Source: C:\Users\user\Desktop\f3ba41ba0b508b0965153c1688d6df6de6b3fdf59b015.exe |
Code function: 0_2_004062D5 FindFirstFileW,FindClose, |
0_2_004062D5 |
Source: C:\Users\user\Desktop\f3ba41ba0b508b0965153c1688d6df6de6b3fdf59b015.exe |
Code function: 0_2_00402E18 FindFirstFileW, |
0_2_00402E18 |
Source: C:\Users\user\Desktop\f3ba41ba0b508b0965153c1688d6df6de6b3fdf59b015.exe |
Code function: 0_2_00406C9B DeleteFileW,lstrcatW,lstrcatW,lstrcatW,lstrlenW,FindFirstFileW,DeleteFileW,FindNextFileW,FindClose,RemoveDirectoryW, |
0_2_00406C9B |
Source: C:\Users\user\AppData\Local\Temp\723582\Flash.pif |
Code function: 11_2_00A34005 FindFirstFileW,DeleteFileW,FindNextFileW,FindClose,FindClose, |
11_2_00A34005 |
Source: C:\Users\user\AppData\Local\Temp\723582\Flash.pif |
Code function: 11_2_00A3494A GetFileAttributesW,FindFirstFileW,FindClose, |
11_2_00A3494A |
Source: C:\Users\user\AppData\Local\Temp\723582\Flash.pif |
Code function: 11_2_00A33CE2 FindFirstFileW,DeleteFileW,DeleteFileW,MoveFileW,DeleteFileW,FindNextFileW,FindClose,FindClose, |
11_2_00A33CE2 |
Source: C:\Users\user\AppData\Local\Temp\723582\Flash.pif |
Code function: 11_2_00A3C2FF FindFirstFileW,_wcscmp,_wcscmp,FindNextFileW,FindClose, |
11_2_00A3C2FF |
Source: C:\Users\user\AppData\Local\Temp\723582\Flash.pif |
Code function: 11_2_00A3CD9F FindFirstFileW,FindClose,FileTimeToLocalFileTime,FileTimeToLocalFileTime,FileTimeToLocalFileTime,FileTimeToSystemTime,__swprintf,__swprintf,__swprintf,__swprintf,__swprintf,__swprintf,__swprintf, |
11_2_00A3CD9F |
Source: C:\Users\user\AppData\Local\Temp\723582\Flash.pif |
Code function: 11_2_00A3CD14 FindFirstFileW,FindClose, |
11_2_00A3CD14 |
Source: C:\Users\user\AppData\Local\Temp\723582\Flash.pif |
Code function: 11_2_00A3F5D8 SetCurrentDirectoryW,FindFirstFileW,FindFirstFileW,_wcscmp,_wcscmp,GetFileAttributesW,SetFileAttributesW,FindNextFileW,FindClose,FindFirstFileW,SetCurrentDirectoryW,_wcscmp,_wcscmp,SetCurrentDirectoryW,SetCurrentDirectoryW,FindNextFileW,FindClose,FindClose, |
11_2_00A3F5D8 |
Source: C:\Users\user\AppData\Local\Temp\723582\Flash.pif |
Code function: 11_2_00A3F735 SetCurrentDirectoryW,FindFirstFileW,FindFirstFileW,_wcscmp,_wcscmp,FindNextFileW,FindClose,FindFirstFileW,SetCurrentDirectoryW,_wcscmp,_wcscmp,SetCurrentDirectoryW,SetCurrentDirectoryW,FindNextFileW,FindClose,FindClose, |
11_2_00A3F735 |
Source: C:\Users\user\AppData\Local\Temp\723582\Flash.pif |
Code function: 11_2_00A3FA36 FindFirstFileW,Sleep,_wcscmp,_wcscmp,FindNextFileW,FindClose, |
11_2_00A3FA36 |
Source: C:\Users\user\AppData\Local\EduTech Dynamics\ApolloSphere.pif |
Code function: 16_2_001E4005 FindFirstFileW,DeleteFileW,FindNextFileW,FindClose,FindClose, |
16_2_001E4005 |
Source: C:\Users\user\AppData\Local\EduTech Dynamics\ApolloSphere.pif |
Code function: 16_2_001E494A GetFileAttributesW,FindFirstFileW,FindClose, |
16_2_001E494A |
Source: C:\Users\user\AppData\Local\EduTech Dynamics\ApolloSphere.pif |
Code function: 16_2_001EC2FF FindFirstFileW,_wcscmp,_wcscmp,FindNextFileW,FindClose, |
16_2_001EC2FF |
Source: C:\Users\user\AppData\Local\EduTech Dynamics\ApolloSphere.pif |
Code function: 16_2_001ECD14 FindFirstFileW,FindClose, |
16_2_001ECD14 |
Source: C:\Users\user\AppData\Local\EduTech Dynamics\ApolloSphere.pif |
Code function: 16_2_001ECD9F FindFirstFileW,FindClose,FileTimeToLocalFileTime,FileTimeToLocalFileTime,FileTimeToLocalFileTime,FileTimeToSystemTime,__swprintf,__swprintf,__swprintf,__swprintf,__swprintf,__swprintf,__swprintf, |
16_2_001ECD9F |
Source: C:\Users\user\AppData\Local\EduTech Dynamics\ApolloSphere.pif |
Code function: 16_2_001EF5D8 SetCurrentDirectoryW,FindFirstFileW,FindFirstFileW,_wcscmp,_wcscmp,GetFileAttributesW,SetFileAttributesW,FindNextFileW,FindClose,FindFirstFileW,SetCurrentDirectoryW,_wcscmp,_wcscmp,SetCurrentDirectoryW,SetCurrentDirectoryW,FindNextFileW,FindClose,FindClose, |
16_2_001EF5D8 |
Source: C:\Users\user\AppData\Local\EduTech Dynamics\ApolloSphere.pif |
Code function: 16_2_001EF735 SetCurrentDirectoryW,FindFirstFileW,FindFirstFileW,_wcscmp,_wcscmp,FindNextFileW,FindClose,FindFirstFileW,SetCurrentDirectoryW,_wcscmp,_wcscmp,SetCurrentDirectoryW,SetCurrentDirectoryW,FindNextFileW,FindClose,FindClose, |
16_2_001EF735 |
Source: C:\Users\user\AppData\Local\EduTech Dynamics\ApolloSphere.pif |
Code function: 16_2_001EFA36 FindFirstFileW,Sleep,_wcscmp,_wcscmp,FindNextFileW,FindClose, |
16_2_001EFA36 |
Source: C:\Users\user\AppData\Local\EduTech Dynamics\ApolloSphere.pif |
Code function: 16_2_001E3CE2 FindFirstFileW,DeleteFileW,DeleteFileW,MoveFileW,DeleteFileW,FindNextFileW,FindClose,FindClose, |
16_2_001E3CE2 |
Source: f3ba41ba0b508b0965153c1688d6df6de6b3fdf59b015.exe |
String found in binary or memory: http://crl.globalsign.com/codesigningrootr45.crl0U |
Source: f3ba41ba0b508b0965153c1688d6df6de6b3fdf59b015.exe, 00000000.00000003.2025611009.0000000002835000.00000004.00000020.00020000.00000000.sdmp, Flash.pif, 0000000B.00000003.2078132463.0000000003B9A000.00000004.00000800.00020000.00000000.sdmp, Flash.pif, 0000000B.00000002.3257234453.00000000039E0000.00000004.00000800.00020000.00000000.sdmp, Flash.pif, 0000000B.00000003.3247044390.00000000039D1000.00000004.00000800.00020000.00000000.sdmp, Confidentiality.0.dr, ApolloSphere.pif.11.dr, Flash.pif.2.dr |
String found in binary or memory: http://crl.globalsign.com/gs/gstimestampingsha2g2.crl0 |
Source: f3ba41ba0b508b0965153c1688d6df6de6b3fdf59b015.exe, 00000000.00000003.2025611009.0000000002835000.00000004.00000020.00020000.00000000.sdmp, Flash.pif, 0000000B.00000003.2078132463.0000000003B9A000.00000004.00000800.00020000.00000000.sdmp, Flash.pif, 0000000B.00000002.3257234453.00000000039E0000.00000004.00000800.00020000.00000000.sdmp, Flash.pif, 0000000B.00000003.3247044390.00000000039D1000.00000004.00000800.00020000.00000000.sdmp, Confidentiality.0.dr, ApolloSphere.pif.11.dr, Flash.pif.2.dr |
String found in binary or memory: http://crl.globalsign.com/gscodesignsha2g3.crl0 |
Source: f3ba41ba0b508b0965153c1688d6df6de6b3fdf59b015.exe |
String found in binary or memory: http://crl.globalsign.com/gsgccr45evcodesignca2020.crl0 |
Source: f3ba41ba0b508b0965153c1688d6df6de6b3fdf59b015.exe, 00000000.00000003.2025611009.0000000002835000.00000004.00000020.00020000.00000000.sdmp, Flash.pif, 0000000B.00000003.2078132463.0000000003B9A000.00000004.00000800.00020000.00000000.sdmp, Flash.pif, 0000000B.00000002.3257234453.00000000039E0000.00000004.00000800.00020000.00000000.sdmp, Flash.pif, 0000000B.00000003.3247044390.00000000039D1000.00000004.00000800.00020000.00000000.sdmp, Confidentiality.0.dr, ApolloSphere.pif.11.dr, Flash.pif.2.dr |
String found in binary or memory: http://crl.globalsign.com/root-r3.crl0c |
Source: f3ba41ba0b508b0965153c1688d6df6de6b3fdf59b015.exe, 00000000.00000003.2025611009.0000000002835000.00000004.00000020.00020000.00000000.sdmp, Flash.pif, 0000000B.00000003.2078132463.0000000003B9A000.00000004.00000800.00020000.00000000.sdmp, Flash.pif, 0000000B.00000002.3257234453.00000000039E0000.00000004.00000800.00020000.00000000.sdmp, Flash.pif, 0000000B.00000003.3247044390.00000000039D1000.00000004.00000800.00020000.00000000.sdmp, Confidentiality.0.dr, ApolloSphere.pif.11.dr, Flash.pif.2.dr |
String found in binary or memory: http://crl.globalsign.net/root-r3.crl0 |
Source: f3ba41ba0b508b0965153c1688d6df6de6b3fdf59b015.exe |
String found in binary or memory: http://crl.sectigo.com/SectigoRSATimeStampingCA.crl0t |
Source: f3ba41ba0b508b0965153c1688d6df6de6b3fdf59b015.exe |
String found in binary or memory: http://crt.sectigo.com/SectigoRSATimeStampingCA.crt0# |
Source: f3ba41ba0b508b0965153c1688d6df6de6b3fdf59b015.exe |
String found in binary or memory: http://nsis.sf.net/NSIS_ErrorError |
Source: f3ba41ba0b508b0965153c1688d6df6de6b3fdf59b015.exe |
String found in binary or memory: http://ocsp.globalsign.com/codesigningrootr450F |
Source: f3ba41ba0b508b0965153c1688d6df6de6b3fdf59b015.exe |
String found in binary or memory: http://ocsp.globalsign.com/gsgccr45evcodesignca20200U |
Source: f3ba41ba0b508b0965153c1688d6df6de6b3fdf59b015.exe |
String found in binary or memory: http://ocsp.sectigo.com0 |
Source: f3ba41ba0b508b0965153c1688d6df6de6b3fdf59b015.exe, 00000000.00000003.2025611009.0000000002835000.00000004.00000020.00020000.00000000.sdmp, Flash.pif, 0000000B.00000003.2078132463.0000000003B9A000.00000004.00000800.00020000.00000000.sdmp, Flash.pif, 0000000B.00000002.3257234453.00000000039E0000.00000004.00000800.00020000.00000000.sdmp, Flash.pif, 0000000B.00000003.3247044390.00000000039D1000.00000004.00000800.00020000.00000000.sdmp, Confidentiality.0.dr, ApolloSphere.pif.11.dr, Flash.pif.2.dr |
String found in binary or memory: http://ocsp2.globalsign.com/gscodesignsha2g30V |
Source: f3ba41ba0b508b0965153c1688d6df6de6b3fdf59b015.exe, 00000000.00000003.2025611009.0000000002835000.00000004.00000020.00020000.00000000.sdmp, Flash.pif, 0000000B.00000003.2078132463.0000000003B9A000.00000004.00000800.00020000.00000000.sdmp, Flash.pif, 0000000B.00000002.3257234453.00000000039E0000.00000004.00000800.00020000.00000000.sdmp, Flash.pif, 0000000B.00000003.3247044390.00000000039D1000.00000004.00000800.00020000.00000000.sdmp, Confidentiality.0.dr, ApolloSphere.pif.11.dr, Flash.pif.2.dr |
String found in binary or memory: http://ocsp2.globalsign.com/gstimestampingsha2g20 |
Source: f3ba41ba0b508b0965153c1688d6df6de6b3fdf59b015.exe, 00000000.00000003.2025611009.0000000002835000.00000004.00000020.00020000.00000000.sdmp, Flash.pif, 0000000B.00000003.2078132463.0000000003B9A000.00000004.00000800.00020000.00000000.sdmp, Flash.pif, 0000000B.00000002.3257234453.00000000039E0000.00000004.00000800.00020000.00000000.sdmp, Flash.pif, 0000000B.00000003.3247044390.00000000039D1000.00000004.00000800.00020000.00000000.sdmp, Confidentiality.0.dr, ApolloSphere.pif.11.dr, Flash.pif.2.dr |
String found in binary or memory: http://ocsp2.globalsign.com/rootr306 |
Source: f3ba41ba0b508b0965153c1688d6df6de6b3fdf59b015.exe |
String found in binary or memory: http://secure.globalsign.com/cacert/codesigningrootr45.crt0A |
Source: f3ba41ba0b508b0965153c1688d6df6de6b3fdf59b015.exe, 00000000.00000003.2025611009.0000000002835000.00000004.00000020.00020000.00000000.sdmp, Flash.pif, 0000000B.00000003.2078132463.0000000003B9A000.00000004.00000800.00020000.00000000.sdmp, Flash.pif, 0000000B.00000002.3257234453.00000000039E0000.00000004.00000800.00020000.00000000.sdmp, Flash.pif, 0000000B.00000003.3247044390.00000000039D1000.00000004.00000800.00020000.00000000.sdmp, Confidentiality.0.dr, ApolloSphere.pif.11.dr, Flash.pif.2.dr |
String found in binary or memory: http://secure.globalsign.com/cacert/gscodesignsha2g3ocsp.crt08 |
Source: f3ba41ba0b508b0965153c1688d6df6de6b3fdf59b015.exe |
String found in binary or memory: http://secure.globalsign.com/cacert/gsgccr45evcodesignca2020.crt0? |
Source: f3ba41ba0b508b0965153c1688d6df6de6b3fdf59b015.exe, 00000000.00000003.2025611009.0000000002835000.00000004.00000020.00020000.00000000.sdmp, Flash.pif, 0000000B.00000003.2078132463.0000000003B9A000.00000004.00000800.00020000.00000000.sdmp, Flash.pif, 0000000B.00000002.3257234453.00000000039E0000.00000004.00000800.00020000.00000000.sdmp, Flash.pif, 0000000B.00000003.3247044390.00000000039D1000.00000004.00000800.00020000.00000000.sdmp, Confidentiality.0.dr, ApolloSphere.pif.11.dr, Flash.pif.2.dr |
String found in binary or memory: http://secure.globalsign.com/cacert/gstimestampingsha2g2.crt0 |
Source: f3ba41ba0b508b0965153c1688d6df6de6b3fdf59b015.exe, 00000000.00000003.2017160041.000000000283A000.00000004.00000020.00020000.00000000.sdmp, Flash.pif, 0000000B.00000003.2078132463.0000000003B9A000.00000004.00000800.00020000.00000000.sdmp, Flash.pif, 0000000B.00000000.2068027405.0000000000A99000.00000002.00000001.01000000.00000005.sdmp, ApolloSphere.pif, 00000010.00000002.3254047841.0000000000249000.00000002.00000001.01000000.00000008.sdmp, ApolloSphere.pif.11.dr, Flash.pif.2.dr, Parents.0.dr |
String found in binary or memory: http://www.autoitscript.com/autoit3/J |
Source: Flash.pif, 0000000B.00000002.3256409691.000000000141A000.00000004.00000800.00020000.00000000.sdmp, Flash.pif, 0000000B.00000002.3256254115.0000000001350000.00000004.00000800.00020000.00000000.sdmp, Flash.pif, 0000000B.00000003.3249041675.00000000030D4000.00000004.00000800.00020000.00000000.sdmp, Flash.pif, 0000000B.00000003.3249083801.000000000139B000.00000004.00000800.00020000.00000000.sdmp, Flash.pif, 0000000B.00000002.3256579902.00000000014CB000.00000004.00000800.00020000.00000000.sdmp, Flash.pif, 0000000B.00000003.3248898877.0000000001351000.00000004.00000800.00020000.00000000.sdmp, Flash.pif, 0000000B.00000003.3248832355.00000000042DB000.00000004.00000800.00020000.00000000.sdmp |
String found in binary or memory: https://api.ip.sb/ip |
Source: f3ba41ba0b508b0965153c1688d6df6de6b3fdf59b015.exe |
String found in binary or memory: https://sectigo.com/CPS0 |
Source: f3ba41ba0b508b0965153c1688d6df6de6b3fdf59b015.exe, 00000000.00000003.2025611009.0000000002835000.00000004.00000020.00020000.00000000.sdmp, Flash.pif, 0000000B.00000003.2078132463.0000000003B9A000.00000004.00000800.00020000.00000000.sdmp, Flash.pif, 0000000B.00000002.3257234453.00000000039E0000.00000004.00000800.00020000.00000000.sdmp, Flash.pif, 0000000B.00000003.3247044390.00000000039D1000.00000004.00000800.00020000.00000000.sdmp, Confidentiality.0.dr, ApolloSphere.pif.11.dr, Flash.pif.2.dr |
String found in binary or memory: https://www.autoitscript.com/autoit3/ |
Source: Flash.pif.2.dr |
String found in binary or memory: https://www.globalsign.com/repository/0 |
Source: f3ba41ba0b508b0965153c1688d6df6de6b3fdf59b015.exe, 00000000.00000003.2025611009.0000000002835000.00000004.00000020.00020000.00000000.sdmp, Flash.pif, 0000000B.00000003.2078132463.0000000003B9A000.00000004.00000800.00020000.00000000.sdmp, Flash.pif, 0000000B.00000002.3257234453.00000000039E0000.00000004.00000800.00020000.00000000.sdmp, Flash.pif, 0000000B.00000003.3247044390.00000000039D1000.00000004.00000800.00020000.00000000.sdmp, Confidentiality.0.dr, ApolloSphere.pif.11.dr, Flash.pif.2.dr |
String found in binary or memory: https://www.globalsign.com/repository/06 |
Source: C:\Users\user\AppData\Local\Temp\723582\Flash.pif |
Code function: 11_2_00A5D164 DefDlgProcW,SendMessageW,GetWindowLongW,SendMessageW,SendMessageW,_wcsncpy,GetKeyState,GetKeyState,GetKeyState,SendMessageW,GetKeyState,SendMessageW,SendMessageW,SendMessageW,ImageList_SetDragCursorImage,ImageList_BeginDrag,SetCapture,ClientToScreen,ImageList_DragEnter,InvalidateRect,ReleaseCapture,GetCursorPos,ScreenToClient,SendMessageW,SendMessageW,SendMessageW,SendMessageW,SendMessageW,SendMessageW,SendMessageW,GetCursorPos,ScreenToClient,GetParent,SendMessageW,SendMessageW,ClientToScreen,TrackPopupMenuEx,SendMessageW,SendMessageW,ClientToScreen,TrackPopupMenuEx,GetWindowLongW, |
11_2_00A5D164 |
Source: C:\Users\user\AppData\Local\EduTech Dynamics\ApolloSphere.pif |
Code function: 16_2_0020D164 DefDlgProcW,SendMessageW,GetWindowLongW,SendMessageW,SendMessageW,_wcsncpy,GetKeyState,GetKeyState,GetKeyState,SendMessageW,GetKeyState,SendMessageW,SendMessageW,SendMessageW,ImageList_SetDragCursorImage,ImageList_BeginDrag,SetCapture,ClientToScreen,ImageList_DragEnter,InvalidateRect,ReleaseCapture,GetCursorPos,ScreenToClient,SendMessageW,SendMessageW,SendMessageW,SendMessageW,SendMessageW,SendMessageW,SendMessageW,GetCursorPos,ScreenToClient,GetParent,SendMessageW,SendMessageW,ClientToScreen,TrackPopupMenuEx,SendMessageW,SendMessageW,ClientToScreen,TrackPopupMenuEx,GetWindowLongW, |
16_2_0020D164 |
Source: C:\Users\user\Desktop\f3ba41ba0b508b0965153c1688d6df6de6b3fdf59b015.exe |
Code function: 0_2_0040497C |
0_2_0040497C |
Source: C:\Users\user\Desktop\f3ba41ba0b508b0965153c1688d6df6de6b3fdf59b015.exe |
Code function: 0_2_00406ED2 |
0_2_00406ED2 |
Source: C:\Users\user\Desktop\f3ba41ba0b508b0965153c1688d6df6de6b3fdf59b015.exe |
Code function: 0_2_004074BB |
0_2_004074BB |
Source: C:\Users\user\AppData\Local\Temp\723582\Flash.pif |
Code function: 11_2_009DB020 |
11_2_009DB020 |
Source: C:\Users\user\AppData\Local\Temp\723582\Flash.pif |
Code function: 11_2_009D94E0 |
11_2_009D94E0 |
Source: C:\Users\user\AppData\Local\Temp\723582\Flash.pif |
Code function: 11_2_009D9C80 |
11_2_009D9C80 |
Source: C:\Users\user\AppData\Local\Temp\723582\Flash.pif |
Code function: 11_2_009F23F5 |
11_2_009F23F5 |
Source: C:\Users\user\AppData\Local\Temp\723582\Flash.pif |
Code function: 11_2_00A58400 |
11_2_00A58400 |
Source: C:\Users\user\AppData\Local\Temp\723582\Flash.pif |
Code function: 11_2_00A06502 |
11_2_00A06502 |
Source: C:\Users\user\AppData\Local\Temp\723582\Flash.pif |
Code function: 11_2_009DE6F0 |
11_2_009DE6F0 |
Source: C:\Users\user\AppData\Local\Temp\723582\Flash.pif |
Code function: 11_2_00A0265E |
11_2_00A0265E |
Source: C:\Users\user\AppData\Local\Temp\723582\Flash.pif |
Code function: 11_2_009F282A |
11_2_009F282A |
Source: C:\Users\user\AppData\Local\Temp\723582\Flash.pif |
Code function: 11_2_00A089BF |
11_2_00A089BF |
Source: C:\Users\user\AppData\Local\Temp\723582\Flash.pif |
Code function: 11_2_00A50A3A |
11_2_00A50A3A |
Source: C:\Users\user\AppData\Local\Temp\723582\Flash.pif |
Code function: 11_2_00A06A74 |
11_2_00A06A74 |
Source: C:\Users\user\AppData\Local\Temp\723582\Flash.pif |
Code function: 11_2_009E0BE0 |
11_2_009E0BE0 |
Source: C:\Users\user\AppData\Local\Temp\723582\Flash.pif |
Code function: 11_2_00A2EDB2 |
11_2_00A2EDB2 |
Source: C:\Users\user\AppData\Local\Temp\723582\Flash.pif |
Code function: 11_2_009FCD51 |
11_2_009FCD51 |
Source: C:\Users\user\AppData\Local\Temp\723582\Flash.pif |
Code function: 11_2_00A50EB7 |
11_2_00A50EB7 |
Source: C:\Users\user\AppData\Local\Temp\723582\Flash.pif |
Code function: 11_2_00A38E44 |
11_2_00A38E44 |
Source: C:\Users\user\AppData\Local\Temp\723582\Flash.pif |
Code function: 11_2_00A06FE6 |
11_2_00A06FE6 |
Source: C:\Users\user\AppData\Local\Temp\723582\Flash.pif |
Code function: 11_2_009F33B7 |
11_2_009F33B7 |
Source: C:\Users\user\AppData\Local\Temp\723582\Flash.pif |
Code function: 11_2_009FF409 |
11_2_009FF409 |
Source: C:\Users\user\AppData\Local\Temp\723582\Flash.pif |
Code function: 11_2_009ED45D |
11_2_009ED45D |
Source: C:\Users\user\AppData\Local\Temp\723582\Flash.pif |
Code function: 11_2_009F16B4 |
11_2_009F16B4 |
Source: C:\Users\user\AppData\Local\Temp\723582\Flash.pif |
Code function: 11_2_009DF6A0 |
11_2_009DF6A0 |
Source: C:\Users\user\AppData\Local\Temp\723582\Flash.pif |
Code function: 11_2_009EF628 |
11_2_009EF628 |
Source: C:\Users\user\AppData\Local\Temp\723582\Flash.pif |
Code function: 11_2_009D1663 |
11_2_009D1663 |
Source: C:\Users\user\AppData\Local\Temp\723582\Flash.pif |
Code function: 11_2_009F78C3 |
11_2_009F78C3 |
Source: C:\Users\user\AppData\Local\Temp\723582\Flash.pif |
Code function: 11_2_009F1BA8 |
11_2_009F1BA8 |
Source: C:\Users\user\AppData\Local\Temp\723582\Flash.pif |
Code function: 11_2_009FDBA5 |
11_2_009FDBA5 |
Source: C:\Users\user\AppData\Local\Temp\723582\Flash.pif |
Code function: 11_2_00A09CE5 |
11_2_00A09CE5 |
Source: C:\Users\user\AppData\Local\Temp\723582\Flash.pif |
Code function: 11_2_009EDD28 |
11_2_009EDD28 |
Source: C:\Users\user\AppData\Local\Temp\723582\Flash.pif |
Code function: 11_2_009FBFD6 |
11_2_009FBFD6 |
Source: C:\Users\user\AppData\Local\Temp\723582\Flash.pif |
Code function: 11_2_009F1FC0 |
11_2_009F1FC0 |
Source: C:\Users\user\AppData\Local\EduTech Dynamics\ApolloSphere.pif |
Code function: 16_2_0018B020 |
16_2_0018B020 |
Source: C:\Users\user\AppData\Local\EduTech Dynamics\ApolloSphere.pif |
Code function: 16_2_001894E0 |
16_2_001894E0 |
Source: C:\Users\user\AppData\Local\EduTech Dynamics\ApolloSphere.pif |
Code function: 16_2_00189C80 |
16_2_00189C80 |
Source: C:\Users\user\AppData\Local\EduTech Dynamics\ApolloSphere.pif |
Code function: 16_2_001A23F5 |
16_2_001A23F5 |
Source: C:\Users\user\AppData\Local\EduTech Dynamics\ApolloSphere.pif |
Code function: 16_2_00208400 |
16_2_00208400 |
Source: C:\Users\user\AppData\Local\EduTech Dynamics\ApolloSphere.pif |
Code function: 16_2_001B6502 |
16_2_001B6502 |
Source: C:\Users\user\AppData\Local\EduTech Dynamics\ApolloSphere.pif |
Code function: 16_2_001B265E |
16_2_001B265E |
Source: C:\Users\user\AppData\Local\EduTech Dynamics\ApolloSphere.pif |
Code function: 16_2_0018E6F0 |
16_2_0018E6F0 |
Source: C:\Users\user\AppData\Local\EduTech Dynamics\ApolloSphere.pif |
Code function: 16_2_001A282A |
16_2_001A282A |
Source: C:\Users\user\AppData\Local\EduTech Dynamics\ApolloSphere.pif |
Code function: 16_2_001B89BF |
16_2_001B89BF |
Source: C:\Users\user\AppData\Local\EduTech Dynamics\ApolloSphere.pif |
Code function: 16_2_00200A3A |
16_2_00200A3A |
Source: C:\Users\user\AppData\Local\EduTech Dynamics\ApolloSphere.pif |
Code function: 16_2_001B6A74 |
16_2_001B6A74 |
Source: C:\Users\user\AppData\Local\EduTech Dynamics\ApolloSphere.pif |
Code function: 16_2_00190BE0 |
16_2_00190BE0 |
Source: C:\Users\user\AppData\Local\EduTech Dynamics\ApolloSphere.pif |
Code function: 16_2_001ACD51 |
16_2_001ACD51 |
Source: C:\Users\user\AppData\Local\EduTech Dynamics\ApolloSphere.pif |
Code function: 16_2_001DEDB2 |
16_2_001DEDB2 |
Source: C:\Users\user\AppData\Local\EduTech Dynamics\ApolloSphere.pif |
Code function: 16_2_001E8E44 |
16_2_001E8E44 |
Source: C:\Users\user\AppData\Local\EduTech Dynamics\ApolloSphere.pif |
Code function: 16_2_00200EB7 |
16_2_00200EB7 |
Source: C:\Users\user\AppData\Local\EduTech Dynamics\ApolloSphere.pif |
Code function: 16_2_001B6FE6 |
16_2_001B6FE6 |
Source: C:\Users\user\AppData\Local\EduTech Dynamics\ApolloSphere.pif |
Code function: 16_2_001A33B7 |
16_2_001A33B7 |
Source: C:\Users\user\AppData\Local\EduTech Dynamics\ApolloSphere.pif |
Code function: 16_2_001AF409 |
16_2_001AF409 |
Source: C:\Users\user\AppData\Local\EduTech Dynamics\ApolloSphere.pif |
Code function: 16_2_0019D45D |
16_2_0019D45D |
Source: C:\Users\user\AppData\Local\EduTech Dynamics\ApolloSphere.pif |
Code function: 16_2_0019F628 |
16_2_0019F628 |
Source: C:\Users\user\AppData\Local\EduTech Dynamics\ApolloSphere.pif |
Code function: 16_2_00181663 |
16_2_00181663 |
Source: C:\Users\user\AppData\Local\EduTech Dynamics\ApolloSphere.pif |
Code function: 16_2_001A16B4 |
16_2_001A16B4 |
Source: C:\Users\user\AppData\Local\EduTech Dynamics\ApolloSphere.pif |
Code function: 16_2_0018F6A0 |
16_2_0018F6A0 |
Source: C:\Users\user\AppData\Local\EduTech Dynamics\ApolloSphere.pif |
Code function: 16_2_001A78C3 |
16_2_001A78C3 |
Source: C:\Users\user\AppData\Local\EduTech Dynamics\ApolloSphere.pif |
Code function: 16_2_001A1BA8 |
16_2_001A1BA8 |
Source: C:\Users\user\AppData\Local\EduTech Dynamics\ApolloSphere.pif |
Code function: 16_2_001ADBA5 |
16_2_001ADBA5 |
Source: C:\Users\user\AppData\Local\EduTech Dynamics\ApolloSphere.pif |
Code function: 16_2_001B9CE5 |
16_2_001B9CE5 |
Source: C:\Users\user\AppData\Local\EduTech Dynamics\ApolloSphere.pif |
Code function: 16_2_0019DD28 |
16_2_0019DD28 |
Source: C:\Users\user\AppData\Local\EduTech Dynamics\ApolloSphere.pif |
Code function: 16_2_001ABFD6 |
16_2_001ABFD6 |
Source: C:\Users\user\AppData\Local\EduTech Dynamics\ApolloSphere.pif |
Code function: 16_2_001A1FC0 |
16_2_001A1FC0 |
Source: unknown |
Process created: C:\Users\user\Desktop\f3ba41ba0b508b0965153c1688d6df6de6b3fdf59b015.exe "C:\Users\user\Desktop\f3ba41ba0b508b0965153c1688d6df6de6b3fdf59b015.exe" |
|
Source: C:\Users\user\Desktop\f3ba41ba0b508b0965153c1688d6df6de6b3fdf59b015.exe |
Process created: C:\Windows\SysWOW64\cmd.exe "C:\Windows\System32\cmd.exe" /k copy Surgeons Surgeons.cmd & Surgeons.cmd & exit |
|
Source: C:\Windows\SysWOW64\cmd.exe |
Process created: C:\Windows\System32\conhost.exe C:\Windows\system32\conhost.exe 0xffffffff -ForceV1 |
|
Source: C:\Windows\SysWOW64\cmd.exe |
Process created: C:\Windows\SysWOW64\tasklist.exe tasklist |
|
Source: C:\Windows\SysWOW64\cmd.exe |
Process created: C:\Windows\SysWOW64\findstr.exe findstr /I "wrsa.exe opssvc.exe" |
|
Source: C:\Windows\SysWOW64\cmd.exe |
Process created: C:\Windows\SysWOW64\tasklist.exe tasklist |
|
Source: C:\Windows\SysWOW64\cmd.exe |
Process created: C:\Windows\SysWOW64\findstr.exe findstr /I "avastui.exe avgui.exe bdservicehost.exe nswscsvc.exe sophoshealth.exe" |
|
Source: C:\Windows\SysWOW64\cmd.exe |
Process created: C:\Windows\SysWOW64\cmd.exe cmd /c md 723582 |
|
Source: C:\Windows\SysWOW64\cmd.exe |
Process created: C:\Windows\SysWOW64\findstr.exe findstr /V "wagemissileaffiliatesgreeting" Fisting |
|
Source: C:\Windows\SysWOW64\cmd.exe |
Process created: C:\Windows\SysWOW64\cmd.exe cmd /c copy /b Restriction + Manager + Screw + Anchor 723582\r |
|
Source: C:\Windows\SysWOW64\cmd.exe |
Process created: C:\Users\user\AppData\Local\Temp\723582\Flash.pif 723582\Flash.pif 723582\r |
|
Source: C:\Windows\SysWOW64\cmd.exe |
Process created: C:\Windows\SysWOW64\timeout.exe timeout 15 |
|
Source: C:\Users\user\AppData\Local\Temp\723582\Flash.pif |
Process created: C:\Windows\SysWOW64\schtasks.exe schtasks.exe /create /tn "ApolloSphere" /tr "wscript //B 'C:\Users\user\AppData\Local\EduTech Dynamics\ApolloSphere.js'" /sc onlogon /F /RL HIGHEST |
|
Source: C:\Windows\SysWOW64\schtasks.exe |
Process created: C:\Windows\System32\conhost.exe C:\Windows\system32\conhost.exe 0xffffffff -ForceV1 |
|
Source: unknown |
Process created: C:\Windows\System32\wscript.exe C:\Windows\system32\wscript.EXE //B "C:\Users\user\AppData\Local\EduTech Dynamics\ApolloSphere.js" |
|
Source: C:\Windows\System32\wscript.exe |
Process created: C:\Users\user\AppData\Local\EduTech Dynamics\ApolloSphere.pif "C:\Users\user\AppData\Local\EduTech Dynamics\ApolloSphere.pif" "C:\Users\user\AppData\Local\EduTech Dynamics\L" |
|
Source: C:\Users\user\AppData\Local\Temp\723582\Flash.pif |
Process created: C:\Users\user\AppData\Local\Temp\723582\RegAsm.exe C:\Users\user\AppData\Local\Temp\723582\RegAsm.exe |
|
Source: C:\Users\user\Desktop\f3ba41ba0b508b0965153c1688d6df6de6b3fdf59b015.exe |
Process created: C:\Windows\SysWOW64\cmd.exe "C:\Windows\System32\cmd.exe" /k copy Surgeons Surgeons.cmd & Surgeons.cmd & exit |
Jump to behavior |
Source: C:\Windows\SysWOW64\cmd.exe |
Process created: C:\Windows\SysWOW64\tasklist.exe tasklist |
Jump to behavior |
Source: C:\Windows\SysWOW64\cmd.exe |
Process created: C:\Windows\SysWOW64\findstr.exe findstr /I "wrsa.exe opssvc.exe" |
Jump to behavior |
Source: C:\Windows\SysWOW64\cmd.exe |
Process created: C:\Windows\SysWOW64\tasklist.exe tasklist |
Jump to behavior |
Source: C:\Windows\SysWOW64\cmd.exe |
Process created: C:\Windows\SysWOW64\findstr.exe findstr /I "avastui.exe avgui.exe bdservicehost.exe nswscsvc.exe sophoshealth.exe" |
Jump to behavior |
Source: C:\Windows\SysWOW64\cmd.exe |
Process created: C:\Windows\SysWOW64\cmd.exe cmd /c md 723582 |
Jump to behavior |
Source: C:\Windows\SysWOW64\cmd.exe |
Process created: C:\Windows\SysWOW64\findstr.exe findstr /V "wagemissileaffiliatesgreeting" Fisting |
Jump to behavior |
Source: C:\Windows\SysWOW64\cmd.exe |
Process created: C:\Windows\SysWOW64\cmd.exe cmd /c copy /b Restriction + Manager + Screw + Anchor 723582\r |
Jump to behavior |
Source: C:\Windows\SysWOW64\cmd.exe |
Process created: C:\Users\user\AppData\Local\Temp\723582\Flash.pif 723582\Flash.pif 723582\r |
Jump to behavior |
Source: C:\Windows\SysWOW64\cmd.exe |
Process created: C:\Windows\SysWOW64\timeout.exe timeout 15 |
Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\723582\Flash.pif |
Process created: C:\Windows\SysWOW64\schtasks.exe schtasks.exe /create /tn "ApolloSphere" /tr "wscript //B 'C:\Users\user\AppData\Local\EduTech Dynamics\ApolloSphere.js'" /sc onlogon /F /RL HIGHEST |
Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\723582\Flash.pif |
Process created: C:\Users\user\AppData\Local\Temp\723582\RegAsm.exe C:\Users\user\AppData\Local\Temp\723582\RegAsm.exe |
Jump to behavior |
Source: C:\Windows\System32\wscript.exe |
Process created: C:\Users\user\AppData\Local\EduTech Dynamics\ApolloSphere.pif "C:\Users\user\AppData\Local\EduTech Dynamics\ApolloSphere.pif" "C:\Users\user\AppData\Local\EduTech Dynamics\L" |
Jump to behavior |
Source: C:\Users\user\Desktop\f3ba41ba0b508b0965153c1688d6df6de6b3fdf59b015.exe |
Section loaded: apphelp.dll |
Jump to behavior |
Source: C:\Users\user\Desktop\f3ba41ba0b508b0965153c1688d6df6de6b3fdf59b015.exe |
Section loaded: version.dll |
Jump to behavior |
Source: C:\Users\user\Desktop\f3ba41ba0b508b0965153c1688d6df6de6b3fdf59b015.exe |
Section loaded: kernel.appcore.dll |
Jump to behavior |
Source: C:\Users\user\Desktop\f3ba41ba0b508b0965153c1688d6df6de6b3fdf59b015.exe |
Section loaded: uxtheme.dll |
Jump to behavior |
Source: C:\Users\user\Desktop\f3ba41ba0b508b0965153c1688d6df6de6b3fdf59b015.exe |
Section loaded: shfolder.dll |
Jump to behavior |
Source: C:\Users\user\Desktop\f3ba41ba0b508b0965153c1688d6df6de6b3fdf59b015.exe |
Section loaded: windows.storage.dll |
Jump to behavior |
Source: C:\Users\user\Desktop\f3ba41ba0b508b0965153c1688d6df6de6b3fdf59b015.exe |
Section loaded: wldp.dll |
Jump to behavior |
Source: C:\Users\user\Desktop\f3ba41ba0b508b0965153c1688d6df6de6b3fdf59b015.exe |
Section loaded: propsys.dll |
Jump to behavior |
Source: C:\Users\user\Desktop\f3ba41ba0b508b0965153c1688d6df6de6b3fdf59b015.exe |
Section loaded: profapi.dll |
Jump to behavior |
Source: C:\Users\user\Desktop\f3ba41ba0b508b0965153c1688d6df6de6b3fdf59b015.exe |
Section loaded: edputil.dll |
Jump to behavior |
Source: C:\Users\user\Desktop\f3ba41ba0b508b0965153c1688d6df6de6b3fdf59b015.exe |
Section loaded: urlmon.dll |
Jump to behavior |
Source: C:\Users\user\Desktop\f3ba41ba0b508b0965153c1688d6df6de6b3fdf59b015.exe |
Section loaded: iertutil.dll |
Jump to behavior |
Source: C:\Users\user\Desktop\f3ba41ba0b508b0965153c1688d6df6de6b3fdf59b015.exe |
Section loaded: srvcli.dll |
Jump to behavior |
Source: C:\Users\user\Desktop\f3ba41ba0b508b0965153c1688d6df6de6b3fdf59b015.exe |
Section loaded: netutils.dll |
Jump to behavior |
Source: C:\Users\user\Desktop\f3ba41ba0b508b0965153c1688d6df6de6b3fdf59b015.exe |
Section loaded: windows.staterepositoryps.dll |
Jump to behavior |
Source: C:\Users\user\Desktop\f3ba41ba0b508b0965153c1688d6df6de6b3fdf59b015.exe |
Section loaded: sspicli.dll |
Jump to behavior |
Source: C:\Users\user\Desktop\f3ba41ba0b508b0965153c1688d6df6de6b3fdf59b015.exe |
Section loaded: wintypes.dll |
Jump to behavior |
Source: C:\Users\user\Desktop\f3ba41ba0b508b0965153c1688d6df6de6b3fdf59b015.exe |
Section loaded: appresolver.dll |
Jump to behavior |
Source: C:\Users\user\Desktop\f3ba41ba0b508b0965153c1688d6df6de6b3fdf59b015.exe |
Section loaded: bcp47langs.dll |
Jump to behavior |
Source: C:\Users\user\Desktop\f3ba41ba0b508b0965153c1688d6df6de6b3fdf59b015.exe |
Section loaded: slc.dll |
Jump to behavior |
Source: C:\Users\user\Desktop\f3ba41ba0b508b0965153c1688d6df6de6b3fdf59b015.exe |
Section loaded: userenv.dll |
Jump to behavior |
Source: C:\Users\user\Desktop\f3ba41ba0b508b0965153c1688d6df6de6b3fdf59b015.exe |
Section loaded: sppc.dll |
Jump to behavior |
Source: C:\Users\user\Desktop\f3ba41ba0b508b0965153c1688d6df6de6b3fdf59b015.exe |
Section loaded: onecorecommonproxystub.dll |
Jump to behavior |
Source: C:\Users\user\Desktop\f3ba41ba0b508b0965153c1688d6df6de6b3fdf59b015.exe |
Section loaded: onecoreuapcommonproxystub.dll |
Jump to behavior |
Source: C:\Windows\SysWOW64\cmd.exe |
Section loaded: ntmarta.dll |
Jump to behavior |
Source: C:\Windows\SysWOW64\cmd.exe |
Section loaded: cmdext.dll |
Jump to behavior |
Source: C:\Windows\SysWOW64\cmd.exe |
Section loaded: apphelp.dll |
Jump to behavior |
Source: C:\Windows\SysWOW64\tasklist.exe |
Section loaded: version.dll |
Jump to behavior |
Source: C:\Windows\SysWOW64\tasklist.exe |
Section loaded: mpr.dll |
Jump to behavior |
Source: C:\Windows\SysWOW64\tasklist.exe |
Section loaded: framedynos.dll |
Jump to behavior |
Source: C:\Windows\SysWOW64\tasklist.exe |
Section loaded: dbghelp.dll |
Jump to behavior |
Source: C:\Windows\SysWOW64\tasklist.exe |
Section loaded: sspicli.dll |
Jump to behavior |
Source: C:\Windows\SysWOW64\tasklist.exe |
Section loaded: srvcli.dll |
Jump to behavior |
Source: C:\Windows\SysWOW64\tasklist.exe |
Section loaded: netutils.dll |
Jump to behavior |
Source: C:\Windows\SysWOW64\tasklist.exe |
Section loaded: sspicli.dll |
Jump to behavior |
Source: C:\Windows\SysWOW64\tasklist.exe |
Section loaded: kernel.appcore.dll |
Jump to behavior |
Source: C:\Windows\SysWOW64\tasklist.exe |
Section loaded: wbemcomn.dll |
Jump to behavior |
Source: C:\Windows\SysWOW64\tasklist.exe |
Section loaded: winsta.dll |
Jump to behavior |
Source: C:\Windows\SysWOW64\tasklist.exe |
Section loaded: amsi.dll |
Jump to behavior |
Source: C:\Windows\SysWOW64\tasklist.exe |
Section loaded: userenv.dll |
Jump to behavior |
Source: C:\Windows\SysWOW64\tasklist.exe |
Section loaded: profapi.dll |
Jump to behavior |
Source: C:\Windows\SysWOW64\tasklist.exe |
Section loaded: version.dll |
Jump to behavior |
Source: C:\Windows\SysWOW64\tasklist.exe |
Section loaded: mpr.dll |
Jump to behavior |
Source: C:\Windows\SysWOW64\tasklist.exe |
Section loaded: framedynos.dll |
Jump to behavior |
Source: C:\Windows\SysWOW64\tasklist.exe |
Section loaded: dbghelp.dll |
Jump to behavior |
Source: C:\Windows\SysWOW64\tasklist.exe |
Section loaded: sspicli.dll |
Jump to behavior |
Source: C:\Windows\SysWOW64\tasklist.exe |
Section loaded: srvcli.dll |
Jump to behavior |
Source: C:\Windows\SysWOW64\tasklist.exe |
Section loaded: netutils.dll |
Jump to behavior |
Source: C:\Windows\SysWOW64\tasklist.exe |
Section loaded: sspicli.dll |
Jump to behavior |
Source: C:\Windows\SysWOW64\tasklist.exe |
Section loaded: kernel.appcore.dll |
Jump to behavior |
Source: C:\Windows\SysWOW64\tasklist.exe |
Section loaded: wbemcomn.dll |
Jump to behavior |
Source: C:\Windows\SysWOW64\tasklist.exe |
Section loaded: winsta.dll |
Jump to behavior |
Source: C:\Windows\SysWOW64\tasklist.exe |
Section loaded: amsi.dll |
Jump to behavior |
Source: C:\Windows\SysWOW64\tasklist.exe |
Section loaded: userenv.dll |
Jump to behavior |
Source: C:\Windows\SysWOW64\tasklist.exe |
Section loaded: profapi.dll |
Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\723582\Flash.pif |
Section loaded: wsock32.dll |
Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\723582\Flash.pif |
Section loaded: version.dll |
Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\723582\Flash.pif |
Section loaded: winmm.dll |
Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\723582\Flash.pif |
Section loaded: mpr.dll |
Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\723582\Flash.pif |
Section loaded: wininet.dll |
Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\723582\Flash.pif |
Section loaded: iphlpapi.dll |
Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\723582\Flash.pif |
Section loaded: userenv.dll |
Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\723582\Flash.pif |
Section loaded: uxtheme.dll |
Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\723582\Flash.pif |
Section loaded: kernel.appcore.dll |
Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\723582\Flash.pif |
Section loaded: windows.storage.dll |
Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\723582\Flash.pif |
Section loaded: wldp.dll |
Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\723582\Flash.pif |
Section loaded: ntmarta.dll |
Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\723582\Flash.pif |
Section loaded: napinsp.dll |
Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\723582\Flash.pif |
Section loaded: pnrpnsp.dll |
Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\723582\Flash.pif |
Section loaded: wshbth.dll |
Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\723582\Flash.pif |
Section loaded: nlaapi.dll |
Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\723582\Flash.pif |
Section loaded: mswsock.dll |
Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\723582\Flash.pif |
Section loaded: dnsapi.dll |
Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\723582\Flash.pif |
Section loaded: winrnr.dll |
Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\723582\Flash.pif |
Section loaded: rasadhlp.dll |
Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\723582\Flash.pif |
Section loaded: apphelp.dll |
Jump to behavior |
Source: C:\Windows\SysWOW64\timeout.exe |
Section loaded: version.dll |
Jump to behavior |
Source: C:\Windows\SysWOW64\schtasks.exe |
Section loaded: kernel.appcore.dll |
Jump to behavior |
Source: C:\Windows\SysWOW64\schtasks.exe |
Section loaded: taskschd.dll |
Jump to behavior |
Source: C:\Windows\SysWOW64\schtasks.exe |
Section loaded: sspicli.dll |
Jump to behavior |
Source: C:\Windows\SysWOW64\schtasks.exe |
Section loaded: xmllite.dll |
Jump to behavior |
Source: C:\Windows\System32\wscript.exe |
Section loaded: version.dll |
Jump to behavior |
Source: C:\Windows\System32\wscript.exe |
Section loaded: kernel.appcore.dll |
Jump to behavior |
Source: C:\Windows\System32\wscript.exe |
Section loaded: uxtheme.dll |
Jump to behavior |
Source: C:\Windows\System32\wscript.exe |
Section loaded: sxs.dll |
Jump to behavior |
Source: C:\Windows\System32\wscript.exe |
Section loaded: jscript.dll |
Jump to behavior |
Source: C:\Windows\System32\wscript.exe |
Section loaded: iertutil.dll |
Jump to behavior |
Source: C:\Windows\System32\wscript.exe |
Section loaded: amsi.dll |
Jump to behavior |
Source: C:\Windows\System32\wscript.exe |
Section loaded: userenv.dll |
Jump to behavior |
Source: C:\Windows\System32\wscript.exe |
Section loaded: profapi.dll |
Jump to behavior |
Source: C:\Windows\System32\wscript.exe |
Section loaded: wldp.dll |
Jump to behavior |
Source: C:\Windows\System32\wscript.exe |
Section loaded: msasn1.dll |
Jump to behavior |
Source: C:\Windows\System32\wscript.exe |
Section loaded: cryptsp.dll |
Jump to behavior |
Source: C:\Windows\System32\wscript.exe |
Section loaded: rsaenh.dll |
Jump to behavior |
Source: C:\Windows\System32\wscript.exe |
Section loaded: cryptbase.dll |
Jump to behavior |
Source: C:\Windows\System32\wscript.exe |
Section loaded: msisip.dll |
Jump to behavior |
Source: C:\Windows\System32\wscript.exe |
Section loaded: wshext.dll |
Jump to behavior |
Source: C:\Windows\System32\wscript.exe |
Section loaded: scrobj.dll |
Jump to behavior |
Source: C:\Windows\System32\wscript.exe |
Section loaded: mpr.dll |
Jump to behavior |
Source: C:\Windows\System32\wscript.exe |
Section loaded: scrrun.dll |
Jump to behavior |
Source: C:\Windows\System32\wscript.exe |
Section loaded: apphelp.dll |
Jump to behavior |
Source: C:\Users\user\AppData\Local\EduTech Dynamics\ApolloSphere.pif |
Section loaded: wsock32.dll |
Jump to behavior |
Source: C:\Users\user\AppData\Local\EduTech Dynamics\ApolloSphere.pif |
Section loaded: version.dll |
Jump to behavior |
Source: C:\Users\user\AppData\Local\EduTech Dynamics\ApolloSphere.pif |
Section loaded: winmm.dll |
Jump to behavior |
Source: C:\Users\user\AppData\Local\EduTech Dynamics\ApolloSphere.pif |
Section loaded: mpr.dll |
Jump to behavior |
Source: C:\Users\user\AppData\Local\EduTech Dynamics\ApolloSphere.pif |
Section loaded: wininet.dll |
Jump to behavior |
Source: C:\Users\user\AppData\Local\EduTech Dynamics\ApolloSphere.pif |
Section loaded: iphlpapi.dll |
Jump to behavior |
Source: C:\Users\user\AppData\Local\EduTech Dynamics\ApolloSphere.pif |
Section loaded: userenv.dll |
Jump to behavior |
Source: C:\Users\user\AppData\Local\EduTech Dynamics\ApolloSphere.pif |
Section loaded: uxtheme.dll |
Jump to behavior |
Source: C:\Users\user\AppData\Local\EduTech Dynamics\ApolloSphere.pif |
Section loaded: kernel.appcore.dll |
Jump to behavior |
Source: C:\Users\user\AppData\Local\EduTech Dynamics\ApolloSphere.pif |
Section loaded: windows.storage.dll |
Jump to behavior |
Source: C:\Users\user\AppData\Local\EduTech Dynamics\ApolloSphere.pif |
Section loaded: wldp.dll |
Jump to behavior |
Source: C:\Users\user\AppData\Local\EduTech Dynamics\ApolloSphere.pif |
Section loaded: napinsp.dll |
Jump to behavior |
Source: C:\Users\user\AppData\Local\EduTech Dynamics\ApolloSphere.pif |
Section loaded: pnrpnsp.dll |
Jump to behavior |
Source: C:\Users\user\AppData\Local\EduTech Dynamics\ApolloSphere.pif |
Section loaded: wshbth.dll |
Jump to behavior |
Source: C:\Users\user\AppData\Local\EduTech Dynamics\ApolloSphere.pif |
Section loaded: nlaapi.dll |
Jump to behavior |
Source: C:\Users\user\AppData\Local\EduTech Dynamics\ApolloSphere.pif |
Section loaded: mswsock.dll |
Jump to behavior |
Source: C:\Users\user\AppData\Local\EduTech Dynamics\ApolloSphere.pif |
Section loaded: dnsapi.dll |
Jump to behavior |
Source: C:\Users\user\AppData\Local\EduTech Dynamics\ApolloSphere.pif |
Section loaded: winrnr.dll |
Jump to behavior |
Source: C:\Users\user\AppData\Local\EduTech Dynamics\ApolloSphere.pif |
Section loaded: rasadhlp.dll |
Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\723582\Flash.pif |
Code function: 11_2_00A559B3 IsWindowVisible,IsWindowEnabled,GetForegroundWindow,IsIconic,IsZoomed, |
11_2_00A559B3 |
Source: C:\Users\user\AppData\Local\Temp\723582\Flash.pif |
Code function: 11_2_009E5EDA GetForegroundWindow,FindWindowW,IsIconic,ShowWindow,SetForegroundWindow,GetWindowThreadProcessId,GetWindowThreadProcessId,GetCurrentThreadId,GetWindowThreadProcessId,AttachThreadInput,AttachThreadInput,AttachThreadInput,AttachThreadInput,SetForegroundWindow,MapVirtualKeyW,MapVirtualKeyW,keybd_event,keybd_event,MapVirtualKeyW,keybd_event,MapVirtualKeyW,keybd_event,MapVirtualKeyW,keybd_event,SetForegroundWindow,AttachThreadInput,AttachThreadInput,AttachThreadInput,AttachThreadInput, |
11_2_009E5EDA |
Source: C:\Users\user\AppData\Local\EduTech Dynamics\ApolloSphere.pif |
Code function: 16_2_002059B3 IsWindowVisible,IsWindowEnabled,GetForegroundWindow,IsIconic,IsZoomed, |
16_2_002059B3 |
Source: C:\Users\user\AppData\Local\EduTech Dynamics\ApolloSphere.pif |
Code function: 16_2_00195EDA GetForegroundWindow,FindWindowW,IsIconic,ShowWindow,SetForegroundWindow,GetWindowThreadProcessId,GetWindowThreadProcessId,GetCurrentThreadId,GetWindowThreadProcessId,AttachThreadInput,AttachThreadInput,AttachThreadInput,AttachThreadInput,SetForegroundWindow,MapVirtualKeyW,MapVirtualKeyW,keybd_event,keybd_event,MapVirtualKeyW,keybd_event,MapVirtualKeyW,keybd_event,MapVirtualKeyW,keybd_event,SetForegroundWindow,AttachThreadInput,AttachThreadInput,AttachThreadInput,AttachThreadInput, |
16_2_00195EDA |
Source: C:\Users\user\Desktop\f3ba41ba0b508b0965153c1688d6df6de6b3fdf59b015.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\Desktop\f3ba41ba0b508b0965153c1688d6df6de6b3fdf59b015.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\Desktop\f3ba41ba0b508b0965153c1688d6df6de6b3fdf59b015.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\Desktop\f3ba41ba0b508b0965153c1688d6df6de6b3fdf59b015.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\Desktop\f3ba41ba0b508b0965153c1688d6df6de6b3fdf59b015.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\Desktop\f3ba41ba0b508b0965153c1688d6df6de6b3fdf59b015.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\Desktop\f3ba41ba0b508b0965153c1688d6df6de6b3fdf59b015.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\Desktop\f3ba41ba0b508b0965153c1688d6df6de6b3fdf59b015.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\Desktop\f3ba41ba0b508b0965153c1688d6df6de6b3fdf59b015.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\Desktop\f3ba41ba0b508b0965153c1688d6df6de6b3fdf59b015.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\Desktop\f3ba41ba0b508b0965153c1688d6df6de6b3fdf59b015.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\Desktop\f3ba41ba0b508b0965153c1688d6df6de6b3fdf59b015.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Windows\SysWOW64\cmd.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Windows\SysWOW64\tasklist.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Windows\SysWOW64\tasklist.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\723582\Flash.pif |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\723582\Flash.pif |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\723582\Flash.pif |
Process information set: FAILCRITICALERRORS | NOALIGNMENTFAULTEXCEPT | NOGPFAULTERRORBOX | NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Windows\System32\wscript.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Windows\System32\wscript.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\AppData\Local\EduTech Dynamics\ApolloSphere.pif |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\AppData\Local\EduTech Dynamics\ApolloSphere.pif |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\AppData\Local\EduTech Dynamics\ApolloSphere.pif |
Process information set: FAILCRITICALERRORS | NOALIGNMENTFAULTEXCEPT | NOGPFAULTERRORBOX | NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\Desktop\f3ba41ba0b508b0965153c1688d6df6de6b3fdf59b015.exe |
Code function: 0_2_004062D5 FindFirstFileW,FindClose, |
0_2_004062D5 |
Source: C:\Users\user\Desktop\f3ba41ba0b508b0965153c1688d6df6de6b3fdf59b015.exe |
Code function: 0_2_00402E18 FindFirstFileW, |
0_2_00402E18 |
Source: C:\Users\user\Desktop\f3ba41ba0b508b0965153c1688d6df6de6b3fdf59b015.exe |
Code function: 0_2_00406C9B DeleteFileW,lstrcatW,lstrcatW,lstrcatW,lstrlenW,FindFirstFileW,DeleteFileW,FindNextFileW,FindClose,RemoveDirectoryW, |
0_2_00406C9B |
Source: C:\Users\user\AppData\Local\Temp\723582\Flash.pif |
Code function: 11_2_00A34005 FindFirstFileW,DeleteFileW,FindNextFileW,FindClose,FindClose, |
11_2_00A34005 |
Source: C:\Users\user\AppData\Local\Temp\723582\Flash.pif |
Code function: 11_2_00A3494A GetFileAttributesW,FindFirstFileW,FindClose, |
11_2_00A3494A |
Source: C:\Users\user\AppData\Local\Temp\723582\Flash.pif |
Code function: 11_2_00A33CE2 FindFirstFileW,DeleteFileW,DeleteFileW,MoveFileW,DeleteFileW,FindNextFileW,FindClose,FindClose, |
11_2_00A33CE2 |
Source: C:\Users\user\AppData\Local\Temp\723582\Flash.pif |
Code function: 11_2_00A3C2FF FindFirstFileW,_wcscmp,_wcscmp,FindNextFileW,FindClose, |
11_2_00A3C2FF |
Source: C:\Users\user\AppData\Local\Temp\723582\Flash.pif |
Code function: 11_2_00A3CD9F FindFirstFileW,FindClose,FileTimeToLocalFileTime,FileTimeToLocalFileTime,FileTimeToLocalFileTime,FileTimeToSystemTime,__swprintf,__swprintf,__swprintf,__swprintf,__swprintf,__swprintf,__swprintf, |
11_2_00A3CD9F |
Source: C:\Users\user\AppData\Local\Temp\723582\Flash.pif |
Code function: 11_2_00A3CD14 FindFirstFileW,FindClose, |
11_2_00A3CD14 |
Source: C:\Users\user\AppData\Local\Temp\723582\Flash.pif |
Code function: 11_2_00A3F5D8 SetCurrentDirectoryW,FindFirstFileW,FindFirstFileW,_wcscmp,_wcscmp,GetFileAttributesW,SetFileAttributesW,FindNextFileW,FindClose,FindFirstFileW,SetCurrentDirectoryW,_wcscmp,_wcscmp,SetCurrentDirectoryW,SetCurrentDirectoryW,FindNextFileW,FindClose,FindClose, |
11_2_00A3F5D8 |
Source: C:\Users\user\AppData\Local\Temp\723582\Flash.pif |
Code function: 11_2_00A3F735 SetCurrentDirectoryW,FindFirstFileW,FindFirstFileW,_wcscmp,_wcscmp,FindNextFileW,FindClose,FindFirstFileW,SetCurrentDirectoryW,_wcscmp,_wcscmp,SetCurrentDirectoryW,SetCurrentDirectoryW,FindNextFileW,FindClose,FindClose, |
11_2_00A3F735 |
Source: C:\Users\user\AppData\Local\Temp\723582\Flash.pif |
Code function: 11_2_00A3FA36 FindFirstFileW,Sleep,_wcscmp,_wcscmp,FindNextFileW,FindClose, |
11_2_00A3FA36 |
Source: C:\Users\user\AppData\Local\EduTech Dynamics\ApolloSphere.pif |
Code function: 16_2_001E4005 FindFirstFileW,DeleteFileW,FindNextFileW,FindClose,FindClose, |
16_2_001E4005 |
Source: C:\Users\user\AppData\Local\EduTech Dynamics\ApolloSphere.pif |
Code function: 16_2_001E494A GetFileAttributesW,FindFirstFileW,FindClose, |
16_2_001E494A |
Source: C:\Users\user\AppData\Local\EduTech Dynamics\ApolloSphere.pif |
Code function: 16_2_001EC2FF FindFirstFileW,_wcscmp,_wcscmp,FindNextFileW,FindClose, |
16_2_001EC2FF |
Source: C:\Users\user\AppData\Local\EduTech Dynamics\ApolloSphere.pif |
Code function: 16_2_001ECD14 FindFirstFileW,FindClose, |
16_2_001ECD14 |
Source: C:\Users\user\AppData\Local\EduTech Dynamics\ApolloSphere.pif |
Code function: 16_2_001ECD9F FindFirstFileW,FindClose,FileTimeToLocalFileTime,FileTimeToLocalFileTime,FileTimeToLocalFileTime,FileTimeToSystemTime,__swprintf,__swprintf,__swprintf,__swprintf,__swprintf,__swprintf,__swprintf, |
16_2_001ECD9F |
Source: C:\Users\user\AppData\Local\EduTech Dynamics\ApolloSphere.pif |
Code function: 16_2_001EF5D8 SetCurrentDirectoryW,FindFirstFileW,FindFirstFileW,_wcscmp,_wcscmp,GetFileAttributesW,SetFileAttributesW,FindNextFileW,FindClose,FindFirstFileW,SetCurrentDirectoryW,_wcscmp,_wcscmp,SetCurrentDirectoryW,SetCurrentDirectoryW,FindNextFileW,FindClose,FindClose, |
16_2_001EF5D8 |
Source: C:\Users\user\AppData\Local\EduTech Dynamics\ApolloSphere.pif |
Code function: 16_2_001EF735 SetCurrentDirectoryW,FindFirstFileW,FindFirstFileW,_wcscmp,_wcscmp,FindNextFileW,FindClose,FindFirstFileW,SetCurrentDirectoryW,_wcscmp,_wcscmp,SetCurrentDirectoryW,SetCurrentDirectoryW,FindNextFileW,FindClose,FindClose, |
16_2_001EF735 |
Source: C:\Users\user\AppData\Local\EduTech Dynamics\ApolloSphere.pif |
Code function: 16_2_001EFA36 FindFirstFileW,Sleep,_wcscmp,_wcscmp,FindNextFileW,FindClose, |
16_2_001EFA36 |
Source: C:\Users\user\AppData\Local\EduTech Dynamics\ApolloSphere.pif |
Code function: 16_2_001E3CE2 FindFirstFileW,DeleteFileW,DeleteFileW,MoveFileW,DeleteFileW,FindNextFileW,FindClose,FindClose, |
16_2_001E3CE2 |
Source: C:\Users\user\Desktop\f3ba41ba0b508b0965153c1688d6df6de6b3fdf59b015.exe |
Process created: C:\Windows\SysWOW64\cmd.exe "C:\Windows\System32\cmd.exe" /k copy Surgeons Surgeons.cmd & Surgeons.cmd & exit |
Jump to behavior |
Source: C:\Windows\SysWOW64\cmd.exe |
Process created: C:\Windows\SysWOW64\tasklist.exe tasklist |
Jump to behavior |
Source: C:\Windows\SysWOW64\cmd.exe |
Process created: C:\Windows\SysWOW64\findstr.exe findstr /I "wrsa.exe opssvc.exe" |
Jump to behavior |
Source: C:\Windows\SysWOW64\cmd.exe |
Process created: C:\Windows\SysWOW64\tasklist.exe tasklist |
Jump to behavior |
Source: C:\Windows\SysWOW64\cmd.exe |
Process created: C:\Windows\SysWOW64\findstr.exe findstr /I "avastui.exe avgui.exe bdservicehost.exe nswscsvc.exe sophoshealth.exe" |
Jump to behavior |
Source: C:\Windows\SysWOW64\cmd.exe |
Process created: C:\Windows\SysWOW64\cmd.exe cmd /c md 723582 |
Jump to behavior |
Source: C:\Windows\SysWOW64\cmd.exe |
Process created: C:\Windows\SysWOW64\findstr.exe findstr /V "wagemissileaffiliatesgreeting" Fisting |
Jump to behavior |
Source: C:\Windows\SysWOW64\cmd.exe |
Process created: C:\Windows\SysWOW64\cmd.exe cmd /c copy /b Restriction + Manager + Screw + Anchor 723582\r |
Jump to behavior |
Source: C:\Windows\SysWOW64\cmd.exe |
Process created: C:\Users\user\AppData\Local\Temp\723582\Flash.pif 723582\Flash.pif 723582\r |
Jump to behavior |
Source: C:\Windows\SysWOW64\cmd.exe |
Process created: C:\Windows\SysWOW64\timeout.exe timeout 15 |
Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\723582\Flash.pif |
Process created: C:\Users\user\AppData\Local\Temp\723582\RegAsm.exe C:\Users\user\AppData\Local\Temp\723582\RegAsm.exe |
Jump to behavior |
Source: C:\Windows\System32\wscript.exe |
Process created: C:\Users\user\AppData\Local\EduTech Dynamics\ApolloSphere.pif "C:\Users\user\AppData\Local\EduTech Dynamics\ApolloSphere.pif" "C:\Users\user\AppData\Local\EduTech Dynamics\L" |
Jump to behavior |