Source: C:\Users\user\Desktop\DHL AWB COMMERCAIL INVOICE AND TRACKNG DETAILS.exe |
Code function: 0_2_00164696 GetFileAttributesW,FindFirstFileW,FindClose, |
0_2_00164696 |
Source: C:\Users\user\Desktop\DHL AWB COMMERCAIL INVOICE AND TRACKNG DETAILS.exe |
Code function: 0_2_0016C93C FindFirstFileW,FindClose, |
0_2_0016C93C |
Source: C:\Users\user\Desktop\DHL AWB COMMERCAIL INVOICE AND TRACKNG DETAILS.exe |
Code function: 0_2_0016C9C7 FindFirstFileW,FindClose,FileTimeToLocalFileTime,FileTimeToLocalFileTime,FileTimeToLocalFileTime,FileTimeToSystemTime,__swprintf,__swprintf,__swprintf,__swprintf,__swprintf,__swprintf,__swprintf, |
0_2_0016C9C7 |
Source: C:\Users\user\Desktop\DHL AWB COMMERCAIL INVOICE AND TRACKNG DETAILS.exe |
Code function: 0_2_0016F200 SetCurrentDirectoryW,FindFirstFileW,FindFirstFileW,_wcscmp,_wcscmp,GetFileAttributesW,SetFileAttributesW,FindNextFileW,FindClose,FindFirstFileW,SetCurrentDirectoryW,_wcscmp,_wcscmp,SetCurrentDirectoryW,SetCurrentDirectoryW,FindNextFileW,FindClose,FindClose, |
0_2_0016F200 |
Source: C:\Users\user\Desktop\DHL AWB COMMERCAIL INVOICE AND TRACKNG DETAILS.exe |
Code function: 0_2_0016F35D SetCurrentDirectoryW,FindFirstFileW,FindFirstFileW,_wcscmp,_wcscmp,FindNextFileW,FindClose,FindFirstFileW,SetCurrentDirectoryW,_wcscmp,_wcscmp,SetCurrentDirectoryW,SetCurrentDirectoryW,FindNextFileW,FindClose,FindClose, |
0_2_0016F35D |
Source: C:\Users\user\Desktop\DHL AWB COMMERCAIL INVOICE AND TRACKNG DETAILS.exe |
Code function: 0_2_0016F65E FindFirstFileW,Sleep,_wcscmp,_wcscmp,FindNextFileW,FindClose, |
0_2_0016F65E |
Source: C:\Users\user\Desktop\DHL AWB COMMERCAIL INVOICE AND TRACKNG DETAILS.exe |
Code function: 0_2_00163A2B FindFirstFileW,DeleteFileW,DeleteFileW,MoveFileW,DeleteFileW,FindNextFileW,FindClose,FindClose, |
0_2_00163A2B |
Source: C:\Users\user\Desktop\DHL AWB COMMERCAIL INVOICE AND TRACKNG DETAILS.exe |
Code function: 0_2_00163D4E FindFirstFileW,DeleteFileW,FindNextFileW,FindClose,FindClose, |
0_2_00163D4E |
Source: C:\Users\user\Desktop\DHL AWB COMMERCAIL INVOICE AND TRACKNG DETAILS.exe |
Code function: 0_2_0016BF27 FindFirstFileW,_wcscmp,_wcscmp,FindNextFileW,FindClose, |
0_2_0016BF27 |
Source: RegSvcs.exe, 00000002.00000002.4551821115.00000000027D1000.00000004.00000800.00020000.00000000.sdmp |
String found in binary or memory: http://ip-api.com |
Source: DHL AWB COMMERCAIL INVOICE AND TRACKNG DETAILS.exe, 00000000.00000002.2106686361.00000000040D0000.00000004.00001000.00020000.00000000.sdmp, RegSvcs.exe, 00000002.00000002.4551821115.00000000027D1000.00000004.00000800.00020000.00000000.sdmp, RegSvcs.exe, 00000002.00000002.4550614282.00000000003B2000.00000040.80000000.00040000.00000000.sdmp |
String found in binary or memory: http://ip-api.com/line/?fields=hosting |
Source: RegSvcs.exe, 00000002.00000002.4551821115.000000000280B000.00000004.00000800.00020000.00000000.sdmp |
String found in binary or memory: http://laboratoriosvilla.com.mx |
Source: RegSvcs.exe, 00000002.00000002.4551821115.000000000280B000.00000004.00000800.00020000.00000000.sdmp |
String found in binary or memory: http://mail.laboratoriosvilla.com.mx |
Source: RegSvcs.exe, 00000002.00000002.4551821115.000000000280B000.00000004.00000800.00020000.00000000.sdmp, RegSvcs.exe, 00000002.00000002.4554516679.00000000058A0000.00000004.00000020.00020000.00000000.sdmp, RegSvcs.exe, 00000002.00000002.4554600303.0000000005914000.00000004.00000020.00020000.00000000.sdmp, RegSvcs.exe, 00000002.00000002.4551171782.0000000000983000.00000004.00000020.00020000.00000000.sdmp, RegSvcs.exe, 00000002.00000002.4554600303.000000000594B000.00000004.00000020.00020000.00000000.sdmp |
String found in binary or memory: http://r10.i.lencr.org/0 |
Source: RegSvcs.exe, 00000002.00000002.4551821115.000000000280B000.00000004.00000800.00020000.00000000.sdmp, RegSvcs.exe, 00000002.00000002.4554516679.00000000058A0000.00000004.00000020.00020000.00000000.sdmp, RegSvcs.exe, 00000002.00000002.4554600303.0000000005914000.00000004.00000020.00020000.00000000.sdmp, RegSvcs.exe, 00000002.00000002.4551171782.0000000000983000.00000004.00000020.00020000.00000000.sdmp, RegSvcs.exe, 00000002.00000002.4554600303.000000000594B000.00000004.00000020.00020000.00000000.sdmp |
String found in binary or memory: http://r10.o.lencr.org0# |
Source: RegSvcs.exe, 00000002.00000002.4551821115.0000000002781000.00000004.00000800.00020000.00000000.sdmp |
String found in binary or memory: http://schemas.xmlsoap.org/ws/2005/05/identity/claims/name |
Source: RegSvcs.exe, 00000002.00000002.4551821115.000000000280B000.00000004.00000800.00020000.00000000.sdmp, RegSvcs.exe, 00000002.00000002.4554516679.00000000058A0000.00000004.00000020.00020000.00000000.sdmp, RegSvcs.exe, 00000002.00000002.4551171782.0000000000983000.00000004.00000020.00020000.00000000.sdmp, RegSvcs.exe, 00000002.00000002.4554600303.000000000594B000.00000004.00000020.00020000.00000000.sdmp |
String found in binary or memory: http://x1.c.lencr.org/0 |
Source: RegSvcs.exe, 00000002.00000002.4551821115.000000000280B000.00000004.00000800.00020000.00000000.sdmp, RegSvcs.exe, 00000002.00000002.4554516679.00000000058A0000.00000004.00000020.00020000.00000000.sdmp, RegSvcs.exe, 00000002.00000002.4551171782.0000000000983000.00000004.00000020.00020000.00000000.sdmp, RegSvcs.exe, 00000002.00000002.4554600303.000000000594B000.00000004.00000020.00020000.00000000.sdmp |
String found in binary or memory: http://x1.i.lencr.org/0 |
Source: DHL AWB COMMERCAIL INVOICE AND TRACKNG DETAILS.exe, 00000000.00000002.2106686361.00000000040D0000.00000004.00001000.00020000.00000000.sdmp, RegSvcs.exe, 00000002.00000002.4550614282.00000000003B2000.00000040.80000000.00040000.00000000.sdmp |
String found in binary or memory: https://account.dyn.com/ |
Source: DHL AWB COMMERCAIL INVOICE AND TRACKNG DETAILS.exe, 00000000.00000002.2106686361.00000000040D0000.00000004.00001000.00020000.00000000.sdmp, RegSvcs.exe, 00000002.00000002.4550614282.00000000003B2000.00000040.80000000.00040000.00000000.sdmp, RegSvcs.exe, 00000002.00000002.4551821115.0000000002781000.00000004.00000800.00020000.00000000.sdmp |
String found in binary or memory: https://api.ipify.org |
Source: RegSvcs.exe, 00000002.00000002.4551821115.0000000002781000.00000004.00000800.00020000.00000000.sdmp |
String found in binary or memory: https://api.ipify.org/ |
Source: RegSvcs.exe, 00000002.00000002.4551821115.0000000002781000.00000004.00000800.00020000.00000000.sdmp |
String found in binary or memory: https://api.ipify.org/t |
Source: C:\Users\user\Desktop\DHL AWB COMMERCAIL INVOICE AND TRACKNG DETAILS.exe |
Code function: 0_2_0018CDAC DefDlgProcW,SendMessageW,GetWindowLongW,SendMessageW,SendMessageW,_wcsncpy,GetKeyState,GetKeyState,GetKeyState,SendMessageW,GetKeyState,SendMessageW,SendMessageW,SendMessageW,ImageList_SetDragCursorImage,ImageList_BeginDrag,SetCapture,ClientToScreen,ImageList_DragEnter,InvalidateRect,ReleaseCapture,GetCursorPos,ScreenToClient,SendMessageW,SendMessageW,SendMessageW,SendMessageW,SendMessageW,SendMessageW,SendMessageW,GetCursorPos,ScreenToClient,GetParent,SendMessageW,SendMessageW,ClientToScreen,TrackPopupMenuEx,SendMessageW,SendMessageW,ClientToScreen,TrackPopupMenuEx,GetWindowLongW, |
0_2_0018CDAC |
Source: C:\Users\user\Desktop\DHL AWB COMMERCAIL INVOICE AND TRACKNG DETAILS.exe |
Code function: 0_2_0010E800 |
0_2_0010E800 |
Source: C:\Users\user\Desktop\DHL AWB COMMERCAIL INVOICE AND TRACKNG DETAILS.exe |
Code function: 0_2_0012DBB5 |
0_2_0012DBB5 |
Source: C:\Users\user\Desktop\DHL AWB COMMERCAIL INVOICE AND TRACKNG DETAILS.exe |
Code function: 0_2_0018804A |
0_2_0018804A |
Source: C:\Users\user\Desktop\DHL AWB COMMERCAIL INVOICE AND TRACKNG DETAILS.exe |
Code function: 0_2_0010E060 |
0_2_0010E060 |
Source: C:\Users\user\Desktop\DHL AWB COMMERCAIL INVOICE AND TRACKNG DETAILS.exe |
Code function: 0_2_00114140 |
0_2_00114140 |
Source: C:\Users\user\Desktop\DHL AWB COMMERCAIL INVOICE AND TRACKNG DETAILS.exe |
Code function: 0_2_00122405 |
0_2_00122405 |
Source: C:\Users\user\Desktop\DHL AWB COMMERCAIL INVOICE AND TRACKNG DETAILS.exe |
Code function: 0_2_00136522 |
0_2_00136522 |
Source: C:\Users\user\Desktop\DHL AWB COMMERCAIL INVOICE AND TRACKNG DETAILS.exe |
Code function: 0_2_0013267E |
0_2_0013267E |
Source: C:\Users\user\Desktop\DHL AWB COMMERCAIL INVOICE AND TRACKNG DETAILS.exe |
Code function: 0_2_00180665 |
0_2_00180665 |
Source: C:\Users\user\Desktop\DHL AWB COMMERCAIL INVOICE AND TRACKNG DETAILS.exe |
Code function: 0_2_0012283A |
0_2_0012283A |
Source: C:\Users\user\Desktop\DHL AWB COMMERCAIL INVOICE AND TRACKNG DETAILS.exe |
Code function: 0_2_00116843 |
0_2_00116843 |
Source: C:\Users\user\Desktop\DHL AWB COMMERCAIL INVOICE AND TRACKNG DETAILS.exe |
Code function: 0_2_001389DF |
0_2_001389DF |
Source: C:\Users\user\Desktop\DHL AWB COMMERCAIL INVOICE AND TRACKNG DETAILS.exe |
Code function: 0_2_00118A0E |
0_2_00118A0E |
Source: C:\Users\user\Desktop\DHL AWB COMMERCAIL INVOICE AND TRACKNG DETAILS.exe |
Code function: 0_2_00136A94 |
0_2_00136A94 |
Source: C:\Users\user\Desktop\DHL AWB COMMERCAIL INVOICE AND TRACKNG DETAILS.exe |
Code function: 0_2_00180AE2 |
0_2_00180AE2 |
Source: C:\Users\user\Desktop\DHL AWB COMMERCAIL INVOICE AND TRACKNG DETAILS.exe |
Code function: 0_2_00168B13 |
0_2_00168B13 |
Source: C:\Users\user\Desktop\DHL AWB COMMERCAIL INVOICE AND TRACKNG DETAILS.exe |
Code function: 0_2_0015EB07 |
0_2_0015EB07 |
Source: C:\Users\user\Desktop\DHL AWB COMMERCAIL INVOICE AND TRACKNG DETAILS.exe |
Code function: 0_2_0012CD61 |
0_2_0012CD61 |
Source: C:\Users\user\Desktop\DHL AWB COMMERCAIL INVOICE AND TRACKNG DETAILS.exe |
Code function: 0_2_00137006 |
0_2_00137006 |
Source: C:\Users\user\Desktop\DHL AWB COMMERCAIL INVOICE AND TRACKNG DETAILS.exe |
Code function: 0_2_0011710E |
0_2_0011710E |
Source: C:\Users\user\Desktop\DHL AWB COMMERCAIL INVOICE AND TRACKNG DETAILS.exe |
Code function: 0_2_00113190 |
0_2_00113190 |
Source: C:\Users\user\Desktop\DHL AWB COMMERCAIL INVOICE AND TRACKNG DETAILS.exe |
Code function: 0_2_00101287 |
0_2_00101287 |
Source: C:\Users\user\Desktop\DHL AWB COMMERCAIL INVOICE AND TRACKNG DETAILS.exe |
Code function: 0_2_001233C7 |
0_2_001233C7 |
Source: C:\Users\user\Desktop\DHL AWB COMMERCAIL INVOICE AND TRACKNG DETAILS.exe |
Code function: 0_2_0012F419 |
0_2_0012F419 |
Source: C:\Users\user\Desktop\DHL AWB COMMERCAIL INVOICE AND TRACKNG DETAILS.exe |
Code function: 0_2_00115680 |
0_2_00115680 |
Source: C:\Users\user\Desktop\DHL AWB COMMERCAIL INVOICE AND TRACKNG DETAILS.exe |
Code function: 0_2_001216C4 |
0_2_001216C4 |
Source: C:\Users\user\Desktop\DHL AWB COMMERCAIL INVOICE AND TRACKNG DETAILS.exe |
Code function: 0_2_001278D3 |
0_2_001278D3 |
Source: C:\Users\user\Desktop\DHL AWB COMMERCAIL INVOICE AND TRACKNG DETAILS.exe |
Code function: 0_2_001158C0 |
0_2_001158C0 |
Source: C:\Users\user\Desktop\DHL AWB COMMERCAIL INVOICE AND TRACKNG DETAILS.exe |
Code function: 0_2_00121BB8 |
0_2_00121BB8 |
Source: C:\Users\user\Desktop\DHL AWB COMMERCAIL INVOICE AND TRACKNG DETAILS.exe |
Code function: 0_2_00139D05 |
0_2_00139D05 |
Source: C:\Users\user\Desktop\DHL AWB COMMERCAIL INVOICE AND TRACKNG DETAILS.exe |
Code function: 0_2_0010FE40 |
0_2_0010FE40 |
Source: C:\Users\user\Desktop\DHL AWB COMMERCAIL INVOICE AND TRACKNG DETAILS.exe |
Code function: 0_2_00121FD0 |
0_2_00121FD0 |
Source: C:\Users\user\Desktop\DHL AWB COMMERCAIL INVOICE AND TRACKNG DETAILS.exe |
Code function: 0_2_0012BFE6 |
0_2_0012BFE6 |
Source: C:\Users\user\Desktop\DHL AWB COMMERCAIL INVOICE AND TRACKNG DETAILS.exe |
Code function: 0_2_024435F0 |
0_2_024435F0 |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe |
Code function: 2_2_02764208 |
2_2_02764208 |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe |
Code function: 2_2_0276F458 |
2_2_0276F458 |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe |
Code function: 2_2_0276BAF0 |
2_2_0276BAF0 |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe |
Code function: 2_2_02764AD8 |
2_2_02764AD8 |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe |
Code function: 2_2_02763EC0 |
2_2_02763EC0 |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe |
Code function: 2_2_0276AF20 |
2_2_0276AF20 |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe |
Code function: 2_2_02761A95 |
2_2_02761A95 |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe |
Code function: 2_2_062CBCEC |
2_2_062CBCEC |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe |
Code function: 2_2_062CA6B8 |
2_2_062CA6B8 |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe |
Code function: 2_2_062CCE18 |
2_2_062CCE18 |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe |
Code function: 2_2_062CEC10 |
2_2_062CEC10 |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe |
Code function: 2_2_062CBCE0 |
2_2_062CBCE0 |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe |
Code function: 2_2_062EB218 |
2_2_062EB218 |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe |
Code function: 2_2_062E2350 |
2_2_062E2350 |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe |
Code function: 2_2_062E51A0 |
2_2_062E51A0 |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe |
Code function: 2_2_062E61D8 |
2_2_062E61D8 |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe |
Code function: 2_2_062E58E0 |
2_2_062E58E0 |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe |
Code function: 2_2_062E7968 |
2_2_062E7968 |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe |
Code function: 2_2_062E7288 |
2_2_062E7288 |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe |
Code function: 2_2_062EE388 |
2_2_062EE388 |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe |
Code function: 2_2_062E0040 |
2_2_062E0040 |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe |
Code function: 2_2_062E003B |
2_2_062E003B |
Source: 0.2.DHL AWB COMMERCAIL INVOICE AND TRACKNG DETAILS.exe.40d0000.1.raw.unpack, ISZbPXDvPz.cs |
Cryptographic APIs: 'TransformFinalBlock' |
Source: 0.2.DHL AWB COMMERCAIL INVOICE AND TRACKNG DETAILS.exe.40d0000.1.raw.unpack, ISZbPXDvPz.cs |
Cryptographic APIs: 'TransformFinalBlock', 'CreateDecryptor' |
Source: 0.2.DHL AWB COMMERCAIL INVOICE AND TRACKNG DETAILS.exe.40d0000.1.raw.unpack, nAXAT51m.cs |
Cryptographic APIs: 'TransformFinalBlock' |
Source: 0.2.DHL AWB COMMERCAIL INVOICE AND TRACKNG DETAILS.exe.40d0000.1.raw.unpack, nAXAT51m.cs |
Cryptographic APIs: 'TransformFinalBlock' |
Source: 0.2.DHL AWB COMMERCAIL INVOICE AND TRACKNG DETAILS.exe.40d0000.1.raw.unpack, nAXAT51m.cs |
Cryptographic APIs: 'TransformFinalBlock' |
Source: 0.2.DHL AWB COMMERCAIL INVOICE AND TRACKNG DETAILS.exe.40d0000.1.raw.unpack, nAXAT51m.cs |
Cryptographic APIs: 'TransformFinalBlock' |
Source: 0.2.DHL AWB COMMERCAIL INVOICE AND TRACKNG DETAILS.exe.40d0000.1.raw.unpack, YpS.cs |
Cryptographic APIs: 'TransformFinalBlock' |
Source: 0.2.DHL AWB COMMERCAIL INVOICE AND TRACKNG DETAILS.exe.40d0000.1.raw.unpack, YpS.cs |
Cryptographic APIs: 'TransformFinalBlock' |
Source: C:\Users\user\Desktop\DHL AWB COMMERCAIL INVOICE AND TRACKNG DETAILS.exe |
Section loaded: wsock32.dll |
Jump to behavior |
Source: C:\Users\user\Desktop\DHL AWB COMMERCAIL INVOICE AND TRACKNG DETAILS.exe |
Section loaded: version.dll |
Jump to behavior |
Source: C:\Users\user\Desktop\DHL AWB COMMERCAIL INVOICE AND TRACKNG DETAILS.exe |
Section loaded: winmm.dll |
Jump to behavior |
Source: C:\Users\user\Desktop\DHL AWB COMMERCAIL INVOICE AND TRACKNG DETAILS.exe |
Section loaded: mpr.dll |
Jump to behavior |
Source: C:\Users\user\Desktop\DHL AWB COMMERCAIL INVOICE AND TRACKNG DETAILS.exe |
Section loaded: wininet.dll |
Jump to behavior |
Source: C:\Users\user\Desktop\DHL AWB COMMERCAIL INVOICE AND TRACKNG DETAILS.exe |
Section loaded: iphlpapi.dll |
Jump to behavior |
Source: C:\Users\user\Desktop\DHL AWB COMMERCAIL INVOICE AND TRACKNG DETAILS.exe |
Section loaded: userenv.dll |
Jump to behavior |
Source: C:\Users\user\Desktop\DHL AWB COMMERCAIL INVOICE AND TRACKNG DETAILS.exe |
Section loaded: uxtheme.dll |
Jump to behavior |
Source: C:\Users\user\Desktop\DHL AWB COMMERCAIL INVOICE AND TRACKNG DETAILS.exe |
Section loaded: kernel.appcore.dll |
Jump to behavior |
Source: C:\Users\user\Desktop\DHL AWB COMMERCAIL INVOICE AND TRACKNG DETAILS.exe |
Section loaded: windows.storage.dll |
Jump to behavior |
Source: C:\Users\user\Desktop\DHL AWB COMMERCAIL INVOICE AND TRACKNG DETAILS.exe |
Section loaded: wldp.dll |
Jump to behavior |
Source: C:\Users\user\AppData\Roaming\KaGeys\KaGeys.exe |
Section loaded: mscoree.dll |
Jump to behavior |
Source: C:\Users\user\AppData\Roaming\KaGeys\KaGeys.exe |
Section loaded: kernel.appcore.dll |
Jump to behavior |
Source: C:\Users\user\AppData\Roaming\KaGeys\KaGeys.exe |
Section loaded: version.dll |
Jump to behavior |
Source: C:\Users\user\AppData\Roaming\KaGeys\KaGeys.exe |
Section loaded: vcruntime140_clr0400.dll |
Jump to behavior |
Source: C:\Users\user\AppData\Roaming\KaGeys\KaGeys.exe |
Section loaded: ucrtbase_clr0400.dll |
Jump to behavior |
Source: C:\Users\user\AppData\Roaming\KaGeys\KaGeys.exe |
Section loaded: ucrtbase_clr0400.dll |
Jump to behavior |
Source: C:\Users\user\AppData\Roaming\KaGeys\KaGeys.exe |
Section loaded: mscoree.dll |
Jump to behavior |
Source: C:\Users\user\AppData\Roaming\KaGeys\KaGeys.exe |
Section loaded: kernel.appcore.dll |
Jump to behavior |
Source: C:\Users\user\AppData\Roaming\KaGeys\KaGeys.exe |
Section loaded: version.dll |
Jump to behavior |
Source: C:\Users\user\AppData\Roaming\KaGeys\KaGeys.exe |
Section loaded: vcruntime140_clr0400.dll |
Jump to behavior |
Source: C:\Users\user\AppData\Roaming\KaGeys\KaGeys.exe |
Section loaded: ucrtbase_clr0400.dll |
Jump to behavior |
Source: C:\Users\user\Desktop\DHL AWB COMMERCAIL INVOICE AND TRACKNG DETAILS.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\Desktop\DHL AWB COMMERCAIL INVOICE AND TRACKNG DETAILS.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\AppData\Roaming\KaGeys\KaGeys.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\AppData\Roaming\KaGeys\KaGeys.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\AppData\Roaming\KaGeys\KaGeys.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\AppData\Roaming\KaGeys\KaGeys.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\AppData\Roaming\KaGeys\KaGeys.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\AppData\Roaming\KaGeys\KaGeys.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\AppData\Roaming\KaGeys\KaGeys.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\AppData\Roaming\KaGeys\KaGeys.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\AppData\Roaming\KaGeys\KaGeys.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\AppData\Roaming\KaGeys\KaGeys.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\AppData\Roaming\KaGeys\KaGeys.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\AppData\Roaming\KaGeys\KaGeys.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\AppData\Roaming\KaGeys\KaGeys.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\AppData\Roaming\KaGeys\KaGeys.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\AppData\Roaming\KaGeys\KaGeys.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\AppData\Roaming\KaGeys\KaGeys.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\AppData\Roaming\KaGeys\KaGeys.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\AppData\Roaming\KaGeys\KaGeys.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\AppData\Roaming\KaGeys\KaGeys.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\AppData\Roaming\KaGeys\KaGeys.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\AppData\Roaming\KaGeys\KaGeys.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\AppData\Roaming\KaGeys\KaGeys.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\AppData\Roaming\KaGeys\KaGeys.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\AppData\Roaming\KaGeys\KaGeys.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\AppData\Roaming\KaGeys\KaGeys.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\AppData\Roaming\KaGeys\KaGeys.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\AppData\Roaming\KaGeys\KaGeys.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\AppData\Roaming\KaGeys\KaGeys.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\AppData\Roaming\KaGeys\KaGeys.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\AppData\Roaming\KaGeys\KaGeys.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\AppData\Roaming\KaGeys\KaGeys.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\AppData\Roaming\KaGeys\KaGeys.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\AppData\Roaming\KaGeys\KaGeys.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\AppData\Roaming\KaGeys\KaGeys.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe |
Thread delayed: delay time: 922337203685477 |
Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe |
Thread delayed: delay time: 600000 |
Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe |
Thread delayed: delay time: 599890 |
Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe |
Thread delayed: delay time: 599781 |
Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe |
Thread delayed: delay time: 599671 |
Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe |
Thread delayed: delay time: 599559 |
Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe |
Thread delayed: delay time: 599453 |
Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe |
Thread delayed: delay time: 599332 |
Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe |
Thread delayed: delay time: 599199 |
Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe |
Thread delayed: delay time: 599093 |
Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe |
Thread delayed: delay time: 598983 |
Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe |
Thread delayed: delay time: 595135 |
Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe |
Thread delayed: delay time: 594993 |
Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe |
Thread delayed: delay time: 594875 |
Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe |
Thread delayed: delay time: 594765 |
Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe |
Thread delayed: delay time: 594656 |
Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe |
Thread delayed: delay time: 594546 |
Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe |
Thread delayed: delay time: 594437 |
Jump to behavior |
Source: C:\Users\user\AppData\Roaming\KaGeys\KaGeys.exe |
Thread delayed: delay time: 922337203685477 |
Jump to behavior |
Source: C:\Users\user\AppData\Roaming\KaGeys\KaGeys.exe |
Thread delayed: delay time: 922337203685477 |
Jump to behavior |
Source: C:\Users\user\Desktop\DHL AWB COMMERCAIL INVOICE AND TRACKNG DETAILS.exe |
Code function: 0_2_00164696 GetFileAttributesW,FindFirstFileW,FindClose, |
0_2_00164696 |
Source: C:\Users\user\Desktop\DHL AWB COMMERCAIL INVOICE AND TRACKNG DETAILS.exe |
Code function: 0_2_0016C93C FindFirstFileW,FindClose, |
0_2_0016C93C |
Source: C:\Users\user\Desktop\DHL AWB COMMERCAIL INVOICE AND TRACKNG DETAILS.exe |
Code function: 0_2_0016C9C7 FindFirstFileW,FindClose,FileTimeToLocalFileTime,FileTimeToLocalFileTime,FileTimeToLocalFileTime,FileTimeToSystemTime,__swprintf,__swprintf,__swprintf,__swprintf,__swprintf,__swprintf,__swprintf, |
0_2_0016C9C7 |
Source: C:\Users\user\Desktop\DHL AWB COMMERCAIL INVOICE AND TRACKNG DETAILS.exe |
Code function: 0_2_0016F200 SetCurrentDirectoryW,FindFirstFileW,FindFirstFileW,_wcscmp,_wcscmp,GetFileAttributesW,SetFileAttributesW,FindNextFileW,FindClose,FindFirstFileW,SetCurrentDirectoryW,_wcscmp,_wcscmp,SetCurrentDirectoryW,SetCurrentDirectoryW,FindNextFileW,FindClose,FindClose, |
0_2_0016F200 |
Source: C:\Users\user\Desktop\DHL AWB COMMERCAIL INVOICE AND TRACKNG DETAILS.exe |
Code function: 0_2_0016F35D SetCurrentDirectoryW,FindFirstFileW,FindFirstFileW,_wcscmp,_wcscmp,FindNextFileW,FindClose,FindFirstFileW,SetCurrentDirectoryW,_wcscmp,_wcscmp,SetCurrentDirectoryW,SetCurrentDirectoryW,FindNextFileW,FindClose,FindClose, |
0_2_0016F35D |
Source: C:\Users\user\Desktop\DHL AWB COMMERCAIL INVOICE AND TRACKNG DETAILS.exe |
Code function: 0_2_0016F65E FindFirstFileW,Sleep,_wcscmp,_wcscmp,FindNextFileW,FindClose, |
0_2_0016F65E |
Source: C:\Users\user\Desktop\DHL AWB COMMERCAIL INVOICE AND TRACKNG DETAILS.exe |
Code function: 0_2_00163A2B FindFirstFileW,DeleteFileW,DeleteFileW,MoveFileW,DeleteFileW,FindNextFileW,FindClose,FindClose, |
0_2_00163A2B |
Source: C:\Users\user\Desktop\DHL AWB COMMERCAIL INVOICE AND TRACKNG DETAILS.exe |
Code function: 0_2_00163D4E FindFirstFileW,DeleteFileW,FindNextFileW,FindClose,FindClose, |
0_2_00163D4E |
Source: C:\Users\user\Desktop\DHL AWB COMMERCAIL INVOICE AND TRACKNG DETAILS.exe |
Code function: 0_2_0016BF27 FindFirstFileW,_wcscmp,_wcscmp,FindNextFileW,FindClose, |
0_2_0016BF27 |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe |
Thread delayed: delay time: 922337203685477 |
Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe |
Thread delayed: delay time: 600000 |
Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe |
Thread delayed: delay time: 599890 |
Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe |
Thread delayed: delay time: 599781 |
Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe |
Thread delayed: delay time: 599671 |
Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe |
Thread delayed: delay time: 599559 |
Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe |
Thread delayed: delay time: 599453 |
Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe |
Thread delayed: delay time: 599332 |
Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe |
Thread delayed: delay time: 599199 |
Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe |
Thread delayed: delay time: 599093 |
Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe |
Thread delayed: delay time: 598983 |
Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe |
Thread delayed: delay time: 100000 |
Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe |
Thread delayed: delay time: 99874 |
Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe |
Thread delayed: delay time: 99765 |
Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe |
Thread delayed: delay time: 99652 |
Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe |
Thread delayed: delay time: 99546 |
Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe |
Thread delayed: delay time: 99437 |
Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe |
Thread delayed: delay time: 99328 |
Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe |
Thread delayed: delay time: 99218 |
Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe |
Thread delayed: delay time: 99109 |
Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe |
Thread delayed: delay time: 98999 |
Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe |
Thread delayed: delay time: 98890 |
Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe |
Thread delayed: delay time: 98781 |
Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe |
Thread delayed: delay time: 98671 |
Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe |
Thread delayed: delay time: 98562 |
Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe |
Thread delayed: delay time: 98453 |
Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe |
Thread delayed: delay time: 98343 |
Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe |
Thread delayed: delay time: 98234 |
Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe |
Thread delayed: delay time: 98124 |
Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe |
Thread delayed: delay time: 98015 |
Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe |
Thread delayed: delay time: 97905 |
Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe |
Thread delayed: delay time: 97796 |
Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe |
Thread delayed: delay time: 97687 |
Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe |
Thread delayed: delay time: 97578 |
Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe |
Thread delayed: delay time: 97464 |
Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe |
Thread delayed: delay time: 97348 |
Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe |
Thread delayed: delay time: 97218 |
Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe |
Thread delayed: delay time: 97109 |
Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe |
Thread delayed: delay time: 96999 |
Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe |
Thread delayed: delay time: 96890 |
Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe |
Thread delayed: delay time: 96772 |
Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe |
Thread delayed: delay time: 96656 |
Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe |
Thread delayed: delay time: 96546 |
Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe |
Thread delayed: delay time: 96436 |
Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe |
Thread delayed: delay time: 96328 |
Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe |
Thread delayed: delay time: 595135 |
Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe |
Thread delayed: delay time: 594993 |
Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe |
Thread delayed: delay time: 594875 |
Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe |
Thread delayed: delay time: 594765 |
Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe |
Thread delayed: delay time: 594656 |
Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe |
Thread delayed: delay time: 594546 |
Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe |
Thread delayed: delay time: 594437 |
Jump to behavior |
Source: C:\Users\user\AppData\Roaming\KaGeys\KaGeys.exe |
Thread delayed: delay time: 922337203685477 |
Jump to behavior |
Source: C:\Users\user\AppData\Roaming\KaGeys\KaGeys.exe |
Thread delayed: delay time: 922337203685477 |
Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe |
Queries volume information: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe VolumeInformation |
Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe |
Queries volume information: C:\Windows\Microsoft.NET\assembly\GAC_MSIL\System.Windows.Forms\v4.0_4.0.0.0__b77a5c561934e089\System.Windows.Forms.dll VolumeInformation |
Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe |
Queries volume information: C:\Windows\Microsoft.NET\assembly\GAC_MSIL\System.Security\v4.0_4.0.0.0__b03f5f7f11d50a3a\System.Security.dll VolumeInformation |
Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe |
Queries volume information: C:\Windows\Microsoft.NET\assembly\GAC_MSIL\Microsoft.VisualBasic\v4.0_10.0.0.0__b03f5f7f11d50a3a\Microsoft.VisualBasic.dll VolumeInformation |
Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe |
Queries volume information: C:\Windows\Microsoft.NET\assembly\GAC_MSIL\System.Drawing\v4.0_4.0.0.0__b03f5f7f11d50a3a\System.Drawing.dll VolumeInformation |
Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe |
Queries volume information: C:\Windows\Microsoft.NET\assembly\GAC_MSIL\Accessibility\v4.0_4.0.0.0__b03f5f7f11d50a3a\Accessibility.dll VolumeInformation |
Jump to behavior |
Source: C:\Users\user\AppData\Roaming\KaGeys\KaGeys.exe |
Queries volume information: C:\Users\user\AppData\Roaming\KaGeys\KaGeys.exe VolumeInformation |
Jump to behavior |
Source: C:\Users\user\AppData\Roaming\KaGeys\KaGeys.exe |
Queries volume information: C:\Windows\Microsoft.NET\assembly\GAC_32\System.EnterpriseServices\v4.0_4.0.0.0__b03f5f7f11d50a3a\System.EnterpriseServices.dll VolumeInformation |
Jump to behavior |
Source: C:\Users\user\AppData\Roaming\KaGeys\KaGeys.exe |
Queries volume information: C:\Windows\Microsoft.NET\assembly\GAC_32\System.EnterpriseServices\v4.0_4.0.0.0__b03f5f7f11d50a3a\System.EnterpriseServices.Wrapper.dll VolumeInformation |
Jump to behavior |
Source: C:\Users\user\AppData\Roaming\KaGeys\KaGeys.exe |
Queries volume information: C:\Windows\Microsoft.NET\assembly\GAC_32\System.EnterpriseServices\v4.0_4.0.0.0__b03f5f7f11d50a3a\System.EnterpriseServices.Wrapper.dll VolumeInformation |
Jump to behavior |
Source: C:\Users\user\AppData\Roaming\KaGeys\KaGeys.exe |
Queries volume information: C:\Windows\Microsoft.NET\assembly\GAC_32\System.EnterpriseServices\v4.0_4.0.0.0__b03f5f7f11d50a3a\System.EnterpriseServices.Wrapper.dll VolumeInformation |
Jump to behavior |
Source: C:\Users\user\AppData\Roaming\KaGeys\KaGeys.exe |
Queries volume information: C:\Users\user\AppData\Roaming\KaGeys\KaGeys.exe VolumeInformation |
Jump to behavior |
Source: C:\Users\user\AppData\Roaming\KaGeys\KaGeys.exe |
Queries volume information: C:\Windows\Microsoft.NET\assembly\GAC_32\System.EnterpriseServices\v4.0_4.0.0.0__b03f5f7f11d50a3a\System.EnterpriseServices.dll VolumeInformation |
Jump to behavior |
Source: C:\Users\user\AppData\Roaming\KaGeys\KaGeys.exe |
Queries volume information: C:\Windows\Microsoft.NET\assembly\GAC_32\System.EnterpriseServices\v4.0_4.0.0.0__b03f5f7f11d50a3a\System.EnterpriseServices.Wrapper.dll VolumeInformation |
Jump to behavior |
Source: C:\Users\user\AppData\Roaming\KaGeys\KaGeys.exe |
Queries volume information: C:\Windows\Microsoft.NET\assembly\GAC_32\System.EnterpriseServices\v4.0_4.0.0.0__b03f5f7f11d50a3a\System.EnterpriseServices.Wrapper.dll VolumeInformation |
Jump to behavior |
Source: C:\Users\user\AppData\Roaming\KaGeys\KaGeys.exe |
Queries volume information: C:\Windows\Microsoft.NET\assembly\GAC_32\System.EnterpriseServices\v4.0_4.0.0.0__b03f5f7f11d50a3a\System.EnterpriseServices.Wrapper.dll VolumeInformation |
Jump to behavior |