Source: | Binary string: D:\a\_work\e\src\out\Release_x64\WebView2Loader.dll.pdb source: SecuriteInfo.com.Trojan.Win64.Meterpreter.11595.2675.exe, 00000000.00000003.1754494111.000001B92F950000.00000004.00000020.00020000.00000000.sdmp |
Source: | Binary string: http://msdl.microsoft.com/download/symbols/twinui.pcshell.pdb/56A53B20B8D4F79E69038072C21547311/twinui.pcshell.pdb source: explorer.exe, 0000000A.00000003.1912234304.000000000BAA9000.00000004.00000020.00020000.00000000.sdmp, explorer.exe, 0000000A.00000003.1863754048.000000000BAA9000.00000004.00000020.00020000.00000000.sdmp, explorer.exe, 0000000A.00000003.2034843476.000000000B8F3000.00000004.00000020.00020000.00000000.sdmp, explorer.exe, 0000000A.00000003.2040664141.000000000BAA9000.00000004.00000020.00020000.00000000.sdmp, explorer.exe, 0000000A.00000003.2044927276.000000000BAA9000.00000004.00000020.00020000.00000000.sdmp |
Source: | Binary string: C:\Users\user\AppData\Roaming\ExplorerPatcher\twinui.pcshell.pdb( source: explorer.exe, 0000000A.00000003.2032672748.000000000BA85000.00000004.00000020.00020000.00000000.sdmp, explorer.exe, 0000000A.00000003.2044927276.000000000BA85000.00000004.00000020.00020000.00000000.sdmp, explorer.exe, 0000000A.00000003.2040664141.000000000BA85000.00000004.00000020.00020000.00000000.sdmp |
Source: | Binary string: eehttp://msdl.microsoft.com/download/symbols/StartUI.pdb/74D47198CB4699BA710AD8B2C5310DD91/StartUI.pdb source: explorer.exe, 0000000A.00000003.2338063758.000000000F533000.00000004.00000020.00020000.00000000.sdmp, explorer.exe, 0000000A.00000003.2338182098.000000000F589000.00000004.00000020.00020000.00000000.sdmp, explorer.exe, 0000000A.00000003.2336219974.000000000F52D000.00000004.00000020.00020000.00000000.sdmp |
Source: | Binary string: D:\a\ExplorerPatcher\ExplorerPatcher\build\Release\x64\ep_weather_host_stub.pdb source: SecuriteInfo.com.Trojan.Win64.Meterpreter.11595.2675.exe, 00000000.00000003.1754219678.000001B92F950000.00000004.00000020.00020000.00000000.sdmp, SecuriteInfo.com.Trojan.Win64.Meterpreter.11595.2675.exe, 00000000.00000003.1754289039.000001B92F96A000.00000004.00000020.00020000.00000000.sdmp |
Source: | Binary string: C:\Users\user\AppData\Roaming\ExplorerPatcher\twinui.pcshell.pdbi source: explorer.exe, 0000000A.00000003.2032672748.000000000BA85000.00000004.00000020.00020000.00000000.sdmp, explorer.exe, 0000000A.00000003.2044927276.000000000BA85000.00000004.00000020.00020000.00000000.sdmp, explorer.exe, 0000000A.00000003.2040664141.000000000BA85000.00000004.00000020.00020000.00000000.sdmp |
Source: | Binary string: \??\C:\Users\user\AppData\Roaming\ExplorerPatcher\twinui.pcshell.pdb0V source: explorer.exe, 0000000A.00000003.1901047401.000000000BD40000.00000004.00000020.00020000.00000000.sdmp |
Source: | Binary string: StartUI.pdb source: explorer.exe, 00000009.00000003.1772607654.0000000002EE1000.00000004.00000020.00020000.00000000.sdmp, explorer.exe, 0000000A.00000003.2045484810.00000000103C4000.00000004.00000020.00020000.00000000.sdmp |
Source: | Binary string: sshttp://msdl.microsoft.com/download/symbols/twinui.pcshell.pdb/56A53B20B8D4F79E69038072C21547311/twinui.pcshell.pdb source: explorer.exe, 0000000A.00000003.2032672748.000000000B946000.00000004.00000020.00020000.00000000.sdmp |
Source: | Binary string: /download/symbols/twinui.pcshell.pdb/56A53B20B8D4F79E69038072C21547311/twinui.pcshell.pdbLXy source: explorer.exe, 0000000A.00000003.2038461778.000000000B9C5000.00000004.00000020.00020000.00000000.sdmp, explorer.exe, 0000000A.00000003.1928410983.000000000B9C5000.00000004.00000020.00020000.00000000.sdmp, explorer.exe, 0000000A.00000003.1912234304.000000000BA34000.00000004.00000020.00020000.00000000.sdmp, explorer.exe, 0000000A.00000003.2032672748.000000000B9C5000.00000004.00000020.00020000.00000000.sdmp |
Source: | Binary string: D:\a\ExplorerPatcher\ExplorerPatcher\build\Release\x64\ep_gui.pdb source: SecuriteInfo.com.Trojan.Win64.Meterpreter.11595.2675.exe, 00000000.00000003.1753512064.000001B932081000.00000004.00000020.00020000.00000000.sdmp |
Source: | Binary string: http://msdl.microsoft.com/download/symbols/twinui.pcshell.pdb/56A53B20B8D4F79E69038072C21547311/twinui.pcshell.pdb source: explorer.exe, 0000000A.00000003.2034843476.000000000B8F3000.00000004.00000020.00020000.00000000.sdmp |
Source: | Binary string: GET /download/symbols/twinui.pcshell.pdb/56A53B20B8D4F79E69038072C21547311/twinui.pcshell.pdb HTTP/1.1 source: explorer.exe, 0000000A.00000003.1884335541.000000000B909000.00000004.00000020.00020000.00000000.sdmp, explorer.exe, 0000000A.00000003.1876558912.000000000B909000.00000004.00000020.00020000.00000000.sdmp |
Source: | Binary string: twinui.pcshell.pdbUGP source: explorer.exe, 00000009.00000003.1773648082.0000000002EE4000.00000004.00000020.00020000.00000000.sdmp, explorer.exe, 00000009.00000003.1771490317.0000000002EEE000.00000004.00000020.00020000.00000000.sdmp, explorer.exe, 0000000A.00000003.1777857049.00000000027F7000.00000004.00000020.00020000.00000000.sdmp, explorer.exe, 0000000A.00000003.1849449600.000000000D44B000.00000004.00000020.00020000.00000000.sdmp |
Source: | Binary string: twinui.pcshell.pdb source: explorer.exe, 00000009.00000003.1773648082.0000000002EE4000.00000004.00000020.00020000.00000000.sdmp, explorer.exe, 00000009.00000003.1771490317.0000000002EEE000.00000004.00000020.00020000.00000000.sdmp, explorer.exe, 0000000A.00000003.1777857049.00000000027F7000.00000004.00000020.00020000.00000000.sdmp, explorer.exe, 0000000A.00000003.1849449600.000000000D44B000.00000004.00000020.00020000.00000000.sdmp |
Source: | Binary string: D:\a\ExplorerPatcher\ExplorerPatcher\build\Release\x64\ExplorerPatcher.amd64.pdb source: SecuriteInfo.com.Trojan.Win64.Meterpreter.11595.2675.exe, 00000000.00000003.1753138409.000001B932081000.00000004.00000020.00020000.00000000.sdmp, explorer.exe, 00000009.00000002.1874656290.00007FFE1829D000.00000002.00000001.01000000.00000008.sdmp |
Source: | Binary string: D:\a\_work\e\src\out\Release_x64\WebView2Loader.dll.pdbOGP source: SecuriteInfo.com.Trojan.Win64.Meterpreter.11595.2675.exe, 00000000.00000003.1754494111.000001B92F950000.00000004.00000020.00020000.00000000.sdmp |
Source: | Binary string: Hostmsdl.microsoft.comGET /download/symbols/twinui.pcshell.pdb/56A53B20B8D4F79E69038072C21547311/twinui.pcshell.pdb HTTP/1.1/download/symbols/twinui.pcshell.pdb/56A53B20B8D4F79E69038072C21547311/twinui.pcshell.pdb source: explorer.exe, 0000000A.00000003.1884335541.000000000B909000.00000004.00000020.00020000.00000000.sdmp, explorer.exe, 0000000A.00000003.1876558912.000000000B909000.00000004.00000020.00020000.00000000.sdmp |
Source: | Binary string: C:\Users\user\AppData\Roaming\ExplorerPatcher\twinui.pcshell.pdb source: explorer.exe, 0000000A.00000003.2032672748.000000000BA85000.00000004.00000020.00020000.00000000.sdmp, explorer.exe, 0000000A.00000003.2044927276.000000000BA85000.00000004.00000020.00020000.00000000.sdmp, explorer.exe, 0000000A.00000003.2034843476.000000000B8F3000.00000004.00000020.00020000.00000000.sdmp, explorer.exe, 0000000A.00000003.2040664141.000000000BA85000.00000004.00000020.00020000.00000000.sdmp, explorer.exe, 0000000A.00000003.1912234304.000000000BA34000.00000004.00000020.00020000.00000000.sdmp, explorer.exe, 0000000A.00000003.1912557909.000000000BA84000.00000004.00000020.00020000.00000000.sdmp, explorer.exe, 0000000A.00000003.2040636400.000000000B905000.00000004.00000020.00020000.00000000.sdmp |
Source: | Binary string: D:\a\ExplorerPatcher\ExplorerPatcher\build\Release\x64\ep_dwm.pdb source: SecuriteInfo.com.Trojan.Win64.Meterpreter.11595.2675.exe, 00000000.00000003.1753761329.000001B92F950000.00000004.00000020.00020000.00000000.sdmp, SecuriteInfo.com.Trojan.Win64.Meterpreter.11595.2675.exe, 00000000.00000003.1753794147.000001B92F96C000.00000004.00000020.00020000.00000000.sdmp |
Source: | Binary string: symbols/StartUI.pdb/74D47198CB4699BA710AD82C5 source: explorer.exe, 0000000A.00000003.2338567821.000000000BD25000.00000004.00000020.00020000.00000000.sdmp |
Source: | Binary string: vC:\Users\user\AppData\Roaming\ExplorerPatcher\StartUI.pdb source: explorer.exe, 0000000A.00000003.2338774634.000000000BAFA000.00000004.00000020.00020000.00000000.sdmp |
Source: | Binary string: tUI.pdb source: explorer.exe, 0000000A.00000003.2338567821.000000000BD25000.00000004.00000020.00020000.00000000.sdmp |
Source: | Binary string: D:\a\ExplorerPatcher\ExplorerPatcher\build\Release\Win32\ExplorerPatcher.IA-32.pdb source: SecuriteInfo.com.Trojan.Win64.Meterpreter.11595.2675.exe, 00000000.00000003.1752836203.000001B92F950000.00000004.00000020.00020000.00000000.sdmp, SecuriteInfo.com.Trojan.Win64.Meterpreter.11595.2675.exe, 00000000.00000003.1752863673.000001B92F975000.00000004.00000020.00020000.00000000.sdmp |
Source: | Binary string: D:\a\ExplorerPatcher\ExplorerPatcher\build\Release\x64\ep_setup.pdb source: SecuriteInfo.com.Trojan.Win64.Meterpreter.11595.2675.exe, 00000000.00000000.1727366409.00007FF733126000.00000002.00000001.01000000.00000003.sdmp, SecuriteInfo.com.Trojan.Win64.Meterpreter.11595.2675.exe, 00000000.00000002.1773069236.00007FF733126000.00000002.00000001.01000000.00000003.sdmp |
Source: | Binary string: D:\a\ExplorerPatcher\ExplorerPatcher\build\Release\x64\ep_weather_host.pdb source: SecuriteInfo.com.Trojan.Win64.Meterpreter.11595.2675.exe, 00000000.00000003.1754054332.000001B92F950000.00000004.00000020.00020000.00000000.sdmp, SecuriteInfo.com.Trojan.Win64.Meterpreter.11595.2675.exe, 00000000.00000003.1754001005.000001B932081000.00000004.00000020.00020000.00000000.sdmp |
Source: | Binary string: StartUI.pdbH source: explorer.exe, 00000009.00000003.1772607654.0000000002EE1000.00000004.00000020.00020000.00000000.sdmp, explorer.exe, 0000000A.00000003.2045484810.00000000103C4000.00000004.00000020.00020000.00000000.sdmp |
Source: | Binary string: /download/symbols/StartUI.pdb/74D47198CB4699BA710AD8B2C5310DD91/StartUI.pdb source: explorer.exe, 0000000A.00000003.2338567821.000000000BD25000.00000004.00000020.00020000.00000000.sdmp |
Source: | Binary string: 2C21547311/twinui.pcshell.pdb HTTP/1.1 source: explorer.exe, 0000000A.00000003.1912234304.000000000BAA9000.00000004.00000020.00020000.00000000.sdmp, explorer.exe, 0000000A.00000003.1863754048.000000000BAA9000.00000004.00000020.00020000.00000000.sdmp, explorer.exe, 0000000A.00000003.2040664141.000000000BAA9000.00000004.00000020.00020000.00000000.sdmp, explorer.exe, 0000000A.00000003.2044927276.000000000BAA9000.00000004.00000020.00020000.00000000.sdmp |
Source: SecuriteInfo.com.Trojan.Win64.Meterpreter.11595.2675.exe, 00000000.00000002.1773069236.00007FF733126000.00000002.00000001.01000000.00000003.sdmp | String found in binary or memory: http://www.winimage.com/zLibDll |
Source: SecuriteInfo.com.Trojan.Win64.Meterpreter.11595.2675.exe, 00000000.00000003.1753138409.000001B932081000.00000004.00000020.00020000.00000000.sdmp, explorer.exe, explorer.exe, 00000009.00000002.1874656290.00007FFE1829D000.00000002.00000001.01000000.00000008.sdmp | String found in binary or memory: https://api.github.com/repos/valinet/ExplorerPatcher/releases?per_page=1 |
Source: explorer.exe, 00000009.00000003.1773648082.0000000002EE4000.00000004.00000020.00020000.00000000.sdmp, explorer.exe, 00000009.00000003.1771490317.0000000002EEE000.00000004.00000020.00020000.00000000.sdmp, explorer.exe, 0000000A.00000003.1777857049.00000000027F7000.00000004.00000020.00020000.00000000.sdmp, explorer.exe, 0000000A.00000003.1849449600.000000000D44B000.00000004.00000020.00020000.00000000.sdmp | String found in binary or memory: https://api.msn.com/v1/News/Feed/Windows?%08x%04x%04x%02x%02x%02x%02x%02x%02x%02x%02xFeedsCNhttps:// |
Source: SecuriteInfo.com.Trojan.Win64.Meterpreter.11595.2675.exe, 00000000.00000003.1753512064.000001B932081000.00000004.00000020.00020000.00000000.sdmp | String found in binary or memory: https://github.com/valinet |
Source: SecuriteInfo.com.Trojan.Win64.Meterpreter.11595.2675.exe, 00000000.00000003.1753512064.000001B932081000.00000004.00000020.00020000.00000000.sdmp | String found in binary or memory: https://github.com/valinet) |
Source: SecuriteInfo.com.Trojan.Win64.Meterpreter.11595.2675.exe, 00000000.00000003.1753512064.000001B932081000.00000004.00000020.00020000.00000000.sdmp | String found in binary or memory: https://github.com/valinet/ExplorerPatcher#donate |
Source: SecuriteInfo.com.Trojan.Win64.Meterpreter.11595.2675.exe, 00000000.00000003.1753512064.000001B932081000.00000004.00000020.00020000.00000000.sdmp | String found in binary or memory: https://github.com/valinet/ExplorerPatcher/blob/master/CHANGELOG.md |
Source: explorer.exe | String found in binary or memory: https://github.com/valinet/ExplorerPatcher/discussions |
Source: explorer.exe | String found in binary or memory: https://github.com/valinet/ExplorerPatcher/discussions/1102 |
Source: SecuriteInfo.com.Trojan.Win64.Meterpreter.11595.2675.exe, 00000000.00000003.1753512064.000001B932081000.00000004.00000020.00020000.00000000.sdmp | String found in binary or memory: https://github.com/valinet/ExplorerPatcher/discussions/1679 |
Source: explorer.exe | String found in binary or memory: https://github.com/valinet/ExplorerPatcher/issues |
Source: SecuriteInfo.com.Trojan.Win64.Meterpreter.11595.2675.exe, 00000000.00000003.1753138409.000001B932081000.00000004.00000020.00020000.00000000.sdmp, explorer.exe, 00000009.00000002.1874656290.00007FFE1829D000.00000002.00000001.01000000.00000008.sdmp | String found in binary or memory: https://github.com/valinet/ExplorerPatcher/issueshttps://github.com/valinet/ExplorerPatcher/discussi |
Source: explorer.exe | String found in binary or memory: https://github.com/valinet/ExplorerPatcher/releases |
Source: SecuriteInfo.com.Trojan.Win64.Meterpreter.11595.2675.exe, 00000000.00000003.1753138409.000001B932081000.00000004.00000020.00020000.00000000.sdmp, explorer.exe, explorer.exe, 00000009.00000002.1874656290.00007FFE1829D000.00000002.00000001.01000000.00000008.sdmp | String found in binary or memory: https://github.com/valinet/ExplorerPatcher/releases/latest |
Source: SecuriteInfo.com.Trojan.Win64.Meterpreter.11595.2675.exe, 00000000.00000003.1753512064.000001B932081000.00000004.00000020.00020000.00000000.sdmp | String found in binary or memory: https://github.com/valinet/ExplorerPatcher/wiki/About-advanced-settings |
Source: SecuriteInfo.com.Trojan.Win64.Meterpreter.11595.2675.exe, 00000000.00000003.1753512064.000001B932081000.00000004.00000020.00020000.00000000.sdmp | String found in binary or memory: https://github.com/valinet/ExplorerPatcher/wiki/Configure-updates |
Source: SecuriteInfo.com.Trojan.Win64.Meterpreter.11595.2675.exe, 00000000.00000003.1753512064.000001B932081000.00000004.00000020.00020000.00000000.sdmp | String found in binary or memory: https://github.com/valinet/ExplorerPatcher/wiki/ExplorerPatcher |
Source: SecuriteInfo.com.Trojan.Win64.Meterpreter.11595.2675.exe, 00000000.00000003.1753512064.000001B932081000.00000004.00000020.00020000.00000000.sdmp | String found in binary or memory: https://github.com/valinet/ExplorerPatcher/wiki/Frequently-asked-questions |
Source: SecuriteInfo.com.Trojan.Win64.Meterpreter.11595.2675.exe, 00000000.00000003.1753512064.000001B932081000.00000004.00000020.00020000.00000000.sdmp | String found in binary or memory: https://github.com/valinet/ExplorerPatcher/wiki/Settings-management |
Source: SecuriteInfo.com.Trojan.Win64.Meterpreter.11595.2675.exe, 00000000.00000003.1753512064.000001B932081000.00000004.00000020.00020000.00000000.sdmp | String found in binary or memory: https://github.com/valinet/ExplorerPatcher/wiki/Simple-Window-Switcher |
Source: explorer.exe, explorer.exe, 00000009.00000002.1874656290.00007FFE1829D000.00000002.00000001.01000000.00000008.sdmp | String found in binary or memory: https://github.com/valinet/ExplorerPatcher/wiki/Symbols |
Source: SecuriteInfo.com.Trojan.Win64.Meterpreter.11595.2675.exe, 00000000.00000003.1753138409.000001B932081000.00000004.00000020.00020000.00000000.sdmp, explorer.exe, 00000009.00000002.1874656290.00007FFE1829D000.00000002.00000001.01000000.00000008.sdmp | String found in binary or memory: https://github.com/valinet/ExplorerPatcher/wiki/SymbolsMicrosoft.Windows.Explorer |
Source: SecuriteInfo.com.Trojan.Win64.Meterpreter.11595.2675.exe, 00000000.00000003.1753512064.000001B932081000.00000004.00000020.00020000.00000000.sdmp | String found in binary or memory: https://github.com/valinet/ExplorerPatcher/wiki/Using-ExplorerPatcher-as-shell-extension |
Source: SecuriteInfo.com.Trojan.Win64.Meterpreter.11595.2675.exe, 00000000.00000003.1753512064.000001B932081000.00000004.00000020.00020000.00000000.sdmp | String found in binary or memory: https://github.com/valinet/ExplorerPatcher/wiki/Weather |
Source: explorer.exe, 00000009.00000003.1772607654.0000000002EE1000.00000004.00000020.00020000.00000000.sdmp, explorer.exe, 0000000A.00000003.2045484810.00000000103C4000.00000004.00000020.00020000.00000000.sdmp | String found in binary or memory: https://msn.comError |
Source: explorer.exe, 0000000A.00000003.1912234304.000000000BAA9000.00000004.00000020.00020000.00000000.sdmp, explorer.exe, 0000000A.00000003.1863754048.000000000BAA9000.00000004.00000020.00020000.00000000.sdmp, explorer.exe, 0000000A.00000003.2040664141.000000000BAA9000.00000004.00000020.00020000.00000000.sdmp, explorer.exe, 0000000A.00000003.2044927276.000000000BAA9000.00000004.00000020.00020000.00000000.sdmp | String found in binary or memory: https://objects.githubusercontent.com/ |
Source: explorer.exe, 0000000A.00000003.1912557909.000000000BACA000.00000004.00000020.00020000.00000000.sdmp | String found in binary or memory: https://objects.githubusercontent.com/github-production-release-asset-2e65be/394318710/d0ea7754-53d3 |
Source: explorer.exe, 0000000A.00000003.1912234304.000000000BAA9000.00000004.00000020.00020000.00000000.sdmp, explorer.exe, 0000000A.00000003.1863754048.000000000BAA9000.00000004.00000020.00020000.00000000.sdmp, explorer.exe, 0000000A.00000003.2040664141.000000000BAA9000.00000004.00000020.00020000.00000000.sdmp, explorer.exe, 0000000A.00000003.2044927276.000000000BAA9000.00000004.00000020.00020000.00000000.sdmp | String found in binary or memory: https://objects.githubusercontent.com/s |
Source: SecuriteInfo.com.Trojan.Win64.Meterpreter.11595.2675.exe, 00000000.00000003.1753138409.000001B932081000.00000004.00000020.00020000.00000000.sdmp, explorer.exe, explorer.exe, 00000009.00000002.1874656290.00007FFE1829D000.00000002.00000001.01000000.00000008.sdmp | String found in binary or memory: https://raw.githubusercontent.com/valinet/ep_make/master/ep_make_safe.ps1 |
Source: SecuriteInfo.com.Trojan.Win64.Meterpreter.11595.2675.exe, 00000000.00000003.1754054332.000001B92F950000.00000004.00000020.00020000.00000000.sdmp | String found in binary or memory: https://user-images.githubusercontent.com/6503598/156949438-4e0c0e0d-67bc-4c76-b75e-e0ffcead3f48.png |
Source: SecuriteInfo.com.Trojan.Win64.Meterpreter.11595.2675.exe, 00000000.00000003.1754054332.000001B92F950000.00000004.00000020.00020000.00000000.sdmp | String found in binary or memory: https://user-images.githubusercontent.com/6503598/156949442-63f14d44-ec0e-40b2-aa1b-8e4a27ec10f5.png |
Source: SecuriteInfo.com.Trojan.Win64.Meterpreter.11595.2675.exe, 00000000.00000003.1754054332.000001B92F950000.00000004.00000020.00020000.00000000.sdmp | String found in binary or memory: https://user-images.githubusercontent.com/6503598/156949443-062a0fa9-88c1-4e07-b6b1-8e52ff64f4f3.png |
Source: SecuriteInfo.com.Trojan.Win64.Meterpreter.11595.2675.exe, 00000000.00000003.1754054332.000001B92F950000.00000004.00000020.00020000.00000000.sdmp | String found in binary or memory: https://user-images.githubusercontent.com/6503598/156949444-d3aea936-4c22-4f17-a201-02155396684d.png |
Source: SecuriteInfo.com.Trojan.Win64.Meterpreter.11595.2675.exe, 00000000.00000003.1754054332.000001B92F950000.00000004.00000020.00020000.00000000.sdmp | String found in binary or memory: https://user-images.githubusercontent.com/6503598/156949445-60d12efa-a21d-40e0-b9a8-1b7a84e58944.png |
Source: SecuriteInfo.com.Trojan.Win64.Meterpreter.11595.2675.exe, 00000000.00000003.1754054332.000001B92F950000.00000004.00000020.00020000.00000000.sdmp | String found in binary or memory: https://user-images.githubusercontent.com/6503598/156949447-a6658710-567e-4977-9316-a80007df3076.png |
Source: SecuriteInfo.com.Trojan.Win64.Meterpreter.11595.2675.exe, 00000000.00000003.1754054332.000001B92F950000.00000004.00000020.00020000.00000000.sdmp | String found in binary or memory: https://user-images.githubusercontent.com/6503598/156949448-cd1b69af-4028-4153-8e40-288526577b58.png |
Source: SecuriteInfo.com.Trojan.Win64.Meterpreter.11595.2675.exe, 00000000.00000003.1754054332.000001B92F950000.00000004.00000020.00020000.00000000.sdmp | String found in binary or memory: https://user-images.githubusercontent.com/6503598/156949449-9320c6f5-15ef-4c17-9e72-740708f4828c.png |
Source: SecuriteInfo.com.Trojan.Win64.Meterpreter.11595.2675.exe, 00000000.00000003.1754054332.000001B92F950000.00000004.00000020.00020000.00000000.sdmp | String found in binary or memory: https://user-images.githubusercontent.com/6503598/156949450-7e03a3f5-580e-4414-aaeb-3a0898afd1da.png |
Source: SecuriteInfo.com.Trojan.Win64.Meterpreter.11595.2675.exe, 00000000.00000003.1754054332.000001B92F950000.00000004.00000020.00020000.00000000.sdmp | String found in binary or memory: https://user-images.githubusercontent.com/6503598/156949451-269d02a3-08cb-4237-9789-f1e60fdc723d.png |
Source: SecuriteInfo.com.Trojan.Win64.Meterpreter.11595.2675.exe, 00000000.00000003.1754054332.000001B92F950000.00000004.00000020.00020000.00000000.sdmp | String found in binary or memory: https://user-images.githubusercontent.com/6503598/156949452-f347fe27-5005-48f2-9c9a-899bb7b8825e.png |
Source: SecuriteInfo.com.Trojan.Win64.Meterpreter.11595.2675.exe, 00000000.00000003.1754054332.000001B92F950000.00000004.00000020.00020000.00000000.sdmp | String found in binary or memory: https://user-images.githubusercontent.com/6503598/156949454-81d5d47d-1f33-4859-a112-5a64ceb549a1.png |
Source: SecuriteInfo.com.Trojan.Win64.Meterpreter.11595.2675.exe, 00000000.00000003.1754054332.000001B92F950000.00000004.00000020.00020000.00000000.sdmp | String found in binary or memory: https://user-images.githubusercontent.com/6503598/156949456-04a4bdbd-ff3b-4484-bb30-8909baff8aa8.png |
Source: SecuriteInfo.com.Trojan.Win64.Meterpreter.11595.2675.exe, 00000000.00000003.1754054332.000001B92F950000.00000004.00000020.00020000.00000000.sdmp | String found in binary or memory: https://user-images.githubusercontent.com/6503598/156949458-dc66775d-8bb9-4d04-838e-7f550d305c26.png |
Source: SecuriteInfo.com.Trojan.Win64.Meterpreter.11595.2675.exe, 00000000.00000003.1754054332.000001B92F950000.00000004.00000020.00020000.00000000.sdmp | String found in binary or memory: https://user-images.githubusercontent.com/6503598/156949459-dfe70eba-6c2c-4b1c-b51b-27c13ce7c08c.png |
Source: SecuriteInfo.com.Trojan.Win64.Meterpreter.11595.2675.exe, 00000000.00000003.1754054332.000001B92F950000.00000004.00000020.00020000.00000000.sdmp | String found in binary or memory: https://user-images.githubusercontent.com/6503598/156949460-7c132d89-efb7-457f-8810-9bf235f5737f.png |
Source: SecuriteInfo.com.Trojan.Win64.Meterpreter.11595.2675.exe, 00000000.00000003.1754054332.000001B92F950000.00000004.00000020.00020000.00000000.sdmp | String found in binary or memory: https://user-images.githubusercontent.com/6503598/156949461-1f058cf3-6fdd-4aeb-80b7-68fa27b02845.png |
Source: SecuriteInfo.com.Trojan.Win64.Meterpreter.11595.2675.exe, 00000000.00000003.1754054332.000001B92F950000.00000004.00000020.00020000.00000000.sdmp | String found in binary or memory: https://user-images.githubusercontent.com/6503598/156949462-f50c21dd-85dd-4d9c-a4eb-516e6cddfb1f.png |
Source: SecuriteInfo.com.Trojan.Win64.Meterpreter.11595.2675.exe, 00000000.00000003.1754054332.000001B92F950000.00000004.00000020.00020000.00000000.sdmp | String found in binary or memory: https://user-images.githubusercontent.com/6503598/156949463-a427edfb-3d7f-4167-bd6f-f5019c482ea1.png |
Source: SecuriteInfo.com.Trojan.Win64.Meterpreter.11595.2675.exe, 00000000.00000003.1754054332.000001B92F950000.00000004.00000020.00020000.00000000.sdmp | String found in binary or memory: https://user-images.githubusercontent.com/6503598/156949465-54dd31c6-7e3a-464a-8e64-8b54b6fb7a65.png |
Source: SecuriteInfo.com.Trojan.Win64.Meterpreter.11595.2675.exe, 00000000.00000003.1754054332.000001B92F950000.00000004.00000020.00020000.00000000.sdmp | String found in binary or memory: https://user-images.githubusercontent.com/6503598/156950233-ccaadb4a-2e9a-4934-b41c-acd36a7f0d9c.png |
Source: explorer.exe, 0000000A.00000003.2032672748.000000000B9C5000.00000004.00000020.00020000.00000000.sdmp, explorer.exe, 0000000A.00000003.1928410983.000000000B950000.00000004.00000020.00020000.00000000.sdmp | String found in binary or memory: https://vsblobprodscussu5shard39.blob.core.windows.net/b-4712e0edc5a240eabf23330d7df68e77/39B7A82995 |
Source: explorer.exe, 0000000A.00000003.2336219974.000000000F4BD000.00000004.00000020.00020000.00000000.sdmp, explorer.exe, 0000000A.00000003.2336219974.000000000F52D000.00000004.00000020.00020000.00000000.sdmp | String found in binary or memory: https://vsblobprodscussu5shard6.blob.core.windows.net/b-4712e0edc5a240eabf23330d7df68e77/C0866EA3E54 |
Source: SecuriteInfo.com.Trojan.Win64.Meterpreter.11595.2675.exe, 00000000.00000003.1754054332.000001B92F950000.00000004.00000020.00020000.00000000.sdmp, SecuriteInfo.com.Trojan.Win64.Meterpreter.11595.2675.exe, 00000000.00000003.1754001005.000001B932081000.00000004.00000020.00020000.00000000.sdmp | String found in binary or memory: https://www.google.com/search?hl=%s&q=weather%s%s%s%s%s%s%s%spCoreWebView2ExecuteScriptCompletedHand |
Source: SecuriteInfo.com.Trojan.Win64.Meterpreter.11595.2675.exe, 00000000.00000003.1753512064.000001B932081000.00000004.00000020.00020000.00000000.sdmp | String found in binary or memory: https://www.valinet.ro |
Source: SecuriteInfo.com.Trojan.Win64.Meterpreter.11595.2675.exe, 00000000.00000003.1753512064.000001B932081000.00000004.00000020.00020000.00000000.sdmp | String found in binary or memory: https://www.valinet.ro) |
Source: C:\Windows\explorer.exe | Code function: 9_2_00007FFE18251870 | 9_2_00007FFE18251870 |
Source: C:\Windows\explorer.exe | Code function: 9_2_00007FFE18246900 | 9_2_00007FFE18246900 |
Source: C:\Windows\explorer.exe | Code function: 9_2_00007FFE18246B70 | 9_2_00007FFE18246B70 |
Source: C:\Windows\explorer.exe | Code function: 9_2_00007FFE1824DB90 | 9_2_00007FFE1824DB90 |
Source: C:\Windows\explorer.exe | Code function: 9_2_00007FFE18265CF0 | 9_2_00007FFE18265CF0 |
Source: C:\Windows\explorer.exe | Code function: 9_2_00007FFE1826FE80 | 9_2_00007FFE1826FE80 |
Source: C:\Windows\explorer.exe | Code function: 9_2_00007FFE1826F250 | 9_2_00007FFE1826F250 |
Source: C:\Windows\explorer.exe | Code function: 9_2_00007FFE1825A350 | 9_2_00007FFE1825A350 |
Source: C:\Windows\explorer.exe | Code function: 9_2_00007FFE1823E500 | 9_2_00007FFE1823E500 |
Source: C:\Windows\explorer.exe | Code function: 9_2_00007FFE18265620 | 9_2_00007FFE18265620 |
Source: C:\Windows\explorer.exe | Code function: 9_2_00007FFE18248800 | 9_2_00007FFE18248800 |
Source: C:\Windows\explorer.exe | Code function: 9_2_00007FFE18243880 | 9_2_00007FFE18243880 |
Source: C:\Windows\explorer.exe | Code function: 9_2_00007FFE182848D0 | 9_2_00007FFE182848D0 |
Source: C:\Windows\explorer.exe | Code function: 9_2_00007FFE18282908 | 9_2_00007FFE18282908 |
Source: C:\Windows\explorer.exe | Code function: 9_2_00007FFE18280A18 | 9_2_00007FFE18280A18 |
Source: C:\Windows\explorer.exe | Code function: 9_2_00007FFE18264A00 | 9_2_00007FFE18264A00 |
Source: C:\Windows\explorer.exe | Code function: 9_2_00007FFE18295A00 | 9_2_00007FFE18295A00 |
Source: C:\Windows\explorer.exe | Code function: 9_2_00007FFE18270A50 | 9_2_00007FFE18270A50 |
Source: C:\Windows\explorer.exe | Code function: 9_2_00007FFE18268A50 | 9_2_00007FFE18268A50 |
Source: C:\Windows\explorer.exe | Code function: 9_2_00007FFE18239AA0 | 9_2_00007FFE18239AA0 |
Source: C:\Windows\explorer.exe | Code function: 9_2_00007FFE1828EA90 | 9_2_00007FFE1828EA90 |
Source: C:\Windows\explorer.exe | Code function: 9_2_00007FFE1823CAC0 | 9_2_00007FFE1823CAC0 |
Source: C:\Windows\explorer.exe | Code function: 9_2_00007FFE18231B20 | 9_2_00007FFE18231B20 |
Source: C:\Windows\explorer.exe | Code function: 9_2_00007FFE18237B50 | 9_2_00007FFE18237B50 |
Source: C:\Windows\explorer.exe | Code function: 9_2_00007FFE18293B58 | 9_2_00007FFE18293B58 |
Source: C:\Windows\explorer.exe | Code function: 9_2_00007FFE18245B40 | 9_2_00007FFE18245B40 |
Source: C:\Windows\explorer.exe | Code function: 9_2_00007FFE1823FBE0 | 9_2_00007FFE1823FBE0 |
Source: C:\Windows\explorer.exe | Code function: 9_2_00007FFE18280C24 | 9_2_00007FFE18280C24 |
Source: C:\Windows\explorer.exe | Code function: 9_2_00007FFE18242C20 | 9_2_00007FFE18242C20 |
Source: C:\Windows\explorer.exe | Code function: 9_2_00007FFE18299CA8 | 9_2_00007FFE18299CA8 |
Source: C:\Windows\explorer.exe | Code function: 9_2_00007FFE1827ECF0 | 9_2_00007FFE1827ECF0 |
Source: C:\Windows\explorer.exe | Code function: 9_2_00007FFE18250D10 | 9_2_00007FFE18250D10 |
Source: C:\Windows\explorer.exe | Code function: 9_2_00007FFE1828CDBC | 9_2_00007FFE1828CDBC |
Source: C:\Windows\explorer.exe | Code function: 9_2_00007FFE18284D94 | 9_2_00007FFE18284D94 |
Source: C:\Windows\explorer.exe | Code function: 9_2_00007FFE1827EDFC | 9_2_00007FFE1827EDFC |
Source: C:\Windows\explorer.exe | Code function: 9_2_00007FFE1828AE7C | 9_2_00007FFE1828AE7C |
Source: C:\Windows\explorer.exe | Code function: 9_2_00007FFE18280E58 | 9_2_00007FFE18280E58 |
Source: C:\Windows\explorer.exe | Code function: 9_2_00007FFE18295E9C | 9_2_00007FFE18295E9C |
Source: C:\Windows\explorer.exe | Code function: 9_2_00007FFE18233EF0 | 9_2_00007FFE18233EF0 |
Source: C:\Windows\explorer.exe | Code function: 9_2_00007FFE1824CEC0 | 9_2_00007FFE1824CEC0 |
Source: C:\Windows\explorer.exe | Code function: 9_2_00007FFE18236F20 | 9_2_00007FFE18236F20 |
Source: C:\Windows\explorer.exe | Code function: 9_2_00007FFE1828EF24 | 9_2_00007FFE1828EF24 |
Source: C:\Windows\explorer.exe | Code function: 9_2_00007FFE1826BF10 | 9_2_00007FFE1826BF10 |
Source: C:\Windows\explorer.exe | Code function: 9_2_00007FFE18264F10 | 9_2_00007FFE18264F10 |
Source: C:\Windows\explorer.exe | Code function: 9_2_00007FFE1827EF08 | 9_2_00007FFE1827EF08 |
Source: C:\Windows\explorer.exe | Code function: 9_2_00007FFE18232F60 | 9_2_00007FFE18232F60 |
Source: C:\Windows\explorer.exe | Code function: 9_2_00007FFE1826DF40 | 9_2_00007FFE1826DF40 |
Source: C:\Windows\explorer.exe | Code function: 9_2_00007FFE18267FB0 | 9_2_00007FFE18267FB0 |
Source: C:\Windows\explorer.exe | Code function: 9_2_00007FFE1823BFA0 | 9_2_00007FFE1823BFA0 |
Source: C:\Windows\explorer.exe | Code function: 9_2_00007FFE1823EF90 | 9_2_00007FFE1823EF90 |
Source: C:\Windows\explorer.exe | Code function: 9_2_00007FFE18242FD0 | 9_2_00007FFE18242FD0 |
Source: C:\Windows\explorer.exe | Code function: 9_2_00007FFE1827F014 | 9_2_00007FFE1827F014 |
Source: C:\Windows\explorer.exe | Code function: 9_2_00007FFE18267010 | 9_2_00007FFE18267010 |
Source: C:\Windows\explorer.exe | Code function: 9_2_00007FFE18250070 | 9_2_00007FFE18250070 |
Source: C:\Windows\explorer.exe | Code function: 9_2_00007FFE1828105C | 9_2_00007FFE1828105C |
Source: C:\Windows\explorer.exe | Code function: 9_2_00007FFE18284094 | 9_2_00007FFE18284094 |
Source: C:\Windows\explorer.exe | Code function: 9_2_00007FFE182320D0 | 9_2_00007FFE182320D0 |
Source: C:\Windows\explorer.exe | Code function: 9_2_00007FFE1827F120 | 9_2_00007FFE1827F120 |
Source: C:\Windows\explorer.exe | Code function: 9_2_00007FFE1823E100 | 9_2_00007FFE1823E100 |
Source: C:\Windows\explorer.exe | Code function: 9_2_00007FFE1823B150 | 9_2_00007FFE1823B150 |
Source: C:\Windows\explorer.exe | Code function: 9_2_00007FFE182401B0 | 9_2_00007FFE182401B0 |
Source: C:\Windows\explorer.exe | Code function: 9_2_00007FFE1824D190 | 9_2_00007FFE1824D190 |
Source: C:\Windows\explorer.exe | Code function: 9_2_00007FFE182851F8 | 9_2_00007FFE182851F8 |
Source: C:\Windows\explorer.exe | Code function: 9_2_00007FFE182821EC | 9_2_00007FFE182821EC |
Source: C:\Windows\explorer.exe | Code function: 9_2_00007FFE182801D0 | 9_2_00007FFE182801D0 |
Source: C:\Windows\explorer.exe | Code function: 9_2_00007FFE1823E230 | 9_2_00007FFE1823E230 |
Source: C:\Windows\explorer.exe | Code function: 9_2_00007FFE1827F22C | 9_2_00007FFE1827F22C |
Source: C:\Windows\explorer.exe | Code function: 9_2_00007FFE1823C200 | 9_2_00007FFE1823C200 |
Source: C:\Windows\explorer.exe | Code function: 9_2_00007FFE18244270 | 9_2_00007FFE18244270 |
Source: C:\Windows\explorer.exe | Code function: 9_2_00007FFE18281268 | 9_2_00007FFE18281268 |
Source: C:\Windows\explorer.exe | Code function: 9_2_00007FFE182652A0 | 9_2_00007FFE182652A0 |
Source: C:\Windows\explorer.exe | Code function: 9_2_00007FFE1826E280 | 9_2_00007FFE1826E280 |
Source: C:\Windows\explorer.exe | Code function: 9_2_00007FFE182322F0 | 9_2_00007FFE182322F0 |
Source: C:\Windows\explorer.exe | Code function: 9_2_00007FFE1827F334 | 9_2_00007FFE1827F334 |
Source: C:\Windows\explorer.exe | Code function: 9_2_00007FFE18246350 | 9_2_00007FFE18246350 |
Source: C:\Windows\explorer.exe | Code function: 9_2_00007FFE18243350 | 9_2_00007FFE18243350 |
Source: C:\Windows\explorer.exe | Code function: 9_2_00007FFE18235380 | 9_2_00007FFE18235380 |
Source: C:\Windows\explorer.exe | Code function: 9_2_00007FFE182553F0 | 9_2_00007FFE182553F0 |
Source: C:\Windows\explorer.exe | Code function: 9_2_00007FFE182803D4 | 9_2_00007FFE182803D4 |
Source: C:\Windows\explorer.exe | Code function: 9_2_00007FFE182683C0 | 9_2_00007FFE182683C0 |
Source: C:\Windows\explorer.exe | Code function: 9_2_00007FFE1827F440 | 9_2_00007FFE1827F440 |
Source: C:\Windows\explorer.exe | Code function: 9_2_00007FFE1823A4E0 | 9_2_00007FFE1823A4E0 |
Source: C:\Windows\explorer.exe | Code function: 9_2_00007FFE182844CC | 9_2_00007FFE182844CC |
Source: C:\Windows\explorer.exe | Code function: 9_2_00007FFE1826E520 | 9_2_00007FFE1826E520 |
Source: C:\Windows\explorer.exe | Code function: 9_2_00007FFE1828B518 | 9_2_00007FFE1828B518 |
Source: C:\Windows\explorer.exe | Code function: 9_2_00007FFE1827F54C | 9_2_00007FFE1827F54C |
Source: C:\Windows\explorer.exe | Code function: 9_2_00007FFE182505A0 | 9_2_00007FFE182505A0 |
Source: C:\Windows\explorer.exe | Code function: 9_2_00007FFE1828F5A4 | 9_2_00007FFE1828F5A4 |
Source: C:\Windows\explorer.exe | Code function: 9_2_00007FFE18282584 | 9_2_00007FFE18282584 |
Source: C:\Windows\explorer.exe | Code function: 9_2_00007FFE182805E0 | 9_2_00007FFE182805E0 |
Source: C:\Windows\explorer.exe | Code function: 9_2_00007FFE18264650 | 9_2_00007FFE18264650 |
Source: C:\Windows\explorer.exe | Code function: 9_2_00007FFE1827F658 | 9_2_00007FFE1827F658 |
Source: C:\Windows\explorer.exe | Code function: 9_2_00007FFE18270750 | 9_2_00007FFE18270750 |
Source: C:\Windows\explorer.exe | Code function: 9_2_00007FFE18276740 | 9_2_00007FFE18276740 |
Source: C:\Windows\explorer.exe | Code function: 9_2_00007FFE1824C7A0 | 9_2_00007FFE1824C7A0 |
Source: C:\Windows\explorer.exe | Code function: 9_2_00007FFE1826E830 | 9_2_00007FFE1826E830 |
Source: C:\Windows\explorer.exe | Code function: 9_2_00007FFE18280814 | 9_2_00007FFE18280814 |
Source: C:\Windows\explorer.exe | Code function: 9_2_00007FFE1824F810 | 9_2_00007FFE1824F810 |
Source: C:\Users\user\Desktop\SecuriteInfo.com.Trojan.Win64.Meterpreter.11595.2675.exe | Section loaded: apphelp.dll | Jump to behavior |
Source: C:\Users\user\Desktop\SecuriteInfo.com.Trojan.Win64.Meterpreter.11595.2675.exe | Section loaded: rstrtmgr.dll | Jump to behavior |
Source: C:\Users\user\Desktop\SecuriteInfo.com.Trojan.Win64.Meterpreter.11595.2675.exe | Section loaded: version.dll | Jump to behavior |
Source: C:\Users\user\Desktop\SecuriteInfo.com.Trojan.Win64.Meterpreter.11595.2675.exe | Section loaded: ncrypt.dll | Jump to behavior |
Source: C:\Users\user\Desktop\SecuriteInfo.com.Trojan.Win64.Meterpreter.11595.2675.exe | Section loaded: ntasn1.dll | Jump to behavior |
Source: C:\Users\user\Desktop\SecuriteInfo.com.Trojan.Win64.Meterpreter.11595.2675.exe | Section loaded: windows.storage.dll | Jump to behavior |
Source: C:\Users\user\Desktop\SecuriteInfo.com.Trojan.Win64.Meterpreter.11595.2675.exe | Section loaded: wldp.dll | Jump to behavior |
Source: C:\Users\user\Desktop\SecuriteInfo.com.Trojan.Win64.Meterpreter.11595.2675.exe | Section loaded: kernel.appcore.dll | Jump to behavior |
Source: C:\Users\user\Desktop\SecuriteInfo.com.Trojan.Win64.Meterpreter.11595.2675.exe | Section loaded: uxtheme.dll | Jump to behavior |
Source: C:\Users\user\Desktop\SecuriteInfo.com.Trojan.Win64.Meterpreter.11595.2675.exe | Section loaded: propsys.dll | Jump to behavior |
Source: C:\Users\user\Desktop\SecuriteInfo.com.Trojan.Win64.Meterpreter.11595.2675.exe | Section loaded: profapi.dll | Jump to behavior |
Source: C:\Users\user\Desktop\SecuriteInfo.com.Trojan.Win64.Meterpreter.11595.2675.exe | Section loaded: edputil.dll | Jump to behavior |
Source: C:\Users\user\Desktop\SecuriteInfo.com.Trojan.Win64.Meterpreter.11595.2675.exe | Section loaded: urlmon.dll | Jump to behavior |
Source: C:\Users\user\Desktop\SecuriteInfo.com.Trojan.Win64.Meterpreter.11595.2675.exe | Section loaded: iertutil.dll | Jump to behavior |
Source: C:\Users\user\Desktop\SecuriteInfo.com.Trojan.Win64.Meterpreter.11595.2675.exe | Section loaded: srvcli.dll | Jump to behavior |
Source: C:\Users\user\Desktop\SecuriteInfo.com.Trojan.Win64.Meterpreter.11595.2675.exe | Section loaded: netutils.dll | Jump to behavior |
Source: C:\Users\user\Desktop\SecuriteInfo.com.Trojan.Win64.Meterpreter.11595.2675.exe | Section loaded: windows.staterepositoryps.dll | Jump to behavior |
Source: C:\Users\user\Desktop\SecuriteInfo.com.Trojan.Win64.Meterpreter.11595.2675.exe | Section loaded: sspicli.dll | Jump to behavior |
Source: C:\Users\user\Desktop\SecuriteInfo.com.Trojan.Win64.Meterpreter.11595.2675.exe | Section loaded: wintypes.dll | Jump to behavior |
Source: C:\Users\user\Desktop\SecuriteInfo.com.Trojan.Win64.Meterpreter.11595.2675.exe | Section loaded: appresolver.dll | Jump to behavior |
Source: C:\Users\user\Desktop\SecuriteInfo.com.Trojan.Win64.Meterpreter.11595.2675.exe | Section loaded: bcp47langs.dll | Jump to behavior |
Source: C:\Users\user\Desktop\SecuriteInfo.com.Trojan.Win64.Meterpreter.11595.2675.exe | Section loaded: slc.dll | Jump to behavior |
Source: C:\Users\user\Desktop\SecuriteInfo.com.Trojan.Win64.Meterpreter.11595.2675.exe | Section loaded: userenv.dll | Jump to behavior |
Source: C:\Users\user\Desktop\SecuriteInfo.com.Trojan.Win64.Meterpreter.11595.2675.exe | Section loaded: sppc.dll | Jump to behavior |
Source: C:\Users\user\Desktop\SecuriteInfo.com.Trojan.Win64.Meterpreter.11595.2675.exe | Section loaded: onecorecommonproxystub.dll | Jump to behavior |
Source: C:\Users\user\Desktop\SecuriteInfo.com.Trojan.Win64.Meterpreter.11595.2675.exe | Section loaded: onecoreuapcommonproxystub.dll | Jump to behavior |
Source: C:\Users\user\Desktop\SecuriteInfo.com.Trojan.Win64.Meterpreter.11595.2675.exe | Section loaded: pcacli.dll | Jump to behavior |
Source: C:\Users\user\Desktop\SecuriteInfo.com.Trojan.Win64.Meterpreter.11595.2675.exe | Section loaded: mpr.dll | Jump to behavior |
Source: C:\Users\user\Desktop\SecuriteInfo.com.Trojan.Win64.Meterpreter.11595.2675.exe | Section loaded: sfc_os.dll | Jump to behavior |
Source: C:\Users\user\Desktop\SecuriteInfo.com.Trojan.Win64.Meterpreter.11595.2675.exe | Section loaded: ntmarta.dll | Jump to behavior |
Source: C:\Users\user\Desktop\SecuriteInfo.com.Trojan.Win64.Meterpreter.11595.2675.exe | Section loaded: linkinfo.dll | Jump to behavior |
Source: C:\Users\user\Desktop\SecuriteInfo.com.Trojan.Win64.Meterpreter.11595.2675.exe | Section loaded: ntshrui.dll | Jump to behavior |
Source: C:\Users\user\Desktop\SecuriteInfo.com.Trojan.Win64.Meterpreter.11595.2675.exe | Section loaded: cscapi.dll | Jump to behavior |
Source: C:\Windows\System32\taskkill.exe | Section loaded: version.dll | Jump to behavior |
Source: C:\Windows\System32\taskkill.exe | Section loaded: mpr.dll | Jump to behavior |
Source: C:\Windows\System32\taskkill.exe | Section loaded: framedynos.dll | Jump to behavior |
Source: C:\Windows\System32\taskkill.exe | Section loaded: dbghelp.dll | Jump to behavior |
Source: C:\Windows\System32\taskkill.exe | Section loaded: sspicli.dll | Jump to behavior |
Source: C:\Windows\System32\taskkill.exe | Section loaded: srvcli.dll | Jump to behavior |
Source: C:\Windows\System32\taskkill.exe | Section loaded: netutils.dll | Jump to behavior |
Source: C:\Windows\System32\taskkill.exe | Section loaded: sspicli.dll | Jump to behavior |
Source: C:\Windows\System32\taskkill.exe | Section loaded: kernel.appcore.dll | Jump to behavior |
Source: C:\Windows\System32\taskkill.exe | Section loaded: wbemcomn.dll | Jump to behavior |
Source: C:\Windows\System32\taskkill.exe | Section loaded: winsta.dll | Jump to behavior |
Source: C:\Windows\System32\taskkill.exe | Section loaded: amsi.dll | Jump to behavior |
Source: C:\Windows\System32\taskkill.exe | Section loaded: userenv.dll | Jump to behavior |
Source: C:\Windows\System32\taskkill.exe | Section loaded: profapi.dll | Jump to behavior |
Source: C:\Windows\System32\regsvr32.exe | Section loaded: apphelp.dll | Jump to behavior |
Source: C:\Windows\System32\regsvr32.exe | Section loaded: aclayers.dll | Jump to behavior |
Source: C:\Windows\System32\regsvr32.exe | Section loaded: sfc.dll | Jump to behavior |
Source: C:\Windows\System32\regsvr32.exe | Section loaded: sfc_os.dll | Jump to behavior |
Source: C:\Windows\System32\regsvr32.exe | Section loaded: kernel.appcore.dll | Jump to behavior |
Source: C:\Windows\System32\regsvr32.exe | Section loaded: uxtheme.dll | Jump to behavior |
Source: C:\Windows\System32\regsvr32.exe | Section loaded: webview2loader.dll | Jump to behavior |
Source: C:\Windows\System32\regsvr32.exe | Section loaded: version.dll | Jump to behavior |
Source: C:\Windows\System32\regsvr32.exe | Section loaded: dwmapi.dll | Jump to behavior |
Source: C:\Windows\System32\regsvr32.exe | Section loaded: windows.storage.dll | Jump to behavior |
Source: C:\Windows\System32\regsvr32.exe | Section loaded: wldp.dll | Jump to behavior |
Source: C:\Windows\System32\regsvr32.exe | Section loaded: apphelp.dll | Jump to behavior |
Source: C:\Windows\System32\regsvr32.exe | Section loaded: aclayers.dll | Jump to behavior |
Source: C:\Windows\System32\regsvr32.exe | Section loaded: sfc.dll | Jump to behavior |
Source: C:\Windows\System32\regsvr32.exe | Section loaded: sfc_os.dll | Jump to behavior |
Source: C:\Windows\System32\regsvr32.exe | Section loaded: kernel.appcore.dll | Jump to behavior |
Source: C:\Windows\System32\regsvr32.exe | Section loaded: uxtheme.dll | Jump to behavior |
Source: C:\Windows\explorer.exe | Section loaded: aepic.dll | Jump to behavior |
Source: C:\Windows\explorer.exe | Section loaded: twinapi.dll | Jump to behavior |
Source: C:\Windows\explorer.exe | Section loaded: ntmarta.dll | Jump to behavior |
Source: C:\Windows\explorer.exe | Section loaded: userenv.dll | Jump to behavior |
Source: C:\Windows\explorer.exe | Section loaded: iphlpapi.dll | Jump to behavior |
Source: C:\Windows\explorer.exe | Section loaded: powrprof.dll | Jump to behavior |
Source: C:\Windows\explorer.exe | Section loaded: windows.storage.dll | Jump to behavior |
Source: C:\Windows\explorer.exe | Section loaded: dxgi.dll | Jump to behavior |
Source: C:\Windows\explorer.exe | Section loaded: windows.storage.dll | Jump to behavior |
Source: C:\Windows\explorer.exe | Section loaded: cryptsp.dll | Jump to behavior |
Source: C:\Windows\explorer.exe | Section loaded: kernel.appcore.dll | Jump to behavior |
Source: C:\Windows\explorer.exe | Section loaded: propsys.dll | Jump to behavior |
Source: C:\Windows\explorer.exe | Section loaded: coremessaging.dll | Jump to behavior |
Source: C:\Windows\explorer.exe | Section loaded: urlmon.dll | Jump to behavior |
Source: C:\Windows\explorer.exe | Section loaded: windows.storage.dll | Jump to behavior |
Source: C:\Windows\explorer.exe | Section loaded: windows.storage.dll | Jump to behavior |
Source: C:\Windows\explorer.exe | Section loaded: kernel.appcore.dll | Jump to behavior |
Source: C:\Windows\explorer.exe | Section loaded: wtsapi32.dll | Jump to behavior |
Source: C:\Windows\explorer.exe | Section loaded: wininet.dll | Jump to behavior |
Source: C:\Windows\explorer.exe | Section loaded: uxtheme.dll | Jump to behavior |
Source: C:\Windows\explorer.exe | Section loaded: dwmapi.dll | Jump to behavior |
Source: C:\Windows\explorer.exe | Section loaded: sspicli.dll | Jump to behavior |
Source: C:\Windows\explorer.exe | Section loaded: kernel.appcore.dll | Jump to behavior |
Source: C:\Windows\explorer.exe | Section loaded: twinapi.appcore.dll | Jump to behavior |
Source: C:\Windows\explorer.exe | Section loaded: wldp.dll | Jump to behavior |
Source: C:\Windows\explorer.exe | Section loaded: iertutil.dll | Jump to behavior |
Source: C:\Windows\explorer.exe | Section loaded: srvcli.dll | Jump to behavior |
Source: C:\Windows\explorer.exe | Section loaded: netutils.dll | Jump to behavior |
Source: C:\Windows\explorer.exe | Section loaded: dbghelp.dll | Jump to behavior |
Source: C:\Windows\explorer.exe | Section loaded: version.dll | Jump to behavior |
Source: C:\Windows\explorer.exe | Section loaded: rstrtmgr.dll | Jump to behavior |
Source: C:\Windows\explorer.exe | Section loaded: oleacc.dll | Jump to behavior |
Source: C:\Windows\explorer.exe | Section loaded: ncrypt.dll | Jump to behavior |
Source: C:\Windows\explorer.exe | Section loaded: umpdc.dll | Jump to behavior |
Source: C:\Windows\explorer.exe | Section loaded: ntasn1.dll | Jump to behavior |
Source: C:\Windows\explorer.exe | Section loaded: dxgi.dll | Jump to behavior |
Source: C:\Windows\explorer.exe | Section loaded: explorerframe.dll | Jump to behavior |
Source: C:\Windows\explorer.exe | Section loaded: windows.ui.fileexplorer.dll | Jump to behavior |
Source: C:\Windows\explorer.exe | Section loaded: rsaenh.dll | Jump to behavior |
Source: C:\Windows\explorer.exe | Section loaded: cryptbase.dll | Jump to behavior |
Source: C:\Windows\explorer.exe | Section loaded: twinui.pcshell.dll | Jump to behavior |
Source: C:\Windows\explorer.exe | Section loaded: wkscli.dll | Jump to behavior |
Source: C:\Windows\explorer.exe | Section loaded: dwrite.dll | Jump to behavior |
Source: C:\Windows\explorer.exe | Section loaded: dcomp.dll | Jump to behavior |
Source: C:\Windows\explorer.exe | Section loaded: wincorlib.dll | Jump to behavior |
Source: C:\Windows\explorer.exe | Section loaded: cdp.dll | Jump to behavior |
Source: C:\Windows\explorer.exe | Section loaded: dsreg.dll | Jump to behavior |
Source: C:\Windows\explorer.exe | Section loaded: msvcp110_win.dll | Jump to behavior |
Source: C:\Windows\explorer.exe | Section loaded: twinui.dll | Jump to behavior |
Source: C:\Windows\explorer.exe | Section loaded: wintypes.dll | Jump to behavior |
Source: C:\Windows\explorer.exe | Section loaded: pdh.dll | Jump to behavior |
Source: C:\Windows\explorer.exe | Section loaded: stobject.dll | Jump to behavior |
Source: C:\Windows\explorer.exe | Section loaded: wmiclnt.dll | Jump to behavior |
Source: C:\Windows\explorer.exe | Section loaded: devobj.dll | Jump to behavior |
Source: C:\Windows\explorer.exe | Section loaded: pnidui.dll | Jump to behavior |
Source: C:\Windows\explorer.exe | Section loaded: mobilenetworking.dll | Jump to behavior |
Source: C:\Windows\explorer.exe | Section loaded: sndvolsso.dll | Jump to behavior |
Source: C:\Windows\explorer.exe | Section loaded: mmdevapi.dll | Jump to behavior |
Source: C:\Windows\explorer.exe | Section loaded: peopleband.dll | Jump to behavior |
Source: C:\Windows\explorer.exe | Section loaded: d2d1.dll | Jump to behavior |
Source: C:\Windows\explorer.exe | Section loaded: d3d11.dll | Jump to behavior |
Source: C:\Windows\explorer.exe | Section loaded: ninput.dll | Jump to behavior |
Source: C:\Windows\explorer.exe | Section loaded: wpnapps.dll | Jump to behavior |
Source: C:\Windows\explorer.exe | Section loaded: rmclient.dll | Jump to behavior |
Source: C:\Windows\explorer.exe | Section loaded: xmllite.dll | Jump to behavior |
Source: C:\Windows\explorer.exe | Section loaded: taskschd.dll | Jump to behavior |
Source: C:\Windows\explorer.exe | Section loaded: aepic.dll | Jump to behavior |
Source: C:\Windows\explorer.exe | Section loaded: twinapi.dll | Jump to behavior |
Source: C:\Windows\explorer.exe | Section loaded: userenv.dll | Jump to behavior |
Source: C:\Windows\explorer.exe | Section loaded: ntmarta.dll | Jump to behavior |
Source: C:\Windows\explorer.exe | Section loaded: cryptsp.dll | Jump to behavior |
Source: C:\Windows\explorer.exe | Section loaded: iphlpapi.dll | Jump to behavior |
Source: C:\Windows\explorer.exe | Section loaded: powrprof.dll | Jump to behavior |
Source: C:\Windows\explorer.exe | Section loaded: windows.storage.dll | Jump to behavior |
Source: C:\Windows\explorer.exe | Section loaded: dxgi.dll | Jump to behavior |
Source: C:\Windows\explorer.exe | Section loaded: windows.storage.dll | Jump to behavior |
Source: C:\Windows\explorer.exe | Section loaded: kernel.appcore.dll | Jump to behavior |
Source: C:\Windows\explorer.exe | Section loaded: propsys.dll | Jump to behavior |
Source: C:\Windows\explorer.exe | Section loaded: coremessaging.dll | Jump to behavior |
Source: C:\Windows\explorer.exe | Section loaded: urlmon.dll | Jump to behavior |
Source: C:\Windows\explorer.exe | Section loaded: windows.storage.dll | Jump to behavior |
Source: C:\Windows\explorer.exe | Section loaded: windows.storage.dll | Jump to behavior |
Source: C:\Windows\explorer.exe | Section loaded: kernel.appcore.dll | Jump to behavior |
Source: C:\Windows\explorer.exe | Section loaded: wtsapi32.dll | Jump to behavior |
Source: C:\Windows\explorer.exe | Section loaded: wininet.dll | Jump to behavior |
Source: C:\Windows\explorer.exe | Section loaded: uxtheme.dll | Jump to behavior |
Source: C:\Windows\explorer.exe | Section loaded: dwmapi.dll | Jump to behavior |
Source: C:\Windows\explorer.exe | Section loaded: sspicli.dll | Jump to behavior |
Source: C:\Windows\explorer.exe | Section loaded: kernel.appcore.dll | Jump to behavior |
Source: C:\Windows\explorer.exe | Section loaded: twinapi.appcore.dll | Jump to behavior |
Source: C:\Windows\explorer.exe | Section loaded: wldp.dll | Jump to behavior |
Source: C:\Windows\explorer.exe | Section loaded: dbghelp.dll | Jump to behavior |
Source: C:\Windows\explorer.exe | Section loaded: uxtheme.dll | Jump to behavior |
Source: C:\Windows\explorer.exe | Section loaded: dwmapi.dll | Jump to behavior |
Source: C:\Windows\explorer.exe | Section loaded: iertutil.dll | Jump to behavior |
Source: C:\Windows\explorer.exe | Section loaded: srvcli.dll | Jump to behavior |
Source: C:\Windows\explorer.exe | Section loaded: netutils.dll | Jump to behavior |
Source: C:\Windows\explorer.exe | Section loaded: wininet.dll | Jump to behavior |
Source: C:\Windows\explorer.exe | Section loaded: version.dll | Jump to behavior |
Source: C:\Windows\explorer.exe | Section loaded: rstrtmgr.dll | Jump to behavior |
Source: C:\Windows\explorer.exe | Section loaded: oleacc.dll | Jump to behavior |
Source: C:\Windows\explorer.exe | Section loaded: ncrypt.dll | Jump to behavior |
Source: C:\Windows\explorer.exe | Section loaded: umpdc.dll | Jump to behavior |
Source: C:\Windows\explorer.exe | Section loaded: ntasn1.dll | Jump to behavior |
Source: C:\Windows\explorer.exe | Section loaded: dxgi.dll | Jump to behavior |
Source: C:\Windows\explorer.exe | Section loaded: explorerframe.dll | Jump to behavior |
Source: C:\Windows\explorer.exe | Section loaded: windows.ui.fileexplorer.dll | Jump to behavior |
Source: C:\Windows\explorer.exe | Section loaded: rsaenh.dll | Jump to behavior |
Source: C:\Windows\explorer.exe | Section loaded: cryptbase.dll | Jump to behavior |
Source: C:\Windows\explorer.exe | Section loaded: twinui.pcshell.dll | Jump to behavior |
Source: C:\Windows\explorer.exe | Section loaded: wkscli.dll | Jump to behavior |
Source: C:\Windows\explorer.exe | Section loaded: dwrite.dll | Jump to behavior |
Source: C:\Windows\explorer.exe | Section loaded: dcomp.dll | Jump to behavior |
Source: C:\Windows\explorer.exe | Section loaded: wincorlib.dll | Jump to behavior |
Source: C:\Windows\explorer.exe | Section loaded: cdp.dll | Jump to behavior |
Source: C:\Windows\explorer.exe | Section loaded: dsreg.dll | Jump to behavior |
Source: C:\Windows\explorer.exe | Section loaded: msvcp110_win.dll | Jump to behavior |
Source: C:\Windows\explorer.exe | Section loaded: twinui.dll | Jump to behavior |
Source: C:\Windows\explorer.exe | Section loaded: wintypes.dll | Jump to behavior |
Source: C:\Windows\explorer.exe | Section loaded: pdh.dll | Jump to behavior |
Source: C:\Windows\explorer.exe | Section loaded: stobject.dll | Jump to behavior |
Source: C:\Windows\explorer.exe | Section loaded: wmiclnt.dll | Jump to behavior |
Source: C:\Windows\explorer.exe | Section loaded: devobj.dll | Jump to behavior |
Source: C:\Windows\explorer.exe | Section loaded: pnidui.dll | Jump to behavior |
Source: C:\Windows\explorer.exe | Section loaded: mobilenetworking.dll | Jump to behavior |
Source: C:\Windows\explorer.exe | Section loaded: sndvolsso.dll | Jump to behavior |
Source: C:\Windows\explorer.exe | Section loaded: mmdevapi.dll | Jump to behavior |
Source: C:\Windows\explorer.exe | Section loaded: peopleband.dll | Jump to behavior |
Source: C:\Windows\explorer.exe | Section loaded: d2d1.dll | Jump to behavior |
Source: C:\Windows\explorer.exe | Section loaded: d3d11.dll | Jump to behavior |
Source: C:\Windows\explorer.exe | Section loaded: ninput.dll | Jump to behavior |
Source: C:\Windows\explorer.exe | Section loaded: wpnapps.dll | Jump to behavior |
Source: C:\Windows\explorer.exe | Section loaded: rmclient.dll | Jump to behavior |
Source: C:\Windows\explorer.exe | Section loaded: xmllite.dll | Jump to behavior |
Source: C:\Windows\explorer.exe | Section loaded: appresolver.dll | Jump to behavior |
Source: C:\Windows\explorer.exe | Section loaded: bcp47langs.dll | Jump to behavior |
Source: C:\Windows\explorer.exe | Section loaded: slc.dll | Jump to behavior |
Source: C:\Windows\explorer.exe | Section loaded: sppc.dll | Jump to behavior |
Source: C:\Windows\explorer.exe | Section loaded: profapi.dll | Jump to behavior |
Source: C:\Windows\explorer.exe | Section loaded: onecoreuapcommonproxystub.dll | Jump to behavior |
Source: C:\Windows\explorer.exe | Section loaded: starttiledata.dll | Jump to behavior |
Source: C:\Windows\explorer.exe | Section loaded: usermgrcli.dll | Jump to behavior |
Source: C:\Windows\explorer.exe | Section loaded: idstore.dll | Jump to behavior |
Source: C:\Windows\explorer.exe | Section loaded: windows.staterepositoryps.dll | Jump to behavior |
Source: C:\Windows\explorer.exe | Section loaded: wlidprov.dll | Jump to behavior |
Source: C:\Windows\explorer.exe | Section loaded: samcli.dll | Jump to behavior |
Source: C:\Windows\explorer.exe | Section loaded: policymanager.dll | Jump to behavior |
Source: C:\Windows\explorer.exe | Section loaded: windows.applicationmodel.dll | Jump to behavior |
Source: C:\Windows\explorer.exe | Section loaded: appxdeploymentclient.dll | Jump to behavior |
Source: C:\Windows\explorer.exe | Section loaded: usermgrproxy.dll | Jump to behavior |
Source: C:\Windows\explorer.exe | Section loaded: winsta.dll | Jump to behavior |
Source: C:\Windows\explorer.exe | Section loaded: textshaping.dll | Jump to behavior |
Source: C:\Windows\explorer.exe | Section loaded: windows.ui.dll | Jump to behavior |
Source: C:\Windows\explorer.exe | Section loaded: windowmanagementapi.dll | Jump to behavior |
Source: C:\Windows\explorer.exe | Section loaded: textinputframework.dll | Jump to behavior |
Source: C:\Windows\explorer.exe | Section loaded: inputhost.dll | Jump to behavior |
Source: C:\Windows\explorer.exe | Section loaded: coreuicomponents.dll | Jump to behavior |
Source: C:\Windows\explorer.exe | Section loaded: coreuicomponents.dll | Jump to behavior |
Source: C:\Windows\explorer.exe | Section loaded: windowscodecs.dll | Jump to behavior |
Source: C:\Windows\explorer.exe | Section loaded: resourcepolicyclient.dll | Jump to behavior |
Source: C:\Windows\explorer.exe | Section loaded: d3d10warp.dll | Jump to behavior |
Source: C:\Windows\explorer.exe | Section loaded: windows.staterepositoryclient.dll | Jump to behavior |
Source: C:\Windows\explorer.exe | Section loaded: dxcore.dll | Jump to behavior |
Source: C:\Windows\explorer.exe | Section loaded: windows.cloudstore.dll | Jump to behavior |
Source: C:\Windows\explorer.exe | Section loaded: appextension.dll | Jump to behavior |
Source: C:\Windows\explorer.exe | Section loaded: cldapi.dll | Jump to behavior |
Source: C:\Windows\explorer.exe | Section loaded: fltlib.dll | Jump to behavior |
Source: C:\Windows\explorer.exe | Section loaded: windows.cloudstore.schema.shell.dll | Jump to behavior |
Source: C:\Windows\explorer.exe | Section loaded: dataexchange.dll | Jump to behavior |
Source: C:\Windows\explorer.exe | Section loaded: apphelp.dll | Jump to behavior |
Source: C:\Windows\explorer.exe | Section loaded: tiledatarepository.dll | Jump to behavior |
Source: C:\Windows\explorer.exe | Section loaded: staterepository.core.dll | Jump to behavior |
Source: C:\Windows\explorer.exe | Section loaded: windows.staterepository.dll | Jump to behavior |
Source: C:\Windows\explorer.exe | Section loaded: windows.staterepositorycore.dll | Jump to behavior |
Source: C:\Windows\explorer.exe | Section loaded: mrmcorer.dll | Jump to behavior |
Source: C:\Windows\explorer.exe | Section loaded: languageoverlayutil.dll | Jump to behavior |
Source: C:\Windows\explorer.exe | Section loaded: bcp47mrm.dll | Jump to behavior |
Source: C:\Windows\explorer.exe | Section loaded: windows.immersiveshell.serviceprovider.dll | Jump to behavior |
Source: C:\Windows\explorer.exe | Section loaded: thumbcache.dll | Jump to behavior |
Source: C:\Windows\explorer.exe | Section loaded: edputil.dll | Jump to behavior |
Source: C:\Windows\explorer.exe | Section loaded: onecorecommonproxystub.dll | Jump to behavior |
Source: C:\Windows\explorer.exe | Section loaded: twinui.appcore.dll | Jump to behavior |
Source: C:\Windows\explorer.exe | Section loaded: applicationframe.dll | Jump to behavior |
Source: C:\Windows\explorer.exe | Section loaded: photometadatahandler.dll | Jump to behavior |
Source: C:\Windows\explorer.exe | Section loaded: ntshrui.dll | Jump to behavior |
Source: C:\Windows\explorer.exe | Section loaded: cscapi.dll | Jump to behavior |
Source: C:\Windows\explorer.exe | Section loaded: linkinfo.dll | Jump to behavior |
Source: C:\Windows\explorer.exe | Section loaded: secur32.dll | Jump to behavior |
Source: C:\Windows\explorer.exe | Section loaded: ehstorshell.dll | Jump to behavior |
Source: C:\Windows\explorer.exe | Section loaded: cscui.dll | Jump to behavior |
Source: C:\Windows\explorer.exe | Section loaded: provsvc.dll | Jump to behavior |
Source: C:\Windows\explorer.exe | Section loaded: holographicextensions.dll | Jump to behavior |
Source: C:\Windows\explorer.exe | Section loaded: virtualmonitormanager.dll | Jump to behavior |
Source: C:\Windows\explorer.exe | Section loaded: resourcepolicyclient.dll | Jump to behavior |
Source: C:\Windows\explorer.exe | Section loaded: windows.ui.immersive.dll | Jump to behavior |
Source: C:\Windows\explorer.exe | Section loaded: abovelockapphost.dll | Jump to behavior |
Source: C:\Windows\explorer.exe | Section loaded: npsm.dll | Jump to behavior |
Source: C:\Windows\explorer.exe | Section loaded: windows.web.dll | Jump to behavior |
Source: C:\Windows\explorer.exe | Section loaded: windows.shell.bluelightreduction.dll | Jump to behavior |
Source: C:\Windows\explorer.exe | Section loaded: windows.internal.signals.dll | Jump to behavior |
Source: C:\Windows\explorer.exe | Section loaded: tdh.dll | Jump to behavior |
Source: C:\Windows\explorer.exe | Section loaded: mscms.dll | Jump to behavior |
Source: C:\Windows\explorer.exe | Section loaded: coloradapterclient.dll | Jump to behavior |
Source: C:\Windows\explorer.exe | Section loaded: vcruntime140_1.dll | Jump to behavior |
Source: C:\Windows\explorer.exe | Section loaded: vcruntime140.dll | Jump to behavior |
Source: C:\Windows\explorer.exe | Section loaded: msvcp140.dll | Jump to behavior |
Source: C:\Windows\explorer.exe | Section loaded: vcruntime140.dll | Jump to behavior |
Source: C:\Windows\explorer.exe | Section loaded: windows.staterepositorybroker.dll | Jump to behavior |
Source: C:\Windows\explorer.exe | Section loaded: mfplat.dll | Jump to behavior |
Source: C:\Windows\explorer.exe | Section loaded: rtworkq.dll | Jump to behavior |
Source: C:\Windows\explorer.exe | Section loaded: taskflowdataengine.dll | Jump to behavior |
Source: C:\Windows\explorer.exe | Section loaded: structuredquery.dll | Jump to behavior |
Source: C:\Windows\explorer.exe | Section loaded: actxprxy.dll | Jump to behavior |
Source: C:\Windows\explorer.exe | Section loaded: windows.security.authentication.web.core.dll | Jump to behavior |
Source: C:\Windows\explorer.exe | Section loaded: windows.data.activities.dll | Jump to behavior |
Source: C:\Windows\explorer.exe | Section loaded: windows.internal.ui.shell.windowtabmanager.dll | Jump to behavior |
Source: C:\Windows\explorer.exe | Section loaded: windows.system.launcher.dll | Jump to behavior |
Source: C:\Windows\explorer.exe | Section loaded: windows.shell.servicehostbuilder.dll | Jump to behavior |
Source: C:\Windows\explorer.exe | Section loaded: notificationcontrollerps.dll | Jump to behavior |
Source: C:\Windows\explorer.exe | Section loaded: windows.devices.enumeration.dll | Jump to behavior |
Source: C:\Windows\explorer.exe | Section loaded: windows.globalization.dll | Jump to behavior |
Source: C:\Windows\explorer.exe | Section loaded: icu.dll | Jump to behavior |
Source: C:\Windows\explorer.exe | Section loaded: mswb7.dll | Jump to behavior |
Source: C:\Windows\explorer.exe | Section loaded: devdispitemprovider.dll | Jump to behavior |
Source: C:\Windows\explorer.exe | Section loaded: windows.networking.connectivity.dll | Jump to behavior |
Source: C:\Windows\explorer.exe | Section loaded: uianimation.dll | Jump to behavior |
Source: C:\Windows\explorer.exe | Section loaded: windows.ui.core.textinput.dll | Jump to behavior |
Source: C:\Windows\explorer.exe | Section loaded: windowsudk.shellcommon.dll | Jump to behavior |
Source: C:\Windows\explorer.exe | Section loaded: dictationmanager.dll | Jump to behavior |
Source: C:\Windows\explorer.exe | Section loaded: npmproxy.dll | Jump to behavior |
Source: C:\Windows\explorer.exe | Section loaded: ondemandconnroutehelper.dll | Jump to behavior |
Source: C:\Windows\explorer.exe | Section loaded: winhttp.dll | Jump to behavior |
Source: C:\Windows\explorer.exe | Section loaded: mswsock.dll | Jump to behavior |
Source: C:\Windows\explorer.exe | Section loaded: winnsi.dll | Jump to behavior |
Source: C:\Windows\explorer.exe | Section loaded: dpapi.dll | Jump to behavior |
Source: C:\Windows\explorer.exe | Section loaded: msasn1.dll | Jump to behavior |
Source: C:\Windows\explorer.exe | Section loaded: dnsapi.dll | Jump to behavior |
Source: C:\Windows\explorer.exe | Section loaded: rasadhlp.dll | Jump to behavior |
Source: C:\Windows\explorer.exe | Section loaded: fwpuclnt.dll | Jump to behavior |
Source: C:\Windows\explorer.exe | Section loaded: workfoldersshell.dll | Jump to behavior |
Source: C:\Windows\explorer.exe | Section loaded: windows.fileexplorer.common.dll | Jump to behavior |
Source: C:\Windows\explorer.exe | Section loaded: schannel.dll | Jump to behavior |
Source: C:\Windows\explorer.exe | Section loaded: taskschd.dll | Jump to behavior |
Source: C:\Windows\explorer.exe | Section loaded: mskeyprotect.dll | Jump to behavior |
Source: C:\Windows\explorer.exe | Section loaded: ncryptsslp.dll | Jump to behavior |
Source: C:\Windows\explorer.exe | Section loaded: gpapi.dll | Jump to behavior |
Source: C:\Windows\explorer.exe | Section loaded: pcshellcommonproxystub.dll | Jump to behavior |
Source: C:\Windows\explorer.exe | Section loaded: cryptngc.dll | Jump to behavior |
Source: C:\Windows\explorer.exe | Section loaded: cflapi.dll | Jump to behavior |
Source: C:\Windows\explorer.exe | Section loaded: execmodelproxy.dll | Jump to behavior |
Source: C:\Windows\explorer.exe | Section loaded: daxexec.dll | Jump to behavior |
Source: C:\Windows\explorer.exe | Section loaded: container.dll | Jump to behavior |
Source: C:\Windows\explorer.exe | Section loaded: shellcommoncommonproxystub.dll | Jump to behavior |
Source: C:\Windows\explorer.exe | Section loaded: uiautomationcore.dll | Jump to behavior |
Source: C:\Windows\explorer.exe | Section loaded: samlib.dll | Jump to behavior |
Source: C:\Windows\explorer.exe | Section loaded: msxml6.dll | Jump to behavior |
Source: C:\Windows\explorer.exe | Section loaded: batmeter.dll | Jump to behavior |
Source: C:\Windows\explorer.exe | Section loaded: capabilityaccessmanagerclient.dll | Jump to behavior |
Source: C:\Windows\explorer.exe | Section loaded: sxs.dll | Jump to behavior |
Source: C:\Windows\explorer.exe | Section loaded: inputswitch.dll | Jump to behavior |
Source: C:\Windows\explorer.exe | Section loaded: windows.ui.shell.dll | Jump to behavior |
Source: C:\Windows\explorer.exe | Section loaded: prnfldr.dll | Jump to behavior |
Source: C:\Windows\explorer.exe | Section loaded: es.dll | Jump to behavior |
Source: C:\Windows\explorer.exe | Section loaded: wpnclient.dll | Jump to behavior |
Source: C:\Windows\explorer.exe | Section loaded: dxp.dll | Jump to behavior |
Source: C:\Windows\explorer.exe | Section loaded: shdocvw.dll | Jump to behavior |
Source: C:\Windows\explorer.exe | Section loaded: atlthunk.dll | Jump to behavior |
Source: C:\Windows\explorer.exe | Section loaded: syncreg.dll | Jump to behavior |
Source: C:\Windows\explorer.exe | Section loaded: actioncenter.dll | Jump to behavior |
Source: C:\Windows\explorer.exe | Section loaded: wevtapi.dll | Jump to behavior |
Source: C:\Windows\explorer.exe | Section loaded: audioses.dll | Jump to behavior |
Source: C:\Windows\explorer.exe | Section loaded: netprofm.dll | Jump to behavior |
Source: C:\Windows\explorer.exe | Section loaded: networkuxbroker.dll | Jump to behavior |
Source: C:\Windows\explorer.exe | Section loaded: ethernetmediamanager.dll | Jump to behavior |
Source: C:\Windows\explorer.exe | Section loaded: dusmapi.dll | Jump to behavior |
Source: C:\Windows\explorer.exe | Section loaded: wlanapi.dll | Jump to behavior |
Source: C:\Windows\explorer.exe | Section loaded: ncsi.dll | Jump to behavior |
Source: C:\Windows\explorer.exe | Section loaded: dhcpcsvc6.dll | Jump to behavior |
Source: C:\Windows\explorer.exe | Section loaded: dhcpcsvc.dll | Jump to behavior |
Source: C:\Windows\explorer.exe | Section loaded: wpdshserviceobj.dll | Jump to behavior |
Source: C:\Windows\explorer.exe | Section loaded: portabledevicetypes.dll | Jump to behavior |
Source: C:\Windows\explorer.exe | Section loaded: portabledeviceapi.dll | Jump to behavior |
Source: C:\Windows\explorer.exe | Section loaded: cscobj.dll | Jump to behavior |
Source: C:\Windows\explorer.exe | Section loaded: srchadmin.dll | Jump to behavior |
Source: C:\Windows\explorer.exe | Section loaded: windows.storage.search.dll | Jump to behavior |
Source: C:\Windows\explorer.exe | Section loaded: synccenter.dll | Jump to behavior |
Source: C:\Windows\explorer.exe | Section loaded: imapi2.dll | Jump to behavior |
Source: C:\Windows\explorer.exe | Section loaded: bluetoothapis.dll | Jump to behavior |
Source: C:\Windows\explorer.exe | Section loaded: bluetoothapis.dll | Jump to behavior |
Source: C:\Windows\explorer.exe | Section loaded: bluetoothapis.dll | Jump to behavior |
Source: C:\Windows\explorer.exe | Section loaded: bluetoothapis.dll | Jump to behavior |
Source: C:\Windows\explorer.exe | Section loaded: settingsync.dll | Jump to behavior |
Source: C:\Windows\explorer.exe | Section loaded: settingsynccore.dll | Jump to behavior |
Source: C:\Windows\explorer.exe | Section loaded: windows.ui.xaml.dll | Jump to behavior |
Source: C:\Windows\explorer.exe | Section loaded: windowsinternal.composableshell.desktophosting.dll | Jump to behavior |
Source: C:\Windows\explorer.exe | Section loaded: uiamanager.dll | Jump to behavior |
Source: C:\Windows\explorer.exe | Section loaded: wscinterop.dll | Jump to behavior |
Source: C:\Windows\explorer.exe | Section loaded: wscapi.dll | Jump to behavior |
Source: C:\Windows\explorer.exe | Section loaded: werconcpl.dll | Jump to behavior |
Source: C:\Windows\explorer.exe | Section loaded: framedynos.dll | Jump to behavior |
Source: C:\Windows\explorer.exe | Section loaded: wer.dll | Jump to behavior |
Source: C:\Windows\explorer.exe | Section loaded: hcproviders.dll | Jump to behavior |
Source: C:\Windows\explorer.exe | Section loaded: ieproxy.dll | Jump to behavior |
Source: | Binary string: D:\a\_work\e\src\out\Release_x64\WebView2Loader.dll.pdb source: SecuriteInfo.com.Trojan.Win64.Meterpreter.11595.2675.exe, 00000000.00000003.1754494111.000001B92F950000.00000004.00000020.00020000.00000000.sdmp |
Source: | Binary string: http://msdl.microsoft.com/download/symbols/twinui.pcshell.pdb/56A53B20B8D4F79E69038072C21547311/twinui.pcshell.pdb source: explorer.exe, 0000000A.00000003.1912234304.000000000BAA9000.00000004.00000020.00020000.00000000.sdmp, explorer.exe, 0000000A.00000003.1863754048.000000000BAA9000.00000004.00000020.00020000.00000000.sdmp, explorer.exe, 0000000A.00000003.2034843476.000000000B8F3000.00000004.00000020.00020000.00000000.sdmp, explorer.exe, 0000000A.00000003.2040664141.000000000BAA9000.00000004.00000020.00020000.00000000.sdmp, explorer.exe, 0000000A.00000003.2044927276.000000000BAA9000.00000004.00000020.00020000.00000000.sdmp |
Source: | Binary string: C:\Users\user\AppData\Roaming\ExplorerPatcher\twinui.pcshell.pdb( source: explorer.exe, 0000000A.00000003.2032672748.000000000BA85000.00000004.00000020.00020000.00000000.sdmp, explorer.exe, 0000000A.00000003.2044927276.000000000BA85000.00000004.00000020.00020000.00000000.sdmp, explorer.exe, 0000000A.00000003.2040664141.000000000BA85000.00000004.00000020.00020000.00000000.sdmp |
Source: | Binary string: eehttp://msdl.microsoft.com/download/symbols/StartUI.pdb/74D47198CB4699BA710AD8B2C5310DD91/StartUI.pdb source: explorer.exe, 0000000A.00000003.2338063758.000000000F533000.00000004.00000020.00020000.00000000.sdmp, explorer.exe, 0000000A.00000003.2338182098.000000000F589000.00000004.00000020.00020000.00000000.sdmp, explorer.exe, 0000000A.00000003.2336219974.000000000F52D000.00000004.00000020.00020000.00000000.sdmp |
Source: | Binary string: D:\a\ExplorerPatcher\ExplorerPatcher\build\Release\x64\ep_weather_host_stub.pdb source: SecuriteInfo.com.Trojan.Win64.Meterpreter.11595.2675.exe, 00000000.00000003.1754219678.000001B92F950000.00000004.00000020.00020000.00000000.sdmp, SecuriteInfo.com.Trojan.Win64.Meterpreter.11595.2675.exe, 00000000.00000003.1754289039.000001B92F96A000.00000004.00000020.00020000.00000000.sdmp |
Source: | Binary string: C:\Users\user\AppData\Roaming\ExplorerPatcher\twinui.pcshell.pdbi source: explorer.exe, 0000000A.00000003.2032672748.000000000BA85000.00000004.00000020.00020000.00000000.sdmp, explorer.exe, 0000000A.00000003.2044927276.000000000BA85000.00000004.00000020.00020000.00000000.sdmp, explorer.exe, 0000000A.00000003.2040664141.000000000BA85000.00000004.00000020.00020000.00000000.sdmp |
Source: | Binary string: \??\C:\Users\user\AppData\Roaming\ExplorerPatcher\twinui.pcshell.pdb0V source: explorer.exe, 0000000A.00000003.1901047401.000000000BD40000.00000004.00000020.00020000.00000000.sdmp |
Source: | Binary string: StartUI.pdb source: explorer.exe, 00000009.00000003.1772607654.0000000002EE1000.00000004.00000020.00020000.00000000.sdmp, explorer.exe, 0000000A.00000003.2045484810.00000000103C4000.00000004.00000020.00020000.00000000.sdmp |
Source: | Binary string: sshttp://msdl.microsoft.com/download/symbols/twinui.pcshell.pdb/56A53B20B8D4F79E69038072C21547311/twinui.pcshell.pdb source: explorer.exe, 0000000A.00000003.2032672748.000000000B946000.00000004.00000020.00020000.00000000.sdmp |
Source: | Binary string: /download/symbols/twinui.pcshell.pdb/56A53B20B8D4F79E69038072C21547311/twinui.pcshell.pdbLXy source: explorer.exe, 0000000A.00000003.2038461778.000000000B9C5000.00000004.00000020.00020000.00000000.sdmp, explorer.exe, 0000000A.00000003.1928410983.000000000B9C5000.00000004.00000020.00020000.00000000.sdmp, explorer.exe, 0000000A.00000003.1912234304.000000000BA34000.00000004.00000020.00020000.00000000.sdmp, explorer.exe, 0000000A.00000003.2032672748.000000000B9C5000.00000004.00000020.00020000.00000000.sdmp |
Source: | Binary string: D:\a\ExplorerPatcher\ExplorerPatcher\build\Release\x64\ep_gui.pdb source: SecuriteInfo.com.Trojan.Win64.Meterpreter.11595.2675.exe, 00000000.00000003.1753512064.000001B932081000.00000004.00000020.00020000.00000000.sdmp |
Source: | Binary string: http://msdl.microsoft.com/download/symbols/twinui.pcshell.pdb/56A53B20B8D4F79E69038072C21547311/twinui.pcshell.pdb source: explorer.exe, 0000000A.00000003.2034843476.000000000B8F3000.00000004.00000020.00020000.00000000.sdmp |
Source: | Binary string: GET /download/symbols/twinui.pcshell.pdb/56A53B20B8D4F79E69038072C21547311/twinui.pcshell.pdb HTTP/1.1 source: explorer.exe, 0000000A.00000003.1884335541.000000000B909000.00000004.00000020.00020000.00000000.sdmp, explorer.exe, 0000000A.00000003.1876558912.000000000B909000.00000004.00000020.00020000.00000000.sdmp |
Source: | Binary string: twinui.pcshell.pdbUGP source: explorer.exe, 00000009.00000003.1773648082.0000000002EE4000.00000004.00000020.00020000.00000000.sdmp, explorer.exe, 00000009.00000003.1771490317.0000000002EEE000.00000004.00000020.00020000.00000000.sdmp, explorer.exe, 0000000A.00000003.1777857049.00000000027F7000.00000004.00000020.00020000.00000000.sdmp, explorer.exe, 0000000A.00000003.1849449600.000000000D44B000.00000004.00000020.00020000.00000000.sdmp |
Source: | Binary string: twinui.pcshell.pdb source: explorer.exe, 00000009.00000003.1773648082.0000000002EE4000.00000004.00000020.00020000.00000000.sdmp, explorer.exe, 00000009.00000003.1771490317.0000000002EEE000.00000004.00000020.00020000.00000000.sdmp, explorer.exe, 0000000A.00000003.1777857049.00000000027F7000.00000004.00000020.00020000.00000000.sdmp, explorer.exe, 0000000A.00000003.1849449600.000000000D44B000.00000004.00000020.00020000.00000000.sdmp |
Source: | Binary string: D:\a\ExplorerPatcher\ExplorerPatcher\build\Release\x64\ExplorerPatcher.amd64.pdb source: SecuriteInfo.com.Trojan.Win64.Meterpreter.11595.2675.exe, 00000000.00000003.1753138409.000001B932081000.00000004.00000020.00020000.00000000.sdmp, explorer.exe, 00000009.00000002.1874656290.00007FFE1829D000.00000002.00000001.01000000.00000008.sdmp |
Source: | Binary string: D:\a\_work\e\src\out\Release_x64\WebView2Loader.dll.pdbOGP source: SecuriteInfo.com.Trojan.Win64.Meterpreter.11595.2675.exe, 00000000.00000003.1754494111.000001B92F950000.00000004.00000020.00020000.00000000.sdmp |
Source: | Binary string: Hostmsdl.microsoft.comGET /download/symbols/twinui.pcshell.pdb/56A53B20B8D4F79E69038072C21547311/twinui.pcshell.pdb HTTP/1.1/download/symbols/twinui.pcshell.pdb/56A53B20B8D4F79E69038072C21547311/twinui.pcshell.pdb source: explorer.exe, 0000000A.00000003.1884335541.000000000B909000.00000004.00000020.00020000.00000000.sdmp, explorer.exe, 0000000A.00000003.1876558912.000000000B909000.00000004.00000020.00020000.00000000.sdmp |
Source: | Binary string: C:\Users\user\AppData\Roaming\ExplorerPatcher\twinui.pcshell.pdb source: explorer.exe, 0000000A.00000003.2032672748.000000000BA85000.00000004.00000020.00020000.00000000.sdmp, explorer.exe, 0000000A.00000003.2044927276.000000000BA85000.00000004.00000020.00020000.00000000.sdmp, explorer.exe, 0000000A.00000003.2034843476.000000000B8F3000.00000004.00000020.00020000.00000000.sdmp, explorer.exe, 0000000A.00000003.2040664141.000000000BA85000.00000004.00000020.00020000.00000000.sdmp, explorer.exe, 0000000A.00000003.1912234304.000000000BA34000.00000004.00000020.00020000.00000000.sdmp, explorer.exe, 0000000A.00000003.1912557909.000000000BA84000.00000004.00000020.00020000.00000000.sdmp, explorer.exe, 0000000A.00000003.2040636400.000000000B905000.00000004.00000020.00020000.00000000.sdmp |
Source: | Binary string: D:\a\ExplorerPatcher\ExplorerPatcher\build\Release\x64\ep_dwm.pdb source: SecuriteInfo.com.Trojan.Win64.Meterpreter.11595.2675.exe, 00000000.00000003.1753761329.000001B92F950000.00000004.00000020.00020000.00000000.sdmp, SecuriteInfo.com.Trojan.Win64.Meterpreter.11595.2675.exe, 00000000.00000003.1753794147.000001B92F96C000.00000004.00000020.00020000.00000000.sdmp |
Source: | Binary string: symbols/StartUI.pdb/74D47198CB4699BA710AD82C5 source: explorer.exe, 0000000A.00000003.2338567821.000000000BD25000.00000004.00000020.00020000.00000000.sdmp |
Source: | Binary string: vC:\Users\user\AppData\Roaming\ExplorerPatcher\StartUI.pdb source: explorer.exe, 0000000A.00000003.2338774634.000000000BAFA000.00000004.00000020.00020000.00000000.sdmp |
Source: | Binary string: tUI.pdb source: explorer.exe, 0000000A.00000003.2338567821.000000000BD25000.00000004.00000020.00020000.00000000.sdmp |
Source: | Binary string: D:\a\ExplorerPatcher\ExplorerPatcher\build\Release\Win32\ExplorerPatcher.IA-32.pdb source: SecuriteInfo.com.Trojan.Win64.Meterpreter.11595.2675.exe, 00000000.00000003.1752836203.000001B92F950000.00000004.00000020.00020000.00000000.sdmp, SecuriteInfo.com.Trojan.Win64.Meterpreter.11595.2675.exe, 00000000.00000003.1752863673.000001B92F975000.00000004.00000020.00020000.00000000.sdmp |
Source: | Binary string: D:\a\ExplorerPatcher\ExplorerPatcher\build\Release\x64\ep_setup.pdb source: SecuriteInfo.com.Trojan.Win64.Meterpreter.11595.2675.exe, 00000000.00000000.1727366409.00007FF733126000.00000002.00000001.01000000.00000003.sdmp, SecuriteInfo.com.Trojan.Win64.Meterpreter.11595.2675.exe, 00000000.00000002.1773069236.00007FF733126000.00000002.00000001.01000000.00000003.sdmp |
Source: | Binary string: D:\a\ExplorerPatcher\ExplorerPatcher\build\Release\x64\ep_weather_host.pdb source: SecuriteInfo.com.Trojan.Win64.Meterpreter.11595.2675.exe, 00000000.00000003.1754054332.000001B92F950000.00000004.00000020.00020000.00000000.sdmp, SecuriteInfo.com.Trojan.Win64.Meterpreter.11595.2675.exe, 00000000.00000003.1754001005.000001B932081000.00000004.00000020.00020000.00000000.sdmp |
Source: | Binary string: StartUI.pdbH source: explorer.exe, 00000009.00000003.1772607654.0000000002EE1000.00000004.00000020.00020000.00000000.sdmp, explorer.exe, 0000000A.00000003.2045484810.00000000103C4000.00000004.00000020.00020000.00000000.sdmp |
Source: | Binary string: /download/symbols/StartUI.pdb/74D47198CB4699BA710AD8B2C5310DD91/StartUI.pdb source: explorer.exe, 0000000A.00000003.2338567821.000000000BD25000.00000004.00000020.00020000.00000000.sdmp |
Source: | Binary string: 2C21547311/twinui.pcshell.pdb HTTP/1.1 source: explorer.exe, 0000000A.00000003.1912234304.000000000BAA9000.00000004.00000020.00020000.00000000.sdmp, explorer.exe, 0000000A.00000003.1863754048.000000000BAA9000.00000004.00000020.00020000.00000000.sdmp, explorer.exe, 0000000A.00000003.2040664141.000000000BAA9000.00000004.00000020.00020000.00000000.sdmp, explorer.exe, 0000000A.00000003.2044927276.000000000BAA9000.00000004.00000020.00020000.00000000.sdmp |
Source: C:\Windows\explorer.exe | Code function: 9_2_00007FFE18243880 GetCursorPos,MonitorFromPoint,FindWindowExW,MonitorFromWindow,FindWindowExW,FindWindowExW,FindWindowW,FindWindowExW,FindWindowExW,GetCursorPos,GetCursorPos,MonitorFromPoint,FindWindowExW,MonitorFromWindow,MonitorFromPoint,GetMonitorInfoW,FindWindowExW,MonitorFromWindow,GetMonitorInfoW,GetWindowRect,SetCursorPos,SetCursorPos,FindWindowW,PostMessageW,PostMessageW,FindWindowExW,FindWindowW,GetCursorPos,GetCursorPos,MonitorFromPoint,FindWindowExW,MonitorFromWindow,MonitorFromPoint,GetMonitorInfoW,FindWindowExW,MonitorFromWindow,GetMonitorInfoW,GetWindowRect,SetCursorPos,FindWindowExW,PostMessageW,GetWindowLongPtrW,GetWindowLongPtrW,SendMessageCallbackW,PostMessageW, | 9_2_00007FFE18243880 |
Source: C:\Windows\explorer.exe | Code function: 9_2_00007FFE18243880 GetCursorPos,MonitorFromPoint,FindWindowExW,MonitorFromWindow,FindWindowExW,FindWindowExW,FindWindowW,FindWindowExW,FindWindowExW,GetCursorPos,GetCursorPos,MonitorFromPoint,FindWindowExW,MonitorFromWindow,MonitorFromPoint,GetMonitorInfoW,FindWindowExW,MonitorFromWindow,GetMonitorInfoW,GetWindowRect,SetCursorPos,SetCursorPos,FindWindowW,PostMessageW,PostMessageW,FindWindowExW,FindWindowW,GetCursorPos,GetCursorPos,MonitorFromPoint,FindWindowExW,MonitorFromWindow,MonitorFromPoint,GetMonitorInfoW,FindWindowExW,MonitorFromWindow,GetMonitorInfoW,GetWindowRect,SetCursorPos,FindWindowExW,PostMessageW,GetWindowLongPtrW,GetWindowLongPtrW,SendMessageCallbackW,PostMessageW, | 9_2_00007FFE18243880 |
Source: C:\Windows\explorer.exe | Code function: 9_2_00007FFE18243880 GetCursorPos,MonitorFromPoint,FindWindowExW,MonitorFromWindow,FindWindowExW,FindWindowExW,FindWindowW,FindWindowExW,FindWindowExW,GetCursorPos,GetCursorPos,MonitorFromPoint,FindWindowExW,MonitorFromWindow,MonitorFromPoint,GetMonitorInfoW,FindWindowExW,MonitorFromWindow,GetMonitorInfoW,GetWindowRect,SetCursorPos,SetCursorPos,FindWindowW,PostMessageW,PostMessageW,FindWindowExW,FindWindowW,GetCursorPos,GetCursorPos,MonitorFromPoint,FindWindowExW,MonitorFromWindow,MonitorFromPoint,GetMonitorInfoW,FindWindowExW,MonitorFromWindow,GetMonitorInfoW,GetWindowRect,SetCursorPos,FindWindowExW,PostMessageW,GetWindowLongPtrW,GetWindowLongPtrW,SendMessageCallbackW,PostMessageW, | 9_2_00007FFE18243880 |
Source: C:\Windows\explorer.exe | Code function: 9_2_00007FFE18243880 GetCursorPos,MonitorFromPoint,FindWindowExW,MonitorFromWindow,FindWindowExW,FindWindowExW,FindWindowW,FindWindowExW,FindWindowExW,GetCursorPos,GetCursorPos,MonitorFromPoint,FindWindowExW,MonitorFromWindow,MonitorFromPoint,GetMonitorInfoW,FindWindowExW,MonitorFromWindow,GetMonitorInfoW,GetWindowRect,SetCursorPos,SetCursorPos,FindWindowW,PostMessageW,PostMessageW,FindWindowExW,FindWindowW,GetCursorPos,GetCursorPos,MonitorFromPoint,FindWindowExW,MonitorFromWindow,MonitorFromPoint,GetMonitorInfoW,FindWindowExW,MonitorFromWindow,GetMonitorInfoW,GetWindowRect,SetCursorPos,FindWindowExW,PostMessageW,GetWindowLongPtrW,GetWindowLongPtrW,SendMessageCallbackW,PostMessageW, | 9_2_00007FFE18243880 |
Source: C:\Windows\explorer.exe | Code function: 9_2_00007FFE18243880 GetCursorPos,MonitorFromPoint,FindWindowExW,MonitorFromWindow,FindWindowExW,FindWindowExW,FindWindowW,FindWindowExW,FindWindowExW,GetCursorPos,GetCursorPos,MonitorFromPoint,FindWindowExW,MonitorFromWindow,MonitorFromPoint,GetMonitorInfoW,FindWindowExW,MonitorFromWindow,GetMonitorInfoW,GetWindowRect,SetCursorPos,SetCursorPos,FindWindowW,PostMessageW,PostMessageW,FindWindowExW,FindWindowW,GetCursorPos,GetCursorPos,MonitorFromPoint,FindWindowExW,MonitorFromWindow,MonitorFromPoint,GetMonitorInfoW,FindWindowExW,MonitorFromWindow,GetMonitorInfoW,GetWindowRect,SetCursorPos,FindWindowExW,PostMessageW,GetWindowLongPtrW,GetWindowLongPtrW,SendMessageCallbackW,PostMessageW, | 9_2_00007FFE18243880 |
Source: C:\Windows\explorer.exe | Code function: 9_2_00007FFE18243DA0 FindWindowExW,FindWindowExW,FindWindowExW,SendMessageW, | 9_2_00007FFE18243DA0 |
Source: C:\Windows\explorer.exe | Code function: 9_2_00007FFE1823F4C0 FindWindowW,SendMessageTimeoutW, | 9_2_00007FFE1823F4C0 |