Source: 0.2.33-o_Installer.exe.5820000.1.raw.unpack |
String decryptor: 117.41.184.33 |
Source: 0.2.33-o_Installer.exe.5820000.1.raw.unpack |
String decryptor: 7000 |
Source: 0.2.33-o_Installer.exe.5820000.1.raw.unpack |
String decryptor: <123456789> |
Source: 0.2.33-o_Installer.exe.5820000.1.raw.unpack |
String decryptor: <Xwormmm> |
Source: 0.2.33-o_Installer.exe.5820000.1.raw.unpack |
String decryptor: XWorm V5.6 |
Source: 0.2.33-o_Installer.exe.5820000.1.raw.unpack |
String decryptor: USB.exe |
Source: unknown |
TCP traffic detected without corresponding DNS query: 117.41.184.33 |
Source: unknown |
TCP traffic detected without corresponding DNS query: 117.41.184.33 |
Source: unknown |
TCP traffic detected without corresponding DNS query: 117.41.184.33 |
Source: unknown |
TCP traffic detected without corresponding DNS query: 117.41.184.33 |
Source: unknown |
TCP traffic detected without corresponding DNS query: 117.41.184.33 |
Source: unknown |
TCP traffic detected without corresponding DNS query: 117.41.184.33 |
Source: unknown |
TCP traffic detected without corresponding DNS query: 117.41.184.33 |
Source: unknown |
TCP traffic detected without corresponding DNS query: 117.41.184.33 |
Source: unknown |
TCP traffic detected without corresponding DNS query: 117.41.184.33 |
Source: unknown |
TCP traffic detected without corresponding DNS query: 117.41.184.33 |
Source: unknown |
TCP traffic detected without corresponding DNS query: 117.41.184.33 |
Source: unknown |
TCP traffic detected without corresponding DNS query: 117.41.184.33 |
Source: unknown |
TCP traffic detected without corresponding DNS query: 117.41.184.33 |
Source: unknown |
TCP traffic detected without corresponding DNS query: 117.41.184.33 |
Source: unknown |
TCP traffic detected without corresponding DNS query: 117.41.184.33 |
Source: unknown |
TCP traffic detected without corresponding DNS query: 117.41.184.33 |
Source: unknown |
TCP traffic detected without corresponding DNS query: 117.41.184.33 |
Source: unknown |
TCP traffic detected without corresponding DNS query: 117.41.184.33 |
Source: unknown |
TCP traffic detected without corresponding DNS query: 117.41.184.33 |
Source: unknown |
TCP traffic detected without corresponding DNS query: 117.41.184.33 |
Source: unknown |
TCP traffic detected without corresponding DNS query: 117.41.184.33 |
Source: unknown |
TCP traffic detected without corresponding DNS query: 117.41.184.33 |
Source: unknown |
TCP traffic detected without corresponding DNS query: 117.41.184.33 |
Source: unknown |
TCP traffic detected without corresponding DNS query: 117.41.184.33 |
Source: unknown |
TCP traffic detected without corresponding DNS query: 117.41.184.33 |
Source: unknown |
TCP traffic detected without corresponding DNS query: 117.41.184.33 |
Source: unknown |
TCP traffic detected without corresponding DNS query: 117.41.184.33 |
Source: unknown |
TCP traffic detected without corresponding DNS query: 117.41.184.33 |
Source: unknown |
TCP traffic detected without corresponding DNS query: 117.41.184.33 |
Source: unknown |
TCP traffic detected without corresponding DNS query: 117.41.184.33 |
Source: unknown |
TCP traffic detected without corresponding DNS query: 117.41.184.33 |
Source: unknown |
TCP traffic detected without corresponding DNS query: 117.41.184.33 |
Source: unknown |
TCP traffic detected without corresponding DNS query: 117.41.184.33 |
Source: unknown |
TCP traffic detected without corresponding DNS query: 117.41.184.33 |
Source: unknown |
TCP traffic detected without corresponding DNS query: 117.41.184.33 |
Source: unknown |
TCP traffic detected without corresponding DNS query: 117.41.184.33 |
Source: unknown |
TCP traffic detected without corresponding DNS query: 117.41.184.33 |
Source: unknown |
TCP traffic detected without corresponding DNS query: 117.41.184.33 |
Source: unknown |
TCP traffic detected without corresponding DNS query: 117.41.184.33 |
Source: unknown |
TCP traffic detected without corresponding DNS query: 117.41.184.33 |
Source: unknown |
TCP traffic detected without corresponding DNS query: 117.41.184.33 |
Source: unknown |
TCP traffic detected without corresponding DNS query: 117.41.184.33 |
Source: unknown |
TCP traffic detected without corresponding DNS query: 117.41.184.33 |
Source: unknown |
TCP traffic detected without corresponding DNS query: 117.41.184.33 |
Source: unknown |
TCP traffic detected without corresponding DNS query: 117.41.184.33 |
Source: unknown |
TCP traffic detected without corresponding DNS query: 117.41.184.33 |
Source: unknown |
TCP traffic detected without corresponding DNS query: 117.41.184.33 |
Source: unknown |
TCP traffic detected without corresponding DNS query: 117.41.184.33 |
Source: unknown |
TCP traffic detected without corresponding DNS query: 117.41.184.33 |
Source: unknown |
TCP traffic detected without corresponding DNS query: 117.41.184.33 |
Source: dump.pcap, type: PCAP |
Matched rule: Windows_Trojan_Donutloader_f40e3759 Author: unknown |
Source: 0.2.33-o_Installer.exe.5820000.1.raw.unpack, type: UNPACKEDPE |
Matched rule: Detects AsyncRAT Author: ditekSHen |
Source: 0.2.33-o_Installer.exe.5820000.1.unpack, type: UNPACKEDPE |
Matched rule: Detects AsyncRAT Author: ditekSHen |
Source: 00000000.00000002.4498830874.0000000005820000.00000004.08000000.00040000.00000000.sdmp, type: MEMORY |
Matched rule: Detects AsyncRAT Author: ditekSHen |
Source: 00000000.00000002.4497904003.0000000003360000.00000040.00001000.00020000.00000000.sdmp, type: MEMORY |
Matched rule: Windows_Trojan_Donutloader_f40e3759 Author: unknown |
Source: C:\Users\user\AppData\Local\Microsoft\Windows\INetCache\IE\T9RRWRNL\33[1].ccp, type: DROPPED |
Matched rule: Windows_Trojan_Donutloader_f40e3759 Author: unknown |
Source: C:\Users\Public\Downloads\ind.cod, type: DROPPED |
Matched rule: Windows_Trojan_Donutloader_f40e3759 Author: unknown |
Source: C:\Users\user\Desktop\33-o_Installer.exe |
Code function: 0_2_00DD007E |
0_2_00DD007E |
Source: C:\Users\user\Desktop\33-o_Installer.exe |
Code function: 0_2_00DD5A2A |
0_2_00DD5A2A |
Source: C:\Users\user\Desktop\33-o_Installer.exe |
Code function: 0_2_00DD0BD6 |
0_2_00DD0BD6 |
Source: C:\Users\user\Desktop\33-o_Installer.exe |
Code function: 0_2_00DCFBE9 |
0_2_00DCFBE9 |
Source: C:\Users\user\Desktop\33-o_Installer.exe |
Code function: 0_2_00DD738F |
0_2_00DD738F |
Source: C:\Users\user\Desktop\33-o_Installer.exe |
Code function: 0_2_00DD54D9 |
0_2_00DD54D9 |
Source: C:\Users\user\Desktop\33-o_Installer.exe |
Code function: 0_2_00DD041C |
0_2_00DD041C |
Source: C:\Users\user\Desktop\33-o_Installer.exe |
Code function: 0_2_00DD6657 |
0_2_00DD6657 |
Source: C:\Users\user\Desktop\33-o_Installer.exe |
Code function: 0_2_00DD07EE |
0_2_00DD07EE |
Source: C:\Users\user\Desktop\33-o_Installer.exe |
Code function: 0_2_00DD7F4F |
0_2_00DD7F4F |
Source: C:\Users\user\Desktop\33-o_Installer.exe |
Code function: 0_2_00DD5F7B |
0_2_00DD5F7B |
Source: C:\Users\user\Desktop\33-o_Installer.exe |
Code function: 0_2_058355D8 |
0_2_058355D8 |
Source: C:\Users\user\Desktop\33-o_Installer.exe |
Code function: 0_2_0583A6B8 |
0_2_0583A6B8 |
Source: C:\Users\user\Desktop\33-o_Installer.exe |
Code function: 0_2_0583B3F8 |
0_2_0583B3F8 |
Source: C:\Users\user\Desktop\33-o_Installer.exe |
Code function: 0_2_0583ED84 |
0_2_0583ED84 |
Source: C:\Users\user\Desktop\33-o_Installer.exe |
Code function: 0_2_05834D08 |
0_2_05834D08 |
Source: C:\Users\user\Desktop\33-o_Installer.exe |
Code function: 0_2_058307A0 |
0_2_058307A0 |
Source: C:\Users\user\Desktop\33-o_Installer.exe |
Code function: 0_2_058349C0 |
0_2_058349C0 |
Source: dump.pcap, type: PCAP |
Matched rule: Windows_Trojan_Donutloader_f40e3759 os = windows, severity = x86, creation_date = 2021-09-15, scan_context = file, memory, license = Elastic License v2, threat_name = Windows.Trojan.Donutloader, fingerprint = 6400b34f762cebb4f91a8d24c5fce647e069a971fb3ec923a63aa98c8cfffab7, id = f40e3759-2531-4e21-946a-fb55104814c0, last_modified = 2022-01-13 |
Source: 0.2.33-o_Installer.exe.5820000.1.raw.unpack, type: UNPACKEDPE |
Matched rule: MALWARE_Win_AsyncRAT author = ditekSHen, description = Detects AsyncRAT |
Source: 0.2.33-o_Installer.exe.5820000.1.unpack, type: UNPACKEDPE |
Matched rule: MALWARE_Win_AsyncRAT author = ditekSHen, description = Detects AsyncRAT |
Source: 00000000.00000002.4498830874.0000000005820000.00000004.08000000.00040000.00000000.sdmp, type: MEMORY |
Matched rule: MALWARE_Win_AsyncRAT author = ditekSHen, description = Detects AsyncRAT |
Source: 00000000.00000002.4497904003.0000000003360000.00000040.00001000.00020000.00000000.sdmp, type: MEMORY |
Matched rule: Windows_Trojan_Donutloader_f40e3759 os = windows, severity = x86, creation_date = 2021-09-15, scan_context = file, memory, license = Elastic License v2, threat_name = Windows.Trojan.Donutloader, fingerprint = 6400b34f762cebb4f91a8d24c5fce647e069a971fb3ec923a63aa98c8cfffab7, id = f40e3759-2531-4e21-946a-fb55104814c0, last_modified = 2022-01-13 |
Source: C:\Users\user\AppData\Local\Microsoft\Windows\INetCache\IE\T9RRWRNL\33[1].ccp, type: DROPPED |
Matched rule: Windows_Trojan_Donutloader_f40e3759 os = windows, severity = x86, creation_date = 2021-09-15, scan_context = file, memory, license = Elastic License v2, threat_name = Windows.Trojan.Donutloader, fingerprint = 6400b34f762cebb4f91a8d24c5fce647e069a971fb3ec923a63aa98c8cfffab7, id = f40e3759-2531-4e21-946a-fb55104814c0, last_modified = 2022-01-13 |
Source: C:\Users\Public\Downloads\ind.cod, type: DROPPED |
Matched rule: Windows_Trojan_Donutloader_f40e3759 os = windows, severity = x86, creation_date = 2021-09-15, scan_context = file, memory, license = Elastic License v2, threat_name = Windows.Trojan.Donutloader, fingerprint = 6400b34f762cebb4f91a8d24c5fce647e069a971fb3ec923a63aa98c8cfffab7, id = f40e3759-2531-4e21-946a-fb55104814c0, last_modified = 2022-01-13 |
Source: C:\Users\user\Desktop\33-o_Installer.exe |
Section loaded: apphelp.dll |
Jump to behavior |
Source: C:\Users\user\Desktop\33-o_Installer.exe |
Section loaded: wininet.dll |
Jump to behavior |
Source: C:\Users\user\Desktop\33-o_Installer.exe |
Section loaded: iertutil.dll |
Jump to behavior |
Source: C:\Users\user\Desktop\33-o_Installer.exe |
Section loaded: sspicli.dll |
Jump to behavior |
Source: C:\Users\user\Desktop\33-o_Installer.exe |
Section loaded: windows.storage.dll |
Jump to behavior |
Source: C:\Users\user\Desktop\33-o_Installer.exe |
Section loaded: wldp.dll |
Jump to behavior |
Source: C:\Users\user\Desktop\33-o_Installer.exe |
Section loaded: profapi.dll |
Jump to behavior |
Source: C:\Users\user\Desktop\33-o_Installer.exe |
Section loaded: kernel.appcore.dll |
Jump to behavior |
Source: C:\Users\user\Desktop\33-o_Installer.exe |
Section loaded: ondemandconnroutehelper.dll |
Jump to behavior |
Source: C:\Users\user\Desktop\33-o_Installer.exe |
Section loaded: winhttp.dll |
Jump to behavior |
Source: C:\Users\user\Desktop\33-o_Installer.exe |
Section loaded: iphlpapi.dll |
Jump to behavior |
Source: C:\Users\user\Desktop\33-o_Installer.exe |
Section loaded: mswsock.dll |
Jump to behavior |
Source: C:\Users\user\Desktop\33-o_Installer.exe |
Section loaded: winnsi.dll |
Jump to behavior |
Source: C:\Users\user\Desktop\33-o_Installer.exe |
Section loaded: urlmon.dll |
Jump to behavior |
Source: C:\Users\user\Desktop\33-o_Installer.exe |
Section loaded: srvcli.dll |
Jump to behavior |
Source: C:\Users\user\Desktop\33-o_Installer.exe |
Section loaded: netutils.dll |
Jump to behavior |
Source: C:\Users\user\Desktop\33-o_Installer.exe |
Section loaded: dnsapi.dll |
Jump to behavior |
Source: C:\Users\user\Desktop\33-o_Installer.exe |
Section loaded: rasadhlp.dll |
Jump to behavior |
Source: C:\Users\user\Desktop\33-o_Installer.exe |
Section loaded: fwpuclnt.dll |
Jump to behavior |
Source: C:\Users\user\Desktop\33-o_Installer.exe |
Section loaded: mscoree.dll |
Jump to behavior |
Source: C:\Users\user\Desktop\33-o_Installer.exe |
Section loaded: amsi.dll |
Jump to behavior |
Source: C:\Users\user\Desktop\33-o_Installer.exe |
Section loaded: vcruntime140_clr0400.dll |
Jump to behavior |
Source: C:\Users\user\Desktop\33-o_Installer.exe |
Section loaded: ucrtbase_clr0400.dll |
Jump to behavior |
Source: C:\Users\user\Desktop\33-o_Installer.exe |
Section loaded: cryptsp.dll |
Jump to behavior |
Source: C:\Users\user\Desktop\33-o_Installer.exe |
Section loaded: rsaenh.dll |
Jump to behavior |
Source: C:\Users\user\Desktop\33-o_Installer.exe |
Section loaded: cryptbase.dll |
Jump to behavior |
Source: C:\Users\user\Desktop\33-o_Installer.exe |
Section loaded: userenv.dll |
Jump to behavior |
Source: C:\Users\user\Desktop\33-o_Installer.exe |
Section loaded: version.dll |
Jump to behavior |
Source: C:\Users\user\Desktop\33-o_Installer.exe |
Section loaded: wbemcomn.dll |
Jump to behavior |
Source: C:\Users\user\Desktop\33-o_Installer.exe |
Section loaded: avicap32.dll |
Jump to behavior |
Source: C:\Users\user\Desktop\33-o_Installer.exe |
Section loaded: msvfw32.dll |
Jump to behavior |
Source: C:\Users\user\Desktop\33-o_Installer.exe |
Section loaded: winmm.dll |
Jump to behavior |
Source: 33-o_Installer.exe |
Static PE information: Data directory: IMAGE_DIRECTORY_ENTRY_IMPORT is in: .rdata |
Source: 33-o_Installer.exe |
Static PE information: Data directory: IMAGE_DIRECTORY_ENTRY_RESOURCE is in: .rsrc |
Source: 33-o_Installer.exe |
Static PE information: Data directory: IMAGE_DIRECTORY_ENTRY_BASERELOC is in: .reloc |
Source: 33-o_Installer.exe |
Static PE information: Data directory: IMAGE_DIRECTORY_ENTRY_LOAD_CONFIG is in: .rdata |
Source: 33-o_Installer.exe |
Static PE information: Data directory: IMAGE_DIRECTORY_ENTRY_IAT is in: .rdata |
Source: 0.2.33-o_Installer.exe.5820000.1.raw.unpack, Messages.cs |
.Net Code: NewLateBinding.LateCall(obj, (Type)null, "Invoke", new object[2]{null,new object[5]{Settings.Host,Settings.Port,Settings.SPL,Settings.KEY,Helper.ID()}}, (string[])null, (Type[])null, (bool[])null, true) |
Source: 0.2.33-o_Installer.exe.5820000.1.raw.unpack, Messages.cs |
.Net Code: NewLateBinding.LateCall(obj, (Type)null, "Invoke", new object[2]{null,new object[2]{Pack[2],Helper.Decompress(Convert.FromBase64String(Pack[3]))}}, (string[])null, (Type[])null, (bool[])null, true) |
Source: C:\Users\user\Desktop\33-o_Installer.exe |
Code function: 0_2_00DD40E4 LoadLibraryW,GetProcAddress,GetProcAddress,EncodePointer,EncodePointer,GetProcAddress,EncodePointer,GetProcAddress,EncodePointer,GetProcAddress,EncodePointer,GetProcAddress,EncodePointer,DecodePointer,DecodePointer,DecodePointer,DecodePointer,DecodePointer,DecodePointer, |
0_2_00DD40E4 |
Source: C:\Users\user\Desktop\33-o_Installer.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\Desktop\33-o_Installer.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\Desktop\33-o_Installer.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\Desktop\33-o_Installer.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\Desktop\33-o_Installer.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\Desktop\33-o_Installer.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\Desktop\33-o_Installer.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\Desktop\33-o_Installer.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\Desktop\33-o_Installer.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\Desktop\33-o_Installer.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\Desktop\33-o_Installer.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\Desktop\33-o_Installer.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\Desktop\33-o_Installer.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\Desktop\33-o_Installer.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\Desktop\33-o_Installer.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\Desktop\33-o_Installer.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\Desktop\33-o_Installer.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\Desktop\33-o_Installer.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\Desktop\33-o_Installer.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\Desktop\33-o_Installer.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\Desktop\33-o_Installer.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\Desktop\33-o_Installer.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\Desktop\33-o_Installer.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\Desktop\33-o_Installer.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\Desktop\33-o_Installer.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\Desktop\33-o_Installer.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\Desktop\33-o_Installer.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\Desktop\33-o_Installer.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\Desktop\33-o_Installer.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\Desktop\33-o_Installer.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\Desktop\33-o_Installer.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\Desktop\33-o_Installer.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\Desktop\33-o_Installer.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\Desktop\33-o_Installer.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\Desktop\33-o_Installer.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\Desktop\33-o_Installer.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\Desktop\33-o_Installer.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\Desktop\33-o_Installer.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\Desktop\33-o_Installer.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\Desktop\33-o_Installer.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\Desktop\33-o_Installer.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\Desktop\33-o_Installer.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\Desktop\33-o_Installer.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\Desktop\33-o_Installer.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\Desktop\33-o_Installer.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\Desktop\33-o_Installer.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\Desktop\33-o_Installer.exe |
Code function: 0_2_00DD40E4 LoadLibraryW,GetProcAddress,GetProcAddress,EncodePointer,EncodePointer,GetProcAddress,EncodePointer,GetProcAddress,EncodePointer,GetProcAddress,EncodePointer,GetProcAddress,EncodePointer,DecodePointer,DecodePointer,DecodePointer,DecodePointer,DecodePointer,DecodePointer, |
0_2_00DD40E4 |
Source: C:\Users\user\Desktop\33-o_Installer.exe |
Code function: __getptd,_LcidFromHexString,GetLocaleInfoA,_TestDefaultLanguage, |
0_2_00DCF895 |
Source: C:\Users\user\Desktop\33-o_Installer.exe |
Code function: GetLocaleInfoA, |
0_2_00DD4859 |
Source: C:\Users\user\Desktop\33-o_Installer.exe |
Code function: ___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo, |
0_2_00DCE04E |
Source: C:\Users\user\Desktop\33-o_Installer.exe |
Code function: __getptd,_TranslateName,_GetLcidFromLangCountry,_GetLcidFromLanguage,_TranslateName,_GetLcidFromLangCountry,_GetLcidFromLanguage,_strlen,EnumSystemLocalesA,GetUserDefaultLCID,IsValidCodePage,IsValidLocale,GetLocaleInfoA,_strcpy_s,__invoke_watson,GetLocaleInfoA,GetLocaleInfoA,__itow_s, |
0_2_00DCF9F8 |
Source: C:\Users\user\Desktop\33-o_Installer.exe |
Code function: _strlen,_GetPrimaryLen,EnumSystemLocalesA, |
0_2_00DCF9BC |
Source: C:\Users\user\Desktop\33-o_Installer.exe |
Code function: _strlen,_strlen,_GetPrimaryLen,EnumSystemLocalesA, |
0_2_00DCF955 |
Source: C:\Users\user\Desktop\33-o_Installer.exe |
Code function: GetLocaleInfoW,GetLocaleInfoW,GetACP, |
0_2_00DCF4CD |
Source: C:\Users\user\Desktop\33-o_Installer.exe |
Code function: GetLocaleInfoW,GetLocaleInfoW,_malloc,GetLocaleInfoW,WideCharToMultiByte,__freea, |
0_2_00DD44BA |
Source: C:\Users\user\Desktop\33-o_Installer.exe |
Code function: __calloc_crt,__malloc_crt,_free,__malloc_crt,_free,_free,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___free_lconv_num,InterlockedDecrement,InterlockedDecrement,InterlockedDecrement,_free,_free, |
0_2_00DCECAA |
Source: C:\Users\user\Desktop\33-o_Installer.exe |
Code function: ___crtGetLocaleInfoA,GetLastError,___crtGetLocaleInfoA,__calloc_crt,___crtGetLocaleInfoA,__calloc_crt,_free,_free,__invoke_watson,GetLocaleInfoW,GetLocaleInfoW,__calloc_crt,GetLocaleInfoW,_free,GetLocaleInfoW, |
0_2_00DCDC2B |
Source: C:\Users\user\Desktop\33-o_Installer.exe |
Code function: __getptd,_LcidFromHexString,GetLocaleInfoA, |
0_2_00DCF5C2 |
Source: C:\Users\user\Desktop\33-o_Installer.exe |
Code function: _LocaleUpdate::_LocaleUpdate,__crtGetLocaleInfoA_stat, |
0_2_00DD4594 |
Source: C:\Users\user\Desktop\33-o_Installer.exe |
Code function: __getptd,_LcidFromHexString,GetLocaleInfoA,GetLocaleInfoA,GetLocaleInfoA,_strlen,GetLocaleInfoA,_strlen,_TestDefaultLanguage, |
0_2_00DCF6C4 |
Source: C:\Users\user\Desktop\33-o_Installer.exe |
Code function: GetLocaleInfoW,_GetPrimaryLen,_strlen, |
0_2_00DCF669 |
Source: C:\Users\user\Desktop\33-o_Installer.exe |
Code function: ___getlocaleinfo,__malloc_crt,__calloc_crt,__calloc_crt,__calloc_crt,__calloc_crt,GetCPInfo,___crtGetStringTypeA,___crtLCMapStringA,___crtLCMapStringA,_memmove,_memmove,_memmove,InterlockedDecrement,_free,_free,_free,_free,_free,_free,_free,_free,_free,InterlockedDecrement, |
0_2_00DC5FC5 |
Source: C:\Users\user\Desktop\33-o_Installer.exe |
Code function: __calloc_crt,__malloc_crt,_free,__malloc_crt,_free,_free,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___free_lconv_mon,_free,_free,_free,InterlockedDecrement,InterlockedDecrement,_free,_free, |
0_2_00DCEF98 |