Source: C:\Users\user\Desktop\8f5WsFcnTc.exe |
Code function: 0_2_00D0DBBE lstrlenW,GetFileAttributesW,FindFirstFileW,FindClose, |
0_2_00D0DBBE |
Source: C:\Users\user\Desktop\8f5WsFcnTc.exe |
Code function: 0_2_00CDC2A2 FindFirstFileExW, |
0_2_00CDC2A2 |
Source: C:\Users\user\Desktop\8f5WsFcnTc.exe |
Code function: 0_2_00D168EE FindFirstFileW,FindClose, |
0_2_00D168EE |
Source: C:\Users\user\Desktop\8f5WsFcnTc.exe |
Code function: 0_2_00D1698F FindFirstFileW,FindClose,FileTimeToLocalFileTime,FileTimeToLocalFileTime,FileTimeToLocalFileTime,FileTimeToSystemTime,FileTimeToSystemTime,FileTimeToSystemTime, |
0_2_00D1698F |
Source: C:\Users\user\Desktop\8f5WsFcnTc.exe |
Code function: 0_2_00D0D076 FindFirstFileW,DeleteFileW,DeleteFileW,MoveFileW,DeleteFileW,FindNextFileW,FindClose,FindClose, |
0_2_00D0D076 |
Source: C:\Users\user\Desktop\8f5WsFcnTc.exe |
Code function: 0_2_00D0D3A9 FindFirstFileW,DeleteFileW,FindNextFileW,FindClose,FindClose, |
0_2_00D0D3A9 |
Source: C:\Users\user\Desktop\8f5WsFcnTc.exe |
Code function: 0_2_00D19642 SetCurrentDirectoryW,FindFirstFileW,FindFirstFileW,GetFileAttributesW,SetFileAttributesW,FindNextFileW,FindClose,FindFirstFileW,SetCurrentDirectoryW,SetCurrentDirectoryW,SetCurrentDirectoryW,FindNextFileW,FindClose,FindClose, |
0_2_00D19642 |
Source: C:\Users\user\Desktop\8f5WsFcnTc.exe |
Code function: 0_2_00D1979D SetCurrentDirectoryW,FindFirstFileW,FindFirstFileW,FindNextFileW,FindClose,FindFirstFileW,SetCurrentDirectoryW,SetCurrentDirectoryW,SetCurrentDirectoryW,FindNextFileW,FindClose,FindClose, |
0_2_00D1979D |
Source: C:\Users\user\Desktop\8f5WsFcnTc.exe |
Code function: 0_2_00D19B2B FindFirstFileW,Sleep,FindNextFileW,FindClose, |
0_2_00D19B2B |
Source: C:\Users\user\Desktop\8f5WsFcnTc.exe |
Code function: 0_2_00D15C97 FindFirstFileW,FindNextFileW,FindClose, |
0_2_00D15C97 |
Source: C:\Users\user\AppData\Local\directory\name.exe |
Code function: 2_2_0022DBBE lstrlenW,GetFileAttributesW,FindFirstFileW,FindClose, |
2_2_0022DBBE |
Source: C:\Users\user\AppData\Local\directory\name.exe |
Code function: 2_2_001FC2A2 FindFirstFileExW, |
2_2_001FC2A2 |
Source: C:\Users\user\AppData\Local\directory\name.exe |
Code function: 2_2_002368EE FindFirstFileW,FindClose, |
2_2_002368EE |
Source: C:\Users\user\AppData\Local\directory\name.exe |
Code function: 2_2_0023698F FindFirstFileW,FindClose,FileTimeToLocalFileTime,FileTimeToLocalFileTime,FileTimeToLocalFileTime,FileTimeToSystemTime,FileTimeToSystemTime,FileTimeToSystemTime, |
2_2_0023698F |
Source: C:\Users\user\AppData\Local\directory\name.exe |
Code function: 2_2_0022D076 FindFirstFileW,DeleteFileW,DeleteFileW,MoveFileW,DeleteFileW,FindNextFileW,FindClose,FindClose, |
2_2_0022D076 |
Source: C:\Users\user\AppData\Local\directory\name.exe |
Code function: 2_2_0022D3A9 FindFirstFileW,DeleteFileW,FindNextFileW,FindClose,FindClose, |
2_2_0022D3A9 |
Source: C:\Users\user\AppData\Local\directory\name.exe |
Code function: 2_2_00239642 SetCurrentDirectoryW,FindFirstFileW,FindFirstFileW,GetFileAttributesW,SetFileAttributesW,FindNextFileW,FindClose,FindFirstFileW,SetCurrentDirectoryW,SetCurrentDirectoryW,SetCurrentDirectoryW,FindNextFileW,FindClose,FindClose, |
2_2_00239642 |
Source: C:\Users\user\AppData\Local\directory\name.exe |
Code function: 2_2_0023979D SetCurrentDirectoryW,FindFirstFileW,FindFirstFileW,FindNextFileW,FindClose,FindFirstFileW,SetCurrentDirectoryW,SetCurrentDirectoryW,SetCurrentDirectoryW,FindNextFileW,FindClose,FindClose, |
2_2_0023979D |
Source: C:\Users\user\AppData\Local\directory\name.exe |
Code function: 2_2_00239B2B FindFirstFileW,Sleep,FindNextFileW,FindClose, |
2_2_00239B2B |
Source: C:\Users\user\AppData\Local\directory\name.exe |
Code function: 2_2_00235C97 FindFirstFileW,FindNextFileW,FindClose, |
2_2_00235C97 |
Source: RegSvcs.exe, 00000003.00000002.2700598845.0000000002A64000.00000004.00000800.00020000.00000000.sdmp, RegSvcs.exe, 00000003.00000002.2699629746.0000000000DC0000.00000004.00000020.00020000.00000000.sdmp |
String found in binary or memory: http://crl.comodoca.com/AAACertificateServices.crl04 |
Source: RegSvcs.exe, 00000003.00000002.2703323664.0000000005CF0000.00000004.00000020.00020000.00000000.sdmp |
String found in binary or memory: http://crl.comodoca.com/AAACertificateServices.crl06 |
Source: RegSvcs.exe, 00000003.00000002.2700598845.0000000002A64000.00000004.00000800.00020000.00000000.sdmp, RegSvcs.exe, 00000003.00000002.2699629746.0000000000DC0000.00000004.00000020.00020000.00000000.sdmp |
String found in binary or memory: http://crl.comodoca.com/COMODORSACertificationAuthority.crl0q |
Source: RegSvcs.exe, 00000003.00000002.2700598845.0000000002A64000.00000004.00000800.00020000.00000000.sdmp, RegSvcs.exe, 00000003.00000002.2703323664.0000000005CF0000.00000004.00000020.00020000.00000000.sdmp |
String found in binary or memory: http://crl.comodoca.com/cPanelIncCertificationAuthority.crl0 |
Source: RegSvcs.exe, 00000003.00000002.2700598845.0000000002A01000.00000004.00000800.00020000.00000000.sdmp |
String found in binary or memory: http://ip-api.com |
Source: name.exe, 00000002.00000002.1474396665.0000000000C70000.00000004.00001000.00020000.00000000.sdmp, RegSvcs.exe, 00000003.00000002.2698924544.0000000000402000.00000040.80000000.00040000.00000000.sdmp, RegSvcs.exe, 00000003.00000002.2699629746.0000000000DDE000.00000004.00000020.00020000.00000000.sdmp, RegSvcs.exe, 00000003.00000002.2700598845.0000000002A01000.00000004.00000800.00020000.00000000.sdmp, name.exe, 0000000A.00000002.1774487883.0000000001340000.00000004.00001000.00020000.00000000.sdmp |
String found in binary or memory: http://ip-api.com/line/?fields=hosting |
Source: RegSvcs.exe, 00000003.00000002.2700598845.0000000002A64000.00000004.00000800.00020000.00000000.sdmp |
String found in binary or memory: http://mail.jaszredony.hu |
Source: RegSvcs.exe, 00000003.00000002.2700598845.0000000002A64000.00000004.00000800.00020000.00000000.sdmp, RegSvcs.exe, 00000003.00000002.2703323664.0000000005CF0000.00000004.00000020.00020000.00000000.sdmp, RegSvcs.exe, 00000003.00000002.2699629746.0000000000DC0000.00000004.00000020.00020000.00000000.sdmp |
String found in binary or memory: http://ocsp.comodoca.com0 |
Source: RegSvcs.exe, 00000003.00000002.2700598845.0000000002A01000.00000004.00000800.00020000.00000000.sdmp |
String found in binary or memory: http://schemas.xmlsoap.org/ws/2005/05/identity/claims/name |
Source: name.exe, 00000002.00000002.1474396665.0000000000C70000.00000004.00001000.00020000.00000000.sdmp, RegSvcs.exe, 00000003.00000002.2698924544.0000000000402000.00000040.80000000.00040000.00000000.sdmp, name.exe, 0000000A.00000002.1774487883.0000000001340000.00000004.00001000.00020000.00000000.sdmp |
String found in binary or memory: https://account.dyn.com/ |
Source: RegSvcs.exe, 00000003.00000002.2700598845.0000000002A64000.00000004.00000800.00020000.00000000.sdmp, RegSvcs.exe, 00000003.00000002.2703323664.0000000005CF0000.00000004.00000020.00020000.00000000.sdmp |
String found in binary or memory: https://sectigo.com/CPS0 |
Source: C:\Users\user\Desktop\8f5WsFcnTc.exe |
Code function: 0_2_00D39576 DefDlgProcW,SendMessageW,GetWindowLongW,SendMessageW,SendMessageW,GetKeyState,GetKeyState,GetKeyState,SendMessageW,GetKeyState,SendMessageW,SendMessageW,SendMessageW,ImageList_SetDragCursorImage,ImageList_BeginDrag,SetCapture,ClientToScreen,ImageList_DragEnter,InvalidateRect,ReleaseCapture,GetCursorPos,ScreenToClient,SendMessageW,SendMessageW,SendMessageW,SendMessageW,SendMessageW,SendMessageW,SendMessageW,GetCursorPos,ScreenToClient,GetParent,SendMessageW,SendMessageW,ClientToScreen,TrackPopupMenuEx,SendMessageW,SendMessageW,ClientToScreen,TrackPopupMenuEx,GetWindowLongW, |
0_2_00D39576 |
Source: C:\Users\user\AppData\Local\directory\name.exe |
Code function: 2_2_00259576 DefDlgProcW,SendMessageW,GetWindowLongW,SendMessageW,SendMessageW,GetKeyState,GetKeyState,GetKeyState,SendMessageW,GetKeyState,SendMessageW,SendMessageW,SendMessageW,ImageList_SetDragCursorImage,ImageList_BeginDrag,SetCapture,ClientToScreen,ImageList_DragEnter,InvalidateRect,ReleaseCapture,GetCursorPos,ScreenToClient,SendMessageW,SendMessageW,SendMessageW,SendMessageW,SendMessageW,SendMessageW,SendMessageW,GetCursorPos,ScreenToClient,GetParent,SendMessageW,SendMessageW,ClientToScreen,TrackPopupMenuEx,SendMessageW,SendMessageW,ClientToScreen,TrackPopupMenuEx,GetWindowLongW, |
2_2_00259576 |
Source: C:\Users\user\Desktop\8f5WsFcnTc.exe |
Code function: 0_2_00D12046 |
0_2_00D12046 |
Source: C:\Users\user\Desktop\8f5WsFcnTc.exe |
Code function: 0_2_00CA8060 |
0_2_00CA8060 |
Source: C:\Users\user\Desktop\8f5WsFcnTc.exe |
Code function: 0_2_00D08298 |
0_2_00D08298 |
Source: C:\Users\user\Desktop\8f5WsFcnTc.exe |
Code function: 0_2_00CDE4FF |
0_2_00CDE4FF |
Source: C:\Users\user\Desktop\8f5WsFcnTc.exe |
Code function: 0_2_00CD676B |
0_2_00CD676B |
Source: C:\Users\user\Desktop\8f5WsFcnTc.exe |
Code function: 0_2_00D34873 |
0_2_00D34873 |
Source: C:\Users\user\Desktop\8f5WsFcnTc.exe |
Code function: 0_2_00CACAF0 |
0_2_00CACAF0 |
Source: C:\Users\user\Desktop\8f5WsFcnTc.exe |
Code function: 0_2_00CCCAA0 |
0_2_00CCCAA0 |
Source: C:\Users\user\Desktop\8f5WsFcnTc.exe |
Code function: 0_2_00CBCC39 |
0_2_00CBCC39 |
Source: C:\Users\user\Desktop\8f5WsFcnTc.exe |
Code function: 0_2_00CD6DD9 |
0_2_00CD6DD9 |
Source: C:\Users\user\Desktop\8f5WsFcnTc.exe |
Code function: 0_2_00CA91C0 |
0_2_00CA91C0 |
Source: C:\Users\user\Desktop\8f5WsFcnTc.exe |
Code function: 0_2_00CBB119 |
0_2_00CBB119 |
Source: C:\Users\user\Desktop\8f5WsFcnTc.exe |
Code function: 0_2_00CC1394 |
0_2_00CC1394 |
Source: C:\Users\user\Desktop\8f5WsFcnTc.exe |
Code function: 0_2_00CC1706 |
0_2_00CC1706 |
Source: C:\Users\user\Desktop\8f5WsFcnTc.exe |
Code function: 0_2_00CC781B |
0_2_00CC781B |
Source: C:\Users\user\Desktop\8f5WsFcnTc.exe |
Code function: 0_2_00CC19B0 |
0_2_00CC19B0 |
Source: C:\Users\user\Desktop\8f5WsFcnTc.exe |
Code function: 0_2_00CB997D |
0_2_00CB997D |
Source: C:\Users\user\Desktop\8f5WsFcnTc.exe |
Code function: 0_2_00CA7920 |
0_2_00CA7920 |
Source: C:\Users\user\Desktop\8f5WsFcnTc.exe |
Code function: 0_2_00CC7A4A |
0_2_00CC7A4A |
Source: C:\Users\user\Desktop\8f5WsFcnTc.exe |
Code function: 0_2_00CC7CA7 |
0_2_00CC7CA7 |
Source: C:\Users\user\Desktop\8f5WsFcnTc.exe |
Code function: 0_2_00CC1C77 |
0_2_00CC1C77 |
Source: C:\Users\user\Desktop\8f5WsFcnTc.exe |
Code function: 0_2_00CD9EEE |
0_2_00CD9EEE |
Source: C:\Users\user\Desktop\8f5WsFcnTc.exe |
Code function: 0_2_00D2BE44 |
0_2_00D2BE44 |
Source: C:\Users\user\Desktop\8f5WsFcnTc.exe |
Code function: 0_2_00CC1F32 |
0_2_00CC1F32 |
Source: C:\Users\user\Desktop\8f5WsFcnTc.exe |
Code function: 0_2_00F53640 |
0_2_00F53640 |
Source: C:\Users\user\AppData\Local\directory\name.exe |
Code function: 2_2_001CBF40 |
2_2_001CBF40 |
Source: C:\Users\user\AppData\Local\directory\name.exe |
Code function: 2_2_00232046 |
2_2_00232046 |
Source: C:\Users\user\AppData\Local\directory\name.exe |
Code function: 2_2_001C8060 |
2_2_001C8060 |
Source: C:\Users\user\AppData\Local\directory\name.exe |
Code function: 2_2_00228298 |
2_2_00228298 |
Source: C:\Users\user\AppData\Local\directory\name.exe |
Code function: 2_2_001FE4FF |
2_2_001FE4FF |
Source: C:\Users\user\AppData\Local\directory\name.exe |
Code function: 2_2_001F676B |
2_2_001F676B |
Source: C:\Users\user\AppData\Local\directory\name.exe |
Code function: 2_2_00254873 |
2_2_00254873 |
Source: C:\Users\user\AppData\Local\directory\name.exe |
Code function: 2_2_001ECAA0 |
2_2_001ECAA0 |
Source: C:\Users\user\AppData\Local\directory\name.exe |
Code function: 2_2_001CCAF0 |
2_2_001CCAF0 |
Source: C:\Users\user\AppData\Local\directory\name.exe |
Code function: 2_2_001DCC39 |
2_2_001DCC39 |
Source: C:\Users\user\AppData\Local\directory\name.exe |
Code function: 2_2_001F6DD9 |
2_2_001F6DD9 |
Source: C:\Users\user\AppData\Local\directory\name.exe |
Code function: 2_2_001DB119 |
2_2_001DB119 |
Source: C:\Users\user\AppData\Local\directory\name.exe |
Code function: 2_2_001C91C0 |
2_2_001C91C0 |
Source: C:\Users\user\AppData\Local\directory\name.exe |
Code function: 2_2_001E1394 |
2_2_001E1394 |
Source: C:\Users\user\AppData\Local\directory\name.exe |
Code function: 2_2_001E1706 |
2_2_001E1706 |
Source: C:\Users\user\AppData\Local\directory\name.exe |
Code function: 2_2_001E781B |
2_2_001E781B |
Source: C:\Users\user\AppData\Local\directory\name.exe |
Code function: 2_2_001C7920 |
2_2_001C7920 |
Source: C:\Users\user\AppData\Local\directory\name.exe |
Code function: 2_2_001D997D |
2_2_001D997D |
Source: C:\Users\user\AppData\Local\directory\name.exe |
Code function: 2_2_001E19B0 |
2_2_001E19B0 |
Source: C:\Users\user\AppData\Local\directory\name.exe |
Code function: 2_2_001E7A4A |
2_2_001E7A4A |
Source: C:\Users\user\AppData\Local\directory\name.exe |
Code function: 2_2_001E1C77 |
2_2_001E1C77 |
Source: C:\Users\user\AppData\Local\directory\name.exe |
Code function: 2_2_001E7CA7 |
2_2_001E7CA7 |
Source: C:\Users\user\AppData\Local\directory\name.exe |
Code function: 2_2_0024BE44 |
2_2_0024BE44 |
Source: C:\Users\user\AppData\Local\directory\name.exe |
Code function: 2_2_001F9EEE |
2_2_001F9EEE |
Source: C:\Users\user\AppData\Local\directory\name.exe |
Code function: 2_2_001E1F32 |
2_2_001E1F32 |
Source: C:\Users\user\AppData\Local\directory\name.exe |
Code function: 2_2_00C63640 |
2_2_00C63640 |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe |
Code function: 3_2_02894208 |
3_2_02894208 |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe |
Code function: 3_2_0289E750 |
3_2_0289E750 |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe |
Code function: 3_2_0289B590 |
3_2_0289B590 |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe |
Code function: 3_2_02894AD8 |
3_2_02894AD8 |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe |
Code function: 3_2_02893EC0 |
3_2_02893EC0 |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe |
Code function: 3_2_061AC880 |
3_2_061AC880 |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe |
Code function: 3_2_061AB25C |
3_2_061AB25C |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe |
Code function: 3_2_061B56A0 |
3_2_061B56A0 |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe |
Code function: 3_2_061B6700 |
3_2_061B6700 |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe |
Code function: 3_2_061B2460 |
3_2_061B2460 |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe |
Code function: 3_2_061BC2A0 |
3_2_061BC2A0 |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe |
Code function: 3_2_061BB358 |
3_2_061BB358 |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe |
Code function: 3_2_061B7E98 |
3_2_061B7E98 |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe |
Code function: 3_2_061B77B8 |
3_2_061B77B8 |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe |
Code function: 3_2_061BE4C0 |
3_2_061BE4C0 |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe |
Code function: 3_2_061B0040 |
3_2_061B0040 |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe |
Code function: 3_2_061B5DF8 |
3_2_061B5DF8 |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe |
Code function: 3_2_06AC3500 |
3_2_06AC3500 |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe |
Code function: 3_2_061B0006 |
3_2_061B0006 |
Source: C:\Users\user\AppData\Local\directory\name.exe |
Code function: 10_2_00A53640 |
10_2_00A53640 |
Source: C:\Users\user\Desktop\8f5WsFcnTc.exe |
Section loaded: wsock32.dll |
Jump to behavior |
Source: C:\Users\user\Desktop\8f5WsFcnTc.exe |
Section loaded: version.dll |
Jump to behavior |
Source: C:\Users\user\Desktop\8f5WsFcnTc.exe |
Section loaded: winmm.dll |
Jump to behavior |
Source: C:\Users\user\Desktop\8f5WsFcnTc.exe |
Section loaded: mpr.dll |
Jump to behavior |
Source: C:\Users\user\Desktop\8f5WsFcnTc.exe |
Section loaded: wininet.dll |
Jump to behavior |
Source: C:\Users\user\Desktop\8f5WsFcnTc.exe |
Section loaded: iphlpapi.dll |
Jump to behavior |
Source: C:\Users\user\Desktop\8f5WsFcnTc.exe |
Section loaded: userenv.dll |
Jump to behavior |
Source: C:\Users\user\Desktop\8f5WsFcnTc.exe |
Section loaded: uxtheme.dll |
Jump to behavior |
Source: C:\Users\user\Desktop\8f5WsFcnTc.exe |
Section loaded: kernel.appcore.dll |
Jump to behavior |
Source: C:\Users\user\Desktop\8f5WsFcnTc.exe |
Section loaded: windows.storage.dll |
Jump to behavior |
Source: C:\Users\user\Desktop\8f5WsFcnTc.exe |
Section loaded: wldp.dll |
Jump to behavior |
Source: C:\Users\user\Desktop\8f5WsFcnTc.exe |
Section loaded: cryptsp.dll |
Jump to behavior |
Source: C:\Users\user\Desktop\8f5WsFcnTc.exe |
Section loaded: rsaenh.dll |
Jump to behavior |
Source: C:\Users\user\Desktop\8f5WsFcnTc.exe |
Section loaded: cryptbase.dll |
Jump to behavior |
Source: C:\Users\user\Desktop\8f5WsFcnTc.exe |
Section loaded: apphelp.dll |
Jump to behavior |
Source: C:\Users\user\AppData\Local\directory\name.exe |
Section loaded: wsock32.dll |
Jump to behavior |
Source: C:\Users\user\AppData\Local\directory\name.exe |
Section loaded: version.dll |
Jump to behavior |
Source: C:\Users\user\AppData\Local\directory\name.exe |
Section loaded: winmm.dll |
Jump to behavior |
Source: C:\Users\user\AppData\Local\directory\name.exe |
Section loaded: mpr.dll |
Jump to behavior |
Source: C:\Users\user\AppData\Local\directory\name.exe |
Section loaded: wininet.dll |
Jump to behavior |
Source: C:\Users\user\AppData\Local\directory\name.exe |
Section loaded: iphlpapi.dll |
Jump to behavior |
Source: C:\Users\user\AppData\Local\directory\name.exe |
Section loaded: userenv.dll |
Jump to behavior |
Source: C:\Users\user\AppData\Local\directory\name.exe |
Section loaded: uxtheme.dll |
Jump to behavior |
Source: C:\Users\user\AppData\Local\directory\name.exe |
Section loaded: kernel.appcore.dll |
Jump to behavior |
Source: C:\Users\user\AppData\Local\directory\name.exe |
Section loaded: windows.storage.dll |
Jump to behavior |
Source: C:\Users\user\AppData\Local\directory\name.exe |
Section loaded: wldp.dll |
Jump to behavior |
Source: C:\Users\user\AppData\Roaming\newfile\newfile.exe |
Section loaded: mscoree.dll |
Jump to behavior |
Source: C:\Users\user\AppData\Roaming\newfile\newfile.exe |
Section loaded: kernel.appcore.dll |
Jump to behavior |
Source: C:\Users\user\AppData\Roaming\newfile\newfile.exe |
Section loaded: version.dll |
Jump to behavior |
Source: C:\Users\user\AppData\Roaming\newfile\newfile.exe |
Section loaded: vcruntime140_clr0400.dll |
Jump to behavior |
Source: C:\Users\user\AppData\Roaming\newfile\newfile.exe |
Section loaded: ucrtbase_clr0400.dll |
Jump to behavior |
Source: C:\Users\user\AppData\Roaming\newfile\newfile.exe |
Section loaded: ucrtbase_clr0400.dll |
Jump to behavior |
Source: C:\Users\user\AppData\Roaming\newfile\newfile.exe |
Section loaded: mscoree.dll |
Jump to behavior |
Source: C:\Users\user\AppData\Roaming\newfile\newfile.exe |
Section loaded: kernel.appcore.dll |
Jump to behavior |
Source: C:\Users\user\AppData\Roaming\newfile\newfile.exe |
Section loaded: version.dll |
Jump to behavior |
Source: C:\Users\user\AppData\Roaming\newfile\newfile.exe |
Section loaded: vcruntime140_clr0400.dll |
Jump to behavior |
Source: C:\Users\user\AppData\Roaming\newfile\newfile.exe |
Section loaded: ucrtbase_clr0400.dll |
Jump to behavior |
Source: C:\Windows\System32\wscript.exe |
Section loaded: version.dll |
Jump to behavior |
Source: C:\Windows\System32\wscript.exe |
Section loaded: kernel.appcore.dll |
Jump to behavior |
Source: C:\Windows\System32\wscript.exe |
Section loaded: uxtheme.dll |
Jump to behavior |
Source: C:\Windows\System32\wscript.exe |
Section loaded: sxs.dll |
Jump to behavior |
Source: C:\Windows\System32\wscript.exe |
Section loaded: vbscript.dll |
Jump to behavior |
Source: C:\Windows\System32\wscript.exe |
Section loaded: amsi.dll |
Jump to behavior |
Source: C:\Windows\System32\wscript.exe |
Section loaded: userenv.dll |
Jump to behavior |
Source: C:\Windows\System32\wscript.exe |
Section loaded: profapi.dll |
Jump to behavior |
Source: C:\Windows\System32\wscript.exe |
Section loaded: wldp.dll |
Jump to behavior |
Source: C:\Windows\System32\wscript.exe |
Section loaded: msasn1.dll |
Jump to behavior |
Source: C:\Windows\System32\wscript.exe |
Section loaded: cryptsp.dll |
Jump to behavior |
Source: C:\Windows\System32\wscript.exe |
Section loaded: rsaenh.dll |
Jump to behavior |
Source: C:\Windows\System32\wscript.exe |
Section loaded: cryptbase.dll |
Jump to behavior |
Source: C:\Windows\System32\wscript.exe |
Section loaded: msisip.dll |
Jump to behavior |
Source: C:\Windows\System32\wscript.exe |
Section loaded: wshext.dll |
Jump to behavior |
Source: C:\Windows\System32\wscript.exe |
Section loaded: scrobj.dll |
Jump to behavior |
Source: C:\Windows\System32\wscript.exe |
Section loaded: mlang.dll |
Jump to behavior |
Source: C:\Windows\System32\wscript.exe |
Section loaded: mpr.dll |
Jump to behavior |
Source: C:\Windows\System32\wscript.exe |
Section loaded: scrrun.dll |
Jump to behavior |
Source: C:\Windows\System32\wscript.exe |
Section loaded: windows.storage.dll |
Jump to behavior |
Source: C:\Windows\System32\wscript.exe |
Section loaded: propsys.dll |
Jump to behavior |
Source: C:\Windows\System32\wscript.exe |
Section loaded: edputil.dll |
Jump to behavior |
Source: C:\Windows\System32\wscript.exe |
Section loaded: urlmon.dll |
Jump to behavior |
Source: C:\Windows\System32\wscript.exe |
Section loaded: iertutil.dll |
Jump to behavior |
Source: C:\Windows\System32\wscript.exe |
Section loaded: srvcli.dll |
Jump to behavior |
Source: C:\Windows\System32\wscript.exe |
Section loaded: netutils.dll |
Jump to behavior |
Source: C:\Windows\System32\wscript.exe |
Section loaded: windows.staterepositoryps.dll |
Jump to behavior |
Source: C:\Windows\System32\wscript.exe |
Section loaded: sspicli.dll |
Jump to behavior |
Source: C:\Windows\System32\wscript.exe |
Section loaded: wintypes.dll |
Jump to behavior |
Source: C:\Windows\System32\wscript.exe |
Section loaded: appresolver.dll |
Jump to behavior |
Source: C:\Windows\System32\wscript.exe |
Section loaded: bcp47langs.dll |
Jump to behavior |
Source: C:\Windows\System32\wscript.exe |
Section loaded: slc.dll |
Jump to behavior |
Source: C:\Windows\System32\wscript.exe |
Section loaded: sppc.dll |
Jump to behavior |
Source: C:\Windows\System32\wscript.exe |
Section loaded: onecorecommonproxystub.dll |
Jump to behavior |
Source: C:\Windows\System32\wscript.exe |
Section loaded: onecoreuapcommonproxystub.dll |
Jump to behavior |
Source: C:\Users\user\AppData\Local\directory\name.exe |
Section loaded: wsock32.dll |
Jump to behavior |
Source: C:\Users\user\AppData\Local\directory\name.exe |
Section loaded: version.dll |
Jump to behavior |
Source: C:\Users\user\AppData\Local\directory\name.exe |
Section loaded: winmm.dll |
Jump to behavior |
Source: C:\Users\user\AppData\Local\directory\name.exe |
Section loaded: mpr.dll |
Jump to behavior |
Source: C:\Users\user\AppData\Local\directory\name.exe |
Section loaded: wininet.dll |
Jump to behavior |
Source: C:\Users\user\AppData\Local\directory\name.exe |
Section loaded: iphlpapi.dll |
Jump to behavior |
Source: C:\Users\user\AppData\Local\directory\name.exe |
Section loaded: userenv.dll |
Jump to behavior |
Source: C:\Users\user\AppData\Local\directory\name.exe |
Section loaded: uxtheme.dll |
Jump to behavior |
Source: C:\Users\user\AppData\Local\directory\name.exe |
Section loaded: kernel.appcore.dll |
Jump to behavior |
Source: C:\Users\user\AppData\Local\directory\name.exe |
Section loaded: windows.storage.dll |
Jump to behavior |
Source: C:\Users\user\AppData\Local\directory\name.exe |
Section loaded: wldp.dll |
Jump to behavior |
Source: C:\Users\user\Desktop\8f5WsFcnTc.exe |
Code function: 0_2_00CF668E push ss; retf |
0_2_00CF668F |
Source: C:\Users\user\Desktop\8f5WsFcnTc.exe |
Code function: 0_2_00CF6686 push ss; retf |
0_2_00CF6687 |
Source: C:\Users\user\Desktop\8f5WsFcnTc.exe |
Code function: 0_2_00CF6682 push ss; retf |
0_2_00CF6683 |
Source: C:\Users\user\Desktop\8f5WsFcnTc.exe |
Code function: 0_2_00CC0A76 push ecx; ret |
0_2_00CC0A89 |
Source: C:\Users\user\Desktop\8f5WsFcnTc.exe |
Code function: 0_2_00CF4CE6 push 0000003Eh; iretd |
0_2_00CF4CE8 |
Source: C:\Users\user\Desktop\8f5WsFcnTc.exe |
Code function: 0_2_00CAD01B push cs; iretd |
0_2_00CAD01E |
Source: C:\Users\user\Desktop\8f5WsFcnTc.exe |
Code function: 0_2_00CB1199 push cs; retf |
0_2_00CB119A |
Source: C:\Users\user\Desktop\8f5WsFcnTc.exe |
Code function: 0_2_00CB119C push cs; retf |
0_2_00CB11A2 |
Source: C:\Users\user\Desktop\8f5WsFcnTc.exe |
Code function: 0_2_00CB124F pushad ; iretd |
0_2_00CB1252 |
Source: C:\Users\user\Desktop\8f5WsFcnTc.exe |
Code function: 0_2_00CB124D pushad ; iretd |
0_2_00CB124E |
Source: C:\Users\user\Desktop\8f5WsFcnTc.exe |
Code function: 0_2_00CB1247 pushad ; iretd |
0_2_00CB124A |
Source: C:\Users\user\Desktop\8f5WsFcnTc.exe |
Code function: 0_2_00CB125F pushad ; iretd |
0_2_00CB1262 |
Source: C:\Users\user\Desktop\8f5WsFcnTc.exe |
Code function: 0_2_00CB1253 pushad ; iretd |
0_2_00CB1256 |
Source: C:\Users\user\Desktop\8f5WsFcnTc.exe |
Code function: 0_2_00CB1263 pushad ; iretd |
0_2_00CB1266 |
Source: C:\Users\user\Desktop\8f5WsFcnTc.exe |
Code function: 0_2_00CF56D8 push eax; iretd |
0_2_00CF56DA |
Source: C:\Users\user\Desktop\8f5WsFcnTc.exe |
Code function: 0_2_00CF56E9 push esp; iretd |
0_2_00CF56EA |
Source: C:\Users\user\Desktop\8f5WsFcnTc.exe |
Code function: 0_2_00CF57E4 push ebx; iretd |
0_2_00CF57FA |
Source: C:\Users\user\Desktop\8f5WsFcnTc.exe |
Code function: 0_2_00CF57E1 push ebx; iretd |
0_2_00CF57E2 |
Source: C:\Users\user\Desktop\8f5WsFcnTc.exe |
Code function: 0_2_00CF57FC push esi; iretd |
0_2_00CF5802 |
Source: C:\Users\user\Desktop\8f5WsFcnTc.exe |
Code function: 0_2_00CF1788 push ss; iretd |
0_2_00CF1789 |
Source: C:\Users\user\Desktop\8f5WsFcnTc.exe |
Code function: 0_2_00CF5788 push eax; iretd |
0_2_00CF578A |
Source: C:\Users\user\Desktop\8f5WsFcnTc.exe |
Code function: 0_2_00CF179F push ss; iretd |
0_2_00CF17A1 |
Source: C:\Users\user\Desktop\8f5WsFcnTc.exe |
Code function: 0_2_00CF5799 push esp; iretd |
0_2_00CF579A |
Source: C:\Users\user\Desktop\8f5WsFcnTc.exe |
Code function: 0_2_00CF1797 push ss; iretd |
0_2_00CF179D |
Source: C:\Users\user\Desktop\8f5WsFcnTc.exe |
Code function: 0_2_00CF17AC push ss; iretd |
0_2_00CF17AD |
Source: C:\Users\user\Desktop\8f5WsFcnTc.exe |
Code function: 0_2_00CF17A8 push ss; iretd |
0_2_00CF17A9 |
Source: C:\Users\user\Desktop\8f5WsFcnTc.exe |
Code function: 0_2_00CF17A3 push ss; iretd |
0_2_00CF17A5 |
Source: C:\Users\user\Desktop\8f5WsFcnTc.exe |
Code function: 0_2_00CF57B8 push ebx; iretd |
0_2_00CF57CE |
Source: C:\Users\user\Desktop\8f5WsFcnTc.exe |
Code function: 0_2_00CF57B5 push ebx; iretd |
0_2_00CF57B6 |
Source: C:\Users\user\Desktop\8f5WsFcnTc.exe |
Code function: 0_2_00CF17B0 push ss; iretd |
0_2_00CF17B1 |
Source: C:\Users\user\Desktop\8f5WsFcnTc.exe |
Code function: 0_2_00CF5741 push esp; iretd |
0_2_00CF5742 |
Source: C:\Users\user\Desktop\8f5WsFcnTc.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\Desktop\8f5WsFcnTc.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\AppData\Local\directory\name.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\AppData\Local\directory\name.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\AppData\Roaming\newfile\newfile.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\AppData\Roaming\newfile\newfile.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\AppData\Roaming\newfile\newfile.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\AppData\Roaming\newfile\newfile.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\AppData\Roaming\newfile\newfile.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\AppData\Roaming\newfile\newfile.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\AppData\Roaming\newfile\newfile.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\AppData\Roaming\newfile\newfile.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\AppData\Roaming\newfile\newfile.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\AppData\Roaming\newfile\newfile.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\AppData\Roaming\newfile\newfile.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\AppData\Roaming\newfile\newfile.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\AppData\Roaming\newfile\newfile.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\AppData\Roaming\newfile\newfile.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\AppData\Roaming\newfile\newfile.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\AppData\Roaming\newfile\newfile.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\AppData\Roaming\newfile\newfile.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\AppData\Roaming\newfile\newfile.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\AppData\Roaming\newfile\newfile.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\AppData\Roaming\newfile\newfile.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\AppData\Roaming\newfile\newfile.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\AppData\Roaming\newfile\newfile.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\AppData\Roaming\newfile\newfile.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\AppData\Roaming\newfile\newfile.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\AppData\Roaming\newfile\newfile.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\AppData\Roaming\newfile\newfile.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\AppData\Roaming\newfile\newfile.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\AppData\Roaming\newfile\newfile.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\AppData\Roaming\newfile\newfile.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\AppData\Roaming\newfile\newfile.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\AppData\Roaming\newfile\newfile.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\AppData\Roaming\newfile\newfile.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\AppData\Roaming\newfile\newfile.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\AppData\Roaming\newfile\newfile.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Windows\System32\wscript.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Windows\System32\wscript.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Windows\System32\wscript.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\AppData\Local\directory\name.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\AppData\Local\directory\name.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Windows\SysWOW64\WerFault.exe |
Process information set: FAILCRITICALERRORS | NOGPFAULTERRORBOX |
Jump to behavior |
Source: C:\Windows\SysWOW64\WerFault.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Windows\SysWOW64\WerFault.exe |
Process information set: FAILCRITICALERRORS | NOGPFAULTERRORBOX |
Jump to behavior |
Source: C:\Windows\SysWOW64\WerFault.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Windows\SysWOW64\WerFault.exe |
Process information set: FAILCRITICALERRORS | NOGPFAULTERRORBOX |
Jump to behavior |
Source: C:\Windows\SysWOW64\WerFault.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Windows\SysWOW64\WerFault.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Windows\SysWOW64\WerFault.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Windows\SysWOW64\WerFault.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Windows\SysWOW64\WerFault.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Windows\SysWOW64\WerFault.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Windows\SysWOW64\WerFault.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Windows\SysWOW64\WerFault.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Windows\SysWOW64\WerFault.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Windows\SysWOW64\WerFault.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Windows\SysWOW64\WerFault.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Windows\SysWOW64\WerFault.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Windows\SysWOW64\WerFault.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Windows\SysWOW64\WerFault.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Windows\SysWOW64\WerFault.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Windows\SysWOW64\WerFault.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Windows\SysWOW64\WerFault.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Windows\SysWOW64\WerFault.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Windows\SysWOW64\WerFault.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Windows\SysWOW64\WerFault.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Windows\SysWOW64\WerFault.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Windows\SysWOW64\WerFault.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Windows\SysWOW64\WerFault.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Windows\SysWOW64\WerFault.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Windows\SysWOW64\WerFault.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Windows\SysWOW64\WerFault.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Windows\SysWOW64\WerFault.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Windows\SysWOW64\WerFault.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Windows\SysWOW64\WerFault.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Windows\SysWOW64\WerFault.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Windows\SysWOW64\WerFault.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Windows\SysWOW64\WerFault.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Windows\SysWOW64\WerFault.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Windows\SysWOW64\WerFault.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Windows\SysWOW64\WerFault.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Windows\SysWOW64\WerFault.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Windows\SysWOW64\WerFault.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Windows\SysWOW64\WerFault.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Windows\SysWOW64\WerFault.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Windows\SysWOW64\WerFault.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Windows\SysWOW64\WerFault.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\Desktop\8f5WsFcnTc.exe |
Code function: 0_2_00D0DBBE lstrlenW,GetFileAttributesW,FindFirstFileW,FindClose, |
0_2_00D0DBBE |
Source: C:\Users\user\Desktop\8f5WsFcnTc.exe |
Code function: 0_2_00CDC2A2 FindFirstFileExW, |
0_2_00CDC2A2 |
Source: C:\Users\user\Desktop\8f5WsFcnTc.exe |
Code function: 0_2_00D168EE FindFirstFileW,FindClose, |
0_2_00D168EE |
Source: C:\Users\user\Desktop\8f5WsFcnTc.exe |
Code function: 0_2_00D1698F FindFirstFileW,FindClose,FileTimeToLocalFileTime,FileTimeToLocalFileTime,FileTimeToLocalFileTime,FileTimeToSystemTime,FileTimeToSystemTime,FileTimeToSystemTime, |
0_2_00D1698F |
Source: C:\Users\user\Desktop\8f5WsFcnTc.exe |
Code function: 0_2_00D0D076 FindFirstFileW,DeleteFileW,DeleteFileW,MoveFileW,DeleteFileW,FindNextFileW,FindClose,FindClose, |
0_2_00D0D076 |
Source: C:\Users\user\Desktop\8f5WsFcnTc.exe |
Code function: 0_2_00D0D3A9 FindFirstFileW,DeleteFileW,FindNextFileW,FindClose,FindClose, |
0_2_00D0D3A9 |
Source: C:\Users\user\Desktop\8f5WsFcnTc.exe |
Code function: 0_2_00D19642 SetCurrentDirectoryW,FindFirstFileW,FindFirstFileW,GetFileAttributesW,SetFileAttributesW,FindNextFileW,FindClose,FindFirstFileW,SetCurrentDirectoryW,SetCurrentDirectoryW,SetCurrentDirectoryW,FindNextFileW,FindClose,FindClose, |
0_2_00D19642 |
Source: C:\Users\user\Desktop\8f5WsFcnTc.exe |
Code function: 0_2_00D1979D SetCurrentDirectoryW,FindFirstFileW,FindFirstFileW,FindNextFileW,FindClose,FindFirstFileW,SetCurrentDirectoryW,SetCurrentDirectoryW,SetCurrentDirectoryW,FindNextFileW,FindClose,FindClose, |
0_2_00D1979D |
Source: C:\Users\user\Desktop\8f5WsFcnTc.exe |
Code function: 0_2_00D19B2B FindFirstFileW,Sleep,FindNextFileW,FindClose, |
0_2_00D19B2B |
Source: C:\Users\user\Desktop\8f5WsFcnTc.exe |
Code function: 0_2_00D15C97 FindFirstFileW,FindNextFileW,FindClose, |
0_2_00D15C97 |
Source: C:\Users\user\AppData\Local\directory\name.exe |
Code function: 2_2_0022DBBE lstrlenW,GetFileAttributesW,FindFirstFileW,FindClose, |
2_2_0022DBBE |
Source: C:\Users\user\AppData\Local\directory\name.exe |
Code function: 2_2_001FC2A2 FindFirstFileExW, |
2_2_001FC2A2 |
Source: C:\Users\user\AppData\Local\directory\name.exe |
Code function: 2_2_002368EE FindFirstFileW,FindClose, |
2_2_002368EE |
Source: C:\Users\user\AppData\Local\directory\name.exe |
Code function: 2_2_0023698F FindFirstFileW,FindClose,FileTimeToLocalFileTime,FileTimeToLocalFileTime,FileTimeToLocalFileTime,FileTimeToSystemTime,FileTimeToSystemTime,FileTimeToSystemTime, |
2_2_0023698F |
Source: C:\Users\user\AppData\Local\directory\name.exe |
Code function: 2_2_0022D076 FindFirstFileW,DeleteFileW,DeleteFileW,MoveFileW,DeleteFileW,FindNextFileW,FindClose,FindClose, |
2_2_0022D076 |
Source: C:\Users\user\AppData\Local\directory\name.exe |
Code function: 2_2_0022D3A9 FindFirstFileW,DeleteFileW,FindNextFileW,FindClose,FindClose, |
2_2_0022D3A9 |
Source: C:\Users\user\AppData\Local\directory\name.exe |
Code function: 2_2_00239642 SetCurrentDirectoryW,FindFirstFileW,FindFirstFileW,GetFileAttributesW,SetFileAttributesW,FindNextFileW,FindClose,FindFirstFileW,SetCurrentDirectoryW,SetCurrentDirectoryW,SetCurrentDirectoryW,FindNextFileW,FindClose,FindClose, |
2_2_00239642 |
Source: C:\Users\user\AppData\Local\directory\name.exe |
Code function: 2_2_0023979D SetCurrentDirectoryW,FindFirstFileW,FindFirstFileW,FindNextFileW,FindClose,FindFirstFileW,SetCurrentDirectoryW,SetCurrentDirectoryW,SetCurrentDirectoryW,FindNextFileW,FindClose,FindClose, |
2_2_0023979D |
Source: C:\Users\user\AppData\Local\directory\name.exe |
Code function: 2_2_00239B2B FindFirstFileW,Sleep,FindNextFileW,FindClose, |
2_2_00239B2B |
Source: C:\Users\user\AppData\Local\directory\name.exe |
Code function: 2_2_00235C97 FindFirstFileW,FindNextFileW,FindClose, |
2_2_00235C97 |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe |
Thread delayed: delay time: 922337203685477 |
Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe |
Thread delayed: delay time: 100000 |
Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe |
Thread delayed: delay time: 99891 |
Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe |
Thread delayed: delay time: 99766 |
Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe |
Thread delayed: delay time: 99657 |
Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe |
Thread delayed: delay time: 99532 |
Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe |
Thread delayed: delay time: 99422 |
Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe |
Thread delayed: delay time: 99313 |
Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe |
Thread delayed: delay time: 99188 |
Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe |
Thread delayed: delay time: 99063 |
Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe |
Thread delayed: delay time: 98938 |
Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe |
Thread delayed: delay time: 98813 |
Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe |
Thread delayed: delay time: 98703 |
Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe |
Thread delayed: delay time: 98594 |
Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe |
Thread delayed: delay time: 98469 |
Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe |
Thread delayed: delay time: 98359 |
Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe |
Thread delayed: delay time: 98250 |
Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe |
Thread delayed: delay time: 98140 |
Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe |
Thread delayed: delay time: 98032 |
Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe |
Thread delayed: delay time: 97907 |
Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe |
Thread delayed: delay time: 97782 |
Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe |
Thread delayed: delay time: 97657 |
Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe |
Thread delayed: delay time: 97547 |
Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe |
Thread delayed: delay time: 97437 |
Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe |
Thread delayed: delay time: 97327 |
Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe |
Thread delayed: delay time: 97219 |
Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe |
Thread delayed: delay time: 97106 |
Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe |
Thread delayed: delay time: 97000 |
Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe |
Thread delayed: delay time: 96891 |
Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe |
Thread delayed: delay time: 96781 |
Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe |
Thread delayed: delay time: 96669 |
Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe |
Thread delayed: delay time: 96563 |
Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe |
Thread delayed: delay time: 96453 |
Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe |
Thread delayed: delay time: 96344 |
Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe |
Thread delayed: delay time: 96219 |
Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe |
Thread delayed: delay time: 96110 |
Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe |
Thread delayed: delay time: 95777 |
Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe |
Thread delayed: delay time: 95672 |
Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe |
Thread delayed: delay time: 95563 |
Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe |
Thread delayed: delay time: 95453 |
Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe |
Thread delayed: delay time: 922337203685477 |
Jump to behavior |
Source: C:\Users\user\AppData\Roaming\newfile\newfile.exe |
Thread delayed: delay time: 922337203685477 |
Jump to behavior |
Source: C:\Users\user\AppData\Roaming\newfile\newfile.exe |
Thread delayed: delay time: 922337203685477 |
Jump to behavior |