Source: C:\Users\user\Desktop\GOmRjFSKNz.exe |
Code function: 0_2_004062D5 FindFirstFileW,FindClose, |
0_2_004062D5 |
Source: C:\Users\user\Desktop\GOmRjFSKNz.exe |
Code function: 0_2_00402E18 FindFirstFileW, |
0_2_00402E18 |
Source: C:\Users\user\Desktop\GOmRjFSKNz.exe |
Code function: 0_2_00406C9B DeleteFileW,lstrcatW,lstrcatW,lstrcatW,lstrlenW,FindFirstFileW,DeleteFileW,FindNextFileW,FindClose,RemoveDirectoryW, |
0_2_00406C9B |
Source: C:\Users\user\AppData\Local\Temp\72076\Launches.pif |
Code function: 10_2_007A4005 FindFirstFileW,DeleteFileW,FindNextFileW,FindClose,FindClose, |
10_2_007A4005 |
Source: C:\Users\user\AppData\Local\Temp\72076\Launches.pif |
Code function: 10_2_007A494A GetFileAttributesW,FindFirstFileW,FindClose, |
10_2_007A494A |
Source: C:\Users\user\AppData\Local\Temp\72076\Launches.pif |
Code function: 10_2_007A3CE2 FindFirstFileW,DeleteFileW,DeleteFileW,MoveFileW,DeleteFileW,FindNextFileW,FindClose,FindClose, |
10_2_007A3CE2 |
Source: C:\Users\user\AppData\Local\Temp\72076\Launches.pif |
Code function: 10_2_007AC2FF FindFirstFileW,_wcscmp,_wcscmp,FindNextFileW,FindClose, |
10_2_007AC2FF |
Source: C:\Users\user\AppData\Local\Temp\72076\Launches.pif |
Code function: 10_2_007ACD14 FindFirstFileW,FindClose, |
10_2_007ACD14 |
Source: C:\Users\user\AppData\Local\Temp\72076\Launches.pif |
Code function: 10_2_007ACD9F FindFirstFileW,FindClose,FileTimeToLocalFileTime,FileTimeToLocalFileTime,FileTimeToLocalFileTime,FileTimeToSystemTime,__swprintf,__swprintf,__swprintf,__swprintf,__swprintf,__swprintf,__swprintf, |
10_2_007ACD9F |
Source: C:\Users\user\AppData\Local\Temp\72076\Launches.pif |
Code function: 10_2_007AF5D8 SetCurrentDirectoryW,FindFirstFileW,FindFirstFileW,_wcscmp,_wcscmp,GetFileAttributesW,SetFileAttributesW,FindNextFileW,FindClose,FindFirstFileW,SetCurrentDirectoryW,_wcscmp,_wcscmp,SetCurrentDirectoryW,SetCurrentDirectoryW,FindNextFileW,FindClose,FindClose, |
10_2_007AF5D8 |
Source: C:\Users\user\AppData\Local\Temp\72076\Launches.pif |
Code function: 10_2_007AF735 SetCurrentDirectoryW,FindFirstFileW,FindFirstFileW,_wcscmp,_wcscmp,FindNextFileW,FindClose,FindFirstFileW,SetCurrentDirectoryW,_wcscmp,_wcscmp,SetCurrentDirectoryW,SetCurrentDirectoryW,FindNextFileW,FindClose,FindClose, |
10_2_007AF735 |
Source: C:\Users\user\AppData\Local\Temp\72076\Launches.pif |
Code function: 10_2_007AFA36 FindFirstFileW,Sleep,_wcscmp,_wcscmp,FindNextFileW,FindClose, |
10_2_007AFA36 |
Source: GOmRjFSKNz.exe, 00000000.00000003.1781635044.0000000002886000.00000004.00000020.00020000.00000000.sdmp, Carol.0.dr, Launches.pif.1.dr |
String found in binary or memory: http://crl.globalsign.com/gs/gstimestampingsha2g2.crl0 |
Source: GOmRjFSKNz.exe, 00000000.00000003.1781635044.0000000002886000.00000004.00000020.00020000.00000000.sdmp, Carol.0.dr, Launches.pif.1.dr |
String found in binary or memory: http://crl.globalsign.com/gscodesignsha2g3.crl0 |
Source: GOmRjFSKNz.exe, 00000000.00000003.1781635044.0000000002886000.00000004.00000020.00020000.00000000.sdmp, Carol.0.dr, Launches.pif.1.dr |
String found in binary or memory: http://crl.globalsign.com/root-r3.crl0c |
Source: GOmRjFSKNz.exe, 00000000.00000003.1781635044.0000000002886000.00000004.00000020.00020000.00000000.sdmp, Carol.0.dr, Launches.pif.1.dr |
String found in binary or memory: http://crl.globalsign.net/root-r3.crl0 |
Source: GOmRjFSKNz.exe |
String found in binary or memory: http://nsis.sf.net/NSIS_ErrorError |
Source: GOmRjFSKNz.exe, 00000000.00000003.1781635044.0000000002886000.00000004.00000020.00020000.00000000.sdmp, Carol.0.dr, Launches.pif.1.dr |
String found in binary or memory: http://ocsp2.globalsign.com/gscodesignsha2g30V |
Source: GOmRjFSKNz.exe, 00000000.00000003.1781635044.0000000002886000.00000004.00000020.00020000.00000000.sdmp, Carol.0.dr, Launches.pif.1.dr |
String found in binary or memory: http://ocsp2.globalsign.com/gstimestampingsha2g20 |
Source: GOmRjFSKNz.exe, 00000000.00000003.1781635044.0000000002886000.00000004.00000020.00020000.00000000.sdmp, Carol.0.dr, Launches.pif.1.dr |
String found in binary or memory: http://ocsp2.globalsign.com/rootr306 |
Source: RegAsm.exe, 00000010.00000002.3033364620.0000000002601000.00000004.00000800.00020000.00000000.sdmp |
String found in binary or memory: http://schemas.xmlsoap.org/soap/actor/next |
Source: RegAsm.exe, 00000010.00000002.3033364620.0000000002601000.00000004.00000800.00020000.00000000.sdmp |
String found in binary or memory: http://schemas.xmlsoap.org/soap/envelope/ |
Source: RegAsm.exe, 00000010.00000002.3033364620.0000000002601000.00000004.00000800.00020000.00000000.sdmp |
String found in binary or memory: http://schemas.xmlsoap.org/ws/2004/08/addressing |
Source: RegAsm.exe, 00000010.00000002.3033364620.0000000002601000.00000004.00000800.00020000.00000000.sdmp |
String found in binary or memory: http://schemas.xmlsoap.org/ws/2004/08/addressing/faultp9 |
Source: RegAsm.exe, 00000010.00000002.3033364620.0000000002601000.00000004.00000800.00020000.00000000.sdmp |
String found in binary or memory: http://schemas.xmlsoap.org/ws/2004/08/addressing/role/anonymous |
Source: RegAsm.exe, 00000010.00000002.3033364620.0000000002601000.00000004.00000800.00020000.00000000.sdmp |
String found in binary or memory: http://schemas.xmlsoap.org/ws/2005/02/rm |
Source: RegAsm.exe, 00000010.00000002.3033364620.0000000002601000.00000004.00000800.00020000.00000000.sdmp |
String found in binary or memory: http://schemas.xmlsoap.org/ws/2005/02/rm/AckRequested |
Source: RegAsm.exe, 00000010.00000002.3033364620.0000000002601000.00000004.00000800.00020000.00000000.sdmp |
String found in binary or memory: http://schemas.xmlsoap.org/ws/2005/02/rm/CreateSequence |
Source: RegAsm.exe, 00000010.00000002.3033364620.0000000002601000.00000004.00000800.00020000.00000000.sdmp |
String found in binary or memory: http://schemas.xmlsoap.org/ws/2005/02/rm/CreateSequenceResponse |
Source: RegAsm.exe, 00000010.00000002.3033364620.0000000002601000.00000004.00000800.00020000.00000000.sdmp |
String found in binary or memory: http://schemas.xmlsoap.org/ws/2005/02/rm/LastMessage |
Source: RegAsm.exe, 00000010.00000002.3033364620.0000000002601000.00000004.00000800.00020000.00000000.sdmp |
String found in binary or memory: http://schemas.xmlsoap.org/ws/2005/02/rm/SequenceAcknowledgement |
Source: RegAsm.exe, 00000010.00000002.3033364620.0000000002601000.00000004.00000800.00020000.00000000.sdmp |
String found in binary or memory: http://schemas.xmlsoap.org/ws/2005/02/rm/TerminateSequence |
Source: RegAsm.exe, 00000010.00000002.3033364620.0000000002601000.00000004.00000800.00020000.00000000.sdmp |
String found in binary or memory: http://schemas.xmlsoap.org/ws/2005/05/identity/claims/dns |
Source: RegAsm.exe, 00000010.00000002.3033364620.0000000002601000.00000004.00000800.00020000.00000000.sdmp |
String found in binary or memory: http://schemas.xmlsoap.org/ws/2005/05/identity/right/possessproperty |
Source: GOmRjFSKNz.exe, 00000000.00000003.1781635044.0000000002886000.00000004.00000020.00020000.00000000.sdmp, Carol.0.dr, Launches.pif.1.dr |
String found in binary or memory: http://secure.globalsign.com/cacert/gscodesignsha2g3ocsp.crt08 |
Source: GOmRjFSKNz.exe, 00000000.00000003.1781635044.0000000002886000.00000004.00000020.00020000.00000000.sdmp, Carol.0.dr, Launches.pif.1.dr |
String found in binary or memory: http://secure.globalsign.com/cacert/gstimestampingsha2g2.crt0 |
Source: RegAsm.exe, 00000010.00000002.3033364620.0000000002601000.00000004.00000800.00020000.00000000.sdmp |
String found in binary or memory: http://tempuri.org/ |
Source: RegAsm.exe, 00000010.00000002.3033364620.0000000002601000.00000004.00000800.00020000.00000000.sdmp |
String found in binary or memory: http://tempuri.org/Entity/ |
Source: RegAsm.exe, 00000010.00000002.3033364620.0000000002601000.00000004.00000800.00020000.00000000.sdmp |
String found in binary or memory: http://tempuri.org/Entity/Id10LRfq |
Source: RegAsm.exe, 00000010.00000002.3033364620.0000000002601000.00000004.00000800.00020000.00000000.sdmp |
String found in binary or memory: http://tempuri.org/Entity/Id10Responsex |
Source: RegAsm.exe, 00000010.00000002.3033364620.0000000002601000.00000004.00000800.00020000.00000000.sdmp |
String found in binary or memory: http://tempuri.org/Entity/Id11LRfq |
Source: RegAsm.exe, 00000010.00000002.3033364620.0000000002601000.00000004.00000800.00020000.00000000.sdmp |
String found in binary or memory: http://tempuri.org/Entity/Id11Responsex |
Source: RegAsm.exe, 00000010.00000002.3033364620.0000000002601000.00000004.00000800.00020000.00000000.sdmp |
String found in binary or memory: http://tempuri.org/Entity/Id12LRfq |
Source: RegAsm.exe, 00000010.00000002.3033364620.0000000002601000.00000004.00000800.00020000.00000000.sdmp |
String found in binary or memory: http://tempuri.org/Entity/Id12Responsex |
Source: RegAsm.exe, 00000010.00000002.3033364620.0000000002601000.00000004.00000800.00020000.00000000.sdmp |
String found in binary or memory: http://tempuri.org/Entity/Id13LRfq |
Source: RegAsm.exe, 00000010.00000002.3033364620.0000000002601000.00000004.00000800.00020000.00000000.sdmp |
String found in binary or memory: http://tempuri.org/Entity/Id13Responsex |
Source: RegAsm.exe, 00000010.00000002.3033364620.0000000002601000.00000004.00000800.00020000.00000000.sdmp |
String found in binary or memory: http://tempuri.org/Entity/Id14LRfq |
Source: RegAsm.exe, 00000010.00000002.3033364620.0000000002601000.00000004.00000800.00020000.00000000.sdmp |
String found in binary or memory: http://tempuri.org/Entity/Id14Responsex |
Source: RegAsm.exe, 00000010.00000002.3033364620.0000000002601000.00000004.00000800.00020000.00000000.sdmp |
String found in binary or memory: http://tempuri.org/Entity/Id15LRfqx/j |
Source: RegAsm.exe, 00000010.00000002.3033364620.0000000002601000.00000004.00000800.00020000.00000000.sdmp |
String found in binary or memory: http://tempuri.org/Entity/Id15Responsex |
Source: RegAsm.exe, 00000010.00000002.3033364620.0000000002601000.00000004.00000800.00020000.00000000.sdmp |
String found in binary or memory: http://tempuri.org/Entity/Id16LRfq |
Source: RegAsm.exe, 00000010.00000002.3033364620.0000000002601000.00000004.00000800.00020000.00000000.sdmp |
String found in binary or memory: http://tempuri.org/Entity/Id16Responsex |
Source: RegAsm.exe, 00000010.00000002.3033364620.0000000002601000.00000004.00000800.00020000.00000000.sdmp |
String found in binary or memory: http://tempuri.org/Entity/Id17LRfq |
Source: RegAsm.exe, 00000010.00000002.3033364620.0000000002601000.00000004.00000800.00020000.00000000.sdmp |
String found in binary or memory: http://tempuri.org/Entity/Id17Responsex |
Source: RegAsm.exe, 00000010.00000002.3033364620.0000000002601000.00000004.00000800.00020000.00000000.sdmp |
String found in binary or memory: http://tempuri.org/Entity/Id18LRfq |
Source: RegAsm.exe, 00000010.00000002.3033364620.0000000002601000.00000004.00000800.00020000.00000000.sdmp |
String found in binary or memory: http://tempuri.org/Entity/Id18Responsex |
Source: RegAsm.exe, 00000010.00000002.3033364620.0000000002601000.00000004.00000800.00020000.00000000.sdmp |
String found in binary or memory: http://tempuri.org/Entity/Id19LRfq |
Source: RegAsm.exe, 00000010.00000002.3033364620.0000000002601000.00000004.00000800.00020000.00000000.sdmp |
String found in binary or memory: http://tempuri.org/Entity/Id19Responsex |
Source: RegAsm.exe, 00000010.00000002.3033364620.0000000002601000.00000004.00000800.00020000.00000000.sdmp |
String found in binary or memory: http://tempuri.org/Entity/Id1LRfq4 |
Source: RegAsm.exe, 00000010.00000002.3033364620.0000000002601000.00000004.00000800.00020000.00000000.sdmp |
String found in binary or memory: http://tempuri.org/Entity/Id1Responsex |
Source: RegAsm.exe, 00000010.00000002.3033364620.0000000002601000.00000004.00000800.00020000.00000000.sdmp |
String found in binary or memory: http://tempuri.org/Entity/Id20LRfq |
Source: RegAsm.exe, 00000010.00000002.3033364620.0000000002601000.00000004.00000800.00020000.00000000.sdmp |
String found in binary or memory: http://tempuri.org/Entity/Id20Responsex |
Source: RegAsm.exe, 00000010.00000002.3033364620.0000000002601000.00000004.00000800.00020000.00000000.sdmp |
String found in binary or memory: http://tempuri.org/Entity/Id21LRfqduj |
Source: RegAsm.exe, 00000010.00000002.3033364620.0000000002601000.00000004.00000800.00020000.00000000.sdmp |
String found in binary or memory: http://tempuri.org/Entity/Id21Responsex |
Source: RegAsm.exe, 00000010.00000002.3033364620.0000000002601000.00000004.00000800.00020000.00000000.sdmp |
String found in binary or memory: http://tempuri.org/Entity/Id22LRfq |
Source: RegAsm.exe, 00000010.00000002.3033364620.0000000002601000.00000004.00000800.00020000.00000000.sdmp |
String found in binary or memory: http://tempuri.org/Entity/Id22Responsex |
Source: RegAsm.exe, 00000010.00000002.3033364620.0000000002601000.00000004.00000800.00020000.00000000.sdmp |
String found in binary or memory: http://tempuri.org/Entity/Id23LRfq |
Source: RegAsm.exe, 00000010.00000002.3033364620.0000000002601000.00000004.00000800.00020000.00000000.sdmp |
String found in binary or memory: http://tempuri.org/Entity/Id23Responsex |
Source: RegAsm.exe, 00000010.00000002.3033364620.0000000002601000.00000004.00000800.00020000.00000000.sdmp |
String found in binary or memory: http://tempuri.org/Entity/Id24LRfq |
Source: RegAsm.exe, 00000010.00000002.3033364620.0000000002601000.00000004.00000800.00020000.00000000.sdmp |
String found in binary or memory: http://tempuri.org/Entity/Id24Responsex |
Source: RegAsm.exe, 00000010.00000002.3033364620.0000000002601000.00000004.00000800.00020000.00000000.sdmp |
String found in binary or memory: http://tempuri.org/Entity/Id2LRfq |
Source: RegAsm.exe, 00000010.00000002.3033364620.0000000002601000.00000004.00000800.00020000.00000000.sdmp |
String found in binary or memory: http://tempuri.org/Entity/Id2Responsex |
Source: RegAsm.exe, 00000010.00000002.3033364620.0000000002601000.00000004.00000800.00020000.00000000.sdmp |
String found in binary or memory: http://tempuri.org/Entity/Id3LRfq |
Source: RegAsm.exe, 00000010.00000002.3033364620.0000000002601000.00000004.00000800.00020000.00000000.sdmp |
String found in binary or memory: http://tempuri.org/Entity/Id3Responsex |
Source: RegAsm.exe, 00000010.00000002.3033364620.0000000002601000.00000004.00000800.00020000.00000000.sdmp |
String found in binary or memory: http://tempuri.org/Entity/Id4LRfq |
Source: RegAsm.exe, 00000010.00000002.3033364620.0000000002601000.00000004.00000800.00020000.00000000.sdmp |
String found in binary or memory: http://tempuri.org/Entity/Id4Responsex |
Source: RegAsm.exe, 00000010.00000002.3033364620.0000000002601000.00000004.00000800.00020000.00000000.sdmp |
String found in binary or memory: http://tempuri.org/Entity/Id5LRfq |
Source: RegAsm.exe, 00000010.00000002.3033364620.0000000002601000.00000004.00000800.00020000.00000000.sdmp |
String found in binary or memory: http://tempuri.org/Entity/Id5Responsex |
Source: RegAsm.exe, 00000010.00000002.3033364620.0000000002601000.00000004.00000800.00020000.00000000.sdmp |
String found in binary or memory: http://tempuri.org/Entity/Id6LRfq |
Source: RegAsm.exe, 00000010.00000002.3033364620.0000000002601000.00000004.00000800.00020000.00000000.sdmp |
String found in binary or memory: http://tempuri.org/Entity/Id6Responsex |
Source: RegAsm.exe, 00000010.00000002.3033364620.0000000002601000.00000004.00000800.00020000.00000000.sdmp |
String found in binary or memory: http://tempuri.org/Entity/Id7LRfqx |
Source: RegAsm.exe, 00000010.00000002.3033364620.0000000002601000.00000004.00000800.00020000.00000000.sdmp |
String found in binary or memory: http://tempuri.org/Entity/Id7Responsex |
Source: RegAsm.exe, 00000010.00000002.3033364620.0000000002601000.00000004.00000800.00020000.00000000.sdmp |
String found in binary or memory: http://tempuri.org/Entity/Id8LRfq |
Source: RegAsm.exe, 00000010.00000002.3033364620.0000000002601000.00000004.00000800.00020000.00000000.sdmp |
String found in binary or memory: http://tempuri.org/Entity/Id8Responsex |
Source: RegAsm.exe, 00000010.00000002.3033364620.0000000002601000.00000004.00000800.00020000.00000000.sdmp |
String found in binary or memory: http://tempuri.org/Entity/Id9LRfq |
Source: RegAsm.exe, 00000010.00000002.3033364620.0000000002601000.00000004.00000800.00020000.00000000.sdmp |
String found in binary or memory: http://tempuri.org/Entity/Id9Responsex |
Source: GOmRjFSKNz.exe, 00000000.00000003.1781635044.0000000002886000.00000004.00000020.00020000.00000000.sdmp, Launches.pif, 0000000A.00000000.1818602986.0000000000809000.00000002.00000001.01000000.00000006.sdmp, Carol.0.dr, Launches.pif.1.dr |
String found in binary or memory: http://www.autoitscript.com/autoit3/J |
Source: Launches.pif, 0000000A.00000003.2825065700.0000000001DDD000.00000004.00000800.00020000.00000000.sdmp, Launches.pif, 0000000A.00000003.2833770879.0000000001F91000.00000004.00000800.00020000.00000000.sdmp, Launches.pif, 0000000A.00000003.2825546542.000000000519F000.00000004.00000800.00020000.00000000.sdmp, Launches.pif, 0000000A.00000003.2825688213.0000000001E5B000.00000004.00000800.00020000.00000000.sdmp, Launches.pif, 0000000A.00000003.2882687318.0000000001DD3000.00000004.00000800.00020000.00000000.sdmp, Launches.pif, 0000000A.00000003.2882687318.0000000001D91000.00000004.00000800.00020000.00000000.sdmp, Launches.pif, 0000000A.00000003.2833826824.000000000449B000.00000004.00000800.00020000.00000000.sdmp, Launches.pif, 0000000A.00000003.2884666788.0000000001DDC000.00000004.00000800.00020000.00000000.sdmp, Launches.pif, 0000000A.00000003.2833895594.0000000004418000.00000004.00000800.00020000.00000000.sdmp, Launches.pif, 0000000A.00000003.2884574282.0000000001E5C000.00000004.00000800.00020000.00000000.sdmp, RegAsm.exe, 00000010.00000002.3032255109.0000000000342000.00000040.00000400.00020000.00000000.sdmp |
String found in binary or memory: https://api.ip.sb/ip |
Source: GOmRjFSKNz.exe, 00000000.00000003.1781635044.0000000002886000.00000004.00000020.00020000.00000000.sdmp, Carol.0.dr, Launches.pif.1.dr |
String found in binary or memory: https://www.autoitscript.com/autoit3/ |
Source: Launches.pif.1.dr |
String found in binary or memory: https://www.globalsign.com/repository/0 |
Source: GOmRjFSKNz.exe, 00000000.00000003.1781635044.0000000002886000.00000004.00000020.00020000.00000000.sdmp, Carol.0.dr, Launches.pif.1.dr |
String found in binary or memory: https://www.globalsign.com/repository/06 |
Source: C:\Users\user\Desktop\GOmRjFSKNz.exe |
Code function: 0_2_0040497C |
0_2_0040497C |
Source: C:\Users\user\Desktop\GOmRjFSKNz.exe |
Code function: 0_2_00406ED2 |
0_2_00406ED2 |
Source: C:\Users\user\Desktop\GOmRjFSKNz.exe |
Code function: 0_2_004074BB |
0_2_004074BB |
Source: C:\Users\user\AppData\Local\Temp\72076\Launches.pif |
Code function: 10_2_0074B020 |
10_2_0074B020 |
Source: C:\Users\user\AppData\Local\Temp\72076\Launches.pif |
Code function: 10_2_007494E0 |
10_2_007494E0 |
Source: C:\Users\user\AppData\Local\Temp\72076\Launches.pif |
Code function: 10_2_00749C80 |
10_2_00749C80 |
Source: C:\Users\user\AppData\Local\Temp\72076\Launches.pif |
Code function: 10_2_007623F5 |
10_2_007623F5 |
Source: C:\Users\user\AppData\Local\Temp\72076\Launches.pif |
Code function: 10_2_007C8400 |
10_2_007C8400 |
Source: C:\Users\user\AppData\Local\Temp\72076\Launches.pif |
Code function: 10_2_00776502 |
10_2_00776502 |
Source: C:\Users\user\AppData\Local\Temp\72076\Launches.pif |
Code function: 10_2_0077265E |
10_2_0077265E |
Source: C:\Users\user\AppData\Local\Temp\72076\Launches.pif |
Code function: 10_2_0074E6F0 |
10_2_0074E6F0 |
Source: C:\Users\user\AppData\Local\Temp\72076\Launches.pif |
Code function: 10_2_0076282A |
10_2_0076282A |
Source: C:\Users\user\AppData\Local\Temp\72076\Launches.pif |
Code function: 10_2_007789BF |
10_2_007789BF |
Source: C:\Users\user\AppData\Local\Temp\72076\Launches.pif |
Code function: 10_2_00776A74 |
10_2_00776A74 |
Source: C:\Users\user\AppData\Local\Temp\72076\Launches.pif |
Code function: 10_2_007C0A3A |
10_2_007C0A3A |
Source: C:\Users\user\AppData\Local\Temp\72076\Launches.pif |
Code function: 10_2_00750BE0 |
10_2_00750BE0 |
Source: C:\Users\user\AppData\Local\Temp\72076\Launches.pif |
Code function: 10_2_0076CD51 |
10_2_0076CD51 |
Source: C:\Users\user\AppData\Local\Temp\72076\Launches.pif |
Code function: 10_2_0079EDB2 |
10_2_0079EDB2 |
Source: C:\Users\user\AppData\Local\Temp\72076\Launches.pif |
Code function: 10_2_007A8E44 |
10_2_007A8E44 |
Source: C:\Users\user\AppData\Local\Temp\72076\Launches.pif |
Code function: 10_2_007C0EB7 |
10_2_007C0EB7 |
Source: C:\Users\user\AppData\Local\Temp\72076\Launches.pif |
Code function: 10_2_00776FE6 |
10_2_00776FE6 |
Source: C:\Users\user\AppData\Local\Temp\72076\Launches.pif |
Code function: 10_2_007633B7 |
10_2_007633B7 |
Source: C:\Users\user\AppData\Local\Temp\72076\Launches.pif |
Code function: 10_2_0075D45D |
10_2_0075D45D |
Source: C:\Users\user\AppData\Local\Temp\72076\Launches.pif |
Code function: 10_2_0076F409 |
10_2_0076F409 |
Source: C:\Users\user\AppData\Local\Temp\72076\Launches.pif |
Code function: 10_2_00741663 |
10_2_00741663 |
Source: C:\Users\user\AppData\Local\Temp\72076\Launches.pif |
Code function: 10_2_0075F628 |
10_2_0075F628 |
Source: C:\Users\user\AppData\Local\Temp\72076\Launches.pif |
Code function: 10_2_007616B4 |
10_2_007616B4 |
Source: C:\Users\user\AppData\Local\Temp\72076\Launches.pif |
Code function: 10_2_0074F6A0 |
10_2_0074F6A0 |
Source: C:\Users\user\AppData\Local\Temp\72076\Launches.pif |
Code function: 10_2_007678C3 |
10_2_007678C3 |
Source: C:\Users\user\AppData\Local\Temp\72076\Launches.pif |
Code function: 10_2_0076DBA5 |
10_2_0076DBA5 |
Source: C:\Users\user\AppData\Local\Temp\72076\Launches.pif |
Code function: 10_2_00761BA8 |
10_2_00761BA8 |
Source: C:\Users\user\AppData\Local\Temp\72076\Launches.pif |
Code function: 10_2_00779CE5 |
10_2_00779CE5 |
Source: C:\Users\user\AppData\Local\Temp\72076\Launches.pif |
Code function: 10_2_0075DD28 |
10_2_0075DD28 |
Source: C:\Users\user\AppData\Local\Temp\72076\Launches.pif |
Code function: 10_2_0076BFD6 |
10_2_0076BFD6 |
Source: C:\Users\user\AppData\Local\Temp\72076\Launches.pif |
Code function: 10_2_00761FC0 |
10_2_00761FC0 |
Source: C:\Users\user\AppData\Local\Temp\72076\RegAsm.exe |
Code function: 16_2_00BBDC74 |
16_2_00BBDC74 |
Source: C:\Users\user\AppData\Local\Temp\72076\RegAsm.exe |
Code function: 16_2_05DA67D8 |
16_2_05DA67D8 |
Source: C:\Users\user\AppData\Local\Temp\72076\RegAsm.exe |
Code function: 16_2_05DAA3E8 |
16_2_05DAA3E8 |
Source: C:\Users\user\AppData\Local\Temp\72076\RegAsm.exe |
Code function: 16_2_05DAA3D8 |
16_2_05DAA3D8 |
Source: C:\Users\user\AppData\Local\Temp\72076\RegAsm.exe |
Code function: 16_2_05DA6FF8 |
16_2_05DA6FF8 |
Source: C:\Users\user\AppData\Local\Temp\72076\RegAsm.exe |
Code function: 16_2_05DA6FE8 |
16_2_05DA6FE8 |
Source: unknown |
Process created: C:\Users\user\Desktop\GOmRjFSKNz.exe "C:\Users\user\Desktop\GOmRjFSKNz.exe" |
|
Source: C:\Users\user\Desktop\GOmRjFSKNz.exe |
Process created: C:\Windows\SysWOW64\cmd.exe "C:\Windows\System32\cmd.exe" /c move Pediatric Pediatric.bat & Pediatric.bat |
|
Source: C:\Windows\SysWOW64\cmd.exe |
Process created: C:\Windows\System32\conhost.exe C:\Windows\system32\conhost.exe 0xffffffff -ForceV1 |
|
Source: C:\Windows\SysWOW64\cmd.exe |
Process created: C:\Windows\SysWOW64\tasklist.exe tasklist |
|
Source: C:\Windows\SysWOW64\cmd.exe |
Process created: C:\Windows\SysWOW64\findstr.exe findstr /I "wrsa opssvc" |
|
Source: C:\Windows\SysWOW64\cmd.exe |
Process created: C:\Windows\SysWOW64\tasklist.exe tasklist |
|
Source: C:\Windows\SysWOW64\cmd.exe |
Process created: C:\Windows\SysWOW64\findstr.exe findstr /I "avastui avgui bdservicehost nswscsvc sophoshealth" |
|
Source: C:\Windows\SysWOW64\cmd.exe |
Process created: C:\Windows\SysWOW64\cmd.exe cmd /c md 72076 |
|
Source: C:\Windows\SysWOW64\cmd.exe |
Process created: C:\Windows\SysWOW64\findstr.exe findstr /V "SILICONLATINOAMPLANDBLOW" Words |
|
Source: C:\Windows\SysWOW64\cmd.exe |
Process created: C:\Windows\SysWOW64\cmd.exe cmd /c copy /b ..\Indoor + ..\An + ..\Transport + ..\Strap + ..\Passed + ..\Treasure s |
|
Source: C:\Windows\SysWOW64\cmd.exe |
Process created: C:\Users\user\AppData\Local\Temp\72076\Launches.pif Launches.pif s |
|
Source: C:\Windows\SysWOW64\cmd.exe |
Process created: C:\Windows\SysWOW64\choice.exe choice /d y /t 5 |
|
Source: C:\Users\user\AppData\Local\Temp\72076\Launches.pif |
Process created: C:\Users\user\AppData\Local\Temp\72076\RegAsm.exe C:\Users\user\AppData\Local\Temp\72076\RegAsm.exe |
|
Source: C:\Users\user\Desktop\GOmRjFSKNz.exe |
Process created: C:\Windows\SysWOW64\cmd.exe "C:\Windows\System32\cmd.exe" /c move Pediatric Pediatric.bat & Pediatric.bat |
Jump to behavior |
Source: C:\Windows\SysWOW64\cmd.exe |
Process created: C:\Windows\SysWOW64\tasklist.exe tasklist |
Jump to behavior |
Source: C:\Windows\SysWOW64\cmd.exe |
Process created: C:\Windows\SysWOW64\findstr.exe findstr /I "wrsa opssvc" |
Jump to behavior |
Source: C:\Windows\SysWOW64\cmd.exe |
Process created: C:\Windows\SysWOW64\tasklist.exe tasklist |
Jump to behavior |
Source: C:\Windows\SysWOW64\cmd.exe |
Process created: C:\Windows\SysWOW64\findstr.exe findstr /I "avastui avgui bdservicehost nswscsvc sophoshealth" |
Jump to behavior |
Source: C:\Windows\SysWOW64\cmd.exe |
Process created: C:\Windows\SysWOW64\cmd.exe cmd /c md 72076 |
Jump to behavior |
Source: C:\Windows\SysWOW64\cmd.exe |
Process created: C:\Windows\SysWOW64\findstr.exe findstr /V "SILICONLATINOAMPLANDBLOW" Words |
Jump to behavior |
Source: C:\Windows\SysWOW64\cmd.exe |
Process created: C:\Windows\SysWOW64\cmd.exe cmd /c copy /b ..\Indoor + ..\An + ..\Transport + ..\Strap + ..\Passed + ..\Treasure s |
Jump to behavior |
Source: C:\Windows\SysWOW64\cmd.exe |
Process created: C:\Users\user\AppData\Local\Temp\72076\Launches.pif Launches.pif s |
Jump to behavior |
Source: C:\Windows\SysWOW64\cmd.exe |
Process created: C:\Windows\SysWOW64\choice.exe choice /d y /t 5 |
Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\72076\Launches.pif |
Process created: C:\Users\user\AppData\Local\Temp\72076\RegAsm.exe C:\Users\user\AppData\Local\Temp\72076\RegAsm.exe |
Jump to behavior |
Source: C:\Users\user\Desktop\GOmRjFSKNz.exe |
Section loaded: apphelp.dll |
Jump to behavior |
Source: C:\Users\user\Desktop\GOmRjFSKNz.exe |
Section loaded: version.dll |
Jump to behavior |
Source: C:\Users\user\Desktop\GOmRjFSKNz.exe |
Section loaded: kernel.appcore.dll |
Jump to behavior |
Source: C:\Users\user\Desktop\GOmRjFSKNz.exe |
Section loaded: uxtheme.dll |
Jump to behavior |
Source: C:\Users\user\Desktop\GOmRjFSKNz.exe |
Section loaded: shfolder.dll |
Jump to behavior |
Source: C:\Users\user\Desktop\GOmRjFSKNz.exe |
Section loaded: windows.storage.dll |
Jump to behavior |
Source: C:\Users\user\Desktop\GOmRjFSKNz.exe |
Section loaded: wldp.dll |
Jump to behavior |
Source: C:\Users\user\Desktop\GOmRjFSKNz.exe |
Section loaded: propsys.dll |
Jump to behavior |
Source: C:\Users\user\Desktop\GOmRjFSKNz.exe |
Section loaded: riched20.dll |
Jump to behavior |
Source: C:\Users\user\Desktop\GOmRjFSKNz.exe |
Section loaded: usp10.dll |
Jump to behavior |
Source: C:\Users\user\Desktop\GOmRjFSKNz.exe |
Section loaded: msls31.dll |
Jump to behavior |
Source: C:\Users\user\Desktop\GOmRjFSKNz.exe |
Section loaded: textinputframework.dll |
Jump to behavior |
Source: C:\Users\user\Desktop\GOmRjFSKNz.exe |
Section loaded: coreuicomponents.dll |
Jump to behavior |
Source: C:\Users\user\Desktop\GOmRjFSKNz.exe |
Section loaded: coremessaging.dll |
Jump to behavior |
Source: C:\Users\user\Desktop\GOmRjFSKNz.exe |
Section loaded: ntmarta.dll |
Jump to behavior |
Source: C:\Users\user\Desktop\GOmRjFSKNz.exe |
Section loaded: coremessaging.dll |
Jump to behavior |
Source: C:\Users\user\Desktop\GOmRjFSKNz.exe |
Section loaded: wintypes.dll |
Jump to behavior |
Source: C:\Users\user\Desktop\GOmRjFSKNz.exe |
Section loaded: wintypes.dll |
Jump to behavior |
Source: C:\Users\user\Desktop\GOmRjFSKNz.exe |
Section loaded: wintypes.dll |
Jump to behavior |
Source: C:\Users\user\Desktop\GOmRjFSKNz.exe |
Section loaded: textshaping.dll |
Jump to behavior |
Source: C:\Users\user\Desktop\GOmRjFSKNz.exe |
Section loaded: profapi.dll |
Jump to behavior |
Source: C:\Users\user\Desktop\GOmRjFSKNz.exe |
Section loaded: edputil.dll |
Jump to behavior |
Source: C:\Users\user\Desktop\GOmRjFSKNz.exe |
Section loaded: urlmon.dll |
Jump to behavior |
Source: C:\Users\user\Desktop\GOmRjFSKNz.exe |
Section loaded: iertutil.dll |
Jump to behavior |
Source: C:\Users\user\Desktop\GOmRjFSKNz.exe |
Section loaded: srvcli.dll |
Jump to behavior |
Source: C:\Users\user\Desktop\GOmRjFSKNz.exe |
Section loaded: netutils.dll |
Jump to behavior |
Source: C:\Users\user\Desktop\GOmRjFSKNz.exe |
Section loaded: windows.staterepositoryps.dll |
Jump to behavior |
Source: C:\Users\user\Desktop\GOmRjFSKNz.exe |
Section loaded: sspicli.dll |
Jump to behavior |
Source: C:\Users\user\Desktop\GOmRjFSKNz.exe |
Section loaded: appresolver.dll |
Jump to behavior |
Source: C:\Users\user\Desktop\GOmRjFSKNz.exe |
Section loaded: bcp47langs.dll |
Jump to behavior |
Source: C:\Users\user\Desktop\GOmRjFSKNz.exe |
Section loaded: slc.dll |
Jump to behavior |
Source: C:\Users\user\Desktop\GOmRjFSKNz.exe |
Section loaded: userenv.dll |
Jump to behavior |
Source: C:\Users\user\Desktop\GOmRjFSKNz.exe |
Section loaded: sppc.dll |
Jump to behavior |
Source: C:\Users\user\Desktop\GOmRjFSKNz.exe |
Section loaded: onecorecommonproxystub.dll |
Jump to behavior |
Source: C:\Users\user\Desktop\GOmRjFSKNz.exe |
Section loaded: onecoreuapcommonproxystub.dll |
Jump to behavior |
Source: C:\Windows\SysWOW64\cmd.exe |
Section loaded: cmdext.dll |
Jump to behavior |
Source: C:\Windows\SysWOW64\cmd.exe |
Section loaded: apphelp.dll |
Jump to behavior |
Source: C:\Windows\SysWOW64\tasklist.exe |
Section loaded: version.dll |
Jump to behavior |
Source: C:\Windows\SysWOW64\tasklist.exe |
Section loaded: mpr.dll |
Jump to behavior |
Source: C:\Windows\SysWOW64\tasklist.exe |
Section loaded: framedynos.dll |
Jump to behavior |
Source: C:\Windows\SysWOW64\tasklist.exe |
Section loaded: dbghelp.dll |
Jump to behavior |
Source: C:\Windows\SysWOW64\tasklist.exe |
Section loaded: sspicli.dll |
Jump to behavior |
Source: C:\Windows\SysWOW64\tasklist.exe |
Section loaded: srvcli.dll |
Jump to behavior |
Source: C:\Windows\SysWOW64\tasklist.exe |
Section loaded: netutils.dll |
Jump to behavior |
Source: C:\Windows\SysWOW64\tasklist.exe |
Section loaded: sspicli.dll |
Jump to behavior |
Source: C:\Windows\SysWOW64\tasklist.exe |
Section loaded: kernel.appcore.dll |
Jump to behavior |
Source: C:\Windows\SysWOW64\tasklist.exe |
Section loaded: wbemcomn.dll |
Jump to behavior |
Source: C:\Windows\SysWOW64\tasklist.exe |
Section loaded: winsta.dll |
Jump to behavior |
Source: C:\Windows\SysWOW64\tasklist.exe |
Section loaded: amsi.dll |
Jump to behavior |
Source: C:\Windows\SysWOW64\tasklist.exe |
Section loaded: userenv.dll |
Jump to behavior |
Source: C:\Windows\SysWOW64\tasklist.exe |
Section loaded: profapi.dll |
Jump to behavior |
Source: C:\Windows\SysWOW64\tasklist.exe |
Section loaded: version.dll |
Jump to behavior |
Source: C:\Windows\SysWOW64\tasklist.exe |
Section loaded: mpr.dll |
Jump to behavior |
Source: C:\Windows\SysWOW64\tasklist.exe |
Section loaded: framedynos.dll |
Jump to behavior |
Source: C:\Windows\SysWOW64\tasklist.exe |
Section loaded: dbghelp.dll |
Jump to behavior |
Source: C:\Windows\SysWOW64\tasklist.exe |
Section loaded: sspicli.dll |
Jump to behavior |
Source: C:\Windows\SysWOW64\tasklist.exe |
Section loaded: srvcli.dll |
Jump to behavior |
Source: C:\Windows\SysWOW64\tasklist.exe |
Section loaded: netutils.dll |
Jump to behavior |
Source: C:\Windows\SysWOW64\tasklist.exe |
Section loaded: sspicli.dll |
Jump to behavior |
Source: C:\Windows\SysWOW64\tasklist.exe |
Section loaded: kernel.appcore.dll |
Jump to behavior |
Source: C:\Windows\SysWOW64\tasklist.exe |
Section loaded: wbemcomn.dll |
Jump to behavior |
Source: C:\Windows\SysWOW64\tasklist.exe |
Section loaded: winsta.dll |
Jump to behavior |
Source: C:\Windows\SysWOW64\tasklist.exe |
Section loaded: amsi.dll |
Jump to behavior |
Source: C:\Windows\SysWOW64\tasklist.exe |
Section loaded: userenv.dll |
Jump to behavior |
Source: C:\Windows\SysWOW64\tasklist.exe |
Section loaded: profapi.dll |
Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\72076\Launches.pif |
Section loaded: wsock32.dll |
Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\72076\Launches.pif |
Section loaded: version.dll |
Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\72076\Launches.pif |
Section loaded: winmm.dll |
Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\72076\Launches.pif |
Section loaded: mpr.dll |
Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\72076\Launches.pif |
Section loaded: wininet.dll |
Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\72076\Launches.pif |
Section loaded: iphlpapi.dll |
Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\72076\Launches.pif |
Section loaded: userenv.dll |
Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\72076\Launches.pif |
Section loaded: uxtheme.dll |
Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\72076\Launches.pif |
Section loaded: kernel.appcore.dll |
Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\72076\Launches.pif |
Section loaded: windows.storage.dll |
Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\72076\Launches.pif |
Section loaded: wldp.dll |
Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\72076\Launches.pif |
Section loaded: napinsp.dll |
Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\72076\Launches.pif |
Section loaded: pnrpnsp.dll |
Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\72076\Launches.pif |
Section loaded: wshbth.dll |
Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\72076\Launches.pif |
Section loaded: nlaapi.dll |
Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\72076\Launches.pif |
Section loaded: mswsock.dll |
Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\72076\Launches.pif |
Section loaded: dnsapi.dll |
Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\72076\Launches.pif |
Section loaded: winrnr.dll |
Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\72076\Launches.pif |
Section loaded: rasadhlp.dll |
Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\72076\Launches.pif |
Section loaded: ntmarta.dll |
Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\72076\Launches.pif |
Section loaded: apphelp.dll |
Jump to behavior |
Source: C:\Windows\SysWOW64\choice.exe |
Section loaded: version.dll |
Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\72076\RegAsm.exe |
Section loaded: mscoree.dll |
Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\72076\RegAsm.exe |
Section loaded: apphelp.dll |
Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\72076\RegAsm.exe |
Section loaded: aclayers.dll |
Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\72076\RegAsm.exe |
Section loaded: mpr.dll |
Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\72076\RegAsm.exe |
Section loaded: sfc.dll |
Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\72076\RegAsm.exe |
Section loaded: sfc_os.dll |
Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\72076\RegAsm.exe |
Section loaded: kernel.appcore.dll |
Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\72076\RegAsm.exe |
Section loaded: version.dll |
Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\72076\RegAsm.exe |
Section loaded: vcruntime140_clr0400.dll |
Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\72076\RegAsm.exe |
Section loaded: ucrtbase_clr0400.dll |
Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\72076\RegAsm.exe |
Section loaded: ucrtbase_clr0400.dll |
Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\72076\RegAsm.exe |
Section loaded: uxtheme.dll |
Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\72076\RegAsm.exe |
Section loaded: windows.storage.dll |
Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\72076\RegAsm.exe |
Section loaded: wldp.dll |
Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\72076\RegAsm.exe |
Section loaded: profapi.dll |
Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\72076\RegAsm.exe |
Section loaded: cryptsp.dll |
Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\72076\RegAsm.exe |
Section loaded: rsaenh.dll |
Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\72076\RegAsm.exe |
Section loaded: cryptbase.dll |
Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\72076\RegAsm.exe |
Section loaded: dwrite.dll |
Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\72076\RegAsm.exe |
Section loaded: msvcp140_clr0400.dll |
Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\72076\RegAsm.exe |
Section loaded: msasn1.dll |
Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\72076\RegAsm.exe |
Section loaded: msisip.dll |
Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\72076\RegAsm.exe |
Section loaded: wshext.dll |
Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\72076\RegAsm.exe |
Section loaded: appxsip.dll |
Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\72076\RegAsm.exe |
Section loaded: opcservices.dll |
Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\72076\RegAsm.exe |
Section loaded: esdsip.dll |
Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\72076\RegAsm.exe |
Section loaded: userenv.dll |
Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\72076\RegAsm.exe |
Section loaded: dpapi.dll |
Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\72076\RegAsm.exe |
Section loaded: gpapi.dll |
Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\72076\RegAsm.exe |
Section loaded: sxs.dll |
Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\72076\RegAsm.exe |
Section loaded: scrrun.dll |
Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\72076\RegAsm.exe |
Section loaded: propsys.dll |
Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\72076\RegAsm.exe |
Section loaded: linkinfo.dll |
Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\72076\RegAsm.exe |
Section loaded: mswsock.dll |
Jump to behavior |
Source: C:\Users\user\Desktop\GOmRjFSKNz.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\Desktop\GOmRjFSKNz.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\Desktop\GOmRjFSKNz.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\Desktop\GOmRjFSKNz.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\Desktop\GOmRjFSKNz.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\Desktop\GOmRjFSKNz.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\Desktop\GOmRjFSKNz.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\Desktop\GOmRjFSKNz.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\Desktop\GOmRjFSKNz.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\Desktop\GOmRjFSKNz.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\Desktop\GOmRjFSKNz.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\Desktop\GOmRjFSKNz.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Windows\SysWOW64\cmd.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Windows\SysWOW64\tasklist.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Windows\SysWOW64\tasklist.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\72076\Launches.pif |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\72076\Launches.pif |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\72076\Launches.pif |
Process information set: FAILCRITICALERRORS | NOALIGNMENTFAULTEXCEPT | NOGPFAULTERRORBOX | NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\72076\RegAsm.exe |
Process information set: NOALIGNMENTFAULTEXCEPT | NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\72076\RegAsm.exe |
Process information set: NOALIGNMENTFAULTEXCEPT | NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\72076\RegAsm.exe |
Process information set: NOALIGNMENTFAULTEXCEPT | NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\72076\RegAsm.exe |
Process information set: NOALIGNMENTFAULTEXCEPT | NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\72076\RegAsm.exe |
Process information set: NOALIGNMENTFAULTEXCEPT | NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\72076\RegAsm.exe |
Process information set: NOALIGNMENTFAULTEXCEPT | NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\72076\RegAsm.exe |
Process information set: NOALIGNMENTFAULTEXCEPT | NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\72076\RegAsm.exe |
Process information set: NOALIGNMENTFAULTEXCEPT | NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\72076\RegAsm.exe |
Process information set: NOALIGNMENTFAULTEXCEPT | NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\72076\RegAsm.exe |
Process information set: NOALIGNMENTFAULTEXCEPT | NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\72076\RegAsm.exe |
Process information set: NOALIGNMENTFAULTEXCEPT | NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\72076\RegAsm.exe |
Process information set: NOALIGNMENTFAULTEXCEPT | NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\72076\RegAsm.exe |
Process information set: NOALIGNMENTFAULTEXCEPT | NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\72076\RegAsm.exe |
Process information set: NOALIGNMENTFAULTEXCEPT | NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\72076\RegAsm.exe |
Process information set: NOALIGNMENTFAULTEXCEPT | NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\72076\RegAsm.exe |
Process information set: NOALIGNMENTFAULTEXCEPT | NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\72076\RegAsm.exe |
Process information set: NOALIGNMENTFAULTEXCEPT | NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\72076\RegAsm.exe |
Process information set: NOALIGNMENTFAULTEXCEPT | NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\72076\RegAsm.exe |
Process information set: NOALIGNMENTFAULTEXCEPT | NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\72076\RegAsm.exe |
Process information set: NOALIGNMENTFAULTEXCEPT | NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\72076\RegAsm.exe |
Process information set: NOALIGNMENTFAULTEXCEPT | NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\72076\RegAsm.exe |
Process information set: NOALIGNMENTFAULTEXCEPT | NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\72076\RegAsm.exe |
Process information set: NOALIGNMENTFAULTEXCEPT | NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\72076\RegAsm.exe |
Process information set: NOALIGNMENTFAULTEXCEPT | NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\72076\RegAsm.exe |
Process information set: NOALIGNMENTFAULTEXCEPT | NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\72076\RegAsm.exe |
Process information set: NOALIGNMENTFAULTEXCEPT | NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\72076\RegAsm.exe |
Process information set: NOALIGNMENTFAULTEXCEPT | NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\72076\RegAsm.exe |
Process information set: NOALIGNMENTFAULTEXCEPT | NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\72076\RegAsm.exe |
Process information set: NOALIGNMENTFAULTEXCEPT | NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\72076\RegAsm.exe |
Process information set: NOALIGNMENTFAULTEXCEPT | NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\72076\RegAsm.exe |
Process information set: NOALIGNMENTFAULTEXCEPT | NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\72076\RegAsm.exe |
Process information set: NOALIGNMENTFAULTEXCEPT | NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\72076\RegAsm.exe |
Process information set: NOALIGNMENTFAULTEXCEPT | NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\72076\RegAsm.exe |
Process information set: NOALIGNMENTFAULTEXCEPT | NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\72076\RegAsm.exe |
Process information set: NOALIGNMENTFAULTEXCEPT | NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\72076\RegAsm.exe |
Process information set: NOALIGNMENTFAULTEXCEPT | NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\72076\RegAsm.exe |
Process information set: NOALIGNMENTFAULTEXCEPT | NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\72076\RegAsm.exe |
Process information set: NOALIGNMENTFAULTEXCEPT | NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\72076\RegAsm.exe |
Process information set: NOALIGNMENTFAULTEXCEPT | NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\72076\RegAsm.exe |
Process information set: NOALIGNMENTFAULTEXCEPT | NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\72076\RegAsm.exe |
Process information set: NOALIGNMENTFAULTEXCEPT | NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\72076\RegAsm.exe |
Process information set: NOALIGNMENTFAULTEXCEPT | NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\72076\RegAsm.exe |
Process information set: NOALIGNMENTFAULTEXCEPT | NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\72076\RegAsm.exe |
Process information set: NOALIGNMENTFAULTEXCEPT | NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\72076\RegAsm.exe |
Process information set: NOALIGNMENTFAULTEXCEPT | NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\72076\RegAsm.exe |
Process information set: NOALIGNMENTFAULTEXCEPT | NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\72076\RegAsm.exe |
Process information set: NOALIGNMENTFAULTEXCEPT | NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\72076\RegAsm.exe |
Process information set: NOALIGNMENTFAULTEXCEPT | NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\72076\RegAsm.exe |
Process information set: NOALIGNMENTFAULTEXCEPT | NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\72076\RegAsm.exe |
Process information set: NOALIGNMENTFAULTEXCEPT | NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\72076\RegAsm.exe |
Process information set: NOALIGNMENTFAULTEXCEPT | NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\72076\RegAsm.exe |
Process information set: NOALIGNMENTFAULTEXCEPT | NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\72076\RegAsm.exe |
Process information set: NOALIGNMENTFAULTEXCEPT | NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\72076\RegAsm.exe |
Process information set: NOALIGNMENTFAULTEXCEPT | NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\72076\RegAsm.exe |
Process information set: NOALIGNMENTFAULTEXCEPT | NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\72076\RegAsm.exe |
Process information set: NOALIGNMENTFAULTEXCEPT | NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\72076\RegAsm.exe |
Process information set: NOALIGNMENTFAULTEXCEPT | NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\72076\RegAsm.exe |
Process information set: NOALIGNMENTFAULTEXCEPT | NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\72076\RegAsm.exe |
Process information set: NOALIGNMENTFAULTEXCEPT | NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\72076\RegAsm.exe |
Process information set: NOALIGNMENTFAULTEXCEPT | NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\Desktop\GOmRjFSKNz.exe |
Code function: 0_2_004062D5 FindFirstFileW,FindClose, |
0_2_004062D5 |
Source: C:\Users\user\Desktop\GOmRjFSKNz.exe |
Code function: 0_2_00402E18 FindFirstFileW, |
0_2_00402E18 |
Source: C:\Users\user\Desktop\GOmRjFSKNz.exe |
Code function: 0_2_00406C9B DeleteFileW,lstrcatW,lstrcatW,lstrcatW,lstrlenW,FindFirstFileW,DeleteFileW,FindNextFileW,FindClose,RemoveDirectoryW, |
0_2_00406C9B |
Source: C:\Users\user\AppData\Local\Temp\72076\Launches.pif |
Code function: 10_2_007A4005 FindFirstFileW,DeleteFileW,FindNextFileW,FindClose,FindClose, |
10_2_007A4005 |
Source: C:\Users\user\AppData\Local\Temp\72076\Launches.pif |
Code function: 10_2_007A494A GetFileAttributesW,FindFirstFileW,FindClose, |
10_2_007A494A |
Source: C:\Users\user\AppData\Local\Temp\72076\Launches.pif |
Code function: 10_2_007A3CE2 FindFirstFileW,DeleteFileW,DeleteFileW,MoveFileW,DeleteFileW,FindNextFileW,FindClose,FindClose, |
10_2_007A3CE2 |
Source: C:\Users\user\AppData\Local\Temp\72076\Launches.pif |
Code function: 10_2_007AC2FF FindFirstFileW,_wcscmp,_wcscmp,FindNextFileW,FindClose, |
10_2_007AC2FF |
Source: C:\Users\user\AppData\Local\Temp\72076\Launches.pif |
Code function: 10_2_007ACD14 FindFirstFileW,FindClose, |
10_2_007ACD14 |
Source: C:\Users\user\AppData\Local\Temp\72076\Launches.pif |
Code function: 10_2_007ACD9F FindFirstFileW,FindClose,FileTimeToLocalFileTime,FileTimeToLocalFileTime,FileTimeToLocalFileTime,FileTimeToSystemTime,__swprintf,__swprintf,__swprintf,__swprintf,__swprintf,__swprintf,__swprintf, |
10_2_007ACD9F |
Source: C:\Users\user\AppData\Local\Temp\72076\Launches.pif |
Code function: 10_2_007AF5D8 SetCurrentDirectoryW,FindFirstFileW,FindFirstFileW,_wcscmp,_wcscmp,GetFileAttributesW,SetFileAttributesW,FindNextFileW,FindClose,FindFirstFileW,SetCurrentDirectoryW,_wcscmp,_wcscmp,SetCurrentDirectoryW,SetCurrentDirectoryW,FindNextFileW,FindClose,FindClose, |
10_2_007AF5D8 |
Source: C:\Users\user\AppData\Local\Temp\72076\Launches.pif |
Code function: 10_2_007AF735 SetCurrentDirectoryW,FindFirstFileW,FindFirstFileW,_wcscmp,_wcscmp,FindNextFileW,FindClose,FindFirstFileW,SetCurrentDirectoryW,_wcscmp,_wcscmp,SetCurrentDirectoryW,SetCurrentDirectoryW,FindNextFileW,FindClose,FindClose, |
10_2_007AF735 |
Source: C:\Users\user\AppData\Local\Temp\72076\Launches.pif |
Code function: 10_2_007AFA36 FindFirstFileW,Sleep,_wcscmp,_wcscmp,FindNextFileW,FindClose, |
10_2_007AFA36 |
Source: Yara match |
File source: 10.3.Launches.pif.1ddc050.0.raw.unpack, type: UNPACKEDPE |
Source: Yara match |
File source: 16.2.RegAsm.exe.340000.0.unpack, type: UNPACKEDPE |
Source: Yara match |
File source: 10.3.Launches.pif.1ddc050.1.raw.unpack, type: UNPACKEDPE |
Source: Yara match |
File source: 0000000A.00000003.2825546542.000000000519F000.00000004.00000800.00020000.00000000.sdmp, type: MEMORY |
Source: Yara match |
File source: 0000000A.00000003.2833770879.0000000001F91000.00000004.00000800.00020000.00000000.sdmp, type: MEMORY |
Source: Yara match |
File source: 0000000A.00000003.2825065700.0000000001DDD000.00000004.00000800.00020000.00000000.sdmp, type: MEMORY |
Source: Yara match |
File source: 0000000A.00000003.2825688213.0000000001E5B000.00000004.00000800.00020000.00000000.sdmp, type: MEMORY |
Source: Yara match |
File source: 0000000A.00000003.2824672801.0000000001E5B000.00000004.00000800.00020000.00000000.sdmp, type: MEMORY |
Source: Yara match |
File source: 0000000A.00000003.2882687318.0000000001DD3000.00000004.00000800.00020000.00000000.sdmp, type: MEMORY |
Source: Yara match |
File source: 00000010.00000002.3032255109.0000000000342000.00000040.00000400.00020000.00000000.sdmp, type: MEMORY |
Source: Yara match |
File source: 0000000A.00000003.2882687318.0000000001D91000.00000004.00000800.00020000.00000000.sdmp, type: MEMORY |
Source: Yara match |
File source: 0000000A.00000003.2825305490.0000000001D91000.00000004.00000800.00020000.00000000.sdmp, type: MEMORY |
Source: Yara match |
File source: 0000000A.00000003.2825305490.0000000001DD3000.00000004.00000800.00020000.00000000.sdmp, type: MEMORY |
Source: Yara match |
File source: 0000000A.00000003.2833826824.000000000449B000.00000004.00000800.00020000.00000000.sdmp, type: MEMORY |
Source: Yara match |
File source: 0000000A.00000003.2884666788.0000000001DDC000.00000004.00000800.00020000.00000000.sdmp, type: MEMORY |
Source: Yara match |
File source: 0000000A.00000003.2825915690.0000000001F91000.00000004.00000800.00020000.00000000.sdmp, type: MEMORY |
Source: Yara match |
File source: 0000000A.00000003.2833895594.0000000004418000.00000004.00000800.00020000.00000000.sdmp, type: MEMORY |
Source: Yara match |
File source: 0000000A.00000003.2884370254.0000000001F02000.00000004.00000800.00020000.00000000.sdmp, type: MEMORY |
Source: Yara match |
File source: 0000000A.00000003.2884574282.0000000001E5C000.00000004.00000800.00020000.00000000.sdmp, type: MEMORY |
Source: Yara match |
File source: Process Memory Space: Launches.pif PID: 4296, type: MEMORYSTR |
Source: Yara match |
File source: Process Memory Space: RegAsm.exe PID: 1144, type: MEMORYSTR |
Source: Yara match |
File source: 10.3.Launches.pif.1ddc050.0.raw.unpack, type: UNPACKEDPE |
Source: Yara match |
File source: 16.2.RegAsm.exe.340000.0.unpack, type: UNPACKEDPE |
Source: Yara match |
File source: 10.3.Launches.pif.1ddc050.1.raw.unpack, type: UNPACKEDPE |
Source: Yara match |
File source: 0000000A.00000003.2825546542.000000000519F000.00000004.00000800.00020000.00000000.sdmp, type: MEMORY |
Source: Yara match |
File source: 0000000A.00000003.2833770879.0000000001F91000.00000004.00000800.00020000.00000000.sdmp, type: MEMORY |
Source: Yara match |
File source: 0000000A.00000003.2825065700.0000000001DDD000.00000004.00000800.00020000.00000000.sdmp, type: MEMORY |
Source: Yara match |
File source: 0000000A.00000003.2825688213.0000000001E5B000.00000004.00000800.00020000.00000000.sdmp, type: MEMORY |
Source: Yara match |
File source: 0000000A.00000003.2824672801.0000000001E5B000.00000004.00000800.00020000.00000000.sdmp, type: MEMORY |
Source: Yara match |
File source: 0000000A.00000003.2882687318.0000000001DD3000.00000004.00000800.00020000.00000000.sdmp, type: MEMORY |
Source: Yara match |
File source: 00000010.00000002.3032255109.0000000000342000.00000040.00000400.00020000.00000000.sdmp, type: MEMORY |
Source: Yara match |
File source: 0000000A.00000003.2882687318.0000000001D91000.00000004.00000800.00020000.00000000.sdmp, type: MEMORY |
Source: Yara match |
File source: 0000000A.00000003.2825305490.0000000001D91000.00000004.00000800.00020000.00000000.sdmp, type: MEMORY |
Source: Yara match |
File source: 0000000A.00000003.2825305490.0000000001DD3000.00000004.00000800.00020000.00000000.sdmp, type: MEMORY |
Source: Yara match |
File source: 0000000A.00000003.2833826824.000000000449B000.00000004.00000800.00020000.00000000.sdmp, type: MEMORY |
Source: Yara match |
File source: 0000000A.00000003.2884666788.0000000001DDC000.00000004.00000800.00020000.00000000.sdmp, type: MEMORY |
Source: Yara match |
File source: 0000000A.00000003.2825915690.0000000001F91000.00000004.00000800.00020000.00000000.sdmp, type: MEMORY |
Source: Yara match |
File source: 0000000A.00000003.2833895594.0000000004418000.00000004.00000800.00020000.00000000.sdmp, type: MEMORY |
Source: Yara match |
File source: 0000000A.00000003.2884370254.0000000001F02000.00000004.00000800.00020000.00000000.sdmp, type: MEMORY |
Source: Yara match |
File source: 0000000A.00000003.2884574282.0000000001E5C000.00000004.00000800.00020000.00000000.sdmp, type: MEMORY |
Source: Yara match |
File source: Process Memory Space: Launches.pif PID: 4296, type: MEMORYSTR |
Source: Yara match |
File source: Process Memory Space: RegAsm.exe PID: 1144, type: MEMORYSTR |