Source: C:\Users\user\Desktop\GOmRjFSKNz.exe | Code function: 0_2_004062D5 FindFirstFileW,FindClose, | 0_2_004062D5 |
Source: C:\Users\user\Desktop\GOmRjFSKNz.exe | Code function: 0_2_00402E18 FindFirstFileW, | 0_2_00402E18 |
Source: C:\Users\user\Desktop\GOmRjFSKNz.exe | Code function: 0_2_00406C9B DeleteFileW,lstrcatW,lstrcatW,lstrcatW,lstrlenW,FindFirstFileW,DeleteFileW,FindNextFileW,FindClose,RemoveDirectoryW, | 0_2_00406C9B |
Source: C:\Users\user\AppData\Local\Temp\72076\Launches.pif | Code function: 10_2_007A4005 FindFirstFileW,DeleteFileW,FindNextFileW,FindClose,FindClose, | 10_2_007A4005 |
Source: C:\Users\user\AppData\Local\Temp\72076\Launches.pif | Code function: 10_2_007A494A GetFileAttributesW,FindFirstFileW,FindClose, | 10_2_007A494A |
Source: C:\Users\user\AppData\Local\Temp\72076\Launches.pif | Code function: 10_2_007A3CE2 FindFirstFileW,DeleteFileW,DeleteFileW,MoveFileW,DeleteFileW,FindNextFileW,FindClose,FindClose, | 10_2_007A3CE2 |
Source: C:\Users\user\AppData\Local\Temp\72076\Launches.pif | Code function: 10_2_007AC2FF FindFirstFileW,_wcscmp,_wcscmp,FindNextFileW,FindClose, | 10_2_007AC2FF |
Source: C:\Users\user\AppData\Local\Temp\72076\Launches.pif | Code function: 10_2_007ACD14 FindFirstFileW,FindClose, | 10_2_007ACD14 |
Source: C:\Users\user\AppData\Local\Temp\72076\Launches.pif | Code function: 10_2_007ACD9F FindFirstFileW,FindClose,FileTimeToLocalFileTime,FileTimeToLocalFileTime,FileTimeToLocalFileTime,FileTimeToSystemTime,__swprintf,__swprintf,__swprintf,__swprintf,__swprintf,__swprintf,__swprintf, | 10_2_007ACD9F |
Source: C:\Users\user\AppData\Local\Temp\72076\Launches.pif | Code function: 10_2_007AF5D8 SetCurrentDirectoryW,FindFirstFileW,FindFirstFileW,_wcscmp,_wcscmp,GetFileAttributesW,SetFileAttributesW,FindNextFileW,FindClose,FindFirstFileW,SetCurrentDirectoryW,_wcscmp,_wcscmp,SetCurrentDirectoryW,SetCurrentDirectoryW,FindNextFileW,FindClose,FindClose, | 10_2_007AF5D8 |
Source: C:\Users\user\AppData\Local\Temp\72076\Launches.pif | Code function: 10_2_007AF735 SetCurrentDirectoryW,FindFirstFileW,FindFirstFileW,_wcscmp,_wcscmp,FindNextFileW,FindClose,FindFirstFileW,SetCurrentDirectoryW,_wcscmp,_wcscmp,SetCurrentDirectoryW,SetCurrentDirectoryW,FindNextFileW,FindClose,FindClose, | 10_2_007AF735 |
Source: C:\Users\user\AppData\Local\Temp\72076\Launches.pif | Code function: 10_2_007AFA36 FindFirstFileW,Sleep,_wcscmp,_wcscmp,FindNextFileW,FindClose, | 10_2_007AFA36 |
Source: GOmRjFSKNz.exe, 00000000.00000003.1781635044.0000000002886000.00000004.00000020.00020000.00000000.sdmp, Carol.0.dr, Launches.pif.1.dr | String found in binary or memory: http://crl.globalsign.com/gs/gstimestampingsha2g2.crl0 |
Source: GOmRjFSKNz.exe, 00000000.00000003.1781635044.0000000002886000.00000004.00000020.00020000.00000000.sdmp, Carol.0.dr, Launches.pif.1.dr | String found in binary or memory: http://crl.globalsign.com/gscodesignsha2g3.crl0 |
Source: GOmRjFSKNz.exe, 00000000.00000003.1781635044.0000000002886000.00000004.00000020.00020000.00000000.sdmp, Carol.0.dr, Launches.pif.1.dr | String found in binary or memory: http://crl.globalsign.com/root-r3.crl0c |
Source: GOmRjFSKNz.exe, 00000000.00000003.1781635044.0000000002886000.00000004.00000020.00020000.00000000.sdmp, Carol.0.dr, Launches.pif.1.dr | String found in binary or memory: http://crl.globalsign.net/root-r3.crl0 |
Source: GOmRjFSKNz.exe | String found in binary or memory: http://nsis.sf.net/NSIS_ErrorError |
Source: GOmRjFSKNz.exe, 00000000.00000003.1781635044.0000000002886000.00000004.00000020.00020000.00000000.sdmp, Carol.0.dr, Launches.pif.1.dr | String found in binary or memory: http://ocsp2.globalsign.com/gscodesignsha2g30V |
Source: GOmRjFSKNz.exe, 00000000.00000003.1781635044.0000000002886000.00000004.00000020.00020000.00000000.sdmp, Carol.0.dr, Launches.pif.1.dr | String found in binary or memory: http://ocsp2.globalsign.com/gstimestampingsha2g20 |
Source: GOmRjFSKNz.exe, 00000000.00000003.1781635044.0000000002886000.00000004.00000020.00020000.00000000.sdmp, Carol.0.dr, Launches.pif.1.dr | String found in binary or memory: http://ocsp2.globalsign.com/rootr306 |
Source: RegAsm.exe, 00000010.00000002.3033364620.0000000002601000.00000004.00000800.00020000.00000000.sdmp | String found in binary or memory: http://schemas.xmlsoap.org/soap/actor/next |
Source: RegAsm.exe, 00000010.00000002.3033364620.0000000002601000.00000004.00000800.00020000.00000000.sdmp | String found in binary or memory: http://schemas.xmlsoap.org/soap/envelope/ |
Source: RegAsm.exe, 00000010.00000002.3033364620.0000000002601000.00000004.00000800.00020000.00000000.sdmp | String found in binary or memory: http://schemas.xmlsoap.org/ws/2004/08/addressing |
Source: RegAsm.exe, 00000010.00000002.3033364620.0000000002601000.00000004.00000800.00020000.00000000.sdmp | String found in binary or memory: http://schemas.xmlsoap.org/ws/2004/08/addressing/faultp9 |
Source: RegAsm.exe, 00000010.00000002.3033364620.0000000002601000.00000004.00000800.00020000.00000000.sdmp | String found in binary or memory: http://schemas.xmlsoap.org/ws/2004/08/addressing/role/anonymous |
Source: RegAsm.exe, 00000010.00000002.3033364620.0000000002601000.00000004.00000800.00020000.00000000.sdmp | String found in binary or memory: http://schemas.xmlsoap.org/ws/2005/02/rm |
Source: RegAsm.exe, 00000010.00000002.3033364620.0000000002601000.00000004.00000800.00020000.00000000.sdmp | String found in binary or memory: http://schemas.xmlsoap.org/ws/2005/02/rm/AckRequested |
Source: RegAsm.exe, 00000010.00000002.3033364620.0000000002601000.00000004.00000800.00020000.00000000.sdmp | String found in binary or memory: http://schemas.xmlsoap.org/ws/2005/02/rm/CreateSequence |
Source: RegAsm.exe, 00000010.00000002.3033364620.0000000002601000.00000004.00000800.00020000.00000000.sdmp | String found in binary or memory: http://schemas.xmlsoap.org/ws/2005/02/rm/CreateSequenceResponse |
Source: RegAsm.exe, 00000010.00000002.3033364620.0000000002601000.00000004.00000800.00020000.00000000.sdmp | String found in binary or memory: http://schemas.xmlsoap.org/ws/2005/02/rm/LastMessage |
Source: RegAsm.exe, 00000010.00000002.3033364620.0000000002601000.00000004.00000800.00020000.00000000.sdmp | String found in binary or memory: http://schemas.xmlsoap.org/ws/2005/02/rm/SequenceAcknowledgement |
Source: RegAsm.exe, 00000010.00000002.3033364620.0000000002601000.00000004.00000800.00020000.00000000.sdmp | String found in binary or memory: http://schemas.xmlsoap.org/ws/2005/02/rm/TerminateSequence |
Source: RegAsm.exe, 00000010.00000002.3033364620.0000000002601000.00000004.00000800.00020000.00000000.sdmp | String found in binary or memory: http://schemas.xmlsoap.org/ws/2005/05/identity/claims/dns |
Source: RegAsm.exe, 00000010.00000002.3033364620.0000000002601000.00000004.00000800.00020000.00000000.sdmp | String found in binary or memory: http://schemas.xmlsoap.org/ws/2005/05/identity/right/possessproperty |
Source: GOmRjFSKNz.exe, 00000000.00000003.1781635044.0000000002886000.00000004.00000020.00020000.00000000.sdmp, Carol.0.dr, Launches.pif.1.dr | String found in binary or memory: http://secure.globalsign.com/cacert/gscodesignsha2g3ocsp.crt08 |
Source: GOmRjFSKNz.exe, 00000000.00000003.1781635044.0000000002886000.00000004.00000020.00020000.00000000.sdmp, Carol.0.dr, Launches.pif.1.dr | String found in binary or memory: http://secure.globalsign.com/cacert/gstimestampingsha2g2.crt0 |
Source: RegAsm.exe, 00000010.00000002.3033364620.0000000002601000.00000004.00000800.00020000.00000000.sdmp | String found in binary or memory: http://tempuri.org/ |
Source: RegAsm.exe, 00000010.00000002.3033364620.0000000002601000.00000004.00000800.00020000.00000000.sdmp | String found in binary or memory: http://tempuri.org/Entity/ |
Source: RegAsm.exe, 00000010.00000002.3033364620.0000000002601000.00000004.00000800.00020000.00000000.sdmp | String found in binary or memory: http://tempuri.org/Entity/Id10LRfq |
Source: RegAsm.exe, 00000010.00000002.3033364620.0000000002601000.00000004.00000800.00020000.00000000.sdmp | String found in binary or memory: http://tempuri.org/Entity/Id10Responsex |
Source: RegAsm.exe, 00000010.00000002.3033364620.0000000002601000.00000004.00000800.00020000.00000000.sdmp | String found in binary or memory: http://tempuri.org/Entity/Id11LRfq |
Source: RegAsm.exe, 00000010.00000002.3033364620.0000000002601000.00000004.00000800.00020000.00000000.sdmp | String found in binary or memory: http://tempuri.org/Entity/Id11Responsex |
Source: RegAsm.exe, 00000010.00000002.3033364620.0000000002601000.00000004.00000800.00020000.00000000.sdmp | String found in binary or memory: http://tempuri.org/Entity/Id12LRfq |
Source: RegAsm.exe, 00000010.00000002.3033364620.0000000002601000.00000004.00000800.00020000.00000000.sdmp | String found in binary or memory: http://tempuri.org/Entity/Id12Responsex |
Source: RegAsm.exe, 00000010.00000002.3033364620.0000000002601000.00000004.00000800.00020000.00000000.sdmp | String found in binary or memory: http://tempuri.org/Entity/Id13LRfq |
Source: RegAsm.exe, 00000010.00000002.3033364620.0000000002601000.00000004.00000800.00020000.00000000.sdmp | String found in binary or memory: http://tempuri.org/Entity/Id13Responsex |
Source: RegAsm.exe, 00000010.00000002.3033364620.0000000002601000.00000004.00000800.00020000.00000000.sdmp | String found in binary or memory: http://tempuri.org/Entity/Id14LRfq |
Source: RegAsm.exe, 00000010.00000002.3033364620.0000000002601000.00000004.00000800.00020000.00000000.sdmp | String found in binary or memory: http://tempuri.org/Entity/Id14Responsex |
Source: RegAsm.exe, 00000010.00000002.3033364620.0000000002601000.00000004.00000800.00020000.00000000.sdmp | String found in binary or memory: http://tempuri.org/Entity/Id15LRfqx/j |
Source: RegAsm.exe, 00000010.00000002.3033364620.0000000002601000.00000004.00000800.00020000.00000000.sdmp | String found in binary or memory: http://tempuri.org/Entity/Id15Responsex |
Source: RegAsm.exe, 00000010.00000002.3033364620.0000000002601000.00000004.00000800.00020000.00000000.sdmp | String found in binary or memory: http://tempuri.org/Entity/Id16LRfq |
Source: RegAsm.exe, 00000010.00000002.3033364620.0000000002601000.00000004.00000800.00020000.00000000.sdmp | String found in binary or memory: http://tempuri.org/Entity/Id16Responsex |
Source: RegAsm.exe, 00000010.00000002.3033364620.0000000002601000.00000004.00000800.00020000.00000000.sdmp | String found in binary or memory: http://tempuri.org/Entity/Id17LRfq |
Source: RegAsm.exe, 00000010.00000002.3033364620.0000000002601000.00000004.00000800.00020000.00000000.sdmp | String found in binary or memory: http://tempuri.org/Entity/Id17Responsex |
Source: RegAsm.exe, 00000010.00000002.3033364620.0000000002601000.00000004.00000800.00020000.00000000.sdmp | String found in binary or memory: http://tempuri.org/Entity/Id18LRfq |
Source: RegAsm.exe, 00000010.00000002.3033364620.0000000002601000.00000004.00000800.00020000.00000000.sdmp | String found in binary or memory: http://tempuri.org/Entity/Id18Responsex |
Source: RegAsm.exe, 00000010.00000002.3033364620.0000000002601000.00000004.00000800.00020000.00000000.sdmp | String found in binary or memory: http://tempuri.org/Entity/Id19LRfq |
Source: RegAsm.exe, 00000010.00000002.3033364620.0000000002601000.00000004.00000800.00020000.00000000.sdmp | String found in binary or memory: http://tempuri.org/Entity/Id19Responsex |
Source: RegAsm.exe, 00000010.00000002.3033364620.0000000002601000.00000004.00000800.00020000.00000000.sdmp | String found in binary or memory: http://tempuri.org/Entity/Id1LRfq4 |
Source: RegAsm.exe, 00000010.00000002.3033364620.0000000002601000.00000004.00000800.00020000.00000000.sdmp | String found in binary or memory: http://tempuri.org/Entity/Id1Responsex |
Source: RegAsm.exe, 00000010.00000002.3033364620.0000000002601000.00000004.00000800.00020000.00000000.sdmp | String found in binary or memory: http://tempuri.org/Entity/Id20LRfq |
Source: RegAsm.exe, 00000010.00000002.3033364620.0000000002601000.00000004.00000800.00020000.00000000.sdmp | String found in binary or memory: http://tempuri.org/Entity/Id20Responsex |
Source: RegAsm.exe, 00000010.00000002.3033364620.0000000002601000.00000004.00000800.00020000.00000000.sdmp | String found in binary or memory: http://tempuri.org/Entity/Id21LRfqduj |
Source: RegAsm.exe, 00000010.00000002.3033364620.0000000002601000.00000004.00000800.00020000.00000000.sdmp | String found in binary or memory: http://tempuri.org/Entity/Id21Responsex |
Source: RegAsm.exe, 00000010.00000002.3033364620.0000000002601000.00000004.00000800.00020000.00000000.sdmp | String found in binary or memory: http://tempuri.org/Entity/Id22LRfq |
Source: RegAsm.exe, 00000010.00000002.3033364620.0000000002601000.00000004.00000800.00020000.00000000.sdmp | String found in binary or memory: http://tempuri.org/Entity/Id22Responsex |
Source: RegAsm.exe, 00000010.00000002.3033364620.0000000002601000.00000004.00000800.00020000.00000000.sdmp | String found in binary or memory: http://tempuri.org/Entity/Id23LRfq |
Source: RegAsm.exe, 00000010.00000002.3033364620.0000000002601000.00000004.00000800.00020000.00000000.sdmp | String found in binary or memory: http://tempuri.org/Entity/Id23Responsex |
Source: RegAsm.exe, 00000010.00000002.3033364620.0000000002601000.00000004.00000800.00020000.00000000.sdmp | String found in binary or memory: http://tempuri.org/Entity/Id24LRfq |
Source: RegAsm.exe, 00000010.00000002.3033364620.0000000002601000.00000004.00000800.00020000.00000000.sdmp | String found in binary or memory: http://tempuri.org/Entity/Id24Responsex |
Source: RegAsm.exe, 00000010.00000002.3033364620.0000000002601000.00000004.00000800.00020000.00000000.sdmp | String found in binary or memory: http://tempuri.org/Entity/Id2LRfq |
Source: RegAsm.exe, 00000010.00000002.3033364620.0000000002601000.00000004.00000800.00020000.00000000.sdmp | String found in binary or memory: http://tempuri.org/Entity/Id2Responsex |
Source: RegAsm.exe, 00000010.00000002.3033364620.0000000002601000.00000004.00000800.00020000.00000000.sdmp | String found in binary or memory: http://tempuri.org/Entity/Id3LRfq |
Source: RegAsm.exe, 00000010.00000002.3033364620.0000000002601000.00000004.00000800.00020000.00000000.sdmp | String found in binary or memory: http://tempuri.org/Entity/Id3Responsex |
Source: RegAsm.exe, 00000010.00000002.3033364620.0000000002601000.00000004.00000800.00020000.00000000.sdmp | String found in binary or memory: http://tempuri.org/Entity/Id4LRfq |
Source: RegAsm.exe, 00000010.00000002.3033364620.0000000002601000.00000004.00000800.00020000.00000000.sdmp | String found in binary or memory: http://tempuri.org/Entity/Id4Responsex |
Source: RegAsm.exe, 00000010.00000002.3033364620.0000000002601000.00000004.00000800.00020000.00000000.sdmp | String found in binary or memory: http://tempuri.org/Entity/Id5LRfq |
Source: RegAsm.exe, 00000010.00000002.3033364620.0000000002601000.00000004.00000800.00020000.00000000.sdmp | String found in binary or memory: http://tempuri.org/Entity/Id5Responsex |
Source: RegAsm.exe, 00000010.00000002.3033364620.0000000002601000.00000004.00000800.00020000.00000000.sdmp | String found in binary or memory: http://tempuri.org/Entity/Id6LRfq |
Source: RegAsm.exe, 00000010.00000002.3033364620.0000000002601000.00000004.00000800.00020000.00000000.sdmp | String found in binary or memory: http://tempuri.org/Entity/Id6Responsex |
Source: RegAsm.exe, 00000010.00000002.3033364620.0000000002601000.00000004.00000800.00020000.00000000.sdmp | String found in binary or memory: http://tempuri.org/Entity/Id7LRfqx |
Source: RegAsm.exe, 00000010.00000002.3033364620.0000000002601000.00000004.00000800.00020000.00000000.sdmp | String found in binary or memory: http://tempuri.org/Entity/Id7Responsex |
Source: RegAsm.exe, 00000010.00000002.3033364620.0000000002601000.00000004.00000800.00020000.00000000.sdmp | String found in binary or memory: http://tempuri.org/Entity/Id8LRfq |
Source: RegAsm.exe, 00000010.00000002.3033364620.0000000002601000.00000004.00000800.00020000.00000000.sdmp | String found in binary or memory: http://tempuri.org/Entity/Id8Responsex |
Source: RegAsm.exe, 00000010.00000002.3033364620.0000000002601000.00000004.00000800.00020000.00000000.sdmp | String found in binary or memory: http://tempuri.org/Entity/Id9LRfq |
Source: RegAsm.exe, 00000010.00000002.3033364620.0000000002601000.00000004.00000800.00020000.00000000.sdmp | String found in binary or memory: http://tempuri.org/Entity/Id9Responsex |
Source: GOmRjFSKNz.exe, 00000000.00000003.1781635044.0000000002886000.00000004.00000020.00020000.00000000.sdmp, Launches.pif, 0000000A.00000000.1818602986.0000000000809000.00000002.00000001.01000000.00000006.sdmp, Carol.0.dr, Launches.pif.1.dr | String found in binary or memory: http://www.autoitscript.com/autoit3/J |
Source: Launches.pif, 0000000A.00000003.2825065700.0000000001DDD000.00000004.00000800.00020000.00000000.sdmp, Launches.pif, 0000000A.00000003.2833770879.0000000001F91000.00000004.00000800.00020000.00000000.sdmp, Launches.pif, 0000000A.00000003.2825546542.000000000519F000.00000004.00000800.00020000.00000000.sdmp, Launches.pif, 0000000A.00000003.2825688213.0000000001E5B000.00000004.00000800.00020000.00000000.sdmp, Launches.pif, 0000000A.00000003.2882687318.0000000001DD3000.00000004.00000800.00020000.00000000.sdmp, Launches.pif, 0000000A.00000003.2882687318.0000000001D91000.00000004.00000800.00020000.00000000.sdmp, Launches.pif, 0000000A.00000003.2833826824.000000000449B000.00000004.00000800.00020000.00000000.sdmp, Launches.pif, 0000000A.00000003.2884666788.0000000001DDC000.00000004.00000800.00020000.00000000.sdmp, Launches.pif, 0000000A.00000003.2833895594.0000000004418000.00000004.00000800.00020000.00000000.sdmp, Launches.pif, 0000000A.00000003.2884574282.0000000001E5C000.00000004.00000800.00020000.00000000.sdmp, RegAsm.exe, 00000010.00000002.3032255109.0000000000342000.00000040.00000400.00020000.00000000.sdmp | String found in binary or memory: https://api.ip.sb/ip |
Source: GOmRjFSKNz.exe, 00000000.00000003.1781635044.0000000002886000.00000004.00000020.00020000.00000000.sdmp, Carol.0.dr, Launches.pif.1.dr | String found in binary or memory: https://www.autoitscript.com/autoit3/ |
Source: Launches.pif.1.dr | String found in binary or memory: https://www.globalsign.com/repository/0 |
Source: GOmRjFSKNz.exe, 00000000.00000003.1781635044.0000000002886000.00000004.00000020.00020000.00000000.sdmp, Carol.0.dr, Launches.pif.1.dr | String found in binary or memory: https://www.globalsign.com/repository/06 |
Source: C:\Users\user\Desktop\GOmRjFSKNz.exe | Code function: 0_2_0040497C | 0_2_0040497C |
Source: C:\Users\user\Desktop\GOmRjFSKNz.exe | Code function: 0_2_00406ED2 | 0_2_00406ED2 |
Source: C:\Users\user\Desktop\GOmRjFSKNz.exe | Code function: 0_2_004074BB | 0_2_004074BB |
Source: C:\Users\user\AppData\Local\Temp\72076\Launches.pif | Code function: 10_2_0074B020 | 10_2_0074B020 |
Source: C:\Users\user\AppData\Local\Temp\72076\Launches.pif | Code function: 10_2_007494E0 | 10_2_007494E0 |
Source: C:\Users\user\AppData\Local\Temp\72076\Launches.pif | Code function: 10_2_00749C80 | 10_2_00749C80 |
Source: C:\Users\user\AppData\Local\Temp\72076\Launches.pif | Code function: 10_2_007623F5 | 10_2_007623F5 |
Source: C:\Users\user\AppData\Local\Temp\72076\Launches.pif | Code function: 10_2_007C8400 | 10_2_007C8400 |
Source: C:\Users\user\AppData\Local\Temp\72076\Launches.pif | Code function: 10_2_00776502 | 10_2_00776502 |
Source: C:\Users\user\AppData\Local\Temp\72076\Launches.pif | Code function: 10_2_0077265E | 10_2_0077265E |
Source: C:\Users\user\AppData\Local\Temp\72076\Launches.pif | Code function: 10_2_0074E6F0 | 10_2_0074E6F0 |
Source: C:\Users\user\AppData\Local\Temp\72076\Launches.pif | Code function: 10_2_0076282A | 10_2_0076282A |
Source: C:\Users\user\AppData\Local\Temp\72076\Launches.pif | Code function: 10_2_007789BF | 10_2_007789BF |
Source: C:\Users\user\AppData\Local\Temp\72076\Launches.pif | Code function: 10_2_00776A74 | 10_2_00776A74 |
Source: C:\Users\user\AppData\Local\Temp\72076\Launches.pif | Code function: 10_2_007C0A3A | 10_2_007C0A3A |
Source: C:\Users\user\AppData\Local\Temp\72076\Launches.pif | Code function: 10_2_00750BE0 | 10_2_00750BE0 |
Source: C:\Users\user\AppData\Local\Temp\72076\Launches.pif | Code function: 10_2_0076CD51 | 10_2_0076CD51 |
Source: C:\Users\user\AppData\Local\Temp\72076\Launches.pif | Code function: 10_2_0079EDB2 | 10_2_0079EDB2 |
Source: C:\Users\user\AppData\Local\Temp\72076\Launches.pif | Code function: 10_2_007A8E44 | 10_2_007A8E44 |
Source: C:\Users\user\AppData\Local\Temp\72076\Launches.pif | Code function: 10_2_007C0EB7 | 10_2_007C0EB7 |
Source: C:\Users\user\AppData\Local\Temp\72076\Launches.pif | Code function: 10_2_00776FE6 | 10_2_00776FE6 |
Source: C:\Users\user\AppData\Local\Temp\72076\Launches.pif | Code function: 10_2_007633B7 | 10_2_007633B7 |
Source: C:\Users\user\AppData\Local\Temp\72076\Launches.pif | Code function: 10_2_0075D45D | 10_2_0075D45D |
Source: C:\Users\user\AppData\Local\Temp\72076\Launches.pif | Code function: 10_2_0076F409 | 10_2_0076F409 |
Source: C:\Users\user\AppData\Local\Temp\72076\Launches.pif | Code function: 10_2_00741663 | 10_2_00741663 |
Source: C:\Users\user\AppData\Local\Temp\72076\Launches.pif | Code function: 10_2_0075F628 | 10_2_0075F628 |
Source: C:\Users\user\AppData\Local\Temp\72076\Launches.pif | Code function: 10_2_007616B4 | 10_2_007616B4 |
Source: C:\Users\user\AppData\Local\Temp\72076\Launches.pif | Code function: 10_2_0074F6A0 | 10_2_0074F6A0 |
Source: C:\Users\user\AppData\Local\Temp\72076\Launches.pif | Code function: 10_2_007678C3 | 10_2_007678C3 |
Source: C:\Users\user\AppData\Local\Temp\72076\Launches.pif | Code function: 10_2_0076DBA5 | 10_2_0076DBA5 |
Source: C:\Users\user\AppData\Local\Temp\72076\Launches.pif | Code function: 10_2_00761BA8 | 10_2_00761BA8 |
Source: C:\Users\user\AppData\Local\Temp\72076\Launches.pif | Code function: 10_2_00779CE5 | 10_2_00779CE5 |
Source: C:\Users\user\AppData\Local\Temp\72076\Launches.pif | Code function: 10_2_0075DD28 | 10_2_0075DD28 |
Source: C:\Users\user\AppData\Local\Temp\72076\Launches.pif | Code function: 10_2_0076BFD6 | 10_2_0076BFD6 |
Source: C:\Users\user\AppData\Local\Temp\72076\Launches.pif | Code function: 10_2_00761FC0 | 10_2_00761FC0 |
Source: C:\Users\user\AppData\Local\Temp\72076\RegAsm.exe | Code function: 16_2_00BBDC74 | 16_2_00BBDC74 |
Source: C:\Users\user\AppData\Local\Temp\72076\RegAsm.exe | Code function: 16_2_05DA67D8 | 16_2_05DA67D8 |
Source: C:\Users\user\AppData\Local\Temp\72076\RegAsm.exe | Code function: 16_2_05DAA3E8 | 16_2_05DAA3E8 |
Source: C:\Users\user\AppData\Local\Temp\72076\RegAsm.exe | Code function: 16_2_05DAA3D8 | 16_2_05DAA3D8 |
Source: C:\Users\user\AppData\Local\Temp\72076\RegAsm.exe | Code function: 16_2_05DA6FF8 | 16_2_05DA6FF8 |
Source: C:\Users\user\AppData\Local\Temp\72076\RegAsm.exe | Code function: 16_2_05DA6FE8 | 16_2_05DA6FE8 |
Source: unknown | Process created: C:\Users\user\Desktop\GOmRjFSKNz.exe "C:\Users\user\Desktop\GOmRjFSKNz.exe" | |
Source: C:\Users\user\Desktop\GOmRjFSKNz.exe | Process created: C:\Windows\SysWOW64\cmd.exe "C:\Windows\System32\cmd.exe" /c move Pediatric Pediatric.bat & Pediatric.bat | |
Source: C:\Windows\SysWOW64\cmd.exe | Process created: C:\Windows\System32\conhost.exe C:\Windows\system32\conhost.exe 0xffffffff -ForceV1 | |
Source: C:\Windows\SysWOW64\cmd.exe | Process created: C:\Windows\SysWOW64\tasklist.exe tasklist | |
Source: C:\Windows\SysWOW64\cmd.exe | Process created: C:\Windows\SysWOW64\findstr.exe findstr /I "wrsa opssvc" | |
Source: C:\Windows\SysWOW64\cmd.exe | Process created: C:\Windows\SysWOW64\tasklist.exe tasklist | |
Source: C:\Windows\SysWOW64\cmd.exe | Process created: C:\Windows\SysWOW64\findstr.exe findstr /I "avastui avgui bdservicehost nswscsvc sophoshealth" | |
Source: C:\Windows\SysWOW64\cmd.exe | Process created: C:\Windows\SysWOW64\cmd.exe cmd /c md 72076 | |
Source: C:\Windows\SysWOW64\cmd.exe | Process created: C:\Windows\SysWOW64\findstr.exe findstr /V "SILICONLATINOAMPLANDBLOW" Words | |
Source: C:\Windows\SysWOW64\cmd.exe | Process created: C:\Windows\SysWOW64\cmd.exe cmd /c copy /b ..\Indoor + ..\An + ..\Transport + ..\Strap + ..\Passed + ..\Treasure s | |
Source: C:\Windows\SysWOW64\cmd.exe | Process created: C:\Users\user\AppData\Local\Temp\72076\Launches.pif Launches.pif s | |
Source: C:\Windows\SysWOW64\cmd.exe | Process created: C:\Windows\SysWOW64\choice.exe choice /d y /t 5 | |
Source: C:\Users\user\AppData\Local\Temp\72076\Launches.pif | Process created: C:\Users\user\AppData\Local\Temp\72076\RegAsm.exe C:\Users\user\AppData\Local\Temp\72076\RegAsm.exe | |
Source: C:\Users\user\Desktop\GOmRjFSKNz.exe | Process created: C:\Windows\SysWOW64\cmd.exe "C:\Windows\System32\cmd.exe" /c move Pediatric Pediatric.bat & Pediatric.bat | Jump to behavior |
Source: C:\Windows\SysWOW64\cmd.exe | Process created: C:\Windows\SysWOW64\tasklist.exe tasklist | Jump to behavior |
Source: C:\Windows\SysWOW64\cmd.exe | Process created: C:\Windows\SysWOW64\findstr.exe findstr /I "wrsa opssvc" | Jump to behavior |
Source: C:\Windows\SysWOW64\cmd.exe | Process created: C:\Windows\SysWOW64\tasklist.exe tasklist | Jump to behavior |
Source: C:\Windows\SysWOW64\cmd.exe | Process created: C:\Windows\SysWOW64\findstr.exe findstr /I "avastui avgui bdservicehost nswscsvc sophoshealth" | Jump to behavior |
Source: C:\Windows\SysWOW64\cmd.exe | Process created: C:\Windows\SysWOW64\cmd.exe cmd /c md 72076 | Jump to behavior |
Source: C:\Windows\SysWOW64\cmd.exe | Process created: C:\Windows\SysWOW64\findstr.exe findstr /V "SILICONLATINOAMPLANDBLOW" Words | Jump to behavior |
Source: C:\Windows\SysWOW64\cmd.exe | Process created: C:\Windows\SysWOW64\cmd.exe cmd /c copy /b ..\Indoor + ..\An + ..\Transport + ..\Strap + ..\Passed + ..\Treasure s | Jump to behavior |
Source: C:\Windows\SysWOW64\cmd.exe | Process created: C:\Users\user\AppData\Local\Temp\72076\Launches.pif Launches.pif s | Jump to behavior |
Source: C:\Windows\SysWOW64\cmd.exe | Process created: C:\Windows\SysWOW64\choice.exe choice /d y /t 5 | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\72076\Launches.pif | Process created: C:\Users\user\AppData\Local\Temp\72076\RegAsm.exe C:\Users\user\AppData\Local\Temp\72076\RegAsm.exe | Jump to behavior |
Source: C:\Users\user\Desktop\GOmRjFSKNz.exe | Section loaded: apphelp.dll | Jump to behavior |
Source: C:\Users\user\Desktop\GOmRjFSKNz.exe | Section loaded: version.dll | Jump to behavior |
Source: C:\Users\user\Desktop\GOmRjFSKNz.exe | Section loaded: kernel.appcore.dll | Jump to behavior |
Source: C:\Users\user\Desktop\GOmRjFSKNz.exe | Section loaded: uxtheme.dll | Jump to behavior |
Source: C:\Users\user\Desktop\GOmRjFSKNz.exe | Section loaded: shfolder.dll | Jump to behavior |
Source: C:\Users\user\Desktop\GOmRjFSKNz.exe | Section loaded: windows.storage.dll | Jump to behavior |
Source: C:\Users\user\Desktop\GOmRjFSKNz.exe | Section loaded: wldp.dll | Jump to behavior |
Source: C:\Users\user\Desktop\GOmRjFSKNz.exe | Section loaded: propsys.dll | Jump to behavior |
Source: C:\Users\user\Desktop\GOmRjFSKNz.exe | Section loaded: riched20.dll | Jump to behavior |
Source: C:\Users\user\Desktop\GOmRjFSKNz.exe | Section loaded: usp10.dll | Jump to behavior |
Source: C:\Users\user\Desktop\GOmRjFSKNz.exe | Section loaded: msls31.dll | Jump to behavior |
Source: C:\Users\user\Desktop\GOmRjFSKNz.exe | Section loaded: textinputframework.dll | Jump to behavior |
Source: C:\Users\user\Desktop\GOmRjFSKNz.exe | Section loaded: coreuicomponents.dll | Jump to behavior |
Source: C:\Users\user\Desktop\GOmRjFSKNz.exe | Section loaded: coremessaging.dll | Jump to behavior |
Source: C:\Users\user\Desktop\GOmRjFSKNz.exe | Section loaded: ntmarta.dll | Jump to behavior |
Source: C:\Users\user\Desktop\GOmRjFSKNz.exe | Section loaded: coremessaging.dll | Jump to behavior |
Source: C:\Users\user\Desktop\GOmRjFSKNz.exe | Section loaded: wintypes.dll | Jump to behavior |
Source: C:\Users\user\Desktop\GOmRjFSKNz.exe | Section loaded: wintypes.dll | Jump to behavior |
Source: C:\Users\user\Desktop\GOmRjFSKNz.exe | Section loaded: wintypes.dll | Jump to behavior |
Source: C:\Users\user\Desktop\GOmRjFSKNz.exe | Section loaded: textshaping.dll | Jump to behavior |
Source: C:\Users\user\Desktop\GOmRjFSKNz.exe | Section loaded: profapi.dll | Jump to behavior |
Source: C:\Users\user\Desktop\GOmRjFSKNz.exe | Section loaded: edputil.dll | Jump to behavior |
Source: C:\Users\user\Desktop\GOmRjFSKNz.exe | Section loaded: urlmon.dll | Jump to behavior |
Source: C:\Users\user\Desktop\GOmRjFSKNz.exe | Section loaded: iertutil.dll | Jump to behavior |
Source: C:\Users\user\Desktop\GOmRjFSKNz.exe | Section loaded: srvcli.dll | Jump to behavior |
Source: C:\Users\user\Desktop\GOmRjFSKNz.exe | Section loaded: netutils.dll | Jump to behavior |
Source: C:\Users\user\Desktop\GOmRjFSKNz.exe | Section loaded: windows.staterepositoryps.dll | Jump to behavior |
Source: C:\Users\user\Desktop\GOmRjFSKNz.exe | Section loaded: sspicli.dll | Jump to behavior |
Source: C:\Users\user\Desktop\GOmRjFSKNz.exe | Section loaded: appresolver.dll | Jump to behavior |
Source: C:\Users\user\Desktop\GOmRjFSKNz.exe | Section loaded: bcp47langs.dll | Jump to behavior |
Source: C:\Users\user\Desktop\GOmRjFSKNz.exe | Section loaded: slc.dll | Jump to behavior |
Source: C:\Users\user\Desktop\GOmRjFSKNz.exe | Section loaded: userenv.dll | Jump to behavior |
Source: C:\Users\user\Desktop\GOmRjFSKNz.exe | Section loaded: sppc.dll | Jump to behavior |
Source: C:\Users\user\Desktop\GOmRjFSKNz.exe | Section loaded: onecorecommonproxystub.dll | Jump to behavior |
Source: C:\Users\user\Desktop\GOmRjFSKNz.exe | Section loaded: onecoreuapcommonproxystub.dll | Jump to behavior |
Source: C:\Windows\SysWOW64\cmd.exe | Section loaded: cmdext.dll | Jump to behavior |
Source: C:\Windows\SysWOW64\cmd.exe | Section loaded: apphelp.dll | Jump to behavior |
Source: C:\Windows\SysWOW64\tasklist.exe | Section loaded: version.dll | Jump to behavior |
Source: C:\Windows\SysWOW64\tasklist.exe | Section loaded: mpr.dll | Jump to behavior |
Source: C:\Windows\SysWOW64\tasklist.exe | Section loaded: framedynos.dll | Jump to behavior |
Source: C:\Windows\SysWOW64\tasklist.exe | Section loaded: dbghelp.dll | Jump to behavior |
Source: C:\Windows\SysWOW64\tasklist.exe | Section loaded: sspicli.dll | Jump to behavior |
Source: C:\Windows\SysWOW64\tasklist.exe | Section loaded: srvcli.dll | Jump to behavior |
Source: C:\Windows\SysWOW64\tasklist.exe | Section loaded: netutils.dll | Jump to behavior |
Source: C:\Windows\SysWOW64\tasklist.exe | Section loaded: sspicli.dll | Jump to behavior |
Source: C:\Windows\SysWOW64\tasklist.exe | Section loaded: kernel.appcore.dll | Jump to behavior |
Source: C:\Windows\SysWOW64\tasklist.exe | Section loaded: wbemcomn.dll | Jump to behavior |
Source: C:\Windows\SysWOW64\tasklist.exe | Section loaded: winsta.dll | Jump to behavior |
Source: C:\Windows\SysWOW64\tasklist.exe | Section loaded: amsi.dll | Jump to behavior |
Source: C:\Windows\SysWOW64\tasklist.exe | Section loaded: userenv.dll | Jump to behavior |
Source: C:\Windows\SysWOW64\tasklist.exe | Section loaded: profapi.dll | Jump to behavior |
Source: C:\Windows\SysWOW64\tasklist.exe | Section loaded: version.dll | Jump to behavior |
Source: C:\Windows\SysWOW64\tasklist.exe | Section loaded: mpr.dll | Jump to behavior |
Source: C:\Windows\SysWOW64\tasklist.exe | Section loaded: framedynos.dll | Jump to behavior |
Source: C:\Windows\SysWOW64\tasklist.exe | Section loaded: dbghelp.dll | Jump to behavior |
Source: C:\Windows\SysWOW64\tasklist.exe | Section loaded: sspicli.dll | Jump to behavior |
Source: C:\Windows\SysWOW64\tasklist.exe | Section loaded: srvcli.dll | Jump to behavior |
Source: C:\Windows\SysWOW64\tasklist.exe | Section loaded: netutils.dll | Jump to behavior |
Source: C:\Windows\SysWOW64\tasklist.exe | Section loaded: sspicli.dll | Jump to behavior |
Source: C:\Windows\SysWOW64\tasklist.exe | Section loaded: kernel.appcore.dll | Jump to behavior |
Source: C:\Windows\SysWOW64\tasklist.exe | Section loaded: wbemcomn.dll | Jump to behavior |
Source: C:\Windows\SysWOW64\tasklist.exe | Section loaded: winsta.dll | Jump to behavior |
Source: C:\Windows\SysWOW64\tasklist.exe | Section loaded: amsi.dll | Jump to behavior |
Source: C:\Windows\SysWOW64\tasklist.exe | Section loaded: userenv.dll | Jump to behavior |
Source: C:\Windows\SysWOW64\tasklist.exe | Section loaded: profapi.dll | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\72076\Launches.pif | Section loaded: wsock32.dll | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\72076\Launches.pif | Section loaded: version.dll | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\72076\Launches.pif | Section loaded: winmm.dll | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\72076\Launches.pif | Section loaded: mpr.dll | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\72076\Launches.pif | Section loaded: wininet.dll | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\72076\Launches.pif | Section loaded: iphlpapi.dll | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\72076\Launches.pif | Section loaded: userenv.dll | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\72076\Launches.pif | Section loaded: uxtheme.dll | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\72076\Launches.pif | Section loaded: kernel.appcore.dll | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\72076\Launches.pif | Section loaded: windows.storage.dll | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\72076\Launches.pif | Section loaded: wldp.dll | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\72076\Launches.pif | Section loaded: napinsp.dll | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\72076\Launches.pif | Section loaded: pnrpnsp.dll | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\72076\Launches.pif | Section loaded: wshbth.dll | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\72076\Launches.pif | Section loaded: nlaapi.dll | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\72076\Launches.pif | Section loaded: mswsock.dll | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\72076\Launches.pif | Section loaded: dnsapi.dll | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\72076\Launches.pif | Section loaded: winrnr.dll | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\72076\Launches.pif | Section loaded: rasadhlp.dll | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\72076\Launches.pif | Section loaded: ntmarta.dll | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\72076\Launches.pif | Section loaded: apphelp.dll | Jump to behavior |
Source: C:\Windows\SysWOW64\choice.exe | Section loaded: version.dll | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\72076\RegAsm.exe | Section loaded: mscoree.dll | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\72076\RegAsm.exe | Section loaded: apphelp.dll | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\72076\RegAsm.exe | Section loaded: aclayers.dll | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\72076\RegAsm.exe | Section loaded: mpr.dll | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\72076\RegAsm.exe | Section loaded: sfc.dll | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\72076\RegAsm.exe | Section loaded: sfc_os.dll | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\72076\RegAsm.exe | Section loaded: kernel.appcore.dll | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\72076\RegAsm.exe | Section loaded: version.dll | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\72076\RegAsm.exe | Section loaded: vcruntime140_clr0400.dll | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\72076\RegAsm.exe | Section loaded: ucrtbase_clr0400.dll | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\72076\RegAsm.exe | Section loaded: ucrtbase_clr0400.dll | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\72076\RegAsm.exe | Section loaded: uxtheme.dll | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\72076\RegAsm.exe | Section loaded: windows.storage.dll | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\72076\RegAsm.exe | Section loaded: wldp.dll | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\72076\RegAsm.exe | Section loaded: profapi.dll | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\72076\RegAsm.exe | Section loaded: cryptsp.dll | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\72076\RegAsm.exe | Section loaded: rsaenh.dll | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\72076\RegAsm.exe | Section loaded: cryptbase.dll | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\72076\RegAsm.exe | Section loaded: dwrite.dll | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\72076\RegAsm.exe | Section loaded: msvcp140_clr0400.dll | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\72076\RegAsm.exe | Section loaded: msasn1.dll | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\72076\RegAsm.exe | Section loaded: msisip.dll | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\72076\RegAsm.exe | Section loaded: wshext.dll | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\72076\RegAsm.exe | Section loaded: appxsip.dll | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\72076\RegAsm.exe | Section loaded: opcservices.dll | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\72076\RegAsm.exe | Section loaded: esdsip.dll | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\72076\RegAsm.exe | Section loaded: userenv.dll | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\72076\RegAsm.exe | Section loaded: dpapi.dll | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\72076\RegAsm.exe | Section loaded: gpapi.dll | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\72076\RegAsm.exe | Section loaded: sxs.dll | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\72076\RegAsm.exe | Section loaded: scrrun.dll | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\72076\RegAsm.exe | Section loaded: propsys.dll | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\72076\RegAsm.exe | Section loaded: linkinfo.dll | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\72076\RegAsm.exe | Section loaded: mswsock.dll | Jump to behavior |
Source: C:\Users\user\Desktop\GOmRjFSKNz.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\GOmRjFSKNz.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\GOmRjFSKNz.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\GOmRjFSKNz.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\GOmRjFSKNz.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\GOmRjFSKNz.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\GOmRjFSKNz.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\GOmRjFSKNz.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\GOmRjFSKNz.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\GOmRjFSKNz.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\GOmRjFSKNz.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\GOmRjFSKNz.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\cmd.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\tasklist.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\tasklist.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\72076\Launches.pif | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\72076\Launches.pif | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\72076\Launches.pif | Process information set: FAILCRITICALERRORS | NOALIGNMENTFAULTEXCEPT | NOGPFAULTERRORBOX | NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\72076\RegAsm.exe | Process information set: NOALIGNMENTFAULTEXCEPT | NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\72076\RegAsm.exe | Process information set: NOALIGNMENTFAULTEXCEPT | NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\72076\RegAsm.exe | Process information set: NOALIGNMENTFAULTEXCEPT | NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\72076\RegAsm.exe | Process information set: NOALIGNMENTFAULTEXCEPT | NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\72076\RegAsm.exe | Process information set: NOALIGNMENTFAULTEXCEPT | NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\72076\RegAsm.exe | Process information set: NOALIGNMENTFAULTEXCEPT | NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\72076\RegAsm.exe | Process information set: NOALIGNMENTFAULTEXCEPT | NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\72076\RegAsm.exe | Process information set: NOALIGNMENTFAULTEXCEPT | NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\72076\RegAsm.exe | Process information set: NOALIGNMENTFAULTEXCEPT | NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\72076\RegAsm.exe | Process information set: NOALIGNMENTFAULTEXCEPT | NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\72076\RegAsm.exe | Process information set: NOALIGNMENTFAULTEXCEPT | NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\72076\RegAsm.exe | Process information set: NOALIGNMENTFAULTEXCEPT | NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\72076\RegAsm.exe | Process information set: NOALIGNMENTFAULTEXCEPT | NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\72076\RegAsm.exe | Process information set: NOALIGNMENTFAULTEXCEPT | NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\72076\RegAsm.exe | Process information set: NOALIGNMENTFAULTEXCEPT | NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\72076\RegAsm.exe | Process information set: NOALIGNMENTFAULTEXCEPT | NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\72076\RegAsm.exe | Process information set: NOALIGNMENTFAULTEXCEPT | NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\72076\RegAsm.exe | Process information set: NOALIGNMENTFAULTEXCEPT | NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\72076\RegAsm.exe | Process information set: NOALIGNMENTFAULTEXCEPT | NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\72076\RegAsm.exe | Process information set: NOALIGNMENTFAULTEXCEPT | NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\72076\RegAsm.exe | Process information set: NOALIGNMENTFAULTEXCEPT | NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\72076\RegAsm.exe | Process information set: NOALIGNMENTFAULTEXCEPT | NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\72076\RegAsm.exe | Process information set: NOALIGNMENTFAULTEXCEPT | NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\72076\RegAsm.exe | Process information set: NOALIGNMENTFAULTEXCEPT | NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\72076\RegAsm.exe | Process information set: NOALIGNMENTFAULTEXCEPT | NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\72076\RegAsm.exe | Process information set: NOALIGNMENTFAULTEXCEPT | NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\72076\RegAsm.exe | Process information set: NOALIGNMENTFAULTEXCEPT | NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\72076\RegAsm.exe | Process information set: NOALIGNMENTFAULTEXCEPT | NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\72076\RegAsm.exe | Process information set: NOALIGNMENTFAULTEXCEPT | NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\72076\RegAsm.exe | Process information set: NOALIGNMENTFAULTEXCEPT | NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\72076\RegAsm.exe | Process information set: NOALIGNMENTFAULTEXCEPT | NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\72076\RegAsm.exe | Process information set: NOALIGNMENTFAULTEXCEPT | NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\72076\RegAsm.exe | Process information set: NOALIGNMENTFAULTEXCEPT | NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\72076\RegAsm.exe | Process information set: NOALIGNMENTFAULTEXCEPT | NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\72076\RegAsm.exe | Process information set: NOALIGNMENTFAULTEXCEPT | NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\72076\RegAsm.exe | Process information set: NOALIGNMENTFAULTEXCEPT | NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\72076\RegAsm.exe | Process information set: NOALIGNMENTFAULTEXCEPT | NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\72076\RegAsm.exe | Process information set: NOALIGNMENTFAULTEXCEPT | NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\72076\RegAsm.exe | Process information set: NOALIGNMENTFAULTEXCEPT | NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\72076\RegAsm.exe | Process information set: NOALIGNMENTFAULTEXCEPT | NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\72076\RegAsm.exe | Process information set: NOALIGNMENTFAULTEXCEPT | NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\72076\RegAsm.exe | Process information set: NOALIGNMENTFAULTEXCEPT | NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\72076\RegAsm.exe | Process information set: NOALIGNMENTFAULTEXCEPT | NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\72076\RegAsm.exe | Process information set: NOALIGNMENTFAULTEXCEPT | NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\72076\RegAsm.exe | Process information set: NOALIGNMENTFAULTEXCEPT | NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\72076\RegAsm.exe | Process information set: NOALIGNMENTFAULTEXCEPT | NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\72076\RegAsm.exe | Process information set: NOALIGNMENTFAULTEXCEPT | NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\72076\RegAsm.exe | Process information set: NOALIGNMENTFAULTEXCEPT | NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\72076\RegAsm.exe | Process information set: NOALIGNMENTFAULTEXCEPT | NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\72076\RegAsm.exe | Process information set: NOALIGNMENTFAULTEXCEPT | NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\72076\RegAsm.exe | Process information set: NOALIGNMENTFAULTEXCEPT | NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\72076\RegAsm.exe | Process information set: NOALIGNMENTFAULTEXCEPT | NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\72076\RegAsm.exe | Process information set: NOALIGNMENTFAULTEXCEPT | NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\72076\RegAsm.exe | Process information set: NOALIGNMENTFAULTEXCEPT | NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\72076\RegAsm.exe | Process information set: NOALIGNMENTFAULTEXCEPT | NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\72076\RegAsm.exe | Process information set: NOALIGNMENTFAULTEXCEPT | NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\72076\RegAsm.exe | Process information set: NOALIGNMENTFAULTEXCEPT | NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\72076\RegAsm.exe | Process information set: NOALIGNMENTFAULTEXCEPT | NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\72076\RegAsm.exe | Process information set: NOALIGNMENTFAULTEXCEPT | NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\72076\RegAsm.exe | Process information set: NOALIGNMENTFAULTEXCEPT | NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\GOmRjFSKNz.exe | Code function: 0_2_004062D5 FindFirstFileW,FindClose, | 0_2_004062D5 |
Source: C:\Users\user\Desktop\GOmRjFSKNz.exe | Code function: 0_2_00402E18 FindFirstFileW, | 0_2_00402E18 |
Source: C:\Users\user\Desktop\GOmRjFSKNz.exe | Code function: 0_2_00406C9B DeleteFileW,lstrcatW,lstrcatW,lstrcatW,lstrlenW,FindFirstFileW,DeleteFileW,FindNextFileW,FindClose,RemoveDirectoryW, | 0_2_00406C9B |
Source: C:\Users\user\AppData\Local\Temp\72076\Launches.pif | Code function: 10_2_007A4005 FindFirstFileW,DeleteFileW,FindNextFileW,FindClose,FindClose, | 10_2_007A4005 |
Source: C:\Users\user\AppData\Local\Temp\72076\Launches.pif | Code function: 10_2_007A494A GetFileAttributesW,FindFirstFileW,FindClose, | 10_2_007A494A |
Source: C:\Users\user\AppData\Local\Temp\72076\Launches.pif | Code function: 10_2_007A3CE2 FindFirstFileW,DeleteFileW,DeleteFileW,MoveFileW,DeleteFileW,FindNextFileW,FindClose,FindClose, | 10_2_007A3CE2 |
Source: C:\Users\user\AppData\Local\Temp\72076\Launches.pif | Code function: 10_2_007AC2FF FindFirstFileW,_wcscmp,_wcscmp,FindNextFileW,FindClose, | 10_2_007AC2FF |
Source: C:\Users\user\AppData\Local\Temp\72076\Launches.pif | Code function: 10_2_007ACD14 FindFirstFileW,FindClose, | 10_2_007ACD14 |
Source: C:\Users\user\AppData\Local\Temp\72076\Launches.pif | Code function: 10_2_007ACD9F FindFirstFileW,FindClose,FileTimeToLocalFileTime,FileTimeToLocalFileTime,FileTimeToLocalFileTime,FileTimeToSystemTime,__swprintf,__swprintf,__swprintf,__swprintf,__swprintf,__swprintf,__swprintf, | 10_2_007ACD9F |
Source: C:\Users\user\AppData\Local\Temp\72076\Launches.pif | Code function: 10_2_007AF5D8 SetCurrentDirectoryW,FindFirstFileW,FindFirstFileW,_wcscmp,_wcscmp,GetFileAttributesW,SetFileAttributesW,FindNextFileW,FindClose,FindFirstFileW,SetCurrentDirectoryW,_wcscmp,_wcscmp,SetCurrentDirectoryW,SetCurrentDirectoryW,FindNextFileW,FindClose,FindClose, | 10_2_007AF5D8 |
Source: C:\Users\user\AppData\Local\Temp\72076\Launches.pif | Code function: 10_2_007AF735 SetCurrentDirectoryW,FindFirstFileW,FindFirstFileW,_wcscmp,_wcscmp,FindNextFileW,FindClose,FindFirstFileW,SetCurrentDirectoryW,_wcscmp,_wcscmp,SetCurrentDirectoryW,SetCurrentDirectoryW,FindNextFileW,FindClose,FindClose, | 10_2_007AF735 |
Source: C:\Users\user\AppData\Local\Temp\72076\Launches.pif | Code function: 10_2_007AFA36 FindFirstFileW,Sleep,_wcscmp,_wcscmp,FindNextFileW,FindClose, | 10_2_007AFA36 |
Source: Yara match | File source: 10.3.Launches.pif.1ddc050.0.raw.unpack, type: UNPACKEDPE |
Source: Yara match | File source: 16.2.RegAsm.exe.340000.0.unpack, type: UNPACKEDPE |
Source: Yara match | File source: 10.3.Launches.pif.1ddc050.1.raw.unpack, type: UNPACKEDPE |
Source: Yara match | File source: 0000000A.00000003.2825546542.000000000519F000.00000004.00000800.00020000.00000000.sdmp, type: MEMORY |
Source: Yara match | File source: 0000000A.00000003.2833770879.0000000001F91000.00000004.00000800.00020000.00000000.sdmp, type: MEMORY |
Source: Yara match | File source: 0000000A.00000003.2825065700.0000000001DDD000.00000004.00000800.00020000.00000000.sdmp, type: MEMORY |
Source: Yara match | File source: 0000000A.00000003.2825688213.0000000001E5B000.00000004.00000800.00020000.00000000.sdmp, type: MEMORY |
Source: Yara match | File source: 0000000A.00000003.2824672801.0000000001E5B000.00000004.00000800.00020000.00000000.sdmp, type: MEMORY |
Source: Yara match | File source: 0000000A.00000003.2882687318.0000000001DD3000.00000004.00000800.00020000.00000000.sdmp, type: MEMORY |
Source: Yara match | File source: 00000010.00000002.3032255109.0000000000342000.00000040.00000400.00020000.00000000.sdmp, type: MEMORY |
Source: Yara match | File source: 0000000A.00000003.2882687318.0000000001D91000.00000004.00000800.00020000.00000000.sdmp, type: MEMORY |
Source: Yara match | File source: 0000000A.00000003.2825305490.0000000001D91000.00000004.00000800.00020000.00000000.sdmp, type: MEMORY |
Source: Yara match | File source: 0000000A.00000003.2825305490.0000000001DD3000.00000004.00000800.00020000.00000000.sdmp, type: MEMORY |
Source: Yara match | File source: 0000000A.00000003.2833826824.000000000449B000.00000004.00000800.00020000.00000000.sdmp, type: MEMORY |
Source: Yara match | File source: 0000000A.00000003.2884666788.0000000001DDC000.00000004.00000800.00020000.00000000.sdmp, type: MEMORY |
Source: Yara match | File source: 0000000A.00000003.2825915690.0000000001F91000.00000004.00000800.00020000.00000000.sdmp, type: MEMORY |
Source: Yara match | File source: 0000000A.00000003.2833895594.0000000004418000.00000004.00000800.00020000.00000000.sdmp, type: MEMORY |
Source: Yara match | File source: 0000000A.00000003.2884370254.0000000001F02000.00000004.00000800.00020000.00000000.sdmp, type: MEMORY |
Source: Yara match | File source: 0000000A.00000003.2884574282.0000000001E5C000.00000004.00000800.00020000.00000000.sdmp, type: MEMORY |
Source: Yara match | File source: Process Memory Space: Launches.pif PID: 4296, type: MEMORYSTR |
Source: Yara match | File source: Process Memory Space: RegAsm.exe PID: 1144, type: MEMORYSTR |
Source: Yara match | File source: 10.3.Launches.pif.1ddc050.0.raw.unpack, type: UNPACKEDPE |
Source: Yara match | File source: 16.2.RegAsm.exe.340000.0.unpack, type: UNPACKEDPE |
Source: Yara match | File source: 10.3.Launches.pif.1ddc050.1.raw.unpack, type: UNPACKEDPE |
Source: Yara match | File source: 0000000A.00000003.2825546542.000000000519F000.00000004.00000800.00020000.00000000.sdmp, type: MEMORY |
Source: Yara match | File source: 0000000A.00000003.2833770879.0000000001F91000.00000004.00000800.00020000.00000000.sdmp, type: MEMORY |
Source: Yara match | File source: 0000000A.00000003.2825065700.0000000001DDD000.00000004.00000800.00020000.00000000.sdmp, type: MEMORY |
Source: Yara match | File source: 0000000A.00000003.2825688213.0000000001E5B000.00000004.00000800.00020000.00000000.sdmp, type: MEMORY |
Source: Yara match | File source: 0000000A.00000003.2824672801.0000000001E5B000.00000004.00000800.00020000.00000000.sdmp, type: MEMORY |
Source: Yara match | File source: 0000000A.00000003.2882687318.0000000001DD3000.00000004.00000800.00020000.00000000.sdmp, type: MEMORY |
Source: Yara match | File source: 00000010.00000002.3032255109.0000000000342000.00000040.00000400.00020000.00000000.sdmp, type: MEMORY |
Source: Yara match | File source: 0000000A.00000003.2882687318.0000000001D91000.00000004.00000800.00020000.00000000.sdmp, type: MEMORY |
Source: Yara match | File source: 0000000A.00000003.2825305490.0000000001D91000.00000004.00000800.00020000.00000000.sdmp, type: MEMORY |
Source: Yara match | File source: 0000000A.00000003.2825305490.0000000001DD3000.00000004.00000800.00020000.00000000.sdmp, type: MEMORY |
Source: Yara match | File source: 0000000A.00000003.2833826824.000000000449B000.00000004.00000800.00020000.00000000.sdmp, type: MEMORY |
Source: Yara match | File source: 0000000A.00000003.2884666788.0000000001DDC000.00000004.00000800.00020000.00000000.sdmp, type: MEMORY |
Source: Yara match | File source: 0000000A.00000003.2825915690.0000000001F91000.00000004.00000800.00020000.00000000.sdmp, type: MEMORY |
Source: Yara match | File source: 0000000A.00000003.2833895594.0000000004418000.00000004.00000800.00020000.00000000.sdmp, type: MEMORY |
Source: Yara match | File source: 0000000A.00000003.2884370254.0000000001F02000.00000004.00000800.00020000.00000000.sdmp, type: MEMORY |
Source: Yara match | File source: 0000000A.00000003.2884574282.0000000001E5C000.00000004.00000800.00020000.00000000.sdmp, type: MEMORY |
Source: Yara match | File source: Process Memory Space: Launches.pif PID: 4296, type: MEMORYSTR |
Source: Yara match | File source: Process Memory Space: RegAsm.exe PID: 1144, type: MEMORYSTR |