Source: unknown | TCP traffic detected without corresponding DNS query: 154.91.82.142 |
Source: unknown | TCP traffic detected without corresponding DNS query: 154.91.82.142 |
Source: unknown | TCP traffic detected without corresponding DNS query: 154.91.82.142 |
Source: unknown | TCP traffic detected without corresponding DNS query: 154.91.82.142 |
Source: unknown | TCP traffic detected without corresponding DNS query: 154.91.82.142 |
Source: unknown | UDP traffic detected without corresponding DNS query: 1.1.1.1 |
Source: unknown | TCP traffic detected without corresponding DNS query: 154.91.82.142 |
Source: unknown | TCP traffic detected without corresponding DNS query: 154.91.82.142 |
Source: unknown | TCP traffic detected without corresponding DNS query: 154.91.82.142 |
Source: unknown | TCP traffic detected without corresponding DNS query: 154.91.82.142 |
Source: unknown | TCP traffic detected without corresponding DNS query: 154.91.82.142 |
Source: unknown | UDP traffic detected without corresponding DNS query: 1.1.1.1 |
Source: unknown | UDP traffic detected without corresponding DNS query: 1.1.1.1 |
Source: unknown | TCP traffic detected without corresponding DNS query: 154.91.82.142 |
Source: unknown | TCP traffic detected without corresponding DNS query: 154.91.82.142 |
Source: unknown | TCP traffic detected without corresponding DNS query: 154.91.82.142 |
Source: unknown | TCP traffic detected without corresponding DNS query: 154.91.82.142 |
Source: C:\Users\user\Desktop\fanyiyouda.exe | Section loaded: msimg32.dll |
Source: C:\Users\user\Desktop\fanyiyouda.exe | Section loaded: uxtheme.dll |
Source: C:\Users\user\Desktop\fanyiyouda.exe | Section loaded: oledlg.dll |
Source: C:\Users\user\Desktop\fanyiyouda.exe | Section loaded: oleacc.dll |
Source: C:\Users\user\Desktop\fanyiyouda.exe | Section loaded: winmm.dll |
Source: C:\Users\user\Desktop\fanyiyouda.exe | Section loaded: winhttp.dll |
Source: C:\Users\user\Desktop\fanyiyouda.exe | Section loaded: ondemandconnroutehelper.dll |
Source: C:\Users\user\Desktop\fanyiyouda.exe | Section loaded: webio.dll |
Source: C:\Users\user\Desktop\fanyiyouda.exe | Section loaded: mswsock.dll |
Source: C:\Users\user\Desktop\fanyiyouda.exe | Section loaded: iphlpapi.dll |
Source: C:\Users\user\Desktop\fanyiyouda.exe | Section loaded: winnsi.dll |
Source: C:\Users\user\Desktop\fanyiyouda.exe | Section loaded: sspicli.dll |
Source: C:\Users\user\Desktop\fanyiyouda.exe | Section loaded: dnsapi.dll |
Source: C:\Users\user\Desktop\fanyiyouda.exe | Section loaded: rasadhlp.dll |
Source: C:\Users\user\Desktop\fanyiyouda.exe | Section loaded: fwpuclnt.dll |
Source: C:\Users\user\Desktop\fanyiyouda.exe | Section loaded: dinput8.dll |
Source: C:\Users\user\Desktop\fanyiyouda.exe | Section loaded: inputhost.dll |
Source: C:\Users\user\Desktop\fanyiyouda.exe | Section loaded: coremessaging.dll |
Source: C:\Users\user\Desktop\fanyiyouda.exe | Section loaded: propsys.dll |
Source: C:\Users\user\Desktop\fanyiyouda.exe | Section loaded: wintypes.dll |
Source: C:\Users\user\Desktop\fanyiyouda.exe | Section loaded: coreuicomponents.dll |
Source: C:\Users\user\Desktop\fanyiyouda.exe | Section loaded: ntmarta.dll |
Source: C:\Users\user\Desktop\fanyiyouda.exe | Section loaded: coremessaging.dll |
Source: C:\Users\user\Desktop\fanyiyouda.exe | Section loaded: kernel.appcore.dll |
Source: C:\Users\user\Desktop\fanyiyouda.exe | Section loaded: kernel.appcore.dll |
Source: C:\Users\user\Desktop\fanyiyouda.exe | Section loaded: napinsp.dll |
Source: C:\Users\user\Desktop\fanyiyouda.exe | Section loaded: pnrpnsp.dll |
Source: C:\Users\user\Desktop\fanyiyouda.exe | Section loaded: wshbth.dll |
Source: C:\Users\user\Desktop\fanyiyouda.exe | Section loaded: nlaapi.dll |
Source: C:\Users\user\Desktop\fanyiyouda.exe | Section loaded: winrnr.dll |
Source: C:\Users\user\Desktop\fanyiyouda.exe | Section loaded: ondemandconnroutehelper.dll |
Source: C:\Users\user\Desktop\fanyiyouda.exe | Section loaded: schannel.dll |
Source: C:\Users\user\Desktop\fanyiyouda.exe | Section loaded: mskeyprotect.dll |
Source: C:\Users\user\Desktop\fanyiyouda.exe | Section loaded: ntasn1.dll |
Source: C:\Users\user\Desktop\fanyiyouda.exe | Section loaded: ncrypt.dll |
Source: C:\Users\user\Desktop\fanyiyouda.exe | Section loaded: ncryptsslp.dll |
Source: C:\Users\user\Desktop\fanyiyouda.exe | Section loaded: msasn1.dll |
Source: C:\Users\user\Desktop\fanyiyouda.exe | Section loaded: cryptsp.dll |
Source: C:\Users\user\Desktop\fanyiyouda.exe | Section loaded: rsaenh.dll |
Source: C:\Users\user\Desktop\fanyiyouda.exe | Section loaded: cryptbase.dll |
Source: C:\Users\user\Desktop\fanyiyouda.exe | Section loaded: gpapi.dll |
Source: C:\Users\user\Desktop\fanyiyouda.exe | Section loaded: dpapi.dll |
Source: C:\Users\user\Desktop\fanyiyouda.exe | Section loaded: ondemandconnroutehelper.dll |
Source: C:\Users\user\Desktop\fanyiyouda.exe | Section loaded: msimg32.dll |
Source: C:\Users\user\Desktop\fanyiyouda.exe | Section loaded: uxtheme.dll |
Source: C:\Users\user\Desktop\fanyiyouda.exe | Section loaded: oledlg.dll |
Source: C:\Users\user\Desktop\fanyiyouda.exe | Section loaded: oleacc.dll |
Source: C:\Users\user\Desktop\fanyiyouda.exe | Section loaded: winmm.dll |
Source: C:\Users\user\Desktop\fanyiyouda.exe | Section loaded: winhttp.dll |
Source: C:\Users\user\Desktop\fanyiyouda.exe | Section loaded: ondemandconnroutehelper.dll |
Source: C:\Users\user\Desktop\fanyiyouda.exe | Section loaded: webio.dll |
Source: C:\Users\user\Desktop\fanyiyouda.exe | Section loaded: mswsock.dll |
Source: C:\Users\user\Desktop\fanyiyouda.exe | Section loaded: iphlpapi.dll |
Source: C:\Users\user\Desktop\fanyiyouda.exe | Section loaded: winnsi.dll |
Source: C:\Users\user\Desktop\fanyiyouda.exe | Section loaded: sspicli.dll |
Source: C:\Users\user\Desktop\fanyiyouda.exe | Section loaded: dnsapi.dll |
Source: C:\Users\user\Desktop\fanyiyouda.exe | Section loaded: rasadhlp.dll |
Source: C:\Users\user\Desktop\fanyiyouda.exe | Section loaded: fwpuclnt.dll |
Source: C:\Users\user\Desktop\fanyiyouda.exe | Section loaded: dinput8.dll |
Source: C:\Users\user\Desktop\fanyiyouda.exe | Section loaded: inputhost.dll |
Source: C:\Users\user\Desktop\fanyiyouda.exe | Section loaded: coremessaging.dll |
Source: C:\Users\user\Desktop\fanyiyouda.exe | Section loaded: propsys.dll |
Source: C:\Users\user\Desktop\fanyiyouda.exe | Section loaded: wintypes.dll |
Source: C:\Users\user\Desktop\fanyiyouda.exe | Section loaded: coreuicomponents.dll |
Source: C:\Users\user\Desktop\fanyiyouda.exe | Section loaded: ntmarta.dll |
Source: C:\Users\user\Desktop\fanyiyouda.exe | Section loaded: kernel.appcore.dll |
Source: C:\Users\user\Desktop\fanyiyouda.exe | Section loaded: kernel.appcore.dll |
Source: C:\Users\user\Desktop\fanyiyouda.exe | Section loaded: wintypes.dll |
Source: C:\Users\user\Desktop\fanyiyouda.exe | Section loaded: wintypes.dll |
Source: C:\Users\user\Desktop\fanyiyouda.exe | Section loaded: wintypes.dll |
Source: C:\Users\user\Desktop\fanyiyouda.exe | Section loaded: napinsp.dll |
Source: C:\Users\user\Desktop\fanyiyouda.exe | Section loaded: pnrpnsp.dll |
Source: C:\Users\user\Desktop\fanyiyouda.exe | Section loaded: wshbth.dll |
Source: C:\Users\user\Desktop\fanyiyouda.exe | Section loaded: nlaapi.dll |
Source: C:\Users\user\Desktop\fanyiyouda.exe | Section loaded: winrnr.dll |
Source: C:\Users\user\Desktop\fanyiyouda.exe | Section loaded: ondemandconnroutehelper.dll |
Source: C:\Users\user\Desktop\fanyiyouda.exe | Section loaded: schannel.dll |
Source: C:\Users\user\Desktop\fanyiyouda.exe | Section loaded: mskeyprotect.dll |
Source: C:\Users\user\Desktop\fanyiyouda.exe | Section loaded: ntasn1.dll |
Source: C:\Users\user\Desktop\fanyiyouda.exe | Section loaded: ncrypt.dll |
Source: C:\Users\user\Desktop\fanyiyouda.exe | Section loaded: ncryptsslp.dll |
Source: C:\Users\user\Desktop\fanyiyouda.exe | Section loaded: msasn1.dll |
Source: C:\Users\user\Desktop\fanyiyouda.exe | Section loaded: cryptsp.dll |
Source: C:\Users\user\Desktop\fanyiyouda.exe | Section loaded: rsaenh.dll |
Source: C:\Users\user\Desktop\fanyiyouda.exe | Section loaded: cryptbase.dll |
Source: C:\Users\user\Desktop\fanyiyouda.exe | Section loaded: gpapi.dll |
Source: C:\Users\user\Desktop\fanyiyouda.exe | Section loaded: dpapi.dll |
Source: C:\Users\user\Desktop\fanyiyouda.exe | Section loaded: ondemandconnroutehelper.dll |
Source: C:\Users\user\Desktop\fanyiyouda.exe TID: 5404 | Thread sleep time: -30000s >= -30000s |
Source: C:\Users\user\Desktop\fanyiyouda.exe TID: 7036 | Thread sleep count: 524 > 30 |
Source: C:\Users\user\Desktop\fanyiyouda.exe TID: 5400 | Thread sleep time: -30000s >= -30000s |
Source: C:\Users\user\Desktop\fanyiyouda.exe TID: 1288 | Thread sleep time: -30000s >= -30000s |
Source: C:\Users\user\Desktop\fanyiyouda.exe TID: 6616 | Thread sleep count: 652 > 30 |
Source: C:\Users\user\Desktop\fanyiyouda.exe TID: 1284 | Thread sleep time: -30000s >= -30000s |
Source: C:\Users\user\Desktop\fanyiyouda.exe TID: 6616 | Thread sleep count: 1423 > 30 |
Source: C:\Users\user\Desktop\fanyiyouda.exe TID: 7036 | Thread sleep count: 4183 > 30 |
Source: C:\Users\user\Desktop\fanyiyouda.exe TID: 7036 | Thread sleep time: -41830s >= -30000s |
Source: C:\Users\user\Desktop\fanyiyouda.exe TID: 6616 | Thread sleep count: 4307 > 30 |
Source: C:\Users\user\Desktop\fanyiyouda.exe TID: 6616 | Thread sleep time: -43070s >= -30000s |