Source: KyrazonSetup.exe, 00000000.00000003.1937924115.00000000050E2000.00000004.00000020.00020000.00000000.sdmp | String found in binary or memory: http://blog.izs.me) |
Source: KyrazonSetup.exe, 00000000.00000003.1937924115.00000000050E2000.00000004.00000020.00020000.00000000.sdmp | String found in binary or memory: http://blog.izs.me/) |
Source: KyrazonSetup.exe, 00000000.00000003.1932544119.00000000050DF000.00000004.00000020.00020000.00000000.sdmp | String found in binary or memory: http://cldr.unicode.org/index/downloads |
Source: KyrazonSetup.exe, 00000000.00000003.1932544119.00000000050DF000.00000004.00000020.00020000.00000000.sdmp | String found in binary or memory: http://code.google.com/p/smhasher/ |
Source: KyrazonSetup.exe, 00000000.00000003.1932544119.00000000050DF000.00000004.00000020.00020000.00000000.sdmp | String found in binary or memory: http://code.google.com/p/v8 |
Source: KyrazonSetup.exe, 00000000.00000003.1932544119.00000000050DF000.00000004.00000020.00020000.00000000.sdmp | String found in binary or memory: http://devel.freebsoft.org/speechd |
Source: KyrazonSetup.exe, 00000000.00000003.1932544119.00000000050DF000.00000004.00000020.00020000.00000000.sdmp | String found in binary or memory: http://developer.android.com/tools/extras/support-library.html |
Source: KyrazonSetup.exe, 00000000.00000003.1937924115.00000000050E2000.00000004.00000020.00020000.00000000.sdmp | String found in binary or memory: http://docs.python.org/library/uuid.html |
Source: KyrazonSetup.exe, 00000000.00000003.1937924115.00000000050E2000.00000004.00000020.00020000.00000000.sdmp | String found in binary or memory: http://dominictarr.com) |
Source: KyrazonSetup.exe, 00000000.00000003.1934910421.00000000007CC000.00000004.00000020.00020000.00000000.sdmp | String found in binary or memory: http://ejemplo.com |
Source: KyrazonSetup.exe, 00000000.00000003.1932544119.00000000050DF000.00000004.00000020.00020000.00000000.sdmp | String found in binary or memory: http://freedesktop.org |
Source: KyrazonSetup.exe, 00000000.00000003.1932544119.00000000050DF000.00000004.00000020.00020000.00000000.sdmp | String found in binary or memory: http://git.linuxtv.org/v4l-utils.git |
Source: KyrazonSetup.exe, 00000000.00000003.1932544119.00000000050DF000.00000004.00000020.00020000.00000000.sdmp | String found in binary or memory: http://google.github.io/snappy/ |
Source: KyrazonSetup.exe, 00000000.00000003.1938061587.00000000007CF000.00000004.00000020.00020000.00000000.sdmp | String found in binary or memory: http://int3.de/ |
Source: KyrazonSetup.exe, 00000000.00000003.1937924115.00000000050E2000.00000004.00000020.00020000.00000000.sdmp | String found in binary or memory: http://ljharb.codes |
Source: KyrazonSetup.exe | String found in binary or memory: http://nsis.sf.net/NSIS_Error |
Source: KyrazonSetup.exe | String found in binary or memory: http://nsis.sf.net/NSIS_ErrorError |
Source: KyrazonSetup.exe, 00000000.00000003.1932544119.00000000050DF000.00000004.00000020.00020000.00000000.sdmp | String found in binary or memory: http://opensource.perlig.de/rjsmin/ |
Source: KyrazonSetup.exe, 00000000.00000003.1937924115.00000000050E2000.00000004.00000020.00020000.00000000.sdmp | String found in binary or memory: http://pajhome.org.uk/crypt/md5 |
Source: KyrazonSetup.exe, 00000000.00000003.1937924115.00000000050E2000.00000004.00000020.00020000.00000000.sdmp | String found in binary or memory: http://re-becca.org/) |
Source: KyrazonSetup.exe, 00000000.00000003.1932544119.00000000050DF000.00000004.00000020.00020000.00000000.sdmp | String found in binary or memory: http://source.android.com/ |
Source: KyrazonSetup.exe, 00000000.00000003.1932544119.00000000050DF000.00000004.00000020.00020000.00000000.sdmp | String found in binary or memory: http://source.android.com/compatibility) |
Source: KyrazonSetup.exe, 00000000.00000003.1932544119.00000000050DF000.00000004.00000020.00020000.00000000.sdmp | String found in binary or memory: http://src.chromium.org/viewvc/chrome/trunk/deps/third_party/xz/COPYING |
Source: KyrazonSetup.exe, 00000000.00000003.1932544119.00000000050DF000.00000004.00000020.00020000.00000000.sdmp | String found in binary or memory: http://tukaani.org/xz/ |
Source: KyrazonSetup.exe, 00000000.00000003.1932544119.00000000050DF000.00000004.00000020.00020000.00000000.sdmp | String found in binary or memory: http://valgrind.org |
Source: KyrazonSetup.exe, 00000000.00000003.1932544119.00000000050DF000.00000004.00000020.00020000.00000000.sdmp | String found in binary or memory: http://webkit.org/ |
Source: KyrazonSetup.exe, 00000000.00000003.1932544119.00000000050DF000.00000004.00000020.00020000.00000000.sdmp | String found in binary or memory: http://website-archive.mozilla.org/www.mozilla.org/mpl/MPL/NPL/1.1/): |
Source: KyrazonSetup.exe, 00000000.00000003.1932544119.00000000050DF000.00000004.00000020.00020000.00000000.sdmp | String found in binary or memory: http://www.apache.org/licenses/ |
Source: KyrazonSetup.exe, 00000000.00000003.1932544119.00000000050DF000.00000004.00000020.00020000.00000000.sdmp | String found in binary or memory: http://www.apache.org/licenses/LICENSE-2.0 |
Source: KyrazonSetup.exe, 00000000.00000003.1932544119.00000000050DF000.00000004.00000020.00020000.00000000.sdmp | String found in binary or memory: http://www.chromium.org |
Source: KyrazonSetup.exe, 00000000.00000003.1932544119.00000000050DF000.00000004.00000020.00020000.00000000.sdmp | String found in binary or memory: http://www.freedesktop.org/wiki/Software/xdg-user-dirs |
Source: KyrazonSetup.exe, 00000000.00000003.1932544119.00000000050DF000.00000004.00000020.00020000.00000000.sdmp | String found in binary or memory: http://www.gutenberg.org/ebooks/53). |
Source: KyrazonSetup.exe, 00000000.00000003.1932544119.00000000050DF000.00000004.00000020.00020000.00000000.sdmp | String found in binary or memory: http://www.linux-usb.org/usb-ids.html |
Source: KyrazonSetup.exe, 00000000.00000003.1937924115.00000000050E2000.00000004.00000020.00020000.00000000.sdmp | String found in binary or memory: http://www.movable-type.co.uk/scripts/sha1.html |
Source: KyrazonSetup.exe, 00000000.00000003.1932544119.00000000050DF000.00000004.00000020.00020000.00000000.sdmp | String found in binary or memory: http://www.mozilla.org/MPL/ |
Source: KyrazonSetup.exe, 00000000.00000003.1932544119.00000000050DF000.00000004.00000020.00020000.00000000.sdmp | String found in binary or memory: http://www.mozilla.org/NPL/ |
Source: KyrazonSetup.exe, 00000000.00000003.1932544119.00000000050DF000.00000004.00000020.00020000.00000000.sdmp | String found in binary or memory: http://www.opensource.org/licenses/bsd-license.php |
Source: KyrazonSetup.exe, 00000000.00000003.1932544119.00000000050DF000.00000004.00000020.00020000.00000000.sdmp | String found in binary or memory: http://www.ploscompbiol.org/static/license |
Source: KyrazonSetup.exe, 00000000.00000003.1932544119.00000000050DF000.00000004.00000020.00020000.00000000.sdmp | String found in binary or memory: http://www.strongtalk.org/ |
Source: KyrazonSetup.exe, 00000000.00000003.1932544119.00000000050DF000.00000004.00000020.00020000.00000000.sdmp | String found in binary or memory: http://www.suitable.com |
Source: KyrazonSetup.exe, 00000000.00000003.1932544119.00000000050DF000.00000004.00000020.00020000.00000000.sdmp | String found in binary or memory: http://www.suitable.com/tools/smslib.html |
Source: KyrazonSetup.exe, 00000000.00000003.1932544119.00000000050DF000.00000004.00000020.00020000.00000000.sdmp | String found in binary or memory: http://www.suitable.com/tools/smslib.html> |
Source: KyrazonSetup.exe, 00000000.00000003.1932544119.00000000050DF000.00000004.00000020.00020000.00000000.sdmp | String found in binary or memory: http://www.webrtc.org |
Source: KyrazonSetup.exe, 00000000.00000003.1932544119.00000000050DF000.00000004.00000020.00020000.00000000.sdmp | String found in binary or memory: http://zlib.net/ |
Source: KyrazonSetup.exe, 00000000.00000003.1932544119.00000000050DF000.00000004.00000020.00020000.00000000.sdmp | String found in binary or memory: https://android.googlesource.com/platform/external/puffin |
Source: KyrazonSetup.exe, 00000000.00000003.1932544119.00000000050DF000.00000004.00000020.00020000.00000000.sdmp | String found in binary or memory: https://android.googlesource.com/platform/external/setupdesign/ |
Source: KyrazonSetup.exe, 00000000.00000003.1937924115.00000000050E2000.00000004.00000020.00020000.00000000.sdmp | String found in binary or memory: https://blueimp.net |
Source: zh-CN.pak.0.dr | String found in binary or memory: https://chrome.google.com/webstore/category/extensions |
Source: KyrazonSetup.exe, 00000000.00000003.1934799027.00000000007CC000.00000004.00000020.00020000.00000000.sdmp | String found in binary or memory: https://chrome.google.com/webstore?hl=en&category=theme81https://myactivity.google.com/myactivity/?u |
Source: KyrazonSetup.exe, 00000000.00000003.1934638566.00000000007CC000.00000004.00000020.00020000.00000000.sdmp | String found in binary or memory: https://chrome.google.com/webstore?hl=en-GB&category=theme81https://myactivity.google.com/myactivity |
Source: KyrazonSetup.exe, 00000000.00000003.1936524133.0000000002F27000.00000004.00000020.00020000.00000000.sdmp | String found in binary or memory: https://chrome.google.com/webstore?hl=pl&category=theme81https://myactivity.google.com/myactivity/?u |
Source: KyrazonSetup.exe, 00000000.00000003.1937505732.0000000002F27000.00000004.00000020.00020000.00000000.sdmp | String found in binary or memory: https://chrome.google.com/webstore?hl=vi&category=theme81https://myactivity.google.com/myactivity/?u |
Source: KyrazonSetup.exe, 00000000.00000003.1937598463.00000000007CC000.00000004.00000020.00020000.00000000.sdmp, zh-CN.pak.0.dr | String found in binary or memory: https://chrome.google.com/webstore?hl=zh-CN&category=theme81https://myactivity.google.com/myactivity |
Source: zh-CN.pak.0.dr | String found in binary or memory: https://chrome.google.com/webstore?hl=zh-CNCtrl$1 |
Source: KyrazonSetup.exe, 00000000.00000003.1937687612.00000000007CC000.00000004.00000020.00020000.00000000.sdmp | String found in binary or memory: https://chrome.google.com/webstore?hl=zh-TW&category=theme81https://myactivity.google.com/myactivity |
Source: KyrazonSetup.exe, 00000000.00000003.1937505732.0000000002F27000.00000004.00000020.00020000.00000000.sdmp, KyrazonSetup.exe, 00000000.00000003.1936524133.0000000002F27000.00000004.00000020.00020000.00000000.sdmp, zh-CN.pak.0.dr | String found in binary or memory: https://chromeenterprise.google/policies/#BrowserSwitcherEnabled |
Source: KyrazonSetup.exe, 00000000.00000003.1937505732.0000000002F27000.00000004.00000020.00020000.00000000.sdmp, KyrazonSetup.exe, 00000000.00000003.1936524133.0000000002F27000.00000004.00000020.00020000.00000000.sdmp, zh-CN.pak.0.dr | String found in binary or memory: https://chromeenterprise.google/policies/#BrowserSwitcherExternalGreylistUrl |
Source: KyrazonSetup.exe, 00000000.00000003.1937505732.0000000002F27000.00000004.00000020.00020000.00000000.sdmp, KyrazonSetup.exe, 00000000.00000003.1936524133.0000000002F27000.00000004.00000020.00020000.00000000.sdmp, zh-CN.pak.0.dr | String found in binary or memory: https://chromeenterprise.google/policies/#BrowserSwitcherExternalSitelistUrl |
Source: KyrazonSetup.exe, 00000000.00000003.1937505732.0000000002F27000.00000004.00000020.00020000.00000000.sdmp, KyrazonSetup.exe, 00000000.00000003.1936524133.0000000002F27000.00000004.00000020.00020000.00000000.sdmp, zh-CN.pak.0.dr | String found in binary or memory: https://chromeenterprise.google/policies/#BrowserSwitcherUrlGreylist |
Source: KyrazonSetup.exe, 00000000.00000003.1937505732.0000000002F27000.00000004.00000020.00020000.00000000.sdmp, KyrazonSetup.exe, 00000000.00000003.1936524133.0000000002F27000.00000004.00000020.00020000.00000000.sdmp, zh-CN.pak.0.dr | String found in binary or memory: https://chromeenterprise.google/policies/#BrowserSwitcherUrlList |
Source: KyrazonSetup.exe, 00000000.00000003.1937505732.0000000002F27000.00000004.00000020.00020000.00000000.sdmp, KyrazonSetup.exe, 00000000.00000003.1936524133.0000000002F27000.00000004.00000020.00020000.00000000.sdmp, zh-CN.pak.0.dr | String found in binary or memory: https://chromeenterprise.google/policies/#BrowserSwitcherUseIeSitelist |
Source: KyrazonSetup.exe, 00000000.00000003.1936778814.00000000007CC000.00000004.00000020.00020000.00000000.sdmp, KyrazonSetup.exe, 00000000.00000003.1937687612.00000000007CC000.00000004.00000020.00020000.00000000.sdmp, KyrazonSetup.exe, 00000000.00000003.1937505732.0000000002F27000.00000004.00000020.00020000.00000000.sdmp, KyrazonSetup.exe, 00000000.00000003.1934910421.00000000007CC000.00000004.00000020.00020000.00000000.sdmp, KyrazonSetup.exe, 00000000.00000003.1936662750.00000000007CC000.00000004.00000020.00020000.00000000.sdmp, KyrazonSetup.exe, 00000000.00000003.1937598463.00000000007CC000.00000004.00000020.00020000.00000000.sdmp, KyrazonSetup.exe, 00000000.00000003.1934799027.00000000007CC000.00000004.00000020.00020000.00000000.sdmp, KyrazonSetup.exe, 00000000.00000003.1936524133.0000000002F27000.00000004.00000020.00020000.00000000.sdmp, KyrazonSetup.exe, 00000000.00000003.1934544289.0000000002F27000.00000004.00000020.00020000.00000000.sdmp, KyrazonSetup.exe, 00000000.00000003.1934638566.00000000007CC000.00000004.00000020.00020000.00000000.sdmp, zh-CN.pak.0.dr | String found in binary or memory: https://chromestatus.com/features#browsers.chrome.status%3A%22Deprecated%22 |
Source: KyrazonSetup.exe, 00000000.00000003.1932544119.00000000050DF000.00000004.00000020.00020000.00000000.sdmp | String found in binary or memory: https://chromium.googlesource.com/chromium/src/ |
Source: KyrazonSetup.exe, 00000000.00000003.1932544119.00000000050DF000.00000004.00000020.00020000.00000000.sdmp | String found in binary or memory: https://chromium.googlesource.com/vulkan-deps/ |
Source: KyrazonSetup.exe, 00000000.00000003.1932544119.00000000050DF000.00000004.00000020.00020000.00000000.sdmp | String found in binary or memory: https://chromium.googlesource.com/webm/libwebm |
Source: KyrazonSetup.exe, 00000000.00000003.1932544119.00000000050DF000.00000004.00000020.00020000.00000000.sdmp | String found in binary or memory: https://chromium.googlesource.com/webm/libwebp |
Source: KyrazonSetup.exe, 00000000.00000003.1932544119.00000000050DF000.00000004.00000020.00020000.00000000.sdmp | String found in binary or memory: https://creativecommons.org/licenses/by/3.0/ |
Source: KyrazonSetup.exe, 00000000.00000003.1932544119.00000000050DF000.00000004.00000020.00020000.00000000.sdmp | String found in binary or memory: https://developers.google.com/android/guides/setup |
Source: KyrazonSetup.exe, 00000000.00000003.1934910421.00000000007CC000.00000004.00000020.00020000.00000000.sdmp | String found in binary or memory: https://ejemplo.com.Se |
Source: KyrazonSetup.exe, 00000000.00000003.1932544119.00000000050DF000.00000004.00000020.00020000.00000000.sdmp | String found in binary or memory: https://github.com/Cyan4973/xxHash |
Source: KyrazonSetup.exe, 00000000.00000003.1932544119.00000000050DF000.00000004.00000020.00020000.00000000.sdmp | String found in binary or memory: https://github.com/GPUOpen-LibrariesAndSDKs/VulkanMemoryAllocator |
Source: KyrazonSetup.exe, 00000000.00000003.1932544119.00000000050DF000.00000004.00000020.00020000.00000000.sdmp | String found in binary or memory: https://github.com/GoogleChromeLabs/text-fragments-polyfill |
Source: KyrazonSetup.exe, 00000000.00000003.1932544119.00000000050DF000.00000004.00000020.00020000.00000000.sdmp | String found in binary or memory: https://github.com/KhronosGroup/SPIRV-Headers.git |
Source: KyrazonSetup.exe, 00000000.00000003.1932544119.00000000050DF000.00000004.00000020.00020000.00000000.sdmp | String found in binary or memory: https://github.com/KhronosGroup/SPIRV-Tools.git |
Source: KyrazonSetup.exe, 00000000.00000003.1932544119.00000000050DF000.00000004.00000020.00020000.00000000.sdmp | String found in binary or memory: https://github.com/KhronosGroup/Vulkan-Headers |
Source: KyrazonSetup.exe, 00000000.00000003.1932544119.00000000050DF000.00000004.00000020.00020000.00000000.sdmp | String found in binary or memory: https://github.com/KhronosGroup/Vulkan-Loader |
Source: KyrazonSetup.exe, 00000000.00000003.1937924115.00000000050E2000.00000004.00000020.00020000.00000000.sdmp | String found in binary or memory: https://github.com/LiosK/UUID.js |
Source: KyrazonSetup.exe, 00000000.00000003.1932544119.00000000050DF000.00000004.00000020.00020000.00000000.sdmp | String found in binary or memory: https://github.com/Maratyszcza/pthreadpool |
Source: KyrazonSetup.exe, 00000000.00000003.1932544119.00000000050DF000.00000004.00000020.00020000.00000000.sdmp | String found in binary or memory: https://github.com/SeleniumHQ/selenium/tree/trunk |
Source: KyrazonSetup.exe, 00000000.00000003.1932544119.00000000050DF000.00000004.00000020.00020000.00000000.sdmp | String found in binary or memory: https://github.com/Squirrel/Squirrel.Mac |
Source: KyrazonSetup.exe, 00000000.00000003.1932544119.00000000050DF000.00000004.00000020.00020000.00000000.sdmp | String found in binary or memory: https://github.com/aawc/unrar.git |
Source: KyrazonSetup.exe, 00000000.00000003.1937924115.00000000050E2000.00000004.00000020.00020000.00000000.sdmp | String found in binary or memory: https://github.com/blueimp/JavaScript-MD5 |
Source: KyrazonSetup.exe, 00000000.00000003.1937924115.00000000050E2000.00000004.00000020.00020000.00000000.sdmp | String found in binary or memory: https://github.com/chalk/wrap-ansi?sponsor=1 |
Source: KyrazonSetup.exe, 00000000.00000003.1937924115.00000000050E2000.00000004.00000020.00020000.00000000.sdmp | String found in binary or memory: https://github.com/dominictarr/varstruct |
Source: KyrazonSetup.exe, 00000000.00000003.1937924115.00000000050E2000.00000004.00000020.00020000.00000000.sdmp | String found in binary or memory: https://github.com/dominictarr/varstruct.git |
Source: KyrazonSetup.exe, 00000000.00000003.1932544119.00000000050DF000.00000004.00000020.00020000.00000000.sdmp | String found in binary or memory: https://github.com/facebook/zstd |
Source: KyrazonSetup.exe, 00000000.00000003.1932544119.00000000050DF000.00000004.00000020.00020000.00000000.sdmp | String found in binary or memory: https://github.com/google/diff-match-patch/tree/master/javascript |
Source: KyrazonSetup.exe, 00000000.00000003.1932544119.00000000050DF000.00000004.00000020.00020000.00000000.sdmp | String found in binary or memory: https://github.com/google/distributed_point_functions |
Source: KyrazonSetup.exe, 00000000.00000003.1932544119.00000000050DF000.00000004.00000020.00020000.00000000.sdmp | String found in binary or memory: https://github.com/google/google-api-cpp-client/ |
Source: KyrazonSetup.exe, 00000000.00000003.1932544119.00000000050DF000.00000004.00000020.00020000.00000000.sdmp | String found in binary or memory: https://github.com/google/pprof/tree/master/proto |
Source: KyrazonSetup.exe, 00000000.00000003.1932544119.00000000050DF000.00000004.00000020.00020000.00000000.sdmp | String found in binary or memory: https://github.com/google/private-join-and-compute |
Source: KyrazonSetup.exe, 00000000.00000003.1932544119.00000000050DF000.00000004.00000020.00020000.00000000.sdmp | String found in binary or memory: https://github.com/google/protobuf |
Source: KyrazonSetup.exe, 00000000.00000003.1932544119.00000000050DF000.00000004.00000020.00020000.00000000.sdmp | String found in binary or memory: https://github.com/google/re2 |
Source: KyrazonSetup.exe, 00000000.00000003.1932544119.00000000050DF000.00000004.00000020.00020000.00000000.sdmp | String found in binary or memory: https://github.com/google/ruy |
Source: KyrazonSetup.exe, 00000000.00000003.1932544119.00000000050DF000.00000004.00000020.00020000.00000000.sdmp | String found in binary or memory: https://github.com/google/securemessage |
Source: KyrazonSetup.exe, 00000000.00000003.1932544119.00000000050DF000.00000004.00000020.00020000.00000000.sdmp | String found in binary or memory: https://github.com/google/sentencepiece |
Source: KyrazonSetup.exe, 00000000.00000003.1932544119.00000000050DF000.00000004.00000020.00020000.00000000.sdmp | String found in binary or memory: https://github.com/google/shell-encryption |
Source: KyrazonSetup.exe, 00000000.00000003.1932544119.00000000050DF000.00000004.00000020.00020000.00000000.sdmp | String found in binary or memory: https://github.com/google/ukey2 |
Source: KyrazonSetup.exe, 00000000.00000003.1932544119.00000000050DF000.00000004.00000020.00020000.00000000.sdmp | String found in binary or memory: https://github.com/google/woff2 |
Source: KyrazonSetup.exe, 00000000.00000003.1932544119.00000000050DF000.00000004.00000020.00020000.00000000.sdmp | String found in binary or memory: https://github.com/google/wuffs-mirror-release-c |
Source: KyrazonSetup.exe, 00000000.00000003.1932544119.00000000050DF000.00000004.00000020.00020000.00000000.sdmp | String found in binary or memory: https://github.com/google/xnnpack |
Source: KyrazonSetup.exe, 00000000.00000003.1937924115.00000000050E2000.00000004.00000020.00020000.00000000.sdmp | String found in binary or memory: https://github.com/iarna/wide-align |
Source: KyrazonSetup.exe, 00000000.00000003.1932544119.00000000050DF000.00000004.00000020.00020000.00000000.sdmp | String found in binary or memory: https://github.com/intel/libva |
Source: KyrazonSetup.exe, 00000000.00000003.1937924115.00000000050E2000.00000004.00000020.00020000.00000000.sdmp | String found in binary or memory: https://github.com/isaacs/yallist.git |
Source: KyrazonSetup.exe, 00000000.00000003.1932544119.00000000050DF000.00000004.00000020.00020000.00000000.sdmp | String found in binary or memory: https://github.com/jrmuizel/qcms/tree/v4 |
Source: KyrazonSetup.exe, 00000000.00000003.1937924115.00000000050E2000.00000004.00000020.00020000.00000000.sdmp | String found in binary or memory: https://github.com/npm/wrappy |
Source: KyrazonSetup.exe, 00000000.00000003.1932544119.00000000050DF000.00000004.00000020.00020000.00000000.sdmp | String found in binary or memory: https://github.com/protocolbuffers/protobuf/blob/master/java/lite.md |
Source: KyrazonSetup.exe, 00000000.00000003.1932544119.00000000050DF000.00000004.00000020.00020000.00000000.sdmp | String found in binary or memory: https://github.com/puppeteer/puppeteer/tree/main/packages/puppeteer-core |
Source: KyrazonSetup.exe, 00000000.00000003.1932544119.00000000050DF000.00000004.00000020.00020000.00000000.sdmp | String found in binary or memory: https://github.com/simplejson/simplejson |
Source: KyrazonSetup.exe, 00000000.00000003.1937924115.00000000050E2000.00000004.00000020.00020000.00000000.sdmp | String found in binary or memory: https://github.com/sponsors/broofa |
Source: KyrazonSetup.exe, 00000000.00000003.1937924115.00000000050E2000.00000004.00000020.00020000.00000000.sdmp | String found in binary or memory: https://github.com/sponsors/ctavan |
Source: KyrazonSetup.exe, 00000000.00000003.1937924115.00000000050E2000.00000004.00000020.00020000.00000000.sdmp | String found in binary or memory: https://github.com/sponsors/ljharb |
Source: KyrazonSetup.exe, 00000000.00000003.1937924115.00000000050E2000.00000004.00000020.00020000.00000000.sdmp | String found in binary or memory: https://github.com/sponsors/sindresorhus |
Source: KyrazonSetup.exe, 00000000.00000003.1932544119.00000000050DF000.00000004.00000020.00020000.00000000.sdmp | String found in binary or memory: https://github.com/tensorflow/models |
Source: KyrazonSetup.exe, 00000000.00000003.1932544119.00000000050DF000.00000004.00000020.00020000.00000000.sdmp | String found in binary or memory: https://github.com/tensorflow/tensorflow |
Source: KyrazonSetup.exe, 00000000.00000003.1932544119.00000000050DF000.00000004.00000020.00020000.00000000.sdmp | String found in binary or memory: https://github.com/tensorflow/text.git |
Source: KyrazonSetup.exe, 00000000.00000003.1932544119.00000000050DF000.00000004.00000020.00020000.00000000.sdmp | String found in binary or memory: https://github.com/tensorflow/tflite-support |
Source: KyrazonSetup.exe, 00000000.00000003.1937924115.00000000050E2000.00000004.00000020.00020000.00000000.sdmp | String found in binary or memory: https://github.com/uuidjs/uuid |
Source: KyrazonSetup.exe, 00000000.00000003.1937924115.00000000050E2000.00000004.00000020.00020000.00000000.sdmp | String found in binary or memory: https://github.com/uuidjs/uuid#getrandomvalues-not-supported |
Source: KyrazonSetup.exe, 00000000.00000003.1937924115.00000000050E2000.00000004.00000020.00020000.00000000.sdmp | String found in binary or memory: https://github.com/uuidjs/uuid.git |
Source: KyrazonSetup.exe, 00000000.00000003.1937924115.00000000050E2000.00000004.00000020.00020000.00000000.sdmp | String found in binary or memory: https://github.com/uuidjs/uuid/pull/434 |
Source: KyrazonSetup.exe, 00000000.00000003.1937924115.00000000050E2000.00000004.00000020.00020000.00000000.sdmp | String found in binary or memory: https://github.com/uuidjs/uuid/pull/677#issuecomment-1757351351 |
Source: KyrazonSetup.exe, 00000000.00000003.1932544119.00000000050DF000.00000004.00000020.00020000.00000000.sdmp | String found in binary or memory: https://github.com/wasdk/wasmparser |
Source: KyrazonSetup.exe, 00000000.00000003.1932544119.00000000050DF000.00000004.00000020.00020000.00000000.sdmp | String found in binary or memory: https://github.com/xiph/rnnoise |
Source: KyrazonSetup.exe, 00000000.00000003.1932544119.00000000050DF000.00000004.00000020.00020000.00000000.sdmp | String found in binary or memory: https://gitlab.freedesktop.org/xdg/xdgmime |
Source: KyrazonSetup.exe, 00000000.00000003.1932544119.00000000050DF000.00000004.00000020.00020000.00000000.sdmp | String found in binary or memory: https://gitlab.freedesktop.org/xorg/proto/xproto/ |
Source: KyrazonSetup.exe, 00000000.00000003.1932544119.00000000050DF000.00000004.00000020.00020000.00000000.sdmp | String found in binary or memory: https://hg.mozilla.org/mozilla-central/file/tip/netwerk/base/nsURLParsers.cpp |
Source: zh-CN.pak.0.dr | String found in binary or memory: https://myactivity.google.com/ |
Source: KyrazonSetup.exe, 00000000.00000003.1937924115.00000000050E2000.00000004.00000020.00020000.00000000.sdmp | String found in binary or memory: https://opensource.org/licenses/MIT |
Source: zh-CN.pak.0.dr | String found in binary or memory: https://passwords.google.comGoogle |
Source: KyrazonSetup.exe, 00000000.00000003.1936524133.0000000002F27000.00000004.00000020.00020000.00000000.sdmp | String found in binary or memory: https://passwords.google.comKonta |
Source: KyrazonSetup.exe, 00000000.00000003.1937505732.0000000002F27000.00000004.00000020.00020000.00000000.sdmp | String found in binary or memory: https://passwords.google.comT |
Source: zh-CN.pak.0.dr | String found in binary or memory: https://photos.google.com/settings?referrer=CHROME_NTP |
Source: zh-CN.pak.0.dr | String found in binary or memory: https://policies.google.com/ |
Source: KyrazonSetup.exe, 00000000.00000003.1932544119.00000000050DF000.00000004.00000020.00020000.00000000.sdmp | String found in binary or memory: https://polymer-library.polymer-project.org |
Source: KyrazonSetup.exe, 00000000.00000003.1932544119.00000000050DF000.00000004.00000020.00020000.00000000.sdmp | String found in binary or memory: https://quiche.googlesource.com/quiche |
Source: KyrazonSetup.exe, 00000000.00000003.1937924115.00000000050E2000.00000004.00000020.00020000.00000000.sdmp | String found in binary or memory: https://sindresorhus.com |
Source: KyrazonSetup.exe, 00000000.00000003.1937924115.00000000050E2000.00000004.00000020.00020000.00000000.sdmp | String found in binary or memory: https://sindresorhus.com) |
Source: KyrazonSetup.exe, 00000000.00000003.1932544119.00000000050DF000.00000004.00000020.00020000.00000000.sdmp | String found in binary or memory: https://sites.google.com/site/gaviotachessengine/Home/endgame-tablebases-1 |
Source: KyrazonSetup.exe, 00000000.00000003.1932544119.00000000050DF000.00000004.00000020.00020000.00000000.sdmp | String found in binary or memory: https://skia.org/ |
Source: KyrazonSetup.exe, 00000000.00000003.1932544119.00000000050DF000.00000004.00000020.00020000.00000000.sdmp | String found in binary or memory: https://source.corp.google.com/piper///depot/google3/third_party/tamachiyomi/README.md |
Source: KyrazonSetup.exe, 00000000.00000003.1932544119.00000000050DF000.00000004.00000020.00020000.00000000.sdmp | String found in binary or memory: https://sourceforge.net/projects/wtl/files/WTL%2010/ |
Source: KyrazonSetup.exe, 00000000.00000003.1932544119.00000000050DF000.00000004.00000020.00020000.00000000.sdmp | String found in binary or memory: https://sqlite.org/ |
Source: KyrazonSetup.exe, 00000000.00000003.1936778814.00000000007CC000.00000004.00000020.00020000.00000000.sdmp, KyrazonSetup.exe, 00000000.00000003.1937687612.00000000007CC000.00000004.00000020.00020000.00000000.sdmp, KyrazonSetup.exe, 00000000.00000003.1937505732.0000000002F27000.00000004.00000020.00020000.00000000.sdmp, KyrazonSetup.exe, 00000000.00000003.1934910421.00000000007CC000.00000004.00000020.00020000.00000000.sdmp, KyrazonSetup.exe, 00000000.00000003.1936662750.00000000007CC000.00000004.00000020.00020000.00000000.sdmp, KyrazonSetup.exe, 00000000.00000003.1937598463.00000000007CC000.00000004.00000020.00020000.00000000.sdmp, KyrazonSetup.exe, 00000000.00000003.1936524133.0000000002F27000.00000004.00000020.00020000.00000000.sdmp, KyrazonSetup.exe, 00000000.00000003.1934544289.0000000002F27000.00000004.00000020.00020000.00000000.sdmp, zh-CN.pak.0.dr | String found in binary or memory: https://support.google.com/chrome/a/answer/9122284 |
Source: KyrazonSetup.exe, 00000000.00000003.1936778814.00000000007CC000.00000004.00000020.00020000.00000000.sdmp, KyrazonSetup.exe, 00000000.00000003.1937687612.00000000007CC000.00000004.00000020.00020000.00000000.sdmp, KyrazonSetup.exe, 00000000.00000003.1937505732.0000000002F27000.00000004.00000020.00020000.00000000.sdmp, KyrazonSetup.exe, 00000000.00000003.1934910421.00000000007CC000.00000004.00000020.00020000.00000000.sdmp, KyrazonSetup.exe, 00000000.00000003.1936662750.00000000007CC000.00000004.00000020.00020000.00000000.sdmp, KyrazonSetup.exe, 00000000.00000003.1937598463.00000000007CC000.00000004.00000020.00020000.00000000.sdmp, KyrazonSetup.exe, 00000000.00000003.1934799027.00000000007CC000.00000004.00000020.00020000.00000000.sdmp, KyrazonSetup.exe, 00000000.00000003.1936524133.0000000002F27000.00000004.00000020.00020000.00000000.sdmp, KyrazonSetup.exe, 00000000.00000003.1934544289.0000000002F27000.00000004.00000020.00020000.00000000.sdmp, zh-CN.pak.0.dr | String found in binary or memory: https://support.google.com/chrome/answer/6098869 |
Source: zh-CN.pak.0.dr | String found in binary or memory: https://support.google.com/chromebook?p=app_intent |
Source: KyrazonSetup.exe, 00000000.00000003.1932544119.00000000050DF000.00000004.00000020.00020000.00000000.sdmp | String found in binary or memory: https://swiftshader.googlesource.com/SwiftShader |
Source: KyrazonSetup.exe, 00000000.00000003.1932544119.00000000050DF000.00000004.00000020.00020000.00000000.sdmp | String found in binary or memory: https://www.apache.org/licenses/ |
Source: KyrazonSetup.exe, 00000000.00000003.1932544119.00000000050DF000.00000004.00000020.00020000.00000000.sdmp | String found in binary or memory: https://www.apache.org/licenses/LICENSE-2.0 |
Source: zh-CN.pak.0.dr | String found in binary or memory: https://www.google.com/chrome/privacy/eula_text.html |
Source: KyrazonSetup.exe, 00000000.00000003.1937924115.00000000050E2000.00000004.00000020.00020000.00000000.sdmp | String found in binary or memory: https://www.rfc-editor.org/rfc/rfc9562.html |
Source: KyrazonSetup.exe, 00000000.00000003.1937924115.00000000050E2000.00000004.00000020.00020000.00000000.sdmp | String found in binary or memory: https://www.rfc-editor.org/rfc/rfc9562.html#name-example-of-a-uuidv7-value |
Source: KyrazonSetup.exe, 00000000.00000003.1937924115.00000000050E2000.00000004.00000020.00020000.00000000.sdmp | String found in binary or memory: https://www.rfc-editor.org/rfc/rfc9562.html#section-6.2-5.1 |
Source: KyrazonSetup.exe, 00000000.00000003.1932544119.00000000050DF000.00000004.00000020.00020000.00000000.sdmp | String found in binary or memory: https://www.unicode.org/copyright.html. |
Source: C:\Windows\SysWOW64\cmd.exe | WMI Queries: IWbemServices::ExecQuery - root\cimv2 : SELECT __PATH, ProcessId, CSName, Caption, SessionId, ThreadCount, WorkingSetSize, KernelModeTime, UserModeTime FROM Win32_Process |
Source: C:\Windows\SysWOW64\tasklist.exe | WMI Queries: IWbemServices::ExecQuery - root\cimv2 : SELECT __PATH, ProcessId, CSName, Caption, SessionId, ThreadCount, WorkingSetSize, KernelModeTime, UserModeTime FROM Win32_Process WHERE Caption = 'KYRAZONGODOT.EXE' |
Source: C:\Windows\System32\tasklist.exe | WMI Queries: IWbemServices::ExecQuery - root\cimv2 : SELECT __PATH, ProcessId, CSName, Caption, SessionId, ThreadCount, WorkingSetSize, KernelModeTime, UserModeTime FROM Win32_Process |
Source: C:\Windows\System32\conhost.exe | WMI Queries: IWbemServices::ExecQuery - root\cimv2 : SELECT __PATH, ProcessId, CSName, Caption, SessionId, ThreadCount, WorkingSetSize, KernelModeTime, UserModeTime FROM Win32_Process |
Source: C:\Windows\System32\tasklist.exe | WMI Queries: IWbemServices::ExecQuery - root\cimv2 : SELECT __PATH, ProcessId, CSName, Caption, SessionId, ThreadCount, WorkingSetSize, KernelModeTime, UserModeTime FROM Win32_Process |
Source: C:\Windows\System32\tasklist.exe | WMI Queries: IWbemServices::ExecQuery - root\cimv2 : SELECT __PATH, ProcessId, CSName, Caption, SessionId, ThreadCount, WorkingSetSize, KernelModeTime, UserModeTime FROM Win32_Process |
Source: C:\Windows\System32\tasklist.exe | WMI Queries: IWbemServices::ExecQuery - root\cimv2 : SELECT __PATH, ProcessId, CSName, Caption, SessionId, ThreadCount, WorkingSetSize, KernelModeTime, UserModeTime FROM Win32_Process |
Source: C:\Windows\System32\tasklist.exe | WMI Queries: IWbemServices::ExecQuery - root\cimv2 : SELECT __PATH, ProcessId, CSName, Caption, SessionId, ThreadCount, WorkingSetSize, KernelModeTime, UserModeTime FROM Win32_Process |
Source: C:\Windows\System32\tasklist.exe | WMI Queries: IWbemServices::ExecQuery - root\cimv2 : SELECT __PATH, ProcessId, CSName, Caption, SessionId, ThreadCount, WorkingSetSize, KernelModeTime, UserModeTime FROM Win32_Process |
Source: C:\Windows\System32\tasklist.exe | WMI Queries: IWbemServices::ExecQuery - root\cimv2 : SELECT __PATH, ProcessId, CSName, Caption, SessionId, ThreadCount, WorkingSetSize, KernelModeTime, UserModeTime FROM Win32_Process |
Source: C:\Windows\System32\tasklist.exe | WMI Queries: IWbemServices::ExecQuery - root\cimv2 : SELECT __PATH, ProcessId, CSName, Caption, SessionId, ThreadCount, WorkingSetSize, KernelModeTime, UserModeTime FROM Win32_Process |
Source: C:\Windows\System32\tasklist.exe | WMI Queries: IWbemServices::ExecQuery - root\cimv2 : SELECT __PATH, ProcessId, CSName, Caption, SessionId, ThreadCount, WorkingSetSize, KernelModeTime, UserModeTime FROM Win32_Process |
Source: C:\Windows\System32\tasklist.exe | WMI Queries: IWbemServices::ExecQuery - root\cimv2 : SELECT __PATH, ProcessId, CSName, Caption, SessionId, ThreadCount, WorkingSetSize, KernelModeTime, UserModeTime FROM Win32_Process |
Source: C:\Windows\System32\tasklist.exe | WMI Queries: IWbemServices::ExecQuery - root\cimv2 : SELECT __PATH, ProcessId, CSName, Caption, SessionId, ThreadCount, WorkingSetSize, KernelModeTime, UserModeTime FROM Win32_Process |
Source: C:\Windows\System32\tasklist.exe | WMI Queries: IWbemServices::ExecQuery - root\cimv2 : SELECT __PATH, ProcessId, CSName, Caption, SessionId, ThreadCount, WorkingSetSize, KernelModeTime, UserModeTime FROM Win32_Process |
Source: C:\Windows\System32\conhost.exe | WMI Queries: IWbemServices::ExecQuery - root\cimv2 : SELECT __PATH, ProcessId, CSName, Caption, SessionId, ThreadCount, WorkingSetSize, KernelModeTime, UserModeTime FROM Win32_Process |
Source: C:\Windows\System32\tasklist.exe | WMI Queries: IWbemServices::ExecQuery - root\cimv2 : SELECT __PATH, ProcessId, CSName, Caption, SessionId, ThreadCount, WorkingSetSize, KernelModeTime, UserModeTime FROM Win32_Process |
Source: C:\Windows\System32\tasklist.exe | WMI Queries: IWbemServices::ExecQuery - root\cimv2 : SELECT __PATH, ProcessId, CSName, Caption, SessionId, ThreadCount, WorkingSetSize, KernelModeTime, UserModeTime FROM Win32_Process |
Source: C:\Windows\System32\tasklist.exe | WMI Queries: IWbemServices::ExecQuery - root\cimv2 : SELECT __PATH, ProcessId, CSName, Caption, SessionId, ThreadCount, WorkingSetSize, KernelModeTime, UserModeTime FROM Win32_Process |
Source: C:\Windows\System32\conhost.exe | WMI Queries: IWbemServices::ExecQuery - root\cimv2 : SELECT __PATH, ProcessId, CSName, Caption, SessionId, ThreadCount, WorkingSetSize, KernelModeTime, UserModeTime FROM Win32_Process |
Source: C:\Windows\System32\tasklist.exe | WMI Queries: IWbemServices::ExecQuery - root\cimv2 : SELECT __PATH, ProcessId, CSName, Caption, SessionId, ThreadCount, WorkingSetSize, KernelModeTime, UserModeTime FROM Win32_Process |
Source: C:\Windows\System32\tasklist.exe | WMI Queries: IWbemServices::ExecQuery - root\cimv2 : SELECT __PATH, ProcessId, CSName, Caption, SessionId, ThreadCount, WorkingSetSize, KernelModeTime, UserModeTime FROM Win32_Process |
Source: C:\Windows\System32\cmd.exe | WMI Queries: IWbemServices::ExecQuery - root\cimv2 : SELECT __PATH, ProcessId, CSName, Caption, SessionId, ThreadCount, WorkingSetSize, KernelModeTime, UserModeTime FROM Win32_Process |
Source: C:\Windows\System32\tasklist.exe | WMI Queries: IWbemServices::ExecQuery - root\cimv2 : SELECT __PATH, ProcessId, CSName, Caption, SessionId, ThreadCount, WorkingSetSize, KernelModeTime, UserModeTime FROM Win32_Process |
Source: C:\Windows\System32\tasklist.exe | WMI Queries: IWbemServices::ExecQuery - root\cimv2 : SELECT __PATH, ProcessId, CSName, Caption, SessionId, ThreadCount, WorkingSetSize, KernelModeTime, UserModeTime FROM Win32_Process |
Source: C:\Windows\System32\tasklist.exe | WMI Queries: IWbemServices::ExecQuery - root\cimv2 : SELECT __PATH, ProcessId, CSName, Caption, SessionId, ThreadCount, WorkingSetSize, KernelModeTime, UserModeTime FROM Win32_Process |
Source: C:\Windows\System32\tasklist.exe | WMI Queries: IWbemServices::ExecQuery - root\cimv2 : SELECT __PATH, ProcessId, CSName, Caption, SessionId, ThreadCount, WorkingSetSize, KernelModeTime, UserModeTime FROM Win32_Process |
Source: C:\Windows\System32\tasklist.exe | WMI Queries: IWbemServices::ExecQuery - root\cimv2 : SELECT __PATH, ProcessId, CSName, Caption, SessionId, ThreadCount, WorkingSetSize, KernelModeTime, UserModeTime FROM Win32_Process |
Source: C:\Windows\System32\tasklist.exe | WMI Queries: IWbemServices::ExecQuery - root\cimv2 : SELECT __PATH, ProcessId, CSName, Caption, SessionId, ThreadCount, WorkingSetSize, KernelModeTime, UserModeTime FROM Win32_Process |
Source: C:\Windows\System32\tasklist.exe | WMI Queries: IWbemServices::ExecQuery - root\cimv2 : SELECT __PATH, ProcessId, CSName, Caption, SessionId, ThreadCount, WorkingSetSize, KernelModeTime, UserModeTime FROM Win32_Process |
Source: C:\Windows\System32\conhost.exe | WMI Queries: IWbemServices::ExecQuery - root\cimv2 : SELECT __PATH, ProcessId, CSName, Caption, SessionId, ThreadCount, WorkingSetSize, KernelModeTime, UserModeTime FROM Win32_Process |
Source: C:\Windows\System32\tasklist.exe | WMI Queries: IWbemServices::ExecQuery - root\cimv2 : SELECT __PATH, ProcessId, CSName, Caption, SessionId, ThreadCount, WorkingSetSize, KernelModeTime, UserModeTime FROM Win32_Process |
Source: C:\Windows\System32\tasklist.exe | WMI Queries: IWbemServices::ExecQuery - root\cimv2 : SELECT __PATH, ProcessId, CSName, Caption, SessionId, ThreadCount, WorkingSetSize, KernelModeTime, UserModeTime FROM Win32_Process |
Source: C:\Windows\System32\tasklist.exe | WMI Queries: IWbemServices::ExecQuery - root\cimv2 : SELECT __PATH, ProcessId, CSName, Caption, SessionId, ThreadCount, WorkingSetSize, KernelModeTime, UserModeTime FROM Win32_Process |
Source: C:\Windows\System32\tasklist.exe | WMI Queries: IWbemServices::ExecQuery - root\cimv2 : SELECT __PATH, ProcessId, CSName, Caption, SessionId, ThreadCount, WorkingSetSize, KernelModeTime, UserModeTime FROM Win32_Process |
Source: C:\Windows\System32\cmd.exe | WMI Queries: IWbemServices::ExecQuery - root\cimv2 : SELECT __PATH, ProcessId, CSName, Caption, SessionId, ThreadCount, WorkingSetSize, KernelModeTime, UserModeTime FROM Win32_Process |
Source: C:\Windows\System32\Conhost.exe | WMI Queries: IWbemServices::ExecQuery - root\cimv2 : SELECT __PATH, ProcessId, CSName, Caption, SessionId, ThreadCount, WorkingSetSize, KernelModeTime, UserModeTime FROM Win32_Process |
Source: C:\Windows\System32\Conhost.exe | WMI Queries: IWbemServices::ExecQuery - root\cimv2 : SELECT __PATH, ProcessId, CSName, Caption, SessionId, ThreadCount, WorkingSetSize, KernelModeTime, UserModeTime FROM Win32_Process |
Source: C:\Windows\System32\Conhost.exe | WMI Queries: IWbemServices::ExecQuery - root\cimv2 : SELECT __PATH, ProcessId, CSName, Caption, SessionId, ThreadCount, WorkingSetSize, KernelModeTime, UserModeTime FROM Win32_Process |
Source: unknown | Process created: C:\Users\user\Desktop\KyrazonSetup.exe "C:\Users\user\Desktop\KyrazonSetup.exe" | |
Source: C:\Users\user\Desktop\KyrazonSetup.exe | Process created: C:\Windows\SysWOW64\cmd.exe "C:\Windows\system32\cmd.exe" /c tasklist /FI "USERNAME eq %USERNAME%" /FI "IMAGENAME eq KyrazonGodot.exe" /FO csv | "C:\Windows\system32\find.exe" "KyrazonGodot.exe" | |
Source: C:\Windows\SysWOW64\cmd.exe | Process created: C:\Windows\System32\conhost.exe C:\Windows\system32\conhost.exe 0xffffffff -ForceV1 | |
Source: C:\Windows\SysWOW64\cmd.exe | Process created: C:\Windows\SysWOW64\tasklist.exe tasklist /FI "USERNAME eq user" /FI "IMAGENAME eq KyrazonGodot.exe" /FO csv | |
Source: C:\Windows\SysWOW64\cmd.exe | Process created: C:\Windows\SysWOW64\find.exe "C:\Windows\system32\find.exe" "KyrazonGodot.exe" | |
Source: unknown | Process created: C:\Users\user\AppData\Local\Programs\KyrazonGodot\KyrazonGodot.exe "C:\Users\user\AppData\Local\Programs\KyrazonGodot\KyrazonGodot.exe" | |
Source: C:\Users\user\AppData\Local\Programs\KyrazonGodot\KyrazonGodot.exe | Process created: C:\Users\user\AppData\Local\Programs\KyrazonGodot\KyrazonGodot.exe "C:\Users\user\AppData\Local\Programs\KyrazonGodot\KyrazonGodot.exe" --type=gpu-process --user-data-dir="C:\Users\user\AppData\Roaming\KyrazonGodot" --gpu-preferences=WAAAAAAAAADgAAAMAAAAAAAAAAAAAAAAAABgAAAAAAA4AAAAAAAAAAAAAAAEAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAGAAAAAAAAAAYAAAAAAAAAAgAAAAAAAAACAAAAAAAAAAIAAAAAAAAAA== --mojo-platform-channel-handle=1772 --field-trial-handle=1776,i,4294901941177378234,17718125093265605642,262144 --disable-features=SpareRendererForSitePerProcess,WinDelaySpellcheckServiceInit,WinRetrieveSuggestionsOnlyOnDemand /prefetch:2 | |
Source: C:\Users\user\AppData\Local\Programs\KyrazonGodot\KyrazonGodot.exe | Process created: C:\Users\user\AppData\Local\Programs\KyrazonGodot\resources\app.asar.unpacked\node_modules\windows-shortcuts\lib\shortcut\Shortcut.exe C:\Users\user\AppData\Local\Programs\KyrazonGodot\resources\app.asar.unpacked\node_modules\windows-shortcuts\lib\shortcut\Shortcut.exe /A:C "/F:C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\KyrazonGodot.lnk" /T:C:\Users\user\AppData\Local\Programs\KyrazonGodot\KyrazonGodot.exe | |
Source: C:\Users\user\AppData\Local\Programs\KyrazonGodot\resources\app.asar.unpacked\node_modules\windows-shortcuts\lib\shortcut\Shortcut.exe | Process created: C:\Windows\System32\conhost.exe C:\Windows\system32\conhost.exe 0xffffffff -ForceV1 | |
Source: C:\Users\user\AppData\Local\Programs\KyrazonGodot\KyrazonGodot.exe | Process created: C:\Windows\System32\cmd.exe C:\Windows\system32\cmd.exe /d /s /c "tasklist" | |
Source: C:\Windows\System32\cmd.exe | Process created: C:\Windows\System32\conhost.exe C:\Windows\system32\conhost.exe 0xffffffff -ForceV1 | |
Source: C:\Windows\System32\cmd.exe | Process created: C:\Windows\System32\tasklist.exe tasklist | |
Source: C:\Users\user\AppData\Local\Programs\KyrazonGodot\KyrazonGodot.exe | Process created: C:\Windows\System32\cmd.exe C:\Windows\system32\cmd.exe /d /s /c "tasklist" | |
Source: C:\Users\user\AppData\Local\Programs\KyrazonGodot\KyrazonGodot.exe | Process created: C:\Windows\System32\cmd.exe C:\Windows\system32\cmd.exe /d /s /c "tasklist" | |
Source: C:\Windows\System32\cmd.exe | Process created: C:\Windows\System32\conhost.exe C:\Windows\system32\conhost.exe 0xffffffff -ForceV1 | |
Source: C:\Users\user\AppData\Local\Programs\KyrazonGodot\KyrazonGodot.exe | Process created: C:\Windows\System32\cmd.exe C:\Windows\system32\cmd.exe /d /s /c "tasklist" | |
Source: C:\Windows\System32\cmd.exe | Process created: C:\Windows\System32\conhost.exe C:\Windows\system32\conhost.exe 0xffffffff -ForceV1 | |
Source: C:\Users\user\AppData\Local\Programs\KyrazonGodot\KyrazonGodot.exe | Process created: C:\Windows\System32\cmd.exe C:\Windows\system32\cmd.exe /d /s /c "where /r . data.sqlite" | |
Source: C:\Windows\System32\cmd.exe | Process created: C:\Windows\System32\conhost.exe C:\Windows\system32\conhost.exe 0xffffffff -ForceV1 | |
Source: C:\Windows\System32\cmd.exe | Process created: C:\Windows\System32\conhost.exe C:\Windows\system32\conhost.exe 0xffffffff -ForceV1 | |
Source: C:\Windows\System32\cmd.exe | Process created: C:\Windows\System32\tasklist.exe tasklist | |
Source: C:\Windows\System32\cmd.exe | Process created: C:\Windows\System32\tasklist.exe tasklist | |
Source: C:\Windows\System32\cmd.exe | Process created: C:\Windows\System32\tasklist.exe tasklist | |
Source: C:\Windows\System32\cmd.exe | Process created: C:\Windows\System32\where.exe where /r . data.sqlite | |
Source: C:\Users\user\AppData\Local\Programs\KyrazonGodot\KyrazonGodot.exe | Process created: C:\Windows\System32\cmd.exe C:\Windows\system32\cmd.exe /d /s /c "tasklist" | |
Source: C:\Windows\System32\cmd.exe | Process created: C:\Windows\System32\conhost.exe C:\Windows\system32\conhost.exe 0xffffffff -ForceV1 | |
Source: C:\Windows\System32\cmd.exe | Process created: C:\Windows\System32\tasklist.exe tasklist | |
Source: C:\Users\user\AppData\Local\Programs\KyrazonGodot\KyrazonGodot.exe | Process created: C:\Users\user\AppData\Local\Programs\KyrazonGodot\KyrazonGodot.exe "C:\Users\user\AppData\Local\Programs\KyrazonGodot\KyrazonGodot.exe" --type=utility --utility-sub-type=network.mojom.NetworkService --lang=en-GB --service-sandbox-type=none --user-data-dir="C:\Users\user\AppData\Roaming\KyrazonGodot" --mojo-platform-channel-handle=2364 --field-trial-handle=1776,i,4294901941177378234,17718125093265605642,262144 --disable-features=SpareRendererForSitePerProcess,WinDelaySpellcheckServiceInit,WinRetrieveSuggestionsOnlyOnDemand /prefetch:8 | |
Source: C:\Users\user\AppData\Local\Programs\KyrazonGodot\KyrazonGodot.exe | Process created: C:\Windows\System32\cmd.exe C:\Windows\system32\cmd.exe /d /s /c "tasklist" | |
Source: C:\Windows\System32\cmd.exe | Process created: C:\Windows\System32\conhost.exe C:\Windows\system32\conhost.exe 0xffffffff -ForceV1 | |
Source: C:\Windows\System32\cmd.exe | Process created: C:\Windows\System32\tasklist.exe tasklist | |
Source: C:\Users\user\AppData\Local\Programs\KyrazonGodot\KyrazonGodot.exe | Process created: C:\Windows\System32\cmd.exe C:\Windows\system32\cmd.exe /d /s /c "tasklist" | |
Source: C:\Windows\System32\cmd.exe | Process created: C:\Windows\System32\conhost.exe C:\Windows\system32\conhost.exe 0xffffffff -ForceV1 | |
Source: C:\Windows\System32\cmd.exe | Process created: C:\Windows\System32\tasklist.exe tasklist | |
Source: C:\Users\user\AppData\Local\Programs\KyrazonGodot\KyrazonGodot.exe | Process created: C:\Windows\System32\cmd.exe C:\Windows\system32\cmd.exe /d /s /c "tasklist" | |
Source: C:\Windows\System32\cmd.exe | Process created: C:\Windows\System32\conhost.exe C:\Windows\system32\conhost.exe 0xffffffff -ForceV1 | |
Source: C:\Windows\System32\cmd.exe | Process created: C:\Windows\System32\tasklist.exe tasklist | |
Source: unknown | Process created: C:\Users\user\AppData\Local\Programs\KyrazonGodot\KyrazonGodot.exe "C:\Users\user\AppData\Local\Programs\KyrazonGodot\KyrazonGodot.exe" | |
Source: C:\Users\user\AppData\Local\Programs\KyrazonGodot\KyrazonGodot.exe | Process created: C:\Windows\System32\cmd.exe C:\Windows\system32\cmd.exe /d /s /c "tasklist" | |
Source: C:\Windows\System32\cmd.exe | Process created: C:\Windows\System32\conhost.exe C:\Windows\system32\conhost.exe 0xffffffff -ForceV1 | |
Source: C:\Windows\System32\cmd.exe | Process created: C:\Windows\System32\tasklist.exe tasklist | |
Source: C:\Users\user\AppData\Local\Programs\KyrazonGodot\KyrazonGodot.exe | Process created: C:\Users\user\AppData\Local\Programs\KyrazonGodot\KyrazonGodot.exe "C:\Users\user\AppData\Local\Programs\KyrazonGodot\KyrazonGodot.exe" --type=gpu-process --user-data-dir="C:\Users\user\AppData\Roaming\KyrazonGodot" --gpu-preferences=WAAAAAAAAADgAAAMAAAAAAAAAAAAAAAAAABgAAAAAAA4AAAAAAAAAAAAAAAEAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAGAAAAAAAAAAYAAAAAAAAAAgAAAAAAAAACAAAAAAAAAAIAAAAAAAAAA== --mojo-platform-channel-handle=1740 --field-trial-handle=1744,i,17217612992806517809,8679626120337516312,262144 --disable-features=SpareRendererForSitePerProcess,WinDelaySpellcheckServiceInit,WinRetrieveSuggestionsOnlyOnDemand /prefetch:2 | |
Source: C:\Users\user\AppData\Local\Programs\KyrazonGodot\KyrazonGodot.exe | Process created: C:\Windows\System32\cmd.exe C:\Windows\system32\cmd.exe /d /s /c "tasklist" | |
Source: C:\Windows\System32\cmd.exe | Process created: C:\Windows\System32\conhost.exe C:\Windows\system32\conhost.exe 0xffffffff -ForceV1 | |
Source: C:\Windows\System32\cmd.exe | Process created: C:\Windows\System32\tasklist.exe tasklist | |
Source: C:\Users\user\AppData\Local\Programs\KyrazonGodot\KyrazonGodot.exe | Process created: C:\Windows\System32\cmd.exe C:\Windows\system32\cmd.exe /d /s /c "tasklist" | |
Source: C:\Windows\System32\cmd.exe | Process created: C:\Windows\System32\conhost.exe C:\Windows\system32\conhost.exe 0xffffffff -ForceV1 | |
Source: C:\Windows\System32\cmd.exe | Process created: C:\Windows\System32\tasklist.exe tasklist | |
Source: C:\Users\user\AppData\Local\Programs\KyrazonGodot\KyrazonGodot.exe | Process created: C:\Users\user\AppData\Local\Programs\KyrazonGodot\KyrazonGodot.exe "C:\Users\user\AppData\Local\Programs\KyrazonGodot\KyrazonGodot.exe" --type=utility --utility-sub-type=network.mojom.NetworkService --lang=en-GB --service-sandbox-type=none --user-data-dir="C:\Users\user\AppData\Roaming\KyrazonGodot" --mojo-platform-channel-handle=2228 --field-trial-handle=1744,i,17217612992806517809,8679626120337516312,262144 --disable-features=SpareRendererForSitePerProcess,WinDelaySpellcheckServiceInit,WinRetrieveSuggestionsOnlyOnDemand /prefetch:8 | |
Source: C:\Users\user\AppData\Local\Programs\KyrazonGodot\KyrazonGodot.exe | Process created: C:\Windows\System32\cmd.exe C:\Windows\system32\cmd.exe /d /s /c "tasklist" | |
Source: C:\Windows\System32\cmd.exe | Process created: C:\Windows\System32\conhost.exe C:\Windows\system32\conhost.exe 0xffffffff -ForceV1 | |
Source: C:\Users\user\AppData\Local\Programs\KyrazonGodot\KyrazonGodot.exe | Process created: C:\Windows\System32\cmd.exe C:\Windows\system32\cmd.exe /d /s /c "tasklist" | |
Source: C:\Users\user\AppData\Local\Programs\KyrazonGodot\KyrazonGodot.exe | Process created: C:\Windows\System32\cmd.exe C:\Windows\system32\cmd.exe /d /s /c "tasklist" | |
Source: C:\Windows\System32\cmd.exe | Process created: C:\Windows\System32\conhost.exe C:\Windows\system32\conhost.exe 0xffffffff -ForceV1 | |
Source: C:\Users\user\AppData\Local\Programs\KyrazonGodot\KyrazonGodot.exe | Process created: C:\Windows\System32\cmd.exe C:\Windows\system32\cmd.exe /d /s /c "where /r . data.sqlite" | |
Source: C:\Windows\System32\cmd.exe | Process created: C:\Windows\System32\conhost.exe C:\Windows\system32\conhost.exe 0xffffffff -ForceV1 | |
Source: C:\Windows\System32\cmd.exe | Process created: C:\Windows\System32\conhost.exe C:\Windows\system32\conhost.exe 0xffffffff -ForceV1 | |
Source: C:\Windows\System32\cmd.exe | Process created: C:\Windows\System32\tasklist.exe tasklist | |
Source: C:\Windows\System32\cmd.exe | Process created: C:\Windows\System32\tasklist.exe tasklist | |
Source: C:\Windows\System32\cmd.exe | Process created: C:\Windows\System32\tasklist.exe tasklist | |
Source: C:\Windows\System32\cmd.exe | Process created: C:\Windows\System32\where.exe where /r . data.sqlite | |
Source: C:\Users\user\AppData\Local\Programs\KyrazonGodot\KyrazonGodot.exe | Process created: C:\Windows\System32\cmd.exe C:\Windows\system32\cmd.exe /d /s /c "tasklist" | |
Source: C:\Windows\System32\cmd.exe | Process created: C:\Windows\System32\conhost.exe C:\Windows\system32\conhost.exe 0xffffffff -ForceV1 | |
Source: C:\Windows\System32\cmd.exe | Process created: C:\Windows\System32\tasklist.exe tasklist | |
Source: C:\Users\user\AppData\Local\Programs\KyrazonGodot\KyrazonGodot.exe | Process created: C:\Windows\System32\cmd.exe C:\Windows\system32\cmd.exe /d /s /c "tasklist" | |
Source: C:\Windows\System32\cmd.exe | Process created: C:\Windows\System32\conhost.exe C:\Windows\system32\conhost.exe 0xffffffff -ForceV1 | |
Source: C:\Windows\System32\cmd.exe | Process created: C:\Windows\System32\tasklist.exe tasklist | |
Source: C:\Users\user\AppData\Local\Programs\KyrazonGodot\KyrazonGodot.exe | Process created: C:\Windows\System32\cmd.exe C:\Windows\system32\cmd.exe /d /s /c "tasklist" | |
Source: C:\Windows\System32\cmd.exe | Process created: C:\Windows\System32\conhost.exe C:\Windows\system32\conhost.exe 0xffffffff -ForceV1 | |
Source: C:\Windows\System32\cmd.exe | Process created: C:\Windows\System32\conhost.exe C:\Windows\system32\conhost.exe 0xffffffff -ForceV1 | |
Source: C:\Windows\System32\cmd.exe | Process created: C:\Windows\System32\tasklist.exe tasklist | |
Source: C:\Users\user\AppData\Local\Programs\KyrazonGodot\KyrazonGodot.exe | Process created: C:\Windows\System32\cmd.exe C:\Windows\system32\cmd.exe /d /s /c "tasklist" | |
Source: C:\Windows\System32\cmd.exe | Process created: C:\Windows\System32\conhost.exe C:\Windows\system32\conhost.exe 0xffffffff -ForceV1 | |
Source: C:\Windows\System32\cmd.exe | Process created: C:\Windows\System32\tasklist.exe tasklist | |
Source: C:\Users\user\AppData\Local\Programs\KyrazonGodot\KyrazonGodot.exe | Process created: C:\Windows\System32\cmd.exe C:\Windows\system32\cmd.exe /d /s /c "tasklist" | |
Source: C:\Windows\System32\cmd.exe | Process created: C:\Windows\System32\conhost.exe C:\Windows\system32\conhost.exe 0xffffffff -ForceV1 | |
Source: C:\Windows\System32\cmd.exe | Process created: C:\Windows\System32\tasklist.exe tasklist | |
Source: C:\Users\user\AppData\Local\Programs\KyrazonGodot\KyrazonGodot.exe | Process created: C:\Windows\System32\cmd.exe C:\Windows\system32\cmd.exe /d /s /c "tasklist" | |
Source: C:\Windows\System32\cmd.exe | Process created: C:\Windows\System32\conhost.exe C:\Windows\system32\conhost.exe 0xffffffff -ForceV1 | |
Source: C:\Windows\System32\cmd.exe | Process created: C:\Windows\System32\tasklist.exe tasklist | |
Source: C:\Users\user\AppData\Local\Programs\KyrazonGodot\KyrazonGodot.exe | Process created: C:\Windows\System32\cmd.exe C:\Windows\system32\cmd.exe /d /s /c "tasklist" | |
Source: C:\Windows\System32\cmd.exe | Process created: C:\Windows\System32\conhost.exe C:\Windows\system32\conhost.exe 0xffffffff -ForceV1 | |
Source: C:\Windows\System32\cmd.exe | Process created: C:\Windows\System32\tasklist.exe tasklist | |
Source: C:\Users\user\AppData\Local\Programs\KyrazonGodot\KyrazonGodot.exe | Process created: C:\Windows\System32\cmd.exe C:\Windows\system32\cmd.exe /d /s /c "tasklist" | |
Source: C:\Windows\System32\cmd.exe | Process created: C:\Windows\System32\conhost.exe C:\Windows\system32\conhost.exe 0xffffffff -ForceV1 | |
Source: C:\Windows\System32\cmd.exe | Process created: C:\Windows\System32\tasklist.exe tasklist | |
Source: C:\Users\user\AppData\Local\Programs\KyrazonGodot\KyrazonGodot.exe | Process created: C:\Windows\System32\cmd.exe C:\Windows\system32\cmd.exe /d /s /c "tasklist" | |
Source: C:\Windows\System32\cmd.exe | Process created: C:\Windows\System32\conhost.exe C:\Windows\system32\conhost.exe 0xffffffff -ForceV1 | |
Source: C:\Windows\System32\cmd.exe | Process created: C:\Windows\System32\tasklist.exe tasklist | |
Source: C:\Users\user\AppData\Local\Programs\KyrazonGodot\KyrazonGodot.exe | Process created: C:\Windows\System32\cmd.exe C:\Windows\system32\cmd.exe /d /s /c "tasklist" | |
Source: C:\Windows\System32\cmd.exe | Process created: C:\Windows\System32\conhost.exe C:\Windows\system32\conhost.exe 0xffffffff -ForceV1 | |
Source: C:\Users\user\AppData\Local\Programs\KyrazonGodot\KyrazonGodot.exe | Process created: C:\Windows\System32\Conhost.exe C:\Windows\system32\conhost.exe 0xffffffff -ForceV1 | |
Source: C:\Users\user\AppData\Local\Programs\KyrazonGodot\KyrazonGodot.exe | Process created: C:\Windows\System32\Conhost.exe C:\Windows\system32\conhost.exe 0xffffffff -ForceV1 | |
Source: C:\Windows\System32\cmd.exe | Process created: C:\Windows\System32\Conhost.exe C:\Windows\system32\conhost.exe 0xffffffff -ForceV1 | |
Source: C:\Users\user\AppData\Local\Programs\KyrazonGodot\KyrazonGodot.exe | Process created: C:\Windows\System32\Conhost.exe C:\Windows\system32\conhost.exe 0xffffffff -ForceV1 | |
Source: C:\Users\user\AppData\Local\Programs\KyrazonGodot\KyrazonGodot.exe | Process created: C:\Windows\System32\Conhost.exe C:\Windows\system32\conhost.exe 0xffffffff -ForceV1 | |
Source: C:\Users\user\AppData\Local\Programs\KyrazonGodot\KyrazonGodot.exe | Process created: C:\Windows\System32\Conhost.exe C:\Windows\system32\conhost.exe 0xffffffff -ForceV1 | |
Source: C:\Windows\System32\cmd.exe | Process created: C:\Windows\System32\Conhost.exe C:\Windows\system32\conhost.exe 0xffffffff -ForceV1 | |
Source: C:\Windows\System32\tasklist.exe | Process created: C:\Windows\System32\Conhost.exe C:\Windows\system32\conhost.exe 0xffffffff -ForceV1 | |
Source: C:\Windows\System32\tasklist.exe | Process created: C:\Windows\System32\Conhost.exe C:\Windows\system32\conhost.exe 0xffffffff -ForceV1 | |
Source: C:\Users\user\AppData\Local\Programs\KyrazonGodot\KyrazonGodot.exe | Process created: C:\Windows\System32\Conhost.exe C:\Windows\system32\conhost.exe 0xffffffff -ForceV1 | |
Source: C:\Windows\System32\Conhost.exe | Process created: C:\Windows\System32\Conhost.exe C:\Windows\system32\conhost.exe 0xffffffff -ForceV1 | |
Source: C:\Users\user\AppData\Local\Programs\KyrazonGodot\KyrazonGodot.exe | Process created: C:\Windows\System32\Conhost.exe C:\Windows\system32\conhost.exe 0xffffffff -ForceV1 | |
Source: C:\Windows\System32\tasklist.exe | Process created: C:\Windows\System32\Conhost.exe C:\Windows\system32\conhost.exe 0xffffffff -ForceV1 | |
Source: C:\Users\user\AppData\Local\Programs\KyrazonGodot\KyrazonGodot.exe | Process created: C:\Windows\System32\Conhost.exe C:\Windows\system32\conhost.exe 0xffffffff -ForceV1 | |
Source: C:\Windows\System32\tasklist.exe | Process created: C:\Windows\System32\Conhost.exe C:\Windows\system32\conhost.exe 0xffffffff -ForceV1 | |
Source: C:\Windows\System32\Conhost.exe | Process created: C:\Windows\System32\Conhost.exe C:\Windows\system32\conhost.exe 0xffffffff -ForceV1 | |
Source: C:\Windows\System32\Conhost.exe | Process created: C:\Windows\System32\Conhost.exe C:\Windows\system32\conhost.exe 0xffffffff -ForceV1 | |
Source: C:\Users\user\AppData\Local\Programs\KyrazonGodot\KyrazonGodot.exe | Process created: C:\Windows\System32\Conhost.exe C:\Windows\system32\conhost.exe 0xffffffff -ForceV1 | |
Source: C:\Windows\System32\tasklist.exe | Process created: C:\Windows\System32\Conhost.exe C:\Windows\system32\conhost.exe 0xffffffff -ForceV1 | |
Source: C:\Windows\System32\tasklist.exe | Process created: C:\Windows\System32\Conhost.exe C:\Windows\system32\conhost.exe 0xffffffff -ForceV1 | |
Source: C:\Windows\System32\Conhost.exe | Process created: C:\Windows\System32\Conhost.exe C:\Windows\system32\conhost.exe 0xffffffff -ForceV1 | |
Source: C:\Windows\System32\cmd.exe | Process created: C:\Windows\System32\Conhost.exe C:\Windows\system32\conhost.exe 0xffffffff -ForceV1 | |
Source: C:\Users\user\AppData\Local\Programs\KyrazonGodot\KyrazonGodot.exe | Process created: C:\Windows\System32\Conhost.exe C:\Windows\system32\conhost.exe 0xffffffff -ForceV1 | |
Source: C:\Users\user\AppData\Local\Programs\KyrazonGodot\KyrazonGodot.exe | Process created: C:\Windows\System32\Conhost.exe C:\Windows\system32\conhost.exe 0xffffffff -ForceV1 | |
Source: C:\Users\user\AppData\Local\Programs\KyrazonGodot\KyrazonGodot.exe | Process created: C:\Windows\System32\Conhost.exe C:\Windows\system32\conhost.exe 0xffffffff -ForceV1 | |
Source: C:\Users\user\AppData\Local\Programs\KyrazonGodot\KyrazonGodot.exe | Process created: C:\Windows\System32\Conhost.exe C:\Windows\system32\conhost.exe 0xffffffff -ForceV1 | |
Source: C:\Windows\System32\cmd.exe | Process created: C:\Windows\System32\Conhost.exe C:\Windows\system32\conhost.exe 0xffffffff -ForceV1 | |
Source: C:\Windows\System32\conhost.exe | Process created: C:\Windows\System32\Conhost.exe C:\Windows\system32\conhost.exe 0xffffffff -ForceV1 | |
Source: C:\Windows\System32\Conhost.exe | Process created: C:\Windows\System32\Conhost.exe C:\Windows\system32\conhost.exe 0xffffffff -ForceV1 | |
Source: C:\Users\user\AppData\Local\Programs\KyrazonGodot\KyrazonGodot.exe | Process created: C:\Windows\System32\Conhost.exe C:\Windows\system32\conhost.exe 0xffffffff -ForceV1 | |
Source: C:\Windows\System32\conhost.exe | Process created: C:\Windows\System32\Conhost.exe C:\Windows\system32\conhost.exe 0xffffffff -ForceV1 | |
Source: C:\Windows\System32\cmd.exe | Process created: C:\Windows\System32\Conhost.exe C:\Windows\system32\conhost.exe 0xffffffff -ForceV1 | |
Source: C:\Windows\System32\Conhost.exe | Process created: C:\Windows\System32\Conhost.exe C:\Windows\system32\conhost.exe 0xffffffff -ForceV1 | |
Source: C:\Windows\System32\Conhost.exe | Process created: C:\Windows\System32\Conhost.exe C:\Windows\system32\conhost.exe 0xffffffff -ForceV1 | |
Source: C:\Windows\System32\Conhost.exe | Process created: C:\Windows\System32\Conhost.exe C:\Windows\system32\conhost.exe 0xffffffff -ForceV1 | |
Source: C:\Windows\System32\Conhost.exe | Process created: C:\Windows\System32\Conhost.exe C:\Windows\system32\conhost.exe 0xffffffff -ForceV1 | |
Source: C:\Users\user\AppData\Local\Programs\KyrazonGodot\KyrazonGodot.exe | Process created: C:\Windows\System32\Conhost.exe C:\Windows\system32\conhost.exe 0xffffffff -ForceV1 | |
Source: C:\Windows\System32\conhost.exe | Process created: C:\Windows\System32\Conhost.exe C:\Windows\system32\conhost.exe 0xffffffff -ForceV1 | |
Source: C:\Users\user\Desktop\KyrazonSetup.exe | Process created: C:\Windows\SysWOW64\cmd.exe "C:\Windows\system32\cmd.exe" /c tasklist /FI "USERNAME eq %USERNAME%" /FI "IMAGENAME eq KyrazonGodot.exe" /FO csv | "C:\Windows\system32\find.exe" "KyrazonGodot.exe" | Jump to behavior |
Source: C:\Windows\SysWOW64\cmd.exe | Process created: C:\Windows\SysWOW64\tasklist.exe tasklist /FI "USERNAME eq user" /FI "IMAGENAME eq KyrazonGodot.exe" /FO csv | Jump to behavior |
Source: C:\Windows\SysWOW64\cmd.exe | Process created: C:\Windows\SysWOW64\find.exe "C:\Windows\system32\find.exe" "KyrazonGodot.exe" | Jump to behavior |
Source: C:\Users\user\AppData\Local\Programs\KyrazonGodot\KyrazonGodot.exe | Process created: C:\Users\user\AppData\Local\Programs\KyrazonGodot\KyrazonGodot.exe "C:\Users\user\AppData\Local\Programs\KyrazonGodot\KyrazonGodot.exe" --type=gpu-process --user-data-dir="C:\Users\user\AppData\Roaming\KyrazonGodot" --gpu-preferences=WAAAAAAAAADgAAAMAAAAAAAAAAAAAAAAAABgAAAAAAA4AAAAAAAAAAAAAAAEAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAGAAAAAAAAAAYAAAAAAAAAAgAAAAAAAAACAAAAAAAAAAIAAAAAAAAAA== --mojo-platform-channel-handle=1772 --field-trial-handle=1776,i,4294901941177378234,17718125093265605642,262144 --disable-features=SpareRendererForSitePerProcess,WinDelaySpellcheckServiceInit,WinRetrieveSuggestionsOnlyOnDemand /prefetch:2 | Jump to behavior |
Source: C:\Users\user\AppData\Local\Programs\KyrazonGodot\KyrazonGodot.exe | Process created: C:\Users\user\AppData\Local\Programs\KyrazonGodot\resources\app.asar.unpacked\node_modules\windows-shortcuts\lib\shortcut\Shortcut.exe C:\Users\user\AppData\Local\Programs\KyrazonGodot\resources\app.asar.unpacked\node_modules\windows-shortcuts\lib\shortcut\Shortcut.exe /A:C "/F:C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\KyrazonGodot.lnk" /T:C:\Users\user\AppData\Local\Programs\KyrazonGodot\KyrazonGodot.exe | Jump to behavior |
Source: C:\Users\user\AppData\Local\Programs\KyrazonGodot\KyrazonGodot.exe | Process created: C:\Windows\System32\cmd.exe C:\Windows\system32\cmd.exe /d /s /c "tasklist" | Jump to behavior |
Source: C:\Users\user\AppData\Local\Programs\KyrazonGodot\KyrazonGodot.exe | Process created: C:\Windows\System32\cmd.exe C:\Windows\system32\cmd.exe /d /s /c "tasklist" | Jump to behavior |
Source: C:\Users\user\AppData\Local\Programs\KyrazonGodot\KyrazonGodot.exe | Process created: C:\Windows\System32\cmd.exe C:\Windows\system32\cmd.exe /d /s /c "tasklist" | Jump to behavior |
Source: C:\Users\user\AppData\Local\Programs\KyrazonGodot\KyrazonGodot.exe | Process created: C:\Windows\System32\cmd.exe C:\Windows\system32\cmd.exe /d /s /c "tasklist" | Jump to behavior |
Source: C:\Users\user\AppData\Local\Programs\KyrazonGodot\KyrazonGodot.exe | Process created: C:\Windows\System32\cmd.exe C:\Windows\system32\cmd.exe /d /s /c "where /r . data.sqlite" | Jump to behavior |
Source: C:\Users\user\AppData\Local\Programs\KyrazonGodot\KyrazonGodot.exe | Process created: C:\Windows\System32\cmd.exe C:\Windows\system32\cmd.exe /d /s /c "tasklist" | Jump to behavior |
Source: C:\Users\user\AppData\Local\Programs\KyrazonGodot\KyrazonGodot.exe | Process created: C:\Users\user\AppData\Local\Programs\KyrazonGodot\KyrazonGodot.exe "C:\Users\user\AppData\Local\Programs\KyrazonGodot\KyrazonGodot.exe" --type=utility --utility-sub-type=network.mojom.NetworkService --lang=en-GB --service-sandbox-type=none --user-data-dir="C:\Users\user\AppData\Roaming\KyrazonGodot" --mojo-platform-channel-handle=2364 --field-trial-handle=1776,i,4294901941177378234,17718125093265605642,262144 --disable-features=SpareRendererForSitePerProcess,WinDelaySpellcheckServiceInit,WinRetrieveSuggestionsOnlyOnDemand /prefetch:8 | Jump to behavior |
Source: C:\Users\user\AppData\Local\Programs\KyrazonGodot\KyrazonGodot.exe | Process created: C:\Windows\System32\cmd.exe C:\Windows\system32\cmd.exe /d /s /c "tasklist" | Jump to behavior |
Source: C:\Users\user\AppData\Local\Programs\KyrazonGodot\KyrazonGodot.exe | Process created: C:\Windows\System32\cmd.exe C:\Windows\system32\cmd.exe /d /s /c "tasklist" | Jump to behavior |
Source: C:\Users\user\AppData\Local\Programs\KyrazonGodot\KyrazonGodot.exe | Process created: C:\Windows\System32\cmd.exe C:\Windows\system32\cmd.exe /d /s /c "tasklist" | Jump to behavior |
Source: C:\Users\user\AppData\Local\Programs\KyrazonGodot\KyrazonGodot.exe | Process created: C:\Windows\System32\cmd.exe C:\Windows\system32\cmd.exe /d /s /c "tasklist" | Jump to behavior |
Source: C:\Users\user\AppData\Local\Programs\KyrazonGodot\KyrazonGodot.exe | Process created: C:\Windows\System32\cmd.exe C:\Windows\system32\cmd.exe /d /s /c "tasklist" | Jump to behavior |
Source: C:\Users\user\AppData\Local\Programs\KyrazonGodot\KyrazonGodot.exe | Process created: C:\Windows\System32\cmd.exe C:\Windows\system32\cmd.exe /d /s /c "tasklist" | Jump to behavior |
Source: C:\Users\user\AppData\Local\Programs\KyrazonGodot\KyrazonGodot.exe | Process created: C:\Windows\System32\cmd.exe C:\Windows\system32\cmd.exe /d /s /c "tasklist" | Jump to behavior |
Source: C:\Users\user\AppData\Local\Programs\KyrazonGodot\KyrazonGodot.exe | Process created: C:\Windows\System32\cmd.exe C:\Windows\system32\cmd.exe /d /s /c "tasklist" | Jump to behavior |
Source: C:\Users\user\AppData\Local\Programs\KyrazonGodot\KyrazonGodot.exe | Process created: C:\Windows\System32\cmd.exe C:\Windows\system32\cmd.exe /d /s /c "tasklist" | Jump to behavior |
Source: C:\Users\user\AppData\Local\Programs\KyrazonGodot\KyrazonGodot.exe | Process created: C:\Windows\System32\cmd.exe C:\Windows\system32\cmd.exe /d /s /c "tasklist" | Jump to behavior |
Source: C:\Users\user\AppData\Local\Programs\KyrazonGodot\KyrazonGodot.exe | Process created: C:\Windows\System32\tasklist.exe tasklist | Jump to behavior |
Source: C:\Users\user\AppData\Local\Programs\KyrazonGodot\KyrazonGodot.exe | Process created: unknown unknown | Jump to behavior |
Source: C:\Users\user\AppData\Local\Programs\KyrazonGodot\KyrazonGodot.exe | Process created: unknown unknown | Jump to behavior |
Source: C:\Users\user\AppData\Local\Programs\KyrazonGodot\KyrazonGodot.exe | Process created: C:\Windows\System32\cmd.exe C:\Windows\system32\cmd.exe /d /s /c "tasklist" | Jump to behavior |
Source: C:\Users\user\AppData\Local\Programs\KyrazonGodot\KyrazonGodot.exe | Process created: unknown unknown | Jump to behavior |
Source: C:\Users\user\AppData\Local\Programs\KyrazonGodot\KyrazonGodot.exe | Process created: unknown unknown | Jump to behavior |
Source: C:\Users\user\AppData\Local\Programs\KyrazonGodot\KyrazonGodot.exe | Process created: unknown unknown | Jump to behavior |
Source: C:\Users\user\AppData\Local\Programs\KyrazonGodot\KyrazonGodot.exe | Process created: unknown unknown | Jump to behavior |
Source: C:\Users\user\AppData\Local\Programs\KyrazonGodot\KyrazonGodot.exe | Process created: C:\Windows\System32\tasklist.exe tasklist | Jump to behavior |
Source: C:\Users\user\AppData\Local\Programs\KyrazonGodot\KyrazonGodot.exe | Process created: C:\Windows\System32\tasklist.exe tasklist | Jump to behavior |
Source: C:\Users\user\AppData\Local\Programs\KyrazonGodot\KyrazonGodot.exe | Process created: C:\Windows\System32\Conhost.exe C:\Windows\system32\conhost.exe 0xffffffff -ForceV1 | Jump to behavior |
Source: C:\Users\user\AppData\Local\Programs\KyrazonGodot\KyrazonGodot.exe | Process created: unknown unknown | Jump to behavior |
Source: C:\Users\user\AppData\Local\Programs\KyrazonGodot\KyrazonGodot.exe | Process created: unknown unknown | Jump to behavior |
Source: C:\Users\user\AppData\Local\Programs\KyrazonGodot\KyrazonGodot.exe | Process created: unknown unknown | Jump to behavior |
Source: C:\Users\user\AppData\Local\Programs\KyrazonGodot\KyrazonGodot.exe | Process created: unknown unknown | Jump to behavior |
Source: C:\Users\user\AppData\Local\Programs\KyrazonGodot\KyrazonGodot.exe | Process created: unknown unknown | Jump to behavior |
Source: C:\Users\user\AppData\Local\Programs\KyrazonGodot\KyrazonGodot.exe | Process created: unknown unknown | Jump to behavior |
Source: C:\Users\user\AppData\Local\Programs\KyrazonGodot\KyrazonGodot.exe | Process created: unknown unknown | Jump to behavior |
Source: C:\Users\user\AppData\Local\Programs\KyrazonGodot\KyrazonGodot.exe | Process created: unknown unknown | Jump to behavior |
Source: C:\Users\user\AppData\Local\Programs\KyrazonGodot\KyrazonGodot.exe | Process created: unknown unknown | Jump to behavior |
Source: C:\Users\user\AppData\Local\Programs\KyrazonGodot\KyrazonGodot.exe | Process created: C:\Windows\System32\tasklist.exe tasklist | Jump to behavior |
Source: C:\Users\user\AppData\Local\Programs\KyrazonGodot\KyrazonGodot.exe | Process created: unknown unknown | Jump to behavior |
Source: C:\Users\user\AppData\Local\Programs\KyrazonGodot\KyrazonGodot.exe | Process created: unknown unknown | Jump to behavior |
Source: C:\Users\user\AppData\Local\Programs\KyrazonGodot\KyrazonGodot.exe | Process created: unknown unknown | Jump to behavior |
Source: C:\Users\user\AppData\Local\Programs\KyrazonGodot\KyrazonGodot.exe | Process created: unknown unknown | Jump to behavior |
Source: C:\Users\user\AppData\Local\Programs\KyrazonGodot\KyrazonGodot.exe | Process created: unknown unknown | Jump to behavior |
Source: C:\Users\user\AppData\Local\Programs\KyrazonGodot\KyrazonGodot.exe | Process created: unknown unknown | Jump to behavior |
Source: C:\Users\user\AppData\Local\Programs\KyrazonGodot\KyrazonGodot.exe | Process created: unknown unknown | Jump to behavior |
Source: C:\Users\user\AppData\Local\Programs\KyrazonGodot\KyrazonGodot.exe | Process created: C:\Windows\System32\tasklist.exe tasklist | Jump to behavior |
Source: C:\Users\user\AppData\Local\Programs\KyrazonGodot\KyrazonGodot.exe | Process created: unknown unknown | Jump to behavior |
Source: C:\Users\user\AppData\Local\Programs\KyrazonGodot\KyrazonGodot.exe | Process created: unknown unknown | Jump to behavior |
Source: C:\Users\user\AppData\Local\Programs\KyrazonGodot\KyrazonGodot.exe | Process created: unknown unknown | Jump to behavior |
Source: C:\Users\user\AppData\Local\Programs\KyrazonGodot\KyrazonGodot.exe | Process created: unknown unknown | Jump to behavior |
Source: C:\Users\user\AppData\Local\Programs\KyrazonGodot\KyrazonGodot.exe | Process created: C:\Windows\System32\cmd.exe C:\Windows\system32\cmd.exe /d /s /c "tasklist" | Jump to behavior |
Source: C:\Users\user\AppData\Local\Programs\KyrazonGodot\KyrazonGodot.exe | Process created: unknown unknown | Jump to behavior |
Source: C:\Users\user\AppData\Local\Programs\KyrazonGodot\KyrazonGodot.exe | Process created: unknown unknown | Jump to behavior |
Source: C:\Users\user\AppData\Local\Programs\KyrazonGodot\KyrazonGodot.exe | Process created: unknown unknown | Jump to behavior |
Source: C:\Users\user\AppData\Local\Programs\KyrazonGodot\KyrazonGodot.exe | Process created: unknown unknown | Jump to behavior |
Source: C:\Users\user\AppData\Local\Programs\KyrazonGodot\KyrazonGodot.exe | Process created: unknown unknown | Jump to behavior |
Source: C:\Users\user\AppData\Local\Programs\KyrazonGodot\KyrazonGodot.exe | Process created: unknown unknown | Jump to behavior |
Source: C:\Users\user\AppData\Local\Programs\KyrazonGodot\KyrazonGodot.exe | Process created: unknown unknown | Jump to behavior |
Source: C:\Users\user\AppData\Local\Programs\KyrazonGodot\KyrazonGodot.exe | Process created: unknown unknown | Jump to behavior |
Source: C:\Users\user\AppData\Local\Programs\KyrazonGodot\KyrazonGodot.exe | Process created: C:\Windows\System32\cmd.exe C:\Windows\system32\cmd.exe /d /s /c "tasklist" | Jump to behavior |
Source: C:\Users\user\AppData\Local\Programs\KyrazonGodot\KyrazonGodot.exe | Process created: unknown unknown | Jump to behavior |
Source: C:\Users\user\AppData\Local\Programs\KyrazonGodot\KyrazonGodot.exe | Process created: unknown unknown | Jump to behavior |
Source: C:\Users\user\AppData\Local\Programs\KyrazonGodot\KyrazonGodot.exe | Process created: unknown unknown | Jump to behavior |
Source: C:\Users\user\AppData\Local\Programs\KyrazonGodot\KyrazonGodot.exe | Process created: C:\Windows\System32\conhost.exe C:\Windows\system32\conhost.exe 0xffffffff -ForceV1 | Jump to behavior |
Source: C:\Users\user\AppData\Local\Programs\KyrazonGodot\KyrazonGodot.exe | Process created: C:\Windows\System32\cmd.exe C:\Windows\system32\cmd.exe /d /s /c "tasklist" | Jump to behavior |
Source: C:\Users\user\AppData\Local\Programs\KyrazonGodot\KyrazonGodot.exe | Process created: unknown unknown | Jump to behavior |
Source: C:\Users\user\AppData\Local\Programs\KyrazonGodot\KyrazonGodot.exe | Process created: unknown unknown | Jump to behavior |
Source: C:\Users\user\AppData\Local\Programs\KyrazonGodot\KyrazonGodot.exe | Process created: C:\Windows\System32\Conhost.exe C:\Windows\system32\conhost.exe 0xffffffff -ForceV1 | Jump to behavior |
Source: C:\Users\user\AppData\Local\Programs\KyrazonGodot\KyrazonGodot.exe | Process created: unknown unknown | Jump to behavior |
Source: C:\Users\user\AppData\Local\Programs\KyrazonGodot\KyrazonGodot.exe | Process created: C:\Windows\System32\conhost.exe C:\Windows\system32\conhost.exe 0xffffffff -ForceV1 | Jump to behavior |
Source: C:\Windows\System32\cmd.exe | Process created: C:\Windows\System32\tasklist.exe tasklist | |
Source: C:\Windows\System32\cmd.exe | Process created: C:\Windows\System32\tasklist.exe tasklist | |
Source: C:\Windows\System32\cmd.exe | Process created: C:\Windows\System32\tasklist.exe tasklist | |
Source: C:\Windows\System32\cmd.exe | Process created: C:\Windows\System32\tasklist.exe tasklist | |
Source: C:\Windows\System32\cmd.exe | Process created: C:\Windows\System32\where.exe where /r . data.sqlite | |
Source: C:\Windows\System32\cmd.exe | Process created: C:\Windows\System32\tasklist.exe tasklist | |
Source: C:\Windows\System32\cmd.exe | Process created: C:\Windows\System32\tasklist.exe tasklist | |
Source: C:\Windows\System32\cmd.exe | Process created: C:\Windows\System32\tasklist.exe tasklist | |
Source: C:\Windows\System32\cmd.exe | Process created: C:\Windows\System32\tasklist.exe tasklist | |
Source: C:\Users\user\AppData\Local\Programs\KyrazonGodot\KyrazonGodot.exe | Process created: C:\Users\user\AppData\Local\Programs\KyrazonGodot\KyrazonGodot.exe "C:\Users\user\AppData\Local\Programs\KyrazonGodot\KyrazonGodot.exe" --type=gpu-process --user-data-dir="C:\Users\user\AppData\Roaming\KyrazonGodot" --gpu-preferences=WAAAAAAAAADgAAAMAAAAAAAAAAAAAAAAAABgAAAAAAA4AAAAAAAAAAAAAAAEAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAGAAAAAAAAAAYAAAAAAAAAAgAAAAAAAAACAAAAAAAAAAIAAAAAAAAAA== --mojo-platform-channel-handle=1740 --field-trial-handle=1744,i,17217612992806517809,8679626120337516312,262144 --disable-features=SpareRendererForSitePerProcess,WinDelaySpellcheckServiceInit,WinRetrieveSuggestionsOnlyOnDemand /prefetch:2 | |
Source: C:\Users\user\AppData\Local\Programs\KyrazonGodot\KyrazonGodot.exe | Process created: C:\Windows\System32\cmd.exe C:\Windows\system32\cmd.exe /d /s /c "tasklist" | |
Source: C:\Users\user\AppData\Local\Programs\KyrazonGodot\KyrazonGodot.exe | Process created: C:\Users\user\AppData\Local\Programs\KyrazonGodot\KyrazonGodot.exe "C:\Users\user\AppData\Local\Programs\KyrazonGodot\KyrazonGodot.exe" --type=utility --utility-sub-type=network.mojom.NetworkService --lang=en-GB --service-sandbox-type=none --user-data-dir="C:\Users\user\AppData\Roaming\KyrazonGodot" --mojo-platform-channel-handle=2228 --field-trial-handle=1744,i,17217612992806517809,8679626120337516312,262144 --disable-features=SpareRendererForSitePerProcess,WinDelaySpellcheckServiceInit,WinRetrieveSuggestionsOnlyOnDemand /prefetch:8 | |
Source: C:\Users\user\AppData\Local\Programs\KyrazonGodot\KyrazonGodot.exe | Process created: C:\Windows\System32\cmd.exe C:\Windows\system32\cmd.exe /d /s /c "tasklist" | |
Source: C:\Users\user\AppData\Local\Programs\KyrazonGodot\KyrazonGodot.exe | Process created: C:\Windows\System32\cmd.exe C:\Windows\system32\cmd.exe /d /s /c "tasklist" | |
Source: C:\Users\user\AppData\Local\Programs\KyrazonGodot\KyrazonGodot.exe | Process created: C:\Windows\System32\cmd.exe C:\Windows\system32\cmd.exe /d /s /c "tasklist" | |
Source: C:\Users\user\AppData\Local\Programs\KyrazonGodot\KyrazonGodot.exe | Process created: C:\Windows\System32\cmd.exe C:\Windows\system32\cmd.exe /d /s /c "where /r . data.sqlite" | |
Source: C:\Users\user\AppData\Local\Programs\KyrazonGodot\KyrazonGodot.exe | Process created: C:\Windows\System32\cmd.exe C:\Windows\system32\cmd.exe /d /s /c "tasklist" | |
Source: C:\Users\user\AppData\Local\Programs\KyrazonGodot\KyrazonGodot.exe | Process created: C:\Windows\System32\cmd.exe C:\Windows\system32\cmd.exe /d /s /c "tasklist" | |
Source: C:\Users\user\AppData\Local\Programs\KyrazonGodot\KyrazonGodot.exe | Process created: C:\Windows\System32\cmd.exe C:\Windows\system32\cmd.exe /d /s /c "tasklist" | |
Source: C:\Users\user\AppData\Local\Programs\KyrazonGodot\KyrazonGodot.exe | Process created: C:\Windows\System32\cmd.exe C:\Windows\system32\cmd.exe /d /s /c "tasklist" | |
Source: C:\Users\user\AppData\Local\Programs\KyrazonGodot\KyrazonGodot.exe | Process created: C:\Windows\System32\cmd.exe C:\Windows\system32\cmd.exe /d /s /c "tasklist" | |
Source: C:\Users\user\AppData\Local\Programs\KyrazonGodot\KyrazonGodot.exe | Process created: unknown unknown | |
Source: C:\Users\user\AppData\Local\Programs\KyrazonGodot\KyrazonGodot.exe | Process created: unknown unknown | |
Source: C:\Users\user\AppData\Local\Programs\KyrazonGodot\KyrazonGodot.exe | Process created: unknown unknown | |
Source: C:\Users\user\AppData\Local\Programs\KyrazonGodot\KyrazonGodot.exe | Process created: unknown unknown | |
Source: C:\Users\user\AppData\Local\Programs\KyrazonGodot\KyrazonGodot.exe | Process created: unknown unknown | |
Source: C:\Users\user\AppData\Local\Programs\KyrazonGodot\KyrazonGodot.exe | Process created: unknown unknown | |
Source: C:\Users\user\AppData\Local\Programs\KyrazonGodot\KyrazonGodot.exe | Process created: unknown unknown | |
Source: C:\Users\user\AppData\Local\Programs\KyrazonGodot\KyrazonGodot.exe | Process created: C:\Windows\System32\Conhost.exe C:\Windows\system32\conhost.exe 0xffffffff -ForceV1 | |
Source: C:\Users\user\AppData\Local\Programs\KyrazonGodot\KyrazonGodot.exe | Process created: C:\Windows\System32\cmd.exe C:\Windows\system32\cmd.exe /d /s /c "tasklist" | |
Source: C:\Users\user\AppData\Local\Programs\KyrazonGodot\KyrazonGodot.exe | Process created: unknown unknown | |
Source: C:\Users\user\AppData\Local\Programs\KyrazonGodot\KyrazonGodot.exe | Process created: unknown unknown | |
Source: C:\Users\user\AppData\Local\Programs\KyrazonGodot\KyrazonGodot.exe | Process created: unknown unknown | |
Source: C:\Users\user\AppData\Local\Programs\KyrazonGodot\KyrazonGodot.exe | Process created: C:\Windows\System32\Conhost.exe C:\Windows\system32\conhost.exe 0xffffffff -ForceV1 | |
Source: C:\Users\user\AppData\Local\Programs\KyrazonGodot\KyrazonGodot.exe | Process created: C:\Windows\System32\Conhost.exe C:\Windows\system32\conhost.exe 0xffffffff -ForceV1 | |
Source: C:\Users\user\AppData\Local\Programs\KyrazonGodot\KyrazonGodot.exe | Process created: unknown unknown | |
Source: C:\Users\user\AppData\Local\Programs\KyrazonGodot\KyrazonGodot.exe | Process created: unknown unknown | |
Source: C:\Users\user\AppData\Local\Programs\KyrazonGodot\KyrazonGodot.exe | Process created: C:\Windows\System32\Conhost.exe C:\Windows\system32\conhost.exe 0xffffffff -ForceV1 | |
Source: C:\Users\user\AppData\Local\Programs\KyrazonGodot\KyrazonGodot.exe | Process created: unknown unknown | |
Source: C:\Users\user\AppData\Local\Programs\KyrazonGodot\KyrazonGodot.exe | Process created: unknown unknown | |
Source: C:\Users\user\AppData\Local\Programs\KyrazonGodot\KyrazonGodot.exe | Process created: C:\Windows\System32\tasklist.exe tasklist | |
Source: C:\Users\user\AppData\Local\Programs\KyrazonGodot\KyrazonGodot.exe | Process created: unknown unknown | |
Source: C:\Users\user\AppData\Local\Programs\KyrazonGodot\KyrazonGodot.exe | Process created: C:\Windows\System32\cmd.exe C:\Windows\system32\cmd.exe /d /s /c "tasklist" | |
Source: C:\Users\user\AppData\Local\Programs\KyrazonGodot\KyrazonGodot.exe | Process created: unknown unknown | |
Source: C:\Users\user\AppData\Local\Programs\KyrazonGodot\KyrazonGodot.exe | Process created: unknown unknown | |
Source: C:\Users\user\AppData\Local\Programs\KyrazonGodot\KyrazonGodot.exe | Process created: unknown unknown | |
Source: C:\Users\user\AppData\Local\Programs\KyrazonGodot\KyrazonGodot.exe | Process created: unknown unknown | |
Source: C:\Users\user\AppData\Local\Programs\KyrazonGodot\KyrazonGodot.exe | Process created: C:\Windows\System32\cmd.exe C:\Windows\system32\cmd.exe /d /s /c "tasklist" | |
Source: C:\Users\user\AppData\Local\Programs\KyrazonGodot\KyrazonGodot.exe | Process created: C:\Windows\System32\Conhost.exe C:\Windows\system32\conhost.exe 0xffffffff -ForceV1 | |
Source: C:\Users\user\AppData\Local\Programs\KyrazonGodot\KyrazonGodot.exe | Process created: unknown unknown | |
Source: C:\Users\user\AppData\Local\Programs\KyrazonGodot\KyrazonGodot.exe | Process created: unknown unknown | |
Source: C:\Users\user\AppData\Local\Programs\KyrazonGodot\KyrazonGodot.exe | Process created: C:\Windows\System32\Conhost.exe C:\Windows\system32\conhost.exe 0xffffffff -ForceV1 | |
Source: C:\Users\user\AppData\Local\Programs\KyrazonGodot\KyrazonGodot.exe | Process created: unknown unknown | |
Source: C:\Users\user\AppData\Local\Programs\KyrazonGodot\KyrazonGodot.exe | Process created: C:\Windows\System32\tasklist.exe tasklist | |
Source: C:\Users\user\AppData\Local\Programs\KyrazonGodot\KyrazonGodot.exe | Process created: unknown unknown | |
Source: C:\Users\user\AppData\Local\Programs\KyrazonGodot\KyrazonGodot.exe | Process created: unknown unknown | |
Source: C:\Users\user\AppData\Local\Programs\KyrazonGodot\KyrazonGodot.exe | Process created: C:\Windows\System32\cmd.exe C:\Windows\system32\cmd.exe /d /s /c "tasklist" | |
Source: C:\Users\user\AppData\Local\Programs\KyrazonGodot\KyrazonGodot.exe | Process created: unknown unknown | |
Source: C:\Users\user\AppData\Local\Programs\KyrazonGodot\KyrazonGodot.exe | Process created: unknown unknown | |
Source: C:\Users\user\AppData\Local\Programs\KyrazonGodot\KyrazonGodot.exe | Process created: unknown unknown | |
Source: C:\Users\user\AppData\Local\Programs\KyrazonGodot\KyrazonGodot.exe | Process created: unknown unknown | |
Source: C:\Users\user\AppData\Local\Programs\KyrazonGodot\KyrazonGodot.exe | Process created: unknown unknown | |
Source: C:\Users\user\AppData\Local\Programs\KyrazonGodot\KyrazonGodot.exe | Process created: unknown unknown | |
Source: C:\Users\user\AppData\Local\Programs\KyrazonGodot\KyrazonGodot.exe | Process created: unknown unknown | |
Source: C:\Users\user\AppData\Local\Programs\KyrazonGodot\KyrazonGodot.exe | Process created: C:\Windows\System32\conhost.exe C:\Windows\system32\conhost.exe 0xffffffff -ForceV1 | |
Source: C:\Users\user\AppData\Local\Programs\KyrazonGodot\KyrazonGodot.exe | Process created: C:\Windows\System32\Conhost.exe C:\Windows\system32\conhost.exe 0xffffffff -ForceV1 | |
Source: C:\Users\user\AppData\Local\Programs\KyrazonGodot\KyrazonGodot.exe | Process created: unknown unknown | |
Source: C:\Users\user\AppData\Local\Programs\KyrazonGodot\KyrazonGodot.exe | Process created: unknown unknown | |
Source: C:\Users\user\AppData\Local\Programs\KyrazonGodot\KyrazonGodot.exe | Process created: unknown unknown | |
Source: C:\Users\user\AppData\Local\Programs\KyrazonGodot\KyrazonGodot.exe | Process created: C:\Windows\System32\Conhost.exe C:\Windows\system32\conhost.exe 0xffffffff -ForceV1 | |
Source: C:\Users\user\AppData\Local\Programs\KyrazonGodot\KyrazonGodot.exe | Process created: unknown unknown | |
Source: C:\Users\user\AppData\Local\Programs\KyrazonGodot\KyrazonGodot.exe | Process created: C:\Windows\System32\cmd.exe C:\Windows\system32\cmd.exe /d /s /c "tasklist" | |
Source: C:\Users\user\AppData\Local\Programs\KyrazonGodot\KyrazonGodot.exe | Process created: C:\Windows\System32\Conhost.exe C:\Windows\system32\conhost.exe 0xffffffff -ForceV1 | |
Source: C:\Users\user\AppData\Local\Programs\KyrazonGodot\KyrazonGodot.exe | Process created: unknown unknown | |
Source: C:\Users\user\AppData\Local\Programs\KyrazonGodot\KyrazonGodot.exe | Process created: C:\Windows\System32\tasklist.exe tasklist | |
Source: C:\Users\user\AppData\Local\Programs\KyrazonGodot\KyrazonGodot.exe | Process created: unknown unknown | |
Source: C:\Users\user\AppData\Local\Programs\KyrazonGodot\KyrazonGodot.exe | Process created: unknown unknown | |
Source: C:\Users\user\AppData\Local\Programs\KyrazonGodot\KyrazonGodot.exe | Process created: unknown unknown | |
Source: C:\Users\user\AppData\Local\Programs\KyrazonGodot\KyrazonGodot.exe | Process created: unknown unknown | |
Source: C:\Users\user\AppData\Local\Programs\KyrazonGodot\KyrazonGodot.exe | Process created: C:\Windows\System32\Conhost.exe C:\Windows\system32\conhost.exe 0xffffffff -ForceV1 | |
Source: C:\Windows\System32\cmd.exe | Process created: C:\Windows\System32\tasklist.exe tasklist | |
Source: C:\Windows\System32\cmd.exe | Process created: C:\Windows\System32\tasklist.exe tasklist | |
Source: C:\Windows\System32\cmd.exe | Process created: C:\Windows\System32\tasklist.exe tasklist | |
Source: C:\Windows\System32\cmd.exe | Process created: C:\Windows\System32\tasklist.exe tasklist | |
Source: C:\Windows\System32\cmd.exe | Process created: C:\Windows\System32\tasklist.exe tasklist | |
Source: C:\Windows\System32\cmd.exe | Process created: C:\Windows\System32\tasklist.exe tasklist | |
Source: C:\Windows\System32\cmd.exe | Process created: C:\Windows\System32\where.exe where /r . data.sqlite | |
Source: C:\Windows\System32\cmd.exe | Process created: C:\Windows\System32\tasklist.exe tasklist | |
Source: C:\Windows\System32\cmd.exe | Process created: C:\Windows\System32\tasklist.exe tasklist | |
Source: C:\Windows\System32\cmd.exe | Process created: C:\Windows\System32\tasklist.exe tasklist | |
Source: C:\Windows\System32\cmd.exe | Process created: C:\Windows\System32\tasklist.exe tasklist | |
Source: C:\Windows\System32\cmd.exe | Process created: C:\Windows\System32\tasklist.exe tasklist | |
Source: C:\Windows\System32\cmd.exe | Process created: C:\Windows\System32\tasklist.exe tasklist | |
Source: C:\Windows\System32\cmd.exe | Process created: C:\Windows\System32\tasklist.exe tasklist | |
Source: C:\Windows\System32\cmd.exe | Process created: C:\Windows\System32\tasklist.exe tasklist | |
Source: C:\Windows\System32\cmd.exe | Process created: C:\Windows\System32\tasklist.exe tasklist | |
Source: C:\Windows\System32\cmd.exe | Process created: C:\Windows\System32\tasklist.exe tasklist | |
Source: C:\Windows\System32\cmd.exe | Process created: unknown unknown | |
Source: C:\Users\user\Desktop\KyrazonSetup.exe | Section loaded: uxtheme.dll | Jump to behavior |
Source: C:\Users\user\Desktop\KyrazonSetup.exe | Section loaded: userenv.dll | Jump to behavior |
Source: C:\Users\user\Desktop\KyrazonSetup.exe | Section loaded: apphelp.dll | Jump to behavior |
Source: C:\Users\user\Desktop\KyrazonSetup.exe | Section loaded: propsys.dll | Jump to behavior |
Source: C:\Users\user\Desktop\KyrazonSetup.exe | Section loaded: dwmapi.dll | Jump to behavior |
Source: C:\Users\user\Desktop\KyrazonSetup.exe | Section loaded: cryptbase.dll | Jump to behavior |
Source: C:\Users\user\Desktop\KyrazonSetup.exe | Section loaded: oleacc.dll | Jump to behavior |
Source: C:\Users\user\Desktop\KyrazonSetup.exe | Section loaded: ntmarta.dll | Jump to behavior |
Source: C:\Users\user\Desktop\KyrazonSetup.exe | Section loaded: version.dll | Jump to behavior |
Source: C:\Users\user\Desktop\KyrazonSetup.exe | Section loaded: shfolder.dll | Jump to behavior |
Source: C:\Users\user\Desktop\KyrazonSetup.exe | Section loaded: kernel.appcore.dll | Jump to behavior |
Source: C:\Users\user\Desktop\KyrazonSetup.exe | Section loaded: windows.storage.dll | Jump to behavior |
Source: C:\Users\user\Desktop\KyrazonSetup.exe | Section loaded: wldp.dll | Jump to behavior |
Source: C:\Users\user\Desktop\KyrazonSetup.exe | Section loaded: iconcodecservice.dll | Jump to behavior |
Source: C:\Users\user\Desktop\KyrazonSetup.exe | Section loaded: windowscodecs.dll | Jump to behavior |
Source: C:\Users\user\Desktop\KyrazonSetup.exe | Section loaded: profapi.dll | Jump to behavior |
Source: C:\Users\user\Desktop\KyrazonSetup.exe | Section loaded: riched20.dll | Jump to behavior |
Source: C:\Users\user\Desktop\KyrazonSetup.exe | Section loaded: usp10.dll | Jump to behavior |
Source: C:\Users\user\Desktop\KyrazonSetup.exe | Section loaded: msls31.dll | Jump to behavior |
Source: C:\Users\user\Desktop\KyrazonSetup.exe | Section loaded: textshaping.dll | Jump to behavior |
Source: C:\Users\user\Desktop\KyrazonSetup.exe | Section loaded: textinputframework.dll | Jump to behavior |
Source: C:\Users\user\Desktop\KyrazonSetup.exe | Section loaded: coreuicomponents.dll | Jump to behavior |
Source: C:\Users\user\Desktop\KyrazonSetup.exe | Section loaded: coremessaging.dll | Jump to behavior |
Source: C:\Users\user\Desktop\KyrazonSetup.exe | Section loaded: wintypes.dll | Jump to behavior |
Source: C:\Users\user\Desktop\KyrazonSetup.exe | Section loaded: wintypes.dll | Jump to behavior |
Source: C:\Users\user\Desktop\KyrazonSetup.exe | Section loaded: wintypes.dll | Jump to behavior |
Source: C:\Users\user\Desktop\KyrazonSetup.exe | Section loaded: windows.staterepositoryps.dll | Jump to behavior |
Source: C:\Users\user\Desktop\KyrazonSetup.exe | Section loaded: windows.fileexplorer.common.dll | Jump to behavior |
Source: C:\Users\user\Desktop\KyrazonSetup.exe | Section loaded: iertutil.dll | Jump to behavior |
Source: C:\Users\user\Desktop\KyrazonSetup.exe | Section loaded: ntshrui.dll | Jump to behavior |
Source: C:\Users\user\Desktop\KyrazonSetup.exe | Section loaded: sspicli.dll | Jump to behavior |
Source: C:\Users\user\Desktop\KyrazonSetup.exe | Section loaded: sxs.dll | Jump to behavior |
Source: C:\Users\user\Desktop\KyrazonSetup.exe | Section loaded: onecorecommonproxystub.dll | Jump to behavior |
Source: C:\Users\user\Desktop\KyrazonSetup.exe | Section loaded: onecoreuapcommonproxystub.dll | Jump to behavior |
Source: C:\Users\user\Desktop\KyrazonSetup.exe | Section loaded: msasn1.dll | Jump to behavior |
Source: C:\Windows\SysWOW64\tasklist.exe | Section loaded: version.dll | Jump to behavior |
Source: C:\Windows\SysWOW64\tasklist.exe | Section loaded: mpr.dll | Jump to behavior |
Source: C:\Windows\SysWOW64\tasklist.exe | Section loaded: framedynos.dll | Jump to behavior |
Source: C:\Windows\SysWOW64\tasklist.exe | Section loaded: dbghelp.dll | Jump to behavior |
Source: C:\Windows\SysWOW64\tasklist.exe | Section loaded: sspicli.dll | Jump to behavior |
Source: C:\Windows\SysWOW64\tasklist.exe | Section loaded: srvcli.dll | Jump to behavior |
Source: C:\Windows\SysWOW64\tasklist.exe | Section loaded: netutils.dll | Jump to behavior |
Source: C:\Windows\SysWOW64\tasklist.exe | Section loaded: sspicli.dll | Jump to behavior |
Source: C:\Windows\SysWOW64\tasklist.exe | Section loaded: kernel.appcore.dll | Jump to behavior |
Source: C:\Windows\SysWOW64\tasklist.exe | Section loaded: wbemcomn.dll | Jump to behavior |
Source: C:\Windows\SysWOW64\tasklist.exe | Section loaded: winsta.dll | Jump to behavior |
Source: C:\Windows\SysWOW64\tasklist.exe | Section loaded: amsi.dll | Jump to behavior |
Source: C:\Windows\SysWOW64\tasklist.exe | Section loaded: userenv.dll | Jump to behavior |
Source: C:\Windows\SysWOW64\tasklist.exe | Section loaded: profapi.dll | Jump to behavior |
Source: C:\Windows\SysWOW64\find.exe | Section loaded: ulib.dll | Jump to behavior |
Source: C:\Windows\SysWOW64\find.exe | Section loaded: fsutilext.dll | Jump to behavior |
Source: C:\Users\user\AppData\Local\Programs\KyrazonGodot\KyrazonGodot.exe | Section loaded: ffmpeg.dll | Jump to behavior |
Source: C:\Users\user\AppData\Local\Programs\KyrazonGodot\KyrazonGodot.exe | Section loaded: dbghelp.dll | Jump to behavior |
Source: C:\Users\user\AppData\Local\Programs\KyrazonGodot\KyrazonGodot.exe | Section loaded: winmm.dll | Jump to behavior |
Source: C:\Users\user\AppData\Local\Programs\KyrazonGodot\KyrazonGodot.exe | Section loaded: iphlpapi.dll | Jump to behavior |
Source: C:\Users\user\AppData\Local\Programs\KyrazonGodot\KyrazonGodot.exe | Section loaded: userenv.dll | Jump to behavior |
Source: C:\Users\user\AppData\Local\Programs\KyrazonGodot\KyrazonGodot.exe | Section loaded: version.dll | Jump to behavior |
Source: C:\Users\user\AppData\Local\Programs\KyrazonGodot\KyrazonGodot.exe | Section loaded: dwrite.dll | Jump to behavior |
Source: C:\Users\user\AppData\Local\Programs\KyrazonGodot\KyrazonGodot.exe | Section loaded: secur32.dll | Jump to behavior |
Source: C:\Users\user\AppData\Local\Programs\KyrazonGodot\KyrazonGodot.exe | Section loaded: winhttp.dll | Jump to behavior |
Source: C:\Users\user\AppData\Local\Programs\KyrazonGodot\KyrazonGodot.exe | Section loaded: dhcpcsvc.dll | Jump to behavior |
Source: C:\Users\user\AppData\Local\Programs\KyrazonGodot\KyrazonGodot.exe | Section loaded: sspicli.dll | Jump to behavior |
Source: C:\Users\user\AppData\Local\Programs\KyrazonGodot\KyrazonGodot.exe | Section loaded: powrprof.dll | Jump to behavior |
Source: C:\Users\user\AppData\Local\Programs\KyrazonGodot\KyrazonGodot.exe | Section loaded: umpdc.dll | Jump to behavior |
Source: C:\Users\user\AppData\Local\Programs\KyrazonGodot\KyrazonGodot.exe | Section loaded: uxtheme.dll | Jump to behavior |
Source: C:\Users\user\AppData\Local\Programs\KyrazonGodot\KyrazonGodot.exe | Section loaded: mswsock.dll | Jump to behavior |
Source: C:\Users\user\AppData\Local\Programs\KyrazonGodot\KyrazonGodot.exe | Section loaded: ntmarta.dll | Jump to behavior |
Source: C:\Users\user\AppData\Local\Programs\KyrazonGodot\KyrazonGodot.exe | Section loaded: kbdus.dll | Jump to behavior |
Source: C:\Users\user\AppData\Local\Programs\KyrazonGodot\KyrazonGodot.exe | Section loaded: kernel.appcore.dll | Jump to behavior |
Source: C:\Users\user\AppData\Local\Programs\KyrazonGodot\KyrazonGodot.exe | Section loaded: windows.storage.dll | Jump to behavior |
Source: C:\Users\user\AppData\Local\Programs\KyrazonGodot\KyrazonGodot.exe | Section loaded: wldp.dll | Jump to behavior |
Source: C:\Users\user\AppData\Local\Programs\KyrazonGodot\KyrazonGodot.exe | Section loaded: dpapi.dll | Jump to behavior |
Source: C:\Users\user\AppData\Local\Programs\KyrazonGodot\KyrazonGodot.exe | Section loaded: cryptbase.dll | Jump to behavior |
Source: C:\Users\user\AppData\Local\Programs\KyrazonGodot\KyrazonGodot.exe | Section loaded: nlaapi.dll | Jump to behavior |
Source: C:\Users\user\AppData\Local\Programs\KyrazonGodot\KyrazonGodot.exe | Section loaded: dhcpcsvc6.dll | Jump to behavior |
Source: C:\Users\user\AppData\Local\Programs\KyrazonGodot\KyrazonGodot.exe | Section loaded: dnsapi.dll | Jump to behavior |
Source: C:\Users\user\AppData\Local\Programs\KyrazonGodot\KyrazonGodot.exe | Section loaded: textinputframework.dll | Jump to behavior |
Source: C:\Users\user\AppData\Local\Programs\KyrazonGodot\KyrazonGodot.exe | Section loaded: coreuicomponents.dll | Jump to behavior |
Source: C:\Users\user\AppData\Local\Programs\KyrazonGodot\KyrazonGodot.exe | Section loaded: coremessaging.dll | Jump to behavior |
Source: C:\Users\user\AppData\Local\Programs\KyrazonGodot\KyrazonGodot.exe | Section loaded: coremessaging.dll | Jump to behavior |
Source: C:\Users\user\AppData\Local\Programs\KyrazonGodot\KyrazonGodot.exe | Section loaded: wintypes.dll | Jump to behavior |
Source: C:\Users\user\AppData\Local\Programs\KyrazonGodot\KyrazonGodot.exe | Section loaded: wintypes.dll | Jump to behavior |
Source: C:\Users\user\AppData\Local\Programs\KyrazonGodot\KyrazonGodot.exe | Section loaded: wintypes.dll | Jump to behavior |
Source: C:\Users\user\AppData\Local\Programs\KyrazonGodot\KyrazonGodot.exe | Section loaded: windows.ui.dll | Jump to behavior |
Source: C:\Users\user\AppData\Local\Programs\KyrazonGodot\KyrazonGodot.exe | Section loaded: windowmanagementapi.dll | Jump to behavior |
Source: C:\Users\user\AppData\Local\Programs\KyrazonGodot\KyrazonGodot.exe | Section loaded: inputhost.dll | Jump to behavior |
Source: C:\Users\user\AppData\Local\Programs\KyrazonGodot\KyrazonGodot.exe | Section loaded: twinapi.appcore.dll | Jump to behavior |
Source: C:\Users\user\AppData\Local\Programs\KyrazonGodot\KyrazonGodot.exe | Section loaded: twinapi.appcore.dll | Jump to behavior |
Source: C:\Users\user\AppData\Local\Programs\KyrazonGodot\KyrazonGodot.exe | Section loaded: propsys.dll | Jump to behavior |
Source: C:\Users\user\AppData\Local\Programs\KyrazonGodot\KyrazonGodot.exe | Section loaded: profapi.dll | Jump to behavior |
Source: C:\Users\user\AppData\Local\Programs\KyrazonGodot\KyrazonGodot.exe | Section loaded: mscms.dll | Jump to behavior |
Source: C:\Users\user\AppData\Local\Programs\KyrazonGodot\KyrazonGodot.exe | Section loaded: coloradapterclient.dll | Jump to behavior |
Source: C:\Users\user\AppData\Local\Programs\KyrazonGodot\KyrazonGodot.exe | Section loaded: wtsapi32.dll | Jump to behavior |
Source: C:\Users\user\AppData\Local\Programs\KyrazonGodot\KyrazonGodot.exe | Section loaded: mmdevapi.dll | Jump to behavior |
Source: C:\Users\user\AppData\Local\Programs\KyrazonGodot\KyrazonGodot.exe | Section loaded: devobj.dll | Jump to behavior |
Source: C:\Users\user\AppData\Local\Programs\KyrazonGodot\KyrazonGodot.exe | Section loaded: winsta.dll | Jump to behavior |
Source: C:\Users\user\AppData\Local\Programs\KyrazonGodot\KyrazonGodot.exe | Section loaded: msasn1.dll | Jump to behavior |
Source: C:\Users\user\AppData\Local\Programs\KyrazonGodot\KyrazonGodot.exe | Section loaded: cryptsp.dll | Jump to behavior |
Source: C:\Users\user\AppData\Local\Programs\KyrazonGodot\KyrazonGodot.exe | Section loaded: rsaenh.dll | Jump to behavior |
Source: C:\Users\user\AppData\Local\Programs\KyrazonGodot\KyrazonGodot.exe | Section loaded: gpapi.dll | Jump to behavior |
Source: C:\Users\user\AppData\Local\Programs\KyrazonGodot\KyrazonGodot.exe | Section loaded: apphelp.dll | Jump to behavior |
Source: C:\Users\user\AppData\Local\Programs\KyrazonGodot\KyrazonGodot.exe | Section loaded: napinsp.dll | Jump to behavior |
Source: C:\Users\user\AppData\Local\Programs\KyrazonGodot\KyrazonGodot.exe | Section loaded: pnrpnsp.dll | Jump to behavior |
Source: C:\Users\user\AppData\Local\Programs\KyrazonGodot\KyrazonGodot.exe | Section loaded: wshbth.dll | Jump to behavior |
Source: C:\Users\user\AppData\Local\Programs\KyrazonGodot\KyrazonGodot.exe | Section loaded: winrnr.dll | Jump to behavior |
Source: C:\Users\user\AppData\Local\Programs\KyrazonGodot\KyrazonGodot.exe | Section loaded: rasadhlp.dll | Jump to behavior |
Source: C:\Users\user\AppData\Local\Programs\KyrazonGodot\KyrazonGodot.exe | Section loaded: fwpuclnt.dll | Jump to behavior |
Source: C:\Users\user\AppData\Local\Programs\KyrazonGodot\KyrazonGodot.exe | Section loaded: ffmpeg.dll | |
Source: C:\Users\user\AppData\Local\Programs\KyrazonGodot\KyrazonGodot.exe | Section loaded: dbghelp.dll | |
Source: C:\Users\user\AppData\Local\Programs\KyrazonGodot\KyrazonGodot.exe | Section loaded: winmm.dll | |
Source: C:\Users\user\AppData\Local\Programs\KyrazonGodot\KyrazonGodot.exe | Section loaded: iphlpapi.dll | |
Source: C:\Users\user\AppData\Local\Programs\KyrazonGodot\KyrazonGodot.exe | Section loaded: userenv.dll | |
Source: C:\Users\user\AppData\Local\Programs\KyrazonGodot\KyrazonGodot.exe | Section loaded: version.dll | |
Source: C:\Users\user\AppData\Local\Programs\KyrazonGodot\KyrazonGodot.exe | Section loaded: dwrite.dll | |
Source: C:\Users\user\AppData\Local\Programs\KyrazonGodot\KyrazonGodot.exe | Section loaded: secur32.dll | |
Source: C:\Users\user\AppData\Local\Programs\KyrazonGodot\KyrazonGodot.exe | Section loaded: winhttp.dll | |
Source: C:\Users\user\AppData\Local\Programs\KyrazonGodot\KyrazonGodot.exe | Section loaded: dhcpcsvc.dll | |
Source: C:\Users\user\AppData\Local\Programs\KyrazonGodot\KyrazonGodot.exe | Section loaded: sspicli.dll | |
Source: C:\Users\user\AppData\Local\Programs\KyrazonGodot\KyrazonGodot.exe | Section loaded: powrprof.dll | |
Source: C:\Users\user\AppData\Local\Programs\KyrazonGodot\KyrazonGodot.exe | Section loaded: umpdc.dll | |
Source: C:\Users\user\AppData\Local\Programs\KyrazonGodot\KyrazonGodot.exe | Section loaded: uxtheme.dll | |
Source: C:\Users\user\AppData\Local\Programs\KyrazonGodot\KyrazonGodot.exe | Section loaded: mswsock.dll | |
Source: C:\Users\user\AppData\Local\Programs\KyrazonGodot\KyrazonGodot.exe | Section loaded: kernel.appcore.dll | |
Source: C:\Users\user\AppData\Local\Programs\KyrazonGodot\KyrazonGodot.exe | Section loaded: dxgi.dll | |
Source: C:\Users\user\AppData\Local\Programs\KyrazonGodot\KyrazonGodot.exe | Section loaded: resourcepolicyclient.dll | |
Source: C:\Users\user\AppData\Local\Programs\KyrazonGodot\KyrazonGodot.exe | Section loaded: cryptbase.dll | |
Source: C:\Users\user\AppData\Local\Programs\KyrazonGodot\KyrazonGodot.exe | Section loaded: mf.dll | |
Source: C:\Users\user\AppData\Local\Programs\KyrazonGodot\KyrazonGodot.exe | Section loaded: mfplat.dll | |
Source: C:\Users\user\AppData\Local\Programs\KyrazonGodot\KyrazonGodot.exe | Section loaded: rtworkq.dll | |
Source: C:\Users\user\AppData\Local\Programs\KyrazonGodot\KyrazonGodot.exe | Section loaded: dwmapi.dll | |
Source: C:\Users\user\AppData\Local\Programs\KyrazonGodot\resources\app.asar.unpacked\node_modules\windows-shortcuts\lib\shortcut\Shortcut.exe | Section loaded: apphelp.dll | |
Source: C:\Users\user\AppData\Local\Programs\KyrazonGodot\resources\app.asar.unpacked\node_modules\windows-shortcuts\lib\shortcut\Shortcut.exe | Section loaded: kernel.appcore.dll | |
Source: C:\Users\user\AppData\Local\Programs\KyrazonGodot\resources\app.asar.unpacked\node_modules\windows-shortcuts\lib\shortcut\Shortcut.exe | Section loaded: uxtheme.dll | |
Source: C:\Users\user\AppData\Local\Programs\KyrazonGodot\resources\app.asar.unpacked\node_modules\windows-shortcuts\lib\shortcut\Shortcut.exe | Section loaded: windows.storage.dll | |
Source: C:\Users\user\AppData\Local\Programs\KyrazonGodot\resources\app.asar.unpacked\node_modules\windows-shortcuts\lib\shortcut\Shortcut.exe | Section loaded: wldp.dll | |
Source: C:\Users\user\AppData\Local\Programs\KyrazonGodot\resources\app.asar.unpacked\node_modules\windows-shortcuts\lib\shortcut\Shortcut.exe | Section loaded: propsys.dll | |
Source: C:\Users\user\AppData\Local\Programs\KyrazonGodot\resources\app.asar.unpacked\node_modules\windows-shortcuts\lib\shortcut\Shortcut.exe | Section loaded: profapi.dll | |
Source: C:\Users\user\AppData\Local\Programs\KyrazonGodot\resources\app.asar.unpacked\node_modules\windows-shortcuts\lib\shortcut\Shortcut.exe | Section loaded: linkinfo.dll | |
Source: C:\Users\user\AppData\Local\Programs\KyrazonGodot\resources\app.asar.unpacked\node_modules\windows-shortcuts\lib\shortcut\Shortcut.exe | Section loaded: ntshrui.dll | |
Source: C:\Users\user\AppData\Local\Programs\KyrazonGodot\resources\app.asar.unpacked\node_modules\windows-shortcuts\lib\shortcut\Shortcut.exe | Section loaded: sspicli.dll | |
Source: C:\Users\user\AppData\Local\Programs\KyrazonGodot\resources\app.asar.unpacked\node_modules\windows-shortcuts\lib\shortcut\Shortcut.exe | Section loaded: srvcli.dll | |
Source: C:\Users\user\AppData\Local\Programs\KyrazonGodot\resources\app.asar.unpacked\node_modules\windows-shortcuts\lib\shortcut\Shortcut.exe | Section loaded: cscapi.dll | |
Source: C:\Users\user\AppData\Local\Programs\KyrazonGodot\resources\app.asar.unpacked\node_modules\windows-shortcuts\lib\shortcut\Shortcut.exe | Section loaded: netutils.dll | |
Source: C:\Windows\System32\tasklist.exe | Section loaded: version.dll | |
Source: C:\Windows\System32\tasklist.exe | Section loaded: mpr.dll | |
Source: C:\Windows\System32\tasklist.exe | Section loaded: framedynos.dll | |
Source: C:\Windows\System32\tasklist.exe | Section loaded: dbghelp.dll | |
Source: C:\Windows\System32\tasklist.exe | Section loaded: sspicli.dll | |
Source: C:\Windows\System32\tasklist.exe | Section loaded: srvcli.dll | |
Source: C:\Windows\System32\tasklist.exe | Section loaded: netutils.dll | |
Source: C:\Windows\System32\tasklist.exe | Section loaded: kernel.appcore.dll | |
Source: C:\Windows\System32\tasklist.exe | Section loaded: wbemcomn.dll | |
Source: C:\Windows\System32\tasklist.exe | Section loaded: winsta.dll | |
Source: C:\Windows\System32\tasklist.exe | Section loaded: amsi.dll | |
Source: C:\Windows\System32\tasklist.exe | Section loaded: userenv.dll | |
Source: C:\Windows\System32\tasklist.exe | Section loaded: profapi.dll | |
Source: C:\Windows\System32\tasklist.exe | Section loaded: version.dll | |
Source: C:\Windows\System32\tasklist.exe | Section loaded: mpr.dll | |
Source: C:\Windows\System32\tasklist.exe | Section loaded: framedynos.dll | |
Source: C:\Windows\System32\tasklist.exe | Section loaded: dbghelp.dll | |
Source: C:\Windows\System32\tasklist.exe | Section loaded: sspicli.dll | |
Source: C:\Windows\System32\tasklist.exe | Section loaded: srvcli.dll | |
Source: C:\Windows\System32\tasklist.exe | Section loaded: netutils.dll | |
Source: C:\Windows\System32\tasklist.exe | Section loaded: sspicli.dll | |
Source: C:\Windows\System32\tasklist.exe | Section loaded: kernel.appcore.dll | |
Source: C:\Windows\System32\tasklist.exe | Section loaded: wbemcomn.dll | |
Source: C:\Windows\System32\tasklist.exe | Section loaded: winsta.dll | |
Source: C:\Windows\System32\tasklist.exe | Section loaded: amsi.dll | |
Source: C:\Windows\System32\tasklist.exe | Section loaded: userenv.dll | |
Source: C:\Windows\System32\tasklist.exe | Section loaded: profapi.dll | |
Source: C:\Windows\System32\tasklist.exe | Section loaded: version.dll | |
Source: C:\Windows\System32\tasklist.exe | Section loaded: mpr.dll | |
Source: C:\Windows\System32\tasklist.exe | Section loaded: framedynos.dll | |
Source: C:\Windows\System32\tasklist.exe | Section loaded: dbghelp.dll | |
Source: C:\Windows\System32\tasklist.exe | Section loaded: sspicli.dll | |
Source: C:\Windows\System32\tasklist.exe | Section loaded: srvcli.dll | |
Source: C:\Windows\System32\tasklist.exe | Section loaded: netutils.dll | |
Source: C:\Windows\System32\tasklist.exe | Section loaded: sspicli.dll | |
Source: C:\Windows\System32\tasklist.exe | Section loaded: kernel.appcore.dll | |
Source: C:\Windows\System32\tasklist.exe | Section loaded: wbemcomn.dll | |
Source: C:\Windows\System32\tasklist.exe | Section loaded: winsta.dll | |
Source: C:\Windows\System32\tasklist.exe | Section loaded: amsi.dll | |
Source: C:\Windows\System32\tasklist.exe | Section loaded: userenv.dll | |
Source: C:\Windows\System32\tasklist.exe | Section loaded: profapi.dll | |
Source: C:\Windows\System32\tasklist.exe | Section loaded: version.dll | |
Source: C:\Windows\System32\tasklist.exe | Section loaded: mpr.dll | |
Source: C:\Windows\System32\tasklist.exe | Section loaded: framedynos.dll | |
Source: C:\Windows\System32\tasklist.exe | Section loaded: dbghelp.dll | |
Source: C:\Windows\System32\tasklist.exe | Section loaded: sspicli.dll | |
Source: C:\Windows\System32\tasklist.exe | Section loaded: srvcli.dll | |
Source: C:\Windows\System32\tasklist.exe | Section loaded: netutils.dll | |
Source: C:\Windows\System32\tasklist.exe | Section loaded: sspicli.dll | |
Source: C:\Windows\System32\tasklist.exe | Section loaded: kernel.appcore.dll | |
Source: C:\Windows\System32\tasklist.exe | Section loaded: wbemcomn.dll | |
Source: C:\Windows\System32\tasklist.exe | Section loaded: winsta.dll | |
Source: C:\Windows\System32\tasklist.exe | Section loaded: amsi.dll | |
Source: C:\Windows\System32\tasklist.exe | Section loaded: userenv.dll | |
Source: C:\Windows\System32\tasklist.exe | Section loaded: profapi.dll | |
Source: C:\Windows\System32\where.exe | Section loaded: version.dll | |
Source: C:\Windows\System32\tasklist.exe | Section loaded: version.dll | |
Source: C:\Windows\System32\tasklist.exe | Section loaded: mpr.dll | |
Source: C:\Windows\System32\tasklist.exe | Section loaded: framedynos.dll | |
Source: C:\Windows\System32\tasklist.exe | Section loaded: dbghelp.dll | |
Source: C:\Windows\System32\tasklist.exe | Section loaded: sspicli.dll | |
Source: C:\Windows\System32\tasklist.exe | Section loaded: srvcli.dll | |
Source: C:\Windows\System32\tasklist.exe | Section loaded: netutils.dll | |
Source: C:\Windows\System32\tasklist.exe | Section loaded: sspicli.dll | |
Source: C:\Windows\System32\tasklist.exe | Section loaded: kernel.appcore.dll | |
Source: C:\Windows\System32\tasklist.exe | Section loaded: wbemcomn.dll | |
Source: C:\Windows\System32\tasklist.exe | Section loaded: winsta.dll | |
Source: C:\Windows\System32\tasklist.exe | Section loaded: amsi.dll | |
Source: C:\Windows\System32\tasklist.exe | Section loaded: userenv.dll | |
Source: C:\Windows\System32\tasklist.exe | Section loaded: profapi.dll | |
Source: C:\Users\user\AppData\Local\Programs\KyrazonGodot\KyrazonGodot.exe | Section loaded: ffmpeg.dll | |
Source: C:\Users\user\AppData\Local\Programs\KyrazonGodot\KyrazonGodot.exe | Section loaded: dbghelp.dll | |
Source: C:\Users\user\AppData\Local\Programs\KyrazonGodot\KyrazonGodot.exe | Section loaded: winmm.dll | |
Source: C:\Users\user\AppData\Local\Programs\KyrazonGodot\KyrazonGodot.exe | Section loaded: iphlpapi.dll | |
Source: C:\Users\user\AppData\Local\Programs\KyrazonGodot\KyrazonGodot.exe | Section loaded: userenv.dll | |
Source: C:\Users\user\AppData\Local\Programs\KyrazonGodot\KyrazonGodot.exe | Section loaded: version.dll | |
Source: C:\Users\user\AppData\Local\Programs\KyrazonGodot\KyrazonGodot.exe | Section loaded: dwrite.dll | |
Source: C:\Users\user\AppData\Local\Programs\KyrazonGodot\KyrazonGodot.exe | Section loaded: secur32.dll | |
Source: C:\Users\user\AppData\Local\Programs\KyrazonGodot\KyrazonGodot.exe | Section loaded: winhttp.dll | |
Source: C:\Users\user\AppData\Local\Programs\KyrazonGodot\KyrazonGodot.exe | Section loaded: dhcpcsvc.dll | |
Source: C:\Users\user\AppData\Local\Programs\KyrazonGodot\KyrazonGodot.exe | Section loaded: sspicli.dll | |
Source: C:\Users\user\AppData\Local\Programs\KyrazonGodot\KyrazonGodot.exe | Section loaded: powrprof.dll | |
Source: C:\Users\user\AppData\Local\Programs\KyrazonGodot\KyrazonGodot.exe | Section loaded: umpdc.dll | |
Source: C:\Users\user\AppData\Local\Programs\KyrazonGodot\KyrazonGodot.exe | Section loaded: uxtheme.dll | |
Source: C:\Users\user\AppData\Local\Programs\KyrazonGodot\KyrazonGodot.exe | Section loaded: mswsock.dll | |
Source: C:\Users\user\AppData\Local\Programs\KyrazonGodot\KyrazonGodot.exe | Section loaded: ntmarta.dll | |
Source: C:\Users\user\AppData\Local\Programs\KyrazonGodot\KyrazonGodot.exe | Section loaded: kbdus.dll | |
Source: C:\Users\user\AppData\Local\Programs\KyrazonGodot\KyrazonGodot.exe | Section loaded: nlaapi.dll | |
Source: C:\Users\user\AppData\Local\Programs\KyrazonGodot\KyrazonGodot.exe | Section loaded: dhcpcsvc6.dll | |
Source: C:\Users\user\AppData\Local\Programs\KyrazonGodot\KyrazonGodot.exe | Section loaded: dnsapi.dll | |
Source: C:\Users\user\AppData\Local\Programs\KyrazonGodot\KyrazonGodot.exe | Section loaded: rasadhlp.dll | |
Source: C:\Users\user\AppData\Local\Programs\KyrazonGodot\KyrazonGodot.exe | Section loaded: kernel.appcore.dll | |
Source: C:\Windows\System32\tasklist.exe | Section loaded: version.dll | |
Source: C:\Windows\System32\tasklist.exe | Section loaded: mpr.dll | |
Source: C:\Windows\System32\tasklist.exe | Section loaded: framedynos.dll | |
Source: C:\Windows\System32\tasklist.exe | Section loaded: dbghelp.dll | |
Source: C:\Windows\System32\tasklist.exe | Section loaded: sspicli.dll | |
Source: C:\Windows\System32\tasklist.exe | Section loaded: srvcli.dll | |
Source: C:\Windows\System32\tasklist.exe | Section loaded: netutils.dll | |
Source: C:\Windows\System32\tasklist.exe | Section loaded: sspicli.dll | |
Source: C:\Windows\System32\tasklist.exe | Section loaded: kernel.appcore.dll | |
Source: C:\Windows\System32\tasklist.exe | Section loaded: wbemcomn.dll | |
Source: C:\Windows\System32\tasklist.exe | Section loaded: winsta.dll | |
Source: C:\Windows\System32\tasklist.exe | Section loaded: amsi.dll | |
Source: C:\Windows\System32\tasklist.exe | Section loaded: userenv.dll | |
Source: C:\Windows\System32\tasklist.exe | Section loaded: profapi.dll | |
Source: C:\Windows\System32\tasklist.exe | Section loaded: version.dll | |
Source: C:\Windows\System32\tasklist.exe | Section loaded: mpr.dll | |
Source: C:\Windows\System32\tasklist.exe | Section loaded: framedynos.dll | |
Source: C:\Windows\System32\tasklist.exe | Section loaded: dbghelp.dll | |
Source: C:\Windows\System32\tasklist.exe | Section loaded: sspicli.dll | |
Source: C:\Windows\System32\tasklist.exe | Section loaded: srvcli.dll | |
Source: C:\Windows\System32\tasklist.exe | Section loaded: netutils.dll | |
Source: C:\Windows\System32\tasklist.exe | Section loaded: sspicli.dll | |
Source: C:\Windows\System32\tasklist.exe | Section loaded: kernel.appcore.dll | |
Source: C:\Windows\System32\tasklist.exe | Section loaded: wbemcomn.dll | |
Source: C:\Windows\System32\tasklist.exe | Section loaded: winsta.dll | |
Source: C:\Windows\System32\tasklist.exe | Section loaded: amsi.dll | |
Source: C:\Windows\System32\tasklist.exe | Section loaded: userenv.dll | |
Source: C:\Windows\System32\tasklist.exe | Section loaded: profapi.dll | |
Source: C:\Windows\System32\tasklist.exe | Section loaded: version.dll | |
Source: C:\Windows\System32\tasklist.exe | Section loaded: mpr.dll | |
Source: C:\Windows\System32\tasklist.exe | Section loaded: framedynos.dll | |
Source: C:\Windows\System32\tasklist.exe | Section loaded: dbghelp.dll | |
Source: C:\Windows\System32\tasklist.exe | Section loaded: sspicli.dll | |
Source: C:\Windows\System32\tasklist.exe | Section loaded: srvcli.dll | |
Source: C:\Windows\System32\tasklist.exe | Section loaded: netutils.dll | |
Source: C:\Windows\System32\tasklist.exe | Section loaded: sspicli.dll | |
Source: C:\Windows\System32\tasklist.exe | Section loaded: kernel.appcore.dll | |
Source: C:\Windows\System32\tasklist.exe | Section loaded: wbemcomn.dll | |
Source: C:\Windows\System32\tasklist.exe | Section loaded: winsta.dll | |
Source: C:\Windows\System32\tasklist.exe | Section loaded: amsi.dll | |
Source: C:\Windows\System32\tasklist.exe | Section loaded: userenv.dll | |
Source: C:\Windows\System32\tasklist.exe | Section loaded: profapi.dll | |
Source: C:\Users\user\AppData\Local\Programs\KyrazonGodot\KyrazonGodot.exe | Section loaded: ffmpeg.dll | |
Source: C:\Users\user\AppData\Local\Programs\KyrazonGodot\KyrazonGodot.exe | Section loaded: dbghelp.dll | |
Source: C:\Users\user\AppData\Local\Programs\KyrazonGodot\KyrazonGodot.exe | Section loaded: winmm.dll | |
Source: C:\Users\user\AppData\Local\Programs\KyrazonGodot\KyrazonGodot.exe | Section loaded: iphlpapi.dll | |
Source: C:\Users\user\AppData\Local\Programs\KyrazonGodot\KyrazonGodot.exe | Section loaded: userenv.dll | |
Source: C:\Users\user\AppData\Local\Programs\KyrazonGodot\KyrazonGodot.exe | Section loaded: version.dll | |
Source: C:\Users\user\AppData\Local\Programs\KyrazonGodot\KyrazonGodot.exe | Section loaded: dwrite.dll | |
Source: C:\Users\user\AppData\Local\Programs\KyrazonGodot\KyrazonGodot.exe | Section loaded: secur32.dll | |
Source: C:\Users\user\AppData\Local\Programs\KyrazonGodot\KyrazonGodot.exe | Section loaded: winhttp.dll | |
Source: C:\Users\user\AppData\Local\Programs\KyrazonGodot\KyrazonGodot.exe | Section loaded: dhcpcsvc.dll | |
Source: C:\Users\user\AppData\Local\Programs\KyrazonGodot\KyrazonGodot.exe | Section loaded: sspicli.dll | |
Source: C:\Users\user\AppData\Local\Programs\KyrazonGodot\KyrazonGodot.exe | Section loaded: powrprof.dll | |
Source: C:\Users\user\AppData\Local\Programs\KyrazonGodot\KyrazonGodot.exe | Section loaded: umpdc.dll | |
Source: C:\Users\user\AppData\Local\Programs\KyrazonGodot\KyrazonGodot.exe | Section loaded: uxtheme.dll | |
Source: C:\Users\user\AppData\Local\Programs\KyrazonGodot\KyrazonGodot.exe | Section loaded: mswsock.dll | |
Source: C:\Users\user\AppData\Local\Programs\KyrazonGodot\KyrazonGodot.exe | Section loaded: ntmarta.dll | |
Source: C:\Users\user\AppData\Local\Programs\KyrazonGodot\KyrazonGodot.exe | Section loaded: kbdus.dll | |
Source: C:\Users\user\AppData\Local\Programs\KyrazonGodot\KyrazonGodot.exe | Section loaded: kernel.appcore.dll | |
Source: C:\Users\user\AppData\Local\Programs\KyrazonGodot\KyrazonGodot.exe | Section loaded: windows.storage.dll | |
Source: C:\Users\user\AppData\Local\Programs\KyrazonGodot\KyrazonGodot.exe | Section loaded: wldp.dll | |
Source: C:\Users\user\AppData\Local\Programs\KyrazonGodot\KyrazonGodot.exe | Section loaded: dpapi.dll | |
Source: C:\Users\user\AppData\Local\Programs\KyrazonGodot\KyrazonGodot.exe | Section loaded: cryptbase.dll | |
Source: C:\Users\user\AppData\Local\Programs\KyrazonGodot\KyrazonGodot.exe | Section loaded: nlaapi.dll | |
Source: C:\Users\user\AppData\Local\Programs\KyrazonGodot\KyrazonGodot.exe | Section loaded: dhcpcsvc6.dll | |
Source: C:\Users\user\AppData\Local\Programs\KyrazonGodot\KyrazonGodot.exe | Section loaded: dnsapi.dll | |
Source: C:\Users\user\AppData\Local\Programs\KyrazonGodot\KyrazonGodot.exe | Section loaded: textinputframework.dll | |
Source: C:\Users\user\AppData\Local\Programs\KyrazonGodot\KyrazonGodot.exe | Section loaded: coreuicomponents.dll | |
Source: C:\Users\user\AppData\Local\Programs\KyrazonGodot\KyrazonGodot.exe | Section loaded: coremessaging.dll | |
Source: C:\Users\user\AppData\Local\Programs\KyrazonGodot\KyrazonGodot.exe | Section loaded: coremessaging.dll | |
Source: C:\Users\user\AppData\Local\Programs\KyrazonGodot\KyrazonGodot.exe | Section loaded: wintypes.dll | |
Source: C:\Users\user\AppData\Local\Programs\KyrazonGodot\KyrazonGodot.exe | Section loaded: wintypes.dll | |
Source: C:\Users\user\AppData\Local\Programs\KyrazonGodot\KyrazonGodot.exe | Section loaded: wintypes.dll | |
Source: C:\Users\user\AppData\Local\Programs\KyrazonGodot\KyrazonGodot.exe | Section loaded: windows.ui.dll | |
Source: C:\Users\user\AppData\Local\Programs\KyrazonGodot\KyrazonGodot.exe | Section loaded: windowmanagementapi.dll | |
Source: C:\Users\user\AppData\Local\Programs\KyrazonGodot\KyrazonGodot.exe | Section loaded: inputhost.dll | |
Source: C:\Users\user\AppData\Local\Programs\KyrazonGodot\KyrazonGodot.exe | Section loaded: twinapi.appcore.dll | |
Source: C:\Users\user\AppData\Local\Programs\KyrazonGodot\KyrazonGodot.exe | Section loaded: twinapi.appcore.dll | |
Source: C:\Users\user\AppData\Local\Programs\KyrazonGodot\KyrazonGodot.exe | Section loaded: propsys.dll | |
Source: C:\Users\user\AppData\Local\Programs\KyrazonGodot\KyrazonGodot.exe | Section loaded: profapi.dll | |
Source: C:\Users\user\AppData\Local\Programs\KyrazonGodot\KyrazonGodot.exe | Section loaded: wtsapi32.dll | |
Source: C:\Users\user\AppData\Local\Programs\KyrazonGodot\KyrazonGodot.exe | Section loaded: winsta.dll | |
Source: C:\Users\user\AppData\Local\Programs\KyrazonGodot\KyrazonGodot.exe | Section loaded: mscms.dll | |
Source: C:\Users\user\AppData\Local\Programs\KyrazonGodot\KyrazonGodot.exe | Section loaded: coloradapterclient.dll | |
Source: C:\Users\user\AppData\Local\Programs\KyrazonGodot\KyrazonGodot.exe | Section loaded: mmdevapi.dll | |
Source: C:\Users\user\AppData\Local\Programs\KyrazonGodot\KyrazonGodot.exe | Section loaded: devobj.dll | |
Source: C:\Users\user\AppData\Local\Programs\KyrazonGodot\KyrazonGodot.exe | Section loaded: msasn1.dll | |
Source: C:\Users\user\AppData\Local\Programs\KyrazonGodot\KyrazonGodot.exe | Section loaded: cryptsp.dll | |
Source: C:\Users\user\AppData\Local\Programs\KyrazonGodot\KyrazonGodot.exe | Section loaded: rsaenh.dll | |
Source: C:\Users\user\AppData\Local\Programs\KyrazonGodot\KyrazonGodot.exe | Section loaded: gpapi.dll | |
Source: C:\Users\user\AppData\Local\Programs\KyrazonGodot\KyrazonGodot.exe | Section loaded: napinsp.dll | |
Source: C:\Users\user\AppData\Local\Programs\KyrazonGodot\KyrazonGodot.exe | Section loaded: pnrpnsp.dll | |
Source: C:\Users\user\AppData\Local\Programs\KyrazonGodot\KyrazonGodot.exe | Section loaded: wshbth.dll | |
Source: C:\Users\user\AppData\Local\Programs\KyrazonGodot\KyrazonGodot.exe | Section loaded: winrnr.dll | |
Source: C:\Users\user\AppData\Local\Programs\KyrazonGodot\KyrazonGodot.exe | Section loaded: rasadhlp.dll | |
Source: C:\Users\user\AppData\Local\Programs\KyrazonGodot\KyrazonGodot.exe | Section loaded: fwpuclnt.dll | |
Source: C:\Windows\System32\tasklist.exe | Section loaded: version.dll | |
Source: C:\Windows\System32\tasklist.exe | Section loaded: mpr.dll | |
Source: C:\Windows\System32\tasklist.exe | Section loaded: framedynos.dll | |
Source: C:\Windows\System32\tasklist.exe | Section loaded: sspicli.dll | |
Source: C:\Windows\System32\tasklist.exe | Section loaded: dbghelp.dll | |
Source: C:\Windows\System32\tasklist.exe | Section loaded: srvcli.dll | |
Source: C:\Windows\System32\tasklist.exe | Section loaded: netutils.dll | |
Source: C:\Windows\System32\tasklist.exe | Section loaded: kernel.appcore.dll | |
Source: C:\Windows\System32\tasklist.exe | Section loaded: wbemcomn.dll | |
Source: C:\Windows\System32\tasklist.exe | Section loaded: winsta.dll | |
Source: C:\Windows\System32\tasklist.exe | Section loaded: amsi.dll | |
Source: C:\Windows\System32\tasklist.exe | Section loaded: userenv.dll | |
Source: C:\Windows\System32\tasklist.exe | Section loaded: profapi.dll | |
Source: C:\Users\user\AppData\Local\Programs\KyrazonGodot\KyrazonGodot.exe | Section loaded: ffmpeg.dll | |
Source: C:\Users\user\AppData\Local\Programs\KyrazonGodot\KyrazonGodot.exe | Section loaded: dbghelp.dll | |
Source: C:\Users\user\AppData\Local\Programs\KyrazonGodot\KyrazonGodot.exe | Section loaded: winmm.dll | |
Source: C:\Users\user\AppData\Local\Programs\KyrazonGodot\KyrazonGodot.exe | Section loaded: iphlpapi.dll | |
Source: C:\Users\user\AppData\Local\Programs\KyrazonGodot\KyrazonGodot.exe | Section loaded: userenv.dll | |
Source: C:\Users\user\AppData\Local\Programs\KyrazonGodot\KyrazonGodot.exe | Section loaded: version.dll | |
Source: C:\Users\user\AppData\Local\Programs\KyrazonGodot\KyrazonGodot.exe | Section loaded: dwrite.dll | |
Source: C:\Users\user\AppData\Local\Programs\KyrazonGodot\KyrazonGodot.exe | Section loaded: secur32.dll | |
Source: C:\Users\user\AppData\Local\Programs\KyrazonGodot\KyrazonGodot.exe | Section loaded: winhttp.dll | |
Source: C:\Users\user\AppData\Local\Programs\KyrazonGodot\KyrazonGodot.exe | Section loaded: dhcpcsvc.dll | |
Source: C:\Users\user\AppData\Local\Programs\KyrazonGodot\KyrazonGodot.exe | Section loaded: sspicli.dll | |
Source: C:\Users\user\AppData\Local\Programs\KyrazonGodot\KyrazonGodot.exe | Section loaded: powrprof.dll | |
Source: C:\Users\user\AppData\Local\Programs\KyrazonGodot\KyrazonGodot.exe | Section loaded: umpdc.dll | |
Source: C:\Users\user\AppData\Local\Programs\KyrazonGodot\KyrazonGodot.exe | Section loaded: uxtheme.dll | |
Source: C:\Users\user\AppData\Local\Programs\KyrazonGodot\KyrazonGodot.exe | Section loaded: mswsock.dll | |
Source: C:\Users\user\AppData\Local\Programs\KyrazonGodot\KyrazonGodot.exe | Section loaded: kernel.appcore.dll | |
Source: C:\Users\user\AppData\Local\Programs\KyrazonGodot\KyrazonGodot.exe | Section loaded: dxgi.dll | |
Source: C:\Users\user\AppData\Local\Programs\KyrazonGodot\KyrazonGodot.exe | Section loaded: resourcepolicyclient.dll | |
Source: C:\Users\user\AppData\Local\Programs\KyrazonGodot\KyrazonGodot.exe | Section loaded: cryptbase.dll | |
Source: C:\Users\user\AppData\Local\Programs\KyrazonGodot\KyrazonGodot.exe | Section loaded: mf.dll | |
Source: C:\Users\user\AppData\Local\Programs\KyrazonGodot\KyrazonGodot.exe | Section loaded: mfplat.dll | |
Source: C:\Users\user\AppData\Local\Programs\KyrazonGodot\KyrazonGodot.exe | Section loaded: rtworkq.dll | |
Source: C:\Users\user\AppData\Local\Programs\KyrazonGodot\KyrazonGodot.exe | Section loaded: dwmapi.dll | |
Source: C:\Windows\System32\tasklist.exe | Section loaded: version.dll | |
Source: C:\Windows\System32\tasklist.exe | Section loaded: mpr.dll | |
Source: C:\Windows\System32\tasklist.exe | Section loaded: framedynos.dll | |
Source: C:\Windows\System32\tasklist.exe | Section loaded: dbghelp.dll | |
Source: C:\Windows\System32\tasklist.exe | Section loaded: sspicli.dll | |
Source: C:\Windows\System32\tasklist.exe | Section loaded: srvcli.dll | |
Source: C:\Windows\System32\tasklist.exe | Section loaded: netutils.dll | |
Source: C:\Windows\System32\tasklist.exe | Section loaded: sspicli.dll | |
Source: C:\Windows\System32\tasklist.exe | Section loaded: kernel.appcore.dll | |
Source: C:\Windows\System32\tasklist.exe | Section loaded: wbemcomn.dll | |
Source: C:\Windows\System32\tasklist.exe | Section loaded: winsta.dll | |
Source: C:\Windows\System32\tasklist.exe | Section loaded: amsi.dll | |
Source: C:\Windows\System32\tasklist.exe | Section loaded: userenv.dll | |
Source: C:\Windows\System32\tasklist.exe | Section loaded: profapi.dll | |
Source: C:\Windows\System32\tasklist.exe | Section loaded: version.dll | |
Source: C:\Windows\System32\tasklist.exe | Section loaded: mpr.dll | |
Source: C:\Windows\System32\tasklist.exe | Section loaded: framedynos.dll | |
Source: C:\Windows\System32\tasklist.exe | Section loaded: dbghelp.dll | |
Source: C:\Windows\System32\tasklist.exe | Section loaded: sspicli.dll | |
Source: C:\Windows\System32\tasklist.exe | Section loaded: srvcli.dll | |
Source: C:\Windows\System32\tasklist.exe | Section loaded: netutils.dll | |
Source: C:\Windows\System32\tasklist.exe | Section loaded: sspicli.dll | |
Source: C:\Windows\System32\tasklist.exe | Section loaded: kernel.appcore.dll | |
Source: C:\Windows\System32\tasklist.exe | Section loaded: wbemcomn.dll | |
Source: C:\Windows\System32\tasklist.exe | Section loaded: winsta.dll | |
Source: C:\Windows\System32\tasklist.exe | Section loaded: amsi.dll | |
Source: C:\Windows\System32\tasklist.exe | Section loaded: userenv.dll | |
Source: C:\Windows\System32\tasklist.exe | Section loaded: profapi.dll | |
Source: C:\Users\user\AppData\Local\Programs\KyrazonGodot\KyrazonGodot.exe | Section loaded: ffmpeg.dll | |
Source: C:\Users\user\AppData\Local\Programs\KyrazonGodot\KyrazonGodot.exe | Section loaded: dbghelp.dll | |
Source: C:\Users\user\AppData\Local\Programs\KyrazonGodot\KyrazonGodot.exe | Section loaded: winmm.dll | |
Source: C:\Users\user\AppData\Local\Programs\KyrazonGodot\KyrazonGodot.exe | Section loaded: iphlpapi.dll | |
Source: C:\Users\user\AppData\Local\Programs\KyrazonGodot\KyrazonGodot.exe | Section loaded: userenv.dll | |
Source: C:\Users\user\AppData\Local\Programs\KyrazonGodot\KyrazonGodot.exe | Section loaded: version.dll | |
Source: C:\Users\user\AppData\Local\Programs\KyrazonGodot\KyrazonGodot.exe | Section loaded: dwrite.dll | |
Source: C:\Users\user\AppData\Local\Programs\KyrazonGodot\KyrazonGodot.exe | Section loaded: secur32.dll | |
Source: C:\Users\user\AppData\Local\Programs\KyrazonGodot\KyrazonGodot.exe | Section loaded: winhttp.dll | |
Source: C:\Users\user\AppData\Local\Programs\KyrazonGodot\KyrazonGodot.exe | Section loaded: dhcpcsvc.dll | |
Source: C:\Users\user\AppData\Local\Programs\KyrazonGodot\KyrazonGodot.exe | Section loaded: sspicli.dll | |
Source: C:\Users\user\AppData\Local\Programs\KyrazonGodot\KyrazonGodot.exe | Section loaded: powrprof.dll | |
Source: C:\Users\user\AppData\Local\Programs\KyrazonGodot\KyrazonGodot.exe | Section loaded: umpdc.dll | |
Source: C:\Users\user\AppData\Local\Programs\KyrazonGodot\KyrazonGodot.exe | Section loaded: uxtheme.dll | |
Source: C:\Users\user\AppData\Local\Programs\KyrazonGodot\KyrazonGodot.exe | Section loaded: mswsock.dll | |
Source: C:\Users\user\AppData\Local\Programs\KyrazonGodot\KyrazonGodot.exe | Section loaded: ntmarta.dll | |
Source: C:\Users\user\AppData\Local\Programs\KyrazonGodot\KyrazonGodot.exe | Section loaded: kbdus.dll | |
Source: C:\Users\user\AppData\Local\Programs\KyrazonGodot\KyrazonGodot.exe | Section loaded: dhcpcsvc6.dll | |
Source: C:\Users\user\AppData\Local\Programs\KyrazonGodot\KyrazonGodot.exe | Section loaded: nlaapi.dll | |
Source: C:\Users\user\AppData\Local\Programs\KyrazonGodot\KyrazonGodot.exe | Section loaded: dnsapi.dll | |
Source: C:\Users\user\AppData\Local\Programs\KyrazonGodot\KyrazonGodot.exe | Section loaded: rasadhlp.dll | |
Source: C:\Users\user\AppData\Local\Programs\KyrazonGodot\KyrazonGodot.exe | Section loaded: kernel.appcore.dll | |
Source: C:\Windows\System32\tasklist.exe | Section loaded: version.dll | |
Source: C:\Windows\System32\tasklist.exe | Section loaded: mpr.dll | |
Source: C:\Windows\System32\tasklist.exe | Section loaded: framedynos.dll | |
Source: C:\Windows\System32\tasklist.exe | Section loaded: dbghelp.dll | |
Source: C:\Windows\System32\tasklist.exe | Section loaded: sspicli.dll | |
Source: C:\Windows\System32\tasklist.exe | Section loaded: srvcli.dll | |
Source: C:\Windows\System32\tasklist.exe | Section loaded: netutils.dll | |
Source: C:\Windows\System32\tasklist.exe | Section loaded: sspicli.dll | |
Source: C:\Windows\System32\tasklist.exe | Section loaded: kernel.appcore.dll | |
Source: C:\Windows\System32\tasklist.exe | Section loaded: wbemcomn.dll | |
Source: C:\Windows\System32\tasklist.exe | Section loaded: winsta.dll | |
Source: C:\Windows\System32\tasklist.exe | Section loaded: amsi.dll | |
Source: C:\Windows\System32\tasklist.exe | Section loaded: userenv.dll | |
Source: C:\Windows\System32\tasklist.exe | Section loaded: profapi.dll | |
Source: C:\Windows\System32\tasklist.exe | Section loaded: version.dll | |
Source: C:\Windows\System32\tasklist.exe | Section loaded: mpr.dll | |
Source: C:\Windows\System32\tasklist.exe | Section loaded: framedynos.dll | |
Source: C:\Windows\System32\tasklist.exe | Section loaded: dbghelp.dll | |
Source: C:\Windows\System32\tasklist.exe | Section loaded: sspicli.dll | |
Source: C:\Windows\System32\tasklist.exe | Section loaded: srvcli.dll | |
Source: C:\Windows\System32\tasklist.exe | Section loaded: netutils.dll | |
Source: C:\Windows\System32\tasklist.exe | Section loaded: sspicli.dll | |
Source: C:\Windows\System32\tasklist.exe | Section loaded: kernel.appcore.dll | |
Source: C:\Windows\System32\tasklist.exe | Section loaded: wbemcomn.dll | |
Source: C:\Windows\System32\tasklist.exe | Section loaded: winsta.dll | |
Source: C:\Windows\System32\tasklist.exe | Section loaded: amsi.dll | |
Source: C:\Windows\System32\tasklist.exe | Section loaded: userenv.dll | |
Source: C:\Windows\System32\tasklist.exe | Section loaded: profapi.dll | |
Source: C:\Windows\System32\tasklist.exe | Section loaded: version.dll | |
Source: C:\Windows\System32\tasklist.exe | Section loaded: mpr.dll | |
Source: C:\Windows\System32\tasklist.exe | Section loaded: framedynos.dll | |
Source: C:\Windows\System32\tasklist.exe | Section loaded: dbghelp.dll | |
Source: C:\Windows\System32\tasklist.exe | Section loaded: sspicli.dll | |
Source: C:\Windows\System32\tasklist.exe | Section loaded: srvcli.dll | |
Source: C:\Windows\System32\tasklist.exe | Section loaded: netutils.dll | |
Source: C:\Windows\System32\tasklist.exe | Section loaded: sspicli.dll | |
Source: C:\Windows\System32\tasklist.exe | Section loaded: kernel.appcore.dll | |
Source: C:\Windows\System32\tasklist.exe | Section loaded: wbemcomn.dll | |
Source: C:\Windows\System32\tasklist.exe | Section loaded: winsta.dll | |
Source: C:\Windows\System32\tasklist.exe | Section loaded: amsi.dll | |
Source: C:\Windows\System32\tasklist.exe | Section loaded: userenv.dll | |
Source: C:\Windows\System32\tasklist.exe | Section loaded: profapi.dll | |
Source: C:\Windows\System32\where.exe | Section loaded: version.dll | |
Source: C:\Windows\System32\tasklist.exe | Section loaded: version.dll | |
Source: C:\Windows\System32\tasklist.exe | Section loaded: mpr.dll | |
Source: C:\Windows\System32\tasklist.exe | Section loaded: framedynos.dll | |
Source: C:\Windows\System32\tasklist.exe | Section loaded: dbghelp.dll | |
Source: C:\Windows\System32\tasklist.exe | Section loaded: sspicli.dll | |
Source: C:\Windows\System32\tasklist.exe | Section loaded: srvcli.dll | |
Source: C:\Windows\System32\tasklist.exe | Section loaded: netutils.dll | |
Source: C:\Windows\System32\tasklist.exe | Section loaded: kernel.appcore.dll | |
Source: C:\Windows\System32\tasklist.exe | Section loaded: wbemcomn.dll | |
Source: C:\Windows\System32\tasklist.exe | Section loaded: winsta.dll | |
Source: C:\Windows\System32\tasklist.exe | Section loaded: amsi.dll | |
Source: C:\Windows\System32\tasklist.exe | Section loaded: userenv.dll | |
Source: C:\Windows\System32\tasklist.exe | Section loaded: profapi.dll | |
Source: C:\Windows\System32\tasklist.exe | Section loaded: version.dll | |
Source: C:\Windows\System32\tasklist.exe | Section loaded: mpr.dll | |
Source: C:\Windows\System32\tasklist.exe | Section loaded: framedynos.dll | |
Source: C:\Windows\System32\tasklist.exe | Section loaded: dbghelp.dll | |
Source: C:\Windows\System32\tasklist.exe | Section loaded: sspicli.dll | |
Source: C:\Windows\System32\tasklist.exe | Section loaded: srvcli.dll | |
Source: C:\Windows\System32\tasklist.exe | Section loaded: netutils.dll | |
Source: C:\Windows\System32\tasklist.exe | Section loaded: sspicli.dll | |
Source: C:\Windows\System32\tasklist.exe | Section loaded: kernel.appcore.dll | |
Source: C:\Windows\System32\tasklist.exe | Section loaded: wbemcomn.dll | |
Source: C:\Windows\System32\tasklist.exe | Section loaded: winsta.dll | |
Source: C:\Windows\System32\tasklist.exe | Section loaded: amsi.dll | |
Source: C:\Windows\System32\tasklist.exe | Section loaded: userenv.dll | |
Source: C:\Windows\System32\tasklist.exe | Section loaded: profapi.dll | |
Source: C:\Windows\System32\tasklist.exe | Section loaded: version.dll | |
Source: C:\Windows\System32\tasklist.exe | Section loaded: mpr.dll | |
Source: C:\Windows\System32\tasklist.exe | Section loaded: framedynos.dll | |
Source: C:\Windows\System32\tasklist.exe | Section loaded: dbghelp.dll | |
Source: C:\Windows\System32\tasklist.exe | Section loaded: sspicli.dll | |
Source: C:\Windows\System32\tasklist.exe | Section loaded: srvcli.dll | |
Source: C:\Windows\System32\tasklist.exe | Section loaded: netutils.dll | |
Source: C:\Windows\System32\tasklist.exe | Section loaded: sspicli.dll | |
Source: C:\Windows\System32\tasklist.exe | Section loaded: kernel.appcore.dll | |
Source: C:\Windows\System32\tasklist.exe | Section loaded: wbemcomn.dll | |
Source: C:\Windows\System32\tasklist.exe | Section loaded: winsta.dll | |
Source: C:\Windows\System32\tasklist.exe | Section loaded: amsi.dll | |
Source: C:\Users\user\Desktop\KyrazonSetup.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\KyrazonSetup.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\KyrazonSetup.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\cmd.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\cmd.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\cmd.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\cmd.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\System32\conhost.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\tasklist.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\tasklist.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\tasklist.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\tasklist.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\AppData\Local\Programs\KyrazonGodot\KyrazonGodot.exe | Process information set: NOGPFAULTERRORBOX | NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\AppData\Local\Programs\KyrazonGodot\KyrazonGodot.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\AppData\Local\Programs\KyrazonGodot\KyrazonGodot.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\AppData\Local\Programs\KyrazonGodot\KyrazonGodot.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\AppData\Local\Programs\KyrazonGodot\KyrazonGodot.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\AppData\Local\Programs\KyrazonGodot\KyrazonGodot.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\AppData\Local\Programs\KyrazonGodot\KyrazonGodot.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\AppData\Local\Programs\KyrazonGodot\KyrazonGodot.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\AppData\Local\Programs\KyrazonGodot\KyrazonGodot.exe | Process information set: NOGPFAULTERRORBOX | NOOPENFILEERRORBOX | |
Source: C:\Users\user\AppData\Local\Programs\KyrazonGodot\KyrazonGodot.exe | Process information set: NOGPFAULTERRORBOX | NOOPENFILEERRORBOX | |
Source: C:\Users\user\AppData\Local\Programs\KyrazonGodot\KyrazonGodot.exe | Process information set: NOGPFAULTERRORBOX | NOOPENFILEERRORBOX | |
Source: C:\Users\user\AppData\Local\Programs\KyrazonGodot\KyrazonGodot.exe | Process information set: NOGPFAULTERRORBOX | NOOPENFILEERRORBOX | |
Source: C:\Users\user\AppData\Local\Programs\KyrazonGodot\resources\app.asar.unpacked\node_modules\windows-shortcuts\lib\shortcut\Shortcut.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Windows\System32\conhost.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Windows\System32\cmd.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Windows\System32\tasklist.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Windows\System32\tasklist.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Windows\System32\tasklist.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Windows\System32\tasklist.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Windows\System32\cmd.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Windows\System32\cmd.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Windows\System32\cmd.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Windows\System32\cmd.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Windows\System32\conhost.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Windows\System32\tasklist.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Windows\System32\tasklist.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Windows\System32\tasklist.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Windows\System32\tasklist.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Windows\System32\tasklist.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Windows\System32\tasklist.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Windows\System32\tasklist.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Windows\System32\tasklist.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Windows\System32\tasklist.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Windows\System32\tasklist.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Windows\System32\tasklist.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Windows\System32\tasklist.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Windows\System32\where.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Windows\System32\where.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Windows\System32\cmd.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Windows\System32\tasklist.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Windows\System32\tasklist.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Windows\System32\tasklist.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Windows\System32\tasklist.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Users\user\AppData\Local\Programs\KyrazonGodot\KyrazonGodot.exe | Process information set: NOGPFAULTERRORBOX | NOOPENFILEERRORBOX | |
Source: C:\Windows\System32\cmd.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Windows\System32\tasklist.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Windows\System32\tasklist.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Windows\System32\tasklist.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Windows\System32\tasklist.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Windows\System32\cmd.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Windows\System32\tasklist.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Windows\System32\tasklist.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Windows\System32\tasklist.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Windows\System32\tasklist.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Windows\System32\cmd.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Windows\System32\tasklist.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Windows\System32\tasklist.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Windows\System32\tasklist.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Windows\System32\tasklist.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Users\user\AppData\Local\Programs\KyrazonGodot\KyrazonGodot.exe | Process information set: NOGPFAULTERRORBOX | NOOPENFILEERRORBOX | |
Source: C:\Users\user\AppData\Local\Programs\KyrazonGodot\KyrazonGodot.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Users\user\AppData\Local\Programs\KyrazonGodot\KyrazonGodot.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Users\user\AppData\Local\Programs\KyrazonGodot\KyrazonGodot.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Users\user\AppData\Local\Programs\KyrazonGodot\KyrazonGodot.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Users\user\AppData\Local\Programs\KyrazonGodot\KyrazonGodot.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Windows\System32\cmd.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Windows\System32\tasklist.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Windows\System32\tasklist.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Windows\System32\tasklist.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Windows\System32\tasklist.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Users\user\AppData\Local\Programs\KyrazonGodot\KyrazonGodot.exe | Process information set: NOGPFAULTERRORBOX | NOOPENFILEERRORBOX | |
Source: C:\Users\user\AppData\Local\Programs\KyrazonGodot\KyrazonGodot.exe | Process information set: NOGPFAULTERRORBOX | NOOPENFILEERRORBOX | |
Source: C:\Users\user\AppData\Local\Programs\KyrazonGodot\KyrazonGodot.exe | Process information set: NOGPFAULTERRORBOX | NOOPENFILEERRORBOX | |
Source: C:\Users\user\AppData\Local\Programs\KyrazonGodot\KyrazonGodot.exe | Process information set: NOGPFAULTERRORBOX | NOOPENFILEERRORBOX | |
Source: C:\Windows\System32\cmd.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Windows\System32\conhost.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Windows\System32\tasklist.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Windows\System32\tasklist.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Windows\System32\tasklist.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Windows\System32\tasklist.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Windows\System32\cmd.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Windows\System32\tasklist.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Windows\System32\tasklist.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Windows\System32\tasklist.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Windows\System32\tasklist.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Users\user\AppData\Local\Programs\KyrazonGodot\KyrazonGodot.exe | Process information set: NOGPFAULTERRORBOX | NOOPENFILEERRORBOX | |
Source: C:\Windows\System32\cmd.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Windows\System32\conhost.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Windows\System32\cmd.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Windows\System32\cmd.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Windows\System32\conhost.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Windows\System32\cmd.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Windows\System32\conhost.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Windows\System32\conhost.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Windows\System32\tasklist.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Windows\System32\tasklist.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Windows\System32\tasklist.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Windows\System32\tasklist.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Windows\System32\tasklist.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Windows\System32\tasklist.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Windows\System32\tasklist.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Windows\System32\tasklist.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Windows\System32\tasklist.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Windows\System32\tasklist.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Windows\System32\tasklist.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Windows\System32\tasklist.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Windows\System32\where.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Windows\System32\where.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Windows\System32\cmd.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Windows\System32\tasklist.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Windows\System32\tasklist.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Windows\System32\tasklist.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Windows\System32\tasklist.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Windows\System32\cmd.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Windows\System32\conhost.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Windows\System32\tasklist.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Windows\System32\tasklist.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Windows\System32\tasklist.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Windows\System32\tasklist.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Windows\System32\cmd.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Windows\System32\tasklist.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Windows\System32\tasklist.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Windows\System32\tasklist.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Windows\System32\tasklist.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Windows\System32\cmd.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Windows\System32\conhost.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Windows\System32\tasklist.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Windows\System32\tasklist.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Windows\System32\tasklist.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Windows\System32\tasklist.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Windows\System32\cmd.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Windows\System32\tasklist.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Windows\System32\tasklist.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Windows\System32\tasklist.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Windows\System32\tasklist.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Windows\System32\cmd.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Windows\System32\conhost.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Windows\System32\tasklist.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Windows\System32\tasklist.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Windows\System32\tasklist.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Windows\System32\tasklist.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Windows\System32\cmd.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Windows\System32\tasklist.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Windows\System32\tasklist.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Windows\System32\tasklist.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Windows\System32\tasklist.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Windows\System32\cmd.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Windows\System32\conhost.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Windows\System32\tasklist.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Windows\System32\tasklist.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Windows\System32\tasklist.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Windows\System32\tasklist.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Windows\System32\cmd.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Windows\System32\tasklist.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Windows\System32\tasklist.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Windows\System32\tasklist.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Windows\System32\tasklist.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Windows\System32\cmd.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Windows\System32\conhost.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Windows\System32\tasklist.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Windows\System32\tasklist.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Windows\System32\tasklist.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Windows\System32\tasklist.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Windows\System32\cmd.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Users\user\Desktop\KyrazonSetup.exe | Process created: C:\Windows\SysWOW64\cmd.exe "C:\Windows\system32\cmd.exe" /c tasklist /FI "USERNAME eq %USERNAME%" /FI "IMAGENAME eq KyrazonGodot.exe" /FO csv | "C:\Windows\system32\find.exe" "KyrazonGodot.exe" | Jump to behavior |
Source: C:\Windows\SysWOW64\cmd.exe | Process created: C:\Windows\SysWOW64\tasklist.exe tasklist /FI "USERNAME eq user" /FI "IMAGENAME eq KyrazonGodot.exe" /FO csv | Jump to behavior |
Source: C:\Windows\SysWOW64\cmd.exe | Process created: C:\Windows\SysWOW64\find.exe "C:\Windows\system32\find.exe" "KyrazonGodot.exe" | Jump to behavior |
Source: C:\Users\user\AppData\Local\Programs\KyrazonGodot\KyrazonGodot.exe | Process created: C:\Users\user\AppData\Local\Programs\KyrazonGodot\KyrazonGodot.exe "C:\Users\user\AppData\Local\Programs\KyrazonGodot\KyrazonGodot.exe" --type=gpu-process --user-data-dir="C:\Users\user\AppData\Roaming\KyrazonGodot" --gpu-preferences=WAAAAAAAAADgAAAMAAAAAAAAAAAAAAAAAABgAAAAAAA4AAAAAAAAAAAAAAAEAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAGAAAAAAAAAAYAAAAAAAAAAgAAAAAAAAACAAAAAAAAAAIAAAAAAAAAA== --mojo-platform-channel-handle=1772 --field-trial-handle=1776,i,4294901941177378234,17718125093265605642,262144 --disable-features=SpareRendererForSitePerProcess,WinDelaySpellcheckServiceInit,WinRetrieveSuggestionsOnlyOnDemand /prefetch:2 | Jump to behavior |
Source: C:\Users\user\AppData\Local\Programs\KyrazonGodot\KyrazonGodot.exe | Process created: C:\Users\user\AppData\Local\Programs\KyrazonGodot\resources\app.asar.unpacked\node_modules\windows-shortcuts\lib\shortcut\Shortcut.exe C:\Users\user\AppData\Local\Programs\KyrazonGodot\resources\app.asar.unpacked\node_modules\windows-shortcuts\lib\shortcut\Shortcut.exe /A:C "/F:C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\KyrazonGodot.lnk" /T:C:\Users\user\AppData\Local\Programs\KyrazonGodot\KyrazonGodot.exe | Jump to behavior |
Source: C:\Users\user\AppData\Local\Programs\KyrazonGodot\KyrazonGodot.exe | Process created: C:\Windows\System32\cmd.exe C:\Windows\system32\cmd.exe /d /s /c "tasklist" | Jump to behavior |
Source: C:\Users\user\AppData\Local\Programs\KyrazonGodot\KyrazonGodot.exe | Process created: C:\Windows\System32\cmd.exe C:\Windows\system32\cmd.exe /d /s /c "tasklist" | Jump to behavior |
Source: C:\Users\user\AppData\Local\Programs\KyrazonGodot\KyrazonGodot.exe | Process created: C:\Windows\System32\cmd.exe C:\Windows\system32\cmd.exe /d /s /c "tasklist" | Jump to behavior |
Source: C:\Users\user\AppData\Local\Programs\KyrazonGodot\KyrazonGodot.exe | Process created: C:\Windows\System32\cmd.exe C:\Windows\system32\cmd.exe /d /s /c "tasklist" | Jump to behavior |
Source: C:\Users\user\AppData\Local\Programs\KyrazonGodot\KyrazonGodot.exe | Process created: C:\Windows\System32\cmd.exe C:\Windows\system32\cmd.exe /d /s /c "where /r . data.sqlite" | Jump to behavior |
Source: C:\Users\user\AppData\Local\Programs\KyrazonGodot\KyrazonGodot.exe | Process created: C:\Windows\System32\cmd.exe C:\Windows\system32\cmd.exe /d /s /c "tasklist" | Jump to behavior |
Source: C:\Users\user\AppData\Local\Programs\KyrazonGodot\KyrazonGodot.exe | Process created: C:\Users\user\AppData\Local\Programs\KyrazonGodot\KyrazonGodot.exe "C:\Users\user\AppData\Local\Programs\KyrazonGodot\KyrazonGodot.exe" --type=utility --utility-sub-type=network.mojom.NetworkService --lang=en-GB --service-sandbox-type=none --user-data-dir="C:\Users\user\AppData\Roaming\KyrazonGodot" --mojo-platform-channel-handle=2364 --field-trial-handle=1776,i,4294901941177378234,17718125093265605642,262144 --disable-features=SpareRendererForSitePerProcess,WinDelaySpellcheckServiceInit,WinRetrieveSuggestionsOnlyOnDemand /prefetch:8 | Jump to behavior |
Source: C:\Users\user\AppData\Local\Programs\KyrazonGodot\KyrazonGodot.exe | Process created: C:\Windows\System32\cmd.exe C:\Windows\system32\cmd.exe /d /s /c "tasklist" | Jump to behavior |
Source: C:\Users\user\AppData\Local\Programs\KyrazonGodot\KyrazonGodot.exe | Process created: C:\Windows\System32\cmd.exe C:\Windows\system32\cmd.exe /d /s /c "tasklist" | Jump to behavior |
Source: C:\Users\user\AppData\Local\Programs\KyrazonGodot\KyrazonGodot.exe | Process created: C:\Windows\System32\cmd.exe C:\Windows\system32\cmd.exe /d /s /c "tasklist" | Jump to behavior |
Source: C:\Users\user\AppData\Local\Programs\KyrazonGodot\KyrazonGodot.exe | Process created: C:\Windows\System32\cmd.exe C:\Windows\system32\cmd.exe /d /s /c "tasklist" | Jump to behavior |
Source: C:\Users\user\AppData\Local\Programs\KyrazonGodot\KyrazonGodot.exe | Process created: C:\Windows\System32\cmd.exe C:\Windows\system32\cmd.exe /d /s /c "tasklist" | Jump to behavior |
Source: C:\Users\user\AppData\Local\Programs\KyrazonGodot\KyrazonGodot.exe | Process created: C:\Windows\System32\cmd.exe C:\Windows\system32\cmd.exe /d /s /c "tasklist" | Jump to behavior |
Source: C:\Users\user\AppData\Local\Programs\KyrazonGodot\KyrazonGodot.exe | Process created: C:\Windows\System32\cmd.exe C:\Windows\system32\cmd.exe /d /s /c "tasklist" | Jump to behavior |
Source: C:\Users\user\AppData\Local\Programs\KyrazonGodot\KyrazonGodot.exe | Process created: C:\Windows\System32\cmd.exe C:\Windows\system32\cmd.exe /d /s /c "tasklist" | Jump to behavior |
Source: C:\Users\user\AppData\Local\Programs\KyrazonGodot\KyrazonGodot.exe | Process created: C:\Windows\System32\cmd.exe C:\Windows\system32\cmd.exe /d /s /c "tasklist" | Jump to behavior |
Source: C:\Users\user\AppData\Local\Programs\KyrazonGodot\KyrazonGodot.exe | Process created: C:\Windows\System32\cmd.exe C:\Windows\system32\cmd.exe /d /s /c "tasklist" | Jump to behavior |
Source: C:\Users\user\AppData\Local\Programs\KyrazonGodot\KyrazonGodot.exe | Process created: C:\Windows\System32\tasklist.exe tasklist | Jump to behavior |
Source: C:\Users\user\AppData\Local\Programs\KyrazonGodot\KyrazonGodot.exe | Process created: unknown unknown | Jump to behavior |
Source: C:\Users\user\AppData\Local\Programs\KyrazonGodot\KyrazonGodot.exe | Process created: unknown unknown | Jump to behavior |
Source: C:\Users\user\AppData\Local\Programs\KyrazonGodot\KyrazonGodot.exe | Process created: C:\Windows\System32\cmd.exe C:\Windows\system32\cmd.exe /d /s /c "tasklist" | Jump to behavior |
Source: C:\Users\user\AppData\Local\Programs\KyrazonGodot\KyrazonGodot.exe | Process created: unknown unknown | Jump to behavior |
Source: C:\Users\user\AppData\Local\Programs\KyrazonGodot\KyrazonGodot.exe | Process created: unknown unknown | Jump to behavior |
Source: C:\Users\user\AppData\Local\Programs\KyrazonGodot\KyrazonGodot.exe | Process created: unknown unknown | Jump to behavior |
Source: C:\Users\user\AppData\Local\Programs\KyrazonGodot\KyrazonGodot.exe | Process created: unknown unknown | Jump to behavior |
Source: C:\Users\user\AppData\Local\Programs\KyrazonGodot\KyrazonGodot.exe | Process created: C:\Windows\System32\tasklist.exe tasklist | Jump to behavior |
Source: C:\Users\user\AppData\Local\Programs\KyrazonGodot\KyrazonGodot.exe | Process created: C:\Windows\System32\tasklist.exe tasklist | Jump to behavior |
Source: C:\Users\user\AppData\Local\Programs\KyrazonGodot\KyrazonGodot.exe | Process created: C:\Windows\System32\Conhost.exe C:\Windows\system32\conhost.exe 0xffffffff -ForceV1 | Jump to behavior |
Source: C:\Users\user\AppData\Local\Programs\KyrazonGodot\KyrazonGodot.exe | Process created: unknown unknown | Jump to behavior |
Source: C:\Users\user\AppData\Local\Programs\KyrazonGodot\KyrazonGodot.exe | Process created: unknown unknown | Jump to behavior |
Source: C:\Users\user\AppData\Local\Programs\KyrazonGodot\KyrazonGodot.exe | Process created: unknown unknown | Jump to behavior |
Source: C:\Users\user\AppData\Local\Programs\KyrazonGodot\KyrazonGodot.exe | Process created: unknown unknown | Jump to behavior |
Source: C:\Users\user\AppData\Local\Programs\KyrazonGodot\KyrazonGodot.exe | Process created: unknown unknown | Jump to behavior |
Source: C:\Users\user\AppData\Local\Programs\KyrazonGodot\KyrazonGodot.exe | Process created: unknown unknown | Jump to behavior |
Source: C:\Users\user\AppData\Local\Programs\KyrazonGodot\KyrazonGodot.exe | Process created: unknown unknown | Jump to behavior |
Source: C:\Users\user\AppData\Local\Programs\KyrazonGodot\KyrazonGodot.exe | Process created: unknown unknown | Jump to behavior |
Source: C:\Users\user\AppData\Local\Programs\KyrazonGodot\KyrazonGodot.exe | Process created: unknown unknown | Jump to behavior |
Source: C:\Users\user\AppData\Local\Programs\KyrazonGodot\KyrazonGodot.exe | Process created: C:\Windows\System32\tasklist.exe tasklist | Jump to behavior |
Source: C:\Users\user\AppData\Local\Programs\KyrazonGodot\KyrazonGodot.exe | Process created: unknown unknown | Jump to behavior |
Source: C:\Users\user\AppData\Local\Programs\KyrazonGodot\KyrazonGodot.exe | Process created: unknown unknown | Jump to behavior |
Source: C:\Users\user\AppData\Local\Programs\KyrazonGodot\KyrazonGodot.exe | Process created: unknown unknown | Jump to behavior |
Source: C:\Users\user\AppData\Local\Programs\KyrazonGodot\KyrazonGodot.exe | Process created: unknown unknown | Jump to behavior |
Source: C:\Users\user\AppData\Local\Programs\KyrazonGodot\KyrazonGodot.exe | Process created: unknown unknown | Jump to behavior |
Source: C:\Users\user\AppData\Local\Programs\KyrazonGodot\KyrazonGodot.exe | Process created: unknown unknown | Jump to behavior |
Source: C:\Users\user\AppData\Local\Programs\KyrazonGodot\KyrazonGodot.exe | Process created: unknown unknown | Jump to behavior |
Source: C:\Users\user\AppData\Local\Programs\KyrazonGodot\KyrazonGodot.exe | Process created: C:\Windows\System32\tasklist.exe tasklist | Jump to behavior |
Source: C:\Users\user\AppData\Local\Programs\KyrazonGodot\KyrazonGodot.exe | Process created: unknown unknown | Jump to behavior |
Source: C:\Users\user\AppData\Local\Programs\KyrazonGodot\KyrazonGodot.exe | Process created: unknown unknown | Jump to behavior |
Source: C:\Users\user\AppData\Local\Programs\KyrazonGodot\KyrazonGodot.exe | Process created: unknown unknown | Jump to behavior |
Source: C:\Users\user\AppData\Local\Programs\KyrazonGodot\KyrazonGodot.exe | Process created: unknown unknown | Jump to behavior |
Source: C:\Users\user\AppData\Local\Programs\KyrazonGodot\KyrazonGodot.exe | Process created: C:\Windows\System32\cmd.exe C:\Windows\system32\cmd.exe /d /s /c "tasklist" | Jump to behavior |
Source: C:\Users\user\AppData\Local\Programs\KyrazonGodot\KyrazonGodot.exe | Process created: unknown unknown | Jump to behavior |
Source: C:\Users\user\AppData\Local\Programs\KyrazonGodot\KyrazonGodot.exe | Process created: unknown unknown | Jump to behavior |
Source: C:\Users\user\AppData\Local\Programs\KyrazonGodot\KyrazonGodot.exe | Process created: unknown unknown | Jump to behavior |
Source: C:\Users\user\AppData\Local\Programs\KyrazonGodot\KyrazonGodot.exe | Process created: unknown unknown | Jump to behavior |
Source: C:\Users\user\AppData\Local\Programs\KyrazonGodot\KyrazonGodot.exe | Process created: unknown unknown | Jump to behavior |
Source: C:\Users\user\AppData\Local\Programs\KyrazonGodot\KyrazonGodot.exe | Process created: unknown unknown | Jump to behavior |
Source: C:\Users\user\AppData\Local\Programs\KyrazonGodot\KyrazonGodot.exe | Process created: unknown unknown | Jump to behavior |
Source: C:\Users\user\AppData\Local\Programs\KyrazonGodot\KyrazonGodot.exe | Process created: unknown unknown | Jump to behavior |
Source: C:\Users\user\AppData\Local\Programs\KyrazonGodot\KyrazonGodot.exe | Process created: C:\Windows\System32\cmd.exe C:\Windows\system32\cmd.exe /d /s /c "tasklist" | Jump to behavior |
Source: C:\Users\user\AppData\Local\Programs\KyrazonGodot\KyrazonGodot.exe | Process created: unknown unknown | Jump to behavior |
Source: C:\Users\user\AppData\Local\Programs\KyrazonGodot\KyrazonGodot.exe | Process created: unknown unknown | Jump to behavior |
Source: C:\Users\user\AppData\Local\Programs\KyrazonGodot\KyrazonGodot.exe | Process created: unknown unknown | Jump to behavior |
Source: C:\Users\user\AppData\Local\Programs\KyrazonGodot\KyrazonGodot.exe | Process created: C:\Windows\System32\conhost.exe C:\Windows\system32\conhost.exe 0xffffffff -ForceV1 | Jump to behavior |
Source: C:\Users\user\AppData\Local\Programs\KyrazonGodot\KyrazonGodot.exe | Process created: C:\Windows\System32\cmd.exe C:\Windows\system32\cmd.exe /d /s /c "tasklist" | Jump to behavior |
Source: C:\Users\user\AppData\Local\Programs\KyrazonGodot\KyrazonGodot.exe | Process created: unknown unknown | Jump to behavior |
Source: C:\Users\user\AppData\Local\Programs\KyrazonGodot\KyrazonGodot.exe | Process created: unknown unknown | Jump to behavior |
Source: C:\Users\user\AppData\Local\Programs\KyrazonGodot\KyrazonGodot.exe | Process created: C:\Windows\System32\Conhost.exe C:\Windows\system32\conhost.exe 0xffffffff -ForceV1 | Jump to behavior |
Source: C:\Users\user\AppData\Local\Programs\KyrazonGodot\KyrazonGodot.exe | Process created: unknown unknown | Jump to behavior |
Source: C:\Users\user\AppData\Local\Programs\KyrazonGodot\KyrazonGodot.exe | Process created: C:\Windows\System32\conhost.exe C:\Windows\system32\conhost.exe 0xffffffff -ForceV1 | Jump to behavior |
Source: C:\Windows\System32\cmd.exe | Process created: C:\Windows\System32\tasklist.exe tasklist | |
Source: C:\Windows\System32\cmd.exe | Process created: C:\Windows\System32\tasklist.exe tasklist | |
Source: C:\Windows\System32\cmd.exe | Process created: C:\Windows\System32\tasklist.exe tasklist | |
Source: C:\Windows\System32\cmd.exe | Process created: C:\Windows\System32\tasklist.exe tasklist | |
Source: C:\Windows\System32\cmd.exe | Process created: C:\Windows\System32\where.exe where /r . data.sqlite | |
Source: C:\Windows\System32\cmd.exe | Process created: C:\Windows\System32\tasklist.exe tasklist | |
Source: C:\Windows\System32\cmd.exe | Process created: C:\Windows\System32\tasklist.exe tasklist | |
Source: C:\Windows\System32\cmd.exe | Process created: C:\Windows\System32\tasklist.exe tasklist | |
Source: C:\Windows\System32\cmd.exe | Process created: C:\Windows\System32\tasklist.exe tasklist | |
Source: C:\Users\user\AppData\Local\Programs\KyrazonGodot\KyrazonGodot.exe | Process created: C:\Users\user\AppData\Local\Programs\KyrazonGodot\KyrazonGodot.exe "C:\Users\user\AppData\Local\Programs\KyrazonGodot\KyrazonGodot.exe" --type=gpu-process --user-data-dir="C:\Users\user\AppData\Roaming\KyrazonGodot" --gpu-preferences=WAAAAAAAAADgAAAMAAAAAAAAAAAAAAAAAABgAAAAAAA4AAAAAAAAAAAAAAAEAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAGAAAAAAAAAAYAAAAAAAAAAgAAAAAAAAACAAAAAAAAAAIAAAAAAAAAA== --mojo-platform-channel-handle=1740 --field-trial-handle=1744,i,17217612992806517809,8679626120337516312,262144 --disable-features=SpareRendererForSitePerProcess,WinDelaySpellcheckServiceInit,WinRetrieveSuggestionsOnlyOnDemand /prefetch:2 | |
Source: C:\Users\user\AppData\Local\Programs\KyrazonGodot\KyrazonGodot.exe | Process created: C:\Windows\System32\cmd.exe C:\Windows\system32\cmd.exe /d /s /c "tasklist" | |
Source: C:\Users\user\AppData\Local\Programs\KyrazonGodot\KyrazonGodot.exe | Process created: C:\Users\user\AppData\Local\Programs\KyrazonGodot\KyrazonGodot.exe "C:\Users\user\AppData\Local\Programs\KyrazonGodot\KyrazonGodot.exe" --type=utility --utility-sub-type=network.mojom.NetworkService --lang=en-GB --service-sandbox-type=none --user-data-dir="C:\Users\user\AppData\Roaming\KyrazonGodot" --mojo-platform-channel-handle=2228 --field-trial-handle=1744,i,17217612992806517809,8679626120337516312,262144 --disable-features=SpareRendererForSitePerProcess,WinDelaySpellcheckServiceInit,WinRetrieveSuggestionsOnlyOnDemand /prefetch:8 | |
Source: C:\Users\user\AppData\Local\Programs\KyrazonGodot\KyrazonGodot.exe | Process created: C:\Windows\System32\cmd.exe C:\Windows\system32\cmd.exe /d /s /c "tasklist" | |
Source: C:\Users\user\AppData\Local\Programs\KyrazonGodot\KyrazonGodot.exe | Process created: C:\Windows\System32\cmd.exe C:\Windows\system32\cmd.exe /d /s /c "tasklist" | |
Source: C:\Users\user\AppData\Local\Programs\KyrazonGodot\KyrazonGodot.exe | Process created: C:\Windows\System32\cmd.exe C:\Windows\system32\cmd.exe /d /s /c "tasklist" | |
Source: C:\Users\user\AppData\Local\Programs\KyrazonGodot\KyrazonGodot.exe | Process created: C:\Windows\System32\cmd.exe C:\Windows\system32\cmd.exe /d /s /c "where /r . data.sqlite" | |
Source: C:\Users\user\AppData\Local\Programs\KyrazonGodot\KyrazonGodot.exe | Process created: C:\Windows\System32\cmd.exe C:\Windows\system32\cmd.exe /d /s /c "tasklist" | |
Source: C:\Users\user\AppData\Local\Programs\KyrazonGodot\KyrazonGodot.exe | Process created: C:\Windows\System32\cmd.exe C:\Windows\system32\cmd.exe /d /s /c "tasklist" | |
Source: C:\Users\user\AppData\Local\Programs\KyrazonGodot\KyrazonGodot.exe | Process created: C:\Windows\System32\cmd.exe C:\Windows\system32\cmd.exe /d /s /c "tasklist" | |
Source: C:\Users\user\AppData\Local\Programs\KyrazonGodot\KyrazonGodot.exe | Process created: C:\Windows\System32\cmd.exe C:\Windows\system32\cmd.exe /d /s /c "tasklist" | |
Source: C:\Users\user\AppData\Local\Programs\KyrazonGodot\KyrazonGodot.exe | Process created: C:\Windows\System32\cmd.exe C:\Windows\system32\cmd.exe /d /s /c "tasklist" | |
Source: C:\Users\user\AppData\Local\Programs\KyrazonGodot\KyrazonGodot.exe | Process created: unknown unknown | |
Source: C:\Users\user\AppData\Local\Programs\KyrazonGodot\KyrazonGodot.exe | Process created: unknown unknown | |
Source: C:\Users\user\AppData\Local\Programs\KyrazonGodot\KyrazonGodot.exe | Process created: unknown unknown | |
Source: C:\Users\user\AppData\Local\Programs\KyrazonGodot\KyrazonGodot.exe | Process created: unknown unknown | |
Source: C:\Users\user\AppData\Local\Programs\KyrazonGodot\KyrazonGodot.exe | Process created: unknown unknown | |
Source: C:\Users\user\AppData\Local\Programs\KyrazonGodot\KyrazonGodot.exe | Process created: unknown unknown | |
Source: C:\Users\user\AppData\Local\Programs\KyrazonGodot\KyrazonGodot.exe | Process created: unknown unknown | |
Source: C:\Users\user\AppData\Local\Programs\KyrazonGodot\KyrazonGodot.exe | Process created: C:\Windows\System32\Conhost.exe C:\Windows\system32\conhost.exe 0xffffffff -ForceV1 | |
Source: C:\Users\user\AppData\Local\Programs\KyrazonGodot\KyrazonGodot.exe | Process created: C:\Windows\System32\cmd.exe C:\Windows\system32\cmd.exe /d /s /c "tasklist" | |
Source: C:\Users\user\AppData\Local\Programs\KyrazonGodot\KyrazonGodot.exe | Process created: unknown unknown | |
Source: C:\Users\user\AppData\Local\Programs\KyrazonGodot\KyrazonGodot.exe | Process created: unknown unknown | |
Source: C:\Users\user\AppData\Local\Programs\KyrazonGodot\KyrazonGodot.exe | Process created: unknown unknown | |
Source: C:\Users\user\AppData\Local\Programs\KyrazonGodot\KyrazonGodot.exe | Process created: C:\Windows\System32\Conhost.exe C:\Windows\system32\conhost.exe 0xffffffff -ForceV1 | |
Source: C:\Users\user\AppData\Local\Programs\KyrazonGodot\KyrazonGodot.exe | Process created: C:\Windows\System32\Conhost.exe C:\Windows\system32\conhost.exe 0xffffffff -ForceV1 | |
Source: C:\Users\user\AppData\Local\Programs\KyrazonGodot\KyrazonGodot.exe | Process created: unknown unknown | |
Source: C:\Users\user\AppData\Local\Programs\KyrazonGodot\KyrazonGodot.exe | Process created: unknown unknown | |
Source: C:\Users\user\AppData\Local\Programs\KyrazonGodot\KyrazonGodot.exe | Process created: C:\Windows\System32\Conhost.exe C:\Windows\system32\conhost.exe 0xffffffff -ForceV1 | |
Source: C:\Users\user\AppData\Local\Programs\KyrazonGodot\KyrazonGodot.exe | Process created: unknown unknown | |
Source: C:\Users\user\AppData\Local\Programs\KyrazonGodot\KyrazonGodot.exe | Process created: unknown unknown | |
Source: C:\Users\user\AppData\Local\Programs\KyrazonGodot\KyrazonGodot.exe | Process created: C:\Windows\System32\tasklist.exe tasklist | |
Source: C:\Users\user\AppData\Local\Programs\KyrazonGodot\KyrazonGodot.exe | Process created: unknown unknown | |
Source: C:\Users\user\AppData\Local\Programs\KyrazonGodot\KyrazonGodot.exe | Process created: C:\Windows\System32\cmd.exe C:\Windows\system32\cmd.exe /d /s /c "tasklist" | |
Source: C:\Users\user\AppData\Local\Programs\KyrazonGodot\KyrazonGodot.exe | Process created: unknown unknown | |
Source: C:\Users\user\AppData\Local\Programs\KyrazonGodot\KyrazonGodot.exe | Process created: unknown unknown | |
Source: C:\Users\user\AppData\Local\Programs\KyrazonGodot\KyrazonGodot.exe | Process created: unknown unknown | |
Source: C:\Users\user\AppData\Local\Programs\KyrazonGodot\KyrazonGodot.exe | Process created: unknown unknown | |
Source: C:\Users\user\AppData\Local\Programs\KyrazonGodot\KyrazonGodot.exe | Process created: C:\Windows\System32\cmd.exe C:\Windows\system32\cmd.exe /d /s /c "tasklist" | |
Source: C:\Users\user\AppData\Local\Programs\KyrazonGodot\KyrazonGodot.exe | Process created: C:\Windows\System32\Conhost.exe C:\Windows\system32\conhost.exe 0xffffffff -ForceV1 | |
Source: C:\Users\user\AppData\Local\Programs\KyrazonGodot\KyrazonGodot.exe | Process created: unknown unknown | |
Source: C:\Users\user\AppData\Local\Programs\KyrazonGodot\KyrazonGodot.exe | Process created: unknown unknown | |
Source: C:\Users\user\AppData\Local\Programs\KyrazonGodot\KyrazonGodot.exe | Process created: C:\Windows\System32\Conhost.exe C:\Windows\system32\conhost.exe 0xffffffff -ForceV1 | |
Source: C:\Users\user\AppData\Local\Programs\KyrazonGodot\KyrazonGodot.exe | Process created: unknown unknown | |
Source: C:\Users\user\AppData\Local\Programs\KyrazonGodot\KyrazonGodot.exe | Process created: C:\Windows\System32\tasklist.exe tasklist | |
Source: C:\Users\user\AppData\Local\Programs\KyrazonGodot\KyrazonGodot.exe | Process created: unknown unknown | |
Source: C:\Users\user\AppData\Local\Programs\KyrazonGodot\KyrazonGodot.exe | Process created: unknown unknown | |
Source: C:\Users\user\AppData\Local\Programs\KyrazonGodot\KyrazonGodot.exe | Process created: C:\Windows\System32\cmd.exe C:\Windows\system32\cmd.exe /d /s /c "tasklist" | |
Source: C:\Users\user\AppData\Local\Programs\KyrazonGodot\KyrazonGodot.exe | Process created: unknown unknown | |
Source: C:\Users\user\AppData\Local\Programs\KyrazonGodot\KyrazonGodot.exe | Process created: unknown unknown | |
Source: C:\Users\user\AppData\Local\Programs\KyrazonGodot\KyrazonGodot.exe | Process created: unknown unknown | |
Source: C:\Users\user\AppData\Local\Programs\KyrazonGodot\KyrazonGodot.exe | Process created: unknown unknown | |
Source: C:\Users\user\AppData\Local\Programs\KyrazonGodot\KyrazonGodot.exe | Process created: unknown unknown | |
Source: C:\Users\user\AppData\Local\Programs\KyrazonGodot\KyrazonGodot.exe | Process created: unknown unknown | |
Source: C:\Users\user\AppData\Local\Programs\KyrazonGodot\KyrazonGodot.exe | Process created: unknown unknown | |
Source: C:\Users\user\AppData\Local\Programs\KyrazonGodot\KyrazonGodot.exe | Process created: C:\Windows\System32\conhost.exe C:\Windows\system32\conhost.exe 0xffffffff -ForceV1 | |
Source: C:\Users\user\AppData\Local\Programs\KyrazonGodot\KyrazonGodot.exe | Process created: C:\Windows\System32\Conhost.exe C:\Windows\system32\conhost.exe 0xffffffff -ForceV1 | |
Source: C:\Users\user\AppData\Local\Programs\KyrazonGodot\KyrazonGodot.exe | Process created: unknown unknown | |
Source: C:\Users\user\AppData\Local\Programs\KyrazonGodot\KyrazonGodot.exe | Process created: unknown unknown | |
Source: C:\Users\user\AppData\Local\Programs\KyrazonGodot\KyrazonGodot.exe | Process created: unknown unknown | |
Source: C:\Users\user\AppData\Local\Programs\KyrazonGodot\KyrazonGodot.exe | Process created: C:\Windows\System32\Conhost.exe C:\Windows\system32\conhost.exe 0xffffffff -ForceV1 | |
Source: C:\Users\user\AppData\Local\Programs\KyrazonGodot\KyrazonGodot.exe | Process created: unknown unknown | |
Source: C:\Users\user\AppData\Local\Programs\KyrazonGodot\KyrazonGodot.exe | Process created: C:\Windows\System32\cmd.exe C:\Windows\system32\cmd.exe /d /s /c "tasklist" | |
Source: C:\Users\user\AppData\Local\Programs\KyrazonGodot\KyrazonGodot.exe | Process created: C:\Windows\System32\Conhost.exe C:\Windows\system32\conhost.exe 0xffffffff -ForceV1 | |
Source: C:\Users\user\AppData\Local\Programs\KyrazonGodot\KyrazonGodot.exe | Process created: unknown unknown | |
Source: C:\Users\user\AppData\Local\Programs\KyrazonGodot\KyrazonGodot.exe | Process created: C:\Windows\System32\tasklist.exe tasklist | |
Source: C:\Users\user\AppData\Local\Programs\KyrazonGodot\KyrazonGodot.exe | Process created: unknown unknown | |
Source: C:\Users\user\AppData\Local\Programs\KyrazonGodot\KyrazonGodot.exe | Process created: unknown unknown | |
Source: C:\Users\user\AppData\Local\Programs\KyrazonGodot\KyrazonGodot.exe | Process created: unknown unknown | |
Source: C:\Users\user\AppData\Local\Programs\KyrazonGodot\KyrazonGodot.exe | Process created: unknown unknown | |
Source: C:\Users\user\AppData\Local\Programs\KyrazonGodot\KyrazonGodot.exe | Process created: C:\Windows\System32\Conhost.exe C:\Windows\system32\conhost.exe 0xffffffff -ForceV1 | |
Source: C:\Windows\System32\cmd.exe | Process created: C:\Windows\System32\tasklist.exe tasklist | |
Source: C:\Windows\System32\cmd.exe | Process created: C:\Windows\System32\tasklist.exe tasklist | |
Source: C:\Windows\System32\cmd.exe | Process created: C:\Windows\System32\tasklist.exe tasklist | |
Source: C:\Windows\System32\cmd.exe | Process created: C:\Windows\System32\tasklist.exe tasklist | |
Source: C:\Windows\System32\cmd.exe | Process created: C:\Windows\System32\tasklist.exe tasklist | |
Source: C:\Windows\System32\cmd.exe | Process created: C:\Windows\System32\tasklist.exe tasklist | |
Source: C:\Windows\System32\cmd.exe | Process created: C:\Windows\System32\where.exe where /r . data.sqlite | |
Source: C:\Windows\System32\cmd.exe | Process created: C:\Windows\System32\tasklist.exe tasklist | |
Source: C:\Windows\System32\cmd.exe | Process created: C:\Windows\System32\tasklist.exe tasklist | |
Source: C:\Windows\System32\cmd.exe | Process created: C:\Windows\System32\tasklist.exe tasklist | |
Source: C:\Windows\System32\cmd.exe | Process created: C:\Windows\System32\tasklist.exe tasklist | |
Source: C:\Windows\System32\cmd.exe | Process created: C:\Windows\System32\tasklist.exe tasklist | |
Source: C:\Windows\System32\cmd.exe | Process created: C:\Windows\System32\tasklist.exe tasklist | |
Source: C:\Windows\System32\cmd.exe | Process created: C:\Windows\System32\tasklist.exe tasklist | |
Source: C:\Windows\System32\cmd.exe | Process created: C:\Windows\System32\tasklist.exe tasklist | |
Source: C:\Windows\System32\cmd.exe | Process created: C:\Windows\System32\tasklist.exe tasklist | |
Source: C:\Windows\System32\cmd.exe | Process created: C:\Windows\System32\tasklist.exe tasklist | |
Source: C:\Windows\System32\cmd.exe | Process created: unknown unknown | |
Source: C:\Users\user\AppData\Local\Programs\KyrazonGodot\KyrazonGodot.exe | Queries volume information: C:\ VolumeInformation | Jump to behavior |
Source: C:\Users\user\AppData\Local\Programs\KyrazonGodot\KyrazonGodot.exe | Queries volume information: C:\Windows\System32\drivers\etc\hosts VolumeInformation | Jump to behavior |
Source: C:\Users\user\AppData\Local\Programs\KyrazonGodot\KyrazonGodot.exe | Queries volume information: C:\Windows\System32\spool\drivers\color\sRGB Color Space Profile.icm VolumeInformation | Jump to behavior |
Source: C:\Users\user\AppData\Local\Programs\KyrazonGodot\KyrazonGodot.exe | Queries volume information: C:\Users\user\AppData\Local\Programs\KyrazonGodot\resources\app.asar.unpacked\node_modules\windows-shortcuts\package.json VolumeInformation | Jump to behavior |
Source: C:\Users\user\AppData\Local\Programs\KyrazonGodot\KyrazonGodot.exe | Queries volume information: C:\Users\user\AppData\Local\Programs\KyrazonGodot\resources\app.asar.unpacked\node_modules\windows-shortcuts\lib\windows-shortcuts.js VolumeInformation | Jump to behavior |
Source: C:\Users\user\AppData\Local\Programs\KyrazonGodot\KyrazonGodot.exe | Queries volume information: C:\Users\user\Downloads VolumeInformation | Jump to behavior |
Source: C:\Users\user\AppData\Local\Programs\KyrazonGodot\KyrazonGodot.exe | Queries volume information: C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Local Storage\leveldb VolumeInformation | Jump to behavior |
Source: C:\Users\user\AppData\Local\Programs\KyrazonGodot\KyrazonGodot.exe | Queries volume information: C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Local Storage\leveldb\000003.log VolumeInformation | Jump to behavior |
Source: C:\Users\user\AppData\Local\Programs\KyrazonGodot\KyrazonGodot.exe | Queries volume information: C:\Users\user\AppData\Local\Microsoft\Edge\User Data\Default\Local Storage\leveldb VolumeInformation | Jump to behavior |
Source: C:\Users\user\AppData\Local\Programs\KyrazonGodot\KyrazonGodot.exe | Queries volume information: C:\Users\user\AppData\Local\Microsoft\Edge\User Data\Default\Local Storage\leveldb\000003.log VolumeInformation | Jump to behavior |
Source: C:\Users\user\AppData\Local\Programs\KyrazonGodot\KyrazonGodot.exe | Queries volume information: C:\Users\user\Downloads\BPMLNOBVSB.pdf VolumeInformation | Jump to behavior |
Source: C:\Users\user\AppData\Local\Programs\KyrazonGodot\KyrazonGodot.exe | Queries volume information: C:\Users\user\Downloads\CURQNKVOIX.jpg VolumeInformation | Jump to behavior |
Source: C:\Users\user\AppData\Local\Programs\KyrazonGodot\KyrazonGodot.exe | Queries volume information: C:\Users\user\Downloads\YPSIACHYXW.jpg VolumeInformation | Jump to behavior |
Source: C:\Users\user\AppData\Local\Programs\KyrazonGodot\KyrazonGodot.exe | Queries volume information: C:\Users\user\Downloads\desktop.ini VolumeInformation | Jump to behavior |
Source: C:\Users\user\AppData\Local\Programs\KyrazonGodot\KyrazonGodot.exe | Queries volume information: C:\Users\user\Documents VolumeInformation | Jump to behavior |
Source: C:\Users\user\AppData\Local\Programs\KyrazonGodot\KyrazonGodot.exe | Queries volume information: C:\Users\user\Documents\CURQNKVOIX.jpg VolumeInformation | Jump to behavior |
Source: C:\Users\user\AppData\Local\Programs\KyrazonGodot\KyrazonGodot.exe | Queries volume information: C:\Users\user\Documents\GAOBCVIQIJ VolumeInformation | Jump to behavior |
Source: C:\Users\user\AppData\Local\Programs\KyrazonGodot\KyrazonGodot.exe | Queries volume information: C:\Users\user\Documents\JSDNGYCOWY.mp3 VolumeInformation | Jump to behavior |
Source: C:\Users\user\AppData\Local\Programs\KyrazonGodot\KyrazonGodot.exe | Queries volume information: C:\Users\user\Documents\JSDNGYCOWY.pdf VolumeInformation | Jump to behavior |
Source: C:\Users\user\AppData\Local\Programs\KyrazonGodot\KyrazonGodot.exe | Queries volume information: C:\Users\user\Documents\JSDNGYCOWY.xlsx VolumeInformation | Jump to behavior |
Source: C:\Users\user\AppData\Local\Programs\KyrazonGodot\KyrazonGodot.exe | Queries volume information: C:\Users\user\Documents\NIKHQAIQAU.jpg VolumeInformation | Jump to behavior |
Source: C:\Users\user\AppData\Local\Programs\KyrazonGodot\KyrazonGodot.exe | Queries volume information: C:\Users\user\Documents\NWTVCDUMOB VolumeInformation | Jump to behavior |
Source: C:\Users\user\AppData\Local\Programs\KyrazonGodot\KyrazonGodot.exe | Queries volume information: C:\Users\user\Documents\NWTVCDUMOB.xlsx VolumeInformation | Jump to behavior |
Source: C:\Users\user\AppData\Local\Programs\KyrazonGodot\KyrazonGodot.exe | Queries volume information: C:\Users\user\Documents\ZTGJILHXQB VolumeInformation | Jump to behavior |
Source: C:\Users\user\AppData\Local\Programs\KyrazonGodot\KyrazonGodot.exe | Queries volume information: C:\Users\user\Desktop\NWTVCDUMOB.docx VolumeInformation | Jump to behavior |
Source: C:\Users\user\AppData\Local\Programs\KyrazonGodot\KyrazonGodot.exe | Queries volume information: C:\Users\user\Desktop\RAYHIWGKDI.png VolumeInformation | Jump to behavior |
Source: C:\Users\user\AppData\Local\Programs\KyrazonGodot\KyrazonGodot.exe | Queries volume information: C:\Users\user\Desktop\WUTJSCBCFX.docx VolumeInformation | Jump to behavior |
Source: C:\Users\user\AppData\Local\Programs\KyrazonGodot\KyrazonGodot.exe | Queries volume information: C:\Users\user\AppData\Local\Google\Chrome\User Data\Local State VolumeInformation | Jump to behavior |
Source: C:\Users\user\AppData\Local\Programs\KyrazonGodot\KyrazonGodot.exe | Queries volume information: C:\Users\user\AppData\Local\Microsoft\Edge\User Data\Local State VolumeInformation | Jump to behavior |
Source: C:\Users\user\AppData\Local\Programs\KyrazonGodot\KyrazonGodot.exe | Queries volume information: C:\Users\user\AppData\Local\Google\Chrome\User Data\Local State VolumeInformation | Jump to behavior |
Source: C:\Users\user\AppData\Local\Programs\KyrazonGodot\KyrazonGodot.exe | Queries volume information: C:\Users\user\AppData\Local\Temp\8488a434-1fc5-4133-b739-6e418d7388dc VolumeInformation | Jump to behavior |
Source: C:\Users\user\AppData\Local\Programs\KyrazonGodot\KyrazonGodot.exe | Queries volume information: C:\Users\user\AppData\Local\Temp\8488a434-1fc5-4133-b739-6e418d7388dc\Applications VolumeInformation | Jump to behavior |
Source: C:\Users\user\AppData\Local\Programs\KyrazonGodot\KyrazonGodot.exe | Queries volume information: C:\Users\user\AppData\Local\Temp\8488a434-1fc5-4133-b739-6e418d7388dc\Applications VolumeInformation | Jump to behavior |
Source: C:\Users\user\AppData\Local\Programs\KyrazonGodot\KyrazonGodot.exe | Queries volume information: C:\Users\user\AppData\Local\Temp\8488a434-1fc5-4133-b739-6e418d7388dc\Cookies\Google_Default.txt VolumeInformation | Jump to behavior |
Source: C:\Users\user\AppData\Local\Programs\KyrazonGodot\KyrazonGodot.exe | Queries volume information: C:\Users\user\AppData\Local\Temp\8488a434-1fc5-4133-b739-6e418d7388dc\Cookies\Google_Default.txt VolumeInformation | Jump to behavior |
Source: C:\Users\user\AppData\Local\Programs\KyrazonGodot\KyrazonGodot.exe | Queries volume information: C:\Users\user\AppData\Local\Temp\8488a434-1fc5-4133-b739-6e418d7388dc\Applications VolumeInformation | Jump to behavior |
Source: C:\Users\user\AppData\Local\Programs\KyrazonGodot\KyrazonGodot.exe | Queries volume information: C:\Users\user\AppData\Local\Temp\8488a434-1fc5-4133-b739-6e418d7388dc\Browser Extensions VolumeInformation | Jump to behavior |
Source: C:\Users\user\AppData\Local\Programs\KyrazonGodot\KyrazonGodot.exe | Queries volume information: C:\Users\user\AppData\Local\Temp\8488a434-1fc5-4133-b739-6e418d7388dc\Cookies\Google_Default.txt VolumeInformation | Jump to behavior |
Source: C:\Users\user\AppData\Local\Programs\KyrazonGodot\KyrazonGodot.exe | Queries volume information: C:\Users\user\AppData\Local\Temp\8488a434-1fc5-4133-b739-6e418d7388dc\Passwords\Google_Default.txt VolumeInformation | Jump to behavior |
Source: C:\Users\user\AppData\Local\Programs\KyrazonGodot\KyrazonGodot.exe | Queries volume information: C:\Users\user\AppData\Local\Temp VolumeInformation | Jump to behavior |
Source: C:\Users\user\AppData\Local\Programs\KyrazonGodot\KyrazonGodot.exe | Queries volume information: C:\Users\user\AppData\Local\Temp\8488a434-1fc5-4133-b739-6e418d7388dc.zip VolumeInformation | Jump to behavior |
Source: C:\Users\user\AppData\Local\Programs\KyrazonGodot\KyrazonGodot.exe | Queries volume information: C:\Users\user\AppData\Local\Temp\8488a434-1fc5-4133-b739-6e418d7388dc.zip VolumeInformation | Jump to behavior |
Source: C:\Users\user\AppData\Local\Programs\KyrazonGodot\KyrazonGodot.exe | Queries volume information: C:\Users\user\AppData\Local\Temp\8488a434-1fc5-4133-b739-6e418d7388dc.zip VolumeInformation | Jump to behavior |
Source: C:\Users\user\AppData\Local\Programs\KyrazonGodot\KyrazonGodot.exe | Queries volume information: C:\Users\user\AppData\Local\Temp\8488a434-1fc5-4133-b739-6e418d7388dc.zip VolumeInformation | Jump to behavior |
Source: C:\Users\user\AppData\Local\Programs\KyrazonGodot\KyrazonGodot.exe | Queries volume information: C:\Users\user\AppData\Local\Temp\8488a434-1fc5-4133-b739-6e418d7388dc.zip VolumeInformation | Jump to behavior |
Source: C:\Users\user\AppData\Local\Programs\KyrazonGodot\KyrazonGodot.exe | Queries volume information: C:\Users\user\AppData\Local\Temp\8488a434-1fc5-4133-b739-6e418d7388dc\Applications VolumeInformation | Jump to behavior |
Source: C:\Users\user\AppData\Local\Programs\KyrazonGodot\KyrazonGodot.exe | Queries volume information: C:\Users\user\AppData\Local\Temp\8488a434-1fc5-4133-b739-6e418d7388dc\Cookies VolumeInformation | Jump to behavior |
Source: C:\Users\user\AppData\Local\Programs\KyrazonGodot\KyrazonGodot.exe | Queries volume information: C:\Users\user\AppData\Local\Temp\8488a434-1fc5-4133-b739-6e418d7388dc\Discord Tokens VolumeInformation | Jump to behavior |
Source: C:\Users\user\AppData\Local\Programs\KyrazonGodot\KyrazonGodot.exe | Queries volume information: C:\Users\user\AppData\Local\Temp\8488a434-1fc5-4133-b739-6e418d7388dc\Browser Extensions VolumeInformation | Jump to behavior |
Source: C:\Users\user\AppData\Local\Programs\KyrazonGodot\KyrazonGodot.exe | Queries volume information: C:\Users\user\AppData\Local\Temp\8488a434-1fc5-4133-b739-6e418d7388dc\Applications VolumeInformation | Jump to behavior |
Source: C:\Users\user\AppData\Local\Programs\KyrazonGodot\KyrazonGodot.exe | Queries volume information: C:\Users\user\AppData\Local\Temp\8488a434-1fc5-4133-b739-6e418d7388dc\Important Files VolumeInformation | Jump to behavior |
Source: C:\Users\user\AppData\Local\Programs\KyrazonGodot\KyrazonGodot.exe | Queries volume information: C:\Users\user\AppData\Local\Temp\8488a434-1fc5-4133-b739-6e418d7388dc\Cookies\Google_Default.txt VolumeInformation | Jump to behavior |
Source: C:\Users\user\AppData\Local\Programs\KyrazonGodot\KyrazonGodot.exe | Queries volume information: C:\Users\user\AppData\Local\Temp\8488a434-1fc5-4133-b739-6e418d7388dc\Passwords\Google_Default.txt VolumeInformation | Jump to behavior |
Source: C:\Users\user\AppData\Local\Programs\KyrazonGodot\KyrazonGodot.exe | Queries volume information: C:\Users\user\AppData\Local\Temp\8488a434-1fc5-4133-b739-6e418d7388dc\Passwords\Microsoft_Default.txt VolumeInformation | Jump to behavior |
Source: C:\Users\user\AppData\Local\Programs\KyrazonGodot\KyrazonGodot.exe | Queries volume information: C:\Users\user\AppData\Local\Temp\8488a434-1fc5-4133-b739-6e418d7388dc VolumeInformation | Jump to behavior |
Source: C:\Users\user\AppData\Local\Programs\KyrazonGodot\KyrazonGodot.exe | Queries volume information: C:\Users\user\AppData\Local\Temp\8488a434-1fc5-4133-b739-6e418d7388dc VolumeInformation | Jump to behavior |
Source: C:\Users\user\AppData\Local\Programs\KyrazonGodot\resources\app.asar.unpacked\node_modules\windows-shortcuts\lib\shortcut\Shortcut.exe | Queries volume information: C:\ VolumeInformation | |
Source: C:\Users\user\AppData\Local\Programs\KyrazonGodot\KyrazonGodot.exe | Queries volume information: C:\Windows\System32\drivers\etc\hosts VolumeInformation | |
Source: C:\Users\user\AppData\Local\Programs\KyrazonGodot\KyrazonGodot.exe | Queries volume information: C:\ VolumeInformation | |
Source: C:\Users\user\AppData\Local\Programs\KyrazonGodot\KyrazonGodot.exe | Queries volume information: C:\Users VolumeInformation | |
Source: C:\Users\user\AppData\Local\Programs\KyrazonGodot\KyrazonGodot.exe | Queries volume information: C:\Users\user VolumeInformation | |
Source: C:\Users\user\AppData\Local\Programs\KyrazonGodot\KyrazonGodot.exe | Queries volume information: C:\Users\user\AppData\Local\Programs\KyrazonGodot\resources VolumeInformation | |
Source: C:\Users\user\AppData\Local\Programs\KyrazonGodot\KyrazonGodot.exe | Queries volume information: C:\Users\user\AppData\Roaming\KyrazonGodot\Local State VolumeInformation | |
Source: C:\Users\user\AppData\Local\Programs\KyrazonGodot\KyrazonGodot.exe | Queries volume information: C:\Windows\System32\drivers\etc\hosts VolumeInformation | |
Source: C:\Users\user\AppData\Local\Programs\KyrazonGodot\KyrazonGodot.exe | Queries volume information: C:\Users\user\AppData\Local\Programs\KyrazonGodot\resources\app.asar.unpacked\node_modules\windows-shortcuts\package.json VolumeInformation | |
Source: C:\Users\user\AppData\Local\Programs\KyrazonGodot\KyrazonGodot.exe | Queries volume information: C:\Users\user\AppData\Local\Programs\KyrazonGodot\resources\app.asar.unpacked\node_modules\windows-shortcuts\lib\windows-shortcuts.js VolumeInformation | |
Source: C:\Users\user\AppData\Local\Programs\KyrazonGodot\KyrazonGodot.exe | Queries volume information: C:\Windows\System32\spool\drivers\color\sRGB Color Space Profile.icm VolumeInformation | |
Source: C:\Users\user\AppData\Local\Programs\KyrazonGodot\KyrazonGodot.exe | Queries volume information: C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Local Storage\leveldb VolumeInformation | |
Source: C:\Users\user\AppData\Local\Programs\KyrazonGodot\KyrazonGodot.exe | Queries volume information: C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Local Storage\leveldb\000003.log VolumeInformation | |
Source: C:\Users\user\AppData\Local\Programs\KyrazonGodot\KyrazonGodot.exe | Queries volume information: C:\Users\user\AppData\Local\Microsoft\Edge\User Data\Default\Local Storage\leveldb VolumeInformation | |
Source: C:\Users\user\AppData\Local\Programs\KyrazonGodot\KyrazonGodot.exe | Queries volume information: C:\Users\user\AppData\Local\Microsoft\Edge\User Data\Default\Local Storage\leveldb\000003.log VolumeInformation | |
Source: C:\Users\user\AppData\Local\Programs\KyrazonGodot\KyrazonGodot.exe | Queries volume information: C:\Users\user\Downloads VolumeInformation | |
Source: C:\Users\user\AppData\Local\Programs\KyrazonGodot\KyrazonGodot.exe | Queries volume information: C:\Users\user\Downloads\BPMLNOBVSB.pdf VolumeInformation | |
Source: C:\Users\user\AppData\Local\Programs\KyrazonGodot\KyrazonGodot.exe | Queries volume information: C:\Users\user\Downloads\CURQNKVOIX.jpg VolumeInformation | |
Source: C:\Users\user\AppData\Local\Programs\KyrazonGodot\KyrazonGodot.exe | Queries volume information: C:\Users\user\Downloads\JSDNGYCOWY.pdf VolumeInformation | |
Source: C:\Users\user\AppData\Local\Programs\KyrazonGodot\KyrazonGodot.exe | Queries volume information: C:\Users\user\Downloads\JSDNGYCOWY.xlsx VolumeInformation | |
Source: C:\Users\user\AppData\Local\Programs\KyrazonGodot\KyrazonGodot.exe | Queries volume information: C:\Users\user\Downloads\NWTVCDUMOB.xlsx VolumeInformation | |
Source: C:\Users\user\AppData\Local\Programs\KyrazonGodot\KyrazonGodot.exe | Queries volume information: C:\Users\user\Downloads\WUTJSCBCFX.pdf VolumeInformation | |
Source: C:\Users\user\AppData\Local\Programs\KyrazonGodot\KyrazonGodot.exe | Queries volume information: C:\Users\user\Downloads\YPSIACHYXW.jpg VolumeInformation | |
Source: C:\Users\user\AppData\Local\Programs\KyrazonGodot\KyrazonGodot.exe | Queries volume information: C:\Users\user\Downloads\YPSIACHYXW.xlsx VolumeInformation | |
Source: C:\Users\user\AppData\Local\Programs\KyrazonGodot\KyrazonGodot.exe | Queries volume information: C:\Users\user\Documents\CURQNKVOIX.jpg VolumeInformation | |
Source: C:\Users\user\AppData\Local\Programs\KyrazonGodot\KyrazonGodot.exe | Queries volume information: C:\Users\user\Documents\CURQNKVOIX.mp3 VolumeInformation | |
Source: C:\Users\user\AppData\Local\Programs\KyrazonGodot\KyrazonGodot.exe | Queries volume information: C:\Users\user\Documents\GAOBCVIQIJ VolumeInformation | |
Source: C:\Users\user\AppData\Local\Programs\KyrazonGodot\KyrazonGodot.exe | Queries volume information: C:\Users\user\Documents\LTKMYBSEYZ.docx VolumeInformation | |
Source: C:\Users\user\AppData\Local\Programs\KyrazonGodot\KyrazonGodot.exe | Queries volume information: C:\Users\user\Documents\MXPXCVPDVN.mp3 VolumeInformation | |
Source: C:\Users\user\AppData\Local\Programs\KyrazonGodot\KyrazonGodot.exe | Queries volume information: C:\Users\user\Pictures VolumeInformation | |
Source: C:\Users\user\AppData\Local\Programs\KyrazonGodot\KyrazonGodot.exe | Queries volume information: C:\Users\user\Documents\NWTVCDUMOB.xlsx VolumeInformation | |
Source: C:\Users\user\AppData\Local\Programs\KyrazonGodot\KyrazonGodot.exe | Queries volume information: C:\Users\user\AppData\Local\Google\Chrome\User Data\Local State VolumeInformation | |
Source: C:\Users\user\AppData\Local\Programs\KyrazonGodot\KyrazonGodot.exe | Queries volume information: C:\Users\user\AppData\Local\Microsoft\Edge\User Data\Local State VolumeInformation | |
Source: C:\Users\user\AppData\Local\Programs\KyrazonGodot\KyrazonGodot.exe | Queries volume information: C:\Users\user\AppData\Local\Google\Chrome\User Data\Local State VolumeInformation | |
Source: C:\Users\user\AppData\Local\Programs\KyrazonGodot\KyrazonGodot.exe | Queries volume information: C:\Users\user\AppData\Local\Temp\a1b85b9a-05dd-4677-8ea9-2048d24632a6 VolumeInformation | |
Source: C:\Users\user\AppData\Local\Programs\KyrazonGodot\KyrazonGodot.exe | Queries volume information: C:\Users\user\AppData\Local\Temp\a1b85b9a-05dd-4677-8ea9-2048d24632a6\Applications VolumeInformation | |
Source: C:\Users\user\AppData\Local\Programs\KyrazonGodot\KyrazonGodot.exe | Queries volume information: C:\Users\user\AppData\Local\Temp\a1b85b9a-05dd-4677-8ea9-2048d24632a6\Cookies\Google_Default.txt VolumeInformation | |
Source: C:\Users\user\AppData\Local\Programs\KyrazonGodot\KyrazonGodot.exe | Queries volume information: C:\Users\user\AppData\Local\Temp\a1b85b9a-05dd-4677-8ea9-2048d24632a6\Applications VolumeInformation | |
Source: C:\Users\user\AppData\Local\Programs\KyrazonGodot\KyrazonGodot.exe | Queries volume information: C:\Users\user\AppData\Local\Temp\a1b85b9a-05dd-4677-8ea9-2048d24632a6\Browser Extensions VolumeInformation | |
Source: C:\Users\user\AppData\Local\Programs\KyrazonGodot\KyrazonGodot.exe | Queries volume information: C:\Users\user\AppData\Local\Temp\a1b85b9a-05dd-4677-8ea9-2048d24632a6\Cookies\Google_Default.txt VolumeInformation | |
Source: C:\Users\user\AppData\Local\Programs\KyrazonGodot\KyrazonGodot.exe | Queries volume information: C:\Users\user\AppData\Local\Temp\a1b85b9a-05dd-4677-8ea9-2048d24632a6\Cookies VolumeInformation | |
Source: C:\Users\user\AppData\Local\Programs\KyrazonGodot\KyrazonGodot.exe | Queries volume information: C:\Users\user\AppData\Local\Temp\a1b85b9a-05dd-4677-8ea9-2048d24632a6\Passwords\Google_Default.txt VolumeInformation | |
Source: C:\Users\user\AppData\Local\Programs\KyrazonGodot\KyrazonGodot.exe | Queries volume information: C:\Users\user\AppData\Local\Temp\a1b85b9a-05dd-4677-8ea9-2048d24632a6\Passwords VolumeInformation | |
Source: C:\Users\user\AppData\Local\Programs\KyrazonGodot\KyrazonGodot.exe | Queries volume information: C:\Users\user\AppData\Local\Temp VolumeInformation | |
Source: C:\Users\user\AppData\Local\Programs\KyrazonGodot\KyrazonGodot.exe | Queries volume information: C:\Users\user\AppData\Local\Temp\a1b85b9a-05dd-4677-8ea9-2048d24632a6.zip VolumeInformation | |
Source: C:\Users\user\AppData\Local\Programs\KyrazonGodot\KyrazonGodot.exe | Queries volume information: C:\Users\user\AppData\Local\Temp\a1b85b9a-05dd-4677-8ea9-2048d24632a6.zip VolumeInformation | |
Source: C:\Users\user\AppData\Local\Programs\KyrazonGodot\KyrazonGodot.exe | Queries volume information: C:\Users\user\AppData\Local\Temp\a1b85b9a-05dd-4677-8ea9-2048d24632a6.zip VolumeInformation | |
Source: C:\Users\user\AppData\Local\Programs\KyrazonGodot\KyrazonGodot.exe | Queries volume information: C:\Users\user\AppData\Local\Temp\a1b85b9a-05dd-4677-8ea9-2048d24632a6.zip VolumeInformation | |
Source: C:\Users\user\AppData\Local\Programs\KyrazonGodot\KyrazonGodot.exe | Queries volume information: C:\Users\user\AppData\Local\Temp\a1b85b9a-05dd-4677-8ea9-2048d24632a6.zip VolumeInformation | |
Source: C:\Users\user\AppData\Local\Programs\KyrazonGodot\KyrazonGodot.exe | Queries volume information: C:\Users\user\AppData\Local\Temp\a1b85b9a-05dd-4677-8ea9-2048d24632a6.zip VolumeInformation | |
Source: C:\Users\user\AppData\Local\Programs\KyrazonGodot\KyrazonGodot.exe | Queries volume information: C:\Users\user\AppData\Local\Temp\a1b85b9a-05dd-4677-8ea9-2048d24632a6\Discord Tokens VolumeInformation | |
Source: C:\Users\user\AppData\Local\Programs\KyrazonGodot\KyrazonGodot.exe | Queries volume information: C:\Users\user\AppData\Local\Temp\a1b85b9a-05dd-4677-8ea9-2048d24632a6\Cookies VolumeInformation | |
Source: C:\Users\user\AppData\Local\Programs\KyrazonGodot\KyrazonGodot.exe | Queries volume information: C:\Users\user\AppData\Local\Temp\a1b85b9a-05dd-4677-8ea9-2048d24632a6\Important Files VolumeInformation | |
Source: C:\Users\user\AppData\Local\Programs\KyrazonGodot\KyrazonGodot.exe | Queries volume information: C:\Users\user\AppData\Local\Temp\a1b85b9a-05dd-4677-8ea9-2048d24632a6\Cookies\Google_Default.txt VolumeInformation | |
Source: C:\Users\user\AppData\Local\Programs\KyrazonGodot\KyrazonGodot.exe | Queries volume information: C:\Users\user\AppData\Local\Temp\a1b85b9a-05dd-4677-8ea9-2048d24632a6\Passwords\Google_Default.txt VolumeInformation | |
Source: C:\Users\user\AppData\Local\Programs\KyrazonGodot\KyrazonGodot.exe | Queries volume information: C:\Users\user\AppData\Local\Temp\a1b85b9a-05dd-4677-8ea9-2048d24632a6\Passwords\Google_Default.txt VolumeInformation | |
Source: C:\Users\user\AppData\Local\Programs\KyrazonGodot\KyrazonGodot.exe | Queries volume information: C:\Windows\System32\drivers\etc\hosts VolumeInformation | |