Source: InstallUtil.exe, 00000003.00000002.3286541234.0000000002E21000.00000004.00000800.00020000.00000000.sdmp | String found in binary or memory: http://ip-api.com |
Source: okmnji.exe, 00000000.00000002.2534480616.0000000003BF1000.00000004.00000800.00020000.00000000.sdmp, okmnji.exe, 00000000.00000002.2534480616.0000000003DC8000.00000004.00000800.00020000.00000000.sdmp, InstallUtil.exe, 00000003.00000002.3285107224.00000000011DF000.00000004.00000020.00020000.00000000.sdmp, InstallUtil.exe, 00000003.00000002.3283492117.0000000000402000.00000040.00000400.00020000.00000000.sdmp, InstallUtil.exe, 00000003.00000002.3286541234.0000000002E21000.00000004.00000800.00020000.00000000.sdmp | String found in binary or memory: http://ip-api.com/line/?fields=hosting |
Source: InstallUtil.exe, 00000003.00000002.3285107224.00000000011DF000.00000004.00000020.00020000.00000000.sdmp | String found in binary or memory: http://ip-api.com/line/?fields=hostingCY |
Source: InstallUtil.exe, 00000003.00000002.3286541234.0000000002E84000.00000004.00000800.00020000.00000000.sdmp | String found in binary or memory: http://mail.kannides.com |
Source: okmnji.exe, 00000000.00000002.2542221820.00000000069B4000.00000004.00000020.00020000.00000000.sdmp | String found in binary or memory: http://purl.oen |
Source: InstallUtil.exe, 00000003.00000002.3286541234.0000000002E84000.00000004.00000800.00020000.00000000.sdmp, InstallUtil.exe, 00000003.00000002.3290939687.000000000611F000.00000004.00000020.00020000.00000000.sdmp | String found in binary or memory: http://r11.i.lencr.org/0 |
Source: InstallUtil.exe, 00000003.00000002.3286541234.0000000002E84000.00000004.00000800.00020000.00000000.sdmp, InstallUtil.exe, 00000003.00000002.3290939687.000000000611F000.00000004.00000020.00020000.00000000.sdmp | String found in binary or memory: http://r11.o.lencr.org0# |
Source: okmnji.exe, 00000000.00000002.2526763060.0000000002BF1000.00000004.00000800.00020000.00000000.sdmp, InstallUtil.exe, 00000003.00000002.3286541234.0000000002E21000.00000004.00000800.00020000.00000000.sdmp | String found in binary or memory: http://schemas.xmlsoap.org/ws/2005/05/identity/claims/name |
Source: okmnji.exe | String found in binary or memory: http://www.google.com |
Source: okmnji.exe, 00000000.00000002.2526763060.0000000002BF1000.00000004.00000800.00020000.00000000.sdmp | String found in binary or memory: http://www.google.com/ |
Source: InstallUtil.exe, 00000003.00000002.3286541234.0000000002E84000.00000004.00000800.00020000.00000000.sdmp, InstallUtil.exe, 00000003.00000002.3290939687.000000000611F000.00000004.00000020.00020000.00000000.sdmp | String found in binary or memory: http://x1.c.lencr.org/0 |
Source: InstallUtil.exe, 00000003.00000002.3286541234.0000000002E84000.00000004.00000800.00020000.00000000.sdmp, InstallUtil.exe, 00000003.00000002.3290939687.000000000611F000.00000004.00000020.00020000.00000000.sdmp | String found in binary or memory: http://x1.i.lencr.org/0 |
Source: okmnji.exe, 00000000.00000002.2534480616.0000000003BF1000.00000004.00000800.00020000.00000000.sdmp, okmnji.exe, 00000000.00000002.2534480616.0000000003DC8000.00000004.00000800.00020000.00000000.sdmp, InstallUtil.exe, 00000003.00000002.3283492117.0000000000402000.00000040.00000400.00020000.00000000.sdmp | String found in binary or memory: https://account.dyn.com/ |
Source: okmnji.exe, 00000000.00000002.2526763060.0000000002C1E000.00000004.00000800.00020000.00000000.sdmp | String found in binary or memory: https://csp.withgoogle.com/csp/gws/other-hp |
Source: 0.2.okmnji.exe.3ed6072.2.unpack, type: UNPACKEDPE | Matched rule: Detects executables referencing Windows vault credential objects. Observed in infostealers Author: ditekSHen |
Source: 3.2.InstallUtil.exe.400000.0.unpack, type: UNPACKEDPE | Matched rule: Detects executables referencing Windows vault credential objects. Observed in infostealers Author: ditekSHen |
Source: 0.2.okmnji.exe.3c34e20.1.unpack, type: UNPACKEDPE | Matched rule: Detects executables referencing Windows vault credential objects. Observed in infostealers Author: ditekSHen |
Source: 0.2.okmnji.exe.3c34e20.1.raw.unpack, type: UNPACKEDPE | Matched rule: Detects executables referencing Windows vault credential objects. Observed in infostealers Author: ditekSHen |
Source: 0.2.okmnji.exe.3e9a7a2.4.unpack, type: UNPACKEDPE | Matched rule: Detects executables referencing Windows vault credential objects. Observed in infostealers Author: ditekSHen |
Source: 0.2.okmnji.exe.3e5eec2.3.unpack, type: UNPACKEDPE | Matched rule: Detects executables referencing Windows vault credential objects. Observed in infostealers Author: ditekSHen |
Source: 0.2.okmnji.exe.3ed6072.2.raw.unpack, type: UNPACKEDPE | Matched rule: Detects executables referencing Windows vault credential objects. Observed in infostealers Author: ditekSHen |
Source: 0.2.okmnji.exe.3e9a7a2.4.raw.unpack, type: UNPACKEDPE | Matched rule: Detects executables referencing Windows vault credential objects. Observed in infostealers Author: ditekSHen |
Source: 0.2.okmnji.exe.3e5eec2.3.raw.unpack, type: UNPACKEDPE | Matched rule: Detects executables referencing Windows vault credential objects. Observed in infostealers Author: ditekSHen |
Source: C:\Users\user\Desktop\okmnji.exe | Code function: 0_2_010E4769 | 0_2_010E4769 |
Source: C:\Users\user\Desktop\okmnji.exe | Code function: 0_2_010E8819 | 0_2_010E8819 |
Source: C:\Users\user\Desktop\okmnji.exe | Code function: 0_2_010EAEC0 | 0_2_010EAEC0 |
Source: C:\Users\user\Desktop\okmnji.exe | Code function: 0_2_010E7AD8 | 0_2_010E7AD8 |
Source: C:\Users\user\Desktop\okmnji.exe | Code function: 0_2_065C10AC | 0_2_065C10AC |
Source: C:\Users\user\Desktop\okmnji.exe | Code function: 0_2_065CD498 | 0_2_065CD498 |
Source: C:\Users\user\Desktop\okmnji.exe | Code function: 0_2_065CD4A8 | 0_2_065CD4A8 |
Source: C:\Users\user\Desktop\okmnji.exe | Code function: 0_2_065CAB24 | 0_2_065CAB24 |
Source: C:\Users\user\Desktop\okmnji.exe | Code function: 0_2_0696A6B0 | 0_2_0696A6B0 |
Source: C:\Users\user\Desktop\okmnji.exe | Code function: 0_2_06962388 | 0_2_06962388 |
Source: C:\Users\user\Desktop\okmnji.exe | Code function: 0_2_0696C2B0 | 0_2_0696C2B0 |
Source: C:\Users\user\Desktop\okmnji.exe | Code function: 0_2_06962362 | 0_2_06962362 |
Source: C:\Users\user\Desktop\okmnji.exe | Code function: 0_2_07C0B13E | 0_2_07C0B13E |
Source: C:\Users\user\Desktop\okmnji.exe | Code function: 0_2_07C01408 | 0_2_07C01408 |
Source: C:\Users\user\Desktop\okmnji.exe | Code function: 0_2_07C0C6D1 | 0_2_07C0C6D1 |
Source: C:\Users\user\Desktop\okmnji.exe | Code function: 0_2_07C0C6E0 | 0_2_07C0C6E0 |
Source: C:\Users\user\Desktop\okmnji.exe | Code function: 0_2_07C61140 | 0_2_07C61140 |
Source: C:\Users\user\Desktop\okmnji.exe | Code function: 0_2_07C6EC2D | 0_2_07C6EC2D |
Source: C:\Users\user\Desktop\okmnji.exe | Code function: 0_2_085EC410 | 0_2_085EC410 |
Source: C:\Users\user\Desktop\okmnji.exe | Code function: 0_2_085EA408 | 0_2_085EA408 |
Source: C:\Users\user\Desktop\okmnji.exe | Code function: 0_2_085EB500 | 0_2_085EB500 |
Source: C:\Users\user\Desktop\okmnji.exe | Code function: 0_2_085EAB30 | 0_2_085EAB30 |
Source: C:\Users\user\Desktop\okmnji.exe | Code function: 0_2_085E87F8 | 0_2_085E87F8 |
Source: C:\Users\user\Desktop\okmnji.exe | Code function: 0_2_085EE510 | 0_2_085EE510 |
Source: C:\Users\user\Desktop\okmnji.exe | Code function: 0_2_085EE520 | 0_2_085EE520 |
Source: C:\Users\user\Desktop\okmnji.exe | Code function: 0_2_085EE1A1 | 0_2_085EE1A1 |
Source: C:\Users\user\Desktop\okmnji.exe | Code function: 0_2_085ED2B8 | 0_2_085ED2B8 |
Source: C:\Users\user\Desktop\okmnji.exe | Code function: 0_2_085EDEB0 | 0_2_085EDEB0 |
Source: C:\Users\user\Desktop\okmnji.exe | Code function: 0_2_085ED2A9 | 0_2_085ED2A9 |
Source: C:\Users\user\Desktop\okmnji.exe | Code function: 0_2_085EDEA0 | 0_2_085EDEA0 |
Source: C:\Users\user\Desktop\okmnji.exe | Code function: 0_2_085EE758 | 0_2_085EE758 |
Source: C:\Users\user\Desktop\okmnji.exe | Code function: 0_2_085EA350 | 0_2_085EA350 |
Source: C:\Users\user\Desktop\okmnji.exe | Code function: 0_2_085EE749 | 0_2_085EE749 |
Source: C:\Users\user\Desktop\okmnji.exe | Code function: 0_2_085EEB7A | 0_2_085EEB7A |
Source: C:\Users\user\Desktop\okmnji.exe | Code function: 0_2_085E97C8 | 0_2_085E97C8 |
Source: C:\Users\user\Desktop\okmnji.exe | Code function: 0_2_085EC39A | 0_2_085EC39A |
Source: C:\Users\user\Desktop\okmnji.exe | Code function: 0_2_0DCF28E0 | 0_2_0DCF28E0 |
Source: C:\Users\user\Desktop\okmnji.exe | Code function: 0_2_0DCF4048 | 0_2_0DCF4048 |
Source: C:\Users\user\Desktop\okmnji.exe | Code function: 0_2_0DCF4BA0 | 0_2_0DCF4BA0 |
Source: C:\Users\user\Desktop\okmnji.exe | Code function: 0_2_0DCF4280 | 0_2_0DCF4280 |
Source: C:\Users\user\Desktop\okmnji.exe | Code function: 0_2_0DCFA248 | 0_2_0DCFA248 |
Source: C:\Users\user\Desktop\okmnji.exe | Code function: 0_2_0DCF85E0 | 0_2_0DCF85E0 |
Source: C:\Users\user\Desktop\okmnji.exe | Code function: 0_2_0DCF68D8 | 0_2_0DCF68D8 |
Source: C:\Users\user\Desktop\okmnji.exe | Code function: 0_2_0DCF28D2 | 0_2_0DCF28D2 |
Source: C:\Users\user\Desktop\okmnji.exe | Code function: 0_2_0DCF68E8 | 0_2_0DCF68E8 |
Source: C:\Users\user\Desktop\okmnji.exe | Code function: 0_2_0DCF80A9 | 0_2_0DCF80A9 |
Source: C:\Users\user\Desktop\okmnji.exe | Code function: 0_2_0DCFE0A8 | 0_2_0DCFE0A8 |
Source: C:\Users\user\Desktop\okmnji.exe | Code function: 0_2_0DCF0040 | 0_2_0DCF0040 |
Source: C:\Users\user\Desktop\okmnji.exe | Code function: 0_2_0DCF3878 | 0_2_0DCF3878 |
Source: C:\Users\user\Desktop\okmnji.exe | Code function: 0_2_0DCF0023 | 0_2_0DCF0023 |
Source: C:\Users\user\Desktop\okmnji.exe | Code function: 0_2_0DCF4038 | 0_2_0DCF4038 |
Source: C:\Users\user\Desktop\okmnji.exe | Code function: 0_2_0DCF2B80 | 0_2_0DCF2B80 |
Source: C:\Users\user\Desktop\okmnji.exe | Code function: 0_2_0DCF2B70 | 0_2_0DCF2B70 |
Source: C:\Users\user\Desktop\okmnji.exe | Code function: 0_2_0DCFEF28 | 0_2_0DCFEF28 |
Source: C:\Users\user\Desktop\okmnji.exe | Code function: 0_2_0DCF7EA1 | 0_2_0DCF7EA1 |
Source: C:\Users\user\Desktop\okmnji.exe | Code function: 0_2_0DCF7EB0 | 0_2_0DCF7EB0 |
Source: C:\Users\user\Desktop\okmnji.exe | Code function: 0_2_0DCF4270 | 0_2_0DCF4270 |
Source: C:\Users\user\Desktop\okmnji.exe | Code function: 0_2_0DCF3200 | 0_2_0DCF3200 |
Source: C:\Users\user\Desktop\okmnji.exe | Code function: 0_2_0DCF3210 | 0_2_0DCF3210 |
Source: C:\Users\user\Desktop\okmnji.exe | Code function: 0_2_07C61127 | 0_2_07C61127 |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\InstallUtil.exe | Code function: 3_2_013CB374 | 3_2_013CB374 |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\InstallUtil.exe | Code function: 3_2_013C4AC0 | 3_2_013C4AC0 |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\InstallUtil.exe | Code function: 3_2_013CAD08 | 3_2_013CAD08 |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\InstallUtil.exe | Code function: 3_2_013CEC10 | 3_2_013CEC10 |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\InstallUtil.exe | Code function: 3_2_013C3EA8 | 3_2_013C3EA8 |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\InstallUtil.exe | Code function: 3_2_013C41F0 | 3_2_013C41F0 |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\InstallUtil.exe | Code function: 3_2_066FC080 | 3_2_066FC080 |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\InstallUtil.exe | Code function: 3_2_066FAA5C | 3_2_066FAA5C |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\InstallUtil.exe | Code function: 3_2_067165C0 | 3_2_067165C0 |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\InstallUtil.exe | Code function: 3_2_0671B200 | 3_2_0671B200 |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\InstallUtil.exe | Code function: 3_2_06715170 | 3_2_06715170 |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\InstallUtil.exe | Code function: 3_2_06717D48 | 3_2_06717D48 |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\InstallUtil.exe | Code function: 3_2_06712AB8 | 3_2_06712AB8 |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\InstallUtil.exe | Code function: 3_2_06717668 | 3_2_06717668 |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\InstallUtil.exe | Code function: 3_2_0671E378 | 3_2_0671E378 |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\InstallUtil.exe | Code function: 3_2_06710040 | 3_2_06710040 |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\InstallUtil.exe | Code function: 3_2_067158C0 | 3_2_067158C0 |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\InstallUtil.exe | Code function: 3_2_06710038 | 3_2_06710038 |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\InstallUtil.exe | Code function: 3_2_06710007 | 3_2_06710007 |
Source: 0.2.okmnji.exe.3ed6072.2.unpack, type: UNPACKEDPE | Matched rule: INDICATOR_SUSPICIOUS_EXE_VaultSchemaGUID author = ditekSHen, description = Detects executables referencing Windows vault credential objects. Observed in infostealers |
Source: 3.2.InstallUtil.exe.400000.0.unpack, type: UNPACKEDPE | Matched rule: INDICATOR_SUSPICIOUS_EXE_VaultSchemaGUID author = ditekSHen, description = Detects executables referencing Windows vault credential objects. Observed in infostealers |
Source: 0.2.okmnji.exe.3c34e20.1.unpack, type: UNPACKEDPE | Matched rule: INDICATOR_SUSPICIOUS_EXE_VaultSchemaGUID author = ditekSHen, description = Detects executables referencing Windows vault credential objects. Observed in infostealers |
Source: 0.2.okmnji.exe.3c34e20.1.raw.unpack, type: UNPACKEDPE | Matched rule: INDICATOR_SUSPICIOUS_EXE_VaultSchemaGUID author = ditekSHen, description = Detects executables referencing Windows vault credential objects. Observed in infostealers |
Source: 0.2.okmnji.exe.3e9a7a2.4.unpack, type: UNPACKEDPE | Matched rule: INDICATOR_SUSPICIOUS_EXE_VaultSchemaGUID author = ditekSHen, description = Detects executables referencing Windows vault credential objects. Observed in infostealers |
Source: 0.2.okmnji.exe.3e5eec2.3.unpack, type: UNPACKEDPE | Matched rule: INDICATOR_SUSPICIOUS_EXE_VaultSchemaGUID author = ditekSHen, description = Detects executables referencing Windows vault credential objects. Observed in infostealers |
Source: 0.2.okmnji.exe.3ed6072.2.raw.unpack, type: UNPACKEDPE | Matched rule: INDICATOR_SUSPICIOUS_EXE_VaultSchemaGUID author = ditekSHen, description = Detects executables referencing Windows vault credential objects. Observed in infostealers |
Source: 0.2.okmnji.exe.3e9a7a2.4.raw.unpack, type: UNPACKEDPE | Matched rule: INDICATOR_SUSPICIOUS_EXE_VaultSchemaGUID author = ditekSHen, description = Detects executables referencing Windows vault credential objects. Observed in infostealers |
Source: 0.2.okmnji.exe.3e5eec2.3.raw.unpack, type: UNPACKEDPE | Matched rule: INDICATOR_SUSPICIOUS_EXE_VaultSchemaGUID author = ditekSHen, description = Detects executables referencing Windows vault credential objects. Observed in infostealers |
Source: 0.2.okmnji.exe.3c34e20.1.raw.unpack, v9Lsz.cs | Cryptographic APIs: 'TransformFinalBlock' |
Source: 0.2.okmnji.exe.3c34e20.1.raw.unpack, VFo.cs | Cryptographic APIs: 'TransformFinalBlock' |
Source: 0.2.okmnji.exe.3c34e20.1.raw.unpack, 5FJ0H20tobu.cs | Cryptographic APIs: 'TransformFinalBlock' |
Source: 0.2.okmnji.exe.3c34e20.1.raw.unpack, NtdoTGO.cs | Cryptographic APIs: 'TransformFinalBlock' |
Source: 0.2.okmnji.exe.3c34e20.1.raw.unpack, XBsYgp.cs | Cryptographic APIs: 'CreateDecryptor', 'TransformBlock' |
Source: 0.2.okmnji.exe.3c34e20.1.raw.unpack, AwxUa2Na.cs | Cryptographic APIs: 'CreateDecryptor' |
Source: 0.2.okmnji.exe.3c34e20.1.raw.unpack, 19C9FfZ.cs | Cryptographic APIs: 'TransformFinalBlock' |
Source: 0.2.okmnji.exe.3c34e20.1.raw.unpack, 19C9FfZ.cs | Cryptographic APIs: 'TransformFinalBlock', 'CreateDecryptor' |
Source: 0.2.okmnji.exe.3c34e20.1.raw.unpack, soCD8XkwU.cs | Cryptographic APIs: 'TransformFinalBlock' |
Source: 0.2.okmnji.exe.3c34e20.1.raw.unpack, soCD8XkwU.cs | Cryptographic APIs: 'TransformFinalBlock' |
Source: C:\Users\user\Desktop\okmnji.exe | Section loaded: mscoree.dll | Jump to behavior |
Source: C:\Users\user\Desktop\okmnji.exe | Section loaded: apphelp.dll | Jump to behavior |
Source: C:\Users\user\Desktop\okmnji.exe | Section loaded: kernel.appcore.dll | Jump to behavior |
Source: C:\Users\user\Desktop\okmnji.exe | Section loaded: version.dll | Jump to behavior |
Source: C:\Users\user\Desktop\okmnji.exe | Section loaded: vcruntime140_clr0400.dll | Jump to behavior |
Source: C:\Users\user\Desktop\okmnji.exe | Section loaded: ucrtbase_clr0400.dll | Jump to behavior |
Source: C:\Users\user\Desktop\okmnji.exe | Section loaded: ucrtbase_clr0400.dll | Jump to behavior |
Source: C:\Users\user\Desktop\okmnji.exe | Section loaded: uxtheme.dll | Jump to behavior |
Source: C:\Users\user\Desktop\okmnji.exe | Section loaded: windows.storage.dll | Jump to behavior |
Source: C:\Users\user\Desktop\okmnji.exe | Section loaded: wldp.dll | Jump to behavior |
Source: C:\Users\user\Desktop\okmnji.exe | Section loaded: profapi.dll | Jump to behavior |
Source: C:\Users\user\Desktop\okmnji.exe | Section loaded: cryptsp.dll | Jump to behavior |
Source: C:\Users\user\Desktop\okmnji.exe | Section loaded: rsaenh.dll | Jump to behavior |
Source: C:\Users\user\Desktop\okmnji.exe | Section loaded: cryptbase.dll | Jump to behavior |
Source: C:\Users\user\Desktop\okmnji.exe | Section loaded: rasapi32.dll | Jump to behavior |
Source: C:\Users\user\Desktop\okmnji.exe | Section loaded: rasman.dll | Jump to behavior |
Source: C:\Users\user\Desktop\okmnji.exe | Section loaded: rtutils.dll | Jump to behavior |
Source: C:\Users\user\Desktop\okmnji.exe | Section loaded: mswsock.dll | Jump to behavior |
Source: C:\Users\user\Desktop\okmnji.exe | Section loaded: winhttp.dll | Jump to behavior |
Source: C:\Users\user\Desktop\okmnji.exe | Section loaded: ondemandconnroutehelper.dll | Jump to behavior |
Source: C:\Users\user\Desktop\okmnji.exe | Section loaded: iphlpapi.dll | Jump to behavior |
Source: C:\Users\user\Desktop\okmnji.exe | Section loaded: dhcpcsvc6.dll | Jump to behavior |
Source: C:\Users\user\Desktop\okmnji.exe | Section loaded: dhcpcsvc.dll | Jump to behavior |
Source: C:\Users\user\Desktop\okmnji.exe | Section loaded: dnsapi.dll | Jump to behavior |
Source: C:\Users\user\Desktop\okmnji.exe | Section loaded: winnsi.dll | Jump to behavior |
Source: C:\Users\user\Desktop\okmnji.exe | Section loaded: rasadhlp.dll | Jump to behavior |
Source: C:\Users\user\Desktop\okmnji.exe | Section loaded: fwpuclnt.dll | Jump to behavior |
Source: C:\Users\user\Desktop\okmnji.exe | Section loaded: amsi.dll | Jump to behavior |
Source: C:\Users\user\Desktop\okmnji.exe | Section loaded: userenv.dll | Jump to behavior |
Source: C:\Users\user\Desktop\okmnji.exe | Section loaded: msasn1.dll | Jump to behavior |
Source: C:\Users\user\Desktop\okmnji.exe | Section loaded: gpapi.dll | Jump to behavior |
Source: C:\Users\user\Desktop\okmnji.exe | Section loaded: dwrite.dll | Jump to behavior |
Source: C:\Users\user\Desktop\okmnji.exe | Section loaded: windowscodecs.dll | Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\InstallUtil.exe | Section loaded: mscoree.dll | Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\InstallUtil.exe | Section loaded: kernel.appcore.dll | Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\InstallUtil.exe | Section loaded: version.dll | Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\InstallUtil.exe | Section loaded: vcruntime140_clr0400.dll | Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\InstallUtil.exe | Section loaded: ucrtbase_clr0400.dll | Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\InstallUtil.exe | Section loaded: ucrtbase_clr0400.dll | Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\InstallUtil.exe | Section loaded: uxtheme.dll | Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\InstallUtil.exe | Section loaded: windows.storage.dll | Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\InstallUtil.exe | Section loaded: wldp.dll | Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\InstallUtil.exe | Section loaded: profapi.dll | Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\InstallUtil.exe | Section loaded: cryptsp.dll | Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\InstallUtil.exe | Section loaded: rsaenh.dll | Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\InstallUtil.exe | Section loaded: cryptbase.dll | Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\InstallUtil.exe | Section loaded: wbemcomn.dll | Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\InstallUtil.exe | Section loaded: amsi.dll | Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\InstallUtil.exe | Section loaded: userenv.dll | Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\InstallUtil.exe | Section loaded: sspicli.dll | Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\InstallUtil.exe | Section loaded: rasapi32.dll | Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\InstallUtil.exe | Section loaded: rasman.dll | Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\InstallUtil.exe | Section loaded: rtutils.dll | Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\InstallUtil.exe | Section loaded: mswsock.dll | Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\InstallUtil.exe | Section loaded: winhttp.dll | Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\InstallUtil.exe | Section loaded: ondemandconnroutehelper.dll | Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\InstallUtil.exe | Section loaded: iphlpapi.dll | Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\InstallUtil.exe | Section loaded: dhcpcsvc6.dll | Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\InstallUtil.exe | Section loaded: dhcpcsvc.dll | Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\InstallUtil.exe | Section loaded: dnsapi.dll | Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\InstallUtil.exe | Section loaded: winnsi.dll | Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\InstallUtil.exe | Section loaded: rasadhlp.dll | Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\InstallUtil.exe | Section loaded: fwpuclnt.dll | Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\InstallUtil.exe | Section loaded: vaultcli.dll | Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\InstallUtil.exe | Section loaded: wintypes.dll | Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\InstallUtil.exe | Section loaded: secur32.dll | Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\InstallUtil.exe | Section loaded: schannel.dll | Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\InstallUtil.exe | Section loaded: mskeyprotect.dll | Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\InstallUtil.exe | Section loaded: ntasn1.dll | Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\InstallUtil.exe | Section loaded: ncrypt.dll | Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\InstallUtil.exe | Section loaded: ncryptsslp.dll | Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\InstallUtil.exe | Section loaded: msasn1.dll | Jump to behavior |
Source: C:\Users\user\Desktop\okmnji.exe | Code function: 0_2_010EB0B0 push 0402BBC1h; ret | 0_2_010EB145 |
Source: C:\Users\user\Desktop\okmnji.exe | Code function: 0_2_010EB3A8 push eax; iretd | 0_2_010EB3B9 |
Source: C:\Users\user\Desktop\okmnji.exe | Code function: 0_2_06966320 push esp; retf | 0_2_06966321 |
Source: C:\Users\user\Desktop\okmnji.exe | Code function: 0_2_06966960 push eax; iretd | 0_2_06966961 |
Source: C:\Users\user\Desktop\okmnji.exe | Code function: 0_2_07C08B9E push FFFFFF8Bh; iretd | 0_2_07C08BA3 |
Source: C:\Users\user\Desktop\okmnji.exe | Code function: 0_2_07C6AB18 pushfd ; ret | 0_2_07C6B181 |
Source: C:\Users\user\Desktop\okmnji.exe | Code function: 0_2_07C6B0B4 pushfd ; ret | 0_2_07C6B181 |
Source: C:\Users\user\Desktop\okmnji.exe | Code function: 0_2_07C600BE push esp; retf | 0_2_07C600C1 |
Source: C:\Users\user\Desktop\okmnji.exe | Code function: 0_2_085E44DF push es; ret | 0_2_085E44F0 |
Source: C:\Users\user\Desktop\okmnji.exe | Code function: 0_2_085E73DA push 0000003Bh; ret | 0_2_085E73DF |
Source: C:\Users\user\Desktop\okmnji.exe | Code function: 0_2_085E73FC push 0000003Bh; ret | 0_2_085E740D |
Source: C:\Users\user\Desktop\okmnji.exe | Code function: 0_2_0DCF2547 push es; iretd | 0_2_0DCF254E |
Source: C:\Users\user\Desktop\okmnji.exe | Code function: 0_2_0DCF2487 push ss; iretd | 0_2_0DCF248E |
Source: C:\Users\user\Desktop\okmnji.exe | Code function: 0_2_0DCF2443 push ds; iretd | 0_2_0DCF2472 |
Source: C:\Users\user\Desktop\okmnji.exe | Code function: 0_2_0DCF686D push edx; iretd | 0_2_0DCF686E |
Source: C:\Users\user\Desktop\okmnji.exe | Code function: 0_2_0DCF6807 push edi; iretd | 0_2_0DCF680E |
Source: C:\Users\user\Desktop\okmnji.exe | Code function: 0_2_0DCF2427 push ss; iretd | 0_2_0DCF243A |
Source: C:\Users\user\Desktop\okmnji.exe | Code function: 0_2_0DCF67C3 push ebp; iretd | 0_2_0DCF67D6 |
Source: C:\Users\user\Desktop\okmnji.exe | Code function: 0_2_0DCF67EF push esp; iretd | 0_2_0DCF67F6 |
Source: C:\Users\user\Desktop\okmnji.exe | Code function: 0_2_0DCF67E7 push ebp; iretd | 0_2_0DCF67EE |
Source: C:\Users\user\Desktop\okmnji.exe | Code function: 0_2_0DCF67FF push esi; iretd | 0_2_0DCF6806 |
Source: C:\Users\user\Desktop\okmnji.exe | Code function: 0_2_0DCF678F push ebx; iretd | 0_2_0DCF67A2 |
Source: C:\Users\user\Desktop\okmnji.exe | Code function: 0_2_0DCF67BB push ebp; iretd | 0_2_0DCF67C2 |
Source: C:\Users\user\Desktop\okmnji.exe | Code function: 0_2_0DCF675B push esp; iretd | 0_2_0DCF6762 |
Source: C:\Users\user\Desktop\okmnji.exe | Code function: 0_2_0DCF6754 pushad ; iretd | 0_2_0DCF675A |
Source: C:\Users\user\Desktop\okmnji.exe | Code function: 0_2_0DCF6773 push ebp; iretd | 0_2_0DCF678E |
Source: C:\Users\user\Desktop\okmnji.exe | Code function: 0_2_0DCF7618 push eax; iretd | 0_2_0DCF7621 |
Source: C:\Users\user\Desktop\okmnji.exe | Code function: 0_2_0DCF2637 push ds; iretd | 0_2_0DCF263E |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\InstallUtil.exe | Code function: 3_2_066F8439 push cs; retf | 3_2_066F843A |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\InstallUtil.exe | Code function: 3_2_066F8409 push cs; retf | 3_2_066F840A |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\InstallUtil.exe | Code function: 3_2_066F84D9 push cs; retf | 3_2_066F84DA |
Source: 0.2.okmnji.exe.3c34e20.1.raw.unpack, Kt2Pvv8tOe2.cs | High entropy of concatenated method names: 'G1IIdug', 'x9I6ks0KTp7', 'KyrReQQ', 'ufcnB51fJ8b', 'dpM5dUa', 'i2WUmSy2h', 'GVADvX', 'tSGoukfQ8m', 'o4nN', 'AZraw2mg8zr' |
Source: 0.2.okmnji.exe.3ed6072.2.raw.unpack, Kt2Pvv8tOe2.cs | High entropy of concatenated method names: 'G1IIdug', 'x9I6ks0KTp7', 'KyrReQQ', 'ufcnB51fJ8b', 'dpM5dUa', 'i2WUmSy2h', 'GVADvX', 'tSGoukfQ8m', 'o4nN', 'AZraw2mg8zr' |
Source: 0.2.okmnji.exe.3e5eec2.3.raw.unpack, Kt2Pvv8tOe2.cs | High entropy of concatenated method names: 'G1IIdug', 'x9I6ks0KTp7', 'KyrReQQ', 'ufcnB51fJ8b', 'dpM5dUa', 'i2WUmSy2h', 'GVADvX', 'tSGoukfQ8m', 'o4nN', 'AZraw2mg8zr' |
Source: 0.2.okmnji.exe.3e9a7a2.4.raw.unpack, Kt2Pvv8tOe2.cs | High entropy of concatenated method names: 'G1IIdug', 'x9I6ks0KTp7', 'KyrReQQ', 'ufcnB51fJ8b', 'dpM5dUa', 'i2WUmSy2h', 'GVADvX', 'tSGoukfQ8m', 'o4nN', 'AZraw2mg8zr' |
Source: C:\Users\user\Desktop\okmnji.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\okmnji.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\okmnji.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\okmnji.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\okmnji.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\okmnji.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\okmnji.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\okmnji.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\okmnji.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\okmnji.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\okmnji.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\okmnji.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\okmnji.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\okmnji.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\okmnji.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\okmnji.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\okmnji.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\okmnji.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\okmnji.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\okmnji.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\okmnji.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\okmnji.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\okmnji.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\okmnji.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\okmnji.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\okmnji.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\okmnji.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\okmnji.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\okmnji.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\okmnji.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\okmnji.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\okmnji.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\okmnji.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\okmnji.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\okmnji.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\okmnji.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\okmnji.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\okmnji.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\okmnji.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\okmnji.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\okmnji.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\okmnji.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\okmnji.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\okmnji.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\okmnji.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\okmnji.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\okmnji.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\okmnji.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\okmnji.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\okmnji.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\okmnji.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\okmnji.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\okmnji.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\okmnji.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\okmnji.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\okmnji.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\InstallUtil.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\InstallUtil.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\InstallUtil.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\InstallUtil.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\InstallUtil.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\InstallUtil.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\InstallUtil.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\InstallUtil.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\InstallUtil.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\InstallUtil.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\InstallUtil.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\InstallUtil.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\InstallUtil.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\InstallUtil.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\InstallUtil.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\InstallUtil.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\InstallUtil.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\InstallUtil.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\InstallUtil.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\InstallUtil.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\InstallUtil.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\InstallUtil.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\InstallUtil.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\InstallUtil.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\InstallUtil.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\InstallUtil.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\InstallUtil.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\InstallUtil.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\InstallUtil.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\InstallUtil.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\InstallUtil.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\InstallUtil.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\InstallUtil.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\InstallUtil.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\InstallUtil.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\InstallUtil.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\InstallUtil.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\InstallUtil.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\InstallUtil.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\InstallUtil.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\InstallUtil.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\InstallUtil.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\InstallUtil.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\InstallUtil.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\InstallUtil.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\InstallUtil.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\InstallUtil.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\InstallUtil.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\InstallUtil.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\InstallUtil.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\InstallUtil.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\InstallUtil.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\InstallUtil.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\InstallUtil.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\InstallUtil.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\InstallUtil.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\InstallUtil.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\InstallUtil.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\InstallUtil.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\InstallUtil.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\InstallUtil.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\InstallUtil.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\InstallUtil.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\okmnji.exe TID: 7252 | Thread sleep time: -32281802128991695s >= -30000s | Jump to behavior |
Source: C:\Users\user\Desktop\okmnji.exe TID: 7332 | Thread sleep time: -58000s >= -30000s | Jump to behavior |
Source: C:\Users\user\Desktop\okmnji.exe TID: 3536 | Thread sleep time: -30000s >= -30000s | Jump to behavior |
Source: C:\Users\user\Desktop\okmnji.exe TID: 1772 | Thread sleep time: -922337203685477s >= -30000s | Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\InstallUtil.exe TID: 7780 | Thread sleep time: -13835058055282155s >= -30000s | Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\InstallUtil.exe TID: 7780 | Thread sleep time: -100000s >= -30000s | Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\InstallUtil.exe TID: 7784 | Thread sleep count: 655 > 30 | Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\InstallUtil.exe TID: 7780 | Thread sleep time: -99890s >= -30000s | Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\InstallUtil.exe TID: 7784 | Thread sleep count: 4724 > 30 | Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\InstallUtil.exe TID: 7780 | Thread sleep time: -99781s >= -30000s | Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\InstallUtil.exe TID: 7780 | Thread sleep time: -99665s >= -30000s | Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\InstallUtil.exe TID: 7780 | Thread sleep time: -99539s >= -30000s | Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\InstallUtil.exe TID: 7780 | Thread sleep time: -99422s >= -30000s | Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\InstallUtil.exe TID: 7780 | Thread sleep time: -99296s >= -30000s | Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\InstallUtil.exe TID: 7780 | Thread sleep time: -99188s >= -30000s | Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\InstallUtil.exe TID: 7780 | Thread sleep time: -99063s >= -30000s | Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\InstallUtil.exe TID: 7780 | Thread sleep time: -98938s >= -30000s | Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\InstallUtil.exe TID: 7780 | Thread sleep time: -98813s >= -30000s | Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\InstallUtil.exe TID: 7780 | Thread sleep time: -98688s >= -30000s | Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\InstallUtil.exe TID: 7780 | Thread sleep time: -98578s >= -30000s | Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\InstallUtil.exe TID: 7780 | Thread sleep time: -98469s >= -30000s | Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\InstallUtil.exe TID: 7780 | Thread sleep time: -98344s >= -30000s | Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\InstallUtil.exe TID: 7780 | Thread sleep time: -98235s >= -30000s | Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\InstallUtil.exe TID: 7780 | Thread sleep time: -98110s >= -30000s | Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\InstallUtil.exe TID: 7780 | Thread sleep time: -97985s >= -30000s | Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\InstallUtil.exe TID: 7780 | Thread sleep time: -97860s >= -30000s | Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\InstallUtil.exe TID: 7780 | Thread sleep time: -97735s >= -30000s | Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\InstallUtil.exe TID: 7780 | Thread sleep time: -97610s >= -30000s | Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\InstallUtil.exe TID: 7780 | Thread sleep time: -97485s >= -30000s | Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\InstallUtil.exe TID: 7780 | Thread sleep time: -97360s >= -30000s | Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\InstallUtil.exe TID: 7780 | Thread sleep time: -97235s >= -30000s | Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\InstallUtil.exe TID: 7780 | Thread sleep time: -97110s >= -30000s | Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\InstallUtil.exe TID: 7780 | Thread sleep time: -96985s >= -30000s | Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\InstallUtil.exe TID: 7780 | Thread sleep time: -922337203685477s >= -30000s | Jump to behavior |
Source: C:\Users\user\Desktop\okmnji.exe | Thread delayed: delay time: 922337203685477 | Jump to behavior |
Source: C:\Users\user\Desktop\okmnji.exe | Thread delayed: delay time: 922337203685477 | Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\InstallUtil.exe | Thread delayed: delay time: 922337203685477 | Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\InstallUtil.exe | Thread delayed: delay time: 100000 | Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\InstallUtil.exe | Thread delayed: delay time: 99890 | Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\InstallUtil.exe | Thread delayed: delay time: 99781 | Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\InstallUtil.exe | Thread delayed: delay time: 99665 | Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\InstallUtil.exe | Thread delayed: delay time: 99539 | Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\InstallUtil.exe | Thread delayed: delay time: 99422 | Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\InstallUtil.exe | Thread delayed: delay time: 99296 | Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\InstallUtil.exe | Thread delayed: delay time: 99188 | Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\InstallUtil.exe | Thread delayed: delay time: 99063 | Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\InstallUtil.exe | Thread delayed: delay time: 98938 | Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\InstallUtil.exe | Thread delayed: delay time: 98813 | Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\InstallUtil.exe | Thread delayed: delay time: 98688 | Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\InstallUtil.exe | Thread delayed: delay time: 98578 | Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\InstallUtil.exe | Thread delayed: delay time: 98469 | Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\InstallUtil.exe | Thread delayed: delay time: 98344 | Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\InstallUtil.exe | Thread delayed: delay time: 98235 | Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\InstallUtil.exe | Thread delayed: delay time: 98110 | Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\InstallUtil.exe | Thread delayed: delay time: 97985 | Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\InstallUtil.exe | Thread delayed: delay time: 97860 | Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\InstallUtil.exe | Thread delayed: delay time: 97735 | Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\InstallUtil.exe | Thread delayed: delay time: 97610 | Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\InstallUtil.exe | Thread delayed: delay time: 97485 | Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\InstallUtil.exe | Thread delayed: delay time: 97360 | Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\InstallUtil.exe | Thread delayed: delay time: 97235 | Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\InstallUtil.exe | Thread delayed: delay time: 97110 | Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\InstallUtil.exe | Thread delayed: delay time: 96985 | Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\InstallUtil.exe | Thread delayed: delay time: 922337203685477 | Jump to behavior |
Source: C:\Users\user\Desktop\okmnji.exe | Queries volume information: C:\Users\user\Desktop\okmnji.exe VolumeInformation | Jump to behavior |
Source: C:\Users\user\Desktop\okmnji.exe | Queries volume information: C:\Windows\Microsoft.NET\assembly\GAC_MSIL\Microsoft.VisualBasic\v4.0_10.0.0.0__b03f5f7f11d50a3a\Microsoft.VisualBasic.dll VolumeInformation | Jump to behavior |
Source: C:\Users\user\Desktop\okmnji.exe | Queries volume information: C:\Windows\Microsoft.NET\assembly\GAC_MSIL\System.Windows.Forms\v4.0_4.0.0.0__b77a5c561934e089\System.Windows.Forms.dll VolumeInformation | Jump to behavior |
Source: C:\Users\user\Desktop\okmnji.exe | Queries volume information: C:\Windows\Microsoft.NET\assembly\GAC_MSIL\System.Drawing\v4.0_4.0.0.0__b03f5f7f11d50a3a\System.Drawing.dll VolumeInformation | Jump to behavior |
Source: C:\Users\user\Desktop\okmnji.exe | Queries volume information: C:\Windows\Microsoft.NET\assembly\GAC_MSIL\Accessibility\v4.0_4.0.0.0__b03f5f7f11d50a3a\Accessibility.dll VolumeInformation | Jump to behavior |
Source: C:\Users\user\Desktop\okmnji.exe | Queries volume information: C:\Windows\Fonts\micross.ttf VolumeInformation | Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\InstallUtil.exe | Queries volume information: C:\Windows\Microsoft.NET\Framework\v4.0.30319\InstallUtil.exe VolumeInformation | Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\InstallUtil.exe | Queries volume information: C:\Windows\Microsoft.NET\assembly\GAC_MSIL\System.Windows.Forms\v4.0_4.0.0.0__b77a5c561934e089\System.Windows.Forms.dll VolumeInformation | Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\InstallUtil.exe | Queries volume information: C:\Windows\Microsoft.NET\assembly\GAC_MSIL\System.Security\v4.0_4.0.0.0__b03f5f7f11d50a3a\System.Security.dll VolumeInformation | Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\InstallUtil.exe | Queries volume information: C:\Windows\Microsoft.NET\assembly\GAC_MSIL\Microsoft.VisualBasic\v4.0_10.0.0.0__b03f5f7f11d50a3a\Microsoft.VisualBasic.dll VolumeInformation | Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\InstallUtil.exe | Queries volume information: C:\Windows\Microsoft.NET\assembly\GAC_MSIL\System.Drawing\v4.0_4.0.0.0__b03f5f7f11d50a3a\System.Drawing.dll VolumeInformation | Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\InstallUtil.exe | Queries volume information: C:\Windows\Microsoft.NET\assembly\GAC_MSIL\Accessibility\v4.0_4.0.0.0__b03f5f7f11d50a3a\Accessibility.dll VolumeInformation | Jump to behavior |
Source: Yara match | File source: 0.2.okmnji.exe.3ed6072.2.unpack, type: UNPACKEDPE |
Source: Yara match | File source: 3.2.InstallUtil.exe.400000.0.unpack, type: UNPACKEDPE |
Source: Yara match | File source: 0.2.okmnji.exe.3c34e20.1.unpack, type: UNPACKEDPE |
Source: Yara match | File source: 0.2.okmnji.exe.3c34e20.1.raw.unpack, type: UNPACKEDPE |
Source: Yara match | File source: 0.2.okmnji.exe.3e9a7a2.4.unpack, type: UNPACKEDPE |
Source: Yara match | File source: 0.2.okmnji.exe.3e5eec2.3.unpack, type: UNPACKEDPE |
Source: Yara match | File source: 0.2.okmnji.exe.3ed6072.2.raw.unpack, type: UNPACKEDPE |
Source: Yara match | File source: 0.2.okmnji.exe.3e9a7a2.4.raw.unpack, type: UNPACKEDPE |
Source: Yara match | File source: 0.2.okmnji.exe.3e5eec2.3.raw.unpack, type: UNPACKEDPE |
Source: Yara match | File source: 00000003.00000002.3286541234.0000000002EA1000.00000004.00000800.00020000.00000000.sdmp, type: MEMORY |
Source: Yara match | File source: 00000003.00000002.3286541234.0000000002E7E000.00000004.00000800.00020000.00000000.sdmp, type: MEMORY |
Source: Yara match | File source: 00000003.00000002.3286541234.0000000002E51000.00000004.00000800.00020000.00000000.sdmp, type: MEMORY |
Source: Yara match | File source: 00000000.00000002.2534480616.0000000003BF1000.00000004.00000800.00020000.00000000.sdmp, type: MEMORY |
Source: Yara match | File source: 00000003.00000002.3283492117.0000000000402000.00000040.00000400.00020000.00000000.sdmp, type: MEMORY |
Source: Yara match | File source: 00000000.00000002.2534480616.0000000003DC8000.00000004.00000800.00020000.00000000.sdmp, type: MEMORY |
Source: Yara match | File source: Process Memory Space: okmnji.exe PID: 5284, type: MEMORYSTR |
Source: Yara match | File source: Process Memory Space: InstallUtil.exe PID: 7336, type: MEMORYSTR |
Source: Yara match | File source: 0.2.okmnji.exe.3ed6072.2.unpack, type: UNPACKEDPE |
Source: Yara match | File source: 3.2.InstallUtil.exe.400000.0.unpack, type: UNPACKEDPE |
Source: Yara match | File source: 0.2.okmnji.exe.3c34e20.1.unpack, type: UNPACKEDPE |
Source: Yara match | File source: 0.2.okmnji.exe.3c34e20.1.raw.unpack, type: UNPACKEDPE |
Source: Yara match | File source: 0.2.okmnji.exe.3e9a7a2.4.unpack, type: UNPACKEDPE |
Source: Yara match | File source: 0.2.okmnji.exe.3e5eec2.3.unpack, type: UNPACKEDPE |
Source: Yara match | File source: 0.2.okmnji.exe.3ed6072.2.raw.unpack, type: UNPACKEDPE |
Source: Yara match | File source: 0.2.okmnji.exe.3e9a7a2.4.raw.unpack, type: UNPACKEDPE |
Source: Yara match | File source: 0.2.okmnji.exe.3e5eec2.3.raw.unpack, type: UNPACKEDPE |
Source: Yara match | File source: 00000003.00000002.3286541234.0000000002EA1000.00000004.00000800.00020000.00000000.sdmp, type: MEMORY |
Source: Yara match | File source: 00000003.00000002.3286541234.0000000002E7E000.00000004.00000800.00020000.00000000.sdmp, type: MEMORY |
Source: Yara match | File source: 00000003.00000002.3286541234.0000000002E51000.00000004.00000800.00020000.00000000.sdmp, type: MEMORY |
Source: Yara match | File source: 00000000.00000002.2534480616.0000000003BF1000.00000004.00000800.00020000.00000000.sdmp, type: MEMORY |
Source: Yara match | File source: 00000003.00000002.3283492117.0000000000402000.00000040.00000400.00020000.00000000.sdmp, type: MEMORY |
Source: Yara match | File source: 00000000.00000002.2534480616.0000000003DC8000.00000004.00000800.00020000.00000000.sdmp, type: MEMORY |
Source: Yara match | File source: Process Memory Space: okmnji.exe PID: 5284, type: MEMORYSTR |
Source: Yara match | File source: Process Memory Space: InstallUtil.exe PID: 7336, type: MEMORYSTR |