Windows Analysis Report
AVKlyo045S.exe

Overview

General Information

Sample name: AVKlyo045S.exe
renamed because original name is a hash value
Original sample name: d484104256e41a509ff52bb9a5bbd7bd63aaf18e0b32b68fe3c4bfa6b81aa267.exe
Analysis ID: 1466950
MD5: 0dba4bed5bf4e4c327b712f723e714c5
SHA1: b8609db0404983d9a7f2bc4639d93a539bb883a6
SHA256: d484104256e41a509ff52bb9a5bbd7bd63aaf18e0b32b68fe3c4bfa6b81aa267
Tags: exe
Infos:

Detection

XenoRAT
Score: 100
Range: 0 - 100
Whitelisted: false
Confidence: 100%

Signatures

Found malware configuration
Multi AV Scanner detection for dropped file
Multi AV Scanner detection for submitted file
Sigma detected: Scheduled temp file as task from temp location
Yara detected XenoRAT
.NET source code contains potential unpacker
AI detected suspicious sample
C2 URLs / IPs found in malware configuration
Injects a PE file into a foreign processes
Machine Learning detection for dropped file
Machine Learning detection for sample
Uses schtasks.exe or at.exe to add and modify task schedules
Allocates memory with a write watch (potentially for evading sandboxes)
Checks if the current process is being debugged
Contains functionality to call native functions
Contains long sleeps (>= 3 min)
Creates a process in suspended mode (likely to inject code)
Detected TCP or UDP traffic on non-standard ports
Detected potential crypto function
Drops PE files
Enables debug privileges
Found a high number of Window / User specific system calls (may be a loop to detect user behavior)
Found inlined nop instructions (likely shell or obfuscated code)
IP address seen in connection with other malware
Internet Provider seen in connection with other malware
May sleep (evasive loops) to hinder dynamic analysis
One or more processes crash
Queries the volume information (name, serial number etc) of a device
Sample file is different than original file name gathered from version info
Sigma detected: Suspicious Add Scheduled Task Parent
Sigma detected: Suspicious Schtasks From Env Var Folder
Uses 32bit PE files
Uses code obfuscation techniques (call, push, ret)

Classification

AV Detection

barindex
Source: 1.2.AVKlyo045S.exe.24cd62c.0.raw.unpack Malware Configuration Extractor: XenoRAT {"C2 url": "91.92.248.167", "Mutex Name": "Wolid_rat_nd8859g", "Install Folder": "appdata"}
Source: C:\Users\user\AppData\Roaming\XenoManager\AVKlyo045S.exe ReversingLabs: Detection: 87%
Source: AVKlyo045S.exe ReversingLabs: Detection: 87%
Source: Submited Sample Integrated Neural Analysis Model: Matched 100.0% probability
Source: C:\Users\user\AppData\Roaming\XenoManager\AVKlyo045S.exe Joe Sandbox ML: detected
Source: AVKlyo045S.exe Joe Sandbox ML: detected
Source: AVKlyo045S.exe Static PE information: EXECUTABLE_IMAGE, 32BIT_MACHINE
Source: AVKlyo045S.exe Static PE information: HIGH_ENTROPY_VA, DYNAMIC_BASE, NX_COMPAT, NO_SEH, TERMINAL_SERVER_AWARE
Source: C:\Users\user\Desktop\AVKlyo045S.exe Code function: 4x nop then jmp 009B17B0h 5_2_009B0B60
Source: C:\Users\user\AppData\Roaming\XenoManager\AVKlyo045S.exe Code function: 4x nop then jmp 017917B0h 11_2_01790B60
Source: C:\Users\user\AppData\Roaming\XenoManager\AVKlyo045S.exe Code function: 4x nop then jmp 017917B0h 11_2_01790B54
Source: C:\Users\user\AppData\Roaming\XenoManager\AVKlyo045S.exe Code function: 4x nop then jmp 02D117B0h 12_2_02D10B60
Source: C:\Users\user\AppData\Roaming\XenoManager\AVKlyo045S.exe Code function: 4x nop then jmp 017317B0h 23_2_01730B60
Source: C:\Users\user\AppData\Roaming\XenoManager\AVKlyo045S.exe Code function: 4x nop then jmp 013317B0h 24_2_01330B60
Source: C:\Users\user\AppData\Roaming\XenoManager\AVKlyo045S.exe Code function: 4x nop then jmp 02F517B0h 25_2_02F50B60

Networking

barindex
Source: Malware configuration extractor URLs: 91.92.248.167
Source: global traffic TCP traffic: 192.168.2.8:49714 -> 91.92.248.167:1280
Source: Joe Sandbox View IP Address: 91.92.248.167 91.92.248.167
Source: Joe Sandbox View ASN Name: THEZONEBG THEZONEBG
Source: unknown TCP traffic detected without corresponding DNS query: 91.92.248.167
Source: unknown TCP traffic detected without corresponding DNS query: 91.92.248.167
Source: unknown TCP traffic detected without corresponding DNS query: 91.92.248.167
Source: unknown TCP traffic detected without corresponding DNS query: 91.92.248.167
Source: unknown TCP traffic detected without corresponding DNS query: 91.92.248.167
Source: unknown TCP traffic detected without corresponding DNS query: 91.92.248.167
Source: unknown TCP traffic detected without corresponding DNS query: 91.92.248.167
Source: unknown TCP traffic detected without corresponding DNS query: 91.92.248.167
Source: unknown TCP traffic detected without corresponding DNS query: 91.92.248.167
Source: unknown TCP traffic detected without corresponding DNS query: 91.92.248.167
Source: unknown TCP traffic detected without corresponding DNS query: 91.92.248.167
Source: unknown TCP traffic detected without corresponding DNS query: 91.92.248.167
Source: unknown TCP traffic detected without corresponding DNS query: 91.92.248.167
Source: unknown TCP traffic detected without corresponding DNS query: 91.92.248.167
Source: unknown TCP traffic detected without corresponding DNS query: 91.92.248.167
Source: unknown TCP traffic detected without corresponding DNS query: 91.92.248.167
Source: unknown TCP traffic detected without corresponding DNS query: 91.92.248.167
Source: unknown TCP traffic detected without corresponding DNS query: 91.92.248.167
Source: unknown TCP traffic detected without corresponding DNS query: 91.92.248.167
Source: unknown TCP traffic detected without corresponding DNS query: 91.92.248.167
Source: unknown TCP traffic detected without corresponding DNS query: 91.92.248.167
Source: unknown TCP traffic detected without corresponding DNS query: 91.92.248.167
Source: unknown TCP traffic detected without corresponding DNS query: 91.92.248.167
Source: unknown TCP traffic detected without corresponding DNS query: 91.92.248.167
Source: unknown TCP traffic detected without corresponding DNS query: 91.92.248.167
Source: unknown TCP traffic detected without corresponding DNS query: 91.92.248.167
Source: unknown TCP traffic detected without corresponding DNS query: 91.92.248.167
Source: unknown TCP traffic detected without corresponding DNS query: 91.92.248.167
Source: unknown TCP traffic detected without corresponding DNS query: 91.92.248.167
Source: unknown TCP traffic detected without corresponding DNS query: 91.92.248.167
Source: unknown TCP traffic detected without corresponding DNS query: 91.92.248.167
Source: unknown TCP traffic detected without corresponding DNS query: 91.92.248.167
Source: unknown TCP traffic detected without corresponding DNS query: 91.92.248.167
Source: unknown TCP traffic detected without corresponding DNS query: 91.92.248.167
Source: unknown TCP traffic detected without corresponding DNS query: 91.92.248.167
Source: unknown TCP traffic detected without corresponding DNS query: 91.92.248.167
Source: unknown TCP traffic detected without corresponding DNS query: 91.92.248.167
Source: unknown TCP traffic detected without corresponding DNS query: 91.92.248.167
Source: unknown TCP traffic detected without corresponding DNS query: 91.92.248.167
Source: unknown TCP traffic detected without corresponding DNS query: 91.92.248.167
Source: unknown TCP traffic detected without corresponding DNS query: 91.92.248.167
Source: unknown TCP traffic detected without corresponding DNS query: 91.92.248.167
Source: unknown TCP traffic detected without corresponding DNS query: 91.92.248.167
Source: unknown TCP traffic detected without corresponding DNS query: 91.92.248.167
Source: unknown TCP traffic detected without corresponding DNS query: 91.92.248.167
Source: unknown TCP traffic detected without corresponding DNS query: 91.92.248.167
Source: unknown TCP traffic detected without corresponding DNS query: 91.92.248.167
Source: unknown TCP traffic detected without corresponding DNS query: 91.92.248.167
Source: unknown TCP traffic detected without corresponding DNS query: 91.92.248.167
Source: unknown TCP traffic detected without corresponding DNS query: 91.92.248.167
Source: C:\Users\user\Desktop\AVKlyo045S.exe Code function: 1_2_0A3A8678 NtWriteVirtualMemory, 1_2_0A3A8678
Source: C:\Users\user\Desktop\AVKlyo045S.exe Code function: 1_2_0A3A82A0 NtReadVirtualMemory, 1_2_0A3A82A0
Source: C:\Users\user\Desktop\AVKlyo045S.exe Code function: 1_2_0A3A8820 NtSetContextThread, 1_2_0A3A8820
Source: C:\Users\user\Desktop\AVKlyo045S.exe Code function: 1_2_0A3A8458 NtResumeThread, 1_2_0A3A8458
Source: C:\Users\user\Desktop\AVKlyo045S.exe Code function: 1_2_0A3A8671 NtWriteVirtualMemory, 1_2_0A3A8671
Source: C:\Users\user\Desktop\AVKlyo045S.exe Code function: 1_2_0A3A8262 NtReadVirtualMemory, 1_2_0A3A8262
Source: C:\Users\user\Desktop\AVKlyo045S.exe Code function: 1_2_0A3A8819 NtSetContextThread, 1_2_0A3A8819
Source: C:\Users\user\Desktop\AVKlyo045S.exe Code function: 1_2_0A3A8450 NtResumeThread, 1_2_0A3A8450
Source: C:\Users\user\Desktop\AVKlyo045S.exe Code function: 1_2_0A3A81D0 NtReadVirtualMemory, 1_2_0A3A81D0
Source: C:\Users\user\AppData\Roaming\XenoManager\AVKlyo045S.exe Code function: 6_2_0A8B82A0 NtReadVirtualMemory, 6_2_0A8B82A0
Source: C:\Users\user\AppData\Roaming\XenoManager\AVKlyo045S.exe Code function: 6_2_0A8B8678 NtWriteVirtualMemory, 6_2_0A8B8678
Source: C:\Users\user\AppData\Roaming\XenoManager\AVKlyo045S.exe Code function: 6_2_0A8B8820 NtSetContextThread, 6_2_0A8B8820
Source: C:\Users\user\AppData\Roaming\XenoManager\AVKlyo045S.exe Code function: 6_2_0A8B8458 NtResumeThread, 6_2_0A8B8458
Source: C:\Users\user\AppData\Roaming\XenoManager\AVKlyo045S.exe Code function: 6_2_0A8B8671 NtWriteVirtualMemory, 6_2_0A8B8671
Source: C:\Users\user\AppData\Roaming\XenoManager\AVKlyo045S.exe Code function: 6_2_0A8B8090 NtReadVirtualMemory, 6_2_0A8B8090
Source: C:\Users\user\AppData\Roaming\XenoManager\AVKlyo045S.exe Code function: 6_2_0A8B8819 NtSetContextThread, 6_2_0A8B8819
Source: C:\Users\user\AppData\Roaming\XenoManager\AVKlyo045S.exe Code function: 6_2_0A8B8450 NtResumeThread, 6_2_0A8B8450
Source: C:\Users\user\AppData\Roaming\XenoManager\AVKlyo045S.exe Code function: 22_2_066A8678 NtWriteVirtualMemory, 22_2_066A8678
Source: C:\Users\user\AppData\Roaming\XenoManager\AVKlyo045S.exe Code function: 22_2_066A82A0 NtReadVirtualMemory, 22_2_066A82A0
Source: C:\Users\user\AppData\Roaming\XenoManager\AVKlyo045S.exe Code function: 22_2_066A8458 NtResumeThread, 22_2_066A8458
Source: C:\Users\user\AppData\Roaming\XenoManager\AVKlyo045S.exe Code function: 22_2_066A8820 NtSetContextThread, 22_2_066A8820
Source: C:\Users\user\AppData\Roaming\XenoManager\AVKlyo045S.exe Code function: 22_2_066A8262 NtReadVirtualMemory, 22_2_066A8262
Source: C:\Users\user\AppData\Roaming\XenoManager\AVKlyo045S.exe Code function: 22_2_066A8671 NtWriteVirtualMemory, 22_2_066A8671
Source: C:\Users\user\AppData\Roaming\XenoManager\AVKlyo045S.exe Code function: 22_2_066A8450 NtResumeThread, 22_2_066A8450
Source: C:\Users\user\AppData\Roaming\XenoManager\AVKlyo045S.exe Code function: 22_2_066A8819 NtSetContextThread, 22_2_066A8819
Source: C:\Users\user\AppData\Roaming\XenoManager\AVKlyo045S.exe Code function: 22_2_066A8143 NtReadVirtualMemory, 22_2_066A8143
Source: C:\Users\user\Desktop\AVKlyo045S.exe Code function: 1_2_00A19C68 1_2_00A19C68
Source: C:\Users\user\Desktop\AVKlyo045S.exe Code function: 1_2_00A10848 1_2_00A10848
Source: C:\Users\user\Desktop\AVKlyo045S.exe Code function: 1_2_00A1B5F8 1_2_00A1B5F8
Source: C:\Users\user\Desktop\AVKlyo045S.exe Code function: 1_2_00A13511 1_2_00A13511
Source: C:\Users\user\Desktop\AVKlyo045S.exe Code function: 1_2_00A17EE0 1_2_00A17EE0
Source: C:\Users\user\Desktop\AVKlyo045S.exe Code function: 1_2_00A12200 1_2_00A12200
Source: C:\Users\user\Desktop\AVKlyo045S.exe Code function: 1_2_00A1A7A0 1_2_00A1A7A0
Source: C:\Users\user\Desktop\AVKlyo045S.exe Code function: 1_2_00A18F90 1_2_00A18F90
Source: C:\Users\user\Desktop\AVKlyo045S.exe Code function: 1_2_00A12B2A 1_2_00A12B2A
Source: C:\Users\user\Desktop\AVKlyo045S.exe Code function: 1_2_00A14348 1_2_00A14348
Source: C:\Users\user\Desktop\AVKlyo045S.exe Code function: 1_2_00A160B1 1_2_00A160B1
Source: C:\Users\user\Desktop\AVKlyo045S.exe Code function: 1_2_00A168E8 1_2_00A168E8
Source: C:\Users\user\Desktop\AVKlyo045S.exe Code function: 1_2_00A168D8 1_2_00A168D8
Source: C:\Users\user\Desktop\AVKlyo045S.exe Code function: 1_2_00A1DC20 1_2_00A1DC20
Source: C:\Users\user\Desktop\AVKlyo045S.exe Code function: 1_2_00A1081F 1_2_00A1081F
Source: C:\Users\user\Desktop\AVKlyo045S.exe Code function: 1_2_00A16468 1_2_00A16468
Source: C:\Users\user\Desktop\AVKlyo045S.exe Code function: 1_2_00A16458 1_2_00A16458
Source: C:\Users\user\Desktop\AVKlyo045S.exe Code function: 1_2_00A15DE8 1_2_00A15DE8
Source: C:\Users\user\Desktop\AVKlyo045S.exe Code function: 1_2_00A1D9C0 1_2_00A1D9C0
Source: C:\Users\user\Desktop\AVKlyo045S.exe Code function: 1_2_00A12171 1_2_00A12171
Source: C:\Users\user\Desktop\AVKlyo045S.exe Code function: 1_2_00A12153 1_2_00A12153
Source: C:\Users\user\Desktop\AVKlyo045S.exe Code function: 1_2_00A1C558 1_2_00A1C558
Source: C:\Users\user\Desktop\AVKlyo045S.exe Code function: 1_2_00A152A8 1_2_00A152A8
Source: C:\Users\user\Desktop\AVKlyo045S.exe Code function: 1_2_00A16AB8 1_2_00A16AB8
Source: C:\Users\user\Desktop\AVKlyo045S.exe Code function: 1_2_00A1529A 1_2_00A1529A
Source: C:\Users\user\Desktop\AVKlyo045S.exe Code function: 1_2_00A17ED1 1_2_00A17ED1
Source: C:\Users\user\Desktop\AVKlyo045S.exe Code function: 1_2_00A182D9 1_2_00A182D9
Source: C:\Users\user\Desktop\AVKlyo045S.exe Code function: 1_2_00A16660 1_2_00A16660
Source: C:\Users\user\Desktop\AVKlyo045S.exe Code function: 1_2_00A16670 1_2_00A16670
Source: C:\Users\user\Desktop\AVKlyo045S.exe Code function: 1_2_00A1427C 1_2_00A1427C
Source: C:\Users\user\Desktop\AVKlyo045S.exe Code function: 1_2_00A1D7B8 1_2_00A1D7B8
Source: C:\Users\user\Desktop\AVKlyo045S.exe Code function: 1_2_00A18F7A 1_2_00A18F7A
Source: C:\Users\user\Desktop\AVKlyo045S.exe Code function: 1_2_0A3A7208 1_2_0A3A7208
Source: C:\Users\user\Desktop\AVKlyo045S.exe Code function: 1_2_0A3AA098 1_2_0A3AA098
Source: C:\Users\user\Desktop\AVKlyo045S.exe Code function: 1_2_0A3A89D0 1_2_0A3A89D0
Source: C:\Users\user\Desktop\AVKlyo045S.exe Code function: 1_2_0A3A2E00 1_2_0A3A2E00
Source: C:\Users\user\Desktop\AVKlyo045S.exe Code function: 1_2_0A3A5F70 1_2_0A3A5F70
Source: C:\Users\user\Desktop\AVKlyo045S.exe Code function: 1_2_0A3A5F61 1_2_0A3A5F61
Source: C:\Users\user\Desktop\AVKlyo045S.exe Code function: 1_2_0A3AA088 1_2_0A3AA088
Source: C:\Users\user\Desktop\AVKlyo045S.exe Code function: 1_2_0A3A2908 1_2_0A3A2908
Source: C:\Users\user\Desktop\AVKlyo045S.exe Code function: 1_2_0A3A71FC 1_2_0A3A71FC
Source: C:\Users\user\Desktop\AVKlyo045S.exe Code function: 1_2_0A3A2DF0 1_2_0A3A2DF0
Source: C:\Users\user\Desktop\AVKlyo045S.exe Code function: 1_2_0A3A89C2 1_2_0A3A89C2
Source: C:\Users\user\Desktop\AVKlyo045S.exe Code function: 5_2_009B0B60 5_2_009B0B60
Source: C:\Users\user\AppData\Roaming\XenoManager\AVKlyo045S.exe Code function: 6_2_00F47C58 6_2_00F47C58
Source: C:\Users\user\AppData\Roaming\XenoManager\AVKlyo045S.exe Code function: 6_2_00F40848 6_2_00F40848
Source: C:\Users\user\AppData\Roaming\XenoManager\AVKlyo045S.exe Code function: 6_2_00F4B5F8 6_2_00F4B5F8
Source: C:\Users\user\AppData\Roaming\XenoManager\AVKlyo045S.exe Code function: 6_2_00F43523 6_2_00F43523
Source: C:\Users\user\AppData\Roaming\XenoManager\AVKlyo045S.exe Code function: 6_2_00F48D08 6_2_00F48D08
Source: C:\Users\user\AppData\Roaming\XenoManager\AVKlyo045S.exe Code function: 6_2_00F42200 6_2_00F42200
Source: C:\Users\user\AppData\Roaming\XenoManager\AVKlyo045S.exe Code function: 6_2_00F44348 6_2_00F44348
Source: C:\Users\user\AppData\Roaming\XenoManager\AVKlyo045S.exe Code function: 6_2_00F42B37 6_2_00F42B37
Source: C:\Users\user\AppData\Roaming\XenoManager\AVKlyo045S.exe Code function: 6_2_00F468E8 6_2_00F468E8
Source: C:\Users\user\AppData\Roaming\XenoManager\AVKlyo045S.exe Code function: 6_2_00F460B1 6_2_00F460B1
Source: C:\Users\user\AppData\Roaming\XenoManager\AVKlyo045S.exe Code function: 6_2_00F48063 6_2_00F48063
Source: C:\Users\user\AppData\Roaming\XenoManager\AVKlyo045S.exe Code function: 6_2_00F46468 6_2_00F46468
Source: C:\Users\user\AppData\Roaming\XenoManager\AVKlyo045S.exe Code function: 6_2_00F47C57 6_2_00F47C57
Source: C:\Users\user\AppData\Roaming\XenoManager\AVKlyo045S.exe Code function: 6_2_00F46458 6_2_00F46458
Source: C:\Users\user\AppData\Roaming\XenoManager\AVKlyo045S.exe Code function: 6_2_00F4DC20 6_2_00F4DC20
Source: C:\Users\user\AppData\Roaming\XenoManager\AVKlyo045S.exe Code function: 6_2_00F499F3 6_2_00F499F3
Source: C:\Users\user\AppData\Roaming\XenoManager\AVKlyo045S.exe Code function: 6_2_00F4D9C0 6_2_00F4D9C0
Source: C:\Users\user\AppData\Roaming\XenoManager\AVKlyo045S.exe Code function: 6_2_00F4C558 6_2_00F4C558
Source: C:\Users\user\AppData\Roaming\XenoManager\AVKlyo045S.exe Code function: 6_2_00F416EB 6_2_00F416EB
Source: C:\Users\user\AppData\Roaming\XenoManager\AVKlyo045S.exe Code function: 6_2_00F452A8 6_2_00F452A8
Source: C:\Users\user\AppData\Roaming\XenoManager\AVKlyo045S.exe Code function: 6_2_00F4529B 6_2_00F4529B
Source: C:\Users\user\AppData\Roaming\XenoManager\AVKlyo045S.exe Code function: 6_2_00F46670 6_2_00F46670
Source: C:\Users\user\AppData\Roaming\XenoManager\AVKlyo045S.exe Code function: 6_2_00F46660 6_2_00F46660
Source: C:\Users\user\AppData\Roaming\XenoManager\AVKlyo045S.exe Code function: 6_2_00F4A7B3 6_2_00F4A7B3
Source: C:\Users\user\AppData\Roaming\XenoManager\AVKlyo045S.exe Code function: 6_2_00F4D7B8 6_2_00F4D7B8
Source: C:\Users\user\AppData\Roaming\XenoManager\AVKlyo045S.exe Code function: 6_2_0A8B7208 6_2_0A8B7208
Source: C:\Users\user\AppData\Roaming\XenoManager\AVKlyo045S.exe Code function: 6_2_0A8BA098 6_2_0A8BA098
Source: C:\Users\user\AppData\Roaming\XenoManager\AVKlyo045S.exe Code function: 6_2_0A8B89D0 6_2_0A8B89D0
Source: C:\Users\user\AppData\Roaming\XenoManager\AVKlyo045S.exe Code function: 6_2_0A8B5F61 6_2_0A8B5F61
Source: C:\Users\user\AppData\Roaming\XenoManager\AVKlyo045S.exe Code function: 6_2_0A8B5F70 6_2_0A8B5F70
Source: C:\Users\user\AppData\Roaming\XenoManager\AVKlyo045S.exe Code function: 6_2_0A8BA088 6_2_0A8BA088
Source: C:\Users\user\AppData\Roaming\XenoManager\AVKlyo045S.exe Code function: 6_2_0A8B89C3 6_2_0A8B89C3
Source: C:\Users\user\AppData\Roaming\XenoManager\AVKlyo045S.exe Code function: 6_2_0A8B71FC 6_2_0A8B71FC
Source: C:\Users\user\AppData\Roaming\XenoManager\AVKlyo045S.exe Code function: 6_2_0A8B2918 6_2_0A8B2918
Source: C:\Users\user\AppData\Roaming\XenoManager\AVKlyo045S.exe Code function: 6_2_0DD965F9 6_2_0DD965F9
Source: C:\Users\user\AppData\Roaming\XenoManager\AVKlyo045S.exe Code function: 6_2_0DD975B0 6_2_0DD975B0
Source: C:\Users\user\AppData\Roaming\XenoManager\AVKlyo045S.exe Code function: 6_2_0DD9B968 6_2_0DD9B968
Source: C:\Users\user\AppData\Roaming\XenoManager\AVKlyo045S.exe Code function: 6_2_0DD90040 6_2_0DD90040
Source: C:\Users\user\AppData\Roaming\XenoManager\AVKlyo045S.exe Code function: 6_2_0DD95C19 6_2_0DD95C19
Source: C:\Users\user\AppData\Roaming\XenoManager\AVKlyo045S.exe Code function: 6_2_0DD9E800 6_2_0DD9E800
Source: C:\Users\user\AppData\Roaming\XenoManager\AVKlyo045S.exe Code function: 6_2_0DD93797 6_2_0DD93797
Source: C:\Users\user\AppData\Roaming\XenoManager\AVKlyo045S.exe Code function: 6_2_0DD95308 6_2_0DD95308
Source: C:\Users\user\AppData\Roaming\XenoManager\AVKlyo045S.exe Code function: 6_2_0DD9CB38 6_2_0DD9CB38
Source: C:\Users\user\AppData\Roaming\XenoManager\AVKlyo045S.exe Code function: 6_2_0DD9D230 6_2_0DD9D230
Source: C:\Users\user\AppData\Roaming\XenoManager\AVKlyo045S.exe Code function: 6_2_0DD995F8 6_2_0DD995F8
Source: C:\Users\user\AppData\Roaming\XenoManager\AVKlyo045S.exe Code function: 6_2_0DD9A960 6_2_0DD9A960
Source: C:\Users\user\AppData\Roaming\XenoManager\AVKlyo045S.exe Code function: 6_2_0DD960C0 6_2_0DD960C0
Source: C:\Users\user\AppData\Roaming\XenoManager\AVKlyo045S.exe Code function: 6_2_0DD9BC70 6_2_0DD9BC70
Source: C:\Users\user\AppData\Roaming\XenoManager\AVKlyo045S.exe Code function: 6_2_0DD99818 6_2_0DD99818
Source: C:\Users\user\AppData\Roaming\XenoManager\AVKlyo045S.exe Code function: 6_2_0DD9001D 6_2_0DD9001D
Source: C:\Users\user\AppData\Roaming\XenoManager\AVKlyo045S.exe Code function: 6_2_0DD94808 6_2_0DD94808
Source: C:\Users\user\AppData\Roaming\XenoManager\AVKlyo045S.exe Code function: 6_2_0DD947F7 6_2_0DD947F7
Source: C:\Users\user\AppData\Roaming\XenoManager\AVKlyo045S.exe Code function: 6_2_0DD9A378 6_2_0DD9A378
Source: C:\Users\user\AppData\Roaming\XenoManager\AVKlyo045S.exe Code function: 6_2_0DD9C368 6_2_0DD9C368
Source: C:\Users\user\AppData\Roaming\XenoManager\AVKlyo045S.exe Code function: 6_2_0DD952D7 6_2_0DD952D7
Source: C:\Users\user\AppData\Roaming\XenoManager\AVKlyo045S.exe Code function: 6_2_0DD952B7 6_2_0DD952B7
Source: C:\Users\user\AppData\Roaming\XenoManager\AVKlyo045S.exe Code function: 6_2_0DD99AA8 6_2_0DD99AA8
Source: C:\Users\user\AppData\Roaming\XenoManager\AVKlyo045S.exe Code function: 6_2_0DD95658 6_2_0DD95658
Source: C:\Users\user\AppData\Roaming\XenoManager\AVKlyo045S.exe Code function: 11_2_01790B60 11_2_01790B60
Source: C:\Users\user\AppData\Roaming\XenoManager\AVKlyo045S.exe Code function: 11_2_01794860 11_2_01794860
Source: C:\Users\user\AppData\Roaming\XenoManager\AVKlyo045S.exe Code function: 11_2_01793660 11_2_01793660
Source: C:\Users\user\AppData\Roaming\XenoManager\AVKlyo045S.exe Code function: 11_2_01792030 11_2_01792030
Source: C:\Users\user\AppData\Roaming\XenoManager\AVKlyo045S.exe Code function: 11_2_01790B54 11_2_01790B54
Source: C:\Users\user\AppData\Roaming\XenoManager\AVKlyo045S.exe Code function: 11_2_01793650 11_2_01793650
Source: C:\Users\user\AppData\Roaming\XenoManager\AVKlyo045S.exe Code function: 12_2_02D10B60 12_2_02D10B60
Source: C:\Users\user\AppData\Roaming\XenoManager\AVKlyo045S.exe Code function: 22_2_012D3511 22_2_012D3511
Source: C:\Users\user\AppData\Roaming\XenoManager\AVKlyo045S.exe Code function: 22_2_012DB5F8 22_2_012DB5F8
Source: C:\Users\user\AppData\Roaming\XenoManager\AVKlyo045S.exe Code function: 22_2_012D9C68 22_2_012D9C68
Source: C:\Users\user\AppData\Roaming\XenoManager\AVKlyo045S.exe Code function: 22_2_012D0848 22_2_012D0848
Source: C:\Users\user\AppData\Roaming\XenoManager\AVKlyo045S.exe Code function: 22_2_012D7C58 22_2_012D7C58
Source: C:\Users\user\AppData\Roaming\XenoManager\AVKlyo045S.exe Code function: 22_2_012D2B31 22_2_012D2B31
Source: C:\Users\user\AppData\Roaming\XenoManager\AVKlyo045S.exe Code function: 22_2_012D4348 22_2_012D4348
Source: C:\Users\user\AppData\Roaming\XenoManager\AVKlyo045S.exe Code function: 22_2_012DA7A0 22_2_012DA7A0
Source: C:\Users\user\AppData\Roaming\XenoManager\AVKlyo045S.exe Code function: 22_2_012D2200 22_2_012D2200
Source: C:\Users\user\AppData\Roaming\XenoManager\AVKlyo045S.exe Code function: 22_2_012DB518 22_2_012DB518
Source: C:\Users\user\AppData\Roaming\XenoManager\AVKlyo045S.exe Code function: 22_2_012D2171 22_2_012D2171
Source: C:\Users\user\AppData\Roaming\XenoManager\AVKlyo045S.exe Code function: 22_2_012DC558 22_2_012DC558
Source: C:\Users\user\AppData\Roaming\XenoManager\AVKlyo045S.exe Code function: 22_2_012D2153 22_2_012D2153
Source: C:\Users\user\AppData\Roaming\XenoManager\AVKlyo045S.exe Code function: 22_2_012DD9C0 22_2_012DD9C0
Source: C:\Users\user\AppData\Roaming\XenoManager\AVKlyo045S.exe Code function: 22_2_012DDC20 22_2_012DDC20
Source: C:\Users\user\AppData\Roaming\XenoManager\AVKlyo045S.exe Code function: 22_2_012D7C00 22_2_012D7C00
Source: C:\Users\user\AppData\Roaming\XenoManager\AVKlyo045S.exe Code function: 22_2_012D081F 22_2_012D081F
Source: C:\Users\user\AppData\Roaming\XenoManager\AVKlyo045S.exe Code function: 22_2_012D6468 22_2_012D6468
Source: C:\Users\user\AppData\Roaming\XenoManager\AVKlyo045S.exe Code function: 22_2_012D6458 22_2_012D6458
Source: C:\Users\user\AppData\Roaming\XenoManager\AVKlyo045S.exe Code function: 22_2_012D60B1 22_2_012D60B1
Source: C:\Users\user\AppData\Roaming\XenoManager\AVKlyo045S.exe Code function: 22_2_012D68E8 22_2_012D68E8
Source: C:\Users\user\AppData\Roaming\XenoManager\AVKlyo045S.exe Code function: 22_2_012D68D8 22_2_012D68D8
Source: C:\Users\user\AppData\Roaming\XenoManager\AVKlyo045S.exe Code function: 22_2_012DD7B8 22_2_012DD7B8
Source: C:\Users\user\AppData\Roaming\XenoManager\AVKlyo045S.exe Code function: 22_2_012D7BE2 22_2_012D7BE2
Source: C:\Users\user\AppData\Roaming\XenoManager\AVKlyo045S.exe Code function: 22_2_012D6660 22_2_012D6660
Source: C:\Users\user\AppData\Roaming\XenoManager\AVKlyo045S.exe Code function: 22_2_012D427C 22_2_012D427C
Source: C:\Users\user\AppData\Roaming\XenoManager\AVKlyo045S.exe Code function: 22_2_012D6670 22_2_012D6670
Source: C:\Users\user\AppData\Roaming\XenoManager\AVKlyo045S.exe Code function: 22_2_012D52A8 22_2_012D52A8
Source: C:\Users\user\AppData\Roaming\XenoManager\AVKlyo045S.exe Code function: 22_2_012D52A0 22_2_012D52A0
Source: C:\Users\user\AppData\Roaming\XenoManager\AVKlyo045S.exe Code function: 22_2_012D82D8 22_2_012D82D8
Source: C:\Users\user\AppData\Roaming\XenoManager\AVKlyo045S.exe Code function: 22_2_066A7208 22_2_066A7208
Source: C:\Users\user\AppData\Roaming\XenoManager\AVKlyo045S.exe Code function: 22_2_066AA098 22_2_066AA098
Source: C:\Users\user\AppData\Roaming\XenoManager\AVKlyo045S.exe Code function: 22_2_066A89D0 22_2_066A89D0
Source: C:\Users\user\AppData\Roaming\XenoManager\AVKlyo045S.exe Code function: 22_2_066A2E00 22_2_066A2E00
Source: C:\Users\user\AppData\Roaming\XenoManager\AVKlyo045S.exe Code function: 22_2_066A5F61 22_2_066A5F61
Source: C:\Users\user\AppData\Roaming\XenoManager\AVKlyo045S.exe Code function: 22_2_066A5F70 22_2_066A5F70
Source: C:\Users\user\AppData\Roaming\XenoManager\AVKlyo045S.exe Code function: 22_2_066AA088 22_2_066AA088
Source: C:\Users\user\AppData\Roaming\XenoManager\AVKlyo045S.exe Code function: 22_2_066A71FC 22_2_066A71FC
Source: C:\Users\user\AppData\Roaming\XenoManager\AVKlyo045S.exe Code function: 22_2_066A2DF2 22_2_066A2DF2
Source: C:\Users\user\AppData\Roaming\XenoManager\AVKlyo045S.exe Code function: 22_2_066A89C2 22_2_066A89C2
Source: C:\Users\user\AppData\Roaming\XenoManager\AVKlyo045S.exe Code function: 23_2_01730B60 23_2_01730B60
Source: C:\Users\user\AppData\Roaming\XenoManager\AVKlyo045S.exe Code function: 24_2_01330B60 24_2_01330B60
Source: C:\Users\user\AppData\Roaming\XenoManager\AVKlyo045S.exe Code function: 25_2_02F50B60 25_2_02F50B60
Source: C:\Users\user\Desktop\AVKlyo045S.exe Process created: C:\Windows\SysWOW64\WerFault.exe C:\Windows\SysWOW64\WerFault.exe -u -p 2848 -s 80
Source: AVKlyo045S.exe, 00000001.00000002.1458741464.00000000026E7000.00000004.00000800.00020000.00000000.sdmp Binary or memory string: OriginalFilenameXolid_manager.exe< vs AVKlyo045S.exe
Source: AVKlyo045S.exe, 00000001.00000002.1458741464.00000000026DA000.00000004.00000800.00020000.00000000.sdmp Binary or memory string: OriginalFilenameXolid_manager.exe< vs AVKlyo045S.exe
Source: AVKlyo045S.exe, 00000001.00000002.1458741464.00000000024C1000.00000004.00000800.00020000.00000000.sdmp Binary or memory string: OriginalFilenameXolid_manager.exe< vs AVKlyo045S.exe
Source: AVKlyo045S.exe, 00000001.00000002.1457663905.000000000089E000.00000004.00000020.00020000.00000000.sdmp Binary or memory string: OriginalFilenameclr.dllT vs AVKlyo045S.exe
Source: AVKlyo045S.exe, 00000001.00000002.1463739900.0000000004AB0000.00000004.08000000.00040000.00000000.sdmp Binary or memory string: OriginalFilenameserver1.exe> vs AVKlyo045S.exe
Source: AVKlyo045S.exe, 00000001.00000000.1439720840.0000000000172000.00000002.00000001.01000000.00000003.sdmp Binary or memory string: OriginalFilenameserver1.exe> vs AVKlyo045S.exe
Source: AVKlyo045S.exe, 00000005.00000002.1457010386.000000000040E000.00000040.00000400.00020000.00000000.sdmp Binary or memory string: OriginalFilenameXolid_manager.exe< vs AVKlyo045S.exe
Source: AVKlyo045S.exe, 00000005.00000002.1457337074.0000000000A85000.00000004.00000020.00020000.00000000.sdmp Binary or memory string: OriginalFilenameserver1.exe> vs AVKlyo045S.exe
Source: AVKlyo045S.exe, 00000006.00000002.1475423833.0000000002B21000.00000004.00000800.00020000.00000000.sdmp Binary or memory string: OriginalFilenameXolid_manager.exe< vs AVKlyo045S.exe
Source: AVKlyo045S.exe, 00000006.00000002.1475423833.0000000002D46000.00000004.00000800.00020000.00000000.sdmp Binary or memory string: OriginalFilenameXolid_manager.exe< vs AVKlyo045S.exe
Source: AVKlyo045S.exe, 00000006.00000002.1475423833.0000000002D55000.00000004.00000800.00020000.00000000.sdmp Binary or memory string: OriginalFilenameXolid_manager.exe< vs AVKlyo045S.exe
Source: AVKlyo045S.exe, 00000006.00000002.1474343405.0000000000D7E000.00000004.00000020.00020000.00000000.sdmp Binary or memory string: OriginalFilenameclr.dllT vs AVKlyo045S.exe
Source: AVKlyo045S.exe, 00000016.00000002.2098007355.0000000002F41000.00000004.00000800.00020000.00000000.sdmp Binary or memory string: OriginalFilenameXolid_manager.exe< vs AVKlyo045S.exe
Source: AVKlyo045S.exe, 00000016.00000002.2098007355.0000000003160000.00000004.00000800.00020000.00000000.sdmp Binary or memory string: OriginalFilenameXolid_manager.exe< vs AVKlyo045S.exe
Source: AVKlyo045S.exe, 00000016.00000002.2098007355.0000000003151000.00000004.00000800.00020000.00000000.sdmp Binary or memory string: OriginalFilenameXolid_manager.exe< vs AVKlyo045S.exe
Source: AVKlyo045S.exe, 00000018.00000002.2090581385.0000000000F77000.00000004.00000020.00020000.00000000.sdmp Binary or memory string: OriginalFilenameclr.dllT vs AVKlyo045S.exe
Source: AVKlyo045S.exe Binary or memory string: OriginalFilenameserver1.exe> vs AVKlyo045S.exe
Source: AVKlyo045S.exe.5.dr Binary or memory string: OriginalFilenameserver1.exe> vs AVKlyo045S.exe
Source: AVKlyo045S.exe Static PE information: EXECUTABLE_IMAGE, 32BIT_MACHINE
Source: AVKlyo045S.exe Static PE information: Section: .text IMAGE_SCN_CNT_CODE, IMAGE_SCN_MEM_EXECUTE, IMAGE_SCN_MEM_READ
Source: AVKlyo045S.exe.5.dr Static PE information: Section: .text IMAGE_SCN_CNT_CODE, IMAGE_SCN_MEM_EXECUTE, IMAGE_SCN_MEM_READ
Source: 1.2.AVKlyo045S.exe.24cd62c.0.raw.unpack, Encryption.cs Cryptographic APIs: 'CreateDecryptor'
Source: 6.2.AVKlyo045S.exe.2b2d670.0.raw.unpack, Encryption.cs Cryptographic APIs: 'CreateDecryptor'
Source: 22.2.AVKlyo045S.exe.2f4e63c.0.raw.unpack, Encryption.cs Cryptographic APIs: 'CreateDecryptor'
Source: classification engine Classification label: mal100.troj.evad.winEXE@28/4@0/1
Source: C:\Users\user\Desktop\AVKlyo045S.exe File created: C:\Users\user\AppData\Local\Microsoft\CLR_v4.0_32\UsageLogs\AVKlyo045S.exe.log Jump to behavior
Source: C:\Users\user\AppData\Roaming\XenoManager\AVKlyo045S.exe Mutant created: NULL
Source: C:\Windows\SysWOW64\WerFault.exe Mutant created: \Sessions\1\BaseNamedObjects\Local\WERReportingForProcess6012
Source: C:\Windows\System32\conhost.exe Mutant created: \Sessions\1\BaseNamedObjects\Local\SM0:3828:120:WilError_03
Source: C:\Windows\SysWOW64\WerFault.exe Mutant created: \Sessions\1\BaseNamedObjects\Local\WERReportingForProcess2848
Source: C:\Users\user\AppData\Roaming\XenoManager\AVKlyo045S.exe Mutant created: \Sessions\1\BaseNamedObjects\Wolid_rat_nd8859g-admin
Source: C:\Windows\SysWOW64\WerFault.exe Mutant created: \Sessions\1\BaseNamedObjects\Local\WERReportingForProcess6108
Source: C:\Windows\SysWOW64\WerFault.exe File created: C:\ProgramData\Microsoft\Windows\WER\Temp\94868277-6a7e-4c5b-a56d-e92e1dc7c39f Jump to behavior
Source: AVKlyo045S.exe Static PE information: Section: .text IMAGE_SCN_CNT_CODE, IMAGE_SCN_MEM_EXECUTE, IMAGE_SCN_MEM_READ
Source: AVKlyo045S.exe Static file information: TRID: Win32 Executable (generic) Net Framework (10011505/4) 49.83%
Source: C:\Users\user\Desktop\AVKlyo045S.exe File read: C:\Users\user\Desktop\desktop.ini Jump to behavior
Source: C:\Users\user\Desktop\AVKlyo045S.exe Key opened: HKEY_CURRENT_USER\Software\Policies\Microsoft\Windows\Safer\CodeIdentifiers Jump to behavior
Source: AVKlyo045S.exe ReversingLabs: Detection: 87%
Source: C:\Users\user\Desktop\AVKlyo045S.exe File read: C:\Users\user\Desktop\AVKlyo045S.exe Jump to behavior
Source: unknown Process created: C:\Users\user\Desktop\AVKlyo045S.exe "C:\Users\user\Desktop\AVKlyo045S.exe"
Source: C:\Users\user\Desktop\AVKlyo045S.exe Process created: C:\Users\user\Desktop\AVKlyo045S.exe C:\Users\user\Desktop\AVKlyo045S.exe
Source: C:\Users\user\Desktop\AVKlyo045S.exe Process created: C:\Users\user\Desktop\AVKlyo045S.exe C:\Users\user\Desktop\AVKlyo045S.exe
Source: C:\Users\user\Desktop\AVKlyo045S.exe Process created: C:\Users\user\Desktop\AVKlyo045S.exe C:\Users\user\Desktop\AVKlyo045S.exe
Source: C:\Users\user\Desktop\AVKlyo045S.exe Process created: C:\Users\user\AppData\Roaming\XenoManager\AVKlyo045S.exe "C:\Users\user\AppData\Roaming\XenoManager\AVKlyo045S.exe"
Source: C:\Users\user\Desktop\AVKlyo045S.exe Process created: C:\Windows\SysWOW64\WerFault.exe C:\Windows\SysWOW64\WerFault.exe -u -p 2848 -s 80
Source: C:\Users\user\Desktop\AVKlyo045S.exe Process created: C:\Windows\SysWOW64\WerFault.exe C:\Windows\SysWOW64\WerFault.exe -u -p 6108 -s 80
Source: C:\Users\user\AppData\Roaming\XenoManager\AVKlyo045S.exe Process created: C:\Users\user\AppData\Roaming\XenoManager\AVKlyo045S.exe C:\Users\user\AppData\Roaming\XenoManager\AVKlyo045S.exe
Source: C:\Users\user\AppData\Roaming\XenoManager\AVKlyo045S.exe Process created: C:\Users\user\AppData\Roaming\XenoManager\AVKlyo045S.exe C:\Users\user\AppData\Roaming\XenoManager\AVKlyo045S.exe
Source: C:\Users\user\AppData\Roaming\XenoManager\AVKlyo045S.exe Process created: C:\Users\user\AppData\Roaming\XenoManager\AVKlyo045S.exe C:\Users\user\AppData\Roaming\XenoManager\AVKlyo045S.exe
Source: C:\Users\user\AppData\Roaming\XenoManager\AVKlyo045S.exe Process created: C:\Windows\SysWOW64\WerFault.exe C:\Windows\SysWOW64\WerFault.exe -u -p 6012 -s 80
Source: C:\Users\user\AppData\Roaming\XenoManager\AVKlyo045S.exe Process created: C:\Windows\SysWOW64\schtasks.exe "schtasks.exe" /Create /TN "cms" /XML "C:\Users\user\AppData\Local\Temp\tmpCEF4.tmp" /F
Source: C:\Windows\SysWOW64\schtasks.exe Process created: C:\Windows\System32\conhost.exe C:\Windows\system32\conhost.exe 0xffffffff -ForceV1
Source: unknown Process created: C:\Users\user\AppData\Roaming\XenoManager\AVKlyo045S.exe C:\Users\user\AppData\Roaming\XenoManager\AVKlyo045S.exe
Source: C:\Users\user\AppData\Roaming\XenoManager\AVKlyo045S.exe Process created: C:\Users\user\AppData\Roaming\XenoManager\AVKlyo045S.exe C:\Users\user\AppData\Roaming\XenoManager\AVKlyo045S.exe
Source: C:\Users\user\AppData\Roaming\XenoManager\AVKlyo045S.exe Process created: C:\Users\user\AppData\Roaming\XenoManager\AVKlyo045S.exe C:\Users\user\AppData\Roaming\XenoManager\AVKlyo045S.exe
Source: C:\Users\user\AppData\Roaming\XenoManager\AVKlyo045S.exe Process created: C:\Users\user\AppData\Roaming\XenoManager\AVKlyo045S.exe C:\Users\user\AppData\Roaming\XenoManager\AVKlyo045S.exe
Source: C:\Users\user\Desktop\AVKlyo045S.exe Process created: C:\Users\user\Desktop\AVKlyo045S.exe C:\Users\user\Desktop\AVKlyo045S.exe Jump to behavior
Source: C:\Users\user\Desktop\AVKlyo045S.exe Process created: C:\Users\user\Desktop\AVKlyo045S.exe C:\Users\user\Desktop\AVKlyo045S.exe Jump to behavior
Source: C:\Users\user\Desktop\AVKlyo045S.exe Process created: C:\Users\user\Desktop\AVKlyo045S.exe C:\Users\user\Desktop\AVKlyo045S.exe Jump to behavior
Source: C:\Users\user\Desktop\AVKlyo045S.exe Process created: C:\Users\user\AppData\Roaming\XenoManager\AVKlyo045S.exe "C:\Users\user\AppData\Roaming\XenoManager\AVKlyo045S.exe" Jump to behavior
Source: C:\Users\user\AppData\Roaming\XenoManager\AVKlyo045S.exe Process created: C:\Users\user\AppData\Roaming\XenoManager\AVKlyo045S.exe C:\Users\user\AppData\Roaming\XenoManager\AVKlyo045S.exe Jump to behavior
Source: C:\Users\user\AppData\Roaming\XenoManager\AVKlyo045S.exe Process created: C:\Users\user\AppData\Roaming\XenoManager\AVKlyo045S.exe C:\Users\user\AppData\Roaming\XenoManager\AVKlyo045S.exe Jump to behavior
Source: C:\Users\user\AppData\Roaming\XenoManager\AVKlyo045S.exe Process created: C:\Users\user\AppData\Roaming\XenoManager\AVKlyo045S.exe C:\Users\user\AppData\Roaming\XenoManager\AVKlyo045S.exe Jump to behavior
Source: C:\Users\user\AppData\Roaming\XenoManager\AVKlyo045S.exe Process created: C:\Windows\SysWOW64\schtasks.exe "schtasks.exe" /Create /TN "cms" /XML "C:\Users\user\AppData\Local\Temp\tmpCEF4.tmp" /F Jump to behavior
Source: C:\Users\user\AppData\Roaming\XenoManager\AVKlyo045S.exe Process created: C:\Users\user\AppData\Roaming\XenoManager\AVKlyo045S.exe C:\Users\user\AppData\Roaming\XenoManager\AVKlyo045S.exe Jump to behavior
Source: C:\Users\user\AppData\Roaming\XenoManager\AVKlyo045S.exe Process created: C:\Users\user\AppData\Roaming\XenoManager\AVKlyo045S.exe C:\Users\user\AppData\Roaming\XenoManager\AVKlyo045S.exe Jump to behavior
Source: C:\Users\user\AppData\Roaming\XenoManager\AVKlyo045S.exe Process created: C:\Users\user\AppData\Roaming\XenoManager\AVKlyo045S.exe C:\Users\user\AppData\Roaming\XenoManager\AVKlyo045S.exe Jump to behavior
Source: C:\Users\user\Desktop\AVKlyo045S.exe Section loaded: mscoree.dll Jump to behavior
Source: C:\Users\user\Desktop\AVKlyo045S.exe Section loaded: apphelp.dll Jump to behavior
Source: C:\Users\user\Desktop\AVKlyo045S.exe Section loaded: kernel.appcore.dll Jump to behavior
Source: C:\Users\user\Desktop\AVKlyo045S.exe Section loaded: version.dll Jump to behavior
Source: C:\Users\user\Desktop\AVKlyo045S.exe Section loaded: vcruntime140_clr0400.dll Jump to behavior
Source: C:\Users\user\Desktop\AVKlyo045S.exe Section loaded: ucrtbase_clr0400.dll Jump to behavior
Source: C:\Users\user\Desktop\AVKlyo045S.exe Section loaded: uxtheme.dll Jump to behavior
Source: C:\Users\user\Desktop\AVKlyo045S.exe Section loaded: wldp.dll Jump to behavior
Source: C:\Users\user\Desktop\AVKlyo045S.exe Section loaded: amsi.dll Jump to behavior
Source: C:\Users\user\Desktop\AVKlyo045S.exe Section loaded: userenv.dll Jump to behavior
Source: C:\Users\user\Desktop\AVKlyo045S.exe Section loaded: profapi.dll Jump to behavior
Source: C:\Users\user\Desktop\AVKlyo045S.exe Section loaded: msasn1.dll Jump to behavior
Source: C:\Users\user\Desktop\AVKlyo045S.exe Section loaded: gpapi.dll Jump to behavior
Source: C:\Users\user\Desktop\AVKlyo045S.exe Section loaded: cryptsp.dll Jump to behavior
Source: C:\Users\user\Desktop\AVKlyo045S.exe Section loaded: rsaenh.dll Jump to behavior
Source: C:\Users\user\Desktop\AVKlyo045S.exe Section loaded: cryptbase.dll Jump to behavior
Source: C:\Users\user\Desktop\AVKlyo045S.exe Section loaded: mscoree.dll Jump to behavior
Source: C:\Users\user\Desktop\AVKlyo045S.exe Section loaded: kernel.appcore.dll Jump to behavior
Source: C:\Users\user\Desktop\AVKlyo045S.exe Section loaded: version.dll Jump to behavior
Source: C:\Users\user\Desktop\AVKlyo045S.exe Section loaded: vcruntime140_clr0400.dll Jump to behavior
Source: C:\Users\user\Desktop\AVKlyo045S.exe Section loaded: ucrtbase_clr0400.dll Jump to behavior
Source: C:\Users\user\Desktop\AVKlyo045S.exe Section loaded: ntmarta.dll Jump to behavior
Source: C:\Users\user\Desktop\AVKlyo045S.exe Section loaded: uxtheme.dll Jump to behavior
Source: C:\Users\user\Desktop\AVKlyo045S.exe Section loaded: windows.storage.dll Jump to behavior
Source: C:\Users\user\Desktop\AVKlyo045S.exe Section loaded: wldp.dll Jump to behavior
Source: C:\Users\user\Desktop\AVKlyo045S.exe Section loaded: propsys.dll Jump to behavior
Source: C:\Users\user\Desktop\AVKlyo045S.exe Section loaded: profapi.dll Jump to behavior
Source: C:\Users\user\Desktop\AVKlyo045S.exe Section loaded: edputil.dll Jump to behavior
Source: C:\Users\user\Desktop\AVKlyo045S.exe Section loaded: urlmon.dll Jump to behavior
Source: C:\Users\user\Desktop\AVKlyo045S.exe Section loaded: iertutil.dll Jump to behavior
Source: C:\Users\user\Desktop\AVKlyo045S.exe Section loaded: srvcli.dll Jump to behavior
Source: C:\Users\user\Desktop\AVKlyo045S.exe Section loaded: netutils.dll Jump to behavior
Source: C:\Users\user\Desktop\AVKlyo045S.exe Section loaded: windows.staterepositoryps.dll Jump to behavior
Source: C:\Users\user\Desktop\AVKlyo045S.exe Section loaded: sspicli.dll Jump to behavior
Source: C:\Users\user\Desktop\AVKlyo045S.exe Section loaded: wintypes.dll Jump to behavior
Source: C:\Users\user\Desktop\AVKlyo045S.exe Section loaded: appresolver.dll Jump to behavior
Source: C:\Users\user\Desktop\AVKlyo045S.exe Section loaded: bcp47langs.dll Jump to behavior
Source: C:\Users\user\Desktop\AVKlyo045S.exe Section loaded: slc.dll Jump to behavior
Source: C:\Users\user\Desktop\AVKlyo045S.exe Section loaded: userenv.dll Jump to behavior
Source: C:\Users\user\Desktop\AVKlyo045S.exe Section loaded: sppc.dll Jump to behavior
Source: C:\Users\user\Desktop\AVKlyo045S.exe Section loaded: onecorecommonproxystub.dll Jump to behavior
Source: C:\Users\user\Desktop\AVKlyo045S.exe Section loaded: onecoreuapcommonproxystub.dll Jump to behavior
Source: C:\Users\user\Desktop\AVKlyo045S.exe Section loaded: apphelp.dll Jump to behavior
Source: C:\Users\user\AppData\Roaming\XenoManager\AVKlyo045S.exe Section loaded: mscoree.dll Jump to behavior
Source: C:\Users\user\AppData\Roaming\XenoManager\AVKlyo045S.exe Section loaded: apphelp.dll Jump to behavior
Source: C:\Users\user\AppData\Roaming\XenoManager\AVKlyo045S.exe Section loaded: kernel.appcore.dll Jump to behavior
Source: C:\Users\user\AppData\Roaming\XenoManager\AVKlyo045S.exe Section loaded: version.dll Jump to behavior
Source: C:\Users\user\AppData\Roaming\XenoManager\AVKlyo045S.exe Section loaded: vcruntime140_clr0400.dll Jump to behavior
Source: C:\Users\user\AppData\Roaming\XenoManager\AVKlyo045S.exe Section loaded: ucrtbase_clr0400.dll Jump to behavior
Source: C:\Users\user\AppData\Roaming\XenoManager\AVKlyo045S.exe Section loaded: ucrtbase_clr0400.dll Jump to behavior
Source: C:\Users\user\AppData\Roaming\XenoManager\AVKlyo045S.exe Section loaded: uxtheme.dll Jump to behavior
Source: C:\Users\user\AppData\Roaming\XenoManager\AVKlyo045S.exe Section loaded: wldp.dll Jump to behavior
Source: C:\Users\user\AppData\Roaming\XenoManager\AVKlyo045S.exe Section loaded: amsi.dll Jump to behavior
Source: C:\Users\user\AppData\Roaming\XenoManager\AVKlyo045S.exe Section loaded: userenv.dll Jump to behavior
Source: C:\Users\user\AppData\Roaming\XenoManager\AVKlyo045S.exe Section loaded: profapi.dll Jump to behavior
Source: C:\Users\user\AppData\Roaming\XenoManager\AVKlyo045S.exe Section loaded: msasn1.dll Jump to behavior
Source: C:\Users\user\AppData\Roaming\XenoManager\AVKlyo045S.exe Section loaded: gpapi.dll Jump to behavior
Source: C:\Users\user\AppData\Roaming\XenoManager\AVKlyo045S.exe Section loaded: cryptsp.dll Jump to behavior
Source: C:\Users\user\AppData\Roaming\XenoManager\AVKlyo045S.exe Section loaded: rsaenh.dll Jump to behavior
Source: C:\Users\user\AppData\Roaming\XenoManager\AVKlyo045S.exe Section loaded: cryptbase.dll Jump to behavior
Source: C:\Users\user\AppData\Roaming\XenoManager\AVKlyo045S.exe Section loaded: mscoree.dll Jump to behavior
Source: C:\Users\user\AppData\Roaming\XenoManager\AVKlyo045S.exe Section loaded: kernel.appcore.dll Jump to behavior
Source: C:\Users\user\AppData\Roaming\XenoManager\AVKlyo045S.exe Section loaded: version.dll Jump to behavior
Source: C:\Users\user\AppData\Roaming\XenoManager\AVKlyo045S.exe Section loaded: vcruntime140_clr0400.dll Jump to behavior
Source: C:\Users\user\AppData\Roaming\XenoManager\AVKlyo045S.exe Section loaded: ucrtbase_clr0400.dll Jump to behavior
Source: C:\Users\user\AppData\Roaming\XenoManager\AVKlyo045S.exe Section loaded: windows.storage.dll Jump to behavior
Source: C:\Users\user\AppData\Roaming\XenoManager\AVKlyo045S.exe Section loaded: wldp.dll Jump to behavior
Source: C:\Users\user\AppData\Roaming\XenoManager\AVKlyo045S.exe Section loaded: profapi.dll Jump to behavior
Source: C:\Users\user\AppData\Roaming\XenoManager\AVKlyo045S.exe Section loaded: cryptsp.dll Jump to behavior
Source: C:\Users\user\AppData\Roaming\XenoManager\AVKlyo045S.exe Section loaded: rsaenh.dll Jump to behavior
Source: C:\Users\user\AppData\Roaming\XenoManager\AVKlyo045S.exe Section loaded: cryptbase.dll Jump to behavior
Source: C:\Users\user\AppData\Roaming\XenoManager\AVKlyo045S.exe Section loaded: mswsock.dll Jump to behavior
Source: C:\Users\user\AppData\Roaming\XenoManager\AVKlyo045S.exe Section loaded: mscoree.dll Jump to behavior
Source: C:\Users\user\AppData\Roaming\XenoManager\AVKlyo045S.exe Section loaded: kernel.appcore.dll Jump to behavior
Source: C:\Users\user\AppData\Roaming\XenoManager\AVKlyo045S.exe Section loaded: version.dll Jump to behavior
Source: C:\Users\user\AppData\Roaming\XenoManager\AVKlyo045S.exe Section loaded: vcruntime140_clr0400.dll Jump to behavior
Source: C:\Users\user\AppData\Roaming\XenoManager\AVKlyo045S.exe Section loaded: ucrtbase_clr0400.dll Jump to behavior
Source: C:\Users\user\AppData\Roaming\XenoManager\AVKlyo045S.exe Section loaded: ucrtbase_clr0400.dll Jump to behavior
Source: C:\Windows\SysWOW64\schtasks.exe Section loaded: kernel.appcore.dll Jump to behavior
Source: C:\Windows\SysWOW64\schtasks.exe Section loaded: taskschd.dll Jump to behavior
Source: C:\Windows\SysWOW64\schtasks.exe Section loaded: sspicli.dll Jump to behavior
Source: C:\Users\user\AppData\Roaming\XenoManager\AVKlyo045S.exe Section loaded: mscoree.dll Jump to behavior
Source: C:\Users\user\AppData\Roaming\XenoManager\AVKlyo045S.exe Section loaded: kernel.appcore.dll Jump to behavior
Source: C:\Users\user\AppData\Roaming\XenoManager\AVKlyo045S.exe Section loaded: version.dll Jump to behavior
Source: C:\Users\user\AppData\Roaming\XenoManager\AVKlyo045S.exe Section loaded: vcruntime140_clr0400.dll Jump to behavior
Source: C:\Users\user\AppData\Roaming\XenoManager\AVKlyo045S.exe Section loaded: ucrtbase_clr0400.dll Jump to behavior
Source: C:\Users\user\AppData\Roaming\XenoManager\AVKlyo045S.exe Section loaded: ucrtbase_clr0400.dll Jump to behavior
Source: C:\Users\user\AppData\Roaming\XenoManager\AVKlyo045S.exe Section loaded: uxtheme.dll Jump to behavior
Source: C:\Users\user\AppData\Roaming\XenoManager\AVKlyo045S.exe Section loaded: wldp.dll Jump to behavior
Source: C:\Users\user\AppData\Roaming\XenoManager\AVKlyo045S.exe Section loaded: amsi.dll Jump to behavior
Source: C:\Users\user\AppData\Roaming\XenoManager\AVKlyo045S.exe Section loaded: userenv.dll Jump to behavior
Source: C:\Users\user\AppData\Roaming\XenoManager\AVKlyo045S.exe Section loaded: profapi.dll Jump to behavior
Source: C:\Users\user\AppData\Roaming\XenoManager\AVKlyo045S.exe Section loaded: msasn1.dll Jump to behavior
Source: C:\Users\user\AppData\Roaming\XenoManager\AVKlyo045S.exe Section loaded: gpapi.dll Jump to behavior
Source: C:\Users\user\AppData\Roaming\XenoManager\AVKlyo045S.exe Section loaded: cryptsp.dll Jump to behavior
Source: C:\Users\user\AppData\Roaming\XenoManager\AVKlyo045S.exe Section loaded: rsaenh.dll Jump to behavior
Source: C:\Users\user\AppData\Roaming\XenoManager\AVKlyo045S.exe Section loaded: cryptbase.dll Jump to behavior
Source: C:\Users\user\AppData\Roaming\XenoManager\AVKlyo045S.exe Section loaded: mscoree.dll Jump to behavior
Source: C:\Users\user\AppData\Roaming\XenoManager\AVKlyo045S.exe Section loaded: kernel.appcore.dll Jump to behavior
Source: C:\Users\user\AppData\Roaming\XenoManager\AVKlyo045S.exe Section loaded: version.dll Jump to behavior
Source: C:\Users\user\AppData\Roaming\XenoManager\AVKlyo045S.exe Section loaded: vcruntime140_clr0400.dll Jump to behavior
Source: C:\Users\user\AppData\Roaming\XenoManager\AVKlyo045S.exe Section loaded: ucrtbase_clr0400.dll Jump to behavior
Source: C:\Users\user\AppData\Roaming\XenoManager\AVKlyo045S.exe Section loaded: mscoree.dll Jump to behavior
Source: C:\Users\user\AppData\Roaming\XenoManager\AVKlyo045S.exe Section loaded: kernel.appcore.dll Jump to behavior
Source: C:\Users\user\AppData\Roaming\XenoManager\AVKlyo045S.exe Section loaded: version.dll Jump to behavior
Source: C:\Users\user\AppData\Roaming\XenoManager\AVKlyo045S.exe Section loaded: vcruntime140_clr0400.dll Jump to behavior
Source: C:\Users\user\AppData\Roaming\XenoManager\AVKlyo045S.exe Section loaded: ucrtbase_clr0400.dll Jump to behavior
Source: C:\Users\user\AppData\Roaming\XenoManager\AVKlyo045S.exe Section loaded: mscoree.dll Jump to behavior
Source: C:\Users\user\AppData\Roaming\XenoManager\AVKlyo045S.exe Section loaded: kernel.appcore.dll Jump to behavior
Source: C:\Users\user\AppData\Roaming\XenoManager\AVKlyo045S.exe Section loaded: version.dll Jump to behavior
Source: C:\Users\user\AppData\Roaming\XenoManager\AVKlyo045S.exe Section loaded: vcruntime140_clr0400.dll Jump to behavior
Source: C:\Users\user\AppData\Roaming\XenoManager\AVKlyo045S.exe Section loaded: ucrtbase_clr0400.dll Jump to behavior
Source: C:\Users\user\AppData\Roaming\XenoManager\AVKlyo045S.exe Section loaded: ucrtbase_clr0400.dll Jump to behavior
Source: C:\Users\user\Desktop\AVKlyo045S.exe Key value queried: HKEY_LOCAL_MACHINE\SOFTWARE\Classes\WOW6432Node\CLSID\{0EE7644B-1BAD-48B1-9889-0281C206EB85}\InprocServer32 Jump to behavior
Source: C:\Users\user\Desktop\AVKlyo045S.exe File opened: C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscorrc.dll Jump to behavior
Source: AVKlyo045S.exe Static PE information: data directory type: IMAGE_DIRECTORY_ENTRY_COM_DESCRIPTOR
Source: AVKlyo045S.exe Static PE information: HIGH_ENTROPY_VA, DYNAMIC_BASE, NX_COMPAT, NO_SEH, TERMINAL_SERVER_AWARE

Data Obfuscation

barindex
Source: 1.2.AVKlyo045S.exe.24cd62c.0.raw.unpack, DllHandler.cs .Net Code: DllNodeHandler System.Reflection.Assembly.Load(byte[])
Source: 1.2.AVKlyo045S.exe.24cd62c.0.raw.unpack, DllHandler.cs .Net Code: DllNodeHandler
Source: 6.2.AVKlyo045S.exe.2b2d670.0.raw.unpack, DllHandler.cs .Net Code: DllNodeHandler System.Reflection.Assembly.Load(byte[])
Source: 6.2.AVKlyo045S.exe.2b2d670.0.raw.unpack, DllHandler.cs .Net Code: DllNodeHandler
Source: 22.2.AVKlyo045S.exe.2f4e63c.0.raw.unpack, DllHandler.cs .Net Code: DllNodeHandler System.Reflection.Assembly.Load(byte[])
Source: 22.2.AVKlyo045S.exe.2f4e63c.0.raw.unpack, DllHandler.cs .Net Code: DllNodeHandler
Source: C:\Users\user\Desktop\AVKlyo045S.exe Code function: 1_2_00A1AB2B pushad ; iretd 1_2_00A1AB2F
Source: C:\Users\user\Desktop\AVKlyo045S.exe Code function: 1_2_0A3A4694 push E904A423h; retf 1_2_0A3A4699
Source: C:\Users\user\Desktop\AVKlyo045S.exe Code function: 1_2_0A3A9885 push esp; retf 1_2_0A3A9889
Source: C:\Users\user\Desktop\AVKlyo045S.exe Code function: 1_2_0A3A650E push 0163BA48h; iretd 1_2_0A3A6522
Source: C:\Users\user\Desktop\AVKlyo045S.exe Code function: 1_2_0A3A45EF push 8BFFFFFFh; retf 1_2_0A3A45F5
Source: C:\Users\user\AppData\Roaming\XenoManager\AVKlyo045S.exe Code function: 6_2_00F4AB2B pushad ; iretd 6_2_00F4AB2F
Source: C:\Users\user\AppData\Roaming\XenoManager\AVKlyo045S.exe Code function: 6_2_0A8B4694 push E90DCC23h; retf 6_2_0A8B4699
Source: C:\Users\user\AppData\Roaming\XenoManager\AVKlyo045S.exe Code function: 6_2_0A8B9885 push esp; retf 6_2_0A8B9889
Source: C:\Users\user\AppData\Roaming\XenoManager\AVKlyo045S.exe Code function: 6_2_0A8B45EF push 8BFFFFFFh; retf 6_2_0A8B45F5
Source: C:\Users\user\AppData\Roaming\XenoManager\AVKlyo045S.exe Code function: 6_2_0A8B651B push 0163BA48h; iretd 6_2_0A8B6522
Source: C:\Users\user\AppData\Roaming\XenoManager\AVKlyo045S.exe Code function: 22_2_012DAB2B pushad ; iretd 22_2_012DAB2F
Source: C:\Users\user\AppData\Roaming\XenoManager\AVKlyo045S.exe Code function: 22_2_066A4694 push E904FD23h; retf 22_2_066A4699
Source: C:\Users\user\AppData\Roaming\XenoManager\AVKlyo045S.exe Code function: 22_2_066A4FCD push 00000006h; ret 22_2_066A4FD8
Source: C:\Users\user\AppData\Roaming\XenoManager\AVKlyo045S.exe Code function: 22_2_066A9885 push esp; retf 22_2_066A9889
Source: C:\Users\user\AppData\Roaming\XenoManager\AVKlyo045S.exe Code function: 22_2_066AB165 push 00000006h; retf 22_2_066AB168
Source: C:\Users\user\AppData\Roaming\XenoManager\AVKlyo045S.exe Code function: 22_2_066A651B push 0163BA48h; iretd 22_2_066A6522
Source: C:\Users\user\AppData\Roaming\XenoManager\AVKlyo045S.exe Code function: 22_2_066A45EF push 8BFFFFFFh; retf 22_2_066A45F5
Source: AVKlyo045S.exe Static PE information: section name: .text entropy: 7.650287897774288
Source: AVKlyo045S.exe.5.dr Static PE information: section name: .text entropy: 7.650287897774288
Source: C:\Users\user\Desktop\AVKlyo045S.exe File created: C:\Users\user\AppData\Roaming\XenoManager\AVKlyo045S.exe Jump to dropped file

Boot Survival

barindex
Source: C:\Users\user\AppData\Roaming\XenoManager\AVKlyo045S.exe Process created: C:\Windows\SysWOW64\schtasks.exe "schtasks.exe" /Create /TN "cms" /XML "C:\Users\user\AppData\Local\Temp\tmpCEF4.tmp" /F
Source: C:\Users\user\Desktop\AVKlyo045S.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Users\user\Desktop\AVKlyo045S.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Users\user\Desktop\AVKlyo045S.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Users\user\Desktop\AVKlyo045S.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Users\user\Desktop\AVKlyo045S.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Users\user\Desktop\AVKlyo045S.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Users\user\Desktop\AVKlyo045S.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Users\user\Desktop\AVKlyo045S.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Users\user\Desktop\AVKlyo045S.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Users\user\Desktop\AVKlyo045S.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Users\user\Desktop\AVKlyo045S.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Users\user\Desktop\AVKlyo045S.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Users\user\Desktop\AVKlyo045S.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Users\user\Desktop\AVKlyo045S.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Users\user\Desktop\AVKlyo045S.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Users\user\Desktop\AVKlyo045S.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Users\user\Desktop\AVKlyo045S.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Users\user\Desktop\AVKlyo045S.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Users\user\Desktop\AVKlyo045S.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Users\user\Desktop\AVKlyo045S.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Users\user\Desktop\AVKlyo045S.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Users\user\Desktop\AVKlyo045S.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Users\user\Desktop\AVKlyo045S.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Users\user\Desktop\AVKlyo045S.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Users\user\Desktop\AVKlyo045S.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Users\user\Desktop\AVKlyo045S.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Users\user\Desktop\AVKlyo045S.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Users\user\Desktop\AVKlyo045S.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Users\user\Desktop\AVKlyo045S.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Users\user\Desktop\AVKlyo045S.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Users\user\Desktop\AVKlyo045S.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Users\user\Desktop\AVKlyo045S.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Users\user\Desktop\AVKlyo045S.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Users\user\Desktop\AVKlyo045S.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Users\user\Desktop\AVKlyo045S.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Users\user\Desktop\AVKlyo045S.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Users\user\Desktop\AVKlyo045S.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Users\user\Desktop\AVKlyo045S.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Users\user\Desktop\AVKlyo045S.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Users\user\Desktop\AVKlyo045S.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Users\user\AppData\Roaming\XenoManager\AVKlyo045S.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Users\user\AppData\Roaming\XenoManager\AVKlyo045S.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Users\user\AppData\Roaming\XenoManager\AVKlyo045S.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Users\user\AppData\Roaming\XenoManager\AVKlyo045S.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Users\user\AppData\Roaming\XenoManager\AVKlyo045S.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Users\user\AppData\Roaming\XenoManager\AVKlyo045S.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Users\user\AppData\Roaming\XenoManager\AVKlyo045S.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Users\user\AppData\Roaming\XenoManager\AVKlyo045S.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Users\user\AppData\Roaming\XenoManager\AVKlyo045S.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Users\user\AppData\Roaming\XenoManager\AVKlyo045S.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Users\user\AppData\Roaming\XenoManager\AVKlyo045S.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Users\user\AppData\Roaming\XenoManager\AVKlyo045S.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Users\user\AppData\Roaming\XenoManager\AVKlyo045S.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Users\user\AppData\Roaming\XenoManager\AVKlyo045S.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Users\user\AppData\Roaming\XenoManager\AVKlyo045S.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Users\user\AppData\Roaming\XenoManager\AVKlyo045S.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Users\user\AppData\Roaming\XenoManager\AVKlyo045S.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Users\user\AppData\Roaming\XenoManager\AVKlyo045S.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Users\user\AppData\Roaming\XenoManager\AVKlyo045S.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Users\user\AppData\Roaming\XenoManager\AVKlyo045S.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Users\user\AppData\Roaming\XenoManager\AVKlyo045S.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Users\user\AppData\Roaming\XenoManager\AVKlyo045S.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Users\user\AppData\Roaming\XenoManager\AVKlyo045S.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Users\user\AppData\Roaming\XenoManager\AVKlyo045S.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Users\user\AppData\Roaming\XenoManager\AVKlyo045S.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Windows\SysWOW64\WerFault.exe Process information set: FAILCRITICALERRORS | NOGPFAULTERRORBOX Jump to behavior
Source: C:\Windows\SysWOW64\WerFault.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Windows\SysWOW64\WerFault.exe Process information set: FAILCRITICALERRORS | NOGPFAULTERRORBOX Jump to behavior
Source: C:\Windows\SysWOW64\WerFault.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Windows\SysWOW64\WerFault.exe Process information set: FAILCRITICALERRORS | NOGPFAULTERRORBOX Jump to behavior
Source: C:\Windows\SysWOW64\WerFault.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Windows\SysWOW64\WerFault.exe Process information set: FAILCRITICALERRORS | NOGPFAULTERRORBOX Jump to behavior
Source: C:\Windows\SysWOW64\WerFault.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Windows\SysWOW64\WerFault.exe Process information set: FAILCRITICALERRORS | NOGPFAULTERRORBOX Jump to behavior
Source: C:\Windows\SysWOW64\WerFault.exe Process information set: FAILCRITICALERRORS | NOGPFAULTERRORBOX Jump to behavior
Source: C:\Windows\SysWOW64\WerFault.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Windows\SysWOW64\WerFault.exe Process information set: FAILCRITICALERRORS | NOGPFAULTERRORBOX Jump to behavior
Source: C:\Windows\SysWOW64\WerFault.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Windows\SysWOW64\WerFault.exe Process information set: FAILCRITICALERRORS | NOGPFAULTERRORBOX Jump to behavior
Source: C:\Windows\SysWOW64\WerFault.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Windows\SysWOW64\WerFault.exe Process information set: FAILCRITICALERRORS | NOGPFAULTERRORBOX Jump to behavior
Source: C:\Windows\SysWOW64\WerFault.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Windows\SysWOW64\WerFault.exe Process information set: FAILCRITICALERRORS | NOGPFAULTERRORBOX Jump to behavior
Source: C:\Users\user\AppData\Roaming\XenoManager\AVKlyo045S.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Users\user\AppData\Roaming\XenoManager\AVKlyo045S.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Users\user\AppData\Roaming\XenoManager\AVKlyo045S.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Users\user\AppData\Roaming\XenoManager\AVKlyo045S.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Users\user\AppData\Roaming\XenoManager\AVKlyo045S.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Users\user\AppData\Roaming\XenoManager\AVKlyo045S.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Users\user\AppData\Roaming\XenoManager\AVKlyo045S.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Users\user\AppData\Roaming\XenoManager\AVKlyo045S.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Users\user\AppData\Roaming\XenoManager\AVKlyo045S.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Users\user\AppData\Roaming\XenoManager\AVKlyo045S.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Users\user\AppData\Roaming\XenoManager\AVKlyo045S.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Users\user\AppData\Roaming\XenoManager\AVKlyo045S.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Users\user\AppData\Roaming\XenoManager\AVKlyo045S.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Users\user\AppData\Roaming\XenoManager\AVKlyo045S.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Users\user\AppData\Roaming\XenoManager\AVKlyo045S.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Users\user\AppData\Roaming\XenoManager\AVKlyo045S.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Users\user\AppData\Roaming\XenoManager\AVKlyo045S.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Users\user\AppData\Roaming\XenoManager\AVKlyo045S.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Users\user\AppData\Roaming\XenoManager\AVKlyo045S.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Users\user\AppData\Roaming\XenoManager\AVKlyo045S.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Users\user\AppData\Roaming\XenoManager\AVKlyo045S.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Users\user\AppData\Roaming\XenoManager\AVKlyo045S.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Users\user\AppData\Roaming\XenoManager\AVKlyo045S.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Users\user\AppData\Roaming\XenoManager\AVKlyo045S.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Users\user\AppData\Roaming\XenoManager\AVKlyo045S.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Users\user\AppData\Roaming\XenoManager\AVKlyo045S.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Users\user\AppData\Roaming\XenoManager\AVKlyo045S.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Users\user\AppData\Roaming\XenoManager\AVKlyo045S.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Users\user\AppData\Roaming\XenoManager\AVKlyo045S.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Users\user\AppData\Roaming\XenoManager\AVKlyo045S.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Users\user\AppData\Roaming\XenoManager\AVKlyo045S.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Users\user\AppData\Roaming\XenoManager\AVKlyo045S.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Users\user\AppData\Roaming\XenoManager\AVKlyo045S.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Users\user\AppData\Roaming\XenoManager\AVKlyo045S.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Users\user\AppData\Roaming\XenoManager\AVKlyo045S.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Users\user\AppData\Roaming\XenoManager\AVKlyo045S.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Users\user\AppData\Roaming\XenoManager\AVKlyo045S.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Users\user\AppData\Roaming\XenoManager\AVKlyo045S.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Users\user\AppData\Roaming\XenoManager\AVKlyo045S.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Users\user\AppData\Roaming\XenoManager\AVKlyo045S.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Users\user\AppData\Roaming\XenoManager\AVKlyo045S.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Users\user\AppData\Roaming\XenoManager\AVKlyo045S.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Users\user\AppData\Roaming\XenoManager\AVKlyo045S.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Users\user\AppData\Roaming\XenoManager\AVKlyo045S.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Users\user\AppData\Roaming\XenoManager\AVKlyo045S.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Windows\SysWOW64\WerFault.exe Process information set: FAILCRITICALERRORS | NOGPFAULTERRORBOX Jump to behavior
Source: C:\Windows\SysWOW64\WerFault.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Windows\SysWOW64\WerFault.exe Process information set: FAILCRITICALERRORS | NOGPFAULTERRORBOX Jump to behavior
Source: C:\Windows\SysWOW64\WerFault.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Windows\SysWOW64\WerFault.exe Process information set: FAILCRITICALERRORS | NOGPFAULTERRORBOX Jump to behavior
Source: C:\Windows\SysWOW64\WerFault.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Windows\SysWOW64\WerFault.exe Process information set: FAILCRITICALERRORS | NOGPFAULTERRORBOX Jump to behavior
Source: C:\Windows\SysWOW64\WerFault.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Windows\SysWOW64\WerFault.exe Process information set: FAILCRITICALERRORS | NOGPFAULTERRORBOX Jump to behavior
Source: C:\Users\user\AppData\Roaming\XenoManager\AVKlyo045S.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Users\user\AppData\Roaming\XenoManager\AVKlyo045S.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Users\user\AppData\Roaming\XenoManager\AVKlyo045S.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Users\user\AppData\Roaming\XenoManager\AVKlyo045S.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Users\user\AppData\Roaming\XenoManager\AVKlyo045S.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Users\user\AppData\Roaming\XenoManager\AVKlyo045S.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Users\user\AppData\Roaming\XenoManager\AVKlyo045S.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Users\user\AppData\Roaming\XenoManager\AVKlyo045S.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Users\user\AppData\Roaming\XenoManager\AVKlyo045S.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Users\user\AppData\Roaming\XenoManager\AVKlyo045S.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Users\user\AppData\Roaming\XenoManager\AVKlyo045S.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Users\user\AppData\Roaming\XenoManager\AVKlyo045S.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Users\user\AppData\Roaming\XenoManager\AVKlyo045S.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Users\user\AppData\Roaming\XenoManager\AVKlyo045S.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Users\user\AppData\Roaming\XenoManager\AVKlyo045S.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Users\user\AppData\Roaming\XenoManager\AVKlyo045S.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Users\user\AppData\Roaming\XenoManager\AVKlyo045S.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Users\user\AppData\Roaming\XenoManager\AVKlyo045S.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Users\user\AppData\Roaming\XenoManager\AVKlyo045S.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Users\user\AppData\Roaming\XenoManager\AVKlyo045S.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Users\user\AppData\Roaming\XenoManager\AVKlyo045S.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Users\user\AppData\Roaming\XenoManager\AVKlyo045S.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Users\user\AppData\Roaming\XenoManager\AVKlyo045S.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Users\user\AppData\Roaming\XenoManager\AVKlyo045S.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Users\user\AppData\Roaming\XenoManager\AVKlyo045S.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Users\user\AppData\Roaming\XenoManager\AVKlyo045S.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Users\user\AppData\Roaming\XenoManager\AVKlyo045S.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Users\user\AppData\Roaming\XenoManager\AVKlyo045S.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Users\user\AppData\Roaming\XenoManager\AVKlyo045S.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Users\user\AppData\Roaming\XenoManager\AVKlyo045S.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Users\user\AppData\Roaming\XenoManager\AVKlyo045S.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Users\user\AppData\Roaming\XenoManager\AVKlyo045S.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Users\user\AppData\Roaming\XenoManager\AVKlyo045S.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Users\user\AppData\Roaming\XenoManager\AVKlyo045S.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Users\user\AppData\Roaming\XenoManager\AVKlyo045S.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Users\user\AppData\Roaming\XenoManager\AVKlyo045S.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Users\user\AppData\Roaming\XenoManager\AVKlyo045S.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Users\user\AppData\Roaming\XenoManager\AVKlyo045S.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Users\user\AppData\Roaming\XenoManager\AVKlyo045S.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Users\user\AppData\Roaming\XenoManager\AVKlyo045S.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Users\user\AppData\Roaming\XenoManager\AVKlyo045S.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Users\user\AppData\Roaming\XenoManager\AVKlyo045S.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Users\user\AppData\Roaming\XenoManager\AVKlyo045S.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Users\user\AppData\Roaming\XenoManager\AVKlyo045S.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Users\user\AppData\Roaming\XenoManager\AVKlyo045S.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Users\user\AppData\Roaming\XenoManager\AVKlyo045S.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Users\user\AppData\Roaming\XenoManager\AVKlyo045S.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Users\user\AppData\Roaming\XenoManager\AVKlyo045S.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Users\user\AppData\Roaming\XenoManager\AVKlyo045S.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Users\user\AppData\Roaming\XenoManager\AVKlyo045S.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Users\user\AppData\Roaming\XenoManager\AVKlyo045S.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Users\user\AppData\Roaming\XenoManager\AVKlyo045S.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Users\user\AppData\Roaming\XenoManager\AVKlyo045S.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Users\user\AppData\Roaming\XenoManager\AVKlyo045S.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Users\user\AppData\Roaming\XenoManager\AVKlyo045S.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Users\user\AppData\Roaming\XenoManager\AVKlyo045S.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Users\user\AppData\Roaming\XenoManager\AVKlyo045S.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Users\user\AppData\Roaming\XenoManager\AVKlyo045S.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Users\user\AppData\Roaming\XenoManager\AVKlyo045S.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Users\user\AppData\Roaming\XenoManager\AVKlyo045S.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Users\user\AppData\Roaming\XenoManager\AVKlyo045S.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Users\user\AppData\Roaming\XenoManager\AVKlyo045S.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Users\user\AppData\Roaming\XenoManager\AVKlyo045S.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Users\user\AppData\Roaming\XenoManager\AVKlyo045S.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Users\user\AppData\Roaming\XenoManager\AVKlyo045S.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Users\user\AppData\Roaming\XenoManager\AVKlyo045S.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Users\user\AppData\Roaming\XenoManager\AVKlyo045S.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Users\user\Desktop\AVKlyo045S.exe Memory allocated: A10000 memory reserve | memory write watch Jump to behavior
Source: C:\Users\user\Desktop\AVKlyo045S.exe Memory allocated: 24C0000 memory reserve | memory write watch Jump to behavior
Source: C:\Users\user\Desktop\AVKlyo045S.exe Memory allocated: 44C0000 memory reserve | memory write watch Jump to behavior
Source: C:\Users\user\Desktop\AVKlyo045S.exe Memory allocated: 4C00000 memory reserve | memory write watch Jump to behavior
Source: C:\Users\user\Desktop\AVKlyo045S.exe Memory allocated: 5C00000 memory reserve | memory write watch Jump to behavior
Source: C:\Users\user\Desktop\AVKlyo045S.exe Memory allocated: 5D30000 memory reserve | memory write watch Jump to behavior
Source: C:\Users\user\Desktop\AVKlyo045S.exe Memory allocated: 6D30000 memory reserve | memory write watch Jump to behavior
Source: C:\Users\user\Desktop\AVKlyo045S.exe Memory allocated: 7180000 memory reserve | memory write watch Jump to behavior
Source: C:\Users\user\Desktop\AVKlyo045S.exe Memory allocated: 8180000 memory reserve | memory write watch Jump to behavior
Source: C:\Users\user\Desktop\AVKlyo045S.exe Memory allocated: 9180000 memory reserve | memory write watch Jump to behavior
Source: C:\Users\user\Desktop\AVKlyo045S.exe Memory allocated: A180000 memory reserve | memory write watch Jump to behavior
Source: C:\Users\user\Desktop\AVKlyo045S.exe Memory allocated: B280000 memory reserve | memory write watch Jump to behavior
Source: C:\Users\user\Desktop\AVKlyo045S.exe Memory allocated: B710000 memory reserve | memory write watch Jump to behavior
Source: C:\Users\user\Desktop\AVKlyo045S.exe Memory allocated: C710000 memory reserve | memory write watch Jump to behavior
Source: C:\Users\user\Desktop\AVKlyo045S.exe Memory allocated: 4C00000 memory reserve | memory write watch Jump to behavior
Source: C:\Users\user\Desktop\AVKlyo045S.exe Memory allocated: 5D30000 memory reserve | memory write watch Jump to behavior
Source: C:\Users\user\Desktop\AVKlyo045S.exe Memory allocated: 7180000 memory reserve | memory write watch Jump to behavior
Source: C:\Users\user\Desktop\AVKlyo045S.exe Memory allocated: 8180000 memory reserve | memory write watch Jump to behavior
Source: C:\Users\user\Desktop\AVKlyo045S.exe Memory allocated: 9180000 memory reserve | memory write watch Jump to behavior
Source: C:\Users\user\Desktop\AVKlyo045S.exe Memory allocated: 9B0000 memory reserve | memory write watch Jump to behavior
Source: C:\Users\user\Desktop\AVKlyo045S.exe Memory allocated: 28F0000 memory reserve | memory write watch Jump to behavior
Source: C:\Users\user\Desktop\AVKlyo045S.exe Memory allocated: E90000 memory reserve | memory write watch Jump to behavior
Source: C:\Users\user\AppData\Roaming\XenoManager\AVKlyo045S.exe Memory allocated: F20000 memory reserve | memory write watch Jump to behavior
Source: C:\Users\user\AppData\Roaming\XenoManager\AVKlyo045S.exe Memory allocated: 2B20000 memory reserve | memory write watch Jump to behavior
Source: C:\Users\user\AppData\Roaming\XenoManager\AVKlyo045S.exe Memory allocated: 27A0000 memory reserve | memory write watch Jump to behavior
Source: C:\Users\user\AppData\Roaming\XenoManager\AVKlyo045S.exe Memory allocated: 5100000 memory reserve | memory write watch Jump to behavior
Source: C:\Users\user\AppData\Roaming\XenoManager\AVKlyo045S.exe Memory allocated: 6100000 memory reserve | memory write watch Jump to behavior
Source: C:\Users\user\AppData\Roaming\XenoManager\AVKlyo045S.exe Memory allocated: 6230000 memory reserve | memory write watch Jump to behavior
Source: C:\Users\user\AppData\Roaming\XenoManager\AVKlyo045S.exe Memory allocated: 7230000 memory reserve | memory write watch Jump to behavior
Source: C:\Users\user\AppData\Roaming\XenoManager\AVKlyo045S.exe Memory allocated: 7680000 memory reserve | memory write watch Jump to behavior
Source: C:\Users\user\AppData\Roaming\XenoManager\AVKlyo045S.exe Memory allocated: 8680000 memory reserve | memory write watch Jump to behavior
Source: C:\Users\user\AppData\Roaming\XenoManager\AVKlyo045S.exe Memory allocated: 9680000 memory reserve | memory write watch Jump to behavior
Source: C:\Users\user\AppData\Roaming\XenoManager\AVKlyo045S.exe Memory allocated: A680000 memory reserve | memory write watch Jump to behavior
Source: C:\Users\user\AppData\Roaming\XenoManager\AVKlyo045S.exe Memory allocated: B780000 memory reserve | memory write watch Jump to behavior
Source: C:\Users\user\AppData\Roaming\XenoManager\AVKlyo045S.exe Memory allocated: BC10000 memory reserve | memory write watch Jump to behavior
Source: C:\Users\user\AppData\Roaming\XenoManager\AVKlyo045S.exe Memory allocated: CC10000 memory reserve | memory write watch Jump to behavior
Source: C:\Users\user\AppData\Roaming\XenoManager\AVKlyo045S.exe Memory allocated: 5100000 memory reserve | memory write watch Jump to behavior
Source: C:\Users\user\AppData\Roaming\XenoManager\AVKlyo045S.exe Memory allocated: 6230000 memory reserve | memory write watch Jump to behavior
Source: C:\Users\user\AppData\Roaming\XenoManager\AVKlyo045S.exe Memory allocated: 7680000 memory reserve | memory write watch Jump to behavior
Source: C:\Users\user\AppData\Roaming\XenoManager\AVKlyo045S.exe Memory allocated: 8680000 memory reserve | memory write watch Jump to behavior
Source: C:\Users\user\AppData\Roaming\XenoManager\AVKlyo045S.exe Memory allocated: 9680000 memory reserve | memory write watch Jump to behavior
Source: C:\Users\user\AppData\Roaming\XenoManager\AVKlyo045S.exe Memory allocated: 1790000 memory reserve | memory write watch Jump to behavior
Source: C:\Users\user\AppData\Roaming\XenoManager\AVKlyo045S.exe Memory allocated: 3100000 memory reserve | memory write watch Jump to behavior
Source: C:\Users\user\AppData\Roaming\XenoManager\AVKlyo045S.exe Memory allocated: 5100000 memory reserve | memory write watch Jump to behavior
Source: C:\Users\user\AppData\Roaming\XenoManager\AVKlyo045S.exe Memory allocated: 2B20000 memory reserve | memory write watch Jump to behavior
Source: C:\Users\user\AppData\Roaming\XenoManager\AVKlyo045S.exe Memory allocated: 2DB0000 memory reserve | memory write watch Jump to behavior
Source: C:\Users\user\AppData\Roaming\XenoManager\AVKlyo045S.exe Memory allocated: 2B20000 memory reserve | memory write watch Jump to behavior
Source: C:\Users\user\AppData\Roaming\XenoManager\AVKlyo045S.exe Memory allocated: 12D0000 memory reserve | memory write watch Jump to behavior
Source: C:\Users\user\AppData\Roaming\XenoManager\AVKlyo045S.exe Memory allocated: 2F40000 memory reserve | memory write watch Jump to behavior
Source: C:\Users\user\AppData\Roaming\XenoManager\AVKlyo045S.exe Memory allocated: 4F40000 memory reserve | memory write watch Jump to behavior
Source: C:\Users\user\AppData\Roaming\XenoManager\AVKlyo045S.exe Memory allocated: 5610000 memory reserve | memory write watch Jump to behavior
Source: C:\Users\user\AppData\Roaming\XenoManager\AVKlyo045S.exe Memory allocated: 6610000 memory reserve | memory write watch Jump to behavior
Source: C:\Users\user\AppData\Roaming\XenoManager\AVKlyo045S.exe Memory allocated: 6740000 memory reserve | memory write watch Jump to behavior
Source: C:\Users\user\AppData\Roaming\XenoManager\AVKlyo045S.exe Memory allocated: 7740000 memory reserve | memory write watch Jump to behavior
Source: C:\Users\user\AppData\Roaming\XenoManager\AVKlyo045S.exe Memory allocated: 7AD0000 memory reserve | memory write watch Jump to behavior
Source: C:\Users\user\AppData\Roaming\XenoManager\AVKlyo045S.exe Memory allocated: 8AD0000 memory reserve | memory write watch Jump to behavior
Source: C:\Users\user\AppData\Roaming\XenoManager\AVKlyo045S.exe Memory allocated: 5610000 memory reserve | memory write watch Jump to behavior
Source: C:\Users\user\AppData\Roaming\XenoManager\AVKlyo045S.exe Memory allocated: 8AD0000 memory reserve | memory write watch Jump to behavior
Source: C:\Users\user\AppData\Roaming\XenoManager\AVKlyo045S.exe Memory allocated: 7AD0000 memory reserve | memory write watch Jump to behavior
Source: C:\Users\user\AppData\Roaming\XenoManager\AVKlyo045S.exe Memory allocated: 9BD0000 memory reserve | memory write watch Jump to behavior
Source: C:\Users\user\AppData\Roaming\XenoManager\AVKlyo045S.exe Memory allocated: ABD0000 memory reserve | memory write watch Jump to behavior
Source: C:\Users\user\AppData\Roaming\XenoManager\AVKlyo045S.exe Memory allocated: 6D70000 memory reserve | memory write watch Jump to behavior
Source: C:\Users\user\AppData\Roaming\XenoManager\AVKlyo045S.exe Memory allocated: BBD0000 memory reserve | memory write watch Jump to behavior
Source: C:\Users\user\AppData\Roaming\XenoManager\AVKlyo045S.exe Memory allocated: CBD0000 memory reserve | memory write watch Jump to behavior
Source: C:\Users\user\AppData\Roaming\XenoManager\AVKlyo045S.exe Memory allocated: 8AD0000 memory reserve | memory write watch Jump to behavior
Source: C:\Users\user\AppData\Roaming\XenoManager\AVKlyo045S.exe Memory allocated: 5610000 memory reserve | memory write watch Jump to behavior
Source: C:\Users\user\AppData\Roaming\XenoManager\AVKlyo045S.exe Memory allocated: 1730000 memory reserve | memory write watch Jump to behavior
Source: C:\Users\user\AppData\Roaming\XenoManager\AVKlyo045S.exe Memory allocated: 31F0000 memory reserve | memory write watch Jump to behavior
Source: C:\Users\user\AppData\Roaming\XenoManager\AVKlyo045S.exe Memory allocated: 51F0000 memory reserve | memory write watch Jump to behavior
Source: C:\Users\user\AppData\Roaming\XenoManager\AVKlyo045S.exe Memory allocated: 12F0000 memory reserve | memory write watch Jump to behavior
Source: C:\Users\user\AppData\Roaming\XenoManager\AVKlyo045S.exe Memory allocated: 30E0000 memory reserve | memory write watch Jump to behavior
Source: C:\Users\user\AppData\Roaming\XenoManager\AVKlyo045S.exe Memory allocated: 1860000 memory reserve | memory write watch Jump to behavior
Source: C:\Users\user\AppData\Roaming\XenoManager\AVKlyo045S.exe Memory allocated: 2F00000 memory reserve | memory write watch Jump to behavior
Source: C:\Users\user\AppData\Roaming\XenoManager\AVKlyo045S.exe Memory allocated: 30E0000 memory reserve | memory write watch Jump to behavior
Source: C:\Users\user\AppData\Roaming\XenoManager\AVKlyo045S.exe Memory allocated: 50E0000 memory reserve | memory write watch Jump to behavior
Source: C:\Users\user\Desktop\AVKlyo045S.exe Thread delayed: delay time: 922337203685477 Jump to behavior
Source: C:\Users\user\Desktop\AVKlyo045S.exe Thread delayed: delay time: 922337203685477 Jump to behavior
Source: C:\Users\user\AppData\Roaming\XenoManager\AVKlyo045S.exe Thread delayed: delay time: 922337203685477 Jump to behavior
Source: C:\Users\user\AppData\Roaming\XenoManager\AVKlyo045S.exe Thread delayed: delay time: 922337203685477 Jump to behavior
Source: C:\Users\user\AppData\Roaming\XenoManager\AVKlyo045S.exe Thread delayed: delay time: 922337203685477 Jump to behavior
Source: C:\Users\user\AppData\Roaming\XenoManager\AVKlyo045S.exe Thread delayed: delay time: 922337203685477 Jump to behavior
Source: C:\Users\user\AppData\Roaming\XenoManager\AVKlyo045S.exe Thread delayed: delay time: 922337203685477 Jump to behavior
Source: C:\Users\user\AppData\Roaming\XenoManager\AVKlyo045S.exe Thread delayed: delay time: 922337203685477 Jump to behavior
Source: C:\Users\user\AppData\Roaming\XenoManager\AVKlyo045S.exe Thread delayed: delay time: 922337203685477 Jump to behavior
Source: C:\Users\user\AppData\Roaming\XenoManager\AVKlyo045S.exe Window / User API: threadDelayed 1244 Jump to behavior
Source: C:\Users\user\AppData\Roaming\XenoManager\AVKlyo045S.exe Window / User API: threadDelayed 8576 Jump to behavior
Source: C:\Users\user\Desktop\AVKlyo045S.exe TID: 3628 Thread sleep time: -922337203685477s >= -30000s Jump to behavior
Source: C:\Users\user\Desktop\AVKlyo045S.exe TID: 6676 Thread sleep time: -922337203685477s >= -30000s Jump to behavior
Source: C:\Users\user\AppData\Roaming\XenoManager\AVKlyo045S.exe TID: 4676 Thread sleep time: -922337203685477s >= -30000s Jump to behavior
Source: C:\Users\user\AppData\Roaming\XenoManager\AVKlyo045S.exe TID: 1436 Thread sleep count: 36 > 30 Jump to behavior
Source: C:\Users\user\AppData\Roaming\XenoManager\AVKlyo045S.exe TID: 1436 Thread sleep time: -33204139332677172s >= -30000s Jump to behavior
Source: C:\Users\user\AppData\Roaming\XenoManager\AVKlyo045S.exe TID: 1436 Thread sleep time: -60000s >= -30000s Jump to behavior
Source: C:\Users\user\AppData\Roaming\XenoManager\AVKlyo045S.exe TID: 344 Thread sleep count: 1244 > 30 Jump to behavior
Source: C:\Users\user\AppData\Roaming\XenoManager\AVKlyo045S.exe TID: 1436 Thread sleep time: -59828s >= -30000s Jump to behavior
Source: C:\Users\user\AppData\Roaming\XenoManager\AVKlyo045S.exe TID: 344 Thread sleep count: 8576 > 30 Jump to behavior
Source: C:\Users\user\AppData\Roaming\XenoManager\AVKlyo045S.exe TID: 1436 Thread sleep time: -59719s >= -30000s Jump to behavior
Source: C:\Users\user\AppData\Roaming\XenoManager\AVKlyo045S.exe TID: 1436 Thread sleep time: -59610s >= -30000s Jump to behavior
Source: C:\Users\user\AppData\Roaming\XenoManager\AVKlyo045S.exe TID: 1436 Thread sleep count: 38 > 30 Jump to behavior
Source: C:\Users\user\AppData\Roaming\XenoManager\AVKlyo045S.exe TID: 1436 Thread sleep time: -59485s >= -30000s Jump to behavior
Source: C:\Users\user\AppData\Roaming\XenoManager\AVKlyo045S.exe TID: 1436 Thread sleep time: -59360s >= -30000s Jump to behavior
Source: C:\Users\user\AppData\Roaming\XenoManager\AVKlyo045S.exe TID: 1436 Thread sleep time: -59235s >= -30000s Jump to behavior
Source: C:\Users\user\AppData\Roaming\XenoManager\AVKlyo045S.exe TID: 1436 Thread sleep time: -59110s >= -30000s Jump to behavior
Source: C:\Users\user\AppData\Roaming\XenoManager\AVKlyo045S.exe TID: 1436 Thread sleep time: -58985s >= -30000s Jump to behavior
Source: C:\Users\user\AppData\Roaming\XenoManager\AVKlyo045S.exe TID: 1436 Thread sleep time: -58860s >= -30000s Jump to behavior
Source: C:\Users\user\AppData\Roaming\XenoManager\AVKlyo045S.exe TID: 1436 Thread sleep time: -58737s >= -30000s Jump to behavior
Source: C:\Users\user\AppData\Roaming\XenoManager\AVKlyo045S.exe TID: 1436 Thread sleep time: -58579s >= -30000s Jump to behavior
Source: C:\Users\user\AppData\Roaming\XenoManager\AVKlyo045S.exe TID: 1436 Thread sleep time: -58453s >= -30000s Jump to behavior
Source: C:\Users\user\AppData\Roaming\XenoManager\AVKlyo045S.exe TID: 1436 Thread sleep time: -58344s >= -30000s Jump to behavior
Source: C:\Users\user\AppData\Roaming\XenoManager\AVKlyo045S.exe TID: 1436 Thread sleep time: -58235s >= -30000s Jump to behavior
Source: C:\Users\user\AppData\Roaming\XenoManager\AVKlyo045S.exe TID: 1436 Thread sleep time: -58110s >= -30000s Jump to behavior
Source: C:\Users\user\AppData\Roaming\XenoManager\AVKlyo045S.exe TID: 1436 Thread sleep time: -57985s >= -30000s Jump to behavior
Source: C:\Users\user\AppData\Roaming\XenoManager\AVKlyo045S.exe TID: 1436 Thread sleep time: -57860s >= -30000s Jump to behavior
Source: C:\Users\user\AppData\Roaming\XenoManager\AVKlyo045S.exe TID: 1436 Thread sleep time: -57735s >= -30000s Jump to behavior
Source: C:\Users\user\AppData\Roaming\XenoManager\AVKlyo045S.exe TID: 1436 Thread sleep time: -57610s >= -30000s Jump to behavior
Source: C:\Users\user\AppData\Roaming\XenoManager\AVKlyo045S.exe TID: 1436 Thread sleep time: -57485s >= -30000s Jump to behavior
Source: C:\Users\user\AppData\Roaming\XenoManager\AVKlyo045S.exe TID: 1436 Thread sleep time: -57360s >= -30000s Jump to behavior
Source: C:\Users\user\AppData\Roaming\XenoManager\AVKlyo045S.exe TID: 1436 Thread sleep time: -57235s >= -30000s Jump to behavior
Source: C:\Users\user\AppData\Roaming\XenoManager\AVKlyo045S.exe TID: 1436 Thread sleep time: -57110s >= -30000s Jump to behavior
Source: C:\Users\user\AppData\Roaming\XenoManager\AVKlyo045S.exe TID: 1436 Thread sleep time: -56985s >= -30000s Jump to behavior
Source: C:\Users\user\AppData\Roaming\XenoManager\AVKlyo045S.exe TID: 1436 Thread sleep time: -56860s >= -30000s Jump to behavior
Source: C:\Users\user\AppData\Roaming\XenoManager\AVKlyo045S.exe TID: 1436 Thread sleep time: -56735s >= -30000s Jump to behavior
Source: C:\Users\user\AppData\Roaming\XenoManager\AVKlyo045S.exe TID: 1436 Thread sleep time: -56610s >= -30000s Jump to behavior
Source: C:\Users\user\AppData\Roaming\XenoManager\AVKlyo045S.exe TID: 1436 Thread sleep time: -56485s >= -30000s Jump to behavior
Source: C:\Users\user\AppData\Roaming\XenoManager\AVKlyo045S.exe TID: 1436 Thread sleep time: -56345s >= -30000s Jump to behavior
Source: C:\Users\user\AppData\Roaming\XenoManager\AVKlyo045S.exe TID: 1436 Thread sleep time: -56219s >= -30000s Jump to behavior
Source: C:\Users\user\AppData\Roaming\XenoManager\AVKlyo045S.exe TID: 1436 Thread sleep time: -56110s >= -30000s Jump to behavior
Source: C:\Users\user\AppData\Roaming\XenoManager\AVKlyo045S.exe TID: 1436 Thread sleep time: -55985s >= -30000s Jump to behavior
Source: C:\Users\user\AppData\Roaming\XenoManager\AVKlyo045S.exe TID: 1436 Thread sleep time: -55860s >= -30000s Jump to behavior
Source: C:\Users\user\AppData\Roaming\XenoManager\AVKlyo045S.exe TID: 1436 Thread sleep time: -55735s >= -30000s Jump to behavior
Source: C:\Users\user\AppData\Roaming\XenoManager\AVKlyo045S.exe TID: 1436 Thread sleep time: -55610s >= -30000s Jump to behavior
Source: C:\Users\user\AppData\Roaming\XenoManager\AVKlyo045S.exe TID: 1436 Thread sleep time: -55485s >= -30000s Jump to behavior
Source: C:\Users\user\AppData\Roaming\XenoManager\AVKlyo045S.exe TID: 1436 Thread sleep time: -55360s >= -30000s Jump to behavior
Source: C:\Users\user\AppData\Roaming\XenoManager\AVKlyo045S.exe TID: 1436 Thread sleep time: -55235s >= -30000s Jump to behavior
Source: C:\Users\user\AppData\Roaming\XenoManager\AVKlyo045S.exe TID: 1436 Thread sleep time: -55110s >= -30000s Jump to behavior
Source: C:\Users\user\AppData\Roaming\XenoManager\AVKlyo045S.exe TID: 1436 Thread sleep time: -54985s >= -30000s Jump to behavior
Source: C:\Users\user\AppData\Roaming\XenoManager\AVKlyo045S.exe TID: 1436 Thread sleep time: -54860s >= -30000s Jump to behavior
Source: C:\Users\user\AppData\Roaming\XenoManager\AVKlyo045S.exe TID: 1436 Thread sleep time: -54735s >= -30000s Jump to behavior
Source: C:\Users\user\AppData\Roaming\XenoManager\AVKlyo045S.exe TID: 1436 Thread sleep time: -54610s >= -30000s Jump to behavior
Source: C:\Users\user\AppData\Roaming\XenoManager\AVKlyo045S.exe TID: 1436 Thread sleep time: -54485s >= -30000s Jump to behavior
Source: C:\Users\user\AppData\Roaming\XenoManager\AVKlyo045S.exe TID: 1436 Thread sleep time: -54360s >= -30000s Jump to behavior
Source: C:\Users\user\AppData\Roaming\XenoManager\AVKlyo045S.exe TID: 1436 Thread sleep time: -54235s >= -30000s Jump to behavior
Source: C:\Users\user\AppData\Roaming\XenoManager\AVKlyo045S.exe TID: 1436 Thread sleep time: -54110s >= -30000s Jump to behavior
Source: C:\Users\user\AppData\Roaming\XenoManager\AVKlyo045S.exe TID: 1436 Thread sleep time: -53985s >= -30000s Jump to behavior
Source: C:\Users\user\AppData\Roaming\XenoManager\AVKlyo045S.exe TID: 1436 Thread sleep time: -53868s >= -30000s Jump to behavior
Source: C:\Users\user\AppData\Roaming\XenoManager\AVKlyo045S.exe TID: 568 Thread sleep time: -922337203685477s >= -30000s Jump to behavior
Source: C:\Users\user\AppData\Roaming\XenoManager\AVKlyo045S.exe TID: 5576 Thread sleep time: -922337203685477s >= -30000s Jump to behavior
Source: C:\Users\user\AppData\Roaming\XenoManager\AVKlyo045S.exe TID: 5304 Thread sleep time: -922337203685477s >= -30000s Jump to behavior
Source: C:\Users\user\AppData\Roaming\XenoManager\AVKlyo045S.exe TID: 5708 Thread sleep time: -922337203685477s >= -30000s Jump to behavior
Source: C:\Users\user\AppData\Roaming\XenoManager\AVKlyo045S.exe TID: 7012 Thread sleep time: -922337203685477s >= -30000s Jump to behavior
Source: C:\Users\user\Desktop\AVKlyo045S.exe Thread delayed: delay time: 922337203685477 Jump to behavior
Source: C:\Users\user\Desktop\AVKlyo045S.exe Thread delayed: delay time: 922337203685477 Jump to behavior
Source: C:\Users\user\AppData\Roaming\XenoManager\AVKlyo045S.exe Thread delayed: delay time: 922337203685477 Jump to behavior
Source: C:\Users\user\AppData\Roaming\XenoManager\AVKlyo045S.exe Thread delayed: delay time: 922337203685477 Jump to behavior
Source: C:\Users\user\AppData\Roaming\XenoManager\AVKlyo045S.exe Thread delayed: delay time: 60000 Jump to behavior
Source: C:\Users\user\AppData\Roaming\XenoManager\AVKlyo045S.exe Thread delayed: delay time: 59828 Jump to behavior
Source: C:\Users\user\AppData\Roaming\XenoManager\AVKlyo045S.exe Thread delayed: delay time: 59719 Jump to behavior
Source: C:\Users\user\AppData\Roaming\XenoManager\AVKlyo045S.exe Thread delayed: delay time: 59610 Jump to behavior
Source: C:\Users\user\AppData\Roaming\XenoManager\AVKlyo045S.exe Thread delayed: delay time: 59485 Jump to behavior
Source: C:\Users\user\AppData\Roaming\XenoManager\AVKlyo045S.exe Thread delayed: delay time: 59360 Jump to behavior
Source: C:\Users\user\AppData\Roaming\XenoManager\AVKlyo045S.exe Thread delayed: delay time: 59235 Jump to behavior
Source: C:\Users\user\AppData\Roaming\XenoManager\AVKlyo045S.exe Thread delayed: delay time: 59110 Jump to behavior
Source: C:\Users\user\AppData\Roaming\XenoManager\AVKlyo045S.exe Thread delayed: delay time: 58985 Jump to behavior
Source: C:\Users\user\AppData\Roaming\XenoManager\AVKlyo045S.exe Thread delayed: delay time: 58860 Jump to behavior
Source: C:\Users\user\AppData\Roaming\XenoManager\AVKlyo045S.exe Thread delayed: delay time: 58737 Jump to behavior
Source: C:\Users\user\AppData\Roaming\XenoManager\AVKlyo045S.exe Thread delayed: delay time: 58579 Jump to behavior
Source: C:\Users\user\AppData\Roaming\XenoManager\AVKlyo045S.exe Thread delayed: delay time: 58453 Jump to behavior
Source: C:\Users\user\AppData\Roaming\XenoManager\AVKlyo045S.exe Thread delayed: delay time: 58344 Jump to behavior
Source: C:\Users\user\AppData\Roaming\XenoManager\AVKlyo045S.exe Thread delayed: delay time: 58235 Jump to behavior
Source: C:\Users\user\AppData\Roaming\XenoManager\AVKlyo045S.exe Thread delayed: delay time: 58110 Jump to behavior
Source: C:\Users\user\AppData\Roaming\XenoManager\AVKlyo045S.exe Thread delayed: delay time: 57985 Jump to behavior
Source: C:\Users\user\AppData\Roaming\XenoManager\AVKlyo045S.exe Thread delayed: delay time: 57860 Jump to behavior
Source: C:\Users\user\AppData\Roaming\XenoManager\AVKlyo045S.exe Thread delayed: delay time: 57735 Jump to behavior
Source: C:\Users\user\AppData\Roaming\XenoManager\AVKlyo045S.exe Thread delayed: delay time: 57610 Jump to behavior
Source: C:\Users\user\AppData\Roaming\XenoManager\AVKlyo045S.exe Thread delayed: delay time: 57485 Jump to behavior
Source: C:\Users\user\AppData\Roaming\XenoManager\AVKlyo045S.exe Thread delayed: delay time: 57360 Jump to behavior
Source: C:\Users\user\AppData\Roaming\XenoManager\AVKlyo045S.exe Thread delayed: delay time: 57235 Jump to behavior
Source: C:\Users\user\AppData\Roaming\XenoManager\AVKlyo045S.exe Thread delayed: delay time: 57110 Jump to behavior
Source: C:\Users\user\AppData\Roaming\XenoManager\AVKlyo045S.exe Thread delayed: delay time: 56985 Jump to behavior
Source: C:\Users\user\AppData\Roaming\XenoManager\AVKlyo045S.exe Thread delayed: delay time: 56860 Jump to behavior
Source: C:\Users\user\AppData\Roaming\XenoManager\AVKlyo045S.exe Thread delayed: delay time: 56735 Jump to behavior
Source: C:\Users\user\AppData\Roaming\XenoManager\AVKlyo045S.exe Thread delayed: delay time: 56610 Jump to behavior
Source: C:\Users\user\AppData\Roaming\XenoManager\AVKlyo045S.exe Thread delayed: delay time: 56485 Jump to behavior
Source: C:\Users\user\AppData\Roaming\XenoManager\AVKlyo045S.exe Thread delayed: delay time: 56345 Jump to behavior
Source: C:\Users\user\AppData\Roaming\XenoManager\AVKlyo045S.exe Thread delayed: delay time: 56219 Jump to behavior
Source: C:\Users\user\AppData\Roaming\XenoManager\AVKlyo045S.exe Thread delayed: delay time: 56110 Jump to behavior
Source: C:\Users\user\AppData\Roaming\XenoManager\AVKlyo045S.exe Thread delayed: delay time: 55985 Jump to behavior
Source: C:\Users\user\AppData\Roaming\XenoManager\AVKlyo045S.exe Thread delayed: delay time: 55860 Jump to behavior
Source: C:\Users\user\AppData\Roaming\XenoManager\AVKlyo045S.exe Thread delayed: delay time: 55735 Jump to behavior
Source: C:\Users\user\AppData\Roaming\XenoManager\AVKlyo045S.exe Thread delayed: delay time: 55610 Jump to behavior
Source: C:\Users\user\AppData\Roaming\XenoManager\AVKlyo045S.exe Thread delayed: delay time: 55485 Jump to behavior
Source: C:\Users\user\AppData\Roaming\XenoManager\AVKlyo045S.exe Thread delayed: delay time: 55360 Jump to behavior
Source: C:\Users\user\AppData\Roaming\XenoManager\AVKlyo045S.exe Thread delayed: delay time: 55235 Jump to behavior
Source: C:\Users\user\AppData\Roaming\XenoManager\AVKlyo045S.exe Thread delayed: delay time: 55110 Jump to behavior
Source: C:\Users\user\AppData\Roaming\XenoManager\AVKlyo045S.exe Thread delayed: delay time: 54985 Jump to behavior
Source: C:\Users\user\AppData\Roaming\XenoManager\AVKlyo045S.exe Thread delayed: delay time: 54860 Jump to behavior
Source: C:\Users\user\AppData\Roaming\XenoManager\AVKlyo045S.exe Thread delayed: delay time: 54735 Jump to behavior
Source: C:\Users\user\AppData\Roaming\XenoManager\AVKlyo045S.exe Thread delayed: delay time: 54610 Jump to behavior
Source: C:\Users\user\AppData\Roaming\XenoManager\AVKlyo045S.exe Thread delayed: delay time: 54485 Jump to behavior
Source: C:\Users\user\AppData\Roaming\XenoManager\AVKlyo045S.exe Thread delayed: delay time: 54360 Jump to behavior
Source: C:\Users\user\AppData\Roaming\XenoManager\AVKlyo045S.exe Thread delayed: delay time: 54235 Jump to behavior
Source: C:\Users\user\AppData\Roaming\XenoManager\AVKlyo045S.exe Thread delayed: delay time: 54110 Jump to behavior
Source: C:\Users\user\AppData\Roaming\XenoManager\AVKlyo045S.exe Thread delayed: delay time: 53985 Jump to behavior
Source: C:\Users\user\AppData\Roaming\XenoManager\AVKlyo045S.exe Thread delayed: delay time: 53868 Jump to behavior
Source: C:\Users\user\AppData\Roaming\XenoManager\AVKlyo045S.exe Thread delayed: delay time: 922337203685477 Jump to behavior
Source: C:\Users\user\AppData\Roaming\XenoManager\AVKlyo045S.exe Thread delayed: delay time: 922337203685477 Jump to behavior
Source: C:\Users\user\AppData\Roaming\XenoManager\AVKlyo045S.exe Thread delayed: delay time: 922337203685477 Jump to behavior
Source: C:\Users\user\AppData\Roaming\XenoManager\AVKlyo045S.exe Thread delayed: delay time: 922337203685477 Jump to behavior
Source: C:\Users\user\AppData\Roaming\XenoManager\AVKlyo045S.exe Thread delayed: delay time: 922337203685477 Jump to behavior
Source: AVKlyo045S.exe, 0000000B.00000002.3911956000.00000000013F1000.00000004.00000020.00020000.00000000.sdmp Binary or memory string: Hyper-V RAW%SystemRoot%\system32\mswsock.dllv
Source: C:\Users\user\Desktop\AVKlyo045S.exe Process queried: DebugPort Jump to behavior
Source: C:\Users\user\Desktop\AVKlyo045S.exe Process queried: DebugPort Jump to behavior
Source: C:\Users\user\Desktop\AVKlyo045S.exe Process queried: DebugPort Jump to behavior
Source: C:\Users\user\Desktop\AVKlyo045S.exe Process queried: DebugPort Jump to behavior
Source: C:\Users\user\AppData\Roaming\XenoManager\AVKlyo045S.exe Process queried: DebugPort Jump to behavior
Source: C:\Users\user\AppData\Roaming\XenoManager\AVKlyo045S.exe Process queried: DebugPort Jump to behavior
Source: C:\Users\user\Desktop\AVKlyo045S.exe Process token adjusted: Debug Jump to behavior
Source: C:\Users\user\AppData\Roaming\XenoManager\AVKlyo045S.exe Process token adjusted: Debug Jump to behavior
Source: C:\Users\user\AppData\Roaming\XenoManager\AVKlyo045S.exe Process token adjusted: Debug Jump to behavior
Source: C:\Users\user\Desktop\AVKlyo045S.exe Memory allocated: page read and write | page guard Jump to behavior

HIPS / PFW / Operating System Protection Evasion

barindex
Source: C:\Users\user\Desktop\AVKlyo045S.exe Memory written: C:\Users\user\Desktop\AVKlyo045S.exe base: 400000 value starts with: 4D5A Jump to behavior
Source: C:\Users\user\AppData\Roaming\XenoManager\AVKlyo045S.exe Memory written: C:\Users\user\AppData\Roaming\XenoManager\AVKlyo045S.exe base: 400000 value starts with: 4D5A Jump to behavior
Source: C:\Users\user\AppData\Roaming\XenoManager\AVKlyo045S.exe Memory written: C:\Users\user\AppData\Roaming\XenoManager\AVKlyo045S.exe base: 400000 value starts with: 4D5A Jump to behavior
Source: C:\Users\user\AppData\Roaming\XenoManager\AVKlyo045S.exe Memory written: C:\Users\user\AppData\Roaming\XenoManager\AVKlyo045S.exe base: 400000 value starts with: 4D5A Jump to behavior
Source: C:\Users\user\AppData\Roaming\XenoManager\AVKlyo045S.exe Memory written: C:\Users\user\AppData\Roaming\XenoManager\AVKlyo045S.exe base: 400000 value starts with: 4D5A Jump to behavior
Source: C:\Users\user\AppData\Roaming\XenoManager\AVKlyo045S.exe Memory written: C:\Users\user\AppData\Roaming\XenoManager\AVKlyo045S.exe base: 400000 value starts with: 4D5A Jump to behavior
Source: C:\Users\user\Desktop\AVKlyo045S.exe Process created: C:\Users\user\Desktop\AVKlyo045S.exe C:\Users\user\Desktop\AVKlyo045S.exe Jump to behavior
Source: C:\Users\user\Desktop\AVKlyo045S.exe Process created: C:\Users\user\Desktop\AVKlyo045S.exe C:\Users\user\Desktop\AVKlyo045S.exe Jump to behavior
Source: C:\Users\user\Desktop\AVKlyo045S.exe Process created: C:\Users\user\Desktop\AVKlyo045S.exe C:\Users\user\Desktop\AVKlyo045S.exe Jump to behavior
Source: C:\Users\user\Desktop\AVKlyo045S.exe Process created: C:\Users\user\AppData\Roaming\XenoManager\AVKlyo045S.exe "C:\Users\user\AppData\Roaming\XenoManager\AVKlyo045S.exe" Jump to behavior
Source: C:\Users\user\AppData\Roaming\XenoManager\AVKlyo045S.exe Process created: C:\Users\user\AppData\Roaming\XenoManager\AVKlyo045S.exe C:\Users\user\AppData\Roaming\XenoManager\AVKlyo045S.exe Jump to behavior
Source: C:\Users\user\AppData\Roaming\XenoManager\AVKlyo045S.exe Process created: C:\Users\user\AppData\Roaming\XenoManager\AVKlyo045S.exe C:\Users\user\AppData\Roaming\XenoManager\AVKlyo045S.exe Jump to behavior
Source: C:\Users\user\AppData\Roaming\XenoManager\AVKlyo045S.exe Process created: C:\Users\user\AppData\Roaming\XenoManager\AVKlyo045S.exe C:\Users\user\AppData\Roaming\XenoManager\AVKlyo045S.exe Jump to behavior
Source: C:\Users\user\AppData\Roaming\XenoManager\AVKlyo045S.exe Process created: C:\Windows\SysWOW64\schtasks.exe "schtasks.exe" /Create /TN "cms" /XML "C:\Users\user\AppData\Local\Temp\tmpCEF4.tmp" /F Jump to behavior
Source: C:\Users\user\AppData\Roaming\XenoManager\AVKlyo045S.exe Process created: C:\Users\user\AppData\Roaming\XenoManager\AVKlyo045S.exe C:\Users\user\AppData\Roaming\XenoManager\AVKlyo045S.exe Jump to behavior
Source: C:\Users\user\AppData\Roaming\XenoManager\AVKlyo045S.exe Process created: C:\Users\user\AppData\Roaming\XenoManager\AVKlyo045S.exe C:\Users\user\AppData\Roaming\XenoManager\AVKlyo045S.exe Jump to behavior
Source: C:\Users\user\AppData\Roaming\XenoManager\AVKlyo045S.exe Process created: C:\Users\user\AppData\Roaming\XenoManager\AVKlyo045S.exe C:\Users\user\AppData\Roaming\XenoManager\AVKlyo045S.exe Jump to behavior
Source: C:\Users\user\Desktop\AVKlyo045S.exe Queries volume information: C:\Users\user\Desktop\AVKlyo045S.exe VolumeInformation Jump to behavior
Source: C:\Users\user\Desktop\AVKlyo045S.exe Queries volume information: C:\Windows\Microsoft.NET\assembly\GAC_MSIL\Microsoft.VisualBasic\v4.0_10.0.0.0__b03f5f7f11d50a3a\Microsoft.VisualBasic.dll VolumeInformation Jump to behavior
Source: C:\Users\user\Desktop\AVKlyo045S.exe Queries volume information: C:\Users\user\Desktop\AVKlyo045S.exe VolumeInformation Jump to behavior
Source: C:\Users\user\AppData\Roaming\XenoManager\AVKlyo045S.exe Queries volume information: C:\Users\user\AppData\Roaming\XenoManager\AVKlyo045S.exe VolumeInformation Jump to behavior
Source: C:\Users\user\AppData\Roaming\XenoManager\AVKlyo045S.exe Queries volume information: C:\Windows\Microsoft.NET\assembly\GAC_MSIL\Microsoft.VisualBasic\v4.0_10.0.0.0__b03f5f7f11d50a3a\Microsoft.VisualBasic.dll VolumeInformation Jump to behavior
Source: C:\Users\user\AppData\Roaming\XenoManager\AVKlyo045S.exe Queries volume information: C:\Users\user\AppData\Roaming\XenoManager\AVKlyo045S.exe VolumeInformation Jump to behavior
Source: C:\Users\user\AppData\Roaming\XenoManager\AVKlyo045S.exe Queries volume information: C:\Users\user\AppData\Roaming\XenoManager\AVKlyo045S.exe VolumeInformation Jump to behavior
Source: C:\Users\user\AppData\Roaming\XenoManager\AVKlyo045S.exe Queries volume information: C:\Users\user\AppData\Roaming\XenoManager\AVKlyo045S.exe VolumeInformation Jump to behavior
Source: C:\Users\user\AppData\Roaming\XenoManager\AVKlyo045S.exe Queries volume information: C:\Windows\Microsoft.NET\assembly\GAC_MSIL\Microsoft.VisualBasic\v4.0_10.0.0.0__b03f5f7f11d50a3a\Microsoft.VisualBasic.dll VolumeInformation Jump to behavior
Source: C:\Users\user\AppData\Roaming\XenoManager\AVKlyo045S.exe Queries volume information: C:\Users\user\AppData\Roaming\XenoManager\AVKlyo045S.exe VolumeInformation Jump to behavior
Source: C:\Users\user\AppData\Roaming\XenoManager\AVKlyo045S.exe Queries volume information: C:\Users\user\AppData\Roaming\XenoManager\AVKlyo045S.exe VolumeInformation Jump to behavior
Source: C:\Users\user\AppData\Roaming\XenoManager\AVKlyo045S.exe Queries volume information: C:\Users\user\AppData\Roaming\XenoManager\AVKlyo045S.exe VolumeInformation Jump to behavior
Source: C:\Users\user\Desktop\AVKlyo045S.exe Key value queried: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Cryptography MachineGuid Jump to behavior

Stealing of Sensitive Information

barindex
Source: Yara match File source: 5.2.AVKlyo045S.exe.400000.0.unpack, type: UNPACKEDPE
Source: Yara match File source: 6.2.AVKlyo045S.exe.2b2d670.0.unpack, type: UNPACKEDPE
Source: Yara match File source: 22.2.AVKlyo045S.exe.2f4e63c.0.unpack, type: UNPACKEDPE
Source: Yara match File source: 1.2.AVKlyo045S.exe.24cd62c.0.unpack, type: UNPACKEDPE
Source: Yara match File source: 6.2.AVKlyo045S.exe.2b2d670.0.raw.unpack, type: UNPACKEDPE
Source: Yara match File source: 22.2.AVKlyo045S.exe.2f4e63c.0.raw.unpack, type: UNPACKEDPE
Source: Yara match File source: 1.2.AVKlyo045S.exe.24cd62c.0.raw.unpack, type: UNPACKEDPE
Source: Yara match File source: 22.2.AVKlyo045S.exe.2f49c90.1.raw.unpack, type: UNPACKEDPE
Source: Yara match File source: 00000001.00000002.1458741464.00000000026DA000.00000004.00000800.00020000.00000000.sdmp, type: MEMORY
Source: Yara match File source: 00000005.00000002.1457010386.0000000000402000.00000040.00000400.00020000.00000000.sdmp, type: MEMORY
Source: Yara match File source: 00000001.00000002.1458741464.00000000026E7000.00000004.00000800.00020000.00000000.sdmp, type: MEMORY
Source: Yara match File source: 00000016.00000002.2098007355.0000000003151000.00000004.00000800.00020000.00000000.sdmp, type: MEMORY
Source: Yara match File source: 00000006.00000002.1475423833.0000000002D46000.00000004.00000800.00020000.00000000.sdmp, type: MEMORY
Source: Yara match File source: 00000006.00000002.1475423833.0000000002D55000.00000004.00000800.00020000.00000000.sdmp, type: MEMORY
Source: Yara match File source: 00000016.00000002.2098007355.0000000003160000.00000004.00000800.00020000.00000000.sdmp, type: MEMORY
Source: Yara match File source: 00000001.00000002.1458741464.00000000024C1000.00000004.00000800.00020000.00000000.sdmp, type: MEMORY
Source: Yara match File source: 00000006.00000002.1475423833.0000000002B21000.00000004.00000800.00020000.00000000.sdmp, type: MEMORY
Source: Yara match File source: 00000016.00000002.2098007355.0000000002F41000.00000004.00000800.00020000.00000000.sdmp, type: MEMORY
Source: Yara match File source: Process Memory Space: AVKlyo045S.exe PID: 6984, type: MEMORYSTR
Source: Yara match File source: Process Memory Space: AVKlyo045S.exe PID: 4464, type: MEMORYSTR
Source: Yara match File source: Process Memory Space: AVKlyo045S.exe PID: 6476, type: MEMORYSTR
Source: Yara match File source: Process Memory Space: AVKlyo045S.exe PID: 3848, type: MEMORYSTR

Remote Access Functionality

barindex
Source: Yara match File source: 5.2.AVKlyo045S.exe.400000.0.unpack, type: UNPACKEDPE
Source: Yara match File source: 6.2.AVKlyo045S.exe.2b2d670.0.unpack, type: UNPACKEDPE
Source: Yara match File source: 22.2.AVKlyo045S.exe.2f4e63c.0.unpack, type: UNPACKEDPE
Source: Yara match File source: 1.2.AVKlyo045S.exe.24cd62c.0.unpack, type: UNPACKEDPE
Source: Yara match File source: 6.2.AVKlyo045S.exe.2b2d670.0.raw.unpack, type: UNPACKEDPE
Source: Yara match File source: 22.2.AVKlyo045S.exe.2f4e63c.0.raw.unpack, type: UNPACKEDPE
Source: Yara match File source: 1.2.AVKlyo045S.exe.24cd62c.0.raw.unpack, type: UNPACKEDPE
Source: Yara match File source: 22.2.AVKlyo045S.exe.2f49c90.1.raw.unpack, type: UNPACKEDPE
Source: Yara match File source: 00000001.00000002.1458741464.00000000026DA000.00000004.00000800.00020000.00000000.sdmp, type: MEMORY
Source: Yara match File source: 00000005.00000002.1457010386.0000000000402000.00000040.00000400.00020000.00000000.sdmp, type: MEMORY
Source: Yara match File source: 00000001.00000002.1458741464.00000000026E7000.00000004.00000800.00020000.00000000.sdmp, type: MEMORY
Source: Yara match File source: 00000016.00000002.2098007355.0000000003151000.00000004.00000800.00020000.00000000.sdmp, type: MEMORY
Source: Yara match File source: 00000006.00000002.1475423833.0000000002D46000.00000004.00000800.00020000.00000000.sdmp, type: MEMORY
Source: Yara match File source: 00000006.00000002.1475423833.0000000002D55000.00000004.00000800.00020000.00000000.sdmp, type: MEMORY
Source: Yara match File source: 00000016.00000002.2098007355.0000000003160000.00000004.00000800.00020000.00000000.sdmp, type: MEMORY
Source: Yara match File source: 00000001.00000002.1458741464.00000000024C1000.00000004.00000800.00020000.00000000.sdmp, type: MEMORY
Source: Yara match File source: 00000006.00000002.1475423833.0000000002B21000.00000004.00000800.00020000.00000000.sdmp, type: MEMORY
Source: Yara match File source: 00000016.00000002.2098007355.0000000002F41000.00000004.00000800.00020000.00000000.sdmp, type: MEMORY
Source: Yara match File source: Process Memory Space: AVKlyo045S.exe PID: 6984, type: MEMORYSTR
Source: Yara match File source: Process Memory Space: AVKlyo045S.exe PID: 4464, type: MEMORYSTR
Source: Yara match File source: Process Memory Space: AVKlyo045S.exe PID: 6476, type: MEMORYSTR
Source: Yara match File source: Process Memory Space: AVKlyo045S.exe PID: 3848, type: MEMORYSTR
  • No. of IPs < 25%
  • 25% < No. of IPs < 50%
  • 50% < No. of IPs < 75%
  • 75% < No. of IPs