Source: C:\Users\user\Desktop\lSmb6nDsrC.exe | Code function: 0_2_0040687E FindFirstFileW,FindClose, | 0_2_0040687E |
Source: C:\Users\user\Desktop\lSmb6nDsrC.exe | Code function: 0_2_00402910 FindFirstFileW, | 0_2_00402910 |
Source: C:\Users\user\Desktop\lSmb6nDsrC.exe | Code function: 0_2_00405C2D GetTempPathW,DeleteFileW,lstrcatW,lstrcatW,lstrlenW,FindFirstFileW,FindNextFileW,FindClose, | 0_2_00405C2D |
Source: C:\Users\user\AppData\Local\Microsoft\Windows\INetCache\55116385\Labs.pif | Code function: 19_2_007D4005 FindFirstFileW,DeleteFileW,FindNextFileW,FindClose,FindClose, | 19_2_007D4005 |
Source: C:\Users\user\AppData\Local\Microsoft\Windows\INetCache\55116385\Labs.pif | Code function: 19_2_007D494A GetFileAttributesW,FindFirstFileW,FindClose, | 19_2_007D494A |
Source: C:\Users\user\AppData\Local\Microsoft\Windows\INetCache\55116385\Labs.pif | Code function: 19_2_007DC2FF FindFirstFileW,_wcscmp,_wcscmp,FindNextFileW,FindClose, | 19_2_007DC2FF |
Source: C:\Users\user\AppData\Local\Microsoft\Windows\INetCache\55116385\Labs.pif | Code function: 19_2_007DCD14 FindFirstFileW,FindClose, | 19_2_007DCD14 |
Source: C:\Users\user\AppData\Local\Microsoft\Windows\INetCache\55116385\Labs.pif | Code function: 19_2_007DCD9F FindFirstFileW,FindClose,FileTimeToLocalFileTime,FileTimeToLocalFileTime,FileTimeToLocalFileTime,FileTimeToSystemTime,__swprintf,__swprintf,__swprintf,__swprintf,__swprintf,__swprintf,__swprintf, | 19_2_007DCD9F |
Source: C:\Users\user\AppData\Local\Microsoft\Windows\INetCache\55116385\Labs.pif | Code function: 19_2_007DF5D8 SetCurrentDirectoryW,FindFirstFileW,FindFirstFileW,_wcscmp,_wcscmp,GetFileAttributesW,SetFileAttributesW,FindNextFileW,FindClose,FindFirstFileW,SetCurrentDirectoryW,_wcscmp,_wcscmp,SetCurrentDirectoryW,SetCurrentDirectoryW,FindNextFileW,FindClose,FindClose, | 19_2_007DF5D8 |
Source: C:\Users\user\AppData\Local\Microsoft\Windows\INetCache\55116385\Labs.pif | Code function: 19_2_007DF735 SetCurrentDirectoryW,FindFirstFileW,FindFirstFileW,_wcscmp,_wcscmp,FindNextFileW,FindClose,FindFirstFileW,SetCurrentDirectoryW,_wcscmp,_wcscmp,SetCurrentDirectoryW,SetCurrentDirectoryW,FindNextFileW,FindClose,FindClose, | 19_2_007DF735 |
Source: C:\Users\user\AppData\Local\Microsoft\Windows\INetCache\55116385\Labs.pif | Code function: 19_2_007DFA36 FindFirstFileW,Sleep,_wcscmp,_wcscmp,FindNextFileW,FindClose, | 19_2_007DFA36 |
Source: C:\Users\user\AppData\Local\Microsoft\Windows\INetCache\55116385\Labs.pif | Code function: 19_2_007D3CE2 FindFirstFileW,DeleteFileW,DeleteFileW,MoveFileW,DeleteFileW,FindNextFileW,FindClose,FindClose, | 19_2_007D3CE2 |
Source: C:\Users\user\AppData\Local\Microsoft\Windows\INetCache\55116385\Labs.pif | Code function: 27_2_007D4005 FindFirstFileW,DeleteFileW,FindNextFileW,FindClose,FindClose, | 27_2_007D4005 |
Source: C:\Users\user\AppData\Local\Microsoft\Windows\INetCache\55116385\Labs.pif | Code function: 27_2_007DC2FF FindFirstFileW,_wcscmp,_wcscmp,FindNextFileW,FindClose, | 27_2_007DC2FF |
Source: C:\Users\user\AppData\Local\Microsoft\Windows\INetCache\55116385\Labs.pif | Code function: 27_2_007D494A GetFileAttributesW,FindFirstFileW,FindClose, | 27_2_007D494A |
Source: C:\Users\user\AppData\Local\Microsoft\Windows\INetCache\55116385\Labs.pif | Code function: 27_2_007DCD14 FindFirstFileW,FindClose, | 27_2_007DCD14 |
Source: C:\Users\user\AppData\Local\Microsoft\Windows\INetCache\55116385\Labs.pif | Code function: 27_2_007DCD9F FindFirstFileW,FindClose,FileTimeToLocalFileTime,FileTimeToLocalFileTime,FileTimeToLocalFileTime,FileTimeToSystemTime,__swprintf,__swprintf,__swprintf,__swprintf,__swprintf,__swprintf,__swprintf, | 27_2_007DCD9F |
Source: C:\Users\user\AppData\Local\Microsoft\Windows\INetCache\55116385\Labs.pif | Code function: 27_2_007DF5D8 SetCurrentDirectoryW,FindFirstFileW,FindFirstFileW,_wcscmp,_wcscmp,GetFileAttributesW,SetFileAttributesW,FindNextFileW,FindClose,FindFirstFileW,SetCurrentDirectoryW,_wcscmp,_wcscmp,SetCurrentDirectoryW,SetCurrentDirectoryW,FindNextFileW,FindClose,FindClose, | 27_2_007DF5D8 |
Source: C:\Users\user\AppData\Local\Microsoft\Windows\INetCache\55116385\Labs.pif | Code function: 27_2_007DF735 SetCurrentDirectoryW,FindFirstFileW,FindFirstFileW,_wcscmp,_wcscmp,FindNextFileW,FindClose,FindFirstFileW,SetCurrentDirectoryW,_wcscmp,_wcscmp,SetCurrentDirectoryW,SetCurrentDirectoryW,FindNextFileW,FindClose,FindClose, | 27_2_007DF735 |
Source: C:\Users\user\AppData\Local\Microsoft\Windows\INetCache\55116385\Labs.pif | Code function: 27_2_007DFA36 FindFirstFileW,Sleep,_wcscmp,_wcscmp,FindNextFileW,FindClose, | 27_2_007DFA36 |
Source: C:\Users\user\AppData\Local\Microsoft\Windows\INetCache\55116385\Labs.pif | Code function: 27_2_007D3CE2 FindFirstFileW,DeleteFileW,DeleteFileW,MoveFileW,DeleteFileW,FindNextFileW,FindClose,FindClose, | 27_2_007D3CE2 |
Source: explorer.exe, 0000001C.00000002.2481065121.0000000007306000.00000004.00000001.00020000.00000000.sdmp, explorer.exe, 0000001C.00000000.2299433125.0000000007306000.00000004.00000001.00020000.00000000.sdmp, explorer.exe, 0000001C.00000000.2307149631.0000000008F4D000.00000004.00000001.00020000.00000000.sdmp, explorer.exe, 0000001C.00000002.2484651579.0000000008F4D000.00000004.00000001.00020000.00000000.sdmp | String found in binary or memory: http://cacerts.digicert.com/DigiCertGlobalRootG2.crt0 |
Source: lSmb6nDsrC.exe | String found in binary or memory: http://crl.globalsign.com/ca/gstsacasha384g4.crl0 |
Source: lSmb6nDsrC.exe, 00000000.00000003.1239683585.000000000282A000.00000004.00000020.00020000.00000000.sdmp, Labs.pif.2.dr, Orders.0.dr | String found in binary or memory: http://crl.globalsign.com/gs/gstimestampingsha2g2.crl0 |
Source: lSmb6nDsrC.exe, 00000000.00000003.1239683585.000000000282A000.00000004.00000020.00020000.00000000.sdmp, Labs.pif.2.dr, Orders.0.dr | String found in binary or memory: http://crl.globalsign.com/gscodesignsha2g3.crl0 |
Source: lSmb6nDsrC.exe | String found in binary or memory: http://crl.globalsign.com/gsgccr45codesignca2020.crl0 |
Source: lSmb6nDsrC.exe | String found in binary or memory: http://crl.globalsign.com/root-r3.crl0G |
Source: lSmb6nDsrC.exe, 00000000.00000003.1239683585.000000000282A000.00000004.00000020.00020000.00000000.sdmp, Labs.pif.2.dr, Orders.0.dr | String found in binary or memory: http://crl.globalsign.com/root-r3.crl0c |
Source: lSmb6nDsrC.exe | String found in binary or memory: http://crl.globalsign.com/root-r6.crl0G |
Source: lSmb6nDsrC.exe, 00000000.00000003.1239683585.000000000282A000.00000004.00000020.00020000.00000000.sdmp, Labs.pif.2.dr, Orders.0.dr | String found in binary or memory: http://crl.globalsign.net/root-r3.crl0 |
Source: explorer.exe, 0000001C.00000002.2481065121.0000000007306000.00000004.00000001.00020000.00000000.sdmp, explorer.exe, 0000001C.00000000.2299433125.0000000007306000.00000004.00000001.00020000.00000000.sdmp, explorer.exe, 0000001C.00000000.2307149631.0000000008F4D000.00000004.00000001.00020000.00000000.sdmp, explorer.exe, 0000001C.00000002.2484651579.0000000008F4D000.00000004.00000001.00020000.00000000.sdmp | String found in binary or memory: http://crl3.digicert.com/DigiCertGlobalRootG2.crl07 |
Source: explorer.exe, 0000001C.00000002.2481065121.0000000007306000.00000004.00000001.00020000.00000000.sdmp, explorer.exe, 0000001C.00000000.2299433125.0000000007306000.00000004.00000001.00020000.00000000.sdmp, explorer.exe, 0000001C.00000000.2307149631.0000000008F4D000.00000004.00000001.00020000.00000000.sdmp, explorer.exe, 0000001C.00000002.2484651579.0000000008F4D000.00000004.00000001.00020000.00000000.sdmp | String found in binary or memory: http://crl4.digicert.com/DigiCertGlobalRootG2.crl0 |
Source: lSmb6nDsrC.exe | String found in binary or memory: http://nsis.sf.net/NSIS_ErrorError |
Source: explorer.exe, 0000001C.00000002.2481065121.0000000007306000.00000004.00000001.00020000.00000000.sdmp, explorer.exe, 0000001C.00000000.2299433125.0000000007306000.00000004.00000001.00020000.00000000.sdmp, explorer.exe, 0000001C.00000000.2307149631.0000000008F4D000.00000004.00000001.00020000.00000000.sdmp, explorer.exe, 0000001C.00000002.2484651579.0000000008F4D000.00000004.00000001.00020000.00000000.sdmp | String found in binary or memory: http://ocsp.digicert.com0 |
Source: explorer.exe, 0000001C.00000000.2299433125.00000000071FC000.00000004.00000001.00020000.00000000.sdmp, explorer.exe, 0000001C.00000002.2481065121.00000000071FC000.00000004.00000001.00020000.00000000.sdmp | String found in binary or memory: http://ocsp.digicert.comhttp://crl3.digicert.com/DigiCertGlobalRootG2.crlhttp://crl4.digicert.com/Di |
Source: lSmb6nDsrC.exe | String found in binary or memory: http://ocsp.globalsign.com/ca/gstsacasha384g40C |
Source: lSmb6nDsrC.exe | String found in binary or memory: http://ocsp.globalsign.com/gsgccr45codesignca20200V |
Source: lSmb6nDsrC.exe, 00000000.00000003.1239683585.000000000282A000.00000004.00000020.00020000.00000000.sdmp, Labs.pif.2.dr, Orders.0.dr | String found in binary or memory: http://ocsp2.globalsign.com/gscodesignsha2g30V |
Source: lSmb6nDsrC.exe, 00000000.00000003.1239683585.000000000282A000.00000004.00000020.00020000.00000000.sdmp, Labs.pif.2.dr, Orders.0.dr | String found in binary or memory: http://ocsp2.globalsign.com/gstimestampingsha2g20 |
Source: lSmb6nDsrC.exe, Labs.pif.2.dr, Orders.0.dr | String found in binary or memory: http://ocsp2.globalsign.com/rootr306 |
Source: lSmb6nDsrC.exe | String found in binary or memory: http://ocsp2.globalsign.com/rootr606 |
Source: explorer.exe, 0000001C.00000002.2483780350.0000000008810000.00000002.00000001.00040000.00000000.sdmp, explorer.exe, 0000001C.00000002.2483829342.0000000008820000.00000002.00000001.00040000.00000000.sdmp, explorer.exe, 0000001C.00000002.2482661406.0000000007C70000.00000002.00000001.00040000.00000000.sdmp | String found in binary or memory: http://schemas.micro |
Source: lSmb6nDsrC.exe, 00000000.00000003.1239683585.000000000282A000.00000004.00000020.00020000.00000000.sdmp, Labs.pif.2.dr, Orders.0.dr | String found in binary or memory: http://secure.globalsign.com/cacert/gscodesignsha2g3ocsp.crt08 |
Source: lSmb6nDsrC.exe | String found in binary or memory: http://secure.globalsign.com/cacert/gsgccr45codesignca2020.crt0= |
Source: lSmb6nDsrC.exe, 00000000.00000003.1239683585.000000000282A000.00000004.00000020.00020000.00000000.sdmp, Labs.pif.2.dr, Orders.0.dr | String found in binary or memory: http://secure.globalsign.com/cacert/gstimestampingsha2g2.crt0 |
Source: lSmb6nDsrC.exe | String found in binary or memory: http://secure.globalsign.com/cacert/gstsacasha384g4.crt0 |
Source: lSmb6nDsrC.exe | String found in binary or memory: http://www.aimp.ru0 |
Source: lSmb6nDsrC.exe, 00000000.00000003.1239683585.000000000282A000.00000004.00000020.00020000.00000000.sdmp, Labs.pif, 00000013.00000000.1277873491.0000000000839000.00000002.00000001.01000000.00000006.sdmp, Labs.pif, 0000001B.00000000.2191675925.0000000000839000.00000002.00000001.01000000.00000006.sdmp, Labs.pif.2.dr, Orders.0.dr | String found in binary or memory: http://www.autoitscript.com/autoit3/J |
Source: explorer.exe, 0000001C.00000002.2481065121.00000000071A4000.00000004.00000001.00020000.00000000.sdmp | String found in binary or memory: http://www.foreca.com |
Source: Labs.pif, 00000013.00000003.2252607198.00000000015A4000.00000004.00000020.00020000.00000000.sdmp, Labs.pif, 00000013.00000002.2257598808.00000000015A4000.00000004.00000020.00020000.00000000.sdmp | String found in binary or memory: https://2no.co/16G965 |
Source: Labs.pif, 00000013.00000003.2252607198.00000000015A4000.00000004.00000020.00020000.00000000.sdmp, Labs.pif, 00000013.00000002.2257598808.00000000015A4000.00000004.00000020.00020000.00000000.sdmp | String found in binary or memory: https://2no.co/16G965ZC |
Source: Labs.pif, 00000013.00000002.2257484669.0000000001514000.00000004.00000020.00020000.00000000.sdmp, Labs.pif, 00000013.00000003.2252929645.000000000150D000.00000004.00000020.00020000.00000000.sdmp, Labs.pif, 00000013.00000003.2252820608.00000000014FD000.00000004.00000020.00020000.00000000.sdmp | String found in binary or memory: https://2no.co/MR) |
Source: Labs.pif, 00000013.00000002.2257484669.0000000001514000.00000004.00000020.00020000.00000000.sdmp, Labs.pif, 00000013.00000003.2252929645.000000000150D000.00000004.00000020.00020000.00000000.sdmp, Labs.pif, 00000013.00000003.2252820608.00000000014FD000.00000004.00000020.00020000.00000000.sdmp | String found in binary or memory: https://2no.co/hR |
Source: explorer.exe, 0000001C.00000000.2307149631.0000000008F4D000.00000004.00000001.00020000.00000000.sdmp, explorer.exe, 0000001C.00000002.2484651579.0000000008F4D000.00000004.00000001.00020000.00000000.sdmp | String found in binary or memory: https://activity.windows.com/UserActivity.ReadWrite.CreatedByApp |
Source: explorer.exe, 0000001C.00000002.2484651579.000000000913F000.00000004.00000001.00020000.00000000.sdmp, explorer.exe, 0000001C.00000000.2307967181.000000000913F000.00000004.00000001.00020000.00000000.sdmp | String found in binary or memory: https://android.notify.windows.com/iOS |
Source: explorer.exe, 0000001C.00000002.2484651579.0000000008F09000.00000004.00000001.00020000.00000000.sdmp | String found in binary or memory: https://api.msn.com/ |
Source: explorer.exe, 0000001C.00000002.2484651579.0000000008DA6000.00000004.00000001.00020000.00000000.sdmp | String found in binary or memory: https://api.msn.com/v1/News/Feed/Windows?apikey=qrUeHGGYvVowZJuHA3XaH0uUvg1ZJ0GUZnXk3mxxPF&ocid=wind |
Source: explorer.exe, 0000001C.00000000.2307149631.0000000008F09000.00000004.00000001.00020000.00000000.sdmp, explorer.exe, 0000001C.00000002.2484651579.0000000008F09000.00000004.00000001.00020000.00000000.sdmp | String found in binary or memory: https://api.msn.com/v1/news/Feed/Windows? |
Source: explorer.exe, 0000001C.00000000.2299433125.00000000071FC000.00000004.00000001.00020000.00000000.sdmp, explorer.exe, 0000001C.00000002.2481065121.00000000071FC000.00000004.00000001.00020000.00000000.sdmp | String found in binary or memory: https://api.msn.com/v1/news/Feed/Windows?activityId=DD4083B70FE54739AB05D6BBA3484042&timeOut=5000&oc |
Source: explorer.exe, 0000001C.00000000.2299433125.00000000071FC000.00000004.00000001.00020000.00000000.sdmp, explorer.exe, 0000001C.00000002.2481065121.00000000071FC000.00000004.00000001.00020000.00000000.sdmp | String found in binary or memory: https://api.msn.com:443/v1/news/Feed/Windows? |
Source: explorer.exe, 0000001C.00000000.2299433125.0000000007276000.00000004.00000001.00020000.00000000.sdmp, explorer.exe, 0000001C.00000002.2481065121.0000000007276000.00000004.00000001.00020000.00000000.sdmp | String found in binary or memory: https://api.msn.com:443/v1/news/Feed/Windows?t |
Source: explorer.exe, 0000001C.00000000.2307149631.0000000008DFE000.00000004.00000001.00020000.00000000.sdmp, explorer.exe, 0000001C.00000002.2484651579.0000000008DFE000.00000004.00000001.00020000.00000000.sdmp | String found in binary or memory: https://arc.msn.com |
Source: explorer.exe, 0000001C.00000002.2481065121.00000000071FC000.00000004.00000001.00020000.00000000.sdmp | String found in binary or memory: https://assets.msn.com/weathermapdata/1/static/finance/1stparty/FinanceTaskbarIcons/Finance_Earnings |
Source: explorer.exe, 0000001C.00000002.2481065121.00000000071FC000.00000004.00000001.00020000.00000000.sdmp | String found in binary or memory: https://assets.msn.com/weathermapdata/1/static/weather/Icons/JyNGQgA=/Condition/AAehwh2.svg |
Source: explorer.exe, 0000001C.00000000.2299433125.00000000071FC000.00000004.00000001.00020000.00000000.sdmp, explorer.exe, 0000001C.00000002.2481065121.00000000071FC000.00000004.00000001.00020000.00000000.sdmp | String found in binary or memory: https://cdn.query.prod.cms.msn.com/cms/api/amp/binary/AA13f2DV |
Source: explorer.exe, 0000001C.00000000.2299433125.00000000071FC000.00000004.00000001.00020000.00000000.sdmp, explorer.exe, 0000001C.00000002.2481065121.00000000071FC000.00000004.00000001.00020000.00000000.sdmp | String found in binary or memory: https://cdn.query.prod.cms.msn.com/cms/api/amp/binary/AA13f2DV-dark |
Source: explorer.exe, 0000001C.00000000.2299433125.00000000071FC000.00000004.00000001.00020000.00000000.sdmp, explorer.exe, 0000001C.00000002.2481065121.00000000071FC000.00000004.00000001.00020000.00000000.sdmp | String found in binary or memory: https://cdn.query.prod.cms.msn.com/cms/api/amp/binary/AA13fcaT |
Source: explorer.exe, 0000001C.00000000.2299433125.00000000071FC000.00000004.00000001.00020000.00000000.sdmp, explorer.exe, 0000001C.00000002.2481065121.00000000071FC000.00000004.00000001.00020000.00000000.sdmp | String found in binary or memory: https://cdn.query.prod.cms.msn.com/cms/api/amp/binary/AA13fcaT-dark |
Source: explorer.exe, 0000001C.00000000.2310676294.000000000C091000.00000004.00000001.00020000.00000000.sdmp, explorer.exe, 0000001C.00000002.2491730290.000000000C091000.00000004.00000001.00020000.00000000.sdmp | String found in binary or memory: https://excel.office.com |
Source: explorer.exe, 0000001C.00000000.2299433125.00000000071FC000.00000004.00000001.00020000.00000000.sdmp, explorer.exe, 0000001C.00000002.2481065121.00000000071FC000.00000004.00000001.00020000.00000000.sdmp | String found in binary or memory: https://img-s-msn-com.akamaized.net/tenant/amp/entityid/AA11f7Wa.img |
Source: explorer.exe, 0000001C.00000000.2299433125.00000000071FC000.00000004.00000001.00020000.00000000.sdmp, explorer.exe, 0000001C.00000002.2481065121.00000000071FC000.00000004.00000001.00020000.00000000.sdmp | String found in binary or memory: https://img-s-msn-com.akamaized.net/tenant/amp/entityid/AA15Yat4.img |
Source: explorer.exe, 0000001C.00000000.2299433125.00000000071FC000.00000004.00000001.00020000.00000000.sdmp, explorer.exe, 0000001C.00000002.2481065121.00000000071FC000.00000004.00000001.00020000.00000000.sdmp | String found in binary or memory: https://img-s-msn-com.akamaized.net/tenant/amp/entityid/AA1bjET8.img |
Source: explorer.exe, 0000001C.00000000.2299433125.00000000071FC000.00000004.00000001.00020000.00000000.sdmp, explorer.exe, 0000001C.00000002.2481065121.00000000071FC000.00000004.00000001.00020000.00000000.sdmp | String found in binary or memory: https://img-s-msn-com.akamaized.net/tenant/amp/entityid/AA1c9Jin.img |
Source: explorer.exe, 0000001C.00000000.2299433125.00000000071FC000.00000004.00000001.00020000.00000000.sdmp, explorer.exe, 0000001C.00000002.2481065121.00000000071FC000.00000004.00000001.00020000.00000000.sdmp | String found in binary or memory: https://img-s-msn-com.akamaized.net/tenant/amp/entityid/BBNvr53.img |
Source: explorer.exe, 0000001C.00000000.2310676294.000000000C091000.00000004.00000001.00020000.00000000.sdmp, explorer.exe, 0000001C.00000002.2491730290.000000000C091000.00000004.00000001.00020000.00000000.sdmp | String found in binary or memory: https://outlook.com |
Source: explorer.exe, 0000001C.00000000.2310676294.000000000C091000.00000004.00000001.00020000.00000000.sdmp, explorer.exe, 0000001C.00000002.2491730290.000000000C091000.00000004.00000001.00020000.00000000.sdmp | String found in binary or memory: https://powerpoint.office.com |
Source: explorer.exe, 0000001C.00000000.2299433125.00000000071FC000.00000004.00000001.00020000.00000000.sdmp, explorer.exe, 0000001C.00000002.2481065121.00000000071FC000.00000004.00000001.00020000.00000000.sdmp | String found in binary or memory: https://windows.msn.com:443/shell?osLocale=en-GB&chosenMarketReason=ImplicitNew |
Source: explorer.exe, 0000001C.00000000.2299433125.00000000071FC000.00000004.00000001.00020000.00000000.sdmp, explorer.exe, 0000001C.00000002.2481065121.00000000071FC000.00000004.00000001.00020000.00000000.sdmp | String found in binary or memory: https://windows.msn.com:443/shellv2?osLocale=en-GB&chosenMarketReason=ImplicitNew |
Source: explorer.exe, 0000001C.00000000.2310676294.000000000C091000.00000004.00000001.00020000.00000000.sdmp, explorer.exe, 0000001C.00000002.2491730290.000000000C091000.00000004.00000001.00020000.00000000.sdmp | String found in binary or memory: https://word.office.com |
Source: lSmb6nDsrC.exe, 00000000.00000003.1239683585.000000000282A000.00000004.00000020.00020000.00000000.sdmp, Labs.pif.2.dr, Orders.0.dr | String found in binary or memory: https://www.autoitscript.com/autoit3/ |
Source: Orders.0.dr | String found in binary or memory: https://www.globalsign.com/repository/0 |
Source: lSmb6nDsrC.exe, 00000000.00000003.1239683585.000000000282A000.00000004.00000020.00020000.00000000.sdmp, Labs.pif.2.dr, Orders.0.dr | String found in binary or memory: https://www.globalsign.com/repository/06 |
Source: explorer.exe, 0000001C.00000000.2299433125.00000000071FC000.00000004.00000001.00020000.00000000.sdmp, explorer.exe, 0000001C.00000002.2481065121.00000000071FC000.00000004.00000001.00020000.00000000.sdmp | String found in binary or memory: https://www.msn.com/en-us/lifestyle/lifestyle-buzz/what-to-do-if-a-worst-case-nuclear-scenario-actua |
Source: explorer.exe, 0000001C.00000000.2299433125.00000000071FC000.00000004.00000001.00020000.00000000.sdmp, explorer.exe, 0000001C.00000002.2481065121.00000000071FC000.00000004.00000001.00020000.00000000.sdmp | String found in binary or memory: https://www.msn.com/en-us/money/careersandeducation/student-loan-debt-forgiveness-arrives-for-some-b |
Source: explorer.exe, 0000001C.00000000.2299433125.00000000071FC000.00000004.00000001.00020000.00000000.sdmp, explorer.exe, 0000001C.00000002.2481065121.00000000071FC000.00000004.00000001.00020000.00000000.sdmp | String found in binary or memory: https://www.msn.com/en-us/money/markets/costco-is-seeing-a-gold-rush-what-s-behind-the-demand-for-it |
Source: explorer.exe, 0000001C.00000000.2299433125.00000000071FC000.00000004.00000001.00020000.00000000.sdmp, explorer.exe, 0000001C.00000002.2481065121.00000000071FC000.00000004.00000001.00020000.00000000.sdmp | String found in binary or memory: https://www.msn.com/en-us/money/realestate/why-this-florida-city-is-a-safe-haven-from-hurricanes/ar- |
Source: explorer.exe, 0000001C.00000000.2299433125.00000000071FC000.00000004.00000001.00020000.00000000.sdmp, explorer.exe, 0000001C.00000002.2481065121.00000000071FC000.00000004.00000001.00020000.00000000.sdmp | String found in binary or memory: https://www.msn.com/en-us/music/news/6-rock-ballads-that-tug-at-the-heartstrings/ar-AA1hIdsm |
Source: explorer.exe, 0000001C.00000000.2299433125.00000000071FC000.00000004.00000001.00020000.00000000.sdmp, explorer.exe, 0000001C.00000002.2481065121.00000000071FC000.00000004.00000001.00020000.00000000.sdmp | String found in binary or memory: https://www.msn.com/en-us/news/politics/kinzinger-has-theory-about-who-next-house-speaker-will-be/vi |
Source: explorer.exe, 0000001C.00000000.2299433125.00000000071FC000.00000004.00000001.00020000.00000000.sdmp, explorer.exe, 0000001C.00000002.2481065121.00000000071FC000.00000004.00000001.00020000.00000000.sdmp | String found in binary or memory: https://www.msn.com/en-us/news/technology/prehistoric-comet-impacted-earth-and-triggered-the-switch- |
Source: explorer.exe, 0000001C.00000000.2299433125.00000000071FC000.00000004.00000001.00020000.00000000.sdmp, explorer.exe, 0000001C.00000002.2481065121.00000000071FC000.00000004.00000001.00020000.00000000.sdmp | String found in binary or memory: https://www.msn.com/en-us/news/us/dumb-and-dumber-12-states-with-the-absolute-worst-education-in-the |
Source: explorer.exe, 0000001C.00000000.2299433125.00000000071FC000.00000004.00000001.00020000.00000000.sdmp, explorer.exe, 0000001C.00000002.2481065121.00000000071FC000.00000004.00000001.00020000.00000000.sdmp | String found in binary or memory: https://www.msn.com/en-us/sports/other/simone-biles-leads-u-s-women-s-team-to-seventh-straight-world |
Source: explorer.exe, 0000001C.00000000.2299433125.00000000071FC000.00000004.00000001.00020000.00000000.sdmp, explorer.exe, 0000001C.00000002.2481065121.00000000071FC000.00000004.00000001.00020000.00000000.sdmp | String found in binary or memory: https://www.msn.com/en-us/weather/topstories/accuweather-el-ni |
Source: explorer.exe, 0000001C.00000000.2299433125.00000000071FC000.00000004.00000001.00020000.00000000.sdmp, explorer.exe, 0000001C.00000002.2481065121.00000000071FC000.00000004.00000001.00020000.00000000.sdmp | String found in binary or memory: https://www.msn.com/en-us/weather/topstories/here-s-who-could-see-above-average-snowfall-this-winter |
Source: explorer.exe, 0000001C.00000000.2299433125.00000000071FC000.00000004.00000001.00020000.00000000.sdmp, explorer.exe, 0000001C.00000002.2481065121.00000000071FC000.00000004.00000001.00020000.00000000.sdmp | String found in binary or memory: https://www.msn.com/en-us/weather/topstories/us-winter-forecast-for-the-2023-2024-season/ar-AA1hGINt |
Source: explorer.exe, 0000001C.00000000.2299433125.00000000071FC000.00000004.00000001.00020000.00000000.sdmp, explorer.exe, 0000001C.00000002.2481065121.00000000071FC000.00000004.00000001.00020000.00000000.sdmp | String found in binary or memory: https://www.msn.com:443/en-us/feed |
Source: explorer.exe, 0000001C.00000002.2481065121.00000000071A4000.00000004.00000001.00020000.00000000.sdmp | String found in binary or memory: https://www.pollensense.com/ |
Source: C:\Users\user\AppData\Local\Microsoft\Windows\INetCache\55116385\Labs.pif | Code function: 19_2_007FD164 DefDlgProcW,SendMessageW,GetWindowLongW,SendMessageW,SendMessageW,_wcsncpy,GetKeyState,GetKeyState,GetKeyState,SendMessageW,GetKeyState,SendMessageW,SendMessageW,SendMessageW,ImageList_SetDragCursorImage,ImageList_BeginDrag,SetCapture,ClientToScreen,ImageList_DragEnter,InvalidateRect,ReleaseCapture,GetCursorPos,ScreenToClient,SendMessageW,SendMessageW,SendMessageW,SendMessageW,SendMessageW,SendMessageW,SendMessageW,GetCursorPos,ScreenToClient,GetParent,SendMessageW,SendMessageW,ClientToScreen,TrackPopupMenuEx,SendMessageW,SendMessageW,ClientToScreen,TrackPopupMenuEx,GetWindowLongW, | 19_2_007FD164 |
Source: C:\Users\user\AppData\Local\Microsoft\Windows\INetCache\55116385\Labs.pif | Code function: 27_2_007FD164 DefDlgProcW,SendMessageW,GetWindowLongW,SendMessageW,SendMessageW,_wcsncpy,GetKeyState,GetKeyState,GetKeyState,SendMessageW,GetKeyState,SendMessageW,SendMessageW,SendMessageW,ImageList_SetDragCursorImage,ImageList_BeginDrag,SetCapture,ClientToScreen,ImageList_DragEnter,InvalidateRect,ReleaseCapture,GetCursorPos,ScreenToClient,SendMessageW,SendMessageW,SendMessageW,SendMessageW,SendMessageW,SendMessageW,SendMessageW,GetCursorPos,ScreenToClient,GetParent,SendMessageW,SendMessageW,ClientToScreen,TrackPopupMenuEx,SendMessageW,SendMessageW,ClientToScreen,TrackPopupMenuEx,GetWindowLongW, | 27_2_007FD164 |
Source: C:\Users\user\AppData\Local\Microsoft\Windows\INetCache\55116385\Labs.pif | Code function: 27_2_00402F13 RtlCreateUserThread,NtTerminateProcess, | 27_2_00402F13 |
Source: C:\Users\user\AppData\Local\Microsoft\Windows\INetCache\55116385\Labs.pif | Code function: 27_2_0040259B NtEnumerateKey, | 27_2_0040259B |
Source: C:\Users\user\AppData\Local\Microsoft\Windows\INetCache\55116385\Labs.pif | Code function: 27_2_004014B0 NtDuplicateObject,NtCreateSection,NtMapViewOfSection,NtMapViewOfSection,NtCreateSection,NtMapViewOfSection,NtMapViewOfSection, | 27_2_004014B0 |
Source: C:\Users\user\AppData\Local\Microsoft\Windows\INetCache\55116385\Labs.pif | Code function: 27_2_00403251 MapViewOfFile,NtMapViewOfSection,NtDuplicateObject,NtQuerySystemInformation,NtOpenKey,strstr,wcsstr,tolower,towlower, | 27_2_00403251 |
Source: C:\Users\user\AppData\Local\Microsoft\Windows\INetCache\55116385\Labs.pif | Code function: 27_2_00402F71 RtlCreateUserThread,NtTerminateProcess, | 27_2_00402F71 |
Source: C:\Users\user\AppData\Local\Microsoft\Windows\INetCache\55116385\Labs.pif | Code function: 27_2_004014CD NtDuplicateObject,NtCreateSection,NtMapViewOfSection,NtMapViewOfSection,NtCreateSection,NtMapViewOfSection,NtMapViewOfSection, | 27_2_004014CD |
Source: C:\Users\user\AppData\Local\Microsoft\Windows\INetCache\55116385\Labs.pif | Code function: 27_2_004014E0 NtDuplicateObject,NtCreateSection,NtMapViewOfSection,NtMapViewOfSection,NtCreateSection,NtMapViewOfSection,NtMapViewOfSection, | 27_2_004014E0 |
Source: C:\Users\user\AppData\Local\Microsoft\Windows\INetCache\55116385\Labs.pif | Code function: 27_2_004014F3 NtDuplicateObject,NtCreateSection,NtMapViewOfSection,NtMapViewOfSection,NtCreateSection,NtMapViewOfSection,NtMapViewOfSection, | 27_2_004014F3 |
Source: C:\Users\user\AppData\Local\Microsoft\Windows\INetCache\55116385\Labs.pif | Code function: 27_2_004014BB NtDuplicateObject,NtCreateSection,NtMapViewOfSection,NtMapViewOfSection,NtCreateSection,NtMapViewOfSection,NtMapViewOfSection, | 27_2_004014BB |
Source: C:\Users\user\Desktop\lSmb6nDsrC.exe | Code function: 0_2_00406C3F | 0_2_00406C3F |
Source: C:\Users\user\AppData\Local\Microsoft\Windows\INetCache\55116385\Labs.pif | Code function: 19_2_0077B020 | 19_2_0077B020 |
Source: C:\Users\user\AppData\Local\Microsoft\Windows\INetCache\55116385\Labs.pif | Code function: 19_2_00779C80 | 19_2_00779C80 |
Source: C:\Users\user\AppData\Local\Microsoft\Windows\INetCache\55116385\Labs.pif | Code function: 19_2_007923F5 | 19_2_007923F5 |
Source: C:\Users\user\AppData\Local\Microsoft\Windows\INetCache\55116385\Labs.pif | Code function: 19_2_007F8400 | 19_2_007F8400 |
Source: C:\Users\user\AppData\Local\Microsoft\Windows\INetCache\55116385\Labs.pif | Code function: 19_2_007A6502 | 19_2_007A6502 |
Source: C:\Users\user\AppData\Local\Microsoft\Windows\INetCache\55116385\Labs.pif | Code function: 19_2_007A265E | 19_2_007A265E |
Source: C:\Users\user\AppData\Local\Microsoft\Windows\INetCache\55116385\Labs.pif | Code function: 19_2_0077E6F0 | 19_2_0077E6F0 |
Source: C:\Users\user\AppData\Local\Microsoft\Windows\INetCache\55116385\Labs.pif | Code function: 19_2_0079282A | 19_2_0079282A |
Source: C:\Users\user\AppData\Local\Microsoft\Windows\INetCache\55116385\Labs.pif | Code function: 19_2_007A89BF | 19_2_007A89BF |
Source: C:\Users\user\AppData\Local\Microsoft\Windows\INetCache\55116385\Labs.pif | Code function: 19_2_007A6A74 | 19_2_007A6A74 |
Source: C:\Users\user\AppData\Local\Microsoft\Windows\INetCache\55116385\Labs.pif | Code function: 19_2_007F0A3A | 19_2_007F0A3A |
Source: C:\Users\user\AppData\Local\Microsoft\Windows\INetCache\55116385\Labs.pif | Code function: 19_2_00780BE0 | 19_2_00780BE0 |
Source: C:\Users\user\AppData\Local\Microsoft\Windows\INetCache\55116385\Labs.pif | Code function: 19_2_0079CD51 | 19_2_0079CD51 |
Source: C:\Users\user\AppData\Local\Microsoft\Windows\INetCache\55116385\Labs.pif | Code function: 19_2_007CEDB2 | 19_2_007CEDB2 |
Source: C:\Users\user\AppData\Local\Microsoft\Windows\INetCache\55116385\Labs.pif | Code function: 19_2_007D8E44 | 19_2_007D8E44 |
Source: C:\Users\user\AppData\Local\Microsoft\Windows\INetCache\55116385\Labs.pif | Code function: 19_2_007F0EB7 | 19_2_007F0EB7 |
Source: C:\Users\user\AppData\Local\Microsoft\Windows\INetCache\55116385\Labs.pif | Code function: 19_2_007A6FE6 | 19_2_007A6FE6 |
Source: C:\Users\user\AppData\Local\Microsoft\Windows\INetCache\55116385\Labs.pif | Code function: 19_2_007933B7 | 19_2_007933B7 |
Source: C:\Users\user\AppData\Local\Microsoft\Windows\INetCache\55116385\Labs.pif | Code function: 19_2_0078D45D | 19_2_0078D45D |
Source: C:\Users\user\AppData\Local\Microsoft\Windows\INetCache\55116385\Labs.pif | Code function: 19_2_0079F409 | 19_2_0079F409 |
Source: C:\Users\user\AppData\Local\Microsoft\Windows\INetCache\55116385\Labs.pif | Code function: 19_2_007794E0 | 19_2_007794E0 |
Source: C:\Users\user\AppData\Local\Microsoft\Windows\INetCache\55116385\Labs.pif | Code function: 19_2_00771663 | 19_2_00771663 |
Source: C:\Users\user\AppData\Local\Microsoft\Windows\INetCache\55116385\Labs.pif | Code function: 19_2_0078F628 | 19_2_0078F628 |
Source: C:\Users\user\AppData\Local\Microsoft\Windows\INetCache\55116385\Labs.pif | Code function: 19_2_007916B4 | 19_2_007916B4 |
Source: C:\Users\user\AppData\Local\Microsoft\Windows\INetCache\55116385\Labs.pif | Code function: 19_2_0077F6A0 | 19_2_0077F6A0 |
Source: C:\Users\user\AppData\Local\Microsoft\Windows\INetCache\55116385\Labs.pif | Code function: 19_2_007978C3 | 19_2_007978C3 |
Source: C:\Users\user\AppData\Local\Microsoft\Windows\INetCache\55116385\Labs.pif | Code function: 19_2_00791BA8 | 19_2_00791BA8 |
Source: C:\Users\user\AppData\Local\Microsoft\Windows\INetCache\55116385\Labs.pif | Code function: 19_2_0079DBA5 | 19_2_0079DBA5 |
Source: C:\Users\user\AppData\Local\Microsoft\Windows\INetCache\55116385\Labs.pif | Code function: 19_2_007A9CE5 | 19_2_007A9CE5 |
Source: C:\Users\user\AppData\Local\Microsoft\Windows\INetCache\55116385\Labs.pif | Code function: 19_2_0078DD28 | 19_2_0078DD28 |
Source: C:\Users\user\AppData\Local\Microsoft\Windows\INetCache\55116385\Labs.pif | Code function: 19_2_0079BFD6 | 19_2_0079BFD6 |
Source: C:\Users\user\AppData\Local\Microsoft\Windows\INetCache\55116385\Labs.pif | Code function: 19_2_00791FC0 | 19_2_00791FC0 |
Source: C:\Users\user\AppData\Local\Microsoft\Windows\INetCache\55116385\Labs.pif | Code function: 27_2_007923F5 | 27_2_007923F5 |
Source: C:\Users\user\AppData\Local\Microsoft\Windows\INetCache\55116385\Labs.pif | Code function: 27_2_007F8400 | 27_2_007F8400 |
Source: C:\Users\user\AppData\Local\Microsoft\Windows\INetCache\55116385\Labs.pif | Code function: 27_2_007A6502 | 27_2_007A6502 |
Source: C:\Users\user\AppData\Local\Microsoft\Windows\INetCache\55116385\Labs.pif | Code function: 27_2_007A265E | 27_2_007A265E |
Source: C:\Users\user\AppData\Local\Microsoft\Windows\INetCache\55116385\Labs.pif | Code function: 27_2_0077E6F0 | 27_2_0077E6F0 |
Source: C:\Users\user\AppData\Local\Microsoft\Windows\INetCache\55116385\Labs.pif | Code function: 27_2_0079282A | 27_2_0079282A |
Source: C:\Users\user\AppData\Local\Microsoft\Windows\INetCache\55116385\Labs.pif | Code function: 27_2_007A89BF | 27_2_007A89BF |
Source: C:\Users\user\AppData\Local\Microsoft\Windows\INetCache\55116385\Labs.pif | Code function: 27_2_007A6A74 | 27_2_007A6A74 |
Source: C:\Users\user\AppData\Local\Microsoft\Windows\INetCache\55116385\Labs.pif | Code function: 27_2_007F0A3A | 27_2_007F0A3A |
Source: C:\Users\user\AppData\Local\Microsoft\Windows\INetCache\55116385\Labs.pif | Code function: 27_2_00780BE0 | 27_2_00780BE0 |
Source: C:\Users\user\AppData\Local\Microsoft\Windows\INetCache\55116385\Labs.pif | Code function: 27_2_0079CD51 | 27_2_0079CD51 |
Source: C:\Users\user\AppData\Local\Microsoft\Windows\INetCache\55116385\Labs.pif | Code function: 27_2_007CEDB2 | 27_2_007CEDB2 |
Source: C:\Users\user\AppData\Local\Microsoft\Windows\INetCache\55116385\Labs.pif | Code function: 27_2_007D8E44 | 27_2_007D8E44 |
Source: C:\Users\user\AppData\Local\Microsoft\Windows\INetCache\55116385\Labs.pif | Code function: 27_2_007F0EB7 | 27_2_007F0EB7 |
Source: C:\Users\user\AppData\Local\Microsoft\Windows\INetCache\55116385\Labs.pif | Code function: 27_2_007A6FE6 | 27_2_007A6FE6 |
Source: C:\Users\user\AppData\Local\Microsoft\Windows\INetCache\55116385\Labs.pif | Code function: 27_2_0077B020 | 27_2_0077B020 |
Source: C:\Users\user\AppData\Local\Microsoft\Windows\INetCache\55116385\Labs.pif | Code function: 27_2_007933B7 | 27_2_007933B7 |
Source: C:\Users\user\AppData\Local\Microsoft\Windows\INetCache\55116385\Labs.pif | Code function: 27_2_0078D45D | 27_2_0078D45D |
Source: C:\Users\user\AppData\Local\Microsoft\Windows\INetCache\55116385\Labs.pif | Code function: 27_2_0079F409 | 27_2_0079F409 |
Source: C:\Users\user\AppData\Local\Microsoft\Windows\INetCache\55116385\Labs.pif | Code function: 27_2_007794E0 | 27_2_007794E0 |
Source: C:\Users\user\AppData\Local\Microsoft\Windows\INetCache\55116385\Labs.pif | Code function: 27_2_00771663 | 27_2_00771663 |
Source: C:\Users\user\AppData\Local\Microsoft\Windows\INetCache\55116385\Labs.pif | Code function: 27_2_0078F628 | 27_2_0078F628 |
Source: C:\Users\user\AppData\Local\Microsoft\Windows\INetCache\55116385\Labs.pif | Code function: 27_2_007916B4 | 27_2_007916B4 |
Source: C:\Users\user\AppData\Local\Microsoft\Windows\INetCache\55116385\Labs.pif | Code function: 27_2_0077F6A0 | 27_2_0077F6A0 |
Source: C:\Users\user\AppData\Local\Microsoft\Windows\INetCache\55116385\Labs.pif | Code function: 27_2_007978C3 | 27_2_007978C3 |
Source: C:\Users\user\AppData\Local\Microsoft\Windows\INetCache\55116385\Labs.pif | Code function: 27_2_00791BA8 | 27_2_00791BA8 |
Source: C:\Users\user\AppData\Local\Microsoft\Windows\INetCache\55116385\Labs.pif | Code function: 27_2_0079DBA5 | 27_2_0079DBA5 |
Source: C:\Users\user\AppData\Local\Microsoft\Windows\INetCache\55116385\Labs.pif | Code function: 27_2_007A9CE5 | 27_2_007A9CE5 |
Source: C:\Users\user\AppData\Local\Microsoft\Windows\INetCache\55116385\Labs.pif | Code function: 27_2_00779C80 | 27_2_00779C80 |
Source: C:\Users\user\AppData\Local\Microsoft\Windows\INetCache\55116385\Labs.pif | Code function: 27_2_0078DD28 | 27_2_0078DD28 |
Source: C:\Users\user\AppData\Local\Microsoft\Windows\INetCache\55116385\Labs.pif | Code function: 27_2_0079BFD6 | 27_2_0079BFD6 |
Source: C:\Users\user\AppData\Local\Microsoft\Windows\INetCache\55116385\Labs.pif | Code function: 27_2_00791FC0 | 27_2_00791FC0 |
Source: unknown | Process created: C:\Users\user\Desktop\lSmb6nDsrC.exe "C:\Users\user\Desktop\lSmb6nDsrC.exe" | |
Source: C:\Users\user\Desktop\lSmb6nDsrC.exe | Process created: C:\Windows\SysWOW64\cmd.exe "C:\Windows\System32\cmd.exe" /k move Origins Origins.cmd & Origins.cmd & exit | |
Source: C:\Windows\SysWOW64\cmd.exe | Process created: C:\Windows\System32\conhost.exe C:\Windows\system32\conhost.exe 0xffffffff -ForceV1 | |
Source: C:\Windows\SysWOW64\cmd.exe | Process created: C:\Windows\SysWOW64\tasklist.exe tasklist | |
Source: C:\Windows\SysWOW64\cmd.exe | Process created: C:\Windows\SysWOW64\findstr.exe findstr /I "wrsa.exe opssvc.exe" | |
Source: C:\Windows\SysWOW64\cmd.exe | Process created: C:\Windows\SysWOW64\tasklist.exe tasklist | |
Source: C:\Windows\SysWOW64\cmd.exe | Process created: C:\Windows\SysWOW64\findstr.exe findstr /I "avastui.exe avgui.exe nswscsvc.exe sophoshealth.exe" | |
Source: C:\Windows\SysWOW64\cmd.exe | Process created: C:\Windows\SysWOW64\cmd.exe cmd /c md 55116385 | |
Source: C:\Windows\SysWOW64\cmd.exe | Process created: C:\Windows\SysWOW64\findstr.exe findstr /V "SlutSteLouisTranslation" Cyprus | |
Source: C:\Windows\SysWOW64\cmd.exe | Process created: C:\Windows\SysWOW64\cmd.exe cmd /c copy /b Breeding + Fuji + Weather 55116385\s | |
Source: C:\Windows\SysWOW64\cmd.exe | Process created: C:\Users\user\AppData\Local\Microsoft\Windows\INetCache\55116385\Labs.pif 55116385\Labs.pif 55116385\s | |
Source: C:\Windows\SysWOW64\cmd.exe | Process created: C:\Windows\SysWOW64\PING.EXE ping -n 5 127.0.0.1 | |
Source: C:\Users\user\AppData\Local\Microsoft\Windows\INetCache\55116385\Labs.pif | Process created: C:\Users\user\AppData\Local\Microsoft\Windows\INetCache\55116385\Labs.pif C:\Users\user\AppData\Local\Microsoft\Windows\INetCache\55116385\Labs.pif | |
Source: C:\Users\user\Desktop\lSmb6nDsrC.exe | Process created: C:\Windows\SysWOW64\cmd.exe "C:\Windows\System32\cmd.exe" /k move Origins Origins.cmd & Origins.cmd & exit | Jump to behavior |
Source: C:\Windows\SysWOW64\cmd.exe | Process created: C:\Windows\SysWOW64\tasklist.exe tasklist | Jump to behavior |
Source: C:\Windows\SysWOW64\cmd.exe | Process created: C:\Windows\SysWOW64\findstr.exe findstr /I "wrsa.exe opssvc.exe" | Jump to behavior |
Source: C:\Windows\SysWOW64\cmd.exe | Process created: C:\Windows\SysWOW64\tasklist.exe tasklist | Jump to behavior |
Source: C:\Windows\SysWOW64\cmd.exe | Process created: C:\Windows\SysWOW64\findstr.exe findstr /I "avastui.exe avgui.exe nswscsvc.exe sophoshealth.exe" | Jump to behavior |
Source: C:\Windows\SysWOW64\cmd.exe | Process created: C:\Windows\SysWOW64\cmd.exe cmd /c md 55116385 | Jump to behavior |
Source: C:\Windows\SysWOW64\cmd.exe | Process created: C:\Windows\SysWOW64\findstr.exe findstr /V "SlutSteLouisTranslation" Cyprus | Jump to behavior |
Source: C:\Windows\SysWOW64\cmd.exe | Process created: C:\Windows\SysWOW64\cmd.exe cmd /c copy /b Breeding + Fuji + Weather 55116385\s | Jump to behavior |
Source: C:\Windows\SysWOW64\cmd.exe | Process created: C:\Users\user\AppData\Local\Microsoft\Windows\INetCache\55116385\Labs.pif 55116385\Labs.pif 55116385\s | Jump to behavior |
Source: C:\Windows\SysWOW64\cmd.exe | Process created: C:\Windows\SysWOW64\PING.EXE ping -n 5 127.0.0.1 | Jump to behavior |
Source: C:\Users\user\AppData\Local\Microsoft\Windows\INetCache\55116385\Labs.pif | Process created: C:\Users\user\AppData\Local\Microsoft\Windows\INetCache\55116385\Labs.pif C:\Users\user\AppData\Local\Microsoft\Windows\INetCache\55116385\Labs.pif | Jump to behavior |
Source: C:\Users\user\Desktop\lSmb6nDsrC.exe | Section loaded: uxtheme.dll | Jump to behavior |
Source: C:\Users\user\Desktop\lSmb6nDsrC.exe | Section loaded: userenv.dll | Jump to behavior |
Source: C:\Users\user\Desktop\lSmb6nDsrC.exe | Section loaded: apphelp.dll | Jump to behavior |
Source: C:\Users\user\Desktop\lSmb6nDsrC.exe | Section loaded: propsys.dll | Jump to behavior |
Source: C:\Users\user\Desktop\lSmb6nDsrC.exe | Section loaded: dwmapi.dll | Jump to behavior |
Source: C:\Users\user\Desktop\lSmb6nDsrC.exe | Section loaded: cryptbase.dll | Jump to behavior |
Source: C:\Users\user\Desktop\lSmb6nDsrC.exe | Section loaded: oleacc.dll | Jump to behavior |
Source: C:\Users\user\Desktop\lSmb6nDsrC.exe | Section loaded: ntmarta.dll | Jump to behavior |
Source: C:\Users\user\Desktop\lSmb6nDsrC.exe | Section loaded: version.dll | Jump to behavior |
Source: C:\Users\user\Desktop\lSmb6nDsrC.exe | Section loaded: shfolder.dll | Jump to behavior |
Source: C:\Users\user\Desktop\lSmb6nDsrC.exe | Section loaded: kernel.appcore.dll | Jump to behavior |
Source: C:\Users\user\Desktop\lSmb6nDsrC.exe | Section loaded: windows.storage.dll | Jump to behavior |
Source: C:\Users\user\Desktop\lSmb6nDsrC.exe | Section loaded: wldp.dll | Jump to behavior |
Source: C:\Users\user\Desktop\lSmb6nDsrC.exe | Section loaded: riched20.dll | Jump to behavior |
Source: C:\Users\user\Desktop\lSmb6nDsrC.exe | Section loaded: usp10.dll | Jump to behavior |
Source: C:\Users\user\Desktop\lSmb6nDsrC.exe | Section loaded: msls31.dll | Jump to behavior |
Source: C:\Users\user\Desktop\lSmb6nDsrC.exe | Section loaded: textinputframework.dll | Jump to behavior |
Source: C:\Users\user\Desktop\lSmb6nDsrC.exe | Section loaded: coreuicomponents.dll | Jump to behavior |
Source: C:\Users\user\Desktop\lSmb6nDsrC.exe | Section loaded: coremessaging.dll | Jump to behavior |
Source: C:\Users\user\Desktop\lSmb6nDsrC.exe | Section loaded: coremessaging.dll | Jump to behavior |
Source: C:\Users\user\Desktop\lSmb6nDsrC.exe | Section loaded: wintypes.dll | Jump to behavior |
Source: C:\Users\user\Desktop\lSmb6nDsrC.exe | Section loaded: wintypes.dll | Jump to behavior |
Source: C:\Users\user\Desktop\lSmb6nDsrC.exe | Section loaded: wintypes.dll | Jump to behavior |
Source: C:\Users\user\Desktop\lSmb6nDsrC.exe | Section loaded: textshaping.dll | Jump to behavior |
Source: C:\Users\user\Desktop\lSmb6nDsrC.exe | Section loaded: profapi.dll | Jump to behavior |
Source: C:\Users\user\Desktop\lSmb6nDsrC.exe | Section loaded: edputil.dll | Jump to behavior |
Source: C:\Users\user\Desktop\lSmb6nDsrC.exe | Section loaded: urlmon.dll | Jump to behavior |
Source: C:\Users\user\Desktop\lSmb6nDsrC.exe | Section loaded: iertutil.dll | Jump to behavior |
Source: C:\Users\user\Desktop\lSmb6nDsrC.exe | Section loaded: srvcli.dll | Jump to behavior |
Source: C:\Users\user\Desktop\lSmb6nDsrC.exe | Section loaded: netutils.dll | Jump to behavior |
Source: C:\Users\user\Desktop\lSmb6nDsrC.exe | Section loaded: windows.staterepositoryps.dll | Jump to behavior |
Source: C:\Users\user\Desktop\lSmb6nDsrC.exe | Section loaded: sspicli.dll | Jump to behavior |
Source: C:\Users\user\Desktop\lSmb6nDsrC.exe | Section loaded: appresolver.dll | Jump to behavior |
Source: C:\Users\user\Desktop\lSmb6nDsrC.exe | Section loaded: bcp47langs.dll | Jump to behavior |
Source: C:\Users\user\Desktop\lSmb6nDsrC.exe | Section loaded: slc.dll | Jump to behavior |
Source: C:\Users\user\Desktop\lSmb6nDsrC.exe | Section loaded: sppc.dll | Jump to behavior |
Source: C:\Users\user\Desktop\lSmb6nDsrC.exe | Section loaded: onecorecommonproxystub.dll | Jump to behavior |
Source: C:\Users\user\Desktop\lSmb6nDsrC.exe | Section loaded: onecoreuapcommonproxystub.dll | Jump to behavior |
Source: C:\Windows\SysWOW64\cmd.exe | Section loaded: cmdext.dll | Jump to behavior |
Source: C:\Windows\SysWOW64\cmd.exe | Section loaded: apphelp.dll | Jump to behavior |
Source: C:\Windows\SysWOW64\tasklist.exe | Section loaded: version.dll | Jump to behavior |
Source: C:\Windows\SysWOW64\tasklist.exe | Section loaded: mpr.dll | Jump to behavior |
Source: C:\Windows\SysWOW64\tasklist.exe | Section loaded: framedynos.dll | Jump to behavior |
Source: C:\Windows\SysWOW64\tasklist.exe | Section loaded: dbghelp.dll | Jump to behavior |
Source: C:\Windows\SysWOW64\tasklist.exe | Section loaded: sspicli.dll | Jump to behavior |
Source: C:\Windows\SysWOW64\tasklist.exe | Section loaded: srvcli.dll | Jump to behavior |
Source: C:\Windows\SysWOW64\tasklist.exe | Section loaded: netutils.dll | Jump to behavior |
Source: C:\Windows\SysWOW64\tasklist.exe | Section loaded: sspicli.dll | Jump to behavior |
Source: C:\Windows\SysWOW64\tasklist.exe | Section loaded: kernel.appcore.dll | Jump to behavior |
Source: C:\Windows\SysWOW64\tasklist.exe | Section loaded: wbemcomn.dll | Jump to behavior |
Source: C:\Windows\SysWOW64\tasklist.exe | Section loaded: winsta.dll | Jump to behavior |
Source: C:\Windows\SysWOW64\tasklist.exe | Section loaded: amsi.dll | Jump to behavior |
Source: C:\Windows\SysWOW64\tasklist.exe | Section loaded: userenv.dll | Jump to behavior |
Source: C:\Windows\SysWOW64\tasklist.exe | Section loaded: profapi.dll | Jump to behavior |
Source: C:\Windows\SysWOW64\tasklist.exe | Section loaded: version.dll | Jump to behavior |
Source: C:\Windows\SysWOW64\tasklist.exe | Section loaded: mpr.dll | Jump to behavior |
Source: C:\Windows\SysWOW64\tasklist.exe | Section loaded: framedynos.dll | Jump to behavior |
Source: C:\Windows\SysWOW64\tasklist.exe | Section loaded: dbghelp.dll | Jump to behavior |
Source: C:\Windows\SysWOW64\tasklist.exe | Section loaded: sspicli.dll | Jump to behavior |
Source: C:\Windows\SysWOW64\tasklist.exe | Section loaded: srvcli.dll | Jump to behavior |
Source: C:\Windows\SysWOW64\tasklist.exe | Section loaded: netutils.dll | Jump to behavior |
Source: C:\Windows\SysWOW64\tasklist.exe | Section loaded: sspicli.dll | Jump to behavior |
Source: C:\Windows\SysWOW64\tasklist.exe | Section loaded: kernel.appcore.dll | Jump to behavior |
Source: C:\Windows\SysWOW64\tasklist.exe | Section loaded: wbemcomn.dll | Jump to behavior |
Source: C:\Windows\SysWOW64\tasklist.exe | Section loaded: winsta.dll | Jump to behavior |
Source: C:\Windows\SysWOW64\tasklist.exe | Section loaded: amsi.dll | Jump to behavior |
Source: C:\Windows\SysWOW64\tasklist.exe | Section loaded: userenv.dll | Jump to behavior |
Source: C:\Windows\SysWOW64\tasklist.exe | Section loaded: profapi.dll | Jump to behavior |
Source: C:\Users\user\AppData\Local\Microsoft\Windows\INetCache\55116385\Labs.pif | Section loaded: wsock32.dll | Jump to behavior |
Source: C:\Users\user\AppData\Local\Microsoft\Windows\INetCache\55116385\Labs.pif | Section loaded: version.dll | Jump to behavior |
Source: C:\Users\user\AppData\Local\Microsoft\Windows\INetCache\55116385\Labs.pif | Section loaded: winmm.dll | Jump to behavior |
Source: C:\Users\user\AppData\Local\Microsoft\Windows\INetCache\55116385\Labs.pif | Section loaded: mpr.dll | Jump to behavior |
Source: C:\Users\user\AppData\Local\Microsoft\Windows\INetCache\55116385\Labs.pif | Section loaded: wininet.dll | Jump to behavior |
Source: C:\Users\user\AppData\Local\Microsoft\Windows\INetCache\55116385\Labs.pif | Section loaded: iphlpapi.dll | Jump to behavior |
Source: C:\Users\user\AppData\Local\Microsoft\Windows\INetCache\55116385\Labs.pif | Section loaded: userenv.dll | Jump to behavior |
Source: C:\Users\user\AppData\Local\Microsoft\Windows\INetCache\55116385\Labs.pif | Section loaded: uxtheme.dll | Jump to behavior |
Source: C:\Users\user\AppData\Local\Microsoft\Windows\INetCache\55116385\Labs.pif | Section loaded: kernel.appcore.dll | Jump to behavior |
Source: C:\Users\user\AppData\Local\Microsoft\Windows\INetCache\55116385\Labs.pif | Section loaded: windows.storage.dll | Jump to behavior |
Source: C:\Users\user\AppData\Local\Microsoft\Windows\INetCache\55116385\Labs.pif | Section loaded: wldp.dll | Jump to behavior |
Source: C:\Users\user\AppData\Local\Microsoft\Windows\INetCache\55116385\Labs.pif | Section loaded: iertutil.dll | Jump to behavior |
Source: C:\Users\user\AppData\Local\Microsoft\Windows\INetCache\55116385\Labs.pif | Section loaded: sspicli.dll | Jump to behavior |
Source: C:\Users\user\AppData\Local\Microsoft\Windows\INetCache\55116385\Labs.pif | Section loaded: profapi.dll | Jump to behavior |
Source: C:\Users\user\AppData\Local\Microsoft\Windows\INetCache\55116385\Labs.pif | Section loaded: ondemandconnroutehelper.dll | Jump to behavior |
Source: C:\Users\user\AppData\Local\Microsoft\Windows\INetCache\55116385\Labs.pif | Section loaded: winhttp.dll | Jump to behavior |
Source: C:\Users\user\AppData\Local\Microsoft\Windows\INetCache\55116385\Labs.pif | Section loaded: mswsock.dll | Jump to behavior |
Source: C:\Users\user\AppData\Local\Microsoft\Windows\INetCache\55116385\Labs.pif | Section loaded: winnsi.dll | Jump to behavior |
Source: C:\Users\user\AppData\Local\Microsoft\Windows\INetCache\55116385\Labs.pif | Section loaded: urlmon.dll | Jump to behavior |
Source: C:\Users\user\AppData\Local\Microsoft\Windows\INetCache\55116385\Labs.pif | Section loaded: srvcli.dll | Jump to behavior |
Source: C:\Users\user\AppData\Local\Microsoft\Windows\INetCache\55116385\Labs.pif | Section loaded: netutils.dll | Jump to behavior |
Source: C:\Users\user\AppData\Local\Microsoft\Windows\INetCache\55116385\Labs.pif | Section loaded: dnsapi.dll | Jump to behavior |
Source: C:\Users\user\AppData\Local\Microsoft\Windows\INetCache\55116385\Labs.pif | Section loaded: rasadhlp.dll | Jump to behavior |
Source: C:\Users\user\AppData\Local\Microsoft\Windows\INetCache\55116385\Labs.pif | Section loaded: fwpuclnt.dll | Jump to behavior |
Source: C:\Users\user\AppData\Local\Microsoft\Windows\INetCache\55116385\Labs.pif | Section loaded: schannel.dll | Jump to behavior |
Source: C:\Users\user\AppData\Local\Microsoft\Windows\INetCache\55116385\Labs.pif | Section loaded: mskeyprotect.dll | Jump to behavior |
Source: C:\Users\user\AppData\Local\Microsoft\Windows\INetCache\55116385\Labs.pif | Section loaded: ntasn1.dll | Jump to behavior |
Source: C:\Users\user\AppData\Local\Microsoft\Windows\INetCache\55116385\Labs.pif | Section loaded: msasn1.dll | Jump to behavior |
Source: C:\Users\user\AppData\Local\Microsoft\Windows\INetCache\55116385\Labs.pif | Section loaded: dpapi.dll | Jump to behavior |
Source: C:\Users\user\AppData\Local\Microsoft\Windows\INetCache\55116385\Labs.pif | Section loaded: cryptsp.dll | Jump to behavior |
Source: C:\Users\user\AppData\Local\Microsoft\Windows\INetCache\55116385\Labs.pif | Section loaded: rsaenh.dll | Jump to behavior |
Source: C:\Users\user\AppData\Local\Microsoft\Windows\INetCache\55116385\Labs.pif | Section loaded: cryptbase.dll | Jump to behavior |
Source: C:\Users\user\AppData\Local\Microsoft\Windows\INetCache\55116385\Labs.pif | Section loaded: gpapi.dll | Jump to behavior |
Source: C:\Users\user\AppData\Local\Microsoft\Windows\INetCache\55116385\Labs.pif | Section loaded: ncrypt.dll | Jump to behavior |
Source: C:\Users\user\AppData\Local\Microsoft\Windows\INetCache\55116385\Labs.pif | Section loaded: ncryptsslp.dll | Jump to behavior |
Source: C:\Users\user\AppData\Local\Microsoft\Windows\INetCache\55116385\Labs.pif | Section loaded: napinsp.dll | Jump to behavior |
Source: C:\Users\user\AppData\Local\Microsoft\Windows\INetCache\55116385\Labs.pif | Section loaded: pnrpnsp.dll | Jump to behavior |
Source: C:\Users\user\AppData\Local\Microsoft\Windows\INetCache\55116385\Labs.pif | Section loaded: wshbth.dll | Jump to behavior |
Source: C:\Users\user\AppData\Local\Microsoft\Windows\INetCache\55116385\Labs.pif | Section loaded: nlaapi.dll | Jump to behavior |
Source: C:\Users\user\AppData\Local\Microsoft\Windows\INetCache\55116385\Labs.pif | Section loaded: winrnr.dll | Jump to behavior |
Source: C:\Windows\SysWOW64\PING.EXE | Section loaded: iphlpapi.dll | Jump to behavior |
Source: C:\Windows\SysWOW64\PING.EXE | Section loaded: winnsi.dll | Jump to behavior |
Source: C:\Windows\SysWOW64\PING.EXE | Section loaded: mswsock.dll | Jump to behavior |
Source: C:\Users\user\Desktop\lSmb6nDsrC.exe | Code function: 0_2_0040687E FindFirstFileW,FindClose, | 0_2_0040687E |
Source: C:\Users\user\Desktop\lSmb6nDsrC.exe | Code function: 0_2_00402910 FindFirstFileW, | 0_2_00402910 |
Source: C:\Users\user\Desktop\lSmb6nDsrC.exe | Code function: 0_2_00405C2D GetTempPathW,DeleteFileW,lstrcatW,lstrcatW,lstrlenW,FindFirstFileW,FindNextFileW,FindClose, | 0_2_00405C2D |
Source: C:\Users\user\AppData\Local\Microsoft\Windows\INetCache\55116385\Labs.pif | Code function: 19_2_007D4005 FindFirstFileW,DeleteFileW,FindNextFileW,FindClose,FindClose, | 19_2_007D4005 |
Source: C:\Users\user\AppData\Local\Microsoft\Windows\INetCache\55116385\Labs.pif | Code function: 19_2_007D494A GetFileAttributesW,FindFirstFileW,FindClose, | 19_2_007D494A |
Source: C:\Users\user\AppData\Local\Microsoft\Windows\INetCache\55116385\Labs.pif | Code function: 19_2_007DC2FF FindFirstFileW,_wcscmp,_wcscmp,FindNextFileW,FindClose, | 19_2_007DC2FF |
Source: C:\Users\user\AppData\Local\Microsoft\Windows\INetCache\55116385\Labs.pif | Code function: 19_2_007DCD14 FindFirstFileW,FindClose, | 19_2_007DCD14 |
Source: C:\Users\user\AppData\Local\Microsoft\Windows\INetCache\55116385\Labs.pif | Code function: 19_2_007DCD9F FindFirstFileW,FindClose,FileTimeToLocalFileTime,FileTimeToLocalFileTime,FileTimeToLocalFileTime,FileTimeToSystemTime,__swprintf,__swprintf,__swprintf,__swprintf,__swprintf,__swprintf,__swprintf, | 19_2_007DCD9F |
Source: C:\Users\user\AppData\Local\Microsoft\Windows\INetCache\55116385\Labs.pif | Code function: 19_2_007DF5D8 SetCurrentDirectoryW,FindFirstFileW,FindFirstFileW,_wcscmp,_wcscmp,GetFileAttributesW,SetFileAttributesW,FindNextFileW,FindClose,FindFirstFileW,SetCurrentDirectoryW,_wcscmp,_wcscmp,SetCurrentDirectoryW,SetCurrentDirectoryW,FindNextFileW,FindClose,FindClose, | 19_2_007DF5D8 |
Source: C:\Users\user\AppData\Local\Microsoft\Windows\INetCache\55116385\Labs.pif | Code function: 19_2_007DF735 SetCurrentDirectoryW,FindFirstFileW,FindFirstFileW,_wcscmp,_wcscmp,FindNextFileW,FindClose,FindFirstFileW,SetCurrentDirectoryW,_wcscmp,_wcscmp,SetCurrentDirectoryW,SetCurrentDirectoryW,FindNextFileW,FindClose,FindClose, | 19_2_007DF735 |
Source: C:\Users\user\AppData\Local\Microsoft\Windows\INetCache\55116385\Labs.pif | Code function: 19_2_007DFA36 FindFirstFileW,Sleep,_wcscmp,_wcscmp,FindNextFileW,FindClose, | 19_2_007DFA36 |
Source: C:\Users\user\AppData\Local\Microsoft\Windows\INetCache\55116385\Labs.pif | Code function: 19_2_007D3CE2 FindFirstFileW,DeleteFileW,DeleteFileW,MoveFileW,DeleteFileW,FindNextFileW,FindClose,FindClose, | 19_2_007D3CE2 |
Source: C:\Users\user\AppData\Local\Microsoft\Windows\INetCache\55116385\Labs.pif | Code function: 27_2_007D4005 FindFirstFileW,DeleteFileW,FindNextFileW,FindClose,FindClose, | 27_2_007D4005 |
Source: C:\Users\user\AppData\Local\Microsoft\Windows\INetCache\55116385\Labs.pif | Code function: 27_2_007DC2FF FindFirstFileW,_wcscmp,_wcscmp,FindNextFileW,FindClose, | 27_2_007DC2FF |
Source: C:\Users\user\AppData\Local\Microsoft\Windows\INetCache\55116385\Labs.pif | Code function: 27_2_007D494A GetFileAttributesW,FindFirstFileW,FindClose, | 27_2_007D494A |
Source: C:\Users\user\AppData\Local\Microsoft\Windows\INetCache\55116385\Labs.pif | Code function: 27_2_007DCD14 FindFirstFileW,FindClose, | 27_2_007DCD14 |
Source: C:\Users\user\AppData\Local\Microsoft\Windows\INetCache\55116385\Labs.pif | Code function: 27_2_007DCD9F FindFirstFileW,FindClose,FileTimeToLocalFileTime,FileTimeToLocalFileTime,FileTimeToLocalFileTime,FileTimeToSystemTime,__swprintf,__swprintf,__swprintf,__swprintf,__swprintf,__swprintf,__swprintf, | 27_2_007DCD9F |
Source: C:\Users\user\AppData\Local\Microsoft\Windows\INetCache\55116385\Labs.pif | Code function: 27_2_007DF5D8 SetCurrentDirectoryW,FindFirstFileW,FindFirstFileW,_wcscmp,_wcscmp,GetFileAttributesW,SetFileAttributesW,FindNextFileW,FindClose,FindFirstFileW,SetCurrentDirectoryW,_wcscmp,_wcscmp,SetCurrentDirectoryW,SetCurrentDirectoryW,FindNextFileW,FindClose,FindClose, | 27_2_007DF5D8 |
Source: C:\Users\user\AppData\Local\Microsoft\Windows\INetCache\55116385\Labs.pif | Code function: 27_2_007DF735 SetCurrentDirectoryW,FindFirstFileW,FindFirstFileW,_wcscmp,_wcscmp,FindNextFileW,FindClose,FindFirstFileW,SetCurrentDirectoryW,_wcscmp,_wcscmp,SetCurrentDirectoryW,SetCurrentDirectoryW,FindNextFileW,FindClose,FindClose, | 27_2_007DF735 |
Source: C:\Users\user\AppData\Local\Microsoft\Windows\INetCache\55116385\Labs.pif | Code function: 27_2_007DFA36 FindFirstFileW,Sleep,_wcscmp,_wcscmp,FindNextFileW,FindClose, | 27_2_007DFA36 |
Source: C:\Users\user\AppData\Local\Microsoft\Windows\INetCache\55116385\Labs.pif | Code function: 27_2_007D3CE2 FindFirstFileW,DeleteFileW,DeleteFileW,MoveFileW,DeleteFileW,FindNextFileW,FindClose,FindClose, | 27_2_007D3CE2 |
Source: explorer.exe, 0000001C.00000000.2297108695.0000000000C74000.00000004.00000020.00020000.00000000.sdmp | Binary or memory string: SCSI\DISK&VEN_VMWARE&PROD_VIRTUAL_DISK\4&1656F219&0&000000I |
Source: explorer.exe, 0000001C.00000000.2297947837.0000000003249000.00000004.00000001.00020000.00000000.sdmp | Binary or memory string: VMware, Inc. |
Source: explorer.exe, 0000001C.00000002.2484651579.0000000008DFE000.00000004.00000001.00020000.00000000.sdmp | Binary or memory string: BBSCSI\CdRom&Ven_NECVMWar&Prod_VMware_SATA_CD00\4&224f42ef&0&000000 |
Source: Labs.pif, 00000013.00000002.2258368297.0000000005070000.00000004.00000800.00020000.00000000.sdmp, explorer.exe, 0000001C.00000000.2307149631.0000000008F4D000.00000004.00000001.00020000.00000000.sdmp, explorer.exe, 0000001C.00000002.2484651579.0000000008F4D000.00000004.00000001.00020000.00000000.sdmp | Binary or memory string: Hyper-V RAW |
Source: explorer.exe, 0000001C.00000000.2297947837.0000000003249000.00000004.00000001.00020000.00000000.sdmp | Binary or memory string: VMware, Inc.NoneVMware-42 27 88 19 56 cc 59 1a-97 79 fb 8c bf a1 e2 9dVMware20,1 |
Source: explorer.exe, 0000001C.00000000.2307149631.0000000009013000.00000004.00000001.00020000.00000000.sdmp | Binary or memory string: SCSI\Disk&Ven_VMware&Prod_Virtual_disk\4&1656f219&0&000000 |
Source: explorer.exe, 0000001C.00000000.2297947837.0000000003249000.00000004.00000001.00020000.00000000.sdmp | Binary or memory string: VMware, Inc.VMW201.00V.20829224.B64.221121184211/21/2022 |
Source: explorer.exe, 0000001C.00000000.2297947837.0000000003249000.00000004.00000001.00020000.00000000.sdmp | Binary or memory string: VMware SVGA II |
Source: explorer.exe, 0000001C.00000000.2299433125.0000000007306000.00000004.00000001.00020000.00000000.sdmp | Binary or memory string: War&Prod_VMware_xU1 |
Source: Labs.pif, 00000013.00000002.2257650033.00000000015B1000.00000004.00000020.00020000.00000000.sdmp | Binary or memory string: Hyper-V RAWX> |
Source: explorer.exe, 0000001C.00000002.2484651579.0000000008DFE000.00000004.00000001.00020000.00000000.sdmp | Binary or memory string: \\?\scsi#cdrom&ven_necvmwar&prod_vmware_sata_cd00#4&224f42ef&0&000000#{53f56308-b6bf-11d0-94f2-00a0c91efb8b}e |
Source: explorer.exe, 0000001C.00000002.2484651579.0000000009052000.00000004.00000001.00020000.00000000.sdmp | Binary or memory string: SCSI\CDROM&VEN_NECVMWAR&PROD_VMWARE_SATA_CD00\4&224F42EF&0&000000}io |
Source: explorer.exe, 0000001C.00000002.2484651579.0000000008F4D000.00000004.00000001.00020000.00000000.sdmp | Binary or memory string: SCSI\Disk&Ven_VMware&Prod_Virtual_disk\4&1656f219&0&000000I}~" |
Source: explorer.exe, 0000001C.00000002.2484651579.0000000008F4D000.00000004.00000001.00020000.00000000.sdmp | Binary or memory string: VMware SATA CD00 |
Source: explorer.exe, 0000001C.00000000.2307149631.0000000008DFE000.00000004.00000001.00020000.00000000.sdmp, explorer.exe, 0000001C.00000002.2484651579.0000000008DFE000.00000004.00000001.00020000.00000000.sdmp | Binary or memory string: Hyper-V RAWystem32\DriverStore\en-US\machine.inf_loc5 |
Source: explorer.exe, 0000001C.00000000.2297947837.0000000003249000.00000004.00000001.00020000.00000000.sdmp | Binary or memory string: VMware20,1 |
Source: explorer.exe, 0000001C.00000000.2297947837.0000000003249000.00000004.00000001.00020000.00000000.sdmp | Binary or memory string: VMware Virtual RAM00000001VMW-4096MBRAM slot #0RAM slot #0 |
Source: explorer.exe, 0000001C.00000002.2484651579.0000000008DFE000.00000004.00000001.00020000.00000000.sdmp | Binary or memory string: VMWare |
Source: explorer.exe, 0000001C.00000002.2484651579.0000000009052000.00000004.00000001.00020000.00000000.sdmp | Binary or memory string: SCSI\CdRom&Ven_NECVMWar&Prod_VMware_SATA_CD00\4&224f42ef&0&000000' |
Source: explorer.exe, 0000001C.00000000.2299433125.0000000007306000.00000004.00000001.00020000.00000000.sdmp | Binary or memory string: War&Prod_VMware_SATA_CD00#4&224f42ef&0&000000#{53f5630d-b6bf-11d0-94f2-00a0c91efb8b}\ |
Source: explorer.exe, 0000001C.00000002.2484651579.0000000008F27000.00000004.00000001.00020000.00000000.sdmp, explorer.exe, 0000001C.00000000.2307149631.0000000008F27000.00000004.00000001.00020000.00000000.sdmp | Binary or memory string: Hyper-V RAWT` |
Source: explorer.exe, 0000001C.00000000.2297947837.0000000003249000.00000004.00000001.00020000.00000000.sdmp | Binary or memory string: VMware SVGA IIES1371 |
Source: explorer.exe, 0000001C.00000000.2297947837.0000000003249000.00000004.00000001.00020000.00000000.sdmp | Binary or memory string: VMware Virtual RAM |
Source: Labs.pif, 00000013.00000002.2258368297.0000000005070000.00000004.00000800.00020000.00000000.sdmp | Binary or memory string: Hyper-V RAWindows\System32\mswsock.dll |
Source: explorer.exe, 0000001C.00000000.2297108695.0000000000C74000.00000004.00000020.00020000.00000000.sdmp | Binary or memory string: SCSI\DISK&VEN_VMWARE&PROD_VIRTUAL_DISK\4&1656F219&0&000000 |
Source: explorer.exe, 0000001C.00000000.2297947837.0000000003249000.00000004.00000001.00020000.00000000.sdmp | Binary or memory string: VMware-42 27 88 19 56 cc 59 1a-97 79 fb 8c bf a1 e2 9d |
Source: explorer.exe, 0000001C.00000002.2484651579.0000000008DFE000.00000004.00000001.00020000.00000000.sdmp | Binary or memory string: \\?\scsi#cdrom&ven_necvmwar&prod_vmware_sata_cd00#4&224f42ef&0&000000#{53f56308-b6bf-11d0-94f2-00a0c91efb8b} |
Source: explorer.exe, 0000001C.00000000.2297108695.0000000000C74000.00000004.00000020.00020000.00000000.sdmp | Binary or memory string: \\?\SCSI#CdRom&Ven_NECVMWar&Prod_VMware_SATA_CD00#4&224f42ef&0&000000#{53f5630d-b6bf-11d0-94f2-00a0c91efb8b} |