Source: | Binary string: D:\a\_work\e\src\out\Release_x64\WebView2Loader.dll.pdb source: SecuriteInfo.com.Trojan.Win64.Meterpreter.11595.2675.exe, 00000000.00000003.2145293156.000001BF13B8D000.00000004.00000020.00020000.00000000.sdmp |
Source: | Binary string: /download/symbols/twinui.pcshell.pdb/56A53B20B8D4F79E69038072C21547311/twinui.pcshell.pdb source: explorer.exe, 0000000B.00000003.2234944578.0000000002E7D000.00000004.00000020.00020000.00000000.sdmp, explorer.exe, 0000000B.00000003.2332407476.0000000002E7D000.00000004.00000020.00020000.00000000.sdmp |
Source: | Binary string: twinui.pcshell.pdb source: explorer.exe, 0000000A.00000003.2167375925.00000000027E3000.00000004.00000020.00020000.00000000.sdmp, explorer.exe, 0000000B.00000003.2174577379.00000000023D5000.00000004.00000020.00020000.00000000.sdmp, explorer.exe, 0000000B.00000003.2178744483.0000000002D5E000.00000004.00000020.00020000.00000000.sdmp, explorer.exe, 0000000B.00000003.2176793588.00000000023D4000.00000004.00000020.00020000.00000000.sdmp |
Source: | Binary string: http://msdl.microsoft.com/download/symbols/twinui.pcshell.pdb/56A53B20B8D4F79E69038072C21547311/twinui.pcshell.pdb source: explorer.exe, 0000000B.00000003.2198671395.0000000002ED7000.00000004.00000020.00020000.00000000.sdmp, explorer.exe, 0000000B.00000003.2192876585.0000000002F1D000.00000004.00000020.00020000.00000000.sdmp, explorer.exe, 0000000B.00000003.2235994933.0000000002F37000.00000004.00000020.00020000.00000000.sdmp, explorer.exe, 0000000B.00000003.2246571830.0000000002F1D000.00000004.00000020.00020000.00000000.sdmp, explorer.exe, 0000000B.00000003.2192876585.0000000002F48000.00000004.00000020.00020000.00000000.sdmp, explorer.exe, 0000000B.00000003.2193206748.0000000002EBD000.00000004.00000020.00020000.00000000.sdmp, explorer.exe, 0000000B.00000003.2288267379.0000000002F1D000.00000004.00000020.00020000.00000000.sdmp, explorer.exe, 0000000B.00000003.2198671395.0000000002F1D000.00000004.00000020.00020000.00000000.sdmp, explorer.exe, 0000000B.00000003.2252874097.0000000002F1D000.00000004.00000020.00020000.00000000.sdmp, explorer.exe, 0000000B.00000003.2235994933.0000000002F1D000.00000004.00000020.00020000.00000000.sdmp, explorer.exe, 0000000B.00000003.2204325725.0000000002F33000.00000004.00000020.00020000.00000000.sdmp, explorer.exe, 0000000B.00000003.2320144168.0000000002F1D000.00000004.00000020.00020000.00000000.sdmp, explorer.exe, 0000000B.00000003.2381212820.0000000002F1D000.00000004.00000020.00020000.00000000.sdmp, explorer.exe, 0000000B.00000003.2234944578.0000000002F37000.00000004.00000020.00020000.00000000.sdmp, explorer.exe, 0000000B.00000003.2234944578.0000000002F1D000.00000004.00000020.00020000.00000000.sdmp |
Source: | Binary string: D:\a\ExplorerPatcher\ExplorerPatcher\build\Release\x64\ExplorerPatcher.amd64.pdb source: SecuriteInfo.com.Trojan.Win64.Meterpreter.11595.2675.exe, 00000000.00000003.2146053134.000001BF162C1000.00000004.00000020.00020000.00000000.sdmp, explorer.exe, 0000000A.00000002.2175083796.00007FF8BEE7D000.00000002.00000001.01000000.00000008.sdmp |
Source: | Binary string: D:\a\ExplorerPatcher\ExplorerPatcher\build\Release\x64\ep_weather_host_stub.pdb source: SecuriteInfo.com.Trojan.Win64.Meterpreter.11595.2675.exe, 00000000.00000003.2145109319.000001BF13BA7000.00000004.00000020.00020000.00000000.sdmp, SecuriteInfo.com.Trojan.Win64.Meterpreter.11595.2675.exe, 00000000.00000003.2145084872.000001BF13B8D000.00000004.00000020.00020000.00000000.sdmp |
Source: | Binary string: D:\a\_work\e\src\out\Release_x64\WebView2Loader.dll.pdbOGP source: SecuriteInfo.com.Trojan.Win64.Meterpreter.11595.2675.exe, 00000000.00000003.2145293156.000001BF13B8D000.00000004.00000020.00020000.00000000.sdmp |
Source: | Binary string: http://msdl.microsoft.com/download/symbols/twinui.pcshell.pdb/56A53B20B8D4F79E69038072C21547311/twinui.pcshell.pdby source: explorer.exe, 0000000B.00000003.2192876585.0000000002F1D000.00000004.00000020.00020000.00000000.sdmp, explorer.exe, 0000000B.00000003.2198671395.0000000002F1D000.00000004.00000020.00020000.00000000.sdmp |
Source: | Binary string: D:\a\ExplorerPatcher\ExplorerPatcher\build\Release\x64\ep_dwm.pdb source: SecuriteInfo.com.Trojan.Win64.Meterpreter.11595.2675.exe, 00000000.00000003.2144537598.000001BF13B8D000.00000004.00000020.00020000.00000000.sdmp, SecuriteInfo.com.Trojan.Win64.Meterpreter.11595.2675.exe, 00000000.00000003.2144601951.000001BF13BA9000.00000004.00000020.00020000.00000000.sdmp |
Source: | Binary string: StartUI.pdb source: explorer.exe, 0000000A.00000003.2166635686.00000000027EA000.00000004.00000020.00020000.00000000.sdmp, explorer.exe, 0000000B.00000003.2175731585.00000000023D3000.00000004.00000020.00020000.00000000.sdmp |
Source: | Binary string: .pcshell.pdb source: explorer.exe, 0000000B.00000003.2235994933.0000000002F37000.00000004.00000020.00020000.00000000.sdmp, explorer.exe, 0000000B.00000003.2246571830.0000000002F1D000.00000004.00000020.00020000.00000000.sdmp, explorer.exe, 0000000B.00000003.2288267379.0000000002F1D000.00000004.00000020.00020000.00000000.sdmp, explorer.exe, 0000000B.00000003.2252874097.0000000002F1D000.00000004.00000020.00020000.00000000.sdmp, explorer.exe, 0000000B.00000003.2204325725.0000000002F33000.00000004.00000020.00020000.00000000.sdmp, explorer.exe, 0000000B.00000003.2320144168.0000000002F1D000.00000004.00000020.00020000.00000000.sdmp, explorer.exe, 0000000B.00000003.2381212820.0000000002F1D000.00000004.00000020.00020000.00000000.sdmp, explorer.exe, 0000000B.00000003.2234944578.0000000002F37000.00000004.00000020.00020000.00000000.sdmp |
Source: | Binary string: {"function" : "getkfmupsellstate", "args" : {}}.pdb source: explorer.exe, 0000000B.00000003.2377129178.000000000AF04000.00000004.00000020.00020000.00000000.sdmp |
Source: | Binary string: http://msdl.microsoft.com/download/symbols/twinui.pcshell.pdb/56A53B20B8D4F79E69038072C21547311/twinui.pcshell.pdbb source: explorer.exe, 0000000B.00000003.2198671395.0000000002F1D000.00000004.00000020.00020000.00000000.sdmp |
Source: | Binary string: http://msdl.microsoft.com/download/symbols/twinui.pcshell.pdb/56A53B20B8D4F79E69038072C21547311/twinui.pcshell.pdb! source: explorer.exe, 0000000B.00000003.2192876585.0000000002F1D000.00000004.00000020.00020000.00000000.sdmp, explorer.exe, 0000000B.00000003.2246571830.0000000002F1D000.00000004.00000020.00020000.00000000.sdmp, explorer.exe, 0000000B.00000003.2288267379.0000000002F1D000.00000004.00000020.00020000.00000000.sdmp, explorer.exe, 0000000B.00000003.2198671395.0000000002F1D000.00000004.00000020.00020000.00000000.sdmp, explorer.exe, 0000000B.00000003.2252874097.0000000002F1D000.00000004.00000020.00020000.00000000.sdmp, explorer.exe, 0000000B.00000003.2235994933.0000000002F1D000.00000004.00000020.00020000.00000000.sdmp, explorer.exe, 0000000B.00000003.2320144168.0000000002F1D000.00000004.00000020.00020000.00000000.sdmp, explorer.exe, 0000000B.00000003.2234944578.0000000002F1D000.00000004.00000020.00020000.00000000.sdmp |
Source: | Binary string: C:\Users\user\AppData\Roaming\ExplorerPatcher\twinui.pcshell.pdb{ source: explorer.exe, 0000000B.00000003.2377129178.000000000AF04000.00000004.00000020.00020000.00000000.sdmp |
Source: | Binary string: D:\a\ExplorerPatcher\ExplorerPatcher\build\Release\Win32\ExplorerPatcher.IA-32.pdb source: SecuriteInfo.com.Trojan.Win64.Meterpreter.11595.2675.exe, 00000000.00000003.2143630593.000001BF13BB2000.00000004.00000020.00020000.00000000.sdmp, SecuriteInfo.com.Trojan.Win64.Meterpreter.11595.2675.exe, 00000000.00000003.2143599851.000001BF13B8D000.00000004.00000020.00020000.00000000.sdmp |
Source: | Binary string: D:\a\ExplorerPatcher\ExplorerPatcher\build\Release\x64\ep_setup.pdb source: SecuriteInfo.com.Trojan.Win64.Meterpreter.11595.2675.exe, 00000000.00000002.2165080505.00007FF7F56F6000.00000002.00000001.01000000.00000003.sdmp, SecuriteInfo.com.Trojan.Win64.Meterpreter.11595.2675.exe, 00000000.00000000.2108533057.00007FF7F56F6000.00000002.00000001.01000000.00000003.sdmp |
Source: | Binary string: C:\Users\user\AppData\Roaming\ExplorerPatcher\twinui.pcshell.pdb source: explorer.exe, 0000000B.00000003.2377129178.000000000AF04000.00000004.00000020.00020000.00000000.sdmp, explorer.exe, 0000000B.00000003.2383069605.0000000008B96000.00000004.00000020.00020000.00000000.sdmp |
Source: | Binary string: D:\a\ExplorerPatcher\ExplorerPatcher\build\Release\x64\ep_gui.pdb source: SecuriteInfo.com.Trojan.Win64.Meterpreter.11595.2675.exe, 00000000.00000003.2144271915.000001BF162C1000.00000004.00000020.00020000.00000000.sdmp, explorer.exe, 0000000A.00000002.2174585427.0000000002880000.00000002.00000001.00040000.00000009.sdmp |
Source: | Binary string: D:\a\ExplorerPatcher\ExplorerPatcher\build\Release\x64\ep_weather_host.pdb source: SecuriteInfo.com.Trojan.Win64.Meterpreter.11595.2675.exe, 00000000.00000003.2144774735.000001BF162C1000.00000004.00000020.00020000.00000000.sdmp, SecuriteInfo.com.Trojan.Win64.Meterpreter.11595.2675.exe, 00000000.00000003.2144908523.000001BF13B8D000.00000004.00000020.00020000.00000000.sdmp |
Source: | Binary string: http://msdl.microsoft.com/download/symbols/twinui.pcshell.pdb/56A53B20B8D4F79E69038072C21547311/twinui.pcshell.pdbO source: explorer.exe, 0000000B.00000003.2235994933.0000000002F37000.00000004.00000020.00020000.00000000.sdmp, explorer.exe, 0000000B.00000003.2246571830.0000000002F1D000.00000004.00000020.00020000.00000000.sdmp, explorer.exe, 0000000B.00000003.2288267379.0000000002F1D000.00000004.00000020.00020000.00000000.sdmp, explorer.exe, 0000000B.00000003.2252874097.0000000002F1D000.00000004.00000020.00020000.00000000.sdmp, explorer.exe, 0000000B.00000003.2204325725.0000000002F33000.00000004.00000020.00020000.00000000.sdmp, explorer.exe, 0000000B.00000003.2320144168.0000000002F1D000.00000004.00000020.00020000.00000000.sdmp, explorer.exe, 0000000B.00000003.2381212820.0000000002F1D000.00000004.00000020.00020000.00000000.sdmp, explorer.exe, 0000000B.00000003.2234944578.0000000002F37000.00000004.00000020.00020000.00000000.sdmp |
Source: | Binary string: StartUI.pdbH source: explorer.exe, 0000000A.00000003.2166635686.00000000027EA000.00000004.00000020.00020000.00000000.sdmp, explorer.exe, 0000000B.00000003.2175731585.00000000023D3000.00000004.00000020.00020000.00000000.sdmp |
Source: | Binary string: twinui.pcshell.pdbUGP source: explorer.exe, 0000000A.00000003.2167375925.00000000027E3000.00000004.00000020.00020000.00000000.sdmp, explorer.exe, 0000000B.00000003.2174577379.00000000023D5000.00000004.00000020.00020000.00000000.sdmp, explorer.exe, 0000000B.00000003.2178744483.0000000002D5E000.00000004.00000020.00020000.00000000.sdmp, explorer.exe, 0000000B.00000003.2176793588.00000000023D4000.00000004.00000020.00020000.00000000.sdmp |
Source: explorer.exe, 0000000B.00000003.2235545227.00000000089C9000.00000004.00000020.00020000.00000000.sdmp, explorer.exe, 0000000B.00000003.2259820542.00000000089CA000.00000004.00000020.00020000.00000000.sdmp, explorer.exe, 0000000B.00000003.2221558741.00000000089AE000.00000004.00000020.00020000.00000000.sdmp | String found in binary or memory: http://cacerts.digicert.com/DigiCertGlobalRootG2.crt0 |
Source: explorer.exe, 0000000B.00000003.2235545227.00000000089C9000.00000004.00000020.00020000.00000000.sdmp, explorer.exe, 0000000B.00000003.2259820542.00000000089CA000.00000004.00000020.00020000.00000000.sdmp, explorer.exe, 0000000B.00000003.2221558741.00000000089AE000.00000004.00000020.00020000.00000000.sdmp | String found in binary or memory: http://crl3.digicert.com/DigiCertGlobalRootG2.crl07 |
Source: explorer.exe, 0000000B.00000003.2235545227.00000000089C9000.00000004.00000020.00020000.00000000.sdmp, explorer.exe, 0000000B.00000003.2259820542.00000000089CA000.00000004.00000020.00020000.00000000.sdmp, explorer.exe, 0000000B.00000003.2221558741.00000000089AE000.00000004.00000020.00020000.00000000.sdmp | String found in binary or memory: http://crl4.digicert.com/DigiCertGlobalRootG2.crl0 |
Source: explorer.exe, 0000000B.00000003.2235545227.00000000089C9000.00000004.00000020.00020000.00000000.sdmp, explorer.exe, 0000000B.00000003.2259820542.00000000089CA000.00000004.00000020.00020000.00000000.sdmp, explorer.exe, 0000000B.00000003.2221558741.00000000089AE000.00000004.00000020.00020000.00000000.sdmp | String found in binary or memory: http://ocsp.digicert.com0 |
Source: explorer.exe, 0000000B.00000003.2381500814.000000000AE96000.00000004.00000020.00020000.00000000.sdmp, explorer.exe, 0000000B.00000003.2319396261.000000000AE96000.00000004.00000020.00020000.00000000.sdmp, explorer.exe, 0000000B.00000003.2311117328.000000000AE96000.00000004.00000020.00020000.00000000.sdmp, explorer.exe, 0000000B.00000003.2377129178.000000000AE96000.00000004.00000020.00020000.00000000.sdmp, explorer.exe, 0000000B.00000003.2317412632.000000000AE96000.00000004.00000020.00020000.00000000.sdmp, explorer.exe, 0000000B.00000003.2378964916.000000000AE96000.00000004.00000020.00020000.00000000.sdmp, explorer.exe, 0000000B.00000003.2388978276.000000000AE96000.00000004.00000020.00020000.00000000.sdmp | String found in binary or memory: http://schemas.micr |
Source: explorer.exe, 0000000B.00000003.2381500814.000000000AE96000.00000004.00000020.00020000.00000000.sdmp, explorer.exe, 0000000B.00000003.2319396261.000000000AE96000.00000004.00000020.00020000.00000000.sdmp, explorer.exe, 0000000B.00000003.2311117328.000000000AE96000.00000004.00000020.00020000.00000000.sdmp, explorer.exe, 0000000B.00000003.2377129178.000000000AE96000.00000004.00000020.00020000.00000000.sdmp, explorer.exe, 0000000B.00000003.2317412632.000000000AE96000.00000004.00000020.00020000.00000000.sdmp, explorer.exe, 0000000B.00000003.2378964916.000000000AE96000.00000004.00000020.00020000.00000000.sdmp, explorer.exe, 0000000B.00000003.2388978276.000000000AE96000.00000004.00000020.00020000.00000000.sdmp | String found in binary or memory: http://schemas.microsoft.co |
Source: SecuriteInfo.com.Trojan.Win64.Meterpreter.11595.2675.exe, 00000000.00000000.2108533057.00007FF7F56F6000.00000002.00000001.01000000.00000003.sdmp | String found in binary or memory: http://www.winimage.com/zLibDll |
Source: SecuriteInfo.com.Trojan.Win64.Meterpreter.11595.2675.exe, 00000000.00000003.2146053134.000001BF162C1000.00000004.00000020.00020000.00000000.sdmp, explorer.exe, explorer.exe, 0000000A.00000002.2175083796.00007FF8BEE7D000.00000002.00000001.01000000.00000008.sdmp | String found in binary or memory: https://api.github.com/repos/valinet/ExplorerPatcher/releases?per_page=1 |
Source: explorer.exe, 0000000B.00000003.2246946920.0000000008B81000.00000004.00000020.00020000.00000000.sdmp, explorer.exe, 0000000B.00000003.2237543521.0000000008B85000.00000004.00000020.00020000.00000000.sdmp, explorer.exe, 0000000B.00000003.2294706642.0000000008B81000.00000004.00000020.00020000.00000000.sdmp, explorer.exe, 0000000B.00000003.2383069605.0000000008B96000.00000004.00000020.00020000.00000000.sdmp, explorer.exe, 0000000B.00000003.2235377127.0000000008B81000.00000004.00000020.00020000.00000000.sdmp | String found in binary or memory: https://api.msn.com/ |
Source: explorer.exe, 0000000A.00000003.2167375925.00000000027E3000.00000004.00000020.00020000.00000000.sdmp, explorer.exe, 0000000B.00000003.2174577379.00000000023D5000.00000004.00000020.00020000.00000000.sdmp, explorer.exe, 0000000B.00000003.2178744483.0000000002D5E000.00000004.00000020.00020000.00000000.sdmp, explorer.exe, 0000000B.00000003.2176793588.00000000023D4000.00000004.00000020.00020000.00000000.sdmp | String found in binary or memory: https://api.msn.com/v1/News/Feed/Windows?%08x%04x%04x%02x%02x%02x%02x%02x%02x%02x%02xFeedsCNhttps:// |
Source: explorer.exe, 0000000B.00000003.2221558741.00000000089AE000.00000004.00000020.00020000.00000000.sdmp | String found in binary or memory: https://api.msn.com/v1/News/Feed/Windows?apikey=qrUeHGGYvVowZJuHA3XaH0uUvg1ZJ0GUZnXk3mxxPF&ocid=wind |
Source: explorer.exe, 0000000B.00000003.2221710068.0000000008A2A000.00000004.00000020.00020000.00000000.sdmp, explorer.exe, 0000000B.00000003.2235545227.00000000089C9000.00000004.00000020.00020000.00000000.sdmp, explorer.exe, 0000000B.00000003.2259820542.00000000089CA000.00000004.00000020.00020000.00000000.sdmp, explorer.exe, 0000000B.00000003.2221558741.00000000089AE000.00000004.00000020.00020000.00000000.sdmp | String found in binary or memory: https://arc.msn.comO |
Source: explorer.exe, 0000000B.00000003.2235377127.0000000008BF9000.00000004.00000020.00020000.00000000.sdmp, explorer.exe, 0000000B.00000003.2235817392.0000000008BF9000.00000004.00000020.00020000.00000000.sdmp | String found in binary or memory: https://github.com/ |
Source: SecuriteInfo.com.Trojan.Win64.Meterpreter.11595.2675.exe, 00000000.00000003.2144271915.000001BF162C1000.00000004.00000020.00020000.00000000.sdmp, explorer.exe, 0000000A.00000002.2174585427.0000000002880000.00000002.00000001.00040000.00000009.sdmp | String found in binary or memory: https://github.com/valinet |
Source: SecuriteInfo.com.Trojan.Win64.Meterpreter.11595.2675.exe, 00000000.00000003.2144271915.000001BF162C1000.00000004.00000020.00020000.00000000.sdmp, explorer.exe, 0000000A.00000002.2174585427.0000000002880000.00000002.00000001.00040000.00000009.sdmp | String found in binary or memory: https://github.com/valinet) |
Source: SecuriteInfo.com.Trojan.Win64.Meterpreter.11595.2675.exe, 00000000.00000003.2144271915.000001BF162C1000.00000004.00000020.00020000.00000000.sdmp, explorer.exe, 0000000A.00000002.2174585427.0000000002880000.00000002.00000001.00040000.00000009.sdmp | String found in binary or memory: https://github.com/valinet/ExplorerPatcher#donate |
Source: SecuriteInfo.com.Trojan.Win64.Meterpreter.11595.2675.exe, 00000000.00000003.2144271915.000001BF162C1000.00000004.00000020.00020000.00000000.sdmp, explorer.exe, 0000000A.00000002.2174585427.0000000002880000.00000002.00000001.00040000.00000009.sdmp | String found in binary or memory: https://github.com/valinet/ExplorerPatcher/blob/master/CHANGELOG.md |
Source: explorer.exe | String found in binary or memory: https://github.com/valinet/ExplorerPatcher/discussions |
Source: explorer.exe | String found in binary or memory: https://github.com/valinet/ExplorerPatcher/discussions/1102 |
Source: SecuriteInfo.com.Trojan.Win64.Meterpreter.11595.2675.exe, 00000000.00000003.2144271915.000001BF162C1000.00000004.00000020.00020000.00000000.sdmp, explorer.exe, 0000000A.00000002.2174585427.0000000002880000.00000002.00000001.00040000.00000009.sdmp | String found in binary or memory: https://github.com/valinet/ExplorerPatcher/discussions/1679 |
Source: explorer.exe | String found in binary or memory: https://github.com/valinet/ExplorerPatcher/issues |
Source: SecuriteInfo.com.Trojan.Win64.Meterpreter.11595.2675.exe, 00000000.00000003.2146053134.000001BF162C1000.00000004.00000020.00020000.00000000.sdmp, explorer.exe, 0000000A.00000002.2175083796.00007FF8BEE7D000.00000002.00000001.01000000.00000008.sdmp | String found in binary or memory: https://github.com/valinet/ExplorerPatcher/issueshttps://github.com/valinet/ExplorerPatcher/discussi |
Source: explorer.exe | String found in binary or memory: https://github.com/valinet/ExplorerPatcher/releases |
Source: explorer.exe, 0000000B.00000003.2246884263.0000000008C45000.00000004.00000020.00020000.00000000.sdmp | String found in binary or memory: https://github.com/valinet/ExplorerPatcher/releases/download/22621.3880.66.5_5094108/ep_setup.exe |
Source: explorer.exe, 0000000B.00000003.2259820542.00000000089CA000.00000004.00000020.00020000.00000000.sdmp | String found in binary or memory: https://github.com/valinet/ExplorerPatcher/releases/download/22621.3880.66.5_5094108/ep_setup.exen |
Source: SecuriteInfo.com.Trojan.Win64.Meterpreter.11595.2675.exe, 00000000.00000003.2146053134.000001BF162C1000.00000004.00000020.00020000.00000000.sdmp, explorer.exe, explorer.exe, 0000000A.00000002.2175083796.00007FF8BEE7D000.00000002.00000001.01000000.00000008.sdmp | String found in binary or memory: https://github.com/valinet/ExplorerPatcher/releases/latest |
Source: explorer.exe, 0000000B.00000003.2235377127.0000000008BF9000.00000004.00000020.00020000.00000000.sdmp, explorer.exe, 0000000B.00000003.2259790641.0000000008C40000.00000004.00000020.00020000.00000000.sdmp, explorer.exe, 0000000B.00000003.2247710864.0000000008BB8000.00000004.00000020.00020000.00000000.sdmp, explorer.exe, 0000000B.00000003.2235968422.0000000008C52000.00000004.00000020.00020000.00000000.sdmp, explorer.exe, 0000000B.00000003.2235545227.00000000089C9000.00000004.00000020.00020000.00000000.sdmp, explorer.exe, 0000000B.00000003.2235377127.0000000008BB8000.00000004.00000020.00020000.00000000.sdmp, explorer.exe, 0000000B.00000003.2235817392.0000000008BF9000.00000004.00000020.00020000.00000000.sdmp, explorer.exe, 0000000B.00000003.2247687864.0000000008C40000.00000004.00000020.00020000.00000000.sdmp, explorer.exe, 0000000B.00000003.2247710864.0000000008BF9000.00000004.00000020.00020000.00000000.sdmp, explorer.exe, 0000000B.00000003.2383069605.0000000008BF9000.00000004.00000020.00020000.00000000.sdmp, explorer.exe, 0000000B.00000003.2294706642.0000000008B81000.00000004.00000020.00020000.00000000.sdmp, explorer.exe, 0000000B.00000003.2259820542.00000000089CA000.00000004.00000020.00020000.00000000.sdmp, explorer.exe, 0000000B.00000003.2383069605.0000000008B96000.00000004.00000020.00020000.00000000.sdmp, explorer.exe, 0000000B.00000003.2235817392.0000000008BB8000.00000004.00000020.00020000.00000000.sdmp, explorer.exe, 0000000B.00000003.2237636676.0000000008C3D000.00000004.00000020.00020000.00000000.sdmp, explorer.exe, 0000000B.00000003.2235771046.0000000008C3D000.00000004.00000020.00020000.00000000.sdmp, explorer.exe, 0000000B.00000003.2294706642.0000000008BF9000.00000004.00000020.00020000.00000000.sdmp, explorer.exe, 0000000B.00000003.2235276763.0000000008C52000.00000004.00000020.00020000.00000000.sdmp | String found in binary or memory: https://github.com/valinet/ExplorerPatcher/releases/latest/download/ep_setup.exe |
Source: explorer.exe, 0000000B.00000003.2247710864.0000000008BB8000.00000004.00000020.00020000.00000000.sdmp, explorer.exe, 0000000B.00000003.2235377127.0000000008BB8000.00000004.00000020.00020000.00000000.sdmp, explorer.exe, 0000000B.00000003.2294706642.0000000008B81000.00000004.00000020.00020000.00000000.sdmp, explorer.exe, 0000000B.00000003.2383069605.0000000008B96000.00000004.00000020.00020000.00000000.sdmp, explorer.exe, 0000000B.00000003.2235817392.0000000008BB8000.00000004.00000020.00020000.00000000.sdmp | String found in binary or memory: https://github.com/valinet/ExplorerPatcher/releases/latest/download/ep_setup.exe04w |
Source: explorer.exe, 0000000B.00000003.2235377127.0000000008BF9000.00000004.00000020.00020000.00000000.sdmp, explorer.exe, 0000000B.00000003.2237636676.0000000008C3D000.00000004.00000020.00020000.00000000.sdmp, explorer.exe, 0000000B.00000003.2235771046.0000000008C3D000.00000004.00000020.00020000.00000000.sdmp | String found in binary or memory: https://github.com/valinet/ExplorerPatcher/releases/latest/download/ep_setup.exeQ |
Source: explorer.exe, 0000000B.00000003.2235377127.0000000008BF9000.00000004.00000020.00020000.00000000.sdmp, explorer.exe, 0000000B.00000003.2235817392.0000000008BF9000.00000004.00000020.00020000.00000000.sdmp, explorer.exe, 0000000B.00000003.2247710864.0000000008BF9000.00000004.00000020.00020000.00000000.sdmp, explorer.exe, 0000000B.00000003.2383069605.0000000008BF9000.00000004.00000020.00020000.00000000.sdmp, explorer.exe, 0000000B.00000003.2294706642.0000000008BF9000.00000004.00000020.00020000.00000000.sdmp | String found in binary or memory: https://github.com/valinet/ExplorerPatcher/releases/latest/download/ep_setup.exeut |
Source: SecuriteInfo.com.Trojan.Win64.Meterpreter.11595.2675.exe, 00000000.00000003.2144271915.000001BF162C1000.00000004.00000020.00020000.00000000.sdmp, explorer.exe, 0000000A.00000002.2174585427.0000000002880000.00000002.00000001.00040000.00000009.sdmp | String found in binary or memory: https://github.com/valinet/ExplorerPatcher/wiki/About-advanced-settings |
Source: SecuriteInfo.com.Trojan.Win64.Meterpreter.11595.2675.exe, 00000000.00000003.2144271915.000001BF162C1000.00000004.00000020.00020000.00000000.sdmp, explorer.exe, 0000000A.00000002.2174585427.0000000002880000.00000002.00000001.00040000.00000009.sdmp | String found in binary or memory: https://github.com/valinet/ExplorerPatcher/wiki/Configure-updates |
Source: SecuriteInfo.com.Trojan.Win64.Meterpreter.11595.2675.exe, 00000000.00000003.2144271915.000001BF162C1000.00000004.00000020.00020000.00000000.sdmp, explorer.exe, 0000000A.00000002.2174585427.0000000002880000.00000002.00000001.00040000.00000009.sdmp | String found in binary or memory: https://github.com/valinet/ExplorerPatcher/wiki/ExplorerPatcher |
Source: SecuriteInfo.com.Trojan.Win64.Meterpreter.11595.2675.exe, 00000000.00000003.2144271915.000001BF162C1000.00000004.00000020.00020000.00000000.sdmp, explorer.exe, 0000000A.00000002.2174585427.0000000002880000.00000002.00000001.00040000.00000009.sdmp | String found in binary or memory: https://github.com/valinet/ExplorerPatcher/wiki/Frequently-asked-questions |
Source: SecuriteInfo.com.Trojan.Win64.Meterpreter.11595.2675.exe, 00000000.00000003.2144271915.000001BF162C1000.00000004.00000020.00020000.00000000.sdmp, explorer.exe, 0000000A.00000002.2174585427.0000000002880000.00000002.00000001.00040000.00000009.sdmp | String found in binary or memory: https://github.com/valinet/ExplorerPatcher/wiki/Settings-management |
Source: SecuriteInfo.com.Trojan.Win64.Meterpreter.11595.2675.exe, 00000000.00000003.2144271915.000001BF162C1000.00000004.00000020.00020000.00000000.sdmp, explorer.exe, 0000000A.00000002.2174585427.0000000002880000.00000002.00000001.00040000.00000009.sdmp | String found in binary or memory: https://github.com/valinet/ExplorerPatcher/wiki/Simple-Window-Switcher |
Source: explorer.exe, explorer.exe, 0000000A.00000002.2175083796.00007FF8BEE7D000.00000002.00000001.01000000.00000008.sdmp, explorer.exe, 0000000A.00000002.2174380843.0000000000B9B000.00000004.00000010.00020000.00000000.sdmp, explorer.exe, 0000000A.00000002.2174887643.0000000002D7E000.00000004.00000020.00020000.00000000.sdmp, explorer.exe, 0000000A.00000002.2174887643.0000000002D70000.00000004.00000020.00020000.00000000.sdmp, explorer.exe, 0000000B.00000003.2188541557.000000000273D000.00000004.00000020.00020000.00000000.sdmp | String found in binary or memory: https://github.com/valinet/ExplorerPatcher/wiki/Symbols |
Source: explorer.exe, 0000000B.00000003.2188541557.0000000002740000.00000004.00000020.00020000.00000000.sdmp | String found in binary or memory: https://github.com/valinet/ExplorerPatcher/wiki/Symbols= |
Source: SecuriteInfo.com.Trojan.Win64.Meterpreter.11595.2675.exe, 00000000.00000003.2146053134.000001BF162C1000.00000004.00000020.00020000.00000000.sdmp, explorer.exe, 0000000A.00000002.2175083796.00007FF8BEE7D000.00000002.00000001.01000000.00000008.sdmp | String found in binary or memory: https://github.com/valinet/ExplorerPatcher/wiki/SymbolsMicrosoft.Windows.Explorer |
Source: explorer.exe, 0000000A.00000002.2174887643.0000000002D7E000.00000004.00000020.00020000.00000000.sdmp | String found in binary or memory: https://github.com/valinet/ExplorerPatcher/wiki/Symbolss |
Source: SecuriteInfo.com.Trojan.Win64.Meterpreter.11595.2675.exe, 00000000.00000003.2144271915.000001BF162C1000.00000004.00000020.00020000.00000000.sdmp, explorer.exe, 0000000A.00000002.2174585427.0000000002880000.00000002.00000001.00040000.00000009.sdmp | String found in binary or memory: https://github.com/valinet/ExplorerPatcher/wiki/Using-ExplorerPatcher-as-shell-extension |
Source: SecuriteInfo.com.Trojan.Win64.Meterpreter.11595.2675.exe, 00000000.00000003.2144271915.000001BF162C1000.00000004.00000020.00020000.00000000.sdmp, explorer.exe, 0000000A.00000002.2174585427.0000000002880000.00000002.00000001.00040000.00000009.sdmp | String found in binary or memory: https://github.com/valinet/ExplorerPatcher/wiki/Weather |
Source: explorer.exe, 0000000A.00000003.2166635686.00000000027EA000.00000004.00000020.00020000.00000000.sdmp, explorer.exe, 0000000B.00000003.2175731585.00000000023D3000.00000004.00000020.00020000.00000000.sdmp | String found in binary or memory: https://msn.comError |
Source: explorer.exe, 0000000B.00000003.2383069605.0000000008BF9000.00000004.00000020.00020000.00000000.sdmp, explorer.exe, 0000000B.00000003.2294706642.0000000008BF9000.00000004.00000020.00020000.00000000.sdmp | String found in binary or memory: https://objects.githubusercontent.com/ |
Source: explorer.exe, 0000000B.00000003.2259820542.00000000089CA000.00000004.00000020.00020000.00000000.sdmp, explorer.exe, 0000000B.00000003.2259633111.000000000ADA7000.00000004.00000020.00020000.00000000.sdmp | String found in binary or memory: https://objects.githubusercontent.com/github-production-release-asset-2e65be/394318710/d0ea7754-53d3 |
Source: explorer.exe, 0000000B.00000003.2247710864.0000000008BB8000.00000004.00000020.00020000.00000000.sdmp, explorer.exe, 0000000B.00000003.2235377127.0000000008BB8000.00000004.00000020.00020000.00000000.sdmp, explorer.exe, 0000000B.00000003.2221330728.0000000008BBA000.00000004.00000020.00020000.00000000.sdmp, explorer.exe, 0000000B.00000003.2235817392.0000000008BB8000.00000004.00000020.00020000.00000000.sdmp | String found in binary or memory: https://outlook.com |
Source: explorer.exe, 0000000B.00000003.2234944578.0000000002E18000.00000004.00000020.00020000.00000000.sdmp, explorer.exe, 0000000B.00000003.2246571830.0000000002E18000.00000004.00000020.00020000.00000000.sdmp, explorer.exe, 0000000B.00000003.2237333080.0000000002E18000.00000004.00000020.00020000.00000000.sdmp | String found in binary or memory: https://powerpoint.office.com |
Source: SecuriteInfo.com.Trojan.Win64.Meterpreter.11595.2675.exe, 00000000.00000003.2146053134.000001BF162C1000.00000004.00000020.00020000.00000000.sdmp, explorer.exe, explorer.exe, 0000000A.00000002.2175083796.00007FF8BEE7D000.00000002.00000001.01000000.00000008.sdmp | String found in binary or memory: https://raw.githubusercontent.com/valinet/ep_make/master/ep_make_safe.ps1 |
Source: SecuriteInfo.com.Trojan.Win64.Meterpreter.11595.2675.exe, 00000000.00000003.2144774735.000001BF162C1000.00000004.00000020.00020000.00000000.sdmp | String found in binary or memory: https://user-images.githubusercontent.com/6503598/156949438-4e0c0e0d-67bc-4c76-b75e-e0ffcead3f48.png |
Source: SecuriteInfo.com.Trojan.Win64.Meterpreter.11595.2675.exe, 00000000.00000003.2144774735.000001BF162C1000.00000004.00000020.00020000.00000000.sdmp | String found in binary or memory: https://user-images.githubusercontent.com/6503598/156949442-63f14d44-ec0e-40b2-aa1b-8e4a27ec10f5.png |
Source: SecuriteInfo.com.Trojan.Win64.Meterpreter.11595.2675.exe, 00000000.00000003.2144774735.000001BF162C1000.00000004.00000020.00020000.00000000.sdmp | String found in binary or memory: https://user-images.githubusercontent.com/6503598/156949443-062a0fa9-88c1-4e07-b6b1-8e52ff64f4f3.png |
Source: SecuriteInfo.com.Trojan.Win64.Meterpreter.11595.2675.exe, 00000000.00000003.2144774735.000001BF162C1000.00000004.00000020.00020000.00000000.sdmp | String found in binary or memory: https://user-images.githubusercontent.com/6503598/156949444-d3aea936-4c22-4f17-a201-02155396684d.png |
Source: SecuriteInfo.com.Trojan.Win64.Meterpreter.11595.2675.exe, 00000000.00000003.2144774735.000001BF162C1000.00000004.00000020.00020000.00000000.sdmp | String found in binary or memory: https://user-images.githubusercontent.com/6503598/156949445-60d12efa-a21d-40e0-b9a8-1b7a84e58944.png |
Source: SecuriteInfo.com.Trojan.Win64.Meterpreter.11595.2675.exe, 00000000.00000003.2144774735.000001BF162C1000.00000004.00000020.00020000.00000000.sdmp | String found in binary or memory: https://user-images.githubusercontent.com/6503598/156949447-a6658710-567e-4977-9316-a80007df3076.png |
Source: SecuriteInfo.com.Trojan.Win64.Meterpreter.11595.2675.exe, 00000000.00000003.2144774735.000001BF162C1000.00000004.00000020.00020000.00000000.sdmp | String found in binary or memory: https://user-images.githubusercontent.com/6503598/156949448-cd1b69af-4028-4153-8e40-288526577b58.png |
Source: SecuriteInfo.com.Trojan.Win64.Meterpreter.11595.2675.exe, 00000000.00000003.2144774735.000001BF162C1000.00000004.00000020.00020000.00000000.sdmp | String found in binary or memory: https://user-images.githubusercontent.com/6503598/156949449-9320c6f5-15ef-4c17-9e72-740708f4828c.png |
Source: SecuriteInfo.com.Trojan.Win64.Meterpreter.11595.2675.exe, 00000000.00000003.2144774735.000001BF162C1000.00000004.00000020.00020000.00000000.sdmp | String found in binary or memory: https://user-images.githubusercontent.com/6503598/156949450-7e03a3f5-580e-4414-aaeb-3a0898afd1da.png |
Source: SecuriteInfo.com.Trojan.Win64.Meterpreter.11595.2675.exe, 00000000.00000003.2144774735.000001BF162C1000.00000004.00000020.00020000.00000000.sdmp | String found in binary or memory: https://user-images.githubusercontent.com/6503598/156949451-269d02a3-08cb-4237-9789-f1e60fdc723d.png |
Source: SecuriteInfo.com.Trojan.Win64.Meterpreter.11595.2675.exe, 00000000.00000003.2144774735.000001BF162C1000.00000004.00000020.00020000.00000000.sdmp | String found in binary or memory: https://user-images.githubusercontent.com/6503598/156949452-f347fe27-5005-48f2-9c9a-899bb7b8825e.png |
Source: SecuriteInfo.com.Trojan.Win64.Meterpreter.11595.2675.exe, 00000000.00000003.2144774735.000001BF162C1000.00000004.00000020.00020000.00000000.sdmp | String found in binary or memory: https://user-images.githubusercontent.com/6503598/156949454-81d5d47d-1f33-4859-a112-5a64ceb549a1.png |
Source: SecuriteInfo.com.Trojan.Win64.Meterpreter.11595.2675.exe, 00000000.00000003.2144774735.000001BF162C1000.00000004.00000020.00020000.00000000.sdmp | String found in binary or memory: https://user-images.githubusercontent.com/6503598/156949456-04a4bdbd-ff3b-4484-bb30-8909baff8aa8.png |
Source: SecuriteInfo.com.Trojan.Win64.Meterpreter.11595.2675.exe, 00000000.00000003.2144774735.000001BF162C1000.00000004.00000020.00020000.00000000.sdmp | String found in binary or memory: https://user-images.githubusercontent.com/6503598/156949458-dc66775d-8bb9-4d04-838e-7f550d305c26.png |
Source: SecuriteInfo.com.Trojan.Win64.Meterpreter.11595.2675.exe, 00000000.00000003.2144774735.000001BF162C1000.00000004.00000020.00020000.00000000.sdmp | String found in binary or memory: https://user-images.githubusercontent.com/6503598/156949459-dfe70eba-6c2c-4b1c-b51b-27c13ce7c08c.png |
Source: SecuriteInfo.com.Trojan.Win64.Meterpreter.11595.2675.exe, 00000000.00000003.2144774735.000001BF162C1000.00000004.00000020.00020000.00000000.sdmp | String found in binary or memory: https://user-images.githubusercontent.com/6503598/156949460-7c132d89-efb7-457f-8810-9bf235f5737f.png |
Source: SecuriteInfo.com.Trojan.Win64.Meterpreter.11595.2675.exe, 00000000.00000003.2144774735.000001BF162C1000.00000004.00000020.00020000.00000000.sdmp | String found in binary or memory: https://user-images.githubusercontent.com/6503598/156949461-1f058cf3-6fdd-4aeb-80b7-68fa27b02845.png |
Source: SecuriteInfo.com.Trojan.Win64.Meterpreter.11595.2675.exe, 00000000.00000003.2144774735.000001BF162C1000.00000004.00000020.00020000.00000000.sdmp | String found in binary or memory: https://user-images.githubusercontent.com/6503598/156949462-f50c21dd-85dd-4d9c-a4eb-516e6cddfb1f.png |
Source: SecuriteInfo.com.Trojan.Win64.Meterpreter.11595.2675.exe, 00000000.00000003.2144774735.000001BF162C1000.00000004.00000020.00020000.00000000.sdmp | String found in binary or memory: https://user-images.githubusercontent.com/6503598/156949463-a427edfb-3d7f-4167-bd6f-f5019c482ea1.png |
Source: SecuriteInfo.com.Trojan.Win64.Meterpreter.11595.2675.exe, 00000000.00000003.2144774735.000001BF162C1000.00000004.00000020.00020000.00000000.sdmp | String found in binary or memory: https://user-images.githubusercontent.com/6503598/156949465-54dd31c6-7e3a-464a-8e64-8b54b6fb7a65.png |
Source: SecuriteInfo.com.Trojan.Win64.Meterpreter.11595.2675.exe, 00000000.00000003.2144774735.000001BF162C1000.00000004.00000020.00020000.00000000.sdmp | String found in binary or memory: https://user-images.githubusercontent.com/6503598/156950233-ccaadb4a-2e9a-4934-b41c-acd36a7f0d9c.png |
Source: explorer.exe, 0000000B.00000003.2221558741.00000000089AE000.00000004.00000020.00020000.00000000.sdmp | String found in binary or memory: https://vsblobprodscussu5shard39.blob.core.windows.net/)a |
Source: explorer.exe, 0000000B.00000003.2221558741.00000000089AE000.00000004.00000020.00020000.00000000.sdmp | String found in binary or memory: https://vsblobprodscussu5shard39.blob.core.windows.net/1a |
Source: explorer.exe, 0000000B.00000003.2235994933.0000000002F00000.00000004.00000020.00020000.00000000.sdmp, explorer.exe, 0000000B.00000003.2234944578.0000000002E7D000.00000004.00000020.00020000.00000000.sdmp, explorer.exe, 0000000B.00000003.2320144168.0000000002F00000.00000004.00000020.00020000.00000000.sdmp, explorer.exe, 0000000B.00000003.2288267379.0000000002F00000.00000004.00000020.00020000.00000000.sdmp, explorer.exe, 0000000B.00000003.2304015552.0000000002F00000.00000004.00000020.00020000.00000000.sdmp, explorer.exe, 0000000B.00000003.2246571830.0000000002F00000.00000004.00000020.00020000.00000000.sdmp, explorer.exe, 0000000B.00000003.2332407476.0000000002E7D000.00000004.00000020.00020000.00000000.sdmp, explorer.exe, 0000000B.00000003.2252874097.0000000002F00000.00000004.00000020.00020000.00000000.sdmp | String found in binary or memory: https://vsblobprodscussu5shard39.blob.core.windows.net/b-4712e0edc5a240eabf23330d7df68e77/39B7A82995 |
Source: SecuriteInfo.com.Trojan.Win64.Meterpreter.11595.2675.exe, 00000000.00000003.2144774735.000001BF162C1000.00000004.00000020.00020000.00000000.sdmp, SecuriteInfo.com.Trojan.Win64.Meterpreter.11595.2675.exe, 00000000.00000003.2144908523.000001BF13B8D000.00000004.00000020.00020000.00000000.sdmp | String found in binary or memory: https://www.google.com/search?hl=%s&q=weather%s%s%s%s%s%s%s%spCoreWebView2ExecuteScriptCompletedHand |
Source: SecuriteInfo.com.Trojan.Win64.Meterpreter.11595.2675.exe, 00000000.00000003.2144271915.000001BF162C1000.00000004.00000020.00020000.00000000.sdmp, explorer.exe, 0000000A.00000002.2174585427.0000000002880000.00000002.00000001.00040000.00000009.sdmp | String found in binary or memory: https://www.valinet.ro |
Source: SecuriteInfo.com.Trojan.Win64.Meterpreter.11595.2675.exe, 00000000.00000003.2144271915.000001BF162C1000.00000004.00000020.00020000.00000000.sdmp, explorer.exe, 0000000A.00000002.2174585427.0000000002880000.00000002.00000001.00040000.00000009.sdmp | String found in binary or memory: https://www.valinet.ro) |
Source: C:\Windows\explorer.exe | Code function: 10_2_00007FF8BEE4FE80 | 10_2_00007FF8BEE4FE80 |
Source: C:\Windows\explorer.exe | Code function: 10_2_00007FF8BEE2DB90 | 10_2_00007FF8BEE2DB90 |
Source: C:\Windows\explorer.exe | Code function: 10_2_00007FF8BEE26B70 | 10_2_00007FF8BEE26B70 |
Source: C:\Windows\explorer.exe | Code function: 10_2_00007FF8BEE45CF0 | 10_2_00007FF8BEE45CF0 |
Source: C:\Windows\explorer.exe | Code function: 10_2_00007FF8BEE26900 | 10_2_00007FF8BEE26900 |
Source: C:\Windows\explorer.exe | Code function: 10_2_00007FF8BEE31870 | 10_2_00007FF8BEE31870 |
Source: C:\Windows\explorer.exe | Code function: 10_2_00007FF8BEE28800 | 10_2_00007FF8BEE28800 |
Source: C:\Windows\explorer.exe | Code function: 10_2_00007FF8BEE1E500 | 10_2_00007FF8BEE1E500 |
Source: C:\Windows\explorer.exe | Code function: 10_2_00007FF8BEE45620 | 10_2_00007FF8BEE45620 |
Source: C:\Windows\explorer.exe | Code function: 10_2_00007FF8BEE3A350 | 10_2_00007FF8BEE3A350 |
Source: C:\Windows\explorer.exe | Code function: 10_2_00007FF8BEE4F250 | 10_2_00007FF8BEE4F250 |
Source: C:\Windows\explorer.exe | Code function: 10_2_00007FF8BEE22FD0 | 10_2_00007FF8BEE22FD0 |
Source: C:\Windows\explorer.exe | Code function: 10_2_00007FF8BEE47FB0 | 10_2_00007FF8BEE47FB0 |
Source: C:\Windows\explorer.exe | Code function: 10_2_00007FF8BEE1BFA0 | 10_2_00007FF8BEE1BFA0 |
Source: C:\Windows\explorer.exe | Code function: 10_2_00007FF8BEE1EF90 | 10_2_00007FF8BEE1EF90 |
Source: C:\Windows\explorer.exe | Code function: 10_2_00007FF8BEE12F60 | 10_2_00007FF8BEE12F60 |
Source: C:\Windows\explorer.exe | Code function: 10_2_00007FF8BEE4DF40 | 10_2_00007FF8BEE4DF40 |
Source: C:\Windows\explorer.exe | Code function: 10_2_00007FF8BEE16F20 | 10_2_00007FF8BEE16F20 |
Source: C:\Windows\explorer.exe | Code function: 10_2_00007FF8BEE6EF24 | 10_2_00007FF8BEE6EF24 |
Source: C:\Windows\explorer.exe | Code function: 10_2_00007FF8BEE5EF08 | 10_2_00007FF8BEE5EF08 |
Source: C:\Windows\explorer.exe | Code function: 10_2_00007FF8BEE44F10 | 10_2_00007FF8BEE44F10 |
Source: C:\Windows\explorer.exe | Code function: 10_2_00007FF8BEE4BF10 | 10_2_00007FF8BEE4BF10 |
Source: C:\Windows\explorer.exe | Code function: 10_2_00007FF8BEE120D0 | 10_2_00007FF8BEE120D0 |
Source: C:\Windows\explorer.exe | Code function: 10_2_00007FF8BEE64094 | 10_2_00007FF8BEE64094 |
Source: C:\Windows\explorer.exe | Code function: 10_2_00007FF8BEE30070 | 10_2_00007FF8BEE30070 |
Source: C:\Windows\explorer.exe | Code function: 10_2_00007FF8BEE6105C | 10_2_00007FF8BEE6105C |
Source: C:\Windows\explorer.exe | Code function: 10_2_00007FF8BEE5F014 | 10_2_00007FF8BEE5F014 |
Source: C:\Windows\explorer.exe | Code function: 10_2_00007FF8BEE47010 | 10_2_00007FF8BEE47010 |
Source: C:\Windows\explorer.exe | Code function: 10_2_00007FF8BEE6CDBC | 10_2_00007FF8BEE6CDBC |
Source: C:\Windows\explorer.exe | Code function: 10_2_00007FF8BEE64D94 | 10_2_00007FF8BEE64D94 |
Source: C:\Windows\explorer.exe | Code function: 10_2_00007FF8BEE30D10 | 10_2_00007FF8BEE30D10 |
Source: C:\Windows\explorer.exe | Code function: 10_2_00007FF8BEE13EF0 | 10_2_00007FF8BEE13EF0 |
Source: C:\Windows\explorer.exe | Code function: 10_2_00007FF8BEE2CEC0 | 10_2_00007FF8BEE2CEC0 |
Source: C:\Windows\explorer.exe | Code function: 10_2_00007FF8BEE75E9C | 10_2_00007FF8BEE75E9C |
Source: C:\Windows\explorer.exe | Code function: 10_2_00007FF8BEE6AE7C | 10_2_00007FF8BEE6AE7C |
Source: C:\Windows\explorer.exe | Code function: 10_2_00007FF8BEE60E58 | 10_2_00007FF8BEE60E58 |
Source: C:\Windows\explorer.exe | Code function: 10_2_00007FF8BEE5EDFC | 10_2_00007FF8BEE5EDFC |
Source: C:\Windows\explorer.exe | Code function: 10_2_00007FF8BEE1FBE0 | 10_2_00007FF8BEE1FBE0 |
Source: C:\Windows\explorer.exe | Code function: 10_2_00007FF8BEE73B58 | 10_2_00007FF8BEE73B58 |
Source: C:\Windows\explorer.exe | Code function: 10_2_00007FF8BEE17B50 | 10_2_00007FF8BEE17B50 |
Source: C:\Windows\explorer.exe | Code function: 10_2_00007FF8BEE25B40 | 10_2_00007FF8BEE25B40 |
Source: C:\Windows\explorer.exe | Code function: 10_2_00007FF8BEE11B20 | 10_2_00007FF8BEE11B20 |
Source: C:\Windows\explorer.exe | Code function: 10_2_00007FF8BEE5ECF0 | 10_2_00007FF8BEE5ECF0 |
Source: C:\Windows\explorer.exe | Code function: 10_2_00007FF8BEE79CA8 | 10_2_00007FF8BEE79CA8 |
Source: C:\Windows\explorer.exe | Code function: 10_2_00007FF8BEE60C24 | 10_2_00007FF8BEE60C24 |
Source: C:\Windows\explorer.exe | Code function: 10_2_00007FF8BEE22C20 | 10_2_00007FF8BEE22C20 |
Source: C:\Windows\explorer.exe | Code function: 10_2_00007FF8BEE62908 | 10_2_00007FF8BEE62908 |
Source: C:\Windows\explorer.exe | Code function: 10_2_00007FF8BEE1CAC0 | 10_2_00007FF8BEE1CAC0 |
Source: C:\Windows\explorer.exe | Code function: 10_2_00007FF8BEE19AA0 | 10_2_00007FF8BEE19AA0 |
Source: C:\Windows\explorer.exe | Code function: 10_2_00007FF8BEE6EA90 | 10_2_00007FF8BEE6EA90 |
Source: C:\Windows\explorer.exe | Code function: 10_2_00007FF8BEE50A50 | 10_2_00007FF8BEE50A50 |
Source: C:\Windows\explorer.exe | Code function: 10_2_00007FF8BEE48A50 | 10_2_00007FF8BEE48A50 |
Source: C:\Windows\explorer.exe | Code function: 10_2_00007FF8BEE60A18 | 10_2_00007FF8BEE60A18 |
Source: C:\Windows\explorer.exe | Code function: 10_2_00007FF8BEE44A00 | 10_2_00007FF8BEE44A00 |
Source: C:\Windows\explorer.exe | Code function: 10_2_00007FF8BEE75A00 | 10_2_00007FF8BEE75A00 |
Source: C:\Windows\explorer.exe | Code function: 10_2_00007FF8BEE2C7A0 | 10_2_00007FF8BEE2C7A0 |
Source: C:\Windows\explorer.exe | Code function: 10_2_00007FF8BEE50750 | 10_2_00007FF8BEE50750 |
Source: C:\Windows\explorer.exe | Code function: 10_2_00007FF8BEE56740 | 10_2_00007FF8BEE56740 |
Source: C:\Windows\explorer.exe | Code function: 10_2_00007FF8BEE648D0 | 10_2_00007FF8BEE648D0 |
Source: C:\Windows\explorer.exe | Code function: 10_2_00007FF8BEE23880 | 10_2_00007FF8BEE23880 |
Source: C:\Windows\explorer.exe | Code function: 10_2_00007FF8BEE4E830 | 10_2_00007FF8BEE4E830 |
Source: C:\Windows\explorer.exe | Code function: 10_2_00007FF8BEE60814 | 10_2_00007FF8BEE60814 |
Source: C:\Windows\explorer.exe | Code function: 10_2_00007FF8BEE2F810 | 10_2_00007FF8BEE2F810 |
Source: C:\Windows\explorer.exe | Code function: 10_2_00007FF8BEE605E0 | 10_2_00007FF8BEE605E0 |
Source: C:\Windows\explorer.exe | Code function: 10_2_00007FF8BEE6F5A4 | 10_2_00007FF8BEE6F5A4 |
Source: C:\Windows\explorer.exe | Code function: 10_2_00007FF8BEE305A0 | 10_2_00007FF8BEE305A0 |
Source: C:\Windows\explorer.exe | Code function: 10_2_00007FF8BEE62584 | 10_2_00007FF8BEE62584 |
Source: C:\Windows\explorer.exe | Code function: 10_2_00007FF8BEE5F54C | 10_2_00007FF8BEE5F54C |
Source: C:\Windows\explorer.exe | Code function: 10_2_00007FF8BEE6B518 | 10_2_00007FF8BEE6B518 |
Source: C:\Windows\explorer.exe | Code function: 10_2_00007FF8BEE4E520 | 10_2_00007FF8BEE4E520 |
Source: C:\Windows\explorer.exe | Code function: 10_2_00007FF8BEE5F658 | 10_2_00007FF8BEE5F658 |
Source: C:\Windows\explorer.exe | Code function: 10_2_00007FF8BEE44650 | 10_2_00007FF8BEE44650 |
Source: C:\Windows\explorer.exe | Code function: 10_2_00007FF8BEE353F0 | 10_2_00007FF8BEE353F0 |
Source: C:\Windows\explorer.exe | Code function: 10_2_00007FF8BEE603D4 | 10_2_00007FF8BEE603D4 |
Source: C:\Windows\explorer.exe | Code function: 10_2_00007FF8BEE483C0 | 10_2_00007FF8BEE483C0 |
Source: C:\Windows\explorer.exe | Code function: 10_2_00007FF8BEE15380 | 10_2_00007FF8BEE15380 |
Source: C:\Windows\explorer.exe | Code function: 10_2_00007FF8BEE26350 | 10_2_00007FF8BEE26350 |
Source: C:\Windows\explorer.exe | Code function: 10_2_00007FF8BEE23350 | 10_2_00007FF8BEE23350 |
Source: C:\Windows\explorer.exe | Code function: 10_2_00007FF8BEE5F334 | 10_2_00007FF8BEE5F334 |
Source: C:\Windows\explorer.exe | Code function: 10_2_00007FF8BEE1A4E0 | 10_2_00007FF8BEE1A4E0 |
Source: C:\Windows\explorer.exe | Code function: 10_2_00007FF8BEE644CC | 10_2_00007FF8BEE644CC |
Source: C:\Windows\explorer.exe | Code function: 10_2_00007FF8BEE5F440 | 10_2_00007FF8BEE5F440 |
Source: C:\Windows\explorer.exe | Code function: 10_2_00007FF8BEE621EC | 10_2_00007FF8BEE621EC |
Source: C:\Windows\explorer.exe | Code function: 10_2_00007FF8BEE601D0 | 10_2_00007FF8BEE601D0 |
Source: C:\Windows\explorer.exe | Code function: 10_2_00007FF8BEE201B0 | 10_2_00007FF8BEE201B0 |
Source: C:\Windows\explorer.exe | Code function: 10_2_00007FF8BEE2D190 | 10_2_00007FF8BEE2D190 |
Source: C:\Windows\explorer.exe | Code function: 10_2_00007FF8BEE1B150 | 10_2_00007FF8BEE1B150 |
Source: C:\Windows\explorer.exe | Code function: 10_2_00007FF8BEE5F120 | 10_2_00007FF8BEE5F120 |
Source: C:\Windows\explorer.exe | Code function: 10_2_00007FF8BEE1E100 | 10_2_00007FF8BEE1E100 |
Source: C:\Windows\explorer.exe | Code function: 10_2_00007FF8BEE122F0 | 10_2_00007FF8BEE122F0 |
Source: C:\Windows\explorer.exe | Code function: 10_2_00007FF8BEE452A0 | 10_2_00007FF8BEE452A0 |
Source: C:\Windows\explorer.exe | Code function: 10_2_00007FF8BEE4E280 | 10_2_00007FF8BEE4E280 |
Source: C:\Windows\explorer.exe | Code function: 10_2_00007FF8BEE61268 | 10_2_00007FF8BEE61268 |
Source: C:\Windows\explorer.exe | Code function: 10_2_00007FF8BEE24270 | 10_2_00007FF8BEE24270 |
Source: C:\Windows\explorer.exe | Code function: 10_2_00007FF8BEE5F22C | 10_2_00007FF8BEE5F22C |
Source: C:\Windows\explorer.exe | Code function: 10_2_00007FF8BEE1E230 | 10_2_00007FF8BEE1E230 |
Source: C:\Windows\explorer.exe | Code function: 10_2_00007FF8BEE651F8 | 10_2_00007FF8BEE651F8 |
Source: C:\Windows\explorer.exe | Code function: 10_2_00007FF8BEE1C200 | 10_2_00007FF8BEE1C200 |
Source: C:\Users\user\Desktop\SecuriteInfo.com.Trojan.Win64.Meterpreter.11595.2675.exe | Section loaded: apphelp.dll | Jump to behavior |
Source: C:\Users\user\Desktop\SecuriteInfo.com.Trojan.Win64.Meterpreter.11595.2675.exe | Section loaded: rstrtmgr.dll | Jump to behavior |
Source: C:\Users\user\Desktop\SecuriteInfo.com.Trojan.Win64.Meterpreter.11595.2675.exe | Section loaded: version.dll | Jump to behavior |
Source: C:\Users\user\Desktop\SecuriteInfo.com.Trojan.Win64.Meterpreter.11595.2675.exe | Section loaded: ncrypt.dll | Jump to behavior |
Source: C:\Users\user\Desktop\SecuriteInfo.com.Trojan.Win64.Meterpreter.11595.2675.exe | Section loaded: ntasn1.dll | Jump to behavior |
Source: C:\Users\user\Desktop\SecuriteInfo.com.Trojan.Win64.Meterpreter.11595.2675.exe | Section loaded: windows.storage.dll | Jump to behavior |
Source: C:\Users\user\Desktop\SecuriteInfo.com.Trojan.Win64.Meterpreter.11595.2675.exe | Section loaded: wldp.dll | Jump to behavior |
Source: C:\Users\user\Desktop\SecuriteInfo.com.Trojan.Win64.Meterpreter.11595.2675.exe | Section loaded: kernel.appcore.dll | Jump to behavior |
Source: C:\Users\user\Desktop\SecuriteInfo.com.Trojan.Win64.Meterpreter.11595.2675.exe | Section loaded: uxtheme.dll | Jump to behavior |
Source: C:\Users\user\Desktop\SecuriteInfo.com.Trojan.Win64.Meterpreter.11595.2675.exe | Section loaded: propsys.dll | Jump to behavior |
Source: C:\Users\user\Desktop\SecuriteInfo.com.Trojan.Win64.Meterpreter.11595.2675.exe | Section loaded: profapi.dll | Jump to behavior |
Source: C:\Users\user\Desktop\SecuriteInfo.com.Trojan.Win64.Meterpreter.11595.2675.exe | Section loaded: edputil.dll | Jump to behavior |
Source: C:\Users\user\Desktop\SecuriteInfo.com.Trojan.Win64.Meterpreter.11595.2675.exe | Section loaded: urlmon.dll | Jump to behavior |
Source: C:\Users\user\Desktop\SecuriteInfo.com.Trojan.Win64.Meterpreter.11595.2675.exe | Section loaded: iertutil.dll | Jump to behavior |
Source: C:\Users\user\Desktop\SecuriteInfo.com.Trojan.Win64.Meterpreter.11595.2675.exe | Section loaded: srvcli.dll | Jump to behavior |
Source: C:\Users\user\Desktop\SecuriteInfo.com.Trojan.Win64.Meterpreter.11595.2675.exe | Section loaded: netutils.dll | Jump to behavior |
Source: C:\Users\user\Desktop\SecuriteInfo.com.Trojan.Win64.Meterpreter.11595.2675.exe | Section loaded: windows.staterepositoryps.dll | Jump to behavior |
Source: C:\Users\user\Desktop\SecuriteInfo.com.Trojan.Win64.Meterpreter.11595.2675.exe | Section loaded: sspicli.dll | Jump to behavior |
Source: C:\Users\user\Desktop\SecuriteInfo.com.Trojan.Win64.Meterpreter.11595.2675.exe | Section loaded: wintypes.dll | Jump to behavior |
Source: C:\Users\user\Desktop\SecuriteInfo.com.Trojan.Win64.Meterpreter.11595.2675.exe | Section loaded: appresolver.dll | Jump to behavior |
Source: C:\Users\user\Desktop\SecuriteInfo.com.Trojan.Win64.Meterpreter.11595.2675.exe | Section loaded: bcp47langs.dll | Jump to behavior |
Source: C:\Users\user\Desktop\SecuriteInfo.com.Trojan.Win64.Meterpreter.11595.2675.exe | Section loaded: slc.dll | Jump to behavior |
Source: C:\Users\user\Desktop\SecuriteInfo.com.Trojan.Win64.Meterpreter.11595.2675.exe | Section loaded: userenv.dll | Jump to behavior |
Source: C:\Users\user\Desktop\SecuriteInfo.com.Trojan.Win64.Meterpreter.11595.2675.exe | Section loaded: sppc.dll | Jump to behavior |
Source: C:\Users\user\Desktop\SecuriteInfo.com.Trojan.Win64.Meterpreter.11595.2675.exe | Section loaded: pcacli.dll | Jump to behavior |
Source: C:\Users\user\Desktop\SecuriteInfo.com.Trojan.Win64.Meterpreter.11595.2675.exe | Section loaded: mpr.dll | Jump to behavior |
Source: C:\Users\user\Desktop\SecuriteInfo.com.Trojan.Win64.Meterpreter.11595.2675.exe | Section loaded: sfc_os.dll | Jump to behavior |
Source: C:\Users\user\Desktop\SecuriteInfo.com.Trojan.Win64.Meterpreter.11595.2675.exe | Section loaded: ntmarta.dll | Jump to behavior |
Source: C:\Users\user\Desktop\SecuriteInfo.com.Trojan.Win64.Meterpreter.11595.2675.exe | Section loaded: linkinfo.dll | Jump to behavior |
Source: C:\Users\user\Desktop\SecuriteInfo.com.Trojan.Win64.Meterpreter.11595.2675.exe | Section loaded: ntshrui.dll | Jump to behavior |
Source: C:\Users\user\Desktop\SecuriteInfo.com.Trojan.Win64.Meterpreter.11595.2675.exe | Section loaded: cscapi.dll | Jump to behavior |
Source: C:\Windows\System32\taskkill.exe | Section loaded: version.dll | Jump to behavior |
Source: C:\Windows\System32\taskkill.exe | Section loaded: mpr.dll | Jump to behavior |
Source: C:\Windows\System32\taskkill.exe | Section loaded: framedynos.dll | Jump to behavior |
Source: C:\Windows\System32\taskkill.exe | Section loaded: dbghelp.dll | Jump to behavior |
Source: C:\Windows\System32\taskkill.exe | Section loaded: sspicli.dll | Jump to behavior |
Source: C:\Windows\System32\taskkill.exe | Section loaded: srvcli.dll | Jump to behavior |
Source: C:\Windows\System32\taskkill.exe | Section loaded: netutils.dll | Jump to behavior |
Source: C:\Windows\System32\taskkill.exe | Section loaded: sspicli.dll | Jump to behavior |
Source: C:\Windows\System32\taskkill.exe | Section loaded: kernel.appcore.dll | Jump to behavior |
Source: C:\Windows\System32\taskkill.exe | Section loaded: wbemcomn.dll | Jump to behavior |
Source: C:\Windows\System32\taskkill.exe | Section loaded: winsta.dll | Jump to behavior |
Source: C:\Windows\System32\taskkill.exe | Section loaded: amsi.dll | Jump to behavior |
Source: C:\Windows\System32\taskkill.exe | Section loaded: userenv.dll | Jump to behavior |
Source: C:\Windows\System32\taskkill.exe | Section loaded: profapi.dll | Jump to behavior |
Source: C:\Windows\System32\regsvr32.exe | Section loaded: apphelp.dll | Jump to behavior |
Source: C:\Windows\System32\regsvr32.exe | Section loaded: aclayers.dll | Jump to behavior |
Source: C:\Windows\System32\regsvr32.exe | Section loaded: sfc.dll | Jump to behavior |
Source: C:\Windows\System32\regsvr32.exe | Section loaded: sfc_os.dll | Jump to behavior |
Source: C:\Windows\System32\regsvr32.exe | Section loaded: kernel.appcore.dll | Jump to behavior |
Source: C:\Windows\System32\regsvr32.exe | Section loaded: uxtheme.dll | Jump to behavior |
Source: C:\Windows\System32\regsvr32.exe | Section loaded: webview2loader.dll | Jump to behavior |
Source: C:\Windows\System32\regsvr32.exe | Section loaded: version.dll | Jump to behavior |
Source: C:\Windows\System32\regsvr32.exe | Section loaded: dwmapi.dll | Jump to behavior |
Source: C:\Windows\System32\regsvr32.exe | Section loaded: windows.storage.dll | Jump to behavior |
Source: C:\Windows\System32\regsvr32.exe | Section loaded: wldp.dll | Jump to behavior |
Source: C:\Windows\System32\regsvr32.exe | Section loaded: apphelp.dll | Jump to behavior |
Source: C:\Windows\System32\regsvr32.exe | Section loaded: aclayers.dll | Jump to behavior |
Source: C:\Windows\System32\regsvr32.exe | Section loaded: sfc.dll | Jump to behavior |
Source: C:\Windows\System32\regsvr32.exe | Section loaded: sfc_os.dll | Jump to behavior |
Source: C:\Windows\System32\regsvr32.exe | Section loaded: kernel.appcore.dll | Jump to behavior |
Source: C:\Windows\System32\regsvr32.exe | Section loaded: uxtheme.dll | Jump to behavior |
Source: C:\Windows\explorer.exe | Section loaded: aepic.dll | Jump to behavior |
Source: C:\Windows\explorer.exe | Section loaded: twinapi.dll | Jump to behavior |
Source: C:\Windows\explorer.exe | Section loaded: userenv.dll | Jump to behavior |
Source: C:\Windows\explorer.exe | Section loaded: iphlpapi.dll | Jump to behavior |
Source: C:\Windows\explorer.exe | Section loaded: powrprof.dll | Jump to behavior |
Source: C:\Windows\explorer.exe | Section loaded: windows.storage.dll | Jump to behavior |
Source: C:\Windows\explorer.exe | Section loaded: dxgi.dll | Jump to behavior |
Source: C:\Windows\explorer.exe | Section loaded: windows.storage.dll | Jump to behavior |
Source: C:\Windows\explorer.exe | Section loaded: kernel.appcore.dll | Jump to behavior |
Source: C:\Windows\explorer.exe | Section loaded: propsys.dll | Jump to behavior |
Source: C:\Windows\explorer.exe | Section loaded: coremessaging.dll | Jump to behavior |
Source: C:\Windows\explorer.exe | Section loaded: urlmon.dll | Jump to behavior |
Source: C:\Windows\explorer.exe | Section loaded: windows.storage.dll | Jump to behavior |
Source: C:\Windows\explorer.exe | Section loaded: windows.storage.dll | Jump to behavior |
Source: C:\Windows\explorer.exe | Section loaded: kernel.appcore.dll | Jump to behavior |
Source: C:\Windows\explorer.exe | Section loaded: wtsapi32.dll | Jump to behavior |
Source: C:\Windows\explorer.exe | Section loaded: wininet.dll | Jump to behavior |
Source: C:\Windows\explorer.exe | Section loaded: uxtheme.dll | Jump to behavior |
Source: C:\Windows\explorer.exe | Section loaded: dwmapi.dll | Jump to behavior |
Source: C:\Windows\explorer.exe | Section loaded: sspicli.dll | Jump to behavior |
Source: C:\Windows\explorer.exe | Section loaded: kernel.appcore.dll | Jump to behavior |
Source: C:\Windows\explorer.exe | Section loaded: twinapi.appcore.dll | Jump to behavior |
Source: C:\Windows\explorer.exe | Section loaded: wldp.dll | Jump to behavior |
Source: C:\Windows\explorer.exe | Section loaded: iertutil.dll | Jump to behavior |
Source: C:\Windows\explorer.exe | Section loaded: srvcli.dll | Jump to behavior |
Source: C:\Windows\explorer.exe | Section loaded: netutils.dll | Jump to behavior |
Source: C:\Windows\explorer.exe | Section loaded: dbghelp.dll | Jump to behavior |
Source: C:\Windows\explorer.exe | Section loaded: uxtheme.dll | Jump to behavior |
Source: C:\Windows\explorer.exe | Section loaded: dwmapi.dll | Jump to behavior |
Source: C:\Windows\explorer.exe | Section loaded: wininet.dll | Jump to behavior |
Source: C:\Windows\explorer.exe | Section loaded: version.dll | Jump to behavior |
Source: C:\Windows\explorer.exe | Section loaded: rstrtmgr.dll | Jump to behavior |
Source: C:\Windows\explorer.exe | Section loaded: oleacc.dll | Jump to behavior |
Source: C:\Windows\explorer.exe | Section loaded: ntmarta.dll | Jump to behavior |
Source: C:\Windows\explorer.exe | Section loaded: cryptsp.dll | Jump to behavior |
Source: C:\Windows\explorer.exe | Section loaded: ncrypt.dll | Jump to behavior |
Source: C:\Windows\explorer.exe | Section loaded: umpdc.dll | Jump to behavior |
Source: C:\Windows\explorer.exe | Section loaded: ntasn1.dll | Jump to behavior |
Source: C:\Windows\explorer.exe | Section loaded: dxgi.dll | Jump to behavior |
Source: C:\Windows\explorer.exe | Section loaded: explorerframe.dll | Jump to behavior |
Source: C:\Windows\explorer.exe | Section loaded: windows.ui.fileexplorer.dll | Jump to behavior |
Source: C:\Windows\explorer.exe | Section loaded: rsaenh.dll | Jump to behavior |
Source: C:\Windows\explorer.exe | Section loaded: cryptbase.dll | Jump to behavior |
Source: C:\Windows\explorer.exe | Section loaded: twinui.pcshell.dll | Jump to behavior |
Source: C:\Windows\explorer.exe | Section loaded: wkscli.dll | Jump to behavior |
Source: C:\Windows\explorer.exe | Section loaded: dwrite.dll | Jump to behavior |
Source: C:\Windows\explorer.exe | Section loaded: dcomp.dll | Jump to behavior |
Source: C:\Windows\explorer.exe | Section loaded: wincorlib.dll | Jump to behavior |
Source: C:\Windows\explorer.exe | Section loaded: cdp.dll | Jump to behavior |
Source: C:\Windows\explorer.exe | Section loaded: dsreg.dll | Jump to behavior |
Source: C:\Windows\explorer.exe | Section loaded: msvcp110_win.dll | Jump to behavior |
Source: C:\Windows\explorer.exe | Section loaded: twinui.dll | Jump to behavior |
Source: C:\Windows\explorer.exe | Section loaded: wintypes.dll | Jump to behavior |
Source: C:\Windows\explorer.exe | Section loaded: pdh.dll | Jump to behavior |
Source: C:\Windows\explorer.exe | Section loaded: stobject.dll | Jump to behavior |
Source: C:\Windows\explorer.exe | Section loaded: wmiclnt.dll | Jump to behavior |
Source: C:\Windows\explorer.exe | Section loaded: devobj.dll | Jump to behavior |
Source: C:\Windows\explorer.exe | Section loaded: pnidui.dll | Jump to behavior |
Source: C:\Windows\explorer.exe | Section loaded: mobilenetworking.dll | Jump to behavior |
Source: C:\Windows\explorer.exe | Section loaded: sndvolsso.dll | Jump to behavior |
Source: C:\Windows\explorer.exe | Section loaded: mmdevapi.dll | Jump to behavior |
Source: C:\Windows\explorer.exe | Section loaded: peopleband.dll | Jump to behavior |
Source: C:\Windows\explorer.exe | Section loaded: d2d1.dll | Jump to behavior |
Source: C:\Windows\explorer.exe | Section loaded: d3d11.dll | Jump to behavior |
Source: C:\Windows\explorer.exe | Section loaded: ninput.dll | Jump to behavior |
Source: C:\Windows\explorer.exe | Section loaded: taskschd.dll | Jump to behavior |
Source: C:\Windows\explorer.exe | Section loaded: xmllite.dll | Jump to behavior |
Source: C:\Windows\explorer.exe | Section loaded: msxml6.dll | Jump to behavior |
Source: C:\Windows\explorer.exe | Section loaded: wpnapps.dll | Jump to behavior |
Source: C:\Windows\explorer.exe | Section loaded: rmclient.dll | Jump to behavior |
Source: C:\Windows\explorer.exe | Section loaded: aepic.dll | Jump to behavior |
Source: C:\Windows\explorer.exe | Section loaded: twinapi.dll | Jump to behavior |
Source: C:\Windows\explorer.exe | Section loaded: userenv.dll | Jump to behavior |
Source: C:\Windows\explorer.exe | Section loaded: iphlpapi.dll | Jump to behavior |
Source: C:\Windows\explorer.exe | Section loaded: powrprof.dll | Jump to behavior |
Source: C:\Windows\explorer.exe | Section loaded: ntmarta.dll | Jump to behavior |
Source: C:\Windows\explorer.exe | Section loaded: cryptsp.dll | Jump to behavior |
Source: C:\Windows\explorer.exe | Section loaded: windows.storage.dll | Jump to behavior |
Source: C:\Windows\explorer.exe | Section loaded: dxgi.dll | Jump to behavior |
Source: C:\Windows\explorer.exe | Section loaded: windows.storage.dll | Jump to behavior |
Source: C:\Windows\explorer.exe | Section loaded: kernel.appcore.dll | Jump to behavior |
Source: C:\Windows\explorer.exe | Section loaded: propsys.dll | Jump to behavior |
Source: C:\Windows\explorer.exe | Section loaded: coremessaging.dll | Jump to behavior |
Source: C:\Windows\explorer.exe | Section loaded: urlmon.dll | Jump to behavior |
Source: C:\Windows\explorer.exe | Section loaded: windows.storage.dll | Jump to behavior |
Source: C:\Windows\explorer.exe | Section loaded: windows.storage.dll | Jump to behavior |
Source: C:\Windows\explorer.exe | Section loaded: kernel.appcore.dll | Jump to behavior |
Source: C:\Windows\explorer.exe | Section loaded: wtsapi32.dll | Jump to behavior |
Source: C:\Windows\explorer.exe | Section loaded: wininet.dll | Jump to behavior |
Source: C:\Windows\explorer.exe | Section loaded: uxtheme.dll | Jump to behavior |
Source: C:\Windows\explorer.exe | Section loaded: dwmapi.dll | Jump to behavior |
Source: C:\Windows\explorer.exe | Section loaded: sspicli.dll | Jump to behavior |
Source: C:\Windows\explorer.exe | Section loaded: kernel.appcore.dll | Jump to behavior |
Source: C:\Windows\explorer.exe | Section loaded: twinapi.appcore.dll | Jump to behavior |
Source: C:\Windows\explorer.exe | Section loaded: wldp.dll | Jump to behavior |
Source: C:\Windows\explorer.exe | Section loaded: dbghelp.dll | Jump to behavior |
Source: C:\Windows\explorer.exe | Section loaded: uxtheme.dll | Jump to behavior |
Source: C:\Windows\explorer.exe | Section loaded: dwmapi.dll | Jump to behavior |
Source: C:\Windows\explorer.exe | Section loaded: wininet.dll | Jump to behavior |
Source: C:\Windows\explorer.exe | Section loaded: version.dll | Jump to behavior |
Source: C:\Windows\explorer.exe | Section loaded: rstrtmgr.dll | Jump to behavior |
Source: C:\Windows\explorer.exe | Section loaded: oleacc.dll | Jump to behavior |
Source: C:\Windows\explorer.exe | Section loaded: iertutil.dll | Jump to behavior |
Source: C:\Windows\explorer.exe | Section loaded: srvcli.dll | Jump to behavior |
Source: C:\Windows\explorer.exe | Section loaded: netutils.dll | Jump to behavior |
Source: C:\Windows\explorer.exe | Section loaded: ncrypt.dll | Jump to behavior |
Source: C:\Windows\explorer.exe | Section loaded: umpdc.dll | Jump to behavior |
Source: C:\Windows\explorer.exe | Section loaded: ntasn1.dll | Jump to behavior |
Source: C:\Windows\explorer.exe | Section loaded: dxgi.dll | Jump to behavior |
Source: C:\Windows\explorer.exe | Section loaded: explorerframe.dll | Jump to behavior |
Source: C:\Windows\explorer.exe | Section loaded: windows.ui.fileexplorer.dll | Jump to behavior |
Source: C:\Windows\explorer.exe | Section loaded: rsaenh.dll | Jump to behavior |
Source: C:\Windows\explorer.exe | Section loaded: cryptbase.dll | Jump to behavior |
Source: C:\Windows\explorer.exe | Section loaded: twinui.pcshell.dll | Jump to behavior |
Source: C:\Windows\explorer.exe | Section loaded: wkscli.dll | Jump to behavior |
Source: C:\Windows\explorer.exe | Section loaded: dwrite.dll | Jump to behavior |
Source: C:\Windows\explorer.exe | Section loaded: dcomp.dll | Jump to behavior |
Source: C:\Windows\explorer.exe | Section loaded: wincorlib.dll | Jump to behavior |
Source: C:\Windows\explorer.exe | Section loaded: cdp.dll | Jump to behavior |
Source: C:\Windows\explorer.exe | Section loaded: dsreg.dll | Jump to behavior |
Source: C:\Windows\explorer.exe | Section loaded: msvcp110_win.dll | Jump to behavior |
Source: C:\Windows\explorer.exe | Section loaded: twinui.dll | Jump to behavior |
Source: C:\Windows\explorer.exe | Section loaded: wintypes.dll | Jump to behavior |
Source: C:\Windows\explorer.exe | Section loaded: pdh.dll | Jump to behavior |
Source: C:\Windows\explorer.exe | Section loaded: stobject.dll | Jump to behavior |
Source: C:\Windows\explorer.exe | Section loaded: wmiclnt.dll | Jump to behavior |
Source: C:\Windows\explorer.exe | Section loaded: devobj.dll | Jump to behavior |
Source: C:\Windows\explorer.exe | Section loaded: pnidui.dll | Jump to behavior |
Source: C:\Windows\explorer.exe | Section loaded: mobilenetworking.dll | Jump to behavior |
Source: C:\Windows\explorer.exe | Section loaded: sndvolsso.dll | Jump to behavior |
Source: C:\Windows\explorer.exe | Section loaded: mmdevapi.dll | Jump to behavior |
Source: C:\Windows\explorer.exe | Section loaded: peopleband.dll | Jump to behavior |
Source: C:\Windows\explorer.exe | Section loaded: d2d1.dll | Jump to behavior |
Source: C:\Windows\explorer.exe | Section loaded: d3d11.dll | Jump to behavior |
Source: C:\Windows\explorer.exe | Section loaded: msxml6.dll | Jump to behavior |
Source: C:\Windows\explorer.exe | Section loaded: wpnapps.dll | Jump to behavior |
Source: C:\Windows\explorer.exe | Section loaded: rmclient.dll | Jump to behavior |
Source: C:\Windows\explorer.exe | Section loaded: xmllite.dll | Jump to behavior |
Source: C:\Windows\explorer.exe | Section loaded: ninput.dll | Jump to behavior |
Source: C:\Windows\explorer.exe | Section loaded: appresolver.dll | Jump to behavior |
Source: C:\Windows\explorer.exe | Section loaded: bcp47langs.dll | Jump to behavior |
Source: C:\Windows\explorer.exe | Section loaded: slc.dll | Jump to behavior |
Source: C:\Windows\explorer.exe | Section loaded: sppc.dll | Jump to behavior |
Source: C:\Windows\explorer.exe | Section loaded: usermgrcli.dll | Jump to behavior |
Source: C:\Windows\explorer.exe | Section loaded: onecoreuapcommonproxystub.dll | Jump to behavior |
Source: C:\Windows\explorer.exe | Section loaded: profapi.dll | Jump to behavior |
Source: C:\Windows\explorer.exe | Section loaded: starttiledata.dll | Jump to behavior |
Source: C:\Windows\explorer.exe | Section loaded: windows.staterepositoryps.dll | Jump to behavior |
Source: C:\Windows\explorer.exe | Section loaded: idstore.dll | Jump to behavior |
Source: C:\Windows\explorer.exe | Section loaded: wlidprov.dll | Jump to behavior |
Source: C:\Windows\explorer.exe | Section loaded: samcli.dll | Jump to behavior |
Source: C:\Windows\explorer.exe | Section loaded: windows.applicationmodel.dll | Jump to behavior |
Source: C:\Windows\explorer.exe | Section loaded: appxdeploymentclient.dll | Jump to behavior |
Source: C:\Windows\explorer.exe | Section loaded: policymanager.dll | Jump to behavior |
Source: C:\Windows\explorer.exe | Section loaded: usermgrproxy.dll | Jump to behavior |
Source: C:\Windows\explorer.exe | Section loaded: windows.staterepositoryclient.dll | Jump to behavior |
Source: C:\Windows\explorer.exe | Section loaded: winsta.dll | Jump to behavior |
Source: C:\Windows\explorer.exe | Section loaded: textshaping.dll | Jump to behavior |
Source: C:\Windows\explorer.exe | Section loaded: windows.ui.dll | Jump to behavior |
Source: C:\Windows\explorer.exe | Section loaded: windowmanagementapi.dll | Jump to behavior |
Source: C:\Windows\explorer.exe | Section loaded: textinputframework.dll | Jump to behavior |
Source: C:\Windows\explorer.exe | Section loaded: inputhost.dll | Jump to behavior |
Source: C:\Windows\explorer.exe | Section loaded: coreuicomponents.dll | Jump to behavior |
Source: C:\Windows\explorer.exe | Section loaded: coreuicomponents.dll | Jump to behavior |
Source: C:\Windows\explorer.exe | Section loaded: windowscodecs.dll | Jump to behavior |
Source: C:\Windows\explorer.exe | Section loaded: windows.cloudstore.dll | Jump to behavior |
Source: C:\Windows\explorer.exe | Section loaded: resourcepolicyclient.dll | Jump to behavior |
Source: C:\Windows\explorer.exe | Section loaded: d3d10warp.dll | Jump to behavior |
Source: C:\Windows\explorer.exe | Section loaded: appextension.dll | Jump to behavior |
Source: C:\Windows\explorer.exe | Section loaded: dxcore.dll | Jump to behavior |
Source: C:\Windows\explorer.exe | Section loaded: windows.cloudstore.schema.shell.dll | Jump to behavior |
Source: C:\Windows\explorer.exe | Section loaded: cldapi.dll | Jump to behavior |
Source: C:\Windows\explorer.exe | Section loaded: fltlib.dll | Jump to behavior |
Source: C:\Windows\explorer.exe | Section loaded: dataexchange.dll | Jump to behavior |
Source: C:\Windows\explorer.exe | Section loaded: apphelp.dll | Jump to behavior |
Source: C:\Windows\explorer.exe | Section loaded: tiledatarepository.dll | Jump to behavior |
Source: C:\Windows\explorer.exe | Section loaded: staterepository.core.dll | Jump to behavior |
Source: C:\Windows\explorer.exe | Section loaded: windows.staterepository.dll | Jump to behavior |
Source: C:\Windows\explorer.exe | Section loaded: windows.staterepositorycore.dll | Jump to behavior |
Source: C:\Windows\explorer.exe | Section loaded: windows.immersiveshell.serviceprovider.dll | Jump to behavior |
Source: C:\Windows\explorer.exe | Section loaded: mrmcorer.dll | Jump to behavior |
Source: C:\Windows\explorer.exe | Section loaded: languageoverlayutil.dll | Jump to behavior |
Source: C:\Windows\explorer.exe | Section loaded: bcp47mrm.dll | Jump to behavior |
Source: C:\Windows\explorer.exe | Section loaded: thumbcache.dll | Jump to behavior |
Source: C:\Windows\explorer.exe | Section loaded: edputil.dll | Jump to behavior |
Source: C:\Windows\explorer.exe | Section loaded: onecorecommonproxystub.dll | Jump to behavior |
Source: C:\Windows\explorer.exe | Section loaded: linkinfo.dll | Jump to behavior |
Source: C:\Windows\explorer.exe | Section loaded: photometadatahandler.dll | Jump to behavior |
Source: C:\Windows\explorer.exe | Section loaded: ntshrui.dll | Jump to behavior |
Source: C:\Windows\explorer.exe | Section loaded: twinui.appcore.dll | Jump to behavior |
Source: C:\Windows\explorer.exe | Section loaded: cscapi.dll | Jump to behavior |
Source: C:\Windows\explorer.exe | Section loaded: applicationframe.dll | Jump to behavior |
Source: C:\Windows\explorer.exe | Section loaded: ondemandconnroutehelper.dll | Jump to behavior |
Source: C:\Windows\explorer.exe | Section loaded: winhttp.dll | Jump to behavior |
Source: C:\Windows\explorer.exe | Section loaded: mswsock.dll | Jump to behavior |
Source: C:\Windows\explorer.exe | Section loaded: winnsi.dll | Jump to behavior |
Source: C:\Windows\explorer.exe | Section loaded: ehstorshell.dll | Jump to behavior |
Source: C:\Windows\explorer.exe | Section loaded: cscui.dll | Jump to behavior |
Source: C:\Windows\explorer.exe | Section loaded: provsvc.dll | Jump to behavior |
Source: C:\Windows\explorer.exe | Section loaded: dnsapi.dll | Jump to behavior |
Source: C:\Windows\explorer.exe | Section loaded: rasadhlp.dll | Jump to behavior |
Source: C:\Windows\explorer.exe | Section loaded: fwpuclnt.dll | Jump to behavior |
Source: C:\Windows\explorer.exe | Section loaded: holographicextensions.dll | Jump to behavior |
Source: C:\Windows\explorer.exe | Section loaded: virtualmonitormanager.dll | Jump to behavior |
Source: C:\Windows\explorer.exe | Section loaded: resourcepolicyclient.dll | Jump to behavior |
Source: C:\Windows\explorer.exe | Section loaded: windows.ui.immersive.dll | Jump to behavior |
Source: C:\Windows\explorer.exe | Section loaded: abovelockapphost.dll | Jump to behavior |
Source: C:\Windows\explorer.exe | Section loaded: npsm.dll | Jump to behavior |
Source: C:\Windows\explorer.exe | Section loaded: windows.shell.bluelightreduction.dll | Jump to behavior |
Source: C:\Windows\explorer.exe | Section loaded: mscms.dll | Jump to behavior |
Source: C:\Windows\explorer.exe | Section loaded: coloradapterclient.dll | Jump to behavior |
Source: C:\Windows\explorer.exe | Section loaded: windows.web.dll | Jump to behavior |
Source: C:\Windows\explorer.exe | Section loaded: windows.internal.signals.dll | Jump to behavior |
Source: C:\Windows\explorer.exe | Section loaded: tdh.dll | Jump to behavior |
Source: C:\Windows\explorer.exe | Section loaded: windows.staterepositorybroker.dll | Jump to behavior |
Source: C:\Windows\explorer.exe | Section loaded: mfplat.dll | Jump to behavior |
Source: C:\Windows\explorer.exe | Section loaded: rtworkq.dll | Jump to behavior |
Source: C:\Windows\explorer.exe | Section loaded: taskflowdataengine.dll | Jump to behavior |
Source: C:\Windows\explorer.exe | Section loaded: structuredquery.dll | Jump to behavior |
Source: C:\Windows\explorer.exe | Section loaded: actxprxy.dll | Jump to behavior |
Source: C:\Windows\explorer.exe | Section loaded: windows.data.activities.dll | Jump to behavior |
Source: C:\Windows\explorer.exe | Section loaded: windows.security.authentication.web.core.dll | Jump to behavior |
Source: C:\Windows\explorer.exe | Section loaded: windows.internal.ui.shell.windowtabmanager.dll | Jump to behavior |
Source: C:\Windows\explorer.exe | Section loaded: windows.system.launcher.dll | Jump to behavior |
Source: C:\Windows\explorer.exe | Section loaded: windows.shell.servicehostbuilder.dll | Jump to behavior |
Source: C:\Windows\explorer.exe | Section loaded: notificationcontrollerps.dll | Jump to behavior |
Source: C:\Windows\explorer.exe | Section loaded: schannel.dll | Jump to behavior |
Source: C:\Windows\explorer.exe | Section loaded: windows.devices.enumeration.dll | Jump to behavior |
Source: C:\Windows\explorer.exe | Section loaded: windows.globalization.dll | Jump to behavior |
Source: C:\Windows\explorer.exe | Section loaded: icu.dll | Jump to behavior |
Source: C:\Windows\explorer.exe | Section loaded: mswb7.dll | Jump to behavior |
Source: C:\Windows\explorer.exe | Section loaded: devdispitemprovider.dll | Jump to behavior |
Source: C:\Windows\explorer.exe | Section loaded: windows.networking.connectivity.dll | Jump to behavior |
Source: C:\Windows\explorer.exe | Section loaded: windows.ui.core.textinput.dll | Jump to behavior |
Source: C:\Windows\explorer.exe | Section loaded: uianimation.dll | Jump to behavior |
Source: C:\Windows\explorer.exe | Section loaded: windowsudk.shellcommon.dll | Jump to behavior |
Source: C:\Windows\explorer.exe | Section loaded: dictationmanager.dll | Jump to behavior |
Source: C:\Windows\explorer.exe | Section loaded: npmproxy.dll | Jump to behavior |
Source: C:\Windows\explorer.exe | Section loaded: dpapi.dll | Jump to behavior |
Source: C:\Windows\explorer.exe | Section loaded: msasn1.dll | Jump to behavior |
Source: C:\Windows\explorer.exe | Section loaded: mskeyprotect.dll | Jump to behavior |
Source: C:\Windows\explorer.exe | Section loaded: ncryptsslp.dll | Jump to behavior |
Source: C:\Windows\explorer.exe | Section loaded: gpapi.dll | Jump to behavior |
Source: C:\Windows\explorer.exe | Section loaded: taskschd.dll | Jump to behavior |
Source: C:\Windows\explorer.exe | Section loaded: pcshellcommonproxystub.dll | Jump to behavior |
Source: C:\Windows\explorer.exe | Section loaded: shellcommoncommonproxystub.dll | Jump to behavior |
Source: C:\Windows\explorer.exe | Section loaded: cryptngc.dll | Jump to behavior |
Source: C:\Windows\explorer.exe | Section loaded: cflapi.dll | Jump to behavior |
Source: C:\Windows\explorer.exe | Section loaded: execmodelproxy.dll | Jump to behavior |
Source: C:\Windows\explorer.exe | Section loaded: daxexec.dll | Jump to behavior |
Source: C:\Windows\explorer.exe | Section loaded: container.dll | Jump to behavior |
Source: C:\Windows\explorer.exe | Section loaded: samlib.dll | Jump to behavior |
Source: C:\Windows\explorer.exe | Section loaded: capabilityaccessmanagerclient.dll | Jump to behavior |
Source: C:\Windows\explorer.exe | Section loaded: batmeter.dll | Jump to behavior |
Source: C:\Windows\explorer.exe | Section loaded: sxs.dll | Jump to behavior |
Source: C:\Windows\explorer.exe | Section loaded: inputswitch.dll | Jump to behavior |
Source: C:\Windows\explorer.exe | Section loaded: windows.ui.shell.dll | Jump to behavior |
Source: C:\Windows\explorer.exe | Section loaded: es.dll | Jump to behavior |
Source: C:\Windows\explorer.exe | Section loaded: prnfldr.dll | Jump to behavior |
Source: C:\Windows\explorer.exe | Section loaded: workfoldersshell.dll | Jump to behavior |
Source: C:\Windows\explorer.exe | Section loaded: windows.fileexplorer.common.dll | Jump to behavior |
Source: C:\Windows\explorer.exe | Section loaded: dxp.dll | Jump to behavior |
Source: C:\Windows\explorer.exe | Section loaded: shdocvw.dll | Jump to behavior |
Source: C:\Windows\explorer.exe | Section loaded: syncreg.dll | Jump to behavior |
Source: C:\Windows\explorer.exe | Section loaded: atlthunk.dll | Jump to behavior |
Source: C:\Windows\explorer.exe | Section loaded: actioncenter.dll | Jump to behavior |
Source: C:\Windows\explorer.exe | Section loaded: wevtapi.dll | Jump to behavior |
Source: C:\Windows\explorer.exe | Section loaded: wscinterop.dll | Jump to behavior |
Source: C:\Windows\explorer.exe | Section loaded: wscapi.dll | Jump to behavior |
Source: C:\Windows\explorer.exe | Section loaded: werconcpl.dll | Jump to behavior |
Source: C:\Windows\explorer.exe | Section loaded: framedynos.dll | Jump to behavior |
Source: C:\Windows\explorer.exe | Section loaded: wer.dll | Jump to behavior |
Source: C:\Windows\explorer.exe | Section loaded: hcproviders.dll | Jump to behavior |
Source: C:\Windows\explorer.exe | Section loaded: audioses.dll | Jump to behavior |
Source: C:\Windows\explorer.exe | Section loaded: netprofm.dll | Jump to behavior |
Source: C:\Windows\explorer.exe | Section loaded: networkuxbroker.dll | Jump to behavior |
Source: C:\Windows\explorer.exe | Section loaded: ethernetmediamanager.dll | Jump to behavior |
Source: C:\Windows\explorer.exe | Section loaded: dusmapi.dll | Jump to behavior |
Source: C:\Windows\explorer.exe | Section loaded: wpnclient.dll | Jump to behavior |
Source: C:\Windows\explorer.exe | Section loaded: wpdshserviceobj.dll | Jump to behavior |
Source: C:\Windows\explorer.exe | Section loaded: portabledevicetypes.dll | Jump to behavior |
Source: C:\Windows\explorer.exe | Section loaded: portabledeviceapi.dll | Jump to behavior |
Source: C:\Windows\explorer.exe | Section loaded: cscobj.dll | Jump to behavior |
Source: C:\Windows\explorer.exe | Section loaded: wlanapi.dll | Jump to behavior |
Source: C:\Windows\explorer.exe | Section loaded: ncsi.dll | Jump to behavior |
Source: C:\Windows\explorer.exe | Section loaded: srchadmin.dll | Jump to behavior |
Source: C:\Windows\explorer.exe | Section loaded: dhcpcsvc6.dll | Jump to behavior |
Source: C:\Windows\explorer.exe | Section loaded: dhcpcsvc.dll | Jump to behavior |
Source: C:\Windows\explorer.exe | Section loaded: windows.storage.search.dll | Jump to behavior |
Source: C:\Windows\explorer.exe | Section loaded: synccenter.dll | Jump to behavior |
Source: C:\Windows\explorer.exe | Section loaded: imapi2.dll | Jump to behavior |
Source: C:\Windows\explorer.exe | Section loaded: storageusage.dll | Jump to behavior |
Source: C:\Windows\explorer.exe | Section loaded: fhcfg.dll | Jump to behavior |
Source: C:\Windows\explorer.exe | Section loaded: efsutil.dll | Jump to behavior |
Source: C:\Windows\explorer.exe | Section loaded: mpr.dll | Jump to behavior |
Source: C:\Windows\explorer.exe | Section loaded: netapi32.dll | Jump to behavior |
Source: C:\Windows\explorer.exe | Section loaded: dsrole.dll | Jump to behavior |
Source: C:\Windows\explorer.exe | Section loaded: ieproxy.dll | Jump to behavior |
Source: C:\Windows\explorer.exe | Section loaded: windows.internal.system.userprofile.dll | Jump to behavior |
Source: C:\Windows\explorer.exe | Section loaded: cloudexperiencehostbroker.dll | Jump to behavior |
Source: C:\Windows\explorer.exe | Section loaded: credui.dll | Jump to behavior |
Source: C:\Windows\explorer.exe | Section loaded: dui70.dll | Jump to behavior |
Source: C:\Windows\explorer.exe | Section loaded: wdscore.dll | Jump to behavior |
Source: C:\Windows\explorer.exe | Section loaded: dbgcore.dll | Jump to behavior |
Source: C:\Windows\explorer.exe | Section loaded: bluetoothapis.dll | Jump to behavior |
Source: C:\Windows\explorer.exe | Section loaded: bluetoothapis.dll | Jump to behavior |
Source: C:\Windows\explorer.exe | Section loaded: vcruntime140_1.dll | Jump to behavior |
Source: C:\Windows\explorer.exe | Section loaded: vcruntime140.dll | Jump to behavior |
Source: C:\Windows\explorer.exe | Section loaded: msvcp140.dll | Jump to behavior |
Source: C:\Windows\explorer.exe | Section loaded: vcruntime140.dll | Jump to behavior |
Source: C:\Windows\explorer.exe | Section loaded: settingsync.dll | Jump to behavior |
Source: C:\Windows\explorer.exe | Section loaded: settingsynccore.dll | Jump to behavior |
Source: C:\Windows\explorer.exe | Section loaded: windows.ui.xaml.dll | Jump to behavior |
Source: C:\Windows\explorer.exe | Section loaded: windowsinternal.composableshell.desktophosting.dll | Jump to behavior |
Source: C:\Windows\explorer.exe | Section loaded: uiamanager.dll | Jump to behavior |
Source: | Binary string: D:\a\_work\e\src\out\Release_x64\WebView2Loader.dll.pdb source: SecuriteInfo.com.Trojan.Win64.Meterpreter.11595.2675.exe, 00000000.00000003.2145293156.000001BF13B8D000.00000004.00000020.00020000.00000000.sdmp |
Source: | Binary string: /download/symbols/twinui.pcshell.pdb/56A53B20B8D4F79E69038072C21547311/twinui.pcshell.pdb source: explorer.exe, 0000000B.00000003.2234944578.0000000002E7D000.00000004.00000020.00020000.00000000.sdmp, explorer.exe, 0000000B.00000003.2332407476.0000000002E7D000.00000004.00000020.00020000.00000000.sdmp |
Source: | Binary string: twinui.pcshell.pdb source: explorer.exe, 0000000A.00000003.2167375925.00000000027E3000.00000004.00000020.00020000.00000000.sdmp, explorer.exe, 0000000B.00000003.2174577379.00000000023D5000.00000004.00000020.00020000.00000000.sdmp, explorer.exe, 0000000B.00000003.2178744483.0000000002D5E000.00000004.00000020.00020000.00000000.sdmp, explorer.exe, 0000000B.00000003.2176793588.00000000023D4000.00000004.00000020.00020000.00000000.sdmp |
Source: | Binary string: http://msdl.microsoft.com/download/symbols/twinui.pcshell.pdb/56A53B20B8D4F79E69038072C21547311/twinui.pcshell.pdb source: explorer.exe, 0000000B.00000003.2198671395.0000000002ED7000.00000004.00000020.00020000.00000000.sdmp, explorer.exe, 0000000B.00000003.2192876585.0000000002F1D000.00000004.00000020.00020000.00000000.sdmp, explorer.exe, 0000000B.00000003.2235994933.0000000002F37000.00000004.00000020.00020000.00000000.sdmp, explorer.exe, 0000000B.00000003.2246571830.0000000002F1D000.00000004.00000020.00020000.00000000.sdmp, explorer.exe, 0000000B.00000003.2192876585.0000000002F48000.00000004.00000020.00020000.00000000.sdmp, explorer.exe, 0000000B.00000003.2193206748.0000000002EBD000.00000004.00000020.00020000.00000000.sdmp, explorer.exe, 0000000B.00000003.2288267379.0000000002F1D000.00000004.00000020.00020000.00000000.sdmp, explorer.exe, 0000000B.00000003.2198671395.0000000002F1D000.00000004.00000020.00020000.00000000.sdmp, explorer.exe, 0000000B.00000003.2252874097.0000000002F1D000.00000004.00000020.00020000.00000000.sdmp, explorer.exe, 0000000B.00000003.2235994933.0000000002F1D000.00000004.00000020.00020000.00000000.sdmp, explorer.exe, 0000000B.00000003.2204325725.0000000002F33000.00000004.00000020.00020000.00000000.sdmp, explorer.exe, 0000000B.00000003.2320144168.0000000002F1D000.00000004.00000020.00020000.00000000.sdmp, explorer.exe, 0000000B.00000003.2381212820.0000000002F1D000.00000004.00000020.00020000.00000000.sdmp, explorer.exe, 0000000B.00000003.2234944578.0000000002F37000.00000004.00000020.00020000.00000000.sdmp, explorer.exe, 0000000B.00000003.2234944578.0000000002F1D000.00000004.00000020.00020000.00000000.sdmp |
Source: | Binary string: D:\a\ExplorerPatcher\ExplorerPatcher\build\Release\x64\ExplorerPatcher.amd64.pdb source: SecuriteInfo.com.Trojan.Win64.Meterpreter.11595.2675.exe, 00000000.00000003.2146053134.000001BF162C1000.00000004.00000020.00020000.00000000.sdmp, explorer.exe, 0000000A.00000002.2175083796.00007FF8BEE7D000.00000002.00000001.01000000.00000008.sdmp |
Source: | Binary string: D:\a\ExplorerPatcher\ExplorerPatcher\build\Release\x64\ep_weather_host_stub.pdb source: SecuriteInfo.com.Trojan.Win64.Meterpreter.11595.2675.exe, 00000000.00000003.2145109319.000001BF13BA7000.00000004.00000020.00020000.00000000.sdmp, SecuriteInfo.com.Trojan.Win64.Meterpreter.11595.2675.exe, 00000000.00000003.2145084872.000001BF13B8D000.00000004.00000020.00020000.00000000.sdmp |
Source: | Binary string: D:\a\_work\e\src\out\Release_x64\WebView2Loader.dll.pdbOGP source: SecuriteInfo.com.Trojan.Win64.Meterpreter.11595.2675.exe, 00000000.00000003.2145293156.000001BF13B8D000.00000004.00000020.00020000.00000000.sdmp |
Source: | Binary string: http://msdl.microsoft.com/download/symbols/twinui.pcshell.pdb/56A53B20B8D4F79E69038072C21547311/twinui.pcshell.pdby source: explorer.exe, 0000000B.00000003.2192876585.0000000002F1D000.00000004.00000020.00020000.00000000.sdmp, explorer.exe, 0000000B.00000003.2198671395.0000000002F1D000.00000004.00000020.00020000.00000000.sdmp |
Source: | Binary string: D:\a\ExplorerPatcher\ExplorerPatcher\build\Release\x64\ep_dwm.pdb source: SecuriteInfo.com.Trojan.Win64.Meterpreter.11595.2675.exe, 00000000.00000003.2144537598.000001BF13B8D000.00000004.00000020.00020000.00000000.sdmp, SecuriteInfo.com.Trojan.Win64.Meterpreter.11595.2675.exe, 00000000.00000003.2144601951.000001BF13BA9000.00000004.00000020.00020000.00000000.sdmp |
Source: | Binary string: StartUI.pdb source: explorer.exe, 0000000A.00000003.2166635686.00000000027EA000.00000004.00000020.00020000.00000000.sdmp, explorer.exe, 0000000B.00000003.2175731585.00000000023D3000.00000004.00000020.00020000.00000000.sdmp |
Source: | Binary string: .pcshell.pdb source: explorer.exe, 0000000B.00000003.2235994933.0000000002F37000.00000004.00000020.00020000.00000000.sdmp, explorer.exe, 0000000B.00000003.2246571830.0000000002F1D000.00000004.00000020.00020000.00000000.sdmp, explorer.exe, 0000000B.00000003.2288267379.0000000002F1D000.00000004.00000020.00020000.00000000.sdmp, explorer.exe, 0000000B.00000003.2252874097.0000000002F1D000.00000004.00000020.00020000.00000000.sdmp, explorer.exe, 0000000B.00000003.2204325725.0000000002F33000.00000004.00000020.00020000.00000000.sdmp, explorer.exe, 0000000B.00000003.2320144168.0000000002F1D000.00000004.00000020.00020000.00000000.sdmp, explorer.exe, 0000000B.00000003.2381212820.0000000002F1D000.00000004.00000020.00020000.00000000.sdmp, explorer.exe, 0000000B.00000003.2234944578.0000000002F37000.00000004.00000020.00020000.00000000.sdmp |
Source: | Binary string: {"function" : "getkfmupsellstate", "args" : {}}.pdb source: explorer.exe, 0000000B.00000003.2377129178.000000000AF04000.00000004.00000020.00020000.00000000.sdmp |
Source: | Binary string: http://msdl.microsoft.com/download/symbols/twinui.pcshell.pdb/56A53B20B8D4F79E69038072C21547311/twinui.pcshell.pdbb source: explorer.exe, 0000000B.00000003.2198671395.0000000002F1D000.00000004.00000020.00020000.00000000.sdmp |
Source: | Binary string: http://msdl.microsoft.com/download/symbols/twinui.pcshell.pdb/56A53B20B8D4F79E69038072C21547311/twinui.pcshell.pdb! source: explorer.exe, 0000000B.00000003.2192876585.0000000002F1D000.00000004.00000020.00020000.00000000.sdmp, explorer.exe, 0000000B.00000003.2246571830.0000000002F1D000.00000004.00000020.00020000.00000000.sdmp, explorer.exe, 0000000B.00000003.2288267379.0000000002F1D000.00000004.00000020.00020000.00000000.sdmp, explorer.exe, 0000000B.00000003.2198671395.0000000002F1D000.00000004.00000020.00020000.00000000.sdmp, explorer.exe, 0000000B.00000003.2252874097.0000000002F1D000.00000004.00000020.00020000.00000000.sdmp, explorer.exe, 0000000B.00000003.2235994933.0000000002F1D000.00000004.00000020.00020000.00000000.sdmp, explorer.exe, 0000000B.00000003.2320144168.0000000002F1D000.00000004.00000020.00020000.00000000.sdmp, explorer.exe, 0000000B.00000003.2234944578.0000000002F1D000.00000004.00000020.00020000.00000000.sdmp |
Source: | Binary string: C:\Users\user\AppData\Roaming\ExplorerPatcher\twinui.pcshell.pdb{ source: explorer.exe, 0000000B.00000003.2377129178.000000000AF04000.00000004.00000020.00020000.00000000.sdmp |
Source: | Binary string: D:\a\ExplorerPatcher\ExplorerPatcher\build\Release\Win32\ExplorerPatcher.IA-32.pdb source: SecuriteInfo.com.Trojan.Win64.Meterpreter.11595.2675.exe, 00000000.00000003.2143630593.000001BF13BB2000.00000004.00000020.00020000.00000000.sdmp, SecuriteInfo.com.Trojan.Win64.Meterpreter.11595.2675.exe, 00000000.00000003.2143599851.000001BF13B8D000.00000004.00000020.00020000.00000000.sdmp |
Source: | Binary string: D:\a\ExplorerPatcher\ExplorerPatcher\build\Release\x64\ep_setup.pdb source: SecuriteInfo.com.Trojan.Win64.Meterpreter.11595.2675.exe, 00000000.00000002.2165080505.00007FF7F56F6000.00000002.00000001.01000000.00000003.sdmp, SecuriteInfo.com.Trojan.Win64.Meterpreter.11595.2675.exe, 00000000.00000000.2108533057.00007FF7F56F6000.00000002.00000001.01000000.00000003.sdmp |
Source: | Binary string: C:\Users\user\AppData\Roaming\ExplorerPatcher\twinui.pcshell.pdb source: explorer.exe, 0000000B.00000003.2377129178.000000000AF04000.00000004.00000020.00020000.00000000.sdmp, explorer.exe, 0000000B.00000003.2383069605.0000000008B96000.00000004.00000020.00020000.00000000.sdmp |
Source: | Binary string: D:\a\ExplorerPatcher\ExplorerPatcher\build\Release\x64\ep_gui.pdb source: SecuriteInfo.com.Trojan.Win64.Meterpreter.11595.2675.exe, 00000000.00000003.2144271915.000001BF162C1000.00000004.00000020.00020000.00000000.sdmp, explorer.exe, 0000000A.00000002.2174585427.0000000002880000.00000002.00000001.00040000.00000009.sdmp |
Source: | Binary string: D:\a\ExplorerPatcher\ExplorerPatcher\build\Release\x64\ep_weather_host.pdb source: SecuriteInfo.com.Trojan.Win64.Meterpreter.11595.2675.exe, 00000000.00000003.2144774735.000001BF162C1000.00000004.00000020.00020000.00000000.sdmp, SecuriteInfo.com.Trojan.Win64.Meterpreter.11595.2675.exe, 00000000.00000003.2144908523.000001BF13B8D000.00000004.00000020.00020000.00000000.sdmp |
Source: | Binary string: http://msdl.microsoft.com/download/symbols/twinui.pcshell.pdb/56A53B20B8D4F79E69038072C21547311/twinui.pcshell.pdbO source: explorer.exe, 0000000B.00000003.2235994933.0000000002F37000.00000004.00000020.00020000.00000000.sdmp, explorer.exe, 0000000B.00000003.2246571830.0000000002F1D000.00000004.00000020.00020000.00000000.sdmp, explorer.exe, 0000000B.00000003.2288267379.0000000002F1D000.00000004.00000020.00020000.00000000.sdmp, explorer.exe, 0000000B.00000003.2252874097.0000000002F1D000.00000004.00000020.00020000.00000000.sdmp, explorer.exe, 0000000B.00000003.2204325725.0000000002F33000.00000004.00000020.00020000.00000000.sdmp, explorer.exe, 0000000B.00000003.2320144168.0000000002F1D000.00000004.00000020.00020000.00000000.sdmp, explorer.exe, 0000000B.00000003.2381212820.0000000002F1D000.00000004.00000020.00020000.00000000.sdmp, explorer.exe, 0000000B.00000003.2234944578.0000000002F37000.00000004.00000020.00020000.00000000.sdmp |
Source: | Binary string: StartUI.pdbH source: explorer.exe, 0000000A.00000003.2166635686.00000000027EA000.00000004.00000020.00020000.00000000.sdmp, explorer.exe, 0000000B.00000003.2175731585.00000000023D3000.00000004.00000020.00020000.00000000.sdmp |
Source: | Binary string: twinui.pcshell.pdbUGP source: explorer.exe, 0000000A.00000003.2167375925.00000000027E3000.00000004.00000020.00020000.00000000.sdmp, explorer.exe, 0000000B.00000003.2174577379.00000000023D5000.00000004.00000020.00020000.00000000.sdmp, explorer.exe, 0000000B.00000003.2178744483.0000000002D5E000.00000004.00000020.00020000.00000000.sdmp, explorer.exe, 0000000B.00000003.2176793588.00000000023D4000.00000004.00000020.00020000.00000000.sdmp |
Source: C:\Windows\explorer.exe | Code function: 10_2_00007FF8BEE23DA0 FindWindowExW,FindWindowExW,FindWindowExW,SendMessageW, | 10_2_00007FF8BEE23DA0 |
Source: C:\Windows\explorer.exe | Code function: 10_2_00007FF8BEE23880 GetCursorPos,MonitorFromPoint,FindWindowExW,MonitorFromWindow,FindWindowExW,FindWindowExW,FindWindowW,FindWindowExW,FindWindowExW,GetCursorPos,GetCursorPos,MonitorFromPoint,FindWindowExW,MonitorFromWindow,MonitorFromPoint,GetMonitorInfoW,FindWindowExW,MonitorFromWindow,GetMonitorInfoW,GetWindowRect,SetCursorPos,SetCursorPos,FindWindowW,PostMessageW,PostMessageW,FindWindowExW,FindWindowW,GetCursorPos,GetCursorPos,MonitorFromPoint,FindWindowExW,MonitorFromWindow,MonitorFromPoint,GetMonitorInfoW,FindWindowExW,MonitorFromWindow,GetMonitorInfoW,GetWindowRect,SetCursorPos,FindWindowExW,PostMessageW,GetWindowLongPtrW,GetWindowLongPtrW,SendMessageCallbackW,PostMessageW, | 10_2_00007FF8BEE23880 |
Source: C:\Windows\explorer.exe | Code function: 10_2_00007FF8BEE23880 GetCursorPos,MonitorFromPoint,FindWindowExW,MonitorFromWindow,FindWindowExW,FindWindowExW,FindWindowW,FindWindowExW,FindWindowExW,GetCursorPos,GetCursorPos,MonitorFromPoint,FindWindowExW,MonitorFromWindow,MonitorFromPoint,GetMonitorInfoW,FindWindowExW,MonitorFromWindow,GetMonitorInfoW,GetWindowRect,SetCursorPos,SetCursorPos,FindWindowW,PostMessageW,PostMessageW,FindWindowExW,FindWindowW,GetCursorPos,GetCursorPos,MonitorFromPoint,FindWindowExW,MonitorFromWindow,MonitorFromPoint,GetMonitorInfoW,FindWindowExW,MonitorFromWindow,GetMonitorInfoW,GetWindowRect,SetCursorPos,FindWindowExW,PostMessageW,GetWindowLongPtrW,GetWindowLongPtrW,SendMessageCallbackW,PostMessageW, | 10_2_00007FF8BEE23880 |
Source: C:\Windows\explorer.exe | Code function: 10_2_00007FF8BEE23880 GetCursorPos,MonitorFromPoint,FindWindowExW,MonitorFromWindow,FindWindowExW,FindWindowExW,FindWindowW,FindWindowExW,FindWindowExW,GetCursorPos,GetCursorPos,MonitorFromPoint,FindWindowExW,MonitorFromWindow,MonitorFromPoint,GetMonitorInfoW,FindWindowExW,MonitorFromWindow,GetMonitorInfoW,GetWindowRect,SetCursorPos,SetCursorPos,FindWindowW,PostMessageW,PostMessageW,FindWindowExW,FindWindowW,GetCursorPos,GetCursorPos,MonitorFromPoint,FindWindowExW,MonitorFromWindow,MonitorFromPoint,GetMonitorInfoW,FindWindowExW,MonitorFromWindow,GetMonitorInfoW,GetWindowRect,SetCursorPos,FindWindowExW,PostMessageW,GetWindowLongPtrW,GetWindowLongPtrW,SendMessageCallbackW,PostMessageW, | 10_2_00007FF8BEE23880 |
Source: C:\Windows\explorer.exe | Code function: 10_2_00007FF8BEE23880 GetCursorPos,MonitorFromPoint,FindWindowExW,MonitorFromWindow,FindWindowExW,FindWindowExW,FindWindowW,FindWindowExW,FindWindowExW,GetCursorPos,GetCursorPos,MonitorFromPoint,FindWindowExW,MonitorFromWindow,MonitorFromPoint,GetMonitorInfoW,FindWindowExW,MonitorFromWindow,GetMonitorInfoW,GetWindowRect,SetCursorPos,SetCursorPos,FindWindowW,PostMessageW,PostMessageW,FindWindowExW,FindWindowW,GetCursorPos,GetCursorPos,MonitorFromPoint,FindWindowExW,MonitorFromWindow,MonitorFromPoint,GetMonitorInfoW,FindWindowExW,MonitorFromWindow,GetMonitorInfoW,GetWindowRect,SetCursorPos,FindWindowExW,PostMessageW,GetWindowLongPtrW,GetWindowLongPtrW,SendMessageCallbackW,PostMessageW, | 10_2_00007FF8BEE23880 |
Source: C:\Windows\explorer.exe | Code function: 10_2_00007FF8BEE23880 GetCursorPos,MonitorFromPoint,FindWindowExW,MonitorFromWindow,FindWindowExW,FindWindowExW,FindWindowW,FindWindowExW,FindWindowExW,GetCursorPos,GetCursorPos,MonitorFromPoint,FindWindowExW,MonitorFromWindow,MonitorFromPoint,GetMonitorInfoW,FindWindowExW,MonitorFromWindow,GetMonitorInfoW,GetWindowRect,SetCursorPos,SetCursorPos,FindWindowW,PostMessageW,PostMessageW,FindWindowExW,FindWindowW,GetCursorPos,GetCursorPos,MonitorFromPoint,FindWindowExW,MonitorFromWindow,MonitorFromPoint,GetMonitorInfoW,FindWindowExW,MonitorFromWindow,GetMonitorInfoW,GetWindowRect,SetCursorPos,FindWindowExW,PostMessageW,GetWindowLongPtrW,GetWindowLongPtrW,SendMessageCallbackW,PostMessageW, | 10_2_00007FF8BEE23880 |
Source: C:\Windows\explorer.exe | Code function: 10_2_00007FF8BEE1F4C0 FindWindowW,SendMessageTimeoutW, | 10_2_00007FF8BEE1F4C0 |