Source: rundll32.exe, 00000004.00000002.2249096373.0000000000BD0000.00000004.00000020.00020000.00000000.sdmp, rundll32.exe, 00000008.00000002.1973694444.0000000002ED1000.00000004.00000020.00020000.00000000.sdmp | String found in binary or memory: URLhttp://www.facebook.com/ equals www.facebook.com (Facebook) |
Source: rundll32.exe, 00000004.00000003.1978441881.0000000000C7F000.00000004.00000020.00020000.00000000.sdmp | String found in binary or memory: URLhttp://www.twitter.com/ equals www.twitter.com (Twitter) |
Source: rundll32.exe, 00000004.00000003.1979816164.0000000000C90000.00000004.00000020.00020000.00000000.sdmp, rundll32.exe, 00000004.00000003.1978441881.0000000000C7F000.00000004.00000020.00020000.00000000.sdmp, rundll32.exe, 00000004.00000002.2249462772.0000000000C91000.00000004.00000020.00020000.00000000.sdmp | String found in binary or memory: URLhttp://www.youtube.com/ equals www.youtube.com (Youtube) |
Source: rundll32.exe, 00000004.00000002.2249096373.0000000000BD0000.00000004.00000020.00020000.00000000.sdmp, rundll32.exe, 00000008.00000002.1973694444.0000000002ED1000.00000004.00000020.00020000.00000000.sdmp | String found in binary or memory: http://www.facebook.com/ equals www.facebook.com (Facebook) |
Source: rundll32.exe, 00000004.00000003.1978441881.0000000000C7F000.00000004.00000020.00020000.00000000.sdmp | String found in binary or memory: http://www.twitter.com/ equals www.twitter.com (Twitter) |
Source: rundll32.exe, 00000004.00000003.1979816164.0000000000C90000.00000004.00000020.00020000.00000000.sdmp, rundll32.exe, 00000004.00000003.1978441881.0000000000C7F000.00000004.00000020.00020000.00000000.sdmp, rundll32.exe, 00000004.00000002.2249462772.0000000000C91000.00000004.00000020.00020000.00000000.sdmp | String found in binary or memory: http://www.youtube.com/ equals www.youtube.com (Youtube) |
Source: SecuriteInfo.com.FileRepMalware.29184.31872.exe, 00000000.00000002.2273016192.0000000002495000.00000004.00000020.00020000.00000000.sdmp | String found in binary or memory: http://dnfex.lofter.com/post/30905118_1c5d041cf |
Source: SecuriteInfo.com.FileRepMalware.29184.31872.exe, 00000000.00000003.2271387003.0000000000984000.00000004.00000020.00020000.00000000.sdmp, SecuriteInfo.com.FileRepMalware.29184.31872.exe, 00000000.00000002.2272720309.0000000000984000.00000004.00000020.00020000.00000000.sdmp | String found in binary or memory: http://dnfex.lofter.com/post/30905118_1c5d041cfU |
Source: rundll32.exe, 00000008.00000002.1973694444.0000000002ED1000.00000004.00000020.00020000.00000000.sdmp | String found in binary or memory: http://www.amazon.com/ |
Source: SecuriteInfo.com.FileRepMalware.29184.31872.exe, 00000000.00000002.2271924208.00000000006A4000.00000040.00000001.01000000.00000003.sdmp | String found in binary or memory: http://www.baidu.com |
Source: SecuriteInfo.com.FileRepMalware.29184.31872.exe, 00000000.00000003.2271387003.0000000000984000.00000004.00000020.00020000.00000000.sdmp, SecuriteInfo.com.FileRepMalware.29184.31872.exe, 00000000.00000002.2272720309.0000000000984000.00000004.00000020.00020000.00000000.sdmp | String found in binary or memory: http://www.baidu.com/ |
Source: SecuriteInfo.com.FileRepMalware.29184.31872.exe, 00000000.00000003.2271387003.0000000000984000.00000004.00000020.00020000.00000000.sdmp, SecuriteInfo.com.FileRepMalware.29184.31872.exe, 00000000.00000002.2272720309.0000000000984000.00000004.00000020.00020000.00000000.sdmp | String found in binary or memory: http://www.baidu.com/G |
Source: SecuriteInfo.com.FileRepMalware.29184.31872.exe, 00000000.00000002.2271924208.00000000006A4000.00000040.00000001.01000000.00000003.sdmp | String found in binary or memory: http://www.baidu.comtest |
Source: rundll32.exe, 00000004.00000003.1978441881.0000000000C7F000.00000004.00000020.00020000.00000000.sdmp | String found in binary or memory: http://www.google.com/ |
Source: rundll32.exe, 00000008.00000002.1973694444.0000000002ED1000.00000004.00000020.00020000.00000000.sdmp | String found in binary or memory: http://www.live.com/ |
Source: rundll32.exe, 00000008.00000002.1973694444.0000000002ED1000.00000004.00000020.00020000.00000000.sdmp | String found in binary or memory: http://www.nytimes.com/ |
Source: rundll32.exe, 00000008.00000002.1973694444.0000000002ED1000.00000004.00000020.00020000.00000000.sdmp | String found in binary or memory: http://www.reddit.com/ |
Source: rundll32.exe, 00000004.00000003.1978441881.0000000000C7F000.00000004.00000020.00020000.00000000.sdmp | String found in binary or memory: http://www.twitter.com/ |
Source: rundll32.exe, 00000008.00000002.1973694444.0000000002EDB000.00000004.00000020.00020000.00000000.sdmp | String found in binary or memory: http://www.wikipedia.com/ |
Source: rundll32.exe, 00000008.00000002.1973694444.0000000002ED1000.00000004.00000020.00020000.00000000.sdmp | String found in binary or memory: http://www.youtube.com/ |
Source: SecuriteInfo.com.FileRepMalware.29184.31872.exe, 00000000.00000003.2271387003.00000000009B4000.00000004.00000020.00020000.00000000.sdmp, SecuriteInfo.com.FileRepMalware.29184.31872.exe, 00000000.00000003.1922772979.00000000009F6000.00000004.00000020.00020000.00000000.sdmp, SecuriteInfo.com.FileRepMalware.29184.31872.exe, 00000000.00000002.2272720309.00000000009B4000.00000004.00000020.00020000.00000000.sdmp | String found in binary or memory: https://lofter.lf127. |
Source: SecuriteInfo.com.FileRepMalware.29184.31872.exe, 00000000.00000003.2271387003.00000000009B4000.00000004.00000020.00020000.00000000.sdmp, SecuriteInfo.com.FileRepMalware.29184.31872.exe, 00000000.00000003.1922772979.00000000009F6000.00000004.00000020.00020000.00000000.sdmp, SecuriteInfo.com.FileRepMalware.29184.31872.exe, 00000000.00000002.2272720309.00000000009B4000.00000004.00000020.00020000.00000000.sdmp | String found in binary or memory: https://lofter.lf127.n |
Source: SecuriteInfo.com.FileRepMalware.29184.31872.exe, 00000000.00000002.2272720309.00000000009B4000.00000004.00000020.00020000.00000000.sdmp | String found in binary or memory: https://lofter.lf127.net/1 |
Source: SecuriteInfo.com.FileRepMalware.29184.31872.exe, 00000000.00000003.2271046263.00000000009FB000.00000004.00000020.00020000.00000000.sdmp, SecuriteInfo.com.FileRepMalware.29184.31872.exe, 00000000.00000002.2272720309.00000000009B0000.00000004.00000020.00020000.00000000.sdmp, SecuriteInfo.com.FileRepMalware.29184.31872.exe, 00000000.00000002.2273135399.00000000026A8000.00000004.00000020.00020000.00000000.sdmp | String found in binary or memory: https://lofter.lf127.net/1667220634500/core-js-stable.3.6.5.mini.js |
Source: SecuriteInfo.com.FileRepMalware.29184.31872.exe, 00000000.00000003.2271046263.00000000009FB000.00000004.00000020.00020000.00000000.sdmp, SecuriteInfo.com.FileRepMalware.29184.31872.exe, 00000000.00000002.2272720309.00000000009B0000.00000004.00000020.00020000.00000000.sdmp, SecuriteInfo.com.FileRepMalware.29184.31872.exe, 00000000.00000002.2273135399.00000000026A8000.00000004.00000020.00020000.00000000.sdmp | String found in binary or memory: https://lofter.lf127.net/1671501343058/sha256.min.js |
Source: SecuriteInfo.com.FileRepMalware.29184.31872.exe, 00000000.00000003.2271046263.00000000009FB000.00000004.00000020.00020000.00000000.sdmp, SecuriteInfo.com.FileRepMalware.29184.31872.exe, 00000000.00000002.2272720309.00000000009B0000.00000004.00000020.00020000.00000000.sdmp, SecuriteInfo.com.FileRepMalware.29184.31872.exe, 00000000.00000002.2273135399.00000000026A8000.00000004.00000020.00020000.00000000.sdmp | String found in binary or memory: https://lofter.lf127.net/1689134055346/captcha.js |
Source: SecuriteInfo.com.FileRepMalware.29184.31872.exe, 00000000.00000003.2271046263.00000000009FB000.00000004.00000020.00020000.00000000.sdmp, SecuriteInfo.com.FileRepMalware.29184.31872.exe, 00000000.00000003.1891147884.00000000009B3000.00000004.00000020.00020000.00000000.sdmp, SecuriteInfo.com.FileRepMalware.29184.31872.exe, 00000000.00000002.2272720309.00000000009B0000.00000004.00000020.00020000.00000000.sdmp, SecuriteInfo.com.FileRepMalware.29184.31872.exe, 00000000.00000002.2273135399.00000000026A8000.00000004.00000020.00020000.00000000.sdmp | String found in binary or memory: https://lofter.lf127.net/webpack/lofter-client-account/src/applications/login/pc.361cf238fde1df7564a |
Source: SecuriteInfo.com.FileRepMalware.29184.31872.exe, 00000000.00000003.2271387003.00000000009B4000.00000004.00000020.00020000.00000000.sdmp, SecuriteInfo.com.FileRepMalware.29184.31872.exe, 00000000.00000003.1891147884.00000000009F7000.00000004.00000020.00020000.00000000.sdmp, SecuriteInfo.com.FileRepMalware.29184.31872.exe, 00000000.00000003.1922772979.00000000009F6000.00000004.00000020.00020000.00000000.sdmp, SecuriteInfo.com.FileRepMalware.29184.31872.exe, 00000000.00000003.2271046263.00000000009FB000.00000004.00000020.00020000.00000000.sdmp, SecuriteInfo.com.FileRepMalware.29184.31872.exe, 00000000.00000002.2272720309.00000000009B4000.00000004.00000020.00020000.00000000.sdmp, SecuriteInfo.com.FileRepMalware.29184.31872.exe, 00000000.00000002.2273135399.00000000026A8000.00000004.00000020.00020000.00000000.sdmp | String found in binary or memory: https://lofter.lf127.net/webpack/lofter-client-account/src/applications/login/pc.c340e0032e06ca157c9 |
Source: SecuriteInfo.com.FileRepMalware.29184.31872.exe, 00000000.00000003.2271046263.00000000009FB000.00000004.00000020.00020000.00000000.sdmp, SecuriteInfo.com.FileRepMalware.29184.31872.exe, 00000000.00000002.2272720309.00000000009B0000.00000004.00000020.00020000.00000000.sdmp, SecuriteInfo.com.FileRepMalware.29184.31872.exe, 00000000.00000002.2273135399.00000000026A8000.00000004.00000020.00020000.00000000.sdmp | String found in binary or memory: https://lofter.lf127.net/webpack/lofter-dll/dll_606a63b015f6fa133c2a.js |
Source: rundll32.exe, 00000004.00000002.2250655736.00000000076E5000.00000004.00000020.00020000.00000000.sdmp | String found in binary or memory: https://login.live.com/oauth20_authorize.srf?client_id=00000000480728C5&scope=service::ssl.live.com: |
Source: rundll32.exe, 00000004.00000002.2250655736.00000000076E5000.00000004.00000020.00020000.00000000.sdmp | String found in binary or memory: https://login.live.com/oauth20_desktop.srf&lw=1&fl=wld2 |
Source: rundll32.exe, 00000004.00000003.1979816164.0000000000C97000.00000004.00000020.00020000.00000000.sdmp, rundll32.exe, 00000004.00000002.2249462772.0000000000C97000.00000004.00000020.00020000.00000000.sdmp, rundll32.exe, 00000004.00000003.1978441881.0000000000C97000.00000004.00000020.00020000.00000000.sdmp | String found in binary or memory: https://login.live.com/oauth20_desktop.srf?lc=1033?4 |
Source: rundll32.exe, 00000004.00000003.1979816164.0000000000C97000.00000004.00000020.00020000.00000000.sdmp, rundll32.exe, 00000004.00000002.2249462772.0000000000C97000.00000004.00000020.00020000.00000000.sdmp, rundll32.exe, 00000004.00000003.1978441881.0000000000C97000.00000004.00000020.00020000.00000000.sdmp | String found in binary or memory: https://login.live.com/oauth20_desktop.srf?lc=1033h#Rk |
Source: rundll32.exe, 00000004.00000002.2249375292.0000000000C7F000.00000004.00000020.00020000.00000000.sdmp, rundll32.exe, 00000004.00000003.1978441881.0000000000C7F000.00000004.00000020.00020000.00000000.sdmp, rundll32.exe, 00000004.00000003.1979479317.0000000000C7F000.00000004.00000020.00020000.00000000.sdmp | String found in binary or memory: https://login.live.com/oauth20_desktop.srfG |
Source: rundll32.exe, 00000004.00000003.1979258413.00000000076E5000.00000004.00000020.00020000.00000000.sdmp, rundll32.exe, 00000004.00000002.2250655736.00000000076E5000.00000004.00000020.00020000.00000000.sdmp, rundll32.exe, 00000004.00000002.2250627891.00000000076D2000.00000004.00000020.00020000.00000000.sdmp, rundll32.exe, 00000004.00000003.1979258413.00000000076D1000.00000004.00000020.00020000.00000000.sdmp | String found in binary or memory: https://login.live.com/oauth20_logout.srf?client_id=00000000480728C5&redirect_uri=https://login.live |
Source: SecuriteInfo.com.FileRepMalware.29184.31872.exe, 00000000.00000003.2271387003.00000000009B4000.00000004.00000020.00020000.00000000.sdmp, SecuriteInfo.com.FileRepMalware.29184.31872.exe, 00000000.00000003.1891147884.00000000009F7000.00000004.00000020.00020000.00000000.sdmp, SecuriteInfo.com.FileRepMalware.29184.31872.exe, 00000000.00000003.1922772979.00000000009F6000.00000004.00000020.00020000.00000000.sdmp, SecuriteInfo.com.FileRepMalware.29184.31872.exe, 00000000.00000003.2271046263.00000000009FB000.00000004.00000020.00020000.00000000.sdmp, SecuriteInfo.com.FileRepMalware.29184.31872.exe, 00000000.00000002.2272720309.00000000009B4000.00000004.00000020.00020000.00000000.sdmp, SecuriteInfo.com.FileRepMalware.29184.31872.exe, 00000000.00000002.2273135399.00000000026A8000.00000004.00000020.00020000.00000000.sdmp | String found in binary or memory: https://s6.music.126.net/puzzle/puzzle |
Source: SecuriteInfo.com.FileRepMalware.29184.31872.exe, 00000000.00000002.2273016192.0000000002495000.00000004.00000020.00020000.00000000.sdmp | String found in binary or memory: https://shop366821780.taobao.com |
Source: SecuriteInfo.com.FileRepMalware.29184.31872.exe, 00000000.00000003.2271046263.00000000009FB000.00000004.00000020.00020000.00000000.sdmp, SecuriteInfo.com.FileRepMalware.29184.31872.exe, 00000000.00000003.1891147884.00000000009B3000.00000004.00000020.00020000.00000000.sdmp, SecuriteInfo.com.FileRepMalware.29184.31872.exe, 00000000.00000002.2272720309.00000000009B0000.00000004.00000020.00020000.00000000.sdmp, SecuriteInfo.com.FileRepMalware.29184.31872.exe, 00000000.00000002.2273135399.00000000026A8000.00000004.00000020.00020000.00000000.sdmp | String found in binary or memory: https://urswebzj.nosdn.127.net/webzj_cdn101/message.js |
Source: SecuriteInfo.com.FileRepMalware.29184.31872.exe, 00000000.00000003.2271091743.0000000000997000.00000004.00000020.00020000.00000000.sdmp, SecuriteInfo.com.FileRepMalware.29184.31872.exe, 00000000.00000003.1922785209.0000000000997000.00000004.00000020.00020000.00000000.sdmp, SecuriteInfo.com.FileRepMalware.29184.31872.exe, 00000000.00000002.2272720309.0000000000997000.00000004.00000020.00020000.00000000.sdmp | String found in binary or memory: https://www.lofter.com/ |
Source: SecuriteInfo.com.FileRepMalware.29184.31872.exe, 00000000.00000002.2272720309.0000000000971000.00000004.00000020.00020000.00000000.sdmp, SecuriteInfo.com.FileRepMalware.29184.31872.exe, 00000000.00000003.2271387003.0000000000971000.00000004.00000020.00020000.00000000.sdmp | String found in binary or memory: https://www.lofter.com/front/login |
Source: SecuriteInfo.com.FileRepMalware.29184.31872.exe, 00000000.00000002.2272720309.0000000000971000.00000004.00000020.00020000.00000000.sdmp, SecuriteInfo.com.FileRepMalware.29184.31872.exe, 00000000.00000003.2271387003.0000000000971000.00000004.00000020.00020000.00000000.sdmp | String found in binary or memory: https://www.lofter.com/front/loginL |
Source: SecuriteInfo.com.FileRepMalware.29184.31872.exe, 00000000.00000002.2272720309.0000000000971000.00000004.00000020.00020000.00000000.sdmp, SecuriteInfo.com.FileRepMalware.29184.31872.exe, 00000000.00000003.2271387003.0000000000971000.00000004.00000020.00020000.00000000.sdmp | String found in binary or memory: https://www.lofter.com/front/loginV |
Source: C:\Users\user\Desktop\SecuriteInfo.com.FileRepMalware.29184.31872.exe | Code function: 0_2_10007A30 GetPropA,NtdllDefWindowProc_A,CallWindowProcA, | 0_2_10007A30 |
Source: C:\Users\user\Desktop\SecuriteInfo.com.FileRepMalware.29184.31872.exe | Code function: 0_2_1000DA90 GetPropA,NtdllDefWindowProc_A,CallWindowProcA, | 0_2_1000DA90 |
Source: C:\Users\user\Desktop\SecuriteInfo.com.FileRepMalware.29184.31872.exe | Code function: 0_2_1001C800 GetPropA,NtdllDefWindowProc_A,CallWindowProcA, | 0_2_1001C800 |
Source: C:\Users\user\Desktop\SecuriteInfo.com.FileRepMalware.29184.31872.exe | Code function: 0_2_10006096 GetSystemMenu,GetMenuState,SendMessageA,NtdllDefWindowProc_A,IsIconic,IsZoomed,GetWindowRect, | 0_2_10006096 |
Source: C:\Users\user\Desktop\SecuriteInfo.com.FileRepMalware.29184.31872.exe | Code function: 0_2_100098B0 GetPropA,NtdllDefWindowProc_A,KillTimer,IsWindowVisible,IsIconic,SetTimer, | 0_2_100098B0 |
Source: C:\Users\user\Desktop\SecuriteInfo.com.FileRepMalware.29184.31872.exe | Code function: 0_2_100048E0 NtdllDefWindowProc_A, | 0_2_100048E0 |
Source: C:\Users\user\Desktop\SecuriteInfo.com.FileRepMalware.29184.31872.exe | Code function: 0_2_1001D8E0 GetPropA,NtdllDefWindowProc_A,CallWindowProcA,InvalidateRect,CallWindowProcA, | 0_2_1001D8E0 |
Source: C:\Users\user\Desktop\SecuriteInfo.com.FileRepMalware.29184.31872.exe | Code function: 0_2_10005910 EnableWindow,NtdllDefWindowProc_A, | 0_2_10005910 |
Source: C:\Users\user\Desktop\SecuriteInfo.com.FileRepMalware.29184.31872.exe | Code function: 0_2_10005940 GetCursorPos,GetWindowRect,PtInRect,PtInRect,PtInRect,PtInRect,PtInRect,KillTimer,NtdllDefWindowProc_A, | 0_2_10005940 |
Source: C:\Users\user\Desktop\SecuriteInfo.com.FileRepMalware.29184.31872.exe | Code function: 0_2_10006239 SendMessageA,SendMessageA,IsZoomed,SendMessageA,NtdllDefWindowProc_A, | 0_2_10006239 |
Source: C:\Users\user\Desktop\SecuriteInfo.com.FileRepMalware.29184.31872.exe | Code function: 0_2_100062B0 IsWindowEnabled,SendMessageA,NtdllDefWindowProc_A, | 0_2_100062B0 |
Source: C:\Users\user\Desktop\SecuriteInfo.com.FileRepMalware.29184.31872.exe | Code function: 0_2_10012AD0 GetPropA,NtdllDefWindowProc_A,CallWindowProcA, | 0_2_10012AD0 |
Source: C:\Users\user\Desktop\SecuriteInfo.com.FileRepMalware.29184.31872.exe | Code function: 0_2_10008310 GetPropA,NtdllDefWindowProc_A,CallWindowProcA,InvalidateRect,CallWindowProcA, | 0_2_10008310 |
Source: C:\Users\user\Desktop\SecuriteInfo.com.FileRepMalware.29184.31872.exe | Code function: 0_2_1000D330 GetPropA,NtdllDefWindowProc_A,CallWindowProcA, | 0_2_1000D330 |
Source: C:\Users\user\Desktop\SecuriteInfo.com.FileRepMalware.29184.31872.exe | Code function: 0_2_1001D330 GetPropA,NtdllDefWindowProc_A,CallWindowProcA, | 0_2_1001D330 |
Source: C:\Users\user\Desktop\SecuriteInfo.com.FileRepMalware.29184.31872.exe | Code function: 0_2_10009340 GetPropA,NtdllDefWindowProc_A,CallWindowProcA,InvalidateRect,CallWindowProcA,CallWindowProcA,GetCursorPos,GetWindowRect,PtInRect,CallWindowProcA, | 0_2_10009340 |
Source: C:\Users\user\Desktop\SecuriteInfo.com.FileRepMalware.29184.31872.exe | Code function: 0_2_10006350 GetPropA,NtdllDefWindowProc_A,CallWindowProcA, | 0_2_10006350 |
Source: C:\Users\user\Desktop\SecuriteInfo.com.FileRepMalware.29184.31872.exe | Code function: 0_2_10021387 NtdllDefWindowProc_A, | 0_2_10021387 |
Source: C:\Users\user\Desktop\SecuriteInfo.com.FileRepMalware.29184.31872.exe | Code function: 0_2_10020B84 NtdllDefWindowProc_A, | 0_2_10020B84 |
Source: C:\Users\user\Desktop\SecuriteInfo.com.FileRepMalware.29184.31872.exe | Code function: 0_2_1000CBC0 GetPropA,NtdllDefWindowProc_A, | 0_2_1000CBC0 |
Source: C:\Users\user\Desktop\SecuriteInfo.com.FileRepMalware.29184.31872.exe | Code function: 0_2_10004BD0 NtdllDefWindowProc_A, | 0_2_10004BD0 |
Source: C:\Users\user\Desktop\SecuriteInfo.com.FileRepMalware.29184.31872.exe | Code function: 0_2_1000C3F0 GetPropA,NtdllDefWindowProc_A,CallWindowProcA,InvalidateRect,CallWindowProcA,CallWindowProcA,GetCursorPos,GetWindowRect,PtInRect,CallWindowProcA, | 0_2_1000C3F0 |
Source: C:\Users\user\Desktop\SecuriteInfo.com.FileRepMalware.29184.31872.exe | Code function: 0_2_10012BF0 GetPropA,NtdllDefWindowProc_A,CallWindowProcA, | 0_2_10012BF0 |
Source: C:\Users\user\Desktop\SecuriteInfo.com.FileRepMalware.29184.31872.exe | Code function: 0_2_1000E454 NtdllDefWindowProc_A, | 0_2_1000E454 |
Source: C:\Users\user\Desktop\SecuriteInfo.com.FileRepMalware.29184.31872.exe | Code function: 0_2_10008CB0 GetPropA,NtdllDefWindowProc_A, | 0_2_10008CB0 |
Source: C:\Users\user\Desktop\SecuriteInfo.com.FileRepMalware.29184.31872.exe | Code function: 0_2_100214C4 NtdllDefWindowProc_A, | 0_2_100214C4 |
Source: C:\Users\user\Desktop\SecuriteInfo.com.FileRepMalware.29184.31872.exe | Code function: 0_2_10004510 NtdllDefWindowProc_A, | 0_2_10004510 |
Source: C:\Users\user\Desktop\SecuriteInfo.com.FileRepMalware.29184.31872.exe | Code function: 0_2_10008D40 GetPropA,RemovePropA,CallWindowProcA,NtdllDefWindowProc_A, | 0_2_10008D40 |
Source: C:\Users\user\Desktop\SecuriteInfo.com.FileRepMalware.29184.31872.exe | Code function: 0_2_1000FD50 GetPropA,NtdllDefWindowProc_A,CallWindowProcA, | 0_2_1000FD50 |
Source: C:\Users\user\Desktop\SecuriteInfo.com.FileRepMalware.29184.31872.exe | Code function: 0_2_1001FD50 GetPropA,GetPropA,NtdllDefWindowProc_A,FindWindowExA,GetPropA,GetWindowRect, | 0_2_1001FD50 |
Source: C:\Users\user\Desktop\SecuriteInfo.com.FileRepMalware.29184.31872.exe | Code function: 0_2_10006574 NtdllDefWindowProc_A, | 0_2_10006574 |
Source: C:\Users\user\Desktop\SecuriteInfo.com.FileRepMalware.29184.31872.exe | Code function: 0_2_10013DA0 GetPropA,NtdllDefWindowProc_A,CallWindowProcA, | 0_2_10013DA0 |
Source: C:\Users\user\Desktop\SecuriteInfo.com.FileRepMalware.29184.31872.exe | Code function: 0_2_10011630 GetPropA,NtdllDefWindowProc_A,CallWindowProcA,CallWindowProcA, | 0_2_10011630 |
Source: C:\Users\user\Desktop\SecuriteInfo.com.FileRepMalware.29184.31872.exe | Code function: 0_2_10002E40 NtdllDefWindowProc_A, | 0_2_10002E40 |
Source: C:\Users\user\Desktop\SecuriteInfo.com.FileRepMalware.29184.31872.exe | Code function: 0_2_1001FEA0 GetPropA,NtdllDefWindowProc_A,InvalidateRect,CallWindowProcA, | 0_2_1001FEA0 |
Source: C:\Users\user\Desktop\SecuriteInfo.com.FileRepMalware.29184.31872.exe | Code function: 0_2_10014EB4 NtdllDefWindowProc_A, | 0_2_10014EB4 |
Source: C:\Users\user\Desktop\SecuriteInfo.com.FileRepMalware.29184.31872.exe | Code function: 0_2_10008710 GetPropA,NtdllDefWindowProc_A,CallWindowProcA,GetParent, | 0_2_10008710 |
Source: C:\Users\user\Desktop\SecuriteInfo.com.FileRepMalware.29184.31872.exe | Code function: 0_2_1000F750 GetPropA,NtdllDefWindowProc_A,CallWindowProcA, | 0_2_1000F750 |
Source: C:\Users\user\Desktop\SecuriteInfo.com.FileRepMalware.29184.31872.exe | Code function: 0_2_10014790 GetPropA,NtdllDefWindowProc_A,CallWindowProcA, | 0_2_10014790 |
Source: C:\Users\user\Desktop\SecuriteInfo.com.FileRepMalware.29184.31872.exe | Code function: 0_2_1001E7F0 GetPropA,NtdllDefWindowProc_A,CallWindowProcA, | 0_2_1001E7F0 |
Source: unknown | Process created: C:\Users\user\Desktop\SecuriteInfo.com.FileRepMalware.29184.31872.exe "C:\Users\user\Desktop\SecuriteInfo.com.FileRepMalware.29184.31872.exe" | |
Source: C:\Users\user\Desktop\SecuriteInfo.com.FileRepMalware.29184.31872.exe | Process created: C:\Windows\SysWOW64\rundll32.exe RunDll32.exe InetCpl.cpl,ClearMyTracksByProcess 255 | |
Source: C:\Windows\SysWOW64\rundll32.exe | Process created: C:\Program Files (x86)\Internet Explorer\iexplore.exe "C:\Program Files (x86)\Internet Explorer\iexplore.exe" -ResetDestinationList | |
Source: C:\Windows\SysWOW64\rundll32.exe | Process created: C:\Windows\SysWOW64\rundll32.exe C:\Windows\system32\rundll32.exe C:\Windows\system32\inetcpl.cpl,ClearMyTracksByProcess Flags:255 WinX:0 WinY:0 IEFrame:00000000 | |
Source: C:\Users\user\Desktop\SecuriteInfo.com.FileRepMalware.29184.31872.exe | Process created: C:\Windows\SysWOW64\rundll32.exe RunDll32.exe InetCpl.cpl,ClearMyTracksByProcess 255 | Jump to behavior |
Source: C:\Windows\SysWOW64\rundll32.exe | Process created: C:\Program Files (x86)\Internet Explorer\iexplore.exe "C:\Program Files (x86)\Internet Explorer\iexplore.exe" -ResetDestinationList | Jump to behavior |
Source: C:\Windows\SysWOW64\rundll32.exe | Process created: C:\Windows\SysWOW64\rundll32.exe C:\Windows\system32\rundll32.exe C:\Windows\system32\inetcpl.cpl,ClearMyTracksByProcess Flags:255 WinX:0 WinY:0 IEFrame:00000000 | Jump to behavior |
Source: C:\Users\user\Desktop\SecuriteInfo.com.FileRepMalware.29184.31872.exe | Section loaded: apphelp.dll | Jump to behavior |
Source: C:\Users\user\Desktop\SecuriteInfo.com.FileRepMalware.29184.31872.exe | Section loaded: avifil32.dll | Jump to behavior |
Source: C:\Users\user\Desktop\SecuriteInfo.com.FileRepMalware.29184.31872.exe | Section loaded: msvfw32.dll | Jump to behavior |
Source: C:\Users\user\Desktop\SecuriteInfo.com.FileRepMalware.29184.31872.exe | Section loaded: rasapi32.dll | Jump to behavior |
Source: C:\Users\user\Desktop\SecuriteInfo.com.FileRepMalware.29184.31872.exe | Section loaded: wininet.dll | Jump to behavior |
Source: C:\Users\user\Desktop\SecuriteInfo.com.FileRepMalware.29184.31872.exe | Section loaded: winmm.dll | Jump to behavior |
Source: C:\Users\user\Desktop\SecuriteInfo.com.FileRepMalware.29184.31872.exe | Section loaded: winmm.dll | Jump to behavior |
Source: C:\Users\user\Desktop\SecuriteInfo.com.FileRepMalware.29184.31872.exe | Section loaded: rasman.dll | Jump to behavior |
Source: C:\Users\user\Desktop\SecuriteInfo.com.FileRepMalware.29184.31872.exe | Section loaded: msacm32.dll | Jump to behavior |
Source: C:\Users\user\Desktop\SecuriteInfo.com.FileRepMalware.29184.31872.exe | Section loaded: winmmbase.dll | Jump to behavior |
Source: C:\Users\user\Desktop\SecuriteInfo.com.FileRepMalware.29184.31872.exe | Section loaded: winmmbase.dll | Jump to behavior |
Source: C:\Users\user\Desktop\SecuriteInfo.com.FileRepMalware.29184.31872.exe | Section loaded: uxtheme.dll | Jump to behavior |
Source: C:\Users\user\Desktop\SecuriteInfo.com.FileRepMalware.29184.31872.exe | Section loaded: kernel.appcore.dll | Jump to behavior |
Source: C:\Users\user\Desktop\SecuriteInfo.com.FileRepMalware.29184.31872.exe | Section loaded: msimg32.dll | Jump to behavior |
Source: C:\Users\user\Desktop\SecuriteInfo.com.FileRepMalware.29184.31872.exe | Section loaded: dciman32.dll | Jump to behavior |
Source: C:\Users\user\Desktop\SecuriteInfo.com.FileRepMalware.29184.31872.exe | Section loaded: textshaping.dll | Jump to behavior |
Source: C:\Users\user\Desktop\SecuriteInfo.com.FileRepMalware.29184.31872.exe | Section loaded: iertutil.dll | Jump to behavior |
Source: C:\Users\user\Desktop\SecuriteInfo.com.FileRepMalware.29184.31872.exe | Section loaded: sspicli.dll | Jump to behavior |
Source: C:\Users\user\Desktop\SecuriteInfo.com.FileRepMalware.29184.31872.exe | Section loaded: windows.storage.dll | Jump to behavior |
Source: C:\Users\user\Desktop\SecuriteInfo.com.FileRepMalware.29184.31872.exe | Section loaded: wldp.dll | Jump to behavior |
Source: C:\Users\user\Desktop\SecuriteInfo.com.FileRepMalware.29184.31872.exe | Section loaded: profapi.dll | Jump to behavior |
Source: C:\Users\user\Desktop\SecuriteInfo.com.FileRepMalware.29184.31872.exe | Section loaded: ondemandconnroutehelper.dll | Jump to behavior |
Source: C:\Users\user\Desktop\SecuriteInfo.com.FileRepMalware.29184.31872.exe | Section loaded: winhttp.dll | Jump to behavior |
Source: C:\Users\user\Desktop\SecuriteInfo.com.FileRepMalware.29184.31872.exe | Section loaded: iphlpapi.dll | Jump to behavior |
Source: C:\Users\user\Desktop\SecuriteInfo.com.FileRepMalware.29184.31872.exe | Section loaded: mswsock.dll | Jump to behavior |
Source: C:\Users\user\Desktop\SecuriteInfo.com.FileRepMalware.29184.31872.exe | Section loaded: winnsi.dll | Jump to behavior |
Source: C:\Users\user\Desktop\SecuriteInfo.com.FileRepMalware.29184.31872.exe | Section loaded: urlmon.dll | Jump to behavior |
Source: C:\Users\user\Desktop\SecuriteInfo.com.FileRepMalware.29184.31872.exe | Section loaded: srvcli.dll | Jump to behavior |
Source: C:\Users\user\Desktop\SecuriteInfo.com.FileRepMalware.29184.31872.exe | Section loaded: netutils.dll | Jump to behavior |
Source: C:\Users\user\Desktop\SecuriteInfo.com.FileRepMalware.29184.31872.exe | Section loaded: dnsapi.dll | Jump to behavior |
Source: C:\Users\user\Desktop\SecuriteInfo.com.FileRepMalware.29184.31872.exe | Section loaded: rasadhlp.dll | Jump to behavior |
Source: C:\Users\user\Desktop\SecuriteInfo.com.FileRepMalware.29184.31872.exe | Section loaded: fwpuclnt.dll | Jump to behavior |
Source: C:\Users\user\Desktop\SecuriteInfo.com.FileRepMalware.29184.31872.exe | Section loaded: dpapi.dll | Jump to behavior |
Source: C:\Users\user\Desktop\SecuriteInfo.com.FileRepMalware.29184.31872.exe | Section loaded: cryptbase.dll | Jump to behavior |
Source: C:\Users\user\Desktop\SecuriteInfo.com.FileRepMalware.29184.31872.exe | Section loaded: schannel.dll | Jump to behavior |
Source: C:\Users\user\Desktop\SecuriteInfo.com.FileRepMalware.29184.31872.exe | Section loaded: mskeyprotect.dll | Jump to behavior |
Source: C:\Users\user\Desktop\SecuriteInfo.com.FileRepMalware.29184.31872.exe | Section loaded: ntasn1.dll | Jump to behavior |
Source: C:\Users\user\Desktop\SecuriteInfo.com.FileRepMalware.29184.31872.exe | Section loaded: msasn1.dll | Jump to behavior |
Source: C:\Users\user\Desktop\SecuriteInfo.com.FileRepMalware.29184.31872.exe | Section loaded: cryptsp.dll | Jump to behavior |
Source: C:\Users\user\Desktop\SecuriteInfo.com.FileRepMalware.29184.31872.exe | Section loaded: rsaenh.dll | Jump to behavior |
Source: C:\Users\user\Desktop\SecuriteInfo.com.FileRepMalware.29184.31872.exe | Section loaded: gpapi.dll | Jump to behavior |
Source: C:\Users\user\Desktop\SecuriteInfo.com.FileRepMalware.29184.31872.exe | Section loaded: ncrypt.dll | Jump to behavior |
Source: C:\Users\user\Desktop\SecuriteInfo.com.FileRepMalware.29184.31872.exe | Section loaded: ncryptsslp.dll | Jump to behavior |
Source: C:\Users\user\Desktop\SecuriteInfo.com.FileRepMalware.29184.31872.exe | Section loaded: textinputframework.dll | Jump to behavior |
Source: C:\Users\user\Desktop\SecuriteInfo.com.FileRepMalware.29184.31872.exe | Section loaded: coreuicomponents.dll | Jump to behavior |
Source: C:\Users\user\Desktop\SecuriteInfo.com.FileRepMalware.29184.31872.exe | Section loaded: coremessaging.dll | Jump to behavior |
Source: C:\Users\user\Desktop\SecuriteInfo.com.FileRepMalware.29184.31872.exe | Section loaded: ntmarta.dll | Jump to behavior |
Source: C:\Users\user\Desktop\SecuriteInfo.com.FileRepMalware.29184.31872.exe | Section loaded: wintypes.dll | Jump to behavior |
Source: C:\Users\user\Desktop\SecuriteInfo.com.FileRepMalware.29184.31872.exe | Section loaded: wintypes.dll | Jump to behavior |
Source: C:\Users\user\Desktop\SecuriteInfo.com.FileRepMalware.29184.31872.exe | Section loaded: wintypes.dll | Jump to behavior |
Source: C:\Users\user\Desktop\SecuriteInfo.com.FileRepMalware.29184.31872.exe | Code function: 0_2_10021800 IsZoomed,SendMessageA,IsIconic,SendMessageA,SendMessageA,GetSystemMenu,GetMenuState,SendMessageA,SendMessageA,KillTimer,GetMenuItemID,SendMessageA,CallWindowProcA, | 0_2_10021800 |
Source: C:\Users\user\Desktop\SecuriteInfo.com.FileRepMalware.29184.31872.exe | Code function: 0_2_10023070 IsWindowVisible,IsRectEmpty,IsRectEmpty,IsIconic,IsRectEmpty,IsRectEmpty,IsZoomed,IsRectEmpty,GetSystemMenu,GetMenuState,IsRectEmpty,SetBkMode,IsRectEmpty,IsRectEmpty,IsRectEmpty,IsIconic,IsRectEmpty,IsZoomed,IsRectEmpty, | 0_2_10023070 |
Source: C:\Users\user\Desktop\SecuriteInfo.com.FileRepMalware.29184.31872.exe | Code function: 0_2_10023070 IsWindowVisible,IsRectEmpty,IsRectEmpty,IsIconic,IsRectEmpty,IsRectEmpty,IsZoomed,IsRectEmpty,GetSystemMenu,GetMenuState,IsRectEmpty,SetBkMode,IsRectEmpty,IsRectEmpty,IsRectEmpty,IsIconic,IsRectEmpty,IsZoomed,IsRectEmpty, | 0_2_10023070 |
Source: C:\Users\user\Desktop\SecuriteInfo.com.FileRepMalware.29184.31872.exe | Code function: 0_2_10006096 GetSystemMenu,GetMenuState,SendMessageA,NtdllDefWindowProc_A,IsIconic,IsZoomed,GetWindowRect, | 0_2_10006096 |
Source: C:\Users\user\Desktop\SecuriteInfo.com.FileRepMalware.29184.31872.exe | Code function: 0_2_100098B0 GetPropA,NtdllDefWindowProc_A,KillTimer,IsWindowVisible,IsIconic,SetTimer, | 0_2_100098B0 |
Source: C:\Users\user\Desktop\SecuriteInfo.com.FileRepMalware.29184.31872.exe | Code function: 0_2_10004E30 IsWindowVisible,GetWindowRect,CreateCompatibleDC,SelectObject,SelectObject,SetBkMode,SelectObject,SetTextColor,DrawIconEx,GetWindowTextA,DrawTextA,IsRectEmpty,IsIconic,IsRectEmpty,IsRectEmpty,IsZoomed,IsRectEmpty,GetSystemMenu,GetMenuState,IsRectEmpty,SetBkMode,SelectObject,DeleteDC,CreateCompatibleDC,SelectObject,DeleteObject, | 0_2_10004E30 |
Source: C:\Users\user\Desktop\SecuriteInfo.com.FileRepMalware.29184.31872.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\SecuriteInfo.com.FileRepMalware.29184.31872.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\SecuriteInfo.com.FileRepMalware.29184.31872.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\SecuriteInfo.com.FileRepMalware.29184.31872.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\SecuriteInfo.com.FileRepMalware.29184.31872.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\rundll32.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\rundll32.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\rundll32.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\rundll32.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\rundll32.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\rundll32.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\rundll32.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\rundll32.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\rundll32.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\rundll32.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\rundll32.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\rundll32.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\rundll32.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\rundll32.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\rundll32.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\rundll32.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\rundll32.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\rundll32.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\rundll32.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\rundll32.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\rundll32.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\rundll32.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\rundll32.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\rundll32.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\rundll32.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\rundll32.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\rundll32.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\rundll32.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\rundll32.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\rundll32.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\rundll32.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\rundll32.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\rundll32.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\rundll32.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\rundll32.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\rundll32.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\rundll32.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\rundll32.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\rundll32.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\rundll32.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\rundll32.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\rundll32.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\rundll32.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\rundll32.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\rundll32.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\rundll32.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\rundll32.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\rundll32.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\rundll32.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\rundll32.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\rundll32.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\rundll32.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\rundll32.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\rundll32.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\rundll32.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\rundll32.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: rundll32.exe, 00000008.00000002.1973694444.0000000002EDB000.00000004.00000020.00020000.00000000.sdmp | Binary or memory string: Hyper-V RAW%SystemRoot%\system32\mswsock.dllW |
Source: SecuriteInfo.com.FileRepMalware.29184.31872.exe, 00000000.00000002.2272469279.000000000091E000.00000004.00000020.00020000.00000000.sdmp | Binary or memory string: Hyper-V RAW8 |
Source: SecuriteInfo.com.FileRepMalware.29184.31872.exe, 00000000.00000003.2271091743.0000000000997000.00000004.00000020.00020000.00000000.sdmp, SecuriteInfo.com.FileRepMalware.29184.31872.exe, 00000000.00000003.1922785209.0000000000997000.00000004.00000020.00020000.00000000.sdmp, SecuriteInfo.com.FileRepMalware.29184.31872.exe, 00000000.00000002.2272720309.0000000000997000.00000004.00000020.00020000.00000000.sdmp | Binary or memory string: Hyper-V RAW |
Source: rundll32.exe, 00000004.00000003.1979816164.0000000000CA7000.00000004.00000020.00020000.00000000.sdmp, rundll32.exe, 00000004.00000003.1978441881.0000000000CA7000.00000004.00000020.00020000.00000000.sdmp | Binary or memory string: Hyper-V RAW%SystemRoot%\system32\mswsock.dllvvC8 |