Source: 0.2.31-o_Installer.exe.5320000.1.raw.unpack |
String decryptor: 156.238.235.31 |
Source: 0.2.31-o_Installer.exe.5320000.1.raw.unpack |
String decryptor: 7000 |
Source: 0.2.31-o_Installer.exe.5320000.1.raw.unpack |
String decryptor: <123456789> |
Source: 0.2.31-o_Installer.exe.5320000.1.raw.unpack |
String decryptor: <Xwormmm> |
Source: 0.2.31-o_Installer.exe.5320000.1.raw.unpack |
String decryptor: XWorm V5.6 |
Source: 0.2.31-o_Installer.exe.5320000.1.raw.unpack |
String decryptor: USB.exe |
Source: unknown |
TCP traffic detected without corresponding DNS query: 156.238.235.31 |
Source: unknown |
TCP traffic detected without corresponding DNS query: 156.238.235.31 |
Source: unknown |
TCP traffic detected without corresponding DNS query: 156.238.235.31 |
Source: unknown |
TCP traffic detected without corresponding DNS query: 156.238.235.31 |
Source: unknown |
TCP traffic detected without corresponding DNS query: 156.238.235.31 |
Source: unknown |
TCP traffic detected without corresponding DNS query: 156.238.235.31 |
Source: unknown |
TCP traffic detected without corresponding DNS query: 156.238.235.31 |
Source: unknown |
TCP traffic detected without corresponding DNS query: 156.238.235.31 |
Source: unknown |
TCP traffic detected without corresponding DNS query: 156.238.235.31 |
Source: unknown |
TCP traffic detected without corresponding DNS query: 156.238.235.31 |
Source: unknown |
TCP traffic detected without corresponding DNS query: 156.238.235.31 |
Source: unknown |
TCP traffic detected without corresponding DNS query: 156.238.235.31 |
Source: unknown |
TCP traffic detected without corresponding DNS query: 156.238.235.31 |
Source: unknown |
TCP traffic detected without corresponding DNS query: 156.238.235.31 |
Source: unknown |
TCP traffic detected without corresponding DNS query: 156.238.235.31 |
Source: unknown |
TCP traffic detected without corresponding DNS query: 156.238.235.31 |
Source: unknown |
TCP traffic detected without corresponding DNS query: 156.238.235.31 |
Source: unknown |
TCP traffic detected without corresponding DNS query: 156.238.235.31 |
Source: unknown |
TCP traffic detected without corresponding DNS query: 156.238.235.31 |
Source: unknown |
TCP traffic detected without corresponding DNS query: 156.238.235.31 |
Source: unknown |
TCP traffic detected without corresponding DNS query: 156.238.235.31 |
Source: unknown |
TCP traffic detected without corresponding DNS query: 156.238.235.31 |
Source: unknown |
TCP traffic detected without corresponding DNS query: 156.238.235.31 |
Source: unknown |
TCP traffic detected without corresponding DNS query: 156.238.235.31 |
Source: unknown |
TCP traffic detected without corresponding DNS query: 156.238.235.31 |
Source: unknown |
TCP traffic detected without corresponding DNS query: 156.238.235.31 |
Source: unknown |
TCP traffic detected without corresponding DNS query: 156.238.235.31 |
Source: unknown |
TCP traffic detected without corresponding DNS query: 156.238.235.31 |
Source: unknown |
TCP traffic detected without corresponding DNS query: 156.238.235.31 |
Source: unknown |
TCP traffic detected without corresponding DNS query: 156.238.235.31 |
Source: unknown |
TCP traffic detected without corresponding DNS query: 156.238.235.31 |
Source: unknown |
TCP traffic detected without corresponding DNS query: 156.238.235.31 |
Source: unknown |
TCP traffic detected without corresponding DNS query: 156.238.235.31 |
Source: unknown |
TCP traffic detected without corresponding DNS query: 156.238.235.31 |
Source: unknown |
TCP traffic detected without corresponding DNS query: 156.238.235.31 |
Source: unknown |
TCP traffic detected without corresponding DNS query: 156.238.235.31 |
Source: unknown |
TCP traffic detected without corresponding DNS query: 156.238.235.31 |
Source: unknown |
TCP traffic detected without corresponding DNS query: 156.238.235.31 |
Source: unknown |
TCP traffic detected without corresponding DNS query: 156.238.235.31 |
Source: unknown |
TCP traffic detected without corresponding DNS query: 156.238.235.31 |
Source: unknown |
TCP traffic detected without corresponding DNS query: 156.238.235.31 |
Source: unknown |
TCP traffic detected without corresponding DNS query: 156.238.235.31 |
Source: unknown |
TCP traffic detected without corresponding DNS query: 156.238.235.31 |
Source: unknown |
TCP traffic detected without corresponding DNS query: 156.238.235.31 |
Source: unknown |
TCP traffic detected without corresponding DNS query: 156.238.235.31 |
Source: unknown |
TCP traffic detected without corresponding DNS query: 156.238.235.31 |
Source: unknown |
TCP traffic detected without corresponding DNS query: 156.238.235.31 |
Source: unknown |
TCP traffic detected without corresponding DNS query: 156.238.235.31 |
Source: unknown |
TCP traffic detected without corresponding DNS query: 156.238.235.31 |
Source: unknown |
TCP traffic detected without corresponding DNS query: 156.238.235.31 |
Source: dump.pcap, type: PCAP |
Matched rule: Windows_Trojan_Donutloader_f40e3759 Author: unknown |
Source: 0.2.31-o_Installer.exe.5320000.1.raw.unpack, type: UNPACKEDPE |
Matched rule: Detects AsyncRAT Author: ditekSHen |
Source: 0.2.31-o_Installer.exe.5320000.1.unpack, type: UNPACKEDPE |
Matched rule: Detects AsyncRAT Author: ditekSHen |
Source: 00000000.00000002.4546753874.0000000002E60000.00000040.00001000.00020000.00000000.sdmp, type: MEMORY |
Matched rule: Windows_Trojan_Donutloader_f40e3759 Author: unknown |
Source: 00000000.00000002.4548525663.0000000005320000.00000004.08000000.00040000.00000000.sdmp, type: MEMORY |
Matched rule: Detects AsyncRAT Author: ditekSHen |
Source: C:\Users\Public\Downloads\ind.cod, type: DROPPED |
Matched rule: Windows_Trojan_Donutloader_f40e3759 Author: unknown |
Source: C:\Users\user\AppData\Local\Microsoft\Windows\INetCache\IE\8HXJSKQQ\31[1].ccp, type: DROPPED |
Matched rule: Windows_Trojan_Donutloader_f40e3759 Author: unknown |
Source: C:\Users\user\Desktop\31-o_Installer.exe |
Code function: 0_2_0027007E |
0_2_0027007E |
Source: C:\Users\user\Desktop\31-o_Installer.exe |
Code function: 0_2_00275A2A |
0_2_00275A2A |
Source: C:\Users\user\Desktop\31-o_Installer.exe |
Code function: 0_2_0027738F |
0_2_0027738F |
Source: C:\Users\user\Desktop\31-o_Installer.exe |
Code function: 0_2_0026FBE9 |
0_2_0026FBE9 |
Source: C:\Users\user\Desktop\31-o_Installer.exe |
Code function: 0_2_00270BD6 |
0_2_00270BD6 |
Source: C:\Users\user\Desktop\31-o_Installer.exe |
Code function: 0_2_0027041C |
0_2_0027041C |
Source: C:\Users\user\Desktop\31-o_Installer.exe |
Code function: 0_2_002754D9 |
0_2_002754D9 |
Source: C:\Users\user\Desktop\31-o_Installer.exe |
Code function: 0_2_00276657 |
0_2_00276657 |
Source: C:\Users\user\Desktop\31-o_Installer.exe |
Code function: 0_2_00275F7B |
0_2_00275F7B |
Source: C:\Users\user\Desktop\31-o_Installer.exe |
Code function: 0_2_00277F4F |
0_2_00277F4F |
Source: C:\Users\user\Desktop\31-o_Installer.exe |
Code function: 0_2_002707EE |
0_2_002707EE |
Source: C:\Users\user\Desktop\31-o_Installer.exe |
Code function: 0_2_0533A418 |
0_2_0533A418 |
Source: C:\Users\user\Desktop\31-o_Installer.exe |
Code function: 0_2_05337CB0 |
0_2_05337CB0 |
Source: C:\Users\user\Desktop\31-o_Installer.exe |
Code function: 0_2_05334E68 |
0_2_05334E68 |
Source: C:\Users\user\Desktop\31-o_Installer.exe |
Code function: 0_2_0533EE5A |
0_2_0533EE5A |
Source: C:\Users\user\Desktop\31-o_Installer.exe |
Code function: 0_2_05335B40 |
0_2_05335B40 |
Source: C:\Users\user\Desktop\31-o_Installer.exe |
Code function: 0_2_053307A0 |
0_2_053307A0 |
Source: C:\Users\user\Desktop\31-o_Installer.exe |
Code function: 0_2_05334B20 |
0_2_05334B20 |
Source: dump.pcap, type: PCAP |
Matched rule: Windows_Trojan_Donutloader_f40e3759 os = windows, severity = x86, creation_date = 2021-09-15, scan_context = file, memory, license = Elastic License v2, threat_name = Windows.Trojan.Donutloader, fingerprint = 6400b34f762cebb4f91a8d24c5fce647e069a971fb3ec923a63aa98c8cfffab7, id = f40e3759-2531-4e21-946a-fb55104814c0, last_modified = 2022-01-13 |
Source: 0.2.31-o_Installer.exe.5320000.1.raw.unpack, type: UNPACKEDPE |
Matched rule: MALWARE_Win_AsyncRAT author = ditekSHen, description = Detects AsyncRAT |
Source: 0.2.31-o_Installer.exe.5320000.1.unpack, type: UNPACKEDPE |
Matched rule: MALWARE_Win_AsyncRAT author = ditekSHen, description = Detects AsyncRAT |
Source: 00000000.00000002.4546753874.0000000002E60000.00000040.00001000.00020000.00000000.sdmp, type: MEMORY |
Matched rule: Windows_Trojan_Donutloader_f40e3759 os = windows, severity = x86, creation_date = 2021-09-15, scan_context = file, memory, license = Elastic License v2, threat_name = Windows.Trojan.Donutloader, fingerprint = 6400b34f762cebb4f91a8d24c5fce647e069a971fb3ec923a63aa98c8cfffab7, id = f40e3759-2531-4e21-946a-fb55104814c0, last_modified = 2022-01-13 |
Source: 00000000.00000002.4548525663.0000000005320000.00000004.08000000.00040000.00000000.sdmp, type: MEMORY |
Matched rule: MALWARE_Win_AsyncRAT author = ditekSHen, description = Detects AsyncRAT |
Source: C:\Users\Public\Downloads\ind.cod, type: DROPPED |
Matched rule: Windows_Trojan_Donutloader_f40e3759 os = windows, severity = x86, creation_date = 2021-09-15, scan_context = file, memory, license = Elastic License v2, threat_name = Windows.Trojan.Donutloader, fingerprint = 6400b34f762cebb4f91a8d24c5fce647e069a971fb3ec923a63aa98c8cfffab7, id = f40e3759-2531-4e21-946a-fb55104814c0, last_modified = 2022-01-13 |
Source: C:\Users\user\AppData\Local\Microsoft\Windows\INetCache\IE\8HXJSKQQ\31[1].ccp, type: DROPPED |
Matched rule: Windows_Trojan_Donutloader_f40e3759 os = windows, severity = x86, creation_date = 2021-09-15, scan_context = file, memory, license = Elastic License v2, threat_name = Windows.Trojan.Donutloader, fingerprint = 6400b34f762cebb4f91a8d24c5fce647e069a971fb3ec923a63aa98c8cfffab7, id = f40e3759-2531-4e21-946a-fb55104814c0, last_modified = 2022-01-13 |
Source: C:\Users\user\Desktop\31-o_Installer.exe |
Section loaded: apphelp.dll |
Jump to behavior |
Source: C:\Users\user\Desktop\31-o_Installer.exe |
Section loaded: wininet.dll |
Jump to behavior |
Source: C:\Users\user\Desktop\31-o_Installer.exe |
Section loaded: iertutil.dll |
Jump to behavior |
Source: C:\Users\user\Desktop\31-o_Installer.exe |
Section loaded: sspicli.dll |
Jump to behavior |
Source: C:\Users\user\Desktop\31-o_Installer.exe |
Section loaded: windows.storage.dll |
Jump to behavior |
Source: C:\Users\user\Desktop\31-o_Installer.exe |
Section loaded: wldp.dll |
Jump to behavior |
Source: C:\Users\user\Desktop\31-o_Installer.exe |
Section loaded: profapi.dll |
Jump to behavior |
Source: C:\Users\user\Desktop\31-o_Installer.exe |
Section loaded: kernel.appcore.dll |
Jump to behavior |
Source: C:\Users\user\Desktop\31-o_Installer.exe |
Section loaded: ondemandconnroutehelper.dll |
Jump to behavior |
Source: C:\Users\user\Desktop\31-o_Installer.exe |
Section loaded: winhttp.dll |
Jump to behavior |
Source: C:\Users\user\Desktop\31-o_Installer.exe |
Section loaded: iphlpapi.dll |
Jump to behavior |
Source: C:\Users\user\Desktop\31-o_Installer.exe |
Section loaded: mswsock.dll |
Jump to behavior |
Source: C:\Users\user\Desktop\31-o_Installer.exe |
Section loaded: winnsi.dll |
Jump to behavior |
Source: C:\Users\user\Desktop\31-o_Installer.exe |
Section loaded: urlmon.dll |
Jump to behavior |
Source: C:\Users\user\Desktop\31-o_Installer.exe |
Section loaded: srvcli.dll |
Jump to behavior |
Source: C:\Users\user\Desktop\31-o_Installer.exe |
Section loaded: netutils.dll |
Jump to behavior |
Source: C:\Users\user\Desktop\31-o_Installer.exe |
Section loaded: dnsapi.dll |
Jump to behavior |
Source: C:\Users\user\Desktop\31-o_Installer.exe |
Section loaded: rasadhlp.dll |
Jump to behavior |
Source: C:\Users\user\Desktop\31-o_Installer.exe |
Section loaded: fwpuclnt.dll |
Jump to behavior |
Source: C:\Users\user\Desktop\31-o_Installer.exe |
Section loaded: mscoree.dll |
Jump to behavior |
Source: C:\Users\user\Desktop\31-o_Installer.exe |
Section loaded: amsi.dll |
Jump to behavior |
Source: C:\Users\user\Desktop\31-o_Installer.exe |
Section loaded: vcruntime140_clr0400.dll |
Jump to behavior |
Source: C:\Users\user\Desktop\31-o_Installer.exe |
Section loaded: ucrtbase_clr0400.dll |
Jump to behavior |
Source: C:\Users\user\Desktop\31-o_Installer.exe |
Section loaded: cryptsp.dll |
Jump to behavior |
Source: C:\Users\user\Desktop\31-o_Installer.exe |
Section loaded: rsaenh.dll |
Jump to behavior |
Source: C:\Users\user\Desktop\31-o_Installer.exe |
Section loaded: cryptbase.dll |
Jump to behavior |
Source: C:\Users\user\Desktop\31-o_Installer.exe |
Section loaded: userenv.dll |
Jump to behavior |
Source: C:\Users\user\Desktop\31-o_Installer.exe |
Section loaded: version.dll |
Jump to behavior |
Source: C:\Users\user\Desktop\31-o_Installer.exe |
Section loaded: wbemcomn.dll |
Jump to behavior |
Source: C:\Users\user\Desktop\31-o_Installer.exe |
Section loaded: avicap32.dll |
Jump to behavior |
Source: C:\Users\user\Desktop\31-o_Installer.exe |
Section loaded: msvfw32.dll |
Jump to behavior |
Source: C:\Users\user\Desktop\31-o_Installer.exe |
Section loaded: winmm.dll |
Jump to behavior |
Source: 31-o_Installer.exe |
Static PE information: Data directory: IMAGE_DIRECTORY_ENTRY_IMPORT is in: .rdata |
Source: 31-o_Installer.exe |
Static PE information: Data directory: IMAGE_DIRECTORY_ENTRY_RESOURCE is in: .rsrc |
Source: 31-o_Installer.exe |
Static PE information: Data directory: IMAGE_DIRECTORY_ENTRY_BASERELOC is in: .reloc |
Source: 31-o_Installer.exe |
Static PE information: Data directory: IMAGE_DIRECTORY_ENTRY_LOAD_CONFIG is in: .rdata |
Source: 31-o_Installer.exe |
Static PE information: Data directory: IMAGE_DIRECTORY_ENTRY_IAT is in: .rdata |
Source: 0.2.31-o_Installer.exe.5320000.1.raw.unpack, Messages.cs |
.Net Code: NewLateBinding.LateCall(obj, (Type)null, "Invoke", new object[2]{null,new object[5]{Settings.Host,Settings.Port,Settings.SPL,Settings.KEY,Helper.ID()}}, (string[])null, (Type[])null, (bool[])null, true) |
Source: 0.2.31-o_Installer.exe.5320000.1.raw.unpack, Messages.cs |
.Net Code: NewLateBinding.LateCall(obj, (Type)null, "Invoke", new object[2]{null,new object[2]{Pack[2],Helper.Decompress(Convert.FromBase64String(Pack[3]))}}, (string[])null, (Type[])null, (bool[])null, true) |
Source: C:\Users\user\Desktop\31-o_Installer.exe |
Code function: 0_2_002740E4 LoadLibraryW,GetProcAddress,GetProcAddress,EncodePointer,EncodePointer,GetProcAddress,EncodePointer,GetProcAddress,EncodePointer,GetProcAddress,EncodePointer,GetProcAddress,EncodePointer,DecodePointer,DecodePointer,DecodePointer,DecodePointer,DecodePointer,DecodePointer, |
0_2_002740E4 |
Source: C:\Users\user\Desktop\31-o_Installer.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\Desktop\31-o_Installer.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\Desktop\31-o_Installer.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\Desktop\31-o_Installer.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\Desktop\31-o_Installer.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\Desktop\31-o_Installer.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\Desktop\31-o_Installer.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\Desktop\31-o_Installer.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\Desktop\31-o_Installer.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\Desktop\31-o_Installer.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\Desktop\31-o_Installer.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\Desktop\31-o_Installer.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\Desktop\31-o_Installer.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\Desktop\31-o_Installer.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\Desktop\31-o_Installer.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\Desktop\31-o_Installer.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\Desktop\31-o_Installer.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\Desktop\31-o_Installer.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\Desktop\31-o_Installer.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\Desktop\31-o_Installer.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\Desktop\31-o_Installer.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\Desktop\31-o_Installer.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\Desktop\31-o_Installer.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\Desktop\31-o_Installer.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\Desktop\31-o_Installer.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\Desktop\31-o_Installer.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\Desktop\31-o_Installer.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\Desktop\31-o_Installer.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\Desktop\31-o_Installer.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\Desktop\31-o_Installer.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\Desktop\31-o_Installer.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\Desktop\31-o_Installer.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\Desktop\31-o_Installer.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\Desktop\31-o_Installer.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\Desktop\31-o_Installer.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\Desktop\31-o_Installer.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\Desktop\31-o_Installer.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\Desktop\31-o_Installer.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\Desktop\31-o_Installer.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\Desktop\31-o_Installer.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\Desktop\31-o_Installer.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\Desktop\31-o_Installer.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\Desktop\31-o_Installer.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\Desktop\31-o_Installer.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\Desktop\31-o_Installer.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\Desktop\31-o_Installer.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\Desktop\31-o_Installer.exe |
Code function: 0_2_002740E4 LoadLibraryW,GetProcAddress,GetProcAddress,EncodePointer,EncodePointer,GetProcAddress,EncodePointer,GetProcAddress,EncodePointer,GetProcAddress,EncodePointer,GetProcAddress,EncodePointer,DecodePointer,DecodePointer,DecodePointer,DecodePointer,DecodePointer,DecodePointer, |
0_2_002740E4 |
Source: C:\Users\user\Desktop\31-o_Installer.exe |
Code function: ___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo, |
0_2_0026E04E |
Source: C:\Users\user\Desktop\31-o_Installer.exe |
Code function: GetLocaleInfoA, |
0_2_00274859 |
Source: C:\Users\user\Desktop\31-o_Installer.exe |
Code function: __getptd,_LcidFromHexString,GetLocaleInfoA,_TestDefaultLanguage, |
0_2_0026F895 |
Source: C:\Users\user\Desktop\31-o_Installer.exe |
Code function: _strlen,_strlen,_GetPrimaryLen,EnumSystemLocalesA, |
0_2_0026F955 |
Source: C:\Users\user\Desktop\31-o_Installer.exe |
Code function: _strlen,_GetPrimaryLen,EnumSystemLocalesA, |
0_2_0026F9BC |
Source: C:\Users\user\Desktop\31-o_Installer.exe |
Code function: __getptd,_TranslateName,_GetLcidFromLangCountry,_GetLcidFromLanguage,_TranslateName,_GetLcidFromLangCountry,_GetLcidFromLanguage,_strlen,EnumSystemLocalesA,GetUserDefaultLCID,IsValidCodePage,IsValidLocale,GetLocaleInfoA,_strcpy_s,__invoke_watson,GetLocaleInfoA,GetLocaleInfoA,__itow_s, |
0_2_0026F9F8 |
Source: C:\Users\user\Desktop\31-o_Installer.exe |
Code function: ___crtGetLocaleInfoA,GetLastError,___crtGetLocaleInfoA,__calloc_crt,___crtGetLocaleInfoA,__calloc_crt,_free,_free,__invoke_watson,GetLocaleInfoW,GetLocaleInfoW,__calloc_crt,GetLocaleInfoW,_free,GetLocaleInfoW, |
0_2_0026DC2B |
Source: C:\Users\user\Desktop\31-o_Installer.exe |
Code function: __calloc_crt,__malloc_crt,_free,__malloc_crt,_free,_free,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___free_lconv_num,InterlockedDecrement,InterlockedDecrement,InterlockedDecrement,_free,_free, |
0_2_0026ECAA |
Source: C:\Users\user\Desktop\31-o_Installer.exe |
Code function: GetLocaleInfoW,GetLocaleInfoW,_malloc,GetLocaleInfoW,WideCharToMultiByte,__freea, |
0_2_002744BA |
Source: C:\Users\user\Desktop\31-o_Installer.exe |
Code function: GetLocaleInfoW,GetLocaleInfoW,GetACP, |
0_2_0026F4CD |
Source: C:\Users\user\Desktop\31-o_Installer.exe |
Code function: _LocaleUpdate::_LocaleUpdate,__crtGetLocaleInfoA_stat, |
0_2_00274594 |
Source: C:\Users\user\Desktop\31-o_Installer.exe |
Code function: __getptd,_LcidFromHexString,GetLocaleInfoA, |
0_2_0026F5C2 |
Source: C:\Users\user\Desktop\31-o_Installer.exe |
Code function: GetLocaleInfoW,_GetPrimaryLen,_strlen, |
0_2_0026F669 |
Source: C:\Users\user\Desktop\31-o_Installer.exe |
Code function: __getptd,_LcidFromHexString,GetLocaleInfoA,GetLocaleInfoA,GetLocaleInfoA,_strlen,GetLocaleInfoA,_strlen,_TestDefaultLanguage, |
0_2_0026F6C4 |
Source: C:\Users\user\Desktop\31-o_Installer.exe |
Code function: __calloc_crt,__malloc_crt,_free,__malloc_crt,_free,_free,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___free_lconv_mon,_free,_free,_free,InterlockedDecrement,InterlockedDecrement,_free,_free, |
0_2_0026EF98 |
Source: C:\Users\user\Desktop\31-o_Installer.exe |
Code function: ___getlocaleinfo,__malloc_crt,__calloc_crt,__calloc_crt,__calloc_crt,__calloc_crt,GetCPInfo,___crtGetStringTypeA,___crtLCMapStringA,___crtLCMapStringA,_memmove,_memmove,_memmove,InterlockedDecrement,_free,_free,_free,_free,_free,_free,_free,_free,_free,InterlockedDecrement, |
0_2_00265FC5 |