000000000296C000.00000004.00000800.00020000.00000000.sdmp, type: MEMORY |
Matched rule: njrat1 date = 2015-05-27, author = Brian Wallace @botnet_hunter, description = Identify njRat, author_email = bwall@ballastsecurity.net |
Source: Process Memory Space: powershell.exe PID: 3276, type: MEMORYSTR |
Matched rule: INDICATOR_SUSPICIOUS_PWSH_B64Encoded_Concatenated_FileEXEC author = ditekSHen, description = Detects PowerShell scripts containing patterns of base64 encoded files, concatenation and execution |
Source: Process Memory Space: powershell.exe PID: 3480, type: MEMORYSTR |
Matched rule: INDICATOR_SUSPICIOUS_PWSH_B64Encoded_Concatenated_FileEXEC author = ditekSHen, description = Detects PowerShell scripts containing patterns of base64 encoded files, concatenation and execution |
Source: C:\Users\user\Desktop\._cache_1.exe |
Section loaded: wow64win.dll |
Jump to behavior |
Source: C:\Users\user\Desktop\._cache_1.exe |
Section loaded: wow64cpu.dll |
Jump to behavior |
Source: C:\Users\user\Desktop\._cache_1.exe |
Section loaded: wsock32.dll |
Jump to behavior |
Source: C:\Users\user\Desktop\._cache_1.exe |
Section loaded: version.dll |
Jump to behavior |
Source: C:\Users\user\Desktop\._cache_1.exe |
Section loaded: winmm.dll |
Jump to behavior |
Source: C:\Users\user\Desktop\._cache_1.exe |
Section loaded: mpr.dll |
Jump to behavior |
Source: C:\Users\user\Desktop\._cache_1.exe |
Section loaded: uxtheme.dll |
Jump to behavior |
Source: C:\Users\user\Desktop\._cache_1.exe |
Section loaded: dwmapi.dll |
Jump to behavior |
Source: C:\Users\user\Desktop\._cache_1.exe |
Section loaded: propsys.dll |
Jump to behavior |
Source: C:\Users\user\Desktop\._cache_1.exe |
Section loaded: apphelp.dll |
Jump to behavior |
Source: C:\Users\user\Desktop\._cache_1.exe |
Section loaded: secur32.dll |
Jump to behavior |
Source: C:\Users\user\Desktop\._cache_1.exe |
Section loaded: sfc_os.dll |
Jump to behavior |
Source: C:\Users\user\Desktop\._cache_1.exe |
Section loaded: devrtl.dll |
Jump to behavior |
Source: C:\Users\user\Desktop\._cache_1.exe |
Section loaded: linkinfo.dll |
Jump to behavior |
Source: C:\Users\user\Desktop\._cache_1.exe |
Section loaded: ntshrui.dll |
Jump to behavior |
Source: C:\Users\user\Desktop\._cache_1.exe |
Section loaded: srvcli.dll |
Jump to behavior |
Source: C:\Users\user\Desktop\._cache_1.exe |
Section loaded: cscapi.dll |
Jump to behavior |
Source: C:\Users\user\Desktop\._cache_1.exe |
Section loaded: slc.dll |
Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\Tr.exe |
Section loaded: wow64win.dll |
Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\Tr.exe |
Section loaded: wow64cpu.dll |
Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\Tr.exe |
Section loaded: wsock32.dll |
Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\Tr.exe |
Section loaded: version.dll |
Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\Tr.exe |
Section loaded: winmm.dll |
Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\Tr.exe |
Section loaded: mpr.dll |
Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\Tr.exe |
Section loaded: iphlpapi.dll |
Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\Tr.exe |
Section loaded: winnsi.dll |
Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\Tr.exe |
Section loaded: uxtheme.dll |
Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\Tr.exe |
Section loaded: dwmapi.dll |
Jump to behavior |
Source: C:\Windows\System32\cmd.exe |
Section loaded: winbrand.dll |
Jump to behavior |
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe |
Section loaded: atl.dll |
Jump to behavior |
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe |
Section loaded: mscoree.dll |
Jump to behavior |
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe |
Section loaded: ntmarta.dll |
Jump to behavior |
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe |
Section loaded: apphelp.dll |
Jump to behavior |
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe |
Section loaded: linkinfo.dll |
Jump to behavior |
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe |
Section loaded: ntshrui.dll |
Jump to behavior |
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe |
Section loaded: srvcli.dll |
Jump to behavior |
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe |
Section loaded: cscapi.dll |
Jump to behavior |
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe |
Section loaded: slc.dll |
Jump to behavior |
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe |
Section loaded: cryptsp.dll |
Jump to behavior |
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe |
Section loaded: version.dll |
Jump to behavior |
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe |
Section loaded: vcruntime140_clr0400.dll |
Jump to behavior |
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe |
Section loaded: ucrtbase_clr0400.dll |
Jump to behavior |
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe |
Section loaded: amsi.dll |
Jump to behavior |
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe |
Section loaded: msisip.dll |
Jump to behavior |
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe |
Section loaded: secur32.dll |
Jump to behavior |
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe |
Section loaded: rpcrtremote.dll |
Jump to behavior |
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe |
Section loaded: amsi.dll |
Jump to behavior |
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe |
Section loaded: amsi.dll |
Jump to behavior |
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe |
Section loaded: bcrypt.dll |
Jump to behavior |
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe |
Section loaded: dnsapi.dll |
Jump to behavior |
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe |
Section loaded: iphlpapi.dll |
Jump to behavior |
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe |
Section loaded: winnsi.dll |
Jump to behavior |
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe |
Section loaded: dhcpcsvc6.dll |
Jump to behavior |
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe |
Section loaded: dhcpcsvc.dll |
Jump to behavior |
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe |
Section loaded: rasadhlp.dll |
Jump to behavior |
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe |
Section loaded: wbemcomn2.dll |
Jump to behavior |
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe |
Section loaded: ntdsapi.dll |
Jump to behavior |
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe |
Section loaded: avicap32.dll |
Jump to behavior |
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe |
Section loaded: winmm.dll |
Jump to behavior |
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe |
Section loaded: msvfw32.dll |
Jump to behavior |
Source: C:\Windows\System32\netsh.exe |
Section loaded: credui.dll |
Jump to behavior |
Source: C:\Windows\System32\netsh.exe |
Section loaded: mpr.dll |
Jump to behavior |
Source: C:\Windows\System32\netsh.exe |
Section loaded: rasmontr.dll |
Jump to behavior |
Source: C:\Windows\System32\netsh.exe |
Section loaded: mprapi.dll |
Jump to behavior |
Source: C:\Windows\System32\netsh.exe |
Section loaded: rasapi32.dll |
Jump to behavior |
Source: C:\Windows\System32\netsh.exe |
Section loaded: rasman.dll |
Jump to behavior |
Source: C:\Windows\System32\netsh.exe |
Section loaded: fwpuclnt.dll |
Jump to behavior |
Source: C:\Windows\System32\netsh.exe |
Section loaded: mfc42u.dll |
Jump to behavior |
Source: C:\Windows\System32\netsh.exe |
Section loaded: odbc32.dll |
Jump to behavior |
Source: C:\Windows\System32\netsh.exe |
Section loaded: iphlpapi.dll |
Jump to behavior |
Source: C:\Windows\System32\netsh.exe |
Section loaded: winnsi.dll |
Jump to behavior |
Source: C:\Windows\System32\netsh.exe |
Section loaded: nshwfp.dll |
Jump to behavior |
Source: C:\Windows\System32\netsh.exe |
Section loaded: slc.dll |
Jump to behavior |
Source: C:\Windows\System32\netsh.exe |
Section loaded: dhcpcmonitor.dll |
Jump to behavior |
Source: C:\Windows\System32\netsh.exe |
Section loaded: dhcpcsvc.dll |
Jump to behavior |
Source: C:\Windows\System32\netsh.exe |
Section loaded: dhcpcsvc6.dll |
Jump to behavior |
Source: C:\Windows\System32\netsh.exe |
Section loaded: dhcpqec.dll |
Jump to behavior |
Source: C:\Windows\System32\netsh.exe |
Section loaded: qutil.dll |
Jump to behavior |
Source: C:\Windows\System32\netsh.exe |
Section loaded: wevtapi.dll |
Jump to behavior |
Source: C:\Windows\System32\netsh.exe |
Section loaded: wshelper.dll |
Jump to behavior |
Source: C:\Windows\System32\netsh.exe |
Section loaded: ws2help.dll |
Jump to behavior |
Source: C:\Windows\System32\netsh.exe |
Section loaded: mswsock.dll |
Jump to behavior |
Source: C:\Windows\System32\netsh.exe |
Section loaded: nshhttp.dll |
Jump to behavior |
Source: C:\Windows\System32\netsh.exe |
Section loaded: httpapi.dll |
Jump to behavior |
Source: C:\Windows\System32\netsh.exe |
Section loaded: fwcfg.dll |
Jump to behavior |
Source: C:\Windows\System32\netsh.exe |
Section loaded: firewallapi.dll |
Jump to behavior |
Source: C:\Windows\System32\netsh.exe |
Section loaded: version.dll |
Jump to behavior |
Source: C:\Windows\System32\netsh.exe |
Section loaded: authfwcfg.dll |
Jump to behavior |
Source: C:\Windows\System32\netsh.exe |
Section loaded: bcrypt.dll |
Jump to behavior |
Source: C:\Windows\System32\netsh.exe |
Section loaded: winipsec.dll |
Jump to behavior |
Source: C:\Windows\System32\netsh.exe |
Section loaded: ifmon.dll |
Jump to behavior |
Source: C:\Windows\System32\netsh.exe |
Section loaded: nci.dll |
Jump to behavior |
Source: C:\Windows\System32\netsh.exe |
Section loaded: devrtl.dll |
Jump to behavior |
Source: C:\Windows\System32\netsh.exe |
Section loaded: netiohlp.dll |
Jump to behavior |
Source: C:\Windows\System32\netsh.exe |
Section loaded: dnsapi.dll |
Jump to behavior |
Source: C:\Windows\System32\netsh.exe |
Section loaded: whhelper.dll |
Jump to behavior |
Source: C:\Windows\System32\netsh.exe |
Section loaded: winhttp.dll |
Jump to behavior |
Source: C:\Windows\System32\netsh.exe |
Section loaded: webio.dll |
Jump to behavior |
Source: C:\Windows\System32\netsh.exe |
Section loaded: hnetmon.dll |
Jump to behavior |
Source: C:\Windows\System32\netsh.exe |
Section loaded: netshell.dll |
Jump to behavior |
Source: C:\Windows\System32\netsh.exe |
Section loaded: nlaapi.dll |
Jump to behavior |
Source: C:\Windows\System32\netsh.exe |
Section loaded: rpcnsh.dll |
Jump to behavior |
Source: C:\Windows\System32\netsh.exe |
Section loaded: dot3cfg.dll |
Jump to behavior |
Source: C:\Windows\System32\netsh.exe |
Section loaded: dot3api.dll |
Jump to behavior |
Source: C:\Windows\System32\netsh.exe |
Section loaded: atl.dll |
Jump to behavior |
Source: C:\Windows\System32\netsh.exe |
Section loaded: eappcfg.dll |
Jump to behavior |
Source: C:\Windows\System32\netsh.exe |
Section loaded: onex.dll |
Jump to behavior |
Source: C:\Windows\System32\netsh.exe |
Section loaded: eappprxy.dll |
Jump to behavior |
Source: C:\Windows\System32\netsh.exe |
Section loaded: napmontr.dll |
Jump to behavior |
Source: C:\Windows\System32\netsh.exe |
Section loaded: certcli.dll |
Jump to behavior |
Source: C:\Windows\System32\netsh.exe |
Section loaded: nshipsec.dll |
Jump to behavior |
Source: C:\Windows\System32\netsh.exe |
Section loaded: netapi32.dll |
Jump to behavior |
Source: C:\Windows\System32\netsh.exe |
Section loaded: netutils.dll |
Jump to behavior |
Source: C:\Windows\System32\netsh.exe |
Section loaded: srvcli.dll |
Jump to behavior |
Source: C:\Windows\System32\netsh.exe |
Section loaded: wkscli.dll |
Jump to behavior |
Source: C:\Windows\System32\netsh.exe |
Section loaded: logoncli.dll |
Jump to behavior |
Source: C:\Windows\System32\netsh.exe |
Section loaded: activeds.dll |
Jump to behavior |
Source: C:\Windows\System32\netsh.exe |
Section loaded: adsldpc.dll |
Jump to behavior |
Source: C:\Windows\System32\netsh.exe |
Section loaded: polstore.dll |
Jump to behavior |
Source: C:\Windows\System32\netsh.exe |
Section loaded: nettrace.dll |
Jump to behavior |
Source: C:\Windows\System32\netsh.exe |
Section loaded: ndfapi.dll |
Jump to behavior |
Source: C:\Windows\System32\netsh.exe |
Section loaded: wdi.dll |
Jump to behavior |
Source: C:\Windows\System32\netsh.exe |
Section loaded: secur32.dll |
Jump to behavior |
Source: C:\Windows\System32\netsh.exe |
Section loaded: tdh.dll |
Jump to behavior |
Source: C:\Windows\System32\netsh.exe |
Section loaded: wcnnetsh.dll |
Jump to behavior |
Source: C:\Windows\System32\netsh.exe |
Section loaded: wlanapi.dll |
Jump to behavior |
Source: C:\Windows\System32\netsh.exe |
Section loaded: wlanutil.dll |
Jump to behavior |
Source: C:\Windows\System32\netsh.exe |
Section loaded: p2pnetsh.dll |
Jump to behavior |
Source: C:\Windows\System32\netsh.exe |
Section loaded: p2p.dll |
Jump to behavior |
Source: C:\Windows\System32\netsh.exe |
Section loaded: p2pcollab.dll |
Jump to behavior |
Source: C:\Windows\System32\netsh.exe |
Section loaded: wwancfg.dll |
Jump to behavior |
Source: C:\Windows\System32\netsh.exe |
Section loaded: wwapi.dll |
Jump to behavior |
Source: C:\Windows\System32\netsh.exe |
Section loaded: wlancfg.dll |
Jump to behavior |
Source: C:\Windows\System32\netsh.exe |
Section loaded: wlanhlp.dll |
Jump to behavior |
Source: C:\Windows\System32\netsh.exe |
Section loaded: peerdistsh.dll |
Jump to behavior |
Source: C:\Windows\System32\netsh.exe |
Section loaded: cryptsp.dll |
Jump to behavior |
Source: C:\Windows\System32\netsh.exe |
Section loaded: rpcrtremote.dll |
Jump to behavior |
Source: C:\Windows\System32\netsh.exe |
Section loaded: gpapi.dll |
Jump to behavior |
Source: C:\Windows\System32\netsh.exe |
Section loaded: mprmsg.dll |
Jump to behavior |
Source: C:\Windows\System32\cmd.exe |
Section loaded: winbrand.dll |
|
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe |
Section loaded: atl.dll |
|
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe |
Section loaded: mscoree.dll |
|
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe |
Section loaded: ntmarta.dll |
|
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe |
Section loaded: apphelp.dll |
|
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe |
Section loaded: linkinfo.dll |
|
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe |
Section loaded: ntshrui.dll |
|
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe |
Section loaded: srvcli.dll |
|
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe |
Section loaded: cscapi.dll |
|
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe |
Section loaded: slc.dll |
|
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe |
Section loaded: cryptsp.dll |
|
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe |
Section loaded: version.dll |
|
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe |
Section loaded: vcruntime140_clr0400.dll |
|
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe |
Section loaded: ucrtbase_clr0400.dll |
|
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe |
Section loaded: amsi.dll |
|
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe |
Section loaded: secur32.dll |
|
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe |
Section loaded: msisip.dll |
|
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe |
Section loaded: rpcrtremote.dll |
|
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe |
Section loaded: amsi.dll |
|
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe |
Section loaded: amsi.dll |
|
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe |
Section loaded: bcrypt.dll |
|
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe |
Section loaded: netutils.dll |
|
Source: C:\Users\user\AppData\Local\Temp\x.exe |
Section loaded: wow64win.dll |
Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\x.exe |
Section loaded: wow64cpu.dll |
Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\x.exe |
Section loaded: wsock32.dll |
Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\x.exe |
Section loaded: version.dll |
Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\x.exe |
Section loaded: winmm.dll |
Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\x.exe |
Section loaded: mpr.dll |
Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\x.exe |
Section loaded: uxtheme.dll |
Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\x.exe |
Section loaded: dwmapi.dll |
Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\x.exe |
Section loaded: propsys.dll |
Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\x.exe |
Section loaded: apphelp.dll |
Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\x.exe |
Section loaded: sfc_os.dll |
Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\x.exe |
Section loaded: devrtl.dll |
Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\x.exe |
Section loaded: linkinfo.dll |
Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\x.exe |
Section loaded: ntshrui.dll |
Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\x.exe |
Section loaded: srvcli.dll |
Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\x.exe |
Section loaded: cscapi.dll |
Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\x.exe |
Section loaded: slc.dll |
Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\Tr.exe |
Section loaded: wow64win.dll |
Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\Tr.exe |
Section loaded: wow64cpu.dll |
Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\Tr.exe |
Section loaded: wsock32.dll |
Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\Tr.exe |
Section loaded: version.dll |
Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\Tr.exe |
Section loaded: winmm.dll |
Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\Tr.exe |
Section loaded: mpr.dll |
Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\Tr.exe |
Section loaded: iphlpapi.dll |
Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\Tr.exe |
Section loaded: winnsi.dll |
Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\Tr.exe |
Section loaded: uxtheme.dll |
Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\Tr.exe |
Section loaded: dwmapi.dll |
Jump to behavior |
Source: C:\Users\user\Desktop\._cache_1.exe |
Code function: 0_2_0047A330 IsWindowVisible,IsWindowEnabled,GetForegroundWindow,IsIconic,IsZoomed, |
0_2_0047A330 |
Source: C:\Users\user\Desktop\._cache_1.exe |
Code function: 0_2_00434418 GetForegroundWindow,FindWindowW,IsIconic,ShowWindow,SetForegroundWindow,GetWindowThreadProcessId,GetWindowThreadProcessId,GetCurrentThreadId,GetWindowThreadProcessId,AttachThreadInput,AttachThreadInput,AttachThreadInput,AttachThreadInput,SetForegroundWindow,MapVirtualKeyW,keybd_event,MapVirtualKeyW,keybd_event,MapVirtualKeyW,keybd_event,MapVirtualKeyW,keybd_event,SetForegroundWindow,AttachThreadInput,AttachThreadInput,AttachThreadInput, |
0_2_00434418 |
Source: C:\Users\user\AppData\Local\Temp\Tr.exe |
Code function: 1_2_00AC4A35 GetForegroundWindow,FindWindowW,IsIconic,ShowWindow,SetForegroundWindow,GetWindowThreadProcessId,GetWindowThreadProcessId,GetCurrentThreadId,GetWindowThreadProcessId,AttachThreadInput,AttachThreadInput,AttachThreadInput,AttachThreadInput,SetForegroundWindow,MapVirtualKeyW,MapVirtualKeyW,keybd_event,keybd_event,MapVirtualKeyW,keybd_event,MapVirtualKeyW,keybd_event,MapVirtualKeyW,keybd_event,SetForegroundWindow,AttachThreadInput,AttachThreadInput,AttachThreadInput,AttachThreadInput, |
1_2_00AC4A35 |
Source: C:\Users\user\AppData\Local\Temp\Tr.exe |
Code function: 1_2_00B453DF IsWindowVisible,IsWindowEnabled,GetForegroundWindow,IsIconic,IsZoomed, |
1_2_00B453DF |
Source: C:\Users\user\AppData\Local\Temp\Tr.exe |
Code function: 12_2_003A4A35 GetForegroundWindow,FindWindowW,IsIconic,ShowWindow,SetForegroundWindow,GetWindowThreadProcessId,GetWindowThreadProcessId,GetCurrentThreadId,GetWindowThreadProcessId,AttachThreadInput,AttachThreadInput,AttachThreadInput,AttachThreadInput,SetForegroundWindow,MapVirtualKeyW,MapVirtualKeyW,keybd_event,keybd_event,MapVirtualKeyW,keybd_event,MapVirtualKeyW,keybd_event,MapVirtualKeyW,keybd_event,SetForegroundWindow,AttachThreadInput,AttachThreadInput,AttachThreadInput,AttachThreadInput, |
12_2_003A4A35 |
Source: C:\Users\user\AppData\Local\Temp\Tr.exe |
Code function: 12_2_004253DF IsWindowVisible,IsWindowEnabled,GetForegroundWindow,IsIconic,IsZoomed, |
12_2_004253DF |
Source: C:\Users\user\Desktop\._cache_1.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\Desktop\._cache_1.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\Desktop\._cache_1.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\Desktop\._cache_1.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\Desktop\._cache_1.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\Desktop\._cache_1.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\Desktop\._cache_1.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\Desktop\._cache_1.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\Desktop\._cache_1.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\Desktop\._cache_1.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\Desktop\._cache_1.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\Desktop\._cache_1.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\Desktop\._cache_1.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\Tr.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\Tr.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Windows\System32\cmd.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Windows\System32\cmd.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Windows\System32\cmd.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Windows\System32\netsh.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Windows\System32\netsh.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe |
Process information set: NOOPENFILEERRORBOX |
|
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe |
Process information set: NOOPENFILEERRORBOX |
|
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe |
Process information set: NOOPENFILEERRORBOX |
|
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe |
Process information set: NOOPENFILEERRORBOX |
|
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe |
Process information set: NOOPENFILEERRORBOX |
|
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe |
Process information set: NOOPENFILEERRORBOX |
|
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe |
Process information set: NOOPENFILEERRORBOX |
|
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe |
Process information set: NOOPENFILEERRORBOX |
|
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe |
Process information set: NOOPENFILEERRORBOX |
|
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe |
Process information set: NOOPENFILEERRORBOX |
|
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe |
Process information set: NOOPENFILEERRORBOX |
|
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe |
Process information set: NOOPENFILEERRORBOX |
|
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe |
Process information set: NOOPENFILEERRORBOX |
|
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe |
Process information set: NOOPENFILEERRORBOX |
|
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe |
Process information set: NOOPENFILEERRORBOX |
|
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe |
Process information set: NOOPENFILEERRORBOX |
|
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe |
Process information set: NOOPENFILEERRORBOX |
|
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe |
Process information set: NOOPENFILEERRORBOX |
|
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe |
Process information set: NOOPENFILEERRORBOX |
|
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe |
Process information set: NOOPENFILEERRORBOX |
|
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe |
Process information set: NOOPENFILEERRORBOX |
|
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe |
Process information set: NOOPENFILEERRORBOX |
|
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe |
Process information set: NOOPENFILEERRORBOX |
|
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe |
Process information set: NOOPENFILEERRORBOX |
|
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe |
Process information set: NOOPENFILEERRORBOX |
|
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe |
Process information set: NOOPENFILEERRORBOX |
|
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe |
Process information set: NOOPENFILEERRORBOX |
|
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe |
Process information set: NOOPENFILEERRORBOX |
|
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe |
Process information set: NOOPENFILEERRORBOX |
|
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe |
Process information set: NOOPENFILEERRORBOX |
|
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe |
Process information set: NOOPENFILEERRORBOX |
|
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe |
Process information set: NOOPENFILEERRORBOX |
|
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe |
Process information set: NOOPENFILEERRORBOX |
|
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe |
Process information set: NOOPENFILEERRORBOX |
|
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe |
Process information set: NOOPENFILEERRORBOX |
|
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe |
Process information set: NOOPENFILEERRORBOX |
|
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe |
Process information set: NOOPENFILEERRORBOX |
|
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe |
Process information set: NOOPENFILEERRORBOX |
|
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe |
Process information set: NOOPENFILEERRORBOX |
|
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe |
Process information set: NOOPENFILEERRORBOX |
|
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe |
Process information set: NOOPENFILEERRORBOX |
|
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe |
Process information set: NOOPENFILEERRORBOX |
|
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe |
Process information set: NOOPENFILEERRORBOX |
|
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe |
Process information set: NOOPENFILEERRORBOX |
|
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe |
Process information set: NOOPENFILEERRORBOX |
|
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe |
Process information set: NOOPENFILEERRORBOX |
|
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe |
Process information set: NOOPENFILEERRORBOX |
|
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe |
Process information set: NOOPENFILEERRORBOX |
|
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe |
Process information set: NOOPENFILEERRORBOX |
|
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe |
Process information set: NOOPENFILEERRORBOX |
|
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe |
Process information set: NOOPENFILEERRORBOX |
|
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe |
Process information set: NOOPENFILEERRORBOX |
|
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe |
Process information set: NOOPENFILEERRORBOX |
|
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe |
Process information set: NOOPENFILEERRORBOX |
|
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe |
Process information set: NOOPENFILEERRORBOX |
|
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe |
Process information set: NOOPENFILEERRORBOX |
|
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe |
Process information set: NOOPENFILEERRORBOX |
|
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe |
Process information set: NOOPENFILEERRORBOX |
|
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe |
Process information set: NOOPENFILEERRORBOX |
|
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe |
Process information set: NOOPENFILEERRORBOX |
|
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe |
Process information set: NOOPENFILEERRORBOX |
|
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe |
Process information set: NOOPENFILEERRORBOX |
|
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe |
Process information set: NOOPENFILEERRORBOX |
|
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe |
Process information set: NOOPENFILEERRORBOX |
|
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe |
Process information set: NOOPENFILEERRORBOX |
|
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe |
Process information set: NOOPENFILEERRORBOX |
|
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe |
Process information set: NOOPENFILEERRORBOX |
|
Source: C:\Users\user\AppData\Local\Temp\x.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\x.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\x.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\x.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\x.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\x.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\x.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\x.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\x.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\x.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\x.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\x.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\Tr.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\Tr.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\Desktop\._cache_1.exe |
Code function: 0_2_004339B6 GetFileAttributesW,FindFirstFileW,FindClose, |
0_2_004339B6 |
Source: C:\Users\user\Desktop\._cache_1.exe |
Code function: 0_2_0044BD27 _wcscat,_wcscat,__wsplitpath,FindFirstFileW,CopyFileW,_wcscpy,_wcscat,_wcscat,lstrcmpiW,DeleteFileW,MoveFileW,CopyFileW,DeleteFileW,CopyFileW,FindClose,MoveFileW,FindNextFileW,FindClose, |
0_2_0044BD27 |
Source: C:\Users\user\Desktop\._cache_1.exe |
Code function: 0_2_0044BF8B _wcscat,__wsplitpath,FindFirstFileW,_wcscpy,_wcscat,_wcscat,DeleteFileW,FindNextFileW,FindClose,FindClose, |
0_2_0044BF8B |
Source: C:\Users\user\Desktop\._cache_1.exe |
Code function: 0_2_00452492 FindFirstFileW,Sleep,FindNextFileW,FindClose, |
0_2_00452492 |
Source: C:\Users\user\Desktop\._cache_1.exe |
Code function: 0_2_00442886 FindFirstFileW,FindFirstFileW,FindNextFileW,FindClose,FindClose,FindClose,FindFirstFileW,SetCurrentDirectoryW,SetCurrentDirectoryW,SetCurrentDirectoryW,FindNextFileW,FindClose,FindClose, |
0_2_00442886 |
Source: C:\Users\user\Desktop\._cache_1.exe |
Code function: 0_2_004788BD FindFirstFileW,FindClose,FileTimeToLocalFileTime,FileTimeToLocalFileTime,FileTimeToLocalFileTime,FileTimeToSystemTime,__swprintf,__swprintf,__swprintf,__swprintf,__swprintf,__swprintf,__swprintf, |
0_2_004788BD |
Source: C:\Users\user\Desktop\._cache_1.exe |
Code function: 0_2_0045CAFA FindFirstFileW,FindNextFileW,FindClose, |
0_2_0045CAFA |
Source: C:\Users\user\Desktop\._cache_1.exe |
Code function: 0_2_00431A86 FindFirstFileW,FindFirstFileW,GetFileAttributesW,SetFileAttributesW,FindNextFileW,FindClose,FindClose,FindClose,FindFirstFileW,SetCurrentDirectoryW,SetCurrentDirectoryW,SetCurrentDirectoryW,FindNextFileW,FindClose,FindClose, |
0_2_00431A86 |
Source: C:\Users\user\Desktop\._cache_1.exe |
Code function: 0_2_0045DE8F FindFirstFileW,FindClose, |
0_2_0045DE8F |
Source: C:\Users\user\AppData\Local\Temp\Tr.exe |
Code function: 1_2_00B2449B GetFileAttributesW,FindFirstFileW,FindClose, |
1_2_00B2449B |
Source: C:\Users\user\AppData\Local\Temp\Tr.exe |
Code function: 1_2_00B2C7E8 FindFirstFileW,FindClose,FileTimeToLocalFileTime,FileTimeToLocalFileTime,FileTimeToLocalFileTime,FileTimeToSystemTime,__swprintf,__swprintf,__swprintf,__swprintf,__swprintf,__swprintf,__swprintf, |
1_2_00B2C7E8 |
Source: C:\Users\user\AppData\Local\Temp\Tr.exe |
Code function: 1_2_00B2C75D FindFirstFileW,FindClose, |
1_2_00B2C75D |
Source: C:\Users\user\AppData\Local\Temp\Tr.exe |
Code function: 1_2_00B2F021 SetCurrentDirectoryW,FindFirstFileW,FindFirstFileW,_wcscmp,_wcscmp,GetFileAttributesW,SetFileAttributesW,FindNextFileW,FindClose,FindFirstFileW,SetCurrentDirectoryW,_wcscmp,_wcscmp,SetCurrentDirectoryW,SetCurrentDirectoryW,FindNextFileW,FindClose,FindClose, |
1_2_00B2F021 |
Source: C:\Users\user\AppData\Local\Temp\Tr.exe |
Code function: 1_2_00B2F17E SetCurrentDirectoryW,FindFirstFileW,FindFirstFileW,_wcscmp,_wcscmp,FindNextFileW,FindClose,FindFirstFileW,SetCurrentDirectoryW,_wcscmp,_wcscmp,SetCurrentDirectoryW,SetCurrentDirectoryW,FindNextFileW,FindClose,FindClose, |
1_2_00B2F17E |
Source: C:\Users\user\AppData\Local\Temp\Tr.exe |
Code function: 1_2_00B2F47F FindFirstFileW,Sleep,_wcscmp,_wcscmp,FindNextFileW,FindClose, |
1_2_00B2F47F |
Source: C:\Users\user\AppData\Local\Temp\Tr.exe |
Code function: 1_2_00B23833 FindFirstFileW,DeleteFileW,DeleteFileW,MoveFileW,DeleteFileW,FindNextFileW,FindClose,FindClose, |
1_2_00B23833 |
Source: C:\Users\user\AppData\Local\Temp\Tr.exe |
Code function: 1_2_00B23B56 FindFirstFileW,DeleteFileW,FindNextFileW,FindClose,FindClose, |
1_2_00B23B56 |
Source: C:\Users\user\AppData\Local\Temp\Tr.exe |
Code function: 1_2_00B2BD48 FindFirstFileW,_wcscmp,_wcscmp,FindNextFileW,FindClose, |
1_2_00B2BD48 |
Source: C:\Users\user\AppData\Local\Temp\Tr.exe |
Code function: 12_2_0040449B GetFileAttributesW,FindFirstFileW,FindClose, |
12_2_0040449B |
Source: C:\Users\user\AppData\Local\Temp\Tr.exe |
Code function: 12_2_0040C75D FindFirstFileW,FindClose, |
12_2_0040C75D |
Source: C:\Users\user\AppData\Local\Temp\Tr.exe |
Code function: 12_2_0040C7E8 FindFirstFileW,FindClose,FileTimeToLocalFileTime,FileTimeToLocalFileTime,FileTimeToLocalFileTime,FileTimeToSystemTime,__swprintf,__swprintf,__swprintf,__swprintf,__swprintf,__swprintf,__swprintf, |
12_2_0040C7E8 |
Source: C:\Users\user\AppData\Local\Temp\Tr.exe |
Code function: 12_2_0040F021 SetCurrentDirectoryW,FindFirstFileW,FindFirstFileW,_wcscmp,_wcscmp,GetFileAttributesW,SetFileAttributesW,FindNextFileW,FindClose,FindFirstFileW,SetCurrentDirectoryW,_wcscmp,_wcscmp,SetCurrentDirectoryW,SetCurrentDirectoryW,FindNextFileW,FindClose,FindClose, |
12_2_0040F021 |
Source: C:\Users\user\AppData\Local\Temp\Tr.exe |
Code function: 12_2_0040F17E SetCurrentDirectoryW,FindFirstFileW,FindFirstFileW,_wcscmp,_wcscmp,FindNextFileW,FindClose,FindFirstFileW,SetCurrentDirectoryW,_wcscmp,_wcscmp,SetCurrentDirectoryW,SetCurrentDirectoryW,FindNextFileW,FindClose,FindClose, |
12_2_0040F17E |
Source: C:\Users\user\AppData\Local\Temp\Tr.exe |
Code function: 12_2_0040F47F FindFirstFileW,Sleep,_wcscmp,_wcscmp,FindNextFileW,FindClose, |
12_2_0040F47F |
Source: C:\Users\user\AppData\Local\Temp\Tr.exe |
Code function: 12_2_00403833 FindFirstFileW,DeleteFileW,DeleteFileW,MoveFileW,DeleteFileW,FindNextFileW,FindClose,FindClose, |
12_2_00403833 |
Source: C:\Users\user\AppData\Local\Temp\Tr.exe |
Code function: 12_2_00403B56 FindFirstFileW,DeleteFileW,FindNextFileW,FindClose,FindClose, |
12_2_00403B56 |
Source: C:\Users\user\AppData\Local\Temp\Tr.exe |
Code function: 12_2_0040BD48 FindFirstFileW,_wcscmp,_wcscmp,FindNextFileW,FindClose, |
12_2_0040BD48 |
Source: C:\Users\user\Desktop\._cache_1.exe |
Queries volume information: C:\ VolumeInformation |
Jump to behavior |
Source: C:\Users\user\Desktop\._cache_1.exe |
Queries volume information: C:\Users\user\AppData\Local\Temp\x.exe VolumeInformation |
Jump to behavior |
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe |
Queries volume information: C:\ VolumeInformation |
Jump to behavior |
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe |
Queries volume information: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Accessories\Windows PowerShell\Windows PowerShell.lnk VolumeInformation |
Jump to behavior |
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe |
Queries volume information: C:\ VolumeInformation |
Jump to behavior |
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe |
Queries volume information: C:\Windows\System32\WindowsPowerShell\v1.0\powershell_ise.exe VolumeInformation |
Jump to behavior |
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe |
Queries volume information: C:\ VolumeInformation |
Jump to behavior |
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe |
Queries volume information: C:\Windows\System32\WindowsPowerShell\v1.0\powershell_ise.exe VolumeInformation |
Jump to behavior |
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe |
Queries volume information: C:\Windows\Microsoft.NET\assembly\GAC_64\System.Data\v4.0_4.0.0.0__b77a5c561934e089\System.Data.dll VolumeInformation |
Jump to behavior |
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe |
Queries volume information: C:\Windows\Microsoft.NET\assembly\GAC_64\System.Transactions\v4.0_4.0.0.0__b77a5c561934e089\System.Transactions.dll VolumeInformation |
Jump to behavior |
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe |
Queries volume information: C:\ VolumeInformation |
Jump to behavior |
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe |
Queries volume information: C:\ VolumeInformation |
Jump to behavior |
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe |
Queries volume information: C:\ VolumeInformation |
Jump to behavior |
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe |
Queries volume information: C:\ VolumeInformation |
Jump to behavior |
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe |
Queries volume information: C:\ VolumeInformation |
Jump to behavior |
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe |
Queries volume information: C:\ VolumeInformation |
Jump to behavior |
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe |
Queries volume information: C:\ VolumeInformation |
Jump to behavior |
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe |
Queries volume information: C:\ VolumeInformation |
Jump to behavior |
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe |
Queries volume information: C:\ VolumeInformation |
Jump to behavior |
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe |
Queries volume information: C:\ VolumeInformation |
Jump to behavior |
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe |
Queries volume information: C:\ VolumeInformation |
Jump to behavior |
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe |
Queries volume information: C:\ VolumeInformation |
Jump to behavior |
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe |
Queries volume information: C:\ VolumeInformation |
Jump to behavior |
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe |
Queries volume information: C:\ VolumeInformation |
Jump to behavior |
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe |
Queries volume information: C:\ VolumeInformation |
Jump to behavior |
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe |
Queries volume information: C:\ VolumeInformation |
|
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe |
Queries volume information: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Accessories\Windows PowerShell\Windows PowerShell.lnk VolumeInformation |
|
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe |
Queries volume information: C:\ VolumeInformation |
|
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe |
Queries volume information: C:\Windows\System32\WindowsPowerShell\v1.0\powershell_ise.exe VolumeInformation |
|
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe |
Queries volume information: C:\ VolumeInformation |
|
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe |
Queries volume information: C:\Windows\System32\WindowsPowerShell\v1.0\powershell_ise.exe VolumeInformation |
|
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe |
Queries volume information: C:\Windows\Microsoft.NET\assembly\GAC_64\System.Data\v4.0_4.0.0.0__b77a5c561934e089\System.Data.dll VolumeInformation |
|
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe |
Queries volume information: C:\Windows\Microsoft.NET\assembly\GAC_64\System.Transactions\v4.0_4.0.0.0__b77a5c561934e089\System.Transactions.dll VolumeInformation |
|
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe |
Queries volume information: C:\ VolumeInformation |
|
Source: C:\Users\user\AppData\Local\Temp\x.exe |
Queries volume information: C:\ VolumeInformation |
Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\x.exe |
Queries volume information: C:\Users\user\AppData\Local\Temp\x.exe VolumeInformation |
Jump to behavior |