Source: https://associationokeo.shop//i | Avira URL Cloud: Label: malware |
Source: https://turkeyunlikelyofw.shop/api | Avira URL Cloud: Label: malware |
Source: https://detectordiscusser.shop/ | Avira URL Cloud: Label: malware |
Source: associationokeo.shop | Avira URL Cloud: Label: malware |
Source: colorfulequalugliess.shop | Avira URL Cloud: Label: phishing |
Source: https://associationokeo.shop/api | Avira URL Cloud: Label: malware |
Source: https://associationokeo.shop// | Avira URL Cloud: Label: malware |
Source: https://associationokeo.shop/ | Avira URL Cloud: Label: malware |
Source: detectordiscusser.shop | Avira URL Cloud: Label: malware |
Source: relevantvoicelesskw.shop | Avira URL Cloud: Label: phishing |
Source: turkeyunlikelyofw.shop | Avira URL Cloud: Label: malware |
Source: https://turkeyunlikelyofw.shop/ | Avira URL Cloud: Label: malware |
Source: 00000003.00000002.1651401322.0000000000400000.00000040.00000400.00020000.00000000.sdmp | String decryptor: associationokeo.shop |
Source: 00000003.00000002.1651401322.0000000000400000.00000040.00000400.00020000.00000000.sdmp | String decryptor: turkeyunlikelyofw.shop |
Source: 00000003.00000002.1651401322.0000000000400000.00000040.00000400.00020000.00000000.sdmp | String decryptor: pooreveningfuseor.pw |
Source: 00000003.00000002.1651401322.0000000000400000.00000040.00000400.00020000.00000000.sdmp | String decryptor: edurestunningcrackyow.fun |
Source: 00000003.00000002.1651401322.0000000000400000.00000040.00000400.00020000.00000000.sdmp | String decryptor: detectordiscusser.shop |
Source: 00000003.00000002.1651401322.0000000000400000.00000040.00000400.00020000.00000000.sdmp | String decryptor: relevantvoicelesskw.shop |
Source: 00000003.00000002.1651401322.0000000000400000.00000040.00000400.00020000.00000000.sdmp | String decryptor: colorfulequalugliess.shop |
Source: 00000003.00000002.1651401322.0000000000400000.00000040.00000400.00020000.00000000.sdmp | String decryptor: wisemassiveharmonious.shop |
Source: 00000003.00000002.1651401322.0000000000400000.00000040.00000400.00020000.00000000.sdmp | String decryptor: sailsystemeyeusjw.shop |
Source: 00000003.00000002.1651401322.0000000000400000.00000040.00000400.00020000.00000000.sdmp | String decryptor: lid=%s&j=%s&ver=4.0 |
Source: 00000003.00000002.1651401322.0000000000400000.00000040.00000400.00020000.00000000.sdmp | String decryptor: TeslaBrowser/5.5 |
Source: 00000003.00000002.1651401322.0000000000400000.00000040.00000400.00020000.00000000.sdmp | String decryptor: - Screen Resoluton: |
Source: 00000003.00000002.1651401322.0000000000400000.00000040.00000400.00020000.00000000.sdmp | String decryptor: - Physical Installed Memory: |
Source: 00000003.00000002.1651401322.0000000000400000.00000040.00000400.00020000.00000000.sdmp | String decryptor: Workgroup: - |
Source: 00000003.00000002.1651401322.0000000000400000.00000040.00000400.00020000.00000000.sdmp | String decryptor: 1AsNN2--babah2 |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegAsm.exe | Code function: 4x nop then mov ecx, dword ptr [esi+08h] | 3_2_00432156 |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegAsm.exe | Code function: 4x nop then movzx eax, byte ptr [esi+ecx] | 3_2_0040D1C0 |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegAsm.exe | Code function: 4x nop then mov eax, dword ptr [esi+00000080h] | 3_2_00423216 |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegAsm.exe | Code function: 4x nop then mov ecx, dword ptr [esi+00000080h] | 3_2_00423216 |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegAsm.exe | Code function: 4x nop then mov eax, dword ptr [esi+00000080h] | 3_2_00423216 |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegAsm.exe | Code function: 4x nop then test esi, esi | 3_2_004352C9 |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegAsm.exe | Code function: 4x nop then mov eax, dword ptr [esi+00000080h] | 3_2_004212E2 |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegAsm.exe | Code function: 4x nop then jmp ecx | 3_2_00433458 |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegAsm.exe | Code function: 4x nop then cmp dword ptr [eax-08h], 5C3924FCh | 3_2_0041541A |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegAsm.exe | Code function: 4x nop then jmp eax | 3_2_00434489 |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegAsm.exe | Code function: 4x nop then mov ecx, dword ptr [esp+10h] | 3_2_004095E0 |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegAsm.exe | Code function: 4x nop then mov ecx, dword ptr [esi+04h] | 3_2_004105BD |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegAsm.exe | Code function: 4x nop then mov eax, dword ptr [esp+28h] | 3_2_0041561D |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegAsm.exe | Code function: 4x nop then movzx ebx, byte ptr [edx] | 3_2_0042D620 |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegAsm.exe | Code function: 4x nop then mov eax, dword ptr [esi+00000080h] | 3_2_00423216 |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegAsm.exe | Code function: 4x nop then mov ecx, dword ptr [esi+00000080h] | 3_2_00423216 |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegAsm.exe | Code function: 4x nop then mov eax, dword ptr [esi+00000080h] | 3_2_00423216 |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegAsm.exe | Code function: 4x nop then lea esi, dword ptr [edx+ecx] | 3_2_0041D860 |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegAsm.exe | Code function: 4x nop then mov ecx, dword ptr [esp+000000A8h] | 3_2_00414810 |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegAsm.exe | Code function: 4x nop then mov eax, dword ptr [esi+04h] | 3_2_0041390E |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegAsm.exe | Code function: 4x nop then jmp eax | 3_2_004119E7 |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegAsm.exe | Code function: 4x nop then jmp ecx | 3_2_0040FA72 |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegAsm.exe | Code function: 4x nop then jmp ecx | 3_2_0040FA7F |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegAsm.exe | Code function: 4x nop then mov eax, dword ptr [0043DC58h] | 3_2_0041CB43 |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegAsm.exe | Code function: 4x nop then add ecx, dword ptr [esp+eax*4+30h] | 3_2_00407B20 |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegAsm.exe | Code function: 4x nop then mov ecx, dword ptr [esp+10h] | 3_2_0041CB80 |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegAsm.exe | Code function: 4x nop then mov edi, dword ptr [esi+0Ch] | 3_2_0041FB8E |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegAsm.exe | Code function: 4x nop then mov eax, dword ptr [esi+08h] | 3_2_00432C52 |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegAsm.exe | Code function: 4x nop then mov ecx, dword ptr [esi+00000080h] | 3_2_00420D8E |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegAsm.exe | Code function: 4x nop then mov ecx, dword ptr [esi+04h] | 3_2_00410E43 |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegAsm.exe | Code function: 4x nop then mov eax, edi | 3_2_00434FB2 |
Source: Malware configuration extractor | URLs: associationokeo.shop |
Source: Malware configuration extractor | URLs: turkeyunlikelyofw.shop |
Source: Malware configuration extractor | URLs: pooreveningfuseor.pw |
Source: Malware configuration extractor | URLs: edurestunningcrackyow.fun |
Source: Malware configuration extractor | URLs: detectordiscusser.shop |
Source: Malware configuration extractor | URLs: relevantvoicelesskw.shop |
Source: Malware configuration extractor | URLs: colorfulequalugliess.shop |
Source: Malware configuration extractor | URLs: wisemassiveharmonious.shop |
Source: Malware configuration extractor | URLs: sailsystemeyeusjw.shop |
Source: RegAsm.exe, 00000003.00000002.1651767284.0000000001522000.00000004.00000020.00020000.00000000.sdmp, RegAsm.exe, 00000003.00000002.1651633572.00000000014DA000.00000004.00000020.00020000.00000000.sdmp | String found in binary or memory: https://associationokeo.shop/ |
Source: RegAsm.exe, 00000003.00000002.1651633572.00000000014DA000.00000004.00000020.00020000.00000000.sdmp | String found in binary or memory: https://associationokeo.shop// |
Source: RegAsm.exe, 00000003.00000002.1651633572.00000000014DA000.00000004.00000020.00020000.00000000.sdmp | String found in binary or memory: https://associationokeo.shop//i |
Source: RegAsm.exe, 00000003.00000002.1651681626.00000000014F8000.00000004.00000020.00020000.00000000.sdmp | String found in binary or memory: https://associationokeo.shop/api |
Source: RegAsm.exe, 00000003.00000002.1651633572.00000000014DA000.00000004.00000020.00020000.00000000.sdmp | String found in binary or memory: https://detectordiscusser.shop/ |
Source: RegAsm.exe, 00000003.00000002.1651633572.00000000014DA000.00000004.00000020.00020000.00000000.sdmp | String found in binary or memory: https://pooreveningfuseor.pw/ |
Source: RegAsm.exe, 00000003.00000002.1651633572.00000000014DA000.00000004.00000020.00020000.00000000.sdmp | String found in binary or memory: https://pooreveningfuseor.pw// |
Source: RegAsm.exe, 00000003.00000002.1651633572.00000000014DA000.00000004.00000020.00020000.00000000.sdmp | String found in binary or memory: https://sailsystemeyeusjw.shop/ |
Source: RegAsm.exe, 00000003.00000002.1651633572.00000000014DA000.00000004.00000020.00020000.00000000.sdmp | String found in binary or memory: https://sailsystemeyeusjw.shop/. |
Source: RegAsm.exe, 00000003.00000002.1651633572.00000000014DA000.00000004.00000020.00020000.00000000.sdmp | String found in binary or memory: https://turkeyunlikelyofw.shop/ |
Source: RegAsm.exe, 00000003.00000002.1651681626.00000000014F8000.00000004.00000020.00020000.00000000.sdmp | String found in binary or memory: https://turkeyunlikelyofw.shop/api |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegAsm.exe | Code function: 3_2_00414280 NtAllocateVirtualMemory,NtFreeVirtualMemory, | 3_2_00414280 |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegAsm.exe | Code function: 3_2_00435440 NtAllocateVirtualMemory,NtFreeVirtualMemory, | 3_2_00435440 |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegAsm.exe | Code function: 3_2_004324B2 NtAllocateVirtualMemory,NtFreeVirtualMemory,NtAllocateVirtualMemory,NtFreeVirtualMemory, | 3_2_004324B2 |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegAsm.exe | Code function: 3_2_004327F1 NtMapViewOfSection, | 3_2_004327F1 |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegAsm.exe | Code function: 3_2_004327AF NtOpenSection, | 3_2_004327AF |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegAsm.exe | Code function: 3_2_0043286A NtClose, | 3_2_0043286A |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegAsm.exe | Code function: 3_2_00432987 NtAllocateVirtualMemory,NtFreeVirtualMemory,NtAllocateVirtualMemory,NtFreeVirtualMemory, | 3_2_00432987 |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegAsm.exe | Code function: 3_2_00436060 NtAllocateVirtualMemory,NtFreeVirtualMemory,NtAllocateVirtualMemory,NtFreeVirtualMemory, | 3_2_00436060 |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegAsm.exe | Code function: 3_2_004220C1 NtAllocateVirtualMemory,NtFreeVirtualMemory, | 3_2_004220C1 |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegAsm.exe | Code function: 3_2_00419080 NtAllocateVirtualMemory,NtFreeVirtualMemory, | 3_2_00419080 |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegAsm.exe | Code function: 3_2_0042F1E0 NtAllocateVirtualMemory,NtFreeVirtualMemory, | 3_2_0042F1E0 |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegAsm.exe | Code function: 3_2_00412277 NtAllocateVirtualMemory,NtFreeVirtualMemory, | 3_2_00412277 |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegAsm.exe | Code function: 3_2_00431220 NtAllocateVirtualMemory,NtFreeVirtualMemory,NtAllocateVirtualMemory,NtFreeVirtualMemory, | 3_2_00431220 |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegAsm.exe | Code function: 3_2_00417305 NtAllocateVirtualMemory,NtFreeVirtualMemory, | 3_2_00417305 |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegAsm.exe | Code function: 3_2_00436400 NtAllocateVirtualMemory,NtFreeVirtualMemory,NtAllocateVirtualMemory,NtFreeVirtualMemory, | 3_2_00436400 |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegAsm.exe | Code function: 3_2_0041541A NtAllocateVirtualMemory,NtFreeVirtualMemory, | 3_2_0041541A |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegAsm.exe | Code function: 3_2_00416492 NtAllocateVirtualMemory,NtFreeVirtualMemory, | 3_2_00416492 |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegAsm.exe | Code function: 3_2_004314A0 NtAllocateVirtualMemory,NtFreeVirtualMemory, | 3_2_004314A0 |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegAsm.exe | Code function: 3_2_0041C5F0 NtAllocateVirtualMemory,NtFreeVirtualMemory, | 3_2_0041C5F0 |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegAsm.exe | Code function: 3_2_00435640 NtAllocateVirtualMemory,NtFreeVirtualMemory, | 3_2_00435640 |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegAsm.exe | Code function: 3_2_00431600 NtAllocateVirtualMemory,NtFreeVirtualMemory, | 3_2_00431600 |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegAsm.exe | Code function: 3_2_0041960A NtAllocateVirtualMemory,NtFreeVirtualMemory,NtAllocateVirtualMemory,NtFreeVirtualMemory, | 3_2_0041960A |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegAsm.exe | Code function: 3_2_004156F7 NtAllocateVirtualMemory,NtFreeVirtualMemory, | 3_2_004156F7 |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegAsm.exe | Code function: 3_2_004146B7 NtAllocateVirtualMemory,NtFreeVirtualMemory, | 3_2_004146B7 |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegAsm.exe | Code function: 3_2_0041A762 NtAllocateVirtualMemory,NtFreeVirtualMemory, | 3_2_0041A762 |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegAsm.exe | Code function: 3_2_0041C765 NtAllocateVirtualMemory,NtFreeVirtualMemory, | 3_2_0041C765 |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegAsm.exe | Code function: 3_2_00412700 NtAllocateVirtualMemory,NtFreeVirtualMemory, | 3_2_00412700 |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegAsm.exe | Code function: 3_2_00431710 NtAllocateVirtualMemory,NtFreeVirtualMemory, | 3_2_00431710 |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegAsm.exe | Code function: 3_2_004367D0 NtAllocateVirtualMemory,NtFreeVirtualMemory,NtAllocateVirtualMemory,NtFreeVirtualMemory, | 3_2_004367D0 |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegAsm.exe | Code function: 3_2_00416790 NtAllocateVirtualMemory,NtFreeVirtualMemory, | 3_2_00416790 |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegAsm.exe | Code function: 3_2_00431840 NtAllocateVirtualMemory,NtFreeVirtualMemory, | 3_2_00431840 |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegAsm.exe | Code function: 3_2_0041D860 NtAllocateVirtualMemory,NtFreeVirtualMemory,NtAllocateVirtualMemory,NtFreeVirtualMemory, | 3_2_0041D860 |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegAsm.exe | Code function: 3_2_00435810 NtAllocateVirtualMemory,NtFreeVirtualMemory, | 3_2_00435810 |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegAsm.exe | Code function: 3_2_0041A880 NtAllocateVirtualMemory,NtFreeVirtualMemory, | 3_2_0041A880 |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegAsm.exe | Code function: 3_2_00435940 NtAllocateVirtualMemory,NtFreeVirtualMemory, | 3_2_00435940 |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegAsm.exe | Code function: 3_2_00431950 NtAllocateVirtualMemory,NtAllocateVirtualMemory,NtFreeVirtualMemory,NtFreeVirtualMemory,NtAllocateVirtualMemory,NtFreeVirtualMemory, | 3_2_00431950 |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegAsm.exe | Code function: 3_2_00435AB0 NtAllocateVirtualMemory,NtFreeVirtualMemory, | 3_2_00435AB0 |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegAsm.exe | Code function: 3_2_00435BD0 NtAllocateVirtualMemory,NtFreeVirtualMemory, | 3_2_00435BD0 |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegAsm.exe | Code function: 3_2_00419C41 NtAllocateVirtualMemory,NtFreeVirtualMemory, | 3_2_00419C41 |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegAsm.exe | Code function: 3_2_00432C52 NtFreeVirtualMemory, | 3_2_00432C52 |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegAsm.exe | Code function: 3_2_00417C59 NtAllocateVirtualMemory,NtFreeVirtualMemory, | 3_2_00417C59 |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegAsm.exe | Code function: 3_2_00435D40 NtAllocateVirtualMemory,NtFreeVirtualMemory,NtAllocateVirtualMemory,NtFreeVirtualMemory, | 3_2_00435D40 |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegAsm.exe | Code function: 3_2_00414D10 NtAllocateVirtualMemory,NtFreeVirtualMemory, | 3_2_00414D10 |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegAsm.exe | Code function: 3_2_0041EDB2 NtAllocateVirtualMemory,NtFreeVirtualMemory, | 3_2_0041EDB2 |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegAsm.exe | Code function: 3_2_00418E50 NtAllocateVirtualMemory,NtFreeVirtualMemory, | 3_2_00418E50 |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegAsm.exe | Code function: 3_2_0041CF46 NtAllocateVirtualMemory,NtFreeVirtualMemory,NtAllocateVirtualMemory,NtFreeVirtualMemory, | 3_2_0041CF46 |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegAsm.exe | Code function: 3_2_00420F04 NtAllocateVirtualMemory,NtFreeVirtualMemory,NtAllocateVirtualMemory,NtFreeVirtualMemory, | 3_2_00420F04 |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegAsm.exe | Code function: 3_2_00430F80 NtAllocateVirtualMemory,NtFreeVirtualMemory,NtAllocateVirtualMemory,NtFreeVirtualMemory, | 3_2_00430F80 |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegAsm.exe | Code function: 3_2_00436060 | 3_2_00436060 |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegAsm.exe | Code function: 3_2_00401000 | 3_2_00401000 |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegAsm.exe | Code function: 3_2_00403240 | 3_2_00403240 |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegAsm.exe | Code function: 3_2_00405274 | 3_2_00405274 |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegAsm.exe | Code function: 3_2_00423216 | 3_2_00423216 |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegAsm.exe | Code function: 3_2_004212E2 | 3_2_004212E2 |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegAsm.exe | Code function: 3_2_0041F3FD | 3_2_0041F3FD |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegAsm.exe | Code function: 3_2_00422382 | 3_2_00422382 |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegAsm.exe | Code function: 3_2_00436400 | 3_2_00436400 |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegAsm.exe | Code function: 3_2_00404640 | 3_2_00404640 |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegAsm.exe | Code function: 3_2_0041960A | 3_2_0041960A |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegAsm.exe | Code function: 3_2_00423216 | 3_2_00423216 |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegAsm.exe | Code function: 3_2_00401700 | 3_2_00401700 |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegAsm.exe | Code function: 3_2_0041D860 | 3_2_0041D860 |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegAsm.exe | Code function: 3_2_00413A27 | 3_2_00413A27 |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegAsm.exe | Code function: 3_2_00417A8C | 3_2_00417A8C |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegAsm.exe | Code function: 3_2_00407B20 | 3_2_00407B20 |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegAsm.exe | Code function: 3_2_00419C41 | 3_2_00419C41 |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegAsm.exe | Code function: 3_2_00403C60 | 3_2_00403C60 |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegAsm.exe | Code function: 3_2_00426D8E | 3_2_00426D8E |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegAsm.exe | Code function: 3_2_0040FDB0 | 3_2_0040FDB0 |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegAsm.exe | Code function: 3_2_00402E70 | 3_2_00402E70 |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegAsm.exe | Code function: 3_2_0041CF46 | 3_2_0041CF46 |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegAsm.exe | Code function: 3_2_00412F77 | 3_2_00412F77 |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegAsm.exe | Code function: 3_2_00420F04 | 3_2_00420F04 |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegAsm.exe | Code function: 3_2_00405F30 | 3_2_00405F30 |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegAsm.exe | Code function: 3_2_0042EF80 | 3_2_0042EF80 |
Source: C:\Users\user\Desktop\LisectAVT_2403002A_96.exe | Section loaded: mscoree.dll | Jump to behavior |
Source: C:\Users\user\Desktop\LisectAVT_2403002A_96.exe | Section loaded: apphelp.dll | Jump to behavior |
Source: C:\Users\user\Desktop\LisectAVT_2403002A_96.exe | Section loaded: kernel.appcore.dll | Jump to behavior |
Source: C:\Users\user\Desktop\LisectAVT_2403002A_96.exe | Section loaded: version.dll | Jump to behavior |
Source: C:\Users\user\Desktop\LisectAVT_2403002A_96.exe | Section loaded: vcruntime140_clr0400.dll | Jump to behavior |
Source: C:\Users\user\Desktop\LisectAVT_2403002A_96.exe | Section loaded: ucrtbase_clr0400.dll | Jump to behavior |
Source: C:\Users\user\Desktop\LisectAVT_2403002A_96.exe | Section loaded: windows.storage.dll | Jump to behavior |
Source: C:\Users\user\Desktop\LisectAVT_2403002A_96.exe | Section loaded: wldp.dll | Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegAsm.exe | Section loaded: apphelp.dll | Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegAsm.exe | Section loaded: aclayers.dll | Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegAsm.exe | Section loaded: mpr.dll | Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegAsm.exe | Section loaded: sfc.dll | Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegAsm.exe | Section loaded: sfc_os.dll | Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegAsm.exe | Section loaded: winhttp.dll | Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegAsm.exe | Section loaded: ondemandconnroutehelper.dll | Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegAsm.exe | Section loaded: webio.dll | Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegAsm.exe | Section loaded: mswsock.dll | Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegAsm.exe | Section loaded: iphlpapi.dll | Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegAsm.exe | Section loaded: winnsi.dll | Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegAsm.exe | Section loaded: sspicli.dll | Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegAsm.exe | Section loaded: dnsapi.dll | Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegAsm.exe | Section loaded: rasadhlp.dll | Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegAsm.exe | Section loaded: ondemandconnroutehelper.dll | Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegAsm.exe | Section loaded: ondemandconnroutehelper.dll | Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegAsm.exe | Section loaded: ondemandconnroutehelper.dll | Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegAsm.exe | Section loaded: ondemandconnroutehelper.dll | Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegAsm.exe | Section loaded: ondemandconnroutehelper.dll | Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegAsm.exe | Section loaded: msasn1.dll | Jump to behavior |
Source: C:\Users\user\Desktop\LisectAVT_2403002A_96.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\LisectAVT_2403002A_96.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\LisectAVT_2403002A_96.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\LisectAVT_2403002A_96.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\LisectAVT_2403002A_96.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\LisectAVT_2403002A_96.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\LisectAVT_2403002A_96.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\LisectAVT_2403002A_96.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\LisectAVT_2403002A_96.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\LisectAVT_2403002A_96.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\LisectAVT_2403002A_96.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\LisectAVT_2403002A_96.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\LisectAVT_2403002A_96.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\LisectAVT_2403002A_96.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\LisectAVT_2403002A_96.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: LisectAVT_2403002A_96.exe, 00000000.00000002.1651239125.0000000003AD5000.00000004.00000800.00020000.00000000.sdmp | String found in binary or memory: associationokeo.shop |
Source: LisectAVT_2403002A_96.exe, 00000000.00000002.1651239125.0000000003AD5000.00000004.00000800.00020000.00000000.sdmp | String found in binary or memory: turkeyunlikelyofw.shop |
Source: LisectAVT_2403002A_96.exe, 00000000.00000002.1651239125.0000000003AD5000.00000004.00000800.00020000.00000000.sdmp | String found in binary or memory: pooreveningfuseor.pw |
Source: LisectAVT_2403002A_96.exe, 00000000.00000002.1651239125.0000000003AD5000.00000004.00000800.00020000.00000000.sdmp | String found in binary or memory: edurestunningcrackyow.fun |
Source: LisectAVT_2403002A_96.exe, 00000000.00000002.1651239125.0000000003AD5000.00000004.00000800.00020000.00000000.sdmp | String found in binary or memory: detectordiscusser.shop |
Source: LisectAVT_2403002A_96.exe, 00000000.00000002.1651239125.0000000003AD5000.00000004.00000800.00020000.00000000.sdmp | String found in binary or memory: relevantvoicelesskw.shop |
Source: LisectAVT_2403002A_96.exe, 00000000.00000002.1651239125.0000000003AD5000.00000004.00000800.00020000.00000000.sdmp | String found in binary or memory: colorfulequalugliess.shop |
Source: LisectAVT_2403002A_96.exe, 00000000.00000002.1651239125.0000000003AD5000.00000004.00000800.00020000.00000000.sdmp | String found in binary or memory: wisemassiveharmonious.shop |
Source: LisectAVT_2403002A_96.exe, 00000000.00000002.1651239125.0000000003AD5000.00000004.00000800.00020000.00000000.sdmp | String found in binary or memory: sailsystemeyeusjw.shop |